HEX
Server: Apache
System: Linux br1102.hostgator.com.br 5.14.0-687.17.1.el9_8.x86_64 #1 SMP PREEMPT_DYNAMIC Mon Jun 22 07:21:26 EDT 2026 x86_64
User: rkcent87 (3754)
PHP: 8.3.32
Disabled: NONE
Upload Files
File: //usr/local/apache/error_log
[Tue Jul 21 07:18:36.939138 2026] [lsapi:notice] [pid 131539:tid 131539] mod_lsapi:  version 1.1-92
[Tue Jul 21 07:18:36.953002 2026] [:notice] [pid 229238:tid 229238] [host root@br1102.hostgator.com.br] mod_lsapi:  Selfstarter 229238 started
[Tue Jul 21 07:18:36.968117 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oppbrazil.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:36.969801 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: locadoracmd.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:36.975301 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbc.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:36.986411 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbr.com.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.000187 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: metodoatracaoconsciente.com.vanderleiasilva.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.002809 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sofiagheller1782846626000.argentajoias.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.003230 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sofiagheller1782846537000.argentajoias.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.008631 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: getveltrixhealth.com.shopmelhorcompraonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.010698 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: adloop.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.011229 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: contafic.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.011762 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: climadek.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.012155 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lojacasacosta.com.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.012687 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: voztricolor.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.013059 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arenaalphaville.com.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.013440 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rioclaroimovel.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.013806 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marketingderua.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.014352 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tabelionatoportoalegre.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.014911 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: learningsociety.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.015311 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: clubmarketplace.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.015824 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arenaalphaville.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.016189 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: app.itqmogiguacu.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.016554 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lp.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.017084 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.017586 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.meupsiquiatraonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.017954 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: empresas.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.018334 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: dizi.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.019035 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rdgoseguros.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.019419 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: diziseguros.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.024384 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rilicitacoes.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.024874 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rilicitacoes.com.br.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.025400 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: espaconeuroascensao.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.025925 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: espaconeuroascensao.com.br.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.029482 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sscoenper.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.029857 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ssvistorias.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.030205 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rastreamentobh.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.030678 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: locamotobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.031083 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: companhiatop.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.031611 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: acheservicos.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.031959 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aluguelmotobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.032315 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aluguelcarrobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.038650 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: patihipopressivo.com.patyhipopressivo.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.039052 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: patihipopressivo.com.br.patyhipopressivo.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.042857 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyer.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.043368 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyerapp.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.043749 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.044101 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vespnutricao.com.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.044615 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.com.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.044994 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.058469 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lojinhadoprofessor.lojinhadaprofessora.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.063100 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: leonardodossantoshen1782739753000.metropollitano.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.065416 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: unoperformancedigital.com.br.karenvieiramarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.065923 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jbms.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.066295 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: benti.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.066640 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: yuribenassi.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.067007 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: wbapoiocontabil.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.067361 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: movimenti.com.br.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.075782 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sigescala.com.sigescala.meusitehostgator.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.088879 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vivenciarempauta.vivenciarempauta.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.095190 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: 3d-surgery.3d-surgery.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.095709 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vivafinanceiras.com.br.vivafinanceira.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.100731 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: academycont.com.goldentrips40.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.103720 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: trendsol.com.br.fusoesaquisicoes.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.105919 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: libertysolutions.figempreendimentos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.108212 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: naturofarma.com.br.farmaciafarmula.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.108746 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: farmacianaturofarma.com.br.farmaciafarmula.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.109784 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: meuamordevoltaa.estriasnuncamaiss.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.110893 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atividadessprontas.online.estriasnuncamaiss.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.117266 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: esidiomass.com.br.eslanguageschool.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.117608 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: porondeeuestive.com.br.eslanguageschool.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.127856 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: deniltoncostasilva1748033966000.samanenergia.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.131936 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: santotchay.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.132314 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: santotchay.com.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.132803 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: osantotchay.com.br.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.133279 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oinglesdescomplicado.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.133613 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: brasilmotoeletrica.com.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.140891 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: thenexbr.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.156045 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: c5liberdades.store.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.156373 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtoswendell.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.156696 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtosnapromo.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.157682 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: c5liberdades.com.br.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.165334 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtosnapromo.com.br.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.170346 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: weddinglarissaefelipe.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.172967 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtoswendellcarvalho.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.173978 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: exclusivepromotiontoday.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.179789 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pandie.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.180189 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guarushop.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.180554 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guarushop2.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.180906 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olhobionico.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.181243 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pandoradango.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.181578 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guiadeoferta.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.181915 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fofoqueironews.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.182262 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: reidocouro.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.182628 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bloquetebrasil.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.182986 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: protetordegraxa.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.186237 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atom-growth.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.186731 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atom-growth.com.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.187239 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: confiancedigital.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.187590 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: buddyclub.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.188066 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gotavitaoriginal.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.188550 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: motoboyjaguariuna.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.189391 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jandiraemdestaque.com.br.jornaldagrandesp.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.205945 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbc.com.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.211715 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.213370 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sociooculto.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.213996 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: exnova.tech.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.214986 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.store.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.215371 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marlonbarreto.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.215706 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.216051 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atilafagundes.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.216393 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: suaconsulta.fun.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.217373 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: escolhasaudavel.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.218022 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinicius-schneider.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.218483 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sociooculto.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.218835 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olimposolar.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.219197 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nextfitjourney.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.219685 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: themaisonhommes.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.220036 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tamojuntomidias.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.220379 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gustvoferraritrader.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.220734 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marlonbarreto.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.221092 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: escolhasaudavel.shop.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.221450 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atilafagundes.online.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.221772 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinicius-schneider.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.222266 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mariabonfim1762105378000.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.222608 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gustvoferraritrader.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.223782 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: flowwshop.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.224296 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agmiz.com.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.224797 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: comecx.online.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.225163 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: flowwshop.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.226163 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.findcomp.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.226678 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: importeicomponentes.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.230534 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aede.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.231059 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: suora.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.231583 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: condmidia.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.232069 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: recowmenda.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.232538 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: valeuefalou.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.233040 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: trilhasdafe.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.233574 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bergsantana.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.234084 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: shyoftherock.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.234576 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pegueaestrada.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.235078 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nocaminhodafe.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.235578 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arielson.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.235929 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: amareloturquesa.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.236310 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: terraluna.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.236639 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: zooparquevet.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.236966 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nosnaestrada.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.356392 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fusoesaquisicoes.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.388508 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conairmfg.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.393193 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.425048 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: revistareflexopolitico.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.425922 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ethanslowell.com.infoalert.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.428022 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: evolvaa.online.evolia.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.430215 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bracks.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.434911 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: raimundol.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.438281 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conhecaonordeste.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.438637 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: overkotz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.438993 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lucaskotovicz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.439358 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: kotovicz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.442510 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agendazap.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.443716 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ebookswl.com.wendelleite.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.445752 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: empacta.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.446770 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: inovaeditorial.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.447432 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: volyoaudiobooks.com.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.450974 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: slapingles.com.teacheraleff.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.451295 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: speakinglikeapro.teacheraleff.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.451628 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: brasilcertdigital.tavarescont.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.455201 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: wenith.com.br.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.455745 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783665345000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.456319 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783664968000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.456881 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783664932000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.457296 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783569474000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.463485 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: solarisimplementos.com.solarisimplementos.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.465628 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: madmoholding.saojorgesiderurgia.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.469462 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: evolvaa.com.evolia.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.471339 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sulmov.com.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.471677 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: expovilhena.com.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.472049 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tinybooks.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.472401 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: planamoveis.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.472716 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: paulakaoana.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.473046 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: expovilhena.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.473373 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: muskintranet.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.473698 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: infonetelecom.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.474027 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agendamasutti.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.474357 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: politicabrasil.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.474672 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: acerteaquestao.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.474987 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mavieloeducacao.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.475312 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: noticiasrondonia.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.475638 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jornalbrasileiro.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.476001 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mavieloperformance.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.476354 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ceramicasantoaugusto.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.478138 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mrragrorepresentacoes.com.mrragrorepresentacoesltda.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.485402 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aprendizadosemlimites.store.peticoesvencedorasofc.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.492338 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gabivet24h.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.493014 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blessoriginal.com.br.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.493848 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marmorariasolare.com.br.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.534439 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: institutonwa.nwalouwacom.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.534971 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: deniansantos.com.nwalouwacom.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.535310 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fitconecta.academiausina.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.536016 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinculampe.com.br.academiausina.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.540891 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: camilajung.mktcouple.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.541693 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mixpedido.mixpdv.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.542055 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guianordestino.mixpdv.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.546784 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sulprimesc.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.547751 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: zyveria.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.548569 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: multicarsc.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.548920 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marquemarketing360.com.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.549430 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pontodooleomecanica.com.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.549756 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: capitalautocentermecanica.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.554173 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.554675 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.store.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.555033 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.online.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.580537 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rcv.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.580871 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rtdi.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.581200 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rego.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.581518 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: forte.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.581882 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: claret.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.582229 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: portali.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.582565 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mcstilo.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.582924 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: joaorocha.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.583277 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: emonteiro.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.583633 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: robertinho.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.583996 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: parqueprado.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.584330 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: asrealestate.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.584635 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lopeslascasas.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.584973 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rstlimoveis.com.br.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.585309 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: residencialvilaliviero.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.592319 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aengenhariadolucro.com.br.infoalert.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.626071 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: beautyline2.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.626798 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: thejapanway.com.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.627591 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: shopbestdaily.com.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.628944 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oferta.roncostop.com.br.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.629317 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: artix.locaiestetica.com.br.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.629691 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: camillasandrini1772124780000.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.639409 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: potencialilimitado.com.br.alzirarhein.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.645153 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.650666 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: triviaodontologi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.696384 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mastercatu.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.703942 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.796168 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 07:18:37.816865 2026] [qos:notice] [pid 131539:tid 131539] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Tue Jul 21 07:18:38.158005 2026] [http2:info] [pid 131539:tid 131539] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Tue Jul 21 07:18:38.165263 2026] [mpm_event:notice] [pid 131539:tid 131539] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Tue Jul 21 07:18:38.165274 2026] [core:notice] [pid 131539:tid 131539] AH00094: Command line: '/usr/sbin/httpd'
[Tue Jul 21 07:18:39.242454 2026] [http2:info] [pid 229246:tid 229246] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 07:18:39.263214 2026] [security2:error] [pid 229246:tid 229377] [client 20.206.105.145:36078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/file5.php"] [unique_id "al9HfyBMYeh5YLVG45xS4AAAAhU"]
[Tue Jul 21 07:18:39.263286 2026] [security2:error] [pid 229246:tid 229376] [client 20.151.10.161:21440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/hur.php"] [unique_id "al9HfyBMYeh5YLVG45xS3wAAAhQ"]
[Tue Jul 21 07:18:39.264101 2026] [security2:error] [pid 229246:tid 229382] [client 4.204.201.85:35425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/file31.php"] [unique_id "al9HfyBMYeh5YLVG45xS4gAAAho"]
[Tue Jul 21 07:18:39.264230 2026] [security2:error] [pid 229246:tid 229388] [client 184.75.221.3:41796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS5AAAAiA"]
[Tue Jul 21 07:18:39.264297 2026] [security2:error] [pid 229246:tid 229388] [client 184.75.221.3:41796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS5AAAAiA"]
[Tue Jul 21 07:18:39.264362 2026] [security2:error] [pid 229246:tid 229385] [client 20.151.10.161:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/fpwch.php"] [unique_id "al9HfyBMYeh5YLVG45xS4wAAAh0"]
[Tue Jul 21 07:18:39.265414 2026] [security2:error] [pid 229246:tid 229394] [client 20.197.192.193:23497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HfyBMYeh5YLVG45xS5gAAAiY"]
[Tue Jul 21 07:18:39.265496 2026] [security2:error] [pid 229246:tid 229397] [client 20.226.60.151:54542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/w3llscc.php"] [unique_id "al9HfyBMYeh5YLVG45xS5wAAAik"]
[Tue Jul 21 07:18:39.266891 2026] [security2:error] [pid 229246:tid 229391] [client 134.19.179.187:54518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS5QAAAiM"]
[Tue Jul 21 07:18:39.267007 2026] [security2:error] [pid 229246:tid 229391] [client 134.19.179.187:54518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS5QAAAiM"]
[Tue Jul 21 07:18:39.269217 2026] [security2:error] [pid 229246:tid 229400] [client 134.19.179.187:54534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS6QAAAiw"]
[Tue Jul 21 07:18:39.269294 2026] [security2:error] [pid 229246:tid 229400] [client 134.19.179.187:54534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS6QAAAiw"]
[Tue Jul 21 07:18:39.270864 2026] [security2:error] [pid 229246:tid 229409] [client 68.235.38.2:47492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS7QAAAjU"]
[Tue Jul 21 07:18:39.270974 2026] [security2:error] [pid 229246:tid 229409] [client 68.235.38.2:47492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xS7QAAAjU"]
[Tue Jul 21 07:18:39.272940 2026] [security2:error] [pid 229246:tid 229383] [client 20.197.192.193:8330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/dragonshell.php"] [unique_id "al9HfyBMYeh5YLVG45xS7gAAAhs"]
[Tue Jul 21 07:18:39.292516 2026] [security2:error] [pid 229246:tid 229454] [client 20.197.192.193:23520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HfyBMYeh5YLVG45xS8AAAAmI"]
[Tue Jul 21 07:18:39.330131 2026] [security2:error] [pid 229246:tid 229463] [client 20.197.192.193:24464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/dp.php"] [unique_id "al9HfyBMYeh5YLVG45xS-QAAAms"]
[Tue Jul 21 07:18:39.380111 2026] [security2:error] [pid 229246:tid 229470] [client 20.220.225.223:47860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/kq1.php"] [unique_id "al9HfyBMYeh5YLVG45xS_gAAAnI"]
[Tue Jul 21 07:18:39.384806 2026] [security2:error] [pid 229246:tid 229471] [client 20.197.192.193:24451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/old.php"] [unique_id "al9HfyBMYeh5YLVG45xS_wAAAnM"]
[Tue Jul 21 07:18:39.395779 2026] [security2:error] [pid 229246:tid 229259] [remote 85.208.96.208:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hauptmann.com.br"] [uri "/robots.txt"] [unique_id "al9HfyBMYeh5YLVG45xTBgACNgw"]
[Tue Jul 21 07:18:39.395959 2026] [security2:error] [pid 229246:tid 229410] [client 85.208.96.208:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hauptmann.com.br"] [uri "/robots.txt"] [unique_id "al9HfyBMYeh5YLVG45xTBgACNgw"]
[Tue Jul 21 07:18:39.399434 2026] [security2:error] [pid 229246:tid 229262] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTCgACOg8"]
[Tue Jul 21 07:18:39.399608 2026] [security2:error] [pid 229246:tid 229414] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTCgACOg8"]
[Tue Jul 21 07:18:39.413828 2026] [security2:error] [pid 229246:tid 229392] [client 173.252.95.25:59344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HfyBMYeh5YLVG45xTHgAAAiQ"]
[Tue Jul 21 07:18:39.415947 2026] [security2:error] [pid 229246:tid 229482] [client 74.7.175.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "senhordostelhados.site"] [uri "/cgi-sys/404.html"] [unique_id "al9HfyBMYeh5YLVG45xTHQAAAn4"]
[Tue Jul 21 07:18:39.418169 2026] [security2:error] [pid 229246:tid 229428] [client 74.7.175.160:36210] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "senhordostelhados.site"] [uri "/robots.txt"] [unique_id "al9HfyBMYeh5YLVG45xTCAACSA0"]
[Tue Jul 21 07:18:39.423966 2026] [security2:error] [pid 229246:tid 229280] [remote 195.26.244.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amandamorau.adv.br"] [uri "/wp-login.php"] [unique_id "al9HfyBMYeh5YLVG45xTJAACQiE"]
[Tue Jul 21 07:18:39.439131 2026] [core:alert] [pid 229246:tid 229495] [client 57.141.18.120:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:18:39.439205 2026] [security2:error] [pid 229246:tid 229496] [client 20.197.192.193:23493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/ms-new.php"] [unique_id "al9HfyBMYeh5YLVG45xTLAAAAow"]
[Tue Jul 21 07:18:39.474777 2026] [security2:error] [pid 229246:tid 229501] [client 20.197.192.193:23498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/track.php"] [unique_id "al9HfyBMYeh5YLVG45xTLwAAApE"]
[Tue Jul 21 07:18:39.506006 2026] [security2:error] [pid 229246:tid 229400] [client 20.197.192.193:24461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/2352356666.php"] [unique_id "al9HfyBMYeh5YLVG45xTMgAAAiw"]
[Tue Jul 21 07:18:39.518208 2026] [security2:error] [pid 229246:tid 229464] [client 209.141.34.121:64398] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "kettlebellevolution.com.br"] [uri "/"] [unique_id "al9HfyBMYeh5YLVG45xTMwAAAmw"]
[Tue Jul 21 07:18:39.534179 2026] [security2:error] [pid 229246:tid 229455] [client 20.197.192.193:23514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/pn.php"] [unique_id "al9HfyBMYeh5YLVG45xTNAAAAmM"]
[Tue Jul 21 07:18:39.550868 2026] [security2:error] [pid 229246:tid 229284] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTNQACTCU"]
[Tue Jul 21 07:18:39.551078 2026] [security2:error] [pid 229246:tid 229432] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTNQACTCU"]
[Tue Jul 21 07:18:39.563012 2026] [security2:error] [pid 229246:tid 229263] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTCwACQRA"]
[Tue Jul 21 07:18:39.563263 2026] [security2:error] [pid 229246:tid 229421] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTCwACQRA"]
[Tue Jul 21 07:18:39.568796 2026] [security2:error] [pid 229246:tid 229285] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTNgACNyY"]
[Tue Jul 21 07:18:39.568994 2026] [security2:error] [pid 229246:tid 229411] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTNgACNyY"]
[Tue Jul 21 07:18:39.573683 2026] [security2:error] [pid 229246:tid 229286] [remote 69.165.67.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.67.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "produto-express.com"] [uri "/index.php"] [unique_id "al9HfyBMYeh5YLVG45xTNwACLSc"], referer: https://produto-express.com
[Tue Jul 21 07:18:39.574656 2026] [security2:error] [pid 229246:tid 229384] [client 20.197.192.193:24021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-wpbak.php"] [unique_id "al9HfyBMYeh5YLVG45xTOAAAAhw"]
[Tue Jul 21 07:18:39.595698 2026] [security2:error] [pid 229246:tid 229408] [client 20.197.192.193:23538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/dr.php"] [unique_id "al9HfyBMYeh5YLVG45xTOgAAAjQ"]
[Tue Jul 21 07:18:39.599219 2026] [security2:error] [pid 229246:tid 229287] [remote 162.19.246.208:53218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTOQACbSg"]
[Tue Jul 21 07:18:39.599427 2026] [security2:error] [pid 229246:tid 229465] [client 162.19.246.208:53218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTOQACbSg"]
[Tue Jul 21 07:18:39.619979 2026] [security2:error] [pid 229246:tid 229470] [client 20.197.192.193:23499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/2x.php"] [unique_id "al9HfyBMYeh5YLVG45xTPAAAAnI"]
[Tue Jul 21 07:18:39.631186 2026] [security2:error] [pid 229246:tid 229474] [client 20.151.10.161:45972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/w2025.php"] [unique_id "al9HfyBMYeh5YLVG45xTPQAAAnY"]
[Tue Jul 21 07:18:39.644986 2026] [security2:error] [pid 229246:tid 229395] [client 20.197.192.193:23491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/kq1.php"] [unique_id "al9HfyBMYeh5YLVG45xTPwAAAic"]
[Tue Jul 21 07:18:39.672428 2026] [security2:error] [pid 229246:tid 229392] [client 20.197.192.193:24469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/zzz.php"] [unique_id "al9HfyBMYeh5YLVG45xTRAAAAiQ"]
[Tue Jul 21 07:18:39.672585 2026] [security2:error] [pid 229246:tid 229381] [client 35.205.139.29:58524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9HfyBMYeh5YLVG45xTQwAAAhk"]
[Tue Jul 21 07:18:39.699692 2026] [security2:error] [pid 229246:tid 229476] [client 20.197.192.193:24456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wicked.php"] [unique_id "al9HfyBMYeh5YLVG45xTRQAAAng"]
[Tue Jul 21 07:18:39.726833 2026] [security2:error] [pid 229246:tid 229491] [client 20.197.192.193:24462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/edit.php"] [unique_id "al9HfyBMYeh5YLVG45xTSQAAAoc"]
[Tue Jul 21 07:18:39.742181 2026] [security2:error] [pid 229246:tid 229494] [client 20.197.192.193:23504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/kua.php"] [unique_id "al9HfyBMYeh5YLVG45xTSgAAAoo"]
[Tue Jul 21 07:18:39.767032 2026] [security2:error] [pid 229246:tid 229496] [client 20.197.192.193:23502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/ez.php"] [unique_id "al9HfyBMYeh5YLVG45xTSwAAAow"]
[Tue Jul 21 07:18:39.788940 2026] [security2:error] [pid 229246:tid 229486] [client 20.197.192.193:24455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/fz.php"] [unique_id "al9HfyBMYeh5YLVG45xTTAAAAoI"]
[Tue Jul 21 07:18:39.817657 2026] [security2:error] [pid 229246:tid 229444] [client 20.197.192.193:24466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/la.php"] [unique_id "al9HfyBMYeh5YLVG45xTTQAAAlg"]
[Tue Jul 21 07:18:39.875456 2026] [security2:error] [pid 229246:tid 229382] [client 20.197.192.193:23532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/nhvoanpl.php"] [unique_id "al9HfyBMYeh5YLVG45xTUgAAAho"]
[Tue Jul 21 07:18:39.895824 2026] [security2:error] [pid 229246:tid 229391] [client 20.197.192.193:23537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/inso.php"] [unique_id "al9HfyBMYeh5YLVG45xTUwAAAiM"]
[Tue Jul 21 07:18:39.919973 2026] [security2:error] [pid 229246:tid 229502] [client 20.197.192.193:23495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wpx.php"] [unique_id "al9HfyBMYeh5YLVG45xTVQAAApI"]
[Tue Jul 21 07:18:39.921822 2026] [security2:error] [pid 229246:tid 229420] [client 14.139.42.196:6849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTVAAAAkA"]
[Tue Jul 21 07:18:39.922032 2026] [security2:error] [pid 229246:tid 229420] [client 14.139.42.196:6849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTVAAAAkA"]
[Tue Jul 21 07:18:39.946023 2026] [security2:error] [pid 229246:tid 229400] [client 20.197.192.193:23535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/berlin.php"] [unique_id "al9HfyBMYeh5YLVG45xTWQAAAiw"]
[Tue Jul 21 07:18:39.949316 2026] [security2:error] [pid 229246:tid 229407] [client 139.135.44.145:54399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTWgAAAjM"]
[Tue Jul 21 07:18:39.949477 2026] [security2:error] [pid 229246:tid 229407] [client 139.135.44.145:54399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTWgAAAjM"]
[Tue Jul 21 07:18:39.968727 2026] [security2:error] [pid 229246:tid 229403] [client 20.197.192.193:24458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/billur.php"] [unique_id "al9HfyBMYeh5YLVG45xTWwAAAi8"]
[Tue Jul 21 07:18:39.986727 2026] [security2:error] [pid 229246:tid 229443] [client 175.45.70.82:61400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTXAAAAlc"]
[Tue Jul 21 07:18:39.986973 2026] [security2:error] [pid 229246:tid 229443] [client 175.45.70.82:61400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTXAAAAlc"]
[Tue Jul 21 07:18:39.990184 2026] [security2:error] [pid 229246:tid 229464] [client 20.197.192.193:24013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/mimpi.php"] [unique_id "al9HfyBMYeh5YLVG45xTXgAAAmw"]
[Tue Jul 21 07:18:39.992882 2026] [security2:error] [pid 229246:tid 229406] [client 20.151.10.161:21454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/zoro.php"] [unique_id "al9HfyBMYeh5YLVG45xTXwAAAjI"]
[Tue Jul 21 07:18:39.993061 2026] [security2:error] [pid 229246:tid 229431] [client 45.251.232.145:56995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTYAAAAks"]
[Tue Jul 21 07:18:39.993197 2026] [security2:error] [pid 229246:tid 229431] [client 45.251.232.145:56995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HfyBMYeh5YLVG45xTYAAAAks"]
[Tue Jul 21 07:18:40.005091 2026] [security2:error] [pid 229246:tid 229438] [client 20.197.192.193:23547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/dp.php"] [unique_id "al9HgCBMYeh5YLVG45xTYgAAAlI"]
[Tue Jul 21 07:18:40.018911 2026] [security2:error] [pid 229246:tid 229429] [client 20.197.192.193:23519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/bootstrap.php"] [unique_id "al9HgCBMYeh5YLVG45xTZAAAAkk"]
[Tue Jul 21 07:18:40.032493 2026] [security2:error] [pid 229246:tid 229441] [client 209.141.34.121:64487] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "kettlebellevolution.com.br"] [uri "/"] [unique_id "al9HgCBMYeh5YLVG45xTZQAAAlU"]
[Tue Jul 21 07:18:40.038998 2026] [security2:error] [pid 229246:tid 229416] [client 74.244.195.153:6198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTZgAAAjw"]
[Tue Jul 21 07:18:40.043287 2026] [security2:error] [pid 229246:tid 229416] [client 74.244.195.153:6198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTZgAAAjw"]
[Tue Jul 21 07:18:40.052410 2026] [security2:error] [pid 229246:tid 229458] [client 20.197.192.193:23528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-editor.php"] [unique_id "al9HgCBMYeh5YLVG45xTZwAAAmY"]
[Tue Jul 21 07:18:40.068583 2026] [security2:error] [pid 229246:tid 229421] [client 20.197.192.193:24488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/cro.php"] [unique_id "al9HgCBMYeh5YLVG45xTaAAAAkE"]
[Tue Jul 21 07:18:40.088235 2026] [security2:error] [pid 229246:tid 229411] [client 20.197.192.193:23540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/cron-tab.php"] [unique_id "al9HgCBMYeh5YLVG45xTagAAAjc"]
[Tue Jul 21 07:18:40.122968 2026] [security2:error] [pid 229246:tid 229384] [client 20.197.192.193:23524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/koiy.php"] [unique_id "al9HgCBMYeh5YLVG45xTawAAAhw"]
[Tue Jul 21 07:18:40.154067 2026] [security2:error] [pid 229246:tid 229408] [client 20.197.192.193:24450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/hp2.php"] [unique_id "al9HgCBMYeh5YLVG45xTbAAAAjQ"]
[Tue Jul 21 07:18:40.169235 2026] [security2:error] [pid 229246:tid 229440] [client 20.151.10.161:45965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/scxy.php"] [unique_id "al9HgCBMYeh5YLVG45xTbQAAAlQ"]
[Tue Jul 21 07:18:40.183073 2026] [security2:error] [pid 229246:tid 229483] [client 20.197.192.193:23546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/hp3.php"] [unique_id "al9HgCBMYeh5YLVG45xTcAAAAn8"]
[Tue Jul 21 07:18:40.237589 2026] [security2:error] [pid 229246:tid 229299] [remote 85.208.96.208:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hauptmann.com.br"] [uri "/home-default/"] [unique_id "al9HgCBMYeh5YLVG45xTcwACLTQ"]
[Tue Jul 21 07:18:40.237826 2026] [security2:error] [pid 229246:tid 229401] [client 85.208.96.208:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hauptmann.com.br"] [uri "/home-default/"] [unique_id "al9HgCBMYeh5YLVG45xTcwACLTQ"]
[Tue Jul 21 07:18:40.240878 2026] [security2:error] [pid 229246:tid 229471] [client 20.197.192.193:24468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/aa1.php"] [unique_id "al9HgCBMYeh5YLVG45xTdAAAAnM"]
[Tue Jul 21 07:18:40.288010 2026] [security2:error] [pid 229246:tid 229381] [client 20.197.192.193:24470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/acew67.php"] [unique_id "al9HgCBMYeh5YLVG45xTdQAAAhk"]
[Tue Jul 21 07:18:40.328161 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:23543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/bscclapb.php"] [unique_id "al9HgCBMYeh5YLVG45xTdwAAAn0"]
[Tue Jul 21 07:18:40.356142 2026] [security2:error] [pid 229246:tid 229475] [client 20.197.192.193:24453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/else1.php"] [unique_id "al9HgCBMYeh5YLVG45xTeAAAAnc"]
[Tue Jul 21 07:18:40.383765 2026] [security2:error] [pid 229246:tid 229444] [client 20.197.192.193:24452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/tkikikoko.php"] [unique_id "al9HgCBMYeh5YLVG45xTewAAAlg"]
[Tue Jul 21 07:18:40.408928 2026] [security2:error] [pid 229246:tid 229503] [client 20.197.192.193:23506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-Blogs.php"] [unique_id "al9HgCBMYeh5YLVG45xTfQAAApM"]
[Tue Jul 21 07:18:40.421698 2026] [security2:error] [pid 229246:tid 229500] [client 20.197.192.193:23549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-css.php"] [unique_id "al9HgCBMYeh5YLVG45xTfwAAApA"]
[Tue Jul 21 07:18:40.436306 2026] [security2:error] [pid 229246:tid 229391] [client 20.197.192.193:24511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-explorer.php"] [unique_id "al9HgCBMYeh5YLVG45xTgwAAAiM"]
[Tue Jul 21 07:18:40.450454 2026] [security2:error] [pid 229246:tid 229502] [client 20.197.192.193:23529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/akismet.php"] [unique_id "al9HgCBMYeh5YLVG45xThAAAApI"]
[Tue Jul 21 07:18:40.469311 2026] [security2:error] [pid 229246:tid 229448] [client 20.197.192.193:24041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/ace2.php"] [unique_id "al9HgCBMYeh5YLVG45xTiAAAAlw"]
[Tue Jul 21 07:18:40.508737 2026] [security2:error] [pid 229246:tid 229464] [client 20.197.192.193:23513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/ms.php"] [unique_id "al9HgCBMYeh5YLVG45xTjgAAAmw"]
[Tue Jul 21 07:18:40.612824 2026] [security2:error] [pid 229246:tid 229429] [client 20.220.225.223:47840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/zzz.php"] [unique_id "al9HgCBMYeh5YLVG45xTngAAAkk"]
[Tue Jul 21 07:18:40.668945 2026] [security2:error] [pid 229246:tid 229290] [remote 65.111.15.124:38003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9HfyBMYeh5YLVG45xTQgACgSs"]
[Tue Jul 21 07:18:40.748067 2026] [security2:error] [pid 229246:tid 229468] [client 20.151.10.161:46073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/FWAZ.php"] [unique_id "al9HgCBMYeh5YLVG45xTrwAAAnA"]
[Tue Jul 21 07:18:40.825268 2026] [security2:error] [pid 229246:tid 229419] [client 120.61.173.56:49584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTuAAAAj8"]
[Tue Jul 21 07:18:40.825444 2026] [security2:error] [pid 229246:tid 229419] [client 120.61.173.56:49584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTuAAAAj8"]
[Tue Jul 21 07:18:40.854224 2026] [security2:error] [pid 229246:tid 229400] [client 35.205.139.29:51216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9HgCBMYeh5YLVG45xTvgAAAiw"]
[Tue Jul 21 07:18:40.891795 2026] [security2:error] [pid 229246:tid 229392] [client 92.119.178.3:59412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTxQAAAiQ"]
[Tue Jul 21 07:18:40.891876 2026] [security2:error] [pid 229246:tid 229392] [client 92.119.178.3:59412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTxQAAAiQ"]
[Tue Jul 21 07:18:40.933758 2026] [security2:error] [pid 229246:tid 229363] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTygACdXQ"]
[Tue Jul 21 07:18:40.933927 2026] [security2:error] [pid 229246:tid 229473] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgCBMYeh5YLVG45xTygACdXQ"]
[Tue Jul 21 07:18:41.243449 2026] [security2:error] [pid 229246:tid 229282] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgSBMYeh5YLVG45xT5QACgyM"]
[Tue Jul 21 07:18:41.243581 2026] [security2:error] [pid 229246:tid 229487] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgSBMYeh5YLVG45xT5QACgyM"]
[Tue Jul 21 07:18:41.255996 2026] [security2:error] [pid 229246:tid 229456] [client 4.204.201.85:35378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/file6.php"] [unique_id "al9HgSBMYeh5YLVG45xT5gAAAmQ"]
[Tue Jul 21 07:18:41.268330 2026] [security2:error] [pid 229246:tid 229488] [client 20.206.105.145:36019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9HgSBMYeh5YLVG45xT5wAAAoQ"]
[Tue Jul 21 07:18:41.327009 2026] [security2:error] [pid 229246:tid 229417] [client 20.151.10.161:21377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/coffexium.php"] [unique_id "al9HgSBMYeh5YLVG45xT6wAAAj0"]
[Tue Jul 21 07:18:41.470508 2026] [security2:error] [pid 229246:tid 229443] [client 20.151.10.161:46040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/qterm.php"] [unique_id "al9HgSBMYeh5YLVG45xT8gAAAlc"]
[Tue Jul 21 07:18:41.496530 2026] [security2:error] [pid 229246:tid 229379] [client 20.197.192.193:27161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9HgSBMYeh5YLVG45xT9AAAAhc"]
[Tue Jul 21 07:18:41.584842 2026] [security2:error] [pid 229246:tid 229404] [client 136.144.33.97:54957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HgSBMYeh5YLVG45xT9wAAAjA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:18:41.607116 2026] [autoindex:error] [pid 229246:tid 229284] [remote 104.253.36.208:37951] AH01276: Cannot serve directory /home2/ric83751/sanovitta.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:18:41.666495 2026] [security2:error] [pid 229246:tid 229429] [client 20.197.192.193:27153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/dr.php"] [unique_id "al9HgSBMYeh5YLVG45xT-gAAAkk"]
[Tue Jul 21 07:18:41.711198 2026] [security2:error] [pid 229246:tid 229416] [client 20.206.105.145:36172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/file.php"] [unique_id "al9HgSBMYeh5YLVG45xT_AAAAjw"]
[Tue Jul 21 07:18:41.807365 2026] [security2:error] [pid 229246:tid 229286] [remote 173.252.95.37:35160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9HgSBMYeh5YLVG45xUBQACXSc"]
[Tue Jul 21 07:18:41.825457 2026] [security2:error] [pid 229246:tid 229407] [client 35.205.139.29:62471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9HgSBMYeh5YLVG45xUBgAAAjM"]
[Tue Jul 21 07:18:42.008158 2026] [security2:error] [pid 229246:tid 229419] [client 4.204.201.85:26584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HgiBMYeh5YLVG45xUCwAAAj8"]
[Tue Jul 21 07:18:42.089183 2026] [security2:error] [pid 229246:tid 229392] [client 92.119.178.3:59426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9HgiBMYeh5YLVG45xUEQAAAiQ"]
[Tue Jul 21 07:18:42.089270 2026] [security2:error] [pid 229246:tid 229392] [client 92.119.178.3:59426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9HgiBMYeh5YLVG45xUEQAAAiQ"]
[Tue Jul 21 07:18:42.237805 2026] [security2:error] [pid 229246:tid 229409] [client 173.252.95.28:48462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HgCBMYeh5YLVG45xTaQAAAjU"]
[Tue Jul 21 07:18:42.267120 2026] [security2:error] [pid 229246:tid 229496] [client 20.151.10.161:46065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/blurbs.php"] [unique_id "al9HgiBMYeh5YLVG45xUGAAAAow"]
[Tue Jul 21 07:18:42.518525 2026] [security2:error] [pid 229246:tid 229376] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9HgiBMYeh5YLVG45xUIgAAAhQ"]
[Tue Jul 21 07:18:42.539626 2026] [security2:error] [pid 229246:tid 229297] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HgiBMYeh5YLVG45xUIwACkTI"]
[Tue Jul 21 07:18:42.539779 2026] [security2:error] [pid 229246:tid 229501] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HgiBMYeh5YLVG45xUIwACkTI"]
[Tue Jul 21 07:18:42.618977 2026] [security2:error] [pid 229246:tid 229488] [client 4.204.201.85:26605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HgiBMYeh5YLVG45xUJAAAAoQ"]
[Tue Jul 21 07:18:42.700321 2026] [security2:error] [pid 229246:tid 229397] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9HgiBMYeh5YLVG45xUKAAAAik"]
[Tue Jul 21 07:18:42.875485 2026] [security2:error] [pid 229246:tid 229454] [client 20.151.10.161:46053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/v543.php"] [unique_id "al9HgiBMYeh5YLVG45xUMQAAAmI"]
[Tue Jul 21 07:18:42.875501 2026] [security2:error] [pid 229246:tid 229404] [client 20.206.105.145:36049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/cfile.php"] [unique_id "al9HgiBMYeh5YLVG45xUMAAAAjA"]
[Tue Jul 21 07:18:42.883881 2026] [security2:error] [pid 229246:tid 229464] [client 20.226.60.151:54580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wpx.php"] [unique_id "al9HgiBMYeh5YLVG45xUMgAAAmw"]
[Tue Jul 21 07:18:42.950296 2026] [security2:error] [pid 229246:tid 229445] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgiBMYeh5YLVG45xUMwAAAlk"]
[Tue Jul 21 07:18:43.029045 2026] [security2:error] [pid 229246:tid 229456] [client 35.205.139.29:51641] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9HgyBMYeh5YLVG45xUNgAAAmQ"]
[Tue Jul 21 07:18:43.034321 2026] [security2:error] [pid 229246:tid 229416] [client 143.244.57.118:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUNwAAAjw"]
[Tue Jul 21 07:18:43.039771 2026] [security2:error] [pid 229246:tid 229458] [client 4.204.201.85:26608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/media.php"] [unique_id "al9HgyBMYeh5YLVG45xUOAAAAmY"]
[Tue Jul 21 07:18:43.114317 2026] [security2:error] [pid 229246:tid 229411] [client 68.235.38.2:60542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUOQAAAjc"]
[Tue Jul 21 07:18:43.114419 2026] [security2:error] [pid 229246:tid 229411] [client 68.235.38.2:60542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUOQAAAjc"]
[Tue Jul 21 07:18:43.387400 2026] [security2:error] [pid 229246:tid 229434] [client 20.206.105.145:36166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/class-wp.php"] [unique_id "al9HgyBMYeh5YLVG45xUSwAAAk4"]
[Tue Jul 21 07:18:43.388682 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:21448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/app.php"] [unique_id "al9HgyBMYeh5YLVG45xUTAAAAnk"]
[Tue Jul 21 07:18:43.483455 2026] [security2:error] [pid 229246:tid 229486] [client 4.204.201.85:26583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/images.php"] [unique_id "al9HgyBMYeh5YLVG45xUUgAAAoI"]
[Tue Jul 21 07:18:43.497139 2026] [security2:error] [pid 229246:tid 229413] [client 173.252.95.32:53258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HgyBMYeh5YLVG45xUUwAAAjk"]
[Tue Jul 21 07:18:43.531604 2026] [security2:error] [pid 229246:tid 229467] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9HgyBMYeh5YLVG45xUVQAAAm8"]
[Tue Jul 21 07:18:43.535258 2026] [security2:error] [pid 229246:tid 229462] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9HgyBMYeh5YLVG45xUVgAAAmo"]
[Tue Jul 21 07:18:43.656088 2026] [security2:error] [pid 229246:tid 229432] [client 103.162.129.114:54962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUWAAAAkw"]
[Tue Jul 21 07:18:43.656263 2026] [security2:error] [pid 229246:tid 229432] [client 103.162.129.114:54962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUWAAAAkw"]
[Tue Jul 21 07:18:43.668910 2026] [security2:error] [pid 229246:tid 229487] [client 20.206.105.145:35980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/admin.php"] [unique_id "al9HgyBMYeh5YLVG45xUWQAAAoM"]
[Tue Jul 21 07:18:43.683348 2026] [security2:error] [pid 229246:tid 229426] [client 134.19.179.187:46464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUWgAAAkY"]
[Tue Jul 21 07:18:43.683453 2026] [security2:error] [pid 229246:tid 229426] [client 134.19.179.187:46464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUWgAAAkY"]
[Tue Jul 21 07:18:43.837341 2026] [security2:error] [pid 229246:tid 229417] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9HgyBMYeh5YLVG45xUXwAAAj0"]
[Tue Jul 21 07:18:43.888379 2026] [security2:error] [pid 229246:tid 229466] [client 103.121.156.110:58085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUYAAAAm4"]
[Tue Jul 21 07:18:43.888529 2026] [security2:error] [pid 229246:tid 229466] [client 103.121.156.110:58085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HgyBMYeh5YLVG45xUYAAAAm4"]
[Tue Jul 21 07:18:43.889318 2026] [security2:error] [pid 229246:tid 229490] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9HgyBMYeh5YLVG45xUYQAAAoY"]
[Tue Jul 21 07:18:43.940262 2026] [security2:error] [pid 229246:tid 229311] [remote 104.207.56.171:34595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.56.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9HgyBMYeh5YLVG45xUYgACgEA"]
[Tue Jul 21 07:18:43.944268 2026] [security2:error] [pid 229246:tid 229499] [client 35.205.139.29:53154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9HgyBMYeh5YLVG45xUYwAAAo8"]
[Tue Jul 21 07:18:44.137039 2026] [security2:error] [pid 229246:tid 229454] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9HhCBMYeh5YLVG45xUawAAAmI"]
[Tue Jul 21 07:18:44.177630 2026] [security2:error] [pid 229246:tid 229455] [client 20.206.105.145:35973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/aa2.php"] [unique_id "al9HhCBMYeh5YLVG45xUbAAAAmM"]
[Tue Jul 21 07:18:44.273633 2026] [security2:error] [pid 229246:tid 229452] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9HhCBMYeh5YLVG45xUdAAAAmA"]
[Tue Jul 21 07:18:44.434294 2026] [security2:error] [pid 229246:tid 229453] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9HhCBMYeh5YLVG45xUewAAAmE"]
[Tue Jul 21 07:18:44.447315 2026] [security2:error] [pid 229246:tid 229320] [remote 192.249.127.213:49172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.127.249.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rqracademy.com"] [uri "/wp-login.php"] [unique_id "al9HhCBMYeh5YLVG45xUfQACk0k"]
[Tue Jul 21 07:18:44.554154 2026] [security2:error] [pid 229246:tid 229410] [client 20.206.105.145:36216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/ccou.php"] [unique_id "al9HhCBMYeh5YLVG45xUfwAAAjY"]
[Tue Jul 21 07:18:44.559633 2026] [security2:error] [pid 229246:tid 229476] [client 20.151.10.161:21486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/core.php"] [unique_id "al9HhCBMYeh5YLVG45xUgAAAAng"]
[Tue Jul 21 07:18:44.642767 2026] [security2:error] [pid 229246:tid 229413] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9HhCBMYeh5YLVG45xUggAAAjk"]
[Tue Jul 21 07:18:44.736266 2026] [security2:error] [pid 229246:tid 229475] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9HhCBMYeh5YLVG45xUhQAAAnc"]
[Tue Jul 21 07:18:44.766652 2026] [security2:error] [pid 229246:tid 229376] [client 4.204.201.85:26562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/gecko.php"] [unique_id "al9HhCBMYeh5YLVG45xUhgAAAhQ"]
[Tue Jul 21 07:18:44.841097 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:51612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HhCBMYeh5YLVG45xUiAAAAn0"]
[Tue Jul 21 07:18:44.862602 2026] [security2:error] [pid 229246:tid 229502] [client 20.197.192.193:51588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HhCBMYeh5YLVG45xUiwAAApI"]
[Tue Jul 21 07:18:44.889840 2026] [security2:error] [pid 229246:tid 229455] [client 20.197.192.193:64072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/dp.php"] [unique_id "al9HhCBMYeh5YLVG45xUjQAAAmM"]
[Tue Jul 21 07:18:44.927076 2026] [security2:error] [pid 229246:tid 229379] [client 20.197.192.193:58732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/old.php"] [unique_id "al9HhCBMYeh5YLVG45xUkAAAAhc"]
[Tue Jul 21 07:18:44.936959 2026] [security2:error] [pid 229246:tid 229470] [client 35.205.139.29:54580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9HhCBMYeh5YLVG45xUkgAAAnI"]
[Tue Jul 21 07:18:45.021922 2026] [security2:error] [pid 229246:tid 229395] [client 20.197.192.193:51643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/ms-new.php"] [unique_id "al9HhSBMYeh5YLVG45xUkwAAAic"]
[Tue Jul 21 07:18:45.026680 2026] [security2:error] [pid 229246:tid 229445] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xUlAAAAlk"]
[Tue Jul 21 07:18:45.034113 2026] [security2:error] [pid 229246:tid 229460] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xUlgAAAmg"]
[Tue Jul 21 07:18:45.047033 2026] [security2:error] [pid 229246:tid 229433] [client 14.139.42.196:12129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HhSBMYeh5YLVG45xUmAAAAk0"]
[Tue Jul 21 07:18:45.047121 2026] [security2:error] [pid 229246:tid 229433] [client 14.139.42.196:12129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HhSBMYeh5YLVG45xUmAAAAk0"]
[Tue Jul 21 07:18:45.050735 2026] [security2:error] [pid 229246:tid 229479] [client 20.197.192.193:58711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/track.php"] [unique_id "al9HhSBMYeh5YLVG45xUmQAAAns"]
[Tue Jul 21 07:18:45.070358 2026] [security2:error] [pid 229246:tid 229496] [client 20.197.192.193:64106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/2352356666.php"] [unique_id "al9HhSBMYeh5YLVG45xUmgAAAow"]
[Tue Jul 21 07:18:45.102128 2026] [security2:error] [pid 229246:tid 229441] [client 20.197.192.193:51608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/pn.php"] [unique_id "al9HhSBMYeh5YLVG45xUmwAAAlU"]
[Tue Jul 21 07:18:45.118782 2026] [security2:error] [pid 229246:tid 229449] [client 20.151.10.161:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/w3lls.php"] [unique_id "al9HhSBMYeh5YLVG45xUnAAAAl0"]
[Tue Jul 21 07:18:45.128908 2026] [security2:error] [pid 229246:tid 229384] [client 20.197.192.193:58739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9HhSBMYeh5YLVG45xUnQAAAhw"]
[Tue Jul 21 07:18:45.136565 2026] [security2:error] [pid 229246:tid 229440] [client 4.204.201.85:26609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/82.php"] [unique_id "al9HhSBMYeh5YLVG45xUngAAAlQ"]
[Tue Jul 21 07:18:45.194733 2026] [security2:error] [pid 229246:tid 229453] [client 20.197.192.193:51590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/dr.php"] [unique_id "al9HhSBMYeh5YLVG45xUoQAAAmE"]
[Tue Jul 21 07:18:45.260995 2026] [security2:error] [pid 229246:tid 229430] [client 20.197.192.193:51637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/2x.php"] [unique_id "al9HhSBMYeh5YLVG45xUogAAAko"]
[Tue Jul 21 07:18:45.290156 2026] [security2:error] [pid 229246:tid 229410] [client 20.197.192.193:60590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/kq1.php"] [unique_id "al9HhSBMYeh5YLVG45xUpQAAAjY"]
[Tue Jul 21 07:18:45.312626 2026] [security2:error] [pid 229246:tid 229489] [client 20.197.192.193:60555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/zzz.php"] [unique_id "al9HhSBMYeh5YLVG45xUpgAAAoU"]
[Tue Jul 21 07:18:45.331733 2026] [security2:error] [pid 229246:tid 229419] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xUpwAAAj8"]
[Tue Jul 21 07:18:45.337827 2026] [security2:error] [pid 229246:tid 229486] [client 20.197.192.193:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wicked.php"] [unique_id "al9HhSBMYeh5YLVG45xUqAAAAoI"]
[Tue Jul 21 07:18:45.355381 2026] [security2:error] [pid 229246:tid 229467] [client 20.197.192.193:51640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/edit.php"] [unique_id "al9HhSBMYeh5YLVG45xUqwAAAm8"]
[Tue Jul 21 07:18:45.375784 2026] [security2:error] [pid 229246:tid 229432] [client 20.197.192.193:58745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/kua.php"] [unique_id "al9HhSBMYeh5YLVG45xUrgAAAkw"]
[Tue Jul 21 07:18:45.404810 2026] [security2:error] [pid 229246:tid 229444] [client 20.197.192.193:64104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/ez.php"] [unique_id "al9HhSBMYeh5YLVG45xUsAAAAlg"]
[Tue Jul 21 07:18:45.422781 2026] [security2:error] [pid 229246:tid 229381] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xUswAAAhk"]
[Tue Jul 21 07:18:45.444143 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:58733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/fz.php"] [unique_id "al9HhSBMYeh5YLVG45xUtQAAAoQ"]
[Tue Jul 21 07:18:45.463235 2026] [security2:error] [pid 229246:tid 229466] [client 20.197.192.193:60599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/la.php"] [unique_id "al9HhSBMYeh5YLVG45xUtgAAAm4"]
[Tue Jul 21 07:18:45.484546 2026] [security2:error] [pid 229246:tid 229402] [client 20.197.192.193:58723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9HhSBMYeh5YLVG45xUtwAAAi4"]
[Tue Jul 21 07:18:45.513362 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.192.193:60563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/inso.php"] [unique_id "al9HhSBMYeh5YLVG45xUuAAAAjI"]
[Tue Jul 21 07:18:45.530305 2026] [security2:error] [pid 229246:tid 229450] [client 20.151.10.161:50361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/main.php"] [unique_id "al9HhSBMYeh5YLVG45xUuQAAAl4"]
[Tue Jul 21 07:18:45.581886 2026] [security2:error] [pid 229246:tid 229464] [client 20.197.192.193:58718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wpx.php"] [unique_id "al9HhSBMYeh5YLVG45xUugAAAmw"]
[Tue Jul 21 07:18:45.620182 2026] [security2:error] [pid 229246:tid 229455] [client 20.197.192.193:51632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/berlin.php"] [unique_id "al9HhSBMYeh5YLVG45xUvAAAAmM"]
[Tue Jul 21 07:18:45.629346 2026] [security2:error] [pid 229246:tid 229379] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xUvQAAAhc"]
[Tue Jul 21 07:18:45.639062 2026] [security2:error] [pid 229246:tid 229456] [client 92.119.178.3:52992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HhSBMYeh5YLVG45xUvgAAAmQ"]
[Tue Jul 21 07:18:45.639186 2026] [security2:error] [pid 229246:tid 229456] [client 92.119.178.3:52992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HhSBMYeh5YLVG45xUvgAAAmQ"]
[Tue Jul 21 07:18:45.662008 2026] [security2:error] [pid 229246:tid 229389] [client 20.197.192.193:51614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/billur.php"] [unique_id "al9HhSBMYeh5YLVG45xUvwAAAiE"]
[Tue Jul 21 07:18:45.685192 2026] [security2:error] [pid 229246:tid 229416] [client 20.197.192.193:64082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/mimpi.php"] [unique_id "al9HhSBMYeh5YLVG45xUwAAAAjw"]
[Tue Jul 21 07:18:45.715527 2026] [security2:error] [pid 229246:tid 229491] [client 20.197.192.193:58690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/dp.php"] [unique_id "al9HhSBMYeh5YLVG45xUwgAAAoc"]
[Tue Jul 21 07:18:45.739507 2026] [security2:error] [pid 229246:tid 229460] [client 4.204.201.85:26607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/admin.php"] [unique_id "al9HhSBMYeh5YLVG45xUwwAAAmg"]
[Tue Jul 21 07:18:45.742562 2026] [security2:error] [pid 229246:tid 229433] [client 20.197.192.193:64097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/bootstrap.php"] [unique_id "al9HhSBMYeh5YLVG45xUxAAAAk0"]
[Tue Jul 21 07:18:45.761565 2026] [security2:error] [pid 229246:tid 229421] [client 20.197.192.193:60593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-editor.php"] [unique_id "al9HhSBMYeh5YLVG45xUxQAAAkE"]
[Tue Jul 21 07:18:45.772926 2026] [security2:error] [pid 229246:tid 229494] [client 20.197.192.193:64071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/cro.php"] [unique_id "al9HhSBMYeh5YLVG45xUxgAAAoo"]
[Tue Jul 21 07:18:45.784253 2026] [security2:error] [pid 229246:tid 229435] [client 20.197.192.193:58702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/cron-tab.php"] [unique_id "al9HhSBMYeh5YLVG45xUxwAAAk8"]
[Tue Jul 21 07:18:45.802701 2026] [security2:error] [pid 229246:tid 229441] [client 20.197.192.193:64112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/koiy.php"] [unique_id "al9HhSBMYeh5YLVG45xUyQAAAlU"]
[Tue Jul 21 07:18:45.815753 2026] [security2:error] [pid 229246:tid 229449] [client 20.197.192.193:51617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/hp2.php"] [unique_id "al9HhSBMYeh5YLVG45xUygAAAl0"]
[Tue Jul 21 07:18:45.824977 2026] [security2:error] [pid 229246:tid 229429] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xUywAAAkk"]
[Tue Jul 21 07:18:45.882772 2026] [security2:error] [pid 229246:tid 229440] [client 20.197.192.193:60553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/hp3.php"] [unique_id "al9HhSBMYeh5YLVG45xUzQAAAlQ"]
[Tue Jul 21 07:18:45.930723 2026] [security2:error] [pid 229246:tid 229492] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xU1QAAAog"]
[Tue Jul 21 07:18:45.932900 2026] [security2:error] [pid 229246:tid 229424] [client 136.144.33.110:20999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HhSBMYeh5YLVG45xU1gAAAkQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:18:45.959598 2026] [security2:error] [pid 229246:tid 229420] [client 35.205.139.29:57112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9HhSBMYeh5YLVG45xU1wAAAkA"]
[Tue Jul 21 07:18:45.965915 2026] [security2:error] [pid 229246:tid 229335] [remote 51.195.39.149:57519] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "equoterapiaprosseguir.com"] [uri "/"] [unique_id "al9HhSBMYeh5YLVG45xU2AACZ1g"]
[Tue Jul 21 07:18:45.991349 2026] [security2:error] [pid 229246:tid 229414] [client 20.197.192.193:58728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/aa1.php"] [unique_id "al9HhSBMYeh5YLVG45xU2QAAAjo"]
[Tue Jul 21 07:18:46.007448 2026] [security2:error] [pid 229246:tid 229489] [client 20.220.225.223:43034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/wicked.php"] [unique_id "al9HhiBMYeh5YLVG45xU2gAAAoU"]
[Tue Jul 21 07:18:46.082827 2026] [security2:error] [pid 229246:tid 229477] [client 20.197.192.193:58735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/acew67.php"] [unique_id "al9HhiBMYeh5YLVG45xU3QAAAnk"]
[Tue Jul 21 07:18:46.104057 2026] [security2:error] [pid 229246:tid 229413] [client 20.197.192.193:51644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/bscclapb.php"] [unique_id "al9HhiBMYeh5YLVG45xU4AAAAjk"]
[Tue Jul 21 07:18:46.139799 2026] [security2:error] [pid 229246:tid 229387] [client 20.197.192.193:60603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/else1.php"] [unique_id "al9HhiBMYeh5YLVG45xU4QAAAh8"]
[Tue Jul 21 07:18:46.167690 2026] [security2:error] [pid 229246:tid 229392] [client 20.197.192.193:60606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/tkikikoko.php"] [unique_id "al9HhiBMYeh5YLVG45xU4wAAAiQ"]
[Tue Jul 21 07:18:46.211375 2026] [security2:error] [pid 229246:tid 229475] [client 20.197.192.193:49752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9HhiBMYeh5YLVG45xU5AAAAnc"]
[Tue Jul 21 07:18:46.233118 2026] [security2:error] [pid 229246:tid 229376] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9HhiBMYeh5YLVG45xU5wAAAhQ"]
[Tue Jul 21 07:18:46.241369 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:60562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-css.php"] [unique_id "al9HhiBMYeh5YLVG45xU6QAAAn0"]
[Tue Jul 21 07:18:46.244519 2026] [security2:error] [pid 229246:tid 229402] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9HhiBMYeh5YLVG45xU6wAAAi4"]
[Tue Jul 21 07:18:46.266177 2026] [security2:error] [pid 229246:tid 229404] [client 4.204.201.85:26387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/adminner.php"] [unique_id "al9HhiBMYeh5YLVG45xU7AAAAjA"]
[Tue Jul 21 07:18:46.293042 2026] [security2:error] [pid 229246:tid 229464] [client 20.197.192.193:64105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-explorer.php"] [unique_id "al9HhiBMYeh5YLVG45xU7QAAAmw"]
[Tue Jul 21 07:18:46.320501 2026] [security2:error] [pid 229246:tid 229399] [client 20.197.192.193:60596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/akismet.php"] [unique_id "al9HhiBMYeh5YLVG45xU7gAAAis"]
[Tue Jul 21 07:18:46.367472 2026] [security2:error] [pid 229246:tid 229445] [client 20.197.192.193:60546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/ace2.php"] [unique_id "al9HhiBMYeh5YLVG45xU7wAAAlk"]
[Tue Jul 21 07:18:46.418155 2026] [security2:error] [pid 229246:tid 229491] [client 20.197.192.193:64085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/ms.php"] [unique_id "al9HhiBMYeh5YLVG45xU9AAAAoc"]
[Tue Jul 21 07:18:46.444737 2026] [security2:error] [pid 229246:tid 229433] [client 20.197.192.193:8350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/wp-mt.php"] [unique_id "al9HhiBMYeh5YLVG45xU9wAAAk0"]
[Tue Jul 21 07:18:46.453470 2026] [security2:error] [pid 229246:tid 229421] [client 20.151.10.161:21471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/init.php"] [unique_id "al9HhiBMYeh5YLVG45xU-AAAAkE"]
[Tue Jul 21 07:18:46.532525 2026] [security2:error] [pid 229246:tid 229407] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9HhiBMYeh5YLVG45xU_wAAAjM"]
[Tue Jul 21 07:18:46.611405 2026] [security2:error] [pid 229246:tid 229436] [client 20.206.105.145:36189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/dr.php"] [unique_id "al9HhiBMYeh5YLVG45xVAQAAAlA"]
[Tue Jul 21 07:18:46.613520 2026] [security2:error] [pid 229246:tid 229453] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9HhiBMYeh5YLVG45xVAgAAAmE"]
[Tue Jul 21 07:18:46.682080 2026] [security2:error] [pid 229246:tid 229348] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HhiBMYeh5YLVG45xVAwACHGU"]
[Tue Jul 21 07:18:46.682266 2026] [security2:error] [pid 229246:tid 229384] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HhiBMYeh5YLVG45xVAwACHGU"]
[Tue Jul 21 07:18:46.738719 2026] [autoindex:error] [pid 229246:tid 229470] [client 4.204.201.85:35408] AH01276: Cannot serve directory /home3/seaport/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:18:46.780983 2026] [security2:error] [pid 229246:tid 229350] [remote 154.61.75.100:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vanderleiasilva.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HhiBMYeh5YLVG45xVBwACgGc"]
[Tue Jul 21 07:18:46.781123 2026] [security2:error] [pid 229246:tid 229484] [client 154.61.75.100:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vanderleiasilva.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HhiBMYeh5YLVG45xVBwACgGc"]
[Tue Jul 21 07:18:46.798577 2026] [security2:error] [pid 229246:tid 229352] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HhiBMYeh5YLVG45xVCAACjWk"]
[Tue Jul 21 07:18:46.798721 2026] [security2:error] [pid 229246:tid 229497] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HhiBMYeh5YLVG45xVCAACjWk"]
[Tue Jul 21 07:18:46.808011 2026] [security2:error] [pid 229246:tid 229489] [client 4.204.201.85:26565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/admin.php"] [unique_id "al9HhiBMYeh5YLVG45xVCgAAAoU"]
[Tue Jul 21 07:18:46.836337 2026] [security2:error] [pid 229246:tid 229474] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9HhiBMYeh5YLVG45xVCwAAAnY"]
[Tue Jul 21 07:18:46.968373 2026] [security2:error] [pid 229246:tid 229429] [client 35.205.139.29:51623] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9HhiBMYeh5YLVG45xVEgAAAkk"]
[Tue Jul 21 07:18:47.025112 2026] [security2:error] [pid 229246:tid 229419] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9HhyBMYeh5YLVG45xVGAAAAj8"]
[Tue Jul 21 07:18:47.032620 2026] [security2:error] [pid 229246:tid 229408] [client 20.151.10.161:50329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/prekel.php"] [unique_id "al9HhyBMYeh5YLVG45xVGgAAAjQ"]
[Tue Jul 21 07:18:47.043929 2026] [security2:error] [pid 229246:tid 229393] [client 4.204.201.85:35420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/adminfuns.php"] [unique_id "al9HhyBMYeh5YLVG45xVHAAAAiU"]
[Tue Jul 21 07:18:47.129455 2026] [access_compat:error] [pid 229246:tid 229404] [client 162.241.63.68:24582] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:18:47.154469 2026] [security2:error] [pid 229246:tid 229385] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9HhyBMYeh5YLVG45xVIgAAAh0"]
[Tue Jul 21 07:18:47.322419 2026] [security2:error] [pid 229246:tid 229438] [client 4.204.201.85:26368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/k.php"] [unique_id "al9HhyBMYeh5YLVG45xVJwAAAlI"]
[Tue Jul 21 07:18:47.359218 2026] [security2:error] [pid 229246:tid 229491] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9HhyBMYeh5YLVG45xVKAAAAoc"]
[Tue Jul 21 07:18:47.406731 2026] [security2:error] [pid 229246:tid 229492] [client 139.135.44.145:53547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HhyBMYeh5YLVG45xVKQAAAog"]
[Tue Jul 21 07:18:47.407323 2026] [security2:error] [pid 229246:tid 229492] [client 139.135.44.145:53547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HhyBMYeh5YLVG45xVKQAAAog"]
[Tue Jul 21 07:18:47.463322 2026] [security2:error] [pid 229246:tid 229494] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9HhyBMYeh5YLVG45xVLQAAAoo"]
[Tue Jul 21 07:18:47.528295 2026] [security2:error] [pid 229246:tid 229477] [client 122.183.40.231:33021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.40.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psiqueflix.online"] [uri "/xmlrpc.php"] [unique_id "al9HhyBMYeh5YLVG45xVLgAAAnk"]
[Tue Jul 21 07:18:47.528429 2026] [security2:error] [pid 229246:tid 229477] [client 122.183.40.231:33021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "psiqueflix.online"] [uri "/xmlrpc.php"] [unique_id "al9HhyBMYeh5YLVG45xVLgAAAnk"]
[Tue Jul 21 07:18:47.673512 2026] [security2:error] [pid 229246:tid 229471] [client 4.204.201.85:26621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/blurbs.php"] [unique_id "al9HhyBMYeh5YLVG45xVMgAAAnM"]
[Tue Jul 21 07:18:47.731575 2026] [security2:error] [pid 229246:tid 229409] [client 4.204.201.85:35369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/goods.php"] [unique_id "al9HhyBMYeh5YLVG45xVNgAAAjU"]
[Tue Jul 21 07:18:47.747661 2026] [security2:error] [pid 229246:tid 229424] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9HhyBMYeh5YLVG45xVNwAAAkQ"]
[Tue Jul 21 07:18:47.795171 2026] [security2:error] [pid 229246:tid 229446] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9HhyBMYeh5YLVG45xVOQAAAlo"]
[Tue Jul 21 07:18:47.801959 2026] [security2:error] [pid 229246:tid 229420] [client 20.206.105.145:36050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/xamp.php"] [unique_id "al9HhyBMYeh5YLVG45xVOgAAAkA"]
[Tue Jul 21 07:18:47.823186 2026] [security2:error] [pid 229246:tid 229481] [client 74.244.195.153:42852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HhyBMYeh5YLVG45xVOwAAAn0"]
[Tue Jul 21 07:18:47.823292 2026] [security2:error] [pid 229246:tid 229481] [client 74.244.195.153:42852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HhyBMYeh5YLVG45xVOwAAAn0"]
[Tue Jul 21 07:18:47.929824 2026] [security2:error] [pid 229246:tid 229400] [client 35.205.139.29:65245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9HhyBMYeh5YLVG45xVQAAAAiw"]
[Tue Jul 21 07:18:48.042743 2026] [security2:error] [pid 229246:tid 229382] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9HiCBMYeh5YLVG45xVRAAAAho"]
[Tue Jul 21 07:18:48.044325 2026] [security2:error] [pid 229246:tid 229493] [client 4.204.201.85:26582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/bajah.php"] [unique_id "al9HiCBMYeh5YLVG45xVRQAAAok"]
[Tue Jul 21 07:18:48.055524 2026] [security2:error] [pid 229246:tid 229370] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HiCBMYeh5YLVG45xVRgACFXs"]
[Tue Jul 21 07:18:48.055668 2026] [security2:error] [pid 229246:tid 229377] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HiCBMYeh5YLVG45xVRgACFXs"]
[Tue Jul 21 07:18:48.102437 2026] [security2:error] [pid 229246:tid 229478] [client 4.204.201.85:35423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/100.php"] [unique_id "al9HiCBMYeh5YLVG45xVRwAAAno"]
[Tue Jul 21 07:18:48.153525 2026] [security2:error] [pid 229246:tid 229402] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9HiCBMYeh5YLVG45xVSgAAAi4"]
[Tue Jul 21 07:18:48.183173 2026] [security2:error] [pid 229246:tid 229454] [client 20.151.10.161:46063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-ws68.php"] [unique_id "al9HiCBMYeh5YLVG45xVSwAAAmI"]
[Tue Jul 21 07:18:48.267990 2026] [security2:error] [pid 229246:tid 229388] [client 20.151.10.161:21455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/0.php"] [unique_id "al9HiCBMYeh5YLVG45xVUAAAAiA"]
[Tue Jul 21 07:18:48.291560 2026] [security2:error] [pid 229246:tid 229445] [client 20.226.60.151:54566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-css.php"] [unique_id "al9HiCBMYeh5YLVG45xVUgAAAlk"]
[Tue Jul 21 07:18:48.469626 2026] [security2:error] [pid 229246:tid 229482] [client 4.204.201.85:26574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/a.php"] [unique_id "al9HiCBMYeh5YLVG45xVVgAAAn4"]
[Tue Jul 21 07:18:48.490349 2026] [security2:error] [pid 229246:tid 229491] [client 20.197.192.193:9454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/ww.php"] [unique_id "al9HiCBMYeh5YLVG45xVWgAAAoc"]
[Tue Jul 21 07:18:48.513906 2026] [security2:error] [pid 229246:tid 229421] [client 4.204.201.85:35411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/about.php"] [unique_id "al9HiCBMYeh5YLVG45xVWwAAAkE"]
[Tue Jul 21 07:18:48.557976 2026] [security2:error] [pid 229246:tid 229259] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HiCBMYeh5YLVG45xVXQACZAw"]
[Tue Jul 21 07:18:48.558134 2026] [security2:error] [pid 229246:tid 229456] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HiCBMYeh5YLVG45xVXQACZAw"]
[Tue Jul 21 07:18:48.688426 2026] [security2:error] [pid 229246:tid 229458] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9HiCBMYeh5YLVG45xVXgAAAmY"]
[Tue Jul 21 07:18:48.695210 2026] [security2:error] [pid 229246:tid 229429] [client 45.251.232.145:57510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiCBMYeh5YLVG45xVXwAAAkk"]
[Tue Jul 21 07:18:48.695356 2026] [security2:error] [pid 229246:tid 229429] [client 45.251.232.145:57510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiCBMYeh5YLVG45xVXwAAAkk"]
[Tue Jul 21 07:18:48.796229 2026] [security2:error] [pid 229246:tid 229441] [client 4.204.201.85:26612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/edit.php"] [unique_id "al9HiCBMYeh5YLVG45xVZAAAAlU"]
[Tue Jul 21 07:18:48.902113 2026] [security2:error] [pid 229246:tid 229435] [client 4.204.201.85:35449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/about.php"] [unique_id "al9HiCBMYeh5YLVG45xVZwAAAk8"]
[Tue Jul 21 07:18:49.033877 2026] [security2:error] [pid 229246:tid 229383] [client 35.205.139.29:61015] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sistedu-mec.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9HiSBMYeh5YLVG45xVbAAAAhs"]
[Tue Jul 21 07:18:49.086981 2026] [security2:error] [pid 229246:tid 229468] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9HiSBMYeh5YLVG45xVbQAAAnA"]
[Tue Jul 21 07:18:49.118536 2026] [security2:error] [pid 229246:tid 229481] [client 4.204.201.85:26597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/hosty.php"] [unique_id "al9HiSBMYeh5YLVG45xVbgAAAn0"]
[Tue Jul 21 07:18:49.162806 2026] [security2:error] [pid 229246:tid 229392] [client 20.151.10.161:21387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/BDKR28.php"] [unique_id "al9HiSBMYeh5YLVG45xVbwAAAiQ"]
[Tue Jul 21 07:18:49.181343 2026] [security2:error] [pid 229246:tid 229459] [client 173.252.95.6:53802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HiSBMYeh5YLVG45xVcAAAAmc"]
[Tue Jul 21 07:18:49.195461 2026] [security2:error] [pid 229246:tid 229469] [client 20.220.225.223:52758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/edit.php"] [unique_id "al9HiSBMYeh5YLVG45xVcQAAAnE"]
[Tue Jul 21 07:18:49.338666 2026] [security2:error] [pid 229246:tid 229487] [client 4.204.201.85:35438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/admin.php"] [unique_id "al9HiSBMYeh5YLVG45xVdQAAAoM"]
[Tue Jul 21 07:18:49.398600 2026] [security2:error] [pid 229246:tid 229475] [client 136.144.33.99:37073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HiSBMYeh5YLVG45xVeAAAAnc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:18:49.409893 2026] [security2:error] [pid 229246:tid 229377] [client 20.206.105.145:36015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/bless.php"] [unique_id "al9HiSBMYeh5YLVG45xVeQAAAhU"]
[Tue Jul 21 07:18:49.460359 2026] [security2:error] [pid 229246:tid 229376] [client 4.204.201.85:26566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/k.php"] [unique_id "al9HiSBMYeh5YLVG45xVewAAAhQ"]
[Tue Jul 21 07:18:49.465136 2026] [security2:error] [pid 229246:tid 229483] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9HiSBMYeh5YLVG45xVfAAAAn8"]
[Tue Jul 21 07:18:49.630388 2026] [security2:error] [pid 229246:tid 229381] [client 20.197.192.193:9426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/cron.php"] [unique_id "al9HiSBMYeh5YLVG45xVgwAAAhk"]
[Tue Jul 21 07:18:49.837474 2026] [security2:error] [pid 229246:tid 229452] [client 4.204.201.85:26614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/aaa.php"] [unique_id "al9HiSBMYeh5YLVG45xVigAAAmA"]
[Tue Jul 21 07:18:49.846314 2026] [security2:error] [pid 229246:tid 229482] [client 20.151.10.161:21446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/f35.update.php"] [unique_id "al9HiSBMYeh5YLVG45xViwAAAn4"]
[Tue Jul 21 07:18:50.055526 2026] [security2:error] [pid 229246:tid 229479] [client 4.204.201.85:35454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/admin.php"] [unique_id "al9HiiBMYeh5YLVG45xVjwAAAns"]
[Tue Jul 21 07:18:50.295719 2026] [security2:error] [pid 229246:tid 229411] [client 4.204.201.85:26586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/file5.php"] [unique_id "al9HiiBMYeh5YLVG45xVlQAAAjc"]
[Tue Jul 21 07:18:50.414104 2026] [security2:error] [pid 229246:tid 229416] [client 175.45.70.82:61895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiiBMYeh5YLVG45xVmgAAAjw"]
[Tue Jul 21 07:18:50.414242 2026] [security2:error] [pid 229246:tid 229416] [client 175.45.70.82:61895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiiBMYeh5YLVG45xVmgAAAjw"]
[Tue Jul 21 07:18:50.625350 2026] [security2:error] [pid 229246:tid 229378] [client 20.226.60.151:54545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/ho.php"] [unique_id "al9HiiBMYeh5YLVG45xVqAAAAhY"]
[Tue Jul 21 07:18:50.757583 2026] [security2:error] [pid 229246:tid 229481] [client 4.204.201.85:35328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/themes.php"] [unique_id "al9HiiBMYeh5YLVG45xVqgAAAn0"]
[Tue Jul 21 07:18:50.890009 2026] [security2:error] [pid 229246:tid 229414] [client 4.204.201.85:26376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/222.php"] [unique_id "al9HiiBMYeh5YLVG45xVrAAAAjo"]
[Tue Jul 21 07:18:51.075662 2026] [security2:error] [pid 229246:tid 229451] [client 20.151.10.161:46060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xyn.php"] [unique_id "al9HiyBMYeh5YLVG45xVswAAAl8"]
[Tue Jul 21 07:18:51.126718 2026] [autoindex:error] [pid 229246:tid 229444] [client 170.106.35.153:58240] AH01276: Cannot serve directory /home2/rebe1126/rebecavivone.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:18:51.234335 2026] [security2:error] [pid 229246:tid 229493] [client 20.151.10.161:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/f900.php"] [unique_id "al9HiyBMYeh5YLVG45xVtQAAAok"]
[Tue Jul 21 07:18:51.299787 2026] [security2:error] [pid 229246:tid 229488] [client 4.204.201.85:26369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/test.php"] [unique_id "al9HiyBMYeh5YLVG45xVtgAAAoQ"]
[Tue Jul 21 07:18:51.416230 2026] [security2:error] [pid 229246:tid 229392] [client 120.61.173.56:50094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiyBMYeh5YLVG45xVuQAAAiQ"]
[Tue Jul 21 07:18:51.416339 2026] [security2:error] [pid 229246:tid 229392] [client 120.61.173.56:50094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiyBMYeh5YLVG45xVuQAAAiQ"]
[Tue Jul 21 07:18:51.457832 2026] [autoindex:error] [pid 229246:tid 229499] [client 4.204.201.85:35408] AH01276: Cannot serve directory /home3/seaport/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:18:51.498247 2026] [security2:error] [pid 229246:tid 229300] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiyBMYeh5YLVG45xVvgACITU"]
[Tue Jul 21 07:18:51.498405 2026] [security2:error] [pid 229246:tid 229389] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiyBMYeh5YLVG45xVvgACITU"]
[Tue Jul 21 07:18:51.757657 2026] [security2:error] [pid 229246:tid 229308] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiyBMYeh5YLVG45xVyQACID0"]
[Tue Jul 21 07:18:51.757867 2026] [security2:error] [pid 229246:tid 229388] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HiyBMYeh5YLVG45xVyQACID0"]
[Tue Jul 21 07:18:51.783231 2026] [security2:error] [pid 229246:tid 229492] [client 20.220.225.223:47850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/kua.php"] [unique_id "al9HiyBMYeh5YLVG45xVygAAAog"]
[Tue Jul 21 07:18:51.862605 2026] [security2:error] [pid 229246:tid 229411] [client 4.204.201.85:26385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/aaa.php"] [unique_id "al9HiyBMYeh5YLVG45xV0AAAAjc"]
[Tue Jul 21 07:18:51.921108 2026] [security2:error] [pid 229246:tid 229471] [client 20.206.105.145:36181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/file46.php"] [unique_id "al9HiyBMYeh5YLVG45xV0gAAAnM"]
[Tue Jul 21 07:18:51.996871 2026] [security2:error] [pid 229246:tid 229436] [client 20.206.105.145:35849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/eee.php"] [unique_id "al9HiyBMYeh5YLVG45xV0wAAAlA"]
[Tue Jul 21 07:18:52.075062 2026] [security2:error] [pid 229246:tid 229378] [client 4.204.201.85:35431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/.well-known/about.php"] [unique_id "al9HjCBMYeh5YLVG45xV2AAAAhY"]
[Tue Jul 21 07:18:52.121171 2026] [security2:error] [pid 229246:tid 229497] [client 20.206.105.145:36184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/file25.php"] [unique_id "al9HjCBMYeh5YLVG45xV3AAAAo0"]
[Tue Jul 21 07:18:52.274926 2026] [security2:error] [pid 229246:tid 229457] [client 20.206.105.145:36214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/file48.php"] [unique_id "al9HjCBMYeh5YLVG45xV3wAAAmU"]
[Tue Jul 21 07:18:52.346820 2026] [security2:error] [pid 229246:tid 229487] [client 4.204.201.85:26390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/11.php"] [unique_id "al9HjCBMYeh5YLVG45xV4QAAAoM"]
[Tue Jul 21 07:18:52.417497 2026] [security2:error] [pid 229246:tid 229474] [client 20.151.10.161:21390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/xmrl.php"] [unique_id "al9HjCBMYeh5YLVG45xV6AAAAnY"]
[Tue Jul 21 07:18:52.419331 2026] [security2:error] [pid 229246:tid 229304] [remote 188.138.102.156:50012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "girassollimpeza.com.br"] [uri "/wp-login.php"] [unique_id "al9HjCBMYeh5YLVG45xV6QACSTk"]
[Tue Jul 21 07:18:52.617183 2026] [security2:error] [pid 229246:tid 229417] [client 20.151.10.161:46018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/green3.php"] [unique_id "al9HjCBMYeh5YLVG45xV9AAAAj0"]
[Tue Jul 21 07:18:52.710554 2026] [security2:error] [pid 229246:tid 229450] [client 4.204.201.85:35407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9HjCBMYeh5YLVG45xV9gAAAl4"]
[Tue Jul 21 07:18:52.829766 2026] [security2:error] [pid 229246:tid 229501] [client 20.197.192.193:8338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/xxx.php"] [unique_id "al9HjCBMYeh5YLVG45xV-AAAApE"]
[Tue Jul 21 07:18:52.855837 2026] [security2:error] [pid 229246:tid 229458] [client 20.197.192.193:17607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HjCBMYeh5YLVG45xV-QAAAmY"]
[Tue Jul 21 07:18:53.009890 2026] [security2:error] [pid 229246:tid 229395] [client 20.197.192.193:22828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HjSBMYeh5YLVG45xV_QAAAic"]
[Tue Jul 21 07:18:53.058636 2026] [security2:error] [pid 229246:tid 229477] [client 4.204.201.85:26599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/mac.php"] [unique_id "al9HjSBMYeh5YLVG45xV_wAAAnk"]
[Tue Jul 21 07:18:53.099709 2026] [security2:error] [pid 229246:tid 229470] [client 20.197.192.193:17615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/dp.php"] [unique_id "al9HjSBMYeh5YLVG45xWAQAAAnI"]
[Tue Jul 21 07:18:53.105599 2026] [security2:error] [pid 229246:tid 229323] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HjSBMYeh5YLVG45xWAgACc0w"]
[Tue Jul 21 07:18:53.105739 2026] [security2:error] [pid 229246:tid 229471] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HjSBMYeh5YLVG45xWAgACc0w"]
[Tue Jul 21 07:18:53.155335 2026] [security2:error] [pid 229246:tid 229378] [client 20.197.192.193:22838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/old.php"] [unique_id "al9HjSBMYeh5YLVG45xWAwAAAhY"]
[Tue Jul 21 07:18:53.179781 2026] [security2:error] [pid 229246:tid 229401] [client 20.197.192.193:17633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/ms-new.php"] [unique_id "al9HjSBMYeh5YLVG45xWBwAAAi0"]
[Tue Jul 21 07:18:53.208083 2026] [security2:error] [pid 229246:tid 229462] [client 20.197.192.193:22789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/track.php"] [unique_id "al9HjSBMYeh5YLVG45xWCQAAAmo"]
[Tue Jul 21 07:18:53.256089 2026] [security2:error] [pid 229246:tid 229449] [client 20.197.192.193:22835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/2352356666.php"] [unique_id "al9HjSBMYeh5YLVG45xWDgAAAl0"]
[Tue Jul 21 07:18:53.400886 2026] [security2:error] [pid 229246:tid 229414] [client 4.204.201.85:35403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wefile.php"] [unique_id "al9HjSBMYeh5YLVG45xWFAAAAjo"]
[Tue Jul 21 07:18:53.513112 2026] [security2:error] [pid 229246:tid 229419] [client 20.197.192.193:17640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/pn.php"] [unique_id "al9HjSBMYeh5YLVG45xWGAAAAj8"]
[Tue Jul 21 07:18:53.554923 2026] [security2:error] [pid 229246:tid 229381] [client 20.197.192.193:22836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wp-wpbak.php"] [unique_id "al9HjSBMYeh5YLVG45xWGgAAAhk"]
[Tue Jul 21 07:18:53.582715 2026] [security2:error] [pid 229246:tid 229500] [client 4.204.201.85:26379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/chosen.php"] [unique_id "al9HjSBMYeh5YLVG45xWGwAAApA"]
[Tue Jul 21 07:18:53.584580 2026] [security2:error] [pid 229246:tid 229435] [client 136.144.33.54:33043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HjSBMYeh5YLVG45xWFgAAAk8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:18:53.602450 2026] [security2:error] [pid 229246:tid 229417] [client 20.197.192.193:22812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/dr.php"] [unique_id "al9HjSBMYeh5YLVG45xWHwAAAj0"]
[Tue Jul 21 07:18:53.625739 2026] [security2:error] [pid 229246:tid 229490] [client 20.151.10.161:50356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/memberfuns.php"] [unique_id "al9HjSBMYeh5YLVG45xWIAAAAoY"]
[Tue Jul 21 07:18:53.684689 2026] [security2:error] [pid 229246:tid 229456] [client 20.197.192.193:22804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/2x.php"] [unique_id "al9HjSBMYeh5YLVG45xWIQAAAmQ"]
[Tue Jul 21 07:18:53.775205 2026] [security2:error] [pid 229246:tid 229501] [client 20.206.105.145:36187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/file6.php"] [unique_id "al9HjSBMYeh5YLVG45xWJQAAApE"]
[Tue Jul 21 07:18:53.901878 2026] [security2:error] [pid 229246:tid 229460] [client 20.197.192.193:22805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/kq1.php"] [unique_id "al9HjSBMYeh5YLVG45xWKwAAAmg"]
[Tue Jul 21 07:18:53.944911 2026] [security2:error] [pid 229246:tid 229446] [client 4.204.201.85:35441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9HjSBMYeh5YLVG45xWLQAAAlo"]
[Tue Jul 21 07:18:54.017401 2026] [security2:error] [pid 229246:tid 229409] [client 20.197.192.193:22785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/zzz.php"] [unique_id "al9HjiBMYeh5YLVG45xWMwAAAjU"]
[Tue Jul 21 07:18:54.049126 2026] [security2:error] [pid 229246:tid 229377] [client 20.197.192.193:17638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wicked.php"] [unique_id "al9HjiBMYeh5YLVG45xWNQAAAhU"]
[Tue Jul 21 07:18:54.108445 2026] [security2:error] [pid 229246:tid 229418] [client 20.226.60.151:54559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/xy.php"] [unique_id "al9HjiBMYeh5YLVG45xWNgAAAj4"]
[Tue Jul 21 07:18:54.114131 2026] [security2:error] [pid 229246:tid 229444] [client 4.204.201.85:26587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/cream1.php"] [unique_id "al9HjiBMYeh5YLVG45xWNwAAAlg"]
[Tue Jul 21 07:18:54.149295 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:17602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/edit.php"] [unique_id "al9HjiBMYeh5YLVG45xWOwAAAoQ"]
[Tue Jul 21 07:18:54.205565 2026] [security2:error] [pid 229246:tid 229390] [client 103.162.129.114:55452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HjiBMYeh5YLVG45xWPAAAAiI"]
[Tue Jul 21 07:18:54.205723 2026] [security2:error] [pid 229246:tid 229390] [client 103.162.129.114:55452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HjiBMYeh5YLVG45xWPAAAAiI"]
[Tue Jul 21 07:18:54.332556 2026] [security2:error] [pid 229246:tid 229381] [client 20.197.192.193:17644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/kua.php"] [unique_id "al9HjiBMYeh5YLVG45xWQQAAAhk"]
[Tue Jul 21 07:18:54.340004 2026] [security2:error] [pid 229246:tid 229451] [client 92.119.178.3:33922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9HjiBMYeh5YLVG45xWQgAAAl8"]
[Tue Jul 21 07:18:54.340108 2026] [security2:error] [pid 229246:tid 229451] [client 92.119.178.3:33922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9HjiBMYeh5YLVG45xWQgAAAl8"]
[Tue Jul 21 07:18:54.395515 2026] [security2:error] [pid 229246:tid 229500] [client 20.197.192.193:22843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/ez.php"] [unique_id "al9HjiBMYeh5YLVG45xWRAAAApA"]
[Tue Jul 21 07:18:54.440042 2026] [security2:error] [pid 229246:tid 229403] [client 20.197.192.193:17642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/fz.php"] [unique_id "al9HjiBMYeh5YLVG45xWRQAAAi8"]
[Tue Jul 21 07:18:54.498641 2026] [security2:error] [pid 229246:tid 229447] [client 103.121.156.110:58412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HjiBMYeh5YLVG45xWSAAAAls"]
[Tue Jul 21 07:18:54.498768 2026] [security2:error] [pid 229246:tid 229447] [client 103.121.156.110:58412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HjiBMYeh5YLVG45xWSAAAAls"]
[Tue Jul 21 07:18:54.514567 2026] [security2:error] [pid 229246:tid 229452] [client 20.197.192.193:22847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/la.php"] [unique_id "al9HjiBMYeh5YLVG45xWSQAAAmA"]
[Tue Jul 21 07:18:54.526519 2026] [security2:error] [pid 229246:tid 229486] [client 20.151.10.161:21490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/ms.php"] [unique_id "al9HjiBMYeh5YLVG45xWSwAAAoI"]
[Tue Jul 21 07:18:54.542208 2026] [security2:error] [pid 229246:tid 229433] [client 20.197.192.193:22839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/nhvoanpl.php"] [unique_id "al9HjiBMYeh5YLVG45xWTwAAAk0"]
[Tue Jul 21 07:18:54.560380 2026] [security2:error] [pid 229246:tid 229421] [client 20.197.192.193:17663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/inso.php"] [unique_id "al9HjiBMYeh5YLVG45xWUAAAAkE"]
[Tue Jul 21 07:18:54.604559 2026] [security2:error] [pid 229246:tid 229389] [client 20.197.192.193:17641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wpx.php"] [unique_id "al9HjiBMYeh5YLVG45xWUwAAAiE"]
[Tue Jul 21 07:18:54.619358 2026] [autoindex:error] [pid 229246:tid 229501] [client 4.204.201.85:35408] AH01276: Cannot serve directory /home3/seaport/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:18:54.674982 2026] [security2:error] [pid 229246:tid 229496] [client 20.197.192.193:22840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/berlin.php"] [unique_id "al9HjiBMYeh5YLVG45xWVwAAAow"]
[Tue Jul 21 07:18:54.740899 2026] [security2:error] [pid 229246:tid 229477] [client 4.204.201.85:26617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/dr.php"] [unique_id "al9HjiBMYeh5YLVG45xWXAAAAnk"]
[Tue Jul 21 07:18:54.764838 2026] [security2:error] [pid 229246:tid 229441] [client 20.197.192.193:22790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/billur.php"] [unique_id "al9HjiBMYeh5YLVG45xWXgAAAlU"]
[Tue Jul 21 07:18:54.866482 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:46041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ccs.php"] [unique_id "al9HjiBMYeh5YLVG45xWXwAAAlo"]
[Tue Jul 21 07:18:54.949764 2026] [autoindex:error] [pid 229246:tid 229464] [client 4.204.201.85:35408] AH01276: Cannot serve directory /home3/seaport/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:18:54.966087 2026] [security2:error] [pid 229246:tid 229377] [client 20.197.192.193:22793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/mimpi.php"] [unique_id "al9HjiBMYeh5YLVG45xWYQAAAhU"]
[Tue Jul 21 07:18:55.109903 2026] [security2:error] [pid 229246:tid 229459] [client 4.204.201.85:35346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9HjyBMYeh5YLVG45xWZwAAAmc"]
[Tue Jul 21 07:18:55.157908 2026] [security2:error] [pid 229246:tid 229475] [client 20.197.192.193:22803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/dp.php"] [unique_id "al9HjyBMYeh5YLVG45xWaQAAAnc"]
[Tue Jul 21 07:18:55.251207 2026] [security2:error] [pid 229246:tid 229448] [client 4.204.201.85:26383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/x.php"] [unique_id "al9HjyBMYeh5YLVG45xWcgAAAlw"]
[Tue Jul 21 07:18:55.276354 2026] [security2:error] [pid 229246:tid 229487] [client 20.197.192.193:22820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/bootstrap.php"] [unique_id "al9HjyBMYeh5YLVG45xWcwAAAoM"]
[Tue Jul 21 07:18:55.320945 2026] [security2:error] [pid 229246:tid 229419] [client 20.206.105.145:36061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/a2.php"] [unique_id "al9HjyBMYeh5YLVG45xWdAAAAj8"]
[Tue Jul 21 07:18:55.323899 2026] [security2:error] [pid 229246:tid 229381] [client 20.197.192.193:22832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wp-editor.php"] [unique_id "al9HjyBMYeh5YLVG45xWdQAAAhk"]
[Tue Jul 21 07:18:55.355970 2026] [security2:error] [pid 229246:tid 229417] [client 20.197.192.193:17654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/cro.php"] [unique_id "al9HjyBMYeh5YLVG45xWdgAAAj0"]
[Tue Jul 21 07:18:55.413775 2026] [security2:error] [pid 229246:tid 229455] [client 20.197.192.193:22819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/cron-tab.php"] [unique_id "al9HjyBMYeh5YLVG45xWdwAAAmM"]
[Tue Jul 21 07:18:55.483546 2026] [security2:error] [pid 229246:tid 229450] [client 20.197.192.193:17652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/koiy.php"] [unique_id "al9HjyBMYeh5YLVG45xWegAAAl4"]
[Tue Jul 21 07:18:55.559918 2026] [security2:error] [pid 229246:tid 229490] [client 20.197.192.193:17435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/hp2.php"] [unique_id "al9HjyBMYeh5YLVG45xWewAAAoY"]
[Tue Jul 21 07:18:55.581671 2026] [security2:error] [pid 229246:tid 229492] [client 4.204.201.85:26595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/155.php"] [unique_id "al9HjyBMYeh5YLVG45xWfQAAAog"]
[Tue Jul 21 07:18:55.660975 2026] [security2:error] [pid 229246:tid 229493] [client 20.197.192.193:22796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/hp3.php"] [unique_id "al9HjyBMYeh5YLVG45xWgQAAAok"]
[Tue Jul 21 07:18:55.739881 2026] [security2:error] [pid 229246:tid 229458] [client 20.197.192.193:17610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/aa1.php"] [unique_id "al9HjyBMYeh5YLVG45xWhQAAAmY"]
[Tue Jul 21 07:18:55.743598 2026] [security2:error] [pid 229246:tid 229451] [client 14.139.42.196:31759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HjyBMYeh5YLVG45xWhgAAAl8"]
[Tue Jul 21 07:18:55.743706 2026] [security2:error] [pid 229246:tid 229451] [client 14.139.42.196:31759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HjyBMYeh5YLVG45xWhgAAAl8"]
[Tue Jul 21 07:18:55.835764 2026] [security2:error] [pid 229246:tid 229491] [client 4.204.201.85:35381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/8.php"] [unique_id "al9HjyBMYeh5YLVG45xWjAAAAoc"]
[Tue Jul 21 07:18:55.873143 2026] [security2:error] [pid 229246:tid 229456] [client 20.197.192.193:17600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/acew67.php"] [unique_id "al9HjyBMYeh5YLVG45xWjQAAAmQ"]
[Tue Jul 21 07:18:56.009254 2026] [security2:error] [pid 229246:tid 229401] [client 20.197.192.193:17627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/bscclapb.php"] [unique_id "al9HkCBMYeh5YLVG45xWjgAAAi0"]
[Tue Jul 21 07:18:56.034686 2026] [security2:error] [pid 229246:tid 229378] [client 4.204.201.85:26571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ops.php"] [unique_id "al9HkCBMYeh5YLVG45xWjwAAAhY"]
[Tue Jul 21 07:18:56.071881 2026] [security2:error] [pid 229246:tid 229377] [client 20.220.225.223:39539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/ez.php"] [unique_id "al9HkCBMYeh5YLVG45xWkAAAAhU"]
[Tue Jul 21 07:18:56.417506 2026] [security2:error] [pid 229246:tid 229390] [client 4.204.201.85:26373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/file31.php"] [unique_id "al9HkCBMYeh5YLVG45xWnAAAAiI"]
[Tue Jul 21 07:18:56.459858 2026] [security2:error] [pid 229246:tid 229476] [client 20.197.192.193:17613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/else1.php"] [unique_id "al9HkCBMYeh5YLVG45xWoAAAAng"]
[Tue Jul 21 07:18:56.749510 2026] [security2:error] [pid 229246:tid 229452] [client 4.204.201.85:26613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/file6.php"] [unique_id "al9HkCBMYeh5YLVG45xWpQAAAmA"]
[Tue Jul 21 07:18:56.912876 2026] [security2:error] [pid 229246:tid 229454] [client 20.197.192.193:17601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/tkikikoko.php"] [unique_id "al9HkCBMYeh5YLVG45xWqgAAAmI"]
[Tue Jul 21 07:18:56.961882 2026] [security2:error] [pid 229246:tid 229431] [client 20.151.10.161:45981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ccc.php"] [unique_id "al9HkCBMYeh5YLVG45xWrAAAAks"]
[Tue Jul 21 07:18:57.193085 2026] [security2:error] [pid 229246:tid 229399] [client 4.204.201.85:26380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/adminfuns.php"] [unique_id "al9HkSBMYeh5YLVG45xWswAAAis"]
[Tue Jul 21 07:18:57.216594 2026] [security2:error] [pid 229246:tid 229248] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HkSBMYeh5YLVG45xWtQACaAE"]
[Tue Jul 21 07:18:57.216730 2026] [security2:error] [pid 229246:tid 229460] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HkSBMYeh5YLVG45xWtQACaAE"]
[Tue Jul 21 07:18:57.235668 2026] [security2:error] [pid 229246:tid 229409] [client 193.36.225.60:23887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HkSBMYeh5YLVG45xWtgAAAjU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:18:57.237060 2026] [security2:error] [pid 229246:tid 229456] [client 20.197.192.193:17650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wp-Blogs.php"] [unique_id "al9HkSBMYeh5YLVG45xWtwAAAmQ"]
[Tue Jul 21 07:18:57.240625 2026] [security2:error] [pid 229246:tid 229482] [client 20.151.10.161:21458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/zz.php"] [unique_id "al9HkSBMYeh5YLVG45xWuQAAAn4"]
[Tue Jul 21 07:18:57.282157 2026] [security2:error] [pid 229246:tid 229497] [client 68.235.38.2:48738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9HkSBMYeh5YLVG45xWvQAAAo0"]
[Tue Jul 21 07:18:57.282251 2026] [security2:error] [pid 229246:tid 229497] [client 68.235.38.2:48738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9HkSBMYeh5YLVG45xWvQAAAo0"]
[Tue Jul 21 07:18:57.359505 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:17439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wp-css.php"] [unique_id "al9HkSBMYeh5YLVG45xWvwAAAn0"]
[Tue Jul 21 07:18:57.417101 2026] [security2:error] [pid 229246:tid 229469] [client 20.197.192.193:22786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/wp-explorer.php"] [unique_id "al9HkSBMYeh5YLVG45xWwwAAAnE"]
[Tue Jul 21 07:18:57.471648 2026] [security2:error] [pid 229246:tid 229402] [client 20.197.192.193:22798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/akismet.php"] [unique_id "al9HkSBMYeh5YLVG45xWxgAAAi4"]
[Tue Jul 21 07:18:57.497558 2026] [security2:error] [pid 229246:tid 229284] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HkSBMYeh5YLVG45xWyAACWiU"]
[Tue Jul 21 07:18:57.497696 2026] [security2:error] [pid 229246:tid 229446] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HkSBMYeh5YLVG45xWyAACWiU"]
[Tue Jul 21 07:18:57.507343 2026] [security2:error] [pid 229246:tid 229466] [client 20.197.192.193:22807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/ace2.php"] [unique_id "al9HkSBMYeh5YLVG45xWyQAAAm4"]
[Tue Jul 21 07:18:57.517403 2026] [security2:error] [pid 229246:tid 229403] [client 4.204.201.85:26569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/goods.php"] [unique_id "al9HkSBMYeh5YLVG45xWygAAAi8"]
[Tue Jul 21 07:18:57.551455 2026] [security2:error] [pid 229246:tid 229382] [client 20.197.192.193:22826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "imap.gradiente.com"] [uri "/ms.php"] [unique_id "al9HkSBMYeh5YLVG45xWzAAAAho"]
[Tue Jul 21 07:18:57.828707 2026] [security2:error] [pid 229246:tid 229474] [client 4.204.201.85:26412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/100.php"] [unique_id "al9HkSBMYeh5YLVG45xWzwAAAnY"]
[Tue Jul 21 07:18:57.944893 2026] [security2:error] [pid 229246:tid 229379] [client 20.206.105.145:36161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/file15.php"] [unique_id "al9HkSBMYeh5YLVG45xW1QAAAhc"]
[Tue Jul 21 07:18:58.070024 2026] [security2:error] [pid 229246:tid 229458] [client 20.220.225.223:52771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/fz.php"] [unique_id "al9HkiBMYeh5YLVG45xW1gAAAmY"]
[Tue Jul 21 07:18:58.093871 2026] [security2:error] [pid 229246:tid 229496] [client 4.204.201.85:35363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9HkiBMYeh5YLVG45xW1wAAAow"]
[Tue Jul 21 07:18:58.213140 2026] [security2:error] [pid 229246:tid 229395] [client 4.204.201.85:26375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/about.php"] [unique_id "al9HkiBMYeh5YLVG45xW2wAAAic"]
[Tue Jul 21 07:18:58.273507 2026] [security2:error] [pid 229246:tid 229452] [client 139.135.44.145:54632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HkiBMYeh5YLVG45xW3AAAAmA"]
[Tue Jul 21 07:18:58.273627 2026] [security2:error] [pid 229246:tid 229452] [client 139.135.44.145:54632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HkiBMYeh5YLVG45xW3AAAAmA"]
[Tue Jul 21 07:18:58.431424 2026] [security2:error] [pid 229246:tid 229418] [client 20.206.105.145:36082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/jp.php"] [unique_id "al9HkiBMYeh5YLVG45xW3gAAAj4"]
[Tue Jul 21 07:18:58.505876 2026] [security2:error] [pid 229246:tid 229463] [client 20.151.10.161:21502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/for.php"] [unique_id "al9HkiBMYeh5YLVG45xW5gAAAms"]
[Tue Jul 21 07:18:58.579456 2026] [security2:error] [pid 229246:tid 229490] [client 74.244.195.153:47569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HkiBMYeh5YLVG45xW6AAAAoY"]
[Tue Jul 21 07:18:58.586604 2026] [security2:error] [pid 229246:tid 229490] [client 74.244.195.153:47569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HkiBMYeh5YLVG45xW6AAAAoY"]
[Tue Jul 21 07:18:58.663406 2026] [security2:error] [pid 229246:tid 229467] [client 20.151.10.161:53578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HkiBMYeh5YLVG45xW6gAAAm8"]
[Tue Jul 21 07:18:58.681115 2026] [security2:error] [pid 229246:tid 229294] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HkiBMYeh5YLVG45xW6wACcS8"]
[Tue Jul 21 07:18:58.695695 2026] [security2:error] [pid 229246:tid 229266] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HkiBMYeh5YLVG45xW7AACVBM"]
[Tue Jul 21 07:18:58.698697 2026] [security2:error] [pid 229246:tid 229501] [client 4.204.201.85:26590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/about.php"] [unique_id "al9HkiBMYeh5YLVG45xW7QAAApE"]
[Tue Jul 21 07:18:58.772518 2026] [security2:error] [pid 229246:tid 229291] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/xyn.php"] [unique_id "al9HkiBMYeh5YLVG45xW8gACNiw"]
[Tue Jul 21 07:18:58.779788 2026] [security2:error] [pid 229246:tid 229296] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HkiBMYeh5YLVG45xW8wACQzE"]
[Tue Jul 21 07:18:58.779925 2026] [security2:error] [pid 229246:tid 229423] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HkiBMYeh5YLVG45xW8wACQzE"]
[Tue Jul 21 07:18:58.822530 2026] [security2:error] [pid 229246:tid 229308] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/patie.php"] [unique_id "al9HkiBMYeh5YLVG45xW9AAChT0"]
[Tue Jul 21 07:18:59.116074 2026] [proxy:error] [pid 229246:tid 229419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:18:59.116120 2026] [proxy_http:error] [pid 229246:tid 229419] [client 146.190.25.162:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:18:59.116722 2026] [proxy:error] [pid 229246:tid 229419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:18:59.116742 2026] [proxy_http:error] [pid 229246:tid 229419] [client 146.190.25.162:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:18:59.118964 2026] [security2:error] [pid 229246:tid 229493] [client 20.151.10.161:53631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HkyBMYeh5YLVG45xW_wAAAok"]
[Tue Jul 21 07:18:59.147119 2026] [security2:error] [pid 229246:tid 229413] [client 20.151.10.161:46064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/get.php"] [unique_id "al9HkyBMYeh5YLVG45xXAQAAAjk"]
[Tue Jul 21 07:18:59.147522 2026] [security2:error] [pid 229246:tid 229431] [client 4.204.201.85:26406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/admin.php"] [unique_id "al9HkyBMYeh5YLVG45xXAgAAAks"]
[Tue Jul 21 07:18:59.182197 2026] [security2:error] [pid 229246:tid 229468] [client 45.251.232.145:58028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HkyBMYeh5YLVG45xXAwAAAnA"]
[Tue Jul 21 07:18:59.182315 2026] [security2:error] [pid 229246:tid 229468] [client 45.251.232.145:58028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HkyBMYeh5YLVG45xXAwAAAnA"]
[Tue Jul 21 07:18:59.324345 2026] [security2:error] [pid 229246:tid 229307] [remote 68.178.160.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9HkyBMYeh5YLVG45xXBgACHTw"]
[Tue Jul 21 07:18:59.332790 2026] [security2:error] [pid 229246:tid 229313] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HkyBMYeh5YLVG45xXBwACIEI"]
[Tue Jul 21 07:18:59.332984 2026] [security2:error] [pid 229246:tid 229388] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HkyBMYeh5YLVG45xXBwACIEI"]
[Tue Jul 21 07:18:59.416010 2026] [proxy:error] [pid 229246:tid 229453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:18:59.416073 2026] [proxy_http:error] [pid 229246:tid 229453] [client 146.190.25.162:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.brunopacolla1749139258240.0721679.meusitehostgator.com.br/
[Tue Jul 21 07:18:59.416762 2026] [proxy:error] [pid 229246:tid 229453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:18:59.416787 2026] [proxy_http:error] [pid 229246:tid 229453] [client 146.190.25.162:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.brunopacolla1749139258240.0721679.meusitehostgator.com.br/
[Tue Jul 21 07:18:59.587221 2026] [security2:error] [pid 229246:tid 229462] [client 4.204.201.85:26377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/admin.php"] [unique_id "al9HkyBMYeh5YLVG45xXGAAAAmo"]
[Tue Jul 21 07:18:59.621904 2026] [security2:error] [pid 229246:tid 229475] [client 20.151.10.161:55253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/x.php"] [unique_id "al9HkyBMYeh5YLVG45xXGgAAAnc"]
[Tue Jul 21 07:18:59.674414 2026] [security2:error] [pid 229246:tid 229464] [client 74.7.230.14:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cristianepbbegosso1748480777915.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9HkyBMYeh5YLVG45xXHAACbEk"]
[Tue Jul 21 07:18:59.899726 2026] [security2:error] [pid 229246:tid 229470] [client 20.226.60.151:54468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/loader.php"] [unique_id "al9HkyBMYeh5YLVG45xXHwAAAnI"]
[Tue Jul 21 07:18:59.984903 2026] [security2:error] [pid 229246:tid 229429] [client 4.204.201.85:35344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/f6.php"] [unique_id "al9HkyBMYeh5YLVG45xXIwAAAkk"]
[Tue Jul 21 07:19:00.070762 2026] [security2:error] [pid 229246:tid 229419] [client 4.204.201.85:26604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/themes.php"] [unique_id "al9HlCBMYeh5YLVG45xXKQAAAj8"]
[Tue Jul 21 07:19:00.109335 2026] [security2:error] [pid 229246:tid 229414] [client 20.220.225.223:52775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/la.php"] [unique_id "al9HlCBMYeh5YLVG45xXLAAAAjo"]
[Tue Jul 21 07:19:00.155780 2026] [security2:error] [pid 229246:tid 229389] [client 20.151.10.161:55253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/j260624_13.php"] [unique_id "al9HlCBMYeh5YLVG45xXLQAAAiE"]
[Tue Jul 21 07:19:00.158222 2026] [security2:error] [pid 229246:tid 229474] [client 20.151.10.161:21378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/yup.php"] [unique_id "al9HlCBMYeh5YLVG45xXLgAAAnY"]
[Tue Jul 21 07:19:00.200683 2026] [security2:error] [pid 229246:tid 229379] [client 68.235.38.2:38400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9HlCBMYeh5YLVG45xXLwAAAhc"]
[Tue Jul 21 07:19:00.200789 2026] [security2:error] [pid 229246:tid 229379] [client 68.235.38.2:38400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9HlCBMYeh5YLVG45xXLwAAAhc"]
[Tue Jul 21 07:19:00.339033 2026] [security2:error] [pid 229246:tid 229458] [client 20.206.105.145:35851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/f35.php"] [unique_id "al9HlCBMYeh5YLVG45xXMgAAAmY"]
[Tue Jul 21 07:19:00.727606 2026] [security2:error] [pid 229246:tid 229490] [client 20.151.10.161:53585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/d62.php"] [unique_id "al9HlCBMYeh5YLVG45xXQAAAAoY"]
[Tue Jul 21 07:19:00.929041 2026] [security2:error] [pid 229246:tid 229463] [client 4.204.201.85:26618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/.well-known/about.php"] [unique_id "al9HlCBMYeh5YLVG45xXRQAAAms"]
[Tue Jul 21 07:19:00.963466 2026] [security2:error] [pid 229246:tid 229406] [client 20.206.105.145:35971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/wp-load.php"] [unique_id "al9HlCBMYeh5YLVG45xXRwAAAjI"]
[Tue Jul 21 07:19:00.969033 2026] [security2:error] [pid 229246:tid 229423] [client 20.151.10.161:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/images.php"] [unique_id "al9HlCBMYeh5YLVG45xXSAAAAkM"]
[Tue Jul 21 07:19:00.992991 2026] [security2:error] [pid 229246:tid 229341] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/aa.php"] [unique_id "al9HlCBMYeh5YLVG45xXSQACPF4"]
[Tue Jul 21 07:19:01.022383 2026] [security2:error] [pid 229246:tid 229345] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/xwpg.php"] [unique_id "al9HlSBMYeh5YLVG45xXSwACcmI"]
[Tue Jul 21 07:19:01.039186 2026] [security2:error] [pid 229246:tid 229346] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ops.php"] [unique_id "al9HlSBMYeh5YLVG45xXTAACg2M"]
[Tue Jul 21 07:19:01.054166 2026] [security2:error] [pid 229246:tid 229344] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/mac.php"] [unique_id "al9HlSBMYeh5YLVG45xXTQACgmE"]
[Tue Jul 21 07:19:01.068323 2026] [security2:error] [pid 229246:tid 229335] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/mg.php"] [unique_id "al9HlSBMYeh5YLVG45xXTgACSVg"]
[Tue Jul 21 07:19:01.081859 2026] [security2:error] [pid 229246:tid 229494] [client 175.45.70.82:62386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HlSBMYeh5YLVG45xXTwAAAoo"]
[Tue Jul 21 07:19:01.081998 2026] [security2:error] [pid 229246:tid 229494] [client 175.45.70.82:62386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HlSBMYeh5YLVG45xXTwAAAoo"]
[Tue Jul 21 07:19:01.082173 2026] [security2:error] [pid 229246:tid 229348] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-post-data.php"] [unique_id "al9HlSBMYeh5YLVG45xXUAACL2U"]
[Tue Jul 21 07:19:01.103473 2026] [security2:error] [pid 229246:tid 229338] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/pucci.php"] [unique_id "al9HlSBMYeh5YLVG45xXVwACTVs"]
[Tue Jul 21 07:19:01.116302 2026] [security2:error] [pid 229246:tid 229467] [client 193.36.225.57:50793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HlCBMYeh5YLVG45xXRgAAAm8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:01.118080 2026] [security2:error] [pid 229246:tid 229352] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/black.php"] [unique_id "al9HlSBMYeh5YLVG45xXWAACdmk"]
[Tue Jul 21 07:19:01.149308 2026] [security2:error] [pid 229246:tid 229340] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/zlece.php"] [unique_id "al9HlSBMYeh5YLVG45xXWQACRl0"]
[Tue Jul 21 07:19:01.195591 2026] [security2:error] [pid 229246:tid 229349] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/vssrs.php"] [unique_id "al9HlSBMYeh5YLVG45xXWgACHGY"]
[Tue Jul 21 07:19:01.245493 2026] [security2:error] [pid 229246:tid 229347] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wicked.php"] [unique_id "al9HlSBMYeh5YLVG45xXXAACGGQ"]
[Tue Jul 21 07:19:01.259524 2026] [security2:error] [pid 229246:tid 229343] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/24.php"] [unique_id "al9HlSBMYeh5YLVG45xXXgACPWA"]
[Tue Jul 21 07:19:01.274955 2026] [security2:error] [pid 229246:tid 229350] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/xacs.php"] [unique_id "al9HlSBMYeh5YLVG45xXYAACLGc"]
[Tue Jul 21 07:19:01.290296 2026] [security2:error] [pid 229246:tid 229357] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/zildan.php"] [unique_id "al9HlSBMYeh5YLVG45xXYwACaW4"]
[Tue Jul 21 07:19:01.294016 2026] [security2:error] [pid 229246:tid 229396] [client 4.204.201.85:26598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9HlSBMYeh5YLVG45xXZAAAAig"]
[Tue Jul 21 07:19:01.305054 2026] [security2:error] [pid 229246:tid 229363] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/csa.php"] [unique_id "al9HlSBMYeh5YLVG45xXZQACe3Q"]
[Tue Jul 21 07:19:01.354849 2026] [security2:error] [pid 229246:tid 229378] [client 20.151.10.161:45996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/alls.php"] [unique_id "al9HlSBMYeh5YLVG45xXaAAAAhY"]
[Tue Jul 21 07:19:01.391456 2026] [security2:error] [pid 229246:tid 229497] [client 20.206.105.145:36060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/xwpg.php"] [unique_id "al9HlSBMYeh5YLVG45xXagAAAo0"]
[Tue Jul 21 07:19:01.452882 2026] [security2:error] [pid 229246:tid 229409] [client 20.151.10.161:53630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ups.php"] [unique_id "al9HlSBMYeh5YLVG45xXawAAAjU"]
[Tue Jul 21 07:19:01.640314 2026] [security2:error] [pid 229246:tid 229457] [client 4.204.201.85:26588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wefile.php"] [unique_id "al9HlSBMYeh5YLVG45xXcwAAAmU"]
[Tue Jul 21 07:19:01.645586 2026] [security2:error] [pid 229246:tid 229371] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/w3llscc.php"] [unique_id "al9HlSBMYeh5YLVG45xXdAACVXw"]
[Tue Jul 21 07:19:01.670884 2026] [security2:error] [pid 229246:tid 229365] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wpx.php"] [unique_id "al9HlSBMYeh5YLVG45xXdQACcXY"]
[Tue Jul 21 07:19:01.711384 2026] [security2:error] [pid 229246:tid 229250] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-css.php"] [unique_id "al9HlSBMYeh5YLVG45xXeAACXAM"]
[Tue Jul 21 07:19:01.743517 2026] [security2:error] [pid 229246:tid 229262] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ho.php"] [unique_id "al9HlSBMYeh5YLVG45xXegAChQ8"]
[Tue Jul 21 07:19:01.875949 2026] [security2:error] [pid 229246:tid 229429] [client 184.75.221.3:46292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9HlSBMYeh5YLVG45xXewAAAkk"]
[Tue Jul 21 07:19:01.876046 2026] [security2:error] [pid 229246:tid 229429] [client 184.75.221.3:46292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9HlSBMYeh5YLVG45xXewAAAkk"]
[Tue Jul 21 07:19:01.917295 2026] [security2:error] [pid 229246:tid 229466] [client 20.151.10.161:53609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k.php"] [unique_id "al9HlSBMYeh5YLVG45xXfQAAAm4"]
[Tue Jul 21 07:19:02.059053 2026] [security2:error] [pid 229246:tid 229454] [client 4.204.201.85:26611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9HliBMYeh5YLVG45xXgAAAAmI"]
[Tue Jul 21 07:19:02.060340 2026] [security2:error] [pid 229246:tid 229280] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HliBMYeh5YLVG45xXgQACLyE"]
[Tue Jul 21 07:19:02.060504 2026] [security2:error] [pid 229246:tid 229403] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HliBMYeh5YLVG45xXgQACLyE"]
[Tue Jul 21 07:19:02.083494 2026] [security2:error] [pid 229246:tid 229452] [client 120.61.173.56:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HliBMYeh5YLVG45xXgwAAAmA"]
[Tue Jul 21 07:19:02.083647 2026] [security2:error] [pid 229246:tid 229452] [client 120.61.173.56:50594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HliBMYeh5YLVG45xXgwAAAmA"]
[Tue Jul 21 07:19:02.097766 2026] [security2:error] [pid 229246:tid 229419] [client 4.204.201.85:35400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/inputs.php"] [unique_id "al9HliBMYeh5YLVG45xXhAAAAj8"]
[Tue Jul 21 07:19:02.277348 2026] [security2:error] [pid 229246:tid 229257] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HliBMYeh5YLVG45xXjQACIAo"]
[Tue Jul 21 07:19:02.277522 2026] [security2:error] [pid 229246:tid 229388] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HliBMYeh5YLVG45xXjQACIAo"]
[Tue Jul 21 07:19:02.293378 2026] [security2:error] [pid 229246:tid 229396] [client 20.206.105.145:36162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/waf.php"] [unique_id "al9HliBMYeh5YLVG45xXjgAAAig"]
[Tue Jul 21 07:19:02.348294 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:46036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/yyu.php"] [unique_id "al9HliBMYeh5YLVG45xXkAAAAns"]
[Tue Jul 21 07:19:02.390665 2026] [security2:error] [pid 229246:tid 229436] [client 20.151.10.161:53620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k2.php"] [unique_id "al9HliBMYeh5YLVG45xXkgAAAlA"]
[Tue Jul 21 07:19:02.438267 2026] [security2:error] [pid 229246:tid 229476] [client 20.206.105.145:35984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/xstelth.php"] [unique_id "al9HliBMYeh5YLVG45xXlAAAAng"]
[Tue Jul 21 07:19:02.478873 2026] [security2:error] [pid 229246:tid 229482] [client 20.206.105.145:35884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/wp-links.php"] [unique_id "al9HliBMYeh5YLVG45xXlQAAAn4"]
[Tue Jul 21 07:19:02.503856 2026] [security2:error] [pid 229246:tid 229484] [client 20.206.105.145:36195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9HliBMYeh5YLVG45xXlwAAAoA"]
[Tue Jul 21 07:19:02.536687 2026] [security2:error] [pid 229246:tid 229462] [client 20.206.105.145:36165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.reidocouro.com.br"] [uri "/aaa.php"] [unique_id "al9HliBMYeh5YLVG45xXmQAAAmo"]
[Tue Jul 21 07:19:02.637234 2026] [security2:error] [pid 229246:tid 229278] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/xy.php"] [unique_id "al9HliBMYeh5YLVG45xXoAACfR8"]
[Tue Jul 21 07:19:02.638917 2026] [security2:error] [pid 229246:tid 229457] [client 4.204.201.85:26006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9HliBMYeh5YLVG45xXoQAAAmU"]
[Tue Jul 21 07:19:02.801649 2026] [security2:error] [pid 229246:tid 229448] [client 20.220.225.223:43033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9HliBMYeh5YLVG45xXowAAAlw"]
[Tue Jul 21 07:19:02.855949 2026] [security2:error] [pid 229246:tid 229401] [client 114.119.130.33:57485] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carrosselbuique.com.br"] [uri "/wp-content/uploads/2017/07/CONTE%C3%9ADOS-PARA-RECUPERA%C3%87%C3%83O-I-SEMESTRE.docx"] [unique_id "al9HliBMYeh5YLVG45xXpQAAAi0"], referer: https://carrosselbuique.com.br/wp-content/uploads/2017/07/CONTE%C3%9ADOS-PARA-RECUPERA%C3%87%C3%83O-I-SEMESTRE.docx
[Tue Jul 21 07:19:02.923225 2026] [security2:error] [pid 229246:tid 229501] [client 4.204.201.85:26620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/8.php"] [unique_id "al9HliBMYeh5YLVG45xXpgAAApE"]
[Tue Jul 21 07:19:02.960326 2026] [security2:error] [pid 229246:tid 229410] [client 20.151.10.161:21312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/wpxml.php"] [unique_id "al9HliBMYeh5YLVG45xXqAAAAjY"]
[Tue Jul 21 07:19:03.097808 2026] [security2:error] [pid 229246:tid 229377] [client 20.151.10.161:53590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k3.php"] [unique_id "al9HlyBMYeh5YLVG45xXqgAAAhU"]
[Tue Jul 21 07:19:03.256526 2026] [security2:error] [pid 229246:tid 229419] [client 20.151.10.161:46046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/by.php"] [unique_id "al9HlyBMYeh5YLVG45xXsAAAAj8"]
[Tue Jul 21 07:19:03.269610 2026] [security2:error] [pid 229246:tid 229431] [client 4.204.201.85:26391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9HlyBMYeh5YLVG45xXsQAAAks"]
[Tue Jul 21 07:19:03.448923 2026] [autoindex:error] [pid 229246:tid 229384] [client 147.185.132.231:58302] AH01276: Cannot serve directory /home4/dralul00/idufinance.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:03.648714 2026] [security2:error] [pid 229246:tid 229390] [client 4.204.201.85:26044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/f6.php"] [unique_id "al9HlyBMYeh5YLVG45xXugAAAiI"]
[Tue Jul 21 07:19:03.651058 2026] [security2:error] [pid 229246:tid 229264] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HlyBMYeh5YLVG45xXuwACHxE"]
[Tue Jul 21 07:19:03.651173 2026] [security2:error] [pid 229246:tid 229387] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HlyBMYeh5YLVG45xXuwACHxE"]
[Tue Jul 21 07:19:03.750554 2026] [security2:error] [pid 229246:tid 229491] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arthromdcanada.online"] [uri "/index.php"] [unique_id "al9HlyBMYeh5YLVG45xXwwAAAoc"]
[Tue Jul 21 07:19:03.751809 2026] [security2:error] [pid 229246:tid 229499] [client 20.10.88.227:2371] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arthromdcanada.online"] [uri "/robots.txt"] [unique_id "al9HlyBMYeh5YLVG45xXwAAAAo8"]
[Tue Jul 21 07:19:03.968059 2026] [security2:error] [pid 229246:tid 229490] [client 4.204.201.85:26602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/inputs.php"] [unique_id "al9HlyBMYeh5YLVG45xXxgAAAoY"]
[Tue Jul 21 07:19:04.247401 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:45921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/FAQ.php"] [unique_id "al9HmCBMYeh5YLVG45xXzQAAAlo"]
[Tue Jul 21 07:19:04.275939 2026] [security2:error] [pid 229246:tid 229470] [client 4.204.201.85:26429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/inputs.php"] [unique_id "al9HmCBMYeh5YLVG45xXzgAAAnI"]
[Tue Jul 21 07:19:04.409880 2026] [security2:error] [pid 229246:tid 229265] [remote 47.128.44.67:29658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gradiente.com.br"] [uri "/soundbar-1000w-woofer-5-2-3d-arc-optica-bth-usb-gst107---gradiente-bivolt/p"] [unique_id "al9HmCBMYeh5YLVG45xX0wACbhI"]
[Tue Jul 21 07:19:04.708546 2026] [security2:error] [pid 229246:tid 229417] [client 4.204.201.85:26603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/classwithtostring.php"] [unique_id "al9HmCBMYeh5YLVG45xX2gAAAj0"]
[Tue Jul 21 07:19:04.857841 2026] [security2:error] [pid 229246:tid 229378] [client 193.36.225.55:47165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HmCBMYeh5YLVG45xX3wAAAhY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:04.878780 2026] [security2:error] [pid 229246:tid 229301] [remote 182.77.62.24:55128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9HmCBMYeh5YLVG45xX4AACKTY"]
[Tue Jul 21 07:19:04.913604 2026] [security2:error] [pid 229246:tid 229489] [client 103.162.129.114:55951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HmCBMYeh5YLVG45xX4QAAAoU"]
[Tue Jul 21 07:19:04.913773 2026] [security2:error] [pid 229246:tid 229489] [client 103.162.129.114:55951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HmCBMYeh5YLVG45xX4QAAAoU"]
[Tue Jul 21 07:19:04.917533 2026] [security2:error] [pid 229246:tid 229390] [client 20.151.10.161:46054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/coffexium.php"] [unique_id "al9HmCBMYeh5YLVG45xX4gAAAiI"]
[Tue Jul 21 07:19:04.918863 2026] [security2:error] [pid 229246:tid 229482] [client 20.226.60.151:54518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/spadex.php"] [unique_id "al9HmCBMYeh5YLVG45xX4wAAAn4"]
[Tue Jul 21 07:19:05.131223 2026] [security2:error] [pid 229246:tid 229414] [client 103.121.156.110:58746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HmSBMYeh5YLVG45xX5QAAAjo"]
[Tue Jul 21 07:19:05.131357 2026] [security2:error] [pid 229246:tid 229414] [client 103.121.156.110:58746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HmSBMYeh5YLVG45xX5QAAAjo"]
[Tue Jul 21 07:19:05.220949 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:26382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9HmSBMYeh5YLVG45xX6QAAAn8"]
[Tue Jul 21 07:19:05.255746 2026] [security2:error] [pid 229246:tid 229434] [client 20.206.67.15:61300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HmSBMYeh5YLVG45xX7QAAAk4"]
[Tue Jul 21 07:19:05.283090 2026] [security2:error] [pid 229246:tid 229481] [client 20.206.67.15:61268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HmSBMYeh5YLVG45xX7wAAAn0"]
[Tue Jul 21 07:19:05.321984 2026] [security2:error] [pid 229246:tid 229469] [client 20.206.67.15:61243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/sql.php"] [unique_id "al9HmSBMYeh5YLVG45xX8AAAAnE"]
[Tue Jul 21 07:19:05.372113 2026] [security2:error] [pid 229246:tid 229448] [client 20.151.10.161:53615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k4.php"] [unique_id "al9HmSBMYeh5YLVG45xX8gAAAlw"]
[Tue Jul 21 07:19:05.380700 2026] [security2:error] [pid 229246:tid 229501] [client 20.206.67.15:61219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/1index.php"] [unique_id "al9HmSBMYeh5YLVG45xX8wAAApE"]
[Tue Jul 21 07:19:05.381786 2026] [security2:error] [pid 229246:tid 229451] [client 20.151.10.161:46044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/red.php"] [unique_id "al9HmSBMYeh5YLVG45xX9AAAAl8"]
[Tue Jul 21 07:19:05.411956 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:51404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/fffm.php"] [unique_id "al9HmSBMYeh5YLVG45xX9gAAAlo"]
[Tue Jul 21 07:19:05.457529 2026] [security2:error] [pid 229246:tid 229377] [client 20.206.67.15:61273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/reop1.php"] [unique_id "al9HmSBMYeh5YLVG45xX9wAAAhU"]
[Tue Jul 21 07:19:05.517650 2026] [security2:error] [pid 229246:tid 229454] [client 20.206.67.15:61283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/trusj18.php"] [unique_id "al9HmSBMYeh5YLVG45xX-QAAAmI"]
[Tue Jul 21 07:19:05.526738 2026] [security2:error] [pid 229246:tid 229423] [client 20.197.192.193:8365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/hunter.php"] [unique_id "al9HmSBMYeh5YLVG45xX-gAAAkM"]
[Tue Jul 21 07:19:05.620155 2026] [security2:error] [pid 229246:tid 229496] [client 20.206.67.15:61206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/trusj15.php"] [unique_id "al9HmSBMYeh5YLVG45xX_wAAAow"]
[Tue Jul 21 07:19:05.655434 2026] [security2:error] [pid 229246:tid 229380] [client 20.206.67.15:61184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/rft8.php"] [unique_id "al9HmSBMYeh5YLVG45xYAQAAAhg"]
[Tue Jul 21 07:19:05.691853 2026] [security2:error] [pid 229246:tid 229436] [client 4.204.201.85:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/inputs.php"] [unique_id "al9HmSBMYeh5YLVG45xYAgAAAlA"]
[Tue Jul 21 07:19:05.730656 2026] [security2:error] [pid 229246:tid 229378] [client 4.204.201.85:26386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-blog.php"] [unique_id "al9HmSBMYeh5YLVG45xYAwAAAhY"]
[Tue Jul 21 07:19:05.758616 2026] [security2:error] [pid 229246:tid 229497] [client 20.206.67.15:61274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ai.php"] [unique_id "al9HmSBMYeh5YLVG45xYBAAAAo0"]
[Tue Jul 21 07:19:05.914110 2026] [security2:error] [pid 229246:tid 229384] [client 20.206.67.15:61245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/fx.php"] [unique_id "al9HmSBMYeh5YLVG45xYCwAAAhw"]
[Tue Jul 21 07:19:06.095082 2026] [security2:error] [pid 229246:tid 229459] [client 20.151.10.161:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9HmiBMYeh5YLVG45xYDwAAAmc"]
[Tue Jul 21 07:19:06.110452 2026] [security2:error] [pid 229246:tid 229392] [client 20.151.10.161:55250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k5.php"] [unique_id "al9HmiBMYeh5YLVG45xYEAAAAiQ"]
[Tue Jul 21 07:19:06.162840 2026] [security2:error] [pid 229246:tid 229434] [client 20.206.67.15:61199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/xxx.php"] [unique_id "al9HmiBMYeh5YLVG45xYFQAAAk4"]
[Tue Jul 21 07:19:06.232829 2026] [security2:error] [pid 229246:tid 229395] [client 20.206.67.15:61204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/dropdown.php"] [unique_id "al9HmiBMYeh5YLVG45xYGgAAAic"]
[Tue Jul 21 07:19:06.238849 2026] [autoindex:error] [pid 229246:tid 229424] [client 66.132.172.205:26998] AH01276: Cannot serve directory /home4/ciclod61/homemsedutoronline.store/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:06.260124 2026] [security2:error] [pid 229246:tid 229418] [client 20.220.225.223:39523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/inso.php"] [unique_id "al9HmiBMYeh5YLVG45xYGwAAAj4"]
[Tue Jul 21 07:19:06.261765 2026] [security2:error] [pid 229246:tid 229478] [client 20.206.67.15:61185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/file11.php"] [unique_id "al9HmiBMYeh5YLVG45xYHAAAAno"]
[Tue Jul 21 07:19:06.343027 2026] [security2:error] [pid 229246:tid 229487] [client 20.206.67.15:61217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/png.php"] [unique_id "al9HmiBMYeh5YLVG45xYIQAAAoM"]
[Tue Jul 21 07:19:06.380741 2026] [security2:error] [pid 229246:tid 229445] [client 20.206.67.15:61257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-slss.php"] [unique_id "al9HmiBMYeh5YLVG45xYIgAAAlk"]
[Tue Jul 21 07:19:06.457159 2026] [security2:error] [pid 229246:tid 229426] [client 14.139.42.196:14272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HmiBMYeh5YLVG45xYJAAAAkY"]
[Tue Jul 21 07:19:06.457268 2026] [security2:error] [pid 229246:tid 229426] [client 14.139.42.196:14272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HmiBMYeh5YLVG45xYJAAAAkY"]
[Tue Jul 21 07:19:06.514589 2026] [security2:error] [pid 229246:tid 229393] [client 20.206.67.15:61235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ah25.php"] [unique_id "al9HmiBMYeh5YLVG45xYJQAAAiU"]
[Tue Jul 21 07:19:06.540005 2026] [security2:error] [pid 229246:tid 229329] [remote 173.252.95.25:56340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9HmiBMYeh5YLVG45xYJgACblI"]
[Tue Jul 21 07:19:06.553362 2026] [security2:error] [pid 229246:tid 229417] [client 4.204.201.85:26573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9HmiBMYeh5YLVG45xYKAAAAj0"]
[Tue Jul 21 07:19:06.560869 2026] [security2:error] [pid 229246:tid 229474] [client 20.151.10.161:50355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/gecko.php"] [unique_id "al9HmiBMYeh5YLVG45xYKQAAAnY"]
[Tue Jul 21 07:19:06.713240 2026] [security2:error] [pid 229246:tid 229396] [client 20.206.67.15:61303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ccou.php"] [unique_id "al9HmiBMYeh5YLVG45xYLAAAAig"]
[Tue Jul 21 07:19:06.762333 2026] [security2:error] [pid 229246:tid 229476] [client 20.206.67.15:59648] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/1.php"] [unique_id "al9HmiBMYeh5YLVG45xYLQAAAng"]
[Tue Jul 21 07:19:06.762439 2026] [security2:error] [pid 229246:tid 229476] [client 20.206.67.15:59648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/1.php"] [unique_id "al9HmiBMYeh5YLVG45xYLQAAAng"]
[Tue Jul 21 07:19:06.779618 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.67.15:61226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/900.php"] [unique_id "al9HmiBMYeh5YLVG45xYLgAAAms"]
[Tue Jul 21 07:19:06.795195 2026] [security2:error] [pid 229246:tid 229400] [client 20.197.192.193:9410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/we.php"] [unique_id "al9HmiBMYeh5YLVG45xYLwAAAiw"]
[Tue Jul 21 07:19:06.838995 2026] [security2:error] [pid 229246:tid 229462] [client 20.206.67.15:61246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/file59.php"] [unique_id "al9HmiBMYeh5YLVG45xYMwAAAmo"]
[Tue Jul 21 07:19:06.911141 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:35334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9HmiBMYeh5YLVG45xYNwAAAn8"]
[Tue Jul 21 07:19:06.932737 2026] [security2:error] [pid 229246:tid 229424] [client 20.206.67.15:59673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/amxloxxr.php"] [unique_id "al9HmiBMYeh5YLVG45xYOAAAAkQ"]
[Tue Jul 21 07:19:06.965029 2026] [security2:error] [pid 229246:tid 229441] [client 20.206.67.15:61279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/aboutc.php"] [unique_id "al9HmiBMYeh5YLVG45xYOQAAAlU"]
[Tue Jul 21 07:19:07.007591 2026] [security2:error] [pid 229246:tid 229418] [client 20.206.67.15:61308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/bless18.php"] [unique_id "al9HmyBMYeh5YLVG45xYOgAAAj4"]
[Tue Jul 21 07:19:07.018669 2026] [security2:error] [pid 229246:tid 229326] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/wp-admin/install.php"] [unique_id "al9HmyBMYeh5YLVG45xYOwACj08"]
[Tue Jul 21 07:19:07.047448 2026] [security2:error] [pid 229246:tid 229501] [client 4.204.201.85:26596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ms-edit.php"] [unique_id "al9HmyBMYeh5YLVG45xYPQAAApE"]
[Tue Jul 21 07:19:07.104681 2026] [security2:error] [pid 229246:tid 229446] [client 20.206.67.15:61215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/crgio.php"] [unique_id "al9HmyBMYeh5YLVG45xYQQAAAlo"]
[Tue Jul 21 07:19:07.169883 2026] [security2:error] [pid 229246:tid 229488] [client 20.151.10.161:53617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/w.php"] [unique_id "al9HmyBMYeh5YLVG45xYRgAAAoQ"]
[Tue Jul 21 07:19:07.182003 2026] [security2:error] [pid 229246:tid 229290] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9HmyBMYeh5YLVG45xYRwACcCs"]
[Tue Jul 21 07:19:07.332099 2026] [security2:error] [pid 229246:tid 229445] [client 173.252.95.25:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HmyBMYeh5YLVG45xYSwAAAlk"]
[Tue Jul 21 07:19:07.349070 2026] [security2:error] [pid 229246:tid 229426] [client 20.151.10.161:46021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/footer.php"] [unique_id "al9HmyBMYeh5YLVG45xYTgAAAkY"]
[Tue Jul 21 07:19:07.404953 2026] [security2:error] [pid 229246:tid 229461] [client 20.151.10.161:21410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/a1.php"] [unique_id "al9HmyBMYeh5YLVG45xYUQAAAmk"]
[Tue Jul 21 07:19:07.671270 2026] [security2:error] [pid 229246:tid 229400] [client 20.206.67.15:61262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-act.php"] [unique_id "al9HmyBMYeh5YLVG45xYVwAAAiw"]
[Tue Jul 21 07:19:07.706480 2026] [security2:error] [pid 229246:tid 229414] [client 20.197.192.193:27140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/kq1.php"] [unique_id "al9HmyBMYeh5YLVG45xYWAAAAjo"]
[Tue Jul 21 07:19:07.710364 2026] [security2:error] [pid 229246:tid 229404] [client 185.198.240.10:26801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mbarcondicionados.com.br"] [uri "/wp-login.php"] [unique_id "al9HmiBMYeh5YLVG45xYKwAAAjA"]
[Tue Jul 21 07:19:07.728655 2026] [security2:error] [pid 229246:tid 229345] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HmyBMYeh5YLVG45xYWQACImI"]
[Tue Jul 21 07:19:07.728807 2026] [security2:error] [pid 229246:tid 229390] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HmyBMYeh5YLVG45xYWQACImI"]
[Tue Jul 21 07:19:07.832696 2026] [security2:error] [pid 229246:tid 229440] [client 20.206.67.15:61194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/new4.php"] [unique_id "al9HmyBMYeh5YLVG45xYXQAAAlQ"]
[Tue Jul 21 07:19:07.893875 2026] [security2:error] [pid 229246:tid 229410] [client 4.204.201.85:35269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9HmyBMYeh5YLVG45xYYgAAAjY"]
[Tue Jul 21 07:19:07.913648 2026] [security2:error] [pid 229246:tid 229435] [client 173.252.95.42:51826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HmyBMYeh5YLVG45xYYwAAAk8"]
[Tue Jul 21 07:19:07.940712 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:16842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HmyBMYeh5YLVG45xYZQAAAoQ"]
[Tue Jul 21 07:19:07.996004 2026] [security2:error] [pid 229246:tid 229472] [client 4.204.201.85:26420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9HmyBMYeh5YLVG45xYbAAAAnQ"]
[Tue Jul 21 07:19:08.065092 2026] [security2:error] [pid 229246:tid 229403] [client 20.206.67.15:61309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-the.php"] [unique_id "al9HnCBMYeh5YLVG45xYbQAAAi8"]
[Tue Jul 21 07:19:08.065738 2026] [security2:error] [pid 229246:tid 229466] [client 20.151.10.161:51392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/k2.php"] [unique_id "al9HnCBMYeh5YLVG45xYbgAAAm4"]
[Tue Jul 21 07:19:08.231616 2026] [security2:error] [pid 229246:tid 229457] [client 20.206.67.15:59595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/atkno.php"] [unique_id "al9HnCBMYeh5YLVG45xYbwAAAmU"]
[Tue Jul 21 07:19:08.254489 2026] [security2:error] [pid 229246:tid 229489] [client 20.206.67.15:61203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/mass.php"] [unique_id "al9HnCBMYeh5YLVG45xYcwAAAoU"]
[Tue Jul 21 07:19:08.299617 2026] [security2:error] [pid 229246:tid 229400] [client 20.206.67.15:59589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wefile.php"] [unique_id "al9HnCBMYeh5YLVG45xYdQAAAiw"]
[Tue Jul 21 07:19:08.318914 2026] [security2:error] [pid 229246:tid 229414] [client 20.151.10.161:53597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/fpwch.php"] [unique_id "al9HnCBMYeh5YLVG45xYdgAAAjo"]
[Tue Jul 21 07:19:08.405983 2026] [security2:error] [pid 229246:tid 229447] [client 20.206.67.15:61291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/min.php"] [unique_id "al9HnCBMYeh5YLVG45xYegAAAls"]
[Tue Jul 21 07:19:08.466894 2026] [security2:error] [pid 229246:tid 229478] [client 4.204.201.85:35399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-blog.php"] [unique_id "al9HnCBMYeh5YLVG45xYfQAAAno"]
[Tue Jul 21 07:19:08.546070 2026] [security2:error] [pid 229246:tid 229479] [client 20.206.67.15:61286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/sid3.php"] [unique_id "al9HnCBMYeh5YLVG45xYgAAAAns"]
[Tue Jul 21 07:19:08.595398 2026] [security2:error] [pid 229246:tid 229347] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HnCBMYeh5YLVG45xYggACfmQ"]
[Tue Jul 21 07:19:08.595548 2026] [security2:error] [pid 229246:tid 229482] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HnCBMYeh5YLVG45xYggACfmQ"]
[Tue Jul 21 07:19:08.627829 2026] [security2:error] [pid 229246:tid 229343] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/loader.php"] [unique_id "al9HnCBMYeh5YLVG45xYgwACLWA"]
[Tue Jul 21 07:19:08.642548 2026] [security2:error] [pid 229246:tid 229350] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/spadex.php"] [unique_id "al9HnCBMYeh5YLVG45xYhAACNmc"]
[Tue Jul 21 07:19:08.643509 2026] [security2:error] [pid 229246:tid 229435] [client 4.204.201.85:26576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9HnCBMYeh5YLVG45xYhQAAAk8"]
[Tue Jul 21 07:19:08.656946 2026] [security2:error] [pid 229246:tid 229356] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/2x.php"] [unique_id "al9HnCBMYeh5YLVG45xYhwAChm0"]
[Tue Jul 21 07:19:08.671106 2026] [security2:error] [pid 229246:tid 229363] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ctex1.php"] [unique_id "al9HnCBMYeh5YLVG45xYiAACgnQ"]
[Tue Jul 21 07:19:08.686835 2026] [security2:error] [pid 229246:tid 229370] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/edorxrr.php"] [unique_id "al9HnCBMYeh5YLVG45xYiQACGns"]
[Tue Jul 21 07:19:08.687280 2026] [security2:error] [pid 229246:tid 229477] [client 20.197.192.193:16855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HnCBMYeh5YLVG45xYigAAAnk"]
[Tue Jul 21 07:19:08.701966 2026] [security2:error] [pid 229246:tid 229354] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/miru1.php"] [unique_id "al9HnCBMYeh5YLVG45xYiwACTms"]
[Tue Jul 21 07:19:08.704582 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:46076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/index.php"] [unique_id "al9HnCBMYeh5YLVG45xYjAAAAlo"]
[Tue Jul 21 07:19:08.716372 2026] [security2:error] [pid 229246:tid 229333] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/sump1.php"] [unique_id "al9HnCBMYeh5YLVG45xYjgACPFY"]
[Tue Jul 21 07:19:08.755368 2026] [security2:error] [pid 229246:tid 229367] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/file5.php"] [unique_id "al9HnCBMYeh5YLVG45xYkAACing"]
[Tue Jul 21 07:19:08.765680 2026] [security2:error] [pid 229246:tid 229445] [client 20.206.67.15:61239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/fileas.php"] [unique_id "al9HnCBMYeh5YLVG45xYkQAAAlk"]
[Tue Jul 21 07:19:08.767113 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:9425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "patihipopressivo.com.br"] [uri "/phpinfo.php1"] [unique_id "al9HnCBMYeh5YLVG45xYkgAAAn0"]
[Tue Jul 21 07:19:08.807635 2026] [security2:error] [pid 229246:tid 229373] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/0xD.php"] [unique_id "al9HnCBMYeh5YLVG45xYlAACbn4"]
[Tue Jul 21 07:19:08.825047 2026] [security2:error] [pid 229246:tid 229371] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/fnstall.php"] [unique_id "al9HnCBMYeh5YLVG45xYlgACQ3w"]
[Tue Jul 21 07:19:08.861521 2026] [security2:error] [pid 229246:tid 229365] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/acp.php"] [unique_id "al9HnCBMYeh5YLVG45xYmQACTXY"]
[Tue Jul 21 07:19:08.912028 2026] [security2:error] [pid 229246:tid 229358] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/mosty.php"] [unique_id "al9HnCBMYeh5YLVG45xYoAACeG8"]
[Tue Jul 21 07:19:08.926095 2026] [security2:error] [pid 229246:tid 229256] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/6.php"] [unique_id "al9HnCBMYeh5YLVG45xYoQACawk"]
[Tue Jul 21 07:19:08.958678 2026] [security2:error] [pid 229246:tid 229280] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9HnCBMYeh5YLVG45xYogACKyE"]
[Tue Jul 21 07:19:09.008987 2026] [security2:error] [pid 229246:tid 229453] [client 20.206.67.15:61207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/bless24.php"] [unique_id "al9HnSBMYeh5YLVG45xYpwAAAmE"]
[Tue Jul 21 07:19:09.010945 2026] [security2:error] [pid 229246:tid 229253] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/qqqa.php"] [unique_id "al9HnSBMYeh5YLVG45xYqAACZwY"]
[Tue Jul 21 07:19:09.058042 2026] [security2:error] [pid 229246:tid 229282] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/aunmc.php"] [unique_id "al9HnSBMYeh5YLVG45xYqQACeiM"]
[Tue Jul 21 07:19:09.095964 2026] [security2:error] [pid 229246:tid 229257] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/uoocf.php"] [unique_id "al9HnSBMYeh5YLVG45xYqwACJwo"]
[Tue Jul 21 07:19:09.137494 2026] [security2:error] [pid 229246:tid 229261] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/iywwi.php"] [unique_id "al9HnSBMYeh5YLVG45xYrAACjw4"]
[Tue Jul 21 07:19:09.168088 2026] [security2:error] [pid 229246:tid 229404] [client 20.206.67.15:61238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/fun.php"] [unique_id "al9HnSBMYeh5YLVG45xYrgAAAjA"]
[Tue Jul 21 07:19:09.188439 2026] [security2:error] [pid 229246:tid 229372] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/gqgsa.php"] [unique_id "al9HnSBMYeh5YLVG45xYsQACNn0"]
[Tue Jul 21 07:19:09.205030 2026] [security2:error] [pid 229246:tid 229435] [client 20.151.10.161:53602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/w2025.php"] [unique_id "al9HnSBMYeh5YLVG45xYsgAAAk8"]
[Tue Jul 21 07:19:09.229526 2026] [security2:error] [pid 229246:tid 229255] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/elbzl.php"] [unique_id "al9HnSBMYeh5YLVG45xYtAAChgg"]
[Tue Jul 21 07:19:09.251172 2026] [security2:error] [pid 229246:tid 229409] [client 136.144.33.97:36295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HnSBMYeh5YLVG45xYtgAAAjU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:09.274774 2026] [security2:error] [pid 229246:tid 229446] [client 20.206.67.15:59667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/drykl.php"] [unique_id "al9HnSBMYeh5YLVG45xYuAAAAlo"]
[Tue Jul 21 07:19:09.280268 2026] [security2:error] [pid 229246:tid 229284] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/adjig.php"] [unique_id "al9HnSBMYeh5YLVG45xYuQACPCU"]
[Tue Jul 21 07:19:09.300536 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:16872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/dp.php"] [unique_id "al9HnSBMYeh5YLVG45xYugAAAoQ"]
[Tue Jul 21 07:19:09.318416 2026] [security2:error] [pid 229246:tid 229267] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/byp.php"] [unique_id "al9HnSBMYeh5YLVG45xYuwACLhQ"]
[Tue Jul 21 07:19:09.334179 2026] [security2:error] [pid 229246:tid 229429] [client 20.151.10.161:21457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/82.php"] [unique_id "al9HnSBMYeh5YLVG45xYvAAAAkk"]
[Tue Jul 21 07:19:09.347297 2026] [security2:error] [pid 229246:tid 229288] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9HnSBMYeh5YLVG45xYvQACYCk"]
[Tue Jul 21 07:19:09.365570 2026] [security2:error] [pid 229246:tid 229445] [client 20.206.67.15:59670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al9HnSBMYeh5YLVG45xYvgAAAlk"]
[Tue Jul 21 07:19:09.391784 2026] [security2:error] [pid 229246:tid 229419] [client 20.206.67.15:61202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/mifta.php"] [unique_id "al9HnSBMYeh5YLVG45xYvwAAAj8"]
[Tue Jul 21 07:19:09.398342 2026] [security2:error] [pid 229246:tid 229368] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/classwithtostring.php"] [unique_id "al9HnSBMYeh5YLVG45xYwAACIXk"]
[Tue Jul 21 07:19:09.412706 2026] [security2:error] [pid 229246:tid 229283] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/root.php"] [unique_id "al9HnSBMYeh5YLVG45xYwQACbiQ"]
[Tue Jul 21 07:19:09.426878 2026] [security2:error] [pid 229246:tid 229286] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/sym403.php"] [unique_id "al9HnSBMYeh5YLVG45xYwgACJSc"]
[Tue Jul 21 07:19:09.441347 2026] [security2:error] [pid 229246:tid 229264] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/v543.php"] [unique_id "al9HnSBMYeh5YLVG45xYxQACIBE"]
[Tue Jul 21 07:19:09.455282 2026] [security2:error] [pid 229246:tid 229297] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/sixxis.php"] [unique_id "al9HnSBMYeh5YLVG45xYxwACSzI"]
[Tue Jul 21 07:19:09.469957 2026] [security2:error] [pid 229246:tid 229293] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ip.php"] [unique_id "al9HnSBMYeh5YLVG45xYyAACdi4"]
[Tue Jul 21 07:19:09.483884 2026] [security2:error] [pid 229246:tid 229289] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/kq1.php"] [unique_id "al9HnSBMYeh5YLVG45xYyQACeCo"]
[Tue Jul 21 07:19:09.498252 2026] [security2:error] [pid 229246:tid 229300] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9HnSBMYeh5YLVG45xYywACHzU"]
[Tue Jul 21 07:19:09.499323 2026] [security2:error] [pid 229246:tid 229406] [client 20.206.67.15:59586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/class-t.api.php"] [unique_id "al9HnSBMYeh5YLVG45xYzAAAAjI"]
[Tue Jul 21 07:19:09.511789 2026] [security2:error] [pid 229246:tid 229366] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/h02ugyh.php"] [unique_id "al9HnSBMYeh5YLVG45xYzQACHXc"]
[Tue Jul 21 07:19:09.515672 2026] [security2:error] [pid 229246:tid 229400] [client 20.206.67.15:61290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/vgtyu.php"] [unique_id "al9HnSBMYeh5YLVG45xYzgAAAiw"]
[Tue Jul 21 07:19:09.539584 2026] [security2:error] [pid 229246:tid 229497] [client 20.206.67.15:61254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/atomlib.php"] [unique_id "al9HnSBMYeh5YLVG45xYzwAAAo0"]
[Tue Jul 21 07:19:09.541524 2026] [security2:error] [pid 229246:tid 229265] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-temp.php"] [unique_id "al9HnSBMYeh5YLVG45xY0AACcxI"]
[Tue Jul 21 07:19:09.569889 2026] [security2:error] [pid 229246:tid 229266] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9HnSBMYeh5YLVG45xY0QACZxM"]
[Tue Jul 21 07:19:09.591209 2026] [security2:error] [pid 229246:tid 229428] [client 20.206.67.15:61210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-access.php"] [unique_id "al9HnSBMYeh5YLVG45xY0wAAAkg"]
[Tue Jul 21 07:19:09.613683 2026] [security2:error] [pid 229246:tid 229378] [client 139.135.44.145:53635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY1QAAAhY"]
[Tue Jul 21 07:19:09.613800 2026] [security2:error] [pid 229246:tid 229378] [client 139.135.44.145:53635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY1QAAAhY"]
[Tue Jul 21 07:19:09.617603 2026] [security2:error] [pid 229246:tid 229489] [client 45.251.232.145:58539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY1gAAAoU"]
[Tue Jul 21 07:19:09.617705 2026] [security2:error] [pid 229246:tid 229489] [client 45.251.232.145:58539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY1gAAAoU"]
[Tue Jul 21 07:19:09.637476 2026] [security2:error] [pid 229246:tid 229440] [client 20.206.67.15:61221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-update.php"] [unique_id "al9HnSBMYeh5YLVG45xY1wAAAlQ"]
[Tue Jul 21 07:19:09.667180 2026] [security2:error] [pid 229246:tid 229478] [client 20.206.67.15:61241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/erty.php"] [unique_id "al9HnSBMYeh5YLVG45xY2QAAAno"]
[Tue Jul 21 07:19:09.670282 2026] [security2:error] [pid 229246:tid 229392] [client 68.235.38.2:34998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY2gAAAiQ"]
[Tue Jul 21 07:19:09.670380 2026] [security2:error] [pid 229246:tid 229392] [client 68.235.38.2:34998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY2gAAAiQ"]
[Tue Jul 21 07:19:09.677717 2026] [security2:error] [pid 229246:tid 229395] [client 20.226.60.151:54532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/2x.php"] [unique_id "al9HnSBMYeh5YLVG45xY2wAAAic"]
[Tue Jul 21 07:19:09.706072 2026] [security2:error] [pid 229246:tid 229499] [client 20.206.67.15:61255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al9HnSBMYeh5YLVG45xY3gAAAo8"]
[Tue Jul 21 07:19:09.732063 2026] [security2:error] [pid 229246:tid 229435] [client 20.206.67.15:61289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/like.php"] [unique_id "al9HnSBMYeh5YLVG45xY3wAAAk8"]
[Tue Jul 21 07:19:09.789778 2026] [security2:error] [pid 229246:tid 229409] [client 4.204.201.85:26610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/abcd.php"] [unique_id "al9HnSBMYeh5YLVG45xY4QAAAjU"]
[Tue Jul 21 07:19:09.797661 2026] [security2:error] [pid 229246:tid 229475] [client 20.206.67.15:61296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/bless5.php"] [unique_id "al9HnSBMYeh5YLVG45xY4gAAAnc"]
[Tue Jul 21 07:19:09.804040 2026] [security2:error] [pid 229246:tid 229434] [client 20.197.192.193:16833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/old.php"] [unique_id "al9HnSBMYeh5YLVG45xY5AAAAk4"]
[Tue Jul 21 07:19:09.812649 2026] [autoindex:error] [pid 229246:tid 229469] [client 4.204.201.85:35400] AH01276: Cannot serve directory /home3/seaport/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:09.864537 2026] [security2:error] [pid 229246:tid 229488] [client 20.151.10.161:46022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/zoro.php"] [unique_id "al9HnSBMYeh5YLVG45xY5QAAAoQ"]
[Tue Jul 21 07:19:09.923673 2026] [security2:error] [pid 229246:tid 229451] [client 74.244.195.153:33829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY5wAAAl8"]
[Tue Jul 21 07:19:09.927234 2026] [security2:error] [pid 229246:tid 229451] [client 74.244.195.153:33829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HnSBMYeh5YLVG45xY5wAAAl8"]
[Tue Jul 21 07:19:09.964633 2026] [security2:error] [pid 229246:tid 229481] [client 20.151.10.161:55239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/scxy.php"] [unique_id "al9HnSBMYeh5YLVG45xY6QAAAn0"]
[Tue Jul 21 07:19:10.021071 2026] [security2:error] [pid 229246:tid 229417] [client 20.197.192.193:11145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/ms-new.php"] [unique_id "al9HniBMYeh5YLVG45xY8AAAAj0"]
[Tue Jul 21 07:19:10.110515 2026] [security2:error] [pid 229246:tid 229406] [client 4.204.201.85:35272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9HniBMYeh5YLVG45xY8wAAAjI"]
[Tue Jul 21 07:19:10.132374 2026] [security2:error] [pid 229246:tid 229311] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HniBMYeh5YLVG45xY9AACPkA"]
[Tue Jul 21 07:19:10.132492 2026] [security2:error] [pid 229246:tid 229418] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HniBMYeh5YLVG45xY9AACPkA"]
[Tue Jul 21 07:19:10.142617 2026] [security2:error] [pid 229246:tid 229314] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HniBMYeh5YLVG45xY9QACGEM"]
[Tue Jul 21 07:19:10.142715 2026] [security2:error] [pid 229246:tid 229380] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HniBMYeh5YLVG45xY9QACGEM"]
[Tue Jul 21 07:19:10.173340 2026] [security2:error] [pid 229246:tid 229400] [client 20.206.67.15:59631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/t.php"] [unique_id "al9HniBMYeh5YLVG45xY-QAAAiw"]
[Tue Jul 21 07:19:10.214777 2026] [security2:error] [pid 229246:tid 229428] [client 20.197.192.193:11238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/track.php"] [unique_id "al9HniBMYeh5YLVG45xY_AAAAkg"]
[Tue Jul 21 07:19:10.256025 2026] [security2:error] [pid 229246:tid 229447] [client 4.204.201.85:26014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/file15.php"] [unique_id "al9HniBMYeh5YLVG45xY_gAAAls"]
[Tue Jul 21 07:19:10.350377 2026] [security2:error] [pid 229246:tid 229491] [client 173.252.95.59:48284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HnSBMYeh5YLVG45xYsAAAAoc"]
[Tue Jul 21 07:19:10.394750 2026] [security2:error] [pid 229246:tid 229501] [client 20.206.67.15:61198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/xoot.php"] [unique_id "al9HniBMYeh5YLVG45xZAQAAApE"]
[Tue Jul 21 07:19:10.396379 2026] [security2:error] [pid 229246:tid 229404] [client 20.151.10.161:21490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/config.json.php"] [unique_id "al9HniBMYeh5YLVG45xZAgAAAjA"]
[Tue Jul 21 07:19:10.496976 2026] [security2:error] [pid 229246:tid 229467] [client 20.151.10.161:53587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/FWAZ.php"] [unique_id "al9HniBMYeh5YLVG45xZBAAAAm8"]
[Tue Jul 21 07:19:10.498162 2026] [security2:error] [pid 229246:tid 229484] [client 4.204.201.85:35352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/ms-edit.php"] [unique_id "al9HniBMYeh5YLVG45xZBQAAAoA"]
[Tue Jul 21 07:19:10.578328 2026] [security2:error] [pid 229246:tid 229402] [client 20.206.67.15:61237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/xqq.php"] [unique_id "al9HniBMYeh5YLVG45xZCgAAAi4"]
[Tue Jul 21 07:19:10.620158 2026] [security2:error] [pid 229246:tid 229393] [client 20.220.225.223:40857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/wpx.php"] [unique_id "al9HniBMYeh5YLVG45xZCwAAAiU"]
[Tue Jul 21 07:19:10.623799 2026] [security2:error] [pid 229246:tid 229472] [client 20.206.67.15:61201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-load.php"] [unique_id "al9HniBMYeh5YLVG45xZDAAAAnQ"]
[Tue Jul 21 07:19:10.667075 2026] [security2:error] [pid 229246:tid 229423] [client 20.206.67.15:59688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/x.php"] [unique_id "al9HniBMYeh5YLVG45xZDQAAAkM"]
[Tue Jul 21 07:19:10.694474 2026] [security2:error] [pid 229246:tid 229431] [client 20.151.10.161:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/admin.php"] [unique_id "al9HniBMYeh5YLVG45xZDgAAAks"]
[Tue Jul 21 07:19:10.706676 2026] [security2:error] [pid 229246:tid 229396] [client 20.206.67.15:61236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/i.php"] [unique_id "al9HniBMYeh5YLVG45xZDwAAAig"]
[Tue Jul 21 07:19:10.765453 2026] [security2:error] [pid 229246:tid 229418] [client 20.206.67.15:61195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ms-edit.php"] [unique_id "al9HniBMYeh5YLVG45xZEQAAAj4"]
[Tue Jul 21 07:19:10.808354 2026] [security2:error] [pid 229246:tid 229476] [client 20.151.10.161:55294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/qterm.php"] [unique_id "al9HniBMYeh5YLVG45xZEgAAAng"]
[Tue Jul 21 07:19:10.820338 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.67.15:61281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/v2.php"] [unique_id "al9HniBMYeh5YLVG45xZEwAAAms"]
[Tue Jul 21 07:19:10.854800 2026] [security2:error] [pid 229246:tid 229399] [client 20.206.67.15:61285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/new.php"] [unique_id "al9HniBMYeh5YLVG45xZFQAAAis"]
[Tue Jul 21 07:19:10.915905 2026] [security2:error] [pid 229246:tid 229424] [client 20.206.67.15:59692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-admin/network/edit.php"] [unique_id "al9HniBMYeh5YLVG45xZFwAAAkQ"]
[Tue Jul 21 07:19:10.932502 2026] [security2:error] [pid 229246:tid 229482] [client 4.204.201.85:35445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9HniBMYeh5YLVG45xZGAAAAn4"]
[Tue Jul 21 07:19:10.935470 2026] [security2:error] [pid 229246:tid 229445] [client 20.206.67.15:59592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/pouhg.php"] [unique_id "al9HniBMYeh5YLVG45xZGQAAAlk"]
[Tue Jul 21 07:19:10.950533 2026] [security2:error] [pid 229246:tid 229489] [client 20.206.67.15:61197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/cilus.php"] [unique_id "al9HniBMYeh5YLVG45xZGgAAAoU"]
[Tue Jul 21 07:19:10.974404 2026] [security2:error] [pid 229246:tid 229478] [client 20.206.67.15:61232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/file4.php"] [unique_id "al9HniBMYeh5YLVG45xZHAAAAno"]
[Tue Jul 21 07:19:11.011473 2026] [security2:error] [pid 229246:tid 229435] [client 20.206.67.15:61191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/samll.php"] [unique_id "al9HnyBMYeh5YLVG45xZJAAAAk8"]
[Tue Jul 21 07:19:11.027374 2026] [security2:error] [pid 229246:tid 229475] [client 20.206.67.15:61280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/Okxob.php"] [unique_id "al9HnyBMYeh5YLVG45xZJwAAAnc"]
[Tue Jul 21 07:19:11.038745 2026] [security2:error] [pid 229246:tid 229409] [client 4.204.201.85:26563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/jp.php"] [unique_id "al9HnyBMYeh5YLVG45xZKAAAAjU"]
[Tue Jul 21 07:19:11.066758 2026] [security2:error] [pid 229246:tid 229382] [client 20.206.67.15:61213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ok.php"] [unique_id "al9HnyBMYeh5YLVG45xZLAAAAho"]
[Tue Jul 21 07:19:11.191458 2026] [security2:error] [pid 229246:tid 229418] [client 20.151.10.161:53592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/blurbs.php"] [unique_id "al9HnyBMYeh5YLVG45xZNAAAAj4"]
[Tue Jul 21 07:19:11.194700 2026] [security2:error] [pid 229246:tid 229380] [client 20.206.67.15:61276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wuasr.php"] [unique_id "al9HnyBMYeh5YLVG45xZNQAAAhg"]
[Tue Jul 21 07:19:11.218122 2026] [security2:error] [pid 229246:tid 229477] [client 20.206.67.15:61188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/bless11.php"] [unique_id "al9HnyBMYeh5YLVG45xZNgAAAnk"]
[Tue Jul 21 07:19:11.223290 2026] [security2:error] [pid 229246:tid 229385] [client 20.151.10.161:46037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/greap.php"] [unique_id "al9HnyBMYeh5YLVG45xZNwAAAh0"]
[Tue Jul 21 07:19:11.237047 2026] [security2:error] [pid 229246:tid 229466] [client 20.206.67.15:61227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-block.php"] [unique_id "al9HnyBMYeh5YLVG45xZOAAAAm4"]
[Tue Jul 21 07:19:11.281668 2026] [security2:error] [pid 229246:tid 229482] [client 20.206.67.15:61250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/aevly.php"] [unique_id "al9HnyBMYeh5YLVG45xZOwAAAn4"]
[Tue Jul 21 07:19:11.324530 2026] [security2:error] [pid 229246:tid 229489] [client 20.206.67.15:59601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/hello.php"] [unique_id "al9HnyBMYeh5YLVG45xZPwAAAoU"]
[Tue Jul 21 07:19:11.360834 2026] [security2:error] [pid 229246:tid 229392] [client 20.206.67.15:59605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-links-opml.php"] [unique_id "al9HnyBMYeh5YLVG45xZQgAAAiQ"]
[Tue Jul 21 07:19:11.404765 2026] [security2:error] [pid 229246:tid 229426] [client 20.206.67.15:61212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/forbidals.php"] [unique_id "al9HnyBMYeh5YLVG45xZQwAAAkY"]
[Tue Jul 21 07:19:11.413555 2026] [security2:error] [pid 229246:tid 229491] [client 20.151.10.161:51415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paulaabrao.com.br"] [uri "/fpwch.php"] [unique_id "al9HnyBMYeh5YLVG45xZRAAAAoc"]
[Tue Jul 21 07:19:11.495011 2026] [security2:error] [pid 229246:tid 229403] [client 20.206.67.15:59674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/file30.php"] [unique_id "al9HnyBMYeh5YLVG45xZRQAAAi8"]
[Tue Jul 21 07:19:11.542749 2026] [security2:error] [pid 229246:tid 229467] [client 20.151.10.161:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/v543.php"] [unique_id "al9HnyBMYeh5YLVG45xZRwAAAm8"]
[Tue Jul 21 07:19:11.578485 2026] [security2:error] [pid 229246:tid 229484] [client 20.206.67.15:61284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/xda.php"] [unique_id "al9HnyBMYeh5YLVG45xZSgAAAoA"]
[Tue Jul 21 07:19:11.633274 2026] [security2:error] [pid 229246:tid 229416] [client 20.206.67.15:61244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/z.php"] [unique_id "al9HnyBMYeh5YLVG45xZTAAAAjw"]
[Tue Jul 21 07:19:11.669377 2026] [security2:error] [pid 229246:tid 229402] [client 20.206.67.15:59695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/b.php"] [unique_id "al9HnyBMYeh5YLVG45xZTQAAAi4"]
[Tue Jul 21 07:19:11.671006 2026] [security2:error] [pid 229246:tid 229429] [client 4.204.201.85:26371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/f35.php"] [unique_id "al9HnyBMYeh5YLVG45xZTgAAAkk"]
[Tue Jul 21 07:19:11.700801 2026] [security2:error] [pid 229246:tid 229393] [client 20.151.10.161:45953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/177.php"] [unique_id "al9HnyBMYeh5YLVG45xZTwAAAiU"]
[Tue Jul 21 07:19:11.705102 2026] [security2:error] [pid 229246:tid 229486] [client 20.206.67.15:61277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/edit.php"] [unique_id "al9HnyBMYeh5YLVG45xZUAAAAoI"]
[Tue Jul 21 07:19:11.718266 2026] [security2:error] [pid 229246:tid 229304] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9HnyBMYeh5YLVG45xZUQACcjk"]
[Tue Jul 21 07:19:11.721885 2026] [security2:error] [pid 229246:tid 229462] [client 20.206.67.15:59671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/app.php"] [unique_id "al9HnyBMYeh5YLVG45xZUgAAAmo"]
[Tue Jul 21 07:19:11.725983 2026] [security2:error] [pid 229246:tid 229446] [client 175.45.70.82:62887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HnyBMYeh5YLVG45xZUwAAAlo"]
[Tue Jul 21 07:19:11.726063 2026] [security2:error] [pid 229246:tid 229446] [client 175.45.70.82:62887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HnyBMYeh5YLVG45xZUwAAAlo"]
[Tue Jul 21 07:19:11.732068 2026] [security2:error] [pid 229246:tid 229290] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/jj.php"] [unique_id "al9HnyBMYeh5YLVG45xZVAACFSs"]
[Tue Jul 21 07:19:11.758239 2026] [security2:error] [pid 229246:tid 229423] [client 20.206.67.15:59685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-png.php"] [unique_id "al9HnyBMYeh5YLVG45xZVQAAAkM"]
[Tue Jul 21 07:19:11.783510 2026] [security2:error] [pid 229246:tid 229337] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9HnyBMYeh5YLVG45xZVgACbFo"]
[Tue Jul 21 07:19:11.790870 2026] [security2:error] [pid 229246:tid 229479] [client 20.206.67.15:59660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/lib.php"] [unique_id "al9HnyBMYeh5YLVG45xZVwAAAns"]
[Tue Jul 21 07:19:11.816006 2026] [security2:error] [pid 229246:tid 229330] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/txets.php"] [unique_id "al9HnyBMYeh5YLVG45xZWgACPlM"]
[Tue Jul 21 07:19:11.825015 2026] [security2:error] [pid 229246:tid 229476] [client 20.151.10.161:53588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/w3lls.php"] [unique_id "al9HnyBMYeh5YLVG45xZWwAAAng"]
[Tue Jul 21 07:19:11.834562 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.67.15:59686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/sys.php"] [unique_id "al9HnyBMYeh5YLVG45xZXAAAAms"]
[Tue Jul 21 07:19:11.847492 2026] [security2:error] [pid 229246:tid 229345] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/dex.php"] [unique_id "al9HnyBMYeh5YLVG45xZXgACc2I"]
[Tue Jul 21 07:19:11.859107 2026] [security2:error] [pid 229246:tid 229414] [client 20.206.67.15:59653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/la.php"] [unique_id "al9HnyBMYeh5YLVG45xZXwAAAjo"]
[Tue Jul 21 07:19:11.871592 2026] [security2:error] [pid 229246:tid 229339] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/xpwer1.php"] [unique_id "al9HnyBMYeh5YLVG45xZYQACblw"]
[Tue Jul 21 07:19:11.883965 2026] [security2:error] [pid 229246:tid 229459] [client 20.206.67.15:61297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/tires.php"] [unique_id "al9HnyBMYeh5YLVG45xZYwAAAmc"]
[Tue Jul 21 07:19:11.885835 2026] [security2:error] [pid 229246:tid 229331] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/flox.php"] [unique_id "al9HnyBMYeh5YLVG45xZZAACYVQ"]
[Tue Jul 21 07:19:11.908709 2026] [security2:error] [pid 229246:tid 229445] [client 20.206.67.15:59608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/lv.php"] [unique_id "al9HnyBMYeh5YLVG45xZZQAAAlk"]
[Tue Jul 21 07:19:11.915523 2026] [security2:error] [pid 229246:tid 229328] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/popo.php"] [unique_id "al9HnyBMYeh5YLVG45xZZgAChVE"]
[Tue Jul 21 07:19:11.929958 2026] [security2:error] [pid 229246:tid 229478] [client 20.206.67.15:61233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/myfile.php"] [unique_id "al9HnyBMYeh5YLVG45xZaAAAAno"]
[Tue Jul 21 07:19:11.954046 2026] [security2:error] [pid 229246:tid 229335] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/yas.php"] [unique_id "al9HnyBMYeh5YLVG45xZawACJ1g"]
[Tue Jul 21 07:19:11.960468 2026] [security2:error] [pid 229246:tid 229488] [client 20.206.67.15:59662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/06.php"] [unique_id "al9HnyBMYeh5YLVG45xZbQAAAoQ"]
[Tue Jul 21 07:19:11.968009 2026] [security2:error] [pid 229246:tid 229332] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/file61.php"] [unique_id "al9HnyBMYeh5YLVG45xZbgACh1U"]
[Tue Jul 21 07:19:11.981798 2026] [security2:error] [pid 229246:tid 229338] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/water.php"] [unique_id "al9HnyBMYeh5YLVG45xZcQACL1s"]
[Tue Jul 21 07:19:11.987357 2026] [security2:error] [pid 229246:tid 229468] [client 20.206.67.15:59658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/fs.php"] [unique_id "al9HnyBMYeh5YLVG45xZcgAAAnA"]
[Tue Jul 21 07:19:11.995601 2026] [security2:error] [pid 229246:tid 229352] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/nano.php"] [unique_id "al9HnyBMYeh5YLVG45xZcwACb2k"]
[Tue Jul 21 07:19:12.009585 2026] [security2:error] [pid 229246:tid 229347] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/moon.php"] [unique_id "al9HoCBMYeh5YLVG45xZdAAChmQ"]
[Tue Jul 21 07:19:12.010181 2026] [security2:error] [pid 229246:tid 229484] [client 20.206.67.15:59584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/asasx.php"] [unique_id "al9HoCBMYeh5YLVG45xZdQAAAoA"]
[Tue Jul 21 07:19:12.037607 2026] [security2:error] [pid 229246:tid 229435] [client 20.206.67.15:61222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-kd4xalrg7m.php"] [unique_id "al9HoCBMYeh5YLVG45xZewAAAk8"]
[Tue Jul 21 07:19:12.051284 2026] [security2:error] [pid 229246:tid 229416] [client 20.197.192.193:11163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/2352356666.php"] [unique_id "al9HoCBMYeh5YLVG45xZfAAAAjw"]
[Tue Jul 21 07:19:12.065377 2026] [security2:error] [pid 229246:tid 229429] [client 20.206.67.15:59707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-good.php"] [unique_id "al9HoCBMYeh5YLVG45xZfQAAAkk"]
[Tue Jul 21 07:19:12.076918 2026] [security2:error] [pid 229246:tid 229486] [client 20.206.67.15:61295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/scxy.php"] [unique_id "al9HoCBMYeh5YLVG45xZfwAAAoI"]
[Tue Jul 21 07:19:12.085774 2026] [autoindex:error] [pid 229246:tid 229481] [client 4.204.201.85:35400] AH01276: Cannot serve directory /home3/seaport/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:12.119424 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:53624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-ws68.php"] [unique_id "al9HoCBMYeh5YLVG45xZgQAAAlo"]
[Tue Jul 21 07:19:12.121041 2026] [security2:error] [pid 229246:tid 229377] [client 20.206.67.15:59640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wmore1.php"] [unique_id "al9HoCBMYeh5YLVG45xZggAAAhU"]
[Tue Jul 21 07:19:12.158728 2026] [security2:error] [pid 229246:tid 229396] [client 20.206.67.15:61306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/like.php"] [unique_id "al9HoCBMYeh5YLVG45xZhgAAAig"]
[Tue Jul 21 07:19:12.196648 2026] [security2:error] [pid 229246:tid 229471] [client 20.206.67.15:59617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/x.php"] [unique_id "al9HoCBMYeh5YLVG45xZiAAAAnM"]
[Tue Jul 21 07:19:12.229500 2026] [security2:error] [pid 229246:tid 229466] [client 4.204.201.85:35409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9HoCBMYeh5YLVG45xZigAAAm4"]
[Tue Jul 21 07:19:12.350300 2026] [security2:error] [pid 229246:tid 229445] [client 20.206.67.15:61224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/xa.php"] [unique_id "al9HoCBMYeh5YLVG45xZjAAAAlk"]
[Tue Jul 21 07:19:12.455874 2026] [security2:error] [pid 229246:tid 229488] [client 20.151.10.161:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/199.php"] [unique_id "al9HoCBMYeh5YLVG45xZkAAAAoQ"]
[Tue Jul 21 07:19:12.466285 2026] [security2:error] [pid 229246:tid 229491] [client 4.204.201.85:26423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-load.php"] [unique_id "al9HoCBMYeh5YLVG45xZkgAAAoc"]
[Tue Jul 21 07:19:12.510629 2026] [security2:error] [pid 229246:tid 229403] [client 20.206.67.15:61261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/kolda.php"] [unique_id "al9HoCBMYeh5YLVG45xZkwAAAi8"]
[Tue Jul 21 07:19:12.527657 2026] [security2:error] [pid 229246:tid 229467] [client 20.151.10.161:53574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xyn.php"] [unique_id "al9HoCBMYeh5YLVG45xZlgAAAm8"]
[Tue Jul 21 07:19:12.532218 2026] [security2:error] [pid 229246:tid 229457] [client 103.187.68.227:62017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.68.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.vivaconcierge.com.br"] [uri "/wp-login.php"] [unique_id "al9HoCBMYeh5YLVG45xZlAAAAmU"], referer: https://www.google.com/
[Tue Jul 21 07:19:12.650767 2026] [security2:error] [pid 229246:tid 229409] [client 20.206.67.15:59703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-aothait.php"] [unique_id "al9HoCBMYeh5YLVG45xZmwAAAjU"]
[Tue Jul 21 07:19:12.652519 2026] [security2:error] [pid 229246:tid 229371] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HoCBMYeh5YLVG45xZnAACLnw"]
[Tue Jul 21 07:19:12.652673 2026] [security2:error] [pid 229246:tid 229402] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HoCBMYeh5YLVG45xZnAACLnw"]
[Tue Jul 21 07:19:12.723966 2026] [security2:error] [pid 229246:tid 229481] [client 20.206.67.15:61292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ftde.php"] [unique_id "al9HoCBMYeh5YLVG45xZnwAAAn0"]
[Tue Jul 21 07:19:12.773161 2026] [autoindex:error] [pid 229246:tid 229423] [client 4.204.201.85:35400] AH01276: Cannot serve directory /home3/seaport/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:12.776121 2026] [security2:error] [pid 229246:tid 229454] [client 20.197.192.193:11194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/pn.php"] [unique_id "al9HoCBMYeh5YLVG45xZoQAAAmI"]
[Tue Jul 21 07:19:12.798293 2026] [security2:error] [pid 229246:tid 229365] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HoCBMYeh5YLVG45xZowACinY"]
[Tue Jul 21 07:19:12.798449 2026] [security2:error] [pid 229246:tid 229494] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HoCBMYeh5YLVG45xZowACinY"]
[Tue Jul 21 07:19:12.802168 2026] [security2:error] [pid 229246:tid 229433] [client 120.61.173.56:51104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HoCBMYeh5YLVG45xZpAAAAk0"]
[Tue Jul 21 07:19:12.802244 2026] [security2:error] [pid 229246:tid 229433] [client 120.61.173.56:51104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HoCBMYeh5YLVG45xZpAAAAk0"]
[Tue Jul 21 07:19:12.937187 2026] [security2:error] [pid 229246:tid 229250] [remote 8.217.108.67:48962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "revistareflexopolitico.com.br"] [uri "/wp-login.php"] [unique_id "al9HoCBMYeh5YLVG45xZqAACegM"]
[Tue Jul 21 07:19:12.988179 2026] [security2:error] [pid 229246:tid 229459] [client 20.151.10.161:53591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/green3.php"] [unique_id "al9HoCBMYeh5YLVG45xZqQAAAmc"]
[Tue Jul 21 07:19:13.044601 2026] [security2:error] [pid 229246:tid 229424] [client 20.206.67.15:59657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/vx.php"] [unique_id "al9HoSBMYeh5YLVG45xZrAAAAkQ"]
[Tue Jul 21 07:19:13.077342 2026] [autoindex:error] [pid 229246:tid 229497] [client 4.204.201.85:35400] AH01276: Cannot serve directory /home3/seaport/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:13.094181 2026] [security2:error] [pid 229246:tid 229448] [client 20.197.192.193:11215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9HoSBMYeh5YLVG45xZsQAAAlw"]
[Tue Jul 21 07:19:13.141644 2026] [security2:error] [pid 229246:tid 229251] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-info.php"] [unique_id "al9HoSBMYeh5YLVG45xZsgACLwQ"]
[Tue Jul 21 07:19:13.156261 2026] [security2:error] [pid 229246:tid 229253] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/2000.php"] [unique_id "al9HoSBMYeh5YLVG45xZtQACZQY"]
[Tue Jul 21 07:19:13.178411 2026] [security2:error] [pid 229246:tid 229501] [client 20.206.67.15:59628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/a5.php"] [unique_id "al9HoSBMYeh5YLVG45xZtwAAApE"]
[Tue Jul 21 07:19:13.193061 2026] [security2:error] [pid 229246:tid 229257] [remote 185.115.217.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.217.115.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "annaguimaraes.com.br"] [uri "/wp-login.php"] [unique_id "al9HoSBMYeh5YLVG45xZuQACYQo"]
[Tue Jul 21 07:19:13.207692 2026] [security2:error] [pid 229246:tid 229261] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/122.php"] [unique_id "al9HoSBMYeh5YLVG45xZugACIg4"]
[Tue Jul 21 07:19:13.230748 2026] [security2:error] [pid 229246:tid 229486] [client 4.204.201.85:35296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/abcd.php"] [unique_id "al9HoSBMYeh5YLVG45xZvQAAAoI"]
[Tue Jul 21 07:19:13.241468 2026] [security2:error] [pid 229246:tid 229255] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/mds.php"] [unique_id "al9HoSBMYeh5YLVG45xZvwACdAg"]
[Tue Jul 21 07:19:13.256681 2026] [security2:error] [pid 229246:tid 229435] [client 20.206.67.15:59661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-sing.php"] [unique_id "al9HoSBMYeh5YLVG45xZwAAAAk8"]
[Tue Jul 21 07:19:13.258172 2026] [security2:error] [pid 229246:tid 229470] [client 4.204.201.85:26397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/xyn.php"] [unique_id "al9HoSBMYeh5YLVG45xZwQAAAnI"]
[Tue Jul 21 07:19:13.270683 2026] [security2:error] [pid 229246:tid 229284] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-blink.php"] [unique_id "al9HoSBMYeh5YLVG45xZwgACWiU"]
[Tue Jul 21 07:19:13.290988 2026] [http2:info] [pid 230252:tid 230252] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 07:19:13.311344 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file52.php"] [unique_id "al9HoSBMYeh5YLVG45xZxgAAAns"]
[Tue Jul 21 07:19:13.342114 2026] [security2:error] [pid 229246:tid 229490] [client 20.197.192.193:16874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/dr.php"] [unique_id "al9HoSBMYeh5YLVG45xZxwAAAoY"]
[Tue Jul 21 07:19:13.446431 2026] [security2:error] [pid 229246:tid 229397] [client 20.151.10.161:53601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ccs.php"] [unique_id "al9HoSBMYeh5YLVG45xZzQAAAik"]
[Tue Jul 21 07:19:13.461681 2026] [security2:error] [pid 230252:tid 230386] [client 20.206.67.15:59696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/database.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1GgAAAps"]
[Tue Jul 21 07:19:13.469753 2026] [security2:error] [pid 229246:tid 229483] [client 193.36.225.58:33553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HoSBMYeh5YLVG45xZxQAAAn8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:13.555289 2026] [security2:error] [pid 229246:tid 229418] [client 209.141.34.121:53052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "odontoclinicms.com.br"] [uri "/"] [unique_id "al9HoSBMYeh5YLVG45xZzgAAAj4"]
[Tue Jul 21 07:19:13.563158 2026] [security2:error] [pid 230252:tid 230389] [client 4.204.201.85:35358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/file15.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1HAAAAp4"]
[Tue Jul 21 07:19:13.572625 2026] [security2:error] [pid 229246:tid 229388] [client 20.206.67.15:61214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/explorer/index_.php"] [unique_id "al9HoSBMYeh5YLVG45xZ0AAAAiA"]
[Tue Jul 21 07:19:13.628259 2026] [security2:error] [pid 230252:tid 230390] [client 20.206.67.15:61311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-at.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1HQAAAp8"]
[Tue Jul 21 07:19:13.659603 2026] [security2:error] [pid 230252:tid 230392] [client 20.206.67.15:61229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-wz.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1HgAAAqE"]
[Tue Jul 21 07:19:13.726370 2026] [security2:error] [pid 229246:tid 229448] [client 20.206.67.15:59655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-ver.php"] [unique_id "al9HoSBMYeh5YLVG45xZ0wAAAlw"]
[Tue Jul 21 07:19:13.742884 2026] [security2:error] [pid 230252:tid 230397] [client 20.197.192.193:11146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/2x.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1IAAAAqY"]
[Tue Jul 21 07:19:13.751647 2026] [security2:error] [pid 229246:tid 229457] [client 20.206.67.15:61230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp5.php"] [unique_id "al9HoSBMYeh5YLVG45xZ1gAAAmU"]
[Tue Jul 21 07:19:13.757123 2026] [security2:error] [pid 230252:tid 230384] [client 103.187.68.225:65518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.68.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.vivaconcierge.com.br"] [uri "/wp-login.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1IgAAApk"], referer: https://www.vivaconcierge.com.br/wp-admin/
[Tue Jul 21 07:19:13.794196 2026] [security2:error] [pid 229246:tid 229468] [client 20.206.67.15:61218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-pp.php"] [unique_id "al9HoSBMYeh5YLVG45xZ2AAAAnA"]
[Tue Jul 21 07:19:13.797603 2026] [security2:error] [pid 230252:tid 230400] [client 20.197.192.193:11148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/kq1.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1IwAAAqk"]
[Tue Jul 21 07:19:13.823120 2026] [security2:error] [pid 229246:tid 229429] [client 20.197.192.193:11199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/zzz.php"] [unique_id "al9HoSBMYeh5YLVG45xZ2QAAAkk"]
[Tue Jul 21 07:19:13.837047 2026] [security2:error] [pid 229246:tid 229390] [client 20.206.67.15:59678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/w3lls.php"] [unique_id "al9HoSBMYeh5YLVG45xZ2gAAAiI"]
[Tue Jul 21 07:19:13.842028 2026] [security2:error] [pid 230252:tid 230402] [client 20.151.10.161:55252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ccc.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1JAAAAqs"]
[Tue Jul 21 07:19:13.902819 2026] [security2:error] [pid 229246:tid 229479] [client 20.206.67.15:61293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/sbhu.php"] [unique_id "al9HoSBMYeh5YLVG45xZ3QAAAns"]
[Tue Jul 21 07:19:13.909535 2026] [security2:error] [pid 229246:tid 229490] [client 20.197.192.193:16860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wicked.php"] [unique_id "al9HoSBMYeh5YLVG45xZ3gAAAoY"]
[Tue Jul 21 07:19:13.926473 2026] [security2:error] [pid 229246:tid 229476] [client 20.206.67.15:59694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-content/uploads/admin.php"] [unique_id "al9HoSBMYeh5YLVG45xZ3wAAAng"]
[Tue Jul 21 07:19:13.947259 2026] [security2:error] [pid 230252:tid 230404] [client 4.204.201.85:35332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/jp.php"] [unique_id "al9HoU0Dwhk5-Z44Xro1JQAAAq0"]
[Tue Jul 21 07:19:13.971754 2026] [security2:error] [pid 229246:tid 229496] [client 20.197.192.193:11152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/edit.php"] [unique_id "al9HoSBMYeh5YLVG45xZ4AAAAow"]
[Tue Jul 21 07:19:14.043458 2026] [security2:error] [pid 229246:tid 229475] [client 20.206.67.15:61299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/favicon.php"] [unique_id "al9HoiBMYeh5YLVG45xZ4wAAAnc"]
[Tue Jul 21 07:19:14.077764 2026] [security2:error] [pid 230252:tid 230403] [client 209.141.34.121:53117] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "odontoclinicms.com.br"] [uri "/"] [unique_id "al9Hok0Dwhk5-Z44Xro1KgAAAqw"]
[Tue Jul 21 07:19:14.121806 2026] [autoindex:error] [pid 229246:tid 229366] [remote 104.253.36.208:52277] AH01276: Cannot serve directory /home2/ric83751/sanovitta.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:14.139615 2026] [security2:error] [pid 229246:tid 229451] [client 20.151.10.161:53573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/get.php"] [unique_id "al9HoiBMYeh5YLVG45xZ5gAAAl8"]
[Tue Jul 21 07:19:14.179856 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:46025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/122.php"] [unique_id "al9HoiBMYeh5YLVG45xZ6AAAAnk"]
[Tue Jul 21 07:19:14.213792 2026] [security2:error] [pid 229246:tid 229385] [client 20.206.67.15:59585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/txets.php"] [unique_id "al9HoiBMYeh5YLVG45xZ6QAAAh0"]
[Tue Jul 21 07:19:14.236537 2026] [security2:error] [pid 229246:tid 229459] [client 20.197.192.193:16878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/kua.php"] [unique_id "al9HoiBMYeh5YLVG45xZ6wAAAmc"]
[Tue Jul 21 07:19:14.275226 2026] [security2:error] [pid 229246:tid 229266] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HoiBMYeh5YLVG45xZ7gACOhM"]
[Tue Jul 21 07:19:14.275377 2026] [security2:error] [pid 229246:tid 229414] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HoiBMYeh5YLVG45xZ7gACOhM"]
[Tue Jul 21 07:19:14.304044 2026] [security2:error] [pid 229246:tid 229448] [client 20.206.67.15:61267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-su.php"] [unique_id "al9HoiBMYeh5YLVG45xZ7wAAAlw"]
[Tue Jul 21 07:19:14.376329 2026] [security2:error] [pid 229246:tid 229404] [client 20.206.67.15:61278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ff.php"] [unique_id "al9HoiBMYeh5YLVG45xZ8AAAAjA"]
[Tue Jul 21 07:19:14.393453 2026] [security2:error] [pid 230252:tid 230414] [client 20.206.67.15:61253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/reze.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1KwAAArc"]
[Tue Jul 21 07:19:14.501207 2026] [security2:error] [pid 230252:tid 230417] [client 20.206.67.15:59711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/666.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1LAAAAro"]
[Tue Jul 21 07:19:14.519090 2026] [security2:error] [pid 230252:tid 230418] [client 20.151.10.161:53577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/images.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1LQAAArs"]
[Tue Jul 21 07:19:14.550909 2026] [security2:error] [pid 230252:tid 230420] [client 20.197.192.193:11137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/ez.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1LwAAAr0"]
[Tue Jul 21 07:19:14.625247 2026] [security2:error] [pid 229246:tid 229435] [client 20.206.67.15:59704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wehrman.php"] [unique_id "al9HoiBMYeh5YLVG45xZ-AAAAk8"]
[Tue Jul 21 07:19:14.686287 2026] [security2:error] [pid 230252:tid 230427] [client 4.204.201.85:35345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/f35.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1MQAAAsQ"]
[Tue Jul 21 07:19:14.696893 2026] [security2:error] [pid 229246:tid 229423] [client 20.206.67.15:59706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-conflg.php"] [unique_id "al9HoiBMYeh5YLVG45xZ-gAAAkM"]
[Tue Jul 21 07:19:14.747374 2026] [security2:error] [pid 229246:tid 229301] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/zc-208.php"] [unique_id "al9HoiBMYeh5YLVG45xZ_AACazY"]
[Tue Jul 21 07:19:14.758343 2026] [security2:error] [pid 229246:tid 229433] [client 20.206.67.15:59675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ff1.php"] [unique_id "al9HoiBMYeh5YLVG45xZ_QAAAk0"]
[Tue Jul 21 07:19:14.790685 2026] [security2:error] [pid 229246:tid 229307] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/sid4.php"] [unique_id "al9HoiBMYeh5YLVG45xZ_gACWzw"]
[Tue Jul 21 07:19:14.805225 2026] [security2:error] [pid 229246:tid 229499] [client 20.206.67.15:61192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/fff.php"] [unique_id "al9HoiBMYeh5YLVG45xZ_wAAAo8"]
[Tue Jul 21 07:19:14.830968 2026] [autoindex:error] [pid 229246:tid 229279] [remote 20.226.60.151:0] AH01276: Cannot serve directory /home4/wende360/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:14.838954 2026] [security2:error] [pid 229246:tid 229496] [client 20.206.67.15:59623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/amax.php"] [unique_id "al9HoiBMYeh5YLVG45xaAgAAAow"]
[Tue Jul 21 07:19:14.876339 2026] [security2:error] [pid 229246:tid 229314] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wmore1.php"] [unique_id "al9HoiBMYeh5YLVG45xaBAACd0M"]
[Tue Jul 21 07:19:14.911870 2026] [security2:error] [pid 230252:tid 230442] [client 20.206.67.15:59634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-firewall.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1NwAAAtM"]
[Tue Jul 21 07:19:14.916267 2026] [security2:error] [pid 229246:tid 229281] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/solo1.php"] [unique_id "al9HoiBMYeh5YLVG45xaCAACbCI"]
[Tue Jul 21 07:19:14.950470 2026] [security2:error] [pid 230252:tid 230446] [client 20.206.67.15:59645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/appt.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1OQAAAtc"]
[Tue Jul 21 07:19:14.974451 2026] [security2:error] [pid 230252:tid 230448] [client 20.206.67.15:59604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-thi.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1OgAAAtk"]
[Tue Jul 21 07:19:14.980733 2026] [security2:error] [pid 230252:tid 230450] [client 20.151.10.161:53596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/alls.php"] [unique_id "al9Hok0Dwhk5-Z44Xro1OwAAAts"]
[Tue Jul 21 07:19:14.998172 2026] [autoindex:error] [pid 229246:tid 229316] [remote 20.226.60.151:0] AH01276: Cannot serve directory /home4/wende360/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:15.003043 2026] [security2:error] [pid 229246:tid 229418] [client 20.206.67.15:61216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/jj.php"] [unique_id "al9HoyBMYeh5YLVG45xaDAAAAj4"]
[Tue Jul 21 07:19:15.046751 2026] [security2:error] [pid 230252:tid 230451] [client 4.204.201.85:26388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ccc.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1PAAAAtw"]
[Tue Jul 21 07:19:15.053239 2026] [security2:error] [pid 229246:tid 229303] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/cong.php"] [unique_id "al9HoyBMYeh5YLVG45xaDwACHTg"]
[Tue Jul 21 07:19:15.062629 2026] [security2:error] [pid 229246:tid 229466] [client 20.206.67.15:61231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/333.php"] [unique_id "al9HoyBMYeh5YLVG45xaEQAAAm4"]
[Tue Jul 21 07:19:15.087340 2026] [autoindex:error] [pid 229246:tid 229317] [remote 20.226.60.151:0] AH01276: Cannot serve directory /home4/wende360/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:15.092471 2026] [security2:error] [pid 230252:tid 230452] [client 20.206.67.15:61234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/albin.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1PQAAAt0"]
[Tue Jul 21 07:19:15.123476 2026] [security2:error] [pid 230252:tid 230455] [client 20.206.67.15:61187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/66.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1PgAAAuA"]
[Tue Jul 21 07:19:15.124518 2026] [security2:error] [pid 230252:tid 230456] [client 4.204.201.85:35451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-load.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1PwAAAuE"]
[Tue Jul 21 07:19:15.134847 2026] [security2:error] [pid 229246:tid 229319] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/public/css.php"] [unique_id "al9HoyBMYeh5YLVG45xaEwACWUg"]
[Tue Jul 21 07:19:15.158391 2026] [security2:error] [pid 230252:tid 230458] [client 20.206.67.15:59656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/motu.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1QAAAAuM"]
[Tue Jul 21 07:19:15.177448 2026] [security2:error] [pid 229246:tid 229327] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/output.php"] [unique_id "al9HoyBMYeh5YLVG45xaFAACOlA"]
[Tue Jul 21 07:19:15.211288 2026] [security2:error] [pid 229246:tid 229296] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-file-120.php"] [unique_id "al9HoyBMYeh5YLVG45xaFQACKTE"]
[Tue Jul 21 07:19:15.225868 2026] [security2:error] [pid 229246:tid 229323] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/special.php"] [unique_id "al9HoyBMYeh5YLVG45xaFgACjUw"]
[Tue Jul 21 07:19:15.239708 2026] [security2:error] [pid 229246:tid 229326] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/as.php"] [unique_id "al9HoyBMYeh5YLVG45xaGAAChE8"]
[Tue Jul 21 07:19:15.253748 2026] [security2:error] [pid 229246:tid 229321] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9HoyBMYeh5YLVG45xaGgACMEo"]
[Tue Jul 21 07:19:15.290109 2026] [security2:error] [pid 229246:tid 229304] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/w1px.php"] [unique_id "al9HoyBMYeh5YLVG45xaGwACkTk"]
[Tue Jul 21 07:19:15.303810 2026] [security2:error] [pid 229246:tid 229290] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/yawa.php"] [unique_id "al9HoyBMYeh5YLVG45xaHAACLis"]
[Tue Jul 21 07:19:15.317960 2026] [security2:error] [pid 229246:tid 229337] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/js.php"] [unique_id "al9HoyBMYeh5YLVG45xaHQACSVo"]
[Tue Jul 21 07:19:15.321335 2026] [security2:error] [pid 230252:tid 230466] [client 20.206.67.15:61307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/kj.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1QgAAAus"]
[Tue Jul 21 07:19:15.322294 2026] [security2:error] [pid 230252:tid 230467] [client 20.151.10.161:55246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/yyu.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1QwAAAuw"]
[Tue Jul 21 07:19:15.370300 2026] [security2:error] [pid 229246:tid 229330] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/core.php"] [unique_id "al9HoyBMYeh5YLVG45xaHgACYVM"]
[Tue Jul 21 07:19:15.392659 2026] [security2:error] [pid 229246:tid 229467] [client 20.206.67.15:57740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp4.php"] [unique_id "al9HoyBMYeh5YLVG45xaHwAAAm8"]
[Tue Jul 21 07:19:15.420220 2026] [security2:error] [pid 229246:tid 229345] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/19.php"] [unique_id "al9HoyBMYeh5YLVG45xaIAACcmI"]
[Tue Jul 21 07:19:15.429007 2026] [security2:error] [pid 229246:tid 229417] [client 20.197.192.193:11175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/fz.php"] [unique_id "al9HoyBMYeh5YLVG45xaIQAAAj0"]
[Tue Jul 21 07:19:15.459864 2026] [security2:error] [pid 229246:tid 229339] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/inc.php"] [unique_id "al9HoyBMYeh5YLVG45xaIwACL1w"]
[Tue Jul 21 07:19:15.464628 2026] [security2:error] [pid 229246:tid 229401] [client 20.206.67.15:59587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/file61.php"] [unique_id "al9HoyBMYeh5YLVG45xaJAAAAi0"]
[Tue Jul 21 07:19:15.482436 2026] [security2:error] [pid 229246:tid 229331] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9HoyBMYeh5YLVG45xaJQACe1Q"]
[Tue Jul 21 07:19:15.496381 2026] [security2:error] [pid 229246:tid 229320] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9HoyBMYeh5YLVG45xaJwACdEk"]
[Tue Jul 21 07:19:15.506618 2026] [security2:error] [pid 229246:tid 229461] [client 4.204.201.85:35402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/xyn.php"] [unique_id "al9HoyBMYeh5YLVG45xaKAAAAmk"]
[Tue Jul 21 07:19:15.510725 2026] [security2:error] [pid 229246:tid 229328] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ss.php"] [unique_id "al9HoyBMYeh5YLVG45xaKQACilE"]
[Tue Jul 21 07:19:15.516649 2026] [security2:error] [pid 229246:tid 229476] [client 4.204.201.85:26606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/w.php"] [unique_id "al9HoyBMYeh5YLVG45xaKgAAAng"]
[Tue Jul 21 07:19:15.526171 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.67.15:59708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp.php"] [unique_id "al9HoyBMYeh5YLVG45xaKwAAAms"]
[Tue Jul 21 07:19:15.538288 2026] [security2:error] [pid 229246:tid 229346] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/min.php"] [unique_id "al9HoyBMYeh5YLVG45xaLAACSGM"]
[Tue Jul 21 07:19:15.553036 2026] [security2:error] [pid 229246:tid 229335] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9HoyBMYeh5YLVG45xaLQACW1g"]
[Tue Jul 21 07:19:15.566001 2026] [security2:error] [pid 229246:tid 229338] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9HoyBMYeh5YLVG45xaLwACRls"]
[Tue Jul 21 07:19:15.579846 2026] [security2:error] [pid 230252:tid 230471] [client 20.206.67.15:61196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-trackback.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1RAAAAvA"]
[Tue Jul 21 07:19:15.580363 2026] [security2:error] [pid 230252:tid 230443] [client 103.162.129.114:56452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1RQAAAtQ"]
[Tue Jul 21 07:19:15.580449 2026] [security2:error] [pid 230252:tid 230443] [client 103.162.129.114:56452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1RQAAAtQ"]
[Tue Jul 21 07:19:15.590176 2026] [security2:error] [pid 229246:tid 229352] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9HoyBMYeh5YLVG45xaMAACcGk"]
[Tue Jul 21 07:19:15.614517 2026] [security2:error] [pid 229246:tid 229347] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9HoyBMYeh5YLVG45xaMQACNmQ"]
[Tue Jul 21 07:19:15.632946 2026] [security2:error] [pid 229246:tid 229356] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/albin.php"] [unique_id "al9HoyBMYeh5YLVG45xaMgACcW0"]
[Tue Jul 21 07:19:15.667351 2026] [security2:error] [pid 230252:tid 230473] [client 20.151.10.161:53605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/by.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1RgAAAvI"]
[Tue Jul 21 07:19:15.673066 2026] [security2:error] [pid 229246:tid 229341] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/cilus.php"] [unique_id "al9HoyBMYeh5YLVG45xaMwACf14"]
[Tue Jul 21 07:19:15.697911 2026] [security2:error] [pid 229246:tid 229354] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/gptsh.php"] [unique_id "al9HoyBMYeh5YLVG45xaNQACh2s"]
[Tue Jul 21 07:19:15.736006 2026] [security2:error] [pid 229246:tid 229357] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/rithin.php"] [unique_id "al9HoyBMYeh5YLVG45xaNgACeW4"]
[Tue Jul 21 07:19:15.750289 2026] [security2:error] [pid 229246:tid 229489] [client 103.121.156.110:59075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HoyBMYeh5YLVG45xaNwAAAoU"]
[Tue Jul 21 07:19:15.750419 2026] [security2:error] [pid 229246:tid 229489] [client 103.121.156.110:59075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HoyBMYeh5YLVG45xaNwAAAoU"]
[Tue Jul 21 07:19:15.761691 2026] [security2:error] [pid 229246:tid 229490] [client 20.206.67.15:59588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/db.php"] [unique_id "al9HoyBMYeh5YLVG45xaOAAAAoY"]
[Tue Jul 21 07:19:15.765519 2026] [security2:error] [pid 229246:tid 229371] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/fffm.php"] [unique_id "al9HoyBMYeh5YLVG45xaOQACIHw"]
[Tue Jul 21 07:19:15.812746 2026] [security2:error] [pid 229246:tid 229367] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/dfre.php"] [unique_id "al9HoyBMYeh5YLVG45xaPAACMng"]
[Tue Jul 21 07:19:15.838503 2026] [security2:error] [pid 230252:tid 230482] [client 20.206.67.15:59602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/NewFile.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1SgAAAvs"]
[Tue Jul 21 07:19:15.859469 2026] [security2:error] [pid 229246:tid 229365] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-happy.php"] [unique_id "al9HoyBMYeh5YLVG45xaPQACbnY"]
[Tue Jul 21 07:19:15.862333 2026] [security2:error] [pid 229246:tid 229459] [client 20.151.10.161:46045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/green1.php"] [unique_id "al9HoyBMYeh5YLVG45xaPgAAAmc"]
[Tue Jul 21 07:19:15.887535 2026] [security2:error] [pid 229246:tid 229333] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/fpr4.php"] [unique_id "al9HoyBMYeh5YLVG45xaQAACS1Y"]
[Tue Jul 21 07:19:15.897071 2026] [security2:error] [pid 230252:tid 230486] [client 20.206.67.15:61301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/xxx.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1SwAAAv8"]
[Tue Jul 21 07:19:15.914478 2026] [security2:error] [pid 229246:tid 229343] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/file88.php"] [unique_id "al9HoyBMYeh5YLVG45xaQQACWWA"]
[Tue Jul 21 07:19:15.946985 2026] [security2:error] [pid 230252:tid 230491] [client 20.206.67.15:59684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/ms.php"] [unique_id "al9Ho00Dwhk5-Z44Xro1TAAAAwQ"]
[Tue Jul 21 07:19:15.971027 2026] [security2:error] [pid 229246:tid 229250] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ccc.php"] [unique_id "al9HoyBMYeh5YLVG45xaQgACOgM"]
[Tue Jul 21 07:19:15.988035 2026] [security2:error] [pid 229246:tid 229397] [client 20.206.67.15:59689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/mini.php"] [unique_id "al9HoyBMYeh5YLVG45xaQwAAAik"]
[Tue Jul 21 07:19:16.031255 2026] [security2:error] [pid 229246:tid 229353] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/777.php"] [unique_id "al9HpCBMYeh5YLVG45xaRQACkmo"]
[Tue Jul 21 07:19:16.055735 2026] [security2:error] [pid 229246:tid 229251] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/for.php"] [unique_id "al9HpCBMYeh5YLVG45xaRgACTgQ"]
[Tue Jul 21 07:19:16.066909 2026] [autoindex:error] [pid 229246:tid 229448] [client 4.204.201.85:35400] AH01276: Cannot serve directory /home3/seaport/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:16.087801 2026] [security2:error] [pid 229246:tid 229253] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/ssla.php"] [unique_id "al9HpCBMYeh5YLVG45xaSAACNQY"]
[Tue Jul 21 07:19:16.095462 2026] [security2:error] [pid 230252:tid 230493] [client 20.206.67.15:57670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/first.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1TgAAAwY"]
[Tue Jul 21 07:19:16.111074 2026] [security2:error] [pid 230252:tid 230495] [client 20.151.10.161:53569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/FAQ.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1TwAAAwg"]
[Tue Jul 21 07:19:16.112844 2026] [security2:error] [pid 229246:tid 229280] [remote 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/zc-131.php"] [unique_id "al9HpCBMYeh5YLVG45xaSQACIiE"]
[Tue Jul 21 07:19:16.161501 2026] [security2:error] [pid 230252:tid 230496] [client 4.204.201.85:26561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1UAAAAwk"]
[Tue Jul 21 07:19:16.176417 2026] [security2:error] [pid 230252:tid 230498] [client 184.75.221.3:38896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1UgAAAws"]
[Tue Jul 21 07:19:16.176509 2026] [security2:error] [pid 230252:tid 230498] [client 184.75.221.3:38896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1UgAAAws"]
[Tue Jul 21 07:19:16.233920 2026] [security2:error] [pid 229246:tid 229435] [client 20.206.67.15:57778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/0okj.php"] [unique_id "al9HpCBMYeh5YLVG45xaTQAAAk8"]
[Tue Jul 21 07:19:16.286404 2026] [security2:error] [pid 229246:tid 229401] [client 20.206.67.15:61294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/grsiuk.php"] [unique_id "al9HpCBMYeh5YLVG45xaTwAAAi0"]
[Tue Jul 21 07:19:16.338089 2026] [security2:error] [pid 230252:tid 230502] [client 20.206.67.15:61205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/shell20211028.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1UwAAAw8"]
[Tue Jul 21 07:19:16.412025 2026] [autoindex:error] [pid 229246:tid 229396] [client 4.204.201.85:35400] AH01276: Cannot serve directory /home3/seaport/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:16.477090 2026] [security2:error] [pid 229246:tid 229496] [client 20.206.67.15:59650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/revealability.php"] [unique_id "al9HpCBMYeh5YLVG45xaVwAAAow"]
[Tue Jul 21 07:19:16.553252 2026] [security2:error] [pid 229246:tid 229387] [client 4.204.201.85:35455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/ccc.php"] [unique_id "al9HpCBMYeh5YLVG45xaWAAAAh8"]
[Tue Jul 21 07:19:16.608109 2026] [security2:error] [pid 229246:tid 229483] [client 20.206.67.15:61252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/btx25.php"] [unique_id "al9HpCBMYeh5YLVG45xaWgAAAn8"]
[Tue Jul 21 07:19:16.627054 2026] [security2:error] [pid 229246:tid 229471] [client 20.197.192.193:11171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/la.php"] [unique_id "al9HpCBMYeh5YLVG45xaWwAAAnM"]
[Tue Jul 21 07:19:16.641027 2026] [security2:error] [pid 230252:tid 230507] [client 20.206.67.15:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/bthil.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1VAAAAxQ"]
[Tue Jul 21 07:19:16.674608 2026] [security2:error] [pid 230252:tid 230509] [client 20.206.67.15:59591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/hplfuns.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1VQAAAxY"]
[Tue Jul 21 07:19:16.682711 2026] [security2:error] [pid 230252:tid 230499] [client 103.187.68.224:57975] ModSecurity: Access denied with code 406 (phase 1). Pattern match "xmlrpc\\\\.php" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "73"] [id "392331"] [rev "3"] [msg "Atomicorp.com WAF Rules: xmlrpc DOS attack"] [severity "CRITICAL"] [hostname "www.vivaconcierge.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1VgAAAww"], referer: https://www.google.com/
[Tue Jul 21 07:19:16.683047 2026] [security2:error] [pid 230252:tid 230499] [client 103.187.68.224:57975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "www.vivaconcierge.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HpE0Dwhk5-Z44Xro1VgAAAww"], referer: https://www.google.com/
[Tue Jul 21 07:19:16.707071 2026] [security2:error] [pid 229246:tid 229377] [client 20.206.67.15:59607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/error.php"] [unique_id "al9HpCBMYeh5YLVG45xaXAAAAhU"]
[Tue Jul 21 07:19:16.788253 2026] [security2:error] [pid 229246:tid 229478] [client 20.206.67.15:59702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/edit.php"] [unique_id "al9HpCBMYeh5YLVG45xaXQAAAno"]
[Tue Jul 21 07:19:16.880558 2026] [security2:error] [pid 229246:tid 229459] [client 4.204.201.85:35410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/w.php"] [unique_id "al9HpCBMYeh5YLVG45xaYQAAAmc"]
[Tue Jul 21 07:19:16.894596 2026] [security2:error] [pid 229246:tid 229424] [client 20.197.192.193:16893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9HpCBMYeh5YLVG45xaYgAAAkQ"]
[Tue Jul 21 07:19:16.908893 2026] [security2:error] [pid 229246:tid 229431] [client 20.206.67.15:61270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/pass4.php"] [unique_id "al9HpCBMYeh5YLVG45xaYwAAAks"]
[Tue Jul 21 07:19:16.914141 2026] [security2:error] [pid 229246:tid 229445] [client 4.204.201.85:26405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/FWAZ.php"] [unique_id "al9HpCBMYeh5YLVG45xaZAAAAlk"]
[Tue Jul 21 07:19:16.946788 2026] [security2:error] [pid 229246:tid 229399] [client 92.119.178.3:33464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HpCBMYeh5YLVG45xaZgAAAis"]
[Tue Jul 21 07:19:16.946911 2026] [security2:error] [pid 229246:tid 229399] [client 92.119.178.3:33464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HpCBMYeh5YLVG45xaZgAAAis"]
[Tue Jul 21 07:19:17.066560 2026] [security2:error] [pid 229246:tid 229288] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xaZwAChik"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.067498 2026] [security2:error] [pid 229246:tid 229278] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xaaAACIB8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.075280 2026] [security2:error] [pid 229246:tid 229368] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xaaQACj3k"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.107673 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:11156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/inso.php"] [unique_id "al9HpSBMYeh5YLVG45xaagAAAoQ"]
[Tue Jul 21 07:19:17.183033 2026] [security2:error] [pid 229246:tid 229385] [client 14.139.42.196:12901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HpSBMYeh5YLVG45xabAAAAh0"]
[Tue Jul 21 07:19:17.183656 2026] [security2:error] [pid 229246:tid 229385] [client 14.139.42.196:12901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HpSBMYeh5YLVG45xabAAAAh0"]
[Tue Jul 21 07:19:17.231769 2026] [security2:error] [pid 229246:tid 229451] [client 20.151.10.161:53580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/coffexium.php"] [unique_id "al9HpSBMYeh5YLVG45xabwAAAl8"]
[Tue Jul 21 07:19:17.264105 2026] [security2:error] [pid 229246:tid 229435] [client 4.204.201.85:35340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9HpSBMYeh5YLVG45xacAAAAk8"]
[Tue Jul 21 07:19:17.277369 2026] [security2:error] [pid 229246:tid 229470] [client 20.197.192.193:11158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wpx.php"] [unique_id "al9HpSBMYeh5YLVG45xacQAAAnI"]
[Tue Jul 21 07:19:17.355792 2026] [security2:error] [pid 229246:tid 229400] [client 20.151.10.161:45971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/biufile.php"] [unique_id "al9HpSBMYeh5YLVG45xacgAAAiw"]
[Tue Jul 21 07:19:17.421520 2026] [security2:error] [pid 229246:tid 229293] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xadgACii4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.428100 2026] [security2:error] [pid 229246:tid 229297] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xadwACazI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.463154 2026] [security2:error] [pid 229246:tid 229358] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xaeAACQ28"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.510447 2026] [security2:error] [pid 229246:tid 229468] [client 20.197.192.193:11159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/berlin.php"] [unique_id "al9HpSBMYeh5YLVG45xaegAAAnA"]
[Tue Jul 21 07:19:17.554004 2026] [security2:error] [pid 229246:tid 229366] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xafAACanc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.586557 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:25990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/miru1.php"] [unique_id "al9HpSBMYeh5YLVG45xafQAAAn8"]
[Tue Jul 21 07:19:17.643669 2026] [security2:error] [pid 229246:tid 229477] [client 4.204.201.85:35342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/FWAZ.php"] [unique_id "al9HpSBMYeh5YLVG45xafwAAAnk"]
[Tue Jul 21 07:19:17.646910 2026] [security2:error] [pid 229246:tid 229476] [client 20.197.192.193:11186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/billur.php"] [unique_id "al9HpSBMYeh5YLVG45xagAAAAng"]
[Tue Jul 21 07:19:17.735066 2026] [security2:error] [pid 229246:tid 229478] [client 20.151.10.161:55244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/red.php"] [unique_id "al9HpSBMYeh5YLVG45xagQAAAno"]
[Tue Jul 21 07:19:17.780118 2026] [security2:error] [pid 229246:tid 229266] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xahAACMhM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.781904 2026] [security2:error] [pid 229246:tid 229300] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xahQACbjU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.865685 2026] [security2:error] [pid 229246:tid 229283] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpSBMYeh5YLVG45xahwACOiQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:17.874287 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.192.193:11218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/mimpi.php"] [unique_id "al9HpSBMYeh5YLVG45xaiAAAAik"]
[Tue Jul 21 07:19:17.927115 2026] [security2:error] [pid 229246:tid 229488] [client 184.75.221.3:38900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HpSBMYeh5YLVG45xajAAAAoQ"]
[Tue Jul 21 07:19:17.927206 2026] [security2:error] [pid 229246:tid 229488] [client 184.75.221.3:38900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HpSBMYeh5YLVG45xajAAAAoQ"]
[Tue Jul 21 07:19:18.017756 2026] [security2:error] [pid 229246:tid 229435] [client 4.204.201.85:35390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/miru1.php"] [unique_id "al9HpiBMYeh5YLVG45xajQAAAk8"]
[Tue Jul 21 07:19:18.053334 2026] [security2:error] [pid 229246:tid 229401] [client 20.197.192.193:16851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/dp.php"] [unique_id "al9HpiBMYeh5YLVG45xakQAAAi0"]
[Tue Jul 21 07:19:18.131758 2026] [security2:error] [pid 229246:tid 229301] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xalAACdDY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.135860 2026] [security2:error] [pid 229246:tid 229307] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xalQACezw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.159584 2026] [security2:error] [pid 229246:tid 229501] [client 136.144.33.241:33449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HpiBMYeh5YLVG45xalgAAApE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:18.233650 2026] [security2:error] [pid 229246:tid 229311] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xamQACSEA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.235329 2026] [security2:error] [pid 229246:tid 229279] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HpiBMYeh5YLVG45xamAACaSA"]
[Tue Jul 21 07:19:18.235464 2026] [security2:error] [pid 229246:tid 229461] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HpiBMYeh5YLVG45xamAACaSA"]
[Tue Jul 21 07:19:18.260189 2026] [security2:error] [pid 229246:tid 229416] [client 20.151.10.161:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9HpiBMYeh5YLVG45xamgAAAjw"]
[Tue Jul 21 07:19:18.431773 2026] [security2:error] [pid 229246:tid 229409] [client 4.204.201.85:26430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/aa.php"] [unique_id "al9HpiBMYeh5YLVG45xaogAAAjU"]
[Tue Jul 21 07:19:18.435115 2026] [security2:error] [pid 229246:tid 229316] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xaowAChUU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.490403 2026] [security2:error] [pid 229246:tid 229303] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xapQACfjg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.493517 2026] [security2:error] [pid 229246:tid 229317] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xapgACMkY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.509268 2026] [security2:error] [pid 229246:tid 229466] [client 20.197.192.193:16839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/bootstrap.php"] [unique_id "al9HpiBMYeh5YLVG45xapwAAAm4"]
[Tue Jul 21 07:19:18.523032 2026] [security2:error] [pid 229246:tid 229459] [client 4.204.201.85:35351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/aa.php"] [unique_id "al9HpiBMYeh5YLVG45xaqAAAAmc"]
[Tue Jul 21 07:19:18.594626 2026] [security2:error] [pid 229246:tid 229327] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xaqgACK1A"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.711235 2026] [security2:error] [pid 229246:tid 229448] [client 20.197.192.193:11255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wp-editor.php"] [unique_id "al9HpiBMYeh5YLVG45xarAAAAlw"]
[Tue Jul 21 07:19:18.810251 2026] [security2:error] [pid 229246:tid 229402] [client 20.197.192.193:16832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/cro.php"] [unique_id "al9HpiBMYeh5YLVG45xarwAAAi4"]
[Tue Jul 21 07:19:18.860778 2026] [security2:error] [pid 229246:tid 229321] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xasgACSko"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.862928 2026] [autoindex:error] [pid 229246:tid 229404] [client 147.185.132.204:62000] AH01276: Cannot serve directory /home2/reser379/megaroteiros.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:18.893412 2026] [security2:error] [pid 229246:tid 229390] [client 20.151.10.161:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/footer.php"] [unique_id "al9HpiBMYeh5YLVG45xatAAAAiI"]
[Tue Jul 21 07:19:18.922622 2026] [security2:error] [pid 229246:tid 229304] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9HpiBMYeh5YLVG45xatgACPTk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:19:18.997997 2026] [security2:error] [pid 229246:tid 229470] [client 4.204.201.85:35336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/122.php"] [unique_id "al9HpiBMYeh5YLVG45xatwAAAnI"]
[Tue Jul 21 07:19:19.073677 2026] [security2:error] [pid 229246:tid 229401] [client 20.197.192.193:16869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/cron-tab.php"] [unique_id "al9HpyBMYeh5YLVG45xauAAAAi0"]
[Tue Jul 21 07:19:19.176237 2026] [security2:error] [pid 230252:tid 230392] [client 4.204.201.85:26585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/122.php"] [unique_id "al9Hp00Dwhk5-Z44Xro1WAAAAqE"]
[Tue Jul 21 07:19:19.350347 2026] [security2:error] [pid 229246:tid 229330] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HpyBMYeh5YLVG45xauwACLFM"]
[Tue Jul 21 07:19:19.350510 2026] [security2:error] [pid 229246:tid 229400] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HpyBMYeh5YLVG45xauwACLFM"]
[Tue Jul 21 07:19:19.404680 2026] [security2:error] [pid 229246:tid 229462] [client 4.204.201.85:35374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/get.php"] [unique_id "al9HpyBMYeh5YLVG45xavQAAAmo"]
[Tue Jul 21 07:19:19.408319 2026] [security2:error] [pid 230252:tid 230393] [client 20.151.10.161:53614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/index.php"] [unique_id "al9Hp00Dwhk5-Z44Xro1WgAAAqI"]
[Tue Jul 21 07:19:19.510105 2026] [security2:error] [pid 229246:tid 229339] [remote 45.146.55.205:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mecanicanogueira.com.br"] [uri "/wp-login.php"] [unique_id "al9HpyBMYeh5YLVG45xawAACRlw"]
[Tue Jul 21 07:19:19.602657 2026] [security2:error] [pid 230252:tid 230401] [client 4.204.201.85:25869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/get.php"] [unique_id "al9Hp00Dwhk5-Z44Xro1XQAAAqo"]
[Tue Jul 21 07:19:19.708729 2026] [security2:error] [pid 229246:tid 229466] [client 20.151.10.161:55290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/zoro.php"] [unique_id "al9HpyBMYeh5YLVG45xawgAAAm4"]
[Tue Jul 21 07:19:19.748807 2026] [security2:error] [pid 230252:tid 230405] [client 20.197.192.193:16849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/koiy.php"] [unique_id "al9Hp00Dwhk5-Z44Xro1XgAAAq4"]
[Tue Jul 21 07:19:19.797248 2026] [security2:error] [pid 230252:tid 230410] [client 4.204.201.85:35347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/as.php"] [unique_id "al9Hp00Dwhk5-Z44Xro1XwAAArM"]
[Tue Jul 21 07:19:19.875327 2026] [security2:error] [pid 230252:tid 230416] [client 20.197.192.193:11155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/hp2.php"] [unique_id "al9Hp00Dwhk5-Z44Xro1YwAAArk"]
[Tue Jul 21 07:19:19.952696 2026] [security2:error] [pid 230252:tid 230418] [client 20.197.192.193:11157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/hp3.php"] [unique_id "al9Hp00Dwhk5-Z44Xro1ZAAAArs"]
[Tue Jul 21 07:19:20.001378 2026] [security2:error] [pid 230252:tid 230425] [client 20.151.10.161:53616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/admin.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1ZwAAAsI"]
[Tue Jul 21 07:19:20.008777 2026] [security2:error] [pid 230252:tid 230426] [client 4.204.201.85:26589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/as.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1aAAAAsM"]
[Tue Jul 21 07:19:20.161708 2026] [security2:error] [pid 230252:tid 230431] [client 4.204.201.85:35330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/ccou.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1aQAAAsg"]
[Tue Jul 21 07:19:20.172564 2026] [security2:error] [pid 229246:tid 229477] [client 45.251.232.145:59062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HqCBMYeh5YLVG45xaxgAAAnk"]
[Tue Jul 21 07:19:20.172689 2026] [security2:error] [pid 229246:tid 229477] [client 45.251.232.145:59062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HqCBMYeh5YLVG45xaxgAAAnk"]
[Tue Jul 21 07:19:20.180083 2026] [security2:error] [pid 229246:tid 229424] [client 20.197.192.193:11177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/aa1.php"] [unique_id "al9HqCBMYeh5YLVG45xaxwAAAkQ"]
[Tue Jul 21 07:19:20.255030 2026] [security2:error] [pid 230252:tid 230400] [client 139.135.44.145:54558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1agAAAqk"]
[Tue Jul 21 07:19:20.255206 2026] [security2:error] [pid 230252:tid 230400] [client 139.135.44.145:54558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1agAAAqk"]
[Tue Jul 21 07:19:20.387169 2026] [security2:error] [pid 230252:tid 230409] [client 20.151.10.161:55234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/greap.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1bAAAArI"]
[Tue Jul 21 07:19:20.397397 2026] [security2:error] [pid 230252:tid 230436] [client 20.197.192.193:11164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/acew67.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1bQAAAs0"]
[Tue Jul 21 07:19:20.442602 2026] [security2:error] [pid 230252:tid 230439] [client 20.151.10.161:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wpconf.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1bwAAAtA"]
[Tue Jul 21 07:19:20.460702 2026] [security2:error] [pid 229246:tid 229388] [client 4.204.201.85:35418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/w3lls.php"] [unique_id "al9HqCBMYeh5YLVG45xaywAAAiA"]
[Tue Jul 21 07:19:20.502462 2026] [security2:error] [pid 229246:tid 229429] [client 4.204.201.85:26579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ccou.php"] [unique_id "al9HqCBMYeh5YLVG45xa0QAAAkk"]
[Tue Jul 21 07:19:20.571347 2026] [security2:error] [pid 229246:tid 229390] [client 134.19.179.187:60274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HqCBMYeh5YLVG45xa1AAAAiI"]
[Tue Jul 21 07:19:20.571441 2026] [security2:error] [pid 229246:tid 229390] [client 134.19.179.187:60274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HqCBMYeh5YLVG45xa1AAAAiI"]
[Tue Jul 21 07:19:20.668949 2026] [security2:error] [pid 230252:tid 230450] [client 20.197.192.193:11212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/bscclapb.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1dQAAAts"]
[Tue Jul 21 07:19:20.811160 2026] [security2:error] [pid 230252:tid 230452] [client 20.151.10.161:53575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/177.php"] [unique_id "al9HqE0Dwhk5-Z44Xro1dwAAAt0"]
[Tue Jul 21 07:19:20.917745 2026] [security2:error] [pid 229246:tid 229357] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HqCBMYeh5YLVG45xa2gACcm4"]
[Tue Jul 21 07:19:20.918033 2026] [security2:error] [pid 229246:tid 229470] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HqCBMYeh5YLVG45xa2gACcm4"]
[Tue Jul 21 07:19:21.020642 2026] [security2:error] [pid 229246:tid 229446] [client 173.252.95.37:45770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HqSBMYeh5YLVG45xa3gAAAlo"]
[Tue Jul 21 07:19:21.126518 2026] [security2:error] [pid 229246:tid 229426] [client 4.204.201.85:35365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/test1.php"] [unique_id "al9HqSBMYeh5YLVG45xa4QAAAkY"]
[Tue Jul 21 07:19:21.158471 2026] [security2:error] [pid 229246:tid 229483] [client 20.151.10.161:55282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/199.php"] [unique_id "al9HqSBMYeh5YLVG45xa4gAAAn8"]
[Tue Jul 21 07:19:21.177584 2026] [security2:error] [pid 230252:tid 230408] [client 74.244.195.153:8808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1eAAAArE"]
[Tue Jul 21 07:19:21.177740 2026] [security2:error] [pid 230252:tid 230408] [client 74.244.195.153:8808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1eAAAArE"]
[Tue Jul 21 07:19:21.226931 2026] [security2:error] [pid 230252:tid 230456] [client 4.204.201.85:26402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/w3lls.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1eQAAAuE"]
[Tue Jul 21 07:19:21.427657 2026] [security2:error] [pid 229246:tid 229424] [client 92.119.178.3:37840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HqSBMYeh5YLVG45xa5gAAAkQ"]
[Tue Jul 21 07:19:21.427751 2026] [security2:error] [pid 229246:tid 229424] [client 92.119.178.3:37840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HqSBMYeh5YLVG45xa5gAAAkQ"]
[Tue Jul 21 07:19:21.563180 2026] [security2:error] [pid 230252:tid 230467] [client 4.204.201.85:35389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/database.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1fAAAAuw"]
[Tue Jul 21 07:19:21.570560 2026] [security2:error] [pid 229246:tid 229477] [client 173.252.95.40:40956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HqSBMYeh5YLVG45xa6wAAAnk"]
[Tue Jul 21 07:19:21.580576 2026] [security2:error] [pid 230252:tid 230469] [client 20.151.10.161:55255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file52.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1fQAAAu4"]
[Tue Jul 21 07:19:21.835174 2026] [security2:error] [pid 230252:tid 230264] [remote 20.153.140.50:55854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1hQAC4go"]
[Tue Jul 21 07:19:21.835353 2026] [security2:error] [pid 230252:tid 230457] [client 20.153.140.50:55854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1hQAC4go"]
[Tue Jul 21 07:19:21.938040 2026] [security2:error] [pid 229246:tid 229401] [client 4.204.201.85:26026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/test1.php"] [unique_id "al9HqSBMYeh5YLVG45xa8QAAAi0"]
[Tue Jul 21 07:19:22.050706 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:53571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/122.php"] [unique_id "al9HqiBMYeh5YLVG45xa9QAAAns"]
[Tue Jul 21 07:19:22.053588 2026] [security2:error] [pid 230252:tid 230482] [client 4.204.201.85:35349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/file.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1hwAAAvs"]
[Tue Jul 21 07:19:22.084117 2026] [security2:error] [pid 230252:tid 230483] [client 20.197.192.193:11162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/else1.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1iAAAAvw"]
[Tue Jul 21 07:19:22.320153 2026] [security2:error] [pid 230252:tid 230492] [client 134.19.179.187:60288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1iQAAAwU"]
[Tue Jul 21 07:19:22.320265 2026] [security2:error] [pid 230252:tid 230492] [client 134.19.179.187:60288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1iQAAAwU"]
[Tue Jul 21 07:19:22.417248 2026] [security2:error] [pid 230252:tid 230473] [client 175.45.70.82:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1igAAAvI"]
[Tue Jul 21 07:19:22.417407 2026] [security2:error] [pid 230252:tid 230473] [client 175.45.70.82:63355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1igAAAvI"]
[Tue Jul 21 07:19:22.432049 2026] [security2:error] [pid 230252:tid 230496] [client 20.151.10.161:53629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/green1.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1iwAAAwk"]
[Tue Jul 21 07:19:22.490981 2026] [security2:error] [pid 229246:tid 229471] [client 4.204.201.85:26427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/database.php"] [unique_id "al9HqiBMYeh5YLVG45xa-wAAAnM"]
[Tue Jul 21 07:19:22.552444 2026] [security2:error] [pid 230252:tid 230265] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1jAADBws"]
[Tue Jul 21 07:19:22.552635 2026] [security2:error] [pid 230252:tid 230494] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1jAADBws"]
[Tue Jul 21 07:19:22.666243 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:35379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/file.php"] [unique_id "al9HqiBMYeh5YLVG45xbAgAAAn8"]
[Tue Jul 21 07:19:22.749691 2026] [security2:error] [pid 230252:tid 230389] [client 20.197.192.193:11166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/tkikikoko.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1lgAAAp4"]
[Tue Jul 21 07:19:22.752806 2026] [security2:error] [pid 229246:tid 229467] [client 193.36.225.73:25867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HqiBMYeh5YLVG45xa_QAAAm8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:22.869484 2026] [security2:error] [pid 230252:tid 230396] [client 4.204.201.85:25998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/file.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1mAAAAqU"]
[Tue Jul 21 07:19:22.905688 2026] [security2:error] [pid 230252:tid 230397] [client 20.197.192.193:16880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9Hqk0Dwhk5-Z44Xro1mQAAAqY"]
[Tue Jul 21 07:19:22.934470 2026] [security2:error] [pid 230252:tid 230453] [client 103.187.68.224:63068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.68.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.vivaconcierge.com.br"] [uri "/administrator/index.php"] [unique_id "al9HqU0Dwhk5-Z44Xro1ggAAAt4"], referer: https://www.google.com/
[Tue Jul 21 07:19:22.955339 2026] [security2:error] [pid 229246:tid 229486] [client 20.197.192.193:16846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wp-css.php"] [unique_id "al9HqiBMYeh5YLVG45xbCAAAAoI"]
[Tue Jul 21 07:19:23.022166 2026] [security2:error] [pid 229246:tid 229397] [client 4.204.201.85:35319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/777.php"] [unique_id "al9HqyBMYeh5YLVG45xbCQAAAik"]
[Tue Jul 21 07:19:23.080599 2026] [security2:error] [pid 229246:tid 229496] [client 20.197.192.193:11191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/wp-explorer.php"] [unique_id "al9HqyBMYeh5YLVG45xbCgAAAow"]
[Tue Jul 21 07:19:23.139179 2026] [security2:error] [pid 229246:tid 229429] [client 20.197.192.193:16838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/akismet.php"] [unique_id "al9HqyBMYeh5YLVG45xbDgAAAkk"]
[Tue Jul 21 07:19:23.198888 2026] [security2:error] [pid 229246:tid 229385] [client 20.151.10.161:53583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/biufile.php"] [unique_id "al9HqyBMYeh5YLVG45xbDwAAAh0"]
[Tue Jul 21 07:19:23.200957 2026] [security2:error] [pid 230252:tid 230266] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1nQACqgw"]
[Tue Jul 21 07:19:23.201122 2026] [security2:error] [pid 230252:tid 230401] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1nQACqgw"]
[Tue Jul 21 07:19:23.241116 2026] [security2:error] [pid 230252:tid 230411] [client 4.204.201.85:26409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/file.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1nwAAArQ"]
[Tue Jul 21 07:19:23.272924 2026] [security2:error] [pid 230252:tid 230414] [client 20.220.225.223:47868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/berlin.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1oAAAArc"]
[Tue Jul 21 07:19:23.283276 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:11181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/ace2.php"] [unique_id "al9HqyBMYeh5YLVG45xbEAAAAn0"]
[Tue Jul 21 07:19:23.296267 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296359 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296466 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296507 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296542 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296649 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296721 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296759 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296810 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296865 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296901 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296938 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.296973 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297008 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297044 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297080 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297115 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297158 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297194 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297229 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297266 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297301 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297336 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297372 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297408 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297444 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297480 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297515 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297600 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297636 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297672 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297707 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297743 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297778 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297820 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297857 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297892 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297929 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.297981 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298016 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298067 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298109 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298153 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298207 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298249 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298285 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298320 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298355 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298404 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298442 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298477 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298513 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298548 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298585 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298620 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298657 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298694 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298730 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298767 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298803 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298849 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298884 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298920 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.298969 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299006 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299042 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299086 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299123 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299163 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299202 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299243 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299281 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299323 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299359 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299393 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299430 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299465 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299501 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299536 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299573 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299609 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299644 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299680 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299715 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299751 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299786 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299838 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299875 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299911 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299946 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.299986 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.300023 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.300069 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.300107 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.300156 2026] [lsapi:warn] [pid 229246:tid 229417] [client 3.89.109.35:50168] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:19:23.329935 2026] [security2:error] [pid 229246:tid 229257] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HqyBMYeh5YLVG45xbEQACIAo"]
[Tue Jul 21 07:19:23.330045 2026] [security2:error] [pid 229246:tid 229388] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HqyBMYeh5YLVG45xbEQACIAo"]
[Tue Jul 21 07:19:23.346085 2026] [security2:error] [pid 230252:tid 230420] [client 20.197.192.193:11256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oficialwebsite.com.br"] [uri "/ms.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1ogAAAr0"]
[Tue Jul 21 07:19:23.514979 2026] [security2:error] [pid 229246:tid 229466] [client 120.61.173.56:51611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HqyBMYeh5YLVG45xbFgAAAm4"]
[Tue Jul 21 07:19:23.515126 2026] [security2:error] [pid 229246:tid 229466] [client 120.61.173.56:51611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HqyBMYeh5YLVG45xbFgAAAm4"]
[Tue Jul 21 07:19:23.589714 2026] [security2:error] [pid 230252:tid 230399] [client 4.204.201.85:35448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/ssixta.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1owAAAqg"]
[Tue Jul 21 07:19:23.674490 2026] [security2:error] [pid 230252:tid 230415] [client 4.204.201.85:26398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/777.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1pQAAArg"]
[Tue Jul 21 07:19:23.935613 2026] [security2:error] [pid 230252:tid 230428] [client 20.206.67.15:61275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/sadcut1.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1pwAAAsU"]
[Tue Jul 21 07:19:23.968658 2026] [security2:error] [pid 230252:tid 230434] [client 20.206.67.15:57694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/bgymj.php"] [unique_id "al9Hq00Dwhk5-Z44Xro1qAAAAss"]
[Tue Jul 21 07:19:24.037527 2026] [security2:error] [pid 229246:tid 229476] [client 20.151.10.161:53572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wpconf.php"] [unique_id "al9HrCBMYeh5YLVG45xbLwAAAng"]
[Tue Jul 21 07:19:24.050185 2026] [security2:error] [pid 229246:tid 229433] [client 20.206.67.15:59681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/yas.php"] [unique_id "al9HrCBMYeh5YLVG45xbMAAAAk0"]
[Tue Jul 21 07:19:24.055592 2026] [security2:error] [pid 229246:tid 229488] [client 184.154.139.40:34782] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.alperembalagens.com.br"] [uri "/eventos.php"] [unique_id "al9HqiBMYeh5YLVG45xbBgAAAoQ"]
[Tue Jul 21 07:19:24.067236 2026] [security2:error] [pid 229246:tid 229406] [client 20.206.67.15:59666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/dx.php"] [unique_id "al9HrCBMYeh5YLVG45xbMQAAAjI"]
[Tue Jul 21 07:19:24.097218 2026] [security2:error] [pid 230252:tid 230437] [client 20.206.67.15:59637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/yellow.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1qgAAAs4"]
[Tue Jul 21 07:19:24.126868 2026] [security2:error] [pid 229246:tid 229482] [client 20.206.67.15:57771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/wp-der.php"] [unique_id "al9HrCBMYeh5YLVG45xbNQAAAn4"]
[Tue Jul 21 07:19:24.181531 2026] [security2:error] [pid 230252:tid 230440] [client 20.206.67.15:61256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/lala.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1rQAAAtE"]
[Tue Jul 21 07:19:24.189120 2026] [security2:error] [pid 230252:tid 230450] [client 4.204.201.85:26591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ssixta.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1rgAAAts"]
[Tue Jul 21 07:19:24.213854 2026] [security2:error] [pid 230252:tid 230452] [client 20.206.67.15:57688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.fitspresso.tryhealth.shop"] [uri "/aa.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1rwAAAt0"]
[Tue Jul 21 07:19:24.237678 2026] [security2:error] [pid 229246:tid 229429] [client 4.204.201.85:35387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/1c.php"] [unique_id "al9HrCBMYeh5YLVG45xbOwAAAkk"]
[Tue Jul 21 07:19:24.327775 2026] [security2:error] [pid 230252:tid 230449] [client 20.151.10.161:46068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/mosty.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1sAAAAto"]
[Tue Jul 21 07:19:24.658666 2026] [security2:error] [pid 229246:tid 229417] [client 4.204.201.85:25865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/1c.php"] [unique_id "al9HrCBMYeh5YLVG45xbRQAAAj0"]
[Tue Jul 21 07:19:24.726974 2026] [security2:error] [pid 230252:tid 230460] [client 4.204.201.85:35368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/test2.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1swAAAuU"]
[Tue Jul 21 07:19:24.802559 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:55241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/mosty.php"] [unique_id "al9HrCBMYeh5YLVG45xbSgAAAlo"]
[Tue Jul 21 07:19:24.817310 2026] [security2:error] [pid 230252:tid 230270] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1tAAC5BA"]
[Tue Jul 21 07:19:24.817494 2026] [security2:error] [pid 230252:tid 230459] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HrE0Dwhk5-Z44Xro1tAAC5BA"]
[Tue Jul 21 07:19:24.898239 2026] [security2:error] [pid 229246:tid 229387] [client 34.74.242.206:1638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "northcomm.com.br"] [uri "/robots.txt"] [unique_id "al9HrCBMYeh5YLVG45xbTQAAAh8"]
[Tue Jul 21 07:19:24.898361 2026] [security2:error] [pid 229246:tid 229387] [client 34.74.242.206:1638] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "northcomm.com.br"] [uri "/robots.txt"] [unique_id "al9HrCBMYeh5YLVG45xbTQAAAh8"]
[Tue Jul 21 07:19:24.996476 2026] [security2:error] [pid 230252:tid 230435] [client 209.141.34.121:54510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "dorathiotoadvogados.com.br"] [uri "/"] [unique_id "al9HrE0Dwhk5-Z44Xro1ugAAAsw"]
[Tue Jul 21 07:19:25.024960 2026] [security2:error] [pid 230252:tid 230444] [client 4.204.201.85:26040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/test2.php"] [unique_id "al9HrU0Dwhk5-Z44Xro1uwAAAtU"]
[Tue Jul 21 07:19:25.058244 2026] [security2:error] [pid 229246:tid 229378] [client 4.204.201.85:35443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/buy.php"] [unique_id "al9HrSBMYeh5YLVG45xbUgAAAhY"]
[Tue Jul 21 07:19:25.122725 2026] [security2:error] [pid 230252:tid 230445] [client 127.0.0.1:31652] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al9HrU0Dwhk5-Z44Xro1vQAAAtY"]
[Tue Jul 21 07:19:25.122767 2026] [security2:error] [pid 229246:tid 229400] [client 127.0.0.1:31640] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.conquisteemcasa.com.br"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al9HrSBMYeh5YLVG45xbUwAAAiw"]
[Tue Jul 21 07:19:25.122860 2026] [security2:error] [pid 230252:tid 230471] [client 74.7.175.170:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.conquisteemcasa.com.br"] [uri "/robots.txt"] [unique_id "al9HrU0Dwhk5-Z44Xro1vAAC8BE"]
[Tue Jul 21 07:19:25.136164 2026] [security2:error] [pid 230252:tid 230477] [client 34.74.242.206:1661] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "northcomm.com.br"] [uri "/"] [unique_id "al9HrU0Dwhk5-Z44Xro1vgAAAvY"]
[Tue Jul 21 07:19:25.136268 2026] [security2:error] [pid 230252:tid 230477] [client 34.74.242.206:1661] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "northcomm.com.br"] [uri "/"] [unique_id "al9HrU0Dwhk5-Z44Xro1vgAAAvY"]
[Tue Jul 21 07:19:25.419032 2026] [security2:error] [pid 229246:tid 229486] [client 4.204.201.85:26594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/buy.php"] [unique_id "al9HrSBMYeh5YLVG45xbWwAAAoI"]
[Tue Jul 21 07:19:25.511393 2026] [security2:error] [pid 229246:tid 229482] [client 209.141.34.121:54568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "dorathiotoadvogados.com.br"] [uri "/"] [unique_id "al9HrSBMYeh5YLVG45xbXQAAAn4"]
[Tue Jul 21 07:19:25.562917 2026] [security2:error] [pid 230252:tid 230490] [client 4.204.201.85:35337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/ssend.php"] [unique_id "al9HrU0Dwhk5-Z44Xro1wQAAAwM"]
[Tue Jul 21 07:19:25.977807 2026] [security2:error] [pid 230252:tid 230509] [client 4.204.201.85:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/item.php"] [unique_id "al9HrU0Dwhk5-Z44Xro1yAAAAxY"]
[Tue Jul 21 07:19:26.000113 2026] [security2:error] [pid 229246:tid 229453] [client 4.204.201.85:26404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ssend.php"] [unique_id "al9HrSBMYeh5YLVG45xbYAAAAmE"]
[Tue Jul 21 07:19:26.062853 2026] [security2:error] [pid 230252:tid 230386] [client 20.151.10.161:55277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/dejavu.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro1yQAAAps"]
[Tue Jul 21 07:19:26.218630 2026] [security2:error] [pid 229246:tid 229435] [client 20.151.10.161:46075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/dejavu.php"] [unique_id "al9HriBMYeh5YLVG45xbYwAAAk8"]
[Tue Jul 21 07:19:26.331283 2026] [security2:error] [pid 230252:tid 230491] [client 103.162.129.114:56947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro1zQAAAwQ"]
[Tue Jul 21 07:19:26.331401 2026] [security2:error] [pid 230252:tid 230491] [client 103.162.129.114:56947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro1zQAAAwQ"]
[Tue Jul 21 07:19:26.337417 2026] [security2:error] [pid 230252:tid 230395] [client 4.204.201.85:26417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/item.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro1zgAAAqQ"]
[Tue Jul 21 07:19:26.390075 2026] [security2:error] [pid 229246:tid 229388] [client 4.204.201.85:35315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/ss.php"] [unique_id "al9HriBMYeh5YLVG45xbZgAAAiA"]
[Tue Jul 21 07:19:26.391614 2026] [security2:error] [pid 230252:tid 230496] [client 103.121.156.110:59494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro10AAAAwk"]
[Tue Jul 21 07:19:26.391713 2026] [security2:error] [pid 230252:tid 230496] [client 103.121.156.110:59494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro10AAAAwk"]
[Tue Jul 21 07:19:26.540622 2026] [security2:error] [pid 230252:tid 230398] [client 173.252.95.32:43800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro10QAAAqc"]
[Tue Jul 21 07:19:26.748045 2026] [security2:error] [pid 230252:tid 230401] [client 4.204.201.85:26622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ss.php"] [unique_id "al9Hrk0Dwhk5-Z44Xro10gAAAqo"]
[Tue Jul 21 07:19:26.972331 2026] [security2:error] [pid 229246:tid 229446] [client 4.204.201.85:35316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/hypo.php"] [unique_id "al9HriBMYeh5YLVG45xbbQAAAlo"]
[Tue Jul 21 07:19:27.095808 2026] [security2:error] [pid 230252:tid 230399] [client 20.197.192.193:27098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/wicked.php"] [unique_id "al9Hr00Dwhk5-Z44Xro12gAAAqg"]
[Tue Jul 21 07:19:27.366840 2026] [security2:error] [pid 230252:tid 230427] [client 4.204.201.85:35361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/users.php"] [unique_id "al9Hr00Dwhk5-Z44Xro13AAAAsQ"]
[Tue Jul 21 07:19:27.422977 2026] [security2:error] [pid 230252:tid 230430] [client 20.226.60.151:54514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/ctex1.php"] [unique_id "al9Hr00Dwhk5-Z44Xro13QAAAsc"]
[Tue Jul 21 07:19:27.780667 2026] [security2:error] [pid 229246:tid 229496] [client 193.36.225.54:30205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HryBMYeh5YLVG45xbdwAAAow"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:27.888114 2026] [security2:error] [pid 230252:tid 230452] [client 4.204.201.85:35355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/177.php"] [unique_id "al9Hr00Dwhk5-Z44Xro14gAAAt0"]
[Tue Jul 21 07:19:28.050845 2026] [security2:error] [pid 229246:tid 229463] [client 14.139.42.196:6546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HsCBMYeh5YLVG45xbfAAAAms"]
[Tue Jul 21 07:19:28.051004 2026] [security2:error] [pid 229246:tid 229463] [client 14.139.42.196:6546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HsCBMYeh5YLVG45xbfAAAAms"]
[Tue Jul 21 07:19:28.087937 2026] [security2:error] [pid 230252:tid 230459] [client 20.151.10.161:53613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/aaf.php"] [unique_id "al9HsE0Dwhk5-Z44Xro15gAAAuQ"]
[Tue Jul 21 07:19:28.151353 2026] [security2:error] [pid 230252:tid 230462] [client 20.151.10.161:46072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/aaf.php"] [unique_id "al9HsE0Dwhk5-Z44Xro16gAAAuc"]
[Tue Jul 21 07:19:28.312507 2026] [security2:error] [pid 230252:tid 230457] [client 4.204.201.85:35274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/config.php"] [unique_id "al9HsE0Dwhk5-Z44Xro17QAAAuI"]
[Tue Jul 21 07:19:28.650647 2026] [security2:error] [pid 230252:tid 230489] [client 4.204.201.85:35290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/gettest.php"] [unique_id "al9HsE0Dwhk5-Z44Xro18QAAAwI"]
[Tue Jul 21 07:19:28.746346 2026] [security2:error] [pid 229246:tid 229350] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HsCBMYeh5YLVG45xbgQACImc"]
[Tue Jul 21 07:19:28.746505 2026] [security2:error] [pid 229246:tid 229390] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HsCBMYeh5YLVG45xbgQACImc"]
[Tue Jul 21 07:19:28.754562 2026] [security2:error] [pid 230252:tid 230480] [client 4.204.201.85:3314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/hypo.php"] [unique_id "al9HsE0Dwhk5-Z44Xro18gAAAvk"]
[Tue Jul 21 07:19:28.931696 2026] [security2:error] [pid 230252:tid 230500] [client 184.154.139.40:37340] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.alperembalagens.com.br"] [uri "/produtos-higiene.php"] [unique_id "al9HsE0Dwhk5-Z44Xro19QAAAw0"]
[Tue Jul 21 07:19:29.010122 2026] [security2:error] [pid 229246:tid 229459] [client 4.204.201.85:35329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/min.php"] [unique_id "al9HsSBMYeh5YLVG45xbhAAAAmc"]
[Tue Jul 21 07:19:29.051597 2026] [security2:error] [pid 230252:tid 230508] [client 74.249.245.134:43887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HsU0Dwhk5-Z44Xro19wAAAxU"]
[Tue Jul 21 07:19:29.324987 2026] [security2:error] [pid 229246:tid 229417] [client 92.119.178.3:54152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9HsSBMYeh5YLVG45xbhwAAAj0"]
[Tue Jul 21 07:19:29.325098 2026] [security2:error] [pid 229246:tid 229417] [client 92.119.178.3:54152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9HsSBMYeh5YLVG45xbhwAAAj0"]
[Tue Jul 21 07:19:29.334751 2026] [security2:error] [pid 230252:tid 230386] [client 4.204.201.85:35359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/dvjul.php"] [unique_id "al9HsU0Dwhk5-Z44Xro1-AAAAps"]
[Tue Jul 21 07:19:29.599833 2026] [security2:error] [pid 230252:tid 230394] [client 20.151.10.161:55237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/term.php"] [unique_id "al9HsU0Dwhk5-Z44Xro1_AAAAqM"]
[Tue Jul 21 07:19:29.639860 2026] [security2:error] [pid 229246:tid 229428] [client 4.204.201.85:35294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/biufile.php"] [unique_id "al9HsSBMYeh5YLVG45xbiwAAAkg"]
[Tue Jul 21 07:19:29.765442 2026] [autoindex:error] [pid 230252:tid 230511] [client 167.94.146.48:51728] AH01276: Cannot serve directory /home4/dralul00/idufinance.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:29.785872 2026] [security2:error] [pid 229246:tid 229468] [client 134.19.179.187:36028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HsSBMYeh5YLVG45xbjwAAAnA"]
[Tue Jul 21 07:19:29.785960 2026] [security2:error] [pid 229246:tid 229468] [client 134.19.179.187:36028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9HsSBMYeh5YLVG45xbjwAAAnA"]
[Tue Jul 21 07:19:29.989911 2026] [security2:error] [pid 229246:tid 229471] [client 4.204.201.85:35270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/av.php"] [unique_id "al9HsSBMYeh5YLVG45xbkAAAAnM"]
[Tue Jul 21 07:19:30.190075 2026] [security2:error] [pid 229246:tid 229267] [remote 192.249.127.213:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.127.249.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tavarescont.com.br"] [uri "/wp-login.php"] [unique_id "al9HsiBMYeh5YLVG45xblAACFRQ"]
[Tue Jul 21 07:19:30.205357 2026] [security2:error] [pid 230252:tid 230285] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Hsk0Dwhk5-Z44Xro2AgACpB8"]
[Tue Jul 21 07:19:30.205474 2026] [security2:error] [pid 230252:tid 230395] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Hsk0Dwhk5-Z44Xro2AgACpB8"]
[Tue Jul 21 07:19:30.579574 2026] [security2:error] [pid 230252:tid 230417] [client 4.204.201.85:35386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/coffexium.php"] [unique_id "al9Hsk0Dwhk5-Z44Xro2BAAAAro"]
[Tue Jul 21 07:19:30.643604 2026] [security2:error] [pid 230252:tid 230397] [client 45.251.232.145:59581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hsk0Dwhk5-Z44Xro2BgAAAqY"]
[Tue Jul 21 07:19:30.643733 2026] [security2:error] [pid 230252:tid 230397] [client 45.251.232.145:59581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hsk0Dwhk5-Z44Xro2BgAAAqY"]
[Tue Jul 21 07:19:30.743340 2026] [security2:error] [pid 230252:tid 230287] [remote 72.167.132.114:60188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Hsk0Dwhk5-Z44Xro2BwACuSE"]
[Tue Jul 21 07:19:30.763387 2026] [security2:error] [pid 230252:tid 230427] [client 20.151.10.161:12050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ha.php"] [unique_id "al9Hsk0Dwhk5-Z44Xro2CAAAAsQ"]
[Tue Jul 21 07:19:30.822723 2026] [security2:error] [pid 229246:tid 229440] [client 20.151.10.161:46029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/term.php"] [unique_id "al9HsiBMYeh5YLVG45xbmgAAAlQ"]
[Tue Jul 21 07:19:30.927300 2026] [security2:error] [pid 229246:tid 229486] [client 4.204.201.85:35377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/core.php"] [unique_id "al9HsiBMYeh5YLVG45xbnAAAAoI"]
[Tue Jul 21 07:19:31.180621 2026] [security2:error] [pid 229246:tid 229457] [client 4.204.201.85:3270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/users.php"] [unique_id "al9HsyBMYeh5YLVG45xboAAAAmU"]
[Tue Jul 21 07:19:31.239287 2026] [security2:error] [pid 229246:tid 229410] [client 4.204.201.85:35383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/als.php"] [unique_id "al9HsyBMYeh5YLVG45xboQAAAjY"]
[Tue Jul 21 07:19:31.327901 2026] [security2:error] [pid 230252:tid 230424] [client 139.135.44.145:53537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2CgAAAsE"]
[Tue Jul 21 07:19:31.328808 2026] [security2:error] [pid 230252:tid 230424] [client 139.135.44.145:53537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2CgAAAsE"]
[Tue Jul 21 07:19:31.598098 2026] [security2:error] [pid 229246:tid 229409] [client 4.204.201.85:35286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/simple.php"] [unique_id "al9HsyBMYeh5YLVG45xbpAAAAjU"]
[Tue Jul 21 07:19:31.626345 2026] [security2:error] [pid 230252:tid 230288] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2CwAC1yI"]
[Tue Jul 21 07:19:31.626492 2026] [security2:error] [pid 230252:tid 230446] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2CwAC1yI"]
[Tue Jul 21 07:19:31.639522 2026] [security2:error] [pid 230252:tid 230418] [client 193.36.225.73:37243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2DAAAArs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:31.776688 2026] [security2:error] [pid 229246:tid 229417] [client 20.226.60.151:54575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/edorxrr.php"] [unique_id "al9HsyBMYeh5YLVG45xbqgAAAj0"]
[Tue Jul 21 07:19:31.919816 2026] [security2:error] [pid 230252:tid 230437] [client 74.244.195.153:55708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2DwAAAs4"]
[Tue Jul 21 07:19:31.923548 2026] [security2:error] [pid 230252:tid 230437] [client 74.244.195.153:55708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2DwAAAs4"]
[Tue Jul 21 07:19:31.958573 2026] [security2:error] [pid 230252:tid 230456] [client 4.204.201.85:35228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/init.php"] [unique_id "al9Hs00Dwhk5-Z44Xro2EAAAAuE"]
[Tue Jul 21 07:19:32.061731 2026] [security2:error] [pid 230252:tid 230289] [remote 182.77.62.24:56052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ellosemijoias.com.br"] [uri "/wp-login.php"] [unique_id "al9HtE0Dwhk5-Z44Xro2EgAC3iM"]
[Tue Jul 21 07:19:32.091157 2026] [security2:error] [pid 229246:tid 229401] [client 74.249.245.134:21870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HtCBMYeh5YLVG45xbrgAAAi0"]
[Tue Jul 21 07:19:32.238112 2026] [security2:error] [pid 229246:tid 229466] [client 74.7.175.163:38062] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.properketo.tryhealth.shop"] [uri "/index.php"] [unique_id "al9HtCBMYeh5YLVG45xbrQACbkA"]
[Tue Jul 21 07:19:32.287457 2026] [security2:error] [pid 230252:tid 230474] [client 4.204.201.85:35292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/fpwch.php"] [unique_id "al9HtE0Dwhk5-Z44Xro2FwAAAvM"]
[Tue Jul 21 07:19:32.643620 2026] [security2:error] [pid 230252:tid 230483] [client 4.204.201.85:35384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/domvf.php"] [unique_id "al9HtE0Dwhk5-Z44Xro2HgAAAvw"]
[Tue Jul 21 07:19:32.649979 2026] [core:alert] [pid 230252:tid 230486] [client 66.249.66.74:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:19:32.920922 2026] [security2:error] [pid 230252:tid 230471] [client 74.7.175.163:38070] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "properketo.tryhealth.shop"] [uri "/index.php"] [unique_id "al9HtE0Dwhk5-Z44Xro2IgAC8CY"], referer: https://www.properketo.tryhealth.shop/robots.txt
[Tue Jul 21 07:19:33.006333 2026] [security2:error] [pid 229246:tid 229467] [client 74.7.228.22:58790] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "properketo.tryhealth.shop"] [uri "/index.php"] [unique_id "al9HtCBMYeh5YLVG45xbvQACb1I"]
[Tue Jul 21 07:19:33.018960 2026] [security2:error] [pid 230252:tid 230508] [client 4.204.201.85:35277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2JQAAAxU"]
[Tue Jul 21 07:19:33.119712 2026] [security2:error] [pid 230252:tid 230509] [client 68.235.38.2:52062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2JgAAAxY"]
[Tue Jul 21 07:19:33.119843 2026] [security2:error] [pid 230252:tid 230509] [client 68.235.38.2:52062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2JgAAAxY"]
[Tue Jul 21 07:19:33.145758 2026] [security2:error] [pid 230252:tid 230386] [client 4.204.201.85:3284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/177.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2JwAAAps"]
[Tue Jul 21 07:19:33.187982 2026] [security2:error] [pid 229246:tid 229426] [client 175.45.70.82:63824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtSBMYeh5YLVG45xbvwAAAkY"]
[Tue Jul 21 07:19:33.188107 2026] [security2:error] [pid 229246:tid 229426] [client 175.45.70.82:63824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtSBMYeh5YLVG45xbvwAAAkY"]
[Tue Jul 21 07:19:33.206185 2026] [security2:error] [pid 229246:tid 229486] [client 20.151.10.161:55272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/hur.php"] [unique_id "al9HtSBMYeh5YLVG45xbwQAAAoI"]
[Tue Jul 21 07:19:33.232360 2026] [security2:error] [pid 229246:tid 229337] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HtSBMYeh5YLVG45xbxAAChVo"]
[Tue Jul 21 07:19:33.232498 2026] [security2:error] [pid 229246:tid 229489] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HtSBMYeh5YLVG45xbxAAChVo"]
[Tue Jul 21 07:19:33.463944 2026] [security2:error] [pid 230252:tid 230396] [client 4.204.201.85:35298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/class.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2KwAAAqU"]
[Tue Jul 21 07:19:33.644894 2026] [security2:error] [pid 230252:tid 230295] [remote 4.205.168.44:33884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/wp-login.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2LgADECk"]
[Tue Jul 21 07:19:33.680252 2026] [security2:error] [pid 230252:tid 230388] [client 74.249.245.134:21863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2LwAAAp0"]
[Tue Jul 21 07:19:33.728056 2026] [security2:error] [pid 229246:tid 229303] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtSBMYeh5YLVG45xbxgACjzg"]
[Tue Jul 21 07:19:33.728241 2026] [security2:error] [pid 229246:tid 229499] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtSBMYeh5YLVG45xbxgACjzg"]
[Tue Jul 21 07:19:33.822979 2026] [security2:error] [pid 229246:tid 229399] [client 4.204.201.85:35338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/echkm.php"] [unique_id "al9HtSBMYeh5YLVG45xbygAAAis"]
[Tue Jul 21 07:19:33.846116 2026] [security2:error] [pid 230252:tid 230296] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2MQACrio"]
[Tue Jul 21 07:19:33.846327 2026] [security2:error] [pid 230252:tid 230405] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtU0Dwhk5-Z44Xro2MQACrio"]
[Tue Jul 21 07:19:33.918856 2026] [security2:error] [pid 229246:tid 229494] [client 20.226.60.151:54470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/miru1.php"] [unique_id "al9HtSBMYeh5YLVG45xbywAAAoo"]
[Tue Jul 21 07:19:34.078757 2026] [security2:error] [pid 230252:tid 230299] [remote 64.225.121.94:47712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedrocromo.com.br"] [uri "/wp-login.php"] [unique_id "al9Htk0Dwhk5-Z44Xro2NAACsy0"]
[Tue Jul 21 07:19:34.093997 2026] [security2:error] [pid 230252:tid 230506] [client 173.252.95.24:54314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9HtE0Dwhk5-Z44Xro2JAAAAxM"]
[Tue Jul 21 07:19:34.151083 2026] [security2:error] [pid 229246:tid 229457] [client 120.61.173.56:52115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtiBMYeh5YLVG45xb0QAAAmU"]
[Tue Jul 21 07:19:34.151191 2026] [security2:error] [pid 229246:tid 229457] [client 120.61.173.56:52115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HtiBMYeh5YLVG45xb0QAAAmU"]
[Tue Jul 21 07:19:34.196830 2026] [security2:error] [pid 229246:tid 229428] [client 4.204.201.85:35411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/lib.php"] [unique_id "al9HtiBMYeh5YLVG45xb0gAAAkg"]
[Tue Jul 21 07:19:34.412804 2026] [security2:error] [pid 230252:tid 230407] [client 4.204.201.85:3208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/config.php"] [unique_id "al9Htk0Dwhk5-Z44Xro2OgAAArA"]
[Tue Jul 21 07:19:34.536657 2026] [security2:error] [pid 230252:tid 230423] [client 4.204.201.85:35366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/login.php"] [unique_id "al9Htk0Dwhk5-Z44Xro2OwAAAsA"]
[Tue Jul 21 07:19:34.588197 2026] [security2:error] [pid 230252:tid 230449] [client 74.249.245.134:56117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/new.php"] [unique_id "al9Htk0Dwhk5-Z44Xro2PQAAAto"]
[Tue Jul 21 07:19:34.830564 2026] [security2:error] [pid 229246:tid 229467] [client 4.204.201.85:35309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/a2.php"] [unique_id "al9HtiBMYeh5YLVG45xb4QAAAm8"]
[Tue Jul 21 07:19:34.861136 2026] [security2:error] [pid 230252:tid 230464] [client 20.197.192.193:27149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/edit.php"] [unique_id "al9Htk0Dwhk5-Z44Xro2RgAAAuk"]
[Tue Jul 21 07:19:34.996126 2026] [security2:error] [pid 229246:tid 229396] [client 4.204.201.85:3215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/gettest.php"] [unique_id "al9HtiBMYeh5YLVG45xb5AAAAig"]
[Tue Jul 21 07:19:35.028900 2026] [security2:error] [pid 230252:tid 230477] [client 4.204.201.85:44016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Ht00Dwhk5-Z44Xro2SQAAAvY"]
[Tue Jul 21 07:19:35.125176 2026] [security2:error] [pid 230252:tid 230486] [client 4.204.201.85:35241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/d61.php"] [unique_id "al9Ht00Dwhk5-Z44Xro2SwAAAv8"]
[Tue Jul 21 07:19:35.375371 2026] [security2:error] [pid 230252:tid 230492] [client 4.204.201.85:3222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/min.php"] [unique_id "al9Ht00Dwhk5-Z44Xro2TQAAAwU"]
[Tue Jul 21 07:19:35.437469 2026] [security2:error] [pid 229246:tid 229402] [client 4.204.201.85:35213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/info.php"] [unique_id "al9HtyBMYeh5YLVG45xb6wAAAi4"]
[Tue Jul 21 07:19:35.440413 2026] [security2:error] [pid 229246:tid 229399] [client 4.204.201.85:43985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HtyBMYeh5YLVG45xb7AAAAis"]
[Tue Jul 21 07:19:35.457618 2026] [security2:error] [pid 229246:tid 229332] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HtyBMYeh5YLVG45xb7QACNlU"]
[Tue Jul 21 07:19:35.457802 2026] [security2:error] [pid 229246:tid 229410] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HtyBMYeh5YLVG45xb7QACNlU"]
[Tue Jul 21 07:19:35.648371 2026] [security2:error] [pid 229246:tid 229441] [client 20.151.10.161:46003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ha.php"] [unique_id "al9HtyBMYeh5YLVG45xb7wAAAlU"]
[Tue Jul 21 07:19:35.674418 2026] [security2:error] [pid 229246:tid 229457] [client 20.151.10.161:12042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/h02ugyh.php"] [unique_id "al9HtyBMYeh5YLVG45xb8AAAAmU"]
[Tue Jul 21 07:19:35.762211 2026] [security2:error] [pid 230252:tid 230389] [client 4.204.201.85:35301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/11.php"] [unique_id "al9Ht00Dwhk5-Z44Xro2TgAAAp4"]
[Tue Jul 21 07:19:35.833869 2026] [security2:error] [pid 230252:tid 230387] [client 4.204.201.85:3313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/dvjul.php"] [unique_id "al9Ht00Dwhk5-Z44Xro2TwAAApw"]
[Tue Jul 21 07:19:36.139615 2026] [security2:error] [pid 229246:tid 229388] [client 4.204.201.85:43971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/media.php"] [unique_id "al9HuCBMYeh5YLVG45xb_AAAAiA"]
[Tue Jul 21 07:19:36.149206 2026] [security2:error] [pid 230252:tid 230406] [client 4.204.201.85:3210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/biufile.php"] [unique_id "al9HuE0Dwhk5-Z44Xro2VwAAAq8"]
[Tue Jul 21 07:19:36.193317 2026] [security2:error] [pid 229246:tid 229462] [client 4.204.201.85:35437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/v2.php"] [unique_id "al9HuCBMYeh5YLVG45xb_QAAAmo"]
[Tue Jul 21 07:19:36.394458 2026] [security2:error] [pid 229246:tid 229406] [client 35.221.17.130:54436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gruposafiramt.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9HuCBMYeh5YLVG45xcAgAAAjI"]
[Tue Jul 21 07:19:36.550486 2026] [security2:error] [pid 229246:tid 229396] [client 74.249.245.134:60802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/class-t.api.php"] [unique_id "al9HuCBMYeh5YLVG45xcBgAAAig"]
[Tue Jul 21 07:19:36.642256 2026] [security2:error] [pid 230252:tid 230419] [client 4.204.201.85:35333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/panel.php"] [unique_id "al9HuE0Dwhk5-Z44Xro2XAAAArw"]
[Tue Jul 21 07:19:36.645502 2026] [security2:error] [pid 229246:tid 229440] [client 4.204.201.85:43997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/images.php"] [unique_id "al9HuCBMYeh5YLVG45xcCAAAAlQ"]
[Tue Jul 21 07:19:36.656889 2026] [security2:error] [pid 230252:tid 230421] [client 35.221.17.130:61545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.17.221.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HuE0Dwhk5-Z44Xro2XQAAAr4"]
[Tue Jul 21 07:19:36.679288 2026] [security2:error] [pid 229246:tid 229404] [client 4.204.201.85:3316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/av.php"] [unique_id "al9HuCBMYeh5YLVG45xcCQAAAjA"]
[Tue Jul 21 07:19:36.742976 2026] [security2:error] [pid 230252:tid 230409] [client 136.144.33.103:48213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HuE0Dwhk5-Z44Xro2WwAAArI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:37.019068 2026] [security2:error] [pid 230252:tid 230388] [client 103.121.156.110:59902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2YwAAAp0"]
[Tue Jul 21 07:19:37.019213 2026] [security2:error] [pid 230252:tid 230388] [client 103.121.156.110:59902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2YwAAAp0"]
[Tue Jul 21 07:19:37.085037 2026] [security2:error] [pid 230252:tid 230426] [client 4.204.201.85:3212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/coffexium.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2ZAAAAsM"]
[Tue Jul 21 07:19:37.087863 2026] [security2:error] [pid 230252:tid 230407] [client 4.204.201.85:35283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/dex.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2ZQAAArA"]
[Tue Jul 21 07:19:37.101807 2026] [security2:error] [pid 230252:tid 230395] [client 103.162.129.114:57449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2ZgAAAqQ"]
[Tue Jul 21 07:19:37.101937 2026] [security2:error] [pid 230252:tid 230395] [client 103.162.129.114:57449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2ZgAAAqQ"]
[Tue Jul 21 07:19:37.275626 2026] [security2:error] [pid 230252:tid 230461] [client 20.151.10.161:53593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/seiso.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2bQAAAuY"]
[Tue Jul 21 07:19:37.305416 2026] [security2:error] [pid 230252:tid 230462] [client 4.204.201.85:43915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/gecko.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2bwAAAuc"]
[Tue Jul 21 07:19:37.550007 2026] [security2:error] [pid 230252:tid 230310] [remote 5.252.52.249:55428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2eAACzTg"]
[Tue Jul 21 07:19:37.567575 2026] [security2:error] [pid 230252:tid 230311] [remote 45.79.123.44:38418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/wp-login.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2eQACwDk"]
[Tue Jul 21 07:19:37.597265 2026] [security2:error] [pid 229246:tid 229408] [client 4.204.201.85:3213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/core.php"] [unique_id "al9HuSBMYeh5YLVG45xcSQAAAjQ"]
[Tue Jul 21 07:19:37.746325 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:35304] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "seaportservicos.com.br"] [uri "/1.php"] [unique_id "al9HuSBMYeh5YLVG45xcUAAAAn8"]
[Tue Jul 21 07:19:37.746430 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:35304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/1.php"] [unique_id "al9HuSBMYeh5YLVG45xcUAAAAn8"]
[Tue Jul 21 07:19:37.796042 2026] [autoindex:error] [pid 229246:tid 229489] [client 101.33.80.42:46630] AH01276: Cannot serve directory /home2/sarare11/milhasexpresso.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:37.803221 2026] [security2:error] [pid 230252:tid 230490] [client 20.220.225.223:52763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/billur.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2ewAAAwM"]
[Tue Jul 21 07:19:37.843403 2026] [security2:error] [pid 229246:tid 229486] [client 35.221.17.130:60572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.17.221.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HuSBMYeh5YLVG45xcUwAAAoI"]
[Tue Jul 21 07:19:37.843501 2026] [security2:error] [pid 229246:tid 229486] [client 35.221.17.130:60572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gruposafiramt.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HuSBMYeh5YLVG45xcUwAAAoI"]
[Tue Jul 21 07:19:37.940425 2026] [core:error] [pid 230252:tid 230445] [client 66.249.66.67:63967] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:19:37.940443 2026] [core:error] [pid 230252:tid 230445] [client 66.249.66.67:63967] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:19:37.968180 2026] [security2:error] [pid 229246:tid 229390] [client 20.197.192.193:27162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/kua.php"] [unique_id "al9HuSBMYeh5YLVG45xcWQAAAiI"]
[Tue Jul 21 07:19:37.992839 2026] [security2:error] [pid 230252:tid 230500] [client 4.204.201.85:3315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/als.php"] [unique_id "al9HuU0Dwhk5-Z44Xro2fQAAAw0"]
[Tue Jul 21 07:19:38.117099 2026] [security2:error] [pid 230252:tid 230391] [client 4.204.201.85:43973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/82.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2gAAAAqA"]
[Tue Jul 21 07:19:38.165719 2026] [security2:error] [pid 229246:tid 229446] [client 4.204.201.85:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/ms.php"] [unique_id "al9HuiBMYeh5YLVG45xcbAAAAlo"]
[Tue Jul 21 07:19:38.314458 2026] [security2:error] [pid 230252:tid 230412] [client 74.249.245.134:61158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/plugins.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2iQAAArU"]
[Tue Jul 21 07:19:38.325901 2026] [security2:error] [pid 230252:tid 230384] [client 4.204.201.85:3268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/simple.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2igAAApk"]
[Tue Jul 21 07:19:38.599800 2026] [security2:error] [pid 230252:tid 230443] [client 4.204.201.85:44027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/admin.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2kgAAAtQ"]
[Tue Jul 21 07:19:38.603735 2026] [security2:error] [pid 230252:tid 230405] [client 14.139.42.196:13751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2kwAAAq4"]
[Tue Jul 21 07:19:38.603857 2026] [security2:error] [pid 230252:tid 230405] [client 14.139.42.196:13751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2kwAAAq4"]
[Tue Jul 21 07:19:38.751620 2026] [security2:error] [pid 230252:tid 230459] [client 4.204.201.85:3301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/init.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2mQAAAuQ"]
[Tue Jul 21 07:19:38.870308 2026] [security2:error] [pid 230252:tid 230476] [client 20.151.10.161:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/hur.php"] [unique_id "al9Huk0Dwhk5-Z44Xro2mwAAAvU"]
[Tue Jul 21 07:19:39.071191 2026] [security2:error] [pid 230252:tid 230482] [client 4.204.201.85:44021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/adminner.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2oAAAAvs"]
[Tue Jul 21 07:19:39.109770 2026] [security2:error] [pid 229246:tid 229499] [client 20.151.10.161:55260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/155.php"] [unique_id "al9HuyBMYeh5YLVG45xcjAAAAo8"]
[Tue Jul 21 07:19:39.161542 2026] [security2:error] [pid 230252:tid 230445] [client 68.235.38.2:37160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2owAAAtY"]
[Tue Jul 21 07:19:39.161641 2026] [security2:error] [pid 230252:tid 230445] [client 68.235.38.2:37160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2owAAAtY"]
[Tue Jul 21 07:19:39.168935 2026] [security2:error] [pid 230252:tid 230494] [client 4.204.201.85:3218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/fpwch.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2pAAAAwc"]
[Tue Jul 21 07:19:39.276507 2026] [autoindex:error] [pid 230252:tid 230436] [client 4.204.201.85:35426] AH01276: Cannot serve directory /home3/seaport/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:39.333909 2026] [security2:error] [pid 230252:tid 230329] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2qAADD0o"]
[Tue Jul 21 07:19:39.334048 2026] [security2:error] [pid 230252:tid 230502] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2qAADD0o"]
[Tue Jul 21 07:19:39.571149 2026] [security2:error] [pid 230252:tid 230492] [client 4.204.201.85:3211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/domvf.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2qQAAAwU"]
[Tue Jul 21 07:19:39.705738 2026] [core:error] [pid 230252:tid 230401] [client 66.249.66.67:37483] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:19:39.705760 2026] [core:error] [pid 230252:tid 230401] [client 66.249.66.67:37483] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:19:39.746710 2026] [security2:error] [pid 230252:tid 230507] [client 4.204.201.85:35422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/memberfuns.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2rAAAAxQ"]
[Tue Jul 21 07:19:39.898357 2026] [security2:error] [pid 230252:tid 230412] [client 4.204.201.85:43917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/admin.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2rQAAArU"]
[Tue Jul 21 07:19:39.985396 2026] [security2:error] [pid 230252:tid 230392] [client 4.204.201.85:3231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp.php"] [unique_id "al9Hu00Dwhk5-Z44Xro2rgAAAqE"]
[Tue Jul 21 07:19:40.085305 2026] [security2:error] [pid 230252:tid 230400] [client 20.151.10.161:53611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ppp.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2tAAAAqk"]
[Tue Jul 21 07:19:40.306750 2026] [security2:error] [pid 230252:tid 230418] [client 74.249.245.134:21907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/jp.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2ugAAArs"]
[Tue Jul 21 07:19:40.337867 2026] [security2:error] [pid 229246:tid 229385] [client 4.204.201.85:43984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/k.php"] [unique_id "al9HvCBMYeh5YLVG45xcmAAAAh0"]
[Tue Jul 21 07:19:40.407708 2026] [security2:error] [pid 230252:tid 230459] [client 4.204.201.85:3214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/class.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2vgAAAuQ"]
[Tue Jul 21 07:19:40.441438 2026] [security2:error] [pid 230252:tid 230433] [client 4.204.201.85:35287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/0.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2vwAAAso"]
[Tue Jul 21 07:19:40.638755 2026] [security2:error] [pid 230252:tid 230388] [client 20.220.225.223:36815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/mimpi.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2wgAAAp0"]
[Tue Jul 21 07:19:40.651914 2026] [security2:error] [pid 229246:tid 229501] [client 4.204.201.85:43977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/blurbs.php"] [unique_id "al9HvCBMYeh5YLVG45xcnQAAApE"]
[Tue Jul 21 07:19:40.760641 2026] [security2:error] [pid 230252:tid 230499] [client 136.144.33.241:25037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2xQAAAww"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:40.787830 2026] [security2:error] [pid 229246:tid 229478] [client 20.151.10.161:55260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/201.php"] [unique_id "al9HvCBMYeh5YLVG45xcogAAAno"]
[Tue Jul 21 07:19:40.801056 2026] [security2:error] [pid 230252:tid 230422] [client 20.226.60.151:54568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/sump1.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2yAAAAr8"]
[Tue Jul 21 07:19:40.920306 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:3202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/echkm.php"] [unique_id "al9HvCBMYeh5YLVG45xcpwAAAn8"]
[Tue Jul 21 07:19:40.946393 2026] [security2:error] [pid 230252:tid 230497] [client 4.204.201.85:35222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/BDKR28.php"] [unique_id "al9HvE0Dwhk5-Z44Xro2yQAAAwo"]
[Tue Jul 21 07:19:41.004591 2026] [security2:error] [pid 230252:tid 230337] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HvU0Dwhk5-Z44Xro2ywADAlI"]
[Tue Jul 21 07:19:41.004820 2026] [security2:error] [pid 230252:tid 230489] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9HvU0Dwhk5-Z44Xro2ywADAlI"]
[Tue Jul 21 07:19:41.114778 2026] [security2:error] [pid 230252:tid 230426] [client 45.251.232.145:60107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HvU0Dwhk5-Z44Xro2zAAAAsM"]
[Tue Jul 21 07:19:41.114947 2026] [security2:error] [pid 230252:tid 230426] [client 45.251.232.145:60107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HvU0Dwhk5-Z44Xro2zAAAAsM"]
[Tue Jul 21 07:19:41.149130 2026] [security2:error] [pid 229246:tid 229430] [client 4.204.201.85:43983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/bajah.php"] [unique_id "al9HvSBMYeh5YLVG45xcqQAAAko"]
[Tue Jul 21 07:19:41.374567 2026] [security2:error] [pid 230252:tid 230491] [client 4.204.201.85:26578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/lib.php"] [unique_id "al9HvU0Dwhk5-Z44Xro21wAAAwQ"]
[Tue Jul 21 07:19:41.466285 2026] [security2:error] [pid 230252:tid 230404] [client 20.197.192.193:27142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/ez.php"] [unique_id "al9HvU0Dwhk5-Z44Xro22AAAAq0"]
[Tue Jul 21 07:19:41.566204 2026] [security2:error] [pid 230252:tid 230469] [client 4.204.201.85:43978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/a.php"] [unique_id "al9HvU0Dwhk5-Z44Xro22QAAAu4"]
[Tue Jul 21 07:19:41.629476 2026] [security2:error] [pid 229246:tid 229440] [client 20.151.10.161:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ops.php"] [unique_id "al9HvSBMYeh5YLVG45xcswAAAlQ"]
[Tue Jul 21 07:19:41.639510 2026] [security2:error] [pid 229246:tid 229457] [client 92.119.178.3:37244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9HvSBMYeh5YLVG45xctAAAAmU"]
[Tue Jul 21 07:19:41.639629 2026] [security2:error] [pid 229246:tid 229457] [client 92.119.178.3:37244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9HvSBMYeh5YLVG45xctAAAAmU"]
[Tue Jul 21 07:19:41.904387 2026] [security2:error] [pid 229246:tid 229402] [client 4.204.201.85:35227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/green1.php"] [unique_id "al9HvSBMYeh5YLVG45xcuwAAAi4"]
[Tue Jul 21 07:19:41.923404 2026] [security2:error] [pid 230252:tid 230416] [client 4.204.201.85:43851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/edit.php"] [unique_id "al9HvU0Dwhk5-Z44Xro23AAAArk"]
[Tue Jul 21 07:19:41.935862 2026] [security2:error] [pid 230252:tid 230341] [remote 37.139.53.11:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.11" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9HvU0Dwhk5-Z44Xro23QACyVY"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:19:41.936047 2026] [security2:error] [pid 230252:tid 230432] [client 37.139.53.11:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9HvU0Dwhk5-Z44Xro23QACyVY"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:19:41.939422 2026] [security2:error] [pid 230252:tid 230415] [client 4.204.201.85:3269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/login.php"] [unique_id "al9HvU0Dwhk5-Z44Xro23gAAArg"]
[Tue Jul 21 07:19:42.002297 2026] [security2:error] [pid 230252:tid 230412] [client 20.197.192.193:6876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro23wAAArU"]
[Tue Jul 21 07:19:42.121099 2026] [security2:error] [pid 230252:tid 230406] [client 20.151.10.161:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/h02ugyh.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro24AAAAq8"]
[Tue Jul 21 07:19:42.258282 2026] [security2:error] [pid 229246:tid 229468] [client 139.135.44.145:54418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HviBMYeh5YLVG45xcwAAAAnA"]
[Tue Jul 21 07:19:42.258953 2026] [security2:error] [pid 229246:tid 229468] [client 139.135.44.145:54418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9HviBMYeh5YLVG45xcwAAAAnA"]
[Tue Jul 21 07:19:42.307578 2026] [security2:error] [pid 230252:tid 230418] [client 4.204.201.85:43909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/hosty.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro25wAAArs"]
[Tue Jul 21 07:19:42.434932 2026] [security2:error] [pid 230252:tid 230342] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro26AACy1c"]
[Tue Jul 21 07:19:42.435128 2026] [security2:error] [pid 230252:tid 230434] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro26AACy1c"]
[Tue Jul 21 07:19:42.526760 2026] [security2:error] [pid 230252:tid 230443] [client 4.204.201.85:3296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/a2.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro27AAAAtQ"]
[Tue Jul 21 07:19:42.715500 2026] [security2:error] [pid 230252:tid 230423] [client 4.204.201.85:43905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/k.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro28gAAAsA"]
[Tue Jul 21 07:19:42.848806 2026] [security2:error] [pid 230252:tid 230480] [client 20.220.225.223:43045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/dp.php"] [unique_id "al9Hvk0Dwhk5-Z44Xro29QAAAvk"]
[Tue Jul 21 07:19:43.069897 2026] [security2:error] [pid 230252:tid 230489] [client 4.204.201.85:35356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/nc4.php"] [unique_id "al9Hv00Dwhk5-Z44Xro29gAAAwI"]
[Tue Jul 21 07:19:43.081596 2026] [security2:error] [pid 229246:tid 229392] [client 4.204.201.85:3283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/d61.php"] [unique_id "al9HvyBMYeh5YLVG45xcygAAAiQ"]
[Tue Jul 21 07:19:43.185396 2026] [security2:error] [pid 230252:tid 230426] [client 20.151.10.161:55285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ingfo.php"] [unique_id "al9Hv00Dwhk5-Z44Xro2-QAAAsM"]
[Tue Jul 21 07:19:43.251731 2026] [security2:error] [pid 230252:tid 230462] [client 74.244.195.153:21999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Hv00Dwhk5-Z44Xro2-gAAAuc"]
[Tue Jul 21 07:19:43.259480 2026] [security2:error] [pid 230252:tid 230462] [client 74.244.195.153:21999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Hv00Dwhk5-Z44Xro2-gAAAuc"]
[Tue Jul 21 07:19:43.261792 2026] [security2:error] [pid 229246:tid 229499] [client 4.204.201.85:43914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/aaa.php"] [unique_id "al9HvyBMYeh5YLVG45xc0AAAAo8"]
[Tue Jul 21 07:19:43.724752 2026] [security2:error] [pid 230252:tid 230507] [client 4.204.201.85:44031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/file5.php"] [unique_id "al9Hv00Dwhk5-Z44Xro2_gAAAxQ"]
[Tue Jul 21 07:19:43.903877 2026] [security2:error] [pid 229246:tid 229463] [client 175.45.70.82:64292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HvyBMYeh5YLVG45xc1wAAAms"]
[Tue Jul 21 07:19:43.903993 2026] [security2:error] [pid 229246:tid 229463] [client 175.45.70.82:64292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HvyBMYeh5YLVG45xc1wAAAms"]
[Tue Jul 21 07:19:43.931647 2026] [security2:error] [pid 229246:tid 229448] [client 4.204.201.85:3228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/info.php"] [unique_id "al9HvyBMYeh5YLVG45xc2AAAAlw"]
[Tue Jul 21 07:19:43.951562 2026] [security2:error] [pid 230252:tid 230406] [client 4.204.201.85:35391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/a1.php"] [unique_id "al9Hv00Dwhk5-Z44Xro3BgAAAq8"]
[Tue Jul 21 07:19:43.953879 2026] [security2:error] [pid 229246:tid 229470] [client 74.249.245.134:61471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/error.php"] [unique_id "al9HvyBMYeh5YLVG45xc2QAAAnI"]
[Tue Jul 21 07:19:44.166158 2026] [security2:error] [pid 230252:tid 230418] [client 20.197.192.193:6344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3GgAAArs"]
[Tue Jul 21 07:19:44.277232 2026] [security2:error] [pid 230252:tid 230376] [remote 152.53.111.131:40644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3IAAC83k"]
[Tue Jul 21 07:19:44.288498 2026] [security2:error] [pid 230252:tid 230377] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3IQAC2no"]
[Tue Jul 21 07:19:44.288660 2026] [security2:error] [pid 230252:tid 230449] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3IQAC2no"]
[Tue Jul 21 07:19:44.339132 2026] [security2:error] [pid 230252:tid 230476] [client 4.204.201.85:44030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/222.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3VAAAAvU"]
[Tue Jul 21 07:19:44.346375 2026] [security2:error] [pid 230252:tid 230499] [client 20.151.10.161:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/seiso.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3VQAAAww"]
[Tue Jul 21 07:19:44.370762 2026] [security2:error] [pid 230252:tid 230318] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3VwAC20A"]
[Tue Jul 21 07:19:44.370863 2026] [security2:error] [pid 230252:tid 230450] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3VwAC20A"]
[Tue Jul 21 07:19:44.550158 2026] [security2:error] [pid 230252:tid 230323] [remote 156.59.198.135:59870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "politicaemdebate.org"] [uri "/wp-content/uploads/2023/03/Joias-ilegaiss-de-michelle.png"] [unique_id "al9HwE0Dwhk5-Z44Xro3XQAC50U"], referer: https://politicaemdebate.org/2023/03/04/joias-trazidas-ilegalmente-para-michelle-bolsonaro/
[Tue Jul 21 07:19:44.691961 2026] [security2:error] [pid 230252:tid 230391] [client 4.204.201.85:3299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/11.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3ZAAAAqA"]
[Tue Jul 21 07:19:44.784555 2026] [security2:error] [pid 230252:tid 230397] [client 120.61.173.56:52612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3bAAAAqY"]
[Tue Jul 21 07:19:44.784684 2026] [security2:error] [pid 230252:tid 230397] [client 120.61.173.56:52612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3bAAAAqY"]
[Tue Jul 21 07:19:44.893389 2026] [security2:error] [pid 230252:tid 230401] [client 4.204.201.85:44003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/test.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3bwAAAqo"]
[Tue Jul 21 07:19:44.894237 2026] [security2:error] [pid 230252:tid 230507] [client 134.19.179.187:34148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3cAAAAxQ"]
[Tue Jul 21 07:19:44.894378 2026] [security2:error] [pid 230252:tid 230507] [client 134.19.179.187:34148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9HwE0Dwhk5-Z44Xro3cAAAAxQ"]
[Tue Jul 21 07:19:44.923731 2026] [security2:error] [pid 229246:tid 229293] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HwCBMYeh5YLVG45xc5AAChS4"]
[Tue Jul 21 07:19:44.923875 2026] [security2:error] [pid 229246:tid 229489] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HwCBMYeh5YLVG45xc5AAChS4"]
[Tue Jul 21 07:19:45.046307 2026] [security2:error] [pid 230252:tid 230458] [client 20.197.192.193:6857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/dp.php"] [unique_id "al9HwU0Dwhk5-Z44Xro3cQAAAuM"]
[Tue Jul 21 07:19:45.304043 2026] [security2:error] [pid 230252:tid 230460] [client 20.220.225.223:59468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/bootstrap.php"] [unique_id "al9HwU0Dwhk5-Z44Xro3cgAAAuU"]
[Tue Jul 21 07:19:45.323171 2026] [security2:error] [pid 230252:tid 230406] [client 20.197.192.193:27073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/fz.php"] [unique_id "al9HwU0Dwhk5-Z44Xro3cwAAAq8"]
[Tue Jul 21 07:19:45.363420 2026] [security2:error] [pid 229246:tid 229453] [client 4.204.201.85:44001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/aaa.php"] [unique_id "al9HwSBMYeh5YLVG45xc6gAAAmE"]
[Tue Jul 21 07:19:45.483175 2026] [security2:error] [pid 229246:tid 229280] [remote 52.128.31.170:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9HvyBMYeh5YLVG45xczAACKyE"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:19:45.567255 2026] [security2:error] [pid 230252:tid 230453] [client 20.151.10.161:53579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/error_log.php"] [unique_id "al9HwU0Dwhk5-Z44Xro3fQAAAt4"]
[Tue Jul 21 07:19:45.681172 2026] [security2:error] [pid 230252:tid 230495] [client 136.144.33.109:57791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9HwU0Dwhk5-Z44Xro3fgAAAwg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:45.860406 2026] [security2:error] [pid 230252:tid 230449] [client 4.204.201.85:3324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/v2.php"] [unique_id "al9HwU0Dwhk5-Z44Xro3gQAAAto"]
[Tue Jul 21 07:19:45.872728 2026] [security2:error] [pid 230252:tid 230499] [client 4.204.201.85:43990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/11.php"] [unique_id "al9HwU0Dwhk5-Z44Xro3ggAAAww"]
[Tue Jul 21 07:19:45.940032 2026] [security2:error] [pid 229246:tid 229486] [client 4.204.201.85:35266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/eee.php"] [unique_id "al9HwSBMYeh5YLVG45xc7wAAAoI"]
[Tue Jul 21 07:19:45.959298 2026] [security2:error] [pid 229246:tid 229494] [client 20.151.10.161:45940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/155.php"] [unique_id "al9HwSBMYeh5YLVG45xc8AAAAoo"]
[Tue Jul 21 07:19:46.000605 2026] [core:alert] [pid 229246:tid 229502] [client 57.141.18.67:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:19:46.087706 2026] [security2:error] [pid 230252:tid 230343] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Hwk0Dwhk5-Z44Xro3hgACv1g"]
[Tue Jul 21 07:19:46.087931 2026] [security2:error] [pid 230252:tid 230422] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Hwk0Dwhk5-Z44Xro3hgACv1g"]
[Tue Jul 21 07:19:46.234636 2026] [security2:error] [pid 229246:tid 229399] [client 52.128.31.170:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9HvyBMYeh5YLVG45xczAACKyE"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:19:46.741527 2026] [security2:error] [pid 230252:tid 230472] [client 74.249.245.134:50998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/classwithtostring.php"] [unique_id "al9Hwk0Dwhk5-Z44Xro3jwAAAvE"]
[Tue Jul 21 07:19:46.823575 2026] [security2:error] [pid 229246:tid 229435] [client 4.204.201.85:35323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-aothait.php"] [unique_id "al9HwiBMYeh5YLVG45xc_AAAAk8"]
[Tue Jul 21 07:19:46.889730 2026] [security2:error] [pid 230252:tid 230361] [remote 154.61.75.100:56562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Hwk0Dwhk5-Z44Xro3kAADA2o"]
[Tue Jul 21 07:19:46.952231 2026] [security2:error] [pid 230252:tid 230507] [client 20.151.10.161:46006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ppp.php"] [unique_id "al9Hwk0Dwhk5-Z44Xro3lAAAAxQ"]
[Tue Jul 21 07:19:47.010473 2026] [security2:error] [pid 230252:tid 230477] [client 4.204.201.85:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/mac.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3lQAAAvY"]
[Tue Jul 21 07:19:47.067173 2026] [security2:error] [pid 230252:tid 230357] [remote 103.112.62.59:50094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3lgADBWY"]
[Tue Jul 21 07:19:47.254333 2026] [security2:error] [pid 230252:tid 230358] [remote 182.77.62.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.hauptmann.com.br"] [uri "/wp-login.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3mgACqmc"]
[Tue Jul 21 07:19:47.273108 2026] [security2:error] [pid 230252:tid 230423] [client 4.204.201.85:35276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/config.json.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3nAAAAsA"]
[Tue Jul 21 07:19:47.329711 2026] [security2:error] [pid 230252:tid 230483] [client 20.226.60.151:54494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/file5.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3nQAAAvw"]
[Tue Jul 21 07:19:47.400476 2026] [access_compat:error] [pid 229246:tid 229388] [client 162.241.63.68:32882] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:19:47.704929 2026] [security2:error] [pid 229246:tid 229377] [client 103.121.156.110:60267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HwyBMYeh5YLVG45xdAwAAAhU"]
[Tue Jul 21 07:19:47.705066 2026] [security2:error] [pid 229246:tid 229377] [client 103.121.156.110:60267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9HwyBMYeh5YLVG45xdAwAAAhU"]
[Tue Jul 21 07:19:47.781779 2026] [security2:error] [pid 230252:tid 230481] [client 20.151.10.161:45902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/201.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3qwAAAvo"]
[Tue Jul 21 07:19:47.805058 2026] [security2:error] [pid 230252:tid 230417] [client 103.162.129.114:57950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3rAAAAro"]
[Tue Jul 21 07:19:47.805184 2026] [security2:error] [pid 230252:tid 230417] [client 103.162.129.114:57950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3rAAAAro"]
[Tue Jul 21 07:19:47.892986 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.192.193:6344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/old.php"] [unique_id "al9HwyBMYeh5YLVG45xdBAAAAik"]
[Tue Jul 21 07:19:47.917422 2026] [security2:error] [pid 230252:tid 230487] [client 4.204.201.85:3233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/panel.php"] [unique_id "al9Hw00Dwhk5-Z44Xro3rQAAAwA"]
[Tue Jul 21 07:19:48.015912 2026] [security2:error] [pid 229246:tid 229441] [client 4.204.201.85:44028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/chosen.php"] [unique_id "al9HxCBMYeh5YLVG45xdCQAAAlU"]
[Tue Jul 21 07:19:48.195742 2026] [security2:error] [pid 230252:tid 230424] [client 4.204.201.85:35307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9HxE0Dwhk5-Z44Xro3tgAAAsE"]
[Tue Jul 21 07:19:48.439078 2026] [security2:error] [pid 230252:tid 230442] [client 20.151.10.161:46069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ops.php"] [unique_id "al9HxE0Dwhk5-Z44Xro3uwAAAtM"]
[Tue Jul 21 07:19:48.790332 2026] [security2:error] [pid 229246:tid 229486] [client 20.10.88.227:9799] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gnxinox.com.br"] [uri "/index.php"] [unique_id "al9HxCBMYeh5YLVG45xdEAAAAoI"]
[Tue Jul 21 07:19:48.906034 2026] [security2:error] [pid 230252:tid 230467] [client 20.151.10.161:46024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ingfo.php"] [unique_id "al9HxE0Dwhk5-Z44Xro3vAAAAuw"]
[Tue Jul 21 07:19:48.920118 2026] [security2:error] [pid 229246:tid 229402] [client 4.204.201.85:44007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/cream1.php"] [unique_id "al9HxCBMYeh5YLVG45xdEwAAAi4"]
[Tue Jul 21 07:19:49.149340 2026] [security2:error] [pid 229246:tid 229497] [client 14.139.42.196:20251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HxSBMYeh5YLVG45xdHAAAAo0"]
[Tue Jul 21 07:19:49.149438 2026] [security2:error] [pid 229246:tid 229497] [client 14.139.42.196:20251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HxSBMYeh5YLVG45xdHAAAAo0"]
[Tue Jul 21 07:19:49.279162 2026] [security2:error] [pid 229246:tid 229496] [client 20.151.10.161:12036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xenon1337.php"] [unique_id "al9HxSBMYeh5YLVG45xdHQAAAow"]
[Tue Jul 21 07:19:49.510475 2026] [security2:error] [pid 229246:tid 229388] [client 4.204.201.85:3271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/dex.php"] [unique_id "al9HxSBMYeh5YLVG45xdHwAAAiA"]
[Tue Jul 21 07:19:49.722873 2026] [security2:error] [pid 229246:tid 229478] [client 20.151.10.161:45998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/error_log.php"] [unique_id "al9HxSBMYeh5YLVG45xdJgAAAno"]
[Tue Jul 21 07:19:49.759084 2026] [security2:error] [pid 230252:tid 230351] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HxU0Dwhk5-Z44Xro3yAAC52A"]
[Tue Jul 21 07:19:49.759220 2026] [security2:error] [pid 230252:tid 230462] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9HxU0Dwhk5-Z44Xro3yAAC52A"]
[Tue Jul 21 07:19:49.807402 2026] [security2:error] [pid 229246:tid 229457] [client 172.245.102.44:56031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HxSBMYeh5YLVG45xdIwAAAmU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:49.853207 2026] [security2:error] [pid 229246:tid 229314] [remote 132.148.72.88:42372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nocaminhodafe.com.br"] [uri "/wp-login.php"] [unique_id "al9HxSBMYeh5YLVG45xdJwACQ0M"]
[Tue Jul 21 07:19:49.880127 2026] [security2:error] [pid 230252:tid 230482] [client 157.90.156.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9HxU0Dwhk5-Z44Xro3ygAC-3Q"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:19:50.101370 2026] [security2:error] [pid 230252:tid 230416] [client 4.204.201.85:3291] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "conectarpessoas.com.br"] [uri "/1.php"] [unique_id "al9Hxk0Dwhk5-Z44Xro30QAAArk"]
[Tue Jul 21 07:19:50.101483 2026] [security2:error] [pid 230252:tid 230416] [client 4.204.201.85:3291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/1.php"] [unique_id "al9Hxk0Dwhk5-Z44Xro30QAAArk"]
[Tue Jul 21 07:19:50.107472 2026] [security2:error] [pid 230252:tid 230495] [client 157.90.156.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9Hxk0Dwhk5-Z44Xro30gADCHY"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:19:50.155475 2026] [security2:error] [pid 230252:tid 230464] [client 20.151.10.161:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xenon1337.php"] [unique_id "al9Hxk0Dwhk5-Z44Xro31QAAAuk"]
[Tue Jul 21 07:19:50.352918 2026] [security2:error] [pid 229246:tid 229393] [client 4.204.201.85:35271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/k2.php"] [unique_id "al9HxiBMYeh5YLVG45xdLwAAAiU"]
[Tue Jul 21 07:19:50.622632 2026] [security2:error] [pid 229246:tid 229463] [client 20.151.10.161:45951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/test11.php"] [unique_id "al9HxiBMYeh5YLVG45xdNAAAAms"]
[Tue Jul 21 07:19:50.635852 2026] [autoindex:error] [pid 229246:tid 229448] [client 205.210.31.180:59630] AH01276: Cannot serve directory /home1/denerd44/dpatrick.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:50.786906 2026] [security2:error] [pid 229246:tid 229468] [client 4.204.201.85:3209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/ms.php"] [unique_id "al9HxiBMYeh5YLVG45xdNwAAAnA"]
[Tue Jul 21 07:19:50.889133 2026] [security2:error] [pid 230252:tid 230405] [client 4.204.201.85:35310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9Hxk0Dwhk5-Z44Xro34QAAAq4"]
[Tue Jul 21 07:19:50.983388 2026] [security2:error] [pid 230252:tid 230433] [client 74.249.245.134:50952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/bless.php"] [unique_id "al9Hxk0Dwhk5-Z44Xro35AAAAso"]
[Tue Jul 21 07:19:51.068626 2026] [security2:error] [pid 229246:tid 229431] [client 20.151.10.161:46061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/koala.php"] [unique_id "al9HxyBMYeh5YLVG45xdOgAAAks"]
[Tue Jul 21 07:19:51.291632 2026] [security2:error] [pid 230252:tid 230502] [client 20.197.192.193:6372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/ms-new.php"] [unique_id "al9Hx00Dwhk5-Z44Xro35gAAAw8"]
[Tue Jul 21 07:19:51.442551 2026] [security2:error] [pid 230252:tid 230395] [client 4.204.201.85:35218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9Hx00Dwhk5-Z44Xro36AAAAqQ"]
[Tue Jul 21 07:19:51.468762 2026] [security2:error] [pid 230252:tid 230507] [client 4.204.201.85:26572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/memberfuns.php"] [unique_id "al9Hx00Dwhk5-Z44Xro36QAAAxQ"]
[Tue Jul 21 07:19:51.618555 2026] [security2:error] [pid 230252:tid 230393] [client 45.251.232.145:60618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hx00Dwhk5-Z44Xro37QAAAqI"]
[Tue Jul 21 07:19:51.618659 2026] [security2:error] [pid 230252:tid 230393] [client 45.251.232.145:60618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hx00Dwhk5-Z44Xro37QAAAqI"]
[Tue Jul 21 07:19:51.798383 2026] [security2:error] [pid 230252:tid 230290] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Hx00Dwhk5-Z44Xro38wAC7iQ"]
[Tue Jul 21 07:19:51.798573 2026] [security2:error] [pid 230252:tid 230469] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Hx00Dwhk5-Z44Xro38wAC7iQ"]
[Tue Jul 21 07:19:51.843137 2026] [security2:error] [pid 229246:tid 229401] [client 20.151.10.161:46007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/mac.php"] [unique_id "al9HxyBMYeh5YLVG45xdQQAAAi0"]
[Tue Jul 21 07:19:51.942137 2026] [security2:error] [pid 230252:tid 230399] [client 4.204.201.85:3318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/0.php"] [unique_id "al9Hx00Dwhk5-Z44Xro39AAAAqg"]
[Tue Jul 21 07:19:52.196907 2026] [security2:error] [pid 229246:tid 229410] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9HyCBMYeh5YLVG45xdRAAAAjY"]
[Tue Jul 21 07:19:52.279156 2026] [security2:error] [pid 229246:tid 229453] [client 4.204.201.85:35285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9HyCBMYeh5YLVG45xdRgAAAmE"]
[Tue Jul 21 07:19:52.420798 2026] [security2:error] [pid 230252:tid 230406] [client 20.151.10.161:46034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9HyE0Dwhk5-Z44Xro3_gAAAq8"]
[Tue Jul 21 07:19:52.620230 2026] [security2:error] [pid 229246:tid 229481] [client 4.204.201.85:3216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/BDKR28.php"] [unique_id "al9HyCBMYeh5YLVG45xdSQAAAn0"]
[Tue Jul 21 07:19:52.940104 2026] [security2:error] [pid 230252:tid 230445] [client 20.151.10.161:45900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wefile.php"] [unique_id "al9HyE0Dwhk5-Z44Xro4AwAAAtY"]
[Tue Jul 21 07:19:52.977888 2026] [security2:error] [pid 230252:tid 230497] [client 4.204.201.85:44019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/dr.php"] [unique_id "al9HyE0Dwhk5-Z44Xro4BQAAAwo"]
[Tue Jul 21 07:19:53.169679 2026] [security2:error] [pid 230252:tid 230433] [client 134.19.179.187:43314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4CwAAAso"]
[Tue Jul 21 07:19:53.169833 2026] [security2:error] [pid 230252:tid 230433] [client 134.19.179.187:43314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4CwAAAso"]
[Tue Jul 21 07:19:53.208287 2026] [security2:error] [pid 230252:tid 230459] [client 4.204.201.85:3282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/green1.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4DAAAAuQ"]
[Tue Jul 21 07:19:53.210775 2026] [security2:error] [pid 230252:tid 230264] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4DQACrgo"]
[Tue Jul 21 07:19:53.210978 2026] [security2:error] [pid 230252:tid 230405] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4DQACrgo"]
[Tue Jul 21 07:19:53.309270 2026] [security2:error] [pid 230252:tid 230387] [client 4.204.201.85:35205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/for.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4EAAAApw"]
[Tue Jul 21 07:19:53.479858 2026] [autoindex:error] [pid 230252:tid 230447] [client 198.235.24.47:63782] AH01276: Cannot serve directory /home4/ciclod61/ciclododinheiro.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:19:53.610104 2026] [security2:error] [pid 230252:tid 230423] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4EwAAAsA"]
[Tue Jul 21 07:19:53.710821 2026] [security2:error] [pid 230252:tid 230483] [client 134.19.179.187:60740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4FgAAAvw"]
[Tue Jul 21 07:19:53.710924 2026] [security2:error] [pid 230252:tid 230483] [client 134.19.179.187:60740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4FgAAAvw"]
[Tue Jul 21 07:19:53.732174 2026] [security2:error] [pid 230252:tid 230428] [client 4.204.201.85:43998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/x.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4FwAAAsU"]
[Tue Jul 21 07:19:53.778415 2026] [security2:error] [pid 230252:tid 230390] [client 194.147.58.101:44780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/localhost.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4GwAAAp8"]
[Tue Jul 21 07:19:53.778555 2026] [security2:error] [pid 230252:tid 230434] [client 194.147.58.101:44674] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/db_backup.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4GgAAAss"]
[Tue Jul 21 07:19:53.778619 2026] [security2:error] [pid 229246:tid 229494] [client 194.147.58.101:44704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/br1102.hostgator.com.br.sql"] [unique_id "al9HySBMYeh5YLVG45xdWAAAAoo"]
[Tue Jul 21 07:19:53.779939 2026] [security2:error] [pid 230252:tid 230395] [client 194.147.58.101:44680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/dbdump.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4HAAAAqQ"]
[Tue Jul 21 07:19:53.780047 2026] [security2:error] [pid 229246:tid 229496] [client 194.147.58.101:44690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/db.sql"] [unique_id "al9HySBMYeh5YLVG45xdWQAAAow"]
[Tue Jul 21 07:19:53.780279 2026] [security2:error] [pid 229246:tid 229433] [client 194.147.58.101:44684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/br1102.hostgator.com.br_db.sql"] [unique_id "al9HySBMYeh5YLVG45xdWgAAAk0"]
[Tue Jul 21 07:19:53.780705 2026] [security2:error] [pid 230252:tid 230414] [client 194.147.58.101:44720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/mysqldump.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4HQAAArc"]
[Tue Jul 21 07:19:53.781194 2026] [security2:error] [pid 229246:tid 229468] [client 194.147.58.101:44730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/mysql.sql"] [unique_id "al9HySBMYeh5YLVG45xdWwAAAnA"]
[Tue Jul 21 07:19:53.781239 2026] [security2:error] [pid 230252:tid 230507] [client 194.147.58.101:44712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/backup.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4HgAAAxQ"]
[Tue Jul 21 07:19:53.781424 2026] [security2:error] [pid 230252:tid 230491] [client 194.147.58.101:44790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wp-content/uploads/dump.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4HwAAAwQ"]
[Tue Jul 21 07:19:53.781538 2026] [security2:error] [pid 230252:tid 230393] [client 194.147.58.101:44764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/translate.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4IAAAAqI"]
[Tue Jul 21 07:19:53.781581 2026] [security2:error] [pid 229246:tid 229462] [client 194.147.58.101:44810] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wp-content/mysql.sql"] [unique_id "al9HySBMYeh5YLVG45xdXAAAAmo"]
[Tue Jul 21 07:19:53.782508 2026] [security2:error] [pid 230252:tid 230401] [client 194.147.58.101:44826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/sql.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4IQAAAqo"]
[Tue Jul 21 07:19:53.783273 2026] [security2:error] [pid 230252:tid 230458] [client 194.147.58.101:44734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/www.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4IgAAAuM"]
[Tue Jul 21 07:19:53.783456 2026] [security2:error] [pid 230252:tid 230503] [client 194.147.58.101:44816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/site.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4IwAAAxA"]
[Tue Jul 21 07:19:53.783686 2026] [security2:error] [pid 230252:tid 230477] [client 194.147.58.101:44804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/dump.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4JAAAAvY"]
[Tue Jul 21 07:19:53.784011 2026] [security2:error] [pid 230252:tid 230425] [client 194.147.58.101:44856] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/data.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4JQAAAsI"]
[Tue Jul 21 07:19:53.784095 2026] [security2:error] [pid 229246:tid 229414] [client 194.147.58.101:44746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/1.sql"] [unique_id "al9HySBMYeh5YLVG45xdXQAAAjo"]
[Tue Jul 21 07:19:53.785463 2026] [security2:error] [pid 230252:tid 230432] [client 194.147.58.101:44842] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/users.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4JgAAAsk"]
[Tue Jul 21 07:19:53.785685 2026] [security2:error] [pid 230252:tid 230475] [client 194.147.58.101:44748] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/temp.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4JwAAAvQ"]
[Tue Jul 21 07:19:53.787315 2026] [security2:error] [pid 230252:tid 230470] [client 194.147.58.101:44688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/database.sql"] [unique_id "al9HyU0Dwhk5-Z44Xro4KAAAAu8"]
[Tue Jul 21 07:19:53.884762 2026] [security2:error] [pid 230252:tid 230495] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/xyn.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4LAAAAwg"]
[Tue Jul 21 07:19:53.962827 2026] [security2:error] [pid 230252:tid 230415] [client 4.204.201.85:26418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/nc4.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4LQAAArg"]
[Tue Jul 21 07:19:53.986078 2026] [security2:error] [pid 230252:tid 230422] [client 8.228.118.177:61230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rlvgestaoempresarial.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9HyU0Dwhk5-Z44Xro4LgAAAr8"]
[Tue Jul 21 07:19:54.158442 2026] [security2:error] [pid 230252:tid 230466] [client 20.151.10.161:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4MQAAAus"]
[Tue Jul 21 07:19:54.219563 2026] [security2:error] [pid 230252:tid 230465] [client 74.249.245.134:34473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/storage/index.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4MwAAAuo"]
[Tue Jul 21 07:19:54.331952 2026] [security2:error] [pid 230252:tid 230442] [client 20.226.60.151:61074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/0xD.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4NgAAAtM"]
[Tue Jul 21 07:19:54.376273 2026] [security2:error] [pid 230252:tid 230481] [client 136.144.33.99:57737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4OAAAAvo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:54.476527 2026] [security2:error] [pid 230252:tid 230399] [client 74.244.195.153:31557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4PgAAAqg"]
[Tue Jul 21 07:19:54.484264 2026] [security2:error] [pid 230252:tid 230399] [client 74.244.195.153:31557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4PgAAAqg"]
[Tue Jul 21 07:19:54.581197 2026] [security2:error] [pid 229246:tid 229471] [client 175.45.70.82:64764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HyiBMYeh5YLVG45xdaQAAAnM"]
[Tue Jul 21 07:19:54.581375 2026] [security2:error] [pid 229246:tid 229471] [client 175.45.70.82:64764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HyiBMYeh5YLVG45xdaQAAAnM"]
[Tue Jul 21 07:19:54.643696 2026] [security2:error] [pid 230252:tid 230423] [client 4.204.201.85:44010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/155.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4QQAAAsA"]
[Tue Jul 21 07:19:54.768516 2026] [security2:error] [pid 229246:tid 229463] [client 20.151.10.161:46077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/2P.php"] [unique_id "al9HyiBMYeh5YLVG45xdbwAAAms"]
[Tue Jul 21 07:19:54.813300 2026] [security2:error] [pid 230252:tid 230395] [client 4.204.201.85:3207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/a1.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4RQAAAqQ"]
[Tue Jul 21 07:19:54.859753 2026] [security2:error] [pid 230252:tid 230288] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4RgADDyI"]
[Tue Jul 21 07:19:54.859977 2026] [security2:error] [pid 230252:tid 230502] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4RgADDyI"]
[Tue Jul 21 07:19:54.907252 2026] [security2:error] [pid 230252:tid 230393] [client 4.204.201.85:35396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/raw.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4RwAAAqI"]
[Tue Jul 21 07:19:54.968248 2026] [security2:error] [pid 230252:tid 230304] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4SAACyzI"]
[Tue Jul 21 07:19:54.968447 2026] [security2:error] [pid 230252:tid 230434] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hyk0Dwhk5-Z44Xro4SAACyzI"]
[Tue Jul 21 07:19:55.075841 2026] [security2:error] [pid 229246:tid 229388] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/patie.php"] [unique_id "al9HyyBMYeh5YLVG45xdcQAAAiA"]
[Tue Jul 21 07:19:55.181176 2026] [security2:error] [pid 230252:tid 230436] [client 4.204.201.85:43970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ops.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4SQAAAs0"]
[Tue Jul 21 07:19:55.347801 2026] [security2:error] [pid 230252:tid 230426] [client 4.204.201.85:3309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/eee.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4SwAAAsM"]
[Tue Jul 21 07:19:55.350918 2026] [security2:error] [pid 229246:tid 229401] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/aa.php"] [unique_id "al9HyyBMYeh5YLVG45xdewAAAi0"]
[Tue Jul 21 07:19:55.456187 2026] [security2:error] [pid 230252:tid 230400] [client 120.61.173.56:53119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4TAAAAqk"]
[Tue Jul 21 07:19:55.456357 2026] [security2:error] [pid 230252:tid 230400] [client 120.61.173.56:53119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4TAAAAqk"]
[Tue Jul 21 07:19:55.486651 2026] [security2:error] [pid 230252:tid 230472] [client 117.222.76.61:55285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.76.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gradiente.com"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4EQAAAvE"]
[Tue Jul 21 07:19:55.486887 2026] [security2:error] [pid 230252:tid 230472] [client 117.222.76.61:55285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gradiente.com"] [uri "/xmlrpc.php"] [unique_id "al9HyU0Dwhk5-Z44Xro4EQAAAvE"]
[Tue Jul 21 07:19:55.489397 2026] [security2:error] [pid 230252:tid 230511] [client 20.151.10.161:45924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4TQAAAxg"]
[Tue Jul 21 07:19:55.671317 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/xwpg.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4TgAAAuk"]
[Tue Jul 21 07:19:55.732069 2026] [security2:error] [pid 229246:tid 229441] [client 159.69.158.189:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9HyyBMYeh5YLVG45xdfgACVXk"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:19:55.910370 2026] [security2:error] [pid 230252:tid 230504] [client 4.204.201.85:43921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/file31.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4UgAAAxE"]
[Tue Jul 21 07:19:55.948243 2026] [security2:error] [pid 230252:tid 230474] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ops.php"] [unique_id "al9Hy00Dwhk5-Z44Xro4UwAAAvM"]
[Tue Jul 21 07:19:55.992875 2026] [security2:error] [pid 229246:tid 229430] [client 4.204.201.85:3263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/wp-aothait.php"] [unique_id "al9HyyBMYeh5YLVG45xdhAAAAko"]
[Tue Jul 21 07:19:56.223029 2026] [security2:error] [pid 230252:tid 230508] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/mac.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4WQAAAxU"]
[Tue Jul 21 07:19:56.225195 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:45924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4WgAAAwY"]
[Tue Jul 21 07:19:56.252040 2026] [security2:error] [pid 230252:tid 230466] [client 20.151.10.161:55249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/test11.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4WwAAAus"]
[Tue Jul 21 07:19:56.267250 2026] [security2:error] [pid 230252:tid 230445] [client 159.69.158.189:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9HzE0Dwhk5-Z44Xro4XAAC1jo"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:19:56.373759 2026] [security2:error] [pid 229246:tid 229377] [client 4.204.201.85:3286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/config.json.php"] [unique_id "al9HzCBMYeh5YLVG45xdjwAAAhU"]
[Tue Jul 21 07:19:56.392510 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.192.193:6870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/track.php"] [unique_id "al9HzCBMYeh5YLVG45xdkAAAAjI"]
[Tue Jul 21 07:19:56.499514 2026] [security2:error] [pid 230252:tid 230469] [client 4.204.201.85:43912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/file6.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4YwAAAu4"]
[Tue Jul 21 07:19:56.527674 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/mg.php"] [unique_id "al9HzCBMYeh5YLVG45xdkgAAAi8"]
[Tue Jul 21 07:19:56.616563 2026] [security2:error] [pid 230252:tid 230483] [client 74.249.245.134:58137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/g.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4ZAAAAvw"]
[Tue Jul 21 07:19:56.688764 2026] [security2:error] [pid 230252:tid 230285] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4ZgACxx8"]
[Tue Jul 21 07:19:56.688937 2026] [security2:error] [pid 230252:tid 230430] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4ZgACxx8"]
[Tue Jul 21 07:19:56.770119 2026] [security2:error] [pid 230252:tid 230440] [client 92.119.178.3:35720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4ZwAAAtE"]
[Tue Jul 21 07:19:56.770227 2026] [security2:error] [pid 230252:tid 230440] [client 92.119.178.3:35720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9HzE0Dwhk5-Z44Xro4ZwAAAtE"]
[Tue Jul 21 07:19:56.822879 2026] [security2:error] [pid 229246:tid 229469] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-post-data.php"] [unique_id "al9HzCBMYeh5YLVG45xdmAAAAnE"]
[Tue Jul 21 07:19:56.885465 2026] [security2:error] [pid 229246:tid 229385] [client 4.204.201.85:3323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9HzCBMYeh5YLVG45xdmQAAAh0"]
[Tue Jul 21 07:19:57.036510 2026] [security2:error] [pid 230252:tid 230491] [client 8.228.118.177:64315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.118.228.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvgestaoempresarial.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4agAAAwQ"]
[Tue Jul 21 07:19:57.036615 2026] [security2:error] [pid 230252:tid 230491] [client 8.228.118.177:64315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rlvgestaoempresarial.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4agAAAwQ"]
[Tue Jul 21 07:19:57.117556 2026] [security2:error] [pid 230252:tid 230307] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4awACtzU"]
[Tue Jul 21 07:19:57.117681 2026] [security2:error] [pid 230252:tid 230414] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4awACtzU"]
[Tue Jul 21 07:19:57.135362 2026] [security2:error] [pid 229246:tid 229378] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/pucci.php"] [unique_id "al9HzSBMYeh5YLVG45xdnQAAAhY"]
[Tue Jul 21 07:19:57.264790 2026] [security2:error] [pid 229246:tid 229414] [client 20.151.10.161:45916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/bob.php"] [unique_id "al9HzSBMYeh5YLVG45xdoQAAAjo"]
[Tue Jul 21 07:19:57.410332 2026] [security2:error] [pid 229246:tid 229388] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/black.php"] [unique_id "al9HzSBMYeh5YLVG45xdpgAAAiA"]
[Tue Jul 21 07:19:57.534953 2026] [security2:error] [pid 230252:tid 230486] [client 20.197.192.193:27186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/la.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4bQAAAv8"]
[Tue Jul 21 07:19:57.607450 2026] [security2:error] [pid 230252:tid 230495] [client 4.204.201.85:3311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/k2.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4bwAAAwg"]
[Tue Jul 21 07:19:57.689442 2026] [security2:error] [pid 229246:tid 229423] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/zlece.php"] [unique_id "al9HzSBMYeh5YLVG45xdpwAAAkM"]
[Tue Jul 21 07:19:57.721256 2026] [security2:error] [pid 230252:tid 230426] [client 134.19.179.187:43342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4cAAAAsM"]
[Tue Jul 21 07:19:57.721368 2026] [security2:error] [pid 230252:tid 230426] [client 134.19.179.187:43342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4cAAAAsM"]
[Tue Jul 21 07:19:57.948328 2026] [security2:error] [pid 230252:tid 230404] [client 20.220.225.223:59491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/wp-editor.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4cwAAAq0"]
[Tue Jul 21 07:19:57.970198 2026] [security2:error] [pid 230252:tid 230454] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/vssrs.php"] [unique_id "al9HzU0Dwhk5-Z44Xro4dwAAAt8"]
[Tue Jul 21 07:19:58.034748 2026] [security2:error] [pid 230252:tid 230407] [client 4.204.201.85:26580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4eAAAArA"]
[Tue Jul 21 07:19:58.093668 2026] [http2:warn] [pid 229246:tid 229386] [client 57.141.18.25:62414] h2_stream(229246-22-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:19:58.273321 2026] [security2:error] [pid 230252:tid 230422] [client 20.151.10.161:46066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/crgio.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4egAAAr8"]
[Tue Jul 21 07:19:58.279278 2026] [security2:error] [pid 230252:tid 230497] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wicked.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4ewAAAwo"]
[Tue Jul 21 07:19:58.343583 2026] [security2:error] [pid 230252:tid 230424] [client 103.121.156.110:60613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4fwAAAsE"]
[Tue Jul 21 07:19:58.343722 2026] [security2:error] [pid 230252:tid 230424] [client 103.121.156.110:60613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4fwAAAsE"]
[Tue Jul 21 07:19:58.371664 2026] [security2:error] [pid 230252:tid 230263] [remote 41.76.214.143:37560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4gQACuQk"]
[Tue Jul 21 07:19:58.459130 2026] [security2:error] [pid 230252:tid 230466] [client 4.204.201.85:3275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4hAAAAus"]
[Tue Jul 21 07:19:58.464285 2026] [security2:error] [pid 229246:tid 229429] [client 103.162.129.114:58491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HziBMYeh5YLVG45xdsQAAAkk"]
[Tue Jul 21 07:19:58.464426 2026] [security2:error] [pid 229246:tid 229429] [client 103.162.129.114:58491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9HziBMYeh5YLVG45xdsQAAAkk"]
[Tue Jul 21 07:19:58.562607 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/24.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4hwAAAuQ"]
[Tue Jul 21 07:19:58.681882 2026] [security2:error] [pid 229246:tid 229446] [client 136.144.33.111:21599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9HziBMYeh5YLVG45xdsgAAAlo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:19:58.689551 2026] [security2:error] [pid 229246:tid 229401] [client 4.204.201.85:43955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/adminfuns.php"] [unique_id "al9HziBMYeh5YLVG45xdtQAAAi0"]
[Tue Jul 21 07:19:58.794650 2026] [security2:error] [pid 230252:tid 230501] [client 4.204.201.85:3272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4iQAAAw4"]
[Tue Jul 21 07:19:58.844150 2026] [security2:error] [pid 230252:tid 230469] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/xacs.php"] [unique_id "al9Hzk0Dwhk5-Z44Xro4igAAAu4"]
[Tue Jul 21 07:19:59.022690 2026] [security2:error] [pid 229246:tid 229483] [client 20.220.225.223:52770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/cro.php"] [unique_id "al9HzyBMYeh5YLVG45xduwAAAn8"]
[Tue Jul 21 07:19:59.124784 2026] [security2:error] [pid 229246:tid 229405] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/zildan.php"] [unique_id "al9HzyBMYeh5YLVG45xdvgAAAjE"]
[Tue Jul 21 07:19:59.172372 2026] [security2:error] [pid 230252:tid 230510] [client 4.204.201.85:26005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/for.php"] [unique_id "al9Hz00Dwhk5-Z44Xro4lAAAAxc"]
[Tue Jul 21 07:19:59.406470 2026] [security2:error] [pid 229246:tid 229402] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/csa.php"] [unique_id "al9HzyBMYeh5YLVG45xdwAAAAi4"]
[Tue Jul 21 07:19:59.589073 2026] [security2:error] [pid 230252:tid 230454] [client 4.204.201.85:43910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/goods.php"] [unique_id "al9Hz00Dwhk5-Z44Xro4mQAAAt8"]
[Tue Jul 21 07:19:59.681233 2026] [security2:error] [pid 230252:tid 230384] [client 4.204.201.85:3249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conectarpessoas.com.br"] [uri "/raw.php"] [unique_id "al9Hz00Dwhk5-Z44Xro4mwAAApk"]
[Tue Jul 21 07:19:59.696890 2026] [security2:error] [pid 230252:tid 230500] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/w3llscc.php"] [unique_id "al9Hz00Dwhk5-Z44Xro4nAAAAw0"]
[Tue Jul 21 07:19:59.968943 2026] [security2:error] [pid 229246:tid 229377] [client 4.204.201.85:43924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/100.php"] [unique_id "al9HzyBMYeh5YLVG45xdzgAAAhU"]
[Tue Jul 21 07:19:59.987808 2026] [security2:error] [pid 230252:tid 230422] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wpx.php"] [unique_id "al9Hz00Dwhk5-Z44Xro4oQAAAr8"]
[Tue Jul 21 07:19:59.989829 2026] [security2:error] [pid 229246:tid 229433] [client 14.139.42.196:19451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HzyBMYeh5YLVG45xdzwAAAk0"]
[Tue Jul 21 07:19:59.989917 2026] [security2:error] [pid 229246:tid 229433] [client 14.139.42.196:19451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9HzyBMYeh5YLVG45xdzwAAAk0"]
[Tue Jul 21 07:20:00.017081 2026] [security2:error] [pid 229246:tid 229365] [remote 124.55.178.99:34008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9H0CBMYeh5YLVG45xd0AACMHY"]
[Tue Jul 21 07:20:00.029898 2026] [security2:error] [pid 229246:tid 229429] [client 20.151.10.161:46008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/pucci.php"] [unique_id "al9H0CBMYeh5YLVG45xd0QAAAkk"]
[Tue Jul 21 07:20:00.222604 2026] [http2:warn] [pid 229246:tid 229480] [client 57.141.18.25:62416] h2_stream(229246-26-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:00.277028 2026] [security2:error] [pid 230252:tid 230300] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H0E0Dwhk5-Z44Xro4owACtS4"]
[Tue Jul 21 07:20:00.277161 2026] [security2:error] [pid 230252:tid 230412] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H0E0Dwhk5-Z44Xro4owACtS4"]
[Tue Jul 21 07:20:00.280030 2026] [security2:error] [pid 230252:tid 230466] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-css.php"] [unique_id "al9H0E0Dwhk5-Z44Xro4pAAAAus"]
[Tue Jul 21 07:20:00.330245 2026] [security2:error] [pid 229246:tid 229469] [client 74.249.245.134:59496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/nf.php"] [unique_id "al9H0CBMYeh5YLVG45xd1gAAAnE"]
[Tue Jul 21 07:20:00.477078 2026] [security2:error] [pid 229246:tid 229393] [client 4.204.201.85:43965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/about.php"] [unique_id "al9H0CBMYeh5YLVG45xd2wAAAiU"]
[Tue Jul 21 07:20:00.597627 2026] [security2:error] [pid 229246:tid 229392] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ho.php"] [unique_id "al9H0CBMYeh5YLVG45xd3wAAAiQ"]
[Tue Jul 21 07:20:00.896439 2026] [security2:error] [pid 229246:tid 229497] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/xy.php"] [unique_id "al9H0CBMYeh5YLVG45xd4AAAAo0"]
[Tue Jul 21 07:20:00.959497 2026] [security2:error] [pid 229246:tid 229423] [client 92.119.178.3:32794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9H0CBMYeh5YLVG45xd4gAAAkM"]
[Tue Jul 21 07:20:00.959605 2026] [security2:error] [pid 229246:tid 229423] [client 92.119.178.3:32794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9H0CBMYeh5YLVG45xd4gAAAkM"]
[Tue Jul 21 07:20:01.167967 2026] [security2:error] [pid 229246:tid 229419] [client 20.197.192.193:27169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9H0SBMYeh5YLVG45xd6AAAAj8"]
[Tue Jul 21 07:20:01.177531 2026] [security2:error] [pid 229246:tid 229406] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/loader.php"] [unique_id "al9H0SBMYeh5YLVG45xd6QAAAjI"]
[Tue Jul 21 07:20:01.452550 2026] [security2:error] [pid 229246:tid 229491] [client 20.220.225.223:47852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/cron-tab.php"] [unique_id "al9H0SBMYeh5YLVG45xd8QAAAoc"]
[Tue Jul 21 07:20:01.460195 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/spadex.php"] [unique_id "al9H0U0Dwhk5-Z44Xro4qQAAAtM"]
[Tue Jul 21 07:20:01.495638 2026] [security2:error] [pid 230252:tid 230396] [client 68.235.38.2:54420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9H0U0Dwhk5-Z44Xro4qwAAAqU"]
[Tue Jul 21 07:20:01.495756 2026] [security2:error] [pid 230252:tid 230396] [client 68.235.38.2:54420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9H0U0Dwhk5-Z44Xro4qwAAAqU"]
[Tue Jul 21 07:20:01.683260 2026] [security2:error] [pid 230252:tid 230432] [client 92.119.178.3:32804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9H0U0Dwhk5-Z44Xro4sgAAAsk"]
[Tue Jul 21 07:20:01.683415 2026] [security2:error] [pid 230252:tid 230432] [client 92.119.178.3:32804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9H0U0Dwhk5-Z44Xro4sgAAAsk"]
[Tue Jul 21 07:20:01.761951 2026] [security2:error] [pid 230252:tid 230475] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/2x.php"] [unique_id "al9H0U0Dwhk5-Z44Xro4tAAAAvQ"]
[Tue Jul 21 07:20:01.875753 2026] [security2:error] [pid 230252:tid 230436] [client 20.197.192.193:6368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/2352356666.php"] [unique_id "al9H0U0Dwhk5-Z44Xro4tQAAAs0"]
[Tue Jul 21 07:20:01.917677 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.917761 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.917885 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.917925 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.917961 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918067 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918150 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918189 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918243 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918279 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918315 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918350 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918385 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918420 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918454 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918489 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918525 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918559 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918593 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918631 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918665 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918700 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918734 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918770 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918804 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918851 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918887 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.918923 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919025 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919083 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919151 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919204 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919259 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919301 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919336 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919372 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919406 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919443 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919497 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919532 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919581 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919624 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919668 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919725 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919764 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919800 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919852 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919886 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919934 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.919972 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920024 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920077 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920124 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920167 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920201 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920236 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920272 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920308 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920343 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920377 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920415 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920450 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920485 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920534 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920571 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920607 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920650 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920688 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920723 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920761 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920800 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920853 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920894 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920929 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.920965 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921000 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921034 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921070 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921104 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921150 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921183 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921217 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921253 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921288 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921322 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921357 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921392 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921429 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921464 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921499 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921539 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921575 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921620 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921656 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:01.921702 2026] [lsapi:warn] [pid 229246:tid 229466] [client 43.134.3.111:38522] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: http://atacadomaster.com
[Tue Jul 21 07:20:02.046682 2026] [security2:error] [pid 230252:tid 230507] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ctex1.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4twAAAxQ"]
[Tue Jul 21 07:20:02.112352 2026] [security2:error] [pid 230252:tid 230397] [client 45.251.232.145:61134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4uAAAAqY"]
[Tue Jul 21 07:20:02.112501 2026] [security2:error] [pid 230252:tid 230397] [client 45.251.232.145:61134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4uAAAAqY"]
[Tue Jul 21 07:20:02.223268 2026] [security2:error] [pid 230252:tid 230394] [client 20.197.192.193:6880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/pn.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4uwAAAqM"]
[Tue Jul 21 07:20:02.335280 2026] [security2:error] [pid 230252:tid 230449] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/edorxrr.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4vAAAAto"]
[Tue Jul 21 07:20:02.386937 2026] [security2:error] [pid 230252:tid 230454] [client 68.235.38.2:34236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4vQAAAt8"]
[Tue Jul 21 07:20:02.387080 2026] [security2:error] [pid 230252:tid 230454] [client 68.235.38.2:34236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4vQAAAt8"]
[Tue Jul 21 07:20:02.387331 2026] [security2:error] [pid 229246:tid 229368] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H0iBMYeh5YLVG45xd_QACSHk"]
[Tue Jul 21 07:20:02.387623 2026] [security2:error] [pid 229246:tid 229428] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H0iBMYeh5YLVG45xd_QACSHk"]
[Tue Jul 21 07:20:02.494937 2026] [security2:error] [pid 229246:tid 229387] [client 20.151.10.161:45999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-temp.php"] [unique_id "al9H0iBMYeh5YLVG45xd_gAAAh8"]
[Tue Jul 21 07:20:02.526355 2026] [security2:error] [pid 230252:tid 230447] [client 193.36.225.61:34387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4wQAAAtg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:02.615977 2026] [security2:error] [pid 230252:tid 230422] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/miru1.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4wwAAAr8"]
[Tue Jul 21 07:20:02.627067 2026] [security2:error] [pid 230252:tid 230437] [client 74.249.245.134:34451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xda.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4xAAAAs4"]
[Tue Jul 21 07:20:02.636093 2026] [security2:error] [pid 230252:tid 230424] [client 20.151.10.161:53618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/koala.php"] [unique_id "al9H0k0Dwhk5-Z44Xro4xgAAAsE"]
[Tue Jul 21 07:20:03.016412 2026] [security2:error] [pid 230252:tid 230419] [client 4.204.201.85:43994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/about.php"] [unique_id "al9H000Dwhk5-Z44Xro4ywAAArw"]
[Tue Jul 21 07:20:03.515188 2026] [security2:error] [pid 229246:tid 229381] [client 4.204.201.85:43941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/admin.php"] [unique_id "al9H0yBMYeh5YLVG45xeDQAAAhk"]
[Tue Jul 21 07:20:03.665521 2026] [security2:error] [pid 229246:tid 229404] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/sump1.php"] [unique_id "al9H0yBMYeh5YLVG45xeEAAAAjA"]
[Tue Jul 21 07:20:03.718982 2026] [http2:warn] [pid 229246:tid 229442] [client 57.141.18.103:36488] h2_stream(229246-31-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:03.731975 2026] [autoindex:error] [pid 230252:tid 230502] [client 43.130.32.245:47032] AH01276: Cannot serve directory /home1/leon6484/lumevisual.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:20:03.770416 2026] [security2:error] [pid 230252:tid 230428] [client 20.197.192.193:6862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9H000Dwhk5-Z44Xro40gAAAsU"]
[Tue Jul 21 07:20:03.909832 2026] [security2:error] [pid 229246:tid 229269] [remote 159.223.116.62:60552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.116.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carrosselbuique.com.br"] [uri "/wp-login.php"] [unique_id "al9H0yBMYeh5YLVG45xeFAACVRY"]
[Tue Jul 21 07:20:03.949448 2026] [security2:error] [pid 229246:tid 229392] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/file5.php"] [unique_id "al9H0yBMYeh5YLVG45xeFQAAAiQ"]
[Tue Jul 21 07:20:03.965779 2026] [security2:error] [pid 230252:tid 230349] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H000Dwhk5-Z44Xro41AAC_F4"]
[Tue Jul 21 07:20:03.965933 2026] [security2:error] [pid 230252:tid 230483] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H000Dwhk5-Z44Xro41AAC_F4"]
[Tue Jul 21 07:20:04.018403 2026] [security2:error] [pid 230252:tid 230395] [client 4.204.201.85:43932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/admin.php"] [unique_id "al9H1E0Dwhk5-Z44Xro41QAAAqQ"]
[Tue Jul 21 07:20:04.259330 2026] [security2:error] [pid 229246:tid 229385] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/0xD.php"] [unique_id "al9H1CBMYeh5YLVG45xeGgAAAh0"]
[Tue Jul 21 07:20:04.465277 2026] [security2:error] [pid 229246:tid 229415] [client 139.135.44.145:54203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H1CBMYeh5YLVG45xeGwAAAjs"]
[Tue Jul 21 07:20:04.465428 2026] [security2:error] [pid 229246:tid 229415] [client 139.135.44.145:54203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H1CBMYeh5YLVG45xeGwAAAjs"]
[Tue Jul 21 07:20:04.521098 2026] [security2:error] [pid 230252:tid 230486] [client 4.204.201.85:43976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/themes.php"] [unique_id "al9H1E0Dwhk5-Z44Xro42AAAAv8"]
[Tue Jul 21 07:20:04.585413 2026] [security2:error] [pid 230252:tid 230473] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/fnstall.php"] [unique_id "al9H1E0Dwhk5-Z44Xro42QAAAvI"]
[Tue Jul 21 07:20:04.652628 2026] [security2:error] [pid 229246:tid 229393] [client 117.222.76.61:62400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.76.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gradiente.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1CBMYeh5YLVG45xeHgAAAiU"]
[Tue Jul 21 07:20:04.652771 2026] [security2:error] [pid 229246:tid 229393] [client 117.222.76.61:62400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gradiente.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1CBMYeh5YLVG45xeHgAAAiU"]
[Tue Jul 21 07:20:04.851645 2026] [security2:error] [pid 230252:tid 230394] [client 74.249.245.134:50996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/shell.php"] [unique_id "al9H1E0Dwhk5-Z44Xro43QAAAqM"]
[Tue Jul 21 07:20:04.887279 2026] [security2:error] [pid 230252:tid 230406] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/acp.php"] [unique_id "al9H1E0Dwhk5-Z44Xro43wAAAq8"]
[Tue Jul 21 07:20:05.004395 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:45888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9H1SBMYeh5YLVG45xeJAAAAlo"]
[Tue Jul 21 07:20:05.173064 2026] [security2:error] [pid 229246:tid 229467] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/mosty.php"] [unique_id "al9H1SBMYeh5YLVG45xeKAAAAm8"]
[Tue Jul 21 07:20:05.191395 2026] [security2:error] [pid 230252:tid 230472] [client 184.75.221.3:39206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9H1U0Dwhk5-Z44Xro44AAAAvE"]
[Tue Jul 21 07:20:05.191501 2026] [security2:error] [pid 230252:tid 230472] [client 184.75.221.3:39206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9H1U0Dwhk5-Z44Xro44AAAAvE"]
[Tue Jul 21 07:20:05.322866 2026] [security2:error] [pid 229246:tid 229431] [client 74.244.195.153:36225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9H1SBMYeh5YLVG45xeLAAAAks"]
[Tue Jul 21 07:20:05.323002 2026] [security2:error] [pid 229246:tid 229431] [client 74.244.195.153:36225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9H1SBMYeh5YLVG45xeLAAAAks"]
[Tue Jul 21 07:20:05.329569 2026] [security2:error] [pid 229246:tid 229410] [client 20.197.192.193:6398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/dr.php"] [unique_id "al9H1SBMYeh5YLVG45xeLQAAAjY"]
[Tue Jul 21 07:20:05.361537 2026] [security2:error] [pid 230252:tid 230320] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1U0Dwhk5-Z44Xro44QAC30I"]
[Tue Jul 21 07:20:05.362029 2026] [security2:error] [pid 230252:tid 230454] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1U0Dwhk5-Z44Xro44QAC30I"]
[Tue Jul 21 07:20:05.400316 2026] [security2:error] [pid 230252:tid 230471] [client 175.45.70.82:65283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1U0Dwhk5-Z44Xro44gAAAvA"]
[Tue Jul 21 07:20:05.400439 2026] [security2:error] [pid 230252:tid 230471] [client 175.45.70.82:65283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1U0Dwhk5-Z44Xro44gAAAvA"]
[Tue Jul 21 07:20:05.447583 2026] [security2:error] [pid 229246:tid 229463] [client 20.226.60.151:54505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/fnstall.php"] [unique_id "al9H1SBMYeh5YLVG45xeMQAAAms"]
[Tue Jul 21 07:20:05.460001 2026] [security2:error] [pid 229246:tid 229399] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/6.php"] [unique_id "al9H1SBMYeh5YLVG45xeMgAAAis"]
[Tue Jul 21 07:20:05.460308 2026] [security2:error] [pid 229246:tid 229405] [client 134.19.179.187:46258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9H1SBMYeh5YLVG45xeMwAAAjE"]
[Tue Jul 21 07:20:05.460376 2026] [security2:error] [pid 229246:tid 229405] [client 134.19.179.187:46258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9H1SBMYeh5YLVG45xeMwAAAjE"]
[Tue Jul 21 07:20:05.501680 2026] [security2:error] [pid 229246:tid 229354] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1SBMYeh5YLVG45xeNAACVWs"]
[Tue Jul 21 07:20:05.501846 2026] [security2:error] [pid 229246:tid 229441] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1SBMYeh5YLVG45xeNAACVWs"]
[Tue Jul 21 07:20:05.765902 2026] [security2:error] [pid 229246:tid 229423] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/32e17094cfindex.php"] [unique_id "al9H1SBMYeh5YLVG45xeOgAAAkM"]
[Tue Jul 21 07:20:05.876123 2026] [security2:error] [pid 229246:tid 229477] [client 20.220.225.223:43061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/koiy.php"] [unique_id "al9H1SBMYeh5YLVG45xePQAAAnk"]
[Tue Jul 21 07:20:06.040043 2026] [security2:error] [pid 229246:tid 229419] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/qqqa.php"] [unique_id "al9H1iBMYeh5YLVG45xeQQAAAj8"]
[Tue Jul 21 07:20:06.098041 2026] [security2:error] [pid 229246:tid 229480] [client 120.61.173.56:53619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1iBMYeh5YLVG45xeQgAAAnw"]
[Tue Jul 21 07:20:06.098223 2026] [security2:error] [pid 229246:tid 229480] [client 120.61.173.56:53619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H1iBMYeh5YLVG45xeQgAAAnw"]
[Tue Jul 21 07:20:06.142605 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:6892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/2x.php"] [unique_id "al9H1iBMYeh5YLVG45xeRAAAAn0"]
[Tue Jul 21 07:20:06.232466 2026] [security2:error] [pid 229246:tid 229462] [client 20.226.60.151:61056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/acp.php"] [unique_id "al9H1iBMYeh5YLVG45xeRwAAAmo"]
[Tue Jul 21 07:20:06.307295 2026] [security2:error] [pid 230252:tid 230457] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/aunmc.php"] [unique_id "al9H1k0Dwhk5-Z44Xro45QAAAuI"]
[Tue Jul 21 07:20:06.431339 2026] [security2:error] [pid 229246:tid 229380] [client 4.204.201.85:43940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/.well-known/about.php"] [unique_id "al9H1iBMYeh5YLVG45xeTAAAAhg"]
[Tue Jul 21 07:20:06.463270 2026] [security2:error] [pid 229246:tid 229495] [client 20.226.60.151:54489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/mosty.php"] [unique_id "al9H1iBMYeh5YLVG45xeTwAAAos"]
[Tue Jul 21 07:20:06.476330 2026] [http2:warn] [pid 229246:tid 229412] [client 57.141.18.41:21028] h2_stream(229246-57-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:06.574431 2026] [security2:error] [pid 230252:tid 230487] [client 91.92.41.64:53483] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.63.69"] [uri "/.env"] [unique_id "al9H1k0Dwhk5-Z44Xro45wAAAwA"]
[Tue Jul 21 07:20:06.580628 2026] [security2:error] [pid 230252:tid 230412] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/uoocf.php"] [unique_id "al9H1k0Dwhk5-Z44Xro46AAAArU"]
[Tue Jul 21 07:20:06.714797 2026] [security2:error] [pid 230252:tid 230511] [client 74.249.245.134:21639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/3.php"] [unique_id "al9H1k0Dwhk5-Z44Xro46gAAAxg"]
[Tue Jul 21 07:20:06.864525 2026] [security2:error] [pid 230252:tid 230504] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/iywwi.php"] [unique_id "al9H1k0Dwhk5-Z44Xro47AAAAxE"]
[Tue Jul 21 07:20:07.021278 2026] [security2:error] [pid 230252:tid 230439] [client 20.151.10.161:55284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/mac.php"] [unique_id "al9H100Dwhk5-Z44Xro47gAAAtA"]
[Tue Jul 21 07:20:07.139002 2026] [security2:error] [pid 229246:tid 229398] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/gqgsa.php"] [unique_id "al9H1yBMYeh5YLVG45xeVQAAAio"]
[Tue Jul 21 07:20:07.276922 2026] [security2:error] [pid 230252:tid 230501] [client 20.197.192.193:6384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/kq1.php"] [unique_id "al9H100Dwhk5-Z44Xro48AAAAw4"]
[Tue Jul 21 07:20:07.373211 2026] [security2:error] [pid 229246:tid 229250] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H1yBMYeh5YLVG45xeWQACRwM"]
[Tue Jul 21 07:20:07.373333 2026] [security2:error] [pid 229246:tid 229427] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H1yBMYeh5YLVG45xeWQACRwM"]
[Tue Jul 21 07:20:07.407123 2026] [security2:error] [pid 229246:tid 229469] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/elbzl.php"] [unique_id "al9H1yBMYeh5YLVG45xeWgAAAnE"]
[Tue Jul 21 07:20:07.412830 2026] [security2:error] [pid 229246:tid 229403] [client 193.36.225.61:35751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9H1iBMYeh5YLVG45xeSAAAAi8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:07.607656 2026] [security2:error] [pid 229246:tid 229439] [client 20.151.10.161:46038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/puc.php"] [unique_id "al9H1yBMYeh5YLVG45xeXQAAAlM"]
[Tue Jul 21 07:20:07.619982 2026] [security2:error] [pid 229246:tid 229377] [client 4.204.201.85:43989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9H1yBMYeh5YLVG45xeXgAAAhU"]
[Tue Jul 21 07:20:07.690753 2026] [security2:error] [pid 229246:tid 229481] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/adjig.php"] [unique_id "al9H1yBMYeh5YLVG45xeYgAAAn0"]
[Tue Jul 21 07:20:07.790361 2026] [security2:error] [pid 229246:tid 229410] [client 20.197.192.193:6868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/zzz.php"] [unique_id "al9H1yBMYeh5YLVG45xeZgAAAjY"]
[Tue Jul 21 07:20:07.977492 2026] [security2:error] [pid 229246:tid 229398] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/byp.php"] [unique_id "al9H1yBMYeh5YLVG45xebwAAAio"]
[Tue Jul 21 07:20:07.991413 2026] [security2:error] [pid 229246:tid 229466] [client 20.220.225.223:39543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/hp2.php"] [unique_id "al9H1yBMYeh5YLVG45xecAAAAm4"]
[Tue Jul 21 07:20:08.124003 2026] [http2:warn] [pid 229246:tid 229437] [client 57.141.18.42:31308] h2_stream(229246-67-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:08.227326 2026] [security2:error] [pid 229246:tid 229435] [client 20.197.192.193:6366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wicked.php"] [unique_id "al9H2CBMYeh5YLVG45xecwAAAk8"]
[Tue Jul 21 07:20:08.272219 2026] [security2:error] [pid 229246:tid 229256] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H2CBMYeh5YLVG45xedgACLwk"]
[Tue Jul 21 07:20:08.272343 2026] [security2:error] [pid 229246:tid 229403] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H2CBMYeh5YLVG45xedgACLwk"]
[Tue Jul 21 07:20:08.286010 2026] [security2:error] [pid 229246:tid 229480] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ortasekerli1.php"] [unique_id "al9H2CBMYeh5YLVG45xedwAAAnw"]
[Tue Jul 21 07:20:08.375278 2026] [security2:error] [pid 229246:tid 229429] [client 134.19.179.187:44074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9H2CBMYeh5YLVG45xeewAAAkk"]
[Tue Jul 21 07:20:08.375372 2026] [security2:error] [pid 229246:tid 229429] [client 134.19.179.187:44074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9H2CBMYeh5YLVG45xeewAAAkk"]
[Tue Jul 21 07:20:08.570259 2026] [security2:error] [pid 230252:tid 230425] [client 20.220.225.223:34189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9H2E0Dwhk5-Z44Xro4-gAAAsI"]
[Tue Jul 21 07:20:08.579253 2026] [security2:error] [pid 230252:tid 230486] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/classwithtostring.php"] [unique_id "al9H2E0Dwhk5-Z44Xro4-wAAAv8"]
[Tue Jul 21 07:20:08.797865 2026] [security2:error] [pid 230252:tid 230458] [client 74.249.245.134:43448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/mds.php"] [unique_id "al9H2E0Dwhk5-Z44Xro4_QAAAuM"]
[Tue Jul 21 07:20:08.862178 2026] [security2:error] [pid 230252:tid 230433] [client 85.208.96.198:49380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivaconcierge.com.br"] [uri "/robots.txt"] [unique_id "al9H2E0Dwhk5-Z44Xro5AQAAAso"]
[Tue Jul 21 07:20:08.862315 2026] [security2:error] [pid 230252:tid 230433] [client 85.208.96.198:49380] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vivaconcierge.com.br"] [uri "/robots.txt"] [unique_id "al9H2E0Dwhk5-Z44Xro5AQAAAso"]
[Tue Jul 21 07:20:08.870692 2026] [security2:error] [pid 230252:tid 230392] [client 20.151.10.161:53596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9H2E0Dwhk5-Z44Xro5AgAAAqE"]
[Tue Jul 21 07:20:08.889221 2026] [security2:error] [pid 230252:tid 230426] [client 74.7.228.31:40322] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "tainaegiovane.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9H2E0Dwhk5-Z44Xro5AwACw04"]
[Tue Jul 21 07:20:08.901082 2026] [security2:error] [pid 230252:tid 230409] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/root.php"] [unique_id "al9H2E0Dwhk5-Z44Xro5BAAAArI"]
[Tue Jul 21 07:20:08.955781 2026] [security2:error] [pid 230252:tid 230394] [client 4.204.201.85:43848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wefile.php"] [unique_id "al9H2E0Dwhk5-Z44Xro5BQAAAqM"]
[Tue Jul 21 07:20:09.009910 2026] [security2:error] [pid 230252:tid 230503] [client 103.121.156.110:60938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H2U0Dwhk5-Z44Xro5BwAAAxA"]
[Tue Jul 21 07:20:09.010032 2026] [security2:error] [pid 230252:tid 230503] [client 103.121.156.110:60938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H2U0Dwhk5-Z44Xro5BwAAAxA"]
[Tue Jul 21 07:20:09.064054 2026] [security2:error] [pid 230252:tid 230432] [client 103.162.129.114:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H2U0Dwhk5-Z44Xro5CAAAAsk"]
[Tue Jul 21 07:20:09.064253 2026] [security2:error] [pid 230252:tid 230432] [client 103.162.129.114:59060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H2U0Dwhk5-Z44Xro5CAAAAsk"]
[Tue Jul 21 07:20:09.095908 2026] [security2:error] [pid 230252:tid 230407] [client 20.197.192.193:6393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/edit.php"] [unique_id "al9H2U0Dwhk5-Z44Xro5CQAAArA"]
[Tue Jul 21 07:20:09.210628 2026] [security2:error] [pid 229246:tid 229466] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/sym403.php"] [unique_id "al9H2SBMYeh5YLVG45xehgAAAm4"]
[Tue Jul 21 07:20:09.424634 2026] [security2:error] [pid 229246:tid 229424] [client 185.191.171.5:15098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivaconcierge.com.br"] [uri "/_detalhes/lavanderia/page/2/"] [unique_id "al9H2SBMYeh5YLVG45xeiwAAAkQ"]
[Tue Jul 21 07:20:09.424741 2026] [security2:error] [pid 229246:tid 229424] [client 185.191.171.5:15098] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vivaconcierge.com.br"] [uri "/_detalhes/lavanderia/page/2/"] [unique_id "al9H2SBMYeh5YLVG45xeiwAAAkQ"]
[Tue Jul 21 07:20:09.516256 2026] [security2:error] [pid 230252:tid 230437] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/v543.php"] [unique_id "al9H2U0Dwhk5-Z44Xro5DgAAAs4"]
[Tue Jul 21 07:20:09.808978 2026] [security2:error] [pid 229246:tid 229390] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/sixxis.php"] [unique_id "al9H2SBMYeh5YLVG45xejgAAAiI"]
[Tue Jul 21 07:20:10.125917 2026] [security2:error] [pid 230252:tid 230399] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ip.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5EwAAAqg"]
[Tue Jul 21 07:20:10.140973 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:45994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/themes.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5FAAAAwY"]
[Tue Jul 21 07:20:10.181368 2026] [core:error] [pid 229246:tid 229277] [remote 198.235.24.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:10.181397 2026] [core:error] [pid 229246:tid 229277] [remote 198.235.24.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:10.273765 2026] [security2:error] [pid 230252:tid 230439] [client 20.220.225.223:34274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5FQAAAtA"]
[Tue Jul 21 07:20:10.419434 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/kq1.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5FwAAAw4"]
[Tue Jul 21 07:20:10.517538 2026] [security2:error] [pid 230252:tid 230461] [client 20.151.10.161:55251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wefile.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5GQAAAuY"]
[Tue Jul 21 07:20:10.715722 2026] [security2:error] [pid 229246:tid 229478] [client 14.139.42.196:3048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H2iBMYeh5YLVG45xenQAAAno"]
[Tue Jul 21 07:20:10.715846 2026] [security2:error] [pid 229246:tid 229478] [client 14.139.42.196:3048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H2iBMYeh5YLVG45xenQAAAno"]
[Tue Jul 21 07:20:10.716768 2026] [security2:error] [pid 230252:tid 230428] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/fw/faiyy.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5GgAAAsU"]
[Tue Jul 21 07:20:10.749503 2026] [security2:error] [pid 230252:tid 230334] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5GwACx08"]
[Tue Jul 21 07:20:10.749643 2026] [security2:error] [pid 230252:tid 230430] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H2k0Dwhk5-Z44Xro5GwACx08"]
[Tue Jul 21 07:20:11.016547 2026] [security2:error] [pid 229246:tid 229495] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/h02ugyh.php"] [unique_id "al9H2yBMYeh5YLVG45xeowAAAos"]
[Tue Jul 21 07:20:11.028564 2026] [security2:error] [pid 229246:tid 229503] [client 74.249.245.134:56111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/archive.php"] [unique_id "al9H2yBMYeh5YLVG45xepAAAApM"]
[Tue Jul 21 07:20:11.204954 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.192.193:6897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/kua.php"] [unique_id "al9H2yBMYeh5YLVG45xeqQAAAjI"]
[Tue Jul 21 07:20:11.208666 2026] [security2:error] [pid 230252:tid 230510] [client 4.204.201.85:44020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9H200Dwhk5-Z44Xro5HgAAAxc"]
[Tue Jul 21 07:20:11.298929 2026] [security2:error] [pid 230252:tid 230410] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-temp.php"] [unique_id "al9H200Dwhk5-Z44Xro5HwAAArM"]
[Tue Jul 21 07:20:11.513866 2026] [security2:error] [pid 229246:tid 229344] [remote 45.79.123.44:56894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "murilomattos.com"] [uri "/wp-login.php"] [unique_id "al9H2yBMYeh5YLVG45xergACHWE"]
[Tue Jul 21 07:20:11.580423 2026] [security2:error] [pid 230252:tid 230397] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-content/cong.php"] [unique_id "al9H200Dwhk5-Z44Xro5IwAAAqY"]
[Tue Jul 21 07:20:11.609315 2026] [security2:error] [pid 229246:tid 229354] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelalves1781880029279.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H2yBMYeh5YLVG45xesQACe2s"]
[Tue Jul 21 07:20:11.659634 2026] [security2:error] [pid 230252:tid 230507] [client 20.151.10.161:53603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9H200Dwhk5-Z44Xro5JQAAAxQ"]
[Tue Jul 21 07:20:11.832246 2026] [security2:error] [pid 230252:tid 230508] [client 193.36.225.65:61021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9H200Dwhk5-Z44Xro5JwAAAxU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:12.095765 2026] [security2:error] [pid 230252:tid 230503] [client 20.197.192.193:6885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/ez.php"] [unique_id "al9H3E0Dwhk5-Z44Xro5KwAAAxA"]
[Tue Jul 21 07:20:12.198743 2026] [security2:error] [pid 230252:tid 230407] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelalves1781880029279.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H3E0Dwhk5-Z44Xro5LAAAArA"]
[Tue Jul 21 07:20:12.384888 2026] [security2:error] [pid 230252:tid 230347] [remote 57.141.18.26:27804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemaph.xml"] [unique_id "al9H3E0Dwhk5-Z44Xro5LQAC11w"]
[Tue Jul 21 07:20:12.592517 2026] [security2:error] [pid 230252:tid 230426] [client 45.251.232.145:61649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H3E0Dwhk5-Z44Xro5MgAAAsM"]
[Tue Jul 21 07:20:12.592636 2026] [security2:error] [pid 230252:tid 230426] [client 45.251.232.145:61649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H3E0Dwhk5-Z44Xro5MgAAAsM"]
[Tue Jul 21 07:20:12.601898 2026] [qos:error] [pid 230252:tid 230330] [remote 74.7.227.54:57656] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=74.7.227.54, id=al9H3E0Dwhk5-Z44Xro5MwACzks, referer: https://arielson.com.br/coursos/?duration=extraLong%2Cmedium&filter_course-category=397&filter_course-tag=134%2C455%2C454%2C249%2C130&filtering=1&orderby=newest_first&price_type=paid&rating_filter=5
[Tue Jul 21 07:20:12.946747 2026] [security2:error] [pid 230252:tid 230354] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H3E0Dwhk5-Z44Xro5NgADCmM"]
[Tue Jul 21 07:20:12.946936 2026] [security2:error] [pid 230252:tid 230497] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H3E0Dwhk5-Z44Xro5NgADCmM"]
[Tue Jul 21 07:20:12.952343 2026] [security2:error] [pid 229246:tid 229356] [remote 165.227.132.137:37770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.132.227.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caminhoneiro.giovanoniadv.com.br"] [uri "/wp-login.php"] [unique_id "al9H3CBMYeh5YLVG45xevgACTG0"]
[Tue Jul 21 07:20:13.026988 2026] [security2:error] [pid 230252:tid 230465] [client 20.151.10.161:46001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/dx.php"] [unique_id "al9H3U0Dwhk5-Z44Xro5OAAAAuo"]
[Tue Jul 21 07:20:13.138990 2026] [security2:error] [pid 230252:tid 230399] [client 74.249.245.134:61472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/amax.php"] [unique_id "al9H3U0Dwhk5-Z44Xro5PQAAAqg"]
[Tue Jul 21 07:20:13.207431 2026] [security2:error] [pid 230252:tid 230391] [client 20.151.10.161:53570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/2P.php"] [unique_id "al9H3U0Dwhk5-Z44Xro5PwAAAqA"]
[Tue Jul 21 07:20:13.523835 2026] [security2:error] [pid 229246:tid 229310] [remote 45.150.79.142:55472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wp-login.php"] [unique_id "al9H3SBMYeh5YLVG45xeyQACST8"]
[Tue Jul 21 07:20:14.192128 2026] [security2:error] [pid 230252:tid 230352] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelalves1781880029279.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H3k0Dwhk5-Z44Xro5RgACs2E"]
[Tue Jul 21 07:20:14.606807 2026] [security2:error] [pid 230252:tid 230397] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelalves1781880029279.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H3k0Dwhk5-Z44Xro5TAAAAqY"]
[Tue Jul 21 07:20:14.738918 2026] [security2:error] [pid 230252:tid 230366] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H3k0Dwhk5-Z44Xro5TgACzW8"]
[Tue Jul 21 07:20:14.739075 2026] [security2:error] [pid 230252:tid 230436] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H3k0Dwhk5-Z44Xro5TgACzW8"]
[Tue Jul 21 07:20:14.794987 2026] [security2:error] [pid 230252:tid 230464] [client 134.19.179.187:53014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9H3k0Dwhk5-Z44Xro5UQAAAuk"]
[Tue Jul 21 07:20:14.795064 2026] [security2:error] [pid 230252:tid 230464] [client 134.19.179.187:53014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9H3k0Dwhk5-Z44Xro5UQAAAuk"]
[Tue Jul 21 07:20:15.017636 2026] [security2:error] [pid 230252:tid 230411] [client 20.226.60.151:54553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/6.php"] [unique_id "al9H300Dwhk5-Z44Xro5VAAAArQ"]
[Tue Jul 21 07:20:15.028622 2026] [security2:error] [pid 230252:tid 230369] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sbbarrosadvocacia.com.br"] [uri "/wp-admin/install.php"] [unique_id "al9H300Dwhk5-Z44Xro5VQADCHI"]
[Tue Jul 21 07:20:15.032642 2026] [http2:warn] [pid 229246:tid 229394] [client 57.141.18.97:24286] h2_stream(229246-97-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:15.065549 2026] [security2:error] [pid 229246:tid 229441] [client 139.135.44.145:53168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H3yBMYeh5YLVG45xe2QAAAlU"]
[Tue Jul 21 07:20:15.065656 2026] [security2:error] [pid 229246:tid 229441] [client 139.135.44.145:53168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H3yBMYeh5YLVG45xe2QAAAlU"]
[Tue Jul 21 07:20:15.089415 2026] [security2:error] [pid 230252:tid 230418] [client 4.204.201.85:43996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9H300Dwhk5-Z44Xro5VgAAArs"]
[Tue Jul 21 07:20:15.181702 2026] [security2:error] [pid 229246:tid 229424] [client 20.151.10.161:12035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/.well-known/about.php"] [unique_id "al9H3yBMYeh5YLVG45xe3AAAAkQ"]
[Tue Jul 21 07:20:15.224221 2026] [security2:error] [pid 230252:tid 230351] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sbbarrosadvocacia.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9H300Dwhk5-Z44Xro5WgAC9WA"]
[Tue Jul 21 07:20:15.530317 2026] [security2:error] [pid 230252:tid 230497] [client 20.151.10.161:46004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/p.php"] [unique_id "al9H300Dwhk5-Z44Xro5XQAAAwo"]
[Tue Jul 21 07:20:15.823196 2026] [security2:error] [pid 230252:tid 230429] [client 20.151.10.161:53582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9H300Dwhk5-Z44Xro5YQAAAsY"]
[Tue Jul 21 07:20:15.917190 2026] [security2:error] [pid 230252:tid 230371] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H300Dwhk5-Z44Xro5YgACtXQ"]
[Tue Jul 21 07:20:15.917312 2026] [security2:error] [pid 230252:tid 230412] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H300Dwhk5-Z44Xro5YgACtXQ"]
[Tue Jul 21 07:20:16.059034 2026] [security2:error] [pid 230252:tid 230447] [client 175.45.70.82:49385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4E0Dwhk5-Z44Xro5ZAAAAtg"]
[Tue Jul 21 07:20:16.059171 2026] [security2:error] [pid 230252:tid 230447] [client 175.45.70.82:49385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4E0Dwhk5-Z44Xro5ZAAAAtg"]
[Tue Jul 21 07:20:16.074862 2026] [security2:error] [pid 229246:tid 229435] [client 92.119.178.3:58902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9H4CBMYeh5YLVG45xe5gAAAk8"]
[Tue Jul 21 07:20:16.074959 2026] [security2:error] [pid 229246:tid 229435] [client 92.119.178.3:58902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9H4CBMYeh5YLVG45xe5gAAAk8"]
[Tue Jul 21 07:20:16.087491 2026] [security2:error] [pid 230252:tid 230373] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4E0Dwhk5-Z44Xro5ZgACqHY"]
[Tue Jul 21 07:20:16.087612 2026] [security2:error] [pid 230252:tid 230399] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4E0Dwhk5-Z44Xro5ZgACqHY"]
[Tue Jul 21 07:20:16.124257 2026] [security2:error] [pid 230252:tid 230462] [client 74.244.195.153:17850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9H4E0Dwhk5-Z44Xro5ZwAAAuc"]
[Tue Jul 21 07:20:16.129176 2026] [security2:error] [pid 230252:tid 230462] [client 74.244.195.153:17850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9H4E0Dwhk5-Z44Xro5ZwAAAuc"]
[Tue Jul 21 07:20:16.177118 2026] [http2:warn] [pid 229246:tid 229376] [client 57.141.18.0:35978] h2_stream(229246-101-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:16.357771 2026] [security2:error] [pid 229246:tid 229407] [client 172.245.102.42:49889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9H4CBMYeh5YLVG45xe6AAAAjM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:16.473827 2026] [security2:error] [pid 229246:tid 229397] [client 20.151.10.161:55247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/bob.php"] [unique_id "al9H4CBMYeh5YLVG45xe6gAAAik"]
[Tue Jul 21 07:20:16.575041 2026] [security2:error] [pid 229246:tid 229463] [client 4.204.201.85:43844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/8.php"] [unique_id "al9H4CBMYeh5YLVG45xe7AAAAms"]
[Tue Jul 21 07:20:16.602464 2026] [security2:error] [pid 230252:tid 230486] [client 20.197.192.193:6872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/fz.php"] [unique_id "al9H4E0Dwhk5-Z44Xro5bgAAAv8"]
[Tue Jul 21 07:20:16.622335 2026] [security2:error] [pid 230252:tid 230491] [client 91.92.41.64:58914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.63.69"] [uri "/.env"] [unique_id "al9H4E0Dwhk5-Z44Xro5bwAAAwQ"]
[Tue Jul 21 07:20:16.694810 2026] [security2:error] [pid 229246:tid 229438] [client 74.249.245.134:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/moon.php"] [unique_id "al9H4CBMYeh5YLVG45xe7wAAAlI"]
[Tue Jul 21 07:20:16.812965 2026] [security2:error] [pid 229246:tid 229462] [client 120.61.173.56:54123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4CBMYeh5YLVG45xe8QAAAmo"]
[Tue Jul 21 07:20:16.813101 2026] [security2:error] [pid 229246:tid 229462] [client 120.61.173.56:54123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4CBMYeh5YLVG45xe8QAAAmo"]
[Tue Jul 21 07:20:17.134789 2026] [http2:warn] [pid 229246:tid 229485] [client 57.141.18.3:20152] h2_stream(229246-108-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:17.173287 2026] [http2:warn] [pid 229246:tid 229473] [client 57.141.18.98:33432] h2_stream(229246-110-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:17.192009 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:47827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5dgAAAto"]
[Tue Jul 21 07:20:17.218323 2026] [security2:error] [pid 229246:tid 229432] [client 20.151.10.161:46057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/bthil.php"] [unique_id "al9H4SBMYeh5YLVG45xe-QAAAkw"]
[Tue Jul 21 07:20:17.501522 2026] [security2:error] [pid 230252:tid 230372] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4U0Dwhk5-Z44Xro5fQADDXU"]
[Tue Jul 21 07:20:17.510344 2026] [security2:error] [pid 230252:tid 230294] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091656000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4U0Dwhk5-Z44Xro5fgADAig"]
[Tue Jul 21 07:20:17.512737 2026] [security2:error] [pid 230252:tid 230268] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091746000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4U0Dwhk5-Z44Xro5fwACvw4"]
[Tue Jul 21 07:20:17.534863 2026] [security2:error] [pid 230252:tid 230457] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091746000.samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4U0Dwhk5-Z44Xro5gQAAAuI"]
[Tue Jul 21 07:20:17.554746 2026] [security2:error] [pid 230252:tid 230473] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091656000.samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4U0Dwhk5-Z44Xro5ggAAAvI"]
[Tue Jul 21 07:20:17.631223 2026] [security2:error] [pid 230252:tid 230400] [client 134.19.179.187:44108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5hQAAAqk"]
[Tue Jul 21 07:20:17.631326 2026] [security2:error] [pid 230252:tid 230400] [client 134.19.179.187:44108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5hQAAAqk"]
[Tue Jul 21 07:20:17.638590 2026] [core:error] [pid 230252:tid 230274] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:17.638604 2026] [core:error] [pid 230252:tid 230274] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:17.701621 2026] [security2:error] [pid 230252:tid 230429] [client 4.204.201.85:44014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5hwAAAsY"]
[Tue Jul 21 07:20:17.757584 2026] [security2:error] [pid 230252:tid 230439] [client 20.151.10.161:55287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/crgio.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5iAAAAtA"]
[Tue Jul 21 07:20:17.761637 2026] [core:error] [pid 230252:tid 230282] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:17.761654 2026] [core:error] [pid 230252:tid 230282] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:17.821935 2026] [security2:error] [pid 230252:tid 230467] [client 34.86.210.0:55487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.210.86.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5jQAAAuw"]
[Tue Jul 21 07:20:17.822012 2026] [security2:error] [pid 230252:tid 230467] [client 34.86.210.0:55487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5jQAAAuw"]
[Tue Jul 21 07:20:17.884732 2026] [core:error] [pid 230252:tid 230376] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:17.884753 2026] [core:error] [pid 230252:tid 230376] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:17.956904 2026] [security2:error] [pid 230252:tid 230264] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5kQADBgo"]
[Tue Jul 21 07:20:17.957026 2026] [security2:error] [pid 230252:tid 230493] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H4U0Dwhk5-Z44Xro5kQADBgo"]
[Tue Jul 21 07:20:18.003998 2026] [security2:error] [pid 230252:tid 230414] [client 20.197.192.193:6851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/la.php"] [unique_id "al9H4k0Dwhk5-Z44Xro5kgAAArc"]
[Tue Jul 21 07:20:18.014072 2026] [core:error] [pid 230252:tid 230275] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:18.014090 2026] [core:error] [pid 230252:tid 230275] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:18.136406 2026] [security2:error] [pid 230252:tid 230425] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4k0Dwhk5-Z44Xro5lAAAAsI"]
[Tue Jul 21 07:20:18.142443 2026] [security2:error] [pid 229246:tid 229479] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091656000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4iBMYeh5YLVG45xfAwAAAns"]
[Tue Jul 21 07:20:18.143289 2026] [security2:error] [pid 230252:tid 230434] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091746000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H4k0Dwhk5-Z44Xro5lQAAAss"]
[Tue Jul 21 07:20:18.222646 2026] [security2:error] [pid 230252:tid 230458] [client 4.204.201.85:44013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/f6.php"] [unique_id "al9H4k0Dwhk5-Z44Xro5lwAAAuM"]
[Tue Jul 21 07:20:18.319479 2026] [core:error] [pid 230252:tid 230288] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:18.319499 2026] [core:error] [pid 230252:tid 230288] [remote 40.77.167.49:64096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:18.458065 2026] [security2:error] [pid 229246:tid 229441] [client 136.144.42.184:36115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9H4iBMYeh5YLVG45xfBwAAAlU"]
[Tue Jul 21 07:20:18.476700 2026] [security2:error] [pid 229246:tid 229437] [client 20.151.10.161:55280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/pucci.php"] [unique_id "al9H4iBMYeh5YLVG45xfCQAAAlE"]
[Tue Jul 21 07:20:18.618030 2026] [security2:error] [pid 230252:tid 230508] [client 136.144.42.186:37295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9H4k0Dwhk5-Z44Xro5nwAAAxU"]
[Tue Jul 21 07:20:18.708149 2026] [http2:warn] [pid 229246:tid 229411] [client 57.141.18.13:24102] h2_stream(229246-116-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:18.867934 2026] [security2:error] [pid 229246:tid 229296] [remote 119.195.102.159:35976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9H4iBMYeh5YLVG45xfGAACTzE"]
[Tue Jul 21 07:20:18.979499 2026] [security2:error] [pid 229246:tid 229394] [client 4.204.201.85:44022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/inputs.php"] [unique_id "al9H4iBMYeh5YLVG45xfGwAAAiY"]
[Tue Jul 21 07:20:19.010473 2026] [security2:error] [pid 229246:tid 229422] [client 20.151.10.161:45894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/7.php"] [unique_id "al9H4yBMYeh5YLVG45xfHAAAAkI"]
[Tue Jul 21 07:20:19.069185 2026] [security2:error] [pid 230252:tid 230400] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091656000.samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H400Dwhk5-Z44Xro5owAAAqk"]
[Tue Jul 21 07:20:19.090764 2026] [security2:error] [pid 230252:tid 230416] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091746000.samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H400Dwhk5-Z44Xro5pAAAArk"]
[Tue Jul 21 07:20:19.119556 2026] [security2:error] [pid 229246:tid 229470] [client 20.151.10.161:55236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-temp.php"] [unique_id "al9H4yBMYeh5YLVG45xfHgAAAnI"]
[Tue Jul 21 07:20:19.402960 2026] [security2:error] [pid 229246:tid 229454] [client 20.197.192.193:6338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9H4yBMYeh5YLVG45xfJQAAAmI"]
[Tue Jul 21 07:20:19.455088 2026] [security2:error] [pid 229246:tid 229412] [client 185.251.19.66:23079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9H4iBMYeh5YLVG45xfCAAAAjg"]
[Tue Jul 21 07:20:19.464997 2026] [security2:error] [pid 230252:tid 230465] [client 4.204.201.85:43980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/inputs.php"] [unique_id "al9H400Dwhk5-Z44Xro5pQAAAuo"]
[Tue Jul 21 07:20:19.670036 2026] [security2:error] [pid 229246:tid 229398] [client 103.121.156.110:61262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H4yBMYeh5YLVG45xfKAAAAio"]
[Tue Jul 21 07:20:19.670205 2026] [security2:error] [pid 229246:tid 229398] [client 103.121.156.110:61262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H4yBMYeh5YLVG45xfKAAAAio"]
[Tue Jul 21 07:20:19.751810 2026] [security2:error] [pid 229246:tid 229319] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H4yBMYeh5YLVG45xfKQACVUg"]
[Tue Jul 21 07:20:19.751990 2026] [security2:error] [pid 229246:tid 229441] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H4yBMYeh5YLVG45xfKQACVUg"]
[Tue Jul 21 07:20:19.770121 2026] [core:error] [pid 230252:tid 230406] [client 47.252.16.44:42048] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Tue Jul 21 07:20:19.825682 2026] [security2:error] [pid 230252:tid 230481] [client 20.151.10.161:55268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9H400Dwhk5-Z44Xro5qQAAAvo"]
[Tue Jul 21 07:20:19.900867 2026] [security2:error] [pid 229246:tid 229503] [client 4.204.201.85:43982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/classwithtostring.php"] [unique_id "al9H4yBMYeh5YLVG45xfMwAAApM"]
[Tue Jul 21 07:20:20.098763 2026] [security2:error] [pid 230252:tid 230310] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091746000.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H5E0Dwhk5-Z44Xro5qgADDzg"]
[Tue Jul 21 07:20:20.169996 2026] [security2:error] [pid 229246:tid 229381] [client 103.162.129.114:59562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H5CBMYeh5YLVG45xfNwAAAhk"]
[Tue Jul 21 07:20:20.170116 2026] [security2:error] [pid 229246:tid 229381] [client 103.162.129.114:59562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H5CBMYeh5YLVG45xfNwAAAhk"]
[Tue Jul 21 07:20:20.198228 2026] [security2:error] [pid 229246:tid 229364] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091656000.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H5CBMYeh5YLVG45xfOgACRHU"]
[Tue Jul 21 07:20:20.199170 2026] [security2:error] [pid 229246:tid 229380] [client 114.119.157.43:64877] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "madeireirapiske.com.br"] [uri "/catalogo/p9"] [unique_id "al9H5CBMYeh5YLVG45xfOwAAAhg"], referer: https://madeireirapiske.com.br/catalogo/p9
[Tue Jul 21 07:20:20.263751 2026] [security2:error] [pid 230252:tid 230254] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H5E0Dwhk5-Z44Xro5qwACrQA"]
[Tue Jul 21 07:20:20.351274 2026] [http2:warn] [pid 229246:tid 229421] [client 57.141.18.111:48642] h2_stream(229246-121-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:20.351666 2026] [security2:error] [pid 229246:tid 229480] [client 20.151.10.161:53598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/puc.php"] [unique_id "al9H5CBMYeh5YLVG45xfPQAAAnw"]
[Tue Jul 21 07:20:20.506428 2026] [security2:error] [pid 230252:tid 230486] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091746000.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H5E0Dwhk5-Z44Xro5rgAAAv8"]
[Tue Jul 21 07:20:20.663803 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-includes/css/index.php"] [unique_id "al9H5E0Dwhk5-Z44Xro5rwAAAsI"]
[Tue Jul 21 07:20:20.672882 2026] [security2:error] [pid 229246:tid 229441] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782091656000.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H5CBMYeh5YLVG45xfRwAAAlU"]
[Tue Jul 21 07:20:20.703748 2026] [security2:error] [pid 230252:tid 230434] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelgoncalvesdesou1782090694588.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H5E0Dwhk5-Z44Xro5sAAAAss"]
[Tue Jul 21 07:20:20.841521 2026] [http2:warn] [pid 229246:tid 229383] [client 57.141.18.103:43206] h2_stream(229246-124-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:20.890349 2026] [security2:error] [pid 229246:tid 229388] [client 20.197.192.193:27135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/wpx.php"] [unique_id "al9H5CBMYeh5YLVG45xfSQAAAiA"]
[Tue Jul 21 07:20:20.918494 2026] [security2:error] [pid 229246:tid 229392] [client 193.36.225.65:28591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9H5CBMYeh5YLVG45xfSgAAAiQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:20.943972 2026] [security2:error] [pid 229246:tid 229415] [client 4.204.201.85:43913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9H5CBMYeh5YLVG45xfTQAAAjs"]
[Tue Jul 21 07:20:20.950441 2026] [security2:error] [pid 229246:tid 229496] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/jj.php"] [unique_id "al9H5CBMYeh5YLVG45xfTwAAAow"]
[Tue Jul 21 07:20:21.125195 2026] [security2:error] [pid 229246:tid 229411] [client 20.197.192.193:6896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/inso.php"] [unique_id "al9H5SBMYeh5YLVG45xfUQAAAjc"]
[Tue Jul 21 07:20:21.264050 2026] [security2:error] [pid 230252:tid 230389] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/class-walker-footer-dev.php"] [unique_id "al9H5U0Dwhk5-Z44Xro5twAAAp4"]
[Tue Jul 21 07:20:21.324463 2026] [security2:error] [pid 229246:tid 229365] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H5SBMYeh5YLVG45xfWQACWnY"]
[Tue Jul 21 07:20:21.324506 2026] [security2:error] [pid 230252:tid 230508] [client 35.219.104.147:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "al9H5U0Dwhk5-Z44Xro5uQAAAxU"]
[Tue Jul 21 07:20:21.324616 2026] [security2:error] [pid 229246:tid 229446] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H5SBMYeh5YLVG45xfWQACWnY"]
[Tue Jul 21 07:20:21.335202 2026] [security2:error] [pid 229246:tid 229426] [client 35.219.104.147:45330] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9H5SBMYeh5YLVG45xfVgAAAkY"]
[Tue Jul 21 07:20:21.523557 2026] [security2:error] [pid 229246:tid 229414] [client 4.204.201.85:43988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-blog.php"] [unique_id "al9H5SBMYeh5YLVG45xfYQAAAjo"]
[Tue Jul 21 07:20:21.569877 2026] [security2:error] [pid 230252:tid 230466] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/txets.php"] [unique_id "al9H5U0Dwhk5-Z44Xro5vwAAAus"]
[Tue Jul 21 07:20:21.638342 2026] [security2:error] [pid 230252:tid 230497] [client 20.151.10.161:12081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/themes.php"] [unique_id "al9H5U0Dwhk5-Z44Xro5wQAAAwo"]
[Tue Jul 21 07:20:21.688792 2026] [security2:error] [pid 230252:tid 230406] [client 35.219.104.147:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "al9H5U0Dwhk5-Z44Xro5xAAAAq8"]
[Tue Jul 21 07:20:21.689282 2026] [security2:error] [pid 230252:tid 230451] [client 35.219.104.147:45334] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9H5U0Dwhk5-Z44Xro5wgAAAtw"]
[Tue Jul 21 07:20:21.717591 2026] [security2:error] [pid 230252:tid 230454] [client 14.139.42.196:22082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H5U0Dwhk5-Z44Xro5xQAAAt8"]
[Tue Jul 21 07:20:21.717685 2026] [security2:error] [pid 230252:tid 230454] [client 14.139.42.196:22082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H5U0Dwhk5-Z44Xro5xQAAAt8"]
[Tue Jul 21 07:20:21.851967 2026] [security2:error] [pid 229246:tid 229432] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/dex.php"] [unique_id "al9H5SBMYeh5YLVG45xfZAAAAkw"]
[Tue Jul 21 07:20:21.950899 2026] [security2:error] [pid 229246:tid 229410] [client 20.197.192.193:6392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wpx.php"] [unique_id "al9H5SBMYeh5YLVG45xfZQAAAjY"]
[Tue Jul 21 07:20:22.133659 2026] [security2:error] [pid 230252:tid 230428] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/xpwer1.php"] [unique_id "al9H5k0Dwhk5-Z44Xro5yQAAAsU"]
[Tue Jul 21 07:20:22.275266 2026] [security2:error] [pid 230252:tid 230510] [client 20.151.10.161:45892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/8.php"] [unique_id "al9H5k0Dwhk5-Z44Xro5ywAAAxc"]
[Tue Jul 21 07:20:22.429200 2026] [security2:error] [pid 229246:tid 229405] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/flox.php"] [unique_id "al9H5iBMYeh5YLVG45xfbAAAAjE"]
[Tue Jul 21 07:20:22.433820 2026] [http2:warn] [pid 229246:tid 229455] [client 57.141.18.87:45288] h2_stream(229246-131-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:22.720050 2026] [security2:error] [pid 230252:tid 230395] [client 20.220.225.223:59511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9H5k0Dwhk5-Z44Xro5zwAAAqQ"]
[Tue Jul 21 07:20:22.720933 2026] [security2:error] [pid 229246:tid 229477] [client 4.204.201.85:43987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9H5iBMYeh5YLVG45xfcgAAAnk"]
[Tue Jul 21 07:20:22.721659 2026] [security2:error] [pid 230252:tid 230486] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/popo.php"] [unique_id "al9H5k0Dwhk5-Z44Xro50AAAAv8"]
[Tue Jul 21 07:20:22.928074 2026] [http2:warn] [pid 229246:tid 229449] [client 57.141.18.13:21514] h2_stream(229246-132-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:23.035712 2026] [security2:error] [pid 230252:tid 230401] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/yas.php"] [unique_id "al9H500Dwhk5-Z44Xro50gAAAqo"]
[Tue Jul 21 07:20:23.056944 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:55238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/dx.php"] [unique_id "al9H500Dwhk5-Z44Xro50wAAAtE"]
[Tue Jul 21 07:20:23.060547 2026] [security2:error] [pid 229246:tid 229388] [client 45.251.232.145:62173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H5yBMYeh5YLVG45xfdQAAAiA"]
[Tue Jul 21 07:20:23.060660 2026] [security2:error] [pid 229246:tid 229388] [client 45.251.232.145:62173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H5yBMYeh5YLVG45xfdQAAAiA"]
[Tue Jul 21 07:20:23.268615 2026] [http2:warn] [pid 229246:tid 229456] [client 57.141.18.96:32164] h2_stream(229246-134-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:23.318165 2026] [security2:error] [pid 230252:tid 230407] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/file61.php"] [unique_id "al9H500Dwhk5-Z44Xro51gAAArA"]
[Tue Jul 21 07:20:23.331240 2026] [security2:error] [pid 230252:tid 230508] [client 4.204.201.85:43845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ms-edit.php"] [unique_id "al9H500Dwhk5-Z44Xro51wAAAxU"]
[Tue Jul 21 07:20:23.336059 2026] [security2:error] [pid 230252:tid 230500] [client 20.197.192.193:27097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/berlin.php"] [unique_id "al9H500Dwhk5-Z44Xro52AAAAw0"]
[Tue Jul 21 07:20:23.408475 2026] [security2:error] [pid 229246:tid 229381] [client 20.197.192.193:6395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/berlin.php"] [unique_id "al9H5yBMYeh5YLVG45xfeQAAAhk"]
[Tue Jul 21 07:20:23.470524 2026] [security2:error] [pid 230252:tid 230255] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H500Dwhk5-Z44Xro53AACsgE"]
[Tue Jul 21 07:20:23.470648 2026] [security2:error] [pid 230252:tid 230409] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H500Dwhk5-Z44Xro53AACsgE"]
[Tue Jul 21 07:20:23.591965 2026] [security2:error] [pid 230252:tid 230497] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/water.php"] [unique_id "al9H500Dwhk5-Z44Xro53QAAAwo"]
[Tue Jul 21 07:20:23.610982 2026] [security2:error] [pid 230252:tid 230437] [client 20.151.10.161:55269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/p.php"] [unique_id "al9H500Dwhk5-Z44Xro54AAAAs4"]
[Tue Jul 21 07:20:23.673508 2026] [security2:error] [pid 230252:tid 230451] [client 4.204.201.85:43916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9H500Dwhk5-Z44Xro54QAAAtw"]
[Tue Jul 21 07:20:23.891516 2026] [security2:error] [pid 230252:tid 230461] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/nano.php"] [unique_id "al9H500Dwhk5-Z44Xro55QAAAuY"]
[Tue Jul 21 07:20:23.970541 2026] [security2:error] [pid 230252:tid 230430] [client 20.220.225.223:34298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/dp.php"] [unique_id "al9H500Dwhk5-Z44Xro55gAAAsc"]
[Tue Jul 21 07:20:24.184205 2026] [security2:error] [pid 230252:tid 230422] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/moon.php"] [unique_id "al9H6E0Dwhk5-Z44Xro56gAAAr8"]
[Tue Jul 21 07:20:24.329767 2026] [security2:error] [pid 229246:tid 229424] [client 114.119.144.38:45201] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tempex.com.br"] [uri "/category/dicas"] [unique_id "al9H6CBMYeh5YLVG45xfhAAAAkQ"], referer: https://www.tempex.com.br/blog
[Tue Jul 21 07:20:24.371236 2026] [security2:error] [pid 230252:tid 230434] [client 184.75.221.3:56966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9H6E0Dwhk5-Z44Xro57AAAAss"]
[Tue Jul 21 07:20:24.371364 2026] [security2:error] [pid 230252:tid 230434] [client 184.75.221.3:56966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9H6E0Dwhk5-Z44Xro57AAAAss"]
[Tue Jul 21 07:20:24.452199 2026] [security2:error] [pid 230252:tid 230464] [client 4.204.201.85:44012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9H6E0Dwhk5-Z44Xro58AAAAuk"]
[Tue Jul 21 07:20:24.465912 2026] [security2:error] [pid 230252:tid 230504] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-info.php"] [unique_id "al9H6E0Dwhk5-Z44Xro58QAAAxE"]
[Tue Jul 21 07:20:24.686688 2026] [security2:error] [pid 230252:tid 230458] [client 173.252.95.13:52814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9H6E0Dwhk5-Z44Xro58gAAAuM"]
[Tue Jul 21 07:20:24.751645 2026] [http2:warn] [pid 229246:tid 229500] [client 57.141.18.17:25310] h2_stream(229246-147-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:24.754224 2026] [security2:error] [pid 230252:tid 230384] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/2000.php"] [unique_id "al9H6E0Dwhk5-Z44Xro59gAAApk"]
[Tue Jul 21 07:20:24.989620 2026] [security2:error] [pid 230252:tid 230400] [client 20.151.10.161:55270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/bthil.php"] [unique_id "al9H6E0Dwhk5-Z44Xro5-QAAAqk"]
[Tue Jul 21 07:20:25.049039 2026] [security2:error] [pid 229246:tid 229431] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/122.php"] [unique_id "al9H6SBMYeh5YLVG45xfigAAAks"]
[Tue Jul 21 07:20:25.072564 2026] [security2:error] [pid 230252:tid 230466] [client 20.151.10.161:45997] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "prospecta.agendaclique.com.br"] [uri "/1.php"] [unique_id "al9H6U0Dwhk5-Z44Xro5_AAAAus"]
[Tue Jul 21 07:20:25.072677 2026] [security2:error] [pid 230252:tid 230466] [client 20.151.10.161:45997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/1.php"] [unique_id "al9H6U0Dwhk5-Z44Xro5_AAAAus"]
[Tue Jul 21 07:20:25.329267 2026] [security2:error] [pid 229246:tid 229407] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/mds.php"] [unique_id "al9H6SBMYeh5YLVG45xfkAAAAjM"]
[Tue Jul 21 07:20:25.381591 2026] [security2:error] [pid 229246:tid 229455] [client 68.235.38.2:56568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9H6SBMYeh5YLVG45xfkgAAAmM"]
[Tue Jul 21 07:20:25.381671 2026] [security2:error] [pid 229246:tid 229455] [client 68.235.38.2:56568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9H6SBMYeh5YLVG45xfkgAAAmM"]
[Tue Jul 21 07:20:25.405827 2026] [security2:error] [pid 230252:tid 230451] [client 20.197.192.193:6346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/billur.php"] [unique_id "al9H6U0Dwhk5-Z44Xro6BAAAAtw"]
[Tue Jul 21 07:20:25.448391 2026] [security2:error] [pid 230252:tid 230462] [client 4.204.201.85:43928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/abcd.php"] [unique_id "al9H6U0Dwhk5-Z44Xro6BgAAAuc"]
[Tue Jul 21 07:20:25.494129 2026] [security2:error] [pid 229246:tid 229289] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H6SBMYeh5YLVG45xflAACZyo"]
[Tue Jul 21 07:20:25.494289 2026] [security2:error] [pid 229246:tid 229459] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H6SBMYeh5YLVG45xflAACZyo"]
[Tue Jul 21 07:20:25.515718 2026] [security2:error] [pid 230252:tid 230452] [client 193.36.225.64:61645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9H6U0Dwhk5-Z44Xro6BwAAAt0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:25.612050 2026] [security2:error] [pid 230252:tid 230430] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-blink.php"] [unique_id "al9H6U0Dwhk5-Z44Xro6CAAAAsc"]
[Tue Jul 21 07:20:25.622801 2026] [core:error] [pid 229246:tid 229267] [remote 40.77.167.14:50307] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:25.622839 2026] [core:error] [pid 229246:tid 229267] [remote 40.77.167.14:50307] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:25.726592 2026] [security2:error] [pid 230252:tid 230493] [client 20.226.60.151:54495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9H6U0Dwhk5-Z44Xro6DAAAAwY"]
[Tue Jul 21 07:20:25.750589 2026] [core:error] [pid 229246:tid 229334] [remote 40.77.167.14:50307] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:25.750608 2026] [core:error] [pid 229246:tid 229334] [remote 40.77.167.14:50307] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:25.836708 2026] [security2:error] [pid 230252:tid 230289] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelsilva1755793355195.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H6U0Dwhk5-Z44Xro6DgAC0yM"]
[Tue Jul 21 07:20:25.877268 2026] [core:error] [pid 229246:tid 229358] [remote 40.77.167.14:50307] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:25.877287 2026] [core:error] [pid 229246:tid 229358] [remote 40.77.167.14:50307] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:25.895487 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/zc-208.php"] [unique_id "al9H6U0Dwhk5-Z44Xro6DwAAAsI"]
[Tue Jul 21 07:20:25.962921 2026] [http2:warn] [pid 229246:tid 229492] [client 57.141.18.16:35796] h2_stream(229246-154-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:26.054996 2026] [security2:error] [pid 229246:tid 229446] [client 4.204.201.85:43859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/file15.php"] [unique_id "al9H6iBMYeh5YLVG45xfmwAAAlo"]
[Tue Jul 21 07:20:26.136421 2026] [security2:error] [pid 229246:tid 229470] [client 20.197.192.193:6371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/mimpi.php"] [unique_id "al9H6iBMYeh5YLVG45xfnAAAAnI"]
[Tue Jul 21 07:20:26.192024 2026] [security2:error] [pid 229246:tid 229424] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/sid4.php"] [unique_id "al9H6iBMYeh5YLVG45xfngAAAkQ"]
[Tue Jul 21 07:20:26.262929 2026] [security2:error] [pid 230252:tid 230404] [client 139.135.44.145:53940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H6k0Dwhk5-Z44Xro6FgAAAq0"]
[Tue Jul 21 07:20:26.263029 2026] [security2:error] [pid 230252:tid 230404] [client 139.135.44.145:53940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H6k0Dwhk5-Z44Xro6FgAAAq0"]
[Tue Jul 21 07:20:26.407620 2026] [security2:error] [pid 229246:tid 229404] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelsilva1755793355195.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9H6iBMYeh5YLVG45xfowAAAjA"]
[Tue Jul 21 07:20:26.417212 2026] [security2:error] [pid 229246:tid 229296] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H6iBMYeh5YLVG45xfpAACjTE"]
[Tue Jul 21 07:20:26.417389 2026] [security2:error] [pid 229246:tid 229497] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H6iBMYeh5YLVG45xfpAACjTE"]
[Tue Jul 21 07:20:26.436699 2026] [security2:error] [pid 229246:tid 229478] [client 74.249.245.134:48075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ws83.php"] [unique_id "al9H6iBMYeh5YLVG45xfpQAAAno"]
[Tue Jul 21 07:20:26.664740 2026] [security2:error] [pid 229246:tid 229276] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H6iBMYeh5YLVG45xfqAACVR0"]
[Tue Jul 21 07:20:26.664912 2026] [security2:error] [pid 229246:tid 229441] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H6iBMYeh5YLVG45xfqAACVR0"]
[Tue Jul 21 07:20:26.678745 2026] [security2:error] [pid 229246:tid 229491] [client 20.197.192.193:6382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/dp.php"] [unique_id "al9H6iBMYeh5YLVG45xfqQAAAoc"]
[Tue Jul 21 07:20:26.751205 2026] [security2:error] [pid 230252:tid 230401] [client 175.45.70.82:49887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H6k0Dwhk5-Z44Xro6GgAAAqo"]
[Tue Jul 21 07:20:26.751329 2026] [security2:error] [pid 230252:tid 230401] [client 175.45.70.82:49887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H6k0Dwhk5-Z44Xro6GgAAAqo"]
[Tue Jul 21 07:20:26.830258 2026] [security2:error] [pid 229246:tid 229428] [client 74.244.195.153:59523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.195.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9H6iBMYeh5YLVG45xfrAAAAkg"]
[Tue Jul 21 07:20:26.840591 2026] [security2:error] [pid 229246:tid 229428] [client 74.244.195.153:59523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9H6iBMYeh5YLVG45xfrAAAAkg"]
[Tue Jul 21 07:20:26.974106 2026] [http2:warn] [pid 229246:tid 229413] [client 57.141.18.32:36788] h2_stream(229246-158-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:26.989945 2026] [security2:error] [pid 229246:tid 229462] [client 20.151.10.161:53586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/7.php"] [unique_id "al9H6iBMYeh5YLVG45xfrQAAAmo"]
[Tue Jul 21 07:20:27.057625 2026] [http2:warn] [pid 229246:tid 229379] [client 57.141.18.79:38222] h2_stream(229246-160-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:27.059490 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:45956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/100.php"] [unique_id "al9H6yBMYeh5YLVG45xfrgAAAns"]
[Tue Jul 21 07:20:27.297376 2026] [security2:error] [pid 230252:tid 230510] [client 20.197.192.193:6391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/bootstrap.php"] [unique_id "al9H600Dwhk5-Z44Xro6JQAAAxc"]
[Tue Jul 21 07:20:27.355676 2026] [security2:error] [pid 230252:tid 230494] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wmore1.php"] [unique_id "al9H600Dwhk5-Z44Xro6JwAAAwc"]
[Tue Jul 21 07:20:27.413925 2026] [security2:error] [pid 230252:tid 230473] [client 120.61.173.56:54618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H600Dwhk5-Z44Xro6KAAAAvI"]
[Tue Jul 21 07:20:27.414097 2026] [security2:error] [pid 230252:tid 230473] [client 120.61.173.56:54618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H600Dwhk5-Z44Xro6KAAAAvI"]
[Tue Jul 21 07:20:27.625104 2026] [security2:error] [pid 229246:tid 229380] [client 20.220.225.223:36840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/dp.php"] [unique_id "al9H6yBMYeh5YLVG45xftQAAAhg"]
[Tue Jul 21 07:20:27.637757 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/solo1.php"] [unique_id "al9H600Dwhk5-Z44Xro6KQAAAtM"]
[Tue Jul 21 07:20:27.694794 2026] [security2:error] [pid 230252:tid 230412] [client 74.249.245.134:44585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/CDX1.php"] [unique_id "al9H600Dwhk5-Z44Xro6KgAAArU"]
[Tue Jul 21 07:20:27.700032 2026] [security2:error] [pid 230252:tid 230491] [client 4.204.201.85:43963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/jp.php"] [unique_id "al9H600Dwhk5-Z44Xro6KwAAAwQ"]
[Tue Jul 21 07:20:27.856506 2026] [security2:error] [pid 230252:tid 230428] [client 173.252.95.18:57226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9H6U0Dwhk5-Z44Xro6CgAAAsU"]
[Tue Jul 21 07:20:28.198684 2026] [security2:error] [pid 230252:tid 230401] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/cong.php"] [unique_id "al9H7E0Dwhk5-Z44Xro6NAAAAqo"]
[Tue Jul 21 07:20:28.201652 2026] [security2:error] [pid 229246:tid 229364] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelsilva1755793355195.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H7CBMYeh5YLVG45xfvwACYnU"]
[Tue Jul 21 07:20:28.416156 2026] [http2:warn] [pid 229246:tid 229458] [client 57.141.18.35:61098] h2_stream(229246-166-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:28.562624 2026] [security2:error] [pid 230252:tid 230464] [client 173.252.95.17:44336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9H7E0Dwhk5-Z44Xro6OwAAAuk"]
[Tue Jul 21 07:20:28.646093 2026] [security2:error] [pid 229246:tid 229478] [client 20.151.10.161:12047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/8.php"] [unique_id "al9H7CBMYeh5YLVG45xfwwAAAno"]
[Tue Jul 21 07:20:28.694281 2026] [security2:error] [pid 230252:tid 230335] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H7E0Dwhk5-Z44Xro6PgACxlA"]
[Tue Jul 21 07:20:28.694468 2026] [security2:error] [pid 230252:tid 230429] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H7E0Dwhk5-Z44Xro6PgACxlA"]
[Tue Jul 21 07:20:28.767205 2026] [security2:error] [pid 230252:tid 230462] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/public/css.php"] [unique_id "al9H7E0Dwhk5-Z44Xro6PwAAAuc"]
[Tue Jul 21 07:20:28.773235 2026] [security2:error] [pid 230252:tid 230406] [client 20.151.10.161:46058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/about.php"] [unique_id "al9H7E0Dwhk5-Z44Xro6QAAAAq8"]
[Tue Jul 21 07:20:28.914598 2026] [security2:error] [pid 230252:tid 230461] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samuelsilva1755793355195.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9H7E0Dwhk5-Z44Xro6QQAAAuY"]
[Tue Jul 21 07:20:29.051314 2026] [security2:error] [pid 229246:tid 229496] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/output.php"] [unique_id "al9H7SBMYeh5YLVG45xfyQAAAow"]
[Tue Jul 21 07:20:29.223032 2026] [http2:warn] [pid 229246:tid 229493] [client 57.141.18.120:26156] h2_stream(229246-168-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:29.327574 2026] [security2:error] [pid 230252:tid 230502] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-file-120.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6QgAAAw8"]
[Tue Jul 21 07:20:29.331682 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:12069] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.jandel.com.br"] [uri "/1.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6QwAAAwY"]
[Tue Jul 21 07:20:29.331772 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:12069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/1.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6QwAAAwY"]
[Tue Jul 21 07:20:29.386803 2026] [security2:error] [pid 230252:tid 230511] [client 4.204.201.85:43992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/f35.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6RAAAAxg"]
[Tue Jul 21 07:20:29.463151 2026] [security2:error] [pid 230252:tid 230486] [client 92.119.178.3:44230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6RwAAAv8"]
[Tue Jul 21 07:20:29.463234 2026] [security2:error] [pid 230252:tid 230486] [client 92.119.178.3:44230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6RwAAAv8"]
[Tue Jul 21 07:20:29.532226 2026] [http2:warn] [pid 229246:tid 229450] [client 57.141.18.71:28578] h2_stream(229246-169-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:29.616801 2026] [security2:error] [pid 230252:tid 230440] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/special.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6TAAAAtE"]
[Tue Jul 21 07:20:29.734717 2026] [core:error] [pid 229246:tid 229362] [remote 40.77.167.49:64068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:29.734744 2026] [core:error] [pid 229246:tid 229362] [remote 40.77.167.49:64068] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:29.932552 2026] [http2:warn] [pid 230252:tid 230496] [client 45.80.104.96:51773] h2_stream(230252-4-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:30.003752 2026] [security2:error] [pid 230252:tid 230389] [client 184.75.221.3:53916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6UQAAAp4"]
[Tue Jul 21 07:20:30.003858 2026] [security2:error] [pid 230252:tid 230389] [client 184.75.221.3:53916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6UQAAAp4"]
[Tue Jul 21 07:20:30.007375 2026] [security2:error] [pid 230252:tid 230495] [client 20.151.10.161:55273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/100.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6UgAAAwg"]
[Tue Jul 21 07:20:30.143188 2026] [security2:error] [pid 230252:tid 230387] [client 4.204.201.85:43956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-load.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6VAAAApw"]
[Tue Jul 21 07:20:30.163144 2026] [security2:error] [pid 229246:tid 229498] [client 20.197.192.193:6902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wp-editor.php"] [unique_id "al9H7iBMYeh5YLVG45xf1AAAAo4"]
[Tue Jul 21 07:20:30.298423 2026] [security2:error] [pid 230252:tid 230470] [client 103.162.129.114:60007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6WQAAAu8"]
[Tue Jul 21 07:20:30.298559 2026] [security2:error] [pid 230252:tid 230470] [client 103.162.129.114:60007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6WQAAAu8"]
[Tue Jul 21 07:20:30.340724 2026] [security2:error] [pid 230252:tid 230498] [client 103.121.156.110:61585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6WgAAAws"]
[Tue Jul 21 07:20:30.340890 2026] [security2:error] [pid 230252:tid 230498] [client 103.121.156.110:61585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6WgAAAws"]
[Tue Jul 21 07:20:30.414257 2026] [security2:error] [pid 229246:tid 229302] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H7iBMYeh5YLVG45xf2AACGTc"]
[Tue Jul 21 07:20:30.414395 2026] [security2:error] [pid 229246:tid 229381] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H7iBMYeh5YLVG45xf2AACGTc"]
[Tue Jul 21 07:20:30.468213 2026] [security2:error] [pid 230252:tid 230445] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/as.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6XAAAAtY"]
[Tue Jul 21 07:20:30.749514 2026] [security2:error] [pid 230252:tid 230451] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/cgi-bin/index.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6XwAAAtw"]
[Tue Jul 21 07:20:30.767457 2026] [security2:error] [pid 230252:tid 230429] [client 20.151.10.161:55235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/about.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6YAAAAsY"]
[Tue Jul 21 07:20:30.889772 2026] [security2:error] [pid 230252:tid 230424] [client 92.119.178.3:44238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6YQAAAsE"]
[Tue Jul 21 07:20:30.889898 2026] [security2:error] [pid 230252:tid 230424] [client 92.119.178.3:44238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9H7k0Dwhk5-Z44Xro6YQAAAsE"]
[Tue Jul 21 07:20:30.945280 2026] [http2:warn] [pid 229246:tid 229460] [client 57.141.18.95:49382] h2_stream(229246-175-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:31.051393 2026] [security2:error] [pid 230252:tid 230447] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/w1px.php"] [unique_id "al9H700Dwhk5-Z44Xro6YwAAAtg"]
[Tue Jul 21 07:20:31.162466 2026] [security2:error] [pid 230252:tid 230476] [client 37.140.223.69:35105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9H7U0Dwhk5-Z44Xro6UAAAAvU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:31.202155 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:53589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/admin.php"] [unique_id "al9H700Dwhk5-Z44Xro6ZgAAAwY"]
[Tue Jul 21 07:20:31.325318 2026] [security2:error] [pid 230252:tid 230494] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/yawa.php"] [unique_id "al9H700Dwhk5-Z44Xro6aAAAAwc"]
[Tue Jul 21 07:20:31.489608 2026] [security2:error] [pid 230252:tid 230434] [client 20.104.96.117:59160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9H700Dwhk5-Z44Xro6aQAAAss"]
[Tue Jul 21 07:20:31.535388 2026] [security2:error] [pid 229246:tid 229478] [client 4.204.201.85:43934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/xyn.php"] [unique_id "al9H7yBMYeh5YLVG45xf6AAAAno"]
[Tue Jul 21 07:20:31.572658 2026] [security2:error] [pid 229246:tid 229473] [client 20.151.10.161:46043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/admin.php"] [unique_id "al9H7yBMYeh5YLVG45xf6QAAAnU"]
[Tue Jul 21 07:20:31.614471 2026] [security2:error] [pid 229246:tid 229392] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/js.php"] [unique_id "al9H7yBMYeh5YLVG45xf6gAAAiQ"]
[Tue Jul 21 07:20:31.858773 2026] [security2:error] [pid 230252:tid 230428] [client 20.151.10.161:55242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/edit.php"] [unique_id "al9H700Dwhk5-Z44Xro6bgAAAsU"]
[Tue Jul 21 07:20:31.932552 2026] [security2:error] [pid 230252:tid 230389] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/core.php"] [unique_id "al9H700Dwhk5-Z44Xro6bwAAAp4"]
[Tue Jul 21 07:20:31.954737 2026] [security2:error] [pid 229246:tid 229273] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H7yBMYeh5YLVG45xf7QACjBo"]
[Tue Jul 21 07:20:31.954865 2026] [security2:error] [pid 229246:tid 229496] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H7yBMYeh5YLVG45xf7QACjBo"]
[Tue Jul 21 07:20:31.991752 2026] [http2:warn] [pid 229246:tid 229487] [client 57.141.18.121:26834] h2_stream(229246-182-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:32.116167 2026] [security2:error] [pid 229246:tid 229388] [client 107.189.6.149:57908] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "contafic.com.br"] [uri "/"] [unique_id "al9H8CBMYeh5YLVG45xf7wAAAiA"]
[Tue Jul 21 07:20:32.210914 2026] [security2:error] [pid 230252:tid 230487] [client 20.226.60.151:61072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/qqqa.php"] [unique_id "al9H8E0Dwhk5-Z44Xro6dgAAAwA"]
[Tue Jul 21 07:20:32.234072 2026] [security2:error] [pid 230252:tid 230498] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/19.php"] [unique_id "al9H8E0Dwhk5-Z44Xro6dwAAAws"]
[Tue Jul 21 07:20:32.291457 2026] [security2:error] [pid 230252:tid 230445] [client 20.151.10.161:53594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9H8E0Dwhk5-Z44Xro6eQAAAtY"]
[Tue Jul 21 07:20:32.309315 2026] [security2:error] [pid 230252:tid 230472] [client 107.189.6.149:57907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "contafic.com.br"] [uri "/"] [unique_id "al9H8E0Dwhk5-Z44Xro6egAAAvE"]
[Tue Jul 21 07:20:32.344037 2026] [security2:error] [pid 230252:tid 230407] [client 14.139.42.196:12847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H8E0Dwhk5-Z44Xro6ewAAArA"]
[Tue Jul 21 07:20:32.344171 2026] [security2:error] [pid 230252:tid 230407] [client 14.139.42.196:12847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H8E0Dwhk5-Z44Xro6ewAAArA"]
[Tue Jul 21 07:20:32.452337 2026] [security2:error] [pid 230252:tid 230419] [client 20.104.96.117:59710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9H8E0Dwhk5-Z44Xro6fQAAArw"]
[Tue Jul 21 07:20:32.515151 2026] [security2:error] [pid 229246:tid 229398] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/inc.php"] [unique_id "al9H8CBMYeh5YLVG45xf8gAAAio"]
[Tue Jul 21 07:20:32.516750 2026] [security2:error] [pid 230252:tid 230409] [client 107.189.6.149:57957] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "contafic.com.br"] [uri "/"] [unique_id "al9H8E0Dwhk5-Z44Xro6fgAAArI"]
[Tue Jul 21 07:20:32.639083 2026] [security2:error] [pid 229246:tid 229438] [client 20.151.10.161:12077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/f6.php"] [unique_id "al9H8CBMYeh5YLVG45xf9QAAAlI"]
[Tue Jul 21 07:20:32.755714 2026] [security2:error] [pid 229246:tid 229471] [client 20.151.10.161:45909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/edit.php"] [unique_id "al9H8CBMYeh5YLVG45xf9gAAAnM"]
[Tue Jul 21 07:20:32.796484 2026] [security2:error] [pid 230252:tid 230452] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-ppoxua4.php"] [unique_id "al9H8E0Dwhk5-Z44Xro6gAAAAt0"]
[Tue Jul 21 07:20:32.867733 2026] [security2:error] [pid 230252:tid 230390] [client 114.119.135.35:40111] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "startonesite.com.br"] [uri "/9618ejodhl3-ffcbo1018686"] [unique_id "al9H8E0Dwhk5-Z44Xro6gQAAAp8"], referer: https://startonesite.com.br/9618ejodhl3-ffcbo1018686
[Tue Jul 21 07:20:32.905690 2026] [security2:error] [pid 229246:tid 229498] [client 107.189.6.149:57979] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "contafic.com.br"] [uri "/"] [unique_id "al9H8CBMYeh5YLVG45xf-QAAAo4"]
[Tue Jul 21 07:20:33.172792 2026] [http2:warn] [pid 229246:tid 229384] [client 57.141.18.24:56438] h2_stream(229246-188-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:33.185718 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:45985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9H8SBMYeh5YLVG45xf_AAAAlo"]
[Tue Jul 21 07:20:33.250398 2026] [security2:error] [pid 230252:tid 230423] [client 20.151.10.161:12041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/inputs.php"] [unique_id "al9H8U0Dwhk5-Z44Xro6hQAAAsA"]
[Tue Jul 21 07:20:33.363349 2026] [security2:error] [pid 230252:tid 230430] [client 20.104.96.117:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/xyn.php"] [unique_id "al9H8U0Dwhk5-Z44Xro6hwAAAsc"]
[Tue Jul 21 07:20:33.515252 2026] [security2:error] [pid 229246:tid 229495] [client 45.251.232.145:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H8SBMYeh5YLVG45xf_wAAAos"]
[Tue Jul 21 07:20:33.515411 2026] [security2:error] [pid 229246:tid 229495] [client 45.251.232.145:62693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H8SBMYeh5YLVG45xf_wAAAos"]
[Tue Jul 21 07:20:33.627474 2026] [http2:warn] [pid 229246:tid 229436] [client 57.141.18.107:52722] h2_stream(229246-193-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:33.639049 2026] [security2:error] [pid 229246:tid 229479] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-u3nxbvx.php"] [unique_id "al9H8SBMYeh5YLVG45xgAgAAAns"]
[Tue Jul 21 07:20:33.834581 2026] [security2:error] [pid 230252:tid 230427] [client 4.204.201.85:43927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ccc.php"] [unique_id "al9H8U0Dwhk5-Z44Xro6jAAAAsQ"]
[Tue Jul 21 07:20:33.879916 2026] [security2:error] [pid 229246:tid 229466] [client 20.151.10.161:12032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/av.php"] [unique_id "al9H8SBMYeh5YLVG45xgBAAAAm4"]
[Tue Jul 21 07:20:33.946964 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ss.php"] [unique_id "al9H8SBMYeh5YLVG45xgBwAAAi8"]
[Tue Jul 21 07:20:33.964962 2026] [security2:error] [pid 229246:tid 229299] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H8SBMYeh5YLVG45xgCAACXjQ"]
[Tue Jul 21 07:20:33.965100 2026] [security2:error] [pid 229246:tid 229450] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H8SBMYeh5YLVG45xgCAACXjQ"]
[Tue Jul 21 07:20:34.231550 2026] [security2:error] [pid 229246:tid 229473] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/min.php"] [unique_id "al9H8iBMYeh5YLVG45xgDwAAAnU"]
[Tue Jul 21 07:20:34.233563 2026] [security2:error] [pid 229246:tid 229460] [client 20.151.10.161:45977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/f6.php"] [unique_id "al9H8iBMYeh5YLVG45xgEAAAAmg"]
[Tue Jul 21 07:20:34.282746 2026] [security2:error] [pid 229246:tid 229421] [client 4.204.201.85:43936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/w.php"] [unique_id "al9H8iBMYeh5YLVG45xgEQAAAkE"]
[Tue Jul 21 07:20:34.513164 2026] [security2:error] [pid 229246:tid 229444] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9H8iBMYeh5YLVG45xgEwAAAlg"]
[Tue Jul 21 07:20:34.542097 2026] [security2:error] [pid 230252:tid 230487] [client 20.220.225.223:39535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/aa1.php"] [unique_id "al9H8k0Dwhk5-Z44Xro6kwAAAwA"]
[Tue Jul 21 07:20:34.737566 2026] [security2:error] [pid 230252:tid 230465] [client 4.204.201.85:43919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9H8k0Dwhk5-Z44Xro6swAAAuo"]
[Tue Jul 21 07:20:34.799953 2026] [security2:error] [pid 230252:tid 230481] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/autoload_classmap.php"] [unique_id "al9H8k0Dwhk5-Z44Xro6tAAAAvo"]
[Tue Jul 21 07:20:34.830488 2026] [http2:warn] [pid 229246:tid 229452] [client 57.141.18.89:25240] h2_stream(229246-196-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:34.903623 2026] [http2:warn] [pid 229246:tid 229474] [client 57.141.18.82:49256] h2_stream(229246-199-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:34.928640 2026] [security2:error] [pid 230252:tid 230458] [client 20.151.10.161:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/inputs.php"] [unique_id "al9H8k0Dwhk5-Z44Xro6tQAAAuM"]
[Tue Jul 21 07:20:34.940249 2026] [security2:error] [pid 230252:tid 230409] [client 20.197.192.193:6877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/cro.php"] [unique_id "al9H8k0Dwhk5-Z44Xro6tgAAArI"]
[Tue Jul 21 07:20:34.968409 2026] [security2:error] [pid 229246:tid 229388] [client 20.151.10.161:55232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/classwithtostring.php"] [unique_id "al9H8iBMYeh5YLVG45xgGAAAAiA"]
[Tue Jul 21 07:20:35.080557 2026] [security2:error] [pid 230252:tid 230452] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-link-zorm.php"] [unique_id "al9H800Dwhk5-Z44Xro6ugAAAt0"]
[Tue Jul 21 07:20:35.181729 2026] [security2:error] [pid 229246:tid 229393] [client 4.204.201.85:44009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/FWAZ.php"] [unique_id "al9H8yBMYeh5YLVG45xgHQAAAiU"]
[Tue Jul 21 07:20:35.334369 2026] [security2:error] [pid 229246:tid 229498] [client 114.119.143.158:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.imobiliariasobrado.com.br"] [uri "/index.php/imovel/sobrado-geminado-3-quartos-com-garagem-9494m2-venda-floresta-joinville-sc-v06183"] [unique_id "al9H8yBMYeh5YLVG45xgIgAAAo4"], referer: https://www.imobiliariasobrado.com.br/index.php
[Tue Jul 21 07:20:35.377879 2026] [security2:error] [pid 229246:tid 229411] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-link-szoppm.php"] [unique_id "al9H8yBMYeh5YLVG45xgIwAAAjc"]
[Tue Jul 21 07:20:35.461033 2026] [autoindex:error] [pid 229246:tid 229442] [client 43.163.112.239:36622] AH01276: Cannot serve directory /home1/joaor255/meupetpaixao.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:20:35.625928 2026] [security2:error] [pid 229246:tid 229406] [client 20.151.10.161:45967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/av.php"] [unique_id "al9H8yBMYeh5YLVG45xgJwAAAjI"]
[Tue Jul 21 07:20:35.675160 2026] [security2:error] [pid 229246:tid 229479] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/albin.php"] [unique_id "al9H8yBMYeh5YLVG45xgKAAAAns"]
[Tue Jul 21 07:20:35.784246 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:59664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/patie.php"] [unique_id "al9H8yBMYeh5YLVG45xgLAAAAi8"]
[Tue Jul 21 07:20:35.850960 2026] [security2:error] [pid 230252:tid 230471] [client 136.144.33.215:55705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9H800Dwhk5-Z44Xro6vAAAAvA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:35.957875 2026] [security2:error] [pid 230252:tid 230473] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/cilus.php"] [unique_id "al9H800Dwhk5-Z44Xro6vQAAAvI"]
[Tue Jul 21 07:20:36.105023 2026] [security2:error] [pid 230252:tid 230510] [client 4.204.201.85:44000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/miru1.php"] [unique_id "al9H9E0Dwhk5-Z44Xro6vgAAAxc"]
[Tue Jul 21 07:20:36.221841 2026] [security2:error] [pid 229246:tid 229276] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H9CBMYeh5YLVG45xgMwACJB0"]
[Tue Jul 21 07:20:36.222004 2026] [security2:error] [pid 229246:tid 229392] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H9CBMYeh5YLVG45xgMwACJB0"]
[Tue Jul 21 07:20:36.237547 2026] [security2:error] [pid 230252:tid 230440] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/gptsh.php"] [unique_id "al9H9E0Dwhk5-Z44Xro6wgAAAtE"]
[Tue Jul 21 07:20:36.275568 2026] [security2:error] [pid 229246:tid 229441] [client 20.151.10.161:55286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9H9CBMYeh5YLVG45xgNgAAAlU"]
[Tue Jul 21 07:20:36.433985 2026] [security2:error] [pid 229246:tid 229400] [client 20.151.10.161:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/classwithtostring.php"] [unique_id "al9H9CBMYeh5YLVG45xgNwAAAiw"]
[Tue Jul 21 07:20:36.512249 2026] [security2:error] [pid 230252:tid 230457] [client 20.197.192.193:6859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/cron-tab.php"] [unique_id "al9H9E0Dwhk5-Z44Xro6xQAAAuI"]
[Tue Jul 21 07:20:36.512448 2026] [security2:error] [pid 230252:tid 230401] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/rithin.php"] [unique_id "al9H9E0Dwhk5-Z44Xro6xgAAAqo"]
[Tue Jul 21 07:20:36.654761 2026] [security2:error] [pid 230252:tid 230389] [client 114.119.145.137:43081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "northcomm.com.br"] [uri "/wp-includes/css/wp-embed-template-ie.css"] [unique_id "al9H9E0Dwhk5-Z44Xro6xwAAAp4"], referer: https://northcomm.com.br/wp-includes/css/?MD
[Tue Jul 21 07:20:36.755376 2026] [http2:warn] [pid 229246:tid 229389] [client 57.141.18.57:54776] h2_stream(229246-202-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:36.821619 2026] [security2:error] [pid 230252:tid 230495] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/fffm.php"] [unique_id "al9H9E0Dwhk5-Z44Xro6yAAAAwg"]
[Tue Jul 21 07:20:36.859245 2026] [security2:error] [pid 230252:tid 230498] [client 20.151.10.161:11740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-blog.php"] [unique_id "al9H9E0Dwhk5-Z44Xro6zAAAAws"]
[Tue Jul 21 07:20:36.929341 2026] [http2:warn] [pid 229246:tid 229382] [client 57.141.18.19:44984] h2_stream(229246-204-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:36.968687 2026] [security2:error] [pid 229246:tid 229304] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9CBMYeh5YLVG45xgQAACUzk"]
[Tue Jul 21 07:20:36.968872 2026] [security2:error] [pid 229246:tid 229439] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9CBMYeh5YLVG45xgQAACUzk"]
[Tue Jul 21 07:20:36.982171 2026] [security2:error] [pid 229246:tid 229387] [client 74.249.245.134:60509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/inputs.php"] [unique_id "al9H9CBMYeh5YLVG45xgQQAAAh8"]
[Tue Jul 21 07:20:37.119288 2026] [security2:error] [pid 230252:tid 230497] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/dfre.php"] [unique_id "al9H9U0Dwhk5-Z44Xro6zgAAAwo"]
[Tue Jul 21 07:20:37.128304 2026] [security2:error] [pid 230252:tid 230384] [client 139.135.44.145:54798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H9U0Dwhk5-Z44Xro6zwAAApk"]
[Tue Jul 21 07:20:37.128458 2026] [security2:error] [pid 230252:tid 230384] [client 139.135.44.145:54798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H9U0Dwhk5-Z44Xro6zwAAApk"]
[Tue Jul 21 07:20:37.169699 2026] [security2:error] [pid 230252:tid 230464] [client 20.151.10.161:45950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9H9U0Dwhk5-Z44Xro60AAAAuk"]
[Tue Jul 21 07:20:37.275719 2026] [security2:error] [pid 230252:tid 230263] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9U0Dwhk5-Z44Xro60gAC3Qk"]
[Tue Jul 21 07:20:37.275922 2026] [security2:error] [pid 230252:tid 230452] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9U0Dwhk5-Z44Xro60gAC3Qk"]
[Tue Jul 21 07:20:37.385382 2026] [security2:error] [pid 230252:tid 230511] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/wp-happy.php"] [unique_id "al9H9U0Dwhk5-Z44Xro61AAAAxg"]
[Tue Jul 21 07:20:37.477433 2026] [security2:error] [pid 230252:tid 230466] [client 175.45.70.82:50624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9U0Dwhk5-Z44Xro61QAAAus"]
[Tue Jul 21 07:20:37.477562 2026] [security2:error] [pid 230252:tid 230466] [client 175.45.70.82:50624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9U0Dwhk5-Z44Xro61QAAAus"]
[Tue Jul 21 07:20:37.604586 2026] [security2:error] [pid 230252:tid 230425] [client 20.197.192.193:6358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/koiy.php"] [unique_id "al9H9U0Dwhk5-Z44Xro63AAAAsI"]
[Tue Jul 21 07:20:37.651111 2026] [security2:error] [pid 230252:tid 230440] [client 4.204.201.85:17891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/aa.php"] [unique_id "al9H9U0Dwhk5-Z44Xro63QAAAtE"]
[Tue Jul 21 07:20:37.659219 2026] [security2:error] [pid 230252:tid 230396] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/fpr4.php"] [unique_id "al9H9U0Dwhk5-Z44Xro63gAAAqU"]
[Tue Jul 21 07:20:37.835865 2026] [security2:error] [pid 229246:tid 229414] [client 20.226.60.151:54486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/aunmc.php"] [unique_id "al9H9SBMYeh5YLVG45xgSQAAAjo"]
[Tue Jul 21 07:20:37.932963 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/file88.php"] [unique_id "al9H9SBMYeh5YLVG45xgTQAAAi8"]
[Tue Jul 21 07:20:38.007958 2026] [security2:error] [pid 229246:tid 229455] [client 20.151.10.161:46056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-blog.php"] [unique_id "al9H9iBMYeh5YLVG45xgTgAAAmM"]
[Tue Jul 21 07:20:38.028509 2026] [core:alert] [pid 230252:tid 230416] [client 49.51.38.193:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:20:38.044773 2026] [security2:error] [pid 230252:tid 230476] [client 120.61.173.56:55118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9k0Dwhk5-Z44Xro64wAAAvU"]
[Tue Jul 21 07:20:38.044968 2026] [security2:error] [pid 230252:tid 230476] [client 120.61.173.56:55118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H9k0Dwhk5-Z44Xro64wAAAvU"]
[Tue Jul 21 07:20:38.222078 2026] [security2:error] [pid 230252:tid 230389] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ccc.php"] [unique_id "al9H9k0Dwhk5-Z44Xro65AAAAp4"]
[Tue Jul 21 07:20:38.227356 2026] [http2:warn] [pid 230252:tid 230385] [client 57.141.18.113:37894] h2_stream(230252-0-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:38.363833 2026] [security2:error] [pid 230252:tid 230489] [client 20.104.96.117:59707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/aa.php"] [unique_id "al9H9k0Dwhk5-Z44Xro65QAAAwI"]
[Tue Jul 21 07:20:38.386641 2026] [security2:error] [pid 230252:tid 230397] [client 20.197.192.193:7004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/hp2.php"] [unique_id "al9H9k0Dwhk5-Z44Xro65gAAAqY"]
[Tue Jul 21 07:20:38.412692 2026] [security2:error] [pid 229246:tid 229404] [client 20.151.10.161:55258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9H9iBMYeh5YLVG45xgUgAAAjA"]
[Tue Jul 21 07:20:38.505860 2026] [security2:error] [pid 230252:tid 230497] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/777.php"] [unique_id "al9H9k0Dwhk5-Z44Xro66wAAAwo"]
[Tue Jul 21 07:20:38.825158 2026] [security2:error] [pid 229246:tid 229460] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/for.php"] [unique_id "al9H9iBMYeh5YLVG45xgVAAAAmg"]
[Tue Jul 21 07:20:38.894602 2026] [security2:error] [pid 230252:tid 230464] [client 20.151.10.161:46023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9H9k0Dwhk5-Z44Xro67QAAAuk"]
[Tue Jul 21 07:20:38.896836 2026] [core:error] [pid 229246:tid 229335] [remote 40.77.167.14:50367] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:38.896851 2026] [core:error] [pid 229246:tid 229335] [remote 40.77.167.14:50367] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:38.989891 2026] [security2:error] [pid 230252:tid 230429] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9H9k0Dwhk5-Z44Xro67wAAAsY"]
[Tue Jul 21 07:20:39.002087 2026] [security2:error] [pid 230252:tid 230406] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9H900Dwhk5-Z44Xro68QAAAq8"]
[Tue Jul 21 07:20:39.015628 2026] [security2:error] [pid 229246:tid 229444] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/sql.php"] [unique_id "al9H9yBMYeh5YLVG45xgWQAAAlg"]
[Tue Jul 21 07:20:39.038275 2026] [security2:error] [pid 229246:tid 229441] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/1index.php"] [unique_id "al9H9yBMYeh5YLVG45xgWgAAAlU"]
[Tue Jul 21 07:20:39.062324 2026] [security2:error] [pid 229246:tid 229332] [remote 5.39.1.238:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "hauptmann.com.br"] [uri "/grid-full-width-2-cols/page/3/"] [unique_id "al9H9yBMYeh5YLVG45xgWwACdlU"]
[Tue Jul 21 07:20:39.062476 2026] [security2:error] [pid 229246:tid 229474] [client 5.39.1.238:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hauptmann.com.br"] [uri "/grid-full-width-2-cols/page/3/"] [unique_id "al9H9yBMYeh5YLVG45xgWwACdlU"]
[Tue Jul 21 07:20:39.076600 2026] [security2:error] [pid 229246:tid 229497] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/reop1.php"] [unique_id "al9H9yBMYeh5YLVG45xgXAAAAo0"]
[Tue Jul 21 07:20:39.101819 2026] [security2:error] [pid 230252:tid 230399] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/trusj18.php"] [unique_id "al9H900Dwhk5-Z44Xro68gAAAqg"]
[Tue Jul 21 07:20:39.107310 2026] [security2:error] [pid 229246:tid 229399] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/ssla.php"] [unique_id "al9H9yBMYeh5YLVG45xgXQAAAis"]
[Tue Jul 21 07:20:39.116040 2026] [security2:error] [pid 229246:tid 229410] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/trusj15.php"] [unique_id "al9H9yBMYeh5YLVG45xgXgAAAjY"]
[Tue Jul 21 07:20:39.128590 2026] [security2:error] [pid 230252:tid 230390] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/rft8.php"] [unique_id "al9H900Dwhk5-Z44Xro68wAAAp8"]
[Tue Jul 21 07:20:39.139924 2026] [security2:error] [pid 230252:tid 230423] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ai.php"] [unique_id "al9H900Dwhk5-Z44Xro69AAAAsA"]
[Tue Jul 21 07:20:39.151394 2026] [security2:error] [pid 230252:tid 230447] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/fx.php"] [unique_id "al9H900Dwhk5-Z44Xro69QAAAtg"]
[Tue Jul 21 07:20:39.163292 2026] [security2:error] [pid 230252:tid 230410] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/xxx.php"] [unique_id "al9H900Dwhk5-Z44Xro69gAAArM"]
[Tue Jul 21 07:20:39.174561 2026] [security2:error] [pid 230252:tid 230395] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/dropdown.php"] [unique_id "al9H900Dwhk5-Z44Xro69wAAAqQ"]
[Tue Jul 21 07:20:39.185325 2026] [security2:error] [pid 230252:tid 230287] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H900Dwhk5-Z44Xro6-AADBiE"]
[Tue Jul 21 07:20:39.185480 2026] [security2:error] [pid 230252:tid 230493] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9H900Dwhk5-Z44Xro6-AADBiE"]
[Tue Jul 21 07:20:39.187948 2026] [security2:error] [pid 230252:tid 230502] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/file11.php"] [unique_id "al9H900Dwhk5-Z44Xro6-QAAAw8"]
[Tue Jul 21 07:20:39.198686 2026] [security2:error] [pid 230252:tid 230510] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/png.php"] [unique_id "al9H900Dwhk5-Z44Xro6-gAAAxc"]
[Tue Jul 21 07:20:39.209563 2026] [security2:error] [pid 230252:tid 230396] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-slss.php"] [unique_id "al9H900Dwhk5-Z44Xro6-wAAAqU"]
[Tue Jul 21 07:20:39.220673 2026] [security2:error] [pid 230252:tid 230392] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ah25.php"] [unique_id "al9H900Dwhk5-Z44Xro6_QAAAqE"]
[Tue Jul 21 07:20:39.232037 2026] [security2:error] [pid 230252:tid 230300] [remote 41.76.214.143:51010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9H900Dwhk5-Z44Xro6_wACvC4"]
[Tue Jul 21 07:20:39.232182 2026] [security2:error] [pid 230252:tid 230457] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ccou.php"] [unique_id "al9H900Dwhk5-Z44Xro6_gAAAuI"]
[Tue Jul 21 07:20:39.237446 2026] [http2:warn] [pid 230252:tid 230413] [client 57.141.18.109:28454] h2_stream(230252-2-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:39.244072 2026] [security2:error] [pid 230252:tid 230426] [client 20.206.67.15:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/1.php"] [unique_id "al9H900Dwhk5-Z44Xro7AAAAAsM"]
[Tue Jul 21 07:20:39.244187 2026] [security2:error] [pid 230252:tid 230426] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/1.php"] [unique_id "al9H900Dwhk5-Z44Xro7AAAAAsM"]
[Tue Jul 21 07:20:39.258600 2026] [security2:error] [pid 230252:tid 230387] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/900.php"] [unique_id "al9H900Dwhk5-Z44Xro7AQAAApw"]
[Tue Jul 21 07:20:39.266236 2026] [security2:error] [pid 230252:tid 230389] [client 20.197.192.193:6861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/hp3.php"] [unique_id "al9H900Dwhk5-Z44Xro7AgAAAp4"]
[Tue Jul 21 07:20:39.278178 2026] [security2:error] [pid 230252:tid 230507] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/file59.php"] [unique_id "al9H900Dwhk5-Z44Xro7AwAAAxQ"]
[Tue Jul 21 07:20:39.290479 2026] [security2:error] [pid 229246:tid 229493] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/amxloxxr.php"] [unique_id "al9H9yBMYeh5YLVG45xgYAAAAok"]
[Tue Jul 21 07:20:39.303630 2026] [security2:error] [pid 229246:tid 229407] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/aboutc.php"] [unique_id "al9H9yBMYeh5YLVG45xgYQAAAjM"]
[Tue Jul 21 07:20:39.307532 2026] [security2:error] [pid 229246:tid 229393] [client 20.197.192.193:6374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/aa1.php"] [unique_id "al9H9yBMYeh5YLVG45xgYgAAAiU"]
[Tue Jul 21 07:20:39.317943 2026] [security2:error] [pid 230252:tid 230397] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/bless18.php"] [unique_id "al9H900Dwhk5-Z44Xro7BAAAAqY"]
[Tue Jul 21 07:20:39.333565 2026] [security2:error] [pid 230252:tid 230436] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/crgio.php"] [unique_id "al9H900Dwhk5-Z44Xro7BQAAAs0"]
[Tue Jul 21 07:20:39.346866 2026] [security2:error] [pid 230252:tid 230445] [client 20.197.192.193:6850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/acew67.php"] [unique_id "al9H900Dwhk5-Z44Xro7BgAAAtY"]
[Tue Jul 21 07:20:39.350622 2026] [security2:error] [pid 230252:tid 230497] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-act.php"] [unique_id "al9H900Dwhk5-Z44Xro7BwAAAwo"]
[Tue Jul 21 07:20:39.369311 2026] [security2:error] [pid 230252:tid 230464] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/new4.php"] [unique_id "al9H900Dwhk5-Z44Xro7CQAAAuk"]
[Tue Jul 21 07:20:39.377847 2026] [security2:error] [pid 230252:tid 230501] [client 20.197.192.193:6899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/bscclapb.php"] [unique_id "al9H900Dwhk5-Z44Xro7CgAAAw4"]
[Tue Jul 21 07:20:39.380350 2026] [security2:error] [pid 230252:tid 230406] [client 20.151.10.161:12049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/adminfuns.php"] [unique_id "al9H900Dwhk5-Z44Xro7CwAAAq8"]
[Tue Jul 21 07:20:39.381736 2026] [security2:error] [pid 230252:tid 230500] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-the.php"] [unique_id "al9H900Dwhk5-Z44Xro7DAAAAw0"]
[Tue Jul 21 07:20:39.388700 2026] [security2:error] [pid 230252:tid 230409] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocara.io"] [uri "/zc-131.php"] [unique_id "al9H900Dwhk5-Z44Xro7DQAAArI"]
[Tue Jul 21 07:20:39.398740 2026] [security2:error] [pid 230252:tid 230461] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/atkno.php"] [unique_id "al9H900Dwhk5-Z44Xro7DgAAAuY"]
[Tue Jul 21 07:20:39.406939 2026] [security2:error] [pid 230252:tid 230511] [client 20.197.192.193:6340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/else1.php"] [unique_id "al9H900Dwhk5-Z44Xro7DwAAAxg"]
[Tue Jul 21 07:20:39.412214 2026] [security2:error] [pid 230252:tid 230390] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/mass.php"] [unique_id "al9H900Dwhk5-Z44Xro7EAAAAp8"]
[Tue Jul 21 07:20:39.429031 2026] [security2:error] [pid 230252:tid 230466] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wefile.php"] [unique_id "al9H900Dwhk5-Z44Xro7EQAAAus"]
[Tue Jul 21 07:20:39.432487 2026] [security2:error] [pid 230252:tid 230430] [client 20.197.192.193:6354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/tkikikoko.php"] [unique_id "al9H900Dwhk5-Z44Xro7EgAAAsc"]
[Tue Jul 21 07:20:39.445359 2026] [security2:error] [pid 229246:tid 229438] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/min.php"] [unique_id "al9H9yBMYeh5YLVG45xgYwAAAlI"]
[Tue Jul 21 07:20:39.461211 2026] [security2:error] [pid 229246:tid 229381] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/sid3.php"] [unique_id "al9H9yBMYeh5YLVG45xgZAAAAhk"]
[Tue Jul 21 07:20:39.478624 2026] [security2:error] [pid 229246:tid 229459] [client 20.197.192.193:6370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9H9yBMYeh5YLVG45xgZQAAAmc"]
[Tue Jul 21 07:20:39.479214 2026] [security2:error] [pid 230252:tid 230395] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/fileas.php"] [unique_id "al9H900Dwhk5-Z44Xro7FAAAAqQ"]
[Tue Jul 21 07:20:39.491047 2026] [security2:error] [pid 229246:tid 229428] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/bless24.php"] [unique_id "al9H9yBMYeh5YLVG45xgZgAAAkg"]
[Tue Jul 21 07:20:39.503100 2026] [security2:error] [pid 230252:tid 230493] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/fun.php"] [unique_id "al9H900Dwhk5-Z44Xro7FgAAAwY"]
[Tue Jul 21 07:20:39.526100 2026] [security2:error] [pid 229246:tid 229391] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/drykl.php"] [unique_id "al9H9yBMYeh5YLVG45xgagAAAiM"]
[Tue Jul 21 07:20:39.528552 2026] [security2:error] [pid 230252:tid 230504] [client 20.197.192.193:7016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wp-css.php"] [unique_id "al9H900Dwhk5-Z44Xro7FwAAAxE"]
[Tue Jul 21 07:20:39.540094 2026] [security2:error] [pid 229246:tid 229384] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al9H9yBMYeh5YLVG45xgawAAAhw"]
[Tue Jul 21 07:20:39.541731 2026] [security2:error] [pid 229246:tid 229401] [client 20.151.10.161:45893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/adminfuns.php"] [unique_id "al9H9yBMYeh5YLVG45xgbAAAAi0"]
[Tue Jul 21 07:20:39.551148 2026] [security2:error] [pid 229246:tid 229495] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/mifta.php"] [unique_id "al9H9yBMYeh5YLVG45xgbQAAAos"]
[Tue Jul 21 07:20:39.569089 2026] [security2:error] [pid 229246:tid 229394] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/class-t.api.php"] [unique_id "al9H9yBMYeh5YLVG45xgbgAAAiY"]
[Tue Jul 21 07:20:39.571860 2026] [security2:error] [pid 230252:tid 230265] [remote 182.77.62.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-login.php"] [unique_id "al9H900Dwhk5-Z44Xro7GQAC9Qs"]
[Tue Jul 21 07:20:39.585863 2026] [security2:error] [pid 229246:tid 229380] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/vgtyu.php"] [unique_id "al9H9yBMYeh5YLVG45xgbwAAAhg"]
[Tue Jul 21 07:20:39.609239 2026] [security2:error] [pid 229246:tid 229379] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/atomlib.php"] [unique_id "al9H9yBMYeh5YLVG45xgcAAAAhc"]
[Tue Jul 21 07:20:39.625049 2026] [security2:error] [pid 230252:tid 230400] [client 193.36.225.73:20495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9H900Dwhk5-Z44Xro7GgAAAqk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:39.628239 2026] [security2:error] [pid 229246:tid 229389] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-access.php"] [unique_id "al9H9yBMYeh5YLVG45xgcQAAAiE"]
[Tue Jul 21 07:20:39.644763 2026] [security2:error] [pid 229246:tid 229429] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-update.php"] [unique_id "al9H9yBMYeh5YLVG45xgcgAAAkk"]
[Tue Jul 21 07:20:39.663989 2026] [security2:error] [pid 229246:tid 229403] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/erty.php"] [unique_id "al9H9yBMYeh5YLVG45xgdAAAAi8"]
[Tue Jul 21 07:20:39.688875 2026] [security2:error] [pid 230252:tid 230428] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al9H900Dwhk5-Z44Xro7GwAAAsU"]
[Tue Jul 21 07:20:39.700672 2026] [security2:error] [pid 230252:tid 230457] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/like.php"] [unique_id "al9H900Dwhk5-Z44Xro7HAAAAuI"]
[Tue Jul 21 07:20:39.713628 2026] [security2:error] [pid 230252:tid 230426] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/bless5.php"] [unique_id "al9H900Dwhk5-Z44Xro7HQAAAsM"]
[Tue Jul 21 07:20:39.724649 2026] [security2:error] [pid 230252:tid 230387] [client 4.204.201.85:17806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/122.php"] [unique_id "al9H900Dwhk5-Z44Xro7HgAAApw"]
[Tue Jul 21 07:20:39.724971 2026] [security2:error] [pid 230252:tid 230401] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/t.php"] [unique_id "al9H900Dwhk5-Z44Xro7HwAAAqo"]
[Tue Jul 21 07:20:39.737015 2026] [security2:error] [pid 229246:tid 229466] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/xoot.php"] [unique_id "al9H9yBMYeh5YLVG45xgdgAAAm4"]
[Tue Jul 21 07:20:39.748403 2026] [security2:error] [pid 229246:tid 229404] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/xqq.php"] [unique_id "al9H9yBMYeh5YLVG45xgdwAAAjA"]
[Tue Jul 21 07:20:39.760846 2026] [security2:error] [pid 229246:tid 229478] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-load.php"] [unique_id "al9H9yBMYeh5YLVG45xgeAAAAno"]
[Tue Jul 21 07:20:39.772939 2026] [security2:error] [pid 229246:tid 229484] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/x.php"] [unique_id "al9H9yBMYeh5YLVG45xgeQAAAoA"]
[Tue Jul 21 07:20:39.798940 2026] [security2:error] [pid 229246:tid 229460] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/i.php"] [unique_id "al9H9yBMYeh5YLVG45xgegAAAmg"]
[Tue Jul 21 07:20:39.807908 2026] [http2:warn] [pid 229246:tid 229395] [client 57.141.18.21:25248] h2_stream(229246-221-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:39.812785 2026] [security2:error] [pid 229246:tid 229421] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ms-edit.php"] [unique_id "al9H9yBMYeh5YLVG45xgewAAAkE"]
[Tue Jul 21 07:20:39.816319 2026] [security2:error] [pid 230252:tid 230397] [client 20.197.192.193:6873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/wp-explorer.php"] [unique_id "al9H900Dwhk5-Z44Xro7IAAAAqY"]
[Tue Jul 21 07:20:39.824337 2026] [security2:error] [pid 229246:tid 229392] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/v2.php"] [unique_id "al9H9yBMYeh5YLVG45xgfAAAAiQ"]
[Tue Jul 21 07:20:39.836964 2026] [security2:error] [pid 229246:tid 229481] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/new.php"] [unique_id "al9H9yBMYeh5YLVG45xgfQAAAn0"]
[Tue Jul 21 07:20:39.844021 2026] [security2:error] [pid 229246:tid 229480] [client 20.151.10.161:12043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/goods.php"] [unique_id "al9H9yBMYeh5YLVG45xgfgAAAnw"]
[Tue Jul 21 07:20:39.850745 2026] [security2:error] [pid 229246:tid 229441] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-admin/network/edit.php"] [unique_id "al9H9yBMYeh5YLVG45xgfwAAAlU"]
[Tue Jul 21 07:20:39.870624 2026] [security2:error] [pid 229246:tid 229474] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/pouhg.php"] [unique_id "al9H9yBMYeh5YLVG45xggAAAAnY"]
[Tue Jul 21 07:20:39.883187 2026] [security2:error] [pid 229246:tid 229496] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/cilus.php"] [unique_id "al9H9yBMYeh5YLVG45xggQAAAow"]
[Tue Jul 21 07:20:39.897357 2026] [security2:error] [pid 230252:tid 230497] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/file4.php"] [unique_id "al9H900Dwhk5-Z44Xro7IQAAAwo"]
[Tue Jul 21 07:20:39.912750 2026] [security2:error] [pid 230252:tid 230472] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/samll.php"] [unique_id "al9H900Dwhk5-Z44Xro7IgAAAvE"]
[Tue Jul 21 07:20:39.927480 2026] [security2:error] [pid 230252:tid 230464] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/Okxob.php"] [unique_id "al9H900Dwhk5-Z44Xro7IwAAAuk"]
[Tue Jul 21 07:20:39.939156 2026] [security2:error] [pid 230252:tid 230501] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ok.php"] [unique_id "al9H900Dwhk5-Z44Xro7JAAAAw4"]
[Tue Jul 21 07:20:39.951444 2026] [security2:error] [pid 229246:tid 229410] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wuasr.php"] [unique_id "al9H9yBMYeh5YLVG45xgggAAAjY"]
[Tue Jul 21 07:20:39.962935 2026] [security2:error] [pid 229246:tid 229491] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/bless11.php"] [unique_id "al9H9yBMYeh5YLVG45xggwAAAoc"]
[Tue Jul 21 07:20:39.976850 2026] [security2:error] [pid 229246:tid 229398] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-block.php"] [unique_id "al9H9yBMYeh5YLVG45xghAAAAio"]
[Tue Jul 21 07:20:39.988926 2026] [security2:error] [pid 229246:tid 229503] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/aevly.php"] [unique_id "al9H9yBMYeh5YLVG45xghQAAApM"]
[Tue Jul 21 07:20:40.002198 2026] [security2:error] [pid 230252:tid 230452] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/hello.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7JQAAAt0"]
[Tue Jul 21 07:20:40.015990 2026] [security2:error] [pid 229246:tid 229452] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-links-opml.php"] [unique_id "al9H-CBMYeh5YLVG45xghgAAAmA"]
[Tue Jul 21 07:20:40.028792 2026] [security2:error] [pid 230252:tid 230461] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/forbidals.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7JwAAAuY"]
[Tue Jul 21 07:20:40.045415 2026] [security2:error] [pid 230252:tid 230424] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/file30.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7KQAAAsE"]
[Tue Jul 21 07:20:40.056808 2026] [security2:error] [pid 229246:tid 229438] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/xda.php"] [unique_id "al9H-CBMYeh5YLVG45xgiQAAAlI"]
[Tue Jul 21 07:20:40.070550 2026] [security2:error] [pid 229246:tid 229477] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/z.php"] [unique_id "al9H-CBMYeh5YLVG45xgigAAAnk"]
[Tue Jul 21 07:20:40.085427 2026] [security2:error] [pid 229246:tid 229413] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/b.php"] [unique_id "al9H-CBMYeh5YLVG45xgjAAAAjk"]
[Tue Jul 21 07:20:40.101407 2026] [security2:error] [pid 229246:tid 229388] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/edit.php"] [unique_id "al9H-CBMYeh5YLVG45xgjQAAAiA"]
[Tue Jul 21 07:20:40.113033 2026] [security2:error] [pid 229246:tid 229439] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/app.php"] [unique_id "al9H-CBMYeh5YLVG45xgjgAAAlM"]
[Tue Jul 21 07:20:40.130961 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-png.php"] [unique_id "al9H-CBMYeh5YLVG45xgjwAAAms"]
[Tue Jul 21 07:20:40.132104 2026] [security2:error] [pid 230252:tid 230410] [client 20.104.96.117:59181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/xwpg.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7LQAAArM"]
[Tue Jul 21 07:20:40.144208 2026] [security2:error] [pid 229246:tid 229501] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/lib.php"] [unique_id "al9H-CBMYeh5YLVG45xgkAAAApE"]
[Tue Jul 21 07:20:40.152444 2026] [security2:error] [pid 230252:tid 230465] [client 20.151.10.161:45905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/goods.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7LgAAAuo"]
[Tue Jul 21 07:20:40.159473 2026] [security2:error] [pid 229246:tid 229470] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/sys.php"] [unique_id "al9H-CBMYeh5YLVG45xgkQAAAnI"]
[Tue Jul 21 07:20:40.173825 2026] [security2:error] [pid 230252:tid 230395] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/la.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7LwAAAqQ"]
[Tue Jul 21 07:20:40.186617 2026] [security2:error] [pid 230252:tid 230493] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/tires.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7MAAAAwY"]
[Tue Jul 21 07:20:40.198950 2026] [security2:error] [pid 230252:tid 230425] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/lv.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7MQAAAsI"]
[Tue Jul 21 07:20:40.211681 2026] [security2:error] [pid 230252:tid 230440] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/myfile.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7MgAAAtE"]
[Tue Jul 21 07:20:40.235709 2026] [security2:error] [pid 229246:tid 229401] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/06.php"] [unique_id "al9H-CBMYeh5YLVG45xgkgAAAi0"]
[Tue Jul 21 07:20:40.243764 2026] [security2:error] [pid 230252:tid 230434] [client 20.151.10.161:55291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ms-edit.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7MwAAAss"]
[Tue Jul 21 07:20:40.250505 2026] [security2:error] [pid 229246:tid 229456] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/fs.php"] [unique_id "al9H-CBMYeh5YLVG45xgkwAAAmQ"]
[Tue Jul 21 07:20:40.265396 2026] [security2:error] [pid 229246:tid 229394] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/asasx.php"] [unique_id "al9H-CBMYeh5YLVG45xglQAAAiY"]
[Tue Jul 21 07:20:40.284037 2026] [security2:error] [pid 230252:tid 230400] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-kd4xalrg7m.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7NAAAAqk"]
[Tue Jul 21 07:20:40.296606 2026] [security2:error] [pid 230252:tid 230419] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-good.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7NQAAArw"]
[Tue Jul 21 07:20:40.313924 2026] [security2:error] [pid 229246:tid 229380] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/scxy.php"] [unique_id "al9H-CBMYeh5YLVG45xglgAAAhg"]
[Tue Jul 21 07:20:40.329719 2026] [security2:error] [pid 230252:tid 230426] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wmore1.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7NwAAAsM"]
[Tue Jul 21 07:20:40.340984 2026] [security2:error] [pid 230252:tid 230387] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/like.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7OAAAApw"]
[Tue Jul 21 07:20:40.376074 2026] [security2:error] [pid 230252:tid 230389] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/x.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7OQAAAp4"]
[Tue Jul 21 07:20:40.391871 2026] [security2:error] [pid 230252:tid 230489] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/xa.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7OgAAAwI"]
[Tue Jul 21 07:20:40.408761 2026] [security2:error] [pid 230252:tid 230498] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/kolda.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7OwAAAws"]
[Tue Jul 21 07:20:40.427321 2026] [security2:error] [pid 230252:tid 230407] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-aothait.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7PAAAArA"]
[Tue Jul 21 07:20:40.455555 2026] [security2:error] [pid 230252:tid 230481] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ftde.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7PgAAAvo"]
[Tue Jul 21 07:20:40.471347 2026] [security2:error] [pid 230252:tid 230406] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/vx.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7QAAAAq8"]
[Tue Jul 21 07:20:40.489631 2026] [security2:error] [pid 230252:tid 230452] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/a5.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7QQAAAt0"]
[Tue Jul 21 07:20:40.505103 2026] [security2:error] [pid 230252:tid 230495] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-sing.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7QgAAAwg"]
[Tue Jul 21 07:20:40.518492 2026] [security2:error] [pid 230252:tid 230399] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/database.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7QwAAAqg"]
[Tue Jul 21 07:20:40.531521 2026] [security2:error] [pid 230252:tid 230390] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/explorer/index_.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7RAAAAp8"]
[Tue Jul 21 07:20:40.548538 2026] [security2:error] [pid 230252:tid 230385] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-at.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7RwAAApo"]
[Tue Jul 21 07:20:40.560826 2026] [security2:error] [pid 230252:tid 230473] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-wz.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7SQAAAvI"]
[Tue Jul 21 07:20:40.580077 2026] [security2:error] [pid 230252:tid 230440] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-ver.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7SgAAAtE"]
[Tue Jul 21 07:20:40.600999 2026] [security2:error] [pid 230252:tid 230434] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp5.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7SwAAAss"]
[Tue Jul 21 07:20:40.603233 2026] [security2:error] [pid 229246:tid 229429] [client 20.151.10.161:55274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/222.php"] [unique_id "al9H-CBMYeh5YLVG45xgmgAAAkk"]
[Tue Jul 21 07:20:40.617581 2026] [security2:error] [pid 230252:tid 230476] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-pp.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7TAAAAvU"]
[Tue Jul 21 07:20:40.632760 2026] [security2:error] [pid 230252:tid 230428] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/w3lls.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7TQAAAsU"]
[Tue Jul 21 07:20:40.648340 2026] [security2:error] [pid 230252:tid 230457] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/sbhu.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7TgAAAuI"]
[Tue Jul 21 07:20:40.662312 2026] [security2:error] [pid 230252:tid 230412] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-content/uploads/admin.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7TwAAArU"]
[Tue Jul 21 07:20:40.674592 2026] [security2:error] [pid 230252:tid 230401] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/favicon.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7UAAAAqo"]
[Tue Jul 21 07:20:40.686303 2026] [security2:error] [pid 230252:tid 230454] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/txets.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7UQAAAt8"]
[Tue Jul 21 07:20:40.698313 2026] [security2:error] [pid 229246:tid 229492] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-su.php"] [unique_id "al9H-CBMYeh5YLVG45xgnAAAAog"]
[Tue Jul 21 07:20:40.710533 2026] [security2:error] [pid 229246:tid 229455] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ff.php"] [unique_id "al9H-CBMYeh5YLVG45xgnQAAAmM"]
[Tue Jul 21 07:20:40.716845 2026] [http2:warn] [pid 230252:tid 230485] [client 57.141.18.116:26954] h2_stream(230252-5-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:40.723273 2026] [security2:error] [pid 230252:tid 230389] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/reze.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7UgAAAp4"]
[Tue Jul 21 07:20:40.739567 2026] [security2:error] [pid 230252:tid 230489] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/666.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7VAAAAwI"]
[Tue Jul 21 07:20:40.758914 2026] [security2:error] [pid 229246:tid 229431] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wehrman.php"] [unique_id "al9H-CBMYeh5YLVG45xgoAAAAks"]
[Tue Jul 21 07:20:40.786360 2026] [security2:error] [pid 229246:tid 229412] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-conflg.php"] [unique_id "al9H-CBMYeh5YLVG45xgoQAAAjg"]
[Tue Jul 21 07:20:40.805220 2026] [security2:error] [pid 229246:tid 229473] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ff1.php"] [unique_id "al9H-CBMYeh5YLVG45xgogAAAnU"]
[Tue Jul 21 07:20:40.825363 2026] [security2:error] [pid 229246:tid 229449] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/fff.php"] [unique_id "al9H-CBMYeh5YLVG45xgowAAAl0"]
[Tue Jul 21 07:20:40.857529 2026] [security2:error] [pid 229246:tid 229383] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/amax.php"] [unique_id "al9H-CBMYeh5YLVG45xgpAAAAhs"]
[Tue Jul 21 07:20:40.869501 2026] [security2:error] [pid 230252:tid 230498] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-firewall.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7VQAAAws"]
[Tue Jul 21 07:20:40.880477 2026] [security2:error] [pid 230252:tid 230407] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/appt.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7VgAAArA"]
[Tue Jul 21 07:20:40.897855 2026] [security2:error] [pid 230252:tid 230472] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-thi.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7VwAAAvE"]
[Tue Jul 21 07:20:40.909390 2026] [security2:error] [pid 230252:tid 230406] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/jj.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7WAAAAq8"]
[Tue Jul 21 07:20:40.920697 2026] [security2:error] [pid 230252:tid 230501] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/333.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7WQAAAw4"]
[Tue Jul 21 07:20:40.922556 2026] [security2:error] [pid 230252:tid 230504] [client 103.121.156.110:61911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7WgAAAxE"]
[Tue Jul 21 07:20:40.922634 2026] [security2:error] [pid 230252:tid 230504] [client 103.121.156.110:61911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7WgAAAxE"]
[Tue Jul 21 07:20:40.928535 2026] [security2:error] [pid 230252:tid 230452] [client 20.151.10.161:46078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ms-edit.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7WwAAAt0"]
[Tue Jul 21 07:20:40.931754 2026] [security2:error] [pid 230252:tid 230461] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/albin.php"] [unique_id "al9H-E0Dwhk5-Z44Xro7XQAAAuY"]
[Tue Jul 21 07:20:40.942949 2026] [security2:error] [pid 229246:tid 229474] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/66.php"] [unique_id "al9H-CBMYeh5YLVG45xgpwAAAnY"]
[Tue Jul 21 07:20:40.955056 2026] [security2:error] [pid 229246:tid 229496] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/motu.php"] [unique_id "al9H-CBMYeh5YLVG45xgqAAAAow"]
[Tue Jul 21 07:20:40.976103 2026] [security2:error] [pid 229246:tid 229410] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/kj.php"] [unique_id "al9H-CBMYeh5YLVG45xgqQAAAjY"]
[Tue Jul 21 07:20:40.996848 2026] [security2:error] [pid 229246:tid 229491] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp4.php"] [unique_id "al9H-CBMYeh5YLVG45xgqgAAAoc"]
[Tue Jul 21 07:20:41.011292 2026] [security2:error] [pid 229246:tid 229398] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/file61.php"] [unique_id "al9H-SBMYeh5YLVG45xgqwAAAio"]
[Tue Jul 21 07:20:41.023940 2026] [security2:error] [pid 229246:tid 229435] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp.php"] [unique_id "al9H-SBMYeh5YLVG45xgrAAAAk8"]
[Tue Jul 21 07:20:41.036345 2026] [security2:error] [pid 229246:tid 229407] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-trackback.php"] [unique_id "al9H-SBMYeh5YLVG45xgrQAAAjM"]
[Tue Jul 21 07:20:41.067722 2026] [security2:error] [pid 230252:tid 230385] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/db.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7ZAAAApo"]
[Tue Jul 21 07:20:41.070346 2026] [security2:error] [pid 229246:tid 229393] [client 20.151.10.161:12071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9H-SBMYeh5YLVG45xgrgAAAiU"]
[Tue Jul 21 07:20:41.080705 2026] [security2:error] [pid 230252:tid 230465] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/NewFile.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7ZQAAAuo"]
[Tue Jul 21 07:20:41.097031 2026] [security2:error] [pid 229246:tid 229381] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/xxx.php"] [unique_id "al9H-SBMYeh5YLVG45xgsgAAAhk"]
[Tue Jul 21 07:20:41.131013 2026] [security2:error] [pid 229246:tid 229428] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/ms.php"] [unique_id "al9H-SBMYeh5YLVG45xgswAAAkg"]
[Tue Jul 21 07:20:41.142888 2026] [security2:error] [pid 229246:tid 229471] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/mini.php"] [unique_id "al9H-SBMYeh5YLVG45xgtAAAAnM"]
[Tue Jul 21 07:20:41.154252 2026] [security2:error] [pid 229246:tid 229386] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/first.php"] [unique_id "al9H-SBMYeh5YLVG45xgtQAAAh4"]
[Tue Jul 21 07:20:41.174922 2026] [security2:error] [pid 229246:tid 229387] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/0okj.php"] [unique_id "al9H-SBMYeh5YLVG45xgtgAAAh8"]
[Tue Jul 21 07:20:41.202120 2026] [security2:error] [pid 229246:tid 229391] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/grsiuk.php"] [unique_id "al9H-SBMYeh5YLVG45xgtwAAAiM"]
[Tue Jul 21 07:20:41.220660 2026] [security2:error] [pid 229246:tid 229384] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/shell20211028.php"] [unique_id "al9H-SBMYeh5YLVG45xguAAAAhw"]
[Tue Jul 21 07:20:41.237254 2026] [security2:error] [pid 229246:tid 229495] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/revealability.php"] [unique_id "al9H-SBMYeh5YLVG45xguQAAAos"]
[Tue Jul 21 07:20:41.255406 2026] [security2:error] [pid 229246:tid 229422] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/btx25.php"] [unique_id "al9H-SBMYeh5YLVG45xguwAAAkI"]
[Tue Jul 21 07:20:41.274772 2026] [security2:error] [pid 230252:tid 230423] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/bthil.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7ZwAAAsA"]
[Tue Jul 21 07:20:41.293441 2026] [security2:error] [pid 230252:tid 230510] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/hplfuns.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7aAAAAxc"]
[Tue Jul 21 07:20:41.310844 2026] [security2:error] [pid 230252:tid 230396] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/error.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7aQAAAqU"]
[Tue Jul 21 07:20:41.328334 2026] [security2:error] [pid 229246:tid 229406] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/edit.php"] [unique_id "al9H-SBMYeh5YLVG45xgvgAAAjI"]
[Tue Jul 21 07:20:41.344731 2026] [security2:error] [pid 229246:tid 229414] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/pass4.php"] [unique_id "al9H-SBMYeh5YLVG45xgvwAAAjo"]
[Tue Jul 21 07:20:41.361628 2026] [security2:error] [pid 229246:tid 229482] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/sadcut1.php"] [unique_id "al9H-SBMYeh5YLVG45xgwQAAAn4"]
[Tue Jul 21 07:20:41.378735 2026] [security2:error] [pid 229246:tid 229485] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/bgymj.php"] [unique_id "al9H-SBMYeh5YLVG45xgwgAAAoE"]
[Tue Jul 21 07:20:41.392363 2026] [security2:error] [pid 229246:tid 229455] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/yas.php"] [unique_id "al9H-SBMYeh5YLVG45xgwwAAAmM"]
[Tue Jul 21 07:20:41.406847 2026] [security2:error] [pid 229246:tid 229466] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/dx.php"] [unique_id "al9H-SBMYeh5YLVG45xgxAAAAm4"]
[Tue Jul 21 07:20:41.412796 2026] [security2:error] [pid 229246:tid 229404] [client 4.204.201.85:17872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/get.php"] [unique_id "al9H-SBMYeh5YLVG45xgxQAAAjA"]
[Tue Jul 21 07:20:41.420114 2026] [security2:error] [pid 230252:tid 230447] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/yellow.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7awAAAtg"]
[Tue Jul 21 07:20:41.432037 2026] [security2:error] [pid 229246:tid 229478] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/wp-der.php"] [unique_id "al9H-SBMYeh5YLVG45xgxgAAAno"]
[Tue Jul 21 07:20:41.443961 2026] [security2:error] [pid 229246:tid 229382] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/lala.php"] [unique_id "al9H-SBMYeh5YLVG45xgxwAAAho"]
[Tue Jul 21 07:20:41.451291 2026] [security2:error] [pid 229246:tid 229430] [client 114.119.128.132:55045] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rtdi.com.br"] [uri "/imoveis/sao-paulo/cidade-moncoes"] [unique_id "al9H-SBMYeh5YLVG45xgyAAAAko"], referer: https://www.rtdi.com.br/imoveis/para-alugar/apartamento%2Bcasa/vila-andrade/sao-paulo?quartos=3%2B&suites=1%2B&caracteristicas=-em-condominio-fechado
[Tue Jul 21 07:20:41.455001 2026] [security2:error] [pid 229246:tid 229484] [client 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.micheleelizabethpere1742863748215.0721679.myhostgator.site"] [uri "/aa.php"] [unique_id "al9H-SBMYeh5YLVG45xgyQAAAoA"]
[Tue Jul 21 07:20:41.481521 2026] [security2:error] [pid 229246:tid 229460] [client 114.119.129.97:29525] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.vivermaishospital.com.br"] [uri "/agendamento-online/"] [unique_id "al9H-SBMYeh5YLVG45xgygAAAmg"], referer: http://www.vivermaishospital.com.br/fale-conosco/
[Tue Jul 21 07:20:41.566291 2026] [security2:error] [pid 230252:tid 230445] [client 103.162.129.114:60464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7bAAAAtY"]
[Tue Jul 21 07:20:41.566409 2026] [security2:error] [pid 230252:tid 230445] [client 103.162.129.114:60464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7bAAAAtY"]
[Tue Jul 21 07:20:41.648443 2026] [security2:error] [pid 229246:tid 229444] [client 20.151.10.161:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9H-SBMYeh5YLVG45xgzwAAAlg"]
[Tue Jul 21 07:20:41.947382 2026] [http2:warn] [pid 229246:tid 229434] [client 57.141.18.76:64566] h2_stream(229246-226-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:41.956193 2026] [security2:error] [pid 230252:tid 230332] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7cQADFE0"]
[Tue Jul 21 07:20:41.956374 2026] [security2:error] [pid 230252:tid 230507] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7cQADFE0"]
[Tue Jul 21 07:20:41.976165 2026] [security2:error] [pid 230252:tid 230486] [client 160.30.136.8:52031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9H-U0Dwhk5-Z44Xro7cgAAAv8"]
[Tue Jul 21 07:20:42.009060 2026] [security2:error] [pid 230252:tid 230470] [client 20.151.10.161:45845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/222.php"] [unique_id "al9H-k0Dwhk5-Z44Xro7cwAAAu8"]
[Tue Jul 21 07:20:42.252204 2026] [security2:error] [pid 229246:tid 229439] [client 20.220.225.223:43066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/old.php"] [unique_id "al9H-iBMYeh5YLVG45xg2QAAAlM"]
[Tue Jul 21 07:20:42.308361 2026] [security2:error] [pid 230252:tid 230472] [client 20.104.96.117:59184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ops.php"] [unique_id "al9H-k0Dwhk5-Z44Xro7dQAAAvE"]
[Tue Jul 21 07:20:42.369991 2026] [qos:error] [pid 230252:tid 230337] [remote 57.141.18.24:65348] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.24, id=al9H-k0Dwhk5-Z44Xro7dgAC6VI
[Tue Jul 21 07:20:42.472234 2026] [security2:error] [pid 230252:tid 230336] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H-k0Dwhk5-Z44Xro7dwAC-lE"]
[Tue Jul 21 07:20:42.472367 2026] [security2:error] [pid 230252:tid 230481] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9H-k0Dwhk5-Z44Xro7dwAC-lE"]
[Tue Jul 21 07:20:42.503569 2026] [http2:warn] [pid 229246:tid 229475] [client 57.141.18.14:62686] h2_stream(229246-228-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:42.542419 2026] [qos:error] [pid 229246:tid 229273] [remote 57.141.18.102:23364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.102, id=al9H-iBMYeh5YLVG45xg3AACHxo
[Tue Jul 21 07:20:42.656330 2026] [security2:error] [pid 229246:tid 229401] [client 20.151.10.161:12055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp.php"] [unique_id "al9H-iBMYeh5YLVG45xg3gAAAi0"]
[Tue Jul 21 07:20:42.683233 2026] [security2:error] [pid 229246:tid 229422] [client 160.30.136.8:56253] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestdealsvalmir.com"] [uri "/"] [unique_id "al9H-iBMYeh5YLVG45xg4AAAAkI"]
[Tue Jul 21 07:20:42.708333 2026] [autoindex:error] [pid 230252:tid 230452] [client 205.210.31.167:61250] AH01276: Cannot serve directory /home2/setpoi24/public_html/setpointgeradores.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:20:42.877951 2026] [security2:error] [pid 230252:tid 230413] [client 20.220.225.223:52755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/acew67.php"] [unique_id "al9H-k0Dwhk5-Z44Xro7egAAArY"]
[Tue Jul 21 07:20:42.903008 2026] [core:error] [pid 230252:tid 230378] [remote 40.77.167.79:45085] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:42.903026 2026] [core:error] [pid 230252:tid 230378] [remote 40.77.167.79:45085] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:20:42.942024 2026] [security2:error] [pid 229246:tid 229405] [client 74.249.245.134:54550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ms-edit.php"] [unique_id "al9H-iBMYeh5YLVG45xg5AAAAjE"]
[Tue Jul 21 07:20:42.998365 2026] [security2:error] [pid 229246:tid 229389] [client 20.151.10.161:12048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/abcd.php"] [unique_id "al9H-iBMYeh5YLVG45xg5QAAAiE"]
[Tue Jul 21 07:20:43.371453 2026] [security2:error] [pid 229246:tid 229404] [client 4.204.201.85:17864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/as.php"] [unique_id "al9H-yBMYeh5YLVG45xg6QAAAjA"]
[Tue Jul 21 07:20:43.387553 2026] [security2:error] [pid 229246:tid 229429] [client 160.30.136.8:63143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9H-yBMYeh5YLVG45xg6gAAAkk"]
[Tue Jul 21 07:20:43.469321 2026] [security2:error] [pid 230252:tid 230440] [client 20.197.192.193:26887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/mimpi.php"] [unique_id "al9H-00Dwhk5-Z44Xro7fwAAAtE"]
[Tue Jul 21 07:20:43.541999 2026] [http2:warn] [pid 229246:tid 229490] [client 57.141.18.25:33736] h2_stream(229246-233-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:43.545655 2026] [security2:error] [pid 230252:tid 230400] [client 20.151.10.161:55267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/a1.php"] [unique_id "al9H-00Dwhk5-Z44Xro7gAAAAqk"]
[Tue Jul 21 07:20:43.715870 2026] [proxy:error] [pid 229246:tid 229392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:20:43.715930 2026] [proxy_http:error] [pid 229246:tid 229392] [client 205.210.31.51:60862] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:20:43.716523 2026] [proxy:error] [pid 229246:tid 229392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:20:43.716564 2026] [proxy_http:error] [pid 229246:tid 229392] [client 205.210.31.51:60862] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:20:43.749424 2026] [security2:error] [pid 229246:tid 229474] [client 20.151.10.161:46012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9H-yBMYeh5YLVG45xg8wAAAnY"]
[Tue Jul 21 07:20:43.818674 2026] [security2:error] [pid 230252:tid 230428] [client 209.141.34.121:64405] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "amandatorresestetica.com.br"] [uri "/"] [unique_id "al9H-00Dwhk5-Z44Xro7gwAAAsU"]
[Tue Jul 21 07:20:43.858191 2026] [security2:error] [pid 229246:tid 229497] [client 20.197.192.193:6848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/akismet.php"] [unique_id "al9H-yBMYeh5YLVG45xg9QAAAo0"]
[Tue Jul 21 07:20:43.978790 2026] [security2:error] [pid 229246:tid 229431] [client 45.251.232.145:63216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H-yBMYeh5YLVG45xg9wAAAks"]
[Tue Jul 21 07:20:43.978916 2026] [security2:error] [pid 229246:tid 229431] [client 45.251.232.145:63216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H-yBMYeh5YLVG45xg9wAAAks"]
[Tue Jul 21 07:20:43.996391 2026] [security2:error] [pid 230252:tid 230454] [client 20.151.10.161:55262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9H-00Dwhk5-Z44Xro7hwAAAt8"]
[Tue Jul 21 07:20:44.096066 2026] [security2:error] [pid 230252:tid 230426] [client 160.30.136.8:59663] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestdealsvalmir.com"] [uri "/"] [unique_id "al9H_E0Dwhk5-Z44Xro7iQAAAsM"]
[Tue Jul 21 07:20:44.193167 2026] [security2:error] [pid 230252:tid 230486] [client 4.204.201.85:17883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ccou.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7jQAAAv8"]
[Tue Jul 21 07:20:44.242410 2026] [security2:error] [pid 230252:tid 230384] [client 37.140.223.69:29189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7kAAAApk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:44.333946 2026] [security2:error] [pid 230252:tid 230466] [client 209.141.34.121:64475] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "amandatorresestetica.com.br"] [uri "/"] [unique_id "al9H_E0Dwhk5-Z44Xro7kgAAAus"]
[Tue Jul 21 07:20:44.436255 2026] [security2:error] [pid 230252:tid 230461] [client 20.104.96.117:59679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/mac.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7mQAAAuY"]
[Tue Jul 21 07:20:44.509443 2026] [security2:error] [pid 230252:tid 230385] [client 20.151.10.161:46015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7mgAAApo"]
[Tue Jul 21 07:20:44.510600 2026] [security2:error] [pid 229246:tid 229286] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H_CBMYeh5YLVG45xhAAACiSc"]
[Tue Jul 21 07:20:44.510766 2026] [security2:error] [pid 229246:tid 229493] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9H_CBMYeh5YLVG45xhAAACiSc"]
[Tue Jul 21 07:20:44.540655 2026] [security2:error] [pid 229246:tid 229460] [client 14.139.42.196:4212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H_CBMYeh5YLVG45xhAQAAAmg"]
[Tue Jul 21 07:20:44.540750 2026] [security2:error] [pid 229246:tid 229460] [client 14.139.42.196:4212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H_CBMYeh5YLVG45xhAQAAAmg"]
[Tue Jul 21 07:20:44.806156 2026] [security2:error] [pid 230252:tid 230404] [client 134.19.179.187:54424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7mwAAAq0"]
[Tue Jul 21 07:20:44.806264 2026] [security2:error] [pid 230252:tid 230404] [client 134.19.179.187:54424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7mwAAAq0"]
[Tue Jul 21 07:20:44.812210 2026] [security2:error] [pid 229246:tid 229401] [client 160.30.136.8:60430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9H_CBMYeh5YLVG45xhCQAAAi0"]
[Tue Jul 21 07:20:44.872081 2026] [security2:error] [pid 229246:tid 229446] [client 4.204.201.85:17807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/w3lls.php"] [unique_id "al9H_CBMYeh5YLVG45xhCgAAAlo"]
[Tue Jul 21 07:20:44.917571 2026] [security2:error] [pid 229246:tid 229495] [client 20.151.10.161:11729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9H_CBMYeh5YLVG45xhCwAAAos"]
[Tue Jul 21 07:20:44.992939 2026] [security2:error] [pid 230252:tid 230440] [client 184.75.221.3:47452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7nQAAAtE"]
[Tue Jul 21 07:20:44.993099 2026] [security2:error] [pid 230252:tid 230440] [client 184.75.221.3:47452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9H_E0Dwhk5-Z44Xro7nQAAAtE"]
[Tue Jul 21 07:20:45.088645 2026] [security2:error] [pid 230252:tid 230360] [remote 42.200.84.61:33100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "prissedermatologia.com.br"] [uri "/wp-login.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7owADCGk"]
[Tue Jul 21 07:20:45.091963 2026] [security2:error] [pid 230252:tid 230342] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7pAAC8Fc"]
[Tue Jul 21 07:20:45.108766 2026] [security2:error] [pid 230252:tid 230344] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7pQACvFk"]
[Tue Jul 21 07:20:45.127748 2026] [security2:error] [pid 230252:tid 230353] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/dp.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7pgACxWI"]
[Tue Jul 21 07:20:45.158486 2026] [security2:error] [pid 230252:tid 230355] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/old.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7pwACx2Q"]
[Tue Jul 21 07:20:45.178823 2026] [security2:error] [pid 230252:tid 230380] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/ms-new.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7qAACqn0"]
[Tue Jul 21 07:20:45.188268 2026] [qos:error] [pid 230252:tid 230368] [remote 57.141.18.74:37864] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.74, id=al9H_U0Dwhk5-Z44Xro7qgAC2HE
[Tue Jul 21 07:20:45.203658 2026] [security2:error] [pid 230252:tid 230372] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/track.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7qwAC0HU"]
[Tue Jul 21 07:20:45.211014 2026] [http2:warn] [pid 229246:tid 229445] [client 57.141.18.2:30472] h2_stream(229246-238-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:45.223636 2026] [security2:error] [pid 230252:tid 230369] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/2352356666.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7rAACtXI"]
[Tue Jul 21 07:20:45.243952 2026] [security2:error] [pid 230252:tid 230371] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/pn.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7rQACw3Q"]
[Tue Jul 21 07:20:45.248947 2026] [security2:error] [pid 230252:tid 230489] [client 20.151.10.161:11724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/gettest.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7rgAAAwI"]
[Tue Jul 21 07:20:45.266004 2026] [security2:error] [pid 230252:tid 230374] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wp-wpbak.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7sAAC53c"]
[Tue Jul 21 07:20:45.288894 2026] [security2:error] [pid 230252:tid 230276] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/dr.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7sQACtxY"]
[Tue Jul 21 07:20:45.308430 2026] [security2:error] [pid 230252:tid 230367] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/2x.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7sgADC3A"]
[Tue Jul 21 07:20:45.328595 2026] [security2:error] [pid 230252:tid 230283] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/kq1.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7swACzR0"]
[Tue Jul 21 07:20:45.346199 2026] [security2:error] [pid 230252:tid 230296] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/zzz.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7tAADCio"]
[Tue Jul 21 07:20:45.367759 2026] [security2:error] [pid 230252:tid 230373] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wicked.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7tQAC8XY"]
[Tue Jul 21 07:20:45.383840 2026] [security2:error] [pid 230252:tid 230370] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/edit.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7tgADFHM"]
[Tue Jul 21 07:20:45.404044 2026] [security2:error] [pid 230252:tid 230376] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/kua.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7twAC6Xk"]
[Tue Jul 21 07:20:45.419331 2026] [security2:error] [pid 230252:tid 230451] [client 4.204.201.85:17813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/test1.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7uAAAAtw"]
[Tue Jul 21 07:20:45.420537 2026] [security2:error] [pid 230252:tid 230294] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/ez.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7uQAC6yg"]
[Tue Jul 21 07:20:45.438764 2026] [security2:error] [pid 230252:tid 230264] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/fz.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7ugAC-go"]
[Tue Jul 21 07:20:45.459112 2026] [security2:error] [pid 230252:tid 230366] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/la.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7uwADDW8"]
[Tue Jul 21 07:20:45.471082 2026] [security2:error] [pid 229246:tid 229403] [client 20.226.60.151:54537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/uoocf.php"] [unique_id "al9H_SBMYeh5YLVG45xhEQAAAi8"]
[Tue Jul 21 07:20:45.477031 2026] [http2:warn] [pid 230252:tid 230448] [client 57.141.18.69:34688] h2_stream(230252-8-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:45.479806 2026] [security2:error] [pid 230252:tid 230282] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/nhvoanpl.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7vAACxhw"]
[Tue Jul 21 07:20:45.501759 2026] [security2:error] [pid 230252:tid 230274] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/inso.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7vQAC5hQ"]
[Tue Jul 21 07:20:45.519293 2026] [security2:error] [pid 230252:tid 230304] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wpx.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7vgACqDI"]
[Tue Jul 21 07:20:45.521599 2026] [security2:error] [pid 229246:tid 229492] [client 160.30.136.8:64579] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestdealsvalmir.com"] [uri "/"] [unique_id "al9H_SBMYeh5YLVG45xhEwAAAog"]
[Tue Jul 21 07:20:45.538928 2026] [security2:error] [pid 230252:tid 230268] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/berlin.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7vwAC_g4"]
[Tue Jul 21 07:20:45.559196 2026] [security2:error] [pid 230252:tid 230312] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/billur.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7wAACtjo"]
[Tue Jul 21 07:20:45.580238 2026] [security2:error] [pid 230252:tid 230311] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/mimpi.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7wQACmjk"]
[Tue Jul 21 07:20:45.598011 2026] [security2:error] [pid 230252:tid 230260] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/dp.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7wgAC6gY"]
[Tue Jul 21 07:20:45.618074 2026] [security2:error] [pid 230252:tid 230310] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/bootstrap.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7wwACrTg"]
[Tue Jul 21 07:20:45.636536 2026] [security2:error] [pid 230252:tid 230306] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wp-editor.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7xAADGDQ"]
[Tue Jul 21 07:20:45.654501 2026] [security2:error] [pid 230252:tid 230288] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/cro.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7xQADBiI"]
[Tue Jul 21 07:20:45.672363 2026] [security2:error] [pid 230252:tid 230357] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/cron-tab.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7xgAC0WY"]
[Tue Jul 21 07:20:45.688747 2026] [security2:error] [pid 230252:tid 230254] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/koiy.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7xwACoQA"]
[Tue Jul 21 07:20:45.704720 2026] [security2:error] [pid 230252:tid 230275] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/hp2.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7yAACqRU"]
[Tue Jul 21 07:20:45.726980 2026] [security2:error] [pid 230252:tid 230285] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/hp3.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7yQADCR8"]
[Tue Jul 21 07:20:45.745373 2026] [security2:error] [pid 230252:tid 230314] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/aa1.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7ygADCDw"]
[Tue Jul 21 07:20:45.766035 2026] [security2:error] [pid 230252:tid 230290] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/acew67.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7ywAC1iQ"]
[Tue Jul 21 07:20:45.783637 2026] [security2:error] [pid 230252:tid 230263] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/bscclapb.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7zQACxQk"]
[Tue Jul 21 07:20:45.806493 2026] [security2:error] [pid 230252:tid 230315] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/else1.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7zgACxz0"]
[Tue Jul 21 07:20:45.823037 2026] [security2:error] [pid 230252:tid 230316] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/tkikikoko.php"] [unique_id "al9H_U0Dwhk5-Z44Xro7zwACnD4"]
[Tue Jul 21 07:20:45.846434 2026] [security2:error] [pid 230252:tid 230273] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wp-Blogs.php"] [unique_id "al9H_U0Dwhk5-Z44Xro70AACqhM"]
[Tue Jul 21 07:20:45.863437 2026] [security2:error] [pid 230252:tid 230287] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wp-css.php"] [unique_id "al9H_U0Dwhk5-Z44Xro70QAC0CE"]
[Tue Jul 21 07:20:45.886428 2026] [security2:error] [pid 230252:tid 230300] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/wp-explorer.php"] [unique_id "al9H_U0Dwhk5-Z44Xro70wACwy4"]
[Tue Jul 21 07:20:45.905192 2026] [security2:error] [pid 230252:tid 230298] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/akismet.php"] [unique_id "al9H_U0Dwhk5-Z44Xro71AAC5yw"]
[Tue Jul 21 07:20:45.922311 2026] [security2:error] [pid 230252:tid 230271] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/ace2.php"] [unique_id "al9H_U0Dwhk5-Z44Xro71QAC9RE"]
[Tue Jul 21 07:20:45.939221 2026] [security2:error] [pid 230252:tid 230265] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.githec.com"] [uri "/ms.php"] [unique_id "al9H_U0Dwhk5-Z44Xro71gAC_ws"]
[Tue Jul 21 07:20:45.988713 2026] [security2:error] [pid 230252:tid 230498] [client 20.151.10.161:12070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/simple.php"] [unique_id "al9H_U0Dwhk5-Z44Xro71wAAAws"]
[Tue Jul 21 07:20:46.075114 2026] [security2:error] [pid 230252:tid 230255] [remote 51.195.39.149:60374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mgdcondominial.com.br"] [uri "/"] [unique_id "al9H_k0Dwhk5-Z44Xro72gAC3wE"]
[Tue Jul 21 07:20:46.178614 2026] [security2:error] [pid 230252:tid 230461] [client 20.151.10.161:45930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp.php"] [unique_id "al9H_k0Dwhk5-Z44Xro74AAAAuY"]
[Tue Jul 21 07:20:46.193900 2026] [http2:warn] [pid 229246:tid 229416] [client 57.141.18.25:38266] h2_stream(229246-241-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:46.252429 2026] [security2:error] [pid 229246:tid 229421] [client 160.30.136.8:54467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9H_iBMYeh5YLVG45xhHAAAAkE"]
[Tue Jul 21 07:20:46.282707 2026] [security2:error] [pid 229246:tid 229478] [client 20.151.10.161:53607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xxx.php"] [unique_id "al9H_iBMYeh5YLVG45xhHwAAAno"]
[Tue Jul 21 07:20:46.525959 2026] [security2:error] [pid 229246:tid 229267] [remote 47.251.82.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.82.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-login.php"] [unique_id "al9H_SBMYeh5YLVG45xhEgACMhQ"]
[Tue Jul 21 07:20:46.617592 2026] [security2:error] [pid 229246:tid 229395] [client 20.104.96.117:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/mg.php"] [unique_id "al9H_iBMYeh5YLVG45xhJgAAAic"]
[Tue Jul 21 07:20:46.671434 2026] [security2:error] [pid 230252:tid 230511] [client 68.235.38.2:49014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9H_k0Dwhk5-Z44Xro74wAAAxg"]
[Tue Jul 21 07:20:46.671565 2026] [security2:error] [pid 230252:tid 230511] [client 68.235.38.2:49014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9H_k0Dwhk5-Z44Xro74wAAAxg"]
[Tue Jul 21 07:20:46.710517 2026] [security2:error] [pid 230252:tid 230416] [client 4.204.201.85:17809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/database.php"] [unique_id "al9H_k0Dwhk5-Z44Xro75AAAArk"]
[Tue Jul 21 07:20:46.729480 2026] [security2:error] [pid 230252:tid 230392] [client 20.220.225.223:34258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/ms-new.php"] [unique_id "al9H_k0Dwhk5-Z44Xro75gAAAqE"]
[Tue Jul 21 07:20:46.730343 2026] [security2:error] [pid 230252:tid 230400] [client 20.197.192.193:6359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/ace2.php"] [unique_id "al9H_k0Dwhk5-Z44Xro75wAAAqk"]
[Tue Jul 21 07:20:46.740477 2026] [security2:error] [pid 230252:tid 230471] [client 20.151.10.161:55266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/hypo.php"] [unique_id "al9H_k0Dwhk5-Z44Xro76AAAAvA"]
[Tue Jul 21 07:20:46.806925 2026] [security2:error] [pid 230252:tid 230445] [client 92.119.178.3:58512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9H_k0Dwhk5-Z44Xro76QAAAtY"]
[Tue Jul 21 07:20:46.807110 2026] [security2:error] [pid 230252:tid 230445] [client 92.119.178.3:58512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9H_k0Dwhk5-Z44Xro76QAAAtY"]
[Tue Jul 21 07:20:46.817939 2026] [security2:error] [pid 230252:tid 230428] [client 20.151.10.161:45973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/abcd.php"] [unique_id "al9H_k0Dwhk5-Z44Xro76wAAAsU"]
[Tue Jul 21 07:20:46.930921 2026] [security2:error] [pid 230252:tid 230486] [client 74.249.245.134:55778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/simple.php"] [unique_id "al9H_k0Dwhk5-Z44Xro77wAAAv8"]
[Tue Jul 21 07:20:46.959623 2026] [security2:error] [pid 230252:tid 230498] [client 160.30.136.8:59751] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestdealsvalmir.com"] [uri "/"] [unique_id "al9H_k0Dwhk5-Z44Xro78AAAAws"]
[Tue Jul 21 07:20:46.963498 2026] [security2:error] [pid 230252:tid 230305] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H_k0Dwhk5-Z44Xro78QADBjM"]
[Tue Jul 21 07:20:46.963731 2026] [security2:error] [pid 230252:tid 230493] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9H_k0Dwhk5-Z44Xro78QADBjM"]
[Tue Jul 21 07:20:47.052963 2026] [security2:error] [pid 230252:tid 230497] [client 20.220.225.223:59483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/bscclapb.php"] [unique_id "al9H_00Dwhk5-Z44Xro78gAAAwo"]
[Tue Jul 21 07:20:47.137237 2026] [security2:error] [pid 230252:tid 230504] [client 20.197.192.193:27175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/dp.php"] [unique_id "al9H_00Dwhk5-Z44Xro79AAAAxE"]
[Tue Jul 21 07:20:47.233617 2026] [security2:error] [pid 230252:tid 230354] [remote 173.252.87.115:55370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9H_00Dwhk5-Z44Xro8NwAC6WM"]
[Tue Jul 21 07:20:47.254479 2026] [security2:error] [pid 230252:tid 230429] [client 20.151.10.161:12076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/chosen.php"] [unique_id "al9H_00Dwhk5-Z44Xro8OAAAAsY"]
[Tue Jul 21 07:20:47.276684 2026] [security2:error] [pid 230252:tid 230409] [client 20.151.10.161:45901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/a1.php"] [unique_id "al9H_00Dwhk5-Z44Xro8OQAAArI"]
[Tue Jul 21 07:20:47.286805 2026] [http2:warn] [pid 229246:tid 229464] [client 57.141.18.50:26728] h2_stream(229246-242-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:47.487119 2026] [security2:error] [pid 230252:tid 230259] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H_00Dwhk5-Z44Xro8RAAC0QU"]
[Tue Jul 21 07:20:47.487269 2026] [security2:error] [pid 230252:tid 230440] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H_00Dwhk5-Z44Xro8RAAC0QU"]
[Tue Jul 21 07:20:47.621115 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:45889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9H_yBMYeh5YLVG45xhMwAAAlo"]
[Tue Jul 21 07:20:47.732718 2026] [access_compat:error] [pid 229246:tid 229479] [client 162.241.63.68:58392] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:20:47.744254 2026] [security2:error] [pid 229246:tid 229386] [client 20.220.225.223:47819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/else1.php"] [unique_id "al9H_yBMYeh5YLVG45xhNwAAAh4"]
[Tue Jul 21 07:20:47.779491 2026] [security2:error] [pid 229246:tid 229470] [client 194.147.58.101:57192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/db_backup.bak"] [unique_id "al9H_yBMYeh5YLVG45xhOAAAAnI"]
[Tue Jul 21 07:20:47.779638 2026] [security2:error] [pid 229246:tid 229442] [client 194.147.58.101:57156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wwwroot.bak"] [unique_id "al9H_yBMYeh5YLVG45xhOQAAAlY"]
[Tue Jul 21 07:20:47.780349 2026] [security2:error] [pid 230252:tid 230495] [client 194.147.58.101:57180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/db.bak"] [unique_id "al9H_00Dwhk5-Z44Xro8TQAAAwg"]
[Tue Jul 21 07:20:47.780351 2026] [security2:error] [pid 230252:tid 230496] [client 194.147.58.101:57152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/sa.bak"] [unique_id "al9H_00Dwhk5-Z44Xro8SwAAAwk"]
[Tue Jul 21 07:20:47.780556 2026] [security2:error] [pid 229246:tid 229387] [client 194.147.58.101:57202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/dbdump.bak"] [unique_id "al9H_yBMYeh5YLVG45xhOgAAAh8"]
[Tue Jul 21 07:20:47.780615 2026] [security2:error] [pid 230252:tid 230471] [client 194.147.58.101:57162] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/dump.bak"] [unique_id "al9H_00Dwhk5-Z44Xro8TAAAAvA"]
[Tue Jul 21 07:20:47.781056 2026] [security2:error] [pid 230252:tid 230445] [client 194.147.58.101:57178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/data.bak"] [unique_id "al9H_00Dwhk5-Z44Xro8TgAAAtY"]
[Tue Jul 21 07:20:47.782205 2026] [security2:error] [pid 230252:tid 230419] [client 194.147.58.101:57214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/backup.bak"] [unique_id "al9H_00Dwhk5-Z44Xro8TwAAArw"]
[Tue Jul 21 07:20:47.783749 2026] [security2:error] [pid 229246:tid 229428] [client 194.147.58.101:57226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/database.bak"] [unique_id "al9H_yBMYeh5YLVG45xhOwAAAkg"]
[Tue Jul 21 07:20:47.804674 2026] [security2:error] [pid 230252:tid 230451] [client 139.135.44.145:53656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H_00Dwhk5-Z44Xro8UAAAAtw"]
[Tue Jul 21 07:20:47.804853 2026] [security2:error] [pid 230252:tid 230451] [client 139.135.44.145:53656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9H_00Dwhk5-Z44Xro8UAAAAtw"]
[Tue Jul 21 07:20:47.831196 2026] [security2:error] [pid 230252:tid 230426] [client 20.151.10.161:55288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/als.php"] [unique_id "al9H_00Dwhk5-Z44Xro8UQAAAsM"]
[Tue Jul 21 07:20:47.862858 2026] [security2:error] [pid 229246:tid 229342] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H_yBMYeh5YLVG45xhPgACd18"]
[Tue Jul 21 07:20:47.863075 2026] [security2:error] [pid 229246:tid 229475] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9H_yBMYeh5YLVG45xhPgACd18"]
[Tue Jul 21 07:20:47.936292 2026] [http2:warn] [pid 230252:tid 230402] [client 57.141.18.15:35936] h2_stream(230252-13-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:48.036186 2026] [qos:error] [pid 229246:tid 229370] [remote 57.141.18.115:65350] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.115, id=al9IACBMYeh5YLVG45xhQgACY3s
[Tue Jul 21 07:20:48.071205 2026] [security2:error] [pid 229246:tid 229497] [client 4.204.201.85:17917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/file.php"] [unique_id "al9IACBMYeh5YLVG45xhRAAAAo0"]
[Tue Jul 21 07:20:48.139168 2026] [security2:error] [pid 229246:tid 229439] [client 175.45.70.82:51305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IACBMYeh5YLVG45xhRgAAAlM"]
[Tue Jul 21 07:20:48.139328 2026] [security2:error] [pid 229246:tid 229439] [client 175.45.70.82:51305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IACBMYeh5YLVG45xhRgAAAlM"]
[Tue Jul 21 07:20:48.146319 2026] [security2:error] [pid 230252:tid 230507] [client 20.220.225.223:34284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/track.php"] [unique_id "al9IAE0Dwhk5-Z44Xro8UwAAAxQ"]
[Tue Jul 21 07:20:48.240487 2026] [security2:error] [pid 230252:tid 230401] [client 136.144.33.215:56797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IAE0Dwhk5-Z44Xro8VAAAAqo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:48.326192 2026] [security2:error] [pid 229246:tid 229398] [client 20.151.10.161:12072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/pol.php"] [unique_id "al9IACBMYeh5YLVG45xhSgAAAio"]
[Tue Jul 21 07:20:48.347747 2026] [security2:error] [pid 229246:tid 229406] [client 20.220.225.223:52752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/ms-new.php"] [unique_id "al9IACBMYeh5YLVG45xhSwAAAjI"]
[Tue Jul 21 07:20:48.638225 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:55275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file5.php"] [unique_id "al9IACBMYeh5YLVG45xhVQAAAns"]
[Tue Jul 21 07:20:48.711639 2026] [security2:error] [pid 229246:tid 229456] [client 20.104.96.117:59683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-post-data.php"] [unique_id "al9IACBMYeh5YLVG45xhVgAAAmQ"]
[Tue Jul 21 07:20:48.722964 2026] [security2:error] [pid 229246:tid 229496] [client 120.61.173.56:55626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IACBMYeh5YLVG45xhVwAAAow"]
[Tue Jul 21 07:20:48.723688 2026] [security2:error] [pid 229246:tid 229496] [client 120.61.173.56:55626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IACBMYeh5YLVG45xhVwAAAow"]
[Tue Jul 21 07:20:48.780131 2026] [security2:error] [pid 229246:tid 229391] [client 194.147.58.101:57244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/br1102.hostgator.com.br.bak"] [unique_id "al9IACBMYeh5YLVG45xhWQAAAiM"]
[Tue Jul 21 07:20:48.782019 2026] [security2:error] [pid 229246:tid 229388] [client 194.147.58.101:57318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/www.bak"] [unique_id "al9IACBMYeh5YLVG45xhWgAAAiA"]
[Tue Jul 21 07:20:48.782176 2026] [security2:error] [pid 229246:tid 229401] [client 194.147.58.101:57324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/translate.bak"] [unique_id "al9IACBMYeh5YLVG45xhXAAAAi0"]
[Tue Jul 21 07:20:48.782247 2026] [security2:error] [pid 230252:tid 230501] [client 194.147.58.101:57284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/mysqldump.bak"] [unique_id "al9IAE0Dwhk5-Z44Xro8WAAAAw4"]
[Tue Jul 21 07:20:48.782292 2026] [security2:error] [pid 229246:tid 229384] [client 194.147.58.101:57344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/sql.bak"] [unique_id "al9IACBMYeh5YLVG45xhWwAAAhw"]
[Tue Jul 21 07:20:48.782296 2026] [security2:error] [pid 230252:tid 230429] [client 194.147.58.101:57274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wp-content/uploads/dump.bak"] [unique_id "al9IAE0Dwhk5-Z44Xro8VwAAAsY"]
[Tue Jul 21 07:20:48.784639 2026] [security2:error] [pid 229246:tid 229377] [client 194.147.58.101:57270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wp-content/mysql.bak"] [unique_id "al9IACBMYeh5YLVG45xhXQAAAhU"]
[Tue Jul 21 07:20:48.784758 2026] [security2:error] [pid 230252:tid 230409] [client 194.147.58.101:57242] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/localhost.bak"] [unique_id "al9IAE0Dwhk5-Z44Xro8WQAAArI"]
[Tue Jul 21 07:20:48.787268 2026] [security2:error] [pid 230252:tid 230461] [client 194.147.58.101:57286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/users.bak"] [unique_id "al9IAE0Dwhk5-Z44Xro8WgAAAuY"]
[Tue Jul 21 07:20:48.787719 2026] [security2:error] [pid 229246:tid 229446] [client 194.147.58.101:57328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/site.bak"] [unique_id "al9IACBMYeh5YLVG45xhXgAAAlo"]
[Tue Jul 21 07:20:48.787784 2026] [security2:error] [pid 230252:tid 230399] [client 194.147.58.101:57256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/br1102.hostgator.com.br_db.bak"] [unique_id "al9IAE0Dwhk5-Z44Xro8WwAAAqg"]
[Tue Jul 21 07:20:48.791184 2026] [security2:error] [pid 230252:tid 230413] [client 194.147.58.101:57306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/mysql.bak"] [unique_id "al9IAE0Dwhk5-Z44Xro8XAAAArY"]
[Tue Jul 21 07:20:48.791201 2026] [security2:error] [pid 229246:tid 229493] [client 194.147.58.101:57300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/temp.bak"] [unique_id "al9IACBMYeh5YLVG45xhXwAAAok"]
[Tue Jul 21 07:20:48.864704 2026] [security2:error] [pid 229246:tid 229428] [client 20.151.10.161:45933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9IACBMYeh5YLVG45xhYAAAAkg"]
[Tue Jul 21 07:20:48.928397 2026] [security2:error] [pid 230252:tid 230502] [client 114.119.151.63:61733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oticapersona.com.br"] [uri "/produto/oculos-speedo-sp3037"] [unique_id "al9IAE0Dwhk5-Z44Xro8XQAAAw8"], referer: https://oticapersona.com.br/categoria-produto/speedo
[Tue Jul 21 07:20:48.985062 2026] [security2:error] [pid 229246:tid 229429] [client 20.151.10.161:55233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9IACBMYeh5YLVG45xhYwAAAkk"]
[Tue Jul 21 07:20:49.242002 2026] [security2:error] [pid 229246:tid 229439] [client 4.204.201.85:17880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/file.php"] [unique_id "al9IASBMYeh5YLVG45xhaAAAAlM"]
[Tue Jul 21 07:20:49.347202 2026] [http2:warn] [pid 230252:tid 230408] [client 57.141.18.33:39370] h2_stream(230252-17-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:49.411679 2026] [security2:error] [pid 230252:tid 230439] [client 20.151.10.161:12083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file.php"] [unique_id "al9IAU0Dwhk5-Z44Xro8XgAAAtA"]
[Tue Jul 21 07:20:49.483991 2026] [security2:error] [pid 230252:tid 230495] [client 20.197.192.193:6363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eltonmelo.com.br"] [uri "/ms.php"] [unique_id "al9IAU0Dwhk5-Z44Xro8XwAAAwg"]
[Tue Jul 21 07:20:49.641214 2026] [security2:error] [pid 229246:tid 229452] [client 20.220.225.223:36845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/track.php"] [unique_id "al9IASBMYeh5YLVG45xhgAAAAmA"]
[Tue Jul 21 07:20:49.776119 2026] [security2:error] [pid 229246:tid 229435] [client 20.151.10.161:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/gettest.php"] [unique_id "al9IASBMYeh5YLVG45xhgwAAAk8"]
[Tue Jul 21 07:20:49.827071 2026] [security2:error] [pid 229246:tid 229371] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IASBMYeh5YLVG45xhhQACJXw"]
[Tue Jul 21 07:20:49.827209 2026] [security2:error] [pid 229246:tid 229393] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IASBMYeh5YLVG45xhhQACJXw"]
[Tue Jul 21 07:20:49.851365 2026] [security2:error] [pid 229246:tid 229392] [client 20.151.10.161:55245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/cfile.php"] [unique_id "al9IASBMYeh5YLVG45xhhgAAAiQ"]
[Tue Jul 21 07:20:49.887181 2026] [http2:warn] [pid 230252:tid 230479] [client 57.141.18.109:26718] h2_stream(230252-20-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:50.022912 2026] [security2:error] [pid 229246:tid 229503] [client 4.204.201.85:17881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/777.php"] [unique_id "al9IAiBMYeh5YLVG45xhkAAAApM"]
[Tue Jul 21 07:20:50.050698 2026] [security2:error] [pid 230252:tid 230410] [client 20.220.225.223:47817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/tkikikoko.php"] [unique_id "al9IAk0Dwhk5-Z44Xro8YwAAArM"]
[Tue Jul 21 07:20:50.051651 2026] [qos:error] [pid 229246:tid 229395] [client 162.241.63.68:34672] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9IAiBMYeh5YLVG45xhkwAAAic
[Tue Jul 21 07:20:50.116790 2026] [http2:warn] [pid 229246:tid 229476] [client 57.141.18.12:49452] h2_stream(229246-252-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:50.329957 2026] [security2:error] [pid 229246:tid 229444] [client 20.151.10.161:55263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/class-wp.php"] [unique_id "al9IAiBMYeh5YLVG45xhmgAAAlg"]
[Tue Jul 21 07:20:50.437567 2026] [security2:error] [pid 229246:tid 229453] [client 20.220.225.223:40875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/2352356666.php"] [unique_id "al9IAiBMYeh5YLVG45xhnQAAAmE"]
[Tue Jul 21 07:20:50.444990 2026] [security2:error] [pid 229246:tid 229450] [client 20.104.96.117:59693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/pucci.php"] [unique_id "al9IAiBMYeh5YLVG45xhngAAAl4"]
[Tue Jul 21 07:20:50.507717 2026] [security2:error] [pid 229246:tid 229382] [client 20.151.10.161:46049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/simple.php"] [unique_id "al9IAiBMYeh5YLVG45xhowAAAho"]
[Tue Jul 21 07:20:50.614719 2026] [security2:error] [pid 230252:tid 230462] [client 4.204.201.85:17904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ssixta.php"] [unique_id "al9IAk0Dwhk5-Z44Xro8ZAAAAuc"]
[Tue Jul 21 07:20:50.634509 2026] [security2:error] [pid 230252:tid 230458] [client 68.235.38.2:35902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IAk0Dwhk5-Z44Xro8ZgAAAuM"]
[Tue Jul 21 07:20:50.634604 2026] [security2:error] [pid 230252:tid 230458] [client 68.235.38.2:35902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IAk0Dwhk5-Z44Xro8ZgAAAuM"]
[Tue Jul 21 07:20:50.732060 2026] [security2:error] [pid 230252:tid 230414] [client 20.151.10.161:12080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/admin.php"] [unique_id "al9IAk0Dwhk5-Z44Xro8ZwAAArc"]
[Tue Jul 21 07:20:50.774510 2026] [security2:error] [pid 229246:tid 229497] [client 92.119.178.3:44372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9IAiBMYeh5YLVG45xhqgAAAo0"]
[Tue Jul 21 07:20:50.774615 2026] [security2:error] [pid 229246:tid 229497] [client 92.119.178.3:44372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9IAiBMYeh5YLVG45xhqgAAAo0"]
[Tue Jul 21 07:20:50.907732 2026] [security2:error] [pid 230252:tid 230510] [client 20.151.10.161:46070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xxx.php"] [unique_id "al9IAk0Dwhk5-Z44Xro8aAAAAxc"]
[Tue Jul 21 07:20:51.151587 2026] [security2:error] [pid 229246:tid 229274] [remote 156.59.198.136:29550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/wp-content/uploads/2025/08/photo30-1-592x444.webp"] [unique_id "al9IAyBMYeh5YLVG45xhtwACexs"], referer: https://powerflats.com.br/condominio/nex-one-pinheiros/
[Tue Jul 21 07:20:51.322065 2026] [security2:error] [pid 230252:tid 230481] [client 20.151.10.161:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/hypo.php"] [unique_id "al9IA00Dwhk5-Z44Xro8aQAAAvo"]
[Tue Jul 21 07:20:51.368038 2026] [security2:error] [pid 229246:tid 229435] [client 173.252.95.36:64606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9IAyBMYeh5YLVG45xhuQAAAk8"]
[Tue Jul 21 07:20:51.459988 2026] [security2:error] [pid 229246:tid 229470] [client 4.204.201.85:17895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/1c.php"] [unique_id "al9IAyBMYeh5YLVG45xhwQAAAnI"]
[Tue Jul 21 07:20:51.680375 2026] [security2:error] [pid 229246:tid 229434] [client 103.121.156.110:62245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IAyBMYeh5YLVG45xhxAAAAk4"]
[Tue Jul 21 07:20:51.680514 2026] [security2:error] [pid 229246:tid 229434] [client 103.121.156.110:62245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IAyBMYeh5YLVG45xhxAAAAk4"]
[Tue Jul 21 07:20:51.680692 2026] [security2:error] [pid 229246:tid 229480] [client 103.162.129.114:61170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IAyBMYeh5YLVG45xhxQAAAnw"]
[Tue Jul 21 07:20:51.680800 2026] [security2:error] [pid 229246:tid 229480] [client 103.162.129.114:61170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IAyBMYeh5YLVG45xhxQAAAnw"]
[Tue Jul 21 07:20:51.791228 2026] [security2:error] [pid 229246:tid 229453] [client 20.151.10.161:53595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/aa2.php"] [unique_id "al9IAyBMYeh5YLVG45xhxwAAAmE"]
[Tue Jul 21 07:20:51.828903 2026] [http2:warn] [pid 230252:tid 230420] [client 57.141.18.80:23700] h2_stream(230252-25-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:51.875191 2026] [security2:error] [pid 229246:tid 229450] [client 20.220.225.223:47869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9IAyBMYeh5YLVG45xhyAAAAl4"]
[Tue Jul 21 07:20:51.959670 2026] [security2:error] [pid 230252:tid 230485] [client 20.104.96.117:59164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/black.php"] [unique_id "al9IA00Dwhk5-Z44Xro8bQAAAv4"]
[Tue Jul 21 07:20:51.994632 2026] [security2:error] [pid 230252:tid 230501] [client 114.119.136.64:49323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.vivaconcierge.com.br"] [uri "/wp-content/uploads/2018/09/04-23-142-1170x738.jpg"] [unique_id "al9IA00Dwhk5-Z44Xro8bwAAAw4"], referer: https://www.vivaconcierge.com.br/wp-content/uploads/2018/09/04-23-142-1170x738.jpg
[Tue Jul 21 07:20:52.002404 2026] [security2:error] [pid 230252:tid 230473] [client 20.151.10.161:45897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/chosen.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8cAAAAvI"]
[Tue Jul 21 07:20:52.027065 2026] [security2:error] [pid 230252:tid 230465] [client 134.19.179.187:53484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8cQAAAuo"]
[Tue Jul 21 07:20:52.027191 2026] [security2:error] [pid 230252:tid 230465] [client 134.19.179.187:53484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8cQAAAuo"]
[Tue Jul 21 07:20:52.143536 2026] [security2:error] [pid 229246:tid 229439] [client 136.144.33.104:49553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IBCBMYeh5YLVG45xhygAAAlM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:52.199059 2026] [security2:error] [pid 229246:tid 229449] [client 105.96.79.38:60876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.79.96.105.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giovanaviana.online"] [uri "/xmlrpc.php"] [unique_id "al9IAyBMYeh5YLVG45xhuAAAAl0"]
[Tue Jul 21 07:20:52.199275 2026] [security2:error] [pid 229246:tid 229449] [client 105.96.79.38:60876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giovanaviana.online"] [uri "/xmlrpc.php"] [unique_id "al9IAyBMYeh5YLVG45xhuAAAAl0"]
[Tue Jul 21 07:20:52.297977 2026] [security2:error] [pid 230252:tid 230428] [client 20.151.10.161:12068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ccou.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8dAAAAsU"]
[Tue Jul 21 07:20:52.307913 2026] [http2:warn] [pid 230252:tid 230431] [client 57.141.18.49:20468] h2_stream(230252-26-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:52.342515 2026] [security2:error] [pid 230252:tid 230412] [client 74.249.245.134:49971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/404.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8dQAAArU"]
[Tue Jul 21 07:20:52.564648 2026] [security2:error] [pid 230252:tid 230378] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8dgAC0Hs"]
[Tue Jul 21 07:20:52.564843 2026] [security2:error] [pid 230252:tid 230439] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8dgAC0Hs"]
[Tue Jul 21 07:20:52.683742 2026] [security2:error] [pid 229246:tid 229466] [client 20.151.10.161:45982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/als.php"] [unique_id "al9IBCBMYeh5YLVG45xh0QAAAm4"]
[Tue Jul 21 07:20:52.897292 2026] [http2:warn] [pid 230252:tid 230441] [client 57.141.18.14:55194] h2_stream(230252-27-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:52.929669 2026] [security2:error] [pid 229246:tid 229436] [client 20.104.96.117:59651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/zlece.php"] [unique_id "al9IBCBMYeh5YLVG45xh1QAAAlA"]
[Tue Jul 21 07:20:52.977061 2026] [security2:error] [pid 230252:tid 230486] [client 68.235.38.2:35918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8eAAAAv8"]
[Tue Jul 21 07:20:52.977177 2026] [security2:error] [pid 230252:tid 230486] [client 68.235.38.2:35918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8eAAAAv8"]
[Tue Jul 21 07:20:52.996997 2026] [security2:error] [pid 230252:tid 230458] [client 4.204.201.85:17911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/test2.php"] [unique_id "al9IBE0Dwhk5-Z44Xro8eQAAAuM"]
[Tue Jul 21 07:20:53.099423 2026] [security2:error] [pid 230252:tid 230342] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IBU0Dwhk5-Z44Xro8ewAC9Vc"]
[Tue Jul 21 07:20:53.099620 2026] [security2:error] [pid 230252:tid 230476] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IBU0Dwhk5-Z44Xro8ewAC9Vc"]
[Tue Jul 21 07:20:53.103667 2026] [security2:error] [pid 230252:tid 230426] [client 114.119.137.28:35199] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jandel.com.br"] [uri "/ldwy6t6/waterford-crystal-made-in-germany"] [unique_id "al9IBU0Dwhk5-Z44Xro8fAAAAsM"], referer: https://jandel.com.br/ldwy6t6/waterford-crystal-made-in-germany
[Tue Jul 21 07:20:53.231927 2026] [core:alert] [pid 229246:tid 229381] [client 57.141.18.25:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:20:53.514029 2026] [http2:warn] [pid 230252:tid 230488] [client 57.141.18.55:53226] h2_stream(230252-30-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:53.531236 2026] [security2:error] [pid 229246:tid 229503] [client 20.151.10.161:45984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/pol.php"] [unique_id "al9IBSBMYeh5YLVG45xh3gAAApM"]
[Tue Jul 21 07:20:53.753235 2026] [security2:error] [pid 229246:tid 229495] [client 14.139.42.196:13493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IBSBMYeh5YLVG45xh4gAAAos"]
[Tue Jul 21 07:20:53.753393 2026] [security2:error] [pid 229246:tid 229495] [client 14.139.42.196:13493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IBSBMYeh5YLVG45xh4gAAAos"]
[Tue Jul 21 07:20:54.016238 2026] [security2:error] [pid 229246:tid 229387] [client 20.220.225.223:43041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/wp-css.php"] [unique_id "al9IBiBMYeh5YLVG45xh5gAAAh8"]
[Tue Jul 21 07:20:54.144828 2026] [security2:error] [pid 229246:tid 229348] [remote 152.53.111.131:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/wp-login.php"] [unique_id "al9IBiBMYeh5YLVG45xh5wACWGU"]
[Tue Jul 21 07:20:54.199890 2026] [security2:error] [pid 230252:tid 230465] [client 20.151.10.161:45968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file5.php"] [unique_id "al9IBk0Dwhk5-Z44Xro8igAAAuo"]
[Tue Jul 21 07:20:54.253008 2026] [security2:error] [pid 230252:tid 230511] [client 20.104.96.117:59650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/vssrs.php"] [unique_id "al9IBk0Dwhk5-Z44Xro8iwAAAxg"]
[Tue Jul 21 07:20:54.348992 2026] [security2:error] [pid 229246:tid 229403] [client 4.204.201.85:44009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/buy.php"] [unique_id "al9IBiBMYeh5YLVG45xh7QAAAi8"]
[Tue Jul 21 07:20:54.455577 2026] [security2:error] [pid 230252:tid 230430] [client 20.151.10.161:53621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/dr.php"] [unique_id "al9IBk0Dwhk5-Z44Xro8jQAAAsc"]
[Tue Jul 21 07:20:54.496577 2026] [security2:error] [pid 230252:tid 230501] [client 45.251.232.145:63733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IBk0Dwhk5-Z44Xro8kAAAAw4"]
[Tue Jul 21 07:20:54.496719 2026] [security2:error] [pid 230252:tid 230501] [client 45.251.232.145:63733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IBk0Dwhk5-Z44Xro8kAAAAw4"]
[Tue Jul 21 07:20:54.634881 2026] [security2:error] [pid 230252:tid 230496] [client 20.151.10.161:45891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9IBk0Dwhk5-Z44Xro8kQAAAwk"]
[Tue Jul 21 07:20:54.881271 2026] [http2:warn] [pid 230252:tid 230398] [client 57.141.18.44:24762] h2_stream(230252-32-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:54.882162 2026] [security2:error] [pid 230252:tid 230489] [client 20.220.225.223:34207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/2352356666.php"] [unique_id "al9IBk0Dwhk5-Z44Xro8kgAAAwI"]
[Tue Jul 21 07:20:54.979631 2026] [security2:error] [pid 229246:tid 229391] [client 92.119.178.3:44374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9IBiBMYeh5YLVG45xh9gAAAiM"]
[Tue Jul 21 07:20:54.979745 2026] [security2:error] [pid 229246:tid 229391] [client 92.119.178.3:44374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9IBiBMYeh5YLVG45xh9gAAAiM"]
[Tue Jul 21 07:20:55.012914 2026] [security2:error] [pid 230252:tid 230353] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IB00Dwhk5-Z44Xro8kwAC0GI"]
[Tue Jul 21 07:20:55.013100 2026] [security2:error] [pid 230252:tid 230439] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IB00Dwhk5-Z44Xro8kwAC0GI"]
[Tue Jul 21 07:20:55.032737 2026] [security2:error] [pid 230252:tid 230486] [client 4.204.201.85:17823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ssend.php"] [unique_id "al9IB00Dwhk5-Z44Xro8lAAAAv8"]
[Tue Jul 21 07:20:55.148307 2026] [security2:error] [pid 230252:tid 230426] [client 20.151.10.161:46027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file.php"] [unique_id "al9IB00Dwhk5-Z44Xro8lgAAAsM"]
[Tue Jul 21 07:20:55.275151 2026] [http2:warn] [pid 229246:tid 229488] [client 57.141.18.102:37838] h2_stream(229246-260-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:55.304582 2026] [security2:error] [pid 229246:tid 229497] [client 20.220.225.223:43050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/wp-explorer.php"] [unique_id "al9IByBMYeh5YLVG45xh-wAAAo0"]
[Tue Jul 21 07:20:55.514188 2026] [security2:error] [pid 230252:tid 230424] [client 20.151.10.161:45976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/cfile.php"] [unique_id "al9IB00Dwhk5-Z44Xro8nwAAAsE"]
[Tue Jul 21 07:20:55.661870 2026] [security2:error] [pid 230252:tid 230464] [client 4.204.201.85:17812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/item.php"] [unique_id "al9IB00Dwhk5-Z44Xro8oAAAAuk"]
[Tue Jul 21 07:20:55.808419 2026] [security2:error] [pid 229246:tid 229392] [client 20.104.96.117:59158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wicked.php"] [unique_id "al9IByBMYeh5YLVG45xiBQAAAiQ"]
[Tue Jul 21 07:20:55.830331 2026] [security2:error] [pid 229246:tid 229484] [client 34.86.210.0:52702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.210.86.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "unigein.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IByBMYeh5YLVG45xiBgAAAoA"]
[Tue Jul 21 07:20:55.830419 2026] [security2:error] [pid 229246:tid 229484] [client 34.86.210.0:52702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "unigein.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IByBMYeh5YLVG45xiBgAAAoA"]
[Tue Jul 21 07:20:55.874960 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:46079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/class-wp.php"] [unique_id "al9IB00Dwhk5-Z44Xro8ogAAAtE"]
[Tue Jul 21 07:20:55.938464 2026] [security2:error] [pid 230252:tid 230430] [client 20.206.105.145:30669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IB00Dwhk5-Z44Xro8owAAAsc"]
[Tue Jul 21 07:20:55.975869 2026] [security2:error] [pid 230252:tid 230428] [client 74.7.230.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "401"] [hostname "webdisk.agrocibus.com"] [uri "/___proxy_subdomain_webdisk/robots.txt"] [unique_id "al9IB00Dwhk5-Z44Xro8pAAAAsU"]
[Tue Jul 21 07:20:56.093279 2026] [security2:error] [pid 229246:tid 229335] [remote 178.18.124.148:36070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.124.18.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ICCBMYeh5YLVG45xiDQACkVg"]
[Tue Jul 21 07:20:56.292451 2026] [security2:error] [pid 230252:tid 230496] [client 20.151.10.161:45890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/admin.php"] [unique_id "al9ICE0Dwhk5-Z44Xro8pwAAAwk"]
[Tue Jul 21 07:20:56.372238 2026] [security2:error] [pid 230252:tid 230471] [client 4.204.201.85:17874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ss.php"] [unique_id "al9ICE0Dwhk5-Z44Xro8qAAAAvA"]
[Tue Jul 21 07:20:56.410397 2026] [security2:error] [pid 230252:tid 230410] [client 136.144.33.99:32859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9ICE0Dwhk5-Z44Xro8pgAAArM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:20:56.418269 2026] [security2:error] [pid 230252:tid 230419] [client 20.151.10.161:55283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xamp.php"] [unique_id "al9ICE0Dwhk5-Z44Xro8vgAAArw"]
[Tue Jul 21 07:20:56.749473 2026] [http2:warn] [pid 229246:tid 229451] [client 57.141.18.64:53814] h2_stream(229246-262-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:56.876109 2026] [security2:error] [pid 230252:tid 230476] [client 114.119.158.18:56025] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gradiente.com"] [uri "/site/produtos/view.asp"] [unique_id "al9ICE0Dwhk5-Z44Xro8wgAAAvU"], referer: https://www.bernabauer.com/gradiente-gf930/
[Tue Jul 21 07:20:57.020677 2026] [security2:error] [pid 230252:tid 230401] [client 20.151.10.161:45853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/aa2.php"] [unique_id "al9ICU0Dwhk5-Z44Xro8xgAAAqo"]
[Tue Jul 21 07:20:57.156097 2026] [security2:error] [pid 229246:tid 229404] [client 20.220.225.223:52793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/pn.php"] [unique_id "al9ICSBMYeh5YLVG45xiFwAAAjA"]
[Tue Jul 21 07:20:57.159017 2026] [security2:error] [pid 230252:tid 230510] [client 4.204.201.85:17913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/hypo.php"] [unique_id "al9ICU0Dwhk5-Z44Xro8ygAAAxc"]
[Tue Jul 21 07:20:57.346493 2026] [http2:warn] [pid 230252:tid 230478] [client 57.141.18.97:23062] h2_stream(230252-40-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:57.497596 2026] [security2:error] [pid 230252:tid 230424] [client 20.206.105.145:30661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9ICU0Dwhk5-Z44Xro8zgAAAsE"]
[Tue Jul 21 07:20:57.703064 2026] [security2:error] [pid 230252:tid 230283] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9ICU0Dwhk5-Z44Xro80gACrx0"]
[Tue Jul 21 07:20:57.703238 2026] [security2:error] [pid 230252:tid 230406] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9ICU0Dwhk5-Z44Xro80gACrx0"]
[Tue Jul 21 07:20:57.768076 2026] [security2:error] [pid 230252:tid 230408] [client 20.220.225.223:59496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/akismet.php"] [unique_id "al9ICU0Dwhk5-Z44Xro80wAAArE"]
[Tue Jul 21 07:20:57.962947 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:59180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/24.php"] [unique_id "al9ICU0Dwhk5-Z44Xro81AAAAuk"]
[Tue Jul 21 07:20:57.977452 2026] [security2:error] [pid 230252:tid 230452] [client 4.204.201.85:17873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/users.php"] [unique_id "al9ICU0Dwhk5-Z44Xro81QAAAt0"]
[Tue Jul 21 07:20:58.065625 2026] [security2:error] [pid 230252:tid 230312] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICk0Dwhk5-Z44Xro82AACtzo"]
[Tue Jul 21 07:20:58.065775 2026] [security2:error] [pid 230252:tid 230414] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICk0Dwhk5-Z44Xro82AACtzo"]
[Tue Jul 21 07:20:58.174327 2026] [security2:error] [pid 230252:tid 230457] [client 20.151.10.161:45919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ccou.php"] [unique_id "al9ICk0Dwhk5-Z44Xro83AAAAuI"]
[Tue Jul 21 07:20:58.176147 2026] [security2:error] [pid 229246:tid 229487] [client 20.151.10.161:12059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/bless.php"] [unique_id "al9ICiBMYeh5YLVG45xiIwAAAoM"]
[Tue Jul 21 07:20:58.397893 2026] [security2:error] [pid 230252:tid 230357] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICk0Dwhk5-Z44Xro85AACnGY"]
[Tue Jul 21 07:20:58.398014 2026] [security2:error] [pid 230252:tid 230387] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICk0Dwhk5-Z44Xro85AACnGY"]
[Tue Jul 21 07:20:58.599308 2026] [http2:warn] [pid 230252:tid 230403] [client 57.141.18.31:38182] h2_stream(230252-46-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:58.625472 2026] [security2:error] [pid 229246:tid 229481] [client 139.135.44.145:54494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ICiBMYeh5YLVG45xiKAAAAn0"]
[Tue Jul 21 07:20:58.625627 2026] [security2:error] [pid 229246:tid 229481] [client 139.135.44.145:54494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ICiBMYeh5YLVG45xiKAAAAn0"]
[Tue Jul 21 07:20:58.669562 2026] [security2:error] [pid 230252:tid 230439] [client 4.204.201.85:17834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/177.php"] [unique_id "al9ICk0Dwhk5-Z44Xro88AAAAtA"]
[Tue Jul 21 07:20:58.782975 2026] [security2:error] [pid 230252:tid 230441] [client 20.197.192.193:27189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/bootstrap.php"] [unique_id "al9ICk0Dwhk5-Z44Xro88QAAAtI"]
[Tue Jul 21 07:20:58.886406 2026] [security2:error] [pid 230252:tid 230428] [client 175.45.70.82:51813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICk0Dwhk5-Z44Xro88wAAAsU"]
[Tue Jul 21 07:20:58.886567 2026] [security2:error] [pid 230252:tid 230428] [client 175.45.70.82:51813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICk0Dwhk5-Z44Xro88wAAAsU"]
[Tue Jul 21 07:20:58.951083 2026] [security2:error] [pid 229246:tid 229503] [client 20.197.192.193:27081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/wp-editor.php"] [unique_id "al9ICiBMYeh5YLVG45xiLAAAApM"]
[Tue Jul 21 07:20:58.965514 2026] [security2:error] [pid 230252:tid 230497] [client 20.206.105.145:30692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/media.php"] [unique_id "al9ICk0Dwhk5-Z44Xro89AAAAwo"]
[Tue Jul 21 07:20:59.090553 2026] [security2:error] [pid 230252:tid 230504] [client 20.220.225.223:47831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9IC00Dwhk5-Z44Xro8-AAAAxE"]
[Tue Jul 21 07:20:59.384687 2026] [security2:error] [pid 229246:tid 229452] [client 120.61.173.56:56127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICyBMYeh5YLVG45xiMAAAAmA"]
[Tue Jul 21 07:20:59.384890 2026] [security2:error] [pid 229246:tid 229452] [client 120.61.173.56:56127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ICyBMYeh5YLVG45xiMAAAAmA"]
[Tue Jul 21 07:20:59.395085 2026] [security2:error] [pid 230252:tid 230485] [client 92.119.178.3:59610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IC00Dwhk5-Z44Xro9AgAAAv4"]
[Tue Jul 21 07:20:59.395227 2026] [security2:error] [pid 230252:tid 230485] [client 92.119.178.3:59610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IC00Dwhk5-Z44Xro9AgAAAv4"]
[Tue Jul 21 07:20:59.428414 2026] [security2:error] [pid 229246:tid 229410] [client 20.226.60.151:54479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/iywwi.php"] [unique_id "al9ICyBMYeh5YLVG45xiMQAAAjY"]
[Tue Jul 21 07:20:59.491103 2026] [http2:warn] [pid 230252:tid 230455] [client 57.141.18.75:31802] h2_stream(230252-50-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:20:59.518332 2026] [security2:error] [pid 229246:tid 229401] [client 114.119.136.139:54203] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "transitoaberto.com.br"] [uri "/pat-disponibiliza-635-vagas-de-emprego-em-varias-areas-em-sao-jose/"] [unique_id "al9ICyBMYeh5YLVG45xiMgAAAi0"], referer: https://transitoaberto.com.br/post-sitemap7.xml
[Tue Jul 21 07:20:59.567534 2026] [security2:error] [pid 230252:tid 230465] [client 4.204.201.85:17868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/config.php"] [unique_id "al9IC00Dwhk5-Z44Xro9BgAAAuo"]
[Tue Jul 21 07:20:59.923326 2026] [security2:error] [pid 230252:tid 230398] [client 20.220.225.223:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/pn.php"] [unique_id "al9IC00Dwhk5-Z44Xro9EgAAAqc"]
[Tue Jul 21 07:20:59.979887 2026] [security2:error] [pid 229246:tid 229477] [client 20.104.96.117:59152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/xacs.php"] [unique_id "al9ICyBMYeh5YLVG45xiNgAAAnk"]
[Tue Jul 21 07:21:00.382509 2026] [security2:error] [pid 229246:tid 229284] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IDCBMYeh5YLVG45xiOwACfCU"]
[Tue Jul 21 07:21:00.382641 2026] [security2:error] [pid 229246:tid 229480] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IDCBMYeh5YLVG45xiOwACfCU"]
[Tue Jul 21 07:21:00.504575 2026] [security2:error] [pid 229246:tid 229429] [client 20.206.105.145:30597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/images.php"] [unique_id "al9IDCBMYeh5YLVG45xiPgAAAkk"]
[Tue Jul 21 07:21:00.547243 2026] [security2:error] [pid 230252:tid 230493] [client 20.220.225.223:40859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/ace2.php"] [unique_id "al9IDE0Dwhk5-Z44Xro9JAAAAwY"]
[Tue Jul 21 07:21:00.570457 2026] [http2:warn] [pid 230252:tid 230509] [client 57.141.18.115:47810] h2_stream(230252-51-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:00.775248 2026] [security2:error] [pid 229246:tid 229430] [client 4.204.201.85:44002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/gettest.php"] [unique_id "al9IDCBMYeh5YLVG45xiQQAAAko"]
[Tue Jul 21 07:21:00.873480 2026] [security2:error] [pid 229246:tid 229454] [client 20.151.10.161:12045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file46.php"] [unique_id "al9IDCBMYeh5YLVG45xiRAAAAmI"]
[Tue Jul 21 07:21:00.911922 2026] [security2:error] [pid 230252:tid 230425] [client 20.151.10.161:45964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/dr.php"] [unique_id "al9IDE0Dwhk5-Z44Xro9LQAAAsI"]
[Tue Jul 21 07:21:00.944190 2026] [security2:error] [pid 230252:tid 230481] [client 74.249.245.134:61928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/file3.php"] [unique_id "al9IDE0Dwhk5-Z44Xro9LgAAAvo"]
[Tue Jul 21 07:21:00.956415 2026] [security2:error] [pid 230252:tid 230454] [client 193.36.225.54:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IDE0Dwhk5-Z44Xro9LwAAAt8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:01.507823 2026] [http2:warn] [pid 229246:tid 229447] [client 57.141.18.2:26722] h2_stream(229246-275-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:01.526880 2026] [security2:error] [pid 230252:tid 230457] [client 20.206.105.145:30681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/adminner.php"] [unique_id "al9IDU0Dwhk5-Z44Xro9PAAAAuI"]
[Tue Jul 21 07:21:01.587457 2026] [security2:error] [pid 230252:tid 230495] [client 20.104.96.117:59663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/zildan.php"] [unique_id "al9IDU0Dwhk5-Z44Xro9PgAAAwg"]
[Tue Jul 21 07:21:01.616879 2026] [security2:error] [pid 230252:tid 230445] [client 20.197.192.193:27100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/cro.php"] [unique_id "al9IDU0Dwhk5-Z44Xro9QgAAAtY"]
[Tue Jul 21 07:21:01.635784 2026] [security2:error] [pid 229246:tid 229275] [remote 199.189.225.40:50855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/wp-login.php"] [unique_id "al9IDSBMYeh5YLVG45xiSgACjRw"]
[Tue Jul 21 07:21:01.837630 2026] [security2:error] [pid 230252:tid 230486] [client 4.204.201.85:17822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/min.php"] [unique_id "al9IDU0Dwhk5-Z44Xro9TAAAAv8"]
[Tue Jul 21 07:21:02.113022 2026] [security2:error] [pid 229246:tid 229471] [client 20.220.225.223:59495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/dr.php"] [unique_id "al9IDiBMYeh5YLVG45xiUAAAAnM"]
[Tue Jul 21 07:21:02.211368 2026] [http2:warn] [pid 230252:tid 230456] [client 57.141.18.22:61362] h2_stream(230252-56-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:02.352997 2026] [security2:error] [pid 230252:tid 230481] [client 20.206.105.145:30697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/admin.php"] [unique_id "al9IDk0Dwhk5-Z44Xro9WQAAAvo"]
[Tue Jul 21 07:21:02.405054 2026] [security2:error] [pid 230252:tid 230399] [client 103.121.156.110:62572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IDk0Dwhk5-Z44Xro9WwAAAqg"]
[Tue Jul 21 07:21:02.405200 2026] [security2:error] [pid 230252:tid 230399] [client 103.121.156.110:62572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IDk0Dwhk5-Z44Xro9WwAAAqg"]
[Tue Jul 21 07:21:02.426093 2026] [security2:error] [pid 230252:tid 230395] [client 103.162.129.114:61811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IDk0Dwhk5-Z44Xro9XAAAAqQ"]
[Tue Jul 21 07:21:02.426216 2026] [security2:error] [pid 230252:tid 230395] [client 103.162.129.114:61811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IDk0Dwhk5-Z44Xro9XAAAAqQ"]
[Tue Jul 21 07:21:02.479576 2026] [security2:error] [pid 229246:tid 229334] [remote 114.119.143.77:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "androapkmod.com"] [uri "/scavenger-hunt-mod-apk/"] [unique_id "al9IDiBMYeh5YLVG45xiVwACe1c"], referer: https://xn--r1a.website/s/androapkmodoficial/57206
[Tue Jul 21 07:21:02.492964 2026] [security2:error] [pid 229246:tid 229435] [client 20.220.225.223:47837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "teste.inonebrasil.com.br"] [uri "/ms.php"] [unique_id "al9IDiBMYeh5YLVG45xiWAAAAk8"]
[Tue Jul 21 07:21:02.508009 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:45945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xamp.php"] [unique_id "al9IDk0Dwhk5-Z44Xro9YQAAAtE"]
[Tue Jul 21 07:21:02.630457 2026] [http2:warn] [pid 229246:tid 229396] [client 57.141.18.11:37344] h2_stream(229246-280-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:02.773254 2026] [security2:error] [pid 230252:tid 230495] [client 4.204.201.85:43842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/dvjul.php"] [unique_id "al9IDk0Dwhk5-Z44Xro9bgAAAwg"]
[Tue Jul 21 07:21:02.938317 2026] [fcgid:warn] [pid 230252:tid 230493] (70014)End of file found: [client 66.132.195.50:41594] mod_fcgid: can't get data from http client
[Tue Jul 21 07:21:03.014330 2026] [security2:error] [pid 230252:tid 230402] [client 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/wp-admin/install.php"] [unique_id "al9ID00Dwhk5-Z44Xro9fwAAAqs"]
[Tue Jul 21 07:21:03.126707 2026] [http2:warn] [pid 230252:tid 230421] [client 57.141.18.61:61818] h2_stream(230252-62-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:03.228094 2026] [security2:error] [pid 229246:tid 229386] [client 20.104.96.117:59146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/csa.php"] [unique_id "al9IDyBMYeh5YLVG45xiXQAAAh4"]
[Tue Jul 21 07:21:03.275093 2026] [security2:error] [pid 230252:tid 230425] [client 20.151.10.161:45975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/bless.php"] [unique_id "al9ID00Dwhk5-Z44Xro9gwAAAsI"]
[Tue Jul 21 07:21:03.300334 2026] [security2:error] [pid 229246:tid 229387] [client 4.204.201.85:17903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/biufile.php"] [unique_id "al9IDyBMYeh5YLVG45xiYAAAAh8"]
[Tue Jul 21 07:21:03.335402 2026] [security2:error] [pid 229246:tid 229380] [client 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9IDyBMYeh5YLVG45xiYgAAAhg"]
[Tue Jul 21 07:21:03.364384 2026] [security2:error] [pid 230252:tid 230267] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ID00Dwhk5-Z44Xro9hwACqg0"]
[Tue Jul 21 07:21:03.364567 2026] [security2:error] [pid 230252:tid 230401] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ID00Dwhk5-Z44Xro9hwACqg0"]
[Tue Jul 21 07:21:03.450142 2026] [security2:error] [pid 230252:tid 230488] [client 20.220.225.223:34178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9ID00Dwhk5-Z44Xro9iAAAAwE"]
[Tue Jul 21 07:21:03.558371 2026] [security2:error] [pid 229246:tid 229450] [client 20.206.105.145:30610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/k.php"] [unique_id "al9IDyBMYeh5YLVG45xiZgAAAl4"]
[Tue Jul 21 07:21:03.571673 2026] [security2:error] [pid 229246:tid 229310] [remote 173.252.70.23:65496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.70.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9IDyBMYeh5YLVG45xiZAACeT8"]
[Tue Jul 21 07:21:03.666959 2026] [security2:error] [pid 230252:tid 230360] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9ID00Dwhk5-Z44Xro9kwACwGk"]
[Tue Jul 21 07:21:03.667170 2026] [security2:error] [pid 230252:tid 230423] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9ID00Dwhk5-Z44Xro9kwACwGk"]
[Tue Jul 21 07:21:03.712261 2026] [security2:error] [pid 229246:tid 229404] [client 20.151.10.161:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file46.php"] [unique_id "al9IDyBMYeh5YLVG45xiagAAAjA"]
[Tue Jul 21 07:21:03.950695 2026] [security2:error] [pid 229246:tid 229454] [client 20.220.225.223:36851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/2x.php"] [unique_id "al9IDyBMYeh5YLVG45xibQAAAmI"]
[Tue Jul 21 07:21:04.072493 2026] [security2:error] [pid 229246:tid 229424] [client 20.151.10.161:46010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/eee.php"] [unique_id "al9IECBMYeh5YLVG45xibgAAAkQ"]
[Tue Jul 21 07:21:04.305276 2026] [security2:error] [pid 229246:tid 229460] [client 114.119.130.14:40031] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gfacil.com.br"] [uri "/201-6188336/nic-nucleo-intensivo-de-cursos-ltda/detalhe.html"] [unique_id "al9IECBMYeh5YLVG45xicwAAAmg"], referer: https://www.pages24.com.br/rio-de-janeiro-rj/61717-nic-nucleo-intensivo-de-cursos-ltda
[Tue Jul 21 07:21:04.309691 2026] [security2:error] [pid 230252:tid 230395] [client 20.151.10.161:11719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/eee.php"] [unique_id "al9IEE0Dwhk5-Z44Xro9qAAAAqQ"]
[Tue Jul 21 07:21:04.367023 2026] [security2:error] [pid 230252:tid 230384] [client 20.151.10.161:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file25.php"] [unique_id "al9IEE0Dwhk5-Z44Xro9qgAAApk"]
[Tue Jul 21 07:21:04.526307 2026] [security2:error] [pid 230252:tid 230400] [client 14.139.42.196:10431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IEE0Dwhk5-Z44Xro9rgAAAqk"]
[Tue Jul 21 07:21:04.526465 2026] [security2:error] [pid 230252:tid 230400] [client 14.139.42.196:10431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IEE0Dwhk5-Z44Xro9rgAAAqk"]
[Tue Jul 21 07:21:04.590207 2026] [security2:error] [pid 230252:tid 230409] [client 20.206.105.145:30611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/x.php"] [unique_id "al9IEE0Dwhk5-Z44Xro9sgAAArI"]
[Tue Jul 21 07:21:04.741647 2026] [security2:error] [pid 230252:tid 230392] [client 4.204.201.85:17882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/av.php"] [unique_id "al9IEE0Dwhk5-Z44Xro9twAAAqE"]
[Tue Jul 21 07:21:04.777036 2026] [http2:warn] [pid 230252:tid 230435] [client 57.141.18.29:37052] h2_stream(230252-73-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:04.872441 2026] [security2:error] [pid 230252:tid 230398] [client 20.151.10.161:45914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file48.php"] [unique_id "al9IEE0Dwhk5-Z44Xro9uQAAAqc"]
[Tue Jul 21 07:21:04.994885 2026] [security2:error] [pid 229246:tid 229490] [client 45.251.232.145:64248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IECBMYeh5YLVG45xiegAAAoY"]
[Tue Jul 21 07:21:04.995028 2026] [security2:error] [pid 229246:tid 229490] [client 45.251.232.145:64248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IECBMYeh5YLVG45xiegAAAoY"]
[Tue Jul 21 07:21:05.299853 2026] [security2:error] [pid 230252:tid 230420] [client 20.206.105.145:30612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wss.php"] [unique_id "al9IEU0Dwhk5-Z44Xro9yQAAAr0"]
[Tue Jul 21 07:21:05.359998 2026] [security2:error] [pid 229246:tid 229481] [client 20.151.10.161:45987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file6.php"] [unique_id "al9IESBMYeh5YLVG45xifwAAAn0"]
[Tue Jul 21 07:21:05.535348 2026] [security2:error] [pid 229246:tid 229410] [client 74.249.245.134:52446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-mail.php"] [unique_id "al9IESBMYeh5YLVG45xigQAAAjY"]
[Tue Jul 21 07:21:05.560113 2026] [http2:warn] [pid 229246:tid 229408] [client 57.141.18.59:61610] h2_stream(229246-284-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:05.569242 2026] [security2:error] [pid 230252:tid 230306] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IEU0Dwhk5-Z44Xro9ywADCTQ"]
[Tue Jul 21 07:21:05.569421 2026] [security2:error] [pid 230252:tid 230496] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IEU0Dwhk5-Z44Xro9ywADCTQ"]
[Tue Jul 21 07:21:05.837050 2026] [security2:error] [pid 230252:tid 230481] [client 4.204.201.85:17893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/coffexium.php"] [unique_id "al9IEU0Dwhk5-Z44Xro90wAAAvo"]
[Tue Jul 21 07:21:05.846025 2026] [security2:error] [pid 230252:tid 230387] [client 136.144.33.107:42377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IEU0Dwhk5-Z44Xro9zgAAApw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:05.987542 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:46048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/a2.php"] [unique_id "al9IEU0Dwhk5-Z44Xro91gAAAtE"]
[Tue Jul 21 07:21:06.005408 2026] [security2:error] [pid 230252:tid 230458] [client 20.220.225.223:47849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/kq1.php"] [unique_id "al9IEk0Dwhk5-Z44Xro91wAAAuM"]
[Tue Jul 21 07:21:06.062570 2026] [http2:warn] [pid 230252:tid 230463] [client 57.141.18.7:49678] h2_stream(230252-80-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:06.130529 2026] [security2:error] [pid 230252:tid 230478] [client 20.104.96.117:59191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/w3llscc.php"] [unique_id "al9IEk0Dwhk5-Z44Xro92AAAAvc"]
[Tue Jul 21 07:21:06.515359 2026] [security2:error] [pid 229246:tid 229463] [client 4.204.201.85:17916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/core.php"] [unique_id "al9IEiBMYeh5YLVG45xikgAAAms"]
[Tue Jul 21 07:21:06.555568 2026] [security2:error] [pid 229246:tid 229430] [client 20.151.10.161:45988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file15.php"] [unique_id "al9IEiBMYeh5YLVG45xilAAAAko"]
[Tue Jul 21 07:21:06.559953 2026] [security2:error] [pid 230252:tid 230404] [client 114.119.143.158:30989] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "essenceclinicadesaude.com.br"] [uri "/blog/page/4"] [unique_id "al9IEk0Dwhk5-Z44Xro94QAAAq0"], referer: https://essenceclinicadesaude.com.br/blog
[Tue Jul 21 07:21:06.850367 2026] [security2:error] [pid 229246:tid 229421] [client 20.206.105.145:30659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/ty.php"] [unique_id "al9IEiBMYeh5YLVG45ximgAAAkE"]
[Tue Jul 21 07:21:06.954359 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:53623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file25.php"] [unique_id "al9IEk0Dwhk5-Z44Xro95AAAAwY"]
[Tue Jul 21 07:21:06.965113 2026] [security2:error] [pid 229246:tid 229436] [client 4.204.201.85:17800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/als.php"] [unique_id "al9IEiBMYeh5YLVG45xinQAAAlA"]
[Tue Jul 21 07:21:07.073548 2026] [autoindex:error] [pid 229246:tid 229416] [client 135.225.181.175:1280] AH01276: Cannot serve directory /home1/edua4721/trabalhista.eduardogoesadv.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:21:07.196848 2026] [security2:error] [pid 229246:tid 229400] [client 20.151.10.161:46005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/jp.php"] [unique_id "al9IEyBMYeh5YLVG45xioAAAAiw"]
[Tue Jul 21 07:21:07.317128 2026] [security2:error] [pid 229246:tid 229496] [client 4.204.201.85:17870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/simple.php"] [unique_id "al9IEyBMYeh5YLVG45xiogAAAow"]
[Tue Jul 21 07:21:07.446825 2026] [http2:warn] [pid 230252:tid 230388] [client 57.141.18.106:50708] h2_stream(230252-87-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:07.513882 2026] [security2:error] [pid 229246:tid 229484] [client 20.151.10.161:53625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file48.php"] [unique_id "al9IEyBMYeh5YLVG45xipwAAAoA"]
[Tue Jul 21 07:21:07.545601 2026] [security2:error] [pid 229246:tid 229488] [client 20.206.105.145:30712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/155.php"] [unique_id "al9IEyBMYeh5YLVG45xiqwAAAoQ"]
[Tue Jul 21 07:21:07.549306 2026] [security2:error] [pid 229246:tid 229452] [client 74.249.245.134:21870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/about.php"] [unique_id "al9IEyBMYeh5YLVG45xirAAAAmA"]
[Tue Jul 21 07:21:07.897793 2026] [security2:error] [pid 230252:tid 230403] [client 4.204.201.85:17804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/init.php"] [unique_id "al9IE00Dwhk5-Z44Xro95gAAAqw"]
[Tue Jul 21 07:21:07.943052 2026] [security2:error] [pid 230252:tid 230507] [client 20.151.10.161:46055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/f35.php"] [unique_id "al9IE00Dwhk5-Z44Xro95wAAAxQ"]
[Tue Jul 21 07:21:08.181003 2026] [security2:error] [pid 230252:tid 230455] [client 114.119.143.75:64741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lojadoclimatizador.com.br"] [uri "/produto-tag/p13/"] [unique_id "al9IFE0Dwhk5-Z44Xro96wAAAuA"], referer: http://lojadoclimatizador.com.br/produto/p13-inovare
[Tue Jul 21 07:21:08.217553 2026] [security2:error] [pid 230252:tid 230458] [client 20.104.96.117:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wpx.php"] [unique_id "al9IFE0Dwhk5-Z44Xro97AAAAuM"]
[Tue Jul 21 07:21:08.269587 2026] [security2:error] [pid 230252:tid 230436] [client 20.151.10.161:45991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-load.php"] [unique_id "al9IFE0Dwhk5-Z44Xro97gAAAs0"]
[Tue Jul 21 07:21:08.451123 2026] [security2:error] [pid 230252:tid 230399] [client 114.119.132.122:63763] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.simleite.com.br"] [uri "/album/32"] [unique_id "al9IFE0Dwhk5-Z44Xro98AAAAqg"], referer: https://www.simleite.com.br/album/32
[Tue Jul 21 07:21:08.462222 2026] [security2:error] [pid 230252:tid 230371] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IFE0Dwhk5-Z44Xro98QADCHQ"]
[Tue Jul 21 07:21:08.462389 2026] [security2:error] [pid 230252:tid 230495] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IFE0Dwhk5-Z44Xro98QADCHQ"]
[Tue Jul 21 07:21:08.501963 2026] [security2:error] [pid 229246:tid 229482] [client 20.206.105.145:30690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/ops.php"] [unique_id "al9IFCBMYeh5YLVG45xitwAAAn4"]
[Tue Jul 21 07:21:08.510851 2026] [security2:error] [pid 230252:tid 230511] [client 34.34.16.122:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "vinculampe.com.br"] [uri "/"] [unique_id "al9IFE0Dwhk5-Z44Xro98gAAAxg"]
[Tue Jul 21 07:21:08.510970 2026] [security2:error] [pid 230252:tid 230511] [client 34.34.16.122:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vinculampe.com.br"] [uri "/"] [unique_id "al9IFE0Dwhk5-Z44Xro98gAAAxg"]
[Tue Jul 21 07:21:08.542786 2026] [security2:error] [pid 230252:tid 230408] [client 20.151.10.161:12058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file6.php"] [unique_id "al9IFE0Dwhk5-Z44Xro99AAAArE"]
[Tue Jul 21 07:21:08.589327 2026] [security2:error] [pid 230252:tid 230283] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFE0Dwhk5-Z44Xro99gAC9x0"]
[Tue Jul 21 07:21:08.589508 2026] [security2:error] [pid 230252:tid 230478] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFE0Dwhk5-Z44Xro99gAC9x0"]
[Tue Jul 21 07:21:08.608196 2026] [http2:warn] [pid 230252:tid 230444] [client 57.141.18.16:59356] h2_stream(230252-91-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:09.023402 2026] [security2:error] [pid 230252:tid 230297] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFU0Dwhk5-Z44Xro9_AAC8Ss"]
[Tue Jul 21 07:21:09.023561 2026] [security2:error] [pid 230252:tid 230472] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFU0Dwhk5-Z44Xro9_AAC8Ss"]
[Tue Jul 21 07:21:09.078327 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:09.078366 2026] [proxy_http:error] [pid 230252:tid 230421] [client 205.210.31.38:61000] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:09.078841 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:09.078875 2026] [proxy_http:error] [pid 230252:tid 230421] [client 205.210.31.38:61000] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:09.127692 2026] [http2:warn] [pid 229246:tid 229472] [client 57.141.18.92:23922] h2_stream(229246-290-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:09.134531 2026] [core:error] [pid 230252:tid 230402] [client 66.249.66.68:48595] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:21:09.134557 2026] [core:error] [pid 230252:tid 230402] [client 66.249.66.68:48595] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:21:09.164759 2026] [security2:error] [pid 230252:tid 230496] [client 114.119.157.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.imobiliariasobrado.net.br"] [uri "/imovel/terreno-venda-costa-e-silva-joinville-sc-v09004"] [unique_id "al9IFU0Dwhk5-Z44Xro-AwAAAwk"], referer: https://www.imobiliariasobrado.net.br/
[Tue Jul 21 07:21:09.252736 2026] [security2:error] [pid 230252:tid 230504] [client 20.220.225.223:34245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/dr.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-CAAAAxE"]
[Tue Jul 21 07:21:09.283945 2026] [security2:error] [pid 230252:tid 230455] [client 20.206.105.145:30713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/ingfo.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-CQAAAuA"]
[Tue Jul 21 07:21:09.320664 2026] [security2:error] [pid 230252:tid 230458] [client 4.204.201.85:17897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/fpwch.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-CgAAAuM"]
[Tue Jul 21 07:21:09.368356 2026] [security2:error] [pid 230252:tid 230426] [client 20.151.10.161:45912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xwpg.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-CwAAAsM"]
[Tue Jul 21 07:21:09.519387 2026] [security2:error] [pid 230252:tid 230401] [client 139.135.44.145:53378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-DAAAAqo"]
[Tue Jul 21 07:21:09.519506 2026] [security2:error] [pid 230252:tid 230401] [client 139.135.44.145:53378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-DAAAAqo"]
[Tue Jul 21 07:21:09.595316 2026] [security2:error] [pid 230252:tid 230409] [client 20.151.10.161:53612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/a2.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-DwAAArI"]
[Tue Jul 21 07:21:09.610190 2026] [security2:error] [pid 230252:tid 230435] [client 20.206.105.145:30665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/error_log.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-EAAAAsw"]
[Tue Jul 21 07:21:09.710837 2026] [security2:error] [pid 230252:tid 230497] [client 175.45.70.82:52325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-EQAAAwo"]
[Tue Jul 21 07:21:09.710981 2026] [security2:error] [pid 230252:tid 230497] [client 175.45.70.82:52325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-EQAAAwo"]
[Tue Jul 21 07:21:09.928674 2026] [security2:error] [pid 230252:tid 230282] [remote 132.148.72.88:54844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-EwACpxw"]
[Tue Jul 21 07:21:09.992232 2026] [security2:error] [pid 230252:tid 230484] [client 4.204.201.85:17900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/domvf.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-FAAAAv0"]
[Tue Jul 21 07:21:09.992806 2026] [security2:error] [pid 230252:tid 230486] [client 20.197.192.193:27075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/cron-tab.php"] [unique_id "al9IFU0Dwhk5-Z44Xro-FQAAAv8"]
[Tue Jul 21 07:21:10.067838 2026] [security2:error] [pid 229246:tid 229414] [client 120.61.173.56:56633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFiBMYeh5YLVG45xixQAAAjo"]
[Tue Jul 21 07:21:10.067965 2026] [security2:error] [pid 229246:tid 229414] [client 120.61.173.56:56633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IFiBMYeh5YLVG45xixQAAAjo"]
[Tue Jul 21 07:21:10.359394 2026] [security2:error] [pid 230252:tid 230509] [client 20.206.105.145:30683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/ok.php"] [unique_id "al9IFk0Dwhk5-Z44Xro-HAAAAxY"]
[Tue Jul 21 07:21:10.385422 2026] [security2:error] [pid 230252:tid 230445] [client 193.36.225.73:58655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IFk0Dwhk5-Z44Xro-HQAAAtY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:10.435250 2026] [security2:error] [pid 229246:tid 229441] [client 4.204.201.85:17861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp.php"] [unique_id "al9IFiBMYeh5YLVG45xiyQAAAlU"]
[Tue Jul 21 07:21:10.535461 2026] [http2:warn] [pid 229246:tid 229499] [client 57.141.18.87:56288] h2_stream(229246-292-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:10.555169 2026] [security2:error] [pid 229246:tid 229496] [client 134.19.179.187:37706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IFiBMYeh5YLVG45xiygAAAow"]
[Tue Jul 21 07:21:10.555289 2026] [security2:error] [pid 229246:tid 229496] [client 134.19.179.187:37706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IFiBMYeh5YLVG45xiygAAAow"]
[Tue Jul 21 07:21:10.717453 2026] [security2:error] [pid 229246:tid 229452] [client 20.104.96.117:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-css.php"] [unique_id "al9IFiBMYeh5YLVG45xi0AAAAmA"]
[Tue Jul 21 07:21:10.740082 2026] [security2:error] [pid 230252:tid 230403] [client 114.119.128.203:27961] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gradiente.com.br"] [uri "/mini-system/gradiente/Preto/139/Bluetooth/de%20101W%20at%C3%A9%20500W/Bivolt"] [unique_id "al9IFk0Dwhk5-Z44Xro-HwAAAqw"], referer: https://www.gradiente.com.br/mini-system/Preto/139/Bluetooth/de%20101W%20at%C3%A9%20500W/Bivolt?PS=12&map=c%2CspecificationFilter_21%2CproductClusterSearchableIds%2CspecificationFilter_18%2CspecificationFilter_22%2CspecificationFilter_20
[Tue Jul 21 07:21:10.760846 2026] [security2:error] [pid 230252:tid 230416] [client 92.119.178.3:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9IFk0Dwhk5-Z44Xro-IAAAArk"]
[Tue Jul 21 07:21:10.760937 2026] [security2:error] [pid 230252:tid 230416] [client 92.119.178.3:49796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9IFk0Dwhk5-Z44Xro-IAAAArk"]
[Tue Jul 21 07:21:10.766923 2026] [security2:error] [pid 229246:tid 229343] [remote 114.119.157.43:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aud-7.com"] [uri "/good.php"] [unique_id "al9IFiBMYeh5YLVG45xi0QACLGA"], referer: https://aud-7.com/good.php?tvvbf/t310000.html
[Tue Jul 21 07:21:10.825029 2026] [security2:error] [pid 229246:tid 229410] [client 4.204.201.85:17796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/class.php"] [unique_id "al9IFiBMYeh5YLVG45xi0gAAAjY"]
[Tue Jul 21 07:21:10.906883 2026] [security2:error] [pid 229246:tid 229476] [client 20.220.225.223:47816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/zzz.php"] [unique_id "al9IFiBMYeh5YLVG45xi1AAAAng"]
[Tue Jul 21 07:21:11.071905 2026] [security2:error] [pid 230252:tid 230354] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IF00Dwhk5-Z44Xro-IQACtmM"]
[Tue Jul 21 07:21:11.072087 2026] [security2:error] [pid 230252:tid 230413] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IF00Dwhk5-Z44Xro-IQACtmM"]
[Tue Jul 21 07:21:11.112502 2026] [http2:warn] [pid 229246:tid 229461] [client 57.141.18.115:63526] h2_stream(229246-294-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:11.173003 2026] [security2:error] [pid 230252:tid 230395] [client 114.119.144.64:42397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ellosemijoias.com.br"] [uri "/product-category/pulseiras/pulseiras-semi-joia/"] [unique_id "al9IF00Dwhk5-Z44Xro-JAAAAqQ"], referer: https://www.ellosemijoias.com.br/product-category/pulseiras/pulseiras-semi-joia/?orderby=menu_order
[Tue Jul 21 07:21:11.434080 2026] [security2:error] [pid 230252:tid 230384] [client 4.204.201.85:17896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/echkm.php"] [unique_id "al9IF00Dwhk5-Z44Xro-JwAAApk"]
[Tue Jul 21 07:21:11.705691 2026] [security2:error] [pid 229246:tid 229429] [client 20.151.10.161:12046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file15.php"] [unique_id "al9IFyBMYeh5YLVG45xi3QAAAkk"]
[Tue Jul 21 07:21:12.171711 2026] [security2:error] [pid 229246:tid 229453] [client 20.104.96.117:59159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ho.php"] [unique_id "al9IGCBMYeh5YLVG45xi4AAAAmE"]
[Tue Jul 21 07:21:12.227046 2026] [security2:error] [pid 230252:tid 230410] [client 20.206.105.145:30709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/mac.php"] [unique_id "al9IGE0Dwhk5-Z44Xro-MAAAArM"]
[Tue Jul 21 07:21:12.300649 2026] [security2:error] [pid 230252:tid 230445] [client 4.204.201.85:17902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/lib.php"] [unique_id "al9IGE0Dwhk5-Z44Xro-OAAAAtY"]
[Tue Jul 21 07:21:12.302737 2026] [security2:error] [pid 229246:tid 229403] [client 74.249.245.134:51019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/adminfuns.php"] [unique_id "al9IGCBMYeh5YLVG45xi4gAAAi8"]
[Tue Jul 21 07:21:12.319168 2026] [autoindex:error] [pid 229246:tid 229463] [client 205.210.31.49:58176] AH01276: Cannot serve directory /home2/tiago878/public_html/hostserv/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:21:12.427222 2026] [security2:error] [pid 230252:tid 230435] [client 47.128.37.143:13046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "drapatriciavarella.com.br"] [uri "/robots.txt"] [unique_id "al9IGE0Dwhk5-Z44Xro-OgAAAsw"]
[Tue Jul 21 07:21:12.504991 2026] [security2:error] [pid 230252:tid 230400] [client 20.226.60.151:54585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/gqgsa.php"] [unique_id "al9IGE0Dwhk5-Z44Xro-PAAAAqk"]
[Tue Jul 21 07:21:12.563580 2026] [security2:error] [pid 230252:tid 230416] [client 20.197.192.193:27101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/koiy.php"] [unique_id "al9IGE0Dwhk5-Z44Xro-PQAAArk"]
[Tue Jul 21 07:21:12.741118 2026] [http2:warn] [pid 230252:tid 230499] [client 57.141.18.82:56708] h2_stream(230252-113-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:12.823121 2026] [http2:warn] [pid 230252:tid 230450] [client 57.141.18.89:60890] h2_stream(230252-114-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:12.897006 2026] [security2:error] [pid 230252:tid 230485] [client 20.151.10.161:46000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/waf.php"] [unique_id "al9IGE0Dwhk5-Z44Xro-QgAAAv4"]
[Tue Jul 21 07:21:12.963046 2026] [security2:error] [pid 230252:tid 230426] [client 4.204.201.85:17792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/login.php"] [unique_id "al9IGE0Dwhk5-Z44Xro-QwAAAsM"]
[Tue Jul 21 07:21:13.098180 2026] [security2:error] [pid 230252:tid 230481] [client 103.121.156.110:62898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IGU0Dwhk5-Z44Xro-RgAAAvo"]
[Tue Jul 21 07:21:13.098318 2026] [security2:error] [pid 230252:tid 230481] [client 103.121.156.110:62898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IGU0Dwhk5-Z44Xro-RgAAAvo"]
[Tue Jul 21 07:21:13.250641 2026] [security2:error] [pid 229246:tid 229394] [client 103.162.129.114:62264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IGSBMYeh5YLVG45xi7wAAAiY"]
[Tue Jul 21 07:21:13.250748 2026] [security2:error] [pid 229246:tid 229394] [client 103.162.129.114:62264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IGSBMYeh5YLVG45xi7wAAAiY"]
[Tue Jul 21 07:21:13.369581 2026] [security2:error] [pid 229246:tid 229381] [client 20.220.225.223:47826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wicked.php"] [unique_id "al9IGSBMYeh5YLVG45xi8QAAAhk"]
[Tue Jul 21 07:21:13.435819 2026] [security2:error] [pid 230252:tid 230385] [client 34.148.166.21:56900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.166.148.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/xmlrpc.php"] [unique_id "al9IGE0Dwhk5-Z44Xro-OwAAApo"]
[Tue Jul 21 07:21:13.440861 2026] [security2:error] [pid 229246:tid 229383] [client 20.104.96.117:59143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/xy.php"] [unique_id "al9IGSBMYeh5YLVG45xi9QAAAhs"]
[Tue Jul 21 07:21:13.532218 2026] [security2:error] [pid 229246:tid 229454] [client 4.204.201.85:17814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/a2.php"] [unique_id "al9IGSBMYeh5YLVG45xi9wAAAmI"]
[Tue Jul 21 07:21:13.676062 2026] [security2:error] [pid 230252:tid 230495] [client 34.148.166.21:57253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/web/wp-includes/wlwmanifest.xml"] [unique_id "al9IGU0Dwhk5-Z44Xro-RwAAAwg"]
[Tue Jul 21 07:21:13.760572 2026] [security2:error] [pid 229246:tid 229493] [client 20.197.192.193:27124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/hp2.php"] [unique_id "al9IGSBMYeh5YLVG45xi-gAAAok"]
[Tue Jul 21 07:21:13.902050 2026] [security2:error] [pid 230252:tid 230478] [client 20.206.105.145:30718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wefile.php"] [unique_id "al9IGU0Dwhk5-Z44Xro-SwAAAvc"]
[Tue Jul 21 07:21:13.949904 2026] [security2:error] [pid 230252:tid 230452] [client 34.148.166.21:51185] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9IGU0Dwhk5-Z44Xro-TAAAAt0"]
[Tue Jul 21 07:21:14.059996 2026] [security2:error] [pid 229246:tid 229387] [client 4.204.201.85:17899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/d61.php"] [unique_id "al9IGiBMYeh5YLVG45xi_QAAAh8"]
[Tue Jul 21 07:21:14.178438 2026] [http2:warn] [pid 230252:tid 230386] [client 57.141.18.31:41848] h2_stream(230252-116-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:14.221345 2026] [security2:error] [pid 229246:tid 229464] [client 34.148.166.21:64274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9IGiBMYeh5YLVG45xi_wAAAmw"]
[Tue Jul 21 07:21:14.222750 2026] [security2:error] [pid 229246:tid 229313] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IGiBMYeh5YLVG45xjAAACekI"]
[Tue Jul 21 07:21:14.222958 2026] [security2:error] [pid 229246:tid 229478] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IGiBMYeh5YLVG45xjAAACekI"]
[Tue Jul 21 07:21:14.277118 2026] [security2:error] [pid 229246:tid 229503] [client 114.119.134.106:52933] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bcsenepol.com.br"] [uri "/home/sem-titulo-2/"] [unique_id "al9IGiBMYeh5YLVG45xjBAAAApM"], referer: https://bcsenepol.com.br/home/sem-titulo-2/
[Tue Jul 21 07:21:14.283014 2026] [security2:error] [pid 230252:tid 230327] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IGk0Dwhk5-Z44Xro-TwACs0g"]
[Tue Jul 21 07:21:14.283183 2026] [security2:error] [pid 230252:tid 230410] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IGk0Dwhk5-Z44Xro-TwACs0g"]
[Tue Jul 21 07:21:14.483131 2026] [security2:error] [pid 229246:tid 229414] [client 193.36.225.61:58863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IGiBMYeh5YLVG45xjBgAAAjo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:14.484768 2026] [security2:error] [pid 229246:tid 229429] [client 34.148.166.21:50429] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9IGiBMYeh5YLVG45xjBwAAAkk"]
[Tue Jul 21 07:21:14.664330 2026] [security2:error] [pid 229246:tid 229403] [client 20.206.105.145:30604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9IGiBMYeh5YLVG45xjCQAAAi8"]
[Tue Jul 21 07:21:14.731419 2026] [security2:error] [pid 230252:tid 230420] [client 34.148.166.21:64680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9IGk0Dwhk5-Z44Xro-UAAAAr0"]
[Tue Jul 21 07:21:14.787477 2026] [http2:warn] [pid 229246:tid 229489] [client 57.141.18.51:39434] h2_stream(229246-298-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:14.810218 2026] [security2:error] [pid 230252:tid 230398] [client 4.204.201.85:17914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/info.php"] [unique_id "al9IGk0Dwhk5-Z44Xro-UQAAAqc"]
[Tue Jul 21 07:21:14.946650 2026] [http2:warn] [pid 229246:tid 229440] [client 57.141.18.5:49164] h2_stream(229246-300-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:14.987099 2026] [security2:error] [pid 230252:tid 230400] [client 34.148.166.21:57053] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9IGk0Dwhk5-Z44Xro-VgAAAqk"]
[Tue Jul 21 07:21:15.037493 2026] [security2:error] [pid 230252:tid 230389] [client 20.104.96.117:59680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/loader.php"] [unique_id "al9IG00Dwhk5-Z44Xro-WAAAAp4"]
[Tue Jul 21 07:21:15.101691 2026] [security2:error] [pid 229246:tid 229459] [client 20.220.225.223:34208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/2x.php"] [unique_id "al9IGyBMYeh5YLVG45xjDwAAAmc"]
[Tue Jul 21 07:21:15.131382 2026] [security2:error] [pid 230252:tid 230430] [client 20.220.225.223:59465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/edit.php"] [unique_id "al9IG00Dwhk5-Z44Xro-WgAAAsc"]
[Tue Jul 21 07:21:15.235475 2026] [security2:error] [pid 230252:tid 230501] [client 14.139.42.196:1816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IG00Dwhk5-Z44Xro-XAAAAw4"]
[Tue Jul 21 07:21:15.235582 2026] [security2:error] [pid 230252:tid 230501] [client 14.139.42.196:1816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IG00Dwhk5-Z44Xro-XAAAAw4"]
[Tue Jul 21 07:21:15.257705 2026] [security2:error] [pid 230252:tid 230440] [client 34.148.166.21:60358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/test/wp-includes/wlwmanifest.xml"] [unique_id "al9IG00Dwhk5-Z44Xro-XQAAAtE"]
[Tue Jul 21 07:21:15.407069 2026] [security2:error] [pid 230252:tid 230395] [client 20.197.192.193:27173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/hp3.php"] [unique_id "al9IG00Dwhk5-Z44Xro-XwAAAqQ"]
[Tue Jul 21 07:21:15.463452 2026] [security2:error] [pid 229246:tid 229391] [client 45.251.232.145:64771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IGyBMYeh5YLVG45xjFwAAAiM"]
[Tue Jul 21 07:21:15.463947 2026] [security2:error] [pid 229246:tid 229391] [client 45.251.232.145:64771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IGyBMYeh5YLVG45xjFwAAAiM"]
[Tue Jul 21 07:21:15.541703 2026] [security2:error] [pid 229246:tid 229441] [client 34.148.166.21:54746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "look.dealspark.com.br"] [uri "/cgi-sys/suspendedpage.cgi/site/wp-includes/wlwmanifest.xml"] [unique_id "al9IGyBMYeh5YLVG45xjGQAAAlU"]
[Tue Jul 21 07:21:15.585733 2026] [security2:error] [pid 229246:tid 229496] [client 4.204.201.85:44006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/11.php"] [unique_id "al9IGyBMYeh5YLVG45xjGwAAAow"]
[Tue Jul 21 07:21:16.004018 2026] [security2:error] [pid 230252:tid 230392] [client 20.197.192.193:27094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/aa1.php"] [unique_id "al9IHE0Dwhk5-Z44Xro-aAAAAqE"]
[Tue Jul 21 07:21:16.014747 2026] [security2:error] [pid 229246:tid 229501] [client 114.119.138.178:51841] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dharmanet.com.br"] [uri "/honganji"] [unique_id "al9IHCBMYeh5YLVG45xjIQAAApE"], referer: http://www.buddhanet.info/wbd/region.php?id=7900&offset=5325
[Tue Jul 21 07:21:16.132548 2026] [security2:error] [pid 230252:tid 230465] [client 20.104.96.117:59183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/spadex.php"] [unique_id "al9IHE0Dwhk5-Z44Xro-aQAAAuo"]
[Tue Jul 21 07:21:16.165386 2026] [security2:error] [pid 229246:tid 229355] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IHCBMYeh5YLVG45xjIgACG2w"]
[Tue Jul 21 07:21:16.165519 2026] [security2:error] [pid 229246:tid 229383] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IHCBMYeh5YLVG45xjIgACG2w"]
[Tue Jul 21 07:21:16.246477 2026] [security2:error] [pid 230252:tid 230428] [client 4.204.201.85:17797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/v2.php"] [unique_id "al9IHE0Dwhk5-Z44Xro-agAAAsU"]
[Tue Jul 21 07:21:16.376432 2026] [security2:error] [pid 230252:tid 230510] [client 173.252.95.57:34208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9IG00Dwhk5-Z44Xro-WwAAAxc"]
[Tue Jul 21 07:21:16.473172 2026] [http2:warn] [pid 230252:tid 230492] [client 57.141.18.95:54948] h2_stream(230252-125-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:16.701256 2026] [security2:error] [pid 229246:tid 229431] [client 20.206.105.145:30694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9IHCBMYeh5YLVG45xjLAAAAks"]
[Tue Jul 21 07:21:16.888439 2026] [security2:error] [pid 230252:tid 230389] [client 4.204.201.85:17816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/panel.php"] [unique_id "al9IHE0Dwhk5-Z44Xro-cwAAAp4"]
[Tue Jul 21 07:21:17.342001 2026] [security2:error] [pid 230252:tid 230412] [client 20.104.96.117:59138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/2x.php"] [unique_id "al9IHU0Dwhk5-Z44Xro-dQAAArU"]
[Tue Jul 21 07:21:17.438213 2026] [security2:error] [pid 229246:tid 229403] [client 20.151.10.161:11762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/jp.php"] [unique_id "al9IHSBMYeh5YLVG45xjNAAAAi8"]
[Tue Jul 21 07:21:17.581767 2026] [security2:error] [pid 230252:tid 230496] [client 20.206.105.145:30644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/like.php"] [unique_id "al9IHU0Dwhk5-Z44Xro-eQAAAwk"]
[Tue Jul 21 07:21:17.581957 2026] [http2:warn] [pid 230252:tid 230453] [client 57.141.18.75:31792] h2_stream(230252-129-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:17.644007 2026] [security2:error] [pid 229246:tid 229430] [client 74.249.245.134:62296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/php8.php"] [unique_id "al9IHSBMYeh5YLVG45xjOQAAAko"]
[Tue Jul 21 07:21:17.649901 2026] [proxy:error] [pid 230252:tid 230395] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:17.649969 2026] [proxy_http:error] [pid 230252:tid 230395] [client 161.35.142.61:58978] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:17.650558 2026] [proxy:error] [pid 230252:tid 230395] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:17.650586 2026] [proxy_http:error] [pid 230252:tid 230395] [client 161.35.142.61:58978] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:17.728333 2026] [security2:error] [pid 229246:tid 229432] [client 8.228.118.177:54822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9IHSBMYeh5YLVG45xjOgAAAkw"]
[Tue Jul 21 07:21:17.745587 2026] [security2:error] [pid 229246:tid 229404] [client 20.197.192.193:27156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/acew67.php"] [unique_id "al9IHSBMYeh5YLVG45xjOwAAAjA"]
[Tue Jul 21 07:21:17.883019 2026] [proxy:error] [pid 230252:tid 230385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:17.883094 2026] [proxy_http:error] [pid 230252:tid 230385] [client 161.35.142.61:58982] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.dpatrick.com.br/
[Tue Jul 21 07:21:17.883746 2026] [proxy:error] [pid 230252:tid 230385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:17.883780 2026] [proxy_http:error] [pid 230252:tid 230385] [client 161.35.142.61:58982] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.dpatrick.com.br/
[Tue Jul 21 07:21:17.975759 2026] [security2:error] [pid 230252:tid 230384] [client 8.228.118.177:54753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.118.228.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IHU0Dwhk5-Z44Xro-fQAAApk"]
[Tue Jul 21 07:21:18.016197 2026] [security2:error] [pid 230252:tid 230409] [client 20.104.96.117:59655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ctex1.php"] [unique_id "al9IHk0Dwhk5-Z44Xro-fwAAArI"]
[Tue Jul 21 07:21:18.063116 2026] [security2:error] [pid 229246:tid 229391] [client 20.220.225.223:36831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/kua.php"] [unique_id "al9IHiBMYeh5YLVG45xjQAAAAiM"]
[Tue Jul 21 07:21:18.227876 2026] [security2:error] [pid 229246:tid 229408] [client 8.228.118.177:65447] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9IHiBMYeh5YLVG45xjQgAAAjQ"]
[Tue Jul 21 07:21:18.346530 2026] [proxy:error] [pid 229246:tid 229472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:18.346568 2026] [proxy_http:error] [pid 229246:tid 229472] [client 161.35.142.61:47716] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:18.347319 2026] [proxy:error] [pid 229246:tid 229472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:18.347358 2026] [proxy_http:error] [pid 229246:tid 229472] [client 161.35.142.61:47716] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:18.389525 2026] [security2:error] [pid 230252:tid 230399] [client 20.226.60.151:54497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/elbzl.php"] [unique_id "al9IHk0Dwhk5-Z44Xro-ggAAAqg"]
[Tue Jul 21 07:21:18.442657 2026] [security2:error] [pid 230252:tid 230478] [client 114.119.141.152:43445] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ssvistorias.com.br"] [uri "/zgkb.php"] [unique_id "al9IHk0Dwhk5-Z44Xro-gwAAAvc"], referer: http://www.ssvistorias.com.br/zgkb.php?mall/-gdq/21/tg_22276/
[Tue Jul 21 07:21:18.478501 2026] [security2:error] [pid 230252:tid 230484] [client 8.228.118.177:55272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9IHk0Dwhk5-Z44Xro-hQAAAv0"]
[Tue Jul 21 07:21:18.616156 2026] [http2:warn] [pid 230252:tid 230506] [client 57.141.18.72:43702] h2_stream(230252-131-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:18.655502 2026] [security2:error] [pid 230252:tid 230454] [client 193.36.225.65:53047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IHk0Dwhk5-Z44Xro-hAAAAt8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:18.711644 2026] [security2:error] [pid 230252:tid 230441] [client 20.197.192.193:27103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/bscclapb.php"] [unique_id "al9IHk0Dwhk5-Z44Xro-igAAAtI"]
[Tue Jul 21 07:21:18.726312 2026] [security2:error] [pid 230252:tid 230510] [client 8.228.118.177:64088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9IHk0Dwhk5-Z44Xro-iwAAAxc"]
[Tue Jul 21 07:21:18.974305 2026] [security2:error] [pid 230252:tid 230421] [client 8.228.118.177:63134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9IHk0Dwhk5-Z44Xro-jQAAAr4"]
[Tue Jul 21 07:21:19.059317 2026] [security2:error] [pid 229246:tid 229453] [client 74.7.241.190:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "printcom.com.br"] [uri "/index.php"] [unique_id "al9IHSBMYeh5YLVG45xjNwACYRI"], referer: http://printcom.com.br/robots.txt
[Tue Jul 21 07:21:19.100501 2026] [security2:error] [pid 230252:tid 230435] [client 114.119.158.106:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sobradoimoveis.com.br"] [uri "/imovel/casa-3-quartos-com-garagem-13405m2-venda-atiradores-joinville-sc-kr444"] [unique_id "al9IH00Dwhk5-Z44Xro-kAAAAsw"], referer: https://www.sobradoimoveis.com.br/imovel/casa-3-quartos-com-garagem-13405m2-venda-atiradores-joinville-sc-kr444?opcao=KR444&cd_empresa=4
[Tue Jul 21 07:21:19.107416 2026] [security2:error] [pid 229246:tid 229452] [client 4.204.201.85:17795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/dex.php"] [unique_id "al9IHyBMYeh5YLVG45xjUwAAAmA"]
[Tue Jul 21 07:21:19.111636 2026] [security2:error] [pid 230252:tid 230332] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IH00Dwhk5-Z44Xro-kQACp00"]
[Tue Jul 21 07:21:19.111770 2026] [security2:error] [pid 230252:tid 230398] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IH00Dwhk5-Z44Xro-kQACp00"]
[Tue Jul 21 07:21:19.121530 2026] [security2:error] [pid 230252:tid 230326] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IH00Dwhk5-Z44Xro-kgAC8Uc"]
[Tue Jul 21 07:21:19.121701 2026] [security2:error] [pid 230252:tid 230472] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IH00Dwhk5-Z44Xro-kgAC8Uc"]
[Tue Jul 21 07:21:19.170584 2026] [http2:warn] [pid 230252:tid 230405] [client 57.141.18.59:53316] h2_stream(230252-135-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:19.226340 2026] [security2:error] [pid 230252:tid 230430] [client 8.228.118.177:63471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9IH00Dwhk5-Z44Xro-kwAAAsc"]
[Tue Jul 21 07:21:19.286024 2026] [security2:error] [pid 230252:tid 230426] [client 20.104.96.117:59657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/edorxrr.php"] [unique_id "al9IH00Dwhk5-Z44Xro-lQAAAsM"]
[Tue Jul 21 07:21:19.292939 2026] [security2:error] [pid 229246:tid 229476] [client 114.119.140.169:46165] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tragaseushow.com.br"] [uri "/projeto/monica-tomasi"] [unique_id "al9IHyBMYeh5YLVG45xjVAAAAng"], referer: http://tragaseushow.com.br/projeto/monica-tomasi
[Tue Jul 21 07:21:19.339211 2026] [security2:error] [pid 230252:tid 230496] [client 20.220.225.223:52782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/ez.php"] [unique_id "al9IH00Dwhk5-Z44Xro-lwAAAwk"]
[Tue Jul 21 07:21:19.403187 2026] [security2:error] [pid 230252:tid 230385] [client 20.206.105.145:30685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/.well-known/about.php"] [unique_id "al9IH00Dwhk5-Z44Xro-mAAAApo"]
[Tue Jul 21 07:21:19.477494 2026] [security2:error] [pid 230252:tid 230409] [client 8.228.118.177:58720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9IH00Dwhk5-Z44Xro-nAAAArI"]
[Tue Jul 21 07:21:19.526934 2026] [security2:error] [pid 230252:tid 230509] [client 20.226.60.151:54473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/adjig.php"] [unique_id "al9IH00Dwhk5-Z44Xro-nQAAAxY"]
[Tue Jul 21 07:21:19.655943 2026] [security2:error] [pid 230252:tid 230267] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IH00Dwhk5-Z44Xro-ogACzQ0"]
[Tue Jul 21 07:21:19.656099 2026] [security2:error] [pid 230252:tid 230436] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IH00Dwhk5-Z44Xro-ogACzQ0"]
[Tue Jul 21 07:21:19.721238 2026] [security2:error] [pid 230252:tid 230510] [client 8.228.118.177:50452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9IH00Dwhk5-Z44Xro-pAAAAxc"]
[Tue Jul 21 07:21:19.965651 2026] [security2:error] [pid 229246:tid 229431] [client 8.228.118.177:50973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9IHyBMYeh5YLVG45xjWAAAAks"]
[Tue Jul 21 07:21:20.064961 2026] [security2:error] [pid 229246:tid 229434] [client 20.151.10.161:45942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xstelth.php"] [unique_id "al9IICBMYeh5YLVG45xjWQAAAk4"]
[Tue Jul 21 07:21:20.150167 2026] [http2:warn] [pid 229246:tid 229457] [client 57.141.18.69:31978] h2_stream(229246-306-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:20.195592 2026] [security2:error] [pid 230252:tid 230451] [client 114.119.143.104:30469] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "inonebrasil.com.br"] [uri "/nyqlf/k110524.html"] [unique_id "al9IIE0Dwhk5-Z44Xro-pwAAAtw"], referer: https://inonebrasil.com.br/nyqlf/k110524.html
[Tue Jul 21 07:21:20.216503 2026] [security2:error] [pid 230252:tid 230403] [client 8.228.118.177:59449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9IIE0Dwhk5-Z44Xro-qQAAAqw"]
[Tue Jul 21 07:21:20.317206 2026] [security2:error] [pid 230252:tid 230269] [remote 45.79.123.44:52574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-qgAC4g8"]
[Tue Jul 21 07:21:20.348361 2026] [security2:error] [pid 230252:tid 230416] [client 20.104.96.117:59703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/miru1.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-qwAAArk"]
[Tue Jul 21 07:21:20.365288 2026] [http2:warn] [pid 229246:tid 229409] [client 57.141.18.50:23848] h2_stream(229246-307-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:20.416109 2026] [security2:error] [pid 230252:tid 230465] [client 175.45.70.82:52825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-rAAAAuo"]
[Tue Jul 21 07:21:20.416261 2026] [security2:error] [pid 230252:tid 230465] [client 175.45.70.82:52825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-rAAAAuo"]
[Tue Jul 21 07:21:20.472483 2026] [security2:error] [pid 230252:tid 230485] [client 8.228.118.177:58224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9IIE0Dwhk5-Z44Xro-rwAAAv4"]
[Tue Jul 21 07:21:20.508803 2026] [security2:error] [pid 230252:tid 230450] [client 20.151.10.161:12063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/f35.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-sQAAAts"]
[Tue Jul 21 07:21:20.567604 2026] [security2:error] [pid 229246:tid 229478] [client 139.135.44.145:54184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IICBMYeh5YLVG45xjXgAAAno"]
[Tue Jul 21 07:21:20.567739 2026] [security2:error] [pid 229246:tid 229478] [client 139.135.44.145:54184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IICBMYeh5YLVG45xjXgAAAno"]
[Tue Jul 21 07:21:20.648529 2026] [security2:error] [pid 229246:tid 229418] [client 20.220.225.223:36825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/fz.php"] [unique_id "al9IICBMYeh5YLVG45xjYAAAAj4"]
[Tue Jul 21 07:21:20.665447 2026] [security2:error] [pid 229246:tid 229401] [client 120.61.173.56:56906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.173.61.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IICBMYeh5YLVG45xjYwAAAi0"]
[Tue Jul 21 07:21:20.665546 2026] [security2:error] [pid 229246:tid 229401] [client 120.61.173.56:56906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IICBMYeh5YLVG45xjYwAAAi0"]
[Tue Jul 21 07:21:20.708886 2026] [security2:error] [pid 230252:tid 230455] [client 4.204.201.85:17879] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "beezar.com.br"] [uri "/1.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-sgAAAuA"]
[Tue Jul 21 07:21:20.708994 2026] [security2:error] [pid 230252:tid 230455] [client 4.204.201.85:17879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/1.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-sgAAAuA"]
[Tue Jul 21 07:21:20.727824 2026] [security2:error] [pid 230252:tid 230425] [client 8.228.118.177:58567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9IIE0Dwhk5-Z44Xro-swAAAsI"]
[Tue Jul 21 07:21:20.803123 2026] [security2:error] [pid 230252:tid 230442] [client 54.39.89.168:37822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "porondeeuestive.com.br"] [uri "/robots.txt"] [unique_id "al9IIE0Dwhk5-Z44Xro-tAAAAtM"]
[Tue Jul 21 07:21:20.803228 2026] [security2:error] [pid 230252:tid 230442] [client 54.39.89.168:37822] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "porondeeuestive.com.br"] [uri "/robots.txt"] [unique_id "al9IIE0Dwhk5-Z44Xro-tAAAAtM"]
[Tue Jul 21 07:21:20.816515 2026] [security2:error] [pid 230252:tid 230384] [client 20.206.105.145:30710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-tQAAApk"]
[Tue Jul 21 07:21:20.870311 2026] [security2:error] [pid 230252:tid 230439] [client 20.104.96.117:59172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/sump1.php"] [unique_id "al9IIE0Dwhk5-Z44Xro-tgAAAtA"]
[Tue Jul 21 07:21:20.940229 2026] [security2:error] [pid 229246:tid 229404] [client 74.249.245.134:52462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/info.php"] [unique_id "al9IICBMYeh5YLVG45xjZwAAAjA"]
[Tue Jul 21 07:21:20.965403 2026] [security2:error] [pid 230252:tid 230499] [client 8.228.118.177:57280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9IIE0Dwhk5-Z44Xro-twAAAww"]
[Tue Jul 21 07:21:21.093115 2026] [proxy:error] [pid 230252:tid 230409] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:21.093169 2026] [proxy_http:error] [pid 230252:tid 230409] [client 161.35.142.61:47844] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.dpatrick.com.br/
[Tue Jul 21 07:21:21.093753 2026] [proxy:error] [pid 230252:tid 230409] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:21.093773 2026] [proxy_http:error] [pid 230252:tid 230409] [client 161.35.142.61:47844] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.dpatrick.com.br/
[Tue Jul 21 07:21:21.145911 2026] [http2:warn] [pid 229246:tid 229468] [client 57.141.18.115:31648] h2_stream(229246-311-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:21.219505 2026] [security2:error] [pid 230252:tid 230454] [client 8.228.118.177:54507] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9IIU0Dwhk5-Z44Xro-uwAAAt8"]
[Tue Jul 21 07:21:21.242022 2026] [security2:error] [pid 230252:tid 230272] [remote 41.76.214.143:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fidellium.com"] [uri "/wp-login.php"] [unique_id "al9IIU0Dwhk5-Z44Xro-vAADGBI"]
[Tue Jul 21 07:21:21.473480 2026] [security2:error] [pid 230252:tid 230420] [client 8.228.118.177:58569] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9IIU0Dwhk5-Z44Xro-vwAAAr0"]
[Tue Jul 21 07:21:21.485761 2026] [security2:error] [pid 229246:tid 229436] [client 20.104.96.117:61154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/file5.php"] [unique_id "al9IISBMYeh5YLVG45xjbAAAAlA"]
[Tue Jul 21 07:21:21.588410 2026] [security2:error] [pid 230252:tid 230355] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IIU0Dwhk5-Z44Xro-wAACs2Q"]
[Tue Jul 21 07:21:21.588602 2026] [security2:error] [pid 230252:tid 230410] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IIU0Dwhk5-Z44Xro-wAACs2Q"]
[Tue Jul 21 07:21:21.644772 2026] [security2:error] [pid 230252:tid 230435] [client 20.151.10.161:11736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-load.php"] [unique_id "al9IIU0Dwhk5-Z44Xro-wQAAAsw"]
[Tue Jul 21 07:21:21.716899 2026] [security2:error] [pid 230252:tid 230476] [client 8.228.118.177:65395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9IIU0Dwhk5-Z44Xro-xQAAAvU"]
[Tue Jul 21 07:21:21.724953 2026] [security2:error] [pid 230252:tid 230430] [client 4.204.201.85:43993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/ms.php"] [unique_id "al9IIU0Dwhk5-Z44Xro-xgAAAsc"]
[Tue Jul 21 07:21:21.831390 2026] [security2:error] [pid 229246:tid 229394] [client 20.206.105.145:30705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/pucci.php"] [unique_id "al9IISBMYeh5YLVG45xjcwAAAiY"]
[Tue Jul 21 07:21:21.965297 2026] [security2:error] [pid 230252:tid 230450] [client 8.228.118.177:60437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.g7laboratoriooptico.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9IIU0Dwhk5-Z44Xro-xwAAAts"]
[Tue Jul 21 07:21:22.058857 2026] [security2:error] [pid 229246:tid 229475] [client 20.220.225.223:36837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/la.php"] [unique_id "al9IIiBMYeh5YLVG45xjdAAAAnc"]
[Tue Jul 21 07:21:22.160151 2026] [security2:error] [pid 230252:tid 230395] [client 20.226.60.151:54561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/byp.php"] [unique_id "al9IIk0Dwhk5-Z44Xro-yAAAAqQ"]
[Tue Jul 21 07:21:22.346932 2026] [security2:error] [pid 230252:tid 230439] [client 20.151.10.161:11666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xwpg.php"] [unique_id "al9IIk0Dwhk5-Z44Xro-zwAAAtA"]
[Tue Jul 21 07:21:22.358797 2026] [security2:error] [pid 230252:tid 230423] [client 20.104.96.117:59689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/0xD.php"] [unique_id "al9IIk0Dwhk5-Z44Xro-0AAAAsA"]
[Tue Jul 21 07:21:22.452002 2026] [http2:warn] [pid 229246:tid 229494] [client 57.141.18.18:23752] h2_stream(229246-314-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:22.992836 2026] [security2:error] [pid 229246:tid 229395] [client 114.119.151.93:37479] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.politicabrasil.com.br"] [uri "/post/prefeito-vitor-valim-visita-sede-da-fiec-e-garante-parcerias-na-%C3%A1rea-da-educa%C3%A7%C3%A3o"] [unique_id "al9IIiBMYeh5YLVG45xjggAAAic"], referer: https://www.politicabrasil.com.br/post/chico-buarque-processa-eduardo-bolsonaro-novamente-e-vence
[Tue Jul 21 07:21:23.071646 2026] [security2:error] [pid 229246:tid 229384] [client 20.104.96.117:59141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/fnstall.php"] [unique_id "al9IIyBMYeh5YLVG45xjgwAAAhw"]
[Tue Jul 21 07:21:23.219081 2026] [security2:error] [pid 229246:tid 229431] [client 134.19.179.187:33450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IIyBMYeh5YLVG45xjhQAAAks"]
[Tue Jul 21 07:21:23.219200 2026] [security2:error] [pid 229246:tid 229431] [client 134.19.179.187:33450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IIyBMYeh5YLVG45xjhQAAAks"]
[Tue Jul 21 07:21:23.226609 2026] [security2:error] [pid 230252:tid 230453] [client 20.151.10.161:55278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/waf.php"] [unique_id "al9II00Dwhk5-Z44Xro-3AAAAt4"]
[Tue Jul 21 07:21:23.550887 2026] [security2:error] [pid 230252:tid 230303] [remote 188.138.102.156:50608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "digitaclick.com"] [uri "/wp-login.php"] [unique_id "al9II00Dwhk5-Z44Xro-4AADGDE"]
[Tue Jul 21 07:21:23.666204 2026] [security2:error] [pid 230252:tid 230485] [client 20.206.105.145:30645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-temp.php"] [unique_id "al9II00Dwhk5-Z44Xro-4wAAAv4"]
[Tue Jul 21 07:21:23.668435 2026] [security2:error] [pid 230252:tid 230431] [client 34.74.242.206:1654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.northcomm.com.br"] [uri "/robots.txt"] [unique_id "al9II00Dwhk5-Z44Xro-5AAAAsg"]
[Tue Jul 21 07:21:23.668526 2026] [security2:error] [pid 230252:tid 230431] [client 34.74.242.206:1654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.northcomm.com.br"] [uri "/robots.txt"] [unique_id "al9II00Dwhk5-Z44Xro-5AAAAsg"]
[Tue Jul 21 07:21:23.688323 2026] [security2:error] [pid 230252:tid 230426] [client 20.104.96.117:59700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/acp.php"] [unique_id "al9II00Dwhk5-Z44Xro-5QAAAsM"]
[Tue Jul 21 07:21:23.703009 2026] [security2:error] [pid 230252:tid 230412] [client 20.151.10.161:12062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xstelth.php"] [unique_id "al9II00Dwhk5-Z44Xro-5gAAArU"]
[Tue Jul 21 07:21:23.721874 2026] [security2:error] [pid 229246:tid 229387] [client 103.162.129.114:62748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IIyBMYeh5YLVG45xjiwAAAh8"]
[Tue Jul 21 07:21:23.721974 2026] [security2:error] [pid 229246:tid 229387] [client 103.162.129.114:62748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IIyBMYeh5YLVG45xjiwAAAh8"]
[Tue Jul 21 07:21:23.811319 2026] [security2:error] [pid 229246:tid 229380] [client 103.121.156.110:63227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IIyBMYeh5YLVG45xjjgAAAhg"]
[Tue Jul 21 07:21:23.811415 2026] [security2:error] [pid 229246:tid 229380] [client 103.121.156.110:63227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IIyBMYeh5YLVG45xjjgAAAhg"]
[Tue Jul 21 07:21:23.916639 2026] [security2:error] [pid 230252:tid 230442] [client 34.74.242.206:1647] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.northcomm.com.br"] [uri "/"] [unique_id "al9II00Dwhk5-Z44Xro-6gAAAtM"]
[Tue Jul 21 07:21:23.916742 2026] [security2:error] [pid 230252:tid 230442] [client 34.74.242.206:1647] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.northcomm.com.br"] [uri "/"] [unique_id "al9II00Dwhk5-Z44Xro-6gAAAtM"]
[Tue Jul 21 07:21:23.980985 2026] [security2:error] [pid 229246:tid 229382] [client 114.119.146.117:63479] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/index.php/wishlist/index/add/product/54/form_key/Su9aBVdW3rd6fsBm"] [unique_id "al9IIyBMYeh5YLVG45xjkQAAAho"], referer: http://www.ceramicasantoaugusto.com.br/index.php/produtos.html?dir=desc&order=position
[Tue Jul 21 07:21:24.006113 2026] [security2:error] [pid 229246:tid 229495] [client 20.151.10.161:53606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-links.php"] [unique_id "al9IJCBMYeh5YLVG45xjkgAAAos"]
[Tue Jul 21 07:21:24.034194 2026] [http2:warn] [pid 230252:tid 230477] [client 57.141.18.108:24376] h2_stream(230252-148-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:24.095621 2026] [security2:error] [pid 230252:tid 230413] [client 114.119.138.251:52965] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/recurso/sauna"] [unique_id "al9IJE0Dwhk5-Z44Xro-7QAAArY"], referer: https://powerflats.com.br/recurso/sauna
[Tue Jul 21 07:21:24.229105 2026] [security2:error] [pid 230252:tid 230496] [client 20.104.96.117:59151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/mosty.php"] [unique_id "al9IJE0Dwhk5-Z44Xro-7gAAAwk"]
[Tue Jul 21 07:21:24.263264 2026] [security2:error] [pid 230252:tid 230439] [client 4.204.201.85:17876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/memberfuns.php"] [unique_id "al9IJE0Dwhk5-Z44Xro-7wAAAtA"]
[Tue Jul 21 07:21:24.407033 2026] [security2:error] [pid 230252:tid 230408] [client 20.220.225.223:47810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9IJE0Dwhk5-Z44Xro-8AAAArE"]
[Tue Jul 21 07:21:24.529943 2026] [security2:error] [pid 229246:tid 229492] [client 20.151.10.161:12067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9IJCBMYeh5YLVG45xjmAAAAog"]
[Tue Jul 21 07:21:24.663131 2026] [security2:error] [pid 230252:tid 230345] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IJE0Dwhk5-Z44Xro-8wACoVo"]
[Tue Jul 21 07:21:24.663327 2026] [security2:error] [pid 230252:tid 230392] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IJE0Dwhk5-Z44Xro-8wACoVo"]
[Tue Jul 21 07:21:24.712662 2026] [security2:error] [pid 229246:tid 229449] [client 20.104.96.117:59150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/6.php"] [unique_id "al9IJCBMYeh5YLVG45xjmgAAAl0"]
[Tue Jul 21 07:21:24.849320 2026] [security2:error] [pid 229246:tid 229460] [client 20.151.10.161:45827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-links.php"] [unique_id "al9IJCBMYeh5YLVG45xjngAAAmg"]
[Tue Jul 21 07:21:24.854521 2026] [security2:error] [pid 230252:tid 230290] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IJE0Dwhk5-Z44Xro-9QAC0SQ"]
[Tue Jul 21 07:21:24.854639 2026] [security2:error] [pid 230252:tid 230440] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IJE0Dwhk5-Z44Xro-9QAC0SQ"]
[Tue Jul 21 07:21:24.920478 2026] [http2:warn] [pid 230252:tid 230474] [client 57.141.18.74:54378] h2_stream(230252-151-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:25.071769 2026] [http2:warn] [pid 229246:tid 229448] [client 57.141.18.104:33866] h2_stream(229246-321-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:25.128339 2026] [security2:error] [pid 229246:tid 229475] [client 4.204.201.85:17803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/0.php"] [unique_id "al9IJSBMYeh5YLVG45xjoAAAAnc"]
[Tue Jul 21 07:21:25.313052 2026] [security2:error] [pid 229246:tid 229400] [client 20.104.96.117:59186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9IJSBMYeh5YLVG45xjpQAAAiw"]
[Tue Jul 21 07:21:25.432720 2026] [security2:error] [pid 229246:tid 229477] [client 20.206.105.145:30535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/xmu.php"] [unique_id "al9IJSBMYeh5YLVG45xjpwAAAnk"]
[Tue Jul 21 07:21:25.777506 2026] [security2:error] [pid 229246:tid 229484] [client 20.220.225.223:59458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/inso.php"] [unique_id "al9IJSBMYeh5YLVG45xjqgAAAoA"]
[Tue Jul 21 07:21:25.901084 2026] [security2:error] [pid 229246:tid 229454] [client 14.139.42.196:26478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IJSBMYeh5YLVG45xjrwAAAmI"]
[Tue Jul 21 07:21:25.901212 2026] [security2:error] [pid 229246:tid 229454] [client 14.139.42.196:26478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IJSBMYeh5YLVG45xjrwAAAmI"]
[Tue Jul 21 07:21:25.938586 2026] [security2:error] [pid 229246:tid 229406] [client 45.251.232.145:65290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IJSBMYeh5YLVG45xjsAAAAjI"]
[Tue Jul 21 07:21:25.938713 2026] [security2:error] [pid 229246:tid 229406] [client 45.251.232.145:65290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IJSBMYeh5YLVG45xjsAAAAjI"]
[Tue Jul 21 07:21:25.971600 2026] [security2:error] [pid 229246:tid 229440] [client 20.104.96.117:61129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/qqqa.php"] [unique_id "al9IJSBMYeh5YLVG45xjsQAAAlQ"]
[Tue Jul 21 07:21:26.118038 2026] [security2:error] [pid 229246:tid 229438] [client 4.204.201.85:43960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/BDKR28.php"] [unique_id "al9IJiBMYeh5YLVG45xjswAAAlI"]
[Tue Jul 21 07:21:26.360361 2026] [security2:error] [pid 229246:tid 229480] [client 20.151.10.161:53600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/aaa.php"] [unique_id "al9IJiBMYeh5YLVG45xjtAAAAnw"]
[Tue Jul 21 07:21:26.362934 2026] [http2:warn] [pid 230252:tid 230482] [client 57.141.18.0:23330] h2_stream(230252-156-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:26.471460 2026] [security2:error] [pid 230252:tid 230402] [client 20.206.105.145:30592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9IJk0Dwhk5-Z44Xro-_gAAAqs"]
[Tue Jul 21 07:21:26.511000 2026] [security2:error] [pid 229246:tid 229289] [remote 192.241.143.148:38168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9IJiBMYeh5YLVG45xjuQACcyo"]
[Tue Jul 21 07:21:26.615369 2026] [security2:error] [pid 230252:tid 230412] [client 4.204.201.85:17853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/green1.php"] [unique_id "al9IJk0Dwhk5-Z44Xro_AAAAArU"]
[Tue Jul 21 07:21:26.622278 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:59149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/aunmc.php"] [unique_id "al9IJk0Dwhk5-Z44Xro_AQAAAw4"]
[Tue Jul 21 07:21:26.779754 2026] [security2:error] [pid 230252:tid 230426] [client 136.144.33.98:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IJk0Dwhk5-Z44Xro-_wAAAsM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:26.798865 2026] [security2:error] [pid 229246:tid 229461] [client 20.226.60.151:54569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9IJiBMYeh5YLVG45xjvAAAAmk"]
[Tue Jul 21 07:21:26.907449 2026] [security2:error] [pid 229246:tid 229313] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IJiBMYeh5YLVG45xjwAACi0I"]
[Tue Jul 21 07:21:26.907618 2026] [security2:error] [pid 229246:tid 229495] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IJiBMYeh5YLVG45xjwAACi0I"]
[Tue Jul 21 07:21:27.101172 2026] [security2:error] [pid 229246:tid 229315] [remote 20.75.217.64:3569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9IJyBMYeh5YLVG45xjxAACVkQ"]
[Tue Jul 21 07:21:27.184432 2026] [security2:error] [pid 230252:tid 230409] [client 20.220.225.223:59484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wpx.php"] [unique_id "al9IJ00Dwhk5-Z44Xro_CAAAArI"]
[Tue Jul 21 07:21:27.228919 2026] [security2:error] [pid 229246:tid 229457] [client 20.206.105.145:30633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/puc.php"] [unique_id "al9IJyBMYeh5YLVG45xjxQAAAmU"]
[Tue Jul 21 07:21:27.323482 2026] [security2:error] [pid 229246:tid 229492] [client 20.104.96.117:59157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/uoocf.php"] [unique_id "al9IJyBMYeh5YLVG45xjxgAAAog"]
[Tue Jul 21 07:21:27.374035 2026] [http2:warn] [pid 230252:tid 230443] [client 57.141.18.114:22366] h2_stream(230252-160-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:27.443948 2026] [security2:error] [pid 230252:tid 230454] [client 20.220.225.223:34265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/kq1.php"] [unique_id "al9IJ00Dwhk5-Z44Xro_DQAAAt8"]
[Tue Jul 21 07:21:27.453680 2026] [security2:error] [pid 229246:tid 229491] [client 20.197.192.193:27160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/else1.php"] [unique_id "al9IJyBMYeh5YLVG45xjyAAAAoc"]
[Tue Jul 21 07:21:27.476672 2026] [security2:error] [pid 230252:tid 230428] [client 4.204.201.85:17820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/nc4.php"] [unique_id "al9IJ00Dwhk5-Z44Xro_DgAAAsU"]
[Tue Jul 21 07:21:27.527421 2026] [security2:error] [pid 229246:tid 229408] [client 92.119.178.3:46294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IJyBMYeh5YLVG45xjyQAAAjQ"]
[Tue Jul 21 07:21:27.527554 2026] [security2:error] [pid 229246:tid 229408] [client 92.119.178.3:46294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IJyBMYeh5YLVG45xjyQAAAjQ"]
[Tue Jul 21 07:21:27.692584 2026] [security2:error] [pid 230252:tid 230440] [client 20.206.105.145:30698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/themes.php"] [unique_id "al9IJ00Dwhk5-Z44Xro_EAAAAtE"]
[Tue Jul 21 07:21:27.697808 2026] [security2:error] [pid 229246:tid 229475] [client 74.249.245.134:58640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/edit.php"] [unique_id "al9IJyBMYeh5YLVG45xjzAAAAnc"]
[Tue Jul 21 07:21:27.734199 2026] [http2:warn] [pid 229246:tid 229425] [client 57.141.18.19:39198] h2_stream(229246-326-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:27.891438 2026] [security2:error] [pid 230252:tid 230368] [remote 114.119.157.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.naturofarma.com.br"] [uri "/imagem.php"] [unique_id "al9IJ00Dwhk5-Z44Xro_EQACnnE"], referer: https://www.naturofarma.com.br/imagem.php?tipo=8&cod_img=179289
[Tue Jul 21 07:21:28.049737 2026] [security2:error] [pid 229246:tid 229398] [client 20.197.192.193:27167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/tkikikoko.php"] [unique_id "al9IKCBMYeh5YLVG45xj0AAAAio"]
[Tue Jul 21 07:21:28.076253 2026] [security2:error] [pid 229246:tid 229476] [client 20.104.96.117:61125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/iywwi.php"] [unique_id "al9IKCBMYeh5YLVG45xj0QAAAng"]
[Tue Jul 21 07:21:28.121165 2026] [security2:error] [pid 230252:tid 230398] [client 4.204.201.85:43949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/a1.php"] [unique_id "al9IKE0Dwhk5-Z44Xro_EwAAAqc"]
[Tue Jul 21 07:21:28.181080 2026] [security2:error] [pid 230252:tid 230291] [remote 156.59.198.136:35660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "issima.net.br"] [uri "/equestre/assina-vert/assina-vert.pdf"] [unique_id "al9IKE0Dwhk5-Z44Xro_FAAC3iU"]
[Tue Jul 21 07:21:28.536729 2026] [security2:error] [pid 230252:tid 230403] [client 4.204.201.85:17892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/eee.php"] [unique_id "al9IKE0Dwhk5-Z44Xro_FgAAAqw"]
[Tue Jul 21 07:21:28.683651 2026] [http2:warn] [pid 230252:tid 230393] [client 57.141.18.50:48664] h2_stream(230252-161-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:28.815446 2026] [security2:error] [pid 229246:tid 229464] [client 134.19.179.187:36292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IKCBMYeh5YLVG45xj3gAAAmw"]
[Tue Jul 21 07:21:28.815543 2026] [security2:error] [pid 229246:tid 229464] [client 134.19.179.187:36292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IKCBMYeh5YLVG45xj3gAAAmw"]
[Tue Jul 21 07:21:28.827199 2026] [security2:error] [pid 229246:tid 229478] [client 92.222.104.192:62314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "porondeeuestive.com.br"] [uri "/"] [unique_id "al9IKCBMYeh5YLVG45xj3wAAAno"]
[Tue Jul 21 07:21:28.827290 2026] [security2:error] [pid 229246:tid 229478] [client 92.222.104.192:62314] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "porondeeuestive.com.br"] [uri "/"] [unique_id "al9IKCBMYeh5YLVG45xj3wAAAno"]
[Tue Jul 21 07:21:28.881489 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:59175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/gqgsa.php"] [unique_id "al9IKE0Dwhk5-Z44Xro_GwAAAw4"]
[Tue Jul 21 07:21:28.986975 2026] [security2:error] [pid 229246:tid 229403] [client 20.220.225.223:52745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/berlin.php"] [unique_id "al9IKCBMYeh5YLVG45xj4gAAAi8"]
[Tue Jul 21 07:21:29.575036 2026] [security2:error] [pid 230252:tid 230409] [client 20.226.60.151:54500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/classwithtostring.php"] [unique_id "al9IKU0Dwhk5-Z44Xro_IgAAArI"]
[Tue Jul 21 07:21:29.609768 2026] [http2:warn] [pid 230252:tid 230415] [client 57.141.18.19:30238] h2_stream(230252-165-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:29.623254 2026] [security2:error] [pid 229246:tid 229304] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IKSBMYeh5YLVG45xj9QACUDk"]
[Tue Jul 21 07:21:29.623431 2026] [security2:error] [pid 229246:tid 229436] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IKSBMYeh5YLVG45xj9QACUDk"]
[Tue Jul 21 07:21:29.808041 2026] [security2:error] [pid 230252:tid 230500] [client 4.204.201.85:17793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/wp-aothait.php"] [unique_id "al9IKU0Dwhk5-Z44Xro_IwAAAw0"]
[Tue Jul 21 07:21:29.911226 2026] [security2:error] [pid 229246:tid 229409] [client 20.206.105.145:30717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/8.php"] [unique_id "al9IKSBMYeh5YLVG45xj-QAAAjU"]
[Tue Jul 21 07:21:29.911481 2026] [security2:error] [pid 229246:tid 229351] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IKSBMYeh5YLVG45xj-AACdGg"]
[Tue Jul 21 07:21:29.911603 2026] [security2:error] [pid 229246:tid 229472] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IKSBMYeh5YLVG45xj-AACdGg"]
[Tue Jul 21 07:21:29.990330 2026] [security2:error] [pid 230252:tid 230442] [client 103.174.34.15:63636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IKU0Dwhk5-Z44Xro_JQAAAtM"]
[Tue Jul 21 07:21:29.990489 2026] [security2:error] [pid 230252:tid 230442] [client 103.174.34.15:63636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IKU0Dwhk5-Z44Xro_JQAAAtM"]
[Tue Jul 21 07:21:30.004643 2026] [security2:error] [pid 229246:tid 229383] [client 20.197.192.193:26892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9IKiBMYeh5YLVG45xj-gAAAhs"]
[Tue Jul 21 07:21:30.044915 2026] [security2:error] [pid 230252:tid 230420] [client 20.206.105.145:30614] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/1.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_JwAAAr0"]
[Tue Jul 21 07:21:30.045036 2026] [security2:error] [pid 230252:tid 230420] [client 20.206.105.145:30614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/1.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_JwAAAr0"]
[Tue Jul 21 07:21:30.158288 2026] [security2:error] [pid 230252:tid 230476] [client 184.75.221.3:58332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_MgAAAvU"]
[Tue Jul 21 07:21:30.158383 2026] [security2:error] [pid 230252:tid 230476] [client 184.75.221.3:58332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_MgAAAvU"]
[Tue Jul 21 07:21:30.163913 2026] [security2:error] [pid 230252:tid 230268] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_MwAC0Q4"]
[Tue Jul 21 07:21:30.164055 2026] [security2:error] [pid 230252:tid 230440] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_MwAC0Q4"]
[Tue Jul 21 07:21:30.253557 2026] [security2:error] [pid 229246:tid 229477] [client 20.206.105.145:30615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/100.php"] [unique_id "al9IKiBMYeh5YLVG45xj_gAAAnk"]
[Tue Jul 21 07:21:30.261737 2026] [security2:error] [pid 230252:tid 230403] [client 4.204.201.85:17815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/config.json.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_NQAAAqw"]
[Tue Jul 21 07:21:30.282298 2026] [security2:error] [pid 230252:tid 230458] [client 20.104.96.117:59669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/elbzl.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_NgAAAuM"]
[Tue Jul 21 07:21:30.408306 2026] [security2:error] [pid 230252:tid 230263] [remote 97.74.87.194:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wp-login.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_NwAC_wk"]
[Tue Jul 21 07:21:30.721483 2026] [security2:error] [pid 230252:tid 230451] [client 4.204.201.85:17867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_PQAAAtw"]
[Tue Jul 21 07:21:30.727357 2026] [security2:error] [pid 230252:tid 230411] [client 20.220.225.223:60092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/billur.php"] [unique_id "al9IKk0Dwhk5-Z44Xro_PgAAArQ"]
[Tue Jul 21 07:21:30.980432 2026] [security2:error] [pid 229246:tid 229431] [client 20.104.96.117:59668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/adjig.php"] [unique_id "al9IKiBMYeh5YLVG45xkAwAAAks"]
[Tue Jul 21 07:21:31.015914 2026] [http2:warn] [pid 229246:tid 229486] [client 57.141.18.26:27796] h2_stream(229246-338-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:31.073850 2026] [security2:error] [pid 229246:tid 229406] [client 20.206.105.145:30613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/about.php"] [unique_id "al9IKyBMYeh5YLVG45xkBwAAAjI"]
[Tue Jul 21 07:21:31.176395 2026] [security2:error] [pid 230252:tid 230511] [client 175.45.70.82:53327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IK00Dwhk5-Z44Xro_QAAAAxg"]
[Tue Jul 21 07:21:31.176522 2026] [security2:error] [pid 230252:tid 230511] [client 175.45.70.82:53327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IK00Dwhk5-Z44Xro_QAAAAxg"]
[Tue Jul 21 07:21:31.338077 2026] [security2:error] [pid 229246:tid 229447] [client 139.135.44.145:53137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IKyBMYeh5YLVG45xkDQAAAls"]
[Tue Jul 21 07:21:31.338282 2026] [security2:error] [pid 229246:tid 229447] [client 139.135.44.145:53137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IKyBMYeh5YLVG45xkDQAAAls"]
[Tue Jul 21 07:21:31.422906 2026] [http2:warn] [pid 230252:tid 230460] [client 57.141.18.110:55522] h2_stream(230252-167-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:31.463869 2026] [security2:error] [pid 229246:tid 229421] [client 136.144.33.97:21539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IKyBMYeh5YLVG45xkCwAAAkE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:31.516565 2026] [security2:error] [pid 230252:tid 230399] [client 20.197.192.193:26901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/wp-css.php"] [unique_id "al9IK00Dwhk5-Z44Xro_QQAAAqg"]
[Tue Jul 21 07:21:31.576873 2026] [security2:error] [pid 229246:tid 229471] [client 4.204.201.85:43931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/k2.php"] [unique_id "al9IKyBMYeh5YLVG45xkEgAAAnM"]
[Tue Jul 21 07:21:31.883165 2026] [security2:error] [pid 230252:tid 230436] [client 74.249.245.134:58669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/166.php"] [unique_id "al9IK00Dwhk5-Z44Xro_RgAAAs0"]
[Tue Jul 21 07:21:31.960658 2026] [security2:error] [pid 230252:tid 230414] [client 20.151.10.161:45898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9IK00Dwhk5-Z44Xro_RwAAArc"]
[Tue Jul 21 07:21:32.015893 2026] [security2:error] [pid 229246:tid 229495] [client 20.104.96.117:59648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/byp.php"] [unique_id "al9ILCBMYeh5YLVG45xkGAAAAos"]
[Tue Jul 21 07:21:32.100584 2026] [security2:error] [pid 230252:tid 230392] [client 74.7.241.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "sobradoimoveis.com"] [uri "/robots.txt"] [unique_id "al9ILE0Dwhk5-Z44Xro_SQAAAqE"]
[Tue Jul 21 07:21:32.188410 2026] [security2:error] [pid 230252:tid 230306] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ILE0Dwhk5-Z44Xro_SgADFzQ"]
[Tue Jul 21 07:21:32.188535 2026] [security2:error] [pid 230252:tid 230510] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ILE0Dwhk5-Z44Xro_SgADFzQ"]
[Tue Jul 21 07:21:32.239402 2026] [security2:error] [pid 229246:tid 229492] [client 20.220.225.223:34192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/zzz.php"] [unique_id "al9ILCBMYeh5YLVG45xkGwAAAog"]
[Tue Jul 21 07:21:32.241063 2026] [security2:error] [pid 229246:tid 229470] [client 4.204.201.85:17810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9ILCBMYeh5YLVG45xkHAAAAnI"]
[Tue Jul 21 07:21:32.271400 2026] [http2:warn] [pid 229246:tid 229433] [client 57.141.18.57:48542] h2_stream(229246-341-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:32.370304 2026] [security2:error] [pid 230252:tid 230264] [remote 202.51.202.242:34532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9ILE0Dwhk5-Z44Xro_SwACxQo"]
[Tue Jul 21 07:21:32.370493 2026] [security2:error] [pid 230252:tid 230428] [client 202.51.202.242:34532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9ILE0Dwhk5-Z44Xro_SwACxQo"]
[Tue Jul 21 07:21:32.383844 2026] [security2:error] [pid 229246:tid 229436] [client 20.206.105.145:30532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/about.php"] [unique_id "al9ILCBMYeh5YLVG45xkIAAAAlA"]
[Tue Jul 21 07:21:32.736980 2026] [security2:error] [pid 230252:tid 230463] [client 20.104.96.117:59672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9ILE0Dwhk5-Z44Xro_UQAAAug"]
[Tue Jul 21 07:21:33.028452 2026] [security2:error] [pid 230252:tid 230451] [client 4.204.201.85:17919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9ILU0Dwhk5-Z44Xro_WwAAAtw"]
[Tue Jul 21 07:21:33.033803 2026] [security2:error] [pid 230252:tid 230385] [client 54.39.136.109:59344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "formaesplendida.com"] [uri "/robots.txt"] [unique_id "al9ILU0Dwhk5-Z44Xro_XQAAApo"]
[Tue Jul 21 07:21:33.033949 2026] [security2:error] [pid 230252:tid 230385] [client 54.39.136.109:59344] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "formaesplendida.com"] [uri "/robots.txt"] [unique_id "al9ILU0Dwhk5-Z44Xro_XQAAApo"]
[Tue Jul 21 07:21:33.052553 2026] [proxy:error] [pid 230252:tid 230511] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.052610 2026] [proxy_http:error] [pid 230252:tid 230511] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.053040 2026] [proxy:error] [pid 230252:tid 230511] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.053064 2026] [proxy_http:error] [pid 230252:tid 230511] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.086374 2026] [proxy:error] [pid 230252:tid 230389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.086452 2026] [proxy_http:error] [pid 230252:tid 230389] [client 2a03:b0c0:3:d0::1413:d001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.087688 2026] [proxy:error] [pid 230252:tid 230389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.087727 2026] [proxy_http:error] [pid 230252:tid 230389] [client 2a03:b0c0:3:d0::1413:d001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.152525 2026] [proxy:error] [pid 230252:tid 230443] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.152577 2026] [proxy_http:error] [pid 230252:tid 230443] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.153020 2026] [proxy:error] [pid 230252:tid 230443] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.153047 2026] [proxy_http:error] [pid 230252:tid 230443] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.198526 2026] [proxy:error] [pid 230252:tid 230485] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.198582 2026] [proxy_http:error] [pid 230252:tid 230485] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.199185 2026] [proxy:error] [pid 230252:tid 230485] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.199218 2026] [proxy_http:error] [pid 230252:tid 230485] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.202786 2026] [proxy:error] [pid 230252:tid 230499] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.202840 2026] [proxy_http:error] [pid 230252:tid 230499] [client 2a03:b0c0:1:d0::e05:9001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.203275 2026] [proxy:error] [pid 230252:tid 230499] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.203296 2026] [proxy_http:error] [pid 230252:tid 230499] [client 2a03:b0c0:1:d0::e05:9001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.226970 2026] [proxy:error] [pid 229246:tid 229452] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.227014 2026] [proxy_http:error] [pid 229246:tid 229452] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.227473 2026] [proxy:error] [pid 229246:tid 229452] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.227497 2026] [proxy_http:error] [pid 229246:tid 229452] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.262016 2026] [security2:error] [pid 229246:tid 229488] [client 184.75.221.3:58336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9ILSBMYeh5YLVG45xkMwAAAoQ"]
[Tue Jul 21 07:21:33.262110 2026] [security2:error] [pid 229246:tid 229488] [client 184.75.221.3:58336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9ILSBMYeh5YLVG45xkMwAAAoQ"]
[Tue Jul 21 07:21:33.337146 2026] [http2:warn] [pid 230252:tid 230475] [client 57.141.18.25:21576] h2_stream(230252-171-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:33.353488 2026] [security2:error] [pid 229246:tid 229484] [client 20.206.105.145:30719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/admin.php"] [unique_id "al9ILSBMYeh5YLVG45xkOAAAAoA"]
[Tue Jul 21 07:21:33.353990 2026] [proxy:error] [pid 230252:tid 230403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.354062 2026] [proxy_http:error] [pid 230252:tid 230403] [client 2a03:b0c0:3:d0::12f7:9001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.354757 2026] [proxy:error] [pid 230252:tid 230403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.354786 2026] [proxy_http:error] [pid 230252:tid 230403] [client 2a03:b0c0:3:d0::12f7:9001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.455327 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.455391 2026] [proxy_http:error] [pid 230252:tid 230447] [client 2400:6180:0:d0::1182:2001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.455937 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:33.455962 2026] [proxy_http:error] [pid 230252:tid 230447] [client 2400:6180:0:d0::1182:2001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:33.788705 2026] [security2:error] [pid 230252:tid 230500] [client 4.204.201.85:43902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9ILU0Dwhk5-Z44Xro_iwAAAw0"]
[Tue Jul 21 07:21:33.822585 2026] [security2:error] [pid 230252:tid 230436] [client 20.197.192.193:27177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/wp-explorer.php"] [unique_id "al9ILU0Dwhk5-Z44Xro_jQAAAs0"]
[Tue Jul 21 07:21:33.854512 2026] [security2:error] [pid 230252:tid 230485] [client 114.119.134.165:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sobradoimoveis.com"] [uri "/imovel/terreno-venda-joao-costa-joinville-sc-2519"] [unique_id "al9ILU0Dwhk5-Z44Xro_jgAAAv4"], referer: https://sobradoimoveis.com/
[Tue Jul 21 07:21:33.946071 2026] [security2:error] [pid 230252:tid 230430] [client 20.151.10.161:45835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/aaa.php"] [unique_id "al9ILU0Dwhk5-Z44Xro_jwAAAsc"]
[Tue Jul 21 07:21:34.082223 2026] [proxy:error] [pid 229246:tid 229414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.082292 2026] [proxy_http:error] [pid 229246:tid 229414] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.082800 2026] [proxy:error] [pid 229246:tid 229414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.082842 2026] [proxy_http:error] [pid 229246:tid 229414] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.095728 2026] [http2:warn] [pid 229246:tid 229483] [client 57.141.18.104:63944] h2_stream(229246-351-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:34.195501 2026] [proxy:error] [pid 230252:tid 230506] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.195560 2026] [proxy_http:error] [pid 230252:tid 230506] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.196027 2026] [proxy:error] [pid 230252:tid 230506] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.196052 2026] [proxy_http:error] [pid 230252:tid 230506] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.225810 2026] [proxy:error] [pid 230252:tid 230403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.225873 2026] [proxy_http:error] [pid 230252:tid 230403] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.226513 2026] [proxy:error] [pid 230252:tid 230403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.226538 2026] [proxy_http:error] [pid 230252:tid 230403] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.233809 2026] [proxy:error] [pid 230252:tid 230416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.233865 2026] [proxy_http:error] [pid 230252:tid 230416] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.234291 2026] [proxy:error] [pid 230252:tid 230416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:34.234313 2026] [proxy_http:error] [pid 230252:tid 230416] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:34.258031 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:61165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/classwithtostring.php"] [unique_id "al9ILk0Dwhk5-Z44Xro_nQAAAtM"]
[Tue Jul 21 07:21:34.335140 2026] [security2:error] [pid 230252:tid 230414] [client 4.204.201.85:17910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/for.php"] [unique_id "al9ILk0Dwhk5-Z44Xro_oQAAArc"]
[Tue Jul 21 07:21:34.350943 2026] [security2:error] [pid 230252:tid 230456] [client 103.162.129.114:63232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9ILk0Dwhk5-Z44Xro_ogAAAuE"]
[Tue Jul 21 07:21:34.351048 2026] [security2:error] [pid 230252:tid 230456] [client 103.162.129.114:63232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9ILk0Dwhk5-Z44Xro_ogAAAuE"]
[Tue Jul 21 07:21:34.445319 2026] [security2:error] [pid 230252:tid 230479] [client 15.235.27.226:15964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "formaesplendida.com"] [uri "/"] [unique_id "al9ILk0Dwhk5-Z44Xro_owAAAvg"]
[Tue Jul 21 07:21:34.445439 2026] [security2:error] [pid 230252:tid 230479] [client 15.235.27.226:15964] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "formaesplendida.com"] [uri "/"] [unique_id "al9ILk0Dwhk5-Z44Xro_owAAAvg"]
[Tue Jul 21 07:21:34.499854 2026] [security2:error] [pid 230252:tid 230484] [client 103.121.156.110:63555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9ILk0Dwhk5-Z44Xro_pwAAAv0"]
[Tue Jul 21 07:21:34.500036 2026] [security2:error] [pid 230252:tid 230484] [client 103.121.156.110:63555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9ILk0Dwhk5-Z44Xro_pwAAAv0"]
[Tue Jul 21 07:21:34.885008 2026] [http2:warn] [pid 229246:tid 229402] [client 57.141.18.100:55070] h2_stream(229246-354-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:35.062662 2026] [proxy:error] [pid 230252:tid 230415] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.062736 2026] [proxy_http:error] [pid 230252:tid 230415] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.063560 2026] [proxy:error] [pid 230252:tid 230415] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.063595 2026] [proxy_http:error] [pid 230252:tid 230415] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.181485 2026] [proxy:error] [pid 229246:tid 229488] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.181542 2026] [proxy_http:error] [pid 229246:tid 229488] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.182146 2026] [proxy:error] [pid 229246:tid 229488] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.182182 2026] [proxy_http:error] [pid 229246:tid 229488] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.203014 2026] [security2:error] [pid 229246:tid 229381] [client 20.206.105.145:30682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/admin.php"] [unique_id "al9ILyBMYeh5YLVG45xkYwAAAhk"]
[Tue Jul 21 07:21:35.204228 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.204276 2026] [proxy_http:error] [pid 230252:tid 230421] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.204837 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.204861 2026] [proxy_http:error] [pid 230252:tid 230421] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.208139 2026] [security2:error] [pid 230252:tid 230340] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IL00Dwhk5-Z44Xro_0gAC_VU"]
[Tue Jul 21 07:21:35.208244 2026] [security2:error] [pid 230252:tid 230484] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IL00Dwhk5-Z44Xro_0gAC_VU"]
[Tue Jul 21 07:21:35.222932 2026] [proxy:error] [pid 230252:tid 230441] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.222979 2026] [proxy_http:error] [pid 230252:tid 230441] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.223464 2026] [proxy:error] [pid 230252:tid 230441] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:35.223486 2026] [proxy_http:error] [pid 230252:tid 230441] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:35.285974 2026] [security2:error] [pid 229246:tid 229478] [client 4.204.201.85:17798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "beezar.com.br"] [uri "/raw.php"] [unique_id "al9ILyBMYeh5YLVG45xkZwAAAno"]
[Tue Jul 21 07:21:35.455998 2026] [security2:error] [pid 230252:tid 230255] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IL00Dwhk5-Z44Xro_4AADFwE"]
[Tue Jul 21 07:21:35.456142 2026] [security2:error] [pid 230252:tid 230510] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IL00Dwhk5-Z44Xro_4AADFwE"]
[Tue Jul 21 07:21:35.710768 2026] [security2:error] [pid 230252:tid 230442] [client 20.220.225.223:34237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wicked.php"] [unique_id "al9IL00Dwhk5-Z44Xro_5wAAAtM"]
[Tue Jul 21 07:21:35.912302 2026] [http2:warn] [pid 230252:tid 230483] [client 57.141.18.110:36590] h2_stream(230252-178-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:35.947350 2026] [security2:error] [pid 230252:tid 230485] [client 206.189.19.19:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webdisk.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/server-status"] [unique_id "al9IL00Dwhk5-Z44Xro_8QAAAv4"]
[Tue Jul 21 07:21:36.066958 2026] [security2:error] [pid 230252:tid 230472] [client 136.144.33.111:32969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IME0Dwhk5-Z44Xro_9wAAAvE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:36.068959 2026] [security2:error] [pid 229246:tid 229384] [client 64.23.218.208:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webmail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/server-status"] [unique_id "al9IMCBMYeh5YLVG45xkgAAAAhw"]
[Tue Jul 21 07:21:36.088865 2026] [security2:error] [pid 229246:tid 229494] [client 157.230.19.140:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webdisk.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/server-status"] [unique_id "al9IMCBMYeh5YLVG45xkgQAAAoo"]
[Tue Jul 21 07:21:36.094384 2026] [security2:error] [pid 229246:tid 229416] [client 143.110.217.244:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpanel.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/server-status"] [unique_id "al9IMCBMYeh5YLVG45xkgwAAAjw"]
[Tue Jul 21 07:21:36.101881 2026] [security2:error] [pid 230252:tid 230443] [client 134.209.25.199:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcontacts.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/server-status"] [unique_id "al9IME0Dwhk5-Z44Xro_-QAAAtQ"]
[Tue Jul 21 07:21:36.164630 2026] [security2:error] [pid 230252:tid 230399] [client 139.59.136.184:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpanel.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/server-status"] [unique_id "al9IME0Dwhk5-Z44Xro_-gAAAqg"]
[Tue Jul 21 07:21:36.171693 2026] [security2:error] [pid 230252:tid 230411] [client 64.226.65.160:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcalendars.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/server-status"] [unique_id "al9IME0Dwhk5-Z44Xro__AAAArQ"]
[Tue Jul 21 07:21:36.171975 2026] [access_compat:error] [pid 229246:tid 229337] [remote 167.172.232.142:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:36.212208 2026] [access_compat:error] [pid 230252:tid 230463] [client 147.182.200.94:0] AH01797: client denied by server configuration: proxy:http://127.0.0.1/cgi-sys/autodiscover.cgi
[Tue Jul 21 07:21:36.233193 2026] [security2:error] [pid 229246:tid 229451] [client 46.101.1.225:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcalendars.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/server-status"] [unique_id "al9IMCBMYeh5YLVG45xkhwAAAl8"]
[Tue Jul 21 07:21:36.279770 2026] [security2:error] [pid 229246:tid 229476] [client 64.23.218.208:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webmail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/server-status"] [unique_id "al9IMCBMYeh5YLVG45xkiAAAAng"]
[Tue Jul 21 07:21:36.288714 2026] [http2:warn] [pid 229246:tid 229423] [client 57.141.18.39:62468] h2_stream(229246-361-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:36.319709 2026] [security2:error] [pid 230252:tid 230506] [client 139.59.132.8:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcontacts.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/server-status"] [unique_id "al9IME0Dwhk5-Z44XrpAAQAAAxM"]
[Tue Jul 21 07:21:36.366435 2026] [access_compat:error] [pid 229246:tid 229400] [client 143.110.213.72:0] AH01797: client denied by server configuration: proxy:http://127.0.0.1/cgi-sys/autodiscover.cgi
[Tue Jul 21 07:21:36.366983 2026] [security2:error] [pid 230252:tid 230404] [client 107.172.140.193:36904] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "gpcom.com.br"] [uri "/"] [unique_id "al9IME0Dwhk5-Z44XrpABAAAAq0"]
[Tue Jul 21 07:21:36.426414 2026] [security2:error] [pid 229246:tid 229414] [client 45.251.232.145:49423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IMCBMYeh5YLVG45xkjAAAAjo"]
[Tue Jul 21 07:21:36.426522 2026] [security2:error] [pid 229246:tid 229414] [client 45.251.232.145:49423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IMCBMYeh5YLVG45xkjAAAAjo"]
[Tue Jul 21 07:21:36.482303 2026] [security2:error] [pid 230252:tid 230410] [client 20.104.96.117:61140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/root.php"] [unique_id "al9IME0Dwhk5-Z44XrpACgAAArM"]
[Tue Jul 21 07:21:36.513088 2026] [access_compat:error] [pid 230252:tid 230458] [client 165.22.235.3:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:36.590357 2026] [access_compat:error] [pid 230252:tid 230403] [client 167.71.175.236:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:36.593364 2026] [access_compat:error] [pid 230252:tid 230509] [client 207.154.197.113:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:36.661119 2026] [security2:error] [pid 230252:tid 230500] [client 14.139.42.196:15932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IME0Dwhk5-Z44XrpAEQAAAw0"]
[Tue Jul 21 07:21:36.661241 2026] [security2:error] [pid 230252:tid 230500] [client 14.139.42.196:15932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IME0Dwhk5-Z44XrpAEQAAAw0"]
[Tue Jul 21 07:21:36.681411 2026] [access_compat:error] [pid 230252:tid 230395] [client 206.189.233.36:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:36.692181 2026] [security2:error] [pid 230252:tid 230442] [client 20.197.192.193:27157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/akismet.php"] [unique_id "al9IME0Dwhk5-Z44XrpAEgAAAtM"]
[Tue Jul 21 07:21:36.698906 2026] [access_compat:error] [pid 230252:tid 230465] [client 146.190.63.248:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:36.849866 2026] [security2:error] [pid 230252:tid 230455] [client 20.206.105.145:30538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/edit.php"] [unique_id "al9IME0Dwhk5-Z44XrpAFQAAAuA"]
[Tue Jul 21 07:21:36.855714 2026] [access_compat:error] [pid 230252:tid 230511] [client 165.227.84.14:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:36.895377 2026] [access_compat:error] [pid 229246:tid 229460] [client 167.71.175.236:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:37.029067 2026] [access_compat:error] [pid 229246:tid 229312] [remote 138.197.191.87:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:37.032291 2026] [security2:error] [pid 230252:tid 230439] [client 114.119.150.95:34871] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acaiofficial.com.br"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/"] [unique_id "al9IMU0Dwhk5-Z44XrpAGAAAAtA"], referer: https://acaiofficial.com.br/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/
[Tue Jul 21 07:21:37.045784 2026] [http2:warn] [pid 230252:tid 230432] [client 57.141.18.109:63044] h2_stream(230252-182-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:37.093129 2026] [access_compat:error] [pid 230252:tid 230415] [client 138.68.144.227:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:37.098586 2026] [access_compat:error] [pid 229246:tid 229473] [client 68.183.180.73:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:37.169591 2026] [security2:error] [pid 230252:tid 230304] [remote 114.34.90.9:41450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9IMU0Dwhk5-Z44XrpAHgAC4jI"]
[Tue Jul 21 07:21:37.527997 2026] [security2:error] [pid 230252:tid 230416] [client 20.206.105.145:30706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-content/admin.php"] [unique_id "al9IMU0Dwhk5-Z44XrpAIwAAArk"]
[Tue Jul 21 07:21:37.576608 2026] [security2:error] [pid 230252:tid 230379] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IMU0Dwhk5-Z44XrpAJwACvXw"]
[Tue Jul 21 07:21:37.576791 2026] [security2:error] [pid 230252:tid 230420] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IMU0Dwhk5-Z44XrpAJwACvXw"]
[Tue Jul 21 07:21:37.825882 2026] [security2:error] [pid 230252:tid 230440] [client 20.104.96.117:59189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/sym403.php"] [unique_id "al9IMU0Dwhk5-Z44XrpAKwAAAtE"]
[Tue Jul 21 07:21:37.835663 2026] [security2:error] [pid 230252:tid 230451] [client 68.235.38.2:52860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IMU0Dwhk5-Z44XrpALAAAAtw"]
[Tue Jul 21 07:21:37.835743 2026] [security2:error] [pid 230252:tid 230451] [client 68.235.38.2:52860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IMU0Dwhk5-Z44XrpALAAAAtw"]
[Tue Jul 21 07:21:37.959976 2026] [http2:warn] [pid 229246:tid 229390] [client 57.141.18.17:59336] h2_stream(229246-365-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:38.056800 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.056879 2026] [proxy_http:error] [pid 230252:tid 230456] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.057585 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.057610 2026] [proxy_http:error] [pid 230252:tid 230456] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.071686 2026] [access_compat:error] [pid 230252:tid 230403] [client 142.93.143.8:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:21:38.185624 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.185693 2026] [proxy_http:error] [pid 230252:tid 230421] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.186335 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.186371 2026] [proxy_http:error] [pid 230252:tid 230421] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.230518 2026] [proxy:error] [pid 230252:tid 230457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.230570 2026] [proxy_http:error] [pid 230252:tid 230457] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.231033 2026] [proxy:error] [pid 230252:tid 230457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.231059 2026] [proxy_http:error] [pid 230252:tid 230457] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.232300 2026] [security2:error] [pid 230252:tid 230409] [client 20.206.105.145:30536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/f6.php"] [unique_id "al9IMk0Dwhk5-Z44XrpAOgAAArI"]
[Tue Jul 21 07:21:38.276433 2026] [proxy:error] [pid 230252:tid 230454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.276509 2026] [proxy_http:error] [pid 230252:tid 230454] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.277256 2026] [proxy:error] [pid 230252:tid 230454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:38.277301 2026] [proxy_http:error] [pid 230252:tid 230454] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:38.323538 2026] [security2:error] [pid 230252:tid 230476] [client 20.226.60.151:54560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/root.php"] [unique_id "al9IMk0Dwhk5-Z44XrpAQAAAAvU"]
[Tue Jul 21 07:21:38.455097 2026] [security2:error] [pid 229246:tid 229382] [client 74.249.245.134:61557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/8.php"] [unique_id "al9IMiBMYeh5YLVG45xkqQAAAho"]
[Tue Jul 21 07:21:38.613560 2026] [security2:error] [pid 229246:tid 229486] [client 20.104.96.117:59666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/v543.php"] [unique_id "al9IMiBMYeh5YLVG45xkrgAAAoI"]
[Tue Jul 21 07:21:38.750872 2026] [security2:error] [pid 229246:tid 229380] [client 20.206.105.145:30696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/inputs.php"] [unique_id "al9IMiBMYeh5YLVG45xksgAAAhg"]
[Tue Jul 21 07:21:38.752641 2026] [security2:error] [pid 229246:tid 229461] [client 20.220.225.223:52792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/mimpi.php"] [unique_id "al9IMiBMYeh5YLVG45xkswAAAmk"]
[Tue Jul 21 07:21:38.978930 2026] [security2:error] [pid 230252:tid 230510] [client 139.59.99.58:59321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.vivaconcierge.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9IMk0Dwhk5-Z44XrpATQAAAxc"]
[Tue Jul 21 07:21:39.043530 2026] [proxy:error] [pid 230252:tid 230402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.043615 2026] [proxy_http:error] [pid 230252:tid 230402] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.044671 2026] [proxy:error] [pid 230252:tid 230402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.044729 2026] [proxy_http:error] [pid 230252:tid 230402] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.057413 2026] [proxy:error] [pid 229246:tid 229389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.057469 2026] [proxy_http:error] [pid 229246:tid 229389] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.057938 2026] [proxy:error] [pid 229246:tid 229389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.057965 2026] [proxy_http:error] [pid 229246:tid 229389] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.071321 2026] [security2:error] [pid 230252:tid 230415] [client 20.206.105.145:30638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/inputs.php"] [unique_id "al9IM00Dwhk5-Z44XrpAUAAAArg"]
[Tue Jul 21 07:21:39.202199 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.202267 2026] [proxy_http:error] [pid 230252:tid 230447] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.202855 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.202884 2026] [proxy_http:error] [pid 230252:tid 230447] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.271024 2026] [proxy:error] [pid 230252:tid 230436] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.271110 2026] [proxy_http:error] [pid 230252:tid 230436] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.271795 2026] [proxy:error] [pid 230252:tid 230436] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:39.271909 2026] [proxy_http:error] [pid 230252:tid 230436] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:39.381634 2026] [security2:error] [pid 230252:tid 230500] [client 20.220.225.223:34199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/edit.php"] [unique_id "al9IM00Dwhk5-Z44XrpAWwAAAw0"]
[Tue Jul 21 07:21:39.396603 2026] [security2:error] [pid 230252:tid 230492] [client 20.206.105.145:30678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/av.php"] [unique_id "al9IM00Dwhk5-Z44XrpAXAAAAwU"]
[Tue Jul 21 07:21:39.534660 2026] [security2:error] [pid 229246:tid 229499] [client 103.174.34.15:64265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IMyBMYeh5YLVG45xkwwAAAo8"]
[Tue Jul 21 07:21:39.534767 2026] [security2:error] [pid 229246:tid 229499] [client 103.174.34.15:64265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IMyBMYeh5YLVG45xkwwAAAo8"]
[Tue Jul 21 07:21:39.715948 2026] [http2:warn] [pid 230252:tid 230394] [client 57.141.18.11:41980] h2_stream(230252-197-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:39.912119 2026] [security2:error] [pid 230252:tid 230462] [client 20.206.105.145:30629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/classwithtostring.php"] [unique_id "al9IM00Dwhk5-Z44XrpAZQAAAuc"]
[Tue Jul 21 07:21:39.925152 2026] [http2:warn] [pid 230252:tid 230446] [client 57.141.18.113:40528] h2_stream(230252-199-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:40.077846 2026] [proxy:error] [pid 229246:tid 229403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.077919 2026] [proxy_http:error] [pid 229246:tid 229403] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.078631 2026] [proxy:error] [pid 229246:tid 229403] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.078672 2026] [proxy_http:error] [pid 229246:tid 229403] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.177182 2026] [security2:error] [pid 230252:tid 230365] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9INE0Dwhk5-Z44XrpAbwACzW4"]
[Tue Jul 21 07:21:40.177356 2026] [security2:error] [pid 230252:tid 230436] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9INE0Dwhk5-Z44XrpAbwACzW4"]
[Tue Jul 21 07:21:40.180085 2026] [proxy:error] [pid 230252:tid 230445] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.180149 2026] [proxy_http:error] [pid 230252:tid 230445] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.180613 2026] [proxy:error] [pid 230252:tid 230445] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.180634 2026] [proxy_http:error] [pid 230252:tid 230445] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.195743 2026] [proxy:error] [pid 230252:tid 230386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.195809 2026] [proxy_http:error] [pid 230252:tid 230386] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.196511 2026] [proxy:error] [pid 230252:tid 230386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.196546 2026] [proxy_http:error] [pid 230252:tid 230386] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.277053 2026] [security2:error] [pid 229246:tid 229442] [client 20.206.105.145:30660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9INCBMYeh5YLVG45xk4AAAAlY"]
[Tue Jul 21 07:21:40.282849 2026] [proxy:error] [pid 230252:tid 230412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.282901 2026] [proxy_http:error] [pid 230252:tid 230412] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.283499 2026] [proxy:error] [pid 230252:tid 230412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.283522 2026] [proxy_http:error] [pid 230252:tid 230412] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.356766 2026] [security2:error] [pid 230252:tid 230408] [client 20.220.225.223:34255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/kua.php"] [unique_id "al9INE0Dwhk5-Z44XrpAdgAAArE"]
[Tue Jul 21 07:21:40.426245 2026] [security2:error] [pid 229246:tid 229459] [client 172.245.102.46:23747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9INCBMYeh5YLVG45xk6QAAAmc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:40.463355 2026] [proxy:error] [pid 229246:tid 229394] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.463427 2026] [proxy_http:error] [pid 229246:tid 229394] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.464396 2026] [proxy:error] [pid 229246:tid 229394] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.464448 2026] [proxy_http:error] [pid 229246:tid 229394] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.548741 2026] [proxy:error] [pid 230252:tid 230410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.548800 2026] [proxy_http:error] [pid 230252:tid 230410] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.549492 2026] [proxy:error] [pid 230252:tid 230410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.549521 2026] [proxy_http:error] [pid 230252:tid 230410] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.652373 2026] [security2:error] [pid 230252:tid 230362] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9INE0Dwhk5-Z44XrpAgwAC92s"]
[Tue Jul 21 07:21:40.652608 2026] [security2:error] [pid 230252:tid 230478] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9INE0Dwhk5-Z44XrpAgwAC92s"]
[Tue Jul 21 07:21:40.750738 2026] [security2:error] [pid 230252:tid 230348] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9INE0Dwhk5-Z44XrpAiQAC-10"]
[Tue Jul 21 07:21:40.750923 2026] [security2:error] [pid 230252:tid 230482] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9INE0Dwhk5-Z44XrpAiQAC-10"]
[Tue Jul 21 07:21:40.777288 2026] [security2:error] [pid 229246:tid 229499] [client 68.235.38.2:45166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9INCBMYeh5YLVG45xk9AAAAo8"]
[Tue Jul 21 07:21:40.777401 2026] [security2:error] [pid 229246:tid 229499] [client 68.235.38.2:45166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9INCBMYeh5YLVG45xk9AAAAo8"]
[Tue Jul 21 07:21:40.795150 2026] [proxy:error] [pid 229246:tid 229473] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.795218 2026] [proxy_http:error] [pid 229246:tid 229473] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.795711 2026] [proxy:error] [pid 229246:tid 229473] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.795746 2026] [proxy_http:error] [pid 229246:tid 229473] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.811761 2026] [security2:error] [pid 230252:tid 230403] [client 139.59.99.58:59963] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.vivaconcierge.com.br"] [uri "/"] [unique_id "al9INE0Dwhk5-Z44XrpAjQAAAqw"]
[Tue Jul 21 07:21:40.851079 2026] [proxy:error] [pid 229246:tid 229424] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.851180 2026] [proxy_http:error] [pid 229246:tid 229424] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.852474 2026] [proxy:error] [pid 229246:tid 229424] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.852536 2026] [proxy_http:error] [pid 229246:tid 229424] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.905756 2026] [proxy:error] [pid 229246:tid 229383] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.905811 2026] [proxy_http:error] [pid 229246:tid 229383] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.906360 2026] [proxy:error] [pid 229246:tid 229383] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:40.906384 2026] [proxy_http:error] [pid 229246:tid 229383] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:40.919006 2026] [security2:error] [pid 230252:tid 230386] [client 20.206.105.145:30700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-blog.php"] [unique_id "al9INE0Dwhk5-Z44XrpAkQAAAps"]
[Tue Jul 21 07:21:41.031234 2026] [security2:error] [pid 230252:tid 230474] [client 20.104.96.117:59711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/sixxis.php"] [unique_id "al9INU0Dwhk5-Z44XrpAlgAAAvM"]
[Tue Jul 21 07:21:41.069825 2026] [proxy:error] [pid 229246:tid 229484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.069890 2026] [proxy_http:error] [pid 229246:tid 229484] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.070498 2026] [proxy:error] [pid 229246:tid 229484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.070523 2026] [proxy_http:error] [pid 229246:tid 229484] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.135460 2026] [http2:warn] [pid 230252:tid 230438] [client 57.141.18.25:58600] h2_stream(230252-204-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:41.246145 2026] [proxy:error] [pid 229246:tid 229501] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.246206 2026] [proxy_http:error] [pid 229246:tid 229501] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.246683 2026] [proxy:error] [pid 229246:tid 229501] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.246713 2026] [proxy_http:error] [pid 229246:tid 229501] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.254632 2026] [proxy:error] [pid 229246:tid 229486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.254681 2026] [proxy_http:error] [pid 229246:tid 229486] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.255269 2026] [proxy:error] [pid 229246:tid 229486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.255297 2026] [proxy_http:error] [pid 229246:tid 229486] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.279713 2026] [proxy:error] [pid 229246:tid 229421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.279788 2026] [proxy_http:error] [pid 229246:tid 229421] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.280545 2026] [proxy:error] [pid 229246:tid 229421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.280599 2026] [proxy_http:error] [pid 229246:tid 229421] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.531253 2026] [proxy:error] [pid 230252:tid 230476] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.531327 2026] [proxy_http:error] [pid 230252:tid 230476] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.532024 2026] [proxy:error] [pid 230252:tid 230476] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.532063 2026] [proxy_http:error] [pid 230252:tid 230476] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.710326 2026] [security2:error] [pid 230252:tid 230419] [client 74.249.245.134:21694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ws38.php"] [unique_id "al9INU0Dwhk5-Z44XrpArQAAArw"]
[Tue Jul 21 07:21:41.734898 2026] [security2:error] [pid 230252:tid 230456] [client 20.104.96.117:61121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ip.php"] [unique_id "al9INU0Dwhk5-Z44XrpAsAAAAuE"]
[Tue Jul 21 07:21:41.794687 2026] [proxy:error] [pid 230252:tid 230483] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.794749 2026] [proxy_http:error] [pid 230252:tid 230483] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.795325 2026] [proxy:error] [pid 230252:tid 230483] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.795351 2026] [proxy_http:error] [pid 230252:tid 230483] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.884630 2026] [security2:error] [pid 229246:tid 229403] [client 175.45.70.82:53827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9INSBMYeh5YLVG45xlGwAAAi8"]
[Tue Jul 21 07:21:41.884772 2026] [security2:error] [pid 229246:tid 229403] [client 175.45.70.82:53827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9INSBMYeh5YLVG45xlGwAAAi8"]
[Tue Jul 21 07:21:41.888604 2026] [proxy:error] [pid 230252:tid 230426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.888697 2026] [proxy_http:error] [pid 230252:tid 230426] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.890031 2026] [proxy:error] [pid 230252:tid 230426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:41.890087 2026] [proxy_http:error] [pid 230252:tid 230426] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:41.982294 2026] [security2:error] [pid 230252:tid 230509] [client 20.206.105.145:30674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-content/admin.php"] [unique_id "al9INU0Dwhk5-Z44XrpAuwAAAxY"]
[Tue Jul 21 07:21:42.063058 2026] [http2:warn] [pid 229246:tid 229465] [client 57.141.18.17:59362] h2_stream(229246-371-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:42.076948 2026] [security2:error] [pid 230252:tid 230481] [client 20.226.60.151:60234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9INk0Dwhk5-Z44XrpAvgAAAvo"]
[Tue Jul 21 07:21:42.186338 2026] [security2:error] [pid 230252:tid 230404] [client 139.135.44.145:53880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9INk0Dwhk5-Z44XrpAwQAAAq0"]
[Tue Jul 21 07:21:42.186478 2026] [security2:error] [pid 230252:tid 230404] [client 139.135.44.145:53880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9INk0Dwhk5-Z44XrpAwQAAAq0"]
[Tue Jul 21 07:21:42.252686 2026] [proxy:error] [pid 230252:tid 230510] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:42.252757 2026] [proxy_http:error] [pid 230252:tid 230510] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:42.253478 2026] [proxy:error] [pid 230252:tid 230510] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:42.253516 2026] [proxy_http:error] [pid 230252:tid 230510] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:42.254220 2026] [proxy:error] [pid 230252:tid 230462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:42.254333 2026] [proxy_http:error] [pid 230252:tid 230462] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:42.255385 2026] [proxy:error] [pid 230252:tid 230462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:42.255449 2026] [proxy_http:error] [pid 230252:tid 230462] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:42.508689 2026] [security2:error] [pid 230252:tid 230436] [client 64.23.218.208:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al9INk0Dwhk5-Z44XrpAyAAAAs0"]
[Tue Jul 21 07:21:42.585427 2026] [security2:error] [pid 229246:tid 229489] [client 64.23.218.208:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al9INiBMYeh5YLVG45xlLAAAAoU"]
[Tue Jul 21 07:21:42.627343 2026] [http2:warn] [pid 230252:tid 230391] [client 57.141.18.117:34682] h2_stream(230252-212-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:42.730320 2026] [security2:error] [pid 229246:tid 229479] [client 167.71.175.236:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9INiBMYeh5YLVG45xlMgAAAns"]
[Tue Jul 21 07:21:42.734516 2026] [security2:error] [pid 230252:tid 230485] [client 165.22.235.3:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9INk0Dwhk5-Z44XrpAzgAAAv4"]
[Tue Jul 21 07:21:42.772971 2026] [proxy:error] [pid 230252:tid 230459] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:42.773046 2026] [proxy_http:error] [pid 230252:tid 230459] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:42.773910 2026] [proxy:error] [pid 230252:tid 230459] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:42.773943 2026] [proxy_http:error] [pid 230252:tid 230459] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:42.851285 2026] [security2:error] [pid 230252:tid 230439] [client 167.71.175.236:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9INk0Dwhk5-Z44XrpA0gAAAtA"]
[Tue Jul 21 07:21:42.857289 2026] [security2:error] [pid 230252:tid 230293] [remote 167.172.232.142:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9INk0Dwhk5-Z44XrpA0wACqyc"]
[Tue Jul 21 07:21:42.924154 2026] [security2:error] [pid 230252:tid 230409] [client 165.227.84.14:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9INk0Dwhk5-Z44XrpA1AAAArI"]
[Tue Jul 21 07:21:42.929260 2026] [security2:error] [pid 230252:tid 230341] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9INk0Dwhk5-Z44XrpA1QACx1Y"]
[Tue Jul 21 07:21:42.929412 2026] [security2:error] [pid 230252:tid 230430] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9INk0Dwhk5-Z44XrpA1QACx1Y"]
[Tue Jul 21 07:21:42.962300 2026] [security2:error] [pid 230252:tid 230481] [client 206.189.19.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al9INk0Dwhk5-Z44XrpA1gAAAvo"]
[Tue Jul 21 07:21:43.056542 2026] [security2:error] [pid 230252:tid 230404] [client 157.230.19.140:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA2gAAAq0"]
[Tue Jul 21 07:21:43.062538 2026] [security2:error] [pid 230252:tid 230486] [client 20.104.96.117:64060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IN00Dwhk5-Z44XrpA2wAAAv8"]
[Tue Jul 21 07:21:43.092161 2026] [proxy:error] [pid 230252:tid 230462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:43.092233 2026] [proxy_http:error] [pid 230252:tid 230462] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:43.092928 2026] [proxy:error] [pid 230252:tid 230462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:43.092956 2026] [proxy_http:error] [pid 230252:tid 230462] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:43.093231 2026] [security2:error] [pid 230252:tid 230463] [client 206.189.233.36:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA3QAAAug"]
[Tue Jul 21 07:21:43.169838 2026] [security2:error] [pid 230252:tid 230472] [client 20.226.60.151:60254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IN00Dwhk5-Z44XrpA3gAAAvE"]
[Tue Jul 21 07:21:43.212667 2026] [security2:error] [pid 230252:tid 230451] [client 146.190.63.248:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA3wAAAtw"]
[Tue Jul 21 07:21:43.246992 2026] [security2:error] [pid 230252:tid 230500] [client 134.209.25.199:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA4QAAAw0"]
[Tue Jul 21 07:21:43.253224 2026] [security2:error] [pid 229246:tid 229491] [client 143.110.213.72:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9INyBMYeh5YLVG45xlNwAAAoc"]
[Tue Jul 21 07:21:43.269336 2026] [security2:error] [pid 230252:tid 230411] [client 64.226.65.160:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA4wAAArQ"]
[Tue Jul 21 07:21:43.280397 2026] [security2:error] [pid 230252:tid 230458] [client 147.182.200.94:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA5AAAAuM"]
[Tue Jul 21 07:21:43.302565 2026] [security2:error] [pid 230252:tid 230453] [client 20.206.105.145:30672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/adminfuns.php"] [unique_id "al9IN00Dwhk5-Z44XrpA5QAAAt4"]
[Tue Jul 21 07:21:43.330682 2026] [security2:error] [pid 230252:tid 230485] [client 20.104.96.117:59155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/kq1.php"] [unique_id "al9IN00Dwhk5-Z44XrpA6AAAAv4"]
[Tue Jul 21 07:21:43.340790 2026] [http2:warn] [pid 229246:tid 229376] [client 57.141.18.100:55082] h2_stream(229246-373-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:43.366073 2026] [security2:error] [pid 229246:tid 229382] [client 143.110.217.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9INyBMYeh5YLVG45xlOAAAAho"]
[Tue Jul 21 07:21:43.376274 2026] [security2:error] [pid 230252:tid 230270] [remote 110.249.201.7:62496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "issimastore.com"] [uri "/imprensa/ficha_cadastral.pdf"] [unique_id "al9IN00Dwhk5-Z44XrpA7QACqxA"]
[Tue Jul 21 07:21:43.386990 2026] [security2:error] [pid 230252:tid 230420] [client 139.59.99.58:60461] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.vivaconcierge.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9IN00Dwhk5-Z44XrpA7gAAAr0"]
[Tue Jul 21 07:21:43.507894 2026] [security2:error] [pid 230252:tid 230432] [client 207.154.197.113:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA7wAAAsk"]
[Tue Jul 21 07:21:43.594158 2026] [security2:error] [pid 229246:tid 229480] [client 138.68.144.227:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9INyBMYeh5YLVG45xlOwAAAnw"]
[Tue Jul 21 07:21:43.754920 2026] [security2:error] [pid 230252:tid 230410] [client 46.101.1.225:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA8gAAArM"]
[Tue Jul 21 07:21:43.839843 2026] [security2:error] [pid 230252:tid 230385] [client 47.128.31.153:17358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cestabasicadocarlao.com.br"] [uri "/robots.txt"] [unique_id "al9IN00Dwhk5-Z44XrpA-QAAApo"]
[Tue Jul 21 07:21:43.927843 2026] [security2:error] [pid 230252:tid 230506] [client 139.59.132.8:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA-gAAAxM"]
[Tue Jul 21 07:21:43.968840 2026] [security2:error] [pid 230252:tid 230277] [remote 138.197.191.87:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9IN00Dwhk5-Z44XrpA-wAC6Bc"]
[Tue Jul 21 07:21:44.237716 2026] [security2:error] [pid 229246:tid 229494] [client 20.206.105.145:30671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/goods.php"] [unique_id "al9IOCBMYeh5YLVG45xlSAAAAoo"]
[Tue Jul 21 07:21:44.238638 2026] [security2:error] [pid 230252:tid 230414] [client 20.226.60.151:54526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/sym403.php"] [unique_id "al9IOE0Dwhk5-Z44XrpBAAAAArc"]
[Tue Jul 21 07:21:44.334897 2026] [security2:error] [pid 229246:tid 229400] [client 20.104.96.117:62934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IOCBMYeh5YLVG45xlTQAAAiw"]
[Tue Jul 21 07:21:44.358713 2026] [security2:error] [pid 229246:tid 229394] [client 139.59.136.184:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9IOCBMYeh5YLVG45xlTgAAAiY"]
[Tue Jul 21 07:21:44.360073 2026] [security2:error] [pid 229246:tid 229423] [client 20.226.60.151:60251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/xyn.php"] [unique_id "al9IOCBMYeh5YLVG45xlTwAAAkM"]
[Tue Jul 21 07:21:44.515005 2026] [http2:warn] [pid 229246:tid 229397] [client 57.141.18.39:62478] h2_stream(229246-381-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:44.523604 2026] [security2:error] [pid 230252:tid 230485] [client 142.93.143.8:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9IOE0Dwhk5-Z44XrpBAgAAAv4"]
[Tue Jul 21 07:21:44.643877 2026] [security2:error] [pid 230252:tid 230504] [client 68.183.180.73:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9IOE0Dwhk5-Z44XrpBAwAAAxE"]
[Tue Jul 21 07:21:44.663071 2026] [security2:error] [pid 230252:tid 230402] [client 20.104.96.117:59653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9IOE0Dwhk5-Z44XrpBBAAAAqs"]
[Tue Jul 21 07:21:44.791039 2026] [security2:error] [pid 229246:tid 229270] [remote 45.117.83.212:32862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9IOCBMYeh5YLVG45xlVAACiBc"]
[Tue Jul 21 07:21:44.791179 2026] [security2:error] [pid 229246:tid 229492] [client 45.117.83.212:32862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9IOCBMYeh5YLVG45xlVAACiBc"]
[Tue Jul 21 07:21:44.890594 2026] [security2:error] [pid 230252:tid 230464] [client 110.249.202.98:28772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "issimastore.com"] [uri "/robots.txt"] [unique_id "al9IOE0Dwhk5-Z44XrpBCwAAAuk"]
[Tue Jul 21 07:21:44.944245 2026] [security2:error] [pid 230252:tid 230399] [client 20.206.105.145:30608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/ms-edit.php"] [unique_id "al9IOE0Dwhk5-Z44XrpBDwAAAqg"]
[Tue Jul 21 07:21:45.030316 2026] [security2:error] [pid 229246:tid 229398] [client 103.162.129.114:63700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IOSBMYeh5YLVG45xlWgAAAio"]
[Tue Jul 21 07:21:45.030525 2026] [security2:error] [pid 229246:tid 229398] [client 103.162.129.114:63700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IOSBMYeh5YLVG45xlWgAAAio"]
[Tue Jul 21 07:21:45.140214 2026] [security2:error] [pid 230252:tid 230496] [client 103.121.156.110:63881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IOU0Dwhk5-Z44XrpBGAAAAwk"]
[Tue Jul 21 07:21:45.140379 2026] [security2:error] [pid 230252:tid 230496] [client 103.121.156.110:63881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IOU0Dwhk5-Z44XrpBGAAAAwk"]
[Tue Jul 21 07:21:45.146221 2026] [http2:warn] [pid 229246:tid 229419] [client 57.141.18.57:38628] h2_stream(229246-386-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:45.249872 2026] [proxy:error] [pid 230252:tid 230472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.249919 2026] [proxy_http:error] [pid 230252:tid 230472] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.250449 2026] [proxy:error] [pid 230252:tid 230472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.250469 2026] [proxy_http:error] [pid 230252:tid 230472] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.267859 2026] [proxy:error] [pid 230252:tid 230506] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.267894 2026] [proxy_http:error] [pid 230252:tid 230506] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.268310 2026] [proxy:error] [pid 230252:tid 230506] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.268329 2026] [proxy_http:error] [pid 230252:tid 230506] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.337946 2026] [security2:error] [pid 230252:tid 230419] [client 193.36.225.73:26839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IOU0Dwhk5-Z44XrpBGQAAArw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:45.458753 2026] [security2:error] [pid 229246:tid 229452] [client 20.206.105.145:30625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/222.php"] [unique_id "al9IOSBMYeh5YLVG45xlZQAAAmA"]
[Tue Jul 21 07:21:45.583243 2026] [proxy:error] [pid 230252:tid 230485] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.583312 2026] [proxy_http:error] [pid 230252:tid 230485] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.583949 2026] [proxy:error] [pid 230252:tid 230485] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.583982 2026] [proxy_http:error] [pid 230252:tid 230485] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.683349 2026] [security2:error] [pid 230252:tid 230511] [client 20.206.105.145:30596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/cgi-bin/index.php"] [unique_id "al9IOU0Dwhk5-Z44XrpBJAAAAxg"]
[Tue Jul 21 07:21:45.753509 2026] [security2:error] [pid 229246:tid 229275] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IOSBMYeh5YLVG45xlZwACGRw"]
[Tue Jul 21 07:21:45.753682 2026] [security2:error] [pid 229246:tid 229381] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IOSBMYeh5YLVG45xlZwACGRw"]
[Tue Jul 21 07:21:45.923594 2026] [security2:error] [pid 229246:tid 229451] [client 68.235.38.2:41102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9IOSBMYeh5YLVG45xlawAAAl8"]
[Tue Jul 21 07:21:45.923693 2026] [security2:error] [pid 229246:tid 229451] [client 68.235.38.2:41102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9IOSBMYeh5YLVG45xlawAAAl8"]
[Tue Jul 21 07:21:45.948569 2026] [proxy:error] [pid 229246:tid 229494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.948640 2026] [proxy_http:error] [pid 229246:tid 229494] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.949731 2026] [proxy:error] [pid 229246:tid 229494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:45.949783 2026] [proxy_http:error] [pid 229246:tid 229494] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:45.970506 2026] [security2:error] [pid 230252:tid 230311] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IOU0Dwhk5-Z44XrpBLAACojk"]
[Tue Jul 21 07:21:45.970635 2026] [security2:error] [pid 230252:tid 230393] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IOU0Dwhk5-Z44XrpBLAACojk"]
[Tue Jul 21 07:21:46.084578 2026] [security2:error] [pid 230252:tid 230463] [client 20.206.105.145:30620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/BDKR28WP.php"] [unique_id "al9IOk0Dwhk5-Z44XrpBLQAAAug"]
[Tue Jul 21 07:21:46.092453 2026] [http2:warn] [pid 229246:tid 229467] [client 57.141.18.20:40562] h2_stream(229246-390-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:46.133487 2026] [security2:error] [pid 229246:tid 229399] [client 74.249.245.134:61528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/a7.php"] [unique_id "al9IOiBMYeh5YLVG45xlbgAAAis"]
[Tue Jul 21 07:21:46.146541 2026] [autoindex:error] [pid 230252:tid 230495] [client 148.113.192.228:42884] AH01276: Cannot serve directory /home3/edua2728/anshin.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:21:46.207908 2026] [security2:error] [pid 229246:tid 229394] [client 20.104.96.117:62918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/media.php"] [unique_id "al9IOiBMYeh5YLVG45xlcAAAAiY"]
[Tue Jul 21 07:21:46.667686 2026] [security2:error] [pid 229246:tid 229432] [client 20.226.60.151:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/patie.php"] [unique_id "al9IOiBMYeh5YLVG45xldgAAAkw"]
[Tue Jul 21 07:21:46.676536 2026] [security2:error] [pid 230252:tid 230451] [client 20.206.105.145:30624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/raw.php"] [unique_id "al9IOk0Dwhk5-Z44XrpBOgAAAtw"]
[Tue Jul 21 07:21:46.885066 2026] [security2:error] [pid 229246:tid 229403] [client 45.251.232.145:49948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IOiBMYeh5YLVG45xleAAAAi8"]
[Tue Jul 21 07:21:46.885215 2026] [security2:error] [pid 229246:tid 229403] [client 45.251.232.145:49948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IOiBMYeh5YLVG45xleAAAAi8"]
[Tue Jul 21 07:21:46.901195 2026] [security2:error] [pid 229246:tid 229493] [client 20.206.105.145:30716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/abcd.php"] [unique_id "al9IOiBMYeh5YLVG45xleQAAAok"]
[Tue Jul 21 07:21:47.108405 2026] [security2:error] [pid 230252:tid 230506] [client 20.206.105.145:30714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/a1.php"] [unique_id "al9IO00Dwhk5-Z44XrpBRwAAAxM"]
[Tue Jul 21 07:21:47.247682 2026] [proxy:error] [pid 230252:tid 230495] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:47.247749 2026] [proxy_http:error] [pid 230252:tid 230495] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:47.248291 2026] [proxy:error] [pid 230252:tid 230495] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:47.248318 2026] [proxy_http:error] [pid 230252:tid 230495] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:47.267917 2026] [proxy:error] [pid 230252:tid 230454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:47.267980 2026] [proxy_http:error] [pid 230252:tid 230454] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:47.268659 2026] [proxy:error] [pid 230252:tid 230454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:47.268694 2026] [proxy_http:error] [pid 230252:tid 230454] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:47.394885 2026] [security2:error] [pid 229246:tid 229262] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IOyBMYeh5YLVG45xlhwACgg8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:47.399498 2026] [http2:warn] [pid 229246:tid 229415] [client 57.141.18.24:32594] h2_stream(229246-392-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:47.437834 2026] [security2:error] [pid 229246:tid 229454] [client 20.206.105.145:30662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9IOyBMYeh5YLVG45xljQAAAmI"]
[Tue Jul 21 07:21:47.443672 2026] [security2:error] [pid 230252:tid 230290] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IO00Dwhk5-Z44XrpBTQACoiQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:47.517366 2026] [security2:error] [pid 230252:tid 230419] [client 14.139.42.196:10874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IO00Dwhk5-Z44XrpBVAAAArw"]
[Tue Jul 21 07:21:47.517455 2026] [security2:error] [pid 230252:tid 230419] [client 14.139.42.196:10874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IO00Dwhk5-Z44XrpBVAAAArw"]
[Tue Jul 21 07:21:47.708025 2026] [security2:error] [pid 229246:tid 229495] [client 20.104.96.117:64002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/images.php"] [unique_id "al9IOyBMYeh5YLVG45xlkAAAAos"]
[Tue Jul 21 07:21:47.739771 2026] [security2:error] [pid 230252:tid 230421] [client 20.206.105.145:30666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9IO00Dwhk5-Z44XrpBWwAAAr4"]
[Tue Jul 21 07:21:47.765484 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:47.765542 2026] [proxy_http:error] [pid 230252:tid 230456] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:47.765976 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:47.765998 2026] [proxy_http:error] [pid 230252:tid 230456] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:47.935658 2026] [security2:error] [pid 230252:tid 230409] [client 20.104.96.117:59681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/h02ugyh.php"] [unique_id "al9IO00Dwhk5-Z44XrpBZQAAArI"]
[Tue Jul 21 07:21:48.014905 2026] [security2:error] [pid 230252:tid 230368] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBaQACz3E"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.032211 2026] [security2:error] [pid 230252:tid 230299] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBagACyS0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.052695 2026] [proxy:error] [pid 229246:tid 229425] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.052768 2026] [proxy_http:error] [pid 229246:tid 229425] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.053521 2026] [proxy:error] [pid 229246:tid 229425] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.053558 2026] [proxy_http:error] [pid 229246:tid 229425] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.058151 2026] [access_compat:error] [pid 230252:tid 230454] [client 162.241.63.68:23230] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:21:48.078908 2026] [security2:error] [pid 230252:tid 230393] [client 20.206.105.145:30658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-content/BypassBest.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBbAAAAqI"]
[Tue Jul 21 07:21:48.195665 2026] [http2:warn] [pid 230252:tid 230418] [client 57.141.18.33:27588] h2_stream(230252-221-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:48.238904 2026] [security2:error] [pid 229246:tid 229367] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IPCBMYeh5YLVG45xlmwACfng"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.258549 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.258614 2026] [proxy_http:error] [pid 230252:tid 230456] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.259186 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.259210 2026] [proxy_http:error] [pid 230252:tid 230456] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.276284 2026] [proxy:error] [pid 229246:tid 229398] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.276344 2026] [proxy_http:error] [pid 229246:tid 229398] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.277080 2026] [proxy:error] [pid 229246:tid 229398] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.277114 2026] [proxy_http:error] [pid 229246:tid 229398] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.278466 2026] [security2:error] [pid 230252:tid 230395] [client 74.249.245.134:44067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/classsmtps.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBeQAAAqQ"]
[Tue Jul 21 07:21:48.296575 2026] [security2:error] [pid 230252:tid 230265] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBfQAC6As"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.373425 2026] [security2:error] [pid 229246:tid 229315] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IOyBMYeh5YLVG45xlhgACkUQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.473166 2026] [security2:error] [pid 230252:tid 230268] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBiAACuQ4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.489059 2026] [security2:error] [pid 230252:tid 230294] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IO00Dwhk5-Z44XrpBUQAC6Cg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.528424 2026] [security2:error] [pid 230252:tid 230287] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBiwACtyE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.582355 2026] [security2:error] [pid 230252:tid 230263] [remote 64.23.157.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBjQAC4wk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:21:48.633631 2026] [core:crit] [pid 230252:tid 230419] (13)Permission denied: [client 45.156.129.171:44938] AH00529: /home4/moadvo53/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home4/moadvo53/public_html/cgi-bin/' is executable
[Tue Jul 21 07:21:48.652881 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.652955 2026] [proxy_http:error] [pid 230252:tid 230447] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.653746 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.653790 2026] [proxy_http:error] [pid 230252:tid 230447] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.759423 2026] [security2:error] [pid 230252:tid 230366] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBmAACyW8"]
[Tue Jul 21 07:21:48.759575 2026] [security2:error] [pid 230252:tid 230432] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IPE0Dwhk5-Z44XrpBmAACyW8"]
[Tue Jul 21 07:21:48.760604 2026] [proxy:error] [pid 230252:tid 230439] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.760680 2026] [proxy_http:error] [pid 230252:tid 230439] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.761652 2026] [proxy:error] [pid 230252:tid 230439] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.761694 2026] [proxy_http:error] [pid 230252:tid 230439] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.771466 2026] [security2:error] [pid 229246:tid 229480] [client 20.104.96.117:64055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/gecko.php"] [unique_id "al9IPCBMYeh5YLVG45xlsAAAAnw"]
[Tue Jul 21 07:21:48.834735 2026] [proxy:error] [pid 230252:tid 230492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.834797 2026] [proxy_http:error] [pid 230252:tid 230492] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.835254 2026] [proxy:error] [pid 230252:tid 230492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.835278 2026] [proxy_http:error] [pid 230252:tid 230492] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.925681 2026] [proxy:error] [pid 230252:tid 230451] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.925751 2026] [proxy_http:error] [pid 230252:tid 230451] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.926481 2026] [proxy:error] [pid 230252:tid 230451] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:48.926512 2026] [proxy_http:error] [pid 230252:tid 230451] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:48.928749 2026] [security2:error] [pid 229246:tid 229380] [client 20.206.105.145:30704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/simple.php"] [unique_id "al9IPCBMYeh5YLVG45xltAAAAhg"]
[Tue Jul 21 07:21:49.035973 2026] [proxy:error] [pid 230252:tid 230479] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.036037 2026] [proxy_http:error] [pid 230252:tid 230479] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.036481 2026] [proxy:error] [pid 230252:tid 230479] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.036503 2026] [proxy_http:error] [pid 230252:tid 230479] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.144421 2026] [proxy:error] [pid 230252:tid 230404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.144487 2026] [proxy_http:error] [pid 230252:tid 230404] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.144970 2026] [proxy:error] [pid 230252:tid 230404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.144999 2026] [proxy_http:error] [pid 230252:tid 230404] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.242566 2026] [http2:warn] [pid 229246:tid 229502] [client 57.141.18.89:26280] h2_stream(229246-394-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:49.281599 2026] [proxy:error] [pid 229246:tid 229414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.281704 2026] [proxy_http:error] [pid 229246:tid 229414] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.283206 2026] [proxy:error] [pid 229246:tid 229414] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.283288 2026] [proxy_http:error] [pid 229246:tid 229414] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.299972 2026] [proxy:error] [pid 229246:tid 229404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.300045 2026] [proxy_http:error] [pid 229246:tid 229404] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.300678 2026] [proxy:error] [pid 229246:tid 229404] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.300713 2026] [proxy_http:error] [pid 229246:tid 229404] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.424150 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.424215 2026] [proxy_http:error] [pid 230252:tid 230484] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.424861 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.424888 2026] [proxy_http:error] [pid 230252:tid 230484] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.533006 2026] [proxy:error] [pid 229246:tid 229423] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.533071 2026] [proxy_http:error] [pid 229246:tid 229423] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.533622 2026] [proxy:error] [pid 229246:tid 229423] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.533647 2026] [proxy_http:error] [pid 229246:tid 229423] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.656837 2026] [security2:error] [pid 230252:tid 230412] [client 136.144.33.99:24769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IPU0Dwhk5-Z44XrpByQAAArU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:49.657657 2026] [security2:error] [pid 230252:tid 230440] [client 20.206.105.145:30667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/xxx.php"] [unique_id "al9IPU0Dwhk5-Z44XrpBygAAAtE"]
[Tue Jul 21 07:21:49.684186 2026] [proxy:error] [pid 230252:tid 230478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.684271 2026] [proxy_http:error] [pid 230252:tid 230478] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.684974 2026] [proxy:error] [pid 230252:tid 230478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.685017 2026] [proxy_http:error] [pid 230252:tid 230478] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.739047 2026] [proxy:error] [pid 230252:tid 230392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.739106 2026] [proxy_http:error] [pid 230252:tid 230392] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.739561 2026] [proxy:error] [pid 230252:tid 230392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.739593 2026] [proxy_http:error] [pid 230252:tid 230392] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.761981 2026] [security2:error] [pid 230252:tid 230453] [client 20.104.96.117:59705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-temp.php"] [unique_id "al9IPU0Dwhk5-Z44XrpB0AAAAt4"]
[Tue Jul 21 07:21:49.810058 2026] [proxy:error] [pid 229246:tid 229499] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.810127 2026] [proxy_http:error] [pid 229246:tid 229499] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.810271 2026] [security2:error] [pid 230252:tid 230482] [client 20.104.96.117:64010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/82.php"] [unique_id "al9IPU0Dwhk5-Z44XrpB0QAAAvs"]
[Tue Jul 21 07:21:49.810803 2026] [proxy:error] [pid 229246:tid 229499] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.810832 2026] [proxy_http:error] [pid 229246:tid 229499] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.920078 2026] [proxy:error] [pid 230252:tid 230438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.920162 2026] [proxy_http:error] [pid 230252:tid 230438] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.920857 2026] [proxy:error] [pid 230252:tid 230438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:49.920896 2026] [proxy_http:error] [pid 230252:tid 230438] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:49.948696 2026] [security2:error] [pid 230252:tid 230465] [client 20.206.105.145:30668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/hypo.php"] [unique_id "al9IPU0Dwhk5-Z44XrpB2AAAAuo"]
[Tue Jul 21 07:21:50.083892 2026] [http2:warn] [pid 229246:tid 229437] [client 57.141.18.81:35606] h2_stream(229246-395-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:50.134253 2026] [proxy:error] [pid 229246:tid 229433] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.134327 2026] [proxy_http:error] [pid 229246:tid 229433] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.134838 2026] [proxy:error] [pid 229246:tid 229433] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.134867 2026] [proxy_http:error] [pid 229246:tid 229433] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.160822 2026] [security2:error] [pid 230252:tid 230509] [client 74.249.245.134:48490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/rip.php"] [unique_id "al9IPk0Dwhk5-Z44XrpB3gAAAxY"]
[Tue Jul 21 07:21:50.210001 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.210072 2026] [proxy_http:error] [pid 230252:tid 230421] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.210868 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.210900 2026] [proxy_http:error] [pid 230252:tid 230421] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.233877 2026] [proxy:error] [pid 230252:tid 230419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.233936 2026] [proxy_http:error] [pid 230252:tid 230419] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.234528 2026] [proxy:error] [pid 230252:tid 230419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.234555 2026] [proxy_http:error] [pid 230252:tid 230419] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.308170 2026] [proxy:error] [pid 229246:tid 229390] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.308232 2026] [proxy_http:error] [pid 229246:tid 229390] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.308683 2026] [proxy:error] [pid 229246:tid 229390] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.308717 2026] [proxy_http:error] [pid 229246:tid 229390] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.383084 2026] [security2:error] [pid 229246:tid 229428] [client 20.220.225.223:34185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/ez.php"] [unique_id "al9IPiBMYeh5YLVG45xl4AAAAkg"]
[Tue Jul 21 07:21:50.396145 2026] [security2:error] [pid 230252:tid 230478] [client 20.226.60.151:60168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/aa.php"] [unique_id "al9IPk0Dwhk5-Z44XrpB6AAAAvc"]
[Tue Jul 21 07:21:50.472277 2026] [security2:error] [pid 229246:tid 229472] [client 103.174.34.15:64777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IPiBMYeh5YLVG45xl4QAAAnQ"]
[Tue Jul 21 07:21:50.472392 2026] [security2:error] [pid 229246:tid 229472] [client 103.174.34.15:64777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IPiBMYeh5YLVG45xl4QAAAnQ"]
[Tue Jul 21 07:21:50.481998 2026] [security2:error] [pid 229246:tid 229349] [remote 132.148.72.88:58730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powertronicseguranca.com"] [uri "/wp-login.php"] [unique_id "al9IPiBMYeh5YLVG45xl4gACTmY"]
[Tue Jul 21 07:21:50.521504 2026] [proxy:error] [pid 230252:tid 230475] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.521570 2026] [proxy_http:error] [pid 230252:tid 230475] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.522277 2026] [proxy:error] [pid 230252:tid 230475] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.522310 2026] [proxy_http:error] [pid 230252:tid 230475] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.689882 2026] [security2:error] [pid 230252:tid 230298] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IPk0Dwhk5-Z44XrpB9AACySw"]
[Tue Jul 21 07:21:50.690037 2026] [security2:error] [pid 230252:tid 230432] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IPk0Dwhk5-Z44XrpB9AACySw"]
[Tue Jul 21 07:21:50.698010 2026] [proxy:error] [pid 230252:tid 230438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.698077 2026] [proxy_http:error] [pid 230252:tid 230438] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.698754 2026] [proxy:error] [pid 230252:tid 230438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.698782 2026] [proxy_http:error] [pid 230252:tid 230438] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.702462 2026] [proxy:error] [pid 230252:tid 230405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.702523 2026] [proxy_http:error] [pid 230252:tid 230405] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.703013 2026] [proxy:error] [pid 230252:tid 230405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.703037 2026] [proxy_http:error] [pid 230252:tid 230405] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.898958 2026] [security2:error] [pid 230252:tid 230331] [remote 192.241.143.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.hauptmann.com.br"] [uri "/wp-login.php"] [unique_id "al9IPk0Dwhk5-Z44XrpB_AACokw"]
[Tue Jul 21 07:21:50.912654 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.912720 2026] [proxy_http:error] [pid 230252:tid 230447] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.913485 2026] [proxy:error] [pid 230252:tid 230447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:50.913516 2026] [proxy_http:error] [pid 230252:tid 230447] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:50.919683 2026] [security2:error] [pid 230252:tid 230402] [client 114.119.136.141:51295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "projetoflechas.org.br"] [uri "/videos/flechas-para-as-nacoes-2011"] [unique_id "al9IPk0Dwhk5-Z44XrpB_gAAAqs"], referer: http://projetoflechas.org.br/videos/flechas-para-as-nacoes-2011?shared=email&msg=fail
[Tue Jul 21 07:21:51.199732 2026] [proxy:error] [pid 229246:tid 229383] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.199791 2026] [proxy_http:error] [pid 229246:tid 229383] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.200362 2026] [proxy:error] [pid 229246:tid 229383] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.200391 2026] [proxy_http:error] [pid 229246:tid 229383] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.297230 2026] [http2:warn] [pid 230252:tid 230449] [client 57.141.18.50:45830] h2_stream(230252-230-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:51.387587 2026] [security2:error] [pid 230252:tid 230283] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IP00Dwhk5-Z44XrpCCQACtB0"]
[Tue Jul 21 07:21:51.387741 2026] [security2:error] [pid 230252:tid 230411] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IP00Dwhk5-Z44XrpCCQACtB0"]
[Tue Jul 21 07:21:51.404472 2026] [security2:error] [pid 230252:tid 230492] [client 20.220.225.223:59471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/bootstrap.php"] [unique_id "al9IP00Dwhk5-Z44XrpCCwAAAwU"]
[Tue Jul 21 07:21:51.410510 2026] [security2:error] [pid 230252:tid 230297] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IP00Dwhk5-Z44XrpCDAAC4Cs"]
[Tue Jul 21 07:21:51.410745 2026] [security2:error] [pid 230252:tid 230455] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IP00Dwhk5-Z44XrpCDAAC4Cs"]
[Tue Jul 21 07:21:51.475844 2026] [security2:error] [pid 229246:tid 229416] [client 20.206.105.145:30529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/chosen.php"] [unique_id "al9IPyBMYeh5YLVG45xl7QAAAjw"]
[Tue Jul 21 07:21:51.507907 2026] [security2:error] [pid 229246:tid 229486] [client 20.104.96.117:59197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9IPyBMYeh5YLVG45xl7gAAAoI"]
[Tue Jul 21 07:21:51.515807 2026] [security2:error] [pid 229246:tid 229454] [client 20.104.96.117:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9IPyBMYeh5YLVG45xl7wAAAmI"]
[Tue Jul 21 07:21:51.584723 2026] [security2:error] [pid 230252:tid 230460] [client 20.226.60.151:54570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/v543.php"] [unique_id "al9IP00Dwhk5-Z44XrpCEAAAAuU"]
[Tue Jul 21 07:21:51.655228 2026] [proxy:error] [pid 230252:tid 230389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.655301 2026] [proxy_http:error] [pid 230252:tid 230389] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.655822 2026] [proxy:error] [pid 230252:tid 230389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.655847 2026] [proxy_http:error] [pid 230252:tid 230389] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.689282 2026] [proxy:error] [pid 230252:tid 230493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.689344 2026] [proxy_http:error] [pid 230252:tid 230493] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.690067 2026] [proxy:error] [pid 230252:tid 230493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.690095 2026] [proxy_http:error] [pid 230252:tid 230493] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.716459 2026] [security2:error] [pid 230252:tid 230415] [client 74.249.245.134:62472] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "drjoaoguedes.com"] [uri "/1.php"] [unique_id "al9IP00Dwhk5-Z44XrpCFQAAArg"]
[Tue Jul 21 07:21:51.716560 2026] [security2:error] [pid 230252:tid 230415] [client 74.249.245.134:62472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/1.php"] [unique_id "al9IP00Dwhk5-Z44XrpCFQAAArg"]
[Tue Jul 21 07:21:51.899188 2026] [security2:error] [pid 230252:tid 230391] [client 165.22.235.3:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.235.22.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IP00Dwhk5-Z44XrpCHQAAAqA"]
[Tue Jul 21 07:21:51.902632 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.902707 2026] [proxy_http:error] [pid 230252:tid 230484] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.903783 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:51.903835 2026] [proxy_http:error] [pid 230252:tid 230484] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:51.917569 2026] [http2:warn] [pid 230252:tid 230467] [client 57.141.18.85:56220] h2_stream(230252-232-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:52.036876 2026] [security2:error] [pid 230252:tid 230393] [client 167.71.175.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.175.71.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IP00Dwhk5-Z44XrpCHAAAAqI"]
[Tue Jul 21 07:21:52.297949 2026] [security2:error] [pid 230252:tid 230504] [client 20.220.225.223:47839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wp-editor.php"] [unique_id "al9IQE0Dwhk5-Z44XrpCLAAAAxE"]
[Tue Jul 21 07:21:52.358439 2026] [security2:error] [pid 229246:tid 229465] [client 206.189.233.36:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.233.189.206.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQCBMYeh5YLVG45xl9gAAAm0"]
[Tue Jul 21 07:21:52.381625 2026] [security2:error] [pid 230252:tid 230420] [client 64.23.218.208:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.218.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQE0Dwhk5-Z44XrpCLgAAAr0"]
[Tue Jul 21 07:21:52.521193 2026] [security2:error] [pid 229246:tid 229495] [client 64.23.218.208:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.218.23.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQCBMYeh5YLVG45xl9wAAAos"]
[Tue Jul 21 07:21:52.767424 2026] [security2:error] [pid 230252:tid 230405] [client 206.189.19.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.19.189.206.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQE0Dwhk5-Z44XrpCMwAAAq4"]
[Tue Jul 21 07:21:52.817408 2026] [http2:warn] [pid 230252:tid 230508] [client 57.141.18.119:39444] h2_stream(230252-235-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:52.984161 2026] [security2:error] [pid 230252:tid 230500] [client 74.7.241.190:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "printcom.com.br"] [uri "/index.php"] [unique_id "al9IQE0Dwhk5-Z44XrpCNgADDWM"]
[Tue Jul 21 07:21:53.104821 2026] [security2:error] [pid 230252:tid 230389] [client 139.135.44.145:54702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCPgAAAp4"]
[Tue Jul 21 07:21:53.104952 2026] [security2:error] [pid 230252:tid 230389] [client 139.135.44.145:54702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCPgAAAp4"]
[Tue Jul 21 07:21:53.203054 2026] [security2:error] [pid 230252:tid 230402] [client 74.249.245.134:50005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/chosen.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCQAAAAqs"]
[Tue Jul 21 07:21:53.204704 2026] [security2:error] [pid 230252:tid 230421] [client 20.197.192.193:42214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCQQAAAr4"]
[Tue Jul 21 07:21:53.205801 2026] [proxy:error] [pid 230252:tid 230463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.205871 2026] [proxy_http:error] [pid 230252:tid 230463] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.206880 2026] [proxy:error] [pid 230252:tid 230463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.206920 2026] [proxy_http:error] [pid 230252:tid 230463] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.240164 2026] [security2:error] [pid 230252:tid 230404] [client 175.45.70.82:54333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCRAAAAq0"]
[Tue Jul 21 07:21:53.240302 2026] [security2:error] [pid 230252:tid 230404] [client 175.45.70.82:54333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCRAAAAq0"]
[Tue Jul 21 07:21:53.257007 2026] [security2:error] [pid 229246:tid 229481] [client 146.190.63.248:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.63.190.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQSBMYeh5YLVG45xmAQAAAn0"]
[Tue Jul 21 07:21:53.286869 2026] [security2:error] [pid 230252:tid 230412] [client 167.71.175.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.175.71.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCRgAAArU"]
[Tue Jul 21 07:21:53.296973 2026] [security2:error] [pid 230252:tid 230443] [client 165.227.84.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.84.227.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.polianoduarteramos1782482019000.polianoduarteramos1781890012818.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCRwAAAtQ"]
[Tue Jul 21 07:21:53.348179 2026] [security2:error] [pid 230252:tid 230504] [client 20.197.192.193:41568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCSQAAAxE"]
[Tue Jul 21 07:21:53.371117 2026] [security2:error] [pid 230252:tid 230475] [client 20.197.192.193:42217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/dp.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCSwAAAvQ"]
[Tue Jul 21 07:21:53.385717 2026] [security2:error] [pid 229246:tid 229485] [client 20.197.192.193:42223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/old.php"] [unique_id "al9IQSBMYeh5YLVG45xmCAAAAoE"]
[Tue Jul 21 07:21:53.402323 2026] [security2:error] [pid 230252:tid 230411] [client 20.197.192.193:41596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/ms-new.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCTAAAArQ"]
[Tue Jul 21 07:21:53.416390 2026] [security2:error] [pid 229246:tid 229382] [client 20.197.192.193:42183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/track.php"] [unique_id "al9IQSBMYeh5YLVG45xmCgAAAho"]
[Tue Jul 21 07:21:53.431651 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.192.193:42206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/2352356666.php"] [unique_id "al9IQSBMYeh5YLVG45xmDAAAAjI"]
[Tue Jul 21 07:21:53.449092 2026] [security2:error] [pid 229246:tid 229388] [client 20.197.192.193:42185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/pn.php"] [unique_id "al9IQSBMYeh5YLVG45xmDgAAAiA"]
[Tue Jul 21 07:21:53.463764 2026] [security2:error] [pid 230252:tid 230312] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCTgAC4Do"]
[Tue Jul 21 07:21:53.463920 2026] [security2:error] [pid 230252:tid 230455] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCTgAC4Do"]
[Tue Jul 21 07:21:53.466438 2026] [security2:error] [pid 229246:tid 229472] [client 20.197.192.193:42189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9IQSBMYeh5YLVG45xmDwAAAnQ"]
[Tue Jul 21 07:21:53.482733 2026] [security2:error] [pid 229246:tid 229452] [client 20.197.192.193:41545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/dr.php"] [unique_id "al9IQSBMYeh5YLVG45xmEAAAAmA"]
[Tue Jul 21 07:21:53.498673 2026] [security2:error] [pid 229246:tid 229477] [client 20.197.192.193:41591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/2x.php"] [unique_id "al9IQSBMYeh5YLVG45xmEQAAAnk"]
[Tue Jul 21 07:21:53.539415 2026] [security2:error] [pid 229246:tid 229421] [client 147.182.200.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.200.182.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQSBMYeh5YLVG45xmEgAAAkE"]
[Tue Jul 21 07:21:53.541872 2026] [security2:error] [pid 229246:tid 229380] [client 20.197.192.193:42193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/kq1.php"] [unique_id "al9IQSBMYeh5YLVG45xmEwAAAhg"]
[Tue Jul 21 07:21:53.554318 2026] [security2:error] [pid 229246:tid 229447] [client 157.230.19.140:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.19.230.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQSBMYeh5YLVG45xmFAAAAls"]
[Tue Jul 21 07:21:53.569460 2026] [security2:error] [pid 230252:tid 230459] [client 20.197.192.193:41593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/zzz.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCUgAAAuQ"]
[Tue Jul 21 07:21:53.578632 2026] [security2:error] [pid 230252:tid 230464] [client 20.220.225.223:34303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/fz.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCUwAAAuk"]
[Tue Jul 21 07:21:53.582335 2026] [security2:error] [pid 229246:tid 229407] [client 143.110.217.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.217.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQCBMYeh5YLVG45xl-QAAAjM"]
[Tue Jul 21 07:21:53.583782 2026] [security2:error] [pid 229246:tid 229381] [client 20.104.96.117:61122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9IQSBMYeh5YLVG45xmFQAAAhk"]
[Tue Jul 21 07:21:53.592701 2026] [security2:error] [pid 230252:tid 230414] [client 20.197.192.193:42227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wicked.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCVAAAArc"]
[Tue Jul 21 07:21:53.613652 2026] [security2:error] [pid 230252:tid 230453] [client 207.154.197.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.197.154.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCTQAAAt4"]
[Tue Jul 21 07:21:53.621075 2026] [security2:error] [pid 229246:tid 229448] [client 20.197.192.193:42197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/edit.php"] [unique_id "al9IQSBMYeh5YLVG45xmFwAAAlw"]
[Tue Jul 21 07:21:53.641409 2026] [proxy:error] [pid 229246:tid 229402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.641473 2026] [proxy_http:error] [pid 229246:tid 229402] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.642063 2026] [proxy:error] [pid 229246:tid 229402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.642088 2026] [proxy_http:error] [pid 229246:tid 229402] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.657449 2026] [security2:error] [pid 230252:tid 230421] [client 20.197.192.193:42191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/kua.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCVQAAAr4"]
[Tue Jul 21 07:21:53.695892 2026] [proxy:error] [pid 229246:tid 229397] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.695962 2026] [proxy_http:error] [pid 229246:tid 229397] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.696621 2026] [proxy:error] [pid 229246:tid 229397] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.696650 2026] [proxy_http:error] [pid 229246:tid 229397] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.698270 2026] [security2:error] [pid 230252:tid 230506] [client 20.197.192.193:42210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/ez.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCVwAAAxM"]
[Tue Jul 21 07:21:53.726728 2026] [security2:error] [pid 229246:tid 229457] [client 143.110.213.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.213.110.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQCBMYeh5YLVG45xl_QAAAmU"]
[Tue Jul 21 07:21:53.727973 2026] [security2:error] [pid 229246:tid 229478] [client 20.197.192.193:41558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/fz.php"] [unique_id "al9IQSBMYeh5YLVG45xmGwAAAno"]
[Tue Jul 21 07:21:53.734192 2026] [security2:error] [pid 230252:tid 230410] [client 193.36.225.56:63057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCUQAAArM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:53.747644 2026] [security2:error] [pid 230252:tid 230492] [client 20.197.192.193:48936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/la.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCWwAAAwU"]
[Tue Jul 21 07:21:53.762007 2026] [security2:error] [pid 229246:tid 229430] [client 134.209.25.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.25.209.134.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQSBMYeh5YLVG45xmFgAAAko"]
[Tue Jul 21 07:21:53.779722 2026] [security2:error] [pid 230252:tid 230482] [client 20.197.192.193:41582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCXgAAAvs"]
[Tue Jul 21 07:21:53.786644 2026] [security2:error] [pid 229246:tid 229404] [client 20.197.192.193:27133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.oticapersona.com.br"] [uri "/ms.php"] [unique_id "al9IQSBMYeh5YLVG45xmIgAAAjA"]
[Tue Jul 21 07:21:53.808597 2026] [security2:error] [pid 229246:tid 229465] [client 20.197.192.193:42224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/inso.php"] [unique_id "al9IQSBMYeh5YLVG45xmIwAAAm0"]
[Tue Jul 21 07:21:53.821619 2026] [security2:error] [pid 229246:tid 229376] [client 20.104.96.117:64014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/adminner.php"] [unique_id "al9IQSBMYeh5YLVG45xmJQAAAhQ"]
[Tue Jul 21 07:21:53.834946 2026] [security2:error] [pid 229246:tid 229495] [client 20.197.192.193:41559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wpx.php"] [unique_id "al9IQSBMYeh5YLVG45xmJgAAAos"]
[Tue Jul 21 07:21:53.864176 2026] [security2:error] [pid 229246:tid 229441] [client 20.197.192.193:41579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/berlin.php"] [unique_id "al9IQSBMYeh5YLVG45xmJwAAAlU"]
[Tue Jul 21 07:21:53.883205 2026] [http2:warn] [pid 229246:tid 229500] [client 57.141.18.60:39706] h2_stream(229246-404-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:53.885797 2026] [security2:error] [pid 230252:tid 230465] [client 20.197.192.193:48930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/billur.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCZgAAAuo"]
[Tue Jul 21 07:21:53.891870 2026] [proxy:error] [pid 229246:tid 229396] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.891946 2026] [proxy_http:error] [pid 229246:tid 229396] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.893320 2026] [proxy:error] [pid 229246:tid 229396] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:53.893367 2026] [proxy_http:error] [pid 229246:tid 229396] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:53.910861 2026] [security2:error] [pid 230252:tid 230405] [client 20.197.192.193:48896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/mimpi.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCZwAAAq4"]
[Tue Jul 21 07:21:53.933191 2026] [security2:error] [pid 230252:tid 230416] [client 20.197.192.193:42220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/dp.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCaAAAArk"]
[Tue Jul 21 07:21:53.962890 2026] [security2:error] [pid 230252:tid 230464] [client 20.197.192.193:42232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/bootstrap.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCaQAAAuk"]
[Tue Jul 21 07:21:53.992713 2026] [security2:error] [pid 230252:tid 230509] [client 20.197.192.193:41573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wp-editor.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCagAAAxY"]
[Tue Jul 21 07:21:54.014933 2026] [security2:error] [pid 230252:tid 230510] [client 20.197.192.193:48901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/cro.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCbQAAAxc"]
[Tue Jul 21 07:21:54.027249 2026] [security2:error] [pid 229246:tid 229482] [client 20.197.192.193:42235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/cron-tab.php"] [unique_id "al9IQiBMYeh5YLVG45xmKQAAAn4"]
[Tue Jul 21 07:21:54.038343 2026] [security2:error] [pid 230252:tid 230506] [client 20.206.105.145:30558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/file5.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCbwAAAxM"]
[Tue Jul 21 07:21:54.039907 2026] [security2:error] [pid 230252:tid 230399] [client 20.197.192.193:48946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/koiy.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCcAAAAqg"]
[Tue Jul 21 07:21:54.059962 2026] [security2:error] [pid 230252:tid 230478] [client 20.197.192.193:48932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/hp2.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCcgAAAvc"]
[Tue Jul 21 07:21:54.087545 2026] [security2:error] [pid 230252:tid 230410] [client 46.101.1.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.1.101.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCcwAAArM"]
[Tue Jul 21 07:21:54.131364 2026] [security2:error] [pid 229246:tid 229425] [client 20.197.192.193:42211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/hp3.php"] [unique_id "al9IQiBMYeh5YLVG45xmKwAAAkU"]
[Tue Jul 21 07:21:54.160985 2026] [security2:error] [pid 230252:tid 230389] [client 64.226.65.160:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.65.226.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCawAAAp4"]
[Tue Jul 21 07:21:54.223751 2026] [security2:error] [pid 230252:tid 230477] [client 74.249.245.134:44059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/css.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCdwAAAvY"]
[Tue Jul 21 07:21:54.241653 2026] [security2:error] [pid 229246:tid 229491] [client 20.197.192.193:42179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/aa1.php"] [unique_id "al9IQiBMYeh5YLVG45xmMAAAAoc"]
[Tue Jul 21 07:21:54.259584 2026] [security2:error] [pid 229246:tid 229479] [client 139.59.132.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.132.59.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQiBMYeh5YLVG45xmMQAAAns"]
[Tue Jul 21 07:21:54.320276 2026] [security2:error] [pid 229246:tid 229432] [client 20.197.192.193:42222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/acew67.php"] [unique_id "al9IQiBMYeh5YLVG45xmMwAAAkw"]
[Tue Jul 21 07:21:54.351435 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.192.193:60461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/bscclapb.php"] [unique_id "al9IQiBMYeh5YLVG45xmNAAAAjI"]
[Tue Jul 21 07:21:54.403000 2026] [http2:warn] [pid 230252:tid 230491] [client 57.141.18.70:52906] h2_stream(230252-241-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:54.403215 2026] [security2:error] [pid 229246:tid 229450] [client 20.197.192.193:42216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/else1.php"] [unique_id "al9IQiBMYeh5YLVG45xmNgAAAl4"]
[Tue Jul 21 07:21:54.432250 2026] [security2:error] [pid 230252:tid 230479] [client 20.197.192.193:48918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/tkikikoko.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCegAAAvg"]
[Tue Jul 21 07:21:54.450792 2026] [security2:error] [pid 230252:tid 230402] [client 20.197.192.193:42207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCewAAAqs"]
[Tue Jul 21 07:21:54.470015 2026] [security2:error] [pid 229246:tid 229472] [client 20.226.60.151:60264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/xwpg.php"] [unique_id "al9IQiBMYeh5YLVG45xmOAAAAnQ"]
[Tue Jul 21 07:21:54.471411 2026] [security2:error] [pid 229246:tid 229434] [client 20.197.192.193:48931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wp-css.php"] [unique_id "al9IQiBMYeh5YLVG45xmOQAAAk4"]
[Tue Jul 21 07:21:54.493289 2026] [security2:error] [pid 230252:tid 230409] [client 20.197.192.193:60437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/wp-explorer.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCfgAAArI"]
[Tue Jul 21 07:21:54.515310 2026] [security2:error] [pid 230252:tid 230442] [client 20.197.192.193:41565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/akismet.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCfwAAAtM"]
[Tue Jul 21 07:21:54.532430 2026] [security2:error] [pid 230252:tid 230459] [client 20.197.192.193:41594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/ace2.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCgAAAAuQ"]
[Tue Jul 21 07:21:54.551758 2026] [security2:error] [pid 230252:tid 230386] [client 20.197.192.193:41576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vinculampe.com.br"] [uri "/ms.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCgQAAAps"]
[Tue Jul 21 07:21:54.596676 2026] [proxy:error] [pid 229246:tid 229492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:54.596742 2026] [proxy_http:error] [pid 229246:tid 229492] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:54.597433 2026] [proxy:error] [pid 229246:tid 229492] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:54.597460 2026] [proxy_http:error] [pid 229246:tid 229492] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:54.676399 2026] [security2:error] [pid 230252:tid 230373] [remote 167.172.232.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.232.172.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCUAAC53Y"]
[Tue Jul 21 07:21:54.776225 2026] [security2:error] [pid 229246:tid 229383] [client 134.19.179.187:34518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IQiBMYeh5YLVG45xmQQAAAhs"]
[Tue Jul 21 07:21:54.776328 2026] [security2:error] [pid 229246:tid 229383] [client 134.19.179.187:34518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IQiBMYeh5YLVG45xmQQAAAhs"]
[Tue Jul 21 07:21:54.845951 2026] [security2:error] [pid 230252:tid 230379] [remote 138.197.191.87:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.191.197.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQU0Dwhk5-Z44XrpCXwAC33w"]
[Tue Jul 21 07:21:55.037486 2026] [proxy:error] [pid 230252:tid 230410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.037577 2026] [proxy_http:error] [pid 230252:tid 230410] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.038465 2026] [proxy:error] [pid 230252:tid 230410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.038513 2026] [proxy_http:error] [pid 230252:tid 230410] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.091759 2026] [proxy:error] [pid 229246:tid 229440] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.091836 2026] [proxy_http:error] [pid 229246:tid 229440] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.092340 2026] [proxy:error] [pid 229246:tid 229440] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.092369 2026] [proxy_http:error] [pid 229246:tid 229440] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.129059 2026] [security2:error] [pid 230252:tid 230511] [client 139.59.136.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.136.59.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQk0Dwhk5-Z44XrpCdgAAAxg"]
[Tue Jul 21 07:21:55.215199 2026] [http2:warn] [pid 230252:tid 230437] [client 57.141.18.107:62350] h2_stream(230252-244-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:55.261917 2026] [proxy:error] [pid 230252:tid 230385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.261984 2026] [proxy_http:error] [pid 230252:tid 230385] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.262648 2026] [proxy:error] [pid 230252:tid 230385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.262677 2026] [proxy_http:error] [pid 230252:tid 230385] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.449061 2026] [security2:error] [pid 229246:tid 229419] [client 20.104.96.117:59161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/jj.php"] [unique_id "al9IQyBMYeh5YLVG45xmUgAAAj8"]
[Tue Jul 21 07:21:55.543173 2026] [security2:error] [pid 230252:tid 230484] [client 74.249.245.134:42870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/php.php"] [unique_id "al9IQ00Dwhk5-Z44XrpClAAAAv0"]
[Tue Jul 21 07:21:55.598595 2026] [proxy:error] [pid 230252:tid 230458] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.598685 2026] [proxy_http:error] [pid 230252:tid 230458] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.600311 2026] [proxy:error] [pid 230252:tid 230458] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:55.600381 2026] [proxy_http:error] [pid 230252:tid 230458] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:55.716524 2026] [security2:error] [pid 230252:tid 230483] [client 103.162.129.114:64168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IQ00Dwhk5-Z44XrpCmAAAAvw"]
[Tue Jul 21 07:21:55.716676 2026] [security2:error] [pid 230252:tid 230483] [client 103.162.129.114:64168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IQ00Dwhk5-Z44XrpCmAAAAvw"]
[Tue Jul 21 07:21:55.724551 2026] [security2:error] [pid 230252:tid 230464] [client 20.226.60.151:60170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ops.php"] [unique_id "al9IQ00Dwhk5-Z44XrpCmgAAAuk"]
[Tue Jul 21 07:21:55.735017 2026] [security2:error] [pid 230252:tid 230492] [client 103.121.156.110:64199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IQ00Dwhk5-Z44XrpCmwAAAwU"]
[Tue Jul 21 07:21:55.735124 2026] [security2:error] [pid 230252:tid 230492] [client 103.121.156.110:64199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IQ00Dwhk5-Z44XrpCmwAAAwU"]
[Tue Jul 21 07:21:55.870430 2026] [security2:error] [pid 229246:tid 229485] [client 142.93.143.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.143.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQyBMYeh5YLVG45xmXQAAAoE"]
[Tue Jul 21 07:21:55.886211 2026] [security2:error] [pid 230252:tid 230399] [client 20.104.96.117:64013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9IQ00Dwhk5-Z44XrpCogAAAqg"]
[Tue Jul 21 07:21:55.940844 2026] [security2:error] [pid 229246:tid 229384] [client 138.68.144.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.144.68.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IQiBMYeh5YLVG45xmQgAAAhw"]
[Tue Jul 21 07:21:56.002272 2026] [proxy:error] [pid 230252:tid 230478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.002346 2026] [proxy_http:error] [pid 230252:tid 230478] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.002797 2026] [proxy:error] [pid 230252:tid 230478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.002840 2026] [proxy_http:error] [pid 230252:tid 230478] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.092018 2026] [proxy:error] [pid 230252:tid 230440] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.092083 2026] [proxy_http:error] [pid 230252:tid 230440] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.092733 2026] [proxy:error] [pid 230252:tid 230440] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.092772 2026] [proxy_http:error] [pid 230252:tid 230440] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.166204 2026] [security2:error] [pid 230252:tid 230402] [client 20.226.60.151:54530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/sixxis.php"] [unique_id "al9IRE0Dwhk5-Z44XrpCqwAAAqs"]
[Tue Jul 21 07:21:56.173464 2026] [http2:warn] [pid 229246:tid 229446] [client 185.89.42.54:49789] h2_stream(229246-433-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:56.262365 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.262439 2026] [proxy_http:error] [pid 230252:tid 230484] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.263213 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.263252 2026] [proxy_http:error] [pid 230252:tid 230484] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.429681 2026] [security2:error] [pid 230252:tid 230338] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IRE0Dwhk5-Z44XrpCtgACm1M"]
[Tue Jul 21 07:21:56.429880 2026] [security2:error] [pid 230252:tid 230386] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9IRE0Dwhk5-Z44XrpCtgACm1M"]
[Tue Jul 21 07:21:56.474383 2026] [http2:warn] [pid 230252:tid 230503] [client 57.141.18.105:58254] h2_stream(230252-247-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:56.597358 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.597443 2026] [proxy_http:error] [pid 230252:tid 230421] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.598850 2026] [proxy:error] [pid 230252:tid 230421] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.598889 2026] [proxy_http:error] [pid 230252:tid 230421] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.622750 2026] [security2:error] [pid 230252:tid 230399] [client 20.226.60.151:60265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/mac.php"] [unique_id "al9IRE0Dwhk5-Z44XrpCugAAAqg"]
[Tue Jul 21 07:21:56.994758 2026] [proxy:error] [pid 230252:tid 230432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.994832 2026] [proxy_http:error] [pid 230252:tid 230432] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:56.995450 2026] [proxy:error] [pid 230252:tid 230432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:56.995473 2026] [proxy_http:error] [pid 230252:tid 230432] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.024546 2026] [security2:error] [pid 230252:tid 230405] [client 74.249.245.134:62509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/aa.php"] [unique_id "al9IRU0Dwhk5-Z44XrpCyQAAAq4"]
[Tue Jul 21 07:21:57.090482 2026] [proxy:error] [pid 230252:tid 230458] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.090549 2026] [proxy_http:error] [pid 230252:tid 230458] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.091200 2026] [proxy:error] [pid 230252:tid 230458] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.091229 2026] [proxy_http:error] [pid 230252:tid 230458] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.115342 2026] [http2:warn] [pid 230252:tid 230469] [client 57.141.18.97:65264] h2_stream(230252-250-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:57.222446 2026] [security2:error] [pid 230252:tid 230483] [client 20.104.96.117:61174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9IRU0Dwhk5-Z44XrpCzQAAAvw"]
[Tue Jul 21 07:21:57.385848 2026] [proxy:error] [pid 230252:tid 230454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.385914 2026] [proxy_http:error] [pid 230252:tid 230454] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.386371 2026] [proxy:error] [pid 230252:tid 230454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.386403 2026] [proxy_http:error] [pid 230252:tid 230454] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.422658 2026] [security2:error] [pid 230252:tid 230443] [client 45.251.232.145:50464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IRU0Dwhk5-Z44XrpC1QAAAtQ"]
[Tue Jul 21 07:21:57.422796 2026] [security2:error] [pid 230252:tid 230443] [client 45.251.232.145:50464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IRU0Dwhk5-Z44XrpC1QAAAtQ"]
[Tue Jul 21 07:21:57.522882 2026] [security2:error] [pid 230252:tid 230455] [client 136.144.33.97:50737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IRU0Dwhk5-Z44XrpC2AAAAuA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:21:57.602758 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.602861 2026] [proxy_http:error] [pid 230252:tid 230456] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.604037 2026] [proxy:error] [pid 230252:tid 230456] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.604097 2026] [proxy_http:error] [pid 230252:tid 230456] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.614892 2026] [security2:error] [pid 229246:tid 229387] [client 20.226.60.151:60177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/mg.php"] [unique_id "al9IRSBMYeh5YLVG45xmfgAAAh8"]
[Tue Jul 21 07:21:57.687393 2026] [security2:error] [pid 230252:tid 230440] [client 20.206.105.145:30600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/file.php"] [unique_id "al9IRU0Dwhk5-Z44XrpC3gAAAtE"]
[Tue Jul 21 07:21:57.771143 2026] [security2:error] [pid 230252:tid 230293] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IRU0Dwhk5-Z44XrpC4AAC9Cc"]
[Tue Jul 21 07:21:57.771326 2026] [security2:error] [pid 230252:tid 230475] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IRU0Dwhk5-Z44XrpC4AAC9Cc"]
[Tue Jul 21 07:21:57.809601 2026] [security2:error] [pid 229246:tid 229388] [client 68.183.180.73:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.180.183.68.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.polianoduarteramos1782482019000.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9IRCBMYeh5YLVG45xmZwAAAiA"]
[Tue Jul 21 07:21:57.998065 2026] [proxy:error] [pid 230252:tid 230416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.998138 2026] [proxy_http:error] [pid 230252:tid 230416] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:57.998701 2026] [proxy:error] [pid 230252:tid 230416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:57.998724 2026] [proxy_http:error] [pid 230252:tid 230416] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:58.011940 2026] [security2:error] [pid 230252:tid 230419] [client 20.226.60.151:60739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/ip.php"] [unique_id "al9IRk0Dwhk5-Z44XrpC6gAAArw"]
[Tue Jul 21 07:21:58.088771 2026] [proxy:error] [pid 230252:tid 230460] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:58.088855 2026] [proxy_http:error] [pid 230252:tid 230460] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:58.089832 2026] [proxy:error] [pid 230252:tid 230460] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:58.089867 2026] [proxy_http:error] [pid 230252:tid 230460] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:58.157011 2026] [security2:error] [pid 230252:tid 230385] [client 14.139.42.196:9421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IRk0Dwhk5-Z44XrpC7wAAApo"]
[Tue Jul 21 07:21:58.157182 2026] [security2:error] [pid 230252:tid 230385] [client 14.139.42.196:9421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IRk0Dwhk5-Z44XrpC7wAAApo"]
[Tue Jul 21 07:21:58.247632 2026] [security2:error] [pid 230252:tid 230430] [client 134.19.179.187:40206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IRk0Dwhk5-Z44XrpC8AAAAsc"]
[Tue Jul 21 07:21:58.247734 2026] [security2:error] [pid 230252:tid 230430] [client 134.19.179.187:40206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IRk0Dwhk5-Z44XrpC8AAAAsc"]
[Tue Jul 21 07:21:58.256061 2026] [proxy:error] [pid 229246:tid 229396] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:58.256142 2026] [proxy_http:error] [pid 229246:tid 229396] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:58.256725 2026] [proxy:error] [pid 229246:tid 229396] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:58.256753 2026] [proxy_http:error] [pid 229246:tid 229396] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:58.275266 2026] [http2:warn] [pid 230252:tid 230494] [client 57.141.18.54:21978] h2_stream(230252-252-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:58.405879 2026] [security2:error] [pid 229246:tid 229503] [client 114.119.159.177:46511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.meuflatnapraia.com.br"] [uri "/image/d235/meu-flat-na-praia-centro-de-porto-de-galinhas-conforto-e-loc-67641776af42c390b5aabfcc"] [unique_id "al9IRiBMYeh5YLVG45xmigAAApM"], referer: https://www.meuflatnapraia.com.br/pt/apartment/MJ01I/a-50m-do-mar-no-centro-de-porto-de-galinhas.
[Tue Jul 21 07:21:58.434045 2026] [security2:error] [pid 229246:tid 229481] [client 20.104.96.117:62943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/k.php"] [unique_id "al9IRiBMYeh5YLVG45xmiwAAAn0"]
[Tue Jul 21 07:21:58.461725 2026] [security2:error] [pid 229246:tid 229489] [client 68.235.38.2:50612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9IRiBMYeh5YLVG45xmjgAAAoU"]
[Tue Jul 21 07:21:58.461829 2026] [security2:error] [pid 229246:tid 229489] [client 68.235.38.2:50612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9IRiBMYeh5YLVG45xmjgAAAoU"]
[Tue Jul 21 07:21:58.603261 2026] [proxy:error] [pid 230252:tid 230506] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:58.603338 2026] [proxy_http:error] [pid 230252:tid 230506] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:58.604245 2026] [proxy:error] [pid 230252:tid 230506] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:58.604292 2026] [proxy_http:error] [pid 230252:tid 230506] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:58.610893 2026] [security2:error] [pid 230252:tid 230493] [client 20.206.105.145:30691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/aa2.php"] [unique_id "al9IRk0Dwhk5-Z44XrpC_QAAAwY"]
[Tue Jul 21 07:21:58.625653 2026] [http2:warn] [pid 229246:tid 229378] [client 57.141.18.7:64074] h2_stream(229246-412-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:58.895904 2026] [security2:error] [pid 230252:tid 230462] [client 74.7.230.56:55276] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lojadoclimatizador.com.br"] [uri "/index.php"] [unique_id "al9IRk0Dwhk5-Z44XrpC7QAC51Q"]
[Tue Jul 21 07:21:59.001926 2026] [proxy:error] [pid 229246:tid 229459] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.002002 2026] [proxy_http:error] [pid 229246:tid 229459] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.002938 2026] [proxy:error] [pid 229246:tid 229459] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.002979 2026] [proxy_http:error] [pid 229246:tid 229459] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.086338 2026] [proxy:error] [pid 230252:tid 230463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.086401 2026] [proxy_http:error] [pid 230252:tid 230463] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.087020 2026] [proxy:error] [pid 230252:tid 230463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.087047 2026] [proxy_http:error] [pid 230252:tid 230463] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.096383 2026] [security2:error] [pid 230252:tid 230399] [client 20.226.60.151:50773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-post-data.php"] [unique_id "al9IR00Dwhk5-Z44XrpDCwAAAqg"]
[Tue Jul 21 07:21:59.149011 2026] [http2:warn] [pid 229246:tid 229458] [client 57.141.18.94:36194] h2_stream(229246-415-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:21:59.199938 2026] [security2:error] [pid 229246:tid 229425] [client 14.237.123.123:61258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.123.237.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giselesaballo.online"] [uri "/xmlrpc.php"] [unique_id "al9IRyBMYeh5YLVG45xmnAAAAkU"]
[Tue Jul 21 07:21:59.200127 2026] [security2:error] [pid 229246:tid 229425] [client 14.237.123.123:61258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giselesaballo.online"] [uri "/xmlrpc.php"] [unique_id "al9IRyBMYeh5YLVG45xmnAAAAkU"]
[Tue Jul 21 07:21:59.367507 2026] [proxy:error] [pid 229246:tid 229472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.367573 2026] [proxy_http:error] [pid 229246:tid 229472] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.368079 2026] [proxy:error] [pid 229246:tid 229472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.368116 2026] [proxy_http:error] [pid 229246:tid 229472] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.439554 2026] [security2:error] [pid 229246:tid 229437] [client 20.206.105.145:30676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/ccou.php"] [unique_id "al9IRyBMYeh5YLVG45xmoQAAAlE"]
[Tue Jul 21 07:21:59.443511 2026] [core:alert] [pid 229246:tid 229477] [client 57.141.18.104:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:21:59.493629 2026] [security2:error] [pid 230252:tid 230359] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IR00Dwhk5-Z44XrpDFwACtWg"]
[Tue Jul 21 07:21:59.493823 2026] [security2:error] [pid 230252:tid 230412] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IR00Dwhk5-Z44XrpDFwACtWg"]
[Tue Jul 21 07:21:59.570069 2026] [security2:error] [pid 229246:tid 229470] [client 68.235.38.2:50620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.38.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9IRyBMYeh5YLVG45xmqgAAAnI"]
[Tue Jul 21 07:21:59.570189 2026] [security2:error] [pid 229246:tid 229470] [client 68.235.38.2:50620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9IRyBMYeh5YLVG45xmqgAAAnI"]
[Tue Jul 21 07:21:59.601557 2026] [proxy:error] [pid 230252:tid 230426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.601623 2026] [proxy_http:error] [pid 230252:tid 230426] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.602243 2026] [proxy:error] [pid 230252:tid 230426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.602271 2026] [proxy_http:error] [pid 230252:tid 230426] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.717406 2026] [security2:error] [pid 230252:tid 230392] [client 20.104.96.117:59167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/txets.php"] [unique_id "al9IR00Dwhk5-Z44XrpDHAAAAqE"]
[Tue Jul 21 07:21:59.747972 2026] [security2:error] [pid 229246:tid 229442] [client 74.249.245.134:21813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/bolt.php"] [unique_id "al9IRyBMYeh5YLVG45xmrwAAAlY"]
[Tue Jul 21 07:21:59.826081 2026] [security2:error] [pid 230252:tid 230476] [client 134.19.179.187:43926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IR00Dwhk5-Z44XrpDHgAAAvU"]
[Tue Jul 21 07:21:59.826193 2026] [security2:error] [pid 230252:tid 230476] [client 134.19.179.187:43926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IR00Dwhk5-Z44XrpDHgAAAvU"]
[Tue Jul 21 07:21:59.944645 2026] [security2:error] [pid 229246:tid 229441] [client 20.226.60.151:54466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/kq1.php"] [unique_id "al9IRyBMYeh5YLVG45xmtQAAAlU"]
[Tue Jul 21 07:21:59.998473 2026] [proxy:error] [pid 229246:tid 229475] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.998559 2026] [proxy_http:error] [pid 229246:tid 229475] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:21:59.999882 2026] [proxy:error] [pid 229246:tid 229475] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:21:59.999940 2026] [proxy_http:error] [pid 229246:tid 229475] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:00.088980 2026] [proxy:error] [pid 229246:tid 229482] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:00.089041 2026] [proxy_http:error] [pid 229246:tid 229482] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:00.089595 2026] [proxy:error] [pid 229246:tid 229482] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:00.089627 2026] [proxy_http:error] [pid 229246:tid 229482] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:00.147273 2026] [security2:error] [pid 230252:tid 230391] [client 20.206.105.145:30650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/dr.php"] [unique_id "al9ISE0Dwhk5-Z44XrpDJwAAAqA"]
[Tue Jul 21 07:22:00.269369 2026] [proxy:error] [pid 230252:tid 230410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:00.269440 2026] [proxy_http:error] [pid 230252:tid 230410] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:00.270124 2026] [proxy:error] [pid 230252:tid 230410] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:00.270173 2026] [proxy_http:error] [pid 230252:tid 230410] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:00.481531 2026] [security2:error] [pid 229246:tid 229489] [client 20.226.60.151:60252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/pucci.php"] [unique_id "al9ISCBMYeh5YLVG45xmvQAAAoU"]
[Tue Jul 21 07:22:00.594679 2026] [security2:error] [pid 229246:tid 229283] [remote 81.173.115.7:44836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9ISCBMYeh5YLVG45xmvwACNCQ"]
[Tue Jul 21 07:22:00.679698 2026] [security2:error] [pid 230252:tid 230411] [client 20.220.225.223:36832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/cro.php"] [unique_id "al9ISE0Dwhk5-Z44XrpDMgAAArQ"]
[Tue Jul 21 07:22:00.707051 2026] [proxy:error] [pid 230252:tid 230493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:00.707114 2026] [proxy_http:error] [pid 230252:tid 230493] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:00.707618 2026] [proxy:error] [pid 230252:tid 230493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:00.707642 2026] [proxy_http:error] [pid 230252:tid 230493] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:00.809101 2026] [security2:error] [pid 229246:tid 229501] [client 20.104.96.117:64042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/blurbs.php"] [unique_id "al9ISCBMYeh5YLVG45xmxwAAApE"]
[Tue Jul 21 07:22:00.842901 2026] [security2:error] [pid 229246:tid 229382] [client 20.220.225.223:34179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/la.php"] [unique_id "al9ISCBMYeh5YLVG45xmyAAAAho"]
[Tue Jul 21 07:22:00.859373 2026] [http2:warn] [pid 230252:tid 230433] [client 57.141.18.61:45498] h2_stream(230252-255-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:01.000880 2026] [security2:error] [pid 230252:tid 230414] [client 74.249.245.134:56989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/x.php"] [unique_id "al9ISU0Dwhk5-Z44XrpDPgAAArc"]
[Tue Jul 21 07:22:01.002087 2026] [proxy:error] [pid 230252:tid 230386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.002177 2026] [proxy_http:error] [pid 230252:tid 230386] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.003451 2026] [proxy:error] [pid 230252:tid 230386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.003493 2026] [proxy_http:error] [pid 230252:tid 230386] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.090970 2026] [proxy:error] [pid 230252:tid 230399] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.091033 2026] [proxy_http:error] [pid 230252:tid 230399] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.091631 2026] [proxy:error] [pid 230252:tid 230399] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.091654 2026] [proxy_http:error] [pid 230252:tid 230399] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.206975 2026] [security2:error] [pid 230252:tid 230344] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISU0Dwhk5-Z44XrpDRgAC9Vk"]
[Tue Jul 21 07:22:01.207116 2026] [security2:error] [pid 230252:tid 230476] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISU0Dwhk5-Z44XrpDRgAC9Vk"]
[Tue Jul 21 07:22:01.260044 2026] [proxy:error] [pid 230252:tid 230504] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.260108 2026] [proxy_http:error] [pid 230252:tid 230504] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.260794 2026] [proxy:error] [pid 230252:tid 230504] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.260831 2026] [proxy_http:error] [pid 230252:tid 230504] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.313260 2026] [security2:error] [pid 229246:tid 229433] [client 103.174.34.15:65235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISSBMYeh5YLVG45xmzQAAAk0"]
[Tue Jul 21 07:22:01.313421 2026] [security2:error] [pid 229246:tid 229433] [client 103.174.34.15:65235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISSBMYeh5YLVG45xmzQAAAk0"]
[Tue Jul 21 07:22:01.402705 2026] [security2:error] [pid 229246:tid 229472] [client 20.104.96.117:59697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/dex.php"] [unique_id "al9ISSBMYeh5YLVG45xmzwAAAnQ"]
[Tue Jul 21 07:22:01.608555 2026] [proxy:error] [pid 229246:tid 229471] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.608633 2026] [proxy_http:error] [pid 229246:tid 229471] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.609483 2026] [proxy:error] [pid 229246:tid 229471] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:01.609535 2026] [proxy_http:error] [pid 229246:tid 229471] [client 134.209.25.199:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:01.772688 2026] [http2:warn] [pid 229246:tid 229426] [client 57.141.18.69:43388] h2_stream(229246-423-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:01.975113 2026] [security2:error] [pid 230252:tid 230308] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISU0Dwhk5-Z44XrpDWgACozY"]
[Tue Jul 21 07:22:01.975321 2026] [security2:error] [pid 230252:tid 230394] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISU0Dwhk5-Z44XrpDWgACozY"]
[Tue Jul 21 07:22:02.019856 2026] [security2:error] [pid 230252:tid 230458] [client 136.144.33.97:48303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9ISk0Dwhk5-Z44XrpDXQAAAuM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:02.020486 2026] [proxy:error] [pid 230252:tid 230480] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:02.020560 2026] [proxy_http:error] [pid 230252:tid 230480] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:02.021505 2026] [proxy:error] [pid 230252:tid 230480] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:02.021541 2026] [proxy_http:error] [pid 230252:tid 230480] [client 64.226.65.160:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:02.182533 2026] [proxy:error] [pid 230252:tid 230449] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:02.182630 2026] [proxy_http:error] [pid 230252:tid 230449] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:02.184199 2026] [proxy:error] [pid 230252:tid 230449] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:02.184254 2026] [proxy_http:error] [pid 230252:tid 230449] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:02.191210 2026] [security2:error] [pid 230252:tid 230368] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9ISk0Dwhk5-Z44XrpDYgACm3E"]
[Tue Jul 21 07:22:02.191416 2026] [security2:error] [pid 230252:tid 230386] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9ISk0Dwhk5-Z44XrpDYgACm3E"]
[Tue Jul 21 07:22:02.267353 2026] [proxy:error] [pid 229246:tid 229442] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:02.267439 2026] [proxy_http:error] [pid 229246:tid 229442] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:02.268824 2026] [proxy:error] [pid 229246:tid 229442] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:02.268876 2026] [proxy_http:error] [pid 229246:tid 229442] [client 139.59.132.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:02.301177 2026] [http2:warn] [pid 230252:tid 230422] [client 57.141.18.101:20786] h2_stream(230252-258-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:02.400118 2026] [security2:error] [pid 230252:tid 230472] [client 20.206.105.145:30663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/file31.php"] [unique_id "al9ISk0Dwhk5-Z44XrpDZgAAAvE"]
[Tue Jul 21 07:22:02.480337 2026] [security2:error] [pid 230252:tid 230430] [client 20.226.60.151:60240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/black.php"] [unique_id "al9ISk0Dwhk5-Z44XrpDZwAAAsc"]
[Tue Jul 21 07:22:02.749025 2026] [security2:error] [pid 229246:tid 229481] [client 20.104.96.117:64061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/bajah.php"] [unique_id "al9ISiBMYeh5YLVG45xm5gAAAn0"]
[Tue Jul 21 07:22:03.079929 2026] [security2:error] [pid 230252:tid 230460] [client 20.104.96.117:59192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/xpwer1.php"] [unique_id "al9IS00Dwhk5-Z44XrpDawAAAuU"]
[Tue Jul 21 07:22:03.293359 2026] [security2:error] [pid 229246:tid 229419] [client 175.45.70.82:54824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISyBMYeh5YLVG45xm6wAAAj8"]
[Tue Jul 21 07:22:03.293462 2026] [security2:error] [pid 229246:tid 229419] [client 175.45.70.82:54824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ISyBMYeh5YLVG45xm6wAAAj8"]
[Tue Jul 21 07:22:03.433257 2026] [security2:error] [pid 229246:tid 229460] [client 20.226.60.151:61057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9ISyBMYeh5YLVG45xm7wAAAmg"]
[Tue Jul 21 07:22:03.461300 2026] [security2:error] [pid 229246:tid 229450] [client 20.104.96.117:64054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/a.php"] [unique_id "al9ISyBMYeh5YLVG45xm8AAAAl4"]
[Tue Jul 21 07:22:03.614348 2026] [http2:warn] [pid 229246:tid 229385] [client 57.141.18.50:24338] h2_stream(229246-424-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:03.894095 2026] [security2:error] [pid 230252:tid 230458] [client 139.135.44.145:53552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IS00Dwhk5-Z44XrpDcwAAAuM"]
[Tue Jul 21 07:22:03.894269 2026] [security2:error] [pid 230252:tid 230458] [client 139.135.44.145:53552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IS00Dwhk5-Z44XrpDcwAAAuM"]
[Tue Jul 21 07:22:03.975537 2026] [security2:error] [pid 229246:tid 229368] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ISyBMYeh5YLVG45xm-wACfHk"]
[Tue Jul 21 07:22:03.975671 2026] [security2:error] [pid 229246:tid 229480] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ISyBMYeh5YLVG45xm-wACfHk"]
[Tue Jul 21 07:22:04.076577 2026] [http2:warn] [pid 230252:tid 230427] [client 57.141.18.17:26292] h2_stream(230252-264-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:04.117903 2026] [security2:error] [pid 229246:tid 229452] [client 20.104.96.117:59706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/flox.php"] [unique_id "al9ITCBMYeh5YLVG45xm_wAAAmA"]
[Tue Jul 21 07:22:04.456828 2026] [security2:error] [pid 230252:tid 230436] [client 92.119.178.3:57712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9ITE0Dwhk5-Z44XrpDdgAAAs0"]
[Tue Jul 21 07:22:04.456929 2026] [security2:error] [pid 230252:tid 230436] [client 92.119.178.3:57712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9ITE0Dwhk5-Z44XrpDdgAAAs0"]
[Tue Jul 21 07:22:04.545012 2026] [security2:error] [pid 229246:tid 229392] [client 20.104.96.117:64033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/edit.php"] [unique_id "al9ITCBMYeh5YLVG45xnBgAAAiQ"]
[Tue Jul 21 07:22:04.547244 2026] [security2:error] [pid 230252:tid 230402] [client 20.220.225.223:47833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/cron-tab.php"] [unique_id "al9ITE0Dwhk5-Z44XrpDdwAAAqs"]
[Tue Jul 21 07:22:04.752142 2026] [security2:error] [pid 229246:tid 229481] [client 20.206.105.145:30643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/file6.php"] [unique_id "al9ITCBMYeh5YLVG45xnCQAAAn0"]
[Tue Jul 21 07:22:04.867365 2026] [security2:error] [pid 230252:tid 230454] [client 134.19.179.187:40214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9ITE0Dwhk5-Z44XrpDeQAAAt8"]
[Tue Jul 21 07:22:04.867475 2026] [security2:error] [pid 230252:tid 230454] [client 134.19.179.187:40214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9ITE0Dwhk5-Z44XrpDeQAAAt8"]
[Tue Jul 21 07:22:04.879927 2026] [security2:error] [pid 229246:tid 229377] [client 20.226.60.151:60275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/zlece.php"] [unique_id "al9ITCBMYeh5YLVG45xnDgAAAhU"]
[Tue Jul 21 07:22:04.998243 2026] [security2:error] [pid 229246:tid 229399] [client 74.249.245.134:15054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/jga.php"] [unique_id "al9ITCBMYeh5YLVG45xnDwAAAis"]
[Tue Jul 21 07:22:05.254042 2026] [http2:warn] [pid 230252:tid 230397] [client 57.141.18.86:27468] h2_stream(230252-269-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:05.355945 2026] [security2:error] [pid 229246:tid 229495] [client 20.104.96.117:61153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/popo.php"] [unique_id "al9ITSBMYeh5YLVG45xnFAAAAos"]
[Tue Jul 21 07:22:05.635322 2026] [security2:error] [pid 229246:tid 229406] [client 173.252.95.7:34466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ITSBMYeh5YLVG45xnFgAAAjI"]
[Tue Jul 21 07:22:05.667637 2026] [security2:error] [pid 229246:tid 229431] [client 20.104.96.117:62914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/hosty.php"] [unique_id "al9ITSBMYeh5YLVG45xnFwAAAks"]
[Tue Jul 21 07:22:05.979181 2026] [http2:warn] [pid 229246:tid 229413] [client 57.141.18.14:27858] h2_stream(229246-430-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:06.055887 2026] [security2:error] [pid 230252:tid 230438] [client 20.104.96.117:59677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/yas.php"] [unique_id "al9ITk0Dwhk5-Z44XrpDhwAAAs8"]
[Tue Jul 21 07:22:06.117524 2026] [security2:error] [pid 229246:tid 229416] [client 20.206.105.145:30609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/file15.php"] [unique_id "al9ITiBMYeh5YLVG45xnHAAAAjw"]
[Tue Jul 21 07:22:06.127486 2026] [security2:error] [pid 229246:tid 229428] [client 20.220.225.223:59467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/koiy.php"] [unique_id "al9ITiBMYeh5YLVG45xnHQAAAkg"]
[Tue Jul 21 07:22:06.342666 2026] [security2:error] [pid 229246:tid 229397] [client 20.226.60.151:61091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/h02ugyh.php"] [unique_id "al9ITiBMYeh5YLVG45xnIAAAAik"]
[Tue Jul 21 07:22:06.366723 2026] [security2:error] [pid 229246:tid 229484] [client 20.220.225.223:34293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9ITiBMYeh5YLVG45xnIQAAAoA"]
[Tue Jul 21 07:22:06.484009 2026] [security2:error] [pid 229246:tid 229479] [client 103.121.156.110:64533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9ITiBMYeh5YLVG45xnIwAAAns"]
[Tue Jul 21 07:22:06.484176 2026] [security2:error] [pid 229246:tid 229479] [client 103.121.156.110:64533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9ITiBMYeh5YLVG45xnIwAAAns"]
[Tue Jul 21 07:22:06.813860 2026] [security2:error] [pid 230252:tid 230418] [client 20.206.105.145:30647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/jp.php"] [unique_id "al9ITk0Dwhk5-Z44XrpDjAAAArs"]
[Tue Jul 21 07:22:06.821298 2026] [security2:error] [pid 230252:tid 230472] [client 20.104.96.117:62933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/k.php"] [unique_id "al9ITk0Dwhk5-Z44XrpDjQAAAvE"]
[Tue Jul 21 07:22:06.858226 2026] [security2:error] [pid 229246:tid 229306] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9ITiBMYeh5YLVG45xnKAACSjs"]
[Tue Jul 21 07:22:06.858394 2026] [security2:error] [pid 229246:tid 229430] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9ITiBMYeh5YLVG45xnKAACSjs"]
[Tue Jul 21 07:22:07.010182 2026] [security2:error] [pid 230252:tid 230393] [client 193.36.225.70:47123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IT00Dwhk5-Z44XrpDjwAAAqI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:07.031419 2026] [security2:error] [pid 229246:tid 229489] [client 74.249.245.134:57007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/k.php"] [unique_id "al9ITyBMYeh5YLVG45xnLQAAAoU"]
[Tue Jul 21 07:22:07.456780 2026] [security2:error] [pid 230252:tid 230419] [client 20.206.105.145:30703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/f35.php"] [unique_id "al9IT00Dwhk5-Z44XrpDkwAAArw"]
[Tue Jul 21 07:22:07.499546 2026] [security2:error] [pid 229246:tid 229345] [remote 188.164.197.230:33430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roha.life"] [uri "/wp-login.php"] [unique_id "al9ITyBMYeh5YLVG45xnMgACfWI"]
[Tue Jul 21 07:22:07.562418 2026] [security2:error] [pid 229246:tid 229252] [remote 119.195.102.159:55212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ITyBMYeh5YLVG45xnNAACOgU"]
[Tue Jul 21 07:22:07.593005 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/file61.php"] [unique_id "al9IT00Dwhk5-Z44XrpDlgAAAuk"]
[Tue Jul 21 07:22:07.667495 2026] [security2:error] [pid 229246:tid 229419] [client 20.104.96.117:64044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/aaa.php"] [unique_id "al9ITyBMYeh5YLVG45xnNwAAAj8"]
[Tue Jul 21 07:22:07.881632 2026] [security2:error] [pid 230252:tid 230508] [client 45.251.232.145:50989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IT00Dwhk5-Z44XrpDlwAAAxU"]
[Tue Jul 21 07:22:07.881826 2026] [security2:error] [pid 230252:tid 230508] [client 45.251.232.145:50989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IT00Dwhk5-Z44XrpDlwAAAxU"]
[Tue Jul 21 07:22:07.984141 2026] [security2:error] [pid 230252:tid 230476] [client 20.206.105.145:30689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-load.php"] [unique_id "al9IT00Dwhk5-Z44XrpDmgAAAvU"]
[Tue Jul 21 07:22:08.104767 2026] [security2:error] [pid 230252:tid 230389] [client 103.162.129.114:64677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IUE0Dwhk5-Z44XrpDmwAAAp4"]
[Tue Jul 21 07:22:08.104929 2026] [security2:error] [pid 230252:tid 230389] [client 103.162.129.114:64677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IUE0Dwhk5-Z44XrpDmwAAAp4"]
[Tue Jul 21 07:22:08.156489 2026] [security2:error] [pid 229246:tid 229431] [client 20.226.60.151:60167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/vssrs.php"] [unique_id "al9IUCBMYeh5YLVG45xnOwAAAks"]
[Tue Jul 21 07:22:08.231041 2026] [security2:error] [pid 229246:tid 229492] [client 20.104.96.117:62912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/file5.php"] [unique_id "al9IUCBMYeh5YLVG45xnPAAAAog"]
[Tue Jul 21 07:22:08.478066 2026] [http2:warn] [pid 229246:tid 229412] [client 57.141.18.43:25632] h2_stream(229246-438-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:08.688583 2026] [security2:error] [pid 230252:tid 230484] [client 20.220.225.223:47836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/hp2.php"] [unique_id "al9IUE0Dwhk5-Z44XrpDoQAAAv0"]
[Tue Jul 21 07:22:08.761084 2026] [security2:error] [pid 229246:tid 229434] [client 20.104.96.117:64058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/222.php"] [unique_id "al9IUCBMYeh5YLVG45xnQAAAAk4"]
[Tue Jul 21 07:22:08.815471 2026] [security2:error] [pid 229246:tid 229397] [client 20.226.60.151:60286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wicked.php"] [unique_id "al9IUCBMYeh5YLVG45xnQgAAAik"]
[Tue Jul 21 07:22:08.924497 2026] [security2:error] [pid 229246:tid 229499] [client 14.139.42.196:17998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IUCBMYeh5YLVG45xnRAAAAo8"]
[Tue Jul 21 07:22:08.924610 2026] [security2:error] [pid 229246:tid 229499] [client 14.139.42.196:17998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IUCBMYeh5YLVG45xnRAAAAo8"]
[Tue Jul 21 07:22:09.041146 2026] [security2:error] [pid 230252:tid 230387] [client 20.206.105.145:30636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9IUU0Dwhk5-Z44XrpDpQAAApw"]
[Tue Jul 21 07:22:09.072683 2026] [http2:warn] [pid 230252:tid 230470] [client 57.141.18.63:60854] h2_stream(230252-282-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:09.178856 2026] [rewrite:error] [pid 229246:tid 229400] [client 57.141.18.104:0] AH10411: Rewritten query string contains control characters or spaces
[Tue Jul 21 07:22:09.395503 2026] [security2:error] [pid 229246:tid 229465] [client 20.104.96.117:59165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/water.php"] [unique_id "al9IUSBMYeh5YLVG45xnTgAAAm0"]
[Tue Jul 21 07:22:09.397218 2026] [security2:error] [pid 229246:tid 229425] [client 74.249.245.134:58074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/vx.php"] [unique_id "al9IUSBMYeh5YLVG45xnTwAAAkU"]
[Tue Jul 21 07:22:09.409356 2026] [security2:error] [pid 229246:tid 229480] [client 20.226.60.151:60174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/24.php"] [unique_id "al9IUSBMYeh5YLVG45xnUQAAAnw"]
[Tue Jul 21 07:22:09.471673 2026] [security2:error] [pid 230252:tid 230399] [client 20.104.96.117:62913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/test.php"] [unique_id "al9IUU0Dwhk5-Z44XrpDpwAAAqg"]
[Tue Jul 21 07:22:09.904531 2026] [http2:warn] [pid 230252:tid 230396] [client 57.141.18.82:48686] h2_stream(230252-287-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:09.941861 2026] [security2:error] [pid 229246:tid 229399] [client 20.220.225.223:36804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/hp3.php"] [unique_id "al9IUSBMYeh5YLVG45xnWQAAAis"]
[Tue Jul 21 07:22:10.114427 2026] [security2:error] [pid 230252:tid 230494] [client 20.206.105.145:30593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wp-links.php"] [unique_id "al9IUk0Dwhk5-Z44XrpDqwAAAwc"]
[Tue Jul 21 07:22:10.156721 2026] [security2:error] [pid 229246:tid 229324] [remote 185.22.228.25:33540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.228.22.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9IUSBMYeh5YLVG45xnSQACXU0"]
[Tue Jul 21 07:22:10.277022 2026] [security2:error] [pid 229246:tid 229299] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IUiBMYeh5YLVG45xnYAACfjQ"]
[Tue Jul 21 07:22:10.277206 2026] [security2:error] [pid 229246:tid 229482] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IUiBMYeh5YLVG45xnYAACfjQ"]
[Tue Jul 21 07:22:10.370367 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:59142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/nano.php"] [unique_id "al9IUk0Dwhk5-Z44XrpDsQAAAuk"]
[Tue Jul 21 07:22:10.616459 2026] [security2:error] [pid 229246:tid 229433] [client 20.104.96.117:62953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/aaa.php"] [unique_id "al9IUiBMYeh5YLVG45xnaAAAAk0"]
[Tue Jul 21 07:22:10.828585 2026] [security2:error] [pid 230252:tid 230391] [client 20.104.96.117:59691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/moon.php"] [unique_id "al9IUk0Dwhk5-Z44XrpDuQAAAqA"]
[Tue Jul 21 07:22:10.878096 2026] [http2:warn] [pid 230252:tid 230407] [client 57.141.18.24:46376] h2_stream(230252-291-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:11.075025 2026] [security2:error] [pid 229246:tid 229477] [client 20.206.105.145:30656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/solo1.php"] [unique_id "al9IUyBMYeh5YLVG45xnbgAAAnk"]
[Tue Jul 21 07:22:11.120966 2026] [security2:error] [pid 229246:tid 229457] [client 74.249.245.134:56997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ws77.php"] [unique_id "al9IUyBMYeh5YLVG45xnbwAAAmU"]
[Tue Jul 21 07:22:11.140225 2026] [security2:error] [pid 230252:tid 230273] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9IUk0Dwhk5-Z44XrpDugACmxM"]
[Tue Jul 21 07:22:11.490416 2026] [security2:error] [pid 229246:tid 229337] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IUyBMYeh5YLVG45xncgACj1o"]
[Tue Jul 21 07:22:11.490549 2026] [security2:error] [pid 229246:tid 229499] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IUyBMYeh5YLVG45xncgACj1o"]
[Tue Jul 21 07:22:11.502628 2026] [security2:error] [pid 230252:tid 230418] [client 20.104.96.117:64045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/11.php"] [unique_id "al9IU00Dwhk5-Z44XrpDvgAAArs"]
[Tue Jul 21 07:22:11.528248 2026] [security2:error] [pid 229246:tid 229367] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/"] [unique_id "al9IUyBMYeh5YLVG45xncwACcng"]
[Tue Jul 21 07:22:11.579518 2026] [http2:warn] [pid 230252:tid 230434] [client 57.141.18.47:23726] h2_stream(230252-292-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:11.739848 2026] [security2:error] [pid 230252:tid 230465] [client 20.206.105.145:30606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/sixxis.php"] [unique_id "al9IU00Dwhk5-Z44XrpDwAAAAuo"]
[Tue Jul 21 07:22:11.760933 2026] [security2:error] [pid 230252:tid 230346] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IU00Dwhk5-Z44XrpDwQACqFs"]
[Tue Jul 21 07:22:11.761120 2026] [security2:error] [pid 230252:tid 230399] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IU00Dwhk5-Z44XrpDwQACqFs"]
[Tue Jul 21 07:22:11.879273 2026] [security2:error] [pid 230252:tid 230500] [client 20.104.96.117:64023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/mac.php"] [unique_id "al9IU00Dwhk5-Z44XrpDxAAAAw0"]
[Tue Jul 21 07:22:11.928586 2026] [security2:error] [pid 230252:tid 230340] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9IU00Dwhk5-Z44XrpDxQAColU"]
[Tue Jul 21 07:22:12.020544 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-info.php"] [unique_id "al9IVE0Dwhk5-Z44XrpDxwAAAtM"]
[Tue Jul 21 07:22:12.068332 2026] [security2:error] [pid 230252:tid 230384] [client 103.174.34.15:49308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IVE0Dwhk5-Z44XrpDyAAAApk"]
[Tue Jul 21 07:22:12.068468 2026] [security2:error] [pid 230252:tid 230384] [client 103.174.34.15:49308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IVE0Dwhk5-Z44XrpDyAAAApk"]
[Tue Jul 21 07:22:12.068938 2026] [security2:error] [pid 230252:tid 230463] [client 20.220.225.223:36856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/aa1.php"] [unique_id "al9IVE0Dwhk5-Z44XrpDyQAAAug"]
[Tue Jul 21 07:22:12.091467 2026] [security2:error] [pid 229246:tid 229417] [client 20.226.60.151:60257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/xacs.php"] [unique_id "al9IVCBMYeh5YLVG45xnewAAAj0"]
[Tue Jul 21 07:22:12.165113 2026] [security2:error] [pid 229246:tid 229418] [client 20.206.105.145:30542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/2P.update.php"] [unique_id "al9IVCBMYeh5YLVG45xngAAAAj4"]
[Tue Jul 21 07:22:12.191072 2026] [security2:error] [pid 230252:tid 230419] [client 74.249.245.134:50036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/2.php"] [unique_id "al9IVE0Dwhk5-Z44XrpDywAAArw"]
[Tue Jul 21 07:22:12.209485 2026] [http2:warn] [pid 229246:tid 229469] [client 57.141.18.37:55552] h2_stream(229246-445-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:12.321671 2026] [security2:error] [pid 230252:tid 230327] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/"] [unique_id "al9IVE0Dwhk5-Z44XrpDzQACrEg"]
[Tue Jul 21 07:22:12.360216 2026] [security2:error] [pid 230252:tid 230487] [client 20.104.96.117:62931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/chosen.php"] [unique_id "al9IVE0Dwhk5-Z44XrpDzgAAAwA"]
[Tue Jul 21 07:22:12.484400 2026] [security2:error] [pid 230252:tid 230323] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9IVE0Dwhk5-Z44XrpD0wAC9UU"]
[Tue Jul 21 07:22:12.520723 2026] [security2:error] [pid 229246:tid 229311] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IVCBMYeh5YLVG45xnggACk0A"]
[Tue Jul 21 07:22:12.520926 2026] [security2:error] [pid 229246:tid 229503] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IVCBMYeh5YLVG45xnggACk0A"]
[Tue Jul 21 07:22:12.768997 2026] [security2:error] [pid 229246:tid 229414] [client 134.19.179.187:51706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9IVCBMYeh5YLVG45xniAAAAjo"]
[Tue Jul 21 07:22:12.769482 2026] [security2:error] [pid 229246:tid 229414] [client 134.19.179.187:51706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9IVCBMYeh5YLVG45xniAAAAjo"]
[Tue Jul 21 07:22:12.798687 2026] [security2:error] [pid 230252:tid 230354] [remote 205.196.217.58:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.217.196.205.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9IU00Dwhk5-Z44XrpDwgAC4WM"]
[Tue Jul 21 07:22:12.802535 2026] [security2:error] [pid 230252:tid 230481] [client 20.220.225.223:47809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/acew67.php"] [unique_id "al9IVE0Dwhk5-Z44XrpD2AAAAvo"]
[Tue Jul 21 07:22:12.867668 2026] [security2:error] [pid 229246:tid 229424] [client 20.206.105.145:30579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/a.php"] [unique_id "al9IVCBMYeh5YLVG45xnigAAAkQ"]
[Tue Jul 21 07:22:12.876199 2026] [security2:error] [pid 230252:tid 230348] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/"] [unique_id "al9IVE0Dwhk5-Z44XrpD2gACoF0"]
[Tue Jul 21 07:22:12.958187 2026] [security2:error] [pid 229246:tid 229352] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IVCBMYeh5YLVG45xniwACNGk"]
[Tue Jul 21 07:22:12.958350 2026] [security2:error] [pid 229246:tid 229408] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IVCBMYeh5YLVG45xniwACNGk"]
[Tue Jul 21 07:22:12.985747 2026] [security2:error] [pid 230252:tid 230386] [client 20.104.96.117:62938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/cream1.php"] [unique_id "al9IVE0Dwhk5-Z44XrpD2wAAAps"]
[Tue Jul 21 07:22:12.999908 2026] [security2:error] [pid 230252:tid 230436] [client 193.36.225.60:64557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IVE0Dwhk5-Z44XrpD2QAAAs0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:13.130469 2026] [security2:error] [pid 230252:tid 230443] [client 20.104.96.117:61157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/2000.php"] [unique_id "al9IVU0Dwhk5-Z44XrpD3AAAAtQ"]
[Tue Jul 21 07:22:13.269577 2026] [security2:error] [pid 230252:tid 230338] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9IVU0Dwhk5-Z44XrpD3wAC8VM"]
[Tue Jul 21 07:22:13.412636 2026] [security2:error] [pid 230252:tid 230451] [client 20.206.105.145:30537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/k.php"] [unique_id "al9IVU0Dwhk5-Z44XrpD4QAAAtw"]
[Tue Jul 21 07:22:13.668704 2026] [security2:error] [pid 230252:tid 230301] [remote 47.90.200.158:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/"] [unique_id "al9IVU0Dwhk5-Z44XrpD5AAC9i8"]
[Tue Jul 21 07:22:13.711545 2026] [security2:error] [pid 229246:tid 229453] [client 20.226.60.151:54550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-temp.php"] [unique_id "al9IVSBMYeh5YLVG45xnlwAAAmE"]
[Tue Jul 21 07:22:13.744274 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:13.744347 2026] [proxy_http:error] [pid 230252:tid 230437] [client 20.104.96.117:4162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:13.745109 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:13.745151 2026] [proxy_http:error] [pid 230252:tid 230437] [client 20.104.96.117:4162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:13.789730 2026] [security2:error] [pid 230252:tid 230499] [client 20.206.105.145:30491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/w.php"] [unique_id "al9IVU0Dwhk5-Z44XrpD6QAAAww"]
[Tue Jul 21 07:22:13.831646 2026] [security2:error] [pid 229246:tid 229277] [remote 114.34.90.9:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9IVSBMYeh5YLVG45xnmQACaB4"]
[Tue Jul 21 07:22:14.010190 2026] [http2:warn] [pid 229246:tid 229455] [client 57.141.18.54:40292] h2_stream(229246-451-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:14.132721 2026] [security2:error] [pid 230252:tid 230450] [client 175.45.70.82:55335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD7gAAAts"]
[Tue Jul 21 07:22:14.132898 2026] [security2:error] [pid 230252:tid 230450] [client 175.45.70.82:55335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD7gAAAts"]
[Tue Jul 21 07:22:14.170760 2026] [security2:error] [pid 230252:tid 230483] [client 74.249.245.134:15089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/asd.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD8AAAAvw"]
[Tue Jul 21 07:22:14.179060 2026] [autoindex:error] [pid 230252:tid 230469] [client 35.196.36.160:52583] AH01276: Cannot serve directory /home1/ofic8899/prime-website.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:22:14.235950 2026] [security2:error] [pid 230252:tid 230395] [client 20.206.105.145:30628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/insc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD8wAAAqQ"]
[Tue Jul 21 07:22:14.294998 2026] [security2:error] [pid 229246:tid 229389] [client 74.7.175.184:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "brasilcertdigital.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9IViBMYeh5YLVG45xnnwAAAiE"]
[Tue Jul 21 07:22:14.296931 2026] [security2:error] [pid 229246:tid 229502] [client 74.7.175.184:52144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "brasilcertdigital.com.br"] [uri "/robots.txt"] [unique_id "al9IViBMYeh5YLVG45xnngACklA"]
[Tue Jul 21 07:22:14.506942 2026] [security2:error] [pid 229246:tid 229390] [client 20.197.192.193:53139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IViBMYeh5YLVG45xnowAAAiI"]
[Tue Jul 21 07:22:14.598654 2026] [security2:error] [pid 230252:tid 230440] [client 20.206.105.145:30488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD-gAAAtE"]
[Tue Jul 21 07:22:14.626922 2026] [security2:error] [pid 230252:tid 230272] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD-wADEBI"]
[Tue Jul 21 07:22:14.627098 2026] [security2:error] [pid 230252:tid 230503] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD-wADEBI"]
[Tue Jul 21 07:22:14.662920 2026] [http2:warn] [pid 229246:tid 229445] [client 57.141.18.26:39468] h2_stream(229246-454-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:14.670330 2026] [security2:error] [pid 230252:tid 230387] [client 35.196.36.160:52583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.36.196.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD_AAAApw"]
[Tue Jul 21 07:22:14.673469 2026] [proxy:error] [pid 230252:tid 230420] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:14.673541 2026] [proxy_http:error] [pid 230252:tid 230420] [client 20.104.96.117:64063] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:14.674222 2026] [proxy:error] [pid 230252:tid 230420] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:14.674258 2026] [proxy_http:error] [pid 230252:tid 230420] [client 20.104.96.117:64063] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:14.722025 2026] [security2:error] [pid 230252:tid 230506] [client 20.104.96.117:61170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/122.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD_gAAAxM"]
[Tue Jul 21 07:22:14.724385 2026] [security2:error] [pid 230252:tid 230459] [client 139.135.44.145:54396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD_wAAAuQ"]
[Tue Jul 21 07:22:14.725348 2026] [security2:error] [pid 230252:tid 230459] [client 139.135.44.145:54396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IVk0Dwhk5-Z44XrpD_wAAAuQ"]
[Tue Jul 21 07:22:14.856570 2026] [security2:error] [pid 229246:tid 229387] [client 74.7.175.184:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "brasilcertdigital.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9IViBMYeh5YLVG45xnqAAAAh8"]
[Tue Jul 21 07:22:14.857009 2026] [security2:error] [pid 229246:tid 229421] [client 74.7.175.184:40486] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "brasilcertdigital.com.br"] [uri "/robots.txt"] [unique_id "al9IViBMYeh5YLVG45xnpwAAAkE"]
[Tue Jul 21 07:22:14.921472 2026] [security2:error] [pid 230252:tid 230442] [client 20.206.105.145:30688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/u.php"] [unique_id "al9IVk0Dwhk5-Z44XrpEAgAAAtM"]
[Tue Jul 21 07:22:15.086951 2026] [security2:error] [pid 229246:tid 229440] [client 35.196.36.160:52212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9IVyBMYeh5YLVG45xnrgAAAlQ"]
[Tue Jul 21 07:22:15.092971 2026] [security2:error] [pid 230252:tid 230477] [client 20.206.105.145:30539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/sss.php"] [unique_id "al9IV00Dwhk5-Z44XrpEBAAAAvY"]
[Tue Jul 21 07:22:15.099208 2026] [security2:error] [pid 230252:tid 230493] [client 92.119.178.3:51896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9IV00Dwhk5-Z44XrpEBQAAAwY"]
[Tue Jul 21 07:22:15.099284 2026] [security2:error] [pid 230252:tid 230493] [client 92.119.178.3:51896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9IV00Dwhk5-Z44XrpEBQAAAwY"]
[Tue Jul 21 07:22:15.435570 2026] [security2:error] [pid 229246:tid 229489] [client 35.196.36.160:63060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9IVyBMYeh5YLVG45xntAAAAoU"]
[Tue Jul 21 07:22:15.449667 2026] [security2:error] [pid 229246:tid 229474] [client 74.249.245.134:49716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/default.php"] [unique_id "al9IVyBMYeh5YLVG45xntQAAAnY"]
[Tue Jul 21 07:22:15.486722 2026] [security2:error] [pid 230252:tid 230438] [client 20.206.105.145:30679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/sss.php"] [unique_id "al9IV00Dwhk5-Z44XrpEBwAAAs8"]
[Tue Jul 21 07:22:15.533658 2026] [security2:error] [pid 229246:tid 229429] [client 20.226.60.151:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/zildan.php"] [unique_id "al9IVyBMYeh5YLVG45xntwAAAkk"]
[Tue Jul 21 07:22:15.683827 2026] [security2:error] [pid 229246:tid 229424] [client 20.104.96.117:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/dr.php"] [unique_id "al9IVyBMYeh5YLVG45xnugAAAkQ"]
[Tue Jul 21 07:22:15.845693 2026] [security2:error] [pid 229246:tid 229419] [client 20.226.60.151:60175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/csa.php"] [unique_id "al9IVyBMYeh5YLVG45xnvwAAAj8"]
[Tue Jul 21 07:22:15.881900 2026] [security2:error] [pid 229246:tid 229385] [client 35.196.36.160:64599] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9IVyBMYeh5YLVG45xnwAAAAh0"]
[Tue Jul 21 07:22:15.886184 2026] [security2:error] [pid 229246:tid 229451] [client 20.226.60.151:60268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/w3llscc.php"] [unique_id "al9IVyBMYeh5YLVG45xnwQAAAl8"]
[Tue Jul 21 07:22:15.977702 2026] [security2:error] [pid 230252:tid 230480] [client 20.104.96.117:59198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/mds.php"] [unique_id "al9IV00Dwhk5-Z44XrpECwAAAvk"]
[Tue Jul 21 07:22:15.979832 2026] [security2:error] [pid 229246:tid 229411] [client 20.151.10.161:26428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IVyBMYeh5YLVG45xnwgAAAjc"]
[Tue Jul 21 07:22:16.000025 2026] [security2:error] [pid 230252:tid 230389] [client 20.206.105.145:30607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/c.php"] [unique_id "al9IV00Dwhk5-Z44XrpEDAAAAp4"]
[Tue Jul 21 07:22:16.130242 2026] [security2:error] [pid 230252:tid 230450] [client 20.226.60.151:60213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wpx.php"] [unique_id "al9IWE0Dwhk5-Z44XrpEDQAAAts"]
[Tue Jul 21 07:22:16.153780 2026] [security2:error] [pid 229246:tid 229467] [client 173.252.95.31:49170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9IWCBMYeh5YLVG45xnxQAAAm8"]
[Tue Jul 21 07:22:16.155304 2026] [http2:warn] [pid 230252:tid 230466] [client 57.141.18.77:62232] h2_stream(230252-297-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:16.295237 2026] [security2:error] [pid 230252:tid 230458] [client 35.196.36.160:63062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9IWE0Dwhk5-Z44XrpEDwAAAuM"]
[Tue Jul 21 07:22:16.331742 2026] [security2:error] [pid 229246:tid 229383] [client 20.197.192.193:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IWCBMYeh5YLVG45xnyQAAAhs"]
[Tue Jul 21 07:22:16.514589 2026] [security2:error] [pid 229246:tid 229397] [client 20.151.10.161:26429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IWCBMYeh5YLVG45xnzAAAAik"]
[Tue Jul 21 07:22:16.545609 2026] [security2:error] [pid 229246:tid 229434] [client 20.104.96.117:62947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/x.php"] [unique_id "al9IWCBMYeh5YLVG45xnzQAAAk4"]
[Tue Jul 21 07:22:16.705616 2026] [security2:error] [pid 230252:tid 230457] [client 35.196.36.160:56399] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9IWE0Dwhk5-Z44XrpEEwAAAuI"]
[Tue Jul 21 07:22:16.738514 2026] [security2:error] [pid 229246:tid 229462] [client 20.220.225.223:34251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/inso.php"] [unique_id "al9IWCBMYeh5YLVG45xnzwAAAmo"]
[Tue Jul 21 07:22:16.829276 2026] [security2:error] [pid 229246:tid 229470] [client 20.206.105.145:30693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/aa.php"] [unique_id "al9IWCBMYeh5YLVG45xn0wAAAnI"]
[Tue Jul 21 07:22:16.925403 2026] [security2:error] [pid 229246:tid 229421] [client 20.151.10.161:26420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/x.php"] [unique_id "al9IWCBMYeh5YLVG45xn1QAAAkE"]
[Tue Jul 21 07:22:16.980109 2026] [security2:error] [pid 229246:tid 229409] [client 74.249.245.134:56987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/gettest.php"] [unique_id "al9IWCBMYeh5YLVG45xn1gAAAjU"]
[Tue Jul 21 07:22:16.987596 2026] [security2:error] [pid 230252:tid 230472] [client 35.196.36.160:51534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9IWE0Dwhk5-Z44XrpEFgAAAvE"]
[Tue Jul 21 07:22:17.098922 2026] [security2:error] [pid 230252:tid 230503] [client 20.220.225.223:59472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/bscclapb.php"] [unique_id "al9IWU0Dwhk5-Z44XrpEFwAAAxA"]
[Tue Jul 21 07:22:17.214626 2026] [security2:error] [pid 229246:tid 229457] [client 103.121.156.110:64863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IWSBMYeh5YLVG45xn1wAAAmU"]
[Tue Jul 21 07:22:17.214764 2026] [security2:error] [pid 229246:tid 229457] [client 103.121.156.110:64863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IWSBMYeh5YLVG45xn1wAAAmU"]
[Tue Jul 21 07:22:17.445717 2026] [security2:error] [pid 229246:tid 229452] [client 35.196.36.160:60802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9IWSBMYeh5YLVG45xn3QAAAmA"]
[Tue Jul 21 07:22:17.482979 2026] [security2:error] [pid 230252:tid 230486] [client 20.151.10.161:26403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/j260624_13.php"] [unique_id "al9IWU0Dwhk5-Z44XrpEGwAAAv8"]
[Tue Jul 21 07:22:17.610634 2026] [security2:error] [pid 230252:tid 230499] [client 20.226.60.151:60198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-css.php"] [unique_id "al9IWU0Dwhk5-Z44XrpEHQAAAww"]
[Tue Jul 21 07:22:17.616303 2026] [security2:error] [pid 230252:tid 230454] [client 20.104.96.117:62924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/155.php"] [unique_id "al9IWU0Dwhk5-Z44XrpEHgAAAt8"]
[Tue Jul 21 07:22:17.725162 2026] [http2:warn] [pid 229246:tid 229379] [client 57.141.18.1:36848] h2_stream(229246-464-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:17.725237 2026] [security2:error] [pid 229246:tid 229491] [client 20.206.105.145:30653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/100.php"] [unique_id "al9IWSBMYeh5YLVG45xn4AAAAoc"]
[Tue Jul 21 07:22:17.740443 2026] [security2:error] [pid 230252:tid 230432] [client 35.196.36.160:52585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9IWU0Dwhk5-Z44XrpEIwAAAsk"]
[Tue Jul 21 07:22:18.125046 2026] [security2:error] [pid 229246:tid 229435] [client 35.196.36.160:65426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9IWiBMYeh5YLVG45xn5wAAAk8"]
[Tue Jul 21 07:22:18.173893 2026] [security2:error] [pid 229246:tid 229450] [client 20.104.96.117:61104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-blink.php"] [unique_id "al9IWiBMYeh5YLVG45xn6AAAAl4"]
[Tue Jul 21 07:22:18.207726 2026] [security2:error] [pid 229246:tid 229408] [client 20.226.60.151:50783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ho.php"] [unique_id "al9IWiBMYeh5YLVG45xn6QAAAjQ"]
[Tue Jul 21 07:22:18.338871 2026] [security2:error] [pid 230252:tid 230278] [remote 188.95.113.76:40794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9IWk0Dwhk5-Z44XrpEJwAC-hg"]
[Tue Jul 21 07:22:18.339069 2026] [security2:error] [pid 230252:tid 230481] [client 188.95.113.76:40794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9IWk0Dwhk5-Z44XrpEJwAC-hg"]
[Tue Jul 21 07:22:18.349069 2026] [security2:error] [pid 230252:tid 230467] [client 20.151.10.161:26416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/d62.php"] [unique_id "al9IWk0Dwhk5-Z44XrpEKAAAAuw"]
[Tue Jul 21 07:22:18.353670 2026] [security2:error] [pid 230252:tid 230422] [client 45.251.232.145:51513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IWk0Dwhk5-Z44XrpEKQAAAr8"]
[Tue Jul 21 07:22:18.353891 2026] [security2:error] [pid 230252:tid 230422] [client 45.251.232.145:51513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IWk0Dwhk5-Z44XrpEKQAAAr8"]
[Tue Jul 21 07:22:18.434371 2026] [security2:error] [pid 230252:tid 230504] [client 35.196.36.160:57798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9IWk0Dwhk5-Z44XrpEKgAAAxE"]
[Tue Jul 21 07:22:18.474424 2026] [security2:error] [pid 229246:tid 229437] [client 136.144.33.110:53435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IWiBMYeh5YLVG45xn7QAAAlE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:18.528641 2026] [security2:error] [pid 229246:tid 229406] [client 20.104.96.117:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ops.php"] [unique_id "al9IWiBMYeh5YLVG45xn7wAAAjI"]
[Tue Jul 21 07:22:18.543213 2026] [security2:error] [pid 229246:tid 229391] [client 74.249.245.134:61845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/tfm.php"] [unique_id "al9IWiBMYeh5YLVG45xn8AAAAiM"]
[Tue Jul 21 07:22:18.669236 2026] [security2:error] [pid 230252:tid 230387] [client 20.206.105.145:30623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/footer.php"] [unique_id "al9IWk0Dwhk5-Z44XrpELQAAApw"]
[Tue Jul 21 07:22:18.699608 2026] [security2:error] [pid 230252:tid 230459] [client 35.196.36.160:49391] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9IWk0Dwhk5-Z44XrpELgAAAuQ"]
[Tue Jul 21 07:22:18.867617 2026] [security2:error] [pid 229246:tid 229389] [client 20.206.105.145:30605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/users.php"] [unique_id "al9IWiBMYeh5YLVG45xn9gAAAiE"]
[Tue Jul 21 07:22:18.906227 2026] [security2:error] [pid 230252:tid 230384] [client 20.226.60.151:60186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/xy.php"] [unique_id "al9IWk0Dwhk5-Z44XrpEMAAAApk"]
[Tue Jul 21 07:22:18.980555 2026] [security2:error] [pid 229246:tid 229492] [client 20.226.60.151:54504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9IWiBMYeh5YLVG45xn9wAAAog"]
[Tue Jul 21 07:22:19.054778 2026] [security2:error] [pid 229246:tid 229428] [client 35.196.36.160:51111] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "prime-website.com.oficialwebsite.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9IWyBMYeh5YLVG45xn-wAAAkg"]
[Tue Jul 21 07:22:19.156055 2026] [http2:warn] [pid 229246:tid 229405] [client 57.141.18.38:48942] h2_stream(229246-466-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:19.290159 2026] [security2:error] [pid 230252:tid 230385] [client 20.197.192.193:53152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/wander.php"] [unique_id "al9IW00Dwhk5-Z44XrpENAAAApo"]
[Tue Jul 21 07:22:19.324301 2026] [security2:error] [pid 230252:tid 230503] [client 103.162.129.114:65188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IW00Dwhk5-Z44XrpENQAAAxA"]
[Tue Jul 21 07:22:19.324420 2026] [security2:error] [pid 230252:tid 230503] [client 103.162.129.114:65188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IW00Dwhk5-Z44XrpENQAAAxA"]
[Tue Jul 21 07:22:19.336805 2026] [security2:error] [pid 230252:tid 230453] [client 20.206.105.145:30547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/177.php"] [unique_id "al9IW00Dwhk5-Z44XrpENgAAAt4"]
[Tue Jul 21 07:22:19.506612 2026] [security2:error] [pid 230252:tid 230442] [client 74.249.245.134:62535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ws81.php"] [unique_id "al9IW00Dwhk5-Z44XrpENwAAAtM"]
[Tue Jul 21 07:22:19.581025 2026] [security2:error] [pid 229246:tid 229390] [client 14.139.42.196:28037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IWyBMYeh5YLVG45xoAgAAAiI"]
[Tue Jul 21 07:22:19.581223 2026] [security2:error] [pid 229246:tid 229390] [client 14.139.42.196:28037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IWyBMYeh5YLVG45xoAgAAAiI"]
[Tue Jul 21 07:22:19.712279 2026] [security2:error] [pid 229246:tid 229430] [client 20.151.10.161:26401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ups.php"] [unique_id "al9IWyBMYeh5YLVG45xoBQAAAko"]
[Tue Jul 21 07:22:19.787516 2026] [security2:error] [pid 229246:tid 229409] [client 20.104.96.117:5100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/file31.php"] [unique_id "al9IWyBMYeh5YLVG45xoBgAAAjU"]
[Tue Jul 21 07:22:19.820933 2026] [security2:error] [pid 230252:tid 230395] [client 134.19.179.187:40028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.179.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IW00Dwhk5-Z44XrpEOAAAAqQ"]
[Tue Jul 21 07:22:19.821019 2026] [security2:error] [pid 230252:tid 230395] [client 134.19.179.187:40028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IW00Dwhk5-Z44XrpEOAAAAqQ"]
[Tue Jul 21 07:22:19.909482 2026] [security2:error] [pid 229246:tid 229499] [client 20.226.60.151:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/loader.php"] [unique_id "al9IWyBMYeh5YLVG45xoBwAAAo8"]
[Tue Jul 21 07:22:20.112416 2026] [security2:error] [pid 229246:tid 229398] [client 20.104.96.117:59162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/zc-208.php"] [unique_id "al9IXCBMYeh5YLVG45xoDAAAAio"]
[Tue Jul 21 07:22:20.143718 2026] [http2:warn] [pid 229246:tid 229422] [client 57.141.18.31:46178] h2_stream(229246-467-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:20.202670 2026] [security2:error] [pid 230252:tid 230456] [client 20.206.105.145:30637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/config.php"] [unique_id "al9IXE0Dwhk5-Z44XrpEOwAAAuE"]
[Tue Jul 21 07:22:20.214137 2026] [security2:error] [pid 230252:tid 230423] [client 20.220.225.223:34246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wpx.php"] [unique_id "al9IXE0Dwhk5-Z44XrpEPAAAAsA"]
[Tue Jul 21 07:22:20.427704 2026] [security2:error] [pid 230252:tid 230422] [client 20.151.10.161:26417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/k.php"] [unique_id "al9IXE0Dwhk5-Z44XrpEPgAAAr8"]
[Tue Jul 21 07:22:20.624938 2026] [security2:error] [pid 229246:tid 229388] [client 20.197.192.193:53154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/jga.php"] [unique_id "al9IXCBMYeh5YLVG45xoFQAAAiA"]
[Tue Jul 21 07:22:20.893212 2026] [autoindex:error] [pid 230252:tid 230418] [client 44.220.233.148:16812] AH01276: Cannot serve directory /home2/bavosc49/juridic.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:22:20.934310 2026] [security2:error] [pid 229246:tid 229313] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IXCBMYeh5YLVG45xoGAACT0I"]
[Tue Jul 21 07:22:20.934537 2026] [security2:error] [pid 229246:tid 229435] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IXCBMYeh5YLVG45xoGAACT0I"]
[Tue Jul 21 07:22:21.012179 2026] [security2:error] [pid 230252:tid 230440] [client 20.220.225.223:43046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/else1.php"] [unique_id "al9IXU0Dwhk5-Z44XrpERQAAAtE"]
[Tue Jul 21 07:22:21.078350 2026] [security2:error] [pid 230252:tid 230433] [client 20.206.105.145:30550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/gettest.php"] [unique_id "al9IXU0Dwhk5-Z44XrpERgAAAso"]
[Tue Jul 21 07:22:21.141286 2026] [security2:error] [pid 229246:tid 229437] [client 20.151.10.161:26422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/k2.php"] [unique_id "al9IXSBMYeh5YLVG45xoHAAAAlE"]
[Tue Jul 21 07:22:21.208013 2026] [security2:error] [pid 229246:tid 229451] [client 20.104.96.117:59171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/sid4.php"] [unique_id "al9IXSBMYeh5YLVG45xoHgAAAl8"]
[Tue Jul 21 07:22:21.257038 2026] [security2:error] [pid 229246:tid 229391] [client 20.226.60.151:60260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/spadex.php"] [unique_id "al9IXSBMYeh5YLVG45xoHwAAAiM"]
[Tue Jul 21 07:22:21.289562 2026] [security2:error] [pid 229246:tid 229454] [client 20.104.96.117:5103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/file6.php"] [unique_id "al9IXSBMYeh5YLVG45xoIAAAAmI"]
[Tue Jul 21 07:22:21.306894 2026] [security2:error] [pid 230252:tid 230292] [remote 160.187.68.132:58918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "knconteudo.com"] [uri "/wp-login.php"] [unique_id "al9IXU0Dwhk5-Z44XrpESAAC5SY"]
[Tue Jul 21 07:22:21.527095 2026] [http2:warn] [pid 230252:tid 230498] [client 57.141.18.56:23924] h2_stream(230252-313-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:21.556079 2026] [security2:error] [pid 229246:tid 229433] [client 20.151.10.161:26499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/k3.php"] [unique_id "al9IXSBMYeh5YLVG45xoIgAAAk0"]
[Tue Jul 21 07:22:21.629376 2026] [security2:error] [pid 229246:tid 229383] [client 37.59.204.139:36380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "hctreinamentos.net"] [uri "/robots.txt"] [unique_id "al9IXSBMYeh5YLVG45xoIwAAAhs"]
[Tue Jul 21 07:22:21.629510 2026] [security2:error] [pid 229246:tid 229383] [client 37.59.204.139:36380] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hctreinamentos.net"] [uri "/robots.txt"] [unique_id "al9IXSBMYeh5YLVG45xoIwAAAhs"]
[Tue Jul 21 07:22:21.882022 2026] [security2:error] [pid 230252:tid 230479] [client 20.226.60.151:54583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9IXU0Dwhk5-Z44XrpESwAAAvg"]
[Tue Jul 21 07:22:21.937094 2026] [security2:error] [pid 229246:tid 229402] [client 20.104.96.117:61057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wmore1.php"] [unique_id "al9IXSBMYeh5YLVG45xoLQAAAi4"]
[Tue Jul 21 07:22:22.038481 2026] [security2:error] [pid 229246:tid 229442] [client 74.249.245.134:62537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/222.php"] [unique_id "al9IXiBMYeh5YLVG45xoLgAAAlY"]
[Tue Jul 21 07:22:22.057489 2026] [proxy:error] [pid 230252:tid 230384] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:22.057582 2026] [proxy_http:error] [pid 230252:tid 230384] [client 20.104.96.117:62916] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:22.058829 2026] [proxy:error] [pid 230252:tid 230384] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:22.058893 2026] [proxy_http:error] [pid 230252:tid 230384] [client 20.104.96.117:62916] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:22.066756 2026] [security2:error] [pid 230252:tid 230477] [client 20.226.60.151:54574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/jj.php"] [unique_id "al9IXk0Dwhk5-Z44XrpETwAAAvY"]
[Tue Jul 21 07:22:22.219463 2026] [security2:error] [pid 230252:tid 230470] [client 20.151.10.161:26509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/k4.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEUQAAAu8"]
[Tue Jul 21 07:22:22.251148 2026] [security2:error] [pid 229246:tid 229441] [client 20.104.96.117:61163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/solo1.php"] [unique_id "al9IXiBMYeh5YLVG45xoMgAAAlU"]
[Tue Jul 21 07:22:22.298116 2026] [security2:error] [pid 230252:tid 230314] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEUgADDDw"]
[Tue Jul 21 07:22:22.298349 2026] [security2:error] [pid 230252:tid 230499] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEUgADDDw"]
[Tue Jul 21 07:22:22.637313 2026] [security2:error] [pid 230252:tid 230389] [client 20.206.105.145:30545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/min.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEVgAAAp4"]
[Tue Jul 21 07:22:22.702748 2026] [security2:error] [pid 230252:tid 230483] [client 20.226.60.151:60277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/2x.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEWQAAAvw"]
[Tue Jul 21 07:22:22.751520 2026] [security2:error] [pid 230252:tid 230480] [client 20.220.225.223:36828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/tkikikoko.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEWgAAAvk"]
[Tue Jul 21 07:22:22.767831 2026] [http2:warn] [pid 229246:tid 229466] [client 57.141.18.79:37592] h2_stream(229246-472-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:22.796261 2026] [security2:error] [pid 229246:tid 229418] [client 20.104.96.117:60935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/cong.php"] [unique_id "al9IXiBMYeh5YLVG45xoOQAAAj4"]
[Tue Jul 21 07:22:22.834608 2026] [security2:error] [pid 229246:tid 229463] [client 103.174.34.15:49780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IXiBMYeh5YLVG45xoOwAAAms"]
[Tue Jul 21 07:22:22.834780 2026] [security2:error] [pid 229246:tid 229463] [client 103.174.34.15:49780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IXiBMYeh5YLVG45xoOwAAAms"]
[Tue Jul 21 07:22:22.855285 2026] [security2:error] [pid 230252:tid 230391] [client 74.249.245.134:62586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/t.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEWwAAAqA"]
[Tue Jul 21 07:22:22.981746 2026] [security2:error] [pid 230252:tid 230423] [client 20.104.96.117:62959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/adminfuns.php"] [unique_id "al9IXk0Dwhk5-Z44XrpEXQAAAsA"]
[Tue Jul 21 07:22:23.039161 2026] [security2:error] [pid 230252:tid 230467] [client 20.151.10.161:26522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/k5.php"] [unique_id "al9IX00Dwhk5-Z44XrpEXgAAAuw"]
[Tue Jul 21 07:22:23.068568 2026] [security2:error] [pid 230252:tid 230311] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IX00Dwhk5-Z44XrpEXwAC4zk"]
[Tue Jul 21 07:22:23.068763 2026] [security2:error] [pid 230252:tid 230458] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IX00Dwhk5-Z44XrpEXwAC4zk"]
[Tue Jul 21 07:22:23.134374 2026] [security2:error] [pid 230252:tid 230303] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IX00Dwhk5-Z44XrpEYAACmzE"]
[Tue Jul 21 07:22:23.134511 2026] [security2:error] [pid 230252:tid 230386] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IX00Dwhk5-Z44XrpEYAACmzE"]
[Tue Jul 21 07:22:23.171399 2026] [security2:error] [pid 229246:tid 229407] [client 136.144.33.102:61343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IXyBMYeh5YLVG45xoPQAAAjM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:23.404996 2026] [security2:error] [pid 230252:tid 230478] [client 20.104.96.117:61151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/public/css.php"] [unique_id "al9IX00Dwhk5-Z44XrpEYwAAAvc"]
[Tue Jul 21 07:22:23.428175 2026] [security2:error] [pid 230252:tid 230421] [client 20.197.192.193:52257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/x.php"] [unique_id "al9IX00Dwhk5-Z44XrpEZAAAAr4"]
[Tue Jul 21 07:22:23.543022 2026] [security2:error] [pid 230252:tid 230433] [client 20.151.10.161:26372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/w.php"] [unique_id "al9IX00Dwhk5-Z44XrpEZQAAAso"]
[Tue Jul 21 07:22:23.568367 2026] [security2:error] [pid 230252:tid 230506] [client 20.206.105.145:30630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/edorxrr.php"] [unique_id "al9IX00Dwhk5-Z44XrpEZgAAAxM"]
[Tue Jul 21 07:22:23.676621 2026] [security2:error] [pid 229246:tid 229481] [client 20.226.60.151:50756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ctex1.php"] [unique_id "al9IXyBMYeh5YLVG45xoQgAAAn0"]
[Tue Jul 21 07:22:23.730662 2026] [security2:error] [pid 229246:tid 229321] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IXyBMYeh5YLVG45xoQwACOko"]
[Tue Jul 21 07:22:23.730818 2026] [security2:error] [pid 229246:tid 229414] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IXyBMYeh5YLVG45xoQwACOko"]
[Tue Jul 21 07:22:23.900592 2026] [security2:error] [pid 230252:tid 230397] [client 20.104.96.117:59136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/output.php"] [unique_id "al9IX00Dwhk5-Z44XrpEbQAAAqY"]
[Tue Jul 21 07:22:23.909950 2026] [security2:error] [pid 229246:tid 229449] [client 20.151.10.161:26431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/fpwch.php"] [unique_id "al9IXyBMYeh5YLVG45xoSQAAAl0"]
[Tue Jul 21 07:22:24.002306 2026] [security2:error] [pid 229246:tid 229406] [client 20.104.96.117:62927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/goods.php"] [unique_id "al9IYCBMYeh5YLVG45xoSgAAAjI"]
[Tue Jul 21 07:22:24.152379 2026] [http2:warn] [pid 230252:tid 230406] [client 57.141.18.112:41010] h2_stream(230252-319-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:24.535372 2026] [security2:error] [pid 230252:tid 230395] [client 20.151.10.161:26508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/w2025.php"] [unique_id "al9IYE0Dwhk5-Z44XrpEdgAAAqQ"]
[Tue Jul 21 07:22:24.563656 2026] [security2:error] [pid 229246:tid 229383] [client 74.249.245.134:62416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/a.php"] [unique_id "al9IYCBMYeh5YLVG45xoUQAAAhs"]
[Tue Jul 21 07:22:24.630839 2026] [security2:error] [pid 230252:tid 230483] [client 20.104.96.117:59177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-file-120.php"] [unique_id "al9IYE0Dwhk5-Z44XrpEdwAAAvw"]
[Tue Jul 21 07:22:24.676621 2026] [security2:error] [pid 230252:tid 230491] [client 20.104.96.117:64039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/100.php"] [unique_id "al9IYE0Dwhk5-Z44XrpEeAAAAwQ"]
[Tue Jul 21 07:22:24.918784 2026] [security2:error] [pid 230252:tid 230499] [client 175.45.70.82:55839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IYE0Dwhk5-Z44XrpEfAAAAww"]
[Tue Jul 21 07:22:24.918967 2026] [security2:error] [pid 230252:tid 230499] [client 175.45.70.82:55839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IYE0Dwhk5-Z44XrpEfAAAAww"]
[Tue Jul 21 07:22:25.151728 2026] [security2:error] [pid 229246:tid 229385] [client 20.151.10.161:26514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/scxy.php"] [unique_id "al9IYSBMYeh5YLVG45xoWQAAAh0"]
[Tue Jul 21 07:22:25.155857 2026] [security2:error] [pid 229246:tid 229277] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IYSBMYeh5YLVG45xoWgACSB4"]
[Tue Jul 21 07:22:25.156015 2026] [security2:error] [pid 229246:tid 229428] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IYSBMYeh5YLVG45xoWgACSB4"]
[Tue Jul 21 07:22:25.162151 2026] [security2:error] [pid 229246:tid 229443] [client 20.104.96.117:61130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/special.php"] [unique_id "al9IYSBMYeh5YLVG45xoWwAAAlc"]
[Tue Jul 21 07:22:25.300608 2026] [security2:error] [pid 230252:tid 230492] [client 185.198.240.209:27417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9IYU0Dwhk5-Z44XrpEgQAAAwU"]
[Tue Jul 21 07:22:25.323634 2026] [security2:error] [pid 230252:tid 230421] [client 20.206.105.145:30641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/hur.php"] [unique_id "al9IYU0Dwhk5-Z44XrpEggAAAr4"]
[Tue Jul 21 07:22:25.516259 2026] [http2:warn] [pid 229246:tid 229439] [client 57.141.18.119:41986] h2_stream(229246-476-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:25.606783 2026] [security2:error] [pid 229246:tid 229416] [client 139.135.44.145:53292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IYSBMYeh5YLVG45xoZAAAAjw"]
[Tue Jul 21 07:22:25.606905 2026] [security2:error] [pid 229246:tid 229416] [client 139.135.44.145:53292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IYSBMYeh5YLVG45xoZAAAAjw"]
[Tue Jul 21 07:22:25.627585 2026] [security2:error] [pid 229246:tid 229404] [client 20.104.96.117:64050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/about.php"] [unique_id "al9IYSBMYeh5YLVG45xoZQAAAjA"]
[Tue Jul 21 07:22:25.689651 2026] [security2:error] [pid 229246:tid 229398] [client 20.104.96.117:59685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/as.php"] [unique_id "al9IYSBMYeh5YLVG45xoZgAAAio"]
[Tue Jul 21 07:22:25.748557 2026] [security2:error] [pid 229246:tid 229392] [client 20.151.10.161:26404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/FWAZ.php"] [unique_id "al9IYSBMYeh5YLVG45xoZwAAAiQ"]
[Tue Jul 21 07:22:25.782959 2026] [security2:error] [pid 230252:tid 230460] [client 20.226.60.151:60246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/edorxrr.php"] [unique_id "al9IYU0Dwhk5-Z44XrpEhAAAAuU"]
[Tue Jul 21 07:22:25.853548 2026] [security2:error] [pid 229246:tid 229457] [client 20.206.105.145:30594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/zoro.php"] [unique_id "al9IYSBMYeh5YLVG45xoagAAAmU"]
[Tue Jul 21 07:22:26.182211 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:62950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/about.php"] [unique_id "al9IYiBMYeh5YLVG45xocgAAAi8"]
[Tue Jul 21 07:22:26.266061 2026] [security2:error] [pid 229246:tid 229481] [client 20.151.10.161:26555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/qterm.php"] [unique_id "al9IYiBMYeh5YLVG45xocwAAAn0"]
[Tue Jul 21 07:22:26.350707 2026] [http2:warn] [pid 229246:tid 229487] [client 57.141.18.66:31450] h2_stream(229246-478-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:26.519246 2026] [security2:error] [pid 229246:tid 229494] [client 20.104.96.117:59661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9IYiBMYeh5YLVG45xoeQAAAoo"]
[Tue Jul 21 07:22:26.816237 2026] [security2:error] [pid 230252:tid 230494] [client 20.104.96.117:64043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9IYk0Dwhk5-Z44XrpEiAAAAwc"]
[Tue Jul 21 07:22:26.856644 2026] [security2:error] [pid 230252:tid 230407] [client 20.151.10.161:26389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/blurbs.php"] [unique_id "al9IYk0Dwhk5-Z44XrpEiQAAArA"]
[Tue Jul 21 07:22:26.905075 2026] [security2:error] [pid 230252:tid 230438] [client 20.226.60.151:54503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9IYk0Dwhk5-Z44XrpEiwAAAs8"]
[Tue Jul 21 07:22:27.228665 2026] [security2:error] [pid 229246:tid 229399] [client 20.104.96.117:61134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/w1px.php"] [unique_id "al9IYyBMYeh5YLVG45xohgAAAis"]
[Tue Jul 21 07:22:27.239895 2026] [security2:error] [pid 229246:tid 229445] [client 20.151.10.161:26507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/v543.php"] [unique_id "al9IYyBMYeh5YLVG45xohwAAAlk"]
[Tue Jul 21 07:22:27.464297 2026] [security2:error] [pid 230252:tid 230469] [client 185.198.240.196:21671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9IYU0Dwhk5-Z44XrpEgAAAAu4"]
[Tue Jul 21 07:22:27.561431 2026] [security2:error] [pid 230252:tid 230442] [client 74.249.245.134:62341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/a1.php"] [unique_id "al9IY00Dwhk5-Z44XrpEkAAAAtM"]
[Tue Jul 21 07:22:27.687649 2026] [security2:error] [pid 229246:tid 229462] [client 20.104.96.117:5066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9IYyBMYeh5YLVG45xokQAAAmo"]
[Tue Jul 21 07:22:27.750304 2026] [security2:error] [pid 230252:tid 230480] [client 20.151.10.161:26397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/w3lls.php"] [unique_id "al9IY00Dwhk5-Z44XrpEkwAAAvk"]
[Tue Jul 21 07:22:27.816579 2026] [security2:error] [pid 230252:tid 230396] [client 20.226.60.151:60236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/miru1.php"] [unique_id "al9IY00Dwhk5-Z44XrpElAAAAqU"]
[Tue Jul 21 07:22:27.894742 2026] [security2:error] [pid 230252:tid 230416] [client 103.121.156.110:65188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IY00Dwhk5-Z44XrpElQAAArk"]
[Tue Jul 21 07:22:27.894899 2026] [security2:error] [pid 230252:tid 230416] [client 103.121.156.110:65188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IY00Dwhk5-Z44XrpElQAAArk"]
[Tue Jul 21 07:22:27.912726 2026] [security2:error] [pid 230252:tid 230420] [client 136.144.33.101:46125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IY00Dwhk5-Z44XrpEkgAAAr0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:27.941491 2026] [security2:error] [pid 229246:tid 229479] [client 20.206.105.145:30701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/coffexium.php"] [unique_id "al9IYyBMYeh5YLVG45xokgAAAns"]
[Tue Jul 21 07:22:28.273402 2026] [http2:warn] [pid 230252:tid 230502] [client 57.141.18.57:42696] h2_stream(230252-327-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:28.399790 2026] [security2:error] [pid 230252:tid 230460] [client 20.151.10.161:26519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-ws68.php"] [unique_id "al9IZE0Dwhk5-Z44XrpEnwAAAuU"]
[Tue Jul 21 07:22:28.447871 2026] [security2:error] [pid 229246:tid 229436] [client 20.104.96.117:64053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/themes.php"] [unique_id "al9IZCBMYeh5YLVG45xonwAAAlA"]
[Tue Jul 21 07:22:28.614498 2026] [security2:error] [pid 229246:tid 229469] [client 20.226.60.151:60241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/sump1.php"] [unique_id "al9IZCBMYeh5YLVG45xopgAAAnE"]
[Tue Jul 21 07:22:28.833112 2026] [security2:error] [pid 230252:tid 230443] [client 45.251.232.145:52031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IZE0Dwhk5-Z44XrpEpgAAAtQ"]
[Tue Jul 21 07:22:28.833216 2026] [security2:error] [pid 230252:tid 230443] [client 45.251.232.145:52031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IZE0Dwhk5-Z44XrpEpgAAAtQ"]
[Tue Jul 21 07:22:29.043862 2026] [security2:error] [pid 230252:tid 230391] [client 20.104.96.117:59169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/yawa.php"] [unique_id "al9IZU0Dwhk5-Z44XrpEqwAAAqA"]
[Tue Jul 21 07:22:29.169576 2026] [security2:error] [pid 229246:tid 229500] [client 20.220.225.223:34275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/berlin.php"] [unique_id "al9IZSBMYeh5YLVG45xoswAAApA"]
[Tue Jul 21 07:22:29.227630 2026] [security2:error] [pid 230252:tid 230416] [client 20.226.60.151:60199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/file5.php"] [unique_id "al9IZU0Dwhk5-Z44XrpErAAAArk"]
[Tue Jul 21 07:22:29.364463 2026] [security2:error] [pid 230252:tid 230458] [client 20.220.225.223:43052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9IZU0Dwhk5-Z44XrpErQAAAuM"]
[Tue Jul 21 07:22:29.408112 2026] [security2:error] [pid 230252:tid 230386] [client 20.151.10.161:26400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/xyn.php"] [unique_id "al9IZU0Dwhk5-Z44XrpErgAAAps"]
[Tue Jul 21 07:22:29.672696 2026] [http2:warn] [pid 230252:tid 230471] [client 57.141.18.95:36116] h2_stream(230252-330-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:29.861306 2026] [security2:error] [pid 229246:tid 229492] [client 20.206.105.145:30601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/app.php"] [unique_id "al9IZSBMYeh5YLVG45xouQAAAog"]
[Tue Jul 21 07:22:29.953606 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:26390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/green3.php"] [unique_id "al9IZSBMYeh5YLVG45xouwAAAnk"]
[Tue Jul 21 07:22:30.155696 2026] [security2:error] [pid 230252:tid 230466] [client 20.226.60.151:60259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/0xD.php"] [unique_id "al9IZk0Dwhk5-Z44XrpEuQAAAus"]
[Tue Jul 21 07:22:30.185839 2026] [security2:error] [pid 230252:tid 230500] [client 20.197.192.193:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/tinyfilemanager.php"] [unique_id "al9IZk0Dwhk5-Z44XrpEugAAAw0"]
[Tue Jul 21 07:22:30.611097 2026] [security2:error] [pid 230252:tid 230438] [client 20.226.60.151:54484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/txets.php"] [unique_id "al9IZk0Dwhk5-Z44XrpExgAAAs8"]
[Tue Jul 21 07:22:30.634795 2026] [security2:error] [pid 230252:tid 230503] [client 20.151.10.161:26511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ccs.php"] [unique_id "al9IZk0Dwhk5-Z44XrpExwAAAxA"]
[Tue Jul 21 07:22:30.865738 2026] [security2:error] [pid 229246:tid 229430] [client 20.226.60.151:60271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/fnstall.php"] [unique_id "al9IZiBMYeh5YLVG45xoyQAAAko"]
[Tue Jul 21 07:22:30.900423 2026] [security2:error] [pid 229246:tid 229409] [client 20.104.96.117:59195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/js.php"] [unique_id "al9IZiBMYeh5YLVG45xoygAAAjU"]
[Tue Jul 21 07:22:31.085481 2026] [http2:warn] [pid 230252:tid 230473] [client 57.141.18.5:61110] h2_stream(230252-335-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:31.162498 2026] [security2:error] [pid 230252:tid 230454] [client 20.151.10.161:26405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ccc.php"] [unique_id "al9IZ00Dwhk5-Z44XrpEyQAAAt8"]
[Tue Jul 21 07:22:31.333475 2026] [proxy:error] [pid 230252:tid 230391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:31.333550 2026] [proxy_http:error] [pid 230252:tid 230391] [client 20.104.96.117:64004] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:31.334164 2026] [proxy:error] [pid 230252:tid 230391] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:31.334193 2026] [proxy_http:error] [pid 230252:tid 230391] [client 20.104.96.117:64004] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:31.572473 2026] [security2:error] [pid 230252:tid 230481] [client 20.220.225.223:46137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IZ00Dwhk5-Z44XrpE4AAAAvo"]
[Tue Jul 21 07:22:31.591011 2026] [security2:error] [pid 229246:tid 229298] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IZyBMYeh5YLVG45xo2QACfDM"]
[Tue Jul 21 07:22:31.591121 2026] [security2:error] [pid 229246:tid 229480] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IZyBMYeh5YLVG45xo2QACfDM"]
[Tue Jul 21 07:22:31.627027 2026] [security2:error] [pid 230252:tid 230415] [client 20.151.10.161:26370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/get.php"] [unique_id "al9IZ00Dwhk5-Z44XrpE4gAAArg"]
[Tue Jul 21 07:22:31.911890 2026] [security2:error] [pid 229246:tid 229502] [client 103.162.129.114:49345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IZyBMYeh5YLVG45xo3gAAApI"]
[Tue Jul 21 07:22:31.912041 2026] [security2:error] [pid 229246:tid 229502] [client 103.162.129.114:49345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IZyBMYeh5YLVG45xo3gAAApI"]
[Tue Jul 21 07:22:31.929876 2026] [security2:error] [pid 230252:tid 230399] [client 20.104.96.117:59660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/core.php"] [unique_id "al9IZ00Dwhk5-Z44XrpE8QAAAqg"]
[Tue Jul 21 07:22:31.931627 2026] [proxy:error] [pid 230252:tid 230478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:31.931679 2026] [proxy_http:error] [pid 230252:tid 230478] [client 20.104.96.117:5091] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:31.932295 2026] [proxy:error] [pid 230252:tid 230478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:31.932323 2026] [proxy_http:error] [pid 230252:tid 230478] [client 20.104.96.117:5091] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:31.961245 2026] [security2:error] [pid 230252:tid 230440] [client 74.249.245.134:61258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/w.php"] [unique_id "al9IZ00Dwhk5-Z44XrpE8wAAAtE"]
[Tue Jul 21 07:22:32.151010 2026] [security2:error] [pid 229246:tid 229455] [client 20.10.88.227:3522] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shop-officialstore.com"] [uri "/index.php"] [unique_id "al9IZyBMYeh5YLVG45xo4AAAAmM"]
[Tue Jul 21 07:22:32.210909 2026] [http2:warn] [pid 229246:tid 229490] [client 57.141.18.14:33272] h2_stream(229246-489-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:32.408962 2026] [security2:error] [pid 229246:tid 229433] [client 20.220.225.223:34277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/billur.php"] [unique_id "al9IaCBMYeh5YLVG45xo6QAAAk0"]
[Tue Jul 21 07:22:32.424540 2026] [security2:error] [pid 230252:tid 230492] [client 20.151.10.161:26413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/images.php"] [unique_id "al9IaE0Dwhk5-Z44XrpE-AAAAwU"]
[Tue Jul 21 07:22:32.588048 2026] [security2:error] [pid 230252:tid 230487] [client 20.206.105.145:30595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/core.php"] [unique_id "al9IaE0Dwhk5-Z44XrpE-gAAAwA"]
[Tue Jul 21 07:22:32.636894 2026] [security2:error] [pid 230252:tid 230472] [client 74.7.241.151:45736] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aron.adv.br"] [uri "/robots.txt"] [unique_id "al9IaE0Dwhk5-Z44XrpE-wAC8UU"]
[Tue Jul 21 07:22:32.775966 2026] [security2:error] [pid 230252:tid 230449] [client 172.245.102.46:40931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IaE0Dwhk5-Z44XrpFBgAAAto"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:32.828860 2026] [security2:error] [pid 230252:tid 230325] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IaE0Dwhk5-Z44XrpFFAACtUY"]
[Tue Jul 21 07:22:32.828987 2026] [security2:error] [pid 230252:tid 230412] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IaE0Dwhk5-Z44XrpFFAACtUY"]
[Tue Jul 21 07:22:32.879242 2026] [security2:error] [pid 230252:tid 230396] [client 20.104.96.117:5114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/.well-known/about.php"] [unique_id "al9IaE0Dwhk5-Z44XrpFJAAAAqU"]
[Tue Jul 21 07:22:32.967578 2026] [security2:error] [pid 230252:tid 230436] [client 20.197.192.193:52269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/ee.php"] [unique_id "al9IaE0Dwhk5-Z44XrpFJgAAAs0"]
[Tue Jul 21 07:22:33.216578 2026] [security2:error] [pid 229246:tid 229479] [client 20.226.60.151:60184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/acp.php"] [unique_id "al9IaSBMYeh5YLVG45xo9QAAAns"]
[Tue Jul 21 07:22:33.300483 2026] [http2:warn] [pid 230252:tid 230489] [client 57.141.18.78:62724] h2_stream(230252-342-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:33.393216 2026] [security2:error] [pid 230252:tid 230405] [client 20.104.96.117:64025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9IaU0Dwhk5-Z44XrpFMAAAAq4"]
[Tue Jul 21 07:22:33.522749 2026] [security2:error] [pid 230252:tid 230399] [client 20.151.10.161:26516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/alls.php"] [unique_id "al9IaU0Dwhk5-Z44XrpFNAAAAqg"]
[Tue Jul 21 07:22:33.581826 2026] [security2:error] [pid 230252:tid 230352] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IaU0Dwhk5-Z44XrpFNgACu2E"]
[Tue Jul 21 07:22:33.581966 2026] [security2:error] [pid 230252:tid 230418] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IaU0Dwhk5-Z44XrpFNgACu2E"]
[Tue Jul 21 07:22:33.621560 2026] [security2:error] [pid 229246:tid 229430] [client 20.104.96.117:59676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/19.php"] [unique_id "al9IaSBMYeh5YLVG45xo-QAAAko"]
[Tue Jul 21 07:22:33.623733 2026] [security2:error] [pid 229246:tid 229366] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IaSBMYeh5YLVG45xo-gACGXc"]
[Tue Jul 21 07:22:33.623869 2026] [security2:error] [pid 229246:tid 229381] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IaSBMYeh5YLVG45xo-gACGXc"]
[Tue Jul 21 07:22:33.638114 2026] [security2:error] [pid 230252:tid 230266] [remote 47.128.56.60:48666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dscbrasil.com.br"] [uri "/inicial"] [unique_id "al9IaU0Dwhk5-Z44XrpFOAAC0Qw"]
[Tue Jul 21 07:22:33.651231 2026] [security2:error] [pid 229246:tid 229391] [client 103.174.34.15:50242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IaSBMYeh5YLVG45xo-wAAAiM"]
[Tue Jul 21 07:22:33.651396 2026] [security2:error] [pid 229246:tid 229391] [client 103.174.34.15:50242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IaSBMYeh5YLVG45xo-wAAAiM"]
[Tue Jul 21 07:22:33.798864 2026] [security2:error] [pid 230252:tid 230466] [client 142.44.233.209:31280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "robertinhoimoveis.com.br"] [uri "/robots.txt"] [unique_id "al9IaU0Dwhk5-Z44XrpFOQAAAus"]
[Tue Jul 21 07:22:33.798962 2026] [security2:error] [pid 230252:tid 230466] [client 142.44.233.209:31280] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "robertinhoimoveis.com.br"] [uri "/robots.txt"] [unique_id "al9IaU0Dwhk5-Z44XrpFOQAAAus"]
[Tue Jul 21 07:22:33.960424 2026] [security2:error] [pid 229246:tid 229429] [client 20.151.10.161:26374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/yyu.php"] [unique_id "al9IaSBMYeh5YLVG45xpAgAAAkk"]
[Tue Jul 21 07:22:34.310697 2026] [security2:error] [pid 230252:tid 230421] [client 20.151.10.161:26523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/by.php"] [unique_id "al9Iak0Dwhk5-Z44XrpFPAAAAr4"]
[Tue Jul 21 07:22:34.376322 2026] [security2:error] [pid 229246:tid 229470] [client 20.104.96.117:5071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wefile.php"] [unique_id "al9IaiBMYeh5YLVG45xpDgAAAnI"]
[Tue Jul 21 07:22:34.543253 2026] [security2:error] [pid 229246:tid 229349] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IaiBMYeh5YLVG45xpDwACXmY"]
[Tue Jul 21 07:22:34.543412 2026] [security2:error] [pid 229246:tid 229450] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IaiBMYeh5YLVG45xpDwACXmY"]
[Tue Jul 21 07:22:34.600705 2026] [security2:error] [pid 230252:tid 230487] [client 20.206.105.145:30557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/main.php"] [unique_id "al9Iak0Dwhk5-Z44XrpFPgAAAwA"]
[Tue Jul 21 07:22:34.659021 2026] [security2:error] [pid 230252:tid 230385] [client 20.151.10.161:26526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/FAQ.php"] [unique_id "al9Iak0Dwhk5-Z44XrpFQAAAApo"]
[Tue Jul 21 07:22:34.708528 2026] [security2:error] [pid 230252:tid 230506] [client 20.104.96.117:61065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/inc.php"] [unique_id "al9Iak0Dwhk5-Z44XrpFRAAAAxM"]
[Tue Jul 21 07:22:34.930795 2026] [security2:error] [pid 229246:tid 229414] [client 20.104.96.117:5062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9IaiBMYeh5YLVG45xpHAAAAjo"]
[Tue Jul 21 07:22:35.004535 2026] [security2:error] [pid 230252:tid 230432] [client 20.151.10.161:26384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/coffexium.php"] [unique_id "al9Ia00Dwhk5-Z44XrpFRgAAAsk"]
[Tue Jul 21 07:22:35.068651 2026] [http2:warn] [pid 230252:tid 230448] [client 57.141.18.23:31734] h2_stream(230252-349-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:35.102944 2026] [security2:error] [pid 230252:tid 230407] [client 185.198.240.97:25107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-login.php"] [unique_id "al9IaE0Dwhk5-Z44XrpFJwAAArA"]
[Tue Jul 21 07:22:35.221277 2026] [security2:error] [pid 229246:tid 229467] [client 142.44.225.88:22172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "robertinhoimoveis.com.br"] [uri "/"] [unique_id "al9IayBMYeh5YLVG45xpHwAAAm8"]
[Tue Jul 21 07:22:35.221395 2026] [security2:error] [pid 229246:tid 229467] [client 142.44.225.88:22172] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "robertinhoimoveis.com.br"] [uri "/"] [unique_id "al9IayBMYeh5YLVG45xpHwAAAm8"]
[Tue Jul 21 07:22:35.330841 2026] [security2:error] [pid 230252:tid 230429] [client 20.104.96.117:59699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9Ia00Dwhk5-Z44XrpFSQAAAsY"]
[Tue Jul 21 07:22:35.365729 2026] [security2:error] [pid 230252:tid 230465] [client 74.7.230.13:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.boostryourorders.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "al9Ia00Dwhk5-Z44XrpFSgAC6hs"]
[Tue Jul 21 07:22:35.374913 2026] [security2:error] [pid 230252:tid 230396] [client 20.226.60.151:60239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/mosty.php"] [unique_id "al9Ia00Dwhk5-Z44XrpFSwAAAqU"]
[Tue Jul 21 07:22:35.385405 2026] [security2:error] [pid 230252:tid 230420] [client 20.151.10.161:26378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/red.php"] [unique_id "al9Ia00Dwhk5-Z44XrpFTAAAAr0"]
[Tue Jul 21 07:22:35.507850 2026] [proxy:error] [pid 229246:tid 229498] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:35.507939 2026] [proxy_http:error] [pid 229246:tid 229498] [client 20.104.96.117:5059] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:35.508641 2026] [proxy:error] [pid 229246:tid 229498] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:35.508685 2026] [proxy_http:error] [pid 229246:tid 229498] [client 20.104.96.117:5059] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:35.661252 2026] [security2:error] [pid 229246:tid 229501] [client 175.45.70.82:56346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IayBMYeh5YLVG45xpKAAAApE"]
[Tue Jul 21 07:22:35.661399 2026] [security2:error] [pid 229246:tid 229501] [client 175.45.70.82:56346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IayBMYeh5YLVG45xpKAAAApE"]
[Tue Jul 21 07:22:35.749682 2026] [security2:error] [pid 230252:tid 230371] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Ia00Dwhk5-Z44XrpFUQACuXQ"]
[Tue Jul 21 07:22:35.749959 2026] [security2:error] [pid 230252:tid 230416] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Ia00Dwhk5-Z44XrpFUQACuXQ"]
[Tue Jul 21 07:22:35.951555 2026] [http2:warn] [pid 229246:tid 229444] [client 57.141.18.16:21870] h2_stream(229246-491-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:35.957121 2026] [security2:error] [pid 230252:tid 230418] [client 20.151.10.161:26393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9Ia00Dwhk5-Z44XrpFVAAAArs"]
[Tue Jul 21 07:22:36.017553 2026] [security2:error] [pid 229246:tid 229487] [client 148.113.130.54:60522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "hctreinamentos.net"] [uri "/"] [unique_id "al9IbCBMYeh5YLVG45xpMQAAAoM"]
[Tue Jul 21 07:22:36.017670 2026] [security2:error] [pid 229246:tid 229487] [client 148.113.130.54:60522] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hctreinamentos.net"] [uri "/"] [unique_id "al9IbCBMYeh5YLVG45xpMQAAAoM"]
[Tue Jul 21 07:22:36.091705 2026] [proxy:error] [pid 230252:tid 230427] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:36.091783 2026] [proxy_http:error] [pid 230252:tid 230427] [client 20.104.96.117:64032] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:36.092661 2026] [proxy:error] [pid 230252:tid 230427] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:36.092706 2026] [proxy_http:error] [pid 230252:tid 230427] [client 20.104.96.117:64032] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:36.198452 2026] [security2:error] [pid 230252:tid 230384] [client 20.206.105.145:30618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/init.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFVgAAApk"]
[Tue Jul 21 07:22:36.268205 2026] [security2:error] [pid 230252:tid 230511] [client 20.104.96.117:61127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFWAAAAxg"]
[Tue Jul 21 07:22:36.369882 2026] [security2:error] [pid 229246:tid 229418] [client 20.220.225.223:47855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wp-css.php"] [unique_id "al9IbCBMYeh5YLVG45xpNAAAAj4"]
[Tue Jul 21 07:22:36.505234 2026] [security2:error] [pid 230252:tid 230472] [client 20.151.10.161:26505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/footer.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFXgAAAvE"]
[Tue Jul 21 07:22:36.664912 2026] [security2:error] [pid 230252:tid 230492] [client 20.206.105.145:30670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/prekel.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFXwAAAwU"]
[Tue Jul 21 07:22:36.839750 2026] [security2:error] [pid 229246:tid 229471] [client 20.104.96.117:62929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9IbCBMYeh5YLVG45xpOwAAAnM"]
[Tue Jul 21 07:22:36.849035 2026] [security2:error] [pid 230252:tid 230506] [client 20.220.225.223:45956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFYAAAAxM"]
[Tue Jul 21 07:22:36.875643 2026] [security2:error] [pid 230252:tid 230433] [client 139.135.44.145:54048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFYwAAAso"]
[Tue Jul 21 07:22:36.875792 2026] [security2:error] [pid 230252:tid 230433] [client 139.135.44.145:54048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFYwAAAso"]
[Tue Jul 21 07:22:36.945399 2026] [security2:error] [pid 229246:tid 229392] [client 20.197.192.193:53145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/blue.php"] [unique_id "al9IbCBMYeh5YLVG45xpPwAAAiQ"]
[Tue Jul 21 07:22:36.982485 2026] [security2:error] [pid 229246:tid 229260] [remote 74.7.241.41:34014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/wp-login.php"] [unique_id "al9IayBMYeh5YLVG45xpLAACWw0"], referer: https://brasilcertdigital.com.br/wp-admin/
[Tue Jul 21 07:22:37.130261 2026] [security2:error] [pid 229246:tid 229425] [client 20.151.10.161:26530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-content/index.php"] [unique_id "al9IbSBMYeh5YLVG45xpQQAAAkU"]
[Tue Jul 21 07:22:37.209027 2026] [security2:error] [pid 230252:tid 230508] [client 20.104.96.117:59701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ss.php"] [unique_id "al9IbU0Dwhk5-Z44XrpFZgAAAxU"]
[Tue Jul 21 07:22:37.227164 2026] [security2:error] [pid 230252:tid 230429] [client 20.226.60.151:60287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/6.php"] [unique_id "al9IbU0Dwhk5-Z44XrpFawAAAsY"]
[Tue Jul 21 07:22:37.303003 2026] [security2:error] [pid 230252:tid 230471] [client 20.104.96.117:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/8.php"] [unique_id "al9IbU0Dwhk5-Z44XrpFbAAAAvA"]
[Tue Jul 21 07:22:37.383965 2026] [security2:error] [pid 229246:tid 229437] [client 172.245.102.46:54011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IbSBMYeh5YLVG45xpQwAAAlE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:37.390845 2026] [security2:error] [pid 230252:tid 230502] [client 109.248.148.246:38082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFXQAAAw8"]
[Tue Jul 21 07:22:37.390981 2026] [security2:error] [pid 230252:tid 230502] [client 109.248.148.246:38082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IbE0Dwhk5-Z44XrpFXQAAAw8"]
[Tue Jul 21 07:22:37.685631 2026] [security2:error] [pid 230252:tid 230499] [client 109.248.148.246:38086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9IbU0Dwhk5-Z44XrpFcAAAAww"]
[Tue Jul 21 07:22:37.685730 2026] [security2:error] [pid 230252:tid 230499] [client 109.248.148.246:38086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9IbU0Dwhk5-Z44XrpFcAAAAww"]
[Tue Jul 21 07:22:37.788719 2026] [security2:error] [pid 230252:tid 230458] [client 20.104.96.117:61062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/min.php"] [unique_id "al9IbU0Dwhk5-Z44XrpFcQAAAuM"]
[Tue Jul 21 07:22:37.820235 2026] [http2:warn] [pid 230252:tid 230461] [client 57.141.18.57:24118] h2_stream(230252-359-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:37.913685 2026] [security2:error] [pid 230252:tid 230384] [client 20.226.60.151:60281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9IbU0Dwhk5-Z44XrpFcgAAApk"]
[Tue Jul 21 07:22:37.995750 2026] [security2:error] [pid 229246:tid 229454] [client 20.206.105.145:30699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/0.php"] [unique_id "al9IbSBMYeh5YLVG45xpTwAAAmI"]
[Tue Jul 21 07:22:38.082258 2026] [security2:error] [pid 229246:tid 229382] [client 20.104.96.117:5076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9IbiBMYeh5YLVG45xpUQAAAho"]
[Tue Jul 21 07:22:38.191425 2026] [security2:error] [pid 230252:tid 230312] [remote 209.97.182.179:36134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "selleto.com.br"] [uri "/wp-login.php"] [unique_id "al9Ibk0Dwhk5-Z44XrpFdgACrjo"]
[Tue Jul 21 07:22:38.541272 2026] [security2:error] [pid 229246:tid 229455] [client 103.121.156.110:65516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IbiBMYeh5YLVG45xpWAAAAmM"]
[Tue Jul 21 07:22:38.541473 2026] [security2:error] [pid 229246:tid 229455] [client 103.121.156.110:65516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IbiBMYeh5YLVG45xpWAAAAmM"]
[Tue Jul 21 07:22:38.628587 2026] [security2:error] [pid 230252:tid 230429] [client 20.104.96.117:4175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/f6.php"] [unique_id "al9Ibk0Dwhk5-Z44XrpFgQAAAsY"]
[Tue Jul 21 07:22:38.680923 2026] [security2:error] [pid 229246:tid 229385] [client 20.151.10.161:26369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/zoro.php"] [unique_id "al9IbiBMYeh5YLVG45xpWgAAAh0"]
[Tue Jul 21 07:22:38.882972 2026] [security2:error] [pid 229246:tid 229405] [client 20.220.225.223:36820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/wp-explorer.php"] [unique_id "al9IbiBMYeh5YLVG45xpXAAAAjE"]
[Tue Jul 21 07:22:39.171708 2026] [security2:error] [pid 229246:tid 229465] [client 20.104.96.117:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/inputs.php"] [unique_id "al9IbyBMYeh5YLVG45xpZgAAAm0"]
[Tue Jul 21 07:22:39.249295 2026] [security2:error] [pid 229246:tid 229463] [client 74.249.245.134:62344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-good.php"] [unique_id "al9IbyBMYeh5YLVG45xpaAAAAms"]
[Tue Jul 21 07:22:39.280919 2026] [security2:error] [pid 229246:tid 229318] [remote 57.141.18.55:38938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9IbyBMYeh5YLVG45xpawACQUc"]
[Tue Jul 21 07:22:39.319541 2026] [security2:error] [pid 229246:tid 229446] [client 45.251.232.145:52554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IbyBMYeh5YLVG45xpbQAAAlo"]
[Tue Jul 21 07:22:39.319645 2026] [security2:error] [pid 229246:tid 229446] [client 45.251.232.145:52554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IbyBMYeh5YLVG45xpbQAAAlo"]
[Tue Jul 21 07:22:39.393803 2026] [security2:error] [pid 229246:tid 229486] [client 20.104.96.117:61059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9IbyBMYeh5YLVG45xpbgAAAoI"]
[Tue Jul 21 07:22:39.609921 2026] [security2:error] [pid 229246:tid 229457] [client 20.104.96.117:4160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/inputs.php"] [unique_id "al9IbyBMYeh5YLVG45xpdQAAAmU"]
[Tue Jul 21 07:22:39.703644 2026] [security2:error] [pid 229246:tid 229325] [remote 104.43.50.80:42439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.50.43.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/wp-login.php"] [unique_id "al9IbyBMYeh5YLVG45xpdgACK04"]
[Tue Jul 21 07:22:39.723762 2026] [http2:warn] [pid 230252:tid 230507] [client 57.141.18.22:42140] h2_stream(230252-361-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:40.008165 2026] [security2:error] [pid 230252:tid 230415] [client 20.226.60.151:60173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/qqqa.php"] [unique_id "al9IcE0Dwhk5-Z44XrpFiQAAArg"]
[Tue Jul 21 07:22:40.010741 2026] [security2:error] [pid 229246:tid 229250] [remote 216.73.160.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-login.php"] [unique_id "al9IcCBMYeh5YLVG45xpewACfAM"]
[Tue Jul 21 07:22:40.040764 2026] [security2:error] [pid 230252:tid 230459] [client 20.151.10.161:26496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/admin.php"] [unique_id "al9IcE0Dwhk5-Z44XrpFigAAAuQ"]
[Tue Jul 21 07:22:40.045039 2026] [security2:error] [pid 230252:tid 230498] [client 20.104.96.117:62969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/classwithtostring.php"] [unique_id "al9IcE0Dwhk5-Z44XrpFiwAAAws"]
[Tue Jul 21 07:22:40.196675 2026] [security2:error] [pid 229246:tid 229494] [client 20.220.225.223:59470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/akismet.php"] [unique_id "al9IcCBMYeh5YLVG45xpgQAAAoo"]
[Tue Jul 21 07:22:40.475072 2026] [security2:error] [pid 229246:tid 229379] [client 20.197.192.193:52275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/wp-signup.php"] [unique_id "al9IcCBMYeh5YLVG45xphAAAAhc"]
[Tue Jul 21 07:22:40.558721 2026] [http2:warn] [pid 230252:tid 230497] [client 57.141.18.114:49560] h2_stream(230252-364-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:40.708590 2026] [security2:error] [pid 230252:tid 230423] [client 20.104.96.117:62935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9IcE0Dwhk5-Z44XrpFjgAAAsA"]
[Tue Jul 21 07:22:40.806963 2026] [security2:error] [pid 229246:tid 229411] [client 20.206.105.145:30673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/BDKR28.php"] [unique_id "al9IcCBMYeh5YLVG45xpjAAAAjc"]
[Tue Jul 21 07:22:40.912574 2026] [security2:error] [pid 229246:tid 229478] [client 103.162.129.114:49808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IcCBMYeh5YLVG45xpjgAAAno"]
[Tue Jul 21 07:22:40.912738 2026] [security2:error] [pid 229246:tid 229478] [client 103.162.129.114:49808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IcCBMYeh5YLVG45xpjgAAAno"]
[Tue Jul 21 07:22:40.918201 2026] [security2:error] [pid 230252:tid 230489] [client 20.104.96.117:59695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9IcE0Dwhk5-Z44XrpFkAAAAwI"]
[Tue Jul 21 07:22:41.134615 2026] [security2:error] [pid 229246:tid 229387] [client 20.104.96.117:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-blog.php"] [unique_id "al9IcSBMYeh5YLVG45xpkgAAAh8"]
[Tue Jul 21 07:22:41.154254 2026] [security2:error] [pid 230252:tid 230429] [client 20.220.225.223:46125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/dp.php"] [unique_id "al9IcU0Dwhk5-Z44XrpFkwAAAsY"]
[Tue Jul 21 07:22:41.202694 2026] [security2:error] [pid 229246:tid 229257] [remote 198.244.242.59:53762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "arthromdcanada.online"] [uri "/robots.txt"] [unique_id "al9IcSBMYeh5YLVG45xplAACjgo"]
[Tue Jul 21 07:22:41.202971 2026] [security2:error] [pid 229246:tid 229498] [client 198.244.242.59:53762] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arthromdcanada.online"] [uri "/robots.txt"] [unique_id "al9IcSBMYeh5YLVG45xplAACjgo"]
[Tue Jul 21 07:22:41.484879 2026] [proxy:error] [pid 230252:tid 230504] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:41.484959 2026] [proxy_http:error] [pid 230252:tid 230504] [client 20.104.96.117:5057] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:41.485628 2026] [proxy:error] [pid 230252:tid 230504] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:41.485657 2026] [proxy_http:error] [pid 230252:tid 230504] [client 20.104.96.117:5057] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:41.586183 2026] [security2:error] [pid 229246:tid 229409] [client 20.104.96.117:59173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9IcSBMYeh5YLVG45xpmQAAAjU"]
[Tue Jul 21 07:22:41.705293 2026] [security2:error] [pid 229246:tid 229463] [client 20.226.60.151:60182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/aunmc.php"] [unique_id "al9IcSBMYeh5YLVG45xpnAAAAms"]
[Tue Jul 21 07:22:41.746638 2026] [http2:warn] [pid 230252:tid 230400] [client 57.141.18.30:34696] h2_stream(230252-367-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:41.765196 2026] [security2:error] [pid 230252:tid 230458] [client 20.226.60.151:54496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/dex.php"] [unique_id "al9IcU0Dwhk5-Z44XrpFmwAAAuM"]
[Tue Jul 21 07:22:41.927178 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:26542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/greap.php"] [unique_id "al9IcSBMYeh5YLVG45xpngAAAlo"]
[Tue Jul 21 07:22:41.990090 2026] [security2:error] [pid 229246:tid 229486] [client 20.104.96.117:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9IcSBMYeh5YLVG45xpnwAAAoI"]
[Tue Jul 21 07:22:42.098544 2026] [security2:error] [pid 230252:tid 230420] [client 117.251.86.144:57674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IcU0Dwhk5-Z44XrpFnQAAAr0"]
[Tue Jul 21 07:22:42.098775 2026] [security2:error] [pid 230252:tid 230420] [client 117.251.86.144:57674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IcU0Dwhk5-Z44XrpFnQAAAr0"]
[Tue Jul 21 07:22:42.168073 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:59708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9Ick0Dwhk5-Z44XrpFpAAAAuk"]
[Tue Jul 21 07:22:42.219047 2026] [security2:error] [pid 229246:tid 229447] [client 20.220.225.223:36829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/ace2.php"] [unique_id "al9IciBMYeh5YLVG45xppAAAAls"]
[Tue Jul 21 07:22:42.454959 2026] [security2:error] [pid 230252:tid 230323] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ick0Dwhk5-Z44XrpFqQAC5EU"]
[Tue Jul 21 07:22:42.455178 2026] [security2:error] [pid 230252:tid 230459] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ick0Dwhk5-Z44XrpFqQAC5EU"]
[Tue Jul 21 07:22:42.613513 2026] [security2:error] [pid 229246:tid 229403] [client 136.144.33.110:21443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IciBMYeh5YLVG45xpqAAAAi8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:42.621554 2026] [http2:warn] [pid 229246:tid 229497] [client 57.141.18.93:32018] h2_stream(229246-498-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:42.673554 2026] [security2:error] [pid 230252:tid 230438] [client 20.104.96.117:61181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/albin.php"] [unique_id "al9Ick0Dwhk5-Z44XrpFqwAAAs8"]
[Tue Jul 21 07:22:42.724321 2026] [security2:error] [pid 230252:tid 230503] [client 20.104.96.117:5058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ms-edit.php"] [unique_id "al9Ick0Dwhk5-Z44XrpFrQAAAxA"]
[Tue Jul 21 07:22:42.919529 2026] [security2:error] [pid 229246:tid 229355] [remote 54.39.89.167:63428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "arthromdcanada.online"] [uri "/"] [unique_id "al9IciBMYeh5YLVG45xpsQACUWw"]
[Tue Jul 21 07:22:42.919746 2026] [security2:error] [pid 229246:tid 229437] [client 54.39.89.167:63428] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arthromdcanada.online"] [uri "/"] [unique_id "al9IciBMYeh5YLVG45xpsQACUWw"]
[Tue Jul 21 07:22:43.002411 2026] [security2:error] [pid 229246:tid 229494] [client 20.104.96.117:61175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/cilus.php"] [unique_id "al9IcyBMYeh5YLVG45xpsgAAAoo"]
[Tue Jul 21 07:22:43.057022 2026] [security2:error] [pid 229246:tid 229452] [client 20.220.225.223:60090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "irrigaplus.com.br"] [uri "/ms.php"] [unique_id "al9IcyBMYeh5YLVG45xptAAAAmA"]
[Tue Jul 21 07:22:43.213223 2026] [security2:error] [pid 230252:tid 230412] [client 20.104.96.117:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Ic00Dwhk5-Z44XrpFsQAAArU"]
[Tue Jul 21 07:22:43.291504 2026] [security2:error] [pid 230252:tid 230429] [client 20.226.60.151:60169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/uoocf.php"] [unique_id "al9Ic00Dwhk5-Z44XrpFtAAAAsY"]
[Tue Jul 21 07:22:43.294962 2026] [security2:error] [pid 230252:tid 230436] [client 20.206.105.145:30680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/f35.update.php"] [unique_id "al9Ic00Dwhk5-Z44XrpFtQAAAs0"]
[Tue Jul 21 07:22:43.321489 2026] [security2:error] [pid 229246:tid 229321] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IcyBMYeh5YLVG45xpuwACV0o"]
[Tue Jul 21 07:22:43.321639 2026] [security2:error] [pid 229246:tid 229443] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IcyBMYeh5YLVG45xpuwACV0o"]
[Tue Jul 21 07:22:43.388990 2026] [security2:error] [pid 230252:tid 230389] [client 20.151.10.161:26515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/177.php"] [unique_id "al9Ic00Dwhk5-Z44XrpFtgAAAp4"]
[Tue Jul 21 07:22:43.516464 2026] [security2:error] [pid 230252:tid 230508] [client 20.104.96.117:61156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/gptsh.php"] [unique_id "al9Ic00Dwhk5-Z44XrpFuwAAAxU"]
[Tue Jul 21 07:22:43.757913 2026] [security2:error] [pid 229246:tid 229352] [remote 199.189.225.40:48641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9IcyBMYeh5YLVG45xpxQACMWk"]
[Tue Jul 21 07:22:43.820888 2026] [security2:error] [pid 229246:tid 229387] [client 20.104.96.117:61113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/rithin.php"] [unique_id "al9IcyBMYeh5YLVG45xpyAAAAh8"]
[Tue Jul 21 07:22:43.892908 2026] [proxy:error] [pid 229246:tid 229434] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:43.892983 2026] [proxy_http:error] [pid 229246:tid 229434] [client 20.104.96.117:64057] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:43.893634 2026] [proxy:error] [pid 229246:tid 229434] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:43.893663 2026] [proxy_http:error] [pid 229246:tid 229434] [client 20.104.96.117:64057] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:44.098204 2026] [security2:error] [pid 230252:tid 230478] [client 20.151.10.161:26399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/199.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFwAAAAvc"]
[Tue Jul 21 07:22:44.122170 2026] [security2:error] [pid 229246:tid 229472] [client 20.104.96.117:59692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/fffm.php"] [unique_id "al9IdCBMYeh5YLVG45xpzQAAAnQ"]
[Tue Jul 21 07:22:44.153912 2026] [security2:error] [pid 230252:tid 230362] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFwgACxGs"]
[Tue Jul 21 07:22:44.154150 2026] [security2:error] [pid 230252:tid 230427] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFwgACxGs"]
[Tue Jul 21 07:22:44.200165 2026] [security2:error] [pid 229246:tid 229426] [client 20.206.105.145:30546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/f900.php"] [unique_id "al9IdCBMYeh5YLVG45xpzgAAAkY"]
[Tue Jul 21 07:22:44.250027 2026] [security2:error] [pid 229246:tid 229310] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IdCBMYeh5YLVG45xp1gACPj8"]
[Tue Jul 21 07:22:44.250157 2026] [security2:error] [pid 229246:tid 229418] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IdCBMYeh5YLVG45xp1gACPj8"]
[Tue Jul 21 07:22:44.292557 2026] [security2:error] [pid 229246:tid 229400] [client 20.197.192.193:53122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/csa.php"] [unique_id "al9IdCBMYeh5YLVG45xp1wAAAiw"]
[Tue Jul 21 07:22:44.485042 2026] [security2:error] [pid 230252:tid 230387] [client 20.104.96.117:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFxwAAApw"]
[Tue Jul 21 07:22:44.537948 2026] [security2:error] [pid 230252:tid 230394] [client 20.104.96.117:61123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/dfre.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFyAAAAqM"]
[Tue Jul 21 07:22:44.584310 2026] [security2:error] [pid 230252:tid 230469] [client 103.174.34.15:50715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFygAAAu4"]
[Tue Jul 21 07:22:44.599156 2026] [security2:error] [pid 230252:tid 230469] [client 103.174.34.15:50715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFygAAAu4"]
[Tue Jul 21 07:22:44.688948 2026] [security2:error] [pid 230252:tid 230338] [remote 157.66.26.183:43862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFywAC7FM"]
[Tue Jul 21 07:22:44.804175 2026] [security2:error] [pid 229246:tid 229471] [client 20.151.10.161:26445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file52.php"] [unique_id "al9IdCBMYeh5YLVG45xp4AAAAnM"]
[Tue Jul 21 07:22:44.867896 2026] [security2:error] [pid 230252:tid 230403] [client 20.104.96.117:59704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-happy.php"] [unique_id "al9IdE0Dwhk5-Z44XrpFzQAAAqw"]
[Tue Jul 21 07:22:44.956675 2026] [http2:warn] [pid 229246:tid 229456] [client 57.141.18.47:60312] h2_stream(229246-502-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:45.149115 2026] [proxy:error] [pid 230252:tid 230386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:45.149199 2026] [proxy_http:error] [pid 230252:tid 230386] [client 20.104.96.117:64026] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:45.149781 2026] [proxy:error] [pid 230252:tid 230386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:45.149822 2026] [proxy_http:error] [pid 230252:tid 230386] [client 20.104.96.117:64026] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:45.152728 2026] [security2:error] [pid 230252:tid 230335] [remote 45.117.83.212:50196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/wp-login.php"] [unique_id "al9IdU0Dwhk5-Z44XrpF0wACx1A"]
[Tue Jul 21 07:22:45.162380 2026] [security2:error] [pid 230252:tid 230432] [client 20.220.225.223:46006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/old.php"] [unique_id "al9IdU0Dwhk5-Z44XrpF1AAAAsk"]
[Tue Jul 21 07:22:45.245084 2026] [security2:error] [pid 230252:tid 230504] [client 20.104.96.117:59153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/fpr4.php"] [unique_id "al9IdU0Dwhk5-Z44XrpF1QAAAxE"]
[Tue Jul 21 07:22:45.271665 2026] [security2:error] [pid 230252:tid 230491] [client 20.206.105.145:30616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/xmrl.php"] [unique_id "al9IdU0Dwhk5-Z44XrpF1gAAAwQ"]
[Tue Jul 21 07:22:45.314968 2026] [security2:error] [pid 230252:tid 230301] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IdU0Dwhk5-Z44XrpF1wAC0y8"]
[Tue Jul 21 07:22:45.315188 2026] [security2:error] [pid 230252:tid 230442] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IdU0Dwhk5-Z44XrpF1wAC0y8"]
[Tue Jul 21 07:22:45.422085 2026] [security2:error] [pid 229246:tid 229382] [client 20.226.60.151:60242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/iywwi.php"] [unique_id "al9IdSBMYeh5YLVG45xp6gAAAho"]
[Tue Jul 21 07:22:45.913517 2026] [security2:error] [pid 230252:tid 230387] [client 20.104.96.117:60946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/file88.php"] [unique_id "al9IdU0Dwhk5-Z44XrpF3wAAApw"]
[Tue Jul 21 07:22:46.028839 2026] [http2:warn] [pid 230252:tid 230388] [client 57.141.18.116:25528] h2_stream(230252-382-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:46.060749 2026] [security2:error] [pid 230252:tid 230480] [client 20.226.60.151:60200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/gqgsa.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF4wAAAvk"]
[Tue Jul 21 07:22:46.088888 2026] [security2:error] [pid 230252:tid 230418] [client 74.249.245.134:60747] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "drjoaoguedes.com"] [uri "/.info.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF5AAAArs"]
[Tue Jul 21 07:22:46.212499 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:26513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/122.php"] [unique_id "al9IdiBMYeh5YLVG45xp8wAAAnk"]
[Tue Jul 21 07:22:46.225576 2026] [security2:error] [pid 229246:tid 229492] [client 20.206.105.145:30534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/memberfuns.php"] [unique_id "al9IdiBMYeh5YLVG45xp9AAAAog"]
[Tue Jul 21 07:22:46.283466 2026] [proxy:error] [pid 229246:tid 229441] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:46.283537 2026] [proxy_http:error] [pid 229246:tid 229441] [client 20.104.96.117:64037] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:46.284256 2026] [proxy:error] [pid 229246:tid 229441] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:46.284295 2026] [proxy_http:error] [pid 229246:tid 229441] [client 20.104.96.117:64037] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:46.406151 2026] [security2:error] [pid 230252:tid 230477] [client 175.45.70.82:56849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF5gAAAvY"]
[Tue Jul 21 07:22:46.406245 2026] [security2:error] [pid 230252:tid 230477] [client 175.45.70.82:56849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF5gAAAvY"]
[Tue Jul 21 07:22:46.429724 2026] [security2:error] [pid 229246:tid 229260] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IdiBMYeh5YLVG45xp-wACbg0"]
[Tue Jul 21 07:22:46.429896 2026] [security2:error] [pid 229246:tid 229466] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IdiBMYeh5YLVG45xp-wACbg0"]
[Tue Jul 21 07:22:46.529577 2026] [security2:error] [pid 230252:tid 230459] [client 20.220.225.223:34268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/mimpi.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF5wAAAuQ"]
[Tue Jul 21 07:22:46.594521 2026] [security2:error] [pid 230252:tid 230487] [client 74.249.245.134:50272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/item.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF6QAAAwA"]
[Tue Jul 21 07:22:46.743600 2026] [security2:error] [pid 230252:tid 230476] [client 20.104.96.117:59649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ccc.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF6gAAAvU"]
[Tue Jul 21 07:22:46.821553 2026] [security2:error] [pid 229246:tid 229487] [client 20.151.10.161:26426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/green1.php"] [unique_id "al9IdiBMYeh5YLVG45xp_gAAAoM"]
[Tue Jul 21 07:22:46.849061 2026] [http2:warn] [pid 229246:tid 229496] [client 57.141.18.42:65424] h2_stream(229246-504-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:46.956480 2026] [security2:error] [pid 230252:tid 230436] [client 20.104.96.117:62946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/abcd.php"] [unique_id "al9Idk0Dwhk5-Z44XrpF6wAAAs0"]
[Tue Jul 21 07:22:47.018906 2026] [security2:error] [pid 229246:tid 229413] [client 14.139.42.196:7606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IdyBMYeh5YLVG45xqBAAAAjk"]
[Tue Jul 21 07:22:47.019026 2026] [security2:error] [pid 229246:tid 229413] [client 14.139.42.196:7606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IdyBMYeh5YLVG45xqBAAAAjk"]
[Tue Jul 21 07:22:47.217069 2026] [security2:error] [pid 230252:tid 230455] [client 20.206.105.145:30686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/ms.php"] [unique_id "al9Id00Dwhk5-Z44XrpF7AAAAuA"]
[Tue Jul 21 07:22:47.256113 2026] [security2:error] [pid 229246:tid 229419] [client 20.226.60.151:60245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/elbzl.php"] [unique_id "al9IdyBMYeh5YLVG45xqBgAAAj8"]
[Tue Jul 21 07:22:47.355801 2026] [security2:error] [pid 230252:tid 230458] [client 136.144.33.28:24257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Id00Dwhk5-Z44XrpF7QAAAuM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:47.553333 2026] [security2:error] [pid 230252:tid 230499] [client 20.151.10.161:26427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/biufile.php"] [unique_id "al9Id00Dwhk5-Z44XrpF8AAAAww"]
[Tue Jul 21 07:22:47.649296 2026] [security2:error] [pid 230252:tid 230471] [client 20.104.96.117:5069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/file15.php"] [unique_id "al9Id00Dwhk5-Z44XrpF8gAAAvA"]
[Tue Jul 21 07:22:47.692340 2026] [security2:error] [pid 229246:tid 229499] [client 139.135.44.145:54843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IdyBMYeh5YLVG45xqCwAAAo8"]
[Tue Jul 21 07:22:47.692485 2026] [security2:error] [pid 229246:tid 229499] [client 139.135.44.145:54843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IdyBMYeh5YLVG45xqCwAAAo8"]
[Tue Jul 21 07:22:47.774461 2026] [security2:error] [pid 230252:tid 230416] [client 20.206.105.145:30551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/zz.php"] [unique_id "al9Id00Dwhk5-Z44XrpF9AAAArk"]
[Tue Jul 21 07:22:47.797154 2026] [security2:error] [pid 230252:tid 230440] [client 109.248.148.246:43020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Id00Dwhk5-Z44XrpF9QAAAtE"]
[Tue Jul 21 07:22:47.797248 2026] [security2:error] [pid 230252:tid 230440] [client 109.248.148.246:43020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Id00Dwhk5-Z44XrpF9QAAAtE"]
[Tue Jul 21 07:22:47.824887 2026] [security2:error] [pid 230252:tid 230478] [client 20.226.60.151:60238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/adjig.php"] [unique_id "al9Id00Dwhk5-Z44XrpF9gAAAvc"]
[Tue Jul 21 07:22:47.838561 2026] [security2:error] [pid 230252:tid 230427] [client 20.104.96.117:61166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/777.php"] [unique_id "al9Id00Dwhk5-Z44XrpF9wAAAsQ"]
[Tue Jul 21 07:22:48.206870 2026] [security2:error] [pid 229246:tid 229437] [client 20.206.105.145:30570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/for.php"] [unique_id "al9IeCBMYeh5YLVG45xqEQAAAlE"]
[Tue Jul 21 07:22:48.274420 2026] [security2:error] [pid 229246:tid 229502] [client 20.197.192.193:53128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/min.php"] [unique_id "al9IeCBMYeh5YLVG45xqEgAAApI"]
[Tue Jul 21 07:22:48.432926 2026] [access_compat:error] [pid 229246:tid 229500] [client 162.241.63.68:31320] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:22:48.499184 2026] [security2:error] [pid 230252:tid 230476] [client 20.206.105.145:30531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/yup.php"] [unique_id "al9IeE0Dwhk5-Z44XrpF_wAAAvU"]
[Tue Jul 21 07:22:48.570217 2026] [security2:error] [pid 230252:tid 230436] [client 20.226.60.151:60279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/byp.php"] [unique_id "al9IeE0Dwhk5-Z44XrpGAgAAAs0"]
[Tue Jul 21 07:22:48.640218 2026] [security2:error] [pid 230252:tid 230430] [client 20.104.96.117:62955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/jp.php"] [unique_id "al9IeE0Dwhk5-Z44XrpGBQAAAsc"]
[Tue Jul 21 07:22:48.659052 2026] [security2:error] [pid 230252:tid 230432] [client 20.151.10.161:26531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wpconf.php"] [unique_id "al9IeE0Dwhk5-Z44XrpGBwAAAsk"]
[Tue Jul 21 07:22:48.707769 2026] [http2:warn] [pid 230252:tid 230425] [client 57.141.18.90:23544] h2_stream(230252-391-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:48.777407 2026] [security2:error] [pid 230252:tid 230465] [client 194.147.58.101:39978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "ns1102.hostgator.com.br"] [uri "/core/ajax/user.ajax.php"] [unique_id "al9IeE0Dwhk5-Z44XrpGCwAAAuo"]
[Tue Jul 21 07:22:48.857394 2026] [security2:error] [pid 229246:tid 229412] [client 20.226.60.151:60215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9IeCBMYeh5YLVG45xqGgAAAjg"]
[Tue Jul 21 07:22:48.859026 2026] [security2:error] [pid 230252:tid 230412] [client 20.206.105.145:30598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/wpxml.php"] [unique_id "al9IeE0Dwhk5-Z44XrpGDQAAArU"]
[Tue Jul 21 07:22:48.979186 2026] [security2:error] [pid 230252:tid 230442] [client 20.226.60.151:60273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/classwithtostring.php"] [unique_id "al9IeE0Dwhk5-Z44XrpGDwAAAtM"]
[Tue Jul 21 07:22:49.039235 2026] [security2:error] [pid 229246:tid 229431] [client 20.104.96.117:61136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/for.php"] [unique_id "al9IeSBMYeh5YLVG45xqIQAAAks"]
[Tue Jul 21 07:22:49.048141 2026] [security2:error] [pid 230252:tid 230483] [client 20.220.225.223:46003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ms-new.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGEAAAAvw"]
[Tue Jul 21 07:22:49.097289 2026] [security2:error] [pid 229246:tid 229387] [client 20.206.105.145:30571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/fffm.php"] [unique_id "al9IeSBMYeh5YLVG45xqJQAAAh8"]
[Tue Jul 21 07:22:49.172037 2026] [security2:error] [pid 229246:tid 229441] [client 20.206.105.145:30649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/gecko.php"] [unique_id "al9IeSBMYeh5YLVG45xqJwAAAlU"]
[Tue Jul 21 07:22:49.273293 2026] [security2:error] [pid 230252:tid 230455] [client 103.121.156.110:49458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGEgAAAuA"]
[Tue Jul 21 07:22:49.273430 2026] [security2:error] [pid 230252:tid 230455] [client 103.121.156.110:49458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGEgAAAuA"]
[Tue Jul 21 07:22:49.433294 2026] [security2:error] [pid 230252:tid 230497] [client 20.206.105.145:30642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/a1.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGFgAAAwo"]
[Tue Jul 21 07:22:49.585040 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.105.145:30544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/k2.php"] [unique_id "al9IeSBMYeh5YLVG45xqLQAAAms"]
[Tue Jul 21 07:22:49.586472 2026] [security2:error] [pid 230252:tid 230385] [client 20.226.60.151:60194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/root.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGGQAAApo"]
[Tue Jul 21 07:22:49.644023 2026] [security2:error] [pid 230252:tid 230468] [client 20.104.96.117:64059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/f35.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGGgAAAu0"]
[Tue Jul 21 07:22:49.774480 2026] [security2:error] [pid 230252:tid 230477] [client 20.206.105.145:30576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/82.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGGwAAAvY"]
[Tue Jul 21 07:22:49.802310 2026] [security2:error] [pid 230252:tid 230420] [client 45.251.232.145:53077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGHAAAAr0"]
[Tue Jul 21 07:22:49.802428 2026] [security2:error] [pid 230252:tid 230420] [client 45.251.232.145:53077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IeU0Dwhk5-Z44XrpGHAAAAr0"]
[Tue Jul 21 07:22:49.807764 2026] [security2:error] [pid 229246:tid 229401] [client 20.104.96.117:59168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/ssla.php"] [unique_id "al9IeSBMYeh5YLVG45xqMAAAAi0"]
[Tue Jul 21 07:22:50.009530 2026] [security2:error] [pid 230252:tid 230503] [client 109.248.148.246:46824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Iek0Dwhk5-Z44XrpGHQAAAxA"]
[Tue Jul 21 07:22:50.009625 2026] [security2:error] [pid 230252:tid 230503] [client 109.248.148.246:46824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Iek0Dwhk5-Z44XrpGHQAAAxA"]
[Tue Jul 21 07:22:50.011217 2026] [security2:error] [pid 230252:tid 230476] [client 20.206.105.145:30702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/config.json.php"] [unique_id "al9Iek0Dwhk5-Z44XrpGHgAAAvU"]
[Tue Jul 21 07:22:50.182145 2026] [security2:error] [pid 230252:tid 230436] [client 62.102.148.164:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Iek0Dwhk5-Z44XrpGHwAAAs0"]
[Tue Jul 21 07:22:50.182253 2026] [security2:error] [pid 230252:tid 230436] [client 62.102.148.164:54212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Iek0Dwhk5-Z44XrpGHwAAAs0"]
[Tue Jul 21 07:22:50.367455 2026] [security2:error] [pid 229246:tid 229485] [client 20.104.96.117:64051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-load.php"] [unique_id "al9IeiBMYeh5YLVG45xqSwAAAoE"]
[Tue Jul 21 07:22:50.371872 2026] [security2:error] [pid 229246:tid 229458] [client 20.226.60.151:60232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/sym403.php"] [unique_id "al9IeiBMYeh5YLVG45xqTAAAAmY"]
[Tue Jul 21 07:22:50.377150 2026] [http2:warn] [pid 229246:tid 229386] [client 57.141.18.81:30240] h2_stream(229246-507-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:50.412303 2026] [security2:error] [pid 230252:tid 230506] [client 20.206.105.145:30568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.psicologafernandaguedes.com"] [uri "/fpwch.php"] [unique_id "al9Iek0Dwhk5-Z44XrpGJQAAAxM"]
[Tue Jul 21 07:22:50.691246 2026] [security2:error] [pid 230252:tid 230416] [client 20.226.60.151:60193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/v543.php"] [unique_id "al9Iek0Dwhk5-Z44XrpGKAAAArk"]
[Tue Jul 21 07:22:50.726782 2026] [security2:error] [pid 229246:tid 229495] [client 20.104.96.117:59196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/zc-131.php"] [unique_id "al9IeiBMYeh5YLVG45xqUgAAAos"]
[Tue Jul 21 07:22:50.824321 2026] [security2:error] [pid 229246:tid 229350] [remote 182.77.62.24:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojadedoces.com"] [uri "/wp-login.php"] [unique_id "al9IeiBMYeh5YLVG45xqXwACK2c"]
[Tue Jul 21 07:22:51.135791 2026] [security2:error] [pid 230252:tid 230473] [client 20.151.10.161:26437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/mosty.php"] [unique_id "al9Ie00Dwhk5-Z44XrpGKgAAAvI"]
[Tue Jul 21 07:22:51.227985 2026] [security2:error] [pid 229246:tid 229483] [client 20.226.60.151:50764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/sixxis.php"] [unique_id "al9IeyBMYeh5YLVG45xqaQAAAn8"]
[Tue Jul 21 07:22:51.278152 2026] [security2:error] [pid 230252:tid 230511] [client 20.197.192.193:52244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/echkm.php"] [unique_id "al9Ie00Dwhk5-Z44XrpGMQAAAxg"]
[Tue Jul 21 07:22:51.622406 2026] [http2:warn] [pid 230252:tid 230413] [client 57.141.18.113:24270] h2_stream(230252-395-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:51.625526 2026] [security2:error] [pid 229246:tid 229304] [remote 150.95.80.135:51516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.80.95.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "health-24.shop"] [uri "/wp-login.php"] [unique_id "al9IeyBMYeh5YLVG45xqcAACTTk"]
[Tue Jul 21 07:22:51.677193 2026] [security2:error] [pid 230252:tid 230497] [client 103.162.129.114:50284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ie00Dwhk5-Z44XrpGOAAAAwo"]
[Tue Jul 21 07:22:51.677311 2026] [security2:error] [pid 230252:tid 230497] [client 103.162.129.114:50284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ie00Dwhk5-Z44XrpGOAAAAwo"]
[Tue Jul 21 07:22:51.960806 2026] [security2:error] [pid 229246:tid 229486] [client 20.104.96.117:64012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/xyn.php"] [unique_id "al9IeyBMYeh5YLVG45xqdwAAAoI"]
[Tue Jul 21 07:22:52.107208 2026] [security2:error] [pid 229246:tid 229466] [client 14.139.42.196:4393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfCBMYeh5YLVG45xqegAAAm4"]
[Tue Jul 21 07:22:52.107314 2026] [security2:error] [pid 229246:tid 229466] [client 14.139.42.196:4393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfCBMYeh5YLVG45xqegAAAm4"]
[Tue Jul 21 07:22:52.235449 2026] [security2:error] [pid 230252:tid 230503] [client 117.251.86.144:38726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IfE0Dwhk5-Z44XrpGPAAAAxA"]
[Tue Jul 21 07:22:52.235584 2026] [security2:error] [pid 230252:tid 230503] [client 117.251.86.144:38726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IfE0Dwhk5-Z44XrpGPAAAAxA"]
[Tue Jul 21 07:22:52.510260 2026] [security2:error] [pid 230252:tid 230433] [client 136.144.33.104:26843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IfE0Dwhk5-Z44XrpGPQAAAso"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:52.606365 2026] [security2:error] [pid 230252:tid 230440] [client 20.226.60.151:60223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ip.php"] [unique_id "al9IfE0Dwhk5-Z44XrpGPwAAAtE"]
[Tue Jul 21 07:22:52.865178 2026] [http2:warn] [pid 229246:tid 229410] [client 57.141.18.16:35932] h2_stream(229246-513-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:53.179438 2026] [security2:error] [pid 230252:tid 230458] [client 20.226.60.151:54471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/xpwer1.php"] [unique_id "al9IfU0Dwhk5-Z44XrpGRAAAAuM"]
[Tue Jul 21 07:22:53.280915 2026] [security2:error] [pid 229246:tid 229357] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IfSBMYeh5YLVG45xqmQACMm4"]
[Tue Jul 21 07:22:53.281073 2026] [security2:error] [pid 229246:tid 229406] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IfSBMYeh5YLVG45xqmQACMm4"]
[Tue Jul 21 07:22:53.387847 2026] [http2:warn] [pid 230252:tid 230435] [client 57.141.18.98:20822] h2_stream(230252-401-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:53.845919 2026] [security2:error] [pid 230252:tid 230385] [client 20.226.60.151:60171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/kq1.php"] [unique_id "al9IfU0Dwhk5-Z44XrpGTgAAApo"]
[Tue Jul 21 07:22:53.863665 2026] [security2:error] [pid 229246:tid 229374] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfSBMYeh5YLVG45xqoAACjn8"]
[Tue Jul 21 07:22:53.863808 2026] [security2:error] [pid 229246:tid 229498] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfSBMYeh5YLVG45xqoAACjn8"]
[Tue Jul 21 07:22:54.198284 2026] [security2:error] [pid 229246:tid 229501] [client 20.151.10.161:26383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/dejavu.php"] [unique_id "al9IfiBMYeh5YLVG45xqowAAApE"]
[Tue Jul 21 07:22:54.472057 2026] [security2:error] [pid 230252:tid 230483] [client 74.249.245.134:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/albin.php"] [unique_id "al9Ifk0Dwhk5-Z44XrpGVgAAAvw"]
[Tue Jul 21 07:22:54.731733 2026] [security2:error] [pid 229246:tid 229364] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfiBMYeh5YLVG45xqrgACiHU"]
[Tue Jul 21 07:22:54.731878 2026] [security2:error] [pid 229246:tid 229492] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfiBMYeh5YLVG45xqrgACiHU"]
[Tue Jul 21 07:22:54.775063 2026] [proxy:error] [pid 230252:tid 230400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:54.775151 2026] [proxy_http:error] [pid 230252:tid 230400] [client 20.104.96.117:4190] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:54.775742 2026] [proxy:error] [pid 230252:tid 230400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:54.775769 2026] [proxy_http:error] [pid 230252:tid 230400] [client 20.104.96.117:4190] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:54.867386 2026] [http2:warn] [pid 230252:tid 230401] [client 57.141.18.121:44834] h2_stream(230252-405-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:54.989522 2026] [security2:error] [pid 229246:tid 229287] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IfiBMYeh5YLVG45xqswACKig"]
[Tue Jul 21 07:22:54.989708 2026] [security2:error] [pid 229246:tid 229398] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IfiBMYeh5YLVG45xqswACKig"]
[Tue Jul 21 07:22:55.355344 2026] [security2:error] [pid 230252:tid 230489] [client 213.152.162.104:43166] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Ifk0Dwhk5-Z44XrpGVAAAAwI"]
[Tue Jul 21 07:22:55.355466 2026] [security2:error] [pid 230252:tid 230489] [client 213.152.162.104:43166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Ifk0Dwhk5-Z44XrpGVAAAAwI"]
[Tue Jul 21 07:22:55.409698 2026] [security2:error] [pid 229246:tid 229447] [client 103.174.34.15:51186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfyBMYeh5YLVG45xqtwAAAls"]
[Tue Jul 21 07:22:55.409881 2026] [security2:error] [pid 229246:tid 229447] [client 103.174.34.15:51186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IfyBMYeh5YLVG45xqtwAAAls"]
[Tue Jul 21 07:22:55.523176 2026] [security2:error] [pid 229246:tid 229402] [client 20.220.225.223:46107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/track.php"] [unique_id "al9IfyBMYeh5YLVG45xqugAAAi4"]
[Tue Jul 21 07:22:55.530688 2026] [security2:error] [pid 230252:tid 230480] [client 20.226.60.151:60162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9If00Dwhk5-Z44XrpGWwAAAvk"]
[Tue Jul 21 07:22:55.537276 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:49124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9If00Dwhk5-Z44XrpGXAAAAwY"]
[Tue Jul 21 07:22:55.713621 2026] [security2:error] [pid 230252:tid 230481] [client 82.102.28.107:33530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9If00Dwhk5-Z44XrpGXQAAAvo"]
[Tue Jul 21 07:22:55.713740 2026] [security2:error] [pid 230252:tid 230481] [client 82.102.28.107:33530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9If00Dwhk5-Z44XrpGXQAAAvo"]
[Tue Jul 21 07:22:55.793387 2026] [security2:error] [pid 230252:tid 230394] [client 109.248.148.246:46840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9If00Dwhk5-Z44XrpGXgAAAqM"]
[Tue Jul 21 07:22:55.793494 2026] [security2:error] [pid 230252:tid 230394] [client 109.248.148.246:46840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9If00Dwhk5-Z44XrpGXgAAAqM"]
[Tue Jul 21 07:22:56.091846 2026] [security2:error] [pid 230252:tid 230487] [client 20.151.10.161:26546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/aaf.php"] [unique_id "al9IgE0Dwhk5-Z44XrpGYAAAAwA"]
[Tue Jul 21 07:22:56.140212 2026] [security2:error] [pid 229246:tid 229318] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IgCBMYeh5YLVG45xqxAACXkc"]
[Tue Jul 21 07:22:56.140357 2026] [security2:error] [pid 229246:tid 229450] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IgCBMYeh5YLVG45xqxAACXkc"]
[Tue Jul 21 07:22:56.306803 2026] [security2:error] [pid 230252:tid 230412] [client 62.102.148.164:46154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9IgE0Dwhk5-Z44XrpGZgAAArU"]
[Tue Jul 21 07:22:56.306911 2026] [security2:error] [pid 230252:tid 230412] [client 62.102.148.164:46154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9IgE0Dwhk5-Z44XrpGZgAAArU"]
[Tue Jul 21 07:22:56.389724 2026] [security2:error] [pid 229246:tid 229382] [client 190.92.174.183:46570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IgCBMYeh5YLVG45xqyQAAAho"]
[Tue Jul 21 07:22:56.389840 2026] [security2:error] [pid 229246:tid 229382] [client 190.92.174.183:46570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IgCBMYeh5YLVG45xqyQAAAho"]
[Tue Jul 21 07:22:56.510366 2026] [security2:error] [pid 229246:tid 229408] [client 128.140.106.114:20642] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9IgCBMYeh5YLVG45xqzwAAAjQ"], referer: https://artetoner.com.br
[Tue Jul 21 07:22:56.731167 2026] [http2:warn] [pid 230252:tid 230488] [client 57.141.18.69:33188] h2_stream(230252-409-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:56.766008 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:26412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/term.php"] [unique_id "al9IgE0Dwhk5-Z44XrpGbQAAAtE"]
[Tue Jul 21 07:22:56.975350 2026] [security2:error] [pid 230252:tid 230368] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IgE0Dwhk5-Z44XrpGcQACmXE"]
[Tue Jul 21 07:22:56.975559 2026] [security2:error] [pid 230252:tid 230384] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IgE0Dwhk5-Z44XrpGcQACmXE"]
[Tue Jul 21 07:22:57.021002 2026] [security2:error] [pid 230252:tid 230388] [client 190.92.174.183:46584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IgU0Dwhk5-Z44XrpGdAAAAp0"]
[Tue Jul 21 07:22:57.021135 2026] [security2:error] [pid 230252:tid 230388] [client 190.92.174.183:46584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IgU0Dwhk5-Z44XrpGdAAAAp0"]
[Tue Jul 21 07:22:57.238071 2026] [security2:error] [pid 230252:tid 230461] [client 175.45.70.82:57354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IgU0Dwhk5-Z44XrpGegAAAuY"]
[Tue Jul 21 07:22:57.238217 2026] [security2:error] [pid 230252:tid 230461] [client 175.45.70.82:57354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IgU0Dwhk5-Z44XrpGegAAAuY"]
[Tue Jul 21 07:22:57.258848 2026] [security2:error] [pid 230252:tid 230511] [client 20.220.225.223:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/2352356666.php"] [unique_id "al9IgU0Dwhk5-Z44XrpGfAAAAxg"]
[Tue Jul 21 07:22:57.264228 2026] [security2:error] [pid 229246:tid 229385] [client 20.151.10.161:26517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ha.php"] [unique_id "al9IgSBMYeh5YLVG45xq1gAAAh0"]
[Tue Jul 21 07:22:57.408023 2026] [proxy:error] [pid 230252:tid 230425] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:57.408098 2026] [proxy_http:error] [pid 230252:tid 230425] [client 20.104.96.117:4184] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:57.408609 2026] [proxy:error] [pid 230252:tid 230425] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:22:57.408644 2026] [proxy_http:error] [pid 230252:tid 230425] [client 20.104.96.117:4184] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:22:57.452796 2026] [security2:error] [pid 230252:tid 230405] [client 193.36.225.10:48545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IgU0Dwhk5-Z44XrpGgAAAAq4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:22:57.489367 2026] [security2:error] [pid 230252:tid 230438] [client 20.226.60.151:60263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/h02ugyh.php"] [unique_id "al9IgU0Dwhk5-Z44XrpGgQAAAs8"]
[Tue Jul 21 07:22:57.531981 2026] [http2:warn] [pid 230252:tid 230424] [client 57.141.18.76:54994] h2_stream(230252-413-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:57.899609 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:26411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/hur.php"] [unique_id "al9IgSBMYeh5YLVG45xq2wAAAns"]
[Tue Jul 21 07:22:58.118393 2026] [security2:error] [pid 229246:tid 229386] [client 20.151.10.161:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IgiBMYeh5YLVG45xq4QAAAh4"]
[Tue Jul 21 07:22:58.373554 2026] [security2:error] [pid 230252:tid 230442] [client 20.151.10.161:26524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/h02ugyh.php"] [unique_id "al9Igk0Dwhk5-Z44XrpGnAAAAtM"]
[Tue Jul 21 07:22:58.401992 2026] [security2:error] [pid 229246:tid 229413] [client 20.104.96.117:5101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ccc.php"] [unique_id "al9IgiBMYeh5YLVG45xq5gAAAjk"]
[Tue Jul 21 07:22:58.521074 2026] [security2:error] [pid 230252:tid 230465] [client 20.226.60.151:61090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/flox.php"] [unique_id "al9Igk0Dwhk5-Z44XrpGnQAAAuo"]
[Tue Jul 21 07:22:58.646661 2026] [security2:error] [pid 229246:tid 229448] [client 139.135.44.145:53697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IgiBMYeh5YLVG45xq6gAAAlw"]
[Tue Jul 21 07:22:58.646793 2026] [security2:error] [pid 229246:tid 229448] [client 139.135.44.145:53697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IgiBMYeh5YLVG45xq6gAAAlw"]
[Tue Jul 21 07:22:59.084766 2026] [security2:error] [pid 229246:tid 229422] [client 20.226.60.151:60181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-temp.php"] [unique_id "al9IgyBMYeh5YLVG45xq8AAAAkI"]
[Tue Jul 21 07:22:59.189662 2026] [http2:warn] [pid 230252:tid 230501] [client 57.141.18.112:64614] h2_stream(230252-423-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:22:59.388059 2026] [security2:error] [pid 229246:tid 229437] [client 74.249.245.134:50255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/alfa.php"] [unique_id "al9IgyBMYeh5YLVG45xq8wAAAlE"]
[Tue Jul 21 07:22:59.602824 2026] [security2:error] [pid 230252:tid 230473] [client 20.151.10.161:26414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/seiso.php"] [unique_id "al9Ig00Dwhk5-Z44XrpGrAAAAvI"]
[Tue Jul 21 07:22:59.613545 2026] [security2:error] [pid 230252:tid 230346] [remote 192.241.143.148:35606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bestsellerdigital.com.br"] [uri "/wp-login.php"] [unique_id "al9Ig00Dwhk5-Z44XrpGrQAC41s"]
[Tue Jul 21 07:22:59.822565 2026] [security2:error] [pid 230252:tid 230488] [client 20.197.192.193:53170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/mac.php"] [unique_id "al9Ig00Dwhk5-Z44XrpGsQAAAwE"]
[Tue Jul 21 07:22:59.875647 2026] [security2:error] [pid 230252:tid 230476] [client 20.104.96.117:64041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/w.php"] [unique_id "al9Ig00Dwhk5-Z44XrpGswAAAvU"]
[Tue Jul 21 07:22:59.940026 2026] [security2:error] [pid 230252:tid 230493] [client 103.121.156.110:49793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Ig00Dwhk5-Z44XrpGtQAAAwY"]
[Tue Jul 21 07:22:59.940174 2026] [security2:error] [pid 230252:tid 230493] [client 103.121.156.110:49793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Ig00Dwhk5-Z44XrpGtQAAAwY"]
[Tue Jul 21 07:23:00.003163 2026] [core:error] [pid 230252:tid 230333] [remote 87.250.224.96:63146] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:23:00.003193 2026] [core:error] [pid 230252:tid 230333] [remote 87.250.224.96:63146] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:23:00.255730 2026] [security2:error] [pid 230252:tid 230461] [client 45.251.232.145:53588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IhE0Dwhk5-Z44XrpGvgAAAuY"]
[Tue Jul 21 07:23:00.255840 2026] [security2:error] [pid 230252:tid 230461] [client 45.251.232.145:53588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IhE0Dwhk5-Z44XrpGvgAAAuY"]
[Tue Jul 21 07:23:00.463582 2026] [security2:error] [pid 229246:tid 229367] [remote 154.61.75.100:53640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9IhCBMYeh5YLVG45xrAAACQXg"]
[Tue Jul 21 07:23:00.671664 2026] [security2:error] [pid 230252:tid 230465] [client 109.248.148.246:46092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9IhE0Dwhk5-Z44XrpGwAAAAuo"]
[Tue Jul 21 07:23:00.671769 2026] [security2:error] [pid 230252:tid 230465] [client 109.248.148.246:46092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9IhE0Dwhk5-Z44XrpGwAAAAuo"]
[Tue Jul 21 07:23:00.965671 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:26504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/155.php"] [unique_id "al9IhE0Dwhk5-Z44XrpGxAAAAtE"]
[Tue Jul 21 07:23:01.019864 2026] [security2:error] [pid 230252:tid 230417] [client 20.151.10.161:49140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/x.php"] [unique_id "al9IhU0Dwhk5-Z44XrpGxQAAAro"]
[Tue Jul 21 07:23:01.126018 2026] [security2:error] [pid 229246:tid 229477] [client 20.226.60.151:54475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/popo.php"] [unique_id "al9IhSBMYeh5YLVG45xrBQAAAnk"]
[Tue Jul 21 07:23:01.297667 2026] [security2:error] [pid 229246:tid 229451] [client 20.104.96.117:62962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9IhSBMYeh5YLVG45xrDAAAAl8"]
[Tue Jul 21 07:23:01.360102 2026] [security2:error] [pid 229246:tid 229472] [client 20.226.60.151:60176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9IhSBMYeh5YLVG45xrDwAAAnQ"]
[Tue Jul 21 07:23:01.441709 2026] [security2:error] [pid 229246:tid 229430] [client 20.220.225.223:34292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/dp.php"] [unique_id "al9IhSBMYeh5YLVG45xrEAAAAko"]
[Tue Jul 21 07:23:01.604597 2026] [security2:error] [pid 229246:tid 229466] [client 20.220.225.223:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/pn.php"] [unique_id "al9IhSBMYeh5YLVG45xrEgAAAm4"]
[Tue Jul 21 07:23:01.875366 2026] [security2:error] [pid 230252:tid 230407] [client 20.104.96.117:4174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/FWAZ.php"] [unique_id "al9IhU0Dwhk5-Z44XrpG0wAAArA"]
[Tue Jul 21 07:23:02.181910 2026] [security2:error] [pid 230252:tid 230397] [client 172.245.102.44:25671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG1AAAAqY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:02.365359 2026] [security2:error] [pid 230252:tid 230432] [client 74.7.175.185:41220] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.bug.esidiomass.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Ihk0Dwhk5-Z44XrpG2QACyUU"]
[Tue Jul 21 07:23:02.405345 2026] [security2:error] [pid 230252:tid 230465] [client 20.197.192.193:52266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/samll.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG2wAAAuo"]
[Tue Jul 21 07:23:02.464618 2026] [security2:error] [pid 230252:tid 230385] [client 103.162.129.114:50763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG3gAAApo"]
[Tue Jul 21 07:23:02.464785 2026] [security2:error] [pid 230252:tid 230385] [client 103.162.129.114:50763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG3gAAApo"]
[Tue Jul 21 07:23:02.497546 2026] [security2:error] [pid 230252:tid 230459] [client 74.7.230.24:33914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "esidiomass.com.br"] [uri "/robots.txt"] [unique_id "al9Ihk0Dwhk5-Z44XrpG3wAAAuQ"]
[Tue Jul 21 07:23:02.502461 2026] [security2:error] [pid 229246:tid 229401] [client 190.92.174.183:39980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IhiBMYeh5YLVG45xrHQAAAi0"]
[Tue Jul 21 07:23:02.502550 2026] [security2:error] [pid 229246:tid 229401] [client 190.92.174.183:39980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IhiBMYeh5YLVG45xrHQAAAi0"]
[Tue Jul 21 07:23:02.503387 2026] [security2:error] [pid 230252:tid 230429] [client 20.104.96.117:64031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/miru1.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG4AAAAsY"]
[Tue Jul 21 07:23:02.750204 2026] [security2:error] [pid 230252:tid 230471] [client 14.139.42.196:6558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG4gAAAvA"]
[Tue Jul 21 07:23:02.750310 2026] [security2:error] [pid 230252:tid 230471] [client 14.139.42.196:6558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG4gAAAvA"]
[Tue Jul 21 07:23:02.753439 2026] [security2:error] [pid 229246:tid 229457] [client 20.197.192.193:53124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/abcd.php"] [unique_id "al9IhiBMYeh5YLVG45xrIgAAAmU"]
[Tue Jul 21 07:23:02.764033 2026] [security2:error] [pid 230252:tid 230403] [client 74.7.230.24:51660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "esidiomass.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Ihk0Dwhk5-Z44XrpG5AACrGM"], referer: http://esidiomass.com.br/robots.txt
[Tue Jul 21 07:23:02.764785 2026] [security2:error] [pid 230252:tid 230403] [client 74.7.230.24:51660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "esidiomass.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Ihk0Dwhk5-Z44XrpG4wACrG4"]
[Tue Jul 21 07:23:02.805600 2026] [security2:error] [pid 229246:tid 229487] [client 20.151.10.161:49101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/j260624_13.php"] [unique_id "al9IhiBMYeh5YLVG45xrIwAAAoM"]
[Tue Jul 21 07:23:02.819411 2026] [security2:error] [pid 230252:tid 230421] [client 190.92.174.183:46588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG5gAAAr4"]
[Tue Jul 21 07:23:02.819500 2026] [security2:error] [pid 230252:tid 230421] [client 190.92.174.183:46588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9Ihk0Dwhk5-Z44XrpG5gAAAr4"]
[Tue Jul 21 07:23:02.912709 2026] [security2:error] [pid 229246:tid 229481] [client 20.151.10.161:26527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ppp.php"] [unique_id "al9IhiBMYeh5YLVG45xrJwAAAn0"]
[Tue Jul 21 07:23:02.950787 2026] [security2:error] [pid 229246:tid 229437] [client 20.104.96.117:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/aa.php"] [unique_id "al9IhiBMYeh5YLVG45xrKAAAAlE"]
[Tue Jul 21 07:23:03.075742 2026] [security2:error] [pid 230252:tid 230507] [client 117.251.86.144:39216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Ih00Dwhk5-Z44XrpG6wAAAxQ"]
[Tue Jul 21 07:23:03.075880 2026] [security2:error] [pid 230252:tid 230507] [client 117.251.86.144:39216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Ih00Dwhk5-Z44XrpG6wAAAxQ"]
[Tue Jul 21 07:23:03.216919 2026] [security2:error] [pid 229246:tid 229452] [client 213.152.162.104:36928] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IhyBMYeh5YLVG45xrKwAAAmA"]
[Tue Jul 21 07:23:03.217018 2026] [security2:error] [pid 229246:tid 229452] [client 213.152.162.104:36928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9IhyBMYeh5YLVG45xrKwAAAmA"]
[Tue Jul 21 07:23:03.461936 2026] [security2:error] [pid 230252:tid 230472] [client 190.92.174.183:41400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9Ih00Dwhk5-Z44XrpG8gAAAvE"]
[Tue Jul 21 07:23:03.462138 2026] [security2:error] [pid 230252:tid 230472] [client 190.92.174.183:41400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9Ih00Dwhk5-Z44XrpG8gAAAvE"]
[Tue Jul 21 07:23:03.517770 2026] [security2:error] [pid 229246:tid 229382] [client 20.104.96.117:64021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/122.php"] [unique_id "al9IhyBMYeh5YLVG45xrLwAAAho"]
[Tue Jul 21 07:23:04.048622 2026] [proxy:error] [pid 230252:tid 230457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:04.048696 2026] [proxy_http:error] [pid 230252:tid 230457] [client 20.226.60.151:60205] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:04.049325 2026] [proxy:error] [pid 230252:tid 230457] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:04.049352 2026] [proxy_http:error] [pid 230252:tid 230457] [client 20.226.60.151:60205] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:04.203955 2026] [security2:error] [pid 230252:tid 230431] [client 190.92.174.183:41406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9IiE0Dwhk5-Z44XrpG-gAAAsg"]
[Tue Jul 21 07:23:04.204103 2026] [security2:error] [pid 230252:tid 230431] [client 190.92.174.183:41406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9IiE0Dwhk5-Z44XrpG-gAAAsg"]
[Tue Jul 21 07:23:04.209454 2026] [security2:error] [pid 229246:tid 229274] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IiCBMYeh5YLVG45xrPAACQRs"]
[Tue Jul 21 07:23:04.209665 2026] [security2:error] [pid 229246:tid 229421] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IiCBMYeh5YLVG45xrPAACQRs"]
[Tue Jul 21 07:23:04.256256 2026] [security2:error] [pid 230252:tid 230498] [client 20.104.96.117:5115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/get.php"] [unique_id "al9IiE0Dwhk5-Z44XrpG-wAAAws"]
[Tue Jul 21 07:23:04.412952 2026] [security2:error] [pid 229246:tid 229276] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IiCBMYeh5YLVG45xrQAACkh0"]
[Tue Jul 21 07:23:04.413113 2026] [security2:error] [pid 229246:tid 229502] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IiCBMYeh5YLVG45xrQAACkh0"]
[Tue Jul 21 07:23:04.511301 2026] [security2:error] [pid 229246:tid 229498] [client 20.220.225.223:45967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-wpbak.php"] [unique_id "al9IiCBMYeh5YLVG45xrQwAAAo4"]
[Tue Jul 21 07:23:04.524514 2026] [security2:error] [pid 230252:tid 230436] [client 20.151.10.161:49038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/d62.php"] [unique_id "al9IiE0Dwhk5-Z44XrpG_gAAAs0"]
[Tue Jul 21 07:23:04.926904 2026] [security2:error] [pid 229246:tid 229409] [client 190.92.174.183:41408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/news/xmlrpc.php"] [unique_id "al9IiCBMYeh5YLVG45xrSgAAAjU"]
[Tue Jul 21 07:23:04.927031 2026] [security2:error] [pid 229246:tid 229409] [client 190.92.174.183:41408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/news/xmlrpc.php"] [unique_id "al9IiCBMYeh5YLVG45xrSgAAAjU"]
[Tue Jul 21 07:23:05.014735 2026] [security2:error] [pid 230252:tid 230480] [client 20.104.96.117:62917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/as.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHCAAAAvk"]
[Tue Jul 21 07:23:05.139988 2026] [security2:error] [pid 230252:tid 230493] [client 20.197.192.193:53143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/xyn.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHCgAAAwY"]
[Tue Jul 21 07:23:05.232642 2026] [security2:error] [pid 230252:tid 230339] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHDAADDlQ"]
[Tue Jul 21 07:23:05.232824 2026] [security2:error] [pid 230252:tid 230501] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHDAADDlQ"]
[Tue Jul 21 07:23:05.376277 2026] [security2:error] [pid 229246:tid 229385] [client 20.220.225.223:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/dr.php"] [unique_id "al9IiSBMYeh5YLVG45xrUQAAAh0"]
[Tue Jul 21 07:23:05.523921 2026] [security2:error] [pid 230252:tid 230375] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHDgAC93g"]
[Tue Jul 21 07:23:05.524054 2026] [security2:error] [pid 230252:tid 230478] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHDgAC93g"]
[Tue Jul 21 07:23:05.647209 2026] [security2:error] [pid 230252:tid 230473] [client 20.151.10.161:49141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ups.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHDwAAAvI"]
[Tue Jul 21 07:23:05.869479 2026] [security2:error] [pid 230252:tid 230430] [client 190.92.174.183:41410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHEgAAAsc"]
[Tue Jul 21 07:23:05.869642 2026] [security2:error] [pid 230252:tid 230430] [client 190.92.174.183:41410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9IiU0Dwhk5-Z44XrpHEgAAAsc"]
[Tue Jul 21 07:23:06.299327 2026] [security2:error] [pid 229246:tid 229487] [client 20.104.96.117:62956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ccou.php"] [unique_id "al9IiiBMYeh5YLVG45xrXQAAAoM"]
[Tue Jul 21 07:23:06.313617 2026] [security2:error] [pid 230252:tid 230472] [client 103.174.34.15:51657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHGAAAAvE"]
[Tue Jul 21 07:23:06.313721 2026] [security2:error] [pid 230252:tid 230472] [client 103.174.34.15:51657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHGAAAAvE"]
[Tue Jul 21 07:23:06.327034 2026] [security2:error] [pid 230252:tid 230442] [client 109.248.148.246:46096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHGQAAAtM"]
[Tue Jul 21 07:23:06.327107 2026] [security2:error] [pid 230252:tid 230442] [client 109.248.148.246:46096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHGQAAAtM"]
[Tue Jul 21 07:23:06.436470 2026] [core:alert] [pid 230252:tid 230498] [client 57.141.18.15:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:23:06.471716 2026] [security2:error] [pid 230252:tid 230422] [client 20.220.225.223:46123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/2x.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHHAAAAr8"]
[Tue Jul 21 07:23:06.586151 2026] [security2:error] [pid 230252:tid 230385] [client 190.92.174.183:41414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/main/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHIAAAApo"]
[Tue Jul 21 07:23:06.586250 2026] [security2:error] [pid 230252:tid 230385] [client 190.92.174.183:41414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/main/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHIAAAApo"]
[Tue Jul 21 07:23:06.773524 2026] [security2:error] [pid 229246:tid 229393] [client 20.226.60.151:56907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IiiBMYeh5YLVG45xrYwAAAiU"]
[Tue Jul 21 07:23:06.834686 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:49054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/k.php"] [unique_id "al9IiiBMYeh5YLVG45xrZAAAAlo"]
[Tue Jul 21 07:23:06.947188 2026] [security2:error] [pid 230252:tid 230353] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHIwACsWI"]
[Tue Jul 21 07:23:06.947342 2026] [security2:error] [pid 230252:tid 230408] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Iik0Dwhk5-Z44XrpHIwACsWI"]
[Tue Jul 21 07:23:07.154304 2026] [security2:error] [pid 229246:tid 229458] [client 204.12.208.18:56720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-includes/addb8871/index.php"] [unique_id "al9IiyBMYeh5YLVG45xraQAAAmY"], referer: https://rkcentroautomotivoo.com.br/wp-includes/addb8871/index.php
[Tue Jul 21 07:23:07.181493 2026] [security2:error] [pid 230252:tid 230489] [client 213.152.162.104:51196] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHKAAAAwI"]
[Tue Jul 21 07:23:07.181601 2026] [security2:error] [pid 230252:tid 230489] [client 213.152.162.104:51196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHKAAAAwI"]
[Tue Jul 21 07:23:07.229239 2026] [security2:error] [pid 230252:tid 230507] [client 190.92.174.183:41416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHKgAAAxQ"]
[Tue Jul 21 07:23:07.229371 2026] [security2:error] [pid 230252:tid 230507] [client 190.92.174.183:41416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHKgAAAxQ"]
[Tue Jul 21 07:23:07.278977 2026] [security2:error] [pid 230252:tid 230504] [client 20.220.225.223:46123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/kq1.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHKwAAAxE"]
[Tue Jul 21 07:23:07.558874 2026] [security2:error] [pid 230252:tid 230292] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHMAACyCY"]
[Tue Jul 21 07:23:07.559056 2026] [security2:error] [pid 230252:tid 230431] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHMAACyCY"]
[Tue Jul 21 07:23:07.659087 2026] [autoindex:error] [pid 230252:tid 230314] [remote 74.7.243.194:50920] AH01276: Cannot serve directory /home1/imperd48/ussabinooffers.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:07.677942 2026] [security2:error] [pid 230252:tid 230481] [client 74.7.241.149:59064] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ussabinooffers.com.imperdivelbestpromotionofthedaytodayonly.com"] [uri "/cgi-sys/404.html"] [unique_id "al9Ii00Dwhk5-Z44XrpHMwAC-iM"]
[Tue Jul 21 07:23:07.691596 2026] [security2:error] [pid 230252:tid 230474] [client 204.12.208.18:56733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-includes/addb8871/index.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHNAAAAvM"], referer: https://rkcentroautomotivoo.com.br/wp-includes/addb8871/index.php
[Tue Jul 21 07:23:07.732557 2026] [security2:error] [pid 230252:tid 230461] [client 20.226.60.151:56833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHNQAAAuY"]
[Tue Jul 21 07:23:07.874943 2026] [security2:error] [pid 230252:tid 230467] [client 190.92.174.183:41424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHNgAAAuw"]
[Tue Jul 21 07:23:07.875076 2026] [security2:error] [pid 230252:tid 230467] [client 190.92.174.183:41424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHNgAAAuw"]
[Tue Jul 21 07:23:07.930247 2026] [security2:error] [pid 230252:tid 230503] [client 20.197.192.193:52277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/byp8.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHNwAAAxA"]
[Tue Jul 21 07:23:07.935456 2026] [security2:error] [pid 230252:tid 230420] [client 109.248.148.246:56324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHOQAAAr0"]
[Tue Jul 21 07:23:07.935536 2026] [security2:error] [pid 230252:tid 230420] [client 109.248.148.246:56324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Ii00Dwhk5-Z44XrpHOQAAAr0"]
[Tue Jul 21 07:23:08.051467 2026] [security2:error] [pid 229246:tid 229416] [client 175.45.70.82:57861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IjCBMYeh5YLVG45xrcwAAAjw"]
[Tue Jul 21 07:23:08.051576 2026] [security2:error] [pid 229246:tid 229416] [client 175.45.70.82:57861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IjCBMYeh5YLVG45xrcwAAAjw"]
[Tue Jul 21 07:23:08.183411 2026] [security2:error] [pid 230252:tid 230408] [client 20.197.192.193:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/user.php"] [unique_id "al9IjE0Dwhk5-Z44XrpHPQAAArE"]
[Tue Jul 21 07:23:08.222994 2026] [security2:error] [pid 230252:tid 230502] [client 136.144.33.98:35859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IjE0Dwhk5-Z44XrpHPgAAAw8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:08.223725 2026] [security2:error] [pid 230252:tid 230413] [client 213.152.162.104:37148] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9IjE0Dwhk5-Z44XrpHQAAAArY"]
[Tue Jul 21 07:23:08.223801 2026] [security2:error] [pid 230252:tid 230413] [client 213.152.162.104:37148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9IjE0Dwhk5-Z44XrpHQAAAArY"]
[Tue Jul 21 07:23:08.243472 2026] [security2:error] [pid 229246:tid 229387] [client 204.12.208.18:56742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-includes/addb8871/index.php"] [unique_id "al9IjCBMYeh5YLVG45xrdgAAAh8"], referer: https://rkcentroautomotivoo.com.br/wp-includes/addb8871/index.php
[Tue Jul 21 07:23:08.330066 2026] [security2:error] [pid 229246:tid 229383] [client 20.151.10.161:49031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/k2.php"] [unique_id "al9IjCBMYeh5YLVG45xreAAAAhs"]
[Tue Jul 21 07:23:08.509561 2026] [security2:error] [pid 229246:tid 229480] [client 190.92.174.183:41426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9IjCBMYeh5YLVG45xrewAAAnw"]
[Tue Jul 21 07:23:08.509680 2026] [security2:error] [pid 229246:tid 229480] [client 190.92.174.183:41426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9IjCBMYeh5YLVG45xrewAAAnw"]
[Tue Jul 21 07:23:08.684703 2026] [security2:error] [pid 229246:tid 229406] [client 20.226.60.151:54551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/yas.php"] [unique_id "al9IjCBMYeh5YLVG45xrfgAAAjI"]
[Tue Jul 21 07:23:08.760093 2026] [security2:error] [pid 229246:tid 229451] [client 74.249.245.134:42800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/autoload_classmap.php"] [unique_id "al9IjCBMYeh5YLVG45xrgAAAAl8"]
[Tue Jul 21 07:23:08.837834 2026] [security2:error] [pid 230252:tid 230427] [client 20.104.96.117:5112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/w3lls.php"] [unique_id "al9IjE0Dwhk5-Z44XrpHRAAAAsQ"]
[Tue Jul 21 07:23:08.893697 2026] [security2:error] [pid 230252:tid 230473] [client 20.226.60.151:56865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/media.php"] [unique_id "al9IjE0Dwhk5-Z44XrpHRQAAAvI"]
[Tue Jul 21 07:23:08.980337 2026] [security2:error] [pid 229246:tid 229484] [client 197.11.70.196:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.70.11.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grupotecc.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IiyBMYeh5YLVG45xrcAAAAoA"]
[Tue Jul 21 07:23:08.980493 2026] [security2:error] [pid 229246:tid 229484] [client 197.11.70.196:46042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grupotecc.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IiyBMYeh5YLVG45xrcAAAAoA"]
[Tue Jul 21 07:23:08.993291 2026] [security2:error] [pid 230252:tid 230511] [client 20.226.60.151:60192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9IjE0Dwhk5-Z44XrpHRgAAAxg"]
[Tue Jul 21 07:23:09.139378 2026] [security2:error] [pid 230252:tid 230431] [client 190.92.174.183:41434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/new/xmlrpc.php"] [unique_id "al9IjU0Dwhk5-Z44XrpHSQAAAsg"]
[Tue Jul 21 07:23:09.139492 2026] [security2:error] [pid 230252:tid 230431] [client 190.92.174.183:41434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "northcomm.com.br"] [uri "/new/xmlrpc.php"] [unique_id "al9IjU0Dwhk5-Z44XrpHSQAAAsg"]
[Tue Jul 21 07:23:09.236532 2026] [security2:error] [pid 229246:tid 229430] [client 74.7.241.175:35124] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.letsgotaxi.com.br.hostag.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9IjSBMYeh5YLVG45xrhQACSi4"]
[Tue Jul 21 07:23:09.479224 2026] [security2:error] [pid 229246:tid 229418] [client 20.220.225.223:46091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/zzz.php"] [unique_id "al9IjSBMYeh5YLVG45xriQAAAj4"]
[Tue Jul 21 07:23:09.552344 2026] [security2:error] [pid 230252:tid 230474] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "unigein.com.br"] [uri "/index.php"] [unique_id "al9IjU0Dwhk5-Z44XrpHTgAAAvM"]
[Tue Jul 21 07:23:09.552699 2026] [security2:error] [pid 230252:tid 230428] [client 74.7.228.54:40052] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "unigein.com.br"] [uri "/robots.txt"] [unique_id "al9IjU0Dwhk5-Z44XrpHTQAAAsU"]
[Tue Jul 21 07:23:09.747691 2026] [security2:error] [pid 230252:tid 230488] [client 139.135.44.145:54552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IjU0Dwhk5-Z44XrpHTwAAAwE"]
[Tue Jul 21 07:23:09.747823 2026] [security2:error] [pid 230252:tid 230488] [client 139.135.44.145:54552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IjU0Dwhk5-Z44XrpHTwAAAwE"]
[Tue Jul 21 07:23:09.902079 2026] [security2:error] [pid 229246:tid 229487] [client 20.151.10.161:49098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/k3.php"] [unique_id "al9IjSBMYeh5YLVG45xrkgAAAoM"]
[Tue Jul 21 07:23:10.072106 2026] [security2:error] [pid 229246:tid 229402] [client 20.226.60.151:56847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/images.php"] [unique_id "al9IjiBMYeh5YLVG45xrlgAAAi4"]
[Tue Jul 21 07:23:10.158501 2026] [security2:error] [pid 230252:tid 230471] [client 109.248.148.246:52622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Ijk0Dwhk5-Z44XrpHVQAAAvA"]
[Tue Jul 21 07:23:10.158621 2026] [security2:error] [pid 230252:tid 230471] [client 109.248.148.246:52622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Ijk0Dwhk5-Z44XrpHVQAAAvA"]
[Tue Jul 21 07:23:10.237385 2026] [security2:error] [pid 229246:tid 229500] [client 20.151.10.161:26418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/201.php"] [unique_id "al9IjiBMYeh5YLVG45xrmQAAApA"]
[Tue Jul 21 07:23:10.630066 2026] [security2:error] [pid 230252:tid 230416] [client 103.121.156.110:50123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Ijk0Dwhk5-Z44XrpHVgAAArk"]
[Tue Jul 21 07:23:10.630225 2026] [security2:error] [pid 230252:tid 230416] [client 103.121.156.110:50123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Ijk0Dwhk5-Z44XrpHVgAAArk"]
[Tue Jul 21 07:23:10.665415 2026] [security2:error] [pid 230252:tid 230389] [client 74.7.241.166:60740] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "clinicaqualis.com.br"] [uri "/index.php"] [unique_id "al9IjU0Dwhk5-Z44XrpHUwACnnI"]
[Tue Jul 21 07:23:10.803610 2026] [security2:error] [pid 229246:tid 229481] [client 45.251.232.145:54115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IjiBMYeh5YLVG45xrpAAAAn0"]
[Tue Jul 21 07:23:10.803715 2026] [security2:error] [pid 229246:tid 229481] [client 45.251.232.145:54115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IjiBMYeh5YLVG45xrpAAAAn0"]
[Tue Jul 21 07:23:11.117388 2026] [security2:error] [pid 230252:tid 230455] [client 20.226.60.151:60204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/jj.php"] [unique_id "al9Ij00Dwhk5-Z44XrpHWwAAAuA"]
[Tue Jul 21 07:23:11.469641 2026] [security2:error] [pid 230252:tid 230452] [client 20.226.60.151:56853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/gecko.php"] [unique_id "al9Ij00Dwhk5-Z44XrpHXQAAAt0"]
[Tue Jul 21 07:23:11.485896 2026] [security2:error] [pid 230252:tid 230499] [client 190.92.174.183:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wp-login.php"] [unique_id "al9Ij00Dwhk5-Z44XrpHXgAAAww"], referer: https://northcomm.com.br/wp-admin/
[Tue Jul 21 07:23:11.849017 2026] [security2:error] [pid 230252:tid 230487] [client 190.92.174.183:41448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wp-login.php"] [unique_id "al9Ij00Dwhk5-Z44XrpHZAAAAwA"]
[Tue Jul 21 07:23:12.340904 2026] [security2:error] [pid 229246:tid 229451] [client 20.220.225.223:34203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/bootstrap.php"] [unique_id "al9IkCBMYeh5YLVG45xrtQAAAl8"]
[Tue Jul 21 07:23:12.362012 2026] [security2:error] [pid 229246:tid 229465] [client 20.226.60.151:50688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9IkCBMYeh5YLVG45xrtgAAAm0"]
[Tue Jul 21 07:23:12.418528 2026] [security2:error] [pid 229246:tid 229433] [client 20.104.96.117:62920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/test1.php"] [unique_id "al9IkCBMYeh5YLVG45xrtwAAAk0"]
[Tue Jul 21 07:23:12.465549 2026] [security2:error] [pid 229246:tid 229428] [client 74.249.245.134:61978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/av.php"] [unique_id "al9IkCBMYeh5YLVG45xruQAAAkg"]
[Tue Jul 21 07:23:12.742111 2026] [security2:error] [pid 230252:tid 230432] [client 20.226.60.151:60233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/txets.php"] [unique_id "al9IkE0Dwhk5-Z44XrpHawAAAsk"]
[Tue Jul 21 07:23:12.807202 2026] [security2:error] [pid 230252:tid 230444] [client 20.226.60.151:56918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/82.php"] [unique_id "al9IkE0Dwhk5-Z44XrpHbwAAAtU"]
[Tue Jul 21 07:23:12.936342 2026] [security2:error] [pid 230252:tid 230389] [client 20.104.96.117:64003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/database.php"] [unique_id "al9IkE0Dwhk5-Z44XrpHcgAAAp4"]
[Tue Jul 21 07:23:13.299287 2026] [security2:error] [pid 229246:tid 229447] [client 20.220.225.223:45412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wicked.php"] [unique_id "al9IkSBMYeh5YLVG45xrygAAAls"]
[Tue Jul 21 07:23:13.312216 2026] [security2:error] [pid 229246:tid 229391] [client 103.162.129.114:51235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IkSBMYeh5YLVG45xrywAAAiM"]
[Tue Jul 21 07:23:13.312311 2026] [security2:error] [pid 229246:tid 229391] [client 103.162.129.114:51235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IkSBMYeh5YLVG45xrywAAAiM"]
[Tue Jul 21 07:23:13.393745 2026] [security2:error] [pid 229246:tid 229490] [client 20.197.192.193:52283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/ops.php"] [unique_id "al9IkSBMYeh5YLVG45xrzQAAAoY"]
[Tue Jul 21 07:23:13.675612 2026] [security2:error] [pid 229246:tid 229437] [client 20.226.60.151:60249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/dex.php"] [unique_id "al9IkSBMYeh5YLVG45xr0gAAAlE"]
[Tue Jul 21 07:23:13.692807 2026] [security2:error] [pid 229246:tid 229393] [client 20.226.60.151:56908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/admin.php"] [unique_id "al9IkSBMYeh5YLVG45xr1AAAAiU"]
[Tue Jul 21 07:23:13.751076 2026] [security2:error] [pid 229246:tid 229473] [client 20.226.60.151:61104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/file61.php"] [unique_id "al9IkSBMYeh5YLVG45xr1QAAAnU"]
[Tue Jul 21 07:23:13.828720 2026] [security2:error] [pid 230252:tid 230418] [client 14.139.42.196:2616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IkU0Dwhk5-Z44XrpHegAAArs"]
[Tue Jul 21 07:23:13.828916 2026] [security2:error] [pid 230252:tid 230418] [client 14.139.42.196:2616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IkU0Dwhk5-Z44XrpHegAAArs"]
[Tue Jul 21 07:23:13.838842 2026] [security2:error] [pid 230252:tid 230501] [client 117.251.86.144:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IkU0Dwhk5-Z44XrpHewAAAw4"]
[Tue Jul 21 07:23:13.838949 2026] [security2:error] [pid 230252:tid 230501] [client 117.251.86.144:36488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IkU0Dwhk5-Z44XrpHewAAAw4"]
[Tue Jul 21 07:23:14.078502 2026] [security2:error] [pid 229246:tid 229396] [client 20.151.10.161:48599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/k4.php"] [unique_id "al9IkiBMYeh5YLVG45xr3gAAAig"]
[Tue Jul 21 07:23:14.270917 2026] [security2:error] [pid 230252:tid 230497] [client 20.226.60.151:60218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/xpwer1.php"] [unique_id "al9Ikk0Dwhk5-Z44XrpHfAAAAwo"]
[Tue Jul 21 07:23:14.320497 2026] [security2:error] [pid 229246:tid 229502] [client 172.245.102.41:37253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IkSBMYeh5YLVG45xrxAAAApI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:14.440795 2026] [security2:error] [pid 229246:tid 229387] [client 74.249.245.134:56027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/gg.php"] [unique_id "al9IkiBMYeh5YLVG45xr5gAAAh8"]
[Tue Jul 21 07:23:14.623338 2026] [security2:error] [pid 229246:tid 229408] [client 109.248.148.246:52636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IkiBMYeh5YLVG45xr6QAAAjQ"]
[Tue Jul 21 07:23:14.623463 2026] [security2:error] [pid 229246:tid 229408] [client 109.248.148.246:52636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IkiBMYeh5YLVG45xr6QAAAjQ"]
[Tue Jul 21 07:23:14.694568 2026] [security2:error] [pid 230252:tid 230464] [client 20.226.60.151:56916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/adminner.php"] [unique_id "al9Ikk0Dwhk5-Z44XrpHfwAAAuk"]
[Tue Jul 21 07:23:14.901319 2026] [security2:error] [pid 229246:tid 229433] [client 20.104.96.117:62930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/file.php"] [unique_id "al9IkiBMYeh5YLVG45xr8AAAAk0"]
[Tue Jul 21 07:23:14.927915 2026] [security2:error] [pid 229246:tid 229291] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IkiBMYeh5YLVG45xr8QACfCw"]
[Tue Jul 21 07:23:14.928121 2026] [security2:error] [pid 229246:tid 229480] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IkiBMYeh5YLVG45xr8QACfCw"]
[Tue Jul 21 07:23:15.062244 2026] [security2:error] [pid 229246:tid 229362] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IkyBMYeh5YLVG45xr9wACMnM"]
[Tue Jul 21 07:23:15.062426 2026] [security2:error] [pid 229246:tid 229406] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IkyBMYeh5YLVG45xr9wACMnM"]
[Tue Jul 21 07:23:15.127628 2026] [security2:error] [pid 229246:tid 229260] [remote 216.73.216.115:46829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swingcuiaba.com.br"] [uri "/goods.php"] [unique_id "al9IkyBMYeh5YLVG45xr-AACNg0"]
[Tue Jul 21 07:23:15.176452 2026] [security2:error] [pid 229246:tid 229426] [client 141.11.107.74:51834] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "whm.arcoll.com.br"] [uri "/___proxy_subdomain_whm/"] [unique_id "al9IkyBMYeh5YLVG45xr-QAAAkY"]
[Tue Jul 21 07:23:15.197053 2026] [security2:error] [pid 229246:tid 229398] [client 141.11.107.74:51840] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ftp.arcoll.com.br"] [uri "/"] [unique_id "al9IkyBMYeh5YLVG45xr_AAAAio"]
[Tue Jul 21 07:23:15.240909 2026] [security2:error] [pid 229246:tid 229472] [client 141.11.107.74:51859] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.arcoll.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9IkyBMYeh5YLVG45xr_QAAAnQ"]
[Tue Jul 21 07:23:15.248146 2026] [security2:error] [pid 229246:tid 229479] [client 141.11.107.74:51868] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arcoll.com.br"] [uri "/"] [unique_id "al9IkyBMYeh5YLVG45xr_gAAAns"]
[Tue Jul 21 07:23:15.261239 2026] [security2:error] [pid 230252:tid 230474] [client 141.11.107.74:51882] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.arcoll.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9Ik00Dwhk5-Z44XrpHggAAAvM"]
[Tue Jul 21 07:23:15.261239 2026] [security2:error] [pid 229246:tid 229399] [client 141.11.107.74:51883] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.arcoll.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9IkyBMYeh5YLVG45xr_wAAAis"]
[Tue Jul 21 07:23:15.261239 2026] [security2:error] [pid 229246:tid 229461] [client 141.11.107.74:51878] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.arcoll.com.br"] [uri "/"] [unique_id "al9IkyBMYeh5YLVG45xsAAAAAmk"]
[Tue Jul 21 07:23:15.262992 2026] [security2:error] [pid 230252:tid 230461] [client 141.11.107.74:51877] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.arcoll.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9Ik00Dwhk5-Z44XrpHgwAAAuY"]
[Tue Jul 21 07:23:15.384881 2026] [security2:error] [pid 230252:tid 230488] [client 20.226.60.151:56955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/admin.php"] [unique_id "al9Ik00Dwhk5-Z44XrpHhQAAAwE"]
[Tue Jul 21 07:23:15.446770 2026] [security2:error] [pid 230252:tid 230403] [client 141.11.107.74:51951] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.arcoll.com.br"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "al9Ik00Dwhk5-Z44XrpHiAAAAqw"]
[Tue Jul 21 07:23:15.752889 2026] [security2:error] [pid 229246:tid 229332] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IkyBMYeh5YLVG45xsCAAChlU"]
[Tue Jul 21 07:23:15.753024 2026] [security2:error] [pid 229246:tid 229490] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IkyBMYeh5YLVG45xsCAAChlU"]
[Tue Jul 21 07:23:15.903177 2026] [security2:error] [pid 230252:tid 230408] [client 20.226.60.151:60178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/flox.php"] [unique_id "al9Ik00Dwhk5-Z44XrpHjQAAArE"]
[Tue Jul 21 07:23:15.995771 2026] [security2:error] [pid 230252:tid 230276] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ik00Dwhk5-Z44XrpHjwAC1RY"]
[Tue Jul 21 07:23:15.995927 2026] [security2:error] [pid 230252:tid 230444] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ik00Dwhk5-Z44XrpHjwAC1RY"]
[Tue Jul 21 07:23:16.274153 2026] [security2:error] [pid 230252:tid 230429] [client 20.151.10.161:26419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ops.php"] [unique_id "al9IlE0Dwhk5-Z44XrpHlAAAAsY"]
[Tue Jul 21 07:23:16.761011 2026] [security2:error] [pid 229246:tid 229407] [client 20.197.192.193:53155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/term.php"] [unique_id "al9IlCBMYeh5YLVG45xsFQAAAjM"]
[Tue Jul 21 07:23:16.843009 2026] [security2:error] [pid 229246:tid 229495] [client 20.226.60.151:56896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/k.php"] [unique_id "al9IlCBMYeh5YLVG45xsFwAAAos"]
[Tue Jul 21 07:23:17.023709 2026] [security2:error] [pid 230252:tid 230405] [client 74.249.245.134:59798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/sql.php"] [unique_id "al9IlU0Dwhk5-Z44XrpHmQAAAq4"]
[Tue Jul 21 07:23:17.101209 2026] [security2:error] [pid 230252:tid 230499] [client 103.174.34.15:52132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IlU0Dwhk5-Z44XrpHmgAAAww"]
[Tue Jul 21 07:23:17.107536 2026] [security2:error] [pid 230252:tid 230499] [client 103.174.34.15:52132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IlU0Dwhk5-Z44XrpHmgAAAww"]
[Tue Jul 21 07:23:17.109489 2026] [security2:error] [pid 230252:tid 230447] [client 20.104.96.117:64020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/file.php"] [unique_id "al9IlU0Dwhk5-Z44XrpHmwAAAtg"]
[Tue Jul 21 07:23:17.268847 2026] [security2:error] [pid 229246:tid 229497] [client 20.226.60.151:50812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/popo.php"] [unique_id "al9IlSBMYeh5YLVG45xsGwAAAo0"]
[Tue Jul 21 07:23:17.756487 2026] [security2:error] [pid 230252:tid 230352] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IlU0Dwhk5-Z44XrpHogACqWE"]
[Tue Jul 21 07:23:17.756690 2026] [security2:error] [pid 230252:tid 230400] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IlU0Dwhk5-Z44XrpHogACqWE"]
[Tue Jul 21 07:23:18.077098 2026] [security2:error] [pid 229246:tid 229369] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IliBMYeh5YLVG45xsKAACG3o"]
[Tue Jul 21 07:23:18.077245 2026] [security2:error] [pid 229246:tid 229383] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IliBMYeh5YLVG45xsKAACG3o"]
[Tue Jul 21 07:23:18.321519 2026] [security2:error] [pid 230252:tid 230478] [client 193.36.225.65:43377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Ilk0Dwhk5-Z44XrpHpAAAAvc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:18.365891 2026] [security2:error] [pid 230252:tid 230487] [client 109.248.148.246:36026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Ilk0Dwhk5-Z44XrpHpQAAAwA"]
[Tue Jul 21 07:23:18.365989 2026] [security2:error] [pid 230252:tid 230487] [client 109.248.148.246:36026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Ilk0Dwhk5-Z44XrpHpQAAAwA"]
[Tue Jul 21 07:23:18.416002 2026] [security2:error] [pid 229246:tid 229465] [client 20.226.60.151:56848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/blurbs.php"] [unique_id "al9IliBMYeh5YLVG45xsLQAAAm0"]
[Tue Jul 21 07:23:18.836594 2026] [security2:error] [pid 230252:tid 230481] [client 175.45.70.82:58362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ilk0Dwhk5-Z44XrpHqAAAAvo"]
[Tue Jul 21 07:23:18.836702 2026] [security2:error] [pid 230252:tid 230481] [client 175.45.70.82:58362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ilk0Dwhk5-Z44XrpHqAAAAvo"]
[Tue Jul 21 07:23:19.106611 2026] [security2:error] [pid 229246:tid 229489] [client 20.104.96.117:64009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/777.php"] [unique_id "al9IlyBMYeh5YLVG45xsNgAAAoU"]
[Tue Jul 21 07:23:19.456265 2026] [security2:error] [pid 230252:tid 230420] [client 109.248.148.246:36042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Il00Dwhk5-Z44XrpHqgAAAr0"]
[Tue Jul 21 07:23:19.456361 2026] [security2:error] [pid 230252:tid 230420] [client 109.248.148.246:36042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Il00Dwhk5-Z44XrpHqgAAAr0"]
[Tue Jul 21 07:23:19.688235 2026] [security2:error] [pid 230252:tid 230439] [client 20.104.96.117:4167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ssixta.php"] [unique_id "al9Il00Dwhk5-Z44XrpHrwAAAtA"]
[Tue Jul 21 07:23:19.912084 2026] [security2:error] [pid 229246:tid 229468] [client 20.226.60.151:60188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/yas.php"] [unique_id "al9IlyBMYeh5YLVG45xsgAAAAnA"]
[Tue Jul 21 07:23:19.945604 2026] [security2:error] [pid 229246:tid 229460] [client 20.226.60.151:54579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/water.php"] [unique_id "al9IlyBMYeh5YLVG45xshQAAAmg"]
[Tue Jul 21 07:23:20.114725 2026] [security2:error] [pid 230252:tid 230441] [client 20.226.60.151:56951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/bajah.php"] [unique_id "al9ImE0Dwhk5-Z44XrpHtgAAAtI"]
[Tue Jul 21 07:23:20.309457 2026] [security2:error] [pid 229246:tid 229389] [client 20.151.10.161:26452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ingfo.php"] [unique_id "al9ImCBMYeh5YLVG45xsiwAAAiE"]
[Tue Jul 21 07:23:20.327083 2026] [security2:error] [pid 229246:tid 229405] [client 139.135.44.145:53420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ImCBMYeh5YLVG45xsjAAAAjE"]
[Tue Jul 21 07:23:20.327199 2026] [security2:error] [pid 229246:tid 229405] [client 139.135.44.145:53420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ImCBMYeh5YLVG45xsjAAAAjE"]
[Tue Jul 21 07:23:20.455871 2026] [security2:error] [pid 229246:tid 229433] [client 20.104.96.117:62915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/1c.php"] [unique_id "al9ImCBMYeh5YLVG45xsjgAAAk0"]
[Tue Jul 21 07:23:20.842989 2026] [security2:error] [pid 230252:tid 230430] [client 20.104.96.117:64027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/test2.php"] [unique_id "al9ImE0Dwhk5-Z44XrpHuwAAAsc"]
[Tue Jul 21 07:23:20.940562 2026] [security2:error] [pid 229246:tid 229470] [client 109.248.148.246:54774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ImCBMYeh5YLVG45xskwAAAnI"]
[Tue Jul 21 07:23:20.940669 2026] [security2:error] [pid 229246:tid 229470] [client 109.248.148.246:54774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ImCBMYeh5YLVG45xskwAAAnI"]
[Tue Jul 21 07:23:21.029596 2026] [security2:error] [pid 230252:tid 230260] [remote 154.61.75.100:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp-login.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHvwAC4gY"]
[Tue Jul 21 07:23:21.032705 2026] [security2:error] [pid 229246:tid 229489] [client 62.102.148.164:33234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9ImSBMYeh5YLVG45xslQAAAoU"]
[Tue Jul 21 07:23:21.032782 2026] [security2:error] [pid 229246:tid 229489] [client 62.102.148.164:33234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9ImSBMYeh5YLVG45xslQAAAoU"]
[Tue Jul 21 07:23:21.194481 2026] [security2:error] [pid 230252:tid 230473] [client 103.121.156.110:50474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHwAAAAvI"]
[Tue Jul 21 07:23:21.194630 2026] [security2:error] [pid 230252:tid 230473] [client 103.121.156.110:50474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHwAAAAvI"]
[Tue Jul 21 07:23:21.269393 2026] [security2:error] [pid 230252:tid 230418] [client 45.251.232.145:54640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHwgAAArs"]
[Tue Jul 21 07:23:21.269508 2026] [security2:error] [pid 230252:tid 230418] [client 45.251.232.145:54640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHwgAAArs"]
[Tue Jul 21 07:23:21.413358 2026] [security2:error] [pid 229246:tid 229440] [client 20.151.10.161:26379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/error_log.php"] [unique_id "al9ImSBMYeh5YLVG45xsmgAAAlQ"]
[Tue Jul 21 07:23:21.434153 2026] [security2:error] [pid 230252:tid 230507] [client 20.226.60.151:56926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/a.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHwwAAAxQ"]
[Tue Jul 21 07:23:21.440907 2026] [security2:error] [pid 230252:tid 230506] [client 20.104.96.117:4177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/buy.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHxAAAAxM"]
[Tue Jul 21 07:23:21.578642 2026] [security2:error] [pid 229246:tid 229453] [client 62.102.148.164:59688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9ImSBMYeh5YLVG45xsmwAAAmE"]
[Tue Jul 21 07:23:21.578750 2026] [security2:error] [pid 229246:tid 229453] [client 62.102.148.164:59688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9ImSBMYeh5YLVG45xsmwAAAmE"]
[Tue Jul 21 07:23:21.812907 2026] [security2:error] [pid 230252:tid 230491] [client 20.151.10.161:49119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/k5.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHyAAAAwQ"]
[Tue Jul 21 07:23:21.817048 2026] [security2:error] [pid 230252:tid 230432] [client 20.104.96.117:64007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ssend.php"] [unique_id "al9ImU0Dwhk5-Z44XrpHyQAAAsk"]
[Tue Jul 21 07:23:22.115200 2026] [security2:error] [pid 229246:tid 229491] [client 20.151.10.161:26497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/xenon1337.php"] [unique_id "al9ImiBMYeh5YLVG45xsowAAAoc"]
[Tue Jul 21 07:23:22.139249 2026] [security2:error] [pid 230252:tid 230403] [client 20.104.96.117:62941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/item.php"] [unique_id "al9Imk0Dwhk5-Z44XrpHywAAAqw"]
[Tue Jul 21 07:23:22.271919 2026] [security2:error] [pid 229246:tid 229426] [client 193.36.225.58:37857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9ImiBMYeh5YLVG45xsogAAAkY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:22.544363 2026] [security2:error] [pid 230252:tid 230455] [client 20.220.225.223:34243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wp-editor.php"] [unique_id "al9Imk0Dwhk5-Z44XrpH0gAAAuA"]
[Tue Jul 21 07:23:22.618499 2026] [security2:error] [pid 230252:tid 230452] [client 20.104.96.117:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ss.php"] [unique_id "al9Imk0Dwhk5-Z44XrpH0wAAAt0"]
[Tue Jul 21 07:23:22.664556 2026] [security2:error] [pid 230252:tid 230413] [client 74.249.245.134:42774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/up.php"] [unique_id "al9Imk0Dwhk5-Z44XrpH1AAAArY"]
[Tue Jul 21 07:23:22.867428 2026] [security2:error] [pid 230252:tid 230469] [client 20.197.192.193:52276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/ah25.php"] [unique_id "al9Imk0Dwhk5-Z44XrpH2QAAAu4"]
[Tue Jul 21 07:23:22.988714 2026] [security2:error] [pid 229246:tid 229392] [client 20.226.60.151:56917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/edit.php"] [unique_id "al9ImiBMYeh5YLVG45xsrQAAAiQ"]
[Tue Jul 21 07:23:23.083004 2026] [security2:error] [pid 230252:tid 230497] [client 20.104.96.117:62922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/hypo.php"] [unique_id "al9Im00Dwhk5-Z44XrpH2gAAAwo"]
[Tue Jul 21 07:23:23.624401 2026] [security2:error] [pid 230252:tid 230428] [client 20.104.96.117:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/users.php"] [unique_id "al9Im00Dwhk5-Z44XrpH4QAAAsU"]
[Tue Jul 21 07:23:23.678164 2026] [security2:error] [pid 230252:tid 230422] [client 20.151.10.161:49111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/w.php"] [unique_id "al9Im00Dwhk5-Z44XrpH4gAAAr8"]
[Tue Jul 21 07:23:23.679809 2026] [security2:error] [pid 229246:tid 229411] [client 20.226.60.151:60163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/file61.php"] [unique_id "al9ImyBMYeh5YLVG45xsuQAAAjc"]
[Tue Jul 21 07:23:23.960938 2026] [security2:error] [pid 230252:tid 230472] [client 103.162.129.114:51726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Im00Dwhk5-Z44XrpH5QAAAvE"]
[Tue Jul 21 07:23:23.961048 2026] [security2:error] [pid 230252:tid 230472] [client 103.162.129.114:51726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Im00Dwhk5-Z44XrpH5QAAAvE"]
[Tue Jul 21 07:23:23.969529 2026] [security2:error] [pid 230252:tid 230300] [remote 51.161.65.213:29676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "neuroalfabetizaanacolombo.com"] [uri "/"] [unique_id "al9Im00Dwhk5-Z44XrpH5gACyS4"]
[Tue Jul 21 07:23:23.969636 2026] [security2:error] [pid 230252:tid 230432] [client 51.161.65.213:29676] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "neuroalfabetizaanacolombo.com"] [uri "/"] [unique_id "al9Im00Dwhk5-Z44XrpH5gACyS4"]
[Tue Jul 21 07:23:24.187495 2026] [security2:error] [pid 230252:tid 230467] [client 14.139.42.196:12431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9InE0Dwhk5-Z44XrpH5wAAAuw"]
[Tue Jul 21 07:23:24.187622 2026] [security2:error] [pid 230252:tid 230467] [client 14.139.42.196:12431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9InE0Dwhk5-Z44XrpH5wAAAuw"]
[Tue Jul 21 07:23:24.235361 2026] [security2:error] [pid 229246:tid 229383] [client 20.104.96.117:5073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/177.php"] [unique_id "al9InCBMYeh5YLVG45xsvwAAAhs"]
[Tue Jul 21 07:23:24.528032 2026] [security2:error] [pid 230252:tid 230408] [client 20.104.96.117:64041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/config.php"] [unique_id "al9InE0Dwhk5-Z44XrpH6gAAArE"]
[Tue Jul 21 07:23:24.535747 2026] [security2:error] [pid 229246:tid 229501] [client 20.226.60.151:56879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/hosty.php"] [unique_id "al9InCBMYeh5YLVG45xsxAAAApE"]
[Tue Jul 21 07:23:24.584759 2026] [security2:error] [pid 230252:tid 230481] [client 117.251.86.144:51968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9InE0Dwhk5-Z44XrpH7AAAAvo"]
[Tue Jul 21 07:23:24.584902 2026] [security2:error] [pid 230252:tid 230481] [client 117.251.86.144:51968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9InE0Dwhk5-Z44XrpH7AAAAvo"]
[Tue Jul 21 07:23:24.616889 2026] [security2:error] [pid 230252:tid 230279] [remote 157.66.26.183:60696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9InE0Dwhk5-Z44XrpH7QACoRk"]
[Tue Jul 21 07:23:25.008716 2026] [security2:error] [pid 229246:tid 229484] [client 20.104.96.117:64049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/gettest.php"] [unique_id "al9InSBMYeh5YLVG45xszgAAAoA"]
[Tue Jul 21 07:23:25.020755 2026] [security2:error] [pid 229246:tid 229477] [client 20.226.60.151:54586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/nano.php"] [unique_id "al9InSBMYeh5YLVG45xszwAAAnk"]
[Tue Jul 21 07:23:25.036624 2026] [security2:error] [pid 229246:tid 229398] [client 20.151.10.161:26398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/test11.php"] [unique_id "al9InSBMYeh5YLVG45xs0gAAAio"]
[Tue Jul 21 07:23:25.160530 2026] [security2:error] [pid 230252:tid 230417] [client 62.102.148.164:59696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9InU0Dwhk5-Z44XrpH8wAAAro"]
[Tue Jul 21 07:23:25.160625 2026] [security2:error] [pid 230252:tid 230417] [client 62.102.148.164:59696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9InU0Dwhk5-Z44XrpH8wAAAro"]
[Tue Jul 21 07:23:25.223019 2026] [security2:error] [pid 230252:tid 230452] [client 20.226.60.151:60244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/water.php"] [unique_id "al9InU0Dwhk5-Z44XrpH9AAAAt0"]
[Tue Jul 21 07:23:25.455138 2026] [security2:error] [pid 230252:tid 230322] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9InU0Dwhk5-Z44XrpH9wACzUQ"]
[Tue Jul 21 07:23:25.455314 2026] [security2:error] [pid 230252:tid 230436] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9InU0Dwhk5-Z44XrpH9wACzUQ"]
[Tue Jul 21 07:23:25.466135 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:62971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/min.php"] [unique_id "al9InU0Dwhk5-Z44XrpH-AAAAw4"]
[Tue Jul 21 07:23:25.849598 2026] [security2:error] [pid 230252:tid 230296] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9InU0Dwhk5-Z44XrpH_AAC2Co"]
[Tue Jul 21 07:23:25.849772 2026] [security2:error] [pid 230252:tid 230447] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9InU0Dwhk5-Z44XrpH_AAC2Co"]
[Tue Jul 21 07:23:25.928914 2026] [security2:error] [pid 230252:tid 230418] [client 20.104.96.117:62974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/dvjul.php"] [unique_id "al9InU0Dwhk5-Z44XrpIAAAAArs"]
[Tue Jul 21 07:23:25.969317 2026] [security2:error] [pid 229246:tid 229393] [client 20.151.10.161:49046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/fpwch.php"] [unique_id "al9InSBMYeh5YLVG45xs3QAAAiU"]
[Tue Jul 21 07:23:26.032752 2026] [security2:error] [pid 230252:tid 230307] [remote 150.95.80.135:40618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.80.95.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIBAAC0jU"]
[Tue Jul 21 07:23:26.032904 2026] [security2:error] [pid 230252:tid 230441] [client 150.95.80.135:40618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIBAAC0jU"]
[Tue Jul 21 07:23:26.330476 2026] [security2:error] [pid 230252:tid 230367] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIBgADAHA"]
[Tue Jul 21 07:23:26.330675 2026] [security2:error] [pid 230252:tid 230487] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIBgADAHA"]
[Tue Jul 21 07:23:26.410255 2026] [security2:error] [pid 229246:tid 229473] [client 20.104.96.117:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/biufile.php"] [unique_id "al9IniBMYeh5YLVG45xs4wAAAnU"]
[Tue Jul 21 07:23:26.455896 2026] [security2:error] [pid 230252:tid 230464] [client 20.226.60.151:56937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/k.php"] [unique_id "al9Ink0Dwhk5-Z44XrpICwAAAuk"]
[Tue Jul 21 07:23:26.542352 2026] [security2:error] [pid 230252:tid 230294] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIDQACySg"]
[Tue Jul 21 07:23:26.542506 2026] [security2:error] [pid 230252:tid 230432] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIDQACySg"]
[Tue Jul 21 07:23:26.839108 2026] [security2:error] [pid 230252:tid 230455] [client 20.104.96.117:62925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/av.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIEQAAAuA"]
[Tue Jul 21 07:23:26.885276 2026] [security2:error] [pid 230252:tid 230452] [client 20.151.10.161:49030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/w2025.php"] [unique_id "al9Ink0Dwhk5-Z44XrpIEgAAAt0"]
[Tue Jul 21 07:23:27.152462 2026] [security2:error] [pid 229246:tid 229496] [client 34.62.211.118:60889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.211.62.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sevenviewlentes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9InyBMYeh5YLVG45xs7wAAAow"]
[Tue Jul 21 07:23:27.165457 2026] [security2:error] [pid 229246:tid 229490] [client 136.144.33.111:27757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9InyBMYeh5YLVG45xs8QAAAoY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:27.268553 2026] [security2:error] [pid 230252:tid 230441] [client 20.104.96.117:62921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/coffexium.php"] [unique_id "al9In00Dwhk5-Z44XrpIOgAAAtI"]
[Tue Jul 21 07:23:27.330413 2026] [security2:error] [pid 229246:tid 229387] [client 109.248.148.246:36062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9InyBMYeh5YLVG45xs8gAAAh8"]
[Tue Jul 21 07:23:27.330510 2026] [security2:error] [pid 229246:tid 229387] [client 109.248.148.246:36062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9InyBMYeh5YLVG45xs8gAAAh8"]
[Tue Jul 21 07:23:27.404999 2026] [security2:error] [pid 230252:tid 230457] [client 20.226.60.151:54582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/moon.php"] [unique_id "al9In00Dwhk5-Z44XrpIRgAAAuI"]
[Tue Jul 21 07:23:27.741864 2026] [security2:error] [pid 229246:tid 229412] [client 20.104.96.117:4172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/core.php"] [unique_id "al9InyBMYeh5YLVG45xs-QAAAjg"]
[Tue Jul 21 07:23:28.005324 2026] [security2:error] [pid 229246:tid 229386] [client 20.226.60.151:56957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/aaa.php"] [unique_id "al9IoCBMYeh5YLVG45xs_QAAAh4"]
[Tue Jul 21 07:23:28.099891 2026] [security2:error] [pid 230252:tid 230420] [client 20.104.96.117:62942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/als.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIYQAAAr0"]
[Tue Jul 21 07:23:28.178479 2026] [security2:error] [pid 229246:tid 229380] [client 34.62.211.118:55250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9IoCBMYeh5YLVG45xtBQAAAhg"]
[Tue Jul 21 07:23:28.187512 2026] [security2:error] [pid 230252:tid 230446] [client 20.226.60.151:60266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/nano.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIYwAAAtc"]
[Tue Jul 21 07:23:28.495152 2026] [security2:error] [pid 230252:tid 230295] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIZgADCCk"]
[Tue Jul 21 07:23:28.495292 2026] [security2:error] [pid 230252:tid 230495] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIZgADCCk"]
[Tue Jul 21 07:23:28.498288 2026] [security2:error] [pid 230252:tid 230416] [client 20.104.96.117:62937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/simple.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIZwAAArk"]
[Tue Jul 21 07:23:28.615349 2026] [security2:error] [pid 230252:tid 230256] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIqwACyQI"]
[Tue Jul 21 07:23:28.615497 2026] [security2:error] [pid 230252:tid 230432] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIqwACyQI"]
[Tue Jul 21 07:23:28.687794 2026] [security2:error] [pid 230252:tid 230447] [client 20.226.60.151:60253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/moon.php"] [unique_id "al9IoE0Dwhk5-Z44XrpIrgAAAtg"]
[Tue Jul 21 07:23:29.094029 2026] [security2:error] [pid 230252:tid 230446] [client 20.104.96.117:64062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/init.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIvAAAAtc"]
[Tue Jul 21 07:23:29.132595 2026] [security2:error] [pid 230252:tid 230427] [client 20.226.60.151:56929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/file5.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIvQAAAsQ"]
[Tue Jul 21 07:23:29.156552 2026] [security2:error] [pid 230252:tid 230388] [client 20.220.225.223:34287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/cro.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIvgAAAp0"]
[Tue Jul 21 07:23:29.192457 2026] [security2:error] [pid 229246:tid 229435] [client 34.62.211.118:50147] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9IoSBMYeh5YLVG45xtFAAAAk8"]
[Tue Jul 21 07:23:29.295276 2026] [security2:error] [pid 230252:tid 230480] [client 20.226.60.151:50785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-info.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIvwAAAvk"]
[Tue Jul 21 07:23:29.510249 2026] [security2:error] [pid 229246:tid 229446] [client 20.104.96.117:64015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/fpwch.php"] [unique_id "al9IoSBMYeh5YLVG45xtGQAAAlo"]
[Tue Jul 21 07:23:29.587103 2026] [security2:error] [pid 229246:tid 229494] [client 175.45.70.82:58859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IoSBMYeh5YLVG45xtHAAAAoo"]
[Tue Jul 21 07:23:29.587206 2026] [security2:error] [pid 229246:tid 229494] [client 175.45.70.82:58859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IoSBMYeh5YLVG45xtHAAAAoo"]
[Tue Jul 21 07:23:29.617790 2026] [security2:error] [pid 230252:tid 230509] [client 103.174.34.15:52616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIwgAAAxY"]
[Tue Jul 21 07:23:29.617911 2026] [security2:error] [pid 230252:tid 230509] [client 103.174.34.15:52616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIwgAAAxY"]
[Tue Jul 21 07:23:29.916519 2026] [security2:error] [pid 230252:tid 230392] [client 20.104.96.117:64052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/domvf.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIyAAAAqE"]
[Tue Jul 21 07:23:29.957593 2026] [security2:error] [pid 230252:tid 230395] [client 20.151.10.161:26391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/koala.php"] [unique_id "al9IoU0Dwhk5-Z44XrpIzQAAAqQ"]
[Tue Jul 21 07:23:30.053088 2026] [security2:error] [pid 229246:tid 229394] [client 34.62.211.118:56830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9IoiBMYeh5YLVG45xtIgAAAiY"]
[Tue Jul 21 07:23:30.131067 2026] [security2:error] [pid 230252:tid 230499] [client 213.152.162.104:53330] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Iok0Dwhk5-Z44XrpIzgAAAww"]
[Tue Jul 21 07:23:30.131223 2026] [security2:error] [pid 230252:tid 230499] [client 213.152.162.104:53330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Iok0Dwhk5-Z44XrpIzgAAAww"]
[Tue Jul 21 07:23:30.227569 2026] [security2:error] [pid 230252:tid 230408] [client 20.220.225.223:34184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/cron-tab.php"] [unique_id "al9Iok0Dwhk5-Z44XrpI0QAAArE"]
[Tue Jul 21 07:23:30.287196 2026] [security2:error] [pid 230252:tid 230498] [client 20.226.60.151:50759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/2000.php"] [unique_id "al9Iok0Dwhk5-Z44XrpI0gAAAws"]
[Tue Jul 21 07:23:30.383154 2026] [security2:error] [pid 230252:tid 230475] [client 20.226.60.151:56864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/222.php"] [unique_id "al9Iok0Dwhk5-Z44XrpI0wAAAvQ"]
[Tue Jul 21 07:23:30.400501 2026] [security2:error] [pid 230252:tid 230457] [client 20.104.96.117:4179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp.php"] [unique_id "al9Iok0Dwhk5-Z44XrpI1AAAAuI"]
[Tue Jul 21 07:23:30.810982 2026] [security2:error] [pid 229246:tid 229467] [client 20.226.60.151:54488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-info.php"] [unique_id "al9IoiBMYeh5YLVG45xtKQAAAm8"]
[Tue Jul 21 07:23:30.876066 2026] [security2:error] [pid 229246:tid 229377] [client 20.104.96.117:64056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/class.php"] [unique_id "al9IoiBMYeh5YLVG45xtKwAAAhU"]
[Tue Jul 21 07:23:30.879743 2026] [security2:error] [pid 229246:tid 229423] [client 34.62.211.118:58086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9IoiBMYeh5YLVG45xtLAAAAkM"]
[Tue Jul 21 07:23:30.916667 2026] [security2:error] [pid 229246:tid 229383] [client 74.249.245.134:62143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/66.php"] [unique_id "al9IoiBMYeh5YLVG45xtLQAAAhs"]
[Tue Jul 21 07:23:31.194196 2026] [security2:error] [pid 229246:tid 229501] [client 20.104.96.117:64019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/echkm.php"] [unique_id "al9IoyBMYeh5YLVG45xtMAAAApE"]
[Tue Jul 21 07:23:31.249275 2026] [security2:error] [pid 230252:tid 230478] [client 139.135.44.145:54219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Io00Dwhk5-Z44XrpI1wAAAvc"]
[Tue Jul 21 07:23:31.249372 2026] [security2:error] [pid 230252:tid 230478] [client 139.135.44.145:54219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Io00Dwhk5-Z44XrpI1wAAAvc"]
[Tue Jul 21 07:23:31.282879 2026] [security2:error] [pid 229246:tid 229427] [client 20.197.192.193:52247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/8.php"] [unique_id "al9IoyBMYeh5YLVG45xtNQAAAkc"]
[Tue Jul 21 07:23:31.312555 2026] [security2:error] [pid 230252:tid 230501] [client 193.36.225.70:52829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Io00Dwhk5-Z44XrpI1gAAAw4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:31.342389 2026] [security2:error] [pid 229246:tid 229406] [client 20.151.10.161:49122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/scxy.php"] [unique_id "al9IoyBMYeh5YLVG45xtNgAAAjI"]
[Tue Jul 21 07:23:31.475215 2026] [security2:error] [pid 229246:tid 229390] [client 20.104.96.117:5098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/lib.php"] [unique_id "al9IoyBMYeh5YLVG45xtOAAAAiI"]
[Tue Jul 21 07:23:31.653299 2026] [security2:error] [pid 230252:tid 230420] [client 20.226.60.151:63343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/test.php"] [unique_id "al9Io00Dwhk5-Z44XrpI2AAAAr0"]
[Tue Jul 21 07:23:31.729519 2026] [security2:error] [pid 229246:tid 229430] [client 34.62.211.118:52005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9IoyBMYeh5YLVG45xtPQAAAko"]
[Tue Jul 21 07:23:31.751342 2026] [security2:error] [pid 229246:tid 229412] [client 45.251.232.145:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IoyBMYeh5YLVG45xtPwAAAjg"]
[Tue Jul 21 07:23:31.751461 2026] [security2:error] [pid 229246:tid 229412] [client 45.251.232.145:55248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IoyBMYeh5YLVG45xtPwAAAjg"]
[Tue Jul 21 07:23:31.759758 2026] [security2:error] [pid 230252:tid 230486] [client 20.104.96.117:4181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/login.php"] [unique_id "al9Io00Dwhk5-Z44XrpI3AAAAv8"]
[Tue Jul 21 07:23:31.848745 2026] [security2:error] [pid 229246:tid 229441] [client 103.121.156.110:50821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IoyBMYeh5YLVG45xtQQAAAlU"]
[Tue Jul 21 07:23:31.848879 2026] [security2:error] [pid 229246:tid 229441] [client 103.121.156.110:50821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IoyBMYeh5YLVG45xtQQAAAlU"]
[Tue Jul 21 07:23:31.963307 2026] [security2:error] [pid 230252:tid 230401] [client 20.226.60.151:60274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/122.php"] [unique_id "al9Io00Dwhk5-Z44XrpI3wAAAqo"]
[Tue Jul 21 07:23:32.126280 2026] [security2:error] [pid 230252:tid 230414] [client 20.220.225.223:46089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/kua.php"] [unique_id "al9IpE0Dwhk5-Z44XrpI4AAAArc"]
[Tue Jul 21 07:23:32.231207 2026] [security2:error] [pid 230252:tid 230482] [client 20.104.96.117:5111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/a2.php"] [unique_id "al9IpE0Dwhk5-Z44XrpI4QAAAvs"]
[Tue Jul 21 07:23:32.368173 2026] [security2:error] [pid 230252:tid 230483] [client 20.226.60.151:60202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/mds.php"] [unique_id "al9IpE0Dwhk5-Z44XrpI4gAAAvw"]
[Tue Jul 21 07:23:32.541786 2026] [security2:error] [pid 230252:tid 230392] [client 34.62.211.118:57364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9IpE0Dwhk5-Z44XrpI4wAAAqE"]
[Tue Jul 21 07:23:32.778585 2026] [security2:error] [pid 229246:tid 229402] [client 20.226.60.151:56845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/aaa.php"] [unique_id "al9IpCBMYeh5YLVG45xtTAAAAi4"]
[Tue Jul 21 07:23:32.861873 2026] [security2:error] [pid 229246:tid 229471] [client 20.226.60.151:50780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-blink.php"] [unique_id "al9IpCBMYeh5YLVG45xtTgAAAnM"]
[Tue Jul 21 07:23:32.861987 2026] [security2:error] [pid 229246:tid 229426] [client 20.104.96.117:4173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/d61.php"] [unique_id "al9IpCBMYeh5YLVG45xtTwAAAkY"]
[Tue Jul 21 07:23:32.912593 2026] [security2:error] [pid 229246:tid 229458] [client 74.249.245.134:60034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/666.php"] [unique_id "al9IpCBMYeh5YLVG45xtUQAAAmY"]
[Tue Jul 21 07:23:33.281586 2026] [security2:error] [pid 230252:tid 230497] [client 20.226.60.151:60191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/zc-208.php"] [unique_id "al9IpU0Dwhk5-Z44XrpI5wAAAwo"]
[Tue Jul 21 07:23:33.418548 2026] [security2:error] [pid 229246:tid 229482] [client 20.104.96.117:4187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/info.php"] [unique_id "al9IpSBMYeh5YLVG45xtVwAAAn4"]
[Tue Jul 21 07:23:33.433491 2026] [security2:error] [pid 229246:tid 229457] [client 34.62.211.118:57223] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9IpSBMYeh5YLVG45xtWAAAAmU"]
[Tue Jul 21 07:23:33.753712 2026] [security2:error] [pid 230252:tid 230502] [client 20.226.60.151:60237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/sid4.php"] [unique_id "al9IpU0Dwhk5-Z44XrpI6wAAAw8"]
[Tue Jul 21 07:23:33.996307 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:5072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/11.php"] [unique_id "al9IpU0Dwhk5-Z44XrpI7gAAAuk"]
[Tue Jul 21 07:23:34.142566 2026] [security2:error] [pid 230252:tid 230431] [client 20.220.225.223:46094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ez.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI7wAAAsg"]
[Tue Jul 21 07:23:34.222732 2026] [proxy:error] [pid 230252:tid 230491] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:34.222797 2026] [proxy_http:error] [pid 230252:tid 230491] [client 20.226.60.151:60216] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:34.223382 2026] [proxy:error] [pid 230252:tid 230491] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:34.223414 2026] [proxy_http:error] [pid 230252:tid 230491] [client 20.226.60.151:60216] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:34.345959 2026] [security2:error] [pid 229246:tid 229483] [client 34.62.211.118:63433] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9IpiBMYeh5YLVG45xtYQAAAn8"]
[Tue Jul 21 07:23:34.450069 2026] [security2:error] [pid 230252:tid 230429] [client 20.104.96.117:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/v2.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI9AAAAsY"]
[Tue Jul 21 07:23:34.672797 2026] [security2:error] [pid 230252:tid 230472] [client 103.162.129.114:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI9gAAAvE"]
[Tue Jul 21 07:23:34.672955 2026] [security2:error] [pid 230252:tid 230472] [client 103.162.129.114:52224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI9gAAAvE"]
[Tue Jul 21 07:23:34.750937 2026] [security2:error] [pid 230252:tid 230401] [client 20.226.60.151:56936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/11.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI9wAAAqo"]
[Tue Jul 21 07:23:34.941966 2026] [security2:error] [pid 230252:tid 230404] [client 20.226.60.151:50711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wmore1.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI_QAAAq0"]
[Tue Jul 21 07:23:34.951495 2026] [security2:error] [pid 230252:tid 230388] [client 14.139.42.196:11409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI_gAAAp0"]
[Tue Jul 21 07:23:34.951647 2026] [security2:error] [pid 230252:tid 230388] [client 14.139.42.196:11409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI_gAAAp0"]
[Tue Jul 21 07:23:34.989323 2026] [security2:error] [pid 230252:tid 230468] [client 20.151.10.161:26430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/mac.php"] [unique_id "al9Ipk0Dwhk5-Z44XrpI_wAAAu0"]
[Tue Jul 21 07:23:35.007111 2026] [security2:error] [pid 230252:tid 230444] [client 20.104.96.117:62957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/panel.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJAAAAAtU"]
[Tue Jul 21 07:23:35.165655 2026] [security2:error] [pid 230252:tid 230452] [client 34.62.211.118:52657] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Ip00Dwhk5-Z44XrpJAwAAAt0"]
[Tue Jul 21 07:23:35.318495 2026] [security2:error] [pid 230252:tid 230436] [client 117.251.86.144:37984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJBAAAAs0"]
[Tue Jul 21 07:23:35.318624 2026] [security2:error] [pid 230252:tid 230436] [client 117.251.86.144:37984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJBAAAAs0"]
[Tue Jul 21 07:23:35.551447 2026] [security2:error] [pid 230252:tid 230507] [client 20.151.10.161:26319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJBgAAAxQ"]
[Tue Jul 21 07:23:35.643689 2026] [security2:error] [pid 230252:tid 230475] [client 20.104.96.117:4245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/dex.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJBwAAAvQ"]
[Tue Jul 21 07:23:35.742446 2026] [security2:error] [pid 230252:tid 230474] [client 20.226.60.151:54590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/2000.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJCAAAAvM"]
[Tue Jul 21 07:23:35.913229 2026] [security2:error] [pid 230252:tid 230389] [client 20.220.225.223:34464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/koiy.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJDAAAAp4"]
[Tue Jul 21 07:23:35.949444 2026] [security2:error] [pid 230252:tid 230311] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJDQAC0jk"]
[Tue Jul 21 07:23:35.949592 2026] [security2:error] [pid 230252:tid 230441] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ip00Dwhk5-Z44XrpJDQAC0jk"]
[Tue Jul 21 07:23:36.007404 2026] [security2:error] [pid 230252:tid 230464] [client 20.197.192.193:52234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/red.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJDgAAAuk"]
[Tue Jul 21 07:23:36.171968 2026] [security2:error] [pid 229246:tid 229479] [client 34.62.211.118:57636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9IqCBMYeh5YLVG45xtcwAAAns"]
[Tue Jul 21 07:23:36.211966 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:62963] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/1.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJEAAAAuQ"]
[Tue Jul 21 07:23:36.212088 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:62963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/1.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJEAAAAuQ"]
[Tue Jul 21 07:23:36.245012 2026] [security2:error] [pid 230252:tid 230471] [client 20.220.225.223:46104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/fz.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJEQAAAvA"]
[Tue Jul 21 07:23:36.263609 2026] [security2:error] [pid 230252:tid 230431] [client 20.226.60.151:56931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/mac.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJEgAAAsg"]
[Tue Jul 21 07:23:36.382245 2026] [security2:error] [pid 230252:tid 230462] [client 193.36.225.69:60971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJEwAAAuc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:36.484857 2026] [security2:error] [pid 229246:tid 229486] [client 20.151.10.161:26408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wefile.php"] [unique_id "al9IqCBMYeh5YLVG45xtdgAAAoI"]
[Tue Jul 21 07:23:36.569495 2026] [security2:error] [pid 230252:tid 230351] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJFgAC7GA"]
[Tue Jul 21 07:23:36.569681 2026] [security2:error] [pid 230252:tid 230467] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJFgAC7GA"]
[Tue Jul 21 07:23:36.593426 2026] [security2:error] [pid 229246:tid 229448] [client 20.104.96.117:5097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/ms.php"] [unique_id "al9IqCBMYeh5YLVG45xteAAAAlw"]
[Tue Jul 21 07:23:36.919370 2026] [security2:error] [pid 230252:tid 230401] [client 20.226.60.151:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/solo1.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJGAAAAqo"]
[Tue Jul 21 07:23:36.940096 2026] [security2:error] [pid 230252:tid 230369] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJGwAC8XI"]
[Tue Jul 21 07:23:36.940283 2026] [security2:error] [pid 230252:tid 230472] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IqE0Dwhk5-Z44XrpJGwAC8XI"]
[Tue Jul 21 07:23:37.022524 2026] [security2:error] [pid 229246:tid 229403] [client 34.62.211.118:61993] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9IqSBMYeh5YLVG45xtfwAAAi8"]
[Tue Jul 21 07:23:37.037753 2026] [security2:error] [pid 229246:tid 229292] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IqSBMYeh5YLVG45xtgAACUS0"]
[Tue Jul 21 07:23:37.037891 2026] [security2:error] [pid 229246:tid 229437] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IqSBMYeh5YLVG45xtgAACUS0"]
[Tue Jul 21 07:23:37.073624 2026] [security2:error] [pid 230252:tid 230413] [client 20.226.60.151:56944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/chosen.php"] [unique_id "al9IqU0Dwhk5-Z44XrpJHAAAArY"]
[Tue Jul 21 07:23:37.088353 2026] [proxy:error] [pid 230252:tid 230393] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:37.088426 2026] [proxy_http:error] [pid 230252:tid 230393] [client 20.104.96.117:5105] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:37.089132 2026] [proxy:error] [pid 230252:tid 230393] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:37.089160 2026] [proxy_http:error] [pid 230252:tid 230393] [client 20.104.96.117:5105] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:37.199209 2026] [security2:error] [pid 230252:tid 230468] [client 109.248.148.246:50054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IqU0Dwhk5-Z44XrpJIQAAAu0"]
[Tue Jul 21 07:23:37.199309 2026] [security2:error] [pid 230252:tid 230468] [client 109.248.148.246:50054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9IqU0Dwhk5-Z44XrpJIQAAAu0"]
[Tue Jul 21 07:23:37.462695 2026] [security2:error] [pid 230252:tid 230410] [client 20.226.60.151:56862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/cream1.php"] [unique_id "al9IqU0Dwhk5-Z44XrpJJAAAArM"]
[Tue Jul 21 07:23:37.473721 2026] [security2:error] [pid 230252:tid 230436] [client 20.104.96.117:62951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/memberfuns.php"] [unique_id "al9IqU0Dwhk5-Z44XrpJJgAAAs0"]
[Tue Jul 21 07:23:37.763462 2026] [security2:error] [pid 229246:tid 229459] [client 20.104.96.117:5064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/0.php"] [unique_id "al9IqSBMYeh5YLVG45xthwAAAmc"]
[Tue Jul 21 07:23:37.881528 2026] [security2:error] [pid 229246:tid 229447] [client 20.151.10.161:49044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/FWAZ.php"] [unique_id "al9IqSBMYeh5YLVG45xtigAAAls"]
[Tue Jul 21 07:23:37.958377 2026] [security2:error] [pid 229246:tid 229462] [client 62.102.148.164:42548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9IqSBMYeh5YLVG45xtjAAAAmo"]
[Tue Jul 21 07:23:37.958470 2026] [security2:error] [pid 229246:tid 229462] [client 62.102.148.164:42548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9IqSBMYeh5YLVG45xtjAAAAmo"]
[Tue Jul 21 07:23:38.036612 2026] [proxy:error] [pid 229246:tid 229273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:38.036647 2026] [proxy_http:error] [pid 229246:tid 229273] [remote 74.7.175.166:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:38.037217 2026] [proxy:error] [pid 229246:tid 229273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:38.037239 2026] [proxy_http:error] [pid 229246:tid 229273] [remote 74.7.175.166:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:38.046571 2026] [security2:error] [pid 229246:tid 229496] [client 74.249.245.134:56013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/byp.php"] [unique_id "al9IqiBMYeh5YLVG45xtjwAAAow"]
[Tue Jul 21 07:23:38.065897 2026] [security2:error] [pid 229246:tid 229394] [client 20.104.96.117:64034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/BDKR28.php"] [unique_id "al9IqiBMYeh5YLVG45xtkAAAAiY"]
[Tue Jul 21 07:23:38.147301 2026] [security2:error] [pid 230252:tid 230507] [client 34.62.211.118:62143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sevenviewlentes.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Iqk0Dwhk5-Z44XrpJLQAAAxQ"]
[Tue Jul 21 07:23:38.441682 2026] [proxy:error] [pid 229246:tid 229499] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:38.441750 2026] [proxy_http:error] [pid 229246:tid 229499] [client 20.226.60.151:50775] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:38.442329 2026] [proxy:error] [pid 229246:tid 229499] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:38.442356 2026] [proxy_http:error] [pid 229246:tid 229499] [client 20.226.60.151:50775] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:38.606401 2026] [security2:error] [pid 230252:tid 230471] [client 20.104.96.117:62936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/green1.php"] [unique_id "al9Iqk0Dwhk5-Z44XrpJMwAAAvA"]
[Tue Jul 21 07:23:38.693987 2026] [security2:error] [pid 230252:tid 230502] [client 103.174.34.15:53109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iqk0Dwhk5-Z44XrpJNQAAAw8"]
[Tue Jul 21 07:23:38.694151 2026] [security2:error] [pid 230252:tid 230502] [client 103.174.34.15:53109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iqk0Dwhk5-Z44XrpJNQAAAw8"]
[Tue Jul 21 07:23:39.120808 2026] [security2:error] [pid 230252:tid 230486] [client 20.151.10.161:26484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Iq00Dwhk5-Z44XrpJOQAAAv8"]
[Tue Jul 21 07:23:39.254008 2026] [security2:error] [pid 230252:tid 230304] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Iq00Dwhk5-Z44XrpJOgAC1zI"]
[Tue Jul 21 07:23:39.254134 2026] [security2:error] [pid 230252:tid 230446] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Iq00Dwhk5-Z44XrpJOgAC1zI"]
[Tue Jul 21 07:23:39.255326 2026] [security2:error] [pid 229246:tid 229255] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IqyBMYeh5YLVG45xtnAACMQg"]
[Tue Jul 21 07:23:39.255437 2026] [security2:error] [pid 229246:tid 229405] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IqyBMYeh5YLVG45xtnAACMQg"]
[Tue Jul 21 07:23:39.262167 2026] [security2:error] [pid 230252:tid 230416] [client 20.104.96.117:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/nc4.php"] [unique_id "al9Iq00Dwhk5-Z44XrpJOwAAArk"]
[Tue Jul 21 07:23:39.424636 2026] [security2:error] [pid 230252:tid 230509] [client 20.226.60.151:50782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/cong.php"] [unique_id "al9Iq00Dwhk5-Z44XrpJPAAAAxY"]
[Tue Jul 21 07:23:39.637068 2026] [security2:error] [pid 230252:tid 230414] [client 20.104.96.117:5084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/a1.php"] [unique_id "al9Iq00Dwhk5-Z44XrpJQAAAArc"]
[Tue Jul 21 07:23:39.967085 2026] [security2:error] [pid 230252:tid 230417] [client 20.220.225.223:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/la.php"] [unique_id "al9Iq00Dwhk5-Z44XrpJQwAAAro"]
[Tue Jul 21 07:23:40.010995 2026] [security2:error] [pid 230252:tid 230429] [client 213.152.162.104:33660] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9IrE0Dwhk5-Z44XrpJRAAAAsY"]
[Tue Jul 21 07:23:40.011102 2026] [security2:error] [pid 230252:tid 230429] [client 213.152.162.104:33660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9IrE0Dwhk5-Z44XrpJRAAAAsY"]
[Tue Jul 21 07:23:40.026540 2026] [security2:error] [pid 229246:tid 229470] [client 20.104.96.117:64030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/eee.php"] [unique_id "al9IrCBMYeh5YLVG45xtqAAAAnI"]
[Tue Jul 21 07:23:40.147609 2026] [autoindex:error] [pid 230252:tid 230508] [client 20.226.60.151:56877] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:40.211365 2026] [autoindex:error] [pid 230252:tid 230497] [client 20.226.60.151:56877] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:40.217443 2026] [security2:error] [pid 230252:tid 230412] [client 20.226.60.151:56940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/dr.php"] [unique_id "al9IrE0Dwhk5-Z44XrpJSQAAArU"]
[Tue Jul 21 07:23:40.349957 2026] [security2:error] [pid 229246:tid 229480] [client 175.45.70.82:59362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IrCBMYeh5YLVG45xtqwAAAnw"]
[Tue Jul 21 07:23:40.350151 2026] [security2:error] [pid 229246:tid 229480] [client 175.45.70.82:59362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IrCBMYeh5YLVG45xtqwAAAnw"]
[Tue Jul 21 07:23:40.443835 2026] [security2:error] [pid 230252:tid 230452] [client 20.104.96.117:4180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/wp-aothait.php"] [unique_id "al9IrE0Dwhk5-Z44XrpJSgAAAt0"]
[Tue Jul 21 07:23:40.453642 2026] [security2:error] [pid 230252:tid 230436] [client 20.151.10.161:26424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/2P.php"] [unique_id "al9IrE0Dwhk5-Z44XrpJSwAAAs0"]
[Tue Jul 21 07:23:40.834211 2026] [proxy:error] [pid 229246:tid 229472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:40.834288 2026] [proxy_http:error] [pid 229246:tid 229472] [client 20.226.60.151:60248] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:40.834887 2026] [proxy:error] [pid 229246:tid 229472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:23:40.834920 2026] [proxy_http:error] [pid 229246:tid 229472] [client 20.226.60.151:60248] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:23:41.155249 2026] [security2:error] [pid 230252:tid 230507] [client 20.104.96.117:62970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/config.json.php"] [unique_id "al9IrU0Dwhk5-Z44XrpJUgAAAxQ"]
[Tue Jul 21 07:23:41.248880 2026] [security2:error] [pid 230252:tid 230488] [client 74.7.175.185:57158] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.hctreinamentos.net"] [uri "/index.php"] [unique_id "al9IrU0Dwhk5-Z44XrpJUwADAQg"]
[Tue Jul 21 07:23:41.352713 2026] [security2:error] [pid 230252:tid 230476] [client 20.197.192.193:53133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/fffm.php"] [unique_id "al9IrU0Dwhk5-Z44XrpJVAAAAvU"]
[Tue Jul 21 07:23:41.643137 2026] [security2:error] [pid 230252:tid 230419] [client 20.104.96.117:5102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9IrU0Dwhk5-Z44XrpJVwAAArw"]
[Tue Jul 21 07:23:41.800351 2026] [security2:error] [pid 229246:tid 229458] [client 20.226.60.151:56925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/x.php"] [unique_id "al9IrSBMYeh5YLVG45xtvwAAAmY"]
[Tue Jul 21 07:23:41.865392 2026] [security2:error] [pid 229246:tid 229451] [client 193.36.225.63:44221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IrSBMYeh5YLVG45xtvgAAAl8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:41.894389 2026] [security2:error] [pid 229246:tid 229402] [client 20.226.60.151:50793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/public/css.php"] [unique_id "al9IrSBMYeh5YLVG45xtwAAAAi4"]
[Tue Jul 21 07:23:41.963049 2026] [security2:error] [pid 229246:tid 229452] [client 20.151.10.161:26540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/.well-known/about.php"] [unique_id "al9IrSBMYeh5YLVG45xtwgAAAmA"]
[Tue Jul 21 07:23:42.142569 2026] [security2:error] [pid 229246:tid 229459] [client 74.249.245.134:43514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/date.php"] [unique_id "al9IriBMYeh5YLVG45xtwwAAAmc"]
[Tue Jul 21 07:23:42.161525 2026] [security2:error] [pid 230252:tid 230427] [client 20.104.96.117:62944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/k2.php"] [unique_id "al9Irk0Dwhk5-Z44XrpJXQAAAsQ"]
[Tue Jul 21 07:23:42.191438 2026] [security2:error] [pid 229246:tid 229426] [client 139.135.44.145:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IriBMYeh5YLVG45xtxQAAAkY"]
[Tue Jul 21 07:23:42.192271 2026] [security2:error] [pid 229246:tid 229426] [client 139.135.44.145:53186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IriBMYeh5YLVG45xtxQAAAkY"]
[Tue Jul 21 07:23:42.220703 2026] [security2:error] [pid 230252:tid 230400] [client 45.251.232.145:56071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Irk0Dwhk5-Z44XrpJXgAAAqk"]
[Tue Jul 21 07:23:42.220800 2026] [security2:error] [pid 230252:tid 230400] [client 45.251.232.145:56071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Irk0Dwhk5-Z44XrpJXgAAAqk"]
[Tue Jul 21 07:23:42.493610 2026] [security2:error] [pid 229246:tid 229421] [client 20.226.60.151:60285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/output.php"] [unique_id "al9IriBMYeh5YLVG45xtygAAAkE"]
[Tue Jul 21 07:23:42.499115 2026] [security2:error] [pid 229246:tid 229456] [client 103.121.156.110:51160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IriBMYeh5YLVG45xtywAAAmQ"]
[Tue Jul 21 07:23:42.499243 2026] [security2:error] [pid 229246:tid 229456] [client 103.121.156.110:51160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IriBMYeh5YLVG45xtywAAAmQ"]
[Tue Jul 21 07:23:42.583243 2026] [security2:error] [pid 230252:tid 230416] [client 213.152.162.104:37556] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Irk0Dwhk5-Z44XrpJXwAAArk"]
[Tue Jul 21 07:23:42.583370 2026] [security2:error] [pid 230252:tid 230416] [client 213.152.162.104:37556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Irk0Dwhk5-Z44XrpJXwAAArk"]
[Tue Jul 21 07:23:42.693669 2026] [security2:error] [pid 229246:tid 229429] [client 20.104.96.117:4227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9IriBMYeh5YLVG45xtzAAAAkk"]
[Tue Jul 21 07:23:42.780785 2026] [security2:error] [pid 230252:tid 230482] [client 20.197.192.193:53156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/ftde.php"] [unique_id "al9Irk0Dwhk5-Z44XrpJYQAAAvs"]
[Tue Jul 21 07:23:42.870763 2026] [security2:error] [pid 230252:tid 230458] [client 20.226.60.151:56914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/155.php"] [unique_id "al9Irk0Dwhk5-Z44XrpJYwAAAuM"]
[Tue Jul 21 07:23:42.976337 2026] [security2:error] [pid 229246:tid 229502] [client 20.226.60.151:60235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-file-120.php"] [unique_id "al9IriBMYeh5YLVG45xt0gAAApI"]
[Tue Jul 21 07:23:43.043686 2026] [security2:error] [pid 229246:tid 229467] [client 20.104.96.117:62932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9IryBMYeh5YLVG45xt0wAAAm8"]
[Tue Jul 21 07:23:43.116939 2026] [security2:error] [pid 230252:tid 230358] [remote 69.63.184.23:41596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.184.63.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Ir00Dwhk5-Z44XrpJZQACmmc"]
[Tue Jul 21 07:23:43.160695 2026] [security2:error] [pid 229246:tid 229400] [client 20.151.10.161:65488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9IryBMYeh5YLVG45xt1AAAAiw"]
[Tue Jul 21 07:23:43.264671 2026] [security2:error] [pid 229246:tid 229411] [client 82.102.28.107:60620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IryBMYeh5YLVG45xt2AAAAjc"]
[Tue Jul 21 07:23:43.264765 2026] [security2:error] [pid 229246:tid 229411] [client 82.102.28.107:60620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9IryBMYeh5YLVG45xt2AAAAjc"]
[Tue Jul 21 07:23:43.299085 2026] [security2:error] [pid 229246:tid 229381] [client 20.197.192.193:52238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/yup.php"] [unique_id "al9IryBMYeh5YLVG45xt2QAAAhk"]
[Tue Jul 21 07:23:43.428893 2026] [autoindex:error] [pid 229246:tid 229415] [client 54.164.167.77:0] AH01276: Cannot serve directory /home2/jurand34/jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:43.444505 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.192.193:52261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/jj.php"] [unique_id "al9IryBMYeh5YLVG45xt3AAAAjI"]
[Tue Jul 21 07:23:43.521806 2026] [security2:error] [pid 229246:tid 229480] [client 20.104.96.117:5119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9IryBMYeh5YLVG45xt4AAAAnw"]
[Tue Jul 21 07:23:43.649768 2026] [security2:error] [pid 229246:tid 229412] [client 20.220.225.223:34295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/hp2.php"] [unique_id "al9IryBMYeh5YLVG45xt4wAAAjg"]
[Tue Jul 21 07:23:43.736476 2026] [security2:error] [pid 230252:tid 230430] [client 20.226.60.151:56837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ops.php"] [unique_id "al9Ir00Dwhk5-Z44XrpJlgAAAsc"]
[Tue Jul 21 07:23:43.750092 2026] [autoindex:error] [pid 230252:tid 230392] [client 98.91.173.173:0] AH01276: Cannot serve directory /home2/jurand34/jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:44.026236 2026] [autoindex:error] [pid 230252:tid 230484] [client 98.91.173.173:0] AH01276: Cannot serve directory /home2/jurand34/jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:44.033830 2026] [autoindex:error] [pid 230252:tid 230498] [client 13.219.67.125:0] AH01276: Cannot serve directory /home2/jurand34/jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:44.256950 2026] [security2:error] [pid 230252:tid 230478] [client 20.104.96.117:5099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/for.php"] [unique_id "al9IsE0Dwhk5-Z44XrpJpQAAAvc"]
[Tue Jul 21 07:23:44.295177 2026] [security2:error] [pid 230252:tid 230394] [client 20.197.192.193:52270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/dragonshell.php"] [unique_id "al9IsE0Dwhk5-Z44XrpJqAAAAqM"]
[Tue Jul 21 07:23:44.410048 2026] [security2:error] [pid 229246:tid 229491] [client 20.220.225.223:46084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/nhvoanpl.php"] [unique_id "al9IsCBMYeh5YLVG45xt7QAAAoc"]
[Tue Jul 21 07:23:44.456825 2026] [security2:error] [pid 230252:tid 230374] [remote 5.252.52.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tavarescont.com.br"] [uri "/wp-login.php"] [unique_id "al9IsE0Dwhk5-Z44XrpJqQACvHc"]
[Tue Jul 21 07:23:44.458553 2026] [security2:error] [pid 229246:tid 229443] [client 20.151.10.161:49132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/qterm.php"] [unique_id "al9IsCBMYeh5YLVG45xt7gAAAlc"]
[Tue Jul 21 07:23:44.540313 2026] [security2:error] [pid 230252:tid 230450] [client 20.226.60.151:56946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/file31.php"] [unique_id "al9IsE0Dwhk5-Z44XrpJqgAAAts"]
[Tue Jul 21 07:23:44.598161 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:5107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.cmpartners.com.br"] [uri "/raw.php"] [unique_id "al9IsCBMYeh5YLVG45xt8AAAAi8"]
[Tue Jul 21 07:23:44.920946 2026] [security2:error] [pid 230252:tid 230471] [client 20.151.10.161:26502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9IsE0Dwhk5-Z44XrpJsAAAAvA"]
[Tue Jul 21 07:23:45.082407 2026] [security2:error] [pid 229246:tid 229426] [client 20.226.60.151:54573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/122.php"] [unique_id "al9IsSBMYeh5YLVG45xt9gAAAkY"]
[Tue Jul 21 07:23:45.249906 2026] [security2:error] [pid 230252:tid 230254] [remote 34.53.218.211:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.218.53.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "santaofertas.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IsU0Dwhk5-Z44XrpJswAC-QA"]
[Tue Jul 21 07:23:45.261441 2026] [security2:error] [pid 230252:tid 230401] [client 20.226.60.151:50809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/special.php"] [unique_id "al9IsU0Dwhk5-Z44XrpJtAAAAqo"]
[Tue Jul 21 07:23:45.261676 2026] [security2:error] [pid 230252:tid 230472] [client 20.226.60.151:56867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/file6.php"] [unique_id "al9IsU0Dwhk5-Z44XrpJtQAAAvE"]
[Tue Jul 21 07:23:45.420706 2026] [security2:error] [pid 230252:tid 230270] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9IsU0Dwhk5-Z44XrpJuQACohA"]
[Tue Jul 21 07:23:45.477666 2026] [security2:error] [pid 230252:tid 230467] [client 103.162.129.114:52688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IsU0Dwhk5-Z44XrpJuwAAAuw"]
[Tue Jul 21 07:23:45.477845 2026] [security2:error] [pid 230252:tid 230467] [client 103.162.129.114:52688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IsU0Dwhk5-Z44XrpJuwAAAuw"]
[Tue Jul 21 07:23:45.563979 2026] [security2:error] [pid 230252:tid 230272] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9IsU0Dwhk5-Z44XrpJvAAC1RI"]
[Tue Jul 21 07:23:45.690719 2026] [security2:error] [pid 229246:tid 229447] [client 14.139.42.196:13682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.42.139.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IsSBMYeh5YLVG45xt-wAAAls"]
[Tue Jul 21 07:23:45.690865 2026] [security2:error] [pid 229246:tid 229447] [client 14.139.42.196:13682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "potencialilimitado.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IsSBMYeh5YLVG45xt-wAAAls"]
[Tue Jul 21 07:23:45.707057 2026] [security2:error] [pid 230252:tid 230381] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9IsU0Dwhk5-Z44XrpJvgADFX4"]
[Tue Jul 21 07:23:45.794568 2026] [security2:error] [pid 229246:tid 229497] [client 20.151.10.161:65441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9IsSBMYeh5YLVG45xt_AAAAo0"]
[Tue Jul 21 07:23:45.847770 2026] [security2:error] [pid 230252:tid 230349] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9IsU0Dwhk5-Z44XrpJwgACoV4"]
[Tue Jul 21 07:23:46.010510 2026] [security2:error] [pid 230252:tid 230328] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Isk0Dwhk5-Z44XrpJwwAC8kk"]
[Tue Jul 21 07:23:46.123260 2026] [security2:error] [pid 230252:tid 230385] [client 117.251.86.144:58942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJxgAAApo"]
[Tue Jul 21 07:23:46.123378 2026] [security2:error] [pid 230252:tid 230385] [client 117.251.86.144:58942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJxgAAApo"]
[Tue Jul 21 07:23:46.193284 2026] [security2:error] [pid 230252:tid 230314] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Isk0Dwhk5-Z44XrpJxwAC9Dw"]
[Tue Jul 21 07:23:46.381733 2026] [security2:error] [pid 230252:tid 230292] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Isk0Dwhk5-Z44XrpJzgAC8yY"]
[Tue Jul 21 07:23:46.413138 2026] [security2:error] [pid 230252:tid 230448] [client 74.249.245.134:61767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/pomo.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJzwAAAtk"]
[Tue Jul 21 07:23:46.472240 2026] [security2:error] [pid 230252:tid 230277] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJ0AADEBc"]
[Tue Jul 21 07:23:46.472345 2026] [security2:error] [pid 230252:tid 230503] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJ0AADEBc"]
[Tue Jul 21 07:23:46.531221 2026] [security2:error] [pid 230252:tid 230325] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Isk0Dwhk5-Z44XrpJ0QAC6UY"]
[Tue Jul 21 07:23:46.638220 2026] [security2:error] [pid 230252:tid 230431] [client 20.197.192.193:53134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/wp-mt.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJ0wAAAsg"]
[Tue Jul 21 07:23:46.733588 2026] [security2:error] [pid 230252:tid 230347] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Isk0Dwhk5-Z44XrpJ1wACmVw"]
[Tue Jul 21 07:23:46.761212 2026] [security2:error] [pid 230252:tid 230411] [client 103.191.123.19:30018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.123.191.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "girassollimpeza.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJ2AAAArQ"]
[Tue Jul 21 07:23:46.761331 2026] [security2:error] [pid 230252:tid 230411] [client 103.191.123.19:30018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "girassollimpeza.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJ2AAAArQ"]
[Tue Jul 21 07:23:46.779618 2026] [security2:error] [pid 230252:tid 230459] [client 193.36.225.54:52569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJ2QAAAuQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:46.873808 2026] [security2:error] [pid 230252:tid 230487] [client 20.220.225.223:45997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/inso.php"] [unique_id "al9Isk0Dwhk5-Z44XrpJ3QAAAwA"]
[Tue Jul 21 07:23:46.945854 2026] [security2:error] [pid 230252:tid 230289] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Isk0Dwhk5-Z44XrpJ3gACxCM"]
[Tue Jul 21 07:23:47.075201 2026] [security2:error] [pid 230252:tid 230445] [client 74.249.245.134:61439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/test1.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ4AAAAtY"]
[Tue Jul 21 07:23:47.077431 2026] [security2:error] [pid 229246:tid 229423] [client 20.220.225.223:34490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/hp3.php"] [unique_id "al9IsyBMYeh5YLVG45xuCQAAAkM"]
[Tue Jul 21 07:23:47.213309 2026] [security2:error] [pid 230252:tid 230458] [client 20.151.10.161:26436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/bob.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ4QAAAuM"]
[Tue Jul 21 07:23:47.260903 2026] [security2:error] [pid 230252:tid 230313] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Is00Dwhk5-Z44XrpJ4wAC_Ds"]
[Tue Jul 21 07:23:47.293287 2026] [security2:error] [pid 230252:tid 230350] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ5QAC518"]
[Tue Jul 21 07:23:47.293440 2026] [security2:error] [pid 230252:tid 230462] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ5QAC518"]
[Tue Jul 21 07:23:47.480987 2026] [security2:error] [pid 230252:tid 230444] [client 20.151.10.161:63695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/media.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ6AAAAtU"]
[Tue Jul 21 07:23:47.481910 2026] [security2:error] [pid 230252:tid 230274] [remote 34.53.218.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "santaofertas.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Is00Dwhk5-Z44XrpJ6QAC0BQ"]
[Tue Jul 21 07:23:47.515175 2026] [security2:error] [pid 230252:tid 230321] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ6gACokM"]
[Tue Jul 21 07:23:47.515330 2026] [security2:error] [pid 230252:tid 230393] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ6gACokM"]
[Tue Jul 21 07:23:47.613658 2026] [security2:error] [pid 230252:tid 230344] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ7AAC9lk"]
[Tue Jul 21 07:23:47.613786 2026] [security2:error] [pid 230252:tid 230477] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Is00Dwhk5-Z44XrpJ7AAC9lk"]
[Tue Jul 21 07:23:48.448810 2026] [autoindex:error] [pid 230252:tid 230484] [client 20.226.60.151:56847] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:23:48.479955 2026] [security2:error] [pid 229246:tid 229398] [client 20.226.60.151:56922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/adminfuns.php"] [unique_id "al9ItCBMYeh5YLVG45xuIAAAAio"]
[Tue Jul 21 07:23:48.493159 2026] [security2:error] [pid 229246:tid 229441] [client 74.249.245.134:21938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/fw.php"] [unique_id "al9ItCBMYeh5YLVG45xuIgAAAlU"]
[Tue Jul 21 07:23:48.740329 2026] [security2:error] [pid 230252:tid 230459] [client 20.226.60.151:60280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/as.php"] [unique_id "al9ItE0Dwhk5-Z44XrpJ_AAAAuQ"]
[Tue Jul 21 07:23:48.818766 2026] [access_compat:error] [pid 230252:tid 230486] [client 162.241.63.68:53204] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:23:49.010586 2026] [security2:error] [pid 230252:tid 230458] [client 149.102.142.63:44864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "bomexito.com.br"] [uri "/"] [unique_id "al9ItU0Dwhk5-Z44XrpKAQAAAuM"]
[Tue Jul 21 07:23:49.251554 2026] [security2:error] [pid 230252:tid 230432] [client 20.151.10.161:49126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/blurbs.php"] [unique_id "al9ItU0Dwhk5-Z44XrpKBgAAAsk"]
[Tue Jul 21 07:23:49.401066 2026] [security2:error] [pid 230252:tid 230412] [client 20.151.10.161:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/images.php"] [unique_id "al9ItU0Dwhk5-Z44XrpKBwAAArU"]
[Tue Jul 21 07:23:49.680668 2026] [security2:error] [pid 230252:tid 230440] [client 103.174.34.15:53587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ItU0Dwhk5-Z44XrpKCwAAAtE"]
[Tue Jul 21 07:23:49.680775 2026] [security2:error] [pid 230252:tid 230440] [client 103.174.34.15:53587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ItU0Dwhk5-Z44XrpKCwAAAtE"]
[Tue Jul 21 07:23:49.742029 2026] [security2:error] [pid 230252:tid 230430] [client 142.44.228.250:53658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "egcbatiment.com"] [uri "/robots.txt"] [unique_id "al9ItU0Dwhk5-Z44XrpKDAAAAsc"]
[Tue Jul 21 07:23:49.742115 2026] [security2:error] [pid 230252:tid 230430] [client 142.44.228.250:53658] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "egcbatiment.com"] [uri "/robots.txt"] [unique_id "al9ItU0Dwhk5-Z44XrpKDAAAAsc"]
[Tue Jul 21 07:23:49.918186 2026] [security2:error] [pid 229246:tid 229459] [client 20.226.60.151:56912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/goods.php"] [unique_id "al9ItSBMYeh5YLVG45xuQgAAAmc"]
[Tue Jul 21 07:23:49.920220 2026] [security2:error] [pid 229246:tid 229249] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ItSBMYeh5YLVG45xuQwACMwI"]
[Tue Jul 21 07:23:49.920341 2026] [security2:error] [pid 229246:tid 229407] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ItSBMYeh5YLVG45xuQwACMwI"]
[Tue Jul 21 07:23:49.999702 2026] [security2:error] [pid 229246:tid 229298] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9ItSBMYeh5YLVG45xuRgACdTM"]
[Tue Jul 21 07:23:49.999854 2026] [security2:error] [pid 229246:tid 229473] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9ItSBMYeh5YLVG45xuRgACdTM"]
[Tue Jul 21 07:23:50.000163 2026] [security2:error] [pid 229246:tid 229462] [client 20.220.225.223:34242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/aa1.php"] [unique_id "al9ItSBMYeh5YLVG45xuRwAAAmo"]
[Tue Jul 21 07:23:50.316774 2026] [security2:error] [pid 229246:tid 229475] [client 20.226.60.151:50712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9ItiBMYeh5YLVG45xuVgAAAnc"]
[Tue Jul 21 07:23:50.661961 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:45989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wpx.php"] [unique_id "al9Itk0Dwhk5-Z44XrpKEQAAAto"]
[Tue Jul 21 07:23:50.832996 2026] [security2:error] [pid 230252:tid 230441] [client 20.226.60.151:56934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/100.php"] [unique_id "al9Itk0Dwhk5-Z44XrpKFAAAAtI"]
[Tue Jul 21 07:23:51.042955 2026] [security2:error] [pid 230252:tid 230471] [client 74.249.245.134:33793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/fm.php"] [unique_id "al9It00Dwhk5-Z44XrpKGQAAAvA"]
[Tue Jul 21 07:23:51.136515 2026] [security2:error] [pid 229246:tid 229376] [client 175.45.70.82:59865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ItyBMYeh5YLVG45xubgAAAhQ"]
[Tue Jul 21 07:23:51.136661 2026] [security2:error] [pid 229246:tid 229376] [client 175.45.70.82:59865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ItyBMYeh5YLVG45xubgAAAhQ"]
[Tue Jul 21 07:23:51.173305 2026] [security2:error] [pid 230252:tid 230445] [client 213.152.162.104:56110] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9It00Dwhk5-Z44XrpKHwAAAtY"]
[Tue Jul 21 07:23:51.173393 2026] [security2:error] [pid 230252:tid 230445] [client 213.152.162.104:56110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9It00Dwhk5-Z44XrpKHwAAAtY"]
[Tue Jul 21 07:23:51.223048 2026] [security2:error] [pid 230252:tid 230401] [client 20.151.10.161:49056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/v543.php"] [unique_id "al9It00Dwhk5-Z44XrpKIAAAAqo"]
[Tue Jul 21 07:23:51.233380 2026] [security2:error] [pid 230252:tid 230458] [client 20.220.225.223:34271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/acew67.php"] [unique_id "al9It00Dwhk5-Z44XrpKIQAAAuM"]
[Tue Jul 21 07:23:51.310786 2026] [security2:error] [pid 230252:tid 230466] [client 51.222.168.44:40780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "egcbatiment.com"] [uri "/"] [unique_id "al9It00Dwhk5-Z44XrpKIwAAAus"]
[Tue Jul 21 07:23:51.310907 2026] [security2:error] [pid 230252:tid 230466] [client 51.222.168.44:40780] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "egcbatiment.com"] [uri "/"] [unique_id "al9It00Dwhk5-Z44XrpKIwAAAus"]
[Tue Jul 21 07:23:51.365447 2026] [security2:error] [pid 229246:tid 229415] [client 20.151.10.161:26465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/crgio.php"] [unique_id "al9ItyBMYeh5YLVG45xucAAAAjs"]
[Tue Jul 21 07:23:51.445774 2026] [security2:error] [pid 230252:tid 230282] [remote 192.241.143.148:35532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9It00Dwhk5-Z44XrpKJAADFhw"]
[Tue Jul 21 07:23:51.683282 2026] [security2:error] [pid 230252:tid 230396] [client 20.226.60.151:54483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/mds.php"] [unique_id "al9It00Dwhk5-Z44XrpKKgAAAqU"]
[Tue Jul 21 07:23:51.711857 2026] [security2:error] [pid 229246:tid 229451] [client 136.144.33.53:55811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9ItyBMYeh5YLVG45xudgAAAl8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:51.736009 2026] [security2:error] [pid 229246:tid 229492] [client 20.151.10.161:65506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/adminner.php"] [unique_id "al9ItyBMYeh5YLVG45xueAAAAog"]
[Tue Jul 21 07:23:51.910010 2026] [security2:error] [pid 230252:tid 230432] [client 20.226.60.151:56884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/about.php"] [unique_id "al9It00Dwhk5-Z44XrpKKwAAAsk"]
[Tue Jul 21 07:23:51.937520 2026] [security2:error] [pid 230252:tid 230388] [client 82.102.28.107:35904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9It00Dwhk5-Z44XrpKLAAAAp0"]
[Tue Jul 21 07:23:51.937625 2026] [security2:error] [pid 230252:tid 230388] [client 82.102.28.107:35904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9It00Dwhk5-Z44XrpKLAAAAp0"]
[Tue Jul 21 07:23:52.149161 2026] [security2:error] [pid 230252:tid 230475] [client 74.249.245.134:60041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ini.php"] [unique_id "al9IuE0Dwhk5-Z44XrpKMgAAAvQ"]
[Tue Jul 21 07:23:52.562987 2026] [security2:error] [pid 230252:tid 230423] [client 20.226.60.151:50774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/w1px.php"] [unique_id "al9IuE0Dwhk5-Z44XrpKNAAAAsA"]
[Tue Jul 21 07:23:52.701300 2026] [security2:error] [pid 229246:tid 229417] [client 213.152.162.104:48302] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IuCBMYeh5YLVG45xuhwAAAj0"]
[Tue Jul 21 07:23:52.701424 2026] [security2:error] [pid 229246:tid 229417] [client 213.152.162.104:48302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9IuCBMYeh5YLVG45xuhwAAAj0"]
[Tue Jul 21 07:23:52.712943 2026] [security2:error] [pid 230252:tid 230422] [client 45.251.232.145:56593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IuE0Dwhk5-Z44XrpKOQAAAr8"]
[Tue Jul 21 07:23:52.713052 2026] [security2:error] [pid 230252:tid 230422] [client 45.251.232.145:56593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IuE0Dwhk5-Z44XrpKOQAAAr8"]
[Tue Jul 21 07:23:53.226263 2026] [security2:error] [pid 229246:tid 229384] [client 103.121.156.110:51483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IuSBMYeh5YLVG45xukAAAAhw"]
[Tue Jul 21 07:23:53.226411 2026] [security2:error] [pid 229246:tid 229384] [client 103.121.156.110:51483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9IuSBMYeh5YLVG45xukAAAAhw"]
[Tue Jul 21 07:23:53.240185 2026] [security2:error] [pid 229246:tid 229464] [client 20.151.10.161:49115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/w3lls.php"] [unique_id "al9IuSBMYeh5YLVG45xukQAAAmw"]
[Tue Jul 21 07:23:53.281591 2026] [security2:error] [pid 229246:tid 229474] [client 20.226.60.151:54491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-blink.php"] [unique_id "al9IuSBMYeh5YLVG45xukgAAAnY"]
[Tue Jul 21 07:23:53.602993 2026] [security2:error] [pid 229246:tid 229338] [remote 64.225.121.94:42798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/wp-login.php"] [unique_id "al9IuSBMYeh5YLVG45xulQACLVs"]
[Tue Jul 21 07:23:53.717152 2026] [security2:error] [pid 230252:tid 230291] [remote 14.128.14.9:47744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.14.128.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-login.php"] [unique_id "al9IuE0Dwhk5-Z44XrpKOgACmiU"]
[Tue Jul 21 07:23:53.748586 2026] [security2:error] [pid 230252:tid 230487] [client 20.226.60.151:56878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/about.php"] [unique_id "al9IuU0Dwhk5-Z44XrpKPQAAAwA"]
[Tue Jul 21 07:23:54.268377 2026] [security2:error] [pid 230252:tid 230409] [client 139.135.44.145:54021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Iuk0Dwhk5-Z44XrpKQAAAArI"]
[Tue Jul 21 07:23:54.268489 2026] [security2:error] [pid 230252:tid 230409] [client 139.135.44.145:54021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Iuk0Dwhk5-Z44XrpKQAAAArI"]
[Tue Jul 21 07:23:54.372496 2026] [security2:error] [pid 229246:tid 229432] [client 20.226.60.151:60212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/yawa.php"] [unique_id "al9IuiBMYeh5YLVG45xupgAAAkw"]
[Tue Jul 21 07:23:54.420925 2026] [security2:error] [pid 229246:tid 229291] [remote 72.167.132.114:33250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9IuiBMYeh5YLVG45xupwACQyw"]
[Tue Jul 21 07:23:54.514562 2026] [security2:error] [pid 230252:tid 230483] [client 20.151.10.161:49032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-ws68.php"] [unique_id "al9Iuk0Dwhk5-Z44XrpKQQAAAvw"]
[Tue Jul 21 07:23:54.557990 2026] [security2:error] [pid 229246:tid 229470] [client 20.220.225.223:46117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/berlin.php"] [unique_id "al9IuiBMYeh5YLVG45xuqgAAAnI"]
[Tue Jul 21 07:23:54.726647 2026] [security2:error] [pid 229246:tid 229398] [client 20.226.60.151:63296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/admin.php"] [unique_id "al9IuiBMYeh5YLVG45xurgAAAio"]
[Tue Jul 21 07:23:54.782232 2026] [security2:error] [pid 230252:tid 230444] [client 74.249.245.134:61798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/themes.php"] [unique_id "al9Iuk0Dwhk5-Z44XrpKRQAAAtU"]
[Tue Jul 21 07:23:54.811167 2026] [security2:error] [pid 230252:tid 230468] [client 20.197.192.193:53165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/ww.php"] [unique_id "al9Iuk0Dwhk5-Z44XrpKRwAAAu0"]
[Tue Jul 21 07:23:55.042414 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:26541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/pucci.php"] [unique_id "al9IuyBMYeh5YLVG45xutgAAAnk"]
[Tue Jul 21 07:23:55.226453 2026] [security2:error] [pid 229246:tid 229454] [client 20.226.60.151:54481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/zc-208.php"] [unique_id "al9IuyBMYeh5YLVG45xuuAAAAmI"]
[Tue Jul 21 07:23:55.281945 2026] [security2:error] [pid 229246:tid 229384] [client 20.226.60.151:56897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/admin.php"] [unique_id "al9IuyBMYeh5YLVG45xuuwAAAhw"]
[Tue Jul 21 07:23:55.289153 2026] [security2:error] [pid 230252:tid 230392] [client 20.151.10.161:65428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/admin.php"] [unique_id "al9Iu00Dwhk5-Z44XrpKSwAAAqE"]
[Tue Jul 21 07:23:55.362413 2026] [security2:error] [pid 230252:tid 230499] [client 20.220.225.223:46014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/billur.php"] [unique_id "al9Iu00Dwhk5-Z44XrpKTAAAAww"]
[Tue Jul 21 07:23:55.550334 2026] [security2:error] [pid 230252:tid 230410] [client 20.151.10.161:49035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/xyn.php"] [unique_id "al9Iu00Dwhk5-Z44XrpKTQAAArM"]
[Tue Jul 21 07:23:56.099939 2026] [security2:error] [pid 230252:tid 230430] [client 20.226.60.151:60220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/js.php"] [unique_id "al9IvE0Dwhk5-Z44XrpKTgAAAsc"]
[Tue Jul 21 07:23:56.236715 2026] [security2:error] [pid 229246:tid 229485] [client 103.162.129.114:53146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IvCBMYeh5YLVG45xuyQAAAoE"]
[Tue Jul 21 07:23:56.237677 2026] [security2:error] [pid 229246:tid 229485] [client 103.162.129.114:53146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IvCBMYeh5YLVG45xuyQAAAoE"]
[Tue Jul 21 07:23:56.585903 2026] [security2:error] [pid 230252:tid 230456] [client 20.151.10.161:49039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/green3.php"] [unique_id "al9IvE0Dwhk5-Z44XrpKUAAAAuE"]
[Tue Jul 21 07:23:56.775941 2026] [security2:error] [pid 229246:tid 229308] [remote 160.187.68.132:55742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9IvCBMYeh5YLVG45xu0AACej0"]
[Tue Jul 21 07:23:56.844691 2026] [security2:error] [pid 229246:tid 229402] [client 117.251.86.144:46802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IvCBMYeh5YLVG45xu0wAAAi4"]
[Tue Jul 21 07:23:56.844824 2026] [security2:error] [pid 229246:tid 229402] [client 117.251.86.144:46802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IvCBMYeh5YLVG45xu0wAAAi4"]
[Tue Jul 21 07:23:56.880100 2026] [security2:error] [pid 229246:tid 229406] [client 20.226.60.151:50804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/core.php"] [unique_id "al9IvCBMYeh5YLVG45xu2AAAAjI"]
[Tue Jul 21 07:23:56.955613 2026] [security2:error] [pid 229246:tid 229413] [client 20.151.10.161:65511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/k.php"] [unique_id "al9IvCBMYeh5YLVG45xu2QAAAjk"]
[Tue Jul 21 07:23:56.986273 2026] [security2:error] [pid 230252:tid 230341] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IvE0Dwhk5-Z44XrpKUgACxlY"]
[Tue Jul 21 07:23:56.986382 2026] [security2:error] [pid 230252:tid 230429] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IvE0Dwhk5-Z44XrpKUgACxlY"]
[Tue Jul 21 07:23:57.184110 2026] [security2:error] [pid 229246:tid 229480] [client 172.245.102.45:49109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IvCBMYeh5YLVG45xuxwAAAnw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:23:57.299845 2026] [security2:error] [pid 229246:tid 229411] [client 20.226.60.151:56941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/themes.php"] [unique_id "al9IvSBMYeh5YLVG45xu3QAAAjc"]
[Tue Jul 21 07:23:57.750470 2026] [security2:error] [pid 230252:tid 230476] [client 20.220.225.223:46085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/mimpi.php"] [unique_id "al9IvU0Dwhk5-Z44XrpKVQAAAvU"]
[Tue Jul 21 07:23:57.790411 2026] [security2:error] [pid 229246:tid 229479] [client 20.226.60.151:54557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/sid4.php"] [unique_id "al9IvSBMYeh5YLVG45xu4gAAAns"]
[Tue Jul 21 07:23:57.963293 2026] [security2:error] [pid 229246:tid 229452] [client 20.226.60.151:60208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/19.php"] [unique_id "al9IvSBMYeh5YLVG45xu7QAAAmA"]
[Tue Jul 21 07:23:58.048326 2026] [security2:error] [pid 229246:tid 229254] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IviBMYeh5YLVG45xu7gACbAc"]
[Tue Jul 21 07:23:58.048487 2026] [security2:error] [pid 229246:tid 229464] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IviBMYeh5YLVG45xu7gACbAc"]
[Tue Jul 21 07:23:58.054357 2026] [security2:error] [pid 229246:tid 229474] [client 20.151.10.161:65422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/x.php"] [unique_id "al9IviBMYeh5YLVG45xu7wAAAnY"]
[Tue Jul 21 07:23:58.066082 2026] [security2:error] [pid 229246:tid 229489] [client 20.151.10.161:26539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-temp.php"] [unique_id "al9IviBMYeh5YLVG45xu8AAAAoU"]
[Tue Jul 21 07:23:58.088153 2026] [security2:error] [pid 229246:tid 229420] [client 74.249.245.134:56475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/dropdown.php"] [unique_id "al9IviBMYeh5YLVG45xu8QAAAkA"]
[Tue Jul 21 07:23:58.100097 2026] [security2:error] [pid 230252:tid 230376] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ivk0Dwhk5-Z44XrpKWQADEHk"]
[Tue Jul 21 07:23:58.100242 2026] [security2:error] [pid 230252:tid 230503] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ivk0Dwhk5-Z44XrpKWQADEHk"]
[Tue Jul 21 07:23:58.101407 2026] [security2:error] [pid 229246:tid 229249] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IviBMYeh5YLVG45xu8gACMwI"]
[Tue Jul 21 07:23:58.101539 2026] [security2:error] [pid 229246:tid 229407] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IviBMYeh5YLVG45xu8gACMwI"]
[Tue Jul 21 07:23:58.487359 2026] [security2:error] [pid 229246:tid 229457] [client 20.197.192.193:52260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/cron.php"] [unique_id "al9IviBMYeh5YLVG45xu9wAAAmU"]
[Tue Jul 21 07:23:59.108529 2026] [security2:error] [pid 229246:tid 229423] [client 20.151.10.161:26396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9IvyBMYeh5YLVG45xvCQAAAkM"]
[Tue Jul 21 07:23:59.123345 2026] [security2:error] [pid 229246:tid 229461] [client 20.226.60.151:50778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/inc.php"] [unique_id "al9IvyBMYeh5YLVG45xvCgAAAmk"]
[Tue Jul 21 07:23:59.139303 2026] [security2:error] [pid 229246:tid 229353] [remote 142.93.10.93:49200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-login.php"] [unique_id "al9IvyBMYeh5YLVG45xvCwACbmo"]
[Tue Jul 21 07:23:59.202190 2026] [security2:error] [pid 229246:tid 229413] [client 20.151.10.161:65450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wss.php"] [unique_id "al9IvyBMYeh5YLVG45xvDAAAAjk"]
[Tue Jul 21 07:23:59.437519 2026] [security2:error] [pid 229246:tid 229408] [client 74.249.245.134:60036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-links.php"] [unique_id "al9IvyBMYeh5YLVG45xvEQAAAjQ"]
[Tue Jul 21 07:24:00.000024 2026] [security2:error] [pid 230252:tid 230400] [client 20.151.10.161:65426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/ty.php"] [unique_id "al9Iv00Dwhk5-Z44XrpKXwAAAqk"]
[Tue Jul 21 07:24:00.108051 2026] [security2:error] [pid 230252:tid 230389] [client 20.151.10.161:26533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/puc.php"] [unique_id "al9IwE0Dwhk5-Z44XrpKYwAAAp4"]
[Tue Jul 21 07:24:00.432804 2026] [security2:error] [pid 229246:tid 229398] [client 103.174.34.15:54060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IwCBMYeh5YLVG45xvJAAAAio"]
[Tue Jul 21 07:24:00.432966 2026] [security2:error] [pid 229246:tid 229398] [client 103.174.34.15:54060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IwCBMYeh5YLVG45xvJAAAAio"]
[Tue Jul 21 07:24:00.515318 2026] [security2:error] [pid 230252:tid 230451] [client 20.226.60.151:60267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9IwE0Dwhk5-Z44XrpKZwAAAtw"]
[Tue Jul 21 07:24:00.596094 2026] [security2:error] [pid 229246:tid 229262] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IwCBMYeh5YLVG45xvJgACZQ8"]
[Tue Jul 21 07:24:00.596214 2026] [security2:error] [pid 229246:tid 229457] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9IwCBMYeh5YLVG45xvJgACZQ8"]
[Tue Jul 21 07:24:00.752701 2026] [security2:error] [pid 229246:tid 229360] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IwCBMYeh5YLVG45xvKAACJnE"]
[Tue Jul 21 07:24:00.752880 2026] [security2:error] [pid 229246:tid 229394] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IwCBMYeh5YLVG45xvKAACJnE"]
[Tue Jul 21 07:24:01.363547 2026] [security2:error] [pid 230252:tid 230412] [client 20.151.10.161:26423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/themes.php"] [unique_id "al9IwU0Dwhk5-Z44XrpKawAAArU"]
[Tue Jul 21 07:24:01.623566 2026] [security2:error] [pid 229246:tid 229388] [client 20.226.60.151:50692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9IwSBMYeh5YLVG45xvOAAAAiA"]
[Tue Jul 21 07:24:01.736826 2026] [security2:error] [pid 229246:tid 229431] [client 175.45.70.82:60364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IwSBMYeh5YLVG45xvOgAAAks"]
[Tue Jul 21 07:24:01.736960 2026] [security2:error] [pid 229246:tid 229431] [client 175.45.70.82:60364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IwSBMYeh5YLVG45xvOgAAAks"]
[Tue Jul 21 07:24:01.780414 2026] [security2:error] [pid 229246:tid 229415] [client 74.249.245.134:61983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmrlpc.php"] [unique_id "al9IwSBMYeh5YLVG45xvOwAAAjs"]
[Tue Jul 21 07:24:01.870263 2026] [security2:error] [pid 230252:tid 230430] [client 20.151.10.161:65483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/155.php"] [unique_id "al9IwU0Dwhk5-Z44XrpKcAAAAsc"]
[Tue Jul 21 07:24:01.903309 2026] [security2:error] [pid 229246:tid 229408] [client 20.197.192.193:53163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/xxx.php"] [unique_id "al9IwSBMYeh5YLVG45xvPgAAAjQ"]
[Tue Jul 21 07:24:01.942449 2026] [security2:error] [pid 229246:tid 229479] [client 20.226.60.151:54499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wmore1.php"] [unique_id "al9IwSBMYeh5YLVG45xvQAAAAns"]
[Tue Jul 21 07:24:02.094373 2026] [security2:error] [pid 229246:tid 229472] [client 20.220.225.223:34283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/bscclapb.php"] [unique_id "al9IwiBMYeh5YLVG45xvRQAAAnQ"]
[Tue Jul 21 07:24:02.137084 2026] [autoindex:error] [pid 229246:tid 229412] [client 20.226.60.151:56849] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:02.351526 2026] [security2:error] [pid 229246:tid 229437] [client 193.36.225.72:24899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IwiBMYeh5YLVG45xvSgAAAlE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:02.426026 2026] [security2:error] [pid 230252:tid 230454] [client 103.106.20.201:55911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IwU0Dwhk5-Z44XrpKbQAAAt8"]
[Tue Jul 21 07:24:02.426209 2026] [security2:error] [pid 230252:tid 230454] [client 103.106.20.201:55911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IwU0Dwhk5-Z44XrpKbQAAAt8"]
[Tue Jul 21 07:24:02.476674 2026] [security2:error] [pid 230252:tid 230429] [client 20.151.10.161:26371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/dx.php"] [unique_id "al9Iwk0Dwhk5-Z44XrpKdgAAAsY"]
[Tue Jul 21 07:24:02.858446 2026] [security2:error] [pid 229246:tid 229407] [client 74.249.245.134:50592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/htaccess.php"] [unique_id "al9IwiBMYeh5YLVG45xvUAAAAjM"]
[Tue Jul 21 07:24:02.889215 2026] [security2:error] [pid 229246:tid 229384] [client 20.151.10.161:63688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/ops.php"] [unique_id "al9IwiBMYeh5YLVG45xvUQAAAhw"]
[Tue Jul 21 07:24:03.200171 2026] [security2:error] [pid 230252:tid 230508] [client 45.251.232.145:57126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKfQAAAxU"]
[Tue Jul 21 07:24:03.200277 2026] [security2:error] [pid 230252:tid 230508] [client 45.251.232.145:57126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKfQAAAxU"]
[Tue Jul 21 07:24:03.302341 2026] [security2:error] [pid 229246:tid 229494] [client 20.151.10.161:26518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/p.php"] [unique_id "al9IwyBMYeh5YLVG45xvWAAAAoo"]
[Tue Jul 21 07:24:03.401653 2026] [security2:error] [pid 230252:tid 230400] [client 20.197.192.193:53144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/hunter.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKhQAAAqk"]
[Tue Jul 21 07:24:03.449431 2026] [security2:error] [pid 230252:tid 230478] [client 20.220.225.223:34301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/else1.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKiAAAAvc"]
[Tue Jul 21 07:24:03.846598 2026] [security2:error] [pid 230252:tid 230431] [client 103.121.156.110:51808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKjQAAAsg"]
[Tue Jul 21 07:24:03.846744 2026] [security2:error] [pid 230252:tid 230431] [client 103.121.156.110:51808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKjQAAAsg"]
[Tue Jul 21 07:24:03.911181 2026] [security2:error] [pid 230252:tid 230396] [client 20.226.60.151:60255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ss.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKjgAAAqU"]
[Tue Jul 21 07:24:03.926025 2026] [security2:error] [pid 230252:tid 230377] [remote 37.156.145.146:36316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.145.156.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tryhealth.shop"] [uri "/wp-login.php"] [unique_id "al9Iw00Dwhk5-Z44XrpKjwACpno"]
[Tue Jul 21 07:24:04.027190 2026] [security2:error] [pid 230252:tid 230455] [client 20.151.10.161:49117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ccs.php"] [unique_id "al9IxE0Dwhk5-Z44XrpKkQAAAuA"]
[Tue Jul 21 07:24:04.152764 2026] [security2:error] [pid 230252:tid 230482] [client 139.135.44.145:54884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IxE0Dwhk5-Z44XrpKkwAAAvs"]
[Tue Jul 21 07:24:04.152907 2026] [security2:error] [pid 230252:tid 230482] [client 139.135.44.145:54884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IxE0Dwhk5-Z44XrpKkwAAAvs"]
[Tue Jul 21 07:24:04.525358 2026] [security2:error] [pid 229246:tid 229466] [client 20.151.10.161:26486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/bthil.php"] [unique_id "al9IxCBMYeh5YLVG45xvZwAAAm4"]
[Tue Jul 21 07:24:04.647496 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:49041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ccc.php"] [unique_id "al9IxE0Dwhk5-Z44XrpKlgAAAtE"]
[Tue Jul 21 07:24:04.815455 2026] [security2:error] [pid 230252:tid 230496] [client 20.151.10.161:65451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/ingfo.php"] [unique_id "al9IxE0Dwhk5-Z44XrpKmgAAAwk"]
[Tue Jul 21 07:24:04.925312 2026] [security2:error] [pid 230252:tid 230447] [client 172.236.52.146:55540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "shop-website.oficialwebsite.com.br"] [uri "/"] [unique_id "al9IxE0Dwhk5-Z44XrpKnQAAAtg"]
[Tue Jul 21 07:24:05.204516 2026] [security2:error] [pid 229246:tid 229484] [client 20.151.10.161:65430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/error_log.php"] [unique_id "al9IxSBMYeh5YLVG45xvbQAAAoA"]
[Tue Jul 21 07:24:05.433544 2026] [security2:error] [pid 229246:tid 229451] [client 20.226.60.151:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/min.php"] [unique_id "al9IxSBMYeh5YLVG45xvcgAAAl8"]
[Tue Jul 21 07:24:05.434073 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:34302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/tkikikoko.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKpQAAAto"]
[Tue Jul 21 07:24:05.499465 2026] [security2:error] [pid 230252:tid 230375] [remote 45.135.2.187:29733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.2.135.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "10db.com.br"] [uri "/wp-login.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKpAAC9Xg"]
[Tue Jul 21 07:24:05.604999 2026] [security2:error] [pid 230252:tid 230460] [client 20.197.192.193:52240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/we.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKqAAAAuU"]
[Tue Jul 21 07:24:05.686786 2026] [security2:error] [pid 230252:tid 230403] [client 20.151.10.161:49143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/get.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKqgAAAqw"]
[Tue Jul 21 07:24:05.697249 2026] [security2:error] [pid 230252:tid 230446] [client 74.249.245.134:43487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/readme.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKqwAAAtc"]
[Tue Jul 21 07:24:05.815582 2026] [security2:error] [pid 230252:tid 230409] [client 20.151.10.161:26387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/7.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKrAAAArI"]
[Tue Jul 21 07:24:05.832688 2026] [security2:error] [pid 230252:tid 230389] [client 20.151.10.161:65509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/ok.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKrgAAAp4"]
[Tue Jul 21 07:24:05.884598 2026] [security2:error] [pid 230252:tid 230511] [client 173.252.95.30:63116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9IxU0Dwhk5-Z44XrpKsAAAAxg"]
[Tue Jul 21 07:24:06.300546 2026] [security2:error] [pid 230252:tid 230479] [client 20.226.60.151:50716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9Ixk0Dwhk5-Z44XrpKtAAAAvg"]
[Tue Jul 21 07:24:06.395621 2026] [security2:error] [pid 230252:tid 230335] [remote 5.182.209.54:40424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9Ixk0Dwhk5-Z44XrpKtwADFVA"]
[Tue Jul 21 07:24:06.893444 2026] [security2:error] [pid 229246:tid 229426] [client 20.151.10.161:65447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/mac.php"] [unique_id "al9IxiBMYeh5YLVG45xvggAAAkY"]
[Tue Jul 21 07:24:06.980690 2026] [security2:error] [pid 229246:tid 229411] [client 103.162.129.114:53604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IxiBMYeh5YLVG45xvgwAAAjc"]
[Tue Jul 21 07:24:06.980825 2026] [security2:error] [pid 229246:tid 229411] [client 103.162.129.114:53604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9IxiBMYeh5YLVG45xvgwAAAjc"]
[Tue Jul 21 07:24:07.090516 2026] [security2:error] [pid 230252:tid 230353] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKvgACoWI"]
[Tue Jul 21 07:24:07.090688 2026] [security2:error] [pid 230252:tid 230392] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKvgACoWI"]
[Tue Jul 21 07:24:07.210542 2026] [security2:error] [pid 229246:tid 229421] [client 20.151.10.161:49037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/images.php"] [unique_id "al9IxyBMYeh5YLVG45xvhgAAAkE"]
[Tue Jul 21 07:24:07.270880 2026] [security2:error] [pid 229246:tid 229480] [client 193.36.225.57:54947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9IxyBMYeh5YLVG45xvhAAAAnw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:07.274149 2026] [security2:error] [pid 230252:tid 230498] [client 20.226.60.151:60195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKvwAAAws"]
[Tue Jul 21 07:24:07.523918 2026] [security2:error] [pid 229246:tid 229340] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IxyBMYeh5YLVG45xvigACc10"]
[Tue Jul 21 07:24:07.524090 2026] [security2:error] [pid 229246:tid 229471] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IxyBMYeh5YLVG45xvigACc10"]
[Tue Jul 21 07:24:07.536293 2026] [security2:error] [pid 230252:tid 230429] [client 20.151.10.161:2713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKxQAAAsY"]
[Tue Jul 21 07:24:07.546350 2026] [security2:error] [pid 230252:tid 230306] [remote 20.153.140.50:50220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "links.principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKxgAC8TQ"]
[Tue Jul 21 07:24:07.645709 2026] [security2:error] [pid 229246:tid 229420] [client 117.251.86.144:58078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IxyBMYeh5YLVG45xvjQAAAkA"]
[Tue Jul 21 07:24:07.645862 2026] [security2:error] [pid 229246:tid 229420] [client 117.251.86.144:58078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9IxyBMYeh5YLVG45xvjQAAAkA"]
[Tue Jul 21 07:24:07.675076 2026] [security2:error] [pid 230252:tid 230428] [client 173.252.95.25:45464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKyQAAAsU"]
[Tue Jul 21 07:24:07.812908 2026] [security2:error] [pid 230252:tid 230433] [client 20.151.10.161:2700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKywAAAso"]
[Tue Jul 21 07:24:08.015528 2026] [security2:error] [pid 229246:tid 229333] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9IxiBMYeh5YLVG45xvfwACYFY"]
[Tue Jul 21 07:24:08.015846 2026] [security2:error] [pid 229246:tid 229452] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9IxiBMYeh5YLVG45xvfwACYFY"]
[Tue Jul 21 07:24:08.070470 2026] [security2:error] [pid 229246:tid 229470] [client 20.151.10.161:65477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wefile.php"] [unique_id "al9IyCBMYeh5YLVG45xvkwAAAnI"]
[Tue Jul 21 07:24:08.103149 2026] [security2:error] [pid 229246:tid 229389] [client 20.151.10.161:2987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/images.php"] [unique_id "al9IyCBMYeh5YLVG45xvlAAAAiE"]
[Tue Jul 21 07:24:08.109894 2026] [security2:error] [pid 229246:tid 229442] [client 20.226.60.151:60231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9IyCBMYeh5YLVG45xvlQAAAlY"]
[Tue Jul 21 07:24:08.176037 2026] [security2:error] [pid 229246:tid 229423] [client 20.151.10.161:26458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/8.php"] [unique_id "al9IyCBMYeh5YLVG45xvlgAAAkM"]
[Tue Jul 21 07:24:08.231283 2026] [security2:error] [pid 229246:tid 229388] [client 74.249.245.134:60069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/403.php"] [unique_id "al9IyCBMYeh5YLVG45xvlwAAAiA"]
[Tue Jul 21 07:24:08.379690 2026] [security2:error] [pid 230252:tid 230506] [client 20.151.10.161:2707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/for.php"] [unique_id "al9IyE0Dwhk5-Z44XrpKzQAAAxM"]
[Tue Jul 21 07:24:08.430984 2026] [security2:error] [pid 230252:tid 230436] [client 213.152.162.104:45850] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKwgAAAs0"]
[Tue Jul 21 07:24:08.431078 2026] [security2:error] [pid 230252:tid 230436] [client 213.152.162.104:45850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Ix00Dwhk5-Z44XrpKwgAAAs0"]
[Tue Jul 21 07:24:08.558415 2026] [security2:error] [pid 230252:tid 230366] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IyE0Dwhk5-Z44XrpKzwAC6W8"]
[Tue Jul 21 07:24:08.558561 2026] [security2:error] [pid 230252:tid 230464] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IyE0Dwhk5-Z44XrpKzwAC6W8"]
[Tue Jul 21 07:24:08.657285 2026] [security2:error] [pid 230252:tid 230399] [client 20.151.10.161:2724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/2larp.php"] [unique_id "al9IyE0Dwhk5-Z44XrpK0QAAAqg"]
[Tue Jul 21 07:24:08.939207 2026] [security2:error] [pid 229246:tid 229431] [client 20.151.10.161:2697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/adminner.php"] [unique_id "al9IyCBMYeh5YLVG45xvpgAAAks"]
[Tue Jul 21 07:24:09.102111 2026] [security2:error] [pid 229246:tid 229359] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IySBMYeh5YLVG45xvpwACWHA"]
[Tue Jul 21 07:24:09.102243 2026] [security2:error] [pid 229246:tid 229444] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9IySBMYeh5YLVG45xvpwACWHA"]
[Tue Jul 21 07:24:09.162536 2026] [security2:error] [pid 230252:tid 230483] [client 20.151.10.161:49100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/alls.php"] [unique_id "al9IyU0Dwhk5-Z44XrpK1QAAAvw"]
[Tue Jul 21 07:24:09.174856 2026] [security2:error] [pid 229246:tid 229258] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IySBMYeh5YLVG45xvqgACdAs"]
[Tue Jul 21 07:24:09.175040 2026] [security2:error] [pid 229246:tid 229472] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9IySBMYeh5YLVG45xvqgACdAs"]
[Tue Jul 21 07:24:09.216920 2026] [security2:error] [pid 229246:tid 229474] [client 20.151.10.161:2980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/82.php"] [unique_id "al9IySBMYeh5YLVG45xvqwAAAnY"]
[Tue Jul 21 07:24:09.254646 2026] [security2:error] [pid 230252:tid 230467] [client 20.226.60.151:50797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9IyU0Dwhk5-Z44XrpK1gAAAuw"]
[Tue Jul 21 07:24:09.493390 2026] [security2:error] [pid 229246:tid 229398] [client 20.151.10.161:2714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.vitacorr.com.br"] [uri "/kir.php"] [unique_id "al9IySBMYeh5YLVG45xvtAAAAio"]
[Tue Jul 21 07:24:09.668521 2026] [security2:error] [pid 230252:tid 230397] [client 20.220.225.223:34191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9IyU0Dwhk5-Z44XrpK2QAAAqY"]
[Tue Jul 21 07:24:09.749620 2026] [security2:error] [pid 229246:tid 229400] [client 198.20.67.201:38254] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pedido-online.net"] [uri "/index.php"] [unique_id "al9IySBMYeh5YLVG45xvsgAAAiw"]
[Tue Jul 21 07:24:09.975763 2026] [security2:error] [pid 230252:tid 230415] [client 20.226.60.151:60278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/albin.php"] [unique_id "al9IyU0Dwhk5-Z44XrpK2wAAArg"]
[Tue Jul 21 07:24:10.038314 2026] [security2:error] [pid 229246:tid 229300] [remote 20.153.140.50:53118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peak-bioboost.shop-officialstore.com"] [uri "/wp-login.php"] [unique_id "al9IyiBMYeh5YLVG45xvvQACczU"]
[Tue Jul 21 07:24:10.471944 2026] [security2:error] [pid 230252:tid 230468] [client 20.151.10.161:63742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9Iyk0Dwhk5-Z44XrpK4AAAAu0"]
[Tue Jul 21 07:24:10.546203 2026] [security2:error] [pid 229246:tid 229379] [client 15.220.152.126:57960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.152.220.15.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pacodasrosas.com.br"] [uri "/adminer.php"] [unique_id "al9IySBMYeh5YLVG45xvrgAAAhc"]
[Tue Jul 21 07:24:10.744994 2026] [security2:error] [pid 230252:tid 230507] [client 74.249.245.134:53484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/max.php"] [unique_id "al9Iyk0Dwhk5-Z44XrpK5QAAAxQ"]
[Tue Jul 21 07:24:10.892705 2026] [security2:error] [pid 229246:tid 229468] [client 103.106.20.201:56442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IyiBMYeh5YLVG45xvxQAAAnA"]
[Tue Jul 21 07:24:10.892819 2026] [security2:error] [pid 229246:tid 229468] [client 103.106.20.201:56442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IyiBMYeh5YLVG45xvxQAAAnA"]
[Tue Jul 21 07:24:10.961856 2026] [security2:error] [pid 229246:tid 229423] [client 20.226.60.151:54580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/solo1.php"] [unique_id "al9IyiBMYeh5YLVG45xvxgAAAkM"]
[Tue Jul 21 07:24:10.994724 2026] [security2:error] [pid 229246:tid 229503] [client 20.151.10.161:26534] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/1.php"] [unique_id "al9IyiBMYeh5YLVG45xvyAAAApM"]
[Tue Jul 21 07:24:10.994825 2026] [security2:error] [pid 229246:tid 229503] [client 20.151.10.161:26534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/1.php"] [unique_id "al9IyiBMYeh5YLVG45xvyAAAApM"]
[Tue Jul 21 07:24:11.036705 2026] [security2:error] [pid 230252:tid 230490] [client 62.102.148.164:35016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK6AAAAwM"]
[Tue Jul 21 07:24:11.036790 2026] [security2:error] [pid 230252:tid 230490] [client 62.102.148.164:35016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK6AAAAwM"]
[Tue Jul 21 07:24:11.162833 2026] [security2:error] [pid 230252:tid 230440] [client 103.174.34.15:54534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK6QAAAtE"]
[Tue Jul 21 07:24:11.162942 2026] [security2:error] [pid 230252:tid 230440] [client 103.174.34.15:54534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK6QAAAtE"]
[Tue Jul 21 07:24:11.169094 2026] [security2:error] [pid 230252:tid 230346] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK6gAC9ls"]
[Tue Jul 21 07:24:11.169217 2026] [security2:error] [pid 230252:tid 230477] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK6gAC9ls"]
[Tue Jul 21 07:24:11.215355 2026] [security2:error] [pid 230252:tid 230486] [client 15.220.152.126:4168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.152.220.15.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pacodasrosas.com.br"] [uri "/adminer.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK6wAAAv8"]
[Tue Jul 21 07:24:11.394735 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:34244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wp-css.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK7AAAAto"]
[Tue Jul 21 07:24:11.449700 2026] [security2:error] [pid 230252:tid 230422] [client 20.226.60.151:60224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/cilus.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK7QAAAr8"]
[Tue Jul 21 07:24:11.493031 2026] [security2:error] [pid 229246:tid 229296] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IyyBMYeh5YLVG45xvzQACTDE"]
[Tue Jul 21 07:24:11.493201 2026] [security2:error] [pid 229246:tid 229432] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9IyyBMYeh5YLVG45xvzQACTDE"]
[Tue Jul 21 07:24:11.673900 2026] [security2:error] [pid 230252:tid 230463] [client 15.220.152.126:7881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.152.220.15.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pacodasrosas.com.br"] [uri "/adminer.php"] [unique_id "al9Iy00Dwhk5-Z44XrpK7gAAAug"]
[Tue Jul 21 07:24:12.113333 2026] [security2:error] [pid 229246:tid 229384] [client 15.220.152.126:10323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.152.220.15.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pacodasrosas.com.br"] [uri "/adminer.php"] [unique_id "al9IzCBMYeh5YLVG45xv2gAAAhw"]
[Tue Jul 21 07:24:12.250669 2026] [security2:error] [pid 230252:tid 230392] [client 193.36.225.61:21497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9IzE0Dwhk5-Z44XrpK7wAAAqE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:12.390808 2026] [security2:error] [pid 229246:tid 229459] [client 74.249.245.134:62114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/m.php"] [unique_id "al9IzCBMYeh5YLVG45xv3gAAAmc"]
[Tue Jul 21 07:24:12.427355 2026] [security2:error] [pid 229246:tid 229414] [client 175.45.70.82:60868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IzCBMYeh5YLVG45xv4AAAAjo"]
[Tue Jul 21 07:24:12.427459 2026] [security2:error] [pid 229246:tid 229414] [client 175.45.70.82:60868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IzCBMYeh5YLVG45xv4AAAAjo"]
[Tue Jul 21 07:24:12.519361 2026] [security2:error] [pid 230252:tid 230399] [client 20.197.192.193:52231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.69"] [uri "/phpinfo.php1"] [unique_id "al9IzE0Dwhk5-Z44XrpK9QAAAqg"]
[Tue Jul 21 07:24:12.565297 2026] [proxy:error] [pid 230252:tid 230389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:12.565385 2026] [proxy_http:error] [pid 230252:tid 230389] [client 20.151.10.161:65438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:12.566790 2026] [proxy:error] [pid 230252:tid 230389] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:12.566867 2026] [proxy_http:error] [pid 230252:tid 230389] [client 20.151.10.161:65438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:12.825167 2026] [security2:error] [pid 229246:tid 229385] [client 20.226.60.151:60165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/gptsh.php"] [unique_id "al9IzCBMYeh5YLVG45xv5gAAAh0"]
[Tue Jul 21 07:24:12.855150 2026] [security2:error] [pid 230252:tid 230462] [client 20.220.225.223:34183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/wp-explorer.php"] [unique_id "al9IzE0Dwhk5-Z44XrpK_AAAAuc"]
[Tue Jul 21 07:24:13.055619 2026] [core:alert] [pid 230252:tid 230444] [client 57.141.18.55:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:24:13.383104 2026] [security2:error] [pid 229246:tid 229421] [client 20.226.60.151:54531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/cong.php"] [unique_id "al9IzSBMYeh5YLVG45xv7wAAAkE"]
[Tue Jul 21 07:24:13.656916 2026] [security2:error] [pid 230252:tid 230469] [client 45.251.232.145:57658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IzU0Dwhk5-Z44XrpLBAAAAu4"]
[Tue Jul 21 07:24:13.657027 2026] [security2:error] [pid 230252:tid 230469] [client 45.251.232.145:57658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9IzU0Dwhk5-Z44XrpLBAAAAu4"]
[Tue Jul 21 07:24:14.001877 2026] [security2:error] [pid 230252:tid 230472] [client 62.102.148.164:35020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLCAAAAvE"]
[Tue Jul 21 07:24:14.001978 2026] [security2:error] [pid 230252:tid 230472] [client 62.102.148.164:35020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLCAAAAvE"]
[Tue Jul 21 07:24:14.068631 2026] [security2:error] [pid 230252:tid 230454] [client 74.249.245.134:61958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/click.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLCQAAAt8"]
[Tue Jul 21 07:24:14.140366 2026] [security2:error] [pid 230252:tid 230423] [client 20.151.10.161:49128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/yyu.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLCgAAAsA"]
[Tue Jul 21 07:24:14.283459 2026] [security2:error] [pid 230252:tid 230412] [client 62.102.148.164:35036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLDQAAArU"]
[Tue Jul 21 07:24:14.283565 2026] [security2:error] [pid 230252:tid 230412] [client 62.102.148.164:35036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLDQAAArU"]
[Tue Jul 21 07:24:14.300806 2026] [security2:error] [pid 229246:tid 229485] [client 20.226.60.151:60183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/rithin.php"] [unique_id "al9IziBMYeh5YLVG45xv_AAAAoE"]
[Tue Jul 21 07:24:14.619559 2026] [security2:error] [pid 230252:tid 230432] [client 103.121.156.110:52144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLEAAAAsk"]
[Tue Jul 21 07:24:14.619674 2026] [security2:error] [pid 230252:tid 230432] [client 103.121.156.110:52144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9Izk0Dwhk5-Z44XrpLEAAAAsk"]
[Tue Jul 21 07:24:15.079237 2026] [proxy:error] [pid 229246:tid 229412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:15.079321 2026] [proxy_http:error] [pid 229246:tid 229412] [client 20.151.10.161:65512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:15.080072 2026] [proxy:error] [pid 229246:tid 229412] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:15.080107 2026] [proxy_http:error] [pid 229246:tid 229412] [client 20.151.10.161:65512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:15.134562 2026] [security2:error] [pid 230252:tid 230422] [client 82.102.28.107:44688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Iz00Dwhk5-Z44XrpLEgAAAr8"]
[Tue Jul 21 07:24:15.134692 2026] [security2:error] [pid 230252:tid 230422] [client 82.102.28.107:44688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Iz00Dwhk5-Z44XrpLEgAAAr8"]
[Tue Jul 21 07:24:15.160827 2026] [security2:error] [pid 230252:tid 230327] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Iz00Dwhk5-Z44XrpLEwAC2kg"]
[Tue Jul 21 07:24:15.161005 2026] [security2:error] [pid 230252:tid 230449] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Iz00Dwhk5-Z44XrpLEwAC2kg"]
[Tue Jul 21 07:24:15.254586 2026] [security2:error] [pid 229246:tid 229492] [client 139.135.44.145:53819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IzyBMYeh5YLVG45xwBwAAAog"]
[Tue Jul 21 07:24:15.254688 2026] [security2:error] [pid 229246:tid 229492] [client 139.135.44.145:53819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9IzyBMYeh5YLVG45xwBwAAAog"]
[Tue Jul 21 07:24:15.404500 2026] [security2:error] [pid 229246:tid 229399] [client 20.220.225.223:34176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/akismet.php"] [unique_id "al9IzyBMYeh5YLVG45xwCAAAAis"]
[Tue Jul 21 07:24:15.660833 2026] [security2:error] [pid 229246:tid 229440] [client 20.226.60.151:50762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/fffm.php"] [unique_id "al9IzyBMYeh5YLVG45xwDwAAAlQ"]
[Tue Jul 21 07:24:16.665747 2026] [security2:error] [pid 229246:tid 229401] [client 74.249.245.134:21025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/lv.php"] [unique_id "al9I0CBMYeh5YLVG45xwGgAAAi0"]
[Tue Jul 21 07:24:16.850320 2026] [security2:error] [pid 230252:tid 230459] [client 20.151.10.161:49047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/by.php"] [unique_id "al9I0E0Dwhk5-Z44XrpLIAAAAuQ"]
[Tue Jul 21 07:24:16.953720 2026] [security2:error] [pid 230252:tid 230433] [client 193.36.225.72:27971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9I0E0Dwhk5-Z44XrpLIQAAAso"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:17.076414 2026] [security2:error] [pid 229246:tid 229265] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I0SBMYeh5YLVG45xwIgACJBI"]
[Tue Jul 21 07:24:17.076599 2026] [security2:error] [pid 229246:tid 229392] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I0SBMYeh5YLVG45xwIgACJBI"]
[Tue Jul 21 07:24:17.378895 2026] [security2:error] [pid 229246:tid 229394] [client 107.150.61.58:47488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.61.150.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marianapsictrab.com.br"] [uri "/wp-content/qqe70f6e/edit.php"] [unique_id "al9I0SBMYeh5YLVG45xwKAAAAiY"], referer: https://marianapsictrab.com.br/wp-content/qqe70f6e/edit.php
[Tue Jul 21 07:24:17.470865 2026] [security2:error] [pid 230252:tid 230508] [client 20.151.10.161:65463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9I0U0Dwhk5-Z44XrpLJgAAAxU"]
[Tue Jul 21 07:24:17.573482 2026] [security2:error] [pid 230252:tid 230457] [client 20.151.10.161:26512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/100.php"] [unique_id "al9I0U0Dwhk5-Z44XrpLKQAAAuI"]
[Tue Jul 21 07:24:17.726900 2026] [security2:error] [pid 229246:tid 229478] [client 103.162.129.114:54065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I0SBMYeh5YLVG45xwLgAAAno"]
[Tue Jul 21 07:24:17.727034 2026] [security2:error] [pid 229246:tid 229478] [client 103.162.129.114:54065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I0SBMYeh5YLVG45xwLgAAAno"]
[Tue Jul 21 07:24:17.762577 2026] [security2:error] [pid 229246:tid 229413] [client 74.7.241.136:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "crislainedefreitasol1782476081805.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9I0SBMYeh5YLVG45xwMAACOR0"]
[Tue Jul 21 07:24:18.044876 2026] [security2:error] [pid 230252:tid 230259] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I0k0Dwhk5-Z44XrpLMgACxgU"]
[Tue Jul 21 07:24:18.044991 2026] [security2:error] [pid 230252:tid 230429] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I0k0Dwhk5-Z44XrpLMgACxgU"]
[Tue Jul 21 07:24:18.126238 2026] [security2:error] [pid 229246:tid 229451] [client 20.151.10.161:49093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/FAQ.php"] [unique_id "al9I0iBMYeh5YLVG45xwNAAAAl8"]
[Tue Jul 21 07:24:18.317185 2026] [security2:error] [pid 229246:tid 229427] [client 20.226.60.151:54571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/public/css.php"] [unique_id "al9I0iBMYeh5YLVG45xwPAAAAkc"]
[Tue Jul 21 07:24:18.383265 2026] [security2:error] [pid 229246:tid 229391] [client 117.251.86.144:59996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I0iBMYeh5YLVG45xwPQAAAiM"]
[Tue Jul 21 07:24:18.383367 2026] [security2:error] [pid 229246:tid 229391] [client 117.251.86.144:59996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I0iBMYeh5YLVG45xwPQAAAiM"]
[Tue Jul 21 07:24:18.455845 2026] [security2:error] [pid 230252:tid 230406] [client 20.226.60.151:60179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/dfre.php"] [unique_id "al9I0k0Dwhk5-Z44XrpLPAAAAq8"]
[Tue Jul 21 07:24:18.738012 2026] [security2:error] [pid 230252:tid 230337] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I0k0Dwhk5-Z44XrpLPwACzVI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:18.744554 2026] [security2:error] [pid 229246:tid 229374] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I0iBMYeh5YLVG45xwQQACOn8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:18.770690 2026] [security2:error] [pid 230252:tid 230509] [client 20.226.60.151:50768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/wp-happy.php"] [unique_id "al9I0k0Dwhk5-Z44XrpLSwAAAxY"]
[Tue Jul 21 07:24:18.781754 2026] [security2:error] [pid 230252:tid 230317] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I0k0Dwhk5-Z44XrpLQgAC1z8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:18.892584 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:49090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/coffexium.php"] [unique_id "al9I0iBMYeh5YLVG45xwRQAAAlo"]
[Tue Jul 21 07:24:18.971306 2026] [security2:error] [pid 229246:tid 229260] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I0iBMYeh5YLVG45xwRgACjQ0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.025093 2026] [security2:error] [pid 230252:tid 230364] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpLiQACuG0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.132796 2026] [security2:error] [pid 230252:tid 230319] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I000Dwhk5-Z44XrpLtQAC9kE"]
[Tue Jul 21 07:24:19.132912 2026] [security2:error] [pid 230252:tid 230477] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I000Dwhk5-Z44XrpLtQAC9kE"]
[Tue Jul 21 07:24:19.329973 2026] [security2:error] [pid 230252:tid 230274] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpL0wAC_xQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.544158 2026] [security2:error] [pid 230252:tid 230289] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpL3wADByM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.561869 2026] [security2:error] [pid 230252:tid 230350] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpL4QADD18"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.608217 2026] [security2:error] [pid 230252:tid 230339] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I000Dwhk5-Z44XrpL4gACqVQ"]
[Tue Jul 21 07:24:19.608389 2026] [security2:error] [pid 230252:tid 230400] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I000Dwhk5-Z44XrpL4gACqVQ"]
[Tue Jul 21 07:24:19.643639 2026] [security2:error] [pid 230252:tid 230313] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpL5wAC4zs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.735988 2026] [security2:error] [pid 229246:tid 229291] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I0iBMYeh5YLVG45xwQAACUSw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.769419 2026] [security2:error] [pid 230252:tid 230262] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpL8wAC0Ag"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.784633 2026] [security2:error] [pid 229246:tid 229302] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I0yBMYeh5YLVG45xwXQACYjc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.883789 2026] [security2:error] [pid 230252:tid 230263] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpL9wACyAk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:19.904229 2026] [security2:error] [pid 230252:tid 230385] [client 20.151.10.161:26545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/about.php"] [unique_id "al9I000Dwhk5-Z44XrpL-AAAApo"]
[Tue Jul 21 07:24:19.918092 2026] [security2:error] [pid 230252:tid 230326] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I000Dwhk5-Z44XrpL-QACwkc"]
[Tue Jul 21 07:24:19.918225 2026] [security2:error] [pid 230252:tid 230425] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I000Dwhk5-Z44XrpL-QACwkc"]
[Tue Jul 21 07:24:19.941776 2026] [security2:error] [pid 229246:tid 229481] [client 20.226.60.151:56939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/.well-known/about.php"] [unique_id "al9I0yBMYeh5YLVG45xwYgAAAn0"]
[Tue Jul 21 07:24:19.990003 2026] [security2:error] [pid 230252:tid 230376] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I000Dwhk5-Z44XrpL-gAC7Xk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:20.011464 2026] [security2:error] [pid 230252:tid 230348] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I1E0Dwhk5-Z44XrpL_AAC8V0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:20.126703 2026] [security2:error] [pid 230252:tid 230287] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I1E0Dwhk5-Z44XrpL_gAC5yE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:20.148736 2026] [security2:error] [pid 230252:tid 230483] [client 20.226.60.151:60256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/fpr4.php"] [unique_id "al9I1E0Dwhk5-Z44XrpL_wAAAvw"]
[Tue Jul 21 07:24:20.238257 2026] [security2:error] [pid 229246:tid 229341] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I1CBMYeh5YLVG45xwZAACGl4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:20.282326 2026] [security2:error] [pid 230252:tid 230445] [client 74.249.245.134:50298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/cong.php"] [unique_id "al9I1E0Dwhk5-Z44XrpMAAAAAtY"]
[Tue Jul 21 07:24:20.283605 2026] [security2:error] [pid 230252:tid 230423] [client 20.151.10.161:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/red.php"] [unique_id "al9I1E0Dwhk5-Z44XrpMAQAAAsA"]
[Tue Jul 21 07:24:20.340234 2026] [security2:error] [pid 230252:tid 230359] [remote 172.187.176.79:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.176.187.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9I1E0Dwhk5-Z44XrpMAgACuGg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:24:20.645977 2026] [proxy:error] [pid 230252:tid 230486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:20.646064 2026] [proxy_http:error] [pid 230252:tid 230486] [client 20.151.10.161:65413] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:20.646757 2026] [proxy:error] [pid 230252:tid 230486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:20.646801 2026] [proxy_http:error] [pid 230252:tid 230486] [client 20.151.10.161:65413] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:21.012410 2026] [security2:error] [pid 230252:tid 230436] [client 20.226.60.151:56870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9I1U0Dwhk5-Z44XrpMPQAAAs0"]
[Tue Jul 21 07:24:21.192517 2026] [security2:error] [pid 230252:tid 230496] [client 2.57.168.28:36069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.168.57.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9I1U0Dwhk5-Z44XrpMPwAAAwk"]
[Tue Jul 21 07:24:21.214695 2026] [proxy:error] [pid 230252:tid 230459] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:21.214773 2026] [proxy_http:error] [pid 230252:tid 230459] [client 20.151.10.161:49025] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:21.215477 2026] [proxy:error] [pid 230252:tid 230459] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:21.215517 2026] [proxy_http:error] [pid 230252:tid 230459] [client 20.151.10.161:49025] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:21.257329 2026] [security2:error] [pid 230252:tid 230411] [client 20.226.60.151:50700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/file88.php"] [unique_id "al9I1U0Dwhk5-Z44XrpMRAAAArQ"]
[Tue Jul 21 07:24:21.331846 2026] [security2:error] [pid 230252:tid 230333] [remote 124.55.178.99:50984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9I1U0Dwhk5-Z44XrpMRQADFE4"]
[Tue Jul 21 07:24:21.356022 2026] [security2:error] [pid 229246:tid 229333] [remote 160.187.68.132:49580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9I1SBMYeh5YLVG45xwbgACaFY"]
[Tue Jul 21 07:24:21.356234 2026] [security2:error] [pid 229246:tid 229460] [client 160.187.68.132:49580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9I1SBMYeh5YLVG45xwbgACaFY"]
[Tue Jul 21 07:24:21.419050 2026] [security2:error] [pid 230252:tid 230451] [client 62.102.148.164:40260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9I1U0Dwhk5-Z44XrpMSgAAAtw"]
[Tue Jul 21 07:24:21.419137 2026] [security2:error] [pid 230252:tid 230451] [client 62.102.148.164:40260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9I1U0Dwhk5-Z44XrpMSgAAAtw"]
[Tue Jul 21 07:24:21.537030 2026] [security2:error] [pid 229246:tid 229287] [remote 65.111.10.106:45779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9I1SBMYeh5YLVG45xwdAACOCg"]
[Tue Jul 21 07:24:21.578274 2026] [security2:error] [pid 229246:tid 229479] [client 103.106.20.201:57168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I1SBMYeh5YLVG45xwdQAAAns"]
[Tue Jul 21 07:24:21.578404 2026] [security2:error] [pid 229246:tid 229479] [client 103.106.20.201:57168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I1SBMYeh5YLVG45xwdQAAAns"]
[Tue Jul 21 07:24:21.718450 2026] [security2:error] [pid 229246:tid 229368] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I1SBMYeh5YLVG45xwdwACO3k"]
[Tue Jul 21 07:24:21.718643 2026] [security2:error] [pid 229246:tid 229415] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I1SBMYeh5YLVG45xwdwACO3k"]
[Tue Jul 21 07:24:21.740334 2026] [security2:error] [pid 230252:tid 230453] [client 193.36.225.63:28417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9I1U0Dwhk5-Z44XrpMVAAAAt4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:21.833176 2026] [security2:error] [pid 229246:tid 229469] [client 20.151.10.161:49150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9I1SBMYeh5YLVG45xwegAAAnE"]
[Tue Jul 21 07:24:21.865515 2026] [security2:error] [pid 230252:tid 230264] [remote 142.44.225.172:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "garagemdoluidi.com.br"] [uri "/my-account/lost-password/"] [unique_id "al9I1U0Dwhk5-Z44XrpMVQAC8Qo"]
[Tue Jul 21 07:24:21.865708 2026] [security2:error] [pid 230252:tid 230472] [client 142.44.225.172:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "garagemdoluidi.com.br"] [uri "/my-account/lost-password/"] [unique_id "al9I1U0Dwhk5-Z44XrpMVQAC8Qo"]
[Tue Jul 21 07:24:22.082221 2026] [security2:error] [pid 230252:tid 230403] [client 103.174.34.15:55008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I1k0Dwhk5-Z44XrpMWAAAAqw"]
[Tue Jul 21 07:24:22.082699 2026] [security2:error] [pid 230252:tid 230403] [client 103.174.34.15:55008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I1k0Dwhk5-Z44XrpMWAAAAqw"]
[Tue Jul 21 07:24:22.139838 2026] [security2:error] [pid 230252:tid 230398] [client 20.151.10.161:65501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/like.php"] [unique_id "al9I1k0Dwhk5-Z44XrpMWwAAAqc"]
[Tue Jul 21 07:24:22.267586 2026] [security2:error] [pid 230252:tid 230312] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I1k0Dwhk5-Z44XrpMXAAC2Do"]
[Tue Jul 21 07:24:22.267759 2026] [security2:error] [pid 230252:tid 230447] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I1k0Dwhk5-Z44XrpMXAAC2Do"]
[Tue Jul 21 07:24:22.273014 2026] [security2:error] [pid 230252:tid 230500] [client 20.226.60.151:56857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wefile.php"] [unique_id "al9I1k0Dwhk5-Z44XrpMXQAAAw0"]
[Tue Jul 21 07:24:22.331339 2026] [security2:error] [pid 230252:tid 230449] [client 20.151.10.161:26460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/admin.php"] [unique_id "al9I1k0Dwhk5-Z44XrpMXgAAAto"]
[Tue Jul 21 07:24:22.942369 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:22.942447 2026] [proxy_http:error] [pid 230252:tid 230484] [client 20.151.10.161:49112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:22.943226 2026] [proxy:error] [pid 230252:tid 230484] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:22.943272 2026] [proxy_http:error] [pid 230252:tid 230484] [client 20.151.10.161:49112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:23.132195 2026] [security2:error] [pid 230252:tid 230486] [client 175.45.70.82:61377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I100Dwhk5-Z44XrpMaAAAAv8"]
[Tue Jul 21 07:24:23.132326 2026] [security2:error] [pid 230252:tid 230486] [client 175.45.70.82:61377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I100Dwhk5-Z44XrpMaAAAAv8"]
[Tue Jul 21 07:24:23.141639 2026] [security2:error] [pid 230252:tid 230461] [client 20.226.60.151:50735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ccc.php"] [unique_id "al9I100Dwhk5-Z44XrpMaQAAAuY"]
[Tue Jul 21 07:24:23.456732 2026] [security2:error] [pid 229246:tid 229364] [remote 116.179.37.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9I1yBMYeh5YLVG45xwiQACHnU"], referer: https://androapkmod.com/tag/block-craft-3d-hack-mod-apk-unlimited-gems/
[Tue Jul 21 07:24:23.547343 2026] [security2:error] [pid 230252:tid 230386] [client 20.220.225.223:34261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/ace2.php"] [unique_id "al9I100Dwhk5-Z44XrpMbgAAAps"]
[Tue Jul 21 07:24:23.691154 2026] [security2:error] [pid 230252:tid 230469] [client 20.151.10.161:49105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/footer.php"] [unique_id "al9I100Dwhk5-Z44XrpMcAAAAu4"]
[Tue Jul 21 07:24:23.697605 2026] [security2:error] [pid 230252:tid 230511] [client 20.226.60.151:56883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9I100Dwhk5-Z44XrpMcQAAAxg"]
[Tue Jul 21 07:24:23.818332 2026] [security2:error] [pid 230252:tid 230472] [client 62.102.148.164:40272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9I100Dwhk5-Z44XrpMcwAAAvE"]
[Tue Jul 21 07:24:23.818436 2026] [security2:error] [pid 230252:tid 230472] [client 62.102.148.164:40272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9I100Dwhk5-Z44XrpMcwAAAvE"]
[Tue Jul 21 07:24:23.914853 2026] [security2:error] [pid 230252:tid 230485] [client 20.220.225.223:48539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-editor.php"] [unique_id "al9I100Dwhk5-Z44XrpMdwAAAv4"]
[Tue Jul 21 07:24:23.934781 2026] [security2:error] [pid 230252:tid 230417] [client 20.151.10.161:26315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/edit.php"] [unique_id "al9I100Dwhk5-Z44XrpMeAAAAro"]
[Tue Jul 21 07:24:23.937805 2026] [security2:error] [pid 229246:tid 229437] [client 74.249.245.134:54466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/brand.php"] [unique_id "al9I1yBMYeh5YLVG45xwkAAAAlE"]
[Tue Jul 21 07:24:23.952237 2026] [security2:error] [pid 230252:tid 230423] [client 20.151.10.161:63683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/.well-known/about.php"] [unique_id "al9I100Dwhk5-Z44XrpMeQAAAsA"]
[Tue Jul 21 07:24:24.030846 2026] [security2:error] [pid 230252:tid 230398] [client 20.52.136.55:1567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9I2E0Dwhk5-Z44XrpMegAAAqc"]
[Tue Jul 21 07:24:24.186940 2026] [security2:error] [pid 230252:tid 230451] [client 45.251.232.145:58181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I2E0Dwhk5-Z44XrpMewAAAtw"]
[Tue Jul 21 07:24:24.187070 2026] [security2:error] [pid 230252:tid 230451] [client 45.251.232.145:58181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I2E0Dwhk5-Z44XrpMewAAAtw"]
[Tue Jul 21 07:24:24.227097 2026] [security2:error] [pid 230252:tid 230409] [client 198.20.67.201:52022] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "pedido-online.net"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al9I2E0Dwhk5-Z44XrpMfAAAArI"]
[Tue Jul 21 07:24:24.227218 2026] [security2:error] [pid 230252:tid 230409] [client 198.20.67.201:52022] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pedido-online.net"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al9I2E0Dwhk5-Z44XrpMfAAAArI"]
[Tue Jul 21 07:24:24.973211 2026] [security2:error] [pid 230252:tid 230396] [client 20.220.225.223:34195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "quattrotech.com.br"] [uri "/ms.php"] [unique_id "al9I2E0Dwhk5-Z44XrpMhQAAAqU"]
[Tue Jul 21 07:24:25.078559 2026] [proxy:error] [pid 230252:tid 230494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:25.078639 2026] [proxy_http:error] [pid 230252:tid 230494] [client 20.151.10.161:49096] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:25.079342 2026] [proxy:error] [pid 230252:tid 230494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:25.079381 2026] [proxy_http:error] [pid 230252:tid 230494] [client 20.151.10.161:49096] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:25.101711 2026] [autoindex:error] [pid 230252:tid 230441] [client 20.226.60.151:56858] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:25.274460 2026] [autoindex:error] [pid 230252:tid 230507] [client 20.226.60.151:56858] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:25.288313 2026] [security2:error] [pid 230252:tid 230471] [client 103.121.156.110:52477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I2U0Dwhk5-Z44XrpMkAAAAvA"]
[Tue Jul 21 07:24:25.288454 2026] [security2:error] [pid 230252:tid 230471] [client 103.121.156.110:52477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I2U0Dwhk5-Z44XrpMkAAAAvA"]
[Tue Jul 21 07:24:26.114637 2026] [security2:error] [pid 230252:tid 230439] [client 139.135.44.145:54706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I2k0Dwhk5-Z44XrpMmgAAAtA"]
[Tue Jul 21 07:24:26.114751 2026] [security2:error] [pid 230252:tid 230439] [client 139.135.44.145:54706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I2k0Dwhk5-Z44XrpMmgAAAtA"]
[Tue Jul 21 07:24:26.245896 2026] [security2:error] [pid 229246:tid 229472] [client 20.151.10.161:65502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9I2iBMYeh5YLVG45xwrQAAAnQ"]
[Tue Jul 21 07:24:26.685294 2026] [security2:error] [pid 230252:tid 230419] [client 20.151.10.161:26450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9I2k0Dwhk5-Z44XrpMnwAAArw"]
[Tue Jul 21 07:24:26.764537 2026] [security2:error] [pid 230252:tid 230328] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I2k0Dwhk5-Z44XrpMoAACr0k"]
[Tue Jul 21 07:24:26.764730 2026] [security2:error] [pid 230252:tid 230406] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I2k0Dwhk5-Z44XrpMoAACr0k"]
[Tue Jul 21 07:24:26.794295 2026] [security2:error] [pid 230252:tid 230484] [client 193.36.225.67:43129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9I2k0Dwhk5-Z44XrpMoQAAAv0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:26.970208 2026] [security2:error] [pid 229246:tid 229493] [client 20.226.60.151:54505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/output.php"] [unique_id "al9I2iBMYeh5YLVG45xwuwAAAok"]
[Tue Jul 21 07:24:27.367760 2026] [security2:error] [pid 229246:tid 229498] [client 20.226.60.151:54540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-file-120.php"] [unique_id "al9I2yBMYeh5YLVG45xwvgAAAo4"]
[Tue Jul 21 07:24:27.389154 2026] [security2:error] [pid 229246:tid 229392] [client 74.249.245.134:43014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/atomlib.php"] [unique_id "al9I2yBMYeh5YLVG45xwwgAAAiQ"]
[Tue Jul 21 07:24:27.492359 2026] [security2:error] [pid 229246:tid 229398] [client 20.226.60.151:54549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/special.php"] [unique_id "al9I2yBMYeh5YLVG45xwxQAAAio"]
[Tue Jul 21 07:24:27.612423 2026] [security2:error] [pid 229246:tid 229437] [client 20.226.60.151:54539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/as.php"] [unique_id "al9I2yBMYeh5YLVG45xwxwAAAlE"]
[Tue Jul 21 07:24:27.618091 2026] [security2:error] [pid 230252:tid 230308] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I200Dwhk5-Z44XrpMqQADBzY"]
[Tue Jul 21 07:24:27.618297 2026] [security2:error] [pid 230252:tid 230494] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I200Dwhk5-Z44XrpMqQADBzY"]
[Tue Jul 21 07:24:27.792597 2026] [security2:error] [pid 229246:tid 229448] [client 20.226.60.151:61074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9I2yBMYeh5YLVG45xwygAAAlw"]
[Tue Jul 21 07:24:27.837687 2026] [security2:error] [pid 229246:tid 229309] [remote 5.252.52.249:55490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nocaminhodafe.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I2yBMYeh5YLVG45xwywACfD4"]
[Tue Jul 21 07:24:27.837863 2026] [security2:error] [pid 229246:tid 229480] [client 5.252.52.249:55490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nocaminhodafe.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I2yBMYeh5YLVG45xwywACfD4"]
[Tue Jul 21 07:24:27.919721 2026] [security2:error] [pid 230252:tid 230458] [client 82.102.28.107:35594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9I200Dwhk5-Z44XrpMqgAAAuM"]
[Tue Jul 21 07:24:27.919833 2026] [security2:error] [pid 230252:tid 230458] [client 82.102.28.107:35594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9I200Dwhk5-Z44XrpMqgAAAuM"]
[Tue Jul 21 07:24:27.936766 2026] [security2:error] [pid 229246:tid 229390] [client 20.151.10.161:49129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-content/index.php"] [unique_id "al9I2yBMYeh5YLVG45xwzwAAAiI"]
[Tue Jul 21 07:24:28.198473 2026] [security2:error] [pid 230252:tid 230400] [client 20.226.60.151:61100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/w1px.php"] [unique_id "al9I3E0Dwhk5-Z44XrpMqwAAAqk"]
[Tue Jul 21 07:24:28.526376 2026] [security2:error] [pid 229246:tid 229389] [client 103.162.129.114:54526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I3CBMYeh5YLVG45xw0wAAAiE"]
[Tue Jul 21 07:24:28.526486 2026] [security2:error] [pid 229246:tid 229389] [client 103.162.129.114:54526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I3CBMYeh5YLVG45xw0wAAAiE"]
[Tue Jul 21 07:24:28.536647 2026] [security2:error] [pid 230252:tid 230386] [client 20.226.60.151:60197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/777.php"] [unique_id "al9I3E0Dwhk5-Z44XrpMrgAAAps"]
[Tue Jul 21 07:24:28.557890 2026] [security2:error] [pid 230252:tid 230334] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I3E0Dwhk5-Z44XrpMrwAC-E8"]
[Tue Jul 21 07:24:28.558034 2026] [security2:error] [pid 230252:tid 230479] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I3E0Dwhk5-Z44XrpMrwAC-E8"]
[Tue Jul 21 07:24:29.035761 2026] [security2:error] [pid 230252:tid 230397] [client 117.251.86.144:60530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I3U0Dwhk5-Z44XrpMsAAAAqY"]
[Tue Jul 21 07:24:29.035888 2026] [security2:error] [pid 230252:tid 230397] [client 117.251.86.144:60530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I3U0Dwhk5-Z44XrpMsAAAAqY"]
[Tue Jul 21 07:24:29.175355 2026] [security2:error] [pid 230252:tid 230476] [client 20.226.60.151:56885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9I3U0Dwhk5-Z44XrpMsQAAAvU"]
[Tue Jul 21 07:24:29.191556 2026] [proxy:error] [pid 229246:tid 229467] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:29.191646 2026] [proxy_http:error] [pid 229246:tid 229467] [client 20.151.10.161:65508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:29.192263 2026] [proxy:error] [pid 229246:tid 229467] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:29.192293 2026] [proxy_http:error] [pid 229246:tid 229467] [client 20.151.10.161:65508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:29.285380 2026] [security2:error] [pid 229246:tid 229473] [client 109.248.148.246:59492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9I3SBMYeh5YLVG45xw3wAAAnU"]
[Tue Jul 21 07:24:29.285502 2026] [security2:error] [pid 229246:tid 229473] [client 109.248.148.246:59492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9I3SBMYeh5YLVG45xw3wAAAnU"]
[Tue Jul 21 07:24:29.390717 2026] [security2:error] [pid 230252:tid 230445] [client 20.220.225.223:46115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/cro.php"] [unique_id "al9I3U0Dwhk5-Z44XrpMswAAAtY"]
[Tue Jul 21 07:24:29.446647 2026] [security2:error] [pid 230252:tid 230415] [client 20.151.10.161:49029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/zoro.php"] [unique_id "al9I3U0Dwhk5-Z44XrpMtgAAArg"]
[Tue Jul 21 07:24:29.690837 2026] [security2:error] [pid 229246:tid 229344] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I3SBMYeh5YLVG45xw5wACZmE"]
[Tue Jul 21 07:24:29.691017 2026] [security2:error] [pid 229246:tid 229458] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I3SBMYeh5YLVG45xw5wACZmE"]
[Tue Jul 21 07:24:30.053921 2026] [security2:error] [pid 229246:tid 229328] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I3iBMYeh5YLVG45xw7gACQVE"]
[Tue Jul 21 07:24:30.054068 2026] [security2:error] [pid 229246:tid 229421] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I3iBMYeh5YLVG45xw7gACQVE"]
[Tue Jul 21 07:24:30.105200 2026] [security2:error] [pid 229246:tid 229447] [client 20.226.60.151:50791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/for.php"] [unique_id "al9I3iBMYeh5YLVG45xw7wAAAls"]
[Tue Jul 21 07:24:30.324129 2026] [security2:error] [pid 230252:tid 230410] [client 20.220.225.223:46134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/cron-tab.php"] [unique_id "al9I3k0Dwhk5-Z44XrpMuQAAArM"]
[Tue Jul 21 07:24:30.363443 2026] [security2:error] [pid 230252:tid 230403] [client 20.226.60.151:56959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/8.php"] [unique_id "al9I3k0Dwhk5-Z44XrpMugAAAqw"]
[Tue Jul 21 07:24:30.531000 2026] [security2:error] [pid 229246:tid 229380] [client 20.151.10.161:26520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/f6.php"] [unique_id "al9I3iBMYeh5YLVG45xw8wAAAhg"]
[Tue Jul 21 07:24:30.561258 2026] [security2:error] [pid 229246:tid 229398] [client 20.226.60.151:61063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/yawa.php"] [unique_id "al9I3iBMYeh5YLVG45xw9gAAAio"]
[Tue Jul 21 07:24:30.693683 2026] [security2:error] [pid 229246:tid 229253] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I3iBMYeh5YLVG45xw9wACMQY"]
[Tue Jul 21 07:24:30.693885 2026] [security2:error] [pid 229246:tid 229405] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I3iBMYeh5YLVG45xw9wACMQY"]
[Tue Jul 21 07:24:30.817967 2026] [security2:error] [pid 229246:tid 229423] [client 213.152.162.104:49786] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9I3iBMYeh5YLVG45xw-gAAAkM"]
[Tue Jul 21 07:24:30.818075 2026] [security2:error] [pid 229246:tid 229423] [client 213.152.162.104:49786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9I3iBMYeh5YLVG45xw-gAAAkM"]
[Tue Jul 21 07:24:31.543356 2026] [proxy:error] [pid 230252:tid 230432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:31.543439 2026] [proxy_http:error] [pid 230252:tid 230432] [client 20.151.10.161:65507] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:31.544199 2026] [proxy:error] [pid 230252:tid 230432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:31.544229 2026] [proxy_http:error] [pid 230252:tid 230432] [client 20.151.10.161:65507] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:31.719775 2026] [security2:error] [pid 230252:tid 230487] [client 74.249.245.134:21429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/0x.php"] [unique_id "al9I300Dwhk5-Z44XrpMwQAAAwA"]
[Tue Jul 21 07:24:32.029661 2026] [security2:error] [pid 229246:tid 229486] [client 20.226.60.151:56868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9I4CBMYeh5YLVG45xxBQAAAoI"]
[Tue Jul 21 07:24:32.079328 2026] [security2:error] [pid 229246:tid 229492] [client 20.151.10.161:48609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/admin.php"] [unique_id "al9I4CBMYeh5YLVG45xxBwAAAog"]
[Tue Jul 21 07:24:32.327057 2026] [security2:error] [pid 229246:tid 229426] [client 103.106.20.201:57756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4CBMYeh5YLVG45xxCgAAAkY"]
[Tue Jul 21 07:24:32.327189 2026] [security2:error] [pid 229246:tid 229426] [client 103.106.20.201:57756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4CBMYeh5YLVG45xxCgAAAkY"]
[Tue Jul 21 07:24:32.365484 2026] [security2:error] [pid 229246:tid 229259] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I4CBMYeh5YLVG45xxCwACOAw"]
[Tue Jul 21 07:24:32.365619 2026] [security2:error] [pid 229246:tid 229412] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I4CBMYeh5YLVG45xxCwACOAw"]
[Tue Jul 21 07:24:32.416766 2026] [security2:error] [pid 229246:tid 229500] [client 20.151.10.161:65468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/pucci.php"] [unique_id "al9I4CBMYeh5YLVG45xxDgAAApA"]
[Tue Jul 21 07:24:32.663631 2026] [security2:error] [pid 230252:tid 230489] [client 103.174.34.15:55480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4E0Dwhk5-Z44XrpMxgAAAwI"]
[Tue Jul 21 07:24:32.663762 2026] [security2:error] [pid 230252:tid 230489] [client 103.174.34.15:55480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4E0Dwhk5-Z44XrpMxgAAAwI"]
[Tue Jul 21 07:24:32.736929 2026] [security2:error] [pid 229246:tid 229417] [client 20.226.60.151:50790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/ssla.php"] [unique_id "al9I4CBMYeh5YLVG45xxFwAAAj0"]
[Tue Jul 21 07:24:32.985341 2026] [security2:error] [pid 230252:tid 230452] [client 62.102.148.164:39406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9I4E0Dwhk5-Z44XrpMygAAAt0"]
[Tue Jul 21 07:24:32.985455 2026] [security2:error] [pid 230252:tid 230452] [client 62.102.148.164:39406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9I4E0Dwhk5-Z44XrpMygAAAt0"]
[Tue Jul 21 07:24:33.001350 2026] [security2:error] [pid 229246:tid 229351] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I4CBMYeh5YLVG45xxHgACHGg"]
[Tue Jul 21 07:24:33.001479 2026] [security2:error] [pid 229246:tid 229384] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I4CBMYeh5YLVG45xxHgACHGg"]
[Tue Jul 21 07:24:33.109496 2026] [security2:error] [pid 229246:tid 229475] [client 20.220.225.223:46012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/koiy.php"] [unique_id "al9I4SBMYeh5YLVG45xxIAAAAnc"]
[Tue Jul 21 07:24:33.366205 2026] [security2:error] [pid 229246:tid 229377] [client 20.151.10.161:26551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/inputs.php"] [unique_id "al9I4SBMYeh5YLVG45xxJgAAAhU"]
[Tue Jul 21 07:24:33.371860 2026] [security2:error] [pid 229246:tid 229385] [client 193.36.225.60:65035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9I4SBMYeh5YLVG45xxJwAAAh0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:33.416497 2026] [security2:error] [pid 229246:tid 229450] [client 20.226.60.151:56935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/f6.php"] [unique_id "al9I4SBMYeh5YLVG45xxKAAAAl4"]
[Tue Jul 21 07:24:33.853163 2026] [security2:error] [pid 230252:tid 230404] [client 82.102.28.107:42626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9I4U0Dwhk5-Z44XrpMzgAAAq0"]
[Tue Jul 21 07:24:33.853327 2026] [security2:error] [pid 230252:tid 230404] [client 82.102.28.107:42626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9I4U0Dwhk5-Z44XrpMzgAAAq0"]
[Tue Jul 21 07:24:33.971944 2026] [proxy:error] [pid 230252:tid 230444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:33.972025 2026] [proxy_http:error] [pid 230252:tid 230444] [client 20.151.10.161:65491] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:33.972628 2026] [proxy:error] [pid 230252:tid 230444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:33.972662 2026] [proxy_http:error] [pid 230252:tid 230444] [client 20.151.10.161:65491] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:34.008978 2026] [security2:error] [pid 229246:tid 229465] [client 175.45.70.82:61886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4iBMYeh5YLVG45xxNQAAAm0"]
[Tue Jul 21 07:24:34.009126 2026] [security2:error] [pid 229246:tid 229465] [client 175.45.70.82:61886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4iBMYeh5YLVG45xxNQAAAm0"]
[Tue Jul 21 07:24:34.064106 2026] [security2:error] [pid 230252:tid 230495] [client 47.128.63.113:60158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dralulmabhering.com"] [uri "/robots.txt"] [unique_id "al9I4k0Dwhk5-Z44XrpM0AAAAwg"]
[Tue Jul 21 07:24:34.109617 2026] [security2:error] [pid 230252:tid 230431] [client 20.226.60.151:56851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/inputs.php"] [unique_id "al9I4k0Dwhk5-Z44XrpM0QAAAsg"]
[Tue Jul 21 07:24:34.377798 2026] [security2:error] [pid 230252:tid 230498] [client 20.220.225.223:48535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/hp2.php"] [unique_id "al9I4k0Dwhk5-Z44XrpM1QAAAws"]
[Tue Jul 21 07:24:34.495418 2026] [security2:error] [pid 229246:tid 229492] [client 74.249.245.134:44122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/buy.php"] [unique_id "al9I4iBMYeh5YLVG45xxPwAAAog"]
[Tue Jul 21 07:24:34.683492 2026] [security2:error] [pid 229246:tid 229388] [client 45.251.232.145:58704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4iBMYeh5YLVG45xxRQAAAiA"]
[Tue Jul 21 07:24:34.683587 2026] [security2:error] [pid 229246:tid 229388] [client 45.251.232.145:58704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I4iBMYeh5YLVG45xxRQAAAiA"]
[Tue Jul 21 07:24:35.007451 2026] [proxy:error] [pid 230252:tid 230392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:35.007531 2026] [proxy_http:error] [pid 230252:tid 230392] [client 20.151.10.161:65520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:35.008130 2026] [proxy:error] [pid 230252:tid 230392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:35.008156 2026] [proxy_http:error] [pid 230252:tid 230392] [client 20.151.10.161:65520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:35.134195 2026] [security2:error] [pid 229246:tid 229445] [client 20.151.10.161:26443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/av.php"] [unique_id "al9I4yBMYeh5YLVG45xxTQAAAlk"]
[Tue Jul 21 07:24:35.269295 2026] [security2:error] [pid 229246:tid 229472] [client 20.226.60.151:63320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/inputs.php"] [unique_id "al9I4yBMYeh5YLVG45xxUAAAAnQ"]
[Tue Jul 21 07:24:35.568143 2026] [security2:error] [pid 229246:tid 229479] [client 20.220.225.223:46086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/hp3.php"] [unique_id "al9I4yBMYeh5YLVG45xxVAAAAns"]
[Tue Jul 21 07:24:35.721961 2026] [security2:error] [pid 230252:tid 230403] [client 154.192.233.199:59372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I400Dwhk5-Z44XrpM4QAAAqw"]
[Tue Jul 21 07:24:35.722066 2026] [security2:error] [pid 230252:tid 230403] [client 154.192.233.199:59372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I400Dwhk5-Z44XrpM4QAAAqw"]
[Tue Jul 21 07:24:35.843724 2026] [security2:error] [pid 230252:tid 230447] [client 103.121.156.110:52795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I400Dwhk5-Z44XrpM5gAAAtg"]
[Tue Jul 21 07:24:35.843846 2026] [security2:error] [pid 230252:tid 230447] [client 103.121.156.110:52795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I400Dwhk5-Z44XrpM5gAAAtg"]
[Tue Jul 21 07:24:36.140298 2026] [security2:error] [pid 230252:tid 230426] [client 20.151.10.161:65460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-temp.php"] [unique_id "al9I5E0Dwhk5-Z44XrpM6gAAAsM"]
[Tue Jul 21 07:24:36.386854 2026] [security2:error] [pid 230252:tid 230506] [client 74.7.244.32:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agmiz.com.br"] [uri "/index.php"] [unique_id "al9I400Dwhk5-Z44XrpM5QAAAxM"]
[Tue Jul 21 07:24:36.387582 2026] [security2:error] [pid 230252:tid 230499] [client 74.7.244.32:49194] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agmiz.com.br"] [uri "/robots.txt"] [unique_id "al9I400Dwhk5-Z44XrpM4wADDBw"]
[Tue Jul 21 07:24:36.476763 2026] [security2:error] [pid 230252:tid 230411] [client 20.151.10.161:49069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/greap.php"] [unique_id "al9I5E0Dwhk5-Z44XrpM7wAAArQ"]
[Tue Jul 21 07:24:37.059248 2026] [security2:error] [pid 230252:tid 230458] [client 139.135.44.145:53578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I5U0Dwhk5-Z44XrpM9AAAAuM"]
[Tue Jul 21 07:24:37.059455 2026] [security2:error] [pid 230252:tid 230458] [client 139.135.44.145:53578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I5U0Dwhk5-Z44XrpM9AAAAuM"]
[Tue Jul 21 07:24:37.110743 2026] [proxy:error] [pid 230252:tid 230490] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:37.110844 2026] [proxy_http:error] [pid 230252:tid 230490] [client 20.151.10.161:65482] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:37.111621 2026] [proxy:error] [pid 230252:tid 230490] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:37.111677 2026] [proxy_http:error] [pid 230252:tid 230490] [client 20.151.10.161:65482] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:37.305312 2026] [security2:error] [pid 229246:tid 229382] [client 20.151.10.161:26537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/classwithtostring.php"] [unique_id "al9I5SBMYeh5YLVG45xxdgAAAho"]
[Tue Jul 21 07:24:37.336092 2026] [security2:error] [pid 229246:tid 229396] [client 20.226.60.151:63358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/classwithtostring.php"] [unique_id "al9I5SBMYeh5YLVG45xxdwAAAig"]
[Tue Jul 21 07:24:37.701305 2026] [security2:error] [pid 230252:tid 230397] [client 20.151.10.161:49095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/177.php"] [unique_id "al9I5U0Dwhk5-Z44XrpM-AAAAqY"]
[Tue Jul 21 07:24:37.794202 2026] [security2:error] [pid 230252:tid 230498] [client 74.249.245.134:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/sx.php"] [unique_id "al9I5U0Dwhk5-Z44XrpM-gAAAws"]
[Tue Jul 21 07:24:37.800838 2026] [security2:error] [pid 230252:tid 230445] [client 20.226.60.151:50726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fernandohipolito.com.br"] [uri "/zc-131.php"] [unique_id "al9I5U0Dwhk5-Z44XrpM-wAAAtY"]
[Tue Jul 21 07:24:37.850795 2026] [security2:error] [pid 229246:tid 229419] [client 20.220.225.223:48564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9I5SBMYeh5YLVG45xxfgAAAj8"]
[Tue Jul 21 07:24:37.884948 2026] [security2:error] [pid 230252:tid 230425] [client 20.226.60.151:54492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/js.php"] [unique_id "al9I5U0Dwhk5-Z44XrpM_AAAAsI"]
[Tue Jul 21 07:24:37.956903 2026] [security2:error] [pid 230252:tid 230461] [client 20.220.225.223:45397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/aa1.php"] [unique_id "al9I5U0Dwhk5-Z44XrpM_gAAAuY"]
[Tue Jul 21 07:24:38.153339 2026] [security2:error] [pid 229246:tid 229347] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I5iBMYeh5YLVG45xxgQACkGQ"]
[Tue Jul 21 07:24:38.153517 2026] [security2:error] [pid 229246:tid 229500] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I5iBMYeh5YLVG45xxgQACkGQ"]
[Tue Jul 21 07:24:38.368366 2026] [security2:error] [pid 229246:tid 229487] [client 62.102.148.164:44712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9I5iBMYeh5YLVG45xxhgAAAoM"]
[Tue Jul 21 07:24:38.368501 2026] [security2:error] [pid 229246:tid 229487] [client 62.102.148.164:44712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9I5iBMYeh5YLVG45xxhgAAAoM"]
[Tue Jul 21 07:24:38.391541 2026] [security2:error] [pid 229246:tid 229440] [client 20.151.10.161:63658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/xmu.php"] [unique_id "al9I5iBMYeh5YLVG45xxhwAAAlQ"]
[Tue Jul 21 07:24:38.843036 2026] [security2:error] [pid 230252:tid 230483] [client 74.249.245.134:54364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9I5k0Dwhk5-Z44XrpNBAAAAvw"]
[Tue Jul 21 07:24:39.093034 2026] [security2:error] [pid 230252:tid 230341] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I500Dwhk5-Z44XrpNBwACvFY"]
[Tue Jul 21 07:24:39.093200 2026] [security2:error] [pid 230252:tid 230419] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I500Dwhk5-Z44XrpNBwACvFY"]
[Tue Jul 21 07:24:39.212196 2026] [security2:error] [pid 230252:tid 230471] [client 172.245.102.41:52151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9I500Dwhk5-Z44XrpNBgAAAvA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:39.233946 2026] [security2:error] [pid 230252:tid 230440] [client 20.151.10.161:49087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/199.php"] [unique_id "al9I500Dwhk5-Z44XrpNCAAAAtE"]
[Tue Jul 21 07:24:39.295087 2026] [security2:error] [pid 230252:tid 230432] [client 173.252.95.62:56136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9I500Dwhk5-Z44XrpNCQAAAsk"]
[Tue Jul 21 07:24:39.492696 2026] [security2:error] [pid 229246:tid 229377] [client 20.220.225.223:48523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/acew67.php"] [unique_id "al9I5yBMYeh5YLVG45xxkgAAAhU"]
[Tue Jul 21 07:24:39.509743 2026] [security2:error] [pid 230252:tid 230429] [client 103.162.129.114:54981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I500Dwhk5-Z44XrpNCwAAAsY"]
[Tue Jul 21 07:24:39.509874 2026] [security2:error] [pid 230252:tid 230429] [client 103.162.129.114:54981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I500Dwhk5-Z44XrpNCwAAAsY"]
[Tue Jul 21 07:24:39.558749 2026] [security2:error] [pid 230252:tid 230494] [client 20.220.225.223:45999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9I500Dwhk5-Z44XrpNDQAAAwc"]
[Tue Jul 21 07:24:39.794264 2026] [security2:error] [pid 230252:tid 230449] [client 117.251.86.144:49222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I500Dwhk5-Z44XrpNDwAAAto"]
[Tue Jul 21 07:24:39.794373 2026] [security2:error] [pid 230252:tid 230449] [client 117.251.86.144:49222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I500Dwhk5-Z44XrpNDwAAAto"]
[Tue Jul 21 07:24:39.857406 2026] [security2:error] [pid 230252:tid 230422] [client 173.252.95.41:43192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9I500Dwhk5-Z44XrpNEAAAAr8"]
[Tue Jul 21 07:24:39.976752 2026] [security2:error] [pid 229246:tid 229470] [client 20.220.225.223:46116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/dp.php"] [unique_id "al9I5yBMYeh5YLVG45xxmQAAAnI"]
[Tue Jul 21 07:24:39.998521 2026] [security2:error] [pid 229246:tid 229380] [client 20.220.225.223:45993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/bscclapb.php"] [unique_id "al9I5yBMYeh5YLVG45xxmgAAAhg"]
[Tue Jul 21 07:24:40.066305 2026] [security2:error] [pid 230252:tid 230509] [client 20.52.136.55:1757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9I6E0Dwhk5-Z44XrpNEQAAAxY"]
[Tue Jul 21 07:24:40.147893 2026] [security2:error] [pid 229246:tid 229406] [client 20.151.10.161:65456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9I6CBMYeh5YLVG45xxnAAAAjI"]
[Tue Jul 21 07:24:40.195491 2026] [security2:error] [pid 229246:tid 229268] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I6CBMYeh5YLVG45xxnQACSxU"]
[Tue Jul 21 07:24:40.195665 2026] [security2:error] [pid 229246:tid 229431] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I6CBMYeh5YLVG45xxnQACSxU"]
[Tue Jul 21 07:24:40.366435 2026] [security2:error] [pid 230252:tid 230470] [client 20.151.10.161:26444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9I6E0Dwhk5-Z44XrpNFQAAAu8"]
[Tue Jul 21 07:24:40.590112 2026] [security2:error] [pid 230252:tid 230263] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I6E0Dwhk5-Z44XrpNHQAC4wk"]
[Tue Jul 21 07:24:40.590303 2026] [security2:error] [pid 230252:tid 230458] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I6E0Dwhk5-Z44XrpNHQAC4wk"]
[Tue Jul 21 07:24:40.870786 2026] [security2:error] [pid 230252:tid 230464] [client 20.151.10.161:49063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file52.php"] [unique_id "al9I6E0Dwhk5-Z44XrpNJgAAAuk"]
[Tue Jul 21 07:24:40.880216 2026] [security2:error] [pid 229246:tid 229379] [client 74.7.241.130:60590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "senseriopreto.com.br.hvrtecnologia.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9I6CBMYeh5YLVG45xxpgACFwk"]
[Tue Jul 21 07:24:40.895126 2026] [security2:error] [pid 230252:tid 230485] [client 20.220.225.223:45959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/else1.php"] [unique_id "al9I6E0Dwhk5-Z44XrpNJwAAAv4"]
[Tue Jul 21 07:24:40.914500 2026] [security2:error] [pid 230252:tid 230414] [client 20.226.60.151:56902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9I6E0Dwhk5-Z44XrpNKAAAArc"]
[Tue Jul 21 07:24:41.106364 2026] [security2:error] [pid 230252:tid 230410] [client 20.226.60.151:54529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/core.php"] [unique_id "al9I6U0Dwhk5-Z44XrpNKQAAArM"]
[Tue Jul 21 07:24:41.276200 2026] [security2:error] [pid 229246:tid 229312] [remote 160.187.68.132:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arterisplus.tryhealth.shop"] [uri "/wp-login.php"] [unique_id "al9I6SBMYeh5YLVG45xxqgACY0E"]
[Tue Jul 21 07:24:41.495429 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/old.php"] [unique_id "al9I6U0Dwhk5-Z44XrpNMwAAAto"]
[Tue Jul 21 07:24:41.534224 2026] [security2:error] [pid 229246:tid 229451] [client 20.151.10.161:63630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/puc.php"] [unique_id "al9I6SBMYeh5YLVG45xxsAAAAl8"]
[Tue Jul 21 07:24:41.715101 2026] [security2:error] [pid 230252:tid 230376] [remote 72.167.132.114:44172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9I6U0Dwhk5-Z44XrpNNwACyXk"]
[Tue Jul 21 07:24:41.755015 2026] [security2:error] [pid 230252:tid 230348] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I6U0Dwhk5-Z44XrpNOAACw10"]
[Tue Jul 21 07:24:41.755174 2026] [security2:error] [pid 230252:tid 230426] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I6U0Dwhk5-Z44XrpNOAACw10"]
[Tue Jul 21 07:24:41.770370 2026] [security2:error] [pid 229246:tid 229435] [client 173.252.95.7:46780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9I6SBMYeh5YLVG45xxsgAAAk8"]
[Tue Jul 21 07:24:41.875055 2026] [security2:error] [pid 229246:tid 229325] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I6SBMYeh5YLVG45xxtgACRk4"]
[Tue Jul 21 07:24:41.875213 2026] [security2:error] [pid 229246:tid 229426] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I6SBMYeh5YLVG45xxtgACRk4"]
[Tue Jul 21 07:24:41.980552 2026] [security2:error] [pid 230252:tid 230509] [client 20.151.10.161:48580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/122.php"] [unique_id "al9I6U0Dwhk5-Z44XrpNOwAAAxY"]
[Tue Jul 21 07:24:42.514567 2026] [security2:error] [pid 230252:tid 230467] [client 74.249.245.134:47083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/article.php"] [unique_id "al9I6k0Dwhk5-Z44XrpNRQAAAuw"]
[Tue Jul 21 07:24:42.807459 2026] [security2:error] [pid 229246:tid 229436] [client 74.249.245.134:54366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9I6iBMYeh5YLVG45xxvAAAAlA"]
[Tue Jul 21 07:24:42.859324 2026] [security2:error] [pid 229246:tid 229460] [client 20.151.10.161:63684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/themes.php"] [unique_id "al9I6iBMYeh5YLVG45xxvQAAAmg"]
[Tue Jul 21 07:24:42.928487 2026] [security2:error] [pid 230252:tid 230377] [remote 199.189.225.40:55787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9I6k0Dwhk5-Z44XrpNSwACyno"]
[Tue Jul 21 07:24:42.974931 2026] [security2:error] [pid 229246:tid 229253] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I6iBMYeh5YLVG45xxwgACjwY"]
[Tue Jul 21 07:24:42.975075 2026] [security2:error] [pid 229246:tid 229499] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I6iBMYeh5YLVG45xxwgACjwY"]
[Tue Jul 21 07:24:43.009529 2026] [security2:error] [pid 229246:tid 229417] [client 20.151.10.161:49066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/green1.php"] [unique_id "al9I6yBMYeh5YLVG45xxwwAAAj0"]
[Tue Jul 21 07:24:43.046129 2026] [security2:error] [pid 230252:tid 230461] [client 20.226.60.151:56877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-blog.php"] [unique_id "al9I600Dwhk5-Z44XrpNTAAAAuY"]
[Tue Jul 21 07:24:43.055687 2026] [security2:error] [pid 230252:tid 230404] [client 103.106.20.201:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I600Dwhk5-Z44XrpNTQAAAq0"]
[Tue Jul 21 07:24:43.055848 2026] [security2:error] [pid 230252:tid 230404] [client 103.106.20.201:58351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I600Dwhk5-Z44XrpNTQAAAq0"]
[Tue Jul 21 07:24:43.237064 2026] [security2:error] [pid 229246:tid 229384] [client 74.7.228.25:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cartoriodecurupira.com.br.bililica.com"] [uri "/index.php"] [unique_id "al9I6yBMYeh5YLVG45xxxwAAAhw"]
[Tue Jul 21 07:24:43.237755 2026] [security2:error] [pid 229246:tid 229472] [client 74.7.228.25:56838] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cartoriodecurupira.com.br.bililica.com"] [uri "/robots.txt"] [unique_id "al9I6yBMYeh5YLVG45xxxQACdBI"]
[Tue Jul 21 07:24:43.347433 2026] [security2:error] [pid 230252:tid 230417] [client 74.7.228.58:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cartoriodecurupira.com.br"] [uri "/index.php"] [unique_id "al9I600Dwhk5-Z44XrpNTwAAAro"]
[Tue Jul 21 07:24:43.348197 2026] [security2:error] [pid 229246:tid 229425] [client 74.7.228.58:50266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cartoriodecurupira.com.br"] [uri "/robots.txt"] [unique_id "al9I6yBMYeh5YLVG45xxywACRQM"]
[Tue Jul 21 07:24:43.407097 2026] [security2:error] [pid 230252:tid 230454] [client 51.195.244.0:50034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dharmanet.com.br"] [uri "/robots.txt"] [unique_id "al9I600Dwhk5-Z44XrpNUQAAAt8"]
[Tue Jul 21 07:24:43.407269 2026] [security2:error] [pid 230252:tid 230454] [client 51.195.244.0:50034] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dharmanet.com.br"] [uri "/robots.txt"] [unique_id "al9I600Dwhk5-Z44XrpNUQAAAt8"]
[Tue Jul 21 07:24:43.433130 2026] [security2:error] [pid 229246:tid 229485] [client 103.174.34.15:55948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I6yBMYeh5YLVG45xx0QAAAoE"]
[Tue Jul 21 07:24:43.433240 2026] [security2:error] [pid 229246:tid 229485] [client 103.174.34.15:55948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I6yBMYeh5YLVG45xx0QAAAoE"]
[Tue Jul 21 07:24:43.464023 2026] [security2:error] [pid 230252:tid 230405] [client 74.249.245.134:50972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/bootstrap.php"] [unique_id "al9I600Dwhk5-Z44XrpNUgAAAq4"]
[Tue Jul 21 07:24:43.526444 2026] [proxy:error] [pid 230252:tid 230451] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:43.526520 2026] [proxy_http:error] [pid 230252:tid 230451] [client 20.151.10.161:63660] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:43.527242 2026] [proxy:error] [pid 230252:tid 230451] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:24:43.527269 2026] [proxy_http:error] [pid 230252:tid 230451] [client 20.151.10.161:63660] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:24:43.583885 2026] [security2:error] [pid 230252:tid 230484] [client 20.220.225.223:45982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ms-new.php"] [unique_id "al9I600Dwhk5-Z44XrpNVAAAAv0"]
[Tue Jul 21 07:24:43.771541 2026] [security2:error] [pid 230252:tid 230494] [client 20.151.10.161:26457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-blog.php"] [unique_id "al9I600Dwhk5-Z44XrpNVgAAAwc"]
[Tue Jul 21 07:24:43.783924 2026] [security2:error] [pid 230252:tid 230281] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I600Dwhk5-Z44XrpNVwACsRs"]
[Tue Jul 21 07:24:43.784046 2026] [security2:error] [pid 230252:tid 230408] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I600Dwhk5-Z44XrpNVwACsRs"]
[Tue Jul 21 07:24:43.951129 2026] [security2:error] [pid 230252:tid 230489] [client 20.151.10.161:49055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/biufile.php"] [unique_id "al9I600Dwhk5-Z44XrpNWQAAAwI"]
[Tue Jul 21 07:24:44.490005 2026] [security2:error] [pid 230252:tid 230457] [client 20.151.10.161:63692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/8.php"] [unique_id "al9I7E0Dwhk5-Z44XrpNZAAAAuI"]
[Tue Jul 21 07:24:44.781863 2026] [security2:error] [pid 230252:tid 230447] [client 175.45.70.82:62395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I7E0Dwhk5-Z44XrpNawAAAtg"]
[Tue Jul 21 07:24:44.781994 2026] [security2:error] [pid 230252:tid 230447] [client 175.45.70.82:62395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I7E0Dwhk5-Z44XrpNawAAAtg"]
[Tue Jul 21 07:24:44.808269 2026] [security2:error] [pid 230252:tid 230511] [client 54.39.203.216:42256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dharmanet.com.br"] [uri "/"] [unique_id "al9I7E0Dwhk5-Z44XrpNbAAAAxg"]
[Tue Jul 21 07:24:44.808392 2026] [security2:error] [pid 230252:tid 230511] [client 54.39.203.216:42256] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dharmanet.com.br"] [uri "/"] [unique_id "al9I7E0Dwhk5-Z44XrpNbAAAAxg"]
[Tue Jul 21 07:24:44.880796 2026] [security2:error] [pid 230252:tid 230498] [client 20.220.225.223:45391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/tkikikoko.php"] [unique_id "al9I7E0Dwhk5-Z44XrpNbQAAAws"]
[Tue Jul 21 07:24:44.960069 2026] [security2:error] [pid 230252:tid 230478] [client 173.252.95.35:47246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9I7E0Dwhk5-Z44XrpNbwAAAvc"]
[Tue Jul 21 07:24:45.195788 2026] [security2:error] [pid 229246:tid 229320] [remote 182.77.62.24:51764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9I7SBMYeh5YLVG45xx7QACKUk"]
[Tue Jul 21 07:24:45.209829 2026] [autoindex:error] [pid 230252:tid 230418] [client 20.226.60.151:56841] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:45.220353 2026] [security2:error] [pid 229246:tid 229379] [client 45.251.232.145:59236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I7SBMYeh5YLVG45xx7gAAAhc"]
[Tue Jul 21 07:24:45.220473 2026] [security2:error] [pid 229246:tid 229379] [client 45.251.232.145:59236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I7SBMYeh5YLVG45xx7gAAAhc"]
[Tue Jul 21 07:24:45.243075 2026] [security2:error] [pid 229246:tid 229378] [client 20.226.60.151:56909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9I7SBMYeh5YLVG45xx7wAAAhY"]
[Tue Jul 21 07:24:45.431091 2026] [security2:error] [pid 230252:tid 230450] [client 20.151.10.161:65486] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.havoy.com.br"] [uri "/1.php"] [unique_id "al9I7U0Dwhk5-Z44XrpNcQAAAts"]
[Tue Jul 21 07:24:45.431225 2026] [security2:error] [pid 230252:tid 230450] [client 20.151.10.161:65486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/1.php"] [unique_id "al9I7U0Dwhk5-Z44XrpNcQAAAts"]
[Tue Jul 21 07:24:45.778574 2026] [security2:error] [pid 230252:tid 230454] [client 20.151.10.161:49027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wpconf.php"] [unique_id "al9I7U0Dwhk5-Z44XrpNcwAAAt8"]
[Tue Jul 21 07:24:45.917125 2026] [security2:error] [pid 230252:tid 230386] [client 136.144.33.104:29005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9I7U0Dwhk5-Z44XrpNdAAAAps"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:46.075967 2026] [security2:error] [pid 230252:tid 230469] [client 20.220.225.223:46143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-Blogs.php"] [unique_id "al9I7k0Dwhk5-Z44XrpNdgAAAu4"]
[Tue Jul 21 07:24:46.276718 2026] [security2:error] [pid 229246:tid 229332] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I7iBMYeh5YLVG45xyAAACOlU"]
[Tue Jul 21 07:24:46.276916 2026] [security2:error] [pid 229246:tid 229414] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I7iBMYeh5YLVG45xyAAACOlU"]
[Tue Jul 21 07:24:46.432884 2026] [security2:error] [pid 230252:tid 230452] [client 20.151.10.161:63685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/100.php"] [unique_id "al9I7k0Dwhk5-Z44XrpNgwAAAt0"]
[Tue Jul 21 07:24:46.453214 2026] [security2:error] [pid 230252:tid 230460] [client 74.249.245.134:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/wp.php"] [unique_id "al9I7k0Dwhk5-Z44XrpNhAAAAuU"]
[Tue Jul 21 07:24:46.480599 2026] [security2:error] [pid 230252:tid 230419] [client 103.121.156.110:53120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I7k0Dwhk5-Z44XrpNhQAAArw"]
[Tue Jul 21 07:24:46.480724 2026] [security2:error] [pid 230252:tid 230419] [client 103.121.156.110:53120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I7k0Dwhk5-Z44XrpNhQAAArw"]
[Tue Jul 21 07:24:46.971339 2026] [security2:error] [pid 230252:tid 230488] [client 154.192.233.199:59882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I7k0Dwhk5-Z44XrpNjAAAAwE"]
[Tue Jul 21 07:24:46.971487 2026] [security2:error] [pid 230252:tid 230488] [client 154.192.233.199:59882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I7k0Dwhk5-Z44XrpNjAAAAwE"]
[Tue Jul 21 07:24:47.205131 2026] [security2:error] [pid 230252:tid 230444] [client 47.128.34.23:40564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alperembalagens.com.br"] [uri "/robots.txt"] [unique_id "al9I700Dwhk5-Z44XrpNjwAAAtU"]
[Tue Jul 21 07:24:47.298591 2026] [security2:error] [pid 230252:tid 230499] [client 20.151.10.161:49146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/mosty.php"] [unique_id "al9I700Dwhk5-Z44XrpNkAAAAww"]
[Tue Jul 21 07:24:47.512556 2026] [security2:error] [pid 230252:tid 230498] [client 20.226.60.151:54535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/19.php"] [unique_id "al9I700Dwhk5-Z44XrpNlAAAAws"]
[Tue Jul 21 07:24:47.619254 2026] [security2:error] [pid 230252:tid 230464] [client 20.151.10.161:65433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/about.php"] [unique_id "al9I700Dwhk5-Z44XrpNlgAAAuk"]
[Tue Jul 21 07:24:47.735529 2026] [security2:error] [pid 230252:tid 230404] [client 20.226.60.151:56876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ms-edit.php"] [unique_id "al9I700Dwhk5-Z44XrpNlwAAAq0"]
[Tue Jul 21 07:24:47.762679 2026] [security2:error] [pid 230252:tid 230467] [client 139.135.44.145:54386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I700Dwhk5-Z44XrpNmAAAAuw"]
[Tue Jul 21 07:24:47.762810 2026] [security2:error] [pid 230252:tid 230467] [client 139.135.44.145:54386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I700Dwhk5-Z44XrpNmAAAAuw"]
[Tue Jul 21 07:24:47.875012 2026] [security2:error] [pid 230252:tid 230423] [client 20.220.225.223:45983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-css.php"] [unique_id "al9I700Dwhk5-Z44XrpNnAAAAsA"]
[Tue Jul 21 07:24:47.975464 2026] [security2:error] [pid 230252:tid 230501] [client 20.52.136.55:1596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/wp.php"] [unique_id "al9I700Dwhk5-Z44XrpNngAAAw4"]
[Tue Jul 21 07:24:48.137711 2026] [security2:error] [pid 230252:tid 230451] [client 20.151.10.161:26554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9I8E0Dwhk5-Z44XrpNpAAAAtw"]
[Tue Jul 21 07:24:48.302404 2026] [security2:error] [pid 230252:tid 230408] [client 20.151.10.161:49148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/dejavu.php"] [unique_id "al9I8E0Dwhk5-Z44XrpNqAAAArE"]
[Tue Jul 21 07:24:48.514641 2026] [security2:error] [pid 229246:tid 229480] [client 20.226.60.151:56950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9I8CBMYeh5YLVG45xyFQAAAnw"]
[Tue Jul 21 07:24:48.524215 2026] [security2:error] [pid 229246:tid 229501] [client 20.151.10.161:65472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/about.php"] [unique_id "al9I8CBMYeh5YLVG45xyFgAAApE"]
[Tue Jul 21 07:24:48.745165 2026] [security2:error] [pid 229246:tid 229365] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I8CBMYeh5YLVG45xyGwACcXY"]
[Tue Jul 21 07:24:48.745314 2026] [security2:error] [pid 229246:tid 229469] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I8CBMYeh5YLVG45xyGwACcXY"]
[Tue Jul 21 07:24:49.042847 2026] [security2:error] [pid 230252:tid 230487] [client 74.249.245.134:5550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/new.php"] [unique_id "al9I8U0Dwhk5-Z44XrpNrwAAAwA"]
[Tue Jul 21 07:24:49.108537 2026] [access_compat:error] [pid 230252:tid 230443] [client 162.241.63.68:54566] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:24:49.237441 2026] [security2:error] [pid 230252:tid 230378] [remote 4.205.168.44:36402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-login.php"] [unique_id "al9I8U0Dwhk5-Z44XrpNtQAC5Hs"]
[Tue Jul 21 07:24:49.436768 2026] [security2:error] [pid 230252:tid 230448] [client 20.151.10.161:65409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/admin.php"] [unique_id "al9I8U0Dwhk5-Z44XrpNugAAAtk"]
[Tue Jul 21 07:24:49.577765 2026] [security2:error] [pid 230252:tid 230425] [client 20.151.10.161:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/aaf.php"] [unique_id "al9I8U0Dwhk5-Z44XrpNvQAAAsI"]
[Tue Jul 21 07:24:49.582772 2026] [security2:error] [pid 230252:tid 230346] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I8U0Dwhk5-Z44XrpNvAADCFs"]
[Tue Jul 21 07:24:49.582939 2026] [security2:error] [pid 230252:tid 230495] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I8U0Dwhk5-Z44XrpNvAADCFs"]
[Tue Jul 21 07:24:49.940607 2026] [security2:error] [pid 229246:tid 229482] [client 20.220.225.223:46120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-explorer.php"] [unique_id "al9I8SBMYeh5YLVG45xyKQAAAn4"]
[Tue Jul 21 07:24:49.966626 2026] [security2:error] [pid 229246:tid 229456] [client 20.220.225.223:45952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/track.php"] [unique_id "al9I8SBMYeh5YLVG45xyKgAAAmQ"]
[Tue Jul 21 07:24:50.164497 2026] [autoindex:error] [pid 230252:tid 230494] [client 20.226.60.151:56841] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:50.170000 2026] [security2:error] [pid 230252:tid 230505] [client 20.226.60.151:56924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9I8k0Dwhk5-Z44XrpNxQAAAxI"]
[Tue Jul 21 07:24:50.242378 2026] [security2:error] [pid 230252:tid 230402] [client 103.162.129.114:55449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I8k0Dwhk5-Z44XrpNyAAAAqs"]
[Tue Jul 21 07:24:50.242511 2026] [security2:error] [pid 230252:tid 230402] [client 103.162.129.114:55449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I8k0Dwhk5-Z44XrpNyAAAAqs"]
[Tue Jul 21 07:24:50.434103 2026] [security2:error] [pid 229246:tid 229427] [client 173.252.95.21:64162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9I8iBMYeh5YLVG45xyMAAAAkc"]
[Tue Jul 21 07:24:50.435085 2026] [security2:error] [pid 230252:tid 230451] [client 20.151.10.161:65517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/admin.php"] [unique_id "al9I8k0Dwhk5-Z44XrpNywAAAtw"]
[Tue Jul 21 07:24:50.551209 2026] [security2:error] [pid 230252:tid 230483] [client 20.226.60.151:54591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/inc.php"] [unique_id "al9I8k0Dwhk5-Z44XrpNzwAAAvw"]
[Tue Jul 21 07:24:50.578957 2026] [security2:error] [pid 230252:tid 230478] [client 117.251.86.144:53502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I8k0Dwhk5-Z44XrpN0QAAAvc"]
[Tue Jul 21 07:24:50.579125 2026] [security2:error] [pid 230252:tid 230478] [client 117.251.86.144:53502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I8k0Dwhk5-Z44XrpN0QAAAvc"]
[Tue Jul 21 07:24:50.810977 2026] [security2:error] [pid 230252:tid 230323] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I8k0Dwhk5-Z44XrpN1QADAkU"]
[Tue Jul 21 07:24:50.811223 2026] [security2:error] [pid 230252:tid 230489] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I8k0Dwhk5-Z44XrpN1QADAkU"]
[Tue Jul 21 07:24:50.970414 2026] [security2:error] [pid 230252:tid 230470] [client 20.151.10.161:49064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/term.php"] [unique_id "al9I8k0Dwhk5-Z44XrpN1gAAAu8"]
[Tue Jul 21 07:24:51.030153 2026] [security2:error] [pid 229246:tid 229385] [client 20.226.60.151:54474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9I8yBMYeh5YLVG45xyNwAAAh0"]
[Tue Jul 21 07:24:51.097647 2026] [security2:error] [pid 230252:tid 230462] [client 20.151.10.161:63691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/edit.php"] [unique_id "al9I800Dwhk5-Z44XrpN1wAAAuc"]
[Tue Jul 21 07:24:51.320068 2026] [security2:error] [pid 230252:tid 230322] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I800Dwhk5-Z44XrpN2AACukQ"]
[Tue Jul 21 07:24:51.320228 2026] [security2:error] [pid 230252:tid 230417] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I800Dwhk5-Z44XrpN2AACukQ"]
[Tue Jul 21 07:24:51.330364 2026] [security2:error] [pid 230252:tid 230437] [client 74.249.245.134:5514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/class-t.api.php"] [unique_id "al9I800Dwhk5-Z44XrpN2QAAAs4"]
[Tue Jul 21 07:24:51.614358 2026] [security2:error] [pid 230252:tid 230459] [client 20.151.10.161:26340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/adminfuns.php"] [unique_id "al9I800Dwhk5-Z44XrpN3AAAAuQ"]
[Tue Jul 21 07:24:51.828404 2026] [security2:error] [pid 230252:tid 230447] [client 20.151.10.161:65414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9I800Dwhk5-Z44XrpN4AAAAtg"]
[Tue Jul 21 07:24:52.051025 2026] [security2:error] [pid 229246:tid 229468] [client 74.249.245.134:5553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/plugins.php"] [unique_id "al9I9CBMYeh5YLVG45xyRQAAAnA"]
[Tue Jul 21 07:24:52.362851 2026] [security2:error] [pid 230252:tid 230404] [client 74.249.245.134:50997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/config-backup.php"] [unique_id "al9I9E0Dwhk5-Z44XrpN5QAAAq0"]
[Tue Jul 21 07:24:52.567688 2026] [security2:error] [pid 230252:tid 230506] [client 74.249.245.134:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/jp.php"] [unique_id "al9I9E0Dwhk5-Z44XrpN5gAAAxM"]
[Tue Jul 21 07:24:52.603699 2026] [security2:error] [pid 230252:tid 230370] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I9E0Dwhk5-Z44XrpN6gAC7XM"]
[Tue Jul 21 07:24:52.603827 2026] [security2:error] [pid 230252:tid 230468] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I9E0Dwhk5-Z44XrpN6gAC7XM"]
[Tue Jul 21 07:24:52.766127 2026] [security2:error] [pid 230252:tid 230431] [client 193.36.225.54:61647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9I9E0Dwhk5-Z44XrpN6QAAAsg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:52.893943 2026] [autoindex:error] [pid 230252:tid 230501] [client 20.226.60.151:56841] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:52.933420 2026] [autoindex:error] [pid 230252:tid 230386] [client 20.226.60.151:56841] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:52.939404 2026] [security2:error] [pid 230252:tid 230464] [client 20.226.60.151:56863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/abcd.php"] [unique_id "al9I9E0Dwhk5-Z44XrpN8QAAAuk"]
[Tue Jul 21 07:24:53.037938 2026] [security2:error] [pid 229246:tid 229478] [client 74.249.245.134:54369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/error.php"] [unique_id "al9I9SBMYeh5YLVG45xyTgAAAno"]
[Tue Jul 21 07:24:53.225145 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:63713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/f6.php"] [unique_id "al9I9U0Dwhk5-Z44XrpN-AAAAwY"]
[Tue Jul 21 07:24:53.232499 2026] [security2:error] [pid 229246:tid 229448] [client 20.151.10.161:26368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/goods.php"] [unique_id "al9I9SBMYeh5YLVG45xyTwAAAlw"]
[Tue Jul 21 07:24:53.563707 2026] [security2:error] [pid 230252:tid 230391] [client 62.102.148.164:48748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9I9U0Dwhk5-Z44XrpN_AAAAqA"]
[Tue Jul 21 07:24:53.563850 2026] [security2:error] [pid 230252:tid 230391] [client 62.102.148.164:48748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9I9U0Dwhk5-Z44XrpN_AAAAqA"]
[Tue Jul 21 07:24:53.582360 2026] [security2:error] [pid 230252:tid 230316] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I9U0Dwhk5-Z44XrpN_gACvz4"]
[Tue Jul 21 07:24:53.582480 2026] [security2:error] [pid 230252:tid 230422] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9I9U0Dwhk5-Z44XrpN_gACvz4"]
[Tue Jul 21 07:24:53.585006 2026] [security2:error] [pid 230252:tid 230392] [client 20.52.136.55:1561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/new.php"] [unique_id "al9I9U0Dwhk5-Z44XrpN_wAAAqE"]
[Tue Jul 21 07:24:53.687965 2026] [security2:error] [pid 230252:tid 230449] [client 74.249.245.134:5547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/classwithtostring.php"] [unique_id "al9I9U0Dwhk5-Z44XrpOAAAAAto"]
[Tue Jul 21 07:24:53.812420 2026] [security2:error] [pid 229246:tid 229481] [client 103.106.20.201:58945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I9SBMYeh5YLVG45xyVgAAAn0"]
[Tue Jul 21 07:24:53.812533 2026] [security2:error] [pid 229246:tid 229481] [client 103.106.20.201:58945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I9SBMYeh5YLVG45xyVgAAAn0"]
[Tue Jul 21 07:24:53.812605 2026] [security2:error] [pid 230252:tid 230470] [client 20.151.10.161:65412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/inputs.php"] [unique_id "al9I9U0Dwhk5-Z44XrpOAQAAAu8"]
[Tue Jul 21 07:24:53.893539 2026] [security2:error] [pid 229246:tid 229418] [client 20.151.10.161:49094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ha.php"] [unique_id "al9I9SBMYeh5YLVG45xyWgAAAj4"]
[Tue Jul 21 07:24:54.083245 2026] [security2:error] [pid 230252:tid 230437] [client 74.249.245.134:5554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/bless.php"] [unique_id "al9I9k0Dwhk5-Z44XrpOBAAAAs4"]
[Tue Jul 21 07:24:54.233795 2026] [security2:error] [pid 229246:tid 229469] [client 103.174.34.15:56422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I9iBMYeh5YLVG45xyXwAAAnE"]
[Tue Jul 21 07:24:54.233934 2026] [security2:error] [pid 229246:tid 229469] [client 103.174.34.15:56422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I9iBMYeh5YLVG45xyXwAAAnE"]
[Tue Jul 21 07:24:54.553377 2026] [security2:error] [pid 230252:tid 230367] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I9k0Dwhk5-Z44XrpODAACmXA"]
[Tue Jul 21 07:24:54.553532 2026] [security2:error] [pid 230252:tid 230384] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9I9k0Dwhk5-Z44XrpODAACmXA"]
[Tue Jul 21 07:24:54.573374 2026] [security2:error] [pid 230252:tid 230425] [client 20.220.225.223:46131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/akismet.php"] [unique_id "al9I9k0Dwhk5-Z44XrpODQAAAsI"]
[Tue Jul 21 07:24:54.664921 2026] [security2:error] [pid 230252:tid 230488] [client 20.226.60.151:56933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/file15.php"] [unique_id "al9I9k0Dwhk5-Z44XrpODgAAAwE"]
[Tue Jul 21 07:24:54.869215 2026] [security2:error] [pid 230252:tid 230404] [client 20.151.10.161:65519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/inputs.php"] [unique_id "al9I9k0Dwhk5-Z44XrpODwAAAq0"]
[Tue Jul 21 07:24:55.002084 2026] [security2:error] [pid 230252:tid 230506] [client 20.151.10.161:49045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/hur.php"] [unique_id "al9I900Dwhk5-Z44XrpOEAAAAxM"]
[Tue Jul 21 07:24:55.107592 2026] [security2:error] [pid 230252:tid 230418] [client 62.102.148.164:48750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9I900Dwhk5-Z44XrpOEQAAArs"]
[Tue Jul 21 07:24:55.107693 2026] [security2:error] [pid 230252:tid 230418] [client 62.102.148.164:48750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9I900Dwhk5-Z44XrpOEQAAArs"]
[Tue Jul 21 07:24:55.462017 2026] [security2:error] [pid 229246:tid 229473] [client 74.249.245.134:5505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/storage/index.php"] [unique_id "al9I9yBMYeh5YLVG45xybQAAAnU"]
[Tue Jul 21 07:24:55.558842 2026] [security2:error] [pid 230252:tid 230435] [client 49.13.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9I900Dwhk5-Z44XrpOFAACzGk"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:24:55.573047 2026] [security2:error] [pid 230252:tid 230395] [client 175.45.70.82:62905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I900Dwhk5-Z44XrpOFQAAAqQ"]
[Tue Jul 21 07:24:55.573192 2026] [security2:error] [pid 230252:tid 230395] [client 175.45.70.82:62905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I900Dwhk5-Z44XrpOFQAAAqQ"]
[Tue Jul 21 07:24:55.615637 2026] [security2:error] [pid 229246:tid 229414] [client 20.151.10.161:65457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/av.php"] [unique_id "al9I9yBMYeh5YLVG45xybgAAAjo"]
[Tue Jul 21 07:24:55.722297 2026] [security2:error] [pid 230252:tid 230414] [client 45.251.232.145:59753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I900Dwhk5-Z44XrpOGAAAArc"]
[Tue Jul 21 07:24:55.722406 2026] [security2:error] [pid 230252:tid 230414] [client 45.251.232.145:59753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I900Dwhk5-Z44XrpOGAAAArc"]
[Tue Jul 21 07:24:56.061524 2026] [security2:error] [pid 229246:tid 229385] [client 20.151.10.161:26385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ms-edit.php"] [unique_id "al9I-CBMYeh5YLVG45xydQAAAh0"]
[Tue Jul 21 07:24:56.118379 2026] [security2:error] [pid 229246:tid 229400] [client 49.13.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9I-CBMYeh5YLVG45xydgACLBE"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:24:56.536213 2026] [security2:error] [pid 229246:tid 229348] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I-CBMYeh5YLVG45xyfQACJGU"]
[Tue Jul 21 07:24:56.536367 2026] [security2:error] [pid 229246:tid 229392] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9I-CBMYeh5YLVG45xyfQACJGU"]
[Tue Jul 21 07:24:56.558469 2026] [security2:error] [pid 230252:tid 230391] [client 20.151.10.161:65411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/classwithtostring.php"] [unique_id "al9I-E0Dwhk5-Z44XrpOHAAAAqA"]
[Tue Jul 21 07:24:56.691260 2026] [security2:error] [pid 230252:tid 230509] [client 74.249.245.134:5535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/g.php"] [unique_id "al9I-E0Dwhk5-Z44XrpOHwAAAxY"]
[Tue Jul 21 07:24:56.854653 2026] [autoindex:error] [pid 230252:tid 230460] [client 205.210.31.161:58310] AH01276: Cannot serve directory /home1/pedid516/cursodepilacaoprofissional.pedido-online.net/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:24:57.018052 2026] [security2:error] [pid 230252:tid 230459] [client 74.249.245.134:60836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/goods.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOKQAAAuQ"]
[Tue Jul 21 07:24:57.140748 2026] [security2:error] [pid 229246:tid 229425] [client 103.121.156.110:53440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I-SBMYeh5YLVG45xyhAAAAkU"]
[Tue Jul 21 07:24:57.140893 2026] [security2:error] [pid 229246:tid 229425] [client 103.121.156.110:53440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9I-SBMYeh5YLVG45xyhAAAAkU"]
[Tue Jul 21 07:24:57.155344 2026] [security2:error] [pid 230252:tid 230489] [client 213.152.162.104:40656] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOKgAAAwI"]
[Tue Jul 21 07:24:57.155427 2026] [security2:error] [pid 230252:tid 230489] [client 213.152.162.104:40656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOKgAAAwI"]
[Tue Jul 21 07:24:57.195711 2026] [security2:error] [pid 230252:tid 230490] [client 20.151.10.161:65504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOKwAAAwM"]
[Tue Jul 21 07:24:57.242797 2026] [security2:error] [pid 230252:tid 230499] [client 213.152.162.104:58138] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOLAAAAww"]
[Tue Jul 21 07:24:57.242902 2026] [security2:error] [pid 230252:tid 230499] [client 213.152.162.104:58138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOLAAAAww"]
[Tue Jul 21 07:24:57.412199 2026] [security2:error] [pid 230252:tid 230457] [client 20.226.60.151:56886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/jp.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOLgAAAuI"]
[Tue Jul 21 07:24:57.551013 2026] [security2:error] [pid 229246:tid 229267] [remote 69.63.184.23:36442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.184.63.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9I-SBMYeh5YLVG45xyjAACGRQ"]
[Tue Jul 21 07:24:57.613079 2026] [security2:error] [pid 229246:tid 229474] [client 20.220.225.223:46096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ace2.php"] [unique_id "al9I-SBMYeh5YLVG45xyjgAAAnY"]
[Tue Jul 21 07:24:57.665608 2026] [security2:error] [pid 229246:tid 229448] [client 20.151.10.161:26409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/222.php"] [unique_id "al9I-SBMYeh5YLVG45xykAAAAlw"]
[Tue Jul 21 07:24:57.676523 2026] [security2:error] [pid 229246:tid 229393] [client 20.226.60.151:54477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9I-SBMYeh5YLVG45xykQAAAiU"]
[Tue Jul 21 07:24:57.717938 2026] [security2:error] [pid 229246:tid 229429] [client 20.151.10.161:65416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-blog.php"] [unique_id "al9I-SBMYeh5YLVG45xykgAAAkk"]
[Tue Jul 21 07:24:57.964330 2026] [security2:error] [pid 229246:tid 229489] [client 74.249.245.134:54353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/nf.php"] [unique_id "al9I-SBMYeh5YLVG45xylAAAAoU"]
[Tue Jul 21 07:24:57.984191 2026] [security2:error] [pid 230252:tid 230488] [client 20.151.10.161:49145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/h02ugyh.php"] [unique_id "al9I-U0Dwhk5-Z44XrpOMgAAAwE"]
[Tue Jul 21 07:24:58.019905 2026] [security2:error] [pid 230252:tid 230467] [client 20.220.225.223:46005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/2352356666.php"] [unique_id "al9I-k0Dwhk5-Z44XrpOMwAAAuw"]
[Tue Jul 21 07:24:58.610632 2026] [security2:error] [pid 230252:tid 230483] [client 136.144.33.28:25095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9I-k0Dwhk5-Z44XrpOOAAAAvw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:24:58.649856 2026] [security2:error] [pid 230252:tid 230479] [client 139.135.44.145:53290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I-k0Dwhk5-Z44XrpOOQAAAvg"]
[Tue Jul 21 07:24:58.654976 2026] [security2:error] [pid 230252:tid 230479] [client 139.135.44.145:53290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9I-k0Dwhk5-Z44XrpOOQAAAvg"]
[Tue Jul 21 07:24:59.177740 2026] [security2:error] [pid 229246:tid 229492] [client 20.52.136.55:1571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/class-t.api.php"] [unique_id "al9I-yBMYeh5YLVG45xynQAAAog"]
[Tue Jul 21 07:24:59.232292 2026] [security2:error] [pid 230252:tid 230466] [client 20.151.10.161:26543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9I-00Dwhk5-Z44XrpOPgAAAus"]
[Tue Jul 21 07:24:59.252730 2026] [security2:error] [pid 230252:tid 230391] [client 74.249.245.134:5566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/xda.php"] [unique_id "al9I-00Dwhk5-Z44XrpOPwAAAqA"]
[Tue Jul 21 07:24:59.260020 2026] [security2:error] [pid 230252:tid 230351] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I-00Dwhk5-Z44XrpOQAACr2A"]
[Tue Jul 21 07:24:59.260245 2026] [security2:error] [pid 230252:tid 230406] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9I-00Dwhk5-Z44XrpOQAACr2A"]
[Tue Jul 21 07:24:59.308951 2026] [security2:error] [pid 230252:tid 230402] [client 154.192.233.199:58634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I-00Dwhk5-Z44XrpOQQAAAqs"]
[Tue Jul 21 07:24:59.309094 2026] [security2:error] [pid 230252:tid 230402] [client 154.192.233.199:58634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I-00Dwhk5-Z44XrpOQQAAAqs"]
[Tue Jul 21 07:24:59.899413 2026] [security2:error] [pid 230252:tid 230413] [client 20.226.60.151:56874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/f35.php"] [unique_id "al9I-00Dwhk5-Z44XrpORgAAArY"]
[Tue Jul 21 07:25:00.153972 2026] [security2:error] [pid 229246:tid 229294] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I_CBMYeh5YLVG45xyqQACLS8"]
[Tue Jul 21 07:25:00.154103 2026] [security2:error] [pid 229246:tid 229401] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I_CBMYeh5YLVG45xyqQACLS8"]
[Tue Jul 21 07:25:00.325613 2026] [security2:error] [pid 230252:tid 230446] [client 20.220.225.223:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ms.php"] [unique_id "al9I_E0Dwhk5-Z44XrpOSQAAAtc"]
[Tue Jul 21 07:25:00.328561 2026] [security2:error] [pid 229246:tid 229476] [client 20.220.225.223:46126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/pn.php"] [unique_id "al9I_CBMYeh5YLVG45xyqwAAAng"]
[Tue Jul 21 07:25:00.473709 2026] [security2:error] [pid 230252:tid 230430] [client 191.102.187.245:33582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "500"] [hostname "tkcorretoradeseguros.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I_E0Dwhk5-Z44XrpOSAAAAsc"]
[Tue Jul 21 07:25:00.655475 2026] [security2:error] [pid 230252:tid 230454] [client 20.226.60.151:56913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-load.php"] [unique_id "al9I_E0Dwhk5-Z44XrpOTAAAAt8"]
[Tue Jul 21 07:25:00.716586 2026] [security2:error] [pid 229246:tid 229499] [client 103.162.129.114:55900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I_CBMYeh5YLVG45xysAAAAo8"]
[Tue Jul 21 07:25:00.716701 2026] [security2:error] [pid 229246:tid 229499] [client 103.162.129.114:55900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9I_CBMYeh5YLVG45xysAAAAo8"]
[Tue Jul 21 07:25:00.810753 2026] [security2:error] [pid 230252:tid 230385] [client 82.102.28.107:38000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9I_E0Dwhk5-Z44XrpOTQAAApo"]
[Tue Jul 21 07:25:00.810854 2026] [security2:error] [pid 230252:tid 230385] [client 82.102.28.107:38000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9I_E0Dwhk5-Z44XrpOTQAAApo"]
[Tue Jul 21 07:25:00.852594 2026] [security2:error] [pid 229246:tid 229400] [client 168.119.123.75:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9I_CBMYeh5YLVG45xyswACLDw"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:25:01.030302 2026] [proxy:error] [pid 229246:tid 229497] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:01.030379 2026] [proxy_http:error] [pid 229246:tid 229497] [client 20.151.10.161:65466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:01.030941 2026] [proxy:error] [pid 229246:tid 229497] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:01.030966 2026] [proxy_http:error] [pid 229246:tid 229497] [client 20.151.10.161:65466] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:01.124354 2026] [security2:error] [pid 230252:tid 230462] [client 74.249.245.134:43405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/init.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOUQAAAuc"]
[Tue Jul 21 07:25:01.242871 2026] [security2:error] [pid 230252:tid 230459] [client 117.251.86.144:44012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOUwAAAuQ"]
[Tue Jul 21 07:25:01.243035 2026] [security2:error] [pid 230252:tid 230459] [client 117.251.86.144:44012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOUwAAAuQ"]
[Tue Jul 21 07:25:01.284394 2026] [security2:error] [pid 230252:tid 230425] [client 74.249.245.134:54346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/shell.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOVQAAAsI"]
[Tue Jul 21 07:25:01.348533 2026] [security2:error] [pid 229246:tid 229358] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I_SBMYeh5YLVG45xyuwACJ28"]
[Tue Jul 21 07:25:01.348703 2026] [security2:error] [pid 229246:tid 229395] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9I_SBMYeh5YLVG45xyuwACJ28"]
[Tue Jul 21 07:25:01.386958 2026] [security2:error] [pid 229246:tid 229391] [client 168.119.123.75:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9I_SBMYeh5YLVG45xyvAACI3M"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:25:01.773191 2026] [security2:error] [pid 230252:tid 230409] [client 62.102.148.164:37494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOXQAAArI"]
[Tue Jul 21 07:25:01.773298 2026] [security2:error] [pid 230252:tid 230409] [client 62.102.148.164:37494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOXQAAArI"]
[Tue Jul 21 07:25:01.926706 2026] [security2:error] [pid 230252:tid 230337] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOXgADDlI"]
[Tue Jul 21 07:25:01.926924 2026] [security2:error] [pid 230252:tid 230501] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOXgADDlI"]
[Tue Jul 21 07:25:02.182375 2026] [security2:error] [pid 230252:tid 230363] [remote 104.207.32.246:9899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.32.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9I_U0Dwhk5-Z44XrpOTgADA2w"]
[Tue Jul 21 07:25:02.843254 2026] [security2:error] [pid 230252:tid 230460] [client 20.226.60.151:63301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/xyn.php"] [unique_id "al9I_k0Dwhk5-Z44XrpObAAAAuU"]
[Tue Jul 21 07:25:02.931489 2026] [security2:error] [pid 230252:tid 230345] [remote 41.76.214.143:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9I_k0Dwhk5-Z44XrpObQAC91o"], referer: http://assumaocontrole.com/
[Tue Jul 21 07:25:03.061446 2026] [ssl:error] [pid 230252:tid 230439] [client 109.53.56.127:60818] AH02032: Hostname www.quattrotech.com.br provided via SNI and hostname open.spotify.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue Jul 21 07:25:03.266061 2026] [security2:error] [pid 230252:tid 230491] [client 20.151.10.161:63651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9I_00Dwhk5-Z44XrpOcAAAAwQ"]
[Tue Jul 21 07:25:03.284231 2026] [ssl:error] [pid 230252:tid 230485] [client 2.194.133.19:42880] AH02032: Hostname www.quattrotech.com.br provided via SNI and hostname open.spotify.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue Jul 21 07:25:03.347590 2026] [security2:error] [pid 230252:tid 230454] [client 74.249.245.134:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/3.php"] [unique_id "al9I_00Dwhk5-Z44XrpOdgAAAt8"]
[Tue Jul 21 07:25:03.483896 2026] [security2:error] [pid 230252:tid 230511] [client 20.151.10.161:26463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9I_00Dwhk5-Z44XrpOeAAAAxg"]
[Tue Jul 21 07:25:03.503067 2026] [security2:error] [pid 230252:tid 230381] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I_00Dwhk5-Z44XrpOeQAC1H4"]
[Tue Jul 21 07:25:03.503275 2026] [security2:error] [pid 230252:tid 230443] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9I_00Dwhk5-Z44XrpOeQAC1H4"]
[Tue Jul 21 07:25:04.297464 2026] [security2:error] [pid 230252:tid 230300] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JAE0Dwhk5-Z44XrpOjgADEC4"]
[Tue Jul 21 07:25:04.297583 2026] [security2:error] [pid 230252:tid 230503] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JAE0Dwhk5-Z44XrpOjgADEC4"]
[Tue Jul 21 07:25:04.569773 2026] [security2:error] [pid 230252:tid 230502] [client 136.144.33.241:25459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JAE0Dwhk5-Z44XrpOkwAAAw8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:04.586373 2026] [security2:error] [pid 230252:tid 230433] [client 103.106.20.201:59537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAE0Dwhk5-Z44XrpOlwAAAso"]
[Tue Jul 21 07:25:04.586525 2026] [security2:error] [pid 230252:tid 230433] [client 103.106.20.201:59537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAE0Dwhk5-Z44XrpOlwAAAso"]
[Tue Jul 21 07:25:04.835334 2026] [security2:error] [pid 229246:tid 229379] [client 109.248.148.246:32806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9JACBMYeh5YLVG45xy2AAAAhc"]
[Tue Jul 21 07:25:04.835419 2026] [security2:error] [pid 229246:tid 229379] [client 109.248.148.246:32806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9JACBMYeh5YLVG45xy2AAAAhc"]
[Tue Jul 21 07:25:04.873585 2026] [security2:error] [pid 230252:tid 230401] [client 103.174.34.15:56897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAE0Dwhk5-Z44XrpOnAAAAqo"]
[Tue Jul 21 07:25:04.873724 2026] [security2:error] [pid 230252:tid 230401] [client 103.174.34.15:56897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAE0Dwhk5-Z44XrpOnAAAAqo"]
[Tue Jul 21 07:25:05.018279 2026] [authz_core:error] [pid 229246:tid 229439] [client 74.249.245.134:53030] AH01630: client denied by server configuration: /home4/drjoao27/public_html/php.ini
[Tue Jul 21 07:25:05.030445 2026] [security2:error] [pid 230252:tid 230452] [client 20.151.10.161:26510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp.php"] [unique_id "al9JAU0Dwhk5-Z44XrpOngAAAt0"]
[Tue Jul 21 07:25:05.120064 2026] [security2:error] [pid 229246:tid 229435] [client 20.151.10.161:63696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/adminfuns.php"] [unique_id "al9JASBMYeh5YLVG45xy3QAAAk8"]
[Tue Jul 21 07:25:05.170646 2026] [security2:error] [pid 229246:tid 229482] [client 74.249.245.134:53030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/settings.php"] [unique_id "al9JASBMYeh5YLVG45xy3gAAAn4"]
[Tue Jul 21 07:25:05.262173 2026] [security2:error] [pid 230252:tid 230410] [client 82.102.28.107:39862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JAU0Dwhk5-Z44XrpOoAAAArM"]
[Tue Jul 21 07:25:05.262275 2026] [security2:error] [pid 230252:tid 230410] [client 82.102.28.107:39862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JAU0Dwhk5-Z44XrpOoAAAArM"]
[Tue Jul 21 07:25:05.316777 2026] [security2:error] [pid 230252:tid 230373] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JAU0Dwhk5-Z44XrpOoQAC0nY"]
[Tue Jul 21 07:25:05.316994 2026] [security2:error] [pid 230252:tid 230441] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JAU0Dwhk5-Z44XrpOoQAC0nY"]
[Tue Jul 21 07:25:05.324596 2026] [proxy:error] [pid 230252:tid 230509] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:05.324649 2026] [proxy_http:error] [pid 230252:tid 230509] [client 185.93.89.147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:05.325245 2026] [proxy:error] [pid 230252:tid 230509] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:05.325274 2026] [proxy_http:error] [pid 230252:tid 230509] [client 185.93.89.147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:05.726067 2026] [security2:error] [pid 230252:tid 230453] [client 74.249.245.134:54347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/mds.php"] [unique_id "al9JAU0Dwhk5-Z44XrpOqAAAAt4"]
[Tue Jul 21 07:25:06.132065 2026] [security2:error] [pid 230252:tid 230444] [client 20.151.10.161:26469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/abcd.php"] [unique_id "al9JAk0Dwhk5-Z44XrpOrwAAAtU"]
[Tue Jul 21 07:25:06.169708 2026] [security2:error] [pid 229246:tid 229496] [client 45.251.232.145:60275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAiBMYeh5YLVG45xy6gAAAow"]
[Tue Jul 21 07:25:06.169909 2026] [security2:error] [pid 229246:tid 229496] [client 45.251.232.145:60275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAiBMYeh5YLVG45xy6gAAAow"]
[Tue Jul 21 07:25:06.268702 2026] [security2:error] [pid 230252:tid 230462] [client 91.92.47.101:50620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/wp-config.php"] [unique_id "al9JAk0Dwhk5-Z44XrpOsgAAAuc"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:25:06.269118 2026] [security2:error] [pid 230252:tid 230384] [client 91.92.47.101:50622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/phpinfo.php"] [unique_id "al9JAk0Dwhk5-Z44XrpOtAAAApk"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:25:06.269380 2026] [security2:error] [pid 230252:tid 230404] [client 91.92.47.101:50606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/config.php"] [unique_id "al9JAk0Dwhk5-Z44XrpOswAAAq0"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:25:06.286984 2026] [security2:error] [pid 230252:tid 230454] [client 175.45.70.82:63413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAk0Dwhk5-Z44XrpOtgAAAt8"]
[Tue Jul 21 07:25:06.287086 2026] [security2:error] [pid 230252:tid 230454] [client 175.45.70.82:63413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAk0Dwhk5-Z44XrpOtgAAAt8"]
[Tue Jul 21 07:25:06.296330 2026] [security2:error] [pid 229246:tid 229488] [client 74.7.241.192:41040] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.a09.arcoll.com.br"] [uri "/public/robots.txt"] [unique_id "al9JAiBMYeh5YLVG45xy6wAChAc"]
[Tue Jul 21 07:25:06.322070 2026] [security2:error] [pid 229246:tid 229402] [client 74.249.245.134:5542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/archive.php"] [unique_id "al9JAiBMYeh5YLVG45xy7QAAAi4"]
[Tue Jul 21 07:25:06.468986 2026] [security2:error] [pid 230252:tid 230405] [client 91.92.47.101:50652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "look.dealspark.com.br"] [uri "/.env"] [unique_id "al9JAk0Dwhk5-Z44XrpOwQAAAq4"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:25:06.479846 2026] [security2:error] [pid 230252:tid 230451] [client 91.92.47.101:50624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/info.php"] [unique_id "al9JAk0Dwhk5-Z44XrpOwgAAAtw"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:25:06.699587 2026] [autoindex:error] [pid 230252:tid 230399] [client 20.226.60.151:56942] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:25:06.913073 2026] [security2:error] [pid 230252:tid 230432] [client 216.73.160.190:49393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/wp-login.php"] [unique_id "al9JAk0Dwhk5-Z44XrpO1AAAAsk"]
[Tue Jul 21 07:25:06.918474 2026] [security2:error] [pid 229246:tid 229406] [client 20.151.10.161:49034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/seiso.php"] [unique_id "al9JAiBMYeh5YLVG45xy9wAAAjI"]
[Tue Jul 21 07:25:07.026983 2026] [security2:error] [pid 229246:tid 229285] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JAyBMYeh5YLVG45xy-gACSyY"]
[Tue Jul 21 07:25:07.027128 2026] [security2:error] [pid 229246:tid 229431] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JAyBMYeh5YLVG45xy-gACSyY"]
[Tue Jul 21 07:25:07.254380 2026] [autoindex:error] [pid 230252:tid 230429] [client 20.226.60.151:56942] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:25:07.275609 2026] [security2:error] [pid 229246:tid 229385] [client 154.192.233.199:60453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAyBMYeh5YLVG45xy-wAAAh0"]
[Tue Jul 21 07:25:07.275739 2026] [security2:error] [pid 229246:tid 229385] [client 154.192.233.199:60453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JAyBMYeh5YLVG45xy-wAAAh0"]
[Tue Jul 21 07:25:07.315714 2026] [security2:error] [pid 230252:tid 230441] [client 20.151.10.161:26528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/a1.php"] [unique_id "al9JA00Dwhk5-Z44XrpO2QAAAtI"]
[Tue Jul 21 07:25:07.615141 2026] [security2:error] [pid 230252:tid 230495] [client 20.151.10.161:65522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/goods.php"] [unique_id "al9JA00Dwhk5-Z44XrpO3gAAAwg"]
[Tue Jul 21 07:25:07.730417 2026] [security2:error] [pid 229246:tid 229446] [client 103.121.156.110:53766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9JAyBMYeh5YLVG45xzAgAAAlo"]
[Tue Jul 21 07:25:07.730577 2026] [security2:error] [pid 229246:tid 229446] [client 103.121.156.110:53766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9JAyBMYeh5YLVG45xzAgAAAlo"]
[Tue Jul 21 07:25:07.851079 2026] [security2:error] [pid 230252:tid 230499] [client 20.226.60.151:63331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ccc.php"] [unique_id "al9JA00Dwhk5-Z44XrpO4AAAAww"]
[Tue Jul 21 07:25:08.077866 2026] [security2:error] [pid 229246:tid 229429] [client 74.249.245.134:5515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/amax.php"] [unique_id "al9JBCBMYeh5YLVG45xzBgAAAkk"]
[Tue Jul 21 07:25:08.161470 2026] [security2:error] [pid 230252:tid 230474] [client 213.152.162.104:36528] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JBE0Dwhk5-Z44XrpO6QAAAvM"]
[Tue Jul 21 07:25:08.161573 2026] [security2:error] [pid 230252:tid 230474] [client 213.152.162.104:36528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JBE0Dwhk5-Z44XrpO6QAAAvM"]
[Tue Jul 21 07:25:08.311756 2026] [security2:error] [pid 230252:tid 230498] [client 20.151.10.161:26536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9JBE0Dwhk5-Z44XrpO7AAAAws"]
[Tue Jul 21 07:25:08.945985 2026] [security2:error] [pid 229246:tid 229398] [client 74.249.245.134:5518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/moon.php"] [unique_id "al9JBCBMYeh5YLVG45xzEAAAAio"]
[Tue Jul 21 07:25:09.019991 2026] [security2:error] [pid 230252:tid 230479] [client 20.226.60.151:56871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/w.php"] [unique_id "al9JBU0Dwhk5-Z44XrpO9gAAAvg"]
[Tue Jul 21 07:25:09.280089 2026] [security2:error] [pid 230252:tid 230398] [client 20.151.10.161:49085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/155.php"] [unique_id "al9JBU0Dwhk5-Z44XrpO-AAAAqc"]
[Tue Jul 21 07:25:09.430210 2026] [security2:error] [pid 229246:tid 229433] [client 62.102.148.164:53424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JBSBMYeh5YLVG45xzFwAAAk0"]
[Tue Jul 21 07:25:09.430306 2026] [security2:error] [pid 229246:tid 229433] [client 62.102.148.164:53424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JBSBMYeh5YLVG45xzFwAAAk0"]
[Tue Jul 21 07:25:09.523995 2026] [security2:error] [pid 229246:tid 229452] [client 139.135.44.145:54031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JBSBMYeh5YLVG45xzGQAAAmA"]
[Tue Jul 21 07:25:09.524099 2026] [security2:error] [pid 229246:tid 229452] [client 139.135.44.145:54031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JBSBMYeh5YLVG45xzGQAAAmA"]
[Tue Jul 21 07:25:09.581412 2026] [security2:error] [pid 230252:tid 230440] [client 74.249.245.134:54380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/ws83.php"] [unique_id "al9JBU0Dwhk5-Z44XrpO_AAAAtE"]
[Tue Jul 21 07:25:09.781727 2026] [security2:error] [pid 230252:tid 230356] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JBU0Dwhk5-Z44XrpO_QACtGU"]
[Tue Jul 21 07:25:09.781977 2026] [security2:error] [pid 230252:tid 230411] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JBU0Dwhk5-Z44XrpO_QACtGU"]
[Tue Jul 21 07:25:09.951236 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:65445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/ms-edit.php"] [unique_id "al9JBSBMYeh5YLVG45xzIAAAAns"]
[Tue Jul 21 07:25:10.089666 2026] [security2:error] [pid 229246:tid 229402] [client 20.151.10.161:26402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9JBiBMYeh5YLVG45xzJAAAAi4"]
[Tue Jul 21 07:25:10.377960 2026] [security2:error] [pid 229246:tid 229330] [remote 102.134.101.35:34782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "polycellassistencia.com.ocsdbodyboarding.com.br"] [uri "/wp-login.php"] [unique_id "al9JBiBMYeh5YLVG45xzKgACLVM"]
[Tue Jul 21 07:25:10.698471 2026] [security2:error] [pid 229246:tid 229313] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JBiBMYeh5YLVG45xzLwACjkI"]
[Tue Jul 21 07:25:10.698657 2026] [security2:error] [pid 229246:tid 229498] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JBiBMYeh5YLVG45xzLwACjkI"]
[Tue Jul 21 07:25:10.842958 2026] [security2:error] [pid 229246:tid 229391] [client 74.249.245.134:54341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/CDX1.php"] [unique_id "al9JBiBMYeh5YLVG45xzMQAAAiM"]
[Tue Jul 21 07:25:10.957390 2026] [security2:error] [pid 230252:tid 230413] [client 136.144.33.28:32563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JBk0Dwhk5-Z44XrpPAwAAArY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:11.101653 2026] [security2:error] [pid 230252:tid 230485] [client 109.248.148.246:44068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JB00Dwhk5-Z44XrpPBgAAAv4"]
[Tue Jul 21 07:25:11.101756 2026] [security2:error] [pid 230252:tid 230485] [client 109.248.148.246:44068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JB00Dwhk5-Z44XrpPBgAAAv4"]
[Tue Jul 21 07:25:11.308651 2026] [security2:error] [pid 230252:tid 230410] [client 103.162.129.114:56372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JB00Dwhk5-Z44XrpPCAAAArM"]
[Tue Jul 21 07:25:11.308776 2026] [security2:error] [pid 230252:tid 230410] [client 103.162.129.114:56372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JB00Dwhk5-Z44XrpPCAAAArM"]
[Tue Jul 21 07:25:11.432480 2026] [security2:error] [pid 229246:tid 229446] [client 20.226.60.151:54469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/ss.php"] [unique_id "al9JByBMYeh5YLVG45xzNwAAAlo"]
[Tue Jul 21 07:25:11.669870 2026] [security2:error] [pid 230252:tid 230417] [client 20.151.10.161:63697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/222.php"] [unique_id "al9JB00Dwhk5-Z44XrpPDAAAAro"]
[Tue Jul 21 07:25:11.686369 2026] [security2:error] [pid 229246:tid 229429] [client 109.248.148.246:44054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JByBMYeh5YLVG45xzPQAAAkk"]
[Tue Jul 21 07:25:11.686487 2026] [security2:error] [pid 229246:tid 229429] [client 109.248.148.246:44054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JByBMYeh5YLVG45xzPQAAAkk"]
[Tue Jul 21 07:25:11.850464 2026] [security2:error] [pid 230252:tid 230353] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JB00Dwhk5-Z44XrpPEAAC02I"]
[Tue Jul 21 07:25:11.850659 2026] [security2:error] [pid 230252:tid 230442] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JB00Dwhk5-Z44XrpPEAAC02I"]
[Tue Jul 21 07:25:12.020067 2026] [security2:error] [pid 230252:tid 230489] [client 117.251.86.144:45904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JCE0Dwhk5-Z44XrpPEQAAAwI"]
[Tue Jul 21 07:25:12.020248 2026] [security2:error] [pid 230252:tid 230489] [client 117.251.86.144:45904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JCE0Dwhk5-Z44XrpPEQAAAwI"]
[Tue Jul 21 07:25:12.180495 2026] [security2:error] [pid 230252:tid 230419] [client 20.151.10.161:26464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/gettest.php"] [unique_id "al9JCE0Dwhk5-Z44XrpPFAAAArw"]
[Tue Jul 21 07:25:12.318406 2026] [security2:error] [pid 230252:tid 230450] [client 20.226.60.151:62347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9JCE0Dwhk5-Z44XrpPFQAAAts"]
[Tue Jul 21 07:25:12.410569 2026] [security2:error] [pid 229246:tid 229378] [client 74.249.245.134:54348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/inputs.php"] [unique_id "al9JCCBMYeh5YLVG45xzRwAAAhY"]
[Tue Jul 21 07:25:12.933716 2026] [security2:error] [pid 229246:tid 229500] [client 20.151.10.161:63735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9JCCBMYeh5YLVG45xzUAAAApA"]
[Tue Jul 21 07:25:12.985000 2026] [security2:error] [pid 229246:tid 229278] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JCCBMYeh5YLVG45xzUQACKx8"]
[Tue Jul 21 07:25:12.985188 2026] [security2:error] [pid 229246:tid 229399] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JCCBMYeh5YLVG45xzUQACKx8"]
[Tue Jul 21 07:25:13.041593 2026] [security2:error] [pid 230252:tid 230295] [remote 68.178.160.25:60046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9JCU0Dwhk5-Z44XrpPGAADBik"]
[Tue Jul 21 07:25:13.641424 2026] [security2:error] [pid 229246:tid 229420] [client 20.226.60.151:54520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/min.php"] [unique_id "al9JCSBMYeh5YLVG45xzXQAAAkA"]
[Tue Jul 21 07:25:13.981131 2026] [proxy:error] [pid 229246:tid 229497] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:13.981215 2026] [proxy_http:error] [pid 229246:tid 229497] [client 20.151.10.161:63706] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:13.981805 2026] [proxy:error] [pid 229246:tid 229497] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:13.981838 2026] [proxy_http:error] [pid 229246:tid 229497] [client 20.151.10.161:63706] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:14.045671 2026] [security2:error] [pid 230252:tid 230399] [client 74.249.245.134:5531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/ms-edit.php"] [unique_id "al9JCk0Dwhk5-Z44XrpPIAAAAqg"]
[Tue Jul 21 07:25:14.100655 2026] [security2:error] [pid 229246:tid 229377] [client 20.226.60.151:56938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/FWAZ.php"] [unique_id "al9JCiBMYeh5YLVG45xzZgAAAhU"]
[Tue Jul 21 07:25:14.227895 2026] [security2:error] [pid 229246:tid 229339] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JCiBMYeh5YLVG45xzaQACcFw"]
[Tue Jul 21 07:25:14.228051 2026] [security2:error] [pid 229246:tid 229468] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JCiBMYeh5YLVG45xzaQACcFw"]
[Tue Jul 21 07:25:14.747704 2026] [security2:error] [pid 229246:tid 229493] [client 74.249.245.134:54377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/simple.php"] [unique_id "al9JCiBMYeh5YLVG45xzbQAAAok"]
[Tue Jul 21 07:25:14.838789 2026] [security2:error] [pid 230252:tid 230382] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JCk0Dwhk5-Z44XrpPKQADF38"]
[Tue Jul 21 07:25:14.839037 2026] [security2:error] [pid 230252:tid 230510] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JCk0Dwhk5-Z44XrpPKQADF38"]
[Tue Jul 21 07:25:14.841006 2026] [security2:error] [pid 230252:tid 230477] [client 20.220.225.223:46011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-wpbak.php"] [unique_id "al9JCk0Dwhk5-Z44XrpPKgAAAvY"]
[Tue Jul 21 07:25:15.314633 2026] [security2:error] [pid 229246:tid 229423] [client 103.106.20.201:60137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JCyBMYeh5YLVG45xzrwAAAkM"]
[Tue Jul 21 07:25:15.314748 2026] [security2:error] [pid 229246:tid 229423] [client 103.106.20.201:60137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JCyBMYeh5YLVG45xzrwAAAkM"]
[Tue Jul 21 07:25:15.326368 2026] [security2:error] [pid 229246:tid 229492] [client 93.123.109.101:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.chefiabarbearia.com.br"] [uri "/___proxy_subdomain_cpcalendars/.svn/wc.db"] [unique_id "al9JCyBMYeh5YLVG45xzsQAAAog"]
[Tue Jul 21 07:25:15.505657 2026] [security2:error] [pid 230252:tid 230389] [client 20.151.10.161:65467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9JC00Dwhk5-Z44XrpPLAAAAp4"]
[Tue Jul 21 07:25:15.635163 2026] [security2:error] [pid 229246:tid 229379] [client 109.248.148.246:54062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JCyBMYeh5YLVG45xzswAAAhc"]
[Tue Jul 21 07:25:15.635254 2026] [security2:error] [pid 229246:tid 229379] [client 109.248.148.246:54062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JCyBMYeh5YLVG45xzswAAAhc"]
[Tue Jul 21 07:25:15.682002 2026] [security2:error] [pid 230252:tid 230485] [client 74.249.245.134:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/404.php"] [unique_id "al9JC00Dwhk5-Z44XrpPLQAAAv4"]
[Tue Jul 21 07:25:15.686627 2026] [security2:error] [pid 229246:tid 229413] [client 103.174.34.15:57370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JCyBMYeh5YLVG45xztAAAAjk"]
[Tue Jul 21 07:25:15.686775 2026] [security2:error] [pid 229246:tid 229413] [client 103.174.34.15:57370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JCyBMYeh5YLVG45xztAAAAjk"]
[Tue Jul 21 07:25:15.737958 2026] [security2:error] [pid 230252:tid 230487] [client 213.152.162.104:38082] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JC00Dwhk5-Z44XrpPLgAAAwA"]
[Tue Jul 21 07:25:15.738097 2026] [security2:error] [pid 230252:tid 230487] [client 213.152.162.104:38082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JC00Dwhk5-Z44XrpPLgAAAwA"]
[Tue Jul 21 07:25:16.072515 2026] [security2:error] [pid 229246:tid 229305] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JDCBMYeh5YLVG45xz3QACbjo"]
[Tue Jul 21 07:25:16.072710 2026] [security2:error] [pid 229246:tid 229466] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JDCBMYeh5YLVG45xz3QACbjo"]
[Tue Jul 21 07:25:16.397943 2026] [security2:error] [pid 230252:tid 230397] [client 20.226.60.151:56901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/miru1.php"] [unique_id "al9JDE0Dwhk5-Z44XrpPMgAAAqY"]
[Tue Jul 21 07:25:16.652849 2026] [security2:error] [pid 229246:tid 229461] [client 45.251.232.145:60794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JDCBMYeh5YLVG45xz5wAAAmk"]
[Tue Jul 21 07:25:16.652974 2026] [security2:error] [pid 229246:tid 229461] [client 45.251.232.145:60794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JDCBMYeh5YLVG45xz5wAAAmk"]
[Tue Jul 21 07:25:16.657842 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:16.657898 2026] [proxy_http:error] [pid 230252:tid 230437] [client 20.151.10.161:63686] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:16.658502 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:16.658525 2026] [proxy_http:error] [pid 230252:tid 230437] [client 20.151.10.161:63686] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:16.809926 2026] [security2:error] [pid 230252:tid 230511] [client 20.151.10.161:26376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/simple.php"] [unique_id "al9JDE0Dwhk5-Z44XrpPNQAAAxg"]
[Tue Jul 21 07:25:16.838339 2026] [security2:error] [pid 229246:tid 229385] [client 193.36.225.54:38303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JDCBMYeh5YLVG45xz6AAAAh0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:16.891321 2026] [security2:error] [pid 229246:tid 229390] [client 175.45.70.82:63925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JDCBMYeh5YLVG45xz6QAAAiI"]
[Tue Jul 21 07:25:16.891429 2026] [security2:error] [pid 229246:tid 229390] [client 175.45.70.82:63925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JDCBMYeh5YLVG45xz6QAAAiI"]
[Tue Jul 21 07:25:17.065115 2026] [security2:error] [pid 230252:tid 230456] [client 62.102.148.164:54670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPOAAAAuE"]
[Tue Jul 21 07:25:17.065216 2026] [security2:error] [pid 230252:tid 230456] [client 62.102.148.164:54670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPOAAAAuE"]
[Tue Jul 21 07:25:17.116532 2026] [security2:error] [pid 230252:tid 230439] [client 74.249.245.134:5541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/file3.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPOQAAAtA"]
[Tue Jul 21 07:25:17.428561 2026] [security2:error] [pid 230252:tid 230467] [client 20.220.225.223:45998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/dr.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPPAAAAuw"]
[Tue Jul 21 07:25:17.431224 2026] [security2:error] [pid 230252:tid 230454] [client 20.151.10.161:26388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/xxx.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPPQAAAt8"]
[Tue Jul 21 07:25:17.720650 2026] [security2:error] [pid 230252:tid 230335] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPRAACwlA"]
[Tue Jul 21 07:25:17.720820 2026] [security2:error] [pid 230252:tid 230425] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPRAACwlA"]
[Tue Jul 21 07:25:17.843877 2026] [security2:error] [pid 229246:tid 229377] [client 154.192.233.199:59848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JDSBMYeh5YLVG45xz_QAAAhU"]
[Tue Jul 21 07:25:17.844007 2026] [security2:error] [pid 229246:tid 229377] [client 154.192.233.199:59848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JDSBMYeh5YLVG45xz_QAAAhU"]
[Tue Jul 21 07:25:17.916045 2026] [security2:error] [pid 230252:tid 230451] [client 20.151.10.161:26467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/hypo.php"] [unique_id "al9JDU0Dwhk5-Z44XrpPRQAAAtw"]
[Tue Jul 21 07:25:18.107389 2026] [security2:error] [pid 229246:tid 229478] [client 93.123.109.101:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.chefiabarbearia.com.br"] [uri "/___proxy_subdomain_cpcalendars/.svn/wc.db"] [unique_id "al9JDiBMYeh5YLVG45x0AgAAAno"]
[Tue Jul 21 07:25:18.116399 2026] [security2:error] [pid 230252:tid 230396] [client 74.249.245.134:5548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/wp-mail.php"] [unique_id "al9JDk0Dwhk5-Z44XrpPSgAAAqU"]
[Tue Jul 21 07:25:18.197071 2026] [security2:error] [pid 229246:tid 229458] [client 82.102.28.107:40042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JDiBMYeh5YLVG45x0AwAAAmY"]
[Tue Jul 21 07:25:18.197207 2026] [security2:error] [pid 229246:tid 229458] [client 82.102.28.107:40042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JDiBMYeh5YLVG45x0AwAAAmY"]
[Tue Jul 21 07:25:18.367740 2026] [security2:error] [pid 230252:tid 230494] [client 103.121.156.110:53994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.156.121.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9JDk0Dwhk5-Z44XrpPSwAAAwc"]
[Tue Jul 21 07:25:18.367888 2026] [security2:error] [pid 230252:tid 230494] [client 103.121.156.110:53994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "littlefreedom.com.au"] [uri "/xmlrpc.php"] [unique_id "al9JDk0Dwhk5-Z44XrpPSwAAAwc"]
[Tue Jul 21 07:25:18.592849 2026] [security2:error] [pid 229246:tid 229379] [client 93.123.109.101:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.chefiabarbearia.com.br"] [uri "/___proxy_subdomain_cpcalendars/.svn/entries"] [unique_id "al9JDiBMYeh5YLVG45x0CwAAAhc"]
[Tue Jul 21 07:25:18.595442 2026] [proxy:error] [pid 230252:tid 230406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:18.595505 2026] [proxy_http:error] [pid 230252:tid 230406] [client 20.151.10.161:65408] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:18.595970 2026] [proxy:error] [pid 230252:tid 230406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:18.596002 2026] [proxy_http:error] [pid 230252:tid 230406] [client 20.151.10.161:65408] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:18.637246 2026] [security2:error] [pid 229246:tid 229439] [client 20.226.60.151:56954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/aa.php"] [unique_id "al9JDiBMYeh5YLVG45x0DAAAAlM"]
[Tue Jul 21 07:25:19.092671 2026] [security2:error] [pid 230252:tid 230414] [client 20.220.225.223:46082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/2x.php"] [unique_id "al9JD00Dwhk5-Z44XrpPVQAAArc"]
[Tue Jul 21 07:25:19.288277 2026] [security2:error] [pid 229246:tid 229427] [client 20.226.60.151:56900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/122.php"] [unique_id "al9JDyBMYeh5YLVG45x0HwAAAkc"]
[Tue Jul 21 07:25:19.425718 2026] [security2:error] [pid 229246:tid 229409] [client 74.249.245.134:54355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/about.php"] [unique_id "al9JDyBMYeh5YLVG45x0IgAAAjU"]
[Tue Jul 21 07:25:19.505621 2026] [security2:error] [pid 230252:tid 230316] [remote 13.159.147.98:34444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.147.159.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JDk0Dwhk5-Z44XrpPTgADDz4"]
[Tue Jul 21 07:25:19.519017 2026] [core:alert] [pid 229246:tid 229488] [client 57.141.18.75:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:25:20.163275 2026] [security2:error] [pid 230252:tid 230456] [client 20.151.10.161:26441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/chosen.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPZAAAAuE"]
[Tue Jul 21 07:25:20.265784 2026] [security2:error] [pid 230252:tid 230486] [client 139.135.44.145:54836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPZQAAAv8"]
[Tue Jul 21 07:25:20.266524 2026] [security2:error] [pid 230252:tid 230486] [client 139.135.44.145:54836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPZQAAAv8"]
[Tue Jul 21 07:25:20.337367 2026] [security2:error] [pid 230252:tid 230366] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPZgACmm8"]
[Tue Jul 21 07:25:20.337518 2026] [security2:error] [pid 230252:tid 230385] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPZgACmm8"]
[Tue Jul 21 07:25:20.375501 2026] [security2:error] [pid 230252:tid 230430] [client 20.226.60.151:56869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/get.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPZwAAAsc"]
[Tue Jul 21 07:25:20.558869 2026] [security2:error] [pid 230252:tid 230454] [client 74.249.245.134:5525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/adminfuns.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPaQAAAt8"]
[Tue Jul 21 07:25:20.704150 2026] [security2:error] [pid 230252:tid 230458] [client 183.83.233.92:61505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.233.83.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "governess.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPaAAAAuM"]
[Tue Jul 21 07:25:20.704352 2026] [security2:error] [pid 230252:tid 230458] [client 183.83.233.92:61505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "governess.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPaAAAAuM"]
[Tue Jul 21 07:25:20.793132 2026] [security2:error] [pid 230252:tid 230436] [client 20.151.10.161:63618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/raw.php"] [unique_id "al9JEE0Dwhk5-Z44XrpPbgAAAs0"]
[Tue Jul 21 07:25:21.002474 2026] [security2:error] [pid 229246:tid 229499] [client 20.220.225.223:46101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/kq1.php"] [unique_id "al9JESBMYeh5YLVG45x0MQAAAo8"]
[Tue Jul 21 07:25:21.169907 2026] [security2:error] [pid 230252:tid 230388] [client 20.226.60.151:56887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/as.php"] [unique_id "al9JEU0Dwhk5-Z44XrpPbwAAAp0"]
[Tue Jul 21 07:25:21.197827 2026] [security2:error] [pid 229246:tid 229300] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JESBMYeh5YLVG45x0NgACVjU"]
[Tue Jul 21 07:25:21.197958 2026] [security2:error] [pid 229246:tid 229442] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JESBMYeh5YLVG45x0NgACVjU"]
[Tue Jul 21 07:25:21.828521 2026] [security2:error] [pid 230252:tid 230493] [client 103.162.129.114:56829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JEU0Dwhk5-Z44XrpPdAAAAwY"]
[Tue Jul 21 07:25:21.828671 2026] [security2:error] [pid 230252:tid 230493] [client 103.162.129.114:56829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JEU0Dwhk5-Z44XrpPdAAAAwY"]
[Tue Jul 21 07:25:21.841960 2026] [security2:error] [pid 230252:tid 230438] [client 20.226.60.151:56927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ccou.php"] [unique_id "al9JEU0Dwhk5-Z44XrpPdQAAAs8"]
[Tue Jul 21 07:25:21.916346 2026] [security2:error] [pid 229246:tid 229380] [client 20.151.10.161:48967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ppp.php"] [unique_id "al9JESBMYeh5YLVG45x0PAAAAhg"]
[Tue Jul 21 07:25:22.025881 2026] [security2:error] [pid 230252:tid 230260] [remote 68.178.160.25:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goldentrips40.com"] [uri "/wp-login.php"] [unique_id "al9JEk0Dwhk5-Z44XrpPdwAC3AY"]
[Tue Jul 21 07:25:22.173486 2026] [security2:error] [pid 230252:tid 230442] [client 193.36.225.10:21677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JEk0Dwhk5-Z44XrpPdgAAAtM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:22.467988 2026] [security2:error] [pid 229246:tid 229318] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JEiBMYeh5YLVG45x0RAACckc"]
[Tue Jul 21 07:25:22.468146 2026] [security2:error] [pid 229246:tid 229470] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JEiBMYeh5YLVG45x0RAACckc"]
[Tue Jul 21 07:25:22.497487 2026] [security2:error] [pid 229246:tid 229396] [client 74.249.245.134:54371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/php8.php"] [unique_id "al9JEiBMYeh5YLVG45x0RQAAAig"]
[Tue Jul 21 07:25:22.692909 2026] [security2:error] [pid 229246:tid 229452] [client 20.151.10.161:26461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/als.php"] [unique_id "al9JEiBMYeh5YLVG45x0SgAAAmA"]
[Tue Jul 21 07:25:22.700798 2026] [security2:error] [pid 230252:tid 230434] [client 20.151.10.161:65420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/abcd.php"] [unique_id "al9JEk0Dwhk5-Z44XrpPegAAAss"]
[Tue Jul 21 07:25:22.769120 2026] [security2:error] [pid 230252:tid 230420] [client 117.251.86.144:37198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JEk0Dwhk5-Z44XrpPfQAAAr0"]
[Tue Jul 21 07:25:22.769293 2026] [security2:error] [pid 230252:tid 230420] [client 117.251.86.144:37198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JEk0Dwhk5-Z44XrpPfQAAAr0"]
[Tue Jul 21 07:25:22.791573 2026] [proxy:error] [pid 229246:tid 229248] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:22.791602 2026] [proxy_http:error] [pid 229246:tid 229248] [remote 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:22.792047 2026] [proxy:error] [pid 229246:tid 229248] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:22.792067 2026] [proxy_http:error] [pid 229246:tid 229248] [remote 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:23.394800 2026] [security2:error] [pid 229246:tid 229414] [client 20.226.60.151:56852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/w3lls.php"] [unique_id "al9JEyBMYeh5YLVG45x0WgAAAjo"]
[Tue Jul 21 07:25:23.866054 2026] [security2:error] [pid 229246:tid 229317] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JEyBMYeh5YLVG45x0YQACQUY"]
[Tue Jul 21 07:25:23.866240 2026] [security2:error] [pid 229246:tid 229421] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JEyBMYeh5YLVG45x0YQACQUY"]
[Tue Jul 21 07:25:24.158146 2026] [security2:error] [pid 230252:tid 230462] [client 20.151.10.161:26521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/pol.php"] [unique_id "al9JFE0Dwhk5-Z44XrpPkwAAAuc"]
[Tue Jul 21 07:25:24.670922 2026] [security2:error] [pid 230252:tid 230423] [client 74.249.245.134:5543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/info.php"] [unique_id "al9JFE0Dwhk5-Z44XrpPlgAAAsA"]
[Tue Jul 21 07:25:24.693598 2026] [security2:error] [pid 230252:tid 230458] [client 20.151.10.161:63693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/a1.php"] [unique_id "al9JFE0Dwhk5-Z44XrpPlwAAAuM"]
[Tue Jul 21 07:25:24.695536 2026] [security2:error] [pid 230252:tid 230415] [client 20.226.60.151:54480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9JFE0Dwhk5-Z44XrpPmAAAArg"]
[Tue Jul 21 07:25:24.714029 2026] [security2:error] [pid 229246:tid 229444] [client 109.248.148.246:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JFCBMYeh5YLVG45x0aAAAAlg"]
[Tue Jul 21 07:25:24.714118 2026] [security2:error] [pid 229246:tid 229444] [client 109.248.148.246:60164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JFCBMYeh5YLVG45x0aAAAAlg"]
[Tue Jul 21 07:25:24.858969 2026] [security2:error] [pid 230252:tid 230342] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JFE0Dwhk5-Z44XrpPmgAC21c"]
[Tue Jul 21 07:25:24.859269 2026] [security2:error] [pid 230252:tid 230450] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JFE0Dwhk5-Z44XrpPmgAC21c"]
[Tue Jul 21 07:25:24.914359 2026] [security2:error] [pid 230252:tid 230479] [client 20.151.10.161:49033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/201.php"] [unique_id "al9JFE0Dwhk5-Z44XrpPnAAAAvg"]
[Tue Jul 21 07:25:25.371661 2026] [security2:error] [pid 230252:tid 230493] [client 20.52.136.55:1755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/jp.php"] [unique_id "al9JFU0Dwhk5-Z44XrpPngAAAwY"]
[Tue Jul 21 07:25:25.378090 2026] [security2:error] [pid 229246:tid 229311] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JFSBMYeh5YLVG45x0cQACXUA"]
[Tue Jul 21 07:25:25.378233 2026] [security2:error] [pid 229246:tid 229449] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JFSBMYeh5YLVG45x0cQACXUA"]
[Tue Jul 21 07:25:25.400228 2026] [security2:error] [pid 230252:tid 230438] [client 20.226.60.151:56910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/test1.php"] [unique_id "al9JFU0Dwhk5-Z44XrpPnwAAAs8"]
[Tue Jul 21 07:25:25.743895 2026] [security2:error] [pid 230252:tid 230386] [client 109.248.148.246:60204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JFU0Dwhk5-Z44XrpPpAAAAps"]
[Tue Jul 21 07:25:25.743979 2026] [security2:error] [pid 230252:tid 230386] [client 109.248.148.246:60204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JFU0Dwhk5-Z44XrpPpAAAAps"]
[Tue Jul 21 07:25:26.023539 2026] [security2:error] [pid 230252:tid 230501] [client 103.106.20.201:60703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JFk0Dwhk5-Z44XrpPpwAAAw4"]
[Tue Jul 21 07:25:26.023682 2026] [security2:error] [pid 230252:tid 230501] [client 103.106.20.201:60703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JFk0Dwhk5-Z44XrpPpwAAAw4"]
[Tue Jul 21 07:25:26.383755 2026] [security2:error] [pid 230252:tid 230440] [client 103.174.34.15:57846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JFk0Dwhk5-Z44XrpPqgAAAtE"]
[Tue Jul 21 07:25:26.383956 2026] [security2:error] [pid 230252:tid 230440] [client 103.174.34.15:57846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JFk0Dwhk5-Z44XrpPqgAAAtE"]
[Tue Jul 21 07:25:26.595460 2026] [security2:error] [pid 229246:tid 229452] [client 20.151.10.161:63709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9JFiBMYeh5YLVG45x0fgAAAmA"]
[Tue Jul 21 07:25:26.597256 2026] [security2:error] [pid 229246:tid 229458] [client 74.249.245.134:54373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/edit.php"] [unique_id "al9JFiBMYeh5YLVG45x0fwAAAmY"]
[Tue Jul 21 07:25:26.817160 2026] [security2:error] [pid 229246:tid 229253] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JFiBMYeh5YLVG45x0gQACKwY"]
[Tue Jul 21 07:25:26.817327 2026] [security2:error] [pid 229246:tid 229399] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JFiBMYeh5YLVG45x0gQACKwY"]
[Tue Jul 21 07:25:27.014766 2026] [security2:error] [pid 229246:tid 229455] [client 136.144.33.54:50309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JFyBMYeh5YLVG45x0hAAAAmM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:27.119503 2026] [security2:error] [pid 230252:tid 230420] [client 45.251.232.145:61315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JF00Dwhk5-Z44XrpPuQAAAr0"]
[Tue Jul 21 07:25:27.119586 2026] [security2:error] [pid 230252:tid 230420] [client 45.251.232.145:61315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JF00Dwhk5-Z44XrpPuQAAAr0"]
[Tue Jul 21 07:25:27.386023 2026] [security2:error] [pid 229246:tid 229402] [client 152.59.154.239:62640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JFSBMYeh5YLVG45x0cgAAAi4"]
[Tue Jul 21 07:25:27.669264 2026] [security2:error] [pid 230252:tid 230474] [client 175.45.70.82:64433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JF00Dwhk5-Z44XrpPwAAAAvM"]
[Tue Jul 21 07:25:27.669431 2026] [security2:error] [pid 230252:tid 230474] [client 175.45.70.82:64433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JF00Dwhk5-Z44XrpPwAAAAvM"]
[Tue Jul 21 07:25:27.949862 2026] [proxy:error] [pid 230252:tid 230285] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:27.949914 2026] [proxy_http:error] [pid 230252:tid 230285] [remote 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:27.950510 2026] [proxy:error] [pid 230252:tid 230285] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:27.950532 2026] [proxy_http:error] [pid 230252:tid 230285] [remote 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:28.012280 2026] [security2:error] [pid 230252:tid 230476] [client 20.151.10.161:26322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file5.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPwwAAAvU"]
[Tue Jul 21 07:25:28.032486 2026] [security2:error] [pid 230252:tid 230296] [remote 20.153.140.50:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPxAAC4yo"]
[Tue Jul 21 07:25:28.142304 2026] [security2:error] [pid 230252:tid 230438] [client 74.249.245.134:17423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/166.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPxQAAAs8"]
[Tue Jul 21 07:25:28.155596 2026] [security2:error] [pid 230252:tid 230331] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPxgACp0w"]
[Tue Jul 21 07:25:28.155738 2026] [security2:error] [pid 230252:tid 230398] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPxgACp0w"]
[Tue Jul 21 07:25:28.164545 2026] [security2:error] [pid 230252:tid 230264] [remote 156.59.198.136:34236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "issima.net.br"] [uri "/equestre/brasao/brasao-azul-e-branco.pdf"] [unique_id "al9JGE0Dwhk5-Z44XrpPyAACpQo"]
[Tue Jul 21 07:25:28.166246 2026] [security2:error] [pid 230252:tid 230386] [client 62.102.148.164:43912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPyQAAAps"]
[Tue Jul 21 07:25:28.166321 2026] [security2:error] [pid 230252:tid 230386] [client 62.102.148.164:43912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPyQAAAps"]
[Tue Jul 21 07:25:28.508940 2026] [security2:error] [pid 230252:tid 230435] [client 154.192.233.199:59886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPzgAAAsw"]
[Tue Jul 21 07:25:28.509121 2026] [security2:error] [pid 230252:tid 230435] [client 154.192.233.199:59886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPzgAAAsw"]
[Tue Jul 21 07:25:28.574545 2026] [security2:error] [pid 230252:tid 230468] [client 20.226.60.151:56840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/database.php"] [unique_id "al9JGE0Dwhk5-Z44XrpPzwAAAu0"]
[Tue Jul 21 07:25:28.741330 2026] [security2:error] [pid 229246:tid 229450] [client 20.220.225.223:45991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/zzz.php"] [unique_id "al9JGCBMYeh5YLVG45x0kQAAAl4"]
[Tue Jul 21 07:25:28.747304 2026] [security2:error] [pid 229246:tid 229431] [client 20.151.10.161:49125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ops.php"] [unique_id "al9JGCBMYeh5YLVG45x0kgAAAks"]
[Tue Jul 21 07:25:29.194824 2026] [security2:error] [pid 229246:tid 229468] [client 109.248.148.246:59096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JGSBMYeh5YLVG45x0mAAAAnA"]
[Tue Jul 21 07:25:29.194957 2026] [security2:error] [pid 229246:tid 229468] [client 109.248.148.246:59096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JGSBMYeh5YLVG45x0mAAAAnA"]
[Tue Jul 21 07:25:29.577902 2026] [security2:error] [pid 229246:tid 229261] [remote 132.148.72.88:50676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinicius-schneider.com"] [uri "/wp-login.php"] [unique_id "al9JGSBMYeh5YLVG45x0ngACaw4"]
[Tue Jul 21 07:25:30.085189 2026] [security2:error] [pid 230252:tid 230456] [client 20.151.10.161:49138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ingfo.php"] [unique_id "al9JGk0Dwhk5-Z44XrpP3AAAAuE"]
[Tue Jul 21 07:25:30.104460 2026] [security2:error] [pid 229246:tid 229483] [client 20.151.10.161:26462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9JGiBMYeh5YLVG45x0pAAAAn8"]
[Tue Jul 21 07:25:30.255564 2026] [security2:error] [pid 229246:tid 229305] [remote 160.187.68.132:45798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "santotchay.com"] [uri "/wp-login.php"] [unique_id "al9JGiBMYeh5YLVG45x0pgAChzo"]
[Tue Jul 21 07:25:30.669685 2026] [security2:error] [pid 229246:tid 229470] [client 20.151.10.161:65479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9JGiBMYeh5YLVG45x0rQAAAnI"]
[Tue Jul 21 07:25:30.868870 2026] [security2:error] [pid 229246:tid 229452] [client 74.249.245.134:54359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/8.php"] [unique_id "al9JGiBMYeh5YLVG45x0rwAAAmA"]
[Tue Jul 21 07:25:30.876511 2026] [security2:error] [pid 229246:tid 229270] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JGiBMYeh5YLVG45x0sAACZhc"]
[Tue Jul 21 07:25:30.876631 2026] [security2:error] [pid 229246:tid 229458] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JGiBMYeh5YLVG45x0sAACZhc"]
[Tue Jul 21 07:25:31.140280 2026] [security2:error] [pid 230252:tid 230430] [client 139.135.44.145:53688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JG00Dwhk5-Z44XrpP6gAAAsc"]
[Tue Jul 21 07:25:31.140879 2026] [security2:error] [pid 230252:tid 230430] [client 139.135.44.145:53688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JG00Dwhk5-Z44XrpP6gAAAsc"]
[Tue Jul 21 07:25:31.270079 2026] [security2:error] [pid 230252:tid 230437] [client 136.144.33.106:61685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JG00Dwhk5-Z44XrpP6QAAAs4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:31.351491 2026] [core:error] [pid 230252:tid 230345] [remote 40.77.167.20:9761] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:25:31.351509 2026] [core:error] [pid 230252:tid 230345] [remote 40.77.167.20:9761] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:25:31.574148 2026] [security2:error] [pid 230252:tid 230496] [client 20.220.225.223:46130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wicked.php"] [unique_id "al9JG00Dwhk5-Z44XrpP7QAAAwk"]
[Tue Jul 21 07:25:31.595146 2026] [security2:error] [pid 229246:tid 229427] [client 20.151.10.161:49040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/error_log.php"] [unique_id "al9JGyBMYeh5YLVG45x0uwAAAkc"]
[Tue Jul 21 07:25:31.714438 2026] [security2:error] [pid 229246:tid 229356] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JGyBMYeh5YLVG45x0vAACK20"]
[Tue Jul 21 07:25:31.714639 2026] [security2:error] [pid 229246:tid 229399] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JGyBMYeh5YLVG45x0vAACK20"]
[Tue Jul 21 07:25:31.828736 2026] [security2:error] [pid 230252:tid 230438] [client 20.226.60.151:63340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/file.php"] [unique_id "al9JG00Dwhk5-Z44XrpP8QAAAs8"]
[Tue Jul 21 07:25:32.169901 2026] [security2:error] [pid 229246:tid 229415] [client 20.151.10.161:48594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/xenon1337.php"] [unique_id "al9JHCBMYeh5YLVG45x0wgAAAjs"]
[Tue Jul 21 07:25:32.437024 2026] [security2:error] [pid 229246:tid 229492] [client 103.162.129.114:57287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JHCBMYeh5YLVG45x0wwAAAog"]
[Tue Jul 21 07:25:32.437177 2026] [security2:error] [pid 229246:tid 229492] [client 103.162.129.114:57287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JHCBMYeh5YLVG45x0wwAAAog"]
[Tue Jul 21 07:25:32.685806 2026] [security2:error] [pid 229246:tid 229461] [client 20.151.10.161:26548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file.php"] [unique_id "al9JHCBMYeh5YLVG45x0xgAAAmk"]
[Tue Jul 21 07:25:32.798333 2026] [security2:error] [pid 229246:tid 229441] [client 74.249.245.134:54357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/ws38.php"] [unique_id "al9JHCBMYeh5YLVG45x0yAAAAlU"]
[Tue Jul 21 07:25:32.813691 2026] [security2:error] [pid 229246:tid 229490] [client 20.151.10.161:49075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/test11.php"] [unique_id "al9JHCBMYeh5YLVG45x0yQAAAoY"]
[Tue Jul 21 07:25:32.829663 2026] [security2:error] [pid 230252:tid 230401] [client 20.226.60.151:63307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/file.php"] [unique_id "al9JHE0Dwhk5-Z44XrpQBgAAAqo"]
[Tue Jul 21 07:25:33.122378 2026] [security2:error] [pid 229246:tid 229362] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JHSBMYeh5YLVG45x0zQACjXM"]
[Tue Jul 21 07:25:33.122524 2026] [security2:error] [pid 229246:tid 229497] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JHSBMYeh5YLVG45x0zQACjXM"]
[Tue Jul 21 07:25:33.239302 2026] [security2:error] [pid 230252:tid 230444] [client 62.102.148.164:43926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQDgAAAtU"]
[Tue Jul 21 07:25:33.239384 2026] [security2:error] [pid 230252:tid 230444] [client 62.102.148.164:43926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQDgAAAtU"]
[Tue Jul 21 07:25:33.262621 2026] [security2:error] [pid 229246:tid 229361] [remote 57.141.18.78:26390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9JGyBMYeh5YLVG45x0tQACNHI"]
[Tue Jul 21 07:25:33.391314 2026] [security2:error] [pid 230252:tid 230484] [client 20.226.60.151:63338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/777.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQFQAAAv0"]
[Tue Jul 21 07:25:33.406226 2026] [security2:error] [pid 230252:tid 230328] [remote 49.12.216.176:34622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limaradiologiadigital.com.br"] [uri "/wp-login.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQFgACpkk"]
[Tue Jul 21 07:25:33.408178 2026] [security2:error] [pid 230252:tid 230441] [client 117.251.86.144:45798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQFwAAAtI"]
[Tue Jul 21 07:25:33.408295 2026] [security2:error] [pid 230252:tid 230441] [client 117.251.86.144:45798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQFwAAAtI"]
[Tue Jul 21 07:25:33.414777 2026] [security2:error] [pid 230252:tid 230474] [client 20.151.10.161:49109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/koala.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQGAAAAvM"]
[Tue Jul 21 07:25:33.469758 2026] [proxy:error] [pid 229246:tid 229447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:33.469793 2026] [proxy_http:error] [pid 229246:tid 229447] [client 198.235.24.89:62214] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:33.470444 2026] [proxy:error] [pid 229246:tid 229447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:33.470471 2026] [proxy_http:error] [pid 229246:tid 229447] [client 198.235.24.89:62214] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:33.495791 2026] [security2:error] [pid 230252:tid 230388] [client 20.151.10.161:26348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/cfile.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQGQAAAp0"]
[Tue Jul 21 07:25:33.541421 2026] [security2:error] [pid 230252:tid 230479] [client 20.226.60.151:54546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9JHU0Dwhk5-Z44XrpQGgAAAvg"]
[Tue Jul 21 07:25:33.727704 2026] [security2:error] [pid 229246:tid 229462] [client 20.151.10.161:63057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9JHSBMYeh5YLVG45x00gAAAmo"]
[Tue Jul 21 07:25:33.893082 2026] [security2:error] [pid 229246:tid 229333] [remote 147.50.252.213:42154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JHSBMYeh5YLVG45x01AACTlY"]
[Tue Jul 21 07:25:34.112342 2026] [autoindex:error] [pid 230252:tid 230440] [client 40.223.127.214:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:25:34.280951 2026] [security2:error] [pid 230252:tid 230478] [client 20.151.10.161:26558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/class-wp.php"] [unique_id "al9JHk0Dwhk5-Z44XrpQKQAAAvc"]
[Tue Jul 21 07:25:34.365253 2026] [security2:error] [pid 230252:tid 230458] [client 20.226.60.151:56841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ssixta.php"] [unique_id "al9JHk0Dwhk5-Z44XrpQLAAAAuM"]
[Tue Jul 21 07:25:34.494429 2026] [security2:error] [pid 230252:tid 230352] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JHk0Dwhk5-Z44XrpQLgADD2E"]
[Tue Jul 21 07:25:34.494557 2026] [security2:error] [pid 230252:tid 230502] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JHk0Dwhk5-Z44XrpQLgADD2E"]
[Tue Jul 21 07:25:34.684457 2026] [security2:error] [pid 229246:tid 229400] [client 74.249.245.134:17435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/a7.php"] [unique_id "al9JHiBMYeh5YLVG45x02wAAAiw"]
[Tue Jul 21 07:25:34.830603 2026] [security2:error] [pid 230252:tid 230420] [client 20.151.10.161:48578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/mac.php"] [unique_id "al9JHk0Dwhk5-Z44XrpQNQAAAr0"]
[Tue Jul 21 07:25:34.934229 2026] [proxy:error] [pid 230252:tid 230488] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:34.934288 2026] [proxy_http:error] [pid 230252:tid 230488] [client 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:34.934883 2026] [proxy:error] [pid 230252:tid 230488] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:34.934909 2026] [proxy_http:error] [pid 230252:tid 230488] [client 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:35.002952 2026] [security2:error] [pid 230252:tid 230461] [client 209.141.34.121:49280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "patriciaressignificar.com.br"] [uri "/"] [unique_id "al9JH00Dwhk5-Z44XrpQOgAAAuY"]
[Tue Jul 21 07:25:35.010280 2026] [security2:error] [pid 230252:tid 230444] [client 20.151.10.161:26491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/admin.php"] [unique_id "al9JH00Dwhk5-Z44XrpQOwAAAtU"]
[Tue Jul 21 07:25:35.119053 2026] [security2:error] [pid 229246:tid 229457] [client 37.140.223.69:23707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JHyBMYeh5YLVG45x04gAAAmU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:35.371829 2026] [security2:error] [pid 229246:tid 229279] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JHyBMYeh5YLVG45x06AACPSA"]
[Tue Jul 21 07:25:35.372020 2026] [security2:error] [pid 229246:tid 229417] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JHyBMYeh5YLVG45x06AACPSA"]
[Tue Jul 21 07:25:35.514755 2026] [security2:error] [pid 229246:tid 229438] [client 209.141.34.121:49347] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "patriciaressignificar.com.br"] [uri "/"] [unique_id "al9JHyBMYeh5YLVG45x06QAAAlI"]
[Tue Jul 21 07:25:35.692993 2026] [security2:error] [pid 229246:tid 229389] [client 20.226.60.151:54497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9JHyBMYeh5YLVG45x06gAAAiE"]
[Tue Jul 21 07:25:35.850773 2026] [security2:error] [pid 229246:tid 229503] [client 20.226.60.151:56958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/1c.php"] [unique_id "al9JHyBMYeh5YLVG45x07wAAApM"]
[Tue Jul 21 07:25:35.949064 2026] [security2:error] [pid 230252:tid 230476] [client 74.249.245.134:5516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/classsmtps.php"] [unique_id "al9JH00Dwhk5-Z44XrpQRAAAAvU"]
[Tue Jul 21 07:25:36.083167 2026] [security2:error] [pid 230252:tid 230361] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JIE0Dwhk5-Z44XrpQRgACzmo"]
[Tue Jul 21 07:25:36.083308 2026] [security2:error] [pid 230252:tid 230437] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JIE0Dwhk5-Z44XrpQRgACzmo"]
[Tue Jul 21 07:25:36.306934 2026] [security2:error] [pid 230252:tid 230386] [client 20.226.60.151:56919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/test2.php"] [unique_id "al9JIE0Dwhk5-Z44XrpQSQAAAps"]
[Tue Jul 21 07:25:36.341835 2026] [proxy:error] [pid 229246:tid 229378] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:36.341910 2026] [proxy_http:error] [pid 229246:tid 229378] [client 20.151.10.161:65495] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:36.342616 2026] [proxy:error] [pid 229246:tid 229378] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:36.342653 2026] [proxy_http:error] [pid 229246:tid 229378] [client 20.151.10.161:65495] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:36.870012 2026] [security2:error] [pid 229246:tid 229495] [client 103.106.20.201:61276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JICBMYeh5YLVG45x0-wAAAos"]
[Tue Jul 21 07:25:36.870160 2026] [security2:error] [pid 229246:tid 229495] [client 103.106.20.201:61276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JICBMYeh5YLVG45x0-wAAAos"]
[Tue Jul 21 07:25:36.942939 2026] [security2:error] [pid 229246:tid 229466] [client 74.249.245.134:5532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/rip.php"] [unique_id "al9JICBMYeh5YLVG45x0_AAAAm4"]
[Tue Jul 21 07:25:37.207907 2026] [security2:error] [pid 230252:tid 230494] [client 103.174.34.15:58327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JIU0Dwhk5-Z44XrpQUQAAAwc"]
[Tue Jul 21 07:25:37.208035 2026] [security2:error] [pid 230252:tid 230494] [client 103.174.34.15:58327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JIU0Dwhk5-Z44XrpQUQAAAwc"]
[Tue Jul 21 07:25:37.565416 2026] [security2:error] [pid 230252:tid 230302] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JIU0Dwhk5-Z44XrpQVAACpTA"]
[Tue Jul 21 07:25:37.565554 2026] [security2:error] [pid 230252:tid 230396] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JIU0Dwhk5-Z44XrpQVAACpTA"]
[Tue Jul 21 07:25:37.588784 2026] [security2:error] [pid 229246:tid 229500] [client 45.251.232.145:61841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JISBMYeh5YLVG45x1CAAAApA"]
[Tue Jul 21 07:25:37.588889 2026] [security2:error] [pid 229246:tid 229500] [client 45.251.232.145:61841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JISBMYeh5YLVG45x1CAAAApA"]
[Tue Jul 21 07:25:37.610936 2026] [security2:error] [pid 229246:tid 229425] [client 20.226.60.151:56855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/buy.php"] [unique_id "al9JISBMYeh5YLVG45x1CQAAAkU"]
[Tue Jul 21 07:25:37.626191 2026] [security2:error] [pid 230252:tid 230397] [client 59.96.220.140:60011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JIU0Dwhk5-Z44XrpQVgAAAqY"]
[Tue Jul 21 07:25:37.626404 2026] [security2:error] [pid 230252:tid 230397] [client 59.96.220.140:60011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JIU0Dwhk5-Z44XrpQVgAAAqY"]
[Tue Jul 21 07:25:37.951704 2026] [security2:error] [pid 230252:tid 230438] [client 173.239.214.239:28185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.214.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dener.design"] [uri "/wp-login.php"] [unique_id "al9JIE0Dwhk5-Z44XrpQTQAAAs8"]
[Tue Jul 21 07:25:38.198375 2026] [security2:error] [pid 229246:tid 229308] [remote 41.186.86.12:62680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/xmlrpc.php"] [unique_id "al9JIiBMYeh5YLVG45x1DwACRj0"]
[Tue Jul 21 07:25:38.198513 2026] [security2:error] [pid 229246:tid 229426] [client 41.186.86.12:62680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "supremaservices.net"] [uri "/xmlrpc.php"] [unique_id "al9JIiBMYeh5YLVG45x1DwACRj0"]
[Tue Jul 21 07:25:38.400613 2026] [security2:error] [pid 230252:tid 230505] [client 175.45.70.82:64965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JIk0Dwhk5-Z44XrpQZQAAAxI"]
[Tue Jul 21 07:25:38.400759 2026] [security2:error] [pid 230252:tid 230505] [client 175.45.70.82:64965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JIk0Dwhk5-Z44XrpQZQAAAxI"]
[Tue Jul 21 07:25:38.425716 2026] [security2:error] [pid 229246:tid 229454] [client 20.151.10.161:63671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/simple.php"] [unique_id "al9JIiBMYeh5YLVG45x1FQAAAmI"]
[Tue Jul 21 07:25:38.559770 2026] [security2:error] [pid 229246:tid 229400] [client 74.249.245.134:17416] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/1.php"] [unique_id "al9JIiBMYeh5YLVG45x1FwAAAiw"]
[Tue Jul 21 07:25:38.559935 2026] [security2:error] [pid 229246:tid 229400] [client 74.249.245.134:17416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/1.php"] [unique_id "al9JIiBMYeh5YLVG45x1FwAAAiw"]
[Tue Jul 21 07:25:38.567521 2026] [security2:error] [pid 230252:tid 230497] [client 20.151.10.161:49107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9JIk0Dwhk5-Z44XrpQZgAAAwo"]
[Tue Jul 21 07:25:38.665741 2026] [security2:error] [pid 229246:tid 229286] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JIiBMYeh5YLVG45x1GQACayc"]
[Tue Jul 21 07:25:38.665914 2026] [security2:error] [pid 229246:tid 229463] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JIiBMYeh5YLVG45x1GQACayc"]
[Tue Jul 21 07:25:39.253484 2026] [security2:error] [pid 229246:tid 229282] [remote 41.186.86.12:2188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-login.php"] [unique_id "al9JIyBMYeh5YLVG45x1HQACiSM"]
[Tue Jul 21 07:25:39.379883 2026] [security2:error] [pid 230252:tid 230450] [client 20.226.60.151:63309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ssend.php"] [unique_id "al9JI00Dwhk5-Z44XrpQbAAAAts"]
[Tue Jul 21 07:25:39.610315 2026] [security2:error] [pid 229246:tid 229405] [client 20.226.60.151:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9JIyBMYeh5YLVG45x1IAAAAjE"]
[Tue Jul 21 07:25:39.731403 2026] [security2:error] [pid 229246:tid 229446] [client 87.58.197.194:54970] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.63.71"] [uri "/.env"] [unique_id "al9JIyBMYeh5YLVG45x1IgAAAlo"]
[Tue Jul 21 07:25:40.160990 2026] [security2:error] [pid 230252:tid 230487] [client 20.151.10.161:49136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wefile.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQgAAAAwA"]
[Tue Jul 21 07:25:40.282722 2026] [security2:error] [pid 230252:tid 230398] [client 154.192.233.199:58924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQgQAAAqc"]
[Tue Jul 21 07:25:40.282857 2026] [security2:error] [pid 230252:tid 230398] [client 154.192.233.199:58924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQgQAAAqc"]
[Tue Jul 21 07:25:40.372640 2026] [security2:error] [pid 230252:tid 230413] [client 193.36.225.10:36559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQhAAAArY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:40.403902 2026] [security2:error] [pid 230252:tid 230410] [client 20.151.10.161:63634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/xxx.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQhgAAArM"]
[Tue Jul 21 07:25:40.641926 2026] [security2:error] [pid 230252:tid 230488] [client 20.151.10.161:26406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/aa2.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQjgAAAwE"]
[Tue Jul 21 07:25:40.653154 2026] [security2:error] [pid 230252:tid 230461] [client 74.249.245.134:54374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/chosen.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQjwAAAuY"]
[Tue Jul 21 07:25:40.767076 2026] [security2:error] [pid 229246:tid 229501] [client 45.8.19.158:24349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9JJCBMYeh5YLVG45x1KgAAApE"]
[Tue Jul 21 07:25:40.769882 2026] [security2:error] [pid 230252:tid 230429] [client 45.8.19.188:59571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQkAAAAsY"]
[Tue Jul 21 07:25:40.972270 2026] [security2:error] [pid 230252:tid 230426] [client 20.226.60.151:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/item.php"] [unique_id "al9JJE0Dwhk5-Z44XrpQlAAAAsM"]
[Tue Jul 21 07:25:41.369687 2026] [security2:error] [pid 230252:tid 230329] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JJU0Dwhk5-Z44XrpQlgADBEo"]
[Tue Jul 21 07:25:41.369890 2026] [security2:error] [pid 230252:tid 230491] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JJU0Dwhk5-Z44XrpQlgADBEo"]
[Tue Jul 21 07:25:41.972598 2026] [security2:error] [pid 230252:tid 230493] [client 117.195.76.197:64208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.76.195.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grupogradiente.com"] [uri "/xmlrpc.php"] [unique_id "al9JI00Dwhk5-Z44XrpQeAAAAwY"]
[Tue Jul 21 07:25:41.972772 2026] [security2:error] [pid 230252:tid 230493] [client 117.195.76.197:64208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grupogradiente.com"] [uri "/xmlrpc.php"] [unique_id "al9JI00Dwhk5-Z44XrpQeAAAAwY"]
[Tue Jul 21 07:25:42.075742 2026] [security2:error] [pid 229246:tid 229440] [client 20.226.60.151:56945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ss.php"] [unique_id "al9JJiBMYeh5YLVG45x1OgAAAlQ"]
[Tue Jul 21 07:25:42.220026 2026] [security2:error] [pid 230252:tid 230336] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJk0Dwhk5-Z44XrpQoQACsVE"]
[Tue Jul 21 07:25:42.220210 2026] [security2:error] [pid 230252:tid 230408] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJk0Dwhk5-Z44XrpQoQACsVE"]
[Tue Jul 21 07:25:42.306661 2026] [security2:error] [pid 229246:tid 229415] [client 74.249.245.134:17464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/css.php"] [unique_id "al9JJiBMYeh5YLVG45x1PwAAAjs"]
[Tue Jul 21 07:25:42.367548 2026] [security2:error] [pid 229246:tid 229448] [client 20.151.10.161:65474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/hypo.php"] [unique_id "al9JJiBMYeh5YLVG45x1QAAAAlw"]
[Tue Jul 21 07:25:42.519625 2026] [security2:error] [pid 230252:tid 230496] [client 139.135.44.145:54558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JJk0Dwhk5-Z44XrpQrQAAAwk"]
[Tue Jul 21 07:25:42.519757 2026] [security2:error] [pid 230252:tid 230496] [client 139.135.44.145:54558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JJk0Dwhk5-Z44XrpQrQAAAwk"]
[Tue Jul 21 07:25:42.818095 2026] [security2:error] [pid 230252:tid 230410] [client 74.7.241.178:42894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.cownnex.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9JJk0Dwhk5-Z44XrpQrwACszQ"]
[Tue Jul 21 07:25:42.846461 2026] [proxy:error] [pid 230252:tid 230394] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:42.846537 2026] [proxy_http:error] [pid 230252:tid 230394] [client 20.151.10.161:49110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:42.847110 2026] [proxy:error] [pid 230252:tid 230394] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:42.847147 2026] [proxy_http:error] [pid 230252:tid 230394] [client 20.151.10.161:49110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:42.926552 2026] [security2:error] [pid 230252:tid 230434] [client 103.162.129.114:57801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JJk0Dwhk5-Z44XrpQsgAAAss"]
[Tue Jul 21 07:25:42.926711 2026] [security2:error] [pid 230252:tid 230434] [client 103.162.129.114:57801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JJk0Dwhk5-Z44XrpQsgAAAss"]
[Tue Jul 21 07:25:42.977684 2026] [security2:error] [pid 230252:tid 230403] [client 20.226.60.151:63330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/hypo.php"] [unique_id "al9JJk0Dwhk5-Z44XrpQswAAAqw"]
[Tue Jul 21 07:25:43.231166 2026] [security2:error] [pid 229246:tid 229264] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JJyBMYeh5YLVG45x1TAACSxE"]
[Tue Jul 21 07:25:43.247770 2026] [security2:error] [pid 229246:tid 229330] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9JJyBMYeh5YLVG45x1TQACalM"]
[Tue Jul 21 07:25:43.262844 2026] [security2:error] [pid 229246:tid 229304] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/sql.php"] [unique_id "al9JJyBMYeh5YLVG45x1TgACIzk"]
[Tue Jul 21 07:25:43.303435 2026] [security2:error] [pid 229246:tid 229256] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/1index.php"] [unique_id "al9JJyBMYeh5YLVG45x1TwACcwk"]
[Tue Jul 21 07:25:43.319922 2026] [security2:error] [pid 229246:tid 229310] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/reop1.php"] [unique_id "al9JJyBMYeh5YLVG45x1UAACNz8"]
[Tue Jul 21 07:25:43.328512 2026] [autoindex:error] [pid 229246:tid 229324] [remote 74.7.242.62:35738] AH01276: Cannot serve directory /home2/luc15241/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:25:43.335560 2026] [security2:error] [pid 229246:tid 229352] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/trusj18.php"] [unique_id "al9JJyBMYeh5YLVG45x1UgACRmk"]
[Tue Jul 21 07:25:43.350494 2026] [security2:error] [pid 229246:tid 229360] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/trusj15.php"] [unique_id "al9JJyBMYeh5YLVG45x1UwACGnE"]
[Tue Jul 21 07:25:43.367173 2026] [security2:error] [pid 229246:tid 229299] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/rft8.php"] [unique_id "al9JJyBMYeh5YLVG45x1VAACcTQ"]
[Tue Jul 21 07:25:43.381724 2026] [security2:error] [pid 229246:tid 229326] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ai.php"] [unique_id "al9JJyBMYeh5YLVG45x1VQACcE8"]
[Tue Jul 21 07:25:43.438822 2026] [security2:error] [pid 229246:tid 229284] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/fx.php"] [unique_id "al9JJyBMYeh5YLVG45x1VgACTiU"]
[Tue Jul 21 07:25:43.486991 2026] [security2:error] [pid 229246:tid 229328] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/xxx.php"] [unique_id "al9JJyBMYeh5YLVG45x1WAACj1E"]
[Tue Jul 21 07:25:43.495230 2026] [security2:error] [pid 229246:tid 229400] [client 20.226.60.151:56859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/users.php"] [unique_id "al9JJyBMYeh5YLVG45x1WQAAAiw"]
[Tue Jul 21 07:25:43.522137 2026] [security2:error] [pid 229246:tid 229314] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/dropdown.php"] [unique_id "al9JJyBMYeh5YLVG45x1WgACJEM"]
[Tue Jul 21 07:25:43.537204 2026] [security2:error] [pid 229246:tid 229247] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/file11.php"] [unique_id "al9JJyBMYeh5YLVG45x1WwACLwA"]
[Tue Jul 21 07:25:43.553052 2026] [security2:error] [pid 229246:tid 229277] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/png.php"] [unique_id "al9JJyBMYeh5YLVG45x1XAACax4"]
[Tue Jul 21 07:25:43.567916 2026] [security2:error] [pid 229246:tid 229312] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-slss.php"] [unique_id "al9JJyBMYeh5YLVG45x1XQACSEE"]
[Tue Jul 21 07:25:43.582160 2026] [security2:error] [pid 229246:tid 229327] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ah25.php"] [unique_id "al9JJyBMYeh5YLVG45x1XgACGVA"]
[Tue Jul 21 07:25:43.597085 2026] [security2:error] [pid 229246:tid 229261] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ccou.php"] [unique_id "al9JJyBMYeh5YLVG45x1XwACjA4"]
[Tue Jul 21 07:25:43.632690 2026] [security2:error] [pid 229246:tid 229378] [client 87.58.197.194:34862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.63.71"] [uri "/.env"] [unique_id "al9JJyBMYeh5YLVG45x1YwAAAhY"]
[Tue Jul 21 07:25:43.640826 2026] [security2:error] [pid 229246:tid 229265] [remote 20.206.67.15:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/1.php"] [unique_id "al9JJyBMYeh5YLVG45x1ZAACWBI"]
[Tue Jul 21 07:25:43.640904 2026] [security2:error] [pid 229246:tid 229265] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/1.php"] [unique_id "al9JJyBMYeh5YLVG45x1ZAACWBI"]
[Tue Jul 21 07:25:43.674471 2026] [security2:error] [pid 229246:tid 229350] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/900.php"] [unique_id "al9JJyBMYeh5YLVG45x1ZgACfGc"]
[Tue Jul 21 07:25:43.679605 2026] [security2:error] [pid 229246:tid 229305] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJyBMYeh5YLVG45x1ZwACdzo"]
[Tue Jul 21 07:25:43.679714 2026] [security2:error] [pid 229246:tid 229475] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJyBMYeh5YLVG45x1ZwACdzo"]
[Tue Jul 21 07:25:43.689147 2026] [security2:error] [pid 229246:tid 229266] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/file59.php"] [unique_id "al9JJyBMYeh5YLVG45x1aAACVhM"]
[Tue Jul 21 07:25:43.754662 2026] [security2:error] [pid 229246:tid 229251] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/amxloxxr.php"] [unique_id "al9JJyBMYeh5YLVG45x1aQACFQQ"]
[Tue Jul 21 07:25:43.812408 2026] [security2:error] [pid 229246:tid 229302] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/aboutc.php"] [unique_id "al9JJyBMYeh5YLVG45x1agAChzc"]
[Tue Jul 21 07:25:43.827320 2026] [security2:error] [pid 229246:tid 229303] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/bless18.php"] [unique_id "al9JJyBMYeh5YLVG45x1awACMTg"]
[Tue Jul 21 07:25:43.841648 2026] [security2:error] [pid 229246:tid 229270] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/crgio.php"] [unique_id "al9JJyBMYeh5YLVG45x1bAACPhc"]
[Tue Jul 21 07:25:43.856267 2026] [security2:error] [pid 229246:tid 229309] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-act.php"] [unique_id "al9JJyBMYeh5YLVG45x1bQACPT4"]
[Tue Jul 21 07:25:43.875826 2026] [security2:error] [pid 229246:tid 229294] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/new4.php"] [unique_id "al9JJyBMYeh5YLVG45x1bwACfy8"]
[Tue Jul 21 07:25:43.891242 2026] [security2:error] [pid 229246:tid 229257] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-the.php"] [unique_id "al9JJyBMYeh5YLVG45x1cQACewo"]
[Tue Jul 21 07:25:43.891737 2026] [security2:error] [pid 229246:tid 229484] [client 117.195.76.197:64248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.76.195.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grupogradiente.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJyBMYeh5YLVG45x1cgAAAoA"]
[Tue Jul 21 07:25:43.891846 2026] [security2:error] [pid 229246:tid 229484] [client 117.195.76.197:64248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grupogradiente.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JJyBMYeh5YLVG45x1cgAAAoA"]
[Tue Jul 21 07:25:43.909370 2026] [security2:error] [pid 229246:tid 229351] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/atkno.php"] [unique_id "al9JJyBMYeh5YLVG45x1cwACgmg"]
[Tue Jul 21 07:25:43.932660 2026] [security2:error] [pid 229246:tid 229339] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/mass.php"] [unique_id "al9JJyBMYeh5YLVG45x1dAACOFw"]
[Tue Jul 21 07:25:43.966564 2026] [security2:error] [pid 230252:tid 230474] [client 20.226.60.151:56932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/177.php"] [unique_id "al9JJ00Dwhk5-Z44XrpQwwAAAvM"]
[Tue Jul 21 07:25:43.972568 2026] [security2:error] [pid 229246:tid 229356] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wefile.php"] [unique_id "al9JJyBMYeh5YLVG45x1dQACKm0"]
[Tue Jul 21 07:25:43.993202 2026] [security2:error] [pid 229246:tid 229319] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/min.php"] [unique_id "al9JJyBMYeh5YLVG45x1dgACF0g"]
[Tue Jul 21 07:25:44.059672 2026] [security2:error] [pid 229246:tid 229357] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/sid3.php"] [unique_id "al9JKCBMYeh5YLVG45x1dwACdm4"]
[Tue Jul 21 07:25:44.074351 2026] [security2:error] [pid 229246:tid 229274] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/fileas.php"] [unique_id "al9JKCBMYeh5YLVG45x1eAACFBs"]
[Tue Jul 21 07:25:44.092141 2026] [security2:error] [pid 229246:tid 229342] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/bless24.php"] [unique_id "al9JKCBMYeh5YLVG45x1eQACIV8"]
[Tue Jul 21 07:25:44.116651 2026] [security2:error] [pid 229246:tid 229363] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/fun.php"] [unique_id "al9JKCBMYeh5YLVG45x1egACkXQ"]
[Tue Jul 21 07:25:44.141652 2026] [security2:error] [pid 229246:tid 229307] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/drykl.php"] [unique_id "al9JKCBMYeh5YLVG45x1fQACYDw"]
[Tue Jul 21 07:25:44.159726 2026] [security2:error] [pid 229246:tid 229354] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al9JKCBMYeh5YLVG45x1fgAChWs"]
[Tue Jul 21 07:25:44.173444 2026] [security2:error] [pid 229246:tid 229298] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/mifta.php"] [unique_id "al9JKCBMYeh5YLVG45x1gAACVzM"]
[Tue Jul 21 07:25:44.209896 2026] [security2:error] [pid 229246:tid 229329] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/class-t.api.php"] [unique_id "al9JKCBMYeh5YLVG45x1gQACQ1I"]
[Tue Jul 21 07:25:44.247204 2026] [proxy:error] [pid 230252:tid 230402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:44.247266 2026] [proxy_http:error] [pid 230252:tid 230402] [client 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:44.247899 2026] [proxy:error] [pid 230252:tid 230402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:44.247932 2026] [proxy_http:error] [pid 230252:tid 230402] [client 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:44.251805 2026] [security2:error] [pid 229246:tid 229503] [client 62.102.148.164:46774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JKCBMYeh5YLVG45x1hQAAApM"]
[Tue Jul 21 07:25:44.251913 2026] [security2:error] [pid 229246:tid 229503] [client 62.102.148.164:46774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JKCBMYeh5YLVG45x1hQAAApM"]
[Tue Jul 21 07:25:44.288282 2026] [security2:error] [pid 230252:tid 230444] [client 117.251.86.144:40300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JKE0Dwhk5-Z44XrpQzQAAAtU"]
[Tue Jul 21 07:25:44.288404 2026] [security2:error] [pid 230252:tid 230444] [client 117.251.86.144:40300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JKE0Dwhk5-Z44XrpQzQAAAtU"]
[Tue Jul 21 07:25:44.309979 2026] [security2:error] [pid 229246:tid 229315] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/vgtyu.php"] [unique_id "al9JKCBMYeh5YLVG45x1iAACR0Q"]
[Tue Jul 21 07:25:44.365836 2026] [security2:error] [pid 229246:tid 229333] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/atomlib.php"] [unique_id "al9JKCBMYeh5YLVG45x1igACY1Y"]
[Tue Jul 21 07:25:44.398131 2026] [security2:error] [pid 229246:tid 229295] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-access.php"] [unique_id "al9JKCBMYeh5YLVG45x1iwACSjA"]
[Tue Jul 21 07:25:44.417181 2026] [security2:error] [pid 229246:tid 229281] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-update.php"] [unique_id "al9JKCBMYeh5YLVG45x1jAACLiI"]
[Tue Jul 21 07:25:44.450000 2026] [security2:error] [pid 230252:tid 230378] [remote 64.225.121.94:59642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9JKE0Dwhk5-Z44XrpQ0QACsns"]
[Tue Jul 21 07:25:44.451988 2026] [security2:error] [pid 229246:tid 229287] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/erty.php"] [unique_id "al9JKCBMYeh5YLVG45x1jgACSSg"]
[Tue Jul 21 07:25:44.485939 2026] [proxy:error] [pid 229246:tid 229436] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:44.486015 2026] [proxy_http:error] [pid 229246:tid 229436] [client 20.151.10.161:63632] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:44.486769 2026] [proxy:error] [pid 229246:tid 229436] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:44.486810 2026] [proxy_http:error] [pid 229246:tid 229436] [client 20.151.10.161:63632] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:44.493531 2026] [security2:error] [pid 229246:tid 229332] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al9JKCBMYeh5YLVG45x1kAACi1U"]
[Tue Jul 21 07:25:44.508527 2026] [security2:error] [pid 229246:tid 229368] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/like.php"] [unique_id "al9JKCBMYeh5YLVG45x1kwACO3k"]
[Tue Jul 21 07:25:44.512364 2026] [security2:error] [pid 230252:tid 230500] [client 20.226.60.151:54536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/albin.php"] [unique_id "al9JKE0Dwhk5-Z44XrpQ0wAAAw0"]
[Tue Jul 21 07:25:44.535676 2026] [security2:error] [pid 229246:tid 229340] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/bless5.php"] [unique_id "al9JKCBMYeh5YLVG45x1lQACXF0"]
[Tue Jul 21 07:25:44.592887 2026] [security2:error] [pid 229246:tid 229347] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/t.php"] [unique_id "al9JKCBMYeh5YLVG45x1lgACiGQ"]
[Tue Jul 21 07:25:44.608273 2026] [security2:error] [pid 229246:tid 229271] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/xoot.php"] [unique_id "al9JKCBMYeh5YLVG45x1lwACOhg"]
[Tue Jul 21 07:25:44.622725 2026] [security2:error] [pid 229246:tid 229276] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/xqq.php"] [unique_id "al9JKCBMYeh5YLVG45x1mAACdR0"]
[Tue Jul 21 07:25:44.636863 2026] [security2:error] [pid 229246:tid 229373] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-load.php"] [unique_id "al9JKCBMYeh5YLVG45x1mQACQH4"]
[Tue Jul 21 07:25:44.651700 2026] [security2:error] [pid 229246:tid 229292] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/x.php"] [unique_id "al9JKCBMYeh5YLVG45x1mgACPC0"]
[Tue Jul 21 07:25:44.669277 2026] [security2:error] [pid 229246:tid 229279] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/i.php"] [unique_id "al9JKCBMYeh5YLVG45x1mwACaSA"]
[Tue Jul 21 07:25:44.679288 2026] [security2:error] [pid 230252:tid 230506] [client 74.249.245.134:5528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/php.php"] [unique_id "al9JKE0Dwhk5-Z44XrpQ1QAAAxM"]
[Tue Jul 21 07:25:44.725754 2026] [security2:error] [pid 229246:tid 229365] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ms-edit.php"] [unique_id "al9JKCBMYeh5YLVG45x1oAACkHY"]
[Tue Jul 21 07:25:44.742095 2026] [security2:error] [pid 229246:tid 229341] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/v2.php"] [unique_id "al9JKCBMYeh5YLVG45x1oQACNF4"]
[Tue Jul 21 07:25:44.758058 2026] [security2:error] [pid 229246:tid 229258] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/new.php"] [unique_id "al9JKCBMYeh5YLVG45x1ogACSws"]
[Tue Jul 21 07:25:44.779578 2026] [security2:error] [pid 229246:tid 229493] [client 152.59.154.239:63189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JKCBMYeh5YLVG45x1nwAAAok"]
[Tue Jul 21 07:25:44.808630 2026] [security2:error] [pid 229246:tid 229306] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-admin/network/edit.php"] [unique_id "al9JKCBMYeh5YLVG45x1pAACWzs"]
[Tue Jul 21 07:25:44.816532 2026] [security2:error] [pid 230252:tid 230422] [client 20.226.60.151:62357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/config.php"] [unique_id "al9JKE0Dwhk5-Z44XrpQ2wAAAr8"]
[Tue Jul 21 07:25:44.840136 2026] [security2:error] [pid 229246:tid 229323] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/pouhg.php"] [unique_id "al9JKCBMYeh5YLVG45x1pQACakw"]
[Tue Jul 21 07:25:44.854921 2026] [security2:error] [pid 229246:tid 229369] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/cilus.php"] [unique_id "al9JKCBMYeh5YLVG45x1pwACRXo"]
[Tue Jul 21 07:25:44.953265 2026] [security2:error] [pid 229246:tid 229300] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/file4.php"] [unique_id "al9JKCBMYeh5YLVG45x1qAACNzU"]
[Tue Jul 21 07:25:44.984437 2026] [security2:error] [pid 229246:tid 229349] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/samll.php"] [unique_id "al9JKCBMYeh5YLVG45x1qQACQWY"]
[Tue Jul 21 07:25:45.034596 2026] [security2:error] [pid 229246:tid 229290] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/Okxob.php"] [unique_id "al9JKSBMYeh5YLVG45x1qwACMis"]
[Tue Jul 21 07:25:45.076063 2026] [security2:error] [pid 229246:tid 229331] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JKSBMYeh5YLVG45x1rQACc1Q"]
[Tue Jul 21 07:25:45.076249 2026] [security2:error] [pid 229246:tid 229471] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JKSBMYeh5YLVG45x1rQACc1Q"]
[Tue Jul 21 07:25:45.139371 2026] [security2:error] [pid 229246:tid 229275] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ok.php"] [unique_id "al9JKSBMYeh5YLVG45x1rgACjRw"]
[Tue Jul 21 07:25:45.154549 2026] [security2:error] [pid 229246:tid 229308] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wuasr.php"] [unique_id "al9JKSBMYeh5YLVG45x1rwACKT0"]
[Tue Jul 21 07:25:45.169279 2026] [security2:error] [pid 229246:tid 229249] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/bless11.php"] [unique_id "al9JKSBMYeh5YLVG45x1sQACGgI"]
[Tue Jul 21 07:25:45.216339 2026] [security2:error] [pid 229246:tid 229269] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-block.php"] [unique_id "al9JKSBMYeh5YLVG45x1tAACYhY"]
[Tue Jul 21 07:25:45.245215 2026] [security2:error] [pid 229246:tid 229272] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/aevly.php"] [unique_id "al9JKSBMYeh5YLVG45x1tgACaxk"]
[Tue Jul 21 07:25:45.271824 2026] [security2:error] [pid 229246:tid 229248] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/hello.php"] [unique_id "al9JKSBMYeh5YLVG45x1twACjAE"]
[Tue Jul 21 07:25:45.282684 2026] [security2:error] [pid 229246:tid 229378] [client 20.226.60.151:56843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/gettest.php"] [unique_id "al9JKSBMYeh5YLVG45x1uAAAAhY"]
[Tue Jul 21 07:25:45.325589 2026] [security2:error] [pid 229246:tid 229286] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-links-opml.php"] [unique_id "al9JKSBMYeh5YLVG45x1uQACWSc"]
[Tue Jul 21 07:25:45.346528 2026] [security2:error] [pid 229246:tid 229285] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/forbidals.php"] [unique_id "al9JKSBMYeh5YLVG45x1ugACVSY"]
[Tue Jul 21 07:25:45.363233 2026] [security2:error] [pid 229246:tid 229336] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/file30.php"] [unique_id "al9JKSBMYeh5YLVG45x1uwACZVk"]
[Tue Jul 21 07:25:45.377760 2026] [security2:error] [pid 229246:tid 229337] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/xda.php"] [unique_id "al9JKSBMYeh5YLVG45x1vAACfFo"]
[Tue Jul 21 07:25:45.390776 2026] [security2:error] [pid 230252:tid 230511] [client 34.148.166.21:50952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.166.148.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lp.oticapersona.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JKU0Dwhk5-Z44XrpQ5AAAAxg"]
[Tue Jul 21 07:25:45.390899 2026] [security2:error] [pid 230252:tid 230511] [client 34.148.166.21:50952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lp.oticapersona.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JKU0Dwhk5-Z44XrpQ5AAAAxg"]
[Tue Jul 21 07:25:45.393001 2026] [security2:error] [pid 229246:tid 229282] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/z.php"] [unique_id "al9JKSBMYeh5YLVG45x1vQACdyM"]
[Tue Jul 21 07:25:45.409534 2026] [security2:error] [pid 229246:tid 229263] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/b.php"] [unique_id "al9JKSBMYeh5YLVG45x1vgACVhA"]
[Tue Jul 21 07:25:45.425254 2026] [security2:error] [pid 229246:tid 229353] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/edit.php"] [unique_id "al9JKSBMYeh5YLVG45x1vwACbWo"]
[Tue Jul 21 07:25:45.460174 2026] [security2:error] [pid 229246:tid 229293] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/app.php"] [unique_id "al9JKSBMYeh5YLVG45x1wAACgS4"]
[Tue Jul 21 07:25:45.467788 2026] [security2:error] [pid 230252:tid 230417] [client 74.7.228.53:53696] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.emulti.agendaclique.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9JKU0Dwhk5-Z44XrpQ5gACumU"]
[Tue Jul 21 07:25:45.470112 2026] [proxy:error] [pid 230252:tid 230472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:45.470155 2026] [proxy_http:error] [pid 230252:tid 230472] [client 20.151.10.161:49035] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:45.470704 2026] [proxy:error] [pid 230252:tid 230472] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:45.470726 2026] [proxy_http:error] [pid 230252:tid 230472] [client 20.151.10.161:49035] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:45.499493 2026] [security2:error] [pid 229246:tid 229289] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-png.php"] [unique_id "al9JKSBMYeh5YLVG45x1wgACeio"]
[Tue Jul 21 07:25:45.516787 2026] [security2:error] [pid 230252:tid 230478] [client 20.151.10.161:63723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/chosen.php"] [unique_id "al9JKU0Dwhk5-Z44XrpQ6AAAAvc"]
[Tue Jul 21 07:25:45.517591 2026] [security2:error] [pid 229246:tid 229317] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/lib.php"] [unique_id "al9JKSBMYeh5YLVG45x1wwACh0Y"]
[Tue Jul 21 07:25:45.532375 2026] [security2:error] [pid 229246:tid 229316] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/sys.php"] [unique_id "al9JKSBMYeh5YLVG45x1xQACMUU"]
[Tue Jul 21 07:25:45.549225 2026] [security2:error] [pid 229246:tid 229288] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/la.php"] [unique_id "al9JKSBMYeh5YLVG45x1xwACWik"]
[Tue Jul 21 07:25:45.550568 2026] [security2:error] [pid 229246:tid 229364] [remote 68.178.160.25:53398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wp-login.php"] [unique_id "al9JKSBMYeh5YLVG45x1xgACdHU"]
[Tue Jul 21 07:25:45.615543 2026] [security2:error] [pid 229246:tid 229370] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/tires.php"] [unique_id "al9JKSBMYeh5YLVG45x1yAACXXs"]
[Tue Jul 21 07:25:45.729545 2026] [security2:error] [pid 229246:tid 229321] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/lv.php"] [unique_id "al9JKSBMYeh5YLVG45x1ygACPUo"]
[Tue Jul 21 07:25:45.769000 2026] [security2:error] [pid 229246:tid 229344] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/myfile.php"] [unique_id "al9JKSBMYeh5YLVG45x1zAACf2E"]
[Tue Jul 21 07:25:45.783873 2026] [security2:error] [pid 229246:tid 229479] [client 82.102.28.107:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JKSBMYeh5YLVG45x1zQAAAns"]
[Tue Jul 21 07:25:45.783976 2026] [security2:error] [pid 229246:tid 229479] [client 82.102.28.107:53186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JKSBMYeh5YLVG45x1zQAAAns"]
[Tue Jul 21 07:25:45.795894 2026] [security2:error] [pid 229246:tid 229260] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/06.php"] [unique_id "al9JKSBMYeh5YLVG45x1zgACgA0"]
[Tue Jul 21 07:25:45.820242 2026] [security2:error] [pid 229246:tid 229366] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/fs.php"] [unique_id "al9JKSBMYeh5YLVG45x1zwACHHc"]
[Tue Jul 21 07:25:45.835589 2026] [security2:error] [pid 229246:tid 229325] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/asasx.php"] [unique_id "al9JKSBMYeh5YLVG45x10AACgk4"]
[Tue Jul 21 07:25:45.859960 2026] [security2:error] [pid 229246:tid 229268] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-kd4xalrg7m.php"] [unique_id "al9JKSBMYeh5YLVG45x10QACRBU"]
[Tue Jul 21 07:25:45.884157 2026] [security2:error] [pid 229246:tid 229311] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-good.php"] [unique_id "al9JKSBMYeh5YLVG45x10gACKEA"]
[Tue Jul 21 07:25:45.899006 2026] [security2:error] [pid 229246:tid 229338] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/scxy.php"] [unique_id "al9JKSBMYeh5YLVG45x10wACOFs"]
[Tue Jul 21 07:25:45.940917 2026] [security2:error] [pid 229246:tid 229346] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wmore1.php"] [unique_id "al9JKSBMYeh5YLVG45x11AACKmM"]
[Tue Jul 21 07:25:45.944482 2026] [security2:error] [pid 230252:tid 230254] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JKU0Dwhk5-Z44XrpQ7gACrAA"]
[Tue Jul 21 07:25:45.944589 2026] [security2:error] [pid 230252:tid 230403] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JKU0Dwhk5-Z44XrpQ7gACrAA"]
[Tue Jul 21 07:25:45.954937 2026] [security2:error] [pid 229246:tid 229374] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/like.php"] [unique_id "al9JKSBMYeh5YLVG45x11QACF38"]
[Tue Jul 21 07:25:46.053354 2026] [security2:error] [pid 229246:tid 229250] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/x.php"] [unique_id "al9JKiBMYeh5YLVG45x11gACFAM"]
[Tue Jul 21 07:25:46.072055 2026] [security2:error] [pid 229246:tid 229348] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/xa.php"] [unique_id "al9JKiBMYeh5YLVG45x11wACIWU"]
[Tue Jul 21 07:25:46.095381 2026] [security2:error] [pid 229246:tid 229291] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/kolda.php"] [unique_id "al9JKiBMYeh5YLVG45x12AACYCw"]
[Tue Jul 21 07:25:46.110516 2026] [security2:error] [pid 229246:tid 229253] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-aothait.php"] [unique_id "al9JKiBMYeh5YLVG45x12QACTAY"]
[Tue Jul 21 07:25:46.123112 2026] [security2:error] [pid 229246:tid 229264] [remote 160.187.68.132:54358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9JKiBMYeh5YLVG45x12wACNhE"]
[Tue Jul 21 07:25:46.125806 2026] [security2:error] [pid 229246:tid 229330] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ftde.php"] [unique_id "al9JKiBMYeh5YLVG45x13AACV1M"]
[Tue Jul 21 07:25:46.163844 2026] [security2:error] [pid 229246:tid 229304] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/vx.php"] [unique_id "al9JKiBMYeh5YLVG45x13QACUzk"]
[Tue Jul 21 07:25:46.195828 2026] [security2:error] [pid 229246:tid 229256] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/a5.php"] [unique_id "al9JKiBMYeh5YLVG45x13gACfQk"]
[Tue Jul 21 07:25:46.226869 2026] [security2:error] [pid 229246:tid 229310] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-sing.php"] [unique_id "al9JKiBMYeh5YLVG45x13wACkz8"]
[Tue Jul 21 07:25:46.243653 2026] [security2:error] [pid 229246:tid 229297] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/database.php"] [unique_id "al9JKiBMYeh5YLVG45x14QACTzI"]
[Tue Jul 21 07:25:46.254414 2026] [security2:error] [pid 230252:tid 230414] [client 136.144.33.241:40555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JKU0Dwhk5-Z44XrpQ4AAAArc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:46.263079 2026] [security2:error] [pid 229246:tid 229352] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/explorer/index_.php"] [unique_id "al9JKiBMYeh5YLVG45x14wACM2k"]
[Tue Jul 21 07:25:46.279339 2026] [security2:error] [pid 229246:tid 229360] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-at.php"] [unique_id "al9JKiBMYeh5YLVG45x15AACK3E"]
[Tue Jul 21 07:25:46.308090 2026] [security2:error] [pid 229246:tid 229299] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-wz.php"] [unique_id "al9JKiBMYeh5YLVG45x15QACIDQ"]
[Tue Jul 21 07:25:46.330542 2026] [security2:error] [pid 229246:tid 229326] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-ver.php"] [unique_id "al9JKiBMYeh5YLVG45x15wACYU8"]
[Tue Jul 21 07:25:46.346950 2026] [security2:error] [pid 229246:tid 229284] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp5.php"] [unique_id "al9JKiBMYeh5YLVG45x16AACSiU"]
[Tue Jul 21 07:25:46.357991 2026] [security2:error] [pid 229246:tid 229402] [client 20.226.60.151:56953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/min.php"] [unique_id "al9JKiBMYeh5YLVG45x16QAAAi4"]
[Tue Jul 21 07:25:46.362787 2026] [security2:error] [pid 229246:tid 229328] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-pp.php"] [unique_id "al9JKiBMYeh5YLVG45x16gACSVE"]
[Tue Jul 21 07:25:46.379284 2026] [security2:error] [pid 229246:tid 229314] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/w3lls.php"] [unique_id "al9JKiBMYeh5YLVG45x16wACZEM"]
[Tue Jul 21 07:25:46.395652 2026] [security2:error] [pid 229246:tid 229247] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/sbhu.php"] [unique_id "al9JKiBMYeh5YLVG45x17AACVAA"]
[Tue Jul 21 07:25:46.454489 2026] [security2:error] [pid 229246:tid 229277] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "al9JKiBMYeh5YLVG45x17QACUB4"]
[Tue Jul 21 07:25:46.484524 2026] [security2:error] [pid 229246:tid 229312] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/favicon.php"] [unique_id "al9JKiBMYeh5YLVG45x18AACTUE"]
[Tue Jul 21 07:25:46.502455 2026] [security2:error] [pid 229246:tid 229327] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/txets.php"] [unique_id "al9JKiBMYeh5YLVG45x18gACJlA"]
[Tue Jul 21 07:25:46.518926 2026] [security2:error] [pid 229246:tid 229261] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-su.php"] [unique_id "al9JKiBMYeh5YLVG45x18wACdQ4"]
[Tue Jul 21 07:25:46.522045 2026] [security2:error] [pid 230252:tid 230436] [client 20.52.136.55:1559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/classwithtostring.php"] [unique_id "al9JKk0Dwhk5-Z44XrpQ9gAAAs0"]
[Tue Jul 21 07:25:46.559353 2026] [security2:error] [pid 229246:tid 229265] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ff.php"] [unique_id "al9JKiBMYeh5YLVG45x19AACbxI"]
[Tue Jul 21 07:25:46.617066 2026] [security2:error] [pid 229246:tid 229350] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/reze.php"] [unique_id "al9JKiBMYeh5YLVG45x1-AACkGc"]
[Tue Jul 21 07:25:46.617423 2026] [security2:error] [pid 229246:tid 229466] [client 74.249.245.134:54354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/aa.php"] [unique_id "al9JKiBMYeh5YLVG45x1-QAAAm4"]
[Tue Jul 21 07:25:46.635888 2026] [security2:error] [pid 229246:tid 229305] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/666.php"] [unique_id "al9JKiBMYeh5YLVG45x1-gACXjo"]
[Tue Jul 21 07:25:46.657198 2026] [security2:error] [pid 229246:tid 229266] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wehrman.php"] [unique_id "al9JKiBMYeh5YLVG45x1-wACMBM"]
[Tue Jul 21 07:25:46.687483 2026] [security2:error] [pid 229246:tid 229251] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-conflg.php"] [unique_id "al9JKiBMYeh5YLVG45x1_QACSwQ"]
[Tue Jul 21 07:25:46.701822 2026] [security2:error] [pid 229246:tid 229302] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ff1.php"] [unique_id "al9JKiBMYeh5YLVG45x1_gACiTc"]
[Tue Jul 21 07:25:46.725374 2026] [security2:error] [pid 229246:tid 229303] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/fff.php"] [unique_id "al9JKiBMYeh5YLVG45x1_wACWzg"]
[Tue Jul 21 07:25:46.749615 2026] [security2:error] [pid 229246:tid 229270] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/amax.php"] [unique_id "al9JKiBMYeh5YLVG45x2AAACRRc"]
[Tue Jul 21 07:25:46.770253 2026] [security2:error] [pid 229246:tid 229257] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-firewall.php"] [unique_id "al9JKiBMYeh5YLVG45x2BAACjQo"]
[Tue Jul 21 07:25:46.785684 2026] [security2:error] [pid 230252:tid 230339] [remote 216.73.217.141:32201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vaporclube.com.br"] [uri "/campinas.php"] [unique_id "al9JKk0Dwhk5-Z44XrpQ-AACz1Q"]
[Tue Jul 21 07:25:46.805685 2026] [security2:error] [pid 229246:tid 229355] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/appt.php"] [unique_id "al9JKiBMYeh5YLVG45x2BgACYmw"]
[Tue Jul 21 07:25:46.821684 2026] [security2:error] [pid 229246:tid 229351] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-thi.php"] [unique_id "al9JKiBMYeh5YLVG45x2BwACj2g"]
[Tue Jul 21 07:25:46.832945 2026] [security2:error] [pid 230252:tid 230371] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JKk0Dwhk5-Z44XrpQ-gACzHQ"]
[Tue Jul 21 07:25:46.833107 2026] [security2:error] [pid 230252:tid 230435] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JKk0Dwhk5-Z44XrpQ-gACzHQ"]
[Tue Jul 21 07:25:46.843948 2026] [security2:error] [pid 229246:tid 229356] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/jj.php"] [unique_id "al9JKiBMYeh5YLVG45x2CQACcG0"]
[Tue Jul 21 07:25:46.861782 2026] [security2:error] [pid 229246:tid 229319] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/333.php"] [unique_id "al9JKiBMYeh5YLVG45x2CgACI0g"]
[Tue Jul 21 07:25:46.933761 2026] [security2:error] [pid 229246:tid 229280] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/albin.php"] [unique_id "al9JKiBMYeh5YLVG45x2DAACjCE"]
[Tue Jul 21 07:25:46.944621 2026] [security2:error] [pid 230252:tid 230322] [remote 216.73.217.141:32201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vaporclube.com.br"] [uri "/termos.php"] [unique_id "al9JKk0Dwhk5-Z44XrpQ-QACz0Q"]
[Tue Jul 21 07:25:46.958148 2026] [security2:error] [pid 229246:tid 229357] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/66.php"] [unique_id "al9JKiBMYeh5YLVG45x2DQACaG4"]
[Tue Jul 21 07:25:47.003153 2026] [security2:error] [pid 229246:tid 229274] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/motu.php"] [unique_id "al9JKyBMYeh5YLVG45x2DgACVRs"]
[Tue Jul 21 07:25:47.020844 2026] [security2:error] [pid 229246:tid 229342] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/kj.php"] [unique_id "al9JKyBMYeh5YLVG45x2DwACZV8"]
[Tue Jul 21 07:25:47.036397 2026] [security2:error] [pid 229246:tid 229363] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp4.php"] [unique_id "al9JKyBMYeh5YLVG45x2EAACfHQ"]
[Tue Jul 21 07:25:47.053058 2026] [security2:error] [pid 229246:tid 229307] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/file61.php"] [unique_id "al9JKyBMYeh5YLVG45x2EQACVjw"]
[Tue Jul 21 07:25:47.069143 2026] [security2:error] [pid 229246:tid 229320] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp.php"] [unique_id "al9JKyBMYeh5YLVG45x2EgACgUk"]
[Tue Jul 21 07:25:47.117160 2026] [security2:error] [pid 229246:tid 229354] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-trackback.php"] [unique_id "al9JKyBMYeh5YLVG45x2EwACems"]
[Tue Jul 21 07:25:47.117933 2026] [security2:error] [pid 230252:tid 230388] [client 20.151.10.161:49084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9JK00Dwhk5-Z44XrpQ_wAAAp0"]
[Tue Jul 21 07:25:47.175688 2026] [security2:error] [pid 229246:tid 229298] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/db.php"] [unique_id "al9JKyBMYeh5YLVG45x2FAACMTM"]
[Tue Jul 21 07:25:47.194582 2026] [proxy:error] [pid 229246:tid 229446] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:47.194635 2026] [proxy_http:error] [pid 229246:tid 229446] [client 20.151.10.161:65516] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:47.195250 2026] [proxy:error] [pid 229246:tid 229446] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:47.195274 2026] [proxy_http:error] [pid 229246:tid 229446] [client 20.151.10.161:65516] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:47.280486 2026] [security2:error] [pid 229246:tid 229361] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/NewFile.php"] [unique_id "al9JKyBMYeh5YLVG45x2GAACknI"]
[Tue Jul 21 07:25:47.296888 2026] [security2:error] [pid 229246:tid 229283] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/xxx.php"] [unique_id "al9JKyBMYeh5YLVG45x2GgACUiQ"]
[Tue Jul 21 07:25:47.312261 2026] [security2:error] [pid 229246:tid 229295] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/ms.php"] [unique_id "al9JKyBMYeh5YLVG45x2HAACfzA"]
[Tue Jul 21 07:25:47.330518 2026] [security2:error] [pid 229246:tid 229281] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/mini.php"] [unique_id "al9JKyBMYeh5YLVG45x2HgACgCI"]
[Tue Jul 21 07:25:47.346615 2026] [security2:error] [pid 229246:tid 229287] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/first.php"] [unique_id "al9JKyBMYeh5YLVG45x2HwACRCg"]
[Tue Jul 21 07:25:47.378998 2026] [security2:error] [pid 229246:tid 229368] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/0okj.php"] [unique_id "al9JKyBMYeh5YLVG45x2IQACJXk"]
[Tue Jul 21 07:25:47.395456 2026] [security2:error] [pid 229246:tid 229340] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/grsiuk.php"] [unique_id "al9JKyBMYeh5YLVG45x2IgACOF0"]
[Tue Jul 21 07:25:47.418639 2026] [security2:error] [pid 229246:tid 229347] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/shell20211028.php"] [unique_id "al9JKyBMYeh5YLVG45x2IwACF2Q"]
[Tue Jul 21 07:25:47.448430 2026] [security2:error] [pid 229246:tid 229271] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/revealability.php"] [unique_id "al9JKyBMYeh5YLVG45x2JAACJxg"]
[Tue Jul 21 07:25:47.518822 2026] [security2:error] [pid 229246:tid 229276] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/btx25.php"] [unique_id "al9JKyBMYeh5YLVG45x2JQACdh0"]
[Tue Jul 21 07:25:47.528140 2026] [security2:error] [pid 229246:tid 229428] [client 103.106.20.201:61835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JKyBMYeh5YLVG45x2JgAAAkg"]
[Tue Jul 21 07:25:47.528254 2026] [security2:error] [pid 229246:tid 229428] [client 103.106.20.201:61835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JKyBMYeh5YLVG45x2JgAAAkg"]
[Tue Jul 21 07:25:47.554706 2026] [security2:error] [pid 229246:tid 229359] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/bthil.php"] [unique_id "al9JKyBMYeh5YLVG45x2JwACFHA"]
[Tue Jul 21 07:25:47.601723 2026] [security2:error] [pid 229246:tid 229345] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/hplfuns.php"] [unique_id "al9JKyBMYeh5YLVG45x2KgACkWI"]
[Tue Jul 21 07:25:47.625209 2026] [security2:error] [pid 229246:tid 229279] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/error.php"] [unique_id "al9JKyBMYeh5YLVG45x2LAACTCA"]
[Tue Jul 21 07:25:47.658199 2026] [security2:error] [pid 229246:tid 229335] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/edit.php"] [unique_id "al9JKyBMYeh5YLVG45x2LQACNlg"]
[Tue Jul 21 07:25:47.664277 2026] [security2:error] [pid 230252:tid 230506] [client 20.226.60.151:56898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/dvjul.php"] [unique_id "al9JK00Dwhk5-Z44XrpRBQAAAxM"]
[Tue Jul 21 07:25:47.723227 2026] [security2:error] [pid 229246:tid 229365] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/pass4.php"] [unique_id "al9JKyBMYeh5YLVG45x2LgACV3Y"]
[Tue Jul 21 07:25:47.739499 2026] [security2:error] [pid 229246:tid 229341] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/sadcut1.php"] [unique_id "al9JKyBMYeh5YLVG45x2LwACU14"]
[Tue Jul 21 07:25:47.769888 2026] [security2:error] [pid 229246:tid 229343] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/bgymj.php"] [unique_id "al9JKyBMYeh5YLVG45x2MAACZmA"]
[Tue Jul 21 07:25:47.812541 2026] [security2:error] [pid 229246:tid 229306] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/yas.php"] [unique_id "al9JKyBMYeh5YLVG45x2MgACMzs"]
[Tue Jul 21 07:25:47.852401 2026] [security2:error] [pid 229246:tid 229369] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/dx.php"] [unique_id "al9JKyBMYeh5YLVG45x2NAACP3o"]
[Tue Jul 21 07:25:47.883487 2026] [security2:error] [pid 229246:tid 229300] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/yellow.php"] [unique_id "al9JKyBMYeh5YLVG45x2NQACYzU"]
[Tue Jul 21 07:25:47.918878 2026] [security2:error] [pid 229246:tid 229349] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/wp-der.php"] [unique_id "al9JKyBMYeh5YLVG45x2NgACHmY"]
[Tue Jul 21 07:25:47.986510 2026] [security2:error] [pid 230252:tid 230409] [client 103.174.34.15:58802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JK00Dwhk5-Z44XrpRCgAAArI"]
[Tue Jul 21 07:25:47.986604 2026] [security2:error] [pid 230252:tid 230409] [client 103.174.34.15:58802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JK00Dwhk5-Z44XrpRCgAAArI"]
[Tue Jul 21 07:25:48.062142 2026] [security2:error] [pid 230252:tid 230473] [client 45.251.232.145:62364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JLE0Dwhk5-Z44XrpRCwAAAvI"]
[Tue Jul 21 07:25:48.062257 2026] [security2:error] [pid 230252:tid 230473] [client 45.251.232.145:62364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JLE0Dwhk5-Z44XrpRCwAAAvI"]
[Tue Jul 21 07:25:48.161998 2026] [security2:error] [pid 229246:tid 229275] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/lala.php"] [unique_id "al9JLCBMYeh5YLVG45x2OQACYRw"]
[Tue Jul 21 07:25:48.189235 2026] [security2:error] [pid 229246:tid 229308] [remote 20.206.67.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.67.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.dralulmabhering.com.br"] [uri "/aa.php"] [unique_id "al9JLCBMYeh5YLVG45x2OgACOT0"]
[Tue Jul 21 07:25:48.314771 2026] [security2:error] [pid 230252:tid 230382] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JLE0Dwhk5-Z44XrpRDQACpn8"]
[Tue Jul 21 07:25:48.314913 2026] [security2:error] [pid 230252:tid 230397] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JLE0Dwhk5-Z44XrpRDQACpn8"]
[Tue Jul 21 07:25:48.348631 2026] [security2:error] [pid 230252:tid 230492] [client 20.151.10.161:63627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/file5.php"] [unique_id "al9JLE0Dwhk5-Z44XrpRDgAAAwU"]
[Tue Jul 21 07:25:48.832627 2026] [security2:error] [pid 229246:tid 229378] [client 59.96.220.140:60444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JLCBMYeh5YLVG45x2QgAAAhY"]
[Tue Jul 21 07:25:48.832781 2026] [security2:error] [pid 229246:tid 229378] [client 59.96.220.140:60444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JLCBMYeh5YLVG45x2QgAAAhY"]
[Tue Jul 21 07:25:48.840836 2026] [security2:error] [pid 229246:tid 229492] [client 74.249.245.134:5534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/bolt.php"] [unique_id "al9JLCBMYeh5YLVG45x2QwAAAog"]
[Tue Jul 21 07:25:48.925314 2026] [security2:error] [pid 230252:tid 230404] [client 20.151.10.161:49074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/2P.php"] [unique_id "al9JLE0Dwhk5-Z44XrpREgAAAq0"]
[Tue Jul 21 07:25:49.177892 2026] [security2:error] [pid 229246:tid 229433] [client 175.45.70.82:65484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JLSBMYeh5YLVG45x2SQAAAk0"]
[Tue Jul 21 07:25:49.178047 2026] [security2:error] [pid 229246:tid 229433] [client 175.45.70.82:65484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JLSBMYeh5YLVG45x2SQAAAk0"]
[Tue Jul 21 07:25:49.207030 2026] [security2:error] [pid 230252:tid 230301] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JLU0Dwhk5-Z44XrpRFAAC4S8"]
[Tue Jul 21 07:25:49.207163 2026] [security2:error] [pid 230252:tid 230456] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JLU0Dwhk5-Z44XrpRFAAC4S8"]
[Tue Jul 21 07:25:49.394664 2026] [access_compat:error] [pid 230252:tid 230505] [client 162.241.63.68:31764] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:25:49.843500 2026] [security2:error] [pid 230252:tid 230453] [client 136.144.33.215:45661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JLU0Dwhk5-Z44XrpRGQAAAt4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:49.989893 2026] [security2:error] [pid 229246:tid 229497] [client 154.192.233.199:59349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JLSBMYeh5YLVG45x2WQAAAo0"]
[Tue Jul 21 07:25:49.990021 2026] [security2:error] [pid 229246:tid 229497] [client 154.192.233.199:59349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JLSBMYeh5YLVG45x2WQAAAo0"]
[Tue Jul 21 07:25:50.001224 2026] [security2:error] [pid 229246:tid 229445] [client 20.151.10.161:49144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/.well-known/about.php"] [unique_id "al9JLiBMYeh5YLVG45x2WwAAAlk"]
[Tue Jul 21 07:25:50.028417 2026] [security2:error] [pid 229246:tid 229293] [remote 5.252.52.249:49314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wp-login.php"] [unique_id "al9JLiBMYeh5YLVG45x2XAACIy4"]
[Tue Jul 21 07:25:50.056821 2026] [security2:error] [pid 229246:tid 229475] [client 20.151.10.161:63624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/file.php"] [unique_id "al9JLiBMYeh5YLVG45x2XQAAAnc"]
[Tue Jul 21 07:25:50.141643 2026] [security2:error] [pid 230252:tid 230511] [client 185.198.240.89:31077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "voweltravel.com.br"] [uri "/wp-login.php"] [unique_id "al9JLU0Dwhk5-Z44XrpRFQAAAxg"]
[Tue Jul 21 07:25:50.454632 2026] [security2:error] [pid 230252:tid 230504] [client 74.249.245.134:47152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/403.php"] [unique_id "al9JLk0Dwhk5-Z44XrpRJwAAAxE"]
[Tue Jul 21 07:25:50.498286 2026] [security2:error] [pid 230252:tid 230436] [client 20.226.60.151:63352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/biufile.php"] [unique_id "al9JLk0Dwhk5-Z44XrpRKQAAAs0"]
[Tue Jul 21 07:25:50.537415 2026] [security2:error] [pid 230252:tid 230482] [client 213.152.162.104:48774] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JLk0Dwhk5-Z44XrpRIAAAAvs"]
[Tue Jul 21 07:25:50.537550 2026] [security2:error] [pid 230252:tid 230482] [client 213.152.162.104:48774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JLk0Dwhk5-Z44XrpRIAAAAvs"]
[Tue Jul 21 07:25:51.077367 2026] [security2:error] [pid 230252:tid 230477] [client 62.102.148.164:53642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JL00Dwhk5-Z44XrpRNAAAAvY"]
[Tue Jul 21 07:25:51.077458 2026] [security2:error] [pid 230252:tid 230477] [client 62.102.148.164:53642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JL00Dwhk5-Z44XrpRNAAAAvY"]
[Tue Jul 21 07:25:51.131755 2026] [security2:error] [pid 230252:tid 230469] [client 20.151.10.161:49080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9JL00Dwhk5-Z44XrpRNQAAAu4"]
[Tue Jul 21 07:25:51.186720 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:51.186789 2026] [proxy_http:error] [pid 230252:tid 230437] [client 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:51.187444 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:51.187480 2026] [proxy_http:error] [pid 230252:tid 230437] [client 93.123.109.101:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:51.519015 2026] [security2:error] [pid 230252:tid 230503] [client 74.249.245.134:54395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/x.php"] [unique_id "al9JL00Dwhk5-Z44XrpROAAAAxA"]
[Tue Jul 21 07:25:51.606690 2026] [security2:error] [pid 230252:tid 230400] [client 20.151.10.161:65469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/aa2.php"] [unique_id "al9JL00Dwhk5-Z44XrpROwAAAqk"]
[Tue Jul 21 07:25:51.889249 2026] [security2:error] [pid 230252:tid 230499] [client 20.151.10.161:49097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/bob.php"] [unique_id "al9JL00Dwhk5-Z44XrpRPgAAAww"]
[Tue Jul 21 07:25:51.898069 2026] [security2:error] [pid 230252:tid 230307] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JL00Dwhk5-Z44XrpRPwACyjU"]
[Tue Jul 21 07:25:51.898227 2026] [security2:error] [pid 230252:tid 230433] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JL00Dwhk5-Z44XrpRPwACyjU"]
[Tue Jul 21 07:25:52.328833 2026] [security2:error] [pid 230252:tid 230472] [client 20.226.60.151:56875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/av.php"] [unique_id "al9JME0Dwhk5-Z44XrpRQQAAAvE"]
[Tue Jul 21 07:25:52.644634 2026] [security2:error] [pid 230252:tid 230420] [client 20.151.10.161:65521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/ccou.php"] [unique_id "al9JME0Dwhk5-Z44XrpRRwAAAr0"]
[Tue Jul 21 07:25:52.747999 2026] [security2:error] [pid 230252:tid 230343] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JME0Dwhk5-Z44XrpRSAACy1g"]
[Tue Jul 21 07:25:52.748137 2026] [security2:error] [pid 230252:tid 230434] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JME0Dwhk5-Z44XrpRSAACy1g"]
[Tue Jul 21 07:25:52.753429 2026] [proxy:error] [pid 230252:tid 230439] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:52.753481 2026] [proxy_http:error] [pid 230252:tid 230439] [client 20.151.10.161:49042] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:52.754277 2026] [proxy:error] [pid 230252:tid 230439] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:52.754306 2026] [proxy_http:error] [pid 230252:tid 230439] [client 20.151.10.161:49042] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:53.202302 2026] [security2:error] [pid 230252:tid 230456] [client 139.135.44.145:53395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRUwAAAuE"]
[Tue Jul 21 07:25:53.202384 2026] [security2:error] [pid 230252:tid 230456] [client 139.135.44.145:53395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRUwAAAuE"]
[Tue Jul 21 07:25:53.252757 2026] [security2:error] [pid 230252:tid 230446] [client 74.249.245.134:5560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/jga.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRVAAAAtc"]
[Tue Jul 21 07:25:53.285287 2026] [security2:error] [pid 230252:tid 230283] [remote 102.134.101.35:59704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRVgADAR0"]
[Tue Jul 21 07:25:53.400911 2026] [security2:error] [pid 230252:tid 230419] [client 103.162.129.114:58281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRWAAAArw"]
[Tue Jul 21 07:25:53.401075 2026] [security2:error] [pid 230252:tid 230419] [client 103.162.129.114:58281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRWAAAArw"]
[Tue Jul 21 07:25:53.471279 2026] [security2:error] [pid 230252:tid 230342] [remote 42.200.84.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onkosclinica.com"] [uri "/wp-login.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRXAACxVc"]
[Tue Jul 21 07:25:53.582163 2026] [security2:error] [pid 230252:tid 230484] [client 20.151.10.161:65423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/dr.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRXQAAAv0"]
[Tue Jul 21 07:25:53.628706 2026] [proxy:error] [pid 230252:tid 230385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:53.628778 2026] [proxy_http:error] [pid 230252:tid 230385] [client 20.151.10.161:49137] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:53.629271 2026] [proxy:error] [pid 230252:tid 230385] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:53.629301 2026] [proxy_http:error] [pid 230252:tid 230385] [client 20.151.10.161:49137] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:53.630560 2026] [security2:error] [pid 230252:tid 230477] [client 20.226.60.151:56850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/coffexium.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRYAAAAvY"]
[Tue Jul 21 07:25:53.714594 2026] [security2:error] [pid 230252:tid 230451] [client 20.151.10.161:26439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/ccou.php"] [unique_id "al9JMU0Dwhk5-Z44XrpRZQAAAtw"]
[Tue Jul 21 07:25:54.247451 2026] [security2:error] [pid 230252:tid 230258] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JMk0Dwhk5-Z44XrpRdAACvQQ"]
[Tue Jul 21 07:25:54.247591 2026] [security2:error] [pid 230252:tid 230420] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JMk0Dwhk5-Z44XrpRdAACvQQ"]
[Tue Jul 21 07:25:54.767668 2026] [security2:error] [pid 230252:tid 230394] [client 193.36.225.55:56717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JMk0Dwhk5-Z44XrpRfQAAAqM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:25:54.810130 2026] [security2:error] [pid 229246:tid 229462] [client 20.226.60.151:56876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/core.php"] [unique_id "al9JMiBMYeh5YLVG45x2jQAAAmo"]
[Tue Jul 21 07:25:54.947207 2026] [security2:error] [pid 230252:tid 230387] [client 74.7.241.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.lp.mannucarvalho.com"] [uri "/robots.txt"] [unique_id "al9JMk0Dwhk5-Z44XrpRggAAApw"]
[Tue Jul 21 07:25:54.948671 2026] [security2:error] [pid 230252:tid 230477] [client 74.7.241.158:34626] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.lp.mannucarvalho.com"] [uri "/robots.txt"] [unique_id "al9JMk0Dwhk5-Z44XrpRgAAC9h8"]
[Tue Jul 21 07:25:55.071939 2026] [security2:error] [pid 229246:tid 229467] [client 117.251.86.144:50158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JMyBMYeh5YLVG45x2kgAAAm8"]
[Tue Jul 21 07:25:55.072042 2026] [security2:error] [pid 229246:tid 229467] [client 117.251.86.144:50158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JMyBMYeh5YLVG45x2kgAAAm8"]
[Tue Jul 21 07:25:55.086941 2026] [security2:error] [pid 230252:tid 230487] [client 74.249.245.134:59758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/api.php"] [unique_id "al9JM00Dwhk5-Z44XrpRiAAAAwA"]
[Tue Jul 21 07:25:55.132559 2026] [security2:error] [pid 230252:tid 230500] [client 74.7.241.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lp.mannucarvalho.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al9JM00Dwhk5-Z44XrpRhwAAAw0"], referer: https://www.lp.mannucarvalho.com/robots.txt
[Tue Jul 21 07:25:55.133403 2026] [security2:error] [pid 230252:tid 230400] [client 74.7.241.158:34626] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.lp.mannucarvalho.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al9JM00Dwhk5-Z44XrpRhQACqSo"], referer: https://www.lp.mannucarvalho.com/robots.txt
[Tue Jul 21 07:25:55.145440 2026] [security2:error] [pid 230252:tid 230449] [client 74.249.245.134:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/k.php"] [unique_id "al9JM00Dwhk5-Z44XrpRiQAAAto"]
[Tue Jul 21 07:25:55.358347 2026] [security2:error] [pid 230252:tid 230506] [client 20.226.60.151:54527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/cilus.php"] [unique_id "al9JM00Dwhk5-Z44XrpRjAAAAxM"]
[Tue Jul 21 07:25:55.581783 2026] [security2:error] [pid 230252:tid 230501] [client 20.151.10.161:63690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/file31.php"] [unique_id "al9JM00Dwhk5-Z44XrpRjwAAAw4"]
[Tue Jul 21 07:25:55.742767 2026] [security2:error] [pid 230252:tid 230467] [client 185.251.19.76:55043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9JM00Dwhk5-Z44XrpRlAAAAuw"]
[Tue Jul 21 07:25:55.938071 2026] [security2:error] [pid 230252:tid 230396] [client 20.52.136.55:1540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/bless.php"] [unique_id "al9JM00Dwhk5-Z44XrpRmgAAAqU"]
[Tue Jul 21 07:25:55.990498 2026] [security2:error] [pid 230252:tid 230455] [client 136.144.42.179:57497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9JM00Dwhk5-Z44XrpRnAAAAuA"]
[Tue Jul 21 07:25:56.088198 2026] [security2:error] [pid 230252:tid 230415] [client 20.226.60.151:56903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/als.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRnQAAArg"]
[Tue Jul 21 07:25:56.093972 2026] [security2:error] [pid 230252:tid 230461] [client 74.249.245.134:17457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/vx.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRngAAAuY"]
[Tue Jul 21 07:25:56.186538 2026] [security2:error] [pid 230252:tid 230325] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRoAACy0Y"]
[Tue Jul 21 07:25:56.186666 2026] [security2:error] [pid 230252:tid 230434] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRoAACy0Y"]
[Tue Jul 21 07:25:56.404669 2026] [security2:error] [pid 230252:tid 230406] [client 20.151.10.161:49051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/crgio.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRowAAAq8"]
[Tue Jul 21 07:25:56.524214 2026] [security2:error] [pid 230252:tid 230363] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRpAAC3Ww"]
[Tue Jul 21 07:25:56.524357 2026] [security2:error] [pid 230252:tid 230452] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRpAAC3Ww"]
[Tue Jul 21 07:25:56.527937 2026] [security2:error] [pid 230252:tid 230411] [client 20.151.10.161:65449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/file6.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRpQAAArQ"]
[Tue Jul 21 07:25:56.618851 2026] [security2:error] [pid 230252:tid 230386] [client 152.59.154.239:63856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRpgAAAps"]
[Tue Jul 21 07:25:56.660785 2026] [security2:error] [pid 230252:tid 230426] [client 74.249.245.134:5562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/ws77.php"] [unique_id "al9JNE0Dwhk5-Z44XrpRqAAAAsM"]
[Tue Jul 21 07:25:57.175187 2026] [security2:error] [pid 230252:tid 230494] [client 20.151.10.161:65461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/file15.php"] [unique_id "al9JNU0Dwhk5-Z44XrpRrwAAAwc"]
[Tue Jul 21 07:25:57.283181 2026] [security2:error] [pid 230252:tid 230428] [client 59.96.220.140:60890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JNU0Dwhk5-Z44XrpRsAAAAsU"]
[Tue Jul 21 07:25:57.283864 2026] [security2:error] [pid 230252:tid 230428] [client 59.96.220.140:60890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JNU0Dwhk5-Z44XrpRsAAAAsU"]
[Tue Jul 21 07:25:57.632465 2026] [security2:error] [pid 230252:tid 230368] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JNU0Dwhk5-Z44XrpRsgACynE"]
[Tue Jul 21 07:25:57.632653 2026] [security2:error] [pid 230252:tid 230433] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JNU0Dwhk5-Z44XrpRsgACynE"]
[Tue Jul 21 07:25:57.680593 2026] [security2:error] [pid 230252:tid 230410] [client 20.151.10.161:63620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/jp.php"] [unique_id "al9JNU0Dwhk5-Z44XrpRtQAAArM"]
[Tue Jul 21 07:25:57.953044 2026] [security2:error] [pid 230252:tid 230409] [client 74.249.245.134:5540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/2.php"] [unique_id "al9JNU0Dwhk5-Z44XrpRugAAArI"]
[Tue Jul 21 07:25:58.200003 2026] [security2:error] [pid 230252:tid 230492] [client 103.106.20.201:62393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRvQAAAwU"]
[Tue Jul 21 07:25:58.200142 2026] [security2:error] [pid 230252:tid 230492] [client 103.106.20.201:62393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRvQAAAwU"]
[Tue Jul 21 07:25:58.401369 2026] [security2:error] [pid 230252:tid 230429] [client 20.151.10.161:49028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/pucci.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRwAAAAsY"]
[Tue Jul 21 07:25:58.530126 2026] [security2:error] [pid 230252:tid 230474] [client 20.151.10.161:63687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/f35.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRxAAAAvM"]
[Tue Jul 21 07:25:58.584315 2026] [security2:error] [pid 230252:tid 230493] [client 45.251.232.145:62883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRxQAAAwY"]
[Tue Jul 21 07:25:58.584452 2026] [security2:error] [pid 230252:tid 230493] [client 45.251.232.145:62883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRxQAAAwY"]
[Tue Jul 21 07:25:58.668260 2026] [security2:error] [pid 230252:tid 230502] [client 4.204.201.85:3220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRxgAAAw8"]
[Tue Jul 21 07:25:58.728019 2026] [security2:error] [pid 230252:tid 230495] [client 103.174.34.15:59280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRxwAAAwg"]
[Tue Jul 21 07:25:58.728132 2026] [security2:error] [pid 230252:tid 230495] [client 103.174.34.15:59280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRxwAAAwg"]
[Tue Jul 21 07:25:58.748033 2026] [security2:error] [pid 230252:tid 230453] [client 20.226.60.151:56942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/simple.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRyAAAAt4"]
[Tue Jul 21 07:25:58.802262 2026] [security2:error] [pid 230252:tid 230511] [client 109.248.148.246:48170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRyQAAAxg"]
[Tue Jul 21 07:25:58.802355 2026] [security2:error] [pid 230252:tid 230511] [client 109.248.148.246:48170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRyQAAAxg"]
[Tue Jul 21 07:25:59.013277 2026] [security2:error] [pid 230252:tid 230484] [client 20.151.10.161:65464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-load.php"] [unique_id "al9JN00Dwhk5-Z44XrpRzgAAAv0"]
[Tue Jul 21 07:25:59.065617 2026] [security2:error] [pid 230252:tid 230274] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JN00Dwhk5-Z44XrpRzwAC-BQ"]
[Tue Jul 21 07:25:59.065753 2026] [security2:error] [pid 230252:tid 230479] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JN00Dwhk5-Z44XrpRzwAC-BQ"]
[Tue Jul 21 07:25:59.294196 2026] [security2:error] [pid 230252:tid 230469] [client 4.204.201.85:3219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9JN00Dwhk5-Z44XrpR0QAAAu4"]
[Tue Jul 21 07:25:59.444876 2026] [security2:error] [pid 230252:tid 230422] [client 20.52.136.55:1586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/storage/index.php"] [unique_id "al9JN00Dwhk5-Z44XrpR1gAAAr8"]
[Tue Jul 21 07:25:59.467350 2026] [proxy:error] [pid 230252:tid 230500] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:59.467414 2026] [proxy_http:error] [pid 230252:tid 230500] [client 20.151.10.161:63046] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:59.467869 2026] [proxy:error] [pid 230252:tid 230500] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:25:59.467897 2026] [proxy_http:error] [pid 230252:tid 230500] [client 20.151.10.161:63046] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:25:59.696692 2026] [security2:error] [pid 230252:tid 230328] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JN00Dwhk5-Z44XrpR2wACoUk"]
[Tue Jul 21 07:25:59.696867 2026] [security2:error] [pid 230252:tid 230392] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JN00Dwhk5-Z44XrpR2wACoUk"]
[Tue Jul 21 07:25:59.873227 2026] [security2:error] [pid 230252:tid 230509] [client 175.45.70.82:49612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JN00Dwhk5-Z44XrpR3QAAAxY"]
[Tue Jul 21 07:25:59.873354 2026] [security2:error] [pid 230252:tid 230509] [client 175.45.70.82:49612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JN00Dwhk5-Z44XrpR3QAAAxY"]
[Tue Jul 21 07:25:59.963772 2026] [security2:error] [pid 230252:tid 230391] [client 4.204.201.85:3297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/media.php"] [unique_id "al9JN00Dwhk5-Z44XrpR3wAAAqA"]
[Tue Jul 21 07:26:00.052000 2026] [security2:error] [pid 230252:tid 230478] [client 31.57.219.92:26488] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "murilomattos.com"] [uri "/"] [unique_id "al9JOE0Dwhk5-Z44XrpR4QAAAvc"]
[Tue Jul 21 07:26:00.218952 2026] [proxy:error] [pid 229246:tid 229383] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:00.219028 2026] [proxy_http:error] [pid 229246:tid 229383] [client 20.151.10.161:65525] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:00.219484 2026] [proxy:error] [pid 229246:tid 229383] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:00.219507 2026] [proxy_http:error] [pid 229246:tid 229383] [client 20.151.10.161:65525] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:00.265247 2026] [security2:error] [pid 230252:tid 230443] [client 20.226.60.151:56834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/init.php"] [unique_id "al9JOE0Dwhk5-Z44XrpR5gAAAtQ"]
[Tue Jul 21 07:26:00.356944 2026] [security2:error] [pid 229246:tid 229439] [client 4.204.201.85:3240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/images.php"] [unique_id "al9JOCBMYeh5YLVG45x2uAAAAlM"]
[Tue Jul 21 07:26:00.452890 2026] [security2:error] [pid 230252:tid 230403] [client 83.97.118.16:12157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.118.97.83.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.tempex.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9JOE0Dwhk5-Z44XrpR6QAAAqw"], referer: https://www.tempex.com.br/contato/
[Tue Jul 21 07:26:00.472709 2026] [proxy:error] [pid 230252:tid 230511] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:00.472788 2026] [proxy_http:error] [pid 230252:tid 230511] [client 20.151.10.161:48582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:00.473390 2026] [proxy:error] [pid 230252:tid 230511] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:00.473418 2026] [proxy_http:error] [pid 230252:tid 230511] [client 20.151.10.161:48582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:00.657856 2026] [security2:error] [pid 230252:tid 230458] [client 4.204.201.85:3209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/gecko.php"] [unique_id "al9JOE0Dwhk5-Z44XrpR7wAAAuM"]
[Tue Jul 21 07:26:00.671569 2026] [security2:error] [pid 230252:tid 230504] [client 154.192.233.199:59564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JOE0Dwhk5-Z44XrpR8AAAAxE"]
[Tue Jul 21 07:26:00.671713 2026] [security2:error] [pid 230252:tid 230504] [client 154.192.233.199:59564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JOE0Dwhk5-Z44XrpR8AAAAxE"]
[Tue Jul 21 07:26:00.798796 2026] [security2:error] [pid 230252:tid 230487] [client 136.144.33.96:24489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JNk0Dwhk5-Z44XrpRwwAAAwA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:00.950677 2026] [security2:error] [pid 229246:tid 229413] [client 4.204.201.85:3287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/82.php"] [unique_id "al9JOCBMYeh5YLVG45x2wAAAAjk"]
[Tue Jul 21 07:26:00.955117 2026] [security2:error] [pid 230252:tid 230444] [client 20.220.225.223:45377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/kua.php"] [unique_id "al9JOE0Dwhk5-Z44XrpR9AAAAtU"]
[Tue Jul 21 07:26:01.043645 2026] [security2:error] [pid 230252:tid 230402] [client 74.249.245.134:5545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/asd.php"] [unique_id "al9JOU0Dwhk5-Z44XrpR9gAAAqs"]
[Tue Jul 21 07:26:01.117779 2026] [security2:error] [pid 230252:tid 230468] [client 20.151.10.161:65494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9JOU0Dwhk5-Z44XrpR-QAAAu0"]
[Tue Jul 21 07:26:01.260156 2026] [security2:error] [pid 229246:tid 229414] [client 82.102.28.107:33788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JOSBMYeh5YLVG45x2xQAAAjo"]
[Tue Jul 21 07:26:01.260257 2026] [security2:error] [pid 229246:tid 229414] [client 82.102.28.107:33788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JOSBMYeh5YLVG45x2xQAAAjo"]
[Tue Jul 21 07:26:01.334343 2026] [security2:error] [pid 229246:tid 229473] [client 4.204.201.85:3218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/admin.php"] [unique_id "al9JOSBMYeh5YLVG45x2xwAAAnU"]
[Tue Jul 21 07:26:01.551901 2026] [security2:error] [pid 230252:tid 230476] [client 20.226.60.151:56899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/fpwch.php"] [unique_id "al9JOU0Dwhk5-Z44XrpR-wAAAvU"]
[Tue Jul 21 07:26:01.554268 2026] [security2:error] [pid 230252:tid 230290] [remote 152.42.185.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.185.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JOU0Dwhk5-Z44XrpR-gACxSQ"], referer: https://covumc.com//wp-login.php
[Tue Jul 21 07:26:01.778749 2026] [security2:error] [pid 230252:tid 230506] [client 20.151.10.161:65510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wp-links.php"] [unique_id "al9JOU0Dwhk5-Z44XrpR_wAAAxM"]
[Tue Jul 21 07:26:01.794146 2026] [security2:error] [pid 230252:tid 230485] [client 4.204.201.85:3282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/adminner.php"] [unique_id "al9JOU0Dwhk5-Z44XrpSAAAAAv4"]
[Tue Jul 21 07:26:01.894749 2026] [security2:error] [pid 229246:tid 229476] [client 20.226.60.151:54578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/gptsh.php"] [unique_id "al9JOSBMYeh5YLVG45x2ywAAAng"]
[Tue Jul 21 07:26:02.030940 2026] [proxy:error] [pid 229246:tid 229493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:02.031022 2026] [proxy_http:error] [pid 229246:tid 229493] [client 20.151.10.161:49089] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:02.031982 2026] [proxy:error] [pid 229246:tid 229493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:02.032020 2026] [proxy_http:error] [pid 229246:tid 229493] [client 20.151.10.161:49089] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:02.354292 2026] [security2:error] [pid 230252:tid 230429] [client 4.204.201.85:26600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/admin.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSBwAAAsY"]
[Tue Jul 21 07:26:02.438119 2026] [security2:error] [pid 230252:tid 230271] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSCAACvRE"]
[Tue Jul 21 07:26:02.438252 2026] [security2:error] [pid 230252:tid 230420] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSCAACvRE"]
[Tue Jul 21 07:26:02.443164 2026] [security2:error] [pid 230252:tid 230435] [client 82.102.28.107:54538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSCQAAAsw"]
[Tue Jul 21 07:26:02.443248 2026] [security2:error] [pid 230252:tid 230435] [client 82.102.28.107:54538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSCQAAAsw"]
[Tue Jul 21 07:26:02.515553 2026] [security2:error] [pid 230252:tid 230417] [client 20.226.60.151:56866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/domvf.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSCwAAAro"]
[Tue Jul 21 07:26:02.748873 2026] [security2:error] [pid 230252:tid 230488] [client 4.204.201.85:3200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/k.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSDgAAAwE"]
[Tue Jul 21 07:26:02.855506 2026] [security2:error] [pid 230252:tid 230496] [client 20.151.10.161:63680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/solo1.php"] [unique_id "al9JOk0Dwhk5-Z44XrpSEAAAAwk"]
[Tue Jul 21 07:26:03.102942 2026] [security2:error] [pid 230252:tid 230388] [client 4.204.201.85:3204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/blurbs.php"] [unique_id "al9JO00Dwhk5-Z44XrpSEgAAAp0"]
[Tue Jul 21 07:26:03.320545 2026] [security2:error] [pid 230252:tid 230311] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JO00Dwhk5-Z44XrpSFgACsDk"]
[Tue Jul 21 07:26:03.320684 2026] [security2:error] [pid 230252:tid 230407] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JO00Dwhk5-Z44XrpSFgACsDk"]
[Tue Jul 21 07:26:03.475528 2026] [security2:error] [pid 230252:tid 230422] [client 4.204.201.85:3273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/bajah.php"] [unique_id "al9JO00Dwhk5-Z44XrpSGAAAAr8"]
[Tue Jul 21 07:26:03.760633 2026] [security2:error] [pid 230252:tid 230477] [client 20.151.10.161:49082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-temp.php"] [unique_id "al9JO00Dwhk5-Z44XrpSHwAAAvY"]
[Tue Jul 21 07:26:04.010003 2026] [security2:error] [pid 230252:tid 230402] [client 103.162.129.114:58737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSJQAAAqs"]
[Tue Jul 21 07:26:04.010127 2026] [security2:error] [pid 230252:tid 230402] [client 103.162.129.114:58737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSJQAAAqs"]
[Tue Jul 21 07:26:04.183430 2026] [security2:error] [pid 229246:tid 229497] [client 4.204.201.85:3231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/a.php"] [unique_id "al9JPCBMYeh5YLVG45x23gAAAo0"]
[Tue Jul 21 07:26:04.189343 2026] [security2:error] [pid 230252:tid 230494] [client 139.135.44.145:54167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSKwAAAwc"]
[Tue Jul 21 07:26:04.189433 2026] [security2:error] [pid 230252:tid 230494] [client 139.135.44.145:54167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSKwAAAwc"]
[Tue Jul 21 07:26:04.283186 2026] [security2:error] [pid 229246:tid 229258] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/.git/config"] [unique_id "al9JPCBMYeh5YLVG45x25wACfAs"]
[Tue Jul 21 07:26:04.284580 2026] [security2:error] [pid 229246:tid 229369] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/rclone.conf"] [unique_id "al9JPCBMYeh5YLVG45x26AACfHo"]
[Tue Jul 21 07:26:04.285543 2026] [security2:error] [pid 229246:tid 229323] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/.aws/credentials"] [unique_id "al9JPCBMYeh5YLVG45x26gACfEw"]
[Tue Jul 21 07:26:04.285579 2026] [security2:error] [pid 229246:tid 229275] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/z9x8c7v6b5-debug-trigger-panel.gradiente.com"] [unique_id "al9JPCBMYeh5YLVG45x27AACfBw"]
[Tue Jul 21 07:26:04.296679 2026] [security2:error] [pid 230252:tid 230401] [client 74.249.245.134:5564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/default.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSLwAAAqo"]
[Tue Jul 21 07:26:04.381270 2026] [security2:error] [pid 230252:tid 230436] [client 20.151.10.161:65443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/sixxis.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSMQAAAs0"]
[Tue Jul 21 07:26:04.478265 2026] [security2:error] [pid 229246:tid 229391] [client 20.226.60.151:62377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp.php"] [unique_id "al9JPCBMYeh5YLVG45x27gAAAiM"]
[Tue Jul 21 07:26:04.495881 2026] [security2:error] [pid 229246:tid 229475] [client 4.204.201.85:3291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/edit.php"] [unique_id "al9JPCBMYeh5YLVG45x27wAAAnc"]
[Tue Jul 21 07:26:04.626912 2026] [security2:error] [pid 229246:tid 229331] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "panel.gradiente.com"] [uri "/graphql"] [unique_id "al9JPCBMYeh5YLVG45x28gACfFQ"]
[Tue Jul 21 07:26:04.662818 2026] [security2:error] [pid 229246:tid 229272] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.gitconfig"] [unique_id "al9JPCBMYeh5YLVG45x29gACfBk"]
[Tue Jul 21 07:26:04.801088 2026] [security2:error] [pid 230252:tid 230415] [client 4.204.201.85:3203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/hosty.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSNgAAArg"]
[Tue Jul 21 07:26:04.820801 2026] [security2:error] [pid 230252:tid 230327] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSNwAC1Eg"]
[Tue Jul 21 07:26:04.820921 2026] [security2:error] [pid 230252:tid 230443] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JPE0Dwhk5-Z44XrpSNwAC1Eg"]
[Tue Jul 21 07:26:04.969484 2026] [security2:error] [pid 229246:tid 229336] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "panel.gradiente.com"] [uri "/api/graphql"] [unique_id "al9JPCBMYeh5YLVG45x2-wACfFk"]
[Tue Jul 21 07:26:04.991935 2026] [security2:error] [pid 229246:tid 229263] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.env"] [unique_id "al9JPCBMYeh5YLVG45x2_QACfBA"]
[Tue Jul 21 07:26:04.992065 2026] [security2:error] [pid 229246:tid 229480] [client 34.35.143.238:47690] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/.env"] [unique_id "al9JPCBMYeh5YLVG45x2_QACfBA"]
[Tue Jul 21 07:26:05.059075 2026] [security2:error] [pid 229246:tid 229337] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/.env.example"] [unique_id "al9JPSBMYeh5YLVG45x3AQACfFo"]
[Tue Jul 21 07:26:05.180091 2026] [security2:error] [pid 230252:tid 230461] [client 4.204.201.85:3308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/k.php"] [unique_id "al9JPU0Dwhk5-Z44XrpSOQAAAuY"]
[Tue Jul 21 07:26:05.217545 2026] [security2:error] [pid 230252:tid 230488] [client 20.220.225.223:38698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JPU0Dwhk5-Z44XrpSOgAAAwE"]
[Tue Jul 21 07:26:05.238416 2026] [security2:error] [pid 230252:tid 230394] [client 172.245.102.41:27749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JPU0Dwhk5-Z44XrpSOwAAAqM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:05.321205 2026] [security2:error] [pid 229246:tid 229316] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "panel.gradiente.com"] [uri "/v1/graphql"] [unique_id "al9JPSBMYeh5YLVG45x3BAACfEU"]
[Tue Jul 21 07:26:05.494682 2026] [security2:error] [pid 229246:tid 229366] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.bak"] [unique_id "al9JPSBMYeh5YLVG45x3CwACfHc"]
[Tue Jul 21 07:26:05.494699 2026] [security2:error] [pid 229246:tid 229260] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.backup"] [unique_id "al9JPSBMYeh5YLVG45x3DAACfA0"]
[Tue Jul 21 07:26:05.552287 2026] [security2:error] [pid 230252:tid 230411] [client 4.204.201.85:3216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/aaa.php"] [unique_id "al9JPU0Dwhk5-Z44XrpSPgAAArQ"]
[Tue Jul 21 07:26:05.802929 2026] [security2:error] [pid 230252:tid 230482] [client 74.249.245.134:54343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/gettest.php"] [unique_id "al9JPU0Dwhk5-Z44XrpSQAAAAvs"]
[Tue Jul 21 07:26:05.809947 2026] [security2:error] [pid 229246:tid 229348] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.old"] [unique_id "al9JPSBMYeh5YLVG45x3FAACXWU"]
[Tue Jul 21 07:26:05.860649 2026] [security2:error] [pid 230252:tid 230453] [client 117.251.86.144:44606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JPU0Dwhk5-Z44XrpSQwAAAt4"]
[Tue Jul 21 07:26:05.860744 2026] [security2:error] [pid 230252:tid 230453] [client 117.251.86.144:44606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JPU0Dwhk5-Z44XrpSQwAAAt4"]
[Tue Jul 21 07:26:05.873458 2026] [security2:error] [pid 229246:tid 229330] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/api/.env"] [unique_id "al9JPSBMYeh5YLVG45x3GQACKFM"]
[Tue Jul 21 07:26:06.156633 2026] [security2:error] [pid 229246:tid 229352] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/config/.env"] [unique_id "al9JPiBMYeh5YLVG45x3HgACG2k"]
[Tue Jul 21 07:26:06.157537 2026] [security2:error] [pid 229246:tid 229360] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/backend/.env"] [unique_id "al9JPiBMYeh5YLVG45x3HwACG3E"]
[Tue Jul 21 07:26:06.163843 2026] [security2:error] [pid 230252:tid 230408] [client 20.226.60.151:56895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/class.php"] [unique_id "al9JPk0Dwhk5-Z44XrpSRwAAArE"]
[Tue Jul 21 07:26:06.174001 2026] [security2:error] [pid 229246:tid 229324] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/serviceAccountKey.json"] [unique_id "al9JPiBMYeh5YLVG45x3JAACSE0"]
[Tue Jul 21 07:26:06.449361 2026] [security2:error] [pid 229246:tid 229426] [client 4.204.201.85:3263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/file5.php"] [unique_id "al9JPiBMYeh5YLVG45x3LAAAAkY"]
[Tue Jul 21 07:26:06.599960 2026] [authz_core:error] [pid 229246:tid 229358] [remote 34.35.143.238:47690] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Tue Jul 21 07:26:06.647537 2026] [security2:error] [pid 229246:tid 229270] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JPiBMYeh5YLVG45x3OgACHhc"]
[Tue Jul 21 07:26:06.647633 2026] [security2:error] [pid 229246:tid 229386] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JPiBMYeh5YLVG45x3OgACHhc"]
[Tue Jul 21 07:26:06.958297 2026] [security2:error] [pid 229246:tid 229294] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.ssh/id_ed25519"] [unique_id "al9JPiBMYeh5YLVG45x3QQACfi8"]
[Tue Jul 21 07:26:06.958535 2026] [security2:error] [pid 229246:tid 229482] [client 34.35.143.238:47690] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/.ssh/id_ed25519"] [unique_id "al9JPiBMYeh5YLVG45x3QQACfi8"]
[Tue Jul 21 07:26:06.993351 2026] [security2:error] [pid 229246:tid 229267] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.ssh/id_rsa"] [unique_id "al9JPiBMYeh5YLVG45x3RAACdRQ"]
[Tue Jul 21 07:26:06.993515 2026] [security2:error] [pid 229246:tid 229339] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/docker-compose.yaml"] [unique_id "al9JPiBMYeh5YLVG45x3RQACdVw"]
[Tue Jul 21 07:26:07.002680 2026] [security2:error] [pid 229246:tid 229357] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.ssh/id_dsa"] [unique_id "al9JPyBMYeh5YLVG45x3RgACdW4"]
[Tue Jul 21 07:26:07.064564 2026] [security2:error] [pid 229246:tid 229450] [client 4.204.201.85:3293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/222.php"] [unique_id "al9JPyBMYeh5YLVG45x3SgAAAl4"]
[Tue Jul 21 07:26:07.294899 2026] [proxy:error] [pid 229246:tid 229447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:07.294976 2026] [proxy_http:error] [pid 229246:tid 229447] [client 20.151.10.161:49067] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:07.295453 2026] [proxy:error] [pid 229246:tid 229447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:07.295488 2026] [proxy_http:error] [pid 229246:tid 229447] [client 20.151.10.161:49067] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:26:07.295830 2026] [security2:error] [pid 229246:tid 229462] [client 20.226.60.151:54568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/rithin.php"] [unique_id "al9JPyBMYeh5YLVG45x3UQAAAmo"]
[Tue Jul 21 07:26:07.366638 2026] [security2:error] [pid 229246:tid 229281] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/id_ecdsa"] [unique_id "al9JPyBMYeh5YLVG45x3VwACHyI"]
[Tue Jul 21 07:26:07.376023 2026] [security2:error] [pid 229246:tid 229295] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/id_rsa"] [unique_id "al9JPyBMYeh5YLVG45x3WQACjzA"]
[Tue Jul 21 07:26:07.417175 2026] [security2:error] [pid 229246:tid 229315] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/id_dsa"] [unique_id "al9JPyBMYeh5YLVG45x3XAACb0Q"]
[Tue Jul 21 07:26:07.417316 2026] [security2:error] [pid 229246:tid 229254] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/key.pem"] [unique_id "al9JPyBMYeh5YLVG45x3XQACbwc"]
[Tue Jul 21 07:26:07.455150 2026] [security2:error] [pid 230252:tid 230286] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JP00Dwhk5-Z44XrpSTAAC2iA"]
[Tue Jul 21 07:26:07.455257 2026] [security2:error] [pid 230252:tid 230449] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JP00Dwhk5-Z44XrpSTAAC2iA"]
[Tue Jul 21 07:26:07.621910 2026] [security2:error] [pid 229246:tid 229400] [client 4.204.201.85:3278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/test.php"] [unique_id "al9JPyBMYeh5YLVG45x3YgAAAiw"]
[Tue Jul 21 07:26:07.658451 2026] [security2:error] [pid 229246:tid 229367] [remote 38.242.157.30:56412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9JPyBMYeh5YLVG45x3ZAACKXg"]
[Tue Jul 21 07:26:07.760933 2026] [security2:error] [pid 229246:tid 229345] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/privatekey.key"] [unique_id "al9JPyBMYeh5YLVG45x3aAACgGI"]
[Tue Jul 21 07:26:07.790823 2026] [security2:error] [pid 229246:tid 229369] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/ssl/server.key"] [unique_id "al9JPyBMYeh5YLVG45x3bAACUno"]
[Tue Jul 21 07:26:07.790958 2026] [security2:error] [pid 229246:tid 229438] [client 34.35.143.238:47690] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/ssl/server.key"] [unique_id "al9JPyBMYeh5YLVG45x3bAACUno"]
[Tue Jul 21 07:26:07.791315 2026] [security2:error] [pid 229246:tid 229323] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/ssl/localhost.key"] [unique_id "al9JPyBMYeh5YLVG45x3bQACUkw"]
[Tue Jul 21 07:26:07.809847 2026] [security2:error] [pid 229246:tid 229418] [client 20.220.225.223:38703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9JPyBMYeh5YLVG45x3cAAAAj4"]
[Tue Jul 21 07:26:07.830397 2026] [security2:error] [pid 229246:tid 229308] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9JPyBMYeh5YLVG45x3cQACPT0"]
[Tue Jul 21 07:26:07.830533 2026] [security2:error] [pid 229246:tid 229417] [client 34.35.143.238:47690] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9JPyBMYeh5YLVG45x3cQACPT0"]
[Tue Jul 21 07:26:07.941992 2026] [security2:error] [pid 229246:tid 229476] [client 59.96.220.140:61318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JPyBMYeh5YLVG45x3dgAAAng"]
[Tue Jul 21 07:26:07.942124 2026] [security2:error] [pid 229246:tid 229476] [client 59.96.220.140:61318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JPyBMYeh5YLVG45x3dgAAAng"]
[Tue Jul 21 07:26:08.004779 2026] [security2:error] [pid 229246:tid 229481] [client 4.204.201.85:3267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/aaa.php"] [unique_id "al9JQCBMYeh5YLVG45x3egAAAn0"]
[Tue Jul 21 07:26:08.083922 2026] [security2:error] [pid 229246:tid 229503] [client 20.151.10.161:65444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/2P.update.php"] [unique_id "al9JQCBMYeh5YLVG45x3fQAAApM"]
[Tue Jul 21 07:26:08.132208 2026] [security2:error] [pid 230252:tid 230323] [remote 188.164.197.230:53424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/wp-login.php"] [unique_id "al9JQE0Dwhk5-Z44XrpSUQAC2EU"]
[Tue Jul 21 07:26:08.181402 2026] [security2:error] [pid 229246:tid 229458] [client 20.226.60.151:56921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/echkm.php"] [unique_id "al9JQCBMYeh5YLVG45x3gAAAAmY"]
[Tue Jul 21 07:26:08.200087 2026] [security2:error] [pid 230252:tid 230304] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JQE0Dwhk5-Z44XrpSUgADEjI"]
[Tue Jul 21 07:26:08.200241 2026] [security2:error] [pid 230252:tid 230505] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JQE0Dwhk5-Z44XrpSUgADEjI"]
[Tue Jul 21 07:26:08.208805 2026] [security2:error] [pid 229246:tid 229455] [client 74.249.245.134:5536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/tfm.php"] [unique_id "al9JQCBMYeh5YLVG45x3gQAAAmM"]
[Tue Jul 21 07:26:08.335417 2026] [security2:error] [pid 229246:tid 229399] [client 4.204.201.85:3321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/11.php"] [unique_id "al9JQCBMYeh5YLVG45x3ggAAAis"]
[Tue Jul 21 07:26:08.433083 2026] [security2:error] [pid 229246:tid 229337] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.hermes/.env"] [unique_id "al9JQCBMYeh5YLVG45x3jQACZFo"]
[Tue Jul 21 07:26:08.778866 2026] [security2:error] [pid 229246:tid 229478] [client 152.59.154.239:64321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQCBMYeh5YLVG45x3lAAAAno"]
[Tue Jul 21 07:26:08.782940 2026] [security2:error] [pid 229246:tid 229321] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/.claude/settings.json"] [unique_id "al9JQCBMYeh5YLVG45x3mQACfko"]
[Tue Jul 21 07:26:08.803732 2026] [security2:error] [pid 229246:tid 229407] [client 4.204.201.85:3221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/mac.php"] [unique_id "al9JQCBMYeh5YLVG45x3nAAAAjM"]
[Tue Jul 21 07:26:08.985646 2026] [security2:error] [pid 230252:tid 230437] [client 103.106.20.201:62962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQE0Dwhk5-Z44XrpSVgAAAs4"]
[Tue Jul 21 07:26:08.985769 2026] [security2:error] [pid 230252:tid 230437] [client 103.106.20.201:62962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQE0Dwhk5-Z44XrpSVgAAAs4"]
[Tue Jul 21 07:26:09.073579 2026] [security2:error] [pid 229246:tid 229376] [client 45.251.232.145:63399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQSBMYeh5YLVG45x3pQAAAhQ"]
[Tue Jul 21 07:26:09.074183 2026] [security2:error] [pid 229246:tid 229376] [client 45.251.232.145:63399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQSBMYeh5YLVG45x3pQAAAhQ"]
[Tue Jul 21 07:26:09.153255 2026] [security2:error] [pid 229246:tid 229250] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "panel.gradiente.com"] [uri "/wp-config.php.old"] [unique_id "al9JQSBMYeh5YLVG45x3qQACcgM"]
[Tue Jul 21 07:26:09.177895 2026] [security2:error] [pid 229246:tid 229374] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "panel.gradiente.com"] [uri "/wp-config.php.bak"] [unique_id "al9JQSBMYeh5YLVG45x3qwACMn8"]
[Tue Jul 21 07:26:09.187602 2026] [security2:error] [pid 229246:tid 229330] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/laravel/.env"] [unique_id "al9JQSBMYeh5YLVG45x3rgACMlM"]
[Tue Jul 21 07:26:09.214830 2026] [security2:error] [pid 229246:tid 229499] [client 4.204.201.85:3301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/chosen.php"] [unique_id "al9JQSBMYeh5YLVG45x3rwAAAo8"]
[Tue Jul 21 07:26:09.256692 2026] [security2:error] [pid 229246:tid 229264] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.env.php.bak"] [unique_id "al9JQSBMYeh5YLVG45x3sQACQRE"]
[Tue Jul 21 07:26:09.258193 2026] [security2:error] [pid 229246:tid 229352] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/core/.env"] [unique_id "al9JQSBMYeh5YLVG45x3sgACQWk"]
[Tue Jul 21 07:26:09.260447 2026] [security2:error] [pid 229246:tid 229360] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/config/.env.php"] [unique_id "al9JQSBMYeh5YLVG45x3swACQXE"]
[Tue Jul 21 07:26:09.527134 2026] [security2:error] [pid 230252:tid 230420] [client 103.174.34.15:59756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQU0Dwhk5-Z44XrpSWAAAAr0"]
[Tue Jul 21 07:26:09.527276 2026] [security2:error] [pid 230252:tid 230420] [client 103.174.34.15:59756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQU0Dwhk5-Z44XrpSWAAAAr0"]
[Tue Jul 21 07:26:09.531736 2026] [security2:error] [pid 229246:tid 229256] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/auth.json"] [unique_id "al9JQSBMYeh5YLVG45x3uAACKQk"]
[Tue Jul 21 07:26:09.547914 2026] [security2:error] [pid 229246:tid 229310] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/config.php.bak"] [unique_id "al9JQSBMYeh5YLVG45x3uQACbD8"]
[Tue Jul 21 07:26:09.547929 2026] [security2:error] [pid 229246:tid 229299] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/configuration.php.bak"] [unique_id "al9JQSBMYeh5YLVG45x3ugACbDQ"]
[Tue Jul 21 07:26:09.556713 2026] [security2:error] [pid 229246:tid 229328] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.env.swp"] [unique_id "al9JQSBMYeh5YLVG45x3vgACbFE"]
[Tue Jul 21 07:26:09.602487 2026] [security2:error] [pid 229246:tid 229314] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/web/.env"] [unique_id "al9JQSBMYeh5YLVG45x3vwACGEM"]
[Tue Jul 21 07:26:09.628562 2026] [security2:error] [pid 229246:tid 229284] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/public/.env"] [unique_id "al9JQSBMYeh5YLVG45x3wAACcSU"]
[Tue Jul 21 07:26:09.816178 2026] [security2:error] [pid 230252:tid 230467] [client 4.204.201.85:3212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/cream1.php"] [unique_id "al9JQU0Dwhk5-Z44XrpSWQAAAuw"]
[Tue Jul 21 07:26:09.845314 2026] [security2:error] [pid 229246:tid 229277] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JQSBMYeh5YLVG45x3xgACWR4"]
[Tue Jul 21 07:26:09.845443 2026] [security2:error] [pid 229246:tid 229445] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JQSBMYeh5YLVG45x3xgACWR4"]
[Tue Jul 21 07:26:09.904074 2026] [security2:error] [pid 229246:tid 229465] [client 20.52.136.55:1568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/g.php"] [unique_id "al9JQSBMYeh5YLVG45x3yAAAAm0"]
[Tue Jul 21 07:26:09.943619 2026] [security2:error] [pid 229246:tid 229485] [client 20.226.60.151:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/lib.php"] [unique_id "al9JQSBMYeh5YLVG45x3ywAAAoE"]
[Tue Jul 21 07:26:10.113591 2026] [security2:error] [pid 229246:tid 229294] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/bootstrap.yml"] [unique_id "al9JQiBMYeh5YLVG45x31AACUi8"]
[Tue Jul 21 07:26:10.197012 2026] [security2:error] [pid 229246:tid 229267] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/appsettings.json"] [unique_id "al9JQiBMYeh5YLVG45x31wACPRQ"]
[Tue Jul 21 07:26:10.270123 2026] [security2:error] [pid 229246:tid 229339] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JQiBMYeh5YLVG45x32AACglw"]
[Tue Jul 21 07:26:10.270298 2026] [security2:error] [pid 229246:tid 229486] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JQiBMYeh5YLVG45x32AACglw"]
[Tue Jul 21 07:26:10.425223 2026] [security2:error] [pid 230252:tid 230494] [client 193.36.225.73:53133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JQk0Dwhk5-Z44XrpSWwAAAwc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:10.427730 2026] [security2:error] [pid 229246:tid 229425] [client 47.128.20.204:32092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.somoszeroum.com.br"] [uri "/robots.txt"] [unique_id "al9JQiBMYeh5YLVG45x33QAAAkU"]
[Tue Jul 21 07:26:10.439343 2026] [security2:error] [pid 229246:tid 229319] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/appsettings.Production.json"] [unique_id "al9JQiBMYeh5YLVG45x33gACkUg"]
[Tue Jul 21 07:26:10.439473 2026] [security2:error] [pid 229246:tid 229501] [client 34.35.143.238:47690] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/appsettings.Production.json"] [unique_id "al9JQiBMYeh5YLVG45x33gACkUg"]
[Tue Jul 21 07:26:10.451440 2026] [security2:error] [pid 229246:tid 229305] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/web.config"] [unique_id "al9JQiBMYeh5YLVG45x34QACfTo"]
[Tue Jul 21 07:26:10.515681 2026] [security2:error] [pid 230252:tid 230499] [client 175.45.70.82:50161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQk0Dwhk5-Z44XrpSXAAAAww"]
[Tue Jul 21 07:26:10.515827 2026] [security2:error] [pid 230252:tid 230499] [client 175.45.70.82:50161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQk0Dwhk5-Z44XrpSXAAAAww"]
[Tue Jul 21 07:26:10.890929 2026] [security2:error] [pid 229246:tid 229312] [remote 217.181.92.4:29811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.92.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JQSBMYeh5YLVG45x3xwACVUE"]
[Tue Jul 21 07:26:11.326862 2026] [security2:error] [pid 229246:tid 229276] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/src/.env"] [unique_id "al9JQyBMYeh5YLVG45x4BQACdR0"]
[Tue Jul 21 07:26:11.327085 2026] [security2:error] [pid 229246:tid 229473] [client 34.35.143.238:47690] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/src/.env"] [unique_id "al9JQyBMYeh5YLVG45x4BQACdR0"]
[Tue Jul 21 07:26:11.341607 2026] [security2:error] [pid 229246:tid 229369] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/frontend/.env"] [unique_id "al9JQyBMYeh5YLVG45x4CQAChXo"]
[Tue Jul 21 07:26:11.361017 2026] [security2:error] [pid 229246:tid 229426] [client 154.192.233.199:58654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQyBMYeh5YLVG45x4EAAAAkY"]
[Tue Jul 21 07:26:11.361128 2026] [security2:error] [pid 229246:tid 229426] [client 154.192.233.199:58654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JQyBMYeh5YLVG45x4EAAAAkY"]
[Tue Jul 21 07:26:11.368032 2026] [security2:error] [pid 229246:tid 229331] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/app/.env"] [unique_id "al9JQyBMYeh5YLVG45x4EQACXlQ"]
[Tue Jul 21 07:26:11.394656 2026] [security2:error] [pid 229246:tid 229448] [client 4.204.201.85:26574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/dr.php"] [unique_id "al9JQyBMYeh5YLVG45x4EgAAAlw"]
[Tue Jul 21 07:26:11.437306 2026] [security2:error] [pid 229246:tid 229451] [client 20.226.60.151:54542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/fffm.php"] [unique_id "al9JQyBMYeh5YLVG45x4FAAAAl8"]
[Tue Jul 21 07:26:11.629976 2026] [security2:error] [pid 229246:tid 229406] [client 20.52.136.55:1734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/nf.php"] [unique_id "al9JQyBMYeh5YLVG45x4GgAAAjI"]
[Tue Jul 21 07:26:11.722820 2026] [security2:error] [pid 229246:tid 229282] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/@fs/root/.env"] [unique_id "al9JQyBMYeh5YLVG45x4IAACTiM"]
[Tue Jul 21 07:26:11.722876 2026] [security2:error] [pid 229246:tid 229293] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/staging/.env"] [unique_id "al9JQyBMYeh5YLVG45x4HwACTi4"]
[Tue Jul 21 07:26:11.722948 2026] [security2:error] [pid 229246:tid 229336] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/production/.env"] [unique_id "al9JQyBMYeh5YLVG45x4HQACTlk"]
[Tue Jul 21 07:26:11.723027 2026] [security2:error] [pid 229246:tid 229263] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/@fs/.env"] [unique_id "al9JQyBMYeh5YLVG45x4IwACThA"]
[Tue Jul 21 07:26:11.723079 2026] [security2:error] [pid 229246:tid 229365] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/server/.env"] [unique_id "al9JQyBMYeh5YLVG45x4JAACTnY"]
[Tue Jul 21 07:26:11.723303 2026] [security2:error] [pid 229246:tid 229334] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.production.bak"] [unique_id "al9JQyBMYeh5YLVG45x4HgACTlc"]
[Tue Jul 21 07:26:11.723309 2026] [security2:error] [pid 229246:tid 229337] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.prod.bak"] [unique_id "al9JQyBMYeh5YLVG45x4IQACTlo"]
[Tue Jul 21 07:26:11.723704 2026] [security2:error] [pid 229246:tid 229353] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/docker/.env"] [unique_id "al9JQyBMYeh5YLVG45x4IgACTmo"]
[Tue Jul 21 07:26:11.724415 2026] [security2:error] [pid 229246:tid 229343] [remote 34.35.143.238:47690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/dev/.env"] [unique_id "al9JQyBMYeh5YLVG45x4JgACTmA"]
[Tue Jul 21 07:26:11.724918 2026] [security2:error] [pid 229246:tid 229317] [remote 34.35.143.238:47690] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "panel.gradiente.com"] [uri "/@fs/proc/self/environ"] [unique_id "al9JQyBMYeh5YLVG45x4JwACTkY"]
[Tue Jul 21 07:26:11.772542 2026] [security2:error] [pid 229246:tid 229409] [client 20.220.225.223:46135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ez.php"] [unique_id "al9JQyBMYeh5YLVG45x4KAAAAjU"]
[Tue Jul 21 07:26:11.789000 2026] [security2:error] [pid 230252:tid 230500] [client 20.151.10.161:49065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9JQ00Dwhk5-Z44XrpSagAAAw0"]
[Tue Jul 21 07:26:11.867868 2026] [security2:error] [pid 229246:tid 229431] [client 4.204.201.85:3225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/x.php"] [unique_id "al9JQyBMYeh5YLVG45x4KgAAAks"]
[Tue Jul 21 07:26:11.875587 2026] [security2:error] [pid 230252:tid 230487] [client 216.73.160.34:31409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9JQ00Dwhk5-Z44XrpSbAAAAwA"]
[Tue Jul 21 07:26:11.881105 2026] [security2:error] [pid 230252:tid 230407] [client 216.73.160.177:31653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9JQ00Dwhk5-Z44XrpSawAAArA"]
[Tue Jul 21 07:26:11.883546 2026] [security2:error] [pid 230252:tid 230425] [client 216.73.160.43:50327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9JQ00Dwhk5-Z44XrpSbgAAAsI"]
[Tue Jul 21 07:26:12.127714 2026] [security2:error] [pid 230252:tid 230404] [client 20.226.60.151:56836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/login.php"] [unique_id "al9JRE0Dwhk5-Z44XrpScgAAAq0"]
[Tue Jul 21 07:26:12.422199 2026] [security2:error] [pid 230252:tid 230409] [client 4.204.201.85:3307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/155.php"] [unique_id "al9JRE0Dwhk5-Z44XrpSdQAAArI"]
[Tue Jul 21 07:26:12.441048 2026] [security2:error] [pid 230252:tid 230447] [client 74.249.245.134:54372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/ws81.php"] [unique_id "al9JRE0Dwhk5-Z44XrpSdgAAAtg"]
[Tue Jul 21 07:26:12.683028 2026] [security2:error] [pid 229246:tid 229442] [client 20.220.225.223:46142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/fz.php"] [unique_id "al9JRCBMYeh5YLVG45x4MgAAAlY"]
[Tue Jul 21 07:26:12.777128 2026] [security2:error] [pid 230252:tid 230429] [client 4.204.201.85:3288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ops.php"] [unique_id "al9JRE0Dwhk5-Z44XrpSeAAAAsY"]
[Tue Jul 21 07:26:12.927980 2026] [security2:error] [pid 230252:tid 230262] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JRE0Dwhk5-Z44XrpSewACqgg"]
[Tue Jul 21 07:26:12.928168 2026] [security2:error] [pid 230252:tid 230401] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JRE0Dwhk5-Z44XrpSewACqgg"]
[Tue Jul 21 07:26:12.985611 2026] [security2:error] [pid 230252:tid 230256] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/values.yaml"] [unique_id "al9JRE0Dwhk5-Z44XrpSfAACogI"]
[Tue Jul 21 07:26:12.985897 2026] [security2:error] [pid 230252:tid 230393] [client 34.35.143.238:47704] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/values.yaml"] [unique_id "al9JRE0Dwhk5-Z44XrpSfAACogI"]
[Tue Jul 21 07:26:13.000682 2026] [security2:error] [pid 230252:tid 230377] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/sa.json"] [unique_id "al9JRU0Dwhk5-Z44XrpSfgACuno"]
[Tue Jul 21 07:26:13.047345 2026] [security2:error] [pid 230252:tid 230413] [client 216.73.160.174:56211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9JQ00Dwhk5-Z44XrpSbQAAArY"]
[Tue Jul 21 07:26:13.131688 2026] [security2:error] [pid 229246:tid 229418] [client 4.204.201.85:26576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/file31.php"] [unique_id "al9JRSBMYeh5YLVG45x4NwAAAj4"]
[Tue Jul 21 07:26:13.470316 2026] [security2:error] [pid 230252:tid 230254] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/config.js"] [unique_id "al9JRU0Dwhk5-Z44XrpSkQADDwA"]
[Tue Jul 21 07:26:13.672751 2026] [security2:error] [pid 229246:tid 229432] [client 4.204.201.85:3299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/file6.php"] [unique_id "al9JRSBMYeh5YLVG45x4PgAAAkw"]
[Tue Jul 21 07:26:13.786984 2026] [security2:error] [pid 229246:tid 229338] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JRSBMYeh5YLVG45x4QQACU1s"]
[Tue Jul 21 07:26:13.787135 2026] [security2:error] [pid 229246:tid 229439] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JRSBMYeh5YLVG45x4QQACU1s"]
[Tue Jul 21 07:26:13.835754 2026] [security2:error] [pid 230252:tid 230419] [client 20.226.60.151:62344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/a2.php"] [unique_id "al9JRU0Dwhk5-Z44XrpSnQAAArw"]
[Tue Jul 21 07:26:13.944773 2026] [security2:error] [pid 230252:tid 230465] [client 20.220.225.223:38680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/wander.php"] [unique_id "al9JRU0Dwhk5-Z44XrpSnwAAAuo"]
[Tue Jul 21 07:26:14.123352 2026] [security2:error] [pid 230252:tid 230460] [client 74.249.245.134:54379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/222.php"] [unique_id "al9JRk0Dwhk5-Z44XrpSpgAAAuU"]
[Tue Jul 21 07:26:14.423106 2026] [security2:error] [pid 229246:tid 229479] [client 4.204.201.85:3309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/adminfuns.php"] [unique_id "al9JRiBMYeh5YLVG45x4RwAAAns"]
[Tue Jul 21 07:26:14.432676 2026] [security2:error] [pid 229246:tid 229428] [client 20.151.10.161:63689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/a.php"] [unique_id "al9JRiBMYeh5YLVG45x4SAAAAkg"]
[Tue Jul 21 07:26:14.473398 2026] [security2:error] [pid 230252:tid 230342] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/openapi.json"] [unique_id "al9JRk0Dwhk5-Z44XrpSugAC9lc"]
[Tue Jul 21 07:26:14.473553 2026] [security2:error] [pid 230252:tid 230477] [client 34.35.143.238:47704] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/openapi.json"] [unique_id "al9JRk0Dwhk5-Z44XrpSugAC9lc"]
[Tue Jul 21 07:26:14.487399 2026] [security2:error] [pid 229246:tid 229388] [client 103.162.129.114:59197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JRiBMYeh5YLVG45x4SQAAAiA"]
[Tue Jul 21 07:26:14.487516 2026] [security2:error] [pid 229246:tid 229388] [client 103.162.129.114:59197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JRiBMYeh5YLVG45x4SQAAAiA"]
[Tue Jul 21 07:26:14.729891 2026] [security2:error] [pid 230252:tid 230453] [client 139.135.44.145:54921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JRk0Dwhk5-Z44XrpSwQAAAt4"]
[Tue Jul 21 07:26:14.729997 2026] [security2:error] [pid 230252:tid 230453] [client 139.135.44.145:54921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JRk0Dwhk5-Z44XrpSwQAAAt4"]
[Tue Jul 21 07:26:14.782448 2026] [security2:error] [pid 230252:tid 230284] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/health"] [unique_id "al9JRk0Dwhk5-Z44XrpSwwACqB4"]
[Tue Jul 21 07:26:14.790950 2026] [security2:error] [pid 230252:tid 230351] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/__env.js"] [unique_id "al9JRk0Dwhk5-Z44XrpSxAAC2mA"]
[Tue Jul 21 07:26:14.791089 2026] [security2:error] [pid 230252:tid 230449] [client 34.35.143.238:47704] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/__env.js"] [unique_id "al9JRk0Dwhk5-Z44XrpSxAAC2mA"]
[Tue Jul 21 07:26:14.841864 2026] [security2:error] [pid 230252:tid 230400] [client 4.204.201.85:3289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/goods.php"] [unique_id "al9JRk0Dwhk5-Z44XrpSxgAAAqk"]
[Tue Jul 21 07:26:14.853322 2026] [security2:error] [pid 230252:tid 230427] [client 20.226.60.151:62390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/d61.php"] [unique_id "al9JRk0Dwhk5-Z44XrpSyAAAAsQ"]
[Tue Jul 21 07:26:15.316978 2026] [security2:error] [pid 230252:tid 230398] [client 193.36.225.57:59295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JR00Dwhk5-Z44XrpS1wAAAqc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:15.365826 2026] [security2:error] [pid 230252:tid 230272] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/actuator/mappings"] [unique_id "al9JR00Dwhk5-Z44XrpS2wACxhI"]
[Tue Jul 21 07:26:15.367453 2026] [security2:error] [pid 230252:tid 230274] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/info.php"] [unique_id "al9JR00Dwhk5-Z44XrpS3AACxhQ"]
[Tue Jul 21 07:26:15.367833 2026] [security2:error] [pid 230252:tid 230278] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/phpinfo.php"] [unique_id "al9JR00Dwhk5-Z44XrpS3QACxhg"]
[Tue Jul 21 07:26:15.378797 2026] [security2:error] [pid 230252:tid 230509] [client 4.204.201.85:3284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/100.php"] [unique_id "al9JR00Dwhk5-Z44XrpS3gAAAxY"]
[Tue Jul 21 07:26:15.397028 2026] [security2:error] [pid 230252:tid 230318] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JR00Dwhk5-Z44XrpS3wADFUA"]
[Tue Jul 21 07:26:15.397168 2026] [security2:error] [pid 230252:tid 230508] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JR00Dwhk5-Z44XrpS3wADFUA"]
[Tue Jul 21 07:26:15.559407 2026] [security2:error] [pid 230252:tid 230308] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/pi.php"] [unique_id "al9JR00Dwhk5-Z44XrpS4wACvTY"]
[Tue Jul 21 07:26:15.692437 2026] [security2:error] [pid 229246:tid 229382] [client 74.249.245.134:5526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/t.php"] [unique_id "al9JRyBMYeh5YLVG45x4VgAAAho"]
[Tue Jul 21 07:26:15.745140 2026] [security2:error] [pid 230252:tid 230434] [client 4.204.201.85:3276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/about.php"] [unique_id "al9JR00Dwhk5-Z44XrpS6AAAAss"]
[Tue Jul 21 07:26:15.794071 2026] [security2:error] [pid 230252:tid 230352] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/test.php"] [unique_id "al9JR00Dwhk5-Z44XrpS6wAC4WE"]
[Tue Jul 21 07:26:15.799388 2026] [security2:error] [pid 230252:tid 230282] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/i.php"] [unique_id "al9JR00Dwhk5-Z44XrpS7wAC-Rw"]
[Tue Jul 21 07:26:15.875291 2026] [security2:error] [pid 230252:tid 230303] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/app_dev.php"] [unique_id "al9JR00Dwhk5-Z44XrpS9QAC6zE"]
[Tue Jul 21 07:26:15.924319 2026] [security2:error] [pid 230252:tid 230311] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/_ignition/health-check"] [unique_id "al9JR00Dwhk5-Z44XrpS9gADCTk"]
[Tue Jul 21 07:26:15.925100 2026] [security2:error] [pid 230252:tid 230361] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/app_dev.php/_profiler"] [unique_id "al9JR00Dwhk5-Z44XrpS9wACvGo"]
[Tue Jul 21 07:26:15.969274 2026] [security2:error] [pid 230252:tid 230269] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/_debugbar/open"] [unique_id "al9JR00Dwhk5-Z44XrpS-QAC-A8"]
[Tue Jul 21 07:26:16.047357 2026] [security2:error] [pid 229246:tid 229466] [client 4.204.201.85:3222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/about.php"] [unique_id "al9JSCBMYeh5YLVG45x4XAAAAm4"]
[Tue Jul 21 07:26:16.214439 2026] [security2:error] [pid 230252:tid 230327] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/trace.axd"] [unique_id "al9JSE0Dwhk5-Z44XrpS_AADD0g"]
[Tue Jul 21 07:26:16.214700 2026] [security2:error] [pid 230252:tid 230330] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/elmah.axd"] [unique_id "al9JSE0Dwhk5-Z44XrpS_gADD0s"]
[Tue Jul 21 07:26:16.214796 2026] [security2:error] [pid 230252:tid 230502] [client 34.35.143.238:47704] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/elmah.axd"] [unique_id "al9JSE0Dwhk5-Z44XrpS_gADD0s"]
[Tue Jul 21 07:26:16.216004 2026] [security2:error] [pid 230252:tid 230338] [remote 34.35.143.238:47704] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/server-info"] [unique_id "al9JSE0Dwhk5-Z44XrpS_wADD1M"]
[Tue Jul 21 07:26:16.272037 2026] [security2:error] [pid 230252:tid 230460] [client 20.226.60.151:63348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/info.php"] [unique_id "al9JSE0Dwhk5-Z44XrpTBQAAAuU"]
[Tue Jul 21 07:26:16.399895 2026] [access_compat:error] [pid 230252:tid 230317] [remote 34.35.143.238:47704] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:26:16.408823 2026] [security2:error] [pid 230252:tid 230435] [client 4.204.201.85:3305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/admin.php"] [unique_id "al9JSE0Dwhk5-Z44XrpTEAAAAsw"]
[Tue Jul 21 07:26:16.444586 2026] [security2:error] [pid 230252:tid 230457] [client 20.226.60.151:54567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/dfre.php"] [unique_id "al9JSE0Dwhk5-Z44XrpTEgAAAuI"]
[Tue Jul 21 07:26:16.500939 2026] [security2:error] [pid 230252:tid 230425] [client 20.220.225.223:31185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/jga.php"] [unique_id "al9JSE0Dwhk5-Z44XrpTEwAAAsI"]
[Tue Jul 21 07:26:16.606761 2026] [security2:error] [pid 229246:tid 229467] [client 117.251.86.144:43378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JSCBMYeh5YLVG45x4YAAAAm8"]
[Tue Jul 21 07:26:16.606890 2026] [security2:error] [pid 229246:tid 229467] [client 117.251.86.144:43378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JSCBMYeh5YLVG45x4YAAAAm8"]
[Tue Jul 21 07:26:16.798746 2026] [security2:error] [pid 229246:tid 229469] [client 74.249.245.134:54358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/a.php"] [unique_id "al9JSCBMYeh5YLVG45x4YwAAAnE"]
[Tue Jul 21 07:26:16.828638 2026] [security2:error] [pid 230252:tid 230453] [client 4.204.201.85:3217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/admin.php"] [unique_id "al9JSE0Dwhk5-Z44XrpTFgAAAt4"]
[Tue Jul 21 07:26:17.122333 2026] [security2:error] [pid 229246:tid 229485] [client 20.226.60.151:56915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/11.php"] [unique_id "al9JSSBMYeh5YLVG45x4ZgAAAoE"]
[Tue Jul 21 07:26:17.221537 2026] [security2:error] [pid 230252:tid 230476] [client 4.204.201.85:3323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/themes.php"] [unique_id "al9JSU0Dwhk5-Z44XrpTGwAAAvU"]
[Tue Jul 21 07:26:17.275037 2026] [security2:error] [pid 230252:tid 230377] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JSU0Dwhk5-Z44XrpTHAACoXo"]
[Tue Jul 21 07:26:17.275214 2026] [security2:error] [pid 230252:tid 230392] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JSU0Dwhk5-Z44XrpTHAACoXo"]
[Tue Jul 21 07:26:17.494075 2026] [security2:error] [pid 230252:tid 230486] [client 74.249.245.134:54391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/a1.php"] [unique_id "al9JSU0Dwhk5-Z44XrpTHwAAAv8"]
[Tue Jul 21 07:26:17.526371 2026] [security2:error] [pid 229246:tid 229491] [client 20.220.225.223:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/la.php"] [unique_id "al9JSSBMYeh5YLVG45x4awAAAoc"]
[Tue Jul 21 07:26:18.079708 2026] [security2:error] [pid 229246:tid 229327] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JSiBMYeh5YLVG45x4dAACgFA"]
[Tue Jul 21 07:26:18.079898 2026] [security2:error] [pid 229246:tid 229484] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JSiBMYeh5YLVG45x4dAACgFA"]
[Tue Jul 21 07:26:18.235905 2026] [security2:error] [pid 230252:tid 230403] [client 20.220.225.223:38707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/x.php"] [unique_id "al9JSk0Dwhk5-Z44XrpTKgAAAqw"]
[Tue Jul 21 07:26:18.327593 2026] [security2:error] [pid 229246:tid 229483] [client 4.204.201.85:3268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/.well-known/about.php"] [unique_id "al9JSiBMYeh5YLVG45x4eQAAAn8"]
[Tue Jul 21 07:26:18.378464 2026] [security2:error] [pid 230252:tid 230494] [client 20.52.136.55:1776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/xda.php"] [unique_id "al9JSk0Dwhk5-Z44XrpTKwAAAwc"]
[Tue Jul 21 07:26:18.602970 2026] [security2:error] [pid 230252:tid 230386] [client 74.249.245.134:54392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/w.php"] [unique_id "al9JSk0Dwhk5-Z44XrpTLgAAAps"]
[Tue Jul 21 07:26:18.652402 2026] [security2:error] [pid 230252:tid 230358] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.git/HEAD"] [unique_id "al9JSk0Dwhk5-Z44XrpTLwACyWc"]
[Tue Jul 21 07:26:18.652608 2026] [security2:error] [pid 230252:tid 230432] [client 34.35.143.238:58534] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/.git/HEAD"] [unique_id "al9JSk0Dwhk5-Z44XrpTLwACyWc"]
[Tue Jul 21 07:26:18.694084 2026] [security2:error] [pid 230252:tid 230367] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JSk0Dwhk5-Z44XrpTPgADCXA"]
[Tue Jul 21 07:26:18.694226 2026] [security2:error] [pid 230252:tid 230496] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JSk0Dwhk5-Z44XrpTPgADCXA"]
[Tue Jul 21 07:26:18.766078 2026] [security2:error] [pid 229246:tid 229440] [client 4.204.201.85:3236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9JSiBMYeh5YLVG45x4iQAAAlQ"]
[Tue Jul 21 07:26:18.790822 2026] [security2:error] [pid 230252:tid 230433] [client 20.220.225.223:46100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/nhvoanpl.php"] [unique_id "al9JSk0Dwhk5-Z44XrpTQAAAAso"]
[Tue Jul 21 07:26:18.809149 2026] [security2:error] [pid 229246:tid 229399] [client 173.252.95.13:44922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JSiBMYeh5YLVG45x4igAAAis"]
[Tue Jul 21 07:26:18.822280 2026] [security2:error] [pid 229246:tid 229498] [client 20.226.60.151:56832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/v2.php"] [unique_id "al9JSiBMYeh5YLVG45x4iwAAAo4"]
[Tue Jul 21 07:26:18.931438 2026] [security2:error] [pid 229246:tid 229408] [client 62.102.148.164:39222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JSiBMYeh5YLVG45x4jwAAAjQ"]
[Tue Jul 21 07:26:18.931549 2026] [security2:error] [pid 229246:tid 229408] [client 62.102.148.164:39222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JSiBMYeh5YLVG45x4jwAAAjQ"]
[Tue Jul 21 07:26:19.101424 2026] [security2:error] [pid 230252:tid 230288] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env"] [unique_id "al9JS00Dwhk5-Z44XrpTRAADECI"]
[Tue Jul 21 07:26:19.254589 2026] [security2:error] [pid 230252:tid 230404] [client 4.204.201.85:3207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wefile.php"] [unique_id "al9JS00Dwhk5-Z44XrpTSwAAAq0"]
[Tue Jul 21 07:26:19.320964 2026] [security2:error] [pid 230252:tid 230447] [client 82.102.28.107:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JS00Dwhk5-Z44XrpTTQAAAtg"]
[Tue Jul 21 07:26:19.321059 2026] [security2:error] [pid 230252:tid 230447] [client 82.102.28.107:59322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JS00Dwhk5-Z44XrpTTQAAAtg"]
[Tue Jul 21 07:26:19.540262 2026] [security2:error] [pid 230252:tid 230295] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/.env.local"] [unique_id "al9JS00Dwhk5-Z44XrpTUwACzSk"]
[Tue Jul 21 07:26:19.543245 2026] [security2:error] [pid 229246:tid 229453] [client 45.251.232.145:63918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JSyBMYeh5YLVG45x4mQAAAmE"]
[Tue Jul 21 07:26:19.543385 2026] [security2:error] [pid 229246:tid 229453] [client 45.251.232.145:63918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JSyBMYeh5YLVG45x4mQAAAmE"]
[Tue Jul 21 07:26:19.596868 2026] [security2:error] [pid 230252:tid 230428] [client 103.106.20.201:63532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JS00Dwhk5-Z44XrpTVgAAAsU"]
[Tue Jul 21 07:26:19.596998 2026] [security2:error] [pid 230252:tid 230428] [client 103.106.20.201:63532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JS00Dwhk5-Z44XrpTVgAAAsU"]
[Tue Jul 21 07:26:19.621989 2026] [security2:error] [pid 230252:tid 230469] [client 74.7.228.20:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "locadoracmd.com.br"] [uri "/index.php"] [unique_id "al9JSE0Dwhk5-Z44XrpTBAAAAu4"]
[Tue Jul 21 07:26:19.624677 2026] [security2:error] [pid 230252:tid 230415] [client 4.204.201.85:3300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9JS00Dwhk5-Z44XrpTVwAAArg"]
[Tue Jul 21 07:26:19.625026 2026] [security2:error] [pid 230252:tid 230465] [client 74.7.228.20:40708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "locadoracmd.com.br"] [uri "/robots.txt"] [unique_id "al9JSE0Dwhk5-Z44XrpTAgAC6mM"]
[Tue Jul 21 07:26:19.742083 2026] [security2:error] [pid 230252:tid 230339] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.backup"] [unique_id "al9JS00Dwhk5-Z44XrpTWAAC91Q"]
[Tue Jul 21 07:26:19.797790 2026] [security2:error] [pid 230252:tid 230371] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/api/.env"] [unique_id "al9JS00Dwhk5-Z44XrpTWQACm3Q"]
[Tue Jul 21 07:26:19.805001 2026] [security2:error] [pid 230252:tid 230322] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/backend/.env"] [unique_id "al9JS00Dwhk5-Z44XrpTWgAC5UQ"]
[Tue Jul 21 07:26:19.819123 2026] [security2:error] [pid 230252:tid 230382] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.bak"] [unique_id "al9JS00Dwhk5-Z44XrpTWwAC5H8"]
[Tue Jul 21 07:26:19.822785 2026] [security2:error] [pid 230252:tid 230375] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.old"] [unique_id "al9JS00Dwhk5-Z44XrpTXQACw3g"]
[Tue Jul 21 07:26:19.865304 2026] [security2:error] [pid 230252:tid 230360] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "gradiente.com"] [uri "/graphql"] [unique_id "al9JS00Dwhk5-Z44XrpTXwACw2k"]
[Tue Jul 21 07:26:19.886328 2026] [security2:error] [pid 230252:tid 230441] [client 20.220.225.223:46083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/inso.php"] [unique_id "al9JS00Dwhk5-Z44XrpTYAAAAtI"]
[Tue Jul 21 07:26:19.993178 2026] [security2:error] [pid 229246:tid 229500] [client 152.59.154.239:64729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JSyBMYeh5YLVG45x4nwAAApA"]
[Tue Jul 21 07:26:20.088304 2026] [security2:error] [pid 230252:tid 230364] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/config/.env"] [unique_id "al9JTE0Dwhk5-Z44XrpTYwACsW0"]
[Tue Jul 21 07:26:20.210912 2026] [security2:error] [pid 230252:tid 230307] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "gradiente.com"] [uri "/api/graphql"] [unique_id "al9JTE0Dwhk5-Z44XrpTcgAC8zU"]
[Tue Jul 21 07:26:20.289307 2026] [security2:error] [pid 230252:tid 230504] [client 103.174.34.15:60228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JTE0Dwhk5-Z44XrpTdgAAAxE"]
[Tue Jul 21 07:26:20.289465 2026] [security2:error] [pid 230252:tid 230504] [client 103.174.34.15:60228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JTE0Dwhk5-Z44XrpTdgAAAxE"]
[Tue Jul 21 07:26:20.458809 2026] [security2:error] [pid 230252:tid 230475] [client 74.249.245.134:5561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/wp-good.php"] [unique_id "al9JTE0Dwhk5-Z44XrpTfQAAAvQ"]
[Tue Jul 21 07:26:20.503067 2026] [authz_core:error] [pid 230252:tid 230498] [client 34.35.143.238:0] AH01630: client denied by server configuration: /home2/rica0429/public_html/.htpasswd
[Tue Jul 21 07:26:20.568132 2026] [security2:error] [pid 230252:tid 230506] [client 173.252.95.3:48658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JS00Dwhk5-Z44XrpTTgAAAxM"]
[Tue Jul 21 07:26:20.570011 2026] [security2:error] [pid 229246:tid 229386] [client 59.96.220.140:61726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JTCBMYeh5YLVG45x4qgAAAh4"]
[Tue Jul 21 07:26:20.570711 2026] [security2:error] [pid 229246:tid 229386] [client 59.96.220.140:61726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JTCBMYeh5YLVG45x4qgAAAh4"]
[Tue Jul 21 07:26:20.572685 2026] [security2:error] [pid 230252:tid 230260] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "gradiente.com"] [uri "/v1/graphql"] [unique_id "al9JTE0Dwhk5-Z44XrpThQADCgY"]
[Tue Jul 21 07:26:20.604678 2026] [security2:error] [pid 230252:tid 230461] [client 136.144.33.29:21953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JTE0Dwhk5-Z44XrpTewAAAuY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:20.617132 2026] [security2:error] [pid 229246:tid 229491] [client 4.204.201.85:3326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-admin/css/colour.php"] [unique_id "al9JTCBMYeh5YLVG45x4qwAAAoc"]
[Tue Jul 21 07:26:20.642635 2026] [security2:error] [pid 230252:tid 230276] [remote 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JTE0Dwhk5-Z44XrpThgACoRY"]
[Tue Jul 21 07:26:20.642836 2026] [security2:error] [pid 230252:tid 230392] [client 2001:4490:4ec1:ec62:f01d:f50d:c923:184c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9JTE0Dwhk5-Z44XrpThgACoRY"]
[Tue Jul 21 07:26:20.656080 2026] [security2:error] [pid 230252:tid 230258] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.svn/entries"] [unique_id "al9JTE0Dwhk5-Z44XrpTigACzQQ"]
[Tue Jul 21 07:26:20.656243 2026] [security2:error] [pid 230252:tid 230436] [client 34.35.143.238:58534] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/.svn/entries"] [unique_id "al9JTE0Dwhk5-Z44XrpTigACzQQ"]
[Tue Jul 21 07:26:20.684549 2026] [security2:error] [pid 230252:tid 230403] [client 20.151.10.161:65431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/k.php"] [unique_id "al9JTE0Dwhk5-Z44XrpTjgAAAqw"]
[Tue Jul 21 07:26:20.696170 2026] [security2:error] [pid 230252:tid 230469] [client 172.236.234.62:38842] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "ns1102.hostgator.com.br"] [uri "/"] [unique_id "al9JTE0Dwhk5-Z44XrpTjwAAAu4"]
[Tue Jul 21 07:26:20.697290 2026] [security2:error] [pid 230252:tid 230284] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.ssh/id_rsa"] [unique_id "al9JTE0Dwhk5-Z44XrpTkAACzR4"]
[Tue Jul 21 07:26:20.745537 2026] [security2:error] [pid 230252:tid 230285] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.ssh/id_dsa"] [unique_id "al9JTE0Dwhk5-Z44XrpTmAACzR8"]
[Tue Jul 21 07:26:20.773949 2026] [security2:error] [pid 229246:tid 229401] [client 20.226.60.151:54489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/wp-happy.php"] [unique_id "al9JTCBMYeh5YLVG45x4sAAAAi0"]
[Tue Jul 21 07:26:20.874282 2026] [security2:error] [pid 229246:tid 229356] [remote 165.227.132.137:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.132.227.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9JTCBMYeh5YLVG45x4swACWm0"]
[Tue Jul 21 07:26:20.876069 2026] [security2:error] [pid 229246:tid 229319] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JTCBMYeh5YLVG45x4tAACGUg"]
[Tue Jul 21 07:26:20.876209 2026] [security2:error] [pid 229246:tid 229381] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JTCBMYeh5YLVG45x4tAACGUg"]
[Tue Jul 21 07:26:21.029024 2026] [security2:error] [pid 230252:tid 230331] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/id_rsa"] [unique_id "al9JTU0Dwhk5-Z44XrpTnQACsUw"]
[Tue Jul 21 07:26:21.029046 2026] [security2:error] [pid 230252:tid 230261] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.ssh/known_hosts"] [unique_id "al9JTU0Dwhk5-Z44XrpTnwACsQc"]
[Tue Jul 21 07:26:21.029363 2026] [security2:error] [pid 230252:tid 230408] [client 34.35.143.238:58534] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/.ssh/known_hosts"] [unique_id "al9JTU0Dwhk5-Z44XrpTnwACsQc"]
[Tue Jul 21 07:26:21.107127 2026] [security2:error] [pid 230252:tid 230363] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/id_dsa"] [unique_id "al9JTU0Dwhk5-Z44XrpTpgACsWw"]
[Tue Jul 21 07:26:21.115946 2026] [security2:error] [pid 229246:tid 229396] [client 4.204.201.85:3279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/8.php"] [unique_id "al9JTSBMYeh5YLVG45x4xgAAAig"]
[Tue Jul 21 07:26:21.186808 2026] [security2:error] [pid 230252:tid 230345] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/key.pem"] [unique_id "al9JTU0Dwhk5-Z44XrpTrAACsVo"]
[Tue Jul 21 07:26:21.230164 2026] [security2:error] [pid 230252:tid 230270] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/privatekey.key"] [unique_id "al9JTU0Dwhk5-Z44XrpTrwACsRA"]
[Tue Jul 21 07:26:21.297382 2026] [security2:error] [pid 230252:tid 230446] [client 175.45.70.82:50951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JTU0Dwhk5-Z44XrpTuwAAAtc"]
[Tue Jul 21 07:26:21.297533 2026] [security2:error] [pid 230252:tid 230446] [client 175.45.70.82:50951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JTU0Dwhk5-Z44XrpTuwAAAtc"]
[Tue Jul 21 07:26:21.328483 2026] [security2:error] [pid 230252:tid 230278] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/host.key"] [unique_id "al9JTU0Dwhk5-Z44XrpTvAACsRg"]
[Tue Jul 21 07:26:21.351768 2026] [security2:error] [pid 229246:tid 229440] [client 20.226.60.151:56943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/panel.php"] [unique_id "al9JTSBMYeh5YLVG45x41QAAAlQ"]
[Tue Jul 21 07:26:21.481989 2026] [security2:error] [pid 230252:tid 230497] [client 4.204.201.85:3303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-content/admin.php"] [unique_id "al9JTU0Dwhk5-Z44XrpTxAAAAwo"]
[Tue Jul 21 07:26:21.557009 2026] [security2:error] [pid 230252:tid 230328] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9JTU0Dwhk5-Z44XrpTxgACnUk"]
[Tue Jul 21 07:26:21.638252 2026] [security2:error] [pid 230252:tid 230434] [client 173.252.95.61:57080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JTU0Dwhk5-Z44XrpTzQAAAss"]
[Tue Jul 21 07:26:21.753230 2026] [security2:error] [pid 230252:tid 230352] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.hermes/.env"] [unique_id "al9JTU0Dwhk5-Z44XrpT0gACnWE"]
[Tue Jul 21 07:26:21.759316 2026] [security2:error] [pid 230252:tid 230280] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "al9JTU0Dwhk5-Z44XrpT1AACnRo"]
[Tue Jul 21 07:26:21.759512 2026] [security2:error] [pid 230252:tid 230388] [client 34.35.143.238:58534] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "al9JTU0Dwhk5-Z44XrpT1AACnRo"]
[Tue Jul 21 07:26:21.904294 2026] [security2:error] [pid 230252:tid 230502] [client 20.220.225.223:48562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wpx.php"] [unique_id "al9JTU0Dwhk5-Z44XrpT2AAAAw8"]
[Tue Jul 21 07:26:21.921167 2026] [security2:error] [pid 230252:tid 230473] [client 213.152.162.104:45656] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JTU0Dwhk5-Z44XrpT2QAAAvI"]
[Tue Jul 21 07:26:21.921320 2026] [security2:error] [pid 230252:tid 230473] [client 213.152.162.104:45656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JTU0Dwhk5-Z44XrpT2QAAAvI"]
[Tue Jul 21 07:26:21.952305 2026] [security2:error] [pid 230252:tid 230282] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/.claude.json"] [unique_id "al9JTU0Dwhk5-Z44XrpT2gAC_hw"]
[Tue Jul 21 07:26:22.017060 2026] [security2:error] [pid 230252:tid 230391] [client 154.192.233.199:58952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JTk0Dwhk5-Z44XrpT3gAAAqA"]
[Tue Jul 21 07:26:22.017201 2026] [security2:error] [pid 230252:tid 230391] [client 154.192.233.199:58952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JTk0Dwhk5-Z44XrpT3gAAAqA"]
[Tue Jul 21 07:26:22.020363 2026] [security2:error] [pid 230252:tid 230398] [client 4.204.201.85:3286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/f6.php"] [unique_id "al9JTk0Dwhk5-Z44XrpT3wAAAqc"]
[Tue Jul 21 07:26:22.117497 2026] [security2:error] [pid 230252:tid 230361] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "gradiente.com"] [uri "/wp-config.php.bak"] [unique_id "al9JTk0Dwhk5-Z44XrpT6QAC_mo"]
[Tue Jul 21 07:26:22.176321 2026] [security2:error] [pid 230252:tid 230404] [client 20.52.136.55:1558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/shell.php"] [unique_id "al9JTk0Dwhk5-Z44XrpT6gAAAq0"]
[Tue Jul 21 07:26:22.202230 2026] [security2:error] [pid 230252:tid 230302] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "gradiente.com"] [uri "/wp-config.php.old"] [unique_id "al9JTk0Dwhk5-Z44XrpT7wAC_jA"]
[Tue Jul 21 07:26:22.255317 2026] [security2:error] [pid 230252:tid 230291] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/laravel/.env"] [unique_id "al9JTk0Dwhk5-Z44XrpT8AAC_iU"]
[Tue Jul 21 07:26:22.268896 2026] [security2:error] [pid 230252:tid 230327] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/config/.env.php"] [unique_id "al9JTk0Dwhk5-Z44XrpT8QAC_kg"]
[Tue Jul 21 07:26:22.313877 2026] [security2:error] [pid 230252:tid 230330] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/.env.php.bak"] [unique_id "al9JTk0Dwhk5-Z44XrpT8gAC_ks"]
[Tue Jul 21 07:26:22.425754 2026] [security2:error] [pid 230252:tid 230498] [client 20.151.10.161:26454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/xamp.php"] [unique_id "al9JTk0Dwhk5-Z44XrpT9QAAAws"]
[Tue Jul 21 07:26:22.446109 2026] [security2:error] [pid 230252:tid 230286] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/core/.env"] [unique_id "al9JTk0Dwhk5-Z44XrpT9gACsSA"]
[Tue Jul 21 07:26:22.510745 2026] [security2:error] [pid 230252:tid 230323] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/config.php.bak"] [unique_id "al9JTk0Dwhk5-Z44XrpT9wADE0U"]
[Tue Jul 21 07:26:22.522958 2026] [security2:error] [pid 230252:tid 230326] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/auth.json"] [unique_id "al9JTk0Dwhk5-Z44XrpT-AADCkc"]
[Tue Jul 21 07:26:22.523060 2026] [security2:error] [pid 230252:tid 230497] [client 34.35.143.238:58534] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/auth.json"] [unique_id "al9JTk0Dwhk5-Z44XrpT-AADCkc"]
[Tue Jul 21 07:26:22.562283 2026] [security2:error] [pid 230252:tid 230304] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/configuration.php.bak"] [unique_id "al9JTk0Dwhk5-Z44XrpT-wACqDI"]
[Tue Jul 21 07:26:22.569198 2026] [security2:error] [pid 230252:tid 230409] [client 4.204.201.85:3210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/inputs.php"] [unique_id "al9JTk0Dwhk5-Z44XrpT_AAAArI"]
[Tue Jul 21 07:26:22.633115 2026] [security2:error] [pid 230252:tid 230376] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.swp"] [unique_id "al9JTk0Dwhk5-Z44XrpT_gADB3k"]
[Tue Jul 21 07:26:22.656446 2026] [security2:error] [pid 230252:tid 230317] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/public/.env"] [unique_id "al9JTk0Dwhk5-Z44XrpT_wAC4T8"]
[Tue Jul 21 07:26:22.667048 2026] [security2:error] [pid 230252:tid 230262] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/web/.env"] [unique_id "al9JTk0Dwhk5-Z44XrpUAgAC4Qg"]
[Tue Jul 21 07:26:22.667669 2026] [security2:error] [pid 230252:tid 230377] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/values.yaml"] [unique_id "al9JTk0Dwhk5-Z44XrpUAwAC4Xo"]
[Tue Jul 21 07:26:22.690063 2026] [security2:error] [pid 230252:tid 230415] [client 104.192.7.114:61199] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.sistedu-mec.com"] [uri "/wp-json/batch/v1"] [unique_id "al9JTk0Dwhk5-Z44XrpUBQAAArg"]
[Tue Jul 21 07:26:22.813917 2026] [security2:error] [pid 230252:tid 230488] [client 20.220.225.223:38691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9JTk0Dwhk5-Z44XrpUCgAAAwE"]
[Tue Jul 21 07:26:22.865805 2026] [security2:error] [pid 230252:tid 230367] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/api/settings"] [unique_id "al9JTk0Dwhk5-Z44XrpUDgAC4XA"]
[Tue Jul 21 07:26:23.100883 2026] [security2:error] [pid 230252:tid 230491] [client 4.204.201.85:3306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/inputs.php"] [unique_id "al9JT00Dwhk5-Z44XrpUGAAAAwQ"]
[Tue Jul 21 07:26:23.423433 2026] [security2:error] [pid 230252:tid 230353] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/api/openapi.json"] [unique_id "al9JT00Dwhk5-Z44XrpUJgADF2I"]
[Tue Jul 21 07:26:23.461217 2026] [security2:error] [pid 229246:tid 229409] [client 4.204.201.85:3229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/classwithtostring.php"] [unique_id "al9JTyBMYeh5YLVG45x48gAAAjU"]
[Tue Jul 21 07:26:23.471212 2026] [security2:error] [pid 229246:tid 229286] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JTyBMYeh5YLVG45x48wACMCc"]
[Tue Jul 21 07:26:23.471404 2026] [security2:error] [pid 229246:tid 229404] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JTyBMYeh5YLVG45x48wACMCc"]
[Tue Jul 21 07:26:23.475244 2026] [security2:error] [pid 230252:tid 230468] [client 20.220.225.223:46000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/berlin.php"] [unique_id "al9JT00Dwhk5-Z44XrpUJwAAAu0"]
[Tue Jul 21 07:26:23.488530 2026] [security2:error] [pid 229246:tid 229431] [client 20.226.60.151:63353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/dex.php"] [unique_id "al9JTyBMYeh5YLVG45x49AAAAks"]
[Tue Jul 21 07:26:23.723253 2026] [security2:error] [pid 230252:tid 230490] [client 20.226.60.151:54543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/fpr4.php"] [unique_id "al9JT00Dwhk5-Z44XrpUMwAAAwM"]
[Tue Jul 21 07:26:23.741429 2026] [security2:error] [pid 230252:tid 230375] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/swagger.json"] [unique_id "al9JT00Dwhk5-Z44XrpUNAADDng"]
[Tue Jul 21 07:26:23.816725 2026] [security2:error] [pid 230252:tid 230475] [client 4.204.201.85:3226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-content/themes/index.php"] [unique_id "al9JT00Dwhk5-Z44XrpUOwAAAvQ"]
[Tue Jul 21 07:26:23.998827 2026] [security2:error] [pid 230252:tid 230315] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/actuator/configprops"] [unique_id "al9JT00Dwhk5-Z44XrpUQgADDj0"]
[Tue Jul 21 07:26:24.173781 2026] [security2:error] [pid 229246:tid 229502] [client 20.226.60.151:56839] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "arielson.com.br"] [uri "/1.php"] [unique_id "al9JUCBMYeh5YLVG45x5BwAAApI"]
[Tue Jul 21 07:26:24.173911 2026] [security2:error] [pid 229246:tid 229502] [client 20.226.60.151:56839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/1.php"] [unique_id "al9JUCBMYeh5YLVG45x5BwAAApI"]
[Tue Jul 21 07:26:24.301216 2026] [security2:error] [pid 230252:tid 230301] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/phpinfo.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUSwADDi8"]
[Tue Jul 21 07:26:24.303438 2026] [security2:error] [pid 229246:tid 229420] [client 4.204.201.85:3315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-blog.php"] [unique_id "al9JUCBMYeh5YLVG45x5CQAAAkA"]
[Tue Jul 21 07:26:24.310152 2026] [security2:error] [pid 230252:tid 230255] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/i.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUTAADDgE"]
[Tue Jul 21 07:26:24.330756 2026] [security2:error] [pid 230252:tid 230316] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/pi.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUTQADDj4"]
[Tue Jul 21 07:26:24.343941 2026] [security2:error] [pid 230252:tid 230310] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/info.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUTgADDjg"]
[Tue Jul 21 07:26:24.369081 2026] [security2:error] [pid 230252:tid 230366] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUUgAC0W8"]
[Tue Jul 21 07:26:24.369224 2026] [security2:error] [pid 230252:tid 230440] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUUgAC0W8"]
[Tue Jul 21 07:26:24.374512 2026] [security2:error] [pid 230252:tid 230343] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/_profiler/open"] [unique_id "al9JUE0Dwhk5-Z44XrpUUwADDlg"]
[Tue Jul 21 07:26:24.379926 2026] [security2:error] [pid 230252:tid 230283] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/test.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUVAADDh0"]
[Tue Jul 21 07:26:24.390579 2026] [security2:error] [pid 230252:tid 230260] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/app_dev.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUVQADDgY"]
[Tue Jul 21 07:26:24.489048 2026] [security2:error] [pid 230252:tid 230494] [client 20.220.225.223:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/billur.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUVwAAAwc"]
[Tue Jul 21 07:26:24.689214 2026] [security2:error] [pid 230252:tid 230258] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/app_dev.php/_profiler"] [unique_id "al9JUE0Dwhk5-Z44XrpUWAADGAQ"]
[Tue Jul 21 07:26:24.709782 2026] [security2:error] [pid 230252:tid 230342] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/elmah.axd"] [unique_id "al9JUE0Dwhk5-Z44XrpUXQADGFc"]
[Tue Jul 21 07:26:24.713242 2026] [security2:error] [pid 230252:tid 230365] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/_debugbar/open"] [unique_id "al9JUE0Dwhk5-Z44XrpUXwADGG4"]
[Tue Jul 21 07:26:24.732198 2026] [access_compat:error] [pid 230252:tid 230268] [remote 34.35.143.238:58534] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Tue Jul 21 07:26:24.740534 2026] [security2:error] [pid 230252:tid 230351] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/server-info"] [unique_id "al9JUE0Dwhk5-Z44XrpUaQADGGA"]
[Tue Jul 21 07:26:24.817943 2026] [security2:error] [pid 230252:tid 230460] [client 213.152.162.104:55572] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUbgAAAuU"]
[Tue Jul 21 07:26:24.818063 2026] [security2:error] [pid 230252:tid 230460] [client 213.152.162.104:55572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUbgAAAuU"]
[Tue Jul 21 07:26:24.873546 2026] [security2:error] [pid 229246:tid 229396] [client 20.151.10.161:26326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/bless.php"] [unique_id "al9JUCBMYeh5YLVG45x5EQAAAig"]
[Tue Jul 21 07:26:24.918242 2026] [security2:error] [pid 230252:tid 230385] [client 20.151.10.161:65419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/w.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUdgAAApo"]
[Tue Jul 21 07:26:24.983164 2026] [security2:error] [pid 229246:tid 229418] [client 103.162.129.114:59651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JUCBMYeh5YLVG45x5FAAAAj4"]
[Tue Jul 21 07:26:24.983322 2026] [security2:error] [pid 229246:tid 229418] [client 103.162.129.114:59651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JUCBMYeh5YLVG45x5FAAAAj4"]
[Tue Jul 21 07:26:24.990904 2026] [security2:error] [pid 230252:tid 230502] [client 4.204.201.85:3258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-content/admin.php"] [unique_id "al9JUE0Dwhk5-Z44XrpUdwAAAw8"]
[Tue Jul 21 07:26:25.266885 2026] [security2:error] [pid 229246:tid 229414] [client 74.249.245.134:62860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/.info.php"] [unique_id "al9JUSBMYeh5YLVG45x5HAAAAjo"]
[Tue Jul 21 07:26:25.349039 2026] [security2:error] [pid 229246:tid 229428] [client 213.152.162.104:45664] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JUSBMYeh5YLVG45x5HgAAAkg"]
[Tue Jul 21 07:26:25.349186 2026] [security2:error] [pid 229246:tid 229428] [client 213.152.162.104:45664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JUSBMYeh5YLVG45x5HgAAAkg"]
[Tue Jul 21 07:26:25.557801 2026] [security2:error] [pid 230252:tid 230482] [client 139.135.44.145:53798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUggAAAvs"]
[Tue Jul 21 07:26:25.557931 2026] [security2:error] [pid 230252:tid 230482] [client 139.135.44.145:53798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUggAAAvs"]
[Tue Jul 21 07:26:25.615306 2026] [security2:error] [pid 230252:tid 230411] [client 4.204.201.85:3249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ms-edit.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUgwAAArQ"]
[Tue Jul 21 07:26:25.699424 2026] [core:alert] [pid 230252:tid 230486] [client 57.141.18.50:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:26:25.798026 2026] [security2:error] [pid 230252:tid 230500] [client 74.7.230.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "drguedes.com.br"] [uri "/index.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUfwAAAw0"]
[Tue Jul 21 07:26:25.799756 2026] [security2:error] [pid 230252:tid 230455] [client 74.7.230.49:57580] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "drguedes.com.br"] [uri "/robots.txt"] [unique_id "al9JUU0Dwhk5-Z44XrpUfQAC4Cs"]
[Tue Jul 21 07:26:25.819296 2026] [security2:error] [pid 230252:tid 230492] [client 20.151.10.161:26392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file46.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUjAAAAwU"]
[Tue Jul 21 07:26:25.926435 2026] [security2:error] [pid 230252:tid 230399] [client 20.220.225.223:45415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/mimpi.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUkAAAAqg"]
[Tue Jul 21 07:26:25.942297 2026] [security2:error] [pid 230252:tid 230350] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUkQAC3F8"]
[Tue Jul 21 07:26:25.942415 2026] [security2:error] [pid 230252:tid 230451] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JUU0Dwhk5-Z44XrpUkQAC3F8"]
[Tue Jul 21 07:26:26.112569 2026] [security2:error] [pid 229246:tid 229425] [client 173.252.95.2:51454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JUCBMYeh5YLVG45x5EwAAAkU"]
[Tue Jul 21 07:26:26.210891 2026] [security2:error] [pid 229246:tid 229382] [client 4.204.201.85:3313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/cgi-bin/index.php"] [unique_id "al9JUiBMYeh5YLVG45x5KAAAAho"]
[Tue Jul 21 07:26:26.221241 2026] [security2:error] [pid 229246:tid 229376] [client 20.52.136.55:1746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/3.php"] [unique_id "al9JUiBMYeh5YLVG45x5KQAAAhQ"]
[Tue Jul 21 07:26:26.533560 2026] [security2:error] [pid 229246:tid 229470] [client 20.220.225.223:31181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/ee.php"] [unique_id "al9JUiBMYeh5YLVG45x5KwAAAnI"]
[Tue Jul 21 07:26:26.776286 2026] [security2:error] [pid 230252:tid 230386] [client 20.226.60.151:62352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/ms.php"] [unique_id "al9JUk0Dwhk5-Z44XrpUoAAAAps"]
[Tue Jul 21 07:26:26.847359 2026] [security2:error] [pid 230252:tid 230511] [client 109.248.148.246:36492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9JUk0Dwhk5-Z44XrpUpgAAAxg"]
[Tue Jul 21 07:26:26.847488 2026] [security2:error] [pid 230252:tid 230511] [client 109.248.148.246:36492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9JUk0Dwhk5-Z44XrpUpgAAAxg"]
[Tue Jul 21 07:26:26.949998 2026] [security2:error] [pid 229246:tid 229390] [client 4.204.201.85:3283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/BDKR28WP.php"] [unique_id "al9JUiBMYeh5YLVG45x5LwAAAiI"]
[Tue Jul 21 07:26:26.962825 2026] [security2:error] [pid 229246:tid 229421] [client 136.144.33.215:56589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JUSBMYeh5YLVG45x5JAAAAkE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:27.186565 2026] [security2:error] [pid 230252:tid 230417] [client 117.251.86.144:52440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JU00Dwhk5-Z44XrpUrAAAAro"]
[Tue Jul 21 07:26:27.186694 2026] [security2:error] [pid 230252:tid 230417] [client 117.251.86.144:52440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JU00Dwhk5-Z44XrpUrAAAAro"]
[Tue Jul 21 07:26:27.827025 2026] [security2:error] [pid 230252:tid 230263] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JU00Dwhk5-Z44XrpUugACqAk"]
[Tue Jul 21 07:26:27.827179 2026] [security2:error] [pid 230252:tid 230399] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JU00Dwhk5-Z44XrpUugACqAk"]
[Tue Jul 21 07:26:27.909281 2026] [security2:error] [pid 230252:tid 230392] [client 62.102.148.164:39928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JU00Dwhk5-Z44XrpUuwAAAqE"]
[Tue Jul 21 07:26:27.909416 2026] [security2:error] [pid 230252:tid 230392] [client 62.102.148.164:39928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JU00Dwhk5-Z44XrpUuwAAAqE"]
[Tue Jul 21 07:26:28.225673 2026] [security2:error] [pid 230252:tid 230434] [client 4.204.201.85:26591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/abcd.php"] [unique_id "al9JVE0Dwhk5-Z44XrpUwwAAAss"]
[Tue Jul 21 07:26:28.394663 2026] [security2:error] [pid 230252:tid 230420] [client 147.93.168.177:55621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.168.93.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "coroneldimas.mg"] [uri "/wp-login.php"] [unique_id "al9JVE0Dwhk5-Z44XrpUyAAAAr0"]
[Tue Jul 21 07:26:28.821078 2026] [security2:error] [pid 229246:tid 229484] [client 4.204.201.85:3241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/file15.php"] [unique_id "al9JVCBMYeh5YLVG45x5RQAAAoA"]
[Tue Jul 21 07:26:28.835978 2026] [security2:error] [pid 229246:tid 229386] [client 20.151.10.161:26373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/eee.php"] [unique_id "al9JVCBMYeh5YLVG45x5RgAAAh4"]
[Tue Jul 21 07:26:29.039410 2026] [security2:error] [pid 229246:tid 229253] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JVSBMYeh5YLVG45x5SAACkgY"]
[Tue Jul 21 07:26:29.039581 2026] [security2:error] [pid 229246:tid 229502] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JVSBMYeh5YLVG45x5SAACkgY"]
[Tue Jul 21 07:26:29.154557 2026] [autoindex:error] [pid 229246:tid 229403] [client 20.226.60.151:62359] AH01276: Cannot serve directory /home1/arielson/public_html/arielson.com.br/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:26:29.250802 2026] [security2:error] [pid 230252:tid 230459] [client 20.226.60.151:54558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/file88.php"] [unique_id "al9JVU0Dwhk5-Z44XrpUzgAAAuQ"]
[Tue Jul 21 07:26:29.297683 2026] [security2:error] [pid 229246:tid 229256] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JVSBMYeh5YLVG45x5SwACdgk"]
[Tue Jul 21 07:26:29.297848 2026] [security2:error] [pid 229246:tid 229474] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JVSBMYeh5YLVG45x5SwACdgk"]
[Tue Jul 21 07:26:29.371989 2026] [security2:error] [pid 229246:tid 229486] [client 4.204.201.85:3318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/jp.php"] [unique_id "al9JVSBMYeh5YLVG45x5TgAAAoI"]
[Tue Jul 21 07:26:29.544278 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:31183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/blue.php"] [unique_id "al9JVU0Dwhk5-Z44XrpU1QAAAto"]
[Tue Jul 21 07:26:29.837679 2026] [security2:error] [pid 230252:tid 230508] [client 4.204.201.85:3235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/f35.php"] [unique_id "al9JVU0Dwhk5-Z44XrpU2AAAAxU"]
[Tue Jul 21 07:26:30.004974 2026] [security2:error] [pid 229246:tid 229424] [client 45.251.232.145:64435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JViBMYeh5YLVG45x5UwAAAkQ"]
[Tue Jul 21 07:26:30.005099 2026] [security2:error] [pid 229246:tid 229424] [client 45.251.232.145:64435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JViBMYeh5YLVG45x5UwAAAkQ"]
[Tue Jul 21 07:26:30.102865 2026] [security2:error] [pid 229246:tid 229436] [client 20.52.136.55:1750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/mds.php"] [unique_id "al9JViBMYeh5YLVG45x5VQAAAlA"]
[Tue Jul 21 07:26:30.282892 2026] [security2:error] [pid 230252:tid 230392] [client 4.204.201.85:3213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-load.php"] [unique_id "al9JVk0Dwhk5-Z44XrpU3gAAAqE"]
[Tue Jul 21 07:26:30.286441 2026] [security2:error] [pid 229246:tid 229501] [client 103.106.20.201:64096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JViBMYeh5YLVG45x5VwAAApE"]
[Tue Jul 21 07:26:30.286534 2026] [security2:error] [pid 229246:tid 229501] [client 103.106.20.201:64096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JViBMYeh5YLVG45x5VwAAApE"]
[Tue Jul 21 07:26:30.605445 2026] [security2:error] [pid 230252:tid 230434] [client 20.151.10.161:65497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/insc.php"] [unique_id "al9JVk0Dwhk5-Z44XrpU4gAAAss"]
[Tue Jul 21 07:26:30.859692 2026] [security2:error] [pid 230252:tid 230391] [client 20.220.225.223:31182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/wp-signup.php"] [unique_id "al9JVk0Dwhk5-Z44XrpU5wAAAqA"]
[Tue Jul 21 07:26:30.899434 2026] [security2:error] [pid 230252:tid 230398] [client 74.249.245.134:54375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/item.php"] [unique_id "al9JVk0Dwhk5-Z44XrpU6QAAAqc"]
[Tue Jul 21 07:26:30.928284 2026] [security2:error] [pid 230252:tid 230443] [client 4.204.201.85:3262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/xyn.php"] [unique_id "al9JVk0Dwhk5-Z44XrpU6wAAAtQ"]
[Tue Jul 21 07:26:31.052368 2026] [security2:error] [pid 229246:tid 229426] [client 20.220.225.223:48565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/dp.php"] [unique_id "al9JVyBMYeh5YLVG45x5XwAAAkY"]
[Tue Jul 21 07:26:31.100297 2026] [security2:error] [pid 230252:tid 230494] [client 103.174.34.15:60703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JV00Dwhk5-Z44XrpU7gAAAwc"]
[Tue Jul 21 07:26:31.100412 2026] [security2:error] [pid 230252:tid 230494] [client 103.174.34.15:60703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JV00Dwhk5-Z44XrpU7gAAAwc"]
[Tue Jul 21 07:26:31.172353 2026] [security2:error] [pid 230252:tid 230477] [client 136.144.33.104:51253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JV00Dwhk5-Z44XrpU8AAAAvY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:31.291010 2026] [security2:error] [pid 230252:tid 230399] [client 152.59.154.239:65149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JV00Dwhk5-Z44XrpU8QAAAqg"]
[Tue Jul 21 07:26:31.356899 2026] [security2:error] [pid 229246:tid 229408] [client 20.226.60.151:63341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/memberfuns.php"] [unique_id "al9JVyBMYeh5YLVG45x5YQAAAjQ"]
[Tue Jul 21 07:26:31.371743 2026] [security2:error] [pid 230252:tid 230281] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JV00Dwhk5-Z44XrpU8gACths"]
[Tue Jul 21 07:26:31.371911 2026] [security2:error] [pid 230252:tid 230413] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JV00Dwhk5-Z44XrpU8gACths"]
[Tue Jul 21 07:26:31.447648 2026] [security2:error] [pid 230252:tid 230462] [client 20.226.60.151:63337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/0.php"] [unique_id "al9JV00Dwhk5-Z44XrpU8wAAAuc"]
[Tue Jul 21 07:26:31.557881 2026] [security2:error] [pid 230252:tid 230511] [client 20.151.10.161:26381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file25.php"] [unique_id "al9JV00Dwhk5-Z44XrpU-gAAAxg"]
[Tue Jul 21 07:26:31.841751 2026] [security2:error] [pid 230252:tid 230392] [client 20.226.60.151:63321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/BDKR28.php"] [unique_id "al9JV00Dwhk5-Z44XrpVDwAAAqE"]
[Tue Jul 21 07:26:31.950227 2026] [security2:error] [pid 230252:tid 230374] [remote 104.207.32.246:56793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.32.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JV00Dwhk5-Z44XrpVEQACv3c"]
[Tue Jul 21 07:26:32.101739 2026] [security2:error] [pid 229246:tid 229439] [client 175.45.70.82:51559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JWCBMYeh5YLVG45x5awAAAlM"]
[Tue Jul 21 07:26:32.101879 2026] [security2:error] [pid 229246:tid 229439] [client 175.45.70.82:51559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JWCBMYeh5YLVG45x5awAAAlM"]
[Tue Jul 21 07:26:32.179178 2026] [security2:error] [pid 230252:tid 230346] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/wp-login.php"] [unique_id "al9JWE0Dwhk5-Z44XrpVEwACu1s"], referer: https://gradiente.com/login
[Tue Jul 21 07:26:32.190669 2026] [security2:error] [pid 230252:tid 230480] [client 4.204.201.85:26567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ccc.php"] [unique_id "al9JWE0Dwhk5-Z44XrpVGAAAAvk"]
[Tue Jul 21 07:26:32.276150 2026] [security2:error] [pid 230252:tid 230426] [client 20.64.106.39:51650] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.69"] [uri "/index.cgi"] [unique_id "al9JWE0Dwhk5-Z44XrpVGQAAAsM"]
[Tue Jul 21 07:26:32.477539 2026] [security2:error] [pid 229246:tid 229412] [client 4.204.201.85:26583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/w.php"] [unique_id "al9JWCBMYeh5YLVG45x5bQAAAjg"]
[Tue Jul 21 07:26:32.503210 2026] [security2:error] [pid 230252:tid 230254] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/wp-login.php"] [unique_id "al9JWE0Dwhk5-Z44XrpVGwACnAA"], referer: https://gradiente.com/wp-admin/
[Tue Jul 21 07:26:32.503335 2026] [security2:error] [pid 230252:tid 230295] [remote 34.35.143.238:58534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/wp-login.php"] [unique_id "al9JWE0Dwhk5-Z44XrpVHAACnCk"], referer: https://gradiente.com/wp-admin/
[Tue Jul 21 07:26:32.531830 2026] [security2:error] [pid 229246:tid 229404] [client 20.226.60.151:62383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/green1.php"] [unique_id "al9JWCBMYeh5YLVG45x5cQAAAjA"]
[Tue Jul 21 07:26:32.627419 2026] [security2:error] [pid 230252:tid 230458] [client 20.151.10.161:26357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file48.php"] [unique_id "al9JWE0Dwhk5-Z44XrpVHgAAAuM"]
[Tue Jul 21 07:26:32.669570 2026] [security2:error] [pid 229246:tid 229376] [client 154.192.233.199:59628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JWCBMYeh5YLVG45x5cwAAAhQ"]
[Tue Jul 21 07:26:32.669697 2026] [security2:error] [pid 229246:tid 229376] [client 154.192.233.199:59628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JWCBMYeh5YLVG45x5cwAAAhQ"]
[Tue Jul 21 07:26:32.716820 2026] [security2:error] [pid 230252:tid 230443] [client 74.249.245.134:17441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/albin.php"] [unique_id "al9JWE0Dwhk5-Z44XrpVIQAAAtQ"]
[Tue Jul 21 07:26:32.830441 2026] [security2:error] [pid 230252:tid 230385] [client 4.204.201.85:3205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9JWE0Dwhk5-Z44XrpVIwAAApo"]
[Tue Jul 21 07:26:33.319510 2026] [security2:error] [pid 230252:tid 230433] [client 4.204.201.85:3281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/FWAZ.php"] [unique_id "al9JWU0Dwhk5-Z44XrpVJgAAAso"]
[Tue Jul 21 07:26:33.321982 2026] [security2:error] [pid 229246:tid 229460] [client 213.152.162.104:52528] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JWSBMYeh5YLVG45x5eQAAAmg"]
[Tue Jul 21 07:26:33.322119 2026] [security2:error] [pid 229246:tid 229460] [client 213.152.162.104:52528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JWSBMYeh5YLVG45x5eQAAAmg"]
[Tue Jul 21 07:26:33.371473 2026] [security2:error] [pid 229246:tid 229475] [client 65.111.28.184:52781] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "giliniservices.com.br"] [uri "/"] [unique_id "al9JWSBMYeh5YLVG45x5egAAAnc"]
[Tue Jul 21 07:26:33.553428 2026] [security2:error] [pid 229246:tid 229491] [client 20.151.10.161:65455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9JWSBMYeh5YLVG45x5fwAAAoc"]
[Tue Jul 21 07:26:33.621419 2026] [security2:error] [pid 229246:tid 229445] [client 65.111.28.184:52781] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "giliniservices.com.br"] [uri "/"] [unique_id "al9JWSBMYeh5YLVG45x5gAAAAlk"]
[Tue Jul 21 07:26:33.640513 2026] [security2:error] [pid 230252:tid 230419] [client 4.204.201.85:3295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/miru1.php"] [unique_id "al9JWU0Dwhk5-Z44XrpVKQAAArw"]
[Tue Jul 21 07:26:33.651072 2026] [security2:error] [pid 229246:tid 229393] [client 20.151.10.161:26535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file6.php"] [unique_id "al9JWSBMYeh5YLVG45x5gQAAAiU"]
[Tue Jul 21 07:26:33.770965 2026] [security2:error] [pid 230252:tid 230487] [client 20.226.60.151:56858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/nc4.php"] [unique_id "al9JWU0Dwhk5-Z44XrpVKwAAAwA"]
[Tue Jul 21 07:26:33.882061 2026] [security2:error] [pid 230252:tid 230382] [remote 38.242.157.30:47242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/wp-login.php"] [unique_id "al9JWU0Dwhk5-Z44XrpVLAADDX8"]
[Tue Jul 21 07:26:33.912919 2026] [security2:error] [pid 230252:tid 230360] [remote 47.128.56.33:50176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dscbrasil.com.br"] [uri "/inicial"] [unique_id "al9JWU0Dwhk5-Z44XrpVLQAC8mk"]
[Tue Jul 21 07:26:33.918825 2026] [security2:error] [pid 230252:tid 230506] [client 20.220.225.223:31189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/csa.php"] [unique_id "al9JWU0Dwhk5-Z44XrpVLgAAAxM"]
[Tue Jul 21 07:26:34.019582 2026] [security2:error] [pid 230252:tid 230364] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVLwACzG0"]
[Tue Jul 21 07:26:34.019734 2026] [security2:error] [pid 230252:tid 230435] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVLwACzG0"]
[Tue Jul 21 07:26:34.123588 2026] [security2:error] [pid 229246:tid 229451] [client 65.111.28.184:52781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9JWiBMYeh5YLVG45x5hgAAAl8"]
[Tue Jul 21 07:26:34.262122 2026] [security2:error] [pid 230252:tid 230498] [client 4.204.201.85:3324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/aa.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVMQAAAws"]
[Tue Jul 21 07:26:34.428362 2026] [security2:error] [pid 229246:tid 229446] [client 20.151.10.161:26448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/a2.php"] [unique_id "al9JWiBMYeh5YLVG45x5iAAAAlo"]
[Tue Jul 21 07:26:34.479364 2026] [security2:error] [pid 230252:tid 230453] [client 109.248.148.246:40258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVMgAAAt4"]
[Tue Jul 21 07:26:34.479507 2026] [security2:error] [pid 230252:tid 230453] [client 109.248.148.246:40258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVMgAAAt4"]
[Tue Jul 21 07:26:34.634431 2026] [security2:error] [pid 229246:tid 229443] [client 65.111.28.184:39051] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "giliniservices.com.br"] [uri "/"] [unique_id "al9JWiBMYeh5YLVG45x5jAAAAlc"]
[Tue Jul 21 07:26:34.681067 2026] [security2:error] [pid 229246:tid 229423] [client 20.226.60.151:56861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/a1.php"] [unique_id "al9JWiBMYeh5YLVG45x5jwAAAkM"]
[Tue Jul 21 07:26:34.734452 2026] [security2:error] [pid 229246:tid 229424] [client 4.204.201.85:3266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/122.php"] [unique_id "al9JWiBMYeh5YLVG45x5kAAAAkQ"]
[Tue Jul 21 07:26:34.869541 2026] [security2:error] [pid 230252:tid 230313] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVOAAC2Ds"]
[Tue Jul 21 07:26:34.869678 2026] [security2:error] [pid 230252:tid 230447] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVOAAC2Ds"]
[Tue Jul 21 07:26:34.887718 2026] [security2:error] [pid 229246:tid 229399] [client 65.111.28.184:39051] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9JWiBMYeh5YLVG45x5kQAAAis"]
[Tue Jul 21 07:26:34.891375 2026] [security2:error] [pid 229246:tid 229441] [client 20.220.225.223:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/bootstrap.php"] [unique_id "al9JWiBMYeh5YLVG45x5kgAAAlU"]
[Tue Jul 21 07:26:34.966217 2026] [security2:error] [pid 229246:tid 229319] [remote 18.61.192.253:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rqracademy.com"] [uri "/wp-login.php"] [unique_id "al9JWiBMYeh5YLVG45x5kwACkUg"]
[Tue Jul 21 07:26:34.997153 2026] [security2:error] [pid 230252:tid 230483] [client 20.151.10.161:26422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/file15.php"] [unique_id "al9JWk0Dwhk5-Z44XrpVOgAAAvw"]
[Tue Jul 21 07:26:35.173024 2026] [security2:error] [pid 229246:tid 229473] [client 20.226.60.151:56911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/eee.php"] [unique_id "al9JWyBMYeh5YLVG45x5mAAAAnU"]
[Tue Jul 21 07:26:35.394113 2026] [security2:error] [pid 229246:tid 229426] [client 65.111.28.184:59419] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9JWyBMYeh5YLVG45x5mwAAAkY"]
[Tue Jul 21 07:26:35.541738 2026] [security2:error] [pid 230252:tid 230410] [client 103.162.129.114:60111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JW00Dwhk5-Z44XrpVPwAAArM"]
[Tue Jul 21 07:26:35.541888 2026] [security2:error] [pid 230252:tid 230410] [client 103.162.129.114:60111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JW00Dwhk5-Z44XrpVPwAAArM"]
[Tue Jul 21 07:26:35.592760 2026] [security2:error] [pid 229246:tid 229481] [client 4.204.201.85:3292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/get.php"] [unique_id "al9JWyBMYeh5YLVG45x5ngAAAn0"]
[Tue Jul 21 07:26:35.627858 2026] [security2:error] [pid 229246:tid 229425] [client 45.227.253.15:36264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.253.227.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.clubelaser.com.br"] [uri "/index.php/jk"] [unique_id "al9JWyBMYeh5YLVG45x5oAAAAkU"]
[Tue Jul 21 07:26:35.638261 2026] [security2:error] [pid 229246:tid 229407] [client 20.226.60.151:63304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-aothait.php"] [unique_id "al9JWyBMYeh5YLVG45x5oQAAAjM"]
[Tue Jul 21 07:26:35.902079 2026] [security2:error] [pid 229246:tid 229412] [client 65.111.28.184:42817] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9JWyBMYeh5YLVG45x5pQAAAjg"]
[Tue Jul 21 07:26:35.905160 2026] [security2:error] [pid 230252:tid 230420] [client 20.151.10.161:26429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/jp.php"] [unique_id "al9JW00Dwhk5-Z44XrpVQQAAAr0"]
[Tue Jul 21 07:26:35.908081 2026] [security2:error] [pid 230252:tid 230508] [client 193.36.225.54:25077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JW00Dwhk5-Z44XrpVQgAAAxU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:35.991210 2026] [security2:error] [pid 229246:tid 229421] [client 213.152.162.104:52536] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9JWyBMYeh5YLVG45x5qQAAAkE"]
[Tue Jul 21 07:26:35.991323 2026] [security2:error] [pid 229246:tid 229421] [client 213.152.162.104:52536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9JWyBMYeh5YLVG45x5qQAAAkE"]
[Tue Jul 21 07:26:36.315447 2026] [security2:error] [pid 229246:tid 229380] [client 4.204.201.85:26596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/as.php"] [unique_id "al9JXCBMYeh5YLVG45x5sAAAAhg"]
[Tue Jul 21 07:26:36.334940 2026] [security2:error] [pid 229246:tid 229493] [client 139.135.44.145:54615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JXCBMYeh5YLVG45x5sQAAAok"]
[Tue Jul 21 07:26:36.339309 2026] [security2:error] [pid 229246:tid 229493] [client 139.135.44.145:54615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JXCBMYeh5YLVG45x5sQAAAok"]
[Tue Jul 21 07:26:36.402643 2026] [security2:error] [pid 230252:tid 230479] [client 20.220.225.223:46128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-editor.php"] [unique_id "al9JXE0Dwhk5-Z44XrpVRAAAAvg"]
[Tue Jul 21 07:26:36.403972 2026] [security2:error] [pid 230252:tid 230385] [client 20.226.60.151:63357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/config.json.php"] [unique_id "al9JXE0Dwhk5-Z44XrpVRQAAApo"]
[Tue Jul 21 07:26:36.410000 2026] [security2:error] [pid 230252:tid 230400] [client 65.111.28.184:15991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9JXE0Dwhk5-Z44XrpVRgAAAqk"]
[Tue Jul 21 07:26:36.446208 2026] [security2:error] [pid 229246:tid 229500] [client 20.151.10.161:26466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/f35.php"] [unique_id "al9JXCBMYeh5YLVG45x5swAAApA"]
[Tue Jul 21 07:26:36.580468 2026] [security2:error] [pid 230252:tid 230301] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JXE0Dwhk5-Z44XrpVRwAC0i8"]
[Tue Jul 21 07:26:36.580634 2026] [security2:error] [pid 230252:tid 230441] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JXE0Dwhk5-Z44XrpVRwAC0i8"]
[Tue Jul 21 07:26:36.783307 2026] [security2:error] [pid 229246:tid 229406] [client 4.204.201.85:3232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ccou.php"] [unique_id "al9JXCBMYeh5YLVG45x5uAAAAjI"]
[Tue Jul 21 07:26:36.801628 2026] [security2:error] [pid 229246:tid 229465] [client 20.220.225.223:31207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/min.php"] [unique_id "al9JXCBMYeh5YLVG45x5uQAAAm0"]
[Tue Jul 21 07:26:36.910039 2026] [security2:error] [pid 230252:tid 230504] [client 65.111.28.184:34019] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9JXE0Dwhk5-Z44XrpVSgAAAxE"]
[Tue Jul 21 07:26:37.020980 2026] [security2:error] [pid 230252:tid 230503] [client 74.249.245.134:17409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/alfa.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVSwAAAxA"]
[Tue Jul 21 07:26:37.062572 2026] [security2:error] [pid 229246:tid 229488] [client 20.52.136.55:1578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/archive.php"] [unique_id "al9JXSBMYeh5YLVG45x5uwAAAoQ"]
[Tue Jul 21 07:26:37.065858 2026] [security2:error] [pid 230252:tid 230482] [client 82.102.28.107:39858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVTAAAAvs"]
[Tue Jul 21 07:26:37.065953 2026] [security2:error] [pid 230252:tid 230482] [client 82.102.28.107:39858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVTAAAAvs"]
[Tue Jul 21 07:26:37.215828 2026] [security2:error] [pid 230252:tid 230396] [client 20.226.60.151:63311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVTwAAAqU"]
[Tue Jul 21 07:26:37.380602 2026] [security2:error] [pid 229246:tid 229386] [client 20.151.10.161:26382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-load.php"] [unique_id "al9JXSBMYeh5YLVG45x5vwAAAh4"]
[Tue Jul 21 07:26:37.437203 2026] [security2:error] [pid 230252:tid 230473] [client 65.111.28.184:24971] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9JXU0Dwhk5-Z44XrpVUgAAAvI"]
[Tue Jul 21 07:26:37.482313 2026] [security2:error] [pid 230252:tid 230435] [client 20.151.10.161:63738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/u.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVUwAAAsw"]
[Tue Jul 21 07:26:37.568574 2026] [security2:error] [pid 230252:tid 230497] [client 4.204.201.85:3296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/w3lls.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVVQAAAwo"]
[Tue Jul 21 07:26:37.698068 2026] [security2:error] [pid 230252:tid 230467] [client 91.92.47.101:21790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/database.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVWAAAAuw"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:26:37.700240 2026] [security2:error] [pid 230252:tid 230498] [client 91.92.47.101:21808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/settings.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVWgAAAws"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:26:37.778952 2026] [security2:error] [pid 230252:tid 230475] [client 20.226.60.151:54479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/ccc.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVXQAAAvQ"]
[Tue Jul 21 07:26:37.806478 2026] [security2:error] [pid 229246:tid 229393] [client 117.251.86.144:60640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JXSBMYeh5YLVG45x5xwAAAiU"]
[Tue Jul 21 07:26:37.806582 2026] [security2:error] [pid 229246:tid 229393] [client 117.251.86.144:60640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JXSBMYeh5YLVG45x5xwAAAiU"]
[Tue Jul 21 07:26:37.934330 2026] [security2:error] [pid 230252:tid 230409] [client 20.226.60.151:63350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/k2.php"] [unique_id "al9JXU0Dwhk5-Z44XrpVXgAAArI"]
[Tue Jul 21 07:26:37.941757 2026] [security2:error] [pid 230252:tid 230469] [client 65.111.28.184:53627] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9JXU0Dwhk5-Z44XrpVXwAAAu4"]
[Tue Jul 21 07:26:38.238756 2026] [security2:error] [pid 229246:tid 229403] [client 4.204.201.85:3228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/test1.php"] [unique_id "al9JXiBMYeh5YLVG45x5yQAAAi8"]
[Tue Jul 21 07:26:38.244769 2026] [security2:error] [pid 229246:tid 229441] [client 91.92.47.101:21822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/db.php"] [unique_id "al9JXiBMYeh5YLVG45x5zAAAAlU"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:26:38.246651 2026] [security2:error] [pid 230252:tid 230393] [client 91.92.47.101:21830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "look.dealspark.com.br"] [uri "/web.config"] [unique_id "al9JXk0Dwhk5-Z44XrpVYwAAAqI"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:26:38.248348 2026] [security2:error] [pid 229246:tid 229418] [client 91.92.47.101:21836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "look.dealspark.com.br"] [uri "/.env.bak"] [unique_id "al9JXiBMYeh5YLVG45x5zQAAAj4"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:26:38.382623 2026] [security2:error] [pid 229246:tid 229398] [client 20.220.225.223:38683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/echkm.php"] [unique_id "al9JXiBMYeh5YLVG45x50AAAAio"]
[Tue Jul 21 07:26:38.456390 2026] [security2:error] [pid 229246:tid 229456] [client 65.111.28.184:31973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9JXiBMYeh5YLVG45x50QAAAmQ"]
[Tue Jul 21 07:26:38.473727 2026] [security2:error] [pid 230252:tid 230319] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JXk0Dwhk5-Z44XrpVaQADBEE"]
[Tue Jul 21 07:26:38.473865 2026] [security2:error] [pid 230252:tid 230491] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JXk0Dwhk5-Z44XrpVaQADBEE"]
[Tue Jul 21 07:26:38.522159 2026] [security2:error] [pid 229246:tid 229422] [client 20.226.60.151:56846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9JXiBMYeh5YLVG45x50gAAAkI"]
[Tue Jul 21 07:26:38.919914 2026] [security2:error] [pid 229246:tid 229492] [client 20.151.10.161:26468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/xwpg.php"] [unique_id "al9JXiBMYeh5YLVG45x52QAAAog"]
[Tue Jul 21 07:26:38.927518 2026] [security2:error] [pid 230252:tid 230407] [client 4.204.201.85:26619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/database.php"] [unique_id "al9JXk0Dwhk5-Z44XrpVcgAAArA"]
[Tue Jul 21 07:26:38.956457 2026] [security2:error] [pid 229246:tid 229498] [client 65.111.28.184:62995] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9JXiBMYeh5YLVG45x52wAAAo4"]
[Tue Jul 21 07:26:39.132891 2026] [security2:error] [pid 230252:tid 230503] [client 20.220.225.223:45995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/cro.php"] [unique_id "al9JX00Dwhk5-Z44XrpVdQAAAxA"]
[Tue Jul 21 07:26:39.354188 2026] [security2:error] [pid 230252:tid 230490] [client 20.104.96.117:59839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JX00Dwhk5-Z44XrpVdgAAAwM"]
[Tue Jul 21 07:26:39.408646 2026] [security2:error] [pid 230252:tid 230505] [client 4.204.201.85:3214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/file.php"] [unique_id "al9JX00Dwhk5-Z44XrpVeAAAAxI"]
[Tue Jul 21 07:26:39.477962 2026] [security2:error] [pid 229246:tid 229430] [client 65.111.28.184:24203] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9JXyBMYeh5YLVG45x54wAAAko"]
[Tue Jul 21 07:26:39.631830 2026] [security2:error] [pid 230252:tid 230258] [remote 162.19.246.208:45822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9JX00Dwhk5-Z44XrpVfAACngQ"]
[Tue Jul 21 07:26:39.752694 2026] [security2:error] [pid 229246:tid 229453] [client 74.249.245.134:54342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9JXyBMYeh5YLVG45x55wAAAmE"]
[Tue Jul 21 07:26:39.807535 2026] [security2:error] [pid 229246:tid 229416] [client 4.204.201.85:26608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/file.php"] [unique_id "al9JXyBMYeh5YLVG45x56QAAAjw"]
[Tue Jul 21 07:26:39.811784 2026] [security2:error] [pid 229246:tid 229421] [client 20.151.10.161:26428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/waf.php"] [unique_id "al9JXyBMYeh5YLVG45x56gAAAkE"]
[Tue Jul 21 07:26:39.825243 2026] [security2:error] [pid 229246:tid 229292] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JXyBMYeh5YLVG45x56wACGi0"]
[Tue Jul 21 07:26:39.825398 2026] [security2:error] [pid 229246:tid 229382] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JXyBMYeh5YLVG45x56wACGi0"]
[Tue Jul 21 07:26:39.852517 2026] [security2:error] [pid 230252:tid 230342] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JX00Dwhk5-Z44XrpVgAACtFc"]
[Tue Jul 21 07:26:39.852713 2026] [security2:error] [pid 230252:tid 230411] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JX00Dwhk5-Z44XrpVgAACtFc"]
[Tue Jul 21 07:26:39.992067 2026] [security2:error] [pid 230252:tid 230499] [client 65.111.28.184:36943] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "giliniservices.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9JX00Dwhk5-Z44XrpVhAAAAww"]
[Tue Jul 21 07:26:40.112158 2026] [security2:error] [pid 230252:tid 230409] [client 20.226.60.151:62355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9JYE0Dwhk5-Z44XrpVigAAArI"]
[Tue Jul 21 07:26:40.150870 2026] [security2:error] [pid 230252:tid 230495] [client 4.204.201.85:3238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/777.php"] [unique_id "al9JYE0Dwhk5-Z44XrpVjAAAAwg"]
[Tue Jul 21 07:26:40.270843 2026] [security2:error] [pid 229246:tid 229391] [client 20.220.225.223:46110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/cron-tab.php"] [unique_id "al9JYCBMYeh5YLVG45x58AAAAiM"]
[Tue Jul 21 07:26:40.477769 2026] [security2:error] [pid 229246:tid 229390] [client 45.251.232.145:64956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JYCBMYeh5YLVG45x59wAAAiI"]
[Tue Jul 21 07:26:40.477878 2026] [security2:error] [pid 229246:tid 229390] [client 45.251.232.145:64956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JYCBMYeh5YLVG45x59wAAAiI"]
[Tue Jul 21 07:26:40.656468 2026] [http2:info] [pid 229246:tid 229383] [client 162.158.171.29:13219] AH10180: h2_stream(229246-1130-1,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:26:40.662642 2026] [security2:error] [pid 229246:tid 229385] [client 4.204.201.85:3253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ssixta.php"] [unique_id "al9JYCBMYeh5YLVG45x5-QAAAh0"]
[Tue Jul 21 07:26:40.938725 2026] [security2:error] [pid 229246:tid 229397] [client 20.226.60.151:63335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9JYCBMYeh5YLVG45x5_AAAAik"]
[Tue Jul 21 07:26:40.986316 2026] [http2:info] [pid 229246:tid 229381] [client 162.158.171.29:13219] AH10180: h2_stream(229246-1130-3,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:26:41.039069 2026] [security2:error] [pid 230252:tid 230458] [client 103.106.20.201:64657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVlgAAAuM"]
[Tue Jul 21 07:26:41.039234 2026] [security2:error] [pid 230252:tid 230458] [client 103.106.20.201:64657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVlgAAAuM"]
[Tue Jul 21 07:26:41.092581 2026] [security2:error] [pid 230252:tid 230385] [client 193.36.225.57:50567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JYE0Dwhk5-Z44XrpVlAAAApo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:41.111834 2026] [security2:error] [pid 230252:tid 230413] [client 20.151.10.161:26314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/xstelth.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVmAAAArY"]
[Tue Jul 21 07:26:41.164410 2026] [security2:error] [pid 229246:tid 229476] [client 4.204.201.85:3239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/1c.php"] [unique_id "al9JYSBMYeh5YLVG45x6AAAAAng"]
[Tue Jul 21 07:26:41.320416 2026] [proxy:error] [pid 230252:tid 230345] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:41.320479 2026] [proxy_http:error] [pid 230252:tid 230345] [remote 198.235.24.40:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.githec.com/
[Tue Jul 21 07:26:41.321254 2026] [proxy:error] [pid 230252:tid 230345] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:26:41.321285 2026] [proxy_http:error] [pid 230252:tid 230345] [remote 198.235.24.40:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.githec.com/
[Tue Jul 21 07:26:41.340003 2026] [security2:error] [pid 229246:tid 229446] [client 74.249.245.134:5513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/av.php"] [unique_id "al9JYSBMYeh5YLVG45x6AwAAAlo"]
[Tue Jul 21 07:26:41.679543 2026] [security2:error] [pid 230252:tid 230430] [client 59.96.220.140:62639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVpgAAAsc"]
[Tue Jul 21 07:26:41.679673 2026] [security2:error] [pid 230252:tid 230430] [client 59.96.220.140:62639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVpgAAAsc"]
[Tue Jul 21 07:26:41.883517 2026] [security2:error] [pid 230252:tid 230497] [client 20.151.10.161:26526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-links.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVrAAAAwo"]
[Tue Jul 21 07:26:41.913687 2026] [security2:error] [pid 230252:tid 230297] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVrQAC_ys"]
[Tue Jul 21 07:26:41.913826 2026] [security2:error] [pid 230252:tid 230486] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVrQAC_ys"]
[Tue Jul 21 07:26:41.917435 2026] [http2:info] [pid 230252:tid 230389] [client 162.158.170.64:10937] AH10180: h2_stream(230252-1310-1,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:26:41.987751 2026] [security2:error] [pid 230252:tid 230445] [client 20.226.60.151:63323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/for.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVsAAAAtY"]
[Tue Jul 21 07:26:41.988868 2026] [security2:error] [pid 230252:tid 230467] [client 20.220.225.223:46124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/koiy.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVsQAAAuw"]
[Tue Jul 21 07:26:42.064285 2026] [security2:error] [pid 230252:tid 230401] [client 4.204.201.85:3230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/test2.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVsgAAAqo"]
[Tue Jul 21 07:26:42.069564 2026] [security2:error] [pid 230252:tid 230257] [remote 114.34.90.9:38428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JYU0Dwhk5-Z44XrpVlwAC-AM"]
[Tue Jul 21 07:26:42.245660 2026] [http2:info] [pid 229246:tid 229456] [client 162.158.171.29:13219] AH10180: h2_stream(229246-1130-5,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:26:42.246639 2026] [security2:error] [pid 230252:tid 230447] [client 20.226.60.151:54508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/777.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVtwAAAtg"]
[Tue Jul 21 07:26:42.296988 2026] [security2:error] [pid 230252:tid 230485] [client 45.8.17.105:43759] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/"] [unique_id "al9JYk0Dwhk5-Z44XrpVuAAAAv4"]
[Tue Jul 21 07:26:42.364484 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:65470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/sss.php"] [unique_id "al9JYiBMYeh5YLVG45x6EgAAAns"]
[Tue Jul 21 07:26:42.533984 2026] [security2:error] [pid 230252:tid 230480] [client 74.249.245.134:54351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/gg.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVuQAAAvk"]
[Tue Jul 21 07:26:42.560041 2026] [security2:error] [pid 230252:tid 230418] [client 4.204.201.85:26377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/buy.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVuwAAArs"]
[Tue Jul 21 07:26:42.572306 2026] [http2:info] [pid 230252:tid 230465] [client 162.158.170.64:10937] AH10180: h2_stream(230252-1310-3,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:26:42.574007 2026] [security2:error] [pid 230252:tid 230436] [client 20.151.10.161:26438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVvAAAAs0"]
[Tue Jul 21 07:26:42.655407 2026] [security2:error] [pid 230252:tid 230471] [client 20.226.60.151:63349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/raw.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVvQAAAvA"]
[Tue Jul 21 07:26:42.785572 2026] [security2:error] [pid 230252:tid 230452] [client 175.45.70.82:52070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVvwAAAt0"]
[Tue Jul 21 07:26:42.785702 2026] [security2:error] [pid 230252:tid 230452] [client 175.45.70.82:52070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVvwAAAt0"]
[Tue Jul 21 07:26:42.894248 2026] [security2:error] [pid 229246:tid 229341] [remote 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/wp-login.php"] [unique_id "al9JYiBMYeh5YLVG45x6GQACJ14"]
[Tue Jul 21 07:26:43.002145 2026] [security2:error] [pid 229246:tid 229482] [client 4.204.201.85:3311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ssend.php"] [unique_id "al9JYyBMYeh5YLVG45x6HQAAAn4"]
[Tue Jul 21 07:26:43.043031 2026] [security2:error] [pid 229246:tid 229407] [client 20.220.225.223:38685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/mac.php"] [unique_id "al9JYyBMYeh5YLVG45x6HgAAAjM"]
[Tue Jul 21 07:26:43.097963 2026] [security2:error] [pid 230252:tid 230442] [client 45.8.17.144:37235] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/core.php"] [unique_id "al9JY00Dwhk5-Z44XrpVwwAAAtM"]
[Tue Jul 21 07:26:43.141166 2026] [security2:error] [pid 230252:tid 230385] [client 20.151.10.161:26522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.engeconconstrucoes.com.br"] [uri "/aaa.php"] [unique_id "al9JY00Dwhk5-Z44XrpVxQAAApo"]
[Tue Jul 21 07:26:43.402037 2026] [security2:error] [pid 230252:tid 230450] [client 154.192.233.199:60207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JY00Dwhk5-Z44XrpVyAAAAts"]
[Tue Jul 21 07:26:43.402197 2026] [security2:error] [pid 230252:tid 230450] [client 154.192.233.199:60207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JY00Dwhk5-Z44XrpVyAAAAts"]
[Tue Jul 21 07:26:43.437217 2026] [security2:error] [pid 230252:tid 230484] [client 74.249.245.134:62883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/sql.php"] [unique_id "al9JY00Dwhk5-Z44XrpVyQAAAv0"]
[Tue Jul 21 07:26:43.583046 2026] [security2:error] [pid 230252:tid 230473] [client 4.204.201.85:3257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/item.php"] [unique_id "al9JY00Dwhk5-Z44XrpVygAAAvI"]
[Tue Jul 21 07:26:43.731977 2026] [security2:error] [pid 230252:tid 230417] [client 20.52.136.55:1477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/amax.php"] [unique_id "al9JY00Dwhk5-Z44XrpVzQAAAro"]
[Tue Jul 21 07:26:43.918262 2026] [security2:error] [pid 230252:tid 230433] [client 20.104.96.117:59586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9JY00Dwhk5-Z44XrpVzgAAAso"]
[Tue Jul 21 07:26:44.121558 2026] [security2:error] [pid 230252:tid 230384] [client 152.59.154.239:49193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JYk0Dwhk5-Z44XrpVvgAAApk"]
[Tue Jul 21 07:26:44.560428 2026] [security2:error] [pid 230252:tid 230280] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JZE0Dwhk5-Z44XrpV2gAC2Bo"]
[Tue Jul 21 07:26:44.560583 2026] [security2:error] [pid 230252:tid 230447] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JZE0Dwhk5-Z44XrpV2gAC2Bo"]
[Tue Jul 21 07:26:44.562751 2026] [security2:error] [pid 230252:tid 230469] [client 4.204.201.85:3274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ss.php"] [unique_id "al9JZE0Dwhk5-Z44XrpV2wAAAu4"]
[Tue Jul 21 07:26:44.917764 2026] [security2:error] [pid 230252:tid 230491] [client 82.102.28.107:56348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JZE0Dwhk5-Z44XrpV4wAAAwQ"]
[Tue Jul 21 07:26:44.917918 2026] [security2:error] [pid 230252:tid 230491] [client 82.102.28.107:56348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JZE0Dwhk5-Z44XrpV4wAAAwQ"]
[Tue Jul 21 07:26:44.956355 2026] [security2:error] [pid 230252:tid 230462] [client 193.36.225.67:65167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JZE0Dwhk5-Z44XrpV5AAAAuc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:45.147011 2026] [security2:error] [pid 230252:tid 230289] [remote 37.60.226.168:45352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.226.60.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fgengenharia.eng.br"] [uri "/wp-login.php"] [unique_id "al9JZU0Dwhk5-Z44XrpV5wADASM"]
[Tue Jul 21 07:26:45.279165 2026] [security2:error] [pid 229246:tid 229472] [client 45.8.17.119:33755] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "al9JZSBMYeh5YLVG45x6PwAAAnQ"]
[Tue Jul 21 07:26:45.409379 2026] [security2:error] [pid 230252:tid 230372] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JZU0Dwhk5-Z44XrpV6gACs3U"]
[Tue Jul 21 07:26:45.409618 2026] [security2:error] [pid 230252:tid 230410] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JZU0Dwhk5-Z44XrpV6gACs3U"]
[Tue Jul 21 07:26:45.538773 2026] [security2:error] [pid 229246:tid 229432] [client 20.220.225.223:46013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/hp2.php"] [unique_id "al9JZSBMYeh5YLVG45x6RQAAAkw"]
[Tue Jul 21 07:26:45.709052 2026] [security2:error] [pid 229246:tid 229443] [client 4.204.201.85:3280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/hypo.php"] [unique_id "al9JZSBMYeh5YLVG45x6SgAAAlc"]
[Tue Jul 21 07:26:45.979405 2026] [security2:error] [pid 229246:tid 229378] [client 20.226.60.151:54467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/for.php"] [unique_id "al9JZSBMYeh5YLVG45x6UQAAAhY"]
[Tue Jul 21 07:26:46.155949 2026] [security2:error] [pid 229246:tid 229496] [client 103.162.129.114:60535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JZiBMYeh5YLVG45x6VQAAAow"]
[Tue Jul 21 07:26:46.156077 2026] [security2:error] [pid 229246:tid 229496] [client 103.162.129.114:60535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JZiBMYeh5YLVG45x6VQAAAow"]
[Tue Jul 21 07:26:46.177920 2026] [security2:error] [pid 230252:tid 230440] [client 74.249.245.134:5556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/up.php"] [unique_id "al9JZk0Dwhk5-Z44XrpWBQAAAtE"]
[Tue Jul 21 07:26:46.276697 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:65515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/sss.php"] [unique_id "al9JZiBMYeh5YLVG45x6WAAAAnk"]
[Tue Jul 21 07:26:46.286318 2026] [security2:error] [pid 230252:tid 230469] [client 45.8.17.121:38563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/admin.php"] [unique_id "al9JZk0Dwhk5-Z44XrpWCAAAAu4"]
[Tue Jul 21 07:26:46.335898 2026] [security2:error] [pid 229246:tid 229481] [client 20.104.96.117:59601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/xyn.php"] [unique_id "al9JZiBMYeh5YLVG45x6WQAAAn0"]
[Tue Jul 21 07:26:46.439824 2026] [security2:error] [pid 229246:tid 229411] [client 103.174.34.15:61175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JZiBMYeh5YLVG45x6WgAAAjc"]
[Tue Jul 21 07:26:46.439995 2026] [security2:error] [pid 229246:tid 229411] [client 103.174.34.15:61175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JZiBMYeh5YLVG45x6WgAAAjc"]
[Tue Jul 21 07:26:46.490007 2026] [security2:error] [pid 230252:tid 230464] [client 213.152.162.104:58834] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JZk0Dwhk5-Z44XrpWCwAAAuk"]
[Tue Jul 21 07:26:46.490119 2026] [security2:error] [pid 230252:tid 230464] [client 213.152.162.104:58834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JZk0Dwhk5-Z44XrpWCwAAAuk"]
[Tue Jul 21 07:26:46.526566 2026] [security2:error] [pid 230252:tid 230451] [client 4.204.201.85:3319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/users.php"] [unique_id "al9JZk0Dwhk5-Z44XrpWDAAAAtw"]
[Tue Jul 21 07:26:46.918139 2026] [security2:error] [pid 229246:tid 229440] [client 4.204.201.85:26577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/177.php"] [unique_id "al9JZiBMYeh5YLVG45x6YAAAAlQ"]
[Tue Jul 21 07:26:47.011598 2026] [security2:error] [pid 229246:tid 229394] [client 74.7.230.49:48536] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alvesmacedo.com"] [uri "/cgi-sys/404.html"] [unique_id "al9JZyBMYeh5YLVG45x6YQACJks"]
[Tue Jul 21 07:26:47.109406 2026] [security2:error] [pid 230252:tid 230294] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JZ00Dwhk5-Z44XrpWEgAC0yg"]
[Tue Jul 21 07:26:47.109601 2026] [security2:error] [pid 230252:tid 230442] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JZ00Dwhk5-Z44XrpWEgAC0yg"]
[Tue Jul 21 07:26:47.193644 2026] [security2:error] [pid 229246:tid 229499] [client 45.8.17.118:42969] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/goods.php"] [unique_id "al9JZyBMYeh5YLVG45x6ZQAAAo8"]
[Tue Jul 21 07:26:47.267602 2026] [security2:error] [pid 230252:tid 230392] [client 4.204.201.85:3260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/config.php"] [unique_id "al9JZ00Dwhk5-Z44XrpWFAAAAqE"]
[Tue Jul 21 07:26:47.276490 2026] [security2:error] [pid 229246:tid 229433] [client 139.135.44.145:53459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JZyBMYeh5YLVG45x6ZwAAAk0"]
[Tue Jul 21 07:26:47.276589 2026] [security2:error] [pid 229246:tid 229433] [client 139.135.44.145:53459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JZyBMYeh5YLVG45x6ZwAAAk0"]
[Tue Jul 21 07:26:47.560622 2026] [security2:error] [pid 229246:tid 229380] [client 20.104.96.117:59798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/patie.php"] [unique_id "al9JZyBMYeh5YLVG45x6bAAAAhg"]
[Tue Jul 21 07:26:47.787445 2026] [security2:error] [pid 230252:tid 230477] [client 4.204.201.85:3312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/gettest.php"] [unique_id "al9JZ00Dwhk5-Z44XrpWFQAAAvY"]
[Tue Jul 21 07:26:48.086692 2026] [security2:error] [pid 230252:tid 230474] [client 20.220.225.223:45403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/hp3.php"] [unique_id "al9JaE0Dwhk5-Z44XrpWGwAAAvM"]
[Tue Jul 21 07:26:48.269240 2026] [security2:error] [pid 230252:tid 230478] [client 4.204.201.85:3285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/min.php"] [unique_id "al9JaE0Dwhk5-Z44XrpWIQAAAvc"]
[Tue Jul 21 07:26:48.341993 2026] [security2:error] [pid 229246:tid 229476] [client 20.220.225.223:31168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/samll.php"] [unique_id "al9JaCBMYeh5YLVG45x6dQAAAng"]
[Tue Jul 21 07:26:48.507229 2026] [security2:error] [pid 230252:tid 230416] [client 117.251.86.144:48712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JaE0Dwhk5-Z44XrpWJgAAArk"]
[Tue Jul 21 07:26:48.507376 2026] [security2:error] [pid 230252:tid 230416] [client 117.251.86.144:48712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JaE0Dwhk5-Z44XrpWJgAAArk"]
[Tue Jul 21 07:26:48.572519 2026] [security2:error] [pid 230252:tid 230467] [client 20.104.96.117:59602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/aa.php"] [unique_id "al9JaE0Dwhk5-Z44XrpWJwAAAuw"]
[Tue Jul 21 07:26:48.600802 2026] [security2:error] [pid 229246:tid 229423] [client 4.204.201.85:26606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/dvjul.php"] [unique_id "al9JaCBMYeh5YLVG45x6ewAAAkM"]
[Tue Jul 21 07:26:48.755514 2026] [security2:error] [pid 230252:tid 230451] [client 74.249.245.134:54361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/66.php"] [unique_id "al9JaE0Dwhk5-Z44XrpWLAAAAtw"]
[Tue Jul 21 07:26:48.987957 2026] [security2:error] [pid 230252:tid 230491] [client 45.8.17.64:25723] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/edit-tags.php"] [unique_id "al9JaE0Dwhk5-Z44XrpWMgAAAwQ"]
[Tue Jul 21 07:26:49.088440 2026] [security2:error] [pid 230252:tid 230439] [client 20.226.60.151:61086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/ssla.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWOAAAAtA"]
[Tue Jul 21 07:26:49.412698 2026] [security2:error] [pid 229246:tid 229456] [client 20.104.96.117:59818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/xwpg.php"] [unique_id "al9JaSBMYeh5YLVG45x6hAAAAmQ"]
[Tue Jul 21 07:26:49.641590 2026] [security2:error] [pid 230252:tid 230430] [client 20.151.10.161:65462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/c.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWOgAAAsc"]
[Tue Jul 21 07:26:49.654203 2026] [security2:error] [pid 230252:tid 230306] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWOwACnTQ"]
[Tue Jul 21 07:26:49.654327 2026] [security2:error] [pid 230252:tid 230388] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWOwACnTQ"]
[Tue Jul 21 07:26:49.654778 2026] [security2:error] [pid 230252:tid 230484] [client 4.204.201.85:3320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/biufile.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWPAAAAv0"]
[Tue Jul 21 07:26:49.660796 2026] [security2:error] [pid 230252:tid 230477] [client 213.152.162.104:42142] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWPQAAAvY"]
[Tue Jul 21 07:26:49.660909 2026] [security2:error] [pid 230252:tid 230477] [client 213.152.162.104:42142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWPQAAAvY"]
[Tue Jul 21 07:26:49.704856 2026] [security2:error] [pid 230252:tid 230374] [remote 182.77.62.24:60756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-login.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWPwACy3c"]
[Tue Jul 21 07:26:49.744039 2026] [security2:error] [pid 230252:tid 230473] [client 193.36.225.73:36805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWQwAAAvI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:49.827176 2026] [access_compat:error] [pid 230252:tid 230419] [client 162.241.63.68:57584] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:26:49.848921 2026] [security2:error] [pid 229246:tid 229303] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9JaSBMYeh5YLVG45x6iQACjDg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:49.861135 2026] [security2:error] [pid 229246:tid 229257] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9JaSBMYeh5YLVG45x6iwACego"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:49.868891 2026] [security2:error] [pid 230252:tid 230329] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWQAAC0ko"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:49.887885 2026] [security2:error] [pid 230252:tid 230288] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9JaU0Dwhk5-Z44XrpWQgAC6CI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:50.108522 2026] [security2:error] [pid 230252:tid 230346] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWTwAC11s"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:50.284962 2026] [security2:error] [pid 230252:tid 230464] [client 45.8.17.127:56373] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/filemanager.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWUQAAAuk"]
[Tue Jul 21 07:26:50.344254 2026] [security2:error] [pid 230252:tid 230254] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWUgAC6gA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:50.411276 2026] [security2:error] [pid 230252:tid 230480] [client 20.104.96.117:59835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ops.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWVAAAAvk"]
[Tue Jul 21 07:26:50.429097 2026] [security2:error] [pid 230252:tid 230379] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWVQAC63w"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:50.434426 2026] [security2:error] [pid 230252:tid 230508] [client 4.204.201.85:3265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/av.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWVgAAAxU"]
[Tue Jul 21 07:26:50.449023 2026] [security2:error] [pid 229246:tid 229467] [client 59.96.220.140:63064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JaiBMYeh5YLVG45x6kgAAAm8"]
[Tue Jul 21 07:26:50.449160 2026] [security2:error] [pid 229246:tid 229467] [client 59.96.220.140:63064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JaiBMYeh5YLVG45x6kgAAAm8"]
[Tue Jul 21 07:26:50.460308 2026] [security2:error] [pid 230252:tid 230339] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWVwAC0VQ"]
[Tue Jul 21 07:26:50.460511 2026] [security2:error] [pid 230252:tid 230440] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWVwAC0VQ"]
[Tue Jul 21 07:26:50.467222 2026] [security2:error] [pid 230252:tid 230354] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWWAADBWM"]
[Tue Jul 21 07:26:50.467394 2026] [security2:error] [pid 230252:tid 230492] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWWAADBWM"]
[Tue Jul 21 07:26:50.511337 2026] [security2:error] [pid 230252:tid 230371] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWWgAC5nQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:50.531044 2026] [security2:error] [pid 229246:tid 229339] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9JaiBMYeh5YLVG45x6lgAChlw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:26:50.626310 2026] [security2:error] [pid 230252:tid 230490] [client 20.52.136.55:1594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/moon.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWWwAAAwM"]
[Tue Jul 21 07:26:50.807919 2026] [security2:error] [pid 230252:tid 230419] [client 20.226.60.151:61062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.acupunturaebemestar.com.br"] [uri "/zc-131.php"] [unique_id "al9Jak0Dwhk5-Z44XrpWXAAAArw"]
[Tue Jul 21 07:26:51.007968 2026] [security2:error] [pid 230252:tid 230471] [client 45.251.232.145:65485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ja00Dwhk5-Z44XrpWXQAAAvA"]
[Tue Jul 21 07:26:51.008110 2026] [security2:error] [pid 230252:tid 230471] [client 45.251.232.145:65485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ja00Dwhk5-Z44XrpWXQAAAvA"]
[Tue Jul 21 07:26:51.014292 2026] [security2:error] [pid 229246:tid 229444] [client 20.220.225.223:60368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JayBMYeh5YLVG45x6nQAAAlg"]
[Tue Jul 21 07:26:51.071694 2026] [security2:error] [pid 229246:tid 229491] [client 20.104.96.117:59787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/mac.php"] [unique_id "al9JayBMYeh5YLVG45x6ngAAAoc"]
[Tue Jul 21 07:26:51.183289 2026] [security2:error] [pid 229246:tid 229385] [client 45.8.17.136:21381] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/"] [unique_id "al9JayBMYeh5YLVG45x6nwAAAh0"]
[Tue Jul 21 07:26:51.219193 2026] [security2:error] [pid 229246:tid 229383] [client 4.204.201.85:3237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/coffexium.php"] [unique_id "al9JayBMYeh5YLVG45x6oAAAAhs"]
[Tue Jul 21 07:26:51.251931 2026] [security2:error] [pid 229246:tid 229406] [client 74.249.245.134:54381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/666.php"] [unique_id "al9JayBMYeh5YLVG45x6oQAAAjI"]
[Tue Jul 21 07:26:51.365871 2026] [security2:error] [pid 230252:tid 230382] [remote 72.167.132.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cromobelo.com.br"] [uri "/wp-login.php"] [unique_id "al9Ja00Dwhk5-Z44XrpWXwAC-H8"]
[Tue Jul 21 07:26:51.451550 2026] [security2:error] [pid 229246:tid 229470] [client 173.252.95.6:47944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JayBMYeh5YLVG45x6owAAAnI"]
[Tue Jul 21 07:26:51.600750 2026] [security2:error] [pid 229246:tid 229417] [client 20.151.10.161:63710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/aa.php"] [unique_id "al9JayBMYeh5YLVG45x6pwAAAj0"]
[Tue Jul 21 07:26:51.630138 2026] [security2:error] [pid 229246:tid 229451] [client 4.204.201.85:3224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/core.php"] [unique_id "al9JayBMYeh5YLVG45x6qAAAAl8"]
[Tue Jul 21 07:26:51.778844 2026] [security2:error] [pid 229246:tid 229483] [client 20.104.96.117:59830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/mg.php"] [unique_id "al9JayBMYeh5YLVG45x6qgAAAn8"]
[Tue Jul 21 07:26:51.852385 2026] [security2:error] [pid 229246:tid 229493] [client 103.106.20.201:65254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JayBMYeh5YLVG45x6qwAAAok"]
[Tue Jul 21 07:26:51.852509 2026] [security2:error] [pid 229246:tid 229493] [client 103.106.20.201:65254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JayBMYeh5YLVG45x6qwAAAok"]
[Tue Jul 21 07:26:52.211135 2026] [security2:error] [pid 229246:tid 229456] [client 20.220.225.223:48547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/aa1.php"] [unique_id "al9JbCBMYeh5YLVG45x6sQAAAmQ"]
[Tue Jul 21 07:26:52.279362 2026] [security2:error] [pid 230252:tid 230418] [client 4.204.201.85:3233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/als.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWZAAAArs"]
[Tue Jul 21 07:26:52.388675 2026] [security2:error] [pid 230252:tid 230451] [client 45.8.17.144:41915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-config-sample.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWZgAAAtw"]
[Tue Jul 21 07:26:52.414045 2026] [security2:error] [pid 230252:tid 230364] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWZwAC2G0"]
[Tue Jul 21 07:26:52.414230 2026] [security2:error] [pid 230252:tid 230447] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWZwAC2G0"]
[Tue Jul 21 07:26:52.579971 2026] [security2:error] [pid 230252:tid 230480] [client 4.204.201.85:3227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/simple.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWagAAAvk"]
[Tue Jul 21 07:26:52.802393 2026] [security2:error] [pid 230252:tid 230499] [client 103.174.34.15:61664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWbAAAAww"]
[Tue Jul 21 07:26:52.802529 2026] [security2:error] [pid 230252:tid 230499] [client 103.174.34.15:61664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWbAAAAww"]
[Tue Jul 21 07:26:52.863636 2026] [security2:error] [pid 230252:tid 230406] [client 20.151.10.161:49083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/themes.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWbQAAAq8"]
[Tue Jul 21 07:26:52.898807 2026] [security2:error] [pid 230252:tid 230400] [client 20.104.96.117:59614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-post-data.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWbgAAAqk"]
[Tue Jul 21 07:26:52.901233 2026] [security2:error] [pid 230252:tid 230494] [client 20.151.10.161:65475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/100.php"] [unique_id "al9JbE0Dwhk5-Z44XrpWbwAAAwc"]
[Tue Jul 21 07:26:53.029377 2026] [security2:error] [pid 230252:tid 230410] [client 4.204.201.85:3215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/init.php"] [unique_id "al9JbU0Dwhk5-Z44XrpWcgAAArM"]
[Tue Jul 21 07:26:53.189775 2026] [security2:error] [pid 229246:tid 229435] [client 74.249.245.134:54376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/byp.php"] [unique_id "al9JbSBMYeh5YLVG45x6vgAAAk8"]
[Tue Jul 21 07:26:53.385919 2026] [security2:error] [pid 230252:tid 230477] [client 45.8.17.144:21349] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403.php"] [unique_id "al9JbU0Dwhk5-Z44XrpWdQAAAvY"]
[Tue Jul 21 07:26:53.426671 2026] [security2:error] [pid 230252:tid 230420] [client 20.220.225.223:60357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9JbU0Dwhk5-Z44XrpWdgAAAr0"]
[Tue Jul 21 07:26:53.438350 2026] [security2:error] [pid 230252:tid 230466] [client 175.45.70.82:52579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JbU0Dwhk5-Z44XrpWdwAAAus"]
[Tue Jul 21 07:26:53.438470 2026] [security2:error] [pid 230252:tid 230466] [client 175.45.70.82:52579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JbU0Dwhk5-Z44XrpWdwAAAus"]
[Tue Jul 21 07:26:53.769327 2026] [security2:error] [pid 230252:tid 230468] [client 4.204.201.85:26560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/fpwch.php"] [unique_id "al9JbU0Dwhk5-Z44XrpWfgAAAu0"]
[Tue Jul 21 07:26:53.879716 2026] [security2:error] [pid 229246:tid 229466] [client 20.104.96.117:59603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/pucci.php"] [unique_id "al9JbSBMYeh5YLVG45x6wgAAAm4"]
[Tue Jul 21 07:26:54.138845 2026] [security2:error] [pid 230252:tid 230501] [client 154.192.233.199:58783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWgAAAAw4"]
[Tue Jul 21 07:26:54.138979 2026] [security2:error] [pid 230252:tid 230501] [client 154.192.233.199:58783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWgAAAAw4"]
[Tue Jul 21 07:26:54.290998 2026] [security2:error] [pid 230252:tid 230511] [client 4.204.201.85:26597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/domvf.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWggAAAxg"]
[Tue Jul 21 07:26:54.291718 2026] [security2:error] [pid 230252:tid 230500] [client 152.59.154.239:49583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWgQAAAw0"]
[Tue Jul 21 07:26:54.461365 2026] [security2:error] [pid 230252:tid 230395] [client 20.220.225.223:45975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/acew67.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWhQAAAqQ"]
[Tue Jul 21 07:26:54.589885 2026] [security2:error] [pid 230252:tid 230408] [client 45.8.17.57:20859] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWhgAAArE"]
[Tue Jul 21 07:26:54.590421 2026] [security2:error] [pid 230252:tid 230493] [client 136.144.33.102:26809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWhwAAAwY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:54.970843 2026] [security2:error] [pid 230252:tid 230393] [client 4.204.201.85:26616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWjAAAAqI"]
[Tue Jul 21 07:26:54.977944 2026] [security2:error] [pid 230252:tid 230418] [client 20.104.96.117:59781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/black.php"] [unique_id "al9Jbk0Dwhk5-Z44XrpWjQAAArs"]
[Tue Jul 21 07:26:55.077159 2026] [security2:error] [pid 230252:tid 230447] [client 20.52.136.55:1756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/ws83.php"] [unique_id "al9Jb00Dwhk5-Z44XrpWjgAAAtg"]
[Tue Jul 21 07:26:55.103487 2026] [security2:error] [pid 229246:tid 229292] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JbyBMYeh5YLVG45x61QACaC0"]
[Tue Jul 21 07:26:55.103619 2026] [security2:error] [pid 229246:tid 229460] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JbyBMYeh5YLVG45x61QACaC0"]
[Tue Jul 21 07:26:55.132040 2026] [security2:error] [pid 230252:tid 230396] [client 74.249.245.134:5563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/date.php"] [unique_id "al9Jb00Dwhk5-Z44XrpWjwAAAqU"]
[Tue Jul 21 07:26:55.436451 2026] [security2:error] [pid 229246:tid 229401] [client 20.220.225.223:38667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/abcd.php"] [unique_id "al9JbyBMYeh5YLVG45x64wAAAi0"]
[Tue Jul 21 07:26:55.546758 2026] [security2:error] [pid 230252:tid 230440] [client 213.152.162.104:42150] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Jb00Dwhk5-Z44XrpWkwAAAtE"]
[Tue Jul 21 07:26:55.546897 2026] [security2:error] [pid 230252:tid 230440] [client 213.152.162.104:42150] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Jb00Dwhk5-Z44XrpWkwAAAtE"]
[Tue Jul 21 07:26:55.546930 2026] [security2:error] [pid 230252:tid 230440] [client 213.152.162.104:42150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Jb00Dwhk5-Z44XrpWkwAAAtE"]
[Tue Jul 21 07:26:55.649346 2026] [security2:error] [pid 229246:tid 229474] [client 4.204.201.85:26579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/class.php"] [unique_id "al9JbyBMYeh5YLVG45x65wAAAnY"]
[Tue Jul 21 07:26:55.734518 2026] [security2:error] [pid 229246:tid 229432] [client 20.151.10.161:63679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/footer.php"] [unique_id "al9JbyBMYeh5YLVG45x67AAAAkw"]
[Tue Jul 21 07:26:55.742890 2026] [security2:error] [pid 229246:tid 229476] [client 20.220.225.223:53488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/wander.php"] [unique_id "al9JbyBMYeh5YLVG45x67QAAAng"]
[Tue Jul 21 07:26:56.092616 2026] [security2:error] [pid 229246:tid 229290] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JcCBMYeh5YLVG45x69wACeis"]
[Tue Jul 21 07:26:56.092789 2026] [security2:error] [pid 229246:tid 229478] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JcCBMYeh5YLVG45x69wACeis"]
[Tue Jul 21 07:26:56.100065 2026] [security2:error] [pid 229246:tid 229395] [client 20.104.96.117:59621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/zlece.php"] [unique_id "al9JcCBMYeh5YLVG45x6-AAAAic"]
[Tue Jul 21 07:26:56.225546 2026] [security2:error] [pid 229246:tid 229435] [client 4.204.201.85:3275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/echkm.php"] [unique_id "al9JcCBMYeh5YLVG45x6-wAAAk8"]
[Tue Jul 21 07:26:56.600572 2026] [security2:error] [pid 229246:tid 229467] [client 4.204.201.85:3325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/lib.php"] [unique_id "al9JcCBMYeh5YLVG45x7AQAAAm8"]
[Tue Jul 21 07:26:56.613188 2026] [security2:error] [pid 229246:tid 229439] [client 20.104.96.117:59824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/vssrs.php"] [unique_id "al9JcCBMYeh5YLVG45x7AgAAAlM"]
[Tue Jul 21 07:26:56.695056 2026] [autoindex:error] [pid 230252:tid 230496] [client 198.235.24.37:63908] AH01276: Cannot serve directory /home1/siteec36/vcacesorios.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:26:56.833677 2026] [security2:error] [pid 230252:tid 230443] [client 103.162.129.114:61184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JcE0Dwhk5-Z44XrpWlwAAAtQ"]
[Tue Jul 21 07:26:56.833821 2026] [security2:error] [pid 230252:tid 230443] [client 103.162.129.114:61184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JcE0Dwhk5-Z44XrpWlwAAAtQ"]
[Tue Jul 21 07:26:57.043706 2026] [security2:error] [pid 230252:tid 230459] [client 4.204.201.85:3277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/login.php"] [unique_id "al9JcU0Dwhk5-Z44XrpWmQAAAuQ"]
[Tue Jul 21 07:26:57.241073 2026] [security2:error] [pid 229246:tid 229499] [client 74.249.245.134:54389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/pomo.php"] [unique_id "al9JcSBMYeh5YLVG45x7CQAAAo8"]
[Tue Jul 21 07:26:57.255685 2026] [security2:error] [pid 230252:tid 230386] [client 20.220.225.223:53457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/jga.php"] [unique_id "al9JcU0Dwhk5-Z44XrpWmwAAAps"]
[Tue Jul 21 07:26:57.322180 2026] [security2:error] [pid 230252:tid 230434] [client 82.102.28.107:50200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JcU0Dwhk5-Z44XrpWnQAAAss"]
[Tue Jul 21 07:26:57.322260 2026] [security2:error] [pid 230252:tid 230434] [client 82.102.28.107:50200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JcU0Dwhk5-Z44XrpWnQAAAss"]
[Tue Jul 21 07:26:57.463871 2026] [security2:error] [pid 230252:tid 230476] [client 4.204.201.85:3327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/a2.php"] [unique_id "al9JcU0Dwhk5-Z44XrpWngAAAvU"]
[Tue Jul 21 07:26:57.658390 2026] [security2:error] [pid 230252:tid 230301] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JcU0Dwhk5-Z44XrpWnwAC8i8"]
[Tue Jul 21 07:26:57.658523 2026] [security2:error] [pid 230252:tid 230473] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JcU0Dwhk5-Z44XrpWnwAC8i8"]
[Tue Jul 21 07:26:57.739566 2026] [security2:error] [pid 229246:tid 229460] [client 20.151.10.161:63732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/users.php"] [unique_id "al9JcSBMYeh5YLVG45x7EAAAAmg"]
[Tue Jul 21 07:26:57.900634 2026] [security2:error] [pid 229246:tid 229465] [client 4.204.201.85:26376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/d61.php"] [unique_id "al9JcSBMYeh5YLVG45x7EwAAAm0"]
[Tue Jul 21 07:26:57.985146 2026] [security2:error] [pid 229246:tid 229383] [client 45.8.17.139:54341] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/"] [unique_id "al9JcSBMYeh5YLVG45x7FAAAAhs"]
[Tue Jul 21 07:26:58.070377 2026] [security2:error] [pid 230252:tid 230458] [client 139.135.44.145:54259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Jck0Dwhk5-Z44XrpWpAAAAuM"]
[Tue Jul 21 07:26:58.070512 2026] [security2:error] [pid 230252:tid 230458] [client 139.135.44.145:54259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Jck0Dwhk5-Z44XrpWpAAAAuM"]
[Tue Jul 21 07:26:58.378636 2026] [security2:error] [pid 229246:tid 229386] [client 4.204.201.85:3314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/info.php"] [unique_id "al9JciBMYeh5YLVG45x7FwAAAh4"]
[Tue Jul 21 07:26:58.450624 2026] [security2:error] [pid 230252:tid 230403] [client 136.144.33.106:21503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Jck0Dwhk5-Z44XrpWqQAAAqw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:26:58.751298 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:65490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/177.php"] [unique_id "al9Jck0Dwhk5-Z44XrpWqwAAAwY"]
[Tue Jul 21 07:26:58.781116 2026] [security2:error] [pid 230252:tid 230467] [client 45.8.17.108:45315] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/item.php"] [unique_id "al9Jck0Dwhk5-Z44XrpWrQAAAuw"]
[Tue Jul 21 07:26:58.853218 2026] [security2:error] [pid 230252:tid 230397] [client 20.104.96.117:59822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wicked.php"] [unique_id "al9Jck0Dwhk5-Z44XrpWrgAAAqY"]
[Tue Jul 21 07:26:59.042337 2026] [security2:error] [pid 229246:tid 229451] [client 20.220.225.223:53471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/x.php"] [unique_id "al9JcyBMYeh5YLVG45x7HQAAAl8"]
[Tue Jul 21 07:26:59.098870 2026] [security2:error] [pid 230252:tid 230462] [client 4.204.201.85:26564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/11.php"] [unique_id "al9Jc00Dwhk5-Z44XrpWswAAAuc"]
[Tue Jul 21 07:26:59.323176 2026] [security2:error] [pid 230252:tid 230395] [client 117.251.86.144:45498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Jc00Dwhk5-Z44XrpWtgAAAqQ"]
[Tue Jul 21 07:26:59.323366 2026] [security2:error] [pid 230252:tid 230395] [client 117.251.86.144:45498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Jc00Dwhk5-Z44XrpWtgAAAqQ"]
[Tue Jul 21 07:26:59.530539 2026] [security2:error] [pid 230252:tid 230423] [client 20.52.136.55:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/CDX1.php"] [unique_id "al9Jc00Dwhk5-Z44XrpWuQAAAsA"]
[Tue Jul 21 07:26:59.762792 2026] [security2:error] [pid 230252:tid 230400] [client 20.151.10.161:63622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/config.php"] [unique_id "al9Jc00Dwhk5-Z44XrpWvwAAAqk"]
[Tue Jul 21 07:26:59.889132 2026] [security2:error] [pid 229246:tid 229436] [client 45.8.17.135:53359] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/adminfuns.php"] [unique_id "al9JcyBMYeh5YLVG45x7JgAAAlA"]
[Tue Jul 21 07:26:59.892689 2026] [security2:error] [pid 230252:tid 230279] [remote 41.76.214.143:60422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9Jc00Dwhk5-Z44XrpWwgACpxk"]
[Tue Jul 21 07:27:00.036500 2026] [security2:error] [pid 230252:tid 230488] [client 4.204.201.85:3255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/v2.php"] [unique_id "al9JdE0Dwhk5-Z44XrpWxAAAAwE"]
[Tue Jul 21 07:27:00.298543 2026] [security2:error] [pid 230252:tid 230443] [client 20.220.225.223:27140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9JdE0Dwhk5-Z44XrpWxgAAAtQ"]
[Tue Jul 21 07:27:00.433768 2026] [security2:error] [pid 230252:tid 230503] [client 20.151.10.161:63731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/gettest.php"] [unique_id "al9JdE0Dwhk5-Z44XrpWyAAAAxA"]
[Tue Jul 21 07:27:00.862393 2026] [security2:error] [pid 229246:tid 229430] [client 4.204.201.85:26614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/panel.php"] [unique_id "al9JdCBMYeh5YLVG45x7LgAAAko"]
[Tue Jul 21 07:27:00.921917 2026] [security2:error] [pid 229246:tid 229291] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JdCBMYeh5YLVG45x7MAACRCw"]
[Tue Jul 21 07:27:00.922144 2026] [security2:error] [pid 229246:tid 229424] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JdCBMYeh5YLVG45x7MAACRCw"]
[Tue Jul 21 07:27:00.986224 2026] [security2:error] [pid 229246:tid 229421] [client 45.8.17.107:60215] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wpx/"] [unique_id "al9JdCBMYeh5YLVG45x7MwAAAkE"]
[Tue Jul 21 07:27:00.993369 2026] [security2:error] [pid 229246:tid 229256] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JdCBMYeh5YLVG45x7NAACgwk"]
[Tue Jul 21 07:27:00.993550 2026] [security2:error] [pid 229246:tid 229487] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JdCBMYeh5YLVG45x7NAACgwk"]
[Tue Jul 21 07:27:01.116893 2026] [security2:error] [pid 229246:tid 229264] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7NQACbxE"]
[Tue Jul 21 07:27:01.117048 2026] [security2:error] [pid 229246:tid 229467] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7NQACbxE"]
[Tue Jul 21 07:27:01.142174 2026] [security2:error] [pid 229246:tid 229382] [client 82.102.28.107:46258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7NgAAAho"]
[Tue Jul 21 07:27:01.142291 2026] [security2:error] [pid 229246:tid 229382] [client 82.102.28.107:46258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7NgAAAho"]
[Tue Jul 21 07:27:01.302212 2026] [security2:error] [pid 230252:tid 230501] [client 4.204.201.85:26586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/dex.php"] [unique_id "al9JdU0Dwhk5-Z44XrpW0gAAAw4"]
[Tue Jul 21 07:27:01.471673 2026] [security2:error] [pid 229246:tid 229402] [client 45.251.232.145:49616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7PgAAAi4"]
[Tue Jul 21 07:27:01.471789 2026] [security2:error] [pid 229246:tid 229402] [client 45.251.232.145:49616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7PgAAAi4"]
[Tue Jul 21 07:27:01.490250 2026] [security2:error] [pid 229246:tid 229388] [client 213.152.162.104:41670] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7PwAAAiA"]
[Tue Jul 21 07:27:01.490341 2026] [security2:error] [pid 229246:tid 229388] [client 213.152.162.104:41670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JdSBMYeh5YLVG45x7PwAAAiA"]
[Tue Jul 21 07:27:01.798653 2026] [security2:error] [pid 230252:tid 230276] [remote 57.141.18.82:45856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemape.xml"] [unique_id "al9JdU0Dwhk5-Z44XrpW1gACtBY"]
[Tue Jul 21 07:27:01.823286 2026] [security2:error] [pid 230252:tid 230384] [client 4.204.201.85:3264] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bcaccj.org"] [uri "/1.php"] [unique_id "al9JdU0Dwhk5-Z44XrpW1wAAApk"]
[Tue Jul 21 07:27:01.823390 2026] [security2:error] [pid 230252:tid 230384] [client 4.204.201.85:3264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/1.php"] [unique_id "al9JdU0Dwhk5-Z44XrpW1wAAApk"]
[Tue Jul 21 07:27:02.080675 2026] [security2:error] [pid 230252:tid 230505] [client 20.151.10.161:65437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/min.php"] [unique_id "al9Jdk0Dwhk5-Z44XrpW4AAAAxI"]
[Tue Jul 21 07:27:02.090680 2026] [security2:error] [pid 230252:tid 230447] [client 45.8.17.142:61523] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/files.php"] [unique_id "al9Jdk0Dwhk5-Z44XrpW4QAAAtg"]
[Tue Jul 21 07:27:02.172198 2026] [security2:error] [pid 229246:tid 229479] [client 59.96.220.140:63496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JdiBMYeh5YLVG45x7UwAAAns"]
[Tue Jul 21 07:27:02.172328 2026] [security2:error] [pid 229246:tid 229479] [client 59.96.220.140:63496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JdiBMYeh5YLVG45x7UwAAAns"]
[Tue Jul 21 07:27:02.329359 2026] [security2:error] [pid 230252:tid 230423] [client 74.249.245.134:54349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/test1.php"] [unique_id "al9Jdk0Dwhk5-Z44XrpW5AAAAsA"]
[Tue Jul 21 07:27:02.916695 2026] [security2:error] [pid 230252:tid 230292] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Jdk0Dwhk5-Z44XrpW6wAC0yY"]
[Tue Jul 21 07:27:02.916832 2026] [security2:error] [pid 230252:tid 230442] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Jdk0Dwhk5-Z44XrpW6wAC0yY"]
[Tue Jul 21 07:27:02.964827 2026] [security2:error] [pid 229246:tid 229400] [client 136.144.33.109:60869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JdiBMYeh5YLVG45x7agAAAiw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:03.021067 2026] [security2:error] [pid 230252:tid 230402] [client 103.106.20.201:49701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jd00Dwhk5-Z44XrpW7QAAAqs"]
[Tue Jul 21 07:27:03.021228 2026] [security2:error] [pid 230252:tid 230402] [client 103.106.20.201:49701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jd00Dwhk5-Z44XrpW7QAAAqs"]
[Tue Jul 21 07:27:03.045706 2026] [security2:error] [pid 230252:tid 230490] [client 4.204.201.85:26622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/ms.php"] [unique_id "al9Jd00Dwhk5-Z44XrpW7gAAAwM"]
[Tue Jul 21 07:27:03.090143 2026] [security2:error] [pid 229246:tid 229430] [client 45.8.17.128:44175] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/news-portal/zdata.php"] [unique_id "al9JdyBMYeh5YLVG45x7cgAAAko"]
[Tue Jul 21 07:27:03.100574 2026] [security2:error] [pid 229246:tid 229435] [client 20.151.10.161:63705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/edorxrr.php"] [unique_id "al9JdyBMYeh5YLVG45x7dAAAAk8"]
[Tue Jul 21 07:27:03.842293 2026] [security2:error] [pid 229246:tid 229421] [client 103.174.34.15:62151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JdyBMYeh5YLVG45x7jQAAAkE"]
[Tue Jul 21 07:27:03.842614 2026] [security2:error] [pid 229246:tid 229421] [client 103.174.34.15:62151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JdyBMYeh5YLVG45x7jQAAAkE"]
[Tue Jul 21 07:27:03.887496 2026] [security2:error] [pid 230252:tid 230473] [client 45.8.17.60:63157] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/"] [unique_id "al9Jd00Dwhk5-Z44XrpW9wAAAvI"]
[Tue Jul 21 07:27:04.196014 2026] [security2:error] [pid 229246:tid 229392] [client 4.204.201.85:3304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/memberfuns.php"] [unique_id "al9JeCBMYeh5YLVG45x7mQAAAiQ"]
[Tue Jul 21 07:27:04.289518 2026] [security2:error] [pid 229246:tid 229415] [client 175.45.70.82:53097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JeCBMYeh5YLVG45x7ngAAAjs"]
[Tue Jul 21 07:27:04.289614 2026] [security2:error] [pid 229246:tid 229415] [client 175.45.70.82:53097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JeCBMYeh5YLVG45x7ngAAAjs"]
[Tue Jul 21 07:27:04.397383 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:59588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/24.php"] [unique_id "al9JeE0Dwhk5-Z44XrpW-wAAAw4"]
[Tue Jul 21 07:27:04.566125 2026] [security2:error] [pid 230252:tid 230455] [client 20.220.225.223:46015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/bscclapb.php"] [unique_id "al9JeE0Dwhk5-Z44XrpW_AAAAuA"]
[Tue Jul 21 07:27:04.573852 2026] [security2:error] [pid 230252:tid 230424] [client 20.151.10.161:63067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/hur.php"] [unique_id "al9JeE0Dwhk5-Z44XrpW_QAAAsE"]
[Tue Jul 21 07:27:04.578290 2026] [security2:error] [pid 230252:tid 230453] [client 4.204.201.85:3274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/0.php"] [unique_id "al9JeE0Dwhk5-Z44XrpW_gAAAt4"]
[Tue Jul 21 07:27:04.644148 2026] [security2:error] [pid 229246:tid 229369] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-subscription/class-wc-subscription-diagnostics.php"] [unique_id "al9JeCBMYeh5YLVG45x7pQACgXo"]
[Tue Jul 21 07:27:04.746280 2026] [security2:error] [pid 230252:tid 230413] [client 74.249.245.134:17447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/fw.php"] [unique_id "al9JeE0Dwhk5-Z44XrpXAgAAArY"]
[Tue Jul 21 07:27:04.850655 2026] [security2:error] [pid 230252:tid 230419] [client 154.192.233.199:59679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JeE0Dwhk5-Z44XrpXAwAAArw"]
[Tue Jul 21 07:27:04.850806 2026] [security2:error] [pid 230252:tid 230419] [client 154.192.233.199:59679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JeE0Dwhk5-Z44XrpXAwAAArw"]
[Tue Jul 21 07:27:04.884525 2026] [security2:error] [pid 230252:tid 230475] [client 45.8.17.126:37605] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/classwithtostring.php"] [unique_id "al9JeE0Dwhk5-Z44XrpXBAAAAvQ"]
[Tue Jul 21 07:27:04.967097 2026] [security2:error] [pid 229246:tid 229343] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-notification/class-wc-subscription-diagnostics.php"] [unique_id "al9JeCBMYeh5YLVG45x7qQACIGA"]
[Tue Jul 21 07:27:05.180046 2026] [security2:error] [pid 229246:tid 229421] [client 109.248.148.246:52892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JeSBMYeh5YLVG45x7rgAAAkE"]
[Tue Jul 21 07:27:05.180149 2026] [security2:error] [pid 229246:tid 229421] [client 109.248.148.246:52892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JeSBMYeh5YLVG45x7rgAAAkE"]
[Tue Jul 21 07:27:05.409365 2026] [security2:error] [pid 229246:tid 229470] [client 20.220.225.223:53447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/ee.php"] [unique_id "al9JeSBMYeh5YLVG45x7sQAAAnI"]
[Tue Jul 21 07:27:05.634049 2026] [security2:error] [pid 230252:tid 230349] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JeU0Dwhk5-Z44XrpXDQAC6V4"]
[Tue Jul 21 07:27:05.634192 2026] [security2:error] [pid 230252:tid 230464] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JeU0Dwhk5-Z44XrpXDQAC6V4"]
[Tue Jul 21 07:27:05.649916 2026] [security2:error] [pid 229246:tid 229391] [client 93.108.115.148:63340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.115.108.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homemsedutoronline.com"] [uri "/xmlrpc.php"] [unique_id "al9JeSBMYeh5YLVG45x7tQAAAiM"]
[Tue Jul 21 07:27:05.650056 2026] [security2:error] [pid 229246:tid 229391] [client 93.108.115.148:63340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "homemsedutoronline.com"] [uri "/xmlrpc.php"] [unique_id "al9JeSBMYeh5YLVG45x7tQAAAiM"]
[Tue Jul 21 07:27:05.766980 2026] [security2:error] [pid 229246:tid 229454] [client 213.152.162.104:52238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JeSBMYeh5YLVG45x7uQAAAmI"]
[Tue Jul 21 07:27:05.767111 2026] [security2:error] [pid 229246:tid 229454] [client 213.152.162.104:52238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JeSBMYeh5YLVG45x7uQAAAmI"]
[Tue Jul 21 07:27:05.893498 2026] [security2:error] [pid 230252:tid 230331] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woo-product-slider-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JeU0Dwhk5-Z44XrpXEwAC3Uw"]
[Tue Jul 21 07:27:05.976573 2026] [security2:error] [pid 230252:tid 230485] [client 152.59.154.239:20624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JeU0Dwhk5-Z44XrpXFAAAAv4"]
[Tue Jul 21 07:27:05.985102 2026] [security2:error] [pid 230252:tid 230408] [client 45.8.17.123:43383] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/"] [unique_id "al9JeU0Dwhk5-Z44XrpXFQAAArE"]
[Tue Jul 21 07:27:05.994145 2026] [security2:error] [pid 229246:tid 229393] [client 20.151.10.161:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/zoro.php"] [unique_id "al9JeSBMYeh5YLVG45x7vAAAAiU"]
[Tue Jul 21 07:27:06.207979 2026] [security2:error] [pid 229246:tid 229260] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/testimonial-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JeiBMYeh5YLVG45x7vgACbA0"]
[Tue Jul 21 07:27:06.531613 2026] [security2:error] [pid 230252:tid 230270] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/smart-show-post-pro/src/Includes/LicenseLoader.php"] [unique_id "al9Jek0Dwhk5-Z44XrpXGwACuhA"]
[Tue Jul 21 07:27:06.553829 2026] [security2:error] [pid 229246:tid 229442] [client 4.204.201.85:3302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/BDKR28.php"] [unique_id "al9JeiBMYeh5YLVG45x7xgAAAlY"]
[Tue Jul 21 07:27:06.626901 2026] [security2:error] [pid 229246:tid 229344] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JeiBMYeh5YLVG45x7xwACP2E"]
[Tue Jul 21 07:27:06.627072 2026] [security2:error] [pid 229246:tid 229419] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JeiBMYeh5YLVG45x7xwACP2E"]
[Tue Jul 21 07:27:06.843197 2026] [security2:error] [pid 229246:tid 229338] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-subscription/class-wc-subscription-diagnostics.php"] [unique_id "al9JeiBMYeh5YLVG45x7zgACW1s"]
[Tue Jul 21 07:27:06.873576 2026] [security2:error] [pid 229246:tid 229411] [client 20.151.10.161:65425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/coffexium.php"] [unique_id "al9JeiBMYeh5YLVG45x70AAAAjc"]
[Tue Jul 21 07:27:06.920413 2026] [security2:error] [pid 229246:tid 229422] [client 4.204.201.85:26585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/green1.php"] [unique_id "al9JeiBMYeh5YLVG45x70QAAAkI"]
[Tue Jul 21 07:27:06.977679 2026] [security2:error] [pid 229246:tid 229492] [client 20.52.136.55:1579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/inputs.php"] [unique_id "al9JeiBMYeh5YLVG45x70wAAAog"]
[Tue Jul 21 07:27:06.993259 2026] [security2:error] [pid 229246:tid 229449] [client 45.8.17.127:61883] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9JeiBMYeh5YLVG45x71AAAAl0"]
[Tue Jul 21 07:27:07.160868 2026] [security2:error] [pid 230252:tid 230277] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-notification/class-wc-subscription-diagnostics.php"] [unique_id "al9Je00Dwhk5-Z44XrpXIAAC1hc"]
[Tue Jul 21 07:27:07.217668 2026] [security2:error] [pid 230252:tid 230473] [client 103.162.129.114:61745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Je00Dwhk5-Z44XrpXIQAAAvI"]
[Tue Jul 21 07:27:07.217795 2026] [security2:error] [pid 230252:tid 230473] [client 103.162.129.114:61745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Je00Dwhk5-Z44XrpXIQAAAvI"]
[Tue Jul 21 07:27:07.281074 2026] [security2:error] [pid 229246:tid 229480] [client 109.248.148.246:52904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JeyBMYeh5YLVG45x71wAAAnw"]
[Tue Jul 21 07:27:07.281249 2026] [security2:error] [pid 229246:tid 229480] [client 109.248.148.246:52904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JeyBMYeh5YLVG45x71wAAAnw"]
[Tue Jul 21 07:27:07.464264 2026] [security2:error] [pid 229246:tid 229387] [client 20.104.96.117:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JeyBMYeh5YLVG45x72wAAAh8"]
[Tue Jul 21 07:27:07.470854 2026] [security2:error] [pid 229246:tid 229402] [client 20.104.96.117:42396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/xacs.php"] [unique_id "al9JeyBMYeh5YLVG45x73AAAAi4"]
[Tue Jul 21 07:27:07.473094 2026] [security2:error] [pid 229246:tid 229330] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woo-product-slider-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JeyBMYeh5YLVG45x73QACdlM"]
[Tue Jul 21 07:27:07.487802 2026] [security2:error] [pid 229246:tid 229479] [client 4.204.201.85:26401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/nc4.php"] [unique_id "al9JeyBMYeh5YLVG45x73gAAAns"]
[Tue Jul 21 07:27:07.655203 2026] [security2:error] [pid 229246:tid 229465] [client 20.10.88.201:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "weightloss-review.shop"] [uri "/index.php"] [unique_id "al9JeyBMYeh5YLVG45x74gAAAm0"]
[Tue Jul 21 07:27:07.656332 2026] [security2:error] [pid 229246:tid 229473] [client 20.10.88.201:61441] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "weightloss-review.shop"] [uri "/robots.txt"] [unique_id "al9JeyBMYeh5YLVG45x74AAAAnU"]
[Tue Jul 21 07:27:07.726653 2026] [security2:error] [pid 230252:tid 230392] [client 193.36.225.73:28859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Je00Dwhk5-Z44XrpXJAAAAqE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:07.792305 2026] [security2:error] [pid 230252:tid 230278] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/testimonial-pro/src/Includes/LicenseLoader.php"] [unique_id "al9Je00Dwhk5-Z44XrpXJQADGBg"]
[Tue Jul 21 07:27:07.832877 2026] [security2:error] [pid 230252:tid 230439] [client 20.104.96.117:64059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Je00Dwhk5-Z44XrpXJwAAAtA"]
[Tue Jul 21 07:27:07.879519 2026] [security2:error] [pid 230252:tid 230425] [client 20.151.10.161:63727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/app.php"] [unique_id "al9Je00Dwhk5-Z44XrpXKQAAAsI"]
[Tue Jul 21 07:27:07.959235 2026] [security2:error] [pid 229246:tid 229380] [client 113.31.186.196:0] ModSecurity: Warning. Matched phrase "Custo" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "drajoanasiqueira.com"] [uri "/index.php"] [unique_id "al9JeiBMYeh5YLVG45x7yQAAAhg"]
[Tue Jul 21 07:27:07.984231 2026] [security2:error] [pid 230252:tid 230471] [client 4.204.201.85:26595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/a1.php"] [unique_id "al9Je00Dwhk5-Z44XrpXLAAAAvA"]
[Tue Jul 21 07:27:08.103324 2026] [security2:error] [pid 229246:tid 229297] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/smart-show-post-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JfCBMYeh5YLVG45x75gACXjI"]
[Tue Jul 21 07:27:08.140428 2026] [security2:error] [pid 230252:tid 230493] [client 20.104.96.117:64028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/media.php"] [unique_id "al9JfE0Dwhk5-Z44XrpXLwAAAwY"]
[Tue Jul 21 07:27:08.266595 2026] [security2:error] [pid 229246:tid 229360] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JfCBMYeh5YLVG45x76QACdHE"]
[Tue Jul 21 07:27:08.266728 2026] [security2:error] [pid 229246:tid 229472] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JfCBMYeh5YLVG45x76QACdHE"]
[Tue Jul 21 07:27:08.309918 2026] [security2:error] [pid 230252:tid 230447] [client 20.220.225.223:53477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/blue.php"] [unique_id "al9JfE0Dwhk5-Z44XrpXMgAAAtg"]
[Tue Jul 21 07:27:08.418293 2026] [security2:error] [pid 230252:tid 230423] [client 4.204.201.85:3244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/eee.php"] [unique_id "al9JfE0Dwhk5-Z44XrpXNgAAAsA"]
[Tue Jul 21 07:27:08.424123 2026] [security2:error] [pid 230252:tid 230257] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-subscription/class-wc-subscription-diagnostics.php"] [unique_id "al9JfE0Dwhk5-Z44XrpXNwACpAM"]
[Tue Jul 21 07:27:08.563030 2026] [security2:error] [pid 229246:tid 229451] [client 74.249.245.134:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/fm.php"] [unique_id "al9JfCBMYeh5YLVG45x77QAAAl8"]
[Tue Jul 21 07:27:08.616694 2026] [security2:error] [pid 229246:tid 229484] [client 20.104.96.117:64060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/images.php"] [unique_id "al9JfCBMYeh5YLVG45x77gAAAoA"]
[Tue Jul 21 07:27:08.734419 2026] [security2:error] [pid 229246:tid 229296] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-notification/class-wc-subscription-diagnostics.php"] [unique_id "al9JfCBMYeh5YLVG45x78gACZTE"]
[Tue Jul 21 07:27:08.755307 2026] [security2:error] [pid 229246:tid 229488] [client 20.151.10.161:65524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/core.php"] [unique_id "al9JfCBMYeh5YLVG45x78wAAAoQ"]
[Tue Jul 21 07:27:08.777929 2026] [security2:error] [pid 230252:tid 230398] [client 109.248.148.246:33912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JfE0Dwhk5-Z44XrpXPQAAAqc"]
[Tue Jul 21 07:27:08.778018 2026] [security2:error] [pid 230252:tid 230398] [client 109.248.148.246:33912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JfE0Dwhk5-Z44XrpXPQAAAqc"]
[Tue Jul 21 07:27:08.963680 2026] [security2:error] [pid 230252:tid 230430] [client 4.204.201.85:26379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/wp-aothait.php"] [unique_id "al9JfE0Dwhk5-Z44XrpXQQAAAsc"]
[Tue Jul 21 07:27:09.040829 2026] [security2:error] [pid 230252:tid 230495] [client 139.135.44.145:53139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXQgAAAwg"]
[Tue Jul 21 07:27:09.053313 2026] [security2:error] [pid 230252:tid 230380] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woo-product-slider-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXQwACrn0"]
[Tue Jul 21 07:27:09.092303 2026] [security2:error] [pid 230252:tid 230485] [client 20.104.96.117:62931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/gecko.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXRQAAAv4"]
[Tue Jul 21 07:27:09.109852 2026] [security2:error] [pid 230252:tid 230495] [client 139.135.44.145:53139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXQgAAAwg"]
[Tue Jul 21 07:27:09.188622 2026] [security2:error] [pid 230252:tid 230460] [client 45.8.17.140:55749] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/fm.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXSQAAAuU"]
[Tue Jul 21 07:27:09.356829 2026] [security2:error] [pid 229246:tid 229414] [client 20.104.96.117:59793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/zildan.php"] [unique_id "al9JfSBMYeh5YLVG45x7-wAAAjo"]
[Tue Jul 21 07:27:09.365795 2026] [security2:error] [pid 229246:tid 229314] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/testimonial-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JfSBMYeh5YLVG45x7_AACTEM"]
[Tue Jul 21 07:27:09.390994 2026] [security2:error] [pid 229246:tid 229436] [client 20.220.225.223:60359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/wp-signup.php"] [unique_id "al9JfSBMYeh5YLVG45x7_QAAAlA"]
[Tue Jul 21 07:27:09.418665 2026] [security2:error] [pid 230252:tid 230468] [client 4.204.201.85:3206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/config.json.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXTQAAAu0"]
[Tue Jul 21 07:27:09.534458 2026] [security2:error] [pid 230252:tid 230511] [client 20.151.10.161:49070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/dx.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXUgAAAxg"]
[Tue Jul 21 07:27:09.677154 2026] [security2:error] [pid 230252:tid 230500] [client 20.104.96.117:62919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/82.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXUwAAAw0"]
[Tue Jul 21 07:27:09.683397 2026] [security2:error] [pid 230252:tid 230265] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/smart-show-post-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXVAACrws"]
[Tue Jul 21 07:27:09.757186 2026] [security2:error] [pid 230252:tid 230455] [client 74.249.245.134:9408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/ini.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXVgAAAuA"]
[Tue Jul 21 07:27:09.759156 2026] [security2:error] [pid 229246:tid 229442] [client 20.151.10.161:63659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/main.php"] [unique_id "al9JfSBMYeh5YLVG45x8AQAAAlY"]
[Tue Jul 21 07:27:09.762317 2026] [security2:error] [pid 230252:tid 230424] [client 4.204.201.85:26593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9JfU0Dwhk5-Z44XrpXVwAAAsE"]
[Tue Jul 21 07:27:09.992871 2026] [security2:error] [pid 229246:tid 229304] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-subscription/class-wc-subscription-diagnostics.php"] [unique_id "al9JfSBMYeh5YLVG45x8BQACSjk"]
[Tue Jul 21 07:27:10.109172 2026] [security2:error] [pid 230252:tid 230411] [client 4.204.201.85:3209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/k2.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXXwAAArQ"]
[Tue Jul 21 07:27:10.171374 2026] [security2:error] [pid 230252:tid 230505] [client 20.52.136.55:1577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/ms-edit.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXYAAAAxI"]
[Tue Jul 21 07:27:10.202842 2026] [security2:error] [pid 230252:tid 230418] [client 20.104.96.117:62923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/admin.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXYgAAArs"]
[Tue Jul 21 07:27:10.259255 2026] [security2:error] [pid 229246:tid 229440] [client 20.220.225.223:53443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/csa.php"] [unique_id "al9JfiBMYeh5YLVG45x8CQAAAlQ"]
[Tue Jul 21 07:27:10.284655 2026] [security2:error] [pid 229246:tid 229378] [client 117.251.86.144:58858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JfiBMYeh5YLVG45x8CgAAAhY"]
[Tue Jul 21 07:27:10.285554 2026] [security2:error] [pid 229246:tid 229378] [client 117.251.86.144:58858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JfiBMYeh5YLVG45x8CgAAAhY"]
[Tue Jul 21 07:27:10.313101 2026] [security2:error] [pid 230252:tid 230328] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-notification/class-wc-subscription-diagnostics.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXZAAC_Ek"]
[Tue Jul 21 07:27:10.479094 2026] [security2:error] [pid 229246:tid 229487] [client 20.104.96.117:64025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/adminner.php"] [unique_id "al9JfiBMYeh5YLVG45x8EAAAAoM"]
[Tue Jul 21 07:27:10.481273 2026] [security2:error] [pid 230252:tid 230398] [client 45.8.17.60:27101] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/"] [unique_id "al9Jfk0Dwhk5-Z44XrpXZwAAAqc"]
[Tue Jul 21 07:27:10.622069 2026] [security2:error] [pid 229246:tid 229294] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woo-product-slider-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JfiBMYeh5YLVG45x8EQACRi8"]
[Tue Jul 21 07:27:10.724405 2026] [security2:error] [pid 230252:tid 230484] [client 4.204.201.85:26581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/uiuvs58l.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXbwAAAv0"]
[Tue Jul 21 07:27:10.840356 2026] [security2:error] [pid 230252:tid 230400] [client 20.104.96.117:5089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/admin.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXcAAAAqk"]
[Tue Jul 21 07:27:10.865575 2026] [security2:error] [pid 230252:tid 230452] [client 20.151.10.161:65481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/init.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXcQAAAt0"]
[Tue Jul 21 07:27:10.957999 2026] [security2:error] [pid 230252:tid 230308] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/testimonial-pro/src/Includes/LicenseLoader.php"] [unique_id "al9Jfk0Dwhk5-Z44XrpXcgADCDY"]
[Tue Jul 21 07:27:11.034371 2026] [security2:error] [pid 230252:tid 230503] [client 4.204.201.85:26569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/40p9ixjd.php"] [unique_id "al9Jf00Dwhk5-Z44XrpXdgAAAxA"]
[Tue Jul 21 07:27:11.082821 2026] [security2:error] [pid 230252:tid 230389] [client 20.104.96.117:59779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/csa.php"] [unique_id "al9Jf00Dwhk5-Z44XrpXdwAAAp4"]
[Tue Jul 21 07:27:11.249713 2026] [security2:error] [pid 229246:tid 229385] [client 20.220.225.223:53472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/min.php"] [unique_id "al9JfyBMYeh5YLVG45x8FwAAAh0"]
[Tue Jul 21 07:27:11.268444 2026] [security2:error] [pid 229246:tid 229257] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/smart-show-post-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JfyBMYeh5YLVG45x8GAACIgo"]
[Tue Jul 21 07:27:11.290054 2026] [security2:error] [pid 229246:tid 229465] [client 45.8.17.64:35167] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/widgets/"] [unique_id "al9JfyBMYeh5YLVG45x8GQAAAm0"]
[Tue Jul 21 07:27:11.306258 2026] [security2:error] [pid 229246:tid 229460] [client 20.104.96.117:62947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/k.php"] [unique_id "al9JfyBMYeh5YLVG45x8GgAAAmg"]
[Tue Jul 21 07:27:11.379396 2026] [security2:error] [pid 229246:tid 229382] [client 4.204.201.85:3211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/uiuvs58l.update.php"] [unique_id "al9JfyBMYeh5YLVG45x8GwAAAho"]
[Tue Jul 21 07:27:11.588183 2026] [security2:error] [pid 230252:tid 230372] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-subscription/class-wc-subscription-diagnostics.php"] [unique_id "al9Jf00Dwhk5-Z44XrpXegACm3U"]
[Tue Jul 21 07:27:11.623793 2026] [security2:error] [pid 229246:tid 229303] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JfyBMYeh5YLVG45x8IAACcjg"]
[Tue Jul 21 07:27:11.623933 2026] [security2:error] [pid 229246:tid 229470] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JfyBMYeh5YLVG45x8IAACcjg"]
[Tue Jul 21 07:27:11.625738 2026] [security2:error] [pid 230252:tid 230441] [client 20.104.96.117:5068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/blurbs.php"] [unique_id "al9Jf00Dwhk5-Z44XrpXewAAAtI"]
[Tue Jul 21 07:27:11.752546 2026] [security2:error] [pid 230252:tid 230282] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jf00Dwhk5-Z44XrpXfAAC-xw"]
[Tue Jul 21 07:27:11.752878 2026] [security2:error] [pid 230252:tid 230482] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jf00Dwhk5-Z44XrpXfAAC-xw"]
[Tue Jul 21 07:27:11.813241 2026] [security2:error] [pid 230252:tid 230458] [client 4.204.201.85:3234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/for.php"] [unique_id "al9Jf00Dwhk5-Z44XrpXfwAAAuM"]
[Tue Jul 21 07:27:11.898278 2026] [security2:error] [pid 229246:tid 229339] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-notification/class-wc-subscription-diagnostics.php"] [unique_id "al9JfyBMYeh5YLVG45x8JAACG1w"]
[Tue Jul 21 07:27:11.910677 2026] [security2:error] [pid 229246:tid 229463] [client 20.151.10.161:65452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/prekel.php"] [unique_id "al9JfyBMYeh5YLVG45x8JQAAAms"]
[Tue Jul 21 07:27:11.962262 2026] [security2:error] [pid 229246:tid 229441] [client 45.251.232.145:50139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JfyBMYeh5YLVG45x8JgAAAlU"]
[Tue Jul 21 07:27:11.962430 2026] [security2:error] [pid 229246:tid 229441] [client 45.251.232.145:50139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JfyBMYeh5YLVG45x8JgAAAlU"]
[Tue Jul 21 07:27:12.149237 2026] [security2:error] [pid 230252:tid 230450] [client 20.220.225.223:53489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/echkm.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXhgAAAts"]
[Tue Jul 21 07:27:12.161406 2026] [security2:error] [pid 229246:tid 229488] [client 4.204.201.85:26605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcaccj.org"] [uri "/raw.php"] [unique_id "al9JgCBMYeh5YLVG45x8KgAAAoQ"]
[Tue Jul 21 07:27:12.189221 2026] [security2:error] [pid 230252:tid 230478] [client 45.8.17.118:64487] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/222.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXhwAAAvc"]
[Tue Jul 21 07:27:12.217151 2026] [security2:error] [pid 230252:tid 230361] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woo-product-slider-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXiAACuWo"]
[Tue Jul 21 07:27:12.255857 2026] [security2:error] [pid 230252:tid 230413] [client 20.104.96.117:5102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/bajah.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXiQAAArY"]
[Tue Jul 21 07:27:12.527070 2026] [security2:error] [pid 229246:tid 229284] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/testimonial-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JgCBMYeh5YLVG45x8LQACJCU"]
[Tue Jul 21 07:27:12.717435 2026] [security2:error] [pid 229246:tid 229468] [client 20.10.88.201:22852] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "weightloss-review.shop"] [uri "/robots.txt"] [unique_id "al9JgCBMYeh5YLVG45x8LwAAAnA"]
[Tue Jul 21 07:27:12.766344 2026] [security2:error] [pid 230252:tid 230300] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXjwACtC4"]
[Tue Jul 21 07:27:12.766477 2026] [security2:error] [pid 230252:tid 230411] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXjwACtC4"]
[Tue Jul 21 07:27:12.807604 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:62959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/a.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXkAAAAsI"]
[Tue Jul 21 07:27:12.846187 2026] [security2:error] [pid 230252:tid 230302] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/smart-show-post-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXkQAC_DA"]
[Tue Jul 21 07:27:12.957507 2026] [security2:error] [pid 230252:tid 230480] [client 20.220.225.223:53458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/mac.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXkwAAAvk"]
[Tue Jul 21 07:27:13.028654 2026] [security2:error] [pid 229246:tid 229448] [client 20.151.10.161:63740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/0.php"] [unique_id "al9JgSBMYeh5YLVG45x8MwAAAlw"]
[Tue Jul 21 07:27:13.050029 2026] [security2:error] [pid 229246:tid 229485] [client 20.104.96.117:59828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/w3llscc.php"] [unique_id "al9JgSBMYeh5YLVG45x8NAAAAoE"]
[Tue Jul 21 07:27:13.070315 2026] [security2:error] [pid 230252:tid 230403] [client 20.52.136.55:1544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/simple.php"] [unique_id "al9JgU0Dwhk5-Z44XrpXlAAAAqw"]
[Tue Jul 21 07:27:13.082512 2026] [security2:error] [pid 229246:tid 229414] [client 45.8.17.135:65065] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/aaa.php"] [unique_id "al9JgSBMYeh5YLVG45x8NQAAAjo"]
[Tue Jul 21 07:27:13.154927 2026] [security2:error] [pid 229246:tid 229329] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-subscription/class-wc-subscription-diagnostics.php"] [unique_id "al9JgSBMYeh5YLVG45x8OAACUFI"]
[Tue Jul 21 07:27:13.313465 2026] [security2:error] [pid 230252:tid 230510] [client 20.104.96.117:64006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/edit.php"] [unique_id "al9JgU0Dwhk5-Z44XrpXmQAAAxc"]
[Tue Jul 21 07:27:13.339761 2026] [security2:error] [pid 230252:tid 230479] [client 103.106.20.201:50266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JgU0Dwhk5-Z44XrpXmgAAAvg"]
[Tue Jul 21 07:27:13.339902 2026] [security2:error] [pid 230252:tid 230479] [client 103.106.20.201:50266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JgU0Dwhk5-Z44XrpXmgAAAvg"]
[Tue Jul 21 07:27:13.474061 2026] [security2:error] [pid 229246:tid 229295] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woocommerce-notification/class-wc-subscription-diagnostics.php"] [unique_id "al9JgSBMYeh5YLVG45x8OwACVjA"]
[Tue Jul 21 07:27:13.523508 2026] [security2:error] [pid 229246:tid 229363] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JgSBMYeh5YLVG45x8PAACd3Q"]
[Tue Jul 21 07:27:13.523686 2026] [security2:error] [pid 229246:tid 229475] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JgSBMYeh5YLVG45x8PAACd3Q"]
[Tue Jul 21 07:27:13.713283 2026] [security2:error] [pid 230252:tid 230387] [client 20.220.225.223:45973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/else1.php"] [unique_id "al9JgU0Dwhk5-Z44XrpXogAAApw"]
[Tue Jul 21 07:27:13.778354 2026] [security2:error] [pid 230252:tid 230460] [client 20.104.96.117:62950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/hosty.php"] [unique_id "al9JgU0Dwhk5-Z44XrpXowAAAuU"]
[Tue Jul 21 07:27:13.794229 2026] [security2:error] [pid 229246:tid 229361] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/woo-product-slider-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JgSBMYeh5YLVG45x8SAACfnI"]
[Tue Jul 21 07:27:13.962531 2026] [security2:error] [pid 229246:tid 229462] [client 20.104.96.117:59609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wpx.php"] [unique_id "al9JgSBMYeh5YLVG45x8SgAAAmo"]
[Tue Jul 21 07:27:14.114804 2026] [security2:error] [pid 229246:tid 229313] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/testimonial-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JgiBMYeh5YLVG45x8TAACIEI"]
[Tue Jul 21 07:27:14.182520 2026] [security2:error] [pid 230252:tid 230441] [client 20.104.96.117:64000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/k.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXrgAAAtI"]
[Tue Jul 21 07:27:14.277295 2026] [security2:error] [pid 229246:tid 229385] [client 20.220.225.223:60361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/samll.php"] [unique_id "al9JgiBMYeh5YLVG45x8UAAAAh0"]
[Tue Jul 21 07:27:14.283933 2026] [security2:error] [pid 230252:tid 230461] [client 45.8.17.108:42693] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXsAAAAuY"]
[Tue Jul 21 07:27:14.296547 2026] [security2:error] [pid 230252:tid 230444] [client 20.151.10.161:65505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/BDKR28.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXsQAAAtU"]
[Tue Jul 21 07:27:14.434582 2026] [security2:error] [pid 229246:tid 229362] [remote 213.35.102.249:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.academiausina.com.br"] [uri "/wp-content/plugins/smart-show-post-pro/src/Includes/LicenseLoader.php"] [unique_id "al9JgiBMYeh5YLVG45x8UgACGnM"]
[Tue Jul 21 07:27:14.543145 2026] [security2:error] [pid 230252:tid 230385] [client 103.174.34.15:62635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXtAAAApo"]
[Tue Jul 21 07:27:14.543280 2026] [security2:error] [pid 230252:tid 230385] [client 103.174.34.15:62635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXtAAAApo"]
[Tue Jul 21 07:27:14.631557 2026] [security2:error] [pid 230252:tid 230494] [client 136.144.33.111:44713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JgE0Dwhk5-Z44XrpXigAAAwc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:14.713997 2026] [security2:error] [pid 230252:tid 230413] [client 20.104.96.117:59807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-css.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXuAAAArY"]
[Tue Jul 21 07:27:14.890572 2026] [security2:error] [pid 230252:tid 230447] [client 62.102.148.164:39630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXvgAAAtg"]
[Tue Jul 21 07:27:14.890686 2026] [security2:error] [pid 230252:tid 230447] [client 62.102.148.164:39630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXvgAAAtg"]
[Tue Jul 21 07:27:14.899404 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/aaa.php"] [unique_id "al9Jgk0Dwhk5-Z44XrpXvwAAAsI"]
[Tue Jul 21 07:27:15.144699 2026] [security2:error] [pid 230252:tid 230391] [client 74.249.245.134:17424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/themes.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXwQAAAqA"]
[Tue Jul 21 07:27:15.251897 2026] [security2:error] [pid 230252:tid 230501] [client 175.45.70.82:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXwwAAAw4"]
[Tue Jul 21 07:27:15.252008 2026] [security2:error] [pid 230252:tid 230501] [client 175.45.70.82:53622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXwwAAAw4"]
[Tue Jul 21 07:27:15.373953 2026] [security2:error] [pid 230252:tid 230490] [client 20.151.10.161:65427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/f35.update.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXygAAAwM"]
[Tue Jul 21 07:27:15.389625 2026] [security2:error] [pid 230252:tid 230502] [client 45.8.17.140:56115] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/inputs.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXywAAAw8"]
[Tue Jul 21 07:27:15.418974 2026] [security2:error] [pid 230252:tid 230430] [client 20.104.96.117:62962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/file5.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXzAAAAsc"]
[Tue Jul 21 07:27:15.614559 2026] [security2:error] [pid 230252:tid 230446] [client 59.96.220.140:63935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXzwAAAtc"]
[Tue Jul 21 07:27:15.615216 2026] [security2:error] [pid 230252:tid 230446] [client 59.96.220.140:63935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Jg00Dwhk5-Z44XrpXzwAAAtc"]
[Tue Jul 21 07:27:15.908510 2026] [security2:error] [pid 229246:tid 229476] [client 20.104.96.117:59837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ho.php"] [unique_id "al9JgyBMYeh5YLVG45x8YgAAAng"]
[Tue Jul 21 07:27:16.069426 2026] [security2:error] [pid 229246:tid 229464] [client 20.104.96.117:62918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/222.php"] [unique_id "al9JhCBMYeh5YLVG45x8ZAAAAmw"]
[Tue Jul 21 07:27:16.165569 2026] [security2:error] [pid 230252:tid 230286] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JhE0Dwhk5-Z44XrpX0gACuiA"]
[Tue Jul 21 07:27:16.165799 2026] [security2:error] [pid 230252:tid 230417] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JhE0Dwhk5-Z44XrpX0gACuiA"]
[Tue Jul 21 07:27:16.255356 2026] [security2:error] [pid 229246:tid 229399] [client 20.220.225.223:53475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/abcd.php"] [unique_id "al9JhCBMYeh5YLVG45x8aAAAAis"]
[Tue Jul 21 07:27:16.289119 2026] [security2:error] [pid 229246:tid 229414] [client 45.8.17.113:34967] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/about.php"] [unique_id "al9JhCBMYeh5YLVG45x8aQAAAjo"]
[Tue Jul 21 07:27:16.400686 2026] [security2:error] [pid 229246:tid 229413] [client 20.151.10.161:63646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/f900.php"] [unique_id "al9JhCBMYeh5YLVG45x8bgAAAjk"]
[Tue Jul 21 07:27:16.485282 2026] [security2:error] [pid 229246:tid 229483] [client 20.104.96.117:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/test.php"] [unique_id "al9JhCBMYeh5YLVG45x8bwAAAn8"]
[Tue Jul 21 07:27:16.874168 2026] [security2:error] [pid 230252:tid 230497] [client 216.73.160.36:45077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9Jg00Dwhk5-Z44XrpX0AAAAwo"]
[Tue Jul 21 07:27:17.116487 2026] [security2:error] [pid 230252:tid 230323] [remote 20.89.83.228:32500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.83.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thiagomartins.com"] [uri "/wp-login.php"] [unique_id "al9JhU0Dwhk5-Z44XrpX1wADFkU"]
[Tue Jul 21 07:27:17.139094 2026] [autoindex:error] [pid 230252:tid 230485] [client 74.7.242.47:0] AH01276: Cannot serve directory /home1/asse7722/flowwshop.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:17.161306 2026] [security2:error] [pid 229246:tid 229343] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JhSBMYeh5YLVG45x8eQACFWA"]
[Tue Jul 21 07:27:17.161449 2026] [security2:error] [pid 229246:tid 229377] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JhSBMYeh5YLVG45x8eQACFWA"]
[Tue Jul 21 07:27:17.183621 2026] [security2:error] [pid 230252:tid 230478] [client 45.8.17.118:50659] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/speculative8.php"] [unique_id "al9JhU0Dwhk5-Z44XrpX3AAAAvc"]
[Tue Jul 21 07:27:17.185759 2026] [security2:error] [pid 230252:tid 230413] [client 20.104.96.117:5106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/aaa.php"] [unique_id "al9JhU0Dwhk5-Z44XrpX3QAAArY"]
[Tue Jul 21 07:27:17.199249 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:65410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/xmrl.php"] [unique_id "al9JhU0Dwhk5-Z44XrpX3gAAAwY"]
[Tue Jul 21 07:27:17.232514 2026] [security2:error] [pid 229246:tid 229492] [client 74.7.244.61:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "flowwshop.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9JhSBMYeh5YLVG45x8ewAAAog"]
[Tue Jul 21 07:27:17.233578 2026] [security2:error] [pid 229246:tid 229440] [client 74.7.244.61:35718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "flowwshop.com.br"] [uri "/robots.txt"] [unique_id "al9JhSBMYeh5YLVG45x8egACVGo"]
[Tue Jul 21 07:27:17.307874 2026] [security2:error] [pid 229246:tid 229467] [client 20.52.136.55:1731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/404.php"] [unique_id "al9JhSBMYeh5YLVG45x8fQAAAm8"]
[Tue Jul 21 07:27:17.530211 2026] [security2:error] [pid 229246:tid 229501] [client 20.104.96.117:59589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/xy.php"] [unique_id "al9JhSBMYeh5YLVG45x8ggAAApE"]
[Tue Jul 21 07:27:17.725632 2026] [security2:error] [pid 230252:tid 230444] [client 103.162.129.114:62187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JhU0Dwhk5-Z44XrpX4wAAAtU"]
[Tue Jul 21 07:27:17.725760 2026] [security2:error] [pid 230252:tid 230444] [client 103.162.129.114:62187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JhU0Dwhk5-Z44XrpX4wAAAtU"]
[Tue Jul 21 07:27:17.793852 2026] [security2:error] [pid 230252:tid 230447] [client 20.104.96.117:62926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/11.php"] [unique_id "al9JhU0Dwhk5-Z44XrpX5AAAAtg"]
[Tue Jul 21 07:27:18.110538 2026] [security2:error] [pid 230252:tid 230490] [client 20.151.10.161:63702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/memberfuns.php"] [unique_id "al9Jhk0Dwhk5-Z44XrpX6wAAAwM"]
[Tue Jul 21 07:27:18.165927 2026] [security2:error] [pid 230252:tid 230438] [client 20.220.225.223:53499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/xyn.php"] [unique_id "al9Jhk0Dwhk5-Z44XrpX7AAAAs8"]
[Tue Jul 21 07:27:18.188061 2026] [security2:error] [pid 230252:tid 230465] [client 45.8.17.127:65123] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/radio.php"] [unique_id "al9Jhk0Dwhk5-Z44XrpX7QAAAuo"]
[Tue Jul 21 07:27:18.306546 2026] [security2:error] [pid 230252:tid 230494] [client 152.59.154.239:50461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jhk0Dwhk5-Z44XrpX7gAAAwc"]
[Tue Jul 21 07:27:18.367158 2026] [security2:error] [pid 229246:tid 229443] [client 20.104.96.117:5085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/mac.php"] [unique_id "al9JhiBMYeh5YLVG45x8iAAAAlc"]
[Tue Jul 21 07:27:18.595912 2026] [security2:error] [pid 229246:tid 229426] [client 20.104.96.117:59615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/loader.php"] [unique_id "al9JhiBMYeh5YLVG45x8iwAAAkY"]
[Tue Jul 21 07:27:18.662363 2026] [security2:error] [pid 230252:tid 230419] [client 154.192.233.199:59752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jhk0Dwhk5-Z44XrpX9QAAArw"]
[Tue Jul 21 07:27:18.662486 2026] [security2:error] [pid 230252:tid 230419] [client 154.192.233.199:59752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jhk0Dwhk5-Z44XrpX9QAAArw"]
[Tue Jul 21 07:27:18.677948 2026] [security2:error] [pid 229246:tid 229460] [client 20.151.10.161:65471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/ms.php"] [unique_id "al9JhiBMYeh5YLVG45x8jAAAAmg"]
[Tue Jul 21 07:27:18.887759 2026] [security2:error] [pid 229246:tid 229308] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JhiBMYeh5YLVG45x8jwACGj0"]
[Tue Jul 21 07:27:18.887919 2026] [security2:error] [pid 229246:tid 229382] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JhiBMYeh5YLVG45x8jwACGj0"]
[Tue Jul 21 07:27:18.946430 2026] [security2:error] [pid 230252:tid 230467] [client 74.7.244.24:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "warleysonlacerdalope1782242261893.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9Jhk0Dwhk5-Z44XrpX-QAC7Gg"]
[Tue Jul 21 07:27:19.125410 2026] [security2:error] [pid 230252:tid 230466] [client 20.104.96.117:64050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/chosen.php"] [unique_id "al9Jh00Dwhk5-Z44XrpX-gAAAus"]
[Tue Jul 21 07:27:19.153231 2026] [security2:error] [pid 229246:tid 229383] [client 20.220.225.223:31180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/byp8.php"] [unique_id "al9JhyBMYeh5YLVG45x8kgAAAhs"]
[Tue Jul 21 07:27:19.382630 2026] [security2:error] [pid 230252:tid 230433] [client 45.8.17.58:60519] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/"] [unique_id "al9Jh00Dwhk5-Z44XrpYAAAAAso"]
[Tue Jul 21 07:27:19.456422 2026] [security2:error] [pid 230252:tid 230482] [client 20.151.10.161:63733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/zz.php"] [unique_id "al9Jh00Dwhk5-Z44XrpYAQAAAvs"]
[Tue Jul 21 07:27:19.789270 2026] [security2:error] [pid 229246:tid 229263] [remote 195.26.253.119:58154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-login.php"] [unique_id "al9JhyBMYeh5YLVG45x8mQACeBA"]
[Tue Jul 21 07:27:19.819615 2026] [security2:error] [pid 230252:tid 230453] [client 20.104.96.117:5095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/cream1.php"] [unique_id "al9Jh00Dwhk5-Z44XrpYAwAAAt4"]
[Tue Jul 21 07:27:19.839903 2026] [security2:error] [pid 229246:tid 229472] [client 139.135.44.145:53880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JhyBMYeh5YLVG45x8mgAAAnQ"]
[Tue Jul 21 07:27:19.839996 2026] [security2:error] [pid 229246:tid 229472] [client 139.135.44.145:53880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JhyBMYeh5YLVG45x8mgAAAnQ"]
[Tue Jul 21 07:27:19.884766 2026] [security2:error] [pid 230252:tid 230491] [client 193.36.225.64:37943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Jh00Dwhk5-Z44XrpYBAAAAwQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:19.892804 2026] [security2:error] [pid 229246:tid 229485] [client 20.104.96.117:59598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/spadex.php"] [unique_id "al9JhyBMYeh5YLVG45x8nAAAAoE"]
[Tue Jul 21 07:27:19.908635 2026] [security2:error] [pid 230252:tid 230472] [client 20.220.225.223:55757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/byp8.php"] [unique_id "al9Jh00Dwhk5-Z44XrpYBQAAAvE"]
[Tue Jul 21 07:27:20.024713 2026] [security2:error] [pid 229246:tid 229398] [client 20.220.225.223:31188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/user.php"] [unique_id "al9JiCBMYeh5YLVG45x8ngAAAio"]
[Tue Jul 21 07:27:20.084419 2026] [security2:error] [pid 230252:tid 230409] [client 20.151.10.161:65499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/for.php"] [unique_id "al9JiE0Dwhk5-Z44XrpYCgAAArI"]
[Tue Jul 21 07:27:20.243433 2026] [security2:error] [pid 230252:tid 230384] [client 20.220.225.223:45414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/tkikikoko.php"] [unique_id "al9JiE0Dwhk5-Z44XrpYDQAAApk"]
[Tue Jul 21 07:27:20.344427 2026] [autoindex:error] [pid 230252:tid 230506] [client 20.104.96.117:62948] AH01276: Cannot serve directory /home4/forev309/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:20.482723 2026] [security2:error] [pid 230252:tid 230444] [client 45.8.17.122:63981] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/updates.php"] [unique_id "al9JiE0Dwhk5-Z44XrpYEAAAAtU"]
[Tue Jul 21 07:27:20.684180 2026] [autoindex:error] [pid 230252:tid 230395] [client 20.104.96.117:62948] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:20.764535 2026] [security2:error] [pid 230252:tid 230416] [client 20.151.10.161:63664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/yup.php"] [unique_id "al9JiE0Dwhk5-Z44XrpYEwAAArk"]
[Tue Jul 21 07:27:20.829895 2026] [autoindex:error] [pid 230252:tid 230267] [remote 74.7.227.176:53416] AH01276: Cannot serve directory /home4/muril041/murilogermanopessagn1777322868000.0721679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:20.885679 2026] [security2:error] [pid 230252:tid 230415] [client 20.104.96.117:62948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/dr.php"] [unique_id "al9JiE0Dwhk5-Z44XrpYFQAAArg"]
[Tue Jul 21 07:27:20.907993 2026] [security2:error] [pid 229246:tid 229418] [client 20.220.225.223:55779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/user.php"] [unique_id "al9JiCBMYeh5YLVG45x8qAAAAj4"]
[Tue Jul 21 07:27:20.978766 2026] [security2:error] [pid 230252:tid 230344] [remote 103.28.36.106:41694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/wp-login.php"] [unique_id "al9JiE0Dwhk5-Z44XrpYFgACyFk"]
[Tue Jul 21 07:27:21.034064 2026] [security2:error] [pid 230252:tid 230391] [client 74.7.230.39:42188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.murilogermanopessagn1777322868000.vaporclube.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9JiU0Dwhk5-Z44XrpYFwACoDQ"]
[Tue Jul 21 07:27:21.089500 2026] [security2:error] [pid 230252:tid 230410] [client 113.31.186.196:15794] ModSecurity: Warning. Matched phrase "Custo" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "drajoanasiqueira.com"] [uri "/"] [unique_id "al9Jek0Dwhk5-Z44XrpXHQAAArM"]
[Tue Jul 21 07:27:21.197794 2026] [security2:error] [pid 230252:tid 230418] [client 117.251.86.144:46580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JiU0Dwhk5-Z44XrpYGgAAArs"]
[Tue Jul 21 07:27:21.197930 2026] [security2:error] [pid 230252:tid 230418] [client 117.251.86.144:46580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JiU0Dwhk5-Z44XrpYGgAAArs"]
[Tue Jul 21 07:27:21.502200 2026] [security2:error] [pid 229246:tid 229378] [client 82.102.28.107:46110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9JiSBMYeh5YLVG45x8sAAAAhY"]
[Tue Jul 21 07:27:21.502288 2026] [security2:error] [pid 229246:tid 229378] [client 82.102.28.107:46110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9JiSBMYeh5YLVG45x8sAAAAhY"]
[Tue Jul 21 07:27:21.513201 2026] [security2:error] [pid 230252:tid 230430] [client 45.8.17.49:63653] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/blue/"] [unique_id "al9JiU0Dwhk5-Z44XrpYHgAAAsc"]
[Tue Jul 21 07:27:21.525162 2026] [fcgid:warn] [pid 230252:tid 230508] (70014)End of file found: [client 66.132.224.231:8430] mod_fcgid: can't get data from http client
[Tue Jul 21 07:27:21.569332 2026] [security2:error] [pid 229246:tid 229466] [client 20.104.96.117:4214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/x.php"] [unique_id "al9JiSBMYeh5YLVG45x8sQAAAm4"]
[Tue Jul 21 07:27:21.587307 2026] [security2:error] [pid 230252:tid 230396] [client 20.151.10.161:63078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/wpxml.php"] [unique_id "al9JiU0Dwhk5-Z44XrpYIgAAAqU"]
[Tue Jul 21 07:27:21.651635 2026] [security2:error] [pid 229246:tid 229437] [client 20.104.96.117:59829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/2x.php"] [unique_id "al9JiSBMYeh5YLVG45x8swAAAlE"]
[Tue Jul 21 07:27:21.664273 2026] [security2:error] [pid 230252:tid 230488] [client 74.249.245.134:62902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/dropdown.php"] [unique_id "al9JiU0Dwhk5-Z44XrpYJAAAAwE"]
[Tue Jul 21 07:27:22.216141 2026] [security2:error] [pid 230252:tid 230467] [client 20.104.96.117:64004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/155.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYKwAAAuw"]
[Tue Jul 21 07:27:22.232457 2026] [security2:error] [pid 230252:tid 230486] [client 20.220.225.223:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-Blogs.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYLAAAAv8"]
[Tue Jul 21 07:27:22.265277 2026] [security2:error] [pid 230252:tid 230346] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYLQACvFs"]
[Tue Jul 21 07:27:22.265425 2026] [security2:error] [pid 230252:tid 230419] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYLQACvFs"]
[Tue Jul 21 07:27:22.288613 2026] [security2:error] [pid 230252:tid 230468] [client 20.52.136.55:1506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/file3.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYLwAAAu0"]
[Tue Jul 21 07:27:22.361023 2026] [security2:error] [pid 230252:tid 230466] [client 20.151.10.161:63052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/fffm.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYMAAAAus"]
[Tue Jul 21 07:27:22.389832 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:59782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ctex1.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYMgAAAtM"]
[Tue Jul 21 07:27:22.396200 2026] [security2:error] [pid 230252:tid 230379] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al9Jik0Dwhk5-Z44XrpYMwAC0nw"], referer: http://bio.deiacakes.com/wp-content/plugins/elementor/readme.txt
[Tue Jul 21 07:27:22.436832 2026] [security2:error] [pid 230252:tid 230404] [client 45.251.232.145:50655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYNQAAAq0"]
[Tue Jul 21 07:27:22.436950 2026] [security2:error] [pid 230252:tid 230404] [client 45.251.232.145:50655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYNQAAAq0"]
[Tue Jul 21 07:27:22.489280 2026] [security2:error] [pid 229246:tid 229428] [client 45.8.17.142:44681] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/theme-compat/"] [unique_id "al9JiiBMYeh5YLVG45x8uAAAAkg"]
[Tue Jul 21 07:27:22.583383 2026] [security2:error] [pid 230252:tid 230339] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYNgAC8lQ"]
[Tue Jul 21 07:27:22.583561 2026] [security2:error] [pid 230252:tid 230473] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYNgAC8lQ"]
[Tue Jul 21 07:27:22.587059 2026] [security2:error] [pid 229246:tid 229408] [client 20.220.225.223:60372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/ops.php"] [unique_id "al9JiiBMYeh5YLVG45x8vAAAAjQ"]
[Tue Jul 21 07:27:22.645580 2026] [security2:error] [pid 229246:tid 229474] [client 173.252.95.16:38856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JiiBMYeh5YLVG45x8vgAAAnY"]
[Tue Jul 21 07:27:22.891900 2026] [security2:error] [pid 230252:tid 230500] [client 20.104.96.117:4204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ops.php"] [unique_id "al9Jik0Dwhk5-Z44XrpYOQAAAw0"]
[Tue Jul 21 07:27:22.914251 2026] [security2:error] [pid 229246:tid 229382] [client 20.151.10.161:63655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/gecko.php"] [unique_id "al9JiiBMYeh5YLVG45x8wgAAAho"]
[Tue Jul 21 07:27:22.957185 2026] [security2:error] [pid 229246:tid 229380] [client 82.102.28.107:57344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JiiBMYeh5YLVG45x8wwAAAhg"]
[Tue Jul 21 07:27:22.957289 2026] [security2:error] [pid 229246:tid 229380] [client 82.102.28.107:57344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JiiBMYeh5YLVG45x8wwAAAhg"]
[Tue Jul 21 07:27:23.229956 2026] [security2:error] [pid 230252:tid 230498] [client 20.104.96.117:64048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/file31.php"] [unique_id "al9Ji00Dwhk5-Z44XrpYPgAAAws"]
[Tue Jul 21 07:27:23.339970 2026] [security2:error] [pid 230252:tid 230463] [client 173.252.95.39:47934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Ji00Dwhk5-Z44XrpYOwAAAug"]
[Tue Jul 21 07:27:23.396909 2026] [security2:error] [pid 230252:tid 230384] [client 20.220.225.223:38716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/ops.php"] [unique_id "al9Ji00Dwhk5-Z44XrpYQgAAApk"]
[Tue Jul 21 07:27:23.486333 2026] [security2:error] [pid 229246:tid 229464] [client 20.104.96.117:59780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/edorxrr.php"] [unique_id "al9JiyBMYeh5YLVG45x8zwAAAmw"]
[Tue Jul 21 07:27:23.559992 2026] [security2:error] [pid 229246:tid 229322] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JiyBMYeh5YLVG45x80QACX0s"]
[Tue Jul 21 07:27:23.560121 2026] [security2:error] [pid 229246:tid 229451] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JiyBMYeh5YLVG45x80QACX0s"]
[Tue Jul 21 07:27:23.573926 2026] [security2:error] [pid 229246:tid 229484] [client 20.104.96.117:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/file6.php"] [unique_id "al9JiyBMYeh5YLVG45x80gAAAoA"]
[Tue Jul 21 07:27:23.582558 2026] [security2:error] [pid 229246:tid 229403] [client 45.8.17.73:65035] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/"] [unique_id "al9JiyBMYeh5YLVG45x80wAAAi8"]
[Tue Jul 21 07:27:23.634447 2026] [proxy:error] [pid 229246:tid 229441] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:23.634481 2026] [proxy_http:error] [pid 229246:tid 229441] [client 147.185.132.31:60036] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:23.635062 2026] [proxy:error] [pid 229246:tid 229441] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:23.635093 2026] [proxy_http:error] [pid 229246:tid 229441] [client 147.185.132.31:60036] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:23.879991 2026] [security2:error] [pid 229246:tid 229247] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-user-avatar/readme.txt"] [unique_id "al9JiyBMYeh5YLVG45x84AACigA"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-user-avatar/readme.txt
[Tue Jul 21 07:27:23.993520 2026] [autoindex:error] [pid 229246:tid 229419] [client 20.104.96.117:62965] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:24.071145 2026] [security2:error] [pid 229246:tid 229374] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JjCBMYeh5YLVG45x85AACd38"]
[Tue Jul 21 07:27:24.071303 2026] [security2:error] [pid 229246:tid 229475] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JjCBMYeh5YLVG45x85AACd38"]
[Tue Jul 21 07:27:24.102279 2026] [security2:error] [pid 229246:tid 229431] [client 103.106.20.201:50836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JjCBMYeh5YLVG45x85gAAAks"]
[Tue Jul 21 07:27:24.102385 2026] [security2:error] [pid 229246:tid 229431] [client 103.106.20.201:50836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JjCBMYeh5YLVG45x85gAAAks"]
[Tue Jul 21 07:27:24.104828 2026] [security2:error] [pid 229246:tid 229258] [remote 65.111.9.171:63947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.9.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JjCBMYeh5YLVG45x85QACMQs"]
[Tue Jul 21 07:27:24.235469 2026] [security2:error] [pid 230252:tid 230451] [client 20.104.96.117:59613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/miru1.php"] [unique_id "al9JjE0Dwhk5-Z44XrpYSQAAAtw"]
[Tue Jul 21 07:27:24.269556 2026] [security2:error] [pid 229246:tid 229482] [client 20.104.96.117:62965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/adminfuns.php"] [unique_id "al9JjCBMYeh5YLVG45x86gAAAn4"]
[Tue Jul 21 07:27:24.305119 2026] [security2:error] [pid 229246:tid 229486] [client 193.36.225.64:35179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JjCBMYeh5YLVG45x86wAAAoI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:24.412306 2026] [core:alert] [pid 230252:tid 230429] [client 66.249.66.74:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:27:24.589069 2026] [security2:error] [pid 229246:tid 229487] [client 45.8.17.140:32835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/plugins/"] [unique_id "al9JjCBMYeh5YLVG45x87AAAAoM"]
[Tue Jul 21 07:27:24.625924 2026] [security2:error] [pid 230252:tid 230488] [client 213.152.162.104:36854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JjE0Dwhk5-Z44XrpYTwAAAwE"]
[Tue Jul 21 07:27:24.626024 2026] [security2:error] [pid 230252:tid 230488] [client 213.152.162.104:36854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9JjE0Dwhk5-Z44XrpYTwAAAwE"]
[Tue Jul 21 07:27:24.629713 2026] [security2:error] [pid 229246:tid 229444] [client 20.151.10.161:63649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/a1.php"] [unique_id "al9JjCBMYeh5YLVG45x87QAAAlg"]
[Tue Jul 21 07:27:24.727622 2026] [security2:error] [pid 230252:tid 230414] [client 173.252.95.114:54308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JjE0Dwhk5-Z44XrpYUAAAArc"]
[Tue Jul 21 07:27:24.826261 2026] [security2:error] [pid 229246:tid 229427] [client 20.220.225.223:46122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-css.php"] [unique_id "al9JjCBMYeh5YLVG45x88gAAAkc"]
[Tue Jul 21 07:27:24.865069 2026] [security2:error] [pid 229246:tid 229387] [client 20.104.96.117:62958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/goods.php"] [unique_id "al9JjCBMYeh5YLVG45x88wAAAh8"]
[Tue Jul 21 07:27:25.002765 2026] [security2:error] [pid 230252:tid 230382] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/bbpress/readme.txt"] [unique_id "al9JjU0Dwhk5-Z44XrpYUgAC-X8"], referer: http://bio.deiacakes.com/wp-content/plugins/bbpress/readme.txt
[Tue Jul 21 07:27:25.161183 2026] [security2:error] [pid 229246:tid 229477] [client 20.104.96.117:59827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/sump1.php"] [unique_id "al9JjSBMYeh5YLVG45x89wAAAnk"]
[Tue Jul 21 07:27:25.304614 2026] [security2:error] [pid 230252:tid 230494] [client 103.174.34.15:63145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JjU0Dwhk5-Z44XrpYVAAAAwc"]
[Tue Jul 21 07:27:25.304942 2026] [security2:error] [pid 230252:tid 230494] [client 103.174.34.15:63145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JjU0Dwhk5-Z44XrpYVAAAAwc"]
[Tue Jul 21 07:27:25.389601 2026] [security2:error] [pid 229246:tid 229407] [client 59.96.220.140:64387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JjSBMYeh5YLVG45x8_QAAAjM"]
[Tue Jul 21 07:27:25.389718 2026] [security2:error] [pid 229246:tid 229407] [client 59.96.220.140:64387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JjSBMYeh5YLVG45x8_QAAAjM"]
[Tue Jul 21 07:27:25.559835 2026] [security2:error] [pid 229246:tid 229473] [client 20.104.96.117:4257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/100.php"] [unique_id "al9JjSBMYeh5YLVG45x9AgAAAnU"]
[Tue Jul 21 07:27:25.587975 2026] [security2:error] [pid 230252:tid 230387] [client 45.8.17.139:27215] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/ioxi-o.php"] [unique_id "al9JjU0Dwhk5-Z44XrpYVwAAApw"]
[Tue Jul 21 07:27:25.739341 2026] [security2:error] [pid 230252:tid 230503] [client 20.220.225.223:60369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/term.php"] [unique_id "al9JjU0Dwhk5-Z44XrpYWgAAAxA"]
[Tue Jul 21 07:27:25.913758 2026] [security2:error] [pid 230252:tid 230299] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/iwp-client/readme.txt"] [unique_id "al9JjU0Dwhk5-Z44XrpYYAADES0"], referer: http://bio.deiacakes.com/wp-content/plugins/iwp-client/readme.txt
[Tue Jul 21 07:27:25.923053 2026] [security2:error] [pid 229246:tid 229421] [client 175.45.70.82:54134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JjSBMYeh5YLVG45x9BwAAAkE"]
[Tue Jul 21 07:27:25.923207 2026] [security2:error] [pid 229246:tid 229421] [client 175.45.70.82:54134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JjSBMYeh5YLVG45x9BwAAAkE"]
[Tue Jul 21 07:27:25.933507 2026] [security2:error] [pid 230252:tid 230264] [remote 151.123.177.119:59659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JjU0Dwhk5-Z44XrpYWwACqQo"]
[Tue Jul 21 07:27:26.128622 2026] [security2:error] [pid 230252:tid 230448] [client 20.104.96.117:59812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/file5.php"] [unique_id "al9Jjk0Dwhk5-Z44XrpYYQAAAtk"]
[Tue Jul 21 07:27:26.148568 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:62952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/about.php"] [unique_id "al9JjiBMYeh5YLVG45x9CAAAAi8"]
[Tue Jul 21 07:27:26.232638 2026] [security2:error] [pid 230252:tid 230467] [client 154.192.233.199:60124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jjk0Dwhk5-Z44XrpYYwAAAuw"]
[Tue Jul 21 07:27:26.232746 2026] [security2:error] [pid 230252:tid 230467] [client 154.192.233.199:60124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jjk0Dwhk5-Z44XrpYYwAAAuw"]
[Tue Jul 21 07:27:26.385829 2026] [security2:error] [pid 230252:tid 230450] [client 45.8.17.130:25467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/IXR/"] [unique_id "al9Jjk0Dwhk5-Z44XrpYZQAAAts"]
[Tue Jul 21 07:27:26.642094 2026] [security2:error] [pid 230252:tid 230320] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-central/readme.txt"] [unique_id "al9Jjk0Dwhk5-Z44XrpYaQAC9EI"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-central/readme.txt
[Tue Jul 21 07:27:26.740526 2026] [security2:error] [pid 230252:tid 230505] [client 20.104.96.117:5079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/about.php"] [unique_id "al9Jjk0Dwhk5-Z44XrpYawAAAxI"]
[Tue Jul 21 07:27:26.770125 2026] [security2:error] [pid 229246:tid 229283] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JjiBMYeh5YLVG45x9EwACPiQ"]
[Tue Jul 21 07:27:26.770254 2026] [security2:error] [pid 229246:tid 229418] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JjiBMYeh5YLVG45x9EwACPiQ"]
[Tue Jul 21 07:27:26.772547 2026] [security2:error] [pid 230252:tid 230444] [client 20.151.10.161:65513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/k2.php"] [unique_id "al9Jjk0Dwhk5-Z44XrpYbAAAAtU"]
[Tue Jul 21 07:27:26.842215 2026] [security2:error] [pid 229246:tid 229309] [remote 45.3.47.223:52717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.47.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JjiBMYeh5YLVG45x9DwACOT4"]
[Tue Jul 21 07:27:27.050722 2026] [security2:error] [pid 230252:tid 230462] [client 82.102.28.107:46122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Jj00Dwhk5-Z44XrpYcgAAAuc"]
[Tue Jul 21 07:27:27.050796 2026] [security2:error] [pid 230252:tid 230462] [client 82.102.28.107:46122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Jj00Dwhk5-Z44XrpYcgAAAuc"]
[Tue Jul 21 07:27:27.379661 2026] [security2:error] [pid 230252:tid 230430] [client 20.104.96.117:64020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/admin.php"] [unique_id "al9Jj00Dwhk5-Z44XrpYdgAAAsc"]
[Tue Jul 21 07:27:27.488281 2026] [security2:error] [pid 229246:tid 229489] [client 20.220.225.223:60353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/ah25.php"] [unique_id "al9JjyBMYeh5YLVG45x9GwAAAoU"]
[Tue Jul 21 07:27:27.658250 2026] [security2:error] [pid 230252:tid 230313] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jj00Dwhk5-Z44XrpYeQAC6Ts"]
[Tue Jul 21 07:27:27.658362 2026] [security2:error] [pid 230252:tid 230464] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jj00Dwhk5-Z44XrpYeQAC6Ts"]
[Tue Jul 21 07:27:27.682618 2026] [security2:error] [pid 230252:tid 230480] [client 45.8.17.65:55421] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/404.php"] [unique_id "al9Jj00Dwhk5-Z44XrpYegAAAvk"]
[Tue Jul 21 07:27:27.797021 2026] [security2:error] [pid 230252:tid 230340] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-time-capsule/readme.txt"] [unique_id "al9Jj00Dwhk5-Z44XrpYewAC8FU"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-time-capsule/readme.txt
[Tue Jul 21 07:27:27.853401 2026] [security2:error] [pid 230252:tid 230401] [client 20.104.96.117:64012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/admin.php"] [unique_id "al9Jj00Dwhk5-Z44XrpYfwAAAqo"]
[Tue Jul 21 07:27:28.100727 2026] [security2:error] [pid 230252:tid 230466] [client 20.151.10.161:63637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/82.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYggAAAus"]
[Tue Jul 21 07:27:28.177320 2026] [security2:error] [pid 230252:tid 230503] [client 20.220.225.223:38669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/term.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYgwAAAxA"]
[Tue Jul 21 07:27:28.220743 2026] [security2:error] [pid 230252:tid 230414] [client 103.162.129.114:62623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYhAAAArc"]
[Tue Jul 21 07:27:28.220875 2026] [security2:error] [pid 230252:tid 230414] [client 103.162.129.114:62623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYhAAAArc"]
[Tue Jul 21 07:27:28.413048 2026] [security2:error] [pid 230252:tid 230510] [client 20.104.96.117:62969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/themes.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYiQAAAxc"]
[Tue Jul 21 07:27:28.493327 2026] [security2:error] [pid 229246:tid 229494] [client 193.36.225.62:35811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JkCBMYeh5YLVG45x9IAAAAoo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:28.621516 2026] [security2:error] [pid 229246:tid 229402] [client 20.104.96.117:59821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/0xD.php"] [unique_id "al9JkCBMYeh5YLVG45x9KAAAAi4"]
[Tue Jul 21 07:27:28.626906 2026] [security2:error] [pid 230252:tid 230467] [client 20.151.10.161:49103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/p.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYjAAAAuw"]
[Tue Jul 21 07:27:28.882283 2026] [security2:error] [pid 230252:tid 230385] [client 45.8.17.61:41913] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/mah.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYkgAAApo"]
[Tue Jul 21 07:27:29.044926 2026] [security2:error] [pid 229246:tid 229380] [client 20.220.225.223:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/wp-explorer.php"] [unique_id "al9JkSBMYeh5YLVG45x9MQAAAhg"]
[Tue Jul 21 07:27:29.213698 2026] [security2:error] [pid 230252:tid 230366] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/fancy-product-designer/readme.txt"] [unique_id "al9JkU0Dwhk5-Z44XrpYlwADBm8"], referer: http://bio.deiacakes.com/wp-content/plugins/fancy-product-designer/readme.txt
[Tue Jul 21 07:27:29.385153 2026] [security2:error] [pid 230252:tid 230505] [client 20.220.225.223:53456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/8.php"] [unique_id "al9JkU0Dwhk5-Z44XrpYmQAAAxI"]
[Tue Jul 21 07:27:29.447154 2026] [security2:error] [pid 229246:tid 229332] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JkSBMYeh5YLVG45x9NQACIFU"]
[Tue Jul 21 07:27:29.447259 2026] [security2:error] [pid 229246:tid 229388] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JkSBMYeh5YLVG45x9NQACIFU"]
[Tue Jul 21 07:27:29.640560 2026] [security2:error] [pid 230252:tid 230426] [client 152.59.154.239:50883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JkU0Dwhk5-Z44XrpYngAAAsM"]
[Tue Jul 21 07:27:29.770044 2026] [security2:error] [pid 230252:tid 230301] [remote 45.3.36.177:17829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.36.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JkE0Dwhk5-Z44XrpYkAADES8"]
[Tue Jul 21 07:27:29.898565 2026] [security2:error] [pid 229246:tid 229468] [client 20.151.10.161:63665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/config.json.php"] [unique_id "al9JkSBMYeh5YLVG45x9OAAAAnA"]
[Tue Jul 21 07:27:29.958122 2026] [security2:error] [pid 230252:tid 230501] [client 213.152.162.104:51286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JkU0Dwhk5-Z44XrpYowAAAw4"]
[Tue Jul 21 07:27:29.958199 2026] [security2:error] [pid 230252:tid 230501] [client 213.152.162.104:51286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9JkU0Dwhk5-Z44XrpYowAAAw4"]
[Tue Jul 21 07:27:30.083543 2026] [security2:error] [pid 230252:tid 230502] [client 45.8.17.123:41699] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/"] [unique_id "al9Jkk0Dwhk5-Z44XrpYpAAAAw8"]
[Tue Jul 21 07:27:30.227200 2026] [security2:error] [pid 230252:tid 230438] [client 74.249.245.134:17455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/wp-links.php"] [unique_id "al9Jkk0Dwhk5-Z44XrpYpwAAAs8"]
[Tue Jul 21 07:27:30.242336 2026] [security2:error] [pid 230252:tid 230273] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "al9Jkk0Dwhk5-Z44XrpYqAADARM"], referer: http://bio.deiacakes.com/wp-content/plugins/code-snippets/readme.txt
[Tue Jul 21 07:27:30.524446 2026] [autoindex:error] [pid 229246:tid 229484] [client 20.104.96.117:5062] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:30.588658 2026] [security2:error] [pid 229246:tid 229426] [client 139.135.44.145:54704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JkiBMYeh5YLVG45x9UQAAAkY"]
[Tue Jul 21 07:27:30.588736 2026] [security2:error] [pid 229246:tid 229426] [client 139.135.44.145:54704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JkiBMYeh5YLVG45x9UQAAAkY"]
[Tue Jul 21 07:27:30.684738 2026] [security2:error] [pid 230252:tid 230405] [client 20.220.225.223:55761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/red.php"] [unique_id "al9Jkk0Dwhk5-Z44XrpYqwAAAq4"]
[Tue Jul 21 07:27:31.092530 2026] [security2:error] [pid 229246:tid 229377] [client 45.8.17.124:65269] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp.php"] [unique_id "al9JkyBMYeh5YLVG45x9kwAAAhU"]
[Tue Jul 21 07:27:31.509050 2026] [security2:error] [pid 229246:tid 229422] [client 20.220.225.223:46137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/akismet.php"] [unique_id "al9JkyBMYeh5YLVG45x9mAAAAkI"]
[Tue Jul 21 07:27:31.551756 2026] [security2:error] [pid 229246:tid 229267] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wpschoolpress/readme.txt"] [unique_id "al9JkyBMYeh5YLVG45x9nQACiRQ"], referer: http://bio.deiacakes.com/wp-content/plugins/wpschoolpress/readme.txt
[Tue Jul 21 07:27:31.746511 2026] [security2:error] [pid 230252:tid 230445] [client 117.251.86.144:39886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Jk00Dwhk5-Z44XrpYtwAAAtY"]
[Tue Jul 21 07:27:31.746647 2026] [security2:error] [pid 230252:tid 230445] [client 117.251.86.144:39886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Jk00Dwhk5-Z44XrpYtwAAAtY"]
[Tue Jul 21 07:27:31.751819 2026] [security2:error] [pid 229246:tid 229408] [client 20.52.136.55:1590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/wp-mail.php"] [unique_id "al9JkyBMYeh5YLVG45x9nwAAAjQ"]
[Tue Jul 21 07:27:31.985521 2026] [security2:error] [pid 229246:tid 229388] [client 45.8.17.135:43323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/hello-plus/classes/ehp-sarang.php"] [unique_id "al9JkyBMYeh5YLVG45x92wAAAiA"]
[Tue Jul 21 07:27:32.175413 2026] [security2:error] [pid 229246:tid 229468] [client 20.151.10.161:63698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.havoy.com.br"] [uri "/fpwch.php"] [unique_id "al9JlCBMYeh5YLVG45x94AAAAnA"]
[Tue Jul 21 07:27:32.175443 2026] [security2:error] [pid 230252:tid 230436] [client 20.220.225.223:55760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/fffm.php"] [unique_id "al9JlE0Dwhk5-Z44XrpYzAAAAs0"]
[Tue Jul 21 07:27:32.257663 2026] [core:alert] [pid 230252:tid 230429] [client 57.141.18.0:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:27:32.264601 2026] [security2:error] [pid 229246:tid 229452] [client 20.104.96.117:5062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/.well-known/about.php"] [unique_id "al9JlCBMYeh5YLVG45x94wAAAmA"]
[Tue Jul 21 07:27:32.570690 2026] [security2:error] [pid 230252:tid 230258] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wordpress-database-reset/readme.txt"] [unique_id "al9JlE0Dwhk5-Z44XrpYzwACvwQ"], referer: http://bio.deiacakes.com/wp-content/plugins/wordpress-database-reset/readme.txt
[Tue Jul 21 07:27:32.687268 2026] [security2:error] [pid 230252:tid 230464] [client 62.102.148.164:54118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JlE0Dwhk5-Z44XrpY0gAAAuk"]
[Tue Jul 21 07:27:32.687353 2026] [security2:error] [pid 230252:tid 230464] [client 62.102.148.164:54118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JlE0Dwhk5-Z44XrpY0gAAAuk"]
[Tue Jul 21 07:27:32.740244 2026] [security2:error] [pid 229246:tid 229424] [client 20.104.96.117:59778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/fnstall.php"] [unique_id "al9JlCBMYeh5YLVG45x98AAAAkQ"]
[Tue Jul 21 07:27:32.741639 2026] [security2:error] [pid 230252:tid 230405] [client 20.220.225.223:27148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/ftde.php"] [unique_id "al9JlE0Dwhk5-Z44XrpY0wAAAq4"]
[Tue Jul 21 07:27:32.823967 2026] [security2:error] [pid 230252:tid 230370] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JlE0Dwhk5-Z44XrpY1AAC-XM"]
[Tue Jul 21 07:27:32.824111 2026] [security2:error] [pid 230252:tid 230480] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JlE0Dwhk5-Z44XrpY1AAC-XM"]
[Tue Jul 21 07:27:32.888462 2026] [security2:error] [pid 230252:tid 230395] [client 20.104.96.117:62922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9JlE0Dwhk5-Z44XrpY1QAAAqQ"]
[Tue Jul 21 07:27:32.901487 2026] [security2:error] [pid 229246:tid 229464] [client 45.251.232.145:51170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JlCBMYeh5YLVG45x9_AAAAmw"]
[Tue Jul 21 07:27:32.901655 2026] [security2:error] [pid 229246:tid 229464] [client 45.251.232.145:51170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JlCBMYeh5YLVG45x9_AAAAmw"]
[Tue Jul 21 07:27:33.085017 2026] [security2:error] [pid 230252:tid 230387] [client 45.8.17.113:36679] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyone/content-index.php"] [unique_id "al9JlU0Dwhk5-Z44XrpY1gAAApw"]
[Tue Jul 21 07:27:33.241277 2026] [security2:error] [pid 229246:tid 229411] [client 20.104.96.117:5096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wefile.php"] [unique_id "al9JlSBMYeh5YLVG45x-EAAAAjc"]
[Tue Jul 21 07:27:33.425916 2026] [security2:error] [pid 230252:tid 230342] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JlU0Dwhk5-Z44XrpY2gACulc"]
[Tue Jul 21 07:27:33.426059 2026] [security2:error] [pid 230252:tid 230417] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JlU0Dwhk5-Z44XrpY2gACulc"]
[Tue Jul 21 07:27:33.452934 2026] [security2:error] [pid 230252:tid 230333] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY2wACvE4"], referer: http://bio.deiacakes.com/wp-content/plugins/contact-form-7/readme.txt
[Tue Jul 21 07:27:33.497030 2026] [security2:error] [pid 230252:tid 230355] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wordfence/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY3QAC92Q"], referer: http://bio.deiacakes.com/wp-content/plugins/wordfence/readme.txt
[Tue Jul 21 07:27:33.503740 2026] [security2:error] [pid 229246:tid 229366] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-EQACinc"], referer: http://bio.deiacakes.com/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt
[Tue Jul 21 07:27:33.508172 2026] [security2:error] [pid 230252:tid 230276] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/litespeed-cache/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY3gAC9hY"], referer: http://bio.deiacakes.com/wp-content/plugins/litespeed-cache/readme.txt
[Tue Jul 21 07:27:33.519704 2026] [security2:error] [pid 229246:tid 229341] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/all-in-one-wp-migration/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-EwACFl4"], referer: http://bio.deiacakes.com/wp-content/plugins/all-in-one-wp-migration/readme.txt
[Tue Jul 21 07:27:33.538377 2026] [security2:error] [pid 230252:tid 230310] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY3wACozg"], referer: http://bio.deiacakes.com/wp-content/plugins/google-site-kit/readme.txt
[Tue Jul 21 07:27:33.548344 2026] [security2:error] [pid 229246:tid 229326] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wordpress-seo/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-FAACfE8"], referer: http://bio.deiacakes.com/wp-content/plugins/wordpress-seo/readme.txt
[Tue Jul 21 07:27:33.561988 2026] [security2:error] [pid 230252:tid 230351] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/insert-headers-and-footers/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY4AACrWA"], referer: http://bio.deiacakes.com/wp-content/plugins/insert-headers-and-footers/readme.txt
[Tue Jul 21 07:27:33.574338 2026] [security2:error] [pid 229246:tid 229278] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/duplicate-page/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-FgACLh8"], referer: http://bio.deiacakes.com/wp-content/plugins/duplicate-page/readme.txt
[Tue Jul 21 07:27:33.575850 2026] [security2:error] [pid 230252:tid 230261] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-super-cache/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY4QAC0gc"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-super-cache/readme.txt
[Tue Jul 21 07:27:33.579852 2026] [security2:error] [pid 230252:tid 230292] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/redirection/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY4gAC1iY"], referer: http://bio.deiacakes.com/wp-content/plugins/redirection/readme.txt
[Tue Jul 21 07:27:33.585702 2026] [security2:error] [pid 230252:tid 230290] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY4wAC5iQ"], referer: http://bio.deiacakes.com/wp-content/plugins/woocommerce/readme.txt
[Tue Jul 21 07:27:33.597246 2026] [security2:error] [pid 230252:tid 230284] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/google-analytics-for-wordpress/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY5QAC2x4"], referer: http://bio.deiacakes.com/wp-content/plugins/google-analytics-for-wordpress/readme.txt
[Tue Jul 21 07:27:33.598274 2026] [security2:error] [pid 230252:tid 230296] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/duplicator/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY5gADBCo"], referer: http://bio.deiacakes.com/wp-content/plugins/duplicator/readme.txt
[Tue Jul 21 07:27:33.604547 2026] [security2:error] [pid 229246:tid 229264] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/seo-by-rank-math/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-GAAChRE"], referer: http://bio.deiacakes.com/wp-content/plugins/seo-by-rank-math/readme.txt
[Tue Jul 21 07:27:33.617879 2026] [security2:error] [pid 230252:tid 230363] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/disable-comments/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY5wADC2w"], referer: http://bio.deiacakes.com/wp-content/plugins/disable-comments/readme.txt
[Tue Jul 21 07:27:33.640470 2026] [security2:error] [pid 229246:tid 229356] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-HwACUW0"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-file-manager/readme.txt
[Tue Jul 21 07:27:33.641471 2026] [security2:error] [pid 230252:tid 230465] [client 59.96.220.140:64840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JlU0Dwhk5-Z44XrpY6AAAAuo"]
[Tue Jul 21 07:27:33.641581 2026] [security2:error] [pid 230252:tid 230465] [client 59.96.220.140:64840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JlU0Dwhk5-Z44XrpY6AAAAuo"]
[Tue Jul 21 07:27:33.651791 2026] [security2:error] [pid 230252:tid 230500] [client 20.104.96.117:64009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9JlU0Dwhk5-Z44XrpY6QAAAw0"]
[Tue Jul 21 07:27:33.651866 2026] [security2:error] [pid 230252:tid 230365] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/w3-total-cache/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY6gADAG4"], referer: http://bio.deiacakes.com/wp-content/plugins/w3-total-cache/readme.txt
[Tue Jul 21 07:27:33.652288 2026] [security2:error] [pid 230252:tid 230349] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/better-search-replace/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY6wADAF4"], referer: http://bio.deiacakes.com/wp-content/plugins/better-search-replace/readme.txt
[Tue Jul 21 07:27:33.674316 2026] [security2:error] [pid 229246:tid 229252] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/loginizer/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-IQACagU"], referer: http://bio.deiacakes.com/wp-content/plugins/loginizer/readme.txt
[Tue Jul 21 07:27:33.675603 2026] [security2:error] [pid 230252:tid 230331] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/ewww-image-optimizer/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY7AAC0Ew"], referer: http://bio.deiacakes.com/wp-content/plugins/ewww-image-optimizer/readme.txt
[Tue Jul 21 07:27:33.679055 2026] [security2:error] [pid 230252:tid 230285] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/all-in-one-wp-security-and-firewall/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY7QAC6B8"], referer: http://bio.deiacakes.com/wp-content/plugins/all-in-one-wp-security-and-firewall/readme.txt
[Tue Jul 21 07:27:33.679590 2026] [security2:error] [pid 229246:tid 229351] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/envato-elements/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-IgACkGg"], referer: http://bio.deiacakes.com/wp-content/plugins/envato-elements/readme.txt
[Tue Jul 21 07:27:33.684931 2026] [security2:error] [pid 230252:tid 230270] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/coming-soon/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY7gAC3xA"], referer: http://bio.deiacakes.com/wp-content/plugins/coming-soon/readme.txt
[Tue Jul 21 07:27:33.687189 2026] [security2:error] [pid 230252:tid 230413] [client 20.52.136.55:1736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/about.php"] [unique_id "al9JlU0Dwhk5-Z44XrpY7wAAArY"]
[Tue Jul 21 07:27:33.757796 2026] [security2:error] [pid 229246:tid 229379] [client 193.36.225.62:38507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JlSBMYeh5YLVG45x-IwAAAhc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:33.782380 2026] [security2:error] [pid 229246:tid 229271] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-TgACMhg"], referer: http://bio.deiacakes.com/wp-content/plugins/wpforms-lite/readme.txt
[Tue Jul 21 07:27:33.802679 2026] [security2:error] [pid 230252:tid 230368] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/akismet/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY8QAC4XE"], referer: http://bio.deiacakes.com/wp-content/plugins/akismet/readme.txt
[Tue Jul 21 07:27:33.847824 2026] [security2:error] [pid 229246:tid 229261] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/duplicate-post/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-UAACGw4"], referer: http://bio.deiacakes.com/wp-content/plugins/duplicate-post/readme.txt
[Tue Jul 21 07:27:33.855038 2026] [security2:error] [pid 229246:tid 229275] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/mailchimp-for-wp/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-UQACexw"], referer: http://bio.deiacakes.com/wp-content/plugins/mailchimp-for-wp/readme.txt
[Tue Jul 21 07:27:33.856227 2026] [security2:error] [pid 230252:tid 230277] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/all-in-one-seo-pack/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY8gACyRc"], referer: http://bio.deiacakes.com/wp-content/plugins/all-in-one-seo-pack/readme.txt
[Tue Jul 21 07:27:33.865666 2026] [security2:error] [pid 230252:tid 230369] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/header-footer-elementor/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY8wAC7HI"], referer: http://bio.deiacakes.com/wp-content/plugins/header-footer-elementor/readme.txt
[Tue Jul 21 07:27:33.867348 2026] [security2:error] [pid 230252:tid 230278] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY9AACrxg"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-fastest-cache/readme.txt
[Tue Jul 21 07:27:33.877300 2026] [security2:error] [pid 229246:tid 229305] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wps-hide-login/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-UgACGjo"], referer: http://bio.deiacakes.com/wp-content/plugins/wps-hide-login/readme.txt
[Tue Jul 21 07:27:33.880205 2026] [security2:error] [pid 230252:tid 230297] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/really-simple-ssl/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY9QAC-ys"], referer: http://bio.deiacakes.com/wp-content/plugins/really-simple-ssl/readme.txt
[Tue Jul 21 07:27:33.880479 2026] [security2:error] [pid 229246:tid 229362] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/astra-sites/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-UwACV3M"], referer: http://bio.deiacakes.com/wp-content/plugins/astra-sites/readme.txt
[Tue Jul 21 07:27:33.885618 2026] [security2:error] [pid 229246:tid 229332] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/limit-login-attempts-reloaded/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-VAACFFU"], referer: http://bio.deiacakes.com/wp-content/plugins/limit-login-attempts-reloaded/readme.txt
[Tue Jul 21 07:27:33.896691 2026] [security2:error] [pid 230252:tid 230381] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/updraftplus/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY9gAC9H4"], referer: http://bio.deiacakes.com/wp-content/plugins/updraftplus/readme.txt
[Tue Jul 21 07:27:33.903980 2026] [security2:error] [pid 230252:tid 230257] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY9wACzAM"], referer: http://bio.deiacakes.com/wp-content/plugins/jetpack/readme.txt
[Tue Jul 21 07:27:33.916316 2026] [security2:error] [pid 230252:tid 230256] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/advanced-custom-fields/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY-AADEgI"], referer: http://bio.deiacakes.com/wp-content/plugins/advanced-custom-fields/readme.txt
[Tue Jul 21 07:27:33.922197 2026] [security2:error] [pid 229246:tid 229372] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/svg-support/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-VQACHH0"], referer: http://bio.deiacakes.com/wp-content/plugins/svg-support/readme.txt
[Tue Jul 21 07:27:33.937366 2026] [security2:error] [pid 230252:tid 230334] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/ultimate-addons-for-gutenberg/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY-QADE08"], referer: http://bio.deiacakes.com/wp-content/plugins/ultimate-addons-for-gutenberg/readme.txt
[Tue Jul 21 07:27:33.941467 2026] [security2:error] [pid 230252:tid 230350] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/sg-security/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY-gACy18"], referer: http://bio.deiacakes.com/wp-content/plugins/sg-security/readme.txt
[Tue Jul 21 07:27:33.957229 2026] [security2:error] [pid 230252:tid 230380] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/smart-slider-3/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY-wAC1X0"], referer: http://bio.deiacakes.com/wp-content/plugins/smart-slider-3/readme.txt
[Tue Jul 21 07:27:33.965105 2026] [security2:error] [pid 230252:tid 230272] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/redux-framework/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY_AACtBI"], referer: http://bio.deiacakes.com/wp-content/plugins/redux-framework/readme.txt
[Tue Jul 21 07:27:33.972710 2026] [security2:error] [pid 229246:tid 229292] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/autoptimize/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-VgACYi0"], referer: http://bio.deiacakes.com/wp-content/plugins/autoptimize/readme.txt
[Tue Jul 21 07:27:33.978574 2026] [security2:error] [pid 230252:tid 230266] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/hostinger/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY_gADBgw"], referer: http://bio.deiacakes.com/wp-content/plugins/hostinger/readme.txt
[Tue Jul 21 07:27:33.978785 2026] [security2:error] [pid 229246:tid 229363] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-optimize/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-VwACaHQ"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-optimize/readme.txt
[Tue Jul 21 07:27:33.979614 2026] [security2:error] [pid 229246:tid 229295] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/better-wp-security/readme.txt"] [unique_id "al9JlSBMYeh5YLVG45x-WAACSTA"], referer: http://bio.deiacakes.com/wp-content/plugins/better-wp-security/readme.txt
[Tue Jul 21 07:27:33.980113 2026] [autoindex:error] [pid 230252:tid 230473] [client 20.104.96.117:62928] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:33.985784 2026] [security2:error] [pid 230252:tid 230321] [remote 45.156.129.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/complianz-gdpr/readme.txt"] [unique_id "al9JlU0Dwhk5-Z44XrpY_wACm0M"], referer: http://bio.deiacakes.com/wp-content/plugins/complianz-gdpr/readme.txt
[Tue Jul 21 07:27:33.989060 2026] [security2:error] [pid 229246:tid 229395] [client 45.8.17.48:49051] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/admin.php"] [unique_id "al9JlSBMYeh5YLVG45x-WQAAAic"]
[Tue Jul 21 07:27:34.030149 2026] [security2:error] [pid 229246:tid 229456] [client 20.220.225.223:46112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ace2.php"] [unique_id "al9JliBMYeh5YLVG45x-WgAAAmQ"]
[Tue Jul 21 07:27:34.219958 2026] [security2:error] [pid 229246:tid 229277] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JliBMYeh5YLVG45x-YgACHR4"]
[Tue Jul 21 07:27:34.220135 2026] [security2:error] [pid 229246:tid 229385] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JliBMYeh5YLVG45x-YgACHR4"]
[Tue Jul 21 07:27:34.344004 2026] [autoindex:error] [pid 230252:tid 230396] [client 20.104.96.117:62928] AH01276: Cannot serve directory /home4/forev309/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:34.372678 2026] [autoindex:error] [pid 229246:tid 229476] [client 192.175.111.239:38103] AH01276: Cannot serve directory /home4/ciclod61/bahtelecom.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:34.482659 2026] [security2:error] [pid 230252:tid 230408] [client 20.104.96.117:62928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Jlk0Dwhk5-Z44XrpZBgAAArE"]
[Tue Jul 21 07:27:34.616503 2026] [security2:error] [pid 229246:tid 229306] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JliBMYeh5YLVG45x-ZwACUzs"]
[Tue Jul 21 07:27:34.616639 2026] [security2:error] [pid 229246:tid 229439] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JliBMYeh5YLVG45x-ZwACUzs"]
[Tue Jul 21 07:27:34.808013 2026] [security2:error] [pid 230252:tid 230479] [client 103.106.20.201:51407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jlk0Dwhk5-Z44XrpZCwAAAvg"]
[Tue Jul 21 07:27:34.808157 2026] [security2:error] [pid 230252:tid 230479] [client 103.106.20.201:51407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jlk0Dwhk5-Z44XrpZCwAAAvg"]
[Tue Jul 21 07:27:34.817560 2026] [security2:error] [pid 229246:tid 229404] [client 20.104.96.117:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/8.php"] [unique_id "al9JliBMYeh5YLVG45x-agAAAjA"]
[Tue Jul 21 07:27:34.983185 2026] [security2:error] [pid 230252:tid 230328] [remote 45.156.129.118:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/kingcomposer/readme.txt"] [unique_id "al9Jlk0Dwhk5-Z44XrpZDAACq0k"], referer: http://bio.deiacakes.com/wp-content/plugins/kingcomposer/readme.txt
[Tue Jul 21 07:27:35.077517 2026] [security2:error] [pid 230252:tid 230265] [remote 157.66.26.183:44642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/wp-login.php"] [unique_id "al9Jlk0Dwhk5-Z44XrpZAAAC4ws"]
[Tue Jul 21 07:27:35.184367 2026] [security2:error] [pid 230252:tid 230494] [client 45.8.17.108:55455] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/404.php"] [unique_id "al9Jl00Dwhk5-Z44XrpZDQAAAwc"]
[Tue Jul 21 07:27:35.188013 2026] [security2:error] [pid 230252:tid 230390] [client 20.220.225.223:60366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/yup.php"] [unique_id "al9Jl00Dwhk5-Z44XrpZDgAAAp8"]
[Tue Jul 21 07:27:35.197726 2026] [security2:error] [pid 230252:tid 230399] [client 20.104.96.117:59592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/acp.php"] [unique_id "al9Jl00Dwhk5-Z44XrpZDwAAAqg"]
[Tue Jul 21 07:27:35.249901 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:5078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-content/admin.php"] [unique_id "al9Jl00Dwhk5-Z44XrpZEgAAAtM"]
[Tue Jul 21 07:27:35.653253 2026] [security2:error] [pid 229246:tid 229434] [client 20.104.96.117:64014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/f6.php"] [unique_id "al9JlyBMYeh5YLVG45x-eQAAAk4"]
[Tue Jul 21 07:27:35.767622 2026] [security2:error] [pid 230252:tid 230314] [remote 20.84.23.222:6141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.23.84.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/wp-login.php"] [unique_id "al9Jlk0Dwhk5-Z44XrpZCgACojw"]
[Tue Jul 21 07:27:35.879530 2026] [security2:error] [pid 229246:tid 229291] [remote 45.156.129.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/wp-video-lightbox/readme.txt"] [unique_id "al9JlyBMYeh5YLVG45x-fQACPCw"], referer: http://bio.deiacakes.com/wp-content/plugins/wp-video-lightbox/readme.txt
[Tue Jul 21 07:27:36.010225 2026] [security2:error] [pid 230252:tid 230456] [client 20.104.96.117:64051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/inputs.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZGwAAAuE"]
[Tue Jul 21 07:27:36.533144 2026] [security2:error] [pid 230252:tid 230439] [client 103.174.34.15:63882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZIgAAAtA"]
[Tue Jul 21 07:27:36.533275 2026] [security2:error] [pid 230252:tid 230439] [client 103.174.34.15:63882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZIgAAAtA"]
[Tue Jul 21 07:27:36.582511 2026] [security2:error] [pid 229246:tid 229428] [client 20.52.136.55:1751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/adminfuns.php"] [unique_id "al9JmCBMYeh5YLVG45x-gwAAAkg"]
[Tue Jul 21 07:27:36.639861 2026] [security2:error] [pid 230252:tid 230506] [client 20.104.96.117:62945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/inputs.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZIwAAAxM"]
[Tue Jul 21 07:27:36.723748 2026] [security2:error] [pid 230252:tid 230508] [client 175.45.70.82:54650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZJAAAAxU"]
[Tue Jul 21 07:27:36.723875 2026] [security2:error] [pid 230252:tid 230508] [client 175.45.70.82:54650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZJAAAAxU"]
[Tue Jul 21 07:27:36.788109 2026] [security2:error] [pid 230252:tid 230467] [client 154.192.233.199:58786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZJQAAAuw"]
[Tue Jul 21 07:27:36.788232 2026] [security2:error] [pid 230252:tid 230467] [client 154.192.233.199:58786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JmE0Dwhk5-Z44XrpZJQAAAuw"]
[Tue Jul 21 07:27:37.004143 2026] [security2:error] [pid 229246:tid 229376] [client 20.104.96.117:62971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/classwithtostring.php"] [unique_id "al9JmSBMYeh5YLVG45x-jQAAAhQ"]
[Tue Jul 21 07:27:37.092673 2026] [security2:error] [pid 230252:tid 230437] [client 45.8.17.60:29563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/file.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZJwAAAs4"]
[Tue Jul 21 07:27:37.097224 2026] [security2:error] [pid 229246:tid 229276] [remote 45.156.129.117:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bio.deiacakes.com"] [uri "/wp-content/plugins/optinmonster/readme.txt"] [unique_id "al9JmSBMYeh5YLVG45x-jgACXh0"], referer: http://bio.deiacakes.com/wp-content/plugins/optinmonster/readme.txt
[Tue Jul 21 07:27:37.317597 2026] [security2:error] [pid 229246:tid 229289] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JmSBMYeh5YLVG45x-kgACjio"]
[Tue Jul 21 07:27:37.317760 2026] [security2:error] [pid 229246:tid 229498] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JmSBMYeh5YLVG45x-kgACjio"]
[Tue Jul 21 07:27:37.321419 2026] [proxy:error] [pid 230252:tid 230462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:37.321499 2026] [proxy_http:error] [pid 230252:tid 230462] [client 20.151.10.161:48608] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:37.322057 2026] [proxy:error] [pid 230252:tid 230462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:37.322094 2026] [proxy_http:error] [pid 230252:tid 230462] [client 20.151.10.161:48608] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:37.345216 2026] [security2:error] [pid 230252:tid 230416] [client 20.104.96.117:64027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZLAAAArk"]
[Tue Jul 21 07:27:37.367809 2026] [security2:error] [pid 230252:tid 230468] [client 109.248.148.246:36968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZLQAAAu0"]
[Tue Jul 21 07:27:37.367912 2026] [security2:error] [pid 230252:tid 230468] [client 109.248.148.246:36968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZLQAAAu0"]
[Tue Jul 21 07:27:37.469325 2026] [security2:error] [pid 229246:tid 229296] [remote 192.249.127.213:51344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.127.249.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JmSBMYeh5YLVG45x-lAACHDE"]
[Tue Jul 21 07:27:37.657600 2026] [security2:error] [pid 230252:tid 230511] [client 20.220.225.223:53502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/jj.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZNQAAAxg"]
[Tue Jul 21 07:27:37.750583 2026] [security2:error] [pid 230252:tid 230391] [client 20.104.96.117:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-blog.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZNgAAAqA"]
[Tue Jul 21 07:27:37.876422 2026] [security2:error] [pid 230252:tid 230372] [remote 4.205.168.44:52088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arthromdcanada.online"] [uri "/wp-login.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZOwADDHU"]
[Tue Jul 21 07:27:37.881972 2026] [security2:error] [pid 230252:tid 230395] [client 45.8.17.106:65161] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/chosen.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZPAAAAqQ"]
[Tue Jul 21 07:27:37.982634 2026] [security2:error] [pid 230252:tid 230387] [client 74.249.245.134:54388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/xmrlpc.php"] [unique_id "al9JmU0Dwhk5-Z44XrpZPgAAApw"]
[Tue Jul 21 07:27:38.099019 2026] [proxy:error] [pid 230252:tid 230419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:38.099118 2026] [proxy_http:error] [pid 230252:tid 230419] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:38.100419 2026] [proxy:error] [pid 230252:tid 230419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:38.100485 2026] [proxy_http:error] [pid 230252:tid 230419] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:38.123976 2026] [autoindex:error] [pid 230252:tid 230397] [client 20.104.96.117:62920] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:38.137300 2026] [security2:error] [pid 230252:tid 230478] [client 20.104.96.117:42407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/mosty.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZQgAAAvc"]
[Tue Jul 21 07:27:38.192205 2026] [security2:error] [pid 230252:tid 230282] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZQwAC9hw"]
[Tue Jul 21 07:27:38.192367 2026] [security2:error] [pid 230252:tid 230477] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZQwAC9hw"]
[Tue Jul 21 07:27:38.404126 2026] [security2:error] [pid 230252:tid 230450] [client 20.104.96.117:62920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-content/admin.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZRQAAAts"]
[Tue Jul 21 07:27:38.705143 2026] [proxy:error] [pid 229246:tid 229415] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:38.705214 2026] [proxy_http:error] [pid 229246:tid 229415] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:38.705797 2026] [proxy:error] [pid 229246:tid 229415] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:38.705835 2026] [proxy_http:error] [pid 229246:tid 229415] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:38.822927 2026] [security2:error] [pid 230252:tid 230474] [client 103.162.129.114:63065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZSgAAAvM"]
[Tue Jul 21 07:27:38.823111 2026] [security2:error] [pid 230252:tid 230474] [client 103.162.129.114:63065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZSgAAAvM"]
[Tue Jul 21 07:27:38.906764 2026] [security2:error] [pid 230252:tid 230434] [client 136.144.33.107:35589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZTAAAAss"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:38.910101 2026] [security2:error] [pid 230252:tid 230505] [client 20.220.225.223:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/dragonshell.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZTQAAAxI"]
[Tue Jul 21 07:27:38.974637 2026] [security2:error] [pid 230252:tid 230439] [client 20.104.96.117:62912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ms-edit.php"] [unique_id "al9Jmk0Dwhk5-Z44XrpZTgAAAtA"]
[Tue Jul 21 07:27:39.180800 2026] [security2:error] [pid 229246:tid 229442] [client 45.8.17.140:37755] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/"] [unique_id "al9JmyBMYeh5YLVG45x-sAAAAlY"]
[Tue Jul 21 07:27:39.316668 2026] [security2:error] [pid 229246:tid 229414] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9JmyBMYeh5YLVG45x-tAAAAjo"]
[Tue Jul 21 07:27:39.350226 2026] [security2:error] [pid 229246:tid 229493] [client 20.104.96.117:62915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/cgi-bin/index.php"] [unique_id "al9JmyBMYeh5YLVG45x-tQAAAok"]
[Tue Jul 21 07:27:39.673410 2026] [security2:error] [pid 230252:tid 230397] [client 20.52.136.55:1582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/php8.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZWAAAAqY"]
[Tue Jul 21 07:27:39.736463 2026] [security2:error] [pid 230252:tid 230419] [client 173.252.95.25:36072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZWQAAArw"]
[Tue Jul 21 07:27:39.861667 2026] [autoindex:error] [pid 230252:tid 230399] [client 20.104.96.117:5083] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:39.862898 2026] [security2:error] [pid 230252:tid 230477] [client 20.220.225.223:46118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketing.androapkmod.com"] [uri "/ms.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZXAAAAvY"]
[Tue Jul 21 07:27:39.881477 2026] [security2:error] [pid 230252:tid 230453] [client 20.220.225.223:53440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/wp-mt.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZXQAAAt4"]
[Tue Jul 21 07:27:39.933048 2026] [security2:error] [pid 230252:tid 230465] [client 159.223.41.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZXgAAAuo"]
[Tue Jul 21 07:27:39.985753 2026] [security2:error] [pid 230252:tid 230373] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZYAAC-nY"]
[Tue Jul 21 07:27:39.985911 2026] [security2:error] [pid 230252:tid 230481] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZYAAC-nY"]
[Tue Jul 21 07:27:39.989751 2026] [security2:error] [pid 230252:tid 230393] [client 45.8.17.112:40955] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/1.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZYQAAAqI"]
[Tue Jul 21 07:27:40.147678 2026] [security2:error] [pid 230252:tid 230432] [client 20.104.96.117:5083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/BDKR28WP.php"] [unique_id "al9JnE0Dwhk5-Z44XrpZZAAAAsk"]
[Tue Jul 21 07:27:40.551416 2026] [proxy:error] [pid 229246:tid 229498] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:40.551484 2026] [proxy_http:error] [pid 229246:tid 229498] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:40.551945 2026] [proxy:error] [pid 229246:tid 229498] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:27:40.551971 2026] [proxy_http:error] [pid 229246:tid 229498] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:27:40.791700 2026] [autoindex:error] [pid 230252:tid 230473] [client 20.104.96.117:64059] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:40.918214 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:55793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/ww.php"] [unique_id "al9JnE0Dwhk5-Z44XrpZbQAAAto"]
[Tue Jul 21 07:27:40.979032 2026] [security2:error] [pid 230252:tid 230303] [remote 45.3.53.205:49993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.53.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9Jm00Dwhk5-Z44XrpZWgACujE"]
[Tue Jul 21 07:27:41.064327 2026] [security2:error] [pid 230252:tid 230403] [client 20.220.225.223:31190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/ah25.php"] [unique_id "al9JnU0Dwhk5-Z44XrpZbwAAAqw"]
[Tue Jul 21 07:27:41.103494 2026] [autoindex:error] [pid 230252:tid 230416] [client 20.104.96.117:64059] AH01276: Cannot serve directory /home4/forev309/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:41.169463 2026] [security2:error] [pid 230252:tid 230446] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9JnU0Dwhk5-Z44XrpZdAAAAtc"]
[Tue Jul 21 07:27:41.241848 2026] [security2:error] [pid 230252:tid 230451] [client 20.104.96.117:64059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/abcd.php"] [unique_id "al9JnU0Dwhk5-Z44XrpZdQAAAtw"]
[Tue Jul 21 07:27:41.392767 2026] [security2:error] [pid 230252:tid 230431] [client 45.8.17.121:42153] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/fukasawa/inc/classes/403.php"] [unique_id "al9JnU0Dwhk5-Z44XrpZdgAAAsg"]
[Tue Jul 21 07:27:41.649254 2026] [security2:error] [pid 230252:tid 230507] [client 139.135.44.145:53567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JnU0Dwhk5-Z44XrpZegAAAxQ"]
[Tue Jul 21 07:27:41.649565 2026] [security2:error] [pid 230252:tid 230507] [client 139.135.44.145:53567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JnU0Dwhk5-Z44XrpZegAAAxQ"]
[Tue Jul 21 07:27:41.779668 2026] [security2:error] [pid 230252:tid 230387] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9JnU0Dwhk5-Z44XrpZfQAAApw"]
[Tue Jul 21 07:27:42.051968 2026] [security2:error] [pid 230252:tid 230442] [client 74.249.245.134:5544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/htaccess.php"] [unique_id "al9Jnk0Dwhk5-Z44XrpZfwAAAtM"]
[Tue Jul 21 07:27:42.377454 2026] [security2:error] [pid 230252:tid 230488] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Jnk0Dwhk5-Z44XrpZgwAAAwE"]
[Tue Jul 21 07:27:42.419239 2026] [security2:error] [pid 230252:tid 230394] [client 20.104.96.117:62975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/file15.php"] [unique_id "al9Jnk0Dwhk5-Z44XrpZhAAAAqM"]
[Tue Jul 21 07:27:42.521213 2026] [security2:error] [pid 230252:tid 230348] [remote 132.148.72.88:49604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.bomnegociopromotora.com.br"] [uri "/wp-login.php"] [unique_id "al9JnU0Dwhk5-Z44XrpZeAACpV0"]
[Tue Jul 21 07:27:42.532299 2026] [security2:error] [pid 229246:tid 229478] [client 117.251.86.144:34044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JniBMYeh5YLVG45x-3AAAAno"]
[Tue Jul 21 07:27:42.532408 2026] [security2:error] [pid 229246:tid 229478] [client 117.251.86.144:34044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JniBMYeh5YLVG45x-3AAAAno"]
[Tue Jul 21 07:27:42.661122 2026] [security2:error] [pid 229246:tid 229464] [client 20.104.96.117:59610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/6.php"] [unique_id "al9JniBMYeh5YLVG45x-3wAAAmw"]
[Tue Jul 21 07:27:42.689622 2026] [security2:error] [pid 230252:tid 230491] [client 20.220.225.223:53478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/cron.php"] [unique_id "al9Jnk0Dwhk5-Z44XrpZiAAAAwQ"]
[Tue Jul 21 07:27:42.761121 2026] [security2:error] [pid 229246:tid 229430] [client 74.7.228.56:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "alexsandrodosreisfer1782517774685.0711679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9JniBMYeh5YLVG45x-5AACSnY"]
[Tue Jul 21 07:27:42.822447 2026] [security2:error] [pid 230252:tid 230424] [client 136.144.33.111:34897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Jnk0Dwhk5-Z44XrpZjAAAAsE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:42.968689 2026] [security2:error] [pid 230252:tid 230437] [client 152.59.154.239:15245] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jnk0Dwhk5-Z44XrpZjQAAAs4"]
[Tue Jul 21 07:27:42.968820 2026] [security2:error] [pid 230252:tid 230437] [client 152.59.154.239:15245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jnk0Dwhk5-Z44XrpZjQAAAs4"]
[Tue Jul 21 07:27:42.977144 2026] [security2:error] [pid 229246:tid 229422] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9JniBMYeh5YLVG45x-6wAAAkI"]
[Tue Jul 21 07:27:43.289919 2026] [security2:error] [pid 229246:tid 229319] [remote 46.105.28.235:49778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-login.php"] [unique_id "al9JnyBMYeh5YLVG45x-9gACLkg"]
[Tue Jul 21 07:27:43.366321 2026] [security2:error] [pid 229246:tid 229479] [client 20.220.225.223:55754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/xxx.php"] [unique_id "al9JnyBMYeh5YLVG45x--gAAAns"]
[Tue Jul 21 07:27:43.391438 2026] [security2:error] [pid 229246:tid 229447] [client 45.251.232.145:51683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JnyBMYeh5YLVG45x--wAAAls"]
[Tue Jul 21 07:27:43.391556 2026] [security2:error] [pid 229246:tid 229447] [client 45.251.232.145:51683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JnyBMYeh5YLVG45x--wAAAls"]
[Tue Jul 21 07:27:43.411576 2026] [security2:error] [pid 229246:tid 229463] [client 74.249.245.134:17451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/readme.php"] [unique_id "al9JnyBMYeh5YLVG45x-_AAAAms"]
[Tue Jul 21 07:27:43.436522 2026] [security2:error] [pid 229246:tid 229353] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JnyBMYeh5YLVG45x-_gACG2o"]
[Tue Jul 21 07:27:43.436630 2026] [security2:error] [pid 229246:tid 229383] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JnyBMYeh5YLVG45x-_gACG2o"]
[Tue Jul 21 07:27:43.585618 2026] [security2:error] [pid 229246:tid 229441] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9JnyBMYeh5YLVG45x_AgAAAlU"]
[Tue Jul 21 07:27:43.614562 2026] [security2:error] [pid 229246:tid 229459] [client 20.104.96.117:62946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/jp.php"] [unique_id "al9JnyBMYeh5YLVG45x_AwAAAmc"]
[Tue Jul 21 07:27:43.812166 2026] [security2:error] [pid 229246:tid 229481] [client 59.96.220.140:65072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JnyBMYeh5YLVG45x_BwAAAn0"]
[Tue Jul 21 07:27:43.812828 2026] [security2:error] [pid 229246:tid 229481] [client 59.96.220.140:65072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JnyBMYeh5YLVG45x_BwAAAn0"]
[Tue Jul 21 07:27:44.136379 2026] [security2:error] [pid 229246:tid 229456] [client 20.52.136.55:1759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/info.php"] [unique_id "al9JoCBMYeh5YLVG45x_CwAAAmQ"]
[Tue Jul 21 07:27:44.192628 2026] [security2:error] [pid 229246:tid 229417] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9JoCBMYeh5YLVG45x_DAAAAj0"]
[Tue Jul 21 07:27:44.584418 2026] [security2:error] [pid 230252:tid 230415] [client 20.220.225.223:60358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/hunter.php"] [unique_id "al9JoE0Dwhk5-Z44XrpZkwAAArg"]
[Tue Jul 21 07:27:44.687240 2026] [security2:error] [pid 229246:tid 229418] [client 74.249.245.134:54350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/403.php"] [unique_id "al9JoCBMYeh5YLVG45x_GAAAAj4"]
[Tue Jul 21 07:27:44.703574 2026] [security2:error] [pid 229246:tid 229377] [client 20.104.96.117:64010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/f35.php"] [unique_id "al9JoCBMYeh5YLVG45x_GQAAAhU"]
[Tue Jul 21 07:27:44.822855 2026] [security2:error] [pid 229246:tid 229442] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9JoCBMYeh5YLVG45x_GwAAAlY"]
[Tue Jul 21 07:27:45.115295 2026] [security2:error] [pid 230252:tid 230427] [client 20.104.96.117:64021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-load.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZlwAAAsQ"]
[Tue Jul 21 07:27:45.125747 2026] [security2:error] [pid 230252:tid 230323] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZmAADDkU"]
[Tue Jul 21 07:27:45.125877 2026] [security2:error] [pid 230252:tid 230501] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZmAADDkU"]
[Tue Jul 21 07:27:45.187999 2026] [security2:error] [pid 229246:tid 229416] [client 109.248.148.246:39706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JoSBMYeh5YLVG45x_IAAAAjw"]
[Tue Jul 21 07:27:45.188115 2026] [security2:error] [pid 229246:tid 229416] [client 109.248.148.246:39706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JoSBMYeh5YLVG45x_IAAAAjw"]
[Tue Jul 21 07:27:45.202308 2026] [security2:error] [pid 230252:tid 230262] [remote 65.111.28.178:40813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZmwAC5wg"]
[Tue Jul 21 07:27:45.439109 2026] [security2:error] [pid 230252:tid 230422] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9JoU0Dwhk5-Z44XrpZnQAAAr8"]
[Tue Jul 21 07:27:45.477346 2026] [security2:error] [pid 230252:tid 230431] [client 20.151.10.161:48587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/bthil.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZngAAAsg"]
[Tue Jul 21 07:27:45.541710 2026] [security2:error] [pid 229246:tid 229310] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JoSBMYeh5YLVG45x_JAACkD8"]
[Tue Jul 21 07:27:45.541862 2026] [security2:error] [pid 229246:tid 229500] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JoSBMYeh5YLVG45x_JAACkD8"]
[Tue Jul 21 07:27:45.555960 2026] [security2:error] [pid 229246:tid 229306] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JoSBMYeh5YLVG45x_JQACXTs"]
[Tue Jul 21 07:27:45.556147 2026] [security2:error] [pid 229246:tid 229449] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JoSBMYeh5YLVG45x_JQACXTs"]
[Tue Jul 21 07:27:45.735700 2026] [security2:error] [pid 230252:tid 230502] [client 103.106.20.201:51979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZnwAAAw8"]
[Tue Jul 21 07:27:45.735810 2026] [security2:error] [pid 230252:tid 230502] [client 103.106.20.201:51979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZnwAAAw8"]
[Tue Jul 21 07:27:45.740992 2026] [security2:error] [pid 230252:tid 230464] [client 74.249.245.134:62871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/max.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZoAAAAuk"]
[Tue Jul 21 07:27:45.831793 2026] [security2:error] [pid 230252:tid 230460] [client 20.104.96.117:64029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/xyn.php"] [unique_id "al9JoU0Dwhk5-Z44XrpZpAAAAuU"]
[Tue Jul 21 07:27:46.022539 2026] [security2:error] [pid 230252:tid 230414] [client 20.220.225.223:55788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/we.php"] [unique_id "al9Jok0Dwhk5-Z44XrpZpQAAArc"]
[Tue Jul 21 07:27:46.050251 2026] [security2:error] [pid 230252:tid 230397] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Jok0Dwhk5-Z44XrpZpwAAAqY"]
[Tue Jul 21 07:27:46.079266 2026] [security2:error] [pid 230252:tid 230419] [client 45.8.17.144:54017] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/alera/gecko.php"] [unique_id "al9Jok0Dwhk5-Z44XrpZqQAAArw"]
[Tue Jul 21 07:27:46.312228 2026] [security2:error] [pid 230252:tid 230461] [client 20.220.225.223:38671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/8.php"] [unique_id "al9Jok0Dwhk5-Z44XrpZqgAAAuY"]
[Tue Jul 21 07:27:46.656673 2026] [security2:error] [pid 230252:tid 230498] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Jok0Dwhk5-Z44XrpZrwAAAws"]
[Tue Jul 21 07:27:46.672495 2026] [security2:error] [pid 229246:tid 229429] [client 74.249.245.134:17443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/m.php"] [unique_id "al9JoiBMYeh5YLVG45x_MAAAAkk"]
[Tue Jul 21 07:27:46.679312 2026] [autoindex:error] [pid 229246:tid 229383] [client 20.104.96.117:62913] AH01276: Cannot serve directory /home4/forev309/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:46.809901 2026] [security2:error] [pid 229246:tid 229471] [client 103.174.34.15:64515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JoiBMYeh5YLVG45x_MgAAAnM"]
[Tue Jul 21 07:27:46.810044 2026] [security2:error] [pid 229246:tid 229471] [client 103.174.34.15:64515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JoiBMYeh5YLVG45x_MgAAAnM"]
[Tue Jul 21 07:27:47.028725 2026] [security2:error] [pid 230252:tid 230478] [client 109.248.148.246:39716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZswAAAvc"]
[Tue Jul 21 07:27:47.028834 2026] [security2:error] [pid 230252:tid 230478] [client 109.248.148.246:39716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZswAAAvc"]
[Tue Jul 21 07:27:47.040731 2026] [autoindex:error] [pid 229246:tid 229392] [client 20.104.96.117:62913] AH01276: Cannot serve directory /home4/forev309/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:47.128477 2026] [security2:error] [pid 230252:tid 230434] [client 20.220.225.223:53500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/phpinfo.php1"] [unique_id "al9Jo00Dwhk5-Z44XrpZtgAAAss"]
[Tue Jul 21 07:27:47.180578 2026] [security2:error] [pid 229246:tid 229379] [client 20.104.96.117:62913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ccc.php"] [unique_id "al9JoyBMYeh5YLVG45x_OAAAAhc"]
[Tue Jul 21 07:27:47.258654 2026] [security2:error] [pid 230252:tid 230425] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Jo00Dwhk5-Z44XrpZtwAAAsI"]
[Tue Jul 21 07:27:47.372515 2026] [security2:error] [pid 229246:tid 229314] [remote 5.182.209.54:48610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JoyBMYeh5YLVG45x_OwACjUM"]
[Tue Jul 21 07:27:47.382274 2026] [security2:error] [pid 230252:tid 230384] [client 45.8.17.132:50505] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/so-pinyin-slugs/inc/main_json.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZugAAApk"]
[Tue Jul 21 07:27:47.433549 2026] [security2:error] [pid 230252:tid 230432] [client 154.192.233.199:60265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZvQAAAsk"]
[Tue Jul 21 07:27:47.433666 2026] [security2:error] [pid 230252:tid 230432] [client 154.192.233.199:60265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZvQAAAsk"]
[Tue Jul 21 07:27:47.437660 2026] [security2:error] [pid 230252:tid 230437] [client 175.45.70.82:55173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZvgAAAs4"]
[Tue Jul 21 07:27:47.437799 2026] [security2:error] [pid 230252:tid 230437] [client 175.45.70.82:55173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZvgAAAs4"]
[Tue Jul 21 07:27:47.655130 2026] [security2:error] [pid 230252:tid 230462] [client 20.151.10.161:48584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/7.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZxAAAAuc"]
[Tue Jul 21 07:27:47.764255 2026] [security2:error] [pid 230252:tid 230398] [client 74.249.245.134:62882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/click.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZyQAAAqc"]
[Tue Jul 21 07:27:47.859543 2026] [security2:error] [pid 230252:tid 230422] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9Jo00Dwhk5-Z44XrpZywAAAr8"]
[Tue Jul 21 07:27:47.862400 2026] [security2:error] [pid 230252:tid 230275] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZzAACyBU"]
[Tue Jul 21 07:27:47.862626 2026] [security2:error] [pid 230252:tid 230431] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZzAACyBU"]
[Tue Jul 21 07:27:47.969084 2026] [security2:error] [pid 230252:tid 230305] [remote 69.63.184.115:47360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.184.63.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZzwACxzM"]
[Tue Jul 21 07:27:47.991269 2026] [security2:error] [pid 230252:tid 230458] [client 20.104.96.117:59799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9Jo00Dwhk5-Z44XrpZ0AAAAuM"]
[Tue Jul 21 07:27:48.132467 2026] [security2:error] [pid 229246:tid 229399] [client 20.104.96.117:62934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/w.php"] [unique_id "al9JpCBMYeh5YLVG45x_RAAAAis"]
[Tue Jul 21 07:27:48.308764 2026] [security2:error] [pid 230252:tid 230448] [client 193.36.225.70:52577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JpE0Dwhk5-Z44XrpZ0QAAAtk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:48.353833 2026] [security2:error] [pid 229246:tid 229478] [client 74.7.228.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "construtoralagodoporto.sbbarrosadvocacia.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9JpCBMYeh5YLVG45x_RwACej0"]
[Tue Jul 21 07:27:48.382686 2026] [security2:error] [pid 229246:tid 229276] [remote 154.61.75.100:44460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-login.php"] [unique_id "al9JpCBMYeh5YLVG45x_SAACGh0"]
[Tue Jul 21 07:27:48.454768 2026] [security2:error] [pid 230252:tid 230394] [client 74.249.245.134:5520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/lv.php"] [unique_id "al9JpE0Dwhk5-Z44XrpZ1wAAAqM"]
[Tue Jul 21 07:27:48.472974 2026] [security2:error] [pid 229246:tid 229454] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9JpCBMYeh5YLVG45x_SgAAAmI"]
[Tue Jul 21 07:27:48.488175 2026] [security2:error] [pid 229246:tid 229431] [client 45.8.17.118:65087] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/assets/"] [unique_id "al9JpCBMYeh5YLVG45x_SwAAAks"]
[Tue Jul 21 07:27:48.713845 2026] [security2:error] [pid 230252:tid 230329] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JpE0Dwhk5-Z44XrpZ3AAC_Eo"]
[Tue Jul 21 07:27:48.714096 2026] [security2:error] [pid 230252:tid 230483] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JpE0Dwhk5-Z44XrpZ3AAC_Eo"]
[Tue Jul 21 07:27:48.914586 2026] [autoindex:error] [pid 230252:tid 230315] [remote 74.7.227.173:0] AH01276: Cannot serve directory /home1/sbbarr09/construtoralagodoporto.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:49.078941 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:64055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9JpU0Dwhk5-Z44XrpZ5AAAAsI"]
[Tue Jul 21 07:27:49.093615 2026] [security2:error] [pid 230252:tid 230423] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9JpU0Dwhk5-Z44XrpZ5QAAAsA"]
[Tue Jul 21 07:27:49.172514 2026] [security2:error] [pid 230252:tid 230387] [client 109.248.148.246:37226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JpU0Dwhk5-Z44XrpZ5gAAApw"]
[Tue Jul 21 07:27:49.172614 2026] [security2:error] [pid 230252:tid 230387] [client 109.248.148.246:37226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9JpU0Dwhk5-Z44XrpZ5gAAApw"]
[Tue Jul 21 07:27:49.229550 2026] [security2:error] [pid 229246:tid 229398] [client 103.162.129.114:63496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JpSBMYeh5YLVG45x_UgAAAio"]
[Tue Jul 21 07:27:49.229756 2026] [security2:error] [pid 229246:tid 229398] [client 103.162.129.114:63496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JpSBMYeh5YLVG45x_UgAAAio"]
[Tue Jul 21 07:27:49.260885 2026] [security2:error] [pid 229246:tid 229455] [client 74.249.245.134:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/cong.php"] [unique_id "al9JpSBMYeh5YLVG45x_UwAAAmM"]
[Tue Jul 21 07:27:49.569865 2026] [security2:error] [pid 229246:tid 229500] [client 20.151.10.161:48577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/8.php"] [unique_id "al9JpSBMYeh5YLVG45x_WQAAApA"]
[Tue Jul 21 07:27:49.597066 2026] [security2:error] [pid 229246:tid 229410] [client 20.104.96.117:64037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/FWAZ.php"] [unique_id "al9JpSBMYeh5YLVG45x_WgAAAjY"]
[Tue Jul 21 07:27:49.717535 2026] [security2:error] [pid 230252:tid 230392] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9JpU0Dwhk5-Z44XrpZ8gAAAqE"]
[Tue Jul 21 07:27:49.766808 2026] [security2:error] [pid 230252:tid 230391] [client 74.249.245.134:54363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/brand.php"] [unique_id "al9JpU0Dwhk5-Z44XrpZ9AAAAqA"]
[Tue Jul 21 07:27:49.890274 2026] [security2:error] [pid 229246:tid 229503] [client 45.8.17.108:60315] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/hello.php"] [unique_id "al9JpSBMYeh5YLVG45x_XQAAApM"]
[Tue Jul 21 07:27:49.923506 2026] [access_compat:error] [pid 229246:tid 229437] [client 162.241.63.68:16052] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:27:49.979907 2026] [security2:error] [pid 229246:tid 229495] [client 20.220.225.223:38665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/red.php"] [unique_id "al9JpSBMYeh5YLVG45x_YgAAAos"]
[Tue Jul 21 07:27:50.100887 2026] [security2:error] [pid 230252:tid 230448] [client 20.104.96.117:62921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/miru1.php"] [unique_id "al9Jpk0Dwhk5-Z44XrpaDgAAAtk"]
[Tue Jul 21 07:27:50.298704 2026] [security2:error] [pid 230252:tid 230477] [client 74.249.245.134:54396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/atomlib.php"] [unique_id "al9Jpk0Dwhk5-Z44XrpaEgAAAvY"]
[Tue Jul 21 07:27:50.326191 2026] [security2:error] [pid 229246:tid 229388] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9JpiBMYeh5YLVG45x_ZAAAAiA"]
[Tue Jul 21 07:27:50.489101 2026] [security2:error] [pid 229246:tid 229457] [client 20.104.96.117:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/aa.php"] [unique_id "al9JpiBMYeh5YLVG45x_bQAAAmU"]
[Tue Jul 21 07:27:50.602485 2026] [security2:error] [pid 229246:tid 229349] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JpiBMYeh5YLVG45x_bwACL2Y"]
[Tue Jul 21 07:27:50.602603 2026] [security2:error] [pid 229246:tid 229403] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JpiBMYeh5YLVG45x_bwACL2Y"]
[Tue Jul 21 07:27:50.756776 2026] [security2:error] [pid 229246:tid 229481] [client 74.249.245.134:62855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/0x.php"] [unique_id "al9JpiBMYeh5YLVG45x_cAAAAn0"]
[Tue Jul 21 07:27:50.802766 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:62973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/122.php"] [unique_id "al9Jpk0Dwhk5-Z44XrpaFQAAAuQ"]
[Tue Jul 21 07:27:51.152143 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:64032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/get.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaJwAAAsI"]
[Tue Jul 21 07:27:51.191492 2026] [security2:error] [pid 230252:tid 230423] [client 45.8.17.57:44371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/maint/"] [unique_id "al9Jp00Dwhk5-Z44XrpaKAAAAsA"]
[Tue Jul 21 07:27:51.312469 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:49151] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.tempex.com.br"] [uri "/1.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaKQAAAwY"]
[Tue Jul 21 07:27:51.312593 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:49151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/1.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaKQAAAwY"]
[Tue Jul 21 07:27:51.338827 2026] [security2:error] [pid 230252:tid 230461] [client 20.104.96.117:42390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/qqqa.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaKgAAAuY"]
[Tue Jul 21 07:27:51.455509 2026] [security2:error] [pid 230252:tid 230444] [client 74.249.245.134:17465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/buy.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaLAAAAtU"]
[Tue Jul 21 07:27:51.455523 2026] [security2:error] [pid 230252:tid 230508] [client 20.104.96.117:64042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/as.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaLQAAAxU"]
[Tue Jul 21 07:27:51.780472 2026] [security2:error] [pid 230252:tid 230427] [client 20.104.96.117:5115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ccou.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaMAAAAsQ"]
[Tue Jul 21 07:27:51.939124 2026] [security2:error] [pid 230252:tid 230417] [client 213.152.162.104:58510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaNAAAAro"]
[Tue Jul 21 07:27:51.939208 2026] [security2:error] [pid 230252:tid 230417] [client 213.152.162.104:58510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Jp00Dwhk5-Z44XrpaNAAAAro"]
[Tue Jul 21 07:27:52.119638 2026] [security2:error] [pid 229246:tid 229416] [client 20.104.96.117:4257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/w3lls.php"] [unique_id "al9JqCBMYeh5YLVG45x_ggAAAjw"]
[Tue Jul 21 07:27:52.184824 2026] [security2:error] [pid 229246:tid 229398] [client 45.8.17.129:50145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wordpress/wp-admin/maint/"] [unique_id "al9JqCBMYeh5YLVG45x_hAAAAio"]
[Tue Jul 21 07:27:52.385561 2026] [security2:error] [pid 230252:tid 230436] [client 139.135.44.145:54393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JqE0Dwhk5-Z44XrpaNwAAAs0"]
[Tue Jul 21 07:27:52.385672 2026] [security2:error] [pid 230252:tid 230436] [client 139.135.44.145:54393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JqE0Dwhk5-Z44XrpaNwAAAs0"]
[Tue Jul 21 07:27:52.532159 2026] [security2:error] [pid 229246:tid 229477] [client 74.249.245.134:5546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/sx.php"] [unique_id "al9JqCBMYeh5YLVG45x_igAAAnk"]
[Tue Jul 21 07:27:52.532615 2026] [security2:error] [pid 230252:tid 230499] [client 20.104.96.117:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/test1.php"] [unique_id "al9JqE0Dwhk5-Z44XrpaOQAAAww"]
[Tue Jul 21 07:27:53.090371 2026] [security2:error] [pid 229246:tid 229489] [client 20.104.96.117:5064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/database.php"] [unique_id "al9JqSBMYeh5YLVG45x_lAAAAoU"]
[Tue Jul 21 07:27:53.220430 2026] [security2:error] [pid 230252:tid 230464] [client 117.251.86.144:43774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaQgAAAuk"]
[Tue Jul 21 07:27:53.220601 2026] [security2:error] [pid 230252:tid 230464] [client 117.251.86.144:43774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaQgAAAuk"]
[Tue Jul 21 07:27:53.256579 2026] [security2:error] [pid 230252:tid 230438] [client 20.104.96.117:59791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/aunmc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaRAAAAs8"]
[Tue Jul 21 07:27:53.442586 2026] [security2:error] [pid 230252:tid 230469] [client 152.59.154.239:51700] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JqE0Dwhk5-Z44XrpaNgAAAu4"]
[Tue Jul 21 07:27:53.443154 2026] [security2:error] [pid 230252:tid 230469] [client 152.59.154.239:51700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JqE0Dwhk5-Z44XrpaNgAAAu4"]
[Tue Jul 21 07:27:53.443766 2026] [security2:error] [pid 230252:tid 230459] [client 109.248.148.246:40158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaSAAAAuQ"]
[Tue Jul 21 07:27:53.443941 2026] [security2:error] [pid 230252:tid 230459] [client 109.248.148.246:40158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaSAAAAuQ"]
[Tue Jul 21 07:27:53.541900 2026] [security2:error] [pid 230252:tid 230407] [client 20.104.96.117:64023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/file.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaSgAAArA"]
[Tue Jul 21 07:27:53.782921 2026] [security2:error] [pid 229246:tid 229407] [client 45.8.17.125:57791] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "al9JqSBMYeh5YLVG45x_nwAAAjM"]
[Tue Jul 21 07:27:53.871182 2026] [security2:error] [pid 230252:tid 230446] [client 45.251.232.145:52208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaTAAAAtc"]
[Tue Jul 21 07:27:53.871316 2026] [security2:error] [pid 230252:tid 230446] [client 45.251.232.145:52208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaTAAAAtc"]
[Tue Jul 21 07:27:53.978377 2026] [security2:error] [pid 230252:tid 230363] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaTQAComw"]
[Tue Jul 21 07:27:53.978529 2026] [security2:error] [pid 230252:tid 230393] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaTQAComw"]
[Tue Jul 21 07:27:53.989636 2026] [security2:error] [pid 229246:tid 229459] [client 20.104.96.117:64043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/file.php"] [unique_id "al9JqSBMYeh5YLVG45x_oQAAAmc"]
[Tue Jul 21 07:27:54.007677 2026] [security2:error] [pid 230252:tid 230478] [client 20.151.10.161:49131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/100.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaTgAAAvc"]
[Tue Jul 21 07:27:54.266328 2026] [autoindex:error] [pid 230252:tid 230435] [client 71.6.134.231:39348] AH01276: Cannot serve directory /home2/uaudis29/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:27:54.393162 2026] [security2:error] [pid 230252:tid 230424] [client 59.96.220.140:163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaUwAAAsE"]
[Tue Jul 21 07:27:54.393279 2026] [security2:error] [pid 230252:tid 230424] [client 59.96.220.140:163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaUwAAAsE"]
[Tue Jul 21 07:27:54.402849 2026] [security2:error] [pid 229246:tid 229483] [client 20.104.96.117:62927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/777.php"] [unique_id "al9JqiBMYeh5YLVG45x_qAAAAn8"]
[Tue Jul 21 07:27:54.420087 2026] [security2:error] [pid 230252:tid 230423] [client 74.249.245.134:17454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/article.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaVAAAAsA"]
[Tue Jul 21 07:27:54.462186 2026] [security2:error] [pid 229246:tid 229451] [client 20.52.136.55:1538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/edit.php"] [unique_id "al9JqiBMYeh5YLVG45x_qgAAAl8"]
[Tue Jul 21 07:27:54.508399 2026] [security2:error] [pid 230252:tid 230384] [client 213.152.162.104:43922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaVwAAApk"]
[Tue Jul 21 07:27:54.508523 2026] [security2:error] [pid 230252:tid 230384] [client 213.152.162.104:43922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaVwAAApk"]
[Tue Jul 21 07:27:54.817827 2026] [security2:error] [pid 230252:tid 230426] [client 20.104.96.117:62917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ssixta.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaWwAAAsM"]
[Tue Jul 21 07:27:54.892357 2026] [security2:error] [pid 230252:tid 230462] [client 20.151.10.161:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/about.php"] [unique_id "al9Jqk0Dwhk5-Z44XrpaXwAAAuc"]
[Tue Jul 21 07:27:55.195489 2026] [security2:error] [pid 230252:tid 230479] [client 45.8.17.61:65439] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "al9Jq00Dwhk5-Z44XrpaZwAAAvg"]
[Tue Jul 21 07:27:55.263911 2026] [security2:error] [pid 230252:tid 230460] [client 20.104.96.117:59785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/uoocf.php"] [unique_id "al9Jq00Dwhk5-Z44XrpaaAAAAuU"]
[Tue Jul 21 07:27:55.299900 2026] [security2:error] [pid 230252:tid 230503] [client 20.104.96.117:64033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/1c.php"] [unique_id "al9Jq00Dwhk5-Z44XrpaagAAAxA"]
[Tue Jul 21 07:27:55.634145 2026] [security2:error] [pid 230252:tid 230443] [client 193.36.225.66:53307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JqU0Dwhk5-Z44XrpaRQAAAtQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:27:55.713614 2026] [security2:error] [pid 230252:tid 230394] [client 20.151.10.161:48589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/admin.php"] [unique_id "al9Jq00Dwhk5-Z44XrpabwAAAqM"]
[Tue Jul 21 07:27:55.716820 2026] [security2:error] [pid 229246:tid 229329] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JqyBMYeh5YLVG45x_uwACMVI"]
[Tue Jul 21 07:27:55.717056 2026] [security2:error] [pid 229246:tid 229405] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JqyBMYeh5YLVG45x_uwACMVI"]
[Tue Jul 21 07:27:56.180762 2026] [security2:error] [pid 230252:tid 230482] [client 20.104.96.117:62925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/test2.php"] [unique_id "al9JrE0Dwhk5-Z44XrpadgAAAvs"]
[Tue Jul 21 07:27:56.257564 2026] [security2:error] [pid 230252:tid 230478] [client 20.151.10.161:49044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/edit.php"] [unique_id "al9JrE0Dwhk5-Z44XrpaewAAAvc"]
[Tue Jul 21 07:27:56.449653 2026] [security2:error] [pid 230252:tid 230297] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JrE0Dwhk5-Z44XrpaggACqSs"]
[Tue Jul 21 07:27:56.449936 2026] [security2:error] [pid 230252:tid 230400] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JrE0Dwhk5-Z44XrpaggACqSs"]
[Tue Jul 21 07:27:56.455607 2026] [security2:error] [pid 230252:tid 230494] [client 103.106.20.201:52554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JrE0Dwhk5-Z44XrpagwAAAwc"]
[Tue Jul 21 07:27:56.455773 2026] [security2:error] [pid 230252:tid 230494] [client 103.106.20.201:52554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JrE0Dwhk5-Z44XrpagwAAAwc"]
[Tue Jul 21 07:27:56.479614 2026] [security2:error] [pid 230252:tid 230493] [client 45.8.17.64:29699] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/edit.php"] [unique_id "al9JrE0Dwhk5-Z44XrpahAAAAwY"]
[Tue Jul 21 07:27:56.559052 2026] [security2:error] [pid 230252:tid 230381] [remote 51.222.168.241:30344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "jurencosmetics.com"] [uri "/product/richee-nanobtx-repair-mass-replenisher-macadamia-oil-2x-1kg/feed/"] [unique_id "al9JrE0Dwhk5-Z44XrpahQACwH4"]
[Tue Jul 21 07:27:56.559221 2026] [security2:error] [pid 230252:tid 230423] [client 51.222.168.241:30344] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jurencosmetics.com"] [uri "/product/richee-nanobtx-repair-mass-replenisher-macadamia-oil-2x-1kg/feed/"] [unique_id "al9JrE0Dwhk5-Z44XrpahQACwH4"]
[Tue Jul 21 07:27:56.589056 2026] [security2:error] [pid 230252:tid 230474] [client 74.249.245.134:5509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/bootstrap.php"] [unique_id "al9JrE0Dwhk5-Z44XrpahgAAAvM"]
[Tue Jul 21 07:27:56.764571 2026] [security2:error] [pid 230252:tid 230386] [client 20.104.96.117:59642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/iywwi.php"] [unique_id "al9JrE0Dwhk5-Z44XrpaiQAAAps"]
[Tue Jul 21 07:27:57.148061 2026] [security2:error] [pid 230252:tid 230256] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JrU0Dwhk5-Z44XrpaiwAC8AI"]
[Tue Jul 21 07:27:57.148261 2026] [security2:error] [pid 230252:tid 230471] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JrU0Dwhk5-Z44XrpaiwAC8AI"]
[Tue Jul 21 07:27:57.279755 2026] [security2:error] [pid 230252:tid 230405] [client 20.104.96.117:64041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/buy.php"] [unique_id "al9JrU0Dwhk5-Z44XrpajAAAAq4"]
[Tue Jul 21 07:27:57.290545 2026] [security2:error] [pid 229246:tid 229447] [client 45.8.17.128:25527] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/archives/"] [unique_id "al9JrSBMYeh5YLVG45x_zwAAAls"]
[Tue Jul 21 07:27:57.432111 2026] [security2:error] [pid 230252:tid 230507] [client 20.151.10.161:48616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9JrU0Dwhk5-Z44XrpajQAAAxQ"]
[Tue Jul 21 07:27:57.515992 2026] [security2:error] [pid 230252:tid 230511] [client 20.104.96.117:59784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/gqgsa.php"] [unique_id "al9JrU0Dwhk5-Z44XrpajgAAAxg"]
[Tue Jul 21 07:27:57.556629 2026] [security2:error] [pid 230252:tid 230436] [client 103.174.34.15:65009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JrU0Dwhk5-Z44XrpajwAAAs0"]
[Tue Jul 21 07:27:57.556747 2026] [security2:error] [pid 230252:tid 230436] [client 103.174.34.15:65009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JrU0Dwhk5-Z44XrpajwAAAs0"]
[Tue Jul 21 07:27:57.588198 2026] [security2:error] [pid 229246:tid 229499] [client 109.248.148.246:40170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JrSBMYeh5YLVG45x_0wAAAo8"]
[Tue Jul 21 07:27:57.588282 2026] [security2:error] [pid 229246:tid 229499] [client 109.248.148.246:40170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JrSBMYeh5YLVG45x_0wAAAo8"]
[Tue Jul 21 07:27:58.116486 2026] [security2:error] [pid 229246:tid 229412] [client 175.45.70.82:55689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JriBMYeh5YLVG45x_4AAAAjg"]
[Tue Jul 21 07:27:58.116607 2026] [security2:error] [pid 229246:tid 229412] [client 175.45.70.82:55689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JriBMYeh5YLVG45x_4AAAAjg"]
[Tue Jul 21 07:27:58.133200 2026] [security2:error] [pid 229246:tid 229450] [client 154.192.233.199:59825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JriBMYeh5YLVG45x_4QAAAl4"]
[Tue Jul 21 07:27:58.133347 2026] [security2:error] [pid 229246:tid 229450] [client 154.192.233.199:59825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JriBMYeh5YLVG45x_4QAAAl4"]
[Tue Jul 21 07:27:58.308123 2026] [security2:error] [pid 230252:tid 230389] [client 20.151.10.161:49102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/f6.php"] [unique_id "al9Jrk0Dwhk5-Z44XrpamwAAAp4"]
[Tue Jul 21 07:27:58.402280 2026] [security2:error] [pid 230252:tid 230350] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Jrk0Dwhk5-Z44XrpanQACo18"]
[Tue Jul 21 07:27:58.402467 2026] [security2:error] [pid 230252:tid 230394] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Jrk0Dwhk5-Z44XrpanQACo18"]
[Tue Jul 21 07:27:58.599203 2026] [security2:error] [pid 229246:tid 229456] [client 45.8.17.118:57269] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/"] [unique_id "al9JriBMYeh5YLVG45x_6QAAAmQ"]
[Tue Jul 21 07:27:58.907319 2026] [security2:error] [pid 230252:tid 230491] [client 20.104.96.117:59618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/elbzl.php"] [unique_id "al9Jrk0Dwhk5-Z44XrpaowAAAwQ"]
[Tue Jul 21 07:27:59.201040 2026] [security2:error] [pid 230252:tid 230463] [client 82.102.28.107:39932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpaqAAAAug"]
[Tue Jul 21 07:27:59.201154 2026] [security2:error] [pid 230252:tid 230463] [client 82.102.28.107:39932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpaqAAAAug"]
[Tue Jul 21 07:27:59.230969 2026] [security2:error] [pid 230252:tid 230280] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpaqQACqRo"]
[Tue Jul 21 07:27:59.231149 2026] [security2:error] [pid 230252:tid 230400] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpaqQACqRo"]
[Tue Jul 21 07:27:59.281442 2026] [security2:error] [pid 230252:tid 230487] [client 182.9.35.66:9362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.35.9.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giliniservices.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpaqgAAAwA"]
[Tue Jul 21 07:27:59.281609 2026] [security2:error] [pid 230252:tid 230487] [client 182.9.35.66:9362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "giliniservices.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpaqgAAAwA"]
[Tue Jul 21 07:27:59.399051 2026] [security2:error] [pid 230252:tid 230467] [client 20.104.96.117:62943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ssend.php"] [unique_id "al9Jr00Dwhk5-Z44XrpargAAAuw"]
[Tue Jul 21 07:27:59.464501 2026] [security2:error] [pid 230252:tid 230427] [client 20.104.96.117:59627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/adjig.php"] [unique_id "al9Jr00Dwhk5-Z44XrpasAAAAsQ"]
[Tue Jul 21 07:27:59.582623 2026] [security2:error] [pid 230252:tid 230473] [client 45.8.17.148:56255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/x.php"] [unique_id "al9Jr00Dwhk5-Z44XrpatAAAAvI"]
[Tue Jul 21 07:27:59.614046 2026] [security2:error] [pid 230252:tid 230401] [client 20.151.10.161:49130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/inputs.php"] [unique_id "al9Jr00Dwhk5-Z44XrpatgAAAqo"]
[Tue Jul 21 07:27:59.636535 2026] [security2:error] [pid 230252:tid 230385] [client 20.220.225.223:38710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/fffm.php"] [unique_id "al9Jr00Dwhk5-Z44XrpauAAAApo"]
[Tue Jul 21 07:27:59.710233 2026] [security2:error] [pid 230252:tid 230455] [client 103.162.129.114:63936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpavAAAAuA"]
[Tue Jul 21 07:27:59.710381 2026] [security2:error] [pid 230252:tid 230455] [client 103.162.129.114:63936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Jr00Dwhk5-Z44XrpavAAAAuA"]
[Tue Jul 21 07:28:00.134682 2026] [security2:error] [pid 230252:tid 230443] [client 20.104.96.117:59783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/byp.php"] [unique_id "al9JsE0Dwhk5-Z44XrpaxQAAAtQ"]
[Tue Jul 21 07:28:00.408870 2026] [security2:error] [pid 230252:tid 230445] [client 136.144.33.29:48215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JsE0Dwhk5-Z44XrpaxgAAAtY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:00.474879 2026] [security2:error] [pid 230252:tid 230466] [client 213.152.162.104:39054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JsE0Dwhk5-Z44XrpaygAAAus"]
[Tue Jul 21 07:28:00.474978 2026] [security2:error] [pid 230252:tid 230466] [client 213.152.162.104:39054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JsE0Dwhk5-Z44XrpaygAAAus"]
[Tue Jul 21 07:28:00.490157 2026] [security2:error] [pid 230252:tid 230357] [remote 173.252.95.3:38258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9JsE0Dwhk5-Z44XrpaywAC-mY"]
[Tue Jul 21 07:28:00.630170 2026] [security2:error] [pid 230252:tid 230435] [client 20.151.10.161:49140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/av.php"] [unique_id "al9JsE0Dwhk5-Z44XrpazwAAAsw"]
[Tue Jul 21 07:28:00.670204 2026] [security2:error] [pid 230252:tid 230475] [client 20.104.96.117:59607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9JsE0Dwhk5-Z44Xrpa0AAAAvQ"]
[Tue Jul 21 07:28:00.889243 2026] [security2:error] [pid 230252:tid 230384] [client 45.8.17.122:28315] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "al9JsE0Dwhk5-Z44Xrpa0gAAApk"]
[Tue Jul 21 07:28:01.118979 2026] [security2:error] [pid 230252:tid 230415] [client 20.104.96.117:64062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/item.php"] [unique_id "al9JsU0Dwhk5-Z44Xrpa1AAAArg"]
[Tue Jul 21 07:28:01.235619 2026] [security2:error] [pid 230252:tid 230271] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JsU0Dwhk5-Z44Xrpa1QACwxE"]
[Tue Jul 21 07:28:01.235752 2026] [security2:error] [pid 230252:tid 230426] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JsU0Dwhk5-Z44Xrpa1QACwxE"]
[Tue Jul 21 07:28:01.304942 2026] [security2:error] [pid 230252:tid 230430] [client 20.197.195.24:12386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JsU0Dwhk5-Z44Xrpa2AAAAsc"]
[Tue Jul 21 07:28:01.333101 2026] [security2:error] [pid 230252:tid 230453] [client 74.249.245.134:5557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/config-backup.php"] [unique_id "al9JsU0Dwhk5-Z44Xrpa2wAAAt4"]
[Tue Jul 21 07:28:01.795720 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:59612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/classwithtostring.php"] [unique_id "al9JsU0Dwhk5-Z44Xrpa4wAAAtM"]
[Tue Jul 21 07:28:02.000053 2026] [security2:error] [pid 229246:tid 229474] [client 45.8.17.105:54773] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/light/"] [unique_id "al9JsSBMYeh5YLVG45yACwAAAnY"]
[Tue Jul 21 07:28:02.186399 2026] [security2:error] [pid 230252:tid 230443] [client 20.104.96.117:5090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ss.php"] [unique_id "al9Jsk0Dwhk5-Z44Xrpa5gAAAtQ"]
[Tue Jul 21 07:28:02.449419 2026] [security2:error] [pid 230252:tid 230485] [client 159.69.158.189:53516] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9Jsk0Dwhk5-Z44Xrpa6wAAAv4"], referer: https://artetoner.com.br
[Tue Jul 21 07:28:02.671770 2026] [security2:error] [pid 229246:tid 229359] [remote 104.207.56.32:24889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.56.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9JsiBMYeh5YLVG45yAEQACe3A"]
[Tue Jul 21 07:28:02.992801 2026] [security2:error] [pid 229246:tid 229379] [client 45.8.17.110:47869] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin.php"] [unique_id "al9JsiBMYeh5YLVG45yAFwAAAhc"]
[Tue Jul 21 07:28:03.309099 2026] [security2:error] [pid 229246:tid 229403] [client 20.220.225.223:31109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/ftde.php"] [unique_id "al9JsyBMYeh5YLVG45yAHQAAAi8"]
[Tue Jul 21 07:28:03.374208 2026] [security2:error] [pid 230252:tid 230452] [client 139.135.44.145:53310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Js00Dwhk5-Z44Xrpa9AAAAt0"]
[Tue Jul 21 07:28:03.374374 2026] [security2:error] [pid 230252:tid 230452] [client 139.135.44.145:53310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Js00Dwhk5-Z44Xrpa9AAAAt0"]
[Tue Jul 21 07:28:03.395486 2026] [security2:error] [pid 229246:tid 229459] [client 20.220.225.223:62115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9JsyBMYeh5YLVG45yAHgAAAmc"]
[Tue Jul 21 07:28:03.399231 2026] [security2:error] [pid 229246:tid 229466] [client 20.104.96.117:59591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/root.php"] [unique_id "al9JsyBMYeh5YLVG45yAHwAAAm4"]
[Tue Jul 21 07:28:03.553976 2026] [security2:error] [pid 229246:tid 229481] [client 20.52.136.55:1570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/166.php"] [unique_id "al9JsyBMYeh5YLVG45yAIAAAAn0"]
[Tue Jul 21 07:28:03.642952 2026] [security2:error] [pid 229246:tid 229460] [client 152.59.154.239:52127] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JsyBMYeh5YLVG45yAJgAAAmg"]
[Tue Jul 21 07:28:03.643063 2026] [security2:error] [pid 229246:tid 229460] [client 152.59.154.239:52127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JsyBMYeh5YLVG45yAJgAAAmg"]
[Tue Jul 21 07:28:03.753740 2026] [security2:error] [pid 230252:tid 230384] [client 20.151.10.161:49111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Js00Dwhk5-Z44Xrpa9wAAApk"]
[Tue Jul 21 07:28:03.995047 2026] [security2:error] [pid 230252:tid 230493] [client 45.8.17.116:41129] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wa/"] [unique_id "al9Js00Dwhk5-Z44Xrpa-AAAAwY"]
[Tue Jul 21 07:28:04.154200 2026] [security2:error] [pid 229246:tid 229425] [client 117.251.86.144:56154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JtCBMYeh5YLVG45yAKQAAAkU"]
[Tue Jul 21 07:28:04.154320 2026] [security2:error] [pid 229246:tid 229425] [client 117.251.86.144:56154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JtCBMYeh5YLVG45yAKQAAAkU"]
[Tue Jul 21 07:28:04.219581 2026] [autoindex:error] [pid 230252:tid 230398] [client 43.134.38.171:51802] AH01276: Cannot serve directory /home3/lianem44/ubaloc.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:04.424474 2026] [security2:error] [pid 230252:tid 230400] [client 45.251.232.145:52731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JtE0Dwhk5-Z44Xrpa_gAAAqk"]
[Tue Jul 21 07:28:04.424609 2026] [security2:error] [pid 230252:tid 230400] [client 45.251.232.145:52731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JtE0Dwhk5-Z44Xrpa_gAAAqk"]
[Tue Jul 21 07:28:04.451118 2026] [security2:error] [pid 230252:tid 230484] [client 20.104.96.117:62953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/hypo.php"] [unique_id "al9JtE0Dwhk5-Z44Xrpa_wAAAv0"]
[Tue Jul 21 07:28:04.519593 2026] [security2:error] [pid 230252:tid 230311] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JtE0Dwhk5-Z44XrpbAQACqjk"]
[Tue Jul 21 07:28:04.519776 2026] [security2:error] [pid 230252:tid 230401] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JtE0Dwhk5-Z44XrpbAQACqjk"]
[Tue Jul 21 07:28:04.611940 2026] [security2:error] [pid 230252:tid 230405] [client 20.220.225.223:38711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/yup.php"] [unique_id "al9JtE0Dwhk5-Z44XrpbAgAAAq4"]
[Tue Jul 21 07:28:04.619822 2026] [security2:error] [pid 230252:tid 230373] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/api/.env"] [unique_id "al9JtE0Dwhk5-Z44XrpbAwADCHY"]
[Tue Jul 21 07:28:04.635014 2026] [security2:error] [pid 230252:tid 230295] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/member/.env"] [unique_id "al9JtE0Dwhk5-Z44XrpbBAACoSk"]
[Tue Jul 21 07:28:04.635062 2026] [security2:error] [pid 230252:tid 230303] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/bank/.env"] [unique_id "al9JtE0Dwhk5-Z44XrpbBQACzTE"]
[Tue Jul 21 07:28:04.644165 2026] [security2:error] [pid 230252:tid 230286] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/backend/.env"] [unique_id "al9JtE0Dwhk5-Z44XrpbBwACvSA"]
[Tue Jul 21 07:28:04.742144 2026] [security2:error] [pid 230252:tid 230293] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/new/.env"] [unique_id "al9JtE0Dwhk5-Z44XrpbDAACuic"]
[Tue Jul 21 07:28:05.000847 2026] [security2:error] [pid 230252:tid 230397] [client 20.197.195.24:12406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9JtU0Dwhk5-Z44XrpbEQAAAqY"]
[Tue Jul 21 07:28:05.285637 2026] [security2:error] [pid 230252:tid 230466] [client 45.8.17.113:43343] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-file.php"] [unique_id "al9JtU0Dwhk5-Z44XrpbFwAAAus"]
[Tue Jul 21 07:28:05.336223 2026] [security2:error] [pid 230252:tid 230501] [client 20.151.10.161:49135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9JtU0Dwhk5-Z44XrpbGAAAAw4"]
[Tue Jul 21 07:28:05.441518 2026] [security2:error] [pid 230252:tid 230322] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/core/.env"] [unique_id "al9JtU0Dwhk5-Z44XrpbGQAC4UQ"]
[Tue Jul 21 07:28:05.830522 2026] [security2:error] [pid 230252:tid 230384] [client 109.248.148.246:42494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JtU0Dwhk5-Z44XrpbHgAAApk"]
[Tue Jul 21 07:28:05.830626 2026] [security2:error] [pid 230252:tid 230384] [client 109.248.148.246:42494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9JtU0Dwhk5-Z44XrpbHgAAApk"]
[Tue Jul 21 07:28:05.834596 2026] [security2:error] [pid 230252:tid 230259] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/.env"] [unique_id "al9JtU0Dwhk5-Z44XrpbHwAC7wU"]
[Tue Jul 21 07:28:06.074915 2026] [security2:error] [pid 229246:tid 229438] [client 20.104.96.117:64058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/users.php"] [unique_id "al9JtiBMYeh5YLVG45yAOAAAAlI"]
[Tue Jul 21 07:28:06.079465 2026] [security2:error] [pid 230252:tid 230426] [client 20.197.195.24:12365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/media.php"] [unique_id "al9Jtk0Dwhk5-Z44XrpbJAAAAsM"]
[Tue Jul 21 07:28:06.142388 2026] [security2:error] [pid 230252:tid 230262] [remote 103.221.220.62:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "androapkmod.com"] [uri "/app/.env"] [unique_id "al9Jtk0Dwhk5-Z44XrpbJQACrQg"]
[Tue Jul 21 07:28:06.259252 2026] [security2:error] [pid 230252:tid 230347] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Jtk0Dwhk5-Z44XrpbKAACm1w"]
[Tue Jul 21 07:28:06.259441 2026] [security2:error] [pid 230252:tid 230386] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Jtk0Dwhk5-Z44XrpbKAACm1w"]
[Tue Jul 21 07:28:06.385190 2026] [security2:error] [pid 229246:tid 229418] [client 45.8.17.127:50705] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/info.php"] [unique_id "al9JtiBMYeh5YLVG45yAPQAAAj4"]
[Tue Jul 21 07:28:06.706669 2026] [security2:error] [pid 230252:tid 230436] [client 20.151.10.161:49079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-blog.php"] [unique_id "al9Jtk0Dwhk5-Z44XrpbMAAAAs0"]
[Tue Jul 21 07:28:06.773315 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:59786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/sym403.php"] [unique_id "al9Jtk0Dwhk5-Z44XrpbMwAAAuk"]
[Tue Jul 21 07:28:07.039826 2026] [security2:error] [pid 230252:tid 230451] [client 59.96.220.140:49605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Jt00Dwhk5-Z44XrpbOAAAAtw"]
[Tue Jul 21 07:28:07.040026 2026] [security2:error] [pid 230252:tid 230451] [client 59.96.220.140:49605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Jt00Dwhk5-Z44XrpbOAAAAtw"]
[Tue Jul 21 07:28:07.121866 2026] [security2:error] [pid 229246:tid 229484] [client 74.249.245.134:62884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/goods.php"] [unique_id "al9JtyBMYeh5YLVG45yAQwAAAoA"]
[Tue Jul 21 07:28:07.181089 2026] [security2:error] [pid 229246:tid 229385] [client 103.106.20.201:53119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JtyBMYeh5YLVG45yARQAAAh0"]
[Tue Jul 21 07:28:07.181230 2026] [security2:error] [pid 229246:tid 229385] [client 103.106.20.201:53119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JtyBMYeh5YLVG45yARQAAAh0"]
[Tue Jul 21 07:28:07.202112 2026] [security2:error] [pid 229246:tid 229408] [client 20.220.225.223:38690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/jj.php"] [unique_id "al9JtyBMYeh5YLVG45yARgAAAjQ"]
[Tue Jul 21 07:28:07.212956 2026] [proxy:error] [pid 230252:tid 230438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:07.213022 2026] [proxy_http:error] [pid 230252:tid 230438] [client 20.151.10.161:49062] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:07.213660 2026] [proxy:error] [pid 230252:tid 230438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:07.213690 2026] [proxy_http:error] [pid 230252:tid 230438] [client 20.151.10.161:49062] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:07.281512 2026] [security2:error] [pid 230252:tid 230419] [client 45.8.17.63:32745] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/ID3/"] [unique_id "al9Jt00Dwhk5-Z44XrpbQAAAArw"]
[Tue Jul 21 07:28:07.359292 2026] [security2:error] [pid 230252:tid 230275] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jt00Dwhk5-Z44XrpbQgADAxU"]
[Tue Jul 21 07:28:07.359437 2026] [security2:error] [pid 230252:tid 230490] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jt00Dwhk5-Z44XrpbQgADAxU"]
[Tue Jul 21 07:28:07.850576 2026] [security2:error] [pid 230252:tid 230410] [client 20.104.96.117:62970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/177.php"] [unique_id "al9Jt00Dwhk5-Z44XrpbSAAAArM"]
[Tue Jul 21 07:28:08.121942 2026] [security2:error] [pid 230252:tid 230306] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbSgADEzQ"]
[Tue Jul 21 07:28:08.122181 2026] [security2:error] [pid 230252:tid 230506] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbSgADEzQ"]
[Tue Jul 21 07:28:08.258442 2026] [security2:error] [pid 230252:tid 230456] [client 103.174.34.15:65499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbTgAAAuE"]
[Tue Jul 21 07:28:08.258576 2026] [security2:error] [pid 230252:tid 230456] [client 103.174.34.15:65499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbTgAAAuE"]
[Tue Jul 21 07:28:08.337384 2026] [security2:error] [pid 230252:tid 230428] [client 20.151.10.161:49126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbUgAAAsU"]
[Tue Jul 21 07:28:08.389369 2026] [security2:error] [pid 230252:tid 230404] [client 45.8.17.121:44965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/index/function.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbVAAAAq0"]
[Tue Jul 21 07:28:08.405651 2026] [security2:error] [pid 230252:tid 230462] [client 74.249.245.134:5519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/init.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbVQAAAuc"]
[Tue Jul 21 07:28:08.679766 2026] [security2:error] [pid 230252:tid 230367] [remote 20.84.23.223:5448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.23.84.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/wp-login.php"] [unique_id "al9Jt00Dwhk5-Z44XrpbRgADBXA"]
[Tue Jul 21 07:28:08.831736 2026] [security2:error] [pid 230252:tid 230494] [client 154.192.233.199:59149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbWQAAAwc"]
[Tue Jul 21 07:28:08.831882 2026] [security2:error] [pid 230252:tid 230494] [client 154.192.233.199:59149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbWQAAAwc"]
[Tue Jul 21 07:28:08.847319 2026] [security2:error] [pid 230252:tid 230488] [client 175.45.70.82:56205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbWgAAAwE"]
[Tue Jul 21 07:28:08.847439 2026] [security2:error] [pid 230252:tid 230488] [client 175.45.70.82:56205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbWgAAAwE"]
[Tue Jul 21 07:28:08.849784 2026] [security2:error] [pid 230252:tid 230509] [client 20.104.96.117:62940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/config.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbWwAAAxY"]
[Tue Jul 21 07:28:08.938620 2026] [security2:error] [pid 230252:tid 230344] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbXgACtlk"]
[Tue Jul 21 07:28:08.938764 2026] [security2:error] [pid 230252:tid 230413] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JuE0Dwhk5-Z44XrpbXgACtlk"]
[Tue Jul 21 07:28:09.205149 2026] [security2:error] [pid 230252:tid 230455] [client 20.197.195.24:12413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/images.php"] [unique_id "al9JuU0Dwhk5-Z44XrpbYQAAAuA"]
[Tue Jul 21 07:28:09.260622 2026] [security2:error] [pid 230252:tid 230510] [client 20.104.96.117:5109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/gettest.php"] [unique_id "al9JuU0Dwhk5-Z44XrpbYgAAAxc"]
[Tue Jul 21 07:28:09.300923 2026] [security2:error] [pid 229246:tid 229407] [client 136.144.33.98:34455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JuSBMYeh5YLVG45yAXgAAAjM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:09.586844 2026] [security2:error] [pid 230252:tid 230447] [client 45.8.17.147:42883] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/upgrade/"] [unique_id "al9JuU0Dwhk5-Z44XrpbZwAAAtg"]
[Tue Jul 21 07:28:09.667677 2026] [security2:error] [pid 229246:tid 229403] [client 20.104.96.117:62954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/min.php"] [unique_id "al9JuSBMYeh5YLVG45yAYgAAAi8"]
[Tue Jul 21 07:28:09.681246 2026] [security2:error] [pid 230252:tid 230408] [client 20.151.10.161:49083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/adminfuns.php"] [unique_id "al9JuU0Dwhk5-Z44XrpbaQAAArE"]
[Tue Jul 21 07:28:09.748498 2026] [security2:error] [pid 230252:tid 230316] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuU0Dwhk5-Z44XrpbagACrj4"]
[Tue Jul 21 07:28:09.748668 2026] [security2:error] [pid 230252:tid 230405] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JuU0Dwhk5-Z44XrpbagACrj4"]
[Tue Jul 21 07:28:10.009398 2026] [security2:error] [pid 230252:tid 230394] [client 20.104.96.117:5094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/dvjul.php"] [unique_id "al9Juk0Dwhk5-Z44XrpbbgAAAqM"]
[Tue Jul 21 07:28:10.137665 2026] [security2:error] [pid 229246:tid 229436] [client 82.102.28.107:58740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9JuiBMYeh5YLVG45yAaAAAAlA"]
[Tue Jul 21 07:28:10.137777 2026] [security2:error] [pid 229246:tid 229436] [client 82.102.28.107:58740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9JuiBMYeh5YLVG45yAaAAAAlA"]
[Tue Jul 21 07:28:10.220036 2026] [security2:error] [pid 230252:tid 230454] [client 20.220.225.223:31170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/dragonshell.php"] [unique_id "al9Juk0Dwhk5-Z44XrpbbwAAAt8"]
[Tue Jul 21 07:28:10.287967 2026] [security2:error] [pid 230252:tid 230477] [client 103.162.129.114:64374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Juk0Dwhk5-Z44XrpbcQAAAvY"]
[Tue Jul 21 07:28:10.288087 2026] [security2:error] [pid 230252:tid 230477] [client 103.162.129.114:64374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Juk0Dwhk5-Z44XrpbcQAAAvY"]
[Tue Jul 21 07:28:10.533441 2026] [security2:error] [pid 229246:tid 229426] [client 20.104.96.117:62936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/biufile.php"] [unique_id "al9JuiBMYeh5YLVG45yAbwAAAkY"]
[Tue Jul 21 07:28:10.608553 2026] [proxy:error] [pid 230252:tid 230500] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:10.608629 2026] [proxy_http:error] [pid 230252:tid 230500] [client 74.249.245.134:54365] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:10.609144 2026] [proxy:error] [pid 230252:tid 230500] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:10.609173 2026] [proxy_http:error] [pid 230252:tid 230500] [client 74.249.245.134:54365] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:10.785083 2026] [security2:error] [pid 230252:tid 230452] [client 45.8.17.110:50193] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/edit-tags.php"] [unique_id "al9Juk0Dwhk5-Z44XrpbdAAAAt0"]
[Tue Jul 21 07:28:10.792844 2026] [security2:error] [pid 230252:tid 230319] [remote 207.180.241.245:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Juk0Dwhk5-Z44XrpbdQAC5EE"], referer: http://assumaocontrole.com/
[Tue Jul 21 07:28:10.902832 2026] [security2:error] [pid 229246:tid 229414] [client 20.104.96.117:62935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/av.php"] [unique_id "al9JuiBMYeh5YLVG45yAdAAAAjo"]
[Tue Jul 21 07:28:11.248003 2026] [security2:error] [pid 230252:tid 230398] [client 20.151.10.161:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/goods.php"] [unique_id "al9Ju00Dwhk5-Z44XrpbfQAAAqc"]
[Tue Jul 21 07:28:11.330448 2026] [security2:error] [pid 230252:tid 230444] [client 20.104.96.117:64005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/coffexium.php"] [unique_id "al9Ju00Dwhk5-Z44XrpbfwAAAtU"]
[Tue Jul 21 07:28:11.641787 2026] [security2:error] [pid 230252:tid 230268] [remote 54.39.0.165:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "marketingderua.com.br"] [uri "/como-funciona-a-programacao-de-conteudo-em-telas-de-ooh/"] [unique_id "al9Ju00Dwhk5-Z44XrpbhwADCA4"]
[Tue Jul 21 07:28:11.641950 2026] [security2:error] [pid 230252:tid 230495] [client 54.39.0.165:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "marketingderua.com.br"] [uri "/como-funciona-a-programacao-de-conteudo-em-telas-de-ooh/"] [unique_id "al9Ju00Dwhk5-Z44XrpbhwADCA4"]
[Tue Jul 21 07:28:11.647190 2026] [security2:error] [pid 230252:tid 230436] [client 20.104.96.117:64049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/core.php"] [unique_id "al9Ju00Dwhk5-Z44XrpbiAAAAs0"]
[Tue Jul 21 07:28:11.876111 2026] [security2:error] [pid 230252:tid 230255] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ju00Dwhk5-Z44XrpbjAADFwE"]
[Tue Jul 21 07:28:11.876246 2026] [security2:error] [pid 230252:tid 230510] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ju00Dwhk5-Z44XrpbjAADFwE"]
[Tue Jul 21 07:28:11.986394 2026] [security2:error] [pid 230252:tid 230503] [client 45.8.17.73:59357] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/log.php"] [unique_id "al9Ju00Dwhk5-Z44XrpbjQAAAxA"]
[Tue Jul 21 07:28:12.034481 2026] [security2:error] [pid 230252:tid 230405] [client 20.104.96.117:64019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/als.php"] [unique_id "al9JvE0Dwhk5-Z44XrpbjgAAAq4"]
[Tue Jul 21 07:28:12.101963 2026] [security2:error] [pid 230252:tid 230394] [client 20.151.10.161:49036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ms-edit.php"] [unique_id "al9JvE0Dwhk5-Z44XrpbkgAAAqM"]
[Tue Jul 21 07:28:12.193665 2026] [proxy:error] [pid 230252:tid 230399] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:12.193748 2026] [proxy_http:error] [pid 230252:tid 230399] [client 74.249.245.134:62861] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:12.194896 2026] [proxy:error] [pid 230252:tid 230399] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:12.194952 2026] [proxy_http:error] [pid 230252:tid 230399] [client 74.249.245.134:62861] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:12.261709 2026] [security2:error] [pid 230252:tid 230477] [client 20.104.96.117:59817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/v543.php"] [unique_id "al9JvE0Dwhk5-Z44XrpblwAAAvY"]
[Tue Jul 21 07:28:12.421803 2026] [security2:error] [pid 230252:tid 230390] [client 20.104.96.117:62939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/simple.php"] [unique_id "al9JvE0Dwhk5-Z44XrpbmgAAAp8"]
[Tue Jul 21 07:28:12.791933 2026] [security2:error] [pid 230252:tid 230428] [client 20.104.96.117:64008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/init.php"] [unique_id "al9JvE0Dwhk5-Z44XrpbowAAAsU"]
[Tue Jul 21 07:28:12.933549 2026] [security2:error] [pid 230252:tid 230462] [client 74.249.245.134:54382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/settings.php"] [unique_id "al9JvE0Dwhk5-Z44XrpbpQAAAuc"]
[Tue Jul 21 07:28:13.166189 2026] [security2:error] [pid 230252:tid 230453] [client 20.104.96.117:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/fpwch.php"] [unique_id "al9JvU0Dwhk5-Z44XrpbqQAAAt4"]
[Tue Jul 21 07:28:13.180343 2026] [security2:error] [pid 229246:tid 229455] [client 45.8.17.64:61063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/bless.php"] [unique_id "al9JvSBMYeh5YLVG45yAiwAAAmM"]
[Tue Jul 21 07:28:13.213093 2026] [security2:error] [pid 230252:tid 230444] [client 173.252.95.25:39386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9JvU0Dwhk5-Z44XrpbqgAAAtU"]
[Tue Jul 21 07:28:13.277889 2026] [security2:error] [pid 229246:tid 229367] [remote 192.241.143.148:40672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9JvSBMYeh5YLVG45yAjAACHXg"]
[Tue Jul 21 07:28:13.479094 2026] [security2:error] [pid 229246:tid 229423] [client 20.197.195.24:12380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/gecko.php"] [unique_id "al9JvSBMYeh5YLVG45yAjgAAAkM"]
[Tue Jul 21 07:28:13.580758 2026] [security2:error] [pid 229246:tid 229454] [client 20.104.96.117:62924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/domvf.php"] [unique_id "al9JvSBMYeh5YLVG45yAkgAAAmI"]
[Tue Jul 21 07:28:13.594568 2026] [security2:error] [pid 230252:tid 230395] [client 20.220.225.223:38705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/wp-mt.php"] [unique_id "al9JvU0Dwhk5-Z44XrpbrAAAAqQ"]
[Tue Jul 21 07:28:13.594863 2026] [security2:error] [pid 230252:tid 230484] [client 20.151.10.161:48634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/222.php"] [unique_id "al9JvU0Dwhk5-Z44XrpbrQAAAv0"]
[Tue Jul 21 07:28:13.871326 2026] [security2:error] [pid 230252:tid 230420] [client 20.104.96.117:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp.php"] [unique_id "al9JvU0Dwhk5-Z44XrpbsAAAAr0"]
[Tue Jul 21 07:28:13.987651 2026] [security2:error] [pid 229246:tid 229427] [client 74.249.245.134:17470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/g.php"] [unique_id "al9JvSBMYeh5YLVG45yAlgAAAkc"]
[Tue Jul 21 07:28:13.993144 2026] [security2:error] [pid 230252:tid 230511] [client 45.8.17.118:57999] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/"] [unique_id "al9JvU0Dwhk5-Z44XrpbswAAAxg"]
[Tue Jul 21 07:28:14.274755 2026] [security2:error] [pid 229246:tid 229503] [client 20.104.96.117:64038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/class.php"] [unique_id "al9JviBMYeh5YLVG45yAnAAAApM"]
[Tue Jul 21 07:28:14.417285 2026] [security2:error] [pid 230252:tid 230498] [client 152.59.154.239:52547] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbwAAAAws"]
[Tue Jul 21 07:28:14.417419 2026] [security2:error] [pid 230252:tid 230498] [client 152.59.154.239:52547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbwAAAAws"]
[Tue Jul 21 07:28:14.420098 2026] [security2:error] [pid 229246:tid 229500] [client 139.135.44.145:54093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JviBMYeh5YLVG45yAnQAAApA"]
[Tue Jul 21 07:28:14.420549 2026] [security2:error] [pid 229246:tid 229500] [client 139.135.44.145:54093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JviBMYeh5YLVG45yAnQAAApA"]
[Tue Jul 21 07:28:14.609836 2026] [security2:error] [pid 230252:tid 230399] [client 20.52.136.55:1580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/8.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbwwAAAqg"]
[Tue Jul 21 07:28:14.791116 2026] [security2:error] [pid 229246:tid 229392] [client 74.249.245.134:5527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/403.php"] [unique_id "al9JviBMYeh5YLVG45yAogAAAiQ"]
[Tue Jul 21 07:28:14.860003 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:5060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/echkm.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbygAAAw4"]
[Tue Jul 21 07:28:14.860675 2026] [security2:error] [pid 230252:tid 230408] [client 45.251.232.145:53253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbywAAArE"]
[Tue Jul 21 07:28:14.860757 2026] [security2:error] [pid 230252:tid 230408] [client 45.251.232.145:53253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbywAAArE"]
[Tue Jul 21 07:28:14.861639 2026] [security2:error] [pid 230252:tid 230510] [client 117.251.86.144:40562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbzAAAAxc"]
[Tue Jul 21 07:28:14.861777 2026] [security2:error] [pid 230252:tid 230510] [client 117.251.86.144:40562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbzAAAAxc"]
[Tue Jul 21 07:28:15.192312 2026] [security2:error] [pid 229246:tid 229354] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JvyBMYeh5YLVG45yAqQACJ2s"]
[Tue Jul 21 07:28:15.192470 2026] [security2:error] [pid 229246:tid 229395] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JvyBMYeh5YLVG45yAqQACJ2s"]
[Tue Jul 21 07:28:15.227941 2026] [security2:error] [pid 230252:tid 230426] [client 20.104.96.117:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/lib.php"] [unique_id "al9Jv00Dwhk5-Z44Xrpb1AAAAsM"]
[Tue Jul 21 07:28:15.284227 2026] [security2:error] [pid 230252:tid 230476] [client 74.7.230.14:56288] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.teste.inonebrasil.com.br"] [uri "/index.php"] [unique_id "al9Jv00Dwhk5-Z44Xrpb1QAC9RQ"]
[Tue Jul 21 07:28:15.383277 2026] [security2:error] [pid 229246:tid 229459] [client 45.8.17.137:28413] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/themes/"] [unique_id "al9JvyBMYeh5YLVG45yArAAAAmc"]
[Tue Jul 21 07:28:15.525284 2026] [security2:error] [pid 230252:tid 230411] [client 20.151.10.161:49041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Jv00Dwhk5-Z44Xrpb1gAAArQ"]
[Tue Jul 21 07:28:15.543780 2026] [security2:error] [pid 230252:tid 230453] [client 74.249.245.134:54339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.petshopterrara.com.br"] [uri "/api.php"] [unique_id "al9Jv00Dwhk5-Z44Xrpb1wAAAt4"]
[Tue Jul 21 07:28:15.567779 2026] [security2:error] [pid 230252:tid 230398] [client 20.104.96.117:62942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/login.php"] [unique_id "al9Jv00Dwhk5-Z44Xrpb2AAAAqc"]
[Tue Jul 21 07:28:15.671318 2026] [security2:error] [pid 229246:tid 229489] [client 59.96.220.140:50064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JvyBMYeh5YLVG45yArwAAAoU"]
[Tue Jul 21 07:28:15.672494 2026] [security2:error] [pid 229246:tid 229489] [client 59.96.220.140:50064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JvyBMYeh5YLVG45yArwAAAoU"]
[Tue Jul 21 07:28:15.682989 2026] [security2:error] [pid 230252:tid 230507] [client 66.42.61.105:37858] ModSecurity: Access denied with code 406 (phase 1). Match of "rx (^/administrator/)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "63"] [id "331216"] [rev "2"] [msg "Atomicorp.com WAF Rules: Wordpress DOS Attack Dropped"] [severity "CRITICAL"] [hostname "cotidianorural.com.br"] [uri "/wp-load.php"] [unique_id "al9Jv00Dwhk5-Z44Xrpb3QAAAxQ"]
[Tue Jul 21 07:28:15.707432 2026] [security2:error] [pid 230252:tid 230467] [client 193.36.225.61:54275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Jvk0Dwhk5-Z44XrpbwQAAAuw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:15.852012 2026] [security2:error] [pid 230252:tid 230508] [client 20.197.195.24:12297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/82.php"] [unique_id "al9Jv00Dwhk5-Z44Xrpb3gAAAxU"]
[Tue Jul 21 07:28:15.936546 2026] [security2:error] [pid 229246:tid 229436] [client 20.104.96.117:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/a2.php"] [unique_id "al9JvyBMYeh5YLVG45yAsgAAAlA"]
[Tue Jul 21 07:28:16.080752 2026] [proxy:error] [pid 229246:tid 229488] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:16.080837 2026] [proxy_http:error] [pid 229246:tid 229488] [client 20.151.10.161:49139] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:16.081300 2026] [proxy:error] [pid 229246:tid 229488] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:16.081327 2026] [proxy_http:error] [pid 229246:tid 229488] [client 20.151.10.161:49139] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:16.081962 2026] [proxy:error] [pid 230252:tid 230464] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:16.082008 2026] [proxy_http:error] [pid 230252:tid 230464] [client 74.249.245.134:54378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:16.082437 2026] [proxy:error] [pid 230252:tid 230464] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:16.082459 2026] [proxy_http:error] [pid 230252:tid 230464] [client 74.249.245.134:54378] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:16.203341 2026] [security2:error] [pid 229246:tid 229451] [client 20.220.225.223:62134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9JwCBMYeh5YLVG45yAuAAAAl8"]
[Tue Jul 21 07:28:16.352378 2026] [security2:error] [pid 230252:tid 230503] [client 20.104.96.117:5075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/d61.php"] [unique_id "al9JwE0Dwhk5-Z44Xrpb5gAAAxA"]
[Tue Jul 21 07:28:16.392135 2026] [security2:error] [pid 230252:tid 230407] [client 45.8.17.110:60631] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/file-upload-types/assets/css/403.php"] [unique_id "al9JwE0Dwhk5-Z44Xrpb5wAAArA"]
[Tue Jul 21 07:28:16.730058 2026] [security2:error] [pid 229246:tid 229501] [client 20.104.96.117:5111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/info.php"] [unique_id "al9JwCBMYeh5YLVG45yAwQAAApE"]
[Tue Jul 21 07:28:16.865947 2026] [security2:error] [pid 230252:tid 230261] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JwE0Dwhk5-Z44Xrpb7AAC1Ac"]
[Tue Jul 21 07:28:16.866103 2026] [security2:error] [pid 230252:tid 230443] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JwE0Dwhk5-Z44Xrpb7AAC1Ac"]
[Tue Jul 21 07:28:16.880567 2026] [security2:error] [pid 230252:tid 230449] [client 20.220.225.223:38674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/ww.php"] [unique_id "al9JwE0Dwhk5-Z44Xrpb7QAAAto"]
[Tue Jul 21 07:28:16.977853 2026] [security2:error] [pid 230252:tid 230477] [client 20.104.96.117:59643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/sixxis.php"] [unique_id "al9JwE0Dwhk5-Z44Xrpb7wAAAvY"]
[Tue Jul 21 07:28:17.080114 2026] [security2:error] [pid 230252:tid 230414] [client 20.104.96.117:4172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/11.php"] [unique_id "al9JwU0Dwhk5-Z44Xrpb8AAAArc"]
[Tue Jul 21 07:28:17.279334 2026] [security2:error] [pid 230252:tid 230493] [client 45.8.17.122:36799] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/autoload_classmap.php"] [unique_id "al9JwU0Dwhk5-Z44Xrpb9AAAAwY"]
[Tue Jul 21 07:28:17.525947 2026] [security2:error] [pid 229246:tid 229418] [client 20.104.96.117:5073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/v2.php"] [unique_id "al9JwSBMYeh5YLVG45yAxwAAAj4"]
[Tue Jul 21 07:28:17.803871 2026] [security2:error] [pid 229246:tid 229475] [client 20.151.10.161:49060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9JwSBMYeh5YLVG45yAywAAAnc"]
[Tue Jul 21 07:28:17.842876 2026] [security2:error] [pid 230252:tid 230466] [client 103.106.20.201:53688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JwU0Dwhk5-Z44XrpcAgAAAus"]
[Tue Jul 21 07:28:17.843007 2026] [security2:error] [pid 230252:tid 230466] [client 103.106.20.201:53688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JwU0Dwhk5-Z44XrpcAgAAAus"]
[Tue Jul 21 07:28:17.992486 2026] [security2:error] [pid 230252:tid 230505] [client 20.197.195.24:12356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/admin.php"] [unique_id "al9JwU0Dwhk5-Z44XrpcAwAAAxI"]
[Tue Jul 21 07:28:17.994905 2026] [security2:error] [pid 230252:tid 230511] [client 20.104.96.117:5087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/panel.php"] [unique_id "al9JwU0Dwhk5-Z44XrpcBAAAAxg"]
[Tue Jul 21 07:28:18.253455 2026] [security2:error] [pid 230252:tid 230376] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcCgACz3k"]
[Tue Jul 21 07:28:18.253688 2026] [security2:error] [pid 230252:tid 230438] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcCgACz3k"]
[Tue Jul 21 07:28:18.254642 2026] [proxy:error] [pid 229246:tid 229408] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:18.254696 2026] [proxy_http:error] [pid 229246:tid 229408] [client 198.235.24.104:61054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:18.255471 2026] [proxy:error] [pid 229246:tid 229408] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:18.255504 2026] [proxy_http:error] [pid 229246:tid 229408] [client 198.235.24.104:61054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:18.393217 2026] [security2:error] [pid 230252:tid 230478] [client 20.104.96.117:5066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/dex.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcDwAAAvc"]
[Tue Jul 21 07:28:18.485754 2026] [security2:error] [pid 230252:tid 230495] [client 45.8.17.146:59169] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/bolt.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcEQAAAwg"]
[Tue Jul 21 07:28:18.665219 2026] [security2:error] [pid 230252:tid 230375] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcEgADB3g"]
[Tue Jul 21 07:28:18.665424 2026] [security2:error] [pid 230252:tid 230494] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcEgADB3g"]
[Tue Jul 21 07:28:18.694531 2026] [security2:error] [pid 230252:tid 230392] [client 20.104.96.117:5056] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "foreverconfidence.com"] [uri "/1.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcEwAAAqE"]
[Tue Jul 21 07:28:18.694646 2026] [security2:error] [pid 230252:tid 230392] [client 20.104.96.117:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/1.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcEwAAAqE"]
[Tue Jul 21 07:28:18.875162 2026] [security2:error] [pid 230252:tid 230389] [client 20.197.195.24:12376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/adminner.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcFgAAAp4"]
[Tue Jul 21 07:28:18.955825 2026] [security2:error] [pid 230252:tid 230408] [client 20.104.96.117:59623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ip.php"] [unique_id "al9Jwk0Dwhk5-Z44XrpcFwAAArE"]
[Tue Jul 21 07:28:19.084338 2026] [security2:error] [pid 230252:tid 230439] [client 20.220.225.223:31187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/cron.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcGwAAAtA"]
[Tue Jul 21 07:28:19.140132 2026] [security2:error] [pid 230252:tid 230472] [client 103.174.34.15:49610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcIgAAAvE"]
[Tue Jul 21 07:28:19.140264 2026] [security2:error] [pid 230252:tid 230472] [client 103.174.34.15:49610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcIgAAAvE"]
[Tue Jul 21 07:28:19.146711 2026] [security2:error] [pid 230252:tid 230404] [client 20.104.96.117:5072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/ms.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcIwAAAq0"]
[Tue Jul 21 07:28:19.470665 2026] [security2:error] [pid 230252:tid 230396] [client 136.144.33.96:46219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcKAAAAqU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:19.503729 2026] [security2:error] [pid 230252:tid 230297] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcKQACzis"]
[Tue Jul 21 07:28:19.503912 2026] [security2:error] [pid 230252:tid 230437] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcKQACzis"]
[Tue Jul 21 07:28:19.505053 2026] [proxy:error] [pid 229246:tid 229474] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:19.505123 2026] [proxy_http:error] [pid 229246:tid 229474] [client 20.151.10.161:49077] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:19.505778 2026] [proxy:error] [pid 229246:tid 229474] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:19.505808 2026] [proxy_http:error] [pid 229246:tid 229474] [client 20.151.10.161:49077] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:19.520736 2026] [security2:error] [pid 229246:tid 229454] [client 74.7.244.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "oscardemattos1745866142707.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9JwyBMYeh5YLVG45yA2QACYkc"]
[Tue Jul 21 07:28:19.528288 2026] [security2:error] [pid 230252:tid 230454] [client 154.192.233.199:59142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcKgAAAt8"]
[Tue Jul 21 07:28:19.528457 2026] [security2:error] [pid 230252:tid 230454] [client 154.192.233.199:59142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcKgAAAt8"]
[Tue Jul 21 07:28:19.554683 2026] [security2:error] [pid 229246:tid 229477] [client 20.197.195.24:12366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/admin.php"] [unique_id "al9JwyBMYeh5YLVG45yA2gAAAnk"]
[Tue Jul 21 07:28:19.555530 2026] [security2:error] [pid 230252:tid 230508] [client 20.220.225.223:62874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/dp.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcKwAAAxU"]
[Tue Jul 21 07:28:19.606018 2026] [security2:error] [pid 230252:tid 230477] [client 175.45.70.82:56720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcLAAAAvY"]
[Tue Jul 21 07:28:19.606185 2026] [security2:error] [pid 230252:tid 230477] [client 175.45.70.82:56720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcLAAAAvY"]
[Tue Jul 21 07:28:19.690941 2026] [autoindex:error] [pid 229246:tid 229390] [client 20.104.96.117:64056] AH01276: Cannot serve directory /home4/forev309/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:19.737778 2026] [security2:error] [pid 229246:tid 229268] [remote 152.42.137.70:46766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.137.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedrocromo.com.br"] [uri "/wp-login.php"] [unique_id "al9JwyBMYeh5YLVG45yA3QACLBU"]
[Tue Jul 21 07:28:19.747663 2026] [security2:error] [pid 229246:tid 229502] [client 62.102.148.164:47580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JwyBMYeh5YLVG45yA3gAAApI"]
[Tue Jul 21 07:28:19.747734 2026] [security2:error] [pid 229246:tid 229502] [client 62.102.148.164:47580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9JwyBMYeh5YLVG45yA3gAAApI"]
[Tue Jul 21 07:28:19.875767 2026] [security2:error] [pid 230252:tid 230417] [client 20.197.195.24:12288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/k.php"] [unique_id "al9Jw00Dwhk5-Z44XrpcLwAAAro"]
[Tue Jul 21 07:28:19.968585 2026] [security2:error] [pid 229246:tid 229500] [client 20.104.96.117:64056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/memberfuns.php"] [unique_id "al9JwyBMYeh5YLVG45yA4QAAApA"]
[Tue Jul 21 07:28:19.993737 2026] [security2:error] [pid 229246:tid 229479] [client 20.197.195.24:12369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/blurbs.php"] [unique_id "al9JwyBMYeh5YLVG45yA4gAAAns"]
[Tue Jul 21 07:28:20.082573 2026] [security2:error] [pid 230252:tid 230503] [client 45.8.17.146:22407] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/maint/chosen.php"] [unique_id "al9JxE0Dwhk5-Z44XrpcMQAAAxA"]
[Tue Jul 21 07:28:20.130863 2026] [security2:error] [pid 229246:tid 229499] [client 213.152.162.104:49150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JxCBMYeh5YLVG45yA4wAAAo8"]
[Tue Jul 21 07:28:20.130958 2026] [security2:error] [pid 229246:tid 229499] [client 213.152.162.104:49150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9JxCBMYeh5YLVG45yA4wAAAo8"]
[Tue Jul 21 07:28:20.265615 2026] [security2:error] [pid 229246:tid 229323] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JxCBMYeh5YLVG45yA5QACW0w"]
[Tue Jul 21 07:28:20.265884 2026] [security2:error] [pid 229246:tid 229447] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JxCBMYeh5YLVG45yA5QACW0w"]
[Tue Jul 21 07:28:20.383902 2026] [security2:error] [pid 229246:tid 229459] [client 20.197.195.24:12360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/bajah.php"] [unique_id "al9JxCBMYeh5YLVG45yA7AAAAmc"]
[Tue Jul 21 07:28:20.405649 2026] [security2:error] [pid 230252:tid 230394] [client 20.104.96.117:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/0.php"] [unique_id "al9JxE0Dwhk5-Z44XrpcMwAAAqM"]
[Tue Jul 21 07:28:20.772349 2026] [security2:error] [pid 230252:tid 230448] [client 103.162.129.114:64814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JxE0Dwhk5-Z44XrpcNAAAAtk"]
[Tue Jul 21 07:28:20.772529 2026] [security2:error] [pid 230252:tid 230448] [client 103.162.129.114:64814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9JxE0Dwhk5-Z44XrpcNAAAAtk"]
[Tue Jul 21 07:28:20.856757 2026] [proxy:error] [pid 229246:tid 229425] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:20.856846 2026] [proxy_http:error] [pid 229246:tid 229425] [client 20.151.10.161:49091] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:20.857407 2026] [proxy:error] [pid 229246:tid 229425] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:20.857438 2026] [proxy_http:error] [pid 229246:tid 229425] [client 20.151.10.161:49091] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:20.943322 2026] [security2:error] [pid 229246:tid 229456] [client 20.104.96.117:62960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/BDKR28.php"] [unique_id "al9JxCBMYeh5YLVG45yA9gAAAmQ"]
[Tue Jul 21 07:28:20.975022 2026] [security2:error] [pid 230252:tid 230392] [client 20.197.195.24:12305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/a.php"] [unique_id "al9JxE0Dwhk5-Z44XrpcNgAAAqE"]
[Tue Jul 21 07:28:21.059094 2026] [security2:error] [pid 230252:tid 230443] [client 20.197.195.24:12327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/edit.php"] [unique_id "al9JxU0Dwhk5-Z44XrpcNwAAAtQ"]
[Tue Jul 21 07:28:21.108763 2026] [security2:error] [pid 230252:tid 230449] [client 20.197.195.24:12396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/hosty.php"] [unique_id "al9JxU0Dwhk5-Z44XrpcOAAAAto"]
[Tue Jul 21 07:28:21.197695 2026] [security2:error] [pid 229246:tid 229378] [client 20.197.195.24:12353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/k.php"] [unique_id "al9JxSBMYeh5YLVG45yA-wAAAhY"]
[Tue Jul 21 07:28:21.305833 2026] [security2:error] [pid 230252:tid 230428] [client 20.197.195.24:12387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/aaa.php"] [unique_id "al9JxU0Dwhk5-Z44XrpcPQAAAsU"]
[Tue Jul 21 07:28:21.319188 2026] [security2:error] [pid 229246:tid 229433] [client 20.104.96.117:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/green1.php"] [unique_id "al9JxSBMYeh5YLVG45yA_AAAAk0"]
[Tue Jul 21 07:28:21.410395 2026] [security2:error] [pid 230252:tid 230506] [client 20.104.96.117:59585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/kq1.php"] [unique_id "al9JxU0Dwhk5-Z44XrpcQAAAAxM"]
[Tue Jul 21 07:28:21.542284 2026] [security2:error] [pid 230252:tid 230483] [client 20.220.225.223:38663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/xxx.php"] [unique_id "al9JxU0Dwhk5-Z44XrpcQQAAAvw"]
[Tue Jul 21 07:28:21.649868 2026] [security2:error] [pid 230252:tid 230463] [client 20.197.195.24:12399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/file5.php"] [unique_id "al9JxU0Dwhk5-Z44XrpcQgAAAug"]
[Tue Jul 21 07:28:21.720993 2026] [security2:error] [pid 229246:tid 229492] [client 20.104.96.117:64003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/nc4.php"] [unique_id "al9JxSBMYeh5YLVG45yBAwAAAog"]
[Tue Jul 21 07:28:21.858162 2026] [security2:error] [pid 230252:tid 230458] [client 45.8.17.116:59291] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JxU0Dwhk5-Z44XrpcQwAAAuM"]
[Tue Jul 21 07:28:21.892431 2026] [security2:error] [pid 229246:tid 229424] [client 20.151.10.161:49142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp.php"] [unique_id "al9JxSBMYeh5YLVG45yBCwAAAkQ"]
[Tue Jul 21 07:28:21.946764 2026] [security2:error] [pid 229246:tid 229480] [client 20.197.195.24:12375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/222.php"] [unique_id "al9JxSBMYeh5YLVG45yBDQAAAnw"]
[Tue Jul 21 07:28:22.067508 2026] [autoindex:error] [pid 229246:tid 229256] [remote 74.7.242.41:59998] AH01276: Cannot serve directory /home2/prove728/valordistribuidora.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:22.111742 2026] [security2:error] [pid 230252:tid 230461] [client 74.7.228.56:35116] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "valordistribuidora.provendasatacado.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Jxk0Dwhk5-Z44XrpcRwAC5hk"]
[Tue Jul 21 07:28:22.119759 2026] [security2:error] [pid 230252:tid 230437] [client 20.104.96.117:4197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/a1.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcSAAAAs4"]
[Tue Jul 21 07:28:22.206300 2026] [security2:error] [pid 230252:tid 230403] [client 20.197.195.24:12367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/test.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcSgAAAqw"]
[Tue Jul 21 07:28:22.413517 2026] [security2:error] [pid 230252:tid 230455] [client 20.104.96.117:62937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/eee.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcTAAAAuA"]
[Tue Jul 21 07:28:22.476417 2026] [security2:error] [pid 230252:tid 230307] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcUQACpzU"]
[Tue Jul 21 07:28:22.476589 2026] [security2:error] [pid 230252:tid 230398] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcUQACpzU"]
[Tue Jul 21 07:28:22.507139 2026] [security2:error] [pid 230252:tid 230395] [client 20.197.195.24:12302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/aaa.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcVAAAAqQ"]
[Tue Jul 21 07:28:22.606113 2026] [security2:error] [pid 230252:tid 230469] [client 20.197.195.24:12377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/11.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcVgAAAu4"]
[Tue Jul 21 07:28:22.610866 2026] [security2:error] [pid 230252:tid 230380] [remote 173.252.95.57:41090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcVwAC030"]
[Tue Jul 21 07:28:22.796635 2026] [security2:error] [pid 230252:tid 230392] [client 45.8.17.141:60433] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/worksec.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcXAAAAqE"]
[Tue Jul 21 07:28:22.923679 2026] [security2:error] [pid 230252:tid 230443] [client 20.104.96.117:4175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-aothait.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcXwAAAtQ"]
[Tue Jul 21 07:28:22.936988 2026] [security2:error] [pid 230252:tid 230449] [client 20.197.195.24:12368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/mac.php"] [unique_id "al9Jxk0Dwhk5-Z44XrpcYgAAAto"]
[Tue Jul 21 07:28:23.044329 2026] [security2:error] [pid 229246:tid 229380] [client 82.102.28.107:56928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JxyBMYeh5YLVG45yBHAAAAhg"]
[Tue Jul 21 07:28:23.044406 2026] [security2:error] [pid 229246:tid 229380] [client 82.102.28.107:56928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9JxyBMYeh5YLVG45yBHAAAAhg"]
[Tue Jul 21 07:28:23.090224 2026] [security2:error] [pid 230252:tid 230462] [client 20.151.10.161:49133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/abcd.php"] [unique_id "al9Jx00Dwhk5-Z44XrpcaQAAAuc"]
[Tue Jul 21 07:28:23.095960 2026] [security2:error] [pid 230252:tid 230384] [client 20.104.96.117:59631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9Jx00Dwhk5-Z44XrpcagAAApk"]
[Tue Jul 21 07:28:23.133137 2026] [security2:error] [pid 230252:tid 230463] [client 20.197.195.24:12299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/chosen.php"] [unique_id "al9Jx00Dwhk5-Z44XrpcawAAAug"]
[Tue Jul 21 07:28:23.211281 2026] [security2:error] [pid 230252:tid 230386] [client 20.104.96.117:64052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/config.json.php"] [unique_id "al9Jx00Dwhk5-Z44XrpcbAAAAps"]
[Tue Jul 21 07:28:23.561385 2026] [security2:error] [pid 230252:tid 230418] [client 20.197.195.24:12343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/cream1.php"] [unique_id "al9Jx00Dwhk5-Z44XrpccgAAArs"]
[Tue Jul 21 07:28:23.605297 2026] [security2:error] [pid 230252:tid 230403] [client 20.104.96.117:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9Jx00Dwhk5-Z44XrpccwAAAqw"]
[Tue Jul 21 07:28:23.949396 2026] [security2:error] [pid 230252:tid 230455] [client 20.104.96.117:4182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/k2.php"] [unique_id "al9Jx00Dwhk5-Z44XrpcdQAAAuA"]
[Tue Jul 21 07:28:24.024440 2026] [security2:error] [pid 230252:tid 230417] [client 20.104.96.117:59646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/h02ugyh.php"] [unique_id "al9JyE0Dwhk5-Z44XrpcdgAAAro"]
[Tue Jul 21 07:28:24.039203 2026] [autoindex:error] [pid 230252:tid 230485] [client 20.197.195.24:12293] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:24.044282 2026] [security2:error] [pid 229246:tid 229384] [client 20.151.10.161:49117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/a1.php"] [unique_id "al9JyCBMYeh5YLVG45yBIwAAAhw"]
[Tue Jul 21 07:28:24.078845 2026] [autoindex:error] [pid 230252:tid 230438] [client 20.197.195.24:12293] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:24.088839 2026] [security2:error] [pid 229246:tid 229407] [client 45.8.17.148:21661] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content.php"] [unique_id "al9JyCBMYeh5YLVG45yBJAAAAjM"]
[Tue Jul 21 07:28:24.097594 2026] [security2:error] [pid 230252:tid 230398] [client 20.197.195.24:12293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/dr.php"] [unique_id "al9JyE0Dwhk5-Z44XrpcewAAAqc"]
[Tue Jul 21 07:28:24.352943 2026] [security2:error] [pid 229246:tid 229467] [client 193.36.225.54:58565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9JyCBMYeh5YLVG45yBKQAAAm8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:24.700494 2026] [security2:error] [pid 229246:tid 229488] [client 20.104.96.117:62929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/uiuvs58l.php"] [unique_id "al9JyCBMYeh5YLVG45yBLwAAAoQ"]
[Tue Jul 21 07:28:24.826572 2026] [security2:error] [pid 229246:tid 229426] [client 20.197.195.24:12320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/x.php"] [unique_id "al9JyCBMYeh5YLVG45yBMQAAAkY"]
[Tue Jul 21 07:28:25.087450 2026] [security2:error] [pid 229246:tid 229460] [client 45.8.17.131:59857] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/chosen.php"] [unique_id "al9JySBMYeh5YLVG45yBNAAAAmg"]
[Tue Jul 21 07:28:25.095329 2026] [security2:error] [pid 229246:tid 229450] [client 139.135.44.145:54891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JySBMYeh5YLVG45yBNQAAAl4"]
[Tue Jul 21 07:28:25.095425 2026] [security2:error] [pid 229246:tid 229450] [client 139.135.44.145:54891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9JySBMYeh5YLVG45yBNQAAAl4"]
[Tue Jul 21 07:28:25.235901 2026] [security2:error] [pid 229246:tid 229433] [client 20.104.96.117:5092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/40p9ixjd.php"] [unique_id "al9JySBMYeh5YLVG45yBOwAAAk0"]
[Tue Jul 21 07:28:25.298109 2026] [security2:error] [pid 229246:tid 229491] [client 20.151.10.161:49118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9JySBMYeh5YLVG45yBPAAAAoc"]
[Tue Jul 21 07:28:25.302113 2026] [security2:error] [pid 230252:tid 230506] [client 20.104.96.117:42405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-temp.php"] [unique_id "al9JyU0Dwhk5-Z44XrpchwAAAxM"]
[Tue Jul 21 07:28:25.343860 2026] [security2:error] [pid 229246:tid 229458] [client 45.251.232.145:53769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JySBMYeh5YLVG45yBPQAAAmY"]
[Tue Jul 21 07:28:25.343975 2026] [security2:error] [pid 229246:tid 229458] [client 45.251.232.145:53769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JySBMYeh5YLVG45yBPQAAAmY"]
[Tue Jul 21 07:28:25.483384 2026] [security2:error] [pid 230252:tid 230469] [client 152.59.154.239:52971] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JyU0Dwhk5-Z44XrpciAAAAu4"]
[Tue Jul 21 07:28:25.483499 2026] [security2:error] [pid 230252:tid 230469] [client 152.59.154.239:52971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JyU0Dwhk5-Z44XrpciAAAAu4"]
[Tue Jul 21 07:28:25.575808 2026] [security2:error] [pid 229246:tid 229418] [client 20.104.96.117:5065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9JySBMYeh5YLVG45yBQAAAAj4"]
[Tue Jul 21 07:28:25.635523 2026] [security2:error] [pid 229246:tid 229445] [client 117.251.86.144:60472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JySBMYeh5YLVG45yBQwAAAlk"]
[Tue Jul 21 07:28:25.635632 2026] [security2:error] [pid 229246:tid 229445] [client 117.251.86.144:60472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9JySBMYeh5YLVG45yBQwAAAlk"]
[Tue Jul 21 07:28:25.703267 2026] [security2:error] [pid 229246:tid 229484] [client 20.197.195.24:20592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/155.php"] [unique_id "al9JySBMYeh5YLVG45yBRgAAAoA"]
[Tue Jul 21 07:28:25.779850 2026] [security2:error] [pid 230252:tid 230357] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JyU0Dwhk5-Z44XrpciwACmWY"]
[Tue Jul 21 07:28:25.779975 2026] [security2:error] [pid 230252:tid 230384] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9JyU0Dwhk5-Z44XrpciwACmWY"]
[Tue Jul 21 07:28:25.951685 2026] [security2:error] [pid 229246:tid 229411] [client 20.197.195.24:20570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ops.php"] [unique_id "al9JySBMYeh5YLVG45yBSAAAAjc"]
[Tue Jul 21 07:28:26.105511 2026] [security2:error] [pid 230252:tid 230488] [client 20.197.195.24:12393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/file31.php"] [unique_id "al9Jyk0Dwhk5-Z44XrpckAAAAwE"]
[Tue Jul 21 07:28:26.132238 2026] [security2:error] [pid 229246:tid 229284] [remote 147.135.213.27:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hauptmann.com.br"] [uri "/robots.txt"] [unique_id "al9JyiBMYeh5YLVG45yBTgACYSU"]
[Tue Jul 21 07:28:26.132354 2026] [security2:error] [pid 229246:tid 229453] [client 147.135.213.27:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.hauptmann.com.br"] [uri "/robots.txt"] [unique_id "al9JyiBMYeh5YLVG45yBTgACYSU"]
[Tue Jul 21 07:28:26.194498 2026] [security2:error] [pid 229246:tid 229428] [client 20.104.96.117:4252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/for.php"] [unique_id "al9JyiBMYeh5YLVG45yBUAAAAkg"]
[Tue Jul 21 07:28:26.242920 2026] [security2:error] [pid 229246:tid 229400] [client 20.197.195.24:12407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/file6.php"] [unique_id "al9JyiBMYeh5YLVG45yBUQAAAiw"]
[Tue Jul 21 07:28:26.392100 2026] [security2:error] [pid 229246:tid 229503] [client 45.8.17.132:37681] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/themes/about.php"] [unique_id "al9JyiBMYeh5YLVG45yBUgAAApM"]
[Tue Jul 21 07:28:26.410487 2026] [autoindex:error] [pid 230252:tid 230509] [client 20.197.195.24:12325] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:26.525341 2026] [security2:error] [pid 230252:tid 230507] [client 20.197.195.24:12325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/adminfuns.php"] [unique_id "al9Jyk0Dwhk5-Z44XrpckwAAAxQ"]
[Tue Jul 21 07:28:26.559091 2026] [security2:error] [pid 230252:tid 230439] [client 20.104.96.117:64045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/raw.php"] [unique_id "al9Jyk0Dwhk5-Z44XrpclAAAAtA"]
[Tue Jul 21 07:28:26.578527 2026] [security2:error] [pid 230252:tid 230389] [client 20.52.136.55:1735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/ws38.php"] [unique_id "al9Jyk0Dwhk5-Z44XrpclQAAAp4"]
[Tue Jul 21 07:28:26.763350 2026] [security2:error] [pid 230252:tid 230500] [client 20.104.96.117:59836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9Jyk0Dwhk5-Z44XrpcnAAAAw0"]
[Tue Jul 21 07:28:26.843127 2026] [security2:error] [pid 229246:tid 229495] [client 20.197.195.24:12415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/goods.php"] [unique_id "al9JyiBMYeh5YLVG45yBWgAAAos"]
[Tue Jul 21 07:28:26.880892 2026] [security2:error] [pid 229246:tid 229251] [remote 8.217.108.67:30818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/wp-login.php"] [unique_id "al9JyiBMYeh5YLVG45yBWwACMgQ"]
[Tue Jul 21 07:28:27.062132 2026] [security2:error] [pid 229246:tid 229379] [client 20.197.195.24:12359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/100.php"] [unique_id "al9JyyBMYeh5YLVG45yBXAAAAhc"]
[Tue Jul 21 07:28:27.219594 2026] [security2:error] [pid 229246:tid 229468] [client 20.197.195.24:12414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/about.php"] [unique_id "al9JyyBMYeh5YLVG45yBXwAAAnA"]
[Tue Jul 21 07:28:27.280176 2026] [security2:error] [pid 229246:tid 229395] [client 20.220.225.223:8913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/old.php"] [unique_id "al9JyyBMYeh5YLVG45yBYgAAAic"]
[Tue Jul 21 07:28:27.306982 2026] [security2:error] [pid 229246:tid 229255] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JyyBMYeh5YLVG45yBYwACGwg"]
[Tue Jul 21 07:28:27.307175 2026] [security2:error] [pid 229246:tid 229383] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9JyyBMYeh5YLVG45yBYwACGwg"]
[Tue Jul 21 07:28:27.404300 2026] [proxy:error] [pid 229246:tid 229467] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:27.404379 2026] [proxy_http:error] [pid 229246:tid 229467] [client 20.151.10.161:49100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:27.404834 2026] [proxy:error] [pid 229246:tid 229467] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:27.404866 2026] [proxy_http:error] [pid 229246:tid 229467] [client 20.151.10.161:49100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:27.686078 2026] [security2:error] [pid 230252:tid 230503] [client 45.8.17.62:25845] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/ssss/src.php"] [unique_id "al9Jy00Dwhk5-Z44XrpcowAAAxA"]
[Tue Jul 21 07:28:27.702586 2026] [security2:error] [pid 229246:tid 229436] [client 20.197.195.24:12397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/about.php"] [unique_id "al9JyyBMYeh5YLVG45yBZwAAAlA"]
[Tue Jul 21 07:28:28.169846 2026] [security2:error] [pid 230252:tid 230401] [client 20.197.195.24:12316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/admin.php"] [unique_id "al9JzE0Dwhk5-Z44XrpcqQAAAqo"]
[Tue Jul 21 07:28:28.317518 2026] [security2:error] [pid 230252:tid 230466] [client 172.245.102.45:55259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9JzE0Dwhk5-Z44XrpcqAAAAus"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:28.510218 2026] [security2:error] [pid 230252:tid 230430] [client 20.197.195.24:20589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/admin.php"] [unique_id "al9JzE0Dwhk5-Z44XrpcrAAAAsc"]
[Tue Jul 21 07:28:28.542593 2026] [proxy:error] [pid 230252:tid 230502] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:28.542666 2026] [proxy_http:error] [pid 230252:tid 230502] [client 20.151.10.161:49090] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:28.543278 2026] [proxy:error] [pid 230252:tid 230502] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:28.543305 2026] [proxy_http:error] [pid 230252:tid 230502] [client 20.151.10.161:49090] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:28.631956 2026] [security2:error] [pid 229246:tid 229497] [client 103.106.20.201:54262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JzCBMYeh5YLVG45yBdAAAAo0"]
[Tue Jul 21 07:28:28.632133 2026] [security2:error] [pid 229246:tid 229497] [client 103.106.20.201:54262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JzCBMYeh5YLVG45yBdAAAAo0"]
[Tue Jul 21 07:28:28.692255 2026] [security2:error] [pid 230252:tid 230399] [client 59.96.220.140:50517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JzE0Dwhk5-Z44XrpcrwAAAqg"]
[Tue Jul 21 07:28:28.692404 2026] [security2:error] [pid 230252:tid 230399] [client 59.96.220.140:50517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9JzE0Dwhk5-Z44XrpcrwAAAqg"]
[Tue Jul 21 07:28:29.177991 2026] [security2:error] [pid 230252:tid 230295] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcuQAC7ik"]
[Tue Jul 21 07:28:29.178182 2026] [security2:error] [pid 230252:tid 230469] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcuQAC7ik"]
[Tue Jul 21 07:28:29.290208 2026] [security2:error] [pid 230252:tid 230303] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcvQACyDE"]
[Tue Jul 21 07:28:29.290395 2026] [security2:error] [pid 230252:tid 230431] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcvQACyDE"]
[Tue Jul 21 07:28:29.304449 2026] [proxy:error] [pid 230252:tid 230387] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:29.304513 2026] [proxy_http:error] [pid 230252:tid 230387] [client 20.151.10.161:49104] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:29.305181 2026] [proxy:error] [pid 230252:tid 230387] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:29.305211 2026] [proxy_http:error] [pid 230252:tid 230387] [client 20.151.10.161:49104] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:29.317885 2026] [security2:error] [pid 229246:tid 229431] [client 82.102.28.107:39130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JzSBMYeh5YLVG45yBewAAAks"]
[Tue Jul 21 07:28:29.318000 2026] [security2:error] [pid 229246:tid 229431] [client 82.102.28.107:39130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9JzSBMYeh5YLVG45yBewAAAks"]
[Tue Jul 21 07:28:29.732090 2026] [security2:error] [pid 229246:tid 229478] [client 20.104.96.117:59611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9JzSBMYeh5YLVG45yBfQAAAno"]
[Tue Jul 21 07:28:29.766620 2026] [security2:error] [pid 229246:tid 229416] [client 20.220.225.223:38657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/hunter.php"] [unique_id "al9JzSBMYeh5YLVG45yBfwAAAjw"]
[Tue Jul 21 07:28:29.785388 2026] [security2:error] [pid 230252:tid 230287] [remote 2a01:239:4db:9500::1:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "expertemrecheios.com"] [uri "/wp-login.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcyAAC2CE"]
[Tue Jul 21 07:28:29.861048 2026] [security2:error] [pid 230252:tid 230461] [client 103.174.34.15:50104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcygAAAuY"]
[Tue Jul 21 07:28:29.861165 2026] [security2:error] [pid 230252:tid 230461] [client 103.174.34.15:50104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcygAAAuY"]
[Tue Jul 21 07:28:29.958870 2026] [security2:error] [pid 230252:tid 230438] [client 20.197.195.24:12403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/themes.php"] [unique_id "al9JzU0Dwhk5-Z44XrpcywAAAs8"]
[Tue Jul 21 07:28:30.038608 2026] [security2:error] [pid 229246:tid 229253] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JziBMYeh5YLVG45yBhgACfAY"]
[Tue Jul 21 07:28:30.038782 2026] [security2:error] [pid 229246:tid 229480] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9JziBMYeh5YLVG45yBhgACfAY"]
[Tue Jul 21 07:28:30.202737 2026] [security2:error] [pid 230252:tid 230429] [client 154.192.233.199:59535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jzk0Dwhk5-Z44XrpczwAAAsY"]
[Tue Jul 21 07:28:30.202861 2026] [security2:error] [pid 230252:tid 230429] [client 154.192.233.199:59535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jzk0Dwhk5-Z44XrpczwAAAsY"]
[Tue Jul 21 07:28:30.220392 2026] [security2:error] [pid 229246:tid 229461] [client 175.45.70.82:57236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JziBMYeh5YLVG45yBiAAAAmk"]
[Tue Jul 21 07:28:30.220501 2026] [security2:error] [pid 229246:tid 229461] [client 175.45.70.82:57236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9JziBMYeh5YLVG45yBiAAAAmk"]
[Tue Jul 21 07:28:30.511720 2026] [security2:error] [pid 230252:tid 230502] [client 20.104.96.117:59819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/jj.php"] [unique_id "al9Jzk0Dwhk5-Z44Xrpc0gAAAw8"]
[Tue Jul 21 07:28:30.766268 2026] [security2:error] [pid 230252:tid 230330] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jzk0Dwhk5-Z44Xrpc1gADB0s"]
[Tue Jul 21 07:28:30.766436 2026] [security2:error] [pid 230252:tid 230494] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Jzk0Dwhk5-Z44Xrpc1gADB0s"]
[Tue Jul 21 07:28:30.871352 2026] [security2:error] [pid 229246:tid 229427] [client 20.220.225.223:62866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/ms-new.php"] [unique_id "al9JziBMYeh5YLVG45yBjQAAAkc"]
[Tue Jul 21 07:28:31.089655 2026] [security2:error] [pid 229246:tid 229303] [remote 20.118.34.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wso112233.php"] [unique_id "al9JzSBMYeh5YLVG45yBhAACiDg"]
[Tue Jul 21 07:28:31.132699 2026] [autoindex:error] [pid 229246:tid 229415] [client 20.197.195.24:12314] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:31.264564 2026] [security2:error] [pid 230252:tid 230397] [client 103.162.129.114:65260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Jz00Dwhk5-Z44Xrpc2QAAAqY"]
[Tue Jul 21 07:28:31.264692 2026] [security2:error] [pid 230252:tid 230397] [client 103.162.129.114:65260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Jz00Dwhk5-Z44Xrpc2QAAAqY"]
[Tue Jul 21 07:28:31.803390 2026] [security2:error] [pid 230252:tid 230467] [client 20.151.10.161:49096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9Jz00Dwhk5-Z44Xrpc4AAAAuw"]
[Tue Jul 21 07:28:32.023853 2026] [security2:error] [pid 230252:tid 230480] [client 20.104.96.117:59808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9J0E0Dwhk5-Z44Xrpc4gAAAvk"]
[Tue Jul 21 07:28:32.183132 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.195.24:12314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/.well-known/about.php"] [unique_id "al9J0CBMYeh5YLVG45yBnQAAAjI"]
[Tue Jul 21 07:28:32.940332 2026] [security2:error] [pid 229246:tid 229466] [client 20.104.96.117:59605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/txets.php"] [unique_id "al9J0CBMYeh5YLVG45yBpAAAAm4"]
[Tue Jul 21 07:28:33.044851 2026] [security2:error] [pid 230252:tid 230262] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J0U0Dwhk5-Z44Xrpc_wAC2gg"]
[Tue Jul 21 07:28:33.045040 2026] [security2:error] [pid 230252:tid 230449] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J0U0Dwhk5-Z44Xrpc_wAC2gg"]
[Tue Jul 21 07:28:33.194486 2026] [security2:error] [pid 230252:tid 230323] [remote 20.75.217.64:9902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-login.php"] [unique_id "al9J0U0Dwhk5-Z44XrpdAgAC3kU"]
[Tue Jul 21 07:28:33.356121 2026] [security2:error] [pid 230252:tid 230463] [client 172.245.102.45:34699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9J0U0Dwhk5-Z44XrpdBgAAAug"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:34.083484 2026] [security2:error] [pid 229246:tid 229483] [client 45.8.17.58:51455] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/files/"] [unique_id "al9J0iBMYeh5YLVG45yBvQAAAn8"]
[Tue Jul 21 07:28:34.380211 2026] [security2:error] [pid 229246:tid 229397] [client 20.151.10.161:49150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/gettest.php"] [unique_id "al9J0iBMYeh5YLVG45yBxQAAAik"]
[Tue Jul 21 07:28:34.566008 2026] [security2:error] [pid 229246:tid 229382] [client 20.104.96.117:59826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/dex.php"] [unique_id "al9J0iBMYeh5YLVG45yBywAAAho"]
[Tue Jul 21 07:28:34.697241 2026] [security2:error] [pid 230252:tid 230483] [client 20.197.195.24:12294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9J0k0Dwhk5-Z44XrpdFgAAAvw"]
[Tue Jul 21 07:28:34.805223 2026] [security2:error] [pid 230252:tid 230396] [client 105.127.11.139:42611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.11.127.105.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9J0k0Dwhk5-Z44XrpdFQAAAqU"]
[Tue Jul 21 07:28:34.805389 2026] [security2:error] [pid 230252:tid 230396] [client 105.127.11.139:42611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9J0k0Dwhk5-Z44XrpdFQAAAqU"]
[Tue Jul 21 07:28:34.888465 2026] [security2:error] [pid 229246:tid 229487] [client 45.8.17.122:64371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/themes.php"] [unique_id "al9J0iBMYeh5YLVG45yBzwAAAoM"]
[Tue Jul 21 07:28:35.790887 2026] [security2:error] [pid 229246:tid 229411] [client 45.8.17.139:22839] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/ahax.php"] [unique_id "al9J0yBMYeh5YLVG45yB2QAAAjc"]
[Tue Jul 21 07:28:35.825800 2026] [security2:error] [pid 230252:tid 230438] [client 45.251.232.145:54283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J000Dwhk5-Z44XrpdHwAAAs8"]
[Tue Jul 21 07:28:35.825932 2026] [security2:error] [pid 230252:tid 230438] [client 45.251.232.145:54283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J000Dwhk5-Z44XrpdHwAAAs8"]
[Tue Jul 21 07:28:36.016424 2026] [security2:error] [pid 230252:tid 230451] [client 139.135.44.145:53749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J1E0Dwhk5-Z44XrpdIQAAAtw"]
[Tue Jul 21 07:28:36.016654 2026] [security2:error] [pid 230252:tid 230451] [client 139.135.44.145:53749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J1E0Dwhk5-Z44XrpdIQAAAtw"]
[Tue Jul 21 07:28:36.358669 2026] [security2:error] [pid 230252:tid 230305] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J1E0Dwhk5-Z44XrpdJwADETM"]
[Tue Jul 21 07:28:36.358842 2026] [security2:error] [pid 230252:tid 230504] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J1E0Dwhk5-Z44XrpdJwADETM"]
[Tue Jul 21 07:28:36.411054 2026] [security2:error] [pid 229246:tid 229385] [client 117.251.86.144:38572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J1CBMYeh5YLVG45yB5QAAAh0"]
[Tue Jul 21 07:28:36.411175 2026] [security2:error] [pid 229246:tid 229385] [client 117.251.86.144:38572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J1CBMYeh5YLVG45yB5QAAAh0"]
[Tue Jul 21 07:28:36.520590 2026] [security2:error] [pid 229246:tid 229400] [client 20.10.88.227:2241] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gnxinox.com.br"] [uri "/index.php"] [unique_id "al9J1CBMYeh5YLVG45yB5gAAAiw"]
[Tue Jul 21 07:28:37.009457 2026] [security2:error] [pid 230252:tid 230490] [client 152.59.154.239:32606] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J1U0Dwhk5-Z44XrpdMgAAAwM"]
[Tue Jul 21 07:28:37.011229 2026] [security2:error] [pid 230252:tid 230490] [client 152.59.154.239:32606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J1U0Dwhk5-Z44XrpdMgAAAwM"]
[Tue Jul 21 07:28:37.079496 2026] [security2:error] [pid 230252:tid 230454] [client 45.8.17.115:43119] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/images/"] [unique_id "al9J1U0Dwhk5-Z44XrpdMwAAAt8"]
[Tue Jul 21 07:28:37.341455 2026] [security2:error] [pid 230252:tid 230502] [client 193.36.225.72:22439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9J1U0Dwhk5-Z44XrpdNgAAAw8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:37.451363 2026] [security2:error] [pid 229246:tid 229457] [client 20.52.136.55:1732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/a7.php"] [unique_id "al9J1SBMYeh5YLVG45yB9AAAAmU"]
[Tue Jul 21 07:28:37.776859 2026] [security2:error] [pid 229246:tid 229459] [client 20.220.225.223:31169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/we.php"] [unique_id "al9J1SBMYeh5YLVG45yB-QAAAmc"]
[Tue Jul 21 07:28:37.782643 2026] [proxy:error] [pid 229246:tid 229466] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:37.782699 2026] [proxy_http:error] [pid 229246:tid 229466] [client 20.151.10.161:49128] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:37.783301 2026] [proxy:error] [pid 229246:tid 229466] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:37.783328 2026] [proxy_http:error] [pid 229246:tid 229466] [client 20.151.10.161:49128] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:37.861475 2026] [security2:error] [pid 229246:tid 229336] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J1SBMYeh5YLVG45yB_wACdVk"]
[Tue Jul 21 07:28:37.861603 2026] [security2:error] [pid 229246:tid 229473] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J1SBMYeh5YLVG45yB_wACdVk"]
[Tue Jul 21 07:28:37.914678 2026] [security2:error] [pid 229246:tid 229436] [client 20.104.96.117:59597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/xpwer1.php"] [unique_id "al9J1SBMYeh5YLVG45yCAAAAAlA"]
[Tue Jul 21 07:28:37.980829 2026] [security2:error] [pid 229246:tid 229481] [client 20.220.225.223:62114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/track.php"] [unique_id "al9J1SBMYeh5YLVG45yCAQAAAn0"]
[Tue Jul 21 07:28:38.234100 2026] [security2:error] [pid 229246:tid 229288] [remote 13.41.15.21:59338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.15.41.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9J1iBMYeh5YLVG45yCAgACLyk"]
[Tue Jul 21 07:28:38.349563 2026] [security2:error] [pid 230252:tid 230461] [client 20.197.195.24:12372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wefile.php"] [unique_id "al9J1k0Dwhk5-Z44XrpdOgAAAuY"]
[Tue Jul 21 07:28:38.438906 2026] [security2:error] [pid 230252:tid 230398] [client 20.52.136.55:1737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/classsmtps.php"] [unique_id "al9J1k0Dwhk5-Z44XrpdPAAAAqc"]
[Tue Jul 21 07:28:38.546842 2026] [security2:error] [pid 230252:tid 230420] [client 20.10.88.227:1856] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealthonline.shop"] [uri "/robots.txt"] [unique_id "al9J1k0Dwhk5-Z44XrpdPwAAAr0"]
[Tue Jul 21 07:28:38.981329 2026] [security2:error] [pid 230252:tid 230474] [client 45.8.17.73:31329] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/preformatted/"] [unique_id "al9J1k0Dwhk5-Z44XrpdRwAAAvM"]
[Tue Jul 21 07:28:39.072162 2026] [security2:error] [pid 230252:tid 230506] [client 20.52.136.55:1548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/rip.php"] [unique_id "al9J100Dwhk5-Z44XrpdSAAAAxM"]
[Tue Jul 21 07:28:39.085236 2026] [core:alert] [pid 230252:tid 230449] [client 57.141.18.27:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:28:39.313898 2026] [security2:error] [pid 229246:tid 229280] [remote 104.207.58.230:58873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9J1iBMYeh5YLVG45yCBAACiSE"]
[Tue Jul 21 07:28:39.338790 2026] [security2:error] [pid 230252:tid 230393] [client 103.106.20.201:54848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J100Dwhk5-Z44XrpdTgAAAqI"]
[Tue Jul 21 07:28:39.338954 2026] [security2:error] [pid 230252:tid 230393] [client 103.106.20.201:54848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J100Dwhk5-Z44XrpdTgAAAqI"]
[Tue Jul 21 07:28:39.452738 2026] [security2:error] [pid 230252:tid 230422] [client 20.197.195.24:12383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9J100Dwhk5-Z44XrpdTwAAAr8"]
[Tue Jul 21 07:28:39.794117 2026] [security2:error] [pid 230252:tid 230415] [client 45.8.17.103:34673] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "al9J100Dwhk5-Z44XrpdVAAAArg"]
[Tue Jul 21 07:28:39.961419 2026] [security2:error] [pid 230252:tid 230344] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J100Dwhk5-Z44XrpdVQAC7lk"]
[Tue Jul 21 07:28:39.961596 2026] [security2:error] [pid 230252:tid 230469] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J100Dwhk5-Z44XrpdVQAC7lk"]
[Tue Jul 21 07:28:39.985739 2026] [security2:error] [pid 230252:tid 230379] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J100Dwhk5-Z44XrpdVgACuXw"]
[Tue Jul 21 07:28:39.985894 2026] [security2:error] [pid 230252:tid 230416] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J100Dwhk5-Z44XrpdVgACuXw"]
[Tue Jul 21 07:28:40.076660 2026] [security2:error] [pid 230252:tid 230509] [client 20.151.10.161:49029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/simple.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdVwAAAxY"]
[Tue Jul 21 07:28:40.442270 2026] [security2:error] [pid 230252:tid 230490] [client 103.174.34.15:50631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdXgAAAwM"]
[Tue Jul 21 07:28:40.442398 2026] [security2:error] [pid 230252:tid 230490] [client 103.174.34.15:50631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdXgAAAwM"]
[Tue Jul 21 07:28:40.517288 2026] [autoindex:error] [pid 229246:tid 229501] [client 20.197.195.24:12324] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:40.577026 2026] [security2:error] [pid 230252:tid 230316] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdYAADCT4"]
[Tue Jul 21 07:28:40.577212 2026] [security2:error] [pid 230252:tid 230496] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdYAADCT4"]
[Tue Jul 21 07:28:40.777646 2026] [security2:error] [pid 230252:tid 230404] [client 59.96.220.140:50990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdZAAAAq0"]
[Tue Jul 21 07:28:40.777760 2026] [security2:error] [pid 230252:tid 230404] [client 59.96.220.140:50990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdZAAAAq0"]
[Tue Jul 21 07:28:40.852609 2026] [autoindex:error] [pid 229246:tid 229477] [client 20.197.195.24:12324] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:40.858331 2026] [security2:error] [pid 229246:tid 229427] [client 20.197.195.24:12324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9J2CBMYeh5YLVG45yCIgAAAkc"]
[Tue Jul 21 07:28:40.866466 2026] [security2:error] [pid 229246:tid 229461] [client 154.192.233.199:58664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2CBMYeh5YLVG45yCIwAAAmk"]
[Tue Jul 21 07:28:40.866562 2026] [security2:error] [pid 229246:tid 229461] [client 154.192.233.199:58664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2CBMYeh5YLVG45yCIwAAAmk"]
[Tue Jul 21 07:28:40.883542 2026] [security2:error] [pid 230252:tid 230425] [client 45.8.17.113:37049] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/customize/"] [unique_id "al9J2E0Dwhk5-Z44XrpdZwAAAsI"]
[Tue Jul 21 07:28:40.930843 2026] [security2:error] [pid 230252:tid 230479] [client 175.45.70.82:57763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdaAAAAvg"]
[Tue Jul 21 07:28:40.931022 2026] [security2:error] [pid 230252:tid 230479] [client 175.45.70.82:57763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdaAAAAvg"]
[Tue Jul 21 07:28:41.288157 2026] [security2:error] [pid 229246:tid 229298] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2SBMYeh5YLVG45yCMAACajM"]
[Tue Jul 21 07:28:41.288375 2026] [security2:error] [pid 229246:tid 229462] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J2SBMYeh5YLVG45yCMAACajM"]
[Tue Jul 21 07:28:41.475603 2026] [security2:error] [pid 230252:tid 230474] [client 20.52.136.55:1503] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.gradiente.com"] [uri "/1.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdbgAAAvM"]
[Tue Jul 21 07:28:41.475730 2026] [security2:error] [pid 230252:tid 230474] [client 20.52.136.55:1503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/1.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdbgAAAvM"]
[Tue Jul 21 07:28:41.511528 2026] [security2:error] [pid 230252:tid 230449] [client 20.104.96.117:59776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/flox.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdbwAAAto"]
[Tue Jul 21 07:28:41.533685 2026] [security2:error] [pid 230252:tid 230453] [client 20.104.96.117:62445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdcAAAAt4"]
[Tue Jul 21 07:28:41.549783 2026] [security2:error] [pid 230252:tid 230441] [client 62.102.148.164:47356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdcQAAAtI"]
[Tue Jul 21 07:28:41.549879 2026] [security2:error] [pid 230252:tid 230441] [client 62.102.148.164:47356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdcQAAAtI"]
[Tue Jul 21 07:28:41.690021 2026] [security2:error] [pid 230252:tid 230385] [client 45.8.17.141:29223] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/classwithtostring.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdcgAAApo"]
[Tue Jul 21 07:28:41.736426 2026] [security2:error] [pid 230252:tid 230499] [client 103.162.129.114:49322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J2U0Dwhk5-Z44XrpddQAAAww"]
[Tue Jul 21 07:28:41.736546 2026] [security2:error] [pid 230252:tid 230499] [client 103.162.129.114:49322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J2U0Dwhk5-Z44XrpddQAAAww"]
[Tue Jul 21 07:28:41.810339 2026] [security2:error] [pid 230252:tid 230472] [client 20.104.96.117:62857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdegAAAvE"]
[Tue Jul 21 07:28:41.975750 2026] [security2:error] [pid 230252:tid 230471] [client 213.152.162.104:56846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdfgAAAvA"]
[Tue Jul 21 07:28:41.975865 2026] [security2:error] [pid 230252:tid 230471] [client 213.152.162.104:56846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdfgAAAvA"]
[Tue Jul 21 07:28:41.984667 2026] [security2:error] [pid 229246:tid 229383] [client 20.220.225.223:31204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bumcash.com.br"] [uri "/phpinfo.php1"] [unique_id "al9J2SBMYeh5YLVG45yCQwAAAhs"]
[Tue Jul 21 07:28:42.092221 2026] [security2:error] [pid 230252:tid 230443] [client 20.104.96.117:62908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/media.php"] [unique_id "al9J2k0Dwhk5-Z44XrpdgQAAAtQ"]
[Tue Jul 21 07:28:42.153882 2026] [security2:error] [pid 230252:tid 230454] [client 172.245.102.46:26313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9J2E0Dwhk5-Z44XrpdaQAAAt8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:42.348746 2026] [security2:error] [pid 229246:tid 229412] [client 20.197.195.24:12408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/8.php"] [unique_id "al9J2iBMYeh5YLVG45yCRQAAAjg"]
[Tue Jul 21 07:28:42.375528 2026] [security2:error] [pid 230252:tid 230448] [client 20.104.96.117:62418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/images.php"] [unique_id "al9J2k0Dwhk5-Z44XrpdggAAAtk"]
[Tue Jul 21 07:28:42.662210 2026] [security2:error] [pid 230252:tid 230401] [client 20.104.96.117:62875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/gecko.php"] [unique_id "al9J2k0Dwhk5-Z44XrpdiAAAAqo"]
[Tue Jul 21 07:28:42.689056 2026] [security2:error] [pid 230252:tid 230481] [client 74.7.175.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/index.php"] [unique_id "al9J2U0Dwhk5-Z44XrpdewAAAvo"]
[Tue Jul 21 07:28:42.689863 2026] [security2:error] [pid 230252:tid 230504] [client 74.7.175.130:56058] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/robots.txt"] [unique_id "al9J2U0Dwhk5-Z44XrpddgADEUI"]
[Tue Jul 21 07:28:42.761173 2026] [security2:error] [pid 230252:tid 230309] [remote 40.77.167.123:5125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/produtos-mercado.php"] [unique_id "al9J2k0Dwhk5-Z44XrpdiQAC9zc"]
[Tue Jul 21 07:28:42.943638 2026] [security2:error] [pid 230252:tid 230399] [client 20.104.96.117:62435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/82.php"] [unique_id "al9J2k0Dwhk5-Z44XrpdjQAAAqg"]
[Tue Jul 21 07:28:43.258238 2026] [security2:error] [pid 230252:tid 230449] [client 20.104.96.117:62862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/admin.php"] [unique_id "al9J200Dwhk5-Z44XrpdjwAAAto"]
[Tue Jul 21 07:28:43.479481 2026] [security2:error] [pid 230252:tid 230393] [client 20.220.225.223:8934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/2352356666.php"] [unique_id "al9J200Dwhk5-Z44XrpdlgAAAqI"]
[Tue Jul 21 07:28:43.488581 2026] [security2:error] [pid 229246:tid 229378] [client 20.197.195.24:12307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9J2yBMYeh5YLVG45yCWQAAAhY"]
[Tue Jul 21 07:28:43.503073 2026] [security2:error] [pid 229246:tid 229444] [client 20.151.10.161:48603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/xxx.php"] [unique_id "al9J2yBMYeh5YLVG45yCWgAAAlg"]
[Tue Jul 21 07:28:43.563847 2026] [security2:error] [pid 230252:tid 230472] [client 20.104.96.117:62417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/adminner.php"] [unique_id "al9J200Dwhk5-Z44XrpdmQAAAvE"]
[Tue Jul 21 07:28:43.586660 2026] [security2:error] [pid 229246:tid 229487] [client 45.8.17.110:24301] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/gallery/"] [unique_id "al9J2yBMYeh5YLVG45yCbgAAAoM"]
[Tue Jul 21 07:28:43.625090 2026] [security2:error] [pid 230252:tid 230335] [remote 128.0.83.186:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.83.0.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J200Dwhk5-Z44XrpdmgACmVA"]
[Tue Jul 21 07:28:43.625239 2026] [security2:error] [pid 230252:tid 230384] [client 128.0.83.186:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "botzappro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J200Dwhk5-Z44XrpdmgACmVA"]
[Tue Jul 21 07:28:44.073051 2026] [security2:error] [pid 230252:tid 230509] [client 20.104.96.117:62902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/admin.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdnwAAAxY"]
[Tue Jul 21 07:28:44.393040 2026] [security2:error] [pid 230252:tid 230470] [client 20.104.96.117:6293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/k.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdqwAAAu8"]
[Tue Jul 21 07:28:44.442562 2026] [security2:error] [pid 229246:tid 229420] [client 20.104.96.117:59816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/popo.php"] [unique_id "al9J3CBMYeh5YLVG45yCfQAAAkA"]
[Tue Jul 21 07:28:44.469343 2026] [security2:error] [pid 230252:tid 230452] [client 20.197.195.24:12323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/f6.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdrgAAAt0"]
[Tue Jul 21 07:28:44.520829 2026] [security2:error] [pid 229246:tid 229501] [client 20.151.10.161:49120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/hypo.php"] [unique_id "al9J3CBMYeh5YLVG45yCfwAAApE"]
[Tue Jul 21 07:28:44.737836 2026] [security2:error] [pid 230252:tid 230504] [client 20.104.96.117:62852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/blurbs.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdswAAAxE"]
[Tue Jul 21 07:28:44.821477 2026] [security2:error] [pid 230252:tid 230424] [client 20.220.225.223:8948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/pn.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdtAAAAsE"]
[Tue Jul 21 07:28:44.851560 2026] [security2:error] [pid 230252:tid 230429] [client 20.197.195.24:12357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/inputs.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdtQAAAsY"]
[Tue Jul 21 07:28:45.034205 2026] [security2:error] [pid 230252:tid 230400] [client 20.104.96.117:62901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/bajah.php"] [unique_id "al9J3U0Dwhk5-Z44XrpduAAAAqk"]
[Tue Jul 21 07:28:45.074558 2026] [security2:error] [pid 230252:tid 230463] [client 20.52.136.55:1740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/chosen.php"] [unique_id "al9J3U0Dwhk5-Z44XrpduQAAAug"]
[Tue Jul 21 07:28:45.114631 2026] [security2:error] [pid 230252:tid 230486] [client 20.197.195.24:12410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/inputs.php"] [unique_id "al9J3U0Dwhk5-Z44XrpduwAAAv8"]
[Tue Jul 21 07:28:45.285333 2026] [security2:error] [pid 230252:tid 230385] [client 45.8.17.57:63385] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/widgets/images/"] [unique_id "al9J3U0Dwhk5-Z44XrpdvQAAApo"]
[Tue Jul 21 07:28:45.408693 2026] [security2:error] [pid 229246:tid 229492] [client 20.104.96.117:62416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/a.php"] [unique_id "al9J3SBMYeh5YLVG45yCkAAAAog"]
[Tue Jul 21 07:28:45.432576 2026] [security2:error] [pid 229246:tid 229407] [client 20.197.195.24:12289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/classwithtostring.php"] [unique_id "al9J3SBMYeh5YLVG45yCkQAAAjM"]
[Tue Jul 21 07:28:45.490355 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:45.490437 2026] [proxy_http:error] [pid 230252:tid 230437] [client 20.151.10.161:49039] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:45.490775 2026] [security2:error] [pid 229246:tid 229447] [client 20.197.195.24:12318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9J3SBMYeh5YLVG45yCkwAAAls"]
[Tue Jul 21 07:28:45.491142 2026] [proxy:error] [pid 230252:tid 230437] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:45.491168 2026] [proxy_http:error] [pid 230252:tid 230437] [client 20.151.10.161:49039] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:45.613922 2026] [security2:error] [pid 229246:tid 229489] [client 20.197.195.24:12370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-blog.php"] [unique_id "al9J3SBMYeh5YLVG45yClQAAAoU"]
[Tue Jul 21 07:28:45.832027 2026] [security2:error] [pid 229246:tid 229498] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/index.php"] [unique_id "al9J3SBMYeh5YLVG45yCmwAAAo4"]
[Tue Jul 21 07:28:45.832906 2026] [security2:error] [pid 229246:tid 229490] [client 20.10.88.227:2244] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/robots.txt"] [unique_id "al9J3SBMYeh5YLVG45yCmQAAAoY"]
[Tue Jul 21 07:28:45.864991 2026] [autoindex:error] [pid 230252:tid 230501] [client 20.197.195.24:12306] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:45.869721 2026] [security2:error] [pid 229246:tid 229384] [client 20.104.96.117:62430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/edit.php"] [unique_id "al9J3SBMYeh5YLVG45yCnAAAAhw"]
[Tue Jul 21 07:28:45.958027 2026] [security2:error] [pid 230252:tid 230419] [client 20.197.195.24:12306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9J3U0Dwhk5-Z44XrpdxwAAArw"]
[Tue Jul 21 07:28:46.088359 2026] [security2:error] [pid 230252:tid 230422] [client 45.8.17.49:54529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/imgareaselect/"] [unique_id "al9J3k0Dwhk5-Z44XrpdyAAAAr8"]
[Tue Jul 21 07:28:46.161261 2026] [security2:error] [pid 229246:tid 229439] [client 20.104.96.117:62905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/hosty.php"] [unique_id "al9J3iBMYeh5YLVG45yCoQAAAlM"]
[Tue Jul 21 07:28:46.197995 2026] [security2:error] [pid 230252:tid 230452] [client 20.197.195.24:12326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ms-edit.php"] [unique_id "al9J3k0Dwhk5-Z44XrpdzQAAAt0"]
[Tue Jul 21 07:28:46.272957 2026] [security2:error] [pid 230252:tid 230401] [client 20.151.10.161:49143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/chosen.php"] [unique_id "al9J3k0Dwhk5-Z44XrpdzwAAAqo"]
[Tue Jul 21 07:28:46.300461 2026] [security2:error] [pid 229246:tid 229473] [client 45.251.232.145:54802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J3iBMYeh5YLVG45yCpAAAAnU"]
[Tue Jul 21 07:28:46.300586 2026] [security2:error] [pid 229246:tid 229473] [client 45.251.232.145:54802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J3iBMYeh5YLVG45yCpAAAAnU"]
[Tue Jul 21 07:28:46.418576 2026] [security2:error] [pid 229246:tid 229497] [client 20.220.225.223:62122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9J3iBMYeh5YLVG45yCpgAAAo0"]
[Tue Jul 21 07:28:46.521576 2026] [security2:error] [pid 229246:tid 229394] [client 20.197.195.24:12319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9J3iBMYeh5YLVG45yCqQAAAiY"]
[Tue Jul 21 07:28:46.599008 2026] [security2:error] [pid 229246:tid 229484] [client 20.104.96.117:62874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/k.php"] [unique_id "al9J3iBMYeh5YLVG45yCqwAAAoA"]
[Tue Jul 21 07:28:46.662159 2026] [security2:error] [pid 230252:tid 230468] [client 138.249.169.117:9983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.169.249.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-comments-post.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdrwAAAu0"], referer: https://evelinemilfontadv.com/2022/04/16/hello-world/#comment-3072
[Tue Jul 21 07:28:46.662267 2026] [security2:error] [pid 230252:tid 230468] [client 138.249.169.117:9983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "evelinemilfontadv.com"] [uri "/wp-comments-post.php"] [unique_id "al9J3E0Dwhk5-Z44XrpdrwAAAu0"], referer: https://evelinemilfontadv.com/2022/04/16/hello-world/#comment-3072
[Tue Jul 21 07:28:46.761050 2026] [autoindex:error] [pid 229246:tid 229391] [client 20.197.195.24:12317] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:46.770042 2026] [security2:error] [pid 229246:tid 229395] [client 20.197.195.24:12317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9J3iBMYeh5YLVG45yCrwAAAic"]
[Tue Jul 21 07:28:46.770306 2026] [security2:error] [pid 230252:tid 230487] [client 139.135.44.145:54573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J3k0Dwhk5-Z44Xrpd1wAAAwA"]
[Tue Jul 21 07:28:46.770417 2026] [security2:error] [pid 230252:tid 230487] [client 139.135.44.145:54573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J3k0Dwhk5-Z44Xrpd1wAAAwA"]
[Tue Jul 21 07:28:46.833465 2026] [security2:error] [pid 230252:tid 230498] [client 193.36.225.58:29555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9J3k0Dwhk5-Z44Xrpd2wAAAws"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:46.884243 2026] [security2:error] [pid 229246:tid 229299] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J3iBMYeh5YLVG45yCsQACQzQ"]
[Tue Jul 21 07:28:46.884432 2026] [security2:error] [pid 229246:tid 229423] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J3iBMYeh5YLVG45yCsQACQzQ"]
[Tue Jul 21 07:28:46.901181 2026] [security2:error] [pid 230252:tid 230397] [client 20.104.96.117:62855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/aaa.php"] [unique_id "al9J3k0Dwhk5-Z44Xrpd3AAAAqY"]
[Tue Jul 21 07:28:46.930910 2026] [autoindex:error] [pid 229246:tid 229501] [client 20.197.195.24:12405] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:46.975353 2026] [autoindex:error] [pid 229246:tid 229461] [client 20.197.195.24:12405] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:46.982200 2026] [security2:error] [pid 230252:tid 230499] [client 45.8.17.62:38871] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "al9J3k0Dwhk5-Z44Xrpd3gAAAww"]
[Tue Jul 21 07:28:47.004415 2026] [security2:error] [pid 229246:tid 229430] [client 20.197.195.24:12405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/abcd.php"] [unique_id "al9J3yBMYeh5YLVG45yCtwAAAko"]
[Tue Jul 21 07:28:47.054823 2026] [security2:error] [pid 230252:tid 230496] [client 117.251.86.144:49588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J300Dwhk5-Z44Xrpd4AAAAwk"]
[Tue Jul 21 07:28:47.054944 2026] [security2:error] [pid 230252:tid 230496] [client 117.251.86.144:49588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J300Dwhk5-Z44Xrpd4AAAAwk"]
[Tue Jul 21 07:28:47.080262 2026] [proxy:error] [pid 229246:tid 229400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:47.080338 2026] [proxy_http:error] [pid 229246:tid 229400] [client 20.151.10.161:49099] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:47.080858 2026] [proxy:error] [pid 229246:tid 229400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:28:47.080881 2026] [proxy_http:error] [pid 229246:tid 229400] [client 20.151.10.161:49099] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:28:47.215072 2026] [security2:error] [pid 229246:tid 229425] [client 20.104.96.117:62411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/file5.php"] [unique_id "al9J3yBMYeh5YLVG45yCvgAAAkU"]
[Tue Jul 21 07:28:47.409703 2026] [security2:error] [pid 229246:tid 229457] [client 20.197.195.24:12400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/file15.php"] [unique_id "al9J3yBMYeh5YLVG45yCxwAAAmU"]
[Tue Jul 21 07:28:47.513982 2026] [security2:error] [pid 229246:tid 229502] [client 20.104.96.117:62854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/222.php"] [unique_id "al9J3yBMYeh5YLVG45yCygAAApI"]
[Tue Jul 21 07:28:47.815142 2026] [security2:error] [pid 229246:tid 229412] [client 20.104.96.117:62894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/test.php"] [unique_id "al9J3yBMYeh5YLVG45yC0AAAAjg"]
[Tue Jul 21 07:28:47.862568 2026] [security2:error] [pid 230252:tid 230419] [client 20.52.136.55:1546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/css.php"] [unique_id "al9J300Dwhk5-Z44Xrpd5AAAArw"]
[Tue Jul 21 07:28:48.096622 2026] [security2:error] [pid 229246:tid 229392] [client 45.8.17.125:42757] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/shell/"] [unique_id "al9J4CBMYeh5YLVG45yC0gAAAiQ"]
[Tue Jul 21 07:28:48.124617 2026] [security2:error] [pid 230252:tid 230470] [client 20.104.96.117:62426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/aaa.php"] [unique_id "al9J4E0Dwhk5-Z44Xrpd7QAAAu8"]
[Tue Jul 21 07:28:48.386305 2026] [security2:error] [pid 229246:tid 229350] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J4CBMYeh5YLVG45yC1gACHGc"]
[Tue Jul 21 07:28:48.386438 2026] [security2:error] [pid 229246:tid 229384] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J4CBMYeh5YLVG45yC1gACHGc"]
[Tue Jul 21 07:28:48.493571 2026] [security2:error] [pid 229246:tid 229402] [client 20.104.96.117:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/11.php"] [unique_id "al9J4CBMYeh5YLVG45yC2AAAAi4"]
[Tue Jul 21 07:28:48.535091 2026] [security2:error] [pid 230252:tid 230488] [client 20.151.10.161:49057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/als.php"] [unique_id "al9J4E0Dwhk5-Z44Xrpd_wAAAwE"]
[Tue Jul 21 07:28:48.618200 2026] [security2:error] [pid 230252:tid 230446] [client 20.104.96.117:59595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/yas.php"] [unique_id "al9J4E0Dwhk5-Z44XrpeAgAAAtc"]
[Tue Jul 21 07:28:48.711039 2026] [security2:error] [pid 230252:tid 230425] [client 20.197.195.24:20566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/jp.php"] [unique_id "al9J4E0Dwhk5-Z44XrpeAwAAAsI"]
[Tue Jul 21 07:28:48.762185 2026] [security2:error] [pid 229246:tid 229386] [client 35.196.36.160:49386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.36.196.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "protagonbh.produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9J4CBMYeh5YLVG45yC3wAAAh4"]
[Tue Jul 21 07:28:48.762288 2026] [security2:error] [pid 229246:tid 229386] [client 35.196.36.160:49386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "protagonbh.produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9J4CBMYeh5YLVG45yC3wAAAh4"]
[Tue Jul 21 07:28:48.813451 2026] [security2:error] [pid 229246:tid 229456] [client 20.104.96.117:62446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/mac.php"] [unique_id "al9J4CBMYeh5YLVG45yC5AAAAmQ"]
[Tue Jul 21 07:28:49.097452 2026] [security2:error] [pid 230252:tid 230479] [client 45.8.17.49:53349] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/mini.php"] [unique_id "al9J4U0Dwhk5-Z44XrpeBgAAAvg"]
[Tue Jul 21 07:28:49.099331 2026] [security2:error] [pid 230252:tid 230433] [client 20.104.96.117:62861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/chosen.php"] [unique_id "al9J4U0Dwhk5-Z44XrpeBwAAAso"]
[Tue Jul 21 07:28:49.190010 2026] [security2:error] [pid 230252:tid 230464] [client 20.151.10.161:49030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/pol.php"] [unique_id "al9J4U0Dwhk5-Z44XrpeDgAAAuk"]
[Tue Jul 21 07:28:49.439648 2026] [security2:error] [pid 230252:tid 230449] [client 20.197.195.24:12378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/f35.php"] [unique_id "al9J4U0Dwhk5-Z44XrpeDwAAAto"]
[Tue Jul 21 07:28:49.574492 2026] [security2:error] [pid 230252:tid 230393] [client 20.104.96.117:62415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/cream1.php"] [unique_id "al9J4U0Dwhk5-Z44XrpeFgAAAqI"]
[Tue Jul 21 07:28:49.751327 2026] [security2:error] [pid 229246:tid 229501] [client 20.151.10.161:49037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file5.php"] [unique_id "al9J4SBMYeh5YLVG45yC8QAAApE"]
[Tue Jul 21 07:28:50.009673 2026] [security2:error] [pid 230252:tid 230474] [client 103.106.20.201:55417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J4k0Dwhk5-Z44XrpeIAAAAvM"]
[Tue Jul 21 07:28:50.009777 2026] [security2:error] [pid 230252:tid 230474] [client 103.106.20.201:55417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J4k0Dwhk5-Z44XrpeIAAAAvM"]
[Tue Jul 21 07:28:50.051255 2026] [autoindex:error] [pid 229246:tid 229398] [client 20.104.96.117:62909] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:50.091434 2026] [security2:error] [pid 230252:tid 230501] [client 45.8.17.115:48271] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/admin/function.php"] [unique_id "al9J4k0Dwhk5-Z44XrpeIQAAAw4"]
[Tue Jul 21 07:28:50.351557 2026] [access_compat:error] [pid 230252:tid 230471] [client 162.241.63.68:46212] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:28:50.361987 2026] [autoindex:error] [pid 229246:tid 229421] [client 20.104.96.117:62909] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:50.375996 2026] [security2:error] [pid 230252:tid 230448] [client 20.197.195.24:20588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-load.php"] [unique_id "al9J4k0Dwhk5-Z44XrpeJgAAAtk"]
[Tue Jul 21 07:28:50.500652 2026] [security2:error] [pid 229246:tid 229485] [client 20.104.96.117:62909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/dr.php"] [unique_id "al9J4iBMYeh5YLVG45yC_gAAAoE"]
[Tue Jul 21 07:28:50.988045 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:7045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/x.php"] [unique_id "al9J4k0Dwhk5-Z44XrpeNgAAAuk"]
[Tue Jul 21 07:28:51.053107 2026] [security2:error] [pid 229246:tid 229282] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDCQACkiM"]
[Tue Jul 21 07:28:51.053315 2026] [security2:error] [pid 229246:tid 229502] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDCQACkiM"]
[Tue Jul 21 07:28:51.115453 2026] [security2:error] [pid 230252:tid 230350] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeNwAC_18"]
[Tue Jul 21 07:28:51.115699 2026] [security2:error] [pid 230252:tid 230486] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeNwAC_18"]
[Tue Jul 21 07:28:51.118833 2026] [security2:error] [pid 230252:tid 230455] [client 20.151.10.161:49059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9J400Dwhk5-Z44XrpeOAAAAuA"]
[Tue Jul 21 07:28:51.166688 2026] [security2:error] [pid 229246:tid 229503] [client 103.174.34.15:51122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDCgAAApM"]
[Tue Jul 21 07:28:51.166876 2026] [security2:error] [pid 229246:tid 229503] [client 103.174.34.15:51122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDCgAAApM"]
[Tue Jul 21 07:28:51.185466 2026] [security2:error] [pid 230252:tid 230449] [client 213.152.162.104:59742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeOgAAAto"]
[Tue Jul 21 07:28:51.185612 2026] [security2:error] [pid 230252:tid 230449] [client 213.152.162.104:59742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeOgAAAto"]
[Tue Jul 21 07:28:51.191152 2026] [security2:error] [pid 230252:tid 230472] [client 45.8.17.136:20787] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/config.php"] [unique_id "al9J400Dwhk5-Z44XrpeOwAAAvE"]
[Tue Jul 21 07:28:51.198705 2026] [security2:error] [pid 230252:tid 230451] [client 74.7.241.144:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "luizmarceloferreirac1748361311214.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9J400Dwhk5-Z44XrpePAAC3Aw"]
[Tue Jul 21 07:28:51.229330 2026] [security2:error] [pid 230252:tid 230385] [client 141.11.107.74:60380] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.jornalbrasileiro.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9J400Dwhk5-Z44XrpePgAAApo"]
[Tue Jul 21 07:28:51.234220 2026] [security2:error] [pid 230252:tid 230496] [client 141.11.107.74:60384] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.jornalbrasileiro.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9J400Dwhk5-Z44XrpePwAAAwk"]
[Tue Jul 21 07:28:51.242320 2026] [security2:error] [pid 230252:tid 230402] [client 141.11.107.74:60386] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.jornalbrasileiro.com.br"] [uri "/"] [unique_id "al9J400Dwhk5-Z44XrpeQAAAAqs"]
[Tue Jul 21 07:28:51.283991 2026] [security2:error] [pid 229246:tid 229437] [client 20.197.195.24:12404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/xyn.php"] [unique_id "al9J4yBMYeh5YLVG45yDCwAAAlE"]
[Tue Jul 21 07:28:51.289559 2026] [security2:error] [pid 230252:tid 230438] [client 141.11.107.74:60419] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.jornalbrasileiro.com.br"] [uri "/"] [unique_id "al9J400Dwhk5-Z44XrpeQQAAAs8"]
[Tue Jul 21 07:28:51.290209 2026] [security2:error] [pid 229246:tid 229436] [client 141.11.107.74:60420] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jornalbrasileiro.com.br"] [uri "/"] [unique_id "al9J4yBMYeh5YLVG45yDDAAAAlA"]
[Tue Jul 21 07:28:51.337228 2026] [security2:error] [pid 230252:tid 230341] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeQwACplY"]
[Tue Jul 21 07:28:51.337417 2026] [security2:error] [pid 230252:tid 230397] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeQwACplY"]
[Tue Jul 21 07:28:51.419670 2026] [security2:error] [pid 230252:tid 230399] [client 59.96.220.140:51449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeRQAAAqg"]
[Tue Jul 21 07:28:51.420374 2026] [security2:error] [pid 230252:tid 230399] [client 59.96.220.140:51449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeRQAAAqg"]
[Tue Jul 21 07:28:51.428286 2026] [security2:error] [pid 230252:tid 230508] [client 20.104.96.117:62438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/155.php"] [unique_id "al9J400Dwhk5-Z44XrpeRgAAAxU"]
[Tue Jul 21 07:28:51.439184 2026] [security2:error] [pid 230252:tid 230471] [client 141.11.107.74:60528] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.jornalbrasileiro.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9J400Dwhk5-Z44XrpeRwAAAvA"]
[Tue Jul 21 07:28:51.482706 2026] [security2:error] [pid 230252:tid 230461] [client 141.11.107.74:60546] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.jornalbrasileiro.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9J400Dwhk5-Z44XrpeTQAAAuY"]
[Tue Jul 21 07:28:51.558323 2026] [security2:error] [pid 229246:tid 229470] [client 154.192.233.199:60532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDEAAAAnI"]
[Tue Jul 21 07:28:51.558708 2026] [security2:error] [pid 229246:tid 229470] [client 154.192.233.199:60532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDEAAAAnI"]
[Tue Jul 21 07:28:51.648196 2026] [security2:error] [pid 230252:tid 230422] [client 74.7.241.157:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.agencia.aede.com.br"] [uri "/index.php"] [unique_id "al9J400Dwhk5-Z44XrpeSwAAAr8"]
[Tue Jul 21 07:28:51.648832 2026] [security2:error] [pid 230252:tid 230386] [client 74.7.241.157:44802] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.agencia.aede.com.br"] [uri "/robots.txt"] [unique_id "al9J400Dwhk5-Z44XrpeSAACm2Y"]
[Tue Jul 21 07:28:51.662010 2026] [security2:error] [pid 230252:tid 230442] [client 136.144.33.97:38803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9J400Dwhk5-Z44XrpeTgAAAtM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:51.766551 2026] [security2:error] [pid 230252:tid 230401] [client 20.52.136.55:1587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/php.php"] [unique_id "al9J400Dwhk5-Z44XrpeUAAAAqo"]
[Tue Jul 21 07:28:51.787278 2026] [security2:error] [pid 230252:tid 230495] [client 175.45.70.82:58282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeUQAAAwg"]
[Tue Jul 21 07:28:51.787397 2026] [security2:error] [pid 230252:tid 230495] [client 175.45.70.82:58282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeUQAAAwg"]
[Tue Jul 21 07:28:51.814192 2026] [security2:error] [pid 230252:tid 230372] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeUwACvHU"]
[Tue Jul 21 07:28:51.814327 2026] [security2:error] [pid 230252:tid 230419] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J400Dwhk5-Z44XrpeUwACvHU"]
[Tue Jul 21 07:28:51.896437 2026] [security2:error] [pid 229246:tid 229447] [client 213.152.162.104:47776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDEwAAAls"]
[Tue Jul 21 07:28:51.896606 2026] [security2:error] [pid 229246:tid 229447] [client 213.152.162.104:47776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9J4yBMYeh5YLVG45yDEwAAAls"]
[Tue Jul 21 07:28:51.950066 2026] [security2:error] [pid 229246:tid 229452] [client 20.104.96.117:62419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ops.php"] [unique_id "al9J4yBMYeh5YLVG45yDFAAAAmA"]
[Tue Jul 21 07:28:52.192798 2026] [security2:error] [pid 230252:tid 230480] [client 45.8.17.114:49611] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/m.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeVwAAAvk"]
[Tue Jul 21 07:28:52.227957 2026] [security2:error] [pid 230252:tid 230510] [client 103.162.129.114:49755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeWAAAAxc"]
[Tue Jul 21 07:28:52.228102 2026] [security2:error] [pid 230252:tid 230510] [client 103.162.129.114:49755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeWAAAAxc"]
[Tue Jul 21 07:28:52.294632 2026] [security2:error] [pid 230252:tid 230308] [remote 65.111.9.127:34371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.9.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeVgAC_jY"]
[Tue Jul 21 07:28:52.333396 2026] [security2:error] [pid 230252:tid 230479] [client 20.104.96.117:7098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/file31.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeXAAAAvg"]
[Tue Jul 21 07:28:52.429666 2026] [security2:error] [pid 230252:tid 230455] [client 20.104.96.117:59823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/file61.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeXQAAAuA"]
[Tue Jul 21 07:28:52.446136 2026] [security2:error] [pid 230252:tid 230491] [client 74.7.241.157:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agencia.aede.com.br"] [uri "/index.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeWwAAAwQ"], referer: https://www.agencia.aede.com.br/robots.txt
[Tue Jul 21 07:28:52.447036 2026] [security2:error] [pid 230252:tid 230487] [client 74.7.241.157:44816] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "agencia.aede.com.br"] [uri "/robots.txt"] [unique_id "al9J5E0Dwhk5-Z44XrpeWQADACU"], referer: https://www.agencia.aede.com.br/robots.txt
[Tue Jul 21 07:28:52.469163 2026] [autoindex:error] [pid 230252:tid 230451] [client 20.197.195.24:12388] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:52.536740 2026] [security2:error] [pid 230252:tid 230393] [client 20.151.10.161:49063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeYAAAAqI"]
[Tue Jul 21 07:28:52.597765 2026] [autoindex:error] [pid 230252:tid 230384] [client 20.197.195.24:12388] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:52.775072 2026] [security2:error] [pid 230252:tid 230397] [client 20.104.96.117:7085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/file6.php"] [unique_id "al9J5E0Dwhk5-Z44XrpeZwAAAqY"]
[Tue Jul 21 07:28:53.027306 2026] [security2:error] [pid 230252:tid 230434] [client 20.197.195.24:12388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ccc.php"] [unique_id "al9J5U0Dwhk5-Z44XrpeawAAAss"]
[Tue Jul 21 07:28:53.288906 2026] [security2:error] [pid 229246:tid 229386] [client 45.8.17.121:29793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/"] [unique_id "al9J5SBMYeh5YLVG45yDHAAAAh4"]
[Tue Jul 21 07:28:53.675521 2026] [autoindex:error] [pid 229246:tid 229395] [client 20.104.96.117:6212] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:53.788387 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.195.24:12304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/w.php"] [unique_id "al9J5SBMYeh5YLVG45yDMgAAAik"]
[Tue Jul 21 07:28:53.950830 2026] [security2:error] [pid 229246:tid 229411] [client 20.104.96.117:6212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/adminfuns.php"] [unique_id "al9J5SBMYeh5YLVG45yDNQAAAjc"]
[Tue Jul 21 07:28:53.970404 2026] [security2:error] [pid 229246:tid 229362] [remote 103.28.36.122:36914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inovasoulfigital.com"] [uri "/wp-login.php"] [unique_id "al9J5SBMYeh5YLVG45yDNgACjXM"]
[Tue Jul 21 07:28:53.996564 2026] [security2:error] [pid 230252:tid 230458] [client 20.151.10.161:49134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/cfile.php"] [unique_id "al9J5U0Dwhk5-Z44XrpefgAAAuM"]
[Tue Jul 21 07:28:54.001213 2026] [security2:error] [pid 229246:tid 229388] [client 109.248.148.246:44320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9J5SBMYeh5YLVG45yDNwAAAiA"]
[Tue Jul 21 07:28:54.001286 2026] [security2:error] [pid 229246:tid 229388] [client 109.248.148.246:44320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9J5SBMYeh5YLVG45yDNwAAAiA"]
[Tue Jul 21 07:28:54.199050 2026] [security2:error] [pid 230252:tid 230449] [client 20.104.96.117:42385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/water.php"] [unique_id "al9J5k0Dwhk5-Z44XrpegQAAAto"]
[Tue Jul 21 07:28:54.357550 2026] [security2:error] [pid 230252:tid 230433] [client 20.197.195.24:12335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9J5k0Dwhk5-Z44XrpehAAAAso"]
[Tue Jul 21 07:28:54.662354 2026] [security2:error] [pid 229246:tid 229387] [client 20.104.96.117:62423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/goods.php"] [unique_id "al9J5iBMYeh5YLVG45yDQAAAAh8"]
[Tue Jul 21 07:28:55.062280 2026] [security2:error] [pid 229246:tid 229379] [client 20.151.10.161:48586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/class-wp.php"] [unique_id "al9J5yBMYeh5YLVG45yDRAAAAhc"]
[Tue Jul 21 07:28:55.179551 2026] [security2:error] [pid 230252:tid 230461] [client 45.8.17.142:50889] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/about.php"] [unique_id "al9J500Dwhk5-Z44XrpekAAAAuY"]
[Tue Jul 21 07:28:55.252435 2026] [security2:error] [pid 229246:tid 229383] [client 20.197.195.24:12390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/FWAZ.php"] [unique_id "al9J5yBMYeh5YLVG45yDSQAAAhs"]
[Tue Jul 21 07:28:55.328646 2026] [security2:error] [pid 229246:tid 229412] [client 20.104.96.117:62409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/100.php"] [unique_id "al9J5yBMYeh5YLVG45yDSwAAAjg"]
[Tue Jul 21 07:28:55.520280 2026] [security2:error] [pid 230252:tid 230455] [client 193.36.225.60:27203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9J500Dwhk5-Z44XrpekQAAAuA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:28:55.533010 2026] [security2:error] [pid 230252:tid 230416] [client 20.104.96.117:59619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/nano.php"] [unique_id "al9J500Dwhk5-Z44XrpekwAAArk"]
[Tue Jul 21 07:28:55.571259 2026] [security2:error] [pid 230252:tid 230394] [client 20.197.195.24:12348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/miru1.php"] [unique_id "al9J500Dwhk5-Z44XrpelgAAAqM"]
[Tue Jul 21 07:28:55.615284 2026] [security2:error] [pid 230252:tid 230419] [client 82.102.28.107:40602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9J500Dwhk5-Z44XrpelwAAArw"]
[Tue Jul 21 07:28:55.615367 2026] [security2:error] [pid 230252:tid 230419] [client 82.102.28.107:40602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9J500Dwhk5-Z44XrpelwAAArw"]
[Tue Jul 21 07:28:55.669474 2026] [security2:error] [pid 230252:tid 230446] [client 20.104.96.117:62867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/about.php"] [unique_id "al9J500Dwhk5-Z44XrpemAAAAtc"]
[Tue Jul 21 07:28:55.801892 2026] [security2:error] [pid 230252:tid 230458] [client 20.151.10.161:49147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/admin.php"] [unique_id "al9J500Dwhk5-Z44XrpenQAAAuM"]
[Tue Jul 21 07:28:55.898745 2026] [security2:error] [pid 230252:tid 230405] [client 20.197.195.24:12308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/aa.php"] [unique_id "al9J500Dwhk5-Z44XrpengAAAq4"]
[Tue Jul 21 07:28:56.001462 2026] [security2:error] [pid 229246:tid 229474] [client 20.104.96.117:62434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/about.php"] [unique_id "al9J6CBMYeh5YLVG45yDUQAAAnY"]
[Tue Jul 21 07:28:56.022973 2026] [security2:error] [pid 230252:tid 230449] [client 213.152.162.104:47784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9J6E0Dwhk5-Z44XrpenwAAAto"]
[Tue Jul 21 07:28:56.023093 2026] [security2:error] [pid 230252:tid 230449] [client 213.152.162.104:47784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9J6E0Dwhk5-Z44XrpenwAAAto"]
[Tue Jul 21 07:28:56.085511 2026] [security2:error] [pid 230252:tid 230472] [client 45.8.17.127:34047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/packed.php"] [unique_id "al9J6E0Dwhk5-Z44XrpeoAAAAvE"]
[Tue Jul 21 07:28:56.372022 2026] [security2:error] [pid 230252:tid 230437] [client 20.104.96.117:62897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/admin.php"] [unique_id "al9J6E0Dwhk5-Z44XrpeogAAAs4"]
[Tue Jul 21 07:28:56.417460 2026] [security2:error] [pid 230252:tid 230415] [client 20.104.96.117:42379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/moon.php"] [unique_id "al9J6E0Dwhk5-Z44XrpepAAAArg"]
[Tue Jul 21 07:28:56.679023 2026] [security2:error] [pid 230252:tid 230446] [client 20.104.96.117:62440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/admin.php"] [unique_id "al9J6E0Dwhk5-Z44XrperAAAAtc"]
[Tue Jul 21 07:28:56.776696 2026] [security2:error] [pid 230252:tid 230473] [client 45.251.232.145:55489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J6E0Dwhk5-Z44XrpergAAAvI"]
[Tue Jul 21 07:28:56.776869 2026] [security2:error] [pid 230252:tid 230473] [client 45.251.232.145:55489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J6E0Dwhk5-Z44XrpergAAAvI"]
[Tue Jul 21 07:28:56.807570 2026] [security2:error] [pid 230252:tid 230480] [client 20.151.10.161:49093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/aa2.php"] [unique_id "al9J6E0Dwhk5-Z44XrperwAAAvk"]
[Tue Jul 21 07:28:56.978257 2026] [security2:error] [pid 230252:tid 230458] [client 20.104.96.117:62876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/themes.php"] [unique_id "al9J6E0Dwhk5-Z44XrpesAAAAuM"]
[Tue Jul 21 07:28:57.210251 2026] [security2:error] [pid 229246:tid 229483] [client 20.197.195.24:12361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/122.php"] [unique_id "al9J6SBMYeh5YLVG45yDXAAAAn8"]
[Tue Jul 21 07:28:57.267869 2026] [autoindex:error] [pid 230252:tid 230486] [client 20.104.96.117:62420] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:57.281288 2026] [security2:error] [pid 230252:tid 230449] [client 45.8.17.141:28083] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyfive/"] [unique_id "al9J6U0Dwhk5-Z44XrpeswAAAto"]
[Tue Jul 21 07:28:57.417859 2026] [security2:error] [pid 230252:tid 230286] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J6U0Dwhk5-Z44XrpetAADACA"]
[Tue Jul 21 07:28:57.418000 2026] [security2:error] [pid 230252:tid 230487] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J6U0Dwhk5-Z44XrpetAADACA"]
[Tue Jul 21 07:28:57.579698 2026] [security2:error] [pid 230252:tid 230421] [client 20.197.195.24:20563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/get.php"] [unique_id "al9J6U0Dwhk5-Z44XrpeuQAAAr4"]
[Tue Jul 21 07:28:57.749015 2026] [security2:error] [pid 229246:tid 229415] [client 139.135.44.145:53495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J6SBMYeh5YLVG45yDZwAAAjs"]
[Tue Jul 21 07:28:57.749127 2026] [security2:error] [pid 229246:tid 229415] [client 139.135.44.145:53495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J6SBMYeh5YLVG45yDZwAAAjs"]
[Tue Jul 21 07:28:57.815947 2026] [security2:error] [pid 229246:tid 229450] [client 117.251.86.144:42636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J6SBMYeh5YLVG45yDaQAAAl4"]
[Tue Jul 21 07:28:57.816084 2026] [security2:error] [pid 229246:tid 229450] [client 117.251.86.144:42636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J6SBMYeh5YLVG45yDaQAAAl4"]
[Tue Jul 21 07:28:58.176044 2026] [security2:error] [pid 230252:tid 230451] [client 59.96.220.140:51918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J6k0Dwhk5-Z44XrpevQAAAtw"]
[Tue Jul 21 07:28:58.176188 2026] [security2:error] [pid 230252:tid 230451] [client 59.96.220.140:51918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J6k0Dwhk5-Z44XrpevQAAAtw"]
[Tue Jul 21 07:28:58.181803 2026] [security2:error] [pid 230252:tid 230402] [client 45.8.17.145:65535] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403x.php"] [unique_id "al9J6k0Dwhk5-Z44XrpevgAAAqs"]
[Tue Jul 21 07:28:58.256227 2026] [security2:error] [pid 229246:tid 229381] [client 20.151.10.161:49148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/ccou.php"] [unique_id "al9J6iBMYeh5YLVG45yDbAAAAhk"]
[Tue Jul 21 07:28:58.349288 2026] [autoindex:error] [pid 229246:tid 229397] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:58.361577 2026] [security2:error] [pid 230252:tid 230399] [client 20.104.96.117:62420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/.well-known/about.php"] [unique_id "al9J6k0Dwhk5-Z44XrpexAAAAqg"]
[Tue Jul 21 07:28:58.434116 2026] [security2:error] [pid 229246:tid 229451] [client 20.104.96.117:42408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-info.php"] [unique_id "al9J6iBMYeh5YLVG45yDbwAAAl8"]
[Tue Jul 21 07:28:58.721277 2026] [security2:error] [pid 230252:tid 230416] [client 20.104.96.117:7070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9J6k0Dwhk5-Z44XrpeyQAAArk"]
[Tue Jul 21 07:28:58.736049 2026] [autoindex:error] [pid 230252:tid 230455] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:58.952209 2026] [autoindex:error] [pid 230252:tid 230446] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:58.958751 2026] [security2:error] [pid 229246:tid 229364] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J6iBMYeh5YLVG45yDewACc3U"]
[Tue Jul 21 07:28:58.958895 2026] [security2:error] [pid 229246:tid 229471] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J6iBMYeh5YLVG45yDewACc3U"]
[Tue Jul 21 07:28:59.031074 2026] [security2:error] [pid 229246:tid 229406] [client 20.104.96.117:7041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wefile.php"] [unique_id "al9J6yBMYeh5YLVG45yDfAAAAjI"]
[Tue Jul 21 07:28:59.161535 2026] [autoindex:error] [pid 229246:tid 229404] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:59.340215 2026] [security2:error] [pid 229246:tid 229468] [client 20.104.96.117:62882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9J6yBMYeh5YLVG45yDgQAAAnA"]
[Tue Jul 21 07:28:59.371810 2026] [autoindex:error] [pid 230252:tid 230491] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:59.391564 2026] [security2:error] [pid 230252:tid 230498] [client 45.8.17.147:41951] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/user/upgrade/"] [unique_id "al9J600Dwhk5-Z44Xrpe9gAAAws"]
[Tue Jul 21 07:28:59.426678 2026] [security2:error] [pid 229246:tid 229487] [client 20.220.225.223:62864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/dr.php"] [unique_id "al9J6yBMYeh5YLVG45yDgwAAAoM"]
[Tue Jul 21 07:28:59.430807 2026] [security2:error] [pid 230252:tid 230506] [client 152.59.154.239:34765] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J600Dwhk5-Z44Xrpe_QAAAxM"]
[Tue Jul 21 07:28:59.430933 2026] [security2:error] [pid 230252:tid 230506] [client 152.59.154.239:34765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J600Dwhk5-Z44Xrpe_QAAAxM"]
[Tue Jul 21 07:28:59.580419 2026] [autoindex:error] [pid 230252:tid 230393] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:59.630089 2026] [security2:error] [pid 229246:tid 229502] [client 20.197.195.24:20575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/as.php"] [unique_id "al9J6yBMYeh5YLVG45yDhgAAApI"]
[Tue Jul 21 07:28:59.789198 2026] [autoindex:error] [pid 230252:tid 230433] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:28:59.796678 2026] [autoindex:error] [pid 230252:tid 230384] [client 20.104.96.117:62903] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:00.004460 2026] [autoindex:error] [pid 230252:tid 230411] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:00.117754 2026] [autoindex:error] [pid 230252:tid 230428] [client 20.104.96.117:62903] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:00.199276 2026] [security2:error] [pid 230252:tid 230452] [client 136.144.33.106:61999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9J7E0Dwhk5-Z44XrpfHwAAAt0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:00.255654 2026] [security2:error] [pid 230252:tid 230419] [client 20.104.96.117:62903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9J7E0Dwhk5-Z44XrpfJQAAArw"]
[Tue Jul 21 07:29:00.484640 2026] [security2:error] [pid 229246:tid 229494] [client 45.8.17.110:30535] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/Diff/"] [unique_id "al9J7CBMYeh5YLVG45yDkwAAAoo"]
[Tue Jul 21 07:29:00.728415 2026] [security2:error] [pid 230252:tid 230504] [client 82.102.28.107:41252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9J7E0Dwhk5-Z44XrpfOgAAAxE"]
[Tue Jul 21 07:29:00.728493 2026] [security2:error] [pid 230252:tid 230504] [client 82.102.28.107:41252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9J7E0Dwhk5-Z44XrpfOgAAAxE"]
[Tue Jul 21 07:29:00.778638 2026] [security2:error] [pid 230252:tid 230455] [client 103.106.20.201:56108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7E0Dwhk5-Z44XrpfPgAAAuA"]
[Tue Jul 21 07:29:00.778750 2026] [security2:error] [pid 230252:tid 230455] [client 103.106.20.201:56108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7E0Dwhk5-Z44XrpfPgAAAuA"]
[Tue Jul 21 07:29:00.792212 2026] [security2:error] [pid 229246:tid 229480] [client 20.104.96.117:62850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/8.php"] [unique_id "al9J7CBMYeh5YLVG45yDlwAAAnw"]
[Tue Jul 21 07:29:01.063655 2026] [security2:error] [pid 230252:tid 230476] [client 20.197.195.24:12411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ccou.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfTgAAAvU"]
[Tue Jul 21 07:29:01.141531 2026] [security2:error] [pid 230252:tid 230391] [client 20.104.96.117:62427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfUgAAAqA"]
[Tue Jul 21 07:29:01.147199 2026] [security2:error] [pid 229246:tid 229417] [client 20.151.10.161:49123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/dr.php"] [unique_id "al9J7SBMYeh5YLVG45yDngAAAj0"]
[Tue Jul 21 07:29:01.489262 2026] [security2:error] [pid 230252:tid 230452] [client 20.104.96.117:62447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/f6.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfXAAAAt0"]
[Tue Jul 21 07:29:01.597101 2026] [security2:error] [pid 230252:tid 230442] [client 45.8.17.107:30661] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/"] [unique_id "al9J7U0Dwhk5-Z44XrpfXQAAAtM"]
[Tue Jul 21 07:29:01.672226 2026] [security2:error] [pid 230252:tid 230282] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfXgACxRw"]
[Tue Jul 21 07:29:01.672491 2026] [security2:error] [pid 230252:tid 230428] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfXgACxRw"]
[Tue Jul 21 07:29:01.759075 2026] [autoindex:error] [pid 230252:tid 230474] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:01.793938 2026] [security2:error] [pid 230252:tid 230467] [client 20.104.96.117:62412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/inputs.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfYgAAAuw"]
[Tue Jul 21 07:29:01.947907 2026] [security2:error] [pid 230252:tid 230300] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfYwAC1y4"]
[Tue Jul 21 07:29:01.948048 2026] [security2:error] [pid 230252:tid 230446] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J7U0Dwhk5-Z44XrpfYwAC1y4"]
[Tue Jul 21 07:29:01.967376 2026] [autoindex:error] [pid 230252:tid 230482] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:02.000994 2026] [security2:error] [pid 230252:tid 230503] [client 20.197.195.24:12321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/w3lls.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfaQAAAxA"]
[Tue Jul 21 07:29:02.057954 2026] [security2:error] [pid 229246:tid 229287] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J7iBMYeh5YLVG45yDqQACaSg"]
[Tue Jul 21 07:29:02.058091 2026] [security2:error] [pid 229246:tid 229461] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J7iBMYeh5YLVG45yDqQACaSg"]
[Tue Jul 21 07:29:02.079244 2026] [security2:error] [pid 230252:tid 230390] [client 103.174.34.15:51613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfagAAAp8"]
[Tue Jul 21 07:29:02.079328 2026] [security2:error] [pid 230252:tid 230390] [client 103.174.34.15:51613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfagAAAp8"]
[Tue Jul 21 07:29:02.102827 2026] [security2:error] [pid 230252:tid 230486] [client 20.104.96.117:7081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/inputs.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfawAAAv8"]
[Tue Jul 21 07:29:02.281661 2026] [security2:error] [pid 230252:tid 230437] [client 20.104.96.117:59811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/2000.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfdQAAAs4"]
[Tue Jul 21 07:29:02.323665 2026] [security2:error] [pid 230252:tid 230311] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfdgACrjk"]
[Tue Jul 21 07:29:02.323821 2026] [security2:error] [pid 230252:tid 230405] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfdgACrjk"]
[Tue Jul 21 07:29:02.360673 2026] [security2:error] [pid 229246:tid 229397] [client 175.45.70.82:58792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7iBMYeh5YLVG45yDqgAAAik"]
[Tue Jul 21 07:29:02.360786 2026] [security2:error] [pid 229246:tid 229397] [client 175.45.70.82:58792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J7iBMYeh5YLVG45yDqgAAAik"]
[Tue Jul 21 07:29:02.386860 2026] [autoindex:error] [pid 230252:tid 230438] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:02.439359 2026] [security2:error] [pid 230252:tid 230432] [client 20.104.96.117:62891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/classwithtostring.php"] [unique_id "al9J7k0Dwhk5-Z44XrpffAAAAsk"]
[Tue Jul 21 07:29:02.485430 2026] [security2:error] [pid 230252:tid 230386] [client 45.8.17.131:26283] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/we.php"] [unique_id "al9J7k0Dwhk5-Z44XrpffQAAAps"]
[Tue Jul 21 07:29:02.583042 2026] [security2:error] [pid 230252:tid 230452] [client 82.102.28.107:41268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpffwAAAt0"]
[Tue Jul 21 07:29:02.583135 2026] [security2:error] [pid 230252:tid 230452] [client 82.102.28.107:41268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpffwAAAt0"]
[Tue Jul 21 07:29:02.596584 2026] [autoindex:error] [pid 230252:tid 230399] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:02.621840 2026] [security2:error] [pid 229246:tid 229453] [client 20.197.195.24:12381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/test1.php"] [unique_id "al9J7iBMYeh5YLVG45yDrQAAAmE"]
[Tue Jul 21 07:29:02.684006 2026] [security2:error] [pid 230252:tid 230479] [client 103.162.129.114:50214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfhQAAAvg"]
[Tue Jul 21 07:29:02.684229 2026] [security2:error] [pid 230252:tid 230479] [client 103.162.129.114:50214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfhQAAAvg"]
[Tue Jul 21 07:29:02.730958 2026] [security2:error] [pid 230252:tid 230445] [client 20.104.96.117:62432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfhwAAAtY"]
[Tue Jul 21 07:29:02.817495 2026] [autoindex:error] [pid 230252:tid 230482] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:02.931255 2026] [security2:error] [pid 230252:tid 230458] [client 204.8.96.141:39388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.96.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfiAAAAuM"]
[Tue Jul 21 07:29:02.931343 2026] [security2:error] [pid 230252:tid 230458] [client 204.8.96.141:39388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfiAAAAuM"]
[Tue Jul 21 07:29:02.942296 2026] [security2:error] [pid 230252:tid 230435] [client 20.220.225.223:62877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/2x.php"] [unique_id "al9J7k0Dwhk5-Z44XrpfjgAAAsw"]
[Tue Jul 21 07:29:03.011108 2026] [security2:error] [pid 230252:tid 230413] [client 20.104.96.117:62444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-blog.php"] [unique_id "al9J700Dwhk5-Z44XrpfjwAAArY"]
[Tue Jul 21 07:29:03.030387 2026] [autoindex:error] [pid 230252:tid 230455] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:03.044382 2026] [security2:error] [pid 230252:tid 230486] [client 20.52.136.55:1763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/aa.php"] [unique_id "al9J700Dwhk5-Z44XrpfkwAAAv8"]
[Tue Jul 21 07:29:03.235869 2026] [security2:error] [pid 230252:tid 230384] [client 213.152.162.104:45002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9J700Dwhk5-Z44XrpfmAAAApk"]
[Tue Jul 21 07:29:03.235987 2026] [security2:error] [pid 230252:tid 230384] [client 213.152.162.104:45002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9J700Dwhk5-Z44XrpfmAAAApk"]
[Tue Jul 21 07:29:03.238987 2026] [autoindex:error] [pid 230252:tid 230454] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:03.310274 2026] [autoindex:error] [pid 230252:tid 230405] [client 20.104.96.117:62859] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:03.405598 2026] [security2:error] [pid 229246:tid 229423] [client 45.146.55.205:33795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lumerah.com.br"] [uri "/wp-login.php"] [unique_id "al9J7yBMYeh5YLVG45yDsgAAAkM"]
[Tue Jul 21 07:29:03.494346 2026] [security2:error] [pid 230252:tid 230411] [client 20.197.195.24:12402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/database.php"] [unique_id "al9J700Dwhk5-Z44XrpfowAAArQ"]
[Tue Jul 21 07:29:03.593669 2026] [security2:error] [pid 230252:tid 230470] [client 45.8.17.146:60449] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/neve/assets/apps/dashboard/build/"] [unique_id "al9J700Dwhk5-Z44XrpfpgAAAu8"]
[Tue Jul 21 07:29:03.595904 2026] [security2:error] [pid 230252:tid 230484] [client 20.104.96.117:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9J700Dwhk5-Z44XrpfpwAAAv0"]
[Tue Jul 21 07:29:03.631941 2026] [security2:error] [pid 230252:tid 230417] [client 20.104.96.117:42370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/122.php"] [unique_id "al9J700Dwhk5-Z44XrpfqAAAAro"]
[Tue Jul 21 07:29:03.642271 2026] [security2:error] [pid 230252:tid 230448] [client 34.11.127.22:58271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.127.11.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J700Dwhk5-Z44XrpfqQAAAtk"]
[Tue Jul 21 07:29:03.681952 2026] [security2:error] [pid 230252:tid 230452] [client 34.11.127.22:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.127.11.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ajsdiesel.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J700Dwhk5-Z44XrpfqgAAAt0"]
[Tue Jul 21 07:29:03.827947 2026] [security2:error] [pid 230252:tid 230424] [client 172.245.102.45:22787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9J700Dwhk5-Z44XrpfsQAAAsE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:03.938823 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:62413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ms-edit.php"] [unique_id "al9J700Dwhk5-Z44XrpfswAAAsI"]
[Tue Jul 21 07:29:04.009982 2026] [security2:error] [pid 230252:tid 230403] [client 34.11.127.22:61054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9J8E0Dwhk5-Z44XrpftAAAAqw"]
[Tue Jul 21 07:29:04.026172 2026] [autoindex:error] [pid 229246:tid 229406] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:04.060558 2026] [security2:error] [pid 230252:tid 230473] [client 34.11.127.22:57996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9J8E0Dwhk5-Z44XrpfuAAAAvI"]
[Tue Jul 21 07:29:04.143035 2026] [security2:error] [pid 230252:tid 230435] [client 20.151.10.161:49095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/xamp.php"] [unique_id "al9J8E0Dwhk5-Z44XrpfuQAAAsw"]
[Tue Jul 21 07:29:04.211303 2026] [security2:error] [pid 230252:tid 230409] [client 20.197.195.24:12362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/file.php"] [unique_id "al9J8E0Dwhk5-Z44XrpfugAAArI"]
[Tue Jul 21 07:29:04.229447 2026] [cgid:error] [pid 230252:tid 230455] [client 82.102.18.182:0] AH01265: stderr from /home1/asse7722/public_html/cgi-bin/: attempt to invoke directory as script
[Tue Jul 21 07:29:04.244126 2026] [security2:error] [pid 229246:tid 229459] [client 20.104.96.117:62403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9J8CBMYeh5YLVG45yDuwAAAmc"]
[Tue Jul 21 07:29:04.260114 2026] [security2:error] [pid 230252:tid 230460] [client 34.11.127.22:55532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9J8E0Dwhk5-Z44XrpfvgAAAuU"]
[Tue Jul 21 07:29:04.385347 2026] [security2:error] [pid 229246:tid 229468] [client 45.8.17.128:42955] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/dist/"] [unique_id "al9J8CBMYeh5YLVG45yDvAAAAnA"]
[Tue Jul 21 07:29:04.387281 2026] [security2:error] [pid 230252:tid 230498] [client 34.11.127.22:59567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9J8E0Dwhk5-Z44XrpfwgAAAws"]
[Tue Jul 21 07:29:04.547891 2026] [autoindex:error] [pid 230252:tid 230411] [client 20.104.96.117:62422] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:04.586236 2026] [security2:error] [pid 229246:tid 229412] [client 34.11.127.22:55754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9J8CBMYeh5YLVG45yDvwAAAjg"]
[Tue Jul 21 07:29:04.630514 2026] [security2:error] [pid 229246:tid 229503] [client 20.197.195.24:12412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/file.php"] [unique_id "al9J8CBMYeh5YLVG45yDwQAAApM"]
[Tue Jul 21 07:29:04.660404 2026] [security2:error] [pid 229246:tid 229466] [client 34.11.127.22:59774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9J8CBMYeh5YLVG45yDwwAAAm4"]
[Tue Jul 21 07:29:04.758910 2026] [security2:error] [pid 230252:tid 230438] [client 20.197.195.24:20496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/777.php"] [unique_id "al9J8E0Dwhk5-Z44XrpfzAAAAs8"]
[Tue Jul 21 07:29:04.830716 2026] [security2:error] [pid 230252:tid 230417] [client 20.104.96.117:62422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9J8E0Dwhk5-Z44XrpfzwAAAro"]
[Tue Jul 21 07:29:04.878734 2026] [security2:error] [pid 230252:tid 230474] [client 20.197.195.24:12296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ssixta.php"] [unique_id "al9J8E0Dwhk5-Z44Xrpf0QAAAvM"]
[Tue Jul 21 07:29:04.879773 2026] [security2:error] [pid 230252:tid 230394] [client 34.11.127.22:56273] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9J8E0Dwhk5-Z44Xrpf0gAAAqM"]
[Tue Jul 21 07:29:04.929518 2026] [security2:error] [pid 230252:tid 230416] [client 34.11.127.22:53534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9J8E0Dwhk5-Z44Xrpf0wAAArk"]
[Tue Jul 21 07:29:04.932995 2026] [security2:error] [pid 229246:tid 229463] [client 204.8.96.141:39392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.96.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J8CBMYeh5YLVG45yDxwAAAms"]
[Tue Jul 21 07:29:04.933122 2026] [security2:error] [pid 229246:tid 229463] [client 204.8.96.141:39392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J8CBMYeh5YLVG45yDxwAAAms"]
[Tue Jul 21 07:29:05.137386 2026] [autoindex:error] [pid 230252:tid 230500] [client 20.104.96.117:62453] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:05.192381 2026] [security2:error] [pid 230252:tid 230485] [client 34.11.127.22:50295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9J8U0Dwhk5-Z44Xrpf3AAAAv4"]
[Tue Jul 21 07:29:05.228465 2026] [security2:error] [pid 230252:tid 230497] [client 34.11.127.22:53984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9J8U0Dwhk5-Z44Xrpf3QAAAwo"]
[Tue Jul 21 07:29:05.247640 2026] [security2:error] [pid 230252:tid 230458] [client 20.197.195.24:12295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/1c.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf3gAAAuM"]
[Tue Jul 21 07:29:05.387486 2026] [security2:error] [pid 230252:tid 230390] [client 45.8.17.113:55525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/media-text/"] [unique_id "al9J8U0Dwhk5-Z44Xrpf5QAAAp8"]
[Tue Jul 21 07:29:05.420027 2026] [autoindex:error] [pid 230252:tid 230498] [client 20.104.96.117:62453] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:05.466582 2026] [security2:error] [pid 229246:tid 229429] [client 34.11.127.22:54841] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9J8SBMYeh5YLVG45yDywAAAkk"]
[Tue Jul 21 07:29:05.473005 2026] [security2:error] [pid 230252:tid 230487] [client 34.11.127.22:51639] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9J8U0Dwhk5-Z44Xrpf6AAAAwA"]
[Tue Jul 21 07:29:05.570323 2026] [security2:error] [pid 230252:tid 230405] [client 20.104.96.117:62453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/abcd.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf6gAAAq4"]
[Tue Jul 21 07:29:05.657553 2026] [security2:error] [pid 230252:tid 230384] [client 20.197.195.24:20559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/test2.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf8AAAApk"]
[Tue Jul 21 07:29:05.757985 2026] [security2:error] [pid 229246:tid 229480] [client 20.197.195.24:20557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/buy.php"] [unique_id "al9J8SBMYeh5YLVG45yD0gAAAnw"]
[Tue Jul 21 07:29:05.788845 2026] [security2:error] [pid 229246:tid 229403] [client 91.92.47.101:49220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/php_info.php"] [unique_id "al9J8SBMYeh5YLVG45yD0wAAAi8"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.789909 2026] [security2:error] [pid 230252:tid 230432] [client 91.92.47.101:49210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/server_info.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf9AAAAsk"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.798820 2026] [security2:error] [pid 229246:tid 229384] [client 91.92.47.101:49292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/pinfo.php"] [unique_id "al9J8SBMYeh5YLVG45yD1gAAAhw"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.799442 2026] [security2:error] [pid 229246:tid 229449] [client 91.92.47.101:49238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/test.php"] [unique_id "al9J8SBMYeh5YLVG45yD2AAAAl0"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.801074 2026] [security2:error] [pid 230252:tid 230452] [client 91.92.47.101:49248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/functions.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf9gAAAt0"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.801768 2026] [security2:error] [pid 230252:tid 230493] [client 91.92.47.101:49308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/index.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf9wAAAwY"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.801789 2026] [security2:error] [pid 229246:tid 229484] [client 91.92.47.101:49216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/configuration.php"] [unique_id "al9J8SBMYeh5YLVG45yD2QAAAoA"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.802326 2026] [security2:error] [pid 230252:tid 230406] [client 91.92.47.101:49240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/portal/phpinfo.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf-AAAAq8"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.802660 2026] [security2:error] [pid 229246:tid 229394] [client 91.92.47.101:49206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "look.dealspark.com.br"] [uri "/phpinfo/info.php"] [unique_id "al9J8SBMYeh5YLVG45yD3AAAAiY"], referer: http://look.dealspark.com.br/
[Tue Jul 21 07:29:05.848698 2026] [security2:error] [pid 229246:tid 229445] [client 34.11.127.22:60130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9J8SBMYeh5YLVG45yD3gAAAlk"]
[Tue Jul 21 07:29:05.856183 2026] [security2:error] [pid 230252:tid 230477] [client 34.11.127.22:57994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9J8U0Dwhk5-Z44Xrpf-gAAAvY"]
[Tue Jul 21 07:29:05.862952 2026] [security2:error] [pid 230252:tid 230415] [client 20.104.96.117:42413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/mds.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf-wAAArg"]
[Tue Jul 21 07:29:05.869984 2026] [security2:error] [pid 230252:tid 230474] [client 20.104.96.117:62878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/file15.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf_AAAAvM"]
[Tue Jul 21 07:29:05.893618 2026] [security2:error] [pid 230252:tid 230419] [client 20.197.195.24:12344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ssend.php"] [unique_id "al9J8U0Dwhk5-Z44XrpgAAAAArw"]
[Tue Jul 21 07:29:05.960969 2026] [security2:error] [pid 229246:tid 229456] [client 20.197.195.24:12352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/item.php"] [unique_id "al9J8SBMYeh5YLVG45yD4gAAAmQ"]
[Tue Jul 21 07:29:05.974247 2026] [security2:error] [pid 230252:tid 230411] [client 173.252.95.8:36986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf-QAAArQ"]
[Tue Jul 21 07:29:06.117713 2026] [autoindex:error] [pid 230252:tid 230436] [client 186.202.163.107:36877] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/planamoveis.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:06.143033 2026] [security2:error] [pid 229246:tid 229432] [client 34.11.127.22:65146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9J8iBMYeh5YLVG45yD4wAAAkw"]
[Tue Jul 21 07:29:06.150233 2026] [security2:error] [pid 229246:tid 229451] [client 34.11.127.22:57265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9J8iBMYeh5YLVG45yD5gAAAl8"]
[Tue Jul 21 07:29:06.172933 2026] [security2:error] [pid 229246:tid 229491] [client 20.104.96.117:6279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/jp.php"] [unique_id "al9J8iBMYeh5YLVG45yD6AAAAoc"]
[Tue Jul 21 07:29:06.224136 2026] [security2:error] [pid 229246:tid 229493] [client 20.197.195.24:12338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ss.php"] [unique_id "al9J8iBMYeh5YLVG45yD6QAAAok"]
[Tue Jul 21 07:29:06.397108 2026] [security2:error] [pid 229246:tid 229442] [client 34.11.127.22:54854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9J8iBMYeh5YLVG45yD9AAAAlY"]
[Tue Jul 21 07:29:06.408951 2026] [security2:error] [pid 230252:tid 230504] [client 34.11.127.22:52346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br.jaypi.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9J8k0Dwhk5-Z44XrpgBQAAAxE"]
[Tue Jul 21 07:29:06.452617 2026] [security2:error] [pid 229246:tid 229471] [client 20.104.96.117:7047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/f35.php"] [unique_id "al9J8iBMYeh5YLVG45yD9QAAAnM"]
[Tue Jul 21 07:29:06.484764 2026] [security2:error] [pid 230252:tid 230401] [client 45.8.17.73:64059] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "al9J8k0Dwhk5-Z44XrpgBgAAAqo"]
[Tue Jul 21 07:29:06.494540 2026] [security2:error] [pid 229246:tid 229406] [client 20.197.195.24:12329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/hypo.php"] [unique_id "al9J8iBMYeh5YLVG45yD9wAAAjI"]
[Tue Jul 21 07:29:06.527682 2026] [security2:error] [pid 230252:tid 230347] [remote 157.66.26.183:60436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "franciscaco.com.br"] [uri "/wp-login.php"] [unique_id "al9J8U0Dwhk5-Z44Xrpf5AACm1w"]
[Tue Jul 21 07:29:06.643695 2026] [security2:error] [pid 229246:tid 229407] [client 20.104.96.117:59593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-blink.php"] [unique_id "al9J8iBMYeh5YLVG45yD_gAAAjM"]
[Tue Jul 21 07:29:06.675639 2026] [security2:error] [pid 229246:tid 229412] [client 34.11.127.22:64664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ajsdiesel.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9J8iBMYeh5YLVG45yD_wAAAjg"]
[Tue Jul 21 07:29:06.744304 2026] [security2:error] [pid 230252:tid 230413] [client 20.104.96.117:7084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-load.php"] [unique_id "al9J8k0Dwhk5-Z44XrpgCAAAArY"]
[Tue Jul 21 07:29:06.763587 2026] [security2:error] [pid 229246:tid 229405] [client 173.252.95.39:36344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9J8iBMYeh5YLVG45yEAAAAAjE"]
[Tue Jul 21 07:29:06.766585 2026] [security2:error] [pid 229246:tid 229497] [client 204.8.96.141:39408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.96.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J8iBMYeh5YLVG45yEAQAAAo0"]
[Tue Jul 21 07:29:06.766675 2026] [security2:error] [pid 229246:tid 229497] [client 204.8.96.141:39408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J8iBMYeh5YLVG45yEAQAAAo0"]
[Tue Jul 21 07:29:06.807200 2026] [security2:error] [pid 229246:tid 229474] [client 20.197.195.24:20600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/users.php"] [unique_id "al9J8iBMYeh5YLVG45yEAgAAAnY"]
[Tue Jul 21 07:29:06.866348 2026] [autoindex:error] [pid 229246:tid 229462] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/admin/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:06.916949 2026] [security2:error] [pid 229246:tid 229502] [client 109.248.148.246:56512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9J8iBMYeh5YLVG45yECQAAApI"]
[Tue Jul 21 07:29:06.917077 2026] [security2:error] [pid 229246:tid 229502] [client 109.248.148.246:56512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9J8iBMYeh5YLVG45yECQAAApI"]
[Tue Jul 21 07:29:07.040629 2026] [security2:error] [pid 230252:tid 230507] [client 20.197.195.24:12379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/177.php"] [unique_id "al9J800Dwhk5-Z44XrpgCwAAAxQ"]
[Tue Jul 21 07:29:07.040769 2026] [security2:error] [pid 230252:tid 230435] [client 20.104.96.117:6276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/xyn.php"] [unique_id "al9J800Dwhk5-Z44XrpgDAAAAsw"]
[Tue Jul 21 07:29:07.069523 2026] [autoindex:error] [pid 230252:tid 230400] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:07.246599 2026] [security2:error] [pid 230252:tid 230391] [client 82.102.28.107:41286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9J800Dwhk5-Z44XrpgEQAAAqA"]
[Tue Jul 21 07:29:07.246692 2026] [security2:error] [pid 230252:tid 230391] [client 82.102.28.107:41286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9J800Dwhk5-Z44XrpgEQAAAqA"]
[Tue Jul 21 07:29:07.296245 2026] [security2:error] [pid 230252:tid 230503] [client 45.251.232.145:56222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J800Dwhk5-Z44XrpgFQAAAxA"]
[Tue Jul 21 07:29:07.296379 2026] [security2:error] [pid 230252:tid 230503] [client 45.251.232.145:56222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J800Dwhk5-Z44XrpgFQAAAxA"]
[Tue Jul 21 07:29:07.347275 2026] [autoindex:error] [pid 229246:tid 229413] [client 20.104.96.117:6295] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:07.394834 2026] [security2:error] [pid 230252:tid 230417] [client 45.8.17.60:62157] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/rest-api/fields/"] [unique_id "al9J800Dwhk5-Z44XrpgGAAAAro"]
[Tue Jul 21 07:29:07.516887 2026] [security2:error] [pid 229246:tid 229484] [client 20.197.195.24:20494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/config.php"] [unique_id "al9J8yBMYeh5YLVG45yEFQAAAoA"]
[Tue Jul 21 07:29:07.552222 2026] [security2:error] [pid 229246:tid 229430] [client 193.36.225.72:49927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9J8yBMYeh5YLVG45yEFwAAAko"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:07.675076 2026] [autoindex:error] [pid 229246:tid 229486] [client 20.104.96.117:6295] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:07.802789 2026] [security2:error] [pid 230252:tid 230421] [client 20.197.195.24:20571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/gettest.php"] [unique_id "al9J800Dwhk5-Z44XrpgHgAAAr4"]
[Tue Jul 21 07:29:07.812913 2026] [security2:error] [pid 229246:tid 229448] [client 20.104.96.117:6295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ccc.php"] [unique_id "al9J8yBMYeh5YLVG45yEHgAAAlw"]
[Tue Jul 21 07:29:07.999247 2026] [security2:error] [pid 230252:tid 230382] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J800Dwhk5-Z44XrpgIwAC-38"]
[Tue Jul 21 07:29:07.999423 2026] [security2:error] [pid 230252:tid 230482] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J800Dwhk5-Z44XrpgIwAC-38"]
[Tue Jul 21 07:29:08.021297 2026] [security2:error] [pid 229246:tid 229399] [client 20.104.96.117:59635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/zc-208.php"] [unique_id "al9J9CBMYeh5YLVG45yEIAAAAis"]
[Tue Jul 21 07:29:08.068483 2026] [security2:error] [pid 230252:tid 230500] [client 20.197.195.24:12392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/min.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgJAAAAw0"]
[Tue Jul 21 07:29:08.157324 2026] [security2:error] [pid 230252:tid 230429] [client 20.104.96.117:62879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/w.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgKAAAAsY"]
[Tue Jul 21 07:29:08.178579 2026] [security2:error] [pid 230252:tid 230390] [client 20.197.195.24:12310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/dvjul.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgKQAAAp8"]
[Tue Jul 21 07:29:08.291367 2026] [security2:error] [pid 230252:tid 230394] [client 139.135.44.145:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgLAAAAqM"]
[Tue Jul 21 07:29:08.292083 2026] [security2:error] [pid 230252:tid 230394] [client 139.135.44.145:54344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgLAAAAqM"]
[Tue Jul 21 07:29:08.337935 2026] [security2:error] [pid 230252:tid 230487] [client 20.197.195.24:12371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/biufile.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgLgAAAwA"]
[Tue Jul 21 07:29:08.419227 2026] [security2:error] [pid 230252:tid 230472] [client 20.197.195.24:12337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/av.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgMAAAAvE"]
[Tue Jul 21 07:29:08.467451 2026] [security2:error] [pid 230252:tid 230455] [client 20.104.96.117:62881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgOAAAAuA"]
[Tue Jul 21 07:29:08.515286 2026] [security2:error] [pid 230252:tid 230454] [client 20.197.195.24:12347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/coffexium.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgOgAAAt8"]
[Tue Jul 21 07:29:08.581042 2026] [security2:error] [pid 230252:tid 230477] [client 45.8.17.49:27701] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentynineteen/sass/site/"] [unique_id "al9J9E0Dwhk5-Z44XrpgPQAAAvY"]
[Tue Jul 21 07:29:08.640263 2026] [security2:error] [pid 230252:tid 230399] [client 117.251.86.144:47412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgPgAAAqg"]
[Tue Jul 21 07:29:08.640453 2026] [security2:error] [pid 230252:tid 230399] [client 117.251.86.144:47412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgPgAAAqg"]
[Tue Jul 21 07:29:08.694946 2026] [security2:error] [pid 230252:tid 230386] [client 193.189.100.203:19867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.100.189.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgOwAAAps"]
[Tue Jul 21 07:29:08.695104 2026] [security2:error] [pid 230252:tid 230386] [client 193.189.100.203:19867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgOwAAAps"]
[Tue Jul 21 07:29:08.764364 2026] [security2:error] [pid 230252:tid 230445] [client 20.104.96.117:62889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/FWAZ.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgRwAAAtY"]
[Tue Jul 21 07:29:08.848377 2026] [security2:error] [pid 230252:tid 230420] [client 20.197.195.24:12298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/core.php"] [unique_id "al9J9E0Dwhk5-Z44XrpgTQAAAr0"]
[Tue Jul 21 07:29:09.063920 2026] [security2:error] [pid 229246:tid 229395] [client 20.104.96.117:59802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/sid4.php"] [unique_id "al9J9SBMYeh5YLVG45yEKQAAAic"]
[Tue Jul 21 07:29:09.217129 2026] [security2:error] [pid 230252:tid 230394] [client 20.197.195.24:12355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/als.php"] [unique_id "al9J9U0Dwhk5-Z44XrpgVAAAAqM"]
[Tue Jul 21 07:29:09.253585 2026] [security2:error] [pid 230252:tid 230464] [client 20.104.96.117:62407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/miru1.php"] [unique_id "al9J9U0Dwhk5-Z44XrpgVQAAAuk"]
[Tue Jul 21 07:29:09.489095 2026] [security2:error] [pid 229246:tid 229457] [client 45.8.17.105:38421] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/fukasawa/inc/classes/403x.php"] [unique_id "al9J9SBMYeh5YLVG45yELgAAAmU"]
[Tue Jul 21 07:29:09.516478 2026] [security2:error] [pid 229246:tid 229357] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J9SBMYeh5YLVG45yELwACRm4"]
[Tue Jul 21 07:29:09.516652 2026] [security2:error] [pid 229246:tid 229426] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9J9SBMYeh5YLVG45yELwACRm4"]
[Tue Jul 21 07:29:09.601393 2026] [security2:error] [pid 229246:tid 229398] [client 20.104.96.117:62869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/aa.php"] [unique_id "al9J9SBMYeh5YLVG45yEMQAAAio"]
[Tue Jul 21 07:29:09.906254 2026] [security2:error] [pid 230252:tid 230406] [client 20.104.96.117:62401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/122.php"] [unique_id "al9J9U0Dwhk5-Z44XrpgYQAAAq8"]
[Tue Jul 21 07:29:10.017643 2026] [security2:error] [pid 230252:tid 230477] [client 20.197.195.24:20500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/simple.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgZAAAAvY"]
[Tue Jul 21 07:29:10.167501 2026] [security2:error] [pid 230252:tid 230386] [client 20.197.195.24:12309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/init.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgZgAAAps"]
[Tue Jul 21 07:29:10.291255 2026] [security2:error] [pid 230252:tid 230446] [client 20.104.96.117:62436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/get.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgaQAAAtc"]
[Tue Jul 21 07:29:10.385100 2026] [security2:error] [pid 229246:tid 229391] [client 59.96.220.140:52386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J9iBMYeh5YLVG45yEPQAAAiM"]
[Tue Jul 21 07:29:10.385229 2026] [security2:error] [pid 229246:tid 229391] [client 59.96.220.140:52386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J9iBMYeh5YLVG45yEPQAAAiM"]
[Tue Jul 21 07:29:10.584911 2026] [security2:error] [pid 230252:tid 230467] [client 20.104.96.117:62851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/as.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgbAAAAuw"]
[Tue Jul 21 07:29:10.691590 2026] [security2:error] [pid 230252:tid 230462] [client 20.197.195.24:12385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/fpwch.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgcAAAAuc"]
[Tue Jul 21 07:29:10.816987 2026] [autoindex:error] [pid 229246:tid 229498] [client 20.104.96.117:0] AH01276: Cannot serve directory /home1/hostag18/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:10.861676 2026] [security2:error] [pid 230252:tid 230491] [client 20.104.96.117:62870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ccou.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgcwAAAwQ"]
[Tue Jul 21 07:29:11.080176 2026] [security2:error] [pid 230252:tid 230400] [client 45.8.17.105:48009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/filester/assets/css/404.php"] [unique_id "al9J900Dwhk5-Z44XrpgeQAAAqk"]
[Tue Jul 21 07:29:11.182614 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:6275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/w3lls.php"] [unique_id "al9J900Dwhk5-Z44XrpgfAAAAw4"]
[Tue Jul 21 07:29:11.283397 2026] [security2:error] [pid 230252:tid 230435] [client 20.197.195.24:12315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/domvf.php"] [unique_id "al9J900Dwhk5-Z44XrpgfwAAAsw"]
[Tue Jul 21 07:29:11.474591 2026] [security2:error] [pid 229246:tid 229455] [client 62.102.148.164:48806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9J9yBMYeh5YLVG45yESAAAAmM"]
[Tue Jul 21 07:29:11.474683 2026] [security2:error] [pid 229246:tid 229455] [client 62.102.148.164:48806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9J9yBMYeh5YLVG45yESAAAAmM"]
[Tue Jul 21 07:29:11.507306 2026] [security2:error] [pid 229246:tid 229460] [client 20.104.96.117:62860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/test1.php"] [unique_id "al9J9yBMYeh5YLVG45yESQAAAmg"]
[Tue Jul 21 07:29:11.522036 2026] [security2:error] [pid 230252:tid 230486] [client 103.106.20.201:56851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J900Dwhk5-Z44XrpghQAAAv8"]
[Tue Jul 21 07:29:11.522207 2026] [security2:error] [pid 230252:tid 230486] [client 103.106.20.201:56851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J900Dwhk5-Z44XrpghQAAAv8"]
[Tue Jul 21 07:29:11.546131 2026] [security2:error] [pid 229246:tid 229402] [client 20.104.96.117:59617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wmore1.php"] [unique_id "al9J9yBMYeh5YLVG45yESgAAAi4"]
[Tue Jul 21 07:29:11.642685 2026] [security2:error] [pid 229246:tid 229403] [client 20.197.195.24:20489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp.php"] [unique_id "al9J9yBMYeh5YLVG45yESwAAAi8"]
[Tue Jul 21 07:29:11.789564 2026] [security2:error] [pid 230252:tid 230415] [client 20.104.96.117:62410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/database.php"] [unique_id "al9J900Dwhk5-Z44XrpgiwAAArg"]
[Tue Jul 21 07:29:11.819461 2026] [security2:error] [pid 230252:tid 230433] [client 172.245.102.44:56999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9J900Dwhk5-Z44XrpghgAAAso"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:11.962302 2026] [security2:error] [pid 229246:tid 229433] [client 20.151.10.161:49049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/bless.php"] [unique_id "al9J9yBMYeh5YLVG45yEVAAAAk0"]
[Tue Jul 21 07:29:11.999042 2026] [security2:error] [pid 230252:tid 230338] [remote 103.112.62.59:43202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "governess.com.br"] [uri "/wp-login.php"] [unique_id "al9J900Dwhk5-Z44XrpgjQAC9VM"]
[Tue Jul 21 07:29:12.119600 2026] [security2:error] [pid 230252:tid 230420] [client 20.104.96.117:62899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/file.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgkQAAAr0"]
[Tue Jul 21 07:29:12.163543 2026] [security2:error] [pid 230252:tid 230281] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgkgACvhs"]
[Tue Jul 21 07:29:12.163680 2026] [security2:error] [pid 230252:tid 230421] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgkgACvhs"]
[Tue Jul 21 07:29:12.183335 2026] [security2:error] [pid 230252:tid 230458] [client 45.8.17.138:62281] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/wp-conflg.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgkwAAAuM"]
[Tue Jul 21 07:29:12.386171 2026] [security2:error] [pid 230252:tid 230413] [client 20.197.195.24:20547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/class.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgmQAAArY"]
[Tue Jul 21 07:29:12.452725 2026] [security2:error] [pid 229246:tid 229399] [client 20.104.96.117:62885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/file.php"] [unique_id "al9J-CBMYeh5YLVG45yEWAAAAis"]
[Tue Jul 21 07:29:12.572130 2026] [security2:error] [pid 230252:tid 230329] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgmwACn0o"]
[Tue Jul 21 07:29:12.572287 2026] [security2:error] [pid 230252:tid 230390] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgmwACn0o"]
[Tue Jul 21 07:29:12.633193 2026] [security2:error] [pid 230252:tid 230367] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgnAADDnA"]
[Tue Jul 21 07:29:12.633336 2026] [security2:error] [pid 230252:tid 230501] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgnAADDnA"]
[Tue Jul 21 07:29:12.754578 2026] [security2:error] [pid 230252:tid 230451] [client 20.104.96.117:62895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/777.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgoAAAAtw"]
[Tue Jul 21 07:29:12.849530 2026] [security2:error] [pid 230252:tid 230370] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgoQACrnM"]
[Tue Jul 21 07:29:12.849708 2026] [security2:error] [pid 230252:tid 230405] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgoQACrnM"]
[Tue Jul 21 07:29:12.882982 2026] [security2:error] [pid 230252:tid 230452] [client 103.174.34.15:52100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgogAAAt0"]
[Tue Jul 21 07:29:12.883131 2026] [security2:error] [pid 230252:tid 230452] [client 103.174.34.15:52100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgogAAAt0"]
[Tue Jul 21 07:29:12.960702 2026] [fcgid:warn] [pid 229246:tid 229425] (70014)End of file found: [client 66.132.195.87:3924] mod_fcgid: can't get data from http client
[Tue Jul 21 07:29:12.989110 2026] [security2:error] [pid 230252:tid 230491] [client 154.192.233.199:60395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgpwAAAwQ"]
[Tue Jul 21 07:29:12.989371 2026] [security2:error] [pid 230252:tid 230491] [client 154.192.233.199:60395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-E0Dwhk5-Z44XrpgpwAAAwQ"]
[Tue Jul 21 07:29:13.074015 2026] [security2:error] [pid 230252:tid 230398] [client 175.45.70.82:59312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-U0Dwhk5-Z44XrpgqAAAAqc"]
[Tue Jul 21 07:29:13.074172 2026] [security2:error] [pid 230252:tid 230398] [client 175.45.70.82:59312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J-U0Dwhk5-Z44XrpgqAAAAqc"]
[Tue Jul 21 07:29:13.186641 2026] [security2:error] [pid 230252:tid 230465] [client 45.8.17.127:35227] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al9J-U0Dwhk5-Z44XrpgqQAAAuo"]
[Tue Jul 21 07:29:13.206310 2026] [security2:error] [pid 230252:tid 230411] [client 20.104.96.117:6294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ssixta.php"] [unique_id "al9J-U0Dwhk5-Z44XrpgqgAAArQ"]
[Tue Jul 21 07:29:13.296646 2026] [security2:error] [pid 230252:tid 230412] [client 152.59.154.239:54669] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgdwAAArU"]
[Tue Jul 21 07:29:13.296791 2026] [security2:error] [pid 230252:tid 230412] [client 152.59.154.239:54669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J9k0Dwhk5-Z44XrpgdwAAArU"]
[Tue Jul 21 07:29:13.302767 2026] [security2:error] [pid 230252:tid 230487] [client 103.162.129.114:50659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J-U0Dwhk5-Z44XrpgrgAAAwA"]
[Tue Jul 21 07:29:13.302924 2026] [security2:error] [pid 230252:tid 230487] [client 103.162.129.114:50659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9J-U0Dwhk5-Z44XrpgrgAAAwA"]
[Tue Jul 21 07:29:13.312266 2026] [autoindex:error] [pid 230252:tid 230403] [client 82.102.18.182:60814] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:13.412736 2026] [security2:error] [pid 230252:tid 230476] [client 20.197.195.24:12374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/echkm.php"] [unique_id "al9J-U0Dwhk5-Z44XrpgsAAAAvU"]
[Tue Jul 21 07:29:13.728075 2026] [security2:error] [pid 230252:tid 230392] [client 20.197.195.24:20546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/lib.php"] [unique_id "al9J-U0Dwhk5-Z44XrpgtgAAAqE"]
[Tue Jul 21 07:29:13.755473 2026] [security2:error] [pid 230252:tid 230401] [client 20.104.96.117:62872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/1c.php"] [unique_id "al9J-U0Dwhk5-Z44XrpguAAAAqo"]
[Tue Jul 21 07:29:13.811598 2026] [autoindex:error] [pid 230252:tid 230453] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:13.887541 2026] [security2:error] [pid 230252:tid 230316] [remote 65.111.22.132:52449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9J-U0Dwhk5-Z44XrpguwADAz4"]
[Tue Jul 21 07:29:14.011181 2026] [security2:error] [pid 230252:tid 230472] [client 20.197.195.24:12332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/login.php"] [unique_id "al9J-k0Dwhk5-Z44XrpgvwAAAvE"]
[Tue Jul 21 07:29:14.048011 2026] [autoindex:error] [pid 230252:tid 230451] [client 82.102.18.182:60814] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:14.131709 2026] [security2:error] [pid 230252:tid 230452] [client 20.104.96.117:62441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/test2.php"] [unique_id "al9J-k0Dwhk5-Z44XrpgwgAAAt0"]
[Tue Jul 21 07:29:14.245381 2026] [security2:error] [pid 230252:tid 230402] [client 20.197.195.24:20567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/a2.php"] [unique_id "al9J-k0Dwhk5-Z44XrpgwwAAAqs"]
[Tue Jul 21 07:29:14.272669 2026] [security2:error] [pid 230252:tid 230432] [client 20.151.10.161:49129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file46.php"] [unique_id "al9J-k0Dwhk5-Z44XrpgxAAAAsk"]
[Tue Jul 21 07:29:14.285396 2026] [authz_core:error] [pid 230252:tid 230406] [client 82.102.18.182:0] AH01630: client denied by server configuration: /home1/asse7722/public_html/wp-content/plugins/akismet/
[Tue Jul 21 07:29:14.434240 2026] [security2:error] [pid 230252:tid 230483] [client 20.197.195.24:12349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/d61.php"] [unique_id "al9J-k0Dwhk5-Z44XrpgyQAAAvw"]
[Tue Jul 21 07:29:14.466120 2026] [security2:error] [pid 230252:tid 230429] [client 109.248.148.246:60922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9J-k0Dwhk5-Z44XrpgygAAAsY"]
[Tue Jul 21 07:29:14.466204 2026] [security2:error] [pid 230252:tid 230429] [client 109.248.148.246:60922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9J-k0Dwhk5-Z44XrpgygAAAsY"]
[Tue Jul 21 07:29:14.471407 2026] [security2:error] [pid 229246:tid 229441] [client 20.52.136.55:1487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/bolt.php"] [unique_id "al9J-iBMYeh5YLVG45yEbwAAAlU"]
[Tue Jul 21 07:29:14.498592 2026] [autoindex:error] [pid 230252:tid 230398] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:14.544793 2026] [security2:error] [pid 229246:tid 229379] [client 20.104.96.117:7066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/buy.php"] [unique_id "al9J-iBMYeh5YLVG45yEcgAAAhc"]
[Tue Jul 21 07:29:14.547892 2026] [security2:error] [pid 230252:tid 230439] [client 20.197.195.24:12300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/info.php"] [unique_id "al9J-k0Dwhk5-Z44Xrpg0AAAAtA"]
[Tue Jul 21 07:29:14.584450 2026] [security2:error] [pid 229246:tid 229407] [client 45.8.17.112:34911] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/maint/includes/"] [unique_id "al9J-iBMYeh5YLVG45yEcwAAAjM"]
[Tue Jul 21 07:29:14.606518 2026] [security2:error] [pid 230252:tid 230430] [client 20.197.195.24:20572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/11.php"] [unique_id "al9J-k0Dwhk5-Z44Xrpg0gAAAsc"]
[Tue Jul 21 07:29:14.705854 2026] [autoindex:error] [pid 230252:tid 230391] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:14.912823 2026] [autoindex:error] [pid 230252:tid 230438] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:14.925764 2026] [security2:error] [pid 229246:tid 229498] [client 20.197.195.24:20562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/v2.php"] [unique_id "al9J-iBMYeh5YLVG45yEdwAAAo4"]
[Tue Jul 21 07:29:14.936598 2026] [security2:error] [pid 230252:tid 230504] [client 20.104.96.117:62896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ssend.php"] [unique_id "al9J-k0Dwhk5-Z44Xrpg3gAAAxE"]
[Tue Jul 21 07:29:15.120327 2026] [autoindex:error] [pid 230252:tid 230464] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:15.217747 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:7083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/item.php"] [unique_id "al9J-00Dwhk5-Z44Xrpg5AAAAuQ"]
[Tue Jul 21 07:29:15.369710 2026] [autoindex:error] [pid 230252:tid 230501] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:15.567987 2026] [security2:error] [pid 230252:tid 230452] [client 20.104.96.117:7088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ss.php"] [unique_id "al9J-00Dwhk5-Z44Xrpg7gAAAt0"]
[Tue Jul 21 07:29:15.573894 2026] [autoindex:error] [pid 230252:tid 230435] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:15.776936 2026] [security2:error] [pid 229246:tid 229402] [client 45.8.17.103:44311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/comment-date/"] [unique_id "al9J-yBMYeh5YLVG45yEgwAAAi4"]
[Tue Jul 21 07:29:15.780283 2026] [autoindex:error] [pid 230252:tid 230491] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:15.879418 2026] [security2:error] [pid 230252:tid 230434] [client 20.104.96.117:62462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/hypo.php"] [unique_id "al9J-00Dwhk5-Z44Xrpg8gAAAss"]
[Tue Jul 21 07:29:15.985322 2026] [autoindex:error] [pid 230252:tid 230416] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:16.026686 2026] [security2:error] [pid 230252:tid 230505] [client 136.144.33.112:44409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9J_E0Dwhk5-Z44Xrpg9gAAAxI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:16.077623 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.195.24:20549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/panel.php"] [unique_id "al9J_CBMYeh5YLVG45yEigAAAoQ"]
[Tue Jul 21 07:29:16.271190 2026] [security2:error] [pid 230252:tid 230456] [client 20.104.96.117:62424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/users.php"] [unique_id "al9J_E0Dwhk5-Z44Xrpg-wAAAuE"]
[Tue Jul 21 07:29:16.411645 2026] [security2:error] [pid 230252:tid 230320] [remote 5.182.209.54:39240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9J_E0Dwhk5-Z44XrphAQACm0I"]
[Tue Jul 21 07:29:16.524299 2026] [autoindex:error] [pid 229246:tid 229417] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:16.589775 2026] [security2:error] [pid 229246:tid 229448] [client 20.104.96.117:6244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/177.php"] [unique_id "al9J_CBMYeh5YLVG45yEjwAAAlw"]
[Tue Jul 21 07:29:16.698269 2026] [security2:error] [pid 230252:tid 230476] [client 20.151.10.161:49050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/eee.php"] [unique_id "al9J_E0Dwhk5-Z44XrphCgAAAvU"]
[Tue Jul 21 07:29:16.764402 2026] [autoindex:error] [pid 230252:tid 230442] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:16.873985 2026] [security2:error] [pid 230252:tid 230326] [remote 202.51.202.242:44436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9J_E0Dwhk5-Z44XrphDgAC0Ec"]
[Tue Jul 21 07:29:16.903136 2026] [security2:error] [pid 230252:tid 230426] [client 20.104.96.117:7054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/config.php"] [unique_id "al9J_E0Dwhk5-Z44XrphEAAAAsM"]
[Tue Jul 21 07:29:16.971467 2026] [autoindex:error] [pid 230252:tid 230498] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:17.092456 2026] [security2:error] [pid 230252:tid 230400] [client 45.8.17.126:58745] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "al9J_U0Dwhk5-Z44XrphFgAAAqk"]
[Tue Jul 21 07:29:17.180398 2026] [autoindex:error] [pid 230252:tid 230477] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:17.201733 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:7058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/gettest.php"] [unique_id "al9J_U0Dwhk5-Z44XrphGgAAAw4"]
[Tue Jul 21 07:29:17.387002 2026] [autoindex:error] [pid 230252:tid 230451] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:17.402996 2026] [security2:error] [pid 229246:tid 229411] [client 216.244.66.195:52216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acheservicos.com.br"] [uri "/"] [unique_id "al9J_SBMYeh5YLVG45yEnAAAAjc"]
[Tue Jul 21 07:29:17.403103 2026] [security2:error] [pid 229246:tid 229411] [client 216.244.66.195:52216] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "acheservicos.com.br"] [uri "/"] [unique_id "al9J_SBMYeh5YLVG45yEnAAAAjc"]
[Tue Jul 21 07:29:17.497957 2026] [security2:error] [pid 229246:tid 229495] [client 20.104.96.117:6272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/min.php"] [unique_id "al9J_SBMYeh5YLVG45yEngAAAos"]
[Tue Jul 21 07:29:17.501484 2026] [security2:error] [pid 229246:tid 229420] [client 20.197.195.24:20550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/dex.php"] [unique_id "al9J_SBMYeh5YLVG45yEnwAAAkA"]
[Tue Jul 21 07:29:17.593137 2026] [autoindex:error] [pid 230252:tid 230406] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:17.763645 2026] [security2:error] [pid 230252:tid 230390] [client 45.251.232.145:56741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J_U0Dwhk5-Z44XrphJwAAAp8"]
[Tue Jul 21 07:29:17.763790 2026] [security2:error] [pid 230252:tid 230390] [client 45.251.232.145:56741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J_U0Dwhk5-Z44XrphJwAAAp8"]
[Tue Jul 21 07:29:17.782397 2026] [security2:error] [pid 230252:tid 230479] [client 20.104.96.117:7092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/dvjul.php"] [unique_id "al9J_U0Dwhk5-Z44XrphKAAAAvg"]
[Tue Jul 21 07:29:17.834765 2026] [autoindex:error] [pid 230252:tid 230391] [client 82.102.18.182:60814] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:17.913662 2026] [security2:error] [pid 230252:tid 230467] [client 74.7.230.22:34148] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "americajoseense.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9J_U0Dwhk5-Z44XrphLgAC7Cw"]
[Tue Jul 21 07:29:18.075746 2026] [autoindex:error] [pid 230252:tid 230458] [client 82.102.18.182:60814] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:18.076420 2026] [security2:error] [pid 230252:tid 230474] [client 20.104.96.117:6273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/biufile.php"] [unique_id "al9J_k0Dwhk5-Z44XrphMAAAAvM"]
[Tue Jul 21 07:29:18.184676 2026] [security2:error] [pid 230252:tid 230442] [client 109.248.148.246:45794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9J_k0Dwhk5-Z44XrphMwAAAtM"]
[Tue Jul 21 07:29:18.184778 2026] [security2:error] [pid 230252:tid 230442] [client 109.248.148.246:45794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9J_k0Dwhk5-Z44XrphMwAAAtM"]
[Tue Jul 21 07:29:18.192235 2026] [autoindex:error] [pid 230252:tid 230444] [client 66.132.195.87:24766] AH01276: Cannot serve directory /home4/ciclod61/homemsedutoronline.store/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:18.368153 2026] [security2:error] [pid 230252:tid 230453] [client 20.104.96.117:7078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/av.php"] [unique_id "al9J_k0Dwhk5-Z44XrphNwAAAt4"]
[Tue Jul 21 07:29:18.482475 2026] [security2:error] [pid 230252:tid 230472] [client 45.8.17.135:35543] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/widgets/chosen.php"] [unique_id "al9J_k0Dwhk5-Z44XrphOwAAAvE"]
[Tue Jul 21 07:29:18.511723 2026] [security2:error] [pid 230252:tid 230452] [client 20.197.195.24:12312] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "lirioshoppy.com.br"] [uri "/1.php"] [unique_id "al9J_k0Dwhk5-Z44XrphPAAAAt0"]
[Tue Jul 21 07:29:18.511896 2026] [security2:error] [pid 230252:tid 230452] [client 20.197.195.24:12312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/1.php"] [unique_id "al9J_k0Dwhk5-Z44XrphPAAAAt0"]
[Tue Jul 21 07:29:18.538097 2026] [security2:error] [pid 230252:tid 230432] [client 20.104.96.117:59634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/solo1.php"] [unique_id "al9J_k0Dwhk5-Z44XrphPwAAAsk"]
[Tue Jul 21 07:29:18.546120 2026] [security2:error] [pid 230252:tid 230277] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J_k0Dwhk5-Z44XrphQgAC9hc"]
[Tue Jul 21 07:29:18.546230 2026] [security2:error] [pid 230252:tid 230477] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9J_k0Dwhk5-Z44XrphQgAC9hc"]
[Tue Jul 21 07:29:18.552043 2026] [security2:error] [pid 230252:tid 230394] [client 65.111.28.166:30567] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "lojaracompressores.com.br"] [uri "/"] [unique_id "al9J_k0Dwhk5-Z44XrphQwAAAqM"]
[Tue Jul 21 07:29:18.662905 2026] [security2:error] [pid 230252:tid 230411] [client 20.104.96.117:62404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/coffexium.php"] [unique_id "al9J_k0Dwhk5-Z44XrphSgAAArQ"]
[Tue Jul 21 07:29:18.759979 2026] [security2:error] [pid 230252:tid 230446] [client 109.248.148.246:45810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9J_k0Dwhk5-Z44XrphTAAAAtc"]
[Tue Jul 21 07:29:18.760092 2026] [security2:error] [pid 230252:tid 230446] [client 109.248.148.246:45810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9J_k0Dwhk5-Z44XrphTAAAAtc"]
[Tue Jul 21 07:29:18.803544 2026] [security2:error] [pid 230252:tid 230467] [client 65.111.28.166:30567] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "lojaracompressores.com.br"] [uri "/"] [unique_id "al9J_k0Dwhk5-Z44XrphTQAAAuw"]
[Tue Jul 21 07:29:18.920569 2026] [security2:error] [pid 230252:tid 230458] [client 20.197.195.24:12401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/ms.php"] [unique_id "al9J_k0Dwhk5-Z44XrphTgAAAuM"]
[Tue Jul 21 07:29:18.949196 2026] [security2:error] [pid 230252:tid 230438] [client 20.104.96.117:62448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/core.php"] [unique_id "al9J_k0Dwhk5-Z44XrphTwAAAs8"]
[Tue Jul 21 07:29:19.052394 2026] [security2:error] [pid 230252:tid 230444] [client 65.111.28.166:30567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9J_00Dwhk5-Z44XrphVQAAAtU"]
[Tue Jul 21 07:29:19.074751 2026] [autoindex:error] [pid 230252:tid 230445] [client 20.197.195.24:20493] AH01276: Cannot serve directory /home1/lirios92/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:19.080064 2026] [security2:error] [pid 230252:tid 230431] [client 139.135.44.145:53275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J_00Dwhk5-Z44XrphWQAAAsg"]
[Tue Jul 21 07:29:19.080171 2026] [security2:error] [pid 230252:tid 230431] [client 139.135.44.145:53275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9J_00Dwhk5-Z44XrphWQAAAsg"]
[Tue Jul 21 07:29:19.088317 2026] [security2:error] [pid 230252:tid 230392] [client 20.197.195.24:20493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/memberfuns.php"] [unique_id "al9J_00Dwhk5-Z44XrphWgAAAqE"]
[Tue Jul 21 07:29:19.229564 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:62429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/als.php"] [unique_id "al9J_00Dwhk5-Z44XrphXQAAAuQ"]
[Tue Jul 21 07:29:19.248999 2026] [security2:error] [pid 230252:tid 230501] [client 20.197.195.24:12303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/0.php"] [unique_id "al9J_00Dwhk5-Z44XrphXwAAAw4"]
[Tue Jul 21 07:29:19.388346 2026] [security2:error] [pid 230252:tid 230483] [client 117.251.86.144:39700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J_00Dwhk5-Z44XrphYAAAAvw"]
[Tue Jul 21 07:29:19.388471 2026] [security2:error] [pid 230252:tid 230483] [client 117.251.86.144:39700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9J_00Dwhk5-Z44XrphYAAAAvw"]
[Tue Jul 21 07:29:19.515602 2026] [security2:error] [pid 230252:tid 230470] [client 20.104.96.117:62880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/simple.php"] [unique_id "al9J_00Dwhk5-Z44XrphYgAAAu8"]
[Tue Jul 21 07:29:19.592071 2026] [security2:error] [pid 230252:tid 230464] [client 45.8.17.119:45897] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/theme-check/main.php"] [unique_id "al9J_00Dwhk5-Z44XrphZAAAAuk"]
[Tue Jul 21 07:29:19.675151 2026] [security2:error] [pid 230252:tid 230465] [client 20.197.195.24:12328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/BDKR28.php"] [unique_id "al9J_00Dwhk5-Z44XrphZgAAAuo"]
[Tue Jul 21 07:29:19.742834 2026] [security2:error] [pid 230252:tid 230429] [client 65.111.28.166:13273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaracompressores.com.br"] [uri "/xmlrpc.php"] [unique_id "al9J_00Dwhk5-Z44XrphYwAAAsY"]
[Tue Jul 21 07:29:19.748823 2026] [security2:error] [pid 230252:tid 230476] [client 59.96.220.140:52871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J_00Dwhk5-Z44XrphbAAAAvU"]
[Tue Jul 21 07:29:19.748929 2026] [security2:error] [pid 230252:tid 230476] [client 59.96.220.140:52871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9J_00Dwhk5-Z44XrphbAAAAvU"]
[Tue Jul 21 07:29:19.808736 2026] [security2:error] [pid 229246:tid 229474] [client 20.104.96.117:7091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/init.php"] [unique_id "al9J_yBMYeh5YLVG45yEtQAAAnY"]
[Tue Jul 21 07:29:19.985088 2026] [security2:error] [pid 229246:tid 229487] [client 20.197.195.24:20568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/green1.php"] [unique_id "al9J_yBMYeh5YLVG45yEtgAAAoM"]
[Tue Jul 21 07:29:20.009292 2026] [security2:error] [pid 229246:tid 229294] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KACBMYeh5YLVG45yEuQACTy8"]
[Tue Jul 21 07:29:20.009440 2026] [security2:error] [pid 229246:tid 229435] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KACBMYeh5YLVG45yEuQACTy8"]
[Tue Jul 21 07:29:20.098873 2026] [security2:error] [pid 229246:tid 229401] [client 20.220.225.223:46108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KACBMYeh5YLVG45yEvgAAAi0"]
[Tue Jul 21 07:29:20.146466 2026] [security2:error] [pid 229246:tid 229477] [client 20.104.96.117:62439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/fpwch.php"] [unique_id "al9KACBMYeh5YLVG45yEvwAAAnk"]
[Tue Jul 21 07:29:20.273069 2026] [security2:error] [pid 229246:tid 229403] [client 65.111.28.166:32409] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "lojaracompressores.com.br"] [uri "/"] [unique_id "al9KACBMYeh5YLVG45yExAAAAi8"]
[Tue Jul 21 07:29:20.371744 2026] [security2:error] [pid 229246:tid 229484] [client 20.197.195.24:20596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/nc4.php"] [unique_id "al9KACBMYeh5YLVG45yEyQAAAoA"]
[Tue Jul 21 07:29:20.437699 2026] [security2:error] [pid 230252:tid 230482] [client 20.104.96.117:6302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/domvf.php"] [unique_id "al9KAE0Dwhk5-Z44XrphcAAAAvs"]
[Tue Jul 21 07:29:20.526601 2026] [security2:error] [pid 229246:tid 229430] [client 65.111.28.166:32409] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9KACBMYeh5YLVG45yEygAAAko"]
[Tue Jul 21 07:29:20.552626 2026] [security2:error] [pid 229246:tid 229378] [client 20.197.195.24:20483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/a1.php"] [unique_id "al9KACBMYeh5YLVG45yEywAAAhY"]
[Tue Jul 21 07:29:20.735598 2026] [security2:error] [pid 230252:tid 230500] [client 20.104.96.117:62406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp.php"] [unique_id "al9KAE0Dwhk5-Z44XrphdAAAAw0"]
[Tue Jul 21 07:29:20.853658 2026] [security2:error] [pid 230252:tid 230431] [client 20.197.195.24:20544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/eee.php"] [unique_id "al9KAE0Dwhk5-Z44XrphdwAAAsg"]
[Tue Jul 21 07:29:20.902018 2026] [autoindex:error] [pid 230252:tid 230415] [client 20.104.96.117:0] AH01276: Cannot serve directory /home1/hostag18/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:20.905482 2026] [security2:error] [pid 230252:tid 230454] [client 193.36.225.56:62371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9J_00Dwhk5-Z44XrphagAAAt8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:21.030590 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:62443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/class.php"] [unique_id "al9KAU0Dwhk5-Z44XrphfgAAAuQ"]
[Tue Jul 21 07:29:21.044561 2026] [security2:error] [pid 230252:tid 230455] [client 65.111.28.166:16699] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9KAU0Dwhk5-Z44XrphfwAAAuA"]
[Tue Jul 21 07:29:21.178099 2026] [security2:error] [pid 230252:tid 230435] [client 20.104.96.117:59590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/cong.php"] [unique_id "al9KAU0Dwhk5-Z44XrphggAAAsw"]
[Tue Jul 21 07:29:21.192789 2026] [security2:error] [pid 230252:tid 230471] [client 20.197.195.24:12311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/wp-aothait.php"] [unique_id "al9KAU0Dwhk5-Z44XrphgwAAAvA"]
[Tue Jul 21 07:29:21.225450 2026] [security2:error] [pid 230252:tid 230483] [client 82.102.28.107:34868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KAU0Dwhk5-Z44XrphhAAAAvw"]
[Tue Jul 21 07:29:21.225542 2026] [security2:error] [pid 230252:tid 230483] [client 82.102.28.107:34868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KAU0Dwhk5-Z44XrphhAAAAvw"]
[Tue Jul 21 07:29:21.312529 2026] [security2:error] [pid 230252:tid 230423] [client 20.104.96.117:7086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/echkm.php"] [unique_id "al9KAU0Dwhk5-Z44XrphhgAAAsA"]
[Tue Jul 21 07:29:21.471375 2026] [security2:error] [pid 229246:tid 229386] [client 20.197.195.24:12342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/config.json.php"] [unique_id "al9KASBMYeh5YLVG45yE1AAAAh4"]
[Tue Jul 21 07:29:21.490984 2026] [security2:error] [pid 229246:tid 229399] [client 45.8.17.49:62579] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/css.php"] [unique_id "al9KASBMYeh5YLVG45yE1QAAAis"]
[Tue Jul 21 07:29:21.560587 2026] [security2:error] [pid 229246:tid 229393] [client 65.111.28.166:41811] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9KASBMYeh5YLVG45yE1wAAAiU"]
[Tue Jul 21 07:29:21.577631 2026] [security2:error] [pid 230252:tid 230511] [client 20.220.225.223:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KAU0Dwhk5-Z44XrphjwAAAxg"]
[Tue Jul 21 07:29:21.603855 2026] [security2:error] [pid 229246:tid 229419] [client 20.104.96.117:62442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/lib.php"] [unique_id "al9KASBMYeh5YLVG45yE2gAAAj8"]
[Tue Jul 21 07:29:21.633737 2026] [security2:error] [pid 229246:tid 229424] [client 82.102.28.107:34870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KASBMYeh5YLVG45yE2wAAAkQ"]
[Tue Jul 21 07:29:21.633842 2026] [security2:error] [pid 229246:tid 229424] [client 82.102.28.107:34870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KASBMYeh5YLVG45yE2wAAAkQ"]
[Tue Jul 21 07:29:21.880543 2026] [security2:error] [pid 229246:tid 229420] [client 20.104.96.117:6278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/login.php"] [unique_id "al9KASBMYeh5YLVG45yE3gAAAkA"]
[Tue Jul 21 07:29:22.006628 2026] [security2:error] [pid 229246:tid 229457] [client 20.197.195.24:20583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9KAiBMYeh5YLVG45yE4wAAAmU"]
[Tue Jul 21 07:29:22.174530 2026] [security2:error] [pid 229246:tid 229458] [client 20.104.96.117:62848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/a2.php"] [unique_id "al9KAiBMYeh5YLVG45yE5QAAAmY"]
[Tue Jul 21 07:29:22.210642 2026] [security2:error] [pid 230252:tid 230464] [client 152.59.154.239:55101] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KAk0Dwhk5-Z44XrphmgAAAuk"]
[Tue Jul 21 07:29:22.210800 2026] [security2:error] [pid 230252:tid 230464] [client 152.59.154.239:55101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KAk0Dwhk5-Z44XrphmgAAAuk"]
[Tue Jul 21 07:29:22.243309 2026] [security2:error] [pid 229246:tid 229377] [client 103.106.20.201:57468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KAiBMYeh5YLVG45yE5wAAAhU"]
[Tue Jul 21 07:29:22.243421 2026] [security2:error] [pid 229246:tid 229377] [client 103.106.20.201:57468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KAiBMYeh5YLVG45yE5wAAAhU"]
[Tue Jul 21 07:29:22.292897 2026] [security2:error] [pid 230252:tid 230415] [client 45.8.17.114:55295] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/admin.php"] [unique_id "al9KAk0Dwhk5-Z44XrphmwAAArg"]
[Tue Jul 21 07:29:22.404141 2026] [autoindex:error] [pid 230252:tid 230439] [client 82.102.18.182:33740] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:22.427184 2026] [security2:error] [pid 230252:tid 230507] [client 65.111.28.166:11763] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9KAk0Dwhk5-Z44XrphnwAAAxQ"]
[Tue Jul 21 07:29:22.451859 2026] [security2:error] [pid 230252:tid 230400] [client 20.104.96.117:62421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/d61.php"] [unique_id "al9KAk0Dwhk5-Z44XrphoAAAAqk"]
[Tue Jul 21 07:29:22.662775 2026] [security2:error] [pid 230252:tid 230313] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KAk0Dwhk5-Z44XrphpQAC3js"]
[Tue Jul 21 07:29:22.662912 2026] [security2:error] [pid 230252:tid 230453] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KAk0Dwhk5-Z44XrphpQAC3js"]
[Tue Jul 21 07:29:22.739515 2026] [security2:error] [pid 230252:tid 230472] [client 20.104.96.117:6236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/info.php"] [unique_id "al9KAk0Dwhk5-Z44XrphpgAAAvE"]
[Tue Jul 21 07:29:22.849501 2026] [security2:error] [pid 230252:tid 230429] [client 20.197.195.24:20597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/k2.php"] [unique_id "al9KAk0Dwhk5-Z44XrphqwAAAsY"]
[Tue Jul 21 07:29:22.851519 2026] [security2:error] [pid 229246:tid 229453] [client 74.7.241.174:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.alphafix.com.br"] [uri "/index.php"] [unique_id "al9KASBMYeh5YLVG45yE4QACYQI"]
[Tue Jul 21 07:29:22.870075 2026] [security2:error] [pid 230252:tid 230434] [client 213.152.162.104:44010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KAk0Dwhk5-Z44XrphrAAAAss"]
[Tue Jul 21 07:29:22.870182 2026] [security2:error] [pid 230252:tid 230434] [client 213.152.162.104:44010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KAk0Dwhk5-Z44XrphrAAAAss"]
[Tue Jul 21 07:29:22.931407 2026] [security2:error] [pid 229246:tid 229379] [client 65.111.28.166:15703] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9KAiBMYeh5YLVG45yE7wAAAhc"]
[Tue Jul 21 07:29:23.062620 2026] [security2:error] [pid 229246:tid 229497] [client 20.52.136.55:1575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/x.php"] [unique_id "al9KAyBMYeh5YLVG45yE8wAAAo0"]
[Tue Jul 21 07:29:23.072493 2026] [security2:error] [pid 229246:tid 229405] [client 20.104.96.117:6309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/11.php"] [unique_id "al9KAyBMYeh5YLVG45yE9AAAAjE"]
[Tue Jul 21 07:29:23.196770 2026] [autoindex:error] [pid 230252:tid 230482] [client 20.104.96.117:0] AH01276: Cannot serve directory /home1/hostag18/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:23.223470 2026] [security2:error] [pid 229246:tid 229412] [client 20.151.10.161:49081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file25.php"] [unique_id "al9KAyBMYeh5YLVG45yE9wAAAjg"]
[Tue Jul 21 07:29:23.235264 2026] [security2:error] [pid 229246:tid 229257] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yE-AACcAo"]
[Tue Jul 21 07:29:23.235432 2026] [security2:error] [pid 229246:tid 229468] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yE-AACcAo"]
[Tue Jul 21 07:29:23.369585 2026] [security2:error] [pid 229246:tid 229321] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yE-gACd0o"]
[Tue Jul 21 07:29:23.369745 2026] [security2:error] [pid 229246:tid 229475] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yE-gACd0o"]
[Tue Jul 21 07:29:23.371259 2026] [security2:error] [pid 229246:tid 229329] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yE-wACGFI"]
[Tue Jul 21 07:29:23.371372 2026] [security2:error] [pid 229246:tid 229380] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yE-wACGFI"]
[Tue Jul 21 07:29:23.378249 2026] [security2:error] [pid 229246:tid 229406] [client 20.104.96.117:62414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/v2.php"] [unique_id "al9KAyBMYeh5YLVG45yE_QAAAjI"]
[Tue Jul 21 07:29:23.380659 2026] [security2:error] [pid 229246:tid 229401] [client 20.220.225.223:46081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/dp.php"] [unique_id "al9KAyBMYeh5YLVG45yE_gAAAi0"]
[Tue Jul 21 07:29:23.423374 2026] [security2:error] [pid 230252:tid 230439] [client 65.111.28.166:14557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9KA00Dwhk5-Z44XrphuwAAAtA"]
[Tue Jul 21 07:29:23.486021 2026] [security2:error] [pid 229246:tid 229480] [client 20.104.96.117:59596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/public/css.php"] [unique_id "al9KAyBMYeh5YLVG45yFAwAAAnw"]
[Tue Jul 21 07:29:23.686281 2026] [security2:error] [pid 230252:tid 230455] [client 45.8.17.62:52579] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/2025/"] [unique_id "al9KA00Dwhk5-Z44XrphwAAAAuA"]
[Tue Jul 21 07:29:23.688347 2026] [security2:error] [pid 230252:tid 230501] [client 20.104.96.117:7096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/panel.php"] [unique_id "al9KA00Dwhk5-Z44XrphwQAAAw4"]
[Tue Jul 21 07:29:23.704991 2026] [security2:error] [pid 229246:tid 229416] [client 103.162.129.114:51102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yFBgAAAjw"]
[Tue Jul 21 07:29:23.705152 2026] [security2:error] [pid 229246:tid 229416] [client 103.162.129.114:51102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KAyBMYeh5YLVG45yFBgAAAjw"]
[Tue Jul 21 07:29:23.787923 2026] [security2:error] [pid 230252:tid 230475] [client 154.192.233.199:59274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KA00Dwhk5-Z44XrphxQAAAvQ"]
[Tue Jul 21 07:29:23.788235 2026] [security2:error] [pid 230252:tid 230475] [client 154.192.233.199:59274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KA00Dwhk5-Z44XrphxQAAAvQ"]
[Tue Jul 21 07:29:23.800156 2026] [security2:error] [pid 230252:tid 230467] [client 175.45.70.82:59819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KA00Dwhk5-Z44XrphxgAAAuw"]
[Tue Jul 21 07:29:23.800252 2026] [security2:error] [pid 230252:tid 230467] [client 175.45.70.82:59819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KA00Dwhk5-Z44XrphxgAAAuw"]
[Tue Jul 21 07:29:23.901113 2026] [security2:error] [pid 230252:tid 230472] [client 20.197.195.24:12333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9KA00Dwhk5-Z44XrphxwAAAvE"]
[Tue Jul 21 07:29:23.924409 2026] [security2:error] [pid 230252:tid 230442] [client 103.174.34.15:52595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KA00Dwhk5-Z44XrphyAAAAtM"]
[Tue Jul 21 07:29:23.924556 2026] [security2:error] [pid 230252:tid 230442] [client 103.174.34.15:52595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KA00Dwhk5-Z44XrphyAAAAtM"]
[Tue Jul 21 07:29:23.929783 2026] [security2:error] [pid 229246:tid 229414] [client 65.111.28.166:33081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9KAyBMYeh5YLVG45yFBwAAAjo"]
[Tue Jul 21 07:29:24.004740 2026] [security2:error] [pid 230252:tid 230478] [client 20.104.96.117:7060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/dex.php"] [unique_id "al9KBE0Dwhk5-Z44XrphzAAAAvc"]
[Tue Jul 21 07:29:24.301207 2026] [security2:error] [pid 229246:tid 229408] [client 20.104.96.117:62865] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "politicabrasil.com.br"] [uri "/1.php"] [unique_id "al9KBCBMYeh5YLVG45yFDwAAAjQ"]
[Tue Jul 21 07:29:24.301322 2026] [security2:error] [pid 229246:tid 229408] [client 20.104.96.117:62865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/1.php"] [unique_id "al9KBCBMYeh5YLVG45yFDwAAAjQ"]
[Tue Jul 21 07:29:24.434180 2026] [security2:error] [pid 229246:tid 229448] [client 65.111.28.166:23631] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9KBCBMYeh5YLVG45yFEQAAAlw"]
[Tue Jul 21 07:29:24.633406 2026] [security2:error] [pid 230252:tid 230415] [client 20.104.96.117:62458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/ms.php"] [unique_id "al9KBE0Dwhk5-Z44Xrph1QAAArg"]
[Tue Jul 21 07:29:24.726060 2026] [security2:error] [pid 229246:tid 229451] [client 62.102.148.164:33452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KBCBMYeh5YLVG45yFFwAAAl8"]
[Tue Jul 21 07:29:24.726183 2026] [security2:error] [pid 229246:tid 229451] [client 62.102.148.164:33452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KBCBMYeh5YLVG45yFFwAAAl8"]
[Tue Jul 21 07:29:24.753919 2026] [security2:error] [pid 230252:tid 230426] [client 213.152.162.104:44018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9KBE0Dwhk5-Z44Xrph2AAAAsM"]
[Tue Jul 21 07:29:24.754024 2026] [security2:error] [pid 230252:tid 230426] [client 213.152.162.104:44018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9KBE0Dwhk5-Z44Xrph2AAAAsM"]
[Tue Jul 21 07:29:24.936981 2026] [security2:error] [pid 230252:tid 230404] [client 65.111.28.166:21351] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9KBE0Dwhk5-Z44Xrph2wAAAq0"]
[Tue Jul 21 07:29:24.989140 2026] [autoindex:error] [pid 230252:tid 230437] [client 20.104.96.117:62866] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/politicabrasil.com.br/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:25.095473 2026] [security2:error] [pid 230252:tid 230501] [client 20.197.195.24:12346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph3QAAAw4"]
[Tue Jul 21 07:29:25.095896 2026] [security2:error] [pid 230252:tid 230486] [client 45.8.17.73:64209] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/comment-content/"] [unique_id "al9KBU0Dwhk5-Z44Xrph3gAAAv8"]
[Tue Jul 21 07:29:25.258205 2026] [autoindex:error] [pid 229246:tid 229377] [client 64.23.212.162:39808] AH01276: Cannot serve directory /home2/andr9968/artemcamadas.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:25.264933 2026] [security2:error] [pid 230252:tid 230477] [client 20.104.96.117:62866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/memberfuns.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph4QAAAvY"]
[Tue Jul 21 07:29:25.444664 2026] [security2:error] [pid 230252:tid 230411] [client 65.111.28.166:63265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9KBU0Dwhk5-Z44Xrph5QAAArQ"]
[Tue Jul 21 07:29:25.511206 2026] [security2:error] [pid 229246:tid 229395] [client 82.102.18.182:51092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-login.php"] [unique_id "al9KBSBMYeh5YLVG45yFJQAAAic"]
[Tue Jul 21 07:29:25.567697 2026] [security2:error] [pid 230252:tid 230429] [client 20.104.96.117:62898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/0.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph5wAAAsY"]
[Tue Jul 21 07:29:25.756946 2026] [security2:error] [pid 230252:tid 230478] [client 20.197.195.24:12313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph7AAAAvc"]
[Tue Jul 21 07:29:25.782590 2026] [security2:error] [pid 229246:tid 229275] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBSBMYeh5YLVG45yFKQACFxw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.782593 2026] [security2:error] [pid 229246:tid 229266] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBSBMYeh5YLVG45yFKgACLBM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.782603 2026] [security2:error] [pid 230252:tid 230375] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph7QADGHg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.845207 2026] [security2:error] [pid 229246:tid 229286] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBSBMYeh5YLVG45yFKwACMCc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.846750 2026] [security2:error] [pid 229246:tid 229261] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBSBMYeh5YLVG45yFLAACZw4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.859979 2026] [security2:error] [pid 229246:tid 229383] [client 20.104.96.117:7067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/BDKR28.php"] [unique_id "al9KBSBMYeh5YLVG45yFLQAAAhs"]
[Tue Jul 21 07:29:25.906325 2026] [security2:error] [pid 229246:tid 229362] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBSBMYeh5YLVG45yFLgACVXM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.909282 2026] [security2:error] [pid 229246:tid 229273] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBSBMYeh5YLVG45yFLwACiBo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.910526 2026] [security2:error] [pid 230252:tid 230278] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph7wAC6hg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:25.965955 2026] [security2:error] [pid 230252:tid 230368] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph8AACsXE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:26.006506 2026] [security2:error] [pid 229246:tid 229332] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBiBMYeh5YLVG45yFMQACT1U"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:26.148862 2026] [security2:error] [pid 230252:tid 230432] [client 20.104.96.117:7043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/green1.php"] [unique_id "al9KBk0Dwhk5-Z44Xrph9QAAAsk"]
[Tue Jul 21 07:29:26.343375 2026] [security2:error] [pid 229246:tid 229493] [client 173.24.185.52:65270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KBSBMYeh5YLVG45yFIQAAAok"]
[Tue Jul 21 07:29:26.343580 2026] [security2:error] [pid 229246:tid 229493] [client 173.24.185.52:65270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KBSBMYeh5YLVG45yFIQAAAok"]
[Tue Jul 21 07:29:26.374397 2026] [autoindex:error] [pid 230252:tid 230504] [client 64.23.212.162:36412] AH01276: Cannot serve directory /home2/andr9968/artemcamadas.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:26.425114 2026] [security2:error] [pid 229246:tid 229406] [client 20.104.96.117:62853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/nc4.php"] [unique_id "al9KBiBMYeh5YLVG45yFOgAAAjI"]
[Tue Jul 21 07:29:26.484492 2026] [security2:error] [pid 229246:tid 229481] [client 45.8.17.129:52521] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/images/"] [unique_id "al9KBiBMYeh5YLVG45yFOwAAAn0"]
[Tue Jul 21 07:29:26.607736 2026] [security2:error] [pid 230252:tid 230507] [client 82.102.18.182:51102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-login.php"] [unique_id "al9KBk0Dwhk5-Z44Xrph-gAAAxQ"]
[Tue Jul 21 07:29:26.646377 2026] [security2:error] [pid 230252:tid 230404] [client 20.104.96.117:42274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/output.php"] [unique_id "al9KBk0Dwhk5-Z44Xrph_AAAAq0"]
[Tue Jul 21 07:29:26.765608 2026] [security2:error] [pid 230252:tid 230437] [client 20.104.96.117:6296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/a1.php"] [unique_id "al9KBk0Dwhk5-Z44Xrph_QAAAs4"]
[Tue Jul 21 07:29:26.769956 2026] [security2:error] [pid 229246:tid 229484] [client 20.151.10.161:49058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file48.php"] [unique_id "al9KBiBMYeh5YLVG45yFQgAAAoA"]
[Tue Jul 21 07:29:26.779535 2026] [security2:error] [pid 230252:tid 230363] [remote 168.226.217.231:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.217.226.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KBU0Dwhk5-Z44Xrph7gAC4Ww"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:29:26.863362 2026] [security2:error] [pid 230252:tid 230471] [client 20.197.195.24:20595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/for.php"] [unique_id "al9KBk0Dwhk5-Z44XrpiAQAAAvA"]
[Tue Jul 21 07:29:26.998808 2026] [security2:error] [pid 229246:tid 229488] [client 82.102.28.107:49466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KBiBMYeh5YLVG45yFRwAAAoQ"]
[Tue Jul 21 07:29:26.998959 2026] [security2:error] [pid 229246:tid 229488] [client 82.102.28.107:49466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KBiBMYeh5YLVG45yFRwAAAoQ"]
[Tue Jul 21 07:29:27.093364 2026] [security2:error] [pid 229246:tid 229408] [client 20.104.96.117:7052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/eee.php"] [unique_id "al9KByBMYeh5YLVG45yFSwAAAjQ"]
[Tue Jul 21 07:29:27.400328 2026] [security2:error] [pid 230252:tid 230411] [client 20.104.96.117:62437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-aothait.php"] [unique_id "al9KB00Dwhk5-Z44XrpiCAAAArQ"]
[Tue Jul 21 07:29:27.482804 2026] [autoindex:error] [pid 230252:tid 230429] [client 82.102.18.182:33740] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:27.758310 2026] [security2:error] [pid 229246:tid 229381] [client 20.104.96.117:6291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/config.json.php"] [unique_id "al9KByBMYeh5YLVG45yFWAAAAhk"]
[Tue Jul 21 07:29:27.777078 2026] [security2:error] [pid 230252:tid 230468] [client 20.197.195.24:20553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lirioshoppy.com.br"] [uri "/raw.php"] [unique_id "al9KB00Dwhk5-Z44XrpiDwAAAu0"]
[Tue Jul 21 07:29:28.079390 2026] [security2:error] [pid 229246:tid 229377] [client 20.104.96.117:62887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9KCCBMYeh5YLVG45yFXAAAAhU"]
[Tue Jul 21 07:29:28.080040 2026] [security2:error] [pid 229246:tid 229427] [client 45.8.17.124:30231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/options.php"] [unique_id "al9KCCBMYeh5YLVG45yFXQAAAkc"]
[Tue Jul 21 07:29:28.238423 2026] [security2:error] [pid 230252:tid 230423] [client 45.251.232.145:57270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KCE0Dwhk5-Z44XrpiEwAAAsA"]
[Tue Jul 21 07:29:28.238549 2026] [security2:error] [pid 230252:tid 230423] [client 45.251.232.145:57270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KCE0Dwhk5-Z44XrpiEwAAAsA"]
[Tue Jul 21 07:29:28.325605 2026] [security2:error] [pid 229246:tid 229459] [client 20.104.96.117:42406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-file-120.php"] [unique_id "al9KCCBMYeh5YLVG45yFZAAAAmc"]
[Tue Jul 21 07:29:28.376362 2026] [security2:error] [pid 230252:tid 230443] [client 37.140.223.68:47785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KCE0Dwhk5-Z44XrpiEgAAAtQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:28.385892 2026] [security2:error] [pid 229246:tid 229489] [client 20.104.96.117:6257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/k2.php"] [unique_id "al9KCCBMYeh5YLVG45yFZgAAAoU"]
[Tue Jul 21 07:29:28.579197 2026] [security2:error] [pid 229246:tid 229502] [client 82.102.18.182:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-login.php"] [unique_id "al9KCCBMYeh5YLVG45yFaAAAApI"]
[Tue Jul 21 07:29:28.702418 2026] [security2:error] [pid 229246:tid 229405] [client 20.104.96.117:7100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9KCCBMYeh5YLVG45yFbAAAAjE"]
[Tue Jul 21 07:29:28.763277 2026] [security2:error] [pid 230252:tid 230407] [client 47.128.44.140:32346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "clinicaleonazevedo.com.br"] [uri "/robots.txt"] [unique_id "al9KCE0Dwhk5-Z44XrpiFQAAArA"]
[Tue Jul 21 07:29:28.783689 2026] [autoindex:error] [pid 229246:tid 229401] [client 82.102.18.182:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:28.978575 2026] [security2:error] [pid 229246:tid 229430] [client 20.104.96.117:7053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9KCCBMYeh5YLVG45yFdgAAAko"]
[Tue Jul 21 07:29:29.077637 2026] [security2:error] [pid 230252:tid 230381] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KCU0Dwhk5-Z44XrpiGAACzH4"]
[Tue Jul 21 07:29:29.077782 2026] [security2:error] [pid 230252:tid 230435] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KCU0Dwhk5-Z44XrpiGAACzH4"]
[Tue Jul 21 07:29:29.178646 2026] [security2:error] [pid 230252:tid 230454] [client 20.104.96.117:42421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/special.php"] [unique_id "al9KCU0Dwhk5-Z44XrpiGQAAAt8"]
[Tue Jul 21 07:29:29.267530 2026] [security2:error] [pid 230252:tid 230404] [client 20.104.96.117:62431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9KCU0Dwhk5-Z44XrpiHAAAAq0"]
[Tue Jul 21 07:29:29.440095 2026] [security2:error] [pid 229246:tid 229472] [client 20.220.225.223:8944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/zzz.php"] [unique_id "al9KCSBMYeh5YLVG45yFgAAAAnQ"]
[Tue Jul 21 07:29:29.578765 2026] [security2:error] [pid 230252:tid 230471] [client 20.104.96.117:62451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/for.php"] [unique_id "al9KCU0Dwhk5-Z44XrpiIgAAAvA"]
[Tue Jul 21 07:29:29.876782 2026] [security2:error] [pid 230252:tid 230446] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9KCU0Dwhk5-Z44XrpiJwAAAtc"]
[Tue Jul 21 07:29:29.950128 2026] [security2:error] [pid 229246:tid 229381] [client 20.104.96.117:62883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/raw.php"] [unique_id "al9KCSBMYeh5YLVG45yFiQAAAhk"]
[Tue Jul 21 07:29:30.131357 2026] [security2:error] [pid 229246:tid 229478] [client 139.135.44.145:54063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KCiBMYeh5YLVG45yFjQAAAno"]
[Tue Jul 21 07:29:30.131486 2026] [security2:error] [pid 229246:tid 229478] [client 139.135.44.145:54063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KCiBMYeh5YLVG45yFjQAAAno"]
[Tue Jul 21 07:29:30.166427 2026] [security2:error] [pid 230252:tid 230478] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KCk0Dwhk5-Z44XrpiKQAAAvc"]
[Tue Jul 21 07:29:30.198093 2026] [security2:error] [pid 229246:tid 229396] [client 20.104.96.117:59797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/as.php"] [unique_id "al9KCiBMYeh5YLVG45yFjgAAAig"]
[Tue Jul 21 07:29:30.238039 2026] [security2:error] [pid 230252:tid 230486] [client 117.251.86.144:36512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KCk0Dwhk5-Z44XrpiKgAAAv8"]
[Tue Jul 21 07:29:30.238177 2026] [security2:error] [pid 230252:tid 230486] [client 117.251.86.144:36512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KCk0Dwhk5-Z44XrpiKgAAAv8"]
[Tue Jul 21 07:29:30.545915 2026] [security2:error] [pid 230252:tid 230343] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KCk0Dwhk5-Z44XrpiMAAC1Vg"]
[Tue Jul 21 07:29:30.546131 2026] [security2:error] [pid 230252:tid 230444] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KCk0Dwhk5-Z44XrpiMAAC1Vg"]
[Tue Jul 21 07:29:30.613586 2026] [security2:error] [pid 229246:tid 229379] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9KCiBMYeh5YLVG45yFlwAAAhc"]
[Tue Jul 21 07:29:30.885199 2026] [security2:error] [pid 229246:tid 229492] [client 45.8.17.145:47829] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/chosen.php"] [unique_id "al9KCiBMYeh5YLVG45yFnAAAAog"]
[Tue Jul 21 07:29:30.898486 2026] [security2:error] [pid 229246:tid 229479] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9KCiBMYeh5YLVG45yFnQAAAns"]
[Tue Jul 21 07:29:31.027632 2026] [security2:error] [pid 230252:tid 230500] [client 173.239.211.139:32571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9KC00Dwhk5-Z44XrpiNAAAAw0"]
[Tue Jul 21 07:29:31.028291 2026] [security2:error] [pid 229246:tid 229377] [client 173.239.211.139:60591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9KCyBMYeh5YLVG45yFnwAAAhU"]
[Tue Jul 21 07:29:31.029827 2026] [security2:error] [pid 230252:tid 230474] [client 173.239.211.122:38649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9KC00Dwhk5-Z44XrpiMwAAAvM"]
[Tue Jul 21 07:29:31.183812 2026] [security2:error] [pid 230252:tid 230400] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9KC00Dwhk5-Z44XrpiNwAAAqk"]
[Tue Jul 21 07:29:31.221169 2026] [security2:error] [pid 230252:tid 230440] [client 59.96.220.140:53337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KC00Dwhk5-Z44XrpiOwAAAtE"]
[Tue Jul 21 07:29:31.221290 2026] [security2:error] [pid 230252:tid 230440] [client 59.96.220.140:53337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KC00Dwhk5-Z44XrpiOwAAAtE"]
[Tue Jul 21 07:29:31.487470 2026] [security2:error] [pid 230252:tid 230452] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9KC00Dwhk5-Z44XrpiQAAAAt0"]
[Tue Jul 21 07:29:31.574294 2026] [security2:error] [pid 229246:tid 229474] [client 20.104.96.117:59622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9KCyBMYeh5YLVG45yFpQAAAnY"]
[Tue Jul 21 07:29:31.773755 2026] [security2:error] [pid 229246:tid 229416] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9KCyBMYeh5YLVG45yFqwAAAjw"]
[Tue Jul 21 07:29:31.845098 2026] [security2:error] [pid 229246:tid 229403] [client 20.52.136.55:1741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/jga.php"] [unique_id "al9KCyBMYeh5YLVG45yFrAAAAi8"]
[Tue Jul 21 07:29:31.884099 2026] [security2:error] [pid 229246:tid 229378] [client 45.8.17.65:21213] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/images/as.php"] [unique_id "al9KCyBMYeh5YLVG45yFsAAAAhY"]
[Tue Jul 21 07:29:32.061247 2026] [security2:error] [pid 229246:tid 229460] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9KDCBMYeh5YLVG45yFswAAAmg"]
[Tue Jul 21 07:29:32.345974 2026] [security2:error] [pid 230252:tid 230429] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9KDE0Dwhk5-Z44XrpiQgAAAsY"]
[Tue Jul 21 07:29:32.560938 2026] [security2:error] [pid 230252:tid 230509] [client 20.151.10.161:48613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file6.php"] [unique_id "al9KDE0Dwhk5-Z44XrpiQwAAAxY"]
[Tue Jul 21 07:29:32.630577 2026] [security2:error] [pid 229246:tid 229425] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9KDCBMYeh5YLVG45yFwgAAAkU"]
[Tue Jul 21 07:29:32.783187 2026] [security2:error] [pid 229246:tid 229442] [client 45.8.17.129:50043] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-security.php"] [unique_id "al9KDCBMYeh5YLVG45yFygAAAlY"]
[Tue Jul 21 07:29:32.914972 2026] [security2:error] [pid 229246:tid 229400] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9KDCBMYeh5YLVG45yFzwAAAiw"]
[Tue Jul 21 07:29:32.962830 2026] [security2:error] [pid 229246:tid 229437] [client 103.106.20.201:58028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDCBMYeh5YLVG45yF0AAAAlE"]
[Tue Jul 21 07:29:32.963005 2026] [security2:error] [pid 229246:tid 229437] [client 103.106.20.201:58028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDCBMYeh5YLVG45yF0AAAAlE"]
[Tue Jul 21 07:29:33.184727 2026] [security2:error] [pid 229246:tid 229373] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KDSBMYeh5YLVG45yF1QAChX4"]
[Tue Jul 21 07:29:33.184858 2026] [security2:error] [pid 229246:tid 229489] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KDSBMYeh5YLVG45yF1QAChX4"]
[Tue Jul 21 07:29:33.199559 2026] [security2:error] [pid 229246:tid 229497] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9KDSBMYeh5YLVG45yF1gAAAo0"]
[Tue Jul 21 07:29:33.309655 2026] [security2:error] [pid 229246:tid 229475] [client 20.104.96.117:59805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/w1px.php"] [unique_id "al9KDSBMYeh5YLVG45yF2AAAAnc"]
[Tue Jul 21 07:29:33.484994 2026] [security2:error] [pid 229246:tid 229406] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9KDSBMYeh5YLVG45yF3AAAAjI"]
[Tue Jul 21 07:29:33.638482 2026] [security2:error] [pid 229246:tid 229483] [client 37.140.223.68:39299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KDSBMYeh5YLVG45yF4AAAAn8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:33.719912 2026] [security2:error] [pid 229246:tid 229407] [client 152.59.154.239:55529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDSBMYeh5YLVG45yF4gAAAjM"]
[Tue Jul 21 07:29:33.720038 2026] [security2:error] [pid 229246:tid 229407] [client 152.59.154.239:55529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDSBMYeh5YLVG45yF4gAAAjM"]
[Tue Jul 21 07:29:33.720358 2026] [security2:error] [pid 230252:tid 230462] [client 20.220.225.223:8953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/wicked.php"] [unique_id "al9KDU0Dwhk5-Z44XrpiRwAAAuc"]
[Tue Jul 21 07:29:33.787607 2026] [security2:error] [pid 230252:tid 230423] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9KDU0Dwhk5-Z44XrpiSAAAAsA"]
[Tue Jul 21 07:29:33.860085 2026] [security2:error] [pid 230252:tid 230334] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDU0Dwhk5-Z44XrpiSgAC_08"]
[Tue Jul 21 07:29:33.860261 2026] [security2:error] [pid 230252:tid 230486] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDU0Dwhk5-Z44XrpiSgAC_08"]
[Tue Jul 21 07:29:33.871733 2026] [security2:error] [pid 230252:tid 230482] [client 213.152.162.104:53258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KDU0Dwhk5-Z44XrpiSwAAAvs"]
[Tue Jul 21 07:29:33.871834 2026] [security2:error] [pid 230252:tid 230482] [client 213.152.162.104:53258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KDU0Dwhk5-Z44XrpiSwAAAvs"]
[Tue Jul 21 07:29:33.931606 2026] [security2:error] [pid 230252:tid 230350] [remote 91.142.222.105:46778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roha.life"] [uri "/wp-login.php"] [unique_id "al9KDU0Dwhk5-Z44XrpiTAACz18"]
[Tue Jul 21 07:29:33.980837 2026] [security2:error] [pid 230252:tid 230386] [client 45.8.17.115:22023] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/system.php"] [unique_id "al9KDU0Dwhk5-Z44XrpiTQAAAps"]
[Tue Jul 21 07:29:33.986003 2026] [security2:error] [pid 229246:tid 229274] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KDSBMYeh5YLVG45yF5QACIRs"]
[Tue Jul 21 07:29:33.986121 2026] [security2:error] [pid 229246:tid 229389] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KDSBMYeh5YLVG45yF5QACIRs"]
[Tue Jul 21 07:29:34.016654 2026] [security2:error] [pid 229246:tid 229343] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KDiBMYeh5YLVG45yF5gACOmA"]
[Tue Jul 21 07:29:34.016776 2026] [security2:error] [pid 229246:tid 229414] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KDiBMYeh5YLVG45yF5gACOmA"]
[Tue Jul 21 07:29:34.072091 2026] [security2:error] [pid 229246:tid 229455] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9KDiBMYeh5YLVG45yF6AAAAmM"]
[Tue Jul 21 07:29:34.110197 2026] [security2:error] [pid 230252:tid 230500] [client 20.151.10.161:49145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/a2.php"] [unique_id "al9KDk0Dwhk5-Z44XrpiUAAAAw0"]
[Tue Jul 21 07:29:34.180848 2026] [security2:error] [pid 230252:tid 230508] [client 103.162.129.114:51547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KDk0Dwhk5-Z44XrpiUQAAAxU"]
[Tue Jul 21 07:29:34.180983 2026] [security2:error] [pid 230252:tid 230508] [client 103.162.129.114:51547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KDk0Dwhk5-Z44XrpiUQAAAxU"]
[Tue Jul 21 07:29:34.356331 2026] [security2:error] [pid 230252:tid 230404] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9KDk0Dwhk5-Z44XrpiVQAAAq0"]
[Tue Jul 21 07:29:34.358311 2026] [security2:error] [pid 230252:tid 230458] [client 154.192.233.199:60305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDk0Dwhk5-Z44XrpiVAAAAuM"]
[Tue Jul 21 07:29:34.358434 2026] [security2:error] [pid 230252:tid 230458] [client 154.192.233.199:60305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDk0Dwhk5-Z44XrpiVAAAAuM"]
[Tue Jul 21 07:29:34.475229 2026] [security2:error] [pid 229246:tid 229416] [client 175.45.70.82:60331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDiBMYeh5YLVG45yF8AAAAjw"]
[Tue Jul 21 07:29:34.475351 2026] [security2:error] [pid 229246:tid 229416] [client 175.45.70.82:60331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDiBMYeh5YLVG45yF8AAAAjw"]
[Tue Jul 21 07:29:34.641726 2026] [security2:error] [pid 229246:tid 229423] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9KDiBMYeh5YLVG45yF8wAAAkM"]
[Tue Jul 21 07:29:34.677977 2026] [security2:error] [pid 229246:tid 229454] [client 20.104.96.117:59594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/yawa.php"] [unique_id "al9KDiBMYeh5YLVG45yF9QAAAmI"]
[Tue Jul 21 07:29:34.686607 2026] [security2:error] [pid 229246:tid 229378] [client 103.174.34.15:53084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDiBMYeh5YLVG45yF9gAAAhY"]
[Tue Jul 21 07:29:34.686690 2026] [security2:error] [pid 229246:tid 229378] [client 103.174.34.15:53084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KDiBMYeh5YLVG45yF9gAAAhY"]
[Tue Jul 21 07:29:34.931386 2026] [security2:error] [pid 230252:tid 230393] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9KDk0Dwhk5-Z44XrpiWQAAAqI"]
[Tue Jul 21 07:29:35.072112 2026] [security2:error] [pid 230252:tid 230466] [client 20.220.225.223:46116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/old.php"] [unique_id "al9KD00Dwhk5-Z44XrpiWgAAAus"]
[Tue Jul 21 07:29:35.084992 2026] [security2:error] [pid 230252:tid 230479] [client 45.8.17.118:35933] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/header.php"] [unique_id "al9KD00Dwhk5-Z44XrpiWwAAAvg"]
[Tue Jul 21 07:29:35.390165 2026] [security2:error] [pid 229246:tid 229390] [client 82.102.28.107:40954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KDyBMYeh5YLVG45yF_wAAAiI"]
[Tue Jul 21 07:29:35.390265 2026] [security2:error] [pid 229246:tid 229390] [client 82.102.28.107:40954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KDyBMYeh5YLVG45yF_wAAAiI"]
[Tue Jul 21 07:29:35.392017 2026] [security2:error] [pid 230252:tid 230493] [client 20.151.10.161:49132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/file15.php"] [unique_id "al9KD00Dwhk5-Z44XrpiXgAAAwY"]
[Tue Jul 21 07:29:35.481936 2026] [security2:error] [pid 230252:tid 230453] [client 173.24.185.52:49438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KD00Dwhk5-Z44XrpiXwAAAt4"]
[Tue Jul 21 07:29:35.482058 2026] [security2:error] [pid 230252:tid 230453] [client 173.24.185.52:49438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KD00Dwhk5-Z44XrpiXwAAAt4"]
[Tue Jul 21 07:29:36.097584 2026] [security2:error] [pid 229246:tid 229471] [client 45.8.17.112:52899] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/fonts/"] [unique_id "al9KECBMYeh5YLVG45yGEAAAAnM"]
[Tue Jul 21 07:29:36.159902 2026] [security2:error] [pid 229246:tid 229475] [client 20.104.96.117:59789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/js.php"] [unique_id "al9KECBMYeh5YLVG45yGEgAAAnc"]
[Tue Jul 21 07:29:36.729577 2026] [security2:error] [pid 230252:tid 230265] [remote 104.207.39.78:60793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.39.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9KD00Dwhk5-Z44XrpiYAADDAs"]
[Tue Jul 21 07:29:36.999651 2026] [security2:error] [pid 230252:tid 230507] [client 20.151.10.161:49025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/jp.php"] [unique_id "al9KEE0Dwhk5-Z44XrpicQAAAxQ"]
[Tue Jul 21 07:29:37.284586 2026] [security2:error] [pid 230252:tid 230410] [client 45.8.17.59:62495] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "al9KEU0Dwhk5-Z44XrpicwAAArM"]
[Tue Jul 21 07:29:38.083847 2026] [security2:error] [pid 230252:tid 230470] [client 45.8.17.132:39409] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/a.php"] [unique_id "al9KEk0Dwhk5-Z44XrpifQAAAu8"]
[Tue Jul 21 07:29:38.350371 2026] [security2:error] [pid 230252:tid 230445] [client 136.144.33.101:31349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KEk0Dwhk5-Z44XrpifwAAAtY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:38.716562 2026] [security2:error] [pid 229246:tid 229424] [client 45.251.232.145:57796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KEiBMYeh5YLVG45yGNgAAAkQ"]
[Tue Jul 21 07:29:38.716660 2026] [security2:error] [pid 229246:tid 229424] [client 45.251.232.145:57796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KEiBMYeh5YLVG45yGNgAAAkQ"]
[Tue Jul 21 07:29:38.789878 2026] [security2:error] [pid 229246:tid 229464] [client 20.52.136.55:1566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/k.php"] [unique_id "al9KEiBMYeh5YLVG45yGNwAAAmw"]
[Tue Jul 21 07:29:39.638280 2026] [security2:error] [pid 229246:tid 229272] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KEyBMYeh5YLVG45yGQwACVBk"]
[Tue Jul 21 07:29:39.638445 2026] [security2:error] [pid 229246:tid 229440] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KEyBMYeh5YLVG45yGQwACVBk"]
[Tue Jul 21 07:29:39.956892 2026] [security2:error] [pid 229246:tid 229483] [client 20.151.10.161:49115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/f35.php"] [unique_id "al9KEyBMYeh5YLVG45yGSQAAAn8"]
[Tue Jul 21 07:29:39.996153 2026] [security2:error] [pid 229246:tid 229401] [client 45.8.17.114:60943] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "al9KEyBMYeh5YLVG45yGTQAAAi0"]
[Tue Jul 21 07:29:40.098810 2026] [security2:error] [pid 229246:tid 229328] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrareginaprata1781718333175.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9KFCBMYeh5YLVG45yGUAACHVE"]
[Tue Jul 21 07:29:40.187007 2026] [security2:error] [pid 230252:tid 230431] [client 34.26.127.63:60289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.127.26.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "startonesite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KFE0Dwhk5-Z44XrpiiwAAAsg"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:29:40.738025 2026] [security2:error] [pid 230252:tid 230473] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrareginaprata1781718333175.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9KFE0Dwhk5-Z44XrpilQAAAvI"]
[Tue Jul 21 07:29:40.822023 2026] [security2:error] [pid 230252:tid 230416] [client 59.96.220.140:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KFE0Dwhk5-Z44XrpilgAAArk"]
[Tue Jul 21 07:29:40.822129 2026] [security2:error] [pid 230252:tid 230416] [client 59.96.220.140:53812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KFE0Dwhk5-Z44XrpilgAAArk"]
[Tue Jul 21 07:29:40.850514 2026] [security2:error] [pid 229246:tid 229389] [client 117.251.86.144:35996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KFCBMYeh5YLVG45yGYgAAAiE"]
[Tue Jul 21 07:29:40.850606 2026] [security2:error] [pid 229246:tid 229389] [client 117.251.86.144:35996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KFCBMYeh5YLVG45yGYgAAAiE"]
[Tue Jul 21 07:29:40.924060 2026] [security2:error] [pid 230252:tid 230501] [client 34.26.127.63:62762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9KFE0Dwhk5-Z44XrpilwAAAw4"]
[Tue Jul 21 07:29:40.973700 2026] [security2:error] [pid 229246:tid 229469] [client 139.135.44.145:54877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KFCBMYeh5YLVG45yGYwAAAnE"]
[Tue Jul 21 07:29:40.973844 2026] [security2:error] [pid 229246:tid 229469] [client 139.135.44.145:54877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KFCBMYeh5YLVG45yGYwAAAnE"]
[Tue Jul 21 07:29:41.090846 2026] [security2:error] [pid 230252:tid 230470] [client 20.104.96.117:59600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/core.php"] [unique_id "al9KFU0Dwhk5-Z44XrpimwAAAu8"]
[Tue Jul 21 07:29:41.345541 2026] [autoindex:error] [pid 229246:tid 229421] [client 98.91.173.173:57554] AH01276: Cannot serve directory /home2/kncont40/knplay.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:41.465804 2026] [security2:error] [pid 230252:tid 230394] [client 34.26.127.63:54492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9KFU0Dwhk5-Z44XrpingAAAqM"]
[Tue Jul 21 07:29:41.736376 2026] [security2:error] [pid 230252:tid 230449] [client 136.144.33.28:42605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KFU0Dwhk5-Z44XrpiowAAAto"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:42.051385 2026] [security2:error] [pid 229246:tid 229497] [client 109.248.148.246:37428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KFiBMYeh5YLVG45yGdQAAAo0"]
[Tue Jul 21 07:29:42.051491 2026] [security2:error] [pid 229246:tid 229497] [client 109.248.148.246:37428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KFiBMYeh5YLVG45yGdQAAAo0"]
[Tue Jul 21 07:29:42.080217 2026] [security2:error] [pid 229246:tid 229489] [client 34.26.127.63:52278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9KFiBMYeh5YLVG45yGeAAAAoU"]
[Tue Jul 21 07:29:42.286111 2026] [security2:error] [pid 230252:tid 230503] [client 45.8.17.132:61029] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Requests/src/Exception/Transport/"] [unique_id "al9KFk0Dwhk5-Z44XrpiqgAAAxA"]
[Tue Jul 21 07:29:42.300551 2026] [security2:error] [pid 230252:tid 230499] [client 62.102.148.164:44312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KFk0Dwhk5-Z44XrpiqwAAAww"]
[Tue Jul 21 07:29:42.300624 2026] [security2:error] [pid 230252:tid 230499] [client 62.102.148.164:44312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KFk0Dwhk5-Z44XrpiqwAAAww"]
[Tue Jul 21 07:29:42.456273 2026] [security2:error] [pid 230252:tid 230461] [client 20.151.10.161:48612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-load.php"] [unique_id "al9KFk0Dwhk5-Z44XrpirQAAAuY"]
[Tue Jul 21 07:29:42.901278 2026] [security2:error] [pid 230252:tid 230410] [client 34.26.127.63:55432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9KFk0Dwhk5-Z44XrpitAAAArM"]
[Tue Jul 21 07:29:43.129453 2026] [security2:error] [pid 230252:tid 230348] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrareginaprata1781718333175.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9KF00Dwhk5-Z44XrpitgAC8F0"]
[Tue Jul 21 07:29:43.511683 2026] [security2:error] [pid 230252:tid 230439] [client 34.26.127.63:54778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9KF00Dwhk5-Z44XrpivAAAAtA"]
[Tue Jul 21 07:29:43.653677 2026] [security2:error] [pid 230252:tid 230456] [client 103.106.20.201:58610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KF00Dwhk5-Z44XrpivgAAAuE"]
[Tue Jul 21 07:29:43.653830 2026] [security2:error] [pid 230252:tid 230456] [client 103.106.20.201:58610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KF00Dwhk5-Z44XrpivgAAAuE"]
[Tue Jul 21 07:29:43.689856 2026] [security2:error] [pid 229246:tid 229430] [client 45.8.17.131:60993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/"] [unique_id "al9KFyBMYeh5YLVG45yGjAAAAko"]
[Tue Jul 21 07:29:43.713345 2026] [security2:error] [pid 229246:tid 229346] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KFyBMYeh5YLVG45yGjgACdGM"]
[Tue Jul 21 07:29:43.713656 2026] [security2:error] [pid 229246:tid 229472] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KFyBMYeh5YLVG45yGjgACdGM"]
[Tue Jul 21 07:29:43.723177 2026] [security2:error] [pid 230252:tid 230453] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrareginaprata1781718333175.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9KF00Dwhk5-Z44XrpivwAAAt4"]
[Tue Jul 21 07:29:44.023953 2026] [security2:error] [pid 229246:tid 229484] [client 20.151.10.161:49053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/xwpg.php"] [unique_id "al9KGCBMYeh5YLVG45yGlgAAAoA"]
[Tue Jul 21 07:29:44.039696 2026] [security2:error] [pid 229246:tid 229336] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGlwACXVk"]
[Tue Jul 21 07:29:44.039876 2026] [security2:error] [pid 229246:tid 229449] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGlwACXVk"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:29:44.240124 2026] [security2:error] [pid 230252:tid 230391] [client 20.220.225.223:46091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/ms-new.php"] [unique_id "al9KGE0Dwhk5-Z44XrpiyAAAAqA"]
[Tue Jul 21 07:29:44.260130 2026] [security2:error] [pid 229246:tid 229417] [client 34.26.127.63:50044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9KGCBMYeh5YLVG45yGmwAAAj0"]
[Tue Jul 21 07:29:44.287159 2026] [security2:error] [pid 229246:tid 229490] [client 20.197.192.193:47951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KGCBMYeh5YLVG45yGnAAAAoY"]
[Tue Jul 21 07:29:44.317514 2026] [security2:error] [pid 229246:tid 229446] [client 20.197.192.193:30296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KGCBMYeh5YLVG45yGngAAAlo"]
[Tue Jul 21 07:29:44.370298 2026] [security2:error] [pid 230252:tid 230506] [client 20.197.192.193:47976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/dp.php"] [unique_id "al9KGE0Dwhk5-Z44XrpizAAAAxM"]
[Tue Jul 21 07:29:44.390786 2026] [security2:error] [pid 229246:tid 229350] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGnwACQGc"]
[Tue Jul 21 07:29:44.391011 2026] [security2:error] [pid 229246:tid 229420] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGnwACQGc"]
[Tue Jul 21 07:29:44.419404 2026] [security2:error] [pid 229246:tid 229478] [client 20.197.192.193:30332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/old.php"] [unique_id "al9KGCBMYeh5YLVG45yGowAAAno"]
[Tue Jul 21 07:29:44.450652 2026] [security2:error] [pid 229246:tid 229427] [client 20.197.192.193:30272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/ms-new.php"] [unique_id "al9KGCBMYeh5YLVG45yGpAAAAkc"]
[Tue Jul 21 07:29:44.494952 2026] [security2:error] [pid 229246:tid 229398] [client 20.197.192.193:47937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/track.php"] [unique_id "al9KGCBMYeh5YLVG45yGpgAAAio"]
[Tue Jul 21 07:29:44.517134 2026] [security2:error] [pid 229246:tid 229464] [client 20.197.192.193:30278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/2352356666.php"] [unique_id "al9KGCBMYeh5YLVG45yGpwAAAmw"]
[Tue Jul 21 07:29:44.552740 2026] [security2:error] [pid 229246:tid 229479] [client 20.197.192.193:47957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/pn.php"] [unique_id "al9KGCBMYeh5YLVG45yGqQAAAns"]
[Tue Jul 21 07:29:44.597860 2026] [security2:error] [pid 229246:tid 229477] [client 20.197.192.193:47992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9KGCBMYeh5YLVG45yGqgAAAnk"]
[Tue Jul 21 07:29:44.645526 2026] [security2:error] [pid 229246:tid 229502] [client 20.197.192.193:30291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/dr.php"] [unique_id "al9KGCBMYeh5YLVG45yGrgAAApI"]
[Tue Jul 21 07:29:44.723954 2026] [security2:error] [pid 229246:tid 229435] [client 20.197.192.193:47989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/2x.php"] [unique_id "al9KGCBMYeh5YLVG45yGrwAAAk8"]
[Tue Jul 21 07:29:44.785412 2026] [security2:error] [pid 229246:tid 229302] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGsgACMTc"]
[Tue Jul 21 07:29:44.785543 2026] [security2:error] [pid 229246:tid 229405] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGsgACMTc"]
[Tue Jul 21 07:29:44.786836 2026] [security2:error] [pid 229246:tid 229463] [client 45.8.17.123:23405] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/profile.php"] [unique_id "al9KGCBMYeh5YLVG45yGtAAAAms"]
[Tue Jul 21 07:29:44.796899 2026] [security2:error] [pid 229246:tid 229387] [client 103.162.129.114:51993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGtgAAAh8"]
[Tue Jul 21 07:29:44.796999 2026] [security2:error] [pid 229246:tid 229387] [client 103.162.129.114:51993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGtgAAAh8"]
[Tue Jul 21 07:29:44.857754 2026] [security2:error] [pid 230252:tid 230404] [client 20.197.192.193:57215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/kq1.php"] [unique_id "al9KGE0Dwhk5-Z44Xrpi0AAAAq0"]
[Tue Jul 21 07:29:44.897167 2026] [security2:error] [pid 229246:tid 229423] [client 152.59.154.239:55957] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGtwAAAkM"]
[Tue Jul 21 07:29:44.897307 2026] [security2:error] [pid 229246:tid 229423] [client 152.59.154.239:55957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGCBMYeh5YLVG45yGtwAAAkM"]
[Tue Jul 21 07:29:44.924460 2026] [security2:error] [pid 229246:tid 229452] [client 20.197.192.193:47975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/zzz.php"] [unique_id "al9KGCBMYeh5YLVG45yGugAAAmA"]
[Tue Jul 21 07:29:44.941322 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:47977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wicked.php"] [unique_id "al9KGCBMYeh5YLVG45yGuwAAAn0"]
[Tue Jul 21 07:29:44.956219 2026] [security2:error] [pid 229246:tid 229403] [client 20.197.192.193:47982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/edit.php"] [unique_id "al9KGCBMYeh5YLVG45yGvAAAAi8"]
[Tue Jul 21 07:29:44.967207 2026] [security2:error] [pid 229246:tid 229394] [client 20.197.192.193:30094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/kua.php"] [unique_id "al9KGCBMYeh5YLVG45yGvwAAAiY"]
[Tue Jul 21 07:29:44.973608 2026] [proxy:error] [pid 229246:tid 229455] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:29:44.973659 2026] [proxy_http:error] [pid 229246:tid 229455] [client 20.151.10.161:49033] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:29:44.974150 2026] [proxy:error] [pid 229246:tid 229455] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:29:44.974178 2026] [proxy_http:error] [pid 229246:tid 229455] [client 20.151.10.161:49033] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:29:44.981638 2026] [security2:error] [pid 229246:tid 229385] [client 20.197.192.193:30096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/ez.php"] [unique_id "al9KGCBMYeh5YLVG45yGwgAAAh0"]
[Tue Jul 21 07:29:45.000500 2026] [security2:error] [pid 229246:tid 229460] [client 20.197.192.193:30965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/fz.php"] [unique_id "al9KGCBMYeh5YLVG45yGwwAAAmg"]
[Tue Jul 21 07:29:45.004343 2026] [security2:error] [pid 229246:tid 229501] [client 34.26.127.63:54855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9KGSBMYeh5YLVG45yGxAAAApE"]
[Tue Jul 21 07:29:45.018848 2026] [security2:error] [pid 229246:tid 229451] [client 20.197.192.193:30334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/la.php"] [unique_id "al9KGSBMYeh5YLVG45yGxQAAAl8"]
[Tue Jul 21 07:29:45.036570 2026] [security2:error] [pid 229246:tid 229416] [client 20.197.192.193:47969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9KGSBMYeh5YLVG45yGxgAAAjw"]
[Tue Jul 21 07:29:45.040027 2026] [security2:error] [pid 229246:tid 229469] [client 175.45.70.82:60830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yGxwAAAnE"]
[Tue Jul 21 07:29:45.040123 2026] [security2:error] [pid 229246:tid 229469] [client 175.45.70.82:60830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yGxwAAAnE"]
[Tue Jul 21 07:29:45.080598 2026] [security2:error] [pid 229246:tid 229378] [client 213.152.162.104:43338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yGyAAAAhY"]
[Tue Jul 21 07:29:45.080671 2026] [security2:error] [pid 229246:tid 229378] [client 213.152.162.104:43338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yGyAAAAhY"]
[Tue Jul 21 07:29:45.091985 2026] [security2:error] [pid 229246:tid 229449] [client 20.197.192.193:57189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/inso.php"] [unique_id "al9KGSBMYeh5YLVG45yGyQAAAl0"]
[Tue Jul 21 07:29:45.115801 2026] [security2:error] [pid 229246:tid 229473] [client 20.197.192.193:30139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wpx.php"] [unique_id "al9KGSBMYeh5YLVG45yGzAAAAnU"]
[Tue Jul 21 07:29:45.140744 2026] [security2:error] [pid 229246:tid 229417] [client 20.197.192.193:30330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/berlin.php"] [unique_id "al9KGSBMYeh5YLVG45yGzQAAAj0"]
[Tue Jul 21 07:29:45.161437 2026] [security2:error] [pid 229246:tid 229284] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yGzgACNCU"]
[Tue Jul 21 07:29:45.161546 2026] [security2:error] [pid 229246:tid 229408] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yGzgACNCU"]
[Tue Jul 21 07:29:45.170642 2026] [security2:error] [pid 229246:tid 229458] [client 20.197.192.193:47979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/billur.php"] [unique_id "al9KGSBMYeh5YLVG45yGzwAAAmY"]
[Tue Jul 21 07:29:45.201100 2026] [security2:error] [pid 229246:tid 229432] [client 20.197.192.193:57173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/mimpi.php"] [unique_id "al9KGSBMYeh5YLVG45yG0AAAAkw"]
[Tue Jul 21 07:29:45.235522 2026] [security2:error] [pid 229246:tid 229398] [client 20.197.192.193:57200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/dp.php"] [unique_id "al9KGSBMYeh5YLVG45yG0gAAAio"]
[Tue Jul 21 07:29:45.250848 2026] [security2:error] [pid 229246:tid 229465] [client 20.197.192.193:30305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/bootstrap.php"] [unique_id "al9KGSBMYeh5YLVG45yG0wAAAm0"]
[Tue Jul 21 07:29:45.275275 2026] [security2:error] [pid 229246:tid 229492] [client 20.197.192.193:57180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wp-editor.php"] [unique_id "al9KGSBMYeh5YLVG45yG1AAAAog"]
[Tue Jul 21 07:29:45.364480 2026] [security2:error] [pid 229246:tid 229435] [client 20.197.192.193:47967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/cro.php"] [unique_id "al9KGSBMYeh5YLVG45yG2AAAAk8"]
[Tue Jul 21 07:29:45.453435 2026] [security2:error] [pid 229246:tid 229387] [client 20.197.192.193:30302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/cron-tab.php"] [unique_id "al9KGSBMYeh5YLVG45yG2gAAAh8"]
[Tue Jul 21 07:29:45.465777 2026] [security2:error] [pid 229246:tid 229399] [client 109.248.148.246:37430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yG2wAAAis"]
[Tue Jul 21 07:29:45.465878 2026] [security2:error] [pid 229246:tid 229399] [client 109.248.148.246:37430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9KGSBMYeh5YLVG45yG2wAAAis"]
[Tue Jul 21 07:29:45.486780 2026] [security2:error] [pid 229246:tid 229423] [client 20.197.192.193:47971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/koiy.php"] [unique_id "al9KGSBMYeh5YLVG45yG3gAAAkM"]
[Tue Jul 21 07:29:45.496697 2026] [security2:error] [pid 230252:tid 230442] [client 20.104.96.117:42403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/19.php"] [unique_id "al9KGU0Dwhk5-Z44Xrpi1QAAAtM"]
[Tue Jul 21 07:29:45.527370 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:30107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/hp2.php"] [unique_id "al9KGSBMYeh5YLVG45yG4AAAAn0"]
[Tue Jul 21 07:29:45.587786 2026] [proxy:error] [pid 229246:tid 229444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:29:45.587865 2026] [proxy_http:error] [pid 229246:tid 229444] [client 20.151.10.161:49052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:29:45.588546 2026] [proxy:error] [pid 229246:tid 229444] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:29:45.588577 2026] [proxy_http:error] [pid 229246:tid 229444] [client 20.151.10.161:49052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:29:45.590232 2026] [security2:error] [pid 230252:tid 230473] [client 103.174.34.15:53577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGU0Dwhk5-Z44Xrpi1gAAAvI"]
[Tue Jul 21 07:29:45.590349 2026] [security2:error] [pid 230252:tid 230473] [client 103.174.34.15:53577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGU0Dwhk5-Z44Xrpi1gAAAvI"]
[Tue Jul 21 07:29:45.591243 2026] [security2:error] [pid 229246:tid 229394] [client 20.197.192.193:30135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/hp3.php"] [unique_id "al9KGSBMYeh5YLVG45yG4gAAAiY"]
[Tue Jul 21 07:29:45.625370 2026] [security2:error] [pid 229246:tid 229482] [client 20.197.192.193:47834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/aa1.php"] [unique_id "al9KGSBMYeh5YLVG45yG4wAAAn4"]
[Tue Jul 21 07:29:45.674861 2026] [security2:error] [pid 229246:tid 229480] [client 20.197.192.193:30279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/acew67.php"] [unique_id "al9KGSBMYeh5YLVG45yG5AAAAnw"]
[Tue Jul 21 07:29:45.693618 2026] [security2:error] [pid 229246:tid 229402] [client 45.8.17.127:61835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/utils/"] [unique_id "al9KGSBMYeh5YLVG45yG5QAAAi4"]
[Tue Jul 21 07:29:45.736956 2026] [security2:error] [pid 229246:tid 229445] [client 20.197.192.193:47830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/bscclapb.php"] [unique_id "al9KGSBMYeh5YLVG45yG5gAAAlk"]
[Tue Jul 21 07:29:45.849584 2026] [security2:error] [pid 229246:tid 229455] [client 34.26.127.63:54549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9KGSBMYeh5YLVG45yG7AAAAmM"]
[Tue Jul 21 07:29:45.861396 2026] [security2:error] [pid 229246:tid 229469] [client 20.197.192.193:30290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/else1.php"] [unique_id "al9KGSBMYeh5YLVG45yG7gAAAnE"]
[Tue Jul 21 07:29:45.881222 2026] [security2:error] [pid 229246:tid 229378] [client 20.197.192.193:57208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/tkikikoko.php"] [unique_id "al9KGSBMYeh5YLVG45yG7wAAAhY"]
[Tue Jul 21 07:29:45.906038 2026] [security2:error] [pid 229246:tid 229473] [client 20.197.192.193:47964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9KGSBMYeh5YLVG45yG8AAAAnU"]
[Tue Jul 21 07:29:45.954109 2026] [security2:error] [pid 229246:tid 229429] [client 20.197.192.193:57202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wp-css.php"] [unique_id "al9KGSBMYeh5YLVG45yG8QAAAkk"]
[Tue Jul 21 07:29:45.993899 2026] [security2:error] [pid 230252:tid 230393] [client 20.197.192.193:30088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/wp-explorer.php"] [unique_id "al9KGU0Dwhk5-Z44Xrpi2AAAAqI"]
[Tue Jul 21 07:29:46.025370 2026] [security2:error] [pid 230252:tid 230394] [client 20.197.192.193:30286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/akismet.php"] [unique_id "al9KGk0Dwhk5-Z44Xrpi2QAAAqM"]
[Tue Jul 21 07:29:46.052974 2026] [security2:error] [pid 229246:tid 229475] [client 154.192.233.199:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGiBMYeh5YLVG45yG9gAAAnc"]
[Tue Jul 21 07:29:46.052983 2026] [security2:error] [pid 229246:tid 229460] [client 173.24.185.52:50766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KGiBMYeh5YLVG45yG9wAAAmg"]
[Tue Jul 21 07:29:46.053087 2026] [security2:error] [pid 229246:tid 229460] [client 173.24.185.52:50766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KGiBMYeh5YLVG45yG9wAAAmg"]
[Tue Jul 21 07:29:46.053095 2026] [security2:error] [pid 229246:tid 229475] [client 154.192.233.199:59035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KGiBMYeh5YLVG45yG9gAAAnc"]
[Tue Jul 21 07:29:46.080034 2026] [security2:error] [pid 230252:tid 230419] [client 20.197.192.193:31170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/ace2.php"] [unique_id "al9KGk0Dwhk5-Z44Xrpi2gAAArw"]
[Tue Jul 21 07:29:46.115177 2026] [security2:error] [pid 229246:tid 229432] [client 20.197.192.193:30287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.moveisrafael.com.br"] [uri "/ms.php"] [unique_id "al9KGiBMYeh5YLVG45yG-QAAAkw"]
[Tue Jul 21 07:29:46.232619 2026] [core:alert] [pid 230252:tid 230417] [client 57.141.18.13:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:29:46.405678 2026] [security2:error] [pid 230252:tid 230511] [client 20.151.10.161:49024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/waf.php"] [unique_id "al9KGk0Dwhk5-Z44Xrpi5gAAAxg"]
[Tue Jul 21 07:29:46.415964 2026] [security2:error] [pid 230252:tid 230480] [client 34.26.127.63:63268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9KGk0Dwhk5-Z44Xrpi5wAAAvk"]
[Tue Jul 21 07:29:46.457389 2026] [security2:error] [pid 229246:tid 229489] [client 193.36.225.69:28745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KGiBMYeh5YLVG45yHEgAAAoU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:47.096499 2026] [security2:error] [pid 230252:tid 230482] [client 34.26.127.63:58548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9KG00Dwhk5-Z44Xrpi8AAAAvs"]
[Tue Jul 21 07:29:47.194901 2026] [security2:error] [pid 230252:tid 230479] [client 45.8.17.115:28135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/block-patterns/"] [unique_id "al9KG00Dwhk5-Z44Xrpi8QAAAvg"]
[Tue Jul 21 07:29:47.205397 2026] [security2:error] [pid 229246:tid 229482] [client 62.102.148.164:44314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KGyBMYeh5YLVG45yHHgAAAn4"]
[Tue Jul 21 07:29:47.205509 2026] [security2:error] [pid 229246:tid 229482] [client 62.102.148.164:44314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KGyBMYeh5YLVG45yHHgAAAn4"]
[Tue Jul 21 07:29:47.342121 2026] [security2:error] [pid 229246:tid 229402] [client 20.151.10.161:49076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/xstelth.php"] [unique_id "al9KGyBMYeh5YLVG45yHIgAAAi4"]
[Tue Jul 21 07:29:47.665038 2026] [security2:error] [pid 229246:tid 229445] [client 34.26.127.63:52752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9KGyBMYeh5YLVG45yHJQAAAlk"]
[Tue Jul 21 07:29:47.827070 2026] [security2:error] [pid 229246:tid 229488] [client 20.151.10.161:48585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-links.php"] [unique_id "al9KGyBMYeh5YLVG45yHJgAAAoQ"]
[Tue Jul 21 07:29:47.991763 2026] [security2:error] [pid 230252:tid 230459] [client 20.104.96.117:59604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/inc.php"] [unique_id "al9KG00Dwhk5-Z44Xrpi-gAAAuQ"]
[Tue Jul 21 07:29:48.337244 2026] [security2:error] [pid 229246:tid 229449] [client 34.26.127.63:54183] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "startonesite.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9KHCBMYeh5YLVG45yHLAAAAl0"]
[Tue Jul 21 07:29:48.586784 2026] [security2:error] [pid 230252:tid 230477] [client 45.8.17.137:46375] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentythree/patterns/template-singl-portfolio.php"] [unique_id "al9KHE0Dwhk5-Z44Xrpi_gAAAvY"]
[Tue Jul 21 07:29:48.671319 2026] [security2:error] [pid 229246:tid 229389] [client 20.220.225.223:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/track.php"] [unique_id "al9KHCBMYeh5YLVG45yHMwAAAiE"]
[Tue Jul 21 07:29:48.796582 2026] [security2:error] [pid 230252:tid 230407] [client 20.151.10.161:49094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9KHE0Dwhk5-Z44Xrpi_wAAArA"]
[Tue Jul 21 07:29:49.200770 2026] [security2:error] [pid 230252:tid 230417] [client 45.251.232.145:58312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KHU0Dwhk5-Z44XrpjAAAAAro"]
[Tue Jul 21 07:29:49.200910 2026] [security2:error] [pid 230252:tid 230417] [client 45.251.232.145:58312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KHU0Dwhk5-Z44XrpjAAAAAro"]
[Tue Jul 21 07:29:49.279146 2026] [security2:error] [pid 229246:tid 229283] [remote 41.186.86.12:19620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9KHSBMYeh5YLVG45yHPgACHCQ"]
[Tue Jul 21 07:29:49.802257 2026] [autoindex:error] [pid 230252:tid 230268] [remote 74.7.242.3:49918] AH01276: Cannot serve directory /home1/ofic8899/sulinex.oficialwebsite.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:49.817783 2026] [security2:error] [pid 229246:tid 229405] [client 74.7.241.149:38254] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.sulinex.oficialwebsite.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9KHSBMYeh5YLVG45yHSAACMSc"]
[Tue Jul 21 07:29:50.096040 2026] [security2:error] [pid 229246:tid 229403] [client 20.151.10.161:49086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.tempex.com.br"] [uri "/aaa.php"] [unique_id "al9KHiBMYeh5YLVG45yHTgAAAi8"]
[Tue Jul 21 07:29:50.143442 2026] [security2:error] [pid 230252:tid 230304] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KHk0Dwhk5-Z44XrpjDAADFTI"]
[Tue Jul 21 07:29:50.143611 2026] [security2:error] [pid 230252:tid 230508] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KHk0Dwhk5-Z44XrpjDAADFTI"]
[Tue Jul 21 07:29:50.206795 2026] [security2:error] [pid 229246:tid 229406] [client 45.8.17.59:64371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/certificates/"] [unique_id "al9KHiBMYeh5YLVG45yHUgAAAjI"]
[Tue Jul 21 07:29:50.538723 2026] [access_compat:error] [pid 229246:tid 229448] [client 162.241.63.68:22484] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:29:50.651644 2026] [security2:error] [pid 230252:tid 230467] [client 136.144.33.107:52127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KHk0Dwhk5-Z44XrpjEwAAAuw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:51.391075 2026] [security2:error] [pid 229246:tid 229475] [client 45.8.17.115:31731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/user/"] [unique_id "al9KHyBMYeh5YLVG45yHYQAAAnc"]
[Tue Jul 21 07:29:51.492543 2026] [security2:error] [pid 230252:tid 230459] [client 59.96.220.140:54285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KH00Dwhk5-Z44XrpjHgAAAuQ"]
[Tue Jul 21 07:29:51.492694 2026] [security2:error] [pid 230252:tid 230459] [client 59.96.220.140:54285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KH00Dwhk5-Z44XrpjHgAAAuQ"]
[Tue Jul 21 07:29:51.634940 2026] [security2:error] [pid 230252:tid 230447] [client 117.251.86.144:35416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KH00Dwhk5-Z44XrpjIAAAAtg"]
[Tue Jul 21 07:29:51.635076 2026] [security2:error] [pid 230252:tid 230447] [client 117.251.86.144:35416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KH00Dwhk5-Z44XrpjIAAAAtg"]
[Tue Jul 21 07:29:51.651466 2026] [security2:error] [pid 230252:tid 230462] [client 20.104.96.117:59796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9KH00Dwhk5-Z44XrpjIQAAAuc"]
[Tue Jul 21 07:29:51.781101 2026] [security2:error] [pid 229246:tid 229496] [client 139.135.44.145:53730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KHyBMYeh5YLVG45yHbgAAAow"]
[Tue Jul 21 07:29:51.781211 2026] [security2:error] [pid 229246:tid 229496] [client 139.135.44.145:53730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KHyBMYeh5YLVG45yHbgAAAow"]
[Tue Jul 21 07:29:51.810475 2026] [security2:error] [pid 230252:tid 230267] [remote 57.141.18.60:58586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9KHk0Dwhk5-Z44XrpjFQACog0"]
[Tue Jul 21 07:29:52.526924 2026] [security2:error] [pid 229246:tid 229257] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KICBMYeh5YLVG45yHvAACawo"]
[Tue Jul 21 07:29:52.527073 2026] [security2:error] [pid 229246:tid 229463] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KICBMYeh5YLVG45yHvAACawo"]
[Tue Jul 21 07:29:52.611078 2026] [security2:error] [pid 230252:tid 230387] [client 103.186.30.230:52485] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "thiagomartins.com"] [uri "/"] [unique_id "al9KIE0Dwhk5-Z44XrpjLQAAApw"]
[Tue Jul 21 07:29:52.777399 2026] [security2:error] [pid 229246:tid 229481] [client 45.8.17.125:38275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/66.php"] [unique_id "al9KICBMYeh5YLVG45yH1QAAAn0"]
[Tue Jul 21 07:29:53.044640 2026] [security2:error] [pid 230252:tid 230487] [client 20.52.136.55:1565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/vx.php"] [unique_id "al9KIU0Dwhk5-Z44XrpjMgAAAwA"]
[Tue Jul 21 07:29:53.632079 2026] [security2:error] [pid 229246:tid 229368] [remote 182.77.62.24:59224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wp-login.php"] [unique_id "al9KISBMYeh5YLVG45yH7gACMXk"]
[Tue Jul 21 07:29:53.802118 2026] [security2:error] [pid 230252:tid 230470] [client 103.186.30.230:52506] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "thiagomartins.com"] [uri "/wp-json/batch/v1"] [unique_id "al9KIU0Dwhk5-Z44XrpjOQAAAu8"]
[Tue Jul 21 07:29:53.913929 2026] [security2:error] [pid 229246:tid 229305] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9KISBMYeh5YLVG45yH8wACFDo"]
[Tue Jul 21 07:29:54.185696 2026] [security2:error] [pid 230252:tid 230405] [client 45.8.17.48:36197] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/autoload_classmap.php"] [unique_id "al9KIk0Dwhk5-Z44XrpjPQAAAq4"]
[Tue Jul 21 07:29:54.235565 2026] [security2:error] [pid 229246:tid 229361] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KIiBMYeh5YLVG45yIHwACR3I"]
[Tue Jul 21 07:29:54.235762 2026] [security2:error] [pid 229246:tid 229427] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KIiBMYeh5YLVG45yIHwACR3I"]
[Tue Jul 21 07:29:54.311621 2026] [security2:error] [pid 230252:tid 230458] [client 136.144.33.97:62407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KIk0Dwhk5-Z44XrpjPgAAAuM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:54.318973 2026] [security2:error] [pid 229246:tid 229389] [client 103.106.20.201:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KIiBMYeh5YLVG45yIJgAAAiE"]
[Tue Jul 21 07:29:54.319085 2026] [security2:error] [pid 229246:tid 229389] [client 103.106.20.201:59178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KIiBMYeh5YLVG45yIJgAAAiE"]
[Tue Jul 21 07:29:54.665461 2026] [security2:error] [pid 230252:tid 230496] [client 20.104.96.117:42404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9KIk0Dwhk5-Z44XrpjQQAAAwk"]
[Tue Jul 21 07:29:54.727693 2026] [security2:error] [pid 229246:tid 229437] [client 20.220.225.223:8928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/kua.php"] [unique_id "al9KIiBMYeh5YLVG45yILgAAAlE"]
[Tue Jul 21 07:29:54.921435 2026] [security2:error] [pid 229246:tid 229280] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KIiBMYeh5YLVG45yIMAACdiE"]
[Tue Jul 21 07:29:54.921590 2026] [security2:error] [pid 229246:tid 229474] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KIiBMYeh5YLVG45yIMAACdiE"]
[Tue Jul 21 07:29:55.033193 2026] [security2:error] [pid 230252:tid 230436] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9KI00Dwhk5-Z44XrpjRgAAAs0"]
[Tue Jul 21 07:29:55.068958 2026] [security2:error] [pid 230252:tid 230410] [client 103.162.129.114:52434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjRwAAArM"]
[Tue Jul 21 07:29:55.069129 2026] [security2:error] [pid 230252:tid 230410] [client 103.162.129.114:52434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjRwAAArM"]
[Tue Jul 21 07:29:55.178977 2026] [autoindex:error] [pid 230252:tid 230469] [client 64.69.216.78:39244] AH01276: Cannot serve directory /home2/marc8022/canelapart.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:55.470383 2026] [security2:error] [pid 230252:tid 230370] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjUQACoHM"]
[Tue Jul 21 07:29:55.470595 2026] [security2:error] [pid 230252:tid 230391] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjUQACoHM"]
[Tue Jul 21 07:29:55.474899 2026] [security2:error] [pid 230252:tid 230511] [client 103.186.30.230:52525] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "thiagomartins.com"] [uri "/"] [unique_id "al9KI00Dwhk5-Z44XrpjUgAAAxg"]
[Tue Jul 21 07:29:55.645583 2026] [security2:error] [pid 229246:tid 229267] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KIyBMYeh5YLVG45yIOwACYRQ"]
[Tue Jul 21 07:29:55.645720 2026] [security2:error] [pid 229246:tid 229453] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KIyBMYeh5YLVG45yIOwACYRQ"]
[Tue Jul 21 07:29:55.678174 2026] [security2:error] [pid 230252:tid 230443] [client 154.192.233.199:59353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjVgAAAtQ"]
[Tue Jul 21 07:29:55.678292 2026] [security2:error] [pid 230252:tid 230443] [client 154.192.233.199:59353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjVgAAAtQ"]
[Tue Jul 21 07:29:55.747849 2026] [security2:error] [pid 230252:tid 230468] [client 175.45.70.82:61339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjVwAAAu0"]
[Tue Jul 21 07:29:55.747957 2026] [security2:error] [pid 230252:tid 230468] [client 175.45.70.82:61339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KI00Dwhk5-Z44XrpjVwAAAu0"]
[Tue Jul 21 07:29:56.101114 2026] [security2:error] [pid 230252:tid 230421] [client 152.59.154.239:56338] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KJE0Dwhk5-Z44XrpjXAAAAr4"]
[Tue Jul 21 07:29:56.101262 2026] [security2:error] [pid 230252:tid 230421] [client 152.59.154.239:56338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KJE0Dwhk5-Z44XrpjXAAAAr4"]
[Tue Jul 21 07:29:56.207381 2026] [autoindex:error] [pid 229246:tid 229480] [client 64.69.216.78:39358] AH01276: Cannot serve directory /home2/marc8022/canelapart.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:29:56.290135 2026] [security2:error] [pid 230252:tid 230428] [client 103.174.34.15:54077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KJE0Dwhk5-Z44XrpjXwAAAsU"]
[Tue Jul 21 07:29:56.290256 2026] [security2:error] [pid 230252:tid 230428] [client 103.174.34.15:54077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KJE0Dwhk5-Z44XrpjXwAAAsU"]
[Tue Jul 21 07:29:56.497806 2026] [security2:error] [pid 230252:tid 230413] [client 45.8.17.110:37633] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/2024/"] [unique_id "al9KJE0Dwhk5-Z44XrpjYAAAArY"]
[Tue Jul 21 07:29:56.611273 2026] [security2:error] [pid 229246:tid 229401] [client 173.24.185.52:51231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KJCBMYeh5YLVG45yITQAAAi0"]
[Tue Jul 21 07:29:56.611471 2026] [security2:error] [pid 229246:tid 229401] [client 173.24.185.52:51231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KJCBMYeh5YLVG45yITQAAAi0"]
[Tue Jul 21 07:29:57.004918 2026] [security2:error] [pid 229246:tid 229412] [client 20.220.225.223:46013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/2352356666.php"] [unique_id "al9KJSBMYeh5YLVG45yIVAAAAjg"]
[Tue Jul 21 07:29:57.093637 2026] [security2:error] [pid 229246:tid 229254] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9KJSBMYeh5YLVG45yIVQACJwc"]
[Tue Jul 21 07:29:57.284520 2026] [core:error] [pid 229246:tid 229458] [client 66.249.66.69:54901] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:29:57.284543 2026] [core:error] [pid 229246:tid 229458] [client 66.249.66.69:54901] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:29:57.556617 2026] [security2:error] [pid 229246:tid 229476] [client 198.204.224.34:57912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/wp-includes/qqf65547/73/index.php"] [unique_id "al9KJSBMYeh5YLVG45yIXQAAAng"], referer: http://roanalacerda.com.br/wp-includes/qqf65547/73/index.php
[Tue Jul 21 07:29:57.754785 2026] [security2:error] [pid 229246:tid 229497] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9KJSBMYeh5YLVG45yIXgAAAo0"]
[Tue Jul 21 07:29:57.994349 2026] [security2:error] [pid 229246:tid 229492] [client 20.104.96.117:42429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ss.php"] [unique_id "al9KJSBMYeh5YLVG45yIZgAAAog"]
[Tue Jul 21 07:29:58.035418 2026] [security2:error] [pid 229246:tid 229483] [client 198.204.224.34:57918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/re/embeds/19/index.php"] [unique_id "al9KJiBMYeh5YLVG45yIaAAAAn8"], referer: http://roanalacerda.com.br/re/embeds/19/index.php
[Tue Jul 21 07:29:58.284782 2026] [core:error] [pid 229246:tid 229463] [client 66.249.66.67:58147] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:29:58.284803 2026] [core:error] [pid 229246:tid 229463] [client 66.249.66.67:58147] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:29:58.582534 2026] [security2:error] [pid 230252:tid 230416] [client 45.8.17.117:38567] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/chosen.php"] [unique_id "al9KJk0Dwhk5-Z44XrpjdgAAArk"]
[Tue Jul 21 07:29:58.898397 2026] [security2:error] [pid 230252:tid 230436] [client 193.36.225.54:41477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KJk0Dwhk5-Z44XrpjeQAAAs0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:29:59.280856 2026] [security2:error] [pid 229246:tid 229480] [client 198.204.224.34:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/us/audits/6/index.php"] [unique_id "al9KJyBMYeh5YLVG45yIeQAAAnw"], referer: http://roanalacerda.com.br/us/audits/6/index.php
[Tue Jul 21 07:29:59.580180 2026] [security2:error] [pid 230252:tid 230458] [client 45.8.17.59:21439] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/footer.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjhwAAAuM"]
[Tue Jul 21 07:29:59.606111 2026] [security2:error] [pid 230252:tid 230491] [client 198.204.224.34:57942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/us/query-content/7/index.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjiAAAAwQ"], referer: http://roanalacerda.com.br/us/query-content/7/index.php
[Tue Jul 21 07:29:59.671946 2026] [security2:error] [pid 230252:tid 230472] [client 45.251.232.145:58833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjiQAAAvE"]
[Tue Jul 21 07:29:59.672157 2026] [security2:error] [pid 230252:tid 230472] [client 45.251.232.145:58833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjiQAAAvE"]
[Tue Jul 21 07:29:59.726530 2026] [security2:error] [pid 230252:tid 230421] [client 20.104.96.117:59809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/min.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjigAAAr4"]
[Tue Jul 21 07:29:59.920967 2026] [security2:error] [pid 230252:tid 230463] [client 198.204.224.34:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/pro/78/index.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjjwAAAug"], referer: http://roanalacerda.com.br/pro/78/index.php
[Tue Jul 21 07:29:59.982237 2026] [security2:error] [pid 230252:tid 230509] [client 82.102.28.107:39972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjkAAAAxY"]
[Tue Jul 21 07:29:59.982364 2026] [security2:error] [pid 230252:tid 230509] [client 82.102.28.107:39972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KJ00Dwhk5-Z44XrpjkAAAAxY"]
[Tue Jul 21 07:30:00.279742 2026] [security2:error] [pid 230252:tid 230406] [client 198.204.224.34:57950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/ra/12/index.php"] [unique_id "al9KKE0Dwhk5-Z44XrpjkgAAAq8"], referer: http://roanalacerda.com.br/ra/12/index.php
[Tue Jul 21 07:30:00.628074 2026] [security2:error] [pid 230252:tid 230385] [client 198.204.224.34:57952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/Avast/98/index.php"] [unique_id "al9KKE0Dwhk5-Z44XrpjmQAAApo"], referer: http://roanalacerda.com.br/Avast/98/index.php
[Tue Jul 21 07:30:00.728318 2026] [security2:error] [pid 230252:tid 230320] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KKE0Dwhk5-Z44XrpjmwADEEI"]
[Tue Jul 21 07:30:00.728457 2026] [security2:error] [pid 230252:tid 230503] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KKE0Dwhk5-Z44XrpjmwADEEI"]
[Tue Jul 21 07:30:00.991779 2026] [security2:error] [pid 230252:tid 230387] [client 198.204.224.34:57958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/wp-includes/32/index.php"] [unique_id "al9KKE0Dwhk5-Z44XrpjnQAAApw"], referer: http://roanalacerda.com.br/wp-includes/32/index.php
[Tue Jul 21 07:30:01.157707 2026] [security2:error] [pid 230252:tid 230454] [client 74.7.175.147:51874] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.radiantus.online"] [uri "/robots.txt"] [unique_id "al9KKU0Dwhk5-Z44XrpjoQAAAt8"]
[Tue Jul 21 07:30:01.291568 2026] [security2:error] [pid 229246:tid 229459] [client 45.8.17.108:25339] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/wp-file-manager-pro/"] [unique_id "al9KKSBMYeh5YLVG45yIkwAAAmc"]
[Tue Jul 21 07:30:01.311591 2026] [security2:error] [pid 230252:tid 230467] [client 198.204.224.34:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/840cb/42/index.php"] [unique_id "al9KKU0Dwhk5-Z44XrpjqQAAAuw"], referer: http://roanalacerda.com.br/840cb/42/index.php
[Tue Jul 21 07:30:01.469817 2026] [security2:error] [pid 230252:tid 230384] [client 213.152.162.104:35784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KKU0Dwhk5-Z44XrpjsQAAApk"]
[Tue Jul 21 07:30:01.469924 2026] [security2:error] [pid 230252:tid 230384] [client 213.152.162.104:35784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KKU0Dwhk5-Z44XrpjsQAAApk"]
[Tue Jul 21 07:30:01.667200 2026] [security2:error] [pid 230252:tid 230298] [remote 116.203.133.192:38008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.133.203.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "frsadvocacia.net"] [uri "/xmlrpc.php"] [unique_id "al9KKU0Dwhk5-Z44XrpjswAC4Sw"]
[Tue Jul 21 07:30:01.667455 2026] [security2:error] [pid 230252:tid 230456] [client 116.203.133.192:38008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "frsadvocacia.net"] [uri "/xmlrpc.php"] [unique_id "al9KKU0Dwhk5-Z44XrpjswAC4Sw"]
[Tue Jul 21 07:30:01.681457 2026] [security2:error] [pid 229246:tid 229471] [client 198.204.224.34:57988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/us/10/index.php"] [unique_id "al9KKSBMYeh5YLVG45yImwAAAnM"], referer: http://roanalacerda.com.br/us/10/index.php
[Tue Jul 21 07:30:01.803492 2026] [security2:error] [pid 230252:tid 230507] [client 20.104.96.117:42372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9KKU0Dwhk5-Z44XrpjtgAAAxQ"]
[Tue Jul 21 07:30:02.388007 2026] [security2:error] [pid 230252:tid 230297] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KKk0Dwhk5-Z44XrpjvgAC0is"]
[Tue Jul 21 07:30:02.388172 2026] [security2:error] [pid 230252:tid 230441] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KKk0Dwhk5-Z44XrpjvgAC0is"]
[Tue Jul 21 07:30:02.418158 2026] [security2:error] [pid 230252:tid 230412] [client 117.251.86.144:58946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KKk0Dwhk5-Z44XrpjwAAAArU"]
[Tue Jul 21 07:30:02.418280 2026] [security2:error] [pid 230252:tid 230412] [client 117.251.86.144:58946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KKk0Dwhk5-Z44XrpjwAAAArU"]
[Tue Jul 21 07:30:02.595794 2026] [security2:error] [pid 229246:tid 229503] [client 45.8.17.126:32983] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/system_log.php"] [unique_id "al9KKiBMYeh5YLVG45yIqQAAApM"]
[Tue Jul 21 07:30:02.600679 2026] [security2:error] [pid 230252:tid 230410] [client 139.135.44.145:54541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KKk0Dwhk5-Z44XrpjxQAAArM"]
[Tue Jul 21 07:30:02.600883 2026] [security2:error] [pid 230252:tid 230410] [client 139.135.44.145:54541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KKk0Dwhk5-Z44XrpjxQAAArM"]
[Tue Jul 21 07:30:02.643275 2026] [security2:error] [pid 230252:tid 230483] [client 136.144.33.108:44581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KKk0Dwhk5-Z44XrpjxgAAAvw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:02.821265 2026] [security2:error] [pid 229246:tid 229474] [client 49.13.167.123:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9KKiBMYeh5YLVG45yIrQACdmE"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:30:03.076524 2026] [security2:error] [pid 229246:tid 229481] [client 20.104.96.117:42401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9KKyBMYeh5YLVG45yIsAAAAn0"]
[Tue Jul 21 07:30:03.155174 2026] [security2:error] [pid 230252:tid 230391] [client 59.96.220.140:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KK00Dwhk5-Z44Xrpj0QAAAqA"]
[Tue Jul 21 07:30:03.155315 2026] [security2:error] [pid 230252:tid 230391] [client 59.96.220.140:54772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KK00Dwhk5-Z44Xrpj0QAAAqA"]
[Tue Jul 21 07:30:03.376546 2026] [security2:error] [pid 230252:tid 230413] [client 49.13.167.123:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9KK00Dwhk5-Z44Xrpj1wACtjs"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:30:03.495825 2026] [security2:error] [pid 230252:tid 230406] [client 45.8.17.107:45325] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/separator/"] [unique_id "al9KK00Dwhk5-Z44Xrpj2AAAAq8"]
[Tue Jul 21 07:30:03.699632 2026] [security2:error] [pid 230252:tid 230444] [client 20.52.136.55:1547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/ws77.php"] [unique_id "al9KK00Dwhk5-Z44Xrpj3AAAAtU"]
[Tue Jul 21 07:30:03.792626 2026] [autoindex:error] [pid 230252:tid 230510] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:03.856769 2026] [security2:error] [pid 229246:tid 229416] [client 62.102.148.164:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KKyBMYeh5YLVG45yIuAAAAjw"]
[Tue Jul 21 07:30:03.856887 2026] [security2:error] [pid 229246:tid 229416] [client 62.102.148.164:49796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KKyBMYeh5YLVG45yIuAAAAjw"]
[Tue Jul 21 07:30:04.238310 2026] [autoindex:error] [pid 230252:tid 230499] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:04.380984 2026] [security2:error] [pid 229246:tid 229455] [client 185.198.240.13:23607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mbarcondicionados.com.br"] [uri "/wp-login.php"] [unique_id "al9KLCBMYeh5YLVG45yIxgAAAmM"]
[Tue Jul 21 07:30:04.515299 2026] [autoindex:error] [pid 230252:tid 230441] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:04.686523 2026] [security2:error] [pid 230252:tid 230409] [client 45.8.17.128:61707] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/mah/function.php"] [unique_id "al9KLE0Dwhk5-Z44Xrpj6AAAArI"]
[Tue Jul 21 07:30:04.745770 2026] [autoindex:error] [pid 230252:tid 230460] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:04.827781 2026] [security2:error] [pid 230252:tid 230274] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KLE0Dwhk5-Z44Xrpj7gACzxQ"]
[Tue Jul 21 07:30:04.827952 2026] [security2:error] [pid 230252:tid 230438] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KLE0Dwhk5-Z44Xrpj7gACzxQ"]
[Tue Jul 21 07:30:05.036218 2026] [autoindex:error] [pid 230252:tid 230410] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:05.068426 2026] [security2:error] [pid 229246:tid 229396] [client 103.106.20.201:59764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLSBMYeh5YLVG45yIzgAAAig"]
[Tue Jul 21 07:30:05.068575 2026] [security2:error] [pid 229246:tid 229396] [client 103.106.20.201:59764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLSBMYeh5YLVG45yIzgAAAig"]
[Tue Jul 21 07:30:05.103000 2026] [security2:error] [pid 230252:tid 230450] [client 20.104.96.117:42398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9KLU0Dwhk5-Z44Xrpj8wAAAts"]
[Tue Jul 21 07:30:05.332825 2026] [autoindex:error] [pid 230252:tid 230491] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:05.459778 2026] [security2:error] [pid 230252:tid 230333] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLU0Dwhk5-Z44Xrpj-QADDk4"]
[Tue Jul 21 07:30:05.459977 2026] [security2:error] [pid 230252:tid 230501] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLU0Dwhk5-Z44Xrpj-QADDk4"]
[Tue Jul 21 07:30:05.613135 2026] [autoindex:error] [pid 230252:tid 230486] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:05.647760 2026] [security2:error] [pid 230252:tid 230467] [client 103.162.129.114:52886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KLU0Dwhk5-Z44Xrpj_QAAAuw"]
[Tue Jul 21 07:30:05.647889 2026] [security2:error] [pid 230252:tid 230467] [client 103.162.129.114:52886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KLU0Dwhk5-Z44Xrpj_QAAAuw"]
[Tue Jul 21 07:30:05.825117 2026] [autoindex:error] [pid 230252:tid 230402] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:06.100158 2026] [security2:error] [pid 230252:tid 230452] [client 213.152.162.104:35806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkBwAAAt0"]
[Tue Jul 21 07:30:06.100261 2026] [security2:error] [pid 230252:tid 230452] [client 213.152.162.104:35806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkBwAAAt0"]
[Tue Jul 21 07:30:06.106439 2026] [security2:error] [pid 230252:tid 230312] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkCAACojo"]
[Tue Jul 21 07:30:06.106667 2026] [security2:error] [pid 230252:tid 230393] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkCAACojo"]
[Tue Jul 21 07:30:06.384317 2026] [security2:error] [pid 230252:tid 230441] [client 45.8.17.119:55033] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/admin.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkCwAAAtI"]
[Tue Jul 21 07:30:06.421423 2026] [security2:error] [pid 230252:tid 230484] [client 175.45.70.82:61847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkDAAAAv0"]
[Tue Jul 21 07:30:06.421586 2026] [security2:error] [pid 230252:tid 230484] [client 175.45.70.82:61847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkDAAAAv0"]
[Tue Jul 21 07:30:06.432985 2026] [security2:error] [pid 229246:tid 229274] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KLiBMYeh5YLVG45yI5AACKxs"]
[Tue Jul 21 07:30:06.433140 2026] [security2:error] [pid 229246:tid 229399] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KLiBMYeh5YLVG45yI5AACKxs"]
[Tue Jul 21 07:30:06.648739 2026] [security2:error] [pid 230252:tid 230415] [client 45.8.19.153:40887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeireirapiske.com.br"] [uri "/wp-login.php"] [unique_id "al9KLk0Dwhk5-Z44XrpkEAAAArg"]
[Tue Jul 21 07:30:06.794550 2026] [security2:error] [pid 230252:tid 230412] [client 3.77.67.4:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9KLk0Dwhk5-Z44XrpkFAACtUw"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:30:07.101512 2026] [security2:error] [pid 230252:tid 230511] [client 103.174.34.15:54569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KL00Dwhk5-Z44XrpkGAAAAxg"]
[Tue Jul 21 07:30:07.102086 2026] [security2:error] [pid 230252:tid 230511] [client 103.174.34.15:54569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KL00Dwhk5-Z44XrpkGAAAAxg"]
[Tue Jul 21 07:30:07.175263 2026] [security2:error] [pid 230252:tid 230396] [client 173.24.185.52:51691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KL00Dwhk5-Z44XrpkGwAAAqU"]
[Tue Jul 21 07:30:07.175375 2026] [security2:error] [pid 230252:tid 230396] [client 173.24.185.52:51691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KL00Dwhk5-Z44XrpkGwAAAqU"]
[Tue Jul 21 07:30:07.212367 2026] [security2:error] [pid 229246:tid 229479] [client 152.59.154.239:56596] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLyBMYeh5YLVG45yI7wAAAns"]
[Tue Jul 21 07:30:07.212495 2026] [security2:error] [pid 229246:tid 229479] [client 152.59.154.239:56596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KLyBMYeh5YLVG45yI7wAAAns"]
[Tue Jul 21 07:30:07.250359 2026] [autoindex:error] [pid 230252:tid 230467] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:07.339159 2026] [security2:error] [pid 229246:tid 229394] [client 3.77.67.4:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9KLyBMYeh5YLVG45yI8wACJiM"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:30:07.397125 2026] [security2:error] [pid 230252:tid 230450] [client 154.192.233.199:59892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KL00Dwhk5-Z44XrpkHwAAAts"]
[Tue Jul 21 07:30:07.397274 2026] [security2:error] [pid 230252:tid 230450] [client 154.192.233.199:59892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KL00Dwhk5-Z44XrpkHwAAAts"]
[Tue Jul 21 07:30:07.537470 2026] [autoindex:error] [pid 230252:tid 230444] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:07.690447 2026] [security2:error] [pid 230252:tid 230385] [client 45.8.17.106:55525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/spacer/"] [unique_id "al9KL00Dwhk5-Z44XrpkJwAAApo"]
[Tue Jul 21 07:30:07.822185 2026] [security2:error] [pid 230252:tid 230490] [client 37.140.223.68:34103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KL00Dwhk5-Z44XrpkKgAAAwM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:08.044517 2026] [autoindex:error] [pid 230252:tid 230441] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:08.124434 2026] [security2:error] [pid 229246:tid 229401] [client 20.104.96.117:59644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9KMCBMYeh5YLVG45yI-wAAAi0"]
[Tue Jul 21 07:30:08.252742 2026] [autoindex:error] [pid 230252:tid 230409] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:08.538284 2026] [autoindex:error] [pid 230252:tid 230410] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:08.755759 2026] [autoindex:error] [pid 230252:tid 230428] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:08.984170 2026] [security2:error] [pid 230252:tid 230405] [client 45.8.17.73:54573] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/certificates/chosen.php"] [unique_id "al9KME0Dwhk5-Z44XrpkPAAAAq4"]
[Tue Jul 21 07:30:09.018776 2026] [autoindex:error] [pid 230252:tid 230416] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:09.856105 2026] [security2:error] [pid 230252:tid 230481] [client 20.104.96.117:42276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/albin.php"] [unique_id "al9KMU0Dwhk5-Z44XrpkRwAAAvo"]
[Tue Jul 21 07:30:10.033129 2026] [security2:error] [pid 230252:tid 230444] [client 20.52.136.55:1595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/2.php"] [unique_id "al9KMk0Dwhk5-Z44XrpkSAAAAtU"]
[Tue Jul 21 07:30:10.087640 2026] [security2:error] [pid 230252:tid 230393] [client 45.8.17.130:51229] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/shortcode/"] [unique_id "al9KMk0Dwhk5-Z44XrpkSwAAAqI"]
[Tue Jul 21 07:30:10.204103 2026] [security2:error] [pid 230252:tid 230509] [client 45.251.232.145:59362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KMk0Dwhk5-Z44XrpkTAAAAxY"]
[Tue Jul 21 07:30:10.204257 2026] [security2:error] [pid 230252:tid 230509] [client 45.251.232.145:59362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KMk0Dwhk5-Z44XrpkTAAAAxY"]
[Tue Jul 21 07:30:10.233512 2026] [autoindex:error] [pid 230252:tid 230503] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:10.243818 2026] [security2:error] [pid 230252:tid 230287] [remote 45.79.123.44:33238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9KMk0Dwhk5-Z44XrpkTgACpyE"]
[Tue Jul 21 07:30:10.522318 2026] [core:crit] [pid 230252:tid 230430] (13)Permission denied: [client 85.204.70.92:33458] AH00529: /home3/frsadv16/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home3/frsadv16/public_html/cgi-bin/' is executable
[Tue Jul 21 07:30:11.089639 2026] [security2:error] [pid 229246:tid 229399] [client 45.8.17.132:50747] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/edit-wolf.php"] [unique_id "al9KMyBMYeh5YLVG45yJHQAAAis"]
[Tue Jul 21 07:30:11.250219 2026] [security2:error] [pid 230252:tid 230495] [client 47.128.112.178:36440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "triviaodontologia.com.br"] [uri "/robots.txt"] [unique_id "al9KM00Dwhk5-Z44XrpkWAAAAwg"]
[Tue Jul 21 07:30:11.377944 2026] [security2:error] [pid 230252:tid 230322] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KM00Dwhk5-Z44XrpkWQAC_UQ"]
[Tue Jul 21 07:30:11.378132 2026] [security2:error] [pid 230252:tid 230484] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KM00Dwhk5-Z44XrpkWQAC_UQ"]
[Tue Jul 21 07:30:11.621090 2026] [security2:error] [pid 229246:tid 229303] [remote 66.249.79.128:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sejabarbara.com.br"] [uri "/robots.txt"] [unique_id "al9KMyBMYeh5YLVG45yJKQACHTg"]
[Tue Jul 21 07:30:11.759527 2026] [security2:error] [pid 230252:tid 230389] [client 136.144.33.111:28273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KM00Dwhk5-Z44XrpkWgAAAp4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:11.929013 2026] [security2:error] [pid 230252:tid 230471] [client 109.248.148.246:59660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KM00Dwhk5-Z44XrpkYAAAAvA"]
[Tue Jul 21 07:30:11.929137 2026] [security2:error] [pid 230252:tid 230471] [client 109.248.148.246:59660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KM00Dwhk5-Z44XrpkYAAAAvA"]
[Tue Jul 21 07:30:12.212852 2026] [security2:error] [pid 230252:tid 230498] [client 20.104.96.117:59838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/cilus.php"] [unique_id "al9KNE0Dwhk5-Z44XrpkZgAAAws"]
[Tue Jul 21 07:30:12.260669 2026] [security2:error] [pid 230252:tid 230343] [remote 66.249.79.130:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sejabarbara.com.br"] [uri "/sindrome-do-impostor/"] [unique_id "al9KNE0Dwhk5-Z44XrpkaQAC6lg"]
[Tue Jul 21 07:30:12.290851 2026] [security2:error] [pid 230252:tid 230488] [client 45.8.17.48:65245] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/2021/10/"] [unique_id "al9KNE0Dwhk5-Z44XrpkawAAAwE"]
[Tue Jul 21 07:30:12.451158 2026] [security2:error] [pid 230252:tid 230458] [client 20.220.225.223:62897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/fz.php"] [unique_id "al9KNE0Dwhk5-Z44XrpkbgAAAuM"]
[Tue Jul 21 07:30:12.702088 2026] [security2:error] [pid 229246:tid 229268] [remote 20.153.140.50:35714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "manual.fernandohipolito.com.br"] [uri "/wp-login.php"] [unique_id "al9KNCBMYeh5YLVG45yJOgACFhU"]
[Tue Jul 21 07:30:12.766446 2026] [security2:error] [pid 229246:tid 229305] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KNCBMYeh5YLVG45yJOwACGjo"]
[Tue Jul 21 07:30:12.766573 2026] [security2:error] [pid 229246:tid 229382] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KNCBMYeh5YLVG45yJOwACGjo"]
[Tue Jul 21 07:30:13.239606 2026] [security2:error] [pid 230252:tid 230426] [client 117.251.86.144:32834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkfQAAAsM"]
[Tue Jul 21 07:30:13.239735 2026] [security2:error] [pid 230252:tid 230426] [client 117.251.86.144:32834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkfQAAAsM"]
[Tue Jul 21 07:30:13.321112 2026] [security2:error] [pid 230252:tid 230496] [client 62.102.148.164:39440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkgAAAAwk"]
[Tue Jul 21 07:30:13.321215 2026] [security2:error] [pid 230252:tid 230496] [client 62.102.148.164:39440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkgAAAAwk"]
[Tue Jul 21 07:30:13.494532 2026] [security2:error] [pid 230252:tid 230504] [client 139.135.44.145:53388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkggAAAxE"]
[Tue Jul 21 07:30:13.494665 2026] [security2:error] [pid 230252:tid 230504] [client 139.135.44.145:53388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkggAAAxE"]
[Tue Jul 21 07:30:13.585547 2026] [security2:error] [pid 229246:tid 229497] [client 45.8.17.117:57377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/widgets/admin.php"] [unique_id "al9KNSBMYeh5YLVG45yJRwAAAo0"]
[Tue Jul 21 07:30:13.613649 2026] [security2:error] [pid 230252:tid 230436] [client 82.102.28.107:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkiAAAAs0"]
[Tue Jul 21 07:30:13.613750 2026] [security2:error] [pid 230252:tid 230436] [client 82.102.28.107:49848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkiAAAAs0"]
[Tue Jul 21 07:30:13.664937 2026] [security2:error] [pid 230252:tid 230404] [client 109.248.148.246:58758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkiQAAAq0"]
[Tue Jul 21 07:30:13.665083 2026] [security2:error] [pid 230252:tid 230404] [client 109.248.148.246:58758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkiQAAAq0"]
[Tue Jul 21 07:30:13.949542 2026] [security2:error] [pid 230252:tid 230511] [client 20.104.96.117:59587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/gptsh.php"] [unique_id "al9KNU0Dwhk5-Z44XrpkjAAAAxg"]
[Tue Jul 21 07:30:14.122219 2026] [security2:error] [pid 229246:tid 229485] [client 20.220.225.223:46094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9KNiBMYeh5YLVG45yJTgAAAoE"]
[Tue Jul 21 07:30:14.586152 2026] [security2:error] [pid 229246:tid 229477] [client 45.8.17.136:53385] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/themes/"] [unique_id "al9KNiBMYeh5YLVG45yJWAAAAnk"]
[Tue Jul 21 07:30:14.809583 2026] [security2:error] [pid 230252:tid 230494] [client 85.204.70.92:46152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.frsadvocacia.net"] [uri "/wp-login.php"] [unique_id "al9KNk0Dwhk5-Z44XrpklAAAAwc"]
[Tue Jul 21 07:30:15.024276 2026] [autoindex:error] [pid 229246:tid 229439] [client 100.50.152.193:53401] AH01276: Cannot serve directory /home2/onfiel33/kotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:15.362735 2026] [security2:error] [pid 229246:tid 229422] [client 20.220.225.223:46136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/dr.php"] [unique_id "al9KNyBMYeh5YLVG45yJZgAAAkI"]
[Tue Jul 21 07:30:15.373421 2026] [security2:error] [pid 229246:tid 229297] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KNyBMYeh5YLVG45yJaAACezI"]
[Tue Jul 21 07:30:15.373548 2026] [security2:error] [pid 229246:tid 229479] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KNyBMYeh5YLVG45yJaAACezI"]
[Tue Jul 21 07:30:15.384721 2026] [security2:error] [pid 230252:tid 230480] [client 45.8.17.105:20279] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/social-link/"] [unique_id "al9KN00Dwhk5-Z44XrpkmwAAAvk"]
[Tue Jul 21 07:30:15.420533 2026] [security2:error] [pid 230252:tid 230403] [client 136.144.33.241:34797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KN00Dwhk5-Z44XrpknAAAAqw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:15.618285 2026] [security2:error] [pid 229246:tid 229480] [client 209.141.34.121:64547] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "patriciarodriguesterapia.com.br"] [uri "/"] [unique_id "al9KNyBMYeh5YLVG45yJbQAAAnw"]
[Tue Jul 21 07:30:15.732030 2026] [security2:error] [pid 230252:tid 230475] [client 103.106.20.201:60356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KN00Dwhk5-Z44XrpkoAAAAvQ"]
[Tue Jul 21 07:30:15.732164 2026] [security2:error] [pid 230252:tid 230475] [client 103.106.20.201:60356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KN00Dwhk5-Z44XrpkoAAAAvQ"]
[Tue Jul 21 07:30:15.959338 2026] [security2:error] [pid 229246:tid 229330] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KNyBMYeh5YLVG45yJcwACc1M"]
[Tue Jul 21 07:30:15.959535 2026] [security2:error] [pid 229246:tid 229471] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KNyBMYeh5YLVG45yJcwACc1M"]
[Tue Jul 21 07:30:16.065481 2026] [security2:error] [pid 230252:tid 230425] [client 20.104.96.117:42397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/rithin.php"] [unique_id "al9KOE0Dwhk5-Z44XrpkpAAAAsI"]
[Tue Jul 21 07:30:16.123693 2026] [security2:error] [pid 230252:tid 230452] [client 103.162.129.114:53331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KOE0Dwhk5-Z44XrpkpgAAAt0"]
[Tue Jul 21 07:30:16.123869 2026] [security2:error] [pid 230252:tid 230452] [client 103.162.129.114:53331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KOE0Dwhk5-Z44XrpkpgAAAt0"]
[Tue Jul 21 07:30:16.128719 2026] [security2:error] [pid 230252:tid 230462] [client 209.141.34.121:64610] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "patriciarodriguesterapia.com.br"] [uri "/"] [unique_id "al9KOE0Dwhk5-Z44XrpkpwAAAuc"]
[Tue Jul 21 07:30:16.336132 2026] [security2:error] [pid 230252:tid 230438] [client 20.151.10.161:57362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KOE0Dwhk5-Z44XrpkqgAAAs8"]
[Tue Jul 21 07:30:16.598694 2026] [security2:error] [pid 230252:tid 230506] [client 45.8.17.121:45789] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-good.php"] [unique_id "al9KOE0Dwhk5-Z44XrpkrwAAAxM"]
[Tue Jul 21 07:30:16.958466 2026] [security2:error] [pid 230252:tid 230321] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KOE0Dwhk5-Z44XrpktQACrUM"]
[Tue Jul 21 07:30:16.958666 2026] [security2:error] [pid 230252:tid 230404] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KOE0Dwhk5-Z44XrpktQACrUM"]
[Tue Jul 21 07:30:16.972986 2026] [security2:error] [pid 230252:tid 230259] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KOE0Dwhk5-Z44XrpktgACngU"]
[Tue Jul 21 07:30:16.973112 2026] [security2:error] [pid 230252:tid 230389] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KOE0Dwhk5-Z44XrpktgACngU"]
[Tue Jul 21 07:30:17.034832 2026] [security2:error] [pid 230252:tid 230468] [client 175.45.70.82:62354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOU0Dwhk5-Z44XrpkuAAAAu0"]
[Tue Jul 21 07:30:17.034937 2026] [security2:error] [pid 230252:tid 230468] [client 175.45.70.82:62354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOU0Dwhk5-Z44XrpkuAAAAu0"]
[Tue Jul 21 07:30:17.153882 2026] [security2:error] [pid 230252:tid 230454] [client 154.192.233.199:59875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOU0Dwhk5-Z44XrpkugAAAt8"]
[Tue Jul 21 07:30:17.153990 2026] [security2:error] [pid 230252:tid 230454] [client 154.192.233.199:59875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOU0Dwhk5-Z44XrpkugAAAt8"]
[Tue Jul 21 07:30:17.492455 2026] [security2:error] [pid 229246:tid 229468] [client 45.8.17.125:29797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/elementor/css/"] [unique_id "al9KOSBMYeh5YLVG45yJhQAAAnA"]
[Tue Jul 21 07:30:17.801151 2026] [security2:error] [pid 230252:tid 230501] [client 103.174.34.15:55065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOU0Dwhk5-Z44XrpkvgAAAw4"]
[Tue Jul 21 07:30:17.801303 2026] [security2:error] [pid 230252:tid 230501] [client 103.174.34.15:55065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOU0Dwhk5-Z44XrpkvgAAAw4"]
[Tue Jul 21 07:30:17.844506 2026] [security2:error] [pid 229246:tid 229436] [client 173.24.185.52:52165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KOSBMYeh5YLVG45yJiAAAAlA"]
[Tue Jul 21 07:30:17.844600 2026] [security2:error] [pid 229246:tid 229436] [client 173.24.185.52:52165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KOSBMYeh5YLVG45yJiAAAAlA"]
[Tue Jul 21 07:30:18.081731 2026] [security2:error] [pid 229246:tid 229452] [client 62.102.148.164:44218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9KOiBMYeh5YLVG45yJkwAAAmA"]
[Tue Jul 21 07:30:18.081871 2026] [security2:error] [pid 229246:tid 229452] [client 62.102.148.164:44218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9KOiBMYeh5YLVG45yJkwAAAmA"]
[Tue Jul 21 07:30:18.371082 2026] [security2:error] [pid 229246:tid 229494] [client 173.252.95.39:52968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KOiBMYeh5YLVG45yJnQAAAoo"]
[Tue Jul 21 07:30:18.386543 2026] [security2:error] [pid 229246:tid 229403] [client 45.8.17.121:24275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/config.php"] [unique_id "al9KOiBMYeh5YLVG45yJngAAAi8"]
[Tue Jul 21 07:30:18.421187 2026] [security2:error] [pid 230252:tid 230455] [client 20.104.96.117:42290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/fffm.php"] [unique_id "al9KOk0Dwhk5-Z44XrpkwwAAAuA"]
[Tue Jul 21 07:30:18.502901 2026] [security2:error] [pid 229246:tid 229384] [client 20.220.225.223:4595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KOiBMYeh5YLVG45yJogAAAhw"]
[Tue Jul 21 07:30:19.329793 2026] [security2:error] [pid 230252:tid 230430] [client 82.102.28.107:39302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KO00Dwhk5-Z44XrpkygAAAsc"]
[Tue Jul 21 07:30:19.329893 2026] [security2:error] [pid 230252:tid 230430] [client 82.102.28.107:39302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KO00Dwhk5-Z44XrpkygAAAsc"]
[Tue Jul 21 07:30:19.400114 2026] [security2:error] [pid 229246:tid 229500] [client 114.119.144.84:48905] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tryhealth.shop"] [uri "/"] [unique_id "al9KOyBMYeh5YLVG45yJsQAAApA"], referer: https://newlyregddomains.com/2024-02-02/44
[Tue Jul 21 07:30:19.574548 2026] [security2:error] [pid 229246:tid 229396] [client 20.151.10.161:51298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KOyBMYeh5YLVG45yJtwAAAig"]
[Tue Jul 21 07:30:19.601029 2026] [security2:error] [pid 230252:tid 230500] [client 45.8.17.146:54575] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "al9KO00Dwhk5-Z44XrpkzgAAAw0"]
[Tue Jul 21 07:30:19.868570 2026] [proxy:error] [pid 230252:tid 230493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:30:19.868641 2026] [proxy_http:error] [pid 230252:tid 230493] [client 195.96.139.107:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:30:19.869083 2026] [proxy:error] [pid 230252:tid 230493] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:30:19.869112 2026] [proxy_http:error] [pid 230252:tid 230493] [client 195.96.139.107:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:30:19.885025 2026] [security2:error] [pid 229246:tid 229459] [client 152.59.154.239:57203] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOiBMYeh5YLVG45yJowAAAmc"]
[Tue Jul 21 07:30:19.885174 2026] [security2:error] [pid 229246:tid 229459] [client 152.59.154.239:57203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KOiBMYeh5YLVG45yJowAAAmc"]
[Tue Jul 21 07:30:20.115454 2026] [security2:error] [pid 229246:tid 229481] [client 136.144.33.53:54683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KPCBMYeh5YLVG45yJwAAAAn0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:20.483430 2026] [security2:error] [pid 230252:tid 230468] [client 45.8.17.122:50603] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/theme-compat/chosen.php"] [unique_id "al9KPE0Dwhk5-Z44Xrpk2gAAAu0"]
[Tue Jul 21 07:30:20.689372 2026] [security2:error] [pid 230252:tid 230414] [client 20.220.225.223:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/2x.php"] [unique_id "al9KPE0Dwhk5-Z44Xrpk3AAAArc"]
[Tue Jul 21 07:30:20.710327 2026] [security2:error] [pid 230252:tid 230443] [client 45.251.232.145:59881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KPE0Dwhk5-Z44Xrpk3QAAAtQ"]
[Tue Jul 21 07:30:20.710465 2026] [security2:error] [pid 230252:tid 230443] [client 45.251.232.145:59881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KPE0Dwhk5-Z44Xrpk3QAAAtQ"]
[Tue Jul 21 07:30:20.864968 2026] [security2:error] [pid 230252:tid 230421] [client 20.104.96.117:59792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/dfre.php"] [unique_id "al9KPE0Dwhk5-Z44Xrpk4QAAAr4"]
[Tue Jul 21 07:30:20.978882 2026] [security2:error] [pid 230252:tid 230488] [client 74.7.244.12:36430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "l-attohome.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9KPE0Dwhk5-Z44Xrpk5gADAXo"]
[Tue Jul 21 07:30:21.028555 2026] [security2:error] [pid 229246:tid 229454] [client 20.151.10.161:50885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/x.php"] [unique_id "al9KPSBMYeh5YLVG45yJzAAAAmI"]
[Tue Jul 21 07:30:21.045873 2026] [security2:error] [pid 229246:tid 229399] [client 62.102.148.164:40502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9KPSBMYeh5YLVG45yJzQAAAis"]
[Tue Jul 21 07:30:21.045973 2026] [security2:error] [pid 229246:tid 229399] [client 62.102.148.164:40502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9KPSBMYeh5YLVG45yJzQAAAis"]
[Tue Jul 21 07:30:21.357659 2026] [security2:error] [pid 229246:tid 229422] [client 20.220.225.223:45981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/kq1.php"] [unique_id "al9KPSBMYeh5YLVG45yJ1QAAAkI"]
[Tue Jul 21 07:30:21.689431 2026] [security2:error] [pid 230252:tid 230446] [client 45.8.17.145:22109] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/root.php"] [unique_id "al9KPU0Dwhk5-Z44XrplMgAAAtc"]
[Tue Jul 21 07:30:21.837681 2026] [security2:error] [pid 230252:tid 230493] [client 20.206.105.145:7472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KPU0Dwhk5-Z44XrplOAAAAwY"]
[Tue Jul 21 07:30:21.985594 2026] [security2:error] [pid 229246:tid 229391] [client 20.151.10.161:50904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/j260624_13.php"] [unique_id "al9KPSBMYeh5YLVG45yJ4AAAAiM"]
[Tue Jul 21 07:30:22.043512 2026] [security2:error] [pid 230252:tid 230369] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KPk0Dwhk5-Z44XrplPwADE3I"]
[Tue Jul 21 07:30:22.043670 2026] [security2:error] [pid 230252:tid 230506] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KPk0Dwhk5-Z44XrplPwADE3I"]
[Tue Jul 21 07:30:22.368891 2026] [security2:error] [pid 229246:tid 229460] [client 20.220.225.223:46114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/zzz.php"] [unique_id "al9KPiBMYeh5YLVG45yJ5AAAAmg"]
[Tue Jul 21 07:30:22.578797 2026] [autoindex:error] [pid 230252:tid 230465] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:22.597101 2026] [security2:error] [pid 230252:tid 230467] [client 45.8.17.110:37249] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/widgets/"] [unique_id "al9KPk0Dwhk5-Z44XrplSAAAAuw"]
[Tue Jul 21 07:30:23.127694 2026] [security2:error] [pid 230252:tid 230413] [client 20.206.105.145:7777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KP00Dwhk5-Z44XrplUAAAArY"]
[Tue Jul 21 07:30:23.138993 2026] [security2:error] [pid 230252:tid 230318] [remote 34.91.119.153:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.luminabeauty.com.br"] [uri "/"] [unique_id "al9KP00Dwhk5-Z44XrplUQADDkA"]
[Tue Jul 21 07:30:23.139130 2026] [security2:error] [pid 230252:tid 230501] [client 34.91.119.153:0] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.luminabeauty.com.br"] [uri "/"] [unique_id "al9KP00Dwhk5-Z44XrplUQADDkA"]
[Tue Jul 21 07:30:23.233095 2026] [autoindex:error] [pid 230252:tid 230433] [client 175.27.171.245:50560] AH01276: Cannot serve directory /home2/onfiel33/lucaskotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:23.297276 2026] [security2:error] [pid 230252:tid 230380] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KP00Dwhk5-Z44XrplUwAC430"]
[Tue Jul 21 07:30:23.297400 2026] [security2:error] [pid 230252:tid 230458] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KP00Dwhk5-Z44XrplUwAC430"]
[Tue Jul 21 07:30:23.487101 2026] [autoindex:error] [pid 230252:tid 230455] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:23.602121 2026] [security2:error] [pid 230252:tid 230494] [client 20.206.105.145:7747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/media.php"] [unique_id "al9KP00Dwhk5-Z44XrplVwAAAwc"]
[Tue Jul 21 07:30:23.691731 2026] [security2:error] [pid 229246:tid 229491] [client 20.220.225.223:46088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wicked.php"] [unique_id "al9KPyBMYeh5YLVG45yJ9wAAAoc"]
[Tue Jul 21 07:30:23.835943 2026] [authz_core:error] [pid 230252:tid 230469] [client 85.204.70.92:33458] AH01630: client denied by server configuration: /home3/frsadv16/public_html/wp-content/plugins/akismet/
[Tue Jul 21 07:30:23.938580 2026] [security2:error] [pid 230252:tid 230456] [client 117.251.86.144:33434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KP00Dwhk5-Z44XrplWgAAAuE"]
[Tue Jul 21 07:30:23.938710 2026] [security2:error] [pid 230252:tid 230456] [client 117.251.86.144:33434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KP00Dwhk5-Z44XrplWgAAAuE"]
[Tue Jul 21 07:30:23.978609 2026] [security2:error] [pid 229246:tid 229459] [client 20.151.10.161:51319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/d62.php"] [unique_id "al9KPyBMYeh5YLVG45yJ-gAAAmc"]
[Tue Jul 21 07:30:24.048969 2026] [autoindex:error] [pid 230252:tid 230403] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:24.272536 2026] [security2:error] [pid 230252:tid 230350] [remote 4.205.168.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/wp-login.php"] [unique_id "al9KQE0Dwhk5-Z44XrplXQACwV8"]
[Tue Jul 21 07:30:24.295066 2026] [security2:error] [pid 229246:tid 229483] [client 20.220.225.223:61958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KQCBMYeh5YLVG45yKAgAAAn8"]
[Tue Jul 21 07:30:24.342975 2026] [autoindex:error] [pid 230252:tid 230510] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:24.446517 2026] [security2:error] [pid 229246:tid 229451] [client 139.135.44.145:54161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.44.135.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KQCBMYeh5YLVG45yKAwAAAl8"]
[Tue Jul 21 07:30:24.446643 2026] [security2:error] [pid 229246:tid 229451] [client 139.135.44.145:54161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9KQCBMYeh5YLVG45yKAwAAAl8"]
[Tue Jul 21 07:30:24.457397 2026] [security2:error] [pid 230252:tid 230446] [client 20.206.105.145:54588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/images.php"] [unique_id "al9KQE0Dwhk5-Z44XrplYgAAAtc"]
[Tue Jul 21 07:30:24.549204 2026] [security2:error] [pid 230252:tid 230493] [client 20.197.192.193:44117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KQE0Dwhk5-Z44XrplZwAAAwY"]
[Tue Jul 21 07:30:24.556619 2026] [autoindex:error] [pid 230252:tid 230500] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:24.689859 2026] [security2:error] [pid 230252:tid 230396] [client 136.144.33.104:22903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KQE0Dwhk5-Z44XrplZAAAAqU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:24.742317 2026] [security2:error] [pid 229246:tid 229482] [client 20.197.192.193:40809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KQCBMYeh5YLVG45yKDQAAAn4"]
[Tue Jul 21 07:30:24.785984 2026] [security2:error] [pid 229246:tid 229492] [client 20.197.192.193:53294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/dp.php"] [unique_id "al9KQCBMYeh5YLVG45yKDwAAAog"]
[Tue Jul 21 07:30:24.786980 2026] [security2:error] [pid 230252:tid 230475] [client 45.8.17.112:61073] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/class.php"] [unique_id "al9KQE0Dwhk5-Z44XrplcAAAAvQ"]
[Tue Jul 21 07:30:24.829393 2026] [autoindex:error] [pid 230252:tid 230428] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:24.833788 2026] [security2:error] [pid 229246:tid 229494] [client 20.197.192.193:44112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/old.php"] [unique_id "al9KQCBMYeh5YLVG45yKEQAAAoo"]
[Tue Jul 21 07:30:24.859339 2026] [security2:error] [pid 229246:tid 229474] [client 20.197.192.193:44155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/ms-new.php"] [unique_id "al9KQCBMYeh5YLVG45yKEgAAAnY"]
[Tue Jul 21 07:30:24.876892 2026] [security2:error] [pid 229246:tid 229487] [client 59.96.220.140:55748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KQCBMYeh5YLVG45yKEwAAAoM"]
[Tue Jul 21 07:30:24.877715 2026] [security2:error] [pid 229246:tid 229487] [client 59.96.220.140:55748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KQCBMYeh5YLVG45yKEwAAAoM"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:30:24.936760 2026] [security2:error] [pid 230252:tid 230405] [client 20.197.192.193:40805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/track.php"] [unique_id "al9KQE0Dwhk5-Z44XrplcwAAAq4"]
[Tue Jul 21 07:30:24.962409 2026] [security2:error] [pid 230252:tid 230389] [client 20.197.192.193:40789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/2352356666.php"] [unique_id "al9KQE0Dwhk5-Z44XrpldAAAAp4"]
[Tue Jul 21 07:30:24.992799 2026] [security2:error] [pid 230252:tid 230441] [client 20.197.192.193:40817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/pn.php"] [unique_id "al9KQE0Dwhk5-Z44XrpldQAAAtI"]
[Tue Jul 21 07:30:25.011272 2026] [security2:error] [pid 230252:tid 230386] [client 20.197.192.193:40776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9KQU0Dwhk5-Z44XrpldgAAAps"]
[Tue Jul 21 07:30:25.029746 2026] [security2:error] [pid 230252:tid 230511] [client 20.197.192.193:40788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/dr.php"] [unique_id "al9KQU0Dwhk5-Z44XrpldwAAAxg"]
[Tue Jul 21 07:30:25.054142 2026] [autoindex:error] [pid 230252:tid 230465] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:25.065885 2026] [security2:error] [pid 230252:tid 230467] [client 20.220.225.223:46138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/edit.php"] [unique_id "al9KQU0Dwhk5-Z44XrplewAAAuw"]
[Tue Jul 21 07:30:25.089789 2026] [security2:error] [pid 230252:tid 230384] [client 20.197.192.193:53297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/2x.php"] [unique_id "al9KQU0Dwhk5-Z44XrplfAAAApk"]
[Tue Jul 21 07:30:25.161635 2026] [security2:error] [pid 230252:tid 230399] [client 20.151.10.161:51274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ups.php"] [unique_id "al9KQU0Dwhk5-Z44XrplgQAAAqg"]
[Tue Jul 21 07:30:25.176085 2026] [security2:error] [pid 230252:tid 230466] [client 20.197.192.193:44098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/kq1.php"] [unique_id "al9KQU0Dwhk5-Z44XrplggAAAus"]
[Tue Jul 21 07:30:25.248191 2026] [security2:error] [pid 230252:tid 230481] [client 20.197.192.193:44145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/zzz.php"] [unique_id "al9KQU0Dwhk5-Z44XrpliAAAAvo"]
[Tue Jul 21 07:30:25.268042 2026] [security2:error] [pid 230252:tid 230483] [client 20.197.192.193:44158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wicked.php"] [unique_id "al9KQU0Dwhk5-Z44XrpljAAAAvw"]
[Tue Jul 21 07:30:25.294902 2026] [security2:error] [pid 230252:tid 230485] [client 20.197.192.193:44107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/edit.php"] [unique_id "al9KQU0Dwhk5-Z44XrpljQAAAv4"]
[Tue Jul 21 07:30:25.327801 2026] [autoindex:error] [pid 230252:tid 230448] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:25.334249 2026] [security2:error] [pid 230252:tid 230449] [client 20.197.192.193:44156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/kua.php"] [unique_id "al9KQU0Dwhk5-Z44XrpljwAAAto"]
[Tue Jul 21 07:30:25.366618 2026] [security2:error] [pid 230252:tid 230401] [client 20.197.192.193:44101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/ez.php"] [unique_id "al9KQU0Dwhk5-Z44XrplkwAAAqo"]
[Tue Jul 21 07:30:25.369677 2026] [security2:error] [pid 230252:tid 230490] [client 20.206.105.145:7767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/adminner.php"] [unique_id "al9KQU0Dwhk5-Z44XrpllAAAAwM"]
[Tue Jul 21 07:30:25.516954 2026] [security2:error] [pid 229246:tid 229415] [client 20.197.192.193:40829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/fz.php"] [unique_id "al9KQSBMYeh5YLVG45yKHAAAAjs"]
[Tue Jul 21 07:30:25.538303 2026] [autoindex:error] [pid 230252:tid 230409] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:25.677597 2026] [security2:error] [pid 229246:tid 229385] [client 20.220.225.223:8936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/la.php"] [unique_id "al9KQSBMYeh5YLVG45yKHwAAAh0"]
[Tue Jul 21 07:30:25.726683 2026] [security2:error] [pid 229246:tid 229376] [client 20.197.192.193:40799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/la.php"] [unique_id "al9KQSBMYeh5YLVG45yKIAAAAhQ"]
[Tue Jul 21 07:30:25.745267 2026] [autoindex:error] [pid 230252:tid 230428] [client 85.204.70.92:33458] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:25.779389 2026] [security2:error] [pid 229246:tid 229473] [client 20.197.192.193:40814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9KQSBMYeh5YLVG45yKIQAAAnU"]
[Tue Jul 21 07:30:25.787014 2026] [security2:error] [pid 229246:tid 229428] [client 45.8.17.62:56127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "al9KQSBMYeh5YLVG45yKIgAAAkg"]
[Tue Jul 21 07:30:25.792764 2026] [security2:error] [pid 229246:tid 229455] [client 20.197.192.193:44122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/inso.php"] [unique_id "al9KQSBMYeh5YLVG45yKIwAAAmM"]
[Tue Jul 21 07:30:25.820475 2026] [security2:error] [pid 230252:tid 230477] [client 74.7.228.30:45502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.espacofabula.com"] [uri "/index.php"] [unique_id "al9KQU0Dwhk5-Z44XrpliwAC9kY"]
[Tue Jul 21 07:30:25.832034 2026] [security2:error] [pid 229246:tid 229408] [client 20.197.192.193:44099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wpx.php"] [unique_id "al9KQSBMYeh5YLVG45yKJgAAAjQ"]
[Tue Jul 21 07:30:25.864341 2026] [security2:error] [pid 230252:tid 230405] [client 20.197.192.193:44153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/berlin.php"] [unique_id "al9KQU0Dwhk5-Z44XrplnwAAAq4"]
[Tue Jul 21 07:30:25.872843 2026] [security2:error] [pid 229246:tid 229252] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KQSBMYeh5YLVG45yKJwACXQU"]
[Tue Jul 21 07:30:25.872984 2026] [security2:error] [pid 229246:tid 229449] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KQSBMYeh5YLVG45yKJwACXQU"]
[Tue Jul 21 07:30:25.895307 2026] [security2:error] [pid 230252:tid 230389] [client 20.197.192.193:40771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/billur.php"] [unique_id "al9KQU0Dwhk5-Z44XrploQAAAp4"]
[Tue Jul 21 07:30:25.937112 2026] [security2:error] [pid 230252:tid 230502] [client 20.197.192.193:44126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/mimpi.php"] [unique_id "al9KQU0Dwhk5-Z44XrplogAAAw8"]
[Tue Jul 21 07:30:25.956716 2026] [security2:error] [pid 230252:tid 230443] [client 20.197.192.193:40791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/dp.php"] [unique_id "al9KQU0Dwhk5-Z44XrplowAAAtQ"]
[Tue Jul 21 07:30:26.099672 2026] [security2:error] [pid 230252:tid 230484] [client 20.197.192.193:44105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/bootstrap.php"] [unique_id "al9KQk0Dwhk5-Z44XrplpgAAAv0"]
[Tue Jul 21 07:30:26.234256 2026] [security2:error] [pid 229246:tid 229500] [client 20.197.192.193:40773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wp-editor.php"] [unique_id "al9KQiBMYeh5YLVG45yKLgAAApA"]
[Tue Jul 21 07:30:26.234635 2026] [security2:error] [pid 229246:tid 229441] [client 20.104.96.117:59814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/wp-happy.php"] [unique_id "al9KQiBMYeh5YLVG45yKLwAAAlU"]
[Tue Jul 21 07:30:26.360358 2026] [security2:error] [pid 229246:tid 229459] [client 20.151.10.161:50929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/k.php"] [unique_id "al9KQiBMYeh5YLVG45yKMAAAAmc"]
[Tue Jul 21 07:30:26.374461 2026] [security2:error] [pid 229246:tid 229481] [client 20.197.192.193:40794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/cro.php"] [unique_id "al9KQiBMYeh5YLVG45yKMgAAAn0"]
[Tue Jul 21 07:30:26.433311 2026] [security2:error] [pid 229246:tid 229468] [client 20.197.192.193:40770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/cron-tab.php"] [unique_id "al9KQiBMYeh5YLVG45yKMwAAAnA"]
[Tue Jul 21 07:30:26.437421 2026] [security2:error] [pid 229246:tid 229409] [client 103.106.20.201:60922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQiBMYeh5YLVG45yKNAAAAjU"]
[Tue Jul 21 07:30:26.437553 2026] [security2:error] [pid 229246:tid 229409] [client 103.106.20.201:60922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQiBMYeh5YLVG45yKNAAAAjU"]
[Tue Jul 21 07:30:26.480342 2026] [security2:error] [pid 229246:tid 229288] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQiBMYeh5YLVG45yKNQAChyk"]
[Tue Jul 21 07:30:26.480969 2026] [security2:error] [pid 229246:tid 229491] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQiBMYeh5YLVG45yKNQAChyk"]
[Tue Jul 21 07:30:26.481166 2026] [security2:error] [pid 229246:tid 229496] [client 20.197.192.193:40800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/koiy.php"] [unique_id "al9KQiBMYeh5YLVG45yKNgAAAow"]
[Tue Jul 21 07:30:26.500529 2026] [security2:error] [pid 229246:tid 229489] [client 20.197.192.193:40780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/hp2.php"] [unique_id "al9KQiBMYeh5YLVG45yKNwAAAoU"]
[Tue Jul 21 07:30:26.530497 2026] [security2:error] [pid 229246:tid 229483] [client 20.197.192.193:44129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/hp3.php"] [unique_id "al9KQiBMYeh5YLVG45yKOAAAAn8"]
[Tue Jul 21 07:30:26.568315 2026] [security2:error] [pid 230252:tid 230404] [client 103.162.129.114:53776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KQk0Dwhk5-Z44XrplqAAAAq0"]
[Tue Jul 21 07:30:26.568473 2026] [security2:error] [pid 230252:tid 230404] [client 103.162.129.114:53776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KQk0Dwhk5-Z44XrplqAAAAq0"]
[Tue Jul 21 07:30:26.581013 2026] [security2:error] [pid 229246:tid 229451] [client 20.197.192.193:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/aa1.php"] [unique_id "al9KQiBMYeh5YLVG45yKOQAAAl8"]
[Tue Jul 21 07:30:26.597618 2026] [security2:error] [pid 229246:tid 229421] [client 20.206.105.145:7690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/admin.php"] [unique_id "al9KQiBMYeh5YLVG45yKOgAAAkE"]
[Tue Jul 21 07:30:26.632491 2026] [security2:error] [pid 229246:tid 229454] [client 20.197.192.193:44106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/acew67.php"] [unique_id "al9KQiBMYeh5YLVG45yKPgAAAmI"]
[Tue Jul 21 07:30:26.694984 2026] [security2:error] [pid 229246:tid 229387] [client 20.197.192.193:53251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/bscclapb.php"] [unique_id "al9KQiBMYeh5YLVG45yKQgAAAh8"]
[Tue Jul 21 07:30:26.729795 2026] [security2:error] [pid 229246:tid 229380] [client 20.197.192.193:40774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/else1.php"] [unique_id "al9KQiBMYeh5YLVG45yKRAAAAhg"]
[Tue Jul 21 07:30:26.747187 2026] [autoindex:error] [pid 229246:tid 229474] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:26.763655 2026] [security2:error] [pid 229246:tid 229472] [client 20.197.192.193:44096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/tkikikoko.php"] [unique_id "al9KQiBMYeh5YLVG45yKRwAAAnQ"]
[Tue Jul 21 07:30:26.802639 2026] [security2:error] [pid 229246:tid 229479] [client 20.197.192.193:40782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9KQiBMYeh5YLVG45yKSQAAAns"]
[Tue Jul 21 07:30:26.830731 2026] [security2:error] [pid 229246:tid 229448] [client 20.197.192.193:40825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wp-css.php"] [unique_id "al9KQiBMYeh5YLVG45yKTQAAAlw"]
[Tue Jul 21 07:30:26.853589 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.192.193:44134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wp-explorer.php"] [unique_id "al9KQiBMYeh5YLVG45yKTgAAAik"]
[Tue Jul 21 07:30:26.878460 2026] [security2:error] [pid 229246:tid 229413] [client 20.197.192.193:44133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/akismet.php"] [unique_id "al9KQiBMYeh5YLVG45yKTwAAAjk"]
[Tue Jul 21 07:30:26.887135 2026] [security2:error] [pid 229246:tid 229393] [client 45.8.17.123:28719] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/news-portal/admins-dir.php"] [unique_id "al9KQiBMYeh5YLVG45yKUQAAAiU"]
[Tue Jul 21 07:30:26.911810 2026] [security2:error] [pid 229246:tid 229377] [client 20.151.10.161:50942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/k2.php"] [unique_id "al9KQiBMYeh5YLVG45yKUgAAAhU"]
[Tue Jul 21 07:30:26.913182 2026] [security2:error] [pid 229246:tid 229460] [client 20.197.192.193:44108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/ace2.php"] [unique_id "al9KQiBMYeh5YLVG45yKUwAAAmg"]
[Tue Jul 21 07:30:26.949077 2026] [security2:error] [pid 229246:tid 229480] [client 20.197.192.193:44149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/ms.php"] [unique_id "al9KQiBMYeh5YLVG45yKVQAAAnw"]
[Tue Jul 21 07:30:27.160573 2026] [security2:error] [pid 229246:tid 229378] [client 20.220.225.223:46015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/kua.php"] [unique_id "al9KQyBMYeh5YLVG45yKVwAAAhY"]
[Tue Jul 21 07:30:27.188668 2026] [security2:error] [pid 229246:tid 229457] [client 20.220.225.223:62871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9KQyBMYeh5YLVG45yKXgAAAmU"]
[Tue Jul 21 07:30:27.212855 2026] [autoindex:error] [pid 229246:tid 229398] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:27.275103 2026] [security2:error] [pid 229246:tid 229323] [remote 188.138.102.156:46806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKYQACekw"]
[Tue Jul 21 07:30:27.275270 2026] [security2:error] [pid 229246:tid 229478] [client 188.138.102.156:46806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKYQACekw"]
[Tue Jul 21 07:30:27.457891 2026] [autoindex:error] [pid 229246:tid 229493] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:27.546830 2026] [security2:error] [pid 229246:tid 229260] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKaAACfQ0"]
[Tue Jul 21 07:30:27.547035 2026] [security2:error] [pid 229246:tid 229481] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKaAACfQ0"]
[Tue Jul 21 07:30:27.585158 2026] [security2:error] [pid 229246:tid 229336] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKaQACTFk"]
[Tue Jul 21 07:30:27.585936 2026] [security2:error] [pid 229246:tid 229432] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKaQACTFk"]
[Tue Jul 21 07:30:27.682978 2026] [autoindex:error] [pid 229246:tid 229491] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:27.857879 2026] [security2:error] [pid 229246:tid 229452] [client 20.206.105.145:7730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/k.php"] [unique_id "al9KQyBMYeh5YLVG45yKdQAAAmA"]
[Tue Jul 21 07:30:27.878715 2026] [security2:error] [pid 229246:tid 229470] [client 175.45.70.82:62875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKdgAAAnI"]
[Tue Jul 21 07:30:27.878851 2026] [security2:error] [pid 229246:tid 229470] [client 175.45.70.82:62875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKdgAAAnI"]
[Tue Jul 21 07:30:27.973308 2026] [autoindex:error] [pid 229246:tid 229379] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:27.998295 2026] [security2:error] [pid 229246:tid 229484] [client 154.192.233.199:60368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKegAAAoA"]
[Tue Jul 21 07:30:27.998429 2026] [security2:error] [pid 229246:tid 229484] [client 154.192.233.199:60368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KQyBMYeh5YLVG45yKegAAAoA"]
[Tue Jul 21 07:30:28.163274 2026] [security2:error] [pid 229246:tid 229454] [client 103.76.88.36:64157] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adsul.focsmart.com.br"] [uri "/.env"] [unique_id "al9KRCBMYeh5YLVG45yKfAAAAmI"]
[Tue Jul 21 07:30:28.184390 2026] [security2:error] [pid 229246:tid 229387] [client 85.208.96.202:34686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivaconcierge.com.br"] [uri "/en/_detalhes/gerador/"] [unique_id "al9KRCBMYeh5YLVG45yKfgAAAh8"]
[Tue Jul 21 07:30:28.184533 2026] [security2:error] [pid 229246:tid 229387] [client 85.208.96.202:34686] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vivaconcierge.com.br"] [uri "/en/_detalhes/gerador/"] [unique_id "al9KRCBMYeh5YLVG45yKfgAAAh8"]
[Tue Jul 21 07:30:28.186237 2026] [security2:error] [pid 229246:tid 229380] [client 45.8.17.57:65501] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/chosen.php"] [unique_id "al9KRCBMYeh5YLVG45yKfwAAAhg"]
[Tue Jul 21 07:30:28.250374 2026] [autoindex:error] [pid 229246:tid 229416] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:28.303280 2026] [autoindex:error] [pid 229246:tid 229494] [client 198.235.24.15:62682] AH01276: Cannot serve directory /home2/cla35313/reidocouro.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:28.330236 2026] [security2:error] [pid 229246:tid 229381] [client 20.151.10.161:50892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/k3.php"] [unique_id "al9KRCBMYeh5YLVG45yKiQAAAhk"]
[Tue Jul 21 07:30:28.504121 2026] [security2:error] [pid 229246:tid 229487] [client 173.24.185.52:52635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KRCBMYeh5YLVG45yKkAAAAoM"]
[Tue Jul 21 07:30:28.504250 2026] [security2:error] [pid 229246:tid 229487] [client 173.24.185.52:52635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KRCBMYeh5YLVG45yKkAAAAoM"]
[Tue Jul 21 07:30:28.560086 2026] [security2:error] [pid 229246:tid 229498] [client 103.174.34.15:55552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRCBMYeh5YLVG45yKkwAAAo4"]
[Tue Jul 21 07:30:28.560216 2026] [security2:error] [pid 229246:tid 229498] [client 103.174.34.15:55552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRCBMYeh5YLVG45yKkwAAAo4"]
[Tue Jul 21 07:30:28.570519 2026] [autoindex:error] [pid 229246:tid 229428] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:28.781474 2026] [security2:error] [pid 229246:tid 229478] [client 20.220.225.223:45959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/ez.php"] [unique_id "al9KRCBMYeh5YLVG45yKmwAAAno"]
[Tue Jul 21 07:30:28.898328 2026] [security2:error] [pid 229246:tid 229500] [client 20.151.10.161:51303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/k4.php"] [unique_id "al9KRCBMYeh5YLVG45yKnQAAApA"]
[Tue Jul 21 07:30:28.976927 2026] [autoindex:error] [pid 229246:tid 229441] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:29.077643 2026] [security2:error] [pid 229246:tid 229481] [client 82.102.28.107:51058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKoQAAAn0"]
[Tue Jul 21 07:30:29.077747 2026] [security2:error] [pid 229246:tid 229481] [client 82.102.28.107:51058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKoQAAAn0"]
[Tue Jul 21 07:30:29.102389 2026] [security2:error] [pid 229246:tid 229462] [client 74.7.230.11:59320] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "havoy.com.br"] [uri "/index.php"] [unique_id "al9KQyBMYeh5YLVG45yKZAACal0"]
[Tue Jul 21 07:30:29.139021 2026] [security2:error] [pid 229246:tid 229409] [client 62.102.148.164:40518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKowAAAjU"]
[Tue Jul 21 07:30:29.139155 2026] [security2:error] [pid 229246:tid 229409] [client 62.102.148.164:40518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKowAAAjU"]
[Tue Jul 21 07:30:29.207596 2026] [security2:error] [pid 229246:tid 229491] [client 20.206.105.145:7481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/x.php"] [unique_id "al9KRSBMYeh5YLVG45yKpgAAAoc"]
[Tue Jul 21 07:30:29.326609 2026] [security2:error] [pid 229246:tid 229356] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKsAACi20"]
[Tue Jul 21 07:30:29.326834 2026] [security2:error] [pid 229246:tid 229495] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKsAACi20"]
[Tue Jul 21 07:30:29.386334 2026] [security2:error] [pid 229246:tid 229484] [client 213.152.162.104:57898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKsgAAAoA"]
[Tue Jul 21 07:30:29.386484 2026] [security2:error] [pid 229246:tid 229484] [client 213.152.162.104:57898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKsgAAAoA"]
[Tue Jul 21 07:30:29.725529 2026] [security2:error] [pid 229246:tid 229408] [client 152.59.154.239:57641] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKvAAAAjQ"]
[Tue Jul 21 07:30:29.725665 2026] [security2:error] [pid 229246:tid 229408] [client 152.59.154.239:57641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRSBMYeh5YLVG45yKvAAAAjQ"]
[Tue Jul 21 07:30:29.837771 2026] [security2:error] [pid 229246:tid 229405] [client 20.151.10.161:57365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/k5.php"] [unique_id "al9KRSBMYeh5YLVG45yKxgAAAjE"]
[Tue Jul 21 07:30:29.883299 2026] [security2:error] [pid 229246:tid 229404] [client 45.8.17.60:63043] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/classwithtostring.php"] [unique_id "al9KRSBMYeh5YLVG45yKxwAAAjA"]
[Tue Jul 21 07:30:30.140258 2026] [security2:error] [pid 229246:tid 229498] [client 20.206.105.145:7698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wss.php"] [unique_id "al9KRiBMYeh5YLVG45yKywAAAo4"]
[Tue Jul 21 07:30:30.186664 2026] [security2:error] [pid 229246:tid 229425] [client 20.104.96.117:59820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/fpr4.php"] [unique_id "al9KRiBMYeh5YLVG45yKzAAAAkU"]
[Tue Jul 21 07:30:30.375230 2026] [security2:error] [pid 229246:tid 229431] [client 136.144.33.98:30013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KRiBMYeh5YLVG45yK1gAAAks"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:30.659986 2026] [security2:error] [pid 229246:tid 229432] [client 20.206.105.145:7475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ty.php"] [unique_id "al9KRiBMYeh5YLVG45yK2wAAAkw"]
[Tue Jul 21 07:30:30.814305 2026] [security2:error] [pid 229246:tid 229491] [client 20.206.105.145:7731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/155.php"] [unique_id "al9KRiBMYeh5YLVG45yK4QAAAoc"]
[Tue Jul 21 07:30:30.833200 2026] [security2:error] [pid 229246:tid 229400] [client 82.102.28.107:35664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KRiBMYeh5YLVG45yK4gAAAiw"]
[Tue Jul 21 07:30:30.833306 2026] [security2:error] [pid 229246:tid 229400] [client 82.102.28.107:35664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KRiBMYeh5YLVG45yK4gAAAiw"]
[Tue Jul 21 07:30:30.838822 2026] [security2:error] [pid 229246:tid 229490] [client 20.52.136.55:1557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/default.php"] [unique_id "al9KRiBMYeh5YLVG45yK4wAAAoY"]
[Tue Jul 21 07:30:30.898136 2026] [security2:error] [pid 229246:tid 229439] [client 20.206.105.145:7451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ops.php"] [unique_id "al9KRiBMYeh5YLVG45yK5QAAAlM"]
[Tue Jul 21 07:30:31.018043 2026] [security2:error] [pid 229246:tid 229492] [client 20.206.105.145:54554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ingfo.php"] [unique_id "al9KRyBMYeh5YLVG45yK6wAAAog"]
[Tue Jul 21 07:30:31.146326 2026] [security2:error] [pid 229246:tid 229335] [remote 173.252.95.21:60628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9KRyBMYeh5YLVG45yK9AACF1g"]
[Tue Jul 21 07:30:31.165243 2026] [security2:error] [pid 229246:tid 229377] [client 45.251.232.145:60402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRyBMYeh5YLVG45yK9gAAAhU"]
[Tue Jul 21 07:30:31.165348 2026] [security2:error] [pid 229246:tid 229377] [client 45.251.232.145:60402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KRyBMYeh5YLVG45yK9gAAAhU"]
[Tue Jul 21 07:30:31.193881 2026] [security2:error] [pid 229246:tid 229389] [client 20.151.10.161:50895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/w.php"] [unique_id "al9KRyBMYeh5YLVG45yK9wAAAiE"]
[Tue Jul 21 07:30:31.349371 2026] [security2:error] [pid 229246:tid 229405] [client 20.206.105.145:7383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/error_log.php"] [unique_id "al9KRyBMYeh5YLVG45yK_gAAAjE"]
[Tue Jul 21 07:30:31.387488 2026] [security2:error] [pid 229246:tid 229445] [client 45.8.17.116:58213] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentytwo/templates/"] [unique_id "al9KRyBMYeh5YLVG45yK_wAAAlk"]
[Tue Jul 21 07:30:31.551739 2026] [security2:error] [pid 229246:tid 229394] [client 20.220.225.223:54508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/dp.php"] [unique_id "al9KRyBMYeh5YLVG45yLBQAAAiY"]
[Tue Jul 21 07:30:31.597547 2026] [security2:error] [pid 229246:tid 229425] [client 109.248.148.246:52752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KRyBMYeh5YLVG45yLCgAAAkU"]
[Tue Jul 21 07:30:31.597681 2026] [security2:error] [pid 229246:tid 229425] [client 109.248.148.246:52752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KRyBMYeh5YLVG45yLCgAAAkU"]
[Tue Jul 21 07:30:32.273624 2026] [security2:error] [pid 229246:tid 229490] [client 20.206.105.145:7750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ok.php"] [unique_id "al9KSCBMYeh5YLVG45yLHAAAAoY"]
[Tue Jul 21 07:30:32.488903 2026] [security2:error] [pid 229246:tid 229452] [client 45.8.17.106:27901] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Requests/src/Utility/"] [unique_id "al9KSCBMYeh5YLVG45yLJAAAAmA"]
[Tue Jul 21 07:30:32.661855 2026] [security2:error] [pid 229246:tid 229256] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KSCBMYeh5YLVG45yLKAACiAk"]
[Tue Jul 21 07:30:32.662057 2026] [security2:error] [pid 229246:tid 229492] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KSCBMYeh5YLVG45yLKAACiAk"]
[Tue Jul 21 07:30:33.141082 2026] [security2:error] [pid 229246:tid 229465] [client 20.151.10.161:50935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/fpwch.php"] [unique_id "al9KSSBMYeh5YLVG45yLNwAAAm0"]
[Tue Jul 21 07:30:33.162258 2026] [security2:error] [pid 229246:tid 229418] [client 20.206.105.145:7708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/mac.php"] [unique_id "al9KSSBMYeh5YLVG45yLOQAAAj4"]
[Tue Jul 21 07:30:33.238040 2026] [security2:error] [pid 229246:tid 229319] [remote 103.112.62.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naldoinvest.com.br"] [uri "/wp-login.php"] [unique_id "al9KSSBMYeh5YLVG45yLOgACF0g"]
[Tue Jul 21 07:30:33.495987 2026] [security2:error] [pid 229246:tid 229500] [client 45.8.17.105:52937] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "al9KSSBMYeh5YLVG45yLQQAAApA"]
[Tue Jul 21 07:30:33.629476 2026] [security2:error] [pid 229246:tid 229411] [client 20.151.10.161:57454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/w2025.php"] [unique_id "al9KSSBMYeh5YLVG45yLRQAAAjc"]
[Tue Jul 21 07:30:33.657939 2026] [security2:error] [pid 229246:tid 229491] [client 20.220.225.223:45971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/fz.php"] [unique_id "al9KSSBMYeh5YLVG45yLRwAAAoc"]
[Tue Jul 21 07:30:33.681094 2026] [security2:error] [pid 229246:tid 229481] [client 20.220.225.223:62848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/inso.php"] [unique_id "al9KSSBMYeh5YLVG45yLSAAAAn0"]
[Tue Jul 21 07:30:33.808395 2026] [security2:error] [pid 229246:tid 229439] [client 20.206.105.145:7686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wefile.php"] [unique_id "al9KSSBMYeh5YLVG45yLSwAAAlM"]
[Tue Jul 21 07:30:33.845183 2026] [security2:error] [pid 229246:tid 229341] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KSSBMYeh5YLVG45yLTAACNV4"]
[Tue Jul 21 07:30:33.845434 2026] [security2:error] [pid 229246:tid 229409] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KSSBMYeh5YLVG45yLTAACNV4"]
[Tue Jul 21 07:30:33.924400 2026] [security2:error] [pid 229246:tid 229483] [client 20.104.96.117:42392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/file88.php"] [unique_id "al9KSSBMYeh5YLVG45yLTgAAAn8"]
[Tue Jul 21 07:30:34.055475 2026] [security2:error] [pid 229246:tid 229426] [client 59.96.220.140:56227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KSiBMYeh5YLVG45yLUgAAAkY"]
[Tue Jul 21 07:30:34.055631 2026] [security2:error] [pid 229246:tid 229426] [client 59.96.220.140:56227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KSiBMYeh5YLVG45yLUgAAAkY"]
[Tue Jul 21 07:30:34.160187 2026] [autoindex:error] [pid 229246:tid 229448] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:34.453150 2026] [security2:error] [pid 229246:tid 229494] [client 20.206.105.145:7426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9KSiBMYeh5YLVG45yLYAAAAoo"]
[Tue Jul 21 07:30:34.651839 2026] [security2:error] [pid 229246:tid 229477] [client 117.251.86.144:35788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KSiBMYeh5YLVG45yLaAAAAnk"]
[Tue Jul 21 07:30:34.651936 2026] [security2:error] [pid 229246:tid 229477] [client 117.251.86.144:35788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KSiBMYeh5YLVG45yLaAAAAnk"]
[Tue Jul 21 07:30:34.686943 2026] [security2:error] [pid 229246:tid 229498] [client 45.8.17.123:48109] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/lock360.php"] [unique_id "al9KSiBMYeh5YLVG45yLagAAAo4"]
[Tue Jul 21 07:30:34.990636 2026] [security2:error] [pid 229246:tid 229398] [client 193.36.225.55:64263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KSiBMYeh5YLVG45yLdAAAAio"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:35.055087 2026] [autoindex:error] [pid 229246:tid 229411] [client 20.206.105.145:7697] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:35.113142 2026] [autoindex:error] [pid 229246:tid 229423] [client 20.206.105.145:7697] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:35.118435 2026] [security2:error] [pid 229246:tid 229489] [client 20.206.105.145:7697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9KSyBMYeh5YLVG45yLfQAAAoU"]
[Tue Jul 21 07:30:35.436715 2026] [security2:error] [pid 229246:tid 229503] [client 20.220.225.223:46126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/la.php"] [unique_id "al9KSyBMYeh5YLVG45yLjQAAApM"]
[Tue Jul 21 07:30:35.689453 2026] [security2:error] [pid 229246:tid 229389] [client 45.8.17.138:23423] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/fonts/wp-conflg.php"] [unique_id "al9KSyBMYeh5YLVG45yLmAAAAiE"]
[Tue Jul 21 07:30:35.695500 2026] [security2:error] [pid 229246:tid 229460] [client 20.151.10.161:51307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/scxy.php"] [unique_id "al9KSyBMYeh5YLVG45yLmQAAAmg"]
[Tue Jul 21 07:30:36.110167 2026] [security2:error] [pid 229246:tid 229465] [client 74.7.230.58:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "luizanonato1755732317052.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9KTCBMYeh5YLVG45yLpQACbR0"]
[Tue Jul 21 07:30:36.432873 2026] [security2:error] [pid 229246:tid 229278] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KTCBMYeh5YLVG45yLrwACeh8"]
[Tue Jul 21 07:30:36.433067 2026] [security2:error] [pid 229246:tid 229478] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KTCBMYeh5YLVG45yLrwACeh8"]
[Tue Jul 21 07:30:36.616572 2026] [security2:error] [pid 229246:tid 229407] [client 20.206.105.145:7720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/like.php"] [unique_id "al9KTCBMYeh5YLVG45yLwwAAAjM"]
[Tue Jul 21 07:30:36.744382 2026] [security2:error] [pid 229246:tid 229421] [client 20.104.96.117:59616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ccc.php"] [unique_id "al9KTCBMYeh5YLVG45yLyQAAAkE"]
[Tue Jul 21 07:30:36.978639 2026] [security2:error] [pid 229246:tid 229295] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTCBMYeh5YLVG45yL0gACRjA"]
[Tue Jul 21 07:30:36.978807 2026] [security2:error] [pid 229246:tid 229426] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTCBMYeh5YLVG45yL0gACRjA"]
[Tue Jul 21 07:30:36.998647 2026] [security2:error] [pid 229246:tid 229493] [client 45.8.17.58:29269] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentythree/patterns/"] [unique_id "al9KTCBMYeh5YLVG45yL0wAAAok"]
[Tue Jul 21 07:30:37.044555 2026] [security2:error] [pid 229246:tid 229385] [client 122.186.204.214:53565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KTSBMYeh5YLVG45yL1AAAAh0"]
[Tue Jul 21 07:30:37.044740 2026] [security2:error] [pid 229246:tid 229385] [client 122.186.204.214:53565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KTSBMYeh5YLVG45yL1AAAAh0"]
[Tue Jul 21 07:30:37.187841 2026] [security2:error] [pid 229246:tid 229500] [client 20.206.105.145:7425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/.well-known/about.php"] [unique_id "al9KTSBMYeh5YLVG45yL2wAAApA"]
[Tue Jul 21 07:30:37.223325 2026] [security2:error] [pid 229246:tid 229440] [client 103.106.20.201:61494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTSBMYeh5YLVG45yL6QAAAlQ"]
[Tue Jul 21 07:30:37.223449 2026] [security2:error] [pid 229246:tid 229440] [client 103.106.20.201:61494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTSBMYeh5YLVG45yL6QAAAlQ"]
[Tue Jul 21 07:30:37.283607 2026] [security2:error] [pid 229246:tid 229312] [remote 157.66.26.183:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9KTSBMYeh5YLVG45yL8QACg0E"]
[Tue Jul 21 07:30:37.312762 2026] [security2:error] [pid 229246:tid 229405] [client 74.7.175.176:57678] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.nrfilmes.com"] [uri "/robots.txt"] [unique_id "al9KTSBMYeh5YLVG45yL8gACMW8"]
[Tue Jul 21 07:30:37.316237 2026] [security2:error] [pid 229246:tid 229441] [client 103.162.129.114:54221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KTSBMYeh5YLVG45yL8wAAAlU"]
[Tue Jul 21 07:30:37.316345 2026] [security2:error] [pid 229246:tid 229441] [client 103.162.129.114:54221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KTSBMYeh5YLVG45yL8wAAAlU"]
[Tue Jul 21 07:30:37.633909 2026] [security2:error] [pid 229246:tid 229423] [client 20.206.105.145:7483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9KTSBMYeh5YLVG45yL-wAAAkM"]
[Tue Jul 21 07:30:37.937999 2026] [security2:error] [pid 229246:tid 229421] [client 85.204.70.92:45742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.frsadvocacia.net"] [uri "/wp-login.php"] [unique_id "al9KTSBMYeh5YLVG45yMCwAAAkE"]
[Tue Jul 21 07:30:38.085364 2026] [security2:error] [pid 229246:tid 229450] [client 45.8.17.108:48101] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/widgets/admin.php"] [unique_id "al9KTiBMYeh5YLVG45yMEQAAAl4"]
[Tue Jul 21 07:30:38.104187 2026] [security2:error] [pid 229246:tid 229493] [client 20.104.96.117:42430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/777.php"] [unique_id "al9KTiBMYeh5YLVG45yMEgAAAok"]
[Tue Jul 21 07:30:38.131776 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:58044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/FWAZ.php"] [unique_id "al9KTiBMYeh5YLVG45yMFQAAAns"]
[Tue Jul 21 07:30:38.155993 2026] [security2:error] [pid 229246:tid 229354] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMFwACSGs"]
[Tue Jul 21 07:30:38.156136 2026] [security2:error] [pid 229246:tid 229428] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMFwACSGs"]
[Tue Jul 21 07:30:38.214862 2026] [security2:error] [pid 229246:tid 229256] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KTiBMYeh5YLVG45yMGgACVgk"]
[Tue Jul 21 07:30:38.278222 2026] [autoindex:error] [pid 229246:tid 229480] [client 20.206.105.145:54577] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:38.471475 2026] [security2:error] [pid 229246:tid 229401] [client 20.220.225.223:45383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9KTiBMYeh5YLVG45yMKAAAAi0"]
[Tue Jul 21 07:30:38.558978 2026] [security2:error] [pid 229246:tid 229451] [client 175.45.70.82:63390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMLgAAAl8"]
[Tue Jul 21 07:30:38.559122 2026] [security2:error] [pid 229246:tid 229451] [client 175.45.70.82:63390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMLgAAAl8"]
[Tue Jul 21 07:30:38.566432 2026] [security2:error] [pid 229246:tid 229332] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMLwACFVU"]
[Tue Jul 21 07:30:38.566616 2026] [security2:error] [pid 229246:tid 229377] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMLwACFVU"]
[Tue Jul 21 07:30:38.726136 2026] [autoindex:error] [pid 229246:tid 229447] [client 20.206.105.145:54577] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:38.731853 2026] [security2:error] [pid 229246:tid 229477] [client 20.206.105.145:54577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/pucci.php"] [unique_id "al9KTiBMYeh5YLVG45yMQwAAAnk"]
[Tue Jul 21 07:30:38.816441 2026] [security2:error] [pid 229246:tid 229385] [client 154.192.233.199:59536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMSQAAAh0"]
[Tue Jul 21 07:30:38.816592 2026] [security2:error] [pid 229246:tid 229385] [client 154.192.233.199:59536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTiBMYeh5YLVG45yMSQAAAh0"]
[Tue Jul 21 07:30:38.847620 2026] [security2:error] [pid 229246:tid 229416] [client 20.151.10.161:50930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/qterm.php"] [unique_id "al9KTiBMYeh5YLVG45yMTgAAAjw"]
[Tue Jul 21 07:30:38.985947 2026] [security2:error] [pid 229246:tid 229474] [client 134.122.44.174:62438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autoq.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9KTiBMYeh5YLVG45yMXQAAAnY"]
[Tue Jul 21 07:30:39.058900 2026] [security2:error] [pid 229246:tid 229278] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTyBMYeh5YLVG45yMYwACbx8"]
[Tue Jul 21 07:30:39.059123 2026] [security2:error] [pid 229246:tid 229467] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTyBMYeh5YLVG45yMYwACbx8"]
[Tue Jul 21 07:30:39.068281 2026] [security2:error] [pid 229246:tid 229476] [client 172.245.102.42:60859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KTiBMYeh5YLVG45yMUwAAAng"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:39.101843 2026] [security2:error] [pid 229246:tid 229464] [client 173.24.185.52:53096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KTyBMYeh5YLVG45yMZAAAAmw"]
[Tue Jul 21 07:30:39.101970 2026] [security2:error] [pid 229246:tid 229464] [client 173.24.185.52:53096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KTyBMYeh5YLVG45yMZAAAAmw"]
[Tue Jul 21 07:30:39.122891 2026] [security2:error] [pid 229246:tid 229262] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KTyBMYeh5YLVG45yMZQACMQ8"]
[Tue Jul 21 07:30:39.290186 2026] [security2:error] [pid 229246:tid 229264] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp.php"] [unique_id "al9KTyBMYeh5YLVG45yMbwACfhE"]
[Tue Jul 21 07:30:39.329794 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:50918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/blurbs.php"] [unique_id "al9KTyBMYeh5YLVG45yMcgAAAnk"]
[Tue Jul 21 07:30:39.391878 2026] [security2:error] [pid 229246:tid 229376] [client 103.174.34.15:56049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTyBMYeh5YLVG45yMdQAAAhQ"]
[Tue Jul 21 07:30:39.392061 2026] [security2:error] [pid 229246:tid 229376] [client 103.174.34.15:56049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTyBMYeh5YLVG45yMdQAAAhQ"]
[Tue Jul 21 07:30:39.400586 2026] [security2:error] [pid 229246:tid 229435] [client 85.204.70.92:45746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.frsadvocacia.net"] [uri "/wp-login.php"] [unique_id "al9KTyBMYeh5YLVG45yMdgAAAk8"]
[Tue Jul 21 07:30:39.468473 2026] [security2:error] [pid 229246:tid 229260] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/new.php"] [unique_id "al9KTyBMYeh5YLVG45yMeAACJg0"]
[Tue Jul 21 07:30:39.545978 2026] [security2:error] [pid 229246:tid 229495] [client 134.122.44.174:63160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.44.122.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autoq.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KTyBMYeh5YLVG45yMfwAAAos"]
[Tue Jul 21 07:30:39.636266 2026] [security2:error] [pid 229246:tid 229315] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/class-t.api.php"] [unique_id "al9KTyBMYeh5YLVG45yMggACSUQ"]
[Tue Jul 21 07:30:39.806908 2026] [security2:error] [pid 229246:tid 229324] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/plugins.php"] [unique_id "al9KTyBMYeh5YLVG45yMhwACMk0"]
[Tue Jul 21 07:30:39.976755 2026] [security2:error] [pid 229246:tid 229307] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/jp.php"] [unique_id "al9KTyBMYeh5YLVG45yMiwACcDw"]
[Tue Jul 21 07:30:40.065215 2026] [security2:error] [pid 229246:tid 229417] [client 20.104.96.117:59810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/for.php"] [unique_id "al9KUCBMYeh5YLVG45yMjwAAAj0"]
[Tue Jul 21 07:30:40.085829 2026] [autoindex:error] [pid 229246:tid 229465] [client 20.206.105.145:54532] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:40.119529 2026] [autoindex:error] [pid 229246:tid 229384] [client 20.206.105.145:54532] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:40.145661 2026] [security2:error] [pid 229246:tid 229248] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/error.php"] [unique_id "al9KUCBMYeh5YLVG45yMlAACRQE"]
[Tue Jul 21 07:30:40.151958 2026] [security2:error] [pid 229246:tid 229466] [client 20.206.105.145:54532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-temp.php"] [unique_id "al9KUCBMYeh5YLVG45yMlQAAAm4"]
[Tue Jul 21 07:30:40.190582 2026] [security2:error] [pid 229246:tid 229411] [client 45.8.17.134:45359] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/dist/vendor/about.php"] [unique_id "al9KUCBMYeh5YLVG45yMlgAAAjc"]
[Tue Jul 21 07:30:40.212679 2026] [security2:error] [pid 229246:tid 229405] [client 20.151.10.161:57359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/v543.php"] [unique_id "al9KUCBMYeh5YLVG45yMlwAAAjE"]
[Tue Jul 21 07:30:40.260536 2026] [security2:error] [pid 229246:tid 229439] [client 20.220.225.223:19672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KUCBMYeh5YLVG45yMngAAAlM"]
[Tue Jul 21 07:30:40.334303 2026] [security2:error] [pid 229246:tid 229360] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/classwithtostring.php"] [unique_id "al9KUCBMYeh5YLVG45yMogACV3E"]
[Tue Jul 21 07:30:40.513906 2026] [security2:error] [pid 229246:tid 229261] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/bless.php"] [unique_id "al9KUCBMYeh5YLVG45yMqAACjA4"]
[Tue Jul 21 07:30:40.606362 2026] [security2:error] [pid 229246:tid 229491] [client 20.220.225.223:45403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/inso.php"] [unique_id "al9KUCBMYeh5YLVG45yMrAAAAoc"]
[Tue Jul 21 07:30:40.609322 2026] [autoindex:error] [pid 229246:tid 229477] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:40.655561 2026] [security2:error] [pid 229246:tid 229435] [client 134.122.44.174:63470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.44.122.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autoq.com.br"] [uri "/wp-login.php"] [unique_id "al9KUCBMYeh5YLVG45yMrQAAAk8"]
[Tue Jul 21 07:30:40.682422 2026] [security2:error] [pid 229246:tid 229356] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/storage/index.php"] [unique_id "al9KUCBMYeh5YLVG45yMrgACjW0"]
[Tue Jul 21 07:30:40.849079 2026] [security2:error] [pid 229246:tid 229266] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/g.php"] [unique_id "al9KUCBMYeh5YLVG45yMugACRhM"]
[Tue Jul 21 07:30:41.456101 2026] [security2:error] [pid 229246:tid 229451] [client 20.220.225.223:19319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KUSBMYeh5YLVG45yMywAAAl8"]
[Tue Jul 21 07:30:41.507787 2026] [security2:error] [pid 229246:tid 229257] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/nf.php"] [unique_id "al9KUSBMYeh5YLVG45yMzAACawo"]
[Tue Jul 21 07:30:41.666747 2026] [security2:error] [pid 229246:tid 229490] [client 45.251.232.145:60920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KUSBMYeh5YLVG45yM0wAAAoY"]
[Tue Jul 21 07:30:41.666888 2026] [security2:error] [pid 229246:tid 229490] [client 45.251.232.145:60920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KUSBMYeh5YLVG45yM0wAAAoY"]
[Tue Jul 21 07:30:41.679349 2026] [security2:error] [pid 229246:tid 229376] [client 152.59.154.239:58083] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KUSBMYeh5YLVG45yM1AAAAhQ"]
[Tue Jul 21 07:30:41.679477 2026] [security2:error] [pid 229246:tid 229376] [client 152.59.154.239:58083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KUSBMYeh5YLVG45yM1AAAAhQ"]
[Tue Jul 21 07:30:41.780513 2026] [security2:error] [pid 229246:tid 229393] [client 62.102.148.164:34404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KUSBMYeh5YLVG45yM3QAAAiU"]
[Tue Jul 21 07:30:41.780606 2026] [security2:error] [pid 229246:tid 229393] [client 62.102.148.164:34404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KUSBMYeh5YLVG45yM3QAAAiU"]
[Tue Jul 21 07:30:41.905692 2026] [security2:error] [pid 229246:tid 229413] [client 85.204.70.92:45748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.frsadvocacia.net"] [uri "/wp-login.php"] [unique_id "al9KUSBMYeh5YLVG45yM5AAAAjk"]
[Tue Jul 21 07:30:41.923064 2026] [autoindex:error] [pid 229246:tid 229497] [client 20.206.105.145:54529] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:42.046472 2026] [security2:error] [pid 229246:tid 229320] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xda.php"] [unique_id "al9KUiBMYeh5YLVG45yM6QACgUk"]
[Tue Jul 21 07:30:42.069560 2026] [security2:error] [pid 229246:tid 229380] [client 20.104.96.117:59804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/ssla.php"] [unique_id "al9KUiBMYeh5YLVG45yM6gAAAhg"]
[Tue Jul 21 07:30:42.087780 2026] [security2:error] [pid 229246:tid 229389] [client 45.8.17.60:32259] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/footnotes/"] [unique_id "al9KUiBMYeh5YLVG45yM7AAAAiE"]
[Tue Jul 21 07:30:42.169633 2026] [autoindex:error] [pid 229246:tid 229498] [client 85.204.70.92:60474] AH01276: Cannot serve directory /home3/frsadv16/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:42.250266 2026] [security2:error] [pid 229246:tid 229290] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/shell.php"] [unique_id "al9KUiBMYeh5YLVG45yM7wACdis"]
[Tue Jul 21 07:30:42.316380 2026] [security2:error] [pid 229246:tid 229480] [client 20.151.10.161:51264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/w3lls.php"] [unique_id "al9KUiBMYeh5YLVG45yM8AAAAnw"]
[Tue Jul 21 07:30:42.440612 2026] [security2:error] [pid 229246:tid 229253] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/3.php"] [unique_id "al9KUiBMYeh5YLVG45yM9wACbQY"]
[Tue Jul 21 07:30:42.546192 2026] [security2:error] [pid 229246:tid 229476] [client 20.206.105.145:54529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/xmu.php"] [unique_id "al9KUiBMYeh5YLVG45yM-gAAAng"]
[Tue Jul 21 07:30:42.609778 2026] [security2:error] [pid 229246:tid 229283] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/mds.php"] [unique_id "al9KUiBMYeh5YLVG45yM_wACWiQ"]
[Tue Jul 21 07:30:42.792865 2026] [security2:error] [pid 229246:tid 229332] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/archive.php"] [unique_id "al9KUiBMYeh5YLVG45yNBQACaVU"]
[Tue Jul 21 07:30:42.888980 2026] [security2:error] [pid 229246:tid 229439] [client 45.8.17.132:33985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/pullquote/"] [unique_id "al9KUiBMYeh5YLVG45yNCwAAAlM"]
[Tue Jul 21 07:30:42.975104 2026] [security2:error] [pid 229246:tid 229363] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/amax.php"] [unique_id "al9KUiBMYeh5YLVG45yNFAACY3Q"]
[Tue Jul 21 07:30:43.147848 2026] [security2:error] [pid 229246:tid 229286] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/moon.php"] [unique_id "al9KUyBMYeh5YLVG45yNFwACgSc"]
[Tue Jul 21 07:30:43.317894 2026] [security2:error] [pid 229246:tid 229258] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KUyBMYeh5YLVG45yNHAACiQs"]
[Tue Jul 21 07:30:43.318044 2026] [security2:error] [pid 229246:tid 229493] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KUyBMYeh5YLVG45yNHAACiQs"]
[Tue Jul 21 07:30:43.324621 2026] [security2:error] [pid 229246:tid 229372] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ws83.php"] [unique_id "al9KUyBMYeh5YLVG45yNHQACTX0"]
[Tue Jul 21 07:30:43.426466 2026] [security2:error] [pid 229246:tid 229429] [client 173.252.95.12:34718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KUyBMYeh5YLVG45yNGgAAAkk"]
[Tue Jul 21 07:30:43.464564 2026] [security2:error] [pid 229246:tid 229481] [client 74.7.241.192:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.hunteron.pedido-online.net"] [uri "/index.php"] [unique_id "al9KUiBMYeh5YLVG45yNCgAAAn0"]
[Tue Jul 21 07:30:43.466320 2026] [security2:error] [pid 229246:tid 229424] [client 74.7.241.192:33772] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.hunteron.pedido-online.net"] [uri "/robots.txt"] [unique_id "al9KUiBMYeh5YLVG45yNCAACRGU"]
[Tue Jul 21 07:30:43.542514 2026] [security2:error] [pid 229246:tid 229483] [client 193.36.225.57:42331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KUyBMYeh5YLVG45yNKQAAAn8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:43.544092 2026] [security2:error] [pid 229246:tid 229451] [client 20.151.10.161:57986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-ws68.php"] [unique_id "al9KUyBMYeh5YLVG45yNKgAAAl8"]
[Tue Jul 21 07:30:43.703349 2026] [security2:error] [pid 229246:tid 229478] [client 20.104.96.117:42378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hostag.com.br"] [uri "/zc-131.php"] [unique_id "al9KUyBMYeh5YLVG45yNKwAAAno"]
[Tue Jul 21 07:30:43.763176 2026] [security2:error] [pid 229246:tid 229293] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/CDX1.php"] [unique_id "al9KUyBMYeh5YLVG45yNLAACdC4"]
[Tue Jul 21 07:30:43.948934 2026] [security2:error] [pid 229246:tid 229281] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/inputs.php"] [unique_id "al9KUyBMYeh5YLVG45yNMgACVSI"]
[Tue Jul 21 07:30:44.012639 2026] [security2:error] [pid 229246:tid 229376] [client 173.252.95.31:37374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KVCBMYeh5YLVG45yNNAAAAhQ"]
[Tue Jul 21 07:30:44.099559 2026] [security2:error] [pid 229246:tid 229452] [client 45.8.17.115:37297] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/simple.php"] [unique_id "al9KVCBMYeh5YLVG45yNPAAAAmA"]
[Tue Jul 21 07:30:44.137946 2026] [security2:error] [pid 229246:tid 229337] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ms-edit.php"] [unique_id "al9KVCBMYeh5YLVG45yNPQACcFo"]
[Tue Jul 21 07:30:44.318903 2026] [security2:error] [pid 229246:tid 229315] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/simple.php"] [unique_id "al9KVCBMYeh5YLVG45yNUgACFkQ"]
[Tue Jul 21 07:30:44.359466 2026] [security2:error] [pid 229246:tid 229252] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KVCBMYeh5YLVG45yNVQACgQU"]
[Tue Jul 21 07:30:44.359598 2026] [security2:error] [pid 229246:tid 229485] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KVCBMYeh5YLVG45yNVQACgQU"]
[Tue Jul 21 07:30:44.391250 2026] [security2:error] [pid 229246:tid 229424] [client 20.220.225.223:19299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/dp.php"] [unique_id "al9KVCBMYeh5YLVG45yNWAAAAkQ"]
[Tue Jul 21 07:30:44.436509 2026] [security2:error] [pid 229246:tid 229379] [client 20.206.105.145:54568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9KVCBMYeh5YLVG45yNWwAAAhc"]
[Tue Jul 21 07:30:44.536519 2026] [security2:error] [pid 229246:tid 229350] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/404.php"] [unique_id "al9KVCBMYeh5YLVG45yNXgACWWc"]
[Tue Jul 21 07:30:44.720689 2026] [security2:error] [pid 229246:tid 229248] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/file3.php"] [unique_id "al9KVCBMYeh5YLVG45yNZQACdAE"]
[Tue Jul 21 07:30:44.888716 2026] [security2:error] [pid 229246:tid 229280] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp-mail.php"] [unique_id "al9KVCBMYeh5YLVG45yNawACgyE"]
[Tue Jul 21 07:30:45.082173 2026] [security2:error] [pid 229246:tid 229270] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/about.php"] [unique_id "al9KVSBMYeh5YLVG45yNcwACeRc"]
[Tue Jul 21 07:30:45.210053 2026] [security2:error] [pid 229246:tid 229494] [client 20.151.10.161:57987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/xyn.php"] [unique_id "al9KVSBMYeh5YLVG45yNdQAAAoo"]
[Tue Jul 21 07:30:45.220773 2026] [security2:error] [pid 229246:tid 229352] [remote 68.178.160.25:48326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fisiopelvicafloripa.com.br"] [uri "/wp-login.php"] [unique_id "al9KVSBMYeh5YLVG45yNdgACemk"]
[Tue Jul 21 07:30:45.233026 2026] [security2:error] [pid 229246:tid 229408] [client 20.206.105.145:7687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/puc.php"] [unique_id "al9KVSBMYeh5YLVG45yNdwAAAjQ"]
[Tue Jul 21 07:30:45.288298 2026] [security2:error] [pid 229246:tid 229469] [client 117.251.86.144:43300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KVSBMYeh5YLVG45yNeQAAAnE"]
[Tue Jul 21 07:30:45.288443 2026] [security2:error] [pid 229246:tid 229469] [client 117.251.86.144:43300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KVSBMYeh5YLVG45yNeQAAAnE"]
[Tue Jul 21 07:30:45.486695 2026] [security2:error] [pid 229246:tid 229474] [client 45.8.17.123:32495] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/admin.php"] [unique_id "al9KVSBMYeh5YLVG45yNgAAAAnY"]
[Tue Jul 21 07:30:45.583916 2026] [security2:error] [pid 229246:tid 229398] [client 20.151.10.161:50900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/green3.php"] [unique_id "al9KVSBMYeh5YLVG45yNiQAAAio"]
[Tue Jul 21 07:30:45.732058 2026] [security2:error] [pid 229246:tid 229434] [client 173.252.95.34:55278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KVSBMYeh5YLVG45yNiAAAAk4"]
[Tue Jul 21 07:30:45.862517 2026] [security2:error] [pid 229246:tid 229386] [client 20.52.136.55:1774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/gettest.php"] [unique_id "al9KVSBMYeh5YLVG45yNjwAAAh4"]
[Tue Jul 21 07:30:46.327898 2026] [security2:error] [pid 229246:tid 229353] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/adminfuns.php"] [unique_id "al9KViBMYeh5YLVG45yNmQACVWo"]
[Tue Jul 21 07:30:46.395874 2026] [security2:error] [pid 229246:tid 229377] [client 45.8.17.124:38957] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/dist/reusable-blocks/"] [unique_id "al9KViBMYeh5YLVG45yNmgAAAhU"]
[Tue Jul 21 07:30:46.475549 2026] [security2:error] [pid 229246:tid 229409] [client 20.206.105.145:54562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/themes.php"] [unique_id "al9KViBMYeh5YLVG45yNnQAAAjU"]
[Tue Jul 21 07:30:46.520927 2026] [security2:error] [pid 229246:tid 229257] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/php8.php"] [unique_id "al9KViBMYeh5YLVG45yNngACHQo"]
[Tue Jul 21 07:30:46.716013 2026] [security2:error] [pid 229246:tid 229335] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/info.php"] [unique_id "al9KViBMYeh5YLVG45yNpQACI1g"]
[Tue Jul 21 07:30:46.935867 2026] [security2:error] [pid 229246:tid 229311] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/edit.php"] [unique_id "al9KViBMYeh5YLVG45yNpgACVEA"]
[Tue Jul 21 07:30:46.937086 2026] [security2:error] [pid 229246:tid 229271] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KViBMYeh5YLVG45yNpwACbBg"]
[Tue Jul 21 07:30:46.937173 2026] [security2:error] [pid 229246:tid 229464] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KViBMYeh5YLVG45yNpwACbBg"]
[Tue Jul 21 07:30:47.116850 2026] [security2:error] [pid 229246:tid 229434] [client 20.151.10.161:51302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ccs.php"] [unique_id "al9KVyBMYeh5YLVG45yNsgAAAk4"]
[Tue Jul 21 07:30:47.119434 2026] [security2:error] [pid 229246:tid 229354] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/166.php"] [unique_id "al9KVyBMYeh5YLVG45yNtAACJms"]
[Tue Jul 21 07:30:47.191586 2026] [security2:error] [pid 229246:tid 229491] [client 122.186.204.214:54220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yNugAAAoc"]
[Tue Jul 21 07:30:47.191707 2026] [security2:error] [pid 229246:tid 229491] [client 122.186.204.214:54220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yNugAAAoc"]
[Tue Jul 21 07:30:47.293706 2026] [security2:error] [pid 229246:tid 229253] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/8.php"] [unique_id "al9KVyBMYeh5YLVG45yNvgACUAY"]
[Tue Jul 21 07:30:47.466984 2026] [security2:error] [pid 229246:tid 229283] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yNwQACGCQ"]
[Tue Jul 21 07:30:47.467150 2026] [security2:error] [pid 229246:tid 229380] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yNwQACGCQ"]
[Tue Jul 21 07:30:47.471024 2026] [security2:error] [pid 229246:tid 229301] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ws38.php"] [unique_id "al9KVyBMYeh5YLVG45yNwwACSzY"]
[Tue Jul 21 07:30:47.487640 2026] [security2:error] [pid 229246:tid 229496] [client 139.167.225.182:55476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yNwgAAAow"]
[Tue Jul 21 07:30:47.487775 2026] [security2:error] [pid 229246:tid 229496] [client 139.167.225.182:55476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yNwgAAAow"]
[Tue Jul 21 07:30:47.638539 2026] [security2:error] [pid 229246:tid 229396] [client 136.144.33.98:61429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KVyBMYeh5YLVG45yNywAAAig"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:47.644092 2026] [security2:error] [pid 229246:tid 229313] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/a7.php"] [unique_id "al9KVyBMYeh5YLVG45yNzQACd0I"]
[Tue Jul 21 07:30:47.763872 2026] [autoindex:error] [pid 229246:tid 229478] [client 198.235.24.248:60640] AH01276: Cannot serve directory /home4/ciclod61/bahtelecom.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:47.785134 2026] [security2:error] [pid 229246:tid 229410] [client 45.8.17.127:55993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-signin.php"] [unique_id "al9KVyBMYeh5YLVG45yN3wAAAjY"]
[Tue Jul 21 07:30:47.834978 2026] [security2:error] [pid 229246:tid 229325] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/classsmtps.php"] [unique_id "al9KVyBMYeh5YLVG45yN4AACU04"]
[Tue Jul 21 07:30:47.926795 2026] [autoindex:error] [pid 229246:tid 229428] [client 20.206.105.145:54585] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:47.935711 2026] [security2:error] [pid 229246:tid 229416] [client 20.206.105.145:54585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/8.php"] [unique_id "al9KVyBMYeh5YLVG45yN4gAAAjw"]
[Tue Jul 21 07:30:47.961421 2026] [security2:error] [pid 229246:tid 229466] [client 103.162.129.114:54669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yN5AAAAm4"]
[Tue Jul 21 07:30:47.961511 2026] [security2:error] [pid 229246:tid 229466] [client 103.162.129.114:54669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yN5AAAAm4"]
[Tue Jul 21 07:30:47.978343 2026] [security2:error] [pid 229246:tid 229493] [client 103.106.20.201:62063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yN5QAAAok"]
[Tue Jul 21 07:30:47.978438 2026] [security2:error] [pid 229246:tid 229493] [client 103.106.20.201:62063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KVyBMYeh5YLVG45yN5QAAAok"]
[Tue Jul 21 07:30:48.053664 2026] [security2:error] [pid 229246:tid 229384] [client 20.151.10.161:51295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ccc.php"] [unique_id "al9KWCBMYeh5YLVG45yN6wAAAhw"]
[Tue Jul 21 07:30:48.149754 2026] [security2:error] [pid 229246:tid 229480] [client 20.220.225.223:6813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KWCBMYeh5YLVG45yN8AAAAnw"]
[Tue Jul 21 07:30:48.272271 2026] [security2:error] [pid 229246:tid 229461] [client 59.96.220.140:56707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KWCBMYeh5YLVG45yN9QAAAmk"]
[Tue Jul 21 07:30:48.272372 2026] [security2:error] [pid 229246:tid 229461] [client 59.96.220.140:56707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KWCBMYeh5YLVG45yN9QAAAmk"]
[Tue Jul 21 07:30:48.274751 2026] [security2:error] [pid 229246:tid 229376] [client 91.217.249.195:58935] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jurencosmetics.com"] [uri "/wp-login.php"] [unique_id "al9KVyBMYeh5YLVG45yN4wAAAhQ"]
[Tue Jul 21 07:30:48.315861 2026] [security2:error] [pid 229246:tid 229337] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/rip.php"] [unique_id "al9KWCBMYeh5YLVG45yN9gACGFo"]
[Tue Jul 21 07:30:48.509658 2026] [security2:error] [pid 229246:tid 229263] [remote 74.249.245.134:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "luminabeauty.com.br"] [uri "/1.php"] [unique_id "al9KWCBMYeh5YLVG45yN-gACFRA"]
[Tue Jul 21 07:30:48.509797 2026] [security2:error] [pid 229246:tid 229263] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/1.php"] [unique_id "al9KWCBMYeh5YLVG45yN-gACFRA"]
[Tue Jul 21 07:30:48.676828 2026] [security2:error] [pid 229246:tid 229276] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/chosen.php"] [unique_id "al9KWCBMYeh5YLVG45yOAwACNx0"]
[Tue Jul 21 07:30:48.703321 2026] [security2:error] [pid 229246:tid 229478] [client 20.220.225.223:23484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KWCBMYeh5YLVG45yOBAAAAno"]
[Tue Jul 21 07:30:48.751523 2026] [security2:error] [pid 229246:tid 229362] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KWCBMYeh5YLVG45yOBQACL3M"]
[Tue Jul 21 07:30:48.751668 2026] [security2:error] [pid 229246:tid 229403] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KWCBMYeh5YLVG45yOBQACL3M"]
[Tue Jul 21 07:30:48.768870 2026] [security2:error] [pid 229246:tid 229439] [client 20.206.105.145:7694] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bastarecomecar.com.br"] [uri "/1.php"] [unique_id "al9KWCBMYeh5YLVG45yOBwAAAlM"]
[Tue Jul 21 07:30:48.768963 2026] [security2:error] [pid 229246:tid 229439] [client 20.206.105.145:7694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/1.php"] [unique_id "al9KWCBMYeh5YLVG45yOBwAAAlM"]
[Tue Jul 21 07:30:48.883446 2026] [security2:error] [pid 229246:tid 229278] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/css.php"] [unique_id "al9KWCBMYeh5YLVG45yOEQACiR8"]
[Tue Jul 21 07:30:48.981231 2026] [security2:error] [pid 229246:tid 229384] [client 20.52.136.55:1757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/tfm.php"] [unique_id "al9KWCBMYeh5YLVG45yOEwAAAhw"]
[Tue Jul 21 07:30:49.058842 2026] [security2:error] [pid 229246:tid 229327] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/php.php"] [unique_id "al9KWSBMYeh5YLVG45yOFwACW1A"]
[Tue Jul 21 07:30:49.074402 2026] [security2:error] [pid 229246:tid 229386] [client 45.8.17.122:38883] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/config.php"] [unique_id "al9KWSBMYeh5YLVG45yOGAAAAh4"]
[Tue Jul 21 07:30:49.229004 2026] [security2:error] [pid 229246:tid 229310] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/aa.php"] [unique_id "al9KWSBMYeh5YLVG45yOIQACTD8"]
[Tue Jul 21 07:30:49.229065 2026] [security2:error] [pid 229246:tid 229446] [client 109.248.148.246:33974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOIgAAAlo"]
[Tue Jul 21 07:30:49.229133 2026] [security2:error] [pid 229246:tid 229446] [client 109.248.148.246:33974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOIgAAAlo"]
[Tue Jul 21 07:30:49.312213 2026] [security2:error] [pid 229246:tid 229260] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOJgACRA0"]
[Tue Jul 21 07:30:49.312339 2026] [security2:error] [pid 229246:tid 229424] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOJgACRA0"]
[Tue Jul 21 07:30:49.317423 2026] [security2:error] [pid 229246:tid 229452] [client 175.45.70.82:63903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOJwAAAmA"]
[Tue Jul 21 07:30:49.317510 2026] [security2:error] [pid 229246:tid 229452] [client 175.45.70.82:63903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOJwAAAmA"]
[Tue Jul 21 07:30:49.427654 2026] [security2:error] [pid 229246:tid 229410] [client 154.192.233.199:58610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOKQAAAjY"]
[Tue Jul 21 07:30:49.427799 2026] [security2:error] [pid 229246:tid 229410] [client 154.192.233.199:58610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOKQAAAjY"]
[Tue Jul 21 07:30:49.431674 2026] [security2:error] [pid 229246:tid 229315] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/bolt.php"] [unique_id "al9KWSBMYeh5YLVG45yOKgACd0Q"]
[Tue Jul 21 07:30:49.474834 2026] [security2:error] [pid 229246:tid 229477] [client 20.220.225.223:19650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/old.php"] [unique_id "al9KWSBMYeh5YLVG45yOKwAAAnk"]
[Tue Jul 21 07:30:49.614598 2026] [security2:error] [pid 229246:tid 229252] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/x.php"] [unique_id "al9KWSBMYeh5YLVG45yOLQACNwU"]
[Tue Jul 21 07:30:49.617827 2026] [security2:error] [pid 229246:tid 229482] [client 91.92.41.115:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.diegocarvalho1781571778941.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9KWSBMYeh5YLVG45yOLgAAAn4"]
[Tue Jul 21 07:30:49.631060 2026] [security2:error] [pid 229246:tid 229307] [remote 42.200.84.61:56390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9KWSBMYeh5YLVG45yOMwACTTw"]
[Tue Jul 21 07:30:49.631625 2026] [security2:error] [pid 229246:tid 229463] [client 173.24.185.52:53560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yONAAAAms"]
[Tue Jul 21 07:30:49.631693 2026] [security2:error] [pid 229246:tid 229463] [client 173.24.185.52:53560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yONAAAAms"]
[Tue Jul 21 07:30:49.674847 2026] [security2:error] [pid 229246:tid 229461] [client 136.144.42.175:39797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/wp-login.php"] [unique_id "al9KWSBMYeh5YLVG45yONQAAAmk"]
[Tue Jul 21 07:30:49.697270 2026] [security2:error] [pid 229246:tid 229485] [client 213.152.162.104:45736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yONwAAAoE"]
[Tue Jul 21 07:30:49.697391 2026] [security2:error] [pid 229246:tid 229485] [client 213.152.162.104:45736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yONwAAAoE"]
[Tue Jul 21 07:30:49.825480 2026] [security2:error] [pid 229246:tid 229324] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/jga.php"] [unique_id "al9KWSBMYeh5YLVG45yOPQACkE0"]
[Tue Jul 21 07:30:49.838820 2026] [security2:error] [pid 229246:tid 229280] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOPgACcCE"]
[Tue Jul 21 07:30:49.838927 2026] [security2:error] [pid 229246:tid 229468] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOPgACcCE"]
[Tue Jul 21 07:30:49.864590 2026] [proxy:error] [pid 229246:tid 229447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:30:49.864670 2026] [proxy_http:error] [pid 229246:tid 229447] [client 91.92.41.115:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:30:49.865395 2026] [proxy:error] [pid 229246:tid 229447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:30:49.865438 2026] [proxy_http:error] [pid 229246:tid 229447] [client 91.92.41.115:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:30:49.997689 2026] [security2:error] [pid 229246:tid 229436] [client 62.102.148.164:38912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOQQAAAlA"]
[Tue Jul 21 07:30:49.997786 2026] [security2:error] [pid 229246:tid 229436] [client 62.102.148.164:38912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9KWSBMYeh5YLVG45yOQQAAAlA"]
[Tue Jul 21 07:30:50.045292 2026] [security2:error] [pid 229246:tid 229465] [client 20.206.105.145:7699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/100.php"] [unique_id "al9KWiBMYeh5YLVG45yORQAAAm0"]
[Tue Jul 21 07:30:50.103326 2026] [security2:error] [pid 229246:tid 229441] [client 103.174.34.15:56542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWiBMYeh5YLVG45yORwAAAlU"]
[Tue Jul 21 07:30:50.103677 2026] [security2:error] [pid 229246:tid 229441] [client 103.174.34.15:56542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KWiBMYeh5YLVG45yORwAAAlU"]
[Tue Jul 21 07:30:50.308383 2026] [security2:error] [pid 229246:tid 229490] [client 20.151.10.161:50886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/get.php"] [unique_id "al9KWiBMYeh5YLVG45yOSgAAAoY"]
[Tue Jul 21 07:30:50.553852 2026] [security2:error] [pid 229246:tid 229333] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/k.php"] [unique_id "al9KWiBMYeh5YLVG45yOUwACT1Y"]
[Tue Jul 21 07:30:50.583057 2026] [security2:error] [pid 229246:tid 229481] [client 45.8.17.124:24447] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/freeform/"] [unique_id "al9KWiBMYeh5YLVG45yOVQAAAn0"]
[Tue Jul 21 07:30:50.672469 2026] [security2:error] [pid 229246:tid 229492] [client 20.206.105.145:7458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/about.php"] [unique_id "al9KWiBMYeh5YLVG45yOWgAAAog"]
[Tue Jul 21 07:30:50.726191 2026] [security2:error] [pid 229246:tid 229353] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/vx.php"] [unique_id "al9KWiBMYeh5YLVG45yOXAACNGo"]
[Tue Jul 21 07:30:50.749680 2026] [access_compat:error] [pid 229246:tid 229421] [client 162.241.63.68:59418] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:30:51.007920 2026] [security2:error] [pid 229246:tid 229453] [client 20.206.105.145:7755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/about.php"] [unique_id "al9KWyBMYeh5YLVG45yOYgAAAmE"]
[Tue Jul 21 07:30:51.045313 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.105.145:7702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/admin.php"] [unique_id "al9KWyBMYeh5YLVG45yOYwAAAms"]
[Tue Jul 21 07:30:51.267156 2026] [security2:error] [pid 229246:tid 229440] [client 136.144.33.108:39551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KWyBMYeh5YLVG45yOaAAAAlQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:51.271668 2026] [security2:error] [pid 229246:tid 229417] [client 20.151.10.161:58001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/images.php"] [unique_id "al9KWyBMYeh5YLVG45yOaQAAAj0"]
[Tue Jul 21 07:30:51.356837 2026] [security2:error] [pid 229246:tid 229388] [client 20.206.105.145:7745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/admin.php"] [unique_id "al9KWyBMYeh5YLVG45yOagAAAiA"]
[Tue Jul 21 07:30:51.527530 2026] [security2:error] [pid 229246:tid 229476] [client 20.206.105.145:54552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/edit.php"] [unique_id "al9KWyBMYeh5YLVG45yObgAAAng"]
[Tue Jul 21 07:30:51.545150 2026] [security2:error] [pid 229246:tid 229398] [client 20.220.225.223:19309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/ms-new.php"] [unique_id "al9KWyBMYeh5YLVG45yObwAAAio"]
[Tue Jul 21 07:30:51.913454 2026] [security2:error] [pid 229246:tid 229379] [client 20.206.105.145:54559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9KWyBMYeh5YLVG45yOfAAAAhc"]
[Tue Jul 21 07:30:52.006157 2026] [security2:error] [pid 229246:tid 229467] [client 45.8.17.135:27361] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/maintenance/"] [unique_id "al9KXCBMYeh5YLVG45yOgQAAAm8"]
[Tue Jul 21 07:30:52.056000 2026] [security2:error] [pid 229246:tid 229396] [client 20.220.225.223:8123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KXCBMYeh5YLVG45yOggAAAig"]
[Tue Jul 21 07:30:52.130740 2026] [security2:error] [pid 229246:tid 229434] [client 45.251.232.145:61440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KXCBMYeh5YLVG45yOhQAAAk4"]
[Tue Jul 21 07:30:52.130879 2026] [security2:error] [pid 229246:tid 229434] [client 45.251.232.145:61440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KXCBMYeh5YLVG45yOhQAAAk4"]
[Tue Jul 21 07:30:52.136275 2026] [security2:error] [pid 229246:tid 229435] [client 20.151.10.161:57395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/alls.php"] [unique_id "al9KXCBMYeh5YLVG45yOhgAAAk8"]
[Tue Jul 21 07:30:52.138054 2026] [security2:error] [pid 229246:tid 229357] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ws77.php"] [unique_id "al9KXCBMYeh5YLVG45yOhwACfW4"]
[Tue Jul 21 07:30:52.206538 2026] [security2:error] [pid 229246:tid 229470] [client 20.206.105.145:54581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/f6.php"] [unique_id "al9KXCBMYeh5YLVG45yOiQAAAnI"]
[Tue Jul 21 07:30:52.306223 2026] [security2:error] [pid 229246:tid 229301] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/2.php"] [unique_id "al9KXCBMYeh5YLVG45yOjgACQzY"]
[Tue Jul 21 07:30:52.385110 2026] [security2:error] [pid 229246:tid 229494] [client 20.220.225.223:46135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wpx.php"] [unique_id "al9KXCBMYeh5YLVG45yOkgAAAoo"]
[Tue Jul 21 07:30:52.496720 2026] [core:alert] [pid 229246:tid 229500] [client 57.141.18.102:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:30:52.504803 2026] [security2:error] [pid 229246:tid 229502] [client 20.206.105.145:54586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/inputs.php"] [unique_id "al9KXCBMYeh5YLVG45yOlwAAApI"]
[Tue Jul 21 07:30:52.519998 2026] [security2:error] [pid 229246:tid 229363] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/asd.php"] [unique_id "al9KXCBMYeh5YLVG45yOmAACW3Q"]
[Tue Jul 21 07:30:52.572855 2026] [security2:error] [pid 229246:tid 229466] [client 20.206.105.145:7762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/inputs.php"] [unique_id "al9KXCBMYeh5YLVG45yOmwAAAm4"]
[Tue Jul 21 07:30:52.687146 2026] [security2:error] [pid 229246:tid 229292] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/default.php"] [unique_id "al9KXCBMYeh5YLVG45yOpQACXy0"]
[Tue Jul 21 07:30:52.729712 2026] [security2:error] [pid 229246:tid 229495] [client 20.206.105.145:54531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/av.php"] [unique_id "al9KXCBMYeh5YLVG45yOpgAAAos"]
[Tue Jul 21 07:30:52.876333 2026] [security2:error] [pid 229246:tid 229273] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/gettest.php"] [unique_id "al9KXCBMYeh5YLVG45yOqQACbxo"]
[Tue Jul 21 07:30:52.894344 2026] [security2:error] [pid 229246:tid 229396] [client 20.206.105.145:7797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/classwithtostring.php"] [unique_id "al9KXCBMYeh5YLVG45yOqgAAAig"]
[Tue Jul 21 07:30:53.024010 2026] [security2:error] [pid 229246:tid 229435] [client 20.151.10.161:57358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/yyu.php"] [unique_id "al9KXSBMYeh5YLVG45yOrQAAAk8"]
[Tue Jul 21 07:30:53.032853 2026] [security2:error] [pid 229246:tid 229318] [remote 68.178.165.65:33048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9KXSBMYeh5YLVG45yOrwACbEc"]
[Tue Jul 21 07:30:53.041576 2026] [security2:error] [pid 229246:tid 229293] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/tfm.php"] [unique_id "al9KXSBMYeh5YLVG45yOsAACVy4"]
[Tue Jul 21 07:30:53.093372 2026] [security2:error] [pid 229246:tid 229477] [client 45.8.17.144:58847] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/module.php"] [unique_id "al9KXSBMYeh5YLVG45yOsgAAAnk"]
[Tue Jul 21 07:30:53.208908 2026] [security2:error] [pid 229246:tid 229325] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ws81.php"] [unique_id "al9KXSBMYeh5YLVG45yOtwACfk4"]
[Tue Jul 21 07:30:53.442011 2026] [security2:error] [pid 229246:tid 229386] [client 20.52.136.55:1780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/ws81.php"] [unique_id "al9KXSBMYeh5YLVG45yOugAAAh4"]
[Tue Jul 21 07:30:53.671965 2026] [security2:error] [pid 229246:tid 229502] [client 20.151.10.161:51301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/by.php"] [unique_id "al9KXSBMYeh5YLVG45yOvwAAApI"]
[Tue Jul 21 07:30:53.928444 2026] [security2:error] [pid 229246:tid 229337] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KXSBMYeh5YLVG45yOxQACbVo"]
[Tue Jul 21 07:30:53.928624 2026] [security2:error] [pid 229246:tid 229465] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KXSBMYeh5YLVG45yOxQACbVo"]
[Tue Jul 21 07:30:54.099298 2026] [security2:error] [pid 229246:tid 229379] [client 82.102.28.107:38242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yOygAAAhc"]
[Tue Jul 21 07:30:54.099377 2026] [security2:error] [pid 229246:tid 229379] [client 82.102.28.107:38242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yOygAAAhc"]
[Tue Jul 21 07:30:54.194865 2026] [security2:error] [pid 229246:tid 229288] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/222.php"] [unique_id "al9KXiBMYeh5YLVG45yOzAACMik"]
[Tue Jul 21 07:30:54.249213 2026] [security2:error] [pid 229246:tid 229449] [client 20.151.10.161:57354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/FAQ.php"] [unique_id "al9KXiBMYeh5YLVG45yOzwAAAl0"]
[Tue Jul 21 07:30:54.307361 2026] [security2:error] [pid 229246:tid 229467] [client 20.220.225.223:8125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/dp.php"] [unique_id "al9KXiBMYeh5YLVG45yO0gAAAm8"]
[Tue Jul 21 07:30:54.333956 2026] [security2:error] [pid 229246:tid 229474] [client 20.206.105.145:7746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9KXiBMYeh5YLVG45yO1AAAAnY"]
[Tue Jul 21 07:30:54.369825 2026] [security2:error] [pid 229246:tid 229289] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/t.php"] [unique_id "al9KXiBMYeh5YLVG45yO1QACfSo"]
[Tue Jul 21 07:30:54.531703 2026] [security2:error] [pid 229246:tid 229434] [client 213.152.162.104:60128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yO1gAAAk4"]
[Tue Jul 21 07:30:54.531797 2026] [security2:error] [pid 229246:tid 229434] [client 213.152.162.104:60128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yO1gAAAk4"]
[Tue Jul 21 07:30:54.539949 2026] [security2:error] [pid 229246:tid 229362] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/a.php"] [unique_id "al9KXiBMYeh5YLVG45yO1wACNHM"]
[Tue Jul 21 07:30:54.579730 2026] [security2:error] [pid 229246:tid 229385] [client 45.8.17.48:37991] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Requests/chosen.php"] [unique_id "al9KXiBMYeh5YLVG45yO3AAAAh0"]
[Tue Jul 21 07:30:54.928313 2026] [security2:error] [pid 229246:tid 229331] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yO4wACilQ"]
[Tue Jul 21 07:30:54.928457 2026] [security2:error] [pid 229246:tid 229494] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yO4wACilQ"]
[Tue Jul 21 07:30:55.204268 2026] [security2:error] [pid 229246:tid 229436] [client 20.206.105.145:7685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-blog.php"] [unique_id "al9KXyBMYeh5YLVG45yO7wAAAlA"]
[Tue Jul 21 07:30:55.211169 2026] [security2:error] [pid 229246:tid 229418] [client 117.217.38.194:51053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yOxgAAAj4"]
[Tue Jul 21 07:30:55.211294 2026] [security2:error] [pid 229246:tid 229418] [client 117.217.38.194:51053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KXiBMYeh5YLVG45yOxgAAAj4"]
[Tue Jul 21 07:30:55.229655 2026] [security2:error] [pid 229246:tid 229259] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/a1.php"] [unique_id "al9KXyBMYeh5YLVG45yO8AACRQw"]
[Tue Jul 21 07:30:55.326162 2026] [security2:error] [pid 229246:tid 229414] [client 20.220.225.223:23485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KXyBMYeh5YLVG45yO9AAAAjo"]
[Tue Jul 21 07:30:55.352865 2026] [security2:error] [pid 229246:tid 229410] [client 59.96.220.140:57159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KXyBMYeh5YLVG45yO9gAAAjY"]
[Tue Jul 21 07:30:55.352996 2026] [security2:error] [pid 229246:tid 229410] [client 59.96.220.140:57159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KXyBMYeh5YLVG45yO9gAAAjY"]
[Tue Jul 21 07:30:55.395931 2026] [security2:error] [pid 229246:tid 229307] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/w.php"] [unique_id "al9KXyBMYeh5YLVG45yO9wACjTw"]
[Tue Jul 21 07:30:55.455229 2026] [security2:error] [pid 229246:tid 229379] [client 20.220.225.223:52341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/ms-new.php"] [unique_id "al9KXyBMYeh5YLVG45yO-AAAAhc"]
[Tue Jul 21 07:30:55.596669 2026] [security2:error] [pid 229246:tid 229324] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp-good.php"] [unique_id "al9KXyBMYeh5YLVG45yPAQACT00"]
[Tue Jul 21 07:30:55.688112 2026] [security2:error] [pid 229246:tid 229470] [client 45.8.17.64:56279] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/admin.php"] [unique_id "al9KXyBMYeh5YLVG45yPBQAAAnI"]
[Tue Jul 21 07:30:55.717950 2026] [security2:error] [pid 229246:tid 229483] [client 20.151.10.161:51326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/coffexium.php"] [unique_id "al9KXyBMYeh5YLVG45yPBgAAAn8"]
[Tue Jul 21 07:30:55.764438 2026] [security2:error] [pid 229246:tid 229343] [remote 74.249.245.134:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "luminabeauty.com.br"] [uri "/.info.php"] [unique_id "al9KXyBMYeh5YLVG45yPCAACKGA"]
[Tue Jul 21 07:30:55.967026 2026] [security2:error] [pid 229246:tid 229269] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/item.php"] [unique_id "al9KXyBMYeh5YLVG45yPDQACiRY"]
[Tue Jul 21 07:30:56.060513 2026] [security2:error] [pid 229246:tid 229398] [client 117.251.86.144:40062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KYCBMYeh5YLVG45yPDwAAAio"]
[Tue Jul 21 07:30:56.060660 2026] [security2:error] [pid 229246:tid 229398] [client 117.251.86.144:40062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KYCBMYeh5YLVG45yPDwAAAio"]
[Tue Jul 21 07:30:56.133542 2026] [security2:error] [pid 229246:tid 229333] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/albin.php"] [unique_id "al9KYCBMYeh5YLVG45yPEQACcFY"]
[Tue Jul 21 07:30:56.308841 2026] [security2:error] [pid 229246:tid 229266] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/alfa.php"] [unique_id "al9KYCBMYeh5YLVG45yPFgACPhM"]
[Tue Jul 21 07:30:56.493691 2026] [security2:error] [pid 229246:tid 229353] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9KYCBMYeh5YLVG45yPGwACS2o"]
[Tue Jul 21 07:30:56.543686 2026] [security2:error] [pid 229246:tid 229497] [client 20.220.225.223:6816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/old.php"] [unique_id "al9KYCBMYeh5YLVG45yPHAAAAo0"]
[Tue Jul 21 07:30:56.666179 2026] [security2:error] [pid 229246:tid 229312] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/av.php"] [unique_id "al9KYCBMYeh5YLVG45yPIQACXUE"]
[Tue Jul 21 07:30:56.682987 2026] [security2:error] [pid 229246:tid 229397] [client 20.220.225.223:23453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/dp.php"] [unique_id "al9KYCBMYeh5YLVG45yPIgAAAik"]
[Tue Jul 21 07:30:56.788875 2026] [security2:error] [pid 229246:tid 229452] [client 45.8.17.128:59305] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/block-patterns/chosen.php"] [unique_id "al9KYCBMYeh5YLVG45yPIwAAAmA"]
[Tue Jul 21 07:30:56.816090 2026] [autoindex:error] [pid 229246:tid 229435] [client 20.206.105.145:7799] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:30:56.824882 2026] [security2:error] [pid 229246:tid 229464] [client 20.206.105.145:7799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9KYCBMYeh5YLVG45yPJQAAAmw"]
[Tue Jul 21 07:30:56.848390 2026] [security2:error] [pid 229246:tid 229370] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/gg.php"] [unique_id "al9KYCBMYeh5YLVG45yPJgACTns"]
[Tue Jul 21 07:30:57.001443 2026] [security2:error] [pid 229246:tid 229428] [client 20.52.136.55:1788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/222.php"] [unique_id "al9KYSBMYeh5YLVG45yPLQAAAkg"]
[Tue Jul 21 07:30:57.020318 2026] [security2:error] [pid 229246:tid 229267] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/sql.php"] [unique_id "al9KYSBMYeh5YLVG45yPLgACHhQ"]
[Tue Jul 21 07:30:57.151002 2026] [security2:error] [pid 229246:tid 229495] [client 193.36.225.58:51417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KXyBMYeh5YLVG45yPDgAAAos"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:30:57.203872 2026] [security2:error] [pid 229246:tid 229251] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/up.php"] [unique_id "al9KYSBMYeh5YLVG45yPNAACPQQ"]
[Tue Jul 21 07:30:57.371211 2026] [security2:error] [pid 229246:tid 229335] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/66.php"] [unique_id "al9KYSBMYeh5YLVG45yPNgACklg"]
[Tue Jul 21 07:30:57.413727 2026] [security2:error] [pid 229246:tid 229321] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPNwACUEo"]
[Tue Jul 21 07:30:57.413916 2026] [security2:error] [pid 229246:tid 229436] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPNwACUEo"]
[Tue Jul 21 07:30:57.487376 2026] [security2:error] [pid 229246:tid 229424] [client 139.167.225.182:56180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPPgAAAkQ"]
[Tue Jul 21 07:30:57.487485 2026] [security2:error] [pid 229246:tid 229424] [client 139.167.225.182:56180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPPgAAAkQ"]
[Tue Jul 21 07:30:57.759881 2026] [security2:error] [pid 229246:tid 229461] [client 20.220.225.223:23477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/old.php"] [unique_id "al9KYSBMYeh5YLVG45yPSAAAAmk"]
[Tue Jul 21 07:30:57.813442 2026] [security2:error] [pid 229246:tid 229467] [client 20.206.105.145:7707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/adminfuns.php"] [unique_id "al9KYSBMYeh5YLVG45yPSQAAAm8"]
[Tue Jul 21 07:30:57.847657 2026] [security2:error] [pid 229246:tid 229355] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/666.php"] [unique_id "al9KYSBMYeh5YLVG45yPSwACYGw"]
[Tue Jul 21 07:30:57.887296 2026] [security2:error] [pid 229246:tid 229481] [client 45.8.17.141:42589] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/ws.php"] [unique_id "al9KYSBMYeh5YLVG45yPTAAAAn0"]
[Tue Jul 21 07:30:57.961657 2026] [security2:error] [pid 229246:tid 229380] [client 122.186.204.214:54703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPTQAAAhg"]
[Tue Jul 21 07:30:57.961829 2026] [security2:error] [pid 229246:tid 229380] [client 122.186.204.214:54703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPTQAAAhg"]
[Tue Jul 21 07:30:57.977067 2026] [security2:error] [pid 229246:tid 229256] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPTgACbAk"]
[Tue Jul 21 07:30:57.977241 2026] [security2:error] [pid 229246:tid 229464] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KYSBMYeh5YLVG45yPTgACbAk"]
[Tue Jul 21 07:30:58.016016 2026] [security2:error] [pid 229246:tid 229320] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/byp.php"] [unique_id "al9KYiBMYeh5YLVG45yPVAACMUk"]
[Tue Jul 21 07:30:58.181497 2026] [security2:error] [pid 229246:tid 229301] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/date.php"] [unique_id "al9KYiBMYeh5YLVG45yPVgACHjY"]
[Tue Jul 21 07:30:58.203764 2026] [security2:error] [pid 229246:tid 229482] [client 20.220.225.223:6787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/ms-new.php"] [unique_id "al9KYiBMYeh5YLVG45yPWgAAAn4"]
[Tue Jul 21 07:30:58.209780 2026] [security2:error] [pid 229246:tid 229489] [client 20.151.10.161:51293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/red.php"] [unique_id "al9KYiBMYeh5YLVG45yPWwAAAoU"]
[Tue Jul 21 07:30:58.358374 2026] [security2:error] [pid 229246:tid 229285] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/pomo.php"] [unique_id "al9KYiBMYeh5YLVG45yPXQACkiY"]
[Tue Jul 21 07:30:58.538895 2026] [security2:error] [pid 229246:tid 229292] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/test1.php"] [unique_id "al9KYiBMYeh5YLVG45yPYgACPi0"]
[Tue Jul 21 07:30:58.622298 2026] [security2:error] [pid 229246:tid 229496] [client 20.206.105.145:7476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/goods.php"] [unique_id "al9KYiBMYeh5YLVG45yPZgAAAow"]
[Tue Jul 21 07:30:58.778718 2026] [security2:error] [pid 229246:tid 229483] [client 103.106.20.201:62630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KYiBMYeh5YLVG45yPaQAAAn8"]
[Tue Jul 21 07:30:58.778843 2026] [security2:error] [pid 229246:tid 229483] [client 103.106.20.201:62630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KYiBMYeh5YLVG45yPaQAAAn8"]
[Tue Jul 21 07:30:58.973413 2026] [security2:error] [pid 229246:tid 229318] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/fw.php"] [unique_id "al9KYiBMYeh5YLVG45yPbgACbEc"]
[Tue Jul 21 07:30:59.067186 2026] [security2:error] [pid 229246:tid 229405] [client 20.220.225.223:52300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/track.php"] [unique_id "al9KYyBMYeh5YLVG45yPcwAAAjE"]
[Tue Jul 21 07:30:59.087226 2026] [security2:error] [pid 229246:tid 229470] [client 45.8.17.57:54441] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/plugins/wp-load.php"] [unique_id "al9KYyBMYeh5YLVG45yPdgAAAnI"]
[Tue Jul 21 07:30:59.124851 2026] [security2:error] [pid 229246:tid 229424] [client 103.162.129.114:55134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPewAAAkQ"]
[Tue Jul 21 07:30:59.124955 2026] [security2:error] [pid 229246:tid 229424] [client 103.162.129.114:55134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPewAAAkQ"]
[Tue Jul 21 07:30:59.140653 2026] [security2:error] [pid 229246:tid 229325] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/fm.php"] [unique_id "al9KYyBMYeh5YLVG45yPfAACX04"]
[Tue Jul 21 07:30:59.250733 2026] [security2:error] [pid 229246:tid 229482] [client 20.206.105.145:54530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ms-edit.php"] [unique_id "al9KYyBMYeh5YLVG45yPfQAAAn4"]
[Tue Jul 21 07:30:59.329665 2026] [security2:error] [pid 229246:tid 229281] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ini.php"] [unique_id "al9KYyBMYeh5YLVG45yPfgACPSI"]
[Tue Jul 21 07:30:59.455424 2026] [security2:error] [pid 229246:tid 229286] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPgwACiyc"]
[Tue Jul 21 07:30:59.455565 2026] [security2:error] [pid 229246:tid 229495] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPgwACiyc"]
[Tue Jul 21 07:30:59.499205 2026] [security2:error] [pid 229246:tid 229369] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPhgACa3o"]
[Tue Jul 21 07:30:59.499369 2026] [security2:error] [pid 229246:tid 229463] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPhgACa3o"]
[Tue Jul 21 07:30:59.519080 2026] [security2:error] [pid 229246:tid 229263] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/themes.php"] [unique_id "al9KYyBMYeh5YLVG45yPiQACHBA"]
[Tue Jul 21 07:30:59.690191 2026] [security2:error] [pid 229246:tid 229348] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/dropdown.php"] [unique_id "al9KYyBMYeh5YLVG45yPkgACkGU"]
[Tue Jul 21 07:30:59.856849 2026] [security2:error] [pid 229246:tid 229278] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp-links.php"] [unique_id "al9KYyBMYeh5YLVG45yPmQACdR8"]
[Tue Jul 21 07:30:59.872639 2026] [security2:error] [pid 229246:tid 229477] [client 20.220.225.223:32396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/ms-new.php"] [unique_id "al9KYyBMYeh5YLVG45yPmgAAAnk"]
[Tue Jul 21 07:30:59.885770 2026] [security2:error] [pid 229246:tid 229447] [client 45.8.17.125:43559] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "al9KYyBMYeh5YLVG45yPmwAAAls"]
[Tue Jul 21 07:30:59.890443 2026] [security2:error] [pid 229246:tid 229379] [client 62.102.148.164:40312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPnAAAAhc"]
[Tue Jul 21 07:30:59.890540 2026] [security2:error] [pid 229246:tid 229379] [client 62.102.148.164:40312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KYyBMYeh5YLVG45yPnAAAAhc"]
[Tue Jul 21 07:30:59.997095 2026] [security2:error] [pid 229246:tid 229390] [client 20.220.225.223:19288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/track.php"] [unique_id "al9KYyBMYeh5YLVG45yPnQAAAiI"]
[Tue Jul 21 07:31:00.068278 2026] [security2:error] [pid 229246:tid 229327] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPoAACKVA"]
[Tue Jul 21 07:31:00.068424 2026] [security2:error] [pid 229246:tid 229397] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPoAACKVA"]
[Tue Jul 21 07:31:00.117281 2026] [security2:error] [pid 229246:tid 229449] [client 20.220.225.223:8082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/track.php"] [unique_id "al9KZCBMYeh5YLVG45yPogAAAl0"]
[Tue Jul 21 07:31:00.120170 2026] [security2:error] [pid 229246:tid 229391] [client 154.192.233.199:59690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPpAAAAiM"]
[Tue Jul 21 07:31:00.120305 2026] [security2:error] [pid 229246:tid 229391] [client 154.192.233.199:59690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPpAAAAiM"]
[Tue Jul 21 07:31:00.139913 2026] [security2:error] [pid 229246:tid 229480] [client 175.45.70.82:64415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPpwAAAnw"]
[Tue Jul 21 07:31:00.140040 2026] [security2:error] [pid 229246:tid 229480] [client 175.45.70.82:64415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPpwAAAnw"]
[Tue Jul 21 07:31:00.276298 2026] [security2:error] [pid 229246:tid 229382] [client 173.24.185.52:54023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPqAAAAho"]
[Tue Jul 21 07:31:00.276423 2026] [security2:error] [pid 229246:tid 229382] [client 173.24.185.52:54023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPqAAAAho"]
[Tue Jul 21 07:31:00.461968 2026] [security2:error] [pid 229246:tid 229310] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmrlpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPrQACaz8"]
[Tue Jul 21 07:31:00.493097 2026] [security2:error] [pid 229246:tid 229259] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPrgACfgw"]
[Tue Jul 21 07:31:00.493230 2026] [security2:error] [pid 229246:tid 229482] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPrgACfgw"]
[Tue Jul 21 07:31:00.632170 2026] [security2:error] [pid 229246:tid 229307] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/htaccess.php"] [unique_id "al9KZCBMYeh5YLVG45yPtAACkDw"]
[Tue Jul 21 07:31:00.714405 2026] [security2:error] [pid 229246:tid 229439] [client 103.174.34.15:57034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPtgAAAlM"]
[Tue Jul 21 07:31:00.714508 2026] [security2:error] [pid 229246:tid 229439] [client 103.174.34.15:57034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZCBMYeh5YLVG45yPtgAAAlM"]
[Tue Jul 21 07:31:00.774159 2026] [security2:error] [pid 229246:tid 229403] [client 20.206.105.145:7287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/222.php"] [unique_id "al9KZCBMYeh5YLVG45yPtwAAAi8"]
[Tue Jul 21 07:31:00.805597 2026] [security2:error] [pid 229246:tid 229350] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/readme.php"] [unique_id "al9KZCBMYeh5YLVG45yPuAACJmc"]
[Tue Jul 21 07:31:01.004968 2026] [security2:error] [pid 229246:tid 229280] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/403.php"] [unique_id "al9KZSBMYeh5YLVG45yPvgACWyE"]
[Tue Jul 21 07:31:01.034426 2026] [autoindex:error] [pid 229246:tid 229379] [client 64.69.216.78:37460] AH01276: Cannot serve directory /home2/onfiel33/kotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:01.140106 2026] [security2:error] [pid 229246:tid 229497] [client 193.36.225.55:46609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KZSBMYeh5YLVG45yPwwAAAo0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:01.182776 2026] [security2:error] [pid 229246:tid 229408] [client 45.8.17.116:38145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/simple.php"] [unique_id "al9KZSBMYeh5YLVG45yPxQAAAjQ"]
[Tue Jul 21 07:31:01.192543 2026] [security2:error] [pid 229246:tid 229248] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/max.php"] [unique_id "al9KZSBMYeh5YLVG45yPxgACXQE"]
[Tue Jul 21 07:31:01.211464 2026] [security2:error] [pid 229246:tid 229391] [client 20.206.105.145:7728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9KZSBMYeh5YLVG45yPxwAAAiM"]
[Tue Jul 21 07:31:01.289743 2026] [proxy:error] [pid 229246:tid 229424] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:01.289834 2026] [proxy_http:error] [pid 229246:tid 229424] [client 20.151.10.161:50911] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:01.290321 2026] [proxy:error] [pid 229246:tid 229424] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:01.290362 2026] [proxy_http:error] [pid 229246:tid 229424] [client 20.151.10.161:50911] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:01.368771 2026] [security2:error] [pid 229246:tid 229469] [client 82.102.28.107:44240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KZSBMYeh5YLVG45yPzgAAAnE"]
[Tue Jul 21 07:31:01.368881 2026] [security2:error] [pid 229246:tid 229469] [client 82.102.28.107:44240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KZSBMYeh5YLVG45yPzgAAAnE"]
[Tue Jul 21 07:31:01.509608 2026] [security2:error] [pid 229246:tid 229463] [client 20.220.225.223:62863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/berlin.php"] [unique_id "al9KZSBMYeh5YLVG45yP0wAAAms"]
[Tue Jul 21 07:31:01.548606 2026] [security2:error] [pid 229246:tid 229470] [client 173.252.95.5:62992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KZSBMYeh5YLVG45yP0AAAAnI"]
[Tue Jul 21 07:31:01.592990 2026] [autoindex:error] [pid 229246:tid 229384] [client 64.69.216.78:37514] AH01276: Cannot serve directory /home2/onfiel33/kotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:01.780130 2026] [security2:error] [pid 229246:tid 229346] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/m.php"] [unique_id "al9KZSBMYeh5YLVG45yP2gACPmM"]
[Tue Jul 21 07:31:01.980253 2026] [security2:error] [pid 229246:tid 229252] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/click.php"] [unique_id "al9KZSBMYeh5YLVG45yP4AACfQU"]
[Tue Jul 21 07:31:01.986744 2026] [security2:error] [pid 229246:tid 229376] [client 173.252.95.63:36664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KZSBMYeh5YLVG45yP4QAAAhQ"]
[Tue Jul 21 07:31:02.013131 2026] [autoindex:error] [pid 229246:tid 229435] [client 20.206.105.145:7379] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:02.043729 2026] [security2:error] [pid 229246:tid 229477] [client 20.206.105.145:7379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9KZiBMYeh5YLVG45yP5AAAAnk"]
[Tue Jul 21 07:31:02.152606 2026] [security2:error] [pid 229246:tid 229370] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/lv.php"] [unique_id "al9KZiBMYeh5YLVG45yP5gACIns"]
[Tue Jul 21 07:31:02.162718 2026] [security2:error] [pid 229246:tid 229379] [client 62.102.148.164:52088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KZiBMYeh5YLVG45yP5wAAAhc"]
[Tue Jul 21 07:31:02.162800 2026] [security2:error] [pid 229246:tid 229379] [client 62.102.148.164:52088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KZiBMYeh5YLVG45yP5wAAAhc"]
[Tue Jul 21 07:31:02.220155 2026] [security2:error] [pid 229246:tid 229397] [client 20.220.225.223:8078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/2352356666.php"] [unique_id "al9KZiBMYeh5YLVG45yP6wAAAik"]
[Tue Jul 21 07:31:02.329918 2026] [security2:error] [pid 229246:tid 229298] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/cong.php"] [unique_id "al9KZiBMYeh5YLVG45yP8AACdTM"]
[Tue Jul 21 07:31:02.393180 2026] [autoindex:error] [pid 229246:tid 229451] [client 20.206.105.145:7455] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:02.425934 2026] [autoindex:error] [pid 229246:tid 229386] [client 20.206.105.145:7455] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:02.515083 2026] [security2:error] [pid 229246:tid 229251] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/brand.php"] [unique_id "al9KZiBMYeh5YLVG45yP9wACSQQ"]
[Tue Jul 21 07:31:02.559373 2026] [security2:error] [pid 229246:tid 229361] [remote 152.53.111.131:36534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cezaretto.com.br"] [uri "/wp-login.php"] [unique_id "al9KZiBMYeh5YLVG45yP-gACiHI"]
[Tue Jul 21 07:31:02.598502 2026] [security2:error] [pid 229246:tid 229440] [client 45.251.232.145:61958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZiBMYeh5YLVG45yP-wAAAlQ"]
[Tue Jul 21 07:31:02.598632 2026] [security2:error] [pid 229246:tid 229440] [client 45.251.232.145:61958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZiBMYeh5YLVG45yP-wAAAlQ"]
[Tue Jul 21 07:31:02.599677 2026] [rewrite:warn] [pid 229246:tid 229328] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:02.646574 2026] [security2:error] [pid 229246:tid 229384] [client 20.220.225.223:45984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/berlin.php"] [unique_id "al9KZiBMYeh5YLVG45yP_QAAAhw"]
[Tue Jul 21 07:31:02.698821 2026] [security2:error] [pid 229246:tid 229321] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/atomlib.php"] [unique_id "al9KZiBMYeh5YLVG45yP_wACfEo"]
[Tue Jul 21 07:31:02.723092 2026] [security2:error] [pid 229246:tid 229388] [client 20.206.105.145:7455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/raw.php"] [unique_id "al9KZiBMYeh5YLVG45yQAgAAAiA"]
[Tue Jul 21 07:31:02.732563 2026] [security2:error] [pid 229246:tid 229254] [remote 173.252.87.39:37268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9KZiBMYeh5YLVG45yQBAACawc"]
[Tue Jul 21 07:31:02.771024 2026] [security2:error] [pid 229246:tid 229334] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naldoinvest.com.br"] [uri "/wp-admin/install.php"] [unique_id "al9KZiBMYeh5YLVG45yQBQACaVc"]
[Tue Jul 21 07:31:02.873901 2026] [security2:error] [pid 229246:tid 229439] [client 213.152.162.104:53042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KZiBMYeh5YLVG45yQBwAAAlM"]
[Tue Jul 21 07:31:02.874013 2026] [security2:error] [pid 229246:tid 229439] [client 213.152.162.104:53042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KZiBMYeh5YLVG45yQBwAAAlM"]
[Tue Jul 21 07:31:02.881806 2026] [security2:error] [pid 229246:tid 229271] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/0x.php"] [unique_id "al9KZiBMYeh5YLVG45yQCAACFRg"]
[Tue Jul 21 07:31:03.011572 2026] [security2:error] [pid 229246:tid 229424] [client 20.10.88.227:1860] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rioclaroimovel.com.br"] [uri "/index.php"] [unique_id "al9KZiBMYeh5YLVG45yP-AAAAkQ"]
[Tue Jul 21 07:31:03.052363 2026] [security2:error] [pid 229246:tid 229253] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/buy.php"] [unique_id "al9KZyBMYeh5YLVG45yQDAACQQY"]
[Tue Jul 21 07:31:03.218258 2026] [security2:error] [pid 229246:tid 229284] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/sx.php"] [unique_id "al9KZyBMYeh5YLVG45yQEQACKSU"]
[Tue Jul 21 07:31:03.269603 2026] [security2:error] [pid 229246:tid 229285] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naldoinvest.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9KZyBMYeh5YLVG45yQFQACTiY"]
[Tue Jul 21 07:31:03.394174 2026] [security2:error] [pid 229246:tid 229290] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/article.php"] [unique_id "al9KZyBMYeh5YLVG45yQGAACXys"]
[Tue Jul 21 07:31:03.568434 2026] [rewrite:warn] [pid 229246:tid 229332] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:03.569066 2026] [rewrite:warn] [pid 229246:tid 229318] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:03.573923 2026] [rewrite:warn] [pid 229246:tid 229341] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:03.573952 2026] [rewrite:warn] [pid 229246:tid 229273] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:03.593306 2026] [security2:error] [pid 229246:tid 229500] [client 45.8.17.131:57183] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/link/"] [unique_id "al9KZyBMYeh5YLVG45yQJwAAApA"]
[Tue Jul 21 07:31:03.599520 2026] [security2:error] [pid 229246:tid 229439] [client 20.206.105.145:7770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/abcd.php"] [unique_id "al9KZyBMYeh5YLVG45yQKAAAAlM"]
[Tue Jul 21 07:31:03.738041 2026] [rewrite:warn] [pid 229246:tid 229293] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:03.742761 2026] [rewrite:warn] [pid 229246:tid 229258] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:03.836217 2026] [security2:error] [pid 229246:tid 229338] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/bootstrap.php"] [unique_id "al9KZyBMYeh5YLVG45yQMQACL1s"]
[Tue Jul 21 07:31:03.971557 2026] [security2:error] [pid 229246:tid 229467] [client 117.217.38.194:51500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZyBMYeh5YLVG45yQNQAAAm8"]
[Tue Jul 21 07:31:03.971693 2026] [security2:error] [pid 229246:tid 229467] [client 117.217.38.194:51500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KZyBMYeh5YLVG45yQNQAAAm8"]
[Tue Jul 21 07:31:04.016943 2026] [security2:error] [pid 229246:tid 229369] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/config-backup.php"] [unique_id "al9KaCBMYeh5YLVG45yQOQACTno"]
[Tue Jul 21 07:31:04.046321 2026] [security2:error] [pid 229246:tid 229391] [client 20.52.136.55:1733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/t.php"] [unique_id "al9KaCBMYeh5YLVG45yQOgAAAiM"]
[Tue Jul 21 07:31:04.186712 2026] [security2:error] [pid 229246:tid 229288] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/goods.php"] [unique_id "al9KaCBMYeh5YLVG45yQQAACKik"]
[Tue Jul 21 07:31:04.371246 2026] [security2:error] [pid 229246:tid 229372] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/init.php"] [unique_id "al9KaCBMYeh5YLVG45yQSAACa30"]
[Tue Jul 21 07:31:04.464112 2026] [autoindex:error] [pid 229246:tid 229362] [remote 100.50.152.193:0] AH01276: Cannot serve directory /home1/bastar15/lacorsini.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:04.521166 2026] [security2:error] [pid 229246:tid 229278] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KaCBMYeh5YLVG45yQSwACah8"]
[Tue Jul 21 07:31:04.521304 2026] [security2:error] [pid 229246:tid 229462] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KaCBMYeh5YLVG45yQSwACah8"]
[Tue Jul 21 07:31:04.695974 2026] [autoindex:error] [pid 229246:tid 229464] [client 3.219.86.171:47030] AH01276: Cannot serve directory /home1/bastar15/lacorsini.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:04.750179 2026] [authz_core:error] [pid 229246:tid 229310] [remote 74.249.245.134:0] AH01630: client denied by server configuration: /home1/deesmo24/luminabeauty.com.br/php.ini
[Tue Jul 21 07:31:04.843238 2026] [security2:error] [pid 229246:tid 229397] [client 20.206.105.145:7176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/a1.php"] [unique_id "al9KaCBMYeh5YLVG45yQWgAAAik"]
[Tue Jul 21 07:31:04.895783 2026] [rewrite:warn] [pid 229246:tid 229259] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:31:04.937999 2026] [security2:error] [pid 229246:tid 229296] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/settings.php"] [unique_id "al9KaCBMYeh5YLVG45yQXAACHjE"]
[Tue Jul 21 07:31:05.107117 2026] [security2:error] [pid 229246:tid 229472] [client 20.220.225.223:8086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/pn.php"] [unique_id "al9KaSBMYeh5YLVG45yQYAAAAnQ"]
[Tue Jul 21 07:31:05.145935 2026] [security2:error] [pid 229246:tid 229307] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/g.php"] [unique_id "al9KaSBMYeh5YLVG45yQYQACNTw"]
[Tue Jul 21 07:31:05.205364 2026] [security2:error] [pid 229246:tid 229492] [client 20.151.10.161:50934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9KaSBMYeh5YLVG45yQZAAAAog"]
[Tue Jul 21 07:31:05.312631 2026] [security2:error] [pid 229246:tid 229343] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/403.php"] [unique_id "al9KaSBMYeh5YLVG45yQbAACXmA"]
[Tue Jul 21 07:31:05.503185 2026] [security2:error] [pid 229246:tid 229367] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/api.php"] [unique_id "al9KaSBMYeh5YLVG45yQcAACf3g"]
[Tue Jul 21 07:31:05.539219 2026] [security2:error] [pid 229246:tid 229289] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KaSBMYeh5YLVG45yQcQACUCo"]
[Tue Jul 21 07:31:05.539342 2026] [security2:error] [pid 229246:tid 229436] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KaSBMYeh5YLVG45yQcQACUCo"]
[Tue Jul 21 07:31:05.593344 2026] [security2:error] [pid 229246:tid 229401] [client 45.8.17.48:29211] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/config.php"] [unique_id "al9KaSBMYeh5YLVG45yQdQAAAi0"]
[Tue Jul 21 07:31:05.903801 2026] [security2:error] [pid 229246:tid 229420] [client 152.59.154.239:59008] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KaSBMYeh5YLVG45yQfgAAAkA"]
[Tue Jul 21 07:31:05.906778 2026] [security2:error] [pid 229246:tid 229420] [client 152.59.154.239:59008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KaSBMYeh5YLVG45yQfgAAAkA"]
[Tue Jul 21 07:31:06.134243 2026] [security2:error] [pid 229246:tid 229492] [client 62.102.148.164:40320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KaiBMYeh5YLVG45yQiwAAAog"]
[Tue Jul 21 07:31:06.134350 2026] [security2:error] [pid 229246:tid 229492] [client 62.102.148.164:40320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KaiBMYeh5YLVG45yQiwAAAog"]
[Tue Jul 21 07:31:06.583810 2026] [security2:error] [pid 229246:tid 229410] [client 45.8.17.148:49807] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "al9KaiBMYeh5YLVG45yQkgAAAjY"]
[Tue Jul 21 07:31:06.708361 2026] [security2:error] [pid 229246:tid 229378] [client 20.206.105.145:7473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9KaiBMYeh5YLVG45yQmQAAAhY"]
[Tue Jul 21 07:31:06.821224 2026] [security2:error] [pid 229246:tid 229451] [client 117.251.86.144:47608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KaiBMYeh5YLVG45yQmwAAAl8"]
[Tue Jul 21 07:31:06.821434 2026] [security2:error] [pid 229246:tid 229451] [client 117.251.86.144:47608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KaiBMYeh5YLVG45yQmwAAAl8"]
[Tue Jul 21 07:31:06.924368 2026] [security2:error] [pid 229246:tid 229428] [client 59.96.220.140:57617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KaiBMYeh5YLVG45yQnwAAAkg"]
[Tue Jul 21 07:31:06.924455 2026] [security2:error] [pid 229246:tid 229428] [client 59.96.220.140:57617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KaiBMYeh5YLVG45yQnwAAAkg"]
[Tue Jul 21 07:31:07.308099 2026] [security2:error] [pid 229246:tid 229361] [remote 117.0.21.154:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9KayBMYeh5YLVG45yQogACTnI"]
[Tue Jul 21 07:31:07.505261 2026] [security2:error] [pid 229246:tid 229388] [client 62.102.148.164:40322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KayBMYeh5YLVG45yQrQAAAiA"]
[Tue Jul 21 07:31:07.505363 2026] [security2:error] [pid 229246:tid 229388] [client 62.102.148.164:40322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KayBMYeh5YLVG45yQrQAAAiA"]
[Tue Jul 21 07:31:07.745198 2026] [security2:error] [pid 229246:tid 229478] [client 20.220.225.223:52190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/track.php"] [unique_id "al9KayBMYeh5YLVG45yQtgAAAno"]
[Tue Jul 21 07:31:07.746013 2026] [security2:error] [pid 229246:tid 229410] [client 20.220.225.223:48529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/billur.php"] [unique_id "al9KayBMYeh5YLVG45yQuAAAAjY"]
[Tue Jul 21 07:31:07.904486 2026] [security2:error] [pid 229246:tid 229427] [client 45.8.17.49:41563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/codemirror/"] [unique_id "al9KayBMYeh5YLVG45yQvgAAAkc"]
[Tue Jul 21 07:31:07.929721 2026] [security2:error] [pid 229246:tid 229335] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KayBMYeh5YLVG45yQvwACLFg"]
[Tue Jul 21 07:31:07.929872 2026] [security2:error] [pid 229246:tid 229400] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KayBMYeh5YLVG45yQvwACLFg"]
[Tue Jul 21 07:31:08.229544 2026] [security2:error] [pid 229246:tid 229384] [client 139.167.225.182:56810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQxwAAAhw"]
[Tue Jul 21 07:31:08.229661 2026] [security2:error] [pid 229246:tid 229384] [client 139.167.225.182:56810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQxwAAAhw"]
[Tue Jul 21 07:31:08.454838 2026] [security2:error] [pid 229246:tid 229290] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ0gACbSs"]
[Tue Jul 21 07:31:08.454997 2026] [security2:error] [pid 229246:tid 229465] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ0gACbSs"]
[Tue Jul 21 07:31:08.626528 2026] [security2:error] [pid 229246:tid 229397] [client 122.186.204.214:55184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ3AAAAik"]
[Tue Jul 21 07:31:08.626656 2026] [security2:error] [pid 229246:tid 229397] [client 122.186.204.214:55184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ3AAAAik"]
[Tue Jul 21 07:31:08.647431 2026] [security2:error] [pid 229246:tid 229390] [client 37.140.223.68:46503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KbCBMYeh5YLVG45yQ3gAAAiI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:08.758076 2026] [security2:error] [pid 229246:tid 229428] [client 103.162.129.114:55553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ4gAAAkg"]
[Tue Jul 21 07:31:08.758224 2026] [security2:error] [pid 229246:tid 229428] [client 103.162.129.114:55553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ4gAAAkg"]
[Tue Jul 21 07:31:08.766664 2026] [security2:error] [pid 229246:tid 229396] [client 20.197.192.193:9412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KbCBMYeh5YLVG45yQ5AAAAig"]
[Tue Jul 21 07:31:09.015252 2026] [security2:error] [pid 229246:tid 229398] [client 45.8.17.125:60823] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/ab.php"] [unique_id "al9KbSBMYeh5YLVG45yQ6wAAAio"]
[Tue Jul 21 07:31:09.031958 2026] [security2:error] [pid 229246:tid 229414] [client 20.206.105.145:7453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9KbSBMYeh5YLVG45yQ7QAAAjo"]
[Tue Jul 21 07:31:09.184605 2026] [security2:error] [pid 229246:tid 229499] [client 20.197.192.193:9410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KbSBMYeh5YLVG45yQ8QAAAo8"]
[Tue Jul 21 07:31:09.544797 2026] [security2:error] [pid 229246:tid 229416] [client 20.220.225.223:63820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/2352356666.php"] [unique_id "al9KbSBMYeh5YLVG45yQ_QAAAjw"]
[Tue Jul 21 07:31:09.544841 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.192.193:9433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wander.php"] [unique_id "al9KbSBMYeh5YLVG45yQ_gAAAik"]
[Tue Jul 21 07:31:09.544966 2026] [security2:error] [pid 229246:tid 229496] [client 103.106.20.201:63197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbSBMYeh5YLVG45yQ_wAAAow"]
[Tue Jul 21 07:31:09.545785 2026] [security2:error] [pid 229246:tid 229496] [client 103.106.20.201:63197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbSBMYeh5YLVG45yQ_wAAAow"]
[Tue Jul 21 07:31:09.979013 2026] [security2:error] [pid 229246:tid 229272] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KbSBMYeh5YLVG45yRCQACNRk"]
[Tue Jul 21 07:31:09.979251 2026] [security2:error] [pid 229246:tid 229409] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KbSBMYeh5YLVG45yRCQACNRk"]
[Tue Jul 21 07:31:10.192243 2026] [security2:error] [pid 229246:tid 229414] [client 45.8.17.119:43567] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/comments-pagination-numbers/"] [unique_id "al9KbiBMYeh5YLVG45yRDQAAAjo"]
[Tue Jul 21 07:31:10.268793 2026] [proxy:error] [pid 229246:tid 229486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:10.268889 2026] [proxy_http:error] [pid 229246:tid 229486] [client 20.151.10.161:50910] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:10.269587 2026] [proxy:error] [pid 229246:tid 229486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:10.269648 2026] [proxy_http:error] [pid 229246:tid 229486] [client 20.151.10.161:50910] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:10.491025 2026] [security2:error] [pid 229246:tid 229502] [client 74.7.241.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealth.shop.oficialwebsite.com.br"] [uri "/index.php"] [unique_id "al9KbCBMYeh5YLVG45yQ2gAAApI"]
[Tue Jul 21 07:31:10.491908 2026] [security2:error] [pid 229246:tid 229431] [client 74.7.241.130:42282] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealth.shop.oficialwebsite.com.br"] [uri "/robots.txt"] [unique_id "al9KbCBMYeh5YLVG45yQ1wACSyQ"]
[Tue Jul 21 07:31:10.520661 2026] [security2:error] [pid 229246:tid 229495] [client 20.197.192.193:8332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/jga.php"] [unique_id "al9KbiBMYeh5YLVG45yRGQAAAos"]
[Tue Jul 21 07:31:10.759529 2026] [security2:error] [pid 229246:tid 229416] [client 109.248.148.246:59756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRGwAAAjw"]
[Tue Jul 21 07:31:10.759620 2026] [security2:error] [pid 229246:tid 229416] [client 109.248.148.246:59756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRGwAAAjw"]
[Tue Jul 21 07:31:10.810696 2026] [security2:error] [pid 229246:tid 229386] [client 154.192.233.199:58876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRHAAAAh4"]
[Tue Jul 21 07:31:10.810794 2026] [security2:error] [pid 229246:tid 229386] [client 154.192.233.199:58876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRHAAAAh4"]
[Tue Jul 21 07:31:10.816265 2026] [security2:error] [pid 229246:tid 229278] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRHQACgR8"]
[Tue Jul 21 07:31:10.816446 2026] [security2:error] [pid 229246:tid 229485] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRHQACgR8"]
[Tue Jul 21 07:31:10.833542 2026] [security2:error] [pid 229246:tid 229403] [client 173.24.185.52:54484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRHwAAAi8"]
[Tue Jul 21 07:31:10.833628 2026] [security2:error] [pid 229246:tid 229403] [client 173.24.185.52:54484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRHwAAAi8"]
[Tue Jul 21 07:31:10.855078 2026] [security2:error] [pid 229246:tid 229482] [client 175.45.70.82:64944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRIAAAAn4"]
[Tue Jul 21 07:31:10.855192 2026] [security2:error] [pid 229246:tid 229482] [client 175.45.70.82:64944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbiBMYeh5YLVG45yRIAAAAn4"]
[Tue Jul 21 07:31:10.879184 2026] [security2:error] [pid 229246:tid 229273] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ5gACIxo"]
[Tue Jul 21 07:31:10.879422 2026] [security2:error] [pid 229246:tid 229391] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KbCBMYeh5YLVG45yQ5gACIxo"]
[Tue Jul 21 07:31:11.175850 2026] [security2:error] [pid 229246:tid 229500] [client 20.197.192.193:9435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/x.php"] [unique_id "al9KbyBMYeh5YLVG45yRLAAAApA"]
[Tue Jul 21 07:31:11.255604 2026] [security2:error] [pid 229246:tid 229276] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbyBMYeh5YLVG45yRMAACPR0"]
[Tue Jul 21 07:31:11.255744 2026] [security2:error] [pid 229246:tid 229417] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbyBMYeh5YLVG45yRMAACPR0"]
[Tue Jul 21 07:31:11.600834 2026] [security2:error] [pid 229246:tid 229395] [client 20.206.105.145:7436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9KbyBMYeh5YLVG45yRPAAAAic"]
[Tue Jul 21 07:31:11.622232 2026] [security2:error] [pid 229246:tid 229418] [client 103.174.34.15:57523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbyBMYeh5YLVG45yRPQAAAj4"]
[Tue Jul 21 07:31:11.622335 2026] [security2:error] [pid 229246:tid 229418] [client 103.174.34.15:57523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KbyBMYeh5YLVG45yRPQAAAj4"]
[Tue Jul 21 07:31:11.641032 2026] [security2:error] [pid 229246:tid 229380] [client 20.197.192.193:8347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9KbyBMYeh5YLVG45yRPgAAAhg"]
[Tue Jul 21 07:31:11.694749 2026] [security2:error] [pid 229246:tid 229502] [client 20.10.88.201:62592] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealth.shop"] [uri "/robots.txt"] [unique_id "al9KbyBMYeh5YLVG45yRPwAAApI"]
[Tue Jul 21 07:31:11.782842 2026] [security2:error] [pid 229246:tid 229485] [client 45.8.17.136:60311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-featured-image/"] [unique_id "al9KbyBMYeh5YLVG45yRQQAAAoE"]
[Tue Jul 21 07:31:12.139652 2026] [security2:error] [pid 229246:tid 229503] [client 20.197.192.193:8364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ee.php"] [unique_id "al9KcCBMYeh5YLVG45yRTwAAApM"]
[Tue Jul 21 07:31:12.148188 2026] [security2:error] [pid 229246:tid 229409] [client 20.151.10.161:57996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/footer.php"] [unique_id "al9KcCBMYeh5YLVG45yRUAAAAjU"]
[Tue Jul 21 07:31:12.354564 2026] [security2:error] [pid 229246:tid 229451] [client 193.36.225.72:59999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KcCBMYeh5YLVG45yRUQAAAl8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:12.365148 2026] [security2:error] [pid 229246:tid 229500] [client 20.197.192.193:8327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/blue.php"] [unique_id "al9KcCBMYeh5YLVG45yRUgAAApA"]
[Tue Jul 21 07:31:12.552499 2026] [security2:error] [pid 229246:tid 229480] [client 20.197.192.193:8343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-signup.php"] [unique_id "al9KcCBMYeh5YLVG45yRWQAAAnw"]
[Tue Jul 21 07:31:12.667532 2026] [security2:error] [pid 229246:tid 229501] [client 20.206.105.145:39257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KcCBMYeh5YLVG45yRXgAAApE"]
[Tue Jul 21 07:31:12.746170 2026] [security2:error] [pid 229246:tid 229472] [client 20.220.225.223:56483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/pn.php"] [unique_id "al9KcCBMYeh5YLVG45yRYQAAAnQ"]
[Tue Jul 21 07:31:12.887222 2026] [security2:error] [pid 229246:tid 229377] [client 45.8.17.118:21225] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/wc-logs/"] [unique_id "al9KcCBMYeh5YLVG45yRYwAAAhU"]
[Tue Jul 21 07:31:12.998540 2026] [security2:error] [pid 229246:tid 229408] [client 20.52.136.55:1585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/a.php"] [unique_id "al9KcCBMYeh5YLVG45yRaAAAAjQ"]
[Tue Jul 21 07:31:13.073900 2026] [security2:error] [pid 229246:tid 229457] [client 45.251.232.145:62484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KcSBMYeh5YLVG45yRagAAAmU"]
[Tue Jul 21 07:31:13.074017 2026] [security2:error] [pid 229246:tid 229457] [client 45.251.232.145:62484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KcSBMYeh5YLVG45yRagAAAmU"]
[Tue Jul 21 07:31:13.182733 2026] [security2:error] [pid 229246:tid 229478] [client 20.220.225.223:6121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/2352356666.php"] [unique_id "al9KcSBMYeh5YLVG45yRbgAAAno"]
[Tue Jul 21 07:31:13.461226 2026] [security2:error] [pid 229246:tid 229401] [client 82.102.28.107:58324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KcSBMYeh5YLVG45yRcwAAAi0"]
[Tue Jul 21 07:31:13.461352 2026] [security2:error] [pid 229246:tid 229401] [client 82.102.28.107:58324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KcSBMYeh5YLVG45yRcwAAAi0"]
[Tue Jul 21 07:31:13.608845 2026] [security2:error] [pid 229246:tid 229477] [client 62.102.148.164:44478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KcSBMYeh5YLVG45yReQAAAnk"]
[Tue Jul 21 07:31:13.608972 2026] [security2:error] [pid 229246:tid 229477] [client 62.102.148.164:44478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9KcSBMYeh5YLVG45yReQAAAnk"]
[Tue Jul 21 07:31:13.658525 2026] [security2:error] [pid 229246:tid 229471] [client 20.197.192.193:8382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/csa.php"] [unique_id "al9KcSBMYeh5YLVG45yRfAAAAnM"]
[Tue Jul 21 07:31:13.717230 2026] [security2:error] [pid 229246:tid 229494] [client 35.202.101.58:41926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.101.202.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9KcCBMYeh5YLVG45yRYAAAAoo"]
[Tue Jul 21 07:31:13.727784 2026] [security2:error] [pid 229246:tid 229413] [client 20.220.225.223:62883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/billur.php"] [unique_id "al9KcSBMYeh5YLVG45yRfwAAAjk"]
[Tue Jul 21 07:31:14.090281 2026] [proxy:error] [pid 229246:tid 229416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:14.090354 2026] [proxy_http:error] [pid 229246:tid 229416] [client 20.151.10.161:51294] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:14.090785 2026] [proxy:error] [pid 229246:tid 229416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:14.090810 2026] [proxy_http:error] [pid 229246:tid 229416] [client 20.151.10.161:51294] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:14.394323 2026] [security2:error] [pid 229246:tid 229383] [client 45.8.17.63:50517] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/upload.php"] [unique_id "al9KciBMYeh5YLVG45yRkQAAAhs"]
[Tue Jul 21 07:31:14.469864 2026] [security2:error] [pid 229246:tid 229424] [client 117.217.38.194:51981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KciBMYeh5YLVG45yRlAAAAkQ"]
[Tue Jul 21 07:31:14.469981 2026] [security2:error] [pid 229246:tid 229424] [client 117.217.38.194:51981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KciBMYeh5YLVG45yRlAAAAkQ"]
[Tue Jul 21 07:31:14.936877 2026] [security2:error] [pid 229246:tid 229440] [client 20.206.105.145:54567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/simple.php"] [unique_id "al9KciBMYeh5YLVG45yRoAAAAlQ"]
[Tue Jul 21 07:31:15.026115 2026] [security2:error] [pid 229246:tid 229480] [client 20.206.105.145:7482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/xxx.php"] [unique_id "al9KcyBMYeh5YLVG45yRowAAAnw"]
[Tue Jul 21 07:31:15.065475 2026] [security2:error] [pid 229246:tid 229395] [client 20.206.105.145:7765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/hypo.php"] [unique_id "al9KcyBMYeh5YLVG45yRpQAAAic"]
[Tue Jul 21 07:31:15.117096 2026] [security2:error] [pid 229246:tid 229251] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KcyBMYeh5YLVG45yRpwACOgQ"]
[Tue Jul 21 07:31:15.117246 2026] [security2:error] [pid 229246:tid 229414] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KcyBMYeh5YLVG45yRpwACOgQ"]
[Tue Jul 21 07:31:15.143768 2026] [security2:error] [pid 229246:tid 229496] [client 104.28.156.104:40169] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "carrosselbuique.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9KcyBMYeh5YLVG45yRqAAAAow"]
[Tue Jul 21 07:31:15.205499 2026] [security2:error] [pid 229246:tid 229484] [client 45.8.17.147:37803] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/maint/network/"] [unique_id "al9KcyBMYeh5YLVG45yRqwAAAoA"]
[Tue Jul 21 07:31:15.221235 2026] [security2:error] [pid 229246:tid 229378] [client 20.197.192.193:8383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/min.php"] [unique_id "al9KcyBMYeh5YLVG45yRrAAAAhY"]
[Tue Jul 21 07:31:15.230892 2026] [autoindex:error] [pid 229246:tid 229427] [client 20.206.105.145:7361] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:15.288190 2026] [security2:error] [pid 229246:tid 229382] [client 20.206.105.145:7361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/chosen.php"] [unique_id "al9KcyBMYeh5YLVG45yRsQAAAho"]
[Tue Jul 21 07:31:15.294857 2026] [security2:error] [pid 229246:tid 229489] [client 20.220.225.223:8079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wp-wpbak.php"] [unique_id "al9KcyBMYeh5YLVG45yRsgAAAoU"]
[Tue Jul 21 07:31:15.491553 2026] [security2:error] [pid 229246:tid 229391] [client 20.197.192.193:8325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/echkm.php"] [unique_id "al9KcyBMYeh5YLVG45yRtAAAAiM"]
[Tue Jul 21 07:31:15.670801 2026] [security2:error] [pid 229246:tid 229390] [client 20.220.225.223:46084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/mimpi.php"] [unique_id "al9KcyBMYeh5YLVG45yRuQAAAiI"]
[Tue Jul 21 07:31:15.784217 2026] [autoindex:error] [pid 229246:tid 229433] [client 20.206.105.145:54549] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:15.803948 2026] [security2:error] [pid 229246:tid 229483] [client 20.206.105.145:54549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file5.php"] [unique_id "al9KcyBMYeh5YLVG45yRvgAAAn8"]
[Tue Jul 21 07:31:15.897410 2026] [security2:error] [pid 229246:tid 229492] [client 62.102.148.164:34120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KcyBMYeh5YLVG45yRwQAAAog"]
[Tue Jul 21 07:31:15.897496 2026] [security2:error] [pid 229246:tid 229492] [client 62.102.148.164:34120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KcyBMYeh5YLVG45yRwQAAAog"]
[Tue Jul 21 07:31:16.039310 2026] [security2:error] [pid 229246:tid 229287] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KdCBMYeh5YLVG45yRwwACkCg"]
[Tue Jul 21 07:31:16.039439 2026] [security2:error] [pid 229246:tid 229500] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KdCBMYeh5YLVG45yRwwACkCg"]
[Tue Jul 21 07:31:16.185435 2026] [security2:error] [pid 229246:tid 229503] [client 45.8.17.146:59885] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/group/"] [unique_id "al9KdCBMYeh5YLVG45yRxwAAApM"]
[Tue Jul 21 07:31:16.240438 2026] [security2:error] [pid 229246:tid 229401] [client 20.197.192.193:9408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/mac.php"] [unique_id "al9KdCBMYeh5YLVG45yRyAAAAi0"]
[Tue Jul 21 07:31:16.272743 2026] [security2:error] [pid 229246:tid 229420] [client 104.28.156.104:40174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "carrosselbuique.com.br"] [uri "/"] [unique_id "al9KdCBMYeh5YLVG45yRygAAAkA"]
[Tue Jul 21 07:31:16.325005 2026] [security2:error] [pid 229246:tid 229458] [client 122.129.67.13:59989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9KcyBMYeh5YLVG45yRpgAAAmY"]
[Tue Jul 21 07:31:16.377438 2026] [security2:error] [pid 229246:tid 229471] [client 193.36.225.68:32809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KdCBMYeh5YLVG45yRzgAAAnM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:16.615170 2026] [security2:error] [pid 229246:tid 229488] [client 59.96.220.140:58110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KdCBMYeh5YLVG45yR1wAAAoQ"]
[Tue Jul 21 07:31:16.615278 2026] [security2:error] [pid 229246:tid 229488] [client 59.96.220.140:58110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KdCBMYeh5YLVG45yR1wAAAoQ"]
[Tue Jul 21 07:31:16.881505 2026] [proxy:error] [pid 229246:tid 229431] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:16.881597 2026] [proxy_http:error] [pid 229246:tid 229431] [client 137.184.89.104:33794] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:16.882217 2026] [proxy:error] [pid 229246:tid 229431] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:16.882245 2026] [proxy_http:error] [pid 229246:tid 229431] [client 137.184.89.104:33794] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:17.221800 2026] [security2:error] [pid 229246:tid 229424] [client 20.220.225.223:8106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/dr.php"] [unique_id "al9KdSBMYeh5YLVG45yR3wAAAkQ"]
[Tue Jul 21 07:31:17.239656 2026] [proxy:error] [pid 229246:tid 229433] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:17.239726 2026] [proxy_http:error] [pid 229246:tid 229433] [client 137.184.89.104:33810] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.lambiduspet.com.br/
[Tue Jul 21 07:31:17.240242 2026] [proxy:error] [pid 229246:tid 229433] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:17.240276 2026] [proxy_http:error] [pid 229246:tid 229433] [client 137.184.89.104:33810] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.lambiduspet.com.br/
[Tue Jul 21 07:31:17.412276 2026] [security2:error] [pid 229246:tid 229429] [client 104.28.156.104:40177] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "carrosselbuique.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9KdSBMYeh5YLVG45yR6QAAAkk"]
[Tue Jul 21 07:31:17.485108 2026] [security2:error] [pid 229246:tid 229425] [client 20.206.105.145:39241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KdSBMYeh5YLVG45yR6gAAAkU"]
[Tue Jul 21 07:31:17.493519 2026] [security2:error] [pid 229246:tid 229503] [client 45.8.17.137:59769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/"] [unique_id "al9KdSBMYeh5YLVG45yR6wAAApM"]
[Tue Jul 21 07:31:17.538560 2026] [security2:error] [pid 229246:tid 229451] [client 20.197.192.193:8351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/samll.php"] [unique_id "al9KdSBMYeh5YLVG45yR7AAAAl8"]
[Tue Jul 21 07:31:17.618944 2026] [security2:error] [pid 229246:tid 229490] [client 117.251.86.144:54020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KdSBMYeh5YLVG45yR7QAAAoY"]
[Tue Jul 21 07:31:17.619076 2026] [security2:error] [pid 229246:tid 229490] [client 117.251.86.144:54020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KdSBMYeh5YLVG45yR7QAAAoY"]
[Tue Jul 21 07:31:17.727778 2026] [security2:error] [pid 229246:tid 229436] [client 20.220.225.223:23452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/pn.php"] [unique_id "al9KdSBMYeh5YLVG45yR8gAAAlA"]
[Tue Jul 21 07:31:17.781145 2026] [security2:error] [pid 229246:tid 229471] [client 20.206.105.145:7452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file.php"] [unique_id "al9KdSBMYeh5YLVG45yR9AAAAnM"]
[Tue Jul 21 07:31:17.933379 2026] [security2:error] [pid 229246:tid 229376] [client 20.197.192.193:8324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/abcd.php"] [unique_id "al9KdSBMYeh5YLVG45yR-gAAAhQ"]
[Tue Jul 21 07:31:17.974028 2026] [proxy:error] [pid 229246:tid 229494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:17.974071 2026] [proxy_http:error] [pid 229246:tid 229494] [client 137.184.89.104:46740] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:17.974640 2026] [proxy:error] [pid 229246:tid 229494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:17.974661 2026] [proxy_http:error] [pid 229246:tid 229494] [client 137.184.89.104:46740] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:18.066675 2026] [security2:error] [pid 229246:tid 229416] [client 20.220.225.223:19300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/pn.php"] [unique_id "al9KdiBMYeh5YLVG45yR_AAAAjw"]
[Tue Jul 21 07:31:18.309270 2026] [security2:error] [pid 229246:tid 229449] [client 20.197.192.193:8368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/xyn.php"] [unique_id "al9KdiBMYeh5YLVG45ySAwAAAl0"]
[Tue Jul 21 07:31:18.402131 2026] [security2:error] [pid 229246:tid 229485] [client 20.220.225.223:46083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/dp.php"] [unique_id "al9KdiBMYeh5YLVG45ySBQAAAoE"]
[Tue Jul 21 07:31:18.466423 2026] [security2:error] [pid 229246:tid 229268] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySCgACGhU"]
[Tue Jul 21 07:31:18.466541 2026] [security2:error] [pid 229246:tid 229382] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySCgACGhU"]
[Tue Jul 21 07:31:18.483075 2026] [security2:error] [pid 229246:tid 229390] [client 45.8.17.127:21191] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/666.php"] [unique_id "al9KdiBMYeh5YLVG45ySCwAAAiI"]
[Tue Jul 21 07:31:18.507306 2026] [security2:error] [pid 229246:tid 229383] [client 20.197.192.193:8370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/byp8.php"] [unique_id "al9KdiBMYeh5YLVG45ySDAAAAhs"]
[Tue Jul 21 07:31:18.596925 2026] [security2:error] [pid 229246:tid 229422] [client 20.197.192.193:9427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/user.php"] [unique_id "al9KdiBMYeh5YLVG45ySDQAAAkI"]
[Tue Jul 21 07:31:18.720326 2026] [security2:error] [pid 229246:tid 229455] [client 139.167.225.182:57429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySEAAAAmM"]
[Tue Jul 21 07:31:18.720433 2026] [security2:error] [pid 229246:tid 229455] [client 139.167.225.182:57429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySEAAAAmM"]
[Tue Jul 21 07:31:18.728541 2026] [security2:error] [pid 229246:tid 229439] [client 20.220.225.223:52307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wp-wpbak.php"] [unique_id "al9KdiBMYeh5YLVG45ySEgAAAlM"]
[Tue Jul 21 07:31:18.758969 2026] [security2:error] [pid 229246:tid 229458] [client 152.59.154.239:59472] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySFAAAAmY"]
[Tue Jul 21 07:31:18.761227 2026] [security2:error] [pid 229246:tid 229458] [client 152.59.154.239:59472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySFAAAAmY"]
[Tue Jul 21 07:31:18.816674 2026] [core:error] [pid 229246:tid 229322] [remote 52.167.144.191:36453] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:31:18.816701 2026] [core:error] [pid 229246:tid 229322] [remote 52.167.144.191:36453] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:31:18.828682 2026] [security2:error] [pid 229246:tid 229388] [client 20.220.225.223:6831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/2x.php"] [unique_id "al9KdiBMYeh5YLVG45ySFwAAAiA"]
[Tue Jul 21 07:31:18.833886 2026] [security2:error] [pid 229246:tid 229503] [client 20.206.105.145:7711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/aa2.php"] [unique_id "al9KdiBMYeh5YLVG45ySGAAAApM"]
[Tue Jul 21 07:31:18.858230 2026] [security2:error] [pid 229246:tid 229396] [client 20.197.192.193:8322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ops.php"] [unique_id "al9KdiBMYeh5YLVG45ySGQAAAig"]
[Tue Jul 21 07:31:18.871646 2026] [security2:error] [pid 229246:tid 229437] [client 20.220.225.223:19683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9KdiBMYeh5YLVG45ySGgAAAlE"]
[Tue Jul 21 07:31:18.978788 2026] [security2:error] [pid 229246:tid 229288] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySHwACNik"]
[Tue Jul 21 07:31:18.978900 2026] [security2:error] [pid 229246:tid 229410] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KdiBMYeh5YLVG45ySHwACNik"]
[Tue Jul 21 07:31:19.181542 2026] [security2:error] [pid 229246:tid 229331] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KdyBMYeh5YLVG45ySIgAChFQ"]
[Tue Jul 21 07:31:19.195785 2026] [security2:error] [pid 229246:tid 229387] [client 20.206.105.145:39276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/x.php"] [unique_id "al9KdyBMYeh5YLVG45ySIwAAAh8"]
[Tue Jul 21 07:31:19.205276 2026] [security2:error] [pid 229246:tid 229459] [client 103.162.129.114:55988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KdyBMYeh5YLVG45ySJAAAAmc"]
[Tue Jul 21 07:31:19.205393 2026] [security2:error] [pid 229246:tid 229459] [client 103.162.129.114:55988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KdyBMYeh5YLVG45ySJAAAAmc"]
[Tue Jul 21 07:31:19.208525 2026] [security2:error] [pid 229246:tid 229327] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KdyBMYeh5YLVG45ySJQACZVA"]
[Tue Jul 21 07:31:19.229539 2026] [security2:error] [pid 229246:tid 229365] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/dp.php"] [unique_id "al9KdyBMYeh5YLVG45ySJgACXXY"]
[Tue Jul 21 07:31:19.252129 2026] [security2:error] [pid 229246:tid 229299] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/old.php"] [unique_id "al9KdyBMYeh5YLVG45ySKAACNDQ"]
[Tue Jul 21 07:31:19.269731 2026] [security2:error] [pid 229246:tid 229427] [client 20.220.225.223:52191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wp-wpbak.php"] [unique_id "al9KdyBMYeh5YLVG45ySKwAAAkc"]
[Tue Jul 21 07:31:19.271416 2026] [security2:error] [pid 229246:tid 229276] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/ms-new.php"] [unique_id "al9KdyBMYeh5YLVG45ySLAACbx0"]
[Tue Jul 21 07:31:19.284965 2026] [security2:error] [pid 229246:tid 229317] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/track.php"] [unique_id "al9KdyBMYeh5YLVG45ySLQACXkY"]
[Tue Jul 21 07:31:19.298098 2026] [security2:error] [pid 229246:tid 229259] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/2352356666.php"] [unique_id "al9KdyBMYeh5YLVG45ySLgACIgw"]
[Tue Jul 21 07:31:19.304196 2026] [security2:error] [pid 229246:tid 229383] [client 20.52.136.55:1586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/a1.php"] [unique_id "al9KdyBMYeh5YLVG45ySLwAAAhs"]
[Tue Jul 21 07:31:19.319574 2026] [security2:error] [pid 229246:tid 229296] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/pn.php"] [unique_id "al9KdyBMYeh5YLVG45ySMAACazE"]
[Tue Jul 21 07:31:19.336740 2026] [security2:error] [pid 229246:tid 229329] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wp-wpbak.php"] [unique_id "al9KdyBMYeh5YLVG45ySMwACSFI"]
[Tue Jul 21 07:31:19.347892 2026] [security2:error] [pid 229246:tid 229492] [client 122.186.204.214:55672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KdyBMYeh5YLVG45ySNgAAAog"]
[Tue Jul 21 07:31:19.347994 2026] [security2:error] [pid 229246:tid 229492] [client 122.186.204.214:55672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KdyBMYeh5YLVG45ySNgAAAog"]
[Tue Jul 21 07:31:19.352377 2026] [security2:error] [pid 229246:tid 229291] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/dr.php"] [unique_id "al9KdyBMYeh5YLVG45ySNwACRCw"]
[Tue Jul 21 07:31:19.373583 2026] [security2:error] [pid 229246:tid 229280] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/2x.php"] [unique_id "al9KdyBMYeh5YLVG45ySOQACMCE"]
[Tue Jul 21 07:31:19.388988 2026] [security2:error] [pid 229246:tid 229248] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/kq1.php"] [unique_id "al9KdyBMYeh5YLVG45ySOgACNQE"]
[Tue Jul 21 07:31:19.401578 2026] [security2:error] [pid 229246:tid 229367] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/zzz.php"] [unique_id "al9KdyBMYeh5YLVG45ySOwACQHg"]
[Tue Jul 21 07:31:19.417059 2026] [security2:error] [pid 229246:tid 229340] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wicked.php"] [unique_id "al9KdyBMYeh5YLVG45ySPAACe10"]
[Tue Jul 21 07:31:19.431287 2026] [security2:error] [pid 229246:tid 229289] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/edit.php"] [unique_id "al9KdyBMYeh5YLVG45ySPQACYyo"]
[Tue Jul 21 07:31:19.455088 2026] [security2:error] [pid 229246:tid 229345] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/kua.php"] [unique_id "al9KdyBMYeh5YLVG45ySQAACeWI"]
[Tue Jul 21 07:31:19.475191 2026] [security2:error] [pid 229246:tid 229440] [client 45.8.17.59:47361] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "al9KdyBMYeh5YLVG45ySQgAAAlQ"]
[Tue Jul 21 07:31:19.477052 2026] [security2:error] [pid 229246:tid 229350] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/ez.php"] [unique_id "al9KdyBMYeh5YLVG45ySQwACSWc"]
[Tue Jul 21 07:31:19.492637 2026] [security2:error] [pid 229246:tid 229269] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/fz.php"] [unique_id "al9KdyBMYeh5YLVG45ySRAACIxY"]
[Tue Jul 21 07:31:19.510682 2026] [security2:error] [pid 229246:tid 229346] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/la.php"] [unique_id "al9KdyBMYeh5YLVG45ySRQACJmM"]
[Tue Jul 21 07:31:19.514269 2026] [security2:error] [pid 229246:tid 229388] [client 20.206.105.145:7577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ccou.php"] [unique_id "al9KdyBMYeh5YLVG45ySRgAAAiA"]
[Tue Jul 21 07:31:19.519300 2026] [security2:error] [pid 229246:tid 229503] [client 20.197.192.193:8328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/term.php"] [unique_id "al9KdyBMYeh5YLVG45ySRwAAApM"]
[Tue Jul 21 07:31:19.529783 2026] [security2:error] [pid 229246:tid 229353] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/nhvoanpl.php"] [unique_id "al9KdyBMYeh5YLVG45ySSAACKGo"]
[Tue Jul 21 07:31:19.549763 2026] [security2:error] [pid 229246:tid 229333] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/inso.php"] [unique_id "al9KdyBMYeh5YLVG45ySSQACf1Y"]
[Tue Jul 21 07:31:19.565918 2026] [security2:error] [pid 229246:tid 229370] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wpx.php"] [unique_id "al9KdyBMYeh5YLVG45ySSgACcns"]
[Tue Jul 21 07:31:19.582234 2026] [security2:error] [pid 229246:tid 229342] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/berlin.php"] [unique_id "al9KdyBMYeh5YLVG45ySSwACUF8"]
[Tue Jul 21 07:31:19.608669 2026] [security2:error] [pid 229246:tid 229261] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/billur.php"] [unique_id "al9KdyBMYeh5YLVG45ySTAACfA4"]
[Tue Jul 21 07:31:19.631759 2026] [security2:error] [pid 229246:tid 229252] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/mimpi.php"] [unique_id "al9KdyBMYeh5YLVG45ySTgACdgU"]
[Tue Jul 21 07:31:19.646391 2026] [security2:error] [pid 229246:tid 229312] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/dp.php"] [unique_id "al9KdyBMYeh5YLVG45ySTwACOEE"]
[Tue Jul 21 07:31:19.667297 2026] [security2:error] [pid 229246:tid 229352] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/bootstrap.php"] [unique_id "al9KdyBMYeh5YLVG45ySUQACNmk"]
[Tue Jul 21 07:31:19.685417 2026] [security2:error] [pid 229246:tid 229274] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wp-editor.php"] [unique_id "al9KdyBMYeh5YLVG45ySUgACPBs"]
[Tue Jul 21 07:31:19.706868 2026] [security2:error] [pid 229246:tid 229339] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/cro.php"] [unique_id "al9KdyBMYeh5YLVG45ySUwACW1w"]
[Tue Jul 21 07:31:19.728175 2026] [security2:error] [pid 229246:tid 229298] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/cron-tab.php"] [unique_id "al9KdyBMYeh5YLVG45ySVAAChTM"]
[Tue Jul 21 07:31:19.743795 2026] [security2:error] [pid 229246:tid 229348] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/koiy.php"] [unique_id "al9KdyBMYeh5YLVG45ySVQACLGU"]
[Tue Jul 21 07:31:19.759122 2026] [security2:error] [pid 229246:tid 229267] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/hp2.php"] [unique_id "al9KdyBMYeh5YLVG45ySVgAChBQ"]
[Tue Jul 21 07:31:19.772164 2026] [security2:error] [pid 229246:tid 229282] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/hp3.php"] [unique_id "al9KdyBMYeh5YLVG45ySWAACkiM"]
[Tue Jul 21 07:31:19.787564 2026] [security2:error] [pid 229246:tid 229328] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/aa1.php"] [unique_id "al9KdyBMYeh5YLVG45ySWgACfVE"]
[Tue Jul 21 07:31:19.809854 2026] [security2:error] [pid 229246:tid 229361] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/acew67.php"] [unique_id "al9KdyBMYeh5YLVG45ySXQACXXI"]
[Tue Jul 21 07:31:19.827315 2026] [security2:error] [pid 229246:tid 229247] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/bscclapb.php"] [unique_id "al9KdyBMYeh5YLVG45ySXgACNAA"]
[Tue Jul 21 07:31:19.850281 2026] [security2:error] [pid 229246:tid 229334] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/else1.php"] [unique_id "al9KdyBMYeh5YLVG45ySYAACS1c"]
[Tue Jul 21 07:31:19.867289 2026] [security2:error] [pid 229246:tid 229308] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/tkikikoko.php"] [unique_id "al9KdyBMYeh5YLVG45ySYgACgT0"]
[Tue Jul 21 07:31:19.893937 2026] [security2:error] [pid 229246:tid 229256] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wp-Blogs.php"] [unique_id "al9KdyBMYeh5YLVG45ySYwACIgk"]
[Tue Jul 21 07:31:19.921465 2026] [security2:error] [pid 229246:tid 229311] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wp-css.php"] [unique_id "al9KdyBMYeh5YLVG45ySZQACG0A"]
[Tue Jul 21 07:31:19.946752 2026] [security2:error] [pid 229246:tid 229335] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/wp-explorer.php"] [unique_id "al9KdyBMYeh5YLVG45ySZgACSFg"]
[Tue Jul 21 07:31:19.959177 2026] [security2:error] [pid 229246:tid 229320] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/akismet.php"] [unique_id "al9KdyBMYeh5YLVG45ySZwACiEk"]
[Tue Jul 21 07:31:19.968650 2026] [security2:error] [pid 229246:tid 229451] [client 193.36.225.72:53249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KdyBMYeh5YLVG45ySaAAAAl8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:19.981647 2026] [security2:error] [pid 229246:tid 229357] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/ace2.php"] [unique_id "al9KdyBMYeh5YLVG45ySawACTW4"]
[Tue Jul 21 07:31:19.997190 2026] [security2:error] [pid 229246:tid 229284] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.arthurferaud.com"] [uri "/ms.php"] [unique_id "al9KdyBMYeh5YLVG45ySbQACeyU"]
[Tue Jul 21 07:31:20.007129 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:50894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-content/index.php"] [unique_id "al9KeCBMYeh5YLVG45ySbgAAAnk"]
[Tue Jul 21 07:31:20.169374 2026] [security2:error] [pid 229246:tid 229384] [client 103.106.20.201:63775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeCBMYeh5YLVG45yScwAAAhw"]
[Tue Jul 21 07:31:20.170126 2026] [security2:error] [pid 229246:tid 229384] [client 103.106.20.201:63775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeCBMYeh5YLVG45yScwAAAhw"]
[Tue Jul 21 07:31:20.320446 2026] [security2:error] [pid 229246:tid 229396] [client 20.206.105.145:7791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/dr.php"] [unique_id "al9KeCBMYeh5YLVG45ySeAAAAig"]
[Tue Jul 21 07:31:20.346489 2026] [security2:error] [pid 229246:tid 229330] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KdyBMYeh5YLVG45ySNQACP1M"]
[Tue Jul 21 07:31:20.346653 2026] [security2:error] [pid 229246:tid 229419] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KdyBMYeh5YLVG45ySNQACP1M"]
[Tue Jul 21 07:31:20.481629 2026] [security2:error] [pid 229246:tid 229257] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KeCBMYeh5YLVG45ySfAACYAo"]
[Tue Jul 21 07:31:20.481772 2026] [security2:error] [pid 229246:tid 229452] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KeCBMYeh5YLVG45ySfAACYAo"]
[Tue Jul 21 07:31:20.609295 2026] [security2:error] [pid 229246:tid 229412] [client 20.197.192.193:9417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ah25.php"] [unique_id "al9KeCBMYeh5YLVG45ySgAAAAjg"]
[Tue Jul 21 07:31:20.780778 2026] [security2:error] [pid 229246:tid 229410] [client 45.8.17.60:58221] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/l10n/wp-conflg.php"] [unique_id "al9KeCBMYeh5YLVG45ySggAAAjY"]
[Tue Jul 21 07:31:21.075709 2026] [security2:error] [pid 229246:tid 229463] [client 20.206.105.145:39288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/j260624_13.php"] [unique_id "al9KeSBMYeh5YLVG45ySjwAAAms"]
[Tue Jul 21 07:31:21.164484 2026] [security2:error] [pid 229246:tid 229451] [client 20.220.225.223:19667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/dr.php"] [unique_id "al9KeSBMYeh5YLVG45ySkAAAAl8"]
[Tue Jul 21 07:31:21.205429 2026] [security2:error] [pid 229246:tid 229420] [client 20.220.225.223:8096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/kq1.php"] [unique_id "al9KeSBMYeh5YLVG45ySkgAAAkA"]
[Tue Jul 21 07:31:21.374495 2026] [security2:error] [pid 229246:tid 229458] [client 20.197.192.193:8379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/8.php"] [unique_id "al9KeSBMYeh5YLVG45ySkwAAAmY"]
[Tue Jul 21 07:31:21.382412 2026] [security2:error] [pid 229246:tid 229428] [client 173.24.185.52:54950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySlAAAAkg"]
[Tue Jul 21 07:31:21.387370 2026] [security2:error] [pid 229246:tid 229428] [client 173.24.185.52:54950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySlAAAAkg"]
[Tue Jul 21 07:31:21.435869 2026] [security2:error] [pid 229246:tid 229484] [client 154.192.233.199:59862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySmAAAAoA"]
[Tue Jul 21 07:31:21.435968 2026] [security2:error] [pid 229246:tid 229484] [client 154.192.233.199:59862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySmAAAAoA"]
[Tue Jul 21 07:31:21.550507 2026] [security2:error] [pid 229246:tid 229402] [client 175.45.70.82:65473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySmwAAAi4"]
[Tue Jul 21 07:31:21.550647 2026] [security2:error] [pid 229246:tid 229402] [client 175.45.70.82:65473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySmwAAAi4"]
[Tue Jul 21 07:31:21.634986 2026] [security2:error] [pid 229246:tid 229399] [client 20.197.192.193:8352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/red.php"] [unique_id "al9KeSBMYeh5YLVG45ySoQAAAis"]
[Tue Jul 21 07:31:21.661563 2026] [security2:error] [pid 229246:tid 229272] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySogACThk"]
[Tue Jul 21 07:31:21.661689 2026] [security2:error] [pid 229246:tid 229434] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySogACThk"]
[Tue Jul 21 07:31:21.840924 2026] [security2:error] [pid 229246:tid 229263] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySowACIBA"]
[Tue Jul 21 07:31:21.841131 2026] [security2:error] [pid 229246:tid 229388] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeSBMYeh5YLVG45ySowACIBA"]
[Tue Jul 21 07:31:21.847166 2026] [security2:error] [pid 229246:tid 229422] [client 20.220.225.223:63864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/dr.php"] [unique_id "al9KeSBMYeh5YLVG45ySpAAAAkI"]
[Tue Jul 21 07:31:22.038650 2026] [security2:error] [pid 229246:tid 229387] [client 20.206.105.145:54555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file31.php"] [unique_id "al9KeiBMYeh5YLVG45ySqQAAAh8"]
[Tue Jul 21 07:31:22.277832 2026] [proxy:error] [pid 229246:tid 229502] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:22.277931 2026] [proxy_http:error] [pid 229246:tid 229502] [client 137.184.89.104:46858] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.lambiduspet.com.br/
[Tue Jul 21 07:31:22.278979 2026] [proxy:error] [pid 229246:tid 229502] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:22.279029 2026] [proxy_http:error] [pid 229246:tid 229502] [client 137.184.89.104:46858] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.lambiduspet.com.br/
[Tue Jul 21 07:31:22.361982 2026] [security2:error] [pid 229246:tid 229474] [client 103.174.34.15:58019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeiBMYeh5YLVG45yStQAAAnY"]
[Tue Jul 21 07:31:22.362108 2026] [security2:error] [pid 229246:tid 229474] [client 103.174.34.15:58019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeiBMYeh5YLVG45yStQAAAnY"]
[Tue Jul 21 07:31:22.411562 2026] [security2:error] [pid 229246:tid 229424] [client 20.197.192.193:9460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/fffm.php"] [unique_id "al9KeiBMYeh5YLVG45ySuAAAAkQ"]
[Tue Jul 21 07:31:22.579568 2026] [security2:error] [pid 229246:tid 229382] [client 45.8.17.49:64587] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/user.php"] [unique_id "al9KeiBMYeh5YLVG45ySvAAAAho"]
[Tue Jul 21 07:31:22.585220 2026] [security2:error] [pid 229246:tid 229331] [remote 45.79.123.44:51838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9KeiBMYeh5YLVG45ySvQACflQ"]
[Tue Jul 21 07:31:22.757399 2026] [security2:error] [pid 229246:tid 229381] [client 122.129.67.13:60422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9KeiBMYeh5YLVG45ySwQAAAhk"]
[Tue Jul 21 07:31:22.936569 2026] [security2:error] [pid 229246:tid 229436] [client 20.197.192.193:8363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ftde.php"] [unique_id "al9KeiBMYeh5YLVG45ySyAAAAlA"]
[Tue Jul 21 07:31:22.965382 2026] [security2:error] [pid 229246:tid 229378] [client 20.206.105.145:39237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/d62.php"] [unique_id "al9KeiBMYeh5YLVG45ySyQAAAhY"]
[Tue Jul 21 07:31:23.273168 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:9569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/yup.php"] [unique_id "al9KeyBMYeh5YLVG45ySzgAAAoQ"]
[Tue Jul 21 07:31:23.481990 2026] [security2:error] [pid 229246:tid 229486] [client 20.197.192.193:8346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/jj.php"] [unique_id "al9KeyBMYeh5YLVG45yS1wAAAoI"]
[Tue Jul 21 07:31:23.559801 2026] [security2:error] [pid 229246:tid 229450] [client 45.251.232.145:63003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeyBMYeh5YLVG45yS2QAAAl4"]
[Tue Jul 21 07:31:23.559960 2026] [security2:error] [pid 229246:tid 229450] [client 45.251.232.145:63003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KeyBMYeh5YLVG45yS2QAAAl4"]
[Tue Jul 21 07:31:23.705006 2026] [security2:error] [pid 229246:tid 229388] [client 45.8.19.164:55247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luanaarruda.com"] [uri "/wp-login.php"] [unique_id "al9KeyBMYeh5YLVG45yS3wAAAiA"]
[Tue Jul 21 07:31:24.063803 2026] [security2:error] [pid 229246:tid 229464] [client 20.197.192.193:8360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/dragonshell.php"] [unique_id "al9KfCBMYeh5YLVG45yS6gAAAmw"]
[Tue Jul 21 07:31:24.129119 2026] [security2:error] [pid 229246:tid 229434] [client 20.206.105.145:7752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file6.php"] [unique_id "al9KfCBMYeh5YLVG45yS7gAAAk4"]
[Tue Jul 21 07:31:24.185987 2026] [security2:error] [pid 229246:tid 229378] [client 45.8.17.110:40857] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/nextpage/"] [unique_id "al9KfCBMYeh5YLVG45yS7wAAAhY"]
[Tue Jul 21 07:31:24.228324 2026] [security2:error] [pid 229246:tid 229364] [remote 49.12.216.176:38812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shop-officialstore.com"] [uri "/wp-login.php"] [unique_id "al9KfCBMYeh5YLVG45yS8AACYnU"]
[Tue Jul 21 07:31:24.324264 2026] [security2:error] [pid 229246:tid 229490] [client 172.245.102.45:29177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KfCBMYeh5YLVG45yS9AAAAoY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:24.368373 2026] [security2:error] [pid 229246:tid 229329] [remote 46.105.28.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/wp-login.php"] [unique_id "al9KeyBMYeh5YLVG45yS0QACH1I"]
[Tue Jul 21 07:31:24.730441 2026] [security2:error] [pid 229246:tid 229450] [client 20.151.10.161:57369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/zoro.php"] [unique_id "al9KfCBMYeh5YLVG45yS_AAAAl4"]
[Tue Jul 21 07:31:24.763625 2026] [security2:error] [pid 229246:tid 229479] [client 20.197.192.193:9421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-mt.php"] [unique_id "al9KfCBMYeh5YLVG45yTAAAAAns"]
[Tue Jul 21 07:31:24.909252 2026] [security2:error] [pid 229246:tid 229400] [client 117.217.38.194:52392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KfCBMYeh5YLVG45yTAgAAAiw"]
[Tue Jul 21 07:31:24.909385 2026] [security2:error] [pid 229246:tid 229400] [client 117.217.38.194:52392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KfCBMYeh5YLVG45yTAgAAAiw"]
[Tue Jul 21 07:31:25.084501 2026] [security2:error] [pid 229246:tid 229482] [client 45.8.17.112:63535] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/code/"] [unique_id "al9KfSBMYeh5YLVG45yTBwAAAn4"]
[Tue Jul 21 07:31:25.260582 2026] [security2:error] [pid 229246:tid 229440] [client 20.206.105.145:7465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file15.php"] [unique_id "al9KfSBMYeh5YLVG45yTCwAAAlQ"]
[Tue Jul 21 07:31:25.384896 2026] [security2:error] [pid 229246:tid 229407] [client 20.197.192.193:8373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ww.php"] [unique_id "al9KfSBMYeh5YLVG45yTDQAAAjM"]
[Tue Jul 21 07:31:25.627807 2026] [security2:error] [pid 229246:tid 229428] [client 173.252.95.30:57344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KfSBMYeh5YLVG45yTFQAAAkg"]
[Tue Jul 21 07:31:25.645544 2026] [security2:error] [pid 229246:tid 229449] [client 20.197.192.193:8353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/cron.php"] [unique_id "al9KfSBMYeh5YLVG45yTFgAAAl0"]
[Tue Jul 21 07:31:25.698378 2026] [security2:error] [pid 229246:tid 229267] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KfSBMYeh5YLVG45yTFwACFhQ"]
[Tue Jul 21 07:31:25.698561 2026] [security2:error] [pid 229246:tid 229378] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KfSBMYeh5YLVG45yTFwACFhQ"]
[Tue Jul 21 07:31:26.070489 2026] [security2:error] [pid 229246:tid 229429] [client 20.220.225.223:8914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/mimpi.php"] [unique_id "al9KfiBMYeh5YLVG45yTJAAAAkk"]
[Tue Jul 21 07:31:26.096371 2026] [security2:error] [pid 229246:tid 229403] [client 20.151.10.161:51321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/admin.php"] [unique_id "al9KfiBMYeh5YLVG45yTJgAAAi8"]
[Tue Jul 21 07:31:26.100307 2026] [security2:error] [pid 229246:tid 229479] [client 20.52.136.55:1766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/w.php"] [unique_id "al9KfiBMYeh5YLVG45yTJwAAAns"]
[Tue Jul 21 07:31:26.190832 2026] [security2:error] [pid 229246:tid 229455] [client 45.8.17.115:60399] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentytwo/assets/fonts/"] [unique_id "al9KfiBMYeh5YLVG45yTKAAAAmM"]
[Tue Jul 21 07:31:26.541471 2026] [security2:error] [pid 229246:tid 229308] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KfiBMYeh5YLVG45yTLQACIj0"]
[Tue Jul 21 07:31:26.541713 2026] [security2:error] [pid 229246:tid 229390] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KfiBMYeh5YLVG45yTLQACIj0"]
[Tue Jul 21 07:31:26.586582 2026] [security2:error] [pid 229246:tid 229311] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KfiBMYeh5YLVG45yTMQACJEA"]
[Tue Jul 21 07:31:26.586713 2026] [security2:error] [pid 229246:tid 229392] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KfiBMYeh5YLVG45yTMQACJEA"]
[Tue Jul 21 07:31:27.290775 2026] [security2:error] [pid 229246:tid 229463] [client 45.8.17.73:39127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/t.php"] [unique_id "al9KfyBMYeh5YLVG45yTRAAAAms"]
[Tue Jul 21 07:31:27.450440 2026] [security2:error] [pid 229246:tid 229490] [client 62.102.148.164:48612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KfyBMYeh5YLVG45yTSQAAAoY"]
[Tue Jul 21 07:31:27.450529 2026] [security2:error] [pid 229246:tid 229490] [client 62.102.148.164:48612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KfyBMYeh5YLVG45yTSQAAAoY"]
[Tue Jul 21 07:31:27.496354 2026] [security2:error] [pid 229246:tid 229479] [client 20.220.225.223:19281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/2x.php"] [unique_id "al9KfyBMYeh5YLVG45yTSgAAAns"]
[Tue Jul 21 07:31:27.585008 2026] [security2:error] [pid 229246:tid 229457] [client 20.151.10.161:57348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/greap.php"] [unique_id "al9KfyBMYeh5YLVG45yTSwAAAmU"]
[Tue Jul 21 07:31:27.771331 2026] [security2:error] [pid 229246:tid 229382] [client 20.206.105.145:39255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ups.php"] [unique_id "al9KfyBMYeh5YLVG45yTUgAAAho"]
[Tue Jul 21 07:31:27.988315 2026] [security2:error] [pid 229246:tid 229475] [client 172.245.102.44:64857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KfyBMYeh5YLVG45yTVwAAAnc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:28.193067 2026] [security2:error] [pid 229246:tid 229399] [client 20.206.105.145:39293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k.php"] [unique_id "al9KgCBMYeh5YLVG45yTXQAAAis"]
[Tue Jul 21 07:31:28.288945 2026] [security2:error] [pid 229246:tid 229440] [client 59.96.220.140:58668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KgCBMYeh5YLVG45yTYAAAAlQ"]
[Tue Jul 21 07:31:28.289618 2026] [security2:error] [pid 229246:tid 229440] [client 59.96.220.140:58668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KgCBMYeh5YLVG45yTYAAAAlQ"]
[Tue Jul 21 07:31:28.293295 2026] [security2:error] [pid 229246:tid 229452] [client 45.8.17.127:34763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/html-api/chosen.php"] [unique_id "al9KgCBMYeh5YLVG45yTYQAAAmA"]
[Tue Jul 21 07:31:28.361584 2026] [security2:error] [pid 229246:tid 229502] [client 117.251.86.144:35336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KgCBMYeh5YLVG45yTZAAAApI"]
[Tue Jul 21 07:31:28.361731 2026] [security2:error] [pid 229246:tid 229502] [client 117.251.86.144:35336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KgCBMYeh5YLVG45yTZAAAApI"]
[Tue Jul 21 07:31:28.395806 2026] [security2:error] [pid 229246:tid 229454] [client 20.206.105.145:38912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k2.php"] [unique_id "al9KgCBMYeh5YLVG45yTZQAAAmI"]
[Tue Jul 21 07:31:28.445615 2026] [security2:error] [pid 229246:tid 229437] [client 20.206.105.145:38917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k3.php"] [unique_id "al9KgCBMYeh5YLVG45yTaQAAAlE"]
[Tue Jul 21 07:31:28.702146 2026] [security2:error] [pid 229246:tid 229427] [client 20.206.105.145:39264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k4.php"] [unique_id "al9KgCBMYeh5YLVG45yTbQAAAkc"]
[Tue Jul 21 07:31:28.826028 2026] [security2:error] [pid 229246:tid 229410] [client 20.151.10.161:57398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/177.php"] [unique_id "al9KgCBMYeh5YLVG45yTbwAAAjY"]
[Tue Jul 21 07:31:28.993943 2026] [security2:error] [pid 229246:tid 229272] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KgCBMYeh5YLVG45yTdAACTRk"]
[Tue Jul 21 07:31:28.994139 2026] [security2:error] [pid 229246:tid 229433] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KgCBMYeh5YLVG45yTdAACTRk"]
[Tue Jul 21 07:31:29.250523 2026] [security2:error] [pid 229246:tid 229482] [client 20.197.192.193:9425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/xxx.php"] [unique_id "al9KgSBMYeh5YLVG45yTegAAAn4"]
[Tue Jul 21 07:31:29.301348 2026] [security2:error] [pid 229246:tid 229419] [client 139.167.225.182:58048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yTfAAAAj8"]
[Tue Jul 21 07:31:29.301512 2026] [security2:error] [pid 229246:tid 229419] [client 139.167.225.182:58048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yTfAAAAj8"]
[Tue Jul 21 07:31:29.474888 2026] [security2:error] [pid 229246:tid 229283] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yTfwACdyQ"]
[Tue Jul 21 07:31:29.475037 2026] [security2:error] [pid 229246:tid 229475] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yTfwACdyQ"]
[Tue Jul 21 07:31:29.596711 2026] [security2:error] [pid 229246:tid 229470] [client 45.8.17.105:52377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/dist/edit-post/"] [unique_id "al9KgSBMYeh5YLVG45yTggAAAnI"]
[Tue Jul 21 07:31:29.805802 2026] [security2:error] [pid 229246:tid 229322] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yThwACPEs"]
[Tue Jul 21 07:31:29.805968 2026] [security2:error] [pid 229246:tid 229416] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yThwACPEs"]
[Tue Jul 21 07:31:29.869117 2026] [security2:error] [pid 229246:tid 229437] [client 20.220.225.223:4192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/2x.php"] [unique_id "al9KgSBMYeh5YLVG45yTiQAAAlE"]
[Tue Jul 21 07:31:29.875345 2026] [security2:error] [pid 229246:tid 229398] [client 103.162.129.114:56436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yTigAAAio"]
[Tue Jul 21 07:31:29.875457 2026] [security2:error] [pid 229246:tid 229398] [client 103.162.129.114:56436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KgSBMYeh5YLVG45yTigAAAio"]
[Tue Jul 21 07:31:29.885440 2026] [security2:error] [pid 229246:tid 229428] [client 20.206.105.145:7468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/jp.php"] [unique_id "al9KgSBMYeh5YLVG45yTiwAAAkg"]
[Tue Jul 21 07:31:29.914693 2026] [security2:error] [pid 229246:tid 229414] [client 20.206.105.145:38931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k5.php"] [unique_id "al9KgSBMYeh5YLVG45yTkQAAAjo"]
[Tue Jul 21 07:31:30.045780 2026] [security2:error] [pid 229246:tid 229392] [client 122.186.204.214:56157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KgiBMYeh5YLVG45yTmwAAAiQ"]
[Tue Jul 21 07:31:30.045904 2026] [security2:error] [pid 229246:tid 229392] [client 122.186.204.214:56157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KgiBMYeh5YLVG45yTmwAAAiQ"]
[Tue Jul 21 07:31:30.176792 2026] [security2:error] [pid 229246:tid 229310] [remote 89.42.136.2:48780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.136.42.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9KgiBMYeh5YLVG45yToAACij8"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:31:30.332487 2026] [security2:error] [pid 229246:tid 229485] [client 20.197.192.193:9420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/hunter.php"] [unique_id "al9KgiBMYeh5YLVG45yTqwAAAoE"]
[Tue Jul 21 07:31:30.677134 2026] [security2:error] [pid 229246:tid 229473] [client 20.151.10.161:57450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/199.php"] [unique_id "al9KgiBMYeh5YLVG45yTsQAAAnU"]
[Tue Jul 21 07:31:30.966013 2026] [security2:error] [pid 229246:tid 229484] [client 103.106.20.201:64346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgiBMYeh5YLVG45yTuAAAAoA"]
[Tue Jul 21 07:31:30.966141 2026] [security2:error] [pid 229246:tid 229484] [client 103.106.20.201:64346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgiBMYeh5YLVG45yTuAAAAoA"]
[Tue Jul 21 07:31:30.983794 2026] [security2:error] [pid 229246:tid 229433] [client 45.8.17.131:53643] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/plugin/"] [unique_id "al9KgiBMYeh5YLVG45yTuQAAAk0"]
[Tue Jul 21 07:31:31.050806 2026] [security2:error] [pid 229246:tid 229291] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KgyBMYeh5YLVG45yTugACZSw"]
[Tue Jul 21 07:31:31.050943 2026] [security2:error] [pid 229246:tid 229457] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KgyBMYeh5YLVG45yTugACZSw"]
[Tue Jul 21 07:31:31.454502 2026] [security2:error] [pid 229246:tid 229500] [client 20.197.192.193:9456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/we.php"] [unique_id "al9KgyBMYeh5YLVG45yTywAAApA"]
[Tue Jul 21 07:31:31.988040 2026] [security2:error] [pid 229246:tid 229408] [client 173.24.185.52:55422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KgyBMYeh5YLVG45yT2AAAAjQ"]
[Tue Jul 21 07:31:31.988182 2026] [security2:error] [pid 229246:tid 229408] [client 173.24.185.52:55422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KgyBMYeh5YLVG45yT2AAAAjQ"]
[Tue Jul 21 07:31:31.992129 2026] [security2:error] [pid 229246:tid 229473] [client 20.206.105.145:7417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/f35.php"] [unique_id "al9KgyBMYeh5YLVG45yT2QAAAnU"]
[Tue Jul 21 07:31:32.061603 2026] [security2:error] [pid 229246:tid 229399] [client 154.192.233.199:60519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT2wAAAis"]
[Tue Jul 21 07:31:32.061726 2026] [security2:error] [pid 229246:tid 229399] [client 154.192.233.199:60519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT2wAAAis"]
[Tue Jul 21 07:31:32.095151 2026] [security2:error] [pid 229246:tid 229391] [client 20.220.225.223:56473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/kq1.php"] [unique_id "al9KhCBMYeh5YLVG45yT3AAAAiM"]
[Tue Jul 21 07:31:32.133593 2026] [security2:error] [pid 229246:tid 229499] [client 20.151.10.161:58006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file52.php"] [unique_id "al9KhCBMYeh5YLVG45yT3wAAAo8"]
[Tue Jul 21 07:31:32.286199 2026] [security2:error] [pid 229246:tid 229474] [client 20.220.225.223:8068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/zzz.php"] [unique_id "al9KhCBMYeh5YLVG45yT4QAAAnY"]
[Tue Jul 21 07:31:32.334160 2026] [security2:error] [pid 229246:tid 229419] [client 74.7.241.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "vivafinanceiras.com.br"] [uri "/index.php"] [unique_id "al9KgyBMYeh5YLVG45yTxAAAAj8"]
[Tue Jul 21 07:31:32.335222 2026] [security2:error] [pid 229246:tid 229429] [client 74.7.241.160:45264] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "vivafinanceiras.com.br"] [uri "/robots.txt"] [unique_id "al9KgyBMYeh5YLVG45yTwgACSWc"]
[Tue Jul 21 07:31:32.348829 2026] [security2:error] [pid 229246:tid 229444] [client 175.45.70.82:49594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT4wAAAlg"]
[Tue Jul 21 07:31:32.348945 2026] [security2:error] [pid 229246:tid 229444] [client 175.45.70.82:49594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT4wAAAlg"]
[Tue Jul 21 07:31:32.360945 2026] [security2:error] [pid 229246:tid 229339] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT5AACRFw"]
[Tue Jul 21 07:31:32.361134 2026] [security2:error] [pid 229246:tid 229424] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT5AACRFw"]
[Tue Jul 21 07:31:32.369318 2026] [security2:error] [pid 229246:tid 229411] [client 82.102.28.107:45014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT5QAAAjc"]
[Tue Jul 21 07:31:32.369390 2026] [security2:error] [pid 229246:tid 229411] [client 82.102.28.107:45014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT5QAAAjc"]
[Tue Jul 21 07:31:32.482489 2026] [security2:error] [pid 229246:tid 229371] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT6gACRnw"]
[Tue Jul 21 07:31:32.482714 2026] [security2:error] [pid 229246:tid 229426] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KhCBMYeh5YLVG45yT6gACRnw"]
[Tue Jul 21 07:31:32.801155 2026] [security2:error] [pid 229246:tid 229410] [client 172.245.102.46:26807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KhCBMYeh5YLVG45yT7AAAAjY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:32.980740 2026] [security2:error] [pid 229246:tid 229454] [client 20.220.225.223:19658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/kq1.php"] [unique_id "al9KhCBMYeh5YLVG45yT9AAAAmI"]
[Tue Jul 21 07:31:33.146725 2026] [security2:error] [pid 229246:tid 229448] [client 103.174.34.15:58519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhSBMYeh5YLVG45yT-QAAAlw"]
[Tue Jul 21 07:31:33.146934 2026] [security2:error] [pid 229246:tid 229448] [client 103.174.34.15:58519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhSBMYeh5YLVG45yT-QAAAlw"]
[Tue Jul 21 07:31:33.475122 2026] [security2:error] [pid 229246:tid 229490] [client 82.102.28.107:60766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9KhSBMYeh5YLVG45yUAgAAAoY"]
[Tue Jul 21 07:31:33.475218 2026] [security2:error] [pid 229246:tid 229490] [client 82.102.28.107:60766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9KhSBMYeh5YLVG45yUAgAAAoY"]
[Tue Jul 21 07:31:33.536727 2026] [security2:error] [pid 229246:tid 229458] [client 20.197.192.193:9446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/phpinfo.php1"] [unique_id "al9KhSBMYeh5YLVG45yUBQAAAmY"]
[Tue Jul 21 07:31:33.716246 2026] [security2:error] [pid 229246:tid 229444] [client 20.151.10.161:51290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/122.php"] [unique_id "al9KhSBMYeh5YLVG45yUDQAAAlg"]
[Tue Jul 21 07:31:34.014310 2026] [security2:error] [pid 229246:tid 229401] [client 45.251.232.145:63516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhiBMYeh5YLVG45yUFgAAAi0"]
[Tue Jul 21 07:31:34.014423 2026] [security2:error] [pid 229246:tid 229401] [client 45.251.232.145:63516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhiBMYeh5YLVG45yUFgAAAi0"]
[Tue Jul 21 07:31:34.139955 2026] [security2:error] [pid 229246:tid 229481] [client 152.59.154.239:59927] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgyBMYeh5YLVG45yT0gAAAn0"]
[Tue Jul 21 07:31:34.140162 2026] [security2:error] [pid 229246:tid 229481] [client 152.59.154.239:59927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KgyBMYeh5YLVG45yT0gAAAn0"]
[Tue Jul 21 07:31:34.166738 2026] [security2:error] [pid 229246:tid 229403] [client 20.220.225.223:4172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/zzz.php"] [unique_id "al9KhiBMYeh5YLVG45yUGQAAAi8"]
[Tue Jul 21 07:31:34.419109 2026] [security2:error] [pid 229246:tid 229398] [client 20.220.225.223:6797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wicked.php"] [unique_id "al9KhiBMYeh5YLVG45yUIAAAAio"]
[Tue Jul 21 07:31:34.679370 2026] [security2:error] [pid 229246:tid 229437] [client 45.8.17.64:48137] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/langs/"] [unique_id "al9KhiBMYeh5YLVG45yUJQAAAlE"]
[Tue Jul 21 07:31:34.805294 2026] [security2:error] [pid 229246:tid 229475] [client 122.129.67.13:60991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9KhiBMYeh5YLVG45yUJgAAAnc"]
[Tue Jul 21 07:31:35.246589 2026] [security2:error] [pid 229246:tid 229494] [client 20.151.10.161:50909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/green1.php"] [unique_id "al9KhyBMYeh5YLVG45yUMwAAAoo"]
[Tue Jul 21 07:31:35.268777 2026] [security2:error] [pid 229246:tid 229249] [remote 134.209.147.209:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.147.209.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9KhyBMYeh5YLVG45yUNAACgAI"]
[Tue Jul 21 07:31:35.418150 2026] [security2:error] [pid 229246:tid 229420] [client 117.217.38.194:52806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhyBMYeh5YLVG45yUNgAAAkA"]
[Tue Jul 21 07:31:35.418262 2026] [security2:error] [pid 229246:tid 229420] [client 117.217.38.194:52806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KhyBMYeh5YLVG45yUNgAAAkA"]
[Tue Jul 21 07:31:35.582983 2026] [security2:error] [pid 229246:tid 229318] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KhyBMYeh5YLVG45yUPQACSUc"]
[Tue Jul 21 07:31:35.583154 2026] [security2:error] [pid 229246:tid 229429] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KhyBMYeh5YLVG45yUPQACSUc"]
[Tue Jul 21 07:31:35.631165 2026] [security2:error] [pid 229246:tid 229360] [remote 72.167.132.114:59628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9KhyBMYeh5YLVG45yUPgAChHE"]
[Tue Jul 21 07:31:35.683968 2026] [security2:error] [pid 229246:tid 229471] [client 45.8.17.63:62887] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/query-pagination-previous/"] [unique_id "al9KhyBMYeh5YLVG45yUQAAAAnM"]
[Tue Jul 21 07:31:35.747219 2026] [security2:error] [pid 229246:tid 229481] [client 20.52.136.55:1777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/wp-good.php"] [unique_id "al9KhyBMYeh5YLVG45yUQQAAAn0"]
[Tue Jul 21 07:31:35.769017 2026] [security2:error] [pid 229246:tid 229410] [client 20.220.225.223:8127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/edit.php"] [unique_id "al9KhyBMYeh5YLVG45yUQgAAAjY"]
[Tue Jul 21 07:31:36.147725 2026] [security2:error] [pid 229246:tid 229502] [client 74.7.228.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "lucasmorgado1781638745686.0721679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9KiCBMYeh5YLVG45yUSAACkkg"]
[Tue Jul 21 07:31:36.259866 2026] [security2:error] [pid 229246:tid 229325] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KiCBMYeh5YLVG45yUSgACNU4"]
[Tue Jul 21 07:31:36.260004 2026] [security2:error] [pid 229246:tid 229409] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KiCBMYeh5YLVG45yUSgACNU4"]
[Tue Jul 21 07:31:36.467603 2026] [security2:error] [pid 229246:tid 229384] [client 20.206.105.145:7463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-load.php"] [unique_id "al9KiCBMYeh5YLVG45yUSwAAAhw"]
[Tue Jul 21 07:31:36.935670 2026] [security2:error] [pid 229246:tid 229306] [remote 42.200.84.61:39992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "archrender.com.br"] [uri "/wp-login.php"] [unique_id "al9KiCBMYeh5YLVG45yUXgACOjs"]
[Tue Jul 21 07:31:37.071290 2026] [security2:error] [pid 229246:tid 229259] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KiSBMYeh5YLVG45yUaQACQAw"]
[Tue Jul 21 07:31:37.071451 2026] [security2:error] [pid 229246:tid 229420] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KiSBMYeh5YLVG45yUaQACQAw"]
[Tue Jul 21 07:31:37.317965 2026] [security2:error] [pid 229246:tid 229248] [remote 72.167.132.114:59632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "volyoaudiobooks.com"] [uri "/wp-login.php"] [unique_id "al9KiSBMYeh5YLVG45yUcAACgAE"]
[Tue Jul 21 07:31:37.359098 2026] [security2:error] [pid 229246:tid 229466] [client 20.220.225.223:31177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KiSBMYeh5YLVG45yUcQAAAm4"]
[Tue Jul 21 07:31:37.474592 2026] [security2:error] [pid 229246:tid 229450] [client 193.36.225.10:35867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KiSBMYeh5YLVG45yUdAAAAl4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:37.587231 2026] [security2:error] [pid 229246:tid 229502] [client 20.151.10.161:50882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/biufile.php"] [unique_id "al9KiSBMYeh5YLVG45yUeQAAApI"]
[Tue Jul 21 07:31:37.714381 2026] [security2:error] [pid 229246:tid 229487] [client 20.206.105.145:39278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/w.php"] [unique_id "al9KiSBMYeh5YLVG45yUfAAAAoM"]
[Tue Jul 21 07:31:38.089415 2026] [security2:error] [pid 229246:tid 229412] [client 45.8.17.73:27959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Requests/src/Auth/"] [unique_id "al9KiiBMYeh5YLVG45yUgwAAAjg"]
[Tue Jul 21 07:31:38.578827 2026] [security2:error] [pid 229246:tid 229420] [client 74.7.175.143:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "taliafernandavidi1783665345000.0711679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9KiiBMYeh5YLVG45yUkgACQGk"]
[Tue Jul 21 07:31:38.617092 2026] [security2:error] [pid 229246:tid 229339] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KiiBMYeh5YLVG45yUlQACXlw"]
[Tue Jul 21 07:31:38.720039 2026] [autoindex:error] [pid 229246:tid 229371] [remote 74.7.227.2:0] AH01276: Cannot serve directory /home2/taliaf34/taliafernandavidi1783665345000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:38.869092 2026] [autoindex:error] [pid 229246:tid 229416] [client 20.206.105.145:7761] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:38.928888 2026] [autoindex:error] [pid 229246:tid 229495] [client 20.206.105.145:7761] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:38.979706 2026] [security2:error] [pid 229246:tid 229441] [client 59.96.220.140:59385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KiiBMYeh5YLVG45yUnwAAAlU"]
[Tue Jul 21 07:31:38.979803 2026] [security2:error] [pid 229246:tid 229441] [client 59.96.220.140:59385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KiiBMYeh5YLVG45yUnwAAAlU"]
[Tue Jul 21 07:31:39.000881 2026] [security2:error] [pid 229246:tid 229453] [client 74.7.244.24:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "abdomenfirme.patihipopressivo.com"] [uri "/index.php"] [unique_id "al9KiCBMYeh5YLVG45yUXQAAAmE"]
[Tue Jul 21 07:31:39.001694 2026] [security2:error] [pid 229246:tid 229433] [client 74.7.244.24:45894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "abdomenfirme.patihipopressivo.com"] [uri "/robots.txt"] [unique_id "al9KiCBMYeh5YLVG45yUWwACTUs"]
[Tue Jul 21 07:31:39.059524 2026] [security2:error] [pid 229246:tid 229267] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KiyBMYeh5YLVG45yUpAACZhQ"]
[Tue Jul 21 07:31:39.106216 2026] [security2:error] [pid 229246:tid 229474] [client 117.251.86.144:55886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUpgAAAnY"]
[Tue Jul 21 07:31:39.106335 2026] [security2:error] [pid 229246:tid 229474] [client 117.251.86.144:55886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUpgAAAnY"]
[Tue Jul 21 07:31:39.145924 2026] [security2:error] [pid 229246:tid 229457] [client 20.151.10.161:57388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wpconf.php"] [unique_id "al9KiyBMYeh5YLVG45yUqgAAAmU"]
[Tue Jul 21 07:31:39.486919 2026] [security2:error] [pid 229246:tid 229401] [client 45.8.17.134:63725] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/wp.php"] [unique_id "al9KiyBMYeh5YLVG45yUsQAAAi0"]
[Tue Jul 21 07:31:39.488580 2026] [security2:error] [pid 229246:tid 229282] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUsAACfSM"]
[Tue Jul 21 07:31:39.488749 2026] [security2:error] [pid 229246:tid 229481] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUsAACfSM"]
[Tue Jul 21 07:31:39.560056 2026] [security2:error] [pid 229246:tid 229308] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/media.php"] [unique_id "al9KiyBMYeh5YLVG45yUtQACXj0"]
[Tue Jul 21 07:31:39.868500 2026] [security2:error] [pid 229246:tid 229460] [client 139.167.225.182:58668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUwwAAAmg"]
[Tue Jul 21 07:31:39.868594 2026] [security2:error] [pid 229246:tid 229460] [client 139.167.225.182:58668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUwwAAAmg"]
[Tue Jul 21 07:31:40.000609 2026] [security2:error] [pid 229246:tid 229285] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUxwACMCY"]
[Tue Jul 21 07:31:40.000748 2026] [security2:error] [pid 229246:tid 229404] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KiyBMYeh5YLVG45yUxwACMCY"]
[Tue Jul 21 07:31:40.199507 2026] [security2:error] [pid 229246:tid 229479] [client 20.151.10.161:51314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/mosty.php"] [unique_id "al9KjCBMYeh5YLVG45yU1AAAAns"]
[Tue Jul 21 07:31:40.275665 2026] [security2:error] [pid 229246:tid 229347] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KjCBMYeh5YLVG45yU1gACUWQ"]
[Tue Jul 21 07:31:40.275820 2026] [security2:error] [pid 229246:tid 229437] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KjCBMYeh5YLVG45yU1gACUWQ"]
[Tue Jul 21 07:31:40.387580 2026] [security2:error] [pid 229246:tid 229500] [client 45.8.17.124:25529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/news-portal/sitebar.php"] [unique_id "al9KjCBMYeh5YLVG45yU2QAAApA"]
[Tue Jul 21 07:31:40.625518 2026] [security2:error] [pid 229246:tid 229423] [client 20.206.105.145:7761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9KjCBMYeh5YLVG45yU5QAAAkM"]
[Tue Jul 21 07:31:40.636260 2026] [security2:error] [pid 229246:tid 229452] [client 103.162.129.114:56875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KjCBMYeh5YLVG45yU5gAAAmA"]
[Tue Jul 21 07:31:40.636422 2026] [security2:error] [pid 229246:tid 229452] [client 103.162.129.114:56875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KjCBMYeh5YLVG45yU5gAAAmA"]
[Tue Jul 21 07:31:40.701310 2026] [security2:error] [pid 229246:tid 229453] [client 122.186.204.214:56647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KjCBMYeh5YLVG45yU6gAAAmE"]
[Tue Jul 21 07:31:40.705706 2026] [security2:error] [pid 229246:tid 229453] [client 122.186.204.214:56647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KjCBMYeh5YLVG45yU6gAAAmE"]
[Tue Jul 21 07:31:41.135110 2026] [security2:error] [pid 229246:tid 229499] [client 172.245.102.42:25001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KjSBMYeh5YLVG45yU9QAAAo8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:41.343034 2026] [security2:error] [pid 229246:tid 229313] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/images.php"] [unique_id "al9KjSBMYeh5YLVG45yU-wACSUI"]
[Tue Jul 21 07:31:41.361969 2026] [security2:error] [pid 229246:tid 229272] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/gecko.php"] [unique_id "al9KjSBMYeh5YLVG45yU_AACeRk"]
[Tue Jul 21 07:31:41.393313 2026] [security2:error] [pid 229246:tid 229316] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/82.php"] [unique_id "al9KjSBMYeh5YLVG45yU_QACKkU"]
[Tue Jul 21 07:31:41.429629 2026] [security2:error] [pid 229246:tid 229410] [client 20.220.225.223:8080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/kua.php"] [unique_id "al9KjSBMYeh5YLVG45yU_wAAAjY"]
[Tue Jul 21 07:31:41.579567 2026] [security2:error] [pid 229246:tid 229487] [client 45.8.17.65:51347] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/database.php"] [unique_id "al9KjSBMYeh5YLVG45yVAQAAAoM"]
[Tue Jul 21 07:31:41.608989 2026] [security2:error] [pid 229246:tid 229279] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KjSBMYeh5YLVG45yVBAACHSA"]
[Tue Jul 21 07:31:41.609152 2026] [security2:error] [pid 229246:tid 229385] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KjSBMYeh5YLVG45yVBAACHSA"]
[Tue Jul 21 07:31:41.789897 2026] [security2:error] [pid 229246:tid 229396] [client 103.106.20.201:64940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjSBMYeh5YLVG45yVDgAAAig"]
[Tue Jul 21 07:31:41.789993 2026] [security2:error] [pid 229246:tid 229396] [client 103.106.20.201:64940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjSBMYeh5YLVG45yVDgAAAig"]
[Tue Jul 21 07:31:41.935370 2026] [security2:error] [pid 229246:tid 229448] [client 20.220.225.223:63836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wicked.php"] [unique_id "al9KjSBMYeh5YLVG45yVFAAAAlw"]
[Tue Jul 21 07:31:42.068215 2026] [security2:error] [pid 229246:tid 229449] [client 20.151.10.161:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/dejavu.php"] [unique_id "al9KjiBMYeh5YLVG45yVFQAAAl0"]
[Tue Jul 21 07:31:42.184273 2026] [security2:error] [pid 229246:tid 229310] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/admin.php"] [unique_id "al9KjiBMYeh5YLVG45yVGQACfj8"]
[Tue Jul 21 07:31:42.204120 2026] [security2:error] [pid 229246:tid 229327] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/adminner.php"] [unique_id "al9KjiBMYeh5YLVG45yVGgACMlA"]
[Tue Jul 21 07:31:42.373500 2026] [security2:error] [pid 229246:tid 229299] [remote 72.167.132.114:59646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9KjiBMYeh5YLVG45yVIwACjTQ"]
[Tue Jul 21 07:31:42.514123 2026] [security2:error] [pid 229246:tid 229455] [client 173.24.185.52:55890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KjiBMYeh5YLVG45yVJwAAAmM"]
[Tue Jul 21 07:31:42.514251 2026] [security2:error] [pid 229246:tid 229455] [client 173.24.185.52:55890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KjiBMYeh5YLVG45yVJwAAAmM"]
[Tue Jul 21 07:31:42.683431 2026] [security2:error] [pid 229246:tid 229277] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/admin.php"] [unique_id "al9KjiBMYeh5YLVG45yVKgACHR4"]
[Tue Jul 21 07:31:42.741592 2026] [security2:error] [pid 229246:tid 229474] [client 154.192.233.199:58980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjiBMYeh5YLVG45yVLQAAAnY"]
[Tue Jul 21 07:31:42.741758 2026] [security2:error] [pid 229246:tid 229474] [client 154.192.233.199:58980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjiBMYeh5YLVG45yVLQAAAnY"]
[Tue Jul 21 07:31:42.779634 2026] [security2:error] [pid 229246:tid 229427] [client 109.248.148.246:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KjiBMYeh5YLVG45yVLgAAAkc"]
[Tue Jul 21 07:31:42.779747 2026] [security2:error] [pid 229246:tid 229427] [client 109.248.148.246:53852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KjiBMYeh5YLVG45yVLgAAAkc"]
[Tue Jul 21 07:31:42.782269 2026] [security2:error] [pid 229246:tid 229364] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/k.php"] [unique_id "al9KjiBMYeh5YLVG45yVLwACd3U"]
[Tue Jul 21 07:31:42.888461 2026] [security2:error] [pid 229246:tid 229442] [client 45.8.17.138:54189] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/login.php"] [unique_id "al9KjiBMYeh5YLVG45yVVAAAAlY"]
[Tue Jul 21 07:31:43.012022 2026] [security2:error] [pid 229246:tid 229249] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjyBMYeh5YLVG45yVcQACRgI"]
[Tue Jul 21 07:31:43.012152 2026] [security2:error] [pid 229246:tid 229426] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjyBMYeh5YLVG45yVcQACRgI"]
[Tue Jul 21 07:31:43.066348 2026] [security2:error] [pid 229246:tid 229500] [client 175.45.70.82:50143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjyBMYeh5YLVG45yVdgAAApA"]
[Tue Jul 21 07:31:43.066452 2026] [security2:error] [pid 229246:tid 229500] [client 175.45.70.82:50143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KjyBMYeh5YLVG45yVdgAAApA"]
[Tue Jul 21 07:31:43.093029 2026] [security2:error] [pid 229246:tid 229374] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KjyBMYeh5YLVG45yVeAACcn8"]
[Tue Jul 21 07:31:43.093194 2026] [security2:error] [pid 229246:tid 229470] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KjyBMYeh5YLVG45yVeAACcn8"]
[Tue Jul 21 07:31:43.132968 2026] [security2:error] [pid 229246:tid 229293] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/blurbs.php"] [unique_id "al9KjyBMYeh5YLVG45yVewACUS4"]
[Tue Jul 21 07:31:43.143559 2026] [security2:error] [pid 229246:tid 229489] [client 20.151.10.161:50931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/aaf.php"] [unique_id "al9KjyBMYeh5YLVG45yVfAAAAoU"]
[Tue Jul 21 07:31:43.160090 2026] [security2:error] [pid 229246:tid 229336] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/bajah.php"] [unique_id "al9KjyBMYeh5YLVG45yVfQACeVk"]
[Tue Jul 21 07:31:43.178958 2026] [security2:error] [pid 229246:tid 229301] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/a.php"] [unique_id "al9KjyBMYeh5YLVG45yVfgACcDY"]
[Tue Jul 21 07:31:43.197944 2026] [security2:error] [pid 229246:tid 229360] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/edit.php"] [unique_id "al9KjyBMYeh5YLVG45yVfwACK3E"]
[Tue Jul 21 07:31:43.202329 2026] [security2:error] [pid 229246:tid 229493] [client 20.220.225.223:31175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KjyBMYeh5YLVG45yVgAAAAok"]
[Tue Jul 21 07:31:43.217631 2026] [security2:error] [pid 229246:tid 229319] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/hosty.php"] [unique_id "al9KjyBMYeh5YLVG45yVgQACbkg"]
[Tue Jul 21 07:31:43.242694 2026] [security2:error] [pid 229246:tid 229272] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/k.php"] [unique_id "al9KjyBMYeh5YLVG45yVhgACdhk"]
[Tue Jul 21 07:31:43.712358 2026] [security2:error] [pid 229246:tid 229331] [remote 57.141.18.73:33948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9KjyBMYeh5YLVG45yVkwACVlQ"]
[Tue Jul 21 07:31:43.797719 2026] [security2:error] [pid 229246:tid 229499] [client 20.220.225.223:6795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/ez.php"] [unique_id "al9KjyBMYeh5YLVG45yVlgAAAo8"]
[Tue Jul 21 07:31:44.097126 2026] [security2:error] [pid 229246:tid 229438] [client 103.174.34.15:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkCBMYeh5YLVG45yVmwAAAlI"]
[Tue Jul 21 07:31:44.097487 2026] [security2:error] [pid 229246:tid 229438] [client 103.174.34.15:59013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkCBMYeh5YLVG45yVmwAAAlI"]
[Tue Jul 21 07:31:44.114249 2026] [security2:error] [pid 229246:tid 229419] [client 152.59.154.239:60396] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkCBMYeh5YLVG45yVnAAAAj8"]
[Tue Jul 21 07:31:44.114422 2026] [security2:error] [pid 229246:tid 229419] [client 152.59.154.239:60396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkCBMYeh5YLVG45yVnAAAAj8"]
[Tue Jul 21 07:31:44.223643 2026] [security2:error] [pid 229246:tid 229473] [client 20.220.225.223:6812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/fz.php"] [unique_id "al9KkCBMYeh5YLVG45yVnwAAAnU"]
[Tue Jul 21 07:31:44.268643 2026] [security2:error] [pid 229246:tid 229280] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/aaa.php"] [unique_id "al9KkCBMYeh5YLVG45yVpgACXyE"]
[Tue Jul 21 07:31:44.306423 2026] [security2:error] [pid 229246:tid 229404] [client 20.206.105.145:7596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-links.php"] [unique_id "al9KkCBMYeh5YLVG45yVqwAAAjA"]
[Tue Jul 21 07:31:44.352684 2026] [security2:error] [pid 229246:tid 229315] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/file5.php"] [unique_id "al9KkCBMYeh5YLVG45yVrAACQEQ"]
[Tue Jul 21 07:31:44.412367 2026] [security2:error] [pid 229246:tid 229248] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/222.php"] [unique_id "al9KkCBMYeh5YLVG45yVsgACTwE"]
[Tue Jul 21 07:31:44.569880 2026] [security2:error] [pid 229246:tid 229482] [client 45.251.232.145:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkCBMYeh5YLVG45yVuAAAAn4"]
[Tue Jul 21 07:31:44.569996 2026] [security2:error] [pid 229246:tid 229482] [client 45.251.232.145:64035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkCBMYeh5YLVG45yVuAAAAn4"]
[Tue Jul 21 07:31:44.698388 2026] [security2:error] [pid 229246:tid 229479] [client 20.220.225.223:31198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/wander.php"] [unique_id "al9KkCBMYeh5YLVG45yVugAAAns"]
[Tue Jul 21 07:31:44.719087 2026] [security2:error] [pid 229246:tid 229346] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/test.php"] [unique_id "al9KkCBMYeh5YLVG45yVuwACVWM"]
[Tue Jul 21 07:31:44.813856 2026] [security2:error] [pid 229246:tid 229434] [client 180.153.236.244:34589] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com.br"] [uri "/"] [unique_id "al9KkCBMYeh5YLVG45yVwQAAAk4"], referer: http://gradiente.com.br/
[Tue Jul 21 07:31:44.814003 2026] [security2:error] [pid 229246:tid 229434] [client 180.153.236.244:34589] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com.br"] [uri "/"] [unique_id "al9KkCBMYeh5YLVG45yVwQAAAk4"], referer: http://gradiente.com.br/
[Tue Jul 21 07:31:44.860350 2026] [security2:error] [pid 229246:tid 229433] [client 20.151.10.161:57370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/term.php"] [unique_id "al9KkCBMYeh5YLVG45yVwgAAAk0"]
[Tue Jul 21 07:31:45.081111 2026] [security2:error] [pid 229246:tid 229443] [client 122.129.67.13:59763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9KkCBMYeh5YLVG45yVzgAAAlc"]
[Tue Jul 21 07:31:45.195751 2026] [security2:error] [pid 229246:tid 229384] [client 45.8.17.57:26525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/user/config.php"] [unique_id "al9KkSBMYeh5YLVG45yV0QAAAhw"]
[Tue Jul 21 07:31:45.250688 2026] [security2:error] [pid 229246:tid 229267] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/aaa.php"] [unique_id "al9KkSBMYeh5YLVG45yV0wACIxQ"]
[Tue Jul 21 07:31:45.270078 2026] [security2:error] [pid 229246:tid 229348] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/11.php"] [unique_id "al9KkSBMYeh5YLVG45yV1AACaGU"]
[Tue Jul 21 07:31:45.288850 2026] [security2:error] [pid 229246:tid 229296] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/mac.php"] [unique_id "al9KkSBMYeh5YLVG45yV1QACTzE"]
[Tue Jul 21 07:31:45.314938 2026] [security2:error] [pid 229246:tid 229414] [client 20.220.225.223:19321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/zzz.php"] [unique_id "al9KkSBMYeh5YLVG45yV1gAAAjo"]
[Tue Jul 21 07:31:45.449849 2026] [security2:error] [pid 229246:tid 229274] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/chosen.php"] [unique_id "al9KkSBMYeh5YLVG45yV3QACFhs"]
[Tue Jul 21 07:31:45.468479 2026] [security2:error] [pid 229246:tid 229283] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/cream1.php"] [unique_id "al9KkSBMYeh5YLVG45yV3wACQiQ"]
[Tue Jul 21 07:31:45.532844 2026] [autoindex:error] [pid 229246:tid 229317] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:45.567629 2026] [autoindex:error] [pid 229246:tid 229278] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:45.609676 2026] [security2:error] [pid 229246:tid 229340] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/dr.php"] [unique_id "al9KkSBMYeh5YLVG45yV5gACRl0"]
[Tue Jul 21 07:31:45.627856 2026] [security2:error] [pid 229246:tid 229371] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/x.php"] [unique_id "al9KkSBMYeh5YLVG45yV5wACO3w"]
[Tue Jul 21 07:31:45.647666 2026] [security2:error] [pid 229246:tid 229329] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/155.php"] [unique_id "al9KkSBMYeh5YLVG45yV6AACWVI"]
[Tue Jul 21 07:31:45.660067 2026] [security2:error] [pid 229246:tid 229455] [client 193.36.225.66:44793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KkSBMYeh5YLVG45yV6QAAAmM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:45.716418 2026] [security2:error] [pid 229246:tid 229350] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ops.php"] [unique_id "al9KkSBMYeh5YLVG45yV6gACWGc"]
[Tue Jul 21 07:31:45.736760 2026] [security2:error] [pid 229246:tid 229252] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/file31.php"] [unique_id "al9KkSBMYeh5YLVG45yV6wACXgU"]
[Tue Jul 21 07:31:45.830806 2026] [security2:error] [pid 229246:tid 229458] [client 82.102.28.107:59130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KkSBMYeh5YLVG45yV7wAAAmY"]
[Tue Jul 21 07:31:45.830913 2026] [security2:error] [pid 229246:tid 229458] [client 82.102.28.107:59130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KkSBMYeh5YLVG45yV7wAAAmY"]
[Tue Jul 21 07:31:45.905603 2026] [security2:error] [pid 229246:tid 229483] [client 117.217.38.194:53226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkSBMYeh5YLVG45yV8gAAAn8"]
[Tue Jul 21 07:31:45.905786 2026] [security2:error] [pid 229246:tid 229483] [client 117.217.38.194:53226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KkSBMYeh5YLVG45yV8gAAAn8"]
[Tue Jul 21 07:31:46.091251 2026] [security2:error] [pid 229246:tid 229475] [client 20.151.10.161:58055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ha.php"] [unique_id "al9KkiBMYeh5YLVG45yV-AAAAnc"]
[Tue Jul 21 07:31:46.233987 2026] [security2:error] [pid 229246:tid 229253] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/file6.php"] [unique_id "al9KkiBMYeh5YLVG45yV-gACYAY"]
[Tue Jul 21 07:31:46.292403 2026] [security2:error] [pid 229246:tid 229461] [client 20.206.105.145:7443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/solo1.php"] [unique_id "al9KkiBMYeh5YLVG45yV_AAAAmk"]
[Tue Jul 21 07:31:46.343086 2026] [security2:error] [pid 229246:tid 229264] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KkiBMYeh5YLVG45yV_QAChBE"]
[Tue Jul 21 07:31:46.343233 2026] [security2:error] [pid 229246:tid 229488] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KkiBMYeh5YLVG45yV_QAChBE"]
[Tue Jul 21 07:31:46.471904 2026] [security2:error] [pid 229246:tid 229469] [client 20.220.225.223:8071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/la.php"] [unique_id "al9KkiBMYeh5YLVG45yWAgAAAnE"]
[Tue Jul 21 07:31:46.485273 2026] [security2:error] [pid 229246:tid 229456] [client 62.102.148.164:51650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9KkiBMYeh5YLVG45yWBAAAAmQ"]
[Tue Jul 21 07:31:46.485347 2026] [security2:error] [pid 229246:tid 229456] [client 62.102.148.164:51650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9KkiBMYeh5YLVG45yWBAAAAmQ"]
[Tue Jul 21 07:31:46.514587 2026] [autoindex:error] [pid 229246:tid 229285] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:46.535542 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.192.193:60972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KkiBMYeh5YLVG45yWCAAAAik"]
[Tue Jul 21 07:31:46.536170 2026] [security2:error] [pid 229246:tid 229373] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/adminfuns.php"] [unique_id "al9KkiBMYeh5YLVG45yWCQACFH4"]
[Tue Jul 21 07:31:46.548092 2026] [security2:error] [pid 229246:tid 229309] [remote 180.153.236.33:57421] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com.br"] [uri "/"] [unique_id "al9KkiBMYeh5YLVG45yWCgACLz4"], referer: https://gradiente.com.br/
[Tue Jul 21 07:31:46.548641 2026] [security2:error] [pid 229246:tid 229403] [client 180.153.236.33:57421] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com.br"] [uri "/"] [unique_id "al9KkiBMYeh5YLVG45yWCgACLz4"], referer: https://gradiente.com.br/
[Tue Jul 21 07:31:46.557194 2026] [security2:error] [pid 229246:tid 229311] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/goods.php"] [unique_id "al9KkiBMYeh5YLVG45yWCwACdkA"]
[Tue Jul 21 07:31:46.609796 2026] [security2:error] [pid 229246:tid 229441] [client 20.197.192.193:44793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KkiBMYeh5YLVG45yWDQAAAlU"]
[Tue Jul 21 07:31:46.612629 2026] [security2:error] [pid 229246:tid 229355] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/100.php"] [unique_id "al9KkiBMYeh5YLVG45yWDgACGWw"]
[Tue Jul 21 07:31:46.634307 2026] [security2:error] [pid 229246:tid 229415] [client 20.197.192.193:60934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/dp.php"] [unique_id "al9KkiBMYeh5YLVG45yWDwAAAjs"]
[Tue Jul 21 07:31:46.671840 2026] [security2:error] [pid 229246:tid 229450] [client 20.197.192.193:60942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/old.php"] [unique_id "al9KkiBMYeh5YLVG45yWEAAAAl4"]
[Tue Jul 21 07:31:46.690835 2026] [security2:error] [pid 229246:tid 229458] [client 45.8.17.128:35389] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/themes/admin.php"] [unique_id "al9KkiBMYeh5YLVG45yWEQAAAmY"]
[Tue Jul 21 07:31:46.776288 2026] [security2:error] [pid 229246:tid 229448] [client 20.220.225.223:61968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/edit.php"] [unique_id "al9KkiBMYeh5YLVG45yWFQAAAlw"]
[Tue Jul 21 07:31:46.794531 2026] [security2:error] [pid 229246:tid 229468] [client 20.197.192.193:60971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/ms-new.php"] [unique_id "al9KkiBMYeh5YLVG45yWFgAAAnA"]
[Tue Jul 21 07:31:46.887078 2026] [security2:error] [pid 229246:tid 229493] [client 20.197.192.193:44771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/track.php"] [unique_id "al9KkiBMYeh5YLVG45yWHAAAAok"]
[Tue Jul 21 07:31:46.892336 2026] [security2:error] [pid 229246:tid 229287] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KkiBMYeh5YLVG45yWHgACNig"]
[Tue Jul 21 07:31:46.892461 2026] [security2:error] [pid 229246:tid 229410] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KkiBMYeh5YLVG45yWHgACNig"]
[Tue Jul 21 07:31:46.953639 2026] [security2:error] [pid 229246:tid 229477] [client 20.151.10.161:57375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/hur.php"] [unique_id "al9KkiBMYeh5YLVG45yWIwAAAnk"]
[Tue Jul 21 07:31:46.960676 2026] [security2:error] [pid 229246:tid 229452] [client 20.197.192.193:60979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/2352356666.php"] [unique_id "al9KkiBMYeh5YLVG45yWJAAAAmA"]
[Tue Jul 21 07:31:47.013701 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:60984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/pn.php"] [unique_id "al9KkyBMYeh5YLVG45yWJQAAAoQ"]
[Tue Jul 21 07:31:47.087437 2026] [security2:error] [pid 229246:tid 229257] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/about.php"] [unique_id "al9KkyBMYeh5YLVG45yWJwACTwo"]
[Tue Jul 21 07:31:47.106012 2026] [security2:error] [pid 229246:tid 229332] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/about.php"] [unique_id "al9KkyBMYeh5YLVG45yWKAACKlU"]
[Tue Jul 21 07:31:47.142839 2026] [security2:error] [pid 229246:tid 229247] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/admin.php"] [unique_id "al9KkyBMYeh5YLVG45yWKQACNQA"]
[Tue Jul 21 07:31:47.168690 2026] [security2:error] [pid 229246:tid 229379] [client 20.197.192.193:60990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9KkyBMYeh5YLVG45yWKgAAAhc"]
[Tue Jul 21 07:31:47.328761 2026] [security2:error] [pid 229246:tid 229427] [client 20.197.192.193:44778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/dr.php"] [unique_id "al9KkyBMYeh5YLVG45yWLAAAAkc"]
[Tue Jul 21 07:31:47.353654 2026] [security2:error] [pid 229246:tid 229374] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/admin.php"] [unique_id "al9KkyBMYeh5YLVG45yWLwACRH8"]
[Tue Jul 21 07:31:47.361130 2026] [security2:error] [pid 229246:tid 229499] [client 20.197.192.193:54088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/2x.php"] [unique_id "al9KkyBMYeh5YLVG45yWMAAAAo8"]
[Tue Jul 21 07:31:47.387394 2026] [security2:error] [pid 229246:tid 229376] [client 20.151.10.161:50920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/h02ugyh.php"] [unique_id "al9KkyBMYeh5YLVG45yWMQAAAhQ"]
[Tue Jul 21 07:31:47.414402 2026] [security2:error] [pid 229246:tid 229474] [client 20.197.192.193:60957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/kq1.php"] [unique_id "al9KkyBMYeh5YLVG45yWMgAAAnY"]
[Tue Jul 21 07:31:47.487598 2026] [security2:error] [pid 229246:tid 229434] [client 20.197.192.193:44798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/zzz.php"] [unique_id "al9KkyBMYeh5YLVG45yWOAAAAk4"]
[Tue Jul 21 07:31:47.526353 2026] [security2:error] [pid 229246:tid 229489] [client 20.197.192.193:44782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wicked.php"] [unique_id "al9KkyBMYeh5YLVG45yWPQAAAoU"]
[Tue Jul 21 07:31:47.616894 2026] [security2:error] [pid 229246:tid 229416] [client 20.197.192.193:44749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/edit.php"] [unique_id "al9KkyBMYeh5YLVG45yWQAAAAjw"]
[Tue Jul 21 07:31:47.649470 2026] [security2:error] [pid 229246:tid 229444] [client 20.197.192.193:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/kua.php"] [unique_id "al9KkyBMYeh5YLVG45yWQgAAAlg"]
[Tue Jul 21 07:31:47.681062 2026] [security2:error] [pid 229246:tid 229263] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KkyBMYeh5YLVG45yWRwACixA"]
[Tue Jul 21 07:31:47.681198 2026] [security2:error] [pid 229246:tid 229495] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KkyBMYeh5YLVG45yWRwACixA"]
[Tue Jul 21 07:31:47.687219 2026] [security2:error] [pid 229246:tid 229404] [client 20.197.192.193:45098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/ez.php"] [unique_id "al9KkyBMYeh5YLVG45yWSAAAAjA"]
[Tue Jul 21 07:31:47.718474 2026] [security2:error] [pid 229246:tid 229313] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/themes.php"] [unique_id "al9KkyBMYeh5YLVG45yWSQACdUI"]
[Tue Jul 21 07:31:47.761001 2026] [security2:error] [pid 229246:tid 229461] [client 20.151.10.161:51313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/seiso.php"] [unique_id "al9KkyBMYeh5YLVG45yWSwAAAmk"]
[Tue Jul 21 07:31:47.784568 2026] [security2:error] [pid 229246:tid 229436] [client 45.8.17.147:38041] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/PHPMailer/"] [unique_id "al9KkyBMYeh5YLVG45yWTgAAAlA"]
[Tue Jul 21 07:31:47.794529 2026] [security2:error] [pid 229246:tid 229488] [client 20.197.192.193:44756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/fz.php"] [unique_id "al9KkyBMYeh5YLVG45yWTwAAAoQ"]
[Tue Jul 21 07:31:47.841624 2026] [security2:error] [pid 229246:tid 229389] [client 20.197.192.193:44736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/la.php"] [unique_id "al9KkyBMYeh5YLVG45yWUAAAAiE"]
[Tue Jul 21 07:31:47.903587 2026] [autoindex:error] [pid 229246:tid 229279] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:47.944052 2026] [security2:error] [pid 229246:tid 229379] [client 20.197.192.193:60952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9KkyBMYeh5YLVG45yWVAAAAhc"]
[Tue Jul 21 07:31:47.994798 2026] [security2:error] [pid 229246:tid 229499] [client 20.206.105.145:38921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/fpwch.php"] [unique_id "al9KkyBMYeh5YLVG45yWWAAAAo8"]
[Tue Jul 21 07:31:48.069198 2026] [security2:error] [pid 229246:tid 229445] [client 20.197.192.193:44775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/inso.php"] [unique_id "al9KlCBMYeh5YLVG45yWXQAAAlk"]
[Tue Jul 21 07:31:48.079328 2026] [security2:error] [pid 229246:tid 229337] [remote 216.73.160.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-login.php"] [unique_id "al9KlCBMYeh5YLVG45yWXgACHFo"]
[Tue Jul 21 07:31:48.096403 2026] [security2:error] [pid 229246:tid 229450] [client 20.151.10.161:57352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/155.php"] [unique_id "al9KlCBMYeh5YLVG45yWYgAAAl4"]
[Tue Jul 21 07:31:48.122490 2026] [security2:error] [pid 229246:tid 229429] [client 20.197.192.193:54085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wpx.php"] [unique_id "al9KlCBMYeh5YLVG45yWZAAAAkk"]
[Tue Jul 21 07:31:48.189592 2026] [security2:error] [pid 229246:tid 229435] [client 173.252.95.4:58934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KlCBMYeh5YLVG45yWWgAAAk8"]
[Tue Jul 21 07:31:48.251801 2026] [security2:error] [pid 229246:tid 229466] [client 20.220.225.223:6814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/nhvoanpl.php"] [unique_id "al9KlCBMYeh5YLVG45yWZgAAAm4"]
[Tue Jul 21 07:31:48.255671 2026] [security2:error] [pid 229246:tid 229470] [client 20.197.192.193:44740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/berlin.php"] [unique_id "al9KlCBMYeh5YLVG45yWZwAAAnI"]
[Tue Jul 21 07:31:48.289977 2026] [security2:error] [pid 229246:tid 229468] [client 20.197.192.193:44753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/billur.php"] [unique_id "al9KlCBMYeh5YLVG45yWaAAAAnA"]
[Tue Jul 21 07:31:48.344819 2026] [security2:error] [pid 229246:tid 229428] [client 20.197.192.193:60974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/mimpi.php"] [unique_id "al9KlCBMYeh5YLVG45yWagAAAkg"]
[Tue Jul 21 07:31:48.425514 2026] [security2:error] [pid 229246:tid 229444] [client 20.197.192.193:60947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/dp.php"] [unique_id "al9KlCBMYeh5YLVG45yWawAAAlg"]
[Tue Jul 21 07:31:48.463082 2026] [security2:error] [pid 229246:tid 229404] [client 20.151.10.161:57997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ppp.php"] [unique_id "al9KlCBMYeh5YLVG45yWbAAAAjA"]
[Tue Jul 21 07:31:48.487199 2026] [security2:error] [pid 229246:tid 229437] [client 20.197.192.193:44795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/bootstrap.php"] [unique_id "al9KlCBMYeh5YLVG45yWbQAAAlE"]
[Tue Jul 21 07:31:48.564118 2026] [security2:error] [pid 229246:tid 229389] [client 20.197.192.193:44776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wp-editor.php"] [unique_id "al9KlCBMYeh5YLVG45yWdAAAAiE"]
[Tue Jul 21 07:31:48.566472 2026] [security2:error] [pid 229246:tid 229385] [client 20.197.195.24:13122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KlCBMYeh5YLVG45yWdQAAAh0"]
[Tue Jul 21 07:31:48.583983 2026] [security2:error] [pid 229246:tid 229409] [client 20.197.192.193:44747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/cro.php"] [unique_id "al9KlCBMYeh5YLVG45yWdgAAAjU"]
[Tue Jul 21 07:31:48.607554 2026] [security2:error] [pid 229246:tid 229422] [client 20.197.192.193:54081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/cron-tab.php"] [unique_id "al9KlCBMYeh5YLVG45yWdwAAAkI"]
[Tue Jul 21 07:31:48.648087 2026] [security2:error] [pid 229246:tid 229460] [client 20.197.192.193:60959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/koiy.php"] [unique_id "al9KlCBMYeh5YLVG45yWeQAAAmg"]
[Tue Jul 21 07:31:48.732317 2026] [security2:error] [pid 229246:tid 229490] [client 20.197.192.193:45110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/hp2.php"] [unique_id "al9KlCBMYeh5YLVG45yWfAAAAoY"]
[Tue Jul 21 07:31:48.828467 2026] [security2:error] [pid 229246:tid 229445] [client 20.197.192.193:60936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/hp3.php"] [unique_id "al9KlCBMYeh5YLVG45yWfgAAAlk"]
[Tue Jul 21 07:31:48.835113 2026] [security2:error] [pid 229246:tid 229455] [client 20.220.225.223:46124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wp-editor.php"] [unique_id "al9KlCBMYeh5YLVG45yWfwAAAmM"]
[Tue Jul 21 07:31:48.865186 2026] [security2:error] [pid 229246:tid 229426] [client 20.151.10.161:51265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/201.php"] [unique_id "al9KlCBMYeh5YLVG45yWgAAAAkY"]
[Tue Jul 21 07:31:48.889839 2026] [security2:error] [pid 229246:tid 229384] [client 20.197.192.193:44764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/aa1.php"] [unique_id "al9KlCBMYeh5YLVG45yWgQAAAhw"]
[Tue Jul 21 07:31:48.902257 2026] [security2:error] [pid 229246:tid 229430] [client 20.220.225.223:4176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/kua.php"] [unique_id "al9KlCBMYeh5YLVG45yWhAAAAko"]
[Tue Jul 21 07:31:48.975507 2026] [security2:error] [pid 229246:tid 229412] [client 20.197.192.193:60951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/acew67.php"] [unique_id "al9KlCBMYeh5YLVG45yWhgAAAjg"]
[Tue Jul 21 07:31:49.088353 2026] [security2:error] [pid 229246:tid 229416] [client 20.197.192.193:44773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/bscclapb.php"] [unique_id "al9KlSBMYeh5YLVG45yWjgAAAjw"]
[Tue Jul 21 07:31:49.104014 2026] [security2:error] [pid 229246:tid 229444] [client 20.197.192.193:54107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/else1.php"] [unique_id "al9KlSBMYeh5YLVG45yWjwAAAlg"]
[Tue Jul 21 07:31:49.126264 2026] [security2:error] [pid 229246:tid 229494] [client 20.197.192.193:44762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/tkikikoko.php"] [unique_id "al9KlSBMYeh5YLVG45yWkgAAAoo"]
[Tue Jul 21 07:31:49.164468 2026] [security2:error] [pid 229246:tid 229248] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/.well-known/about.php"] [unique_id "al9KlSBMYeh5YLVG45yWkwACaQE"]
[Tue Jul 21 07:31:49.186438 2026] [security2:error] [pid 229246:tid 229436] [client 20.206.105.145:54537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/sixxis.php"] [unique_id "al9KlSBMYeh5YLVG45yWlAAAAlA"]
[Tue Jul 21 07:31:49.192018 2026] [security2:error] [pid 229246:tid 229277] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9KlSBMYeh5YLVG45yWlQACcx4"]
[Tue Jul 21 07:31:49.196026 2026] [security2:error] [pid 229246:tid 229389] [client 20.197.192.193:54080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9KlSBMYeh5YLVG45yWlgAAAiE"]
[Tue Jul 21 07:31:49.237686 2026] [security2:error] [pid 229246:tid 229381] [client 20.220.225.223:62135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/bootstrap.php"] [unique_id "al9KlSBMYeh5YLVG45yWmgAAAhk"]
[Tue Jul 21 07:31:49.246960 2026] [security2:error] [pid 229246:tid 229379] [client 20.151.10.161:57465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ops.php"] [unique_id "al9KlSBMYeh5YLVG45yWnAAAAhc"]
[Tue Jul 21 07:31:49.301828 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.192.193:60928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wp-css.php"] [unique_id "al9KlSBMYeh5YLVG45yWoQAAAik"]
[Tue Jul 21 07:31:49.339752 2026] [security2:error] [pid 229246:tid 229376] [client 20.52.136.55:1743] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "webmail.gradiente.com"] [uri "/.info.php"] [unique_id "al9KlSBMYeh5YLVG45yWogAAAhQ"]
[Tue Jul 21 07:31:49.352609 2026] [security2:error] [pid 229246:tid 229345] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wefile.php"] [unique_id "al9KlSBMYeh5YLVG45yWowACfmI"]
[Tue Jul 21 07:31:49.366211 2026] [security2:error] [pid 229246:tid 229433] [client 20.220.225.223:4581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/ez.php"] [unique_id "al9KlSBMYeh5YLVG45yWpAAAAk0"]
[Tue Jul 21 07:31:49.408140 2026] [security2:error] [pid 229246:tid 229499] [client 20.197.192.193:44799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/wp-explorer.php"] [unique_id "al9KlSBMYeh5YLVG45yWpgAAAo8"]
[Tue Jul 21 07:31:49.513530 2026] [security2:error] [pid 229246:tid 229408] [client 20.220.225.223:8094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/inso.php"] [unique_id "al9KlSBMYeh5YLVG45yWqAAAAjQ"]
[Tue Jul 21 07:31:49.556710 2026] [security2:error] [pid 229246:tid 229464] [client 20.151.10.161:57995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ingfo.php"] [unique_id "al9KlSBMYeh5YLVG45yWqQAAAmw"]
[Tue Jul 21 07:31:49.577458 2026] [security2:error] [pid 229246:tid 229492] [client 193.36.225.68:55209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KlSBMYeh5YLVG45yWrQAAAog"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:49.581870 2026] [security2:error] [pid 229246:tid 229500] [client 20.197.192.193:45072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/akismet.php"] [unique_id "al9KlSBMYeh5YLVG45yWrwAAApA"]
[Tue Jul 21 07:31:49.592772 2026] [security2:error] [pid 229246:tid 229485] [client 45.8.17.115:20967] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/wp-file-manager/file_folder_manager.php"] [unique_id "al9KlSBMYeh5YLVG45yWsQAAAoE"]
[Tue Jul 21 07:31:49.681315 2026] [security2:error] [pid 229246:tid 229404] [client 20.197.192.193:60988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/ace2.php"] [unique_id "al9KlSBMYeh5YLVG45yWtwAAAjA"]
[Tue Jul 21 07:31:49.696796 2026] [security2:error] [pid 229246:tid 229339] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9KlSBMYeh5YLVG45yWuAACilw"]
[Tue Jul 21 07:31:49.798830 2026] [autoindex:error] [pid 229246:tid 229370] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:49.805125 2026] [security2:error] [pid 229246:tid 229461] [client 20.197.192.193:44786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/ms.php"] [unique_id "al9KlSBMYeh5YLVG45yWvgAAAmk"]
[Tue Jul 21 07:31:49.858919 2026] [security2:error] [pid 229246:tid 229381] [client 20.151.10.161:57471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/error_log.php"] [unique_id "al9KlSBMYeh5YLVG45yWwQAAAhk"]
[Tue Jul 21 07:31:49.889260 2026] [autoindex:error] [pid 229246:tid 229367] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:49.925713 2026] [security2:error] [pid 229246:tid 229397] [client 20.197.195.24:13126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9KlSBMYeh5YLVG45yWwgAAAik"]
[Tue Jul 21 07:31:49.940115 2026] [security2:error] [pid 229246:tid 229356] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9KlSBMYeh5YLVG45yWwwACfW0"]
[Tue Jul 21 07:31:49.958424 2026] [security2:error] [pid 229246:tid 229267] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/8.php"] [unique_id "al9KlSBMYeh5YLVG45yWxAACQhQ"]
[Tue Jul 21 07:31:50.014534 2026] [security2:error] [pid 229246:tid 229391] [client 59.96.220.140:59962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yWxQAAAiM"]
[Tue Jul 21 07:31:50.014634 2026] [security2:error] [pid 229246:tid 229391] [client 59.96.220.140:59962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yWxQAAAiM"]
[Tue Jul 21 07:31:50.044547 2026] [security2:error] [pid 229246:tid 229305] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yWxgACVTo"]
[Tue Jul 21 07:31:50.044647 2026] [security2:error] [pid 229246:tid 229441] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yWxgACVTo"]
[Tue Jul 21 07:31:50.116575 2026] [security2:error] [pid 229246:tid 229296] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9KliBMYeh5YLVG45yWywACYzE"]
[Tue Jul 21 07:31:50.135387 2026] [security2:error] [pid 229246:tid 229274] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/f6.php"] [unique_id "al9KliBMYeh5YLVG45yWzwACkhs"]
[Tue Jul 21 07:31:50.203695 2026] [security2:error] [pid 229246:tid 229283] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/inputs.php"] [unique_id "al9KliBMYeh5YLVG45yW0gACiCQ"]
[Tue Jul 21 07:31:50.251689 2026] [security2:error] [pid 229246:tid 229317] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/inputs.php"] [unique_id "al9KliBMYeh5YLVG45yW1AACXUY"]
[Tue Jul 21 07:31:50.269463 2026] [security2:error] [pid 229246:tid 229466] [client 20.220.225.223:38693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/jga.php"] [unique_id "al9KliBMYeh5YLVG45yW1QAAAm4"]
[Tue Jul 21 07:31:50.273326 2026] [security2:error] [pid 229246:tid 229278] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/classwithtostring.php"] [unique_id "al9KliBMYeh5YLVG45yW1gACOB8"]
[Tue Jul 21 07:31:50.286929 2026] [security2:error] [pid 229246:tid 229485] [client 20.151.10.161:51282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/xenon1337.php"] [unique_id "al9KliBMYeh5YLVG45yW1wAAAoE"]
[Tue Jul 21 07:31:50.291970 2026] [security2:error] [pid 229246:tid 229298] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9KliBMYeh5YLVG45yW2AACXzM"]
[Tue Jul 21 07:31:50.382807 2026] [security2:error] [pid 229246:tid 229475] [client 45.8.17.107:33821] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "al9KliBMYeh5YLVG45yW2wAAAnc"]
[Tue Jul 21 07:31:50.431777 2026] [security2:error] [pid 229246:tid 229329] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-blog.php"] [unique_id "al9KliBMYeh5YLVG45yW3AACPFI"]
[Tue Jul 21 07:31:50.495662 2026] [security2:error] [pid 229246:tid 229470] [client 139.167.225.182:59292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW3QAAAnI"]
[Tue Jul 21 07:31:50.495759 2026] [security2:error] [pid 229246:tid 229470] [client 139.167.225.182:59292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW3QAAAnI"]
[Tue Jul 21 07:31:50.509347 2026] [autoindex:error] [pid 229246:tid 229350] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:50.511085 2026] [security2:error] [pid 229246:tid 229252] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW3wACWAU"]
[Tue Jul 21 07:31:50.511188 2026] [security2:error] [pid 229246:tid 229444] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW3wACWAU"]
[Tue Jul 21 07:31:50.531106 2026] [security2:error] [pid 229246:tid 229308] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9KliBMYeh5YLVG45yW4AACPz0"]
[Tue Jul 21 07:31:50.704195 2026] [security2:error] [pid 229246:tid 229461] [client 20.151.10.161:51316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/test11.php"] [unique_id "al9KliBMYeh5YLVG45yW5wAAAmk"]
[Tue Jul 21 07:31:50.742434 2026] [security2:error] [pid 229246:tid 229294] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW6AACdS8"]
[Tue Jul 21 07:31:50.742658 2026] [security2:error] [pid 229246:tid 229473] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW6AACdS8"]
[Tue Jul 21 07:31:50.815082 2026] [security2:error] [pid 229246:tid 229399] [client 213.152.162.104:37222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW6wAAAis"]
[Tue Jul 21 07:31:50.815186 2026] [security2:error] [pid 229246:tid 229399] [client 213.152.162.104:37222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW6wAAAis"]
[Tue Jul 21 07:31:50.849583 2026] [access_compat:error] [pid 229246:tid 229438] [client 162.241.63.68:11734] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:31:50.911474 2026] [security2:error] [pid 229246:tid 229497] [client 103.162.129.114:57315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW7QAAAo0"]
[Tue Jul 21 07:31:50.911612 2026] [security2:error] [pid 229246:tid 229497] [client 103.162.129.114:57315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KliBMYeh5YLVG45yW7QAAAo0"]
[Tue Jul 21 07:31:50.916160 2026] [security2:error] [pid 229246:tid 229253] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ms-edit.php"] [unique_id "al9KliBMYeh5YLVG45yW7gACOgY"]
[Tue Jul 21 07:31:50.917486 2026] [security2:error] [pid 229246:tid 229481] [client 20.206.105.145:7400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/2P.update.php"] [unique_id "al9KliBMYeh5YLVG45yW7wAAAn0"]
[Tue Jul 21 07:31:50.936020 2026] [security2:error] [pid 229246:tid 229264] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9KliBMYeh5YLVG45yW8AACQhE"]
[Tue Jul 21 07:31:50.970881 2026] [autoindex:error] [pid 229246:tid 229255] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:50.995140 2026] [security2:error] [pid 229246:tid 229357] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9KliBMYeh5YLVG45yW8wACe24"]
[Tue Jul 21 07:31:51.030848 2026] [security2:error] [pid 229246:tid 229474] [client 20.197.195.24:13084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/media.php"] [unique_id "al9KlyBMYeh5YLVG45yW9AAAAnY"]
[Tue Jul 21 07:31:51.096738 2026] [security2:error] [pid 229246:tid 229445] [client 213.152.162.104:42006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KlyBMYeh5YLVG45yW9QAAAlk"]
[Tue Jul 21 07:31:51.096810 2026] [security2:error] [pid 229246:tid 229445] [client 213.152.162.104:42006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KlyBMYeh5YLVG45yW9QAAAlk"]
[Tue Jul 21 07:31:51.178034 2026] [autoindex:error] [pid 229246:tid 229309] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:51.189315 2026] [security2:error] [pid 229246:tid 229386] [client 20.151.10.161:50919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/koala.php"] [unique_id "al9KlyBMYeh5YLVG45yW-gAAAh4"]
[Tue Jul 21 07:31:51.225434 2026] [autoindex:error] [pid 229246:tid 229355] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:51.249894 2026] [security2:error] [pid 229246:tid 229368] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/abcd.php"] [unique_id "al9KlyBMYeh5YLVG45yW_wACXXk"]
[Tue Jul 21 07:31:51.332370 2026] [security2:error] [pid 229246:tid 229284] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/file15.php"] [unique_id "al9KlyBMYeh5YLVG45yXBwACPCU"]
[Tue Jul 21 07:31:51.385933 2026] [security2:error] [pid 229246:tid 229429] [client 122.186.204.214:57138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KlyBMYeh5YLVG45yXCAAAAkk"]
[Tue Jul 21 07:31:51.386095 2026] [security2:error] [pid 229246:tid 229429] [client 122.186.204.214:57138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KlyBMYeh5YLVG45yXCAAAAkk"]
[Tue Jul 21 07:31:51.428063 2026] [security2:error] [pid 229246:tid 229287] [remote 104.207.39.187:45425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.39.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9KlyBMYeh5YLVG45yXAQACVSg"]
[Tue Jul 21 07:31:51.691929 2026] [security2:error] [pid 229246:tid 229495] [client 45.8.17.138:24807] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/about.php"] [unique_id "al9KlyBMYeh5YLVG45yXEAAAAos"]
[Tue Jul 21 07:31:51.714852 2026] [security2:error] [pid 229246:tid 229488] [client 20.151.10.161:57374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/mac.php"] [unique_id "al9KlyBMYeh5YLVG45yXEgAAAoQ"]
[Tue Jul 21 07:31:52.012422 2026] [security2:error] [pid 229246:tid 229290] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KmCBMYeh5YLVG45yXFgACKys"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:52.016942 2026] [security2:error] [pid 229246:tid 229293] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KmCBMYeh5YLVG45yXGAACfS4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:52.048205 2026] [security2:error] [pid 229246:tid 229258] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KmCBMYeh5YLVG45yXGQACGQs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:52.055942 2026] [security2:error] [pid 229246:tid 229336] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/jp.php"] [unique_id "al9KmCBMYeh5YLVG45yXGgACFFk"]
[Tue Jul 21 07:31:52.122674 2026] [security2:error] [pid 229246:tid 229301] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KmCBMYeh5YLVG45yXGwACOjY"]
[Tue Jul 21 07:31:52.122916 2026] [security2:error] [pid 229246:tid 229414] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KmCBMYeh5YLVG45yXGwACOjY"]
[Tue Jul 21 07:31:52.125590 2026] [security2:error] [pid 229246:tid 229360] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/f35.php"] [unique_id "al9KmCBMYeh5YLVG45yXHAACfnE"]
[Tue Jul 21 07:31:52.147437 2026] [security2:error] [pid 229246:tid 229319] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-load.php"] [unique_id "al9KmCBMYeh5YLVG45yXHQACI0g"]
[Tue Jul 21 07:31:52.178267 2026] [security2:error] [pid 229246:tid 229374] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9KmCBMYeh5YLVG45yXFwACIX8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:52.193346 2026] [security2:error] [pid 229246:tid 229263] [remote 207.180.241.245:49690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9KmCBMYeh5YLVG45yXHgACKRA"]
[Tue Jul 21 07:31:52.558528 2026] [security2:error] [pid 229246:tid 229497] [client 103.106.20.201:65520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KmCBMYeh5YLVG45yXIAAAAo0"]
[Tue Jul 21 07:31:52.558652 2026] [security2:error] [pid 229246:tid 229497] [client 103.106.20.201:65520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KmCBMYeh5YLVG45yXIAAAAo0"]
[Tue Jul 21 07:31:53.050990 2026] [http2:info] [pid 254995:tid 254995] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 07:31:53.070677 2026] [security2:error] [pid 254995:tid 255126] [client 20.206.105.145:7191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/a.php"] [unique_id "al9Kmf7v0rlcEGmVraEfHQAAAx8"]
[Tue Jul 21 07:31:53.071245 2026] [security2:error] [pid 254995:tid 255125] [client 20.151.10.161:57400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9Kmf7v0rlcEGmVraEfHgAAAx4"]
[Tue Jul 21 07:31:53.071269 2026] [security2:error] [pid 254995:tid 255129] [client 20.197.195.24:13169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/images.php"] [unique_id "al9Kmf7v0rlcEGmVraEfHwAAAyI"]
[Tue Jul 21 07:31:53.072970 2026] [security2:error] [pid 254995:tid 255133] [client 45.8.17.122:43029] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/sitemaps/admin.php"] [unique_id "al9Kmf7v0rlcEGmVraEfIQAAAyY"]
[Tue Jul 21 07:31:53.072986 2026] [security2:error] [pid 254995:tid 255134] [client 20.220.225.223:8917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/wp-editor.php"] [unique_id "al9Kmf7v0rlcEGmVraEfIAAAAyc"]
[Tue Jul 21 07:31:53.077636 2026] [security2:error] [pid 254995:tid 255123] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/xyn.php"] [unique_id "al9Kmf7v0rlcEGmVraEfIwADIH8"]
[Tue Jul 21 07:31:53.106580 2026] [autoindex:error] [pid 254995:tid 254997] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:53.120625 2026] [security2:error] [pid 254995:tid 255152] [client 20.220.225.223:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/cro.php"] [unique_id "al9Kmf7v0rlcEGmVraEfJQAAAzk"]
[Tue Jul 21 07:31:53.208598 2026] [autoindex:error] [pid 254995:tid 254998] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:53.231576 2026] [security2:error] [pid 254995:tid 255003] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ccc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfLwADQgc"]
[Tue Jul 21 07:31:53.243419 2026] [security2:error] [pid 254995:tid 255005] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfMQADRgk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.243698 2026] [security2:error] [pid 254995:tid 255007] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfMwADSAs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.243795 2026] [security2:error] [pid 254995:tid 255006] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfMgADRwo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.243954 2026] [security2:error] [pid 254995:tid 255008] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfNAADSQw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.292570 2026] [security2:error] [pid 254995:tid 255009] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/w.php"] [unique_id "al9Kmf7v0rlcEGmVraEfNQADUg0"]
[Tue Jul 21 07:31:53.315070 2026] [security2:error] [pid 254995:tid 255011] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Kmf7v0rlcEGmVraEfNwADVA8"]
[Tue Jul 21 07:31:53.335923 2026] [security2:error] [pid 254995:tid 255012] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/FWAZ.php"] [unique_id "al9Kmf7v0rlcEGmVraEfOgADWhA"]
[Tue Jul 21 07:31:53.375891 2026] [security2:error] [pid 254995:tid 255137] [client 173.24.185.52:56361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfPAAAAyo"]
[Tue Jul 21 07:31:53.376036 2026] [security2:error] [pid 254995:tid 255137] [client 173.24.185.52:56361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfPAAAAyo"]
[Tue Jul 21 07:31:53.393915 2026] [security2:error] [pid 254995:tid 255014] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/miru1.php"] [unique_id "al9Kmf7v0rlcEGmVraEfPQADXRI"]
[Tue Jul 21 07:31:53.457941 2026] [security2:error] [pid 254995:tid 255018] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfQwADZxY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.468400 2026] [security2:error] [pid 254995:tid 255019] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfRQADahc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.490757 2026] [security2:error] [pid 254995:tid 255203] [client 20.220.225.223:4571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/fz.php"] [unique_id "al9Kmf7v0rlcEGmVraEfRwAAA2w"]
[Tue Jul 21 07:31:53.533789 2026] [security2:error] [pid 254995:tid 255021] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfSgADchk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.570043 2026] [security2:error] [pid 254995:tid 255022] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/aa.php"] [unique_id "al9Kmf7v0rlcEGmVraEfSwADcxo"]
[Tue Jul 21 07:31:53.584202 2026] [security2:error] [pid 254995:tid 255023] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfTAADdxs"]
[Tue Jul 21 07:31:53.584317 2026] [security2:error] [pid 254995:tid 255215] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfTAADdxs"]
[Tue Jul 21 07:31:53.592654 2026] [security2:error] [pid 254995:tid 255024] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfTQADeBw"]
[Tue Jul 21 07:31:53.592875 2026] [security2:error] [pid 254995:tid 255216] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfTQADeBw"]
[Tue Jul 21 07:31:53.608371 2026] [security2:error] [pid 254995:tid 255025] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/122.php"] [unique_id "al9Kmf7v0rlcEGmVraEfTgADeh0"]
[Tue Jul 21 07:31:53.683584 2026] [security2:error] [pid 254995:tid 255222] [client 20.151.10.161:57397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wefile.php"] [unique_id "al9Kmf7v0rlcEGmVraEfTwAAA34"]
[Tue Jul 21 07:31:53.695679 2026] [security2:error] [pid 254995:tid 255026] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfUAADfx4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.758770 2026] [security2:error] [pid 254995:tid 255027] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/get.php"] [unique_id "al9Kmf7v0rlcEGmVraEfUQADgR8"]
[Tue Jul 21 07:31:53.765726 2026] [security2:error] [pid 254995:tid 255139] [client 154.192.233.199:59426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfUgAAAyw"]
[Tue Jul 21 07:31:53.765886 2026] [security2:error] [pid 254995:tid 255139] [client 154.192.233.199:59426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmf7v0rlcEGmVraEfUgAAAyw"]
[Tue Jul 21 07:31:53.768913 2026] [security2:error] [pid 254995:tid 255028] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfUwADgiA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.778362 2026] [security2:error] [pid 254995:tid 255029] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/as.php"] [unique_id "al9Kmf7v0rlcEGmVraEfVAADgyE"]
[Tue Jul 21 07:31:53.804966 2026] [security2:error] [pid 254995:tid 255030] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfVQADfSI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.915069 2026] [security2:error] [pid 254995:tid 255031] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmf7v0rlcEGmVraEfVgADhyM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:53.927427 2026] [security2:error] [pid 254995:tid 255032] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ccou.php"] [unique_id "al9Kmf7v0rlcEGmVraEfVwADiCQ"]
[Tue Jul 21 07:31:53.947903 2026] [security2:error] [pid 254995:tid 255033] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/w3lls.php"] [unique_id "al9Kmf7v0rlcEGmVraEfWAADiSU"]
[Tue Jul 21 07:31:53.968081 2026] [security2:error] [pid 254995:tid 255035] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/test1.php"] [unique_id "al9Kmf7v0rlcEGmVraEfXAADjSc"]
[Tue Jul 21 07:31:53.971146 2026] [security2:error] [pid 254995:tid 255265] [client 20.197.195.24:13179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/gecko.php"] [unique_id "al9Kmf7v0rlcEGmVraEfXQAAA48"]
[Tue Jul 21 07:31:53.989253 2026] [security2:error] [pid 254995:tid 255037] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/database.php"] [unique_id "al9Kmf7v0rlcEGmVraEfXwADlCk"]
[Tue Jul 21 07:31:54.001741 2026] [security2:error] [pid 254995:tid 255038] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmv7v0rlcEGmVraEfYAADlio"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:54.031183 2026] [security2:error] [pid 254995:tid 255039] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmv7v0rlcEGmVraEfYQADmSs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:54.039493 2026] [security2:error] [pid 254995:tid 255040] [remote 165.232.76.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.76.232.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmv7v0rlcEGmVraEfYgADmiw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:31:54.044256 2026] [security2:error] [pid 254995:tid 255041] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/file.php"] [unique_id "al9Kmv7v0rlcEGmVraEfYwADmy0"]
[Tue Jul 21 07:31:54.183535 2026] [security2:error] [pid 254995:tid 255046] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/file.php"] [unique_id "al9Kmv7v0rlcEGmVraEfawADNDI"]
[Tue Jul 21 07:31:54.203320 2026] [security2:error] [pid 254995:tid 255130] [client 172.245.102.46:38729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Kmv7v0rlcEGmVraEfbAAAAyM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:54.256210 2026] [security2:error] [pid 254995:tid 255148] [client 20.220.225.223:38673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/x.php"] [unique_id "al9Kmv7v0rlcEGmVraEfbQAAAzU"]
[Tue Jul 21 07:31:54.316426 2026] [security2:error] [pid 254995:tid 255151] [client 20.206.105.145:7367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/k.php"] [unique_id "al9Kmv7v0rlcEGmVraEfbgAAAzg"]
[Tue Jul 21 07:31:54.378430 2026] [security2:error] [pid 254995:tid 255047] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/777.php"] [unique_id "al9Kmv7v0rlcEGmVraEfbwADPDM"]
[Tue Jul 21 07:31:54.389015 2026] [security2:error] [pid 254995:tid 255158] [client 20.220.225.223:9222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wpx.php"] [unique_id "al9Kmv7v0rlcEGmVraEfcAAAAz8"]
[Tue Jul 21 07:31:54.426571 2026] [proxy:error] [pid 254995:tid 255162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:54.426612 2026] [proxy_http:error] [pid 254995:tid 255162] [client 20.151.10.161:51275] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:54.427176 2026] [proxy:error] [pid 254995:tid 255162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:54.427197 2026] [proxy_http:error] [pid 254995:tid 255162] [client 20.151.10.161:51275] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:54.432960 2026] [security2:error] [pid 254995:tid 255224] [client 175.45.70.82:50931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmv7v0rlcEGmVraEfcgAAA4A"]
[Tue Jul 21 07:31:54.433100 2026] [security2:error] [pid 254995:tid 255224] [client 175.45.70.82:50931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmv7v0rlcEGmVraEfcgAAA4A"]
[Tue Jul 21 07:31:54.601772 2026] [security2:error] [pid 254995:tid 255051] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ssixta.php"] [unique_id "al9Kmv7v0rlcEGmVraEfegADSzc"]
[Tue Jul 21 07:31:54.678496 2026] [security2:error] [pid 254995:tid 255172] [client 45.8.17.59:52259] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/widgets/maint/"] [unique_id "al9Kmv7v0rlcEGmVraEffQAAA00"]
[Tue Jul 21 07:31:54.753679 2026] [security2:error] [pid 254995:tid 255141] [client 103.174.34.15:59511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmv7v0rlcEGmVraEffgAAAy4"]
[Tue Jul 21 07:31:54.753822 2026] [security2:error] [pid 254995:tid 255141] [client 103.174.34.15:59511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kmv7v0rlcEGmVraEffgAAAy4"]
[Tue Jul 21 07:31:54.807298 2026] [security2:error] [pid 254995:tid 255054] [remote 113.160.142.119:43426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/wp-login.php"] [unique_id "al9Kmv7v0rlcEGmVraEffwADMzo"]
[Tue Jul 21 07:31:54.989172 2026] [security2:error] [pid 254995:tid 255057] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/1c.php"] [unique_id "al9Kmv7v0rlcEGmVraEfhgADXD0"]
[Tue Jul 21 07:31:55.042758 2026] [security2:error] [pid 254995:tid 255152] [client 45.251.232.145:64553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Km_7v0rlcEGmVraEfiwAAAzk"]
[Tue Jul 21 07:31:55.042887 2026] [security2:error] [pid 254995:tid 255152] [client 45.251.232.145:64553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Km_7v0rlcEGmVraEfiwAAAzk"]
[Tue Jul 21 07:31:55.212636 2026] [security2:error] [pid 254995:tid 255062] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/test2.php"] [unique_id "al9Km_7v0rlcEGmVraEfkgADdEI"]
[Tue Jul 21 07:31:55.226892 2026] [security2:error] [pid 254995:tid 255213] [client 20.197.195.24:13162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/82.php"] [unique_id "al9Km_7v0rlcEGmVraEfkwAAA3U"]
[Tue Jul 21 07:31:55.234027 2026] [security2:error] [pid 254995:tid 255063] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/buy.php"] [unique_id "al9Km_7v0rlcEGmVraEflAADdkM"]
[Tue Jul 21 07:31:55.277407 2026] [security2:error] [pid 254995:tid 255064] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ssend.php"] [unique_id "al9Km_7v0rlcEGmVraEflQADO0Q"]
[Tue Jul 21 07:31:55.366965 2026] [security2:error] [pid 254995:tid 255215] [client 213.152.162.104:37236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Km_7v0rlcEGmVraEflgAAA3c"]
[Tue Jul 21 07:31:55.367082 2026] [security2:error] [pid 254995:tid 255215] [client 213.152.162.104:37236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Km_7v0rlcEGmVraEflgAAA3c"]
[Tue Jul 21 07:31:55.416894 2026] [security2:error] [pid 254995:tid 255066] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/item.php"] [unique_id "al9Km_7v0rlcEGmVraEfmgADekY"]
[Tue Jul 21 07:31:55.553206 2026] [proxy:error] [pid 254995:tid 255178] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:55.553276 2026] [proxy_http:error] [pid 254995:tid 255178] [client 20.151.10.161:50906] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:55.553802 2026] [proxy:error] [pid 254995:tid 255178] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:31:55.553833 2026] [proxy_http:error] [pid 254995:tid 255178] [client 20.151.10.161:50906] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:31:55.669981 2026] [security2:error] [pid 254995:tid 255071] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ss.php"] [unique_id "al9Km_7v0rlcEGmVraEfpgADkEs"]
[Tue Jul 21 07:31:55.684491 2026] [security2:error] [pid 254995:tid 255185] [client 122.129.67.13:60578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9Km_7v0rlcEGmVraEfpAAAA1o"]
[Tue Jul 21 07:31:55.688349 2026] [security2:error] [pid 254995:tid 255072] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/hypo.php"] [unique_id "al9Km_7v0rlcEGmVraEfpwADikw"]
[Tue Jul 21 07:31:55.785218 2026] [security2:error] [pid 254995:tid 255275] [client 45.8.17.114:59261] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/classwithtostring.php"] [unique_id "al9Km_7v0rlcEGmVraEfqgAAA5k"]
[Tue Jul 21 07:31:56.061136 2026] [security2:error] [pid 254995:tid 255182] [client 152.59.154.239:60788] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KnP7v0rlcEGmVraEfqwAAA1c"]
[Tue Jul 21 07:31:56.061349 2026] [security2:error] [pid 254995:tid 255182] [client 152.59.154.239:60788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KnP7v0rlcEGmVraEfqwAAA1c"]
[Tue Jul 21 07:31:56.135862 2026] [security2:error] [pid 254995:tid 255153] [client 20.206.105.145:54576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/w.php"] [unique_id "al9KnP7v0rlcEGmVraEfswAAAzo"]
[Tue Jul 21 07:31:56.156243 2026] [security2:error] [pid 254995:tid 255078] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/users.php"] [unique_id "al9KnP7v0rlcEGmVraEftAADPFI"]
[Tue Jul 21 07:31:56.242747 2026] [security2:error] [pid 254995:tid 255079] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/177.php"] [unique_id "al9KnP7v0rlcEGmVraEftQADP1M"]
[Tue Jul 21 07:31:56.339684 2026] [security2:error] [pid 254995:tid 255081] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/config.php"] [unique_id "al9KnP7v0rlcEGmVraEftwADPVU"]
[Tue Jul 21 07:31:56.361297 2026] [security2:error] [pid 254995:tid 255082] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/gettest.php"] [unique_id "al9KnP7v0rlcEGmVraEfuAADKFY"]
[Tue Jul 21 07:31:56.441239 2026] [security2:error] [pid 254995:tid 255274] [client 117.217.38.194:53643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KnP7v0rlcEGmVraEfuQAAA5g"]
[Tue Jul 21 07:31:56.441405 2026] [security2:error] [pid 254995:tid 255274] [client 117.217.38.194:53643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KnP7v0rlcEGmVraEfuQAAA5g"]
[Tue Jul 21 07:31:56.484280 2026] [security2:error] [pid 254995:tid 255165] [client 82.102.28.107:33976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KnP7v0rlcEGmVraEfvQAAA0Y"]
[Tue Jul 21 07:31:56.484415 2026] [security2:error] [pid 254995:tid 255165] [client 82.102.28.107:33976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KnP7v0rlcEGmVraEfvQAAA0Y"]
[Tue Jul 21 07:31:56.484656 2026] [security2:error] [pid 254995:tid 255083] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/min.php"] [unique_id "al9KnP7v0rlcEGmVraEfvAADSFc"]
[Tue Jul 21 07:31:56.507067 2026] [security2:error] [pid 254995:tid 255084] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/dvjul.php"] [unique_id "al9KnP7v0rlcEGmVraEfvgADRFg"]
[Tue Jul 21 07:31:56.517148 2026] [security2:error] [pid 254995:tid 255085] [remote 192.241.143.148:40094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9KnP7v0rlcEGmVraEfvwADQFk"]
[Tue Jul 21 07:31:56.545644 2026] [security2:error] [pid 254995:tid 255168] [client 20.220.225.223:46139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/cron-tab.php"] [unique_id "al9KnP7v0rlcEGmVraEfwQAAA0k"]
[Tue Jul 21 07:31:56.619495 2026] [security2:error] [pid 254995:tid 255089] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/biufile.php"] [unique_id "al9KnP7v0rlcEGmVraEfxwADPl0"]
[Tue Jul 21 07:31:56.642214 2026] [security2:error] [pid 254995:tid 255090] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/av.php"] [unique_id "al9KnP7v0rlcEGmVraEfyQADLl4"]
[Tue Jul 21 07:31:56.670630 2026] [security2:error] [pid 254995:tid 255092] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/coffexium.php"] [unique_id "al9KnP7v0rlcEGmVraEfywADUmA"]
[Tue Jul 21 07:31:56.696029 2026] [security2:error] [pid 254995:tid 255093] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/core.php"] [unique_id "al9KnP7v0rlcEGmVraEfzAADM2E"]
[Tue Jul 21 07:31:56.736272 2026] [security2:error] [pid 254995:tid 255094] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/als.php"] [unique_id "al9KnP7v0rlcEGmVraEfzQADWGI"]
[Tue Jul 21 07:31:56.758206 2026] [security2:error] [pid 254995:tid 255095] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/simple.php"] [unique_id "al9KnP7v0rlcEGmVraEfzgADXWM"]
[Tue Jul 21 07:31:56.778302 2026] [security2:error] [pid 254995:tid 255096] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/init.php"] [unique_id "al9KnP7v0rlcEGmVraEfzwADKmQ"]
[Tue Jul 21 07:31:56.799927 2026] [security2:error] [pid 254995:tid 255097] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/fpwch.php"] [unique_id "al9KnP7v0rlcEGmVraEf0AADX2U"]
[Tue Jul 21 07:31:56.810273 2026] [security2:error] [pid 254995:tid 255173] [client 20.197.195.24:13145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/admin.php"] [unique_id "al9KnP7v0rlcEGmVraEf0QAAA04"]
[Tue Jul 21 07:31:56.823949 2026] [security2:error] [pid 254995:tid 255098] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/domvf.php"] [unique_id "al9KnP7v0rlcEGmVraEf0gADXGY"]
[Tue Jul 21 07:31:56.845477 2026] [security2:error] [pid 254995:tid 255099] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp.php"] [unique_id "al9KnP7v0rlcEGmVraEf0wADZ2c"]
[Tue Jul 21 07:31:56.883818 2026] [security2:error] [pid 254995:tid 255202] [client 45.8.17.129:62363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al9KnP7v0rlcEGmVraEf1AAAA2s"]
[Tue Jul 21 07:31:56.908470 2026] [security2:error] [pid 254995:tid 255100] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/class.php"] [unique_id "al9KnP7v0rlcEGmVraEf1QADbGg"]
[Tue Jul 21 07:31:57.154739 2026] [security2:error] [pid 254995:tid 255208] [client 20.220.225.223:19652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/wicked.php"] [unique_id "al9Knf7v0rlcEGmVraEf3AAAA3A"]
[Tue Jul 21 07:31:57.162885 2026] [security2:error] [pid 254995:tid 255103] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Knf7v0rlcEGmVraEf3QADYGs"]
[Tue Jul 21 07:31:57.163005 2026] [security2:error] [pid 254995:tid 255191] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Knf7v0rlcEGmVraEf3QADYGs"]
[Tue Jul 21 07:31:57.289017 2026] [security2:error] [pid 254995:tid 255106] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/echkm.php"] [unique_id "al9Knf7v0rlcEGmVraEf4gADUW4"]
[Tue Jul 21 07:31:57.354166 2026] [security2:error] [pid 254995:tid 255209] [client 20.206.105.145:7461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/insc.php"] [unique_id "al9Knf7v0rlcEGmVraEf4wAAA3E"]
[Tue Jul 21 07:31:57.415967 2026] [security2:error] [pid 254995:tid 255220] [client 20.151.10.161:50922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Knf7v0rlcEGmVraEf5AAAA3w"]
[Tue Jul 21 07:31:57.558177 2026] [security2:error] [pid 254995:tid 255108] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Knf7v0rlcEGmVraEf6AADhXA"]
[Tue Jul 21 07:31:57.558385 2026] [security2:error] [pid 254995:tid 255255] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Knf7v0rlcEGmVraEf6AADhXA"]
[Tue Jul 21 07:31:57.560627 2026] [security2:error] [pid 254995:tid 255109] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/lib.php"] [unique_id "al9Knf7v0rlcEGmVraEf6QADg3E"]
[Tue Jul 21 07:31:57.621056 2026] [security2:error] [pid 254995:tid 255111] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/login.php"] [unique_id "al9Knf7v0rlcEGmVraEf6wADU3M"]
[Tue Jul 21 07:31:57.638796 2026] [security2:error] [pid 254995:tid 255112] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/a2.php"] [unique_id "al9Knf7v0rlcEGmVraEf7gADgXQ"]
[Tue Jul 21 07:31:57.657458 2026] [security2:error] [pid 254995:tid 255113] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/d61.php"] [unique_id "al9Knf7v0rlcEGmVraEf7wADVnU"]
[Tue Jul 21 07:31:57.687833 2026] [security2:error] [pid 254995:tid 255264] [client 45.8.17.65:27709] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/modern/test2.php"] [unique_id "al9Knf7v0rlcEGmVraEf8gAAA44"]
[Tue Jul 21 07:31:57.779704 2026] [security2:error] [pid 254995:tid 255116] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/info.php"] [unique_id "al9Knf7v0rlcEGmVraEf9QADlXg"]
[Tue Jul 21 07:31:57.809967 2026] [security2:error] [pid 254995:tid 255117] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/11.php"] [unique_id "al9Knf7v0rlcEGmVraEf9gADmnk"]
[Tue Jul 21 07:31:57.830124 2026] [security2:error] [pid 254995:tid 255118] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/v2.php"] [unique_id "al9Knf7v0rlcEGmVraEf9wADm3o"]
[Tue Jul 21 07:31:57.867984 2026] [security2:error] [pid 254995:tid 255120] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/panel.php"] [unique_id "al9Knf7v0rlcEGmVraEf-QADMnw"]
[Tue Jul 21 07:31:57.910195 2026] [security2:error] [pid 254995:tid 255121] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/dex.php"] [unique_id "al9Knf7v0rlcEGmVraEf-gADNn0"]
[Tue Jul 21 07:31:58.036597 2026] [security2:error] [pid 254995:tid 255122] [remote 20.197.195.24:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mcandidoadvocacia.com.br"] [uri "/1.php"] [unique_id "al9Knv7v0rlcEGmVraEf-wADI34"]
[Tue Jul 21 07:31:58.036695 2026] [security2:error] [pid 254995:tid 255122] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/1.php"] [unique_id "al9Knv7v0rlcEGmVraEf-wADI34"]
[Tue Jul 21 07:31:58.059296 2026] [autoindex:error] [pid 254995:tid 255148] [client 172.252.90.143:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:58.066075 2026] [security2:error] [pid 254995:tid 254996] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Knv7v0rlcEGmVraEf_wADnQA"]
[Tue Jul 21 07:31:58.066194 2026] [security2:error] [pid 254995:tid 255279] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Knv7v0rlcEGmVraEf_wADnQA"]
[Tue Jul 21 07:31:58.099854 2026] [security2:error] [pid 254995:tid 255123] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/ms.php"] [unique_id "al9Knv7v0rlcEGmVraEgAAADk38"]
[Tue Jul 21 07:31:58.302744 2026] [security2:error] [pid 254995:tid 255157] [client 20.206.105.145:39250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/w2025.php"] [unique_id "al9Knv7v0rlcEGmVraEgCgAAAz4"]
[Tue Jul 21 07:31:58.320947 2026] [security2:error] [pid 254995:tid 255172] [client 20.52.136.55:1779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/item.php"] [unique_id "al9Knv7v0rlcEGmVraEgCwAAA00"]
[Tue Jul 21 07:31:58.412091 2026] [security2:error] [pid 254995:tid 255007] [remote 162.19.246.208:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9Knv7v0rlcEGmVraEgDQADJws"]
[Tue Jul 21 07:31:58.522711 2026] [security2:error] [pid 254995:tid 255141] [client 173.252.95.13:56210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Knv7v0rlcEGmVraEgDwAAAy4"]
[Tue Jul 21 07:31:58.545031 2026] [autoindex:error] [pid 254995:tid 255006] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/mcandi55/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:31:58.557780 2026] [security2:error] [pid 254995:tid 255137] [client 20.151.10.161:50937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/2P.php"] [unique_id "al9Knv7v0rlcEGmVraEgEAAAAyo"]
[Tue Jul 21 07:31:58.597784 2026] [security2:error] [pid 254995:tid 255202] [client 20.220.225.223:45968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/koiy.php"] [unique_id "al9Knv7v0rlcEGmVraEgFAAAA2s"]
[Tue Jul 21 07:31:58.656761 2026] [core:alert] [pid 254995:tid 255197] [client 57.141.18.32:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:31:58.787201 2026] [security2:error] [pid 254995:tid 255220] [client 45.8.17.148:61255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyfive/parts/"] [unique_id "al9Knv7v0rlcEGmVraEgIAAAA3w"]
[Tue Jul 21 07:31:58.852077 2026] [security2:error] [pid 254995:tid 255255] [client 20.206.105.145:7700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Knv7v0rlcEGmVraEgIgAAA4U"]
[Tue Jul 21 07:31:58.965852 2026] [security2:error] [pid 254995:tid 255014] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/memberfuns.php"] [unique_id "al9Knv7v0rlcEGmVraEgJQADhxI"]
[Tue Jul 21 07:31:58.985566 2026] [security2:error] [pid 254995:tid 255018] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/0.php"] [unique_id "al9Knv7v0rlcEGmVraEgJgADihY"]
[Tue Jul 21 07:31:59.005196 2026] [security2:error] [pid 254995:tid 255019] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/BDKR28.php"] [unique_id "al9Kn_7v0rlcEGmVraEgJwADWhc"]
[Tue Jul 21 07:31:59.042981 2026] [security2:error] [pid 254995:tid 255216] [client 172.245.102.42:40739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Kn_7v0rlcEGmVraEgKAAAA3g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:31:59.080334 2026] [security2:error] [pid 254995:tid 255016] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/green1.php"] [unique_id "al9Kn_7v0rlcEGmVraEgKQADlBQ"]
[Tue Jul 21 07:31:59.105384 2026] [security2:error] [pid 254995:tid 255017] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/nc4.php"] [unique_id "al9Kn_7v0rlcEGmVraEgKgADmRU"]
[Tue Jul 21 07:31:59.130341 2026] [security2:error] [pid 254995:tid 255021] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/a1.php"] [unique_id "al9Kn_7v0rlcEGmVraEgKwADmhk"]
[Tue Jul 21 07:31:59.142216 2026] [security2:error] [pid 254995:tid 255126] [client 20.151.10.161:50921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Kn_7v0rlcEGmVraEgLAAAAx8"]
[Tue Jul 21 07:31:59.150210 2026] [security2:error] [pid 254995:tid 255022] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/eee.php"] [unique_id "al9Kn_7v0rlcEGmVraEgLQADIho"]
[Tue Jul 21 07:31:59.172205 2026] [security2:error] [pid 254995:tid 255023] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/wp-aothait.php"] [unique_id "al9Kn_7v0rlcEGmVraEgMAADNhs"]
[Tue Jul 21 07:31:59.190806 2026] [security2:error] [pid 254995:tid 255020] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/config.json.php"] [unique_id "al9Kn_7v0rlcEGmVraEgMQADIxg"]
[Tue Jul 21 07:31:59.211467 2026] [security2:error] [pid 254995:tid 255024] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9Kn_7v0rlcEGmVraEgMgADnBw"]
[Tue Jul 21 07:31:59.215231 2026] [security2:error] [pid 254995:tid 255179] [client 59.96.220.140:60414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Kn_7v0rlcEGmVraEgMwAAA1Q"]
[Tue Jul 21 07:31:59.215319 2026] [security2:error] [pid 254995:tid 255179] [client 59.96.220.140:60414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Kn_7v0rlcEGmVraEgMwAAA1Q"]
[Tue Jul 21 07:31:59.229976 2026] [security2:error] [pid 254995:tid 255025] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/k2.php"] [unique_id "al9Kn_7v0rlcEGmVraEgNAADnR0"]
[Tue Jul 21 07:31:59.395387 2026] [security2:error] [pid 254995:tid 255172] [client 20.220.225.223:8908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/cro.php"] [unique_id "al9Kn_7v0rlcEGmVraEgPQAAA00"]
[Tue Jul 21 07:31:59.457416 2026] [security2:error] [pid 254995:tid 255164] [client 20.197.195.24:13129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/adminner.php"] [unique_id "al9Kn_7v0rlcEGmVraEgPgAAA0U"]
[Tue Jul 21 07:31:59.463105 2026] [security2:error] [pid 254995:tid 255177] [client 20.151.10.161:57382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Kn_7v0rlcEGmVraEgPwAAA1I"]
[Tue Jul 21 07:31:59.995735 2026] [security2:error] [pid 254995:tid 255152] [client 20.151.10.161:57453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/bob.php"] [unique_id "al9Kn_7v0rlcEGmVraEgUwAAAzk"]
[Tue Jul 21 07:32:00.003783 2026] [security2:error] [pid 254995:tid 255034] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9KoP7v0rlcEGmVraEgVAADdiY"]
[Tue Jul 21 07:32:00.023885 2026] [security2:error] [pid 254995:tid 255037] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9KoP7v0rlcEGmVraEgVQADUCk"]
[Tue Jul 21 07:32:00.059909 2026] [security2:error] [pid 254995:tid 255039] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9KoP7v0rlcEGmVraEgVwADYCs"]
[Tue Jul 21 07:32:00.079688 2026] [security2:error] [pid 254995:tid 255040] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/for.php"] [unique_id "al9KoP7v0rlcEGmVraEgWgADUSw"]
[Tue Jul 21 07:32:00.089293 2026] [security2:error] [pid 254995:tid 255223] [client 45.8.17.146:53091] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/query-title/"] [unique_id "al9KoP7v0rlcEGmVraEgWwAAA38"]
[Tue Jul 21 07:32:00.105900 2026] [security2:error] [pid 254995:tid 255186] [client 20.220.225.223:6803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/berlin.php"] [unique_id "al9KoP7v0rlcEGmVraEgXAAAA1s"]
[Tue Jul 21 07:32:00.140408 2026] [security2:error] [pid 254995:tid 255041] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mcandidoadvocacia.com.br"] [uri "/raw.php"] [unique_id "al9KoP7v0rlcEGmVraEgXQADgi0"]
[Tue Jul 21 07:32:00.268513 2026] [security2:error] [pid 254995:tid 255252] [client 20.220.225.223:19289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/edit.php"] [unique_id "al9KoP7v0rlcEGmVraEgXwAAA4M"]
[Tue Jul 21 07:32:00.489546 2026] [proxy:error] [pid 254995:tid 255151] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:00.489619 2026] [proxy_http:error] [pid 254995:tid 255151] [client 20.151.10.161:57353] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:00.490269 2026] [proxy:error] [pid 254995:tid 255151] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:00.490310 2026] [proxy_http:error] [pid 254995:tid 255151] [client 20.151.10.161:57353] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:00.528556 2026] [security2:error] [pid 254995:tid 255133] [client 74.7.175.162:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "michaellacerda1748029545263.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9KoP7v0rlcEGmVraEgawADJig"]
[Tue Jul 21 07:32:00.563355 2026] [security2:error] [pid 254995:tid 255048] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KoP7v0rlcEGmVraEgbQADVDQ"]
[Tue Jul 21 07:32:00.563489 2026] [security2:error] [pid 254995:tid 255179] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KoP7v0rlcEGmVraEgbQADVDQ"]
[Tue Jul 21 07:32:00.781537 2026] [security2:error] [pid 254995:tid 255163] [client 213.152.162.104:54550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9KoP7v0rlcEGmVraEgbgAAA0Q"]
[Tue Jul 21 07:32:00.781646 2026] [security2:error] [pid 254995:tid 255163] [client 213.152.162.104:54550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9KoP7v0rlcEGmVraEgbgAAA0Q"]
[Tue Jul 21 07:32:01.020674 2026] [security2:error] [pid 254995:tid 255051] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgdgADjTc"]
[Tue Jul 21 07:32:01.020834 2026] [security2:error] [pid 254995:tid 255263] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgdgADjTc"]
[Tue Jul 21 07:32:01.175378 2026] [security2:error] [pid 254995:tid 255132] [client 20.197.195.24:13086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/admin.php"] [unique_id "al9Kof7v0rlcEGmVraEgeQAAAyU"]
[Tue Jul 21 07:32:01.211972 2026] [security2:error] [pid 254995:tid 255055] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgewADMzs"]
[Tue Jul 21 07:32:01.212148 2026] [security2:error] [pid 254995:tid 255146] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgewADMzs"]
[Tue Jul 21 07:32:01.291491 2026] [security2:error] [pid 254995:tid 255256] [client 139.167.225.182:59918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgfQAAA4Y"]
[Tue Jul 21 07:32:01.291625 2026] [security2:error] [pid 254995:tid 255256] [client 139.167.225.182:59918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgfQAAA4Y"]
[Tue Jul 21 07:32:01.294606 2026] [proxy:error] [pid 254995:tid 255218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:01.294659 2026] [proxy_http:error] [pid 254995:tid 255218] [client 20.151.10.161:50932] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:01.295520 2026] [proxy:error] [pid 254995:tid 255218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:01.295552 2026] [proxy_http:error] [pid 254995:tid 255218] [client 20.151.10.161:50932] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:01.480011 2026] [security2:error] [pid 254995:tid 255152] [client 20.220.225.223:38669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9Kof7v0rlcEGmVraEgiAAAAzk"]
[Tue Jul 21 07:32:01.508605 2026] [security2:error] [pid 254995:tid 255175] [client 20.220.225.223:9266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/billur.php"] [unique_id "al9Kof7v0rlcEGmVraEgiQAAA1A"]
[Tue Jul 21 07:32:01.563787 2026] [security2:error] [pid 254995:tid 255206] [client 20.206.105.145:7696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/u.php"] [unique_id "al9Kof7v0rlcEGmVraEgigAAA28"]
[Tue Jul 21 07:32:01.597911 2026] [security2:error] [pid 254995:tid 255144] [client 45.8.17.61:48947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/config.php"] [unique_id "al9Kof7v0rlcEGmVraEgiwAAAzE"]
[Tue Jul 21 07:32:01.759591 2026] [security2:error] [pid 254995:tid 255162] [client 103.162.129.114:57816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgjQAAA0M"]
[Tue Jul 21 07:32:01.759719 2026] [security2:error] [pid 254995:tid 255162] [client 103.162.129.114:57816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgjQAAA0M"]
[Tue Jul 21 07:32:01.863065 2026] [security2:error] [pid 254995:tid 255064] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgjAADfEQ"]
[Tue Jul 21 07:32:01.863273 2026] [security2:error] [pid 254995:tid 255220] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kof7v0rlcEGmVraEgjAADfEQ"]
[Tue Jul 21 07:32:02.083619 2026] [security2:error] [pid 254995:tid 255190] [client 122.186.204.214:57636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kov7v0rlcEGmVraEgnAAAA18"]
[Tue Jul 21 07:32:02.083846 2026] [security2:error] [pid 254995:tid 255190] [client 122.186.204.214:57636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kov7v0rlcEGmVraEgnAAAA18"]
[Tue Jul 21 07:32:02.440282 2026] [security2:error] [pid 254995:tid 255167] [client 20.151.10.161:57434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/crgio.php"] [unique_id "al9Kov7v0rlcEGmVraEgowAAA0g"]
[Tue Jul 21 07:32:02.632188 2026] [core:error] [pid 254995:tid 255075] [remote 74.7.230.22:59558] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:32:02.632215 2026] [core:error] [pid 254995:tid 255075] [remote 74.7.230.22:59558] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:32:02.632380 2026] [security2:error] [pid 254995:tid 255147] [client 74.7.230.22:59558] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "limaradiologiadigital.com.br.limaradiologiadigital.com.br"] [uri "/index.php"] [unique_id "al9Kov7v0rlcEGmVraEgpwADNE8"]
[Tue Jul 21 07:32:02.738653 2026] [security2:error] [pid 254995:tid 255074] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kov7v0rlcEGmVraEgqAADLU4"]
[Tue Jul 21 07:32:02.738867 2026] [security2:error] [pid 254995:tid 255140] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kov7v0rlcEGmVraEgqAADLU4"]
[Tue Jul 21 07:32:02.984360 2026] [security2:error] [pid 254995:tid 255201] [client 20.206.105.145:38924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/scxy.php"] [unique_id "al9Kov7v0rlcEGmVraEgsgAAA2o"]
[Tue Jul 21 07:32:02.989433 2026] [security2:error] [pid 254995:tid 255208] [client 45.8.17.126:29699] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/images/"] [unique_id "al9Kov7v0rlcEGmVraEgswAAA3A"]
[Tue Jul 21 07:32:03.035591 2026] [security2:error] [pid 254995:tid 255171] [client 20.220.225.223:19325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/kua.php"] [unique_id "al9Ko_7v0rlcEGmVraEgtAAAA0w"]
[Tue Jul 21 07:32:03.197637 2026] [security2:error] [pid 254995:tid 255082] [remote 198.244.242.28:45266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "upitech.com.br"] [uri "/robots.txt"] [unique_id "al9Ko_7v0rlcEGmVraEgtgADWFY"]
[Tue Jul 21 07:32:03.197847 2026] [security2:error] [pid 254995:tid 255183] [client 198.244.242.28:45266] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "upitech.com.br"] [uri "/robots.txt"] [unique_id "al9Ko_7v0rlcEGmVraEgtgADWFY"]
[Tue Jul 21 07:32:03.338421 2026] [security2:error] [pid 254995:tid 255156] [client 103.106.20.201:49962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ko_7v0rlcEGmVraEgtwAAAz0"]
[Tue Jul 21 07:32:03.338567 2026] [security2:error] [pid 254995:tid 255156] [client 103.106.20.201:49962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ko_7v0rlcEGmVraEgtwAAAz0"]
[Tue Jul 21 07:32:03.504690 2026] [security2:error] [pid 254995:tid 255261] [client 20.151.10.161:57364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/pucci.php"] [unique_id "al9Ko_7v0rlcEGmVraEgwAAAA4s"]
[Tue Jul 21 07:32:03.633123 2026] [security2:error] [pid 254995:tid 255206] [client 173.24.185.52:56832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ko_7v0rlcEGmVraEgwgAAA28"]
[Tue Jul 21 07:32:03.633311 2026] [security2:error] [pid 254995:tid 255206] [client 173.24.185.52:56832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ko_7v0rlcEGmVraEgwgAAA28"]
[Tue Jul 21 07:32:03.716789 2026] [security2:error] [pid 254995:tid 255216] [client 62.102.148.164:57184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Ko_7v0rlcEGmVraEgxAAAA3g"]
[Tue Jul 21 07:32:03.716906 2026] [security2:error] [pid 254995:tid 255216] [client 62.102.148.164:57184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Ko_7v0rlcEGmVraEgxAAAA3g"]
[Tue Jul 21 07:32:03.831601 2026] [security2:error] [pid 254995:tid 255176] [client 172.245.102.45:40589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Ko_7v0rlcEGmVraEgxgAAA1E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:03.895634 2026] [security2:error] [pid 254995:tid 255276] [client 20.197.195.24:13182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/k.php"] [unique_id "al9Ko_7v0rlcEGmVraEgyAAAA5o"]
[Tue Jul 21 07:32:03.896739 2026] [proxy:error] [pid 254995:tid 255270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:03.896823 2026] [proxy_http:error] [pid 254995:tid 255270] [client 20.151.10.161:57344] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:03.897791 2026] [proxy:error] [pid 254995:tid 255270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:03.897826 2026] [proxy_http:error] [pid 254995:tid 255270] [client 20.151.10.161:57344] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:04.106407 2026] [security2:error] [pid 254995:tid 255091] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg0QADlV8"]
[Tue Jul 21 07:32:04.106570 2026] [security2:error] [pid 254995:tid 255271] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg0QADlV8"]
[Tue Jul 21 07:32:04.186252 2026] [security2:error] [pid 254995:tid 255159] [client 45.8.17.125:42459] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/index-string.php"] [unique_id "al9KpP7v0rlcEGmVraEg0wAAA0A"]
[Tue Jul 21 07:32:04.213096 2026] [security2:error] [pid 254995:tid 255094] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg1AADH2I"]
[Tue Jul 21 07:32:04.213233 2026] [security2:error] [pid 254995:tid 255126] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg1AADH2I"]
[Tue Jul 21 07:32:04.287630 2026] [security2:error] [pid 254995:tid 255257] [client 154.192.233.199:59862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg1wAAA4c"]
[Tue Jul 21 07:32:04.287769 2026] [security2:error] [pid 254995:tid 255257] [client 154.192.233.199:59862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg1wAAA4c"]
[Tue Jul 21 07:32:04.301447 2026] [proxy:error] [pid 254995:tid 255274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:04.301508 2026] [proxy_http:error] [pid 254995:tid 255274] [client 20.151.10.161:51306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:04.302432 2026] [proxy:error] [pid 254995:tid 255274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:04.302473 2026] [proxy_http:error] [pid 254995:tid 255274] [client 20.151.10.161:51306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:04.499500 2026] [security2:error] [pid 254995:tid 255269] [client 20.206.105.145:7725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/sss.php"] [unique_id "al9KpP7v0rlcEGmVraEg3AAAA5M"]
[Tue Jul 21 07:32:04.604490 2026] [security2:error] [pid 254995:tid 255199] [client 20.206.105.145:38930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/FWAZ.php"] [unique_id "al9KpP7v0rlcEGmVraEg5gAAA2g"]
[Tue Jul 21 07:32:04.674695 2026] [security2:error] [pid 254995:tid 255259] [client 175.45.70.82:51528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg6AAAA4k"]
[Tue Jul 21 07:32:04.674846 2026] [security2:error] [pid 254995:tid 255259] [client 175.45.70.82:51528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KpP7v0rlcEGmVraEg6AAAA4k"]
[Tue Jul 21 07:32:04.707699 2026] [security2:error] [pid 254995:tid 255152] [client 20.220.225.223:6122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/kq1.php"] [unique_id "al9KpP7v0rlcEGmVraEg6gAAAzk"]
[Tue Jul 21 07:32:04.755229 2026] [security2:error] [pid 254995:tid 255103] [remote 142.44.233.186:37744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "upitech.com.br"] [uri "/"] [unique_id "al9KpP7v0rlcEGmVraEg6wADaWs"]
[Tue Jul 21 07:32:04.755862 2026] [security2:error] [pid 254995:tid 255200] [client 142.44.233.186:37744] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "upitech.com.br"] [uri "/"] [unique_id "al9KpP7v0rlcEGmVraEg6wADaWs"]
[Tue Jul 21 07:32:04.763254 2026] [security2:error] [pid 254995:tid 255212] [client 20.151.10.161:58020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-temp.php"] [unique_id "al9KpP7v0rlcEGmVraEg7AAAA3Q"]
[Tue Jul 21 07:32:05.566039 2026] [security2:error] [pid 254995:tid 255156] [client 45.251.232.145:65072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpf7v0rlcEGmVraEhFAAAAz0"]
[Tue Jul 21 07:32:05.566157 2026] [security2:error] [pid 254995:tid 255156] [client 45.251.232.145:65072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpf7v0rlcEGmVraEhFAAAAz0"]
[Tue Jul 21 07:32:05.571642 2026] [security2:error] [pid 254995:tid 255196] [client 103.174.34.15:60003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpf7v0rlcEGmVraEhFQAAA2U"]
[Tue Jul 21 07:32:05.571763 2026] [security2:error] [pid 254995:tid 255196] [client 103.174.34.15:60003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpf7v0rlcEGmVraEhFQAAA2U"]
[Tue Jul 21 07:32:05.600271 2026] [proxy:error] [pid 254995:tid 255197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:05.600373 2026] [proxy_http:error] [pid 254995:tid 255197] [client 20.151.10.161:58007] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:05.601295 2026] [proxy:error] [pid 254995:tid 255197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:05.601330 2026] [proxy_http:error] [pid 254995:tid 255197] [client 20.151.10.161:58007] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:05.687348 2026] [security2:error] [pid 254995:tid 255212] [client 45.8.17.108:32315] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/images/index.php"] [unique_id "al9Kpf7v0rlcEGmVraEhGwAAA3Q"]
[Tue Jul 21 07:32:06.083548 2026] [security2:error] [pid 254995:tid 255266] [client 20.151.10.161:57461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9Kpv7v0rlcEGmVraEhHgAAA5A"]
[Tue Jul 21 07:32:06.093605 2026] [security2:error] [pid 254995:tid 255277] [client 20.206.105.145:39244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/qterm.php"] [unique_id "al9Kpv7v0rlcEGmVraEhHwAAA5s"]
[Tue Jul 21 07:32:06.458865 2026] [security2:error] [pid 254995:tid 255173] [client 122.129.67.13:59218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9Kpv7v0rlcEGmVraEhKgAAA04"]
[Tue Jul 21 07:32:06.484881 2026] [security2:error] [pid 254995:tid 254996] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpv7v0rlcEGmVraEhKwADhwA"]
[Tue Jul 21 07:32:06.484986 2026] [security2:error] [pid 254995:tid 255257] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpv7v0rlcEGmVraEhKwADhwA"]
[Tue Jul 21 07:32:06.492156 2026] [security2:error] [pid 254995:tid 255125] [client 20.220.225.223:56459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/la.php"] [unique_id "al9Kpv7v0rlcEGmVraEhLAAAAx4"]
[Tue Jul 21 07:32:06.663985 2026] [security2:error] [pid 254995:tid 255154] [client 20.197.195.24:13059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/blurbs.php"] [unique_id "al9Kpv7v0rlcEGmVraEhOAAAAzs"]
[Tue Jul 21 07:32:06.759350 2026] [security2:error] [pid 254995:tid 255190] [client 20.151.10.161:51287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/puc.php"] [unique_id "al9Kpv7v0rlcEGmVraEhbQAAA18"]
[Tue Jul 21 07:32:06.909637 2026] [security2:error] [pid 254995:tid 255138] [client 20.220.225.223:8954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/cron-tab.php"] [unique_id "al9Kpv7v0rlcEGmVraEhcgAAAys"]
[Tue Jul 21 07:32:06.950122 2026] [security2:error] [pid 254995:tid 255179] [client 117.217.38.194:54070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpv7v0rlcEGmVraEhcwAAA1Q"]
[Tue Jul 21 07:32:06.950279 2026] [security2:error] [pid 254995:tid 255179] [client 117.217.38.194:54070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kpv7v0rlcEGmVraEhcwAAA1Q"]
[Tue Jul 21 07:32:07.109590 2026] [security2:error] [pid 254995:tid 255261] [client 152.59.154.239:61268] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEhgAAAA4s"]
[Tue Jul 21 07:32:07.109746 2026] [security2:error] [pid 254995:tid 255261] [client 152.59.154.239:61268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEhgAAAA4s"]
[Tue Jul 21 07:32:07.301197 2026] [security2:error] [pid 254995:tid 255278] [client 20.151.10.161:57350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/themes.php"] [unique_id "al9Kp_7v0rlcEGmVraEhwgAAA5w"]
[Tue Jul 21 07:32:07.337257 2026] [security2:error] [pid 254995:tid 255197] [client 62.102.148.164:57192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEhwwAAA2Y"]
[Tue Jul 21 07:32:07.337355 2026] [security2:error] [pid 254995:tid 255197] [client 62.102.148.164:57192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEhwwAAA2Y"]
[Tue Jul 21 07:32:07.423190 2026] [security2:error] [pid 254995:tid 255196] [client 82.102.28.107:47372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEhygAAA2U"]
[Tue Jul 21 07:32:07.423295 2026] [security2:error] [pid 254995:tid 255196] [client 82.102.28.107:47372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEhygAAA2U"]
[Tue Jul 21 07:32:07.451797 2026] [security2:error] [pid 254995:tid 255205] [client 20.52.136.55:1537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/albin.php"] [unique_id "al9Kp_7v0rlcEGmVraEhywAAA24"]
[Tue Jul 21 07:32:07.504679 2026] [security2:error] [pid 254995:tid 255177] [client 20.197.195.24:13158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/bajah.php"] [unique_id "al9Kp_7v0rlcEGmVraEhzAAAA1I"]
[Tue Jul 21 07:32:07.548256 2026] [security2:error] [pid 254995:tid 255149] [client 136.144.33.100:33607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Kp_7v0rlcEGmVraEhyAAAAzY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:07.585509 2026] [security2:error] [pid 254995:tid 255194] [client 45.8.17.108:46009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/update-core-time.php"] [unique_id "al9Kp_7v0rlcEGmVraEhzQAAA2M"]
[Tue Jul 21 07:32:07.638993 2026] [security2:error] [pid 254995:tid 255200] [client 20.206.105.145:39242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/blurbs.php"] [unique_id "al9Kp_7v0rlcEGmVraEhzgAAA2k"]
[Tue Jul 21 07:32:07.673530 2026] [security2:error] [pid 254995:tid 255212] [client 20.206.105.145:7682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/sss.php"] [unique_id "al9Kp_7v0rlcEGmVraEhzwAAA3Q"]
[Tue Jul 21 07:32:07.772144 2026] [security2:error] [pid 254995:tid 255137] [client 20.220.225.223:62087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/koiy.php"] [unique_id "al9Kp_7v0rlcEGmVraEh1gAAAyo"]
[Tue Jul 21 07:32:07.776018 2026] [security2:error] [pid 254995:tid 255277] [client 20.151.10.161:57368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/dx.php"] [unique_id "al9Kp_7v0rlcEGmVraEh1wAAA5s"]
[Tue Jul 21 07:32:07.858773 2026] [security2:error] [pid 254995:tid 255005] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEh2wADXwk"]
[Tue Jul 21 07:32:07.858909 2026] [security2:error] [pid 254995:tid 255190] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kp_7v0rlcEGmVraEh2wADXwk"]
[Tue Jul 21 07:32:07.891088 2026] [security2:error] [pid 254995:tid 255255] [client 20.220.225.223:19315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/ez.php"] [unique_id "al9Kp_7v0rlcEGmVraEh3AAAA4U"]
[Tue Jul 21 07:32:08.153956 2026] [security2:error] [pid 254995:tid 255034] [remote 217.165.161.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.161.165.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KqP7v0rlcEGmVraEh9gADRCY"]
[Tue Jul 21 07:32:08.154105 2026] [security2:error] [pid 254995:tid 255163] [client 217.165.161.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9KqP7v0rlcEGmVraEh9gADRCY"]
[Tue Jul 21 07:32:08.273725 2026] [security2:error] [pid 254995:tid 255166] [client 20.151.10.161:58002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/p.php"] [unique_id "al9KqP7v0rlcEGmVraEh_gAAA0c"]
[Tue Jul 21 07:32:08.450804 2026] [security2:error] [pid 254995:tid 255147] [client 218.252.242.195:1803] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "onkosclinica.com.br"] [uri "/home/wp-content/uploads/2017/08/IMG_5987-310x200.jpg"] [unique_id "al9KqP7v0rlcEGmVraEiAwAAAzQ"]
[Tue Jul 21 07:32:08.612452 2026] [security2:error] [pid 254995:tid 255041] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KqP7v0rlcEGmVraEiBAADmS0"]
[Tue Jul 21 07:32:08.612589 2026] [security2:error] [pid 254995:tid 255275] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KqP7v0rlcEGmVraEiBAADmS0"]
[Tue Jul 21 07:32:08.871089 2026] [proxy:error] [pid 254995:tid 255193] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:08.871181 2026] [proxy_http:error] [pid 254995:tid 255193] [client 20.151.10.161:50923] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:08.872546 2026] [proxy:error] [pid 254995:tid 255193] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:08.872580 2026] [proxy_http:error] [pid 254995:tid 255193] [client 20.151.10.161:50923] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:08.894851 2026] [security2:error] [pid 254995:tid 255153] [client 20.220.225.223:8955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/hp2.php"] [unique_id "al9KqP7v0rlcEGmVraEiFAAAAzo"]
[Tue Jul 21 07:32:09.000987 2026] [security2:error] [pid 254995:tid 255218] [client 20.197.195.24:13147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/a.php"] [unique_id "al9Kqf7v0rlcEGmVraEiFQAAA3o"]
[Tue Jul 21 07:32:09.007834 2026] [security2:error] [pid 254995:tid 255173] [client 141.11.107.74:60165] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ftp.happynbox.com.br"] [uri "/"] [unique_id "al9Kqf7v0rlcEGmVraEiFgAAA04"]
[Tue Jul 21 07:32:09.013186 2026] [security2:error] [pid 254995:tid 255159] [client 141.11.107.74:60175] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.happynbox.com.br"] [uri "/"] [unique_id "al9Kqf7v0rlcEGmVraEiGAAAA0A"]
[Tue Jul 21 07:32:09.018887 2026] [security2:error] [pid 254995:tid 255256] [client 141.11.107.74:60172] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "happynbox.com.br"] [uri "/"] [unique_id "al9Kqf7v0rlcEGmVraEiGQAAA4Y"]
[Tue Jul 21 07:32:09.393986 2026] [security2:error] [pid 254995:tid 255196] [client 20.220.225.223:8122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/mimpi.php"] [unique_id "al9Kqf7v0rlcEGmVraEiJAAAA2U"]
[Tue Jul 21 07:32:09.397620 2026] [security2:error] [pid 254995:tid 255149] [client 45.8.17.125:24287] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/woocommerce-call.php"] [unique_id "al9Kqf7v0rlcEGmVraEiJQAAAzY"]
[Tue Jul 21 07:32:09.415914 2026] [security2:error] [pid 254995:tid 255229] [client 20.151.10.161:50907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/bthil.php"] [unique_id "al9Kqf7v0rlcEGmVraEiJgAAA4I"]
[Tue Jul 21 07:32:09.738403 2026] [security2:error] [pid 254995:tid 255174] [client 193.36.225.102:36437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Kqf7v0rlcEGmVraEiJwAAA08"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:09.940283 2026] [security2:error] [pid 254995:tid 255259] [client 20.206.105.145:54569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/c.php"] [unique_id "al9Kqf7v0rlcEGmVraEiMgAAA4k"]
[Tue Jul 21 07:32:10.016447 2026] [security2:error] [pid 254995:tid 255127] [client 20.206.105.145:39234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/v543.php"] [unique_id "al9Kqv7v0rlcEGmVraEiNAAAAyA"]
[Tue Jul 21 07:32:10.028623 2026] [security2:error] [pid 254995:tid 255130] [client 20.197.195.24:13167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/edit.php"] [unique_id "al9Kqv7v0rlcEGmVraEiNQAAAyM"]
[Tue Jul 21 07:32:10.153003 2026] [security2:error] [pid 254995:tid 255167] [client 20.151.10.161:57405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/7.php"] [unique_id "al9Kqv7v0rlcEGmVraEiNgAAA0g"]
[Tue Jul 21 07:32:10.261765 2026] [security2:error] [pid 254995:tid 255158] [client 20.220.225.223:19674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/fz.php"] [unique_id "al9Kqv7v0rlcEGmVraEiOAAAAz8"]
[Tue Jul 21 07:32:10.489186 2026] [security2:error] [pid 254995:tid 255128] [client 45.8.17.105:38105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/user/upgrade/index.php"] [unique_id "al9Kqv7v0rlcEGmVraEiQQAAAyE"]
[Tue Jul 21 07:32:10.809589 2026] [autoindex:error] [pid 254995:tid 255099] [remote 74.7.242.40:60190] AH01276: Cannot serve directory /home2/tamoio74/engeconconstrucoes.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:32:10.859395 2026] [security2:error] [pid 254995:tid 255190] [client 59.96.220.140:60878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Kqv7v0rlcEGmVraEidAAAA18"]
[Tue Jul 21 07:32:10.861259 2026] [security2:error] [pid 254995:tid 255190] [client 59.96.220.140:60878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Kqv7v0rlcEGmVraEidAAAA18"]
[Tue Jul 21 07:32:10.931485 2026] [security2:error] [pid 254995:tid 255261] [client 20.151.10.161:50917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/8.php"] [unique_id "al9Kqv7v0rlcEGmVraEiewAAA4s"]
[Tue Jul 21 07:32:11.060419 2026] [security2:error] [pid 254995:tid 255137] [client 20.197.195.24:13144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/hosty.php"] [unique_id "al9Kq_7v0rlcEGmVraEigAAAAyo"]
[Tue Jul 21 07:32:11.092241 2026] [security2:error] [pid 254995:tid 255105] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEigQADkm0"]
[Tue Jul 21 07:32:11.092423 2026] [security2:error] [pid 254995:tid 255268] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEigQADkm0"]
[Tue Jul 21 07:32:11.284225 2026] [security2:error] [pid 254995:tid 255279] [client 20.220.225.223:61959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/nhvoanpl.php"] [unique_id "al9Kq_7v0rlcEGmVraEihAAAA50"]
[Tue Jul 21 07:32:11.433615 2026] [security2:error] [pid 254995:tid 255127] [client 74.7.230.1:46248] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Kq_7v0rlcEGmVraEikQADIAA"]
[Tue Jul 21 07:32:11.533361 2026] [security2:error] [pid 254995:tid 255026] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEilgADhR4"]
[Tue Jul 21 07:32:11.533470 2026] [security2:error] [pid 254995:tid 255255] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEilgADhR4"]
[Tue Jul 21 07:32:11.565300 2026] [security2:error] [pid 254995:tid 255149] [client 139.167.225.182:60549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEimAAAAzY"]
[Tue Jul 21 07:32:11.565398 2026] [security2:error] [pid 254995:tid 255149] [client 139.167.225.182:60549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEimAAAAzY"]
[Tue Jul 21 07:32:11.592572 2026] [security2:error] [pid 254995:tid 255169] [client 20.151.10.161:57403] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.reabfit.com.br"] [uri "/1.php"] [unique_id "al9Kq_7v0rlcEGmVraEimQAAA0o"]
[Tue Jul 21 07:32:11.592654 2026] [security2:error] [pid 254995:tid 255169] [client 20.151.10.161:57403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/1.php"] [unique_id "al9Kq_7v0rlcEGmVraEimQAAA0o"]
[Tue Jul 21 07:32:11.636250 2026] [security2:error] [pid 254995:tid 255263] [client 117.251.86.144:36386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEinAAAA40"]
[Tue Jul 21 07:32:11.636334 2026] [security2:error] [pid 254995:tid 255263] [client 117.251.86.144:36386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEinAAAA40"]
[Tue Jul 21 07:32:11.683108 2026] [security2:error] [pid 254995:tid 255006] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEingADTQo"]
[Tue Jul 21 07:32:11.683244 2026] [security2:error] [pid 254995:tid 255172] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kq_7v0rlcEGmVraEingADTQo"]
[Tue Jul 21 07:32:11.844995 2026] [security2:error] [pid 254995:tid 255206] [client 20.206.105.145:39279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/w3lls.php"] [unique_id "al9Kq_7v0rlcEGmVraEiowAAA28"]
[Tue Jul 21 07:32:11.859464 2026] [security2:error] [pid 254995:tid 255214] [client 20.220.225.223:6793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/dp.php"] [unique_id "al9Kq_7v0rlcEGmVraEipAAAA3Y"]
[Tue Jul 21 07:32:11.896172 2026] [security2:error] [pid 254995:tid 255161] [client 45.8.17.73:31493] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/maint/css/index.php"] [unique_id "al9Kq_7v0rlcEGmVraEiqQAAA0I"]
[Tue Jul 21 07:32:11.914577 2026] [security2:error] [pid 254995:tid 255268] [client 20.197.195.24:13083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/k.php"] [unique_id "al9Kq_7v0rlcEGmVraEiqgAAA5I"]
[Tue Jul 21 07:32:11.952759 2026] [security2:error] [pid 254995:tid 255277] [client 20.206.105.145:7479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/aa.php"] [unique_id "al9Kq_7v0rlcEGmVraEiqwAAA5s"]
[Tue Jul 21 07:32:12.056570 2026] [security2:error] [pid 254995:tid 255178] [client 20.151.10.161:57379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/100.php"] [unique_id "al9KrP7v0rlcEGmVraEitgAAA1M"]
[Tue Jul 21 07:32:12.198195 2026] [security2:error] [pid 254995:tid 255276] [client 193.36.225.66:36611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KrP7v0rlcEGmVraEivAAAA5o"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:12.230301 2026] [security2:error] [pid 254995:tid 255224] [client 103.162.129.114:58275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KrP7v0rlcEGmVraEivQAAA4A"]
[Tue Jul 21 07:32:12.230447 2026] [security2:error] [pid 254995:tid 255224] [client 103.162.129.114:58275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KrP7v0rlcEGmVraEivQAAA4A"]
[Tue Jul 21 07:32:12.631344 2026] [security2:error] [pid 254995:tid 255181] [client 20.151.10.161:50889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/about.php"] [unique_id "al9KrP7v0rlcEGmVraEiyAAAA1Y"]
[Tue Jul 21 07:32:12.701120 2026] [security2:error] [pid 254995:tid 255173] [client 122.186.204.214:58131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KrP7v0rlcEGmVraEiyQAAA04"]
[Tue Jul 21 07:32:12.701270 2026] [security2:error] [pid 254995:tid 255173] [client 122.186.204.214:58131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KrP7v0rlcEGmVraEiyQAAA04"]
[Tue Jul 21 07:32:12.984750 2026] [security2:error] [pid 254995:tid 255134] [client 20.151.10.161:51325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/admin.php"] [unique_id "al9KrP7v0rlcEGmVraEi0wAAAyc"]
[Tue Jul 21 07:32:13.069093 2026] [security2:error] [pid 254995:tid 255182] [client 20.206.105.145:38923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-ws68.php"] [unique_id "al9Krf7v0rlcEGmVraEi1gAAA1c"]
[Tue Jul 21 07:32:13.198525 2026] [security2:error] [pid 254995:tid 255145] [client 20.220.225.223:6080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/zzz.php"] [unique_id "al9Krf7v0rlcEGmVraEi2QAAAzI"]
[Tue Jul 21 07:32:13.397302 2026] [security2:error] [pid 254995:tid 255036] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Krf7v0rlcEGmVraEi4gADayg"]
[Tue Jul 21 07:32:13.397487 2026] [security2:error] [pid 254995:tid 255202] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Krf7v0rlcEGmVraEi4gADayg"]
[Tue Jul 21 07:32:13.525280 2026] [security2:error] [pid 254995:tid 255205] [client 20.197.195.24:13093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/aaa.php"] [unique_id "al9Krf7v0rlcEGmVraEi6gAAA24"]
[Tue Jul 21 07:32:13.701546 2026] [security2:error] [pid 254995:tid 255181] [client 20.220.225.223:4185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/inso.php"] [unique_id "al9Krf7v0rlcEGmVraEi6wAAA1Y"]
[Tue Jul 21 07:32:13.862992 2026] [security2:error] [pid 254995:tid 255138] [client 20.151.10.161:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/edit.php"] [unique_id "al9Krf7v0rlcEGmVraEi8wAAAys"]
[Tue Jul 21 07:32:14.010251 2026] [security2:error] [pid 254995:tid 255277] [client 20.206.105.145:39246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xyn.php"] [unique_id "al9Krv7v0rlcEGmVraEi9wAAA5s"]
[Tue Jul 21 07:32:14.076894 2026] [security2:error] [pid 254995:tid 255208] [client 103.106.20.201:50537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Krv7v0rlcEGmVraEi_wAAA3A"]
[Tue Jul 21 07:32:14.077017 2026] [security2:error] [pid 254995:tid 255208] [client 103.106.20.201:50537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Krv7v0rlcEGmVraEi_wAAA3A"]
[Tue Jul 21 07:32:14.079023 2026] [security2:error] [pid 254995:tid 255187] [client 20.206.105.145:7459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/100.php"] [unique_id "al9Krv7v0rlcEGmVraEjAAAAA1w"]
[Tue Jul 21 07:32:14.093156 2026] [http2:info] [pid 255769:tid 255769] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 07:32:14.288809 2026] [security2:error] [pid 254995:tid 255156] [client 173.24.185.52:57295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Krv7v0rlcEGmVraEjBQAAAz0"]
[Tue Jul 21 07:32:14.288965 2026] [security2:error] [pid 254995:tid 255156] [client 173.24.185.52:57295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Krv7v0rlcEGmVraEjBQAAAz0"]
[Tue Jul 21 07:32:14.302880 2026] [security2:error] [pid 255769:tid 255901] [client 109.248.148.246:54240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KrrxMYwyVGnfuwsJ8TQAAA6U"]
[Tue Jul 21 07:32:14.302995 2026] [security2:error] [pid 255769:tid 255901] [client 109.248.148.246:54240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9KrrxMYwyVGnfuwsJ8TQAAA6U"]
[Tue Jul 21 07:32:14.310137 2026] [security2:error] [pid 255769:tid 255903] [client 45.8.17.129:29255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/pattern/index.php"] [unique_id "al9KrrxMYwyVGnfuwsJ8TwAAA6c"]
[Tue Jul 21 07:32:14.737508 2026] [security2:error] [pid 254995:tid 255171] [client 193.36.225.121:57871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Krv7v0rlcEGmVraEjDQAAA0w"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:14.800540 2026] [security2:error] [pid 254995:tid 255064] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Krv7v0rlcEGmVraEjEQADWEQ"]
[Tue Jul 21 07:32:14.800719 2026] [security2:error] [pid 254995:tid 255183] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Krv7v0rlcEGmVraEjEQADWEQ"]
[Tue Jul 21 07:32:14.802996 2026] [security2:error] [pid 254995:tid 255148] [client 20.151.10.161:57414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Krv7v0rlcEGmVraEjEgAAAzU"]
[Tue Jul 21 07:32:14.824330 2026] [security2:error] [pid 255769:tid 255771] [remote 124.55.178.99:36982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/wp-login.php"] [unique_id "al9KrrxMYwyVGnfuwsJ8VQADowE"]
[Tue Jul 21 07:32:14.917842 2026] [security2:error] [pid 255769:tid 255772] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KrrxMYwyVGnfuwsJ8VgADuQI"]
[Tue Jul 21 07:32:14.918026 2026] [security2:error] [pid 255769:tid 255921] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KrrxMYwyVGnfuwsJ8VgADuQI"]
[Tue Jul 21 07:32:15.281373 2026] [security2:error] [pid 254995:tid 255225] [client 20.206.105.145:38913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/green3.php"] [unique_id "al9Kr_7v0rlcEGmVraEjHAAAA4E"]
[Tue Jul 21 07:32:15.407385 2026] [security2:error] [pid 255769:tid 255920] [client 175.45.70.82:52043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kr7xMYwyVGnfuwsJ8VwAAA7g"]
[Tue Jul 21 07:32:15.407510 2026] [security2:error] [pid 255769:tid 255920] [client 175.45.70.82:52043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kr7xMYwyVGnfuwsJ8VwAAA7g"]
[Tue Jul 21 07:32:15.436794 2026] [security2:error] [pid 254995:tid 255145] [client 20.220.225.223:6120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wicked.php"] [unique_id "al9Kr_7v0rlcEGmVraEjHgAAAzI"]
[Tue Jul 21 07:32:15.682436 2026] [security2:error] [pid 255769:tid 255906] [client 136.144.33.96:58321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Kr7xMYwyVGnfuwsJ8WAAAA6o"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:15.685615 2026] [security2:error] [pid 254995:tid 255181] [client 45.8.17.57:37453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/upgrade-temp-backup/chosen.php"] [unique_id "al9Kr_7v0rlcEGmVraEjLQAAA1Y"]
[Tue Jul 21 07:32:16.039306 2026] [security2:error] [pid 254995:tid 255125] [client 45.251.232.145:49215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsP7v0rlcEGmVraEjMAAAAx4"]
[Tue Jul 21 07:32:16.039446 2026] [security2:error] [pid 254995:tid 255125] [client 45.251.232.145:49215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsP7v0rlcEGmVraEjMAAAAx4"]
[Tue Jul 21 07:32:16.182083 2026] [security2:error] [pid 255769:tid 255931] [client 20.151.10.161:50933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/f6.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8WgAAA8M"]
[Tue Jul 21 07:32:16.188457 2026] [security2:error] [pid 254995:tid 255133] [client 154.192.233.199:60342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsP7v0rlcEGmVraEjNwAAAyY"]
[Tue Jul 21 07:32:16.188549 2026] [security2:error] [pid 254995:tid 255133] [client 154.192.233.199:60342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsP7v0rlcEGmVraEjNwAAAyY"]
[Tue Jul 21 07:32:16.209482 2026] [security2:error] [pid 255769:tid 255932] [client 20.206.105.145:7469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/footer.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8WwAAA8Q"]
[Tue Jul 21 07:32:16.381154 2026] [security2:error] [pid 255769:tid 255926] [client 103.174.34.15:60496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8XAAAA74"]
[Tue Jul 21 07:32:16.381297 2026] [security2:error] [pid 255769:tid 255926] [client 103.174.34.15:60496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8XAAAA74"]
[Tue Jul 21 07:32:16.417032 2026] [security2:error] [pid 255769:tid 255937] [client 20.206.105.145:39287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ccs.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8XgAAA8k"]
[Tue Jul 21 07:32:16.562572 2026] [security2:error] [pid 254995:tid 255196] [client 20.197.195.24:13078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/file5.php"] [unique_id "al9KsP7v0rlcEGmVraEjPAAAA2U"]
[Tue Jul 21 07:32:16.581943 2026] [security2:error] [pid 254995:tid 255255] [client 45.8.17.73:37743] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/elementor/includes/template-library/classes/view.php"] [unique_id "al9KsP7v0rlcEGmVraEjPQAAA4U"]
[Tue Jul 21 07:32:16.943369 2026] [security2:error] [pid 255769:tid 255953] [client 82.102.28.107:39482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8ZwAAA9k"]
[Tue Jul 21 07:32:16.943503 2026] [security2:error] [pid 255769:tid 255953] [client 82.102.28.107:39482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8ZwAAA9k"]
[Tue Jul 21 07:32:16.979681 2026] [security2:error] [pid 255769:tid 255954] [client 62.102.148.164:49654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8aAAAA9o"]
[Tue Jul 21 07:32:16.979788 2026] [security2:error] [pid 255769:tid 255954] [client 62.102.148.164:49654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8aAAAA9o"]
[Tue Jul 21 07:32:16.996656 2026] [core:error] [pid 254995:tid 255134] [client 101.37.88.240:57356] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Tue Jul 21 07:32:17.178075 2026] [security2:error] [pid 254995:tid 255166] [client 20.206.105.145:7771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/users.php"] [unique_id "al9Ksf7v0rlcEGmVraEjTgAAA0c"]
[Tue Jul 21 07:32:17.181782 2026] [security2:error] [pid 254995:tid 255169] [client 20.206.105.145:39280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ccc.php"] [unique_id "al9Ksf7v0rlcEGmVraEjTwAAA0o"]
[Tue Jul 21 07:32:17.389493 2026] [security2:error] [pid 255769:tid 255780] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsbxMYwyVGnfuwsJ8bAAD4go"]
[Tue Jul 21 07:32:17.389634 2026] [security2:error] [pid 255769:tid 255962] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KsbxMYwyVGnfuwsJ8bAAD4go"]
[Tue Jul 21 07:32:17.439324 2026] [security2:error] [pid 254995:tid 255259] [client 117.217.38.194:54509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ksf7v0rlcEGmVraEjUAAAA4k"]
[Tue Jul 21 07:32:17.439463 2026] [security2:error] [pid 254995:tid 255259] [client 117.217.38.194:54509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ksf7v0rlcEGmVraEjUAAAA4k"]
[Tue Jul 21 07:32:17.614248 2026] [security2:error] [pid 255769:tid 255935] [client 74.7.230.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.royalbsolutions.com"] [uri "/index.php"] [unique_id "al9KsLxMYwyVGnfuwsJ8YAADxwU"]
[Tue Jul 21 07:32:17.829222 2026] [security2:error] [pid 255769:tid 255980] [client 20.197.195.24:13080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/222.php"] [unique_id "al9KsbxMYwyVGnfuwsJ8dQAAA_Q"]
[Tue Jul 21 07:32:17.880256 2026] [security2:error] [pid 255769:tid 255982] [client 45.8.17.116:53877] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/theme-install-function.php"] [unique_id "al9KsbxMYwyVGnfuwsJ8dwAAA_Y"]
[Tue Jul 21 07:32:18.106799 2026] [security2:error] [pid 255769:tid 255984] [client 74.7.230.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "royalbsolutions.com"] [uri "/index.php"] [unique_id "al9KsrxMYwyVGnfuwsJ8egAD-A4"], referer: https://www.royalbsolutions.com/robots.txt
[Tue Jul 21 07:32:18.110283 2026] [security2:error] [pid 255769:tid 255963] [client 193.36.225.139:61797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9KsbxMYwyVGnfuwsJ8eAAAA-M"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:18.344470 2026] [security2:error] [pid 255769:tid 255998] [client 20.206.105.145:39286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/get.php"] [unique_id "al9KsrxMYwyVGnfuwsJ8fQAABAQ"]
[Tue Jul 21 07:32:18.525941 2026] [security2:error] [pid 254995:tid 255114] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ksv7v0rlcEGmVraEjZgADhHY"]
[Tue Jul 21 07:32:18.526090 2026] [security2:error] [pid 254995:tid 255254] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ksv7v0rlcEGmVraEjZgADhHY"]
[Tue Jul 21 07:32:18.731842 2026] [security2:error] [pid 254995:tid 255169] [client 20.197.195.24:13075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/test.php"] [unique_id "al9Ksv7v0rlcEGmVraEjawAAA0o"]
[Tue Jul 21 07:32:19.057529 2026] [security2:error] [pid 254995:tid 255173] [client 20.206.105.145:38950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/images.php"] [unique_id "al9Ks_7v0rlcEGmVraEjbgAAA04"]
[Tue Jul 21 07:32:19.120605 2026] [security2:error] [pid 254995:tid 255122] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Ks_7v0rlcEGmVraEjbwADVn4"]
[Tue Jul 21 07:32:19.120747 2026] [security2:error] [pid 254995:tid 255181] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Ks_7v0rlcEGmVraEjbwADVn4"]
[Tue Jul 21 07:32:19.183580 2026] [security2:error] [pid 254995:tid 255204] [client 45.8.17.112:64421] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/shadow-bot.php"] [unique_id "al9Ks_7v0rlcEGmVraEjcQAAA20"]
[Tue Jul 21 07:32:19.223179 2026] [security2:error] [pid 255769:tid 255988] [client 152.59.154.239:61723] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ks7xMYwyVGnfuwsJ8iAAAA_w"]
[Tue Jul 21 07:32:19.223293 2026] [security2:error] [pid 255769:tid 255988] [client 152.59.154.239:61723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ks7xMYwyVGnfuwsJ8iAAAA_w"]
[Tue Jul 21 07:32:19.364178 2026] [security2:error] [pid 254995:tid 255167] [client 20.220.225.223:52182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/edit.php"] [unique_id "al9Ks_7v0rlcEGmVraEjdgAAA0g"]
[Tue Jul 21 07:32:19.553181 2026] [security2:error] [pid 255769:tid 255787] [remote 65.111.14.163:36739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.14.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9Ks7xMYwyVGnfuwsJ8jgAEIBE"]
[Tue Jul 21 07:32:19.651123 2026] [security2:error] [pid 254995:tid 255214] [client 20.197.195.24:13183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/aaa.php"] [unique_id "al9Ks_7v0rlcEGmVraEjewAAA3Y"]
[Tue Jul 21 07:32:19.662780 2026] [security2:error] [pid 255769:tid 255939] [client 122.129.67.13:60395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9KsbxMYwyVGnfuwsJ8awAAA8s"]
[Tue Jul 21 07:32:20.223502 2026] [security2:error] [pid 255769:tid 255923] [client 20.206.105.145:7260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/177.php"] [unique_id "al9KtLxMYwyVGnfuwsJ8lQAAA7s"]
[Tue Jul 21 07:32:20.504869 2026] [security2:error] [pid 255769:tid 255925] [client 20.206.105.145:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/alls.php"] [unique_id "al9KtLxMYwyVGnfuwsJ8lwAAA70"]
[Tue Jul 21 07:32:20.634977 2026] [security2:error] [pid 255769:tid 255791] [remote 45.79.123.44:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9KtLxMYwyVGnfuwsJ8mAADuhU"]
[Tue Jul 21 07:32:20.740525 2026] [security2:error] [pid 254995:tid 255199] [client 136.144.33.106:23771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KtP7v0rlcEGmVraEjkgAAA2g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:20.954189 2026] [security2:error] [pid 254995:tid 255143] [client 173.252.95.21:33822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KtP7v0rlcEGmVraEjmAAAAzA"]
[Tue Jul 21 07:32:21.220311 2026] [security2:error] [pid 255769:tid 255958] [client 20.197.195.24:13148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/11.php"] [unique_id "al9KtbxMYwyVGnfuwsJ8oAAAA94"]
[Tue Jul 21 07:32:21.295947 2026] [security2:error] [pid 255769:tid 255903] [client 59.96.220.140:61362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KtbxMYwyVGnfuwsJ8oQAAA6c"]
[Tue Jul 21 07:32:21.296078 2026] [security2:error] [pid 255769:tid 255903] [client 59.96.220.140:61362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KtbxMYwyVGnfuwsJ8oQAAA6c"]
[Tue Jul 21 07:32:21.395535 2026] [security2:error] [pid 254995:tid 255264] [client 20.220.225.223:6130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/kua.php"] [unique_id "al9Ktf7v0rlcEGmVraEjogAAA44"]
[Tue Jul 21 07:32:21.413754 2026] [security2:error] [pid 254995:tid 255159] [client 37.140.223.157:29167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Ktf7v0rlcEGmVraEjnwAAA0A"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:21.416516 2026] [security2:error] [pid 254995:tid 255224] [client 20.151.10.161:57463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/inputs.php"] [unique_id "al9Ktf7v0rlcEGmVraEjowAAA4A"]
[Tue Jul 21 07:32:21.630523 2026] [security2:error] [pid 255769:tid 255793] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KtbxMYwyVGnfuwsJ8qQAD8xc"]
[Tue Jul 21 07:32:21.630642 2026] [security2:error] [pid 255769:tid 255979] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KtbxMYwyVGnfuwsJ8qQAD8xc"]
[Tue Jul 21 07:32:21.782043 2026] [security2:error] [pid 255769:tid 255981] [client 45.8.17.113:40993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/shadow-bot.php"] [unique_id "al9KtbxMYwyVGnfuwsJ8qgAAA_U"]
[Tue Jul 21 07:32:21.928402 2026] [security2:error] [pid 254995:tid 255257] [client 20.206.105.145:7727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/config.php"] [unique_id "al9Ktf7v0rlcEGmVraEjqwAAA4c"]
[Tue Jul 21 07:32:21.937712 2026] [security2:error] [pid 254995:tid 255254] [client 20.206.105.145:38971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/yyu.php"] [unique_id "al9Ktf7v0rlcEGmVraEjrQAAA4Q"]
[Tue Jul 21 07:32:21.961744 2026] [security2:error] [pid 255769:tid 255795] [remote 188.138.102.156:58226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compressoresra.com.br"] [uri "/wp-login.php"] [unique_id "al9KtbxMYwyVGnfuwsJ8rAAD6xk"]
[Tue Jul 21 07:32:22.000587 2026] [security2:error] [pid 255769:tid 255950] [client 117.251.86.144:43482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8rQAAA9Y"]
[Tue Jul 21 07:32:22.000741 2026] [security2:error] [pid 255769:tid 255950] [client 117.251.86.144:43482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8rQAAA9Y"]
[Tue Jul 21 07:32:22.039762 2026] [security2:error] [pid 255769:tid 255796] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8rgAD8ho"]
[Tue Jul 21 07:32:22.039948 2026] [security2:error] [pid 255769:tid 255978] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8rgAD8ho"]
[Tue Jul 21 07:32:22.060091 2026] [security2:error] [pid 255769:tid 255961] [client 139.167.225.182:61184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8rwAAA-E"]
[Tue Jul 21 07:32:22.060252 2026] [security2:error] [pid 255769:tid 255961] [client 139.167.225.182:61184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8rwAAA-E"]
[Tue Jul 21 07:32:22.693634 2026] [security2:error] [pid 255769:tid 255990] [client 103.162.129.114:58712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8tQAAA_4"]
[Tue Jul 21 07:32:22.693795 2026] [security2:error] [pid 255769:tid 255990] [client 103.162.129.114:58712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KtrxMYwyVGnfuwsJ8tQAAA_4"]
[Tue Jul 21 07:32:22.732852 2026] [security2:error] [pid 254995:tid 255268] [client 20.220.225.223:62093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/hp3.php"] [unique_id "al9Ktv7v0rlcEGmVraEjuwAAA5I"]
[Tue Jul 21 07:32:23.140262 2026] [security2:error] [pid 255769:tid 255916] [client 20.206.105.145:7567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/gettest.php"] [unique_id "al9Kt7xMYwyVGnfuwsJ8vAAAA7Q"]
[Tue Jul 21 07:32:23.150518 2026] [security2:error] [pid 254995:tid 255025] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ktv7v0rlcEGmVraEjtAADPh0"]
[Tue Jul 21 07:32:23.150741 2026] [security2:error] [pid 254995:tid 255157] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ktv7v0rlcEGmVraEjtAADPh0"]
[Tue Jul 21 07:32:23.422630 2026] [security2:error] [pid 255769:tid 256021] [client 122.186.204.214:58637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kt7xMYwyVGnfuwsJ8wQAABBs"]
[Tue Jul 21 07:32:23.442543 2026] [security2:error] [pid 255769:tid 256021] [client 122.186.204.214:58637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kt7xMYwyVGnfuwsJ8wQAABBs"]
[Tue Jul 21 07:32:23.487683 2026] [security2:error] [pid 254995:tid 255196] [client 45.8.17.125:58881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/load.php"] [unique_id "al9Kt_7v0rlcEGmVraEjywAAA2U"]
[Tue Jul 21 07:32:23.539031 2026] [security2:error] [pid 255769:tid 255934] [client 82.102.28.107:36868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Kt7xMYwyVGnfuwsJ8wwAAA8Y"]
[Tue Jul 21 07:32:23.539137 2026] [security2:error] [pid 255769:tid 255934] [client 82.102.28.107:36868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Kt7xMYwyVGnfuwsJ8wwAAA8Y"]
[Tue Jul 21 07:32:23.937263 2026] [security2:error] [pid 255769:tid 255802] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kt7xMYwyVGnfuwsJ8yAAD0CA"]
[Tue Jul 21 07:32:23.937434 2026] [security2:error] [pid 255769:tid 255944] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Kt7xMYwyVGnfuwsJ8yAAD0CA"]
[Tue Jul 21 07:32:23.975895 2026] [security2:error] [pid 254995:tid 255229] [client 20.206.105.145:38969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/by.php"] [unique_id "al9Kt_7v0rlcEGmVraEj0wAAA4I"]
[Tue Jul 21 07:32:24.384845 2026] [security2:error] [pid 254995:tid 255154] [client 45.8.17.145:35073] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/wp-activate.php"] [unique_id "al9KuP7v0rlcEGmVraEj2gAAAzs"]
[Tue Jul 21 07:32:24.495444 2026] [security2:error] [pid 254995:tid 255224] [client 136.144.33.29:60971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KuP7v0rlcEGmVraEj3gAAA4A"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:24.551974 2026] [security2:error] [pid 255769:tid 255968] [client 20.220.225.223:62003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wpx.php"] [unique_id "al9KuLxMYwyVGnfuwsJ8zQAAA-g"]
[Tue Jul 21 07:32:24.574733 2026] [security2:error] [pid 255769:tid 255975] [client 20.206.105.145:54534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/min.php"] [unique_id "al9KuLxMYwyVGnfuwsJ8zwAAA-8"]
[Tue Jul 21 07:32:24.589033 2026] [security2:error] [pid 255769:tid 255976] [client 20.220.225.223:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/ez.php"] [unique_id "al9KuLxMYwyVGnfuwsJ80AAAA_A"]
[Tue Jul 21 07:32:24.746428 2026] [security2:error] [pid 255769:tid 255805] [remote 156.67.31.167:46732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/xmlrpc.php"] [unique_id "al9KuLxMYwyVGnfuwsJ80gADuCM"]
[Tue Jul 21 07:32:24.746627 2026] [security2:error] [pid 255769:tid 255920] [client 156.67.31.167:46732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "buyonlinetodayatadiscount.net"] [uri "/xmlrpc.php"] [unique_id "al9KuLxMYwyVGnfuwsJ80gADuCM"]
[Tue Jul 21 07:32:24.782922 2026] [security2:error] [pid 254995:tid 255194] [client 103.106.20.201:51106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KuP7v0rlcEGmVraEj5gAAA2M"]
[Tue Jul 21 07:32:24.783634 2026] [security2:error] [pid 254995:tid 255194] [client 103.106.20.201:51106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KuP7v0rlcEGmVraEj5gAAA2M"]
[Tue Jul 21 07:32:24.843190 2026] [security2:error] [pid 255769:tid 255935] [client 173.24.185.52:57763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KuLxMYwyVGnfuwsJ80wAAA8c"]
[Tue Jul 21 07:32:24.843338 2026] [security2:error] [pid 255769:tid 255935] [client 173.24.185.52:57763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KuLxMYwyVGnfuwsJ80wAAA8c"]
[Tue Jul 21 07:32:25.340504 2026] [security2:error] [pid 254995:tid 255172] [client 20.197.195.24:13063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/mac.php"] [unique_id "al9Kuf7v0rlcEGmVraEj7AAAA00"]
[Tue Jul 21 07:32:25.394806 2026] [security2:error] [pid 254995:tid 255053] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kuf7v0rlcEGmVraEj7QADVDk"]
[Tue Jul 21 07:32:25.394984 2026] [security2:error] [pid 254995:tid 255179] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kuf7v0rlcEGmVraEj7QADVDk"]
[Tue Jul 21 07:32:25.420266 2026] [security2:error] [pid 254995:tid 255213] [client 154.192.233.199:58804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kuf7v0rlcEGmVraEj7gAAA3U"]
[Tue Jul 21 07:32:25.420390 2026] [security2:error] [pid 254995:tid 255213] [client 154.192.233.199:58804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kuf7v0rlcEGmVraEj7gAAA3U"]
[Tue Jul 21 07:32:25.995084 2026] [security2:error] [pid 255769:tid 255809] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KubxMYwyVGnfuwsJ83gAD1yc"]
[Tue Jul 21 07:32:25.995271 2026] [security2:error] [pid 255769:tid 255951] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KubxMYwyVGnfuwsJ83gAD1yc"]
[Tue Jul 21 07:32:26.089531 2026] [security2:error] [pid 255769:tid 256014] [client 45.8.17.124:65189] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/module.php"] [unique_id "al9KurxMYwyVGnfuwsJ84gAABBQ"]
[Tue Jul 21 07:32:26.116094 2026] [security2:error] [pid 255769:tid 256019] [client 20.206.105.145:38949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/FAQ.php"] [unique_id "al9KurxMYwyVGnfuwsJ85AAABBk"]
[Tue Jul 21 07:32:26.131114 2026] [security2:error] [pid 255769:tid 255999] [client 175.45.70.82:52553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KurxMYwyVGnfuwsJ85gAABAU"]
[Tue Jul 21 07:32:26.131242 2026] [security2:error] [pid 255769:tid 255999] [client 175.45.70.82:52553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KurxMYwyVGnfuwsJ85gAABAU"]
[Tue Jul 21 07:32:26.405233 2026] [security2:error] [pid 255769:tid 255909] [client 213.152.162.104:50588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KurxMYwyVGnfuwsJ87AAAA60"]
[Tue Jul 21 07:32:26.405368 2026] [security2:error] [pid 255769:tid 255909] [client 213.152.162.104:50588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9KurxMYwyVGnfuwsJ87AAAA60"]
[Tue Jul 21 07:32:26.427080 2026] [security2:error] [pid 255769:tid 255911] [client 20.220.225.223:8956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/aa1.php"] [unique_id "al9KurxMYwyVGnfuwsJ87QAAA68"]
[Tue Jul 21 07:32:26.497277 2026] [autoindex:error] [pid 255769:tid 255919] [client 172.252.73.13:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:32:26.499169 2026] [security2:error] [pid 254995:tid 255167] [client 45.251.232.145:49743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kuv7v0rlcEGmVraEj_wAAA0g"]
[Tue Jul 21 07:32:26.499271 2026] [security2:error] [pid 254995:tid 255167] [client 45.251.232.145:49743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kuv7v0rlcEGmVraEj_wAAA0g"]
[Tue Jul 21 07:32:26.614224 2026] [security2:error] [pid 255769:tid 256021] [client 20.197.195.24:13057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/chosen.php"] [unique_id "al9KurxMYwyVGnfuwsJ88wAABBs"]
[Tue Jul 21 07:32:26.653786 2026] [security2:error] [pid 255769:tid 255927] [client 20.206.105.145:38964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/coffexium.php"] [unique_id "al9KurxMYwyVGnfuwsJ89AAAA78"]
[Tue Jul 21 07:32:26.908565 2026] [security2:error] [pid 254995:tid 255216] [client 20.206.105.145:39285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/red.php"] [unique_id "al9Kuv7v0rlcEGmVraEkCAAAA3g"]
[Tue Jul 21 07:32:26.986666 2026] [security2:error] [pid 254995:tid 255169] [client 20.151.10.161:57347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/av.php"] [unique_id "al9Kuv7v0rlcEGmVraEkCQAAA0o"]
[Tue Jul 21 07:32:27.080598 2026] [security2:error] [pid 255769:tid 255912] [client 103.174.34.15:60987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ89gAAA7A"]
[Tue Jul 21 07:32:27.080778 2026] [security2:error] [pid 255769:tid 255912] [client 103.174.34.15:60987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ89gAAA7A"]
[Tue Jul 21 07:32:27.166607 2026] [security2:error] [pid 255769:tid 255940] [client 20.220.225.223:23463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/fz.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ8-AAAA8w"]
[Tue Jul 21 07:32:27.341644 2026] [security2:error] [pid 255769:tid 255954] [client 20.206.105.145:7613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/edorxrr.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ8-wAAA9o"]
[Tue Jul 21 07:32:27.390698 2026] [security2:error] [pid 255769:tid 255960] [client 45.8.17.134:38441] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ8_gAAA-A"]
[Tue Jul 21 07:32:27.532212 2026] [security2:error] [pid 255769:tid 255970] [client 20.220.225.223:46118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/hp3.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ9AgAAA-o"]
[Tue Jul 21 07:32:27.658255 2026] [security2:error] [pid 254995:tid 255172] [client 20.197.195.24:13153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/cream1.php"] [unique_id "al9Ku_7v0rlcEGmVraEkEwAAA00"]
[Tue Jul 21 07:32:27.741995 2026] [security2:error] [pid 254995:tid 255144] [client 213.152.162.104:50602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Ku_7v0rlcEGmVraEkFwAAAzE"]
[Tue Jul 21 07:32:27.742088 2026] [security2:error] [pid 254995:tid 255144] [client 213.152.162.104:50602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Ku_7v0rlcEGmVraEkFwAAAzE"]
[Tue Jul 21 07:32:27.909107 2026] [security2:error] [pid 255769:tid 255946] [client 117.217.38.194:54935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ9BwAAA9I"]
[Tue Jul 21 07:32:27.909227 2026] [security2:error] [pid 255769:tid 255946] [client 117.217.38.194:54935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ9BwAAA9I"]
[Tue Jul 21 07:32:27.918553 2026] [security2:error] [pid 255769:tid 255819] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ9CAAD8TE"]
[Tue Jul 21 07:32:27.918707 2026] [security2:error] [pid 255769:tid 255977] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ku7xMYwyVGnfuwsJ9CAAD8TE"]
[Tue Jul 21 07:32:28.067572 2026] [proxy:error] [pid 255769:tid 255979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:28.067619 2026] [proxy_http:error] [pid 255769:tid 255979] [client 20.206.105.145:38916] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:28.068138 2026] [proxy:error] [pid 255769:tid 255979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:28.068158 2026] [proxy_http:error] [pid 255769:tid 255979] [client 20.206.105.145:38916] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:28.097352 2026] [security2:error] [pid 255769:tid 255932] [client 122.129.67.13:59347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9KvLxMYwyVGnfuwsJ9CQAAA8Q"]
[Tue Jul 21 07:32:28.589656 2026] [security2:error] [pid 255769:tid 255951] [client 45.8.17.62:23323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/system.php"] [unique_id "al9KvLxMYwyVGnfuwsJ9FQAAA9c"]
[Tue Jul 21 07:32:28.629766 2026] [security2:error] [pid 255769:tid 255953] [client 172.245.102.42:21371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KvLxMYwyVGnfuwsJ9EwAAA9k"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:28.849519 2026] [security2:error] [pid 255769:tid 255900] [client 20.206.105.145:39273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9KvLxMYwyVGnfuwsJ9GgAAA6Q"]
[Tue Jul 21 07:32:28.977523 2026] [security2:error] [pid 254995:tid 255157] [client 20.151.10.161:50891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/classwithtostring.php"] [unique_id "al9KvP7v0rlcEGmVraEkKQAAAz4"]
[Tue Jul 21 07:32:29.278393 2026] [security2:error] [pid 255769:tid 255919] [client 20.220.225.223:4578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/berlin.php"] [unique_id "al9KvbxMYwyVGnfuwsJ9HQAAA7c"]
[Tue Jul 21 07:32:29.284675 2026] [security2:error] [pid 255769:tid 255826] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KvbxMYwyVGnfuwsJ9HgAEIDg"]
[Tue Jul 21 07:32:29.284823 2026] [security2:error] [pid 255769:tid 256026] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KvbxMYwyVGnfuwsJ9HgAEIDg"]
[Tue Jul 21 07:32:29.604071 2026] [security2:error] [pid 254995:tid 255270] [client 109.248.148.246:40464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Kvf7v0rlcEGmVraEkMwAAA5Q"]
[Tue Jul 21 07:32:29.604185 2026] [security2:error] [pid 254995:tid 255270] [client 109.248.148.246:40464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Kvf7v0rlcEGmVraEkMwAAA5Q"]
[Tue Jul 21 07:32:29.708035 2026] [security2:error] [pid 254995:tid 255119] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Kvf7v0rlcEGmVraEkNwADdXs"]
[Tue Jul 21 07:32:29.708174 2026] [security2:error] [pid 254995:tid 255213] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9Kvf7v0rlcEGmVraEkNwADdXs"]
[Tue Jul 21 07:32:29.881863 2026] [security2:error] [pid 254995:tid 255199] [client 45.8.17.145:44235] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/wp-links-opml.php"] [unique_id "al9Kvf7v0rlcEGmVraEkOwAAA2g"]
[Tue Jul 21 07:32:30.275562 2026] [security2:error] [pid 254995:tid 255148] [client 20.151.10.161:57433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9Kvv7v0rlcEGmVraEkQgAAAzU"]
[Tue Jul 21 07:32:30.766127 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:30.766206 2026] [proxy_http:error] [pid 254995:tid 255147] [client 20.206.105.145:38980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:30.766796 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:30.766836 2026] [proxy_http:error] [pid 254995:tid 255147] [client 20.206.105.145:38980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:30.785261 2026] [security2:error] [pid 255769:tid 255977] [client 20.206.105.145:7756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/hur.php"] [unique_id "al9KvrxMYwyVGnfuwsJ9MQAAA_E"]
[Tue Jul 21 07:32:31.015042 2026] [security2:error] [pid 254995:tid 255254] [client 20.220.225.223:8077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wp-editor.php"] [unique_id "al9Kv_7v0rlcEGmVraEkVAAAA4Q"]
[Tue Jul 21 07:32:31.066965 2026] [security2:error] [pid 255769:tid 255983] [client 20.151.10.161:57433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-blog.php"] [unique_id "al9Kv7xMYwyVGnfuwsJ9NgAAA_c"]
[Tue Jul 21 07:32:31.091253 2026] [security2:error] [pid 254995:tid 255156] [client 45.8.17.142:28349] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "al9Kv_7v0rlcEGmVraEkVgAAAz0"]
[Tue Jul 21 07:32:31.116437 2026] [security2:error] [pid 255769:tid 255954] [client 59.96.220.140:61606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Kv7xMYwyVGnfuwsJ9NwAAA9o"]
[Tue Jul 21 07:32:31.117361 2026] [security2:error] [pid 255769:tid 255954] [client 59.96.220.140:61606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Kv7xMYwyVGnfuwsJ9NwAAA9o"]
[Tue Jul 21 07:32:31.348927 2026] [security2:error] [pid 254995:tid 255193] [client 20.220.225.223:56497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/billur.php"] [unique_id "al9Kv_7v0rlcEGmVraEkWAAAA2I"]
[Tue Jul 21 07:32:31.448170 2026] [autoindex:error] [pid 255769:tid 255994] [client 20.197.195.24:48883] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:32:31.466408 2026] [autoindex:error] [pid 255769:tid 255992] [client 20.197.195.24:48883] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:32:31.470789 2026] [security2:error] [pid 255769:tid 255952] [client 20.197.195.24:48883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/dr.php"] [unique_id "al9Kv7xMYwyVGnfuwsJ9PQAAA9g"]
[Tue Jul 21 07:32:31.822364 2026] [security2:error] [pid 255769:tid 255979] [client 66.116.242.211:33118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.242.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-login.php"] [unique_id "al9KvrxMYwyVGnfuwsJ9MgAAA_M"], referer: https://bravacomunicacao.com/wp-login.php
[Tue Jul 21 07:32:32.071380 2026] [security2:error] [pid 254995:tid 255149] [client 20.220.225.223:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/aa1.php"] [unique_id "al9KwP7v0rlcEGmVraEkawAAAzY"]
[Tue Jul 21 07:32:32.164721 2026] [security2:error] [pid 255769:tid 255836] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9QwAEFUI"]
[Tue Jul 21 07:32:32.164909 2026] [security2:error] [pid 255769:tid 256015] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9QwAEFUI"]
[Tue Jul 21 07:32:32.211661 2026] [proxy:error] [pid 255769:tid 256020] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:32.211735 2026] [proxy_http:error] [pid 255769:tid 256020] [client 20.151.10.161:58011] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:32.212294 2026] [proxy:error] [pid 255769:tid 256020] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:32.212321 2026] [proxy_http:error] [pid 255769:tid 256020] [client 20.151.10.161:58011] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:32.275553 2026] [security2:error] [pid 255769:tid 256025] [client 20.220.225.223:19298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9RQAABB8"]
[Tue Jul 21 07:32:32.305799 2026] [security2:error] [pid 255769:tid 255986] [client 152.59.154.239:62198] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9RgAAA_o"]
[Tue Jul 21 07:32:32.305951 2026] [security2:error] [pid 255769:tid 255986] [client 152.59.154.239:62198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9RgAAA_o"]
[Tue Jul 21 07:32:32.338023 2026] [security2:error] [pid 255769:tid 255963] [client 193.36.225.60:30471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9SAAAA-M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:32.552952 2026] [security2:error] [pid 255769:tid 255838] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9TAAEGEQ"]
[Tue Jul 21 07:32:32.553077 2026] [security2:error] [pid 255769:tid 256018] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9TAAEGEQ"]
[Tue Jul 21 07:32:32.617532 2026] [security2:error] [pid 255769:tid 255839] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9TQADrUU"]
[Tue Jul 21 07:32:32.617698 2026] [security2:error] [pid 255769:tid 255909] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9TQADrUU"]
[Tue Jul 21 07:32:32.727090 2026] [security2:error] [pid 255769:tid 256011] [client 117.251.86.144:46190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9UAAABBE"]
[Tue Jul 21 07:32:32.727214 2026] [security2:error] [pid 255769:tid 256011] [client 117.251.86.144:46190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9UAAABBE"]
[Tue Jul 21 07:32:32.800026 2026] [security2:error] [pid 255769:tid 255999] [client 139.167.225.182:61812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9UQAABAU"]
[Tue Jul 21 07:32:32.800171 2026] [security2:error] [pid 255769:tid 255999] [client 139.167.225.182:61812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9UQAABAU"]
[Tue Jul 21 07:32:32.806558 2026] [security2:error] [pid 254995:tid 255193] [client 20.220.225.223:8098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/cro.php"] [unique_id "al9KwP7v0rlcEGmVraEkewAAA2I"]
[Tue Jul 21 07:32:32.878748 2026] [security2:error] [pid 255769:tid 256021] [client 20.206.105.145:7780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/zoro.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9UgAABBs"]
[Tue Jul 21 07:32:32.981195 2026] [security2:error] [pid 255769:tid 255927] [client 45.8.17.141:38363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugin-install.php"] [unique_id "al9KwLxMYwyVGnfuwsJ9UwAAA78"]
[Tue Jul 21 07:32:33.158824 2026] [security2:error] [pid 255769:tid 255912] [client 66.116.242.211:44004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.242.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-login.php"] [unique_id "al9KwbxMYwyVGnfuwsJ9VAAAA7A"], referer: https://bravacomunicacao.com/wp-login.php
[Tue Jul 21 07:32:33.455797 2026] [security2:error] [pid 255769:tid 255959] [client 20.206.105.145:39232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/footer.php"] [unique_id "al9KwbxMYwyVGnfuwsJ9XAAAA98"]
[Tue Jul 21 07:32:33.529202 2026] [security2:error] [pid 255769:tid 255915] [client 103.162.129.114:59150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KwbxMYwyVGnfuwsJ9XgAAA7M"]
[Tue Jul 21 07:32:33.529346 2026] [security2:error] [pid 255769:tid 255915] [client 103.162.129.114:59150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KwbxMYwyVGnfuwsJ9XgAAA7M"]
[Tue Jul 21 07:32:33.593466 2026] [security2:error] [pid 255769:tid 255842] [remote 45.146.55.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mecanicanogueira.com.br"] [uri "/wp-login.php"] [unique_id "al9KwbxMYwyVGnfuwsJ9YAAD1Ug"]
[Tue Jul 21 07:32:33.791596 2026] [security2:error] [pid 255769:tid 255984] [client 20.220.225.223:46141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/acew67.php"] [unique_id "al9KwbxMYwyVGnfuwsJ9YgAAA_g"]
[Tue Jul 21 07:32:33.845303 2026] [security2:error] [pid 255769:tid 255978] [client 20.151.10.161:50925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9KwbxMYwyVGnfuwsJ9YwAAA_I"]
[Tue Jul 21 07:32:34.051469 2026] [security2:error] [pid 255769:tid 255960] [client 122.186.204.214:59147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KwrxMYwyVGnfuwsJ9awAAA-A"]
[Tue Jul 21 07:32:34.051603 2026] [security2:error] [pid 255769:tid 255960] [client 122.186.204.214:59147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KwrxMYwyVGnfuwsJ9awAAA-A"]
[Tue Jul 21 07:32:34.110379 2026] [security2:error] [pid 254995:tid 255127] [client 20.220.225.223:19307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/inso.php"] [unique_id "al9Kwv7v0rlcEGmVraEkkAAAAyA"]
[Tue Jul 21 07:32:34.332235 2026] [security2:error] [pid 255769:tid 256009] [client 66.116.242.211:44010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.242.116.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-login.php"] [unique_id "al9KwrxMYwyVGnfuwsJ9cAAABA8"], referer: https://bravacomunicacao.com/wp-login.php
[Tue Jul 21 07:32:34.473421 2026] [security2:error] [pid 254995:tid 255149] [client 20.220.225.223:62007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/mimpi.php"] [unique_id "al9Kwv7v0rlcEGmVraEklwAAAzY"]
[Tue Jul 21 07:32:34.482491 2026] [security2:error] [pid 255769:tid 255847] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KwrxMYwyVGnfuwsJ9cQAEFE0"]
[Tue Jul 21 07:32:34.482633 2026] [security2:error] [pid 255769:tid 256014] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KwrxMYwyVGnfuwsJ9cQAEFE0"]
[Tue Jul 21 07:32:34.745771 2026] [security2:error] [pid 254995:tid 255166] [client 20.206.105.145:7759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/coffexium.php"] [unique_id "al9Kwv7v0rlcEGmVraEkoAAAA0c"]
[Tue Jul 21 07:32:35.091683 2026] [security2:error] [pid 255769:tid 255939] [client 20.151.10.161:51322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/adminfuns.php"] [unique_id "al9Kw7xMYwyVGnfuwsJ9eAAAA8s"]
[Tue Jul 21 07:32:35.401102 2026] [security2:error] [pid 255769:tid 255911] [client 173.24.185.52:58232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Kw7xMYwyVGnfuwsJ9fgAAA68"]
[Tue Jul 21 07:32:35.401239 2026] [security2:error] [pid 255769:tid 255911] [client 173.24.185.52:58232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Kw7xMYwyVGnfuwsJ9fgAAA68"]
[Tue Jul 21 07:32:35.486039 2026] [security2:error] [pid 254995:tid 255204] [client 45.8.17.107:27499] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/class-walker-nav-menu-edit-interpreter.php"] [unique_id "al9Kw_7v0rlcEGmVraEkqwAAA20"]
[Tue Jul 21 07:32:35.548749 2026] [security2:error] [pid 255769:tid 255904] [client 103.106.20.201:51642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kw7xMYwyVGnfuwsJ9ggAAA6g"]
[Tue Jul 21 07:32:35.548896 2026] [security2:error] [pid 255769:tid 255904] [client 103.106.20.201:51642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kw7xMYwyVGnfuwsJ9ggAAA6g"]
[Tue Jul 21 07:32:35.865943 2026] [security2:error] [pid 254995:tid 255147] [client 20.197.195.24:13124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/x.php"] [unique_id "al9Kw_7v0rlcEGmVraEksAAAAzQ"]
[Tue Jul 21 07:32:35.992098 2026] [security2:error] [pid 254995:tid 255078] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kw_7v0rlcEGmVraEktAADSVI"]
[Tue Jul 21 07:32:35.992247 2026] [security2:error] [pid 254995:tid 255168] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kw_7v0rlcEGmVraEktAADSVI"]
[Tue Jul 21 07:32:35.993946 2026] [security2:error] [pid 255769:tid 255942] [client 20.151.10.161:57361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/goods.php"] [unique_id "al9Kw7xMYwyVGnfuwsJ9hgAAA84"]
[Tue Jul 21 07:32:36.063919 2026] [proxy:error] [pid 254995:tid 255218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:36.064000 2026] [proxy_http:error] [pid 254995:tid 255218] [client 20.206.105.145:38942] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:36.064536 2026] [proxy:error] [pid 254995:tid 255218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:36.064559 2026] [proxy_http:error] [pid 254995:tid 255218] [client 20.206.105.145:38942] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:36.114897 2026] [security2:error] [pid 255769:tid 256026] [client 154.192.233.199:59268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9hwAABCA"]
[Tue Jul 21 07:32:36.115024 2026] [security2:error] [pid 255769:tid 256026] [client 154.192.233.199:59268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9hwAABCA"]
[Tue Jul 21 07:32:36.150824 2026] [security2:error] [pid 254995:tid 255138] [client 20.220.225.223:19272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/wpx.php"] [unique_id "al9KxP7v0rlcEGmVraEkuAAAAys"]
[Tue Jul 21 07:32:36.189247 2026] [fcgid:warn] [pid 255769:tid 255959] (70014)End of file found: [client 199.45.155.74:42534] mod_fcgid: can't get data from http client
[Tue Jul 21 07:32:36.442377 2026] [security2:error] [pid 254995:tid 255257] [client 62.102.148.164:50644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9KxP7v0rlcEGmVraEkuwAAA4c"]
[Tue Jul 21 07:32:36.442498 2026] [security2:error] [pid 254995:tid 255257] [client 62.102.148.164:50644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9KxP7v0rlcEGmVraEkuwAAA4c"]
[Tue Jul 21 07:32:36.499979 2026] [security2:error] [pid 255769:tid 255967] [client 20.206.105.145:7758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/app.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9kQAAA-c"]
[Tue Jul 21 07:32:36.714821 2026] [security2:error] [pid 255769:tid 255856] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9lgAD7FY"]
[Tue Jul 21 07:32:36.715014 2026] [security2:error] [pid 255769:tid 255972] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9lgAD7FY"]
[Tue Jul 21 07:32:36.753585 2026] [security2:error] [pid 255769:tid 255993] [client 20.220.225.223:6796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/cron-tab.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9mAAABAA"]
[Tue Jul 21 07:32:36.787122 2026] [security2:error] [pid 255769:tid 255994] [client 45.8.17.64:57763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/customize/class-wp-widget-area-customize-control-interpreter.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9mQAABAE"]
[Tue Jul 21 07:32:36.830092 2026] [security2:error] [pid 255769:tid 255997] [client 20.206.105.145:39281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/index.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9nAAABAM"]
[Tue Jul 21 07:32:36.872887 2026] [security2:error] [pid 255769:tid 255965] [client 175.45.70.82:53064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9ngAAA-U"]
[Tue Jul 21 07:32:36.873077 2026] [security2:error] [pid 255769:tid 255965] [client 175.45.70.82:53064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9ngAAA-U"]
[Tue Jul 21 07:32:36.988017 2026] [security2:error] [pid 255769:tid 255975] [client 45.251.232.145:50260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9nwAAA-8"]
[Tue Jul 21 07:32:36.988138 2026] [security2:error] [pid 255769:tid 255975] [client 45.251.232.145:50260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9nwAAA-8"]
[Tue Jul 21 07:32:37.168569 2026] [security2:error] [pid 255769:tid 255910] [client 37.140.223.138:23125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9KxLxMYwyVGnfuwsJ9nQAAA64"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:37.521250 2026] [security2:error] [pid 255769:tid 255861] [remote 41.76.214.143:40854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiferreira.com.br"] [uri "/wp-login.php"] [unique_id "al9KxbxMYwyVGnfuwsJ9rQAEAls"]
[Tue Jul 21 07:32:37.625795 2026] [security2:error] [pid 255769:tid 255902] [client 213.152.162.104:39486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KxbxMYwyVGnfuwsJ9rgAAA6Y"]
[Tue Jul 21 07:32:37.625947 2026] [security2:error] [pid 255769:tid 255902] [client 213.152.162.104:39486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9KxbxMYwyVGnfuwsJ9rgAAA6Y"]
[Tue Jul 21 07:32:37.667634 2026] [security2:error] [pid 255769:tid 255947] [client 193.36.225.58:42171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9KxbxMYwyVGnfuwsJ9rAAAA9M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:37.695189 2026] [security2:error] [pid 255769:tid 255939] [client 45.8.17.124:65439] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/ai-client/adapters/admin.php"] [unique_id "al9KxbxMYwyVGnfuwsJ9rwAAA8s"]
[Tue Jul 21 07:32:37.717949 2026] [security2:error] [pid 254995:tid 255131] [client 20.206.105.145:39282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/zoro.php"] [unique_id "al9Kxf7v0rlcEGmVraEkygAAAyQ"]
[Tue Jul 21 07:32:37.889900 2026] [security2:error] [pid 254995:tid 255254] [client 103.174.34.15:61477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kxf7v0rlcEGmVraEkzwAAA4Q"]
[Tue Jul 21 07:32:37.890036 2026] [security2:error] [pid 254995:tid 255254] [client 103.174.34.15:61477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kxf7v0rlcEGmVraEkzwAAA4Q"]
[Tue Jul 21 07:32:38.046072 2026] [security2:error] [pid 255769:tid 255922] [client 20.220.225.223:19664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/berlin.php"] [unique_id "al9KxrxMYwyVGnfuwsJ9tgAAA7o"]
[Tue Jul 21 07:32:38.273505 2026] [security2:error] [pid 255769:tid 256019] [client 74.248.121.109:2136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9KxbxMYwyVGnfuwsJ9pgAABBk"]
[Tue Jul 21 07:32:38.394641 2026] [security2:error] [pid 255769:tid 255903] [client 117.217.38.194:55370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxrxMYwyVGnfuwsJ9wgAAA6c"]
[Tue Jul 21 07:32:38.394748 2026] [security2:error] [pid 255769:tid 255903] [client 117.217.38.194:55370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KxrxMYwyVGnfuwsJ9wgAAA6c"]
[Tue Jul 21 07:32:38.472347 2026] [security2:error] [pid 254995:tid 255222] [client 20.206.105.145:7573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/core.php"] [unique_id "al9Kxv7v0rlcEGmVraEk2QAAA34"]
[Tue Jul 21 07:32:38.472353 2026] [security2:error] [pid 254995:tid 255005] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kxv7v0rlcEGmVraEk2gADPgk"]
[Tue Jul 21 07:32:38.472508 2026] [security2:error] [pid 254995:tid 255157] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kxv7v0rlcEGmVraEk2gADPgk"]
[Tue Jul 21 07:32:38.817131 2026] [security2:error] [pid 254995:tid 255174] [client 74.248.121.109:1086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Kxv7v0rlcEGmVraEk3wAAA08"]
[Tue Jul 21 07:32:38.843184 2026] [security2:error] [pid 255769:tid 255926] [client 122.129.67.13:60792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9KxrxMYwyVGnfuwsJ9xgAAA74"]
[Tue Jul 21 07:32:38.900074 2026] [security2:error] [pid 255769:tid 255960] [client 45.8.17.103:55285] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/widget-group/index.php"] [unique_id "al9KxrxMYwyVGnfuwsJ9ywAAA-A"]
[Tue Jul 21 07:32:38.975850 2026] [security2:error] [pid 255769:tid 255978] [client 173.252.95.41:53416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9KxrxMYwyVGnfuwsJ9zgAAA_I"]
[Tue Jul 21 07:32:39.261632 2026] [security2:error] [pid 254995:tid 255145] [client 74.248.121.109:1025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/wp.php"] [unique_id "al9Kx_7v0rlcEGmVraEk5AAAAzI"]
[Tue Jul 21 07:32:39.492691 2026] [security2:error] [pid 255769:tid 256015] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/12ohqpluagtoz1nkdo1tqazo1e.php"] [unique_id "al9Kx7xMYwyVGnfuwsJ91wAABBU"]
[Tue Jul 21 07:32:39.723365 2026] [security2:error] [pid 254995:tid 255136] [client 74.248.121.109:1036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/new.php"] [unique_id "al9Kx_7v0rlcEGmVraEk7wAAAyk"]
[Tue Jul 21 07:32:39.935938 2026] [security2:error] [pid 255769:tid 255870] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kx7xMYwyVGnfuwsJ94QADy2Q"]
[Tue Jul 21 07:32:39.936204 2026] [security2:error] [pid 255769:tid 255939] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kx7xMYwyVGnfuwsJ94QADy2Q"]
[Tue Jul 21 07:32:39.937533 2026] [security2:error] [pid 254995:tid 255229] [client 20.206.105.145:7689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/main.php"] [unique_id "al9Kx_7v0rlcEGmVraEk9QAAA4I"]
[Tue Jul 21 07:32:39.993651 2026] [security2:error] [pid 255769:tid 256018] [client 45.8.17.60:22601] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/preformatted/index.php"] [unique_id "al9Kx7xMYwyVGnfuwsJ94wAABBg"]
[Tue Jul 21 07:32:40.168464 2026] [security2:error] [pid 254995:tid 255268] [client 74.248.121.109:2129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/class-t.api.php"] [unique_id "al9KyP7v0rlcEGmVraEk-QAAA5I"]
[Tue Jul 21 07:32:40.185177 2026] [security2:error] [pid 255769:tid 255899] [client 20.220.225.223:19292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/billur.php"] [unique_id "al9KyLxMYwyVGnfuwsJ95AAAA6M"]
[Tue Jul 21 07:32:40.197453 2026] [security2:error] [pid 255769:tid 255921] [client 20.206.105.145:39292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/admin.php"] [unique_id "al9KyLxMYwyVGnfuwsJ95QAAA7k"]
[Tue Jul 21 07:32:40.226506 2026] [security2:error] [pid 254995:tid 255001] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KyP7v0rlcEGmVraEk-gADRgU"]
[Tue Jul 21 07:32:40.226636 2026] [security2:error] [pid 254995:tid 255165] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9KyP7v0rlcEGmVraEk-gADRgU"]
[Tue Jul 21 07:32:40.385272 2026] [security2:error] [pid 255769:tid 255942] [client 20.220.225.223:46098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/bscclapb.php"] [unique_id "al9KyLxMYwyVGnfuwsJ96wAAA84"]
[Tue Jul 21 07:32:40.414928 2026] [security2:error] [pid 255769:tid 256019] [client 20.151.10.161:50914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ms-edit.php"] [unique_id "al9KyLxMYwyVGnfuwsJ97AAABBk"]
[Tue Jul 21 07:32:40.524150 2026] [security2:error] [pid 254995:tid 255149] [client 20.220.225.223:6823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/koiy.php"] [unique_id "al9KyP7v0rlcEGmVraElBQAAAzY"]
[Tue Jul 21 07:32:40.610044 2026] [security2:error] [pid 255769:tid 255924] [client 74.248.121.109:1084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/plugins.php"] [unique_id "al9KyLxMYwyVGnfuwsJ97QAAA7w"]
[Tue Jul 21 07:32:40.795541 2026] [security2:error] [pid 254995:tid 255127] [client 193.36.225.142:20799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9KyP7v0rlcEGmVraElBgAAAyA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:40.862509 2026] [security2:error] [pid 254995:tid 255125] [client 20.197.195.24:13170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/155.php"] [unique_id "al9KyP7v0rlcEGmVraElCwAAAx4"]
[Tue Jul 21 07:32:40.951588 2026] [security2:error] [pid 254995:tid 255177] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/backend/.env"] [unique_id "al9KyP7v0rlcEGmVraElDgAAA1I"]
[Tue Jul 21 07:32:41.086329 2026] [security2:error] [pid 255769:tid 255944] [client 74.248.121.109:1067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/jp.php"] [unique_id "al9KybxMYwyVGnfuwsJ99wAAA9A"]
[Tue Jul 21 07:32:41.283084 2026] [security2:error] [pid 255769:tid 255983] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9KybxMYwyVGnfuwsJ9-AAAA_c"]
[Tue Jul 21 07:32:41.487208 2026] [security2:error] [pid 255769:tid 255997] [client 20.206.105.145:7705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/init.php"] [unique_id "al9KybxMYwyVGnfuwsJ9_QAABAM"]
[Tue Jul 21 07:32:41.506724 2026] [security2:error] [pid 255769:tid 255965] [client 74.248.121.109:1052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/error.php"] [unique_id "al9KybxMYwyVGnfuwsJ9_gAAA-U"]
[Tue Jul 21 07:32:41.639582 2026] [security2:error] [pid 254995:tid 255154] [client 20.206.105.145:39277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/greap.php"] [unique_id "al9Kyf7v0rlcEGmVraElGQAAAzs"]
[Tue Jul 21 07:32:41.876571 2026] [security2:error] [pid 254995:tid 255229] [client 20.220.225.223:46011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/else1.php"] [unique_id "al9Kyf7v0rlcEGmVraElGwAAA4I"]
[Tue Jul 21 07:32:41.941427 2026] [security2:error] [pid 254995:tid 255195] [client 74.248.121.109:1059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/classwithtostring.php"] [unique_id "al9Kyf7v0rlcEGmVraElHAAAA2Q"]
[Tue Jul 21 07:32:41.989511 2026] [security2:error] [pid 255769:tid 255974] [client 45.8.17.129:27927] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/list/list/wp-config.php"] [unique_id "al9KybxMYwyVGnfuwsJ-BAAAA-4"]
[Tue Jul 21 07:32:42.382841 2026] [security2:error] [pid 254995:tid 255148] [client 172.245.102.44:49415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Kyv7v0rlcEGmVraElJgAAAzU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:42.408322 2026] [security2:error] [pid 254995:tid 255200] [client 74.248.121.109:2119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/bless.php"] [unique_id "al9Kyv7v0rlcEGmVraElJwAAA2k"]
[Tue Jul 21 07:32:42.543144 2026] [security2:error] [pid 255769:tid 256016] [client 20.151.10.161:51308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/222.php"] [unique_id "al9KyrxMYwyVGnfuwsJ-CwAABBY"]
[Tue Jul 21 07:32:42.626803 2026] [security2:error] [pid 254995:tid 255222] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/source/.env"] [unique_id "al9Kyv7v0rlcEGmVraElKwAAA34"]
[Tue Jul 21 07:32:42.729562 2026] [security2:error] [pid 255769:tid 255879] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KyrxMYwyVGnfuwsJ-DQADqW0"]
[Tue Jul 21 07:32:42.729715 2026] [security2:error] [pid 255769:tid 255905] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9KyrxMYwyVGnfuwsJ-DQADqW0"]
[Tue Jul 21 07:32:42.789220 2026] [security2:error] [pid 255769:tid 255957] [client 59.96.220.140:62310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KyrxMYwyVGnfuwsJ-DgAAA90"]
[Tue Jul 21 07:32:42.789341 2026] [security2:error] [pid 255769:tid 255957] [client 59.96.220.140:62310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9KyrxMYwyVGnfuwsJ-DgAAA90"]
[Tue Jul 21 07:32:42.912214 2026] [security2:error] [pid 254995:tid 255163] [client 74.248.121.109:2143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/storage/index.php"] [unique_id "al9Kyv7v0rlcEGmVraElLgAAA0Q"]
[Tue Jul 21 07:32:42.982509 2026] [security2:error] [pid 254995:tid 255138] [client 20.220.225.223:46122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/tkikikoko.php"] [unique_id "al9Kyv7v0rlcEGmVraElLwAAAys"]
[Tue Jul 21 07:32:43.008523 2026] [security2:error] [pid 255769:tid 255900] [client 20.220.225.223:19296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/mimpi.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-EQAAA6Q"]
[Tue Jul 21 07:32:43.083522 2026] [security2:error] [pid 254995:tid 255036] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ky_7v0rlcEGmVraElMQADiig"]
[Tue Jul 21 07:32:43.083701 2026] [security2:error] [pid 254995:tid 255260] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ky_7v0rlcEGmVraElMQADiig"]
[Tue Jul 21 07:32:43.086446 2026] [security2:error] [pid 255769:tid 255880] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-EwADtW4"]
[Tue Jul 21 07:32:43.086610 2026] [security2:error] [pid 255769:tid 255917] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-EwADtW4"]
[Tue Jul 21 07:32:43.138362 2026] [security2:error] [pid 255769:tid 255947] [client 139.167.225.182:62447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-FgAAA9M"]
[Tue Jul 21 07:32:43.138500 2026] [security2:error] [pid 255769:tid 255947] [client 139.167.225.182:62447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-FgAAA9M"]
[Tue Jul 21 07:32:43.164488 2026] [security2:error] [pid 255769:tid 255982] [client 20.206.105.145:7247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/prekel.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-GAAAA_Y"]
[Tue Jul 21 07:32:43.184106 2026] [security2:error] [pid 254995:tid 255150] [client 20.206.105.145:38920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/177.php"] [unique_id "al9Ky_7v0rlcEGmVraElNAAAAzc"]
[Tue Jul 21 07:32:43.348876 2026] [security2:error] [pid 255769:tid 255940] [client 74.248.121.109:1031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/g.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-GwAAA8w"]
[Tue Jul 21 07:32:43.479535 2026] [security2:error] [pid 254995:tid 255157] [client 117.251.86.144:39844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Ky_7v0rlcEGmVraElOgAAAz4"]
[Tue Jul 21 07:32:43.479652 2026] [security2:error] [pid 254995:tid 255157] [client 117.251.86.144:39844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Ky_7v0rlcEGmVraElOgAAAz4"]
[Tue Jul 21 07:32:43.520040 2026] [security2:error] [pid 255769:tid 255884] [remote 81.173.115.7:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-IwAD23I"]
[Tue Jul 21 07:32:43.555995 2026] [security2:error] [pid 255769:tid 255970] [client 20.220.225.223:9252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/hp2.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-JgAAA-o"]
[Tue Jul 21 07:32:43.697723 2026] [security2:error] [pid 255769:tid 255885] [remote 45.79.123.44:57184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-KAAD3HM"]
[Tue Jul 21 07:32:43.777228 2026] [security2:error] [pid 254995:tid 255137] [client 74.248.121.109:2091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/nf.php"] [unique_id "al9Ky_7v0rlcEGmVraElPgAAAyo"]
[Tue Jul 21 07:32:43.778937 2026] [security2:error] [pid 255769:tid 255983] [client 45.8.17.129:53027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-author-biography/post-author-biography/class-wp-http.php"] [unique_id "al9Ky7xMYwyVGnfuwsJ-KQAAA_c"]
[Tue Jul 21 07:32:44.030786 2026] [security2:error] [pid 254995:tid 255127] [client 103.162.129.114:59585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KzP7v0rlcEGmVraElQwAAAyA"]
[Tue Jul 21 07:32:44.030917 2026] [security2:error] [pid 254995:tid 255127] [client 103.162.129.114:59585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9KzP7v0rlcEGmVraElQwAAAyA"]
[Tue Jul 21 07:32:44.212615 2026] [security2:error] [pid 255769:tid 255990] [client 74.248.121.109:2140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/xda.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-NgAAA_4"]
[Tue Jul 21 07:32:44.311386 2026] [security2:error] [pid 255769:tid 256025] [client 20.151.10.161:57372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-OgAABB8"]
[Tue Jul 21 07:32:44.358598 2026] [security2:error] [pid 255769:tid 255958] [client 152.59.154.239:62742] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-OwAAA94"]
[Tue Jul 21 07:32:44.358755 2026] [security2:error] [pid 255769:tid 255958] [client 152.59.154.239:62742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-OwAAA94"]
[Tue Jul 21 07:32:44.588428 2026] [security2:error] [pid 255769:tid 255975] [client 20.220.225.223:19266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/dp.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-PAAAA-8"]
[Tue Jul 21 07:32:44.637993 2026] [security2:error] [pid 254995:tid 255200] [client 74.248.121.109:1055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/shell.php"] [unique_id "al9KzP7v0rlcEGmVraElTgAAA2k"]
[Tue Jul 21 07:32:44.650694 2026] [security2:error] [pid 255769:tid 255972] [client 122.186.204.214:59651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-PgAAA-w"]
[Tue Jul 21 07:32:44.650840 2026] [security2:error] [pid 255769:tid 255972] [client 122.186.204.214:59651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-PgAAA-w"]
[Tue Jul 21 07:32:44.686572 2026] [security2:error] [pid 255769:tid 256023] [client 45.8.17.61:32121] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-time-to-read/post-time-to-read/post-template.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-QQAABB0"]
[Tue Jul 21 07:32:44.958649 2026] [security2:error] [pid 255769:tid 256008] [client 193.36.225.103:38971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9KzLxMYwyVGnfuwsJ-RAAABA4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:44.976585 2026] [security2:error] [pid 254995:tid 255077] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KzP7v0rlcEGmVraElUgADe1E"]
[Tue Jul 21 07:32:44.976733 2026] [security2:error] [pid 254995:tid 255219] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9KzP7v0rlcEGmVraElUgADe1E"]
[Tue Jul 21 07:32:45.085982 2026] [security2:error] [pid 255769:tid 255904] [client 74.248.121.109:1069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/3.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-RgAAA6g"]
[Tue Jul 21 07:32:45.328258 2026] [security2:error] [pid 255769:tid 255934] [client 20.52.136.55:1785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/autoload_classmap.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-TAAAA8Y"]
[Tue Jul 21 07:32:45.350074 2026] [security2:error] [pid 255769:tid 255924] [client 20.206.105.145:38956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/199.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-TQAAA7w"]
[Tue Jul 21 07:32:45.414254 2026] [security2:error] [pid 255769:tid 256026] [client 20.220.225.223:9223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/hp3.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-UAAABCA"]
[Tue Jul 21 07:32:45.506711 2026] [security2:error] [pid 255769:tid 255770] [remote 41.186.86.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexandrevitor1781543539748.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-UQAEGQA"]
[Tue Jul 21 07:32:45.506957 2026] [security2:error] [pid 255769:tid 256019] [client 41.186.86.12:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alexandrevitor1781543539748.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-UQAEGQA"]
[Tue Jul 21 07:32:45.592984 2026] [security2:error] [pid 255769:tid 255955] [client 45.8.17.125:30861] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-template/post-template/api-gateway.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-UwAAA9s"]
[Tue Jul 21 07:32:45.606116 2026] [security2:error] [pid 255769:tid 255973] [client 74.248.121.109:1077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/mds.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-VAAAA-0"]
[Tue Jul 21 07:32:45.635485 2026] [security2:error] [pid 255769:tid 255946] [client 20.220.225.223:46134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-VgAAA9I"]
[Tue Jul 21 07:32:45.798148 2026] [security2:error] [pid 255769:tid 255960] [client 20.206.105.145:7787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/0.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-XQAAA-A"]
[Tue Jul 21 07:32:45.906357 2026] [security2:error] [pid 255769:tid 255980] [client 62.102.148.164:55366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-XgAAA_Q"]
[Tue Jul 21 07:32:45.906476 2026] [security2:error] [pid 255769:tid 255980] [client 62.102.148.164:55366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-XgAAA_Q"]
[Tue Jul 21 07:32:45.907614 2026] [security2:error] [pid 255769:tid 256006] [client 20.197.195.24:13177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ops.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-XwAABAw"]
[Tue Jul 21 07:32:45.948480 2026] [security2:error] [pid 255769:tid 255968] [client 173.24.185.52:58705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-YAAAA-g"]
[Tue Jul 21 07:32:45.948620 2026] [security2:error] [pid 255769:tid 255968] [client 173.24.185.52:58705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9KzbxMYwyVGnfuwsJ-YAAAA-g"]
[Tue Jul 21 07:32:46.054616 2026] [security2:error] [pid 255769:tid 256000] [client 74.248.121.109:2139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/archive.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-YQAABAY"]
[Tue Jul 21 07:32:46.244043 2026] [security2:error] [pid 255769:tid 256013] [client 20.220.225.223:8115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/aa1.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-agAABBM"]
[Tue Jul 21 07:32:46.255729 2026] [security2:error] [pid 255769:tid 256028] [client 103.106.20.201:52187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-awAABCI"]
[Tue Jul 21 07:32:46.255877 2026] [security2:error] [pid 255769:tid 256028] [client 103.106.20.201:52187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-awAABCI"]
[Tue Jul 21 07:32:46.261935 2026] [security2:error] [pid 255769:tid 255964] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/framework/.env"] [unique_id "al9KzrxMYwyVGnfuwsJ-bAAAA-Q"]
[Tue Jul 21 07:32:46.264222 2026] [security2:error] [pid 255769:tid 255972] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/config.inc.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-bQAAA-w"]
[Tue Jul 21 07:32:46.343421 2026] [security2:error] [pid 254995:tid 255190] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/ikiwiki/.env"] [unique_id "al9Kzv7v0rlcEGmVraElYwAAA18"]
[Tue Jul 21 07:32:46.468480 2026] [security2:error] [pid 254995:tid 255078] [remote 8.217.108.67:19650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Kzv7v0rlcEGmVraElZgADPVI"]
[Tue Jul 21 07:32:46.473427 2026] [security2:error] [pid 254995:tid 255181] [client 74.248.121.109:2134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/amax.php"] [unique_id "al9Kzv7v0rlcEGmVraElZwAAA1Y"]
[Tue Jul 21 07:32:46.518094 2026] [security2:error] [pid 255769:tid 255907] [client 136.144.33.53:56073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-cQAAA6s"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:46.629843 2026] [security2:error] [pid 255769:tid 255778] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-eQAEHQg"]
[Tue Jul 21 07:32:46.629978 2026] [security2:error] [pid 255769:tid 256023] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-eQAEHQg"]
[Tue Jul 21 07:32:46.788864 2026] [security2:error] [pid 255769:tid 255947] [client 45.8.17.113:43467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/customize/network/index.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-ewAAA9M"]
[Tue Jul 21 07:32:46.800552 2026] [security2:error] [pid 255769:tid 256014] [client 154.192.233.199:59730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-fAAABBQ"]
[Tue Jul 21 07:32:46.800657 2026] [security2:error] [pid 255769:tid 256014] [client 154.192.233.199:59730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-fAAABBQ"]
[Tue Jul 21 07:32:46.906358 2026] [security2:error] [pid 255769:tid 255908] [client 74.248.121.109:1064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/moon.php"] [unique_id "al9KzrxMYwyVGnfuwsJ-gAAAA6w"]
[Tue Jul 21 07:32:46.969480 2026] [security2:error] [pid 254995:tid 255166] [client 82.102.28.107:41192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Kzv7v0rlcEGmVraElbQAAA0c"]
[Tue Jul 21 07:32:46.969579 2026] [security2:error] [pid 254995:tid 255166] [client 82.102.28.107:41192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Kzv7v0rlcEGmVraElbQAAA0c"]
[Tue Jul 21 07:32:47.299433 2026] [security2:error] [pid 255769:tid 255970] [client 20.206.105.145:7709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/BDKR28.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-gwAAA-o"]
[Tue Jul 21 07:32:47.419085 2026] [security2:error] [pid 255769:tid 255973] [client 37.140.223.191:59345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-ggAAA-0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:47.443757 2026] [security2:error] [pid 255769:tid 255923] [client 74.248.121.109:1035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/ws83.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-hwAAA7s"]
[Tue Jul 21 07:32:47.468589 2026] [security2:error] [pid 255769:tid 255937] [client 45.251.232.145:50772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-iAAAA8k"]
[Tue Jul 21 07:32:47.468730 2026] [security2:error] [pid 255769:tid 255937] [client 45.251.232.145:50772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-iAAAA8k"]
[Tue Jul 21 07:32:47.643985 2026] [proxy:error] [pid 254995:tid 255185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:47.644054 2026] [proxy_http:error] [pid 254995:tid 255185] [client 20.151.10.161:50898] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:47.644483 2026] [proxy:error] [pid 254995:tid 255185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:47.644516 2026] [proxy_http:error] [pid 254995:tid 255185] [client 20.151.10.161:50898] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:47.661911 2026] [security2:error] [pid 255769:tid 255792] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-jAAD3xY"]
[Tue Jul 21 07:32:47.662713 2026] [security2:error] [pid 255769:tid 255959] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-jAAD3xY"]
[Tue Jul 21 07:32:47.668292 2026] [security2:error] [pid 255769:tid 256026] [client 175.45.70.82:53585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-jgAABCA"]
[Tue Jul 21 07:32:47.668393 2026] [security2:error] [pid 255769:tid 256026] [client 175.45.70.82:53585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-jgAABCA"]
[Tue Jul 21 07:32:47.892580 2026] [security2:error] [pid 255769:tid 255950] [client 20.220.225.223:49578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Kz7xMYwyVGnfuwsJ-kgAAA9Y"]
[Tue Jul 21 07:32:47.908878 2026] [security2:error] [pid 254995:tid 255149] [client 74.248.121.109:1071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/CDX1.php"] [unique_id "al9Kz_7v0rlcEGmVraElhAAAAzY"]
[Tue Jul 21 07:32:47.993228 2026] [security2:error] [pid 254995:tid 255252] [client 20.220.225.223:8075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/acew67.php"] [unique_id "al9Kz_7v0rlcEGmVraElhQAAA4M"]
[Tue Jul 21 07:32:48.016978 2026] [security2:error] [pid 254995:tid 255133] [client 213.152.162.104:55686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9K0P7v0rlcEGmVraElhgAAAyY"]
[Tue Jul 21 07:32:48.017105 2026] [security2:error] [pid 254995:tid 255133] [client 213.152.162.104:55686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9K0P7v0rlcEGmVraElhgAAAyY"]
[Tue Jul 21 07:32:48.092911 2026] [security2:error] [pid 255769:tid 256015] [client 45.8.17.142:58255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/widgets/theme-compat/index.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-lAAABBU"]
[Tue Jul 21 07:32:48.359473 2026] [security2:error] [pid 255769:tid 256028] [client 74.248.121.109:2117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/inputs.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-mQAABCI"]
[Tue Jul 21 07:32:48.419013 2026] [security2:error] [pid 255769:tid 255916] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/system/.env"] [unique_id "al9K0LxMYwyVGnfuwsJ-nwAAA7Q"]
[Tue Jul 21 07:32:48.421666 2026] [security2:error] [pid 255769:tid 255952] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/wp-config.php.backup"] [unique_id "al9K0LxMYwyVGnfuwsJ-oAAAA9g"]
[Tue Jul 21 07:32:48.461787 2026] [security2:error] [pid 255769:tid 255957] [client 20.220.225.223:38686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/wp-signup.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-ogAAA90"]
[Tue Jul 21 07:32:48.481188 2026] [security2:error] [pid 255769:tid 256006] [client 103.174.34.15:61966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-owAABAw"]
[Tue Jul 21 07:32:48.481337 2026] [security2:error] [pid 255769:tid 256006] [client 103.174.34.15:61966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-owAABAw"]
[Tue Jul 21 07:32:48.540381 2026] [security2:error] [pid 255769:tid 255990] [client 171.61.166.54:30552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.166.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiapleno.com"] [uri "/xmlrpc.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-mgAAA_4"]
[Tue Jul 21 07:32:48.540556 2026] [security2:error] [pid 255769:tid 255990] [client 171.61.166.54:30552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "guiapleno.com"] [uri "/xmlrpc.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-mgAAA_4"]
[Tue Jul 21 07:32:48.736205 2026] [security2:error] [pid 255769:tid 256021] [client 20.220.225.223:4562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/dp.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-pQAABBs"]
[Tue Jul 21 07:32:48.791860 2026] [security2:error] [pid 255769:tid 255900] [client 74.248.121.109:1061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/ms-edit.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-pwAAA6Q"]
[Tue Jul 21 07:32:48.919102 2026] [security2:error] [pid 254995:tid 255174] [client 117.217.38.194:55805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K0P7v0rlcEGmVraElkAAAA08"]
[Tue Jul 21 07:32:48.919215 2026] [security2:error] [pid 254995:tid 255174] [client 117.217.38.194:55805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K0P7v0rlcEGmVraElkAAAA08"]
[Tue Jul 21 07:32:48.943070 2026] [security2:error] [pid 254995:tid 255193] [client 20.220.225.223:24205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9K0P7v0rlcEGmVraElkwAAA2I"]
[Tue Jul 21 07:32:48.987520 2026] [security2:error] [pid 255769:tid 255799] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-qwADuR0"]
[Tue Jul 21 07:32:48.987684 2026] [security2:error] [pid 255769:tid 255921] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K0LxMYwyVGnfuwsJ-qwADuR0"]
[Tue Jul 21 07:32:49.090205 2026] [security2:error] [pid 254995:tid 255139] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/app_dev.php/_profiler/open"] [unique_id "al9K0f7v0rlcEGmVraEllQAAAyw"]
[Tue Jul 21 07:32:49.102420 2026] [security2:error] [pid 254995:tid 255156] [client 20.206.105.145:7704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/f35.update.php"] [unique_id "al9K0f7v0rlcEGmVraEllgAAAz0"]
[Tue Jul 21 07:32:49.142358 2026] [security2:error] [pid 254995:tid 255181] [client 20.206.105.145:39235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file52.php"] [unique_id "al9K0f7v0rlcEGmVraEllwAAA1Y"]
[Tue Jul 21 07:32:49.190922 2026] [security2:error] [pid 255769:tid 255924] [client 20.220.225.223:49819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9K0bxMYwyVGnfuwsJ-rQAAA7w"]
[Tue Jul 21 07:32:49.252336 2026] [security2:error] [pid 255769:tid 255955] [client 74.248.121.109:2113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/simple.php"] [unique_id "al9K0bxMYwyVGnfuwsJ-sAAAA9s"]
[Tue Jul 21 07:32:49.255330 2026] [security2:error] [pid 254995:tid 255155] [client 20.197.195.24:13172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/file31.php"] [unique_id "al9K0f7v0rlcEGmVraElmgAAAzw"]
[Tue Jul 21 07:32:49.286396 2026] [security2:error] [pid 254995:tid 255154] [client 45.8.17.59:40259] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/upgrade/patterns/index.php"] [unique_id "al9K0f7v0rlcEGmVraElnAAAAzs"]
[Tue Jul 21 07:32:49.301148 2026] [security2:error] [pid 254995:tid 255202] [client 20.220.225.223:6791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/bscclapb.php"] [unique_id "al9K0f7v0rlcEGmVraElnQAAA2s"]
[Tue Jul 21 07:32:49.328292 2026] [security2:error] [pid 254995:tid 255136] [client 213.152.162.104:48208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9K0f7v0rlcEGmVraElngAAAyk"]
[Tue Jul 21 07:32:49.328374 2026] [security2:error] [pid 254995:tid 255136] [client 213.152.162.104:48208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9K0f7v0rlcEGmVraElngAAAyk"]
[Tue Jul 21 07:32:49.472533 2026] [security2:error] [pid 255769:tid 255994] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/wp-content/mysql.sql"] [unique_id "al9K0bxMYwyVGnfuwsJ-twAABAE"]
[Tue Jul 21 07:32:49.698450 2026] [security2:error] [pid 255769:tid 255998] [client 74.248.121.109:2154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/404.php"] [unique_id "al9K0bxMYwyVGnfuwsJ-uQAABAQ"]
[Tue Jul 21 07:32:49.769024 2026] [security2:error] [pid 255769:tid 255992] [client 193.36.225.103:45273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K0bxMYwyVGnfuwsJ-vQAAA_8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:49.833912 2026] [security2:error] [pid 254995:tid 255084] [remote 57.141.18.84:38554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9Kz_7v0rlcEGmVraElggADK1g"]
[Tue Jul 21 07:32:49.874333 2026] [security2:error] [pid 255769:tid 256000] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/php-info.php"] [unique_id "al9K0bxMYwyVGnfuwsJ-vwAABAY"]
[Tue Jul 21 07:32:50.163307 2026] [security2:error] [pid 254995:tid 255219] [client 74.248.121.109:1079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/file3.php"] [unique_id "al9K0v7v0rlcEGmVraElrQAAA3s"]
[Tue Jul 21 07:32:50.492396 2026] [security2:error] [pid 255769:tid 255975] [client 45.8.17.128:50475] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/images/widgets/index.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-yQAAA-8"]
[Tue Jul 21 07:32:50.574203 2026] [security2:error] [pid 254995:tid 255135] [client 20.197.195.24:13168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/file6.php"] [unique_id "al9K0v7v0rlcEGmVraElswAAAyg"]
[Tue Jul 21 07:32:50.600714 2026] [security2:error] [pid 255769:tid 255952] [client 74.248.121.109:1037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/wp-mail.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-zAAAA9g"]
[Tue Jul 21 07:32:50.647847 2026] [security2:error] [pid 255769:tid 255804] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-zQAD3iI"]
[Tue Jul 21 07:32:50.647968 2026] [security2:error] [pid 255769:tid 255958] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-zQAD3iI"]
[Tue Jul 21 07:32:50.703450 2026] [security2:error] [pid 255769:tid 256006] [client 20.151.10.161:50896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-zgAABAw"]
[Tue Jul 21 07:32:50.730274 2026] [security2:error] [pid 255769:tid 255907] [client 20.206.105.145:7717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/f900.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-zwAAA6s"]
[Tue Jul 21 07:32:50.742678 2026] [security2:error] [pid 255769:tid 255809] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-0QAD_ic"]
[Tue Jul 21 07:32:50.742848 2026] [security2:error] [pid 255769:tid 255990] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K0rxMYwyVGnfuwsJ-0QAD_ic"]
[Tue Jul 21 07:32:51.032827 2026] [security2:error] [pid 255769:tid 256014] [client 20.206.105.145:39253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/122.php"] [unique_id "al9K07xMYwyVGnfuwsJ-2AAABBQ"]
[Tue Jul 21 07:32:51.070219 2026] [security2:error] [pid 255769:tid 255908] [client 74.248.121.109:1043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/about.php"] [unique_id "al9K07xMYwyVGnfuwsJ-2gAAA6w"]
[Tue Jul 21 07:32:51.207182 2026] [access_compat:error] [pid 255769:tid 255948] [client 162.241.63.68:22062] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:32:51.243500 2026] [security2:error] [pid 254995:tid 255160] [client 136.144.33.29:60405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9K0_7v0rlcEGmVraElwAAAA0E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:51.420472 2026] [proxy:error] [pid 255769:tid 255956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:51.420511 2026] [proxy_http:error] [pid 255769:tid 255956] [client 198.235.24.243:59450] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:51.420946 2026] [proxy:error] [pid 255769:tid 255956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:51.420968 2026] [proxy_http:error] [pid 255769:tid 255956] [client 198.235.24.243:59450] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:51.706762 2026] [security2:error] [pid 255769:tid 255923] [client 20.206.105.145:7581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/xmrl.php"] [unique_id "al9K07xMYwyVGnfuwsJ-4QAAA7s"]
[Tue Jul 21 07:32:51.759817 2026] [security2:error] [pid 255769:tid 255984] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/info.php.bak"] [unique_id "al9K07xMYwyVGnfuwsJ-5AAAA_g"]
[Tue Jul 21 07:32:51.797228 2026] [security2:error] [pid 255769:tid 255994] [client 74.248.121.109:2057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/adminfuns.php"] [unique_id "al9K07xMYwyVGnfuwsJ-5QAABAE"]
[Tue Jul 21 07:32:51.908340 2026] [security2:error] [pid 255769:tid 255973] [client 193.36.225.105:24885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K07xMYwyVGnfuwsJ-4gAAA-0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:51.996980 2026] [security2:error] [pid 254995:tid 255275] [client 20.220.225.223:24242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9K0_7v0rlcEGmVraEl0AAAA5k"]
[Tue Jul 21 07:32:52.003954 2026] [autoindex:error] [pid 254995:tid 255166] [client 20.197.195.24:13121] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:32:52.012803 2026] [security2:error] [pid 254995:tid 255131] [client 20.197.195.24:13121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/adminfuns.php"] [unique_id "al9K1P7v0rlcEGmVraEl0QAAAyQ"]
[Tue Jul 21 07:32:52.115852 2026] [security2:error] [pid 254995:tid 255254] [client 20.52.136.55:1552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/av.php"] [unique_id "al9K1P7v0rlcEGmVraEl1QAAA4Q"]
[Tue Jul 21 07:32:52.157092 2026] [security2:error] [pid 254995:tid 255183] [client 82.102.28.107:49552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9K1P7v0rlcEGmVraEl1gAAA1g"]
[Tue Jul 21 07:32:52.157167 2026] [security2:error] [pid 254995:tid 255183] [client 82.102.28.107:49552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9K1P7v0rlcEGmVraEl1gAAA1g"]
[Tue Jul 21 07:32:52.284214 2026] [security2:error] [pid 254995:tid 255144] [client 45.8.17.108:58275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/customize/includes/index.php"] [unique_id "al9K1P7v0rlcEGmVraEl2AAAAzE"]
[Tue Jul 21 07:32:52.337553 2026] [security2:error] [pid 254995:tid 255189] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/phpinfo.php.bak"] [unique_id "al9K1P7v0rlcEGmVraEl2QAAA14"]
[Tue Jul 21 07:32:52.405384 2026] [security2:error] [pid 255769:tid 255961] [client 74.248.121.109:2069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/php8.php"] [unique_id "al9K1LxMYwyVGnfuwsJ-6gAAA-E"]
[Tue Jul 21 07:32:52.419226 2026] [security2:error] [pid 254995:tid 255138] [client 20.220.225.223:19267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/bootstrap.php"] [unique_id "al9K1P7v0rlcEGmVraEl2wAAAys"]
[Tue Jul 21 07:32:52.555058 2026] [security2:error] [pid 255769:tid 256002] [client 20.220.225.223:46086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wp-css.php"] [unique_id "al9K1LxMYwyVGnfuwsJ-6wAABAg"]
[Tue Jul 21 07:32:52.662043 2026] [security2:error] [pid 254995:tid 255198] [client 20.206.105.145:54573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/memberfuns.php"] [unique_id "al9K1P7v0rlcEGmVraEl4QAAA2c"]
[Tue Jul 21 07:32:52.724882 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.195.24:13069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/goods.php"] [unique_id "al9K1LxMYwyVGnfuwsJ-7wAABCI"]
[Tue Jul 21 07:32:52.729393 2026] [security2:error] [pid 255769:tid 255975] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/env/.env"] [unique_id "al9K1LxMYwyVGnfuwsJ-8AAAA-8"]
[Tue Jul 21 07:32:52.883602 2026] [security2:error] [pid 254995:tid 255141] [client 74.248.121.109:2125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/info.php"] [unique_id "al9K1P7v0rlcEGmVraEl5AAAAy4"]
[Tue Jul 21 07:32:52.995156 2026] [security2:error] [pid 255769:tid 255907] [client 74.7.244.14:47002] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "a12.arcoll.com.br"] [uri "/robots.txt"] [unique_id "al9K1LxMYwyVGnfuwsJ-9QADqy8"]
[Tue Jul 21 07:32:53.243112 2026] [security2:error] [pid 255769:tid 255927] [client 213.152.162.104:48220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ--gAAA78"]
[Tue Jul 21 07:32:53.243260 2026] [security2:error] [pid 255769:tid 255927] [client 213.152.162.104:48220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ--gAAA78"]
[Tue Jul 21 07:32:53.317001 2026] [security2:error] [pid 255769:tid 255820] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ-_AAEGzI"]
[Tue Jul 21 07:32:53.317161 2026] [security2:error] [pid 255769:tid 256021] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ-_AAEGzI"]
[Tue Jul 21 07:32:53.317725 2026] [security2:error] [pid 254995:tid 255155] [client 59.96.220.140:62791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K1f7v0rlcEGmVraEl7AAAAzw"]
[Tue Jul 21 07:32:53.317880 2026] [security2:error] [pid 254995:tid 255155] [client 59.96.220.140:62791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K1f7v0rlcEGmVraEl7AAAAzw"]
[Tue Jul 21 07:32:53.386676 2026] [security2:error] [pid 255769:tid 255904] [client 45.8.17.145:37063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/upgrade/index.php"] [unique_id "al9K1bxMYwyVGnfuwsJ-_QAAA6g"]
[Tue Jul 21 07:32:53.388570 2026] [security2:error] [pid 255769:tid 256022] [client 74.248.121.109:1049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/edit.php"] [unique_id "al9K1bxMYwyVGnfuwsJ-_gAABBw"]
[Tue Jul 21 07:32:53.400391 2026] [security2:error] [pid 255769:tid 255919] [client 20.197.195.24:13140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/100.php"] [unique_id "al9K1bxMYwyVGnfuwsJ-_wAAA7c"]
[Tue Jul 21 07:32:53.512643 2026] [security2:error] [pid 254995:tid 255157] [client 20.220.225.223:31213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/csa.php"] [unique_id "al9K1f7v0rlcEGmVraEl7wAAAz4"]
[Tue Jul 21 07:32:53.581495 2026] [security2:error] [pid 254995:tid 255024] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K1f7v0rlcEGmVraEl8AADOhw"]
[Tue Jul 21 07:32:53.581683 2026] [security2:error] [pid 254995:tid 255153] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K1f7v0rlcEGmVraEl8AADOhw"]
[Tue Jul 21 07:32:53.583075 2026] [security2:error] [pid 255769:tid 255953] [client 20.206.105.145:7466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ms.php"] [unique_id "al9K1bxMYwyVGnfuwsJ_AgAAA9k"]
[Tue Jul 21 07:32:53.599240 2026] [security2:error] [pid 255769:tid 255947] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/src/.env"] [unique_id "al9K1bxMYwyVGnfuwsJ_AwAAA9M"]
[Tue Jul 21 07:32:53.688796 2026] [security2:error] [pid 255769:tid 255934] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/config/app.php"] [unique_id "al9K1bxMYwyVGnfuwsJ_BgAAA8Y"]
[Tue Jul 21 07:32:53.796428 2026] [security2:error] [pid 255769:tid 255916] [client 139.167.225.182:63085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ_BwAAA7Q"]
[Tue Jul 21 07:32:53.796563 2026] [security2:error] [pid 255769:tid 255916] [client 139.167.225.182:63085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ_BwAAA7Q"]
[Tue Jul 21 07:32:53.846374 2026] [security2:error] [pid 254995:tid 255139] [client 74.248.121.109:1065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/166.php"] [unique_id "al9K1f7v0rlcEGmVraEl9wAAAyw"]
[Tue Jul 21 07:32:54.248393 2026] [security2:error] [pid 254995:tid 255267] [client 117.251.86.144:60520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K1v7v0rlcEGmVraEmAAAAA5E"]
[Tue Jul 21 07:32:54.248499 2026] [security2:error] [pid 254995:tid 255267] [client 117.251.86.144:60520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K1v7v0rlcEGmVraEmAAAAA5E"]
[Tue Jul 21 07:32:54.315280 2026] [security2:error] [pid 255769:tid 256018] [client 74.248.121.109:1083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/8.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_DgAABBg"]
[Tue Jul 21 07:32:54.377141 2026] [security2:error] [pid 255769:tid 255984] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/web/.env"] [unique_id "al9K1rxMYwyVGnfuwsJ_DwAAA_g"]
[Tue Jul 21 07:32:54.388483 2026] [security2:error] [pid 255769:tid 255937] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_EAAAA8k"]
[Tue Jul 21 07:32:54.440874 2026] [security2:error] [pid 255769:tid 255973] [client 20.206.105.145:39247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/green1.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_EQAAA-0"]
[Tue Jul 21 07:32:54.553102 2026] [security2:error] [pid 255769:tid 255822] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ_AQAD9jQ"]
[Tue Jul 21 07:32:54.553313 2026] [security2:error] [pid 255769:tid 255982] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K1bxMYwyVGnfuwsJ_AQAD9jQ"]
[Tue Jul 21 07:32:54.609950 2026] [security2:error] [pid 255769:tid 256000] [client 20.197.195.24:13066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/about.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_FQAABAY"]
[Tue Jul 21 07:32:54.684931 2026] [security2:error] [pid 255769:tid 255981] [client 45.8.17.48:40049] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/news-portal/user-install.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_GAAAA_U"]
[Tue Jul 21 07:32:54.721713 2026] [security2:error] [pid 255769:tid 256025] [client 20.206.105.145:7751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/zz.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_HAAABB8"]
[Tue Jul 21 07:32:54.780992 2026] [security2:error] [pid 254995:tid 255268] [client 109.248.148.246:58816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9K1v7v0rlcEGmVraEmCwAAA5I"]
[Tue Jul 21 07:32:54.781172 2026] [security2:error] [pid 254995:tid 255268] [client 109.248.148.246:58816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9K1v7v0rlcEGmVraEmCwAAA5I"]
[Tue Jul 21 07:32:54.781208 2026] [security2:error] [pid 254995:tid 255254] [client 74.248.121.109:2048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/ws38.php"] [unique_id "al9K1v7v0rlcEGmVraEmDAAAA4Q"]
[Tue Jul 21 07:32:54.814379 2026] [security2:error] [pid 255769:tid 255949] [client 103.162.129.114:60030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_HwAAA9U"]
[Tue Jul 21 07:32:54.814507 2026] [security2:error] [pid 255769:tid 255949] [client 103.162.129.114:60030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K1rxMYwyVGnfuwsJ_HwAAA9U"]
[Tue Jul 21 07:32:55.225181 2026] [security2:error] [pid 255769:tid 255925] [client 20.206.105.145:54589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/for.php"] [unique_id "al9K17xMYwyVGnfuwsJ_IgAAA70"]
[Tue Jul 21 07:32:55.281022 2026] [security2:error] [pid 255769:tid 255939] [client 74.248.121.109:1074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/a7.php"] [unique_id "al9K17xMYwyVGnfuwsJ_JAAAA8s"]
[Tue Jul 21 07:32:55.381833 2026] [security2:error] [pid 255769:tid 256002] [client 122.186.204.214:60159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K17xMYwyVGnfuwsJ_KQAABAg"]
[Tue Jul 21 07:32:55.381966 2026] [security2:error] [pid 255769:tid 256002] [client 122.186.204.214:60159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K17xMYwyVGnfuwsJ_KQAABAg"]
[Tue Jul 21 07:32:55.446155 2026] [security2:error] [pid 255769:tid 256022] [client 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/core/.env"] [unique_id "al9K17xMYwyVGnfuwsJ_KgAABBw"]
[Tue Jul 21 07:32:55.587685 2026] [security2:error] [pid 255769:tid 256007] [client 20.197.195.24:13082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/about.php"] [unique_id "al9K17xMYwyVGnfuwsJ_LAAABA0"]
[Tue Jul 21 07:32:55.604376 2026] [security2:error] [pid 255769:tid 255953] [client 20.220.225.223:9256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/else1.php"] [unique_id "al9K17xMYwyVGnfuwsJ_LgAAA9k"]
[Tue Jul 21 07:32:55.707611 2026] [security2:error] [pid 255769:tid 255825] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K17xMYwyVGnfuwsJ_LwAEFDc"]
[Tue Jul 21 07:32:55.707749 2026] [security2:error] [pid 255769:tid 256014] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K17xMYwyVGnfuwsJ_LwAEFDc"]
[Tue Jul 21 07:32:55.741411 2026] [security2:error] [pid 254995:tid 255174] [client 172.245.102.42:58803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9K1_7v0rlcEGmVraEmFwAAA08"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:32:55.758921 2026] [security2:error] [pid 255769:tid 256011] [client 74.248.121.109:2112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/classsmtps.php"] [unique_id "al9K17xMYwyVGnfuwsJ_MgAABBE"]
[Tue Jul 21 07:32:55.764252 2026] [proxy:error] [pid 255769:tid 255948] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:55.764306 2026] [proxy_http:error] [pid 255769:tid 255948] [client 20.151.10.161:57383] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:55.765101 2026] [proxy:error] [pid 255769:tid 255948] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:32:55.765144 2026] [proxy_http:error] [pid 255769:tid 255948] [client 20.151.10.161:57383] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:32:55.788543 2026] [security2:error] [pid 255769:tid 255946] [client 45.8.17.148:57047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/missing/missing/theme-single.php"] [unique_id "al9K17xMYwyVGnfuwsJ_NwAAA9I"]
[Tue Jul 21 07:32:56.170484 2026] [security2:error] [pid 255769:tid 255994] [client 20.10.88.201:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "produto-express.com"] [uri "/index.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_PQAEAUA"]
[Tue Jul 21 07:32:56.174429 2026] [security2:error] [pid 255769:tid 255977] [client 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/phpinfo.php3"] [unique_id "al9K2LxMYwyVGnfuwsJ_PgAAA_E"]
[Tue Jul 21 07:32:56.253771 2026] [security2:error] [pid 255769:tid 255960] [client 74.248.121.109:1030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/rip.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_PwAAA-A"]
[Tue Jul 21 07:32:56.501123 2026] [security2:error] [pid 255769:tid 255835] [remote 45.79.123.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp/wp-login.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_RQAD9EE"]
[Tue Jul 21 07:32:56.551300 2026] [security2:error] [pid 255769:tid 255972] [client 20.220.225.223:19670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/wp-editor.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_RgAAA-w"]
[Tue Jul 21 07:32:56.589287 2026] [security2:error] [pid 255769:tid 256027] [client 173.24.185.52:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_RwAABCE"]
[Tue Jul 21 07:32:56.593970 2026] [security2:error] [pid 255769:tid 256027] [client 173.24.185.52:59182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_RwAABCE"]
[Tue Jul 21 07:32:56.630239 2026] [security2:error] [pid 255769:tid 255978] [client 20.206.105.145:39260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/biufile.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_SgAAA_I"]
[Tue Jul 21 07:32:56.716642 2026] [security2:error] [pid 255769:tid 255952] [client 74.248.121.109:1056] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "issimastore.com.issima.net.br"] [uri "/1.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_SwAAA9g"]
[Tue Jul 21 07:32:56.716799 2026] [security2:error] [pid 255769:tid 255952] [client 74.248.121.109:1056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/1.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_SwAAA9g"]
[Tue Jul 21 07:32:56.787587 2026] [security2:error] [pid 255769:tid 255979] [client 45.8.17.126:38965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/admin-header-string.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_TAAAA_M"]
[Tue Jul 21 07:32:56.828632 2026] [security2:error] [pid 255769:tid 255907] [client 20.220.225.223:24264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/wander.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_TQAAA6s"]
[Tue Jul 21 07:32:56.830260 2026] [security2:error] [pid 254995:tid 255270] [client 20.206.105.145:54563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/yup.php"] [unique_id "al9K2P7v0rlcEGmVraEmJgAAA5Q"]
[Tue Jul 21 07:32:56.973158 2026] [security2:error] [pid 255769:tid 256000] [client 103.106.20.201:52729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_TwAABAY"]
[Tue Jul 21 07:32:56.973288 2026] [security2:error] [pid 255769:tid 256000] [client 103.106.20.201:52729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2LxMYwyVGnfuwsJ_TwAABAY"]
[Tue Jul 21 07:32:57.260968 2026] [security2:error] [pid 254995:tid 255223] [client 74.248.121.109:2147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/chosen.php"] [unique_id "al9K2f7v0rlcEGmVraEmLQAAA38"]
[Tue Jul 21 07:32:57.265993 2026] [security2:error] [pid 255769:tid 255837] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_VAAEDUM"]
[Tue Jul 21 07:32:57.266161 2026] [security2:error] [pid 255769:tid 256007] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_VAAEDUM"]
[Tue Jul 21 07:32:57.463337 2026] [security2:error] [pid 255769:tid 256006] [client 154.192.233.199:60206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_WAAABAw"]
[Tue Jul 21 07:32:57.463444 2026] [security2:error] [pid 255769:tid 256006] [client 154.192.233.199:60206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_WAAABAw"]
[Tue Jul 21 07:32:57.537997 2026] [security2:error] [pid 255769:tid 255903] [client 20.220.225.223:6100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/nhvoanpl.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_WQAAA6c"]
[Tue Jul 21 07:32:57.559523 2026] [security2:error] [pid 255769:tid 255976] [client 20.197.195.24:13104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/admin.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_WgAAA_A"]
[Tue Jul 21 07:32:57.731253 2026] [security2:error] [pid 255769:tid 255933] [client 74.248.121.109:1054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/css.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_XwAAA8U"]
[Tue Jul 21 07:32:57.788322 2026] [security2:error] [pid 254995:tid 255172] [client 45.8.17.113:63713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/fonts-long.php"] [unique_id "al9K2f7v0rlcEGmVraEmNgAAA00"]
[Tue Jul 21 07:32:57.795443 2026] [security2:error] [pid 255769:tid 255987] [client 20.220.225.223:19316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/cro.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_ZAAAA_s"]
[Tue Jul 21 07:32:57.944744 2026] [security2:error] [pid 255769:tid 255919] [client 45.251.232.145:51291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_agAAA7c"]
[Tue Jul 21 07:32:57.944871 2026] [security2:error] [pid 255769:tid 255919] [client 45.251.232.145:51291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2bxMYwyVGnfuwsJ_agAAA7c"]
[Tue Jul 21 07:32:58.001641 2026] [security2:error] [pid 255769:tid 255980] [client 20.206.105.145:7571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wpxml.php"] [unique_id "al9K2rxMYwyVGnfuwsJ_awAAA_Q"]
[Tue Jul 21 07:32:58.192553 2026] [security2:error] [pid 254995:tid 255220] [client 74.248.121.109:1063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/php.php"] [unique_id "al9K2v7v0rlcEGmVraEmOgAAA3w"]
[Tue Jul 21 07:32:58.270628 2026] [security2:error] [pid 255769:tid 256000] [client 20.220.225.223:44229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/bootstrap.php"] [unique_id "al9K2rxMYwyVGnfuwsJ_fgAABAY"]
[Tue Jul 21 07:32:58.332322 2026] [security2:error] [pid 254995:tid 255121] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K2v7v0rlcEGmVraEmPgADKX0"]
[Tue Jul 21 07:32:58.332461 2026] [security2:error] [pid 254995:tid 255136] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K2v7v0rlcEGmVraEmPgADKX0"]
[Tue Jul 21 07:32:58.491501 2026] [security2:error] [pid 255769:tid 255982] [client 175.45.70.82:54089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2rxMYwyVGnfuwsJ_hwAAA_Y"]
[Tue Jul 21 07:32:58.491595 2026] [security2:error] [pid 255769:tid 255982] [client 175.45.70.82:54089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K2rxMYwyVGnfuwsJ_hwAAA_Y"]
[Tue Jul 21 07:32:58.554266 2026] [security2:error] [pid 254995:tid 255134] [client 20.206.105.145:38947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wpconf.php"] [unique_id "al9K2v7v0rlcEGmVraEmQwAAAyc"]
[Tue Jul 21 07:32:58.704319 2026] [security2:error] [pid 255769:tid 255906] [client 109.248.148.246:36748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9K2rxMYwyVGnfuwsJ_kwAAA6o"]
[Tue Jul 21 07:32:58.704408 2026] [security2:error] [pid 255769:tid 255906] [client 109.248.148.246:36748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9K2rxMYwyVGnfuwsJ_kwAAA6o"]
[Tue Jul 21 07:32:58.706260 2026] [security2:error] [pid 255769:tid 255961] [client 185.198.240.213:45347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9K2rxMYwyVGnfuwsJ_kgAAA-E"]
[Tue Jul 21 07:32:58.706682 2026] [security2:error] [pid 254995:tid 255173] [client 185.198.240.194:24577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9K2v7v0rlcEGmVraEmRwAAA04"]
[Tue Jul 21 07:32:58.711736 2026] [security2:error] [pid 254995:tid 255215] [client 20.220.225.223:23482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/inso.php"] [unique_id "al9K2v7v0rlcEGmVraEmSAAAA3c"]
[Tue Jul 21 07:32:58.755299 2026] [security2:error] [pid 254995:tid 255195] [client 74.248.121.109:2133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/aa.php"] [unique_id "al9K2v7v0rlcEGmVraEmSgAAA2Q"]
[Tue Jul 21 07:32:58.986479 2026] [security2:error] [pid 254995:tid 255141] [client 45.8.17.131:50529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/wp-config/index.php"] [unique_id "al9K2v7v0rlcEGmVraEmTgAAAy4"]
[Tue Jul 21 07:32:59.249279 2026] [security2:error] [pid 255769:tid 255965] [client 74.248.121.109:2116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/bolt.php"] [unique_id "al9K27xMYwyVGnfuwsJ_owAAA-U"]
[Tue Jul 21 07:32:59.321774 2026] [security2:error] [pid 255769:tid 256011] [client 103.174.34.15:62456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K27xMYwyVGnfuwsJ_pgAABBE"]
[Tue Jul 21 07:32:59.321909 2026] [security2:error] [pid 255769:tid 256011] [client 103.174.34.15:62456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K27xMYwyVGnfuwsJ_pgAABBE"]
[Tue Jul 21 07:32:59.381253 2026] [security2:error] [pid 255769:tid 256026] [client 117.217.38.194:56240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K27xMYwyVGnfuwsJ_qAAABCA"]
[Tue Jul 21 07:32:59.381397 2026] [security2:error] [pid 255769:tid 256026] [client 117.217.38.194:56240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K27xMYwyVGnfuwsJ_qAAABCA"]
[Tue Jul 21 07:32:59.501892 2026] [security2:error] [pid 255769:tid 255944] [client 20.197.195.24:13176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/admin.php"] [unique_id "al9K27xMYwyVGnfuwsJ_qQAAA9A"]
[Tue Jul 21 07:32:59.512507 2026] [security2:error] [pid 255769:tid 255926] [client 172.245.102.30:57379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K27xMYwyVGnfuwsJ_pwAAA74"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:32:59.521124 2026] [security2:error] [pid 255769:tid 255878] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K27xMYwyVGnfuwsJ_rAAD7mw"]
[Tue Jul 21 07:32:59.521334 2026] [security2:error] [pid 255769:tid 255974] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K27xMYwyVGnfuwsJ_rAAD7mw"]
[Tue Jul 21 07:32:59.594555 2026] [security2:error] [pid 255769:tid 255972] [client 20.220.225.223:61954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wp-editor.php"] [unique_id "al9K27xMYwyVGnfuwsJ_rwAAA-w"]
[Tue Jul 21 07:32:59.635600 2026] [security2:error] [pid 255769:tid 255978] [client 20.220.225.223:46107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/wp-explorer.php"] [unique_id "al9K27xMYwyVGnfuwsJ_sAAAA_I"]
[Tue Jul 21 07:32:59.727423 2026] [security2:error] [pid 255769:tid 255988] [client 74.248.121.109:1050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/x.php"] [unique_id "al9K27xMYwyVGnfuwsJ_tAAAA_w"]
[Tue Jul 21 07:32:59.883222 2026] [security2:error] [pid 255769:tid 255884] [remote 103.112.62.59:42670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psooffshore.com.br"] [uri "/wp-login.php"] [unique_id "al9K27xMYwyVGnfuwsJ_twAEFXI"]
[Tue Jul 21 07:32:59.884240 2026] [security2:error] [pid 254995:tid 255153] [client 45.8.17.119:46709] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/cyber-security-blocks/parts/parts/user-edit.php"] [unique_id "al9K2_7v0rlcEGmVraEmWgAAAzo"]
[Tue Jul 21 07:33:00.191757 2026] [security2:error] [pid 255769:tid 256007] [client 74.248.121.109:2049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/jga.php"] [unique_id "al9K3LxMYwyVGnfuwsJ_vAAABA0"]
[Tue Jul 21 07:33:00.508318 2026] [security2:error] [pid 254995:tid 255084] [remote 34.141.229.34:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "marmorariasolare.com.br"] [uri "/data:,"] [unique_id "al9K3P7v0rlcEGmVraEmYwADIlg"]
[Tue Jul 21 07:33:00.508550 2026] [security2:error] [pid 254995:tid 255129] [client 34.141.229.34:0] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "marmorariasolare.com.br"] [uri "/data:,"] [unique_id "al9K3P7v0rlcEGmVraEmYwADIlg"]
[Tue Jul 21 07:33:00.658380 2026] [security2:error] [pid 255769:tid 255976] [client 20.206.105.145:7437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/fffm.php"] [unique_id "al9K3LxMYwyVGnfuwsJ_wgAAA_A"]
[Tue Jul 21 07:33:00.689234 2026] [security2:error] [pid 254995:tid 255165] [client 136.144.33.215:56033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9K2_7v0rlcEGmVraEmVAAAA0Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:00.931679 2026] [security2:error] [pid 254995:tid 255185] [client 62.102.148.164:53418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9K3P7v0rlcEGmVraEmcwAAA1o"]
[Tue Jul 21 07:33:00.931766 2026] [security2:error] [pid 254995:tid 255185] [client 62.102.148.164:53418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9K3P7v0rlcEGmVraEmcwAAA1o"]
[Tue Jul 21 07:33:00.946124 2026] [security2:error] [pid 254995:tid 255183] [client 74.248.121.109:2159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/k.php"] [unique_id "al9K3P7v0rlcEGmVraEmdAAAA1g"]
[Tue Jul 21 07:33:01.049494 2026] [security2:error] [pid 255769:tid 255887] [remote 154.61.75.100:54126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-login.php"] [unique_id "al9K3bxMYwyVGnfuwsJ_ygADvHU"]
[Tue Jul 21 07:33:01.081446 2026] [security2:error] [pid 254995:tid 255179] [client 45.8.17.62:30319] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/shadow-bot.php"] [unique_id "al9K3f7v0rlcEGmVraEmdgAAA1Q"]
[Tue Jul 21 07:33:01.316460 2026] [security2:error] [pid 254995:tid 255008] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K3f7v0rlcEGmVraEmfgADXQw"]
[Tue Jul 21 07:33:01.316653 2026] [security2:error] [pid 254995:tid 255188] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K3f7v0rlcEGmVraEmfgADXQw"]
[Tue Jul 21 07:33:01.398890 2026] [security2:error] [pid 255769:tid 255980] [client 213.152.162.104:50228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9K3bxMYwyVGnfuwsJ_0QAAA_Q"]
[Tue Jul 21 07:33:01.399013 2026] [security2:error] [pid 255769:tid 255980] [client 213.152.162.104:50228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9K3bxMYwyVGnfuwsJ_0QAAA_Q"]
[Tue Jul 21 07:33:01.542901 2026] [security2:error] [pid 254995:tid 255028] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K3f7v0rlcEGmVraEmfwADiCA"]
[Tue Jul 21 07:33:01.543040 2026] [security2:error] [pid 254995:tid 255258] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K3f7v0rlcEGmVraEmfwADiCA"]
[Tue Jul 21 07:33:01.591221 2026] [security2:error] [pid 254995:tid 255229] [client 74.248.121.109:2060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/vx.php"] [unique_id "al9K3f7v0rlcEGmVraEmgAAAA4I"]
[Tue Jul 21 07:33:01.775801 2026] [security2:error] [pid 255769:tid 256024] [client 20.206.105.145:39274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/mosty.php"] [unique_id "al9K3bxMYwyVGnfuwsJ_1AAABB4"]
[Tue Jul 21 07:33:01.811129 2026] [security2:error] [pid 255769:tid 255886] [remote 65.111.10.224:26611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9K3LxMYwyVGnfuwsJ_wAADxnQ"]
[Tue Jul 21 07:33:02.187644 2026] [security2:error] [pid 255769:tid 255919] [client 45.8.17.107:50777] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/html/html/dark-mode.php"] [unique_id "al9K3rxMYwyVGnfuwsJ_5QAAA7c"]
[Tue Jul 21 07:33:02.325068 2026] [security2:error] [pid 255769:tid 255946] [client 20.197.195.24:13139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/themes.php"] [unique_id "al9K3rxMYwyVGnfuwsJ_5wAAA9I"]
[Tue Jul 21 07:33:02.367076 2026] [security2:error] [pid 254995:tid 255146] [client 74.248.121.109:1070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/ws77.php"] [unique_id "al9K3v7v0rlcEGmVraEmjgAAAzM"]
[Tue Jul 21 07:33:02.745201 2026] [security2:error] [pid 254995:tid 255206] [client 20.220.225.223:46095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/akismet.php"] [unique_id "al9K3v7v0rlcEGmVraEmlAAAA28"]
[Tue Jul 21 07:33:02.860506 2026] [security2:error] [pid 255769:tid 255935] [client 74.248.121.109:2120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/2.php"] [unique_id "al9K3rxMYwyVGnfuwsJ_7AAAA8c"]
[Tue Jul 21 07:33:02.931493 2026] [security2:error] [pid 254995:tid 255158] [client 20.52.136.55:1759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/gg.php"] [unique_id "al9K3v7v0rlcEGmVraEmmAAAAz8"]
[Tue Jul 21 07:33:03.085510 2026] [security2:error] [pid 255769:tid 255981] [client 20.206.105.145:39294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/dejavu.php"] [unique_id "al9K37xMYwyVGnfuwsJ_8AAAA_U"]
[Tue Jul 21 07:33:03.224306 2026] [security2:error] [pid 255769:tid 256019] [client 20.220.225.223:6792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/tkikikoko.php"] [unique_id "al9K37xMYwyVGnfuwsJ_9QAABBk"]
[Tue Jul 21 07:33:03.290567 2026] [security2:error] [pid 255769:tid 255949] [client 45.8.17.137:53445] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/menu-beta.php"] [unique_id "al9K37xMYwyVGnfuwsJ_9wAAA9U"]
[Tue Jul 21 07:33:03.294514 2026] [security2:error] [pid 254995:tid 255027] [remote 209.42.21.221:56636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9K3_7v0rlcEGmVraEmnwADXx8"]
[Tue Jul 21 07:33:03.368616 2026] [security2:error] [pid 255769:tid 255980] [client 20.220.225.223:63856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/cro.php"] [unique_id "al9K37xMYwyVGnfuwsJ_-QAAA_Q"]
[Tue Jul 21 07:33:03.370349 2026] [security2:error] [pid 254995:tid 255164] [client 74.248.121.109:2173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/asd.php"] [unique_id "al9K3_7v0rlcEGmVraEmoQAAA0U"]
[Tue Jul 21 07:33:03.506277 2026] [autoindex:error] [pid 254995:tid 255186] [client 20.197.195.24:13133] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:03.622468 2026] [security2:error] [pid 254995:tid 255256] [client 193.36.225.123:40361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K3v7v0rlcEGmVraEmjwAAA4Y"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:03.870867 2026] [security2:error] [pid 254995:tid 255091] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K3_7v0rlcEGmVraEmsQADQF8"]
[Tue Jul 21 07:33:03.871032 2026] [security2:error] [pid 254995:tid 255159] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K3_7v0rlcEGmVraEmsQADQF8"]
[Tue Jul 21 07:33:03.914280 2026] [security2:error] [pid 255769:tid 255905] [client 74.248.121.109:2130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/default.php"] [unique_id "al9K37xMYwyVGnfuwsJ_-gAAA6k"]
[Tue Jul 21 07:33:04.022329 2026] [security2:error] [pid 255769:tid 255780] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsJ__QADvQo"]
[Tue Jul 21 07:33:04.022555 2026] [security2:error] [pid 255769:tid 255925] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsJ__QADvQo"]
[Tue Jul 21 07:33:04.079772 2026] [security2:error] [pid 255769:tid 255782] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsJ__wADqww"]
[Tue Jul 21 07:33:04.079956 2026] [security2:error] [pid 255769:tid 255907] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsJ__wADqww"]
[Tue Jul 21 07:33:04.089682 2026] [security2:error] [pid 255769:tid 255957] [client 59.96.220.140:63246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsKAAAAAA90"]
[Tue Jul 21 07:33:04.089831 2026] [security2:error] [pid 255769:tid 255957] [client 59.96.220.140:63246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsKAAAAAA90"]
[Tue Jul 21 07:33:04.156308 2026] [security2:error] [pid 254995:tid 255012] [remote 104.207.36.190:45493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.36.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9K4P7v0rlcEGmVraEmtAADYxA"]
[Tue Jul 21 07:33:04.286709 2026] [security2:error] [pid 255769:tid 255982] [client 45.8.17.124:36847] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/block-bindings/lib/index.php"] [unique_id "al9K4LxMYwyVGnfuwsKABAAAA_Y"]
[Tue Jul 21 07:33:04.339849 2026] [security2:error] [pid 254995:tid 255166] [client 74.248.121.109:2156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/gettest.php"] [unique_id "al9K4P7v0rlcEGmVraEmuQAAA0c"]
[Tue Jul 21 07:33:04.362228 2026] [security2:error] [pid 254995:tid 255263] [client 20.206.105.145:38926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/aaf.php"] [unique_id "al9K4P7v0rlcEGmVraEmugAAA40"]
[Tue Jul 21 07:33:04.423611 2026] [security2:error] [pid 254995:tid 255140] [client 139.167.225.182:63716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K4P7v0rlcEGmVraEmvAAAAy0"]
[Tue Jul 21 07:33:04.423752 2026] [security2:error] [pid 254995:tid 255140] [client 139.167.225.182:63716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K4P7v0rlcEGmVraEmvAAAAy0"]
[Tue Jul 21 07:33:04.449311 2026] [security2:error] [pid 255769:tid 256023] [client 20.220.225.223:8945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/else1.php"] [unique_id "al9K4LxMYwyVGnfuwsKABQAABB0"]
[Tue Jul 21 07:33:04.784307 2026] [security2:error] [pid 254995:tid 255169] [client 20.197.195.24:13133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/.well-known/about.php"] [unique_id "al9K4P7v0rlcEGmVraEmwgAAA0o"]
[Tue Jul 21 07:33:04.952439 2026] [security2:error] [pid 255769:tid 255922] [client 117.251.86.144:39764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsKADAAAA7o"]
[Tue Jul 21 07:33:04.952551 2026] [security2:error] [pid 255769:tid 255922] [client 117.251.86.144:39764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K4LxMYwyVGnfuwsKADAAAA7o"]
[Tue Jul 21 07:33:05.039504 2026] [security2:error] [pid 255769:tid 255917] [client 74.248.121.109:1076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/tfm.php"] [unique_id "al9K4bxMYwyVGnfuwsKAEAAAA7U"]
[Tue Jul 21 07:33:05.073972 2026] [security2:error] [pid 255769:tid 255955] [client 209.141.34.121:62554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "oliviapintoadv.com.br"] [uri "/"] [unique_id "al9K4bxMYwyVGnfuwsKAEwAAA9s"]
[Tue Jul 21 07:33:05.289949 2026] [security2:error] [pid 255769:tid 255994] [client 45.8.17.140:35769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/theme-install-table.php"] [unique_id "al9K4bxMYwyVGnfuwsKAGQAABAE"]
[Tue Jul 21 07:33:05.403034 2026] [security2:error] [pid 255769:tid 255952] [client 172.245.102.42:43205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9K4bxMYwyVGnfuwsKAHAAAA9g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:05.517239 2026] [security2:error] [pid 255769:tid 255968] [client 74.248.121.109:2122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/ws81.php"] [unique_id "al9K4bxMYwyVGnfuwsKAHwAAA-g"]
[Tue Jul 21 07:33:05.589139 2026] [security2:error] [pid 255769:tid 255947] [client 209.141.34.121:62597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "oliviapintoadv.com.br"] [uri "/"] [unique_id "al9K4bxMYwyVGnfuwsKAIAAAA9M"]
[Tue Jul 21 07:33:05.638632 2026] [core:alert] [pid 255769:tid 255904] [client 57.141.18.21:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:33:05.726673 2026] [security2:error] [pid 255769:tid 255976] [client 74.7.241.174:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bellascleaningsolutionsllc.com"] [uri "/index.php"] [unique_id "al9K4bxMYwyVGnfuwsKAEQAAA_A"]
[Tue Jul 21 07:33:05.727675 2026] [security2:error] [pid 254995:tid 255151] [client 74.7.241.174:51948] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bellascleaningsolutionsllc.com"] [uri "/robots.txt"] [unique_id "al9K4f7v0rlcEGmVraEmxwADOD8"]
[Tue Jul 21 07:33:05.795571 2026] [security2:error] [pid 255769:tid 255970] [client 103.162.129.114:60480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K4bxMYwyVGnfuwsKAJwAAA-o"]
[Tue Jul 21 07:33:05.795726 2026] [security2:error] [pid 255769:tid 255970] [client 103.162.129.114:60480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K4bxMYwyVGnfuwsKAJwAAA-o"]
[Tue Jul 21 07:33:05.851294 2026] [security2:error] [pid 254995:tid 255172] [client 20.206.105.145:7486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/gecko.php"] [unique_id "al9K4f7v0rlcEGmVraEm2AAAA00"]
[Tue Jul 21 07:33:05.962348 2026] [security2:error] [pid 254995:tid 255268] [client 74.248.121.109:1068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/222.php"] [unique_id "al9K4f7v0rlcEGmVraEm2wAAA5I"]
[Tue Jul 21 07:33:06.054095 2026] [security2:error] [pid 254995:tid 255077] [remote 162.19.246.208:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9K4v7v0rlcEGmVraEm4AADa1E"]
[Tue Jul 21 07:33:06.064029 2026] [security2:error] [pid 255769:tid 255966] [client 122.186.204.214:60662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K4rxMYwyVGnfuwsKAMAAAA-Y"]
[Tue Jul 21 07:33:06.064168 2026] [security2:error] [pid 255769:tid 255966] [client 122.186.204.214:60662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K4rxMYwyVGnfuwsKAMAAAA-Y"]
[Tue Jul 21 07:33:06.121122 2026] [security2:error] [pid 254995:tid 255136] [client 20.197.195.24:13152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9K4v7v0rlcEGmVraEm4QAAAyk"]
[Tue Jul 21 07:33:06.175324 2026] [security2:error] [pid 255769:tid 255783] [remote 163.61.236.12:36566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.236.61.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9K4bxMYwyVGnfuwsKAFgAEDg0"]
[Tue Jul 21 07:33:06.287909 2026] [security2:error] [pid 255769:tid 256014] [client 45.8.17.146:47565] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/chosen.php"] [unique_id "al9K4rxMYwyVGnfuwsKAMwAABBQ"]
[Tue Jul 21 07:33:06.601217 2026] [security2:error] [pid 255769:tid 255906] [client 74.248.121.109:2135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/t.php"] [unique_id "al9K4rxMYwyVGnfuwsKANQAAA6o"]
[Tue Jul 21 07:33:06.801851 2026] [security2:error] [pid 254995:tid 255277] [client 122.162.144.145:30753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9K4v7v0rlcEGmVraEm6gAAA5s"]
[Tue Jul 21 07:33:06.802054 2026] [security2:error] [pid 254995:tid 255277] [client 122.162.144.145:30753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9K4v7v0rlcEGmVraEm6gAAA5s"]
[Tue Jul 21 07:33:06.826962 2026] [security2:error] [pid 254995:tid 255117] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K4v7v0rlcEGmVraEm6wADXXk"]
[Tue Jul 21 07:33:06.827124 2026] [security2:error] [pid 254995:tid 255188] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K4v7v0rlcEGmVraEm6wADXXk"]
[Tue Jul 21 07:33:06.870276 2026] [security2:error] [pid 255769:tid 255973] [client 62.102.148.164:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9K4rxMYwyVGnfuwsKAPQAAA-0"]
[Tue Jul 21 07:33:06.870359 2026] [security2:error] [pid 255769:tid 255973] [client 62.102.148.164:59068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9K4rxMYwyVGnfuwsKAPQAAA-0"]
[Tue Jul 21 07:33:07.059872 2026] [security2:error] [pid 254995:tid 255229] [client 74.248.121.109:1044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/a.php"] [unique_id "al9K4_7v0rlcEGmVraEm8AAAA4I"]
[Tue Jul 21 07:33:07.194010 2026] [security2:error] [pid 255769:tid 255993] [client 173.24.185.52:59656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K47xMYwyVGnfuwsKARQAABAA"]
[Tue Jul 21 07:33:07.194193 2026] [security2:error] [pid 255769:tid 255993] [client 173.24.185.52:59656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K47xMYwyVGnfuwsKARQAABAA"]
[Tue Jul 21 07:33:07.207098 2026] [security2:error] [pid 255769:tid 255935] [client 78.47.98.55:19106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9K47xMYwyVGnfuwsKARgAAA8c"], referer: https://artetoner.com.br
[Tue Jul 21 07:33:07.483253 2026] [security2:error] [pid 255769:tid 255918] [client 45.8.17.119:22879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/SimplePie/src/Content/autoload_classmap.php"] [unique_id "al9K47xMYwyVGnfuwsKATAAAA7Y"]
[Tue Jul 21 07:33:07.599673 2026] [security2:error] [pid 254995:tid 255224] [client 74.248.121.109:1080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/a1.php"] [unique_id "al9K4_7v0rlcEGmVraEm9AAAA4A"]
[Tue Jul 21 07:33:07.664015 2026] [security2:error] [pid 255769:tid 255912] [client 103.106.20.201:53288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K47xMYwyVGnfuwsKATwAAA7A"]
[Tue Jul 21 07:33:07.664847 2026] [security2:error] [pid 255769:tid 255912] [client 103.106.20.201:53288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K47xMYwyVGnfuwsKATwAAA7A"]
[Tue Jul 21 07:33:07.858982 2026] [security2:error] [pid 255769:tid 256021] [client 20.220.225.223:4195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/cron-tab.php"] [unique_id "al9K47xMYwyVGnfuwsKAVAAABBs"]
[Tue Jul 21 07:33:07.947655 2026] [security2:error] [pid 254995:tid 255073] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K4_7v0rlcEGmVraEm-wADik0"]
[Tue Jul 21 07:33:07.947789 2026] [security2:error] [pid 254995:tid 255260] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K4_7v0rlcEGmVraEm-wADik0"]
[Tue Jul 21 07:33:08.196380 2026] [security2:error] [pid 255769:tid 255976] [client 154.192.233.199:58671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5LxMYwyVGnfuwsKAYQAAA_A"]
[Tue Jul 21 07:33:08.196540 2026] [security2:error] [pid 255769:tid 255976] [client 154.192.233.199:58671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5LxMYwyVGnfuwsKAYQAAA_A"]
[Tue Jul 21 07:33:08.207092 2026] [security2:error] [pid 255769:tid 255931] [client 20.220.225.223:8089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wp-Blogs.php"] [unique_id "al9K5LxMYwyVGnfuwsKAYgAAA8M"]
[Tue Jul 21 07:33:08.289779 2026] [security2:error] [pid 255769:tid 255958] [client 74.248.121.109:2003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/w.php"] [unique_id "al9K5LxMYwyVGnfuwsKAZQAAA94"]
[Tue Jul 21 07:33:08.485701 2026] [security2:error] [pid 255769:tid 255970] [client 45.251.232.145:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5LxMYwyVGnfuwsKAfgAAA-o"]
[Tue Jul 21 07:33:08.485901 2026] [security2:error] [pid 255769:tid 255970] [client 45.251.232.145:51814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5LxMYwyVGnfuwsKAfgAAA-o"]
[Tue Jul 21 07:33:08.691993 2026] [security2:error] [pid 255769:tid 256011] [client 45.8.17.110:58575] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/IXR/shadow-bot.php"] [unique_id "al9K5LxMYwyVGnfuwsKAgwAABBE"]
[Tue Jul 21 07:33:08.771243 2026] [security2:error] [pid 255769:tid 255947] [client 20.220.225.223:19668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/cron-tab.php"] [unique_id "al9K5LxMYwyVGnfuwsKAhQAAA9M"]
[Tue Jul 21 07:33:08.776238 2026] [security2:error] [pid 255769:tid 255981] [client 20.206.105.145:38939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/term.php"] [unique_id "al9K5LxMYwyVGnfuwsKAhgAAA_U"]
[Tue Jul 21 07:33:08.827610 2026] [security2:error] [pid 255769:tid 255996] [client 74.248.121.109:2141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/wp-good.php"] [unique_id "al9K5LxMYwyVGnfuwsKAhwAABAI"]
[Tue Jul 21 07:33:09.144378 2026] [security2:error] [pid 255769:tid 255837] [remote 41.76.214.143:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9K5bxMYwyVGnfuwsKAkwADvkM"]
[Tue Jul 21 07:33:09.172790 2026] [security2:error] [pid 255769:tid 255932] [client 20.220.225.223:49836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/old.php"] [unique_id "al9K5bxMYwyVGnfuwsKAlQAAA8Q"]
[Tue Jul 21 07:33:09.219967 2026] [security2:error] [pid 255769:tid 256028] [client 193.36.225.72:50881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9K5bxMYwyVGnfuwsKAkAAABCI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:09.228069 2026] [security2:error] [pid 254995:tid 255162] [client 175.45.70.82:54602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5f7v0rlcEGmVraEnDAAAA0M"]
[Tue Jul 21 07:33:09.228178 2026] [security2:error] [pid 254995:tid 255162] [client 175.45.70.82:54602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5f7v0rlcEGmVraEnDAAAA0M"]
[Tue Jul 21 07:33:09.376473 2026] [security2:error] [pid 255769:tid 255944] [client 74.248.121.109:2109] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "issimastore.com.issima.net.br"] [uri "/.info.php"] [unique_id "al9K5bxMYwyVGnfuwsKAmwAAA9A"]
[Tue Jul 21 07:33:09.403986 2026] [security2:error] [pid 255769:tid 255840] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K5bxMYwyVGnfuwsKAnQADqUY"]
[Tue Jul 21 07:33:09.404173 2026] [security2:error] [pid 255769:tid 255905] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K5bxMYwyVGnfuwsKAnQADqUY"]
[Tue Jul 21 07:33:09.658345 2026] [security2:error] [pid 255769:tid 255998] [client 152.59.154.239:63895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5bxMYwyVGnfuwsKAoAAABAQ"]
[Tue Jul 21 07:33:09.658534 2026] [security2:error] [pid 255769:tid 255998] [client 152.59.154.239:63895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5bxMYwyVGnfuwsKAoAAABAQ"]
[Tue Jul 21 07:33:09.689251 2026] [security2:error] [pid 254995:tid 255186] [client 45.8.17.127:54079] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/chosen.php"] [unique_id "al9K5f7v0rlcEGmVraEnEQAAA1s"]
[Tue Jul 21 07:33:09.841354 2026] [security2:error] [pid 255769:tid 255957] [client 117.217.38.194:56679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5bxMYwyVGnfuwsKApgAAA90"]
[Tue Jul 21 07:33:09.841525 2026] [security2:error] [pid 255769:tid 255957] [client 117.217.38.194:56679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5bxMYwyVGnfuwsKApgAAA90"]
[Tue Jul 21 07:33:09.883190 2026] [security2:error] [pid 254995:tid 255182] [client 74.248.121.109:1072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/item.php"] [unique_id "al9K5f7v0rlcEGmVraEnFAAAA1c"]
[Tue Jul 21 07:33:09.973032 2026] [security2:error] [pid 254995:tid 255181] [client 20.197.195.24:13178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wefile.php"] [unique_id "al9K5f7v0rlcEGmVraEnFQAAA1Y"]
[Tue Jul 21 07:33:10.010240 2026] [security2:error] [pid 255769:tid 256018] [client 103.174.34.15:62963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5rxMYwyVGnfuwsKAqgAABBg"]
[Tue Jul 21 07:33:10.010355 2026] [security2:error] [pid 255769:tid 256018] [client 103.174.34.15:62963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K5rxMYwyVGnfuwsKAqgAABBg"]
[Tue Jul 21 07:33:10.355590 2026] [security2:error] [pid 255769:tid 255959] [client 74.248.121.109:1027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/albin.php"] [unique_id "al9K5rxMYwyVGnfuwsKArQAAA98"]
[Tue Jul 21 07:33:10.408096 2026] [security2:error] [pid 254995:tid 255066] [remote 54.39.210.190:21530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.gpbikesbrasil.com.br"] [uri "/robots.txt"] [unique_id "al9K5v7v0rlcEGmVraEnIQADmEY"]
[Tue Jul 21 07:33:10.408239 2026] [security2:error] [pid 254995:tid 255274] [client 54.39.210.190:21530] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.gpbikesbrasil.com.br"] [uri "/robots.txt"] [unique_id "al9K5v7v0rlcEGmVraEnIQADmEY"]
[Tue Jul 21 07:33:10.581875 2026] [security2:error] [pid 254995:tid 255187] [client 20.197.195.24:13117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9K5v7v0rlcEGmVraEnJQAAA1w"]
[Tue Jul 21 07:33:10.583403 2026] [security2:error] [pid 255769:tid 255935] [client 20.206.105.145:54538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/a1.php"] [unique_id "al9K5rxMYwyVGnfuwsKAsAAAA8c"]
[Tue Jul 21 07:33:10.629465 2026] [autoindex:error] [pid 255769:tid 255981] [client 20.197.195.24:13056] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:10.687398 2026] [autoindex:error] [pid 255769:tid 255937] [client 20.197.195.24:13056] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:10.692372 2026] [security2:error] [pid 255769:tid 255910] [client 45.8.17.146:48091] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/prenota/gecko.php"] [unique_id "al9K5rxMYwyVGnfuwsKAtAAAA64"]
[Tue Jul 21 07:33:10.695966 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.195.24:13056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9K5rxMYwyVGnfuwsKAtQAAA7Y"]
[Tue Jul 21 07:33:10.754849 2026] [security2:error] [pid 255769:tid 255903] [client 82.102.28.107:48214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9K5rxMYwyVGnfuwsKAtgAAA6c"]
[Tue Jul 21 07:33:10.755013 2026] [security2:error] [pid 255769:tid 255903] [client 82.102.28.107:48214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9K5rxMYwyVGnfuwsKAtgAAA6c"]
[Tue Jul 21 07:33:10.846356 2026] [security2:error] [pid 254995:tid 255224] [client 74.248.121.109:2065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/alfa.php"] [unique_id "al9K5v7v0rlcEGmVraEnKgAAA4A"]
[Tue Jul 21 07:33:11.004081 2026] [proxy:error] [pid 254995:tid 255197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:11.004154 2026] [proxy_http:error] [pid 254995:tid 255197] [client 20.151.10.161:57991] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:11.005513 2026] [proxy:error] [pid 254995:tid 255197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:11.005557 2026] [proxy_http:error] [pid 254995:tid 255197] [client 20.151.10.161:57991] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:11.026553 2026] [security2:error] [pid 255769:tid 255960] [client 20.197.195.24:48862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/8.php"] [unique_id "al9K57xMYwyVGnfuwsKAvAAAA-A"]
[Tue Jul 21 07:33:11.246152 2026] [security2:error] [pid 254995:tid 255198] [client 20.206.105.145:38948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ha.php"] [unique_id "al9K5_7v0rlcEGmVraEnNgAAA2c"]
[Tue Jul 21 07:33:11.270303 2026] [security2:error] [pid 255769:tid 255983] [client 122.129.67.13:59626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9K57xMYwyVGnfuwsKAwAAAA_c"]
[Tue Jul 21 07:33:11.313543 2026] [security2:error] [pid 255769:tid 255934] [client 20.220.225.223:8081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wp-css.php"] [unique_id "al9K57xMYwyVGnfuwsKAxAAAA8Y"]
[Tue Jul 21 07:33:11.655425 2026] [security2:error] [pid 255769:tid 255941] [client 74.248.121.109:2146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/autoload_classmap.php"] [unique_id "al9K57xMYwyVGnfuwsKAzgAAA80"]
[Tue Jul 21 07:33:11.753975 2026] [security2:error] [pid 255769:tid 255857] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K57xMYwyVGnfuwsKA1AAD3Fc"]
[Tue Jul 21 07:33:11.754136 2026] [security2:error] [pid 255769:tid 255956] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K57xMYwyVGnfuwsKA1AAD3Fc"]
[Tue Jul 21 07:33:11.895336 2026] [security2:error] [pid 255769:tid 255907] [client 45.8.17.64:32247] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/as.php"] [unique_id "al9K57xMYwyVGnfuwsKA2wAAA6s"]
[Tue Jul 21 07:33:11.945773 2026] [security2:error] [pid 255769:tid 255863] [remote 167.114.139.57:16806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.gpbikesbrasil.com.br"] [uri "/"] [unique_id "al9K57xMYwyVGnfuwsKA4AAD3l0"]
[Tue Jul 21 07:33:11.945923 2026] [security2:error] [pid 255769:tid 255958] [client 167.114.139.57:16806] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.gpbikesbrasil.com.br"] [uri "/"] [unique_id "al9K57xMYwyVGnfuwsKA4AAD3l0"]
[Tue Jul 21 07:33:12.156213 2026] [security2:error] [pid 255769:tid 255879] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K6LxMYwyVGnfuwsKA7gAEBW0"]
[Tue Jul 21 07:33:12.156375 2026] [security2:error] [pid 255769:tid 255999] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K6LxMYwyVGnfuwsKA7gAEBW0"]
[Tue Jul 21 07:33:12.274946 2026] [security2:error] [pid 255769:tid 255893] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K6LxMYwyVGnfuwsKA-QAEAHs"]
[Tue Jul 21 07:33:12.275079 2026] [security2:error] [pid 255769:tid 255993] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K6LxMYwyVGnfuwsKA-QAEAHs"]
[Tue Jul 21 07:33:12.277078 2026] [security2:error] [pid 254995:tid 255270] [client 20.220.225.223:45973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/ace2.php"] [unique_id "al9K6P7v0rlcEGmVraEncAAAA5Q"]
[Tue Jul 21 07:33:12.358933 2026] [security2:error] [pid 255769:tid 255983] [client 74.248.121.109:2126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/av.php"] [unique_id "al9K6LxMYwyVGnfuwsKBAAAAA_c"]
[Tue Jul 21 07:33:12.563220 2026] [security2:error] [pid 255769:tid 256003] [client 20.52.136.55:1563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/sql.php"] [unique_id "al9K6LxMYwyVGnfuwsKBDQAABAk"]
[Tue Jul 21 07:33:12.569377 2026] [security2:error] [pid 255769:tid 255931] [client 20.206.105.145:7478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/k2.php"] [unique_id "al9K6LxMYwyVGnfuwsKBDgAAA8M"]
[Tue Jul 21 07:33:12.670432 2026] [security2:error] [pid 254995:tid 255165] [client 20.151.10.161:58029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp.php"] [unique_id "al9K6P7v0rlcEGmVraEnewAAA0Y"]
[Tue Jul 21 07:33:12.757933 2026] [security2:error] [pid 255769:tid 256024] [client 20.220.225.223:6106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wpx.php"] [unique_id "al9K6LxMYwyVGnfuwsKBFwAABB4"]
[Tue Jul 21 07:33:12.830145 2026] [security2:error] [pid 255769:tid 256022] [client 74.248.121.109:2094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/gg.php"] [unique_id "al9K6LxMYwyVGnfuwsKBHAAABBw"]
[Tue Jul 21 07:33:13.023583 2026] [security2:error] [pid 255769:tid 255923] [client 193.36.225.60:34373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9K6bxMYwyVGnfuwsKBIQAAA7s"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:13.120117 2026] [security2:error] [pid 254995:tid 255254] [client 20.197.195.24:13062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-content/admin.php"] [unique_id "al9K6f7v0rlcEGmVraEnhQAAA4Q"]
[Tue Jul 21 07:33:13.401329 2026] [security2:error] [pid 254995:tid 255125] [client 74.248.121.109:2138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/sql.php"] [unique_id "al9K6f7v0rlcEGmVraEniAAAAx4"]
[Tue Jul 21 07:33:13.686562 2026] [security2:error] [pid 255769:tid 255988] [client 59.96.220.140:63726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K6bxMYwyVGnfuwsKBKwAAA_w"]
[Tue Jul 21 07:33:13.687329 2026] [security2:error] [pid 255769:tid 255988] [client 59.96.220.140:63726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K6bxMYwyVGnfuwsKBKwAAA_w"]
[Tue Jul 21 07:33:13.830421 2026] [security2:error] [pid 255769:tid 256021] [client 20.220.225.223:24275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/x.php"] [unique_id "al9K6bxMYwyVGnfuwsKBLgAABBs"]
[Tue Jul 21 07:33:13.851723 2026] [security2:error] [pid 255769:tid 255960] [client 45.8.17.116:44185] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/home-link/wp-login.php"] [unique_id "al9K6bxMYwyVGnfuwsKBKgAAA-A"]
[Tue Jul 21 07:33:13.942364 2026] [security2:error] [pid 254995:tid 255209] [client 136.144.33.213:24145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K6P7v0rlcEGmVraEnfQAAA3E"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:14.032435 2026] [security2:error] [pid 255769:tid 256004] [client 20.220.225.223:45977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br.bomexito.com.br"] [uri "/ms.php"] [unique_id "al9K6rxMYwyVGnfuwsKBMgAABAo"]
[Tue Jul 21 07:33:14.087212 2026] [security2:error] [pid 254995:tid 255220] [client 74.248.121.109:2089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/up.php"] [unique_id "al9K6v7v0rlcEGmVraEnlwAAA3w"]
[Tue Jul 21 07:33:14.163445 2026] [security2:error] [pid 255769:tid 255921] [client 20.206.105.145:39289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/hur.php"] [unique_id "al9K6rxMYwyVGnfuwsKBNQAAA7k"]
[Tue Jul 21 07:33:14.250823 2026] [security2:error] [pid 255769:tid 255919] [client 20.206.105.145:7749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/82.php"] [unique_id "al9K6rxMYwyVGnfuwsKBPAAAA7c"]
[Tue Jul 21 07:33:14.397957 2026] [security2:error] [pid 254995:tid 255258] [client 20.151.10.161:57404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/abcd.php"] [unique_id "al9K6v7v0rlcEGmVraEnnAAAA4g"]
[Tue Jul 21 07:33:14.408420 2026] [security2:error] [pid 254995:tid 255111] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K6v7v0rlcEGmVraEnnQADg3M"]
[Tue Jul 21 07:33:14.408535 2026] [security2:error] [pid 254995:tid 255252] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K6v7v0rlcEGmVraEnnQADg3M"]
[Tue Jul 21 07:33:14.598930 2026] [security2:error] [pid 255769:tid 255808] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K6rxMYwyVGnfuwsKBQgAD4SY"]
[Tue Jul 21 07:33:14.599043 2026] [security2:error] [pid 255769:tid 255961] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K6rxMYwyVGnfuwsKBQgAD4SY"]
[Tue Jul 21 07:33:14.610730 2026] [security2:error] [pid 254995:tid 255157] [client 74.7.244.48:41668] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "politicaemdebate.org"] [uri "/robots.txt"] [unique_id "al9K6v7v0rlcEGmVraEnpwADPg4"]
[Tue Jul 21 07:33:14.647904 2026] [security2:error] [pid 254995:tid 255109] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K6v7v0rlcEGmVraEnnwADSnE"]
[Tue Jul 21 07:33:14.648136 2026] [security2:error] [pid 254995:tid 255169] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K6v7v0rlcEGmVraEnnwADSnE"]
[Tue Jul 21 07:33:14.690804 2026] [security2:error] [pid 255769:tid 255917] [client 74.248.121.109:1991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/66.php"] [unique_id "al9K6rxMYwyVGnfuwsKBRgAAA7U"]
[Tue Jul 21 07:33:14.953844 2026] [security2:error] [pid 255769:tid 255984] [client 139.167.225.182:64348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K6rxMYwyVGnfuwsKBSQAAA_g"]
[Tue Jul 21 07:33:14.954003 2026] [security2:error] [pid 255769:tid 255984] [client 139.167.225.182:64348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K6rxMYwyVGnfuwsKBSQAAA_g"]
[Tue Jul 21 07:33:15.118787 2026] [security2:error] [pid 255769:tid 255996] [client 20.220.225.223:6827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/wp-explorer.php"] [unique_id "al9K67xMYwyVGnfuwsKBTQAABAI"]
[Tue Jul 21 07:33:15.186461 2026] [security2:error] [pid 255769:tid 255937] [client 20.197.195.24:13079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/f6.php"] [unique_id "al9K67xMYwyVGnfuwsKBTwAAA8k"]
[Tue Jul 21 07:33:15.262804 2026] [security2:error] [pid 255769:tid 255924] [client 20.151.10.161:57467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/a1.php"] [unique_id "al9K67xMYwyVGnfuwsKBUgAAA7w"]
[Tue Jul 21 07:33:15.297826 2026] [security2:error] [pid 255769:tid 255810] [remote 154.61.75.100:35842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9K67xMYwyVGnfuwsKBUwADrig"]
[Tue Jul 21 07:33:15.395850 2026] [security2:error] [pid 255769:tid 255986] [client 45.8.17.58:64657] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/fix/admin.php"] [unique_id "al9K67xMYwyVGnfuwsKBVQAAA_o"]
[Tue Jul 21 07:33:15.462870 2026] [security2:error] [pid 255769:tid 255804] [remote 116.179.37.99:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9K6rxMYwyVGnfuwsKBPQADpCI"], referer: https://androapkmod.com/groovepad-premium/
[Tue Jul 21 07:33:15.634905 2026] [security2:error] [pid 254995:tid 255164] [client 117.251.86.144:50824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K6_7v0rlcEGmVraEntQAAA0U"]
[Tue Jul 21 07:33:15.635063 2026] [security2:error] [pid 254995:tid 255164] [client 117.251.86.144:50824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K6_7v0rlcEGmVraEntQAAA0U"]
[Tue Jul 21 07:33:15.722310 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:15.722346 2026] [proxy_http:error] [pid 254995:tid 255268] [client 198.235.24.152:60750] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:15.722869 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:15.722898 2026] [proxy_http:error] [pid 254995:tid 255268] [client 198.235.24.152:60750] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:15.732663 2026] [security2:error] [pid 255769:tid 256004] [client 20.151.10.161:57381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9K67xMYwyVGnfuwsKBXgAABAo"]
[Tue Jul 21 07:33:15.802388 2026] [security2:error] [pid 255769:tid 255930] [client 103.162.129.114:61055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K67xMYwyVGnfuwsKBYAAAA8I"]
[Tue Jul 21 07:33:15.802527 2026] [security2:error] [pid 255769:tid 255930] [client 103.162.129.114:61055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K67xMYwyVGnfuwsKBYAAAA8I"]
[Tue Jul 21 07:33:16.096011 2026] [security2:error] [pid 255769:tid 255941] [client 74.248.121.109:2063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/666.php"] [unique_id "al9K7LxMYwyVGnfuwsKBZQAAA80"]
[Tue Jul 21 07:33:16.453736 2026] [security2:error] [pid 254995:tid 255194] [client 20.206.105.145:7445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/config.json.php"] [unique_id "al9K7P7v0rlcEGmVraEnwwAAA2M"]
[Tue Jul 21 07:33:16.485683 2026] [proxy:error] [pid 254995:tid 255174] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:16.485758 2026] [proxy_http:error] [pid 254995:tid 255174] [client 20.151.10.161:51288] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:16.486913 2026] [proxy:error] [pid 254995:tid 255174] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:16.486971 2026] [proxy_http:error] [pid 254995:tid 255174] [client 20.151.10.161:51288] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:16.513979 2026] [security2:error] [pid 254995:tid 255154] [client 20.220.225.223:8074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/akismet.php"] [unique_id "al9K7P7v0rlcEGmVraEnxgAAAzs"]
[Tue Jul 21 07:33:16.649985 2026] [security2:error] [pid 255769:tid 256007] [client 74.248.121.109:2127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/byp.php"] [unique_id "al9K7LxMYwyVGnfuwsKBbAAABA0"]
[Tue Jul 21 07:33:16.699704 2026] [security2:error] [pid 255769:tid 256022] [client 45.8.17.137:56889] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/fix/ioxi-o.php"] [unique_id "al9K7LxMYwyVGnfuwsKBbwAABBw"]
[Tue Jul 21 07:33:16.747970 2026] [security2:error] [pid 254995:tid 255269] [client 122.186.204.214:61166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K7P7v0rlcEGmVraEnywAAA5M"]
[Tue Jul 21 07:33:16.748118 2026] [security2:error] [pid 254995:tid 255269] [client 122.186.204.214:61166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K7P7v0rlcEGmVraEnywAAA5M"]
[Tue Jul 21 07:33:16.761659 2026] [security2:error] [pid 254995:tid 255195] [client 37.140.223.191:62655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K7P7v0rlcEGmVraEnzAAAA2Q"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:16.883758 2026] [security2:error] [pid 255769:tid 255947] [client 20.206.105.145:7439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/fpwch.php"] [unique_id "al9K7LxMYwyVGnfuwsKBdgAAA9M"]
[Tue Jul 21 07:33:17.016289 2026] [security2:error] [pid 255769:tid 255955] [client 20.206.105.145:38972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/h02ugyh.php"] [unique_id "al9K7bxMYwyVGnfuwsKBeAAAA9s"]
[Tue Jul 21 07:33:17.085102 2026] [proxy:error] [pid 255769:tid 255910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:17.085166 2026] [proxy_http:error] [pid 255769:tid 255910] [client 20.151.10.161:57443] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:17.085617 2026] [proxy:error] [pid 255769:tid 255910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:17.085650 2026] [proxy_http:error] [pid 255769:tid 255910] [client 20.151.10.161:57443] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:17.175806 2026] [security2:error] [pid 254995:tid 255181] [client 193.36.225.70:26573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9K7f7v0rlcEGmVraEnzwAAA1Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:17.276285 2026] [security2:error] [pid 255769:tid 255957] [client 122.162.144.145:24914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9K7bxMYwyVGnfuwsKBhQAAA90"]
[Tue Jul 21 07:33:17.276378 2026] [security2:error] [pid 255769:tid 255957] [client 122.162.144.145:24914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9K7bxMYwyVGnfuwsKBhQAAA90"]
[Tue Jul 21 07:33:17.362097 2026] [security2:error] [pid 254995:tid 255211] [client 20.220.225.223:4546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/koiy.php"] [unique_id "al9K7f7v0rlcEGmVraEn1QAAA3M"]
[Tue Jul 21 07:33:17.386548 2026] [security2:error] [pid 254995:tid 255107] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K7f7v0rlcEGmVraEn1gADcW8"]
[Tue Jul 21 07:33:17.386682 2026] [security2:error] [pid 254995:tid 255209] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K7f7v0rlcEGmVraEn1gADcW8"]
[Tue Jul 21 07:33:17.398402 2026] [security2:error] [pid 255769:tid 255960] [client 74.248.121.109:2073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/date.php"] [unique_id "al9K7bxMYwyVGnfuwsKBhgAAA-A"]
[Tue Jul 21 07:33:17.563257 2026] [proxy:error] [pid 254995:tid 255135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:17.563324 2026] [proxy_http:error] [pid 254995:tid 255135] [client 20.151.10.161:50881] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:17.563754 2026] [proxy:error] [pid 254995:tid 255135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:17.563781 2026] [proxy_http:error] [pid 254995:tid 255135] [client 20.151.10.161:50881] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:17.617761 2026] [security2:error] [pid 254995:tid 255271] [client 20.220.225.223:62134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/tkikikoko.php"] [unique_id "al9K7f7v0rlcEGmVraEn3AAAA5U"]
[Tue Jul 21 07:33:17.654803 2026] [security2:error] [pid 254995:tid 255198] [client 20.197.195.24:13076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/inputs.php"] [unique_id "al9K7f7v0rlcEGmVraEn3QAAA2c"]
[Tue Jul 21 07:33:17.655603 2026] [security2:error] [pid 255769:tid 255976] [client 20.220.225.223:9279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/ace2.php"] [unique_id "al9K7bxMYwyVGnfuwsKBhwAAA_A"]
[Tue Jul 21 07:33:17.711939 2026] [security2:error] [pid 255769:tid 255934] [client 173.24.185.52:60326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K7bxMYwyVGnfuwsKBiAAAA8Y"]
[Tue Jul 21 07:33:17.712062 2026] [security2:error] [pid 255769:tid 255934] [client 173.24.185.52:60326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K7bxMYwyVGnfuwsKBiAAAA8Y"]
[Tue Jul 21 07:33:17.872355 2026] [security2:error] [pid 254995:tid 255169] [client 20.151.10.161:57407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9K7f7v0rlcEGmVraEn5gAAA0o"]
[Tue Jul 21 07:33:17.883747 2026] [security2:error] [pid 255769:tid 256020] [client 74.248.121.109:2167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/pomo.php"] [unique_id "al9K7bxMYwyVGnfuwsKBiwAABBo"]
[Tue Jul 21 07:33:18.029130 2026] [security2:error] [pid 254995:tid 255139] [client 20.206.105.145:38959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/seiso.php"] [unique_id "al9K7v7v0rlcEGmVraEn5wAAAyw"]
[Tue Jul 21 07:33:18.177267 2026] [security2:error] [pid 254995:tid 255190] [client 20.151.10.161:58073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/gettest.php"] [unique_id "al9K7v7v0rlcEGmVraEn6QAAA18"]
[Tue Jul 21 07:33:18.194918 2026] [security2:error] [pid 255769:tid 255950] [client 20.220.225.223:6799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/ms.php"] [unique_id "al9K7rxMYwyVGnfuwsKBkgAAA9Y"]
[Tue Jul 21 07:33:18.291177 2026] [security2:error] [pid 255769:tid 255899] [client 20.52.136.55:1577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/up.php"] [unique_id "al9K7rxMYwyVGnfuwsKBlgAAA6M"]
[Tue Jul 21 07:33:18.327170 2026] [security2:error] [pid 255769:tid 255931] [client 103.106.20.201:53851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K7rxMYwyVGnfuwsKBlwAAA8M"]
[Tue Jul 21 07:33:18.327278 2026] [security2:error] [pid 255769:tid 255931] [client 103.106.20.201:53851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K7rxMYwyVGnfuwsKBlwAAA8M"]
[Tue Jul 21 07:33:18.526724 2026] [security2:error] [pid 255769:tid 255821] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K7rxMYwyVGnfuwsKBmwAD8zM"]
[Tue Jul 21 07:33:18.526867 2026] [security2:error] [pid 255769:tid 255979] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K7rxMYwyVGnfuwsKBmwAD8zM"]
[Tue Jul 21 07:33:18.542410 2026] [security2:error] [pid 255769:tid 255937] [client 74.248.121.109:1032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/test1.php"] [unique_id "al9K7rxMYwyVGnfuwsKBnAAAA8k"]
[Tue Jul 21 07:33:18.671622 2026] [proxy:error] [pid 255769:tid 255955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:18.671702 2026] [proxy_http:error] [pid 255769:tid 255955] [client 20.151.10.161:51277] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:18.672167 2026] [proxy:error] [pid 255769:tid 255955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:18.672195 2026] [proxy_http:error] [pid 255769:tid 255955] [client 20.151.10.161:51277] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:18.945992 2026] [security2:error] [pid 255769:tid 255917] [client 45.251.232.145:52339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K7rxMYwyVGnfuwsKBpAAAA7U"]
[Tue Jul 21 07:33:18.946108 2026] [security2:error] [pid 255769:tid 255917] [client 45.251.232.145:52339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K7rxMYwyVGnfuwsKBpAAAA7U"]
[Tue Jul 21 07:33:18.981058 2026] [security2:error] [pid 255769:tid 255972] [client 45.8.17.121:45757] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/ioxi-o.php"] [unique_id "al9K7rxMYwyVGnfuwsKBpgAAA-w"]
[Tue Jul 21 07:33:19.003003 2026] [security2:error] [pid 255769:tid 255974] [client 107.149.152.43:29309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.152.149.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-plain.php"] [unique_id "al9K77xMYwyVGnfuwsKBqAAAA-4"], referer: www.google.com
[Tue Jul 21 07:33:19.003700 2026] [security2:error] [pid 254995:tid 255164] [client 107.149.152.43:62971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.152.149.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9K7_7v0rlcEGmVraEn9AAAA0U"]
[Tue Jul 21 07:33:19.005391 2026] [security2:error] [pid 254995:tid 255150] [client 107.149.152.43:51039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.152.149.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9K7_7v0rlcEGmVraEn9QAAAzc"], referer: www.google.com
[Tue Jul 21 07:33:19.127337 2026] [security2:error] [pid 254995:tid 255183] [client 20.151.10.161:57393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/simple.php"] [unique_id "al9K7_7v0rlcEGmVraEn9wAAA1g"]
[Tue Jul 21 07:33:19.212314 2026] [security2:error] [pid 254995:tid 255222] [client 107.149.152.43:30543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.152.149.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/nwmbnobn.php"] [unique_id "al9K7_7v0rlcEGmVraEn-gAAA34"], referer: www.google.com
[Tue Jul 21 07:33:19.253666 2026] [security2:error] [pid 255769:tid 255906] [client 154.192.233.199:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K77xMYwyVGnfuwsKBqQAAA6o"]
[Tue Jul 21 07:33:19.253859 2026] [security2:error] [pid 255769:tid 255906] [client 154.192.233.199:59140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K77xMYwyVGnfuwsKBqQAAA6o"]
[Tue Jul 21 07:33:19.265979 2026] [security2:error] [pid 255769:tid 255926] [client 74.248.121.109:2082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/fw.php"] [unique_id "al9K77xMYwyVGnfuwsKBqgAAA74"]
[Tue Jul 21 07:33:19.670712 2026] [security2:error] [pid 255769:tid 255941] [client 20.151.10.161:50924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/xxx.php"] [unique_id "al9K77xMYwyVGnfuwsKB3AAAA80"]
[Tue Jul 21 07:33:19.712032 2026] [security2:error] [pid 254995:tid 255215] [client 20.197.195.24:13163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/inputs.php"] [unique_id "al9K7_7v0rlcEGmVraEoAQAAA3c"]
[Tue Jul 21 07:33:19.767355 2026] [security2:error] [pid 254995:tid 255269] [client 20.220.225.223:61970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/hp2.php"] [unique_id "al9K7_7v0rlcEGmVraEoAwAAA5M"]
[Tue Jul 21 07:33:19.793798 2026] [security2:error] [pid 254995:tid 255194] [client 107.149.152.43:42563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.152.149.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9K7_7v0rlcEGmVraEoBAAAA2M"], referer: www.google.com
[Tue Jul 21 07:33:19.834025 2026] [security2:error] [pid 255769:tid 255969] [client 20.206.105.145:39262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/155.php"] [unique_id "al9K77xMYwyVGnfuwsKB4gAAA-k"]
[Tue Jul 21 07:33:19.962301 2026] [security2:error] [pid 254995:tid 255140] [client 74.248.121.109:2102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/fm.php"] [unique_id "al9K7_7v0rlcEGmVraEoCQAAAy0"]
[Tue Jul 21 07:33:20.008638 2026] [security2:error] [pid 255769:tid 256019] [client 175.45.70.82:55119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKB6QAABBk"]
[Tue Jul 21 07:33:20.008734 2026] [security2:error] [pid 255769:tid 256019] [client 175.45.70.82:55119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKB6QAABBk"]
[Tue Jul 21 07:33:20.091263 2026] [security2:error] [pid 255769:tid 255990] [client 107.149.152.43:47109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.152.149.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-plain.php"] [unique_id "al9K8LxMYwyVGnfuwsKCMwAAA_4"], referer: www.google.com
[Tue Jul 21 07:33:20.178664 2026] [security2:error] [pid 255769:tid 255829] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKCPQADvTs"]
[Tue Jul 21 07:33:20.178773 2026] [security2:error] [pid 255769:tid 255925] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKCPQADvTs"]
[Tue Jul 21 07:33:20.295320 2026] [security2:error] [pid 255769:tid 256011] [client 20.151.10.161:51300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/hypo.php"] [unique_id "al9K8LxMYwyVGnfuwsKCPgAABBE"]
[Tue Jul 21 07:33:20.323122 2026] [security2:error] [pid 254995:tid 255154] [client 117.217.38.194:57122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8P7v0rlcEGmVraEoDAAAAzs"]
[Tue Jul 21 07:33:20.323261 2026] [security2:error] [pid 254995:tid 255154] [client 117.217.38.194:57122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8P7v0rlcEGmVraEoDAAAAzs"]
[Tue Jul 21 07:33:20.336007 2026] [security2:error] [pid 255769:tid 256001] [client 20.220.225.223:49592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9K8LxMYwyVGnfuwsKCQQAABAc"]
[Tue Jul 21 07:33:20.770551 2026] [security2:error] [pid 254995:tid 255205] [client 74.248.121.109:1084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/ini.php"] [unique_id "al9K8P7v0rlcEGmVraEoFAAAA24"]
[Tue Jul 21 07:33:20.780766 2026] [security2:error] [pid 255769:tid 255952] [client 45.8.17.148:43519] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wpx/index.php"] [unique_id "al9K8LxMYwyVGnfuwsKCRQAAA9g"]
[Tue Jul 21 07:33:20.825698 2026] [security2:error] [pid 255769:tid 256022] [client 103.174.34.15:63544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKCRgAABBw"]
[Tue Jul 21 07:33:20.826716 2026] [security2:error] [pid 255769:tid 256022] [client 103.174.34.15:63544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKCRgAABBw"]
[Tue Jul 21 07:33:20.829913 2026] [security2:error] [pid 255769:tid 255848] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKCRwAEG04"]
[Tue Jul 21 07:33:20.830061 2026] [security2:error] [pid 255769:tid 256021] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K8LxMYwyVGnfuwsKCRwAEG04"]
[Tue Jul 21 07:33:20.959886 2026] [security2:error] [pid 254995:tid 255012] [remote 154.61.75.100:35846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9K8P7v0rlcEGmVraEoFgADdhA"]
[Tue Jul 21 07:33:21.142633 2026] [security2:error] [pid 255769:tid 255906] [client 20.206.105.145:38932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ppp.php"] [unique_id "al9K8bxMYwyVGnfuwsKCTgAAA6o"]
[Tue Jul 21 07:33:21.282508 2026] [security2:error] [pid 255769:tid 255956] [client 172.245.102.41:20991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9K8bxMYwyVGnfuwsKCTQAAA9w"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:21.527128 2026] [proxy:error] [pid 254995:tid 255171] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:21.527218 2026] [proxy_http:error] [pid 254995:tid 255171] [client 20.151.10.161:57989] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:21.528482 2026] [proxy:error] [pid 254995:tid 255171] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:21.528529 2026] [proxy_http:error] [pid 254995:tid 255171] [client 20.151.10.161:57989] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:21.642281 2026] [security2:error] [pid 254995:tid 255257] [client 20.220.225.223:48142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9K8f7v0rlcEGmVraEoIgAAA4c"]
[Tue Jul 21 07:33:21.710014 2026] [security2:error] [pid 254995:tid 255201] [client 20.220.225.223:4549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/hp3.php"] [unique_id "al9K8f7v0rlcEGmVraEoIwAAA2o"]
[Tue Jul 21 07:33:21.902483 2026] [security2:error] [pid 254995:tid 255165] [client 74.248.121.109:1066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/themes.php"] [unique_id "al9K8f7v0rlcEGmVraEoJwAAA0Y"]
[Tue Jul 21 07:33:21.988456 2026] [security2:error] [pid 254995:tid 255268] [client 45.8.17.135:26129] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-matcha1.php"] [unique_id "al9K8f7v0rlcEGmVraEoLAAAA5I"]
[Tue Jul 21 07:33:22.300841 2026] [security2:error] [pid 255769:tid 255959] [client 107.149.152.43:33549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.152.149.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/tsogegba.php"] [unique_id "al9K8rxMYwyVGnfuwsKCXgAAA98"], referer: www.google.com
[Tue Jul 21 07:33:22.330319 2026] [security2:error] [pid 255769:tid 255858] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K8rxMYwyVGnfuwsKCXwAD9Vg"]
[Tue Jul 21 07:33:22.331043 2026] [security2:error] [pid 255769:tid 255981] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K8rxMYwyVGnfuwsKCXwAD9Vg"]
[Tue Jul 21 07:33:22.518427 2026] [security2:error] [pid 255769:tid 255910] [client 20.151.10.161:50943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/chosen.php"] [unique_id "al9K8rxMYwyVGnfuwsKCZAAAA64"]
[Tue Jul 21 07:33:22.629347 2026] [security2:error] [pid 255769:tid 255908] [client 74.248.121.109:2086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/dropdown.php"] [unique_id "al9K8rxMYwyVGnfuwsKCaAAAA6w"]
[Tue Jul 21 07:33:22.881414 2026] [security2:error] [pid 255769:tid 255926] [client 20.220.225.223:49563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ms-new.php"] [unique_id "al9K8rxMYwyVGnfuwsKCdwAAA74"]
[Tue Jul 21 07:33:22.967713 2026] [security2:error] [pid 255769:tid 255788] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K8rxMYwyVGnfuwsKCewAD5BI"]
[Tue Jul 21 07:33:22.967847 2026] [security2:error] [pid 255769:tid 255964] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K8rxMYwyVGnfuwsKCewAD5BI"]
[Tue Jul 21 07:33:23.090867 2026] [security2:error] [pid 255769:tid 256004] [client 45.8.17.124:28871] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwenty/assets/js/index.php"] [unique_id "al9K87xMYwyVGnfuwsKCkAAABAo"]
[Tue Jul 21 07:33:23.091480 2026] [security2:error] [pid 254995:tid 255187] [client 20.220.225.223:8933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9K8_7v0rlcEGmVraEoOQAAA1w"]
[Tue Jul 21 07:33:23.133575 2026] [security2:error] [pid 255769:tid 255983] [client 74.248.121.109:1039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/wp-links.php"] [unique_id "al9K87xMYwyVGnfuwsKCkgAAA_c"]
[Tue Jul 21 07:33:23.268323 2026] [security2:error] [pid 255769:tid 255912] [client 104.28.163.33:27054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "10db.com.br"] [uri "/"] [unique_id "al9K87xMYwyVGnfuwsKCnAAAA7A"]
[Tue Jul 21 07:33:23.475614 2026] [security2:error] [pid 255769:tid 255915] [client 20.197.195.24:13061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/classwithtostring.php"] [unique_id "al9K87xMYwyVGnfuwsKCnwAAA7M"]
[Tue Jul 21 07:33:23.758465 2026] [security2:error] [pid 255769:tid 255944] [client 2.57.168.20:32477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.168.57.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9K87xMYwyVGnfuwsKCowAAA9A"]
[Tue Jul 21 07:33:23.813609 2026] [security2:error] [pid 255769:tid 255968] [client 152.59.154.239:64414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K87xMYwyVGnfuwsKCpAAAA-g"]
[Tue Jul 21 07:33:23.813740 2026] [security2:error] [pid 255769:tid 255968] [client 152.59.154.239:64414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K87xMYwyVGnfuwsKCpAAAA-g"]
[Tue Jul 21 07:33:23.851393 2026] [security2:error] [pid 254995:tid 255211] [client 74.248.121.109:1999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/xmrlpc.php"] [unique_id "al9K8_7v0rlcEGmVraEoQwAAA3M"]
[Tue Jul 21 07:33:24.283503 2026] [security2:error] [pid 255769:tid 255917] [client 45.8.17.137:48409] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/dlex/dlex.php"] [unique_id "al9K9LxMYwyVGnfuwsKCsgAAA7U"]
[Tue Jul 21 07:33:24.288882 2026] [security2:error] [pid 255769:tid 256007] [client 193.36.225.104:24235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K87xMYwyVGnfuwsKCpgAABA0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:24.323607 2026] [security2:error] [pid 255769:tid 255939] [client 59.96.220.140:64208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCswAAA8s"]
[Tue Jul 21 07:33:24.323714 2026] [security2:error] [pid 255769:tid 255939] [client 59.96.220.140:64208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCswAAA8s"]
[Tue Jul 21 07:33:24.335985 2026] [security2:error] [pid 255769:tid 255910] [client 74.248.121.109:2161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/htaccess.php"] [unique_id "al9K9LxMYwyVGnfuwsKCtAAAA64"]
[Tue Jul 21 07:33:24.476439 2026] [security2:error] [pid 255769:tid 255906] [client 20.151.10.161:2709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9K9LxMYwyVGnfuwsKCugAAA6o"]
[Tue Jul 21 07:33:24.677601 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:24.677675 2026] [proxy_http:error] [pid 255769:tid 256028] [client 20.151.10.161:57411] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:24.678224 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:24.678249 2026] [proxy_http:error] [pid 255769:tid 256028] [client 20.151.10.161:57411] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:24.761496 2026] [security2:error] [pid 255769:tid 255980] [client 20.151.10.161:2718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9K9LxMYwyVGnfuwsKCwAAAA_Q"]
[Tue Jul 21 07:33:24.927453 2026] [security2:error] [pid 255769:tid 255793] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCwwAD1xc"]
[Tue Jul 21 07:33:24.927592 2026] [security2:error] [pid 255769:tid 255951] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCwwAD1xc"]
[Tue Jul 21 07:33:24.959917 2026] [security2:error] [pid 255769:tid 255777] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCxAAEBQc"]
[Tue Jul 21 07:33:24.960101 2026] [security2:error] [pid 255769:tid 255999] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCxAAEBQc"]
[Tue Jul 21 07:33:24.963177 2026] [security2:error] [pid 255769:tid 255921] [client 109.248.148.246:44020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCxQAAA7k"]
[Tue Jul 21 07:33:24.963286 2026] [security2:error] [pid 255769:tid 255921] [client 109.248.148.246:44020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9K9LxMYwyVGnfuwsKCxQAAA7k"]
[Tue Jul 21 07:33:24.993805 2026] [security2:error] [pid 254995:tid 255189] [client 193.36.225.70:31909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9K9P7v0rlcEGmVraEoTwAAA14"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:25.039920 2026] [security2:error] [pid 254995:tid 255252] [client 20.151.10.161:2947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/images.php"] [unique_id "al9K9f7v0rlcEGmVraEoUAAAA4M"]
[Tue Jul 21 07:33:25.143262 2026] [security2:error] [pid 255769:tid 255774] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K9bxMYwyVGnfuwsKCxgADswQ"]
[Tue Jul 21 07:33:25.143411 2026] [security2:error] [pid 255769:tid 255915] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K9bxMYwyVGnfuwsKCxgADswQ"]
[Tue Jul 21 07:33:25.246871 2026] [security2:error] [pid 255769:tid 255969] [client 74.248.121.109:1073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/readme.php"] [unique_id "al9K9bxMYwyVGnfuwsKCxwAAA-k"]
[Tue Jul 21 07:33:25.325633 2026] [security2:error] [pid 254995:tid 255169] [client 20.151.10.161:2953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/for.php"] [unique_id "al9K9f7v0rlcEGmVraEoVgAAA0o"]
[Tue Jul 21 07:33:25.327222 2026] [security2:error] [pid 255769:tid 255926] [client 139.167.225.182:64981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K9bxMYwyVGnfuwsKCygAAA74"]
[Tue Jul 21 07:33:25.327404 2026] [security2:error] [pid 255769:tid 255926] [client 139.167.225.182:64981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K9bxMYwyVGnfuwsKCygAAA74"]
[Tue Jul 21 07:33:25.398159 2026] [security2:error] [pid 255769:tid 255916] [client 104.28.163.33:27060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "10db.com.br"] [uri "/"] [unique_id "al9K9bxMYwyVGnfuwsKCywAAA7Q"]
[Tue Jul 21 07:33:25.507299 2026] [security2:error] [pid 255769:tid 255944] [client 20.220.225.223:62133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/wp-css.php"] [unique_id "al9K9bxMYwyVGnfuwsKCzQAAA9A"]
[Tue Jul 21 07:33:25.603362 2026] [security2:error] [pid 255769:tid 255943] [client 20.151.10.161:2708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/2larp.php"] [unique_id "al9K9bxMYwyVGnfuwsKC0QAAA88"]
[Tue Jul 21 07:33:25.820566 2026] [security2:error] [pid 255769:tid 255918] [client 20.52.136.55:1753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/66.php"] [unique_id "al9K9bxMYwyVGnfuwsKC1AAAA7Y"]
[Tue Jul 21 07:33:25.879605 2026] [security2:error] [pid 255769:tid 255903] [client 20.151.10.161:2721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/adminner.php"] [unique_id "al9K9bxMYwyVGnfuwsKC1QAAA6c"]
[Tue Jul 21 07:33:25.994192 2026] [security2:error] [pid 254995:tid 255208] [client 45.8.17.141:50725] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/view-source/ioxi-o.php"] [unique_id "al9K9f7v0rlcEGmVraEoYQAAA3A"]
[Tue Jul 21 07:33:26.157233 2026] [security2:error] [pid 255769:tid 255937] [client 20.151.10.161:2702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/82.php"] [unique_id "al9K9rxMYwyVGnfuwsKC2gAAA8k"]
[Tue Jul 21 07:33:26.229865 2026] [security2:error] [pid 255769:tid 256009] [client 20.197.195.24:13100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9K9rxMYwyVGnfuwsKC4QAABA8"]
[Tue Jul 21 07:33:26.274915 2026] [security2:error] [pid 255769:tid 255994] [client 103.162.129.114:61631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K9rxMYwyVGnfuwsKC5AAABAE"]
[Tue Jul 21 07:33:26.275080 2026] [security2:error] [pid 255769:tid 255994] [client 103.162.129.114:61631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9K9rxMYwyVGnfuwsKC5AAABAE"]
[Tue Jul 21 07:33:26.325345 2026] [security2:error] [pid 254995:tid 255190] [client 117.251.86.144:45134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K9v7v0rlcEGmVraEoagAAA18"]
[Tue Jul 21 07:33:26.325439 2026] [security2:error] [pid 254995:tid 255190] [client 117.251.86.144:45134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9K9v7v0rlcEGmVraEoagAAA18"]
[Tue Jul 21 07:33:26.434297 2026] [security2:error] [pid 255769:tid 255980] [client 20.151.10.161:2747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mitolyn.tryhealth.shop"] [uri "/kir.php"] [unique_id "al9K9rxMYwyVGnfuwsKC6gAAA_Q"]
[Tue Jul 21 07:33:26.454104 2026] [security2:error] [pid 255769:tid 255983] [client 74.248.121.109:2058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/403.php"] [unique_id "al9K9rxMYwyVGnfuwsKC6wAAA_c"]
[Tue Jul 21 07:33:26.516177 2026] [security2:error] [pid 255769:tid 255922] [client 104.28.163.33:27066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "10db.com.br"] [uri "/"] [unique_id "al9K9rxMYwyVGnfuwsKC7QAAA7o"]
[Tue Jul 21 07:33:26.553774 2026] [security2:error] [pid 254995:tid 255222] [client 20.151.10.161:51323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/als.php"] [unique_id "al9K9v7v0rlcEGmVraEocQAAA34"]
[Tue Jul 21 07:33:26.980522 2026] [security2:error] [pid 255769:tid 255968] [client 20.220.225.223:4589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/aa1.php"] [unique_id "al9K9rxMYwyVGnfuwsKC-AAAA-g"]
[Tue Jul 21 07:33:27.289362 2026] [security2:error] [pid 255769:tid 256006] [client 45.8.17.117:46663] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/cache/index.php"] [unique_id "al9K97xMYwyVGnfuwsKC_gAABAw"]
[Tue Jul 21 07:33:27.451042 2026] [security2:error] [pid 255769:tid 255969] [client 122.186.204.214:61669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K97xMYwyVGnfuwsKDBQAAA-k"]
[Tue Jul 21 07:33:27.451141 2026] [security2:error] [pid 255769:tid 255969] [client 122.186.204.214:61669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9K97xMYwyVGnfuwsKDBQAAA-k"]
[Tue Jul 21 07:33:27.619860 2026] [security2:error] [pid 255769:tid 255985] [client 20.220.225.223:51493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/track.php"] [unique_id "al9K97xMYwyVGnfuwsKDCgAAA_k"]
[Tue Jul 21 07:33:27.648168 2026] [security2:error] [pid 255769:tid 255984] [client 104.28.163.33:27072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "10db.com.br"] [uri "/"] [unique_id "al9K97xMYwyVGnfuwsKDCwAAA_g"]
[Tue Jul 21 07:33:27.710125 2026] [security2:error] [pid 254995:tid 255196] [client 20.151.10.161:58034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/pol.php"] [unique_id "al9K9_7v0rlcEGmVraEoiQAAA2U"]
[Tue Jul 21 07:33:27.825646 2026] [autoindex:error] [pid 255769:tid 255894] [remote 74.7.242.38:51988] AH01276: Cannot serve directory /home4/arcoll06/y.arcoll.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:27.880397 2026] [security2:error] [pid 254995:tid 255149] [client 74.248.121.109:1078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/max.php"] [unique_id "al9K9_7v0rlcEGmVraEojQAAAzY"]
[Tue Jul 21 07:33:28.053102 2026] [authz_core:error] [pid 254995:tid 255197] [client 213.35.113.47:62265] AH01630: client denied by server configuration: /home1/ofic8899/aizenpower.shop-officialstore.com/wp-content/uploads/index.php
[Tue Jul 21 07:33:28.076408 2026] [security2:error] [pid 255769:tid 255997] [client 20.220.225.223:8939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/wp-explorer.php"] [unique_id "al9K-LxMYwyVGnfuwsKDEAAABAM"]
[Tue Jul 21 07:33:28.091039 2026] [security2:error] [pid 255769:tid 255955] [client 122.162.144.145:15598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDEQAAA9s"]
[Tue Jul 21 07:33:28.091174 2026] [security2:error] [pid 255769:tid 255955] [client 122.162.144.145:15598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDEQAAA9s"]
[Tue Jul 21 07:33:28.177872 2026] [security2:error] [pid 255769:tid 255896] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDEgAEIn4"]
[Tue Jul 21 07:33:28.178064 2026] [security2:error] [pid 255769:tid 256028] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDEgAEIn4"]
[Tue Jul 21 07:33:28.261674 2026] [security2:error] [pid 254995:tid 255198] [client 193.36.225.105:39479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9K-P7v0rlcEGmVraEolwAAA2c"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:28.300920 2026] [security2:error] [pid 255769:tid 255980] [client 173.24.185.52:60792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDGAAAA_Q"]
[Tue Jul 21 07:33:28.301013 2026] [security2:error] [pid 255769:tid 255980] [client 173.24.185.52:60792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDGAAAA_Q"]
[Tue Jul 21 07:33:28.453772 2026] [security2:error] [pid 255769:tid 255909] [client 213.152.162.104:41514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDGQAAA60"]
[Tue Jul 21 07:33:28.453882 2026] [security2:error] [pid 255769:tid 255909] [client 213.152.162.104:41514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9K-LxMYwyVGnfuwsKDGQAAA60"]
[Tue Jul 21 07:33:28.578138 2026] [security2:error] [pid 255769:tid 255961] [client 74.7.175.169:39230] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.y.arcoll.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9K-LxMYwyVGnfuwsKDGwAD4QU"]
[Tue Jul 21 07:33:28.672467 2026] [security2:error] [pid 255769:tid 255931] [client 20.52.136.55:1588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/666.php"] [unique_id "al9K-LxMYwyVGnfuwsKDHgAAA8M"]
[Tue Jul 21 07:33:28.784865 2026] [security2:error] [pid 254995:tid 255161] [client 45.8.17.144:55669] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/table/table/updater-tool.php"] [unique_id "al9K-P7v0rlcEGmVraEopwAAA0I"]
[Tue Jul 21 07:33:28.822110 2026] [security2:error] [pid 254995:tid 255261] [client 20.220.225.223:38692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/echkm.php"] [unique_id "al9K-P7v0rlcEGmVraEoqAAAA4s"]
[Tue Jul 21 07:33:28.959483 2026] [security2:error] [pid 254995:tid 255279] [client 20.151.10.161:50927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file5.php"] [unique_id "al9K-P7v0rlcEGmVraEorQAAA50"]
[Tue Jul 21 07:33:29.005027 2026] [security2:error] [pid 255769:tid 255916] [client 103.106.20.201:54462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDJgAAA7Q"]
[Tue Jul 21 07:33:29.005175 2026] [security2:error] [pid 255769:tid 255916] [client 103.106.20.201:54462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDJgAAA7Q"]
[Tue Jul 21 07:33:29.018109 2026] [security2:error] [pid 254995:tid 255186] [client 20.197.195.24:13103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-blog.php"] [unique_id "al9K-f7v0rlcEGmVraEosAAAA1s"]
[Tue Jul 21 07:33:29.095571 2026] [security2:error] [pid 255769:tid 255785] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDJwADow8"]
[Tue Jul 21 07:33:29.095746 2026] [security2:error] [pid 255769:tid 255899] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDJwADow8"]
[Tue Jul 21 07:33:29.114794 2026] [autoindex:error] [pid 254995:tid 255138] [client 213.35.113.47:62265] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:29.252646 2026] [security2:error] [pid 254995:tid 255135] [client 160.30.136.8:65172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9K-f7v0rlcEGmVraEougAAAyg"]
[Tue Jul 21 07:33:29.254627 2026] [security2:error] [pid 254995:tid 255159] [client 20.220.225.223:24244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/tinyfilemanager.php"] [unique_id "al9K-f7v0rlcEGmVraEouwAAA0A"]
[Tue Jul 21 07:33:29.317232 2026] [security2:error] [pid 254995:tid 255259] [client 74.248.121.109:2076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/m.php"] [unique_id "al9K-f7v0rlcEGmVraEowAAAA4k"]
[Tue Jul 21 07:33:29.362238 2026] [security2:error] [pid 254995:tid 255019] [remote 162.19.86.63:52048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9K-f7v0rlcEGmVraEowgADehc"]
[Tue Jul 21 07:33:29.371461 2026] [security2:error] [pid 254995:tid 255136] [client 20.206.105.145:39275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/201.php"] [unique_id "al9K-f7v0rlcEGmVraEowwAAAyk"]
[Tue Jul 21 07:33:29.434830 2026] [security2:error] [pid 255769:tid 255987] [client 45.251.232.145:52861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDKQAAA_s"]
[Tue Jul 21 07:33:29.434957 2026] [security2:error] [pid 255769:tid 255987] [client 45.251.232.145:52861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDKQAAA_s"]
[Tue Jul 21 07:33:29.664273 2026] [security2:error] [pid 255769:tid 255908] [client 62.102.148.164:48932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDLQAAA6w"]
[Tue Jul 21 07:33:29.664394 2026] [security2:error] [pid 255769:tid 255908] [client 62.102.148.164:48932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9K-bxMYwyVGnfuwsKDLQAAA6w"]
[Tue Jul 21 07:33:29.757189 2026] [security2:error] [pid 255769:tid 255966] [client 20.151.10.161:57373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9K-bxMYwyVGnfuwsKDLgAAA-Y"]
[Tue Jul 21 07:33:29.824545 2026] [security2:error] [pid 255769:tid 256015] [client 136.144.33.101:59705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9K-bxMYwyVGnfuwsKDLAAABBU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:29.840908 2026] [security2:error] [pid 255769:tid 255985] [client 20.206.105.145:38929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ops.php"] [unique_id "al9K-bxMYwyVGnfuwsKDMQAAA_k"]
[Tue Jul 21 07:33:29.846507 2026] [security2:error] [pid 254995:tid 255221] [client 154.192.233.199:59595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-f7v0rlcEGmVraEozwAAA30"]
[Tue Jul 21 07:33:29.846668 2026] [security2:error] [pid 254995:tid 255221] [client 154.192.233.199:59595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-f7v0rlcEGmVraEozwAAA30"]
[Tue Jul 21 07:33:29.963079 2026] [security2:error] [pid 254995:tid 255269] [client 160.30.136.8:57524] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "buyonlinetodayatadiscount.net"] [uri "/"] [unique_id "al9K-f7v0rlcEGmVraEo0gAAA5M"]
[Tue Jul 21 07:33:30.407987 2026] [security2:error] [pid 255769:tid 255999] [client 20.220.225.223:8934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/akismet.php"] [unique_id "al9K-rxMYwyVGnfuwsKDNwAABAU"]
[Tue Jul 21 07:33:30.562616 2026] [security2:error] [pid 254995:tid 255275] [client 213.35.113.47:62379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.113.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-login.php"] [unique_id "al9K-v7v0rlcEGmVraEo4gAAA5k"]
[Tue Jul 21 07:33:30.590058 2026] [security2:error] [pid 255769:tid 256005] [client 74.248.121.109:2105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/click.php"] [unique_id "al9K-rxMYwyVGnfuwsKDOQAABAs"]
[Tue Jul 21 07:33:30.678296 2026] [security2:error] [pid 255769:tid 255962] [client 160.30.136.8:61280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9K-rxMYwyVGnfuwsKDPgAAA-I"]
[Tue Jul 21 07:33:30.758969 2026] [security2:error] [pid 255769:tid 255982] [client 175.45.70.82:55633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-rxMYwyVGnfuwsKDQAAAA_Y"]
[Tue Jul 21 07:33:30.759069 2026] [security2:error] [pid 255769:tid 255982] [client 175.45.70.82:55633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-rxMYwyVGnfuwsKDQAAAA_Y"]
[Tue Jul 21 07:33:30.809544 2026] [security2:error] [pid 255769:tid 255983] [client 117.217.38.194:57557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-rxMYwyVGnfuwsKDQQAAA_c"]
[Tue Jul 21 07:33:30.809662 2026] [security2:error] [pid 255769:tid 255983] [client 117.217.38.194:57557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-rxMYwyVGnfuwsKDQQAAA_c"]
[Tue Jul 21 07:33:31.160725 2026] [security2:error] [pid 254995:tid 255177] [client 20.151.10.161:50926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file.php"] [unique_id "al9K-_7v0rlcEGmVraEo7QAAA1I"]
[Tue Jul 21 07:33:31.279889 2026] [security2:error] [pid 255769:tid 255916] [client 45.8.17.146:52029] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/maintenance.php"] [unique_id "al9K-7xMYwyVGnfuwsKDSgAAA7Q"]
[Tue Jul 21 07:33:31.356090 2026] [security2:error] [pid 254995:tid 255068] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-_7v0rlcEGmVraEo8AADh0g"]
[Tue Jul 21 07:33:31.356232 2026] [security2:error] [pid 254995:tid 255257] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-_7v0rlcEGmVraEo8AADh0g"]
[Tue Jul 21 07:33:31.393214 2026] [security2:error] [pid 254995:tid 255201] [client 160.30.136.8:53968] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "buyonlinetodayatadiscount.net"] [uri "/"] [unique_id "al9K-_7v0rlcEGmVraEo8QAAA2o"]
[Tue Jul 21 07:33:31.413945 2026] [security2:error] [pid 255769:tid 255930] [client 103.174.34.15:64238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-7xMYwyVGnfuwsKDTgAAA8I"]
[Tue Jul 21 07:33:31.414076 2026] [security2:error] [pid 255769:tid 255930] [client 103.174.34.15:64238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K-7xMYwyVGnfuwsKDTgAAA8I"]
[Tue Jul 21 07:33:31.703555 2026] [security2:error] [pid 255769:tid 256020] [client 20.220.225.223:62850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/ace2.php"] [unique_id "al9K-7xMYwyVGnfuwsKDUgAABBo"]
[Tue Jul 21 07:33:31.788311 2026] [security2:error] [pid 255769:tid 255905] [client 20.206.105.145:38940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ingfo.php"] [unique_id "al9K-7xMYwyVGnfuwsKDUwAAA6k"]
[Tue Jul 21 07:33:31.797141 2026] [security2:error] [pid 255769:tid 256022] [client 20.220.225.223:19697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/hp2.php"] [unique_id "al9K-7xMYwyVGnfuwsKDVAAABBw"]
[Tue Jul 21 07:33:31.827189 2026] [autoindex:error] [pid 255769:tid 255959] [client 20.197.195.24:13074] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:31.974987 2026] [security2:error] [pid 254995:tid 255139] [client 20.220.225.223:24261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/ee.php"] [unique_id "al9K-_7v0rlcEGmVraEo_wAAAyw"]
[Tue Jul 21 07:33:32.085638 2026] [security2:error] [pid 254995:tid 255159] [client 74.248.121.109:2169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/lv.php"] [unique_id "al9K_P7v0rlcEGmVraEpAQAAA0A"]
[Tue Jul 21 07:33:32.123679 2026] [security2:error] [pid 254995:tid 255178] [client 160.30.136.8:52391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9K_P7v0rlcEGmVraEpAgAAA1M"]
[Tue Jul 21 07:33:32.154474 2026] [security2:error] [pid 255769:tid 255925] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K-rxMYwyVGnfuwsKDRAADvWo"]
[Tue Jul 21 07:33:32.771653 2026] [security2:error] [pid 255769:tid 255940] [client 20.197.195.24:13074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-content/admin.php"] [unique_id "al9K_LxMYwyVGnfuwsKDYQAAA8w"]
[Tue Jul 21 07:33:32.831254 2026] [security2:error] [pid 254995:tid 255090] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K_P7v0rlcEGmVraEpHQADQV4"]
[Tue Jul 21 07:33:32.831443 2026] [security2:error] [pid 254995:tid 255160] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9K_P7v0rlcEGmVraEpHQADQV4"]
[Tue Jul 21 07:33:32.840212 2026] [security2:error] [pid 255769:tid 256025] [client 160.30.136.8:51299] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "buyonlinetodayatadiscount.net"] [uri "/"] [unique_id "al9K_LxMYwyVGnfuwsKDYgAABB8"]
[Tue Jul 21 07:33:32.876721 2026] [security2:error] [pid 255769:tid 255912] [client 20.206.105.145:38951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/error_log.php"] [unique_id "al9K_LxMYwyVGnfuwsKDYwAAA7A"]
[Tue Jul 21 07:33:32.959256 2026] [security2:error] [pid 254995:tid 255224] [client 20.220.225.223:19310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/hp3.php"] [unique_id "al9K_P7v0rlcEGmVraEpHwAAA4A"]
[Tue Jul 21 07:33:33.017423 2026] [security2:error] [pid 254995:tid 255211] [client 74.248.121.109:2175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/cong.php"] [unique_id "al9K_f7v0rlcEGmVraEpIQAAA3M"]
[Tue Jul 21 07:33:33.184830 2026] [security2:error] [pid 255769:tid 255989] [client 20.220.225.223:8958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.pousadaalpesdeminas.com.br"] [uri "/ms.php"] [unique_id "al9K_bxMYwyVGnfuwsKDZgAAA_0"]
[Tue Jul 21 07:33:33.272506 2026] [security2:error] [pid 255769:tid 255909] [client 20.220.225.223:49841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/2352356666.php"] [unique_id "al9K_bxMYwyVGnfuwsKDaAAAA60"]
[Tue Jul 21 07:33:33.479749 2026] [security2:error] [pid 254995:tid 255155] [client 45.8.17.118:20509] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/admin.php"] [unique_id "al9K_f7v0rlcEGmVraEpKAAAAzw"]
[Tue Jul 21 07:33:33.616113 2026] [security2:error] [pid 254995:tid 255115] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K_f7v0rlcEGmVraEpLQADeHc"]
[Tue Jul 21 07:33:33.616284 2026] [security2:error] [pid 254995:tid 255216] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9K_f7v0rlcEGmVraEpLQADeHc"]
[Tue Jul 21 07:33:33.647297 2026] [security2:error] [pid 254995:tid 255177] [client 160.30.136.8:55953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9K_f7v0rlcEGmVraEpLgAAA1I"]
[Tue Jul 21 07:33:33.649593 2026] [security2:error] [pid 255769:tid 255918] [client 74.248.121.109:1029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/brand.php"] [unique_id "al9K_bxMYwyVGnfuwsKDbgAAA7Y"]
[Tue Jul 21 07:33:33.663970 2026] [security2:error] [pid 255769:tid 255903] [client 20.220.225.223:61997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/acew67.php"] [unique_id "al9K_bxMYwyVGnfuwsKDbwAAA6c"]
[Tue Jul 21 07:33:33.724456 2026] [security2:error] [pid 255769:tid 255930] [client 20.52.136.55:1545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/byp.php"] [unique_id "al9K_bxMYwyVGnfuwsKDcAAAA8I"]
[Tue Jul 21 07:33:33.745665 2026] [security2:error] [pid 255769:tid 255967] [client 20.197.195.24:13077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ms-edit.php"] [unique_id "al9K_bxMYwyVGnfuwsKDcQAAA-c"]
[Tue Jul 21 07:33:33.802530 2026] [core:error] [pid 255769:tid 255859] [remote 40.77.167.77:18347] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:33:33.802552 2026] [core:error] [pid 255769:tid 255859] [remote 40.77.167.77:18347] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:33:34.036797 2026] [security2:error] [pid 255769:tid 256026] [client 20.151.10.161:57392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/cfile.php"] [unique_id "al9K_rxMYwyVGnfuwsKDdQAABCA"]
[Tue Jul 21 07:33:34.362288 2026] [security2:error] [pid 255769:tid 255959] [client 160.30.136.8:50387] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "buyonlinetodayatadiscount.net"] [uri "/"] [unique_id "al9K_rxMYwyVGnfuwsKDdwAAA98"]
[Tue Jul 21 07:33:34.384652 2026] [security2:error] [pid 255769:tid 255915] [client 136.144.33.29:25117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9K_rxMYwyVGnfuwsKDeAAAA7M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:34.393562 2026] [security2:error] [pid 255769:tid 256009] [client 45.8.17.145:44875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/home.php"] [unique_id "al9K_rxMYwyVGnfuwsKDeQAABA8"]
[Tue Jul 21 07:33:34.549942 2026] [security2:error] [pid 255769:tid 255937] [client 20.206.105.145:39132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xenon1337.php"] [unique_id "al9K_rxMYwyVGnfuwsKDfAAAA8k"]
[Tue Jul 21 07:33:34.579454 2026] [security2:error] [pid 255769:tid 255850] [remote 173.212.252.15:52902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9K_rxMYwyVGnfuwsKDfQAEGlA"]
[Tue Jul 21 07:33:34.693540 2026] [security2:error] [pid 255769:tid 255993] [client 74.248.121.109:1042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/atomlib.php"] [unique_id "al9K_rxMYwyVGnfuwsKDfgAABAA"]
[Tue Jul 21 07:33:34.862366 2026] [security2:error] [pid 255769:tid 255994] [client 59.96.220.140:64702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K_rxMYwyVGnfuwsKDgQAABAE"]
[Tue Jul 21 07:33:34.862498 2026] [security2:error] [pid 255769:tid 255994] [client 59.96.220.140:64702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9K_rxMYwyVGnfuwsKDgQAABAE"]
[Tue Jul 21 07:33:35.253036 2026] [security2:error] [pid 255769:tid 255953] [client 20.151.10.161:57441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/class-wp.php"] [unique_id "al9K_7xMYwyVGnfuwsKDiQAAA9k"]
[Tue Jul 21 07:33:35.410585 2026] [security2:error] [pid 255769:tid 255943] [client 74.248.121.109:2056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/0x.php"] [unique_id "al9K_7xMYwyVGnfuwsKDjAAAA88"]
[Tue Jul 21 07:33:35.425969 2026] [security2:error] [pid 254995:tid 254996] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K__7v0rlcEGmVraEpZQADHgA"]
[Tue Jul 21 07:33:35.426140 2026] [security2:error] [pid 254995:tid 255125] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9K__7v0rlcEGmVraEpZQADHgA"]
[Tue Jul 21 07:33:35.481003 2026] [security2:error] [pid 254995:tid 254999] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K__7v0rlcEGmVraEpZwADeQM"]
[Tue Jul 21 07:33:35.481152 2026] [security2:error] [pid 254995:tid 255217] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9K__7v0rlcEGmVraEpZwADeQM"]
[Tue Jul 21 07:33:35.522910 2026] [security2:error] [pid 255769:tid 255906] [client 20.197.195.24:13110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/cgi-bin/index.php"] [unique_id "al9K_7xMYwyVGnfuwsKDjwAAA6o"]
[Tue Jul 21 07:33:35.671311 2026] [security2:error] [pid 255769:tid 255845] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K_7xMYwyVGnfuwsKDkQAD20s"]
[Tue Jul 21 07:33:35.671453 2026] [security2:error] [pid 255769:tid 255955] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K_7xMYwyVGnfuwsKDkQAD20s"]
[Tue Jul 21 07:33:35.792919 2026] [security2:error] [pid 254995:tid 255195] [client 74.7.241.156:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fernandadealencarluc1748790617000.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9K__7v0rlcEGmVraEpbAADZEA"]
[Tue Jul 21 07:33:35.808899 2026] [security2:error] [pid 254995:tid 255223] [client 139.167.225.182:49234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K__7v0rlcEGmVraEpbQAAA38"]
[Tue Jul 21 07:33:35.808996 2026] [security2:error] [pid 254995:tid 255223] [client 139.167.225.182:49234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9K__7v0rlcEGmVraEpbQAAA38"]
[Tue Jul 21 07:33:35.977563 2026] [security2:error] [pid 255769:tid 255938] [client 20.220.225.223:19275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/aa1.php"] [unique_id "al9K_7xMYwyVGnfuwsKDtwAAA8o"]
[Tue Jul 21 07:33:36.092164 2026] [security2:error] [pid 255769:tid 256001] [client 20.151.10.161:50908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/admin.php"] [unique_id "al9LALxMYwyVGnfuwsKDuAAABAc"]
[Tue Jul 21 07:33:36.184858 2026] [security2:error] [pid 254995:tid 255154] [client 45.8.17.58:35511] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/oceanwp/content-index.php"] [unique_id "al9LAP7v0rlcEGmVraEpgQAAAzs"]
[Tue Jul 21 07:33:36.194838 2026] [security2:error] [pid 255769:tid 255996] [client 74.248.121.109:1062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/buy.php"] [unique_id "al9LALxMYwyVGnfuwsKD0AAABAI"]
[Tue Jul 21 07:33:36.302622 2026] [security2:error] [pid 254995:tid 255222] [client 47.128.29.176:55094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "casaejardimperfeito.com.br"] [uri "/robots.txt"] [unique_id "al9LAP7v0rlcEGmVraEphwAAA34"]
[Tue Jul 21 07:33:36.491134 2026] [security2:error] [pid 255769:tid 255973] [client 20.206.105.145:38927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/test11.php"] [unique_id "al9LALxMYwyVGnfuwsKD0wAAA-0"]
[Tue Jul 21 07:33:36.566293 2026] [security2:error] [pid 254995:tid 255170] [client 74.7.230.16:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "divmax.com.br"] [uri "/index.php"] [unique_id "al9K__7v0rlcEGmVraEpYQAAA0s"]
[Tue Jul 21 07:33:36.567150 2026] [security2:error] [pid 255769:tid 255956] [client 74.7.230.16:46884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "divmax.com.br"] [uri "/robots.txt"] [unique_id "al9K_7xMYwyVGnfuwsKDigAD3Ds"]
[Tue Jul 21 07:33:36.623868 2026] [security2:error] [pid 255769:tid 255958] [client 20.220.225.223:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/pn.php"] [unique_id "al9LALxMYwyVGnfuwsKD1QAAA94"]
[Tue Jul 21 07:33:36.711493 2026] [security2:error] [pid 255769:tid 255916] [client 152.59.154.239:64910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LALxMYwyVGnfuwsKD4QAAA7Q"]
[Tue Jul 21 07:33:36.711575 2026] [security2:error] [pid 255769:tid 255916] [client 152.59.154.239:64910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LALxMYwyVGnfuwsKD4QAAA7Q"]
[Tue Jul 21 07:33:36.745539 2026] [security2:error] [pid 254995:tid 255129] [client 20.151.10.161:57355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/aa2.php"] [unique_id "al9LAP7v0rlcEGmVraEplgAAAyI"]
[Tue Jul 21 07:33:36.930741 2026] [security2:error] [pid 254995:tid 255133] [client 103.162.129.114:62074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LAP7v0rlcEGmVraEpmAAAAyY"]
[Tue Jul 21 07:33:36.930888 2026] [security2:error] [pid 254995:tid 255133] [client 103.162.129.114:62074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LAP7v0rlcEGmVraEpmAAAAyY"]
[Tue Jul 21 07:33:37.026235 2026] [security2:error] [pid 255769:tid 255998] [client 117.251.86.144:49132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LAbxMYwyVGnfuwsKD8QAABAQ"]
[Tue Jul 21 07:33:37.026416 2026] [security2:error] [pid 255769:tid 255998] [client 117.251.86.144:49132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LAbxMYwyVGnfuwsKD8QAABAQ"]
[Tue Jul 21 07:33:37.213420 2026] [security2:error] [pid 255769:tid 255967] [client 74.248.121.109:2166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/sx.php"] [unique_id "al9LAbxMYwyVGnfuwsKD_AAAA-c"]
[Tue Jul 21 07:33:37.275803 2026] [security2:error] [pid 255769:tid 255990] [client 20.151.10.161:58065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/ccou.php"] [unique_id "al9LAbxMYwyVGnfuwsKD_wAAA_4"]
[Tue Jul 21 07:33:37.318555 2026] [autoindex:error] [pid 255769:tid 255968] [client 20.197.195.24:13108] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:37.343435 2026] [security2:error] [pid 255769:tid 255988] [client 20.197.195.24:13108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/BDKR28WP.php"] [unique_id "al9LAbxMYwyVGnfuwsKEAgAAA_w"]
[Tue Jul 21 07:33:37.413357 2026] [security2:error] [pid 255769:tid 256020] [client 20.220.225.223:49854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-wpbak.php"] [unique_id "al9LAbxMYwyVGnfuwsKEVwAABBo"]
[Tue Jul 21 07:33:37.497088 2026] [security2:error] [pid 255769:tid 256003] [client 45.8.17.118:39855] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/Divi/content-index.php"] [unique_id "al9LAbxMYwyVGnfuwsKEWgAABAk"]
[Tue Jul 21 07:33:37.543331 2026] [security2:error] [pid 255769:tid 255998] [client 20.220.225.223:19659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/acew67.php"] [unique_id "al9LAbxMYwyVGnfuwsKEWwAABAQ"]
[Tue Jul 21 07:33:37.789288 2026] [security2:error] [pid 255769:tid 255989] [client 20.151.10.161:50941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/dr.php"] [unique_id "al9LAbxMYwyVGnfuwsKEYAAAA_0"]
[Tue Jul 21 07:33:38.127783 2026] [security2:error] [pid 255769:tid 255952] [client 122.186.204.214:62175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LArxMYwyVGnfuwsKEZgAAA9g"]
[Tue Jul 21 07:33:38.127911 2026] [security2:error] [pid 255769:tid 255952] [client 122.186.204.214:62175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LArxMYwyVGnfuwsKEZgAAA9g"]
[Tue Jul 21 07:33:38.133135 2026] [security2:error] [pid 254995:tid 255257] [client 193.36.225.55:26227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LAv7v0rlcEGmVraEpxwAAA4c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:38.250447 2026] [security2:error] [pid 255769:tid 255966] [client 20.220.225.223:49811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/old.php"] [unique_id "al9LArxMYwyVGnfuwsKEZwAAA-Y"]
[Tue Jul 21 07:33:38.299400 2026] [security2:error] [pid 254995:tid 255170] [client 20.220.225.223:38701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/mac.php"] [unique_id "al9LAv7v0rlcEGmVraEpzgAAA0s"]
[Tue Jul 21 07:33:38.335058 2026] [security2:error] [pid 254995:tid 255177] [client 20.151.10.161:51272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/xamp.php"] [unique_id "al9LAv7v0rlcEGmVraEpzwAAA1I"]
[Tue Jul 21 07:33:38.489295 2026] [security2:error] [pid 255769:tid 255903] [client 74.248.121.109:2165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/article.php"] [unique_id "al9LArxMYwyVGnfuwsKEaQAAA6c"]
[Tue Jul 21 07:33:38.548123 2026] [autoindex:error] [pid 255769:tid 256001] [client 20.197.195.24:48870] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:38.567387 2026] [autoindex:error] [pid 255769:tid 255924] [client 20.197.195.24:48870] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:38.572915 2026] [security2:error] [pid 255769:tid 256020] [client 20.197.195.24:48870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/abcd.php"] [unique_id "al9LArxMYwyVGnfuwsKEbwAABBo"]
[Tue Jul 21 07:33:38.721419 2026] [security2:error] [pid 254995:tid 255213] [client 20.52.136.55:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/date.php"] [unique_id "al9LAv7v0rlcEGmVraEp2AAAA3U"]
[Tue Jul 21 07:33:38.731230 2026] [security2:error] [pid 254995:tid 255204] [client 82.102.28.107:37168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9LAv7v0rlcEGmVraEp2QAAA20"]
[Tue Jul 21 07:33:38.731316 2026] [security2:error] [pid 254995:tid 255204] [client 82.102.28.107:37168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9LAv7v0rlcEGmVraEp2QAAA20"]
[Tue Jul 21 07:33:38.753865 2026] [security2:error] [pid 255769:tid 255986] [client 173.24.185.52:61249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LArxMYwyVGnfuwsKEeQAAA_o"]
[Tue Jul 21 07:33:38.753974 2026] [security2:error] [pid 255769:tid 255986] [client 173.24.185.52:61249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LArxMYwyVGnfuwsKEeQAAA_o"]
[Tue Jul 21 07:33:38.788924 2026] [security2:error] [pid 255769:tid 256025] [client 45.8.17.123:53309] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/exnova/content-index.php"] [unique_id "al9LArxMYwyVGnfuwsKEfQAABB8"]
[Tue Jul 21 07:33:38.878959 2026] [security2:error] [pid 255769:tid 255926] [client 20.151.10.161:57406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/bless.php"] [unique_id "al9LArxMYwyVGnfuwsKEfwAAA74"]
[Tue Jul 21 07:33:38.905394 2026] [security2:error] [pid 254995:tid 255199] [client 122.162.144.145:29947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LAv7v0rlcEGmVraEp4AAAA2g"]
[Tue Jul 21 07:33:38.905501 2026] [security2:error] [pid 254995:tid 255199] [client 122.162.144.145:29947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LAv7v0rlcEGmVraEp4AAAA2g"]
[Tue Jul 21 07:33:39.039790 2026] [security2:error] [pid 255769:tid 256006] [client 20.206.105.145:38966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/koala.php"] [unique_id "al9LA7xMYwyVGnfuwsKEhAAABAw"]
[Tue Jul 21 07:33:39.158477 2026] [security2:error] [pid 255769:tid 255808] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LA7xMYwyVGnfuwsKEhwAD2yY"]
[Tue Jul 21 07:33:39.158608 2026] [security2:error] [pid 255769:tid 255955] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LA7xMYwyVGnfuwsKEhwAD2yY"]
[Tue Jul 21 07:33:39.247863 2026] [security2:error] [pid 255769:tid 255923] [client 20.151.10.161:58037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file46.php"] [unique_id "al9LA7xMYwyVGnfuwsKEiAAAA7s"]
[Tue Jul 21 07:33:39.334905 2026] [security2:error] [pid 254995:tid 255223] [client 74.248.121.109:2068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/bootstrap.php"] [unique_id "al9LA_7v0rlcEGmVraEp5gAAA38"]
[Tue Jul 21 07:33:39.361358 2026] [security2:error] [pid 255769:tid 255899] [client 20.220.225.223:4217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/bscclapb.php"] [unique_id "al9LA7xMYwyVGnfuwsKEiwAAA6M"]
[Tue Jul 21 07:33:39.519372 2026] [security2:error] [pid 254995:tid 255224] [client 20.220.225.223:6107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/billur.php"] [unique_id "al9LA_7v0rlcEGmVraEp6gAAA4A"]
[Tue Jul 21 07:33:39.634806 2026] [security2:error] [pid 254995:tid 255073] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LA_7v0rlcEGmVraEp7wADWU0"]
[Tue Jul 21 07:33:39.635004 2026] [security2:error] [pid 254995:tid 255184] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LA_7v0rlcEGmVraEp7wADWU0"]
[Tue Jul 21 07:33:39.664075 2026] [security2:error] [pid 254995:tid 255176] [client 103.106.20.201:55039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LA_7v0rlcEGmVraEp8AAAA1E"]
[Tue Jul 21 07:33:39.665730 2026] [security2:error] [pid 254995:tid 255176] [client 103.106.20.201:55039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LA_7v0rlcEGmVraEp8AAAA1E"]
[Tue Jul 21 07:33:39.667230 2026] [security2:error] [pid 254995:tid 255218] [client 20.197.195.24:13137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/file15.php"] [unique_id "al9LA_7v0rlcEGmVraEp8QAAA3o"]
[Tue Jul 21 07:33:39.883679 2026] [security2:error] [pid 255769:tid 255930] [client 45.251.232.145:53387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LA7xMYwyVGnfuwsKEkQAAA8I"]
[Tue Jul 21 07:33:39.883853 2026] [security2:error] [pid 255769:tid 255930] [client 45.251.232.145:53387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LA7xMYwyVGnfuwsKEkQAAA8I"]
[Tue Jul 21 07:33:39.894228 2026] [security2:error] [pid 254995:tid 255181] [client 20.151.10.161:58627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/eee.php"] [unique_id "al9LA_7v0rlcEGmVraEp9gAAA1Y"]
[Tue Jul 21 07:33:39.951214 2026] [security2:error] [pid 254995:tid 255173] [client 20.220.225.223:24193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/blue.php"] [unique_id "al9LA_7v0rlcEGmVraEp9wAAA04"]
[Tue Jul 21 07:33:39.986326 2026] [security2:error] [pid 254995:tid 255156] [client 45.8.17.128:35119] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/specia/content-index.php"] [unique_id "al9LA_7v0rlcEGmVraEp-QAAAz0"]
[Tue Jul 21 07:33:40.297078 2026] [security2:error] [pid 254995:tid 255229] [client 74.248.121.109:2081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/config-backup.php"] [unique_id "al9LBP7v0rlcEGmVraEqAAAAA4I"]
[Tue Jul 21 07:33:40.301726 2026] [security2:error] [pid 255769:tid 255985] [client 20.151.10.161:57998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file25.php"] [unique_id "al9LBLxMYwyVGnfuwsKEkgAAA_k"]
[Tue Jul 21 07:33:40.484939 2026] [security2:error] [pid 254995:tid 255220] [client 154.192.233.199:60071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBP7v0rlcEGmVraEqAwAAA3w"]
[Tue Jul 21 07:33:40.485102 2026] [security2:error] [pid 254995:tid 255220] [client 154.192.233.199:60071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBP7v0rlcEGmVraEqAwAAA3w"]
[Tue Jul 21 07:33:41.000686 2026] [security2:error] [pid 254995:tid 255183] [client 74.248.121.109:2114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/goods.php"] [unique_id "al9LBP7v0rlcEGmVraEqEgAAA1g"]
[Tue Jul 21 07:33:41.099394 2026] [security2:error] [pid 255769:tid 256010] [client 109.248.148.246:55524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LBbxMYwyVGnfuwsKEnAAABBA"]
[Tue Jul 21 07:33:41.099486 2026] [security2:error] [pid 255769:tid 256010] [client 109.248.148.246:55524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LBbxMYwyVGnfuwsKEnAAABBA"]
[Tue Jul 21 07:33:41.187269 2026] [security2:error] [pid 255769:tid 256021] [client 45.8.17.62:63391] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "al9LBbxMYwyVGnfuwsKEnwAABBs"]
[Tue Jul 21 07:33:41.273020 2026] [security2:error] [pid 255769:tid 256018] [client 117.217.38.194:57996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBbxMYwyVGnfuwsKEoQAABBg"]
[Tue Jul 21 07:33:41.273145 2026] [security2:error] [pid 255769:tid 256018] [client 117.217.38.194:57996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBbxMYwyVGnfuwsKEoQAABBg"]
[Tue Jul 21 07:33:41.284618 2026] [security2:error] [pid 255769:tid 255987] [client 20.151.10.161:51285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file48.php"] [unique_id "al9LBbxMYwyVGnfuwsKEogAAA_s"]
[Tue Jul 21 07:33:41.450243 2026] [security2:error] [pid 254995:tid 255264] [client 74.7.175.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "taliafernandavidi1782074982000.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9LBf7v0rlcEGmVraEqGQADjnE"]
[Tue Jul 21 07:33:41.457219 2026] [security2:error] [pid 254995:tid 255265] [client 175.45.70.82:56142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBf7v0rlcEGmVraEqGgAAA48"]
[Tue Jul 21 07:33:41.457336 2026] [security2:error] [pid 254995:tid 255265] [client 175.45.70.82:56142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBf7v0rlcEGmVraEqGgAAA48"]
[Tue Jul 21 07:33:41.519849 2026] [security2:error] [pid 254995:tid 255159] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LBf7v0rlcEGmVraEqGwADQGw"]
[Tue Jul 21 07:33:41.527600 2026] [security2:error] [pid 254995:tid 255136] [client 74.248.121.109:2171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/init.php"] [unique_id "al9LBf7v0rlcEGmVraEqHAAAAyk"]
[Tue Jul 21 07:33:41.670595 2026] [security2:error] [pid 255769:tid 255974] [client 37.140.223.118:39935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LBbxMYwyVGnfuwsKEowAAA-4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:41.755506 2026] [security2:error] [pid 254995:tid 255135] [client 20.151.10.161:50887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file6.php"] [unique_id "al9LBf7v0rlcEGmVraEqIAAAAyg"]
[Tue Jul 21 07:33:41.764960 2026] [security2:error] [pid 254995:tid 255160] [client 20.220.225.223:49580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ms-new.php"] [unique_id "al9LBf7v0rlcEGmVraEqIQAAA0E"]
[Tue Jul 21 07:33:41.918153 2026] [security2:error] [pid 255769:tid 255989] [client 20.220.225.223:6098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/mimpi.php"] [unique_id "al9LBbxMYwyVGnfuwsKErAAAA_0"]
[Tue Jul 21 07:33:42.071758 2026] [security2:error] [pid 255769:tid 255988] [client 20.52.136.55:1584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/pomo.php"] [unique_id "al9LBrxMYwyVGnfuwsKEuAAAA_w"]
[Tue Jul 21 07:33:42.125082 2026] [security2:error] [pid 255769:tid 255899] [client 20.220.225.223:56496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/else1.php"] [unique_id "al9LBrxMYwyVGnfuwsKEuQAAA6M"]
[Tue Jul 21 07:33:42.181762 2026] [security2:error] [pid 255769:tid 255996] [client 20.151.10.161:57448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/a2.php"] [unique_id "al9LBrxMYwyVGnfuwsKEuwAABAI"]
[Tue Jul 21 07:33:42.215114 2026] [security2:error] [pid 255769:tid 255980] [client 20.197.195.24:48846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/jp.php"] [unique_id "al9LBrxMYwyVGnfuwsKEwQAAA_Q"]
[Tue Jul 21 07:33:42.318538 2026] [security2:error] [pid 255769:tid 255820] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBrxMYwyVGnfuwsKEzQAD2DI"]
[Tue Jul 21 07:33:42.318686 2026] [security2:error] [pid 255769:tid 255952] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBrxMYwyVGnfuwsKEzQAD2DI"]
[Tue Jul 21 07:33:42.353831 2026] [security2:error] [pid 255769:tid 255906] [client 103.174.34.15:64771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBrxMYwyVGnfuwsKEzgAAA6o"]
[Tue Jul 21 07:33:42.353949 2026] [security2:error] [pid 255769:tid 255906] [client 103.174.34.15:64771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LBrxMYwyVGnfuwsKEzgAAA6o"]
[Tue Jul 21 07:33:42.383315 2026] [security2:error] [pid 255769:tid 255958] [client 193.36.225.71:24999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LBrxMYwyVGnfuwsKEwAAAA94"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:42.401148 2026] [security2:error] [pid 255769:tid 255854] [remote 154.61.75.100:51118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9LBrxMYwyVGnfuwsKE0AADs1Q"]
[Tue Jul 21 07:33:42.431458 2026] [security2:error] [pid 255769:tid 255902] [client 20.206.105.145:38957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/mac.php"] [unique_id "al9LBrxMYwyVGnfuwsKE1QAAA6Y"]
[Tue Jul 21 07:33:42.460366 2026] [authz_core:error] [pid 255769:tid 255910] [client 74.248.121.109:2137] AH01630: client denied by server configuration: /home2/issima95/issimastore.com/php.ini
[Tue Jul 21 07:33:42.489572 2026] [security2:error] [pid 255769:tid 256000] [client 20.151.10.161:57385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/file15.php"] [unique_id "al9LBrxMYwyVGnfuwsKE3gAABAY"]
[Tue Jul 21 07:33:42.599515 2026] [security2:error] [pid 255769:tid 255986] [client 45.8.17.113:24377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/eroor.php"] [unique_id "al9LBrxMYwyVGnfuwsKE3wAAA_o"]
[Tue Jul 21 07:33:42.671658 2026] [security2:error] [pid 255769:tid 255997] [client 74.248.121.109:2137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/settings.php"] [unique_id "al9LBrxMYwyVGnfuwsKE6AAABAM"]
[Tue Jul 21 07:33:42.894544 2026] [security2:error] [pid 255769:tid 255950] [client 20.151.10.161:57396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/jp.php"] [unique_id "al9LBrxMYwyVGnfuwsKE6gAAA9Y"]
[Tue Jul 21 07:33:43.170131 2026] [security2:error] [pid 255769:tid 255880] [remote 51.68.111.209:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "githec.com"] [uri "/robots.txt"] [unique_id "al9LB7xMYwyVGnfuwsKE6wADvm4"]
[Tue Jul 21 07:33:43.170276 2026] [security2:error] [pid 255769:tid 255926] [client 51.68.111.209:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "githec.com"] [uri "/robots.txt"] [unique_id "al9LB7xMYwyVGnfuwsKE6wADvm4"]
[Tue Jul 21 07:33:43.283810 2026] [security2:error] [pid 255769:tid 255918] [client 74.248.121.109:2080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/g.php"] [unique_id "al9LB7xMYwyVGnfuwsKE7gAAA7Y"]
[Tue Jul 21 07:33:43.290877 2026] [security2:error] [pid 255769:tid 255983] [client 20.220.225.223:31191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/samll.php"] [unique_id "al9LB7xMYwyVGnfuwsKE7wAAA_c"]
[Tue Jul 21 07:33:43.338779 2026] [security2:error] [pid 255769:tid 255879] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LB7xMYwyVGnfuwsKE8AAEC20"]
[Tue Jul 21 07:33:43.338943 2026] [security2:error] [pid 255769:tid 256005] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LB7xMYwyVGnfuwsKE8AAEC20"]
[Tue Jul 21 07:33:43.513102 2026] [security2:error] [pid 255769:tid 255943] [client 20.151.10.161:57345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/f35.php"] [unique_id "al9LB7xMYwyVGnfuwsKE9AAAA88"]
[Tue Jul 21 07:33:43.562969 2026] [security2:error] [pid 255769:tid 255955] [client 20.10.88.201:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "digital-universo.com"] [uri "/index.php"] [unique_id "al9LB7xMYwyVGnfuwsKE8wAD2w8"]
[Tue Jul 21 07:33:43.836731 2026] [security2:error] [pid 255769:tid 256015] [client 20.220.225.223:48131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/track.php"] [unique_id "al9LB7xMYwyVGnfuwsKE_QAABBU"]
[Tue Jul 21 07:33:43.888476 2026] [security2:error] [pid 255769:tid 255953] [client 74.248.121.109:1048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/403.php"] [unique_id "al9LB7xMYwyVGnfuwsKE_gAAA9k"]
[Tue Jul 21 07:33:43.963277 2026] [security2:error] [pid 254995:tid 255098] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9LB_7v0rlcEGmVraEqPwADQmY"]
[Tue Jul 21 07:33:43.979338 2026] [security2:error] [pid 254995:tid 255150] [client 20.220.225.223:24194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/wp-signup.php"] [unique_id "al9LB_7v0rlcEGmVraEqQgAAAzc"]
[Tue Jul 21 07:33:43.986380 2026] [security2:error] [pid 254995:tid 255127] [client 45.8.17.110:48343] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/themes/home.php"] [unique_id "al9LB_7v0rlcEGmVraEqQwAAAyA"]
[Tue Jul 21 07:33:43.994810 2026] [security2:error] [pid 255769:tid 255931] [client 20.220.225.223:23428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/dp.php"] [unique_id "al9LB7xMYwyVGnfuwsKFAAAAA8M"]
[Tue Jul 21 07:33:44.185672 2026] [security2:error] [pid 255769:tid 255952] [client 20.151.10.161:57993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-load.php"] [unique_id "al9LCLxMYwyVGnfuwsKFAQAAA9g"]
[Tue Jul 21 07:33:44.272341 2026] [security2:error] [pid 255769:tid 255915] [client 216.244.66.229:54006] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "megaroteiros.com.br"] [uri "/wp-content/uploads/2015/07/tam.png"] [unique_id "al9LCLxMYwyVGnfuwsKFBQAAA7M"]
[Tue Jul 21 07:33:44.272468 2026] [security2:error] [pid 255769:tid 255915] [client 216.244.66.229:54006] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "megaroteiros.com.br"] [uri "/wp-content/uploads/2015/07/tam.png"] [unique_id "al9LCLxMYwyVGnfuwsKFBQAAA7M"]
[Tue Jul 21 07:33:44.303970 2026] [security2:error] [pid 255769:tid 255847] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LCLxMYwyVGnfuwsKFBgAD-E0"]
[Tue Jul 21 07:33:44.304120 2026] [security2:error] [pid 255769:tid 255984] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LCLxMYwyVGnfuwsKFBgAD-E0"]
[Tue Jul 21 07:33:44.342136 2026] [security2:error] [pid 255769:tid 256004] [client 180.153.236.67:51211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.treeoflifehealth.online"] [uri "/"] [unique_id "al9LCLxMYwyVGnfuwsKFCAAABAo"], referer: http://www.treeoflifehealth.online/
[Tue Jul 21 07:33:44.342244 2026] [security2:error] [pid 255769:tid 256004] [client 180.153.236.67:51211] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.treeoflifehealth.online"] [uri "/"] [unique_id "al9LCLxMYwyVGnfuwsKFCAAABAo"], referer: http://www.treeoflifehealth.online/
[Tue Jul 21 07:33:44.411389 2026] [security2:error] [pid 255769:tid 255957] [client 74.248.121.109:2066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.121.248.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "issimastore.com.issima.net.br"] [uri "/api.php"] [unique_id "al9LCLxMYwyVGnfuwsKFCgAAA90"]
[Tue Jul 21 07:33:44.502214 2026] [security2:error] [pid 254995:tid 255136] [client 20.151.10.161:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/xwpg.php"] [unique_id "al9LCP7v0rlcEGmVraEqUQAAAyk"]
[Tue Jul 21 07:33:44.653763 2026] [security2:error] [pid 255769:tid 256010] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9LCLxMYwyVGnfuwsKFDgAABBA"]
[Tue Jul 21 07:33:44.771752 2026] [security2:error] [pid 255769:tid 256018] [client 122.129.67.13:59594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LB7xMYwyVGnfuwsKE8QAABBg"]
[Tue Jul 21 07:33:44.895821 2026] [proxy:error] [pid 254995:tid 255224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:44.895899 2026] [proxy_http:error] [pid 254995:tid 255224] [client 20.151.10.161:57458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:44.896551 2026] [proxy:error] [pid 254995:tid 255224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:44.896587 2026] [proxy_http:error] [pid 254995:tid 255224] [client 20.151.10.161:57458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:44.937146 2026] [security2:error] [pid 254995:tid 254996] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9LCP7v0rlcEGmVraEqVwADQQA"]
[Tue Jul 21 07:33:44.977313 2026] [security2:error] [pid 254995:tid 255028] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/media.php"] [unique_id "al9LCP7v0rlcEGmVraEqWAADLyA"]
[Tue Jul 21 07:33:45.007098 2026] [security2:error] [pid 254995:tid 255045] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/images.php"] [unique_id "al9LCf7v0rlcEGmVraEqWQADKjE"]
[Tue Jul 21 07:33:45.022732 2026] [security2:error] [pid 254995:tid 254999] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/gecko.php"] [unique_id "al9LCf7v0rlcEGmVraEqWgADWQM"]
[Tue Jul 21 07:33:45.093170 2026] [security2:error] [pid 254995:tid 255217] [client 85.204.70.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LCP7v0rlcEGmVraEqVgAAA3k"]
[Tue Jul 21 07:33:45.146491 2026] [security2:error] [pid 254995:tid 255274] [client 20.220.225.223:31202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/abcd.php"] [unique_id "al9LCf7v0rlcEGmVraEqXwAAA5g"]
[Tue Jul 21 07:33:45.161020 2026] [security2:error] [pid 255769:tid 255912] [client 213.152.162.104:52174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LCbxMYwyVGnfuwsKFFAAAA7A"]
[Tue Jul 21 07:33:45.161137 2026] [security2:error] [pid 255769:tid 255912] [client 213.152.162.104:52174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LCbxMYwyVGnfuwsKFFAAAA7A"]
[Tue Jul 21 07:33:45.285605 2026] [proxy:error] [pid 255769:tid 255998] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:45.285693 2026] [proxy_http:error] [pid 255769:tid 255998] [client 20.151.10.161:58000] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:45.286588 2026] [proxy:error] [pid 255769:tid 255998] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:45.286631 2026] [proxy_http:error] [pid 255769:tid 255998] [client 20.151.10.161:58000] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:45.377688 2026] [security2:error] [pid 255769:tid 255993] [client 45.8.17.130:58089] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/plugins/options.php"] [unique_id "al9LCbxMYwyVGnfuwsKFGAAABAA"]
[Tue Jul 21 07:33:45.410719 2026] [autoindex:error] [pid 254995:tid 255141] [client 198.235.24.72:60142] AH01276: Cannot serve directory /home2/cla35313/olhobionico.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:45.418691 2026] [security2:error] [pid 255769:tid 255948] [client 59.96.220.140:65187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LCbxMYwyVGnfuwsKFGgAAA9Q"]
[Tue Jul 21 07:33:45.419291 2026] [security2:error] [pid 255769:tid 255948] [client 59.96.220.140:65187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LCbxMYwyVGnfuwsKFGgAAA9Q"]
[Tue Jul 21 07:33:45.509622 2026] [security2:error] [pid 254995:tid 255268] [client 37.140.223.190:45457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LCP7v0rlcEGmVraEqSgAAA5I"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:45.534440 2026] [security2:error] [pid 255769:tid 255967] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9LCbxMYwyVGnfuwsKFHwAAA-c"]
[Tue Jul 21 07:33:45.659608 2026] [security2:error] [pid 255769:tid 256005] [client 20.151.10.161:51327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/waf.php"] [unique_id "al9LCbxMYwyVGnfuwsKFIAAABAs"]
[Tue Jul 21 07:33:45.693250 2026] [security2:error] [pid 255769:tid 255960] [client 20.197.195.24:13156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/f35.php"] [unique_id "al9LCbxMYwyVGnfuwsKFIQAAA-A"]
[Tue Jul 21 07:33:45.741258 2026] [security2:error] [pid 255769:tid 255939] [client 74.7.228.40:48792] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ewfconstrucao.com.br"] [uri "/index.php"] [unique_id "al9LCLxMYwyVGnfuwsKFDAADy0k"]
[Tue Jul 21 07:33:45.808095 2026] [security2:error] [pid 254995:tid 255189] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9LCf7v0rlcEGmVraEqZwAAA14"]
[Tue Jul 21 07:33:45.896266 2026] [security2:error] [pid 254995:tid 255006] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LCf7v0rlcEGmVraEqaQADNgo"]
[Tue Jul 21 07:33:45.896390 2026] [security2:error] [pid 254995:tid 255149] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LCf7v0rlcEGmVraEqaQADNgo"]
[Tue Jul 21 07:33:45.930312 2026] [security2:error] [pid 255769:tid 255899] [client 20.220.225.223:19654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/bscclapb.php"] [unique_id "al9LCbxMYwyVGnfuwsKFJAAAA6M"]
[Tue Jul 21 07:33:45.944031 2026] [security2:error] [pid 254995:tid 255038] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/82.php"] [unique_id "al9LCf7v0rlcEGmVraEqagADhyo"]
[Tue Jul 21 07:33:45.978107 2026] [security2:error] [pid 254995:tid 255044] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/admin.php"] [unique_id "al9LCf7v0rlcEGmVraEqbAADkDA"]
[Tue Jul 21 07:33:46.005529 2026] [security2:error] [pid 254995:tid 255012] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/adminner.php"] [unique_id "al9LCv7v0rlcEGmVraEqbQADORA"]
[Tue Jul 21 07:33:46.015331 2026] [security2:error] [pid 254995:tid 255017] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LCv7v0rlcEGmVraEqbwADZxU"]
[Tue Jul 21 07:33:46.015550 2026] [security2:error] [pid 254995:tid 255198] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LCv7v0rlcEGmVraEqbwADZxU"]
[Tue Jul 21 07:33:46.019491 2026] [security2:error] [pid 255769:tid 255908] [client 20.151.10.161:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/xstelth.php"] [unique_id "al9LCrxMYwyVGnfuwsKFJgAAA6w"]
[Tue Jul 21 07:33:46.081447 2026] [security2:error] [pid 255769:tid 256016] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9LCrxMYwyVGnfuwsKFKAAABBY"]
[Tue Jul 21 07:33:46.174753 2026] [security2:error] [pid 255769:tid 255980] [client 20.220.225.223:49556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/2352356666.php"] [unique_id "al9LCrxMYwyVGnfuwsKFKQAAA_Q"]
[Tue Jul 21 07:33:46.190685 2026] [security2:error] [pid 255769:tid 255852] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LCrxMYwyVGnfuwsKFKgAD21I"]
[Tue Jul 21 07:33:46.190852 2026] [security2:error] [pid 255769:tid 255955] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LCrxMYwyVGnfuwsKFKgAD21I"]
[Tue Jul 21 07:33:46.206620 2026] [security2:error] [pid 255769:tid 255953] [client 20.220.225.223:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/dr.php"] [unique_id "al9LCrxMYwyVGnfuwsKFLQAAA9k"]
[Tue Jul 21 07:33:46.355880 2026] [security2:error] [pid 255769:tid 255973] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9LCrxMYwyVGnfuwsKFLwAAA-0"]
[Tue Jul 21 07:33:46.364774 2026] [security2:error] [pid 255769:tid 256001] [client 20.151.10.161:58009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-links.php"] [unique_id "al9LCrxMYwyVGnfuwsKFMQAABAc"]
[Tue Jul 21 07:33:46.381053 2026] [security2:error] [pid 254995:tid 255173] [client 139.167.225.182:49864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LCv7v0rlcEGmVraEqcgAAA04"]
[Tue Jul 21 07:33:46.381155 2026] [security2:error] [pid 254995:tid 255173] [client 139.167.225.182:49864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LCv7v0rlcEGmVraEqcgAAA04"]
[Tue Jul 21 07:33:46.541800 2026] [security2:error] [pid 254995:tid 255014] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/admin.php"] [unique_id "al9LCv7v0rlcEGmVraEqdgADdBI"]
[Tue Jul 21 07:33:46.608005 2026] [security2:error] [pid 254995:tid 255024] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/k.php"] [unique_id "al9LCv7v0rlcEGmVraEqeQADQhw"]
[Tue Jul 21 07:33:46.624141 2026] [security2:error] [pid 254995:tid 255091] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/blurbs.php"] [unique_id "al9LCv7v0rlcEGmVraEqegADJl8"]
[Tue Jul 21 07:33:46.629717 2026] [security2:error] [pid 255769:tid 255927] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9LCrxMYwyVGnfuwsKFNgAAA78"]
[Tue Jul 21 07:33:46.672138 2026] [security2:error] [pid 254995:tid 255172] [client 20.151.10.161:51286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9LCv7v0rlcEGmVraEqewAAA00"]
[Tue Jul 21 07:33:46.681127 2026] [security2:error] [pid 255769:tid 255906] [client 45.8.17.144:34581] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/themes/panel.php"] [unique_id "al9LCrxMYwyVGnfuwsKFNwAAA6o"]
[Tue Jul 21 07:33:46.697863 2026] [security2:error] [pid 254995:tid 255055] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/bajah.php"] [unique_id "al9LCv7v0rlcEGmVraEqfAADXTs"]
[Tue Jul 21 07:33:46.714418 2026] [security2:error] [pid 254995:tid 255051] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/a.php"] [unique_id "al9LCv7v0rlcEGmVraEqfQADPDc"]
[Tue Jul 21 07:33:46.738472 2026] [security2:error] [pid 254995:tid 255015] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/edit.php"] [unique_id "al9LCv7v0rlcEGmVraEqfgADlBM"]
[Tue Jul 21 07:33:46.754856 2026] [security2:error] [pid 254995:tid 255048] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/hosty.php"] [unique_id "al9LCv7v0rlcEGmVraEqfwADPjQ"]
[Tue Jul 21 07:33:46.772274 2026] [security2:error] [pid 254995:tid 255119] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/k.php"] [unique_id "al9LCv7v0rlcEGmVraEqgAADmXs"]
[Tue Jul 21 07:33:46.787646 2026] [security2:error] [pid 254995:tid 255056] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/aaa.php"] [unique_id "al9LCv7v0rlcEGmVraEqgQADXzw"]
[Tue Jul 21 07:33:46.828265 2026] [security2:error] [pid 254995:tid 255064] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/file5.php"] [unique_id "al9LCv7v0rlcEGmVraEqggADbUQ"]
[Tue Jul 21 07:33:46.856799 2026] [security2:error] [pid 254995:tid 255072] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/222.php"] [unique_id "al9LCv7v0rlcEGmVraEqgwADNUw"]
[Tue Jul 21 07:33:46.902765 2026] [security2:error] [pid 255769:tid 255900] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9LCrxMYwyVGnfuwsKFOwAAA6Q"]
[Tue Jul 21 07:33:46.909798 2026] [security2:error] [pid 255769:tid 255811] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/test.php"] [unique_id "al9LCrxMYwyVGnfuwsKFPAAEGyk"]
[Tue Jul 21 07:33:46.942985 2026] [security2:error] [pid 254995:tid 255070] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/aaa.php"] [unique_id "al9LCv7v0rlcEGmVraEqhgADcEo"]
[Tue Jul 21 07:33:46.982680 2026] [security2:error] [pid 254995:tid 255068] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/11.php"] [unique_id "al9LCv7v0rlcEGmVraEqhwADSkg"]
[Tue Jul 21 07:33:47.002797 2026] [security2:error] [pid 254995:tid 255065] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/mac.php"] [unique_id "al9LC_7v0rlcEGmVraEqiAADaEU"]
[Tue Jul 21 07:33:47.009627 2026] [security2:error] [pid 254995:tid 255278] [client 20.151.10.161:57366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reabfit.com.br"] [uri "/aaa.php"] [unique_id "al9LC_7v0rlcEGmVraEqiQAAA5w"]
[Tue Jul 21 07:33:47.176260 2026] [security2:error] [pid 255769:tid 255916] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9LC7xMYwyVGnfuwsKFPgAAA7Q"]
[Tue Jul 21 07:33:47.249810 2026] [security2:error] [pid 254995:tid 255151] [client 20.220.225.223:19972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/else1.php"] [unique_id "al9LC_7v0rlcEGmVraEqjgAAAzg"]
[Tue Jul 21 07:33:47.255539 2026] [security2:error] [pid 254995:tid 255185] [client 103.162.129.114:62507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LC_7v0rlcEGmVraEqjwAAA1o"]
[Tue Jul 21 07:33:47.255656 2026] [security2:error] [pid 254995:tid 255185] [client 103.162.129.114:62507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LC_7v0rlcEGmVraEqjwAAA1o"]
[Tue Jul 21 07:33:47.294999 2026] [security2:error] [pid 254995:tid 255215] [client 172.245.102.41:23197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LC_7v0rlcEGmVraEqkAAAA3c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:47.448598 2026] [security2:error] [pid 255769:tid 255971] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9LC7xMYwyVGnfuwsKFRAAAA-s"]
[Tue Jul 21 07:33:47.452354 2026] [security2:error] [pid 255769:tid 255967] [client 109.248.148.246:38406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LC7xMYwyVGnfuwsKFRQAAA-c"]
[Tue Jul 21 07:33:47.452423 2026] [security2:error] [pid 255769:tid 255967] [client 109.248.148.246:38406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LC7xMYwyVGnfuwsKFRQAAA-c"]
[Tue Jul 21 07:33:47.489208 2026] [security2:error] [pid 255769:tid 255977] [client 20.220.225.223:49799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/2x.php"] [unique_id "al9LC7xMYwyVGnfuwsKFSgAAA_E"]
[Tue Jul 21 07:33:47.550314 2026] [security2:error] [pid 255769:tid 255960] [client 20.220.225.223:49828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/pn.php"] [unique_id "al9LC7xMYwyVGnfuwsKFTAAAA-A"]
[Tue Jul 21 07:33:47.589770 2026] [security2:error] [pid 254995:tid 255071] [remote 160.187.68.132:45396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/wp-login.php"] [unique_id "al9LC_7v0rlcEGmVraEqlAADm0s"]
[Tue Jul 21 07:33:47.654217 2026] [security2:error] [pid 255769:tid 255908] [client 20.220.225.223:31173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/xyn.php"] [unique_id "al9LC7xMYwyVGnfuwsKFUgAAA6w"]
[Tue Jul 21 07:33:47.655720 2026] [security2:error] [pid 255769:tid 255986] [client 117.251.86.144:34536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LC7xMYwyVGnfuwsKFUQAAA_o"]
[Tue Jul 21 07:33:47.655807 2026] [security2:error] [pid 255769:tid 255986] [client 117.251.86.144:34536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LC7xMYwyVGnfuwsKFUQAAA_o"]
[Tue Jul 21 07:33:47.672928 2026] [security2:error] [pid 255769:tid 255963] [client 20.197.195.24:13060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-load.php"] [unique_id "al9LC7xMYwyVGnfuwsKFUwAAA-M"]
[Tue Jul 21 07:33:47.723375 2026] [security2:error] [pid 255769:tid 255980] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9LC7xMYwyVGnfuwsKFVAAAA_Q"]
[Tue Jul 21 07:33:47.773719 2026] [security2:error] [pid 255769:tid 255988] [client 173.252.95.58:49248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LC7xMYwyVGnfuwsKFVwAAA_w"]
[Tue Jul 21 07:33:47.864339 2026] [security2:error] [pid 254995:tid 255033] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/chosen.php"] [unique_id "al9LC_7v0rlcEGmVraEqmAADUyU"]
[Tue Jul 21 07:33:47.881060 2026] [security2:error] [pid 254995:tid 255052] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/cream1.php"] [unique_id "al9LC_7v0rlcEGmVraEqmQADgDg"]
[Tue Jul 21 07:33:47.909995 2026] [autoindex:error] [pid 254995:tid 255059] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:47.938293 2026] [autoindex:error] [pid 254995:tid 255076] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:47.985230 2026] [security2:error] [pid 254995:tid 255079] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/dr.php"] [unique_id "al9LC_7v0rlcEGmVraEqnQADQVM"]
[Tue Jul 21 07:33:47.996380 2026] [security2:error] [pid 255769:tid 255950] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9LC7xMYwyVGnfuwsKFXAAAA9Y"]
[Tue Jul 21 07:33:48.002140 2026] [security2:error] [pid 254995:tid 255118] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/x.php"] [unique_id "al9LDP7v0rlcEGmVraEqngADL3o"]
[Tue Jul 21 07:33:48.086294 2026] [security2:error] [pid 255769:tid 255985] [client 45.8.17.116:31969] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Requests/Response/Response/multisite-setup.php"] [unique_id "al9LDLxMYwyVGnfuwsKFXgAAA_k"]
[Tue Jul 21 07:33:48.270463 2026] [security2:error] [pid 255769:tid 256004] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9LDLxMYwyVGnfuwsKFYAAABAo"]
[Tue Jul 21 07:33:48.345602 2026] [security2:error] [pid 255769:tid 255915] [client 173.252.95.14:57822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LDLxMYwyVGnfuwsKFYQAAA7M"]
[Tue Jul 21 07:33:48.543806 2026] [security2:error] [pid 255769:tid 255946] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9LDLxMYwyVGnfuwsKFaAAAA9I"]
[Tue Jul 21 07:33:48.771537 2026] [security2:error] [pid 255769:tid 256007] [client 152.59.154.239:65384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDLxMYwyVGnfuwsKFagAABA0"]
[Tue Jul 21 07:33:48.776276 2026] [security2:error] [pid 255769:tid 256007] [client 152.59.154.239:65384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDLxMYwyVGnfuwsKFagAABA0"]
[Tue Jul 21 07:33:48.810972 2026] [security2:error] [pid 255769:tid 255958] [client 122.186.204.214:62676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LDLxMYwyVGnfuwsKFbQAAA94"]
[Tue Jul 21 07:33:48.811085 2026] [security2:error] [pid 255769:tid 255958] [client 122.186.204.214:62676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LDLxMYwyVGnfuwsKFbQAAA94"]
[Tue Jul 21 07:33:48.818070 2026] [security2:error] [pid 255769:tid 256006] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9LDLxMYwyVGnfuwsKFbgAABAw"]
[Tue Jul 21 07:33:48.880498 2026] [security2:error] [pid 254995:tid 255116] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/155.php"] [unique_id "al9LDP7v0rlcEGmVraEqqQADM3g"]
[Tue Jul 21 07:33:49.082528 2026] [security2:error] [pid 255769:tid 255899] [client 20.220.225.223:49817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-wpbak.php"] [unique_id "al9LDbxMYwyVGnfuwsKFcwAAA6M"]
[Tue Jul 21 07:33:49.090220 2026] [security2:error] [pid 254995:tid 255222] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9LDf7v0rlcEGmVraEqrwAAA34"]
[Tue Jul 21 07:33:49.119586 2026] [security2:error] [pid 254995:tid 255141] [client 173.252.95.16:50228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LDP7v0rlcEGmVraEqqwAAAy4"]
[Tue Jul 21 07:33:49.348079 2026] [security2:error] [pid 255769:tid 255907] [client 173.24.185.52:61721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LDbxMYwyVGnfuwsKFdQAAA6s"]
[Tue Jul 21 07:33:49.348219 2026] [security2:error] [pid 255769:tid 255907] [client 173.24.185.52:61721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LDbxMYwyVGnfuwsKFdQAAA6s"]
[Tue Jul 21 07:33:49.365647 2026] [security2:error] [pid 254995:tid 255272] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9LDf7v0rlcEGmVraEqswAAA5Y"]
[Tue Jul 21 07:33:49.565442 2026] [security2:error] [pid 255769:tid 256015] [client 20.197.195.24:48844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/xyn.php"] [unique_id "al9LDbxMYwyVGnfuwsKFeQAABBU"]
[Tue Jul 21 07:33:49.638240 2026] [security2:error] [pid 255769:tid 255956] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "laisdocarmoguimaraes1782183946914.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9LDbxMYwyVGnfuwsKFewAAA9w"]
[Tue Jul 21 07:33:49.640446 2026] [security2:error] [pid 255769:tid 255902] [client 20.206.105.145:38922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/25d653587fdfd1.php"] [unique_id "al9LDbxMYwyVGnfuwsKFfAAAA6Y"]
[Tue Jul 21 07:33:49.765549 2026] [security2:error] [pid 254995:tid 255042] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LDf7v0rlcEGmVraEqugADQi4"]
[Tue Jul 21 07:33:49.765704 2026] [security2:error] [pid 254995:tid 255161] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LDf7v0rlcEGmVraEqugADQi4"]
[Tue Jul 21 07:33:49.781121 2026] [security2:error] [pid 255769:tid 255939] [client 122.162.144.145:14032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LDbxMYwyVGnfuwsKFfwAAA8s"]
[Tue Jul 21 07:33:49.781266 2026] [security2:error] [pid 255769:tid 255939] [client 122.162.144.145:14032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LDbxMYwyVGnfuwsKFfwAAA8s"]
[Tue Jul 21 07:33:49.790245 2026] [security2:error] [pid 255769:tid 255957] [client 45.8.17.124:25027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/data.php"] [unique_id "al9LDbxMYwyVGnfuwsKFgQAAA90"]
[Tue Jul 21 07:33:49.822372 2026] [security2:error] [pid 255769:tid 256028] [client 47.128.26.55:52884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nrfilmes.com"] [uri "/robots.txt"] [unique_id "al9LDbxMYwyVGnfuwsKFggAABCI"]
[Tue Jul 21 07:33:50.165879 2026] [security2:error] [pid 255769:tid 255804] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDrxMYwyVGnfuwsKFhAADySI"]
[Tue Jul 21 07:33:50.166000 2026] [security2:error] [pid 255769:tid 255937] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDrxMYwyVGnfuwsKFhAADySI"]
[Tue Jul 21 07:33:50.218694 2026] [security2:error] [pid 254995:tid 255112] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ops.php"] [unique_id "al9LDv7v0rlcEGmVraEqxAADNXQ"]
[Tue Jul 21 07:33:50.272106 2026] [security2:error] [pid 254995:tid 255104] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/file31.php"] [unique_id "al9LDv7v0rlcEGmVraEqyAADIWw"]
[Tue Jul 21 07:33:50.287276 2026] [security2:error] [pid 254995:tid 255097] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/file6.php"] [unique_id "al9LDv7v0rlcEGmVraEqyQADcGU"]
[Tue Jul 21 07:33:50.318276 2026] [autoindex:error] [pid 254995:tid 255026] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:50.354514 2026] [security2:error] [pid 254995:tid 255122] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/adminfuns.php"] [unique_id "al9LDv7v0rlcEGmVraEqzQADk34"]
[Tue Jul 21 07:33:50.368282 2026] [security2:error] [pid 255769:tid 256022] [client 45.251.232.145:53907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDrxMYwyVGnfuwsKFhwAABBw"]
[Tue Jul 21 07:33:50.368384 2026] [security2:error] [pid 255769:tid 256022] [client 45.251.232.145:53907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDrxMYwyVGnfuwsKFhwAABBw"]
[Tue Jul 21 07:33:50.373700 2026] [security2:error] [pid 254995:tid 255100] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/goods.php"] [unique_id "al9LDv7v0rlcEGmVraEqzgADMWg"]
[Tue Jul 21 07:33:50.394106 2026] [security2:error] [pid 255769:tid 256003] [client 103.106.20.201:55614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDrxMYwyVGnfuwsKFiAAABAk"]
[Tue Jul 21 07:33:50.394179 2026] [security2:error] [pid 255769:tid 256003] [client 103.106.20.201:55614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LDrxMYwyVGnfuwsKFiAAABAk"]
[Tue Jul 21 07:33:50.493094 2026] [autoindex:error] [pid 255769:tid 255973] [client 20.197.195.24:48854] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:50.575254 2026] [autoindex:error] [pid 255769:tid 255930] [client 20.197.195.24:48854] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:50.599187 2026] [security2:error] [pid 255769:tid 255998] [client 20.197.195.24:48854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ccc.php"] [unique_id "al9LDrxMYwyVGnfuwsKFjwAABAQ"]
[Tue Jul 21 07:33:50.622639 2026] [security2:error] [pid 254995:tid 255185] [client 20.220.225.223:48130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/kq1.php"] [unique_id "al9LDv7v0rlcEGmVraEq0AAAA1o"]
[Tue Jul 21 07:33:50.872510 2026] [security2:error] [pid 254995:tid 255223] [client 20.220.225.223:44230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/tkikikoko.php"] [unique_id "al9LDv7v0rlcEGmVraEq1QAAA38"]
[Tue Jul 21 07:33:50.972019 2026] [security2:error] [pid 254995:tid 255105] [remote 13.41.15.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.15.41.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "extrapro21.com"] [uri "/wp-login.php"] [unique_id "al9LDv7v0rlcEGmVraEq1gADnW0"]
[Tue Jul 21 07:33:51.044911 2026] [security2:error] [pid 255769:tid 255959] [client 37.140.223.68:42471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LD7xMYwyVGnfuwsKFkwAAA98"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:51.218685 2026] [security2:error] [pid 255769:tid 256002] [client 154.192.233.199:60527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LD7xMYwyVGnfuwsKFlwAABAg"]
[Tue Jul 21 07:33:51.218800 2026] [security2:error] [pid 255769:tid 256002] [client 154.192.233.199:60527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LD7xMYwyVGnfuwsKFlwAABAg"]
[Tue Jul 21 07:33:51.263407 2026] [access_compat:error] [pid 255769:tid 255982] [client 162.241.63.68:38972] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:33:51.665732 2026] [security2:error] [pid 255769:tid 255990] [client 20.220.225.223:31176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/byp8.php"] [unique_id "al9LD7xMYwyVGnfuwsKFnQAAA_4"]
[Tue Jul 21 07:33:51.739946 2026] [security2:error] [pid 254995:tid 255005] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/100.php"] [unique_id "al9LD_7v0rlcEGmVraEq4QADOwk"]
[Tue Jul 21 07:33:51.798035 2026] [security2:error] [pid 255769:tid 255907] [client 20.197.195.24:13128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/w.php"] [unique_id "al9LD7xMYwyVGnfuwsKFnwAAA6s"]
[Tue Jul 21 07:33:51.825308 2026] [security2:error] [pid 255769:tid 255967] [client 117.217.38.194:58435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LD7xMYwyVGnfuwsKFoQAAA-c"]
[Tue Jul 21 07:33:51.826019 2026] [security2:error] [pid 255769:tid 255967] [client 117.217.38.194:58435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LD7xMYwyVGnfuwsKFoQAAA-c"]
[Tue Jul 21 07:33:51.981448 2026] [security2:error] [pid 255769:tid 255923] [client 45.8.17.62:26763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/crop/crop/sitemap-generator.php"] [unique_id "al9LD7xMYwyVGnfuwsKFpwAAA7s"]
[Tue Jul 21 07:33:52.031184 2026] [security2:error] [pid 255769:tid 255902] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LD7xMYwyVGnfuwsKFpgADpjo"]
[Tue Jul 21 07:33:52.094978 2026] [security2:error] [pid 254995:tid 255134] [client 175.45.70.82:56658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LEP7v0rlcEGmVraEq5QAAAyc"]
[Tue Jul 21 07:33:52.095116 2026] [security2:error] [pid 254995:tid 255134] [client 175.45.70.82:56658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LEP7v0rlcEGmVraEq5QAAAyc"]
[Tue Jul 21 07:33:52.559726 2026] [security2:error] [pid 255769:tid 256010] [client 20.206.105.145:39248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wefile.php"] [unique_id "al9LELxMYwyVGnfuwsKFrAAABBA"]
[Tue Jul 21 07:33:52.779333 2026] [security2:error] [pid 255769:tid 255973] [client 62.102.148.164:35950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LELxMYwyVGnfuwsKFsQAAA-0"]
[Tue Jul 21 07:33:52.779425 2026] [security2:error] [pid 255769:tid 255973] [client 62.102.148.164:35950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LELxMYwyVGnfuwsKFsQAAA-0"]
[Tue Jul 21 07:33:52.901286 2026] [security2:error] [pid 255769:tid 255930] [client 20.220.225.223:48134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/dr.php"] [unique_id "al9LELxMYwyVGnfuwsKFtAAAA8I"]
[Tue Jul 21 07:33:52.947479 2026] [security2:error] [pid 255769:tid 255993] [client 20.220.225.223:48154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/zzz.php"] [unique_id "al9LELxMYwyVGnfuwsKFtgAABAA"]
[Tue Jul 21 07:33:52.965150 2026] [security2:error] [pid 254995:tid 254997] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/about.php"] [unique_id "al9LEP7v0rlcEGmVraEq8wADcgE"]
[Tue Jul 21 07:33:53.087533 2026] [security2:error] [pid 255769:tid 256005] [client 45.8.17.135:31279] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Requests/Transport/Transport/spam-filter.php"] [unique_id "al9LEbxMYwyVGnfuwsKFvwAABAs"]
[Tue Jul 21 07:33:53.113733 2026] [security2:error] [pid 255769:tid 256009] [client 103.174.34.15:65288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LEbxMYwyVGnfuwsKFwgAABA8"]
[Tue Jul 21 07:33:53.113836 2026] [security2:error] [pid 255769:tid 256009] [client 103.174.34.15:65288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LEbxMYwyVGnfuwsKFwgAABA8"]
[Tue Jul 21 07:33:53.187350 2026] [security2:error] [pid 255769:tid 255885] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LEbxMYwyVGnfuwsKFyQAD5nM"]
[Tue Jul 21 07:33:53.187507 2026] [security2:error] [pid 255769:tid 255966] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LEbxMYwyVGnfuwsKFyQAD5nM"]
[Tue Jul 21 07:33:53.193241 2026] [security2:error] [pid 255769:tid 255968] [client 20.197.195.24:13134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9LEbxMYwyVGnfuwsKFygAAA-g"]
[Tue Jul 21 07:33:53.491575 2026] [security2:error] [pid 254995:tid 255041] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/about.php"] [unique_id "al9LEf7v0rlcEGmVraErMwADjC0"]
[Tue Jul 21 07:33:53.512699 2026] [security2:error] [pid 254995:tid 255037] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/admin.php"] [unique_id "al9LEf7v0rlcEGmVraErNAADbCk"]
[Tue Jul 21 07:33:53.527983 2026] [security2:error] [pid 254995:tid 254996] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/admin.php"] [unique_id "al9LEf7v0rlcEGmVraErNQADjQA"]
[Tue Jul 21 07:33:53.569781 2026] [security2:error] [pid 254995:tid 255028] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/themes.php"] [unique_id "al9LEf7v0rlcEGmVraErNgADiSA"]
[Tue Jul 21 07:33:53.596797 2026] [autoindex:error] [pid 254995:tid 255045] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:53.846731 2026] [security2:error] [pid 254995:tid 255001] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LEf7v0rlcEGmVraErQQADnAU"]
[Tue Jul 21 07:33:53.846933 2026] [security2:error] [pid 254995:tid 255278] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LEf7v0rlcEGmVraErQQADnAU"]
[Tue Jul 21 07:33:53.896785 2026] [security2:error] [pid 254995:tid 255060] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/.well-known/about.php"] [unique_id "al9LEf7v0rlcEGmVraErRAADNkA"]
[Tue Jul 21 07:33:53.913168 2026] [security2:error] [pid 254995:tid 255054] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9LEf7v0rlcEGmVraErRQADXDo"]
[Tue Jul 21 07:33:53.941299 2026] [security2:error] [pid 254995:tid 255006] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wefile.php"] [unique_id "al9LEf7v0rlcEGmVraErRwADSQo"]
[Tue Jul 21 07:33:53.956598 2026] [security2:error] [pid 254995:tid 255038] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9LEf7v0rlcEGmVraErSAADbyo"]
[Tue Jul 21 07:33:54.048128 2026] [security2:error] [pid 255769:tid 255909] [client 20.197.195.24:13067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/FWAZ.php"] [unique_id "al9LErxMYwyVGnfuwsKF5QAAA60"]
[Tue Jul 21 07:33:54.151404 2026] [autoindex:error] [pid 254995:tid 255012] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:54.187298 2026] [security2:error] [pid 255769:tid 255999] [client 45.8.17.106:40875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/db-status.php"] [unique_id "al9LErxMYwyVGnfuwsKF6AAABAU"]
[Tue Jul 21 07:33:54.292582 2026] [autoindex:error] [pid 254995:tid 255017] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:54.311942 2026] [security2:error] [pid 254995:tid 255040] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9LEv7v0rlcEGmVraErUQADciw"]
[Tue Jul 21 07:33:54.328119 2026] [security2:error] [pid 254995:tid 255032] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/8.php"] [unique_id "al9LEv7v0rlcEGmVraErUwADJCQ"]
[Tue Jul 21 07:33:54.595222 2026] [security2:error] [pid 254995:tid 255050] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9LEv7v0rlcEGmVraErXAADXTY"]
[Tue Jul 21 07:33:55.028179 2026] [security2:error] [pid 255769:tid 255810] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LE7xMYwyVGnfuwsKF8QADsCg"]
[Tue Jul 21 07:33:55.028347 2026] [security2:error] [pid 255769:tid 255912] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LE7xMYwyVGnfuwsKF8QADsCg"]
[Tue Jul 21 07:33:55.049963 2026] [security2:error] [pid 254995:tid 255119] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/f6.php"] [unique_id "al9LE_7v0rlcEGmVraErYQADSns"]
[Tue Jul 21 07:33:55.072576 2026] [security2:error] [pid 254995:tid 255064] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/inputs.php"] [unique_id "al9LE_7v0rlcEGmVraErYwADVUQ"]
[Tue Jul 21 07:33:55.087618 2026] [security2:error] [pid 254995:tid 255030] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/inputs.php"] [unique_id "al9LE_7v0rlcEGmVraErZAADkyI"]
[Tue Jul 21 07:33:55.102909 2026] [security2:error] [pid 254995:tid 255072] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/classwithtostring.php"] [unique_id "al9LE_7v0rlcEGmVraErZgADPkw"]
[Tue Jul 21 07:33:55.172064 2026] [rewrite:error] [pid 255769:tid 255951] [client 187.49.76.218:17473] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:33:55.173207 2026] [rewrite:error] [pid 255769:tid 255948] [client 187.49.76.218:17505] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:33:55.179926 2026] [security2:error] [pid 254995:tid 255221] [client 20.220.225.223:49833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wicked.php"] [unique_id "al9LE_7v0rlcEGmVraEraQAAA30"]
[Tue Jul 21 07:33:55.192500 2026] [rewrite:error] [pid 254995:tid 255264] [client 187.49.76.218:17633] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:33:55.395586 2026] [security2:error] [pid 255769:tid 255960] [client 45.8.17.146:26419] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/SimplePie/XML/XML/sitemap-generator.php"] [unique_id "al9LE7xMYwyVGnfuwsKF-gAAA-A"]
[Tue Jul 21 07:33:55.711544 2026] [security2:error] [pid 255769:tid 255963] [client 20.197.195.24:13142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/miru1.php"] [unique_id "al9LE7xMYwyVGnfuwsKGAwAAA-M"]
[Tue Jul 21 07:33:55.880626 2026] [security2:error] [pid 254995:tid 255198] [client 136.144.33.110:24355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LE_7v0rlcEGmVraEreAAAA2c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:55.891294 2026] [security2:error] [pid 254995:tid 255265] [client 82.102.28.107:54066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LE_7v0rlcEGmVraEreQAAA48"]
[Tue Jul 21 07:33:55.891399 2026] [security2:error] [pid 254995:tid 255265] [client 82.102.28.107:54066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LE_7v0rlcEGmVraEreQAAA48"]
[Tue Jul 21 07:33:56.003630 2026] [security2:error] [pid 254995:tid 255052] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9LFP7v0rlcEGmVraErewADLTg"]
[Tue Jul 21 07:33:56.011465 2026] [proxy:error] [pid 254995:tid 255137] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:56.011532 2026] [proxy_http:error] [pid 254995:tid 255137] [client 20.206.105.145:38963] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:56.012195 2026] [proxy:error] [pid 254995:tid 255137] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:56.012225 2026] [proxy_http:error] [pid 254995:tid 255137] [client 20.206.105.145:38963] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:56.033734 2026] [security2:error] [pid 254995:tid 255219] [client 122.129.67.13:59014] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LFP7v0rlcEGmVraErfQAAA3s"]
[Tue Jul 21 07:33:56.033905 2026] [security2:error] [pid 254995:tid 255219] [client 122.129.67.13:59014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LFP7v0rlcEGmVraErfQAAA3s"]
[Tue Jul 21 07:33:56.382304 2026] [security2:error] [pid 254995:tid 255086] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-blog.php"] [unique_id "al9LFP7v0rlcEGmVraErgAADI1o"]
[Tue Jul 21 07:33:56.410354 2026] [autoindex:error] [pid 254995:tid 255118] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:56.426452 2026] [security2:error] [pid 255769:tid 255886] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGCgAEB3Q"]
[Tue Jul 21 07:33:56.426658 2026] [security2:error] [pid 255769:tid 256001] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGCgAEB3Q"]
[Tue Jul 21 07:33:56.428166 2026] [security2:error] [pid 254995:tid 255123] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9LFP7v0rlcEGmVraErgwADnH8"]
[Tue Jul 21 07:33:56.444167 2026] [security2:error] [pid 254995:tid 255067] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ms-edit.php"] [unique_id "al9LFP7v0rlcEGmVraErhAADNkc"]
[Tue Jul 21 07:33:56.460500 2026] [security2:error] [pid 254995:tid 255092] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9LFP7v0rlcEGmVraErhQADXGA"]
[Tue Jul 21 07:33:56.572525 2026] [security2:error] [pid 255769:tid 255892] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGCwAEGno"]
[Tue Jul 21 07:33:56.572697 2026] [security2:error] [pid 255769:tid 256020] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGCwAEGno"]
[Tue Jul 21 07:33:56.691865 2026] [security2:error] [pid 255769:tid 255799] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGEAADph0"]
[Tue Jul 21 07:33:56.692076 2026] [security2:error] [pid 255769:tid 255902] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGEAADph0"]
[Tue Jul 21 07:33:56.870022 2026] [autoindex:error] [pid 254995:tid 255082] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:56.889374 2026] [security2:error] [pid 255769:tid 255931] [client 45.8.17.137:59581] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/test.php"] [unique_id "al9LFLxMYwyVGnfuwsKGEQAAA8M"]
[Tue Jul 21 07:33:56.920493 2026] [security2:error] [pid 255769:tid 255987] [client 139.167.225.182:50499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGEgAAA_s"]
[Tue Jul 21 07:33:56.922182 2026] [security2:error] [pid 255769:tid 255987] [client 139.167.225.182:50499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LFLxMYwyVGnfuwsKGEgAAA_s"]
[Tue Jul 21 07:33:57.217304 2026] [security2:error] [pid 254995:tid 255200] [client 20.197.195.24:13161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/aa.php"] [unique_id "al9LFf7v0rlcEGmVraErkgAAA2k"]
[Tue Jul 21 07:33:57.319454 2026] [security2:error] [pid 254995:tid 255002] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9LFf7v0rlcEGmVraErkwADkgY"]
[Tue Jul 21 07:33:57.740724 2026] [autoindex:error] [pid 254995:tid 255058] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:57.802717 2026] [security2:error] [pid 255769:tid 256011] [client 37.140.223.49:45739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LFLxMYwyVGnfuwsKGDwAABBE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:33:57.815744 2026] [security2:error] [pid 254995:tid 255271] [client 103.162.129.114:62944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LFf7v0rlcEGmVraErmwAAA5U"]
[Tue Jul 21 07:33:57.815898 2026] [security2:error] [pid 254995:tid 255271] [client 103.162.129.114:62944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LFf7v0rlcEGmVraErmwAAA5U"]
[Tue Jul 21 07:33:57.890274 2026] [security2:error] [pid 255769:tid 256005] [client 109.248.148.246:38876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9LFbxMYwyVGnfuwsKGHwAABAs"]
[Tue Jul 21 07:33:57.890383 2026] [security2:error] [pid 255769:tid 256005] [client 109.248.148.246:38876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9LFbxMYwyVGnfuwsKGHwAABAs"]
[Tue Jul 21 07:33:57.917467 2026] [autoindex:error] [pid 254995:tid 255042] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:57.936067 2026] [security2:error] [pid 254995:tid 255111] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/abcd.php"] [unique_id "al9LFf7v0rlcEGmVraEroAADdnM"]
[Tue Jul 21 07:33:57.985191 2026] [security2:error] [pid 255769:tid 255943] [client 82.102.28.107:54078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LFbxMYwyVGnfuwsKGIQAAA88"]
[Tue Jul 21 07:33:57.985288 2026] [security2:error] [pid 255769:tid 255943] [client 82.102.28.107:54078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LFbxMYwyVGnfuwsKGIQAAA88"]
[Tue Jul 21 07:33:58.012153 2026] [security2:error] [pid 254995:tid 255103] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/file15.php"] [unique_id "al9LFv7v0rlcEGmVraEroQADSms"]
[Tue Jul 21 07:33:58.056503 2026] [security2:error] [pid 254995:tid 255115] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/jp.php"] [unique_id "al9LFv7v0rlcEGmVraErogADVXc"]
[Tue Jul 21 07:33:58.085050 2026] [security2:error] [pid 254995:tid 255010] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/f35.php"] [unique_id "al9LFv7v0rlcEGmVraErpAADPg4"]
[Tue Jul 21 07:33:58.112080 2026] [security2:error] [pid 254995:tid 255104] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-load.php"] [unique_id "al9LFv7v0rlcEGmVraErqAADbWw"]
[Tue Jul 21 07:33:58.125738 2026] [security2:error] [pid 254995:tid 255144] [client 20.220.225.223:48137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/edit.php"] [unique_id "al9LFv7v0rlcEGmVraErqgAAAzE"]
[Tue Jul 21 07:33:58.127883 2026] [security2:error] [pid 254995:tid 255097] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/xyn.php"] [unique_id "al9LFv7v0rlcEGmVraErqwADd2U"]
[Tue Jul 21 07:33:58.154170 2026] [autoindex:error] [pid 254995:tid 255089] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:58.171455 2026] [security2:error] [pid 254995:tid 255223] [client 20.197.195.24:13106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/122.php"] [unique_id "al9LFv7v0rlcEGmVraErrwAAA38"]
[Tue Jul 21 07:33:58.188433 2026] [security2:error] [pid 254995:tid 255195] [client 45.8.17.60:38515] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/jquery/ui/ui/forum-engine.php"] [unique_id "al9LFv7v0rlcEGmVraErsAAAA2Q"]
[Tue Jul 21 07:33:58.317200 2026] [autoindex:error] [pid 254995:tid 255100] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:33:58.436167 2026] [security2:error] [pid 254995:tid 255011] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ccc.php"] [unique_id "al9LFv7v0rlcEGmVraEruAADWQ8"]
[Tue Jul 21 07:33:58.451807 2026] [security2:error] [pid 254995:tid 255114] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/w.php"] [unique_id "al9LFv7v0rlcEGmVraEruQADZ3Y"]
[Tue Jul 21 07:33:58.457124 2026] [security2:error] [pid 255769:tid 256018] [client 117.251.86.144:50928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LFrxMYwyVGnfuwsKGJQAABBg"]
[Tue Jul 21 07:33:58.457231 2026] [security2:error] [pid 255769:tid 256018] [client 117.251.86.144:50928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LFrxMYwyVGnfuwsKGJQAABBg"]
[Tue Jul 21 07:33:58.467916 2026] [security2:error] [pid 254995:tid 255093] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9LFv7v0rlcEGmVraErugADj2E"]
[Tue Jul 21 07:33:58.481070 2026] [security2:error] [pid 255769:tid 255772] [remote 117.50.194.130:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "denarios.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9LFLxMYwyVGnfuwsKGFAAD5QI"]
[Tue Jul 21 07:33:58.502611 2026] [security2:error] [pid 254995:tid 255031] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/FWAZ.php"] [unique_id "al9LFv7v0rlcEGmVraEruwADeSM"]
[Tue Jul 21 07:33:58.517543 2026] [security2:error] [pid 254995:tid 255105] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/miru1.php"] [unique_id "al9LFv7v0rlcEGmVraErvAADU20"]
[Tue Jul 21 07:33:58.559891 2026] [security2:error] [pid 254995:tid 255080] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/aa.php"] [unique_id "al9LFv7v0rlcEGmVraErvQADelQ"]
[Tue Jul 21 07:33:58.827387 2026] [security2:error] [pid 254995:tid 255201] [client 20.197.195.24:13123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/get.php"] [unique_id "al9LFv7v0rlcEGmVraErxQAAA2o"]
[Tue Jul 21 07:33:58.862564 2026] [proxy:error] [pid 255769:tid 255953] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:58.862643 2026] [proxy_http:error] [pid 255769:tid 255953] [client 20.206.105.145:39127] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:58.863459 2026] [proxy:error] [pid 255769:tid 255953] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:33:58.863490 2026] [proxy_http:error] [pid 255769:tid 255953] [client 20.206.105.145:39127] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:33:58.917534 2026] [security2:error] [pid 254995:tid 255005] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/122.php"] [unique_id "al9LFv7v0rlcEGmVraEryAADcQk"]
[Tue Jul 21 07:33:58.944019 2026] [security2:error] [pid 254995:tid 255094] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/get.php"] [unique_id "al9LFv7v0rlcEGmVraEryQADXmI"]
[Tue Jul 21 07:33:58.951483 2026] [security2:error] [pid 254995:tid 255141] [client 20.52.136.55:1593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/test1.php"] [unique_id "al9LFv7v0rlcEGmVraErygAAAy4"]
[Tue Jul 21 07:33:59.138246 2026] [security2:error] [pid 254995:tid 255000] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/as.php"] [unique_id "al9LF_7v0rlcEGmVraErzAADRwQ"]
[Tue Jul 21 07:33:59.153751 2026] [security2:error] [pid 254995:tid 255083] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ccou.php"] [unique_id "al9LF_7v0rlcEGmVraErzQADNFc"]
[Tue Jul 21 07:33:59.169220 2026] [security2:error] [pid 254995:tid 255007] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/w3lls.php"] [unique_id "al9LF_7v0rlcEGmVraErzgADJAs"]
[Tue Jul 21 07:33:59.232616 2026] [security2:error] [pid 255769:tid 255965] [client 117.50.194.130:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "denarios.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9LFLxMYwyVGnfuwsKGFAAD5QI"]
[Tue Jul 21 07:33:59.456164 2026] [security2:error] [pid 254995:tid 255278] [client 122.186.204.214:63176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LF_7v0rlcEGmVraEr0wAAA5w"]
[Tue Jul 21 07:33:59.456269 2026] [security2:error] [pid 254995:tid 255278] [client 122.186.204.214:63176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LF_7v0rlcEGmVraEr0wAAA5w"]
[Tue Jul 21 07:33:59.488136 2026] [security2:error] [pid 255769:tid 255937] [client 45.8.17.58:53647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/plugins/ms-files.php"] [unique_id "al9LF7xMYwyVGnfuwsKGMwAAA8k"]
[Tue Jul 21 07:33:59.623736 2026] [security2:error] [pid 254995:tid 255061] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/test1.php"] [unique_id "al9LF_7v0rlcEGmVraEr1QADQkE"]
[Tue Jul 21 07:33:59.677118 2026] [security2:error] [pid 254995:tid 254997] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/database.php"] [unique_id "al9LF_7v0rlcEGmVraEr1wADJgE"]
[Tue Jul 21 07:33:59.777991 2026] [security2:error] [pid 254995:tid 255155] [client 20.220.225.223:49547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/2x.php"] [unique_id "al9LF_7v0rlcEGmVraEr2QAAAzw"]
[Tue Jul 21 07:33:59.802104 2026] [security2:error] [pid 254995:tid 255279] [client 193.36.225.62:28065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LF_7v0rlcEGmVraEr2gAAA50"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:33:59.895608 2026] [security2:error] [pid 255769:tid 255978] [client 173.24.185.52:62194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LF7xMYwyVGnfuwsKGOwAAA_I"]
[Tue Jul 21 07:33:59.895719 2026] [security2:error] [pid 255769:tid 255978] [client 173.24.185.52:62194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LF7xMYwyVGnfuwsKGOwAAA_I"]
[Tue Jul 21 07:33:59.915538 2026] [security2:error] [pid 255769:tid 255964] [client 20.197.195.24:13118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/as.php"] [unique_id "al9LF7xMYwyVGnfuwsKGPQAAA-Q"]
[Tue Jul 21 07:33:59.915980 2026] [security2:error] [pid 254995:tid 255088] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/file.php"] [unique_id "al9LF_7v0rlcEGmVraEr3QADX1w"]
[Tue Jul 21 07:34:00.081233 2026] [core:error] [pid 255769:tid 255784] [remote 74.7.244.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:34:00.081252 2026] [core:error] [pid 255769:tid 255784] [remote 74.7.244.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:34:00.081447 2026] [security2:error] [pid 255769:tid 255994] [client 74.7.244.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.digitalbelfort.com"] [uri "/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/htdocs/bagisto-2.4/public/___proxy_subdomain_webmail/robots.txt"] [unique_id "al9LGLxMYwyVGnfuwsKGPgAEAQ4"]
[Tue Jul 21 07:34:00.156112 2026] [security2:error] [pid 254995:tid 255037] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/file.php"] [unique_id "al9LGP7v0rlcEGmVraEr4QADSik"]
[Tue Jul 21 07:34:00.380682 2026] [security2:error] [pid 255769:tid 255911] [client 37.140.223.117:47279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LGLxMYwyVGnfuwsKGQwAAA68"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:00.387978 2026] [security2:error] [pid 255769:tid 255802] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGRAADzyA"]
[Tue Jul 21 07:34:00.388163 2026] [security2:error] [pid 255769:tid 255943] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGRAADzyA"]
[Tue Jul 21 07:34:00.475124 2026] [security2:error] [pid 255769:tid 255900] [client 122.162.144.145:4626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGRwAAA6Q"]
[Tue Jul 21 07:34:00.475213 2026] [security2:error] [pid 255769:tid 255900] [client 122.162.144.145:4626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGRwAAA6Q"]
[Tue Jul 21 07:34:00.620755 2026] [security2:error] [pid 255769:tid 255996] [client 152.59.154.239:20657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGSQAABAI"]
[Tue Jul 21 07:34:00.625784 2026] [security2:error] [pid 255769:tid 255996] [client 152.59.154.239:20657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGSQAABAI"]
[Tue Jul 21 07:34:00.644239 2026] [security2:error] [pid 254995:tid 255021] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/777.php"] [unique_id "al9LGP7v0rlcEGmVraEr5gADfRk"]
[Tue Jul 21 07:34:00.681448 2026] [security2:error] [pid 254995:tid 255045] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ssixta.php"] [unique_id "al9LGP7v0rlcEGmVraEr5wADjjE"]
[Tue Jul 21 07:34:00.745331 2026] [security2:error] [pid 254995:tid 255101] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/1c.php"] [unique_id "al9LGP7v0rlcEGmVraEr6QADf2k"]
[Tue Jul 21 07:34:00.757924 2026] [security2:error] [pid 255769:tid 255956] [client 20.220.225.223:49831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/kua.php"] [unique_id "al9LGLxMYwyVGnfuwsKGTAAAA9w"]
[Tue Jul 21 07:34:00.788628 2026] [security2:error] [pid 255769:tid 255877] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGUAAEFms"]
[Tue Jul 21 07:34:00.788763 2026] [security2:error] [pid 255769:tid 256016] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGUAAEFms"]
[Tue Jul 21 07:34:00.860256 2026] [security2:error] [pid 255769:tid 255947] [client 82.102.28.107:40156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGUgAAA9M"]
[Tue Jul 21 07:34:00.860344 2026] [security2:error] [pid 255769:tid 255947] [client 82.102.28.107:40156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGUgAAA9M"]
[Tue Jul 21 07:34:00.876072 2026] [security2:error] [pid 255769:tid 256011] [client 45.251.232.145:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGUwAABBE"]
[Tue Jul 21 07:34:00.876172 2026] [security2:error] [pid 255769:tid 256011] [client 45.251.232.145:54436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGLxMYwyVGnfuwsKGUwAABBE"]
[Tue Jul 21 07:34:00.885425 2026] [security2:error] [pid 255769:tid 255927] [client 45.8.17.121:41323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/includes/logo/se.php"] [unique_id "al9LGLxMYwyVGnfuwsKGVAAAA78"]
[Tue Jul 21 07:34:00.894794 2026] [security2:error] [pid 255769:tid 256004] [client 20.220.225.223:49812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/kq1.php"] [unique_id "al9LGLxMYwyVGnfuwsKGVQAABAo"]
[Tue Jul 21 07:34:01.094613 2026] [security2:error] [pid 254995:tid 254999] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/test2.php"] [unique_id "al9LGf7v0rlcEGmVraEr7AADJQM"]
[Tue Jul 21 07:34:01.110658 2026] [security2:error] [pid 254995:tid 255060] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/buy.php"] [unique_id "al9LGf7v0rlcEGmVraEr7QADVkA"]
[Tue Jul 21 07:34:01.162795 2026] [security2:error] [pid 255769:tid 255963] [client 103.106.20.201:56361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGbxMYwyVGnfuwsKGWAAAA-M"]
[Tue Jul 21 07:34:01.162975 2026] [security2:error] [pid 255769:tid 255963] [client 103.106.20.201:56361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGbxMYwyVGnfuwsKGWAAAA-M"]
[Tue Jul 21 07:34:01.191075 2026] [security2:error] [pid 254995:tid 255006] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ssend.php"] [unique_id "al9LGf7v0rlcEGmVraEr7wADYwo"]
[Tue Jul 21 07:34:01.254698 2026] [security2:error] [pid 254995:tid 255018] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/item.php"] [unique_id "al9LGf7v0rlcEGmVraEr8wADgBY"]
[Tue Jul 21 07:34:01.397999 2026] [security2:error] [pid 254995:tid 255218] [client 20.197.195.24:48814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ccou.php"] [unique_id "al9LGf7v0rlcEGmVraEr-AAAA3o"]
[Tue Jul 21 07:34:01.760646 2026] [security2:error] [pid 254995:tid 255130] [client 20.206.105.145:39148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9LGf7v0rlcEGmVraEsAQAAAyM"]
[Tue Jul 21 07:34:01.841556 2026] [security2:error] [pid 254995:tid 255032] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ss.php"] [unique_id "al9LGf7v0rlcEGmVraEsAgADaiQ"]
[Tue Jul 21 07:34:01.903883 2026] [security2:error] [pid 254995:tid 255009] [remote 160.187.68.132:57878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tempex.com.br"] [uri "/wp-login.php"] [unique_id "al9LGf7v0rlcEGmVraEsBAADYg0"]
[Tue Jul 21 07:34:01.960127 2026] [security2:error] [pid 255769:tid 255931] [client 154.192.233.199:58965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGbxMYwyVGnfuwsKGZgAAA8M"]
[Tue Jul 21 07:34:01.960317 2026] [security2:error] [pid 255769:tid 255931] [client 154.192.233.199:58965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGbxMYwyVGnfuwsKGZgAAA8M"]
[Tue Jul 21 07:34:02.263845 2026] [security2:error] [pid 255769:tid 255996] [client 20.197.195.24:13064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/w3lls.php"] [unique_id "al9LGrxMYwyVGnfuwsKGbAAABAI"]
[Tue Jul 21 07:34:02.365772 2026] [security2:error] [pid 255769:tid 255964] [client 117.217.38.194:58878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGrxMYwyVGnfuwsKGcAAAA-Q"]
[Tue Jul 21 07:34:02.365880 2026] [security2:error] [pid 255769:tid 255964] [client 117.217.38.194:58878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGrxMYwyVGnfuwsKGcAAAA-Q"]
[Tue Jul 21 07:34:02.406953 2026] [security2:error] [pid 254995:tid 255257] [client 109.248.148.246:52432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9LGv7v0rlcEGmVraEsCQAAA4c"]
[Tue Jul 21 07:34:02.407043 2026] [security2:error] [pid 254995:tid 255257] [client 109.248.148.246:52432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9LGv7v0rlcEGmVraEsCQAAA4c"]
[Tue Jul 21 07:34:02.465280 2026] [security2:error] [pid 254995:tid 255125] [client 37.140.223.157:33277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LGv7v0rlcEGmVraEsCwAAAx4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:02.480075 2026] [security2:error] [pid 254995:tid 255266] [client 45.8.17.144:36105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/widgets/shadow-bot.php"] [unique_id "al9LGv7v0rlcEGmVraEsDAAAA5A"]
[Tue Jul 21 07:34:02.571124 2026] [security2:error] [pid 255769:tid 255988] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LGrxMYwyVGnfuwsKGdQAD_GE"]
[Tue Jul 21 07:34:02.645314 2026] [rewrite:error] [pid 254995:tid 255134] [client 187.49.76.218:17761] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2409
[Tue Jul 21 07:34:02.647241 2026] [rewrite:error] [pid 255769:tid 255909] [client 187.49.76.218:17793] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2409
[Tue Jul 21 07:34:02.666954 2026] [rewrite:error] [pid 254995:tid 255272] [client 187.49.76.218:17857] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2409
[Tue Jul 21 07:34:02.781244 2026] [security2:error] [pid 255769:tid 255936] [client 175.45.70.82:57166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGrxMYwyVGnfuwsKGewAAA8g"]
[Tue Jul 21 07:34:02.781372 2026] [security2:error] [pid 255769:tid 255936] [client 175.45.70.82:57166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LGrxMYwyVGnfuwsKGewAAA8g"]
[Tue Jul 21 07:34:02.855749 2026] [security2:error] [pid 254995:tid 255274] [client 18.233.221.210:29095] ModSecurity: Warning. Matched phrase "Who.is Bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.combolog.com.br"] [uri "/index.php"] [unique_id "al9LGf7v0rlcEGmVraEr-gAAA5g"]
[Tue Jul 21 07:34:03.369208 2026] [security2:error] [pid 254995:tid 255173] [client 20.220.225.223:49595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ez.php"] [unique_id "al9LG_7v0rlcEGmVraEsGgAAA04"]
[Tue Jul 21 07:34:03.381329 2026] [security2:error] [pid 254995:tid 255056] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/hypo.php"] [unique_id "al9LG_7v0rlcEGmVraEsGwADNTw"]
[Tue Jul 21 07:34:03.402508 2026] [security2:error] [pid 254995:tid 255065] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/users.php"] [unique_id "al9LG_7v0rlcEGmVraEsHAADhEU"]
[Tue Jul 21 07:34:03.439130 2026] [security2:error] [pid 254995:tid 255070] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/177.php"] [unique_id "al9LG_7v0rlcEGmVraEsHQADdko"]
[Tue Jul 21 07:34:03.476028 2026] [security2:error] [pid 254995:tid 255121] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/config.php"] [unique_id "al9LG_7v0rlcEGmVraEsHwADmX0"]
[Tue Jul 21 07:34:03.492538 2026] [security2:error] [pid 254995:tid 255025] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/gettest.php"] [unique_id "al9LG_7v0rlcEGmVraEsIAADVR0"]
[Tue Jul 21 07:34:03.507697 2026] [security2:error] [pid 254995:tid 255095] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/min.php"] [unique_id "al9LG_7v0rlcEGmVraEsIgADXWM"]
[Tue Jul 21 07:34:03.685525 2026] [security2:error] [pid 255769:tid 255994] [client 45.8.17.142:54803] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/login.php"] [unique_id "al9LG7xMYwyVGnfuwsKGiAAABAE"]
[Tue Jul 21 07:34:03.814910 2026] [security2:error] [pid 255769:tid 255969] [client 20.197.195.24:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/test1.php"] [unique_id "al9LG7xMYwyVGnfuwsKGigAAA-k"]
[Tue Jul 21 07:34:03.828244 2026] [security2:error] [pid 254995:tid 255172] [client 18.233.221.210:9218] ModSecurity: Warning. Matched phrase "Who.is Bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "combolog.com.br"] [uri "/index.php"] [unique_id "al9LG_7v0rlcEGmVraEsHgAAA00"]
[Tue Jul 21 07:34:03.868457 2026] [security2:error] [pid 255769:tid 255982] [client 62.102.148.164:42554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9LG7xMYwyVGnfuwsKGiwAAA_Y"]
[Tue Jul 21 07:34:03.868543 2026] [security2:error] [pid 255769:tid 255982] [client 62.102.148.164:42554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9LG7xMYwyVGnfuwsKGiwAAA_Y"]
[Tue Jul 21 07:34:04.515350 2026] [security2:error] [pid 255769:tid 255985] [client 193.36.225.66:46143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LHLxMYwyVGnfuwsKGkgAAA_k"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:04.611445 2026] [security2:error] [pid 254995:tid 255076] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LHP7v0rlcEGmVraEsMwADl1A"]
[Tue Jul 21 07:34:04.611566 2026] [security2:error] [pid 254995:tid 255273] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LHP7v0rlcEGmVraEsMwADl1A"]
[Tue Jul 21 07:34:04.710829 2026] [security2:error] [pid 254995:tid 255126] [client 20.220.225.223:49852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/zzz.php"] [unique_id "al9LHP7v0rlcEGmVraEsNQAAAx8"]
[Tue Jul 21 07:34:04.799914 2026] [security2:error] [pid 254995:tid 255118] [remote 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samilacalculos.com.br"] [uri "/wp-login.php"] [unique_id "al9LHP7v0rlcEGmVraEsNgADWXo"]
[Tue Jul 21 07:34:04.921412 2026] [security2:error] [pid 255769:tid 256004] [client 20.220.225.223:24246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/min.php"] [unique_id "al9LHLxMYwyVGnfuwsKGmwAABAo"]
[Tue Jul 21 07:34:05.039538 2026] [security2:error] [pid 255769:tid 255974] [client 103.174.34.15:49390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LHbxMYwyVGnfuwsKGowAAA-4"]
[Tue Jul 21 07:34:05.039633 2026] [security2:error] [pid 255769:tid 255974] [client 103.174.34.15:49390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LHbxMYwyVGnfuwsKGowAAA-4"]
[Tue Jul 21 07:34:05.093697 2026] [security2:error] [pid 255769:tid 255905] [client 45.8.17.136:64615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/well-known/index.php"] [unique_id "al9LHbxMYwyVGnfuwsKGpAAAA6k"]
[Tue Jul 21 07:34:05.132317 2026] [security2:error] [pid 254995:tid 255225] [client 20.197.195.24:48856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/database.php"] [unique_id "al9LHf7v0rlcEGmVraEsOwAAA4E"]
[Tue Jul 21 07:34:05.253568 2026] [security2:error] [pid 254995:tid 255087] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/dvjul.php"] [unique_id "al9LHf7v0rlcEGmVraEsPQADL1s"]
[Tue Jul 21 07:34:05.271771 2026] [security2:error] [pid 254995:tid 255079] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/biufile.php"] [unique_id "al9LHf7v0rlcEGmVraEsPgADK1M"]
[Tue Jul 21 07:34:05.301492 2026] [proxy:error] [pid 255769:tid 255915] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:05.301530 2026] [proxy_http:error] [pid 255769:tid 255915] [client 147.185.132.249:63832] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:05.302200 2026] [proxy:error] [pid 255769:tid 255915] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:05.302227 2026] [proxy_http:error] [pid 255769:tid 255915] [client 147.185.132.249:63832] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:05.441714 2026] [security2:error] [pid 255769:tid 256022] [client 173.252.95.21:36358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LHbxMYwyVGnfuwsKGrAAABBw"]
[Tue Jul 21 07:34:05.466391 2026] [security2:error] [pid 254995:tid 255120] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/av.php"] [unique_id "al9LHf7v0rlcEGmVraEsQgADM3w"]
[Tue Jul 21 07:34:05.482666 2026] [security2:error] [pid 254995:tid 255102] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/coffexium.php"] [unique_id "al9LHf7v0rlcEGmVraEsQwADbGo"]
[Tue Jul 21 07:34:05.499405 2026] [security2:error] [pid 254995:tid 255002] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/core.php"] [unique_id "al9LHf7v0rlcEGmVraEsRAADPQY"]
[Tue Jul 21 07:34:05.721242 2026] [security2:error] [pid 255769:tid 255834] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LHbxMYwyVGnfuwsKGtQADyUA"]
[Tue Jul 21 07:34:05.721396 2026] [security2:error] [pid 255769:tid 255937] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LHbxMYwyVGnfuwsKGtQADyUA"]
[Tue Jul 21 07:34:05.726744 2026] [security2:error] [pid 255769:tid 256002] [client 74.7.228.46:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "safirarentacar.com.br.bomexito.com.br"] [uri "/index.php"] [unique_id "al9LHbxMYwyVGnfuwsKGpwAABAg"]
[Tue Jul 21 07:34:05.727510 2026] [security2:error] [pid 255769:tid 256010] [client 74.7.228.46:44978] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "safirarentacar.com.br.bomexito.com.br"] [uri "/robots.txt"] [unique_id "al9LHbxMYwyVGnfuwsKGpQAEEB8"]
[Tue Jul 21 07:34:05.761130 2026] [security2:error] [pid 254995:tid 255195] [client 173.252.95.37:50650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LHP7v0rlcEGmVraEsMgAAA2Q"]
[Tue Jul 21 07:34:05.818689 2026] [security2:error] [pid 255769:tid 255949] [client 136.144.33.24:25469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LHLxMYwyVGnfuwsKGlwAAA9U"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:05.859408 2026] [security2:error] [pid 255769:tid 255983] [client 20.220.225.223:63854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wp-Blogs.php"] [unique_id "al9LHbxMYwyVGnfuwsKGtgAAA_c"]
[Tue Jul 21 07:34:06.028373 2026] [security2:error] [pid 254995:tid 255042] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/als.php"] [unique_id "al9LHv7v0rlcEGmVraEsTgADJy4"]
[Tue Jul 21 07:34:06.055357 2026] [security2:error] [pid 254995:tid 255191] [client 20.220.225.223:19277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9LHv7v0rlcEGmVraEsTwAAA2A"]
[Tue Jul 21 07:34:06.186524 2026] [security2:error] [pid 254995:tid 255161] [client 45.8.17.131:45145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/backup.php"] [unique_id "al9LHv7v0rlcEGmVraEsUQAAA0I"]
[Tue Jul 21 07:34:06.245092 2026] [security2:error] [pid 254995:tid 255085] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LHv7v0rlcEGmVraEsUgADllk"]
[Tue Jul 21 07:34:06.245231 2026] [security2:error] [pid 254995:tid 255272] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LHv7v0rlcEGmVraEsUgADllk"]
[Tue Jul 21 07:34:06.442983 2026] [security2:error] [pid 254995:tid 255150] [client 20.220.225.223:49834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wicked.php"] [unique_id "al9LHv7v0rlcEGmVraEsVwAAAzc"]
[Tue Jul 21 07:34:06.500649 2026] [security2:error] [pid 254995:tid 255010] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/simple.php"] [unique_id "al9LHv7v0rlcEGmVraEsWQADlA4"]
[Tue Jul 21 07:34:06.520179 2026] [security2:error] [pid 254995:tid 255104] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/init.php"] [unique_id "al9LHv7v0rlcEGmVraEsWgADTmw"]
[Tue Jul 21 07:34:06.536375 2026] [security2:error] [pid 254995:tid 255112] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/fpwch.php"] [unique_id "al9LHv7v0rlcEGmVraEsWwADNXQ"]
[Tue Jul 21 07:34:06.557273 2026] [security2:error] [pid 254995:tid 255097] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/domvf.php"] [unique_id "al9LHv7v0rlcEGmVraEsXAADhGU"]
[Tue Jul 21 07:34:06.590193 2026] [security2:error] [pid 254995:tid 255089] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp.php"] [unique_id "al9LHv7v0rlcEGmVraEsXQADdl0"]
[Tue Jul 21 07:34:06.605223 2026] [security2:error] [pid 254995:tid 255026] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/class.php"] [unique_id "al9LHv7v0rlcEGmVraEsXgADmR4"]
[Tue Jul 21 07:34:06.739983 2026] [security2:error] [pid 254995:tid 255152] [client 59.96.220.140:49551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LHv7v0rlcEGmVraEsYAAAAzk"]
[Tue Jul 21 07:34:06.740123 2026] [security2:error] [pid 254995:tid 255152] [client 59.96.220.140:49551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LHv7v0rlcEGmVraEsYAAAAzk"]
[Tue Jul 21 07:34:06.892935 2026] [security2:error] [pid 255769:tid 255806] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LHrxMYwyVGnfuwsKGzwADtyQ"]
[Tue Jul 21 07:34:06.893116 2026] [security2:error] [pid 255769:tid 255919] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LHrxMYwyVGnfuwsKGzwADtyQ"]
[Tue Jul 21 07:34:07.098688 2026] [security2:error] [pid 255769:tid 255872] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LH7xMYwyVGnfuwsKG0QAD7mY"]
[Tue Jul 21 07:34:07.098877 2026] [security2:error] [pid 255769:tid 255974] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LH7xMYwyVGnfuwsKG0QAD7mY"]
[Tue Jul 21 07:34:07.198195 2026] [security2:error] [pid 254995:tid 255031] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LH_7v0rlcEGmVraEsbAADhiM"]
[Tue Jul 21 07:34:07.198352 2026] [security2:error] [pid 254995:tid 255256] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LH_7v0rlcEGmVraEsbAADhiM"]
[Tue Jul 21 07:34:07.272538 2026] [security2:error] [pid 254995:tid 255105] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/echkm.php"] [unique_id "al9LH_7v0rlcEGmVraEsbQADZm0"]
[Tue Jul 21 07:34:07.383411 2026] [security2:error] [pid 254995:tid 255224] [client 20.220.225.223:4196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wp-css.php"] [unique_id "al9LH_7v0rlcEGmVraEscQAAA4A"]
[Tue Jul 21 07:34:07.464504 2026] [security2:error] [pid 254995:tid 255022] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/lib.php"] [unique_id "al9LH_7v0rlcEGmVraEscwADWRo"]
[Tue Jul 21 07:34:07.595871 2026] [security2:error] [pid 254995:tid 255225] [client 45.8.17.60:31495] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/user/freedoms-old.php"] [unique_id "al9LH_7v0rlcEGmVraEseAAAA4E"]
[Tue Jul 21 07:34:07.740498 2026] [security2:error] [pid 254995:tid 255066] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/login.php"] [unique_id "al9LH_7v0rlcEGmVraEsewADKkY"]
[Tue Jul 21 07:34:07.757789 2026] [security2:error] [pid 254995:tid 255000] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/a2.php"] [unique_id "al9LH_7v0rlcEGmVraEsfAADMwQ"]
[Tue Jul 21 07:34:07.863682 2026] [security2:error] [pid 254995:tid 255199] [client 139.167.225.182:51130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LH_7v0rlcEGmVraEsfgAAA2g"]
[Tue Jul 21 07:34:07.863772 2026] [security2:error] [pid 254995:tid 255199] [client 139.167.225.182:51130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LH_7v0rlcEGmVraEsfgAAA2g"]
[Tue Jul 21 07:34:08.017797 2026] [security2:error] [pid 255769:tid 255921] [client 20.197.195.24:48845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/file.php"] [unique_id "al9LILxMYwyVGnfuwsKG9gAAA7k"]
[Tue Jul 21 07:34:08.205756 2026] [security2:error] [pid 255769:tid 255828] [remote 216.73.216.238:11436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/contato.php"] [unique_id "al9LILxMYwyVGnfuwsKG_QADsjo"]
[Tue Jul 21 07:34:08.502613 2026] [security2:error] [pid 254995:tid 255084] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/d61.php"] [unique_id "al9LIP7v0rlcEGmVraEsiAADLlg"]
[Tue Jul 21 07:34:08.539597 2026] [security2:error] [pid 255769:tid 255800] [remote 216.73.216.238:11436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/mapa.php"] [unique_id "al9LILxMYwyVGnfuwsKHGwADqx4"]
[Tue Jul 21 07:34:08.575386 2026] [security2:error] [pid 254995:tid 255013] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/info.php"] [unique_id "al9LIP7v0rlcEGmVraEsjAADNBE"]
[Tue Jul 21 07:34:08.593933 2026] [security2:error] [pid 254995:tid 255107] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/11.php"] [unique_id "al9LIP7v0rlcEGmVraEsjQADcW8"]
[Tue Jul 21 07:34:08.614990 2026] [security2:error] [pid 254995:tid 255134] [client 20.220.225.223:24224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/echkm.php"] [unique_id "al9LIP7v0rlcEGmVraEsjgAAAyc"]
[Tue Jul 21 07:34:08.645304 2026] [security2:error] [pid 254995:tid 255088] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/v2.php"] [unique_id "al9LIP7v0rlcEGmVraEsjwADI1w"]
[Tue Jul 21 07:34:08.661280 2026] [security2:error] [pid 255769:tid 255967] [client 20.52.136.55:1474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/fw.php"] [unique_id "al9LILxMYwyVGnfuwsKHHAAAA-c"]
[Tue Jul 21 07:34:08.802371 2026] [security2:error] [pid 255769:tid 255958] [client 103.162.129.114:63382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LILxMYwyVGnfuwsKHHgAAA94"]
[Tue Jul 21 07:34:08.802484 2026] [security2:error] [pid 255769:tid 255958] [client 103.162.129.114:63382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LILxMYwyVGnfuwsKHHgAAA94"]
[Tue Jul 21 07:34:08.880480 2026] [security2:error] [pid 255769:tid 255971] [client 45.8.17.124:35711] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-author-name-path.php"] [unique_id "al9LILxMYwyVGnfuwsKHHwAAA-s"]
[Tue Jul 21 07:34:08.921970 2026] [security2:error] [pid 254995:tid 255037] [remote 124.55.178.99:58746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sogastro.com.br"] [uri "/wp-login.php"] [unique_id "al9LIP7v0rlcEGmVraEskgADJSk"]
[Tue Jul 21 07:34:08.938647 2026] [security2:error] [pid 254995:tid 255041] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/panel.php"] [unique_id "al9LIP7v0rlcEGmVraEskwADOi0"]
[Tue Jul 21 07:34:09.140114 2026] [security2:error] [pid 255769:tid 255943] [client 117.251.86.144:39790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LIbxMYwyVGnfuwsKHJwAAA88"]
[Tue Jul 21 07:34:09.140242 2026] [security2:error] [pid 255769:tid 255943] [client 117.251.86.144:39790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LIbxMYwyVGnfuwsKHJwAAA88"]
[Tue Jul 21 07:34:09.419005 2026] [security2:error] [pid 254995:tid 255265] [client 193.36.225.67:21903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LIf7v0rlcEGmVraEsnAAAA48"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:09.747916 2026] [security2:error] [pid 254995:tid 255008] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/dex.php"] [unique_id "al9LIf7v0rlcEGmVraEspAADUgw"]
[Tue Jul 21 07:34:09.894092 2026] [security2:error] [pid 255769:tid 256017] [client 45.8.17.73:57507] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/class-wp-error-character.php"] [unique_id "al9LIbxMYwyVGnfuwsKHLwAABBc"]
[Tue Jul 21 07:34:10.116240 2026] [security2:error] [pid 255769:tid 255972] [client 122.186.204.214:63679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LIrxMYwyVGnfuwsKHMgAAA-w"]
[Tue Jul 21 07:34:10.116382 2026] [security2:error] [pid 255769:tid 255972] [client 122.186.204.214:63679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LIrxMYwyVGnfuwsKHMgAAA-w"]
[Tue Jul 21 07:34:10.427637 2026] [security2:error] [pid 255769:tid 256003] [client 20.197.195.24:13181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/file.php"] [unique_id "al9LIrxMYwyVGnfuwsKHNQAABAk"]
[Tue Jul 21 07:34:10.551490 2026] [security2:error] [pid 255769:tid 255946] [client 173.24.185.52:62662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LIrxMYwyVGnfuwsKHOQAAA9I"]
[Tue Jul 21 07:34:10.551623 2026] [security2:error] [pid 255769:tid 255946] [client 173.24.185.52:62662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LIrxMYwyVGnfuwsKHOQAAA9I"]
[Tue Jul 21 07:34:10.619222 2026] [security2:error] [pid 254995:tid 255038] [remote 20.197.195.24:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "hauptmann.com.br"] [uri "/1.php"] [unique_id "al9LIv7v0rlcEGmVraEsrQADZio"]
[Tue Jul 21 07:34:10.619324 2026] [security2:error] [pid 254995:tid 255038] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/1.php"] [unique_id "al9LIv7v0rlcEGmVraEsrQADZio"]
[Tue Jul 21 07:34:10.635252 2026] [security2:error] [pid 254995:tid 255019] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/ms.php"] [unique_id "al9LIv7v0rlcEGmVraEsrgADMhc"]
[Tue Jul 21 07:34:10.639385 2026] [security2:error] [pid 254995:tid 255159] [client 20.220.225.223:49577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/fz.php"] [unique_id "al9LIv7v0rlcEGmVraEssAAAA0A"]
[Tue Jul 21 07:34:10.728462 2026] [autoindex:error] [pid 254995:tid 255027] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home2/jeffe476/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:34:10.749897 2026] [security2:error] [pid 254995:tid 255044] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/memberfuns.php"] [unique_id "al9LIv7v0rlcEGmVraEsswADVjA"]
[Tue Jul 21 07:34:10.808019 2026] [security2:error] [pid 254995:tid 255040] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/0.php"] [unique_id "al9LIv7v0rlcEGmVraEstAADKSw"]
[Tue Jul 21 07:34:10.823778 2026] [security2:error] [pid 254995:tid 255032] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/BDKR28.php"] [unique_id "al9LIv7v0rlcEGmVraEstQADWSQ"]
[Tue Jul 21 07:34:10.867707 2026] [security2:error] [pid 254995:tid 255009] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/green1.php"] [unique_id "al9LIv7v0rlcEGmVraEstgADKA0"]
[Tue Jul 21 07:34:10.886302 2026] [security2:error] [pid 255769:tid 255875] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LIrxMYwyVGnfuwsKHPgAEFWk"]
[Tue Jul 21 07:34:10.886488 2026] [security2:error] [pid 255769:tid 256015] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LIrxMYwyVGnfuwsKHPgAEFWk"]
[Tue Jul 21 07:34:10.903273 2026] [security2:error] [pid 254995:tid 255024] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/nc4.php"] [unique_id "al9LIv7v0rlcEGmVraEsuAADjRw"]
[Tue Jul 21 07:34:10.918971 2026] [security2:error] [pid 254995:tid 255091] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/a1.php"] [unique_id "al9LIv7v0rlcEGmVraEsuQADiV8"]
[Tue Jul 21 07:34:10.946932 2026] [security2:error] [pid 255769:tid 255918] [client 20.206.105.145:39284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/2P.php"] [unique_id "al9LIrxMYwyVGnfuwsKHQQAAA7Y"]
[Tue Jul 21 07:34:10.954365 2026] [security2:error] [pid 254995:tid 255043] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/eee.php"] [unique_id "al9LIv7v0rlcEGmVraEsugADeS8"]
[Tue Jul 21 07:34:11.158153 2026] [security2:error] [pid 254995:tid 255179] [client 122.162.144.145:4495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LI_7v0rlcEGmVraEsvQAAA1Q"]
[Tue Jul 21 07:34:11.160749 2026] [security2:error] [pid 254995:tid 255179] [client 122.162.144.145:4495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LI_7v0rlcEGmVraEsvQAAA1Q"]
[Tue Jul 21 07:34:11.297476 2026] [autoindex:error] [pid 254995:tid 255142] [client 205.210.31.14:61988] AH01276: Cannot serve directory /home2/inlaud99/erp.choppcontrol.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:34:11.317754 2026] [security2:error] [pid 254995:tid 255178] [client 62.102.148.164:38362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9LI_7v0rlcEGmVraEswQAAA1M"]
[Tue Jul 21 07:34:11.317849 2026] [security2:error] [pid 254995:tid 255178] [client 62.102.148.164:38362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9LI_7v0rlcEGmVraEswQAAA1M"]
[Tue Jul 21 07:34:11.376711 2026] [security2:error] [pid 254995:tid 255258] [client 45.251.232.145:54954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LI_7v0rlcEGmVraEswwAAA4g"]
[Tue Jul 21 07:34:11.376825 2026] [security2:error] [pid 254995:tid 255258] [client 45.251.232.145:54954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LI_7v0rlcEGmVraEswwAAA4g"]
[Tue Jul 21 07:34:11.446312 2026] [security2:error] [pid 255769:tid 255857] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LI7xMYwyVGnfuwsKHRwAD6Fc"]
[Tue Jul 21 07:34:11.446446 2026] [security2:error] [pid 255769:tid 255968] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LI7xMYwyVGnfuwsKHRwAD6Fc"]
[Tue Jul 21 07:34:11.698880 2026] [security2:error] [pid 255769:tid 255902] [client 136.144.33.25:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LIrxMYwyVGnfuwsKHOAAAA6Y"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:11.925835 2026] [security2:error] [pid 254995:tid 255056] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-aothait.php"] [unique_id "al9LI_7v0rlcEGmVraEsyQADNjw"]
[Tue Jul 21 07:34:11.937458 2026] [security2:error] [pid 255769:tid 255967] [client 103.106.20.201:57053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LI7xMYwyVGnfuwsKHUAAAA-c"]
[Tue Jul 21 07:34:11.937645 2026] [security2:error] [pid 255769:tid 255967] [client 103.106.20.201:57053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LI7xMYwyVGnfuwsKHUAAAA-c"]
[Tue Jul 21 07:34:12.101670 2026] [security2:error] [pid 255769:tid 256017] [client 20.197.195.24:13073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/777.php"] [unique_id "al9LJLxMYwyVGnfuwsKHUgAABBc"]
[Tue Jul 21 07:34:12.184279 2026] [security2:error] [pid 254995:tid 255125] [client 45.8.17.136:60491] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-cron-element.php"] [unique_id "al9LJP7v0rlcEGmVraEszQAAAx4"]
[Tue Jul 21 07:34:12.713639 2026] [security2:error] [pid 255769:tid 255988] [client 154.192.233.199:59422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJLxMYwyVGnfuwsKHWQAAA_w"]
[Tue Jul 21 07:34:12.713859 2026] [security2:error] [pid 255769:tid 255988] [client 154.192.233.199:59422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJLxMYwyVGnfuwsKHWQAAA_w"]
[Tue Jul 21 07:34:12.730878 2026] [security2:error] [pid 255769:tid 255812] [remote 216.73.216.238:25891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/tarifas.php"] [unique_id "al9LJLxMYwyVGnfuwsKHWgAEGyo"]
[Tue Jul 21 07:34:12.766465 2026] [security2:error] [pid 255769:tid 255856] [remote 216.73.216.238:25891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/regulamento.php"] [unique_id "al9LJLxMYwyVGnfuwsKHWwAEAVY"]
[Tue Jul 21 07:34:12.826841 2026] [security2:error] [pid 255769:tid 256028] [client 152.59.154.239:49947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJLxMYwyVGnfuwsKHXgAABCI"]
[Tue Jul 21 07:34:12.826933 2026] [security2:error] [pid 255769:tid 256028] [client 152.59.154.239:49947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJLxMYwyVGnfuwsKHXgAABCI"]
[Tue Jul 21 07:34:12.839204 2026] [security2:error] [pid 255769:tid 255974] [client 117.217.38.194:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJLxMYwyVGnfuwsKHXwAAA-4"]
[Tue Jul 21 07:34:12.839327 2026] [security2:error] [pid 255769:tid 255974] [client 117.217.38.194:59322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJLxMYwyVGnfuwsKHXwAAA-4"]
[Tue Jul 21 07:34:12.927898 2026] [core:alert] [pid 255769:tid 255918] [client 57.141.18.45:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:34:13.012285 2026] [security2:error] [pid 255769:tid 255931] [client 62.102.148.164:38372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LJbxMYwyVGnfuwsKHZQAAA8M"]
[Tue Jul 21 07:34:13.012371 2026] [security2:error] [pid 255769:tid 255931] [client 62.102.148.164:38372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LJbxMYwyVGnfuwsKHZQAAA8M"]
[Tue Jul 21 07:34:13.041979 2026] [security2:error] [pid 254995:tid 255062] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/config.json.php"] [unique_id "al9LJf7v0rlcEGmVraEs2AADeEI"]
[Tue Jul 21 07:34:13.060978 2026] [security2:error] [pid 254995:tid 255033] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9LJf7v0rlcEGmVraEs2QADnSU"]
[Tue Jul 21 07:34:13.121185 2026] [security2:error] [pid 254995:tid 255077] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/k2.php"] [unique_id "al9LJf7v0rlcEGmVraEs2wADlVE"]
[Tue Jul 21 07:34:13.161201 2026] [security2:error] [pid 254995:tid 255086] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9LJf7v0rlcEGmVraEs3QADlFo"]
[Tue Jul 21 07:34:13.203404 2026] [security2:error] [pid 254995:tid 255118] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9LJf7v0rlcEGmVraEs3gADRXo"]
[Tue Jul 21 07:34:13.211791 2026] [security2:error] [pid 255769:tid 255957] [client 193.36.225.10:47415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LJbxMYwyVGnfuwsKHagAAA90"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:13.232579 2026] [security2:error] [pid 254995:tid 255123] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9LJf7v0rlcEGmVraEs4AADNX8"]
[Tue Jul 21 07:34:13.286563 2026] [security2:error] [pid 254995:tid 255275] [client 45.8.17.134:26487] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/sitemaps/chosen.php"] [unique_id "al9LJf7v0rlcEGmVraEs4wAAA5k"]
[Tue Jul 21 07:34:13.321075 2026] [security2:error] [pid 254995:tid 255081] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/for.php"] [unique_id "al9LJf7v0rlcEGmVraEs5QADVVU"]
[Tue Jul 21 07:34:13.351790 2026] [security2:error] [pid 254995:tid 255079] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/raw.php"] [unique_id "al9LJf7v0rlcEGmVraEs5wADTlM"]
[Tue Jul 21 07:34:13.386948 2026] [security2:error] [pid 254995:tid 255177] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LJf7v0rlcEGmVraEs5gADUls"]
[Tue Jul 21 07:34:13.592451 2026] [security2:error] [pid 255769:tid 256015] [client 175.45.70.82:57702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJbxMYwyVGnfuwsKHcAAABBU"]
[Tue Jul 21 07:34:13.592627 2026] [security2:error] [pid 255769:tid 256015] [client 175.45.70.82:57702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJbxMYwyVGnfuwsKHcAAABBU"]
[Tue Jul 21 07:34:13.792049 2026] [security2:error] [pid 255769:tid 255967] [client 20.197.195.24:48838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ssixta.php"] [unique_id "al9LJbxMYwyVGnfuwsKHcwAAA-c"]
[Tue Jul 21 07:34:13.873954 2026] [security2:error] [pid 255769:tid 255919] [client 82.102.28.107:50368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LJbxMYwyVGnfuwsKHdwAAA7c"]
[Tue Jul 21 07:34:13.874065 2026] [security2:error] [pid 255769:tid 255919] [client 82.102.28.107:50368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LJbxMYwyVGnfuwsKHdwAAA7c"]
[Tue Jul 21 07:34:13.892297 2026] [security2:error] [pid 255769:tid 256027] [client 185.251.19.67:22895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiferreira.com.br"] [uri "/wp-login.php"] [unique_id "al9LJbxMYwyVGnfuwsKHeAAABCE"]
[Tue Jul 21 07:34:14.284851 2026] [security2:error] [pid 254995:tid 255145] [client 45.8.17.49:60097] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/antiperfo.php"] [unique_id "al9LJv7v0rlcEGmVraEs8QAAAzI"]
[Tue Jul 21 07:34:14.536408 2026] [security2:error] [pid 255769:tid 255939] [client 103.174.34.15:49885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJrxMYwyVGnfuwsKHfAAAA8s"]
[Tue Jul 21 07:34:14.536533 2026] [security2:error] [pid 255769:tid 255939] [client 103.174.34.15:49885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJrxMYwyVGnfuwsKHfAAAA8s"]
[Tue Jul 21 07:34:14.761052 2026] [security2:error] [pid 254995:tid 255217] [client 20.197.195.24:48768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/1c.php"] [unique_id "al9LJv7v0rlcEGmVraEs-QAAA3k"]
[Tue Jul 21 07:34:14.862488 2026] [security2:error] [pid 255769:tid 256022] [client 213.152.162.104:43138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LJrxMYwyVGnfuwsKHfgAABBw"]
[Tue Jul 21 07:34:14.862592 2026] [security2:error] [pid 255769:tid 256022] [client 213.152.162.104:43138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LJrxMYwyVGnfuwsKHfgAABBw"]
[Tue Jul 21 07:34:14.942488 2026] [security2:error] [pid 254995:tid 255183] [client 193.36.225.153:34183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LJf7v0rlcEGmVraEs7QAAA1g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:15.290967 2026] [security2:error] [pid 255769:tid 255891] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LJ7xMYwyVGnfuwsKHhgAD13k"]
[Tue Jul 21 07:34:15.291099 2026] [security2:error] [pid 255769:tid 255951] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LJ7xMYwyVGnfuwsKHhgAD13k"]
[Tue Jul 21 07:34:15.496744 2026] [security2:error] [pid 254995:tid 255110] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJ_7v0rlcEGmVraEtBQADYnI"]
[Tue Jul 21 07:34:15.496870 2026] [security2:error] [pid 254995:tid 255193] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LJ_7v0rlcEGmVraEtBQADYnI"]
[Tue Jul 21 07:34:15.682629 2026] [security2:error] [pid 254995:tid 255174] [client 45.8.17.122:30935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/blog-stream/inc/upgrade-to-pro/section-pro.php"] [unique_id "al9LJ_7v0rlcEGmVraEtCAAAA08"]
[Tue Jul 21 07:34:15.823794 2026] [security2:error] [pid 254995:tid 255166] [client 20.220.225.223:61973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/wp-explorer.php"] [unique_id "al9LJ_7v0rlcEGmVraEtDgAAA0c"]
[Tue Jul 21 07:34:16.096410 2026] [security2:error] [pid 255769:tid 255785] [remote 216.73.216.238:25695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/casa.php"] [unique_id "al9LKLxMYwyVGnfuwsKHjwAEAg8"]
[Tue Jul 21 07:34:16.221799 2026] [security2:error] [pid 255769:tid 255776] [remote 216.73.216.238:25695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/galeria.php"] [unique_id "al9LKLxMYwyVGnfuwsKHkAAD-QY"]
[Tue Jul 21 07:34:16.336693 2026] [security2:error] [pid 255769:tid 255913] [client 20.197.195.24:13120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/test2.php"] [unique_id "al9LKLxMYwyVGnfuwsKHkgAAA7E"]
[Tue Jul 21 07:34:16.381586 2026] [security2:error] [pid 255769:tid 255876] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LKLxMYwyVGnfuwsKHkwAD92o"]
[Tue Jul 21 07:34:16.381763 2026] [security2:error] [pid 255769:tid 255983] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LKLxMYwyVGnfuwsKHkwAD92o"]
[Tue Jul 21 07:34:16.782050 2026] [security2:error] [pid 255769:tid 255888] [remote 160.187.68.132:36550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "companhiatop.com.br"] [uri "/wp-login.php"] [unique_id "al9LKLxMYwyVGnfuwsKHlQADtXY"]
[Tue Jul 21 07:34:16.800925 2026] [security2:error] [pid 255769:tid 255806] [remote 212.47.76.178:52028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.76.47.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9LKLxMYwyVGnfuwsKHlgAEESQ"]
[Tue Jul 21 07:34:16.986009 2026] [security2:error] [pid 254995:tid 255275] [client 45.8.17.115:30941] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/fusion-styles/user/index.php"] [unique_id "al9LKP7v0rlcEGmVraEtHQAAA5k"]
[Tue Jul 21 07:34:17.093214 2026] [security2:error] [pid 254995:tid 255272] [client 216.73.160.27:30785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/wp-login.php"] [unique_id "al9LKf7v0rlcEGmVraEtIAAAA5Y"]
[Tue Jul 21 07:34:17.366678 2026] [security2:error] [pid 254995:tid 255216] [client 59.96.220.140:50071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LKf7v0rlcEGmVraEtJAAAA3g"]
[Tue Jul 21 07:34:17.366807 2026] [security2:error] [pid 254995:tid 255216] [client 59.96.220.140:50071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LKf7v0rlcEGmVraEtJAAAA3g"]
[Tue Jul 21 07:34:17.373339 2026] [security2:error] [pid 254995:tid 255161] [client 193.36.225.71:20827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LKf7v0rlcEGmVraEtJgAAA0I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:17.377125 2026] [security2:error] [pid 254995:tid 255122] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LKf7v0rlcEGmVraEtJwADWn4"]
[Tue Jul 21 07:34:17.377252 2026] [security2:error] [pid 254995:tid 255185] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LKf7v0rlcEGmVraEtJwADWn4"]
[Tue Jul 21 07:34:17.571449 2026] [security2:error] [pid 255769:tid 255919] [client 20.220.225.223:48155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/la.php"] [unique_id "al9LKbxMYwyVGnfuwsKHmQAAA7c"]
[Tue Jul 21 07:34:17.658402 2026] [security2:error] [pid 255769:tid 255872] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LKbxMYwyVGnfuwsKHmwAEA2Y"]
[Tue Jul 21 07:34:17.658550 2026] [security2:error] [pid 255769:tid 255997] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LKbxMYwyVGnfuwsKHmwAEA2Y"]
[Tue Jul 21 07:34:17.707184 2026] [security2:error] [pid 255769:tid 255831] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LKbxMYwyVGnfuwsKHnAADpj0"]
[Tue Jul 21 07:34:17.707339 2026] [security2:error] [pid 255769:tid 255902] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LKbxMYwyVGnfuwsKHnAADpj0"]
[Tue Jul 21 07:34:18.003724 2026] [security2:error] [pid 255769:tid 256023] [client 20.220.225.223:4222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/akismet.php"] [unique_id "al9LKrxMYwyVGnfuwsKHpAAABB0"]
[Tue Jul 21 07:34:18.190769 2026] [security2:error] [pid 254995:tid 255136] [client 45.8.17.145:32231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyfive/parts/upgrade/index.php"] [unique_id "al9LKv7v0rlcEGmVraEtNwAAAyk"]
[Tue Jul 21 07:34:18.192122 2026] [security2:error] [pid 254995:tid 255217] [client 20.197.195.24:13109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/buy.php"] [unique_id "al9LKv7v0rlcEGmVraEtOAAAA3k"]
[Tue Jul 21 07:34:18.493110 2026] [security2:error] [pid 255769:tid 255976] [client 139.167.225.182:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LKrxMYwyVGnfuwsKHrAAAA_A"]
[Tue Jul 21 07:34:18.493221 2026] [security2:error] [pid 255769:tid 255976] [client 139.167.225.182:51766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LKrxMYwyVGnfuwsKHrAAAA_A"]
[Tue Jul 21 07:34:19.103960 2026] [security2:error] [pid 255769:tid 255836] [remote 45.79.123.44:54968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9LK7xMYwyVGnfuwsKHrwADpEI"]
[Tue Jul 21 07:34:19.390717 2026] [security2:error] [pid 254995:tid 255187] [client 45.8.17.146:39211] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/theme-install-variable.php"] [unique_id "al9LK_7v0rlcEGmVraEtSwAAA1w"]
[Tue Jul 21 07:34:19.480514 2026] [security2:error] [pid 255769:tid 255994] [client 20.220.225.223:56489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/ace2.php"] [unique_id "al9LK7xMYwyVGnfuwsKHtQAABAE"]
[Tue Jul 21 07:34:19.549181 2026] [security2:error] [pid 255769:tid 256007] [client 20.29.57.244:49468] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.68"] [uri "/index.cgi"] [unique_id "al9LK7xMYwyVGnfuwsKHuAAABA0"]
[Tue Jul 21 07:34:19.614920 2026] [security2:error] [pid 254995:tid 255191] [client 20.197.195.24:13136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ssend.php"] [unique_id "al9LK_7v0rlcEGmVraEtTgAAA2A"]
[Tue Jul 21 07:34:19.811053 2026] [security2:error] [pid 254995:tid 255219] [client 117.251.86.144:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LK_7v0rlcEGmVraEtUgAAA3s"]
[Tue Jul 21 07:34:19.811167 2026] [security2:error] [pid 254995:tid 255219] [client 117.251.86.144:36206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LK_7v0rlcEGmVraEtUgAAA3s"]
[Tue Jul 21 07:34:20.159329 2026] [security2:error] [pid 254995:tid 255168] [client 103.162.129.114:63825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LLP7v0rlcEGmVraEtWgAAA0k"]
[Tue Jul 21 07:34:20.159469 2026] [security2:error] [pid 254995:tid 255168] [client 103.162.129.114:63825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LLP7v0rlcEGmVraEtWgAAA0k"]
[Tue Jul 21 07:34:20.345413 2026] [security2:error] [pid 255769:tid 255999] [client 20.220.225.223:24249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/mac.php"] [unique_id "al9LLLxMYwyVGnfuwsKHxQAABAU"]
[Tue Jul 21 07:34:20.767327 2026] [security2:error] [pid 255769:tid 255909] [client 122.186.204.214:64177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LLLxMYwyVGnfuwsKHygAAA60"]
[Tue Jul 21 07:34:20.767457 2026] [security2:error] [pid 255769:tid 255909] [client 122.186.204.214:64177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LLLxMYwyVGnfuwsKHygAAA60"]
[Tue Jul 21 07:34:20.890771 2026] [security2:error] [pid 254995:tid 255127] [client 45.8.17.115:53501] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentynineteen/sass/site/index.php"] [unique_id "al9LLP7v0rlcEGmVraEtYgAAAyA"]
[Tue Jul 21 07:34:21.308445 2026] [security2:error] [pid 255769:tid 255918] [client 173.252.95.0:54614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LLbxMYwyVGnfuwsKHzwAAA7Y"]
[Tue Jul 21 07:34:21.363160 2026] [security2:error] [pid 255769:tid 256002] [client 173.24.185.52:63141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LLbxMYwyVGnfuwsKH0AAABAg"]
[Tue Jul 21 07:34:21.363299 2026] [security2:error] [pid 255769:tid 256002] [client 173.24.185.52:63141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LLbxMYwyVGnfuwsKH0AAABAg"]
[Tue Jul 21 07:34:21.472632 2026] [security2:error] [pid 255769:tid 255871] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LLbxMYwyVGnfuwsKH0wADwWU"]
[Tue Jul 21 07:34:21.472820 2026] [security2:error] [pid 255769:tid 255929] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LLbxMYwyVGnfuwsKH0wADwWU"]
[Tue Jul 21 07:34:21.501417 2026] [security2:error] [pid 254995:tid 255019] [remote 216.73.216.238:23998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/casa.php"] [unique_id "al9LLf7v0rlcEGmVraEtbAADbRc"]
[Tue Jul 21 07:34:21.501572 2026] [security2:error] [pid 254995:tid 255012] [remote 216.73.216.238:23998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/casa.php"] [unique_id "al9LLf7v0rlcEGmVraEtbQADbRA"]
[Tue Jul 21 07:34:21.511373 2026] [security2:error] [pid 255769:tid 255925] [client 20.220.225.223:49585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/edit.php"] [unique_id "al9LLbxMYwyVGnfuwsKH1AAAA70"]
[Tue Jul 21 07:34:21.772650 2026] [security2:error] [pid 255769:tid 255957] [client 20.220.225.223:24200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/samll.php"] [unique_id "al9LLbxMYwyVGnfuwsKH2QAAA90"]
[Tue Jul 21 07:34:21.788327 2026] [security2:error] [pid 254995:tid 255223] [client 20.220.225.223:38702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/ops.php"] [unique_id "al9LLf7v0rlcEGmVraEtcAAAA38"]
[Tue Jul 21 07:34:21.823935 2026] [security2:error] [pid 254995:tid 255224] [client 20.197.195.24:13058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/item.php"] [unique_id "al9LLf7v0rlcEGmVraEtcgAAA4A"]
[Tue Jul 21 07:34:21.851481 2026] [security2:error] [pid 255769:tid 255998] [client 45.251.232.145:55736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LLbxMYwyVGnfuwsKH3QAABAQ"]
[Tue Jul 21 07:34:21.851604 2026] [security2:error] [pid 255769:tid 255998] [client 45.251.232.145:55736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LLbxMYwyVGnfuwsKH3QAABAQ"]
[Tue Jul 21 07:34:21.954086 2026] [security2:error] [pid 255769:tid 255967] [client 20.52.136.55:1755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/fm.php"] [unique_id "al9LLbxMYwyVGnfuwsKH4gAAA-c"]
[Tue Jul 21 07:34:22.048173 2026] [security2:error] [pid 254995:tid 255277] [client 122.162.144.145:3089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LLv7v0rlcEGmVraEtdgAAA5s"]
[Tue Jul 21 07:34:22.048312 2026] [security2:error] [pid 254995:tid 255277] [client 122.162.144.145:3089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LLv7v0rlcEGmVraEtdgAAA5s"]
[Tue Jul 21 07:34:22.080062 2026] [security2:error] [pid 254995:tid 255184] [client 45.8.17.148:54035] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyone/assets/sass/05-blocks/preformatted/index.php"] [unique_id "al9LLv7v0rlcEGmVraEteAAAA1k"]
[Tue Jul 21 07:34:22.092788 2026] [security2:error] [pid 255769:tid 255952] [client 172.245.102.33:58211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LLLxMYwyVGnfuwsKHyQAAA9g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:22.177057 2026] [security2:error] [pid 254995:tid 255091] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LLv7v0rlcEGmVraEtegADMF8"]
[Tue Jul 21 07:34:22.177193 2026] [security2:error] [pid 254995:tid 255143] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LLv7v0rlcEGmVraEtegADMF8"]
[Tue Jul 21 07:34:22.313696 2026] [security2:error] [pid 255769:tid 256001] [client 193.36.225.66:55855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LLrxMYwyVGnfuwsKH6AAABAc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:22.486215 2026] [security2:error] [pid 255769:tid 256008] [client 20.220.225.223:49539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/nhvoanpl.php"] [unique_id "al9LLrxMYwyVGnfuwsKH7QAABA4"]
[Tue Jul 21 07:34:22.586698 2026] [security2:error] [pid 255769:tid 255909] [client 20.197.195.24:13071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ss.php"] [unique_id "al9LLrxMYwyVGnfuwsKH8AAAA60"]
[Tue Jul 21 07:34:22.618594 2026] [security2:error] [pid 255769:tid 255975] [client 103.106.20.201:57632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LLrxMYwyVGnfuwsKH8QAAA-8"]
[Tue Jul 21 07:34:22.618738 2026] [security2:error] [pid 255769:tid 255975] [client 103.106.20.201:57632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LLrxMYwyVGnfuwsKH8QAAA-8"]
[Tue Jul 21 07:34:23.305664 2026] [security2:error] [pid 254995:tid 255154] [client 117.217.38.194:59769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LL_7v0rlcEGmVraEtjAAAAzs"]
[Tue Jul 21 07:34:23.305917 2026] [security2:error] [pid 254995:tid 255154] [client 117.217.38.194:59769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LL_7v0rlcEGmVraEtjAAAAzs"]
[Tue Jul 21 07:34:23.393387 2026] [security2:error] [pid 255769:tid 255994] [client 45.8.17.121:27577] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/elex/elex.php"] [unique_id "al9LL7xMYwyVGnfuwsKH_gAABAE"]
[Tue Jul 21 07:34:23.500028 2026] [security2:error] [pid 254995:tid 255153] [client 20.220.225.223:48152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/inso.php"] [unique_id "al9LL_7v0rlcEGmVraEtkAAAAzo"]
[Tue Jul 21 07:34:23.523678 2026] [security2:error] [pid 255769:tid 255973] [client 154.192.233.199:59891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LL7xMYwyVGnfuwsKIAQAAA-0"]
[Tue Jul 21 07:34:23.523850 2026] [security2:error] [pid 255769:tid 255973] [client 154.192.233.199:59891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LL7xMYwyVGnfuwsKIAQAAA-0"]
[Tue Jul 21 07:34:23.802139 2026] [security2:error] [pid 255769:tid 255957] [client 20.220.225.223:6131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wp-editor.php"] [unique_id "al9LL7xMYwyVGnfuwsKIBAAAA90"]
[Tue Jul 21 07:34:23.888278 2026] [security2:error] [pid 254995:tid 255025] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LL_7v0rlcEGmVraEtlgADKx0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:23.892213 2026] [security2:error] [pid 254995:tid 255064] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LL_7v0rlcEGmVraEtmAADj0Q"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:23.945258 2026] [security2:error] [pid 255769:tid 255804] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LL7xMYwyVGnfuwsKIAwADsCI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:23.963143 2026] [security2:error] [pid 255769:tid 255904] [client 20.197.195.24:13097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/hypo.php"] [unique_id "al9LL7xMYwyVGnfuwsKIBgAAA6g"]
[Tue Jul 21 07:34:24.046434 2026] [security2:error] [pid 255769:tid 255846] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LL7xMYwyVGnfuwsKIAgAD3Ew"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:24.240838 2026] [security2:error] [pid 255769:tid 255913] [client 175.45.70.82:58235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMLxMYwyVGnfuwsKICAAAA7E"]
[Tue Jul 21 07:34:24.240955 2026] [security2:error] [pid 255769:tid 255913] [client 175.45.70.82:58235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMLxMYwyVGnfuwsKICAAAA7E"]
[Tue Jul 21 07:34:24.305956 2026] [security2:error] [pid 254995:tid 255077] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMP7v0rlcEGmVraEtowADX1E"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:24.340332 2026] [security2:error] [pid 255769:tid 256009] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LMLxMYwyVGnfuwsKICgAEDyU"]
[Tue Jul 21 07:34:24.389117 2026] [security2:error] [pid 255769:tid 255967] [client 45.8.17.62:45947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/oceanwp/sass/base/1.php"] [unique_id "al9LMLxMYwyVGnfuwsKIDAAAA-c"]
[Tue Jul 21 07:34:24.399313 2026] [security2:error] [pid 254995:tid 255086] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMP7v0rlcEGmVraEtpgADhVo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:24.514175 2026] [security2:error] [pid 254995:tid 255223] [client 213.152.162.104:47970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LMP7v0rlcEGmVraEtqQAAA38"]
[Tue Jul 21 07:34:24.514286 2026] [security2:error] [pid 254995:tid 255223] [client 213.152.162.104:47970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LMP7v0rlcEGmVraEtqQAAA38"]
[Tue Jul 21 07:34:24.812940 2026] [security2:error] [pid 254995:tid 255081] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMP7v0rlcEGmVraEtrwADiVU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:24.834778 2026] [security2:error] [pid 255769:tid 255961] [client 152.59.154.239:50430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMLxMYwyVGnfuwsKIEAAAA-E"]
[Tue Jul 21 07:34:24.834877 2026] [security2:error] [pid 255769:tid 255961] [client 152.59.154.239:50430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMLxMYwyVGnfuwsKIEAAAA-E"]
[Tue Jul 21 07:34:24.887358 2026] [security2:error] [pid 255769:tid 255963] [client 20.220.225.223:24263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/abcd.php"] [unique_id "al9LMLxMYwyVGnfuwsKIEQAAA-M"]
[Tue Jul 21 07:34:24.955448 2026] [security2:error] [pid 254995:tid 255079] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMP7v0rlcEGmVraEtsQADKlM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:25.001598 2026] [security2:error] [pid 254995:tid 255262] [client 20.197.195.24:13165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/users.php"] [unique_id "al9LMf7v0rlcEGmVraEtswAAA4w"]
[Tue Jul 21 07:34:25.073335 2026] [security2:error] [pid 254995:tid 255053] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMf7v0rlcEGmVraEttQADWTk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:25.175653 2026] [security2:error] [pid 255769:tid 255907] [client 20.220.225.223:49552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wpx.php"] [unique_id "al9LMbxMYwyVGnfuwsKIHAAAA6s"]
[Tue Jul 21 07:34:25.213973 2026] [security2:error] [pid 254995:tid 255082] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMf7v0rlcEGmVraEtuAADbFY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:25.316251 2026] [security2:error] [pid 255769:tid 255819] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMbxMYwyVGnfuwsKIHQAEDjE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:25.323726 2026] [security2:error] [pid 255769:tid 255945] [client 103.174.34.15:50367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMbxMYwyVGnfuwsKIHgAAA9E"]
[Tue Jul 21 07:34:25.323839 2026] [security2:error] [pid 255769:tid 255945] [client 103.174.34.15:50367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMbxMYwyVGnfuwsKIHgAAA9E"]
[Tue Jul 21 07:34:25.363623 2026] [security2:error] [pid 255769:tid 255830] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMbxMYwyVGnfuwsKIHwADpDw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:25.385917 2026] [security2:error] [pid 254995:tid 255201] [client 45.8.17.114:62789] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyone/emerance.php"] [unique_id "al9LMf7v0rlcEGmVraEtvAAAA2o"]
[Tue Jul 21 07:34:25.408123 2026] [security2:error] [pid 254995:tid 254998] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LMf7v0rlcEGmVraEtvQADawI"]
[Tue Jul 21 07:34:25.408239 2026] [security2:error] [pid 254995:tid 255202] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LMf7v0rlcEGmVraEtvQADawI"]
[Tue Jul 21 07:34:25.617158 2026] [security2:error] [pid 254995:tid 255106] [remote 140.245.218.10:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.218.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LMf7v0rlcEGmVraEtwwADb24"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:34:26.024496 2026] [security2:error] [pid 255769:tid 255883] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMrxMYwyVGnfuwsKIJgAEEXE"]
[Tue Jul 21 07:34:26.024645 2026] [security2:error] [pid 255769:tid 256011] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LMrxMYwyVGnfuwsKIJgAEEXE"]
[Tue Jul 21 07:34:26.140324 2026] [security2:error] [pid 254995:tid 255143] [client 193.36.225.63:41051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LMv7v0rlcEGmVraEtyQAAAzA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:26.252422 2026] [security2:error] [pid 254995:tid 255002] [remote 195.26.253.119:44838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-login.php"] [unique_id "al9LMf7v0rlcEGmVraEtugADUwY"]
[Tue Jul 21 07:34:26.812108 2026] [security2:error] [pid 254995:tid 255129] [client 37.140.223.134:20881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LMv7v0rlcEGmVraEt0AAAAyI"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:26.847843 2026] [security2:error] [pid 254995:tid 255089] [remote 45.79.123.44:38476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9LMv7v0rlcEGmVraEt1QADfl0"]
[Tue Jul 21 07:34:26.847967 2026] [security2:error] [pid 254995:tid 255222] [client 45.79.123.44:38476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9LMv7v0rlcEGmVraEt1QADfl0"]
[Tue Jul 21 07:34:26.849400 2026] [security2:error] [pid 255769:tid 255996] [client 20.197.195.24:13094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/177.php"] [unique_id "al9LMrxMYwyVGnfuwsKIKwAABAI"]
[Tue Jul 21 07:34:27.238929 2026] [security2:error] [pid 255769:tid 255855] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LM7xMYwyVGnfuwsKILwAEA1U"]
[Tue Jul 21 07:34:27.239129 2026] [security2:error] [pid 255769:tid 255997] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LM7xMYwyVGnfuwsKILwAEA1U"]
[Tue Jul 21 07:34:27.691887 2026] [security2:error] [pid 254995:tid 255190] [client 45.8.17.65:20671] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentynineteen/content-index.php"] [unique_id "al9LM_7v0rlcEGmVraEt3wAAA18"]
[Tue Jul 21 07:34:28.186200 2026] [security2:error] [pid 254995:tid 255093] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LNP7v0rlcEGmVraEt6gADVmE"]
[Tue Jul 21 07:34:28.186401 2026] [security2:error] [pid 254995:tid 255181] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LNP7v0rlcEGmVraEt6gADVmE"]
[Tue Jul 21 07:34:28.234230 2026] [security2:error] [pid 255769:tid 255837] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LNLxMYwyVGnfuwsKIMAAD0EM"]
[Tue Jul 21 07:34:28.234361 2026] [security2:error] [pid 255769:tid 255944] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LNLxMYwyVGnfuwsKIMAAD0EM"]
[Tue Jul 21 07:34:28.319359 2026] [security2:error] [pid 255769:tid 255968] [client 20.197.195.24:13157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/config.php"] [unique_id "al9LNLxMYwyVGnfuwsKIMQAAA-g"]
[Tue Jul 21 07:34:28.365135 2026] [rewrite:error] [pid 254995:tid 255146] [client 187.49.76.218:18177] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:34:28.367182 2026] [rewrite:error] [pid 255769:tid 255905] [client 187.49.76.218:18241] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:34:28.386681 2026] [rewrite:error] [pid 254995:tid 255221] [client 187.49.76.218:18273] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:34:28.505316 2026] [security2:error] [pid 254995:tid 255215] [client 122.129.67.13:59877] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LNP7v0rlcEGmVraEt8QAAA3c"]
[Tue Jul 21 07:34:28.505445 2026] [security2:error] [pid 254995:tid 255215] [client 122.129.67.13:59877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LNP7v0rlcEGmVraEt8QAAA3c"]
[Tue Jul 21 07:34:28.719344 2026] [autoindex:error] [pid 254995:tid 255144] [client 66.132.172.218:4136] AH01276: Cannot serve directory /home4/dralul00/deiacakes.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:34:28.845856 2026] [security2:error] [pid 254995:tid 255031] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LM_7v0rlcEGmVraEt5QADlyM"]
[Tue Jul 21 07:34:28.846121 2026] [security2:error] [pid 254995:tid 255273] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LM_7v0rlcEGmVraEt5QADlyM"]
[Tue Jul 21 07:34:29.032628 2026] [security2:error] [pid 254995:tid 255193] [client 20.197.195.24:13114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/gettest.php"] [unique_id "al9LNf7v0rlcEGmVraEt-gAAA2I"]
[Tue Jul 21 07:34:29.111700 2026] [security2:error] [pid 254995:tid 255137] [client 139.167.225.182:52395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LNf7v0rlcEGmVraEt-wAAAyo"]
[Tue Jul 21 07:34:29.111798 2026] [security2:error] [pid 254995:tid 255137] [client 139.167.225.182:52395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LNf7v0rlcEGmVraEt-wAAAyo"]
[Tue Jul 21 07:34:29.356544 2026] [security2:error] [pid 255769:tid 255853] [remote 65.111.0.247:58643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.0.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9LNbxMYwyVGnfuwsKIPgADuVM"]
[Tue Jul 21 07:34:29.743010 2026] [security2:error] [pid 254995:tid 255222] [client 20.197.195.24:13141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/min.php"] [unique_id "al9LNf7v0rlcEGmVraEuCwAAA34"]
[Tue Jul 21 07:34:29.774904 2026] [security2:error] [pid 254995:tid 255168] [client 20.220.225.223:49798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/kua.php"] [unique_id "al9LNf7v0rlcEGmVraEuDQAAA0k"]
[Tue Jul 21 07:34:29.837943 2026] [security2:error] [pid 254995:tid 255254] [client 20.52.136.55:1497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/ini.php"] [unique_id "al9LNf7v0rlcEGmVraEuEAAAA4Q"]
[Tue Jul 21 07:34:30.087019 2026] [autoindex:error] [pid 255769:tid 255828] [remote 2a03:2880:10ff:7:::0] AH01276: Cannot serve directory /home1/bastar15/lacorsini.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:34:30.248412 2026] [security2:error] [pid 255769:tid 256008] [client 193.36.225.140:38345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LNrxMYwyVGnfuwsKIPwAABA4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:30.464068 2026] [security2:error] [pid 254995:tid 255278] [client 117.251.86.144:58636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LNv7v0rlcEGmVraEuGwAAA5w"]
[Tue Jul 21 07:34:30.464201 2026] [security2:error] [pid 254995:tid 255278] [client 117.251.86.144:58636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LNv7v0rlcEGmVraEuGwAAA5w"]
[Tue Jul 21 07:34:30.563464 2026] [security2:error] [pid 254995:tid 255272] [client 20.220.225.223:56504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.barcob.com"] [uri "/ms.php"] [unique_id "al9LNv7v0rlcEGmVraEuHwAAA5Y"]
[Tue Jul 21 07:34:30.703205 2026] [security2:error] [pid 255769:tid 255919] [client 20.220.225.223:31179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/term.php"] [unique_id "al9LNrxMYwyVGnfuwsKIQwAAA7c"]
[Tue Jul 21 07:34:30.791912 2026] [security2:error] [pid 254995:tid 255256] [client 103.162.129.114:64274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LNv7v0rlcEGmVraEuIAAAA4Y"]
[Tue Jul 21 07:34:30.792019 2026] [security2:error] [pid 254995:tid 255256] [client 103.162.129.114:64274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LNv7v0rlcEGmVraEuIAAAA4Y"]
[Tue Jul 21 07:34:30.889007 2026] [security2:error] [pid 254995:tid 255208] [client 45.8.17.125:46583] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/responsive-lightbox/assets/nivo/themes/wp-load.php"] [unique_id "al9LNv7v0rlcEGmVraEuIwAAA3A"]
[Tue Jul 21 07:34:30.895419 2026] [security2:error] [pid 255769:tid 255998] [client 20.197.195.24:48836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/dvjul.php"] [unique_id "al9LNrxMYwyVGnfuwsKIRQAABAQ"]
[Tue Jul 21 07:34:31.074524 2026] [rewrite:error] [pid 254995:tid 255194] [client 187.49.76.218:18273] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2410
[Tue Jul 21 07:34:31.074629 2026] [rewrite:error] [pid 255769:tid 255986] [client 187.49.76.218:18241] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2410
[Tue Jul 21 07:34:31.075020 2026] [rewrite:error] [pid 254995:tid 255156] [client 187.49.76.218:18177] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2410
[Tue Jul 21 07:34:31.209493 2026] [security2:error] [pid 254995:tid 255260] [client 172.245.102.44:51955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LN_7v0rlcEGmVraEuKQAAA4o"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:31.396513 2026] [security2:error] [pid 254995:tid 255184] [client 122.186.204.214:64684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LN_7v0rlcEGmVraEuMAAAA1k"]
[Tue Jul 21 07:34:31.396633 2026] [security2:error] [pid 254995:tid 255184] [client 122.186.204.214:64684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LN_7v0rlcEGmVraEuMAAAA1k"]
[Tue Jul 21 07:34:32.049345 2026] [security2:error] [pid 255769:tid 256017] [client 20.220.225.223:25431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/xyn.php"] [unique_id "al9LOLxMYwyVGnfuwsKITwAABBc"]
[Tue Jul 21 07:34:32.117668 2026] [security2:error] [pid 254995:tid 255205] [client 173.24.185.52:63655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuQgAAA24"]
[Tue Jul 21 07:34:32.117779 2026] [security2:error] [pid 254995:tid 255205] [client 173.24.185.52:63655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuQgAAA24"]
[Tue Jul 21 07:34:32.127642 2026] [security2:error] [pid 255769:tid 255777] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LOLxMYwyVGnfuwsKIUQADvQc"]
[Tue Jul 21 07:34:32.127759 2026] [security2:error] [pid 255769:tid 255925] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LOLxMYwyVGnfuwsKIUQADvQc"]
[Tue Jul 21 07:34:32.219624 2026] [security2:error] [pid 254995:tid 255155] [client 59.96.220.140:50564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuRAAAAzw"]
[Tue Jul 21 07:34:32.219755 2026] [security2:error] [pid 254995:tid 255155] [client 59.96.220.140:50564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuRAAAAzw"]
[Tue Jul 21 07:34:32.281030 2026] [security2:error] [pid 254995:tid 254999] [remote 195.26.244.42:58580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/wp-login.php"] [unique_id "al9LOP7v0rlcEGmVraEuRgADiAM"]
[Tue Jul 21 07:34:32.357588 2026] [security2:error] [pid 254995:tid 255154] [client 45.251.232.145:56356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuSAAAAzs"]
[Tue Jul 21 07:34:32.357668 2026] [security2:error] [pid 254995:tid 255154] [client 45.251.232.145:56356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuSAAAAzs"]
[Tue Jul 21 07:34:32.542188 2026] [security2:error] [pid 255769:tid 255961] [client 172.245.102.34:52363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LOLxMYwyVGnfuwsKIVQAAA-E"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:32.679242 2026] [security2:error] [pid 255769:tid 255993] [client 45.8.17.107:64621] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/responsive-lightbox/assets/jstree/themes/system.php"] [unique_id "al9LOLxMYwyVGnfuwsKIXAAABAA"]
[Tue Jul 21 07:34:32.685822 2026] [security2:error] [pid 255769:tid 255927] [client 20.220.225.223:49587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/berlin.php"] [unique_id "al9LOLxMYwyVGnfuwsKIXQAAA78"]
[Tue Jul 21 07:34:32.693765 2026] [security2:error] [pid 255769:tid 255946] [client 20.220.225.223:48156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ez.php"] [unique_id "al9LOLxMYwyVGnfuwsKIXgAAA9I"]
[Tue Jul 21 07:34:32.741595 2026] [security2:error] [pid 255769:tid 255893] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOLxMYwyVGnfuwsKIXwADp3s"]
[Tue Jul 21 07:34:32.741750 2026] [security2:error] [pid 255769:tid 255903] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOLxMYwyVGnfuwsKIXwADp3s"]
[Tue Jul 21 07:34:32.753076 2026] [security2:error] [pid 254995:tid 255129] [client 122.162.144.145:10387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuTwAAAyI"]
[Tue Jul 21 07:34:32.753191 2026] [security2:error] [pid 254995:tid 255129] [client 122.162.144.145:10387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LOP7v0rlcEGmVraEuTwAAAyI"]
[Tue Jul 21 07:34:33.043792 2026] [security2:error] [pid 255769:tid 255815] [remote 124.55.178.99:41810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9LObxMYwyVGnfuwsKIYgAD7C0"]
[Tue Jul 21 07:34:33.339232 2026] [security2:error] [pid 255769:tid 256022] [client 103.106.20.201:58211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LObxMYwyVGnfuwsKIagAABBw"]
[Tue Jul 21 07:34:33.339358 2026] [security2:error] [pid 255769:tid 256022] [client 103.106.20.201:58211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LObxMYwyVGnfuwsKIagAABBw"]
[Tue Jul 21 07:34:33.565908 2026] [security2:error] [pid 255769:tid 255973] [client 20.197.195.24:13150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/biufile.php"] [unique_id "al9LObxMYwyVGnfuwsKIbQAAA-0"]
[Tue Jul 21 07:34:33.590552 2026] [security2:error] [pid 255769:tid 255969] [client 45.8.17.130:59973] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/contact-form-7/includes/js/jquery-ui/themes/data.php"] [unique_id "al9LObxMYwyVGnfuwsKIbgAAA-k"]
[Tue Jul 21 07:34:33.795699 2026] [security2:error] [pid 254995:tid 255224] [client 117.217.38.194:60215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOf7v0rlcEGmVraEuYQAAA4A"]
[Tue Jul 21 07:34:33.795841 2026] [security2:error] [pid 254995:tid 255224] [client 117.217.38.194:60215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOf7v0rlcEGmVraEuYQAAA4A"]
[Tue Jul 21 07:34:34.107785 2026] [security2:error] [pid 255769:tid 255974] [client 20.220.225.223:23454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/cro.php"] [unique_id "al9LOrxMYwyVGnfuwsKIdAAAA-4"]
[Tue Jul 21 07:34:34.142127 2026] [security2:error] [pid 255769:tid 255994] [client 154.192.233.199:60372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOrxMYwyVGnfuwsKIdQAABAE"]
[Tue Jul 21 07:34:34.142269 2026] [security2:error] [pid 255769:tid 255994] [client 154.192.233.199:60372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOrxMYwyVGnfuwsKIdQAABAE"]
[Tue Jul 21 07:34:34.396727 2026] [security2:error] [pid 255769:tid 255771] [remote 45.3.41.95:50043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9LObxMYwyVGnfuwsKIawADuQE"]
[Tue Jul 21 07:34:34.693867 2026] [security2:error] [pid 255769:tid 256017] [client 45.8.17.118:36155] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/windazo/inc/plugins/wp-blog-header.php"] [unique_id "al9LOrxMYwyVGnfuwsKIegAABBc"]
[Tue Jul 21 07:34:34.696664 2026] [security2:error] [pid 255769:tid 255936] [client 20.220.225.223:59167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/cron-tab.php"] [unique_id "al9LOrxMYwyVGnfuwsKIewAAA8g"]
[Tue Jul 21 07:34:34.900381 2026] [security2:error] [pid 255769:tid 255998] [client 193.36.225.55:48623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LOrxMYwyVGnfuwsKIfgAABAQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:34.966808 2026] [security2:error] [pid 254995:tid 255137] [client 175.45.70.82:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOv7v0rlcEGmVraEudQAAAyo"]
[Tue Jul 21 07:34:34.966949 2026] [security2:error] [pid 254995:tid 255137] [client 175.45.70.82:58750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LOv7v0rlcEGmVraEudQAAAyo"]
[Tue Jul 21 07:34:35.249748 2026] [security2:error] [pid 254995:tid 255134] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LO_7v0rlcEGmVraEuewADJzg"]
[Tue Jul 21 07:34:35.450228 2026] [security2:error] [pid 254995:tid 255211] [client 213.14.231.164:3316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.231.14.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "health-24.shop"] [uri "/xmlrpc.php"] [unique_id "al9LO_7v0rlcEGmVraEufQAAA3M"]
[Tue Jul 21 07:34:35.450373 2026] [security2:error] [pid 254995:tid 255211] [client 213.14.231.164:3316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "health-24.shop"] [uri "/xmlrpc.php"] [unique_id "al9LO_7v0rlcEGmVraEufQAAA3M"]
[Tue Jul 21 07:34:35.602825 2026] [security2:error] [pid 254995:tid 255087] [remote 97.74.87.194:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9LO_7v0rlcEGmVraEugQADg1s"]
[Tue Jul 21 07:34:35.705352 2026] [security2:error] [pid 255769:tid 256021] [client 20.220.225.223:23425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/koiy.php"] [unique_id "al9LO7xMYwyVGnfuwsKIhgAABBs"]
[Tue Jul 21 07:34:35.786655 2026] [security2:error] [pid 254995:tid 255277] [client 45.8.17.63:63927] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/js_composer/include/classes/vendors/plugins/api.php"] [unique_id "al9LO_7v0rlcEGmVraEujgAAA5s"]
[Tue Jul 21 07:34:35.958583 2026] [security2:error] [pid 255769:tid 256012] [client 213.152.162.104:32866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LO7xMYwyVGnfuwsKIiQAABBI"]
[Tue Jul 21 07:34:35.958696 2026] [security2:error] [pid 255769:tid 256012] [client 213.152.162.104:32866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LO7xMYwyVGnfuwsKIiQAABBI"]
[Tue Jul 21 07:34:35.991438 2026] [security2:error] [pid 254995:tid 255067] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LO_7v0rlcEGmVraEukQADVEc"]
[Tue Jul 21 07:34:35.991574 2026] [security2:error] [pid 254995:tid 255179] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LO_7v0rlcEGmVraEukQADVEc"]
[Tue Jul 21 07:34:36.021426 2026] [security2:error] [pid 255769:tid 255922] [client 103.174.34.15:50853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPLxMYwyVGnfuwsKIiwAAA7o"]
[Tue Jul 21 07:34:36.021536 2026] [security2:error] [pid 255769:tid 255922] [client 103.174.34.15:50853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPLxMYwyVGnfuwsKIiwAAA7o"]
[Tue Jul 21 07:34:36.148101 2026] [security2:error] [pid 254995:tid 255117] [remote 49.12.216.176:35468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9LPP7v0rlcEGmVraEulwADZnk"]
[Tue Jul 21 07:34:36.561925 2026] [security2:error] [pid 254995:tid 255129] [client 152.59.154.239:50901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPP7v0rlcEGmVraEuoQAAAyI"]
[Tue Jul 21 07:34:36.566622 2026] [security2:error] [pid 254995:tid 255129] [client 152.59.154.239:50901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPP7v0rlcEGmVraEuoQAAAyI"]
[Tue Jul 21 07:34:36.582520 2026] [security2:error] [pid 255769:tid 255889] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPLxMYwyVGnfuwsKIlgAEHHc"]
[Tue Jul 21 07:34:36.582745 2026] [security2:error] [pid 255769:tid 256022] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPLxMYwyVGnfuwsKIlgAEHHc"]
[Tue Jul 21 07:34:36.700116 2026] [security2:error] [pid 255769:tid 255989] [client 20.197.195.24:13127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/av.php"] [unique_id "al9LPLxMYwyVGnfuwsKInAAAA_0"]
[Tue Jul 21 07:34:36.949975 2026] [security2:error] [pid 254995:tid 255268] [client 20.220.225.223:38718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/ah25.php"] [unique_id "al9LPP7v0rlcEGmVraEuqQAAA5I"]
[Tue Jul 21 07:34:37.045800 2026] [security2:error] [pid 254995:tid 255137] [client 85.208.96.204:13620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9LPf7v0rlcEGmVraEuqwAAAyo"]
[Tue Jul 21 07:34:37.045971 2026] [security2:error] [pid 254995:tid 255137] [client 85.208.96.204:13620] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9LPf7v0rlcEGmVraEuqwAAAyo"]
[Tue Jul 21 07:34:37.094658 2026] [security2:error] [pid 254995:tid 255274] [client 45.8.17.130:32061] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/stockholm/woocommerce/single-product/add-to-cart/internal.php"] [unique_id "al9LPf7v0rlcEGmVraEurAAAA5g"]
[Tue Jul 21 07:34:37.402708 2026] [security2:error] [pid 255769:tid 255947] [client 85.208.96.201:39294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9LPbxMYwyVGnfuwsKIogAAA9M"]
[Tue Jul 21 07:34:37.402872 2026] [security2:error] [pid 255769:tid 255947] [client 85.208.96.201:39294] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9LPbxMYwyVGnfuwsKIogAAA9M"]
[Tue Jul 21 07:34:37.740091 2026] [security2:error] [pid 255769:tid 255918] [client 74.7.244.14:37926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "evolutionlisbon.kettlebellevolution.com.br"] [uri "/index.php"] [unique_id "al9LPbxMYwyVGnfuwsKIngADtgQ"]
[Tue Jul 21 07:34:37.893888 2026] [security2:error] [pid 255769:tid 255908] [client 20.52.136.55:1762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/themes.php"] [unique_id "al9LPbxMYwyVGnfuwsKIqAAAA6w"]
[Tue Jul 21 07:34:37.927735 2026] [security2:error] [pid 255769:tid 255800] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LPbxMYwyVGnfuwsKIqQAD5B4"]
[Tue Jul 21 07:34:37.927931 2026] [security2:error] [pid 255769:tid 255964] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LPbxMYwyVGnfuwsKIqQAD5B4"]
[Tue Jul 21 07:34:38.187641 2026] [security2:error] [pid 255769:tid 255950] [client 45.8.17.73:41767] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-template/index.php"] [unique_id "al9LPrxMYwyVGnfuwsKIqwAAA9Y"]
[Tue Jul 21 07:34:38.315824 2026] [security2:error] [pid 255769:tid 255784] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIsAADyw4"]
[Tue Jul 21 07:34:38.315948 2026] [security2:error] [pid 255769:tid 255939] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIsAADyw4"]
[Tue Jul 21 07:34:38.601569 2026] [security2:error] [pid 255769:tid 255906] [client 59.96.220.140:51072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIugAAA6o"]
[Tue Jul 21 07:34:38.602337 2026] [security2:error] [pid 255769:tid 255906] [client 59.96.220.140:51072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIugAAA6o"]
[Tue Jul 21 07:34:38.744628 2026] [security2:error] [pid 255769:tid 255877] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIwgADyms"]
[Tue Jul 21 07:34:38.744763 2026] [security2:error] [pid 255769:tid 255938] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIwgADyms"]
[Tue Jul 21 07:34:38.756343 2026] [security2:error] [pid 255769:tid 255775] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIxAADtAU"]
[Tue Jul 21 07:34:38.756485 2026] [security2:error] [pid 255769:tid 255916] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LPrxMYwyVGnfuwsKIxAADtAU"]
[Tue Jul 21 07:34:38.929935 2026] [security2:error] [pid 254995:tid 255099] [remote 130.185.118.215:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/wp-login.php"] [unique_id "al9LPv7v0rlcEGmVraEu0wADPmc"]
[Tue Jul 21 07:34:39.210137 2026] [security2:error] [pid 255769:tid 255929] [client 20.220.225.223:49561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/fz.php"] [unique_id "al9LP7xMYwyVGnfuwsKI0QAAA8E"]
[Tue Jul 21 07:34:39.486476 2026] [security2:error] [pid 255769:tid 256010] [client 139.167.225.182:53030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LP7xMYwyVGnfuwsKI2wAABBA"]
[Tue Jul 21 07:34:39.486590 2026] [security2:error] [pid 255769:tid 256010] [client 139.167.225.182:53030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LP7xMYwyVGnfuwsKI2wAABBA"]
[Tue Jul 21 07:34:39.654665 2026] [security2:error] [pid 255769:tid 255905] [client 20.206.105.145:39123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9LP7xMYwyVGnfuwsKI4QAAA6k"]
[Tue Jul 21 07:34:39.690460 2026] [security2:error] [pid 255769:tid 255962] [client 45.8.17.141:62879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "al9LP7xMYwyVGnfuwsKI5AAAA-I"]
[Tue Jul 21 07:34:39.861291 2026] [security2:error] [pid 255769:tid 255902] [client 136.144.33.99:48087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LP7xMYwyVGnfuwsKI4wAAA6Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:39.877476 2026] [security2:error] [pid 255769:tid 255930] [client 20.220.225.223:23429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/hp2.php"] [unique_id "al9LP7xMYwyVGnfuwsKI6QAAA8I"]
[Tue Jul 21 07:34:40.163734 2026] [security2:error] [pid 254995:tid 255162] [client 20.197.195.24:13132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/coffexium.php"] [unique_id "al9LQP7v0rlcEGmVraEu3wAAA0M"]
[Tue Jul 21 07:34:40.893160 2026] [security2:error] [pid 255769:tid 255900] [client 45.8.17.134:28335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/dist/block-directory/index.php"] [unique_id "al9LQLxMYwyVGnfuwsKI9wAAA6Q"]
[Tue Jul 21 07:34:41.276439 2026] [security2:error] [pid 254995:tid 255209] [client 103.162.129.114:64712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LQf7v0rlcEGmVraEu7wAAA3E"]
[Tue Jul 21 07:34:41.276545 2026] [security2:error] [pid 254995:tid 255209] [client 103.162.129.114:64712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LQf7v0rlcEGmVraEu7wAAA3E"]
[Tue Jul 21 07:34:41.314941 2026] [security2:error] [pid 255769:tid 255926] [client 117.251.86.144:37556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LQbxMYwyVGnfuwsKI_AAAA74"]
[Tue Jul 21 07:34:41.315073 2026] [security2:error] [pid 255769:tid 255926] [client 117.251.86.144:37556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LQbxMYwyVGnfuwsKI_AAAA74"]
[Tue Jul 21 07:34:41.320866 2026] [security2:error] [pid 255769:tid 255959] [client 109.248.148.246:48390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LQbxMYwyVGnfuwsKI_gAAA98"]
[Tue Jul 21 07:34:41.320971 2026] [security2:error] [pid 255769:tid 255959] [client 109.248.148.246:48390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LQbxMYwyVGnfuwsKI_gAAA98"]
[Tue Jul 21 07:34:41.364698 2026] [security2:error] [pid 255769:tid 255969] [client 122.129.67.13:59690] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LQbxMYwyVGnfuwsKJAAAAA-k"]
[Tue Jul 21 07:34:41.364862 2026] [security2:error] [pid 255769:tid 255969] [client 122.129.67.13:59690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LQbxMYwyVGnfuwsKJAAAAA-k"]
[Tue Jul 21 07:34:41.731933 2026] [security2:error] [pid 255769:tid 255856] [remote 34.91.119.153:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "alangefersonsouzabat1751481531845.0721679.meusitehostgator.com.br"] [uri "/"] [unique_id "al9LQbxMYwyVGnfuwsKJBgAEF1Y"]
[Tue Jul 21 07:34:41.732135 2026] [security2:error] [pid 255769:tid 256017] [client 34.91.119.153:0] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alangefersonsouzabat1751481531845.0721679.meusitehostgator.com.br"] [uri "/"] [unique_id "al9LQbxMYwyVGnfuwsKJBgAEF1Y"]
[Tue Jul 21 07:34:41.877333 2026] [security2:error] [pid 255769:tid 256003] [client 20.197.195.24:13112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/core.php"] [unique_id "al9LQbxMYwyVGnfuwsKJCwAABAk"]
[Tue Jul 21 07:34:41.881049 2026] [security2:error] [pid 254995:tid 255167] [client 45.8.17.140:62769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "al9LQf7v0rlcEGmVraEu-AAAA0g"]
[Tue Jul 21 07:34:42.116466 2026] [security2:error] [pid 255769:tid 256004] [client 122.186.204.214:65184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LQrxMYwyVGnfuwsKJDQAABAo"]
[Tue Jul 21 07:34:42.116582 2026] [security2:error] [pid 255769:tid 256004] [client 122.186.204.214:65184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LQrxMYwyVGnfuwsKJDQAABAo"]
[Tue Jul 21 07:34:42.191087 2026] [security2:error] [pid 255769:tid 255787] [remote 216.73.216.238:7748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/casa.php"] [unique_id "al9LQrxMYwyVGnfuwsKJDwAD2xE"]
[Tue Jul 21 07:34:42.249762 2026] [security2:error] [pid 254995:tid 255179] [client 82.102.28.107:56996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LQv7v0rlcEGmVraEvAQAAA1Q"]
[Tue Jul 21 07:34:42.249870 2026] [security2:error] [pid 254995:tid 255179] [client 82.102.28.107:56996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LQv7v0rlcEGmVraEvAQAAA1Q"]
[Tue Jul 21 07:34:42.721707 2026] [security2:error] [pid 254995:tid 255204] [client 173.24.185.52:64150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LQv7v0rlcEGmVraEvCQAAA20"]
[Tue Jul 21 07:34:42.721810 2026] [security2:error] [pid 254995:tid 255204] [client 173.24.185.52:64150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LQv7v0rlcEGmVraEvCQAAA20"]
[Tue Jul 21 07:34:42.834370 2026] [security2:error] [pid 254995:tid 255254] [client 45.251.232.145:56891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LQv7v0rlcEGmVraEvCgAAA4Q"]
[Tue Jul 21 07:34:42.834477 2026] [security2:error] [pid 254995:tid 255254] [client 45.251.232.145:56891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LQv7v0rlcEGmVraEvCgAAA4Q"]
[Tue Jul 21 07:34:42.892309 2026] [security2:error] [pid 255769:tid 255833] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LQrxMYwyVGnfuwsKJHgADvz8"]
[Tue Jul 21 07:34:42.892459 2026] [security2:error] [pid 255769:tid 255927] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LQrxMYwyVGnfuwsKJHgADvz8"]
[Tue Jul 21 07:34:43.281482 2026] [security2:error] [pid 255769:tid 255891] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LQ7xMYwyVGnfuwsKJJgADynk"]
[Tue Jul 21 07:34:43.281615 2026] [security2:error] [pid 255769:tid 255938] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LQ7xMYwyVGnfuwsKJJgADynk"]
[Tue Jul 21 07:34:43.287674 2026] [security2:error] [pid 255769:tid 255986] [client 45.8.17.134:51065] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "al9LQ7xMYwyVGnfuwsKJJwAAA_o"]
[Tue Jul 21 07:34:43.338031 2026] [security2:error] [pid 254995:tid 255054] [remote 188.95.113.76:41894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kaducontractor.com"] [uri "/wp-login.php"] [unique_id "al9LQ_7v0rlcEGmVraEvDwADVjo"]
[Tue Jul 21 07:34:43.566639 2026] [security2:error] [pid 255769:tid 256006] [client 122.162.144.145:2913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LQ7xMYwyVGnfuwsKJLwAABAw"]
[Tue Jul 21 07:34:43.566758 2026] [security2:error] [pid 255769:tid 256006] [client 122.162.144.145:2913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LQ7xMYwyVGnfuwsKJLwAABAw"]
[Tue Jul 21 07:34:44.015832 2026] [security2:error] [pid 255769:tid 256004] [client 20.220.225.223:49586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/la.php"] [unique_id "al9LRLxMYwyVGnfuwsKJOAAABAo"]
[Tue Jul 21 07:34:44.046598 2026] [security2:error] [pid 255769:tid 256014] [client 103.106.20.201:58791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRLxMYwyVGnfuwsKJOQAABBQ"]
[Tue Jul 21 07:34:44.046742 2026] [security2:error] [pid 255769:tid 256014] [client 103.106.20.201:58791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRLxMYwyVGnfuwsKJOQAABBQ"]
[Tue Jul 21 07:34:44.207145 2026] [security2:error] [pid 255769:tid 256021] [client 20.206.105.145:39267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/bob.php"] [unique_id "al9LRLxMYwyVGnfuwsKJPQAABBs"]
[Tue Jul 21 07:34:44.314742 2026] [security2:error] [pid 255769:tid 255941] [client 117.217.38.194:60662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRLxMYwyVGnfuwsKJRAAAA80"]
[Tue Jul 21 07:34:44.314863 2026] [security2:error] [pid 255769:tid 255941] [client 117.217.38.194:60662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRLxMYwyVGnfuwsKJRAAAA80"]
[Tue Jul 21 07:34:44.385052 2026] [security2:error] [pid 255769:tid 255976] [client 20.197.195.24:13085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/als.php"] [unique_id "al9LRLxMYwyVGnfuwsKJRgAAA_A"]
[Tue Jul 21 07:34:44.454277 2026] [security2:error] [pid 255769:tid 255927] [client 20.220.225.223:24196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/byp8.php"] [unique_id "al9LRLxMYwyVGnfuwsKJSAAAA78"]
[Tue Jul 21 07:34:44.484087 2026] [security2:error] [pid 255769:tid 255973] [client 45.8.17.105:22165] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9LRLxMYwyVGnfuwsKJSgAAA-0"]
[Tue Jul 21 07:34:44.537085 2026] [security2:error] [pid 255769:tid 256022] [client 82.102.28.107:56998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LRLxMYwyVGnfuwsKJSwAABBw"]
[Tue Jul 21 07:34:44.537185 2026] [security2:error] [pid 255769:tid 256022] [client 82.102.28.107:56998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LRLxMYwyVGnfuwsKJSwAABBw"]
[Tue Jul 21 07:34:44.599565 2026] [security2:error] [pid 254995:tid 255256] [client 193.36.225.10:33627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LRP7v0rlcEGmVraEvHwAAA4Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:44.616626 2026] [security2:error] [pid 255769:tid 255948] [client 20.197.195.24:62700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9LRLxMYwyVGnfuwsKJTwAAA9Q"]
[Tue Jul 21 07:34:44.838848 2026] [security2:error] [pid 254995:tid 255194] [client 154.192.233.199:59275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRP7v0rlcEGmVraEvIwAAA2M"]
[Tue Jul 21 07:34:44.838949 2026] [security2:error] [pid 254995:tid 255194] [client 154.192.233.199:59275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRP7v0rlcEGmVraEvIwAAA2M"]
[Tue Jul 21 07:34:45.186855 2026] [security2:error] [pid 255769:tid 255952] [client 104.196.214.11:61135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.214.196.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oab.arcoll.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRbxMYwyVGnfuwsKJXAAAA9g"]
[Tue Jul 21 07:34:45.361861 2026] [security2:error] [pid 254995:tid 255189] [client 20.220.225.223:23451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/hp3.php"] [unique_id "al9LRf7v0rlcEGmVraEvKgAAA14"]
[Tue Jul 21 07:34:45.366833 2026] [security2:error] [pid 255769:tid 256009] [client 20.52.136.55:1536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/dropdown.php"] [unique_id "al9LRbxMYwyVGnfuwsKJXgAABA8"]
[Tue Jul 21 07:34:45.597360 2026] [security2:error] [pid 254995:tid 255134] [client 45.8.17.139:52433] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "al9LRf7v0rlcEGmVraEvLQAAAyc"]
[Tue Jul 21 07:34:45.651540 2026] [security2:error] [pid 255769:tid 255953] [client 175.45.70.82:59261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRbxMYwyVGnfuwsKJZQAAA9k"]
[Tue Jul 21 07:34:45.651689 2026] [security2:error] [pid 255769:tid 255953] [client 175.45.70.82:59261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRbxMYwyVGnfuwsKJZQAAA9k"]
[Tue Jul 21 07:34:45.703899 2026] [security2:error] [pid 255769:tid 256004] [client 20.220.225.223:38696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/8.php"] [unique_id "al9LRbxMYwyVGnfuwsKJZgAABAo"]
[Tue Jul 21 07:34:45.782762 2026] [security2:error] [pid 254995:tid 255275] [client 20.197.195.24:62621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9LRf7v0rlcEGmVraEvNgAAA5k"]
[Tue Jul 21 07:34:46.054106 2026] [security2:error] [pid 255769:tid 255961] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LRbxMYwyVGnfuwsKJbgAD4Sw"]
[Tue Jul 21 07:34:46.096398 2026] [security2:error] [pid 255769:tid 255907] [client 20.197.195.24:48800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/simple.php"] [unique_id "al9LRrxMYwyVGnfuwsKJcQAAA6s"]
[Tue Jul 21 07:34:46.199434 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:46.199502 2026] [proxy_http:error] [pid 255769:tid 255964] [client 20.206.105.145:38915] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:46.200213 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:46.200243 2026] [proxy_http:error] [pid 255769:tid 255964] [client 20.206.105.145:38915] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:46.298578 2026] [security2:error] [pid 254995:tid 255177] [client 213.152.162.104:34914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LRv7v0rlcEGmVraEvQQAAA1I"]
[Tue Jul 21 07:34:46.298675 2026] [security2:error] [pid 254995:tid 255177] [client 213.152.162.104:34914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LRv7v0rlcEGmVraEvQQAAA1I"]
[Tue Jul 21 07:34:46.383471 2026] [security2:error] [pid 255769:tid 256027] [client 74.7.230.33:59540] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "kolkehillot.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9LRrxMYwyVGnfuwsKJegAEIQg"]
[Tue Jul 21 07:34:46.412743 2026] [security2:error] [pid 255769:tid 256024] [client 20.220.225.223:49803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/nhvoanpl.php"] [unique_id "al9LRrxMYwyVGnfuwsKJfAAABB4"]
[Tue Jul 21 07:34:46.501365 2026] [security2:error] [pid 255769:tid 255859] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LRrxMYwyVGnfuwsKJfQAEBVk"]
[Tue Jul 21 07:34:46.501529 2026] [security2:error] [pid 255769:tid 255999] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LRrxMYwyVGnfuwsKJfQAEBVk"]
[Tue Jul 21 07:34:46.685883 2026] [security2:error] [pid 255769:tid 255990] [client 103.174.34.15:51338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRrxMYwyVGnfuwsKJgAAAA_4"]
[Tue Jul 21 07:34:46.686015 2026] [security2:error] [pid 255769:tid 255990] [client 103.174.34.15:51338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LRrxMYwyVGnfuwsKJgAAAA_4"]
[Tue Jul 21 07:34:46.838865 2026] [security2:error] [pid 255769:tid 256015] [client 20.197.195.24:62628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/media.php"] [unique_id "al9LRrxMYwyVGnfuwsKJhgAABBU"]
[Tue Jul 21 07:34:46.883309 2026] [security2:error] [pid 255769:tid 255996] [client 45.8.17.115:60067] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/wp-conflg.php"] [unique_id "al9LRrxMYwyVGnfuwsKJhwAABAI"]
[Tue Jul 21 07:34:47.218428 2026] [security2:error] [pid 254995:tid 255181] [client 82.102.28.107:55102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LR_7v0rlcEGmVraEvTAAAA1Y"]
[Tue Jul 21 07:34:47.218505 2026] [security2:error] [pid 254995:tid 255181] [client 82.102.28.107:55102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LR_7v0rlcEGmVraEvTAAAA1Y"]
[Tue Jul 21 07:34:47.292153 2026] [security2:error] [pid 254995:tid 255175] [client 20.197.195.24:62677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/images.php"] [unique_id "al9LR_7v0rlcEGmVraEvUgAAA1A"]
[Tue Jul 21 07:34:47.454355 2026] [security2:error] [pid 255769:tid 255933] [client 20.197.195.24:13098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/init.php"] [unique_id "al9LR7xMYwyVGnfuwsKJkgAAA8U"]
[Tue Jul 21 07:34:47.620337 2026] [security2:error] [pid 255769:tid 255909] [client 20.220.225.223:49597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/inso.php"] [unique_id "al9LR7xMYwyVGnfuwsKJlgAAA60"]
[Tue Jul 21 07:34:47.828400 2026] [security2:error] [pid 255769:tid 255843] [remote 45.3.50.206:63361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.50.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9LR7xMYwyVGnfuwsKJngAD5Uk"]
[Tue Jul 21 07:34:48.164613 2026] [security2:error] [pid 255769:tid 255948] [client 20.197.195.24:62682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/gecko.php"] [unique_id "al9LSLxMYwyVGnfuwsKJpAAAA9Q"]
[Tue Jul 21 07:34:48.195895 2026] [security2:error] [pid 254995:tid 255153] [client 45.8.17.63:34411] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/function/function.php"] [unique_id "al9LSP7v0rlcEGmVraEvYAAAAzo"]
[Tue Jul 21 07:34:48.327780 2026] [security2:error] [pid 255769:tid 255990] [client 20.220.225.223:31180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/red.php"] [unique_id "al9LSLxMYwyVGnfuwsKJqAAAA_4"]
[Tue Jul 21 07:34:48.352201 2026] [security2:error] [pid 255769:tid 255935] [client 193.36.225.66:36263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LSLxMYwyVGnfuwsKJqQAAA8c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:48.426913 2026] [security2:error] [pid 254995:tid 255147] [client 37.140.223.138:58911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LSP7v0rlcEGmVraEvYwAAAzQ"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:48.653072 2026] [security2:error] [pid 255769:tid 255790] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LSLxMYwyVGnfuwsKJtAAD3BQ"]
[Tue Jul 21 07:34:48.653264 2026] [security2:error] [pid 255769:tid 255956] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LSLxMYwyVGnfuwsKJtAAD3BQ"]
[Tue Jul 21 07:34:48.752470 2026] [security2:error] [pid 255769:tid 255952] [client 20.197.195.24:62674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/82.php"] [unique_id "al9LSLxMYwyVGnfuwsKJuQAAA9g"]
[Tue Jul 21 07:34:48.969990 2026] [security2:error] [pid 255769:tid 255902] [client 20.220.225.223:19293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/wp-explorer.php"] [unique_id "al9LSLxMYwyVGnfuwsKJvQAAA6Y"]
[Tue Jul 21 07:34:48.975913 2026] [proxy:error] [pid 254995:tid 255276] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:48.975985 2026] [proxy_http:error] [pid 254995:tid 255276] [client 20.206.105.145:39107] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:48.976658 2026] [proxy:error] [pid 254995:tid 255276] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:48.976681 2026] [proxy_http:error] [pid 254995:tid 255276] [client 20.206.105.145:39107] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:49.190239 2026] [security2:error] [pid 255769:tid 255961] [client 109.248.148.246:52208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9LSbxMYwyVGnfuwsKJwQAAA-E"]
[Tue Jul 21 07:34:49.190341 2026] [security2:error] [pid 255769:tid 255961] [client 109.248.148.246:52208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9LSbxMYwyVGnfuwsKJwQAAA-E"]
[Tue Jul 21 07:34:49.209745 2026] [security2:error] [pid 255769:tid 255850] [remote 124.55.178.99:36678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9LSbxMYwyVGnfuwsKJwwAD7lA"]
[Tue Jul 21 07:34:49.209907 2026] [security2:error] [pid 255769:tid 255974] [client 124.55.178.99:36678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9LSbxMYwyVGnfuwsKJwwAD7lA"]
[Tue Jul 21 07:34:49.287056 2026] [security2:error] [pid 255769:tid 255792] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LSbxMYwyVGnfuwsKJxAADrRY"]
[Tue Jul 21 07:34:49.287245 2026] [security2:error] [pid 255769:tid 255909] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LSbxMYwyVGnfuwsKJxAADrRY"]
[Tue Jul 21 07:34:49.299312 2026] [security2:error] [pid 255769:tid 255903] [client 45.8.17.110:59701] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "al9LSbxMYwyVGnfuwsKJxQAAA6c"]
[Tue Jul 21 07:34:49.300893 2026] [security2:error] [pid 254995:tid 255089] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LSf7v0rlcEGmVraEvdgADPF0"]
[Tue Jul 21 07:34:49.301015 2026] [security2:error] [pid 254995:tid 255155] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LSf7v0rlcEGmVraEvdgADPF0"]
[Tue Jul 21 07:34:49.336007 2026] [security2:error] [pid 255769:tid 255870] [remote 216.73.216.238:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/casa.php"] [unique_id "al9LSbxMYwyVGnfuwsKJxwAEDmQ"]
[Tue Jul 21 07:34:49.376106 2026] [security2:error] [pid 254995:tid 255110] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LSf7v0rlcEGmVraEveAADg3I"]
[Tue Jul 21 07:34:49.376237 2026] [security2:error] [pid 254995:tid 255252] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LSf7v0rlcEGmVraEveAADg3I"]
[Tue Jul 21 07:34:49.444619 2026] [security2:error] [pid 255769:tid 256007] [client 20.206.105.145:39258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/crgio.php"] [unique_id "al9LSbxMYwyVGnfuwsKJ0AAABA0"]
[Tue Jul 21 07:34:49.471874 2026] [security2:error] [pid 255769:tid 255957] [client 20.197.195.24:62602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9LSbxMYwyVGnfuwsKJ0QAAA90"]
[Tue Jul 21 07:34:49.910133 2026] [security2:error] [pid 254995:tid 255011] [remote 149.54.9.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.9.54.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LSf7v0rlcEGmVraEvgAADLQ8"]
[Tue Jul 21 07:34:49.910261 2026] [security2:error] [pid 254995:tid 255140] [client 149.54.9.42:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LSf7v0rlcEGmVraEvgAADLQ8"]
[Tue Jul 21 07:34:50.027063 2026] [security2:error] [pid 255769:tid 256026] [client 20.197.195.24:62705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/adminner.php"] [unique_id "al9LSrxMYwyVGnfuwsKJ3AAABCA"]
[Tue Jul 21 07:34:50.133656 2026] [security2:error] [pid 255769:tid 255862] [remote 45.3.39.244:40027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.39.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9LSrxMYwyVGnfuwsKJ3QADqFw"]
[Tue Jul 21 07:34:50.151669 2026] [security2:error] [pid 255769:tid 255972] [client 139.167.225.182:53662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LSrxMYwyVGnfuwsKJ3gAAA-w"]
[Tue Jul 21 07:34:50.151755 2026] [security2:error] [pid 255769:tid 255972] [client 139.167.225.182:53662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LSrxMYwyVGnfuwsKJ3gAAA-w"]
[Tue Jul 21 07:34:50.253482 2026] [security2:error] [pid 255769:tid 255969] [client 59.96.220.140:51573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LSrxMYwyVGnfuwsKJ4AAAA-k"]
[Tue Jul 21 07:34:50.253562 2026] [security2:error] [pid 255769:tid 255969] [client 59.96.220.140:51573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LSrxMYwyVGnfuwsKJ4AAAA-k"]
[Tue Jul 21 07:34:50.384968 2026] [security2:error] [pid 255769:tid 255937] [client 20.206.105.145:39163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/pucci.php"] [unique_id "al9LSrxMYwyVGnfuwsKJ5AAAA8k"]
[Tue Jul 21 07:34:50.661733 2026] [security2:error] [pid 254995:tid 255181] [client 20.10.88.201:61376] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gnxinox.com.br"] [uri "/index.php"] [unique_id "al9LSv7v0rlcEGmVraEvjAAAA1Y"]
[Tue Jul 21 07:34:50.983870 2026] [security2:error] [pid 254995:tid 255198] [client 20.197.195.24:13164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/fpwch.php"] [unique_id "al9LSv7v0rlcEGmVraEvkQAAA2c"]
[Tue Jul 21 07:34:51.012555 2026] [security2:error] [pid 254995:tid 255225] [client 20.220.225.223:6084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/aa1.php"] [unique_id "al9LS_7v0rlcEGmVraEvkwAAA4E"]
[Tue Jul 21 07:34:51.294825 2026] [security2:error] [pid 254995:tid 255163] [client 45.8.17.49:44839] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/upgrade/index.php"] [unique_id "al9LS_7v0rlcEGmVraEvlgAAA0Q"]
[Tue Jul 21 07:34:51.322713 2026] [security2:error] [pid 255769:tid 255927] [client 20.197.195.24:62638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9LS7xMYwyVGnfuwsKJ9QAAA78"]
[Tue Jul 21 07:34:51.447130 2026] [security2:error] [pid 255769:tid 255948] [client 37.140.223.117:23779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LS7xMYwyVGnfuwsKJ-gAAA9Q"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:51.477005 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:51.477075 2026] [proxy_http:error] [pid 254995:tid 255184] [client 20.206.105.145:38925] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:51.477666 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:51.477694 2026] [proxy_http:error] [pid 254995:tid 255184] [client 20.206.105.145:38925] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:51.583072 2026] [access_compat:error] [pid 255769:tid 255910] [client 162.241.63.68:52872] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:34:51.829186 2026] [security2:error] [pid 255769:tid 255936] [client 20.197.195.24:62702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/k.php"] [unique_id "al9LS7xMYwyVGnfuwsKKAAAAA8g"]
[Tue Jul 21 07:34:51.852800 2026] [security2:error] [pid 254995:tid 255193] [client 103.162.129.114:65157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LS_7v0rlcEGmVraEvoAAAA2I"]
[Tue Jul 21 07:34:51.852906 2026] [security2:error] [pid 254995:tid 255193] [client 103.162.129.114:65157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LS_7v0rlcEGmVraEvoAAAA2I"]
[Tue Jul 21 07:34:52.008293 2026] [security2:error] [pid 254995:tid 255256] [client 117.251.86.144:49962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LTP7v0rlcEGmVraEvoQAAA4Y"]
[Tue Jul 21 07:34:52.008389 2026] [security2:error] [pid 254995:tid 255256] [client 117.251.86.144:49962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LTP7v0rlcEGmVraEvoQAAA4Y"]
[Tue Jul 21 07:34:52.284181 2026] [rewrite:error] [pid 255769:tid 256017] [client 187.49.76.218:18625] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:34:52.285719 2026] [rewrite:error] [pid 255769:tid 255913] [client 187.49.76.218:18689] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:34:52.293222 2026] [security2:error] [pid 254995:tid 255205] [client 213.152.162.104:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LTP7v0rlcEGmVraEvpQAAA24"]
[Tue Jul 21 07:34:52.293310 2026] [security2:error] [pid 254995:tid 255205] [client 213.152.162.104:42094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LTP7v0rlcEGmVraEvpQAAA24"]
[Tue Jul 21 07:34:52.304720 2026] [rewrite:error] [pid 255769:tid 255952] [client 187.49.76.218:18721] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:34:52.309398 2026] [proxy:error] [pid 255769:tid 255901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:52.309459 2026] [proxy_http:error] [pid 255769:tid 255901] [client 20.206.105.145:38919] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:52.310132 2026] [proxy:error] [pid 255769:tid 255901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:52.310169 2026] [proxy_http:error] [pid 255769:tid 255901] [client 20.206.105.145:38919] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:52.417090 2026] [security2:error] [pid 255769:tid 255855] [remote 104.207.33.244:45183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9LTLxMYwyVGnfuwsKKDAAD51U"]
[Tue Jul 21 07:34:52.430438 2026] [security2:error] [pid 255769:tid 256014] [client 20.197.195.24:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/blurbs.php"] [unique_id "al9LTLxMYwyVGnfuwsKKFAAABBQ"]
[Tue Jul 21 07:34:52.488463 2026] [security2:error] [pid 255769:tid 255956] [client 45.8.17.63:62549] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "al9LTLxMYwyVGnfuwsKKFgAAA9w"]
[Tue Jul 21 07:34:52.553561 2026] [security2:error] [pid 255769:tid 255922] [client 20.197.195.24:13070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/domvf.php"] [unique_id "al9LTLxMYwyVGnfuwsKKFwAAA7o"]
[Tue Jul 21 07:34:52.642470 2026] [security2:error] [pid 255769:tid 255963] [client 20.220.225.223:49540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wpx.php"] [unique_id "al9LTLxMYwyVGnfuwsKKGQAAA-M"]
[Tue Jul 21 07:34:52.705242 2026] [security2:error] [pid 255769:tid 255941] [client 20.206.105.145:39271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-temp.php"] [unique_id "al9LTLxMYwyVGnfuwsKKGgAAA80"]
[Tue Jul 21 07:34:52.802630 2026] [security2:error] [pid 255769:tid 255918] [client 122.186.204.214:49309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LTLxMYwyVGnfuwsKKHQAAA7Y"]
[Tue Jul 21 07:34:52.802768 2026] [security2:error] [pid 255769:tid 255918] [client 122.186.204.214:49309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LTLxMYwyVGnfuwsKKHQAAA7Y"]
[Tue Jul 21 07:34:52.819221 2026] [proxy:error] [pid 255769:tid 256008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:52.819286 2026] [proxy_http:error] [pid 255769:tid 256008] [client 20.206.105.145:38975] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:52.819783 2026] [proxy:error] [pid 255769:tid 256008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:52.819808 2026] [proxy_http:error] [pid 255769:tid 256008] [client 20.206.105.145:38975] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:52.963364 2026] [security2:error] [pid 254995:tid 255269] [client 20.220.225.223:19264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/akismet.php"] [unique_id "al9LTP7v0rlcEGmVraEvrQAAA5M"]
[Tue Jul 21 07:34:53.042584 2026] [security2:error] [pid 255769:tid 255934] [client 20.197.195.24:62623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/bajah.php"] [unique_id "al9LTbxMYwyVGnfuwsKKJQAAA8Y"]
[Tue Jul 21 07:34:53.238967 2026] [security2:error] [pid 255769:tid 255985] [client 173.24.185.52:64819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKKAAAA_k"]
[Tue Jul 21 07:34:53.239080 2026] [security2:error] [pid 255769:tid 255985] [client 173.24.185.52:64819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKKAAAA_k"]
[Tue Jul 21 07:34:53.305504 2026] [security2:error] [pid 255769:tid 255944] [client 45.251.232.145:57414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKLAAAA9A"]
[Tue Jul 21 07:34:53.306126 2026] [security2:error] [pid 255769:tid 255944] [client 45.251.232.145:57414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKLAAAA9A"]
[Tue Jul 21 07:34:53.477416 2026] [security2:error] [pid 254995:tid 255268] [client 136.144.33.111:33971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LTf7v0rlcEGmVraEvsgAAA5I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:53.569008 2026] [security2:error] [pid 254995:tid 255133] [client 82.102.28.107:54454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9LTf7v0rlcEGmVraEvuQAAAyY"]
[Tue Jul 21 07:34:53.569182 2026] [security2:error] [pid 254995:tid 255133] [client 82.102.28.107:54454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9LTf7v0rlcEGmVraEvuQAAAyY"]
[Tue Jul 21 07:34:53.570795 2026] [security2:error] [pid 255769:tid 256024] [client 20.220.225.223:24233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/user.php"] [unique_id "al9LTbxMYwyVGnfuwsKKMAAABB4"]
[Tue Jul 21 07:34:53.583054 2026] [security2:error] [pid 255769:tid 255878] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKMQADrmw"]
[Tue Jul 21 07:34:53.583218 2026] [security2:error] [pid 255769:tid 255910] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKMQADrmw"]
[Tue Jul 21 07:34:53.744561 2026] [security2:error] [pid 255769:tid 255929] [client 20.197.195.24:62692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/a.php"] [unique_id "al9LTbxMYwyVGnfuwsKKNgAAA8E"]
[Tue Jul 21 07:34:53.810332 2026] [rewrite:error] [pid 255769:tid 255969] [client 187.49.76.218:18721] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2411
[Tue Jul 21 07:34:53.810729 2026] [rewrite:error] [pid 255769:tid 255998] [client 187.49.76.218:18689] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2411
[Tue Jul 21 07:34:53.812966 2026] [rewrite:error] [pid 255769:tid 256006] [client 187.49.76.218:18625] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2411
[Tue Jul 21 07:34:53.842212 2026] [security2:error] [pid 255769:tid 255783] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKPQADsw0"]
[Tue Jul 21 07:34:53.842321 2026] [security2:error] [pid 255769:tid 255915] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTbxMYwyVGnfuwsKKPQADsw0"]
[Tue Jul 21 07:34:53.885141 2026] [security2:error] [pid 255769:tid 256009] [client 45.8.17.138:45593] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9LTbxMYwyVGnfuwsKKPwAABA8"]
[Tue Jul 21 07:34:54.041749 2026] [security2:error] [pid 255769:tid 255953] [client 20.206.105.145:39252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9LTrxMYwyVGnfuwsKKQwAAA9k"]
[Tue Jul 21 07:34:54.184862 2026] [security2:error] [pid 255769:tid 256012] [client 20.52.136.55:1554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/wp-links.php"] [unique_id "al9LTrxMYwyVGnfuwsKKRwAABBI"]
[Tue Jul 21 07:34:54.301913 2026] [security2:error] [pid 254995:tid 255166] [client 122.162.144.145:12647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LTv7v0rlcEGmVraEvwAAAA0c"]
[Tue Jul 21 07:34:54.302067 2026] [security2:error] [pid 254995:tid 255166] [client 122.162.144.145:12647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LTv7v0rlcEGmVraEvwAAAA0c"]
[Tue Jul 21 07:34:54.314959 2026] [security2:error] [pid 255769:tid 255961] [client 20.197.195.24:62629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/edit.php"] [unique_id "al9LTrxMYwyVGnfuwsKKSQAAA-E"]
[Tue Jul 21 07:34:54.501624 2026] [security2:error] [pid 255769:tid 255964] [client 20.197.195.24:48886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp.php"] [unique_id "al9LTrxMYwyVGnfuwsKKTgAAA-Q"]
[Tue Jul 21 07:34:54.712512 2026] [security2:error] [pid 255769:tid 255934] [client 20.220.225.223:19323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/ace2.php"] [unique_id "al9LTrxMYwyVGnfuwsKKUgAAA8Y"]
[Tue Jul 21 07:34:54.764361 2026] [security2:error] [pid 255769:tid 255955] [client 103.106.20.201:59360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTrxMYwyVGnfuwsKKVQAAA9s"]
[Tue Jul 21 07:34:54.764463 2026] [security2:error] [pid 255769:tid 255955] [client 103.106.20.201:59360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTrxMYwyVGnfuwsKKVQAAA9s"]
[Tue Jul 21 07:34:54.782370 2026] [security2:error] [pid 255769:tid 255967] [client 117.217.38.194:61105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTrxMYwyVGnfuwsKKVwAAA-c"]
[Tue Jul 21 07:34:54.782452 2026] [security2:error] [pid 255769:tid 255967] [client 117.217.38.194:61105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LTrxMYwyVGnfuwsKKVwAAA-c"]
[Tue Jul 21 07:34:55.119350 2026] [security2:error] [pid 255769:tid 255935] [client 20.220.225.223:38705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/fffm.php"] [unique_id "al9LT7xMYwyVGnfuwsKKXgAAA8c"]
[Tue Jul 21 07:34:55.188785 2026] [security2:error] [pid 255769:tid 256024] [client 45.8.17.73:39065] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9LT7xMYwyVGnfuwsKKXwAABB4"]
[Tue Jul 21 07:34:55.441045 2026] [autoindex:error] [pid 255769:tid 255989] [client 198.235.24.15:64692] AH01276: Cannot serve directory /home1/warlle02/ewfconstrucao.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:34:55.491228 2026] [security2:error] [pid 254995:tid 255129] [client 20.197.195.24:48852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/class.php"] [unique_id "al9LT_7v0rlcEGmVraEv0AAAAyI"]
[Tue Jul 21 07:34:55.782674 2026] [security2:error] [pid 255769:tid 256001] [client 20.197.195.24:62595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/hosty.php"] [unique_id "al9LT7xMYwyVGnfuwsKKbAAABAc"]
[Tue Jul 21 07:34:55.901624 2026] [security2:error] [pid 254995:tid 255143] [client 20.206.105.145:39131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/puc.php"] [unique_id "al9LT_7v0rlcEGmVraEv1gAAAzA"]
[Tue Jul 21 07:34:56.094280 2026] [security2:error] [pid 255769:tid 255913] [client 20.220.225.223:6086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/acew67.php"] [unique_id "al9LULxMYwyVGnfuwsKKcAAAA7E"]
[Tue Jul 21 07:34:56.183843 2026] [security2:error] [pid 255769:tid 256004] [client 20.197.195.24:13115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/echkm.php"] [unique_id "al9LULxMYwyVGnfuwsKKcgAABAo"]
[Tue Jul 21 07:34:56.264525 2026] [security2:error] [pid 255769:tid 255975] [client 20.220.225.223:49816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/mimpi.php"] [unique_id "al9LULxMYwyVGnfuwsKKdAAAA-8"]
[Tue Jul 21 07:34:56.420397 2026] [security2:error] [pid 255769:tid 255922] [client 20.206.105.145:38968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/themes.php"] [unique_id "al9LULxMYwyVGnfuwsKKdgAAA7o"]
[Tue Jul 21 07:34:56.476865 2026] [security2:error] [pid 254995:tid 255193] [client 175.45.70.82:59779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LUP7v0rlcEGmVraEv4AAAA2I"]
[Tue Jul 21 07:34:56.477012 2026] [security2:error] [pid 254995:tid 255193] [client 175.45.70.82:59779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LUP7v0rlcEGmVraEv4AAAA2I"]
[Tue Jul 21 07:34:56.537399 2026] [security2:error] [pid 255769:tid 255960] [client 154.192.233.199:59726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LULxMYwyVGnfuwsKKegAAA-A"]
[Tue Jul 21 07:34:56.537547 2026] [security2:error] [pid 255769:tid 255960] [client 154.192.233.199:59726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LULxMYwyVGnfuwsKKegAAA-A"]
[Tue Jul 21 07:34:56.678895 2026] [security2:error] [pid 255769:tid 255827] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/1vluqojw5imsz1tiek5x9hr85p.php"] [unique_id "al9LULxMYwyVGnfuwsKKfwAEHDk"]
[Tue Jul 21 07:34:56.683663 2026] [security2:error] [pid 255769:tid 255976] [client 45.8.17.134:54375] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/chosen.php"] [unique_id "al9LULxMYwyVGnfuwsKKgAAAA_A"]
[Tue Jul 21 07:34:56.695341 2026] [security2:error] [pid 255769:tid 255945] [client 20.197.195.24:48855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/lib.php"] [unique_id "al9LULxMYwyVGnfuwsKKgQAAA9E"]
[Tue Jul 21 07:34:56.797777 2026] [security2:error] [pid 255769:tid 255955] [client 109.248.148.246:37718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LULxMYwyVGnfuwsKKhgAAA9s"]
[Tue Jul 21 07:34:56.797862 2026] [security2:error] [pid 255769:tid 255955] [client 109.248.148.246:37718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9LULxMYwyVGnfuwsKKhgAAA9s"]
[Tue Jul 21 07:34:56.959855 2026] [security2:error] [pid 255769:tid 255974] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LULxMYwyVGnfuwsKKhwAD7ig"]
[Tue Jul 21 07:34:56.968842 2026] [security2:error] [pid 254995:tid 255127] [client 87.58.197.194:42922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.63.71"] [uri "/.env"] [unique_id "al9LUP7v0rlcEGmVraEv5QAAAyA"]
[Tue Jul 21 07:34:56.978595 2026] [security2:error] [pid 254995:tid 255152] [client 82.102.28.107:54456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LUP7v0rlcEGmVraEv5gAAAzk"]
[Tue Jul 21 07:34:56.978683 2026] [security2:error] [pid 254995:tid 255152] [client 82.102.28.107:54456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LUP7v0rlcEGmVraEv5gAAAzk"]
[Tue Jul 21 07:34:57.016017 2026] [security2:error] [pid 255769:tid 255910] [client 20.206.105.145:39233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/dx.php"] [unique_id "al9LUbxMYwyVGnfuwsKKjAAAA64"]
[Tue Jul 21 07:34:57.083276 2026] [security2:error] [pid 255769:tid 255893] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/.env"] [unique_id "al9LUbxMYwyVGnfuwsKKjwAD_Xs"]
[Tue Jul 21 07:34:57.083845 2026] [security2:error] [pid 254995:tid 255057] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/backend/.env"] [unique_id "al9LUf7v0rlcEGmVraEv6gADVz0"]
[Tue Jul 21 07:34:57.098063 2026] [security2:error] [pid 254995:tid 255015] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LUf7v0rlcEGmVraEv6wADNhM"]
[Tue Jul 21 07:34:57.098177 2026] [security2:error] [pid 254995:tid 255149] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LUf7v0rlcEGmVraEv6wADNhM"]
[Tue Jul 21 07:34:57.260224 2026] [security2:error] [pid 254995:tid 255261] [client 103.174.34.15:51818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LUf7v0rlcEGmVraEv7QAAA4s"]
[Tue Jul 21 07:34:57.260367 2026] [security2:error] [pid 254995:tid 255261] [client 103.174.34.15:51818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LUf7v0rlcEGmVraEv7QAAA4s"]
[Tue Jul 21 07:34:57.290628 2026] [security2:error] [pid 255769:tid 255925] [client 20.206.105.145:39259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/p.php"] [unique_id "al9LUbxMYwyVGnfuwsKKlwAAA70"]
[Tue Jul 21 07:34:57.421055 2026] [proxy:error] [pid 255769:tid 255983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:57.421146 2026] [proxy_http:error] [pid 255769:tid 255983] [client 20.206.105.145:39261] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:57.421831 2026] [proxy:error] [pid 255769:tid 255983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:34:57.421871 2026] [proxy_http:error] [pid 255769:tid 255983] [client 20.206.105.145:39261] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:34:57.473196 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.195.24:13091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/login.php"] [unique_id "al9LUbxMYwyVGnfuwsKKnQAABCI"]
[Tue Jul 21 07:34:57.519897 2026] [security2:error] [pid 255769:tid 256004] [client 20.220.225.223:19973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.folegofinanceiro.com.br"] [uri "/ms.php"] [unique_id "al9LUbxMYwyVGnfuwsKKngAABAo"]
[Tue Jul 21 07:34:57.538201 2026] [security2:error] [pid 254995:tid 255218] [client 20.52.136.55:1791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/xmrlpc.php"] [unique_id "al9LUf7v0rlcEGmVraEv8QAAA3o"]
[Tue Jul 21 07:34:57.628330 2026] [security2:error] [pid 254995:tid 255009] [remote 159.223.116.62:48680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.116.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/wp-login.php"] [unique_id "al9LUf7v0rlcEGmVraEv8gADmw0"]
[Tue Jul 21 07:34:57.645511 2026] [core:error] [pid 255769:tid 255794] [remote 45.148.10.238:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:34:57.645530 2026] [core:error] [pid 255769:tid 255794] [remote 45.148.10.238:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:34:57.659292 2026] [security2:error] [pid 255769:tid 255886] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LUbxMYwyVGnfuwsKKowADxXQ"]
[Tue Jul 21 07:34:57.659416 2026] [security2:error] [pid 255769:tid 255933] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LUbxMYwyVGnfuwsKKowADxXQ"]
[Tue Jul 21 07:34:57.715365 2026] [security2:error] [pid 254995:tid 255140] [client 20.206.105.145:38954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/bthil.php"] [unique_id "al9LUf7v0rlcEGmVraEv9AAAAy0"]
[Tue Jul 21 07:34:57.739903 2026] [security2:error] [pid 254995:tid 255159] [client 20.220.225.223:49800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/dp.php"] [unique_id "al9LUf7v0rlcEGmVraEv9gAAA0A"]
[Tue Jul 21 07:34:57.783213 2026] [security2:error] [pid 255769:tid 255971] [client 20.197.195.24:62701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/k.php"] [unique_id "al9LUbxMYwyVGnfuwsKKpgAAA-s"]
[Tue Jul 21 07:34:57.790214 2026] [security2:error] [pid 255769:tid 255992] [client 20.206.105.145:39290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/7.php"] [unique_id "al9LUbxMYwyVGnfuwsKKpwAAA_8"]
[Tue Jul 21 07:34:57.852746 2026] [security2:error] [pid 255769:tid 255892] [remote 160.187.68.132:45580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9LUbxMYwyVGnfuwsKKqgADqXo"]
[Tue Jul 21 07:34:57.852931 2026] [security2:error] [pid 255769:tid 255905] [client 160.187.68.132:45580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9LUbxMYwyVGnfuwsKKqgADqXo"]
[Tue Jul 21 07:34:57.870011 2026] [security2:error] [pid 254995:tid 255165] [client 20.206.105.145:39129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/8.php"] [unique_id "al9LUf7v0rlcEGmVraEv-gAAA0Y"]
[Tue Jul 21 07:34:57.987787 2026] [security2:error] [pid 254995:tid 255262] [client 45.8.17.138:38655] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "al9LUf7v0rlcEGmVraEv-wAAA4w"]
[Tue Jul 21 07:34:58.096898 2026] [security2:error] [pid 255769:tid 255952] [client 193.36.225.71:23687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LUrxMYwyVGnfuwsKKsAAAA9g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:34:58.279064 2026] [security2:error] [pid 255769:tid 255899] [client 20.220.225.223:24259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/ops.php"] [unique_id "al9LUrxMYwyVGnfuwsKKsgAAA6M"]
[Tue Jul 21 07:34:58.346133 2026] [security2:error] [pid 255769:tid 255906] [client 20.206.105.145:39156] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.goldentrips40.com"] [uri "/1.php"] [unique_id "al9LUrxMYwyVGnfuwsKKswAAA6o"]
[Tue Jul 21 07:34:58.346240 2026] [security2:error] [pid 255769:tid 255906] [client 20.206.105.145:39156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/1.php"] [unique_id "al9LUrxMYwyVGnfuwsKKswAAA6o"]
[Tue Jul 21 07:34:58.501616 2026] [security2:error] [pid 254995:tid 255033] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/source/.env"] [unique_id "al9LUv7v0rlcEGmVraEwBAADaiU"]
[Tue Jul 21 07:34:58.632215 2026] [security2:error] [pid 254995:tid 255142] [client 20.206.105.145:38914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/100.php"] [unique_id "al9LUv7v0rlcEGmVraEwCAAAAy8"]
[Tue Jul 21 07:34:58.752436 2026] [security2:error] [pid 254995:tid 255225] [client 20.206.105.145:39283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/about.php"] [unique_id "al9LUv7v0rlcEGmVraEwCwAAA4E"]
[Tue Jul 21 07:34:59.016394 2026] [security2:error] [pid 254995:tid 255279] [client 20.206.105.145:39238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/admin.php"] [unique_id "al9LU_7v0rlcEGmVraEwEQAAA50"]
[Tue Jul 21 07:34:59.106982 2026] [security2:error] [pid 254995:tid 255067] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/framework/.env"] [unique_id "al9LU_7v0rlcEGmVraEwFgADJUc"]
[Tue Jul 21 07:34:59.113311 2026] [security2:error] [pid 255769:tid 255774] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/ikiwiki/.env"] [unique_id "al9LU7xMYwyVGnfuwsKKvAADrQQ"]
[Tue Jul 21 07:34:59.120888 2026] [security2:error] [pid 254995:tid 255168] [client 20.220.225.223:38709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/ftde.php"] [unique_id "al9LU_7v0rlcEGmVraEwFwAAA0k"]
[Tue Jul 21 07:34:59.227694 2026] [security2:error] [pid 254995:tid 255108] [remote 119.195.102.159:49004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9LU_7v0rlcEGmVraEwGAADZ3A"]
[Tue Jul 21 07:34:59.240150 2026] [security2:error] [pid 254995:tid 255042] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/config.inc.php"] [unique_id "al9LU_7v0rlcEGmVraEwGQADHy4"]
[Tue Jul 21 07:34:59.274403 2026] [security2:error] [pid 255769:tid 255800] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LU7xMYwyVGnfuwsKKvwADyh4"]
[Tue Jul 21 07:34:59.274538 2026] [security2:error] [pid 255769:tid 255938] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LU7xMYwyVGnfuwsKKvwADyh4"]
[Tue Jul 21 07:34:59.327182 2026] [security2:error] [pid 254995:tid 255274] [client 20.197.195.24:62631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/aaa.php"] [unique_id "al9LU_7v0rlcEGmVraEwGwAAA5g"]
[Tue Jul 21 07:34:59.419806 2026] [security2:error] [pid 255769:tid 255784] [remote 38.242.157.30:50532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9LU7xMYwyVGnfuwsKKwQAD4g4"]
[Tue Jul 21 07:34:59.585964 2026] [security2:error] [pid 255769:tid 255947] [client 20.197.195.24:13065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/a2.php"] [unique_id "al9LU7xMYwyVGnfuwsKKxQAAA9M"]
[Tue Jul 21 07:34:59.767386 2026] [security2:error] [pid 254995:tid 255058] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LU_7v0rlcEGmVraEwIQADQz4"]
[Tue Jul 21 07:34:59.767585 2026] [security2:error] [pid 254995:tid 255162] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LU_7v0rlcEGmVraEwIQADQz4"]
[Tue Jul 21 07:34:59.818270 2026] [security2:error] [pid 255769:tid 255772] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/system/.env"] [unique_id "al9LU7xMYwyVGnfuwsKKxwAECgI"]
[Tue Jul 21 07:34:59.827500 2026] [security2:error] [pid 254995:tid 255187] [client 59.96.220.140:52067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LU_7v0rlcEGmVraEwIwAAA1w"]
[Tue Jul 21 07:34:59.829302 2026] [security2:error] [pid 254995:tid 255187] [client 59.96.220.140:52067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LU_7v0rlcEGmVraEwIwAAA1w"]
[Tue Jul 21 07:34:59.831442 2026] [security2:error] [pid 254995:tid 255001] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LU_7v0rlcEGmVraEwJAADcQU"]
[Tue Jul 21 07:34:59.831676 2026] [security2:error] [pid 254995:tid 255209] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LU_7v0rlcEGmVraEwJAADcQU"]
[Tue Jul 21 07:34:59.851364 2026] [security2:error] [pid 255769:tid 255975] [client 20.206.105.145:39111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/edit.php"] [unique_id "al9LU7xMYwyVGnfuwsKKyAAAA-8"]
[Tue Jul 21 07:34:59.973691 2026] [security2:error] [pid 254995:tid 255258] [client 37.140.223.134:23739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LU_7v0rlcEGmVraEwKAAAA4g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:34:59.997625 2026] [security2:error] [pid 255769:tid 255958] [client 20.197.195.24:62649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/file5.php"] [unique_id "al9LU7xMYwyVGnfuwsKK0AAAA94"]
[Tue Jul 21 07:35:00.428614 2026] [security2:error] [pid 255769:tid 255981] [client 20.197.195.24:62645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/222.php"] [unique_id "al9LVLxMYwyVGnfuwsKK2QAAA_U"]
[Tue Jul 21 07:35:00.554135 2026] [security2:error] [pid 255769:tid 255896] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/app_dev.php/_profiler/open"] [unique_id "al9LVLxMYwyVGnfuwsKK3gAEHH4"]
[Tue Jul 21 07:35:00.690628 2026] [security2:error] [pid 255769:tid 255976] [client 45.8.17.134:61805] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/news-portal/fm.php"] [unique_id "al9LVLxMYwyVGnfuwsKK4AAAA_A"]
[Tue Jul 21 07:35:00.753487 2026] [security2:error] [pid 255769:tid 255934] [client 20.197.195.24:62619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/test.php"] [unique_id "al9LVLxMYwyVGnfuwsKK4gAAA8Y"]
[Tue Jul 21 07:35:00.777360 2026] [security2:error] [pid 255769:tid 255907] [client 20.197.195.24:48863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/d61.php"] [unique_id "al9LVLxMYwyVGnfuwsKK4wAAA6s"]
[Tue Jul 21 07:35:00.834603 2026] [security2:error] [pid 254995:tid 255271] [client 20.220.225.223:6111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/bscclapb.php"] [unique_id "al9LVP7v0rlcEGmVraEwNAAAA5U"]
[Tue Jul 21 07:35:00.942079 2026] [security2:error] [pid 255769:tid 255941] [client 139.167.225.182:54291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LVLxMYwyVGnfuwsKK5gAAA80"]
[Tue Jul 21 07:35:00.942243 2026] [security2:error] [pid 255769:tid 255941] [client 139.167.225.182:54291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LVLxMYwyVGnfuwsKK5gAAA80"]
[Tue Jul 21 07:35:00.994417 2026] [security2:error] [pid 255769:tid 255944] [client 20.206.105.145:39249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/admin.php"] [unique_id "al9LVLxMYwyVGnfuwsKK6AAAA9A"]
[Tue Jul 21 07:35:01.099660 2026] [security2:error] [pid 255769:tid 255926] [client 87.58.197.194:47480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.63.71"] [uri "/.env"] [unique_id "al9LVbxMYwyVGnfuwsKK6wAAA74"]
[Tue Jul 21 07:35:01.106477 2026] [security2:error] [pid 255769:tid 255875] [remote 192.241.143.148:49288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/wp-login.php"] [unique_id "al9LVbxMYwyVGnfuwsKK7AAD22k"]
[Tue Jul 21 07:35:01.211662 2026] [security2:error] [pid 255769:tid 255988] [client 20.197.195.24:62626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/aaa.php"] [unique_id "al9LVbxMYwyVGnfuwsKK7gAAA_w"]
[Tue Jul 21 07:35:01.434377 2026] [security2:error] [pid 254995:tid 255122] [remote 160.187.68.132:50658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9LVf7v0rlcEGmVraEwQAADQX4"]
[Tue Jul 21 07:35:01.701751 2026] [security2:error] [pid 255769:tid 255947] [client 20.197.195.24:62713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/11.php"] [unique_id "al9LVbxMYwyVGnfuwsKK-gAAA9M"]
[Tue Jul 21 07:35:01.871107 2026] [security2:error] [pid 255769:tid 255975] [client 20.206.105.145:38958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/f6.php"] [unique_id "al9LVbxMYwyVGnfuwsKK_wAAA-8"]
[Tue Jul 21 07:35:01.877241 2026] [security2:error] [pid 255769:tid 255901] [client 45.8.17.139:32121] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/customize/index.php"] [unique_id "al9LVbxMYwyVGnfuwsKLAAAAA6U"]
[Tue Jul 21 07:35:02.186821 2026] [security2:error] [pid 255769:tid 255902] [client 20.197.195.24:62710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/mac.php"] [unique_id "al9LVrxMYwyVGnfuwsKLBAAAA6Y"]
[Tue Jul 21 07:35:02.481912 2026] [security2:error] [pid 255769:tid 256004] [client 103.162.129.114:49211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LVrxMYwyVGnfuwsKLCQAABAo"]
[Tue Jul 21 07:35:02.482091 2026] [security2:error] [pid 255769:tid 256004] [client 103.162.129.114:49211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LVrxMYwyVGnfuwsKLCQAABAo"]
[Tue Jul 21 07:35:02.562588 2026] [security2:error] [pid 255769:tid 255959] [client 20.220.225.223:38707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/yup.php"] [unique_id "al9LVrxMYwyVGnfuwsKLCwAAA98"]
[Tue Jul 21 07:35:02.615199 2026] [security2:error] [pid 255769:tid 255817] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/wp-content/mysql.sql"] [unique_id "al9LVrxMYwyVGnfuwsKLDQAD0S8"]
[Tue Jul 21 07:35:02.635775 2026] [security2:error] [pid 255769:tid 255934] [client 20.197.195.24:62603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/chosen.php"] [unique_id "al9LVrxMYwyVGnfuwsKLEAAAA8Y"]
[Tue Jul 21 07:35:02.714399 2026] [security2:error] [pid 254995:tid 255255] [client 193.36.225.67:24815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LVv7v0rlcEGmVraEwUAAAA4U"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:02.771916 2026] [security2:error] [pid 254995:tid 255163] [client 117.251.86.144:57002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LVv7v0rlcEGmVraEwUgAAA0Q"]
[Tue Jul 21 07:35:02.772062 2026] [security2:error] [pid 254995:tid 255163] [client 117.251.86.144:57002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LVv7v0rlcEGmVraEwUgAAA0Q"]
[Tue Jul 21 07:35:02.843967 2026] [security2:error] [pid 255769:tid 255944] [client 20.220.225.223:48133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/berlin.php"] [unique_id "al9LVrxMYwyVGnfuwsKLFAAAA9A"]
[Tue Jul 21 07:35:02.885580 2026] [security2:error] [pid 255769:tid 256011] [client 45.8.17.62:35957] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css/colors/admin.php"] [unique_id "al9LVrxMYwyVGnfuwsKLFQAABBE"]
[Tue Jul 21 07:35:03.188113 2026] [security2:error] [pid 254995:tid 255188] [client 82.102.28.107:48602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9LV_7v0rlcEGmVraEwWAAAA10"]
[Tue Jul 21 07:35:03.188239 2026] [security2:error] [pid 254995:tid 255188] [client 82.102.28.107:48602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9LV_7v0rlcEGmVraEwWAAAA10"]
[Tue Jul 21 07:35:03.277052 2026] [security2:error] [pid 255769:tid 255989] [client 20.197.195.24:13087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/info.php"] [unique_id "al9LV7xMYwyVGnfuwsKLGAAAA_0"]
[Tue Jul 21 07:35:03.288618 2026] [security2:error] [pid 255769:tid 255909] [client 20.220.225.223:24215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/term.php"] [unique_id "al9LV7xMYwyVGnfuwsKLGgAAA60"]
[Tue Jul 21 07:35:03.367402 2026] [security2:error] [pid 255769:tid 255787] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/php-info.php"] [unique_id "al9LV7xMYwyVGnfuwsKLHQADvRE"]
[Tue Jul 21 07:35:03.399556 2026] [security2:error] [pid 255769:tid 255990] [client 20.220.225.223:49549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/billur.php"] [unique_id "al9LV7xMYwyVGnfuwsKLIAAAA_4"]
[Tue Jul 21 07:35:03.457555 2026] [security2:error] [pid 255769:tid 256027] [client 122.186.204.214:49827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LV7xMYwyVGnfuwsKLIQAABCE"]
[Tue Jul 21 07:35:03.457674 2026] [security2:error] [pid 255769:tid 256027] [client 122.186.204.214:49827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LV7xMYwyVGnfuwsKLIQAABCE"]
[Tue Jul 21 07:35:03.466767 2026] [security2:error] [pid 254995:tid 255130] [client 152.59.154.239:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LV_7v0rlcEGmVraEwXQAAAyM"]
[Tue Jul 21 07:35:03.466869 2026] [security2:error] [pid 254995:tid 255130] [client 152.59.154.239:51796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LV_7v0rlcEGmVraEwXQAAAyM"]
[Tue Jul 21 07:35:03.750436 2026] [security2:error] [pid 254995:tid 255109] [remote 216.73.216.238:40513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9LV_7v0rlcEGmVraEwYQADYnE"]
[Tue Jul 21 07:35:03.783943 2026] [security2:error] [pid 255769:tid 255969] [client 173.24.185.52:65475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LV7xMYwyVGnfuwsKLJwAAA-k"]
[Tue Jul 21 07:35:03.784089 2026] [security2:error] [pid 255769:tid 255969] [client 173.24.185.52:65475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LV7xMYwyVGnfuwsKLJwAAA-k"]
[Tue Jul 21 07:35:03.806612 2026] [security2:error] [pid 255769:tid 256024] [client 45.251.232.145:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LV7xMYwyVGnfuwsKLKAAABB4"]
[Tue Jul 21 07:35:03.806740 2026] [security2:error] [pid 255769:tid 256024] [client 45.251.232.145:57948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LV7xMYwyVGnfuwsKLKAAABB4"]
[Tue Jul 21 07:35:03.842245 2026] [security2:error] [pid 255769:tid 255833] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/info.php.bak"] [unique_id "al9LV7xMYwyVGnfuwsKLKgAEFz8"]
[Tue Jul 21 07:35:03.842451 2026] [security2:error] [pid 255769:tid 255834] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/phpinfo.php.bak"] [unique_id "al9LV7xMYwyVGnfuwsKLKwAEF0A"]
[Tue Jul 21 07:35:04.036148 2026] [security2:error] [pid 254995:tid 255147] [client 193.36.225.102:48853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LVv7v0rlcEGmVraEwVAAAAzQ"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:35:04.088412 2026] [security2:error] [pid 255769:tid 255902] [client 45.8.17.112:23479] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/images/wp-conflg.php"] [unique_id "al9LWLxMYwyVGnfuwsKLMQAAA6Y"]
[Tue Jul 21 07:35:04.097699 2026] [security2:error] [pid 254995:tid 255209] [client 173.252.95.114:36138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LWP7v0rlcEGmVraEwZgAAA3E"]
[Tue Jul 21 07:35:04.119132 2026] [security2:error] [pid 255769:tid 255884] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LWLxMYwyVGnfuwsKLMgAD43I"]
[Tue Jul 21 07:35:04.119310 2026] [security2:error] [pid 255769:tid 255963] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LWLxMYwyVGnfuwsKLMgAD43I"]
[Tue Jul 21 07:35:04.133598 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.195.24:62715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/cream1.php"] [unique_id "al9LWLxMYwyVGnfuwsKLMwAAA7Y"]
[Tue Jul 21 07:35:04.207220 2026] [security2:error] [pid 255769:tid 255981] [client 20.206.105.145:38933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/inputs.php"] [unique_id "al9LWLxMYwyVGnfuwsKLNgAAA_U"]
[Tue Jul 21 07:35:04.392268 2026] [security2:error] [pid 255769:tid 255786] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/env/.env"] [unique_id "al9LWLxMYwyVGnfuwsKLPgADqhA"]
[Tue Jul 21 07:35:04.470158 2026] [security2:error] [pid 255769:tid 255814] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWLxMYwyVGnfuwsKLQAADzCw"]
[Tue Jul 21 07:35:04.470287 2026] [security2:error] [pid 255769:tid 255940] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWLxMYwyVGnfuwsKLQAADzCw"]
[Tue Jul 21 07:35:04.532428 2026] [security2:error] [pid 255769:tid 255941] [client 20.220.225.223:6141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/else1.php"] [unique_id "al9LWLxMYwyVGnfuwsKLQQAAA80"]
[Tue Jul 21 07:35:04.806372 2026] [security2:error] [pid 255769:tid 255917] [client 20.220.225.223:49566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/bootstrap.php"] [unique_id "al9LWLxMYwyVGnfuwsKLRgAAA7U"]
[Tue Jul 21 07:35:04.825854 2026] [security2:error] [pid 255769:tid 255859] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/src/.env"] [unique_id "al9LWLxMYwyVGnfuwsKLSAAD_Vk"]
[Tue Jul 21 07:35:04.857946 2026] [security2:error] [pid 255769:tid 255909] [client 20.220.225.223:31168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/jj.php"] [unique_id "al9LWLxMYwyVGnfuwsKLSgAAA60"]
[Tue Jul 21 07:35:05.011622 2026] [security2:error] [pid 255769:tid 255976] [client 122.162.144.145:27020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LWbxMYwyVGnfuwsKLTgAAA_A"]
[Tue Jul 21 07:35:05.011739 2026] [security2:error] [pid 255769:tid 255976] [client 122.162.144.145:27020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LWbxMYwyVGnfuwsKLTgAAA_A"]
[Tue Jul 21 07:35:05.184583 2026] [security2:error] [pid 255769:tid 256009] [client 45.8.17.64:20693] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/chosen.php"] [unique_id "al9LWbxMYwyVGnfuwsKLTwAABA8"]
[Tue Jul 21 07:35:05.243538 2026] [security2:error] [pid 254995:tid 255176] [client 117.217.38.194:61555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWf7v0rlcEGmVraEwdgAAA1E"]
[Tue Jul 21 07:35:05.243649 2026] [security2:error] [pid 254995:tid 255176] [client 117.217.38.194:61555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWf7v0rlcEGmVraEwdgAAA1E"]
[Tue Jul 21 07:35:05.530492 2026] [security2:error] [pid 255769:tid 256008] [client 103.106.20.201:59970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWbxMYwyVGnfuwsKLWQAABA4"]
[Tue Jul 21 07:35:05.530629 2026] [security2:error] [pid 255769:tid 256008] [client 103.106.20.201:59970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWbxMYwyVGnfuwsKLWQAABA4"]
[Tue Jul 21 07:35:05.555005 2026] [security2:error] [pid 255769:tid 255843] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/config/app.php"] [unique_id "al9LWbxMYwyVGnfuwsKLWgAD6Ek"]
[Tue Jul 21 07:35:05.562205 2026] [security2:error] [pid 255769:tid 255836] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9LWbxMYwyVGnfuwsKLWwAD70I"]
[Tue Jul 21 07:35:05.641618 2026] [security2:error] [pid 255769:tid 256012] [client 20.52.136.55:1750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/htaccess.php"] [unique_id "al9LWbxMYwyVGnfuwsKLXgAABBI"]
[Tue Jul 21 07:35:05.720224 2026] [security2:error] [pid 254995:tid 255175] [client 20.220.225.223:6137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/tkikikoko.php"] [unique_id "al9LWf7v0rlcEGmVraEwfwAAA1A"]
[Tue Jul 21 07:35:05.767449 2026] [security2:error] [pid 254995:tid 255144] [client 20.197.195.24:48861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/11.php"] [unique_id "al9LWf7v0rlcEGmVraEwgQAAAzE"]
[Tue Jul 21 07:35:05.905124 2026] [security2:error] [pid 255769:tid 255958] [client 20.220.225.223:49822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-editor.php"] [unique_id "al9LWbxMYwyVGnfuwsKLYAAAA94"]
[Tue Jul 21 07:35:06.050598 2026] [security2:error] [pid 255769:tid 255871] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/web/.env"] [unique_id "al9LWrxMYwyVGnfuwsKLZQAD2GU"]
[Tue Jul 21 07:35:06.050659 2026] [security2:error] [pid 255769:tid 255781] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphafix.com.br"] [uri "/core/.env"] [unique_id "al9LWrxMYwyVGnfuwsKLZAAD2As"]
[Tue Jul 21 07:35:06.146257 2026] [security2:error] [pid 254995:tid 255165] [client 154.192.233.199:59324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWv7v0rlcEGmVraEwhwAAA0Y"]
[Tue Jul 21 07:35:06.146388 2026] [security2:error] [pid 254995:tid 255165] [client 154.192.233.199:59324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LWv7v0rlcEGmVraEwhwAAA0Y"]
[Tue Jul 21 07:35:06.401025 2026] [security2:error] [pid 255769:tid 255870] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/phpinfo.php3"] [unique_id "al9LWrxMYwyVGnfuwsKLawADt2Q"]
[Tue Jul 21 07:35:06.592706 2026] [security2:error] [pid 255769:tid 255831] [remote 65.111.0.167:42973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.0.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9LWLxMYwyVGnfuwsKLQgAD-z0"]
[Tue Jul 21 07:35:06.701819 2026] [security2:error] [pid 255769:tid 255926] [client 20.220.225.223:31123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/dragonshell.php"] [unique_id "al9LWrxMYwyVGnfuwsKLdgAAA74"]
[Tue Jul 21 07:35:06.890439 2026] [security2:error] [pid 255769:tid 256027] [client 45.8.17.125:41237] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/chosen.php"] [unique_id "al9LWrxMYwyVGnfuwsKLegAABCE"]
[Tue Jul 21 07:35:07.065660 2026] [security2:error] [pid 255769:tid 256003] [client 20.206.105.145:39291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/av.php"] [unique_id "al9LW7xMYwyVGnfuwsKLfQAABAk"]
[Tue Jul 21 07:35:07.170784 2026] [security2:error] [pid 255769:tid 255955] [client 175.45.70.82:60289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LW7xMYwyVGnfuwsKLfwAAA9s"]
[Tue Jul 21 07:35:07.170935 2026] [security2:error] [pid 255769:tid 255955] [client 175.45.70.82:60289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LW7xMYwyVGnfuwsKLfwAAA9s"]
[Tue Jul 21 07:35:07.183796 2026] [security2:error] [pid 254995:tid 255127] [client 213.152.162.104:58988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LW_7v0rlcEGmVraEwmAAAAyA"]
[Tue Jul 21 07:35:07.183908 2026] [security2:error] [pid 254995:tid 255127] [client 213.152.162.104:58988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LW_7v0rlcEGmVraEwmAAAAyA"]
[Tue Jul 21 07:35:07.230020 2026] [security2:error] [pid 255769:tid 256001] [client 128.140.106.114:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9LW7xMYwyVGnfuwsKLgAAEB1s"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:35:07.281624 2026] [autoindex:error] [pid 255769:tid 255901] [client 20.197.195.24:62668] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:07.475014 2026] [security2:error] [pid 254995:tid 255182] [client 193.36.225.57:62763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LW_7v0rlcEGmVraEwmgAAA1c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:07.574255 2026] [security2:error] [pid 255769:tid 255951] [client 20.220.225.223:49840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/cro.php"] [unique_id "al9LW7xMYwyVGnfuwsKLhgAAA9c"]
[Tue Jul 21 07:35:07.583557 2026] [security2:error] [pid 254995:tid 255056] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LW_7v0rlcEGmVraEwoAADNjw"]
[Tue Jul 21 07:35:07.583658 2026] [security2:error] [pid 254995:tid 255149] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LW_7v0rlcEGmVraEwoAADNjw"]
[Tue Jul 21 07:35:07.689050 2026] [security2:error] [pid 255769:tid 256021] [client 45.8.17.137:48941] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/system.php"] [unique_id "al9LW7xMYwyVGnfuwsKLhwAABBs"]
[Tue Jul 21 07:35:07.756075 2026] [rewrite:error] [pid 254995:tid 255155] [client 187.49.76.218:19201] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:35:07.758460 2026] [rewrite:error] [pid 254995:tid 255271] [client 187.49.76.218:19233] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:35:07.774376 2026] [security2:error] [pid 254995:tid 255223] [client 128.140.106.114:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9LW_7v0rlcEGmVraEwpwADfyE"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:35:07.777775 2026] [rewrite:error] [pid 254995:tid 255268] [client 187.49.76.218:19265] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:35:07.926860 2026] [security2:error] [pid 254995:tid 255218] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LW_7v0rlcEGmVraEwqwADekw"]
[Tue Jul 21 07:35:07.993376 2026] [security2:error] [pid 255769:tid 255975] [client 103.174.34.15:52303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LW7xMYwyVGnfuwsKLigAAA-8"]
[Tue Jul 21 07:35:07.993481 2026] [security2:error] [pid 255769:tid 255975] [client 103.174.34.15:52303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LW7xMYwyVGnfuwsKLigAAA-8"]
[Tue Jul 21 07:35:08.000714 2026] [security2:error] [pid 255769:tid 255952] [client 20.197.195.24:48840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/v2.php"] [unique_id "al9LXLxMYwyVGnfuwsKLiwAAA9g"]
[Tue Jul 21 07:35:08.033805 2026] [autoindex:error] [pid 255769:tid 255977] [client 20.197.195.24:62668] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:08.056164 2026] [security2:error] [pid 255769:tid 255943] [client 20.197.195.24:62668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/dr.php"] [unique_id "al9LXLxMYwyVGnfuwsKLjQAAA88"]
[Tue Jul 21 07:35:08.097315 2026] [security2:error] [pid 254995:tid 255063] [remote 152.42.137.70:49868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.137.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9LXP7v0rlcEGmVraEwsAADN0M"]
[Tue Jul 21 07:35:08.202495 2026] [security2:error] [pid 255769:tid 255838] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LXLxMYwyVGnfuwsKLjwADo0Q"]
[Tue Jul 21 07:35:08.202606 2026] [security2:error] [pid 255769:tid 255899] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LXLxMYwyVGnfuwsKLjwADo0Q"]
[Tue Jul 21 07:35:08.991613 2026] [security2:error] [pid 255769:tid 255959] [client 45.8.17.140:32507] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/PHPMailer/wp-conflg.php"] [unique_id "al9LXLxMYwyVGnfuwsKLnwAAA98"]
[Tue Jul 21 07:35:09.056392 2026] [security2:error] [pid 255769:tid 255962] [client 20.197.195.24:62717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/x.php"] [unique_id "al9LXbxMYwyVGnfuwsKLoQAAA-I"]
[Tue Jul 21 07:35:09.096326 2026] [security2:error] [pid 255769:tid 256002] [client 20.220.225.223:49593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/cron-tab.php"] [unique_id "al9LXbxMYwyVGnfuwsKLogAABAg"]
[Tue Jul 21 07:35:09.261733 2026] [security2:error] [pid 254995:tid 255262] [client 20.206.105.145:39254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/classwithtostring.php"] [unique_id "al9LXf7v0rlcEGmVraEwwwAAA4w"]
[Tue Jul 21 07:35:09.821982 2026] [security2:error] [pid 254995:tid 255143] [client 20.197.195.24:48894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/panel.php"] [unique_id "al9LXf7v0rlcEGmVraEwzQAAAzA"]
[Tue Jul 21 07:35:09.905099 2026] [security2:error] [pid 255769:tid 255881] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LXbxMYwyVGnfuwsKLrgAEAm8"]
[Tue Jul 21 07:35:09.905278 2026] [security2:error] [pid 255769:tid 255996] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LXbxMYwyVGnfuwsKLrgAEAm8"]
[Tue Jul 21 07:35:10.014196 2026] [security2:error] [pid 254995:tid 255042] [remote 212.80.9.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9LXv7v0rlcEGmVraEw0wADaC4"]
[Tue Jul 21 07:35:10.085118 2026] [security2:error] [pid 255769:tid 255945] [client 45.8.17.60:37177] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/news-portal/wp-admins.php"] [unique_id "al9LXrxMYwyVGnfuwsKLtAAAA9E"]
[Tue Jul 21 07:35:10.285831 2026] [security2:error] [pid 255769:tid 255853] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LXrxMYwyVGnfuwsKLtwADrVM"]
[Tue Jul 21 07:35:10.285962 2026] [security2:error] [pid 255769:tid 255909] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LXrxMYwyVGnfuwsKLtwADrVM"]
[Tue Jul 21 07:35:10.385185 2026] [security2:error] [pid 255769:tid 255813] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LXrxMYwyVGnfuwsKLuwAD5ys"]
[Tue Jul 21 07:35:10.385326 2026] [security2:error] [pid 255769:tid 255967] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LXrxMYwyVGnfuwsKLuwAD5ys"]
[Tue Jul 21 07:35:10.430835 2026] [security2:error] [pid 255769:tid 255925] [client 20.197.195.24:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/155.php"] [unique_id "al9LXrxMYwyVGnfuwsKLvAAAA70"]
[Tue Jul 21 07:35:10.442394 2026] [security2:error] [pid 255769:tid 255951] [client 59.96.220.140:52585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LXrxMYwyVGnfuwsKLvQAAA9c"]
[Tue Jul 21 07:35:10.443214 2026] [security2:error] [pid 255769:tid 255951] [client 59.96.220.140:52585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LXrxMYwyVGnfuwsKLvQAAA9c"]
[Tue Jul 21 07:35:10.896948 2026] [security2:error] [pid 255769:tid 255931] [client 45.8.17.103:52979] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/images/chosen.php"] [unique_id "al9LXrxMYwyVGnfuwsKLygAAA8M"]
[Tue Jul 21 07:35:10.911804 2026] [security2:error] [pid 255769:tid 256020] [client 20.197.195.24:62669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ops.php"] [unique_id "al9LXrxMYwyVGnfuwsKLzAAABBo"]
[Tue Jul 21 07:35:11.311351 2026] [security2:error] [pid 255769:tid 255975] [client 20.220.225.223:24212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/ah25.php"] [unique_id "al9LX7xMYwyVGnfuwsKMDwAAA-8"]
[Tue Jul 21 07:35:11.639460 2026] [security2:error] [pid 255769:tid 255927] [client 139.167.225.182:55076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LX7xMYwyVGnfuwsKMGAAAA78"]
[Tue Jul 21 07:35:11.639552 2026] [security2:error] [pid 255769:tid 255927] [client 139.167.225.182:55076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LX7xMYwyVGnfuwsKMGAAAA78"]
[Tue Jul 21 07:35:11.730641 2026] [security2:error] [pid 255769:tid 255962] [client 69.171.230.27:38410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LXrxMYwyVGnfuwsKLwAAAA-I"]
[Tue Jul 21 07:35:11.784070 2026] [security2:error] [pid 255769:tid 256006] [client 20.197.195.24:50341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/file31.php"] [unique_id "al9LX7xMYwyVGnfuwsKMHQAABAw"]
[Tue Jul 21 07:35:11.899184 2026] [security2:error] [pid 255769:tid 256022] [client 172.245.102.44:33999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LX7xMYwyVGnfuwsKMIwAABBw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:12.164081 2026] [security2:error] [pid 254995:tid 255131] [client 20.197.195.24:62618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/file6.php"] [unique_id "al9LYP7v0rlcEGmVraEw8AAAAyQ"]
[Tue Jul 21 07:35:12.258950 2026] [security2:error] [pid 255769:tid 255923] [client 20.52.136.55:1756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/readme.php"] [unique_id "al9LYLxMYwyVGnfuwsKMJQAAA7s"]
[Tue Jul 21 07:35:12.441561 2026] [security2:error] [pid 255769:tid 255920] [client 20.220.225.223:49829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/koiy.php"] [unique_id "al9LYLxMYwyVGnfuwsKMKgAAA7g"]
[Tue Jul 21 07:35:12.465533 2026] [autoindex:error] [pid 255769:tid 255919] [client 20.197.195.24:62654] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:12.489616 2026] [security2:error] [pid 255769:tid 256011] [client 20.197.195.24:62654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/adminfuns.php"] [unique_id "al9LYLxMYwyVGnfuwsKMLQAABBE"]
[Tue Jul 21 07:35:12.533201 2026] [security2:error] [pid 255769:tid 255952] [client 168.119.53.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9LYLxMYwyVGnfuwsKMLgAD2BY"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:35:12.553276 2026] [security2:error] [pid 255769:tid 256010] [client 185.213.175.37:40356] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/"] [unique_id "al9LYLxMYwyVGnfuwsKMLwAABBA"]
[Tue Jul 21 07:35:12.692453 2026] [security2:error] [pid 254995:tid 255163] [client 45.8.17.124:61813] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/css.php"] [unique_id "al9LYP7v0rlcEGmVraEw-wAAA0Q"]
[Tue Jul 21 07:35:12.760841 2026] [security2:error] [pid 255769:tid 255990] [client 168.119.53.160:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9LYLxMYwyVGnfuwsKMNQAD_hw"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:35:12.912981 2026] [security2:error] [pid 255769:tid 256027] [client 20.197.195.24:62646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/goods.php"] [unique_id "al9LYLxMYwyVGnfuwsKMNwAABCE"]
[Tue Jul 21 07:35:13.094850 2026] [security2:error] [pid 255769:tid 256002] [client 20.206.105.145:39149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9LYbxMYwyVGnfuwsKMOAAABAg"]
[Tue Jul 21 07:35:13.358818 2026] [security2:error] [pid 255769:tid 255976] [client 103.162.129.114:49649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LYbxMYwyVGnfuwsKMPgAAA_A"]
[Tue Jul 21 07:35:13.358932 2026] [security2:error] [pid 255769:tid 255976] [client 103.162.129.114:49649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LYbxMYwyVGnfuwsKMPgAAA_A"]
[Tue Jul 21 07:35:13.371479 2026] [security2:error] [pid 255769:tid 255937] [client 74.7.241.184:45380] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "orixmed.com.inlaudo.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9LYbxMYwyVGnfuwsKMQAADySI"]
[Tue Jul 21 07:35:13.397929 2026] [security2:error] [pid 255769:tid 255897] [remote 104.207.58.230:47405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9LYbxMYwyVGnfuwsKMQgAD338"]
[Tue Jul 21 07:35:13.439385 2026] [security2:error] [pid 254995:tid 255135] [client 117.251.86.144:39372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LYf7v0rlcEGmVraExCAAAAyg"]
[Tue Jul 21 07:35:13.439494 2026] [security2:error] [pid 254995:tid 255135] [client 117.251.86.144:39372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LYf7v0rlcEGmVraExCAAAAyg"]
[Tue Jul 21 07:35:13.698375 2026] [security2:error] [pid 255769:tid 256010] [client 20.206.105.145:38944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-blog.php"] [unique_id "al9LYbxMYwyVGnfuwsKMTQAABBA"]
[Tue Jul 21 07:35:13.702315 2026] [security2:error] [pid 255769:tid 255977] [client 20.197.195.24:13068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/dex.php"] [unique_id "al9LYbxMYwyVGnfuwsKMTgAAA_E"]
[Tue Jul 21 07:35:13.711672 2026] [security2:error] [pid 254995:tid 255168] [client 20.197.195.24:62650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/100.php"] [unique_id "al9LYf7v0rlcEGmVraExDAAAA0k"]
[Tue Jul 21 07:35:13.832174 2026] [security2:error] [pid 255769:tid 255909] [client 74.7.230.46:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "www.digiterapia.com.br"] [uri "/public/robots.txt"] [unique_id "al9LYbxMYwyVGnfuwsKMUAADrUQ"]
[Tue Jul 21 07:35:14.117450 2026] [security2:error] [pid 254995:tid 255200] [client 20.197.195.24:13154] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "eduardogoesadv.com"] [uri "/1.php"] [unique_id "al9LYv7v0rlcEGmVraExFAAAA2k"]
[Tue Jul 21 07:35:14.117557 2026] [security2:error] [pid 254995:tid 255200] [client 20.197.195.24:13154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/1.php"] [unique_id "al9LYv7v0rlcEGmVraExFAAAA2k"]
[Tue Jul 21 07:35:14.190899 2026] [security2:error] [pid 255769:tid 256012] [client 122.186.204.214:50341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LYrxMYwyVGnfuwsKMVAAABBI"]
[Tue Jul 21 07:35:14.191070 2026] [security2:error] [pid 255769:tid 256012] [client 122.186.204.214:50341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LYrxMYwyVGnfuwsKMVAAABBI"]
[Tue Jul 21 07:35:14.252931 2026] [security2:error] [pid 255769:tid 255947] [client 20.197.195.24:50349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/about.php"] [unique_id "al9LYrxMYwyVGnfuwsKMXQAAA9M"]
[Tue Jul 21 07:35:14.261132 2026] [security2:error] [pid 254995:tid 255275] [client 45.251.232.145:58475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LYv7v0rlcEGmVraExFwAAA5k"]
[Tue Jul 21 07:35:14.261213 2026] [security2:error] [pid 254995:tid 255275] [client 45.251.232.145:58475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LYv7v0rlcEGmVraExFwAAA5k"]
[Tue Jul 21 07:35:14.262080 2026] [security2:error] [pid 254995:tid 255180] [client 74.7.241.163:43964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "carlaalbuquerqueugc.online"] [uri "/index.php"] [unique_id "al9LYf7v0rlcEGmVraExDQADVX0"]
[Tue Jul 21 07:35:14.314517 2026] [proxy:error] [pid 254995:tid 255218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:14.314586 2026] [proxy_http:error] [pid 254995:tid 255218] [client 20.206.105.145:38970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:14.315148 2026] [proxy:error] [pid 254995:tid 255218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:14.315174 2026] [proxy_http:error] [pid 254995:tid 255218] [client 20.206.105.145:38970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:14.347019 2026] [security2:error] [pid 255769:tid 256018] [client 20.197.195.24:48802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/ms.php"] [unique_id "al9LYrxMYwyVGnfuwsKMXwAABBg"]
[Tue Jul 21 07:35:14.433245 2026] [security2:error] [pid 255769:tid 255985] [client 173.24.185.52:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LYrxMYwyVGnfuwsKMYQAAA_k"]
[Tue Jul 21 07:35:14.433328 2026] [security2:error] [pid 255769:tid 255985] [client 173.24.185.52:49614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LYrxMYwyVGnfuwsKMYQAAA_k"]
[Tue Jul 21 07:35:14.762733 2026] [security2:error] [pid 255769:tid 255826] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LYrxMYwyVGnfuwsKMcQAD6zg"]
[Tue Jul 21 07:35:14.762895 2026] [security2:error] [pid 255769:tid 255971] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LYrxMYwyVGnfuwsKMcQAD6zg"]
[Tue Jul 21 07:35:14.869942 2026] [security2:error] [pid 255769:tid 255948] [client 69.171.230.41:39536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LYLxMYwyVGnfuwsKMNAAAA9Q"]
[Tue Jul 21 07:35:14.873090 2026] [security2:error] [pid 255769:tid 255940] [client 45.8.17.58:38713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "al9LYrxMYwyVGnfuwsKMegAAA8w"]
[Tue Jul 21 07:35:15.028049 2026] [security2:error] [pid 255769:tid 256003] [client 20.220.225.223:49793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/hp2.php"] [unique_id "al9LY7xMYwyVGnfuwsKMfgAABAk"]
[Tue Jul 21 07:35:15.159647 2026] [security2:error] [pid 255769:tid 255927] [client 20.197.195.24:49170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/about.php"] [unique_id "al9LY7xMYwyVGnfuwsKMfwAAA78"]
[Tue Jul 21 07:35:15.168571 2026] [security2:error] [pid 254995:tid 255120] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LY_7v0rlcEGmVraExIgADl3w"]
[Tue Jul 21 07:35:15.168724 2026] [security2:error] [pid 254995:tid 255273] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LY_7v0rlcEGmVraExIgADl3w"]
[Tue Jul 21 07:35:15.499514 2026] [security2:error] [pid 255769:tid 255921] [client 136.144.33.99:56775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LY7xMYwyVGnfuwsKMhwAAA7k"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:15.542376 2026] [security2:error] [pid 254995:tid 255279] [client 74.7.230.23:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "guilhermegleinobende1781912616969.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9LY_7v0rlcEGmVraExKQADnQg"]
[Tue Jul 21 07:35:15.713846 2026] [security2:error] [pid 254995:tid 255265] [client 122.162.144.145:31623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LY_7v0rlcEGmVraExKgAAA48"]
[Tue Jul 21 07:35:15.713952 2026] [security2:error] [pid 254995:tid 255265] [client 122.162.144.145:31623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LY_7v0rlcEGmVraExKgAAA48"]
[Tue Jul 21 07:35:15.724631 2026] [security2:error] [pid 255769:tid 255901] [client 117.217.38.194:62009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LY7xMYwyVGnfuwsKMjQAAA6U"]
[Tue Jul 21 07:35:15.724726 2026] [security2:error] [pid 255769:tid 255901] [client 117.217.38.194:62009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LY7xMYwyVGnfuwsKMjQAAA6U"]
[Tue Jul 21 07:35:15.875277 2026] [security2:error] [pid 255769:tid 255907] [client 45.8.17.126:60311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/advanced-product-fields-for-woocommerce/db.php"] [unique_id "al9LY7xMYwyVGnfuwsKMkwAAA6s"]
[Tue Jul 21 07:35:15.880438 2026] [security2:error] [pid 255769:tid 255941] [client 20.197.195.24:62614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9LY7xMYwyVGnfuwsKMlAAAA80"]
[Tue Jul 21 07:35:16.142725 2026] [security2:error] [pid 254995:tid 255220] [client 20.206.105.145:39144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/admin.php"] [unique_id "al9LZP7v0rlcEGmVraExMQAAA3w"]
[Tue Jul 21 07:35:16.323188 2026] [security2:error] [pid 255769:tid 255968] [client 103.106.20.201:60566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZLxMYwyVGnfuwsKMmwAAA-g"]
[Tue Jul 21 07:35:16.323274 2026] [security2:error] [pid 255769:tid 255968] [client 103.106.20.201:60566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZLxMYwyVGnfuwsKMmwAAA-g"]
[Tue Jul 21 07:35:16.326826 2026] [security2:error] [pid 255769:tid 255945] [client 20.220.225.223:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wp-Blogs.php"] [unique_id "al9LZLxMYwyVGnfuwsKMnAAAA9E"]
[Tue Jul 21 07:35:16.377009 2026] [autoindex:error] [pid 255769:tid 256004] [client 20.197.195.24:48842] AH01276: Cannot serve directory /home1/edua4721/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:16.406306 2026] [security2:error] [pid 255769:tid 255899] [client 20.197.195.24:48842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/memberfuns.php"] [unique_id "al9LZLxMYwyVGnfuwsKMngAAA6M"]
[Tue Jul 21 07:35:16.413468 2026] [security2:error] [pid 255769:tid 255894] [remote 207.180.241.245:56044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9LZLxMYwyVGnfuwsKMnwADrXw"]
[Tue Jul 21 07:35:16.651906 2026] [security2:error] [pid 255769:tid 255973] [client 152.59.154.239:52341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZLxMYwyVGnfuwsKMowAAA-0"]
[Tue Jul 21 07:35:16.652058 2026] [security2:error] [pid 255769:tid 255973] [client 152.59.154.239:52341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZLxMYwyVGnfuwsKMowAAA-0"]
[Tue Jul 21 07:35:16.717412 2026] [security2:error] [pid 254995:tid 255148] [client 20.220.225.223:31188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9LZP7v0rlcEGmVraExOgAAAzU"]
[Tue Jul 21 07:35:16.757542 2026] [security2:error] [pid 254995:tid 255054] [remote 64.225.121.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onlinebuyerwebsite.com"] [uri "/wp-login.php"] [unique_id "al9LZP7v0rlcEGmVraExOwADXTo"]
[Tue Jul 21 07:35:16.789349 2026] [security2:error] [pid 255769:tid 256013] [client 154.192.233.199:60129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZLxMYwyVGnfuwsKMpAAABBM"]
[Tue Jul 21 07:35:16.789469 2026] [security2:error] [pid 255769:tid 256013] [client 154.192.233.199:60129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZLxMYwyVGnfuwsKMpAAABBM"]
[Tue Jul 21 07:35:16.883145 2026] [security2:error] [pid 255769:tid 255917] [client 45.33.101.131:51126] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "ns1103.hostgator.com.br"] [uri "/"] [unique_id "al9LZLxMYwyVGnfuwsKMqAAAA7U"]
[Tue Jul 21 07:35:16.956114 2026] [security2:error] [pid 255769:tid 256022] [client 20.197.195.24:62594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9LZLxMYwyVGnfuwsKMqwAABBw"]
[Tue Jul 21 07:35:17.087455 2026] [security2:error] [pid 254995:tid 255192] [client 20.197.195.24:13135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/0.php"] [unique_id "al9LZf7v0rlcEGmVraExRQAAA2E"]
[Tue Jul 21 07:35:17.185930 2026] [security2:error] [pid 254995:tid 255135] [client 45.8.17.148:33405] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/wp.php"] [unique_id "al9LZf7v0rlcEGmVraExRgAAAyg"]
[Tue Jul 21 07:35:17.391659 2026] [security2:error] [pid 255769:tid 255907] [client 20.197.195.24:62616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/themes.php"] [unique_id "al9LZbxMYwyVGnfuwsKMsQAAA6s"]
[Tue Jul 21 07:35:17.513872 2026] [security2:error] [pid 255769:tid 255928] [client 20.197.195.24:48851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/BDKR28.php"] [unique_id "al9LZbxMYwyVGnfuwsKMsgAAA8A"]
[Tue Jul 21 07:35:17.771879 2026] [security2:error] [pid 255769:tid 255988] [client 20.220.225.223:38665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/wp-mt.php"] [unique_id "al9LZbxMYwyVGnfuwsKMtgAAA_w"]
[Tue Jul 21 07:35:17.804018 2026] [autoindex:error] [pid 255769:tid 255969] [client 20.197.195.24:62672] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:17.845957 2026] [security2:error] [pid 255769:tid 255926] [client 20.197.195.24:48872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/green1.php"] [unique_id "al9LZbxMYwyVGnfuwsKMugAAA74"]
[Tue Jul 21 07:35:17.897484 2026] [security2:error] [pid 255769:tid 255774] [remote 160.187.68.132:56652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZbxMYwyVGnfuwsKMvQAECQQ"]
[Tue Jul 21 07:35:17.897619 2026] [security2:error] [pid 255769:tid 256003] [client 160.187.68.132:56652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZbxMYwyVGnfuwsKMvQAECQQ"]
[Tue Jul 21 07:35:17.947349 2026] [security2:error] [pid 255769:tid 255996] [client 175.45.70.82:60812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZbxMYwyVGnfuwsKMvgAABAI"]
[Tue Jul 21 07:35:17.947506 2026] [security2:error] [pid 255769:tid 255996] [client 175.45.70.82:60812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZbxMYwyVGnfuwsKMvgAABAI"]
[Tue Jul 21 07:35:18.135945 2026] [security2:error] [pid 255769:tid 255848] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMxAADrU4"]
[Tue Jul 21 07:35:18.136067 2026] [security2:error] [pid 255769:tid 255909] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMxAADrU4"]
[Tue Jul 21 07:35:18.355618 2026] [security2:error] [pid 255769:tid 255998] [client 20.197.195.24:13105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/nc4.php"] [unique_id "al9LZrxMYwyVGnfuwsKMxQAABAQ"]
[Tue Jul 21 07:35:18.463663 2026] [security2:error] [pid 255769:tid 255946] [client 20.220.225.223:31169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9LZrxMYwyVGnfuwsKMyAAAA9I"]
[Tue Jul 21 07:35:18.556187 2026] [security2:error] [pid 255769:tid 256009] [client 37.140.223.150:38047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LZrxMYwyVGnfuwsKMyQAABA8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:35:18.737595 2026] [security2:error] [pid 255769:tid 255925] [client 103.174.34.15:52788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMzQAAA70"]
[Tue Jul 21 07:35:18.737699 2026] [security2:error] [pid 255769:tid 255925] [client 103.174.34.15:52788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMzQAAA70"]
[Tue Jul 21 07:35:18.742708 2026] [security2:error] [pid 255769:tid 255921] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMzAADuUA"]
[Tue Jul 21 07:35:18.759500 2026] [security2:error] [pid 255769:tid 255829] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMzgADwzs"]
[Tue Jul 21 07:35:18.759632 2026] [security2:error] [pid 255769:tid 255931] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMzgADwzs"]
[Tue Jul 21 07:35:18.827595 2026] [security2:error] [pid 255769:tid 255908] [client 122.164.127.47:64290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMzwAAA6w"]
[Tue Jul 21 07:35:18.827717 2026] [security2:error] [pid 255769:tid 255908] [client 122.164.127.47:64290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LZrxMYwyVGnfuwsKMzwAAA6w"]
[Tue Jul 21 07:35:18.869823 2026] [security2:error] [pid 255769:tid 255856] [remote 5.252.52.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9LZrxMYwyVGnfuwsKM0AADulY"]
[Tue Jul 21 07:35:18.872277 2026] [security2:error] [pid 255769:tid 256010] [client 45.8.17.73:64177] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9LZrxMYwyVGnfuwsKM0QAABBA"]
[Tue Jul 21 07:35:19.679179 2026] [security2:error] [pid 255769:tid 255899] [client 20.220.225.223:51516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/hp3.php"] [unique_id "al9LZ7xMYwyVGnfuwsKM3gAAA6M"]
[Tue Jul 21 07:35:19.732203 2026] [security2:error] [pid 255769:tid 255909] [client 213.152.162.104:53120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9LZ7xMYwyVGnfuwsKM4wAAA60"]
[Tue Jul 21 07:35:19.732292 2026] [security2:error] [pid 255769:tid 255909] [client 213.152.162.104:53120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9LZ7xMYwyVGnfuwsKM4wAAA60"]
[Tue Jul 21 07:35:19.814715 2026] [security2:error] [pid 255769:tid 255891] [remote 216.73.216.238:24122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9LZ7xMYwyVGnfuwsKM5QAECnk"]
[Tue Jul 21 07:35:19.815110 2026] [core:alert] [pid 255769:tid 255947] [client 57.141.18.22:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:35:19.882761 2026] [security2:error] [pid 255769:tid 255918] [client 45.8.17.59:45791] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9LZ7xMYwyVGnfuwsKM5wAAA7Y"]
[Tue Jul 21 07:35:20.006809 2026] [security2:error] [pid 255769:tid 255962] [client 20.197.195.24:48827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/a1.php"] [unique_id "al9LaLxMYwyVGnfuwsKM6QAAA-I"]
[Tue Jul 21 07:35:20.080628 2026] [security2:error] [pid 255769:tid 255972] [client 136.144.33.98:35011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LaLxMYwyVGnfuwsKM7wAAA-w"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:20.588334 2026] [security2:error] [pid 254995:tid 255087] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LaP7v0rlcEGmVraExeAADRls"]
[Tue Jul 21 07:35:20.588475 2026] [security2:error] [pid 254995:tid 255165] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LaP7v0rlcEGmVraExeAADRls"]
[Tue Jul 21 07:35:20.785928 2026] [security2:error] [pid 255769:tid 255969] [client 213.152.162.104:33382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LaLxMYwyVGnfuwsKM_AAAA-k"]
[Tue Jul 21 07:35:20.786010 2026] [security2:error] [pid 255769:tid 255969] [client 213.152.162.104:33382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LaLxMYwyVGnfuwsKM_AAAA-k"]
[Tue Jul 21 07:35:20.814906 2026] [security2:error] [pid 255769:tid 255778] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LaLxMYwyVGnfuwsKM_QADuwg"]
[Tue Jul 21 07:35:20.815066 2026] [security2:error] [pid 255769:tid 255923] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LaLxMYwyVGnfuwsKM_QADuwg"]
[Tue Jul 21 07:35:20.934721 2026] [security2:error] [pid 255769:tid 255770] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LaLxMYwyVGnfuwsKM_gAD6AA"]
[Tue Jul 21 07:35:20.934922 2026] [security2:error] [pid 255769:tid 255968] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LaLxMYwyVGnfuwsKM_gAD6AA"]
[Tue Jul 21 07:35:21.051988 2026] [security2:error] [pid 254995:tid 255205] [client 213.152.162.104:53132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Laf7v0rlcEGmVraExfwAAA24"]
[Tue Jul 21 07:35:21.052096 2026] [security2:error] [pid 254995:tid 255205] [client 213.152.162.104:53132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Laf7v0rlcEGmVraExfwAAA24"]
[Tue Jul 21 07:35:21.136263 2026] [security2:error] [pid 255769:tid 256002] [client 20.197.195.24:48877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/eee.php"] [unique_id "al9LabxMYwyVGnfuwsKNBAAABAg"]
[Tue Jul 21 07:35:21.175334 2026] [security2:error] [pid 254995:tid 255270] [client 45.8.17.48:52263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/Simple.php"] [unique_id "al9Laf7v0rlcEGmVraExgAAAA5Q"]
[Tue Jul 21 07:35:21.336300 2026] [security2:error] [pid 255769:tid 255948] [client 216.73.160.183:40429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9LabxMYwyVGnfuwsKNCAAAA9Q"]
[Tue Jul 21 07:35:21.501700 2026] [security2:error] [pid 254995:tid 255225] [client 216.73.160.25:62561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9Laf7v0rlcEGmVraExggAAA4E"]
[Tue Jul 21 07:35:21.503275 2026] [security2:error] [pid 255769:tid 255988] [client 216.73.160.39:25757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9LabxMYwyVGnfuwsKNCQAAA_w"]
[Tue Jul 21 07:35:21.510887 2026] [security2:error] [pid 254995:tid 255260] [client 59.96.220.140:53091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Laf7v0rlcEGmVraExhAAAA4o"]
[Tue Jul 21 07:35:21.510966 2026] [security2:error] [pid 254995:tid 255260] [client 59.96.220.140:53091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Laf7v0rlcEGmVraExhAAAA4o"]
[Tue Jul 21 07:35:21.517215 2026] [security2:error] [pid 255769:tid 255882] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "santaofertas.com.br"] [uri "/.env"] [unique_id "al9LabxMYwyVGnfuwsKNCwADtHA"]
[Tue Jul 21 07:35:21.532137 2026] [security2:error] [pid 255769:tid 255971] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "santaofertas.com.br.anapaulaguimaraesdos1781613203317.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9LabxMYwyVGnfuwsKNDQAAA-s"]
[Tue Jul 21 07:35:21.602648 2026] [security2:error] [pid 255769:tid 255917] [client 20.197.195.24:62672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/.well-known/about.php"] [unique_id "al9LabxMYwyVGnfuwsKNEQAAA7U"]
[Tue Jul 21 07:35:21.662966 2026] [security2:error] [pid 255769:tid 255806] [remote 74.7.243.250:51534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orixmed.com.inlaudo.com.br"] [uri "/blog/artigo2.php"] [unique_id "al9LabxMYwyVGnfuwsKNCgAD-SQ"], referer: https://orixmed.com.inlaudo.com.br/blog/
[Tue Jul 21 07:35:21.681544 2026] [security2:error] [pid 255769:tid 255941] [client 20.197.195.24:50333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9LabxMYwyVGnfuwsKNEwAAA80"]
[Tue Jul 21 07:35:21.922660 2026] [security2:error] [pid 254995:tid 255168] [client 20.197.195.24:62704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wefile.php"] [unique_id "al9Laf7v0rlcEGmVraExiwAAA0k"]
[Tue Jul 21 07:35:21.998408 2026] [security2:error] [pid 254995:tid 255193] [client 216.73.160.194:33433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9Laf7v0rlcEGmVraExjAAAA2I"]
[Tue Jul 21 07:35:22.116153 2026] [security2:error] [pid 254995:tid 255211] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "santaofertas.com.br"] [uri "/.env"] [unique_id "al9Lav7v0rlcEGmVraExkQAAA3M"]
[Tue Jul 21 07:35:22.125960 2026] [security2:error] [pid 254995:tid 255169] [client 172.245.102.30:58675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LaP7v0rlcEGmVraExfAAAA0o"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:35:22.207201 2026] [security2:error] [pid 255769:tid 255963] [client 20.197.195.24:48891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-aothait.php"] [unique_id "al9LarxMYwyVGnfuwsKNHAAAA-M"]
[Tue Jul 21 07:35:22.363777 2026] [security2:error] [pid 254995:tid 255192] [client 139.167.225.182:55869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lav7v0rlcEGmVraExlwAAA2E"]
[Tue Jul 21 07:35:22.363934 2026] [security2:error] [pid 254995:tid 255192] [client 139.167.225.182:55869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lav7v0rlcEGmVraExlwAAA2E"]
[Tue Jul 21 07:35:22.624978 2026] [security2:error] [pid 255769:tid 255946] [client 20.197.195.24:62661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9LarxMYwyVGnfuwsKNJQAAA9I"]
[Tue Jul 21 07:35:22.863521 2026] [security2:error] [pid 254995:tid 255125] [client 20.206.105.145:39105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/adminfuns.php"] [unique_id "al9Lav7v0rlcEGmVraExpAAAAx4"]
[Tue Jul 21 07:35:22.868775 2026] [autoindex:error] [pid 255769:tid 255948] [client 20.197.195.24:49195] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:22.958706 2026] [autoindex:error] [pid 255769:tid 255988] [client 20.197.195.24:49195] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:22.991397 2026] [security2:error] [pid 255769:tid 255925] [client 20.197.195.24:48848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/config.json.php"] [unique_id "al9LarxMYwyVGnfuwsKNLgAAA70"]
[Tue Jul 21 07:35:23.028749 2026] [security2:error] [pid 255769:tid 255972] [client 20.220.225.223:31137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/ww.php"] [unique_id "al9La7xMYwyVGnfuwsKNLwAAA-w"]
[Tue Jul 21 07:35:23.033603 2026] [security2:error] [pid 255769:tid 255902] [client 20.197.195.24:49195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9La7xMYwyVGnfuwsKNMAAAA6Y"]
[Tue Jul 21 07:35:23.175967 2026] [security2:error] [pid 255769:tid 255941] [client 45.8.17.62:40195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/index.php"] [unique_id "al9La7xMYwyVGnfuwsKNMwAAA80"]
[Tue Jul 21 07:35:23.409679 2026] [security2:error] [pid 254995:tid 255257] [client 20.197.195.24:62683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/8.php"] [unique_id "al9La_7v0rlcEGmVraExrQAAA4c"]
[Tue Jul 21 07:35:23.592117 2026] [security2:error] [pid 255769:tid 255967] [client 20.220.225.223:6128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wp-css.php"] [unique_id "al9La7xMYwyVGnfuwsKNQgAAA-c"]
[Tue Jul 21 07:35:23.735330 2026] [security2:error] [pid 255769:tid 255847] [remote 74.7.243.250:51534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orixmed.com.inlaudo.com.br"] [uri "/blog/artigo3.php"] [unique_id "al9La7xMYwyVGnfuwsKNSgADuk0"], referer: https://orixmed.com.inlaudo.com.br/blog/
[Tue Jul 21 07:35:23.820499 2026] [security2:error] [pid 254995:tid 255160] [client 20.197.195.24:13155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9La_7v0rlcEGmVraExuAAAA0E"]
[Tue Jul 21 07:35:23.832526 2026] [security2:error] [pid 255769:tid 255985] [client 103.162.129.114:50117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9La7xMYwyVGnfuwsKNSwAAA_k"]
[Tue Jul 21 07:35:23.832652 2026] [security2:error] [pid 255769:tid 255985] [client 103.162.129.114:50117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9La7xMYwyVGnfuwsKNSwAAA_k"]
[Tue Jul 21 07:35:24.067984 2026] [security2:error] [pid 255769:tid 255946] [client 20.197.195.24:62592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9LbLxMYwyVGnfuwsKNTQAAA9I"]
[Tue Jul 21 07:35:24.115302 2026] [security2:error] [pid 254995:tid 255176] [client 172.245.102.42:44063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LbP7v0rlcEGmVraExvwAAA1E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:24.133799 2026] [security2:error] [pid 255769:tid 255910] [client 20.220.225.223:24211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/8.php"] [unique_id "al9LbLxMYwyVGnfuwsKNUAAAA64"]
[Tue Jul 21 07:35:24.190841 2026] [security2:error] [pid 255769:tid 255902] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "santaofertas.com.br.anapaulaguimaraesdos1781613203317.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9LbLxMYwyVGnfuwsKNUgAAA6Y"]
[Tue Jul 21 07:35:24.270107 2026] [security2:error] [pid 255769:tid 255931] [client 117.251.86.144:45492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNVQAAA8M"]
[Tue Jul 21 07:35:24.270222 2026] [security2:error] [pid 255769:tid 255931] [client 117.251.86.144:45492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNVQAAA8M"]
[Tue Jul 21 07:35:24.599789 2026] [security2:error] [pid 255769:tid 255915] [client 20.197.195.24:62617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/f6.php"] [unique_id "al9LbLxMYwyVGnfuwsKNXAAAA7M"]
[Tue Jul 21 07:35:24.752184 2026] [security2:error] [pid 255769:tid 255960] [client 45.251.232.145:59006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNYwAAA-A"]
[Tue Jul 21 07:35:24.752343 2026] [security2:error] [pid 255769:tid 255960] [client 45.251.232.145:59006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNYwAAA-A"]
[Tue Jul 21 07:35:24.807623 2026] [security2:error] [pid 255769:tid 255987] [client 122.186.204.214:50846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNZAAAA_s"]
[Tue Jul 21 07:35:24.807757 2026] [security2:error] [pid 255769:tid 255987] [client 122.186.204.214:50846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNZAAAA_s"]
[Tue Jul 21 07:35:24.878518 2026] [security2:error] [pid 255769:tid 255954] [client 45.8.17.64:52591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/storage/framework/views/shell.php"] [unique_id "al9LbLxMYwyVGnfuwsKNZwAAA9o"]
[Tue Jul 21 07:35:24.951953 2026] [security2:error] [pid 255769:tid 256003] [client 173.24.185.52:50957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNaAAABAk"]
[Tue Jul 21 07:35:24.952094 2026] [security2:error] [pid 255769:tid 256003] [client 173.24.185.52:50957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LbLxMYwyVGnfuwsKNaAAABAk"]
[Tue Jul 21 07:35:25.174657 2026] [security2:error] [pid 254995:tid 255223] [client 20.197.195.24:13096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/k2.php"] [unique_id "al9Lbf7v0rlcEGmVraEx0wAAA38"]
[Tue Jul 21 07:35:25.185695 2026] [security2:error] [pid 254995:tid 255203] [client 20.197.195.24:62612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/inputs.php"] [unique_id "al9Lbf7v0rlcEGmVraEx1AAAA2w"]
[Tue Jul 21 07:35:25.299974 2026] [security2:error] [pid 254995:tid 255023] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lbf7v0rlcEGmVraEx2AADUhs"]
[Tue Jul 21 07:35:25.300164 2026] [security2:error] [pid 254995:tid 255177] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lbf7v0rlcEGmVraEx2AADUhs"]
[Tue Jul 21 07:35:25.430377 2026] [security2:error] [pid 254995:tid 255215] [client 20.197.195.24:50309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/inputs.php"] [unique_id "al9Lbf7v0rlcEGmVraEx2gAAA3c"]
[Tue Jul 21 07:35:25.431480 2026] [security2:error] [pid 254995:tid 255268] [client 20.220.225.223:49832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/dp.php"] [unique_id "al9Lbf7v0rlcEGmVraEx2wAAA5I"]
[Tue Jul 21 07:35:25.545376 2026] [security2:error] [pid 255769:tid 255787] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "santaofertas.com.br"] [uri "/api/.env"] [unique_id "al9LbbxMYwyVGnfuwsKNbwAD_BE"]
[Tue Jul 21 07:35:25.618978 2026] [security2:error] [pid 255769:tid 255905] [client 20.197.195.24:62608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/classwithtostring.php"] [unique_id "al9LbbxMYwyVGnfuwsKNcAAAA6k"]
[Tue Jul 21 07:35:25.777273 2026] [security2:error] [pid 255769:tid 255902] [client 45.8.17.59:35275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/tinyfilemanager/tinyfilemanager.php"] [unique_id "al9LbbxMYwyVGnfuwsKNcgAAA6Y"]
[Tue Jul 21 07:35:25.953153 2026] [security2:error] [pid 255769:tid 255945] [client 20.197.195.24:49181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9LbbxMYwyVGnfuwsKNdAAAA9E"]
[Tue Jul 21 07:35:26.052831 2026] [security2:error] [pid 255769:tid 255789] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LbrxMYwyVGnfuwsKNdwADvRM"]
[Tue Jul 21 07:35:26.052970 2026] [security2:error] [pid 255769:tid 255925] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LbrxMYwyVGnfuwsKNdwADvRM"]
[Tue Jul 21 07:35:26.076037 2026] [security2:error] [pid 255769:tid 256013] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "santaofertas.com.br"] [uri "/api/.env"] [unique_id "al9LbrxMYwyVGnfuwsKNeAAABBM"]
[Tue Jul 21 07:35:26.230833 2026] [security2:error] [pid 254995:tid 255142] [client 117.217.38.194:62471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lbv7v0rlcEGmVraEx7AAAAy8"]
[Tue Jul 21 07:35:26.230979 2026] [security2:error] [pid 254995:tid 255142] [client 117.217.38.194:62471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lbv7v0rlcEGmVraEx7AAAAy8"]
[Tue Jul 21 07:35:26.504474 2026] [security2:error] [pid 255769:tid 255908] [client 122.162.144.145:16723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LbrxMYwyVGnfuwsKNgAAAA6w"]
[Tue Jul 21 07:35:26.507183 2026] [security2:error] [pid 255769:tid 255908] [client 122.162.144.145:16723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LbrxMYwyVGnfuwsKNgAAAA6w"]
[Tue Jul 21 07:35:26.627368 2026] [security2:error] [pid 254995:tid 255194] [client 20.197.195.24:62688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-blog.php"] [unique_id "al9Lbv7v0rlcEGmVraEx8gAAA2M"]
[Tue Jul 21 07:35:26.680003 2026] [security2:error] [pid 254995:tid 255148] [client 45.8.17.135:32257] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/shell.php"] [unique_id "al9Lbv7v0rlcEGmVraEx9QAAAzU"]
[Tue Jul 21 07:35:26.813795 2026] [security2:error] [pid 254995:tid 255126] [client 20.197.195.24:48864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/uiuvs58l.php"] [unique_id "al9Lbv7v0rlcEGmVraEx-gAAAx8"]
[Tue Jul 21 07:35:27.166150 2026] [security2:error] [pid 254995:tid 255264] [client 103.106.20.201:61148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lb_7v0rlcEGmVraEyBAAAA44"]
[Tue Jul 21 07:35:27.166399 2026] [security2:error] [pid 254995:tid 255264] [client 103.106.20.201:61148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lb_7v0rlcEGmVraEyBAAAA44"]
[Tue Jul 21 07:35:27.508504 2026] [security2:error] [pid 254995:tid 255145] [client 154.192.233.199:58875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lb_7v0rlcEGmVraEyCgAAAzI"]
[Tue Jul 21 07:35:27.508684 2026] [security2:error] [pid 254995:tid 255145] [client 154.192.233.199:58875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lb_7v0rlcEGmVraEyCgAAAzI"]
[Tue Jul 21 07:35:27.579930 2026] [rewrite:error] [pid 254995:tid 255272] [client 187.49.76.218:19425] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2413
[Tue Jul 21 07:35:27.580605 2026] [rewrite:error] [pid 254995:tid 255277] [client 187.49.76.218:19457] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2413
[Tue Jul 21 07:35:27.601481 2026] [rewrite:error] [pid 254995:tid 255167] [client 187.49.76.218:19489] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2413
[Tue Jul 21 07:35:27.601497 2026] [security2:error] [pid 255769:tid 255987] [client 136.144.33.104:46983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Lb7xMYwyVGnfuwsKNiAAAA_s"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:27.703911 2026] [security2:error] [pid 255769:tid 255946] [client 20.197.195.24:48865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/40p9ixjd.php"] [unique_id "al9Lb7xMYwyVGnfuwsKNiQAAA9I"]
[Tue Jul 21 07:35:27.714776 2026] [autoindex:error] [pid 254995:tid 255155] [client 20.197.195.24:62599] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:27.723922 2026] [security2:error] [pid 254995:tid 255223] [client 20.197.195.24:62599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Lb_7v0rlcEGmVraEyFAAAA38"]
[Tue Jul 21 07:35:27.886187 2026] [security2:error] [pid 254995:tid 255170] [client 45.8.17.146:38735] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/aatdgetgdg/main.php"] [unique_id "al9Lb_7v0rlcEGmVraEyGQAAA0s"]
[Tue Jul 21 07:35:28.212619 2026] [security2:error] [pid 254995:tid 255206] [client 20.220.225.223:38691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/wander.php"] [unique_id "al9LcP7v0rlcEGmVraEyJAAAA28"]
[Tue Jul 21 07:35:28.315439 2026] [security2:error] [pid 254995:tid 255144] [client 20.197.195.24:62707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ms-edit.php"] [unique_id "al9LcP7v0rlcEGmVraEyJgAAAzE"]
[Tue Jul 21 07:35:28.488554 2026] [security2:error] [pid 255769:tid 255972] [client 20.197.195.24:48873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9LcLxMYwyVGnfuwsKNkQAAA-w"]
[Tue Jul 21 07:35:28.693593 2026] [security2:error] [pid 255769:tid 255790] [remote 151.255.40.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.40.255.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LcLxMYwyVGnfuwsKNlwADtRQ"]
[Tue Jul 21 07:35:28.693705 2026] [security2:error] [pid 255769:tid 255917] [client 151.255.40.189:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9LcLxMYwyVGnfuwsKNlwADtRQ"]
[Tue Jul 21 07:35:28.761215 2026] [security2:error] [pid 255769:tid 255959] [client 20.206.105.145:39268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/goods.php"] [unique_id "al9LcLxMYwyVGnfuwsKNmAAAA98"]
[Tue Jul 21 07:35:29.057561 2026] [security2:error] [pid 254995:tid 255134] [client 109.248.148.246:55180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Lcf7v0rlcEGmVraEyNgAAAyc"]
[Tue Jul 21 07:35:29.057685 2026] [security2:error] [pid 254995:tid 255134] [client 109.248.148.246:55180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Lcf7v0rlcEGmVraEyNgAAAyc"]
[Tue Jul 21 07:35:29.082964 2026] [security2:error] [pid 254995:tid 255258] [client 45.8.17.126:29927] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/asasx.php"] [unique_id "al9Lcf7v0rlcEGmVraEyOAAAA4g"]
[Tue Jul 21 07:35:29.165553 2026] [security2:error] [pid 255769:tid 255971] [client 122.164.127.47:64973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNnQAAA-s"]
[Tue Jul 21 07:35:29.165663 2026] [security2:error] [pid 255769:tid 255971] [client 122.164.127.47:64973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNnQAAA-s"]
[Tue Jul 21 07:35:29.325310 2026] [security2:error] [pid 255769:tid 255798] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNnwAD4Bw"]
[Tue Jul 21 07:35:29.325449 2026] [security2:error] [pid 255769:tid 255960] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNnwAD4Bw"]
[Tue Jul 21 07:35:29.327541 2026] [security2:error] [pid 255769:tid 255932] [client 20.197.195.24:48803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/for.php"] [unique_id "al9LcbxMYwyVGnfuwsKNoAAAA8Q"]
[Tue Jul 21 07:35:29.449995 2026] [security2:error] [pid 255769:tid 255921] [client 20.197.195.24:50359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9LcbxMYwyVGnfuwsKNpAAAA7k"]
[Tue Jul 21 07:35:29.493227 2026] [security2:error] [pid 255769:tid 255957] [client 103.174.34.15:53270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNpQAAA90"]
[Tue Jul 21 07:35:29.493355 2026] [security2:error] [pid 255769:tid 255957] [client 103.174.34.15:53270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNpQAAA90"]
[Tue Jul 21 07:35:29.517914 2026] [security2:error] [pid 254995:tid 255055] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lcf7v0rlcEGmVraEyQgADUTs"]
[Tue Jul 21 07:35:29.518050 2026] [security2:error] [pid 254995:tid 255176] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lcf7v0rlcEGmVraEyQgADUTs"]
[Tue Jul 21 07:35:29.825394 2026] [security2:error] [pid 255769:tid 255923] [client 193.36.225.104:61439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LcbxMYwyVGnfuwsKNpgAAA7s"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:35:29.947367 2026] [security2:error] [pid 255769:tid 255969] [client 152.59.154.239:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNrAAAA-k"]
[Tue Jul 21 07:35:29.947477 2026] [security2:error] [pid 255769:tid 255969] [client 152.59.154.239:52848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LcbxMYwyVGnfuwsKNrAAAA-k"]
[Tue Jul 21 07:35:30.077443 2026] [security2:error] [pid 254995:tid 255277] [client 45.8.17.125:32263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/template-wploader.php"] [unique_id "al9Lcv7v0rlcEGmVraEyTgAAA5s"]
[Tue Jul 21 07:35:30.150049 2026] [security2:error] [pid 255769:tid 255974] [client 20.220.225.223:38704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/cron.php"] [unique_id "al9LcrxMYwyVGnfuwsKNsAAAA-4"]
[Tue Jul 21 07:35:30.479268 2026] [security2:error] [pid 254995:tid 255191] [client 103.69.96.15:48964] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 15.96.69.103.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-comments-post.php"] [unique_id "al9Lcf7v0rlcEGmVraEyPgAAA2A"]
[Tue Jul 21 07:35:30.479422 2026] [security2:error] [pid 254995:tid 255191] [client 103.69.96.15:48964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "diariomineral.com"] [uri "/wp-comments-post.php"] [unique_id "al9Lcf7v0rlcEGmVraEyPgAAA2A"]
[Tue Jul 21 07:35:31.080286 2026] [security2:error] [pid 255769:tid 256009] [client 45.8.17.60:56731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/test.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNvQAABA8"]
[Tue Jul 21 07:35:31.082717 2026] [security2:error] [pid 255769:tid 256025] [client 20.197.195.24:13092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/raw.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNvwAABB8"]
[Tue Jul 21 07:35:31.093017 2026] [autoindex:error] [pid 255769:tid 255948] [client 20.197.195.24:62680] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:31.109196 2026] [security2:error] [pid 255769:tid 255915] [client 20.197.195.24:62680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNwAAAA7M"]
[Tue Jul 21 07:35:31.166336 2026] [security2:error] [pid 255769:tid 255818] [remote 74.7.243.250:45036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orixmed.com.inlaudo.com.br"] [uri "/index.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNwQAD4TA"], referer: https://orixmed.com.inlaudo.com.br/blog/
[Tue Jul 21 07:35:31.224830 2026] [security2:error] [pid 255769:tid 255838] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNwwAEE0Q"]
[Tue Jul 21 07:35:31.224954 2026] [security2:error] [pid 255769:tid 256013] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNwwAEE0Q"]
[Tue Jul 21 07:35:31.419459 2026] [security2:error] [pid 255769:tid 256015] [client 172.245.102.44:60773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNxAAABBU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:31.464897 2026] [security2:error] [pid 255769:tid 255864] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNxQADp14"]
[Tue Jul 21 07:35:31.465074 2026] [security2:error] [pid 255769:tid 255903] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNxQADp14"]
[Tue Jul 21 07:35:31.544637 2026] [security2:error] [pid 255769:tid 255908] [client 20.220.225.223:38662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/jga.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNxgAAA6w"]
[Tue Jul 21 07:35:31.616776 2026] [security2:error] [pid 255769:tid 255960] [client 20.206.105.145:38961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ms-edit.php"] [unique_id "al9Lc7xMYwyVGnfuwsKNyAAAA-A"]
[Tue Jul 21 07:35:32.171657 2026] [security2:error] [pid 255769:tid 255900] [client 45.8.17.135:36423] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "al9LdLxMYwyVGnfuwsKNzQAAA6Q"]
[Tue Jul 21 07:35:32.303006 2026] [security2:error] [pid 254995:tid 255148] [client 37.140.223.200:29103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Lc_7v0rlcEGmVraEyeAAAAzU"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:35:32.347811 2026] [security2:error] [pid 255769:tid 255821] [remote 4.205.168.44:48986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/wp-login.php"] [unique_id "al9LdLxMYwyVGnfuwsKNzwADyjM"]
[Tue Jul 21 07:35:32.869881 2026] [security2:error] [pid 255769:tid 256024] [client 139.167.225.182:56520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LdLxMYwyVGnfuwsKN0wAABB4"]
[Tue Jul 21 07:35:32.870007 2026] [security2:error] [pid 255769:tid 256024] [client 139.167.225.182:56520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LdLxMYwyVGnfuwsKN0wAABB4"]
[Tue Jul 21 07:35:32.949891 2026] [security2:error] [pid 255769:tid 255977] [client 59.96.220.140:53587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LdLxMYwyVGnfuwsKN1gAAA_E"]
[Tue Jul 21 07:35:32.950014 2026] [security2:error] [pid 255769:tid 255977] [client 59.96.220.140:53587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LdLxMYwyVGnfuwsKN1gAAA_E"]
[Tue Jul 21 07:35:33.050912 2026] [security2:error] [pid 254995:tid 254998] [remote 216.73.216.238:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9Ldf7v0rlcEGmVraEyjQADLgI"]
[Tue Jul 21 07:35:33.081437 2026] [security2:error] [pid 255769:tid 255985] [client 45.8.17.60:27061] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/moon.php"] [unique_id "al9LdbxMYwyVGnfuwsKN1wAAA_k"]
[Tue Jul 21 07:35:33.163126 2026] [autoindex:error] [pid 255769:tid 255910] [client 20.197.195.24:62659] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:33.565229 2026] [autoindex:error] [pid 255769:tid 255996] [client 20.197.195.24:62659] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:33.571087 2026] [security2:error] [pid 255769:tid 256007] [client 20.197.195.24:62659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/abcd.php"] [unique_id "al9LdbxMYwyVGnfuwsKN5QAABA0"]
[Tue Jul 21 07:35:33.608703 2026] [security2:error] [pid 255769:tid 255976] [client 82.102.28.107:34030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9LdbxMYwyVGnfuwsKN5wAAA_A"]
[Tue Jul 21 07:35:33.608787 2026] [security2:error] [pid 255769:tid 255976] [client 82.102.28.107:34030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9LdbxMYwyVGnfuwsKN5wAAA_A"]
[Tue Jul 21 07:35:33.658452 2026] [security2:error] [pid 254995:tid 255223] [client 82.102.28.107:58328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Ldf7v0rlcEGmVraEylAAAA38"]
[Tue Jul 21 07:35:33.658531 2026] [security2:error] [pid 254995:tid 255223] [client 82.102.28.107:58328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Ldf7v0rlcEGmVraEylAAAA38"]
[Tue Jul 21 07:35:33.855932 2026] [security2:error] [pid 254995:tid 255129] [client 20.220.225.223:49568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/bootstrap.php"] [unique_id "al9Ldf7v0rlcEGmVraEymQAAAyI"]
[Tue Jul 21 07:35:33.867887 2026] [security2:error] [pid 255769:tid 255855] [remote 216.73.216.238:64131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9LdbxMYwyVGnfuwsKN6wAD01U"]
[Tue Jul 21 07:35:33.925192 2026] [security2:error] [pid 255769:tid 255788] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LdbxMYwyVGnfuwsKN7QADphI"]
[Tue Jul 21 07:35:33.925307 2026] [security2:error] [pid 255769:tid 255902] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LdbxMYwyVGnfuwsKN7QADphI"]
[Tue Jul 21 07:35:34.086021 2026] [security2:error] [pid 254995:tid 255142] [client 20.220.225.223:23477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/wp-explorer.php"] [unique_id "al9Ldv7v0rlcEGmVraEymwAAAy8"]
[Tue Jul 21 07:35:34.127629 2026] [security2:error] [pid 255769:tid 255901] [client 20.206.105.145:39165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/222.php"] [unique_id "al9LdrxMYwyVGnfuwsKN7gAAA6U"]
[Tue Jul 21 07:35:34.395084 2026] [security2:error] [pid 254995:tid 255201] [client 45.8.17.110:30757] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/upload/"] [unique_id "al9Ldv7v0rlcEGmVraEyogAAA2o"]
[Tue Jul 21 07:35:34.596257 2026] [security2:error] [pid 255769:tid 256016] [client 103.162.129.114:50547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LdrxMYwyVGnfuwsKN-gAABBY"]
[Tue Jul 21 07:35:34.596369 2026] [security2:error] [pid 255769:tid 256016] [client 103.162.129.114:50547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LdrxMYwyVGnfuwsKN-gAABBY"]
[Tue Jul 21 07:35:34.792003 2026] [security2:error] [pid 255769:tid 255905] [client 20.220.225.223:52198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/akismet.php"] [unique_id "al9LdrxMYwyVGnfuwsKN_QAAA6k"]
[Tue Jul 21 07:35:34.802684 2026] [security2:error] [pid 254995:tid 255143] [client 20.197.195.24:62719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/file15.php"] [unique_id "al9Ldv7v0rlcEGmVraEyrAAAAzA"]
[Tue Jul 21 07:35:34.875306 2026] [security2:error] [pid 255769:tid 255927] [client 117.251.86.144:37374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LdrxMYwyVGnfuwsKOAQAAA78"]
[Tue Jul 21 07:35:34.875435 2026] [security2:error] [pid 255769:tid 255927] [client 117.251.86.144:37374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LdrxMYwyVGnfuwsKOAQAAA78"]
[Tue Jul 21 07:35:35.136135 2026] [security2:error] [pid 254995:tid 255144] [client 193.36.225.68:26373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Ld_7v0rlcEGmVraEysAAAAzE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:35.200477 2026] [security2:error] [pid 255769:tid 255975] [client 20.220.225.223:31182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/xxx.php"] [unique_id "al9Ld7xMYwyVGnfuwsKOBQAAA-8"]
[Tue Jul 21 07:35:35.228920 2026] [security2:error] [pid 254995:tid 255128] [client 45.251.232.145:59531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEysQAAAyE"]
[Tue Jul 21 07:35:35.229042 2026] [security2:error] [pid 254995:tid 255128] [client 45.251.232.145:59531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEysQAAAyE"]
[Tue Jul 21 07:35:35.276452 2026] [security2:error] [pid 255769:tid 255996] [client 45.8.17.110:52925] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/css/index.php"] [unique_id "al9Ld7xMYwyVGnfuwsKOCAAABAI"]
[Tue Jul 21 07:35:35.496754 2026] [security2:error] [pid 254995:tid 255185] [client 109.248.148.246:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEytwAAA1o"]
[Tue Jul 21 07:35:35.496859 2026] [security2:error] [pid 254995:tid 255185] [client 109.248.148.246:55188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEytwAAA1o"]
[Tue Jul 21 07:35:35.498190 2026] [security2:error] [pid 255769:tid 255959] [client 173.24.185.52:51438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ld7xMYwyVGnfuwsKOCwAAA98"]
[Tue Jul 21 07:35:35.498304 2026] [security2:error] [pid 255769:tid 255959] [client 173.24.185.52:51438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ld7xMYwyVGnfuwsKOCwAAA98"]
[Tue Jul 21 07:35:35.784820 2026] [security2:error] [pid 254995:tid 255090] [remote 202.51.202.242:53698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "growe-ag.jaypi.com.br"] [uri "/wp-login.php"] [unique_id "al9Ld_7v0rlcEGmVraEyuQADZl4"]
[Tue Jul 21 07:35:35.787041 2026] [security2:error] [pid 254995:tid 255186] [client 122.186.204.214:51359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEyugAAA1s"]
[Tue Jul 21 07:35:35.787170 2026] [security2:error] [pid 254995:tid 255186] [client 122.186.204.214:51359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEyugAAA1s"]
[Tue Jul 21 07:35:35.787538 2026] [security2:error] [pid 254995:tid 255114] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEyuwADlHY"]
[Tue Jul 21 07:35:35.787680 2026] [security2:error] [pid 254995:tid 255270] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ld_7v0rlcEGmVraEyuwADlHY"]
[Tue Jul 21 07:35:36.283607 2026] [security2:error] [pid 254995:tid 255137] [client 45.8.17.135:28145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/network/cache/"] [unique_id "al9LeP7v0rlcEGmVraEyyAAAAyo"]
[Tue Jul 21 07:35:36.333843 2026] [security2:error] [pid 254995:tid 255146] [client 172.245.102.31:21397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Ldv7v0rlcEGmVraEynQAAAzM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:35:36.610931 2026] [security2:error] [pid 255769:tid 255957] [client 20.197.195.24:62634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/jp.php"] [unique_id "al9LeLxMYwyVGnfuwsKOFQAAA90"]
[Tue Jul 21 07:35:36.720312 2026] [security2:error] [pid 255769:tid 255951] [client 20.206.105.145:39166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/cgi-bin/index.php"] [unique_id "al9LeLxMYwyVGnfuwsKOFgAAA9c"]
[Tue Jul 21 07:35:36.729049 2026] [security2:error] [pid 254995:tid 255141] [client 117.217.38.194:62934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LeP7v0rlcEGmVraEyzwAAAy4"]
[Tue Jul 21 07:35:36.729180 2026] [security2:error] [pid 254995:tid 255141] [client 117.217.38.194:62934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LeP7v0rlcEGmVraEyzwAAAy4"]
[Tue Jul 21 07:35:36.743544 2026] [security2:error] [pid 255769:tid 255827] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LeLxMYwyVGnfuwsKOFwAEFzk"]
[Tue Jul 21 07:35:36.743673 2026] [security2:error] [pid 255769:tid 256017] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LeLxMYwyVGnfuwsKOFwAEFzk"]
[Tue Jul 21 07:35:37.248513 2026] [security2:error] [pid 255769:tid 255966] [client 122.162.144.145:2938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LebxMYwyVGnfuwsKOHAAAA-Y"]
[Tue Jul 21 07:35:37.248647 2026] [security2:error] [pid 255769:tid 255966] [client 122.162.144.145:2938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LebxMYwyVGnfuwsKOHAAAA-Y"]
[Tue Jul 21 07:35:37.282714 2026] [security2:error] [pid 254995:tid 255217] [client 45.8.17.63:36631] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/abcd.php"] [unique_id "al9Lef7v0rlcEGmVraEy2AAAA3k"]
[Tue Jul 21 07:35:37.292219 2026] [security2:error] [pid 254995:tid 255219] [client 196.251.121.187:49163] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "bestdealsvalmir.com"] [uri "/"] [unique_id "al9Lef7v0rlcEGmVraEy2QAAA3s"]
[Tue Jul 21 07:35:37.297934 2026] [security2:error] [pid 254995:tid 255136] [client 185.213.175.37:63116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "appontime.com.br"] [uri "/"] [unique_id "al9Lef7v0rlcEGmVraEy2gAAAyk"]
[Tue Jul 21 07:35:37.298000 2026] [security2:error] [pid 254995:tid 255136] [client 185.213.175.37:63116] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "appontime.com.br"] [uri "/"] [unique_id "al9Lef7v0rlcEGmVraEy2gAAAyk"]
[Tue Jul 21 07:35:37.581400 2026] [security2:error] [pid 254995:tid 255199] [client 20.220.225.223:23450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/ace2.php"] [unique_id "al9Lef7v0rlcEGmVraEy4wAAA2g"]
[Tue Jul 21 07:35:37.651105 2026] [security2:error] [pid 255769:tid 255945] [client 213.152.162.104:50464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LebxMYwyVGnfuwsKOIwAAA9E"]
[Tue Jul 21 07:35:37.651202 2026] [security2:error] [pid 255769:tid 255945] [client 213.152.162.104:50464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LebxMYwyVGnfuwsKOIwAAA9E"]
[Tue Jul 21 07:35:37.871105 2026] [security2:error] [pid 255769:tid 255931] [client 103.106.20.201:61721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LebxMYwyVGnfuwsKOKAAAA8M"]
[Tue Jul 21 07:35:37.871192 2026] [security2:error] [pid 255769:tid 255931] [client 103.106.20.201:61721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LebxMYwyVGnfuwsKOKAAAA8M"]
[Tue Jul 21 07:35:37.916722 2026] [security2:error] [pid 254995:tid 255172] [client 40.124.175.30:53082] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.72"] [uri "/index.cgi"] [unique_id "al9Lef7v0rlcEGmVraEy6AAAA00"]
[Tue Jul 21 07:35:38.013574 2026] [security2:error] [pid 255769:tid 256007] [client 20.220.225.223:24213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/red.php"] [unique_id "al9LerxMYwyVGnfuwsKOKwAABA0"]
[Tue Jul 21 07:35:38.076014 2026] [security2:error] [pid 255769:tid 255961] [client 45.8.17.126:28535] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyfour/patterns/template-singl-portfolio.php"] [unique_id "al9LerxMYwyVGnfuwsKOLQAAA-E"]
[Tue Jul 21 07:35:38.294481 2026] [security2:error] [pid 255769:tid 255908] [client 20.197.195.24:62690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/f35.php"] [unique_id "al9LerxMYwyVGnfuwsKOMQAAA6w"]
[Tue Jul 21 07:35:38.333793 2026] [security2:error] [pid 254995:tid 255214] [client 20.220.225.223:38685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/hunter.php"] [unique_id "al9Lev7v0rlcEGmVraEy6wAAA3Y"]
[Tue Jul 21 07:35:38.644806 2026] [security2:error] [pid 255769:tid 255996] [client 154.192.233.199:60443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LerxMYwyVGnfuwsKOPAAABAI"]
[Tue Jul 21 07:35:38.645220 2026] [security2:error] [pid 255769:tid 255996] [client 154.192.233.199:60443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LerxMYwyVGnfuwsKOPAAABAI"]
[Tue Jul 21 07:35:39.168262 2026] [security2:error] [pid 254995:tid 255264] [client 193.36.225.54:37343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Le_7v0rlcEGmVraEy9QAAA44"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:39.378069 2026] [security2:error] [pid 255769:tid 255972] [client 45.8.17.103:49591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/class-wp-smtp-bar.php"] [unique_id "al9Le7xMYwyVGnfuwsKORgAAA-w"]
[Tue Jul 21 07:35:39.605095 2026] [security2:error] [pid 254995:tid 255268] [client 20.197.195.24:62655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-load.php"] [unique_id "al9Le_7v0rlcEGmVraEy-QAAA5I"]
[Tue Jul 21 07:35:39.643011 2026] [security2:error] [pid 255769:tid 255993] [client 136.144.33.25:49339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LerxMYwyVGnfuwsKONwAABAA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:35:39.856595 2026] [security2:error] [pid 254995:tid 255155] [client 109.248.148.246:35392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Le_7v0rlcEGmVraEy_QAAAzw"]
[Tue Jul 21 07:35:39.856692 2026] [security2:error] [pid 254995:tid 255155] [client 109.248.148.246:35392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Le_7v0rlcEGmVraEy_QAAAzw"]
[Tue Jul 21 07:35:39.911880 2026] [security2:error] [pid 254995:tid 255028] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Le_7v0rlcEGmVraEy_gADYiA"]
[Tue Jul 21 07:35:39.912112 2026] [security2:error] [pid 254995:tid 255193] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Le_7v0rlcEGmVraEy_gADYiA"]
[Tue Jul 21 07:35:40.113399 2026] [security2:error] [pid 255769:tid 255998] [client 122.164.127.47:65533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LfLxMYwyVGnfuwsKOTgAABAQ"]
[Tue Jul 21 07:35:40.114134 2026] [security2:error] [pid 255769:tid 255998] [client 122.164.127.47:65533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LfLxMYwyVGnfuwsKOTgAABAQ"]
[Tue Jul 21 07:35:40.157618 2026] [security2:error] [pid 254995:tid 255203] [client 103.174.34.15:53754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LfP7v0rlcEGmVraEzBQAAA2w"]
[Tue Jul 21 07:35:40.157718 2026] [security2:error] [pid 254995:tid 255203] [client 103.174.34.15:53754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LfP7v0rlcEGmVraEzBQAAA2w"]
[Tue Jul 21 07:35:40.253764 2026] [security2:error] [pid 254995:tid 255167] [client 173.252.95.19:58388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LfP7v0rlcEGmVraEzBgAAA0g"]
[Tue Jul 21 07:35:40.376215 2026] [security2:error] [pid 254995:tid 255019] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LfP7v0rlcEGmVraEzCgADgxc"]
[Tue Jul 21 07:35:40.376429 2026] [security2:error] [pid 254995:tid 255252] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LfP7v0rlcEGmVraEzCgADgxc"]
[Tue Jul 21 07:35:40.583487 2026] [security2:error] [pid 254995:tid 255150] [client 45.8.17.61:27451] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/assets/images/selam.php"] [unique_id "al9LfP7v0rlcEGmVraEzDwAAAzc"]
[Tue Jul 21 07:35:40.643749 2026] [security2:error] [pid 255769:tid 255923] [client 20.220.225.223:52177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.getveltrixhealth.com"] [uri "/ms.php"] [unique_id "al9LfLxMYwyVGnfuwsKOUAAAA7s"]
[Tue Jul 21 07:35:40.820050 2026] [security2:error] [pid 254995:tid 255044] [remote 156.59.198.136:11984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "issima.net.br"] [uri "/equestre/brasao/brasao-azul-e-branco.pdf"] [unique_id "al9LfP7v0rlcEGmVraEzFAADeTA"]
[Tue Jul 21 07:35:40.934081 2026] [security2:error] [pid 255769:tid 255929] [client 20.197.195.24:50304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/xyn.php"] [unique_id "al9LfLxMYwyVGnfuwsKOUgAAA8E"]
[Tue Jul 21 07:35:41.617382 2026] [autoindex:error] [pid 255769:tid 255969] [client 20.197.195.24:50316] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:41.667779 2026] [security2:error] [pid 255769:tid 255918] [client 45.8.17.106:64121] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/manager.php"] [unique_id "al9LfbxMYwyVGnfuwsKOYAAAA7Y"]
[Tue Jul 21 07:35:41.709676 2026] [autoindex:error] [pid 255769:tid 255968] [client 20.197.195.24:50316] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:35:41.736568 2026] [security2:error] [pid 255769:tid 255985] [client 20.197.195.24:50316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ccc.php"] [unique_id "al9LfbxMYwyVGnfuwsKOYwAAA_k"]
[Tue Jul 21 07:35:41.836408 2026] [security2:error] [pid 255769:tid 255978] [client 20.220.225.223:24222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/fffm.php"] [unique_id "al9LfbxMYwyVGnfuwsKOZAAAA_I"]
[Tue Jul 21 07:35:41.875558 2026] [security2:error] [pid 255769:tid 255802] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LfbxMYwyVGnfuwsKOZQADyCA"]
[Tue Jul 21 07:35:41.875726 2026] [security2:error] [pid 255769:tid 255936] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LfbxMYwyVGnfuwsKOZQADyCA"]
[Tue Jul 21 07:35:41.888914 2026] [security2:error] [pid 255769:tid 255886] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LfbxMYwyVGnfuwsKOZgAEF3Q"]
[Tue Jul 21 07:35:41.889063 2026] [security2:error] [pid 255769:tid 256017] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LfbxMYwyVGnfuwsKOZgAEF3Q"]
[Tue Jul 21 07:35:41.899753 2026] [security2:error] [pid 254995:tid 255147] [client 152.59.154.239:53333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lff7v0rlcEGmVraEzIQAAAzQ"]
[Tue Jul 21 07:35:41.899911 2026] [security2:error] [pid 254995:tid 255147] [client 152.59.154.239:53333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lff7v0rlcEGmVraEzIQAAAzQ"]
[Tue Jul 21 07:35:42.017656 2026] [security2:error] [pid 255769:tid 255811] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LfrxMYwyVGnfuwsKOaQADwCk"]
[Tue Jul 21 07:35:42.017841 2026] [security2:error] [pid 255769:tid 255928] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LfrxMYwyVGnfuwsKOaQADwCk"]
[Tue Jul 21 07:35:42.505549 2026] [security2:error] [pid 255769:tid 255957] [client 59.96.220.140:54098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LfrxMYwyVGnfuwsKOdAAAA90"]
[Tue Jul 21 07:35:42.506291 2026] [security2:error] [pid 255769:tid 255957] [client 59.96.220.140:54098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LfrxMYwyVGnfuwsKOdAAAA90"]
[Tue Jul 21 07:35:42.645021 2026] [proxy:error] [pid 255769:tid 255980] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:42.645123 2026] [proxy_http:error] [pid 255769:tid 255980] [client 20.206.105.145:38986] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:42.645723 2026] [proxy:error] [pid 255769:tid 255980] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:42.645750 2026] [proxy_http:error] [pid 255769:tid 255980] [client 20.206.105.145:38986] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:42.667863 2026] [security2:error] [pid 255769:tid 255959] [client 20.197.195.24:62609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/w.php"] [unique_id "al9LfrxMYwyVGnfuwsKOdwAAA98"]
[Tue Jul 21 07:35:42.740778 2026] [security2:error] [pid 255769:tid 256013] [client 20.220.225.223:24192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/ftde.php"] [unique_id "al9LfrxMYwyVGnfuwsKOegAABBM"]
[Tue Jul 21 07:35:43.055272 2026] [security2:error] [pid 255769:tid 255915] [client 193.36.225.11:29367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LfrxMYwyVGnfuwsKOjQAAA7M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:43.071737 2026] [security2:error] [pid 254995:tid 255210] [client 45.8.17.129:49735] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/upload.php"] [unique_id "al9Lf_7v0rlcEGmVraEzPAAAA3I"]
[Tue Jul 21 07:35:43.636115 2026] [security2:error] [pid 255769:tid 256008] [client 20.197.195.24:62641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Lf7xMYwyVGnfuwsKOoAAABA4"]
[Tue Jul 21 07:35:43.851548 2026] [security2:error] [pid 255769:tid 255957] [client 20.197.195.24:62647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/FWAZ.php"] [unique_id "al9Lf7xMYwyVGnfuwsKOpQAAA90"]
[Tue Jul 21 07:35:43.871414 2026] [security2:error] [pid 255769:tid 255938] [client 45.8.17.139:60087] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "al9Lf7xMYwyVGnfuwsKOpgAAA8o"]
[Tue Jul 21 07:35:44.297656 2026] [security2:error] [pid 255769:tid 255847] [remote 103.112.62.59:48934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/wp-login.php"] [unique_id "al9LgLxMYwyVGnfuwsKOrwAEH00"]
[Tue Jul 21 07:35:44.403225 2026] [security2:error] [pid 254995:tid 255147] [client 20.206.105.145:38468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9LgP7v0rlcEGmVraEzXAAAAzQ"]
[Tue Jul 21 07:35:44.497155 2026] [security2:error] [pid 255769:tid 255916] [client 139.167.225.182:57176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LgLxMYwyVGnfuwsKOswAAA7Q"]
[Tue Jul 21 07:35:44.497308 2026] [security2:error] [pid 255769:tid 255916] [client 139.167.225.182:57176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LgLxMYwyVGnfuwsKOswAAA7Q"]
[Tue Jul 21 07:35:44.543086 2026] [security2:error] [pid 254995:tid 255267] [client 20.197.195.24:50348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/miru1.php"] [unique_id "al9LgP7v0rlcEGmVraEzXgAAA5E"]
[Tue Jul 21 07:35:44.814226 2026] [security2:error] [pid 255769:tid 255843] [remote 159.223.116.62:37234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.116.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9LgLxMYwyVGnfuwsKOuQAD80k"]
[Tue Jul 21 07:35:44.843285 2026] [security2:error] [pid 255769:tid 255867] [remote 47.128.25.17:50984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcoll.com.br"] [uri "/web/page.php"] [unique_id "al9LgLxMYwyVGnfuwsKOugAD-GE"]
[Tue Jul 21 07:35:44.867179 2026] [security2:error] [pid 255769:tid 255954] [client 20.197.195.24:62716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/aa.php"] [unique_id "al9LgLxMYwyVGnfuwsKOvAAAA9o"]
[Tue Jul 21 07:35:44.980250 2026] [security2:error] [pid 255769:tid 256016] [client 45.8.17.103:59917] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/buy.php"] [unique_id "al9LgLxMYwyVGnfuwsKOvQAABBY"]
[Tue Jul 21 07:35:45.486396 2026] [security2:error] [pid 255769:tid 255969] [client 103.162.129.114:51006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LgbxMYwyVGnfuwsKOwwAAA-k"]
[Tue Jul 21 07:35:45.486550 2026] [security2:error] [pid 255769:tid 255969] [client 103.162.129.114:51006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LgbxMYwyVGnfuwsKOwwAAA-k"]
[Tue Jul 21 07:35:45.540304 2026] [security2:error] [pid 255769:tid 255952] [client 117.251.86.144:40332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LgbxMYwyVGnfuwsKOxAAAA9g"]
[Tue Jul 21 07:35:45.540414 2026] [security2:error] [pid 255769:tid 255952] [client 117.251.86.144:40332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LgbxMYwyVGnfuwsKOxAAAA9g"]
[Tue Jul 21 07:35:45.673774 2026] [security2:error] [pid 255769:tid 255948] [client 20.220.225.223:49837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-editor.php"] [unique_id "al9LgbxMYwyVGnfuwsKOxQAAA9Q"]
[Tue Jul 21 07:35:45.679217 2026] [security2:error] [pid 255769:tid 255973] [client 45.251.232.145:60051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LgbxMYwyVGnfuwsKOxgAAA-0"]
[Tue Jul 21 07:35:45.679348 2026] [security2:error] [pid 255769:tid 255973] [client 45.251.232.145:60051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LgbxMYwyVGnfuwsKOxgAAA-0"]
[Tue Jul 21 07:35:45.879529 2026] [security2:error] [pid 255769:tid 255962] [client 20.197.195.24:49165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/122.php"] [unique_id "al9LgbxMYwyVGnfuwsKOywAAA-I"]
[Tue Jul 21 07:35:46.043062 2026] [security2:error] [pid 255769:tid 255980] [client 20.220.225.223:24197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/yup.php"] [unique_id "al9LgrxMYwyVGnfuwsKOzgAAA_Q"]
[Tue Jul 21 07:35:46.130024 2026] [security2:error] [pid 254995:tid 255272] [client 173.24.185.52:51910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Lgv7v0rlcEGmVraEzcAAAA5Y"]
[Tue Jul 21 07:35:46.130154 2026] [security2:error] [pid 254995:tid 255272] [client 173.24.185.52:51910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Lgv7v0rlcEGmVraEzcAAAA5Y"]
[Tue Jul 21 07:35:46.173981 2026] [security2:error] [pid 255769:tid 255932] [client 45.8.17.117:25031] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/zgbrarc/cong.php"] [unique_id "al9LgrxMYwyVGnfuwsKO0AAAA8Q"]
[Tue Jul 21 07:35:46.299880 2026] [security2:error] [pid 255769:tid 255832] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LgrxMYwyVGnfuwsKO0QAD9z4"]
[Tue Jul 21 07:35:46.300090 2026] [security2:error] [pid 255769:tid 255983] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LgrxMYwyVGnfuwsKO0QAD9z4"]
[Tue Jul 21 07:35:46.590743 2026] [security2:error] [pid 255769:tid 255996] [client 20.197.195.24:62675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/get.php"] [unique_id "al9LgrxMYwyVGnfuwsKO1AAABAI"]
[Tue Jul 21 07:35:46.624960 2026] [security2:error] [pid 255769:tid 255959] [client 20.206.105.145:39118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/BDKR28WP.php"] [unique_id "al9LgrxMYwyVGnfuwsKO1QAAA98"]
[Tue Jul 21 07:35:46.637316 2026] [security2:error] [pid 255769:tid 255938] [client 122.186.204.214:51869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LgrxMYwyVGnfuwsKO1gAAA8o"]
[Tue Jul 21 07:35:46.637417 2026] [security2:error] [pid 255769:tid 255938] [client 122.186.204.214:51869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LgrxMYwyVGnfuwsKO1gAAA8o"]
[Tue Jul 21 07:35:46.697769 2026] [security2:error] [pid 254995:tid 255169] [client 20.197.195.24:49173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/as.php"] [unique_id "al9Lgv7v0rlcEGmVraEzoAAAA0o"]
[Tue Jul 21 07:35:46.805305 2026] [security2:error] [pid 255769:tid 256003] [client 20.197.195.24:62689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ccou.php"] [unique_id "al9LgrxMYwyVGnfuwsKO2AAABAk"]
[Tue Jul 21 07:35:46.850079 2026] [security2:error] [pid 255769:tid 255789] [remote 132.148.72.88:38916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9LgrxMYwyVGnfuwsKO2QADthM"]
[Tue Jul 21 07:35:47.026825 2026] [security2:error] [pid 255769:tid 255997] [client 20.197.195.24:50315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/w3lls.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO3gAABAM"]
[Tue Jul 21 07:35:47.127104 2026] [security2:error] [pid 255769:tid 255982] [client 20.206.105.145:37931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO4AAAA_Y"]
[Tue Jul 21 07:35:47.219055 2026] [security2:error] [pid 255769:tid 255961] [client 117.217.38.194:63405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO4QAAA-E"]
[Tue Jul 21 07:35:47.219185 2026] [security2:error] [pid 255769:tid 255961] [client 117.217.38.194:63405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO4QAAA-E"]
[Tue Jul 21 07:35:47.222780 2026] [security2:error] [pid 255769:tid 256011] [client 193.36.225.70:55413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO4gAABBE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:47.227983 2026] [security2:error] [pid 255769:tid 255926] [client 20.197.195.24:62630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/test1.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO4wAAA74"]
[Tue Jul 21 07:35:47.371172 2026] [security2:error] [pid 255769:tid 255870] [remote 173.212.252.15:50404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "odontoclinicms.com.br"] [uri "/wp-login.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO5QADuWQ"]
[Tue Jul 21 07:35:47.409518 2026] [security2:error] [pid 255769:tid 256005] [client 122.129.67.13:59520] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LgrxMYwyVGnfuwsKOzwAABAs"]
[Tue Jul 21 07:35:47.409623 2026] [security2:error] [pid 255769:tid 256005] [client 122.129.67.13:59520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LgrxMYwyVGnfuwsKOzwAABAs"]
[Tue Jul 21 07:35:47.431341 2026] [security2:error] [pid 255769:tid 255793] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO5gADwBc"]
[Tue Jul 21 07:35:47.431516 2026] [security2:error] [pid 255769:tid 255928] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO5gADwBc"]
[Tue Jul 21 07:35:47.535717 2026] [proxy:error] [pid 254995:tid 255269] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:47.535791 2026] [proxy_http:error] [pid 254995:tid 255269] [client 20.206.105.145:39293] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:47.536325 2026] [proxy:error] [pid 254995:tid 255269] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:47.536349 2026] [proxy_http:error] [pid 254995:tid 255269] [client 20.206.105.145:39293] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:47.726141 2026] [security2:error] [pid 255769:tid 255980] [client 20.197.195.24:62635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/database.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO6QAAA_Q"]
[Tue Jul 21 07:35:47.734975 2026] [security2:error] [pid 255769:tid 256024] [client 175.45.70.82:56989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO6gAABB4"]
[Tue Jul 21 07:35:47.735076 2026] [security2:error] [pid 255769:tid 256024] [client 175.45.70.82:56989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO6gAABB4"]
[Tue Jul 21 07:35:47.910512 2026] [security2:error] [pid 255769:tid 256026] [client 122.162.144.145:6879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO7gAABCA"]
[Tue Jul 21 07:35:47.913172 2026] [security2:error] [pid 255769:tid 256026] [client 122.162.144.145:6879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Lg7xMYwyVGnfuwsKO7gAABCA"]
[Tue Jul 21 07:35:47.996874 2026] [security2:error] [pid 254995:tid 255182] [client 20.220.225.223:24274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/jj.php"] [unique_id "al9Lg_7v0rlcEGmVraEzvgAAA1c"]
[Tue Jul 21 07:35:48.048249 2026] [proxy:error] [pid 254995:tid 255185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:48.048332 2026] [proxy_http:error] [pid 254995:tid 255185] [client 20.206.105.145:39112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:48.048936 2026] [proxy:error] [pid 254995:tid 255185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:48.048974 2026] [proxy_http:error] [pid 254995:tid 255185] [client 20.206.105.145:39112] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:48.343158 2026] [security2:error] [pid 254995:tid 255130] [client 20.197.195.24:62665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/file.php"] [unique_id "al9LhP7v0rlcEGmVraEzyQAAAyM"]
[Tue Jul 21 07:35:48.511677 2026] [security2:error] [pid 255769:tid 255983] [client 20.220.225.223:49825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/cro.php"] [unique_id "al9LhLxMYwyVGnfuwsKO9gAAA_c"]
[Tue Jul 21 07:35:48.557592 2026] [security2:error] [pid 255769:tid 255948] [client 103.106.20.201:62287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LhLxMYwyVGnfuwsKO9wAAA9Q"]
[Tue Jul 21 07:35:48.557723 2026] [security2:error] [pid 255769:tid 255948] [client 103.106.20.201:62287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LhLxMYwyVGnfuwsKO9wAAA9Q"]
[Tue Jul 21 07:35:48.573840 2026] [security2:error] [pid 254995:tid 255210] [client 45.8.17.144:31753] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9LhP7v0rlcEGmVraEz0QAAA3I"]
[Tue Jul 21 07:35:48.977002 2026] [security2:error] [pid 254995:tid 255125] [client 20.197.195.24:62651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/file.php"] [unique_id "al9LhP7v0rlcEGmVraEz3gAAAx4"]
[Tue Jul 21 07:35:49.082541 2026] [security2:error] [pid 255769:tid 255919] [client 20.206.105.145:38955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp.php"] [unique_id "al9LhbxMYwyVGnfuwsKO-gAAA7c"]
[Tue Jul 21 07:35:49.153053 2026] [security2:error] [pid 254995:tid 255166] [client 20.206.105.145:37899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/x.php"] [unique_id "al9Lhf7v0rlcEGmVraEz7QAAA0c"]
[Tue Jul 21 07:35:49.374252 2026] [security2:error] [pid 254995:tid 255140] [client 45.8.17.62:58553] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/customize/wp-conflg.php"] [unique_id "al9Lhf7v0rlcEGmVraEz-QAAAy0"]
[Tue Jul 21 07:35:49.564042 2026] [security2:error] [pid 255769:tid 255903] [client 20.197.195.24:50319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/777.php"] [unique_id "al9LhbxMYwyVGnfuwsKO_QAAA6c"]
[Tue Jul 21 07:35:49.673008 2026] [security2:error] [pid 255769:tid 256021] [client 20.206.105.145:39295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/abcd.php"] [unique_id "al9LhbxMYwyVGnfuwsKO_gAABBs"]
[Tue Jul 21 07:35:50.270514 2026] [rewrite:error] [pid 255769:tid 255966] [client 187.49.76.218:19841] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:35:50.272545 2026] [rewrite:error] [pid 255769:tid 255943] [client 187.49.76.218:19873] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:35:50.290880 2026] [rewrite:error] [pid 255769:tid 255999] [client 187.49.76.218:19905] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:35:50.462222 2026] [security2:error] [pid 255769:tid 255790] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LhrxMYwyVGnfuwsKPCQADvhQ"]
[Tue Jul 21 07:35:50.462423 2026] [security2:error] [pid 255769:tid 255926] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LhrxMYwyVGnfuwsKPCQADvhQ"]
[Tue Jul 21 07:35:50.593552 2026] [security2:error] [pid 254995:tid 255229] [client 122.164.127.47:49688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Lhv7v0rlcEGmVraE0GQAAA4I"]
[Tue Jul 21 07:35:50.593666 2026] [security2:error] [pid 254995:tid 255229] [client 122.164.127.47:49688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Lhv7v0rlcEGmVraE0GQAAA4I"]
[Tue Jul 21 07:35:50.674436 2026] [security2:error] [pid 255769:tid 255962] [client 45.8.17.128:60189] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/themes.php"] [unique_id "al9LhrxMYwyVGnfuwsKPFgAAA-I"]
[Tue Jul 21 07:35:50.681195 2026] [security2:error] [pid 255769:tid 255957] [client 20.206.105.145:37910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/j260624_13.php"] [unique_id "al9LhrxMYwyVGnfuwsKPGAAAA90"]
[Tue Jul 21 07:35:50.686909 2026] [security2:error] [pid 255769:tid 255986] [client 20.220.225.223:31105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/we.php"] [unique_id "al9LhrxMYwyVGnfuwsKPGQAAA_o"]
[Tue Jul 21 07:35:50.698846 2026] [security2:error] [pid 255769:tid 255899] [client 20.197.195.24:49158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ssixta.php"] [unique_id "al9LhrxMYwyVGnfuwsKPGgAAA6M"]
[Tue Jul 21 07:35:50.955024 2026] [security2:error] [pid 255769:tid 255920] [client 103.174.34.15:54243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LhrxMYwyVGnfuwsKPHAAAA7g"]
[Tue Jul 21 07:35:50.955169 2026] [security2:error] [pid 255769:tid 255920] [client 103.174.34.15:54243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LhrxMYwyVGnfuwsKPHAAAA7g"]
[Tue Jul 21 07:35:51.185423 2026] [security2:error] [pid 255769:tid 255979] [client 136.144.33.105:30871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Lh7xMYwyVGnfuwsKPHgAAA_M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:51.249783 2026] [security2:error] [pid 255769:tid 255818] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lh7xMYwyVGnfuwsKPJgADwjA"]
[Tue Jul 21 07:35:51.250047 2026] [security2:error] [pid 255769:tid 255930] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lh7xMYwyVGnfuwsKPJgADwjA"]
[Tue Jul 21 07:35:51.582894 2026] [security2:error] [pid 255769:tid 255987] [client 45.8.17.135:46075] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/fmadmin.php"] [unique_id "al9Lh7xMYwyVGnfuwsKPKwAAA_s"]
[Tue Jul 21 07:35:51.811200 2026] [security2:error] [pid 255769:tid 255982] [client 20.52.136.55:1729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/max.php"] [unique_id "al9Lh7xMYwyVGnfuwsKPLgAAA_Y"]
[Tue Jul 21 07:35:51.853281 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.195.24:62686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/1c.php"] [unique_id "al9Lh7xMYwyVGnfuwsKPLwAABAU"]
[Tue Jul 21 07:35:51.957643 2026] [access_compat:error] [pid 255769:tid 255950] [client 162.241.63.68:58306] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:35:52.056690 2026] [security2:error] [pid 254995:tid 255168] [client 20.220.225.223:49835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/cron-tab.php"] [unique_id "al9LiP7v0rlcEGmVraE0KgAAA0k"]
[Tue Jul 21 07:35:52.087641 2026] [security2:error] [pid 255769:tid 255864] [remote 74.7.243.250:50296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orixmed.com.inlaudo.com.br"] [uri "/blog/artigo1.php"] [unique_id "al9LiLxMYwyVGnfuwsKPNAAD2F4"], referer: https://orixmed.com.inlaudo.com.br/blog/
[Tue Jul 21 07:35:52.355613 2026] [security2:error] [pid 255769:tid 255839] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LiLxMYwyVGnfuwsKPNwAD4kU"]
[Tue Jul 21 07:35:52.355776 2026] [security2:error] [pid 255769:tid 255962] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LiLxMYwyVGnfuwsKPNwAD4kU"]
[Tue Jul 21 07:35:52.540980 2026] [security2:error] [pid 254995:tid 255074] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LiP7v0rlcEGmVraE0MgADgU4"]
[Tue Jul 21 07:35:52.541131 2026] [security2:error] [pid 254995:tid 255225] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LiP7v0rlcEGmVraE0MgADgU4"]
[Tue Jul 21 07:35:52.565350 2026] [security2:error] [pid 255769:tid 255837] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LiLxMYwyVGnfuwsKPOwADpUM"]
[Tue Jul 21 07:35:52.565486 2026] [security2:error] [pid 255769:tid 255901] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LiLxMYwyVGnfuwsKPOwADpUM"]
[Tue Jul 21 07:35:52.809953 2026] [rewrite:error] [pid 255769:tid 255948] [client 187.49.76.218:19905] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2414
[Tue Jul 21 07:35:52.809954 2026] [rewrite:error] [pid 255769:tid 255970] [client 187.49.76.218:19873] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2414
[Tue Jul 21 07:35:52.811993 2026] [rewrite:error] [pid 255769:tid 255960] [client 187.49.76.218:19841] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2414
[Tue Jul 21 07:35:53.218133 2026] [security2:error] [pid 255769:tid 255925] [client 20.52.136.55:1539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/m.php"] [unique_id "al9LibxMYwyVGnfuwsKPRQAAA70"]
[Tue Jul 21 07:35:53.283239 2026] [security2:error] [pid 255769:tid 255916] [client 20.197.195.24:62658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/test2.php"] [unique_id "al9LibxMYwyVGnfuwsKPRgAAA7Q"]
[Tue Jul 21 07:35:53.679106 2026] [security2:error] [pid 255769:tid 256021] [client 45.8.17.60:38865] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/class.api.php"] [unique_id "al9LibxMYwyVGnfuwsKPTgAABBs"]
[Tue Jul 21 07:35:53.805807 2026] [security2:error] [pid 254995:tid 255126] [client 20.206.105.145:38497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/d62.php"] [unique_id "al9Lif7v0rlcEGmVraE0RwAAAx8"]
[Tue Jul 21 07:35:53.992604 2026] [security2:error] [pid 255769:tid 255929] [client 152.59.154.239:53825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LibxMYwyVGnfuwsKPUgAAA8E"]
[Tue Jul 21 07:35:53.992728 2026] [security2:error] [pid 255769:tid 255929] [client 152.59.154.239:53825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LibxMYwyVGnfuwsKPUgAAA8E"]
[Tue Jul 21 07:35:54.087054 2026] [security2:error] [pid 254995:tid 255199] [client 109.248.148.246:55884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Liv7v0rlcEGmVraE0TwAAA2g"]
[Tue Jul 21 07:35:54.087173 2026] [security2:error] [pid 254995:tid 255199] [client 109.248.148.246:55884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Liv7v0rlcEGmVraE0TwAAA2g"]
[Tue Jul 21 07:35:54.255372 2026] [security2:error] [pid 254995:tid 255182] [client 20.197.195.24:62662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/buy.php"] [unique_id "al9Liv7v0rlcEGmVraE0VgAAA1c"]
[Tue Jul 21 07:35:54.462423 2026] [security2:error] [pid 254995:tid 255091] [remote 45.150.79.142:36632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oferta.happynbox.com.br"] [uri "/wp-login.php"] [unique_id "al9Liv7v0rlcEGmVraE0VwADNF8"]
[Tue Jul 21 07:35:54.509524 2026] [security2:error] [pid 254995:tid 255269] [client 139.167.225.182:57819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Liv7v0rlcEGmVraE0WAAAA5M"]
[Tue Jul 21 07:35:54.509687 2026] [security2:error] [pid 254995:tid 255269] [client 139.167.225.182:57819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Liv7v0rlcEGmVraE0WAAAA5M"]
[Tue Jul 21 07:35:54.584173 2026] [security2:error] [pid 254995:tid 255215] [client 20.206.105.145:39126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/a1.php"] [unique_id "al9Liv7v0rlcEGmVraE0WgAAA3c"]
[Tue Jul 21 07:35:54.676639 2026] [security2:error] [pid 255769:tid 256008] [client 45.8.17.59:20693] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "al9LirxMYwyVGnfuwsKPUwAABA4"]
[Tue Jul 21 07:35:54.784510 2026] [security2:error] [pid 255769:tid 255936] [client 20.52.136.55:1741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/click.php"] [unique_id "al9LirxMYwyVGnfuwsKPVgAAA8g"]
[Tue Jul 21 07:35:54.940114 2026] [security2:error] [pid 254995:tid 255188] [client 213.152.162.104:48696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Liv7v0rlcEGmVraE0YQAAA10"]
[Tue Jul 21 07:35:54.940222 2026] [security2:error] [pid 254995:tid 255188] [client 213.152.162.104:48696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Liv7v0rlcEGmVraE0YQAAA10"]
[Tue Jul 21 07:35:55.111827 2026] [security2:error] [pid 254995:tid 255176] [client 20.197.195.24:62699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ssend.php"] [unique_id "al9Li_7v0rlcEGmVraE0ZAAAA1E"]
[Tue Jul 21 07:35:55.341568 2026] [security2:error] [pid 254995:tid 255170] [client 20.220.225.223:48139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/koiy.php"] [unique_id "al9Li_7v0rlcEGmVraE0awAAA0s"]
[Tue Jul 21 07:35:55.353966 2026] [security2:error] [pid 255769:tid 256013] [client 20.220.225.223:31184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9Li7xMYwyVGnfuwsKPYAAABBM"]
[Tue Jul 21 07:35:55.456551 2026] [security2:error] [pid 255769:tid 255985] [client 20.220.225.223:38660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "spiarcursos.com.br"] [uri "/phpinfo.php1"] [unique_id "al9Li7xMYwyVGnfuwsKPYQAAA_k"]
[Tue Jul 21 07:35:55.500137 2026] [security2:error] [pid 255769:tid 256009] [client 20.197.195.24:50308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/item.php"] [unique_id "al9Li7xMYwyVGnfuwsKPYgAABA8"]
[Tue Jul 21 07:35:55.677746 2026] [security2:error] [pid 254995:tid 255141] [client 45.8.17.105:45195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/index.php"] [unique_id "al9Li_7v0rlcEGmVraE0bQAAAy4"]
[Tue Jul 21 07:35:55.909954 2026] [security2:error] [pid 255769:tid 256025] [client 20.197.195.24:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ss.php"] [unique_id "al9Li7xMYwyVGnfuwsKPZQAABB8"]
[Tue Jul 21 07:35:56.030836 2026] [security2:error] [pid 255769:tid 255940] [client 103.162.129.114:51487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LjLxMYwyVGnfuwsKPZwAAA8w"]
[Tue Jul 21 07:35:56.030945 2026] [security2:error] [pid 255769:tid 255940] [client 103.162.129.114:51487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LjLxMYwyVGnfuwsKPZwAAA8w"]
[Tue Jul 21 07:35:56.209197 2026] [security2:error] [pid 254995:tid 255132] [client 45.251.232.145:60582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LjP7v0rlcEGmVraE0dwAAAyU"]
[Tue Jul 21 07:35:56.209304 2026] [security2:error] [pid 254995:tid 255132] [client 45.251.232.145:60582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LjP7v0rlcEGmVraE0dwAAAyU"]
[Tue Jul 21 07:35:56.267070 2026] [security2:error] [pid 255769:tid 255990] [client 20.197.195.24:62604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/hypo.php"] [unique_id "al9LjLxMYwyVGnfuwsKPagAAA_4"]
[Tue Jul 21 07:35:56.585696 2026] [security2:error] [pid 255769:tid 256022] [client 45.8.17.134:64773] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9LjLxMYwyVGnfuwsKPbwAABBw"]
[Tue Jul 21 07:35:56.616759 2026] [security2:error] [pid 255769:tid 255965] [client 20.197.195.24:62601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/users.php"] [unique_id "al9LjLxMYwyVGnfuwsKPcAAAA-U"]
[Tue Jul 21 07:35:56.769247 2026] [security2:error] [pid 255769:tid 255855] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LjLxMYwyVGnfuwsKPdAAECVU"]
[Tue Jul 21 07:35:56.769426 2026] [security2:error] [pid 255769:tid 256003] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LjLxMYwyVGnfuwsKPdAAECVU"]
[Tue Jul 21 07:35:56.819868 2026] [security2:error] [pid 255769:tid 255938] [client 173.24.185.52:52391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LjLxMYwyVGnfuwsKPdQAAA8o"]
[Tue Jul 21 07:35:56.819998 2026] [security2:error] [pid 255769:tid 255938] [client 173.24.185.52:52391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LjLxMYwyVGnfuwsKPdQAAA8o"]
[Tue Jul 21 07:35:56.831269 2026] [security2:error] [pid 255769:tid 255788] [remote 41.76.214.143:40600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinadona.com"] [uri "/wp-login.php"] [unique_id "al9LjLxMYwyVGnfuwsKPdgAD1BI"]
[Tue Jul 21 07:35:56.992921 2026] [security2:error] [pid 255769:tid 256014] [client 20.206.105.145:38478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ups.php"] [unique_id "al9LjLxMYwyVGnfuwsKPeQAABBQ"]
[Tue Jul 21 07:35:57.271134 2026] [security2:error] [pid 255769:tid 255935] [client 122.186.204.214:52386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LjbxMYwyVGnfuwsKPfAAAA8c"]
[Tue Jul 21 07:35:57.271257 2026] [security2:error] [pid 255769:tid 255935] [client 122.186.204.214:52386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LjbxMYwyVGnfuwsKPfAAAA8c"]
[Tue Jul 21 07:35:57.402009 2026] [security2:error] [pid 255769:tid 256028] [client 82.102.28.107:39710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9LjbxMYwyVGnfuwsKPfQAABCI"]
[Tue Jul 21 07:35:57.402118 2026] [security2:error] [pid 255769:tid 256028] [client 82.102.28.107:39710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9LjbxMYwyVGnfuwsKPfQAABCI"]
[Tue Jul 21 07:35:57.418793 2026] [security2:error] [pid 255769:tid 255944] [client 20.197.195.24:62648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/177.php"] [unique_id "al9LjbxMYwyVGnfuwsKPfgAAA9A"]
[Tue Jul 21 07:35:57.490995 2026] [security2:error] [pid 254995:tid 255222] [client 20.197.195.24:62606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/config.php"] [unique_id "al9Ljf7v0rlcEGmVraE0iQAAA34"]
[Tue Jul 21 07:35:57.613663 2026] [security2:error] [pid 254995:tid 255148] [client 173.252.95.41:51124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Ljf7v0rlcEGmVraE0igAAAzU"]
[Tue Jul 21 07:35:57.678091 2026] [security2:error] [pid 255769:tid 256013] [client 45.8.17.135:32019] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/assets/index.php"] [unique_id "al9LjbxMYwyVGnfuwsKPhAAABBM"]
[Tue Jul 21 07:35:57.686953 2026] [security2:error] [pid 255769:tid 255926] [client 117.217.38.194:63873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LjbxMYwyVGnfuwsKPhQAAA74"]
[Tue Jul 21 07:35:57.687062 2026] [security2:error] [pid 255769:tid 255926] [client 117.217.38.194:63873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LjbxMYwyVGnfuwsKPhQAAA74"]
[Tue Jul 21 07:35:57.795653 2026] [security2:error] [pid 254995:tid 255151] [client 20.206.105.145:37902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/k.php"] [unique_id "al9Ljf7v0rlcEGmVraE0jQAAAzg"]
[Tue Jul 21 07:35:57.834528 2026] [security2:error] [pid 255769:tid 255920] [client 20.197.195.24:62632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/gettest.php"] [unique_id "al9LjbxMYwyVGnfuwsKPhwAAA7g"]
[Tue Jul 21 07:35:58.122997 2026] [security2:error] [pid 255769:tid 255890] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LjrxMYwyVGnfuwsKPiwAD03g"]
[Tue Jul 21 07:35:58.123188 2026] [security2:error] [pid 255769:tid 255947] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LjrxMYwyVGnfuwsKPiwAD03g"]
[Tue Jul 21 07:35:58.339501 2026] [security2:error] [pid 254995:tid 255161] [client 136.144.33.98:24731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Ljv7v0rlcEGmVraE0mgAAA0I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:35:58.393494 2026] [security2:error] [pid 254995:tid 255177] [client 20.197.195.24:62639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/min.php"] [unique_id "al9Ljv7v0rlcEGmVraE0nAAAA1I"]
[Tue Jul 21 07:35:58.400645 2026] [security2:error] [pid 254995:tid 255196] [client 175.45.70.82:58069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ljv7v0rlcEGmVraE0nQAAA2U"]
[Tue Jul 21 07:35:58.400762 2026] [security2:error] [pid 254995:tid 255196] [client 175.45.70.82:58069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ljv7v0rlcEGmVraE0nQAAA2U"]
[Tue Jul 21 07:35:58.404638 2026] [security2:error] [pid 254995:tid 255184] [client 20.206.105.145:38952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9Ljv7v0rlcEGmVraE0ngAAA1k"]
[Tue Jul 21 07:35:58.581522 2026] [security2:error] [pid 254995:tid 255133] [client 45.8.17.117:53445] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "al9Ljv7v0rlcEGmVraE0pwAAAyY"]
[Tue Jul 21 07:35:58.677517 2026] [security2:error] [pid 254995:tid 255194] [client 122.162.144.145:24465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Ljv7v0rlcEGmVraE0qgAAA2M"]
[Tue Jul 21 07:35:58.677624 2026] [security2:error] [pid 254995:tid 255194] [client 122.162.144.145:24465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Ljv7v0rlcEGmVraE0qgAAA2M"]
[Tue Jul 21 07:35:58.927715 2026] [security2:error] [pid 254995:tid 255219] [client 20.197.195.24:62663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/dvjul.php"] [unique_id "al9Ljv7v0rlcEGmVraE0tAAAA3s"]
[Tue Jul 21 07:35:59.312847 2026] [security2:error] [pid 254995:tid 255145] [client 103.106.20.201:62862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lj_7v0rlcEGmVraE0vQAAAzI"]
[Tue Jul 21 07:35:59.313057 2026] [security2:error] [pid 254995:tid 255145] [client 103.106.20.201:62862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lj_7v0rlcEGmVraE0vQAAAzI"]
[Tue Jul 21 07:35:59.444970 2026] [security2:error] [pid 255769:tid 255929] [client 20.197.195.24:62633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/biufile.php"] [unique_id "al9Lj7xMYwyVGnfuwsKPlwAAA8E"]
[Tue Jul 21 07:35:59.475638 2026] [security2:error] [pid 255769:tid 255984] [client 45.8.17.107:31875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/load.php"] [unique_id "al9Lj7xMYwyVGnfuwsKPmAAAA_g"]
[Tue Jul 21 07:35:59.635692 2026] [security2:error] [pid 255769:tid 255986] [client 20.220.225.223:31168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/ee.php"] [unique_id "al9Lj7xMYwyVGnfuwsKPnAAAA_o"]
[Tue Jul 21 07:35:59.665540 2026] [proxy:error] [pid 254995:tid 255157] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:59.665600 2026] [proxy_http:error] [pid 254995:tid 255157] [client 20.206.105.145:39106] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:59.666090 2026] [proxy:error] [pid 254995:tid 255157] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:35:59.666120 2026] [proxy_http:error] [pid 254995:tid 255157] [client 20.206.105.145:39106] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:35:59.754706 2026] [security2:error] [pid 255769:tid 255827] [remote 103.82.22.235:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9LjrxMYwyVGnfuwsKPkAAEDDk"]
[Tue Jul 21 07:35:59.896175 2026] [security2:error] [pid 255769:tid 255775] [remote 132.148.72.88:56946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9Lj7xMYwyVGnfuwsKPoQADpgU"]
[Tue Jul 21 07:36:00.145001 2026] [security2:error] [pid 255769:tid 255901] [client 37.140.223.157:62359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LjbxMYwyVGnfuwsKPigAAA6U"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:00.175212 2026] [autoindex:error] [pid 255769:tid 255810] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:00.407240 2026] [security2:error] [pid 254995:tid 255213] [client 45.8.17.114:35573] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/index.php"] [unique_id "al9LkP7v0rlcEGmVraE00QAAA3U"]
[Tue Jul 21 07:36:00.705623 2026] [security2:error] [pid 254995:tid 255146] [client 20.197.195.24:50335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/av.php"] [unique_id "al9LkP7v0rlcEGmVraE01gAAAzM"]
[Tue Jul 21 07:36:00.764366 2026] [proxy:error] [pid 255769:tid 255921] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:00.764430 2026] [proxy_http:error] [pid 255769:tid 255921] [client 20.206.105.145:39008] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:00.764952 2026] [proxy:error] [pid 255769:tid 255921] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:00.764976 2026] [proxy_http:error] [pid 255769:tid 255921] [client 20.206.105.145:39008] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:00.985291 2026] [security2:error] [pid 255769:tid 255878] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LkLxMYwyVGnfuwsKPrgAEH2w"]
[Tue Jul 21 07:36:00.985456 2026] [security2:error] [pid 255769:tid 256025] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LkLxMYwyVGnfuwsKPrgAEH2w"]
[Tue Jul 21 07:36:01.249010 2026] [security2:error] [pid 255769:tid 255985] [client 122.164.127.47:50188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LkbxMYwyVGnfuwsKPtAAAA_k"]
[Tue Jul 21 07:36:01.249154 2026] [security2:error] [pid 255769:tid 255985] [client 122.164.127.47:50188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LkbxMYwyVGnfuwsKPtAAAA_k"]
[Tue Jul 21 07:36:01.281468 2026] [security2:error] [pid 254995:tid 255168] [client 45.8.17.119:50495] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/k.php"] [unique_id "al9Lkf7v0rlcEGmVraE03wAAA0k"]
[Tue Jul 21 07:36:01.366249 2026] [security2:error] [pid 255769:tid 255860] [remote 195.211.44.104:57384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.44.211.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/wp-login.php"] [unique_id "al9Lj7xMYwyVGnfuwsKPlAADtFo"]
[Tue Jul 21 07:36:01.508894 2026] [security2:error] [pid 255769:tid 255994] [client 20.220.225.223:24272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/dragonshell.php"] [unique_id "al9LkbxMYwyVGnfuwsKPuQAABAE"]
[Tue Jul 21 07:36:01.690968 2026] [security2:error] [pid 255769:tid 255905] [client 103.174.34.15:54726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LkbxMYwyVGnfuwsKPwAAAA6k"]
[Tue Jul 21 07:36:01.691080 2026] [security2:error] [pid 255769:tid 255905] [client 103.174.34.15:54726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LkbxMYwyVGnfuwsKPwAAAA6k"]
[Tue Jul 21 07:36:02.029335 2026] [security2:error] [pid 255769:tid 255802] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LkrxMYwyVGnfuwsKPxwAD-CA"]
[Tue Jul 21 07:36:02.029597 2026] [security2:error] [pid 255769:tid 255984] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LkrxMYwyVGnfuwsKPxwAD-CA"]
[Tue Jul 21 07:36:02.044204 2026] [security2:error] [pid 254995:tid 255193] [client 136.144.33.108:53639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Lkv7v0rlcEGmVraE06wAAA2I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:02.160537 2026] [security2:error] [pid 254995:tid 255156] [client 20.197.195.24:62671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/coffexium.php"] [unique_id "al9Lkv7v0rlcEGmVraE07wAAAz0"]
[Tue Jul 21 07:36:02.180409 2026] [security2:error] [pid 255769:tid 255957] [client 45.8.17.48:35327] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-conflg.php"] [unique_id "al9LkrxMYwyVGnfuwsKPzwAAA90"]
[Tue Jul 21 07:36:02.414781 2026] [security2:error] [pid 254995:tid 255218] [client 173.252.95.38:43320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Lkv7v0rlcEGmVraE08AAAA3o"]
[Tue Jul 21 07:36:02.841884 2026] [security2:error] [pid 255769:tid 256008] [client 20.206.105.145:37929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/k2.php"] [unique_id "al9LkbxMYwyVGnfuwsKPwwAABA4"]
[Tue Jul 21 07:36:02.877563 2026] [security2:error] [pid 255769:tid 255811] [remote 103.190.239.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.239.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LkrxMYwyVGnfuwsKP1gAEBCk"]
[Tue Jul 21 07:36:02.877725 2026] [security2:error] [pid 255769:tid 255998] [client 103.190.239.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LkrxMYwyVGnfuwsKP1gAEBCk"]
[Tue Jul 21 07:36:03.082278 2026] [security2:error] [pid 255769:tid 255892] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Lk7xMYwyVGnfuwsKP2AAD-Xo"]
[Tue Jul 21 07:36:03.082414 2026] [security2:error] [pid 255769:tid 255985] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Lk7xMYwyVGnfuwsKP2AAD-Xo"]
[Tue Jul 21 07:36:03.134783 2026] [security2:error] [pid 255769:tid 255916] [client 20.220.225.223:24232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/wp-mt.php"] [unique_id "al9Lk7xMYwyVGnfuwsKP8gAAA7Q"]
[Tue Jul 21 07:36:03.177736 2026] [security2:error] [pid 255769:tid 256012] [client 45.8.17.106:30475] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/block-bindings/"] [unique_id "al9Lk7xMYwyVGnfuwsKP_AAABBI"]
[Tue Jul 21 07:36:03.235937 2026] [security2:error] [pid 255769:tid 255951] [client 37.140.223.50:53805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LkrxMYwyVGnfuwsKPywAAA9c"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:03.247581 2026] [security2:error] [pid 254995:tid 255090] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lk_7v0rlcEGmVraE0_gADMl4"]
[Tue Jul 21 07:36:03.247768 2026] [security2:error] [pid 254995:tid 255145] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lk_7v0rlcEGmVraE0_gADMl4"]
[Tue Jul 21 07:36:03.465889 2026] [security2:error] [pid 254995:tid 255148] [client 20.197.195.24:50318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/core.php"] [unique_id "al9Lk_7v0rlcEGmVraE1AAAAAzU"]
[Tue Jul 21 07:36:03.615311 2026] [proxy:error] [pid 255769:tid 256016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:03.615378 2026] [proxy_http:error] [pid 255769:tid 256016] [client 20.206.105.145:38931] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:03.615915 2026] [proxy:error] [pid 255769:tid 256016] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:03.615943 2026] [proxy_http:error] [pid 255769:tid 256016] [client 20.206.105.145:38931] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:03.851879 2026] [security2:error] [pid 255769:tid 255984] [client 20.206.105.145:38464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/k3.php"] [unique_id "al9Lk7xMYwyVGnfuwsKQCgAAA_g"]
[Tue Jul 21 07:36:03.921876 2026] [security2:error] [pid 255769:tid 255902] [client 20.197.195.24:50314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/als.php"] [unique_id "al9Lk7xMYwyVGnfuwsKQCwAAA6Y"]
[Tue Jul 21 07:36:04.028120 2026] [security2:error] [pid 254995:tid 255162] [client 213.152.162.104:58078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LlP7v0rlcEGmVraE1CAAAA0M"]
[Tue Jul 21 07:36:04.028211 2026] [security2:error] [pid 254995:tid 255162] [client 213.152.162.104:58078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LlP7v0rlcEGmVraE1CAAAA0M"]
[Tue Jul 21 07:36:04.097341 2026] [security2:error] [pid 255769:tid 255977] [client 20.52.136.55:1565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/lv.php"] [unique_id "al9LlLxMYwyVGnfuwsKQEwAAA_E"]
[Tue Jul 21 07:36:04.129897 2026] [security2:error] [pid 255769:tid 255901] [client 20.220.225.223:48189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/hp2.php"] [unique_id "al9LlLxMYwyVGnfuwsKQGAAAA6U"]
[Tue Jul 21 07:36:04.176337 2026] [security2:error] [pid 255769:tid 255993] [client 45.8.17.49:63183] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-confiq.php"] [unique_id "al9LlLxMYwyVGnfuwsKQGQAABAA"]
[Tue Jul 21 07:36:04.385018 2026] [security2:error] [pid 255769:tid 255952] [client 20.197.195.24:62698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/simple.php"] [unique_id "al9LlLxMYwyVGnfuwsKQJAAAA9g"]
[Tue Jul 21 07:36:04.866334 2026] [security2:error] [pid 255769:tid 255923] [client 20.197.195.24:62653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/init.php"] [unique_id "al9LlLxMYwyVGnfuwsKQNQAAA7s"]
[Tue Jul 21 07:36:05.077757 2026] [security2:error] [pid 255769:tid 255953] [client 45.8.17.147:46761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/fm.php/sts.php"] [unique_id "al9LlbxMYwyVGnfuwsKQPgAAA9k"]
[Tue Jul 21 07:36:05.131111 2026] [security2:error] [pid 255769:tid 255975] [client 152.59.154.239:54290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LlbxMYwyVGnfuwsKQPwAAA-8"]
[Tue Jul 21 07:36:05.131208 2026] [security2:error] [pid 255769:tid 255975] [client 152.59.154.239:54290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LlbxMYwyVGnfuwsKQPwAAA-8"]
[Tue Jul 21 07:36:05.452790 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.195.24:49198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/fpwch.php"] [unique_id "al9LlbxMYwyVGnfuwsKQRwAABAU"]
[Tue Jul 21 07:36:05.499099 2026] [security2:error] [pid 255769:tid 256003] [client 20.206.105.145:37940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/k4.php"] [unique_id "al9LlbxMYwyVGnfuwsKQSAAABAk"]
[Tue Jul 21 07:36:05.569272 2026] [security2:error] [pid 255769:tid 255994] [client 122.129.67.13:59133] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LlbxMYwyVGnfuwsKQSQAABAE"]
[Tue Jul 21 07:36:05.569421 2026] [security2:error] [pid 255769:tid 255994] [client 122.129.67.13:59133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9LlbxMYwyVGnfuwsKQSQAABAE"]
[Tue Jul 21 07:36:05.757492 2026] [security2:error] [pid 255769:tid 256020] [client 20.220.225.223:49545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/hp3.php"] [unique_id "al9LlbxMYwyVGnfuwsKQTQAABBo"]
[Tue Jul 21 07:36:05.784756 2026] [security2:error] [pid 255769:tid 255951] [client 139.167.225.182:58463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LlbxMYwyVGnfuwsKQTgAAA9c"]
[Tue Jul 21 07:36:05.784874 2026] [security2:error] [pid 255769:tid 255951] [client 139.167.225.182:58463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LlbxMYwyVGnfuwsKQTgAAA9c"]
[Tue Jul 21 07:36:05.973887 2026] [security2:error] [pid 254995:tid 255272] [client 59.96.220.140:54918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Llf7v0rlcEGmVraE1JAAAA5Y"]
[Tue Jul 21 07:36:05.975379 2026] [security2:error] [pid 254995:tid 255272] [client 59.96.220.140:54918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Llf7v0rlcEGmVraE1JAAAA5Y"]
[Tue Jul 21 07:36:06.275563 2026] [security2:error] [pid 254995:tid 255218] [client 45.8.17.127:34561] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/upload/index.php"] [unique_id "al9Llv7v0rlcEGmVraE1JwAAA3o"]
[Tue Jul 21 07:36:06.409033 2026] [security2:error] [pid 255769:tid 255921] [client 82.102.28.107:59374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LlrxMYwyVGnfuwsKQUQAAA7k"]
[Tue Jul 21 07:36:06.409129 2026] [security2:error] [pid 255769:tid 255921] [client 82.102.28.107:59374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LlrxMYwyVGnfuwsKQUQAAA7k"]
[Tue Jul 21 07:36:06.424306 2026] [security2:error] [pid 255769:tid 255966] [client 20.197.195.24:50323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/domvf.php"] [unique_id "al9LlrxMYwyVGnfuwsKQUgAAA-Y"]
[Tue Jul 21 07:36:06.682401 2026] [security2:error] [pid 255769:tid 255962] [client 45.251.232.145:61101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LlrxMYwyVGnfuwsKQVAAAA-I"]
[Tue Jul 21 07:36:06.682519 2026] [security2:error] [pid 255769:tid 255962] [client 45.251.232.145:61101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LlrxMYwyVGnfuwsKQVAAAA-I"]
[Tue Jul 21 07:36:06.701787 2026] [security2:error] [pid 255769:tid 255969] [client 20.206.105.145:37936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/k5.php"] [unique_id "al9LlrxMYwyVGnfuwsKQVQAAA-k"]
[Tue Jul 21 07:36:06.821019 2026] [security2:error] [pid 255769:tid 255955] [client 136.144.33.97:51763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LlrxMYwyVGnfuwsKQUwAAA9s"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:06.838839 2026] [rewrite:error] [pid 255769:tid 255939] [client 187.49.76.218:20161] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:06.841273 2026] [rewrite:error] [pid 255769:tid 256009] [client 187.49.76.218:20193] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:06.862565 2026] [rewrite:error] [pid 255769:tid 255976] [client 187.49.76.218:20321] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:07.138060 2026] [security2:error] [pid 254995:tid 255276] [client 103.162.129.114:51951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll_7v0rlcEGmVraE1MgAAA5o"]
[Tue Jul 21 07:36:07.138211 2026] [security2:error] [pid 254995:tid 255276] [client 103.162.129.114:51951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll_7v0rlcEGmVraE1MgAAA5o"]
[Tue Jul 21 07:36:07.168869 2026] [security2:error] [pid 254995:tid 255145] [client 20.220.225.223:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/bscclapb.php"] [unique_id "al9Ll_7v0rlcEGmVraE1MwAAAzI"]
[Tue Jul 21 07:36:07.176590 2026] [security2:error] [pid 254995:tid 255128] [client 45.8.17.113:27227] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/images/index.php"] [unique_id "al9Ll_7v0rlcEGmVraE1NgAAAyE"]
[Tue Jul 21 07:36:07.322711 2026] [security2:error] [pid 255769:tid 255819] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll7xMYwyVGnfuwsKQYAAEGzE"]
[Tue Jul 21 07:36:07.322856 2026] [security2:error] [pid 255769:tid 256021] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll7xMYwyVGnfuwsKQYAAEGzE"]
[Tue Jul 21 07:36:07.431407 2026] [security2:error] [pid 254995:tid 255154] [client 37.140.223.191:24821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Ll_7v0rlcEGmVraE1OAAAAzs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:07.449036 2026] [security2:error] [pid 255769:tid 256007] [client 173.24.185.52:52866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll7xMYwyVGnfuwsKQYQAABA0"]
[Tue Jul 21 07:36:07.449154 2026] [security2:error] [pid 255769:tid 256007] [client 173.24.185.52:52866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll7xMYwyVGnfuwsKQYQAABA0"]
[Tue Jul 21 07:36:07.737372 2026] [security2:error] [pid 254995:tid 255262] [client 20.197.195.24:62649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp.php"] [unique_id "al9Ll_7v0rlcEGmVraE1RQAAA4w"]
[Tue Jul 21 07:36:07.972017 2026] [security2:error] [pid 254995:tid 255263] [client 122.186.204.214:52968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll_7v0rlcEGmVraE1SAAAA40"]
[Tue Jul 21 07:36:07.975752 2026] [security2:error] [pid 254995:tid 255263] [client 122.186.204.214:52968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ll_7v0rlcEGmVraE1SAAAA40"]
[Tue Jul 21 07:36:07.996401 2026] [security2:error] [pid 254995:tid 255136] [client 20.206.105.145:37946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/w.php"] [unique_id "al9Ll_7v0rlcEGmVraE1TAAAAyk"]
[Tue Jul 21 07:36:08.078369 2026] [security2:error] [pid 254995:tid 255134] [client 45.8.17.146:62145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "al9LmP7v0rlcEGmVraE1TQAAAyc"]
[Tue Jul 21 07:36:08.180649 2026] [security2:error] [pid 255769:tid 256014] [client 117.217.38.194:64346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LmLxMYwyVGnfuwsKQZAAABBQ"]
[Tue Jul 21 07:36:08.180761 2026] [security2:error] [pid 255769:tid 256014] [client 117.217.38.194:64346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LmLxMYwyVGnfuwsKQZAAABBQ"]
[Tue Jul 21 07:36:08.561306 2026] [rewrite:error] [pid 255769:tid 255951] [client 187.49.76.218:20193] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2415
[Tue Jul 21 07:36:08.561306 2026] [rewrite:error] [pid 255769:tid 255924] [client 187.49.76.218:20321] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2415
[Tue Jul 21 07:36:08.563321 2026] [rewrite:error] [pid 255769:tid 255944] [client 187.49.76.218:20161] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2415
[Tue Jul 21 07:36:08.872211 2026] [security2:error] [pid 255769:tid 255899] [client 45.8.17.61:20647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "al9LmLxMYwyVGnfuwsKQbwAAA6M"]
[Tue Jul 21 07:36:08.997619 2026] [security2:error] [pid 255769:tid 255788] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LmLxMYwyVGnfuwsKQcwAECxI"]
[Tue Jul 21 07:36:08.997768 2026] [security2:error] [pid 255769:tid 256005] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LmLxMYwyVGnfuwsKQcwAECxI"]
[Tue Jul 21 07:36:09.070528 2026] [security2:error] [pid 255769:tid 255966] [client 20.197.195.24:50358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/class.php"] [unique_id "al9LmbxMYwyVGnfuwsKQdgAAA-Y"]
[Tue Jul 21 07:36:09.149214 2026] [security2:error] [pid 255769:tid 256008] [client 20.206.105.145:39159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9LmbxMYwyVGnfuwsKQeAAABA4"]
[Tue Jul 21 07:36:09.163775 2026] [security2:error] [pid 255769:tid 255992] [client 20.52.136.55:1595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/cong.php"] [unique_id "al9LmbxMYwyVGnfuwsKQeQAAA_8"]
[Tue Jul 21 07:36:09.223217 2026] [security2:error] [pid 254995:tid 255194] [client 175.45.70.82:58654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lmf7v0rlcEGmVraE1WQAAA2M"]
[Tue Jul 21 07:36:09.223368 2026] [security2:error] [pid 254995:tid 255194] [client 175.45.70.82:58654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lmf7v0rlcEGmVraE1WQAAA2M"]
[Tue Jul 21 07:36:09.445651 2026] [autoindex:error] [pid 254995:tid 255212] [client 147.185.132.57:59012] AH01276: Cannot serve directory /home1/taina869/tvexpressiva.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:09.450679 2026] [security2:error] [pid 255769:tid 255957] [client 122.162.144.145:21003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LmbxMYwyVGnfuwsKQggAAA90"]
[Tue Jul 21 07:36:09.450788 2026] [security2:error] [pid 255769:tid 255957] [client 122.162.144.145:21003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LmbxMYwyVGnfuwsKQggAAA90"]
[Tue Jul 21 07:36:09.467968 2026] [security2:error] [pid 255769:tid 255930] [client 20.206.105.145:37922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/fpwch.php"] [unique_id "al9LmbxMYwyVGnfuwsKQgwAAA8I"]
[Tue Jul 21 07:36:09.674412 2026] [security2:error] [pid 255769:tid 255978] [client 45.8.17.146:64513] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "al9LmbxMYwyVGnfuwsKQhwAAA_I"]
[Tue Jul 21 07:36:09.898917 2026] [security2:error] [pid 255769:tid 255948] [client 20.197.195.24:62676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/echkm.php"] [unique_id "al9LmbxMYwyVGnfuwsKQjAAAA9Q"]
[Tue Jul 21 07:36:10.045688 2026] [security2:error] [pid 255769:tid 255932] [client 103.106.20.201:63444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LmrxMYwyVGnfuwsKQjwAAA8Q"]
[Tue Jul 21 07:36:10.045849 2026] [security2:error] [pid 255769:tid 255932] [client 103.106.20.201:63444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LmrxMYwyVGnfuwsKQjwAAA8Q"]
[Tue Jul 21 07:36:10.237313 2026] [security2:error] [pid 255769:tid 255905] [client 185.251.19.73:27395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9LmrxMYwyVGnfuwsKQkwAAA6k"]
[Tue Jul 21 07:36:10.479000 2026] [security2:error] [pid 255769:tid 255974] [client 185.251.19.80:26839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9LmbxMYwyVGnfuwsKQiAAAA-4"]
[Tue Jul 21 07:36:10.507133 2026] [security2:error] [pid 255769:tid 255981] [client 193.36.225.67:21923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LmrxMYwyVGnfuwsKQlwAAA_U"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:10.668578 2026] [security2:error] [pid 255769:tid 255920] [client 20.197.195.24:62670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/lib.php"] [unique_id "al9LmrxMYwyVGnfuwsKQmQAAA7g"]
[Tue Jul 21 07:36:10.777206 2026] [security2:error] [pid 254995:tid 255264] [client 45.8.17.125:49537] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "al9Lmv7v0rlcEGmVraE1bQAAA44"]
[Tue Jul 21 07:36:10.902488 2026] [security2:error] [pid 255769:tid 256002] [client 20.206.105.145:37932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/w2025.php"] [unique_id "al9LmrxMYwyVGnfuwsKQmgAABAg"]
[Tue Jul 21 07:36:10.962164 2026] [security2:error] [pid 255769:tid 255786] [remote 124.55.178.99:56036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9LmrxMYwyVGnfuwsKQnQADpRA"]
[Tue Jul 21 07:36:11.444565 2026] [security2:error] [pid 255769:tid 255919] [client 20.197.195.24:50322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/login.php"] [unique_id "al9Lm7xMYwyVGnfuwsKQowAAA7c"]
[Tue Jul 21 07:36:11.507617 2026] [security2:error] [pid 255769:tid 255840] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lm7xMYwyVGnfuwsKQqAAD90Y"]
[Tue Jul 21 07:36:11.507744 2026] [security2:error] [pid 255769:tid 255983] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lm7xMYwyVGnfuwsKQqAAD90Y"]
[Tue Jul 21 07:36:11.736196 2026] [security2:error] [pid 255769:tid 256021] [client 20.220.225.223:24247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/ww.php"] [unique_id "al9Lm7xMYwyVGnfuwsKQqgAABBs"]
[Tue Jul 21 07:36:11.804621 2026] [security2:error] [pid 255769:tid 256012] [client 20.197.195.24:62624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/a2.php"] [unique_id "al9Lm7xMYwyVGnfuwsKQrAAABBI"]
[Tue Jul 21 07:36:12.026227 2026] [security2:error] [pid 254995:tid 255222] [client 122.164.127.47:50698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LnP7v0rlcEGmVraE1fgAAA34"]
[Tue Jul 21 07:36:12.026322 2026] [security2:error] [pid 254995:tid 255222] [client 122.164.127.47:50698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LnP7v0rlcEGmVraE1fgAAA34"]
[Tue Jul 21 07:36:12.274565 2026] [security2:error] [pid 254995:tid 255255] [client 20.197.195.24:62627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/d61.php"] [unique_id "al9LnP7v0rlcEGmVraE1gQAAA4U"]
[Tue Jul 21 07:36:12.373548 2026] [security2:error] [pid 254995:tid 255148] [client 103.174.34.15:55206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LnP7v0rlcEGmVraE1ggAAAzU"]
[Tue Jul 21 07:36:12.374059 2026] [security2:error] [pid 254995:tid 255148] [client 103.174.34.15:55206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LnP7v0rlcEGmVraE1ggAAAzU"]
[Tue Jul 21 07:36:12.531458 2026] [security2:error] [pid 255769:tid 255900] [client 37.140.223.137:64763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LmrxMYwyVGnfuwsKQlAAAA6Q"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:12.819202 2026] [security2:error] [pid 255769:tid 255944] [client 20.197.195.24:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/info.php"] [unique_id "al9LnLxMYwyVGnfuwsKQtAAAA9A"]
[Tue Jul 21 07:36:12.902061 2026] [security2:error] [pid 254995:tid 255011] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LnP7v0rlcEGmVraE1igADjQ8"]
[Tue Jul 21 07:36:12.902217 2026] [security2:error] [pid 254995:tid 255263] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LnP7v0rlcEGmVraE1igADjQ8"]
[Tue Jul 21 07:36:12.972646 2026] [security2:error] [pid 254995:tid 255187] [client 45.8.17.146:42073] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/languages/index.php"] [unique_id "al9LnP7v0rlcEGmVraE1jAAAA1w"]
[Tue Jul 21 07:36:13.066974 2026] [security2:error] [pid 254995:tid 255179] [client 20.197.195.24:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/11.php"] [unique_id "al9Lnf7v0rlcEGmVraE1jQAAA1Q"]
[Tue Jul 21 07:36:13.075931 2026] [security2:error] [pid 255769:tid 256013] [client 20.52.136.55:1574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/brand.php"] [unique_id "al9LnbxMYwyVGnfuwsKQuAAABBM"]
[Tue Jul 21 07:36:13.197187 2026] [security2:error] [pid 254995:tid 255213] [client 20.206.105.145:38117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/scxy.php"] [unique_id "al9Lnf7v0rlcEGmVraE1kQAAA3U"]
[Tue Jul 21 07:36:13.485091 2026] [security2:error] [pid 255769:tid 256003] [client 20.197.195.24:50353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/v2.php"] [unique_id "al9LnbxMYwyVGnfuwsKQugAABAk"]
[Tue Jul 21 07:36:13.584074 2026] [security2:error] [pid 255769:tid 255802] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LnbxMYwyVGnfuwsKQuwAD5iA"]
[Tue Jul 21 07:36:13.584224 2026] [security2:error] [pid 255769:tid 255966] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LnbxMYwyVGnfuwsKQuwAD5iA"]
[Tue Jul 21 07:36:13.748966 2026] [security2:error] [pid 254995:tid 255167] [client 20.197.195.24:62695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/panel.php"] [unique_id "al9Lnf7v0rlcEGmVraE1nAAAA0g"]
[Tue Jul 21 07:36:13.918120 2026] [security2:error] [pid 255769:tid 255801] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LnbxMYwyVGnfuwsKQvwAD_x8"]
[Tue Jul 21 07:36:13.918282 2026] [security2:error] [pid 255769:tid 255992] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LnbxMYwyVGnfuwsKQvwAD_x8"]
[Tue Jul 21 07:36:14.181684 2026] [security2:error] [pid 255769:tid 255976] [client 45.8.17.129:52867] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/media-new.php"] [unique_id "al9LnrxMYwyVGnfuwsKQwAAAA_A"]
[Tue Jul 21 07:36:14.406594 2026] [security2:error] [pid 254995:tid 255152] [client 59.96.220.140:55668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Lnv7v0rlcEGmVraE1qAAAAzk"]
[Tue Jul 21 07:36:14.406723 2026] [security2:error] [pid 254995:tid 255152] [client 59.96.220.140:55668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Lnv7v0rlcEGmVraE1qAAAAzk"]
[Tue Jul 21 07:36:14.567301 2026] [security2:error] [pid 255769:tid 255937] [client 136.144.33.97:33441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LnrxMYwyVGnfuwsKQxQAAA8k"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:14.630021 2026] [security2:error] [pid 255769:tid 255892] [remote 216.73.216.238:41157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9LnrxMYwyVGnfuwsKQxgADtno"]
[Tue Jul 21 07:36:14.636040 2026] [security2:error] [pid 254995:tid 255070] [remote 116.179.37.119:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9Lnf7v0rlcEGmVraE1lwADY0o"], referer: https://androapkmod.com/esposa-de-detetive-lobisomem-apk-mod/
[Tue Jul 21 07:36:15.120888 2026] [security2:error] [pid 255769:tid 255900] [client 20.206.105.145:39158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/gettest.php"] [unique_id "al9Ln7xMYwyVGnfuwsKQzwAAA6Q"]
[Tue Jul 21 07:36:15.205527 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.195.24:62657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/dex.php"] [unique_id "al9Ln7xMYwyVGnfuwsKQ0QAABCI"]
[Tue Jul 21 07:36:15.251116 2026] [security2:error] [pid 255769:tid 255834] [remote 182.77.62.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amandamorau.adv.br"] [uri "/wp-login.php"] [unique_id "al9Ln7xMYwyVGnfuwsKQ0gADqUA"]
[Tue Jul 21 07:36:15.384949 2026] [security2:error] [pid 254995:tid 255153] [client 20.206.105.145:38483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/FWAZ.php"] [unique_id "al9Ln_7v0rlcEGmVraE1uAAAAzo"]
[Tue Jul 21 07:36:15.778881 2026] [security2:error] [pid 254995:tid 255269] [client 45.8.17.130:20057] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/tiny.php"] [unique_id "al9Ln_7v0rlcEGmVraE1uwAAA5M"]
[Tue Jul 21 07:36:16.368845 2026] [security2:error] [pid 255769:tid 255989] [client 152.59.154.239:54785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LoLxMYwyVGnfuwsKQ2wAAA_0"]
[Tue Jul 21 07:36:16.368958 2026] [security2:error] [pid 255769:tid 255989] [client 152.59.154.239:54785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LoLxMYwyVGnfuwsKQ2wAAA_0"]
[Tue Jul 21 07:36:16.509423 2026] [security2:error] [pid 254995:tid 255211] [client 20.197.195.24:49179] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.cmpartners.com.br"] [uri "/1.php"] [unique_id "al9LoP7v0rlcEGmVraE1ygAAA3M"]
[Tue Jul 21 07:36:16.509590 2026] [security2:error] [pid 254995:tid 255211] [client 20.197.195.24:49179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/1.php"] [unique_id "al9LoP7v0rlcEGmVraE1ygAAA3M"]
[Tue Jul 21 07:36:16.939287 2026] [security2:error] [pid 255769:tid 255907] [client 20.52.136.55:1506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/atomlib.php"] [unique_id "al9LoLxMYwyVGnfuwsKQ3wAAA6s"]
[Tue Jul 21 07:36:17.068556 2026] [security2:error] [pid 254995:tid 255146] [client 45.8.17.61:37417] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/license.php"] [unique_id "al9Lof7v0rlcEGmVraE10gAAAzM"]
[Tue Jul 21 07:36:17.144177 2026] [security2:error] [pid 254995:tid 255256] [client 45.251.232.145:61622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lof7v0rlcEGmVraE11AAAA4Y"]
[Tue Jul 21 07:36:17.144317 2026] [security2:error] [pid 254995:tid 255256] [client 45.251.232.145:61622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lof7v0rlcEGmVraE11AAAA4Y"]
[Tue Jul 21 07:36:17.275058 2026] [security2:error] [pid 254995:tid 255268] [client 20.220.225.223:49584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/aa1.php"] [unique_id "al9Lof7v0rlcEGmVraE11QAAA5I"]
[Tue Jul 21 07:36:17.343614 2026] [security2:error] [pid 254995:tid 255155] [client 20.220.225.223:38677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/wp-signup.php"] [unique_id "al9Lof7v0rlcEGmVraE11wAAAzw"]
[Tue Jul 21 07:36:17.597714 2026] [security2:error] [pid 255769:tid 255985] [client 139.167.225.182:59106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LobxMYwyVGnfuwsKQ4wAAA_k"]
[Tue Jul 21 07:36:17.597833 2026] [security2:error] [pid 255769:tid 255985] [client 139.167.225.182:59106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LobxMYwyVGnfuwsKQ4wAAA_k"]
[Tue Jul 21 07:36:17.740918 2026] [security2:error] [pid 255769:tid 256025] [client 117.251.86.144:39874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LobxMYwyVGnfuwsKQ5AAABB8"]
[Tue Jul 21 07:36:17.741049 2026] [security2:error] [pid 255769:tid 256025] [client 117.251.86.144:39874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LobxMYwyVGnfuwsKQ5AAABB8"]
[Tue Jul 21 07:36:17.808800 2026] [security2:error] [pid 255769:tid 255884] [remote 216.73.216.238:61649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9LobxMYwyVGnfuwsKQ5QAD2XI"]
[Tue Jul 21 07:36:17.856554 2026] [security2:error] [pid 255769:tid 255996] [client 103.162.129.114:52404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LobxMYwyVGnfuwsKQ5gAABAI"]
[Tue Jul 21 07:36:17.856637 2026] [security2:error] [pid 255769:tid 255996] [client 103.162.129.114:52404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LobxMYwyVGnfuwsKQ5gAABAI"]
[Tue Jul 21 07:36:17.904359 2026] [rewrite:error] [pid 254995:tid 255260] [client 187.49.76.218:20385] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:17.907179 2026] [rewrite:error] [pid 255769:tid 256021] [client 187.49.76.218:20417] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:17.926594 2026] [rewrite:error] [pid 254995:tid 255160] [client 187.49.76.218:20449] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:18.013192 2026] [security2:error] [pid 255769:tid 255975] [client 173.24.185.52:53340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LorxMYwyVGnfuwsKQ6wAAA-8"]
[Tue Jul 21 07:36:18.013331 2026] [security2:error] [pid 255769:tid 255975] [client 173.24.185.52:53340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LorxMYwyVGnfuwsKQ6wAAA-8"]
[Tue Jul 21 07:36:18.071375 2026] [security2:error] [pid 254995:tid 255219] [client 20.197.195.24:50313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/ms.php"] [unique_id "al9Lov7v0rlcEGmVraE16QAAA3s"]
[Tue Jul 21 07:36:18.076055 2026] [security2:error] [pid 255769:tid 255939] [client 45.8.17.148:54915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/av.php"] [unique_id "al9LorxMYwyVGnfuwsKQ7QAAA8s"]
[Tue Jul 21 07:36:18.087844 2026] [security2:error] [pid 254995:tid 255206] [client 62.102.148.164:47890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Lov7v0rlcEGmVraE16gAAA28"]
[Tue Jul 21 07:36:18.087933 2026] [security2:error] [pid 254995:tid 255206] [client 62.102.148.164:47890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Lov7v0rlcEGmVraE16gAAA28"]
[Tue Jul 21 07:36:18.117154 2026] [security2:error] [pid 254995:tid 255049] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lov7v0rlcEGmVraE16wADizU"]
[Tue Jul 21 07:36:18.117287 2026] [security2:error] [pid 254995:tid 255261] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lov7v0rlcEGmVraE16wADizU"]
[Tue Jul 21 07:36:18.420880 2026] [fcgid:warn] [pid 255769:tid 256020] (70014)End of file found: [client 45.79.115.59:37647] mod_fcgid: can't get data from http client
[Tue Jul 21 07:36:18.565627 2026] [security2:error] [pid 254995:tid 255178] [client 122.186.204.214:53782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lov7v0rlcEGmVraE18wAAA1M"]
[Tue Jul 21 07:36:18.570308 2026] [security2:error] [pid 254995:tid 255178] [client 122.186.204.214:53782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lov7v0rlcEGmVraE18wAAA1M"]
[Tue Jul 21 07:36:18.648532 2026] [security2:error] [pid 255769:tid 256014] [client 117.217.38.194:64813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LorxMYwyVGnfuwsKQ9QAABBQ"]
[Tue Jul 21 07:36:18.648613 2026] [security2:error] [pid 255769:tid 256014] [client 117.217.38.194:64813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LorxMYwyVGnfuwsKQ9QAABBQ"]
[Tue Jul 21 07:36:18.855110 2026] [autoindex:error] [pid 255769:tid 255981] [client 20.197.195.24:50350] AH01276: Cannot serve directory /home4/cmpart62/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:18.877509 2026] [security2:error] [pid 255769:tid 255925] [client 20.197.195.24:50350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/memberfuns.php"] [unique_id "al9LorxMYwyVGnfuwsKQ9wAAA70"]
[Tue Jul 21 07:36:19.117200 2026] [security2:error] [pid 255769:tid 256009] [client 20.206.105.145:38476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/qterm.php"] [unique_id "al9Lo7xMYwyVGnfuwsKQ_gAABA8"]
[Tue Jul 21 07:36:19.136149 2026] [security2:error] [pid 255769:tid 255905] [client 122.129.67.13:59393] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9Lo7xMYwyVGnfuwsKQ_wAAA6k"]
[Tue Jul 21 07:36:19.136262 2026] [security2:error] [pid 255769:tid 255905] [client 122.129.67.13:59393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9Lo7xMYwyVGnfuwsKQ_wAAA6k"]
[Tue Jul 21 07:36:19.180154 2026] [security2:error] [pid 255769:tid 255998] [client 45.8.17.136:44659] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-login-css.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRAAAABAQ"]
[Tue Jul 21 07:36:19.310610 2026] [security2:error] [pid 255769:tid 255785] [remote 154.61.75.100:58612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteoficialgs.com"] [uri "/wp-login.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRAQAD3w8"]
[Tue Jul 21 07:36:19.443004 2026] [rewrite:error] [pid 254995:tid 255182] [client 187.49.76.218:20449] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2417
[Tue Jul 21 07:36:19.443006 2026] [rewrite:error] [pid 255769:tid 255983] [client 187.49.76.218:20417] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2417
[Tue Jul 21 07:36:19.445223 2026] [rewrite:error] [pid 254995:tid 255215] [client 187.49.76.218:20385] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ver-ordem-producao/ver-ordem-producao/2417
[Tue Jul 21 07:36:19.459256 2026] [proxy:error] [pid 255769:tid 255923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:19.459335 2026] [proxy_http:error] [pid 255769:tid 255923] [client 20.206.105.145:39135] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:19.459879 2026] [proxy:error] [pid 255769:tid 255923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:19.459909 2026] [proxy_http:error] [pid 255769:tid 255923] [client 20.206.105.145:39135] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:19.506207 2026] [security2:error] [pid 255769:tid 255795] [remote 45.117.83.212:52014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRBwAD3hk"]
[Tue Jul 21 07:36:19.576419 2026] [security2:error] [pid 255769:tid 255772] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRCQAD2wI"]
[Tue Jul 21 07:36:19.576560 2026] [security2:error] [pid 255769:tid 255955] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRCQAD2wI"]
[Tue Jul 21 07:36:19.839105 2026] [security2:error] [pid 255769:tid 255953] [client 20.206.105.145:37915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/blurbs.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRDAAAA9k"]
[Tue Jul 21 07:36:19.953064 2026] [security2:error] [pid 255769:tid 255929] [client 20.206.105.145:38496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/v543.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRDwAAA8E"]
[Tue Jul 21 07:36:19.967688 2026] [security2:error] [pid 255769:tid 256007] [client 20.197.195.24:62666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/0.php"] [unique_id "al9Lo7xMYwyVGnfuwsKREAAABA0"]
[Tue Jul 21 07:36:19.969971 2026] [security2:error] [pid 255769:tid 255937] [client 136.144.33.99:25389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Lo7xMYwyVGnfuwsKRCwAAA8k"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:20.024019 2026] [security2:error] [pid 255769:tid 255903] [client 20.206.105.145:37890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/w3lls.php"] [unique_id "al9LpLxMYwyVGnfuwsKRFAAAA6c"]
[Tue Jul 21 07:36:20.040198 2026] [security2:error] [pid 254995:tid 255183] [client 175.45.70.82:59215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LpP7v0rlcEGmVraE2BAAAA1g"]
[Tue Jul 21 07:36:20.040295 2026] [security2:error] [pid 254995:tid 255183] [client 175.45.70.82:59215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LpP7v0rlcEGmVraE2BAAAA1g"]
[Tue Jul 21 07:36:20.168992 2026] [security2:error] [pid 255769:tid 255946] [client 122.162.144.145:3056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LpLxMYwyVGnfuwsKRGAAAA9I"]
[Tue Jul 21 07:36:20.169109 2026] [security2:error] [pid 255769:tid 255946] [client 122.162.144.145:3056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LpLxMYwyVGnfuwsKRGAAAA9I"]
[Tue Jul 21 07:36:20.187839 2026] [security2:error] [pid 255769:tid 255944] [client 45.8.17.103:28105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/classwithtostring.php"] [unique_id "al9LpLxMYwyVGnfuwsKRGQAAA9A"]
[Tue Jul 21 07:36:20.259405 2026] [security2:error] [pid 255769:tid 255924] [client 62.102.148.164:33090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9LpLxMYwyVGnfuwsKRGwAAA7w"]
[Tue Jul 21 07:36:20.259495 2026] [security2:error] [pid 255769:tid 255924] [client 62.102.148.164:33090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9LpLxMYwyVGnfuwsKRGwAAA7w"]
[Tue Jul 21 07:36:20.692467 2026] [security2:error] [pid 255769:tid 256003] [client 173.252.95.57:58770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LpLxMYwyVGnfuwsKRIQAABAk"]
[Tue Jul 21 07:36:20.813529 2026] [security2:error] [pid 255769:tid 255984] [client 103.106.20.201:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LpLxMYwyVGnfuwsKRIgAAA_g"]
[Tue Jul 21 07:36:20.813693 2026] [security2:error] [pid 255769:tid 255984] [client 103.106.20.201:64024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LpLxMYwyVGnfuwsKRIgAAA_g"]
[Tue Jul 21 07:36:20.814698 2026] [security2:error] [pid 254995:tid 255164] [client 213.152.162.104:45462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9LpP7v0rlcEGmVraE2DQAAA0U"]
[Tue Jul 21 07:36:20.814783 2026] [security2:error] [pid 254995:tid 255164] [client 213.152.162.104:45462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9LpP7v0rlcEGmVraE2DQAAA0U"]
[Tue Jul 21 07:36:20.869996 2026] [security2:error] [pid 254995:tid 255196] [client 20.206.105.145:37913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-ws68.php"] [unique_id "al9LpP7v0rlcEGmVraE2DwAAA2U"]
[Tue Jul 21 07:36:21.205088 2026] [security2:error] [pid 255769:tid 255947] [client 20.197.195.24:62697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/BDKR28.php"] [unique_id "al9LpbxMYwyVGnfuwsKRJwAAA9M"]
[Tue Jul 21 07:36:21.586204 2026] [security2:error] [pid 255769:tid 255953] [client 45.8.17.48:36405] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/Diff/Engine/template-singl-portfolio.php"] [unique_id "al9LpbxMYwyVGnfuwsKRLwAAA9k"]
[Tue Jul 21 07:36:22.053914 2026] [security2:error] [pid 255769:tid 255776] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LprxMYwyVGnfuwsKRNAAEHAY"]
[Tue Jul 21 07:36:22.054125 2026] [security2:error] [pid 255769:tid 256022] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LprxMYwyVGnfuwsKRNAAEHAY"]
[Tue Jul 21 07:36:22.349945 2026] [security2:error] [pid 254995:tid 255275] [client 20.52.136.55:1586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/0x.php"] [unique_id "al9Lpv7v0rlcEGmVraE2IwAAA5k"]
[Tue Jul 21 07:36:22.352921 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.195.24:50365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/green1.php"] [unique_id "al9LprxMYwyVGnfuwsKRNgAABCI"]
[Tue Jul 21 07:36:22.590297 2026] [security2:error] [pid 255769:tid 255965] [client 193.36.225.143:51567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LpbxMYwyVGnfuwsKRLgAAA-U"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:22.728306 2026] [security2:error] [pid 255769:tid 256014] [client 20.220.225.223:51463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/acew67.php"] [unique_id "al9LprxMYwyVGnfuwsKRQAAABBQ"]
[Tue Jul 21 07:36:22.824969 2026] [security2:error] [pid 255769:tid 255973] [client 122.164.127.47:51200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LprxMYwyVGnfuwsKRQwAAA-0"]
[Tue Jul 21 07:36:22.825123 2026] [security2:error] [pid 255769:tid 255973] [client 122.164.127.47:51200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LprxMYwyVGnfuwsKRQwAAA-0"]
[Tue Jul 21 07:36:22.875667 2026] [security2:error] [pid 254995:tid 255221] [client 45.8.17.126:24785] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "al9Lpv7v0rlcEGmVraE2LgAAA30"]
[Tue Jul 21 07:36:23.031644 2026] [security2:error] [pid 254995:tid 255206] [client 20.197.195.24:62636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/nc4.php"] [unique_id "al9Lp_7v0rlcEGmVraE2MQAAA28"]
[Tue Jul 21 07:36:23.094762 2026] [security2:error] [pid 254995:tid 255208] [client 20.220.225.223:31172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/csa.php"] [unique_id "al9Lp_7v0rlcEGmVraE2NgAAA3A"]
[Tue Jul 21 07:36:23.119702 2026] [security2:error] [pid 255769:tid 255915] [client 103.174.34.15:55684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lp7xMYwyVGnfuwsKRRwAAA7M"]
[Tue Jul 21 07:36:23.119881 2026] [security2:error] [pid 255769:tid 255915] [client 103.174.34.15:55684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lp7xMYwyVGnfuwsKRRwAAA7M"]
[Tue Jul 21 07:36:23.162169 2026] [security2:error] [pid 254995:tid 255272] [client 74.7.175.183:40840] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.abrsolar.org.br"] [uri "/index.php"] [unique_id "al9Lp_7v0rlcEGmVraE2NQADlj8"]
[Tue Jul 21 07:36:23.212284 2026] [fcgid:warn] [pid 254995:tid 255205] (70014)End of file found: [client 199.45.154.126:53748] mod_fcgid: can't get data from http client
[Tue Jul 21 07:36:23.355116 2026] [security2:error] [pid 254995:tid 255181] [client 20.104.96.117:59687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Lp_7v0rlcEGmVraE2PAAAA1Y"]
[Tue Jul 21 07:36:23.410896 2026] [security2:error] [pid 254995:tid 255259] [client 20.206.105.145:37933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/xyn.php"] [unique_id "al9Lp_7v0rlcEGmVraE2PQAAA4k"]
[Tue Jul 21 07:36:23.525419 2026] [security2:error] [pid 254995:tid 255123] [remote 216.73.216.238:60084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9Lp_7v0rlcEGmVraE2QAADZH8"]
[Tue Jul 21 07:36:23.679958 2026] [security2:error] [pid 255769:tid 255911] [client 136.144.33.108:47377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Lp7xMYwyVGnfuwsKRSQAAA68"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:23.786944 2026] [security2:error] [pid 255769:tid 255784] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lp7xMYwyVGnfuwsKRTQAD0Q4"]
[Tue Jul 21 07:36:23.787099 2026] [security2:error] [pid 255769:tid 255945] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lp7xMYwyVGnfuwsKRTQAD0Q4"]
[Tue Jul 21 07:36:23.876186 2026] [security2:error] [pid 255769:tid 256021] [client 45.8.17.107:35051] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/lock360.php"] [unique_id "al9Lp7xMYwyVGnfuwsKRUQAABBs"]
[Tue Jul 21 07:36:24.097713 2026] [security2:error] [pid 255769:tid 255876] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRVAADtmo"]
[Tue Jul 21 07:36:24.097932 2026] [security2:error] [pid 255769:tid 255918] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRVAADtmo"]
[Tue Jul 21 07:36:24.308736 2026] [security2:error] [pid 255769:tid 255982] [client 20.197.195.24:49166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/a1.php"] [unique_id "al9LqLxMYwyVGnfuwsKRWAAAA_Y"]
[Tue Jul 21 07:36:24.405322 2026] [security2:error] [pid 255769:tid 255935] [client 20.206.105.145:39242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/simple.php"] [unique_id "al9LqLxMYwyVGnfuwsKRXgAAA8c"]
[Tue Jul 21 07:36:24.578114 2026] [security2:error] [pid 255769:tid 255814] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRYgAD7Cw"]
[Tue Jul 21 07:36:24.578256 2026] [security2:error] [pid 255769:tid 255972] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRYgAD7Cw"]
[Tue Jul 21 07:36:24.685396 2026] [security2:error] [pid 255769:tid 256002] [client 213.152.162.104:45470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRZQAABAg"]
[Tue Jul 21 07:36:24.685519 2026] [security2:error] [pid 255769:tid 256002] [client 213.152.162.104:45470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRZQAABAg"]
[Tue Jul 21 07:36:24.707615 2026] [security2:error] [pid 255769:tid 255969] [client 82.102.28.107:40380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRZgAAA-k"]
[Tue Jul 21 07:36:24.707712 2026] [security2:error] [pid 255769:tid 255969] [client 82.102.28.107:40380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9LqLxMYwyVGnfuwsKRZgAAA-k"]
[Tue Jul 21 07:36:24.718879 2026] [security2:error] [pid 254995:tid 255127] [client 20.104.96.117:59198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9LqP7v0rlcEGmVraE2UQAAAyA"]
[Tue Jul 21 07:36:25.062667 2026] [security2:error] [pid 254995:tid 255197] [client 59.96.220.140:56174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Lqf7v0rlcEGmVraE2VwAAA2Y"]
[Tue Jul 21 07:36:25.063361 2026] [security2:error] [pid 254995:tid 255197] [client 59.96.220.140:56174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Lqf7v0rlcEGmVraE2VwAAA2Y"]
[Tue Jul 21 07:36:25.133313 2026] [security2:error] [pid 255769:tid 255976] [client 20.197.195.24:49213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/eee.php"] [unique_id "al9LqbxMYwyVGnfuwsKRawAAA_A"]
[Tue Jul 21 07:36:25.287215 2026] [security2:error] [pid 255769:tid 255955] [client 20.220.225.223:24201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/cron.php"] [unique_id "al9LqbxMYwyVGnfuwsKRbwAAA9s"]
[Tue Jul 21 07:36:25.467641 2026] [security2:error] [pid 255769:tid 255985] [client 45.8.17.123:29907] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/alfa.php"] [unique_id "al9LqbxMYwyVGnfuwsKRcAAAA_k"]
[Tue Jul 21 07:36:25.599244 2026] [security2:error] [pid 255769:tid 255996] [client 20.206.105.145:37921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/green3.php"] [unique_id "al9LqbxMYwyVGnfuwsKRdQAABAI"]
[Tue Jul 21 07:36:25.657147 2026] [security2:error] [pid 255769:tid 255967] [client 20.197.195.24:50327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/wp-aothait.php"] [unique_id "al9LqbxMYwyVGnfuwsKRdgAAA-c"]
[Tue Jul 21 07:36:26.208080 2026] [core:alert] [pid 255769:tid 255922] [client 57.141.18.102:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:36:26.301722 2026] [security2:error] [pid 254995:tid 255152] [client 20.104.96.117:59169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/xyn.php"] [unique_id "al9Lqv7v0rlcEGmVraE2ygAAAzk"]
[Tue Jul 21 07:36:26.494021 2026] [security2:error] [pid 254995:tid 255150] [client 20.197.195.24:50334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/config.json.php"] [unique_id "al9Lqv7v0rlcEGmVraE2zQAAAzc"]
[Tue Jul 21 07:36:26.711281 2026] [security2:error] [pid 255769:tid 255992] [client 20.206.105.145:37917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ccs.php"] [unique_id "al9LqrxMYwyVGnfuwsKRiAAAA_8"]
[Tue Jul 21 07:36:26.774972 2026] [security2:error] [pid 255769:tid 255984] [client 45.8.17.124:41265] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "al9LqrxMYwyVGnfuwsKRiQAAA_g"]
[Tue Jul 21 07:36:26.834236 2026] [security2:error] [pid 255769:tid 256024] [client 20.104.96.117:59665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/patie.php"] [unique_id "al9LqrxMYwyVGnfuwsKRjAAABB4"]
[Tue Jul 21 07:36:26.856461 2026] [security2:error] [pid 254995:tid 255153] [client 20.220.225.223:24297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/xxx.php"] [unique_id "al9Lqv7v0rlcEGmVraE20gAAAzo"]
[Tue Jul 21 07:36:27.041004 2026] [security2:error] [pid 254995:tid 255178] [client 139.167.225.182:59742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lq_7v0rlcEGmVraE2_wAAA1M"]
[Tue Jul 21 07:36:27.041141 2026] [security2:error] [pid 254995:tid 255178] [client 139.167.225.182:59742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lq_7v0rlcEGmVraE2_wAAA1M"]
[Tue Jul 21 07:36:27.244696 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.195.24:62694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRnQAAA7Y"]
[Tue Jul 21 07:36:27.344988 2026] [security2:error] [pid 255769:tid 255999] [client 20.104.96.117:59145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/aa.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRoAAABAU"]
[Tue Jul 21 07:36:27.387012 2026] [security2:error] [pid 255769:tid 255948] [client 20.220.225.223:38681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/min.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRoQAAA9Q"]
[Tue Jul 21 07:36:27.595784 2026] [security2:error] [pid 254995:tid 255265] [client 152.59.154.239:55265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lq_7v0rlcEGmVraE3BgAAA48"]
[Tue Jul 21 07:36:27.595931 2026] [security2:error] [pid 254995:tid 255265] [client 152.59.154.239:55265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lq_7v0rlcEGmVraE3BgAAA48"]
[Tue Jul 21 07:36:27.596058 2026] [security2:error] [pid 255769:tid 255974] [client 37.140.223.134:42359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRogAAA-4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:27.596710 2026] [security2:error] [pid 254995:tid 255145] [client 45.251.232.145:62147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lq_7v0rlcEGmVraE3BwAAAzI"]
[Tue Jul 21 07:36:27.596802 2026] [security2:error] [pid 254995:tid 255145] [client 45.251.232.145:62147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lq_7v0rlcEGmVraE3BwAAAzI"]
[Tue Jul 21 07:36:27.698382 2026] [security2:error] [pid 255769:tid 255970] [client 20.104.96.117:59703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/xwpg.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRpAAAA-o"]
[Tue Jul 21 07:36:27.773511 2026] [security2:error] [pid 255769:tid 255951] [client 20.206.105.145:37900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ccc.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRpQAAA9c"]
[Tue Jul 21 07:36:27.775657 2026] [security2:error] [pid 255769:tid 255935] [client 45.8.17.118:37715] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/templates/atomic/templates.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRpgAAA8c"]
[Tue Jul 21 07:36:27.966073 2026] [security2:error] [pid 255769:tid 255903] [client 216.73.160.185:55701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9Lq7xMYwyVGnfuwsKRpwAAA6c"]
[Tue Jul 21 07:36:28.181120 2026] [security2:error] [pid 255769:tid 255926] [client 20.104.96.117:59707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ops.php"] [unique_id "al9LrLxMYwyVGnfuwsKRrgAAA74"]
[Tue Jul 21 07:36:28.187965 2026] [security2:error] [pid 255769:tid 256003] [client 20.197.195.24:62712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/k2.php"] [unique_id "al9LrLxMYwyVGnfuwsKRrwAABAk"]
[Tue Jul 21 07:36:28.205989 2026] [security2:error] [pid 254995:tid 255264] [client 193.36.225.63:31033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LrP7v0rlcEGmVraE3DgAAA44"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:28.233122 2026] [security2:error] [pid 255769:tid 255961] [client 20.206.105.145:38974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xxx.php"] [unique_id "al9LrLxMYwyVGnfuwsKRsAAAA-E"]
[Tue Jul 21 07:36:28.298177 2026] [security2:error] [pid 255769:tid 255947] [client 20.206.105.145:37924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/get.php"] [unique_id "al9LrLxMYwyVGnfuwsKRsgAAA9M"]
[Tue Jul 21 07:36:28.359509 2026] [security2:error] [pid 255769:tid 255919] [client 20.197.195.24:49208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9LrLxMYwyVGnfuwsKRtQAAA7c"]
[Tue Jul 21 07:36:28.514958 2026] [security2:error] [pid 254995:tid 255211] [client 117.251.86.144:34930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LrP7v0rlcEGmVraE3FwAAA3M"]
[Tue Jul 21 07:36:28.515071 2026] [security2:error] [pid 254995:tid 255211] [client 117.251.86.144:34930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LrP7v0rlcEGmVraE3FwAAA3M"]
[Tue Jul 21 07:36:28.590692 2026] [security2:error] [pid 254995:tid 255136] [client 103.162.129.114:52851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LrP7v0rlcEGmVraE3HAAAAyk"]
[Tue Jul 21 07:36:28.590828 2026] [security2:error] [pid 254995:tid 255136] [client 103.162.129.114:52851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LrP7v0rlcEGmVraE3HAAAAyk"]
[Tue Jul 21 07:36:28.602072 2026] [security2:error] [pid 255769:tid 255994] [client 173.24.185.52:53807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LrLxMYwyVGnfuwsKRugAABAE"]
[Tue Jul 21 07:36:28.602175 2026] [security2:error] [pid 255769:tid 255994] [client 173.24.185.52:53807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LrLxMYwyVGnfuwsKRugAABAE"]
[Tue Jul 21 07:36:28.827111 2026] [security2:error] [pid 254995:tid 255260] [client 20.104.96.117:59688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/mac.php"] [unique_id "al9LrP7v0rlcEGmVraE3HgAAA4o"]
[Tue Jul 21 07:36:28.910776 2026] [security2:error] [pid 255769:tid 255863] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LrLxMYwyVGnfuwsKRvQAD5F0"]
[Tue Jul 21 07:36:28.910915 2026] [security2:error] [pid 255769:tid 255964] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LrLxMYwyVGnfuwsKRvQAD5F0"]
[Tue Jul 21 07:36:29.059964 2026] [security2:error] [pid 255769:tid 255943] [client 109.248.148.246:37606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9LrbxMYwyVGnfuwsKRvgAAA88"]
[Tue Jul 21 07:36:29.060073 2026] [security2:error] [pid 255769:tid 255943] [client 109.248.148.246:37606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9LrbxMYwyVGnfuwsKRvgAAA88"]
[Tue Jul 21 07:36:29.065122 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.195.24:62605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9LrbxMYwyVGnfuwsKRvwAABAU"]
[Tue Jul 21 07:36:29.190673 2026] [security2:error] [pid 254995:tid 255189] [client 117.217.38.194:65289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lrf7v0rlcEGmVraE3JAAAA14"]
[Tue Jul 21 07:36:29.191143 2026] [security2:error] [pid 254995:tid 255189] [client 117.217.38.194:65289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lrf7v0rlcEGmVraE3JAAAA14"]
[Tue Jul 21 07:36:29.228280 2026] [security2:error] [pid 255769:tid 255971] [client 122.186.204.214:54374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LrbxMYwyVGnfuwsKRxAAAA-s"]
[Tue Jul 21 07:36:29.228410 2026] [security2:error] [pid 255769:tid 255971] [client 122.186.204.214:54374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LrbxMYwyVGnfuwsKRxAAAA-s"]
[Tue Jul 21 07:36:29.509327 2026] [security2:error] [pid 255769:tid 255958] [client 20.206.105.145:38494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/images.php"] [unique_id "al9LrbxMYwyVGnfuwsKRzAAAA94"]
[Tue Jul 21 07:36:29.542427 2026] [security2:error] [pid 254995:tid 255171] [client 62.102.148.164:42992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Lrf7v0rlcEGmVraE3KAAAA0w"]
[Tue Jul 21 07:36:29.542501 2026] [security2:error] [pid 254995:tid 255171] [client 62.102.148.164:42992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Lrf7v0rlcEGmVraE3KAAAA0w"]
[Tue Jul 21 07:36:29.572303 2026] [security2:error] [pid 254995:tid 255165] [client 45.8.17.132:40047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-links.php"] [unique_id "al9Lrf7v0rlcEGmVraE3KQAAA0Y"]
[Tue Jul 21 07:36:29.590483 2026] [security2:error] [pid 255769:tid 255946] [client 69.171.230.15:41182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9LrbxMYwyVGnfuwsKRyAAAA9I"]
[Tue Jul 21 07:36:29.635550 2026] [security2:error] [pid 254995:tid 255218] [client 20.104.96.117:59678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/mg.php"] [unique_id "al9Lrf7v0rlcEGmVraE3LQAAA3o"]
[Tue Jul 21 07:36:29.923262 2026] [security2:error] [pid 254995:tid 255192] [client 20.197.195.24:62597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9Lrf7v0rlcEGmVraE3MAAAA2E"]
[Tue Jul 21 07:36:30.031173 2026] [security2:error] [pid 255769:tid 255973] [client 20.104.96.117:59681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-post-data.php"] [unique_id "al9LrrxMYwyVGnfuwsKRzgAAA-0"]
[Tue Jul 21 07:36:30.118282 2026] [security2:error] [pid 254995:tid 255041] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lrv7v0rlcEGmVraE3NAADiS0"]
[Tue Jul 21 07:36:30.118468 2026] [security2:error] [pid 254995:tid 255259] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lrv7v0rlcEGmVraE3NAADiS0"]
[Tue Jul 21 07:36:30.274753 2026] [security2:error] [pid 254995:tid 255178] [client 20.197.195.24:50366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/for.php"] [unique_id "al9Lrv7v0rlcEGmVraE3OQAAA1M"]
[Tue Jul 21 07:36:30.349984 2026] [security2:error] [pid 254995:tid 255269] [client 69.171.230.10:54460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Lrv7v0rlcEGmVraE3OgAAA5M"]
[Tue Jul 21 07:36:30.703657 2026] [security2:error] [pid 254995:tid 255143] [client 175.45.70.82:59761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lrv7v0rlcEGmVraE3QAAAAzA"]
[Tue Jul 21 07:36:30.703765 2026] [security2:error] [pid 254995:tid 255143] [client 175.45.70.82:59761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lrv7v0rlcEGmVraE3QAAAAzA"]
[Tue Jul 21 07:36:30.741946 2026] [security2:error] [pid 255769:tid 255915] [client 20.104.96.117:59183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/pucci.php"] [unique_id "al9LrrxMYwyVGnfuwsKR2wAAA7M"]
[Tue Jul 21 07:36:30.959464 2026] [security2:error] [pid 255769:tid 255984] [client 122.162.144.145:27302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LrrxMYwyVGnfuwsKR4gAAA_g"]
[Tue Jul 21 07:36:30.959601 2026] [security2:error] [pid 255769:tid 255984] [client 122.162.144.145:27302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LrrxMYwyVGnfuwsKR4gAAA_g"]
[Tue Jul 21 07:36:31.070379 2026] [ssl:error] [pid 255769:tid 255945] [client 185.226.197.34:21926] AH02032: Hostname www.gradiente.com.br provided via SNI and hostname gradiente.com provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.gradiente.com.br/
[Tue Jul 21 07:36:31.165622 2026] [security2:error] [pid 255769:tid 255998] [client 20.206.105.145:38481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/alls.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR5wAABAQ"]
[Tue Jul 21 07:36:31.173720 2026] [security2:error] [pid 255769:tid 255954] [client 69.171.230.27:41044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR6QAAA9o"]
[Tue Jul 21 07:36:31.270852 2026] [security2:error] [pid 255769:tid 256028] [client 20.104.96.117:59143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/black.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR6wAABCI"]
[Tue Jul 21 07:36:31.340130 2026] [security2:error] [pid 255769:tid 255971] [client 20.197.195.24:62644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.cmpartners.com.br"] [uri "/raw.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR7AAAA-s"]
[Tue Jul 21 07:36:31.474893 2026] [security2:error] [pid 255769:tid 255924] [client 45.8.17.115:24151] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR8AAAA7w"]
[Tue Jul 21 07:36:31.668407 2026] [security2:error] [pid 255769:tid 255929] [client 103.106.20.201:64602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR9AAAA8E"]
[Tue Jul 21 07:36:31.668540 2026] [security2:error] [pid 255769:tid 255929] [client 103.106.20.201:64602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR9AAAA8E"]
[Tue Jul 21 07:36:31.747803 2026] [security2:error] [pid 255769:tid 255939] [client 185.198.240.12:21195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dener.design"] [uri "/wp-login.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR9gAAA8s"]
[Tue Jul 21 07:36:31.895880 2026] [security2:error] [pid 255769:tid 255903] [client 20.104.96.117:59175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/zlece.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR-AAAA6c"]
[Tue Jul 21 07:36:31.928049 2026] [security2:error] [pid 255769:tid 255969] [client 20.206.105.145:38484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/yyu.php"] [unique_id "al9Lr7xMYwyVGnfuwsKR-gAAA-k"]
[Tue Jul 21 07:36:32.131259 2026] [security2:error] [pid 255769:tid 256025] [client 136.144.33.97:43775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LsLxMYwyVGnfuwsKR_AAABB8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:32.132377 2026] [security2:error] [pid 254995:tid 255199] [client 20.206.105.145:39016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/hypo.php"] [unique_id "al9LsP7v0rlcEGmVraE3TQAAA2g"]
[Tue Jul 21 07:36:32.433323 2026] [security2:error] [pid 254995:tid 255205] [client 20.104.96.117:59137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/vssrs.php"] [unique_id "al9LsP7v0rlcEGmVraE3UwAAA24"]
[Tue Jul 21 07:36:32.446952 2026] [security2:error] [pid 254995:tid 255266] [client 20.220.225.223:51495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/bscclapb.php"] [unique_id "al9LsP7v0rlcEGmVraE3VAAAA5A"]
[Tue Jul 21 07:36:32.471728 2026] [security2:error] [pid 254995:tid 255197] [client 45.8.17.115:52241] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "al9LsP7v0rlcEGmVraE3VgAAA2Y"]
[Tue Jul 21 07:36:32.568041 2026] [security2:error] [pid 255769:tid 255869] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LsLxMYwyVGnfuwsKSAgADtGM"]
[Tue Jul 21 07:36:32.568190 2026] [security2:error] [pid 255769:tid 255916] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LsLxMYwyVGnfuwsKSAgADtGM"]
[Tue Jul 21 07:36:32.781014 2026] [security2:error] [pid 255769:tid 256021] [client 20.206.105.145:37923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/by.php"] [unique_id "al9LsLxMYwyVGnfuwsKSBAAABBs"]
[Tue Jul 21 07:36:32.802234 2026] [security2:error] [pid 255769:tid 255968] [client 20.104.96.117:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wicked.php"] [unique_id "al9LsLxMYwyVGnfuwsKSBQAAA-g"]
[Tue Jul 21 07:36:33.138357 2026] [security2:error] [pid 255769:tid 255900] [client 20.104.96.117:59163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/24.php"] [unique_id "al9LsbxMYwyVGnfuwsKSCgAAA6Q"]
[Tue Jul 21 07:36:33.582215 2026] [security2:error] [pid 254995:tid 255158] [client 45.8.17.64:57235] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/new.php"] [unique_id "al9Lsf7v0rlcEGmVraE3ZgAAAz8"]
[Tue Jul 21 07:36:33.693716 2026] [rewrite:error] [pid 255769:tid 255924] [client 187.49.76.218:21057] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:33.694654 2026] [rewrite:error] [pid 255769:tid 255974] [client 187.49.76.218:21185] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:33.713295 2026] [rewrite:error] [pid 254995:tid 255206] [client 187.49.76.218:21313] AH10411: Rewritten query string contains control characters or spaces, referer: http://mdmetal.net.br/ordem-producao/listar
[Tue Jul 21 07:36:33.733531 2026] [security2:error] [pid 255769:tid 255908] [client 20.104.96.117:59711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/xacs.php"] [unique_id "al9LsbxMYwyVGnfuwsKSDwAAA6w"]
[Tue Jul 21 07:36:33.817731 2026] [security2:error] [pid 255769:tid 255982] [client 103.174.34.15:56167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LsbxMYwyVGnfuwsKSEAAAA_Y"]
[Tue Jul 21 07:36:33.817857 2026] [security2:error] [pid 255769:tid 255982] [client 103.174.34.15:56167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LsbxMYwyVGnfuwsKSEAAAA_Y"]
[Tue Jul 21 07:36:33.989255 2026] [security2:error] [pid 254995:tid 255056] [remote 173.252.87.15:52220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Lsf7v0rlcEGmVraE3agADRzw"]
[Tue Jul 21 07:36:34.338002 2026] [security2:error] [pid 255769:tid 255988] [client 82.102.28.107:50256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LsrxMYwyVGnfuwsKSFgAAA_w"]
[Tue Jul 21 07:36:34.338119 2026] [security2:error] [pid 255769:tid 255988] [client 82.102.28.107:50256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9LsrxMYwyVGnfuwsKSFgAAA_w"]
[Tue Jul 21 07:36:34.396381 2026] [security2:error] [pid 254995:tid 255198] [client 20.220.225.223:31176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/echkm.php"] [unique_id "al9Lsv7v0rlcEGmVraE3cgAAA2c"]
[Tue Jul 21 07:36:34.413045 2026] [security2:error] [pid 255769:tid 256002] [client 20.104.96.117:59151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/zildan.php"] [unique_id "al9LsrxMYwyVGnfuwsKSGwAABAg"]
[Tue Jul 21 07:36:34.637471 2026] [security2:error] [pid 255769:tid 255885] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LsrxMYwyVGnfuwsKSHgAD6nM"]
[Tue Jul 21 07:36:34.637602 2026] [security2:error] [pid 255769:tid 255970] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LsrxMYwyVGnfuwsKSHgAD6nM"]
[Tue Jul 21 07:36:34.668735 2026] [security2:error] [pid 254995:tid 255008] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lsv7v0rlcEGmVraE3dgADOAw"]
[Tue Jul 21 07:36:34.668866 2026] [security2:error] [pid 254995:tid 255151] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lsv7v0rlcEGmVraE3dgADOAw"]
[Tue Jul 21 07:36:34.791242 2026] [security2:error] [pid 254995:tid 255071] [remote 18.61.192.253:54146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lsf7v0rlcEGmVraE3aAADJEs"]
[Tue Jul 21 07:36:34.791422 2026] [security2:error] [pid 254995:tid 255131] [client 18.61.192.253:54146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lsf7v0rlcEGmVraE3aAADJEs"]
[Tue Jul 21 07:36:34.950932 2026] [security2:error] [pid 255769:tid 256025] [client 20.104.96.117:61123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/csa.php"] [unique_id "al9LsrxMYwyVGnfuwsKSIQAABB8"]
[Tue Jul 21 07:36:34.975136 2026] [security2:error] [pid 255769:tid 255905] [client 45.8.17.121:34761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "al9LsrxMYwyVGnfuwsKSIgAAA6k"]
[Tue Jul 21 07:36:35.222959 2026] [security2:error] [pid 255769:tid 255870] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ls7xMYwyVGnfuwsKSJwADwmQ"]
[Tue Jul 21 07:36:35.223181 2026] [security2:error] [pid 255769:tid 255930] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ls7xMYwyVGnfuwsKSJwADwmQ"]
[Tue Jul 21 07:36:35.258164 2026] [security2:error] [pid 255769:tid 255791] [remote 216.73.216.238:65438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/chales.php"] [unique_id "al9Ls7xMYwyVGnfuwsKSKQADsxU"]
[Tue Jul 21 07:36:35.362977 2026] [security2:error] [pid 254995:tid 255178] [client 20.104.96.117:59675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/w3llscc.php"] [unique_id "al9Ls_7v0rlcEGmVraE3fgAAA1M"]
[Tue Jul 21 07:36:35.759521 2026] [security2:error] [pid 255769:tid 255959] [client 59.96.220.140:56441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Ls7xMYwyVGnfuwsKSNAAAA98"]
[Tue Jul 21 07:36:35.760037 2026] [security2:error] [pid 255769:tid 255959] [client 59.96.220.140:56441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Ls7xMYwyVGnfuwsKSNAAAA98"]
[Tue Jul 21 07:36:36.049991 2026] [proxy:error] [pid 254995:tid 255258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:36.050078 2026] [proxy_http:error] [pid 254995:tid 255258] [client 20.206.105.145:39250] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:36.050517 2026] [proxy:error] [pid 254995:tid 255258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:36.050544 2026] [proxy_http:error] [pid 254995:tid 255258] [client 20.206.105.145:39250] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:36.334275 2026] [security2:error] [pid 255769:tid 255972] [client 74.7.175.154:54930] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "getecma.com"] [uri "/cgi-sys/404.html"] [unique_id "al9LtLxMYwyVGnfuwsKSOgAD7BQ"]
[Tue Jul 21 07:36:36.337759 2026] [security2:error] [pid 255769:tid 256026] [client 20.104.96.117:59197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wpx.php"] [unique_id "al9LtLxMYwyVGnfuwsKSOwAABCA"]
[Tue Jul 21 07:36:36.819850 2026] [security2:error] [pid 255769:tid 255927] [client 193.36.225.57:38253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LtLxMYwyVGnfuwsKSPQAAA78"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:36.972001 2026] [security2:error] [pid 255769:tid 256024] [client 45.8.17.126:46809] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-links-opml.php"] [unique_id "al9LtLxMYwyVGnfuwsKSQAAABB4"]
[Tue Jul 21 07:36:37.101423 2026] [security2:error] [pid 255769:tid 256025] [client 20.104.96.117:61150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-css.php"] [unique_id "al9LtbxMYwyVGnfuwsKSQgAABB8"]
[Tue Jul 21 07:36:37.143797 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:37.143883 2026] [proxy_http:error] [pid 254995:tid 255147] [client 185.93.89.147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:37.144449 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:37.144474 2026] [proxy_http:error] [pid 254995:tid 255147] [client 185.93.89.147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:37.516076 2026] [security2:error] [pid 254995:tid 255196] [client 103.86.117.203:51441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ltf7v0rlcEGmVraE3mQAAA2U"]
[Tue Jul 21 07:36:37.516276 2026] [security2:error] [pid 254995:tid 255196] [client 103.86.117.203:51441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ltf7v0rlcEGmVraE3mQAAA2U"]
[Tue Jul 21 07:36:37.533127 2026] [security2:error] [pid 254995:tid 255214] [client 20.206.105.145:37898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/FAQ.php"] [unique_id "al9Ltf7v0rlcEGmVraE3ngAAA3Y"]
[Tue Jul 21 07:36:37.678158 2026] [security2:error] [pid 255769:tid 255967] [client 20.220.225.223:48138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/else1.php"] [unique_id "al9LtbxMYwyVGnfuwsKSRgAAA-c"]
[Tue Jul 21 07:36:37.691113 2026] [core:error] [pid 255769:tid 255798] [remote 52.167.144.232:10688] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:37.691133 2026] [core:error] [pid 255769:tid 255798] [remote 52.167.144.232:10688] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:37.765229 2026] [autoindex:error] [pid 254995:tid 255058] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:37.824585 2026] [security2:error] [pid 255769:tid 255900] [client 20.206.105.145:37897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/coffexium.php"] [unique_id "al9LtbxMYwyVGnfuwsKSSgAAA6Q"]
[Tue Jul 21 07:36:37.860594 2026] [security2:error] [pid 255769:tid 255944] [client 20.104.96.117:59648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ho.php"] [unique_id "al9LtbxMYwyVGnfuwsKSSwAAA9A"]
[Tue Jul 21 07:36:37.875697 2026] [security2:error] [pid 254995:tid 255132] [client 20.206.105.145:37895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/red.php"] [unique_id "al9Ltf7v0rlcEGmVraE3pwAAAyU"]
[Tue Jul 21 07:36:37.972375 2026] [autoindex:error] [pid 254995:tid 255169] [client 20.206.105.145:37896] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:37.981288 2026] [security2:error] [pid 254995:tid 255172] [client 20.206.105.145:37896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9Ltf7v0rlcEGmVraE3qgAAA00"]
[Tue Jul 21 07:36:37.982944 2026] [security2:error] [pid 255769:tid 255932] [client 139.167.225.182:60393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LtbxMYwyVGnfuwsKSTgAAA8Q"]
[Tue Jul 21 07:36:37.984696 2026] [security2:error] [pid 255769:tid 255932] [client 139.167.225.182:60393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LtbxMYwyVGnfuwsKSTgAAA8Q"]
[Tue Jul 21 07:36:38.162836 2026] [security2:error] [pid 255769:tid 255984] [client 45.251.232.145:62675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LtrxMYwyVGnfuwsKSUgAAA_g"]
[Tue Jul 21 07:36:38.162985 2026] [security2:error] [pid 255769:tid 255984] [client 45.251.232.145:62675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LtrxMYwyVGnfuwsKSUgAAA_g"]
[Tue Jul 21 07:36:38.165122 2026] [autoindex:error] [pid 254995:tid 255100] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:38.250149 2026] [security2:error] [pid 254995:tid 255181] [client 20.206.105.145:39246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/chosen.php"] [unique_id "al9Ltv7v0rlcEGmVraE3tAAAA1Y"]
[Tue Jul 21 07:36:38.252763 2026] [core:error] [pid 255769:tid 255831] [remote 52.167.144.232:10688] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:38.252780 2026] [core:error] [pid 255769:tid 255831] [remote 52.167.144.232:10688] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:38.277229 2026] [security2:error] [pid 255769:tid 255908] [client 45.8.17.138:63609] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/revslider/includes/external/page/index.php"] [unique_id "al9LtrxMYwyVGnfuwsKSVAAAA6w"]
[Tue Jul 21 07:36:38.358153 2026] [security2:error] [pid 254995:tid 255151] [client 20.104.96.117:59691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/xy.php"] [unique_id "al9Ltv7v0rlcEGmVraE3tgAAAzg"]
[Tue Jul 21 07:36:38.383454 2026] [autoindex:error] [pid 255769:tid 255919] [client 20.206.105.145:37903] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:38.574643 2026] [security2:error] [pid 255769:tid 256013] [client 20.206.105.145:37903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/footer.php"] [unique_id "al9LtrxMYwyVGnfuwsKSWQAABBM"]
[Tue Jul 21 07:36:38.692819 2026] [security2:error] [pid 254995:tid 255182] [client 20.220.225.223:38702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/mac.php"] [unique_id "al9Ltv7v0rlcEGmVraE3uwAAA1c"]
[Tue Jul 21 07:36:38.764572 2026] [security2:error] [pid 255769:tid 255851] [remote 195.26.244.42:57354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9LtrxMYwyVGnfuwsKSXgAD2VE"]
[Tue Jul 21 07:36:38.776554 2026] [security2:error] [pid 255769:tid 256026] [client 20.52.136.55:1738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/buy.php"] [unique_id "al9LtrxMYwyVGnfuwsKSXwAABCA"]
[Tue Jul 21 07:36:39.018162 2026] [autoindex:error] [pid 254995:tid 255084] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:39.155128 2026] [security2:error] [pid 254995:tid 255131] [client 117.251.86.144:43814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE3xQAAAyQ"]
[Tue Jul 21 07:36:39.155293 2026] [security2:error] [pid 254995:tid 255131] [client 117.251.86.144:43814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE3xQAAAyQ"]
[Tue Jul 21 07:36:39.265585 2026] [security2:error] [pid 254995:tid 255134] [client 20.104.96.117:59167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/loader.php"] [unique_id "al9Lt_7v0rlcEGmVraE3ygAAAyc"]
[Tue Jul 21 07:36:39.305254 2026] [security2:error] [pid 255769:tid 255969] [client 103.162.129.114:53296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt7xMYwyVGnfuwsKSYQAAA-k"]
[Tue Jul 21 07:36:39.305381 2026] [security2:error] [pid 255769:tid 255969] [client 103.162.129.114:53296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt7xMYwyVGnfuwsKSYQAAA-k"]
[Tue Jul 21 07:36:39.311656 2026] [security2:error] [pid 254995:tid 255150] [client 152.59.154.239:55756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE3zQAAAzc"]
[Tue Jul 21 07:36:39.311763 2026] [security2:error] [pid 254995:tid 255150] [client 152.59.154.239:55756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE3zQAAAzc"]
[Tue Jul 21 07:36:39.333463 2026] [autoindex:error] [pid 254995:tid 255004] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:39.386723 2026] [security2:error] [pid 254995:tid 255137] [client 45.8.17.64:33633] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/222.php"] [unique_id "al9Lt_7v0rlcEGmVraE30AAAAyo"]
[Tue Jul 21 07:36:39.493516 2026] [autoindex:error] [pid 255769:tid 255961] [client 20.206.105.145:38471] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:39.508236 2026] [security2:error] [pid 255769:tid 255966] [client 20.206.105.145:38471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-content/index.php"] [unique_id "al9Lt7xMYwyVGnfuwsKSYwAAA-Y"]
[Tue Jul 21 07:36:39.521867 2026] [security2:error] [pid 255769:tid 255947] [client 20.220.225.223:24268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/hunter.php"] [unique_id "al9Lt7xMYwyVGnfuwsKSZAAAA9M"]
[Tue Jul 21 07:36:39.594258 2026] [security2:error] [pid 254995:tid 255209] [client 173.24.185.52:54286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE30QAAA3E"]
[Tue Jul 21 07:36:39.594356 2026] [security2:error] [pid 254995:tid 255209] [client 173.24.185.52:54286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE30QAAA3E"]
[Tue Jul 21 07:36:39.663600 2026] [security2:error] [pid 254995:tid 255046] [remote 209.97.182.179:43996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "monicamirandapereira1751478737000.bellarthconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "al9Lt_7v0rlcEGmVraE31AADkDI"]
[Tue Jul 21 07:36:39.702323 2026] [security2:error] [pid 254995:tid 255254] [client 117.217.38.194:49376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE31gAAA4Q"]
[Tue Jul 21 07:36:39.702498 2026] [security2:error] [pid 254995:tid 255254] [client 117.217.38.194:49376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE31gAAA4Q"]
[Tue Jul 21 07:36:39.710207 2026] [security2:error] [pid 255769:tid 255845] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt7xMYwyVGnfuwsKSaQAECUs"]
[Tue Jul 21 07:36:39.710407 2026] [security2:error] [pid 255769:tid 256003] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt7xMYwyVGnfuwsKSaQAECUs"]
[Tue Jul 21 07:36:39.792783 2026] [security2:error] [pid 254995:tid 255143] [client 122.186.204.214:54895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE32QAAAzA"]
[Tue Jul 21 07:36:39.792914 2026] [security2:error] [pid 254995:tid 255143] [client 122.186.204.214:54895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lt_7v0rlcEGmVraE32QAAAzA"]
[Tue Jul 21 07:36:39.821757 2026] [autoindex:error] [pid 254995:tid 255002] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:40.159883 2026] [security2:error] [pid 255769:tid 256000] [client 45.33.12.214:40856] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.68"] [uri "/index.cgi"] [unique_id "al9LuLxMYwyVGnfuwsKSdQAABAY"]
[Tue Jul 21 07:36:40.253191 2026] [autoindex:error] [pid 254995:tid 255007] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/rest-api/endpoints/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:40.481262 2026] [security2:error] [pid 255769:tid 255946] [client 45.8.17.107:47671] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/about/function.php"] [unique_id "al9LuLxMYwyVGnfuwsKSgQAAA9I"]
[Tue Jul 21 07:36:40.591718 2026] [security2:error] [pid 255769:tid 256026] [client 82.102.28.107:53162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LuLxMYwyVGnfuwsKSgwAABCA"]
[Tue Jul 21 07:36:40.591828 2026] [security2:error] [pid 255769:tid 256026] [client 82.102.28.107:53162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9LuLxMYwyVGnfuwsKSgwAABCA"]
[Tue Jul 21 07:36:40.671076 2026] [proxy:error] [pid 254995:tid 255189] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:40.671152 2026] [proxy_http:error] [pid 254995:tid 255189] [client 20.206.105.145:39240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:40.671715 2026] [proxy:error] [pid 254995:tid 255189] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:40.671745 2026] [proxy_http:error] [pid 254995:tid 255189] [client 20.206.105.145:39240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:40.691005 2026] [security2:error] [pid 255769:tid 255918] [client 20.206.105.145:38486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/zoro.php"] [unique_id "al9LuLxMYwyVGnfuwsKShQAAA7Y"]
[Tue Jul 21 07:36:40.726425 2026] [security2:error] [pid 255769:tid 255926] [client 20.104.96.117:59193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/spadex.php"] [unique_id "al9LuLxMYwyVGnfuwsKShgAAA74"]
[Tue Jul 21 07:36:40.921430 2026] [security2:error] [pid 255769:tid 255858] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LuLxMYwyVGnfuwsKSiwAEFVg"]
[Tue Jul 21 07:36:40.921618 2026] [security2:error] [pid 255769:tid 256015] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LuLxMYwyVGnfuwsKSiwAEFVg"]
[Tue Jul 21 07:36:41.092615 2026] [security2:error] [pid 254995:tid 255204] [client 82.102.28.107:53170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Luf7v0rlcEGmVraE37QAAA20"]
[Tue Jul 21 07:36:41.092714 2026] [security2:error] [pid 254995:tid 255204] [client 82.102.28.107:53170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Luf7v0rlcEGmVraE37QAAA20"]
[Tue Jul 21 07:36:41.138729 2026] [security2:error] [pid 254995:tid 255256] [client 136.144.33.99:60847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Luf7v0rlcEGmVraE37gAAA4Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:41.292845 2026] [security2:error] [pid 255769:tid 255907] [client 20.104.96.117:59161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/2x.php"] [unique_id "al9LubxMYwyVGnfuwsKSjgAAA6s"]
[Tue Jul 21 07:36:41.295849 2026] [security2:error] [pid 255769:tid 255911] [client 62.102.148.164:40504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LubxMYwyVGnfuwsKSjwAAA68"]
[Tue Jul 21 07:36:41.295948 2026] [security2:error] [pid 255769:tid 255911] [client 62.102.148.164:40504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9LubxMYwyVGnfuwsKSjwAAA68"]
[Tue Jul 21 07:36:41.357942 2026] [security2:error] [pid 255769:tid 255965] [client 109.248.148.246:53848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9LubxMYwyVGnfuwsKSkAAAA-U"]
[Tue Jul 21 07:36:41.358054 2026] [security2:error] [pid 255769:tid 255965] [client 109.248.148.246:53848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9LubxMYwyVGnfuwsKSkAAAA-U"]
[Tue Jul 21 07:36:41.373200 2026] [autoindex:error] [pid 254995:tid 255068] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:41.521740 2026] [security2:error] [pid 254995:tid 255122] [remote 141.98.11.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.11.98.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9Luf7v0rlcEGmVraE38wADVn4"], referer: https://www.binance.com
[Tue Jul 21 07:36:41.682665 2026] [security2:error] [pid 254995:tid 255149] [client 45.8.17.147:53455] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/maint/about.php"] [unique_id "al9Luf7v0rlcEGmVraE3-QAAAzY"]
[Tue Jul 21 07:36:41.705858 2026] [security2:error] [pid 254995:tid 255166] [client 175.45.70.82:60320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Luf7v0rlcEGmVraE3-wAAA0c"]
[Tue Jul 21 07:36:41.705978 2026] [security2:error] [pid 254995:tid 255166] [client 175.45.70.82:60320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Luf7v0rlcEGmVraE3-wAAA0c"]
[Tue Jul 21 07:36:41.743742 2026] [security2:error] [pid 255769:tid 256025] [client 122.162.144.145:28727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LubxMYwyVGnfuwsKSlQAABB8"]
[Tue Jul 21 07:36:41.743849 2026] [security2:error] [pid 255769:tid 256025] [client 122.162.144.145:28727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LubxMYwyVGnfuwsKSlQAABB8"]
[Tue Jul 21 07:36:41.896764 2026] [security2:error] [pid 254995:tid 255190] [client 20.220.225.223:38695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Luf7v0rlcEGmVraE4AwAAA18"]
[Tue Jul 21 07:36:41.910124 2026] [security2:error] [pid 254995:tid 255216] [client 213.152.162.104:49134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Luf7v0rlcEGmVraE4BQAAA3g"]
[Tue Jul 21 07:36:41.910211 2026] [security2:error] [pid 254995:tid 255216] [client 213.152.162.104:49134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Luf7v0rlcEGmVraE4BQAAA3g"]
[Tue Jul 21 07:36:42.098829 2026] [autoindex:error] [pid 254995:tid 255154] [client 104.236.113.248:60359] AH01276: Cannot serve directory /home2/tamoio74/engeconconstrucoes.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:42.156332 2026] [security2:error] [pid 255769:tid 256017] [client 20.104.96.117:59191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ctex1.php"] [unique_id "al9LurxMYwyVGnfuwsKSlwAABBc"]
[Tue Jul 21 07:36:42.174724 2026] [security2:error] [pid 254995:tid 255222] [client 136.144.33.25:33307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Luv7v0rlcEGmVraE4CwAAA34"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:42.212921 2026] [security2:error] [pid 255769:tid 255974] [client 20.206.105.145:37904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/admin.php"] [unique_id "al9LurxMYwyVGnfuwsKSmAAAA-4"]
[Tue Jul 21 07:36:42.271893 2026] [core:error] [pid 254995:tid 255091] [remote 52.167.144.191:38405] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:42.271917 2026] [core:error] [pid 254995:tid 255091] [remote 52.167.144.191:38405] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:42.325731 2026] [autoindex:error] [pid 254995:tid 255019] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/Diff/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:42.331666 2026] [autoindex:error] [pid 254995:tid 255180] [client 104.236.113.248:60359] AH01276: Cannot serve directory /home2/tamoio74/engeconconstrucoes.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:42.356231 2026] [security2:error] [pid 254995:tid 255202] [client 20.220.225.223:24225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/we.php"] [unique_id "al9Luv7v0rlcEGmVraE4FAAAA2s"]
[Tue Jul 21 07:36:42.381199 2026] [security2:error] [pid 254995:tid 255147] [client 20.206.105.145:39257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/als.php"] [unique_id "al9Luv7v0rlcEGmVraE4FgAAAzQ"]
[Tue Jul 21 07:36:42.411031 2026] [security2:error] [pid 254995:tid 255186] [client 103.106.20.201:65209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Luv7v0rlcEGmVraE4FwAAA1s"]
[Tue Jul 21 07:36:42.411189 2026] [security2:error] [pid 254995:tid 255186] [client 103.106.20.201:65209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Luv7v0rlcEGmVraE4FwAAA1s"]
[Tue Jul 21 07:36:42.445262 2026] [security2:error] [pid 254995:tid 255136] [client 104.236.113.248:60359] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Luv7v0rlcEGmVraE4HAAAAyk"]
[Tue Jul 21 07:36:42.475790 2026] [security2:error] [pid 254995:tid 255212] [client 213.152.162.104:49144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Luv7v0rlcEGmVraE4HQAAA3Q"]
[Tue Jul 21 07:36:42.475938 2026] [security2:error] [pid 254995:tid 255212] [client 213.152.162.104:49144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Luv7v0rlcEGmVraE4HQAAA3Q"]
[Tue Jul 21 07:36:42.697972 2026] [security2:error] [pid 254995:tid 255275] [client 104.236.113.248:61361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.113.236.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Luv7v0rlcEGmVraE4HwAAA5k"]
[Tue Jul 21 07:36:42.947855 2026] [autoindex:error] [pid 255769:tid 255981] [client 104.236.113.248:61953] AH01276: Cannot serve directory /home2/tamoio74/engeconconstrucoes.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:43.063820 2026] [security2:error] [pid 254995:tid 255035] [remote 68.178.160.25:55540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agrocibus.com.br"] [uri "/wp-login.php"] [unique_id "al9Lu_7v0rlcEGmVraE4JwADOSc"]
[Tue Jul 21 07:36:43.103299 2026] [security2:error] [pid 254995:tid 255003] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lu_7v0rlcEGmVraE4KAADewc"]
[Tue Jul 21 07:36:43.103412 2026] [security2:error] [pid 254995:tid 255219] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lu_7v0rlcEGmVraE4KAADewc"]
[Tue Jul 21 07:36:43.149586 2026] [security2:error] [pid 254995:tid 255187] [client 20.104.96.117:59168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/edorxrr.php"] [unique_id "al9Lu_7v0rlcEGmVraE4KQAAA1w"]
[Tue Jul 21 07:36:43.153668 2026] [security2:error] [pid 255769:tid 255909] [client 20.220.225.223:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/samll.php"] [unique_id "al9Lu7xMYwyVGnfuwsKSogAAA60"]
[Tue Jul 21 07:36:43.173612 2026] [security2:error] [pid 255769:tid 255988] [client 104.236.113.248:61953] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Lu7xMYwyVGnfuwsKSowAAA_w"]
[Tue Jul 21 07:36:43.225905 2026] [security2:error] [pid 254995:tid 255192] [client 20.226.60.151:27569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Lu_7v0rlcEGmVraE4KwAAA2E"]
[Tue Jul 21 07:36:43.281325 2026] [security2:error] [pid 255769:tid 255903] [client 45.8.17.61:42335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/upload/upload.php"] [unique_id "al9Lu7xMYwyVGnfuwsKSpAAAA6c"]
[Tue Jul 21 07:36:43.407997 2026] [security2:error] [pid 255769:tid 255972] [client 104.236.113.248:62819] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Lu7xMYwyVGnfuwsKSpwAAA-w"]
[Tue Jul 21 07:36:43.643421 2026] [security2:error] [pid 255769:tid 255980] [client 104.236.113.248:63300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Lu7xMYwyVGnfuwsKSqgAAA_Q"]
[Tue Jul 21 07:36:43.709970 2026] [security2:error] [pid 255769:tid 255966] [client 20.206.105.145:38502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/greap.php"] [unique_id "al9Lu7xMYwyVGnfuwsKSrAAAA-Y"]
[Tue Jul 21 07:36:43.723517 2026] [security2:error] [pid 255769:tid 255841] [remote 51.79.215.219:56910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.215.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthsmart.shop"] [uri "/wp-login.php"] [unique_id "al9Lu7xMYwyVGnfuwsKSrgAD80c"]
[Tue Jul 21 07:36:43.876675 2026] [security2:error] [pid 255769:tid 255978] [client 104.236.113.248:63819] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9Lu7xMYwyVGnfuwsKSsQAAA_I"]
[Tue Jul 21 07:36:43.952583 2026] [security2:error] [pid 255769:tid 256021] [client 20.206.105.145:38969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/pol.php"] [unique_id "al9Lu7xMYwyVGnfuwsKStAAABBs"]
[Tue Jul 21 07:36:44.030595 2026] [security2:error] [pid 254995:tid 255165] [client 122.164.127.47:52373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LvP7v0rlcEGmVraE4OAAAA0Y"]
[Tue Jul 21 07:36:44.030714 2026] [security2:error] [pid 254995:tid 255165] [client 122.164.127.47:52373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LvP7v0rlcEGmVraE4OAAAA0Y"]
[Tue Jul 21 07:36:44.113042 2026] [security2:error] [pid 254995:tid 255258] [client 104.236.113.248:64374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9LvP7v0rlcEGmVraE4PAAAA4g"]
[Tue Jul 21 07:36:44.127643 2026] [security2:error] [pid 254995:tid 255193] [client 47.128.40.173:39874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "applarifo.com.br"] [uri "/robots.txt"] [unique_id "al9LvP7v0rlcEGmVraE4PgAAA2I"]
[Tue Jul 21 07:36:44.188707 2026] [security2:error] [pid 254995:tid 255173] [client 45.8.17.140:49351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wpc.php"] [unique_id "al9LvP7v0rlcEGmVraE4PwAAA04"]
[Tue Jul 21 07:36:44.345388 2026] [security2:error] [pid 254995:tid 255263] [client 20.220.225.223:24228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/phpinfo.php1"] [unique_id "al9LvP7v0rlcEGmVraE4VwAAA40"]
[Tue Jul 21 07:36:44.346354 2026] [security2:error] [pid 254995:tid 255262] [client 104.236.113.248:64933] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9LvP7v0rlcEGmVraE4WAAAA4w"]
[Tue Jul 21 07:36:44.377054 2026] [security2:error] [pid 254995:tid 255146] [client 20.104.96.117:61130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/miru1.php"] [unique_id "al9LvP7v0rlcEGmVraE4WQAAAzM"]
[Tue Jul 21 07:36:44.424512 2026] [security2:error] [pid 254995:tid 255137] [client 20.220.225.223:38684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/abcd.php"] [unique_id "al9LvP7v0rlcEGmVraE4cAAAAyo"]
[Tue Jul 21 07:36:44.471333 2026] [security2:error] [pid 254995:tid 255224] [client 20.197.195.24:13295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9LvP7v0rlcEGmVraE4cQAAA4A"]
[Tue Jul 21 07:36:44.492550 2026] [security2:error] [pid 254995:tid 255190] [client 103.174.34.15:56649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LvP7v0rlcEGmVraE4cgAAA18"]
[Tue Jul 21 07:36:44.492974 2026] [security2:error] [pid 254995:tid 255190] [client 103.174.34.15:56649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LvP7v0rlcEGmVraE4cgAAA18"]
[Tue Jul 21 07:36:44.613075 2026] [security2:error] [pid 254995:tid 255141] [client 104.236.113.248:49259] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9LvP7v0rlcEGmVraE4dwAAAy4"]
[Tue Jul 21 07:36:44.710520 2026] [security2:error] [pid 255769:tid 255860] [remote 8.217.108.67:31338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9LvLxMYwyVGnfuwsKSwQADwFo"]
[Tue Jul 21 07:36:44.830065 2026] [security2:error] [pid 254995:tid 255260] [client 20.220.225.223:38671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/xyn.php"] [unique_id "al9LvP7v0rlcEGmVraE4fwAAA4o"]
[Tue Jul 21 07:36:44.845990 2026] [security2:error] [pid 255769:tid 255960] [client 104.236.113.248:49873] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9LvLxMYwyVGnfuwsKSxQAAA-A"]
[Tue Jul 21 07:36:44.949126 2026] [security2:error] [pid 255769:tid 256009] [client 20.206.105.145:38995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file5.php"] [unique_id "al9LvLxMYwyVGnfuwsKSxgAABA8"]
[Tue Jul 21 07:36:44.973805 2026] [security2:error] [pid 255769:tid 255944] [client 74.7.175.138:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.luminabeauty.com.br"] [uri "/index.php"] [unique_id "al9LurxMYwyVGnfuwsKSngAD0Cs"]
[Tue Jul 21 07:36:44.987585 2026] [security2:error] [pid 254995:tid 255127] [client 20.197.195.24:13209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9LvP7v0rlcEGmVraE4gAAAAyA"]
[Tue Jul 21 07:36:44.994589 2026] [security2:error] [pid 254995:tid 255142] [client 20.226.60.151:27561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9LvP7v0rlcEGmVraE4gQAAAy8"]
[Tue Jul 21 07:36:45.017086 2026] [security2:error] [pid 254995:tid 255197] [client 20.206.105.145:38917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Lvf7v0rlcEGmVraE4gwAAA2Y"]
[Tue Jul 21 07:36:45.056782 2026] [security2:error] [pid 254995:tid 255090] [remote 141.98.11.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.11.98.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9Lvf7v0rlcEGmVraE4hAADcl4"], referer: https://www.binance.com
[Tue Jul 21 07:36:45.080642 2026] [security2:error] [pid 254995:tid 255189] [client 104.236.113.248:50549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Lvf7v0rlcEGmVraE4hQAAA14"]
[Tue Jul 21 07:36:45.083892 2026] [security2:error] [pid 255769:tid 255903] [client 20.206.105.145:39263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file.php"] [unique_id "al9LvbxMYwyVGnfuwsKSyAAAA6c"]
[Tue Jul 21 07:36:45.177540 2026] [security2:error] [pid 255769:tid 255811] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LvbxMYwyVGnfuwsKSzgAD3ik"]
[Tue Jul 21 07:36:45.177689 2026] [security2:error] [pid 255769:tid 255958] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9LvbxMYwyVGnfuwsKSzgAD3ik"]
[Tue Jul 21 07:36:45.316363 2026] [security2:error] [pid 254995:tid 255169] [client 104.236.113.248:51156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Lvf7v0rlcEGmVraE4igAAA0o"]
[Tue Jul 21 07:36:45.317091 2026] [security2:error] [pid 255769:tid 256026] [client 20.206.105.145:39270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/cfile.php"] [unique_id "al9LvbxMYwyVGnfuwsKSzwAABCA"]
[Tue Jul 21 07:36:45.462915 2026] [security2:error] [pid 255769:tid 255976] [client 20.206.105.145:39162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/class-wp.php"] [unique_id "al9LvbxMYwyVGnfuwsKS0gAAA_A"]
[Tue Jul 21 07:36:45.493889 2026] [security2:error] [pid 254995:tid 255099] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lvf7v0rlcEGmVraE4jgADP2c"]
[Tue Jul 21 07:36:45.494069 2026] [security2:error] [pid 254995:tid 255158] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lvf7v0rlcEGmVraE4jgADP2c"]
[Tue Jul 21 07:36:45.548717 2026] [security2:error] [pid 254995:tid 255181] [client 104.236.113.248:51676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Lvf7v0rlcEGmVraE4kAAAA1Y"]
[Tue Jul 21 07:36:45.665191 2026] [security2:error] [pid 254995:tid 255276] [client 20.206.105.145:39011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/admin.php"] [unique_id "al9Lvf7v0rlcEGmVraE4lAAAA5o"]
[Tue Jul 21 07:36:45.675738 2026] [security2:error] [pid 254995:tid 255149] [client 45.8.17.58:22767] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "al9Lvf7v0rlcEGmVraE4lQAAAzY"]
[Tue Jul 21 07:36:45.687355 2026] [autoindex:error] [pid 254995:tid 255081] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:45.718233 2026] [security2:error] [pid 254995:tid 255267] [client 20.206.105.145:37912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/177.php"] [unique_id "al9Lvf7v0rlcEGmVraE4lwAAA5E"]
[Tue Jul 21 07:36:45.783332 2026] [security2:error] [pid 255769:tid 256003] [client 104.236.113.248:52200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9LvbxMYwyVGnfuwsKS1gAABAk"]
[Tue Jul 21 07:36:45.783719 2026] [security2:error] [pid 254995:tid 255269] [client 20.104.96.117:61129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/sump1.php"] [unique_id "al9Lvf7v0rlcEGmVraE4mQAAA5M"]
[Tue Jul 21 07:36:45.815277 2026] [security2:error] [pid 254995:tid 255279] [client 20.206.105.145:39292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/aa2.php"] [unique_id "al9Lvf7v0rlcEGmVraE4mgAAA50"]
[Tue Jul 21 07:36:45.827121 2026] [security2:error] [pid 255769:tid 255773] [remote 81.173.115.7:58786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "link.aede.com.br"] [uri "/wp-login.php"] [unique_id "al9LvbxMYwyVGnfuwsKS1wAD8wM"]
[Tue Jul 21 07:36:45.849783 2026] [autoindex:error] [pid 254995:tid 255046] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:45.852946 2026] [security2:error] [pid 254995:tid 255194] [client 20.197.195.24:13194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/media.php"] [unique_id "al9Lvf7v0rlcEGmVraE4nAAAA2M"]
[Tue Jul 21 07:36:45.939329 2026] [security2:error] [pid 254995:tid 255093] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lvf7v0rlcEGmVraE4nwADd2E"]
[Tue Jul 21 07:36:45.939420 2026] [security2:error] [pid 254995:tid 255215] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Lvf7v0rlcEGmVraE4nwADd2E"]
[Tue Jul 21 07:36:45.954564 2026] [security2:error] [pid 255769:tid 255920] [client 136.144.33.100:24443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9LvbxMYwyVGnfuwsKS2QAAA7g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:46.017807 2026] [security2:error] [pid 254995:tid 255145] [client 104.236.113.248:52629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9Lvv7v0rlcEGmVraE4owAAAzI"]
[Tue Jul 21 07:36:46.089551 2026] [security2:error] [pid 254995:tid 255178] [client 20.206.105.145:39109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ccou.php"] [unique_id "al9Lvv7v0rlcEGmVraE4pgAAA1M"]
[Tue Jul 21 07:36:46.140741 2026] [security2:error] [pid 255769:tid 255954] [client 20.226.60.151:27603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/media.php"] [unique_id "al9LvrxMYwyVGnfuwsKS3AAAA9o"]
[Tue Jul 21 07:36:46.252666 2026] [security2:error] [pid 255769:tid 255900] [client 104.236.113.248:53094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9LvrxMYwyVGnfuwsKS3gAAA6Q"]
[Tue Jul 21 07:36:46.431180 2026] [security2:error] [pid 255769:tid 256025] [client 20.206.105.145:37949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/199.php"] [unique_id "al9LvrxMYwyVGnfuwsKS4AAABB8"]
[Tue Jul 21 07:36:46.476697 2026] [security2:error] [pid 255769:tid 255977] [client 20.197.195.24:13297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/images.php"] [unique_id "al9LvrxMYwyVGnfuwsKS5AAAA_E"]
[Tue Jul 21 07:36:46.479698 2026] [security2:error] [pid 255769:tid 255934] [client 59.96.220.140:56948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LvrxMYwyVGnfuwsKS5QAAA8Y"]
[Tue Jul 21 07:36:46.480282 2026] [security2:error] [pid 255769:tid 255934] [client 59.96.220.140:56948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LvrxMYwyVGnfuwsKS5QAAA8Y"]
[Tue Jul 21 07:36:46.488906 2026] [security2:error] [pid 255769:tid 255932] [client 104.236.113.248:53656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9LvrxMYwyVGnfuwsKS5gAAA8Q"]
[Tue Jul 21 07:36:46.689359 2026] [security2:error] [pid 255769:tid 255908] [client 20.206.105.145:38960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/dr.php"] [unique_id "al9LvrxMYwyVGnfuwsKS6QAAA6w"]
[Tue Jul 21 07:36:46.721128 2026] [security2:error] [pid 255769:tid 255960] [client 104.236.113.248:54134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "engeconconstrucoes.com.br.tamoiomix.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9LvrxMYwyVGnfuwsKS7QAAA-A"]
[Tue Jul 21 07:36:46.866372 2026] [autoindex:error] [pid 254995:tid 255075] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:46.866692 2026] [autoindex:error] [pid 254995:tid 255010] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:46.899443 2026] [security2:error] [pid 254995:tid 255143] [client 20.104.96.117:59158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/file5.php"] [unique_id "al9Lvv7v0rlcEGmVraE4swAAAzA"]
[Tue Jul 21 07:36:47.207067 2026] [security2:error] [pid 255769:tid 255972] [client 20.206.105.145:38987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xamp.php"] [unique_id "al9Lv7xMYwyVGnfuwsKS9QAAA-w"]
[Tue Jul 21 07:36:47.211889 2026] [security2:error] [pid 254995:tid 255175] [client 20.220.225.223:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Lv_7v0rlcEGmVraE4uQAAA1A"]
[Tue Jul 21 07:36:47.279458 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.195.24:13258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/gecko.php"] [unique_id "al9Lv7xMYwyVGnfuwsKS9gAAA7Y"]
[Tue Jul 21 07:36:47.474014 2026] [security2:error] [pid 255769:tid 256024] [client 45.8.17.49:42479] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/as.php"] [unique_id "al9Lv7xMYwyVGnfuwsKS-gAABB4"]
[Tue Jul 21 07:36:47.498098 2026] [security2:error] [pid 254995:tid 255205] [client 103.86.117.203:52031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lv_7v0rlcEGmVraE4vAAAA24"]
[Tue Jul 21 07:36:47.498225 2026] [security2:error] [pid 254995:tid 255205] [client 103.86.117.203:52031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lv_7v0rlcEGmVraE4vAAAA24"]
[Tue Jul 21 07:36:47.642805 2026] [security2:error] [pid 255769:tid 255961] [client 20.104.96.117:59651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/0xD.php"] [unique_id "al9Lv7xMYwyVGnfuwsKS-wAAA-E"]
[Tue Jul 21 07:36:47.658335 2026] [security2:error] [pid 255769:tid 255973] [client 20.226.60.151:27542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/images.php"] [unique_id "al9Lv7xMYwyVGnfuwsKS_AAAA-0"]
[Tue Jul 21 07:36:47.681291 2026] [security2:error] [pid 255769:tid 255992] [client 20.206.105.145:38469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file52.php"] [unique_id "al9Lv7xMYwyVGnfuwsKS_gAAA_8"]
[Tue Jul 21 07:36:47.802000 2026] [autoindex:error] [pid 254995:tid 255028] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/rest-api/endpoints/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:47.808231 2026] [autoindex:error] [pid 254995:tid 255122] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:48.152469 2026] [autoindex:error] [pid 254995:tid 255182] [client 147.185.132.58:60746] AH01276: Cannot serve directory /home3/agroci73/agrocibus.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:48.175976 2026] [security2:error] [pid 255769:tid 255952] [client 20.104.96.117:59653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/fnstall.php"] [unique_id "al9LwLxMYwyVGnfuwsKTBwAAA9g"]
[Tue Jul 21 07:36:48.216016 2026] [security2:error] [pid 255769:tid 255944] [client 37.140.223.163:55933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Lv7xMYwyVGnfuwsKS8QAAA9A"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:48.242195 2026] [security2:error] [pid 254995:tid 255267] [client 20.197.195.24:13271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/82.php"] [unique_id "al9LwP7v0rlcEGmVraE4zgAAA5E"]
[Tue Jul 21 07:36:48.607462 2026] [autoindex:error] [pid 254995:tid 255019] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:48.610481 2026] [autoindex:error] [pid 254995:tid 255055] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:48.615484 2026] [security2:error] [pid 254995:tid 255134] [client 20.206.105.145:39161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/bless.php"] [unique_id "al9LwP7v0rlcEGmVraE41wAAAyc"]
[Tue Jul 21 07:36:48.644892 2026] [security2:error] [pid 255769:tid 255945] [client 45.251.232.145:63201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LwLxMYwyVGnfuwsKTDAAAA9E"]
[Tue Jul 21 07:36:48.645020 2026] [security2:error] [pid 255769:tid 255945] [client 45.251.232.145:63201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LwLxMYwyVGnfuwsKTDAAAA9E"]
[Tue Jul 21 07:36:48.753954 2026] [security2:error] [pid 255769:tid 255785] [remote 81.173.115.7:50276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autoq.com.br"] [uri "/wp-login.php"] [unique_id "al9LwLxMYwyVGnfuwsKTEAAD-Q8"]
[Tue Jul 21 07:36:48.873867 2026] [security2:error] [pid 254995:tid 255276] [client 139.167.225.182:61029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LwP7v0rlcEGmVraE42wAAA5o"]
[Tue Jul 21 07:36:48.873960 2026] [security2:error] [pid 254995:tid 255276] [client 139.167.225.182:61029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LwP7v0rlcEGmVraE42wAAA5o"]
[Tue Jul 21 07:36:48.886517 2026] [security2:error] [pid 255769:tid 255943] [client 20.206.105.145:38480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/122.php"] [unique_id "al9LwLxMYwyVGnfuwsKTEQAAA88"]
[Tue Jul 21 07:36:48.976718 2026] [security2:error] [pid 254995:tid 255138] [client 45.8.17.65:52017] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyfive/patterns/template-singl-portfolio.php"] [unique_id "al9LwP7v0rlcEGmVraE43AAAAys"]
[Tue Jul 21 07:36:48.991781 2026] [autoindex:error] [pid 254995:tid 255032] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/Diff/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:48.993945 2026] [autoindex:error] [pid 254995:tid 255030] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/Diff/Engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:49.029046 2026] [security2:error] [pid 255769:tid 256026] [client 20.197.195.24:13193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/admin.php"] [unique_id "al9LwbxMYwyVGnfuwsKTEwAABCA"]
[Tue Jul 21 07:36:49.063655 2026] [security2:error] [pid 255769:tid 255993] [client 20.226.60.151:27543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/gecko.php"] [unique_id "al9LwbxMYwyVGnfuwsKTFgAABAA"]
[Tue Jul 21 07:36:49.091110 2026] [security2:error] [pid 255769:tid 256024] [client 20.206.105.145:39269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file46.php"] [unique_id "al9LwbxMYwyVGnfuwsKTFwAABB4"]
[Tue Jul 21 07:36:49.323685 2026] [security2:error] [pid 255769:tid 255989] [client 20.206.105.145:39255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/eee.php"] [unique_id "al9LwbxMYwyVGnfuwsKTGAAAA_0"]
[Tue Jul 21 07:36:49.350560 2026] [autoindex:error] [pid 254995:tid 255057] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:49.351427 2026] [autoindex:error] [pid 254995:tid 255053] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:49.425659 2026] [security2:error] [pid 255769:tid 255979] [client 20.206.105.145:38942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file25.php"] [unique_id "al9LwbxMYwyVGnfuwsKTHgAAA_M"]
[Tue Jul 21 07:36:49.505486 2026] [security2:error] [pid 254995:tid 255160] [client 20.206.105.145:39237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file48.php"] [unique_id "al9Lwf7v0rlcEGmVraE47QAAA0E"]
[Tue Jul 21 07:36:49.613417 2026] [security2:error] [pid 255769:tid 255942] [client 20.197.195.24:13272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/adminner.php"] [unique_id "al9LwbxMYwyVGnfuwsKTIQAAA84"]
[Tue Jul 21 07:36:49.678586 2026] [security2:error] [pid 254995:tid 255179] [client 20.206.105.145:37937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/green1.php"] [unique_id "al9Lwf7v0rlcEGmVraE48gAAA1Q"]
[Tue Jul 21 07:36:49.721892 2026] [security2:error] [pid 255769:tid 256014] [client 20.104.96.117:59185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/acp.php"] [unique_id "al9LwbxMYwyVGnfuwsKTKAAABBQ"]
[Tue Jul 21 07:36:49.763801 2026] [security2:error] [pid 254995:tid 255200] [client 20.206.105.145:39282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file6.php"] [unique_id "al9Lwf7v0rlcEGmVraE4-wAAA2k"]
[Tue Jul 21 07:36:49.767958 2026] [autoindex:error] [pid 254995:tid 255039] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:49.768810 2026] [autoindex:error] [pid 254995:tid 255087] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:49.805565 2026] [security2:error] [pid 255769:tid 255929] [client 193.36.225.63:58105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9LwbxMYwyVGnfuwsKTKgAAA8E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:49.817066 2026] [security2:error] [pid 254995:tid 255127] [client 173.24.185.52:54750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Lwf7v0rlcEGmVraE4_AAAAyA"]
[Tue Jul 21 07:36:49.817165 2026] [security2:error] [pid 254995:tid 255127] [client 173.24.185.52:54750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Lwf7v0rlcEGmVraE4_AAAAyA"]
[Tue Jul 21 07:36:49.909074 2026] [security2:error] [pid 254995:tid 255133] [client 117.251.86.144:35550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Lwf7v0rlcEGmVraE4_gAAAyY"]
[Tue Jul 21 07:36:49.909208 2026] [security2:error] [pid 254995:tid 255133] [client 117.251.86.144:35550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Lwf7v0rlcEGmVraE4_gAAAyY"]
[Tue Jul 21 07:36:50.012924 2026] [security2:error] [pid 255769:tid 255927] [client 103.162.129.114:53737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LwrxMYwyVGnfuwsKTLwAAA78"]
[Tue Jul 21 07:36:50.013065 2026] [security2:error] [pid 255769:tid 255927] [client 103.162.129.114:53737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LwrxMYwyVGnfuwsKTLwAAA78"]
[Tue Jul 21 07:36:50.055903 2026] [security2:error] [pid 255769:tid 256022] [client 20.226.60.151:27600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/82.php"] [unique_id "al9LwrxMYwyVGnfuwsKTMQAABBw"]
[Tue Jul 21 07:36:50.174559 2026] [security2:error] [pid 255769:tid 255935] [client 20.206.105.145:38930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/a2.php"] [unique_id "al9LwrxMYwyVGnfuwsKTNQAAA8c"]
[Tue Jul 21 07:36:50.206246 2026] [security2:error] [pid 254995:tid 255197] [client 117.217.38.194:49961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lwv7v0rlcEGmVraE5BAAAA2Y"]
[Tue Jul 21 07:36:50.206406 2026] [security2:error] [pid 254995:tid 255197] [client 117.217.38.194:49961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lwv7v0rlcEGmVraE5BAAAA2Y"]
[Tue Jul 21 07:36:50.275403 2026] [security2:error] [pid 255769:tid 255903] [client 45.8.17.148:43391] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wso.php"] [unique_id "al9LwrxMYwyVGnfuwsKTOQAAA6c"]
[Tue Jul 21 07:36:50.349548 2026] [security2:error] [pid 255769:tid 255784] [remote 173.252.87.35:40842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9LwrxMYwyVGnfuwsKTOgADzA4"]
[Tue Jul 21 07:36:50.436296 2026] [security2:error] [pid 255769:tid 255962] [client 20.197.195.24:13287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/admin.php"] [unique_id "al9LwrxMYwyVGnfuwsKTPwAAA-I"]
[Tue Jul 21 07:36:50.502430 2026] [security2:error] [pid 255769:tid 255989] [client 20.104.96.117:61127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/mosty.php"] [unique_id "al9LwrxMYwyVGnfuwsKTQAAAA_0"]
[Tue Jul 21 07:36:50.565943 2026] [security2:error] [pid 255769:tid 255928] [client 122.186.204.214:55427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LwrxMYwyVGnfuwsKTQgAAA8A"]
[Tue Jul 21 07:36:50.566081 2026] [security2:error] [pid 255769:tid 255928] [client 122.186.204.214:55427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LwrxMYwyVGnfuwsKTQgAAA8A"]
[Tue Jul 21 07:36:50.807323 2026] [security2:error] [pid 255769:tid 255859] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LwrxMYwyVGnfuwsKTSAAEBFk"]
[Tue Jul 21 07:36:50.807504 2026] [security2:error] [pid 255769:tid 255998] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9LwrxMYwyVGnfuwsKTSAAEBFk"]
[Tue Jul 21 07:36:50.813832 2026] [security2:error] [pid 255769:tid 255919] [client 20.197.195.24:51812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9LwrxMYwyVGnfuwsKTSQAAA7c"]
[Tue Jul 21 07:36:50.838982 2026] [security2:error] [pid 254995:tid 255274] [client 20.197.195.24:13212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/k.php"] [unique_id "al9Lwv7v0rlcEGmVraE5EQAAA5g"]
[Tue Jul 21 07:36:50.867859 2026] [security2:error] [pid 254995:tid 255217] [client 151.241.100.27:57852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.100.241.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/phpMyAdmin/index.php"] [unique_id "al9Lwv7v0rlcEGmVraE5FAAAA3k"]
[Tue Jul 21 07:36:50.880858 2026] [proxy_http:error] [pid 255769:tid 255830] (20014)Internal error (specific information not available): [remote 185.93.89.147:0] AH01102: error reading status line from remote server 127.0.0.1:2082
[Tue Jul 21 07:36:50.899833 2026] [security2:error] [pid 254995:tid 255258] [client 151.241.100.27:57854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.100.241.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/phpmyadmin/index.php"] [unique_id "al9Lwv7v0rlcEGmVraE5FgAAA4g"]
[Tue Jul 21 07:36:51.128305 2026] [autoindex:error] [pid 254995:tid 255047] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:51.136577 2026] [autoindex:error] [pid 254995:tid 254998] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:51.259921 2026] [security2:error] [pid 255769:tid 255976] [client 20.206.105.145:39019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file15.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTVQAAA_A"]
[Tue Jul 21 07:36:51.303992 2026] [security2:error] [pid 255769:tid 255968] [client 20.197.195.24:13276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/blurbs.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTVwAAA-g"]
[Tue Jul 21 07:36:51.322627 2026] [security2:error] [pid 255769:tid 255974] [client 20.104.96.117:59660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/6.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTWAAAA-4"]
[Tue Jul 21 07:36:51.322977 2026] [security2:error] [pid 255769:tid 255933] [client 20.197.195.24:51722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTWQAAA8U"]
[Tue Jul 21 07:36:51.419553 2026] [security2:error] [pid 255769:tid 255938] [client 62.102.148.164:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTXgAAA8o"]
[Tue Jul 21 07:36:51.419667 2026] [security2:error] [pid 255769:tid 255938] [client 62.102.148.164:52900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTXgAAA8o"]
[Tue Jul 21 07:36:51.442465 2026] [security2:error] [pid 255769:tid 255943] [client 20.206.105.145:37944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/biufile.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTXwAAA88"]
[Tue Jul 21 07:36:51.475141 2026] [security2:error] [pid 255769:tid 255935] [client 45.8.17.105:42453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-info.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTYAAAA8c"]
[Tue Jul 21 07:36:51.557571 2026] [security2:error] [pid 255769:tid 255847] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTYgADxk0"]
[Tue Jul 21 07:36:51.557798 2026] [security2:error] [pid 255769:tid 255934] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lw7xMYwyVGnfuwsKTYgADxk0"]
[Tue Jul 21 07:36:51.633774 2026] [security2:error] [pid 254995:tid 255213] [client 20.197.195.24:13259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/bajah.php"] [unique_id "al9Lw_7v0rlcEGmVraE5IwAAA3U"]
[Tue Jul 21 07:36:52.043120 2026] [security2:error] [pid 255769:tid 255962] [client 20.197.195.24:51815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/media.php"] [unique_id "al9LxLxMYwyVGnfuwsKTaQAAA-I"]
[Tue Jul 21 07:36:52.078624 2026] [security2:error] [pid 255769:tid 255956] [client 20.104.96.117:59680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9LxLxMYwyVGnfuwsKTagAAA9w"]
[Tue Jul 21 07:36:52.109337 2026] [security2:error] [pid 254995:tid 255190] [client 20.197.195.24:13299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/a.php"] [unique_id "al9LxP7v0rlcEGmVraE5KwAAA18"]
[Tue Jul 21 07:36:52.309039 2026] [security2:error] [pid 255769:tid 255992] [client 20.206.105.145:39277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/jp.php"] [unique_id "al9LxLxMYwyVGnfuwsKTbAAAA_8"]
[Tue Jul 21 07:36:52.345121 2026] [security2:error] [pid 254995:tid 255195] [client 20.206.105.145:38465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wpconf.php"] [unique_id "al9LxP7v0rlcEGmVraE5MQAAA2Q"]
[Tue Jul 21 07:36:52.349983 2026] [security2:error] [pid 254995:tid 255169] [client 20.226.60.151:27578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/admin.php"] [unique_id "al9LxP7v0rlcEGmVraE5MgAAA0o"]
[Tue Jul 21 07:36:52.399075 2026] [access_compat:error] [pid 254995:tid 255131] [client 162.241.63.68:10780] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:36:52.409209 2026] [security2:error] [pid 254995:tid 255193] [client 175.45.70.82:60894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LxP7v0rlcEGmVraE5NAAAA2I"]
[Tue Jul 21 07:36:52.409301 2026] [security2:error] [pid 254995:tid 255193] [client 175.45.70.82:60894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LxP7v0rlcEGmVraE5NAAAA2I"]
[Tue Jul 21 07:36:52.487456 2026] [security2:error] [pid 254995:tid 255272] [client 20.197.195.24:13187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/edit.php"] [unique_id "al9LxP7v0rlcEGmVraE5OAAAA5Y"]
[Tue Jul 21 07:36:52.574046 2026] [security2:error] [pid 254995:tid 255212] [client 122.162.144.145:31421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LxP7v0rlcEGmVraE5OwAAA3Q"]
[Tue Jul 21 07:36:52.574172 2026] [security2:error] [pid 254995:tid 255212] [client 122.162.144.145:31421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9LxP7v0rlcEGmVraE5OwAAA3Q"]
[Tue Jul 21 07:36:52.680130 2026] [security2:error] [pid 254995:tid 255267] [client 20.197.195.24:13200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/hosty.php"] [unique_id "al9LxP7v0rlcEGmVraE5PwAAA5E"]
[Tue Jul 21 07:36:52.680278 2026] [security2:error] [pid 255769:tid 255916] [client 45.8.17.138:39685] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/s.php"] [unique_id "al9LxLxMYwyVGnfuwsKTcAAAA7Q"]
[Tue Jul 21 07:36:52.703105 2026] [security2:error] [pid 255769:tid 256021] [client 20.104.96.117:59657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/qqqa.php"] [unique_id "al9LxLxMYwyVGnfuwsKTcQAABBs"]
[Tue Jul 21 07:36:52.714654 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:51273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9LxP7v0rlcEGmVraE5QAAAAx4"]
[Tue Jul 21 07:36:52.877823 2026] [security2:error] [pid 255769:tid 256004] [client 20.197.195.24:13249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/k.php"] [unique_id "al9LxLxMYwyVGnfuwsKTcgAABAo"]
[Tue Jul 21 07:36:52.981986 2026] [security2:error] [pid 254995:tid 255274] [client 20.197.195.24:13264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/aaa.php"] [unique_id "al9LxP7v0rlcEGmVraE5QwAAA5g"]
[Tue Jul 21 07:36:53.012437 2026] [security2:error] [pid 255769:tid 255942] [client 20.197.195.24:51734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/images.php"] [unique_id "al9LxbxMYwyVGnfuwsKTcwAAA84"]
[Tue Jul 21 07:36:53.057354 2026] [autoindex:error] [pid 254995:tid 255001] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:53.062504 2026] [autoindex:error] [pid 254995:tid 255077] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:53.083984 2026] [security2:error] [pid 255769:tid 255930] [client 151.241.100.27:57853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.100.241.151.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/adminer.php"] [unique_id "al9LxbxMYwyVGnfuwsKTdAAAA8I"]
[Tue Jul 21 07:36:53.084164 2026] [security2:error] [pid 254995:tid 255020] [remote 74.7.243.250:49658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "orixmed.com.inlaudo.com.br"] [uri "/blog/index.php"] [unique_id "al9Lxf7v0rlcEGmVraE5SAADIhg"], referer: https://orixmed.com.inlaudo.com.br/blog/
[Tue Jul 21 07:36:53.123438 2026] [security2:error] [pid 254995:tid 255263] [client 20.197.195.24:13277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file5.php"] [unique_id "al9Lxf7v0rlcEGmVraE5SwAAA40"]
[Tue Jul 21 07:36:53.148417 2026] [security2:error] [pid 254995:tid 255152] [client 154.192.233.199:59824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5TAAAAzk"]
[Tue Jul 21 07:36:53.148558 2026] [security2:error] [pid 254995:tid 255152] [client 154.192.233.199:59824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5TAAAAzk"]
[Tue Jul 21 07:36:53.160049 2026] [security2:error] [pid 254995:tid 255197] [client 103.106.20.201:49405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5TQAAA2Y"]
[Tue Jul 21 07:36:53.160162 2026] [security2:error] [pid 254995:tid 255197] [client 103.106.20.201:49405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5TQAAA2Y"]
[Tue Jul 21 07:36:53.338216 2026] [security2:error] [pid 255769:tid 255929] [client 20.104.96.117:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/aunmc.php"] [unique_id "al9LxbxMYwyVGnfuwsKTewAAA8E"]
[Tue Jul 21 07:36:53.425949 2026] [security2:error] [pid 255769:tid 255977] [client 20.197.195.24:13270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/222.php"] [unique_id "al9LxbxMYwyVGnfuwsKTgAAAA_E"]
[Tue Jul 21 07:36:53.501828 2026] [security2:error] [pid 254995:tid 255213] [client 20.226.60.151:61197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Lxf7v0rlcEGmVraE5iAAAA3U"]
[Tue Jul 21 07:36:53.588596 2026] [security2:error] [pid 254995:tid 255148] [client 62.102.148.164:52906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5iQAAAzU"]
[Tue Jul 21 07:36:53.588717 2026] [security2:error] [pid 254995:tid 255148] [client 62.102.148.164:52906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5iQAAAzU"]
[Tue Jul 21 07:36:53.649010 2026] [security2:error] [pid 254995:tid 255141] [client 20.206.105.145:37908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/mosty.php"] [unique_id "al9Lxf7v0rlcEGmVraE5iwAAAy4"]
[Tue Jul 21 07:36:53.664937 2026] [security2:error] [pid 254995:tid 255051] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5jAADRzc"]
[Tue Jul 21 07:36:53.665056 2026] [security2:error] [pid 254995:tid 255166] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lxf7v0rlcEGmVraE5jAADRzc"]
[Tue Jul 21 07:36:53.680397 2026] [security2:error] [pid 254995:tid 255160] [client 20.197.195.24:13215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/test.php"] [unique_id "al9Lxf7v0rlcEGmVraE5kgAAA0E"]
[Tue Jul 21 07:36:53.867008 2026] [security2:error] [pid 255769:tid 256028] [client 20.104.96.117:59195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/uoocf.php"] [unique_id "al9LxbxMYwyVGnfuwsKTkgAABCI"]
[Tue Jul 21 07:36:53.998792 2026] [autoindex:error] [pid 254995:tid 255100] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/Text/Diff/Engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:54.000782 2026] [autoindex:error] [pid 254995:tid 255060] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/jcrop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:54.177284 2026] [security2:error] [pid 255769:tid 255916] [client 45.8.17.103:57999] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/69.php"] [unique_id "al9LxrxMYwyVGnfuwsKTlgAAA7Q"]
[Tue Jul 21 07:36:54.265172 2026] [security2:error] [pid 255769:tid 255941] [client 20.197.195.24:13266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/aaa.php"] [unique_id "al9LxrxMYwyVGnfuwsKTlwAAA80"]
[Tue Jul 21 07:36:54.437532 2026] [security2:error] [pid 255769:tid 255967] [client 20.197.195.24:51808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/gecko.php"] [unique_id "al9LxrxMYwyVGnfuwsKTngAAA-c"]
[Tue Jul 21 07:36:54.438289 2026] [security2:error] [pid 254995:tid 255194] [client 20.104.96.117:59697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/iywwi.php"] [unique_id "al9Lxv7v0rlcEGmVraE5_QAAA2M"]
[Tue Jul 21 07:36:54.593172 2026] [security2:error] [pid 255769:tid 255880] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LxrxMYwyVGnfuwsKTogAECW4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:54.595743 2026] [security2:error] [pid 254995:tid 255159] [client 20.197.195.24:13265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/11.php"] [unique_id "al9Lxv7v0rlcEGmVraE6AQAAA0A"]
[Tue Jul 21 07:36:54.602038 2026] [security2:error] [pid 255769:tid 255846] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LxrxMYwyVGnfuwsKTowAD00w"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:54.607336 2026] [security2:error] [pid 255769:tid 255815] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LxrxMYwyVGnfuwsKTpAAEBC0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:54.607497 2026] [security2:error] [pid 255769:tid 255790] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LxrxMYwyVGnfuwsKTpQADrRQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:54.646415 2026] [security2:error] [pid 255769:tid 255956] [client 122.164.127.47:52940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LxrxMYwyVGnfuwsKTqAAAA9w"]
[Tue Jul 21 07:36:54.646549 2026] [security2:error] [pid 255769:tid 255956] [client 122.164.127.47:52940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9LxrxMYwyVGnfuwsKTqAAAA9w"]
[Tue Jul 21 07:36:54.877010 2026] [security2:error] [pid 255769:tid 255984] [client 20.197.195.24:13303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/mac.php"] [unique_id "al9LxrxMYwyVGnfuwsKTqQAAA_g"]
[Tue Jul 21 07:36:54.922258 2026] [security2:error] [pid 255769:tid 255945] [client 20.197.195.24:13224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/chosen.php"] [unique_id "al9LxrxMYwyVGnfuwsKTqgAAA9E"]
[Tue Jul 21 07:36:54.943850 2026] [security2:error] [pid 255769:tid 255901] [client 20.197.195.24:13296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/cream1.php"] [unique_id "al9LxrxMYwyVGnfuwsKTqwAAA6U"]
[Tue Jul 21 07:36:54.947738 2026] [autoindex:error] [pid 254995:tid 255044] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:54.959578 2026] [security2:error] [pid 255769:tid 255831] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LxrxMYwyVGnfuwsKTrAADyD0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:54.964019 2026] [security2:error] [pid 255769:tid 255828] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LxrxMYwyVGnfuwsKTrQAD6Do"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:54.968569 2026] [security2:error] [pid 255769:tid 255972] [client 20.206.105.145:38477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/dejavu.php"] [unique_id "al9LxrxMYwyVGnfuwsKTrgAAA-w"]
[Tue Jul 21 07:36:54.990452 2026] [autoindex:error] [pid 255769:tid 255927] [client 20.197.195.24:13196] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:54.998795 2026] [security2:error] [pid 255769:tid 255938] [client 20.197.195.24:51759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/82.php"] [unique_id "al9LxrxMYwyVGnfuwsKTsQAAA8o"]
[Tue Jul 21 07:36:55.011310 2026] [autoindex:error] [pid 255769:tid 255948] [client 20.197.195.24:13196] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:36:55.020033 2026] [security2:error] [pid 255769:tid 255888] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTswADzHY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.034162 2026] [security2:error] [pid 255769:tid 255926] [client 20.197.195.24:13196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/dr.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTtAAAA74"]
[Tue Jul 21 07:36:55.059854 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:51316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xyn.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTtQAAA_4"]
[Tue Jul 21 07:36:55.084596 2026] [security2:error] [pid 254995:tid 255266] [client 20.197.195.24:13226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/x.php"] [unique_id "al9Lx_7v0rlcEGmVraE6EwAAA5A"]
[Tue Jul 21 07:36:55.125546 2026] [security2:error] [pid 255769:tid 255935] [client 20.151.10.161:45953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTtwAAA8c"]
[Tue Jul 21 07:36:55.186177 2026] [security2:error] [pid 255769:tid 255980] [client 20.206.105.145:38472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/aaf.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTuAAAA_Q"]
[Tue Jul 21 07:36:55.203750 2026] [security2:error] [pid 254995:tid 255222] [client 20.197.195.24:51823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/admin.php"] [unique_id "al9Lx_7v0rlcEGmVraE6FAAAA34"]
[Tue Jul 21 07:36:55.274950 2026] [security2:error] [pid 254995:tid 255147] [client 20.206.105.145:38479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/term.php"] [unique_id "al9Lx_7v0rlcEGmVraE6FgAAAzQ"]
[Tue Jul 21 07:36:55.283318 2026] [security2:error] [pid 254995:tid 255136] [client 20.197.195.24:13251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/155.php"] [unique_id "al9Lx_7v0rlcEGmVraE6FwAAAyk"]
[Tue Jul 21 07:36:55.313681 2026] [security2:error] [pid 255769:tid 255857] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTuQADw1c"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.334749 2026] [security2:error] [pid 255769:tid 255851] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTvAAEE1E"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.356059 2026] [security2:error] [pid 254995:tid 255129] [client 103.174.34.15:57134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lx_7v0rlcEGmVraE6GwAAAyI"]
[Tue Jul 21 07:36:55.356482 2026] [security2:error] [pid 254995:tid 255129] [client 103.174.34.15:57134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lx_7v0rlcEGmVraE6GwAAAyI"]
[Tue Jul 21 07:36:55.365636 2026] [security2:error] [pid 255769:tid 255867] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTvgAEHmE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.384772 2026] [security2:error] [pid 254995:tid 255275] [client 20.197.195.24:51829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/adminner.php"] [unique_id "al9Lx_7v0rlcEGmVraE6NwAAA5k"]
[Tue Jul 21 07:36:55.423605 2026] [security2:error] [pid 255769:tid 255920] [client 193.36.225.56:23885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTwgAAA7g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:55.469372 2026] [security2:error] [pid 255769:tid 255979] [client 20.104.96.117:59674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/gqgsa.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTxAAAA_M"]
[Tue Jul 21 07:36:55.556995 2026] [security2:error] [pid 254995:tid 255075] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx_7v0rlcEGmVraE6SAADbk8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.566032 2026] [autoindex:error] [pid 254995:tid 254998] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:55.611225 2026] [security2:error] [pid 255769:tid 255930] [client 20.197.195.24:51787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/admin.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTxwAAA8I"]
[Tue Jul 21 07:36:55.667741 2026] [security2:error] [pid 255769:tid 255864] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTyAADpF4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.686512 2026] [security2:error] [pid 255769:tid 256025] [client 45.8.17.103:42933] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-crom.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTyQAABB8"]
[Tue Jul 21 07:36:55.691080 2026] [security2:error] [pid 255769:tid 255821] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTygAEFDM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.698598 2026] [security2:error] [pid 254995:tid 255056] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Lx_7v0rlcEGmVraE6TAADSTw"]
[Tue Jul 21 07:36:55.698736 2026] [security2:error] [pid 254995:tid 255168] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Lx_7v0rlcEGmVraE6TAADSTw"]
[Tue Jul 21 07:36:55.719640 2026] [security2:error] [pid 255769:tid 255782] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTzAAD0ww"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:55.744604 2026] [security2:error] [pid 255769:tid 255970] [client 20.206.105.145:37938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ha.php"] [unique_id "al9Lx7xMYwyVGnfuwsKTzgAAA-o"]
[Tue Jul 21 07:36:55.950539 2026] [autoindex:error] [pid 254995:tid 255012] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:56.027449 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.195.24:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ops.php"] [unique_id "al9LyLxMYwyVGnfuwsKT_gAAA7Y"]
[Tue Jul 21 07:36:56.040207 2026] [security2:error] [pid 255769:tid 255965] [client 20.226.60.151:27339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/adminner.php"] [unique_id "al9LyLxMYwyVGnfuwsKUAAAAA-U"]
[Tue Jul 21 07:36:56.101980 2026] [security2:error] [pid 255769:tid 255966] [client 20.206.105.145:39286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/f35.php"] [unique_id "al9LyLxMYwyVGnfuwsKUAQAAA-Y"]
[Tue Jul 21 07:36:56.122953 2026] [security2:error] [pid 255769:tid 255961] [client 20.197.195.24:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/k.php"] [unique_id "al9LyLxMYwyVGnfuwsKUAgAAA-E"]
[Tue Jul 21 07:36:56.147735 2026] [security2:error] [pid 255769:tid 255780] [remote 159.223.32.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.32.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9LyLxMYwyVGnfuwsKUAwAEDgo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:36:56.191098 2026] [security2:error] [pid 255769:tid 255941] [client 20.104.96.117:59685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/elbzl.php"] [unique_id "al9LyLxMYwyVGnfuwsKUBAAAA80"]
[Tue Jul 21 07:36:56.313874 2026] [autoindex:error] [pid 254995:tid 255097] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:56.351423 2026] [autoindex:error] [pid 254995:tid 255116] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:56.364738 2026] [security2:error] [pid 255769:tid 255891] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LyLxMYwyVGnfuwsKUBQADw3k"]
[Tue Jul 21 07:36:56.364910 2026] [security2:error] [pid 255769:tid 255931] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LyLxMYwyVGnfuwsKUBQADw3k"]
[Tue Jul 21 07:36:56.534582 2026] [security2:error] [pid 255769:tid 255971] [client 20.220.225.223:38675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/byp8.php"] [unique_id "al9LyLxMYwyVGnfuwsKUCQAAA-s"]
[Tue Jul 21 07:36:56.646721 2026] [security2:error] [pid 255769:tid 255781] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LyLxMYwyVGnfuwsKUCwADzgs"]
[Tue Jul 21 07:36:56.646875 2026] [security2:error] [pid 255769:tid 255942] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9LyLxMYwyVGnfuwsKUCwADzgs"]
[Tue Jul 21 07:36:56.729481 2026] [security2:error] [pid 255769:tid 255947] [client 20.197.195.24:51780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/blurbs.php"] [unique_id "al9LyLxMYwyVGnfuwsKUDQAAA9M"]
[Tue Jul 21 07:36:56.813910 2026] [security2:error] [pid 255769:tid 255909] [client 20.220.225.223:38673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/wander.php"] [unique_id "al9LyLxMYwyVGnfuwsKUDwAAA60"]
[Tue Jul 21 07:36:56.847898 2026] [security2:error] [pid 255769:tid 255934] [client 193.36.225.151:50405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9LyLxMYwyVGnfuwsKUDAAAA8Y"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:56.885149 2026] [security2:error] [pid 255769:tid 255956] [client 20.206.105.145:38085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/hur.php"] [unique_id "al9LyLxMYwyVGnfuwsKUEAAAA9w"]
[Tue Jul 21 07:36:57.064546 2026] [security2:error] [pid 255769:tid 255779] [remote 154.61.75.100:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9LybxMYwyVGnfuwsKUFQAEGgk"]
[Tue Jul 21 07:36:57.175621 2026] [security2:error] [pid 255769:tid 255950] [client 45.8.17.65:61415] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9LybxMYwyVGnfuwsKUFgAAA9Y"]
[Tue Jul 21 07:36:57.380503 2026] [security2:error] [pid 255769:tid 255980] [client 74.7.230.23:53482] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "zooparquevet.com.br"] [uri "/index.php"] [unique_id "al9LyLxMYwyVGnfuwsKT_wAAA_Q"]
[Tue Jul 21 07:36:57.386211 2026] [security2:error] [pid 255769:tid 255948] [client 20.151.10.161:46016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9LybxMYwyVGnfuwsKUGAAAA9Q"]
[Tue Jul 21 07:36:57.406298 2026] [autoindex:error] [pid 254995:tid 255010] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/jcrop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:57.425094 2026] [autoindex:error] [pid 254995:tid 255014] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:57.480153 2026] [security2:error] [pid 254995:tid 255130] [client 20.226.60.151:61191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/patie.php"] [unique_id "al9Lyf7v0rlcEGmVraE6bAAAAyM"]
[Tue Jul 21 07:36:57.523198 2026] [security2:error] [pid 255769:tid 255958] [client 20.206.105.145:39273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-load.php"] [unique_id "al9LybxMYwyVGnfuwsKUGgAAA94"]
[Tue Jul 21 07:36:57.565261 2026] [security2:error] [pid 255769:tid 255935] [client 20.197.195.24:51712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/bajah.php"] [unique_id "al9LybxMYwyVGnfuwsKUGwAAA8c"]
[Tue Jul 21 07:36:57.566982 2026] [security2:error] [pid 254995:tid 255137] [client 20.104.96.117:59172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/adjig.php"] [unique_id "al9Lyf7v0rlcEGmVraE6cQAAAyo"]
[Tue Jul 21 07:36:57.596038 2026] [core:error] [pid 255769:tid 255940] [client 66.249.66.67:50562] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:57.596056 2026] [core:error] [pid 255769:tid 255940] [client 66.249.66.67:50562] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:57.753002 2026] [security2:error] [pid 255769:tid 256013] [client 20.197.195.24:62423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file31.php"] [unique_id "al9LybxMYwyVGnfuwsKUHQAABBM"]
[Tue Jul 21 07:36:57.879837 2026] [security2:error] [pid 255769:tid 255916] [client 59.96.220.140:57678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LybxMYwyVGnfuwsKUHwAAA7Q"]
[Tue Jul 21 07:36:57.880016 2026] [security2:error] [pid 255769:tid 255916] [client 59.96.220.140:57678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9LybxMYwyVGnfuwsKUHwAAA7Q"]
[Tue Jul 21 07:36:57.982655 2026] [security2:error] [pid 255769:tid 255981] [client 103.86.117.203:52545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LybxMYwyVGnfuwsKUIAAAA_U"]
[Tue Jul 21 07:36:57.982766 2026] [security2:error] [pid 255769:tid 255981] [client 103.86.117.203:52545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LybxMYwyVGnfuwsKUIAAAA_U"]
[Tue Jul 21 07:36:58.023646 2026] [autoindex:error] [pid 254995:tid 255045] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:58.215104 2026] [security2:error] [pid 254995:tid 255190] [client 20.197.195.24:51773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/a.php"] [unique_id "al9Lyv7v0rlcEGmVraE6gQAAA18"]
[Tue Jul 21 07:36:58.337829 2026] [security2:error] [pid 254995:tid 255195] [client 20.220.225.223:38694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/jga.php"] [unique_id "al9Lyv7v0rlcEGmVraE6gwAAA2Q"]
[Tue Jul 21 07:36:58.371723 2026] [security2:error] [pid 254995:tid 255146] [client 20.226.60.151:27618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/admin.php"] [unique_id "al9Lyv7v0rlcEGmVraE6hAAAAzM"]
[Tue Jul 21 07:36:58.413161 2026] [security2:error] [pid 255769:tid 255954] [client 20.104.96.117:59149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/byp.php"] [unique_id "al9LyrxMYwyVGnfuwsKUJwAAA9o"]
[Tue Jul 21 07:36:58.413203 2026] [security2:error] [pid 255769:tid 255925] [client 20.206.105.145:38083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/h02ugyh.php"] [unique_id "al9LyrxMYwyVGnfuwsKUKAAAA70"]
[Tue Jul 21 07:36:58.472017 2026] [security2:error] [pid 254995:tid 255061] [remote 119.195.102.159:38504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9Lyv7v0rlcEGmVraE6hgADVUE"]
[Tue Jul 21 07:36:58.625192 2026] [core:error] [pid 254995:tid 255131] [client 66.249.66.68:40130] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:58.625210 2026] [core:error] [pid 254995:tid 255131] [client 66.249.66.68:40130] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:36:58.700796 2026] [autoindex:error] [pid 254995:tid 255001] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/css/dist/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:58.749535 2026] [autoindex:error] [pid 254995:tid 255020] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:58.754147 2026] [security2:error] [pid 254995:tid 255223] [client 20.197.195.24:51755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/edit.php"] [unique_id "al9Lyv7v0rlcEGmVraE6jAAAA38"]
[Tue Jul 21 07:36:58.771343 2026] [security2:error] [pid 255769:tid 255947] [client 45.8.17.59:29489] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/click.php"] [unique_id "al9LyrxMYwyVGnfuwsKULwAAA9M"]
[Tue Jul 21 07:36:58.843678 2026] [security2:error] [pid 255769:tid 255929] [client 20.197.195.24:51719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/hosty.php"] [unique_id "al9LyrxMYwyVGnfuwsKUMgAAA8E"]
[Tue Jul 21 07:36:58.874160 2026] [security2:error] [pid 255769:tid 255970] [client 20.197.195.24:51743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/k.php"] [unique_id "al9LyrxMYwyVGnfuwsKUMwAAA-o"]
[Tue Jul 21 07:36:58.995737 2026] [security2:error] [pid 255769:tid 255988] [client 20.197.195.24:62891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file6.php"] [unique_id "al9LyrxMYwyVGnfuwsKUNAAAA_w"]
[Tue Jul 21 07:36:59.074730 2026] [security2:error] [pid 255769:tid 255972] [client 20.197.195.24:51776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/aaa.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUOAAAA-w"]
[Tue Jul 21 07:36:59.099294 2026] [security2:error] [pid 255769:tid 256004] [client 45.251.232.145:63733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUOQAABAo"]
[Tue Jul 21 07:36:59.099367 2026] [security2:error] [pid 255769:tid 256004] [client 45.251.232.145:63733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUOQAABAo"]
[Tue Jul 21 07:36:59.110189 2026] [security2:error] [pid 254995:tid 255163] [client 139.167.225.182:61670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ly_7v0rlcEGmVraE6kgAAA0Q"]
[Tue Jul 21 07:36:59.110262 2026] [security2:error] [pid 254995:tid 255163] [client 139.167.225.182:61670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ly_7v0rlcEGmVraE6kgAAA0Q"]
[Tue Jul 21 07:36:59.173035 2026] [security2:error] [pid 255769:tid 256018] [client 20.220.225.223:31192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/user.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUPQAABBg"]
[Tue Jul 21 07:36:59.192925 2026] [security2:error] [pid 255769:tid 255958] [client 20.197.195.24:51822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/file5.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUPgAAA94"]
[Tue Jul 21 07:36:59.228159 2026] [security2:error] [pid 255769:tid 255990] [client 20.206.105.145:39287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xwpg.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUPwAAA_4"]
[Tue Jul 21 07:36:59.323060 2026] [security2:error] [pid 255769:tid 255918] [client 85.204.70.100:43192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Ly7xMYwyVGnfuwsKUQAAAA7Y"]
[Tue Jul 21 07:36:59.364227 2026] [security2:error] [pid 255769:tid 255940] [client 20.226.60.151:51283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/aa.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUQQAAA8w"]
[Tue Jul 21 07:36:59.376965 2026] [security2:error] [pid 255769:tid 255983] [client 20.104.96.117:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUQgAAA_c"]
[Tue Jul 21 07:36:59.418197 2026] [security2:error] [pid 255769:tid 255915] [client 20.197.195.24:51718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/222.php"] [unique_id "al9Ly7xMYwyVGnfuwsKURAAAA7M"]
[Tue Jul 21 07:36:59.531911 2026] [security2:error] [pid 255769:tid 256015] [client 20.197.195.24:51818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/test.php"] [unique_id "al9Ly7xMYwyVGnfuwsKURwAABBU"]
[Tue Jul 21 07:36:59.672784 2026] [security2:error] [pid 254995:tid 255264] [client 37.140.223.50:58719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Ly_7v0rlcEGmVraE6mAAAA44"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:36:59.679461 2026] [security2:error] [pid 254995:tid 255126] [client 45.8.17.145:56365] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/byp.php"] [unique_id "al9Ly_7v0rlcEGmVraE6mQAAAx8"]
[Tue Jul 21 07:36:59.723595 2026] [security2:error] [pid 255769:tid 255954] [client 20.197.195.24:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/aaa.php"] [unique_id "al9Ly7xMYwyVGnfuwsKUTgAAA9o"]
[Tue Jul 21 07:36:59.779345 2026] [security2:error] [pid 254995:tid 255161] [client 20.206.105.145:37892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/seiso.php"] [unique_id "al9Ly_7v0rlcEGmVraE6mwAAA0I"]
[Tue Jul 21 07:36:59.791110 2026] [security2:error] [pid 254995:tid 255170] [client 193.36.225.67:59871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Ly_7v0rlcEGmVraE6nAAAA0s"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:36:59.837655 2026] [autoindex:error] [pid 254995:tid 255118] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:59.837759 2026] [autoindex:error] [pid 254995:tid 255006] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:36:59.991376 2026] [proxy:error] [pid 255769:tid 256006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:59.991449 2026] [proxy_http:error] [pid 255769:tid 256006] [client 20.206.105.145:39266] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:36:59.992070 2026] [proxy:error] [pid 255769:tid 256006] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:36:59.992102 2026] [proxy_http:error] [pid 255769:tid 256006] [client 20.206.105.145:39266] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:37:00.081172 2026] [security2:error] [pid 255769:tid 255976] [client 85.204.70.100:43206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9LzLxMYwyVGnfuwsKUVgAAA_A"]
[Tue Jul 21 07:37:00.107180 2026] [security2:error] [pid 255769:tid 255988] [client 20.197.195.24:51775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/11.php"] [unique_id "al9LzLxMYwyVGnfuwsKUVwAAA_w"]
[Tue Jul 21 07:37:00.204331 2026] [autoindex:error] [pid 254995:tid 255028] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:00.207059 2026] [autoindex:error] [pid 254995:tid 255091] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:00.218578 2026] [security2:error] [pid 255769:tid 255979] [client 20.197.195.24:51825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/mac.php"] [unique_id "al9LzLxMYwyVGnfuwsKUXAAAA_M"]
[Tue Jul 21 07:37:00.290426 2026] [security2:error] [pid 255769:tid 256004] [client 20.197.195.24:51765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/chosen.php"] [unique_id "al9LzLxMYwyVGnfuwsKUXgAABAo"]
[Tue Jul 21 07:37:00.368460 2026] [security2:error] [pid 255769:tid 255943] [client 20.197.195.24:51794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/cream1.php"] [unique_id "al9LzLxMYwyVGnfuwsKUXwAAA88"]
[Tue Jul 21 07:37:00.475574 2026] [security2:error] [pid 255769:tid 255980] [client 85.204.70.100:59244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9LzLxMYwyVGnfuwsKUYgAAA_Q"]
[Tue Jul 21 07:37:00.515213 2026] [security2:error] [pid 255769:tid 256024] [client 173.24.185.52:55217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LzLxMYwyVGnfuwsKUYwAABB4"]
[Tue Jul 21 07:37:00.515347 2026] [security2:error] [pid 255769:tid 256024] [client 173.24.185.52:55217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9LzLxMYwyVGnfuwsKUYwAABB4"]
[Tue Jul 21 07:37:00.555225 2026] [proxy:error] [pid 255769:tid 256018] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:37:00.555306 2026] [proxy_http:error] [pid 255769:tid 256018] [client 20.206.105.145:39281] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:37:00.556392 2026] [proxy:error] [pid 255769:tid 256018] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:37:00.556426 2026] [proxy_http:error] [pid 255769:tid 256018] [client 20.206.105.145:39281] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:37:00.576914 2026] [security2:error] [pid 255769:tid 255952] [client 117.251.86.144:38768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LzLxMYwyVGnfuwsKUZgAAA9g"]
[Tue Jul 21 07:37:00.577068 2026] [security2:error] [pid 255769:tid 255952] [client 117.251.86.144:38768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9LzLxMYwyVGnfuwsKUZgAAA9g"]
[Tue Jul 21 07:37:00.592102 2026] [security2:error] [pid 255769:tid 255903] [client 20.104.96.117:61066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/classwithtostring.php"] [unique_id "al9LzLxMYwyVGnfuwsKUZwAAA6c"]
[Tue Jul 21 07:37:00.689623 2026] [autoindex:error] [pid 254995:tid 255059] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:00.690382 2026] [autoindex:error] [pid 254995:tid 255032] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/css/dist/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:00.694316 2026] [security2:error] [pid 254995:tid 255151] [client 117.217.38.194:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LzP7v0rlcEGmVraE6rgAAAzg"]
[Tue Jul 21 07:37:00.694410 2026] [security2:error] [pid 254995:tid 255151] [client 117.217.38.194:50594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LzP7v0rlcEGmVraE6rgAAAzg"]
[Tue Jul 21 07:37:00.796474 2026] [security2:error] [pid 255769:tid 255911] [client 103.162.129.114:54177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LzLxMYwyVGnfuwsKUbgAAA68"]
[Tue Jul 21 07:37:00.796606 2026] [security2:error] [pid 255769:tid 255911] [client 103.162.129.114:54177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9LzLxMYwyVGnfuwsKUbgAAA68"]
[Tue Jul 21 07:37:00.855929 2026] [security2:error] [pid 255769:tid 255951] [client 85.204.70.100:53102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9LzLxMYwyVGnfuwsKUbwAAA9c"]
[Tue Jul 21 07:37:00.860167 2026] [security2:error] [pid 254995:tid 255213] [client 20.206.105.145:39116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/waf.php"] [unique_id "al9LzP7v0rlcEGmVraE6sAAAA3U"]
[Tue Jul 21 07:37:00.906978 2026] [security2:error] [pid 255769:tid 255974] [client 20.206.105.145:38936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xstelth.php"] [unique_id "al9LzLxMYwyVGnfuwsKUcQAAA-4"]
[Tue Jul 21 07:37:00.970993 2026] [security2:error] [pid 255769:tid 255925] [client 20.151.10.161:46047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/x.php"] [unique_id "al9LzLxMYwyVGnfuwsKUcwAAA70"]
[Tue Jul 21 07:37:01.028264 2026] [autoindex:error] [pid 255769:tid 255919] [client 20.197.195.24:51751] AH01276: Cannot serve directory /home3/equote29/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:01.049035 2026] [security2:error] [pid 255769:tid 255944] [client 20.104.96.117:61078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/root.php"] [unique_id "al9LzbxMYwyVGnfuwsKUdgAAA9A"]
[Tue Jul 21 07:37:01.085473 2026] [security2:error] [pid 255769:tid 256006] [client 45.8.17.57:33995] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/ateprivacy-policy-guide.php"] [unique_id "al9LzbxMYwyVGnfuwsKUeAAABAw"]
[Tue Jul 21 07:37:01.087780 2026] [autoindex:error] [pid 255769:tid 255910] [client 20.197.195.24:51751] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:01.093360 2026] [security2:error] [pid 255769:tid 255930] [client 20.197.195.24:51751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/dr.php"] [unique_id "al9LzbxMYwyVGnfuwsKUeQAAA8I"]
[Tue Jul 21 07:37:01.155398 2026] [security2:error] [pid 255769:tid 255984] [client 20.206.105.145:39151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-links.php"] [unique_id "al9LzbxMYwyVGnfuwsKUegAAA_g"]
[Tue Jul 21 07:37:01.197515 2026] [security2:error] [pid 255769:tid 255887] [remote 114.34.90.9:33200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9LzbxMYwyVGnfuwsKUfAAEA3U"]
[Tue Jul 21 07:37:01.243796 2026] [security2:error] [pid 255769:tid 255932] [client 85.204.70.100:62449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9LzbxMYwyVGnfuwsKUfQAAA8Q"]
[Tue Jul 21 07:37:01.262723 2026] [security2:error] [pid 254995:tid 255008] [remote 117.0.21.154:57618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Lzf7v0rlcEGmVraE6uwADdww"]
[Tue Jul 21 07:37:01.265598 2026] [security2:error] [pid 255769:tid 255945] [client 122.186.204.214:55959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LzbxMYwyVGnfuwsKUfgAAA9E"]
[Tue Jul 21 07:37:01.265704 2026] [security2:error] [pid 255769:tid 255945] [client 122.186.204.214:55959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9LzbxMYwyVGnfuwsKUfgAAA9E"]
[Tue Jul 21 07:37:01.308631 2026] [autoindex:error] [pid 254995:tid 255191] [client 20.197.195.24:62430] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:01.338932 2026] [security2:error] [pid 254995:tid 255189] [client 20.197.195.24:62430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/adminfuns.php"] [unique_id "al9Lzf7v0rlcEGmVraE6vgAAA14"]
[Tue Jul 21 07:37:01.356536 2026] [security2:error] [pid 255769:tid 255972] [client 82.102.28.107:33010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LzbxMYwyVGnfuwsKUgwAAA-w"]
[Tue Jul 21 07:37:01.356675 2026] [security2:error] [pid 255769:tid 255972] [client 82.102.28.107:33010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9LzbxMYwyVGnfuwsKUgwAAA-w"]
[Tue Jul 21 07:37:01.626363 2026] [security2:error] [pid 254995:tid 255169] [client 85.204.70.100:53120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Lzf7v0rlcEGmVraE6wQAAA0o"]
[Tue Jul 21 07:37:01.653852 2026] [security2:error] [pid 255769:tid 255958] [client 20.206.105.145:38093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/155.php"] [unique_id "al9LzbxMYwyVGnfuwsKUhwAAA94"]
[Tue Jul 21 07:37:01.660991 2026] [security2:error] [pid 255769:tid 255903] [client 20.104.96.117:59188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/sym403.php"] [unique_id "al9LzbxMYwyVGnfuwsKUiAAAA6c"]
[Tue Jul 21 07:37:01.751739 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.195.24:51804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/x.php"] [unique_id "al9LzbxMYwyVGnfuwsKUigAAA7Y"]
[Tue Jul 21 07:37:01.858932 2026] [security2:error] [pid 254995:tid 255064] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lzf7v0rlcEGmVraE6ywADi0Q"]
[Tue Jul 21 07:37:01.859088 2026] [security2:error] [pid 254995:tid 255261] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Lzf7v0rlcEGmVraE6ywADi0Q"]
[Tue Jul 21 07:37:01.902807 2026] [security2:error] [pid 255769:tid 255992] [client 152.59.154.239:56722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LzbxMYwyVGnfuwsKUjgAAA_8"]
[Tue Jul 21 07:37:01.902925 2026] [security2:error] [pid 255769:tid 255992] [client 152.59.154.239:56722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9LzbxMYwyVGnfuwsKUjgAAA_8"]
[Tue Jul 21 07:37:02.000211 2026] [security2:error] [pid 255769:tid 255911] [client 85.204.70.100:53128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9LzbxMYwyVGnfuwsKUkAAAA68"]
[Tue Jul 21 07:37:02.216299 2026] [security2:error] [pid 254995:tid 255095] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lzv7v0rlcEGmVraE61QADJmM"]
[Tue Jul 21 07:37:02.216420 2026] [security2:error] [pid 254995:tid 255133] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lzv7v0rlcEGmVraE61QADJmM"]
[Tue Jul 21 07:37:02.217177 2026] [security2:error] [pid 255769:tid 255966] [client 20.197.195.24:51805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/155.php"] [unique_id "al9LzrxMYwyVGnfuwsKUkwAAA-Y"]
[Tue Jul 21 07:37:02.218695 2026] [security2:error] [pid 255769:tid 255974] [client 20.226.60.151:27612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/k.php"] [unique_id "al9LzrxMYwyVGnfuwsKUlAAAA-4"]
[Tue Jul 21 07:37:02.233430 2026] [security2:error] [pid 255769:tid 255941] [client 20.151.10.161:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/j260624_13.php"] [unique_id "al9LzrxMYwyVGnfuwsKUlgAAA80"]
[Tue Jul 21 07:37:02.234495 2026] [security2:error] [pid 255769:tid 256021] [client 20.226.60.151:51299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xwpg.php"] [unique_id "al9LzrxMYwyVGnfuwsKUlwAABBs"]
[Tue Jul 21 07:37:02.355841 2026] [security2:error] [pid 254995:tid 255161] [client 20.206.105.145:38943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9Lzv7v0rlcEGmVraE62wAAA0I"]
[Tue Jul 21 07:37:02.374292 2026] [security2:error] [pid 254995:tid 255134] [client 85.204.70.100:53132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9Lzv7v0rlcEGmVraE63AAAAyc"]
[Tue Jul 21 07:37:02.426610 2026] [security2:error] [pid 254995:tid 255145] [client 20.197.195.24:13196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/goods.php"] [unique_id "al9Lzv7v0rlcEGmVraE63gAAAzI"]
[Tue Jul 21 07:37:02.499301 2026] [security2:error] [pid 255769:tid 255956] [client 20.197.195.24:51802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ops.php"] [unique_id "al9LzrxMYwyVGnfuwsKUnQAAA9w"]
[Tue Jul 21 07:37:02.565647 2026] [autoindex:error] [pid 254995:tid 255053] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:02.581119 2026] [security2:error] [pid 255769:tid 255934] [client 45.8.17.57:38173] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "al9LzrxMYwyVGnfuwsKUngAAA8Y"]
[Tue Jul 21 07:37:02.612502 2026] [security2:error] [pid 254995:tid 255263] [client 20.197.195.24:51736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/file31.php"] [unique_id "al9Lzv7v0rlcEGmVraE66wAAA40"]
[Tue Jul 21 07:37:02.759942 2026] [security2:error] [pid 254995:tid 255213] [client 85.204.70.100:42981] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Lzv7v0rlcEGmVraE7BgAAA3U"]
[Tue Jul 21 07:37:02.841701 2026] [security2:error] [pid 255769:tid 256014] [client 20.197.195.24:51720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/file6.php"] [unique_id "al9LzrxMYwyVGnfuwsKUoQAABBQ"]
[Tue Jul 21 07:37:02.921244 2026] [security2:error] [pid 254995:tid 255092] [remote 4.205.168.44:58076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/wp-login.php"] [unique_id "al9Lzf7v0rlcEGmVraE6zQADb2A"]
[Tue Jul 21 07:37:03.038340 2026] [security2:error] [pid 254995:tid 255256] [client 20.206.105.145:38943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/aaa.php"] [unique_id "al9Lz_7v0rlcEGmVraE7FAAAA4Y"]
[Tue Jul 21 07:37:03.042179 2026] [security2:error] [pid 254995:tid 255173] [client 20.104.96.117:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/v543.php"] [unique_id "al9Lz_7v0rlcEGmVraE7FQAAA04"]
[Tue Jul 21 07:37:03.116651 2026] [security2:error] [pid 254995:tid 255273] [client 20.206.105.145:38527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ppp.php"] [unique_id "al9Lz_7v0rlcEGmVraE7GwAAA5c"]
[Tue Jul 21 07:37:03.131453 2026] [security2:error] [pid 254995:tid 255177] [client 85.204.70.100:53156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Lz_7v0rlcEGmVraE7HAAAA1I"]
[Tue Jul 21 07:37:03.152678 2026] [security2:error] [pid 254995:tid 255194] [client 175.45.70.82:61404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lz_7v0rlcEGmVraE7HQAAA2M"]
[Tue Jul 21 07:37:03.152782 2026] [security2:error] [pid 254995:tid 255194] [client 175.45.70.82:61404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lz_7v0rlcEGmVraE7HQAAA2M"]
[Tue Jul 21 07:37:03.274733 2026] [security2:error] [pid 255769:tid 255984] [client 122.162.144.145:29071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Lz7xMYwyVGnfuwsKUpwAAA_g"]
[Tue Jul 21 07:37:03.274838 2026] [security2:error] [pid 255769:tid 255984] [client 122.162.144.145:29071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Lz7xMYwyVGnfuwsKUpwAAA_g"]
[Tue Jul 21 07:37:03.459537 2026] [autoindex:error] [pid 254995:tid 255254] [client 20.197.195.24:51837] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:03.469206 2026] [security2:error] [pid 254995:tid 255205] [client 20.197.195.24:51837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/adminfuns.php"] [unique_id "al9Lz_7v0rlcEGmVraE7KQAAA24"]
[Tue Jul 21 07:37:03.512604 2026] [security2:error] [pid 255769:tid 255977] [client 85.204.70.100:1254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Lz7xMYwyVGnfuwsKUqgAAA_E"]
[Tue Jul 21 07:37:03.748533 2026] [security2:error] [pid 255769:tid 255936] [client 154.192.233.199:58615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lz7xMYwyVGnfuwsKUrwAAA8g"]
[Tue Jul 21 07:37:03.748664 2026] [security2:error] [pid 255769:tid 255936] [client 154.192.233.199:58615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lz7xMYwyVGnfuwsKUrwAAA8g"]
[Tue Jul 21 07:37:03.814995 2026] [security2:error] [pid 254995:tid 255190] [client 103.106.20.201:50243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lz_7v0rlcEGmVraE7MAAAA18"]
[Tue Jul 21 07:37:03.815110 2026] [security2:error] [pid 254995:tid 255190] [client 103.106.20.201:50243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Lz_7v0rlcEGmVraE7MAAAA18"]
[Tue Jul 21 07:37:03.889349 2026] [security2:error] [pid 255769:tid 255965] [client 85.204.70.100:53200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9Lz7xMYwyVGnfuwsKUtgAAA-U"]
[Tue Jul 21 07:37:03.922548 2026] [autoindex:error] [pid 254995:tid 254996] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:03.932054 2026] [autoindex:error] [pid 254995:tid 255027] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:04.190924 2026] [security2:error] [pid 255769:tid 255833] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L0LxMYwyVGnfuwsKUvAAEGz8"]
[Tue Jul 21 07:37:04.191094 2026] [security2:error] [pid 255769:tid 256021] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L0LxMYwyVGnfuwsKUvAAEGz8"]
[Tue Jul 21 07:37:04.219748 2026] [security2:error] [pid 255769:tid 255959] [client 20.197.195.24:62862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/100.php"] [unique_id "al9L0LxMYwyVGnfuwsKUvgAAA98"]
[Tue Jul 21 07:37:04.226479 2026] [security2:error] [pid 255769:tid 256009] [client 20.104.96.117:59196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/sixxis.php"] [unique_id "al9L0LxMYwyVGnfuwsKUvwAABA8"]
[Tue Jul 21 07:37:04.273777 2026] [security2:error] [pid 255769:tid 255954] [client 85.204.70.100:53210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9L0LxMYwyVGnfuwsKUwQAAA9o"]
[Tue Jul 21 07:37:04.310594 2026] [security2:error] [pid 255769:tid 255836] [remote 185.115.217.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.217.115.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9L0LxMYwyVGnfuwsKUxAAD8kI"]
[Tue Jul 21 07:37:04.310784 2026] [security2:error] [pid 255769:tid 255978] [client 185.115.217.185:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9L0LxMYwyVGnfuwsKUxAAD8kI"]
[Tue Jul 21 07:37:04.480407 2026] [security2:error] [pid 255769:tid 255932] [client 20.206.105.145:37926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/201.php"] [unique_id "al9L0LxMYwyVGnfuwsKUyQAAA8Q"]
[Tue Jul 21 07:37:04.545741 2026] [security2:error] [pid 255769:tid 255972] [client 20.197.195.24:51836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/goods.php"] [unique_id "al9L0LxMYwyVGnfuwsKUzAAAA-w"]
[Tue Jul 21 07:37:04.645998 2026] [security2:error] [pid 255769:tid 255921] [client 85.204.70.100:53218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9L0LxMYwyVGnfuwsKUzgAAA7k"]
[Tue Jul 21 07:37:04.678057 2026] [security2:error] [pid 255769:tid 255923] [client 20.151.10.161:45965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/d62.php"] [unique_id "al9L0LxMYwyVGnfuwsKUzwAAA7s"]
[Tue Jul 21 07:37:05.032393 2026] [security2:error] [pid 255769:tid 255940] [client 85.204.70.100:53232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "okdbrasil.com.br.bililica.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9L0bxMYwyVGnfuwsKU2QAAA8w"]
[Tue Jul 21 07:37:05.100224 2026] [security2:error] [pid 255769:tid 256005] [client 20.226.60.151:27541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/blurbs.php"] [unique_id "al9L0bxMYwyVGnfuwsKU2gAABAs"]
[Tue Jul 21 07:37:05.159656 2026] [security2:error] [pid 255769:tid 255955] [client 122.164.127.47:53445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L0bxMYwyVGnfuwsKU3QAAA9s"]
[Tue Jul 21 07:37:05.159763 2026] [security2:error] [pid 255769:tid 255955] [client 122.164.127.47:53445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L0bxMYwyVGnfuwsKU3QAAA9s"]
[Tue Jul 21 07:37:05.237256 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.195.24:51747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/100.php"] [unique_id "al9L0bxMYwyVGnfuwsKU4AAABCI"]
[Tue Jul 21 07:37:05.333474 2026] [security2:error] [pid 254995:tid 255264] [client 173.252.95.7:41270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9L0f7v0rlcEGmVraE7bgAAA44"]
[Tue Jul 21 07:37:05.553458 2026] [security2:error] [pid 254995:tid 255152] [client 20.220.225.223:31190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/ops.php"] [unique_id "al9L0f7v0rlcEGmVraE7kQAAAzk"]
[Tue Jul 21 07:37:05.658018 2026] [security2:error] [pid 254995:tid 255149] [client 173.252.95.37:57544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9L0f7v0rlcEGmVraE7mwAAAzY"]
[Tue Jul 21 07:37:05.751630 2026] [security2:error] [pid 255769:tid 255910] [client 20.197.195.24:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/about.php"] [unique_id "al9L0bxMYwyVGnfuwsKU7AAAA64"]
[Tue Jul 21 07:37:05.757266 2026] [security2:error] [pid 255769:tid 256008] [client 20.206.105.145:38081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ops.php"] [unique_id "al9L0bxMYwyVGnfuwsKU7QAABA4"]
[Tue Jul 21 07:37:05.845633 2026] [security2:error] [pid 255769:tid 255929] [client 20.104.96.117:61146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ip.php"] [unique_id "al9L0bxMYwyVGnfuwsKU7gAAA8E"]
[Tue Jul 21 07:37:05.856196 2026] [security2:error] [pid 255769:tid 255919] [client 172.245.102.45:39807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Lz7xMYwyVGnfuwsKUrgAAA7c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:06.015159 2026] [security2:error] [pid 255769:tid 255959] [client 103.174.34.15:57619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L0rxMYwyVGnfuwsKU8QAAA98"]
[Tue Jul 21 07:37:06.015254 2026] [security2:error] [pid 255769:tid 255959] [client 103.174.34.15:57619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L0rxMYwyVGnfuwsKU8QAAA98"]
[Tue Jul 21 07:37:06.124334 2026] [autoindex:error] [pid 254995:tid 255101] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:06.136602 2026] [autoindex:error] [pid 254995:tid 255083] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/blocks/shortcode/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:06.165699 2026] [security2:error] [pid 255769:tid 255908] [client 20.226.60.151:27585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/bajah.php"] [unique_id "al9L0rxMYwyVGnfuwsKU9AAAA6w"]
[Tue Jul 21 07:37:06.219719 2026] [security2:error] [pid 255769:tid 255921] [client 20.151.10.161:46071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ups.php"] [unique_id "al9L0rxMYwyVGnfuwsKU9wAAA7k"]
[Tue Jul 21 07:37:06.238755 2026] [security2:error] [pid 254995:tid 255068] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L0v7v0rlcEGmVraE7sgADfkg"]
[Tue Jul 21 07:37:06.238889 2026] [security2:error] [pid 254995:tid 255222] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L0v7v0rlcEGmVraE7sgADfkg"]
[Tue Jul 21 07:37:06.346295 2026] [security2:error] [pid 255769:tid 256015] [client 45.8.17.121:31793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/bltm/wp-login.php"] [unique_id "al9L0bxMYwyVGnfuwsKU3gAABBU"]
[Tue Jul 21 07:37:06.526112 2026] [security2:error] [pid 255769:tid 255990] [client 20.197.195.24:51793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/about.php"] [unique_id "al9L0rxMYwyVGnfuwsKU_QAAA_4"]
[Tue Jul 21 07:37:06.713496 2026] [security2:error] [pid 255769:tid 255965] [client 20.197.195.24:51776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/admin.php"] [unique_id "al9L0rxMYwyVGnfuwsKVAQAAA-U"]
[Tue Jul 21 07:37:06.967239 2026] [security2:error] [pid 254995:tid 255127] [client 20.226.60.151:51304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ops.php"] [unique_id "al9L0v7v0rlcEGmVraE7vgAAAyA"]
[Tue Jul 21 07:37:07.236906 2026] [security2:error] [pid 255769:tid 255992] [client 20.104.96.117:61077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/kq1.php"] [unique_id "al9L07xMYwyVGnfuwsKVBwAAA_8"]
[Tue Jul 21 07:37:07.258119 2026] [security2:error] [pid 254995:tid 255184] [client 20.197.195.24:51714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/admin.php"] [unique_id "al9L0_7v0rlcEGmVraE7xAAAA1k"]
[Tue Jul 21 07:37:07.267822 2026] [security2:error] [pid 254995:tid 255055] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L0_7v0rlcEGmVraE7xQADbDs"]
[Tue Jul 21 07:37:07.268008 2026] [security2:error] [pid 254995:tid 255203] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L0_7v0rlcEGmVraE7xQADbDs"]
[Tue Jul 21 07:37:07.282042 2026] [autoindex:error] [pid 254995:tid 255044] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:07.336495 2026] [security2:error] [pid 254995:tid 255066] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L0_7v0rlcEGmVraE7yAADmUY"]
[Tue Jul 21 07:37:07.336634 2026] [security2:error] [pid 254995:tid 255275] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L0_7v0rlcEGmVraE7yAADmUY"]
[Tue Jul 21 07:37:07.370548 2026] [security2:error] [pid 254995:tid 255090] [remote 45.90.123.233:34526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "growe-ag.jaypi.com.br"] [uri "/wp-login.php"] [unique_id "al9L0_7v0rlcEGmVraE7yQADiV4"]
[Tue Jul 21 07:37:07.451889 2026] [security2:error] [pid 255769:tid 255944] [client 20.206.105.145:38473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ingfo.php"] [unique_id "al9L07xMYwyVGnfuwsKVDAAAA9A"]
[Tue Jul 21 07:37:07.573128 2026] [security2:error] [pid 255769:tid 255967] [client 45.8.17.122:35479] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/includes/nav.php"] [unique_id "al9L07xMYwyVGnfuwsKVEAAAA-c"]
[Tue Jul 21 07:37:07.617198 2026] [security2:error] [pid 255769:tid 255988] [client 82.102.28.107:34332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9L07xMYwyVGnfuwsKVEQAAA_w"]
[Tue Jul 21 07:37:07.617294 2026] [security2:error] [pid 255769:tid 255988] [client 82.102.28.107:34332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9L07xMYwyVGnfuwsKVEQAAA_w"]
[Tue Jul 21 07:37:07.619851 2026] [security2:error] [pid 255769:tid 255955] [client 59.96.220.140:58201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L07xMYwyVGnfuwsKVEgAAA9s"]
[Tue Jul 21 07:37:07.621363 2026] [security2:error] [pid 255769:tid 255955] [client 59.96.220.140:58201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L07xMYwyVGnfuwsKVEgAAA9s"]
[Tue Jul 21 07:37:07.641451 2026] [security2:error] [pid 254995:tid 255201] [client 20.220.225.223:31110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/term.php"] [unique_id "al9L0_7v0rlcEGmVraE7zgAAA2o"]
[Tue Jul 21 07:37:08.348252 2026] [security2:error] [pid 255769:tid 255921] [client 20.197.195.24:62417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/about.php"] [unique_id "al9L1LxMYwyVGnfuwsKVGwAAA7k"]
[Tue Jul 21 07:37:08.422604 2026] [security2:error] [pid 254995:tid 255145] [client 20.104.96.117:59177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9L1P7v0rlcEGmVraE71AAAAzI"]
[Tue Jul 21 07:37:08.465003 2026] [security2:error] [pid 255769:tid 255929] [client 103.86.117.203:53061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L1LxMYwyVGnfuwsKVHQAAA8E"]
[Tue Jul 21 07:37:08.465172 2026] [security2:error] [pid 255769:tid 255929] [client 103.86.117.203:53061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L1LxMYwyVGnfuwsKVHQAAA8E"]
[Tue Jul 21 07:37:08.476682 2026] [security2:error] [pid 255769:tid 255923] [client 20.226.60.151:27613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/a.php"] [unique_id "al9L1LxMYwyVGnfuwsKVHgAAA7s"]
[Tue Jul 21 07:37:08.492520 2026] [security2:error] [pid 255769:tid 255984] [client 45.8.17.123:65391] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/shell3.php"] [unique_id "al9L1LxMYwyVGnfuwsKVHwAAA_g"]
[Tue Jul 21 07:37:08.619902 2026] [security2:error] [pid 254995:tid 255149] [client 20.197.195.24:21037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/themes.php"] [unique_id "al9L1P7v0rlcEGmVraE72gAAAzY"]
[Tue Jul 21 07:37:08.953402 2026] [security2:error] [pid 255769:tid 255940] [client 20.220.225.223:49564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/tkikikoko.php"] [unique_id "al9L1LxMYwyVGnfuwsKVIwAAA8w"]
[Tue Jul 21 07:37:09.154799 2026] [security2:error] [pid 254995:tid 255274] [client 20.104.96.117:59684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/h02ugyh.php"] [unique_id "al9L1f7v0rlcEGmVraE74gAAA5g"]
[Tue Jul 21 07:37:09.284564 2026] [security2:error] [pid 254995:tid 255164] [client 20.226.60.151:51390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/mac.php"] [unique_id "al9L1f7v0rlcEGmVraE76QAAA0U"]
[Tue Jul 21 07:37:09.363618 2026] [security2:error] [pid 255769:tid 255983] [client 20.197.195.24:62863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/about.php"] [unique_id "al9L1bxMYwyVGnfuwsKVJgAAA_c"]
[Tue Jul 21 07:37:09.429796 2026] [security2:error] [pid 254995:tid 255222] [client 213.152.162.104:56142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9L1f7v0rlcEGmVraE77QAAA34"]
[Tue Jul 21 07:37:09.429898 2026] [security2:error] [pid 254995:tid 255222] [client 213.152.162.104:56142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9L1f7v0rlcEGmVraE77QAAA34"]
[Tue Jul 21 07:37:09.518611 2026] [security2:error] [pid 255769:tid 255985] [client 20.104.96.117:59159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-temp.php"] [unique_id "al9L1bxMYwyVGnfuwsKVKAAAA_k"]
[Tue Jul 21 07:37:09.557520 2026] [security2:error] [pid 255769:tid 256004] [client 45.251.232.145:64262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L1bxMYwyVGnfuwsKVKQAABAo"]
[Tue Jul 21 07:37:09.557617 2026] [security2:error] [pid 255769:tid 256004] [client 45.251.232.145:64262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L1bxMYwyVGnfuwsKVKQAABAo"]
[Tue Jul 21 07:37:09.666183 2026] [autoindex:error] [pid 254995:tid 255169] [client 20.197.195.24:51739] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:09.793553 2026] [security2:error] [pid 254995:tid 255158] [client 20.151.10.161:45954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/k.php"] [unique_id "al9L1f7v0rlcEGmVraE7_QAAAz8"]
[Tue Jul 21 07:37:09.912481 2026] [security2:error] [pid 255769:tid 255915] [client 139.167.225.182:62297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L1bxMYwyVGnfuwsKVKwAAA7M"]
[Tue Jul 21 07:37:09.912596 2026] [security2:error] [pid 255769:tid 255915] [client 139.167.225.182:62297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L1bxMYwyVGnfuwsKVKwAAA7M"]
[Tue Jul 21 07:37:09.926593 2026] [security2:error] [pid 255769:tid 255790] [remote 173.212.252.15:55992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9L1bxMYwyVGnfuwsKVLAADtBQ"]
[Tue Jul 21 07:37:09.974269 2026] [security2:error] [pid 254995:tid 255223] [client 45.8.17.63:33529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/hplfuns.php"] [unique_id "al9L1f7v0rlcEGmVraE8AwAAA38"]
[Tue Jul 21 07:37:09.982553 2026] [autoindex:error] [pid 254995:tid 255043] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:09.985274 2026] [autoindex:error] [pid 254995:tid 255084] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:10.016506 2026] [security2:error] [pid 255769:tid 255969] [client 20.220.225.223:49555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-Blogs.php"] [unique_id "al9L1rxMYwyVGnfuwsKVLgAAA-k"]
[Tue Jul 21 07:37:10.056363 2026] [security2:error] [pid 255769:tid 255902] [client 20.197.195.24:62857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/admin.php"] [unique_id "al9L1rxMYwyVGnfuwsKVMAAAA6Y"]
[Tue Jul 21 07:37:10.273510 2026] [security2:error] [pid 255769:tid 255910] [client 20.104.96.117:59700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9L1rxMYwyVGnfuwsKVNAAAA64"]
[Tue Jul 21 07:37:10.437767 2026] [security2:error] [pid 255769:tid 255997] [client 20.220.225.223:38667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/ah25.php"] [unique_id "al9L1rxMYwyVGnfuwsKVOgAABAM"]
[Tue Jul 21 07:37:10.462210 2026] [security2:error] [pid 255769:tid 255945] [client 20.197.195.24:62431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/admin.php"] [unique_id "al9L1rxMYwyVGnfuwsKVOwAAA9E"]
[Tue Jul 21 07:37:10.780825 2026] [security2:error] [pid 255769:tid 255927] [client 193.36.225.64:50385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9L1rxMYwyVGnfuwsKVPQAAA78"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:10.962671 2026] [autoindex:error] [pid 254995:tid 255042] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/blocks/shortcode/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:10.963276 2026] [autoindex:error] [pid 254995:tid 255025] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/codemirror/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:10.986977 2026] [security2:error] [pid 254995:tid 255185] [client 45.8.17.128:49035] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/admin/index.php"] [unique_id "al9L1v7v0rlcEGmVraE8FQAAA1o"]
[Tue Jul 21 07:37:11.047652 2026] [security2:error] [pid 255769:tid 255980] [client 20.197.195.24:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/themes.php"] [unique_id "al9L17xMYwyVGnfuwsKVRAAAA_Q"]
[Tue Jul 21 07:37:11.180913 2026] [security2:error] [pid 255769:tid 255932] [client 117.217.38.194:51216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L17xMYwyVGnfuwsKVRwAAA8Q"]
[Tue Jul 21 07:37:11.181047 2026] [security2:error] [pid 255769:tid 255932] [client 117.217.38.194:51216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L17xMYwyVGnfuwsKVRwAAA8Q"]
[Tue Jul 21 07:37:11.224669 2026] [security2:error] [pid 255769:tid 255918] [client 20.104.96.117:59142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9L17xMYwyVGnfuwsKVSgAAA7Y"]
[Tue Jul 21 07:37:11.242375 2026] [security2:error] [pid 255769:tid 255975] [client 20.226.60.151:51388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/mg.php"] [unique_id "al9L17xMYwyVGnfuwsKVTAAAA-8"]
[Tue Jul 21 07:37:11.309510 2026] [security2:error] [pid 254995:tid 255132] [client 117.251.86.144:54770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L1_7v0rlcEGmVraE8HQAAAyU"]
[Tue Jul 21 07:37:11.309608 2026] [security2:error] [pid 254995:tid 255132] [client 117.251.86.144:54770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L1_7v0rlcEGmVraE8HQAAAyU"]
[Tue Jul 21 07:37:11.361286 2026] [security2:error] [pid 254995:tid 255186] [client 173.24.185.52:55698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L1_7v0rlcEGmVraE8HgAAA1s"]
[Tue Jul 21 07:37:11.361420 2026] [security2:error] [pid 254995:tid 255186] [client 173.24.185.52:55698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L1_7v0rlcEGmVraE8HgAAA1s"]
[Tue Jul 21 07:37:11.497899 2026] [security2:error] [pid 255769:tid 255923] [client 103.162.129.114:54621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L17xMYwyVGnfuwsKVTgAAA7s"]
[Tue Jul 21 07:37:11.498057 2026] [security2:error] [pid 255769:tid 255923] [client 103.162.129.114:54621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L17xMYwyVGnfuwsKVTgAAA7s"]
[Tue Jul 21 07:37:11.659108 2026] [security2:error] [pid 254995:tid 255136] [client 20.226.60.151:27554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/edit.php"] [unique_id "al9L1_7v0rlcEGmVraE8JAAAAyk"]
[Tue Jul 21 07:37:11.699229 2026] [autoindex:error] [pid 254995:tid 255274] [client 20.197.195.24:62897] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:11.864790 2026] [security2:error] [pid 254995:tid 255156] [client 20.104.96.117:59147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/jj.php"] [unique_id "al9L1_7v0rlcEGmVraE8KgAAAz0"]
[Tue Jul 21 07:37:12.055405 2026] [security2:error] [pid 254995:tid 255263] [client 122.186.204.214:56483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L2P7v0rlcEGmVraE8LwAAA40"]
[Tue Jul 21 07:37:12.077564 2026] [security2:error] [pid 254995:tid 255263] [client 122.186.204.214:56483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L2P7v0rlcEGmVraE8LwAAA40"]
[Tue Jul 21 07:37:12.266363 2026] [security2:error] [pid 254995:tid 255215] [client 82.102.28.107:42150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9L2P7v0rlcEGmVraE8MwAAA3c"]
[Tue Jul 21 07:37:12.266455 2026] [security2:error] [pid 254995:tid 255215] [client 82.102.28.107:42150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9L2P7v0rlcEGmVraE8MwAAA3c"]
[Tue Jul 21 07:37:12.337074 2026] [security2:error] [pid 254995:tid 255277] [client 20.104.96.117:61154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9L2P7v0rlcEGmVraE8NgAAA5s"]
[Tue Jul 21 07:37:12.364293 2026] [security2:error] [pid 254995:tid 255076] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L2P7v0rlcEGmVraE8NwADklA"]
[Tue Jul 21 07:37:12.364468 2026] [security2:error] [pid 254995:tid 255268] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L2P7v0rlcEGmVraE8NwADklA"]
[Tue Jul 21 07:37:12.633730 2026] [security2:error] [pid 254995:tid 255117] [remote 124.55.178.99:48542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/wp-login.php"] [unique_id "al9L2P7v0rlcEGmVraE8PQADY3k"]
[Tue Jul 21 07:37:12.661195 2026] [security2:error] [pid 254995:tid 255214] [client 20.197.195.24:51739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/.well-known/about.php"] [unique_id "al9L2P7v0rlcEGmVraE8PgAAA3Y"]
[Tue Jul 21 07:37:12.763575 2026] [security2:error] [pid 255769:tid 255978] [client 20.206.105.145:37950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/error_log.php"] [unique_id "al9L2LxMYwyVGnfuwsKVXgAAA_I"]
[Tue Jul 21 07:37:12.794654 2026] [autoindex:error] [pid 254995:tid 255107] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:12.799190 2026] [security2:error] [pid 254995:tid 255019] [remote 207.180.241.245:45724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/wp-login.php"] [unique_id "al9L2P7v0rlcEGmVraE8QwADIhc"]
[Tue Jul 21 07:37:12.804369 2026] [autoindex:error] [pid 254995:tid 255072] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/plupload/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:13.009578 2026] [security2:error] [pid 255769:tid 255818] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2bxMYwyVGnfuwsKVYQAD_DA"]
[Tue Jul 21 07:37:13.009717 2026] [security2:error] [pid 255769:tid 255988] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2bxMYwyVGnfuwsKVYQAD_DA"]
[Tue Jul 21 07:37:13.066847 2026] [security2:error] [pid 254995:tid 255278] [client 20.104.96.117:61122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/txets.php"] [unique_id "al9L2f7v0rlcEGmVraE8SQAAA5w"]
[Tue Jul 21 07:37:13.072145 2026] [security2:error] [pid 255769:tid 255919] [client 20.220.225.223:38697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/8.php"] [unique_id "al9L2bxMYwyVGnfuwsKVYgAAA7c"]
[Tue Jul 21 07:37:13.177434 2026] [security2:error] [pid 254995:tid 255161] [client 45.8.17.48:55155] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/admin-wolf.php"] [unique_id "al9L2f7v0rlcEGmVraE8TQAAA0I"]
[Tue Jul 21 07:37:13.197606 2026] [security2:error] [pid 254995:tid 255185] [client 20.52.136.55:1589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/article.php"] [unique_id "al9L2f7v0rlcEGmVraE8TgAAA1o"]
[Tue Jul 21 07:37:13.332308 2026] [security2:error] [pid 254995:tid 255130] [client 20.197.195.24:62897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/.well-known/about.php"] [unique_id "al9L2f7v0rlcEGmVraE8UAAAAyM"]
[Tue Jul 21 07:37:13.427980 2026] [security2:error] [pid 255769:tid 255945] [client 20.104.96.117:59170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/dex.php"] [unique_id "al9L2bxMYwyVGnfuwsKVZQAAA9E"]
[Tue Jul 21 07:37:13.472868 2026] [security2:error] [pid 254995:tid 255173] [client 152.59.154.239:57219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2f7v0rlcEGmVraE8UwAAA04"]
[Tue Jul 21 07:37:13.473004 2026] [security2:error] [pid 254995:tid 255173] [client 152.59.154.239:57219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2f7v0rlcEGmVraE8UwAAA04"]
[Tue Jul 21 07:37:13.636891 2026] [security2:error] [pid 255769:tid 256025] [client 20.197.195.24:51748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9L2bxMYwyVGnfuwsKVZwAABB8"]
[Tue Jul 21 07:37:13.906186 2026] [security2:error] [pid 254995:tid 255156] [client 20.104.96.117:61128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/xpwer1.php"] [unique_id "al9L2f7v0rlcEGmVraE8XAAAAz0"]
[Tue Jul 21 07:37:13.961725 2026] [security2:error] [pid 255769:tid 255971] [client 175.45.70.82:61918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2bxMYwyVGnfuwsKVbgAAA-s"]
[Tue Jul 21 07:37:13.961853 2026] [security2:error] [pid 255769:tid 255971] [client 175.45.70.82:61918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2bxMYwyVGnfuwsKVbgAAA-s"]
[Tue Jul 21 07:37:13.967083 2026] [security2:error] [pid 255769:tid 255943] [client 20.197.195.24:62889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9L2bxMYwyVGnfuwsKVbwAAA88"]
[Tue Jul 21 07:37:14.038017 2026] [security2:error] [pid 254995:tid 255152] [client 122.162.144.145:19297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L2v7v0rlcEGmVraE8ZQAAAzk"]
[Tue Jul 21 07:37:14.038196 2026] [security2:error] [pid 254995:tid 255152] [client 122.162.144.145:19297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L2v7v0rlcEGmVraE8ZQAAAzk"]
[Tue Jul 21 07:37:14.073001 2026] [security2:error] [pid 254995:tid 255177] [client 45.8.17.135:56087] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "al9L2v7v0rlcEGmVraE8ZgAAA1I"]
[Tue Jul 21 07:37:14.076042 2026] [security2:error] [pid 254995:tid 255195] [client 20.151.10.161:46058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/k2.php"] [unique_id "al9L2v7v0rlcEGmVraE8ZwAAA2Q"]
[Tue Jul 21 07:37:14.340576 2026] [security2:error] [pid 255769:tid 255975] [client 20.197.195.24:62403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wefile.php"] [unique_id "al9L2rxMYwyVGnfuwsKVdgAAA-8"]
[Tue Jul 21 07:37:14.515991 2026] [security2:error] [pid 254995:tid 255143] [client 20.104.96.117:59679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/flox.php"] [unique_id "al9L2v7v0rlcEGmVraE8cAAAAzA"]
[Tue Jul 21 07:37:14.533014 2026] [security2:error] [pid 254995:tid 255147] [client 154.192.233.199:59925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2v7v0rlcEGmVraE8cQAAAzQ"]
[Tue Jul 21 07:37:14.533152 2026] [security2:error] [pid 254995:tid 255147] [client 154.192.233.199:59925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2v7v0rlcEGmVraE8cQAAAzQ"]
[Tue Jul 21 07:37:14.551425 2026] [security2:error] [pid 254995:tid 255180] [client 20.197.195.24:62860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9L2v7v0rlcEGmVraE8cgAAA1U"]
[Tue Jul 21 07:37:14.588993 2026] [security2:error] [pid 255769:tid 255984] [client 103.106.20.201:50826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2rxMYwyVGnfuwsKVdwAAA_g"]
[Tue Jul 21 07:37:14.589133 2026] [security2:error] [pid 255769:tid 255984] [client 103.106.20.201:50826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2rxMYwyVGnfuwsKVdwAAA_g"]
[Tue Jul 21 07:37:14.685477 2026] [security2:error] [pid 254995:tid 255131] [client 20.197.195.24:51740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wefile.php"] [unique_id "al9L2v7v0rlcEGmVraE8cwAAAyQ"]
[Tue Jul 21 07:37:14.697626 2026] [security2:error] [pid 254995:tid 255070] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2v7v0rlcEGmVraE8dAADf0o"]
[Tue Jul 21 07:37:14.697768 2026] [security2:error] [pid 254995:tid 255223] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L2v7v0rlcEGmVraE8dAADf0o"]
[Tue Jul 21 07:37:14.703347 2026] [autoindex:error] [pid 255769:tid 255923] [client 104.28.234.178:61991] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/conhecaonordeste.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:14.751888 2026] [autoindex:error] [pid 255769:tid 255906] [client 20.197.195.24:62901] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:14.810125 2026] [autoindex:error] [pid 255769:tid 255958] [client 20.197.195.24:62901] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:14.833488 2026] [security2:error] [pid 255769:tid 255937] [client 20.197.195.24:62901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9L2rxMYwyVGnfuwsKVfwAAA8k"]
[Tue Jul 21 07:37:14.841394 2026] [security2:error] [pid 254995:tid 255168] [client 20.220.225.223:48191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-css.php"] [unique_id "al9L2v7v0rlcEGmVraE8eQAAA0k"]
[Tue Jul 21 07:37:14.927426 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.195.24:62404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/8.php"] [unique_id "al9L2rxMYwyVGnfuwsKVgQAABCI"]
[Tue Jul 21 07:37:14.949130 2026] [security2:error] [pid 255769:tid 256021] [client 20.104.96.117:59694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/popo.php"] [unique_id "al9L2rxMYwyVGnfuwsKVhAAABBs"]
[Tue Jul 21 07:37:14.979310 2026] [security2:error] [pid 255769:tid 255916] [client 45.8.17.115:50243] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/2021/file.php"] [unique_id "al9L2rxMYwyVGnfuwsKVhQAAA7Q"]
[Tue Jul 21 07:37:15.077847 2026] [security2:error] [pid 255769:tid 255902] [client 20.226.60.151:51286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-post-data.php"] [unique_id "al9L27xMYwyVGnfuwsKVhwAAA6Y"]
[Tue Jul 21 07:37:15.124927 2026] [security2:error] [pid 254995:tid 255278] [client 20.197.195.24:51813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9L2_7v0rlcEGmVraE8gQAAA5w"]
[Tue Jul 21 07:37:15.463729 2026] [security2:error] [pid 255769:tid 255988] [client 20.104.96.117:61161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/yas.php"] [unique_id "al9L27xMYwyVGnfuwsKViwAAA_w"]
[Tue Jul 21 07:37:15.547530 2026] [security2:error] [pid 255769:tid 255930] [client 193.36.225.121:35797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9L27xMYwyVGnfuwsKVjQAAA8I"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:37:15.573631 2026] [security2:error] [pid 254995:tid 255165] [client 20.197.195.24:62879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-content/admin.php"] [unique_id "al9L2_7v0rlcEGmVraE8igAAA0Y"]
[Tue Jul 21 07:37:15.635007 2026] [security2:error] [pid 255769:tid 255956] [client 172.245.102.45:21267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9L27xMYwyVGnfuwsKVjgAAA9w"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:15.820506 2026] [security2:error] [pid 255769:tid 255959] [client 20.226.60.151:51323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/pucci.php"] [unique_id "al9L27xMYwyVGnfuwsKVjwAAA98"]
[Tue Jul 21 07:37:15.852079 2026] [security2:error] [pid 255769:tid 255945] [client 20.104.96.117:59139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/file61.php"] [unique_id "al9L27xMYwyVGnfuwsKVkAAAA9E"]
[Tue Jul 21 07:37:15.975527 2026] [security2:error] [pid 255769:tid 256014] [client 20.197.195.24:62866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/f6.php"] [unique_id "al9L27xMYwyVGnfuwsKVkQAABBQ"]
[Tue Jul 21 07:37:16.051769 2026] [security2:error] [pid 254995:tid 255185] [client 122.164.127.47:53950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L3P7v0rlcEGmVraE8kgAAA1o"]
[Tue Jul 21 07:37:16.051918 2026] [security2:error] [pid 254995:tid 255185] [client 122.164.127.47:53950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L3P7v0rlcEGmVraE8kgAAA1o"]
[Tue Jul 21 07:37:16.183263 2026] [security2:error] [pid 255769:tid 256016] [client 45.8.17.105:45303] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "al9L3LxMYwyVGnfuwsKVkwAABBY"]
[Tue Jul 21 07:37:16.251314 2026] [autoindex:error] [pid 255769:tid 255922] [client 20.197.195.24:51713] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:16.256040 2026] [security2:error] [pid 255769:tid 255943] [client 20.197.195.24:62890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/inputs.php"] [unique_id "al9L3LxMYwyVGnfuwsKVlQAAA88"]
[Tue Jul 21 07:37:16.306619 2026] [autoindex:error] [pid 255769:tid 256022] [client 20.197.195.24:51713] AH01276: Cannot serve directory /home3/equote29/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:16.341935 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:27544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/hosty.php"] [unique_id "al9L3LxMYwyVGnfuwsKVmQAAA_4"]
[Tue Jul 21 07:37:16.362712 2026] [security2:error] [pid 255769:tid 255946] [client 20.104.96.117:61171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/water.php"] [unique_id "al9L3LxMYwyVGnfuwsKVmgAAA9I"]
[Tue Jul 21 07:37:16.529667 2026] [security2:error] [pid 254995:tid 255164] [client 20.197.195.24:13246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/inputs.php"] [unique_id "al9L3P7v0rlcEGmVraE8mAAAA0U"]
[Tue Jul 21 07:37:16.763266 2026] [security2:error] [pid 255769:tid 255923] [client 20.197.195.24:51713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9L3LxMYwyVGnfuwsKVnQAAA7s"]
[Tue Jul 21 07:37:16.788469 2026] [security2:error] [pid 255769:tid 255835] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L3LxMYwyVGnfuwsKVnwAD-UE"]
[Tue Jul 21 07:37:16.788605 2026] [security2:error] [pid 255769:tid 255985] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L3LxMYwyVGnfuwsKVnwAD-UE"]
[Tue Jul 21 07:37:16.799573 2026] [security2:error] [pid 255769:tid 255937] [client 20.104.96.117:59189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/nano.php"] [unique_id "al9L3LxMYwyVGnfuwsKVoQAAA8k"]
[Tue Jul 21 07:37:16.886775 2026] [security2:error] [pid 255769:tid 256013] [client 20.226.60.151:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/black.php"] [unique_id "al9L3LxMYwyVGnfuwsKVogAABBM"]
[Tue Jul 21 07:37:16.930043 2026] [security2:error] [pid 255769:tid 255960] [client 20.206.105.145:37889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/xenon1337.php"] [unique_id "al9L3LxMYwyVGnfuwsKVowAAA-A"]
[Tue Jul 21 07:37:17.035398 2026] [security2:error] [pid 255769:tid 255941] [client 20.151.10.161:46057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/k3.php"] [unique_id "al9L3bxMYwyVGnfuwsKVpAAAA80"]
[Tue Jul 21 07:37:17.340239 2026] [security2:error] [pid 255769:tid 255978] [client 20.197.195.24:21098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/8.php"] [unique_id "al9L3bxMYwyVGnfuwsKVrAAAA_I"]
[Tue Jul 21 07:37:17.353903 2026] [security2:error] [pid 255769:tid 255961] [client 20.104.96.117:59165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/moon.php"] [unique_id "al9L3bxMYwyVGnfuwsKVrQAAA-E"]
[Tue Jul 21 07:37:17.386341 2026] [security2:error] [pid 255769:tid 255930] [client 45.8.17.108:65069] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "al9L3bxMYwyVGnfuwsKVrgAAA8I"]
[Tue Jul 21 07:37:17.426989 2026] [security2:error] [pid 254995:tid 255190] [client 20.197.195.24:62411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/classwithtostring.php"] [unique_id "al9L3f7v0rlcEGmVraE8pwAAA18"]
[Tue Jul 21 07:37:17.528765 2026] [security2:error] [pid 255769:tid 255858] [remote 124.55.178.99:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samilacalculos.com.br"] [uri "/wp-login.php"] [unique_id "al9L3bxMYwyVGnfuwsKVsQAD3Fg"]
[Tue Jul 21 07:37:17.575333 2026] [security2:error] [pid 254995:tid 255156] [client 103.174.34.15:58106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L3f7v0rlcEGmVraE8qAAAAz0"]
[Tue Jul 21 07:37:17.575432 2026] [security2:error] [pid 254995:tid 255156] [client 103.174.34.15:58106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L3f7v0rlcEGmVraE8qAAAAz0"]
[Tue Jul 21 07:37:17.685432 2026] [security2:error] [pid 254995:tid 255221] [client 20.197.195.24:51744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-content/admin.php"] [unique_id "al9L3f7v0rlcEGmVraE8rQAAA30"]
[Tue Jul 21 07:37:17.730522 2026] [security2:error] [pid 254995:tid 255184] [client 20.226.60.151:51382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/zlece.php"] [unique_id "al9L3f7v0rlcEGmVraE8rgAAA1k"]
[Tue Jul 21 07:37:17.829365 2026] [security2:error] [pid 254995:tid 255198] [client 20.197.195.24:51733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/f6.php"] [unique_id "al9L3f7v0rlcEGmVraE8sAAAA2c"]
[Tue Jul 21 07:37:17.888634 2026] [security2:error] [pid 254995:tid 255187] [client 20.197.195.24:51760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/inputs.php"] [unique_id "al9L3f7v0rlcEGmVraE8twAAA1w"]
[Tue Jul 21 07:37:17.949530 2026] [security2:error] [pid 254995:tid 255126] [client 20.104.96.117:61168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-info.php"] [unique_id "al9L3f7v0rlcEGmVraE8uQAAAx8"]
[Tue Jul 21 07:37:17.988810 2026] [security2:error] [pid 255769:tid 255808] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L3bxMYwyVGnfuwsKVtAAEAyY"]
[Tue Jul 21 07:37:17.989003 2026] [security2:error] [pid 255769:tid 255997] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L3bxMYwyVGnfuwsKVtAAEAyY"]
[Tue Jul 21 07:37:17.999729 2026] [security2:error] [pid 254995:tid 255278] [client 20.197.195.24:62408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9L3f7v0rlcEGmVraE8ugAAA5w"]
[Tue Jul 21 07:37:18.012857 2026] [security2:error] [pid 254995:tid 255264] [client 20.197.195.24:21119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/inputs.php"] [unique_id "al9L3v7v0rlcEGmVraE8uwAAA44"]
[Tue Jul 21 07:37:18.122958 2026] [security2:error] [pid 255769:tid 255921] [client 20.220.225.223:38682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9L3rxMYwyVGnfuwsKVtgAAA7k"]
[Tue Jul 21 07:37:18.161278 2026] [security2:error] [pid 254995:tid 255197] [client 20.197.195.24:51726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/classwithtostring.php"] [unique_id "al9L3v7v0rlcEGmVraE8vwAAA2Y"]
[Tue Jul 21 07:37:18.204941 2026] [security2:error] [pid 255769:tid 256015] [client 213.152.162.104:54814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9L3rxMYwyVGnfuwsKVuQAABBU"]
[Tue Jul 21 07:37:18.205056 2026] [security2:error] [pid 255769:tid 256015] [client 213.152.162.104:54814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9L3rxMYwyVGnfuwsKVuQAABBU"]
[Tue Jul 21 07:37:18.222112 2026] [security2:error] [pid 254995:tid 255088] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L3v7v0rlcEGmVraE8wgADIVw"]
[Tue Jul 21 07:37:18.222242 2026] [security2:error] [pid 254995:tid 255128] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L3v7v0rlcEGmVraE8wgADIVw"]
[Tue Jul 21 07:37:18.472240 2026] [security2:error] [pid 255769:tid 255932] [client 20.197.195.24:51789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9L3rxMYwyVGnfuwsKVvAAAA8Q"]
[Tue Jul 21 07:37:18.475955 2026] [security2:error] [pid 255769:tid 255940] [client 45.8.17.57:39033] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/xml.php"] [unique_id "al9L3rxMYwyVGnfuwsKVvQAAA8w"]
[Tue Jul 21 07:37:18.519584 2026] [security2:error] [pid 255769:tid 255918] [client 20.226.60.151:51334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/vssrs.php"] [unique_id "al9L3rxMYwyVGnfuwsKVvgAAA7Y"]
[Tue Jul 21 07:37:18.591245 2026] [security2:error] [pid 255769:tid 255975] [client 20.220.225.223:38698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/ee.php"] [unique_id "al9L3rxMYwyVGnfuwsKVvwAAA-8"]
[Tue Jul 21 07:37:18.610738 2026] [security2:error] [pid 255769:tid 256005] [client 20.197.195.24:51795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-blog.php"] [unique_id "al9L3rxMYwyVGnfuwsKVwAAABAs"]
[Tue Jul 21 07:37:18.667219 2026] [security2:error] [pid 254995:tid 255265] [client 74.7.241.135:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.sugar-delete.online"] [uri "/index.php"] [unique_id "al9L3v7v0rlcEGmVraE8wAAAA48"]
[Tue Jul 21 07:37:18.673649 2026] [security2:error] [pid 254995:tid 255133] [client 74.7.241.135:35880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.sugar-delete.online"] [uri "/robots.txt"] [unique_id "al9L3v7v0rlcEGmVraE8vQADJgw"]
[Tue Jul 21 07:37:18.675599 2026] [autoindex:error] [pid 255769:tid 256004] [client 20.197.195.24:51800] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:18.686429 2026] [security2:error] [pid 255769:tid 255964] [client 20.197.195.24:51800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-content/admin.php"] [unique_id "al9L3rxMYwyVGnfuwsKVxwAAA-Q"]
[Tue Jul 21 07:37:18.753990 2026] [security2:error] [pid 255769:tid 255945] [client 59.96.220.140:58713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L3rxMYwyVGnfuwsKVygAAA9E"]
[Tue Jul 21 07:37:18.754692 2026] [security2:error] [pid 255769:tid 255945] [client 59.96.220.140:58713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L3rxMYwyVGnfuwsKVygAAA9E"]
[Tue Jul 21 07:37:18.809510 2026] [security2:error] [pid 255769:tid 255938] [client 20.104.96.117:61132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/2000.php"] [unique_id "al9L3rxMYwyVGnfuwsKVzAAAA8o"]
[Tue Jul 21 07:37:18.882212 2026] [security2:error] [pid 255769:tid 255974] [client 20.197.195.24:51749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ms-edit.php"] [unique_id "al9L3rxMYwyVGnfuwsKVzgAAA-4"]
[Tue Jul 21 07:37:18.940544 2026] [security2:error] [pid 254995:tid 255138] [client 103.86.117.203:53577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L3v7v0rlcEGmVraE8zAAAAys"]
[Tue Jul 21 07:37:18.940641 2026] [security2:error] [pid 254995:tid 255138] [client 103.86.117.203:53577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L3v7v0rlcEGmVraE8zAAAAys"]
[Tue Jul 21 07:37:18.963658 2026] [security2:error] [pid 255769:tid 255925] [client 20.197.195.24:21071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/cgi-bin/index.php"] [unique_id "al9L3rxMYwyVGnfuwsKV0QAAA70"]
[Tue Jul 21 07:37:18.994630 2026] [autoindex:error] [pid 255769:tid 255988] [client 20.197.195.24:51832] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:19.037738 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:61198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wicked.php"] [unique_id "al9L3_7v0rlcEGmVraE8zgAAA5c"]
[Tue Jul 21 07:37:19.052348 2026] [security2:error] [pid 255769:tid 255919] [client 20.197.195.24:51832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/BDKR28WP.php"] [unique_id "al9L37xMYwyVGnfuwsKV1wAAA7c"]
[Tue Jul 21 07:37:19.115057 2026] [security2:error] [pid 255769:tid 255976] [client 20.197.195.24:62426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-blog.php"] [unique_id "al9L37xMYwyVGnfuwsKV2gAAA_A"]
[Tue Jul 21 07:37:19.116883 2026] [security2:error] [pid 255769:tid 255942] [client 74.7.241.135:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sugar-delete.online"] [uri "/index.php"] [unique_id "al9L37xMYwyVGnfuwsKV2AAAA84"], referer: https://www.sugar-delete.online/robots.txt
[Tue Jul 21 07:37:19.117749 2026] [security2:error] [pid 254995:tid 255212] [client 74.7.241.135:35884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sugar-delete.online"] [uri "/robots.txt"] [unique_id "al9L3_7v0rlcEGmVraE8zwADdAc"], referer: https://www.sugar-delete.online/robots.txt
[Tue Jul 21 07:37:19.124223 2026] [autoindex:error] [pid 255769:tid 255909] [client 20.197.195.24:51835] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:19.180312 2026] [security2:error] [pid 255769:tid 255908] [client 20.151.10.161:45959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/k4.php"] [unique_id "al9L37xMYwyVGnfuwsKV3gAAA6w"]
[Tue Jul 21 07:37:19.242147 2026] [autoindex:error] [pid 255769:tid 256015] [client 20.197.195.24:51835] AH01276: Cannot serve directory /home3/equote29/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:19.247569 2026] [security2:error] [pid 255769:tid 256016] [client 20.197.195.24:51835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/abcd.php"] [unique_id "al9L37xMYwyVGnfuwsKV4AAABBY"]
[Tue Jul 21 07:37:19.380771 2026] [security2:error] [pid 254995:tid 255255] [client 45.8.17.116:28725] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-conflg/function.php"] [unique_id "al9L3_7v0rlcEGmVraE81gAAA4U"]
[Tue Jul 21 07:37:19.389619 2026] [security2:error] [pid 255769:tid 255927] [client 136.144.33.29:56333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9L37xMYwyVGnfuwsKV5AAAA78"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:19.404742 2026] [security2:error] [pid 255769:tid 256022] [client 20.226.60.151:51277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/24.php"] [unique_id "al9L37xMYwyVGnfuwsKV5QAABBw"]
[Tue Jul 21 07:37:19.478808 2026] [security2:error] [pid 254995:tid 255222] [client 20.197.195.24:51827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/file15.php"] [unique_id "al9L3_7v0rlcEGmVraE81wAAA34"]
[Tue Jul 21 07:37:19.625306 2026] [security2:error] [pid 254995:tid 255147] [client 20.104.96.117:59180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/122.php"] [unique_id "al9L3_7v0rlcEGmVraE82wAAAzQ"]
[Tue Jul 21 07:37:19.771071 2026] [autoindex:error] [pid 254995:tid 255223] [client 20.197.195.24:62856] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:19.781138 2026] [security2:error] [pid 254995:tid 255194] [client 20.197.195.24:62856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-content/admin.php"] [unique_id "al9L3_7v0rlcEGmVraE84QAAA2M"]
[Tue Jul 21 07:37:20.009945 2026] [security2:error] [pid 255769:tid 255945] [client 20.197.195.24:51715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/jp.php"] [unique_id "al9L4LxMYwyVGnfuwsKV7wAAA9E"]
[Tue Jul 21 07:37:20.031496 2026] [security2:error] [pid 255769:tid 256012] [client 45.251.232.145:64787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L4LxMYwyVGnfuwsKV8AAABBI"]
[Tue Jul 21 07:37:20.031623 2026] [security2:error] [pid 255769:tid 256012] [client 45.251.232.145:64787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L4LxMYwyVGnfuwsKV8AAABBI"]
[Tue Jul 21 07:37:20.036863 2026] [security2:error] [pid 254995:tid 255259] [client 193.36.225.141:57207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9L3f7v0rlcEGmVraE8tAAAA4k"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:37:20.101186 2026] [security2:error] [pid 255769:tid 255974] [client 82.102.28.107:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.28.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9L4LxMYwyVGnfuwsKV8gAAA-4"]
[Tue Jul 21 07:37:20.101281 2026] [security2:error] [pid 255769:tid 255974] [client 82.102.28.107:54356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9L4LxMYwyVGnfuwsKV8gAAA-4"]
[Tue Jul 21 07:37:20.135785 2026] [security2:error] [pid 255769:tid 256000] [client 20.197.195.24:62884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ms-edit.php"] [unique_id "al9L4LxMYwyVGnfuwsKV8wAABAY"]
[Tue Jul 21 07:37:20.174296 2026] [security2:error] [pid 254995:tid 255125] [client 20.104.96.117:59658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/mds.php"] [unique_id "al9L4P7v0rlcEGmVraE86AAAAx4"]
[Tue Jul 21 07:37:20.375074 2026] [security2:error] [pid 255769:tid 255978] [client 20.226.60.151:61017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xacs.php"] [unique_id "al9L4LxMYwyVGnfuwsKV9gAAA_I"]
[Tue Jul 21 07:37:20.463455 2026] [security2:error] [pid 255769:tid 255976] [client 20.206.105.145:37909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/test11.php"] [unique_id "al9L4LxMYwyVGnfuwsKV-AAAA_A"]
[Tue Jul 21 07:37:20.553198 2026] [security2:error] [pid 255769:tid 255983] [client 74.7.230.20:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.trab.giovanoniadv.com.br"] [uri "/index.php"] [unique_id "al9L37xMYwyVGnfuwsKV6AAAA_c"]
[Tue Jul 21 07:37:20.553884 2026] [security2:error] [pid 255769:tid 255932] [client 74.7.230.20:42916] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.trab.giovanoniadv.com.br"] [uri "/robots.txt"] [unique_id "al9L37xMYwyVGnfuwsKV5wADxEY"]
[Tue Jul 21 07:37:20.619839 2026] [security2:error] [pid 255769:tid 256015] [client 20.197.195.24:51785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/f35.php"] [unique_id "al9L4LxMYwyVGnfuwsKV_QAABBU"]
[Tue Jul 21 07:37:20.665832 2026] [security2:error] [pid 255769:tid 256006] [client 20.151.10.161:45922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/k5.php"] [unique_id "al9L4LxMYwyVGnfuwsKV_gAABAw"]
[Tue Jul 21 07:37:20.732802 2026] [security2:error] [pid 255769:tid 255922] [client 20.197.195.24:51768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-load.php"] [unique_id "al9L4LxMYwyVGnfuwsKV_wAAA7o"]
[Tue Jul 21 07:37:20.788557 2026] [security2:error] [pid 255769:tid 255943] [client 20.197.195.24:62402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/cgi-bin/index.php"] [unique_id "al9L4LxMYwyVGnfuwsKWAgAAA88"]
[Tue Jul 21 07:37:20.849003 2026] [autoindex:error] [pid 255769:tid 255777] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:20.853050 2026] [autoindex:error] [pid 255769:tid 255894] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/blocks/calendar/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:20.874809 2026] [security2:error] [pid 255769:tid 255926] [client 139.167.225.182:62941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L4LxMYwyVGnfuwsKWBQAAA74"]
[Tue Jul 21 07:37:20.874909 2026] [security2:error] [pid 255769:tid 255926] [client 139.167.225.182:62941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L4LxMYwyVGnfuwsKWBQAAA74"]
[Tue Jul 21 07:37:20.967777 2026] [security2:error] [pid 255769:tid 255946] [client 20.104.96.117:61126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-blink.php"] [unique_id "al9L4LxMYwyVGnfuwsKWCAAAA9I"]
[Tue Jul 21 07:37:20.971285 2026] [security2:error] [pid 255769:tid 255918] [client 45.8.17.123:25369] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/network_xo.php"] [unique_id "al9L4LxMYwyVGnfuwsKWCQAAA7Y"]
[Tue Jul 21 07:37:21.164895 2026] [security2:error] [pid 255769:tid 256020] [client 20.197.195.24:51754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/xyn.php"] [unique_id "al9L4bxMYwyVGnfuwsKWDAAABBo"]
[Tue Jul 21 07:37:21.174481 2026] [security2:error] [pid 255769:tid 255962] [client 74.7.230.20:42932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "trab.giovanoniadv.com.br"] [uri "/robots.txt"] [unique_id "al9L4bxMYwyVGnfuwsKWCwAD4i4"], referer: https://www.trab.giovanoniadv.com.br/robots.txt
[Tue Jul 21 07:37:21.318223 2026] [security2:error] [pid 255769:tid 256021] [client 213.152.162.104:59154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9L4bxMYwyVGnfuwsKWEQAABBs"]
[Tue Jul 21 07:37:21.318315 2026] [security2:error] [pid 255769:tid 256021] [client 213.152.162.104:59154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9L4bxMYwyVGnfuwsKWEQAABBs"]
[Tue Jul 21 07:37:21.325150 2026] [autoindex:error] [pid 255769:tid 255931] [client 20.197.195.24:62868] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:21.373095 2026] [security2:error] [pid 255769:tid 255947] [client 20.197.195.24:62868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/BDKR28WP.php"] [unique_id "al9L4bxMYwyVGnfuwsKWEwAAA9M"]
[Tue Jul 21 07:37:21.437707 2026] [security2:error] [pid 255769:tid 256013] [client 20.220.225.223:51496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-Blogs.php"] [unique_id "al9L4bxMYwyVGnfuwsKWFQAABBM"]
[Tue Jul 21 07:37:21.618209 2026] [security2:error] [pid 254995:tid 255144] [client 20.226.60.151:51380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/zildan.php"] [unique_id "al9L4f7v0rlcEGmVraE8-wAAAzE"]
[Tue Jul 21 07:37:21.665781 2026] [security2:error] [pid 255769:tid 255975] [client 117.217.38.194:51737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L4bxMYwyVGnfuwsKWGQAAA-8"]
[Tue Jul 21 07:37:21.665961 2026] [security2:error] [pid 255769:tid 255975] [client 117.217.38.194:51737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L4bxMYwyVGnfuwsKWGQAAA-8"]
[Tue Jul 21 07:37:21.678809 2026] [autoindex:error] [pid 254995:tid 255132] [client 20.197.195.24:21057] AH01276: Cannot serve directory /home3/equote29/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:21.762085 2026] [autoindex:error] [pid 254995:tid 255186] [client 20.197.195.24:21057] AH01276: Cannot serve directory /home3/equote29/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:21.767133 2026] [security2:error] [pid 254995:tid 255208] [client 20.197.195.24:21057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ccc.php"] [unique_id "al9L4f7v0rlcEGmVraE8_wAAA3A"]
[Tue Jul 21 07:37:21.796057 2026] [security2:error] [pid 254995:tid 255265] [client 20.151.10.161:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/w.php"] [unique_id "al9L4f7v0rlcEGmVraE9AAAAA48"]
[Tue Jul 21 07:37:21.883029 2026] [security2:error] [pid 255769:tid 255917] [client 45.8.17.59:48789] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/sitemaps/"] [unique_id "al9L4bxMYwyVGnfuwsKWGgAAA7U"]
[Tue Jul 21 07:37:21.889741 2026] [security2:error] [pid 255769:tid 255985] [client 173.24.185.52:56165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L4bxMYwyVGnfuwsKWGwAAA_k"]
[Tue Jul 21 07:37:21.889846 2026] [security2:error] [pid 255769:tid 255985] [client 173.24.185.52:56165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L4bxMYwyVGnfuwsKWGwAAA_k"]
[Tue Jul 21 07:37:22.193314 2026] [security2:error] [pid 254995:tid 255269] [client 117.251.86.144:43792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L4v7v0rlcEGmVraE9CAAAA5M"]
[Tue Jul 21 07:37:22.193431 2026] [security2:error] [pid 254995:tid 255269] [client 117.251.86.144:43792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L4v7v0rlcEGmVraE9CAAAA5M"]
[Tue Jul 21 07:37:22.297347 2026] [autoindex:error] [pid 255769:tid 255932] [client 20.197.195.24:62898] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:22.317693 2026] [autoindex:error] [pid 255769:tid 255929] [client 20.197.195.24:62898] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:22.322267 2026] [security2:error] [pid 255769:tid 256015] [client 20.151.10.161:46022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/fpwch.php"] [unique_id "al9L4rxMYwyVGnfuwsKWIwAABBU"]
[Tue Jul 21 07:37:22.342875 2026] [security2:error] [pid 255769:tid 256016] [client 20.197.195.24:62898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/abcd.php"] [unique_id "al9L4rxMYwyVGnfuwsKWJAAABBY"]
[Tue Jul 21 07:37:22.466044 2026] [security2:error] [pid 255769:tid 255922] [client 20.220.225.223:49853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-explorer.php"] [unique_id "al9L4rxMYwyVGnfuwsKWJQAAA7o"]
[Tue Jul 21 07:37:22.474244 2026] [security2:error] [pid 254995:tid 255178] [client 20.104.96.117:61165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/zc-208.php"] [unique_id "al9L4v7v0rlcEGmVraE9DQAAA1M"]
[Tue Jul 21 07:37:22.568354 2026] [security2:error] [pid 254995:tid 255255] [client 20.226.60.151:61190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/csa.php"] [unique_id "al9L4v7v0rlcEGmVraE9DgAAA4U"]
[Tue Jul 21 07:37:22.578846 2026] [security2:error] [pid 254995:tid 255148] [client 20.197.195.24:20998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/w.php"] [unique_id "al9L4v7v0rlcEGmVraE9DwAAAzU"]
[Tue Jul 21 07:37:22.854514 2026] [security2:error] [pid 255769:tid 255892] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L4rxMYwyVGnfuwsKWKQAD0Ho"]
[Tue Jul 21 07:37:22.854662 2026] [security2:error] [pid 255769:tid 255944] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L4rxMYwyVGnfuwsKWKQAD0Ho"]
[Tue Jul 21 07:37:22.872980 2026] [security2:error] [pid 255769:tid 255926] [client 20.197.195.24:51745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9L4rxMYwyVGnfuwsKWKgAAA74"]
[Tue Jul 21 07:37:22.972613 2026] [security2:error] [pid 254995:tid 255212] [client 103.162.129.114:55081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L4v7v0rlcEGmVraE9GAAAA3Q"]
[Tue Jul 21 07:37:22.972730 2026] [security2:error] [pid 254995:tid 255212] [client 103.162.129.114:55081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L4v7v0rlcEGmVraE9GAAAA3Q"]
[Tue Jul 21 07:37:22.995078 2026] [security2:error] [pid 255769:tid 256022] [client 20.197.195.24:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file15.php"] [unique_id "al9L4rxMYwyVGnfuwsKWKwAABBw"]
[Tue Jul 21 07:37:22.999094 2026] [security2:error] [pid 255769:tid 255940] [client 20.104.96.117:59686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/sid4.php"] [unique_id "al9L4rxMYwyVGnfuwsKWLAAAA8w"]
[Tue Jul 21 07:37:23.075610 2026] [security2:error] [pid 255769:tid 255953] [client 45.8.17.117:63733] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/pomo/index.php"] [unique_id "al9L47xMYwyVGnfuwsKWLwAAA9k"]
[Tue Jul 21 07:37:23.115587 2026] [security2:error] [pid 255769:tid 255911] [client 20.206.105.145:38086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/koala.php"] [unique_id "al9L47xMYwyVGnfuwsKWMAAAA68"]
[Tue Jul 21 07:37:23.211368 2026] [security2:error] [pid 255769:tid 255965] [client 20.197.195.24:51732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/FWAZ.php"] [unique_id "al9L47xMYwyVGnfuwsKWNAAAA-U"]
[Tue Jul 21 07:37:23.227841 2026] [security2:error] [pid 255769:tid 255979] [client 122.186.204.214:57017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L47xMYwyVGnfuwsKWNQAAA_M"]
[Tue Jul 21 07:37:23.227959 2026] [security2:error] [pid 255769:tid 255979] [client 122.186.204.214:57017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L47xMYwyVGnfuwsKWNQAAA_M"]
[Tue Jul 21 07:37:23.327865 2026] [security2:error] [pid 255769:tid 255984] [client 107.189.6.149:58031] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "portalrepercutnews.com.br"] [uri "/"] [unique_id "al9L47xMYwyVGnfuwsKWOAAAA_g"]
[Tue Jul 21 07:37:23.332396 2026] [autoindex:error] [pid 255769:tid 255822] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/codemirror/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:23.332707 2026] [autoindex:error] [pid 255769:tid 255852] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:23.483063 2026] [security2:error] [pid 254995:tid 255213] [client 136.144.33.101:39193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9L4_7v0rlcEGmVraE9HAAAA3U"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:23.523611 2026] [security2:error] [pid 254995:tid 255209] [client 107.189.6.149:58030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "portalrepercutnews.com.br"] [uri "/"] [unique_id "al9L4_7v0rlcEGmVraE9HgAAA3E"]
[Tue Jul 21 07:37:23.722555 2026] [security2:error] [pid 255769:tid 255996] [client 20.197.195.24:62909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/jp.php"] [unique_id "al9L47xMYwyVGnfuwsKWPgAABAI"]
[Tue Jul 21 07:37:23.724702 2026] [security2:error] [pid 254995:tid 255198] [client 107.189.6.149:58088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "portalrepercutnews.com.br"] [uri "/"] [unique_id "al9L4_7v0rlcEGmVraE9IgAAA2c"]
[Tue Jul 21 07:37:23.735469 2026] [security2:error] [pid 255769:tid 255773] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L47xMYwyVGnfuwsKWQQAD0wM"]
[Tue Jul 21 07:37:23.735673 2026] [security2:error] [pid 255769:tid 255947] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L47xMYwyVGnfuwsKWQQAD0wM"]
[Tue Jul 21 07:37:23.751366 2026] [autoindex:error] [pid 255769:tid 255778] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/js/plupload/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:23.752948 2026] [autoindex:error] [pid 255769:tid 255872] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:23.858867 2026] [security2:error] [pid 255769:tid 255969] [client 34.91.119.153:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.barcob.com"] [uri "/"] [unique_id "al9L47xMYwyVGnfuwsKWRQAAA-k"]
[Tue Jul 21 07:37:23.858965 2026] [security2:error] [pid 255769:tid 255969] [client 34.91.119.153:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.barcob.com"] [uri "/"] [unique_id "al9L47xMYwyVGnfuwsKWRQAAA-k"]
[Tue Jul 21 07:37:23.926567 2026] [security2:error] [pid 255769:tid 255902] [client 35.226.57.170:56758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "adifarmabella.com"] [uri "/"] [unique_id "al9L47xMYwyVGnfuwsKWRgAAA6Y"]
[Tue Jul 21 07:37:23.951222 2026] [security2:error] [pid 254995:tid 255211] [client 20.197.195.24:51809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/miru1.php"] [unique_id "al9L4_7v0rlcEGmVraE9JQAAA3M"]
[Tue Jul 21 07:37:23.966582 2026] [security2:error] [pid 255769:tid 255983] [client 20.151.10.161:46062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/w2025.php"] [unique_id "al9L47xMYwyVGnfuwsKWRwAAA_c"]
[Tue Jul 21 07:37:24.017798 2026] [security2:error] [pid 255769:tid 255942] [client 20.104.96.117:59199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wmore1.php"] [unique_id "al9L5LxMYwyVGnfuwsKWSAAAA84"]
[Tue Jul 21 07:37:24.112853 2026] [security2:error] [pid 255769:tid 255909] [client 107.189.6.149:58120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "portalrepercutnews.com.br"] [uri "/"] [unique_id "al9L5LxMYwyVGnfuwsKWSwAAA60"]
[Tue Jul 21 07:37:24.174351 2026] [security2:error] [pid 255769:tid 255943] [client 45.8.17.112:20821] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/plugins/revslider/includes/external/page/"] [unique_id "al9L5LxMYwyVGnfuwsKWTQAAA88"]
[Tue Jul 21 07:37:24.193728 2026] [security2:error] [pid 255769:tid 255908] [client 20.197.195.24:62446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/f35.php"] [unique_id "al9L5LxMYwyVGnfuwsKWTgAAA6w"]
[Tue Jul 21 07:37:24.209370 2026] [security2:error] [pid 255769:tid 255992] [client 20.226.60.151:51358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/w3llscc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWTwAAA_8"]
[Tue Jul 21 07:37:24.242900 2026] [autoindex:error] [pid 255769:tid 255829] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/blocks/calendar/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:24.257368 2026] [security2:error] [pid 255769:tid 255990] [client 20.197.195.24:62420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-load.php"] [unique_id "al9L5LxMYwyVGnfuwsKWVAAAA_4"]
[Tue Jul 21 07:37:24.269924 2026] [security2:error] [pid 255769:tid 255940] [client 20.197.195.24:62895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/xyn.php"] [unique_id "al9L5LxMYwyVGnfuwsKWVQAAA8w"]
[Tue Jul 21 07:37:24.286138 2026] [security2:error] [pid 255769:tid 255889] [remote 97.74.93.24:35940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-login.php"] [unique_id "al9L5LxMYwyVGnfuwsKWVwADo3c"]
[Tue Jul 21 07:37:24.332434 2026] [autoindex:error] [pid 255769:tid 255923] [client 20.197.195.24:62441] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:24.395704 2026] [autoindex:error] [pid 255769:tid 255906] [client 20.197.195.24:62441] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:24.401096 2026] [security2:error] [pid 255769:tid 255952] [client 20.197.195.24:62441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ccc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWXAAAA9g"]
[Tue Jul 21 07:37:24.439275 2026] [security2:error] [pid 255769:tid 256004] [client 20.197.195.24:62434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/w.php"] [unique_id "al9L5LxMYwyVGnfuwsKWXQAABAo"]
[Tue Jul 21 07:37:24.492905 2026] [security2:error] [pid 255769:tid 255965] [client 20.197.195.24:51820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/aa.php"] [unique_id "al9L5LxMYwyVGnfuwsKWYAAAA-U"]
[Tue Jul 21 07:37:24.519685 2026] [security2:error] [pid 255769:tid 255946] [client 185.213.175.37:50398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "applarifo.com.br"] [uri "/tabela.php"] [unique_id "al9L5LxMYwyVGnfuwsKWYgAAA9I"]
[Tue Jul 21 07:37:24.543539 2026] [security2:error] [pid 255769:tid 255931] [client 20.197.195.24:62908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9L5LxMYwyVGnfuwsKWZAAAA8M"]
[Tue Jul 21 07:37:24.563643 2026] [security2:error] [pid 255769:tid 255976] [client 175.45.70.82:62431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWZgAAA_A"]
[Tue Jul 21 07:37:24.563759 2026] [security2:error] [pid 255769:tid 255976] [client 175.45.70.82:62431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWZgAAA_A"]
[Tue Jul 21 07:37:24.773215 2026] [security2:error] [pid 255769:tid 255903] [client 20.52.136.55:1765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/bootstrap.php"] [unique_id "al9L5LxMYwyVGnfuwsKWbQAAA6c"]
[Tue Jul 21 07:37:24.789259 2026] [security2:error] [pid 255769:tid 255975] [client 20.197.195.24:62410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/FWAZ.php"] [unique_id "al9L5LxMYwyVGnfuwsKWbgAAA-8"]
[Tue Jul 21 07:37:24.812066 2026] [security2:error] [pid 255769:tid 255956] [client 152.59.154.239:57715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWbwAAA9w"]
[Tue Jul 21 07:37:24.812188 2026] [security2:error] [pid 255769:tid 255956] [client 152.59.154.239:57715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWbwAAA9w"]
[Tue Jul 21 07:37:24.891873 2026] [security2:error] [pid 255769:tid 255935] [client 20.197.195.24:51716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/122.php"] [unique_id "al9L5LxMYwyVGnfuwsKWcQAAA8c"]
[Tue Jul 21 07:37:24.909101 2026] [security2:error] [pid 255769:tid 255997] [client 20.197.195.24:62871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/miru1.php"] [unique_id "al9L5LxMYwyVGnfuwsKWcgAABAM"]
[Tue Jul 21 07:37:24.937623 2026] [security2:error] [pid 255769:tid 255968] [client 122.162.144.145:26937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWcwAAA-g"]
[Tue Jul 21 07:37:24.937727 2026] [security2:error] [pid 255769:tid 255968] [client 122.162.144.145:26937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWcwAAA-g"]
[Tue Jul 21 07:37:24.941529 2026] [security2:error] [pid 255769:tid 255907] [client 74.7.230.29:38242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "admin.powerflats.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9L5LxMYwyVGnfuwsKWdAADqwo"]
[Tue Jul 21 07:37:24.948533 2026] [autoindex:error] [pid 254995:tid 255031] [remote 74.7.241.53:37634] AH01276: Cannot serve directory /home4/fabi0417/admin.powerflats.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:24.997598 2026] [security2:error] [pid 255769:tid 255901] [client 109.248.148.246:49000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWdQAAA6U"]
[Tue Jul 21 07:37:24.997736 2026] [security2:error] [pid 255769:tid 255901] [client 109.248.148.246:49000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9L5LxMYwyVGnfuwsKWdQAAA6U"]
[Tue Jul 21 07:37:25.015970 2026] [security2:error] [pid 255769:tid 255919] [client 20.220.225.223:31220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/red.php"] [unique_id "al9L5bxMYwyVGnfuwsKWdgAAA7c"]
[Tue Jul 21 07:37:25.028663 2026] [autoindex:error] [pid 255769:tid 255850] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:25.036478 2026] [autoindex:error] [pid 255769:tid 255891] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/languages/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:25.130648 2026] [security2:error] [pid 255769:tid 255908] [client 20.197.195.24:13197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/aa.php"] [unique_id "al9L5bxMYwyVGnfuwsKWewAAA6w"]
[Tue Jul 21 07:37:25.216038 2026] [security2:error] [pid 255769:tid 255779] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5bxMYwyVGnfuwsKWgAAD6wk"]
[Tue Jul 21 07:37:25.216187 2026] [security2:error] [pid 255769:tid 255971] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5bxMYwyVGnfuwsKWgAAD6wk"]
[Tue Jul 21 07:37:25.260447 2026] [security2:error] [pid 254995:tid 255179] [client 154.192.233.199:60508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5f7v0rlcEGmVraE9PwAAA1Q"]
[Tue Jul 21 07:37:25.260595 2026] [security2:error] [pid 254995:tid 255179] [client 154.192.233.199:60508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5f7v0rlcEGmVraE9PwAAA1Q"]
[Tue Jul 21 07:37:25.318211 2026] [security2:error] [pid 254995:tid 255136] [client 20.226.60.151:51267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wpx.php"] [unique_id "al9L5f7v0rlcEGmVraE9RAAAAyk"]
[Tue Jul 21 07:37:25.318485 2026] [security2:error] [pid 255769:tid 256000] [client 103.106.20.201:51413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5bxMYwyVGnfuwsKWgQAABAY"]
[Tue Jul 21 07:37:25.319187 2026] [security2:error] [pid 255769:tid 256000] [client 103.106.20.201:51413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5bxMYwyVGnfuwsKWgQAABAY"]
[Tue Jul 21 07:37:25.579460 2026] [security2:error] [pid 254995:tid 255191] [client 45.8.17.64:21745] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "al9L5f7v0rlcEGmVraE9SgAAA2A"]
[Tue Jul 21 07:37:25.650624 2026] [security2:error] [pid 254995:tid 255217] [client 20.220.225.223:48166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-css.php"] [unique_id "al9L5f7v0rlcEGmVraE9TgAAA3k"]
[Tue Jul 21 07:37:25.701128 2026] [security2:error] [pid 255769:tid 255979] [client 20.226.60.151:27371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/k.php"] [unique_id "al9L5bxMYwyVGnfuwsKWhAAAA_M"]
[Tue Jul 21 07:37:25.714234 2026] [security2:error] [pid 254995:tid 255164] [client 20.206.105.145:38487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/mac.php"] [unique_id "al9L5f7v0rlcEGmVraE9TwAAA0U"]
[Tue Jul 21 07:37:25.767187 2026] [security2:error] [pid 254995:tid 255190] [client 20.197.195.24:62437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/122.php"] [unique_id "al9L5f7v0rlcEGmVraE9UAAAA18"]
[Tue Jul 21 07:37:25.999600 2026] [autoindex:error] [pid 255769:tid 255823] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:26.014223 2026] [security2:error] [pid 255769:tid 255903] [client 20.151.10.161:46060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/scxy.php"] [unique_id "al9L5rxMYwyVGnfuwsKWjgAAA6c"]
[Tue Jul 21 07:37:26.014712 2026] [security2:error] [pid 255769:tid 255937] [client 20.197.195.24:51779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/get.php"] [unique_id "al9L5rxMYwyVGnfuwsKWjwAAA8k"]
[Tue Jul 21 07:37:26.103766 2026] [security2:error] [pid 254995:tid 255206] [client 20.197.195.24:62854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/get.php"] [unique_id "al9L5v7v0rlcEGmVraE9WQAAA28"]
[Tue Jul 21 07:37:26.137507 2026] [security2:error] [pid 255769:tid 255955] [client 49.47.154.42:55907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.154.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiadeoferta.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5bxMYwyVGnfuwsKWfAAAA9s"]
[Tue Jul 21 07:37:26.137710 2026] [security2:error] [pid 255769:tid 255955] [client 49.47.154.42:55907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "guiadeoferta.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5bxMYwyVGnfuwsKWfAAAA9s"]
[Tue Jul 21 07:37:26.326175 2026] [security2:error] [pid 255769:tid 256028] [client 122.164.127.47:54457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L5rxMYwyVGnfuwsKWkwAABCI"]
[Tue Jul 21 07:37:26.326282 2026] [security2:error] [pid 255769:tid 256028] [client 122.164.127.47:54457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L5rxMYwyVGnfuwsKWkwAABCI"]
[Tue Jul 21 07:37:26.371097 2026] [security2:error] [pid 255769:tid 256009] [client 20.197.195.24:51752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/as.php"] [unique_id "al9L5rxMYwyVGnfuwsKWlAAABA8"]
[Tue Jul 21 07:37:26.384099 2026] [security2:error] [pid 254995:tid 255129] [client 20.104.96.117:59677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/solo1.php"] [unique_id "al9L5v7v0rlcEGmVraE9XwAAAyI"]
[Tue Jul 21 07:37:26.385067 2026] [security2:error] [pid 254995:tid 255260] [client 20.197.195.24:62861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/as.php"] [unique_id "al9L5v7v0rlcEGmVraE9YAAAA4o"]
[Tue Jul 21 07:37:26.492005 2026] [security2:error] [pid 255769:tid 255942] [client 20.226.60.151:61203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-css.php"] [unique_id "al9L5rxMYwyVGnfuwsKWlQAAA84"]
[Tue Jul 21 07:37:26.574827 2026] [security2:error] [pid 255769:tid 255784] [remote 104.207.32.246:63573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.32.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9L5rxMYwyVGnfuwsKWlwAD4Q4"]
[Tue Jul 21 07:37:26.683999 2026] [security2:error] [pid 255769:tid 255982] [client 45.8.17.145:20425] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/nrhogjyecktixbal0fnt5Cakc.php"] [unique_id "al9L5rxMYwyVGnfuwsKWngAAA_Y"]
[Tue Jul 21 07:37:26.777384 2026] [security2:error] [pid 255769:tid 255996] [client 103.177.242.200:64921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.242.177.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiferreira.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5rxMYwyVGnfuwsKWrQAABAI"]
[Tue Jul 21 07:37:26.777507 2026] [security2:error] [pid 255769:tid 255996] [client 103.177.242.200:64921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "guiferreira.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5rxMYwyVGnfuwsKWrQAABAI"]
[Tue Jul 21 07:37:26.881597 2026] [security2:error] [pid 255769:tid 256025] [client 20.197.195.24:62905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ccou.php"] [unique_id "al9L5rxMYwyVGnfuwsKWrwAABB8"]
[Tue Jul 21 07:37:27.028431 2026] [security2:error] [pid 254995:tid 255176] [client 20.206.105.145:38464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9L5_7v0rlcEGmVraE9agAAA1E"]
[Tue Jul 21 07:37:27.190991 2026] [autoindex:error] [pid 255769:tid 255930] [client 16.163.108.56:0] AH01276: Cannot serve directory /home2/senatr95/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:27.192178 2026] [security2:error] [pid 255769:tid 255930] [client 16.163.108.56:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "senatruckdiesel.com.br"] [uri "/cgi-sys/403.html"] [unique_id "al9L57xMYwyVGnfuwsKW2QAAA8I"]
[Tue Jul 21 07:37:27.192800 2026] [security2:error] [pid 255769:tid 255980] [client 16.163.108.56:52886] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "senatruckdiesel.com.br"] [uri "/"] [unique_id "al9L57xMYwyVGnfuwsKW1gAAA_Q"]
[Tue Jul 21 07:37:27.519919 2026] [security2:error] [pid 254995:tid 255156] [client 103.174.34.15:58586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5_7v0rlcEGmVraE9egAAAz0"]
[Tue Jul 21 07:37:27.520058 2026] [security2:error] [pid 254995:tid 255156] [client 103.174.34.15:58586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L5_7v0rlcEGmVraE9egAAAz0"]
[Tue Jul 21 07:37:27.599970 2026] [security2:error] [pid 255769:tid 255961] [client 20.220.225.223:38673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/fffm.php"] [unique_id "al9L57xMYwyVGnfuwsKXBgAAA-E"]
[Tue Jul 21 07:37:27.645077 2026] [security2:error] [pid 255769:tid 255943] [client 20.197.195.24:51757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ccou.php"] [unique_id "al9L57xMYwyVGnfuwsKXBwAAA88"]
[Tue Jul 21 07:37:27.778295 2026] [security2:error] [pid 254995:tid 255178] [client 45.8.17.60:62635] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-trackback.php"] [unique_id "al9L5_7v0rlcEGmVraE9gQAAA1M"]
[Tue Jul 21 07:37:27.782652 2026] [security2:error] [pid 254995:tid 255151] [client 20.151.10.161:46068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/FWAZ.php"] [unique_id "al9L5_7v0rlcEGmVraE9ggAAAzg"]
[Tue Jul 21 07:37:27.855415 2026] [security2:error] [pid 255769:tid 256000] [client 20.104.96.117:59683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/cong.php"] [unique_id "al9L57xMYwyVGnfuwsKXGwAABAY"]
[Tue Jul 21 07:37:28.117967 2026] [security2:error] [pid 255769:tid 256021] [client 20.226.60.151:51287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ho.php"] [unique_id "al9L6LxMYwyVGnfuwsKXKAAABBs"]
[Tue Jul 21 07:37:28.295368 2026] [core:error] [pid 255769:tid 255776] [remote 52.167.144.232:64872] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:37:28.295394 2026] [core:error] [pid 255769:tid 255776] [remote 52.167.144.232:64872] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:37:28.385200 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.195.24:51742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/w3lls.php"] [unique_id "al9L6LxMYwyVGnfuwsKXOwAABCI"]
[Tue Jul 21 07:37:28.399401 2026] [security2:error] [pid 255769:tid 256020] [client 20.197.195.24:63651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/w3lls.php"] [unique_id "al9L6LxMYwyVGnfuwsKXPAAABBo"]
[Tue Jul 21 07:37:28.436223 2026] [security2:error] [pid 255769:tid 255983] [client 20.220.225.223:49804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/akismet.php"] [unique_id "al9L6LxMYwyVGnfuwsKXPQAAA_c"]
[Tue Jul 21 07:37:28.465327 2026] [security2:error] [pid 255769:tid 255907] [client 20.104.96.117:59192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/public/css.php"] [unique_id "al9L6LxMYwyVGnfuwsKXQQAAA6s"]
[Tue Jul 21 07:37:28.534701 2026] [security2:error] [pid 254995:tid 255221] [client 193.36.225.68:63433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9L6P7v0rlcEGmVraE9hwAAA30"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:28.551955 2026] [security2:error] [pid 255769:tid 256012] [client 20.151.10.161:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/qterm.php"] [unique_id "al9L6LxMYwyVGnfuwsKXSAAABBI"]
[Tue Jul 21 07:37:28.657402 2026] [security2:error] [pid 255769:tid 255863] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L6LxMYwyVGnfuwsKXUAAED10"]
[Tue Jul 21 07:37:28.657521 2026] [security2:error] [pid 255769:tid 256009] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L6LxMYwyVGnfuwsKXUAAED10"]
[Tue Jul 21 07:37:28.764331 2026] [security2:error] [pid 255769:tid 255923] [client 20.220.225.223:38700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/blue.php"] [unique_id "al9L6LxMYwyVGnfuwsKXWAAAA7s"]
[Tue Jul 21 07:37:28.834116 2026] [security2:error] [pid 255769:tid 255833] [remote 104.207.35.166:27173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.35.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9L6LxMYwyVGnfuwsKXUwADvT8"]
[Tue Jul 21 07:37:28.881755 2026] [security2:error] [pid 255769:tid 255807] [remote 41.186.86.12:21414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colegioperseveranca.com"] [uri "/wp-login.php"] [unique_id "al9L6LxMYwyVGnfuwsKXWgADtSU"]
[Tue Jul 21 07:37:28.885880 2026] [security2:error] [pid 255769:tid 255804] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L6LxMYwyVGnfuwsKXWwAD_CI"]
[Tue Jul 21 07:37:28.885988 2026] [security2:error] [pid 255769:tid 255988] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L6LxMYwyVGnfuwsKXWwAD_CI"]
[Tue Jul 21 07:37:28.950604 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.195.24:51769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/test1.php"] [unique_id "al9L6LxMYwyVGnfuwsKXXQAABAU"]
[Tue Jul 21 07:37:28.989871 2026] [security2:error] [pid 255769:tid 255936] [client 20.206.105.145:38515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wefile.php"] [unique_id "al9L6LxMYwyVGnfuwsKXYAAAA8g"]
[Tue Jul 21 07:37:29.082662 2026] [security2:error] [pid 255769:tid 255973] [client 20.220.225.223:48140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/wp-explorer.php"] [unique_id "al9L6bxMYwyVGnfuwsKXcgAAA-0"]
[Tue Jul 21 07:37:29.136760 2026] [security2:error] [pid 254995:tid 255066] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L6f7v0rlcEGmVraE9lAADdUY"]
[Tue Jul 21 07:37:29.136883 2026] [security2:error] [pid 254995:tid 255213] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L6f7v0rlcEGmVraE9lAADdUY"]
[Tue Jul 21 07:37:29.403837 2026] [security2:error] [pid 255769:tid 256019] [client 20.197.195.24:21095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/database.php"] [unique_id "al9L6bxMYwyVGnfuwsKXfgAABBk"]
[Tue Jul 21 07:37:29.411607 2026] [security2:error] [pid 255769:tid 256012] [client 20.104.96.117:59650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/output.php"] [unique_id "al9L6bxMYwyVGnfuwsKXhAAABBI"]
[Tue Jul 21 07:37:29.426903 2026] [security2:error] [pid 254995:tid 255212] [client 103.86.117.203:54100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L6f7v0rlcEGmVraE9mwAAA3Q"]
[Tue Jul 21 07:37:29.427013 2026] [security2:error] [pid 254995:tid 255212] [client 103.86.117.203:54100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L6f7v0rlcEGmVraE9mwAAA3Q"]
[Tue Jul 21 07:37:29.676016 2026] [security2:error] [pid 255769:tid 255996] [client 45.8.17.148:24627] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/ty.php"] [unique_id "al9L6bxMYwyVGnfuwsKXjAAABAI"]
[Tue Jul 21 07:37:29.840225 2026] [security2:error] [pid 255769:tid 255921] [client 20.151.10.161:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/blurbs.php"] [unique_id "al9L6bxMYwyVGnfuwsKXlQAAA7k"]
[Tue Jul 21 07:37:29.894370 2026] [autoindex:error] [pid 255769:tid 256000] [client 20.206.105.145:37939] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:30.041973 2026] [security2:error] [pid 255769:tid 255917] [client 20.104.96.117:61138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-file-120.php"] [unique_id "al9L6rxMYwyVGnfuwsKXngAAA7U"]
[Tue Jul 21 07:37:30.081295 2026] [autoindex:error] [pid 255769:tid 255993] [client 20.206.105.145:37939] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:30.092302 2026] [security2:error] [pid 255769:tid 255999] [client 20.206.105.145:37939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9L6rxMYwyVGnfuwsKXoQAABAU"]
[Tue Jul 21 07:37:30.223880 2026] [security2:error] [pid 254995:tid 255186] [client 20.220.225.223:49851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/akismet.php"] [unique_id "al9L6v7v0rlcEGmVraE9qAAAA1s"]
[Tue Jul 21 07:37:30.283055 2026] [security2:error] [pid 254995:tid 255265] [client 20.197.195.24:51771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/file.php"] [unique_id "al9L6v7v0rlcEGmVraE9qQAAA48"]
[Tue Jul 21 07:37:30.353972 2026] [security2:error] [pid 254995:tid 255257] [client 20.151.10.161:46049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/v543.php"] [unique_id "al9L6v7v0rlcEGmVraE9qwAAA4c"]
[Tue Jul 21 07:37:30.411060 2026] [security2:error] [pid 255769:tid 255958] [client 20.197.195.24:63624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/test1.php"] [unique_id "al9L6rxMYwyVGnfuwsKXpwAAA94"]
[Tue Jul 21 07:37:30.509996 2026] [security2:error] [pid 255769:tid 255905] [client 45.251.232.145:65314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L6rxMYwyVGnfuwsKXqgAAA6k"]
[Tue Jul 21 07:37:30.510151 2026] [security2:error] [pid 255769:tid 255905] [client 45.251.232.145:65314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L6rxMYwyVGnfuwsKXqgAAA6k"]
[Tue Jul 21 07:37:30.741348 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.195.24:51717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/file.php"] [unique_id "al9L6rxMYwyVGnfuwsKX1AAAA7Y"]
[Tue Jul 21 07:37:30.762414 2026] [security2:error] [pid 255769:tid 255935] [client 20.104.96.117:61120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/special.php"] [unique_id "al9L6rxMYwyVGnfuwsKX1QAAA8c"]
[Tue Jul 21 07:37:30.934037 2026] [autoindex:error] [pid 255769:tid 255776] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/languages/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:30.982091 2026] [security2:error] [pid 255769:tid 255964] [client 139.167.225.182:63581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L6rxMYwyVGnfuwsKX2gAAA-Q"]
[Tue Jul 21 07:37:30.982193 2026] [security2:error] [pid 255769:tid 255964] [client 139.167.225.182:63581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L6rxMYwyVGnfuwsKX2gAAA-Q"]
[Tue Jul 21 07:37:31.222571 2026] [security2:error] [pid 255769:tid 256006] [client 20.151.10.161:46026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/w3lls.php"] [unique_id "al9L67xMYwyVGnfuwsKX3gAABAw"]
[Tue Jul 21 07:37:31.243339 2026] [security2:error] [pid 255769:tid 255959] [client 20.226.60.151:51295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xy.php"] [unique_id "al9L67xMYwyVGnfuwsKX3wAAA98"]
[Tue Jul 21 07:37:31.458771 2026] [security2:error] [pid 255769:tid 255859] [remote 202.51.202.242:48588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9L67xMYwyVGnfuwsKX5gAD-Vk"]
[Tue Jul 21 07:37:31.542976 2026] [security2:error] [pid 254995:tid 255195] [client 20.104.96.117:61134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/as.php"] [unique_id "al9L6_7v0rlcEGmVraE9vAAAA2Q"]
[Tue Jul 21 07:37:31.584162 2026] [security2:error] [pid 255769:tid 255917] [client 45.8.17.139:40709] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/default.php"] [unique_id "al9L67xMYwyVGnfuwsKX6QAAA7U"]
[Tue Jul 21 07:37:31.637121 2026] [security2:error] [pid 254995:tid 255222] [client 20.197.195.24:51772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/777.php"] [unique_id "al9L6_7v0rlcEGmVraE9vQAAA34"]
[Tue Jul 21 07:37:31.649603 2026] [security2:error] [pid 255769:tid 255988] [client 20.197.195.24:63662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/database.php"] [unique_id "al9L67xMYwyVGnfuwsKX6gAAA_w"]
[Tue Jul 21 07:37:31.768531 2026] [security2:error] [pid 254995:tid 255148] [client 20.206.105.145:38507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/2P.php"] [unique_id "al9L6_7v0rlcEGmVraE9vwAAAzU"]
[Tue Jul 21 07:37:31.780156 2026] [security2:error] [pid 255769:tid 255916] [client 20.151.10.161:46024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-ws68.php"] [unique_id "al9L67xMYwyVGnfuwsKX7wAAA7Q"]
[Tue Jul 21 07:37:31.965046 2026] [security2:error] [pid 254995:tid 255217] [client 20.104.96.117:59154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9L6_7v0rlcEGmVraE9wQAAA3k"]
[Tue Jul 21 07:37:32.103827 2026] [security2:error] [pid 255769:tid 255931] [client 20.197.195.24:51790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ssixta.php"] [unique_id "al9L7LxMYwyVGnfuwsKX8gAAA8M"]
[Tue Jul 21 07:37:32.146091 2026] [security2:error] [pid 255769:tid 256003] [client 117.217.38.194:52239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7LxMYwyVGnfuwsKX8wAABAk"]
[Tue Jul 21 07:37:32.146470 2026] [security2:error] [pid 255769:tid 256003] [client 117.217.38.194:52239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7LxMYwyVGnfuwsKX8wAABAk"]
[Tue Jul 21 07:37:32.281515 2026] [security2:error] [pid 254995:tid 255194] [client 59.96.220.140:59541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L7P7v0rlcEGmVraE9yAAAA2M"]
[Tue Jul 21 07:37:32.281635 2026] [security2:error] [pid 254995:tid 255194] [client 59.96.220.140:59541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L7P7v0rlcEGmVraE9yAAAA2M"]
[Tue Jul 21 07:37:32.326270 2026] [security2:error] [pid 255769:tid 255932] [client 136.144.33.112:37401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9L7LxMYwyVGnfuwsKX9QAAA8Q"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:32.344626 2026] [security2:error] [pid 254995:tid 255084] [remote 38.242.157.30:40806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9L7P7v0rlcEGmVraE9ygADRVg"]
[Tue Jul 21 07:37:32.378546 2026] [security2:error] [pid 254995:tid 255155] [client 45.8.17.113:48793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/SimplePie/font-editor.php"] [unique_id "al9L7P7v0rlcEGmVraE9zAAAAzw"]
[Tue Jul 21 07:37:32.454069 2026] [security2:error] [pid 255769:tid 255997] [client 173.24.185.52:56634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L7LxMYwyVGnfuwsKX9wAABAM"]
[Tue Jul 21 07:37:32.454235 2026] [security2:error] [pid 255769:tid 255997] [client 173.24.185.52:56634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L7LxMYwyVGnfuwsKX9wAABAM"]
[Tue Jul 21 07:37:32.480564 2026] [security2:error] [pid 255769:tid 255937] [client 20.104.96.117:61121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/w1px.php"] [unique_id "al9L7LxMYwyVGnfuwsKX-AAAA8k"]
[Tue Jul 21 07:37:32.694506 2026] [core:alert] [pid 254995:tid 255214] [client 57.141.18.46:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:37:32.820909 2026] [security2:error] [pid 254995:tid 255225] [client 20.226.60.151:51270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/loader.php"] [unique_id "al9L7P7v0rlcEGmVraE92AAAA4E"]
[Tue Jul 21 07:37:32.883799 2026] [security2:error] [pid 254995:tid 255204] [client 20.151.10.161:46030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xyn.php"] [unique_id "al9L7P7v0rlcEGmVraE92gAAA20"]
[Tue Jul 21 07:37:32.884583 2026] [security2:error] [pid 254995:tid 255143] [client 117.251.86.144:36992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L7P7v0rlcEGmVraE92QAAAzA"]
[Tue Jul 21 07:37:32.884734 2026] [security2:error] [pid 254995:tid 255143] [client 117.251.86.144:36992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L7P7v0rlcEGmVraE92QAAAzA"]
[Tue Jul 21 07:37:32.889216 2026] [security2:error] [pid 254995:tid 255264] [client 20.104.96.117:61081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/yawa.php"] [unique_id "al9L7P7v0rlcEGmVraE92wAAA44"]
[Tue Jul 21 07:37:32.890895 2026] [autoindex:error] [pid 255769:tid 255863] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:32.925319 2026] [security2:error] [pid 254995:tid 255140] [client 20.197.195.24:21102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/1c.php"] [unique_id "al9L7P7v0rlcEGmVraE93AAAAy0"]
[Tue Jul 21 07:37:33.084272 2026] [security2:error] [pid 254995:tid 255256] [client 103.162.129.114:55503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L7f7v0rlcEGmVraE94QAAA4Y"]
[Tue Jul 21 07:37:33.084414 2026] [security2:error] [pid 254995:tid 255256] [client 103.162.129.114:55503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L7f7v0rlcEGmVraE94QAAA4Y"]
[Tue Jul 21 07:37:33.177173 2026] [security2:error] [pid 254995:tid 255208] [client 45.8.17.121:54239] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "al9L7f7v0rlcEGmVraE94gAAA3A"]
[Tue Jul 21 07:37:33.258042 2026] [security2:error] [pid 254995:tid 255170] [client 20.197.195.24:63308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file.php"] [unique_id "al9L7f7v0rlcEGmVraE95wAAA0s"]
[Tue Jul 21 07:37:33.468132 2026] [security2:error] [pid 254995:tid 255133] [client 20.104.96.117:59166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/js.php"] [unique_id "al9L7f7v0rlcEGmVraE96wAAAyY"]
[Tue Jul 21 07:37:33.493316 2026] [security2:error] [pid 254995:tid 255193] [client 122.186.204.214:57538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L7f7v0rlcEGmVraE97AAAA2I"]
[Tue Jul 21 07:37:33.493444 2026] [security2:error] [pid 254995:tid 255193] [client 122.186.204.214:57538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L7f7v0rlcEGmVraE97AAAA2I"]
[Tue Jul 21 07:37:33.735527 2026] [security2:error] [pid 255769:tid 256006] [client 20.197.195.24:51784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/test2.php"] [unique_id "al9L7bxMYwyVGnfuwsKYBAAABAw"]
[Tue Jul 21 07:37:33.822490 2026] [security2:error] [pid 254995:tid 255062] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L7f7v0rlcEGmVraE9_AADWkI"]
[Tue Jul 21 07:37:33.822598 2026] [security2:error] [pid 254995:tid 255185] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L7f7v0rlcEGmVraE9_AADWkI"]
[Tue Jul 21 07:37:33.834473 2026] [security2:error] [pid 254995:tid 255215] [client 20.151.10.161:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/green3.php"] [unique_id "al9L7f7v0rlcEGmVraE9_QAAA3c"]
[Tue Jul 21 07:37:33.898696 2026] [security2:error] [pid 255769:tid 256000] [client 20.197.195.24:63631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file.php"] [unique_id "al9L7bxMYwyVGnfuwsKYEgAABAY"]
[Tue Jul 21 07:37:33.942395 2026] [security2:error] [pid 255769:tid 255934] [client 20.104.96.117:59181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/core.php"] [unique_id "al9L7bxMYwyVGnfuwsKYEwAAA8Y"]
[Tue Jul 21 07:37:34.020101 2026] [security2:error] [pid 255769:tid 255988] [client 20.197.195.24:51799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/buy.php"] [unique_id "al9L7rxMYwyVGnfuwsKYFQAAA_w"]
[Tue Jul 21 07:37:34.176142 2026] [security2:error] [pid 255769:tid 255939] [client 45.8.17.147:42781] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al9L7rxMYwyVGnfuwsKYGwAAA8s"]
[Tue Jul 21 07:37:34.372715 2026] [autoindex:error] [pid 255769:tid 255864] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/languages/themes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:34.422190 2026] [security2:error] [pid 255769:tid 255954] [client 20.220.225.223:49792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ace2.php"] [unique_id "al9L7rxMYwyVGnfuwsKYLAAAA9o"]
[Tue Jul 21 07:37:34.460959 2026] [security2:error] [pid 255769:tid 255818] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7rxMYwyVGnfuwsKYLQAD8zA"]
[Tue Jul 21 07:37:34.461094 2026] [security2:error] [pid 255769:tid 255979] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7rxMYwyVGnfuwsKYLQAD8zA"]
[Tue Jul 21 07:37:34.663749 2026] [security2:error] [pid 255769:tid 255960] [client 20.197.195.24:63329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/777.php"] [unique_id "al9L7rxMYwyVGnfuwsKYMQAAA-A"]
[Tue Jul 21 07:37:34.714226 2026] [security2:error] [pid 255769:tid 255902] [client 20.104.96.117:61112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/19.php"] [unique_id "al9L7rxMYwyVGnfuwsKYMgAAA6Y"]
[Tue Jul 21 07:37:34.727218 2026] [security2:error] [pid 254995:tid 255259] [client 20.206.105.145:38485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/.well-known/about.php"] [unique_id "al9L7v7v0rlcEGmVraE-EQAAA4k"]
[Tue Jul 21 07:37:34.734577 2026] [security2:error] [pid 254995:tid 255225] [client 20.226.60.151:51309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/spadex.php"] [unique_id "al9L7v7v0rlcEGmVraE-EgAAA4E"]
[Tue Jul 21 07:37:34.745414 2026] [security2:error] [pid 254995:tid 255125] [client 20.197.195.24:51737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ssend.php"] [unique_id "al9L7v7v0rlcEGmVraE-EwAAAx4"]
[Tue Jul 21 07:37:35.086734 2026] [security2:error] [pid 255769:tid 255992] [client 20.197.195.24:51807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/item.php"] [unique_id "al9L77xMYwyVGnfuwsKYNwAAA_8"]
[Tue Jul 21 07:37:35.150025 2026] [security2:error] [pid 255769:tid 255990] [client 20.197.195.24:63343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ssixta.php"] [unique_id "al9L77xMYwyVGnfuwsKYOQAAA_4"]
[Tue Jul 21 07:37:35.171381 2026] [security2:error] [pid 255769:tid 255982] [client 20.151.10.161:45995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ccs.php"] [unique_id "al9L77xMYwyVGnfuwsKYOwAAA_Y"]
[Tue Jul 21 07:37:35.252660 2026] [security2:error] [pid 255769:tid 255921] [client 20.197.195.24:51782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ss.php"] [unique_id "al9L77xMYwyVGnfuwsKYPAAAA7k"]
[Tue Jul 21 07:37:35.288887 2026] [security2:error] [pid 254995:tid 255265] [client 20.104.96.117:59662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/inc.php"] [unique_id "al9L7_7v0rlcEGmVraE-HQAAA48"]
[Tue Jul 21 07:37:35.291045 2026] [security2:error] [pid 255769:tid 255935] [client 175.45.70.82:62946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L77xMYwyVGnfuwsKYPQAAA8c"]
[Tue Jul 21 07:37:35.291130 2026] [security2:error] [pid 255769:tid 255935] [client 175.45.70.82:62946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L77xMYwyVGnfuwsKYPQAAA8c"]
[Tue Jul 21 07:37:35.373480 2026] [security2:error] [pid 255769:tid 255934] [client 45.8.17.131:57067] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-atom.php"] [unique_id "al9L77xMYwyVGnfuwsKYPwAAA8Y"]
[Tue Jul 21 07:37:35.445895 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.195.24:21089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/hypo.php"] [unique_id "al9L77xMYwyVGnfuwsKYSQAABAU"]
[Tue Jul 21 07:37:35.504706 2026] [autoindex:error] [pid 255769:tid 255808] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:35.548497 2026] [security2:error] [pid 255769:tid 255975] [client 20.197.195.24:63339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/1c.php"] [unique_id "al9L77xMYwyVGnfuwsKYTwAAA-8"]
[Tue Jul 21 07:37:35.571224 2026] [security2:error] [pid 255769:tid 255978] [client 20.197.195.24:51767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/users.php"] [unique_id "al9L77xMYwyVGnfuwsKYUgAAA_I"]
[Tue Jul 21 07:37:35.637186 2026] [security2:error] [pid 254995:tid 255153] [client 20.197.195.24:21011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/177.php"] [unique_id "al9L7_7v0rlcEGmVraE-IwAAAzo"]
[Tue Jul 21 07:37:35.710568 2026] [security2:error] [pid 255769:tid 255901] [client 122.162.144.145:9884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L77xMYwyVGnfuwsKYVQAAA6U"]
[Tue Jul 21 07:37:35.712946 2026] [security2:error] [pid 255769:tid 255901] [client 122.162.144.145:9884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L77xMYwyVGnfuwsKYVQAAA6U"]
[Tue Jul 21 07:37:35.734127 2026] [security2:error] [pid 255769:tid 255775] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L77xMYwyVGnfuwsKYVgAECQU"]
[Tue Jul 21 07:37:35.734304 2026] [security2:error] [pid 255769:tid 256003] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L77xMYwyVGnfuwsKYVgAECQU"]
[Tue Jul 21 07:37:35.807526 2026] [security2:error] [pid 254995:tid 255183] [client 20.104.96.117:59693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9L7_7v0rlcEGmVraE-JgAAA1g"]
[Tue Jul 21 07:37:35.819109 2026] [autoindex:error] [pid 255769:tid 255894] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:35.867655 2026] [security2:error] [pid 254995:tid 255208] [client 154.192.233.199:59381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7_7v0rlcEGmVraE-JwAAA3A"]
[Tue Jul 21 07:37:35.867808 2026] [security2:error] [pid 254995:tid 255208] [client 154.192.233.199:59381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7_7v0rlcEGmVraE-JwAAA3A"]
[Tue Jul 21 07:37:35.975252 2026] [security2:error] [pid 254995:tid 255188] [client 152.59.154.239:58204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7_7v0rlcEGmVraE-LQAAA10"]
[Tue Jul 21 07:37:35.975367 2026] [security2:error] [pid 254995:tid 255188] [client 152.59.154.239:58204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L7_7v0rlcEGmVraE-LQAAA10"]
[Tue Jul 21 07:37:35.999181 2026] [security2:error] [pid 254995:tid 255195] [client 20.197.195.24:51763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/config.php"] [unique_id "al9L7_7v0rlcEGmVraE-LgAAA2Q"]
[Tue Jul 21 07:37:36.052947 2026] [security2:error] [pid 255769:tid 255993] [client 103.106.20.201:51991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L8LxMYwyVGnfuwsKYWQAABAA"]
[Tue Jul 21 07:37:36.053068 2026] [security2:error] [pid 255769:tid 255993] [client 103.106.20.201:51991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L8LxMYwyVGnfuwsKYWQAABAA"]
[Tue Jul 21 07:37:36.192041 2026] [autoindex:error] [pid 255769:tid 255788] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:36.211278 2026] [security2:error] [pid 254995:tid 255158] [client 20.197.195.24:51810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/gettest.php"] [unique_id "al9L8P7v0rlcEGmVraE-SAAAAz8"]
[Tue Jul 21 07:37:36.313396 2026] [security2:error] [pid 254995:tid 255152] [client 20.220.225.223:51399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ms.php"] [unique_id "al9L8P7v0rlcEGmVraE-TQAAAzk"]
[Tue Jul 21 07:37:36.357296 2026] [security2:error] [pid 255769:tid 256005] [client 20.197.195.24:51821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/min.php"] [unique_id "al9L8LxMYwyVGnfuwsKYXgAABAs"]
[Tue Jul 21 07:37:36.491419 2026] [security2:error] [pid 254995:tid 255198] [client 20.197.195.24:51817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/dvjul.php"] [unique_id "al9L8P7v0rlcEGmVraE-VgAAA2c"]
[Tue Jul 21 07:37:36.526096 2026] [core:error] [pid 254995:tid 255147] [client 164.92.100.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:37:36.526130 2026] [core:error] [pid 254995:tid 255147] [client 164.92.100.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:37:36.706318 2026] [security2:error] [pid 255769:tid 256019] [client 20.104.96.117:59144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9L8LxMYwyVGnfuwsKYZQAABBk"]
[Tue Jul 21 07:37:36.834026 2026] [security2:error] [pid 255769:tid 255929] [client 20.197.195.24:51828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/biufile.php"] [unique_id "al9L8LxMYwyVGnfuwsKYZwAAA8E"]
[Tue Jul 21 07:37:36.877746 2026] [security2:error] [pid 254995:tid 255126] [client 45.8.17.147:30403] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/tinymce/themes/inlite/"] [unique_id "al9L8P7v0rlcEGmVraE-YQAAAx8"]
[Tue Jul 21 07:37:36.938997 2026] [security2:error] [pid 254995:tid 255175] [client 122.164.127.47:54966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L8P7v0rlcEGmVraE-YgAAA1A"]
[Tue Jul 21 07:37:36.939168 2026] [security2:error] [pid 254995:tid 255175] [client 122.164.127.47:54966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L8P7v0rlcEGmVraE-YgAAA1A"]
[Tue Jul 21 07:37:36.958108 2026] [security2:error] [pid 254995:tid 255204] [client 20.197.195.24:63300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/test2.php"] [unique_id "al9L8P7v0rlcEGmVraE-YwAAA20"]
[Tue Jul 21 07:37:37.122667 2026] [security2:error] [pid 255769:tid 255816] [remote 210.211.113.135:60520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.113.211.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9L8LxMYwyVGnfuwsKYWgAD0y4"]
[Tue Jul 21 07:37:37.310823 2026] [security2:error] [pid 254995:tid 255256] [client 20.197.195.24:21016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/av.php"] [unique_id "al9L8f7v0rlcEGmVraE-aQAAA4Y"]
[Tue Jul 21 07:37:37.326598 2026] [security2:error] [pid 254995:tid 255265] [client 20.206.105.145:37951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9L8f7v0rlcEGmVraE-agAAA48"]
[Tue Jul 21 07:37:37.443657 2026] [security2:error] [pid 255769:tid 255988] [client 20.104.96.117:59672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ss.php"] [unique_id "al9L8bxMYwyVGnfuwsKYdgAAA_w"]
[Tue Jul 21 07:37:37.479582 2026] [security2:error] [pid 255769:tid 255940] [client 136.144.33.109:49501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9L8bxMYwyVGnfuwsKYdwAAA8w"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:37.565516 2026] [security2:error] [pid 255769:tid 255930] [client 20.151.10.161:45895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ccc.php"] [unique_id "al9L8bxMYwyVGnfuwsKYeQAAA8I"]
[Tue Jul 21 07:37:37.609792 2026] [security2:error] [pid 255769:tid 255923] [client 16.163.108.56:48810] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "senatruckdiesel.com.br"] [uri "/cgi-sys/js/jquery-1.11.2.min.js"] [unique_id "al9L8bxMYwyVGnfuwsKYegAAA7s"]
[Tue Jul 21 07:37:37.626228 2026] [security2:error] [pid 255769:tid 255941] [client 20.197.195.24:63341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/buy.php"] [unique_id "al9L8bxMYwyVGnfuwsKYewAAA80"]
[Tue Jul 21 07:37:37.652556 2026] [security2:error] [pid 255769:tid 255976] [client 16.163.108.56:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "senatruckdiesel.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9L8bxMYwyVGnfuwsKYfgAAA_A"]
[Tue Jul 21 07:37:37.653204 2026] [security2:error] [pid 255769:tid 256000] [client 16.163.108.56:48826] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "senatruckdiesel.com.br"] [uri "/CHANGELOG.txt"] [unique_id "al9L8bxMYwyVGnfuwsKYfAAABAY"]
[Tue Jul 21 07:37:37.826482 2026] [security2:error] [pid 255769:tid 255834] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L8bxMYwyVGnfuwsKYhQADv0A"]
[Tue Jul 21 07:37:37.826639 2026] [security2:error] [pid 255769:tid 255927] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L8bxMYwyVGnfuwsKYhQADv0A"]
[Tue Jul 21 07:37:38.089678 2026] [security2:error] [pid 254995:tid 255136] [client 20.197.192.193:6365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9L8v7v0rlcEGmVraE-kgAAAyk"]
[Tue Jul 21 07:37:38.100829 2026] [security2:error] [pid 255769:tid 255980] [client 103.174.34.15:59063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L8rxMYwyVGnfuwsKYkAAAA_Q"]
[Tue Jul 21 07:37:38.100978 2026] [security2:error] [pid 255769:tid 255980] [client 103.174.34.15:59063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L8rxMYwyVGnfuwsKYkAAAA_Q"]
[Tue Jul 21 07:37:38.131942 2026] [security2:error] [pid 254995:tid 255178] [client 20.52.136.55:1743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/config-backup.php"] [unique_id "al9L8v7v0rlcEGmVraE-kwAAA1M"]
[Tue Jul 21 07:37:38.177722 2026] [security2:error] [pid 255769:tid 255929] [client 20.197.195.24:51723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/coffexium.php"] [unique_id "al9L8rxMYwyVGnfuwsKYlwAAA8E"]
[Tue Jul 21 07:37:38.275247 2026] [security2:error] [pid 255769:tid 255909] [client 45.8.17.145:37815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/uploads/about.php"] [unique_id "al9L8rxMYwyVGnfuwsKYmAAAA60"]
[Tue Jul 21 07:37:38.450324 2026] [security2:error] [pid 255769:tid 255957] [client 173.252.95.54:47874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9L8bxMYwyVGnfuwsKYcgAAA90"]
[Tue Jul 21 07:37:38.602345 2026] [security2:error] [pid 255769:tid 255982] [client 20.151.10.161:46001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/get.php"] [unique_id "al9L8rxMYwyVGnfuwsKYngAAA_Y"]
[Tue Jul 21 07:37:38.650668 2026] [security2:error] [pid 254995:tid 255002] [remote 212.47.76.178:50412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.76.47.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dscbrasil.com.br"] [uri "/wp-login.php"] [unique_id "al9L8v7v0rlcEGmVraE-ogADMgY"]
[Tue Jul 21 07:37:38.803204 2026] [autoindex:error] [pid 255769:tid 255785] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:38.891321 2026] [security2:error] [pid 254995:tid 255175] [client 20.197.195.24:63655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ssend.php"] [unique_id "al9L8v7v0rlcEGmVraE-pQAAA1A"]
[Tue Jul 21 07:37:38.939898 2026] [security2:error] [pid 254995:tid 255143] [client 20.197.195.24:21060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/core.php"] [unique_id "al9L8v7v0rlcEGmVraE-pgAAAzA"]
[Tue Jul 21 07:37:38.990858 2026] [security2:error] [pid 255769:tid 255961] [client 20.206.105.145:37947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/bob.php"] [unique_id "al9L8rxMYwyVGnfuwsKYpwAAA-E"]
[Tue Jul 21 07:37:39.107416 2026] [autoindex:error] [pid 255769:tid 255778] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:37:39.279906 2026] [security2:error] [pid 254995:tid 255276] [client 45.8.17.117:28163] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/covr-wpcom/assets/fonts/manrope_normal.php"] [unique_id "al9L8_7v0rlcEGmVraE-qgAAA5o"]
[Tue Jul 21 07:37:39.357247 2026] [security2:error] [pid 255769:tid 255889] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L87xMYwyVGnfuwsKYrAAD_3c"]
[Tue Jul 21 07:37:39.357447 2026] [security2:error] [pid 255769:tid 255992] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L87xMYwyVGnfuwsKYrAAD_3c"]
[Tue Jul 21 07:37:39.364717 2026] [security2:error] [pid 255769:tid 255922] [client 59.96.220.140:60111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L87xMYwyVGnfuwsKYrQAAA7o"]
[Tue Jul 21 07:37:39.365421 2026] [security2:error] [pid 255769:tid 255922] [client 59.96.220.140:60111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L87xMYwyVGnfuwsKYrQAAA7o"]
[Tue Jul 21 07:37:39.374129 2026] [security2:error] [pid 254995:tid 255161] [client 20.197.195.24:23410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/als.php"] [unique_id "al9L8_7v0rlcEGmVraE-rAAAA0I"]
[Tue Jul 21 07:37:39.466270 2026] [security2:error] [pid 254995:tid 255212] [client 89.124.113.107:59452] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.113.107" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "trconsultcontabilidade.com"] [uri "/wp-comments-post.php"] [unique_id "al9L8_7v0rlcEGmVraE-sAAAA3Q"], referer: https://trconsultcontabilidade.com/2023/06/02/ola-mundo/
[Tue Jul 21 07:37:39.466366 2026] [security2:error] [pid 254995:tid 255212] [client 89.124.113.107:59452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "trconsultcontabilidade.com"] [uri "/wp-comments-post.php"] [unique_id "al9L8_7v0rlcEGmVraE-sAAAA3Q"], referer: https://trconsultcontabilidade.com/2023/06/02/ola-mundo/
[Tue Jul 21 07:37:39.517396 2026] [security2:error] [pid 254995:tid 255178] [client 20.151.10.161:46051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/images.php"] [unique_id "al9L8_7v0rlcEGmVraE-uQAAA1M"]
[Tue Jul 21 07:37:39.583609 2026] [security2:error] [pid 255769:tid 256018] [client 185.198.240.95:35187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-login.php"] [unique_id "al9L8rxMYwyVGnfuwsKYnAAABBg"]
[Tue Jul 21 07:37:39.699649 2026] [security2:error] [pid 255769:tid 256028] [client 20.226.60.151:51331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/2x.php"] [unique_id "al9L87xMYwyVGnfuwsKYsgAABCI"]
[Tue Jul 21 07:37:39.721075 2026] [security2:error] [pid 254995:tid 255151] [client 20.104.96.117:59676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/min.php"] [unique_id "al9L8_7v0rlcEGmVraE-vQAAAzg"]
[Tue Jul 21 07:37:39.739568 2026] [security2:error] [pid 254995:tid 255217] [client 20.197.192.193:6393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9L8_7v0rlcEGmVraE-vgAAA3k"]
[Tue Jul 21 07:37:39.825249 2026] [security2:error] [pid 254995:tid 255166] [client 20.197.195.24:63346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/item.php"] [unique_id "al9L8_7v0rlcEGmVraE-wAAAA0c"]
[Tue Jul 21 07:37:39.910944 2026] [security2:error] [pid 254995:tid 255252] [client 103.86.117.203:54623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L8_7v0rlcEGmVraE-xAAAA4M"]
[Tue Jul 21 07:37:39.911056 2026] [security2:error] [pid 254995:tid 255252] [client 103.86.117.203:54623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L8_7v0rlcEGmVraE-xAAAA4M"]
[Tue Jul 21 07:37:39.992567 2026] [security2:error] [pid 254995:tid 255013] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L8_7v0rlcEGmVraE-xgADYBE"]
[Tue Jul 21 07:37:39.992717 2026] [security2:error] [pid 254995:tid 255191] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L8_7v0rlcEGmVraE-xgADYBE"]
[Tue Jul 21 07:37:40.030060 2026] [security2:error] [pid 254995:tid 255145] [client 20.151.10.161:46038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/alls.php"] [unique_id "al9L9P7v0rlcEGmVraE-xwAAAzI"]
[Tue Jul 21 07:37:40.054049 2026] [security2:error] [pid 254995:tid 255167] [client 20.197.195.24:21076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/simple.php"] [unique_id "al9L9P7v0rlcEGmVraE-yAAAA0g"]
[Tue Jul 21 07:37:40.191912 2026] [security2:error] [pid 255769:tid 255955] [client 20.197.195.24:63334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ss.php"] [unique_id "al9L9LxMYwyVGnfuwsKYtQAAA9s"]
[Tue Jul 21 07:37:40.338158 2026] [autoindex:error] [pid 254995:tid 255223] [client 20.206.105.145:38466] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:40.360836 2026] [security2:error] [pid 255769:tid 255865] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-includes/woocommerce-call.php"] [unique_id "al9L9LxMYwyVGnfuwsKYuAAD118"], referer: http://aud-7.com/wp-includes/woocommerce-call.php
[Tue Jul 21 07:37:40.413718 2026] [autoindex:error] [pid 254995:tid 255142] [client 20.206.105.145:38466] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:40.419046 2026] [security2:error] [pid 254995:tid 255218] [client 20.206.105.145:38466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/crgio.php"] [unique_id "al9L9P7v0rlcEGmVraE-0AAAA3o"]
[Tue Jul 21 07:37:40.601442 2026] [security2:error] [pid 254995:tid 255127] [client 20.151.10.161:46078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/yyu.php"] [unique_id "al9L9P7v0rlcEGmVraE-1AAAAyA"]
[Tue Jul 21 07:37:40.783257 2026] [security2:error] [pid 255769:tid 255947] [client 45.8.17.137:48737] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/privacy-tools.min.php"] [unique_id "al9L9LxMYwyVGnfuwsKYvwAAA9M"]
[Tue Jul 21 07:37:40.831381 2026] [security2:error] [pid 254995:tid 255023] [remote 45.132.115.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.115.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lunarium.tec.br"] [uri "/wp-login.php"] [unique_id "al9L9P7v0rlcEGmVraE-2gADXhs"]
[Tue Jul 21 07:37:40.871955 2026] [security2:error] [pid 254995:tid 255267] [client 20.197.195.24:63635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/hypo.php"] [unique_id "al9L9P7v0rlcEGmVraE-3AAAA5E"]
[Tue Jul 21 07:37:40.874058 2026] [security2:error] [pid 255769:tid 255881] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/wordpress-seo/wp-seo-main-float.php"] [unique_id "al9L9LxMYwyVGnfuwsKYwgADxm8"], referer: http://aud-7.com/wp-content/plugins/wordpress-seo/wp-seo-main-float.php
[Tue Jul 21 07:37:40.903058 2026] [core:error] [pid 254995:tid 255265] [client 164.92.100.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.health-24.shop/
[Tue Jul 21 07:37:40.903078 2026] [core:error] [pid 254995:tid 255265] [client 164.92.100.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.health-24.shop/
[Tue Jul 21 07:37:41.059990 2026] [security2:error] [pid 255769:tid 255902] [client 45.251.232.145:49376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.232.251.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L9bxMYwyVGnfuwsKYxQAAA6Y"]
[Tue Jul 21 07:37:41.060115 2026] [security2:error] [pid 255769:tid 255902] [client 45.251.232.145:49376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L9bxMYwyVGnfuwsKYxQAAA6Y"]
[Tue Jul 21 07:37:41.111767 2026] [security2:error] [pid 255769:tid 255952] [client 20.151.10.161:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/by.php"] [unique_id "al9L9bxMYwyVGnfuwsKYxwAAA9g"]
[Tue Jul 21 07:37:41.188280 2026] [security2:error] [pid 255769:tid 256000] [client 20.197.195.24:63674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/users.php"] [unique_id "al9L9bxMYwyVGnfuwsKYyQAABAY"]
[Tue Jul 21 07:37:41.217007 2026] [security2:error] [pid 255769:tid 255931] [client 20.104.96.117:59659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9L9bxMYwyVGnfuwsKYygAAA8M"]
[Tue Jul 21 07:37:41.324179 2026] [security2:error] [pid 254995:tid 255208] [client 20.197.195.24:51830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/init.php"] [unique_id "al9L9f7v0rlcEGmVraE_AAAAA3A"]
[Tue Jul 21 07:37:41.399691 2026] [security2:error] [pid 255769:tid 256020] [client 136.144.33.108:42883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9L9bxMYwyVGnfuwsKYywAABBo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:41.539221 2026] [security2:error] [pid 255769:tid 255940] [client 139.167.225.182:64222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L9bxMYwyVGnfuwsKY0AAAA8w"]
[Tue Jul 21 07:37:41.539349 2026] [security2:error] [pid 255769:tid 255940] [client 139.167.225.182:64222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L9bxMYwyVGnfuwsKY0AAAA8w"]
[Tue Jul 21 07:37:41.573427 2026] [security2:error] [pid 254995:tid 255273] [client 20.197.195.24:21025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/fpwch.php"] [unique_id "al9L9f7v0rlcEGmVraE_BAAAA5c"]
[Tue Jul 21 07:37:41.634144 2026] [security2:error] [pid 254995:tid 255212] [client 20.197.195.24:63650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/177.php"] [unique_id "al9L9f7v0rlcEGmVraE_BQAAA3Q"]
[Tue Jul 21 07:37:41.733909 2026] [security2:error] [pid 255769:tid 255887] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403x.php"] [unique_id "al9L9bxMYwyVGnfuwsKY0QAECXU"], referer: http://aud-7.com/wp-content/plugins/enhanced-text-widget/analyst/src/403x.php
[Tue Jul 21 07:37:41.760883 2026] [security2:error] [pid 254995:tid 255148] [client 20.151.10.161:46018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/FAQ.php"] [unique_id "al9L9f7v0rlcEGmVraE_CgAAAzU"]
[Tue Jul 21 07:37:41.906660 2026] [security2:error] [pid 254995:tid 255144] [client 20.104.96.117:61125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9L9f7v0rlcEGmVraE_DAAAAzE"]
[Tue Jul 21 07:37:42.075255 2026] [security2:error] [pid 255769:tid 255955] [client 45.8.17.118:59965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/options.php"] [unique_id "al9L9rxMYwyVGnfuwsKY1wAAA9s"]
[Tue Jul 21 07:37:42.249076 2026] [security2:error] [pid 255769:tid 255869] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "al9L9rxMYwyVGnfuwsKY2gAD4GM"], referer: http://aud-7.com/wp-content/themes/news-portal/error.php
[Tue Jul 21 07:37:42.362835 2026] [security2:error] [pid 255769:tid 256021] [client 20.220.225.223:49558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ace2.php"] [unique_id "al9L9rxMYwyVGnfuwsKY3QAABBs"]
[Tue Jul 21 07:37:42.383381 2026] [security2:error] [pid 254995:tid 255167] [client 20.197.195.24:63303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/config.php"] [unique_id "al9L9v7v0rlcEGmVraE_GwAAA0g"]
[Tue Jul 21 07:37:42.424488 2026] [autoindex:error] [pid 254995:tid 255213] [client 43.165.125.66:54716] AH01276: Cannot serve directory /home3/lianem44/ubaloc.store/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:42.595056 2026] [security2:error] [pid 254995:tid 255262] [client 173.252.95.18:49814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9L9v7v0rlcEGmVraE_JQAAA4w"]
[Tue Jul 21 07:37:42.608151 2026] [security2:error] [pid 254995:tid 255217] [client 117.217.38.194:52713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L9v7v0rlcEGmVraE_JgAAA3k"]
[Tue Jul 21 07:37:42.608248 2026] [security2:error] [pid 254995:tid 255217] [client 117.217.38.194:52713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L9v7v0rlcEGmVraE_JgAAA3k"]
[Tue Jul 21 07:37:42.629134 2026] [security2:error] [pid 255769:tid 255859] [remote 45.3.49.137:46551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.49.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9L9rxMYwyVGnfuwsKY4QAEFlk"]
[Tue Jul 21 07:37:42.658383 2026] [security2:error] [pid 254995:tid 255182] [client 20.151.10.161:45968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/coffexium.php"] [unique_id "al9L9v7v0rlcEGmVraE_JwAAA1c"]
[Tue Jul 21 07:37:42.711786 2026] [security2:error] [pid 255769:tid 255909] [client 20.197.195.24:51834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/domvf.php"] [unique_id "al9L9rxMYwyVGnfuwsKY4gAAA60"]
[Tue Jul 21 07:37:42.767283 2026] [security2:error] [pid 255769:tid 255856] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/fukasawa/inc/classes/403.php"] [unique_id "al9L9rxMYwyVGnfuwsKY4wAD5FY"], referer: http://aud-7.com/wp-content/themes/fukasawa/inc/classes/403.php
[Tue Jul 21 07:37:42.787894 2026] [security2:error] [pid 254995:tid 255127] [client 20.104.96.117:61079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9L9v7v0rlcEGmVraE_KwAAAyA"]
[Tue Jul 21 07:37:42.836093 2026] [security2:error] [pid 255769:tid 255866] [remote 217.182.128.41:43374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bellascleaningsolutionsllc.com"] [uri "/wp-login.php"] [unique_id "al9L9rxMYwyVGnfuwsKY5QAD4WA"]
[Tue Jul 21 07:37:42.899657 2026] [security2:error] [pid 254995:tid 255176] [client 20.197.195.24:63315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/gettest.php"] [unique_id "al9L9v7v0rlcEGmVraE_LgAAA1E"]
[Tue Jul 21 07:37:43.039533 2026] [security2:error] [pid 255769:tid 256002] [client 20.206.105.145:37906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/pucci.php"] [unique_id "al9L97xMYwyVGnfuwsKY5wAABAg"]
[Tue Jul 21 07:37:43.176381 2026] [security2:error] [pid 255769:tid 255900] [client 45.8.17.121:29303] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/user/wp-conflg.php"] [unique_id "al9L97xMYwyVGnfuwsKY6QAAA6Q"]
[Tue Jul 21 07:37:43.179987 2026] [security2:error] [pid 255769:tid 255917] [client 20.197.195.24:63621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/min.php"] [unique_id "al9L97xMYwyVGnfuwsKY6gAAA7U"]
[Tue Jul 21 07:37:43.229305 2026] [security2:error] [pid 254995:tid 255189] [client 173.24.185.52:57106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L9_7v0rlcEGmVraE_NAAAA14"]
[Tue Jul 21 07:37:43.229464 2026] [security2:error] [pid 254995:tid 255189] [client 173.24.185.52:57106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9L9_7v0rlcEGmVraE_NAAAA14"]
[Tue Jul 21 07:37:43.284705 2026] [security2:error] [pid 255769:tid 255873] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/hello-plus/classes/ehp-sarang.php"] [unique_id "al9L97xMYwyVGnfuwsKY6wAD_Wc"], referer: http://aud-7.com/wp-content/plugins/hello-plus/classes/ehp-sarang.php
[Tue Jul 21 07:37:43.330450 2026] [security2:error] [pid 255769:tid 255895] [remote 173.252.95.20:43756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9L97xMYwyVGnfuwsKY6AAEFH0"]
[Tue Jul 21 07:37:43.441800 2026] [security2:error] [pid 255769:tid 255958] [client 20.197.195.24:21105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp.php"] [unique_id "al9L97xMYwyVGnfuwsKY8gAAA94"]
[Tue Jul 21 07:37:43.480879 2026] [security2:error] [pid 255769:tid 255911] [client 20.151.10.161:46077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/red.php"] [unique_id "al9L97xMYwyVGnfuwsKY8wAAA68"]
[Tue Jul 21 07:37:43.530183 2026] [security2:error] [pid 254995:tid 255275] [client 20.197.195.24:63314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/dvjul.php"] [unique_id "al9L9_7v0rlcEGmVraE_OAAAA5k"]
[Tue Jul 21 07:37:43.600846 2026] [security2:error] [pid 254995:tid 255204] [client 117.251.86.144:35610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L9_7v0rlcEGmVraE_PQAAA20"]
[Tue Jul 21 07:37:43.600967 2026] [security2:error] [pid 254995:tid 255204] [client 117.251.86.144:35610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9L9_7v0rlcEGmVraE_PQAAA20"]
[Tue Jul 21 07:37:43.791244 2026] [security2:error] [pid 255769:tid 255943] [client 103.162.129.114:55940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L97xMYwyVGnfuwsKY9AAAA88"]
[Tue Jul 21 07:37:43.791409 2026] [security2:error] [pid 255769:tid 255943] [client 103.162.129.114:55940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9L97xMYwyVGnfuwsKY9AAAA88"]
[Tue Jul 21 07:37:43.800362 2026] [security2:error] [pid 255769:tid 255863] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/so-pinyin-slugs/inc/main_json.php"] [unique_id "al9L97xMYwyVGnfuwsKY9gADxF0"], referer: http://aud-7.com/wp-content/plugins/so-pinyin-slugs/inc/main_json.php
[Tue Jul 21 07:37:43.909187 2026] [autoindex:error] [pid 254995:tid 255112] [remote 49.234.192.248:0] AH01276: Cannot serve directory /home1/tavar035/brasilcertdigital.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://brasilcertdigital.online
[Tue Jul 21 07:37:43.959596 2026] [security2:error] [pid 254995:tid 255114] [remote 103.112.62.59:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9L9_7v0rlcEGmVraE_RQADIXY"]
[Tue Jul 21 07:37:44.091745 2026] [security2:error] [pid 255769:tid 255966] [client 20.197.195.24:63309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/biufile.php"] [unique_id "al9L-LxMYwyVGnfuwsKY_QAAA-Y"]
[Tue Jul 21 07:37:44.182787 2026] [security2:error] [pid 254995:tid 255170] [client 122.186.204.214:58069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L-P7v0rlcEGmVraE_SQAAA0s"]
[Tue Jul 21 07:37:44.182951 2026] [security2:error] [pid 254995:tid 255170] [client 122.186.204.214:58069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L-P7v0rlcEGmVraE_SQAAA0s"]
[Tue Jul 21 07:37:44.319808 2026] [security2:error] [pid 255769:tid 255833] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/filester/assets/css/404.php"] [unique_id "al9L-LxMYwyVGnfuwsKZBAAD6T8"], referer: http://aud-7.com/wp-content/plugins/filester/assets/css/404.php
[Tue Jul 21 07:37:44.363483 2026] [security2:error] [pid 254995:tid 255257] [client 20.104.96.117:59173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9L-P7v0rlcEGmVraE_TgAAA4c"]
[Tue Jul 21 07:37:44.369905 2026] [security2:error] [pid 254995:tid 255158] [client 45.8.17.144:40257] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/.well-known/"] [unique_id "al9L-P7v0rlcEGmVraE_TwAAAz8"]
[Tue Jul 21 07:37:44.417909 2026] [security2:error] [pid 255769:tid 255993] [client 193.36.225.152:49257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9L-LxMYwyVGnfuwsKZAgAABAA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:37:44.574367 2026] [security2:error] [pid 254995:tid 255167] [client 20.226.60.151:51369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ctex1.php"] [unique_id "al9L-P7v0rlcEGmVraE_UwAAA0g"]
[Tue Jul 21 07:37:44.584645 2026] [security2:error] [pid 254995:tid 255017] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L-P7v0rlcEGmVraE_VAADQxU"]
[Tue Jul 21 07:37:44.584846 2026] [security2:error] [pid 254995:tid 255162] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9L-P7v0rlcEGmVraE_VAADQxU"]
[Tue Jul 21 07:37:44.608830 2026] [security2:error] [pid 254995:tid 255169] [client 20.197.195.24:21021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/class.php"] [unique_id "al9L-P7v0rlcEGmVraE_VgAAA0o"]
[Tue Jul 21 07:37:44.811905 2026] [core:error] [pid 255769:tid 255964] [client 119.3.162.103:33358] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Tue Jul 21 07:37:44.841945 2026] [security2:error] [pid 255769:tid 255854] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/neve/assets/apps/dashboard/build/index.php"] [unique_id "al9L-LxMYwyVGnfuwsKZDAAD1lQ"], referer: http://aud-7.com/wp-content/themes/neve/assets/apps/dashboard/build/index.php
[Tue Jul 21 07:37:44.934939 2026] [autoindex:error] [pid 255769:tid 255985] [client 20.206.105.145:37945] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:44.939316 2026] [security2:error] [pid 255769:tid 255847] [remote 141.98.11.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.11.98.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9L-LxMYwyVGnfuwsKZEQAECE0"], referer: https://www.binance.com
[Tue Jul 21 07:37:44.941795 2026] [security2:error] [pid 255769:tid 255843] [remote 141.98.11.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.11.98.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9L-LxMYwyVGnfuwsKZEgAD_0k"], referer: https://www.binance.com
[Tue Jul 21 07:37:44.963294 2026] [autoindex:error] [pid 255769:tid 255922] [client 20.206.105.145:37945] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:44.969002 2026] [security2:error] [pid 255769:tid 255994] [client 20.206.105.145:37945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-temp.php"] [unique_id "al9L-LxMYwyVGnfuwsKZFQAABAE"]
[Tue Jul 21 07:37:45.103213 2026] [security2:error] [pid 255769:tid 255934] [client 20.151.10.161:46055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9L-bxMYwyVGnfuwsKZGwAAA8Y"]
[Tue Jul 21 07:37:45.116043 2026] [security2:error] [pid 255769:tid 255803] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-bxMYwyVGnfuwsKZHAAD_iE"]
[Tue Jul 21 07:37:45.116196 2026] [security2:error] [pid 255769:tid 255990] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-bxMYwyVGnfuwsKZHAAD_iE"]
[Tue Jul 21 07:37:45.230325 2026] [security2:error] [pid 255769:tid 255902] [client 20.197.195.24:21008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/echkm.php"] [unique_id "al9L-bxMYwyVGnfuwsKZHgAAA6Y"]
[Tue Jul 21 07:37:45.242653 2026] [security2:error] [pid 255769:tid 255956] [client 20.197.195.24:63305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/av.php"] [unique_id "al9L-bxMYwyVGnfuwsKZIAAAA9w"]
[Tue Jul 21 07:37:45.264154 2026] [security2:error] [pid 255769:tid 255951] [client 34.14.85.22:64969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.85.14.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seguryredes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-LxMYwyVGnfuwsKZAwAAA9c"]
[Tue Jul 21 07:37:45.329138 2026] [core:crit] [pid 255769:tid 255817] (13)Permission denied: [remote 141.98.11.42:0] AH00529: /home2/androa31/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home2/androa31/public_html/cgi-bin/' is executable, referer: https://www.binance.com
[Tue Jul 21 07:37:45.331468 2026] [core:crit] [pid 255769:tid 255862] (13)Permission denied: [remote 141.98.11.42:0] AH00529: /home2/androa31/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home2/androa31/public_html/cgi-bin/' is executable, referer: https://www.binance.com
[Tue Jul 21 07:37:45.355210 2026] [security2:error] [pid 255769:tid 255821] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/theme-check/main.php"] [unique_id "al9L-bxMYwyVGnfuwsKZIwAD7zM"], referer: http://aud-7.com/wp-content/themes/theme-check/main.php
[Tue Jul 21 07:37:45.503928 2026] [security2:error] [pid 254995:tid 255186] [client 20.197.195.24:20995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/lib.php"] [unique_id "al9L-f7v0rlcEGmVraE_jAAAA1s"]
[Tue Jul 21 07:37:45.575259 2026] [security2:error] [pid 254995:tid 255161] [client 45.8.17.105:56461] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-configs.php"] [unique_id "al9L-f7v0rlcEGmVraE_jgAAA0I"]
[Tue Jul 21 07:37:45.608884 2026] [security2:error] [pid 254995:tid 255137] [client 193.36.225.64:60837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9L-f7v0rlcEGmVraE_kAAAAyo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:45.661098 2026] [security2:error] [pid 254995:tid 255204] [client 34.14.85.22:62496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9L-f7v0rlcEGmVraE_kwAAA20"]
[Tue Jul 21 07:37:45.775598 2026] [security2:error] [pid 254995:tid 255272] [client 20.197.195.24:21063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/login.php"] [unique_id "al9L-f7v0rlcEGmVraE_lQAAA5Y"]
[Tue Jul 21 07:37:45.877574 2026] [security2:error] [pid 255769:tid 255798] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/elementor/includes/interfaces/about.php"] [unique_id "al9L-bxMYwyVGnfuwsKZLAAD8xw"], referer: http://aud-7.com/wp-content/plugins/elementor/includes/interfaces/about.php
[Tue Jul 21 07:37:45.993847 2026] [security2:error] [pid 255769:tid 255955] [client 20.220.225.223:49809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "emiesse.cursosonlinesiteoficial.com"] [uri "/ms.php"] [unique_id "al9L-bxMYwyVGnfuwsKZMAAAA9s"]
[Tue Jul 21 07:37:45.997909 2026] [security2:error] [pid 254995:tid 255176] [client 175.45.70.82:63461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-f7v0rlcEGmVraE_mgAAA1E"]
[Tue Jul 21 07:37:45.998044 2026] [security2:error] [pid 254995:tid 255176] [client 175.45.70.82:63461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-f7v0rlcEGmVraE_mgAAA1E"]
[Tue Jul 21 07:37:46.115805 2026] [security2:error] [pid 255769:tid 255993] [client 20.151.10.161:46046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/footer.php"] [unique_id "al9L-rxMYwyVGnfuwsKZMgAABAA"]
[Tue Jul 21 07:37:46.151358 2026] [security2:error] [pid 254995:tid 255177] [client 34.14.85.22:57030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9L-v7v0rlcEGmVraE_nQAAA1I"]
[Tue Jul 21 07:37:46.247144 2026] [security2:error] [pid 255769:tid 255796] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZNgADrRo"]
[Tue Jul 21 07:37:46.247267 2026] [security2:error] [pid 255769:tid 255909] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZNgADrRo"]
[Tue Jul 21 07:37:46.272207 2026] [security2:error] [pid 255769:tid 256019] [client 20.104.96.117:61067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/albin.php"] [unique_id "al9L-rxMYwyVGnfuwsKZOAAABBk"]
[Tue Jul 21 07:37:46.383506 2026] [autoindex:error] [pid 254995:tid 255170] [client 20.206.105.145:37942] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:46.391754 2026] [security2:error] [pid 255769:tid 255864] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/wp-cache-sys/index.php"] [unique_id "al9L-rxMYwyVGnfuwsKZOgAD-V4"], referer: http://aud-7.com/wp-content/plugins/wp-cache-sys/index.php
[Tue Jul 21 07:37:46.393894 2026] [security2:error] [pid 254995:tid 255144] [client 20.206.105.145:37942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9L-v7v0rlcEGmVraE_owAAAzE"]
[Tue Jul 21 07:37:46.483498 2026] [security2:error] [pid 255769:tid 255835] [remote 184.168.124.4:33290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.124.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "frsadvocacia.net"] [uri "/wp-login.php"] [unique_id "al9L-rxMYwyVGnfuwsKZPgAD_EE"]
[Tue Jul 21 07:37:46.533282 2026] [security2:error] [pid 255769:tid 255986] [client 154.192.233.199:59926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZPwAAA_o"]
[Tue Jul 21 07:37:46.533383 2026] [security2:error] [pid 255769:tid 255986] [client 154.192.233.199:59926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZPwAAA_o"]
[Tue Jul 21 07:37:46.550657 2026] [security2:error] [pid 255769:tid 256022] [client 122.162.144.145:32394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZQQAABBw"]
[Tue Jul 21 07:37:46.550853 2026] [security2:error] [pid 255769:tid 256022] [client 122.162.144.145:32394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZQQAABBw"]
[Tue Jul 21 07:37:46.580546 2026] [security2:error] [pid 255769:tid 255900] [client 45.8.17.125:35681] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/class.php"] [unique_id "al9L-rxMYwyVGnfuwsKZQgAAA6Q"]
[Tue Jul 21 07:37:46.642381 2026] [security2:error] [pid 254995:tid 255266] [client 34.14.85.22:63445] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9L-v7v0rlcEGmVraE_qQAAA5A"]
[Tue Jul 21 07:37:46.718941 2026] [security2:error] [pid 255769:tid 255939] [client 20.197.195.24:21107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/a2.php"] [unique_id "al9L-rxMYwyVGnfuwsKZRQAAA8s"]
[Tue Jul 21 07:37:46.798977 2026] [security2:error] [pid 255769:tid 255956] [client 20.197.195.24:63663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/coffexium.php"] [unique_id "al9L-rxMYwyVGnfuwsKZSAAAA9w"]
[Tue Jul 21 07:37:46.816327 2026] [security2:error] [pid 255769:tid 256009] [client 103.106.20.201:52583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZTQAABA8"]
[Tue Jul 21 07:37:46.816451 2026] [security2:error] [pid 255769:tid 256009] [client 103.106.20.201:52583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-rxMYwyVGnfuwsKZTQAABA8"]
[Tue Jul 21 07:37:46.909616 2026] [security2:error] [pid 255769:tid 255799] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/aatdgetgdg/main.php"] [unique_id "al9L-rxMYwyVGnfuwsKZTgAD3h0"], referer: http://aud-7.com/wp-content/plugins/aatdgetgdg/main.php
[Tue Jul 21 07:37:47.000310 2026] [core:error] [pid 254995:tid 255102] [remote 95.108.213.234:52058] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:37:47.000342 2026] [core:error] [pid 254995:tid 255102] [remote 95.108.213.234:52058] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:37:47.062477 2026] [security2:error] [pid 255769:tid 255943] [client 34.14.85.22:56528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9L-7xMYwyVGnfuwsKZUwAAA88"]
[Tue Jul 21 07:37:47.076754 2026] [security2:error] [pid 255769:tid 255969] [client 152.59.154.239:14080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-7xMYwyVGnfuwsKZVAAAA-k"]
[Tue Jul 21 07:37:47.076897 2026] [security2:error] [pid 255769:tid 255969] [client 152.59.154.239:14080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L-7xMYwyVGnfuwsKZVAAAA-k"]
[Tue Jul 21 07:37:47.423605 2026] [security2:error] [pid 255769:tid 255771] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "al9L-7xMYwyVGnfuwsKZXAAD8gE"], referer: http://aud-7.com/wp-content/plugins/pwnd/pwnd.php
[Tue Jul 21 07:37:47.466834 2026] [security2:error] [pid 255769:tid 255905] [client 20.197.195.24:63323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/core.php"] [unique_id "al9L-7xMYwyVGnfuwsKZXQAAA6k"]
[Tue Jul 21 07:37:47.471520 2026] [security2:error] [pid 254995:tid 255261] [client 34.14.85.22:62837] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9L-_7v0rlcEGmVraE_uAAAA4s"]
[Tue Jul 21 07:37:47.516909 2026] [security2:error] [pid 255769:tid 255930] [client 122.164.127.47:55475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L-7xMYwyVGnfuwsKZXwAAA8I"]
[Tue Jul 21 07:37:47.517052 2026] [security2:error] [pid 255769:tid 255930] [client 122.164.127.47:55475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9L-7xMYwyVGnfuwsKZXwAAA8I"]
[Tue Jul 21 07:37:47.673197 2026] [security2:error] [pid 255769:tid 255980] [client 20.197.195.24:51758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/d61.php"] [unique_id "al9L-7xMYwyVGnfuwsKZYQAAA_Q"]
[Tue Jul 21 07:37:47.887835 2026] [security2:error] [pid 255769:tid 255954] [client 45.8.17.103:54447] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/Diff/Engine/"] [unique_id "al9L-7xMYwyVGnfuwsKZZAAAA9o"]
[Tue Jul 21 07:37:47.939264 2026] [security2:error] [pid 255769:tid 255890] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/StylePlugin/up.php"] [unique_id "al9L-7xMYwyVGnfuwsKZZQAEGXg"], referer: http://aud-7.com/wp-content/plugins/StylePlugin/up.php
[Tue Jul 21 07:37:47.941342 2026] [security2:error] [pid 254995:tid 255276] [client 34.14.85.22:58108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9L-_7v0rlcEGmVraE_wQAAA5o"]
[Tue Jul 21 07:37:47.987966 2026] [security2:error] [pid 255769:tid 255867] [remote 178.18.124.148:22066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.124.18.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/xmlrpc.php"] [unique_id "al9L-7xMYwyVGnfuwsKZZgAEG2E"]
[Tue Jul 21 07:37:47.988178 2026] [security2:error] [pid 255769:tid 256021] [client 178.18.124.148:22066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rlvmultiofertas.com"] [uri "/xmlrpc.php"] [unique_id "al9L-7xMYwyVGnfuwsKZZgAEG2E"]
[Tue Jul 21 07:37:48.092626 2026] [security2:error] [pid 255769:tid 255985] [client 20.220.225.223:38660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/yup.php"] [unique_id "al9L_LxMYwyVGnfuwsKZagAAA_k"]
[Tue Jul 21 07:37:48.280540 2026] [security2:error] [pid 255769:tid 255992] [client 173.252.95.20:45736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9L_LxMYwyVGnfuwsKZbwAAA_8"]
[Tue Jul 21 07:37:48.326430 2026] [security2:error] [pid 255769:tid 255899] [client 20.151.10.161:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/index.php"] [unique_id "al9L_LxMYwyVGnfuwsKZcQAAA6M"]
[Tue Jul 21 07:37:48.392691 2026] [security2:error] [pid 255769:tid 255827] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L_LxMYwyVGnfuwsKZcgADzTk"]
[Tue Jul 21 07:37:48.392886 2026] [security2:error] [pid 255769:tid 255941] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9L_LxMYwyVGnfuwsKZcgADzTk"]
[Tue Jul 21 07:37:48.399273 2026] [security2:error] [pid 255769:tid 255923] [client 34.14.85.22:62733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9L_LxMYwyVGnfuwsKZcwAAA7s"]
[Tue Jul 21 07:37:48.454889 2026] [security2:error] [pid 255769:tid 255813] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/semrush/x.php"] [unique_id "al9L_LxMYwyVGnfuwsKZdAAD6ys"], referer: http://aud-7.com/wp-content/plugins/semrush/x.php
[Tue Jul 21 07:37:48.655445 2026] [security2:error] [pid 254995:tid 255133] [client 20.197.195.24:51762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/info.php"] [unique_id "al9L_P7v0rlcEGmVraE_zQAAAyY"]
[Tue Jul 21 07:37:48.664059 2026] [security2:error] [pid 255769:tid 255975] [client 20.226.60.151:51351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/edorxrr.php"] [unique_id "al9L_LxMYwyVGnfuwsKZegAAA-8"]
[Tue Jul 21 07:37:48.761037 2026] [security2:error] [pid 255769:tid 256002] [client 103.174.34.15:59545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L_LxMYwyVGnfuwsKZhAAABAg"]
[Tue Jul 21 07:37:48.761174 2026] [security2:error] [pid 255769:tid 256002] [client 103.174.34.15:59545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L_LxMYwyVGnfuwsKZhAAABAg"]
[Tue Jul 21 07:37:48.849336 2026] [security2:error] [pid 254995:tid 255212] [client 34.14.85.22:54253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9L_P7v0rlcEGmVraE_0QAAA3Q"]
[Tue Jul 21 07:37:48.941305 2026] [security2:error] [pid 255769:tid 255946] [client 20.197.195.24:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/als.php"] [unique_id "al9L_LxMYwyVGnfuwsKZoQAAA9I"]
[Tue Jul 21 07:37:48.970320 2026] [security2:error] [pid 255769:tid 255993] [client 45.8.17.137:39579] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/content.php"] [unique_id "al9L_LxMYwyVGnfuwsKZpAAABAA"]
[Tue Jul 21 07:37:48.974955 2026] [security2:error] [pid 255769:tid 255881] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9L_LxMYwyVGnfuwsKZpQAD9G8"], referer: http://aud-7.com/wp-content/plugins/fix/up.php
[Tue Jul 21 07:37:49.319973 2026] [security2:error] [pid 254995:tid 255177] [client 34.14.85.22:49167] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9L_f7v0rlcEGmVraE_1wAAA1I"]
[Tue Jul 21 07:37:49.475673 2026] [security2:error] [pid 255769:tid 255917] [client 20.197.195.24:63649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/simple.php"] [unique_id "al9L_bxMYwyVGnfuwsKZuAAAA7U"]
[Tue Jul 21 07:37:49.489951 2026] [security2:error] [pid 255769:tid 255877] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/wpcall-button/button-image.php"] [unique_id "al9L_bxMYwyVGnfuwsKZuQADpGs"], referer: http://aud-7.com/wp-content/plugins/wpcall-button/button-image.php
[Tue Jul 21 07:37:49.723654 2026] [security2:error] [pid 255769:tid 255915] [client 20.197.195.24:63297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/init.php"] [unique_id "al9L_bxMYwyVGnfuwsKZyAAAA7M"]
[Tue Jul 21 07:37:49.742067 2026] [security2:error] [pid 255769:tid 255975] [client 34.14.85.22:56857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9L_bxMYwyVGnfuwsKZygAAA-8"]
[Tue Jul 21 07:37:49.791640 2026] [security2:error] [pid 255769:tid 255982] [client 173.252.95.40:50200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9L_LxMYwyVGnfuwsKZeQAAA_Y"]
[Tue Jul 21 07:37:49.907264 2026] [security2:error] [pid 255769:tid 255935] [client 136.144.33.97:44455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9L_bxMYwyVGnfuwsKZyQAAA8c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:49.953455 2026] [security2:error] [pid 255769:tid 255964] [client 59.96.220.140:60576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L_bxMYwyVGnfuwsKZ2wAAA-Q"]
[Tue Jul 21 07:37:49.954219 2026] [security2:error] [pid 255769:tid 255964] [client 59.96.220.140:60576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9L_bxMYwyVGnfuwsKZ2wAAA-Q"]
[Tue Jul 21 07:37:49.964778 2026] [security2:error] [pid 255769:tid 255951] [client 20.206.105.145:37907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/puc.php"] [unique_id "al9L_bxMYwyVGnfuwsKZ3AAAA9c"]
[Tue Jul 21 07:37:49.984875 2026] [security2:error] [pid 255769:tid 255901] [client 20.220.225.223:38659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/csa.php"] [unique_id "al9L_bxMYwyVGnfuwsKZ3wAAA6U"]
[Tue Jul 21 07:37:49.985635 2026] [security2:error] [pid 255769:tid 255953] [client 45.8.17.119:47463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/css/dist/block-library/"] [unique_id "al9L_bxMYwyVGnfuwsKZ4AAAA9k"]
[Tue Jul 21 07:37:50.003936 2026] [security2:error] [pid 255769:tid 255798] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ4gAEIhw"]
[Tue Jul 21 07:37:50.004067 2026] [security2:error] [pid 255769:tid 256028] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ4gAEIhw"]
[Tue Jul 21 07:37:50.148977 2026] [security2:error] [pid 255769:tid 255796] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/index.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ8AADtxo"], referer: http://aud-7.com/wp-content/plugins/index.php
[Tue Jul 21 07:37:50.234254 2026] [security2:error] [pid 255769:tid 255960] [client 34.14.85.22:57848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9L_rxMYwyVGnfuwsKZ8wAAA-A"]
[Tue Jul 21 07:37:50.238388 2026] [security2:error] [pid 255769:tid 256019] [client 37.140.223.119:53321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9L_bxMYwyVGnfuwsKZqgAABBk"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:37:50.239042 2026] [security2:error] [pid 254995:tid 255206] [client 20.197.195.24:63324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/fpwch.php"] [unique_id "al9L_v7v0rlcEGmVraE_4gAAA28"]
[Tue Jul 21 07:37:50.253026 2026] [security2:error] [pid 255769:tid 255965] [client 20.197.195.24:21067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/11.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ9AAAA-U"]
[Tue Jul 21 07:37:50.303036 2026] [security2:error] [pid 255769:tid 255983] [client 20.104.96.117:61179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/cilus.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ-QAAA_c"]
[Tue Jul 21 07:37:50.408215 2026] [security2:error] [pid 255769:tid 255944] [client 103.86.117.203:55141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ-gAAA9A"]
[Tue Jul 21 07:37:50.408344 2026] [security2:error] [pid 255769:tid 255944] [client 103.86.117.203:55141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ-gAAA9A"]
[Tue Jul 21 07:37:50.655990 2026] [security2:error] [pid 254995:tid 255252] [client 20.197.192.193:6339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/dp.php"] [unique_id "al9L_v7v0rlcEGmVraE_6wAAA4M"]
[Tue Jul 21 07:37:50.674509 2026] [security2:error] [pid 255769:tid 255800] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/advanced-llms-txt-generator/assets/css/css_json.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ_AADpB4"], referer: http://aud-7.com/wp-content/plugins/advanced-llms-txt-generator/assets/css/css_json.php
[Tue Jul 21 07:37:50.686487 2026] [security2:error] [pid 255769:tid 255990] [client 34.14.85.22:62674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9L_rxMYwyVGnfuwsKZ_QAAA_4"]
[Tue Jul 21 07:37:50.725453 2026] [security2:error] [pid 255769:tid 255945] [client 20.206.105.145:38503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/themes.php"] [unique_id "al9L_rxMYwyVGnfuwsKZ_gAAA9E"]
[Tue Jul 21 07:37:50.798697 2026] [security2:error] [pid 255769:tid 255902] [client 20.52.136.55:1585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/goods.php"] [unique_id "al9L_rxMYwyVGnfuwsKaAQAAA6Y"]
[Tue Jul 21 07:37:50.861187 2026] [security2:error] [pid 254995:tid 255050] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L_v7v0rlcEGmVraE_7wADSDY"]
[Tue Jul 21 07:37:50.861322 2026] [security2:error] [pid 254995:tid 255167] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9L_v7v0rlcEGmVraE_7wADSDY"]
[Tue Jul 21 07:37:50.887096 2026] [security2:error] [pid 254995:tid 255056] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9L_v7v0rlcEGmVraE_8QADdjw"]
[Tue Jul 21 07:37:51.195848 2026] [security2:error] [pid 255769:tid 255818] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/linkpreview/index.php"] [unique_id "al9L_7xMYwyVGnfuwsKaCAAD6DA"], referer: http://aud-7.com/wp-content/plugins/linkpreview/index.php
[Tue Jul 21 07:37:51.320095 2026] [security2:error] [pid 254995:tid 255053] [remote 82.102.18.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/xmlrpc.php"] [unique_id "al9L__7v0rlcEGmVraE_-QADbjk"]
[Tue Jul 21 07:37:51.384862 2026] [security2:error] [pid 255769:tid 255901] [client 20.197.195.24:63620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/domvf.php"] [unique_id "al9L_7xMYwyVGnfuwsKaCwAAA6U"]
[Tue Jul 21 07:37:51.386455 2026] [security2:error] [pid 254995:tid 255126] [client 20.104.96.117:59160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/gptsh.php"] [unique_id "al9L__7v0rlcEGmVraE_-wAAAx8"]
[Tue Jul 21 07:37:51.427087 2026] [security2:error] [pid 254995:tid 255129] [client 20.197.195.24:21054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/v2.php"] [unique_id "al9L__7v0rlcEGmVraE__gAAAyI"]
[Tue Jul 21 07:37:51.491243 2026] [security2:error] [pid 254995:tid 255276] [client 20.197.195.24:13286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp.php"] [unique_id "al9L__7v0rlcEGmVraFAAAAAA5o"]
[Tue Jul 21 07:37:51.554405 2026] [security2:error] [pid 254995:tid 255154] [client 20.197.195.24:63665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/class.php"] [unique_id "al9L__7v0rlcEGmVraFAAgAAAzs"]
[Tue Jul 21 07:37:51.555868 2026] [security2:error] [pid 255769:tid 256026] [client 20.206.105.145:38474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/dx.php"] [unique_id "al9L_7xMYwyVGnfuwsKaDgAABCA"]
[Tue Jul 21 07:37:51.593805 2026] [security2:error] [pid 255769:tid 255905] [client 20.197.195.24:62873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/echkm.php"] [unique_id "al9L_7xMYwyVGnfuwsKaDwAAA6k"]
[Tue Jul 21 07:37:51.636798 2026] [security2:error] [pid 254995:tid 255117] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9L__7v0rlcEGmVraFABAADgnk"]
[Tue Jul 21 07:37:51.705830 2026] [security2:error] [pid 255769:tid 255867] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9L_7xMYwyVGnfuwsKaFAADt2E"], referer: http://aud-7.com/wp-content/themes/index.php
[Tue Jul 21 07:37:51.769539 2026] [security2:error] [pid 254995:tid 255204] [client 20.197.195.24:62858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/lib.php"] [unique_id "al9L__7v0rlcEGmVraFABwAAA20"]
[Tue Jul 21 07:37:51.791646 2026] [security2:error] [pid 254995:tid 255111] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9L__7v0rlcEGmVraFACQADLXM"]
[Tue Jul 21 07:37:51.946029 2026] [security2:error] [pid 254995:tid 255069] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9L__7v0rlcEGmVraFADAADREk"]
[Tue Jul 21 07:37:52.045335 2026] [security2:error] [pid 255769:tid 255979] [client 20.104.96.117:61147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/rithin.php"] [unique_id "al9MALxMYwyVGnfuwsKaHgAAA_M"]
[Tue Jul 21 07:37:52.100123 2026] [security2:error] [pid 254995:tid 255107] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9MAP7v0rlcEGmVraFADwADTm8"]
[Tue Jul 21 07:37:52.176738 2026] [security2:error] [pid 255769:tid 255928] [client 20.197.195.24:63638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/login.php"] [unique_id "al9MALxMYwyVGnfuwsKaIAAAA8A"]
[Tue Jul 21 07:37:52.231197 2026] [security2:error] [pid 255769:tid 255808] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/builder-and-developer/inc/tgm/error.php"] [unique_id "al9MALxMYwyVGnfuwsKaIwAD1iY"], referer: http://aud-7.com/wp-content/themes/builder-and-developer/inc/tgm/error.php
[Tue Jul 21 07:37:52.254805 2026] [security2:error] [pid 254995:tid 255093] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9MAP7v0rlcEGmVraFAEgADYWE"]
[Tue Jul 21 07:37:52.266097 2026] [security2:error] [pid 254995:tid 255269] [client 20.197.195.24:21012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/panel.php"] [unique_id "al9MAP7v0rlcEGmVraFAEwAAA5M"]
[Tue Jul 21 07:37:52.311417 2026] [security2:error] [pid 255769:tid 255988] [client 20.151.10.161:46040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/zoro.php"] [unique_id "al9MALxMYwyVGnfuwsKaJAAAA_w"]
[Tue Jul 21 07:37:52.409919 2026] [security2:error] [pid 254995:tid 255013] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9MAP7v0rlcEGmVraFAFQADKhE"]
[Tue Jul 21 07:37:52.512617 2026] [security2:error] [pid 254995:tid 255131] [client 128.127.105.184:37736] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9L__7v0rlcEGmVraFAAQAAAyQ"]
[Tue Jul 21 07:37:52.512749 2026] [security2:error] [pid 254995:tid 255131] [client 128.127.105.184:37736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9L__7v0rlcEGmVraFAAQAAAyQ"]
[Tue Jul 21 07:37:52.525295 2026] [access_compat:error] [pid 254995:tid 255277] [client 162.241.63.68:30522] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:37:52.564949 2026] [security2:error] [pid 254995:tid 255024] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9MAP7v0rlcEGmVraFAGQADVBw"]
[Tue Jul 21 07:37:52.600827 2026] [security2:error] [pid 255769:tid 255945] [client 20.206.105.145:37943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/p.php"] [unique_id "al9MALxMYwyVGnfuwsKaJwAAA9E"]
[Tue Jul 21 07:37:52.661124 2026] [security2:error] [pid 255769:tid 255947] [client 20.220.225.223:38661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/min.php"] [unique_id "al9MALxMYwyVGnfuwsKaKgAAA9M"]
[Tue Jul 21 07:37:52.661158 2026] [security2:error] [pid 255769:tid 255902] [client 20.104.96.117:61148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/fffm.php"] [unique_id "al9MALxMYwyVGnfuwsKaKQAAA6Y"]
[Tue Jul 21 07:37:52.719829 2026] [security2:error] [pid 254995:tid 255015] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9MAP7v0rlcEGmVraFAGwADNhM"]
[Tue Jul 21 07:37:52.749701 2026] [security2:error] [pid 255769:tid 255839] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al9MALxMYwyVGnfuwsKaKwADo0U"], referer: http://aud-7.com/wp-content/themes/pridmag/db.php?u
[Tue Jul 21 07:37:52.794062 2026] [security2:error] [pid 255769:tid 255987] [client 194.99.104.35:33212] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MALxMYwyVGnfuwsKaKAAAA_s"]
[Tue Jul 21 07:37:52.794156 2026] [security2:error] [pid 255769:tid 255987] [client 194.99.104.35:33212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MALxMYwyVGnfuwsKaKAAAA_s"]
[Tue Jul 21 07:37:52.873667 2026] [security2:error] [pid 254995:tid 255116] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9MAP7v0rlcEGmVraFAHwADU3g"]
[Tue Jul 21 07:37:52.909866 2026] [security2:error] [pid 255769:tid 256014] [client 20.197.195.24:21013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/dex.php"] [unique_id "al9MALxMYwyVGnfuwsKaLwAABBQ"]
[Tue Jul 21 07:37:53.028932 2026] [security2:error] [pid 254995:tid 255010] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9MAf7v0rlcEGmVraFAIQADTw4"]
[Tue Jul 21 07:37:53.112068 2026] [security2:error] [pid 255769:tid 255999] [client 20.104.96.117:59136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/dfre.php"] [unique_id "al9MAbxMYwyVGnfuwsKaMQAABAU"]
[Tue Jul 21 07:37:53.157468 2026] [autoindex:error] [pid 255769:tid 255943] [client 20.206.105.145:38504] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:53.162904 2026] [security2:error] [pid 255769:tid 255932] [client 117.217.38.194:53190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MAbxMYwyVGnfuwsKaMwAAA8Q"]
[Tue Jul 21 07:37:53.163008 2026] [security2:error] [pid 255769:tid 255932] [client 117.217.38.194:53190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MAbxMYwyVGnfuwsKaMwAAA8Q"]
[Tue Jul 21 07:37:53.167503 2026] [security2:error] [pid 255769:tid 255982] [client 20.206.105.145:38504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/bthil.php"] [unique_id "al9MAbxMYwyVGnfuwsKaNAAAA_Y"]
[Tue Jul 21 07:37:53.203138 2026] [security2:error] [pid 254995:tid 255058] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9MAf7v0rlcEGmVraFAJgADKT4"]
[Tue Jul 21 07:37:53.274394 2026] [security2:error] [pid 255769:tid 255840] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "al9MAbxMYwyVGnfuwsKaNQAEGkY"], referer: http://aud-7.com/wp-content/themes/theme-check/theme-check.php
[Tue Jul 21 07:37:53.334254 2026] [security2:error] [pid 255769:tid 256006] [client 193.36.225.63:61157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MAbxMYwyVGnfuwsKaNwAABAw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:53.359131 2026] [security2:error] [pid 254995:tid 255104] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9MAf7v0rlcEGmVraFAKgADb2w"]
[Tue Jul 21 07:37:53.418125 2026] [security2:error] [pid 255769:tid 255920] [client 20.104.96.117:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/wp-happy.php"] [unique_id "al9MAbxMYwyVGnfuwsKaOQAAA7g"]
[Tue Jul 21 07:37:53.460373 2026] [security2:error] [pid 254995:tid 255141] [client 20.226.60.151:51314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/miru1.php"] [unique_id "al9MAf7v0rlcEGmVraFALAAAAy4"]
[Tue Jul 21 07:37:53.513519 2026] [security2:error] [pid 254995:tid 255045] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9MAf7v0rlcEGmVraFALQADYjE"]
[Tue Jul 21 07:37:53.514152 2026] [security2:error] [pid 254995:tid 255023] [remote 104.207.54.136:30305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.54.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9MAf7v0rlcEGmVraFAKQADVhs"]
[Tue Jul 21 07:37:53.667973 2026] [security2:error] [pid 254995:tid 255021] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9MAf7v0rlcEGmVraFAMgADQxk"]
[Tue Jul 21 07:37:53.788144 2026] [security2:error] [pid 255769:tid 255949] [client 173.24.185.52:57573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MAbxMYwyVGnfuwsKaQAAAA9U"]
[Tue Jul 21 07:37:53.788265 2026] [security2:error] [pid 255769:tid 255949] [client 173.24.185.52:57573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MAbxMYwyVGnfuwsKaQAAAA9U"]
[Tue Jul 21 07:37:53.790029 2026] [security2:error] [pid 255769:tid 255802] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/Divi/404.php"] [unique_id "al9MAbxMYwyVGnfuwsKaQQAD0iA"], referer: http://aud-7.com/wp-content/themes/Divi/404.php
[Tue Jul 21 07:37:53.822172 2026] [security2:error] [pid 254995:tid 255001] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9MAf7v0rlcEGmVraFAMwADXAU"]
[Tue Jul 21 07:37:53.879066 2026] [security2:error] [pid 255769:tid 255998] [client 45.8.17.146:62463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/post-terms/"] [unique_id "al9MAbxMYwyVGnfuwsKaQwAABAQ"]
[Tue Jul 21 07:37:53.970936 2026] [security2:error] [pid 255769:tid 255962] [client 20.206.105.145:38492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/7.php"] [unique_id "al9MAbxMYwyVGnfuwsKaRAAAA-I"]
[Tue Jul 21 07:37:53.975948 2026] [security2:error] [pid 254995:tid 255065] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ewfconstrucao.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9MAf7v0rlcEGmVraFANgADSEU"]
[Tue Jul 21 07:37:54.050539 2026] [security2:error] [pid 255769:tid 255966] [client 20.104.96.117:61145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/fpr4.php"] [unique_id "al9MArxMYwyVGnfuwsKaSAAAA-Y"]
[Tue Jul 21 07:37:54.245589 2026] [security2:error] [pid 255769:tid 256024] [client 20.197.195.24:51770] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "equoterapiaprosseguir.com"] [uri "/1.php"] [unique_id "al9MArxMYwyVGnfuwsKaSgAABB4"]
[Tue Jul 21 07:37:54.245703 2026] [security2:error] [pid 255769:tid 256024] [client 20.197.195.24:51770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/1.php"] [unique_id "al9MArxMYwyVGnfuwsKaSgAABB4"]
[Tue Jul 21 07:37:54.256875 2026] [security2:error] [pid 255769:tid 256016] [client 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/wp-admin/install.php"] [unique_id "al9MArxMYwyVGnfuwsKaSwAABBY"]
[Tue Jul 21 07:37:54.334001 2026] [security2:error] [pid 255769:tid 255953] [client 117.251.86.144:48168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaTwAAA9k"]
[Tue Jul 21 07:37:54.334135 2026] [security2:error] [pid 255769:tid 255953] [client 117.251.86.144:48168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaTwAAA9k"]
[Tue Jul 21 07:37:54.386886 2026] [security2:error] [pid 255769:tid 255922] [client 173.252.95.12:39850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9MArxMYwyVGnfuwsKaUgAAA7o"]
[Tue Jul 21 07:37:54.391190 2026] [security2:error] [pid 255769:tid 255990] [client 20.197.195.24:62867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/a2.php"] [unique_id "al9MArxMYwyVGnfuwsKaUwAAA_4"]
[Tue Jul 21 07:37:54.424355 2026] [security2:error] [pid 255769:tid 255902] [client 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9MArxMYwyVGnfuwsKaVAAAA6Y"]
[Tue Jul 21 07:37:54.521096 2026] [security2:error] [pid 254995:tid 255210] [client 20.206.105.145:37930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/8.php"] [unique_id "al9MAv7v0rlcEGmVraFAPwAAA3I"]
[Tue Jul 21 07:37:54.552134 2026] [security2:error] [pid 255769:tid 255967] [client 20.151.10.161:45981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/admin.php"] [unique_id "al9MArxMYwyVGnfuwsKaVQAAA-c"]
[Tue Jul 21 07:37:54.674393 2026] [security2:error] [pid 255769:tid 255912] [client 20.104.96.117:59179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/file88.php"] [unique_id "al9MArxMYwyVGnfuwsKaWQAAA7A"]
[Tue Jul 21 07:37:54.733203 2026] [security2:error] [pid 255769:tid 255952] [client 62.102.148.187:58438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaWgAAA9g"]
[Tue Jul 21 07:37:54.733328 2026] [security2:error] [pid 255769:tid 255952] [client 62.102.148.187:58438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaWgAAA9g"]
[Tue Jul 21 07:37:54.778656 2026] [security2:error] [pid 255769:tid 256021] [client 103.162.129.114:56385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaWwAABBs"]
[Tue Jul 21 07:37:54.778793 2026] [security2:error] [pid 255769:tid 256021] [client 103.162.129.114:56385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaWwAABBs"]
[Tue Jul 21 07:37:54.916773 2026] [security2:error] [pid 255769:tid 255950] [client 122.186.204.214:58596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaXQAAA9Y"]
[Tue Jul 21 07:37:54.916889 2026] [security2:error] [pid 255769:tid 255950] [client 122.186.204.214:58596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MArxMYwyVGnfuwsKaXQAAA9Y"]
[Tue Jul 21 07:37:54.934706 2026] [security2:error] [pid 255769:tid 255956] [client 172.245.102.34:38685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MArxMYwyVGnfuwsKaXgAAA9w"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:37:54.975275 2026] [security2:error] [pid 255769:tid 255964] [client 45.8.17.122:22549] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/b.php"] [unique_id "al9MArxMYwyVGnfuwsKaXwAAA-Q"]
[Tue Jul 21 07:37:55.062516 2026] [security2:error] [pid 254995:tid 255265] [client 20.206.105.145:38089] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.liranesuliano.com.br"] [uri "/1.php"] [unique_id "al9MA_7v0rlcEGmVraFARgAAA48"]
[Tue Jul 21 07:37:55.062633 2026] [security2:error] [pid 254995:tid 255265] [client 20.206.105.145:38089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/1.php"] [unique_id "al9MA_7v0rlcEGmVraFARgAAA48"]
[Tue Jul 21 07:37:55.074819 2026] [security2:error] [pid 255769:tid 256017] [client 20.197.195.24:63672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/d61.php"] [unique_id "al9MA7xMYwyVGnfuwsKaYAAABBc"]
[Tue Jul 21 07:37:55.082030 2026] [security2:error] [pid 255769:tid 255884] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MA7xMYwyVGnfuwsKaYQADv3I"]
[Tue Jul 21 07:37:55.082178 2026] [security2:error] [pid 255769:tid 255927] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MA7xMYwyVGnfuwsKaYQADv3I"]
[Tue Jul 21 07:37:55.136026 2026] [security2:error] [pid 255769:tid 255968] [client 20.104.96.117:61109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ccc.php"] [unique_id "al9MA7xMYwyVGnfuwsKaZQAAA-g"]
[Tue Jul 21 07:37:55.161345 2026] [security2:error] [pid 254995:tid 255262] [client 20.220.225.223:38690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/jj.php"] [unique_id "al9MA_7v0rlcEGmVraFASAAAA4w"]
[Tue Jul 21 07:37:55.268420 2026] [security2:error] [pid 254995:tid 255083] [remote 152.42.137.70:32984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.137.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-login.php"] [unique_id "al9MA_7v0rlcEGmVraFASgADOVc"]
[Tue Jul 21 07:37:55.278936 2026] [security2:error] [pid 255769:tid 255928] [client 20.197.195.24:51791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/ms.php"] [unique_id "al9MA7xMYwyVGnfuwsKabgAAA8A"]
[Tue Jul 21 07:37:55.307057 2026] [security2:error] [pid 255769:tid 255970] [client 139.167.225.182:64867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MA7xMYwyVGnfuwsKaZgAAA-o"]
[Tue Jul 21 07:37:55.307156 2026] [security2:error] [pid 255769:tid 255970] [client 139.167.225.182:64867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MA7xMYwyVGnfuwsKaZgAAA-o"]
[Tue Jul 21 07:37:55.481835 2026] [security2:error] [pid 255769:tid 255816] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/bltm/wp-login.php"] [unique_id "al9MArxMYwyVGnfuwsKaTgAD_C4"], referer: http://aud-7.com/wp-content/themes/bltm/wp-login.php
[Tue Jul 21 07:37:55.653934 2026] [security2:error] [pid 255769:tid 255852] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MA7xMYwyVGnfuwsKadQAD6VI"]
[Tue Jul 21 07:37:55.654127 2026] [security2:error] [pid 255769:tid 255969] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MA7xMYwyVGnfuwsKadQAD6VI"]
[Tue Jul 21 07:37:55.888917 2026] [security2:error] [pid 255769:tid 255951] [client 20.226.60.151:51281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/sump1.php"] [unique_id "al9MA7xMYwyVGnfuwsKaegAAA9c"]
[Tue Jul 21 07:37:55.934140 2026] [security2:error] [pid 255769:tid 255910] [client 20.206.105.145:38491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/100.php"] [unique_id "al9MA7xMYwyVGnfuwsKafAAAA64"]
[Tue Jul 21 07:37:55.961178 2026] [security2:error] [pid 255769:tid 256020] [client 20.104.96.117:61087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/777.php"] [unique_id "al9MA7xMYwyVGnfuwsKafgAABBo"]
[Tue Jul 21 07:37:55.996893 2026] [security2:error] [pid 255769:tid 255777] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9MA7xMYwyVGnfuwsKafwADuwc"], referer: http://aud-7.com/wp-content/themes/seotheme/db.php?u
[Tue Jul 21 07:37:56.008439 2026] [security2:error] [pid 255769:tid 256021] [client 20.197.195.24:63641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/info.php"] [unique_id "al9MBLxMYwyVGnfuwsKagAAABBs"]
[Tue Jul 21 07:37:56.091093 2026] [security2:error] [pid 255769:tid 255956] [client 20.151.10.161:45991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/greap.php"] [unique_id "al9MBLxMYwyVGnfuwsKaggAAA9w"]
[Tue Jul 21 07:37:56.184002 2026] [security2:error] [pid 255769:tid 255964] [client 45.8.17.137:41093] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/blocks/audio/"] [unique_id "al9MBLxMYwyVGnfuwsKagwAAA-Q"]
[Tue Jul 21 07:37:56.232186 2026] [autoindex:error] [pid 254995:tid 255273] [client 20.197.195.24:21103] AH01276: Cannot serve directory /home3/equote29/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:37:56.241312 2026] [security2:error] [pid 254995:tid 255274] [client 20.197.195.24:21103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/memberfuns.php"] [unique_id "al9MBP7v0rlcEGmVraFAXQAAA5g"]
[Tue Jul 21 07:37:56.315105 2026] [security2:error] [pid 254995:tid 255171] [client 128.127.105.184:37750] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MBP7v0rlcEGmVraFAXgAAA0w"]
[Tue Jul 21 07:37:56.315215 2026] [security2:error] [pid 254995:tid 255171] [client 128.127.105.184:37750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MBP7v0rlcEGmVraFAXgAAA0w"]
[Tue Jul 21 07:37:56.364919 2026] [http2:info] [pid 255769:tid 255968] [client 162.158.163.150:14241] AH10180: h2_stream(255769-1264-1,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:37:56.513841 2026] [security2:error] [pid 255769:tid 255905] [client 74.7.241.178:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eltonrpferreira1782856652665.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9MBLxMYwyVGnfuwsKaigADqUc"]
[Tue Jul 21 07:37:56.516616 2026] [security2:error] [pid 255769:tid 255891] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "al9MBLxMYwyVGnfuwsKaiwAECXk"], referer: http://aud-7.com/wp-content/themes/twentytwentythree/patterns/index.php
[Tue Jul 21 07:37:56.685905 2026] [security2:error] [pid 255769:tid 255926] [client 20.220.225.223:38703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/dragonshell.php"] [unique_id "al9MBLxMYwyVGnfuwsKakAAAA74"]
[Tue Jul 21 07:37:56.692182 2026] [http2:info] [pid 255769:tid 255966] [client 162.158.163.150:14241] AH10180: h2_stream(255769-1264-3,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:37:56.767965 2026] [security2:error] [pid 255769:tid 255970] [client 20.104.96.117:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/for.php"] [unique_id "al9MBLxMYwyVGnfuwsKalAAAA-o"]
[Tue Jul 21 07:37:56.783038 2026] [security2:error] [pid 255769:tid 255875] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBLxMYwyVGnfuwsKalgADt2k"]
[Tue Jul 21 07:37:56.783231 2026] [security2:error] [pid 255769:tid 255919] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBLxMYwyVGnfuwsKalgADt2k"]
[Tue Jul 21 07:37:56.784169 2026] [security2:error] [pid 254995:tid 255137] [client 175.45.70.82:63975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBP7v0rlcEGmVraFAZQAAAyo"]
[Tue Jul 21 07:37:56.784264 2026] [security2:error] [pid 254995:tid 255137] [client 175.45.70.82:63975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBP7v0rlcEGmVraFAZQAAAyo"]
[Tue Jul 21 07:37:56.871366 2026] [security2:error] [pid 254995:tid 255156] [client 20.151.10.161:46056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/177.php"] [unique_id "al9MBP7v0rlcEGmVraFAZwAAAz0"]
[Tue Jul 21 07:37:56.934791 2026] [security2:error] [pid 254995:tid 255215] [client 20.197.195.24:63322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/11.php"] [unique_id "al9MBP7v0rlcEGmVraFAaAAAA3c"]
[Tue Jul 21 07:37:57.013721 2026] [http2:info] [pid 255769:tid 255934] [client 162.158.163.150:14241] AH10180: h2_stream(255769-1264-5,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:37:57.030038 2026] [security2:error] [pid 255769:tid 255809] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/SecurityFin/SecurityFin.php"] [unique_id "al9MBbxMYwyVGnfuwsKamAAD0Sc"], referer: http://aud-7.com/wp-content/plugins/SecurityFin/SecurityFin.php
[Tue Jul 21 07:37:57.225910 2026] [security2:error] [pid 254995:tid 255160] [client 20.206.105.145:38516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/about.php"] [unique_id "al9MBf7v0rlcEGmVraFAbgAAA0E"]
[Tue Jul 21 07:37:57.260902 2026] [security2:error] [pid 254995:tid 255170] [client 122.162.144.145:4708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MBf7v0rlcEGmVraFAbwAAA0s"]
[Tue Jul 21 07:37:57.261005 2026] [security2:error] [pid 254995:tid 255170] [client 122.162.144.145:4708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MBf7v0rlcEGmVraFAbwAAA0s"]
[Tue Jul 21 07:37:57.263214 2026] [security2:error] [pid 254995:tid 255144] [client 154.192.233.199:59837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBf7v0rlcEGmVraFAcAAAAzE"]
[Tue Jul 21 07:37:57.263336 2026] [security2:error] [pid 254995:tid 255144] [client 154.192.233.199:59837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBf7v0rlcEGmVraFAcAAAAzE"]
[Tue Jul 21 07:37:57.275201 2026] [security2:error] [pid 254995:tid 255130] [client 45.8.17.141:37499] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/class-db.php"] [unique_id "al9MBf7v0rlcEGmVraFAcgAAAyM"]
[Tue Jul 21 07:37:57.282092 2026] [security2:error] [pid 254995:tid 255217] [client 20.197.195.24:51746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/0.php"] [unique_id "al9MBf7v0rlcEGmVraFAcwAAA3k"]
[Tue Jul 21 07:37:57.340375 2026] [http2:info] [pid 255769:tid 255911] [client 162.158.163.150:14241] AH10180: h2_stream(255769-1264-7,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:37:57.391261 2026] [security2:error] [pid 254995:tid 255147] [client 20.226.60.151:27595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file5.php"] [unique_id "al9MBf7v0rlcEGmVraFAdQAAAzQ"]
[Tue Jul 21 07:37:57.487082 2026] [security2:error] [pid 255769:tid 255915] [client 20.197.195.24:63664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/v2.php"] [unique_id "al9MBbxMYwyVGnfuwsKangAAA7M"]
[Tue Jul 21 07:37:57.556288 2026] [security2:error] [pid 255769:tid 255939] [client 184.75.223.211:58094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MBbxMYwyVGnfuwsKaoAAAA8s"]
[Tue Jul 21 07:37:57.556424 2026] [security2:error] [pid 255769:tid 255939] [client 184.75.223.211:58094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MBbxMYwyVGnfuwsKaoAAAA8s"]
[Tue Jul 21 07:37:57.562162 2026] [security2:error] [pid 255769:tid 255846] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/file-upload-types/assets/css/403x.php"] [unique_id "al9MBbxMYwyVGnfuwsKaogAEFEw"], referer: http://aud-7.com/wp-content/plugins/file-upload-types/assets/css/403x.php
[Tue Jul 21 07:37:57.608639 2026] [security2:error] [pid 254995:tid 255257] [client 103.106.20.201:53166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBf7v0rlcEGmVraFAfwAAA4c"]
[Tue Jul 21 07:37:57.609309 2026] [security2:error] [pid 254995:tid 255257] [client 103.106.20.201:53166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBf7v0rlcEGmVraFAfwAAA4c"]
[Tue Jul 21 07:37:57.670766 2026] [http2:info] [pid 255769:tid 255912] [client 162.158.163.150:14241] AH10180: h2_stream(255769-1264-9,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:37:57.674027 2026] [security2:error] [pid 255769:tid 255981] [client 20.104.96.117:59701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/ssla.php"] [unique_id "al9MBbxMYwyVGnfuwsKapgAAA_U"]
[Tue Jul 21 07:37:57.769003 2026] [security2:error] [pid 255769:tid 255921] [client 20.226.60.151:51374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file5.php"] [unique_id "al9MBbxMYwyVGnfuwsKapwAAA7k"]
[Tue Jul 21 07:37:57.955571 2026] [security2:error] [pid 254995:tid 255208] [client 20.151.10.161:46044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/199.php"] [unique_id "al9MBf7v0rlcEGmVraFAhwAAA3A"]
[Tue Jul 21 07:37:58.100258 2026] [security2:error] [pid 255769:tid 255869] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/penci-bookmark-follow/inc/admin/forms/penci-bf-users-logs-profile.php"] [unique_id "al9MBrxMYwyVGnfuwsKaqwAEImM"], referer: http://aud-7.com/wp-content/plugins/penci-bookmark-follow/inc/admin/forms/penci-bf-users-logs-profile.php
[Tue Jul 21 07:37:58.192706 2026] [security2:error] [pid 255769:tid 255937] [client 20.197.195.24:20993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/BDKR28.php"] [unique_id "al9MBrxMYwyVGnfuwsKargAAA8k"]
[Tue Jul 21 07:37:58.298429 2026] [security2:error] [pid 255769:tid 255950] [client 193.36.225.10:64369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MBrxMYwyVGnfuwsKarQAAA9Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:37:58.372317 2026] [security2:error] [pid 254995:tid 255131] [client 45.8.17.117:39225] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/readme.php"] [unique_id "al9MBv7v0rlcEGmVraFAjgAAAyQ"]
[Tue Jul 21 07:37:58.530276 2026] [security2:error] [pid 254995:tid 255254] [client 20.104.96.117:59176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gssbrasil.com.br"] [uri "/zc-131.php"] [unique_id "al9MBv7v0rlcEGmVraFAkAAAA4Q"]
[Tue Jul 21 07:37:58.620765 2026] [security2:error] [pid 255769:tid 255866] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/penci-mobile-templates/functions.php"] [unique_id "al9MBrxMYwyVGnfuwsKasQADqWA"], referer: http://aud-7.com/wp-content/plugins/penci-mobile-templates/functions.php
[Tue Jul 21 07:37:58.741198 2026] [security2:error] [pid 255769:tid 255971] [client 20.206.105.145:38226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/admin.php"] [unique_id "al9MBrxMYwyVGnfuwsKaswAAA-s"]
[Tue Jul 21 07:37:58.763166 2026] [security2:error] [pid 255769:tid 255982] [client 152.59.154.239:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBrxMYwyVGnfuwsKatAAAA_Y"]
[Tue Jul 21 07:37:58.767876 2026] [security2:error] [pid 255769:tid 255982] [client 152.59.154.239:59194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MBrxMYwyVGnfuwsKatAAAA_Y"]
[Tue Jul 21 07:37:58.897384 2026] [security2:error] [pid 255769:tid 255979] [client 20.151.10.161:46067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file52.php"] [unique_id "al9MBrxMYwyVGnfuwsKatwAAA_M"]
[Tue Jul 21 07:37:58.901170 2026] [security2:error] [pid 254995:tid 255052] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MBv7v0rlcEGmVraFAlwADTTg"]
[Tue Jul 21 07:37:58.901372 2026] [security2:error] [pid 254995:tid 255172] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MBv7v0rlcEGmVraFAlwADTTg"]
[Tue Jul 21 07:37:58.966751 2026] [security2:error] [pid 255769:tid 255970] [client 20.197.195.24:63328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/panel.php"] [unique_id "al9MBrxMYwyVGnfuwsKaugAAA-o"]
[Tue Jul 21 07:37:59.084834 2026] [security2:error] [pid 255769:tid 255969] [client 122.164.127.47:55979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MB7xMYwyVGnfuwsKauwAAA-k"]
[Tue Jul 21 07:37:59.086670 2026] [security2:error] [pid 255769:tid 255969] [client 122.164.127.47:55979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MB7xMYwyVGnfuwsKauwAAA-k"]
[Tue Jul 21 07:37:59.143775 2026] [security2:error] [pid 255769:tid 255848] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "al9MB7xMYwyVGnfuwsKavAAEFk4"], referer: http://aud-7.com/wp-content/plugins/dummyyummy/wp-signup.php
[Tue Jul 21 07:37:59.182487 2026] [security2:error] [pid 255769:tid 255986] [client 45.8.17.135:45339] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/files/index.php"] [unique_id "al9MB7xMYwyVGnfuwsKavQAAA_o"]
[Tue Jul 21 07:37:59.199759 2026] [security2:error] [pid 255769:tid 255859] [remote 45.3.41.202:33757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9MBrxMYwyVGnfuwsKarwAD2Fk"]
[Tue Jul 21 07:37:59.245181 2026] [security2:error] [pid 254995:tid 255137] [client 193.36.225.118:43843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MB_7v0rlcEGmVraFAmQAAAyo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:37:59.371983 2026] [security2:error] [pid 254995:tid 255174] [client 20.197.195.24:21073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/green1.php"] [unique_id "al9MB_7v0rlcEGmVraFAoAAAA08"]
[Tue Jul 21 07:37:59.428249 2026] [security2:error] [pid 255769:tid 255899] [client 20.197.192.193:6341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/old.php"] [unique_id "al9MB7xMYwyVGnfuwsKaxAAAA6M"]
[Tue Jul 21 07:37:59.511570 2026] [security2:error] [pid 255769:tid 255926] [client 103.174.34.15:60035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MB7xMYwyVGnfuwsKayAAAA74"]
[Tue Jul 21 07:37:59.511675 2026] [security2:error] [pid 255769:tid 255926] [client 103.174.34.15:60035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MB7xMYwyVGnfuwsKayAAAA74"]
[Tue Jul 21 07:37:59.586430 2026] [security2:error] [pid 255769:tid 255987] [client 20.220.225.223:38693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/echkm.php"] [unique_id "al9MB7xMYwyVGnfuwsKaywAAA_s"]
[Tue Jul 21 07:37:59.651524 2026] [security2:error] [pid 255769:tid 255912] [client 4.204.201.85:55495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MB7xMYwyVGnfuwsKazgAAA7A"]
[Tue Jul 21 07:37:59.661151 2026] [security2:error] [pid 255769:tid 255886] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/core/core.php"] [unique_id "al9MB7xMYwyVGnfuwsKazwAD9XQ"], referer: http://aud-7.com/wp-content/plugins/core/core.php
[Tue Jul 21 07:37:59.869328 2026] [security2:error] [pid 255769:tid 255935] [client 184.75.223.211:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9MB7xMYwyVGnfuwsKa1gAAA8c"]
[Tue Jul 21 07:37:59.869415 2026] [security2:error] [pid 255769:tid 255935] [client 184.75.223.211:46002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9MB7xMYwyVGnfuwsKa1gAAA8c"]
[Tue Jul 21 07:37:59.937508 2026] [security2:error] [pid 255769:tid 255990] [client 184.154.139.46:36456] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "diskvidros.com.br"] [uri "/index.php"] [unique_id "al9MB7xMYwyVGnfuwsKayQAAA_4"]
[Tue Jul 21 07:37:59.958144 2026] [security2:error] [pid 254995:tid 255194] [client 20.52.136.55:1567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/init.php"] [unique_id "al9MB_7v0rlcEGmVraFAqAAAA2M"]
[Tue Jul 21 07:37:59.961996 2026] [security2:error] [pid 254995:tid 255223] [client 4.204.201.85:55991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MB_7v0rlcEGmVraFAqgAAA38"]
[Tue Jul 21 07:37:59.997898 2026] [security2:error] [pid 255769:tid 255937] [client 20.197.195.24:63669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/dex.php"] [unique_id "al9MB7xMYwyVGnfuwsKa1wAAA8k"]
[Tue Jul 21 07:38:00.176521 2026] [security2:error] [pid 255769:tid 255833] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/schema/yanz.php"] [unique_id "al9MCLxMYwyVGnfuwsKa2QAD1T8"], referer: http://aud-7.com/wp-content/plugins/schema/yanz.php
[Tue Jul 21 07:38:00.276760 2026] [security2:error] [pid 254995:tid 255144] [client 45.8.17.123:49431] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "al9MCP7v0rlcEGmVraFArgAAAzE"]
[Tue Jul 21 07:38:00.347100 2026] [security2:error] [pid 255769:tid 255965] [client 20.226.60.151:51268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/0xD.php"] [unique_id "al9MCLxMYwyVGnfuwsKa2wAAA-U"]
[Tue Jul 21 07:38:00.347624 2026] [security2:error] [pid 254995:tid 255261] [client 4.204.201.85:57100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/x.php"] [unique_id "al9MCP7v0rlcEGmVraFAsQAAA4s"]
[Tue Jul 21 07:38:00.372081 2026] [security2:error] [pid 254995:tid 255150] [client 20.197.192.193:6347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/ms-new.php"] [unique_id "al9MCP7v0rlcEGmVraFAsgAAAzc"]
[Tue Jul 21 07:38:00.593616 2026] [security2:error] [pid 255769:tid 256016] [client 20.197.195.24:51764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/nc4.php"] [unique_id "al9MCLxMYwyVGnfuwsKa4wAABBY"]
[Tue Jul 21 07:38:00.664915 2026] [security2:error] [pid 255769:tid 255954] [client 4.204.201.85:57123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/mgrr.php"] [unique_id "al9MCLxMYwyVGnfuwsKbCQAAA9o"]
[Tue Jul 21 07:38:00.682102 2026] [security2:error] [pid 255769:tid 255810] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MCLxMYwyVGnfuwsKbCgAD4Sg"]
[Tue Jul 21 07:38:00.682265 2026] [security2:error] [pid 255769:tid 255961] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MCLxMYwyVGnfuwsKbCgAD4Sg"]
[Tue Jul 21 07:38:00.826054 2026] [security2:error] [pid 255769:tid 255894] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/pwnd-1/pwnd.php"] [unique_id "al9MCLxMYwyVGnfuwsKbGAAD3Xw"], referer: http://aud-7.com/wp-content/plugins/pwnd-1/pwnd.php
[Tue Jul 21 07:38:00.868012 2026] [security2:error] [pid 255769:tid 255946] [client 103.86.117.203:55662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MCLxMYwyVGnfuwsKbHgAAA9I"]
[Tue Jul 21 07:38:00.868173 2026] [security2:error] [pid 255769:tid 255946] [client 103.86.117.203:55662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MCLxMYwyVGnfuwsKbHgAAA9I"]
[Tue Jul 21 07:38:00.888108 2026] [security2:error] [pid 255769:tid 255936] [client 20.151.10.161:46021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/122.php"] [unique_id "al9MCLxMYwyVGnfuwsKbHwAAA8g"]
[Tue Jul 21 07:38:00.932718 2026] [security2:error] [pid 254995:tid 255266] [client 20.197.192.193:6870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/track.php"] [unique_id "al9MCP7v0rlcEGmVraFAuAAAA5A"]
[Tue Jul 21 07:38:00.974485 2026] [security2:error] [pid 254995:tid 255211] [client 4.204.201.85:57167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/stdin.php"] [unique_id "al9MCP7v0rlcEGmVraFAugAAA3M"]
[Tue Jul 21 07:38:01.260740 2026] [security2:error] [pid 255769:tid 255922] [client 4.204.201.85:57180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/BDKR28.php"] [unique_id "al9MCbxMYwyVGnfuwsKbKQAAA7o"]
[Tue Jul 21 07:38:01.343000 2026] [security2:error] [pid 255769:tid 255872] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/plugins/init-help/init.php"] [unique_id "al9MCbxMYwyVGnfuwsKbLAAED2Y"], referer: http://aud-7.com/wp-content/plugins/init-help/init.php
[Tue Jul 21 07:38:01.476238 2026] [security2:error] [pid 254995:tid 255208] [client 45.8.17.60:21087] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/js/"] [unique_id "al9MCf7v0rlcEGmVraFAwQAAA3A"]
[Tue Jul 21 07:38:01.481419 2026] [security2:error] [pid 255769:tid 256021] [client 20.197.192.193:6370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/2352356666.php"] [unique_id "al9MCbxMYwyVGnfuwsKbLwAABBs"]
[Tue Jul 21 07:38:01.539792 2026] [security2:error] [pid 254995:tid 255140] [client 4.204.201.85:57206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/001.php"] [unique_id "al9MCf7v0rlcEGmVraFAwgAAAy0"]
[Tue Jul 21 07:38:01.590377 2026] [security2:error] [pid 254995:tid 255173] [client 20.197.195.24:63348] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "evelinemilfontadv.com"] [uri "/1.php"] [unique_id "al9MCf7v0rlcEGmVraFAxAAAA04"]
[Tue Jul 21 07:38:01.590496 2026] [security2:error] [pid 254995:tid 255173] [client 20.197.195.24:63348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/1.php"] [unique_id "al9MCf7v0rlcEGmVraFAxAAAA04"]
[Tue Jul 21 07:38:01.605562 2026] [security2:error] [pid 255769:tid 255901] [client 59.96.220.140:61087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MCbxMYwyVGnfuwsKbNAAAA6U"]
[Tue Jul 21 07:38:01.606091 2026] [security2:error] [pid 255769:tid 255901] [client 59.96.220.140:61087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MCbxMYwyVGnfuwsKbNAAAA6U"]
[Tue Jul 21 07:38:01.648703 2026] [security2:error] [pid 254995:tid 255094] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MCf7v0rlcEGmVraFAxgADQmI"]
[Tue Jul 21 07:38:01.649046 2026] [security2:error] [pid 254995:tid 255161] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MCf7v0rlcEGmVraFAxgADQmI"]
[Tue Jul 21 07:38:01.720795 2026] [security2:error] [pid 255769:tid 255970] [client 20.206.105.145:37916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/edit.php"] [unique_id "al9MCbxMYwyVGnfuwsKbOAAAA-o"]
[Tue Jul 21 07:38:01.830885 2026] [security2:error] [pid 254995:tid 255202] [client 4.204.201.85:57213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/dZ3wP5.php"] [unique_id "al9MCf7v0rlcEGmVraFAygAAA2s"]
[Tue Jul 21 07:38:01.859535 2026] [security2:error] [pid 255769:tid 255850] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/languages/index.php"] [unique_id "al9MCbxMYwyVGnfuwsKbPAADwFA"], referer: http://aud-7.com/wp-content/languages/index.php
[Tue Jul 21 07:38:01.894286 2026] [security2:error] [pid 255769:tid 255969] [client 20.197.195.24:51811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/a1.php"] [unique_id "al9MCbxMYwyVGnfuwsKbPQAAA-k"]
[Tue Jul 21 07:38:01.946313 2026] [security2:error] [pid 255769:tid 255962] [client 193.36.225.62:44783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MCbxMYwyVGnfuwsKbPgAAA-I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:01.987992 2026] [security2:error] [pid 255769:tid 255953] [client 20.52.136.55:1747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/settings.php"] [unique_id "al9MCbxMYwyVGnfuwsKbQQAAA9k"]
[Tue Jul 21 07:38:02.097986 2026] [security2:error] [pid 254995:tid 255263] [client 194.99.104.35:53842] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MCv7v0rlcEGmVraFA0AAAA40"]
[Tue Jul 21 07:38:02.098146 2026] [security2:error] [pid 254995:tid 255263] [client 194.99.104.35:53842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MCv7v0rlcEGmVraFA0AAAA40"]
[Tue Jul 21 07:38:02.117497 2026] [security2:error] [pid 255769:tid 255976] [client 4.204.201.85:55543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/yup.php"] [unique_id "al9MCrxMYwyVGnfuwsKbQwAAA_A"]
[Tue Jul 21 07:38:02.226145 2026] [security2:error] [pid 255769:tid 255967] [client 194.99.104.35:53858] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MCrxMYwyVGnfuwsKbRgAAA-c"]
[Tue Jul 21 07:38:02.226232 2026] [security2:error] [pid 255769:tid 255967] [client 194.99.104.35:53858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MCrxMYwyVGnfuwsKbRgAAA-c"]
[Tue Jul 21 07:38:02.235075 2026] [security2:error] [pid 255769:tid 255992] [client 20.197.195.24:21066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/eee.php"] [unique_id "al9MCrxMYwyVGnfuwsKbSAAAA_8"]
[Tue Jul 21 07:38:02.327273 2026] [security2:error] [pid 255769:tid 255951] [client 20.220.225.223:38716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/wp-mt.php"] [unique_id "al9MCrxMYwyVGnfuwsKbSgAAA9c"]
[Tue Jul 21 07:38:02.376356 2026] [security2:error] [pid 255769:tid 255910] [client 45.8.17.112:36029] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-includes/Requests/library/"] [unique_id "al9MCrxMYwyVGnfuwsKbTQAAA64"]
[Tue Jul 21 07:38:02.379565 2026] [security2:error] [pid 255769:tid 255891] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/languages/plugins/index.php"] [unique_id "al9MCrxMYwyVGnfuwsKbTgAD4Hk"], referer: http://aud-7.com/wp-content/languages/plugins/index.php
[Tue Jul 21 07:38:02.395650 2026] [security2:error] [pid 254995:tid 255268] [client 20.197.195.24:21072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-aothait.php"] [unique_id "al9MCv7v0rlcEGmVraFA2QAAA5I"]
[Tue Jul 21 07:38:02.400344 2026] [security2:error] [pid 254995:tid 255206] [client 4.204.201.85:55999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/X.php"] [unique_id "al9MCv7v0rlcEGmVraFA2gAAA28"]
[Tue Jul 21 07:38:02.449463 2026] [security2:error] [pid 255769:tid 255948] [client 20.226.60.151:27540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/222.php"] [unique_id "al9MCrxMYwyVGnfuwsKbUwAAA9Q"]
[Tue Jul 21 07:38:02.691480 2026] [security2:error] [pid 254995:tid 255174] [client 4.204.201.85:55527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/1polka.php"] [unique_id "al9MCv7v0rlcEGmVraFA4AAAA08"]
[Tue Jul 21 07:38:02.694828 2026] [security2:error] [pid 254995:tid 255255] [client 20.197.195.24:21047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/config.json.php"] [unique_id "al9MCv7v0rlcEGmVraFA4QAAA4U"]
[Tue Jul 21 07:38:02.820440 2026] [security2:error] [pid 254995:tid 255176] [client 139.167.225.182:65520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MCv7v0rlcEGmVraFA4gAAA1E"]
[Tue Jul 21 07:38:02.820571 2026] [security2:error] [pid 254995:tid 255176] [client 139.167.225.182:65520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MCv7v0rlcEGmVraFA4gAAA1E"]
[Tue Jul 21 07:38:02.897977 2026] [security2:error] [pid 255769:tid 255779] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/languages/themes/index.php"] [unique_id "al9MCrxMYwyVGnfuwsKbWAAD1gk"], referer: http://aud-7.com/wp-content/languages/themes/index.php
[Tue Jul 21 07:38:02.973531 2026] [security2:error] [pid 255769:tid 256003] [client 4.204.201.85:57165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/gec.php"] [unique_id "al9MCrxMYwyVGnfuwsKbWgAABAk"]
[Tue Jul 21 07:38:03.089060 2026] [security2:error] [pid 255769:tid 255965] [client 20.52.136.55:1597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/g.php"] [unique_id "al9MC7xMYwyVGnfuwsKbXgAAA-U"]
[Tue Jul 21 07:38:03.252391 2026] [security2:error] [pid 254995:tid 255198] [client 4.204.201.85:55986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/sky.php"] [unique_id "al9MC_7v0rlcEGmVraFA6QAAA2c"]
[Tue Jul 21 07:38:03.358800 2026] [security2:error] [pid 255769:tid 255958] [client 20.206.105.145:38513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MC7xMYwyVGnfuwsKbYwAAA94"]
[Tue Jul 21 07:38:03.412112 2026] [security2:error] [pid 255769:tid 255783] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/fonts/index.php"] [unique_id "al9MC7xMYwyVGnfuwsKbZAADxg0"], referer: http://aud-7.com/wp-content/fonts/index.php
[Tue Jul 21 07:38:03.543547 2026] [security2:error] [pid 255769:tid 255957] [client 4.204.201.85:57183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/fffm.php"] [unique_id "al9MC7xMYwyVGnfuwsKbZgAAA90"]
[Tue Jul 21 07:38:03.572820 2026] [security2:error] [pid 255769:tid 255944] [client 45.8.17.57:36553] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/twentytwentyfour/"] [unique_id "al9MC7xMYwyVGnfuwsKbZwAAA9A"]
[Tue Jul 21 07:38:03.626528 2026] [security2:error] [pid 255769:tid 255925] [client 117.217.38.194:53666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MC7xMYwyVGnfuwsKbaAAAA70"]
[Tue Jul 21 07:38:03.626657 2026] [security2:error] [pid 255769:tid 255925] [client 117.217.38.194:53666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MC7xMYwyVGnfuwsKbaAAAA70"]
[Tue Jul 21 07:38:03.707443 2026] [security2:error] [pid 255769:tid 255936] [client 20.197.195.24:63619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ms.php"] [unique_id "al9MC7xMYwyVGnfuwsKbbAAAA8g"]
[Tue Jul 21 07:38:03.834880 2026] [security2:error] [pid 255769:tid 255992] [client 4.204.201.85:55977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/sixxis.php"] [unique_id "al9MC7xMYwyVGnfuwsKbbgAAA_8"]
[Tue Jul 21 07:38:03.935366 2026] [security2:error] [pid 255769:tid 255881] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-content/index.php"] [unique_id "al9MC7xMYwyVGnfuwsKbcAADuW8"], referer: http://aud-7.com/wp-content/index.php
[Tue Jul 21 07:38:03.956411 2026] [security2:error] [pid 255769:tid 255960] [client 20.226.60.151:61185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/fnstall.php"] [unique_id "al9MC7xMYwyVGnfuwsKbcQAAA-A"]
[Tue Jul 21 07:38:03.993166 2026] [security2:error] [pid 255769:tid 255922] [client 20.226.60.151:27573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/test.php"] [unique_id "al9MC7xMYwyVGnfuwsKbcgAAA7o"]
[Tue Jul 21 07:38:04.031464 2026] [security2:error] [pid 254995:tid 255225] [client 31.14.72.5:58059] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9MDP7v0rlcEGmVraFA9AAAA4E"]
[Tue Jul 21 07:38:04.115030 2026] [security2:error] [pid 255769:tid 255943] [client 4.204.201.85:57175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/yj09.php"] [unique_id "al9MDLxMYwyVGnfuwsKbfQAAA88"]
[Tue Jul 21 07:38:04.334521 2026] [security2:error] [pid 255769:tid 255964] [client 173.24.185.52:58041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MDLxMYwyVGnfuwsKbjQAAA-Q"]
[Tue Jul 21 07:38:04.334698 2026] [security2:error] [pid 255769:tid 255964] [client 173.24.185.52:58041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MDLxMYwyVGnfuwsKbjQAAA-Q"]
[Tue Jul 21 07:38:04.406777 2026] [security2:error] [pid 255769:tid 256014] [client 4.204.201.85:55980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/f900.php"] [unique_id "al9MDLxMYwyVGnfuwsKbkgAABBQ"]
[Tue Jul 21 07:38:04.452934 2026] [security2:error] [pid 255769:tid 255820] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-admin/fmadmin.php"] [unique_id "al9MDLxMYwyVGnfuwsKblAAD9DI"], referer: http://aud-7.com/wp-admin/fmadmin.php
[Tue Jul 21 07:38:04.528399 2026] [security2:error] [pid 254995:tid 255186] [client 20.197.192.193:6375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/pn.php"] [unique_id "al9MDP7v0rlcEGmVraFA-wAAA1s"]
[Tue Jul 21 07:38:04.626480 2026] [security2:error] [pid 254995:tid 255127] [client 20.151.10.161:46005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/green1.php"] [unique_id "al9MDP7v0rlcEGmVraFA_QAAAyA"]
[Tue Jul 21 07:38:04.697832 2026] [security2:error] [pid 255769:tid 255928] [client 4.204.201.85:55948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ups.php"] [unique_id "al9MDLxMYwyVGnfuwsKblwAAA8A"]
[Tue Jul 21 07:38:04.776849 2026] [security2:error] [pid 254995:tid 255195] [client 45.8.17.106:34723] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-content/themes/radio.php"] [unique_id "al9MDP7v0rlcEGmVraFBAQAAA2Q"]
[Tue Jul 21 07:38:04.868636 2026] [security2:error] [pid 255769:tid 255962] [client 20.206.105.145:37888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/f6.php"] [unique_id "al9MDLxMYwyVGnfuwsKbmQAAA-I"]
[Tue Jul 21 07:38:04.901868 2026] [security2:error] [pid 255769:tid 255942] [client 20.197.195.24:51803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9MDLxMYwyVGnfuwsKbmwAAA84"]
[Tue Jul 21 07:38:04.969009 2026] [security2:error] [pid 255769:tid 255849] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-admin/images/index.php"] [unique_id "al9MDLxMYwyVGnfuwsKbnAAD2U8"], referer: http://aud-7.com/wp-admin/images/index.php
[Tue Jul 21 07:38:04.971418 2026] [security2:error] [pid 255769:tid 255954] [client 4.204.201.85:55508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/k.php"] [unique_id "al9MDLxMYwyVGnfuwsKbnQAAA9o"]
[Tue Jul 21 07:38:04.985845 2026] [security2:error] [pid 255769:tid 256022] [client 117.251.86.144:39060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MDLxMYwyVGnfuwsKbngAABBw"]
[Tue Jul 21 07:38:04.985947 2026] [security2:error] [pid 255769:tid 256022] [client 117.251.86.144:39060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MDLxMYwyVGnfuwsKbngAABBw"]
[Tue Jul 21 07:38:05.081299 2026] [security2:error] [pid 254995:tid 255202] [client 20.151.10.161:46054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/biufile.php"] [unique_id "al9MDf7v0rlcEGmVraFBBgAAA2s"]
[Tue Jul 21 07:38:05.140603 2026] [security2:error] [pid 254995:tid 255131] [client 20.220.225.223:38676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/mac.php"] [unique_id "al9MDf7v0rlcEGmVraFBCAAAAyQ"]
[Tue Jul 21 07:38:05.175074 2026] [autoindex:error] [pid 254995:tid 255168] [client 20.197.195.24:63330] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:05.187284 2026] [security2:error] [pid 254995:tid 255192] [client 20.197.195.24:63330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/memberfuns.php"] [unique_id "al9MDf7v0rlcEGmVraFBCQAAA2E"]
[Tue Jul 21 07:38:05.245120 2026] [security2:error] [pid 254995:tid 255259] [client 4.204.201.85:55512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/k2.php"] [unique_id "al9MDf7v0rlcEGmVraFBCwAAA4k"]
[Tue Jul 21 07:38:05.360245 2026] [security2:error] [pid 255769:tid 255899] [client 20.197.195.24:21096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/k2.php"] [unique_id "al9MDbxMYwyVGnfuwsKbowAAA6M"]
[Tue Jul 21 07:38:05.366296 2026] [security2:error] [pid 255769:tid 255902] [client 20.52.136.55:1759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/403.php"] [unique_id "al9MDbxMYwyVGnfuwsKbpAAAA6Y"]
[Tue Jul 21 07:38:05.404050 2026] [security2:error] [pid 254995:tid 255125] [client 20.197.195.24:21001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/uiuvs58l.php"] [unique_id "al9MDf7v0rlcEGmVraFBDAAAAx4"]
[Tue Jul 21 07:38:05.479558 2026] [security2:error] [pid 254995:tid 255269] [client 20.220.225.223:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MDf7v0rlcEGmVraFBDwAAA5M"]
[Tue Jul 21 07:38:05.483927 2026] [security2:error] [pid 255769:tid 255870] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-admin/maint/index.php"] [unique_id "al9MDbxMYwyVGnfuwsKbqAAD52Q"], referer: http://aud-7.com/wp-admin/maint/index.php
[Tue Jul 21 07:38:05.520723 2026] [security2:error] [pid 255769:tid 255973] [client 4.204.201.85:55997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/w.php"] [unique_id "al9MDbxMYwyVGnfuwsKbqQAAA-0"]
[Tue Jul 21 07:38:05.557276 2026] [security2:error] [pid 254995:tid 255275] [client 103.162.129.114:56808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9MDf7v0rlcEGmVraFBEgAAA5k"]
[Tue Jul 21 07:38:05.557420 2026] [security2:error] [pid 254995:tid 255275] [client 103.162.129.114:56808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9MDf7v0rlcEGmVraFBEgAAA5k"]
[Tue Jul 21 07:38:05.559739 2026] [security2:error] [pid 254995:tid 255171] [client 20.197.195.24:21094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/40p9ixjd.php"] [unique_id "al9MDf7v0rlcEGmVraFBEwAAA0w"]
[Tue Jul 21 07:38:05.584255 2026] [security2:error] [pid 254995:tid 255268] [client 20.226.60.151:27627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/aaa.php"] [unique_id "al9MDf7v0rlcEGmVraFBFAAAA5I"]
[Tue Jul 21 07:38:05.592887 2026] [security2:error] [pid 254995:tid 255163] [client 122.186.204.214:59133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MDf7v0rlcEGmVraFBFQAAA0Q"]
[Tue Jul 21 07:38:05.593034 2026] [security2:error] [pid 254995:tid 255163] [client 122.186.204.214:59133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MDf7v0rlcEGmVraFBFQAAA0Q"]
[Tue Jul 21 07:38:05.776940 2026] [security2:error] [pid 255769:tid 256009] [client 45.8.17.64:29899] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/shell.php"] [unique_id "al9MDbxMYwyVGnfuwsKbtQAABA8"]
[Tue Jul 21 07:38:05.800542 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:57164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/fpwch.php"] [unique_id "al9MDf7v0rlcEGmVraFBGgAAA0o"]
[Tue Jul 21 07:38:05.833532 2026] [security2:error] [pid 255769:tid 255968] [client 20.197.195.24:62906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/0.php"] [unique_id "al9MDbxMYwyVGnfuwsKbtgAAA-g"]
[Tue Jul 21 07:38:05.883739 2026] [security2:error] [pid 255769:tid 255908] [client 20.206.105.145:38210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/inputs.php"] [unique_id "al9MDbxMYwyVGnfuwsKbuQAAA6w"]
[Tue Jul 21 07:38:06.005233 2026] [security2:error] [pid 255769:tid 255814] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9MDrxMYwyVGnfuwsKbugAEEyw"], referer: http://aud-7.com/wp-admin/js/index.php
[Tue Jul 21 07:38:06.077052 2026] [security2:error] [pid 255769:tid 255901] [client 4.204.201.85:55540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/w2025.php"] [unique_id "al9MDrxMYwyVGnfuwsKbvAAAA6U"]
[Tue Jul 21 07:38:06.260884 2026] [security2:error] [pid 255769:tid 255867] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MDrxMYwyVGnfuwsKb2AAECWE"]
[Tue Jul 21 07:38:06.261058 2026] [security2:error] [pid 255769:tid 256003] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MDrxMYwyVGnfuwsKb2AAECWE"]
[Tue Jul 21 07:38:06.281567 2026] [security2:error] [pid 255769:tid 255983] [client 20.197.195.24:21111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9MDrxMYwyVGnfuwsKb2wAAA_c"]
[Tue Jul 21 07:38:06.325821 2026] [security2:error] [pid 255769:tid 255942] [client 20.220.225.223:31231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/samll.php"] [unique_id "al9MDrxMYwyVGnfuwsKb3AAAA84"]
[Tue Jul 21 07:38:06.363503 2026] [security2:error] [pid 254995:tid 255167] [client 4.204.201.85:57108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/FWAZ.php"] [unique_id "al9MDv7v0rlcEGmVraFBIwAAA0g"]
[Tue Jul 21 07:38:06.524128 2026] [security2:error] [pid 255769:tid 255801] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-admin/css/index.php"] [unique_id "al9MDrxMYwyVGnfuwsKb6QAD6x8"], referer: http://aud-7.com/wp-admin/css/index.php
[Tue Jul 21 07:38:06.530156 2026] [security2:error] [pid 255769:tid 255925] [client 20.151.10.161:46041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wpconf.php"] [unique_id "al9MDrxMYwyVGnfuwsKb6gAAA70"]
[Tue Jul 21 07:38:06.546450 2026] [security2:error] [pid 255769:tid 255969] [client 31.14.72.5:58788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.72.14.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psiqueflix.online"] [uri "/xmlrpc.php"] [unique_id "al9MDbxMYwyVGnfuwsKbpQAAA-k"]
[Tue Jul 21 07:38:06.652495 2026] [security2:error] [pid 254995:tid 255130] [client 4.204.201.85:57215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/qterm.php"] [unique_id "al9MDv7v0rlcEGmVraFBKQAAAyM"]
[Tue Jul 21 07:38:06.788175 2026] [security2:error] [pid 254995:tid 255261] [client 20.197.195.24:21010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/for.php"] [unique_id "al9MDv7v0rlcEGmVraFBKgAAA4s"]
[Tue Jul 21 07:38:06.814703 2026] [security2:error] [pid 255769:tid 255934] [client 20.226.60.151:51319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/acp.php"] [unique_id "al9MDrxMYwyVGnfuwsKb7AAAA8Y"]
[Tue Jul 21 07:38:06.929761 2026] [security2:error] [pid 255769:tid 255902] [client 4.204.201.85:55514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/blurbs.php"] [unique_id "al9MDrxMYwyVGnfuwsKb7gAAA6Y"]
[Tue Jul 21 07:38:06.977031 2026] [security2:error] [pid 254995:tid 255225] [client 45.8.17.117:50187] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guiasaudeplena.com.br"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "al9MDv7v0rlcEGmVraFBLgAAA4E"]
[Tue Jul 21 07:38:07.040741 2026] [security2:error] [pid 255769:tid 255860] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-includes/assets/index.php"] [unique_id "al9MD7xMYwyVGnfuwsKb7wADyFo"], referer: http://aud-7.com/wp-includes/assets/index.php
[Tue Jul 21 07:38:07.067777 2026] [security2:error] [pid 255769:tid 255915] [client 20.206.105.145:37948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/av.php"] [unique_id "al9MD7xMYwyVGnfuwsKb8QAAA7M"]
[Tue Jul 21 07:38:07.103204 2026] [security2:error] [pid 255769:tid 255912] [client 20.151.10.161:46073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/mosty.php"] [unique_id "al9MD7xMYwyVGnfuwsKb9AAAA7A"]
[Tue Jul 21 07:38:07.208549 2026] [security2:error] [pid 254995:tid 255266] [client 4.204.201.85:57126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/v543.php"] [unique_id "al9MD_7v0rlcEGmVraFBNAAAA5A"]
[Tue Jul 21 07:38:07.244259 2026] [security2:error] [pid 254995:tid 255006] [remote 69.171.234.8:42018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9MD_7v0rlcEGmVraFBMgADbgo"]
[Tue Jul 21 07:38:07.290745 2026] [security2:error] [pid 255769:tid 255788] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MD7xMYwyVGnfuwsKb9wAD3BI"]
[Tue Jul 21 07:38:07.290892 2026] [security2:error] [pid 255769:tid 255956] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MD7xMYwyVGnfuwsKb9wAD3BI"]
[Tue Jul 21 07:38:07.384031 2026] [security2:error] [pid 255769:tid 256005] [client 20.197.195.24:63629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/BDKR28.php"] [unique_id "al9MD7xMYwyVGnfuwsKb_AAABAs"]
[Tue Jul 21 07:38:07.469783 2026] [security2:error] [pid 255769:tid 256013] [client 184.75.223.211:44032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9MD7xMYwyVGnfuwsKcAgAABBM"]
[Tue Jul 21 07:38:07.469902 2026] [security2:error] [pid 255769:tid 256013] [client 184.75.223.211:44032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9MD7xMYwyVGnfuwsKcAgAABBM"]
[Tue Jul 21 07:38:07.472336 2026] [security2:error] [pid 255769:tid 255905] [client 20.220.225.223:31184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/abcd.php"] [unique_id "al9MD7xMYwyVGnfuwsKcAwAAA6k"]
[Tue Jul 21 07:38:07.486843 2026] [security2:error] [pid 255769:tid 255980] [client 4.204.201.85:57129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/w3lls.php"] [unique_id "al9MD7xMYwyVGnfuwsKcBAAAA_Q"]
[Tue Jul 21 07:38:07.563106 2026] [security2:error] [pid 255769:tid 255825] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-includes/Requests/src/Auth/index.php"] [unique_id "al9MD7xMYwyVGnfuwsKcBQADpTc"], referer: http://aud-7.com/wp-includes/Requests/src/Auth/index.php
[Tue Jul 21 07:38:07.621331 2026] [security2:error] [pid 254995:tid 255155] [client 175.45.70.82:64489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MD_7v0rlcEGmVraFBPQAAAzw"]
[Tue Jul 21 07:38:07.621486 2026] [security2:error] [pid 254995:tid 255155] [client 175.45.70.82:64489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MD_7v0rlcEGmVraFBPQAAAzw"]
[Tue Jul 21 07:38:07.760534 2026] [security2:error] [pid 255769:tid 255966] [client 20.197.195.24:21082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/raw.php"] [unique_id "al9MD7xMYwyVGnfuwsKcCwAAA-Y"]
[Tue Jul 21 07:38:07.770823 2026] [security2:error] [pid 255769:tid 255962] [client 4.204.201.85:55506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-ws68.php"] [unique_id "al9MD7xMYwyVGnfuwsKcDAAAA-I"]
[Tue Jul 21 07:38:07.781333 2026] [security2:error] [pid 255769:tid 255978] [client 20.151.10.161:45989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/dejavu.php"] [unique_id "al9MD7xMYwyVGnfuwsKcDQAAA_I"]
[Tue Jul 21 07:38:07.850290 2026] [security2:error] [pid 254995:tid 255191] [client 154.192.233.199:59967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MD_7v0rlcEGmVraFBPwAAA2A"]
[Tue Jul 21 07:38:07.850518 2026] [security2:error] [pid 254995:tid 255191] [client 154.192.233.199:59967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MD_7v0rlcEGmVraFBPwAAA2A"]
[Tue Jul 21 07:38:07.887757 2026] [security2:error] [pid 255769:tid 255953] [client 20.226.60.151:51368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/mosty.php"] [unique_id "al9MD7xMYwyVGnfuwsKcDgAAA9k"]
[Tue Jul 21 07:38:07.960782 2026] [security2:error] [pid 255769:tid 255914] [client 20.220.225.223:31196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/ww.php"] [unique_id "al9MD7xMYwyVGnfuwsKcEQAAA7I"]
[Tue Jul 21 07:38:08.013570 2026] [security2:error] [pid 254995:tid 255186] [client 122.162.144.145:17356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MEP7v0rlcEGmVraFBQgAAA1s"]
[Tue Jul 21 07:38:08.013661 2026] [security2:error] [pid 254995:tid 255186] [client 122.162.144.145:17356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MEP7v0rlcEGmVraFBQgAAA1s"]
[Tue Jul 21 07:38:08.044979 2026] [security2:error] [pid 254995:tid 255037] [remote 88.99.30.91:44016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.30.99.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9MEP7v0rlcEGmVraFBQwADdCk"]
[Tue Jul 21 07:38:08.048196 2026] [security2:error] [pid 255769:tid 255957] [client 4.204.201.85:57156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/xyn.php"] [unique_id "al9MELxMYwyVGnfuwsKcEgAAA90"]
[Tue Jul 21 07:38:08.089890 2026] [security2:error] [pid 255769:tid 255785] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-includes/core.php"] [unique_id "al9MELxMYwyVGnfuwsKcFQAD6Q8"], referer: http://aud-7.com/wp-includes/core.php
[Tue Jul 21 07:38:08.229229 2026] [security2:error] [pid 255769:tid 255952] [client 193.36.225.57:33339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MDrxMYwyVGnfuwsKbuwAAA9g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:08.242822 2026] [security2:error] [pid 254995:tid 255179] [client 31.14.72.5:59987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9MEP7v0rlcEGmVraFBRwAAA1Q"]
[Tue Jul 21 07:38:08.285249 2026] [security2:error] [pid 254995:tid 255165] [client 20.226.60.151:27619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/11.php"] [unique_id "al9MEP7v0rlcEGmVraFBSAAAA0Y"]
[Tue Jul 21 07:38:08.323364 2026] [security2:error] [pid 255769:tid 255986] [client 103.106.20.201:53749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MELxMYwyVGnfuwsKcGAAAA_o"]
[Tue Jul 21 07:38:08.324167 2026] [security2:error] [pid 255769:tid 255986] [client 103.106.20.201:53749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MELxMYwyVGnfuwsKcGAAAA_o"]
[Tue Jul 21 07:38:08.324242 2026] [security2:error] [pid 255769:tid 255912] [client 4.204.201.85:55541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/green3.php"] [unique_id "al9MELxMYwyVGnfuwsKcGQAAA7A"]
[Tue Jul 21 07:38:08.417226 2026] [security2:error] [pid 255769:tid 255956] [client 20.206.105.145:38508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/classwithtostring.php"] [unique_id "al9MELxMYwyVGnfuwsKcHAAAA9w"]
[Tue Jul 21 07:38:08.525051 2026] [security2:error] [pid 255769:tid 255891] [remote 192.241.143.148:52784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/wp-login.php"] [unique_id "al9MELxMYwyVGnfuwsKcIAADs3k"]
[Tue Jul 21 07:38:08.562793 2026] [autoindex:error] [pid 255769:tid 255793] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:38:08.564541 2026] [autoindex:error] [pid 255769:tid 255878] [remote 141.98.11.42:0] AH01276: Cannot serve directory /home2/androa31/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Tue Jul 21 07:38:08.583548 2026] [security2:error] [pid 255769:tid 255832] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MELxMYwyVGnfuwsKcIwAEGj4"]
[Tue Jul 21 07:38:08.583700 2026] [security2:error] [pid 255769:tid 256020] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MELxMYwyVGnfuwsKcIwAEGj4"]
[Tue Jul 21 07:38:08.609568 2026] [security2:error] [pid 255769:tid 255875] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-includes/Text/Diff/Engine/template-singl-portfolio.php"] [unique_id "al9MELxMYwyVGnfuwsKcJAAEF2k"], referer: http://aud-7.com/wp-includes/Text/Diff/Engine/template-singl-portfolio.php
[Tue Jul 21 07:38:08.619576 2026] [security2:error] [pid 255769:tid 255900] [client 4.204.201.85:57099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ccc.php"] [unique_id "al9MELxMYwyVGnfuwsKcJgAAA6Q"]
[Tue Jul 21 07:38:08.642479 2026] [security2:error] [pid 255769:tid 255908] [client 20.197.195.24:63327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/green1.php"] [unique_id "al9MELxMYwyVGnfuwsKcKAAAA6w"]
[Tue Jul 21 07:38:08.685267 2026] [security2:error] [pid 255769:tid 255919] [client 122.164.127.47:56485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MELxMYwyVGnfuwsKcKwAAA7c"]
[Tue Jul 21 07:38:08.685362 2026] [security2:error] [pid 255769:tid 255919] [client 122.164.127.47:56485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MELxMYwyVGnfuwsKcKwAAA7c"]
[Tue Jul 21 07:38:08.763326 2026] [security2:error] [pid 255769:tid 255987] [client 20.226.60.151:61184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/6.php"] [unique_id "al9MELxMYwyVGnfuwsKcLQAAA_s"]
[Tue Jul 21 07:38:08.913533 2026] [security2:error] [pid 254995:tid 255137] [client 4.204.201.85:55944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/get.php"] [unique_id "al9MEP7v0rlcEGmVraFBVAAAAyo"]
[Tue Jul 21 07:38:09.080504 2026] [security2:error] [pid 254995:tid 255252] [client 20.151.10.161:46072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/aaf.php"] [unique_id "al9MEf7v0rlcEGmVraFBVwAAA4M"]
[Tue Jul 21 07:38:09.096266 2026] [security2:error] [pid 254995:tid 255174] [client 62.102.148.187:40906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9MEf7v0rlcEGmVraFBWAAAA08"]
[Tue Jul 21 07:38:09.096358 2026] [security2:error] [pid 254995:tid 255174] [client 62.102.148.187:40906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9MEf7v0rlcEGmVraFBWAAAA08"]
[Tue Jul 21 07:38:09.141192 2026] [security2:error] [pid 255769:tid 255776] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "al9MEbxMYwyVGnfuwsKcMgAD5gY"], referer: http://aud-7.com/wp-includes/ID3/index.php
[Tue Jul 21 07:38:09.177186 2026] [security2:error] [pid 254995:tid 255209] [client 20.197.195.24:63331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/nc4.php"] [unique_id "al9MEf7v0rlcEGmVraFBXAAAA3E"]
[Tue Jul 21 07:38:09.194524 2026] [security2:error] [pid 254995:tid 255256] [client 4.204.201.85:57203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/images.php"] [unique_id "al9MEf7v0rlcEGmVraFBXQAAA4Y"]
[Tue Jul 21 07:38:09.269563 2026] [security2:error] [pid 255769:tid 255954] [client 194.99.104.35:56540] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MEbxMYwyVGnfuwsKcNAAAA9o"]
[Tue Jul 21 07:38:09.269641 2026] [security2:error] [pid 255769:tid 255954] [client 194.99.104.35:56540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MEbxMYwyVGnfuwsKcNAAAA9o"]
[Tue Jul 21 07:38:09.432503 2026] [security2:error] [pid 255769:tid 255927] [client 152.59.154.239:59681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MEbxMYwyVGnfuwsKcPQAAA78"]
[Tue Jul 21 07:38:09.432859 2026] [security2:error] [pid 255769:tid 255881] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MEbxMYwyVGnfuwsKcPgADxm8"]
[Tue Jul 21 07:38:09.432970 2026] [security2:error] [pid 255769:tid 255934] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MEbxMYwyVGnfuwsKcPgADxm8"]
[Tue Jul 21 07:38:09.435060 2026] [security2:error] [pid 255769:tid 255925] [client 20.206.105.145:37901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9MEbxMYwyVGnfuwsKcPwAAA70"]
[Tue Jul 21 07:38:09.437172 2026] [security2:error] [pid 255769:tid 255927] [client 152.59.154.239:59681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MEbxMYwyVGnfuwsKcPQAAA78"]
[Tue Jul 21 07:38:09.489676 2026] [security2:error] [pid 255769:tid 255936] [client 4.204.201.85:55490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/alls.php"] [unique_id "al9MEbxMYwyVGnfuwsKcQQAAA8g"]
[Tue Jul 21 07:38:09.611703 2026] [security2:error] [pid 254995:tid 255172] [client 31.14.72.5:60713] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9MEf7v0rlcEGmVraFBYgAAA00"]
[Tue Jul 21 07:38:09.679879 2026] [security2:error] [pid 255769:tid 255856] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-includes/js/index.php"] [unique_id "al9MEbxMYwyVGnfuwsKcQwAEDFY"], referer: http://aud-7.com/wp-includes/js/index.php
[Tue Jul 21 07:38:09.710587 2026] [security2:error] [pid 255769:tid 255920] [client 20.197.195.24:63643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/a1.php"] [unique_id "al9MEbxMYwyVGnfuwsKcRQAAA7g"]
[Tue Jul 21 07:38:09.719285 2026] [security2:error] [pid 255769:tid 255981] [client 20.226.60.151:61193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9MEbxMYwyVGnfuwsKcRgAAA_U"]
[Tue Jul 21 07:38:09.766144 2026] [security2:error] [pid 255769:tid 255915] [client 4.204.201.85:60616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/coffexium.php"] [unique_id "al9MEbxMYwyVGnfuwsKcRwAAA7M"]
[Tue Jul 21 07:38:09.963304 2026] [security2:error] [pid 254995:tid 255039] [remote 69.171.234.112:57540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9MEf7v0rlcEGmVraFBaAADiys"]
[Tue Jul 21 07:38:10.042569 2026] [security2:error] [pid 255769:tid 255908] [client 4.204.201.85:55492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/red.php"] [unique_id "al9MErxMYwyVGnfuwsKcTAAAA6w"]
[Tue Jul 21 07:38:10.124992 2026] [security2:error] [pid 255769:tid 255964] [client 20.220.225.223:22471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MErxMYwyVGnfuwsKcTQAAA-Q"]
[Tue Jul 21 07:38:10.199530 2026] [security2:error] [pid 255769:tid 255823] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9MErxMYwyVGnfuwsKcUAAD0zU"], referer: http://aud-7.com/modules/mod_simplefileuploadv1.3/elements/filemanager.php
[Tue Jul 21 07:38:10.211707 2026] [security2:error] [pid 255769:tid 255905] [client 20.197.195.24:63345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/eee.php"] [unique_id "al9MErxMYwyVGnfuwsKcUQAAA6k"]
[Tue Jul 21 07:38:10.251165 2026] [security2:error] [pid 255769:tid 256024] [client 20.226.60.151:61230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/qqqa.php"] [unique_id "al9MErxMYwyVGnfuwsKcUgAABB4"]
[Tue Jul 21 07:38:10.272075 2026] [security2:error] [pid 255769:tid 255989] [client 20.151.10.161:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/term.php"] [unique_id "al9MErxMYwyVGnfuwsKcVAAAA_0"]
[Tue Jul 21 07:38:10.356930 2026] [security2:error] [pid 255769:tid 255912] [client 103.174.34.15:60520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MErxMYwyVGnfuwsKcVwAAA7A"]
[Tue Jul 21 07:38:10.357182 2026] [security2:error] [pid 255769:tid 255912] [client 103.174.34.15:60520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MErxMYwyVGnfuwsKcVwAAA7A"]
[Tue Jul 21 07:38:10.362676 2026] [autoindex:error] [pid 255769:tid 255966] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:10.498341 2026] [security2:error] [pid 255769:tid 255951] [client 184.75.223.211:50280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MErxMYwyVGnfuwsKcWAAAA9c"]
[Tue Jul 21 07:38:10.498440 2026] [security2:error] [pid 255769:tid 255951] [client 184.75.223.211:50280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MErxMYwyVGnfuwsKcWAAAA9c"]
[Tue Jul 21 07:38:10.515791 2026] [security2:error] [pid 254995:tid 255210] [client 20.226.60.151:51353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/aunmc.php"] [unique_id "al9MEv7v0rlcEGmVraFBbwAAA3I"]
[Tue Jul 21 07:38:10.576444 2026] [security2:error] [pid 254995:tid 255143] [client 20.226.60.151:51356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/uoocf.php"] [unique_id "al9MEv7v0rlcEGmVraFBcQAAAzA"]
[Tue Jul 21 07:38:10.638798 2026] [security2:error] [pid 254995:tid 255189] [client 4.204.201.85:57127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9MEv7v0rlcEGmVraFBcgAAA14"]
[Tue Jul 21 07:38:10.715171 2026] [security2:error] [pid 255769:tid 255866] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/.well-known/index.php"] [unique_id "al9MErxMYwyVGnfuwsKcXAAD3WA"], referer: http://aud-7.com/.well-known/index.php
[Tue Jul 21 07:38:10.756455 2026] [security2:error] [pid 254995:tid 255142] [client 20.226.60.151:51338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/iywwi.php"] [unique_id "al9MEv7v0rlcEGmVraFBdgAAAy8"]
[Tue Jul 21 07:38:10.943517 2026] [security2:error] [pid 254995:tid 255222] [client 20.226.60.151:27596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/mac.php"] [unique_id "al9MEv7v0rlcEGmVraFBegAAA34"]
[Tue Jul 21 07:38:10.950700 2026] [autoindex:error] [pid 254995:tid 255208] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:10.959851 2026] [security2:error] [pid 255769:tid 255984] [client 31.14.72.5:61400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9MErxMYwyVGnfuwsKcYAAAA_g"]
[Tue Jul 21 07:38:11.025563 2026] [security2:error] [pid 255769:tid 255942] [client 20.226.60.151:51359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/gqgsa.php"] [unique_id "al9ME7xMYwyVGnfuwsKcYQAAA84"]
[Tue Jul 21 07:38:11.209285 2026] [security2:error] [pid 255769:tid 255978] [client 59.96.220.140:61601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9ME7xMYwyVGnfuwsKcZAAAA_I"]
[Tue Jul 21 07:38:11.209408 2026] [security2:error] [pid 255769:tid 255978] [client 59.96.220.140:61601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9ME7xMYwyVGnfuwsKcZAAAA_I"]
[Tue Jul 21 07:38:11.232604 2026] [security2:error] [pid 255769:tid 255895] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/classwithtostring.php"] [unique_id "al9ME7xMYwyVGnfuwsKcaAADtH0"], referer: http://aud-7.com/classwithtostring.php
[Tue Jul 21 07:38:11.235920 2026] [authz_core:error] [pid 255769:tid 255952] [client 4.204.201.85:0] AH01630: client denied by server configuration: /home1/ofic8899/qcharge.tryhealth.shop/wp-content/uploads/index.php
[Tue Jul 21 07:38:11.270662 2026] [security2:error] [pid 254995:tid 255168] [client 20.226.60.151:61209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/elbzl.php"] [unique_id "al9ME_7v0rlcEGmVraFBgQAAA0k"]
[Tue Jul 21 07:38:11.278010 2026] [security2:error] [pid 254995:tid 255211] [client 20.220.225.223:31881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/dp.php"] [unique_id "al9ME_7v0rlcEGmVraFBggAAA3M"]
[Tue Jul 21 07:38:11.351877 2026] [security2:error] [pid 255769:tid 255859] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9ME7xMYwyVGnfuwsKcaQAD6Vk"]
[Tue Jul 21 07:38:11.352031 2026] [security2:error] [pid 255769:tid 255969] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9ME7xMYwyVGnfuwsKcaQAD6Vk"]
[Tue Jul 21 07:38:11.365643 2026] [security2:error] [pid 255769:tid 255914] [client 103.86.117.203:56184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9ME7xMYwyVGnfuwsKcagAAA7I"]
[Tue Jul 21 07:38:11.365781 2026] [security2:error] [pid 255769:tid 255914] [client 103.86.117.203:56184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9ME7xMYwyVGnfuwsKcagAAA7I"]
[Tue Jul 21 07:38:11.376357 2026] [security2:error] [pid 255769:tid 255922] [client 4.204.201.85:57112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-content/index.php"] [unique_id "al9ME7xMYwyVGnfuwsKcawAAA7o"]
[Tue Jul 21 07:38:11.406438 2026] [security2:error] [pid 255769:tid 255899] [client 20.197.195.24:63644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-aothait.php"] [unique_id "al9ME7xMYwyVGnfuwsKcbAAAA6M"]
[Tue Jul 21 07:38:11.548280 2026] [security2:error] [pid 255769:tid 255920] [client 20.226.60.151:51288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/adjig.php"] [unique_id "al9ME7xMYwyVGnfuwsKcbQAAA7g"]
[Tue Jul 21 07:38:11.597596 2026] [proxy:error] [pid 255769:tid 255950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.597645 2026] [proxy_http:error] [pid 255769:tid 255950] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.598110 2026] [proxy:error] [pid 255769:tid 255950] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.598136 2026] [proxy_http:error] [pid 255769:tid 255950] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.628302 2026] [proxy:error] [pid 255769:tid 255908] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.628373 2026] [proxy_http:error] [pid 255769:tid 255908] [client 2604:a880:4:1d0::36c:6000:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.628992 2026] [proxy:error] [pid 255769:tid 255908] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.629032 2026] [proxy_http:error] [pid 255769:tid 255908] [client 2604:a880:4:1d0::36c:6000:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.630672 2026] [proxy:error] [pid 254995:tid 255165] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.630734 2026] [proxy_http:error] [pid 254995:tid 255165] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.631314 2026] [proxy:error] [pid 254995:tid 255165] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.631347 2026] [proxy_http:error] [pid 254995:tid 255165] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.651170 2026] [security2:error] [pid 255769:tid 255964] [client 20.197.192.193:6353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-wpbak.php"] [unique_id "al9ME7xMYwyVGnfuwsKcdgAAA-Q"]
[Tue Jul 21 07:38:11.667477 2026] [security2:error] [pid 255769:tid 256015] [client 4.204.201.85:57119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/admin.php"] [unique_id "al9ME7xMYwyVGnfuwsKceAAABBU"]
[Tue Jul 21 07:38:11.726494 2026] [proxy:error] [pid 255769:tid 256024] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.726550 2026] [proxy_http:error] [pid 255769:tid 256024] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.727005 2026] [proxy:error] [pid 255769:tid 256024] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.727047 2026] [proxy_http:error] [pid 255769:tid 256024] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.745512 2026] [security2:error] [pid 255769:tid 255877] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/filemanager.php"] [unique_id "al9ME7xMYwyVGnfuwsKcgAAD9Gs"], referer: http://aud-7.com/filemanager.php
[Tue Jul 21 07:38:11.746997 2026] [proxy:error] [pid 254995:tid 255177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.747056 2026] [proxy_http:error] [pid 254995:tid 255177] [client 2a03:b0c0:2:d0::1737:1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.747566 2026] [proxy:error] [pid 254995:tid 255177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.747588 2026] [proxy_http:error] [pid 254995:tid 255177] [client 2a03:b0c0:2:d0::1737:1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.753551 2026] [security2:error] [pid 255769:tid 255901] [client 20.151.10.161:46037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ha.php"] [unique_id "al9ME7xMYwyVGnfuwsKcgQAAA6U"]
[Tue Jul 21 07:38:11.804411 2026] [security2:error] [pid 255769:tid 255979] [client 20.226.60.151:51327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/byp.php"] [unique_id "al9ME7xMYwyVGnfuwsKchAAAA_M"]
[Tue Jul 21 07:38:11.809864 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.809914 2026] [proxy_http:error] [pid 254995:tid 255268] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.810386 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.810405 2026] [proxy_http:error] [pid 254995:tid 255268] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.847422 2026] [proxy:error] [pid 254995:tid 255166] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.847499 2026] [proxy_http:error] [pid 254995:tid 255166] [client 2400:6180:0:d0::13e9:e001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.848527 2026] [proxy:error] [pid 254995:tid 255166] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.848562 2026] [proxy_http:error] [pid 254995:tid 255166] [client 2400:6180:0:d0::13e9:e001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.875406 2026] [security2:error] [pid 255769:tid 255954] [client 20.197.195.24:63319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/config.json.php"] [unique_id "al9ME7xMYwyVGnfuwsKciAAAA9o"]
[Tue Jul 21 07:38:11.903095 2026] [proxy:error] [pid 255769:tid 255957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.903162 2026] [proxy_http:error] [pid 255769:tid 255957] [client 2a03:b0c0:3:d0::12f7:9001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.903592 2026] [proxy:error] [pid 255769:tid 255957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:11.903617 2026] [proxy_http:error] [pid 255769:tid 255957] [client 2a03:b0c0:3:d0::12f7:9001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:11.942077 2026] [security2:error] [pid 255769:tid 255927] [client 4.204.201.85:57187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/177.php"] [unique_id "al9ME7xMYwyVGnfuwsKcjgAAA78"]
[Tue Jul 21 07:38:11.942750 2026] [security2:error] [pid 254995:tid 255157] [client 20.206.105.145:38519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-blog.php"] [unique_id "al9ME_7v0rlcEGmVraFBlgAAAz4"]
[Tue Jul 21 07:38:12.148684 2026] [security2:error] [pid 255769:tid 255916] [client 20.197.195.24:63358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9MFLxMYwyVGnfuwsKckwAAA7Q"]
[Tue Jul 21 07:38:12.218255 2026] [security2:error] [pid 255769:tid 255932] [client 4.204.201.85:55989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/199.php"] [unique_id "al9MFLxMYwyVGnfuwsKclAAAA8Q"]
[Tue Jul 21 07:38:12.259032 2026] [security2:error] [pid 255769:tid 255936] [client 20.197.195.24:63312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/k2.php"] [unique_id "al9MFLxMYwyVGnfuwsKclQAAA8g"]
[Tue Jul 21 07:38:12.259642 2026] [security2:error] [pid 255769:tid 255873] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9MFLxMYwyVGnfuwsKclgAD_2c"], referer: http://aud-7.com/4PJcpMFsD8B.php
[Tue Jul 21 07:38:12.292685 2026] [security2:error] [pid 254995:tid 255125] [client 31.14.72.5:62591] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9MFP7v0rlcEGmVraFBoAAAAx4"]
[Tue Jul 21 07:38:12.491128 2026] [security2:error] [pid 254995:tid 255214] [client 4.204.201.85:60548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/file52.php"] [unique_id "al9MFP7v0rlcEGmVraFBpgAAA3Y"]
[Tue Jul 21 07:38:12.591037 2026] [security2:error] [pid 255769:tid 255848] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MFLxMYwyVGnfuwsKcnAADyk4"]
[Tue Jul 21 07:38:12.591175 2026] [security2:error] [pid 255769:tid 255938] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MFLxMYwyVGnfuwsKcnAADyk4"]
[Tue Jul 21 07:38:12.592142 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.592188 2026] [proxy_http:error] [pid 255769:tid 255964] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.592746 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.592768 2026] [proxy_http:error] [pid 255769:tid 255964] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.601098 2026] [security2:error] [pid 254995:tid 255216] [client 20.226.60.151:51308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9MFP7v0rlcEGmVraFBqwAAA3g"]
[Tue Jul 21 07:38:12.610102 2026] [security2:error] [pid 255769:tid 256005] [client 20.151.10.161:2946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MFLxMYwyVGnfuwsKcngAABAs"]
[Tue Jul 21 07:38:12.619973 2026] [security2:error] [pid 255769:tid 255918] [client 20.52.136.55:1540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.gradiente.com"] [uri "/api.php"] [unique_id "al9MFLxMYwyVGnfuwsKcnwAAA7Y"]
[Tue Jul 21 07:38:12.627241 2026] [security2:error] [pid 254995:tid 255049] [remote 45.150.79.142:42632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9MFP7v0rlcEGmVraFBrAADfzU"]
[Tue Jul 21 07:38:12.724524 2026] [proxy:error] [pid 255769:tid 255970] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.724583 2026] [proxy_http:error] [pid 255769:tid 255970] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.724652 2026] [proxy:error] [pid 255769:tid 256013] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.724700 2026] [proxy_http:error] [pid 255769:tid 256013] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.725042 2026] [proxy:error] [pid 255769:tid 255970] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.725067 2026] [proxy_http:error] [pid 255769:tid 255970] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.725142 2026] [proxy:error] [pid 255769:tid 256013] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.725164 2026] [proxy_http:error] [pid 255769:tid 256013] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.731340 2026] [security2:error] [pid 255769:tid 256009] [client 157.90.155.240:29986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9MFLxMYwyVGnfuwsKcpgAABA8"], referer: https://artetoner.com.br
[Tue Jul 21 07:38:12.776803 2026] [security2:error] [pid 255769:tid 255901] [client 4.204.201.85:57191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/geck.php"] [unique_id "al9MFLxMYwyVGnfuwsKcqQAAA6U"]
[Tue Jul 21 07:38:12.782110 2026] [security2:error] [pid 255769:tid 255833] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "al9MFLxMYwyVGnfuwsKcqgAD_T8"], referer: http://aud-7.com/3PJcpMFsD8B.php
[Tue Jul 21 07:38:12.789578 2026] [proxy:error] [pid 255769:tid 255912] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.789633 2026] [proxy_http:error] [pid 255769:tid 255912] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.790245 2026] [proxy:error] [pid 255769:tid 255912] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:12.790272 2026] [proxy_http:error] [pid 255769:tid 255912] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:12.868995 2026] [autoindex:error] [pid 255769:tid 255953] [client 198.235.24.155:61912] AH01276: Cannot serve directory /home4/ciclod61/bahinternet.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:12.878721 2026] [security2:error] [pid 255769:tid 255902] [client 136.144.33.99:55013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MFLxMYwyVGnfuwsKcrwAAA6Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:12.885300 2026] [security2:error] [pid 255769:tid 255917] [client 20.151.10.161:2698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MFLxMYwyVGnfuwsKcsAAAA7U"]
[Tue Jul 21 07:38:13.019061 2026] [autoindex:error] [pid 255769:tid 255978] [client 20.206.105.145:38080] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:13.029189 2026] [security2:error] [pid 255769:tid 255946] [client 20.206.105.145:38080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MFbxMYwyVGnfuwsKctwAAA9I"]
[Tue Jul 21 07:38:13.043827 2026] [security2:error] [pid 254995:tid 255276] [client 20.197.195.24:13311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/uiuvs58l.php"] [unique_id "al9MFf7v0rlcEGmVraFBsQAAA5o"]
[Tue Jul 21 07:38:13.056647 2026] [security2:error] [pid 254995:tid 255210] [client 4.204.201.85:55954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/biufile.php"] [unique_id "al9MFf7v0rlcEGmVraFBsgAAA3I"]
[Tue Jul 21 07:38:13.167733 2026] [security2:error] [pid 255769:tid 255923] [client 20.151.10.161:2735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/images.php"] [unique_id "al9MFbxMYwyVGnfuwsKcvwAAA7s"]
[Tue Jul 21 07:38:13.245165 2026] [security2:error] [pid 254995:tid 255213] [client 139.167.225.182:49789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MFf7v0rlcEGmVraFBuAAAA3U"]
[Tue Jul 21 07:38:13.245350 2026] [security2:error] [pid 254995:tid 255213] [client 139.167.225.182:49789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MFf7v0rlcEGmVraFBuAAAA3U"]
[Tue Jul 21 07:38:13.287254 2026] [security2:error] [pid 254995:tid 255175] [client 20.226.60.151:51305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9MFf7v0rlcEGmVraFBuQAAA1A"]
[Tue Jul 21 07:38:13.295657 2026] [security2:error] [pid 255769:tid 255853] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/5PJcpMFsD8B.php"] [unique_id "al9MFbxMYwyVGnfuwsKcxAADuFM"], referer: http://aud-7.com/5PJcpMFsD8B.php
[Tue Jul 21 07:38:13.348943 2026] [security2:error] [pid 255769:tid 255915] [client 4.204.201.85:57102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/mosty.php"] [unique_id "al9MFbxMYwyVGnfuwsKcxwAAA7M"]
[Tue Jul 21 07:38:13.446971 2026] [security2:error] [pid 255769:tid 256028] [client 20.151.10.161:2740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/for.php"] [unique_id "al9MFbxMYwyVGnfuwsKcygAABCI"]
[Tue Jul 21 07:38:13.586587 2026] [security2:error] [pid 255769:tid 255905] [client 194.99.104.35:46680] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MFbxMYwyVGnfuwsKczgAAA6k"]
[Tue Jul 21 07:38:13.586711 2026] [security2:error] [pid 255769:tid 255905] [client 194.99.104.35:46680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MFbxMYwyVGnfuwsKczgAAA6k"]
[Tue Jul 21 07:38:13.592191 2026] [proxy:error] [pid 254995:tid 255173] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.592242 2026] [proxy_http:error] [pid 254995:tid 255173] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.592870 2026] [proxy:error] [pid 254995:tid 255173] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.592892 2026] [proxy_http:error] [pid 254995:tid 255173] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.631379 2026] [security2:error] [pid 255769:tid 255976] [client 31.14.72.5:63929] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9MFbxMYwyVGnfuwsKc0AAAA_A"]
[Tue Jul 21 07:38:13.635483 2026] [security2:error] [pid 255769:tid 256009] [client 4.204.201.85:60613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/dejavu.php"] [unique_id "al9MFbxMYwyVGnfuwsKc0gAABA8"]
[Tue Jul 21 07:38:13.666550 2026] [proxy:error] [pid 254995:tid 255168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.666606 2026] [proxy_http:error] [pid 254995:tid 255168] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.667222 2026] [proxy:error] [pid 254995:tid 255168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.667259 2026] [proxy_http:error] [pid 254995:tid 255168] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.726019 2026] [proxy:error] [pid 254995:tid 255153] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.726078 2026] [proxy_http:error] [pid 254995:tid 255153] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.726582 2026] [proxy:error] [pid 254995:tid 255153] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.726610 2026] [proxy_http:error] [pid 254995:tid 255153] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.727240 2026] [security2:error] [pid 255769:tid 255966] [client 20.151.10.161:2724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/2larp.php"] [unique_id "al9MFbxMYwyVGnfuwsKc1wAAA-Y"]
[Tue Jul 21 07:38:13.773549 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:61192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/root.php"] [unique_id "al9MFbxMYwyVGnfuwsKc2AAAA_4"]
[Tue Jul 21 07:38:13.792046 2026] [proxy:error] [pid 255769:tid 255929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.792109 2026] [proxy_http:error] [pid 255769:tid 255929] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.793063 2026] [proxy:error] [pid 255769:tid 255929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:13.793107 2026] [proxy_http:error] [pid 255769:tid 255929] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:13.796458 2026] [security2:error] [pid 254995:tid 255179] [client 20.206.105.145:38230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/adminfuns.php"] [unique_id "al9MFf7v0rlcEGmVraFBygAAA1Q"]
[Tue Jul 21 07:38:13.918925 2026] [security2:error] [pid 255769:tid 255807] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/dropdown.php"] [unique_id "al9MFbxMYwyVGnfuwsKc5AAD3iU"], referer: http://aud-7.com/dropdown.php
[Tue Jul 21 07:38:13.934460 2026] [security2:error] [pid 255769:tid 255928] [client 4.204.201.85:55544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/aaf.php"] [unique_id "al9MFbxMYwyVGnfuwsKc5QAAA8A"]
[Tue Jul 21 07:38:14.000066 2026] [fcgid:warn] [pid 254995:tid 255268] (70014)End of file found: [client 184.154.139.46:42706] mod_fcgid: can't get data from http client
[Tue Jul 21 07:38:14.004651 2026] [security2:error] [pid 255769:tid 255913] [client 20.151.10.161:2717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/adminner.php"] [unique_id "al9MFrxMYwyVGnfuwsKc5gAAA7E"]
[Tue Jul 21 07:38:14.012388 2026] [security2:error] [pid 255769:tid 255942] [client 20.220.225.223:38669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/cron.php"] [unique_id "al9MFrxMYwyVGnfuwsKc6AAAA84"]
[Tue Jul 21 07:38:14.059248 2026] [security2:error] [pid 255769:tid 256012] [client 20.197.195.24:63639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/40p9ixjd.php"] [unique_id "al9MFrxMYwyVGnfuwsKc6gAABBI"]
[Tue Jul 21 07:38:14.193609 2026] [security2:error] [pid 255769:tid 256005] [client 117.217.38.194:54144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MFrxMYwyVGnfuwsKc8AAABAs"]
[Tue Jul 21 07:38:14.193720 2026] [security2:error] [pid 255769:tid 256005] [client 117.217.38.194:54144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MFrxMYwyVGnfuwsKc8AAABAs"]
[Tue Jul 21 07:38:14.218300 2026] [security2:error] [pid 255769:tid 255920] [client 4.204.201.85:55981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ha.php"] [unique_id "al9MFrxMYwyVGnfuwsKc8QAAA7g"]
[Tue Jul 21 07:38:14.233534 2026] [security2:error] [pid 255769:tid 256021] [client 20.226.60.151:51297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/sym403.php"] [unique_id "al9MFrxMYwyVGnfuwsKc8gAABBs"]
[Tue Jul 21 07:38:14.266568 2026] [security2:error] [pid 255769:tid 255915] [client 20.151.10.161:45988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/hur.php"] [unique_id "al9MFrxMYwyVGnfuwsKc8wAAA7M"]
[Tue Jul 21 07:38:14.284608 2026] [security2:error] [pid 255769:tid 255950] [client 20.151.10.161:2715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/82.php"] [unique_id "al9MFrxMYwyVGnfuwsKc9AAAA9Y"]
[Tue Jul 21 07:38:14.435989 2026] [security2:error] [pid 255769:tid 255790] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp-admin.php"] [unique_id "al9MFrxMYwyVGnfuwsKc-AAD6hQ"], referer: http://aud-7.com/wp-admin.php
[Tue Jul 21 07:38:14.480207 2026] [access_compat:error] [pid 254995:tid 255163] [client 165.227.39.235:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:14.496809 2026] [security2:error] [pid 254995:tid 255209] [client 4.204.201.85:57135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/hur.php"] [unique_id "al9MFv7v0rlcEGmVraFB4QAAA3E"]
[Tue Jul 21 07:38:14.529367 2026] [security2:error] [pid 255769:tid 255919] [client 138.197.191.87:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webmail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/server-status"] [unique_id "al9MFrxMYwyVGnfuwsKc-wAAA7c"]
[Tue Jul 21 07:38:14.557620 2026] [security2:error] [pid 255769:tid 256024] [client 20.151.10.161:2959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "santotchay.com.br"] [uri "/kir.php"] [unique_id "al9MFrxMYwyVGnfuwsKc_QAABB4"]
[Tue Jul 21 07:38:14.559849 2026] [security2:error] [pid 255769:tid 255987] [client 20.220.225.223:31187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/xyn.php"] [unique_id "al9MFrxMYwyVGnfuwsKc_gAAA_s"]
[Tue Jul 21 07:38:14.596979 2026] [security2:error] [pid 255769:tid 255900] [client 157.245.36.108:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcontacts.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/server-status"] [unique_id "al9MFrxMYwyVGnfuwsKc_wAAA6Q"]
[Tue Jul 21 07:38:14.615146 2026] [security2:error] [pid 255769:tid 255989] [client 178.128.207.138:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webdisk.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/server-status"] [unique_id "al9MFrxMYwyVGnfuwsKdAAAAA_0"]
[Tue Jul 21 07:38:14.642293 2026] [security2:error] [pid 255769:tid 255918] [client 147.182.149.75:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcalendars.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/server-status"] [unique_id "al9MFrxMYwyVGnfuwsKdAQAAA7Y"]
[Tue Jul 21 07:38:14.702617 2026] [security2:error] [pid 254995:tid 255138] [client 146.190.63.248:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpanel.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/server-status"] [unique_id "al9MFv7v0rlcEGmVraFB5gAAAys"]
[Tue Jul 21 07:38:14.720239 2026] [security2:error] [pid 254995:tid 255160] [client 46.101.1.225:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcontacts.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/server-status"] [unique_id "al9MFv7v0rlcEGmVraFB5wAAA0E"]
[Tue Jul 21 07:38:14.785855 2026] [security2:error] [pid 255769:tid 255967] [client 4.204.201.85:57117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/h02ugyh.php"] [unique_id "al9MFrxMYwyVGnfuwsKdAwAAA-c"]
[Tue Jul 21 07:38:14.860558 2026] [security2:error] [pid 255769:tid 255901] [client 173.24.185.52:58509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MFrxMYwyVGnfuwsKdBQAAA6U"]
[Tue Jul 21 07:38:14.860665 2026] [security2:error] [pid 255769:tid 255901] [client 173.24.185.52:58509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MFrxMYwyVGnfuwsKdBQAAA6U"]
[Tue Jul 21 07:38:14.864183 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:61199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/v543.php"] [unique_id "al9MFrxMYwyVGnfuwsKdBwAAA_4"]
[Tue Jul 21 07:38:14.864237 2026] [security2:error] [pid 255769:tid 255983] [client 138.68.82.23:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcalendars.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/server-status"] [unique_id "al9MFrxMYwyVGnfuwsKdBgAAA_c"]
[Tue Jul 21 07:38:14.922490 2026] [security2:error] [pid 255769:tid 255932] [client 128.199.182.55:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpanel.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/server-status"] [unique_id "al9MFrxMYwyVGnfuwsKdCQAAA8Q"]
[Tue Jul 21 07:38:14.950407 2026] [security2:error] [pid 255769:tid 255821] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/license.php"] [unique_id "al9MFrxMYwyVGnfuwsKdDAAD3jM"], referer: http://aud-7.com/license.php
[Tue Jul 21 07:38:14.975462 2026] [security2:error] [pid 254995:tid 255220] [client 31.14.72.5:65218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9MFv7v0rlcEGmVraFB6QAAA3w"]
[Tue Jul 21 07:38:14.988469 2026] [access_compat:error] [pid 255769:tid 256004] [client 167.99.210.137:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:15.017129 2026] [access_compat:error] [pid 255769:tid 255951] [client 165.227.173.41:0] AH01797: client denied by server configuration: proxy:http://127.0.0.1/cgi-sys/autodiscover.cgi
[Tue Jul 21 07:38:15.064271 2026] [security2:error] [pid 254995:tid 255182] [client 4.204.201.85:55547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/155.php"] [unique_id "al9MF_7v0rlcEGmVraFB7AAAA1c"]
[Tue Jul 21 07:38:15.067021 2026] [access_compat:error] [pid 255769:tid 255912] [client 64.226.65.160:0] AH01797: client denied by server configuration: proxy:http://127.0.0.1/cgi-sys/autodiscover.cgi
[Tue Jul 21 07:38:15.089170 2026] [security2:error] [pid 255769:tid 255913] [client 20.197.195.24:62425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9MF7xMYwyVGnfuwsKdEAAAA7E"]
[Tue Jul 21 07:38:15.097279 2026] [security2:error] [pid 254995:tid 255223] [client 165.227.173.41:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webmail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/server-status"] [unique_id "al9MF_7v0rlcEGmVraFB7QAAA38"]
[Tue Jul 21 07:38:15.188184 2026] [security2:error] [pid 254995:tid 255129] [client 139.59.143.102:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webdisk.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/server-status"] [unique_id "al9MF_7v0rlcEGmVraFB8AAAAyI"]
[Tue Jul 21 07:38:15.325063 2026] [security2:error] [pid 255769:tid 255936] [client 62.102.148.187:56938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MF7xMYwyVGnfuwsKdEwAAA8g"]
[Tue Jul 21 07:38:15.325185 2026] [security2:error] [pid 255769:tid 255936] [client 62.102.148.187:56938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MF7xMYwyVGnfuwsKdEwAAA8g"]
[Tue Jul 21 07:38:15.347130 2026] [security2:error] [pid 254995:tid 255136] [client 4.204.201.85:61309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/pp.php"] [unique_id "al9MF_7v0rlcEGmVraFB8wAAAyk"]
[Tue Jul 21 07:38:15.374507 2026] [security2:error] [pid 254995:tid 255217] [client 20.226.60.151:51272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/sixxis.php"] [unique_id "al9MF_7v0rlcEGmVraFB9QAAA3k"]
[Tue Jul 21 07:38:15.462636 2026] [security2:error] [pid 255769:tid 255890] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/content.php"] [unique_id "al9MF7xMYwyVGnfuwsKdGwADung"], referer: http://aud-7.com/content.php
[Tue Jul 21 07:38:15.485598 2026] [access_compat:error] [pid 255769:tid 255923] [client 138.68.86.32:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:15.543721 2026] [access_compat:error] [pid 254995:tid 255010] [remote 159.65.144.72:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:15.584101 2026] [access_compat:error] [pid 254995:tid 255149] [client 138.68.86.32:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:15.623348 2026] [access_compat:error] [pid 254995:tid 255116] [remote 159.65.144.72:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:15.637755 2026] [security2:error] [pid 254995:tid 255144] [client 4.204.201.85:57205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ops.php"] [unique_id "al9MF_7v0rlcEGmVraFB-gAAAzE"]
[Tue Jul 21 07:38:15.733038 2026] [security2:error] [pid 255769:tid 255897] [remote 202.51.202.242:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-login.php"] [unique_id "al9MF7xMYwyVGnfuwsKdIwAD-38"]
[Tue Jul 21 07:38:15.836468 2026] [access_compat:error] [pid 255769:tid 255976] [client 46.101.111.185:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:15.853022 2026] [security2:error] [pid 255769:tid 256017] [client 117.251.86.144:45980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MF7xMYwyVGnfuwsKdJgAABBc"]
[Tue Jul 21 07:38:15.853125 2026] [security2:error] [pid 255769:tid 256017] [client 117.251.86.144:45980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MF7xMYwyVGnfuwsKdJgAABBc"]
[Tue Jul 21 07:38:15.941603 2026] [access_compat:error] [pid 255769:tid 256005] [client 64.227.70.2:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:38:15.945482 2026] [security2:error] [pid 255769:tid 255955] [client 4.204.201.85:55937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ingfo.php"] [unique_id "al9MF7xMYwyVGnfuwsKdJwAAA9s"]
[Tue Jul 21 07:38:15.973357 2026] [security2:error] [pid 255769:tid 255858] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/install.php"] [unique_id "al9MF7xMYwyVGnfuwsKdKgAD91g"], referer: http://aud-7.com/install.php
[Tue Jul 21 07:38:16.060785 2026] [security2:error] [pid 255769:tid 255902] [client 20.197.195.24:63648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/for.php"] [unique_id "al9MGLxMYwyVGnfuwsKdKwAAA6Y"]
[Tue Jul 21 07:38:16.202330 2026] [security2:error] [pid 255769:tid 255957] [client 20.226.60.151:27634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/chosen.php"] [unique_id "al9MGLxMYwyVGnfuwsKdLQAAA90"]
[Tue Jul 21 07:38:16.242614 2026] [security2:error] [pid 255769:tid 255928] [client 4.204.201.85:57193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/error_log.php"] [unique_id "al9MGLxMYwyVGnfuwsKdLwAAA8A"]
[Tue Jul 21 07:38:16.259748 2026] [security2:error] [pid 254995:tid 255210] [client 103.162.129.114:56999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.129.162.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9MGP7v0rlcEGmVraFCBAAAA3I"]
[Tue Jul 21 07:38:16.259881 2026] [security2:error] [pid 254995:tid 255210] [client 103.162.129.114:56999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wilkermoronicriminalista.com"] [uri "/xmlrpc.php"] [unique_id "al9MGP7v0rlcEGmVraFCBAAAA3I"]
[Tue Jul 21 07:38:16.272335 2026] [security2:error] [pid 254995:tid 255266] [client 122.186.204.214:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MGP7v0rlcEGmVraFCBgAAA5A"]
[Tue Jul 21 07:38:16.272445 2026] [security2:error] [pid 254995:tid 255266] [client 122.186.204.214:59654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MGP7v0rlcEGmVraFCBgAAA5A"]
[Tue Jul 21 07:38:16.325565 2026] [security2:error] [pid 254995:tid 255154] [client 31.14.72.5:50129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9MGP7v0rlcEGmVraFCCAAAAzs"]
[Tue Jul 21 07:38:16.343769 2026] [security2:error] [pid 255769:tid 255942] [client 20.226.60.151:51370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ip.php"] [unique_id "al9MGLxMYwyVGnfuwsKdMgAAA84"]
[Tue Jul 21 07:38:16.397929 2026] [security2:error] [pid 254995:tid 255140] [client 20.197.195.24:62883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/raw.php"] [unique_id "al9MGP7v0rlcEGmVraFCCgAAAy0"]
[Tue Jul 21 07:38:16.482632 2026] [security2:error] [pid 255769:tid 255787] [remote 124.55.178.99:40832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9MF7xMYwyVGnfuwsKdHAADwRE"]
[Tue Jul 21 07:38:16.493476 2026] [security2:error] [pid 255769:tid 255797] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/inputs.php"] [unique_id "al9MGLxMYwyVGnfuwsKdOQAD4Bs"], referer: http://aud-7.com/inputs.php
[Tue Jul 21 07:38:16.493748 2026] [security2:error] [pid 255769:tid 255992] [client 20.206.105.145:38500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/goods.php"] [unique_id "al9MGLxMYwyVGnfuwsKdOgAAA_8"]
[Tue Jul 21 07:38:16.531321 2026] [security2:error] [pid 255769:tid 255899] [client 4.204.201.85:57210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/test10.php"] [unique_id "al9MGLxMYwyVGnfuwsKdPAAAA6M"]
[Tue Jul 21 07:38:16.592739 2026] [proxy:error] [pid 254995:tid 255219] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.592805 2026] [proxy_http:error] [pid 254995:tid 255219] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.593714 2026] [proxy:error] [pid 254995:tid 255219] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.593755 2026] [proxy_http:error] [pid 254995:tid 255219] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.641128 2026] [proxy:error] [pid 254995:tid 255274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.641206 2026] [proxy_http:error] [pid 254995:tid 255274] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.642118 2026] [proxy:error] [pid 254995:tid 255274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.642165 2026] [proxy_http:error] [pid 254995:tid 255274] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.723978 2026] [proxy:error] [pid 254995:tid 255177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.724051 2026] [proxy_http:error] [pid 254995:tid 255177] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.724739 2026] [proxy:error] [pid 254995:tid 255177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.724769 2026] [proxy_http:error] [pid 254995:tid 255177] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.767778 2026] [security2:error] [pid 255769:tid 256028] [client 20.220.225.223:31183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/xxx.php"] [unique_id "al9MGLxMYwyVGnfuwsKdQAAABCI"]
[Tue Jul 21 07:38:16.786959 2026] [proxy:error] [pid 254995:tid 255159] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.787036 2026] [proxy_http:error] [pid 254995:tid 255159] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.787692 2026] [proxy:error] [pid 254995:tid 255159] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:16.787739 2026] [proxy_http:error] [pid 254995:tid 255159] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:16.812619 2026] [security2:error] [pid 255769:tid 255935] [client 4.204.201.85:57092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/koala.php"] [unique_id "al9MGLxMYwyVGnfuwsKdQgAAA8c"]
[Tue Jul 21 07:38:16.881726 2026] [security2:error] [pid 255769:tid 255987] [client 20.226.60.151:51363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/kq1.php"] [unique_id "al9MGLxMYwyVGnfuwsKdRAAAA_s"]
[Tue Jul 21 07:38:16.995371 2026] [security2:error] [pid 254995:tid 255067] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGP7v0rlcEGmVraFCGgADk0c"]
[Tue Jul 21 07:38:16.995502 2026] [security2:error] [pid 254995:tid 255269] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGP7v0rlcEGmVraFCGgADk0c"]
[Tue Jul 21 07:38:17.010468 2026] [security2:error] [pid 255769:tid 255893] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/style2.php"] [unique_id "al9MGbxMYwyVGnfuwsKdTgAD5Xs"], referer: http://aud-7.com/style2.php
[Tue Jul 21 07:38:17.152925 2026] [security2:error] [pid 255769:tid 256022] [client 4.204.201.85:55979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/mac.php"] [unique_id "al9MGbxMYwyVGnfuwsKdUQAABBw"]
[Tue Jul 21 07:38:17.177117 2026] [security2:error] [pid 255769:tid 255970] [client 193.36.225.152:54549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MGbxMYwyVGnfuwsKdUgAAA-o"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:17.459202 2026] [security2:error] [pid 254995:tid 255162] [client 4.204.201.85:55939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wefile.php"] [unique_id "al9MGf7v0rlcEGmVraFCIwAAA0M"]
[Tue Jul 21 07:38:17.522909 2026] [security2:error] [pid 255769:tid 255802] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/simple.php"] [unique_id "al9MGbxMYwyVGnfuwsKdXAADtCA"], referer: http://aud-7.com/simple.php
[Tue Jul 21 07:38:17.608636 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.608709 2026] [proxy_http:error] [pid 255769:tid 255960] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.609272 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.609309 2026] [proxy_http:error] [pid 255769:tid 255960] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.628315 2026] [proxy:error] [pid 255769:tid 255992] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.628380 2026] [proxy_http:error] [pid 255769:tid 255992] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.628830 2026] [proxy:error] [pid 255769:tid 255992] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.628856 2026] [proxy_http:error] [pid 255769:tid 255992] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.700967 2026] [security2:error] [pid 255769:tid 255990] [client 31.14.72.5:51353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9MGbxMYwyVGnfuwsKdYwAAA_4"]
[Tue Jul 21 07:38:17.777540 2026] [proxy:error] [pid 254995:tid 255214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.777608 2026] [proxy_http:error] [pid 254995:tid 255214] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.778292 2026] [proxy:error] [pid 254995:tid 255214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.778324 2026] [proxy_http:error] [pid 254995:tid 255214] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.831369 2026] [security2:error] [pid 255769:tid 255855] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGbxMYwyVGnfuwsKdZgAD2FU"]
[Tue Jul 21 07:38:17.831547 2026] [security2:error] [pid 255769:tid 255952] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGbxMYwyVGnfuwsKdZgAD2FU"]
[Tue Jul 21 07:38:17.873774 2026] [security2:error] [pid 255769:tid 255932] [client 20.226.60.151:51378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9MGbxMYwyVGnfuwsKdZwAAA8Q"]
[Tue Jul 21 07:38:17.915042 2026] [proxy:error] [pid 255769:tid 255908] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.915107 2026] [proxy_http:error] [pid 255769:tid 255908] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.915843 2026] [proxy:error] [pid 255769:tid 255908] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:17.915872 2026] [proxy_http:error] [pid 255769:tid 255908] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:17.916370 2026] [security2:error] [pid 254995:tid 255182] [client 20.226.60.151:27587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/cream1.php"] [unique_id "al9MGf7v0rlcEGmVraFCLgAAA1c"]
[Tue Jul 21 07:38:17.958145 2026] [autoindex:error] [pid 255769:tid 256020] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:18.034773 2026] [security2:error] [pid 255769:tid 255801] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/chosen.php"] [unique_id "al9MGrxMYwyVGnfuwsKdbwAD6R8"], referer: http://aud-7.com/chosen.php
[Tue Jul 21 07:38:18.131915 2026] [security2:error] [pid 254995:tid 255225] [client 20.151.10.161:45915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/h02ugyh.php"] [unique_id "al9MGv7v0rlcEGmVraFCMQAAA4E"]
[Tue Jul 21 07:38:18.150328 2026] [security2:error] [pid 254995:tid 255178] [client 20.206.105.145:37928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ms-edit.php"] [unique_id "al9MGv7v0rlcEGmVraFCMwAAA1M"]
[Tue Jul 21 07:38:18.243176 2026] [proxy:error] [pid 255769:tid 255951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.243241 2026] [proxy_http:error] [pid 255769:tid 255951] [client 159.203.172.133:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.243807 2026] [proxy:error] [pid 255769:tid 255951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.243858 2026] [proxy_http:error] [pid 255769:tid 255951] [client 159.203.172.133:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.311275 2026] [security2:error] [pid 254995:tid 255279] [client 175.45.70.82:64999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGv7v0rlcEGmVraFCOAAAA50"]
[Tue Jul 21 07:38:18.311396 2026] [security2:error] [pid 254995:tid 255279] [client 175.45.70.82:64999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGv7v0rlcEGmVraFCOAAAA50"]
[Tue Jul 21 07:38:18.328618 2026] [autoindex:error] [pid 255769:tid 256012] [client 4.204.201.85:55949] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:18.457516 2026] [security2:error] [pid 255769:tid 255906] [client 154.192.233.199:60146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGrxMYwyVGnfuwsKdgQAAA6o"]
[Tue Jul 21 07:38:18.457712 2026] [security2:error] [pid 255769:tid 255906] [client 154.192.233.199:60146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGrxMYwyVGnfuwsKdgQAAA6o"]
[Tue Jul 21 07:38:18.466643 2026] [security2:error] [pid 255769:tid 255899] [client 4.204.201.85:55949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/makeasmtp.php"] [unique_id "al9MGrxMYwyVGnfuwsKdggAAA6M"]
[Tue Jul 21 07:38:18.504240 2026] [proxy:error] [pid 255769:tid 255914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.504302 2026] [proxy_http:error] [pid 255769:tid 255914] [client 159.203.172.133:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.reginaldomilagresrei1755908069857.0721679.meusitehostgator.com.br/
[Tue Jul 21 07:38:18.505380 2026] [proxy:error] [pid 255769:tid 255914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.505413 2026] [proxy_http:error] [pid 255769:tid 255914] [client 159.203.172.133:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.reginaldomilagresrei1755908069857.0721679.meusitehostgator.com.br/
[Tue Jul 21 07:38:18.548553 2026] [security2:error] [pid 255769:tid 255816] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/bypass.php"] [unique_id "al9MGrxMYwyVGnfuwsKdiAAD1i4"], referer: http://aud-7.com/bypass.php
[Tue Jul 21 07:38:18.601501 2026] [proxy:error] [pid 254995:tid 255142] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.601570 2026] [proxy_http:error] [pid 254995:tid 255142] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.602238 2026] [proxy:error] [pid 254995:tid 255142] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.602270 2026] [proxy_http:error] [pid 254995:tid 255142] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.636416 2026] [proxy:error] [pid 255769:tid 255974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.636469 2026] [proxy_http:error] [pid 255769:tid 255974] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.636973 2026] [proxy:error] [pid 255769:tid 255974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.637001 2026] [proxy_http:error] [pid 255769:tid 255974] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.768308 2026] [proxy:error] [pid 254995:tid 255145] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.768371 2026] [proxy_http:error] [pid 254995:tid 255145] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.768911 2026] [proxy:error] [pid 254995:tid 255145] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.768936 2026] [proxy_http:error] [pid 254995:tid 255145] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.785408 2026] [security2:error] [pid 255769:tid 255955] [client 122.162.144.145:22758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MGrxMYwyVGnfuwsKdkQAAA9s"]
[Tue Jul 21 07:38:18.785511 2026] [security2:error] [pid 255769:tid 255955] [client 122.162.144.145:22758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MGrxMYwyVGnfuwsKdkQAAA9s"]
[Tue Jul 21 07:38:18.882566 2026] [proxy:error] [pid 254995:tid 255272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.882636 2026] [proxy_http:error] [pid 254995:tid 255272] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.883652 2026] [proxy:error] [pid 254995:tid 255272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.883700 2026] [proxy_http:error] [pid 254995:tid 255272] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.917214 2026] [proxy:error] [pid 255769:tid 255976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.917278 2026] [proxy_http:error] [pid 255769:tid 255976] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.917808 2026] [proxy:error] [pid 255769:tid 255976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.917853 2026] [proxy_http:error] [pid 255769:tid 255976] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.989153 2026] [security2:error] [pid 254995:tid 255144] [client 103.106.20.201:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGv7v0rlcEGmVraFCTAAAAzE"]
[Tue Jul 21 07:38:18.989273 2026] [security2:error] [pid 254995:tid 255144] [client 103.106.20.201:54356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MGv7v0rlcEGmVraFCTAAAAzE"]
[Tue Jul 21 07:38:18.989285 2026] [proxy:error] [pid 255769:tid 255917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.989325 2026] [proxy_http:error] [pid 255769:tid 255917] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:18.989780 2026] [proxy:error] [pid 255769:tid 255917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:18.989801 2026] [proxy_http:error] [pid 255769:tid 255917] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.043496 2026] [security2:error] [pid 255769:tid 255968] [client 4.204.201.85:55551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/2P.php"] [unique_id "al9MG7xMYwyVGnfuwsKduAAAA-g"]
[Tue Jul 21 07:38:19.050887 2026] [security2:error] [pid 254995:tid 255180] [client 31.14.72.5:52036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9MG_7v0rlcEGmVraFCTgAAA1U"]
[Tue Jul 21 07:38:19.060340 2026] [security2:error] [pid 255769:tid 255887] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/config.php"] [unique_id "al9MG7xMYwyVGnfuwsKduQAEE3U"], referer: http://aud-7.com/config.php
[Tue Jul 21 07:38:19.107591 2026] [security2:error] [pid 255769:tid 255996] [client 122.164.127.47:56990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MG7xMYwyVGnfuwsKdugAABAI"]
[Tue Jul 21 07:38:19.109131 2026] [security2:error] [pid 255769:tid 255996] [client 122.164.127.47:56990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MG7xMYwyVGnfuwsKdugAABAI"]
[Tue Jul 21 07:38:19.146841 2026] [security2:error] [pid 255769:tid 256012] [client 20.206.105.145:38090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/222.php"] [unique_id "al9MG7xMYwyVGnfuwsKdvQAABBI"]
[Tue Jul 21 07:38:19.207050 2026] [proxy:error] [pid 255769:tid 255929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.207110 2026] [proxy_http:error] [pid 255769:tid 255929] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.207676 2026] [proxy:error] [pid 255769:tid 255929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.207701 2026] [proxy_http:error] [pid 255769:tid 255929] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.211193 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:51373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/h02ugyh.php"] [unique_id "al9MG_7v0rlcEGmVraFCUQAAA5k"]
[Tue Jul 21 07:38:19.250117 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.250187 2026] [proxy_http:error] [pid 255769:tid 255960] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.250614 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.250638 2026] [proxy_http:error] [pid 255769:tid 255960] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.324572 2026] [proxy:error] [pid 255769:tid 255978] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.324652 2026] [proxy_http:error] [pid 255769:tid 255978] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.325446 2026] [proxy:error] [pid 255769:tid 255978] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.325487 2026] [proxy_http:error] [pid 255769:tid 255978] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.376057 2026] [proxy:error] [pid 254995:tid 255188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.376113 2026] [proxy_http:error] [pid 254995:tid 255188] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.376610 2026] [proxy:error] [pid 254995:tid 255188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.376634 2026] [proxy_http:error] [pid 254995:tid 255188] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.381538 2026] [security2:error] [pid 254995:tid 255215] [client 4.204.201.85:57140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/.well-known/about.php"] [unique_id "al9MG_7v0rlcEGmVraFCWAAAA3c"]
[Tue Jul 21 07:38:19.505181 2026] [proxy:error] [pid 255769:tid 255949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.505255 2026] [proxy_http:error] [pid 255769:tid 255949] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.505803 2026] [proxy:error] [pid 255769:tid 255949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.505847 2026] [proxy_http:error] [pid 255769:tid 255949] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.538515 2026] [proxy:error] [pid 255769:tid 255987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.538590 2026] [proxy_http:error] [pid 255769:tid 255987] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.539222 2026] [proxy:error] [pid 255769:tid 255987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.539250 2026] [proxy_http:error] [pid 255769:tid 255987] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.575002 2026] [security2:error] [pid 255769:tid 255829] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/themes.php"] [unique_id "al9MG7xMYwyVGnfuwsKd0gAD-js"], referer: http://aud-7.com/themes.php
[Tue Jul 21 07:38:19.703343 2026] [security2:error] [pid 255769:tid 255869] [remote 72.167.132.114:35372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/wp-login.php"] [unique_id "al9MG7xMYwyVGnfuwsKd1wADo2M"]
[Tue Jul 21 07:38:19.765321 2026] [proxy:error] [pid 254995:tid 255156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.765393 2026] [proxy_http:error] [pid 254995:tid 255156] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.766011 2026] [proxy:error] [pid 254995:tid 255156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.766055 2026] [proxy_http:error] [pid 254995:tid 255156] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.776211 2026] [security2:error] [pid 255769:tid 255921] [client 20.220.225.223:31173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/hunter.php"] [unique_id "al9MG7xMYwyVGnfuwsKd2gAAA7k"]
[Tue Jul 21 07:38:19.856261 2026] [security2:error] [pid 254995:tid 255172] [client 172.245.102.43:22279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.245.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MG_7v0rlcEGmVraFCZAAAA00"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:19.928066 2026] [proxy:error] [pid 255769:tid 255941] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.928130 2026] [proxy_http:error] [pid 255769:tid 255941] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.928615 2026] [proxy:error] [pid 255769:tid 255941] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:19.928653 2026] [proxy_http:error] [pid 255769:tid 255941] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:19.977729 2026] [security2:error] [pid 255769:tid 255913] [client 20.206.105.145:38112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9MG7xMYwyVGnfuwsKd6QAAA7E"]
[Tue Jul 21 07:38:19.983008 2026] [security2:error] [pid 254995:tid 255039] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MG_7v0rlcEGmVraFCbgADZys"]
[Tue Jul 21 07:38:19.983147 2026] [security2:error] [pid 254995:tid 255198] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MG_7v0rlcEGmVraFCbgADZys"]
[Tue Jul 21 07:38:20.030242 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.030306 2026] [proxy_http:error] [pid 255769:tid 256017] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.030770 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.030806 2026] [proxy_http:error] [pid 255769:tid 256017] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.049666 2026] [security2:error] [pid 255769:tid 255859] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MHLxMYwyVGnfuwsKd7gAD01k"]
[Tue Jul 21 07:38:20.049807 2026] [security2:error] [pid 255769:tid 255947] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MHLxMYwyVGnfuwsKd7gAD01k"]
[Tue Jul 21 07:38:20.096249 2026] [security2:error] [pid 255769:tid 255877] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/admin.php"] [unique_id "al9MHLxMYwyVGnfuwsKd8AAD4ms"], referer: http://aud-7.com/admin.php
[Tue Jul 21 07:38:20.116233 2026] [security2:error] [pid 254995:tid 255273] [client 4.204.201.85:57159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9MHP7v0rlcEGmVraFCcgAAA5c"]
[Tue Jul 21 07:38:20.172032 2026] [security2:error] [pid 255769:tid 256021] [client 20.226.60.151:27593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/dr.php"] [unique_id "al9MHLxMYwyVGnfuwsKd9gAABBs"]
[Tue Jul 21 07:38:20.218823 2026] [security2:error] [pid 255769:tid 255908] [client 20.226.60.151:56217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MHLxMYwyVGnfuwsKd-QAAA6w"]
[Tue Jul 21 07:38:20.400481 2026] [security2:error] [pid 255769:tid 255966] [client 31.14.72.5:52728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9MHLxMYwyVGnfuwsKd_QAAA-Y"]
[Tue Jul 21 07:38:20.411083 2026] [proxy:error] [pid 255769:tid 255935] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.411152 2026] [proxy_http:error] [pid 255769:tid 255935] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.411667 2026] [proxy:error] [pid 255769:tid 255935] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.411691 2026] [proxy_http:error] [pid 255769:tid 255935] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.448406 2026] [security2:error] [pid 255769:tid 255914] [client 20.197.192.193:59959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MHLxMYwyVGnfuwsKeAQAAA7I"]
[Tue Jul 21 07:38:20.468400 2026] [security2:error] [pid 254995:tid 255224] [client 20.197.192.193:59912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MHP7v0rlcEGmVraFCfAAAA4A"]
[Tue Jul 21 07:38:20.479211 2026] [security2:error] [pid 255769:tid 255954] [client 20.197.192.193:20768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/dp.php"] [unique_id "al9MHLxMYwyVGnfuwsKeBQAAA9o"]
[Tue Jul 21 07:38:20.495654 2026] [proxy:error] [pid 255769:tid 255917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.495723 2026] [proxy_http:error] [pid 255769:tid 255917] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.496435 2026] [proxy:error] [pid 255769:tid 255917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.496468 2026] [proxy_http:error] [pid 255769:tid 255917] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.498649 2026] [security2:error] [pid 255769:tid 255984] [client 20.197.192.193:59937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/old.php"] [unique_id "al9MHLxMYwyVGnfuwsKeBwAAA_g"]
[Tue Jul 21 07:38:20.545988 2026] [security2:error] [pid 255769:tid 255953] [client 20.197.192.193:20755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/ms-new.php"] [unique_id "al9MHLxMYwyVGnfuwsKeCQAAA9k"]
[Tue Jul 21 07:38:20.609264 2026] [security2:error] [pid 255769:tid 255873] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/about.php"] [unique_id "al9MHLxMYwyVGnfuwsKeCgADpWc"], referer: http://aud-7.com/about.php
[Tue Jul 21 07:38:20.618289 2026] [security2:error] [pid 254995:tid 255173] [client 20.197.192.193:59909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/track.php"] [unique_id "al9MHP7v0rlcEGmVraFCgQAAA04"]
[Tue Jul 21 07:38:20.618587 2026] [security2:error] [pid 254995:tid 255257] [client 4.204.201.85:55960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/system_log.php"] [unique_id "al9MHP7v0rlcEGmVraFCggAAA4c"]
[Tue Jul 21 07:38:20.630087 2026] [security2:error] [pid 255769:tid 255932] [client 20.197.192.193:20766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/2352356666.php"] [unique_id "al9MHLxMYwyVGnfuwsKeDAAAA8Q"]
[Tue Jul 21 07:38:20.639948 2026] [security2:error] [pid 255769:tid 255989] [client 152.59.154.239:1099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MHLxMYwyVGnfuwsKeDQAAA_0"]
[Tue Jul 21 07:38:20.640050 2026] [security2:error] [pid 255769:tid 255989] [client 152.59.154.239:1099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MHLxMYwyVGnfuwsKeDQAAA_0"]
[Tue Jul 21 07:38:20.641058 2026] [security2:error] [pid 255769:tid 256013] [client 20.197.192.193:20756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/pn.php"] [unique_id "al9MHLxMYwyVGnfuwsKeDgAABBM"]
[Tue Jul 21 07:38:20.650962 2026] [security2:error] [pid 254995:tid 255217] [client 20.197.192.193:59954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9MHP7v0rlcEGmVraFCgwAAA3k"]
[Tue Jul 21 07:38:20.660602 2026] [security2:error] [pid 254995:tid 255168] [client 20.197.192.193:20743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/dr.php"] [unique_id "al9MHP7v0rlcEGmVraFChAAAA0k"]
[Tue Jul 21 07:38:20.668274 2026] [security2:error] [pid 254995:tid 255272] [client 138.197.191.87:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al9MHP7v0rlcEGmVraFChQAAA5Y"]
[Tue Jul 21 07:38:20.672451 2026] [security2:error] [pid 254995:tid 255153] [client 20.197.192.193:20780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/2x.php"] [unique_id "al9MHP7v0rlcEGmVraFChgAAAzo"]
[Tue Jul 21 07:38:20.686257 2026] [security2:error] [pid 254995:tid 255254] [client 20.197.192.193:59932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/kq1.php"] [unique_id "al9MHP7v0rlcEGmVraFChwAAA4Q"]
[Tue Jul 21 07:38:20.697417 2026] [security2:error] [pid 254995:tid 255179] [client 20.197.192.193:20797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/zzz.php"] [unique_id "al9MHP7v0rlcEGmVraFCiAAAA1Q"]
[Tue Jul 21 07:38:20.701336 2026] [security2:error] [pid 254995:tid 255126] [client 184.154.139.46:44982] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "diskvidros.com.br"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "al9MHP7v0rlcEGmVraFCiQAAAx8"]
[Tue Jul 21 07:38:20.710732 2026] [security2:error] [pid 254995:tid 255144] [client 20.197.192.193:59925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wicked.php"] [unique_id "al9MHP7v0rlcEGmVraFCigAAAzE"]
[Tue Jul 21 07:38:20.725483 2026] [security2:error] [pid 255769:tid 255979] [client 20.197.192.193:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/edit.php"] [unique_id "al9MHLxMYwyVGnfuwsKeEAAAA_M"]
[Tue Jul 21 07:38:20.736505 2026] [security2:error] [pid 254995:tid 255165] [client 20.197.192.193:59931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/kua.php"] [unique_id "al9MHP7v0rlcEGmVraFCiwAAA0Y"]
[Tue Jul 21 07:38:20.746904 2026] [security2:error] [pid 254995:tid 255155] [client 20.197.192.193:59949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/ez.php"] [unique_id "al9MHP7v0rlcEGmVraFCjAAAAzw"]
[Tue Jul 21 07:38:20.759771 2026] [security2:error] [pid 254995:tid 255275] [client 20.197.192.193:20772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/fz.php"] [unique_id "al9MHP7v0rlcEGmVraFCjQAAA5k"]
[Tue Jul 21 07:38:20.774973 2026] [proxy:error] [pid 254995:tid 255190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.775029 2026] [proxy_http:error] [pid 254995:tid 255190] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.775471 2026] [proxy:error] [pid 254995:tid 255190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.775492 2026] [proxy_http:error] [pid 254995:tid 255190] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.777589 2026] [security2:error] [pid 254995:tid 255159] [client 20.226.60.151:51379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-temp.php"] [unique_id "al9MHP7v0rlcEGmVraFCkAAAA0A"]
[Tue Jul 21 07:38:20.778144 2026] [security2:error] [pid 254995:tid 255212] [client 20.197.192.193:20742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/la.php"] [unique_id "al9MHP7v0rlcEGmVraFCkQAAA3Q"]
[Tue Jul 21 07:38:20.795510 2026] [security2:error] [pid 254995:tid 255171] [client 20.197.192.193:59905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9MHP7v0rlcEGmVraFCkgAAA0w"]
[Tue Jul 21 07:38:20.807177 2026] [security2:error] [pid 254995:tid 255137] [client 20.197.192.193:59961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/inso.php"] [unique_id "al9MHP7v0rlcEGmVraFCkwAAAyo"]
[Tue Jul 21 07:38:20.824573 2026] [security2:error] [pid 255769:tid 256012] [client 20.151.10.161:46000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/seiso.php"] [unique_id "al9MHLxMYwyVGnfuwsKeEgAABBI"]
[Tue Jul 21 07:38:20.837337 2026] [security2:error] [pid 254995:tid 255188] [client 20.197.192.193:20753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wpx.php"] [unique_id "al9MHP7v0rlcEGmVraFClQAAA10"]
[Tue Jul 21 07:38:20.849598 2026] [security2:error] [pid 255769:tid 255957] [client 20.197.192.193:59921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/berlin.php"] [unique_id "al9MHLxMYwyVGnfuwsKeFAAAA90"]
[Tue Jul 21 07:38:20.859655 2026] [security2:error] [pid 254995:tid 255252] [client 165.227.39.235:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHP7v0rlcEGmVraFClgAAA4M"]
[Tue Jul 21 07:38:20.860847 2026] [security2:error] [pid 254995:tid 255200] [client 20.197.192.193:20745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/billur.php"] [unique_id "al9MHP7v0rlcEGmVraFClwAAA2k"]
[Tue Jul 21 07:38:20.878197 2026] [security2:error] [pid 254995:tid 255211] [client 20.197.192.193:59924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/mimpi.php"] [unique_id "al9MHP7v0rlcEGmVraFCmQAAA3M"]
[Tue Jul 21 07:38:20.888325 2026] [security2:error] [pid 255769:tid 255997] [client 20.197.192.193:59933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/dp.php"] [unique_id "al9MHLxMYwyVGnfuwsKeFgAABAM"]
[Tue Jul 21 07:38:20.899641 2026] [security2:error] [pid 255769:tid 255996] [client 20.197.192.193:20744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/bootstrap.php"] [unique_id "al9MHLxMYwyVGnfuwsKeFwAABAI"]
[Tue Jul 21 07:38:20.911050 2026] [security2:error] [pid 254995:tid 255271] [client 20.197.192.193:20740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wp-editor.php"] [unique_id "al9MHP7v0rlcEGmVraFCmwAAA5U"]
[Tue Jul 21 07:38:20.922540 2026] [security2:error] [pid 254995:tid 255183] [client 20.197.192.193:59957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/cro.php"] [unique_id "al9MHP7v0rlcEGmVraFCnAAAA1g"]
[Tue Jul 21 07:38:20.927121 2026] [proxy:error] [pid 255769:tid 255967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.927167 2026] [proxy_http:error] [pid 255769:tid 255967] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.927706 2026] [proxy:error] [pid 255769:tid 255967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:20.927730 2026] [proxy_http:error] [pid 255769:tid 255967] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:20.933035 2026] [security2:error] [pid 254995:tid 255196] [client 20.197.192.193:20826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/cron-tab.php"] [unique_id "al9MHP7v0rlcEGmVraFCnQAAA2U"]
[Tue Jul 21 07:38:20.933542 2026] [security2:error] [pid 255769:tid 255962] [client 62.102.148.187:41936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9MHLxMYwyVGnfuwsKeGgAAA-I"]
[Tue Jul 21 07:38:20.933617 2026] [security2:error] [pid 255769:tid 255962] [client 62.102.148.187:41936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9MHLxMYwyVGnfuwsKeGgAAA-I"]
[Tue Jul 21 07:38:20.942676 2026] [security2:error] [pid 254995:tid 255184] [client 20.197.192.193:59926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/koiy.php"] [unique_id "al9MHP7v0rlcEGmVraFCngAAA1k"]
[Tue Jul 21 07:38:20.953345 2026] [security2:error] [pid 255769:tid 255944] [client 20.197.192.193:59922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/hp2.php"] [unique_id "al9MHLxMYwyVGnfuwsKeGwAAA9A"]
[Tue Jul 21 07:38:20.963511 2026] [security2:error] [pid 255769:tid 255906] [client 20.197.192.193:20769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/hp3.php"] [unique_id "al9MHLxMYwyVGnfuwsKeHQAAA6o"]
[Tue Jul 21 07:38:20.974343 2026] [security2:error] [pid 255769:tid 256021] [client 20.197.192.193:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/aa1.php"] [unique_id "al9MHLxMYwyVGnfuwsKeHwAABBs"]
[Tue Jul 21 07:38:20.989165 2026] [security2:error] [pid 255769:tid 255956] [client 20.197.192.193:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/acew67.php"] [unique_id "al9MHLxMYwyVGnfuwsKeIAAAA9w"]
[Tue Jul 21 07:38:21.000750 2026] [security2:error] [pid 255769:tid 255910] [client 20.197.192.193:20737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/bscclapb.php"] [unique_id "al9MHLxMYwyVGnfuwsKeIQAAA64"]
[Tue Jul 21 07:38:21.012886 2026] [security2:error] [pid 255769:tid 255961] [client 20.197.192.193:59938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/else1.php"] [unique_id "al9MHbxMYwyVGnfuwsKeIgAAA-E"]
[Tue Jul 21 07:38:21.013390 2026] [security2:error] [pid 255769:tid 255986] [client 103.174.34.15:60990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MHbxMYwyVGnfuwsKeJAAAA_o"]
[Tue Jul 21 07:38:21.013473 2026] [security2:error] [pid 255769:tid 255986] [client 103.174.34.15:60990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MHbxMYwyVGnfuwsKeJAAAA_o"]
[Tue Jul 21 07:38:21.027430 2026] [security2:error] [pid 255769:tid 256000] [client 20.197.192.193:20764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/tkikikoko.php"] [unique_id "al9MHbxMYwyVGnfuwsKeJQAABAY"]
[Tue Jul 21 07:38:21.037712 2026] [security2:error] [pid 254995:tid 255135] [client 20.197.192.193:59956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9MHf7v0rlcEGmVraFCoQAAAyg"]
[Tue Jul 21 07:38:21.049495 2026] [security2:error] [pid 255769:tid 255935] [client 20.197.192.193:20855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wp-css.php"] [unique_id "al9MHbxMYwyVGnfuwsKeJgAAA8c"]
[Tue Jul 21 07:38:21.061425 2026] [security2:error] [pid 254995:tid 255269] [client 20.197.192.193:59916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/wp-explorer.php"] [unique_id "al9MHf7v0rlcEGmVraFCogAAA5M"]
[Tue Jul 21 07:38:21.072975 2026] [security2:error] [pid 255769:tid 255905] [client 20.197.192.193:59934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/akismet.php"] [unique_id "al9MHbxMYwyVGnfuwsKeJwAAA6k"]
[Tue Jul 21 07:38:21.087444 2026] [security2:error] [pid 255769:tid 255981] [client 20.197.192.193:20823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/ace2.php"] [unique_id "al9MHbxMYwyVGnfuwsKeKAAAA_U"]
[Tue Jul 21 07:38:21.105860 2026] [security2:error] [pid 254995:tid 255256] [client 20.197.192.193:59941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.crr.com.br"] [uri "/ms.php"] [unique_id "al9MHf7v0rlcEGmVraFCowAAA4Y"]
[Tue Jul 21 07:38:21.112436 2026] [security2:error] [pid 254995:tid 255043] [remote 104.193.142.247:46438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.142.193.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/wp-login.php"] [unique_id "al9MHf7v0rlcEGmVraFCpAADbS8"]
[Tue Jul 21 07:38:21.127260 2026] [security2:error] [pid 255769:tid 255863] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/style.php"] [unique_id "al9MHbxMYwyVGnfuwsKeKgAD-F0"], referer: http://aud-7.com/style.php
[Tue Jul 21 07:38:21.142574 2026] [autoindex:error] [pid 255769:tid 255900] [client 4.204.201.85:55493] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:21.162984 2026] [security2:error] [pid 255769:tid 255921] [client 37.140.223.117:50435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MHbxMYwyVGnfuwsKeLAAAA7k"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:21.322672 2026] [security2:error] [pid 254995:tid 255150] [client 178.128.207.138:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al9MHf7v0rlcEGmVraFCqgAAAzc"]
[Tue Jul 21 07:38:21.353107 2026] [security2:error] [pid 255769:tid 255932] [client 20.226.60.151:56296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MHbxMYwyVGnfuwsKeMQAAA8Q"]
[Tue Jul 21 07:38:21.378574 2026] [proxy:error] [pid 255769:tid 255928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:21.378635 2026] [proxy_http:error] [pid 255769:tid 255928] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:21.379233 2026] [proxy:error] [pid 255769:tid 255928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:21.379260 2026] [proxy_http:error] [pid 255769:tid 255928] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:21.470827 2026] [autoindex:error] [pid 255769:tid 255989] [client 4.204.201.85:55493] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:21.493051 2026] [security2:error] [pid 255769:tid 255975] [client 147.182.149.75:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9MHbxMYwyVGnfuwsKeNgAAA-8"]
[Tue Jul 21 07:38:21.520538 2026] [security2:error] [pid 255769:tid 255792] [remote 62.60.130.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bomnegociopromotora.com.br"] [uri "/wp-includes/id3/license.txt/"] [unique_id "al9MHbxMYwyVGnfuwsKeOgADsxY"]
[Tue Jul 21 07:38:21.587494 2026] [autoindex:error] [pid 255769:tid 256012] [client 20.206.105.145:38493] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:21.588471 2026] [security2:error] [pid 255769:tid 256003] [client 20.226.60.151:51280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9MHbxMYwyVGnfuwsKePgAABAk"]
[Tue Jul 21 07:38:21.597357 2026] [security2:error] [pid 255769:tid 255997] [client 20.206.105.145:38493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9MHbxMYwyVGnfuwsKeQAAABAM"]
[Tue Jul 21 07:38:21.630610 2026] [security2:error] [pid 255769:tid 255947] [client 64.226.65.160:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHbxMYwyVGnfuwsKeQgAAA9M"]
[Tue Jul 21 07:38:21.638720 2026] [security2:error] [pid 255769:tid 255879] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/file2.php"] [unique_id "al9MHbxMYwyVGnfuwsKeQwAD520"], referer: http://aud-7.com/file2.php
[Tue Jul 21 07:38:21.644610 2026] [security2:error] [pid 255769:tid 255962] [client 4.204.201.85:55493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/crgio.php"] [unique_id "al9MHbxMYwyVGnfuwsKeRAAAA-I"]
[Tue Jul 21 07:38:21.695210 2026] [security2:error] [pid 254995:tid 255277] [client 20.226.60.151:27545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/x.php"] [unique_id "al9MHf7v0rlcEGmVraFCsAAAA5s"]
[Tue Jul 21 07:38:21.777870 2026] [security2:error] [pid 255769:tid 255849] [remote 62.60.130.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bomnegociopromotora.com.br"] [uri "/wp-includes/id3/license.txt/wp-json/batch/v1"] [unique_id "al9MHbxMYwyVGnfuwsKeSQADuE8"]
[Tue Jul 21 07:38:21.779549 2026] [security2:error] [pid 255769:tid 255992] [client 157.245.36.108:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al9MHbxMYwyVGnfuwsKeSgAAA_8"]
[Tue Jul 21 07:38:21.785298 2026] [security2:error] [pid 255769:tid 256028] [client 31.14.72.5:53384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9MHbxMYwyVGnfuwsKeSwAABCI"]
[Tue Jul 21 07:38:21.840567 2026] [security2:error] [pid 255769:tid 255944] [client 74.7.244.3:44416] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "eduhenmac.com.br"] [uri "/robots.txt"] [unique_id "al9MHbxMYwyVGnfuwsKeTQAD0FM"]
[Tue Jul 21 07:38:21.844320 2026] [security2:error] [pid 255769:tid 255983] [client 103.86.117.203:56708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MHbxMYwyVGnfuwsKeTgAAA_c"]
[Tue Jul 21 07:38:21.844475 2026] [security2:error] [pid 255769:tid 255983] [client 103.86.117.203:56708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MHbxMYwyVGnfuwsKeTgAAA_c"]
[Tue Jul 21 07:38:21.915915 2026] [security2:error] [pid 254995:tid 255175] [client 165.227.173.41:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al9MHf7v0rlcEGmVraFCtQAAA1A"]
[Tue Jul 21 07:38:21.920316 2026] [security2:error] [pid 255769:tid 255910] [client 46.101.1.225:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al9MHbxMYwyVGnfuwsKeTwAAA64"]
[Tue Jul 21 07:38:21.926819 2026] [security2:error] [pid 255769:tid 256022] [client 59.96.220.140:62085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MHbxMYwyVGnfuwsKeUAAABBw"]
[Tue Jul 21 07:38:21.926960 2026] [security2:error] [pid 255769:tid 256022] [client 59.96.220.140:62085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MHbxMYwyVGnfuwsKeUAAABBw"]
[Tue Jul 21 07:38:22.011391 2026] [security2:error] [pid 254995:tid 255049] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MHv7v0rlcEGmVraFCtgADnTU"]
[Tue Jul 21 07:38:22.011529 2026] [security2:error] [pid 254995:tid 255279] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MHv7v0rlcEGmVraFCtgADnTU"]
[Tue Jul 21 07:38:22.022012 2026] [security2:error] [pid 254995:tid 255133] [client 64.227.70.2:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHv7v0rlcEGmVraFCtwAAAyY"]
[Tue Jul 21 07:38:22.135867 2026] [security2:error] [pid 254995:tid 255224] [client 4.204.201.85:57152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/pucci.php"] [unique_id "al9MHv7v0rlcEGmVraFCugAAA4A"]
[Tue Jul 21 07:38:22.152702 2026] [security2:error] [pid 255769:tid 255845] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/jsonq.php"] [unique_id "al9MHrxMYwyVGnfuwsKeVAADsks"], referer: http://aud-7.com/jsonq.php
[Tue Jul 21 07:38:22.194204 2026] [security2:error] [pid 254995:tid 254999] [remote 159.65.144.72:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHv7v0rlcEGmVraFCvgADLwM"]
[Tue Jul 21 07:38:22.268085 2026] [security2:error] [pid 254995:tid 255154] [client 20.151.10.161:45900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/155.php"] [unique_id "al9MHv7v0rlcEGmVraFCvwAAAzs"]
[Tue Jul 21 07:38:22.343152 2026] [security2:error] [pid 254995:tid 255056] [remote 159.65.144.72:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHv7v0rlcEGmVraFCwgADeTw"]
[Tue Jul 21 07:38:22.343198 2026] [security2:error] [pid 254995:tid 255145] [client 138.68.86.32:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHv7v0rlcEGmVraFCwwAAAzI"]
[Tue Jul 21 07:38:22.363991 2026] [security2:error] [pid 254995:tid 255168] [client 167.99.210.137:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHv7v0rlcEGmVraFCxAAAA0k"]
[Tue Jul 21 07:38:22.364389 2026] [security2:error] [pid 254995:tid 255222] [client 139.59.143.102:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al9MHv7v0rlcEGmVraFCxQAAA34"]
[Tue Jul 21 07:38:22.368841 2026] [security2:error] [pid 255769:tid 255917] [client 184.154.139.46:45254] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "diskvidros.com.br"] [uri "/index.php"] [unique_id "al9MHbxMYwyVGnfuwsKeMwAAA7U"]
[Tue Jul 21 07:38:22.399195 2026] [security2:error] [pid 254995:tid 255272] [client 138.68.86.32:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHv7v0rlcEGmVraFCxgAAA5Y"]
[Tue Jul 21 07:38:22.420362 2026] [security2:error] [pid 255769:tid 256004] [client 138.68.82.23:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9MHrxMYwyVGnfuwsKeWAAABAo"]
[Tue Jul 21 07:38:22.578477 2026] [autoindex:error] [pid 254995:tid 255191] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:22.618192 2026] [security2:error] [pid 255769:tid 255970] [client 46.101.111.185:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHrxMYwyVGnfuwsKeXwAAA-o"]
[Tue Jul 21 07:38:22.715426 2026] [security2:error] [pid 255769:tid 255814] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/gel4y.php"] [unique_id "al9MHrxMYwyVGnfuwsKeYwAD0yw"], referer: http://aud-7.com/gel4y.php
[Tue Jul 21 07:38:22.751713 2026] [security2:error] [pid 254995:tid 255180] [client 146.190.63.248:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9MHv7v0rlcEGmVraFCzAAAA1U"]
[Tue Jul 21 07:38:22.775127 2026] [security2:error] [pid 255769:tid 255967] [client 165.227.173.41:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MHrxMYwyVGnfuwsKeZAAAA-c"]
[Tue Jul 21 07:38:22.824398 2026] [security2:error] [pid 254995:tid 255177] [client 20.226.60.151:27553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/155.php"] [unique_id "al9MHv7v0rlcEGmVraFCzgAAA1I"]
[Tue Jul 21 07:38:22.857403 2026] [autoindex:error] [pid 255769:tid 255960] [client 20.206.105.145:38108] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:22.878545 2026] [autoindex:error] [pid 255769:tid 255952] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:22.884450 2026] [autoindex:error] [pid 255769:tid 256021] [client 20.206.105.145:38108] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:22.890348 2026] [security2:error] [pid 255769:tid 255992] [client 20.206.105.145:38108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp.php"] [unique_id "al9MHrxMYwyVGnfuwsKeaQAAA_8"]
[Tue Jul 21 07:38:22.981453 2026] [security2:error] [pid 255769:tid 255943] [client 128.127.105.184:49584] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MHrxMYwyVGnfuwsKebgAAA88"]
[Tue Jul 21 07:38:22.981545 2026] [security2:error] [pid 255769:tid 255943] [client 128.127.105.184:49584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MHrxMYwyVGnfuwsKebgAAA88"]
[Tue Jul 21 07:38:23.018083 2026] [security2:error] [pid 255769:tid 255994] [client 4.204.201.85:55960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-temp.php"] [unique_id "al9MH7xMYwyVGnfuwsKebwAABAE"]
[Tue Jul 21 07:38:23.136969 2026] [security2:error] [pid 255769:tid 255901] [client 31.14.72.5:54037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9MH7xMYwyVGnfuwsKecgAAA6U"]
[Tue Jul 21 07:38:23.218050 2026] [security2:error] [pid 254995:tid 255157] [client 184.154.139.46:45966] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "diskvidros.com.br"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al9MH_7v0rlcEGmVraFC2AAAAz4"]
[Tue Jul 21 07:38:23.226690 2026] [security2:error] [pid 255769:tid 255799] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/tiny.php"] [unique_id "al9MH7xMYwyVGnfuwsKedAADyB0"], referer: http://aud-7.com/tiny.php
[Tue Jul 21 07:38:23.362734 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:23.362796 2026] [proxy_http:error] [pid 255769:tid 255981] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:23.363427 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:23.363453 2026] [proxy_http:error] [pid 255769:tid 255981] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:23.537334 2026] [security2:error] [pid 254995:tid 255013] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MH_7v0rlcEGmVraFC4AADZBE"]
[Tue Jul 21 07:38:23.537547 2026] [security2:error] [pid 254995:tid 255195] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MH_7v0rlcEGmVraFC4AADZBE"]
[Tue Jul 21 07:38:23.742379 2026] [security2:error] [pid 255769:tid 255857] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/file.php"] [unique_id "al9MH7xMYwyVGnfuwsKeeQAEClc"], referer: http://aud-7.com/file.php
[Tue Jul 21 07:38:23.772459 2026] [proxy:error] [pid 255769:tid 255907] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:23.772531 2026] [proxy_http:error] [pid 255769:tid 255907] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:23.773234 2026] [proxy:error] [pid 255769:tid 255907] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:23.773265 2026] [proxy_http:error] [pid 255769:tid 255907] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:23.841696 2026] [security2:error] [pid 254995:tid 255256] [client 20.151.10.161:45967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ppp.php"] [unique_id "al9MH_7v0rlcEGmVraFC5wAAA4Y"]
[Tue Jul 21 07:38:23.903788 2026] [security2:error] [pid 255769:tid 255975] [client 20.226.60.151:27599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ops.php"] [unique_id "al9MH7xMYwyVGnfuwsKefQAAA-8"]
[Tue Jul 21 07:38:23.930901 2026] [proxy:error] [pid 255769:tid 255979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:23.930990 2026] [proxy_http:error] [pid 255769:tid 255979] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:23.932215 2026] [proxy:error] [pid 255769:tid 255979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:23.932281 2026] [proxy_http:error] [pid 255769:tid 255979] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:23.963112 2026] [security2:error] [pid 254995:tid 255204] [client 20.226.60.151:56297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/xyn.php"] [unique_id "al9MH_7v0rlcEGmVraFC6QAAA20"]
[Tue Jul 21 07:38:24.260646 2026] [security2:error] [pid 255769:tid 255810] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/alfa.php"] [unique_id "al9MILxMYwyVGnfuwsKehgAD_ig"], referer: http://aud-7.com/alfa.php
[Tue Jul 21 07:38:24.289834 2026] [security2:error] [pid 254995:tid 255132] [client 184.154.139.46:46192] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "diskvidros.com.br"] [uri "/index.php"] [unique_id "al9MH_7v0rlcEGmVraFC6AAAAyU"]
[Tue Jul 21 07:38:24.410863 2026] [proxy:error] [pid 255769:tid 255910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:24.410924 2026] [proxy_http:error] [pid 255769:tid 255910] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:24.411352 2026] [proxy:error] [pid 255769:tid 255910] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:24.411375 2026] [proxy_http:error] [pid 255769:tid 255910] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:24.499127 2026] [security2:error] [pid 254995:tid 255172] [client 31.14.72.5:54692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9MIP7v0rlcEGmVraFC9wAAA00"]
[Tue Jul 21 07:38:24.535354 2026] [security2:error] [pid 255769:tid 255972] [client 4.204.201.85:55501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-admin/js/index.php"] [unique_id "al9MILxMYwyVGnfuwsKekQAAA-w"]
[Tue Jul 21 07:38:24.651501 2026] [security2:error] [pid 255769:tid 255956] [client 20.206.105.145:38475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/abcd.php"] [unique_id "al9MILxMYwyVGnfuwsKelQAAA9w"]
[Tue Jul 21 07:38:24.658759 2026] [security2:error] [pid 255769:tid 256013] [client 117.217.38.194:54623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MILxMYwyVGnfuwsKelwAABBM"]
[Tue Jul 21 07:38:24.658882 2026] [security2:error] [pid 255769:tid 256013] [client 117.217.38.194:54623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MILxMYwyVGnfuwsKelwAABBM"]
[Tue Jul 21 07:38:24.693906 2026] [security2:error] [pid 255769:tid 255932] [client 128.199.182.55:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9MILxMYwyVGnfuwsKemQAAA8Q"]
[Tue Jul 21 07:38:24.774083 2026] [security2:error] [pid 255769:tid 255807] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/403.php"] [unique_id "al9MILxMYwyVGnfuwsKemwAD_SU"], referer: http://aud-7.com/403.php
[Tue Jul 21 07:38:24.969089 2026] [security2:error] [pid 255769:tid 255953] [client 193.36.225.69:42903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MILxMYwyVGnfuwsKenQAAA9k"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:25.261039 2026] [security2:error] [pid 254995:tid 255058] [remote 41.76.214.143:51408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9MIf7v0rlcEGmVraFDDQADbD4"]
[Tue Jul 21 07:38:25.287739 2026] [security2:error] [pid 255769:tid 255782] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/m.php"] [unique_id "al9MIbxMYwyVGnfuwsKeywAEBgw"], referer: http://aud-7.com/m.php
[Tue Jul 21 07:38:25.454478 2026] [security2:error] [pid 255769:tid 255912] [client 20.226.60.151:27617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file31.php"] [unique_id "al9MIbxMYwyVGnfuwsKe1gAAA7A"]
[Tue Jul 21 07:38:25.502144 2026] [proxy:error] [pid 255769:tid 255956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:25.502219 2026] [proxy_http:error] [pid 255769:tid 255956] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:25.502774 2026] [proxy:error] [pid 255769:tid 255956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:25.502807 2026] [proxy_http:error] [pid 255769:tid 255956] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:25.570379 2026] [security2:error] [pid 255769:tid 255950] [client 173.24.185.52:58984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MIbxMYwyVGnfuwsKe4QAAA9Y"]
[Tue Jul 21 07:38:25.570468 2026] [security2:error] [pid 255769:tid 255950] [client 173.24.185.52:58984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MIbxMYwyVGnfuwsKe4QAAA9Y"]
[Tue Jul 21 07:38:25.584199 2026] [security2:error] [pid 255769:tid 255964] [client 4.204.201.85:60621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/puc.php"] [unique_id "al9MIbxMYwyVGnfuwsKe4wAAA-Q"]
[Tue Jul 21 07:38:25.776758 2026] [proxy:error] [pid 255769:tid 255979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:25.776835 2026] [proxy_http:error] [pid 255769:tid 255979] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:25.777506 2026] [proxy:error] [pid 255769:tid 255979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:25.777533 2026] [proxy_http:error] [pid 255769:tid 255979] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:25.797842 2026] [security2:error] [pid 255769:tid 255887] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/a.php"] [unique_id "al9MIbxMYwyVGnfuwsKe6wADs3U"], referer: http://aud-7.com/a.php
[Tue Jul 21 07:38:25.832195 2026] [security2:error] [pid 255769:tid 256021] [client 31.14.72.5:55372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9MIbxMYwyVGnfuwsKe7QAABBs"]
[Tue Jul 21 07:38:25.935183 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:25.935256 2026] [proxy_http:error] [pid 255769:tid 255981] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:25.935810 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:25.935845 2026] [proxy_http:error] [pid 255769:tid 255981] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.146062 2026] [security2:error] [pid 254995:tid 255162] [client 62.102.148.187:41940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MIv7v0rlcEGmVraFDIQAAA0M"]
[Tue Jul 21 07:38:26.146151 2026] [security2:error] [pid 254995:tid 255162] [client 62.102.148.187:41940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MIv7v0rlcEGmVraFDIQAAA0M"]
[Tue Jul 21 07:38:26.311534 2026] [security2:error] [pid 255769:tid 255885] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/1.php"] [unique_id "al9MIrxMYwyVGnfuwsKe9QAD-3M"], referer: http://aud-7.com/1.php
[Tue Jul 21 07:38:26.406881 2026] [security2:error] [pid 254995:tid 255172] [client 20.226.60.151:27588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file6.php"] [unique_id "al9MIv7v0rlcEGmVraFDMAAAA00"]
[Tue Jul 21 07:38:26.441300 2026] [security2:error] [pid 255769:tid 255904] [client 20.206.105.145:38517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/a1.php"] [unique_id "al9MIrxMYwyVGnfuwsKe-AAAA6g"]
[Tue Jul 21 07:38:26.446572 2026] [security2:error] [pid 254995:tid 255277] [client 20.220.225.223:38688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/byp8.php"] [unique_id "al9MIv7v0rlcEGmVraFDMQAAA5s"]
[Tue Jul 21 07:38:26.500268 2026] [proxy:error] [pid 254995:tid 255223] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.500335 2026] [proxy_http:error] [pid 254995:tid 255223] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.500921 2026] [proxy:error] [pid 254995:tid 255223] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.500952 2026] [proxy_http:error] [pid 254995:tid 255223] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.504055 2026] [proxy:error] [pid 254995:tid 255128] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.504100 2026] [proxy_http:error] [pid 254995:tid 255128] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.504525 2026] [proxy:error] [pid 254995:tid 255128] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.504546 2026] [proxy_http:error] [pid 254995:tid 255128] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.622726 2026] [security2:error] [pid 255769:tid 255957] [client 37.140.223.190:57951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MILxMYwyVGnfuwsKekAAAA90"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:26.692949 2026] [security2:error] [pid 255769:tid 255970] [client 117.251.86.144:34794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MIrxMYwyVGnfuwsKfAgAAA-o"]
[Tue Jul 21 07:38:26.693067 2026] [security2:error] [pid 255769:tid 255970] [client 117.251.86.144:34794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MIrxMYwyVGnfuwsKfAgAAA-o"]
[Tue Jul 21 07:38:26.700366 2026] [security2:error] [pid 254995:tid 255257] [client 20.226.60.151:27564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/adminfuns.php"] [unique_id "al9MIv7v0rlcEGmVraFDPQAAA4c"]
[Tue Jul 21 07:38:26.748414 2026] [proxy:error] [pid 255769:tid 255956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.748476 2026] [proxy_http:error] [pid 255769:tid 255956] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.748978 2026] [proxy:error] [pid 255769:tid 255956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.749000 2026] [proxy_http:error] [pid 255769:tid 255956] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.776712 2026] [proxy:error] [pid 254995:tid 255143] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.776774 2026] [proxy_http:error] [pid 254995:tid 255143] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.777237 2026] [proxy:error] [pid 254995:tid 255143] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.777263 2026] [proxy_http:error] [pid 254995:tid 255143] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.785599 2026] [proxy:error] [pid 254995:tid 255140] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.785671 2026] [proxy_http:error] [pid 254995:tid 255140] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.786552 2026] [proxy:error] [pid 254995:tid 255140] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:26.786603 2026] [proxy_http:error] [pid 254995:tid 255140] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:26.822464 2026] [security2:error] [pid 255769:tid 255984] [client 4.204.201.85:57201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/dx.php"] [unique_id "al9MIrxMYwyVGnfuwsKfBwAAA_g"]
[Tue Jul 21 07:38:26.825831 2026] [security2:error] [pid 255769:tid 255784] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/x.php"] [unique_id "al9MIrxMYwyVGnfuwsKfCAAD_Q4"], referer: http://aud-7.com/x.php
[Tue Jul 21 07:38:26.893370 2026] [security2:error] [pid 255769:tid 255928] [client 122.186.204.214:60176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MIrxMYwyVGnfuwsKfCgAAA8A"]
[Tue Jul 21 07:38:26.893546 2026] [security2:error] [pid 255769:tid 255928] [client 122.186.204.214:60176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MIrxMYwyVGnfuwsKfCgAAA8A"]
[Tue Jul 21 07:38:27.081604 2026] [proxy:error] [pid 254995:tid 255179] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.081681 2026] [proxy_http:error] [pid 254995:tid 255179] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.082254 2026] [proxy:error] [pid 254995:tid 255179] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.082288 2026] [proxy_http:error] [pid 254995:tid 255179] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.131247 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.131312 2026] [proxy_http:error] [pid 255769:tid 255960] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.131989 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.132024 2026] [proxy_http:error] [pid 255769:tid 255960] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.161806 2026] [proxy:error] [pid 255769:tid 255952] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.161865 2026] [proxy_http:error] [pid 255769:tid 255952] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.162371 2026] [proxy:error] [pid 255769:tid 255952] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.162403 2026] [proxy_http:error] [pid 255769:tid 255952] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.171028 2026] [security2:error] [pid 255769:tid 255966] [client 31.14.72.5:56040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9MI7xMYwyVGnfuwsKfGwAAA-Y"]
[Tue Jul 21 07:38:27.205634 2026] [security2:error] [pid 254995:tid 255278] [client 20.226.60.151:61004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9MI_7v0rlcEGmVraFDTQAAA5w"]
[Tue Jul 21 07:38:27.216387 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:27575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/goods.php"] [unique_id "al9MI7xMYwyVGnfuwsKfHAAAA_4"]
[Tue Jul 21 07:38:27.329748 2026] [security2:error] [pid 255769:tid 255922] [client 20.226.60.151:27526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/100.php"] [unique_id "al9MI7xMYwyVGnfuwsKfHwAAA7o"]
[Tue Jul 21 07:38:27.335987 2026] [security2:error] [pid 255769:tid 255824] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/ws.php"] [unique_id "al9MI7xMYwyVGnfuwsKfIAAEIjY"], referer: http://aud-7.com/ws.php
[Tue Jul 21 07:38:27.373673 2026] [proxy:error] [pid 255769:tid 255904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.373736 2026] [proxy_http:error] [pid 255769:tid 255904] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.374256 2026] [proxy:error] [pid 255769:tid 255904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.374280 2026] [proxy_http:error] [pid 255769:tid 255904] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.378805 2026] [security2:error] [pid 254995:tid 255252] [client 20.226.60.151:56193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/patie.php"] [unique_id "al9MI_7v0rlcEGmVraFDVAAAA4M"]
[Tue Jul 21 07:38:27.387789 2026] [proxy:error] [pid 255769:tid 256010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.387869 2026] [proxy_http:error] [pid 255769:tid 256010] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.388339 2026] [proxy:error] [pid 255769:tid 256010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.388374 2026] [proxy_http:error] [pid 255769:tid 256010] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.511429 2026] [proxy:error] [pid 254995:tid 255195] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.511483 2026] [proxy_http:error] [pid 254995:tid 255195] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.511906 2026] [proxy:error] [pid 254995:tid 255195] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.511927 2026] [proxy_http:error] [pid 254995:tid 255195] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.543326 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.543396 2026] [proxy_http:error] [pid 254995:tid 255184] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.543957 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.543987 2026] [proxy_http:error] [pid 254995:tid 255184] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.643035 2026] [security2:error] [pid 255769:tid 255826] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MI7xMYwyVGnfuwsKfNwADzzg"]
[Tue Jul 21 07:38:27.643158 2026] [security2:error] [pid 255769:tid 255943] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MI7xMYwyVGnfuwsKfNwADzzg"]
[Tue Jul 21 07:38:27.664418 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.664492 2026] [proxy_http:error] [pid 255769:tid 255981] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.664933 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.664958 2026] [proxy_http:error] [pid 255769:tid 255981] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.681031 2026] [autoindex:error] [pid 255769:tid 255962] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:27.742401 2026] [proxy:error] [pid 254995:tid 255273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.742470 2026] [proxy_http:error] [pid 254995:tid 255273] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.743114 2026] [proxy:error] [pid 254995:tid 255273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.743152 2026] [proxy_http:error] [pid 254995:tid 255273] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.795786 2026] [security2:error] [pid 254995:tid 255223] [client 20.226.60.151:27583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/about.php"] [unique_id "al9MI_7v0rlcEGmVraFDbgAAA38"]
[Tue Jul 21 07:38:27.896269 2026] [proxy:error] [pid 255769:tid 255925] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.896357 2026] [proxy_http:error] [pid 255769:tid 255925] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.897375 2026] [proxy:error] [pid 255769:tid 255925] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.897427 2026] [proxy_http:error] [pid 255769:tid 255925] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.939546 2026] [proxy:error] [pid 255769:tid 255944] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.939595 2026] [proxy_http:error] [pid 255769:tid 255944] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.940101 2026] [proxy:error] [pid 255769:tid 255944] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.940127 2026] [proxy_http:error] [pid 255769:tid 255944] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.953438 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.953489 2026] [proxy_http:error] [pid 255769:tid 256028] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:27.953954 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:27.953990 2026] [proxy_http:error] [pid 255769:tid 256028] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.009768 2026] [security2:error] [pid 255769:tid 255836] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/wp.php"] [unique_id "al9MJLxMYwyVGnfuwsKfUgAEAUI"], referer: http://aud-7.com/wp.php
[Tue Jul 21 07:38:28.035684 2026] [security2:error] [pid 255769:tid 255923] [client 20.151.10.161:45982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/201.php"] [unique_id "al9MJLxMYwyVGnfuwsKfVAAAA7s"]
[Tue Jul 21 07:38:28.084997 2026] [security2:error] [pid 255769:tid 255959] [client 4.204.201.85:55530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/bthil.php"] [unique_id "al9MJLxMYwyVGnfuwsKfVQAAA98"]
[Tue Jul 21 07:38:28.096634 2026] [proxy:error] [pid 255769:tid 255921] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.096697 2026] [proxy_http:error] [pid 255769:tid 255921] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.097368 2026] [proxy:error] [pid 255769:tid 255921] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.097397 2026] [proxy_http:error] [pid 255769:tid 255921] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.135901 2026] [security2:error] [pid 255769:tid 255997] [client 20.206.105.145:38096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9MJLxMYwyVGnfuwsKfWAAABAM"]
[Tue Jul 21 07:38:28.207362 2026] [security2:error] [pid 255769:tid 255910] [client 20.226.60.151:27620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/about.php"] [unique_id "al9MJLxMYwyVGnfuwsKfWwAAA64"]
[Tue Jul 21 07:38:28.280355 2026] [proxy:error] [pid 255769:tid 255913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.280409 2026] [proxy_http:error] [pid 255769:tid 255913] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.280898 2026] [proxy:error] [pid 255769:tid 255913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.280926 2026] [proxy_http:error] [pid 255769:tid 255913] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.332738 2026] [security2:error] [pid 255769:tid 255848] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJLxMYwyVGnfuwsKfZgAD4U4"]
[Tue Jul 21 07:38:28.332879 2026] [security2:error] [pid 255769:tid 255961] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJLxMYwyVGnfuwsKfZgAD4U4"]
[Tue Jul 21 07:38:28.387692 2026] [proxy:error] [pid 255769:tid 255916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.387760 2026] [proxy_http:error] [pid 255769:tid 255916] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.388260 2026] [proxy:error] [pid 255769:tid 255916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.388292 2026] [proxy_http:error] [pid 255769:tid 255916] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.459477 2026] [proxy:error] [pid 255769:tid 255967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.459541 2026] [proxy_http:error] [pid 255769:tid 255967] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.460239 2026] [proxy:error] [pid 255769:tid 255967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.460264 2026] [proxy_http:error] [pid 255769:tid 255967] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.514311 2026] [security2:error] [pid 254995:tid 255224] [client 31.14.72.5:56788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psiqueflix.online"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9MJP7v0rlcEGmVraFDhwAAA4A"]
[Tue Jul 21 07:38:28.526541 2026] [security2:error] [pid 255769:tid 255880] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/modules/scrollbottom/anamama-2.php"] [unique_id "al9MJLxMYwyVGnfuwsKfcAAEGG4"], referer: http://aud-7.com/modules/scrollbottom/anamama-2.php
[Tue Jul 21 07:38:28.571745 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:27568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/admin.php"] [unique_id "al9MJLxMYwyVGnfuwsKfcgAAA_4"]
[Tue Jul 21 07:38:28.637709 2026] [security2:error] [pid 255769:tid 255974] [client 193.36.225.58:23787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MJLxMYwyVGnfuwsKfdAAAA-4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:28.638343 2026] [security2:error] [pid 255769:tid 255992] [client 20.226.60.151:27347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/admin.php"] [unique_id "al9MJLxMYwyVGnfuwsKfdQAAA_8"]
[Tue Jul 21 07:38:28.671966 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.672041 2026] [proxy_http:error] [pid 255769:tid 256017] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.672514 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.672543 2026] [proxy_http:error] [pid 255769:tid 256017] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.684821 2026] [security2:error] [pid 255769:tid 255944] [client 4.204.201.85:61218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/7.php"] [unique_id "al9MJLxMYwyVGnfuwsKfeAAAA9A"]
[Tue Jul 21 07:38:28.824287 2026] [proxy:error] [pid 255769:tid 255947] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.824362 2026] [proxy_http:error] [pid 255769:tid 255947] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.825090 2026] [proxy:error] [pid 255769:tid 255947] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.825131 2026] [proxy_http:error] [pid 255769:tid 255947] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.836645 2026] [security2:error] [pid 255769:tid 255863] [remote 192.249.127.213:45386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.127.249.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9MJLxMYwyVGnfuwsKffwAD810"]
[Tue Jul 21 07:38:28.841171 2026] [proxy:error] [pid 254995:tid 255190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.841232 2026] [proxy_http:error] [pid 254995:tid 255190] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.841855 2026] [proxy:error] [pid 254995:tid 255190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.841891 2026] [proxy_http:error] [pid 254995:tid 255190] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.917692 2026] [security2:error] [pid 254995:tid 255176] [client 139.167.225.182:50433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJP7v0rlcEGmVraFDmAAAA1E"]
[Tue Jul 21 07:38:28.917837 2026] [security2:error] [pid 254995:tid 255176] [client 139.167.225.182:50433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJP7v0rlcEGmVraFDmAAAA1E"]
[Tue Jul 21 07:38:28.929740 2026] [security2:error] [pid 254995:tid 255209] [client 20.226.60.151:27365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/themes.php"] [unique_id "al9MJP7v0rlcEGmVraFDmQAAA3E"]
[Tue Jul 21 07:38:28.957603 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.957671 2026] [proxy_http:error] [pid 254995:tid 255268] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:28.958325 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:28.958361 2026] [proxy_http:error] [pid 254995:tid 255268] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:29.041718 2026] [security2:error] [pid 255769:tid 255895] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/modules/ets_whatsapp/security.php"] [unique_id "al9MJbxMYwyVGnfuwsKfggAD3X0"], referer: http://aud-7.com/modules/ets_whatsapp/security.php
[Tue Jul 21 07:38:29.075715 2026] [security2:error] [pid 254995:tid 255184] [client 20.226.60.151:27581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/.well-known/about.php"] [unique_id "al9MJf7v0rlcEGmVraFDoQAAA1k"]
[Tue Jul 21 07:38:29.136800 2026] [security2:error] [pid 255769:tid 255960] [client 175.45.70.82:65523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJbxMYwyVGnfuwsKfhAAAA-A"]
[Tue Jul 21 07:38:29.136907 2026] [security2:error] [pid 255769:tid 255960] [client 175.45.70.82:65523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJbxMYwyVGnfuwsKfhAAAA-A"]
[Tue Jul 21 07:38:29.148212 2026] [security2:error] [pid 255769:tid 255918] [client 154.192.233.199:59306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJbxMYwyVGnfuwsKfhQAAA7Y"]
[Tue Jul 21 07:38:29.148319 2026] [security2:error] [pid 255769:tid 255918] [client 154.192.233.199:59306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJbxMYwyVGnfuwsKfhQAAA7Y"]
[Tue Jul 21 07:38:29.186570 2026] [proxy:error] [pid 254995:tid 255201] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:29.186629 2026] [proxy_http:error] [pid 254995:tid 255201] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:29.187175 2026] [proxy:error] [pid 254995:tid 255201] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:29.187202 2026] [proxy_http:error] [pid 254995:tid 255201] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:29.233052 2026] [ssl:error] [pid 255769:tid 255936] [client 2.192.64.45:46454] AH02032: Hostname www.quietum-plus.tryhealth.shop provided via SNI and hostname www.bbcgoodfood.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue Jul 21 07:38:29.251972 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:57142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/8.php"] [unique_id "al9MJf7v0rlcEGmVraFDqQAAA0o"]
[Tue Jul 21 07:38:29.290494 2026] [security2:error] [pid 254995:tid 255274] [client 20.226.60.151:27537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9MJf7v0rlcEGmVraFDqgAAA5g"]
[Tue Jul 21 07:38:29.507445 2026] [security2:error] [pid 255769:tid 255902] [client 20.226.60.151:27591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wefile.php"] [unique_id "al9MJbxMYwyVGnfuwsKfkAAAA6Y"]
[Tue Jul 21 07:38:29.516617 2026] [security2:error] [pid 255769:tid 255986] [client 122.164.127.47:57492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MJbxMYwyVGnfuwsKfkgAAA_o"]
[Tue Jul 21 07:38:29.516734 2026] [security2:error] [pid 255769:tid 255986] [client 122.164.127.47:57492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MJbxMYwyVGnfuwsKfkgAAA_o"]
[Tue Jul 21 07:38:29.543553 2026] [security2:error] [pid 254995:tid 255202] [client 122.162.144.145:23167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MJf7v0rlcEGmVraFDswAAA2s"]
[Tue Jul 21 07:38:29.543685 2026] [security2:error] [pid 254995:tid 255202] [client 122.162.144.145:23167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MJf7v0rlcEGmVraFDswAAA2s"]
[Tue Jul 21 07:38:29.555848 2026] [security2:error] [pid 255769:tid 255879] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/cassiopeia/error.php"] [unique_id "al9MJbxMYwyVGnfuwsKfkwAD4W0"], referer: http://aud-7.com/templates/cassiopeia/error.php
[Tue Jul 21 07:38:29.560608 2026] [security2:error] [pid 254995:tid 255223] [client 20.226.60.151:27584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9MJf7v0rlcEGmVraFDtwAAA38"]
[Tue Jul 21 07:38:29.661455 2026] [security2:error] [pid 255769:tid 255916] [client 4.204.201.85:55525] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "qcharge.tryhealth.shop"] [uri "/1.php"] [unique_id "al9MJbxMYwyVGnfuwsKflwAAA7Q"]
[Tue Jul 21 07:38:29.661556 2026] [security2:error] [pid 255769:tid 255916] [client 4.204.201.85:55525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/1.php"] [unique_id "al9MJbxMYwyVGnfuwsKflwAAA7Q"]
[Tue Jul 21 07:38:29.664348 2026] [proxy:error] [pid 255769:tid 255962] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:29.664415 2026] [proxy_http:error] [pid 255769:tid 255962] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:29.665503 2026] [proxy:error] [pid 255769:tid 255962] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:29.665552 2026] [proxy_http:error] [pid 255769:tid 255962] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:29.674786 2026] [security2:error] [pid 254995:tid 255129] [client 37.140.223.117:64573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MJf7v0rlcEGmVraFDuQAAAyI"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:29.753854 2026] [security2:error] [pid 254995:tid 255269] [client 103.106.20.201:54933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJf7v0rlcEGmVraFDwAAAA5M"]
[Tue Jul 21 07:38:29.753978 2026] [security2:error] [pid 254995:tid 255269] [client 103.106.20.201:54933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJf7v0rlcEGmVraFDwAAAA5M"]
[Tue Jul 21 07:38:29.763704 2026] [security2:error] [pid 254995:tid 255143] [client 20.226.60.151:27525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9MJf7v0rlcEGmVraFDwgAAAzA"]
[Tue Jul 21 07:38:29.787248 2026] [security2:error] [pid 254995:tid 255087] [remote 124.55.178.99:45726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tempex.com.br"] [uri "/wp-login.php"] [unique_id "al9MJf7v0rlcEGmVraFDwwADZ1s"]
[Tue Jul 21 07:38:29.795190 2026] [proxy:error] [pid 254995:tid 255222] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:29.795237 2026] [proxy_http:error] [pid 254995:tid 255222] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:29.795713 2026] [proxy:error] [pid 254995:tid 255222] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:29.795736 2026] [proxy_http:error] [pid 254995:tid 255222] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:29.944367 2026] [security2:error] [pid 255769:tid 255971] [client 20.151.10.161:45976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ops.php"] [unique_id "al9MJbxMYwyVGnfuwsKfnAAAA-s"]
[Tue Jul 21 07:38:30.071144 2026] [security2:error] [pid 255769:tid 255849] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/ja_purity/index.php"] [unique_id "al9MJrxMYwyVGnfuwsKfnwAD3k8"], referer: http://aud-7.com/templates/ja_purity/index.php
[Tue Jul 21 07:38:30.087098 2026] [security2:error] [pid 255769:tid 255946] [client 20.226.60.151:27616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/8.php"] [unique_id "al9MJrxMYwyVGnfuwsKfowAAA9I"]
[Tue Jul 21 07:38:30.139646 2026] [security2:error] [pid 255769:tid 255906] [client 20.197.192.193:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MJrxMYwyVGnfuwsKfpAAAA6o"]
[Tue Jul 21 07:38:30.146000 2026] [security2:error] [pid 254995:tid 255146] [client 4.204.201.85:61263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/100.php"] [unique_id "al9MJv7v0rlcEGmVraFD1wAAAzM"]
[Tue Jul 21 07:38:30.181751 2026] [security2:error] [pid 254995:tid 255224] [client 20.197.192.193:42230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MJv7v0rlcEGmVraFD2QAAA4A"]
[Tue Jul 21 07:38:30.208197 2026] [proxy:error] [pid 254995:tid 255144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:30.208255 2026] [proxy_http:error] [pid 254995:tid 255144] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:30.208727 2026] [proxy:error] [pid 254995:tid 255144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:30.208749 2026] [proxy_http:error] [pid 254995:tid 255144] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:30.245308 2026] [security2:error] [pid 255769:tid 255951] [client 20.197.192.193:41570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/dp.php"] [unique_id "al9MJrxMYwyVGnfuwsKfqAAAA9c"]
[Tue Jul 21 07:38:30.321260 2026] [security2:error] [pid 255769:tid 255921] [client 20.197.192.193:41583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/old.php"] [unique_id "al9MJrxMYwyVGnfuwsKfrgAAA7k"]
[Tue Jul 21 07:38:30.399556 2026] [security2:error] [pid 255769:tid 255936] [client 20.197.192.193:41565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/ms-new.php"] [unique_id "al9MJrxMYwyVGnfuwsKfsAAAA8g"]
[Tue Jul 21 07:38:30.432761 2026] [security2:error] [pid 255769:tid 255964] [client 20.197.192.193:48899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/track.php"] [unique_id "al9MJrxMYwyVGnfuwsKftAAAA-Q"]
[Tue Jul 21 07:38:30.452155 2026] [security2:error] [pid 255769:tid 256005] [client 20.197.192.193:60458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/2352356666.php"] [unique_id "al9MJrxMYwyVGnfuwsKftgAABAs"]
[Tue Jul 21 07:38:30.473634 2026] [security2:error] [pid 255769:tid 256021] [client 20.197.192.193:42186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/pn.php"] [unique_id "al9MJrxMYwyVGnfuwsKfugAABBs"]
[Tue Jul 21 07:38:30.480248 2026] [security2:error] [pid 255769:tid 255932] [client 4.204.201.85:55945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/about.php"] [unique_id "al9MJrxMYwyVGnfuwsKfuwAAA8Q"]
[Tue Jul 21 07:38:30.500802 2026] [security2:error] [pid 255769:tid 255901] [client 20.197.192.193:41560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9MJrxMYwyVGnfuwsKfvQAAA6U"]
[Tue Jul 21 07:38:30.519787 2026] [security2:error] [pid 255769:tid 255870] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MJrxMYwyVGnfuwsKfwAADo2Q"]
[Tue Jul 21 07:38:30.519918 2026] [security2:error] [pid 255769:tid 255899] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MJrxMYwyVGnfuwsKfwAADo2Q"]
[Tue Jul 21 07:38:30.534296 2026] [security2:error] [pid 255769:tid 255916] [client 20.197.192.193:42192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/dr.php"] [unique_id "al9MJrxMYwyVGnfuwsKfwQAAA7Q"]
[Tue Jul 21 07:38:30.546268 2026] [security2:error] [pid 255769:tid 255871] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MJrxMYwyVGnfuwsKfwgADs2U"]
[Tue Jul 21 07:38:30.546411 2026] [security2:error] [pid 255769:tid 255915] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MJrxMYwyVGnfuwsKfwgADs2U"]
[Tue Jul 21 07:38:30.553609 2026] [security2:error] [pid 255769:tid 255996] [client 138.197.191.87:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.191.197.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MJrxMYwyVGnfuwsKfwwAABAI"]
[Tue Jul 21 07:38:30.561837 2026] [security2:error] [pid 254995:tid 255268] [client 20.197.192.193:42219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/2x.php"] [unique_id "al9MJv7v0rlcEGmVraFD_AAAA5I"]
[Tue Jul 21 07:38:30.571829 2026] [security2:error] [pid 255769:tid 255917] [client 162.241.63.68:33560] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "liranesuliano.com.br"] [uri "/index.php"] [unique_id "al9MJrxMYwyVGnfuwsKfvAAAA7U"], referer: http://liranesuliano.com.br/wp-cron.php?doing_wp_cron=1784630310.2090170383453369140625
[Tue Jul 21 07:38:30.588914 2026] [security2:error] [pid 255769:tid 255796] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/protostar/error.php"] [unique_id "al9MJrxMYwyVGnfuwsKfxQAD5xo"], referer: http://aud-7.com/templates/protostar/error.php
[Tue Jul 21 07:38:30.634104 2026] [security2:error] [pid 255769:tid 255950] [client 20.226.60.151:27361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MJrxMYwyVGnfuwsKfyAAAA9Y"]
[Tue Jul 21 07:38:30.644966 2026] [security2:error] [pid 254995:tid 255196] [client 20.197.192.193:41594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/kq1.php"] [unique_id "al9MJv7v0rlcEGmVraFD_gAAA2U"]
[Tue Jul 21 07:38:30.669460 2026] [security2:error] [pid 255769:tid 256012] [client 20.197.192.193:42190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/zzz.php"] [unique_id "al9MJrxMYwyVGnfuwsKfywAABBI"]
[Tue Jul 21 07:38:30.694248 2026] [security2:error] [pid 255769:tid 255983] [client 20.197.192.193:41563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wicked.php"] [unique_id "al9MJrxMYwyVGnfuwsKfzAAAA_c"]
[Tue Jul 21 07:38:30.712758 2026] [security2:error] [pid 255769:tid 256022] [client 20.197.192.193:41547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/edit.php"] [unique_id "al9MJrxMYwyVGnfuwsKfzQAABBw"]
[Tue Jul 21 07:38:30.732251 2026] [security2:error] [pid 255769:tid 255947] [client 20.197.192.193:42231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/kua.php"] [unique_id "al9MJrxMYwyVGnfuwsKfzgAAA9M"]
[Tue Jul 21 07:38:30.777630 2026] [security2:error] [pid 255769:tid 255994] [client 20.197.192.193:42225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/ez.php"] [unique_id "al9MJrxMYwyVGnfuwsKfzwAABAE"]
[Tue Jul 21 07:38:30.794236 2026] [security2:error] [pid 255769:tid 255968] [client 162.241.63.68:33560] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "liranesuliano.com.br"] [uri "/index.php"] [unique_id "al9MJrxMYwyVGnfuwsKfxAAAA-g"], referer: http://liranesuliano.com.br/wp-cron.php?doing_wp_cron=1784630310.2090170383453369140625
[Tue Jul 21 07:38:30.830516 2026] [security2:error] [pid 255769:tid 256028] [client 20.197.192.193:41592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/fz.php"] [unique_id "al9MJrxMYwyVGnfuwsKf0QAABCI"]
[Tue Jul 21 07:38:30.864309 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.192.193:42209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/la.php"] [unique_id "al9MJrxMYwyVGnfuwsKf0gAAA7Y"]
[Tue Jul 21 07:38:30.899050 2026] [security2:error] [pid 255769:tid 256017] [client 20.197.192.193:41545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9MJrxMYwyVGnfuwsKf0wAABBc"]
[Tue Jul 21 07:38:30.903683 2026] [security2:error] [pid 255769:tid 256025] [client 4.204.201.85:55528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/admin.php"] [unique_id "al9MJrxMYwyVGnfuwsKf1AAABB8"]
[Tue Jul 21 07:38:30.921915 2026] [security2:error] [pid 255769:tid 255936] [client 20.197.192.193:48949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/inso.php"] [unique_id "al9MJrxMYwyVGnfuwsKf1QAAA8g"]
[Tue Jul 21 07:38:30.935196 2026] [security2:error] [pid 255769:tid 255940] [client 20.197.192.193:42188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wpx.php"] [unique_id "al9MJrxMYwyVGnfuwsKf1gAAA8w"]
[Tue Jul 21 07:38:30.950797 2026] [security2:error] [pid 255769:tid 255957] [client 20.197.192.193:41541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/berlin.php"] [unique_id "al9MJrxMYwyVGnfuwsKf1wAAA90"]
[Tue Jul 21 07:38:30.956524 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:30.956571 2026] [proxy_http:error] [pid 255769:tid 255964] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:30.957028 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:30.957048 2026] [proxy_http:error] [pid 255769:tid 255964] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:30.964556 2026] [security2:error] [pid 255769:tid 255984] [client 20.197.192.193:41597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/billur.php"] [unique_id "al9MJrxMYwyVGnfuwsKf2gAAA_g"]
[Tue Jul 21 07:38:30.980894 2026] [security2:error] [pid 255769:tid 256021] [client 20.197.192.193:42177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/mimpi.php"] [unique_id "al9MJrxMYwyVGnfuwsKf3AAABBs"]
[Tue Jul 21 07:38:30.990054 2026] [security2:error] [pid 255769:tid 255907] [client 20.206.105.145:38498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9MJrxMYwyVGnfuwsKf3gAAA6s"]
[Tue Jul 21 07:38:30.993342 2026] [security2:error] [pid 254995:tid 255135] [client 178.128.207.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.207.128.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MJv7v0rlcEGmVraFEEAAAAyg"]
[Tue Jul 21 07:38:31.005542 2026] [security2:error] [pid 255769:tid 255961] [client 20.197.192.193:41556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/dp.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf3wAAA-E"]
[Tue Jul 21 07:38:31.049838 2026] [security2:error] [pid 254995:tid 255156] [client 20.197.192.193:42224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/bootstrap.php"] [unique_id "al9MJ_7v0rlcEGmVraFEFAAAAz0"]
[Tue Jul 21 07:38:31.101213 2026] [security2:error] [pid 254995:tid 255169] [client 20.197.192.193:41543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wp-editor.php"] [unique_id "al9MJ_7v0rlcEGmVraFEFwAAA0o"]
[Tue Jul 21 07:38:31.105635 2026] [security2:error] [pid 255769:tid 255781] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/beez3/jsstrings.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf4gADtAs"], referer: http://aud-7.com/templates/beez3/jsstrings.php
[Tue Jul 21 07:38:31.115661 2026] [security2:error] [pid 255769:tid 255962] [client 20.197.192.193:41595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/cro.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf4wAAA-I"]
[Tue Jul 21 07:38:31.133404 2026] [security2:error] [pid 255769:tid 255923] [client 20.197.192.193:42226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/cron-tab.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf5AAAA7s"]
[Tue Jul 21 07:38:31.189400 2026] [security2:error] [pid 255769:tid 255950] [client 20.197.192.193:42195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/koiy.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf6QAAA9Y"]
[Tue Jul 21 07:38:31.247228 2026] [security2:error] [pid 254995:tid 255177] [client 147.182.149.75:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.149.182.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MJ_7v0rlcEGmVraFEGwAAA1I"]
[Tue Jul 21 07:38:31.332945 2026] [security2:error] [pid 254995:tid 255150] [client 20.197.192.193:42199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/hp2.php"] [unique_id "al9MJ_7v0rlcEGmVraFEHgAAAzc"]
[Tue Jul 21 07:38:31.365061 2026] [security2:error] [pid 255769:tid 256012] [client 20.197.192.193:42179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/hp3.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf7AAABBI"]
[Tue Jul 21 07:38:31.415315 2026] [security2:error] [pid 254995:tid 255197] [client 4.204.201.85:57104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/edit.php"] [unique_id "al9MJ_7v0rlcEGmVraFEIwAAA2Y"]
[Tue Jul 21 07:38:31.419970 2026] [security2:error] [pid 254995:tid 255223] [client 20.197.192.193:41546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/aa1.php"] [unique_id "al9MJ_7v0rlcEGmVraFEJAAAA38"]
[Tue Jul 21 07:38:31.469268 2026] [security2:error] [pid 254995:tid 255128] [client 20.197.192.193:41555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/acew67.php"] [unique_id "al9MJ_7v0rlcEGmVraFEJQAAAyE"]
[Tue Jul 21 07:38:31.493056 2026] [security2:error] [pid 254995:tid 255151] [client 20.197.192.193:48897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/bscclapb.php"] [unique_id "al9MJ_7v0rlcEGmVraFEJgAAAzg"]
[Tue Jul 21 07:38:31.504606 2026] [security2:error] [pid 255769:tid 255944] [client 64.226.65.160:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.65.226.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf7QAAA9A"]
[Tue Jul 21 07:38:31.524483 2026] [security2:error] [pid 254995:tid 255163] [client 20.197.192.193:41539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/else1.php"] [unique_id "al9MJ_7v0rlcEGmVraFEKQAAA0Q"]
[Tue Jul 21 07:38:31.541735 2026] [security2:error] [pid 255769:tid 255992] [client 20.197.192.193:42239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/tkikikoko.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf7wAAA_8"]
[Tue Jul 21 07:38:31.592102 2026] [security2:error] [pid 255769:tid 255951] [client 20.197.192.193:42222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf8QAAA9c"]
[Tue Jul 21 07:38:31.620492 2026] [security2:error] [pid 255769:tid 255817] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/atomic/index.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf8wAEGC8"], referer: http://aud-7.com/templates/atomic/index.php
[Tue Jul 21 07:38:31.631211 2026] [security2:error] [pid 255769:tid 255910] [client 20.197.192.193:48932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wp-css.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf9AAAA64"]
[Tue Jul 21 07:38:31.644856 2026] [security2:error] [pid 255769:tid 255959] [client 20.197.192.193:42228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/wp-explorer.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf9QAAA98"]
[Tue Jul 21 07:38:31.662316 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:31.662384 2026] [proxy_http:error] [pid 255769:tid 256028] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:31.663020 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:31.663048 2026] [proxy_http:error] [pid 255769:tid 256028] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:31.663173 2026] [security2:error] [pid 254995:tid 255143] [client 20.197.192.193:48941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/akismet.php"] [unique_id "al9MJ_7v0rlcEGmVraFELAAAAzA"]
[Tue Jul 21 07:38:31.675051 2026] [security2:error] [pid 255769:tid 255918] [client 20.197.192.193:42234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/ace2.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf-QAAA7Y"]
[Tue Jul 21 07:38:31.676927 2026] [security2:error] [pid 255769:tid 255960] [client 165.227.173.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.173.227.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf-AAAA-A"]
[Tue Jul 21 07:38:31.690822 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.192.193:41554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.drleandroavelar.com.br"] [uri "/ms.php"] [unique_id "al9MJ7xMYwyVGnfuwsKf-gAABAU"]
[Tue Jul 21 07:38:31.741000 2026] [security2:error] [pid 254995:tid 255140] [client 4.204.201.85:61227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-content/admin.php"] [unique_id "al9MJ_7v0rlcEGmVraFELgAAAy0"]
[Tue Jul 21 07:38:31.806708 2026] [proxy:error] [pid 255769:tid 256019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:31.806770 2026] [proxy_http:error] [pid 255769:tid 256019] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:31.807296 2026] [proxy:error] [pid 255769:tid 256019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:31.807322 2026] [proxy_http:error] [pid 255769:tid 256019] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:31.927898 2026] [security2:error] [pid 255769:tid 255941] [client 103.174.34.15:61480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJ7xMYwyVGnfuwsKgEAAAA80"]
[Tue Jul 21 07:38:31.928027 2026] [security2:error] [pid 255769:tid 255941] [client 103.174.34.15:61480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MJ7xMYwyVGnfuwsKgEAAAA80"]
[Tue Jul 21 07:38:31.938733 2026] [security2:error] [pid 255769:tid 255984] [client 139.59.143.102:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.143.59.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MJ7xMYwyVGnfuwsKgAwAAA_g"]
[Tue Jul 21 07:38:31.968700 2026] [security2:error] [pid 255769:tid 255902] [client 20.206.105.145:38099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/gettest.php"] [unique_id "al9MJ7xMYwyVGnfuwsKgEgAAA6Y"]
[Tue Jul 21 07:38:32.046257 2026] [security2:error] [pid 255769:tid 255949] [client 46.101.1.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.1.101.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKLxMYwyVGnfuwsKgFgAAA9U"]
[Tue Jul 21 07:38:32.114468 2026] [security2:error] [pid 255769:tid 256008] [client 20.226.60.151:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/jj.php"] [unique_id "al9MKLxMYwyVGnfuwsKgGwAABA4"]
[Tue Jul 21 07:38:32.132440 2026] [security2:error] [pid 255769:tid 255786] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/beez3/error.php"] [unique_id "al9MKLxMYwyVGnfuwsKgIgAD5hA"], referer: http://aud-7.com/templates/beez3/error.php
[Tue Jul 21 07:38:32.180621 2026] [proxy:error] [pid 255769:tid 255928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:32.180683 2026] [proxy_http:error] [pid 255769:tid 255928] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:32.181294 2026] [proxy:error] [pid 255769:tid 255928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:32.181325 2026] [proxy_http:error] [pid 255769:tid 255928] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:32.187235 2026] [security2:error] [pid 255769:tid 256012] [client 20.226.60.151:27520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/f6.php"] [unique_id "al9MKLxMYwyVGnfuwsKgNQAABBI"]
[Tue Jul 21 07:38:32.198018 2026] [security2:error] [pid 255769:tid 255917] [client 157.245.36.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.36.245.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKLxMYwyVGnfuwsKgNgAAA7U"]
[Tue Jul 21 07:38:32.251607 2026] [proxy:error] [pid 255769:tid 255925] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:32.251674 2026] [proxy_http:error] [pid 255769:tid 255925] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:32.252152 2026] [proxy:error] [pid 255769:tid 255925] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:32.252182 2026] [proxy_http:error] [pid 255769:tid 255925] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:32.253541 2026] [security2:error] [pid 254995:tid 255153] [client 4.204.201.85:55961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ss.php"] [unique_id "al9MKP7v0rlcEGmVraFENQAAAzo"]
[Tue Jul 21 07:38:32.310803 2026] [security2:error] [pid 255769:tid 256018] [client 167.99.210.137:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.210.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKLxMYwyVGnfuwsKgOgAABBg"]
[Tue Jul 21 07:38:32.329144 2026] [security2:error] [pid 255769:tid 255914] [client 103.86.117.203:57234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MKLxMYwyVGnfuwsKgOwAAA7I"]
[Tue Jul 21 07:38:32.329231 2026] [security2:error] [pid 255769:tid 255914] [client 103.86.117.203:57234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MKLxMYwyVGnfuwsKgOwAAA7I"]
[Tue Jul 21 07:38:32.398757 2026] [security2:error] [pid 254995:tid 255172] [client 165.227.39.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.39.227.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MJ_7v0rlcEGmVraFEIgAAA00"]
[Tue Jul 21 07:38:32.498541 2026] [security2:error] [pid 254995:tid 255165] [client 165.227.173.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.173.227.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKP7v0rlcEGmVraFEPQAAA0Y"]
[Tue Jul 21 07:38:32.511207 2026] [security2:error] [pid 254995:tid 255189] [client 59.96.220.140:62568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MKP7v0rlcEGmVraFEPgAAA14"]
[Tue Jul 21 07:38:32.511323 2026] [security2:error] [pid 254995:tid 255189] [client 59.96.220.140:62568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MKP7v0rlcEGmVraFEPgAAA14"]
[Tue Jul 21 07:38:32.534486 2026] [security2:error] [pid 255769:tid 255939] [client 138.68.82.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.82.68.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKLxMYwyVGnfuwsKgRAAAA8s"]
[Tue Jul 21 07:38:32.574636 2026] [security2:error] [pid 255769:tid 255975] [client 4.204.201.85:55491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/inputs.php"] [unique_id "al9MKLxMYwyVGnfuwsKgRgAAA-8"]
[Tue Jul 21 07:38:32.646409 2026] [security2:error] [pid 255769:tid 255816] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/beez3/index.php"] [unique_id "al9MKLxMYwyVGnfuwsKgSAADpS4"], referer: http://aud-7.com/templates/beez3/index.php
[Tue Jul 21 07:38:32.655583 2026] [security2:error] [pid 255769:tid 255981] [client 20.226.60.151:27594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/inputs.php"] [unique_id "al9MKLxMYwyVGnfuwsKgSQAAA_U"]
[Tue Jul 21 07:38:32.674389 2026] [security2:error] [pid 255769:tid 255916] [client 146.190.63.248:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.63.190.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKLxMYwyVGnfuwsKgSgAAA7Q"]
[Tue Jul 21 07:38:32.773590 2026] [security2:error] [pid 255769:tid 255892] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MKLxMYwyVGnfuwsKgTgAD2no"]
[Tue Jul 21 07:38:32.773690 2026] [security2:error] [pid 255769:tid 255954] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MKLxMYwyVGnfuwsKgTgAD2no"]
[Tue Jul 21 07:38:32.783093 2026] [security2:error] [pid 255769:tid 255966] [client 184.75.223.211:46732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MKLxMYwyVGnfuwsKgUAAAA-Y"]
[Tue Jul 21 07:38:32.783198 2026] [security2:error] [pid 255769:tid 255966] [client 184.75.223.211:46732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MKLxMYwyVGnfuwsKgUAAAA-Y"]
[Tue Jul 21 07:38:32.854126 2026] [security2:error] [pid 255769:tid 256012] [client 20.151.10.161:45917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ingfo.php"] [unique_id "al9MKLxMYwyVGnfuwsKgUwAABBI"]
[Tue Jul 21 07:38:32.889986 2026] [security2:error] [pid 254995:tid 255137] [client 20.220.225.223:38690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/user.php"] [unique_id "al9MKP7v0rlcEGmVraFESAAAAyo"]
[Tue Jul 21 07:38:33.063705 2026] [proxy:error] [pid 255769:tid 255996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.063783 2026] [proxy_http:error] [pid 255769:tid 255996] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.064359 2026] [proxy:error] [pid 255769:tid 255996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.064402 2026] [proxy_http:error] [pid 255769:tid 255996] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.072290 2026] [security2:error] [pid 255769:tid 255972] [client 138.68.86.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.86.68.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKbxMYwyVGnfuwsKgWQAAA-w"]
[Tue Jul 21 07:38:33.105519 2026] [security2:error] [pid 254995:tid 255100] [remote 159.65.144.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.144.65.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKf7v0rlcEGmVraFEUAADTGg"]
[Tue Jul 21 07:38:33.147342 2026] [security2:error] [pid 254995:tid 255275] [client 4.204.201.85:57177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/av.php"] [unique_id "al9MKf7v0rlcEGmVraFEUQAAA5k"]
[Tue Jul 21 07:38:33.160558 2026] [security2:error] [pid 255769:tid 255959] [client 138.68.86.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.86.68.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKbxMYwyVGnfuwsKgXAAAA98"]
[Tue Jul 21 07:38:33.162353 2026] [security2:error] [pid 255769:tid 255777] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/modules/mod%20ariimageslidersa/mod%20ariimageslidersa.php"] [unique_id "al9MKbxMYwyVGnfuwsKgXQADtgc"], referer: http://aud-7.com/modules/mod%20ariimageslidersa/mod%20ariimageslidersa.php
[Tue Jul 21 07:38:33.191073 2026] [proxy:error] [pid 255769:tid 255955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.191137 2026] [proxy_http:error] [pid 255769:tid 255955] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.191792 2026] [proxy:error] [pid 255769:tid 255955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.191835 2026] [proxy_http:error] [pid 255769:tid 255955] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.225744 2026] [security2:error] [pid 255769:tid 255921] [client 20.206.105.145:38470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/simple.php"] [unique_id "al9MKbxMYwyVGnfuwsKgYQAAA7k"]
[Tue Jul 21 07:38:33.249610 2026] [proxy:error] [pid 254995:tid 255183] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.249693 2026] [proxy_http:error] [pid 254995:tid 255183] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.250559 2026] [proxy:error] [pid 254995:tid 255183] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.250609 2026] [proxy_http:error] [pid 254995:tid 255183] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.331487 2026] [security2:error] [pid 255769:tid 255939] [client 20.220.225.223:38705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/we.php"] [unique_id "al9MKbxMYwyVGnfuwsKgZAAAA8s"]
[Tue Jul 21 07:38:33.366204 2026] [security2:error] [pid 255769:tid 255975] [client 20.197.192.193:6387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/2x.php"] [unique_id "al9MKbxMYwyVGnfuwsKgZQAAA-8"]
[Tue Jul 21 07:38:33.372993 2026] [security2:error] [pid 254995:tid 255060] [remote 159.65.144.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.144.65.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKf7v0rlcEGmVraFEVwADiEA"]
[Tue Jul 21 07:38:33.466720 2026] [security2:error] [pid 255769:tid 255956] [client 4.204.201.85:57196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/classwithtostring.php"] [unique_id "al9MKbxMYwyVGnfuwsKgaQAAA9w"]
[Tue Jul 21 07:38:33.491547 2026] [security2:error] [pid 255769:tid 255936] [client 172.245.102.45:48195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MKbxMYwyVGnfuwsKgYwAAA8g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:33.513785 2026] [security2:error] [pid 255769:tid 255902] [client 20.226.60.151:56288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/aa.php"] [unique_id "al9MKbxMYwyVGnfuwsKgawAAA6Y"]
[Tue Jul 21 07:38:33.533451 2026] [security2:error] [pid 255769:tid 255961] [client 20.226.60.151:8606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MKbxMYwyVGnfuwsKgbQAAA-E"]
[Tue Jul 21 07:38:33.535392 2026] [proxy:error] [pid 255769:tid 255899] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.535446 2026] [proxy_http:error] [pid 255769:tid 255899] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.535947 2026] [proxy:error] [pid 255769:tid 255899] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:33.535974 2026] [proxy_http:error] [pid 255769:tid 255899] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:33.616018 2026] [security2:error] [pid 255769:tid 256008] [client 20.226.60.151:51386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9MKbxMYwyVGnfuwsKgcQAABA4"]
[Tue Jul 21 07:38:33.677141 2026] [security2:error] [pid 255769:tid 255832] [remote 185.82.72.203:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aud-7.com"] [uri "/templates/beez/index.php"] [unique_id "al9MKbxMYwyVGnfuwsKgeAAEDD4"], referer: http://aud-7.com/templates/beez/index.php
[Tue Jul 21 07:38:33.774138 2026] [security2:error] [pid 255769:tid 255958] [client 20.197.192.193:6356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/kq1.php"] [unique_id "al9MKbxMYwyVGnfuwsKgegAAA94"]
[Tue Jul 21 07:38:33.795995 2026] [security2:error] [pid 255769:tid 255942] [client 4.204.201.85:57109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-content/themes/index.php"] [unique_id "al9MKbxMYwyVGnfuwsKgewAAA84"]
[Tue Jul 21 07:38:33.884675 2026] [security2:error] [pid 255769:tid 255944] [client 46.101.111.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.111.101.46.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKbxMYwyVGnfuwsKgfwAAA9A"]
[Tue Jul 21 07:38:33.998793 2026] [security2:error] [pid 255769:tid 256018] [client 20.226.60.151:27358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/inputs.php"] [unique_id "al9MKbxMYwyVGnfuwsKggwAABBg"]
[Tue Jul 21 07:38:34.065300 2026] [proxy:error] [pid 255769:tid 255959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.065364 2026] [proxy_http:error] [pid 255769:tid 255959] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.065805 2026] [proxy:error] [pid 255769:tid 255959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.065840 2026] [proxy_http:error] [pid 255769:tid 255959] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.190594 2026] [proxy:error] [pid 255769:tid 256001] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.190660 2026] [proxy_http:error] [pid 255769:tid 256001] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.191255 2026] [proxy:error] [pid 255769:tid 256001] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.191280 2026] [proxy_http:error] [pid 255769:tid 256001] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.245679 2026] [security2:error] [pid 254995:tid 255125] [client 64.227.70.2:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.70.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MKf7v0rlcEGmVraFETgAAAx4"]
[Tue Jul 21 07:38:34.251368 2026] [proxy:error] [pid 255769:tid 255997] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.251442 2026] [proxy_http:error] [pid 255769:tid 255997] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.252569 2026] [proxy:error] [pid 255769:tid 255997] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.252613 2026] [proxy_http:error] [pid 255769:tid 255997] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.363068 2026] [security2:error] [pid 255769:tid 256021] [client 4.204.201.85:57190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-blog.php"] [unique_id "al9MKrxMYwyVGnfuwsKgjgAABBs"]
[Tue Jul 21 07:38:34.432533 2026] [security2:error] [pid 255769:tid 255952] [client 193.36.225.152:46105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MKrxMYwyVGnfuwsKgkwAAA9g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:34.509129 2026] [security2:error] [pid 255769:tid 255846] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MKrxMYwyVGnfuwsKglgADuEw"]
[Tue Jul 21 07:38:34.509302 2026] [security2:error] [pid 255769:tid 255920] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MKrxMYwyVGnfuwsKglgADuEw"]
[Tue Jul 21 07:38:34.510558 2026] [security2:error] [pid 255769:tid 255961] [client 20.226.60.151:56261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/xwpg.php"] [unique_id "al9MKrxMYwyVGnfuwsKglwAAA-E"]
[Tue Jul 21 07:38:34.544837 2026] [proxy:error] [pid 255769:tid 255923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.544905 2026] [proxy_http:error] [pid 255769:tid 255923] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.545362 2026] [proxy:error] [pid 255769:tid 255923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:34.545388 2026] [proxy_http:error] [pid 255769:tid 255923] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:34.665378 2026] [security2:error] [pid 255769:tid 255971] [client 20.226.60.151:8623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MKrxMYwyVGnfuwsKgnQAAA-s"]
[Tue Jul 21 07:38:34.817649 2026] [autoindex:error] [pid 255769:tid 255944] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:34.986145 2026] [security2:error] [pid 255769:tid 255957] [client 62.102.148.187:34608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MKrxMYwyVGnfuwsKgpwAAA90"]
[Tue Jul 21 07:38:34.986232 2026] [security2:error] [pid 255769:tid 255957] [client 62.102.148.187:34608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MKrxMYwyVGnfuwsKgpwAAA90"]
[Tue Jul 21 07:38:35.049550 2026] [security2:error] [pid 255769:tid 255785] [remote 37.60.226.168:54094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.226.60.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moneyclass.com.br"] [uri "/wp-login.php"] [unique_id "al9MK7xMYwyVGnfuwsKgqQADqA8"]
[Tue Jul 21 07:38:35.065018 2026] [proxy:error] [pid 255769:tid 255922] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.065070 2026] [proxy_http:error] [pid 255769:tid 255922] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.065648 2026] [proxy:error] [pid 255769:tid 255922] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.065672 2026] [proxy_http:error] [pid 255769:tid 255922] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.097663 2026] [security2:error] [pid 255769:tid 255968] [client 4.204.201.85:57212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-content/admin.php"] [unique_id "al9MK7xMYwyVGnfuwsKgrAAAA-g"]
[Tue Jul 21 07:38:35.110302 2026] [security2:error] [pid 254995:tid 255133] [client 20.206.105.145:38128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/xxx.php"] [unique_id "al9MK_7v0rlcEGmVraFEeQAAAyY"]
[Tue Jul 21 07:38:35.166615 2026] [security2:error] [pid 255769:tid 255912] [client 117.217.38.194:55099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MK7xMYwyVGnfuwsKgrQAAA7A"]
[Tue Jul 21 07:38:35.166929 2026] [security2:error] [pid 255769:tid 255912] [client 117.217.38.194:55099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MK7xMYwyVGnfuwsKgrQAAA7A"]
[Tue Jul 21 07:38:35.191031 2026] [proxy:error] [pid 254995:tid 255255] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.191096 2026] [proxy_http:error] [pid 254995:tid 255255] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.191534 2026] [proxy:error] [pid 254995:tid 255255] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.191561 2026] [proxy_http:error] [pid 254995:tid 255255] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.209788 2026] [security2:error] [pid 255769:tid 255989] [client 20.226.60.151:8658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/media.php"] [unique_id "al9MK7xMYwyVGnfuwsKgrwAAA_0"]
[Tue Jul 21 07:38:35.229572 2026] [security2:error] [pid 254995:tid 255208] [client 152.59.154.239:60616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MK_7v0rlcEGmVraFEfwAAA3A"]
[Tue Jul 21 07:38:35.229668 2026] [security2:error] [pid 254995:tid 255208] [client 152.59.154.239:60616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MK_7v0rlcEGmVraFEfwAAA3A"]
[Tue Jul 21 07:38:35.243186 2026] [proxy:error] [pid 255769:tid 255987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.243238 2026] [proxy_http:error] [pid 255769:tid 255987] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.243804 2026] [proxy:error] [pid 255769:tid 255987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.243834 2026] [proxy_http:error] [pid 255769:tid 255987] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.267551 2026] [security2:error] [pid 255769:tid 255947] [client 139.167.225.182:51075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MK7xMYwyVGnfuwsKgsgAAA9M"]
[Tue Jul 21 07:38:35.267681 2026] [security2:error] [pid 255769:tid 255947] [client 139.167.225.182:51075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MK7xMYwyVGnfuwsKgsgAAA9M"]
[Tue Jul 21 07:38:35.320310 2026] [security2:error] [pid 255769:tid 256025] [client 20.226.60.151:61186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/txets.php"] [unique_id "al9MK7xMYwyVGnfuwsKgtgAABB8"]
[Tue Jul 21 07:38:35.451971 2026] [security2:error] [pid 255769:tid 255920] [client 20.226.60.151:8730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/images.php"] [unique_id "al9MK7xMYwyVGnfuwsKgvgAAA7g"]
[Tue Jul 21 07:38:35.534085 2026] [proxy:error] [pid 255769:tid 255984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.534144 2026] [proxy_http:error] [pid 255769:tid 255984] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.534595 2026] [proxy:error] [pid 255769:tid 255984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:35.534618 2026] [proxy_http:error] [pid 255769:tid 255984] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:35.565269 2026] [security2:error] [pid 255769:tid 255910] [client 4.204.201.85:55976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/adminfuns.php"] [unique_id "al9MK7xMYwyVGnfuwsKgwAAAA64"]
[Tue Jul 21 07:38:35.965050 2026] [security2:error] [pid 255769:tid 255951] [client 4.204.201.85:55978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/goods.php"] [unique_id "al9MK7xMYwyVGnfuwsKgzwAAA9c"]
[Tue Jul 21 07:38:36.063500 2026] [proxy:error] [pid 254995:tid 255215] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.063572 2026] [proxy_http:error] [pid 254995:tid 255215] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.064195 2026] [proxy:error] [pid 254995:tid 255215] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.064227 2026] [proxy_http:error] [pid 254995:tid 255215] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.164736 2026] [security2:error] [pid 255769:tid 255912] [client 172.245.102.34:35667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MLLxMYwyVGnfuwsKg0gAAA7A"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:36.194262 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.194330 2026] [proxy_http:error] [pid 255769:tid 255981] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.195003 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.195045 2026] [proxy_http:error] [pid 255769:tid 255981] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.223558 2026] [security2:error] [pid 254995:tid 255003] [remote 173.252.82.112:38496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9MLP7v0rlcEGmVraFElQADkgc"]
[Tue Jul 21 07:38:36.261280 2026] [proxy:error] [pid 254995:tid 255135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.261352 2026] [proxy_http:error] [pid 254995:tid 255135] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.261946 2026] [proxy:error] [pid 254995:tid 255135] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.261973 2026] [proxy_http:error] [pid 254995:tid 255135] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.283540 2026] [security2:error] [pid 255769:tid 255987] [client 20.226.60.151:8637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/gecko.php"] [unique_id "al9MLLxMYwyVGnfuwsKg1gAAA_s"]
[Tue Jul 21 07:38:36.352789 2026] [security2:error] [pid 254995:tid 255258] [client 20.226.60.151:27582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/classwithtostring.php"] [unique_id "al9MLP7v0rlcEGmVraFEmwAAA4g"]
[Tue Jul 21 07:38:36.370555 2026] [security2:error] [pid 255769:tid 255932] [client 128.199.182.55:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.182.199.128.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.alessandramartinsstr1782482993283.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MK7xMYwyVGnfuwsKguAAAA8Q"]
[Tue Jul 21 07:38:36.404107 2026] [security2:error] [pid 254995:tid 255142] [client 4.204.201.85:55523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ms-edit.php"] [unique_id "al9MLP7v0rlcEGmVraFEnQAAAy8"]
[Tue Jul 21 07:38:36.534820 2026] [proxy:error] [pid 254995:tid 255136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.534882 2026] [proxy_http:error] [pid 254995:tid 255136] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.535344 2026] [proxy:error] [pid 254995:tid 255136] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:36.535370 2026] [proxy_http:error] [pid 254995:tid 255136] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:36.693526 2026] [security2:error] [pid 254995:tid 255147] [client 173.24.185.52:59463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MLP7v0rlcEGmVraFEpQAAAzQ"]
[Tue Jul 21 07:38:36.693641 2026] [security2:error] [pid 254995:tid 255147] [client 173.24.185.52:59463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MLP7v0rlcEGmVraFEpQAAAzQ"]
[Tue Jul 21 07:38:36.707808 2026] [security2:error] [pid 254995:tid 255202] [client 4.204.201.85:57111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/222.php"] [unique_id "al9MLP7v0rlcEGmVraFEpgAAA2s"]
[Tue Jul 21 07:38:36.708909 2026] [security2:error] [pid 255769:tid 255964] [client 20.226.60.151:8610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/82.php"] [unique_id "al9MLLxMYwyVGnfuwsKg3wAAA-Q"]
[Tue Jul 21 07:38:36.967517 2026] [security2:error] [pid 254995:tid 255277] [client 20.226.60.151:8643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/admin.php"] [unique_id "al9MLP7v0rlcEGmVraFErgAAA5s"]
[Tue Jul 21 07:38:37.039491 2026] [security2:error] [pid 255769:tid 255944] [client 37.140.223.69:57211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MLbxMYwyVGnfuwsKg5QAAA9A"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:37.061927 2026] [proxy:error] [pid 254995:tid 255198] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.061990 2026] [proxy_http:error] [pid 254995:tid 255198] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.062570 2026] [proxy:error] [pid 254995:tid 255198] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.062599 2026] [proxy_http:error] [pid 254995:tid 255198] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.100037 2026] [security2:error] [pid 254995:tid 255140] [client 4.204.201.85:55990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/cgi-bin/index.php"] [unique_id "al9MLf7v0rlcEGmVraFEtAAAAy0"]
[Tue Jul 21 07:38:37.127444 2026] [security2:error] [pid 255769:tid 255949] [client 20.226.60.151:8598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/adminner.php"] [unique_id "al9MLbxMYwyVGnfuwsKg5gAAA9U"]
[Tue Jul 21 07:38:37.152034 2026] [security2:error] [pid 255769:tid 255989] [client 106.215.181.8:17504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MLLxMYwyVGnfuwsKg4gAAA_0"]
[Tue Jul 21 07:38:37.152176 2026] [security2:error] [pid 255769:tid 255989] [client 106.215.181.8:17504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MLLxMYwyVGnfuwsKg4gAAA_0"]
[Tue Jul 21 07:38:37.168593 2026] [security2:error] [pid 255769:tid 256016] [client 184.75.223.211:46736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MLbxMYwyVGnfuwsKg6wAABBY"]
[Tue Jul 21 07:38:37.168662 2026] [security2:error] [pid 255769:tid 256016] [client 184.75.223.211:46736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MLbxMYwyVGnfuwsKg6wAABBY"]
[Tue Jul 21 07:38:37.194511 2026] [proxy:error] [pid 255769:tid 255990] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.194573 2026] [proxy_http:error] [pid 255769:tid 255990] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.195102 2026] [proxy:error] [pid 255769:tid 255990] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.195130 2026] [proxy_http:error] [pid 255769:tid 255990] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.249719 2026] [proxy:error] [pid 255769:tid 256008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.249780 2026] [proxy_http:error] [pid 255769:tid 256008] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.250507 2026] [proxy:error] [pid 255769:tid 256008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.250547 2026] [proxy_http:error] [pid 255769:tid 256008] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.386731 2026] [security2:error] [pid 255769:tid 256003] [client 20.197.192.193:6855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/zzz.php"] [unique_id "al9MLbxMYwyVGnfuwsKg9AAABAk"]
[Tue Jul 21 07:38:37.424794 2026] [security2:error] [pid 255769:tid 255909] [client 20.226.60.151:51282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/dex.php"] [unique_id "al9MLbxMYwyVGnfuwsKg9QAAA60"]
[Tue Jul 21 07:38:37.439880 2026] [security2:error] [pid 255769:tid 255962] [client 20.226.60.151:8665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/admin.php"] [unique_id "al9MLbxMYwyVGnfuwsKg9gAAA-I"]
[Tue Jul 21 07:38:37.460113 2026] [security2:error] [pid 254995:tid 255149] [client 20.226.60.151:8590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/k.php"] [unique_id "al9MLf7v0rlcEGmVraFEuQAAAzY"]
[Tue Jul 21 07:38:37.475567 2026] [autoindex:error] [pid 254995:tid 255260] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:37.551449 2026] [security2:error] [pid 255769:tid 255912] [client 20.226.60.151:8627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/blurbs.php"] [unique_id "al9MLbxMYwyVGnfuwsKg_QAAA7A"]
[Tue Jul 21 07:38:37.557666 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.557735 2026] [proxy_http:error] [pid 255769:tid 255981] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.558271 2026] [proxy:error] [pid 255769:tid 255981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:37.558298 2026] [proxy_http:error] [pid 255769:tid 255981] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:37.613513 2026] [security2:error] [pid 254995:tid 255217] [client 20.226.60.151:8626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/bajah.php"] [unique_id "al9MLf7v0rlcEGmVraFEwQAAA3k"]
[Tue Jul 21 07:38:37.633390 2026] [security2:error] [pid 255769:tid 256019] [client 122.186.204.214:60700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MLbxMYwyVGnfuwsKhAwAABBk"]
[Tue Jul 21 07:38:37.633535 2026] [security2:error] [pid 255769:tid 256019] [client 122.186.204.214:60700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MLbxMYwyVGnfuwsKhAwAABBk"]
[Tue Jul 21 07:38:37.653927 2026] [security2:error] [pid 255769:tid 256005] [client 117.251.86.144:49744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MLbxMYwyVGnfuwsKhBAAABAs"]
[Tue Jul 21 07:38:37.654090 2026] [security2:error] [pid 255769:tid 256005] [client 117.251.86.144:49744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MLbxMYwyVGnfuwsKhBAAABAs"]
[Tue Jul 21 07:38:37.679639 2026] [security2:error] [pid 255769:tid 255932] [client 20.226.60.151:8624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/a.php"] [unique_id "al9MLbxMYwyVGnfuwsKhBwAAA8Q"]
[Tue Jul 21 07:38:37.721717 2026] [security2:error] [pid 255769:tid 256028] [client 20.206.105.145:38082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/hypo.php"] [unique_id "al9MLbxMYwyVGnfuwsKhCQAABCI"]
[Tue Jul 21 07:38:37.739081 2026] [security2:error] [pid 254995:tid 255144] [client 20.151.10.161:45990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/error_log.php"] [unique_id "al9MLf7v0rlcEGmVraFEwwAAAzE"]
[Tue Jul 21 07:38:37.754229 2026] [security2:error] [pid 255769:tid 256021] [client 4.204.201.85:57153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/BDKR28WP.php"] [unique_id "al9MLbxMYwyVGnfuwsKhCgAABBs"]
[Tue Jul 21 07:38:37.767125 2026] [security2:error] [pid 254995:tid 255210] [client 20.226.60.151:8655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/edit.php"] [unique_id "al9MLf7v0rlcEGmVraFExAAAA3I"]
[Tue Jul 21 07:38:37.833106 2026] [security2:error] [pid 255769:tid 255944] [client 20.226.60.151:8669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/hosty.php"] [unique_id "al9MLbxMYwyVGnfuwsKhDwAAA9A"]
[Tue Jul 21 07:38:37.878365 2026] [security2:error] [pid 255769:tid 255984] [client 20.226.60.151:51292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xpwer1.php"] [unique_id "al9MLbxMYwyVGnfuwsKhEQAAA_g"]
[Tue Jul 21 07:38:37.924974 2026] [security2:error] [pid 255769:tid 256022] [client 20.226.60.151:8690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/k.php"] [unique_id "al9MLbxMYwyVGnfuwsKhFAAABBw"]
[Tue Jul 21 07:38:37.955948 2026] [security2:error] [pid 254995:tid 255206] [client 20.226.60.151:8628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/aaa.php"] [unique_id "al9MLf7v0rlcEGmVraFExwAAA28"]
[Tue Jul 21 07:38:38.027065 2026] [security2:error] [pid 254995:tid 255145] [client 20.226.60.151:8584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/file5.php"] [unique_id "al9MLv7v0rlcEGmVraFEyAAAAzI"]
[Tue Jul 21 07:38:38.064270 2026] [proxy:error] [pid 255769:tid 256008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.064354 2026] [proxy_http:error] [pid 255769:tid 256008] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.065483 2026] [proxy:error] [pid 255769:tid 256008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.065527 2026] [proxy_http:error] [pid 255769:tid 256008] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.096329 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096425 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096534 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096576 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096633 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096740 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096836 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096910 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.096973 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097019 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097055 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097090 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097138 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097191 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097228 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097262 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097317 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097370 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097412 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097464 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097518 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097572 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097621 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097663 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097698 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097734 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097769 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097804 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097916 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.097982 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098050 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098084 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098119 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098173 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098250 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098296 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098336 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098374 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098425 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098460 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098510 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098551 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098590 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098666 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098711 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098746 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098780 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098823 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098874 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098947 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.098982 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099028 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099064 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099100 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099147 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099186 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099240 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099314 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099349 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099400 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099458 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099511 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099557 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099618 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099689 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099741 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099809 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099891 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.099954 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100001 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100061 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100099 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100141 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100176 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100211 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100246 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100280 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100314 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100355 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100389 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100425 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100477 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100520 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100554 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100589 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100623 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100658 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100705 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100744 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100779 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100825 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100861 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100925 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.100967 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.101019 2026] [lsapi:warn] [pid 255769:tid 255936] [client 147.135.175.49:5858] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:38:38.129178 2026] [security2:error] [pid 255769:tid 256012] [client 20.226.60.151:8639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/222.php"] [unique_id "al9MLrxMYwyVGnfuwsKhGAAABBI"]
[Tue Jul 21 07:38:38.177545 2026] [security2:error] [pid 255769:tid 255958] [client 20.226.60.151:8654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/test.php"] [unique_id "al9MLrxMYwyVGnfuwsKhGgAAA94"]
[Tue Jul 21 07:38:38.191929 2026] [proxy:error] [pid 255769:tid 255942] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.191991 2026] [proxy_http:error] [pid 255769:tid 255942] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.192444 2026] [proxy:error] [pid 255769:tid 255942] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.192469 2026] [proxy_http:error] [pid 255769:tid 255942] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.207739 2026] [security2:error] [pid 255769:tid 255988] [client 20.226.60.151:8599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/aaa.php"] [unique_id "al9MLrxMYwyVGnfuwsKhHgAAA_w"]
[Tue Jul 21 07:38:38.215057 2026] [autoindex:error] [pid 254995:tid 255275] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:38.233658 2026] [security2:error] [pid 255769:tid 255829] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MLrxMYwyVGnfuwsKhHwADuzs"]
[Tue Jul 21 07:38:38.233836 2026] [security2:error] [pid 255769:tid 255923] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MLrxMYwyVGnfuwsKhHwADuzs"]
[Tue Jul 21 07:38:38.251669 2026] [proxy:error] [pid 255769:tid 255940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.251768 2026] [proxy_http:error] [pid 255769:tid 255940] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.252941 2026] [proxy:error] [pid 255769:tid 255940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.253000 2026] [proxy_http:error] [pid 255769:tid 255940] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.255001 2026] [security2:error] [pid 254995:tid 255174] [client 20.226.60.151:8609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/11.php"] [unique_id "al9MLv7v0rlcEGmVraFE0gAAA08"]
[Tue Jul 21 07:38:38.275602 2026] [security2:error] [pid 254995:tid 255268] [client 20.226.60.151:8676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/mac.php"] [unique_id "al9MLv7v0rlcEGmVraFE0wAAA5I"]
[Tue Jul 21 07:38:38.332684 2026] [security2:error] [pid 255769:tid 255922] [client 184.75.223.211:37940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MLrxMYwyVGnfuwsKhIgAAA7o"]
[Tue Jul 21 07:38:38.332790 2026] [security2:error] [pid 255769:tid 255922] [client 184.75.223.211:37940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MLrxMYwyVGnfuwsKhIgAAA7o"]
[Tue Jul 21 07:38:38.367825 2026] [security2:error] [pid 255769:tid 255918] [client 20.220.225.223:32312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/ms-new.php"] [unique_id "al9MLrxMYwyVGnfuwsKhJgAAA7Y"]
[Tue Jul 21 07:38:38.435223 2026] [security2:error] [pid 254995:tid 255271] [client 20.226.60.151:8579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/chosen.php"] [unique_id "al9MLv7v0rlcEGmVraFE1wAAA5U"]
[Tue Jul 21 07:38:38.506586 2026] [authz_core:error] [pid 255769:tid 255932] [client 4.204.201.85:0] AH01630: client denied by server configuration: /home1/ofic8899/qcharge.tryhealth.shop/wp-content/uploads/index.php
[Tue Jul 21 07:38:38.518476 2026] [security2:error] [pid 255769:tid 256013] [client 20.226.60.151:8649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/cream1.php"] [unique_id "al9MLrxMYwyVGnfuwsKhKwAABBM"]
[Tue Jul 21 07:38:38.534094 2026] [proxy:error] [pid 255769:tid 255994] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.534164 2026] [proxy_http:error] [pid 255769:tid 255994] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.534880 2026] [proxy:error] [pid 255769:tid 255994] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.534922 2026] [proxy_http:error] [pid 255769:tid 255994] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.596608 2026] [proxy:error] [pid 255769:tid 256025] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.596684 2026] [proxy_http:error] [pid 255769:tid 256025] [client 20.226.60.151:8604] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.597305 2026] [proxy:error] [pid 255769:tid 256025] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.597343 2026] [proxy_http:error] [pid 255769:tid 256025] [client 20.226.60.151:8604] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.649666 2026] [security2:error] [pid 255769:tid 255907] [client 4.204.201.85:57174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp.php"] [unique_id "al9MLrxMYwyVGnfuwsKhMQAAA6s"]
[Tue Jul 21 07:38:38.701868 2026] [proxy:error] [pid 255769:tid 255983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.701915 2026] [proxy_http:error] [pid 255769:tid 255983] [client 20.226.60.151:8648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.702344 2026] [proxy:error] [pid 255769:tid 255983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:38.702366 2026] [proxy_http:error] [pid 255769:tid 255983] [client 20.226.60.151:8648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:38.857202 2026] [security2:error] [pid 255769:tid 255824] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MLrxMYwyVGnfuwsKhOwAD_TY"]
[Tue Jul 21 07:38:38.857386 2026] [security2:error] [pid 255769:tid 255989] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MLrxMYwyVGnfuwsKhOwAD_TY"]
[Tue Jul 21 07:38:38.863461 2026] [security2:error] [pid 255769:tid 255971] [client 20.226.60.151:8661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/dr.php"] [unique_id "al9MLrxMYwyVGnfuwsKhPAAAA-s"]
[Tue Jul 21 07:38:38.935001 2026] [security2:error] [pid 255769:tid 256012] [client 4.204.201.85:57094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/abcd.php"] [unique_id "al9MLrxMYwyVGnfuwsKhQAAABBI"]
[Tue Jul 21 07:38:38.981120 2026] [autoindex:error] [pid 255769:tid 256008] [client 20.206.105.145:38499] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:38.987712 2026] [security2:error] [pid 255769:tid 255934] [client 20.226.60.151:8660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/x.php"] [unique_id "al9MLrxMYwyVGnfuwsKhRAAAA8Y"]
[Tue Jul 21 07:38:38.992654 2026] [security2:error] [pid 255769:tid 255936] [client 20.206.105.145:38499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/chosen.php"] [unique_id "al9MLrxMYwyVGnfuwsKhRQAAA8g"]
[Tue Jul 21 07:38:39.051700 2026] [proxy:error] [pid 255769:tid 255953] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.051764 2026] [proxy_http:error] [pid 255769:tid 255953] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.052203 2026] [proxy:error] [pid 255769:tid 255953] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.052227 2026] [proxy_http:error] [pid 255769:tid 255953] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.060307 2026] [autoindex:error] [pid 255769:tid 256010] [client 20.206.105.145:37941] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:39.064212 2026] [core:alert] [pid 254995:tid 255200] [client 57.141.18.45:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:38:39.072953 2026] [security2:error] [pid 255769:tid 256003] [client 20.206.105.145:37941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/als.php"] [unique_id "al9ML7xMYwyVGnfuwsKhTAAABAk"]
[Tue Jul 21 07:38:39.082358 2026] [security2:error] [pid 255769:tid 255911] [client 20.226.60.151:8629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/155.php"] [unique_id "al9ML7xMYwyVGnfuwsKhTQAAA68"]
[Tue Jul 21 07:38:39.193883 2026] [proxy:error] [pid 255769:tid 255959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.193953 2026] [proxy_http:error] [pid 255769:tid 255959] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.194443 2026] [proxy:error] [pid 255769:tid 255959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.194465 2026] [proxy_http:error] [pid 255769:tid 255959] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.226061 2026] [security2:error] [pid 255769:tid 255918] [client 20.151.10.161:46066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xenon1337.php"] [unique_id "al9ML7xMYwyVGnfuwsKhUQAAA7Y"]
[Tue Jul 21 07:38:39.232055 2026] [security2:error] [pid 255769:tid 255794] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ML7xMYwyVGnfuwsKhSwAD_Bg"]
[Tue Jul 21 07:38:39.232300 2026] [security2:error] [pid 255769:tid 255988] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ML7xMYwyVGnfuwsKhSwAD_Bg"]
[Tue Jul 21 07:38:39.241587 2026] [security2:error] [pid 255769:tid 255912] [client 4.204.201.85:55496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/a1.php"] [unique_id "al9ML7xMYwyVGnfuwsKhUgAAA7A"]
[Tue Jul 21 07:38:39.251796 2026] [proxy:error] [pid 254995:tid 255181] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.251846 2026] [proxy_http:error] [pid 254995:tid 255181] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.252307 2026] [proxy:error] [pid 254995:tid 255181] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.252327 2026] [proxy_http:error] [pid 254995:tid 255181] [client 147.182.149.75:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.283939 2026] [security2:error] [pid 255769:tid 256000] [client 20.226.60.151:8594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ops.php"] [unique_id "al9ML7xMYwyVGnfuwsKhVAAABAY"]
[Tue Jul 21 07:38:39.434870 2026] [security2:error] [pid 254995:tid 255154] [client 20.226.60.151:8668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/file31.php"] [unique_id "al9ML_7v0rlcEGmVraFE8AAAAzs"]
[Tue Jul 21 07:38:39.485224 2026] [security2:error] [pid 255769:tid 255915] [client 20.226.60.151:8702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/file6.php"] [unique_id "al9ML7xMYwyVGnfuwsKhVgAAA7M"]
[Tue Jul 21 07:38:39.489751 2026] [security2:error] [pid 255769:tid 255941] [client 74.7.230.27:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealth.shop"] [uri "/index.php"] [unique_id "al9MLrxMYwyVGnfuwsKhQwAAA80"]
[Tue Jul 21 07:38:39.490834 2026] [security2:error] [pid 255769:tid 255935] [client 74.7.230.27:34028] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealth.shop"] [uri "/robots.txt"] [unique_id "al9MLrxMYwyVGnfuwsKhQQADx2A"]
[Tue Jul 21 07:38:39.499555 2026] [proxy:error] [pid 254995:tid 255140] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.499628 2026] [proxy_http:error] [pid 254995:tid 255140] [client 20.226.60.151:8697] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.500103 2026] [proxy:error] [pid 254995:tid 255140] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.500128 2026] [proxy_http:error] [pid 254995:tid 255140] [client 20.226.60.151:8697] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.501574 2026] [security2:error] [pid 254995:tid 255272] [client 20.226.60.151:60995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/flox.php"] [unique_id "al9ML_7v0rlcEGmVraFE9AAAA5Y"]
[Tue Jul 21 07:38:39.537361 2026] [security2:error] [pid 254995:tid 255219] [client 20.226.60.151:8646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/adminfuns.php"] [unique_id "al9ML_7v0rlcEGmVraFE9gAAA3s"]
[Tue Jul 21 07:38:39.537511 2026] [security2:error] [pid 254995:tid 255178] [client 4.204.201.85:60622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9ML_7v0rlcEGmVraFE9wAAA1M"]
[Tue Jul 21 07:38:39.563301 2026] [proxy:error] [pid 254995:tid 255269] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.563371 2026] [proxy_http:error] [pid 254995:tid 255269] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.564100 2026] [proxy:error] [pid 254995:tid 255269] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:39.564131 2026] [proxy_http:error] [pid 254995:tid 255269] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:39.564224 2026] [security2:error] [pid 254995:tid 255149] [client 20.206.105.145:38105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/pol.php"] [unique_id "al9ML_7v0rlcEGmVraFE-QAAAzY"]
[Tue Jul 21 07:38:39.587693 2026] [security2:error] [pid 255769:tid 255964] [client 20.226.60.151:8602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/goods.php"] [unique_id "al9ML7xMYwyVGnfuwsKhWAAAA-Q"]
[Tue Jul 21 07:38:39.605537 2026] [security2:error] [pid 254995:tid 255260] [client 20.197.192.193:6882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wicked.php"] [unique_id "al9ML_7v0rlcEGmVraFE-gAAA4o"]
[Tue Jul 21 07:38:39.620239 2026] [security2:error] [pid 254995:tid 255213] [client 20.226.60.151:8652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/100.php"] [unique_id "al9ML_7v0rlcEGmVraFE-wAAA3U"]
[Tue Jul 21 07:38:39.670400 2026] [security2:error] [pid 254995:tid 255217] [client 20.226.60.151:8596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/about.php"] [unique_id "al9ML_7v0rlcEGmVraFFAAAAA3k"]
[Tue Jul 21 07:38:39.734899 2026] [security2:error] [pid 254995:tid 255210] [client 194.99.104.35:49696] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ML_7v0rlcEGmVraFFAQAAA3I"]
[Tue Jul 21 07:38:39.734998 2026] [security2:error] [pid 254995:tid 255210] [client 194.99.104.35:49696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ML_7v0rlcEGmVraFFAQAAA3I"]
[Tue Jul 21 07:38:39.809767 2026] [security2:error] [pid 255769:tid 255940] [client 175.45.70.82:49645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ML7xMYwyVGnfuwsKhXQAAA8w"]
[Tue Jul 21 07:38:39.809917 2026] [security2:error] [pid 255769:tid 255940] [client 175.45.70.82:49645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ML7xMYwyVGnfuwsKhXQAAA8w"]
[Tue Jul 21 07:38:39.815239 2026] [security2:error] [pid 254995:tid 255189] [client 4.204.201.85:61193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/cgi-bin/admin.php"] [unique_id "al9ML_7v0rlcEGmVraFFBQAAA14"]
[Tue Jul 21 07:38:39.827854 2026] [security2:error] [pid 255769:tid 255949] [client 20.220.225.223:31185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "provendasatacado.com.br"] [uri "/phpinfo.php1"] [unique_id "al9ML7xMYwyVGnfuwsKhXgAAA9U"]
[Tue Jul 21 07:38:39.882495 2026] [security2:error] [pid 255769:tid 255922] [client 154.192.233.199:59278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ML7xMYwyVGnfuwsKhYAAAA7o"]
[Tue Jul 21 07:38:39.882640 2026] [security2:error] [pid 255769:tid 255922] [client 154.192.233.199:59278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ML7xMYwyVGnfuwsKhYAAAA7o"]
[Tue Jul 21 07:38:39.965818 2026] [security2:error] [pid 254995:tid 255148] [client 20.226.60.151:8642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/about.php"] [unique_id "al9ML_7v0rlcEGmVraFFCAAAAzU"]
[Tue Jul 21 07:38:40.034051 2026] [security2:error] [pid 254995:tid 255166] [client 20.206.105.145:37893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file5.php"] [unique_id "al9MMP7v0rlcEGmVraFFCgAAA0c"]
[Tue Jul 21 07:38:40.051305 2026] [security2:error] [pid 255769:tid 255947] [client 122.164.127.47:57997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhZAAAA9M"]
[Tue Jul 21 07:38:40.052881 2026] [security2:error] [pid 255769:tid 255947] [client 122.164.127.47:57997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhZAAAA9M"]
[Tue Jul 21 07:38:40.066731 2026] [proxy:error] [pid 254995:tid 255278] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.066791 2026] [proxy_http:error] [pid 254995:tid 255278] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.067492 2026] [proxy:error] [pid 254995:tid 255278] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.067521 2026] [proxy_http:error] [pid 254995:tid 255278] [client 46.101.1.225:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.086085 2026] [security2:error] [pid 254995:tid 255145] [client 20.226.60.151:27556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9MMP7v0rlcEGmVraFFDAAAAzI"]
[Tue Jul 21 07:38:40.106531 2026] [security2:error] [pid 255769:tid 255943] [client 4.204.201.85:60544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/gettest.php"] [unique_id "al9MMLxMYwyVGnfuwsKhZQAAA88"]
[Tue Jul 21 07:38:40.162479 2026] [security2:error] [pid 255769:tid 256001] [client 122.162.144.145:17350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhZgAABAc"]
[Tue Jul 21 07:38:40.162614 2026] [security2:error] [pid 255769:tid 256001] [client 122.162.144.145:17350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhZgAABAc"]
[Tue Jul 21 07:38:40.207278 2026] [proxy:error] [pid 254995:tid 255171] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.207347 2026] [proxy_http:error] [pid 254995:tid 255171] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.207894 2026] [proxy:error] [pid 254995:tid 255171] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.207916 2026] [proxy_http:error] [pid 254995:tid 255171] [client 157.245.36.108:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.336745 2026] [security2:error] [pid 254995:tid 255135] [client 20.226.60.151:8597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/admin.php"] [unique_id "al9MMP7v0rlcEGmVraFFGQAAAyg"]
[Tue Jul 21 07:38:40.392949 2026] [security2:error] [pid 254995:tid 255215] [client 20.226.60.151:8650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/admin.php"] [unique_id "al9MMP7v0rlcEGmVraFFIAAAA3c"]
[Tue Jul 21 07:38:40.452228 2026] [security2:error] [pid 255769:tid 255942] [client 20.226.60.151:8592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/themes.php"] [unique_id "al9MMLxMYwyVGnfuwsKhbAAAA84"]
[Tue Jul 21 07:38:40.463104 2026] [security2:error] [pid 255769:tid 255899] [client 103.106.20.201:55515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhbwAAA6M"]
[Tue Jul 21 07:38:40.463200 2026] [security2:error] [pid 255769:tid 255899] [client 103.106.20.201:55515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhbwAAA6M"]
[Tue Jul 21 07:38:40.494894 2026] [security2:error] [pid 255769:tid 255967] [client 20.197.192.193:6391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/edit.php"] [unique_id "al9MMLxMYwyVGnfuwsKhcgAAA-c"]
[Tue Jul 21 07:38:40.499043 2026] [proxy:error] [pid 255769:tid 255959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.499105 2026] [proxy_http:error] [pid 255769:tid 255959] [client 20.226.60.151:8641] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.499733 2026] [proxy:error] [pid 255769:tid 255959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.499760 2026] [proxy_http:error] [pid 255769:tid 255959] [client 20.226.60.151:8641] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.501020 2026] [security2:error] [pid 255769:tid 255917] [client 20.10.88.227:9795] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealth.shop"] [uri "/robots.txt"] [unique_id "al9MMLxMYwyVGnfuwsKhcQAAA7U"]
[Tue Jul 21 07:38:40.537643 2026] [proxy:error] [pid 255769:tid 255986] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.537721 2026] [proxy_http:error] [pid 255769:tid 255986] [client 20.226.60.151:8683] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.538062 2026] [proxy:error] [pid 254995:tid 255138] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.538112 2026] [proxy_http:error] [pid 254995:tid 255138] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.538528 2026] [proxy:error] [pid 255769:tid 255986] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.538531 2026] [proxy:error] [pid 254995:tid 255138] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:40.538564 2026] [proxy_http:error] [pid 254995:tid 255138] [client 138.68.82.23:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.538568 2026] [proxy_http:error] [pid 255769:tid 255986] [client 20.226.60.151:8683] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:40.553126 2026] [security2:error] [pid 254995:tid 255185] [client 4.204.201.85:57122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/simple.php"] [unique_id "al9MMP7v0rlcEGmVraFFJgAAA1o"]
[Tue Jul 21 07:38:40.597160 2026] [security2:error] [pid 254995:tid 255142] [client 20.220.225.223:22492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/track.php"] [unique_id "al9MMP7v0rlcEGmVraFFJwAAAy8"]
[Tue Jul 21 07:38:40.644235 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:8587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/.well-known/about.php"] [unique_id "al9MMP7v0rlcEGmVraFFKQAAA5c"]
[Tue Jul 21 07:38:40.903781 2026] [security2:error] [pid 254995:tid 255163] [client 4.204.201.85:61310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/xxx.php"] [unique_id "al9MMP7v0rlcEGmVraFFLgAAA0Q"]
[Tue Jul 21 07:38:40.914783 2026] [security2:error] [pid 255769:tid 255994] [client 20.226.60.151:8731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9MMLxMYwyVGnfuwsKhewAABAE"]
[Tue Jul 21 07:38:40.979625 2026] [security2:error] [pid 255769:tid 255836] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhfQADzUI"]
[Tue Jul 21 07:38:40.979776 2026] [security2:error] [pid 255769:tid 255941] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MMLxMYwyVGnfuwsKhfQADzUI"]
[Tue Jul 21 07:38:41.019283 2026] [security2:error] [pid 254995:tid 255057] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MMf7v0rlcEGmVraFFMwADOz0"]
[Tue Jul 21 07:38:41.019441 2026] [security2:error] [pid 254995:tid 255154] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MMf7v0rlcEGmVraFFMwADOz0"]
[Tue Jul 21 07:38:41.062551 2026] [security2:error] [pid 255769:tid 255982] [client 20.151.10.161:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/test11.php"] [unique_id "al9MMbxMYwyVGnfuwsKhgQAAA_Y"]
[Tue Jul 21 07:38:41.111590 2026] [security2:error] [pid 255769:tid 255955] [client 20.226.60.151:8612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wefile.php"] [unique_id "al9MMbxMYwyVGnfuwsKhggAAA9s"]
[Tue Jul 21 07:38:41.219969 2026] [security2:error] [pid 255769:tid 255960] [client 128.127.105.184:37040] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MMbxMYwyVGnfuwsKhhAAAA-A"]
[Tue Jul 21 07:38:41.220096 2026] [security2:error] [pid 255769:tid 255960] [client 128.127.105.184:37040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MMbxMYwyVGnfuwsKhhAAAA-A"]
[Tue Jul 21 07:38:41.222389 2026] [security2:error] [pid 255769:tid 255998] [client 4.204.201.85:55994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/hypo.php"] [unique_id "al9MMbxMYwyVGnfuwsKhhQAABAQ"]
[Tue Jul 21 07:38:41.271382 2026] [security2:error] [pid 254995:tid 255129] [client 20.226.60.151:8640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9MMf7v0rlcEGmVraFFOAAAAyI"]
[Tue Jul 21 07:38:41.297039 2026] [security2:error] [pid 254995:tid 255266] [client 20.226.60.151:56222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ops.php"] [unique_id "al9MMf7v0rlcEGmVraFFOQAAA5A"]
[Tue Jul 21 07:38:41.358948 2026] [security2:error] [pid 255769:tid 255902] [client 136.144.33.108:34009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MMbxMYwyVGnfuwsKhiAAAA6Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:41.465960 2026] [proxy:error] [pid 255769:tid 255943] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:41.466046 2026] [proxy_http:error] [pid 255769:tid 255943] [client 20.226.60.151:8737] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:41.466709 2026] [proxy:error] [pid 255769:tid 255943] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:41.466742 2026] [proxy_http:error] [pid 255769:tid 255943] [client 20.226.60.151:8737] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:41.472257 2026] [security2:error] [pid 255769:tid 255975] [client 20.197.192.193:6880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/kua.php"] [unique_id "al9MMbxMYwyVGnfuwsKhigAAA-8"]
[Tue Jul 21 07:38:41.519330 2026] [security2:error] [pid 255769:tid 256001] [client 20.226.60.151:61194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/popo.php"] [unique_id "al9MMbxMYwyVGnfuwsKhiwAABAc"]
[Tue Jul 21 07:38:41.590761 2026] [proxy:error] [pid 255769:tid 255934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:41.590835 2026] [proxy_http:error] [pid 255769:tid 255934] [client 20.226.60.151:8657] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:41.591277 2026] [proxy:error] [pid 255769:tid 255934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:41.591299 2026] [proxy_http:error] [pid 255769:tid 255934] [client 20.226.60.151:8657] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:41.641327 2026] [autoindex:error] [pid 255769:tid 255936] [client 4.204.201.85:55950] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:41.719085 2026] [security2:error] [pid 254995:tid 255173] [client 20.226.60.151:8631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9MMf7v0rlcEGmVraFFQQAAA04"]
[Tue Jul 21 07:38:41.783967 2026] [security2:error] [pid 255769:tid 256010] [client 20.226.60.151:8638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/8.php"] [unique_id "al9MMbxMYwyVGnfuwsKhkQAABBA"]
[Tue Jul 21 07:38:41.792918 2026] [security2:error] [pid 254995:tid 255179] [client 20.206.105.145:38506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9MMf7v0rlcEGmVraFFRAAAA1Q"]
[Tue Jul 21 07:38:41.827235 2026] [security2:error] [pid 255769:tid 255899] [client 20.226.60.151:8607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MMbxMYwyVGnfuwsKhlAAAA6M"]
[Tue Jul 21 07:38:41.893295 2026] [security2:error] [pid 255769:tid 255906] [client 20.151.10.161:46059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/koala.php"] [unique_id "al9MMbxMYwyVGnfuwsKhlgAAA6o"]
[Tue Jul 21 07:38:41.914161 2026] [security2:error] [pid 255769:tid 255967] [client 4.204.201.85:55950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/chosen.php"] [unique_id "al9MMbxMYwyVGnfuwsKhlwAAA-c"]
[Tue Jul 21 07:38:41.938106 2026] [security2:error] [pid 255769:tid 255959] [client 20.226.60.151:8578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/f6.php"] [unique_id "al9MMbxMYwyVGnfuwsKhmAAAA98"]
[Tue Jul 21 07:38:42.027968 2026] [security2:error] [pid 254995:tid 255206] [client 20.226.60.151:27369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-blog.php"] [unique_id "al9MMv7v0rlcEGmVraFFSAAAA28"]
[Tue Jul 21 07:38:42.030059 2026] [security2:error] [pid 255769:tid 255923] [client 20.226.60.151:8600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/inputs.php"] [unique_id "al9MMrxMYwyVGnfuwsKhmQAAA7s"]
[Tue Jul 21 07:38:42.085403 2026] [security2:error] [pid 254995:tid 255137] [client 20.220.225.223:38713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/ops.php"] [unique_id "al9MMv7v0rlcEGmVraFFSQAAAyo"]
[Tue Jul 21 07:38:42.162688 2026] [security2:error] [pid 255769:tid 256018] [client 20.226.60.151:8616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/inputs.php"] [unique_id "al9MMrxMYwyVGnfuwsKhmwAABBg"]
[Tue Jul 21 07:38:42.205124 2026] [security2:error] [pid 255769:tid 256005] [client 20.226.60.151:8662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/classwithtostring.php"] [unique_id "al9MMrxMYwyVGnfuwsKhnAAABAs"]
[Tue Jul 21 07:38:42.220631 2026] [security2:error] [pid 254995:tid 255176] [client 20.226.60.151:8576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9MMv7v0rlcEGmVraFFTQAAA1E"]
[Tue Jul 21 07:38:42.247345 2026] [security2:error] [pid 255769:tid 255999] [client 20.226.60.151:8644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-blog.php"] [unique_id "al9MMrxMYwyVGnfuwsKhnQAABAU"]
[Tue Jul 21 07:38:42.274630 2026] [proxy:error] [pid 254995:tid 255127] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.274708 2026] [proxy_http:error] [pid 254995:tid 255127] [client 20.226.60.151:8705] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.275265 2026] [proxy:error] [pid 254995:tid 255127] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.275292 2026] [proxy_http:error] [pid 254995:tid 255127] [client 20.226.60.151:8705] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.296327 2026] [security2:error] [pid 254995:tid 255141] [client 20.226.60.151:8677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MMv7v0rlcEGmVraFFTwAAAy4"]
[Tue Jul 21 07:38:42.322142 2026] [security2:error] [pid 255769:tid 256028] [client 20.226.60.151:8667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ms-edit.php"] [unique_id "al9MMrxMYwyVGnfuwsKhngAABCI"]
[Tue Jul 21 07:38:42.341205 2026] [security2:error] [pid 254995:tid 255216] [client 20.226.60.151:8591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9MMv7v0rlcEGmVraFFUQAAA3g"]
[Tue Jul 21 07:38:42.387609 2026] [proxy:error] [pid 254995:tid 255162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.387683 2026] [proxy_http:error] [pid 254995:tid 255162] [client 20.226.60.151:8674] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.388305 2026] [proxy:error] [pid 254995:tid 255162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.388331 2026] [proxy_http:error] [pid 254995:tid 255162] [client 20.226.60.151:8674] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.408859 2026] [security2:error] [pid 254995:tid 255258] [client 20.226.60.151:8738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9MMv7v0rlcEGmVraFFVgAAA4g"]
[Tue Jul 21 07:38:42.427436 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.427513 2026] [proxy_http:error] [pid 254995:tid 255184] [client 20.226.60.151:8711] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.428195 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.428229 2026] [proxy_http:error] [pid 254995:tid 255184] [client 20.226.60.151:8711] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.433282 2026] [security2:error] [pid 255769:tid 256025] [client 20.151.10.161:45964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/mac.php"] [unique_id "al9MMrxMYwyVGnfuwsKhoAAABB8"]
[Tue Jul 21 07:38:42.450117 2026] [proxy:error] [pid 255769:tid 255982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.450201 2026] [proxy_http:error] [pid 255769:tid 255982] [client 20.226.60.151:8603] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.451254 2026] [proxy:error] [pid 255769:tid 255982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.451310 2026] [proxy_http:error] [pid 255769:tid 255982] [client 20.226.60.151:8603] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.469771 2026] [security2:error] [pid 255769:tid 256004] [client 20.226.60.151:8718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/abcd.php"] [unique_id "al9MMrxMYwyVGnfuwsKhogAABAo"]
[Tue Jul 21 07:38:42.485051 2026] [autoindex:error] [pid 255769:tid 255940] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:42.507519 2026] [security2:error] [pid 255769:tid 255998] [client 20.226.60.151:8608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/file15.php"] [unique_id "al9MMrxMYwyVGnfuwsKhpgAABAQ"]
[Tue Jul 21 07:38:42.554507 2026] [security2:error] [pid 255769:tid 255984] [client 20.226.60.151:8671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/jp.php"] [unique_id "al9MMrxMYwyVGnfuwsKhqQAAA_g"]
[Tue Jul 21 07:38:42.573041 2026] [security2:error] [pid 254995:tid 255195] [client 128.127.105.184:60942] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MMv7v0rlcEGmVraFFWAAAA2Q"]
[Tue Jul 21 07:38:42.573122 2026] [security2:error] [pid 254995:tid 255195] [client 128.127.105.184:60942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MMv7v0rlcEGmVraFFWAAAA2Q"]
[Tue Jul 21 07:38:42.580635 2026] [security2:error] [pid 254995:tid 255214] [client 20.226.60.151:8647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/f35.php"] [unique_id "al9MMv7v0rlcEGmVraFFWQAAA3Y"]
[Tue Jul 21 07:38:42.597995 2026] [security2:error] [pid 254995:tid 255138] [client 20.226.60.151:8672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-load.php"] [unique_id "al9MMv7v0rlcEGmVraFFWgAAAys"]
[Tue Jul 21 07:38:42.651768 2026] [security2:error] [pid 255769:tid 255918] [client 103.174.34.15:61959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MMrxMYwyVGnfuwsKhqgAAA7Y"]
[Tue Jul 21 07:38:42.651926 2026] [security2:error] [pid 255769:tid 255918] [client 103.174.34.15:61959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MMrxMYwyVGnfuwsKhqgAAA7Y"]
[Tue Jul 21 07:38:42.654272 2026] [security2:error] [pid 255769:tid 256016] [client 20.226.60.151:8706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/xyn.php"] [unique_id "al9MMrxMYwyVGnfuwsKhqwAABBY"]
[Tue Jul 21 07:38:42.680279 2026] [proxy:error] [pid 255769:tid 256001] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.680364 2026] [proxy_http:error] [pid 255769:tid 256001] [client 20.226.60.151:8714] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.681453 2026] [proxy:error] [pid 255769:tid 256001] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.681516 2026] [proxy_http:error] [pid 255769:tid 256001] [client 20.226.60.151:8714] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.753526 2026] [proxy:error] [pid 255769:tid 256012] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.753621 2026] [proxy_http:error] [pid 255769:tid 256012] [client 20.226.60.151:8582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.754937 2026] [proxy:error] [pid 255769:tid 256012] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:42.754994 2026] [proxy_http:error] [pid 255769:tid 256012] [client 20.226.60.151:8582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:42.759777 2026] [security2:error] [pid 255769:tid 255934] [client 4.204.201.85:55965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/als.php"] [unique_id "al9MMrxMYwyVGnfuwsKhrgAAA8Y"]
[Tue Jul 21 07:38:42.800651 2026] [security2:error] [pid 254995:tid 255261] [client 20.226.60.151:8653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ccc.php"] [unique_id "al9MMv7v0rlcEGmVraFFXwAAA4s"]
[Tue Jul 21 07:38:42.822140 2026] [security2:error] [pid 254995:tid 255155] [client 103.86.117.203:57762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MMv7v0rlcEGmVraFFYAAAAzw"]
[Tue Jul 21 07:38:42.822294 2026] [security2:error] [pid 254995:tid 255155] [client 103.86.117.203:57762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MMv7v0rlcEGmVraFFYAAAAzw"]
[Tue Jul 21 07:38:42.934093 2026] [security2:error] [pid 255769:tid 255942] [client 20.226.60.151:8675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/w.php"] [unique_id "al9MMrxMYwyVGnfuwsKhsQAAA84"]
[Tue Jul 21 07:38:42.971533 2026] [security2:error] [pid 254995:tid 255181] [client 128.127.105.184:60948] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MMv7v0rlcEGmVraFFZQAAA1Y"]
[Tue Jul 21 07:38:42.971649 2026] [security2:error] [pid 254995:tid 255181] [client 128.127.105.184:60948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MMv7v0rlcEGmVraFFZQAAA1Y"]
[Tue Jul 21 07:38:42.974692 2026] [security2:error] [pid 255769:tid 255911] [client 20.226.60.151:8625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9MMrxMYwyVGnfuwsKhsgAAA68"]
[Tue Jul 21 07:38:43.022124 2026] [security2:error] [pid 255769:tid 255958] [client 20.226.60.151:8611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/FWAZ.php"] [unique_id "al9MM7xMYwyVGnfuwsKhtQAAA94"]
[Tue Jul 21 07:38:43.037491 2026] [security2:error] [pid 255769:tid 255972] [client 4.204.201.85:57168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/pol.php"] [unique_id "al9MM7xMYwyVGnfuwsKhtgAAA-w"]
[Tue Jul 21 07:38:43.054475 2026] [security2:error] [pid 255769:tid 255917] [client 20.226.60.151:8743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/miru1.php"] [unique_id "al9MM7xMYwyVGnfuwsKhtwAAA7U"]
[Tue Jul 21 07:38:43.072259 2026] [security2:error] [pid 254995:tid 255259] [client 59.96.220.140:63065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MM_7v0rlcEGmVraFFZgAAA4k"]
[Tue Jul 21 07:38:43.072846 2026] [security2:error] [pid 254995:tid 255259] [client 59.96.220.140:63065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MM_7v0rlcEGmVraFFZgAAA4k"]
[Tue Jul 21 07:38:43.164412 2026] [security2:error] [pid 254995:tid 255150] [client 20.226.60.151:8613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/aa.php"] [unique_id "al9MM_7v0rlcEGmVraFFaAAAAzc"]
[Tue Jul 21 07:38:43.226668 2026] [security2:error] [pid 255769:tid 256005] [client 20.226.60.151:27535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MM7xMYwyVGnfuwsKhvQAABAs"]
[Tue Jul 21 07:38:43.241650 2026] [security2:error] [pid 254995:tid 255154] [client 20.226.60.151:8636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/122.php"] [unique_id "al9MM_7v0rlcEGmVraFFaQAAAzs"]
[Tue Jul 21 07:38:43.319195 2026] [security2:error] [pid 254995:tid 255140] [client 4.204.201.85:57089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/file5.php"] [unique_id "al9MM_7v0rlcEGmVraFFagAAAy0"]
[Tue Jul 21 07:38:43.344243 2026] [security2:error] [pid 255769:tid 256013] [client 20.226.60.151:8726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/get.php"] [unique_id "al9MM7xMYwyVGnfuwsKhvgAABBM"]
[Tue Jul 21 07:38:43.407859 2026] [security2:error] [pid 255769:tid 255941] [client 20.226.60.151:8750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/as.php"] [unique_id "al9MM7xMYwyVGnfuwsKhwAAAA80"]
[Tue Jul 21 07:38:43.418972 2026] [security2:error] [pid 255769:tid 256025] [client 20.151.10.161:45983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9MM7xMYwyVGnfuwsKhwgAABB8"]
[Tue Jul 21 07:38:43.462218 2026] [security2:error] [pid 254995:tid 255219] [client 20.226.60.151:51296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/yas.php"] [unique_id "al9MM_7v0rlcEGmVraFFbQAAA3s"]
[Tue Jul 21 07:38:43.489793 2026] [security2:error] [pid 255769:tid 255940] [client 20.226.60.151:8689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ccou.php"] [unique_id "al9MM7xMYwyVGnfuwsKhxAAAA8w"]
[Tue Jul 21 07:38:43.521054 2026] [security2:error] [pid 254995:tid 255014] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MM_7v0rlcEGmVraFFbgADjhI"]
[Tue Jul 21 07:38:43.521168 2026] [security2:error] [pid 254995:tid 255264] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MM_7v0rlcEGmVraFFbgADjhI"]
[Tue Jul 21 07:38:43.526525 2026] [security2:error] [pid 254995:tid 255149] [client 20.206.105.145:38522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file.php"] [unique_id "al9MM_7v0rlcEGmVraFFbwAAAzY"]
[Tue Jul 21 07:38:43.660247 2026] [security2:error] [pid 255769:tid 255984] [client 20.226.60.151:8586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/w3lls.php"] [unique_id "al9MM7xMYwyVGnfuwsKhyAAAA_g"]
[Tue Jul 21 07:38:43.761246 2026] [security2:error] [pid 255769:tid 255971] [client 20.226.60.151:27374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ms-edit.php"] [unique_id "al9MM7xMYwyVGnfuwsKhygAAA-s"]
[Tue Jul 21 07:38:43.804757 2026] [security2:error] [pid 255769:tid 255943] [client 4.204.201.85:55539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/file.php"] [unique_id "al9MM7xMYwyVGnfuwsKhywAAA88"]
[Tue Jul 21 07:38:43.882054 2026] [security2:error] [pid 255769:tid 255966] [client 20.226.60.151:8716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/test1.php"] [unique_id "al9MM7xMYwyVGnfuwsKhzAAAA-Y"]
[Tue Jul 21 07:38:44.004803 2026] [security2:error] [pid 255769:tid 255901] [client 20.226.60.151:8708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/database.php"] [unique_id "al9MNLxMYwyVGnfuwsKh0AAAA6U"]
[Tue Jul 21 07:38:44.029872 2026] [security2:error] [pid 255769:tid 255974] [client 82.169.226.84:62889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.226.169.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "heyidiomas.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MM7xMYwyVGnfuwsKhtAAAA-4"]
[Tue Jul 21 07:38:44.030042 2026] [security2:error] [pid 255769:tid 255974] [client 82.169.226.84:62889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "heyidiomas.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MM7xMYwyVGnfuwsKhtAAAA-4"]
[Tue Jul 21 07:38:44.089739 2026] [security2:error] [pid 255769:tid 255942] [client 4.204.201.85:55953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/cfile.php"] [unique_id "al9MNLxMYwyVGnfuwsKh1AAAA84"]
[Tue Jul 21 07:38:44.103882 2026] [core:error] [pid 255769:tid 255979] [client 66.249.66.67:60864] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:38:44.103904 2026] [core:error] [pid 255769:tid 255979] [client 66.249.66.67:60864] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:38:44.167765 2026] [security2:error] [pid 254995:tid 255192] [client 20.151.10.161:45986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wefile.php"] [unique_id "al9MNP7v0rlcEGmVraFFfAAAA2E"]
[Tue Jul 21 07:38:44.216344 2026] [security2:error] [pid 255769:tid 255917] [client 20.226.60.151:27390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9MNLxMYwyVGnfuwsKh2gAAA7U"]
[Tue Jul 21 07:38:44.247244 2026] [security2:error] [pid 255769:tid 256018] [client 20.226.60.151:8729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/file.php"] [unique_id "al9MNLxMYwyVGnfuwsKh3gAABBg"]
[Tue Jul 21 07:38:44.326237 2026] [security2:error] [pid 254995:tid 255137] [client 20.226.60.151:8663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/file.php"] [unique_id "al9MNP7v0rlcEGmVraFFgQAAAyo"]
[Tue Jul 21 07:38:44.371705 2026] [security2:error] [pid 255769:tid 255994] [client 4.204.201.85:55995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/admin.php"] [unique_id "al9MNLxMYwyVGnfuwsKh4AAABAE"]
[Tue Jul 21 07:38:44.377438 2026] [security2:error] [pid 254995:tid 255209] [client 20.226.60.151:8698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/777.php"] [unique_id "al9MNP7v0rlcEGmVraFFhAAAA3E"]
[Tue Jul 21 07:38:44.430470 2026] [security2:error] [pid 254995:tid 255180] [client 20.226.60.151:8622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ssixta.php"] [unique_id "al9MNP7v0rlcEGmVraFFhwAAA1U"]
[Tue Jul 21 07:38:44.446880 2026] [security2:error] [pid 254995:tid 255256] [client 20.226.60.151:8684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/1c.php"] [unique_id "al9MNP7v0rlcEGmVraFFiAAAA4Y"]
[Tue Jul 21 07:38:44.511355 2026] [security2:error] [pid 255769:tid 255982] [client 20.226.60.151:8740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/test2.php"] [unique_id "al9MNLxMYwyVGnfuwsKh4gAAA_Y"]
[Tue Jul 21 07:38:44.580474 2026] [security2:error] [pid 254995:tid 255193] [client 20.226.60.151:8686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/buy.php"] [unique_id "al9MNP7v0rlcEGmVraFFjgAAA2I"]
[Tue Jul 21 07:38:44.672619 2026] [security2:error] [pid 254995:tid 255188] [client 4.204.201.85:57147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/aa2.php"] [unique_id "al9MNP7v0rlcEGmVraFFkwAAA10"]
[Tue Jul 21 07:38:44.715855 2026] [security2:error] [pid 254995:tid 255271] [client 20.226.60.151:9043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ssend.php"] [unique_id "al9MNP7v0rlcEGmVraFFmAAAA5U"]
[Tue Jul 21 07:38:44.768334 2026] [security2:error] [pid 254995:tid 255156] [client 20.226.60.151:8760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/item.php"] [unique_id "al9MNP7v0rlcEGmVraFFmwAAAz0"]
[Tue Jul 21 07:38:44.795161 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:8759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ss.php"] [unique_id "al9MNP7v0rlcEGmVraFFnQAAA5c"]
[Tue Jul 21 07:38:44.837846 2026] [security2:error] [pid 254995:tid 255229] [client 20.226.60.151:8619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/hypo.php"] [unique_id "al9MNP7v0rlcEGmVraFFngAAA4I"]
[Tue Jul 21 07:38:44.897469 2026] [security2:error] [pid 255769:tid 255902] [client 20.226.60.151:9052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/users.php"] [unique_id "al9MNLxMYwyVGnfuwsKh4wAAA6Y"]
[Tue Jul 21 07:38:44.915423 2026] [security2:error] [pid 254995:tid 255265] [client 20.226.60.151:27579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9MNP7v0rlcEGmVraFFvwAAA48"]
[Tue Jul 21 07:38:44.923470 2026] [autoindex:error] [pid 255769:tid 255961] [client 195.154.254.70:60568] AH01276: Cannot serve directory /home2/onfiel33/kotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:44.948273 2026] [security2:error] [pid 255769:tid 256001] [client 20.226.60.151:8727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/177.php"] [unique_id "al9MNLxMYwyVGnfuwsKh5wAABAc"]
[Tue Jul 21 07:38:44.970805 2026] [security2:error] [pid 254995:tid 255181] [client 4.204.201.85:61265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ccou.php"] [unique_id "al9MNP7v0rlcEGmVraFFwQAAA1Y"]
[Tue Jul 21 07:38:44.985882 2026] [security2:error] [pid 255769:tid 255928] [client 20.226.60.151:8717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/config.php"] [unique_id "al9MNLxMYwyVGnfuwsKh6AAAA8A"]
[Tue Jul 21 07:38:45.026344 2026] [security2:error] [pid 255769:tid 255908] [client 20.226.60.151:8635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/gettest.php"] [unique_id "al9MNbxMYwyVGnfuwsKh6QAAA6w"]
[Tue Jul 21 07:38:45.116515 2026] [security2:error] [pid 254995:tid 255277] [client 20.151.10.161:46017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9MNf7v0rlcEGmVraFFwgAAA5s"]
[Tue Jul 21 07:38:45.141080 2026] [security2:error] [pid 255769:tid 255918] [client 193.36.225.57:22003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MNbxMYwyVGnfuwsKh6gAAA7Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:45.162873 2026] [security2:error] [pid 255769:tid 255974] [client 20.226.60.151:8693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/min.php"] [unique_id "al9MNbxMYwyVGnfuwsKh6wAAA-4"]
[Tue Jul 21 07:38:45.196458 2026] [security2:error] [pid 255769:tid 255899] [client 20.226.60.151:8691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/dvjul.php"] [unique_id "al9MNbxMYwyVGnfuwsKh7AAAA6M"]
[Tue Jul 21 07:38:45.249352 2026] [security2:error] [pid 254995:tid 255199] [client 20.226.60.151:8618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/biufile.php"] [unique_id "al9MNf7v0rlcEGmVraFFxQAAA2g"]
[Tue Jul 21 07:38:45.267857 2026] [security2:error] [pid 255769:tid 255911] [client 4.204.201.85:55995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/dr.php"] [unique_id "al9MNbxMYwyVGnfuwsKh7gAAA68"]
[Tue Jul 21 07:38:45.280480 2026] [security2:error] [pid 255769:tid 255958] [client 20.226.60.151:8682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/av.php"] [unique_id "al9MNbxMYwyVGnfuwsKh7wAAA94"]
[Tue Jul 21 07:38:45.345476 2026] [security2:error] [pid 255769:tid 255870] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh8AAD9WQ"]
[Tue Jul 21 07:38:45.345645 2026] [security2:error] [pid 255769:tid 255981] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh8AAD9WQ"]
[Tue Jul 21 07:38:45.365212 2026] [security2:error] [pid 254995:tid 255140] [client 20.226.60.151:8710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/coffexium.php"] [unique_id "al9MNf7v0rlcEGmVraFFywAAAy0"]
[Tue Jul 21 07:38:45.498374 2026] [security2:error] [pid 255769:tid 256018] [client 20.206.105.145:38094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/cfile.php"] [unique_id "al9MNbxMYwyVGnfuwsKh8wAABBg"]
[Tue Jul 21 07:38:45.505186 2026] [security2:error] [pid 255769:tid 256005] [client 20.226.60.151:8735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/core.php"] [unique_id "al9MNbxMYwyVGnfuwsKh9AAABAs"]
[Tue Jul 21 07:38:45.515721 2026] [autoindex:error] [pid 255769:tid 255946] [client 195.154.254.70:35984] AH01276: Cannot serve directory /home2/onfiel33/kotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:45.535982 2026] [security2:error] [pid 255769:tid 255932] [client 139.167.225.182:51718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh9gAAA8Q"]
[Tue Jul 21 07:38:45.536116 2026] [security2:error] [pid 255769:tid 255932] [client 139.167.225.182:51718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh9gAAA8Q"]
[Tue Jul 21 07:38:45.576586 2026] [security2:error] [pid 255769:tid 255997] [client 194.99.104.35:46542] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh-AAABAM"]
[Tue Jul 21 07:38:45.576681 2026] [security2:error] [pid 255769:tid 255997] [client 194.99.104.35:46542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh-AAABAM"]
[Tue Jul 21 07:38:45.596570 2026] [security2:error] [pid 255769:tid 255871] [remote 72.167.132.114:48850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9MNbxMYwyVGnfuwsKh-QADzmU"]
[Tue Jul 21 07:38:45.645110 2026] [security2:error] [pid 255769:tid 255941] [client 4.204.201.85:57116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/xamp.php"] [unique_id "al9MNbxMYwyVGnfuwsKh-gAAA80"]
[Tue Jul 21 07:38:45.657840 2026] [security2:error] [pid 255769:tid 255966] [client 117.217.38.194:55572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh-wAAA-Y"]
[Tue Jul 21 07:38:45.657964 2026] [security2:error] [pid 255769:tid 255966] [client 117.217.38.194:55572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MNbxMYwyVGnfuwsKh-wAAA-Y"]
[Tue Jul 21 07:38:45.660493 2026] [security2:error] [pid 255769:tid 255983] [client 20.226.60.151:9082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/als.php"] [unique_id "al9MNbxMYwyVGnfuwsKh_AAAA_c"]
[Tue Jul 21 07:38:45.776312 2026] [security2:error] [pid 255769:tid 255938] [client 20.226.60.151:8601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/simple.php"] [unique_id "al9MNbxMYwyVGnfuwsKh_wAAA8o"]
[Tue Jul 21 07:38:45.853061 2026] [security2:error] [pid 255769:tid 255944] [client 20.226.60.151:56225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/mac.php"] [unique_id "al9MNbxMYwyVGnfuwsKiAAAAA9A"]
[Tue Jul 21 07:38:45.859589 2026] [security2:error] [pid 255769:tid 255907] [client 20.151.10.161:45997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/2P.php"] [unique_id "al9MNbxMYwyVGnfuwsKiAQAAA6s"]
[Tue Jul 21 07:38:45.933901 2026] [security2:error] [pid 255769:tid 256022] [client 4.204.201.85:57115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/bless.php"] [unique_id "al9MNbxMYwyVGnfuwsKiAwAABBw"]
[Tue Jul 21 07:38:45.978046 2026] [security2:error] [pid 255769:tid 255930] [client 20.226.60.151:8673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/init.php"] [unique_id "al9MNbxMYwyVGnfuwsKiBQAAA8I"]
[Tue Jul 21 07:38:46.036399 2026] [security2:error] [pid 255769:tid 255908] [client 20.226.60.151:51389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file61.php"] [unique_id "al9MNrxMYwyVGnfuwsKiBwAAA6w"]
[Tue Jul 21 07:38:46.118208 2026] [security2:error] [pid 255769:tid 255831] [remote 212.47.76.178:50774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.76.47.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "domuscondominios.com.br"] [uri "/wp-login.php"] [unique_id "al9MNrxMYwyVGnfuwsKiCQAD-z0"]
[Tue Jul 21 07:38:46.246607 2026] [security2:error] [pid 254995:tid 255268] [client 74.7.175.145:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.polianoduarteramos1782911169000.lojaracompressores.com.br"] [uri "/index.php"] [unique_id "al9MNP7v0rlcEGmVraFFjAAAA5I"]
[Tue Jul 21 07:38:46.247421 2026] [security2:error] [pid 254995:tid 255166] [client 74.7.175.145:55402] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.polianoduarteramos1782911169000.lojaracompressores.com.br"] [uri "/robots.txt"] [unique_id "al9MNP7v0rlcEGmVraFFiQADRys"]
[Tue Jul 21 07:38:46.266298 2026] [security2:error] [pid 254995:tid 255203] [client 20.226.60.151:8666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/fpwch.php"] [unique_id "al9MNv7v0rlcEGmVraFF2QAAA2w"]
[Tue Jul 21 07:38:46.274448 2026] [security2:error] [pid 254995:tid 255278] [client 20.226.60.151:27555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/abcd.php"] [unique_id "al9MNv7v0rlcEGmVraFF2wAAA5w"]
[Tue Jul 21 07:38:46.306099 2026] [security2:error] [pid 255769:tid 256000] [client 4.204.201.85:57192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/file25.php"] [unique_id "al9MNrxMYwyVGnfuwsKiEgAABAY"]
[Tue Jul 21 07:38:46.390858 2026] [security2:error] [pid 255769:tid 256015] [client 20.226.60.151:55308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/water.php"] [unique_id "al9MNrxMYwyVGnfuwsKiEwAABBU"]
[Tue Jul 21 07:38:46.536169 2026] [security2:error] [pid 255769:tid 256013] [client 20.226.60.151:8614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/domvf.php"] [unique_id "al9MNrxMYwyVGnfuwsKiFQAABBM"]
[Tue Jul 21 07:38:46.563979 2026] [security2:error] [pid 255769:tid 255994] [client 20.151.10.161:46035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/.well-known/about.php"] [unique_id "al9MNrxMYwyVGnfuwsKiFgAABAE"]
[Tue Jul 21 07:38:46.615033 2026] [security2:error] [pid 255769:tid 255941] [client 4.204.201.85:57197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/file6.php"] [unique_id "al9MNrxMYwyVGnfuwsKiGQAAA80"]
[Tue Jul 21 07:38:46.757656 2026] [security2:error] [pid 255769:tid 256026] [client 20.206.105.145:37891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/class-wp.php"] [unique_id "al9MNrxMYwyVGnfuwsKiHgAABCA"]
[Tue Jul 21 07:38:46.789171 2026] [security2:error] [pid 254995:tid 255138] [client 20.226.60.151:8679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp.php"] [unique_id "al9MNv7v0rlcEGmVraFF5QAAAys"]
[Tue Jul 21 07:38:46.848325 2026] [security2:error] [pid 254995:tid 255142] [client 20.220.225.223:31198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/term.php"] [unique_id "al9MNv7v0rlcEGmVraFF6AAAAy8"]
[Tue Jul 21 07:38:46.925730 2026] [security2:error] [pid 254995:tid 255212] [client 4.204.201.85:55497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/a2.php"] [unique_id "al9MNv7v0rlcEGmVraFF6QAAA3Q"]
[Tue Jul 21 07:38:46.975277 2026] [security2:error] [pid 254995:tid 255215] [client 173.24.185.52:59932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MNv7v0rlcEGmVraFF6gAAA3c"]
[Tue Jul 21 07:38:46.975424 2026] [security2:error] [pid 254995:tid 255215] [client 173.24.185.52:59932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MNv7v0rlcEGmVraFF6gAAA3c"]
[Tue Jul 21 07:38:47.052370 2026] [security2:error] [pid 254995:tid 255174] [client 74.7.244.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "polianoduarteramos1782911169000.0721679.meusitehostgator.com.br"] [uri "/index.php"] [unique_id "al9MNv7v0rlcEGmVraFF4AADTyg"]
[Tue Jul 21 07:38:47.060348 2026] [security2:error] [pid 255769:tid 255914] [client 106.215.181.8:22574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MN7xMYwyVGnfuwsKiIgAAA7I"]
[Tue Jul 21 07:38:47.060540 2026] [security2:error] [pid 255769:tid 255914] [client 106.215.181.8:22574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MN7xMYwyVGnfuwsKiIgAAA7I"]
[Tue Jul 21 07:38:47.076532 2026] [security2:error] [pid 254995:tid 255155] [client 20.226.60.151:51328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/nano.php"] [unique_id "al9MN_7v0rlcEGmVraFF7gAAAzw"]
[Tue Jul 21 07:38:47.192320 2026] [security2:error] [pid 254995:tid 255128] [client 20.226.60.151:9058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/class.php"] [unique_id "al9MN_7v0rlcEGmVraFF8wAAAyE"]
[Tue Jul 21 07:38:47.208129 2026] [security2:error] [pid 254995:tid 255187] [client 4.204.201.85:57107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/file15.php"] [unique_id "al9MN_7v0rlcEGmVraFF9AAAA1w"]
[Tue Jul 21 07:38:47.452218 2026] [security2:error] [pid 255769:tid 255901] [client 20.226.60.151:27337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file15.php"] [unique_id "al9MN7xMYwyVGnfuwsKiKgAAA6U"]
[Tue Jul 21 07:38:47.504836 2026] [security2:error] [pid 255769:tid 255974] [client 4.204.201.85:57176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/f35.php"] [unique_id "al9MN7xMYwyVGnfuwsKiKwAAA-4"]
[Tue Jul 21 07:38:47.590420 2026] [security2:error] [pid 254995:tid 255254] [client 20.226.60.151:8709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/echkm.php"] [unique_id "al9MN_7v0rlcEGmVraFGBQAAA4Q"]
[Tue Jul 21 07:38:47.782386 2026] [security2:error] [pid 255769:tid 255911] [client 4.204.201.85:57154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-load.php"] [unique_id "al9MN7xMYwyVGnfuwsKiLAAAA68"]
[Tue Jul 21 07:38:47.834702 2026] [security2:error] [pid 255769:tid 255987] [client 20.226.60.151:56226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/mg.php"] [unique_id "al9MN7xMYwyVGnfuwsKiLQAAA_s"]
[Tue Jul 21 07:38:48.001022 2026] [security2:error] [pid 255769:tid 255950] [client 20.151.10.161:46043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9MOLxMYwyVGnfuwsKiMAAAA9Y"]
[Tue Jul 21 07:38:48.032483 2026] [security2:error] [pid 255769:tid 256003] [client 20.206.105.145:37914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/admin.php"] [unique_id "al9MOLxMYwyVGnfuwsKiMgAABAk"]
[Tue Jul 21 07:38:48.037312 2026] [security2:error] [pid 254995:tid 255143] [client 216.24.219.119:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "naldoinvest.com.br"] [uri "/wp-login.php"] [unique_id "al9MNf7v0rlcEGmVraFFzAADMCU"]
[Tue Jul 21 07:38:48.079584 2026] [security2:error] [pid 255769:tid 255986] [client 20.226.60.151:9037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/lib.php"] [unique_id "al9MOLxMYwyVGnfuwsKiMwAAA_o"]
[Tue Jul 21 07:38:48.093248 2026] [security2:error] [pid 255769:tid 255857] [remote 41.76.214.143:37238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lp.agenciawats.com.br"] [uri "/wp-login.php"] [unique_id "al9MOLxMYwyVGnfuwsKiNAADtlc"]
[Tue Jul 21 07:38:48.108378 2026] [security2:error] [pid 255769:tid 255937] [client 4.204.201.85:55535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/xwpg.php"] [unique_id "al9MOLxMYwyVGnfuwsKiOAAAA8k"]
[Tue Jul 21 07:38:48.176660 2026] [security2:error] [pid 254995:tid 255204] [client 122.186.204.214:61221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MOP7v0rlcEGmVraFGDAAAA20"]
[Tue Jul 21 07:38:48.176801 2026] [security2:error] [pid 254995:tid 255204] [client 122.186.204.214:61221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MOP7v0rlcEGmVraFGDAAAA20"]
[Tue Jul 21 07:38:48.337314 2026] [security2:error] [pid 255769:tid 255807] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiPgAD_iU"]
[Tue Jul 21 07:38:48.337486 2026] [security2:error] [pid 255769:tid 255990] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiPgAD_iU"]
[Tue Jul 21 07:38:48.338990 2026] [security2:error] [pid 255769:tid 255994] [client 20.226.60.151:8725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/login.php"] [unique_id "al9MOLxMYwyVGnfuwsKiPwAABAE"]
[Tue Jul 21 07:38:48.384173 2026] [security2:error] [pid 255769:tid 255932] [client 20.226.60.151:61213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/moon.php"] [unique_id "al9MOLxMYwyVGnfuwsKiQQAAA8Q"]
[Tue Jul 21 07:38:48.399980 2026] [security2:error] [pid 255769:tid 255979] [client 152.59.154.239:61176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiRQAAA_M"]
[Tue Jul 21 07:38:48.400131 2026] [security2:error] [pid 255769:tid 255979] [client 152.59.154.239:61176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiRQAAA_M"]
[Tue Jul 21 07:38:48.403154 2026] [autoindex:error] [pid 255769:tid 255941] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:48.443052 2026] [security2:error] [pid 254995:tid 255206] [client 20.197.192.193:6866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/ez.php"] [unique_id "al9MOP7v0rlcEGmVraFGEAAAA28"]
[Tue Jul 21 07:38:48.449965 2026] [security2:error] [pid 255769:tid 255899] [client 117.251.86.144:55810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiRgAAA6M"]
[Tue Jul 21 07:38:48.450079 2026] [security2:error] [pid 255769:tid 255899] [client 117.251.86.144:55810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiRgAAA6M"]
[Tue Jul 21 07:38:48.578868 2026] [security2:error] [pid 255769:tid 255973] [client 20.226.60.151:8597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/a2.php"] [unique_id "al9MOLxMYwyVGnfuwsKiSAAAA-0"]
[Tue Jul 21 07:38:48.761789 2026] [autoindex:error] [pid 255769:tid 255907] [client 4.204.201.85:61297] AH01276: Cannot serve directory /home1/ofic8899/qcharge.tryhealth.shop/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:38:48.802109 2026] [security2:error] [pid 255769:tid 255830] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiTwAEGzw"]
[Tue Jul 21 07:38:48.802260 2026] [security2:error] [pid 255769:tid 256021] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOLxMYwyVGnfuwsKiTwAEGzw"]
[Tue Jul 21 07:38:48.899983 2026] [security2:error] [pid 255769:tid 255920] [client 4.204.201.85:61297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/xstelth.php"] [unique_id "al9MOLxMYwyVGnfuwsKiUQAAA7g"]
[Tue Jul 21 07:38:49.060088 2026] [security2:error] [pid 255769:tid 255971] [client 20.226.60.151:8699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/d61.php"] [unique_id "al9MObxMYwyVGnfuwsKiVAAAA-s"]
[Tue Jul 21 07:38:49.193793 2026] [security2:error] [pid 255769:tid 255900] [client 4.204.201.85:57172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9MObxMYwyVGnfuwsKiVwAAA6Q"]
[Tue Jul 21 07:38:49.358466 2026] [security2:error] [pid 255769:tid 255838] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MObxMYwyVGnfuwsKiWQADpUQ"]
[Tue Jul 21 07:38:49.358629 2026] [security2:error] [pid 255769:tid 255901] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MObxMYwyVGnfuwsKiWQADpUQ"]
[Tue Jul 21 07:38:49.406215 2026] [security2:error] [pid 254995:tid 255168] [client 20.197.192.193:6850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/fz.php"] [unique_id "al9MOf7v0rlcEGmVraFGGwAAA0k"]
[Tue Jul 21 07:38:49.411962 2026] [security2:error] [pid 254995:tid 255135] [client 20.226.60.151:9066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/info.php"] [unique_id "al9MOf7v0rlcEGmVraFGHAAAAyg"]
[Tue Jul 21 07:38:49.523753 2026] [security2:error] [pid 254995:tid 255258] [client 4.204.201.85:57130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/aaa.php"] [unique_id "al9MOf7v0rlcEGmVraFGIAAAA4g"]
[Tue Jul 21 07:38:49.570147 2026] [security2:error] [pid 254995:tid 255208] [client 20.226.60.151:27562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/jp.php"] [unique_id "al9MOf7v0rlcEGmVraFGIgAAA3A"]
[Tue Jul 21 07:38:49.715536 2026] [security2:error] [pid 254995:tid 255210] [client 193.36.225.69:51325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MOf7v0rlcEGmVraFGKQAAA3I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:49.843618 2026] [security2:error] [pid 255769:tid 255968] [client 4.204.201.85:57128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/gecko.php"] [unique_id "al9MObxMYwyVGnfuwsKiXAAAA-g"]
[Tue Jul 21 07:38:49.907891 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:8633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/11.php"] [unique_id "al9MOf7v0rlcEGmVraFGKgAAA5k"]
[Tue Jul 21 07:38:50.258047 2026] [security2:error] [pid 255769:tid 255934] [client 4.204.201.85:57186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/sh3ll.php"] [unique_id "al9MOrxMYwyVGnfuwsKiXwAAA8Y"]
[Tue Jul 21 07:38:50.283298 2026] [security2:error] [pid 255769:tid 256005] [client 20.226.60.151:8589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/v2.php"] [unique_id "al9MOrxMYwyVGnfuwsKiYAAABAs"]
[Tue Jul 21 07:38:50.320102 2026] [security2:error] [pid 255769:tid 255858] [remote 45.90.123.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "printcom.com.br"] [uri "/wp-login.php"] [unique_id "al9MOrxMYwyVGnfuwsKiYQADqlg"]
[Tue Jul 21 07:38:50.497732 2026] [security2:error] [pid 255769:tid 255918] [client 154.192.233.199:59484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZAAAA7Y"]
[Tue Jul 21 07:38:50.497845 2026] [security2:error] [pid 255769:tid 255918] [client 154.192.233.199:59484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZAAAA7Y"]
[Tue Jul 21 07:38:50.499096 2026] [security2:error] [pid 255769:tid 255986] [client 175.45.70.82:50161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZQAAA_o"]
[Tue Jul 21 07:38:50.499205 2026] [security2:error] [pid 255769:tid 255986] [client 175.45.70.82:50161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZQAAA_o"]
[Tue Jul 21 07:38:50.552682 2026] [security2:error] [pid 254995:tid 255222] [client 4.204.201.85:61303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/pbck.php"] [unique_id "al9MOv7v0rlcEGmVraFGOAAAA34"]
[Tue Jul 21 07:38:50.710404 2026] [security2:error] [pid 255769:tid 255937] [client 122.164.127.47:58508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZgAAA8k"]
[Tue Jul 21 07:38:50.710564 2026] [security2:error] [pid 255769:tid 255937] [client 122.164.127.47:58508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZgAAA8k"]
[Tue Jul 21 07:38:50.756893 2026] [security2:error] [pid 254995:tid 255202] [client 20.226.60.151:8728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/panel.php"] [unique_id "al9MOv7v0rlcEGmVraFGPgAAA2s"]
[Tue Jul 21 07:38:50.843718 2026] [security2:error] [pid 254995:tid 255221] [client 4.204.201.85:57163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/xiugai.php"] [unique_id "al9MOv7v0rlcEGmVraFGPwAAA30"]
[Tue Jul 21 07:38:50.855804 2026] [security2:error] [pid 255769:tid 256019] [client 122.162.144.145:20853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZwAABBk"]
[Tue Jul 21 07:38:50.855953 2026] [security2:error] [pid 255769:tid 256019] [client 122.162.144.145:20853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MOrxMYwyVGnfuwsKiZwAABBk"]
[Tue Jul 21 07:38:50.999360 2026] [security2:error] [pid 255769:tid 255914] [client 20.220.225.223:38678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/ah25.php"] [unique_id "al9MOrxMYwyVGnfuwsKibAAAA7I"]
[Tue Jul 21 07:38:51.114787 2026] [security2:error] [pid 255769:tid 255943] [client 20.226.60.151:8749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/dex.php"] [unique_id "al9MO7xMYwyVGnfuwsKibwAAA88"]
[Tue Jul 21 07:38:51.140227 2026] [security2:error] [pid 255769:tid 256021] [client 4.204.201.85:60645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/e.php"] [unique_id "al9MO7xMYwyVGnfuwsKicAAABBs"]
[Tue Jul 21 07:38:51.244626 2026] [security2:error] [pid 254995:tid 255169] [client 103.106.20.201:56240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MO_7v0rlcEGmVraFGRQAAA0o"]
[Tue Jul 21 07:38:51.244750 2026] [security2:error] [pid 254995:tid 255169] [client 103.106.20.201:56240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MO_7v0rlcEGmVraFGRQAAA0o"]
[Tue Jul 21 07:38:51.440029 2026] [security2:error] [pid 255769:tid 255911] [client 20.206.105.145:38102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/aa2.php"] [unique_id "al9MO7xMYwyVGnfuwsKieQAAA68"]
[Tue Jul 21 07:38:51.468022 2026] [security2:error] [pid 255769:tid 255972] [client 4.204.201.85:61244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/for.php"] [unique_id "al9MO7xMYwyVGnfuwsKiewAAA-w"]
[Tue Jul 21 07:38:51.499892 2026] [security2:error] [pid 254995:tid 255123] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MO_7v0rlcEGmVraFGSwADVH8"]
[Tue Jul 21 07:38:51.500045 2026] [security2:error] [pid 254995:tid 255179] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MO_7v0rlcEGmVraFGSwADVH8"]
[Tue Jul 21 07:38:51.560169 2026] [security2:error] [pid 255769:tid 255867] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MO7xMYwyVGnfuwsKifwAEFWE"]
[Tue Jul 21 07:38:51.560310 2026] [security2:error] [pid 255769:tid 256015] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MO7xMYwyVGnfuwsKifwAEFWE"]
[Tue Jul 21 07:38:51.571695 2026] [security2:error] [pid 255769:tid 255917] [client 20.226.60.151:27604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/f35.php"] [unique_id "al9MO7xMYwyVGnfuwsKigAAAA7U"]
[Tue Jul 21 07:38:51.670118 2026] [security2:error] [pid 255769:tid 255968] [client 20.226.60.151:9046] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/1.php"] [unique_id "al9MO7xMYwyVGnfuwsKiggAAA-g"]
[Tue Jul 21 07:38:51.670194 2026] [security2:error] [pid 255769:tid 255968] [client 20.226.60.151:9046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/1.php"] [unique_id "al9MO7xMYwyVGnfuwsKiggAAA-g"]
[Tue Jul 21 07:38:51.802968 2026] [security2:error] [pid 254995:tid 255216] [client 4.204.201.85:60617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ssh3ll.php"] [unique_id "al9MO_7v0rlcEGmVraFGTQAAA3g"]
[Tue Jul 21 07:38:51.829695 2026] [security2:error] [pid 255769:tid 255804] [remote 65.111.1.237:26997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.1.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9MO7xMYwyVGnfuwsKigQAD2iI"]
[Tue Jul 21 07:38:52.024842 2026] [security2:error] [pid 255769:tid 255999] [client 20.151.10.161:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/bob.php"] [unique_id "al9MPLxMYwyVGnfuwsKihQAABAU"]
[Tue Jul 21 07:38:52.076390 2026] [security2:error] [pid 255769:tid 256005] [client 20.226.60.151:8685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/ms.php"] [unique_id "al9MPLxMYwyVGnfuwsKihwAABAs"]
[Tue Jul 21 07:38:52.092201 2026] [security2:error] [pid 255769:tid 255906] [client 4.204.201.85:55962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/adminner.php"] [unique_id "al9MPLxMYwyVGnfuwsKiiAAAA6o"]
[Tue Jul 21 07:38:52.213527 2026] [security2:error] [pid 254995:tid 255268] [client 193.36.225.105:57725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MPP7v0rlcEGmVraFGVAAAA5I"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:52.238986 2026] [security2:error] [pid 255769:tid 255947] [client 184.75.223.211:48820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MPLxMYwyVGnfuwsKiiQAAA9M"]
[Tue Jul 21 07:38:52.239105 2026] [security2:error] [pid 255769:tid 255947] [client 184.75.223.211:48820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MPLxMYwyVGnfuwsKiiQAAA9M"]
[Tue Jul 21 07:38:52.380443 2026] [security2:error] [pid 255769:tid 255997] [client 20.226.60.151:51325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-info.php"] [unique_id "al9MPLxMYwyVGnfuwsKiiwAABAM"]
[Tue Jul 21 07:38:52.409002 2026] [security2:error] [pid 255769:tid 255994] [client 4.204.201.85:57132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/82.php"] [unique_id "al9MPLxMYwyVGnfuwsKijAAABAE"]
[Tue Jul 21 07:38:52.453822 2026] [security2:error] [pid 254995:tid 255193] [client 20.226.60.151:56283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-post-data.php"] [unique_id "al9MPP7v0rlcEGmVraFGWwAAA2I"]
[Tue Jul 21 07:38:52.571643 2026] [proxy:error] [pid 254995:tid 255195] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:52.571712 2026] [proxy_http:error] [pid 254995:tid 255195] [client 20.226.60.151:8617] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:52.572186 2026] [proxy:error] [pid 254995:tid 255195] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:38:52.572210 2026] [proxy_http:error] [pid 254995:tid 255195] [client 20.226.60.151:8617] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:38:52.703938 2026] [security2:error] [pid 255769:tid 256004] [client 4.204.201.85:55504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/kir.php"] [unique_id "al9MPLxMYwyVGnfuwsKikwAABAo"]
[Tue Jul 21 07:38:52.827328 2026] [access_compat:error] [pid 255769:tid 255907] [client 162.241.63.68:56988] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:38:52.848469 2026] [security2:error] [pid 255769:tid 255956] [client 20.226.60.151:27388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-load.php"] [unique_id "al9MPLxMYwyVGnfuwsKimAAAA9w"]
[Tue Jul 21 07:38:52.985122 2026] [security2:error] [pid 255769:tid 255969] [client 4.204.201.85:55963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/up4.php"] [unique_id "al9MPLxMYwyVGnfuwsKinAAAA-k"]
[Tue Jul 21 07:38:53.045179 2026] [security2:error] [pid 255769:tid 255901] [client 20.206.105.145:38095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/ccou.php"] [unique_id "al9MPbxMYwyVGnfuwsKioAAAA6U"]
[Tue Jul 21 07:38:53.248204 2026] [security2:error] [pid 254995:tid 255152] [client 20.197.192.193:6374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/la.php"] [unique_id "al9MPf7v0rlcEGmVraFGdgAAAzk"]
[Tue Jul 21 07:38:53.290732 2026] [security2:error] [pid 255769:tid 255990] [client 4.204.201.85:57134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/xhar.php"] [unique_id "al9MPbxMYwyVGnfuwsKiqAAAA_4"]
[Tue Jul 21 07:38:53.298465 2026] [security2:error] [pid 255769:tid 255944] [client 103.86.117.203:58286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MPbxMYwyVGnfuwsKiqQAAA9A"]
[Tue Jul 21 07:38:53.298581 2026] [security2:error] [pid 255769:tid 255944] [client 103.86.117.203:58286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MPbxMYwyVGnfuwsKiqQAAA9A"]
[Tue Jul 21 07:38:53.348685 2026] [security2:error] [pid 255769:tid 255984] [client 103.174.34.15:62456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MPbxMYwyVGnfuwsKiqgAAA_g"]
[Tue Jul 21 07:38:53.348823 2026] [security2:error] [pid 255769:tid 255984] [client 103.174.34.15:62456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MPbxMYwyVGnfuwsKiqgAAA_g"]
[Tue Jul 21 07:38:53.401747 2026] [security2:error] [pid 254995:tid 255179] [client 20.226.60.151:8712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/memberfuns.php"] [unique_id "al9MPf7v0rlcEGmVraFGewAAA1Q"]
[Tue Jul 21 07:38:53.455326 2026] [security2:error] [pid 254995:tid 255166] [client 20.226.60.151:8766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/0.php"] [unique_id "al9MPf7v0rlcEGmVraFGfQAAA0c"]
[Tue Jul 21 07:38:53.499044 2026] [security2:error] [pid 254995:tid 255206] [client 20.226.60.151:9054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/BDKR28.php"] [unique_id "al9MPf7v0rlcEGmVraFGfwAAA28"]
[Tue Jul 21 07:38:53.541901 2026] [security2:error] [pid 254995:tid 255161] [client 20.226.60.151:8693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/green1.php"] [unique_id "al9MPf7v0rlcEGmVraFGgAAAA0I"]
[Tue Jul 21 07:38:53.665503 2026] [security2:error] [pid 254995:tid 255209] [client 20.220.225.223:31209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/8.php"] [unique_id "al9MPf7v0rlcEGmVraFGhAAAA3E"]
[Tue Jul 21 07:38:53.784543 2026] [security2:error] [pid 254995:tid 255128] [client 59.96.220.140:63560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MPf7v0rlcEGmVraFGiAAAAyE"]
[Tue Jul 21 07:38:53.787252 2026] [security2:error] [pid 254995:tid 255128] [client 59.96.220.140:63560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MPf7v0rlcEGmVraFGiAAAAyE"]
[Tue Jul 21 07:38:53.804572 2026] [security2:error] [pid 254995:tid 255137] [client 20.226.60.151:8878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/nc4.php"] [unique_id "al9MPf7v0rlcEGmVraFGiQAAAyo"]
[Tue Jul 21 07:38:53.865558 2026] [security2:error] [pid 255769:tid 255955] [client 4.204.201.85:57209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/file1221.php"] [unique_id "al9MPbxMYwyVGnfuwsKitQAAA9s"]
[Tue Jul 21 07:38:53.907205 2026] [security2:error] [pid 255769:tid 255910] [client 20.206.105.145:38139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/dr.php"] [unique_id "al9MPbxMYwyVGnfuwsKiuAAAA64"]
[Tue Jul 21 07:38:54.119364 2026] [security2:error] [pid 254995:tid 255168] [client 20.226.60.151:8593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/a1.php"] [unique_id "al9MPv7v0rlcEGmVraFGjAAAA0k"]
[Tue Jul 21 07:38:54.251051 2026] [security2:error] [pid 255769:tid 255968] [client 37.140.223.157:30327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MPrxMYwyVGnfuwsKivwAAA-g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:38:54.263604 2026] [security2:error] [pid 255769:tid 255846] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MPrxMYwyVGnfuwsKiwAAD_0w"]
[Tue Jul 21 07:38:54.263780 2026] [security2:error] [pid 255769:tid 255992] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MPrxMYwyVGnfuwsKiwAAD_0w"]
[Tue Jul 21 07:38:54.267292 2026] [security2:error] [pid 254995:tid 255265] [client 20.197.192.193:6889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/nhvoanpl.php"] [unique_id "al9MPv7v0rlcEGmVraFGkQAAA48"]
[Tue Jul 21 07:38:54.311880 2026] [security2:error] [pid 255769:tid 255962] [client 20.226.60.151:8744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/eee.php"] [unique_id "al9MPrxMYwyVGnfuwsKiwwAAA-I"]
[Tue Jul 21 07:38:54.322233 2026] [security2:error] [pid 255769:tid 255999] [client 74.7.228.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.healthsmart.shop.oficialwebsite.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9MPrxMYwyVGnfuwsKixAAABAU"]
[Tue Jul 21 07:38:54.324046 2026] [security2:error] [pid 255769:tid 255904] [client 74.7.228.10:38762] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.healthsmart.shop.oficialwebsite.com.br"] [uri "/robots.txt"] [unique_id "al9MPrxMYwyVGnfuwsKiwQADqAU"]
[Tue Jul 21 07:38:54.362000 2026] [security2:error] [pid 255769:tid 256018] [client 4.204.201.85:57183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/inx.php"] [unique_id "al9MPrxMYwyVGnfuwsKixQAABBg"]
[Tue Jul 21 07:38:54.521467 2026] [security2:error] [pid 255769:tid 255984] [client 20.206.105.145:38087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/xamp.php"] [unique_id "al9MPrxMYwyVGnfuwsKiyQAAA_g"]
[Tue Jul 21 07:38:54.597363 2026] [security2:error] [pid 254995:tid 255160] [client 20.226.60.151:8630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/wp-aothait.php"] [unique_id "al9MPv7v0rlcEGmVraFGmQAAA0E"]
[Tue Jul 21 07:38:54.613385 2026] [security2:error] [pid 255769:tid 256013] [client 193.36.225.65:23235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MPrxMYwyVGnfuwsKiyAAABBM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:54.661378 2026] [security2:error] [pid 254995:tid 255026] [remote 192.241.143.148:37234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "robertaramos.com.br"] [uri "/wp-login.php"] [unique_id "al9MPv7v0rlcEGmVraFGnAADdx4"]
[Tue Jul 21 07:38:54.751182 2026] [security2:error] [pid 255769:tid 256019] [client 20.226.60.151:60998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/2000.php"] [unique_id "al9MPrxMYwyVGnfuwsKizwAABBk"]
[Tue Jul 21 07:38:54.751322 2026] [security2:error] [pid 255769:tid 255964] [client 20.197.192.193:6362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/inso.php"] [unique_id "al9MPrxMYwyVGnfuwsKi0AAAA-Q"]
[Tue Jul 21 07:38:54.755630 2026] [security2:error] [pid 254995:tid 255229] [client 4.204.201.85:55515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/qqqa.php"] [unique_id "al9MPv7v0rlcEGmVraFGnwAAA4I"]
[Tue Jul 21 07:38:54.846925 2026] [security2:error] [pid 254995:tid 255132] [client 20.151.10.161:46076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/crgio.php"] [unique_id "al9MPv7v0rlcEGmVraFGogAAAyU"]
[Tue Jul 21 07:38:54.862337 2026] [security2:error] [pid 255769:tid 255942] [client 20.226.60.151:9081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/config.json.php"] [unique_id "al9MPrxMYwyVGnfuwsKi0QAAA84"]
[Tue Jul 21 07:38:54.978125 2026] [security2:error] [pid 254995:tid 255140] [client 184.75.223.211:48832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MPv7v0rlcEGmVraFGpwAAAy0"]
[Tue Jul 21 07:38:54.978229 2026] [security2:error] [pid 254995:tid 255140] [client 184.75.223.211:48832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MPv7v0rlcEGmVraFGpwAAAy0"]
[Tue Jul 21 07:38:55.025471 2026] [security2:error] [pid 254995:tid 255181] [client 20.226.60.151:27611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/xyn.php"] [unique_id "al9MP_7v0rlcEGmVraFGqQAAA1Y"]
[Tue Jul 21 07:38:55.054989 2026] [security2:error] [pid 254995:tid 255201] [client 20.197.192.193:6376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wpx.php"] [unique_id "al9MP_7v0rlcEGmVraFGqgAAA2o"]
[Tue Jul 21 07:38:55.056753 2026] [security2:error] [pid 254995:tid 255175] [client 4.204.201.85:55987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/ffffile.php"] [unique_id "al9MP_7v0rlcEGmVraFGqwAAA1A"]
[Tue Jul 21 07:38:55.396087 2026] [security2:error] [pid 255769:tid 255907] [client 20.226.60.151:27635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ccc.php"] [unique_id "al9MP7xMYwyVGnfuwsKi1gAAA6s"]
[Tue Jul 21 07:38:55.473539 2026] [security2:error] [pid 255769:tid 255930] [client 20.226.60.151:8621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9MP7xMYwyVGnfuwsKi2AAAA8I"]
[Tue Jul 21 07:38:55.500246 2026] [security2:error] [pid 254995:tid 255133] [client 4.204.201.85:55538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/wp-firewall.php"] [unique_id "al9MP_7v0rlcEGmVraFGsgAAAyY"]
[Tue Jul 21 07:38:55.501355 2026] [security2:error] [pid 255769:tid 255955] [client 20.197.192.193:6361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/berlin.php"] [unique_id "al9MP7xMYwyVGnfuwsKi2wAAA9s"]
[Tue Jul 21 07:38:55.711163 2026] [security2:error] [pid 254995:tid 255053] [remote 104.207.63.248:55115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.63.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9MPf7v0rlcEGmVraFGgQADnTk"]
[Tue Jul 21 07:38:55.719114 2026] [security2:error] [pid 254995:tid 255275] [client 139.167.225.182:52363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MP_7v0rlcEGmVraFGuwAAA5k"]
[Tue Jul 21 07:38:55.720871 2026] [security2:error] [pid 254995:tid 255275] [client 139.167.225.182:52363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MP_7v0rlcEGmVraFGuwAAA5k"]
[Tue Jul 21 07:38:55.834969 2026] [security2:error] [pid 254995:tid 255263] [client 20.206.105.145:38134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/bless.php"] [unique_id "al9MP_7v0rlcEGmVraFGvgAAA40"]
[Tue Jul 21 07:38:56.001136 2026] [security2:error] [pid 255769:tid 255920] [client 4.204.201.85:61251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qcharge.tryhealth.shop"] [uri "/reviall.php"] [unique_id "al9MQLxMYwyVGnfuwsKi4QAAA7g"]
[Tue Jul 21 07:38:56.006961 2026] [core:error] [pid 254995:tid 255061] [remote 34.182.235.64:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:38:56.006980 2026] [core:error] [pid 254995:tid 255061] [remote 34.182.235.64:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:38:56.080555 2026] [security2:error] [pid 255769:tid 256000] [client 20.226.60.151:27563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/w.php"] [unique_id "al9MQLxMYwyVGnfuwsKi4wAABAY"]
[Tue Jul 21 07:38:56.116114 2026] [security2:error] [pid 255769:tid 256021] [client 117.217.38.194:56051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQLxMYwyVGnfuwsKi5QAABBs"]
[Tue Jul 21 07:38:56.116716 2026] [security2:error] [pid 255769:tid 256021] [client 117.217.38.194:56051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQLxMYwyVGnfuwsKi5QAABBs"]
[Tue Jul 21 07:38:56.171467 2026] [security2:error] [pid 254995:tid 255001] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MQP7v0rlcEGmVraFGxwADIQU"]
[Tue Jul 21 07:38:56.171660 2026] [security2:error] [pid 254995:tid 255128] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MQP7v0rlcEGmVraFGxwADIQU"]
[Tue Jul 21 07:38:56.178534 2026] [security2:error] [pid 255769:tid 255975] [client 20.226.60.151:8694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/k2.php"] [unique_id "al9MQLxMYwyVGnfuwsKi5wAAA-8"]
[Tue Jul 21 07:38:56.215492 2026] [security2:error] [pid 255769:tid 255936] [client 20.197.192.193:6373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/billur.php"] [unique_id "al9MQLxMYwyVGnfuwsKi6AAAA8g"]
[Tue Jul 21 07:38:56.576753 2026] [core:error] [pid 254995:tid 255115] [remote 34.182.235.64:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:38:56.576777 2026] [core:error] [pid 254995:tid 255115] [remote 34.182.235.64:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:38:56.622525 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:8840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9MQP7v0rlcEGmVraFG0AAAA5c"]
[Tue Jul 21 07:38:56.780830 2026] [security2:error] [pid 254995:tid 255021] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9MQP7v0rlcEGmVraFG1AADixk"]
[Tue Jul 21 07:38:56.905064 2026] [security2:error] [pid 254995:tid 255122] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9MQP7v0rlcEGmVraFG1gADPX4"]
[Tue Jul 21 07:38:56.934890 2026] [security2:error] [pid 254995:tid 255142] [client 20.197.192.193:6385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/mimpi.php"] [unique_id "al9MQP7v0rlcEGmVraFG2AAAAy8"]
[Tue Jul 21 07:38:56.982123 2026] [security2:error] [pid 255769:tid 255947] [client 20.226.60.151:56302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/pucci.php"] [unique_id "al9MQLxMYwyVGnfuwsKi7wAAA9M"]
[Tue Jul 21 07:38:56.982386 2026] [security2:error] [pid 255769:tid 255990] [client 20.206.105.145:38509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file46.php"] [unique_id "al9MQLxMYwyVGnfuwsKi8AAAA_4"]
[Tue Jul 21 07:38:57.069869 2026] [security2:error] [pid 254995:tid 255092] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9MQf7v0rlcEGmVraFG3AADf2A"]
[Tue Jul 21 07:38:57.115733 2026] [security2:error] [pid 255769:tid 255979] [client 20.226.60.151:27629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9MQbxMYwyVGnfuwsKi8gAAA_M"]
[Tue Jul 21 07:38:57.135034 2026] [security2:error] [pid 255769:tid 256013] [client 20.151.10.161:46020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/pucci.php"] [unique_id "al9MQbxMYwyVGnfuwsKi8wAABBM"]
[Tue Jul 21 07:38:57.240751 2026] [security2:error] [pid 254995:tid 255074] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9MQf7v0rlcEGmVraFG3wADIk4"]
[Tue Jul 21 07:38:57.393275 2026] [security2:error] [pid 254995:tid 255101] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9MQf7v0rlcEGmVraFG4QADamk"]
[Tue Jul 21 07:38:57.573461 2026] [security2:error] [pid 254995:tid 255102] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9MQf7v0rlcEGmVraFG5QADdWo"]
[Tue Jul 21 07:38:57.574179 2026] [security2:error] [pid 255769:tid 255944] [client 173.24.185.52:60607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MQbxMYwyVGnfuwsKi-gAAA9A"]
[Tue Jul 21 07:38:57.574271 2026] [security2:error] [pid 255769:tid 255944] [client 173.24.185.52:60607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MQbxMYwyVGnfuwsKi-gAAA9A"]
[Tue Jul 21 07:38:57.605372 2026] [security2:error] [pid 254995:tid 255205] [client 106.215.181.8:28503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQf7v0rlcEGmVraFG6AAAA24"]
[Tue Jul 21 07:38:57.605484 2026] [security2:error] [pid 254995:tid 255205] [client 106.215.181.8:28503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQf7v0rlcEGmVraFG6AAAA24"]
[Tue Jul 21 07:38:57.613885 2026] [security2:error] [pid 254995:tid 255185] [client 20.226.60.151:61019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/122.php"] [unique_id "al9MQf7v0rlcEGmVraFG6QAAA1o"]
[Tue Jul 21 07:38:57.713121 2026] [security2:error] [pid 254995:tid 255099] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9MQf7v0rlcEGmVraFG6gADimc"]
[Tue Jul 21 07:38:57.883421 2026] [security2:error] [pid 255769:tid 255961] [client 20.226.60.151:8733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9MQbxMYwyVGnfuwsKjAQAAA-E"]
[Tue Jul 21 07:38:58.087421 2026] [security2:error] [pid 255769:tid 255823] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9MQrxMYwyVGnfuwsKjBQAEEDU"]
[Tue Jul 21 07:38:58.198383 2026] [security2:error] [pid 255769:tid 255971] [client 20.197.192.193:6366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/dp.php"] [unique_id "al9MQrxMYwyVGnfuwsKjBgAAA-s"]
[Tue Jul 21 07:38:58.245855 2026] [security2:error] [pid 254995:tid 255109] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9MQv7v0rlcEGmVraFG8QADjnE"]
[Tue Jul 21 07:38:58.369981 2026] [security2:error] [pid 255769:tid 255824] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9MQrxMYwyVGnfuwsKjCwADpDY"]
[Tue Jul 21 07:38:58.376325 2026] [security2:error] [pid 255769:tid 255954] [client 20.226.60.151:27549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/FWAZ.php"] [unique_id "al9MQrxMYwyVGnfuwsKjDAAAA9o"]
[Tue Jul 21 07:38:58.443837 2026] [security2:error] [pid 255769:tid 255966] [client 136.144.33.106:51463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MQrxMYwyVGnfuwsKjDwAAA-Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:38:58.617383 2026] [security2:error] [pid 255769:tid 255927] [client 20.226.60.151:56231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/black.php"] [unique_id "al9MQrxMYwyVGnfuwsKjEQAAA78"]
[Tue Jul 21 07:38:58.628210 2026] [security2:error] [pid 255769:tid 255947] [client 20.226.60.151:8724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9MQrxMYwyVGnfuwsKjEgAAA9M"]
[Tue Jul 21 07:38:58.632825 2026] [security2:error] [pid 254995:tid 255118] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9MQv7v0rlcEGmVraFG9gADb3o"]
[Tue Jul 21 07:38:58.730172 2026] [security2:error] [pid 254995:tid 255275] [client 20.206.105.145:37911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/eee.php"] [unique_id "al9MQv7v0rlcEGmVraFG-QAAA5k"]
[Tue Jul 21 07:38:58.780996 2026] [security2:error] [pid 255769:tid 255882] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.conquisteemcasa.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9MQrxMYwyVGnfuwsKjFAADzXA"]
[Tue Jul 21 07:38:58.852935 2026] [security2:error] [pid 255769:tid 256021] [client 122.186.204.214:61744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MQrxMYwyVGnfuwsKjFQAABBs"]
[Tue Jul 21 07:38:58.853062 2026] [security2:error] [pid 255769:tid 256021] [client 122.186.204.214:61744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MQrxMYwyVGnfuwsKjFQAABBs"]
[Tue Jul 21 07:38:58.903121 2026] [security2:error] [pid 255769:tid 256013] [client 20.226.60.151:27646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/miru1.php"] [unique_id "al9MQrxMYwyVGnfuwsKjFwAABBM"]
[Tue Jul 21 07:38:59.259833 2026] [security2:error] [pid 255769:tid 255942] [client 20.197.192.193:6894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/bootstrap.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjGwAAA84"]
[Tue Jul 21 07:38:59.287067 2026] [security2:error] [pid 255769:tid 255999] [client 117.251.86.144:36988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjHAAABAU"]
[Tue Jul 21 07:38:59.287171 2026] [security2:error] [pid 255769:tid 255999] [client 117.251.86.144:36988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjHAAABAU"]
[Tue Jul 21 07:38:59.334244 2026] [security2:error] [pid 255769:tid 255869] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjHQAEHmM"]
[Tue Jul 21 07:38:59.334408 2026] [security2:error] [pid 255769:tid 256024] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjHQAEHmM"]
[Tue Jul 21 07:38:59.341411 2026] [security2:error] [pid 255769:tid 255866] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjHgADvGA"]
[Tue Jul 21 07:38:59.341536 2026] [security2:error] [pid 255769:tid 255924] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjHgADvGA"]
[Tue Jul 21 07:38:59.553204 2026] [security2:error] [pid 255769:tid 255922] [client 20.226.60.151:27356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/aa.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjIwAAA7o"]
[Tue Jul 21 07:38:59.813612 2026] [security2:error] [pid 255769:tid 255908] [client 20.151.10.161:45897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-temp.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjLQAAA6w"]
[Tue Jul 21 07:38:59.893473 2026] [security2:error] [pid 255769:tid 255971] [client 20.226.60.151:8700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/for.php"] [unique_id "al9MQ7xMYwyVGnfuwsKjLgAAA-s"]
[Tue Jul 21 07:39:00.000794 2026] [security2:error] [pid 255769:tid 255900] [client 20.226.60.151:51278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/mds.php"] [unique_id "al9MRLxMYwyVGnfuwsKjNAAAA6Q"]
[Tue Jul 21 07:39:00.392310 2026] [security2:error] [pid 254995:tid 255265] [client 74.7.175.177:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "roanalacerda.com.br"] [uri "/index.php"] [unique_id "al9MRP7v0rlcEGmVraFHCwAAA48"]
[Tue Jul 21 07:39:00.393819 2026] [security2:error] [pid 255769:tid 255988] [client 74.7.175.177:54586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "roanalacerda.com.br"] [uri "/robots.txt"] [unique_id "al9MRLxMYwyVGnfuwsKjPQAD_F0"]
[Tue Jul 21 07:39:00.505178 2026] [security2:error] [pid 255769:tid 255997] [client 194.99.104.35:43342] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9MRLxMYwyVGnfuwsKjQQAABAM"]
[Tue Jul 21 07:39:00.505282 2026] [security2:error] [pid 255769:tid 255997] [client 194.99.104.35:43342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9MRLxMYwyVGnfuwsKjQQAABAM"]
[Tue Jul 21 07:39:00.750299 2026] [security2:error] [pid 255769:tid 256019] [client 20.226.60.151:56265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/zlece.php"] [unique_id "al9MRLxMYwyVGnfuwsKjRAAABBk"]
[Tue Jul 21 07:39:00.812206 2026] [security2:error] [pid 255769:tid 255906] [client 20.226.60.151:27592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/122.php"] [unique_id "al9MRLxMYwyVGnfuwsKjRgAAA6o"]
[Tue Jul 21 07:39:01.093782 2026] [security2:error] [pid 254995:tid 255156] [client 20.197.192.193:6394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-editor.php"] [unique_id "al9MRf7v0rlcEGmVraFHFwAAAz0"]
[Tue Jul 21 07:39:01.095834 2026] [security2:error] [pid 255769:tid 256003] [client 154.192.233.199:59044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjSgAABAk"]
[Tue Jul 21 07:39:01.096103 2026] [security2:error] [pid 255769:tid 256003] [client 154.192.233.199:59044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjSgAABAk"]
[Tue Jul 21 07:39:01.117323 2026] [security2:error] [pid 254995:tid 255182] [client 62.102.148.187:55790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MRf7v0rlcEGmVraFHGAAAA1c"]
[Tue Jul 21 07:39:01.117429 2026] [security2:error] [pid 254995:tid 255182] [client 62.102.148.187:55790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MRf7v0rlcEGmVraFHGAAAA1c"]
[Tue Jul 21 07:39:01.177041 2026] [security2:error] [pid 255769:tid 255943] [client 20.151.10.161:45980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9MRbxMYwyVGnfuwsKjSwAAA88"]
[Tue Jul 21 07:39:01.192048 2026] [security2:error] [pid 255769:tid 255990] [client 175.45.70.82:50673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjTAAAA_4"]
[Tue Jul 21 07:39:01.192152 2026] [security2:error] [pid 255769:tid 255990] [client 175.45.70.82:50673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjTAAAA_4"]
[Tue Jul 21 07:39:01.233773 2026] [security2:error] [pid 255769:tid 255947] [client 122.164.127.47:59014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjTQAAA9M"]
[Tue Jul 21 07:39:01.233961 2026] [security2:error] [pid 255769:tid 255947] [client 122.164.127.47:59014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjTQAAA9M"]
[Tue Jul 21 07:39:01.356029 2026] [core:error] [pid 254995:tid 255073] [remote 5.255.231.176:55980] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:39:01.356055 2026] [core:error] [pid 254995:tid 255073] [remote 5.255.231.176:55980] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:39:01.548719 2026] [security2:error] [pid 255769:tid 255912] [client 74.7.175.162:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.psicologafernandaguedes.com"] [uri "/___proxy_subdomain_webmail/cgi-sys/404.html"] [unique_id "al9MRbxMYwyVGnfuwsKjUwAAA7A"]
[Tue Jul 21 07:39:01.550651 2026] [security2:error] [pid 254995:tid 255211] [client 74.7.175.162:35476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "webmail.psicologafernandaguedes.com"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "al9MRf7v0rlcEGmVraFHKgADc0Y"]
[Tue Jul 21 07:39:01.636086 2026] [security2:error] [pid 255769:tid 255999] [client 122.162.144.145:13927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjVwAABAU"]
[Tue Jul 21 07:39:01.636244 2026] [security2:error] [pid 255769:tid 255999] [client 122.162.144.145:13927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjVwAABAU"]
[Tue Jul 21 07:39:01.784947 2026] [security2:error] [pid 254995:tid 255153] [client 20.151.10.161:45934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/puc.php"] [unique_id "al9MRf7v0rlcEGmVraFHLwAAAzo"]
[Tue Jul 21 07:39:01.891285 2026] [security2:error] [pid 254995:tid 255279] [client 20.226.60.151:27605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/get.php"] [unique_id "al9MRf7v0rlcEGmVraFHMQAAA50"]
[Tue Jul 21 07:39:01.953770 2026] [security2:error] [pid 255769:tid 256020] [client 103.106.20.201:56946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjXQAABBo"]
[Tue Jul 21 07:39:01.953936 2026] [security2:error] [pid 255769:tid 256020] [client 103.106.20.201:56946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MRbxMYwyVGnfuwsKjXQAABBo"]
[Tue Jul 21 07:39:02.010288 2026] [security2:error] [pid 255769:tid 255886] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MRrxMYwyVGnfuwsKjXwAD43Q"]
[Tue Jul 21 07:39:02.010447 2026] [security2:error] [pid 255769:tid 255963] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MRrxMYwyVGnfuwsKjXwAD43Q"]
[Tue Jul 21 07:39:02.106486 2026] [security2:error] [pid 255769:tid 255853] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MRrxMYwyVGnfuwsKjYQADxlM"]
[Tue Jul 21 07:39:02.106660 2026] [security2:error] [pid 255769:tid 255934] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MRrxMYwyVGnfuwsKjYQADxlM"]
[Tue Jul 21 07:39:02.131972 2026] [security2:error] [pid 255769:tid 255936] [client 193.36.225.139:55279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MRbxMYwyVGnfuwsKjXgAAA8g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:02.177909 2026] [security2:error] [pid 254995:tid 255252] [client 20.226.60.151:8651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.psooffshore.com.br"] [uri "/raw.php"] [unique_id "al9MRv7v0rlcEGmVraFHNgAAA4M"]
[Tue Jul 21 07:39:02.262131 2026] [security2:error] [pid 255769:tid 256013] [client 4.204.201.85:49904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MRrxMYwyVGnfuwsKjZwAABBM"]
[Tue Jul 21 07:39:02.362529 2026] [security2:error] [pid 255769:tid 256026] [client 20.226.60.151:56271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/vssrs.php"] [unique_id "al9MRrxMYwyVGnfuwsKjagAABCA"]
[Tue Jul 21 07:39:02.375490 2026] [security2:error] [pid 255769:tid 255919] [client 20.226.60.151:27372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/as.php"] [unique_id "al9MRrxMYwyVGnfuwsKjawAAA7c"]
[Tue Jul 21 07:39:02.416592 2026] [security2:error] [pid 255769:tid 255964] [client 20.226.60.151:61055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-blink.php"] [unique_id "al9MRrxMYwyVGnfuwsKjbAAAA-Q"]
[Tue Jul 21 07:39:02.542643 2026] [security2:error] [pid 255769:tid 255942] [client 4.204.201.85:49820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MRrxMYwyVGnfuwsKjbQAAA84"]
[Tue Jul 21 07:39:02.605828 2026] [security2:error] [pid 254995:tid 255172] [client 20.197.192.193:6890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/cro.php"] [unique_id "al9MRv7v0rlcEGmVraFHPwAAA00"]
[Tue Jul 21 07:39:02.672240 2026] [security2:error] [pid 255769:tid 255986] [client 20.151.10.161:45987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/themes.php"] [unique_id "al9MRrxMYwyVGnfuwsKjbwAAA_o"]
[Tue Jul 21 07:39:02.718901 2026] [security2:error] [pid 254995:tid 255183] [client 193.36.225.62:25667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MRv7v0rlcEGmVraFHOgAAA1g"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:02.949358 2026] [security2:error] [pid 255769:tid 255935] [client 20.226.60.151:27571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ccou.php"] [unique_id "al9MRrxMYwyVGnfuwsKjdgAAA8c"]
[Tue Jul 21 07:39:03.019888 2026] [security2:error] [pid 255769:tid 255910] [client 4.204.201.85:4464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/x.php"] [unique_id "al9MR7xMYwyVGnfuwsKjdwAAA64"]
[Tue Jul 21 07:39:03.097907 2026] [security2:error] [pid 255769:tid 255998] [client 20.226.60.151:27532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/w3lls.php"] [unique_id "al9MR7xMYwyVGnfuwsKjeAAABAQ"]
[Tue Jul 21 07:39:03.217113 2026] [security2:error] [pid 254995:tid 255130] [client 20.206.105.145:38219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file25.php"] [unique_id "al9MR_7v0rlcEGmVraFHRwAAAyM"]
[Tue Jul 21 07:39:03.397198 2026] [security2:error] [pid 255769:tid 255911] [client 4.204.201.85:49813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/mgrr.php"] [unique_id "al9MR7xMYwyVGnfuwsKjgAAAA68"]
[Tue Jul 21 07:39:03.472374 2026] [security2:error] [pid 254995:tid 255160] [client 20.226.60.151:27546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/test1.php"] [unique_id "al9MR_7v0rlcEGmVraFHTQAAA0E"]
[Tue Jul 21 07:39:03.534322 2026] [security2:error] [pid 254995:tid 255126] [client 20.226.60.151:61224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/zc-208.php"] [unique_id "al9MR_7v0rlcEGmVraFHTgAAAx8"]
[Tue Jul 21 07:39:03.669365 2026] [security2:error] [pid 254995:tid 255156] [client 20.226.60.151:27522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/database.php"] [unique_id "al9MR_7v0rlcEGmVraFHUgAAAz0"]
[Tue Jul 21 07:39:03.749684 2026] [security2:error] [pid 255769:tid 256009] [client 4.204.201.85:4419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/stdin.php"] [unique_id "al9MR7xMYwyVGnfuwsKjhQAABA8"]
[Tue Jul 21 07:39:03.788160 2026] [security2:error] [pid 254995:tid 255195] [client 103.86.117.203:58808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MR_7v0rlcEGmVraFHUwAAA2Q"]
[Tue Jul 21 07:39:03.788250 2026] [security2:error] [pid 254995:tid 255195] [client 103.86.117.203:58808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MR_7v0rlcEGmVraFHUwAAA2Q"]
[Tue Jul 21 07:39:03.942147 2026] [security2:error] [pid 255769:tid 255992] [client 20.151.10.161:45913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/dx.php"] [unique_id "al9MR7xMYwyVGnfuwsKjiQAAA_8"]
[Tue Jul 21 07:39:04.034882 2026] [security2:error] [pid 255769:tid 255985] [client 4.204.201.85:49908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/BDKR28.php"] [unique_id "al9MSLxMYwyVGnfuwsKjigAAA_k"]
[Tue Jul 21 07:39:04.038267 2026] [security2:error] [pid 255769:tid 255934] [client 20.226.60.151:27565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file.php"] [unique_id "al9MSLxMYwyVGnfuwsKjiwAAA8Y"]
[Tue Jul 21 07:39:04.050488 2026] [security2:error] [pid 254995:tid 255273] [client 103.174.34.15:62971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSP7v0rlcEGmVraFHWQAAA5c"]
[Tue Jul 21 07:39:04.050780 2026] [security2:error] [pid 254995:tid 255273] [client 103.174.34.15:62971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSP7v0rlcEGmVraFHWQAAA5c"]
[Tue Jul 21 07:39:04.320792 2026] [security2:error] [pid 255769:tid 256021] [client 4.204.201.85:4524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/001.php"] [unique_id "al9MSLxMYwyVGnfuwsKjlAAABBs"]
[Tue Jul 21 07:39:04.570462 2026] [security2:error] [pid 255769:tid 255986] [client 37.140.223.117:52783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MSLxMYwyVGnfuwsKjmAAAA_o"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:04.708656 2026] [security2:error] [pid 255769:tid 255907] [client 4.204.201.85:49869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/dZ3wP5.php"] [unique_id "al9MSLxMYwyVGnfuwsKjnAAAA6s"]
[Tue Jul 21 07:39:04.736780 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:27550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file.php"] [unique_id "al9MSLxMYwyVGnfuwsKjnQAAA_4"]
[Tue Jul 21 07:39:04.775518 2026] [security2:error] [pid 255769:tid 255910] [client 20.206.105.145:38084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file48.php"] [unique_id "al9MSLxMYwyVGnfuwsKjngAAA64"]
[Tue Jul 21 07:39:04.790226 2026] [security2:error] [pid 255769:tid 255938] [client 20.151.10.161:45971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/p.php"] [unique_id "al9MSLxMYwyVGnfuwsKjnwAAA8o"]
[Tue Jul 21 07:39:04.882889 2026] [security2:error] [pid 255769:tid 255789] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MSLxMYwyVGnfuwsKjoAADqBM"]
[Tue Jul 21 07:39:04.883105 2026] [security2:error] [pid 255769:tid 255904] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MSLxMYwyVGnfuwsKjoAADqBM"]
[Tue Jul 21 07:39:05.052934 2026] [security2:error] [pid 254995:tid 255254] [client 4.204.201.85:4467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/yup.php"] [unique_id "al9MSf7v0rlcEGmVraFHZwAAA4Q"]
[Tue Jul 21 07:39:05.116800 2026] [security2:error] [pid 254995:tid 255211] [client 20.226.60.151:51301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/sid4.php"] [unique_id "al9MSf7v0rlcEGmVraFHaAAAA3M"]
[Tue Jul 21 07:39:05.288169 2026] [security2:error] [pid 254995:tid 255036] [remote 8.217.108.67:5594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wp-login.php"] [unique_id "al9MSf7v0rlcEGmVraFHbgADmCg"]
[Tue Jul 21 07:39:05.324862 2026] [security2:error] [pid 254995:tid 255153] [client 20.226.60.151:27534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/777.php"] [unique_id "al9MSf7v0rlcEGmVraFHbwAAAzo"]
[Tue Jul 21 07:39:05.360033 2026] [security2:error] [pid 254995:tid 255267] [client 4.204.201.85:4439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/X.php"] [unique_id "al9MSf7v0rlcEGmVraFHcAAAA5E"]
[Tue Jul 21 07:39:05.397632 2026] [security2:error] [pid 254995:tid 255166] [client 20.220.225.223:31177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/red.php"] [unique_id "al9MSf7v0rlcEGmVraFHdAAAA0c"]
[Tue Jul 21 07:39:05.545771 2026] [security2:error] [pid 255769:tid 255976] [client 20.151.10.161:46013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/bthil.php"] [unique_id "al9MSbxMYwyVGnfuwsKjqQAAA_A"]
[Tue Jul 21 07:39:05.763000 2026] [security2:error] [pid 255769:tid 255985] [client 4.204.201.85:49881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/1polka.php"] [unique_id "al9MSbxMYwyVGnfuwsKjrQAAA_k"]
[Tue Jul 21 07:39:05.776882 2026] [security2:error] [pid 255769:tid 255999] [client 59.96.220.140:64043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MSbxMYwyVGnfuwsKjrgAABAU"]
[Tue Jul 21 07:39:05.777638 2026] [security2:error] [pid 255769:tid 255999] [client 59.96.220.140:64043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MSbxMYwyVGnfuwsKjrgAABAU"]
[Tue Jul 21 07:39:06.017773 2026] [security2:error] [pid 254995:tid 255190] [client 20.226.60.151:27524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ssixta.php"] [unique_id "al9MSv7v0rlcEGmVraFHfAAAA18"]
[Tue Jul 21 07:39:06.079995 2026] [security2:error] [pid 254995:tid 255203] [client 4.204.201.85:49914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/gec.php"] [unique_id "al9MSv7v0rlcEGmVraFHfgAAA2w"]
[Tue Jul 21 07:39:06.194058 2026] [security2:error] [pid 255769:tid 256009] [client 139.167.225.182:53006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSrxMYwyVGnfuwsKjtQAABA8"]
[Tue Jul 21 07:39:06.194191 2026] [security2:error] [pid 255769:tid 256009] [client 139.167.225.182:53006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSrxMYwyVGnfuwsKjtQAABA8"]
[Tue Jul 21 07:39:06.268950 2026] [security2:error] [pid 255769:tid 256026] [client 20.151.10.161:46048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/7.php"] [unique_id "al9MSrxMYwyVGnfuwsKjtgAABCA"]
[Tue Jul 21 07:39:06.281902 2026] [autoindex:error] [pid 255769:tid 255946] [client 20.226.60.151:61196] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:06.294747 2026] [security2:error] [pid 255769:tid 255919] [client 20.206.105.145:38130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file6.php"] [unique_id "al9MSrxMYwyVGnfuwsKjuQAAA7c"]
[Tue Jul 21 07:39:06.298608 2026] [security2:error] [pid 255769:tid 255905] [client 20.226.60.151:61196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wmore1.php"] [unique_id "al9MSrxMYwyVGnfuwsKjugAAA6k"]
[Tue Jul 21 07:39:06.369811 2026] [security2:error] [pid 255769:tid 255899] [client 4.204.201.85:49814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/sky.php"] [unique_id "al9MSrxMYwyVGnfuwsKjvAAAA6M"]
[Tue Jul 21 07:39:06.535616 2026] [security2:error] [pid 255769:tid 255986] [client 20.226.60.151:56218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wicked.php"] [unique_id "al9MSrxMYwyVGnfuwsKjvgAAA_o"]
[Tue Jul 21 07:39:06.585375 2026] [security2:error] [pid 254995:tid 255220] [client 117.217.38.194:56530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSv7v0rlcEGmVraFHiAAAA3w"]
[Tue Jul 21 07:39:06.585524 2026] [security2:error] [pid 254995:tid 255220] [client 117.217.38.194:56530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSv7v0rlcEGmVraFHiAAAA3w"]
[Tue Jul 21 07:39:06.637566 2026] [security2:error] [pid 255769:tid 256015] [client 193.36.225.62:53151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MSrxMYwyVGnfuwsKjwAAABBU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:06.653730 2026] [security2:error] [pid 254995:tid 255156] [client 4.204.201.85:49815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/fffm.php"] [unique_id "al9MSv7v0rlcEGmVraFHiQAAAz0"]
[Tue Jul 21 07:39:06.718207 2026] [security2:error] [pid 255769:tid 256005] [client 20.197.192.193:6848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/cron-tab.php"] [unique_id "al9MSrxMYwyVGnfuwsKjwwAABAs"]
[Tue Jul 21 07:39:06.732439 2026] [autoindex:error] [pid 255769:tid 255943] [client 34.26.20.91:52252] AH01276: Cannot serve directory /home3/sabri472/evolvaa.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:06.846429 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:51269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/solo1.php"] [unique_id "al9MSv7v0rlcEGmVraFHiwAAA5c"]
[Tue Jul 21 07:39:06.934356 2026] [security2:error] [pid 255769:tid 255934] [client 152.59.154.239:61658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSrxMYwyVGnfuwsKjyQAAA8Y"]
[Tue Jul 21 07:39:06.934487 2026] [security2:error] [pid 255769:tid 255934] [client 152.59.154.239:61658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MSrxMYwyVGnfuwsKjyQAAA8Y"]
[Tue Jul 21 07:39:06.955801 2026] [security2:error] [pid 254995:tid 255201] [client 20.220.225.223:38687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/fffm.php"] [unique_id "al9MSv7v0rlcEGmVraFHjAAAA2o"]
[Tue Jul 21 07:39:06.958763 2026] [security2:error] [pid 255769:tid 255902] [client 4.204.201.85:4454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/sixxis.php"] [unique_id "al9MSrxMYwyVGnfuwsKjygAAA6Y"]
[Tue Jul 21 07:39:07.075112 2026] [security2:error] [pid 254995:tid 255140] [client 20.226.60.151:27530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/1c.php"] [unique_id "al9MS_7v0rlcEGmVraFHjwAAAy0"]
[Tue Jul 21 07:39:07.147926 2026] [security2:error] [pid 255769:tid 255897] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MS7xMYwyVGnfuwsKjywAEEH8"]
[Tue Jul 21 07:39:07.148108 2026] [security2:error] [pid 255769:tid 256010] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MS7xMYwyVGnfuwsKjywAEEH8"]
[Tue Jul 21 07:39:07.211631 2026] [security2:error] [pid 255769:tid 255955] [client 20.151.10.161:45914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/8.php"] [unique_id "al9MS7xMYwyVGnfuwsKjzwAAA9s"]
[Tue Jul 21 07:39:07.241581 2026] [security2:error] [pid 255769:tid 256000] [client 4.204.201.85:49845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/yj09.php"] [unique_id "al9MS7xMYwyVGnfuwsKj0gAABAY"]
[Tue Jul 21 07:39:07.497864 2026] [autoindex:error] [pid 255769:tid 255999] [client 20.226.60.151:51318] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:07.527510 2026] [security2:error] [pid 255769:tid 255959] [client 20.226.60.151:51318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/cong.php"] [unique_id "al9MS7xMYwyVGnfuwsKj2AAAA98"]
[Tue Jul 21 07:39:07.527525 2026] [security2:error] [pid 255769:tid 255974] [client 4.204.201.85:4475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/f900.php"] [unique_id "al9MS7xMYwyVGnfuwsKj1wAAA-4"]
[Tue Jul 21 07:39:07.608466 2026] [security2:error] [pid 255769:tid 255941] [client 20.151.10.161:46003] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "prospecta.agendaclique.com.br"] [uri "/1.php"] [unique_id "al9MS7xMYwyVGnfuwsKj3AAAA80"]
[Tue Jul 21 07:39:07.608551 2026] [security2:error] [pid 255769:tid 255941] [client 20.151.10.161:46003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/1.php"] [unique_id "al9MS7xMYwyVGnfuwsKj3AAAA80"]
[Tue Jul 21 07:39:07.831594 2026] [security2:error] [pid 255769:tid 255899] [client 4.204.201.85:49806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ups.php"] [unique_id "al9MS7xMYwyVGnfuwsKj4QAAA6M"]
[Tue Jul 21 07:39:07.939798 2026] [security2:error] [pid 255769:tid 256023] [client 106.215.181.8:8593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MS7xMYwyVGnfuwsKj4gAABB0"]
[Tue Jul 21 07:39:07.939923 2026] [security2:error] [pid 255769:tid 256023] [client 106.215.181.8:8593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MS7xMYwyVGnfuwsKj4gAABB0"]
[Tue Jul 21 07:39:07.978174 2026] [fcgid:warn] [pid 255769:tid 255960] (70014)End of file found: [client 66.132.186.182:61094] mod_fcgid: can't get data from http client
[Tue Jul 21 07:39:07.980128 2026] [security2:error] [pid 255769:tid 255925] [client 20.226.60.151:27538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/test2.php"] [unique_id "al9MS7xMYwyVGnfuwsKj5AAAA70"]
[Tue Jul 21 07:39:08.026858 2026] [security2:error] [pid 255769:tid 256015] [client 20.206.105.145:38118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/a2.php"] [unique_id "al9MTLxMYwyVGnfuwsKj5wAABBU"]
[Tue Jul 21 07:39:08.130240 2026] [security2:error] [pid 254995:tid 255208] [client 4.204.201.85:4429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/k.php"] [unique_id "al9MTP7v0rlcEGmVraFHnQAAA3A"]
[Tue Jul 21 07:39:08.146740 2026] [security2:error] [pid 254995:tid 255175] [client 20.151.10.161:46036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/100.php"] [unique_id "al9MTP7v0rlcEGmVraFHnwAAA1A"]
[Tue Jul 21 07:39:08.158170 2026] [security2:error] [pid 255769:tid 255970] [client 173.24.185.52:61072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MTLxMYwyVGnfuwsKj6QAAA-o"]
[Tue Jul 21 07:39:08.158271 2026] [security2:error] [pid 255769:tid 255970] [client 173.24.185.52:61072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MTLxMYwyVGnfuwsKj6QAAA-o"]
[Tue Jul 21 07:39:08.252021 2026] [autoindex:error] [pid 255769:tid 255903] [client 20.226.60.151:51315] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:08.269617 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:51315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/public/css.php"] [unique_id "al9MTLxMYwyVGnfuwsKj7QAAA_4"]
[Tue Jul 21 07:39:08.408344 2026] [security2:error] [pid 255769:tid 255928] [client 4.204.201.85:4505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/k2.php"] [unique_id "al9MTLxMYwyVGnfuwsKj8AAAA8A"]
[Tue Jul 21 07:39:08.576342 2026] [security2:error] [pid 255769:tid 256010] [client 20.226.60.151:27614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/buy.php"] [unique_id "al9MTLxMYwyVGnfuwsKj8QAABBA"]
[Tue Jul 21 07:39:08.730109 2026] [security2:error] [pid 254995:tid 255263] [client 20.220.225.223:38262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/pn.php"] [unique_id "al9MTP7v0rlcEGmVraFHvQAAA40"]
[Tue Jul 21 07:39:08.732899 2026] [security2:error] [pid 254995:tid 255275] [client 62.102.148.187:60000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MTP7v0rlcEGmVraFHvgAAA5k"]
[Tue Jul 21 07:39:08.732972 2026] [security2:error] [pid 254995:tid 255275] [client 62.102.148.187:60000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MTP7v0rlcEGmVraFHvgAAA5k"]
[Tue Jul 21 07:39:08.744689 2026] [security2:error] [pid 254995:tid 255206] [client 4.204.201.85:4441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/w.php"] [unique_id "al9MTP7v0rlcEGmVraFHvwAAA28"]
[Tue Jul 21 07:39:08.779135 2026] [security2:error] [pid 254995:tid 255159] [client 20.151.10.161:46053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/about.php"] [unique_id "al9MTP7v0rlcEGmVraFHwgAAA0A"]
[Tue Jul 21 07:39:08.889088 2026] [security2:error] [pid 255769:tid 255921] [client 20.220.225.223:38686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/ftde.php"] [unique_id "al9MTLxMYwyVGnfuwsKj9QAAA7k"]
[Tue Jul 21 07:39:08.909797 2026] [security2:error] [pid 255769:tid 255900] [client 20.226.60.151:51311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/output.php"] [unique_id "al9MTLxMYwyVGnfuwsKj9gAAA6Q"]
[Tue Jul 21 07:39:09.022692 2026] [security2:error] [pid 255769:tid 255931] [client 20.226.60.151:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/24.php"] [unique_id "al9MTbxMYwyVGnfuwsKj-AAAA8M"]
[Tue Jul 21 07:39:09.088966 2026] [security2:error] [pid 254995:tid 255135] [client 4.204.201.85:4534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/fpwch.php"] [unique_id "al9MTf7v0rlcEGmVraFH0QAAAyg"]
[Tue Jul 21 07:39:09.394189 2026] [security2:error] [pid 254995:tid 255184] [client 4.204.201.85:4510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/w2025.php"] [unique_id "al9MTf7v0rlcEGmVraFH2wAAA1k"]
[Tue Jul 21 07:39:09.508322 2026] [security2:error] [pid 255769:tid 255985] [client 20.226.60.151:51302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-file-120.php"] [unique_id "al9MTbxMYwyVGnfuwsKj-wAAA_k"]
[Tue Jul 21 07:39:09.535949 2026] [security2:error] [pid 255769:tid 256017] [client 122.186.204.214:62273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MTbxMYwyVGnfuwsKj_AAABBc"]
[Tue Jul 21 07:39:09.536074 2026] [security2:error] [pid 255769:tid 256017] [client 122.186.204.214:62273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MTbxMYwyVGnfuwsKj_AAABBc"]
[Tue Jul 21 07:39:09.726960 2026] [security2:error] [pid 255769:tid 255959] [client 4.204.201.85:4466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/FWAZ.php"] [unique_id "al9MTbxMYwyVGnfuwsKj_gAAA98"]
[Tue Jul 21 07:39:09.907463 2026] [security2:error] [pid 254995:tid 255157] [client 117.251.86.144:49470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MTf7v0rlcEGmVraFH5wAAAz4"]
[Tue Jul 21 07:39:09.907597 2026] [security2:error] [pid 254995:tid 255157] [client 117.251.86.144:49470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MTf7v0rlcEGmVraFH5wAAAz4"]
[Tue Jul 21 07:39:09.944602 2026] [security2:error] [pid 254995:tid 255069] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MTf7v0rlcEGmVraFH6AADbkk"]
[Tue Jul 21 07:39:09.944769 2026] [security2:error] [pid 254995:tid 255205] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MTf7v0rlcEGmVraFH6AADbkk"]
[Tue Jul 21 07:39:10.069474 2026] [security2:error] [pid 254995:tid 255199] [client 4.204.201.85:49817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/qterm.php"] [unique_id "al9MTv7v0rlcEGmVraFH6gAAA2g"]
[Tue Jul 21 07:39:10.075349 2026] [security2:error] [pid 254995:tid 255042] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MTv7v0rlcEGmVraFH6wADmi4"]
[Tue Jul 21 07:39:10.075485 2026] [security2:error] [pid 254995:tid 255276] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MTv7v0rlcEGmVraFH6wADmi4"]
[Tue Jul 21 07:39:10.119742 2026] [security2:error] [pid 254995:tid 255129] [client 20.226.60.151:27354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ssend.php"] [unique_id "al9MTv7v0rlcEGmVraFH7wAAAyI"]
[Tue Jul 21 07:39:10.120310 2026] [security2:error] [pid 254995:tid 255169] [client 20.226.60.151:56309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/xacs.php"] [unique_id "al9MTv7v0rlcEGmVraFH8AAAA0o"]
[Tue Jul 21 07:39:10.133225 2026] [security2:error] [pid 254995:tid 255255] [client 20.206.105.145:38467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/file15.php"] [unique_id "al9MTv7v0rlcEGmVraFH8gAAA4U"]
[Tue Jul 21 07:39:10.366219 2026] [security2:error] [pid 255769:tid 256025] [client 20.226.60.151:51347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/special.php"] [unique_id "al9MTrxMYwyVGnfuwsKkWgAABB8"]
[Tue Jul 21 07:39:10.406520 2026] [security2:error] [pid 255769:tid 255928] [client 4.204.201.85:49884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/blurbs.php"] [unique_id "al9MTrxMYwyVGnfuwsKkrwAAA8A"]
[Tue Jul 21 07:39:10.449849 2026] [qos:error] [pid 255769:tid 256021] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKk9gAABBs, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.449870 2026] [qos:error] [pid 254995:tid 255273] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9MTv7v0rlcEGmVraFIJAAAA5c, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.449878 2026] [qos:error] [pid 255769:tid 255951] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKk9wAAA9c, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.450119 2026] [qos:error] [pid 255769:tid 255916] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKlCwAAA7Q, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.450130 2026] [qos:error] [pid 254995:tid 255222] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.100.222, id=al9MTv7v0rlcEGmVraFIJgAAA34, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.450156 2026] [qos:error] [pid 254995:tid 255201] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.100.222, id=al9MTv7v0rlcEGmVraFIKAAAA2o, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.450277 2026] [qos:error] [pid 255769:tid 256018] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKk-QAABBg, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.450466 2026] [qos:error] [pid 254995:tid 255157] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9MTv7v0rlcEGmVraFIJwAAAz4, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.450669 2026] [qos:error] [pid 255769:tid 255937] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKk-gAAA8k, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.450679 2026] [qos:error] [pid 255769:tid 255971] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKk_AAAA-s, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.451260 2026] [qos:error] [pid 255769:tid 255932] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKk_gAAA8Q, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.451269 2026] [qos:error] [pid 255769:tid 255899] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKk_QAAA6M, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.452162 2026] [security2:error] [pid 254995:tid 255260] [client 20.151.10.161:46069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/admin.php"] [unique_id "al9MTv7v0rlcEGmVraFILgAAA4o"]
[Tue Jul 21 07:39:10.452944 2026] [qos:error] [pid 255769:tid 255923] [client 177.162.81.57:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9MTrxMYwyVGnfuwsKlDAAAA7s, referer: https://woma.com.br/
[Tue Jul 21 07:39:10.795923 2026] [security2:error] [pid 255769:tid 255986] [client 4.204.201.85:4449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/v543.php"] [unique_id "al9MTrxMYwyVGnfuwsKlGAAAA_o"]
[Tue Jul 21 07:39:11.040597 2026] [autoindex:error] [pid 254995:tid 255138] [client 66.132.186.182:61114] AH01276: Cannot serve directory /home2/rica0429/gradiente.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:11.094826 2026] [security2:error] [pid 254995:tid 255217] [client 4.204.201.85:49816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/w3lls.php"] [unique_id "al9MT_7v0rlcEGmVraFIPwAAA3k"]
[Tue Jul 21 07:39:11.338286 2026] [security2:error] [pid 254995:tid 255132] [client 193.36.225.58:60707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MT_7v0rlcEGmVraFIRAAAAyU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:11.505748 2026] [security2:error] [pid 254995:tid 255177] [client 4.204.201.85:49840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-ws68.php"] [unique_id "al9MT_7v0rlcEGmVraFISQAAA1I"]
[Tue Jul 21 07:39:11.672147 2026] [security2:error] [pid 255769:tid 255937] [client 194.99.104.35:40302] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MT7xMYwyVGnfuwsKlIgAAA8k"]
[Tue Jul 21 07:39:11.672273 2026] [security2:error] [pid 255769:tid 255937] [client 194.99.104.35:40302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MT7xMYwyVGnfuwsKlIgAAA8k"]
[Tue Jul 21 07:39:11.741636 2026] [security2:error] [pid 255769:tid 255997] [client 20.226.60.151:27576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/item.php"] [unique_id "al9MT7xMYwyVGnfuwsKlJQAABAM"]
[Tue Jul 21 07:39:11.776803 2026] [security2:error] [pid 255769:tid 255922] [client 154.192.233.199:59259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MT7xMYwyVGnfuwsKlKAAAA7o"]
[Tue Jul 21 07:39:11.776947 2026] [security2:error] [pid 255769:tid 255922] [client 154.192.233.199:59259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MT7xMYwyVGnfuwsKlKAAAA7o"]
[Tue Jul 21 07:39:11.778993 2026] [security2:error] [pid 255769:tid 255984] [client 20.151.10.161:46079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/edit.php"] [unique_id "al9MT7xMYwyVGnfuwsKlKQAAA_g"]
[Tue Jul 21 07:39:11.829617 2026] [security2:error] [pid 254995:tid 255198] [client 4.204.201.85:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/xyn.php"] [unique_id "al9MT_7v0rlcEGmVraFITAAAA2c"]
[Tue Jul 21 07:39:11.893714 2026] [security2:error] [pid 255769:tid 255935] [client 20.226.60.151:56200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/zildan.php"] [unique_id "al9MT7xMYwyVGnfuwsKlLAAAA8c"]
[Tue Jul 21 07:39:11.970317 2026] [security2:error] [pid 255769:tid 255996] [client 20.226.60.151:51349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/as.php"] [unique_id "al9MT7xMYwyVGnfuwsKlLwAABAI"]
[Tue Jul 21 07:39:12.058846 2026] [security2:error] [pid 255769:tid 255925] [client 175.45.70.82:51194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlMQAAA70"]
[Tue Jul 21 07:39:12.058964 2026] [security2:error] [pid 255769:tid 255925] [client 175.45.70.82:51194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlMQAAA70"]
[Tue Jul 21 07:39:12.096483 2026] [security2:error] [pid 255769:tid 256013] [client 122.164.127.47:59522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlMgAABBM"]
[Tue Jul 21 07:39:12.096600 2026] [security2:error] [pid 255769:tid 256013] [client 122.164.127.47:59522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlMgAABBM"]
[Tue Jul 21 07:39:12.135128 2026] [security2:error] [pid 255769:tid 255901] [client 4.204.201.85:49900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/green3.php"] [unique_id "al9MULxMYwyVGnfuwsKlNgAAA6U"]
[Tue Jul 21 07:39:12.387729 2026] [security2:error] [pid 254995:tid 255160] [client 20.226.60.151:56220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/csa.php"] [unique_id "al9MUP7v0rlcEGmVraFIXwAAA0E"]
[Tue Jul 21 07:39:12.390208 2026] [security2:error] [pid 254995:tid 255142] [client 20.206.105.145:38091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/jp.php"] [unique_id "al9MUP7v0rlcEGmVraFIYAAAAy8"]
[Tue Jul 21 07:39:12.399451 2026] [security2:error] [pid 255769:tid 256003] [client 122.162.144.145:9947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlcgAABAk"]
[Tue Jul 21 07:39:12.399544 2026] [security2:error] [pid 255769:tid 256003] [client 122.162.144.145:9947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlcgAABAk"]
[Tue Jul 21 07:39:12.439433 2026] [security2:error] [pid 254995:tid 255181] [client 20.226.60.151:51340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9MUP7v0rlcEGmVraFIdgAAA1Y"]
[Tue Jul 21 07:39:12.482989 2026] [security2:error] [pid 255769:tid 255980] [client 4.204.201.85:4485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ccc.php"] [unique_id "al9MULxMYwyVGnfuwsKldwAAA_Q"]
[Tue Jul 21 07:39:12.568555 2026] [security2:error] [pid 255769:tid 255956] [client 103.106.20.201:57525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlkwAAA9w"]
[Tue Jul 21 07:39:12.568642 2026] [security2:error] [pid 255769:tid 255956] [client 103.106.20.201:57525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlkwAAA9w"]
[Tue Jul 21 07:39:12.569298 2026] [security2:error] [pid 255769:tid 255888] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKllAAD13Y"]
[Tue Jul 21 07:39:12.569382 2026] [security2:error] [pid 255769:tid 255951] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKllAAD13Y"]
[Tue Jul 21 07:39:12.629367 2026] [security2:error] [pid 255769:tid 255790] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlqQAD_xQ"]
[Tue Jul 21 07:39:12.629509 2026] [security2:error] [pid 255769:tid 255992] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MULxMYwyVGnfuwsKlqQAD_xQ"]
[Tue Jul 21 07:39:12.727266 2026] [security2:error] [pid 255769:tid 256012] [client 20.197.192.193:6883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/koiy.php"] [unique_id "al9MULxMYwyVGnfuwsKlrQAABBI"]
[Tue Jul 21 07:39:12.847364 2026] [security2:error] [pid 255769:tid 255985] [client 20.226.60.151:61005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/w1px.php"] [unique_id "al9MULxMYwyVGnfuwsKltAAAA_k"]
[Tue Jul 21 07:39:12.859376 2026] [security2:error] [pid 254995:tid 255162] [client 20.226.60.151:27572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ss.php"] [unique_id "al9MUP7v0rlcEGmVraFIwgAAA0M"]
[Tue Jul 21 07:39:12.942208 2026] [security2:error] [pid 255769:tid 255930] [client 4.204.201.85:4520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/get.php"] [unique_id "al9MULxMYwyVGnfuwsKlwQAAA8I"]
[Tue Jul 21 07:39:13.297254 2026] [security2:error] [pid 254995:tid 255258] [client 20.226.60.151:61239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/yawa.php"] [unique_id "al9MUf7v0rlcEGmVraFIyQAAA4g"]
[Tue Jul 21 07:39:13.319983 2026] [security2:error] [pid 254995:tid 255220] [client 4.204.201.85:4496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/images.php"] [unique_id "al9MUf7v0rlcEGmVraFIygAAA3w"]
[Tue Jul 21 07:39:13.348366 2026] [security2:error] [pid 255769:tid 255909] [client 20.151.10.161:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MUbxMYwyVGnfuwsKlxAAAA60"]
[Tue Jul 21 07:39:13.641674 2026] [security2:error] [pid 255769:tid 256003] [client 20.220.225.223:22502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9MUbxMYwyVGnfuwsKlygAABAk"]
[Tue Jul 21 07:39:13.691929 2026] [security2:error] [pid 255769:tid 255983] [client 20.197.192.193:7021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/hp2.php"] [unique_id "al9MUbxMYwyVGnfuwsKlzAAAA_c"]
[Tue Jul 21 07:39:13.716379 2026] [security2:error] [pid 255769:tid 255906] [client 20.226.60.151:51385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/js.php"] [unique_id "al9MUbxMYwyVGnfuwsKlzQAAA6o"]
[Tue Jul 21 07:39:13.719058 2026] [security2:error] [pid 255769:tid 255932] [client 4.204.201.85:4487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/alls.php"] [unique_id "al9MUbxMYwyVGnfuwsKlzgAAA8Q"]
[Tue Jul 21 07:39:14.036901 2026] [security2:error] [pid 254995:tid 255275] [client 4.204.201.85:21823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/coffexium.php"] [unique_id "al9MUv7v0rlcEGmVraFI1QAAA5k"]
[Tue Jul 21 07:39:14.075800 2026] [security2:error] [pid 255769:tid 255956] [client 20.226.60.151:51355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/core.php"] [unique_id "al9MUrxMYwyVGnfuwsKl_AAAA9w"]
[Tue Jul 21 07:39:14.153051 2026] [security2:error] [pid 254995:tid 255177] [client 20.226.60.151:51369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/19.php"] [unique_id "al9MUv7v0rlcEGmVraFI2gAAA1I"]
[Tue Jul 21 07:39:14.209474 2026] [security2:error] [pid 255769:tid 255999] [client 20.226.60.151:51322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/inc.php"] [unique_id "al9MUrxMYwyVGnfuwsKmBAAABAU"]
[Tue Jul 21 07:39:14.272122 2026] [security2:error] [pid 255769:tid 255942] [client 103.86.117.203:59333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MUrxMYwyVGnfuwsKmBQAAA84"]
[Tue Jul 21 07:39:14.272270 2026] [security2:error] [pid 255769:tid 255942] [client 103.86.117.203:59333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MUrxMYwyVGnfuwsKmBQAAA84"]
[Tue Jul 21 07:39:14.295265 2026] [security2:error] [pid 254995:tid 255201] [client 20.226.60.151:61214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9MUv7v0rlcEGmVraFI2wAAA2o"]
[Tue Jul 21 07:39:14.338222 2026] [security2:error] [pid 254995:tid 255262] [client 4.204.201.85:49793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/red.php"] [unique_id "al9MUv7v0rlcEGmVraFI3AAAA4w"]
[Tue Jul 21 07:39:14.427529 2026] [security2:error] [pid 255769:tid 255946] [client 20.226.60.151:27377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/hypo.php"] [unique_id "al9MUrxMYwyVGnfuwsKmBgAAA9I"]
[Tue Jul 21 07:39:14.438324 2026] [security2:error] [pid 255769:tid 255992] [client 20.226.60.151:61187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9MUrxMYwyVGnfuwsKmCAAAA_8"]
[Tue Jul 21 07:39:14.442875 2026] [security2:error] [pid 255769:tid 255958] [client 20.226.60.151:56304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/w3llscc.php"] [unique_id "al9MUrxMYwyVGnfuwsKmCQAAA94"]
[Tue Jul 21 07:39:14.493130 2026] [security2:error] [pid 255769:tid 256028] [client 20.206.105.145:38097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/f35.php"] [unique_id "al9MUrxMYwyVGnfuwsKmCwAABCI"]
[Tue Jul 21 07:39:14.601507 2026] [security2:error] [pid 255769:tid 255974] [client 20.226.60.151:51348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ss.php"] [unique_id "al9MUrxMYwyVGnfuwsKmDwAAA-4"]
[Tue Jul 21 07:39:14.689922 2026] [security2:error] [pid 255769:tid 255943] [client 20.226.60.151:51343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/min.php"] [unique_id "al9MUrxMYwyVGnfuwsKmEwAAA88"]
[Tue Jul 21 07:39:14.758979 2026] [security2:error] [pid 255769:tid 256013] [client 20.220.225.223:31190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/yup.php"] [unique_id "al9MUrxMYwyVGnfuwsKmFQAABBM"]
[Tue Jul 21 07:39:14.785989 2026] [autoindex:error] [pid 255769:tid 256000] [client 4.204.201.85:49883] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:14.908218 2026] [security2:error] [pid 255769:tid 255920] [client 103.174.34.15:63565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MUrxMYwyVGnfuwsKmFwAAA7g"]
[Tue Jul 21 07:39:14.908371 2026] [security2:error] [pid 255769:tid 255920] [client 103.174.34.15:63565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MUrxMYwyVGnfuwsKmFwAAA7g"]
[Tue Jul 21 07:39:14.989573 2026] [security2:error] [pid 254995:tid 255219] [client 59.96.220.140:64528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MUv7v0rlcEGmVraFI5wAAA3s"]
[Tue Jul 21 07:39:14.990189 2026] [security2:error] [pid 254995:tid 255219] [client 59.96.220.140:64528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MUv7v0rlcEGmVraFI5wAAA3s"]
[Tue Jul 21 07:39:15.060280 2026] [security2:error] [pid 255769:tid 255901] [client 4.204.201.85:49883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9MU7xMYwyVGnfuwsKmGwAAA6U"]
[Tue Jul 21 07:39:15.153264 2026] [security2:error] [pid 254995:tid 255279] [client 194.99.104.35:40318] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MU_7v0rlcEGmVraFI6wAAA50"]
[Tue Jul 21 07:39:15.153383 2026] [security2:error] [pid 254995:tid 255279] [client 194.99.104.35:40318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MU_7v0rlcEGmVraFI6wAAA50"]
[Tue Jul 21 07:39:15.254450 2026] [security2:error] [pid 255769:tid 255987] [client 193.36.225.69:36737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MU7xMYwyVGnfuwsKmHAAAA_s"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:15.385463 2026] [security2:error] [pid 255769:tid 255968] [client 20.151.10.161:45985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/f6.php"] [unique_id "al9MU7xMYwyVGnfuwsKmMQAAA-g"]
[Tue Jul 21 07:39:15.387671 2026] [autoindex:error] [pid 255769:tid 255963] [client 4.204.201.85:4503] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:15.546389 2026] [security2:error] [pid 255769:tid 255954] [client 20.226.60.151:27642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/users.php"] [unique_id "al9MU7xMYwyVGnfuwsKmNgAAA9o"]
[Tue Jul 21 07:39:15.548278 2026] [security2:error] [pid 254995:tid 255010] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MU_7v0rlcEGmVraFJVQADjg4"]
[Tue Jul 21 07:39:15.548413 2026] [security2:error] [pid 254995:tid 255264] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MU_7v0rlcEGmVraFJVQADjg4"]
[Tue Jul 21 07:39:15.685683 2026] [autoindex:error] [pid 255769:tid 256010] [client 4.204.201.85:4503] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:15.825946 2026] [security2:error] [pid 255769:tid 255958] [client 4.204.201.85:4503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-content/index.php"] [unique_id "al9MU7xMYwyVGnfuwsKmOgAAA94"]
[Tue Jul 21 07:39:15.825996 2026] [security2:error] [pid 255769:tid 255992] [client 20.226.60.151:61033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9MU7xMYwyVGnfuwsKmOwAAA_8"]
[Tue Jul 21 07:39:15.867739 2026] [security2:error] [pid 254995:tid 255225] [client 62.102.148.187:48566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MU_7v0rlcEGmVraFJWwAAA4E"]
[Tue Jul 21 07:39:15.867853 2026] [security2:error] [pid 254995:tid 255225] [client 62.102.148.187:48566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MU_7v0rlcEGmVraFJWwAAA4E"]
[Tue Jul 21 07:39:15.936463 2026] [security2:error] [pid 254995:tid 255196] [client 20.206.105.145:38140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-load.php"] [unique_id "al9MU_7v0rlcEGmVraFJXQAAA2U"]
[Tue Jul 21 07:39:15.950668 2026] [security2:error] [pid 255769:tid 255907] [client 193.36.225.152:33441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MU7xMYwyVGnfuwsKmPQAAA6s"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:16.150207 2026] [security2:error] [pid 255769:tid 255922] [client 4.204.201.85:4476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/admin.php"] [unique_id "al9MVLxMYwyVGnfuwsKmQAAAA7o"]
[Tue Jul 21 07:39:16.521268 2026] [security2:error] [pid 255769:tid 256013] [client 20.226.60.151:61232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9MVLxMYwyVGnfuwsKmRAAABBM"]
[Tue Jul 21 07:39:16.526655 2026] [security2:error] [pid 255769:tid 256000] [client 4.204.201.85:4486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/177.php"] [unique_id "al9MVLxMYwyVGnfuwsKmRQAABAY"]
[Tue Jul 21 07:39:16.551080 2026] [security2:error] [pid 254995:tid 255217] [client 20.220.225.223:31174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/jj.php"] [unique_id "al9MVP7v0rlcEGmVraFJbgAAA3k"]
[Tue Jul 21 07:39:16.726047 2026] [security2:error] [pid 255769:tid 256021] [client 139.167.225.182:53648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MVLxMYwyVGnfuwsKmSAAABBs"]
[Tue Jul 21 07:39:16.726237 2026] [security2:error] [pid 255769:tid 256021] [client 139.167.225.182:53648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MVLxMYwyVGnfuwsKmSAAABBs"]
[Tue Jul 21 07:39:16.875231 2026] [security2:error] [pid 254995:tid 255132] [client 4.204.201.85:49847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/199.php"] [unique_id "al9MVP7v0rlcEGmVraFJcwAAAyU"]
[Tue Jul 21 07:39:16.895922 2026] [security2:error] [pid 254995:tid 255206] [client 20.151.10.161:45904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/inputs.php"] [unique_id "al9MVP7v0rlcEGmVraFJdAAAA28"]
[Tue Jul 21 07:39:17.014176 2026] [security2:error] [pid 254995:tid 255178] [client 20.226.60.151:61205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9MVf7v0rlcEGmVraFJeQAAA1M"]
[Tue Jul 21 07:39:17.069482 2026] [security2:error] [pid 255769:tid 255935] [client 117.217.38.194:57000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MVbxMYwyVGnfuwsKmSQAAA8c"]
[Tue Jul 21 07:39:17.069839 2026] [security2:error] [pid 255769:tid 255935] [client 117.217.38.194:57000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MVbxMYwyVGnfuwsKmSQAAA8c"]
[Tue Jul 21 07:39:17.193559 2026] [security2:error] [pid 255769:tid 255920] [client 4.204.201.85:4427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/file52.php"] [unique_id "al9MVbxMYwyVGnfuwsKmSgAAA7g"]
[Tue Jul 21 07:39:17.199769 2026] [security2:error] [pid 255769:tid 255931] [client 20.226.60.151:51330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9MVbxMYwyVGnfuwsKmTAAAA8M"]
[Tue Jul 21 07:39:17.240196 2026] [security2:error] [pid 255769:tid 256004] [client 20.226.60.151:51371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/albin.php"] [unique_id "al9MVbxMYwyVGnfuwsKmTgAABAo"]
[Tue Jul 21 07:39:17.303864 2026] [security2:error] [pid 255769:tid 255987] [client 20.226.60.151:61233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/cilus.php"] [unique_id "al9MVbxMYwyVGnfuwsKmTwAAA_s"]
[Tue Jul 21 07:39:17.403903 2026] [security2:error] [pid 255769:tid 256014] [client 20.226.60.151:55347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/gptsh.php"] [unique_id "al9MVbxMYwyVGnfuwsKmUQAABBQ"]
[Tue Jul 21 07:39:17.489895 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:51391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/rithin.php"] [unique_id "al9MVbxMYwyVGnfuwsKmUwAAA_4"]
[Tue Jul 21 07:39:17.565229 2026] [security2:error] [pid 254995:tid 255160] [client 4.204.201.85:49894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/geck.php"] [unique_id "al9MVf7v0rlcEGmVraFJggAAA0E"]
[Tue Jul 21 07:39:17.755087 2026] [security2:error] [pid 254995:tid 255193] [client 20.226.60.151:51290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/fffm.php"] [unique_id "al9MVf7v0rlcEGmVraFJiwAAA2I"]
[Tue Jul 21 07:39:17.852662 2026] [security2:error] [pid 255769:tid 255902] [client 4.204.201.85:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/biufile.php"] [unique_id "al9MVbxMYwyVGnfuwsKmVAAAA6Y"]
[Tue Jul 21 07:39:17.896435 2026] [security2:error] [pid 255769:tid 256017] [client 20.226.60.151:51312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/dfre.php"] [unique_id "al9MVbxMYwyVGnfuwsKmVQAABBc"]
[Tue Jul 21 07:39:17.902139 2026] [security2:error] [pid 254995:tid 255254] [client 20.151.10.161:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/av.php"] [unique_id "al9MVf7v0rlcEGmVraFJjgAAA4Q"]
[Tue Jul 21 07:39:17.956994 2026] [security2:error] [pid 255769:tid 255872] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MVbxMYwyVGnfuwsKmVgADrWY"]
[Tue Jul 21 07:39:17.957171 2026] [security2:error] [pid 255769:tid 255909] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MVbxMYwyVGnfuwsKmVgADrWY"]
[Tue Jul 21 07:39:17.970340 2026] [security2:error] [pid 255769:tid 255981] [client 20.206.105.145:38114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/xwpg.php"] [unique_id "al9MVbxMYwyVGnfuwsKmVwAAA_U"]
[Tue Jul 21 07:39:18.173446 2026] [security2:error] [pid 255769:tid 255959] [client 4.204.201.85:4488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/mosty.php"] [unique_id "al9MVrxMYwyVGnfuwsKmWwAAA98"]
[Tue Jul 21 07:39:18.218234 2026] [security2:error] [pid 255769:tid 255946] [client 20.226.60.151:27531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/177.php"] [unique_id "al9MVrxMYwyVGnfuwsKmXgAAA9I"]
[Tue Jul 21 07:39:18.257872 2026] [security2:error] [pid 255769:tid 255907] [client 20.226.60.151:61012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-happy.php"] [unique_id "al9MVrxMYwyVGnfuwsKmXwAAA6s"]
[Tue Jul 21 07:39:18.358687 2026] [security2:error] [pid 254995:tid 255221] [client 20.226.60.151:56211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wpx.php"] [unique_id "al9MVv7v0rlcEGmVraFJlAAAA30"]
[Tue Jul 21 07:39:18.491287 2026] [security2:error] [pid 254995:tid 255225] [client 4.204.201.85:4442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/dejavu.php"] [unique_id "al9MVv7v0rlcEGmVraFJlwAAA4E"]
[Tue Jul 21 07:39:18.517995 2026] [security2:error] [pid 255769:tid 255957] [client 20.197.195.24:13167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MVrxMYwyVGnfuwsKmYQAAA90"]
[Tue Jul 21 07:39:18.532176 2026] [security2:error] [pid 254995:tid 255266] [client 106.215.181.8:29618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MVv7v0rlcEGmVraFJmAAAA5A"]
[Tue Jul 21 07:39:18.532341 2026] [security2:error] [pid 254995:tid 255266] [client 106.215.181.8:29618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MVv7v0rlcEGmVraFJmAAAA5A"]
[Tue Jul 21 07:39:18.533168 2026] [security2:error] [pid 255769:tid 256005] [client 20.197.192.193:6860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/hp3.php"] [unique_id "al9MVrxMYwyVGnfuwsKmYgAABAs"]
[Tue Jul 21 07:39:18.607278 2026] [security2:error] [pid 255769:tid 256013] [client 20.226.60.151:55300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/fpr4.php"] [unique_id "al9MVrxMYwyVGnfuwsKmYwAABBM"]
[Tue Jul 21 07:39:18.887449 2026] [security2:error] [pid 255769:tid 255939] [client 173.24.185.52:61544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MVrxMYwyVGnfuwsKmaQAAA8s"]
[Tue Jul 21 07:39:18.887588 2026] [security2:error] [pid 255769:tid 255939] [client 173.24.185.52:61544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MVrxMYwyVGnfuwsKmaQAAA8s"]
[Tue Jul 21 07:39:18.941961 2026] [security2:error] [pid 254995:tid 255209] [client 117.132.188.205:32974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/produtos-higiene.php"] [unique_id "al9MVv7v0rlcEGmVraFJngAAA3E"]
[Tue Jul 21 07:39:18.971882 2026] [security2:error] [pid 254995:tid 255272] [client 4.204.201.85:4506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/aaf.php"] [unique_id "al9MVv7v0rlcEGmVraFJoAAAA5Y"]
[Tue Jul 21 07:39:18.987561 2026] [security2:error] [pid 255769:tid 255987] [client 20.226.60.151:61038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file88.php"] [unique_id "al9MVrxMYwyVGnfuwsKmagAAA_s"]
[Tue Jul 21 07:39:19.036258 2026] [security2:error] [pid 254995:tid 255277] [client 136.144.33.29:39051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MV_7v0rlcEGmVraFJpAAAA5s"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:19.339616 2026] [security2:error] [pid 255769:tid 255941] [client 4.204.201.85:49797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ha.php"] [unique_id "al9MV7xMYwyVGnfuwsKmcAAAA80"]
[Tue Jul 21 07:39:19.591420 2026] [security2:error] [pid 255769:tid 256003] [client 184.75.223.211:40304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MV7xMYwyVGnfuwsKmdAAABAk"]
[Tue Jul 21 07:39:19.591542 2026] [security2:error] [pid 255769:tid 256003] [client 184.75.223.211:40304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MV7xMYwyVGnfuwsKmdAAABAk"]
[Tue Jul 21 07:39:19.620678 2026] [security2:error] [pid 254995:tid 255164] [client 20.226.60.151:61189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ccc.php"] [unique_id "al9MV_7v0rlcEGmVraFJtAAAA0U"]
[Tue Jul 21 07:39:19.665126 2026] [security2:error] [pid 255769:tid 255902] [client 4.204.201.85:4527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/hur.php"] [unique_id "al9MV7xMYwyVGnfuwsKmdgAAA6Y"]
[Tue Jul 21 07:39:19.737347 2026] [security2:error] [pid 255769:tid 255919] [client 20.197.195.24:13145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MV7xMYwyVGnfuwsKmeQAAA7c"]
[Tue Jul 21 07:39:19.838340 2026] [security2:error] [pid 255769:tid 255956] [client 193.36.225.105:47497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MV7xMYwyVGnfuwsKmewAAA9w"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:19.903927 2026] [security2:error] [pid 254995:tid 255199] [client 20.226.60.151:51294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/777.php"] [unique_id "al9MV_7v0rlcEGmVraFJvgAAA2g"]
[Tue Jul 21 07:39:19.949878 2026] [security2:error] [pid 255769:tid 255979] [client 4.204.201.85:49856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/h02ugyh.php"] [unique_id "al9MV7xMYwyVGnfuwsKmfAAAA_M"]
[Tue Jul 21 07:39:20.044792 2026] [security2:error] [pid 255769:tid 255967] [client 20.226.60.151:27633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/config.php"] [unique_id "al9MWLxMYwyVGnfuwsKmfQAAA-c"]
[Tue Jul 21 07:39:20.102477 2026] [security2:error] [pid 255769:tid 255976] [client 20.197.192.193:6891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/aa1.php"] [unique_id "al9MWLxMYwyVGnfuwsKmfgAAA_A"]
[Tue Jul 21 07:39:20.266142 2026] [security2:error] [pid 255769:tid 255992] [client 4.204.201.85:4530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/155.php"] [unique_id "al9MWLxMYwyVGnfuwsKmgAAAA_8"]
[Tue Jul 21 07:39:20.281306 2026] [security2:error] [pid 255769:tid 255960] [client 122.186.204.214:62803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmgQAAA-A"]
[Tue Jul 21 07:39:20.281447 2026] [security2:error] [pid 255769:tid 255960] [client 122.186.204.214:62803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmgQAAA-A"]
[Tue Jul 21 07:39:20.368616 2026] [security2:error] [pid 255769:tid 255927] [client 20.220.225.223:38668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/dragonshell.php"] [unique_id "al9MWLxMYwyVGnfuwsKmhAAAA78"]
[Tue Jul 21 07:39:20.376470 2026] [security2:error] [pid 254995:tid 255160] [client 20.151.10.161:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/classwithtostring.php"] [unique_id "al9MWP7v0rlcEGmVraFJyQAAA0E"]
[Tue Jul 21 07:39:20.442880 2026] [security2:error] [pid 255769:tid 255999] [client 20.226.60.151:61011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/for.php"] [unique_id "al9MWLxMYwyVGnfuwsKmhQAABAU"]
[Tue Jul 21 07:39:20.574227 2026] [security2:error] [pid 255769:tid 255982] [client 20.226.60.151:27598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/gettest.php"] [unique_id "al9MWLxMYwyVGnfuwsKmhgAAA_Y"]
[Tue Jul 21 07:39:20.577466 2026] [security2:error] [pid 254995:tid 255157] [client 4.204.201.85:56660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/pp.php"] [unique_id "al9MWP7v0rlcEGmVraFJzAAAAz4"]
[Tue Jul 21 07:39:20.617032 2026] [security2:error] [pid 255769:tid 255965] [client 117.251.86.144:33500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmhwAAA-U"]
[Tue Jul 21 07:39:20.617165 2026] [security2:error] [pid 255769:tid 255965] [client 117.251.86.144:33500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmhwAAA-U"]
[Tue Jul 21 07:39:20.631626 2026] [security2:error] [pid 254995:tid 255140] [client 20.197.195.24:13084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/media.php"] [unique_id "al9MWP7v0rlcEGmVraFJzgAAAy0"]
[Tue Jul 21 07:39:20.667399 2026] [security2:error] [pid 255769:tid 255858] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmiAADq1g"]
[Tue Jul 21 07:39:20.667582 2026] [security2:error] [pid 255769:tid 255907] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmiAADq1g"]
[Tue Jul 21 07:39:20.790623 2026] [security2:error] [pid 255769:tid 256013] [client 20.220.225.223:31192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/wp-mt.php"] [unique_id "al9MWLxMYwyVGnfuwsKmigAABBM"]
[Tue Jul 21 07:39:20.791430 2026] [security2:error] [pid 255769:tid 255909] [client 152.59.154.239:62233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmiwAAA60"]
[Tue Jul 21 07:39:20.791567 2026] [security2:error] [pid 255769:tid 255909] [client 152.59.154.239:62233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmiwAAA60"]
[Tue Jul 21 07:39:20.791618 2026] [security2:error] [pid 255769:tid 255788] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmjAADuhI"]
[Tue Jul 21 07:39:20.791737 2026] [security2:error] [pid 255769:tid 255922] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWLxMYwyVGnfuwsKmjAADuhI"]
[Tue Jul 21 07:39:20.861513 2026] [security2:error] [pid 254995:tid 255149] [client 4.204.201.85:49858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ops.php"] [unique_id "al9MWP7v0rlcEGmVraFJ0gAAAzY"]
[Tue Jul 21 07:39:21.026611 2026] [security2:error] [pid 255769:tid 255935] [client 20.226.60.151:27350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/min.php"] [unique_id "al9MWbxMYwyVGnfuwsKmkAAAA8c"]
[Tue Jul 21 07:39:21.115389 2026] [security2:error] [pid 254995:tid 255193] [client 117.132.188.205:32975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/produtos-fast.php"] [unique_id "al9MWf7v0rlcEGmVraFJ1wAAA2I"]
[Tue Jul 21 07:39:21.130409 2026] [security2:error] [pid 255769:tid 255908] [client 20.226.60.151:27386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/dvjul.php"] [unique_id "al9MWbxMYwyVGnfuwsKmkQAAA6w"]
[Tue Jul 21 07:39:21.157903 2026] [security2:error] [pid 254995:tid 255264] [client 20.226.60.151:27529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/biufile.php"] [unique_id "al9MWf7v0rlcEGmVraFJ2AAAA44"]
[Tue Jul 21 07:39:21.159925 2026] [security2:error] [pid 255769:tid 255901] [client 4.204.201.85:21759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ingfo.php"] [unique_id "al9MWbxMYwyVGnfuwsKmkgAAA6U"]
[Tue Jul 21 07:39:21.207983 2026] [autoindex:error] [pid 255769:tid 255934] [client 20.206.105.145:38511] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:21.272300 2026] [autoindex:error] [pid 255769:tid 255996] [client 20.206.105.145:38511] AH01276: Cannot serve directory /home2/acupu265/public_html/liranesuliano.com.br/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:21.278254 2026] [security2:error] [pid 255769:tid 255921] [client 20.206.105.145:38511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/waf.php"] [unique_id "al9MWbxMYwyVGnfuwsKmlwAAA7k"]
[Tue Jul 21 07:39:21.400773 2026] [security2:error] [pid 255769:tid 256014] [client 20.197.195.24:13133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/images.php"] [unique_id "al9MWbxMYwyVGnfuwsKmmAAABBQ"]
[Tue Jul 21 07:39:21.438489 2026] [security2:error] [pid 254995:tid 255185] [client 4.204.201.85:49835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/error_log.php"] [unique_id "al9MWf7v0rlcEGmVraFJ3wAAA1o"]
[Tue Jul 21 07:39:21.662698 2026] [security2:error] [pid 254995:tid 255004] [remote 45.79.123.44:46224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9MWf7v0rlcEGmVraFJ4gADnQg"]
[Tue Jul 21 07:39:21.713871 2026] [security2:error] [pid 254995:tid 255209] [client 74.7.244.16:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "maikikaufmann1781880068561.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9MWf7v0rlcEGmVraFJ5AADcVs"]
[Tue Jul 21 07:39:21.716634 2026] [security2:error] [pid 255769:tid 255953] [client 4.204.201.85:49841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/test10.php"] [unique_id "al9MWbxMYwyVGnfuwsKmmwAAA9k"]
[Tue Jul 21 07:39:21.847046 2026] [security2:error] [pid 255769:tid 255978] [client 20.226.60.151:56235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-css.php"] [unique_id "al9MWbxMYwyVGnfuwsKmnQAAA_I"]
[Tue Jul 21 07:39:21.914274 2026] [security2:error] [pid 255769:tid 255928] [client 20.151.10.161:46075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9MWbxMYwyVGnfuwsKmngAAA8A"]
[Tue Jul 21 07:39:21.930935 2026] [security2:error] [pid 255769:tid 255918] [client 20.226.60.151:27533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/av.php"] [unique_id "al9MWbxMYwyVGnfuwsKmoQAAA7Y"]
[Tue Jul 21 07:39:21.968590 2026] [security2:error] [pid 255769:tid 255919] [client 20.226.60.151:51366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ssla.php"] [unique_id "al9MWbxMYwyVGnfuwsKmogAAA7c"]
[Tue Jul 21 07:39:22.004920 2026] [security2:error] [pid 255769:tid 255988] [client 4.204.201.85:4540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/koala.php"] [unique_id "al9MWrxMYwyVGnfuwsKmowAAA_w"]
[Tue Jul 21 07:39:22.242819 2026] [security2:error] [pid 255769:tid 255910] [client 117.132.188.205:32976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/produtos-confeitaria.php"] [unique_id "al9MWrxMYwyVGnfuwsKmpAAAA64"]
[Tue Jul 21 07:39:22.274848 2026] [security2:error] [pid 255769:tid 255973] [client 20.197.195.24:13166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/gecko.php"] [unique_id "al9MWrxMYwyVGnfuwsKmpQAAA-0"]
[Tue Jul 21 07:39:22.282713 2026] [security2:error] [pid 254995:tid 255192] [client 4.204.201.85:49895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/mac.php"] [unique_id "al9MWv7v0rlcEGmVraFJ7wAAA2E"]
[Tue Jul 21 07:39:22.426782 2026] [autoindex:error] [pid 255769:tid 255983] [client 85.204.70.114:48888] AH01276: Cannot serve directory /home1/guiiaz25/werneckepereiraadvogados.guiiaz.com.br/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:22.493865 2026] [security2:error] [pid 255769:tid 255990] [client 154.192.233.199:58603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWrxMYwyVGnfuwsKmqQAAA_4"]
[Tue Jul 21 07:39:22.494000 2026] [security2:error] [pid 255769:tid 255990] [client 154.192.233.199:58603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWrxMYwyVGnfuwsKmqQAAA_4"]
[Tue Jul 21 07:39:22.563269 2026] [security2:error] [pid 254995:tid 255184] [client 4.204.201.85:4529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wefile.php"] [unique_id "al9MWv7v0rlcEGmVraFJ9QAAA1k"]
[Tue Jul 21 07:39:22.611631 2026] [security2:error] [pid 254995:tid 255176] [client 122.164.127.47:60027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MWv7v0rlcEGmVraFJ9wAAA1E"]
[Tue Jul 21 07:39:22.611741 2026] [security2:error] [pid 254995:tid 255176] [client 122.164.127.47:60027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MWv7v0rlcEGmVraFJ9wAAA1E"]
[Tue Jul 21 07:39:22.649132 2026] [security2:error] [pid 254995:tid 255178] [client 128.127.105.184:35676] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MWv7v0rlcEGmVraFJ-AAAA1M"]
[Tue Jul 21 07:39:22.649226 2026] [security2:error] [pid 254995:tid 255178] [client 128.127.105.184:35676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MWv7v0rlcEGmVraFJ-AAAA1M"]
[Tue Jul 21 07:39:22.687398 2026] [security2:error] [pid 254995:tid 255199] [client 20.226.60.151:27590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/coffexium.php"] [unique_id "al9MWv7v0rlcEGmVraFJ-gAAA2g"]
[Tue Jul 21 07:39:22.857986 2026] [autoindex:error] [pid 254995:tid 255195] [client 4.204.201.85:4536] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:22.875045 2026] [security2:error] [pid 255769:tid 255968] [client 175.45.70.82:51704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWrxMYwyVGnfuwsKmrAAAA-g"]
[Tue Jul 21 07:39:22.875152 2026] [security2:error] [pid 255769:tid 255968] [client 175.45.70.82:51704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MWrxMYwyVGnfuwsKmrAAAA-g"]
[Tue Jul 21 07:39:22.922486 2026] [security2:error] [pid 254995:tid 255162] [client 136.144.33.99:26145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MWv7v0rlcEGmVraFKAAAAA0M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:23.046872 2026] [security2:error] [pid 254995:tid 255200] [client 20.226.60.151:27589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/core.php"] [unique_id "al9MW_7v0rlcEGmVraFKBAAAA2k"]
[Tue Jul 21 07:39:23.118153 2026] [security2:error] [pid 254995:tid 255019] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKBgADexc"]
[Tue Jul 21 07:39:23.118360 2026] [security2:error] [pid 254995:tid 255219] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKBgADexc"]
[Tue Jul 21 07:39:23.163320 2026] [security2:error] [pid 254995:tid 255187] [client 122.162.144.145:32578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKCQAAA1w"]
[Tue Jul 21 07:39:23.163462 2026] [security2:error] [pid 254995:tid 255187] [client 122.162.144.145:32578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKCQAAA1w"]
[Tue Jul 21 07:39:23.163870 2026] [security2:error] [pid 254995:tid 255175] [client 20.220.225.223:34260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MW_7v0rlcEGmVraFKCgAAA1A"]
[Tue Jul 21 07:39:23.181314 2026] [autoindex:error] [pid 254995:tid 255148] [client 4.204.201.85:4536] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:23.184418 2026] [security2:error] [pid 254995:tid 255260] [client 20.197.195.24:13179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/82.php"] [unique_id "al9MW_7v0rlcEGmVraFKCwAAA4o"]
[Tue Jul 21 07:39:23.233302 2026] [security2:error] [pid 254995:tid 255276] [client 103.106.20.201:58108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKDQAAA5o"]
[Tue Jul 21 07:39:23.233991 2026] [security2:error] [pid 254995:tid 255276] [client 103.106.20.201:58108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKDQAAA5o"]
[Tue Jul 21 07:39:23.239094 2026] [security2:error] [pid 254995:tid 255088] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKDgADLVw"]
[Tue Jul 21 07:39:23.239299 2026] [security2:error] [pid 254995:tid 255140] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MW_7v0rlcEGmVraFKDgADLVw"]
[Tue Jul 21 07:39:23.251404 2026] [security2:error] [pid 254995:tid 255045] [remote 41.186.86.12:1565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.site"] [uri "/wp-login.php"] [unique_id "al9MW_7v0rlcEGmVraFKDwADYDE"]
[Tue Jul 21 07:39:23.320431 2026] [security2:error] [pid 254995:tid 255179] [client 4.204.201.85:4536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/makeasmtp.php"] [unique_id "al9MW_7v0rlcEGmVraFKEwAAA1Q"]
[Tue Jul 21 07:39:23.336866 2026] [security2:error] [pid 255769:tid 255984] [client 20.226.60.151:61215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/zc-131.php"] [unique_id "al9MW7xMYwyVGnfuwsKmsgAAA_g"]
[Tue Jul 21 07:39:23.388254 2026] [security2:error] [pid 254995:tid 255151] [client 117.132.188.205:32977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/produtos-oriental.php"] [unique_id "al9MW_7v0rlcEGmVraFKFAAAAzg"]
[Tue Jul 21 07:39:23.431128 2026] [security2:error] [pid 255769:tid 255943] [client 20.226.60.151:27552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/als.php"] [unique_id "al9MW7xMYwyVGnfuwsKmtQAAA88"]
[Tue Jul 21 07:39:23.448652 2026] [security2:error] [pid 254995:tid 255193] [client 20.151.10.161:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-blog.php"] [unique_id "al9MW_7v0rlcEGmVraFKFgAAA2I"]
[Tue Jul 21 07:39:23.604020 2026] [security2:error] [pid 255769:tid 255962] [client 4.204.201.85:4507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/2P.php"] [unique_id "al9MW7xMYwyVGnfuwsKmuAAAA-I"]
[Tue Jul 21 07:39:23.803183 2026] [security2:error] [pid 254995:tid 255208] [client 20.226.60.151:9360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/simple.php"] [unique_id "al9MW_7v0rlcEGmVraFKGAAAA3A"]
[Tue Jul 21 07:39:23.896997 2026] [security2:error] [pid 255769:tid 255923] [client 4.204.201.85:49890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/.well-known/about.php"] [unique_id "al9MW7xMYwyVGnfuwsKmvAAAA7s"]
[Tue Jul 21 07:39:24.012801 2026] [autoindex:error] [pid 255769:tid 255939] [client 147.185.132.171:57906] AH01276: Cannot serve directory /home2/supr7264/monalizacleaning.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:24.020190 2026] [security2:error] [pid 255769:tid 255974] [client 20.226.60.151:27334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/init.php"] [unique_id "al9MXLxMYwyVGnfuwsKmwAAAA-4"]
[Tue Jul 21 07:39:24.027299 2026] [security2:error] [pid 255769:tid 255987] [client 20.197.195.24:13152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/admin.php"] [unique_id "al9MXLxMYwyVGnfuwsKmwQAAA_s"]
[Tue Jul 21 07:39:24.179419 2026] [security2:error] [pid 255769:tid 255970] [client 4.204.201.85:49843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9MXLxMYwyVGnfuwsKmxAAAA-o"]
[Tue Jul 21 07:39:24.420201 2026] [security2:error] [pid 255769:tid 255918] [client 20.220.225.223:38656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/ww.php"] [unique_id "al9MXLxMYwyVGnfuwsKmyAAAA7Y"]
[Tue Jul 21 07:39:24.470589 2026] [security2:error] [pid 255769:tid 255899] [client 4.204.201.85:49819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/system_log.php"] [unique_id "al9MXLxMYwyVGnfuwsKmyQAAA6M"]
[Tue Jul 21 07:39:24.535552 2026] [security2:error] [pid 255769:tid 256014] [client 117.132.188.205:32978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/faleconosco.php"] [unique_id "al9MXLxMYwyVGnfuwsKmygAABBQ"]
[Tue Jul 21 07:39:24.554699 2026] [security2:error] [pid 255769:tid 255980] [client 20.206.105.145:38133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/xstelth.php"] [unique_id "al9MXLxMYwyVGnfuwsKmywAAA_Q"]
[Tue Jul 21 07:39:24.576544 2026] [security2:error] [pid 254995:tid 255147] [client 20.226.60.151:27615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/fpwch.php"] [unique_id "al9MXP7v0rlcEGmVraFKJAAAAzQ"]
[Tue Jul 21 07:39:24.590932 2026] [security2:error] [pid 255769:tid 255936] [client 20.197.195.24:13172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/adminner.php"] [unique_id "al9MXLxMYwyVGnfuwsKmzAAAA8g"]
[Tue Jul 21 07:39:24.637986 2026] [security2:error] [pid 255769:tid 255912] [client 20.197.195.24:13071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/admin.php"] [unique_id "al9MXLxMYwyVGnfuwsKmzgAAA7A"]
[Tue Jul 21 07:39:24.686693 2026] [security2:error] [pid 255769:tid 255988] [client 20.197.195.24:13122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/k.php"] [unique_id "al9MXLxMYwyVGnfuwsKmzwAAA_w"]
[Tue Jul 21 07:39:24.731217 2026] [security2:error] [pid 255769:tid 255951] [client 20.197.195.24:13151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/blurbs.php"] [unique_id "al9MXLxMYwyVGnfuwsKm0AAAA9c"]
[Tue Jul 21 07:39:24.755749 2026] [security2:error] [pid 255769:tid 255950] [client 103.86.117.203:59855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MXLxMYwyVGnfuwsKm0gAAA9Y"]
[Tue Jul 21 07:39:24.755900 2026] [security2:error] [pid 255769:tid 255950] [client 103.86.117.203:59855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MXLxMYwyVGnfuwsKm0gAAA9Y"]
[Tue Jul 21 07:39:24.770200 2026] [security2:error] [pid 255769:tid 255983] [client 20.220.225.223:31885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/dr.php"] [unique_id "al9MXLxMYwyVGnfuwsKm0wAAA_c"]
[Tue Jul 21 07:39:24.801393 2026] [autoindex:error] [pid 255769:tid 255973] [client 4.204.201.85:4519] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:24.900157 2026] [security2:error] [pid 255769:tid 255889] [remote 124.55.178.99:59622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9MXLxMYwyVGnfuwsKm2wAD8nc"]
[Tue Jul 21 07:39:24.960895 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:9347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/domvf.php"] [unique_id "al9MXP7v0rlcEGmVraFKLwAAA5k"]
[Tue Jul 21 07:39:25.001989 2026] [security2:error] [pid 255769:tid 255927] [client 20.197.195.24:13180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/bajah.php"] [unique_id "al9MXbxMYwyVGnfuwsKm3AAAA78"]
[Tue Jul 21 07:39:25.130729 2026] [autoindex:error] [pid 255769:tid 255999] [client 4.204.201.85:4519] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:25.269038 2026] [security2:error] [pid 255769:tid 256025] [client 4.204.201.85:4519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/crgio.php"] [unique_id "al9MXbxMYwyVGnfuwsKm4AAABB8"]
[Tue Jul 21 07:39:25.269663 2026] [security2:error] [pid 255769:tid 255833] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MXbxMYwyVGnfuwsKm4QADpz8"]
[Tue Jul 21 07:39:25.269781 2026] [security2:error] [pid 255769:tid 255903] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MXbxMYwyVGnfuwsKm4QADpz8"]
[Tue Jul 21 07:39:25.279917 2026] [security2:error] [pid 255769:tid 255957] [client 20.197.195.24:13082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/a.php"] [unique_id "al9MXbxMYwyVGnfuwsKm4gAAA90"]
[Tue Jul 21 07:39:25.288134 2026] [security2:error] [pid 255769:tid 256019] [client 20.226.60.151:27342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp.php"] [unique_id "al9MXbxMYwyVGnfuwsKm4wAABBk"]
[Tue Jul 21 07:39:25.562446 2026] [security2:error] [pid 254995:tid 255192] [client 103.174.34.15:64255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MXf7v0rlcEGmVraFKOgAAA2E"]
[Tue Jul 21 07:39:25.562580 2026] [security2:error] [pid 254995:tid 255192] [client 103.174.34.15:64255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MXf7v0rlcEGmVraFKOgAAA2E"]
[Tue Jul 21 07:39:25.574447 2026] [security2:error] [pid 255769:tid 255985] [client 4.204.201.85:49862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/pucci.php"] [unique_id "al9MXbxMYwyVGnfuwsKm5QAAA_k"]
[Tue Jul 21 07:39:25.597223 2026] [security2:error] [pid 254995:tid 255270] [client 20.226.60.151:27343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/class.php"] [unique_id "al9MXf7v0rlcEGmVraFKOwAAA5Q"]
[Tue Jul 21 07:39:25.623159 2026] [security2:error] [pid 254995:tid 255162] [client 20.206.105.145:38111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-links.php"] [unique_id "al9MXf7v0rlcEGmVraFKQAAAA0M"]
[Tue Jul 21 07:39:25.706066 2026] [security2:error] [pid 254995:tid 255206] [client 117.132.188.205:32979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/eventos.php"] [unique_id "al9MXf7v0rlcEGmVraFKQQAAA28"]
[Tue Jul 21 07:39:25.820491 2026] [security2:error] [pid 255769:tid 256009] [client 20.197.192.193:6879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/acew67.php"] [unique_id "al9MXbxMYwyVGnfuwsKm5wAABA8"]
[Tue Jul 21 07:39:25.866132 2026] [autoindex:error] [pid 255769:tid 255904] [client 4.204.201.85:4424] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:25.898487 2026] [security2:error] [pid 254995:tid 255182] [client 20.197.195.24:13141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/edit.php"] [unique_id "al9MXf7v0rlcEGmVraFKQwAAA1c"]
[Tue Jul 21 07:39:26.118668 2026] [security2:error] [pid 255769:tid 255947] [client 20.220.225.223:34261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MXrxMYwyVGnfuwsKm7AAAA9M"]
[Tue Jul 21 07:39:26.151339 2026] [autoindex:error] [pid 255769:tid 255953] [client 4.204.201.85:4424] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:26.169454 2026] [security2:error] [pid 254995:tid 255212] [client 20.151.10.161:46029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MXv7v0rlcEGmVraFKSgAAA3Q"]
[Tue Jul 21 07:39:26.210923 2026] [security2:error] [pid 255769:tid 255842] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MXrxMYwyVGnfuwsKm8AADzEg"]
[Tue Jul 21 07:39:26.211104 2026] [security2:error] [pid 255769:tid 255940] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MXrxMYwyVGnfuwsKm8AADzEg"]
[Tue Jul 21 07:39:26.214946 2026] [security2:error] [pid 255769:tid 255970] [client 20.197.195.24:13072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/hosty.php"] [unique_id "al9MXrxMYwyVGnfuwsKm8QAAA-o"]
[Tue Jul 21 07:39:26.264736 2026] [security2:error] [pid 254995:tid 255191] [client 20.226.60.151:56314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ho.php"] [unique_id "al9MXv7v0rlcEGmVraFKTQAAA2A"]
[Tue Jul 21 07:39:26.272309 2026] [security2:error] [pid 254995:tid 255158] [client 20.220.225.223:31188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/cron.php"] [unique_id "al9MXv7v0rlcEGmVraFKTgAAAz8"]
[Tue Jul 21 07:39:26.289384 2026] [security2:error] [pid 255769:tid 255944] [client 4.204.201.85:4424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-temp.php"] [unique_id "al9MXrxMYwyVGnfuwsKm8wAAA9A"]
[Tue Jul 21 07:39:26.334761 2026] [security2:error] [pid 254995:tid 255179] [client 20.226.60.151:27566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/echkm.php"] [unique_id "al9MXv7v0rlcEGmVraFKTwAAA1Q"]
[Tue Jul 21 07:39:26.421263 2026] [security2:error] [pid 255769:tid 255823] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MXrxMYwyVGnfuwsKm9QAEFDU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:26.421263 2026] [security2:error] [pid 254995:tid 255037] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MXv7v0rlcEGmVraFKUAADiSk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:26.545649 2026] [security2:error] [pid 255769:tid 255790] [remote 90.148.142.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.142.148.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MXrxMYwyVGnfuwsKm9wADoxQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:26.576362 2026] [security2:error] [pid 255769:tid 255981] [client 4.204.201.85:49839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9MXrxMYwyVGnfuwsKm-AAAA_U"]
[Tue Jul 21 07:39:26.643764 2026] [security2:error] [pid 254995:tid 255150] [client 20.197.192.193:6892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/bscclapb.php"] [unique_id "al9MXv7v0rlcEGmVraFKVwAAAzc"]
[Tue Jul 21 07:39:26.667904 2026] [security2:error] [pid 254995:tid 255047] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MXv7v0rlcEGmVraFKWgADSjM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:26.676703 2026] [security2:error] [pid 255769:tid 255773] [remote 188.49.170.205:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.170.49.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MXrxMYwyVGnfuwsKm-gADsAM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:26.804405 2026] [security2:error] [pid 254995:tid 255126] [client 193.36.225.11:44439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MXv7v0rlcEGmVraFKVQAAAx8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:26.863202 2026] [security2:error] [pid 255769:tid 255959] [client 20.197.195.24:13182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/k.php"] [unique_id "al9MXrxMYwyVGnfuwsKm-wAAA98"]
[Tue Jul 21 07:39:26.864792 2026] [security2:error] [pid 255769:tid 256010] [client 4.204.201.85:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/puc.php"] [unique_id "al9MXrxMYwyVGnfuwsKm_AAABBA"]
[Tue Jul 21 07:39:26.884489 2026] [security2:error] [pid 255769:tid 255902] [client 117.132.188.205:32980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/produtos-mercado.php"] [unique_id "al9MXrxMYwyVGnfuwsKm_QAAA6Y"]
[Tue Jul 21 07:39:26.918040 2026] [security2:error] [pid 255769:tid 255878] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MXrxMYwyVGnfuwsKm_gAD1mw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:26.961712 2026] [security2:error] [pid 255769:tid 255978] [client 20.206.105.145:38482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9MXrxMYwyVGnfuwsKnAgAAA_I"]
[Tue Jul 21 07:39:26.971309 2026] [security2:error] [pid 255769:tid 255771] [remote 188.49.170.205:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.170.49.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MXrxMYwyVGnfuwsKnAwAD_wE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:26.976673 2026] [security2:error] [pid 255769:tid 255924] [client 20.220.225.223:31708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/2x.php"] [unique_id "al9MXrxMYwyVGnfuwsKnBAAAA7w"]
[Tue Jul 21 07:39:27.045767 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.195.24:13120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/aaa.php"] [unique_id "al9MX7xMYwyVGnfuwsKnCAAABAU"]
[Tue Jul 21 07:39:27.098194 2026] [security2:error] [pid 255769:tid 255967] [client 59.96.220.140:64912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MX7xMYwyVGnfuwsKnCQAAA-c"]
[Tue Jul 21 07:39:27.098306 2026] [security2:error] [pid 255769:tid 255967] [client 59.96.220.140:64912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MX7xMYwyVGnfuwsKnCQAAA-c"]
[Tue Jul 21 07:39:27.133241 2026] [security2:error] [pid 254995:tid 255107] [remote 90.148.142.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.142.148.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MX_7v0rlcEGmVraFKYQADR28"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:27.161883 2026] [security2:error] [pid 255769:tid 255869] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MX7xMYwyVGnfuwsKnCgAD5WM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:27.164030 2026] [security2:error] [pid 255769:tid 255903] [client 4.204.201.85:4512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/dx.php"] [unique_id "al9MX7xMYwyVGnfuwsKnCwAAA6c"]
[Tue Jul 21 07:39:27.180172 2026] [security2:error] [pid 255769:tid 255957] [client 20.226.60.151:27577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/lib.php"] [unique_id "al9MX7xMYwyVGnfuwsKnDAAAA90"]
[Tue Jul 21 07:39:27.188993 2026] [security2:error] [pid 255769:tid 255844] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MX7xMYwyVGnfuwsKnDQAEGUo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:27.203723 2026] [security2:error] [pid 255769:tid 255943] [client 20.220.225.223:34197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/dp.php"] [unique_id "al9MX7xMYwyVGnfuwsKnDwAAA88"]
[Tue Jul 21 07:39:27.211675 2026] [security2:error] [pid 255769:tid 255909] [client 20.197.195.24:13074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/file5.php"] [unique_id "al9MX7xMYwyVGnfuwsKnEAAAA60"]
[Tue Jul 21 07:39:27.223591 2026] [core:error] [pid 255769:tid 255882] [remote 52.167.144.232:64833] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:39:27.223606 2026] [core:error] [pid 255769:tid 255882] [remote 52.167.144.232:64833] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:39:27.261673 2026] [security2:error] [pid 254995:tid 255145] [client 20.220.225.223:31173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/xxx.php"] [unique_id "al9MX_7v0rlcEGmVraFKZwAAAzI"]
[Tue Jul 21 07:39:27.366727 2026] [rewrite:warn] [pid 255769:tid 255862] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:39:27.404422 2026] [security2:error] [pid 255769:tid 255787] [remote 90.148.142.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.142.148.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MX7xMYwyVGnfuwsKnFgADrBE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:27.405247 2026] [security2:error] [pid 254995:tid 255034] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9MX_7v0rlcEGmVraFKagADISY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:39:27.426756 2026] [security2:error] [pid 255769:tid 255988] [client 122.179.91.63:21603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MX7xMYwyVGnfuwsKnEwAAA_w"]
[Tue Jul 21 07:39:27.426863 2026] [security2:error] [pid 255769:tid 255988] [client 122.179.91.63:21603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MX7xMYwyVGnfuwsKnEwAAA_w"]
[Tue Jul 21 07:39:27.453316 2026] [autoindex:error] [pid 255769:tid 255987] [client 4.204.201.85:21810] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:27.483002 2026] [security2:error] [pid 255769:tid 255996] [client 20.197.195.24:13134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/222.php"] [unique_id "al9MX7xMYwyVGnfuwsKnGwAABAI"]
[Tue Jul 21 07:39:27.542504 2026] [security2:error] [pid 255769:tid 255954] [client 117.217.38.194:57472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MX7xMYwyVGnfuwsKnHgAAA9o"]
[Tue Jul 21 07:39:27.542697 2026] [security2:error] [pid 255769:tid 255954] [client 117.217.38.194:57472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MX7xMYwyVGnfuwsKnHgAAA9o"]
[Tue Jul 21 07:39:27.666218 2026] [security2:error] [pid 255769:tid 255918] [client 20.226.60.151:27625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/login.php"] [unique_id "al9MX7xMYwyVGnfuwsKnIgAAA7Y"]
[Tue Jul 21 07:39:27.728980 2026] [security2:error] [pid 255769:tid 256017] [client 4.204.201.85:21810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/bthil.php"] [unique_id "al9MX7xMYwyVGnfuwsKnJwAABBc"]
[Tue Jul 21 07:39:27.830248 2026] [rewrite:warn] [pid 255769:tid 255875] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:39:27.898952 2026] [security2:error] [pid 255769:tid 256010] [client 20.226.60.151:9353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/a2.php"] [unique_id "al9MX7xMYwyVGnfuwsKnLAAABBA"]
[Tue Jul 21 07:39:28.037474 2026] [security2:error] [pid 255769:tid 255921] [client 117.132.188.205:32981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/atuacao.php"] [unique_id "al9MYLxMYwyVGnfuwsKnVAAAA7k"]
[Tue Jul 21 07:39:28.044285 2026] [security2:error] [pid 255769:tid 255958] [client 4.204.201.85:4422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/7.php"] [unique_id "al9MYLxMYwyVGnfuwsKnVQAAA94"]
[Tue Jul 21 07:39:28.095236 2026] [security2:error] [pid 254995:tid 255165] [client 139.167.225.182:54296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MYP7v0rlcEGmVraFKdwAAA0Y"]
[Tue Jul 21 07:39:28.095383 2026] [security2:error] [pid 254995:tid 255165] [client 139.167.225.182:54296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MYP7v0rlcEGmVraFKdwAAA0Y"]
[Tue Jul 21 07:39:28.146133 2026] [security2:error] [pid 255769:tid 255916] [client 20.226.60.151:27637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/d61.php"] [unique_id "al9MYLxMYwyVGnfuwsKnXAAAA7Q"]
[Tue Jul 21 07:39:28.276655 2026] [security2:error] [pid 255769:tid 255984] [client 20.220.225.223:34283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/old.php"] [unique_id "al9MYLxMYwyVGnfuwsKnagAAA_g"]
[Tue Jul 21 07:39:28.305779 2026] [security2:error] [pid 255769:tid 256025] [client 20.197.195.24:13158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/test.php"] [unique_id "al9MYLxMYwyVGnfuwsKnawAABB8"]
[Tue Jul 21 07:39:28.368297 2026] [security2:error] [pid 255769:tid 255903] [client 20.220.225.223:22473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/kq1.php"] [unique_id "al9MYLxMYwyVGnfuwsKnbAAAA6c"]
[Tue Jul 21 07:39:28.395092 2026] [security2:error] [pid 255769:tid 255957] [client 20.226.60.151:27348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/info.php"] [unique_id "al9MYLxMYwyVGnfuwsKnbQAAA90"]
[Tue Jul 21 07:39:28.407330 2026] [security2:error] [pid 255769:tid 256019] [client 4.204.201.85:49882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/8.php"] [unique_id "al9MYLxMYwyVGnfuwsKnbgAABBk"]
[Tue Jul 21 07:39:28.695587 2026] [security2:error] [pid 255769:tid 255953] [client 4.204.201.85:49888] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "x45consultoria.com.br"] [uri "/1.php"] [unique_id "al9MYLxMYwyVGnfuwsKneQAAA9k"]
[Tue Jul 21 07:39:28.695709 2026] [security2:error] [pid 255769:tid 255953] [client 4.204.201.85:49888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/1.php"] [unique_id "al9MYLxMYwyVGnfuwsKneQAAA9k"]
[Tue Jul 21 07:39:28.746692 2026] [security2:error] [pid 255769:tid 255784] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MYLxMYwyVGnfuwsKnfQAD9g4"]
[Tue Jul 21 07:39:28.746909 2026] [security2:error] [pid 255769:tid 255982] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MYLxMYwyVGnfuwsKnfQAD9g4"]
[Tue Jul 21 07:39:28.953099 2026] [security2:error] [pid 255769:tid 255932] [client 20.206.105.145:38505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.liranesuliano.com.br"] [uri "/aaa.php"] [unique_id "al9MYLxMYwyVGnfuwsKnfgAAA8Q"]
[Tue Jul 21 07:39:28.957867 2026] [security2:error] [pid 254995:tid 255260] [client 20.197.192.193:6992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/else1.php"] [unique_id "al9MYP7v0rlcEGmVraFKgwAAA4o"]
[Tue Jul 21 07:39:28.979966 2026] [security2:error] [pid 254995:tid 255148] [client 4.204.201.85:4473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/100.php"] [unique_id "al9MYP7v0rlcEGmVraFKhAAAAzU"]
[Tue Jul 21 07:39:29.074484 2026] [security2:error] [pid 255769:tid 255913] [client 20.197.195.24:13169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/aaa.php"] [unique_id "al9MYbxMYwyVGnfuwsKngAAAA7E"]
[Tue Jul 21 07:39:29.193232 2026] [security2:error] [pid 255769:tid 255906] [client 117.132.188.205:32982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.188.132.117.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/index.php"] [unique_id "al9MYbxMYwyVGnfuwsKnggAAA6o"]
[Tue Jul 21 07:39:29.204462 2026] [security2:error] [pid 255769:tid 255936] [client 20.220.225.223:31179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/hunter.php"] [unique_id "al9MYbxMYwyVGnfuwsKngwAAA8g"]
[Tue Jul 21 07:39:29.261747 2026] [security2:error] [pid 255769:tid 255985] [client 106.215.181.8:32834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MYbxMYwyVGnfuwsKnhQAAA_k"]
[Tue Jul 21 07:39:29.261904 2026] [security2:error] [pid 255769:tid 255985] [client 106.215.181.8:32834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MYbxMYwyVGnfuwsKnhQAAA_k"]
[Tue Jul 21 07:39:29.299380 2026] [security2:error] [pid 254995:tid 255211] [client 4.204.201.85:49913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/about.php"] [unique_id "al9MYf7v0rlcEGmVraFKjAAAA3M"]
[Tue Jul 21 07:39:29.357984 2026] [security2:error] [pid 255769:tid 255799] [remote 103.75.187.26:41006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.187.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9MYbxMYwyVGnfuwsKnhgAD-x0"]
[Tue Jul 21 07:39:29.396986 2026] [security2:error] [pid 255769:tid 255899] [client 173.24.185.52:62009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MYbxMYwyVGnfuwsKnhwAAA6M"]
[Tue Jul 21 07:39:29.397110 2026] [security2:error] [pid 255769:tid 255899] [client 173.24.185.52:62009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MYbxMYwyVGnfuwsKnhwAAA6M"]
[Tue Jul 21 07:39:29.461304 2026] [security2:error] [pid 254995:tid 255254] [client 20.197.192.193:6898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/tkikikoko.php"] [unique_id "al9MYf7v0rlcEGmVraFKjgAAA4Q"]
[Tue Jul 21 07:39:29.654170 2026] [security2:error] [pid 254995:tid 255163] [client 4.204.201.85:4490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/admin.php"] [unique_id "al9MYf7v0rlcEGmVraFKlAAAA0Q"]
[Tue Jul 21 07:39:29.723769 2026] [security2:error] [pid 254995:tid 255264] [client 20.197.195.24:13056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/11.php"] [unique_id "al9MYf7v0rlcEGmVraFKlQAAA44"]
[Tue Jul 21 07:39:29.886154 2026] [security2:error] [pid 255769:tid 255942] [client 20.226.60.151:9348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/11.php"] [unique_id "al9MYbxMYwyVGnfuwsKnigAAA84"]
[Tue Jul 21 07:39:29.976389 2026] [security2:error] [pid 255769:tid 255990] [client 4.204.201.85:21736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/edit.php"] [unique_id "al9MYbxMYwyVGnfuwsKnjAAAA_4"]
[Tue Jul 21 07:39:30.015323 2026] [security2:error] [pid 254995:tid 255126] [client 194.164.163.80:37364] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sphawks.com.br"] [uri "/index.html"] [unique_id "al9MYv7v0rlcEGmVraFKmQAAAx8"]
[Tue Jul 21 07:39:30.020716 2026] [proxy:error] [pid 255769:tid 255801] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:39:30.020759 2026] [proxy_http:error] [pid 255769:tid 255801] [remote 205.210.31.253:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:39:30.021377 2026] [proxy:error] [pid 255769:tid 255801] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:39:30.021410 2026] [proxy_http:error] [pid 255769:tid 255801] [remote 205.210.31.253:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:39:30.198447 2026] [security2:error] [pid 255769:tid 255924] [client 20.226.60.151:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/xy.php"] [unique_id "al9MYrxMYwyVGnfuwsKnkQAAA7w"]
[Tue Jul 21 07:39:30.268899 2026] [security2:error] [pid 255769:tid 255907] [client 4.204.201.85:4480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MYrxMYwyVGnfuwsKnkwAAA6s"]
[Tue Jul 21 07:39:30.281168 2026] [security2:error] [pid 255769:tid 256019] [client 20.151.10.161:46070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/adminfuns.php"] [unique_id "al9MYrxMYwyVGnfuwsKnlAAABBk"]
[Tue Jul 21 07:39:30.569194 2026] [autoindex:error] [pid 255769:tid 255909] [client 43.135.145.117:45290] AH01276: Cannot serve directory /home1/leon6484/lumevisual.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.lumevisual.online
[Tue Jul 21 07:39:30.586693 2026] [security2:error] [pid 255769:tid 256009] [client 4.204.201.85:49852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ss.php"] [unique_id "al9MYrxMYwyVGnfuwsKnnAAABA8"]
[Tue Jul 21 07:39:30.626585 2026] [security2:error] [pid 255769:tid 256000] [client 20.197.195.24:13100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/mac.php"] [unique_id "al9MYrxMYwyVGnfuwsKnoQAABAY"]
[Tue Jul 21 07:39:30.775318 2026] [security2:error] [pid 255769:tid 255940] [client 20.226.60.151:27527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/v2.php"] [unique_id "al9MYrxMYwyVGnfuwsKnogAAA8w"]
[Tue Jul 21 07:39:30.883516 2026] [security2:error] [pid 254995:tid 255252] [client 4.204.201.85:4468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/inputs.php"] [unique_id "al9MYv7v0rlcEGmVraFKpQAAA4M"]
[Tue Jul 21 07:39:31.022267 2026] [security2:error] [pid 255769:tid 256012] [client 122.186.204.214:63331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnpwAABBI"]
[Tue Jul 21 07:39:31.022415 2026] [security2:error] [pid 255769:tid 256012] [client 122.186.204.214:63331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnpwAABBI"]
[Tue Jul 21 07:39:31.146469 2026] [security2:error] [pid 255769:tid 255979] [client 136.144.33.96:59639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MY7xMYwyVGnfuwsKnqAAAA_M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:31.166267 2026] [security2:error] [pid 254995:tid 255164] [client 4.204.201.85:21813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/av.php"] [unique_id "al9MY_7v0rlcEGmVraFKqQAAA0U"]
[Tue Jul 21 07:39:31.262977 2026] [security2:error] [pid 255769:tid 256028] [client 117.251.86.144:37106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnqgAABCI"]
[Tue Jul 21 07:39:31.263130 2026] [security2:error] [pid 255769:tid 256028] [client 117.251.86.144:37106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnqgAABCI"]
[Tue Jul 21 07:39:31.318859 2026] [security2:error] [pid 255769:tid 255981] [client 20.226.60.151:27521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/panel.php"] [unique_id "al9MY7xMYwyVGnfuwsKnqwAAA_U"]
[Tue Jul 21 07:39:31.451807 2026] [security2:error] [pid 255769:tid 255896] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnrgAEF34"]
[Tue Jul 21 07:39:31.451946 2026] [security2:error] [pid 255769:tid 256017] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnrgAEF34"]
[Tue Jul 21 07:39:31.483962 2026] [security2:error] [pid 254995:tid 255183] [client 193.36.225.143:47571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MY_7v0rlcEGmVraFKrQAAA1g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:31.492692 2026] [security2:error] [pid 255769:tid 255902] [client 20.226.60.151:27559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/dex.php"] [unique_id "al9MY7xMYwyVGnfuwsKnrwAAA6Y"]
[Tue Jul 21 07:39:31.537614 2026] [security2:error] [pid 255769:tid 255822] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnsAAECTQ"]
[Tue Jul 21 07:39:31.537717 2026] [security2:error] [pid 255769:tid 256003] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MY7xMYwyVGnfuwsKnsAAECTQ"]
[Tue Jul 21 07:39:31.551733 2026] [security2:error] [pid 255769:tid 255942] [client 4.204.201.85:21743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/classwithtostring.php"] [unique_id "al9MY7xMYwyVGnfuwsKnsgAAA84"]
[Tue Jul 21 07:39:31.564940 2026] [security2:error] [pid 255769:tid 255963] [client 20.226.60.151:27560] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "alperembalagens.com.br"] [uri "/1.php"] [unique_id "al9MY7xMYwyVGnfuwsKnswAAA-M"]
[Tue Jul 21 07:39:31.565073 2026] [security2:error] [pid 255769:tid 255963] [client 20.226.60.151:27560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/1.php"] [unique_id "al9MY7xMYwyVGnfuwsKnswAAA-M"]
[Tue Jul 21 07:39:31.600672 2026] [security2:error] [pid 255769:tid 255808] [remote 45.150.79.142:44920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spazziojardins.com"] [uri "/wp-login.php"] [unique_id "al9MY7xMYwyVGnfuwsKntAADsSY"]
[Tue Jul 21 07:39:31.618903 2026] [rewrite:warn] [pid 255769:tid 255840] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:39:31.628769 2026] [security2:error] [pid 254995:tid 255176] [client 20.226.60.151:9365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ms.php"] [unique_id "al9MY_7v0rlcEGmVraFKrwAAA1E"]
[Tue Jul 21 07:39:31.715319 2026] [security2:error] [pid 254995:tid 255141] [client 20.197.195.24:13118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/chosen.php"] [unique_id "al9MY_7v0rlcEGmVraFKswAAAy4"]
[Tue Jul 21 07:39:31.828191 2026] [security2:error] [pid 255769:tid 255903] [client 20.226.60.151:27586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/memberfuns.php"] [unique_id "al9MY7xMYwyVGnfuwsKnuQAAA6c"]
[Tue Jul 21 07:39:31.836064 2026] [security2:error] [pid 255769:tid 255907] [client 4.204.201.85:49854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9MY7xMYwyVGnfuwsKnugAAA6s"]
[Tue Jul 21 07:39:32.017190 2026] [security2:error] [pid 255769:tid 255901] [client 20.226.60.151:27370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/0.php"] [unique_id "al9MZLxMYwyVGnfuwsKnvwAAA6U"]
[Tue Jul 21 07:39:32.058656 2026] [security2:error] [pid 255769:tid 255974] [client 20.226.60.151:9357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/BDKR28.php"] [unique_id "al9MZLxMYwyVGnfuwsKnwAAAA-4"]
[Tue Jul 21 07:39:32.089451 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:27330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/green1.php"] [unique_id "al9MZP7v0rlcEGmVraFKtwAAAx4"]
[Tue Jul 21 07:39:32.113809 2026] [security2:error] [pid 255769:tid 256022] [client 4.204.201.85:49889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-blog.php"] [unique_id "al9MZLxMYwyVGnfuwsKnwQAABBw"]
[Tue Jul 21 07:39:32.138132 2026] [security2:error] [pid 255769:tid 255950] [client 20.197.195.24:13178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/cream1.php"] [unique_id "al9MZLxMYwyVGnfuwsKnwwAAA9Y"]
[Tue Jul 21 07:39:32.155954 2026] [security2:error] [pid 255769:tid 256024] [client 20.226.60.151:27609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/nc4.php"] [unique_id "al9MZLxMYwyVGnfuwsKnxAAABB4"]
[Tue Jul 21 07:39:32.194385 2026] [security2:error] [pid 255769:tid 255841] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZLxMYwyVGnfuwsKnxwAD10c"]
[Tue Jul 21 07:39:32.194490 2026] [security2:error] [pid 255769:tid 255951] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZLxMYwyVGnfuwsKnxwAD10c"]
[Tue Jul 21 07:39:32.199597 2026] [security2:error] [pid 255769:tid 255935] [client 20.220.225.223:32290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/zzz.php"] [unique_id "al9MZLxMYwyVGnfuwsKnyAAAA8c"]
[Tue Jul 21 07:39:32.270721 2026] [security2:error] [pid 255769:tid 255975] [client 20.226.60.151:27349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/a1.php"] [unique_id "al9MZLxMYwyVGnfuwsKnygAAA-8"]
[Tue Jul 21 07:39:32.436283 2026] [autoindex:error] [pid 255769:tid 255915] [client 4.204.201.85:4522] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:32.532285 2026] [autoindex:error] [pid 255769:tid 255825] [remote 74.7.227.191:59500] AH01276: Cannot serve directory /home2/inlaud99/erp.asserradaliberdade.ong.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:32.561165 2026] [security2:error] [pid 255769:tid 255990] [client 152.59.154.239:62814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZLxMYwyVGnfuwsKn0wAAA_4"]
[Tue Jul 21 07:39:32.561284 2026] [security2:error] [pid 255769:tid 255990] [client 152.59.154.239:62814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZLxMYwyVGnfuwsKn0wAAA_4"]
[Tue Jul 21 07:39:32.597133 2026] [autoindex:error] [pid 255769:tid 255889] [remote 74.7.227.63:60800] AH01276: Cannot serve directory /home3/lianem44/ubaloc.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:32.608764 2026] [security2:error] [pid 255769:tid 255978] [client 20.226.60.151:27570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/eee.php"] [unique_id "al9MZLxMYwyVGnfuwsKn1wAAA_I"]
[Tue Jul 21 07:39:32.619871 2026] [security2:error] [pid 255769:tid 256017] [client 74.7.241.180:51080] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ubaloc.online"] [uri "/cgi-sys/404.html"] [unique_id "al9MZLxMYwyVGnfuwsKn2AAEFz8"]
[Tue Jul 21 07:39:32.663483 2026] [security2:error] [pid 255769:tid 255913] [client 20.151.10.161:45894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/goods.php"] [unique_id "al9MZLxMYwyVGnfuwsKn2QAAA7E"]
[Tue Jul 21 07:39:32.689397 2026] [security2:error] [pid 255769:tid 255947] [client 20.226.60.151:9377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-aothait.php"] [unique_id "al9MZLxMYwyVGnfuwsKn2wAAA9M"]
[Tue Jul 21 07:39:32.711783 2026] [security2:error] [pid 255769:tid 255939] [client 4.204.201.85:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MZLxMYwyVGnfuwsKn3AAAA8s"]
[Tue Jul 21 07:39:32.744084 2026] [security2:error] [pid 255769:tid 255942] [client 74.7.175.132:58882] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "erp.asserradaliberdade.ong.br"] [uri "/cgi-sys/404.html"] [unique_id "al9MZLxMYwyVGnfuwsKn3QADzkg"]
[Tue Jul 21 07:39:32.902723 2026] [security2:error] [pid 255769:tid 256019] [client 20.226.60.151:27551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/config.json.php"] [unique_id "al9MZLxMYwyVGnfuwsKn5AAABBk"]
[Tue Jul 21 07:39:33.011427 2026] [security2:error] [pid 255769:tid 255905] [client 194.99.104.35:57062] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn5QAAA6k"]
[Tue Jul 21 07:39:33.011540 2026] [security2:error] [pid 255769:tid 255905] [client 194.99.104.35:57062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn5QAAA6k"]
[Tue Jul 21 07:39:33.012198 2026] [security2:error] [pid 255769:tid 255938] [client 20.226.60.151:27608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9MZbxMYwyVGnfuwsKn5gAAA8o"]
[Tue Jul 21 07:39:33.019644 2026] [security2:error] [pid 255769:tid 255998] [client 4.204.201.85:21783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/adminfuns.php"] [unique_id "al9MZbxMYwyVGnfuwsKn5wAABAQ"]
[Tue Jul 21 07:39:33.160070 2026] [security2:error] [pid 255769:tid 255988] [client 20.226.60.151:9401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/k2.php"] [unique_id "al9MZbxMYwyVGnfuwsKn6QAAA_w"]
[Tue Jul 21 07:39:33.190873 2026] [security2:error] [pid 255769:tid 255972] [client 154.192.233.199:59865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn6gAAA-w"]
[Tue Jul 21 07:39:33.190990 2026] [security2:error] [pid 255769:tid 255972] [client 154.192.233.199:59865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn6gAAA-w"]
[Tue Jul 21 07:39:33.193928 2026] [security2:error] [pid 255769:tid 255953] [client 20.226.60.151:56223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/loader.php"] [unique_id "al9MZbxMYwyVGnfuwsKn6wAAA9k"]
[Tue Jul 21 07:39:33.223335 2026] [security2:error] [pid 255769:tid 256008] [client 20.226.60.151:27352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9MZbxMYwyVGnfuwsKn7gAABA4"]
[Tue Jul 21 07:39:33.325525 2026] [authz_core:error] [pid 255769:tid 255925] [client 20.197.195.24:13073] AH01630: client denied by server configuration: /home2/ren85318/public_html/wp-content/uploads/index.php
[Tue Jul 21 07:39:33.334171 2026] [security2:error] [pid 255769:tid 255951] [client 4.204.201.85:4538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/goods.php"] [unique_id "al9MZbxMYwyVGnfuwsKn9AAAA9c"]
[Tue Jul 21 07:39:33.371100 2026] [autoindex:error] [pid 255769:tid 255944] [client 20.197.195.24:13073] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:33.388850 2026] [security2:error] [pid 255769:tid 255979] [client 20.197.195.24:13073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/dr.php"] [unique_id "al9MZbxMYwyVGnfuwsKn9gAAA_M"]
[Tue Jul 21 07:39:33.618963 2026] [security2:error] [pid 255769:tid 256010] [client 20.220.225.223:31728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wicked.php"] [unique_id "al9MZbxMYwyVGnfuwsKn-wAABBA"]
[Tue Jul 21 07:39:33.620193 2026] [security2:error] [pid 255769:tid 255967] [client 175.45.70.82:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn_AAAA-c"]
[Tue Jul 21 07:39:33.620344 2026] [security2:error] [pid 255769:tid 255967] [client 175.45.70.82:52224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn_AAAA-c"]
[Tue Jul 21 07:39:33.641187 2026] [security2:error] [pid 255769:tid 255790] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn_QAD-hQ"]
[Tue Jul 21 07:39:33.641329 2026] [security2:error] [pid 255769:tid 255986] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKn_QAD-hQ"]
[Tue Jul 21 07:39:33.644059 2026] [security2:error] [pid 255769:tid 255956] [client 4.204.201.85:4492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ms-edit.php"] [unique_id "al9MZbxMYwyVGnfuwsKn_wAAA9w"]
[Tue Jul 21 07:39:33.644509 2026] [security2:error] [pid 255769:tid 255929] [client 107.189.2.5:60386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/.env"] [unique_id "al9MZbxMYwyVGnfuwsKn_gAAA8E"]
[Tue Jul 21 07:39:33.688098 2026] [security2:error] [pid 254995:tid 255154] [client 194.99.104.35:46156] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MZf7v0rlcEGmVraFKygAAAzs"]
[Tue Jul 21 07:39:33.688176 2026] [security2:error] [pid 254995:tid 255154] [client 194.99.104.35:46156] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MZf7v0rlcEGmVraFKygAAAzs"]
[Tue Jul 21 07:39:33.688193 2026] [security2:error] [pid 254995:tid 255154] [client 194.99.104.35:46156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MZf7v0rlcEGmVraFKygAAAzs"]
[Tue Jul 21 07:39:33.692629 2026] [security2:error] [pid 255769:tid 255990] [client 20.220.225.223:38706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/we.php"] [unique_id "al9MZbxMYwyVGnfuwsKoAQAAA_4"]
[Tue Jul 21 07:39:33.746966 2026] [security2:error] [pid 254995:tid 255211] [client 20.226.60.151:27539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9MZf7v0rlcEGmVraFKzgAAA3M"]
[Tue Jul 21 07:39:33.760955 2026] [security2:error] [pid 255769:tid 255893] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKoBgAEB3s"]
[Tue Jul 21 07:39:33.761104 2026] [security2:error] [pid 255769:tid 256001] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKoBgAEB3s"]
[Tue Jul 21 07:39:33.934766 2026] [security2:error] [pid 255769:tid 255950] [client 122.162.144.145:6502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKoDgAAA9Y"]
[Tue Jul 21 07:39:33.934887 2026] [security2:error] [pid 255769:tid 255950] [client 122.162.144.145:6502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKoDgAAA9Y"]
[Tue Jul 21 07:39:33.969434 2026] [security2:error] [pid 255769:tid 255920] [client 4.204.201.85:4535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/222.php"] [unique_id "al9MZbxMYwyVGnfuwsKoDwAAA7g"]
[Tue Jul 21 07:39:33.978351 2026] [security2:error] [pid 255769:tid 256006] [client 103.106.20.201:58702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKoEAAABAw"]
[Tue Jul 21 07:39:33.978479 2026] [security2:error] [pid 255769:tid 256006] [client 103.106.20.201:58702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MZbxMYwyVGnfuwsKoEAAABAw"]
[Tue Jul 21 07:39:34.253060 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:49829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9MZv7v0rlcEGmVraFK1AAAA0o"]
[Tue Jul 21 07:39:34.395787 2026] [security2:error] [pid 255769:tid 255961] [client 20.197.195.24:13170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/x.php"] [unique_id "al9MZrxMYwyVGnfuwsKoPgAAA-E"]
[Tue Jul 21 07:39:34.565019 2026] [autoindex:error] [pid 255769:tid 255902] [client 4.204.201.85:49891] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:34.613573 2026] [security2:error] [pid 255769:tid 255921] [client 20.151.10.161:45993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ms-edit.php"] [unique_id "al9MZrxMYwyVGnfuwsKoTgAAA7k"]
[Tue Jul 21 07:39:34.618232 2026] [security2:error] [pid 255769:tid 255947] [client 184.75.223.211:46528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MZrxMYwyVGnfuwsKoTwAAA9M"]
[Tue Jul 21 07:39:34.618301 2026] [security2:error] [pid 255769:tid 255947] [client 184.75.223.211:46528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9MZrxMYwyVGnfuwsKoTwAAA9M"]
[Tue Jul 21 07:39:34.683418 2026] [security2:error] [pid 254995:tid 255158] [client 193.36.225.102:63189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MZf7v0rlcEGmVraFKyQAAAz8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:34.839833 2026] [security2:error] [pid 255769:tid 255959] [client 4.204.201.85:49891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9MZrxMYwyVGnfuwsKoWAAAA98"]
[Tue Jul 21 07:39:34.917483 2026] [security2:error] [pid 254995:tid 255127] [client 20.220.225.223:31899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/edit.php"] [unique_id "al9MZv7v0rlcEGmVraFK3wAAAyA"]
[Tue Jul 21 07:39:35.119990 2026] [security2:error] [pid 255769:tid 255925] [client 107.189.2.5:60466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/.env.old"] [unique_id "al9MZ7xMYwyVGnfuwsKoYwAAA70"]
[Tue Jul 21 07:39:35.121495 2026] [security2:error] [pid 255769:tid 255919] [client 107.189.2.5:60538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/backend/.env"] [unique_id "al9MZ7xMYwyVGnfuwsKoZgAAA7c"]
[Tue Jul 21 07:39:35.121674 2026] [security2:error] [pid 255769:tid 255945] [client 107.189.2.5:60454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/.env.swp"] [unique_id "al9MZ7xMYwyVGnfuwsKoZQAAA9E"]
[Tue Jul 21 07:39:35.121748 2026] [security2:error] [pid 254995:tid 255221] [client 107.189.2.5:60464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/.env.backup"] [unique_id "al9MZ_7v0rlcEGmVraFK5QAAA30"]
[Tue Jul 21 07:39:35.122312 2026] [security2:error] [pid 255769:tid 256012] [client 107.189.2.5:60442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/.env.bak"] [unique_id "al9MZ7xMYwyVGnfuwsKoZwAABBI"]
[Tue Jul 21 07:39:35.122353 2026] [security2:error] [pid 255769:tid 255979] [client 107.189.2.5:60500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/.env~"] [unique_id "al9MZ7xMYwyVGnfuwsKoagAAA_M"]
[Tue Jul 21 07:39:35.130695 2026] [autoindex:error] [pid 255769:tid 255936] [client 4.204.201.85:4421] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:35.237838 2026] [security2:error] [pid 254995:tid 255272] [client 103.86.117.203:60381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MZ_7v0rlcEGmVraFK7AAAA5Y"]
[Tue Jul 21 07:39:35.237981 2026] [security2:error] [pid 254995:tid 255272] [client 103.86.117.203:60381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MZ_7v0rlcEGmVraFK7AAAA5Y"]
[Tue Jul 21 07:39:35.345323 2026] [security2:error] [pid 255769:tid 255974] [client 20.220.225.223:38697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ewfmontagens.com.br"] [uri "/phpinfo.php1"] [unique_id "al9MZ7xMYwyVGnfuwsKocQAAA-4"]
[Tue Jul 21 07:39:35.421218 2026] [autoindex:error] [pid 255769:tid 255940] [client 4.204.201.85:4421] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:35.505788 2026] [security2:error] [pid 254995:tid 255225] [client 20.197.195.24:13124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/155.php"] [unique_id "al9MZ_7v0rlcEGmVraFK8QAAA4E"]
[Tue Jul 21 07:39:35.565535 2026] [security2:error] [pid 255769:tid 255915] [client 4.204.201.85:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp.php"] [unique_id "al9MZ7xMYwyVGnfuwsKoegAAA7M"]
[Tue Jul 21 07:39:35.579526 2026] [security2:error] [pid 255769:tid 255983] [client 107.189.2.5:60386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/api/.env"] [unique_id "al9MZ7xMYwyVGnfuwsKofAAAA_c"]
[Tue Jul 21 07:39:35.579629 2026] [security2:error] [pid 254995:tid 255279] [client 107.189.2.5:60546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/app/.env"] [unique_id "al9MZ_7v0rlcEGmVraFK9AAAA50"]
[Tue Jul 21 07:39:35.675897 2026] [security2:error] [pid 255769:tid 255967] [client 107.189.2.5:60476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/src/.env"] [unique_id "al9MZ7xMYwyVGnfuwsKofQAAA-c"]
[Tue Jul 21 07:39:35.676100 2026] [security2:error] [pid 255769:tid 255935] [client 20.226.60.151:27628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9MZ7xMYwyVGnfuwsKofgAAA8c"]
[Tue Jul 21 07:39:35.677183 2026] [security2:error] [pid 255769:tid 256010] [client 107.189.2.5:60500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/config/.env"] [unique_id "al9MZ7xMYwyVGnfuwsKofwAABBA"]
[Tue Jul 21 07:39:35.677724 2026] [security2:error] [pid 255769:tid 255902] [client 107.189.2.5:60486] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/server/.env"] [unique_id "al9MZ7xMYwyVGnfuwsKogQAAA6Y"]
[Tue Jul 21 07:39:35.678545 2026] [security2:error] [pid 254995:tid 255190] [client 107.189.2.5:60394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karaoke.botecocarnenalata.com.br"] [uri "/web/.env"] [unique_id "al9MZ_7v0rlcEGmVraFK-QAAA18"]
[Tue Jul 21 07:39:35.840118 2026] [security2:error] [pid 254995:tid 255198] [client 4.204.201.85:4532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/abcd.php"] [unique_id "al9MZ_7v0rlcEGmVraFLAAAAA2c"]
[Tue Jul 21 07:39:35.849022 2026] [security2:error] [pid 255769:tid 255955] [client 20.151.10.161:45999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/222.php"] [unique_id "al9MZ7xMYwyVGnfuwsKoiwAAA9s"]
[Tue Jul 21 07:39:35.990031 2026] [security2:error] [pid 255769:tid 255913] [client 136.144.33.97:55947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MZ7xMYwyVGnfuwsKoigAAA7E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:36.121099 2026] [security2:error] [pid 254995:tid 255197] [client 4.204.201.85:57276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/a1.php"] [unique_id "al9MaP7v0rlcEGmVraFLBgAAA2Y"]
[Tue Jul 21 07:39:36.397091 2026] [security2:error] [pid 255769:tid 255919] [client 4.204.201.85:4416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9MaLxMYwyVGnfuwsKooQAAA7c"]
[Tue Jul 21 07:39:36.400657 2026] [security2:error] [pid 255769:tid 255980] [client 47.74.5.98:57948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9MaLxMYwyVGnfuwsKomAAAA_Q"]
[Tue Jul 21 07:39:36.469443 2026] [security2:error] [pid 254995:tid 255171] [client 103.174.34.15:64777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MaP7v0rlcEGmVraFLCQAAA0w"]
[Tue Jul 21 07:39:36.469568 2026] [security2:error] [pid 254995:tid 255171] [client 103.174.34.15:64777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MaP7v0rlcEGmVraFLCQAAA0w"]
[Tue Jul 21 07:39:36.652741 2026] [security2:error] [pid 255769:tid 255972] [client 20.151.10.161:45939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9MaLxMYwyVGnfuwsKorwAAA-w"]
[Tue Jul 21 07:39:36.685848 2026] [security2:error] [pid 255769:tid 255940] [client 4.204.201.85:57271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9MaLxMYwyVGnfuwsKosQAAA8w"]
[Tue Jul 21 07:39:36.848332 2026] [security2:error] [pid 255769:tid 255790] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MaLxMYwyVGnfuwsKouQAEIRQ"]
[Tue Jul 21 07:39:36.848447 2026] [security2:error] [pid 255769:tid 256027] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MaLxMYwyVGnfuwsKouQAEIRQ"]
[Tue Jul 21 07:39:36.877587 2026] [security2:error] [pid 255769:tid 255912] [client 20.226.60.151:27351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/for.php"] [unique_id "al9MaLxMYwyVGnfuwsKovQAAA7A"]
[Tue Jul 21 07:39:36.962422 2026] [security2:error] [pid 255769:tid 256017] [client 4.204.201.85:4458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/gettest.php"] [unique_id "al9MaLxMYwyVGnfuwsKowQAABBc"]
[Tue Jul 21 07:39:37.177682 2026] [security2:error] [pid 255769:tid 255984] [client 194.99.104.35:46172] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKoygAAA_g"]
[Tue Jul 21 07:39:37.177744 2026] [security2:error] [pid 255769:tid 255984] [client 194.99.104.35:46172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKoygAAA_g"]
[Tue Jul 21 07:39:37.212577 2026] [security2:error] [pid 254995:tid 255142] [client 184.75.223.211:49638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Maf7v0rlcEGmVraFLEQAAAy8"]
[Tue Jul 21 07:39:37.212648 2026] [security2:error] [pid 254995:tid 255142] [client 184.75.223.211:49638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Maf7v0rlcEGmVraFLEQAAAy8"]
[Tue Jul 21 07:39:37.262761 2026] [security2:error] [pid 255769:tid 255999] [client 47.74.5.98:57965] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/"] [unique_id "al9MabxMYwyVGnfuwsKozAAABAU"]
[Tue Jul 21 07:39:37.270369 2026] [security2:error] [pid 255769:tid 256021] [client 59.96.220.140:42] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKozQAABBs"]
[Tue Jul 21 07:39:37.271380 2026] [security2:error] [pid 255769:tid 256021] [client 59.96.220.140:42] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKozQAABBs"]
[Tue Jul 21 07:39:37.446151 2026] [security2:error] [pid 255769:tid 255959] [client 20.226.60.151:27332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/raw.php"] [unique_id "al9MabxMYwyVGnfuwsKo0QAAA98"]
[Tue Jul 21 07:39:37.474611 2026] [security2:error] [pid 255769:tid 255977] [client 20.151.10.161:55243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MabxMYwyVGnfuwsKo0gAAA_E"]
[Tue Jul 21 07:39:37.771728 2026] [security2:error] [pid 254995:tid 255159] [client 20.151.10.161:45836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Maf7v0rlcEGmVraFLGgAAA0A"]
[Tue Jul 21 07:39:37.848957 2026] [security2:error] [pid 255769:tid 255976] [client 139.167.225.182:55094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKo1gAAA_A"]
[Tue Jul 21 07:39:37.849057 2026] [security2:error] [pid 255769:tid 255976] [client 139.167.225.182:55094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKo1gAAA_A"]
[Tue Jul 21 07:39:37.857852 2026] [security2:error] [pid 255769:tid 255921] [client 122.179.91.63:7298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKo1wAAA7k"]
[Tue Jul 21 07:39:37.857934 2026] [security2:error] [pid 255769:tid 255921] [client 122.179.91.63:7298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MabxMYwyVGnfuwsKo1wAAA7k"]
[Tue Jul 21 07:39:37.905407 2026] [security2:error] [pid 255769:tid 255972] [client 20.226.60.151:56266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/spadex.php"] [unique_id "al9MabxMYwyVGnfuwsKo2QAAA-w"]
[Tue Jul 21 07:39:37.978313 2026] [security2:error] [pid 255769:tid 255934] [client 4.204.201.85:4438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/simple.php"] [unique_id "al9MabxMYwyVGnfuwsKo2wAAA8Y"]
[Tue Jul 21 07:39:37.995683 2026] [security2:error] [pid 254995:tid 255149] [client 117.217.38.194:57944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Maf7v0rlcEGmVraFLHgAAAzY"]
[Tue Jul 21 07:39:37.995822 2026] [security2:error] [pid 254995:tid 255149] [client 117.217.38.194:57944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Maf7v0rlcEGmVraFLHgAAAzY"]
[Tue Jul 21 07:39:38.134897 2026] [security2:error] [pid 255769:tid 255908] [client 47.74.5.98:57972] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9MarxMYwyVGnfuwsKo4AAAA6w"]
[Tue Jul 21 07:39:38.253417 2026] [security2:error] [pid 255769:tid 255929] [client 20.220.225.223:19299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MarxMYwyVGnfuwsKo5gAAA8E"]
[Tue Jul 21 07:39:38.254329 2026] [security2:error] [pid 255769:tid 256003] [client 4.204.201.85:49823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/xxx.php"] [unique_id "al9MarxMYwyVGnfuwsKo5wAABAk"]
[Tue Jul 21 07:39:38.333440 2026] [security2:error] [pid 255769:tid 256020] [client 193.36.225.96:30083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MarxMYwyVGnfuwsKo4gAABBo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:38.529231 2026] [security2:error] [pid 255769:tid 255994] [client 4.204.201.85:21737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/hypo.php"] [unique_id "al9MarxMYwyVGnfuwsKo7AAABAE"]
[Tue Jul 21 07:39:38.742598 2026] [security2:error] [pid 255769:tid 255992] [client 20.197.195.24:48841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ops.php"] [unique_id "al9MarxMYwyVGnfuwsKo7wAAA_8"]
[Tue Jul 21 07:39:38.860348 2026] [autoindex:error] [pid 255769:tid 255971] [client 4.204.201.85:21822] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:38.963429 2026] [security2:error] [pid 255769:tid 256019] [client 20.151.10.161:45946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp.php"] [unique_id "al9MarxMYwyVGnfuwsKo8wAABBk"]
[Tue Jul 21 07:39:38.976219 2026] [security2:error] [pid 255769:tid 255947] [client 47.74.5.98:57985] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/"] [unique_id "al9MarxMYwyVGnfuwsKo9AAAA9M"]
[Tue Jul 21 07:39:39.134922 2026] [security2:error] [pid 255769:tid 255939] [client 4.204.201.85:21822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/chosen.php"] [unique_id "al9Ma7xMYwyVGnfuwsKo9QAAA8s"]
[Tue Jul 21 07:39:39.422362 2026] [security2:error] [pid 255769:tid 255795] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ma7xMYwyVGnfuwsKo_QADqxk"]
[Tue Jul 21 07:39:39.422942 2026] [security2:error] [pid 255769:tid 255907] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ma7xMYwyVGnfuwsKo_QADqxk"]
[Tue Jul 21 07:39:39.428441 2026] [autoindex:error] [pid 255769:tid 255899] [client 4.204.201.85:21751] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:39.705862 2026] [security2:error] [pid 255769:tid 255982] [client 4.204.201.85:21751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/als.php"] [unique_id "al9Ma7xMYwyVGnfuwsKo_wAAA_Y"]
[Tue Jul 21 07:39:39.783391 2026] [security2:error] [pid 255769:tid 255985] [client 20.151.10.161:46011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/abcd.php"] [unique_id "al9Ma7xMYwyVGnfuwsKpAQAAA_k"]
[Tue Jul 21 07:39:39.824668 2026] [security2:error] [pid 254995:tid 255272] [client 47.74.5.98:57999] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9Ma_7v0rlcEGmVraFLNQAAA5Y"]
[Tue Jul 21 07:39:39.841165 2026] [security2:error] [pid 255769:tid 255908] [client 20.220.225.223:34254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/ms-new.php"] [unique_id "al9Ma7xMYwyVGnfuwsKpAgAAA6w"]
[Tue Jul 21 07:39:39.932446 2026] [security2:error] [pid 254995:tid 255264] [client 106.215.181.8:28768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ma_7v0rlcEGmVraFLOQAAA44"]
[Tue Jul 21 07:39:39.932546 2026] [security2:error] [pid 254995:tid 255264] [client 106.215.181.8:28768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ma_7v0rlcEGmVraFLOQAAA44"]
[Tue Jul 21 07:39:39.944228 2026] [security2:error] [pid 255769:tid 255940] [client 173.24.185.52:62537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ma7xMYwyVGnfuwsKpAwAAA8w"]
[Tue Jul 21 07:39:39.944357 2026] [security2:error] [pid 255769:tid 255940] [client 173.24.185.52:62537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Ma7xMYwyVGnfuwsKpAwAAA8w"]
[Tue Jul 21 07:39:39.995427 2026] [security2:error] [pid 255769:tid 255967] [client 4.204.201.85:4470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/pol.php"] [unique_id "al9Ma7xMYwyVGnfuwsKpBAAAA-c"]
[Tue Jul 21 07:39:40.290442 2026] [security2:error] [pid 255769:tid 256016] [client 4.204.201.85:21700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/file5.php"] [unique_id "al9MbLxMYwyVGnfuwsKpBwAABBY"]
[Tue Jul 21 07:39:40.356465 2026] [security2:error] [pid 254995:tid 255198] [client 20.151.10.161:55254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MbP7v0rlcEGmVraFLQwAAA2c"]
[Tue Jul 21 07:39:40.577656 2026] [security2:error] [pid 255769:tid 255968] [client 4.204.201.85:49811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/file.php"] [unique_id "al9MbLxMYwyVGnfuwsKpDAAAA-g"]
[Tue Jul 21 07:39:40.653868 2026] [security2:error] [pid 254995:tid 255262] [client 47.74.5.98:58011] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/"] [unique_id "al9MbP7v0rlcEGmVraFLSQAAA4w"]
[Tue Jul 21 07:39:40.661039 2026] [security2:error] [pid 255769:tid 255805] [remote 203.161.62.87:46588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.62.161.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9MbLxMYwyVGnfuwsKpCgAD9SM"]
[Tue Jul 21 07:39:40.889227 2026] [security2:error] [pid 255769:tid 255938] [client 4.204.201.85:49875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/cfile.php"] [unique_id "al9MbLxMYwyVGnfuwsKpEQAAA8o"]
[Tue Jul 21 07:39:40.956867 2026] [security2:error] [pid 254995:tid 255191] [client 184.75.223.211:50754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9MbP7v0rlcEGmVraFLTwAAA2A"]
[Tue Jul 21 07:39:40.956955 2026] [security2:error] [pid 254995:tid 255191] [client 184.75.223.211:50754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9MbP7v0rlcEGmVraFLTwAAA2A"]
[Tue Jul 21 07:39:41.013153 2026] [security2:error] [pid 255769:tid 255997] [client 136.144.33.215:22495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MbbxMYwyVGnfuwsKpEwAABAM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:41.178372 2026] [security2:error] [pid 255769:tid 255925] [client 4.204.201.85:4539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/admin.php"] [unique_id "al9MbbxMYwyVGnfuwsKpFAAAA70"]
[Tue Jul 21 07:39:41.462664 2026] [security2:error] [pid 255769:tid 255979] [client 20.197.195.24:48850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/file31.php"] [unique_id "al9MbbxMYwyVGnfuwsKpFgAAA_M"]
[Tue Jul 21 07:39:41.480627 2026] [security2:error] [pid 254995:tid 255174] [client 47.74.5.98:58025] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9Mbf7v0rlcEGmVraFLWwAAA08"]
[Tue Jul 21 07:39:41.547290 2026] [security2:error] [pid 255769:tid 256010] [client 4.204.201.85:49879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/aa2.php"] [unique_id "al9MbbxMYwyVGnfuwsKpGAAABBA"]
[Tue Jul 21 07:39:41.753518 2026] [security2:error] [pid 255769:tid 256017] [client 20.151.10.161:45926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/a1.php"] [unique_id "al9MbbxMYwyVGnfuwsKpHgAABBc"]
[Tue Jul 21 07:39:41.770493 2026] [security2:error] [pid 255769:tid 255945] [client 122.186.204.214:63862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MbbxMYwyVGnfuwsKpHwAAA9E"]
[Tue Jul 21 07:39:41.770607 2026] [security2:error] [pid 255769:tid 255945] [client 122.186.204.214:63862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MbbxMYwyVGnfuwsKpHwAAA9E"]
[Tue Jul 21 07:39:41.818883 2026] [security2:error] [pid 254995:tid 255274] [client 20.220.225.223:31726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/kua.php"] [unique_id "al9Mbf7v0rlcEGmVraFLZAAAA5g"]
[Tue Jul 21 07:39:41.828664 2026] [security2:error] [pid 255769:tid 256000] [client 4.204.201.85:49846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ccou.php"] [unique_id "al9MbbxMYwyVGnfuwsKpIAAABAY"]
[Tue Jul 21 07:39:41.912681 2026] [security2:error] [pid 255769:tid 256006] [client 117.251.86.144:35510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MbbxMYwyVGnfuwsKpIwAABAw"]
[Tue Jul 21 07:39:41.912867 2026] [security2:error] [pid 255769:tid 256006] [client 117.251.86.144:35510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MbbxMYwyVGnfuwsKpIwAABAw"]
[Tue Jul 21 07:39:41.929551 2026] [security2:error] [pid 255769:tid 255883] [remote 45.79.123.44:56186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rustikusboxingschool.com"] [uri "/wp-login.php"] [unique_id "al9MbbxMYwyVGnfuwsKpJAAD93E"]
[Tue Jul 21 07:39:41.953387 2026] [security2:error] [pid 255769:tid 255854] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MbbxMYwyVGnfuwsKpJQAD-1Q"]
[Tue Jul 21 07:39:41.953507 2026] [security2:error] [pid 255769:tid 255987] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MbbxMYwyVGnfuwsKpJQAD-1Q"]
[Tue Jul 21 07:39:42.082629 2026] [security2:error] [pid 254995:tid 255027] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mbv7v0rlcEGmVraFLZwADdR8"]
[Tue Jul 21 07:39:42.082741 2026] [security2:error] [pid 254995:tid 255213] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mbv7v0rlcEGmVraFLZwADdR8"]
[Tue Jul 21 07:39:42.115923 2026] [security2:error] [pid 255769:tid 255984] [client 4.204.201.85:4472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/dr.php"] [unique_id "al9MbrxMYwyVGnfuwsKpKgAAA_g"]
[Tue Jul 21 07:39:42.214796 2026] [security2:error] [pid 254995:tid 255254] [client 37.140.223.201:46393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mbf7v0rlcEGmVraFLVAAAA4Q"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:42.294750 2026] [security2:error] [pid 255769:tid 256011] [client 47.74.5.98:58037] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "avermetais.com.br"] [uri "/"] [unique_id "al9MbrxMYwyVGnfuwsKpLgAABBE"]
[Tue Jul 21 07:39:42.372081 2026] [security2:error] [pid 254995:tid 255130] [client 20.197.195.24:13144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/file6.php"] [unique_id "al9Mbv7v0rlcEGmVraFLawAAAyM"]
[Tue Jul 21 07:39:42.456178 2026] [security2:error] [pid 254995:tid 255264] [client 4.204.201.85:4528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/xamp.php"] [unique_id "al9Mbv7v0rlcEGmVraFLbAAAA44"]
[Tue Jul 21 07:39:42.493490 2026] [security2:error] [pid 255769:tid 255836] [remote 41.76.214.143:36216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atilafagundes.com.br"] [uri "/wp-login.php"] [unique_id "al9MbrxMYwyVGnfuwsKpMgAD1UI"]
[Tue Jul 21 07:39:42.524140 2026] [security2:error] [pid 254995:tid 255220] [client 20.220.225.223:19676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Mbv7v0rlcEGmVraFLbQAAA3w"]
[Tue Jul 21 07:39:42.718970 2026] [autoindex:error] [pid 255769:tid 255988] [client 20.197.195.24:13137] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:42.755143 2026] [security2:error] [pid 255769:tid 255920] [client 20.197.195.24:13137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/adminfuns.php"] [unique_id "al9MbrxMYwyVGnfuwsKpNQAAA7g"]
[Tue Jul 21 07:39:42.759764 2026] [security2:error] [pid 255769:tid 255925] [client 4.204.201.85:4443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/bless.php"] [unique_id "al9MbrxMYwyVGnfuwsKpNgAAA70"]
[Tue Jul 21 07:39:42.919152 2026] [security2:error] [pid 255769:tid 255899] [client 20.151.10.161:55250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/x.php"] [unique_id "al9MbrxMYwyVGnfuwsKpNwAAA6M"]
[Tue Jul 21 07:39:42.922935 2026] [security2:error] [pid 254995:tid 255184] [client 128.127.105.184:46706] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Mbv7v0rlcEGmVraFLdgAAA1k"]
[Tue Jul 21 07:39:42.923024 2026] [security2:error] [pid 254995:tid 255184] [client 128.127.105.184:46706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Mbv7v0rlcEGmVraFLdgAAA1k"]
[Tue Jul 21 07:39:43.027633 2026] [security2:error] [pid 255769:tid 255818] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpOAADzzA"]
[Tue Jul 21 07:39:43.027784 2026] [security2:error] [pid 255769:tid 255943] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpOAADzzA"]
[Tue Jul 21 07:39:43.039701 2026] [security2:error] [pid 255769:tid 256022] [client 4.204.201.85:21821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/file25.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpOQAABBw"]
[Tue Jul 21 07:39:43.098865 2026] [security2:error] [pid 255769:tid 255974] [client 20.197.195.24:13079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/goods.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpOgAAA-4"]
[Tue Jul 21 07:39:43.181424 2026] [security2:error] [pid 255769:tid 255906] [client 194.99.104.35:56072] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpOwAAA6o"]
[Tue Jul 21 07:39:43.181500 2026] [security2:error] [pid 255769:tid 255906] [client 194.99.104.35:56072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpOwAAA6o"]
[Tue Jul 21 07:39:43.328956 2026] [security2:error] [pid 255769:tid 255985] [client 4.204.201.85:49868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/file6.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpPgAAA_k"]
[Tue Jul 21 07:39:43.358110 2026] [security2:error] [pid 255769:tid 255935] [client 20.197.195.24:13150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/100.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpPwAAA8c"]
[Tue Jul 21 07:39:43.473485 2026] [security2:error] [pid 255769:tid 256001] [client 62.102.148.187:60750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpQwAABAc"]
[Tue Jul 21 07:39:43.473579 2026] [security2:error] [pid 255769:tid 256001] [client 62.102.148.187:60750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpQwAABAc"]
[Tue Jul 21 07:39:43.602409 2026] [security2:error] [pid 255769:tid 255956] [client 4.204.201.85:49859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/a2.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpSwAAA9w"]
[Tue Jul 21 07:39:43.783518 2026] [security2:error] [pid 255769:tid 256019] [client 20.197.195.24:13065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/about.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpTQAABBk"]
[Tue Jul 21 07:39:43.803708 2026] [security2:error] [pid 255769:tid 255930] [client 20.226.60.151:56227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/2x.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpTgAAA8I"]
[Tue Jul 21 07:39:43.885951 2026] [security2:error] [pid 255769:tid 255959] [client 4.204.201.85:21702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/file15.php"] [unique_id "al9Mb7xMYwyVGnfuwsKpUwAAA98"]
[Tue Jul 21 07:39:44.081703 2026] [security2:error] [pid 254995:tid 255200] [client 20.151.10.161:45984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9McP7v0rlcEGmVraFLhgAAA2k"]
[Tue Jul 21 07:39:44.143840 2026] [security2:error] [pid 254995:tid 255273] [client 20.151.10.161:53583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/j260624_13.php"] [unique_id "al9McP7v0rlcEGmVraFLiAAAA5c"]
[Tue Jul 21 07:39:44.164449 2026] [security2:error] [pid 254995:tid 255260] [client 4.204.201.85:49828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/f35.php"] [unique_id "al9McP7v0rlcEGmVraFLiQAAA4o"]
[Tue Jul 21 07:39:44.270033 2026] [security2:error] [pid 255769:tid 255821] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpYwADzzM"]
[Tue Jul 21 07:39:44.270190 2026] [security2:error] [pid 255769:tid 255943] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpYwADzzM"]
[Tue Jul 21 07:39:44.401635 2026] [security2:error] [pid 255769:tid 255816] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpZAAEHC4"]
[Tue Jul 21 07:39:44.401873 2026] [security2:error] [pid 255769:tid 256022] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpZAAEHC4"]
[Tue Jul 21 07:39:44.423225 2026] [security2:error] [pid 254995:tid 255262] [client 175.45.70.82:52738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McP7v0rlcEGmVraFLjAAAA4w"]
[Tue Jul 21 07:39:44.423336 2026] [security2:error] [pid 254995:tid 255262] [client 175.45.70.82:52738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McP7v0rlcEGmVraFLjAAAA4w"]
[Tue Jul 21 07:39:44.457305 2026] [security2:error] [pid 255769:tid 256004] [client 4.204.201.85:49905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-load.php"] [unique_id "al9McLxMYwyVGnfuwsKpZwAABAo"]
[Tue Jul 21 07:39:44.461552 2026] [security2:error] [pid 254995:tid 255156] [client 154.192.233.199:58820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McP7v0rlcEGmVraFLjgAAAz0"]
[Tue Jul 21 07:39:44.461638 2026] [security2:error] [pid 254995:tid 255156] [client 154.192.233.199:58820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McP7v0rlcEGmVraFLjgAAAz0"]
[Tue Jul 21 07:39:44.557287 2026] [security2:error] [pid 255769:tid 255969] [client 20.226.60.151:56192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ctex1.php"] [unique_id "al9McLxMYwyVGnfuwsKpaQAAA-k"]
[Tue Jul 21 07:39:44.586081 2026] [security2:error] [pid 255769:tid 255935] [client 20.220.225.223:38235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/ez.php"] [unique_id "al9McLxMYwyVGnfuwsKpagAAA8c"]
[Tue Jul 21 07:39:44.596601 2026] [security2:error] [pid 255769:tid 256016] [client 20.197.195.24:13064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/about.php"] [unique_id "al9McLxMYwyVGnfuwsKpawAABBY"]
[Tue Jul 21 07:39:44.671708 2026] [security2:error] [pid 255769:tid 255917] [client 103.106.20.201:59287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpbAAAA7U"]
[Tue Jul 21 07:39:44.671834 2026] [security2:error] [pid 255769:tid 255917] [client 103.106.20.201:59287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpbAAAA7U"]
[Tue Jul 21 07:39:44.766331 2026] [security2:error] [pid 255769:tid 255997] [client 122.162.144.145:26000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpcAAABAM"]
[Tue Jul 21 07:39:44.766423 2026] [security2:error] [pid 255769:tid 255997] [client 122.162.144.145:26000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpcAAABAM"]
[Tue Jul 21 07:39:44.769351 2026] [security2:error] [pid 255769:tid 255948] [client 4.204.201.85:21787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/xwpg.php"] [unique_id "al9McLxMYwyVGnfuwsKpcQAAA9Q"]
[Tue Jul 21 07:39:44.853364 2026] [security2:error] [pid 255769:tid 255945] [client 193.36.225.58:41875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9McLxMYwyVGnfuwsKpdAAAA9E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:44.977747 2026] [security2:error] [pid 255769:tid 255938] [client 152.59.154.239:63407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpdgAAA8o"]
[Tue Jul 21 07:39:44.977855 2026] [security2:error] [pid 255769:tid 255938] [client 152.59.154.239:63407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9McLxMYwyVGnfuwsKpdgAAA8o"]
[Tue Jul 21 07:39:45.079716 2026] [autoindex:error] [pid 255769:tid 255984] [client 4.204.201.85:49855] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:45.159932 2026] [security2:error] [pid 254995:tid 255163] [client 20.151.10.161:53609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/d62.php"] [unique_id "al9Mcf7v0rlcEGmVraFLlQAAA0Q"]
[Tue Jul 21 07:39:45.174994 2026] [security2:error] [pid 254995:tid 255149] [client 184.75.223.211:50756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Mcf7v0rlcEGmVraFLlgAAAzY"]
[Tue Jul 21 07:39:45.175084 2026] [security2:error] [pid 254995:tid 255149] [client 184.75.223.211:50756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Mcf7v0rlcEGmVraFLlgAAAzY"]
[Tue Jul 21 07:39:45.187065 2026] [security2:error] [pid 254995:tid 255161] [client 20.226.60.151:56219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/edorxrr.php"] [unique_id "al9Mcf7v0rlcEGmVraFLlwAAA0I"]
[Tue Jul 21 07:39:45.419960 2026] [autoindex:error] [pid 255769:tid 255999] [client 4.204.201.85:49855] AH01276: Cannot serve directory /home4/dani2139/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:45.561150 2026] [security2:error] [pid 255769:tid 255905] [client 4.204.201.85:49855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/xstelth.php"] [unique_id "al9McbxMYwyVGnfuwsKpegAAA6k"]
[Tue Jul 21 07:39:45.580914 2026] [security2:error] [pid 255769:tid 255965] [client 128.127.105.184:46712] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9McbxMYwyVGnfuwsKpewAAA-U"]
[Tue Jul 21 07:39:45.581023 2026] [security2:error] [pid 255769:tid 255965] [client 128.127.105.184:46712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9McbxMYwyVGnfuwsKpewAAA-U"]
[Tue Jul 21 07:39:45.708542 2026] [security2:error] [pid 254995:tid 255144] [client 103.86.117.203:60902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mcf7v0rlcEGmVraFLpAAAAzE"]
[Tue Jul 21 07:39:45.708675 2026] [security2:error] [pid 254995:tid 255144] [client 103.86.117.203:60902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mcf7v0rlcEGmVraFLpAAAAzE"]
[Tue Jul 21 07:39:45.712610 2026] [security2:error] [pid 255769:tid 255958] [client 20.197.192.193:56442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9McbxMYwyVGnfuwsKpfwAAA94"]
[Tue Jul 21 07:39:45.724556 2026] [security2:error] [pid 255769:tid 255791] [remote 47.128.25.144:19084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arcoll.com.br"] [uri "/web/page.php"] [unique_id "al9McbxMYwyVGnfuwsKpgQAD9BU"]
[Tue Jul 21 07:39:45.730733 2026] [security2:error] [pid 255769:tid 255966] [client 20.197.192.193:58465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9McbxMYwyVGnfuwsKpggAAA-Y"]
[Tue Jul 21 07:39:45.749387 2026] [security2:error] [pid 255769:tid 256009] [client 20.197.192.193:58463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/dp.php"] [unique_id "al9McbxMYwyVGnfuwsKphAAABA8"]
[Tue Jul 21 07:39:45.757149 2026] [security2:error] [pid 254995:tid 255213] [client 20.197.195.24:48862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/admin.php"] [unique_id "al9Mcf7v0rlcEGmVraFLpwAAA3U"]
[Tue Jul 21 07:39:45.761526 2026] [security2:error] [pid 255769:tid 255907] [client 20.197.192.193:58468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/old.php"] [unique_id "al9McbxMYwyVGnfuwsKphgAAA6s"]
[Tue Jul 21 07:39:45.773144 2026] [security2:error] [pid 255769:tid 255921] [client 20.197.192.193:58438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ms-new.php"] [unique_id "al9McbxMYwyVGnfuwsKphwAAA7k"]
[Tue Jul 21 07:39:45.785086 2026] [security2:error] [pid 255769:tid 255964] [client 20.197.192.193:58204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/track.php"] [unique_id "al9McbxMYwyVGnfuwsKpiAAAA-Q"]
[Tue Jul 21 07:39:45.795413 2026] [security2:error] [pid 255769:tid 255982] [client 20.197.192.193:56444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/2352356666.php"] [unique_id "al9McbxMYwyVGnfuwsKpiQAAA_Y"]
[Tue Jul 21 07:39:45.806722 2026] [security2:error] [pid 255769:tid 256004] [client 20.197.192.193:56419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/pn.php"] [unique_id "al9McbxMYwyVGnfuwsKpigAABAo"]
[Tue Jul 21 07:39:45.829390 2026] [security2:error] [pid 255769:tid 256008] [client 20.197.192.193:58193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-wpbak.php"] [unique_id "al9McbxMYwyVGnfuwsKpiwAABA4"]
[Tue Jul 21 07:39:45.844786 2026] [security2:error] [pid 255769:tid 255954] [client 20.197.192.193:58477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/dr.php"] [unique_id "al9McbxMYwyVGnfuwsKpjQAAA9o"]
[Tue Jul 21 07:39:45.850061 2026] [security2:error] [pid 255769:tid 255908] [client 4.204.201.85:4525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9McbxMYwyVGnfuwsKpjgAAA6w"]
[Tue Jul 21 07:39:45.863527 2026] [security2:error] [pid 255769:tid 255985] [client 20.197.192.193:58457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/2x.php"] [unique_id "al9McbxMYwyVGnfuwsKpkAAAA_k"]
[Tue Jul 21 07:39:45.881263 2026] [security2:error] [pid 255769:tid 256010] [client 20.197.192.193:58458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/kq1.php"] [unique_id "al9McbxMYwyVGnfuwsKpkgAABBA"]
[Tue Jul 21 07:39:45.902195 2026] [security2:error] [pid 255769:tid 256016] [client 20.197.192.193:56443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/zzz.php"] [unique_id "al9McbxMYwyVGnfuwsKplAAABBY"]
[Tue Jul 21 07:39:45.917881 2026] [security2:error] [pid 255769:tid 255917] [client 20.197.192.193:58450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wicked.php"] [unique_id "al9McbxMYwyVGnfuwsKplQAAA7U"]
[Tue Jul 21 07:39:45.928402 2026] [security2:error] [pid 254995:tid 255254] [client 20.197.192.193:58470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/edit.php"] [unique_id "al9Mcf7v0rlcEGmVraFLqgAAA4Q"]
[Tue Jul 21 07:39:45.943851 2026] [core:alert] [pid 254995:tid 255225] [client 57.141.18.46:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:39:45.944873 2026] [security2:error] [pid 254995:tid 255128] [client 20.197.192.193:58494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/kua.php"] [unique_id "al9Mcf7v0rlcEGmVraFLrgAAAyE"]
[Tue Jul 21 07:39:45.960078 2026] [security2:error] [pid 255769:tid 256027] [client 20.197.192.193:56431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ez.php"] [unique_id "al9McbxMYwyVGnfuwsKplwAABCE"]
[Tue Jul 21 07:39:45.977549 2026] [security2:error] [pid 255769:tid 255953] [client 20.197.192.193:58433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/fz.php"] [unique_id "al9McbxMYwyVGnfuwsKpmAAAA9k"]
[Tue Jul 21 07:39:45.989795 2026] [security2:error] [pid 254995:tid 255195] [client 20.197.192.193:56441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/la.php"] [unique_id "al9Mcf7v0rlcEGmVraFLsQAAA2Q"]
[Tue Jul 21 07:39:46.007519 2026] [security2:error] [pid 255769:tid 255915] [client 20.197.192.193:56424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/nhvoanpl.php"] [unique_id "al9McrxMYwyVGnfuwsKpmwAAA7M"]
[Tue Jul 21 07:39:46.021902 2026] [security2:error] [pid 254995:tid 255190] [client 20.197.192.193:58474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/inso.php"] [unique_id "al9Mcv7v0rlcEGmVraFLswAAA18"]
[Tue Jul 21 07:39:46.042608 2026] [security2:error] [pid 255769:tid 255929] [client 20.197.192.193:49558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wpx.php"] [unique_id "al9McrxMYwyVGnfuwsKpnAAAA8E"]
[Tue Jul 21 07:39:46.061983 2026] [security2:error] [pid 254995:tid 255165] [client 20.197.192.193:56447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/berlin.php"] [unique_id "al9Mcv7v0rlcEGmVraFLtQAAA0Y"]
[Tue Jul 21 07:39:46.083836 2026] [security2:error] [pid 254995:tid 255201] [client 20.197.192.193:58215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/billur.php"] [unique_id "al9Mcv7v0rlcEGmVraFLtwAAA2o"]
[Tue Jul 21 07:39:46.099757 2026] [security2:error] [pid 254995:tid 255155] [client 20.197.192.193:56386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/mimpi.php"] [unique_id "al9Mcv7v0rlcEGmVraFLuAAAAzw"]
[Tue Jul 21 07:39:46.101646 2026] [security2:error] [pid 254995:tid 255215] [client 20.151.10.161:46064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9Mcv7v0rlcEGmVraFLuQAAA3c"]
[Tue Jul 21 07:39:46.116647 2026] [security2:error] [pid 254995:tid 255132] [client 20.197.192.193:56414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/dp.php"] [unique_id "al9Mcv7v0rlcEGmVraFLugAAAyU"]
[Tue Jul 21 07:39:46.131381 2026] [security2:error] [pid 254995:tid 255209] [client 20.197.192.193:56425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/bootstrap.php"] [unique_id "al9Mcv7v0rlcEGmVraFLuwAAA3E"]
[Tue Jul 21 07:39:46.132612 2026] [security2:error] [pid 255769:tid 255987] [client 4.204.201.85:4515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/aaa.php"] [unique_id "al9McrxMYwyVGnfuwsKpngAAA_s"]
[Tue Jul 21 07:39:46.147185 2026] [security2:error] [pid 255769:tid 255938] [client 20.197.192.193:58476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-editor.php"] [unique_id "al9McrxMYwyVGnfuwsKpnwAAA8o"]
[Tue Jul 21 07:39:46.161047 2026] [security2:error] [pid 255769:tid 255971] [client 20.197.192.193:58486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/cro.php"] [unique_id "al9McrxMYwyVGnfuwsKpoAAAA-s"]
[Tue Jul 21 07:39:46.171832 2026] [security2:error] [pid 255769:tid 255924] [client 20.197.192.193:58491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/cron-tab.php"] [unique_id "al9McrxMYwyVGnfuwsKpoQAAA7w"]
[Tue Jul 21 07:39:46.182186 2026] [security2:error] [pid 255769:tid 255984] [client 20.197.192.193:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/koiy.php"] [unique_id "al9McrxMYwyVGnfuwsKpogAAA_g"]
[Tue Jul 21 07:39:46.194868 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.192.193:58202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/hp2.php"] [unique_id "al9McrxMYwyVGnfuwsKpowAABAU"]
[Tue Jul 21 07:39:46.205954 2026] [security2:error] [pid 255769:tid 256021] [client 20.197.192.193:49595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/hp3.php"] [unique_id "al9McrxMYwyVGnfuwsKppAAABBs"]
[Tue Jul 21 07:39:46.215949 2026] [security2:error] [pid 255769:tid 255959] [client 20.197.192.193:56440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/aa1.php"] [unique_id "al9McrxMYwyVGnfuwsKppQAAA98"]
[Tue Jul 21 07:39:46.225470 2026] [security2:error] [pid 255769:tid 255965] [client 20.197.192.193:58455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/acew67.php"] [unique_id "al9McrxMYwyVGnfuwsKppgAAA-U"]
[Tue Jul 21 07:39:46.236576 2026] [security2:error] [pid 255769:tid 255968] [client 20.197.192.193:56434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/bscclapb.php"] [unique_id "al9McrxMYwyVGnfuwsKppwAAA-g"]
[Tue Jul 21 07:39:46.248436 2026] [security2:error] [pid 255769:tid 255932] [client 20.197.192.193:58179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/else1.php"] [unique_id "al9McrxMYwyVGnfuwsKpqAAAA8Q"]
[Tue Jul 21 07:39:46.260723 2026] [security2:error] [pid 255769:tid 255909] [client 20.197.192.193:56417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/tkikikoko.php"] [unique_id "al9McrxMYwyVGnfuwsKpqgAAA60"]
[Tue Jul 21 07:39:46.273231 2026] [security2:error] [pid 255769:tid 255978] [client 20.197.192.193:58203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-Blogs.php"] [unique_id "al9McrxMYwyVGnfuwsKpqwAAA_I"]
[Tue Jul 21 07:39:46.286038 2026] [security2:error] [pid 255769:tid 255966] [client 20.197.192.193:49554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-css.php"] [unique_id "al9McrxMYwyVGnfuwsKprQAAA-Y"]
[Tue Jul 21 07:39:46.302894 2026] [security2:error] [pid 254995:tid 255160] [client 20.197.192.193:58435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-explorer.php"] [unique_id "al9Mcv7v0rlcEGmVraFLvwAAA0E"]
[Tue Jul 21 07:39:46.315899 2026] [security2:error] [pid 254995:tid 255260] [client 20.197.192.193:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/akismet.php"] [unique_id "al9Mcv7v0rlcEGmVraFLwAAAA4o"]
[Tue Jul 21 07:39:46.329835 2026] [security2:error] [pid 255769:tid 255921] [client 20.197.192.193:58216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ace2.php"] [unique_id "al9McrxMYwyVGnfuwsKpsAAAA7k"]
[Tue Jul 21 07:39:46.341440 2026] [security2:error] [pid 255769:tid 256024] [client 20.197.192.193:58185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ms.php"] [unique_id "al9McrxMYwyVGnfuwsKpsQAABB4"]
[Tue Jul 21 07:39:46.413808 2026] [security2:error] [pid 254995:tid 255148] [client 4.204.201.85:49892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/gecko.php"] [unique_id "al9Mcv7v0rlcEGmVraFLwQAAAzU"]
[Tue Jul 21 07:39:46.502576 2026] [security2:error] [pid 254995:tid 255181] [client 20.226.60.151:56282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/miru1.php"] [unique_id "al9Mcv7v0rlcEGmVraFLxAAAA1Y"]
[Tue Jul 21 07:39:46.527840 2026] [security2:error] [pid 255769:tid 256008] [client 62.102.148.187:60760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9McrxMYwyVGnfuwsKptwAABA4"]
[Tue Jul 21 07:39:46.527935 2026] [security2:error] [pid 255769:tid 256008] [client 62.102.148.187:60760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9McrxMYwyVGnfuwsKptwAABA4"]
[Tue Jul 21 07:39:46.706761 2026] [security2:error] [pid 254995:tid 255150] [client 4.204.201.85:49849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/sh3ll.php"] [unique_id "al9Mcv7v0rlcEGmVraFLxwAAAzc"]
[Tue Jul 21 07:39:46.953279 2026] [security2:error] [pid 255769:tid 256011] [client 20.151.10.161:55246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ups.php"] [unique_id "al9McrxMYwyVGnfuwsKpvwAABBE"]
[Tue Jul 21 07:39:46.990821 2026] [security2:error] [pid 255769:tid 256001] [client 4.204.201.85:21732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/pbck.php"] [unique_id "al9McrxMYwyVGnfuwsKpwAAABAc"]
[Tue Jul 21 07:39:47.055793 2026] [security2:error] [pid 255769:tid 255814] [remote 162.19.86.63:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produto-express.com"] [uri "/wp-login.php"] [unique_id "al9Mc7xMYwyVGnfuwsKpwQADtSw"]
[Tue Jul 21 07:39:47.272630 2026] [security2:error] [pid 255769:tid 255987] [client 4.204.201.85:49865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/xiugai.php"] [unique_id "al9Mc7xMYwyVGnfuwsKpxgAAA_s"]
[Tue Jul 21 07:39:47.280862 2026] [security2:error] [pid 254995:tid 255273] [client 59.96.220.140:49478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Mc_7v0rlcEGmVraFL0gAAA5c"]
[Tue Jul 21 07:39:47.281561 2026] [security2:error] [pid 254995:tid 255273] [client 59.96.220.140:49478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Mc_7v0rlcEGmVraFL0gAAA5c"]
[Tue Jul 21 07:39:47.587787 2026] [security2:error] [pid 254995:tid 255111] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mc_7v0rlcEGmVraFL2AADS3M"]
[Tue Jul 21 07:39:47.587922 2026] [security2:error] [pid 254995:tid 255170] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mc_7v0rlcEGmVraFL2AADS3M"]
[Tue Jul 21 07:39:47.602062 2026] [security2:error] [pid 255769:tid 256009] [client 4.204.201.85:21785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/e.php"] [unique_id "al9Mc7xMYwyVGnfuwsKp0wAABA8"]
[Tue Jul 21 07:39:47.624396 2026] [security2:error] [pid 255769:tid 255907] [client 20.197.195.24:48873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/admin.php"] [unique_id "al9Mc7xMYwyVGnfuwsKp1AAAA6s"]
[Tue Jul 21 07:39:47.762978 2026] [security2:error] [pid 255769:tid 255948] [client 103.174.34.15:65260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mc7xMYwyVGnfuwsKp2gAAA9Q"]
[Tue Jul 21 07:39:47.763088 2026] [security2:error] [pid 255769:tid 255948] [client 103.174.34.15:65260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mc7xMYwyVGnfuwsKp2gAAA9Q"]
[Tue Jul 21 07:39:47.818564 2026] [security2:error] [pid 255769:tid 255931] [client 20.151.10.161:53612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k.php"] [unique_id "al9Mc7xMYwyVGnfuwsKp3AAAA8M"]
[Tue Jul 21 07:39:47.901445 2026] [security2:error] [pid 254995:tid 255127] [client 4.204.201.85:21795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/for.php"] [unique_id "al9Mc_7v0rlcEGmVraFL3wAAAyA"]
[Tue Jul 21 07:39:48.036895 2026] [security2:error] [pid 255769:tid 255914] [client 20.151.10.161:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/gettest.php"] [unique_id "al9MdLxMYwyVGnfuwsKp4QAAA7I"]
[Tue Jul 21 07:39:48.166584 2026] [security2:error] [pid 255769:tid 256016] [client 20.151.10.161:55238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k2.php"] [unique_id "al9MdLxMYwyVGnfuwsKp5gAABBY"]
[Tue Jul 21 07:39:48.181774 2026] [security2:error] [pid 255769:tid 255902] [client 4.204.201.85:4447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ssh3ll.php"] [unique_id "al9MdLxMYwyVGnfuwsKp5wAAA6Y"]
[Tue Jul 21 07:39:48.404710 2026] [security2:error] [pid 255769:tid 255915] [client 20.220.225.223:19317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/dp.php"] [unique_id "al9MdLxMYwyVGnfuwsKp6gAAA7M"]
[Tue Jul 21 07:39:48.419096 2026] [security2:error] [pid 255769:tid 255911] [client 20.220.225.223:34301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/track.php"] [unique_id "al9MdLxMYwyVGnfuwsKp6wAAA68"]
[Tue Jul 21 07:39:48.455726 2026] [security2:error] [pid 254995:tid 255269] [client 122.179.91.63:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MdP7v0rlcEGmVraFL6QAAA5M"]
[Tue Jul 21 07:39:48.455990 2026] [security2:error] [pid 254995:tid 255269] [client 122.179.91.63:13666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MdP7v0rlcEGmVraFL6QAAA5M"]
[Tue Jul 21 07:39:48.459314 2026] [security2:error] [pid 255769:tid 255972] [client 139.167.225.182:55878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MdLxMYwyVGnfuwsKp7AAAA-w"]
[Tue Jul 21 07:39:48.459389 2026] [security2:error] [pid 255769:tid 255972] [client 139.167.225.182:55878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MdLxMYwyVGnfuwsKp7AAAA-w"]
[Tue Jul 21 07:39:48.473371 2026] [security2:error] [pid 255769:tid 255997] [client 4.204.201.85:49807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/adminner.php"] [unique_id "al9MdLxMYwyVGnfuwsKp7QAABAM"]
[Tue Jul 21 07:39:48.526632 2026] [security2:error] [pid 255769:tid 255954] [client 117.217.38.194:58421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MdLxMYwyVGnfuwsKp7wAAA9o"]
[Tue Jul 21 07:39:48.526990 2026] [security2:error] [pid 255769:tid 255954] [client 117.217.38.194:58421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MdLxMYwyVGnfuwsKp7wAAA9o"]
[Tue Jul 21 07:39:48.571671 2026] [security2:error] [pid 255769:tid 255983] [client 20.226.60.151:56270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/sump1.php"] [unique_id "al9MdLxMYwyVGnfuwsKp8wAAA_c"]
[Tue Jul 21 07:39:48.697886 2026] [security2:error] [pid 254995:tid 255141] [client 20.151.10.161:53618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k3.php"] [unique_id "al9MdP7v0rlcEGmVraFL7wAAAy4"]
[Tue Jul 21 07:39:48.759348 2026] [security2:error] [pid 254995:tid 255162] [client 4.204.201.85:49795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/82.php"] [unique_id "al9MdP7v0rlcEGmVraFL8AAAA0M"]
[Tue Jul 21 07:39:49.044682 2026] [security2:error] [pid 255769:tid 255978] [client 4.204.201.85:21792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/kir.php"] [unique_id "al9MdbxMYwyVGnfuwsKp-wAAA_I"]
[Tue Jul 21 07:39:49.062093 2026] [security2:error] [pid 254995:tid 255206] [client 20.197.195.24:13062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/themes.php"] [unique_id "al9Mdf7v0rlcEGmVraFL9QAAA28"]
[Tue Jul 21 07:39:49.318780 2026] [security2:error] [pid 254995:tid 255160] [client 4.204.201.85:49870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/up4.php"] [unique_id "al9Mdf7v0rlcEGmVraFL-gAAA0E"]
[Tue Jul 21 07:39:49.499911 2026] [security2:error] [pid 255769:tid 255943] [client 20.197.192.193:6864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-css.php"] [unique_id "al9MdbxMYwyVGnfuwsKqBQAAA88"]
[Tue Jul 21 07:39:49.545836 2026] [security2:error] [pid 254995:tid 255154] [client 20.151.10.161:55251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k4.php"] [unique_id "al9Mdf7v0rlcEGmVraFMBAAAAzs"]
[Tue Jul 21 07:39:49.629700 2026] [security2:error] [pid 255769:tid 255969] [client 4.204.201.85:49917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/xhar.php"] [unique_id "al9MdbxMYwyVGnfuwsKqBwAAA-k"]
[Tue Jul 21 07:39:49.631257 2026] [security2:error] [pid 255769:tid 255964] [client 136.144.33.106:52841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MdbxMYwyVGnfuwsKqBAAAA-Q"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:49.932643 2026] [security2:error] [pid 255769:tid 255908] [client 4.204.201.85:49867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/file1221.php"] [unique_id "al9MdbxMYwyVGnfuwsKqCwAAA6w"]
[Tue Jul 21 07:39:50.057208 2026] [security2:error] [pid 255769:tid 255967] [client 20.151.10.161:53587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/k5.php"] [unique_id "al9MdrxMYwyVGnfuwsKqDAAAA-c"]
[Tue Jul 21 07:39:50.177614 2026] [security2:error] [pid 255769:tid 255784] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MdrxMYwyVGnfuwsKqEgAD_g4"]
[Tue Jul 21 07:39:50.177773 2026] [security2:error] [pid 255769:tid 255990] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MdrxMYwyVGnfuwsKqEgAD_g4"]
[Tue Jul 21 07:39:50.214880 2026] [security2:error] [pid 255769:tid 255987] [client 4.204.201.85:4434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/inx.php"] [unique_id "al9MdrxMYwyVGnfuwsKqEwAAA_s"]
[Tue Jul 21 07:39:50.352408 2026] [autoindex:error] [pid 255769:tid 255956] [client 20.197.195.24:13076] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:50.460415 2026] [security2:error] [pid 255769:tid 255999] [client 20.226.60.151:56203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/file5.php"] [unique_id "al9MdrxMYwyVGnfuwsKqGQAABAU"]
[Tue Jul 21 07:39:50.468658 2026] [security2:error] [pid 255769:tid 255963] [client 20.151.10.161:46065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/simple.php"] [unique_id "al9MdrxMYwyVGnfuwsKqGgAAA-M"]
[Tue Jul 21 07:39:50.492025 2026] [security2:error] [pid 254995:tid 255277] [client 4.204.201.85:49877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/qqqa.php"] [unique_id "al9Mdv7v0rlcEGmVraFMEwAAA5s"]
[Tue Jul 21 07:39:50.548808 2026] [security2:error] [pid 255769:tid 255938] [client 173.24.185.52:63015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MdrxMYwyVGnfuwsKqGwAAA8o"]
[Tue Jul 21 07:39:50.548921 2026] [security2:error] [pid 255769:tid 255938] [client 173.24.185.52:63015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MdrxMYwyVGnfuwsKqGwAAA8o"]
[Tue Jul 21 07:39:50.614769 2026] [security2:error] [pid 255769:tid 255902] [client 106.215.181.8:17151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MdrxMYwyVGnfuwsKqHQAAA6Y"]
[Tue Jul 21 07:39:50.614896 2026] [security2:error] [pid 255769:tid 255902] [client 106.215.181.8:17151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MdrxMYwyVGnfuwsKqHQAAA6Y"]
[Tue Jul 21 07:39:50.644939 2026] [security2:error] [pid 254995:tid 255217] [client 20.151.10.161:55242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/w.php"] [unique_id "al9Mdv7v0rlcEGmVraFMGQAAA3k"]
[Tue Jul 21 07:39:50.791689 2026] [security2:error] [pid 254995:tid 255213] [client 4.204.201.85:4428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/ffffile.php"] [unique_id "al9Mdv7v0rlcEGmVraFMHAAAA3U"]
[Tue Jul 21 07:39:50.929944 2026] [security2:error] [pid 255769:tid 255931] [client 20.197.195.24:13076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/.well-known/about.php"] [unique_id "al9MdrxMYwyVGnfuwsKqJgAAA8M"]
[Tue Jul 21 07:39:51.068713 2026] [security2:error] [pid 254995:tid 255275] [client 4.204.201.85:21770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/wp-firewall.php"] [unique_id "al9Md_7v0rlcEGmVraFMIQAAA5k"]
[Tue Jul 21 07:39:51.342273 2026] [security2:error] [pid 255769:tid 255919] [client 4.204.201.85:21699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "x45consultoria.com.br"] [uri "/reviall.php"] [unique_id "al9Md7xMYwyVGnfuwsKqLgAAA7c"]
[Tue Jul 21 07:39:51.504908 2026] [security2:error] [pid 254995:tid 255165] [client 20.151.10.161:55286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/fpwch.php"] [unique_id "al9Md_7v0rlcEGmVraFMKQAAA0Y"]
[Tue Jul 21 07:39:51.542570 2026] [security2:error] [pid 254995:tid 255137] [client 20.226.60.151:51212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/0xD.php"] [unique_id "al9Md_7v0rlcEGmVraFMKwAAAyo"]
[Tue Jul 21 07:39:51.685637 2026] [security2:error] [pid 255769:tid 255971] [client 20.220.225.223:19300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/old.php"] [unique_id "al9Md7xMYwyVGnfuwsKqNwAAA-s"]
[Tue Jul 21 07:39:51.745399 2026] [security2:error] [pid 255769:tid 255981] [client 20.197.192.193:6656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-explorer.php"] [unique_id "al9Md7xMYwyVGnfuwsKqOQAAA_U"]
[Tue Jul 21 07:39:51.869875 2026] [security2:error] [pid 255769:tid 256022] [client 20.197.195.24:13080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Md7xMYwyVGnfuwsKqOwAABBw"]
[Tue Jul 21 07:39:52.140762 2026] [security2:error] [pid 254995:tid 255209] [client 20.151.10.161:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/w2025.php"] [unique_id "al9MeP7v0rlcEGmVraFMMwAAA3E"]
[Tue Jul 21 07:39:52.329446 2026] [security2:error] [pid 255769:tid 255918] [client 20.151.10.161:45956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xxx.php"] [unique_id "al9MeLxMYwyVGnfuwsKqQQAAA7Y"]
[Tue Jul 21 07:39:52.471163 2026] [security2:error] [pid 255769:tid 255822] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MeLxMYwyVGnfuwsKqQwAD9jQ"]
[Tue Jul 21 07:39:52.471302 2026] [security2:error] [pid 255769:tid 255982] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MeLxMYwyVGnfuwsKqQwAD9jQ"]
[Tue Jul 21 07:39:52.477042 2026] [security2:error] [pid 255769:tid 256021] [client 122.186.204.214:64393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MeLxMYwyVGnfuwsKqRAAABBs"]
[Tue Jul 21 07:39:52.477149 2026] [security2:error] [pid 255769:tid 256021] [client 122.186.204.214:64393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MeLxMYwyVGnfuwsKqRAAABBs"]
[Tue Jul 21 07:39:52.481316 2026] [security2:error] [pid 255769:tid 256018] [client 117.251.86.144:41582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MeLxMYwyVGnfuwsKqRQAABBg"]
[Tue Jul 21 07:39:52.481424 2026] [security2:error] [pid 255769:tid 256018] [client 117.251.86.144:41582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MeLxMYwyVGnfuwsKqRQAABBg"]
[Tue Jul 21 07:39:52.505976 2026] [security2:error] [pid 254995:tid 255187] [client 20.151.10.161:53605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/scxy.php"] [unique_id "al9MeP7v0rlcEGmVraFMPwAAA1w"]
[Tue Jul 21 07:39:52.706668 2026] [security2:error] [pid 254995:tid 255156] [client 20.197.192.193:6985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/akismet.php"] [unique_id "al9MeP7v0rlcEGmVraFMRAAAAz0"]
[Tue Jul 21 07:39:52.724458 2026] [security2:error] [pid 254995:tid 255150] [client 184.75.223.211:49684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MeP7v0rlcEGmVraFMRQAAAzc"]
[Tue Jul 21 07:39:52.724570 2026] [security2:error] [pid 254995:tid 255150] [client 184.75.223.211:49684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MeP7v0rlcEGmVraFMRQAAAzc"]
[Tue Jul 21 07:39:52.791028 2026] [security2:error] [pid 254995:tid 255103] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MeP7v0rlcEGmVraFMSQADNWs"]
[Tue Jul 21 07:39:52.791157 2026] [security2:error] [pid 254995:tid 255148] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MeP7v0rlcEGmVraFMSQADNWs"]
[Tue Jul 21 07:39:53.163126 2026] [access_compat:error] [pid 254995:tid 255273] [client 162.241.63.68:39804] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:39:53.199624 2026] [security2:error] [pid 254995:tid 255278] [client 20.220.225.223:19290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/ms-new.php"] [unique_id "al9Mef7v0rlcEGmVraFMVAAAA5w"]
[Tue Jul 21 07:39:53.281441 2026] [security2:error] [pid 255769:tid 255919] [client 20.197.195.24:13106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wefile.php"] [unique_id "al9MebxMYwyVGnfuwsKqTQAAA7c"]
[Tue Jul 21 07:39:53.299256 2026] [security2:error] [pid 254995:tid 255170] [client 20.151.10.161:12084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/FWAZ.php"] [unique_id "al9Mef7v0rlcEGmVraFMVgAAA0s"]
[Tue Jul 21 07:39:53.461678 2026] [security2:error] [pid 254995:tid 255204] [client 20.226.60.151:23160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Mef7v0rlcEGmVraFMWAAAA20"]
[Tue Jul 21 07:39:53.578596 2026] [security2:error] [pid 254995:tid 255174] [client 20.151.10.161:45916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/hypo.php"] [unique_id "al9Mef7v0rlcEGmVraFMYAAAA08"]
[Tue Jul 21 07:39:53.589865 2026] [security2:error] [pid 255769:tid 255908] [client 37.140.223.122:44515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Md7xMYwyVGnfuwsKqNQAAA6w"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:53.922270 2026] [security2:error] [pid 254995:tid 255038] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mef7v0rlcEGmVraFMZQADIyo"]
[Tue Jul 21 07:39:53.922414 2026] [security2:error] [pid 254995:tid 255130] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mef7v0rlcEGmVraFMZQADIyo"]
[Tue Jul 21 07:39:54.006078 2026] [security2:error] [pid 255769:tid 255948] [client 20.197.192.193:6896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/ace2.php"] [unique_id "al9MerxMYwyVGnfuwsKqWgAAA9Q"]
[Tue Jul 21 07:39:54.014266 2026] [security2:error] [pid 255769:tid 256022] [client 20.197.195.24:13103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9MerxMYwyVGnfuwsKqWwAABBw"]
[Tue Jul 21 07:39:54.037571 2026] [security2:error] [pid 254995:tid 255220] [client 20.151.10.161:53616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/qterm.php"] [unique_id "al9Mev7v0rlcEGmVraFMawAAA3w"]
[Tue Jul 21 07:39:54.109423 2026] [security2:error] [pid 255769:tid 256014] [client 20.220.225.223:34264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/2352356666.php"] [unique_id "al9MerxMYwyVGnfuwsKqXwAABBQ"]
[Tue Jul 21 07:39:54.120537 2026] [security2:error] [pid 254995:tid 255172] [client 20.226.60.151:56236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/fnstall.php"] [unique_id "al9Mev7v0rlcEGmVraFMbwAAA00"]
[Tue Jul 21 07:39:54.275144 2026] [security2:error] [pid 255769:tid 255949] [client 20.151.10.161:46063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/chosen.php"] [unique_id "al9MerxMYwyVGnfuwsKqYwAAA9U"]
[Tue Jul 21 07:39:54.347976 2026] [security2:error] [pid 255769:tid 255842] [remote 45.150.79.142:34728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-login.php"] [unique_id "al9MerxMYwyVGnfuwsKqZQAD5Ug"]
[Tue Jul 21 07:39:54.387980 2026] [security2:error] [pid 255769:tid 255912] [client 196.251.121.187:55287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "fisioevida.com"] [uri "/"] [unique_id "al9MerxMYwyVGnfuwsKqaAAAA7A"]
[Tue Jul 21 07:39:54.566871 2026] [security2:error] [pid 255769:tid 255967] [client 154.192.233.199:58585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MerxMYwyVGnfuwsKqbwAAA-c"]
[Tue Jul 21 07:39:54.567000 2026] [security2:error] [pid 255769:tid 255967] [client 154.192.233.199:58585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MerxMYwyVGnfuwsKqbwAAA-c"]
[Tue Jul 21 07:39:54.635968 2026] [security2:error] [pid 255769:tid 255925] [client 20.151.10.161:55255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/blurbs.php"] [unique_id "al9MerxMYwyVGnfuwsKqcAAAA70"]
[Tue Jul 21 07:39:54.698290 2026] [autoindex:error] [pid 255769:tid 255776] [remote 74.7.227.191:42906] AH01276: Cannot serve directory /home1/imperd48/sabino-tracker.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:54.762664 2026] [security2:error] [pid 255769:tid 255828] [remote 41.76.214.143:58544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9MerxMYwyVGnfuwsKqdAAEEDo"]
[Tue Jul 21 07:39:54.774560 2026] [security2:error] [pid 254995:tid 255194] [client 74.7.228.9:40690] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "sabino-tracker.com.imperdivelbestpromotionofthedaytodayonly.com"] [uri "/cgi-sys/404.html"] [unique_id "al9Mev7v0rlcEGmVraFMgQADYyE"]
[Tue Jul 21 07:39:54.818295 2026] [security2:error] [pid 254995:tid 255062] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mev7v0rlcEGmVraFMgwADSkI"]
[Tue Jul 21 07:39:54.818441 2026] [security2:error] [pid 254995:tid 255169] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mev7v0rlcEGmVraFMgwADSkI"]
[Tue Jul 21 07:39:54.914391 2026] [autoindex:error] [pid 254995:tid 255155] [client 20.197.195.24:13130] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:54.924070 2026] [security2:error] [pid 255769:tid 256009] [client 20.226.60.151:23150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MerxMYwyVGnfuwsKqewAABA8"]
[Tue Jul 21 07:39:54.955201 2026] [security2:error] [pid 255769:tid 256011] [client 20.151.10.161:45928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/als.php"] [unique_id "al9MerxMYwyVGnfuwsKqfAAABBE"]
[Tue Jul 21 07:39:55.167151 2026] [security2:error] [pid 255769:tid 255893] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Me7xMYwyVGnfuwsKqgwAD-Xs"]
[Tue Jul 21 07:39:55.167290 2026] [security2:error] [pid 255769:tid 255985] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Me7xMYwyVGnfuwsKqgwAD-Xs"]
[Tue Jul 21 07:39:55.170934 2026] [autoindex:error] [pid 254995:tid 255181] [client 20.197.195.24:13130] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:55.175835 2026] [security2:error] [pid 255769:tid 256027] [client 74.7.230.43:52430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.app.pedido-online.net"] [uri "/index.php"] [unique_id "al9Me7xMYwyVGnfuwsKqgAAEIVY"]
[Tue Jul 21 07:39:55.182096 2026] [security2:error] [pid 255769:tid 255931] [client 175.45.70.82:53259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Me7xMYwyVGnfuwsKqhAAAA8M"]
[Tue Jul 21 07:39:55.182200 2026] [security2:error] [pid 255769:tid 255931] [client 175.45.70.82:53259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Me7xMYwyVGnfuwsKqhAAAA8M"]
[Tue Jul 21 07:39:55.189229 2026] [security2:error] [pid 254995:tid 255179] [client 20.197.195.24:13130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Me_7v0rlcEGmVraFMiQAAA1Q"]
[Tue Jul 21 07:39:55.247122 2026] [security2:error] [pid 254995:tid 255173] [client 20.151.10.161:55245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/v543.php"] [unique_id "al9Me_7v0rlcEGmVraFMigAAA04"]
[Tue Jul 21 07:39:55.389221 2026] [security2:error] [pid 255769:tid 255914] [client 103.106.20.201:59901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Me7xMYwyVGnfuwsKqigAAA7I"]
[Tue Jul 21 07:39:55.389309 2026] [security2:error] [pid 255769:tid 255914] [client 103.106.20.201:59901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Me7xMYwyVGnfuwsKqigAAA7I"]
[Tue Jul 21 07:39:55.427922 2026] [security2:error] [pid 254995:tid 255166] [client 20.197.192.193:6996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/ms.php"] [unique_id "al9Me_7v0rlcEGmVraFMjgAAA0c"]
[Tue Jul 21 07:39:55.484465 2026] [security2:error] [pid 255769:tid 255977] [client 4.204.201.85:3527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Me7xMYwyVGnfuwsKqjAAAA_E"]
[Tue Jul 21 07:39:55.548275 2026] [security2:error] [pid 254995:tid 255168] [client 122.162.144.145:14064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Me_7v0rlcEGmVraFMjwAAA0k"]
[Tue Jul 21 07:39:55.548402 2026] [security2:error] [pid 254995:tid 255168] [client 122.162.144.145:14064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Me_7v0rlcEGmVraFMjwAAA0k"]
[Tue Jul 21 07:39:55.741963 2026] [security2:error] [pid 254995:tid 255262] [client 152.59.154.239:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Me_7v0rlcEGmVraFMkgAAA4w"]
[Tue Jul 21 07:39:55.746545 2026] [security2:error] [pid 254995:tid 255262] [client 152.59.154.239:63958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Me_7v0rlcEGmVraFMkgAAA4w"]
[Tue Jul 21 07:39:55.814049 2026] [security2:error] [pid 255769:tid 255949] [client 74.7.230.0:51746] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "app.institutocrismonteiro.com.br"] [uri "/index.php"] [unique_id "al9Me7xMYwyVGnfuwsKqkgAD1Uo"]
[Tue Jul 21 07:39:55.850769 2026] [security2:error] [pid 255769:tid 255910] [client 136.144.33.98:36303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Me7xMYwyVGnfuwsKqmQAAA64"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:56.136398 2026] [security2:error] [pid 255769:tid 256017] [client 20.226.60.151:56195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/acp.php"] [unique_id "al9MfLxMYwyVGnfuwsKqvAAABBc"]
[Tue Jul 21 07:39:56.136994 2026] [autoindex:error] [pid 254995:tid 255140] [client 100.50.152.193:5603] AH01276: Cannot serve directory /home2/tropi058/loja.tropicaliaeyewear.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:39:56.205562 2026] [security2:error] [pid 255769:tid 255903] [client 103.86.117.203:61431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MfLxMYwyVGnfuwsKqxAAAA6c"]
[Tue Jul 21 07:39:56.205704 2026] [security2:error] [pid 255769:tid 255903] [client 103.86.117.203:61431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MfLxMYwyVGnfuwsKqxAAAA6c"]
[Tue Jul 21 07:39:56.380484 2026] [security2:error] [pid 255769:tid 255971] [client 20.151.10.161:53588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/w3lls.php"] [unique_id "al9MfLxMYwyVGnfuwsKqyQAAA-s"]
[Tue Jul 21 07:39:56.412061 2026] [security2:error] [pid 255769:tid 255936] [client 20.151.10.161:45889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/pol.php"] [unique_id "al9MfLxMYwyVGnfuwsKqygAAA8g"]
[Tue Jul 21 07:39:56.478134 2026] [security2:error] [pid 255769:tid 255990] [client 124.222.194.8:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "marmorariasolare.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9Me7xMYwyVGnfuwsKqggAAA_4"]
[Tue Jul 21 07:39:56.543291 2026] [security2:error] [pid 255769:tid 255990] [client 124.222.194.8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "marmorariasolare.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9Me7xMYwyVGnfuwsKqggAAA_4"]
[Tue Jul 21 07:39:56.812993 2026] [security2:error] [pid 255769:tid 255999] [client 20.197.195.24:13098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/8.php"] [unique_id "al9MfLxMYwyVGnfuwsKqzwAABAU"]
[Tue Jul 21 07:39:56.816377 2026] [security2:error] [pid 254995:tid 255127] [client 20.151.10.161:53625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-ws68.php"] [unique_id "al9MfP7v0rlcEGmVraFMowAAAyA"]
[Tue Jul 21 07:39:56.904341 2026] [security2:error] [pid 255769:tid 255938] [client 20.226.60.151:23115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/media.php"] [unique_id "al9MfLxMYwyVGnfuwsKq0QAAA8o"]
[Tue Jul 21 07:39:57.013524 2026] [security2:error] [pid 255769:tid 255902] [client 4.204.201.85:3532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MfbxMYwyVGnfuwsKq1QAAA6Y"]
[Tue Jul 21 07:39:57.038399 2026] [security2:error] [pid 255769:tid 255960] [client 20.226.60.151:56279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/mosty.php"] [unique_id "al9MfbxMYwyVGnfuwsKq1gAAA-A"]
[Tue Jul 21 07:39:57.128776 2026] [security2:error] [pid 255769:tid 255939] [client 37.140.223.118:20769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MfLxMYwyVGnfuwsKq0gAAA8s"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:39:57.132475 2026] [security2:error] [pid 255769:tid 256012] [client 20.151.10.161:12077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xyn.php"] [unique_id "al9MfbxMYwyVGnfuwsKq2AAABBI"]
[Tue Jul 21 07:39:57.430757 2026] [security2:error] [pid 255769:tid 255978] [client 59.96.220.140:49983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MfbxMYwyVGnfuwsKq3wAAA_I"]
[Tue Jul 21 07:39:57.432316 2026] [security2:error] [pid 255769:tid 255978] [client 59.96.220.140:49983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MfbxMYwyVGnfuwsKq3wAAA_I"]
[Tue Jul 21 07:39:57.509490 2026] [security2:error] [pid 255769:tid 255974] [client 20.151.10.161:53586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/green3.php"] [unique_id "al9MfbxMYwyVGnfuwsKq4QAAA-4"]
[Tue Jul 21 07:39:57.956720 2026] [security2:error] [pid 255769:tid 255949] [client 103.174.34.15:49353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MfbxMYwyVGnfuwsKq6gAAA9U"]
[Tue Jul 21 07:39:57.956840 2026] [security2:error] [pid 255769:tid 255949] [client 103.174.34.15:49353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MfbxMYwyVGnfuwsKq6gAAA9U"]
[Tue Jul 21 07:39:57.976021 2026] [security2:error] [pid 255769:tid 256020] [client 20.151.10.161:53595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ccs.php"] [unique_id "al9MfbxMYwyVGnfuwsKq6wAABBo"]
[Tue Jul 21 07:39:58.210362 2026] [security2:error] [pid 255769:tid 255992] [client 20.220.225.223:19693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/track.php"] [unique_id "al9MfrxMYwyVGnfuwsKq8AAAA_8"]
[Tue Jul 21 07:39:58.264738 2026] [security2:error] [pid 255769:tid 255816] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MfrxMYwyVGnfuwsKq8QADry4"]
[Tue Jul 21 07:39:58.264925 2026] [security2:error] [pid 255769:tid 255911] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MfrxMYwyVGnfuwsKq8QADry4"]
[Tue Jul 21 07:39:58.280567 2026] [security2:error] [pid 255769:tid 255903] [client 20.151.10.161:45937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file5.php"] [unique_id "al9MfrxMYwyVGnfuwsKq8wAAA6c"]
[Tue Jul 21 07:39:58.285896 2026] [security2:error] [pid 255769:tid 256015] [client 122.164.127.47:62161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MfrxMYwyVGnfuwsKq9AAABBU"]
[Tue Jul 21 07:39:58.286012 2026] [security2:error] [pid 255769:tid 256015] [client 122.164.127.47:62161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MfrxMYwyVGnfuwsKq9AAABBU"]
[Tue Jul 21 07:39:58.523675 2026] [security2:error] [pid 254995:tid 255182] [client 4.204.201.85:7451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/media.php"] [unique_id "al9Mfv7v0rlcEGmVraFMvAAAA1c"]
[Tue Jul 21 07:39:58.702638 2026] [security2:error] [pid 254995:tid 255209] [client 20.226.60.151:22927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/images.php"] [unique_id "al9Mfv7v0rlcEGmVraFMvgAAA3E"]
[Tue Jul 21 07:39:58.977380 2026] [security2:error] [pid 255769:tid 256006] [client 117.217.38.194:58896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MfrxMYwyVGnfuwsKq-QAABAw"]
[Tue Jul 21 07:39:58.977634 2026] [security2:error] [pid 255769:tid 256006] [client 117.217.38.194:58896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MfrxMYwyVGnfuwsKq-QAABAw"]
[Tue Jul 21 07:39:59.109055 2026] [security2:error] [pid 255769:tid 255936] [client 122.179.91.63:18461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mf7xMYwyVGnfuwsKq_AAAA8g"]
[Tue Jul 21 07:39:59.109190 2026] [security2:error] [pid 255769:tid 255936] [client 122.179.91.63:18461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mf7xMYwyVGnfuwsKq_AAAA8g"]
[Tue Jul 21 07:39:59.130713 2026] [security2:error] [pid 254995:tid 255181] [client 20.220.225.223:34296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/pn.php"] [unique_id "al9Mf_7v0rlcEGmVraFMxgAAA1Y"]
[Tue Jul 21 07:39:59.287546 2026] [security2:error] [pid 255769:tid 255963] [client 20.226.60.151:23107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/gecko.php"] [unique_id "al9Mf7xMYwyVGnfuwsKq_gAAA-M"]
[Tue Jul 21 07:39:59.377656 2026] [security2:error] [pid 254995:tid 255187] [client 74.7.228.47:47172] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pedido-online.net"] [uri "/index.php"] [unique_id "al9Mfv7v0rlcEGmVraFMvwADXDE"]
[Tue Jul 21 07:39:59.385502 2026] [security2:error] [pid 255769:tid 255781] [remote 66.249.74.164:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "nerdshoppe.com.br"] [uri "/robots.txt"] [unique_id "al9Mf7xMYwyVGnfuwsKrBAAEFAs"]
[Tue Jul 21 07:39:59.527446 2026] [security2:error] [pid 254995:tid 255212] [client 20.226.60.151:22931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/82.php"] [unique_id "al9Mf_7v0rlcEGmVraFMzAAAA3Q"]
[Tue Jul 21 07:39:59.580419 2026] [security2:error] [pid 254995:tid 255129] [client 20.226.60.151:56285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/6.php"] [unique_id "al9Mf_7v0rlcEGmVraFMzQAAAyI"]
[Tue Jul 21 07:39:59.704442 2026] [security2:error] [pid 255769:tid 255941] [client 20.226.60.151:23136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/admin.php"] [unique_id "al9Mf7xMYwyVGnfuwsKrDAAAA80"]
[Tue Jul 21 07:39:59.758075 2026] [security2:error] [pid 255769:tid 255954] [client 136.144.33.109:55045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Mf7xMYwyVGnfuwsKrDQAAA9o"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:39:59.781546 2026] [security2:error] [pid 254995:tid 255170] [client 20.197.195.24:13133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-content/admin.php"] [unique_id "al9Mf_7v0rlcEGmVraFMzwAAA0s"]
[Tue Jul 21 07:39:59.846409 2026] [security2:error] [pid 255769:tid 255791] [remote 66.249.74.165:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "nerdshoppe.com.br"] [uri "/"] [unique_id "al9Mf7xMYwyVGnfuwsKrDgADrRU"]
[Tue Jul 21 07:39:59.974092 2026] [security2:error] [pid 255769:tid 255972] [client 20.226.60.151:23126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/adminner.php"] [unique_id "al9Mf7xMYwyVGnfuwsKrFQAAA-w"]
[Tue Jul 21 07:39:59.985586 2026] [security2:error] [pid 254995:tid 255200] [client 139.167.225.182:56540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mf_7v0rlcEGmVraFM0wAAA2k"]
[Tue Jul 21 07:39:59.987402 2026] [security2:error] [pid 254995:tid 255200] [client 139.167.225.182:56540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mf_7v0rlcEGmVraFM0wAAA2k"]
[Tue Jul 21 07:40:00.149351 2026] [security2:error] [pid 255769:tid 255992] [client 4.204.201.85:3548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/images.php"] [unique_id "al9MgLxMYwyVGnfuwsKrFgAAA_8"]
[Tue Jul 21 07:40:00.627715 2026] [security2:error] [pid 254995:tid 255126] [client 37.140.223.49:37861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MgP7v0rlcEGmVraFM3wAAAx8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:00.930849 2026] [security2:error] [pid 255769:tid 255959] [client 20.151.10.161:53630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ccc.php"] [unique_id "al9MgLxMYwyVGnfuwsKrHgAAA98"]
[Tue Jul 21 07:40:00.961187 2026] [security2:error] [pid 254995:tid 255012] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MgP7v0rlcEGmVraFM5QADQhA"]
[Tue Jul 21 07:40:00.961378 2026] [security2:error] [pid 254995:tid 255161] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MgP7v0rlcEGmVraFM5QADQhA"]
[Tue Jul 21 07:40:01.163977 2026] [security2:error] [pid 255769:tid 255938] [client 173.24.185.52:63490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MgbxMYwyVGnfuwsKrIgAAA8o"]
[Tue Jul 21 07:40:01.164107 2026] [security2:error] [pid 255769:tid 255938] [client 173.24.185.52:63490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MgbxMYwyVGnfuwsKrIgAAA8o"]
[Tue Jul 21 07:40:01.243655 2026] [security2:error] [pid 254995:tid 255075] [remote 210.211.125.205:45456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.125.211.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moneyclass.com.br"] [uri "/wp-login.php"] [unique_id "al9Mgf7v0rlcEGmVraFM7QADjk8"]
[Tue Jul 21 07:40:01.276071 2026] [security2:error] [pid 255769:tid 255980] [client 184.75.223.211:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MgbxMYwyVGnfuwsKrJQAAA_Q"]
[Tue Jul 21 07:40:01.276161 2026] [security2:error] [pid 255769:tid 255980] [client 184.75.223.211:35376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MgbxMYwyVGnfuwsKrJQAAA_Q"]
[Tue Jul 21 07:40:01.312115 2026] [security2:error] [pid 255769:tid 256006] [client 106.215.181.8:28771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MgbxMYwyVGnfuwsKrJgAABAw"]
[Tue Jul 21 07:40:01.312229 2026] [security2:error] [pid 255769:tid 256006] [client 106.215.181.8:28771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MgbxMYwyVGnfuwsKrJgAABAw"]
[Tue Jul 21 07:40:01.512404 2026] [security2:error] [pid 254995:tid 255199] [client 4.204.201.85:7484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/gecko.php"] [unique_id "al9Mgf7v0rlcEGmVraFM8QAAA2g"]
[Tue Jul 21 07:40:01.646053 2026] [security2:error] [pid 255769:tid 255916] [client 20.151.10.161:53591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/get.php"] [unique_id "al9MgbxMYwyVGnfuwsKrLwAAA7Q"]
[Tue Jul 21 07:40:01.735131 2026] [security2:error] [pid 254995:tid 255132] [client 20.220.225.223:19661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/2352356666.php"] [unique_id "al9Mgf7v0rlcEGmVraFM9QAAAyU"]
[Tue Jul 21 07:40:01.800302 2026] [security2:error] [pid 255769:tid 256001] [client 20.226.60.151:22912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/admin.php"] [unique_id "al9MgbxMYwyVGnfuwsKrMwAABAc"]
[Tue Jul 21 07:40:02.257066 2026] [security2:error] [pid 254995:tid 255175] [client 4.204.201.85:7424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/82.php"] [unique_id "al9Mgv7v0rlcEGmVraFM_wAAA1A"]
[Tue Jul 21 07:40:02.300609 2026] [autoindex:error] [pid 254995:tid 255151] [client 100.50.152.193:22733] AH01276: Cannot serve directory /home2/acupu265/liranesuliano.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:02.341594 2026] [security2:error] [pid 254995:tid 255173] [client 20.151.10.161:55270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/images.php"] [unique_id "al9Mgv7v0rlcEGmVraFNAQAAA04"]
[Tue Jul 21 07:40:02.367488 2026] [security2:error] [pid 255769:tid 255839] [remote 97.74.93.24:44952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-login.php"] [unique_id "al9MgrxMYwyVGnfuwsKrNwAD7EU"]
[Tue Jul 21 07:40:02.543793 2026] [security2:error] [pid 255769:tid 255946] [client 20.226.60.151:23141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/k.php"] [unique_id "al9MgrxMYwyVGnfuwsKrPwAAA9I"]
[Tue Jul 21 07:40:02.797963 2026] [security2:error] [pid 255769:tid 255939] [client 20.151.10.161:53624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/alls.php"] [unique_id "al9MgrxMYwyVGnfuwsKrRgAAA8s"]
[Tue Jul 21 07:40:03.069934 2026] [security2:error] [pid 255769:tid 256003] [client 20.151.10.161:45949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrSAAABAk"]
[Tue Jul 21 07:40:03.137319 2026] [security2:error] [pid 255769:tid 255903] [client 122.186.204.214:64924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrSgAAA6c"]
[Tue Jul 21 07:40:03.137459 2026] [security2:error] [pid 255769:tid 255903] [client 122.186.204.214:64924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrSgAAA6c"]
[Tue Jul 21 07:40:03.141619 2026] [security2:error] [pid 254995:tid 255152] [client 117.251.86.144:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mg_7v0rlcEGmVraFNDAAAAzk"]
[Tue Jul 21 07:40:03.141728 2026] [security2:error] [pid 254995:tid 255152] [client 117.251.86.144:60312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mg_7v0rlcEGmVraFNDAAAAzk"]
[Tue Jul 21 07:40:03.257749 2026] [security2:error] [pid 255769:tid 255978] [client 4.204.201.85:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/admin.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrTgAAA_I"]
[Tue Jul 21 07:40:03.297361 2026] [security2:error] [pid 255769:tid 255998] [client 20.226.60.151:23112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/blurbs.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrTwAABAQ"]
[Tue Jul 21 07:40:03.332217 2026] [security2:error] [pid 254995:tid 255211] [client 20.151.10.161:53606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/yyu.php"] [unique_id "al9Mg_7v0rlcEGmVraFNEwAAA3M"]
[Tue Jul 21 07:40:03.492221 2026] [security2:error] [pid 255769:tid 255872] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrVAADvGY"]
[Tue Jul 21 07:40:03.492359 2026] [security2:error] [pid 255769:tid 255924] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrVAADvGY"]
[Tue Jul 21 07:40:03.494621 2026] [security2:error] [pid 254995:tid 255179] [client 172.245.102.46:42427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Mg_7v0rlcEGmVraFNEQAAA1Q"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:03.545870 2026] [security2:error] [pid 255769:tid 255923] [client 193.36.225.151:48713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrUAAAA7s"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:03.561846 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.561883 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.562446 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Globo-2.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.575052 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.575080 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.575287 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/IstoE.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.588540 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.588548 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.588766 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Terra.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.601061 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.601080 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.601296 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Caras.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.613230 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.613240 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.613462 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Contigo.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.624633 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.624645 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.624860 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Bons-Fluidos.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.637316 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.637330 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.637609 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Boa-Forma.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.649169 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.649192 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.649385 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Globo-2.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.649433 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.649441 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.649712 2026] [lsapi:warn] [pid 254995:tid 255262] [client 100.50.152.193:41479] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Lance.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.661369 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.661380 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.661637 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/IstoE.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.665467 2026] [security2:error] [pid 255769:tid 255954] [client 20.226.60.151:23119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/bajah.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrVgAAA9o"]
[Tue Jul 21 07:40:03.673425 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.673442 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.673629 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Terra.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.685315 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.685331 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.685552 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Caras.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.697537 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.697559 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.697941 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Contigo.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.711712 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.711741 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.712606 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Bons-Fluidos.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.725277 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.725297 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.726028 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Boa-Forma.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.736834 2026] [security2:error] [pid 255769:tid 255916] [client 20.220.225.223:34198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrWwAAA7Q"]
[Tue Jul 21 07:40:03.738923 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.738940 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.739312 2026] [lsapi:warn] [pid 254995:tid 255277] [client 100.50.152.193:27695] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Lance.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:40:03.845595 2026] [security2:error] [pid 255769:tid 255935] [client 4.204.201.85:7444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/adminner.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrXQAAA8c"]
[Tue Jul 21 07:40:03.855370 2026] [security2:error] [pid 255769:tid 255929] [client 20.151.10.161:53590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/by.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrXgAAA8E"]
[Tue Jul 21 07:40:03.932495 2026] [security2:error] [pid 255769:tid 255964] [client 20.226.60.151:56292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9Mg7xMYwyVGnfuwsKrXwAAA-Q"]
[Tue Jul 21 07:40:04.221961 2026] [security2:error] [pid 255769:tid 255985] [client 184.75.223.211:35386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MhLxMYwyVGnfuwsKrZQAAA_k"]
[Tue Jul 21 07:40:04.222063 2026] [security2:error] [pid 255769:tid 255985] [client 184.75.223.211:35386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MhLxMYwyVGnfuwsKrZQAAA_k"]
[Tue Jul 21 07:40:04.265215 2026] [security2:error] [pid 254995:tid 255144] [client 20.226.60.151:22920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/a.php"] [unique_id "al9MhP7v0rlcEGmVraFNIQAAAzE"]
[Tue Jul 21 07:40:04.269550 2026] [security2:error] [pid 255769:tid 255972] [client 20.151.10.161:53617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/FAQ.php"] [unique_id "al9MhLxMYwyVGnfuwsKrZwAAA-w"]
[Tue Jul 21 07:40:04.287518 2026] [security2:error] [pid 254995:tid 255224] [client 4.204.201.85:7425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/admin.php"] [unique_id "al9MhP7v0rlcEGmVraFNIgAAA4A"]
[Tue Jul 21 07:40:04.584614 2026] [security2:error] [pid 254995:tid 255161] [client 20.226.60.151:23142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/edit.php"] [unique_id "al9MhP7v0rlcEGmVraFNJAAAA0I"]
[Tue Jul 21 07:40:04.611343 2026] [security2:error] [pid 254995:tid 255269] [client 4.204.201.85:3545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/k.php"] [unique_id "al9MhP7v0rlcEGmVraFNJQAAA5M"]
[Tue Jul 21 07:40:04.670010 2026] [security2:error] [pid 255769:tid 255885] [remote 41.186.86.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9MhLxMYwyVGnfuwsKrbwAD0nM"]
[Tue Jul 21 07:40:04.670184 2026] [security2:error] [pid 255769:tid 255946] [client 41.186.86.12:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9MhLxMYwyVGnfuwsKrbwAD0nM"]
[Tue Jul 21 07:40:04.767149 2026] [security2:error] [pid 255769:tid 255858] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhLxMYwyVGnfuwsKrcQAD41g"]
[Tue Jul 21 07:40:04.767332 2026] [security2:error] [pid 255769:tid 255963] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhLxMYwyVGnfuwsKrcQAD41g"]
[Tue Jul 21 07:40:04.829970 2026] [security2:error] [pid 254995:tid 255176] [client 20.226.60.151:23134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/hosty.php"] [unique_id "al9MhP7v0rlcEGmVraFNLAAAA1E"]
[Tue Jul 21 07:40:04.952608 2026] [security2:error] [pid 255769:tid 255912] [client 4.204.201.85:7429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/blurbs.php"] [unique_id "al9MhLxMYwyVGnfuwsKrcwAAA7A"]
[Tue Jul 21 07:40:04.954944 2026] [security2:error] [pid 255769:tid 255939] [client 173.252.95.58:40688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9MhLxMYwyVGnfuwsKrdAAAA8s"]
[Tue Jul 21 07:40:05.023613 2026] [security2:error] [pid 255769:tid 255973] [client 20.151.10.161:55232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/coffexium.php"] [unique_id "al9MhbxMYwyVGnfuwsKrdQAAA-0"]
[Tue Jul 21 07:40:05.072723 2026] [security2:error] [pid 255769:tid 255903] [client 20.226.60.151:23138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/k.php"] [unique_id "al9MhbxMYwyVGnfuwsKrdgAAA6c"]
[Tue Jul 21 07:40:05.329233 2026] [security2:error] [pid 254995:tid 255072] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mhf7v0rlcEGmVraFNMQADZ0w"]
[Tue Jul 21 07:40:05.329378 2026] [security2:error] [pid 254995:tid 255198] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mhf7v0rlcEGmVraFNMQADZ0w"]
[Tue Jul 21 07:40:05.415272 2026] [security2:error] [pid 255769:tid 255927] [client 4.204.201.85:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/bajah.php"] [unique_id "al9MhbxMYwyVGnfuwsKrfwAAA78"]
[Tue Jul 21 07:40:05.526789 2026] [security2:error] [pid 254995:tid 255121] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mhf7v0rlcEGmVraFNNAADYH0"]
[Tue Jul 21 07:40:05.526911 2026] [security2:error] [pid 254995:tid 255191] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mhf7v0rlcEGmVraFNNAADYH0"]
[Tue Jul 21 07:40:05.550926 2026] [security2:error] [pid 254995:tid 255133] [client 20.151.10.161:55253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/red.php"] [unique_id "al9Mhf7v0rlcEGmVraFNNwAAAyY"]
[Tue Jul 21 07:40:05.620500 2026] [security2:error] [pid 255769:tid 255990] [client 20.197.195.24:48871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/f6.php"] [unique_id "al9MhbxMYwyVGnfuwsKrxAAAA_4"]
[Tue Jul 21 07:40:05.643181 2026] [security2:error] [pid 255769:tid 255891] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MhbxMYwyVGnfuwsKryAADtnk"]
[Tue Jul 21 07:40:05.643309 2026] [security2:error] [pid 255769:tid 255918] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MhbxMYwyVGnfuwsKryAADtnk"]
[Tue Jul 21 07:40:05.694927 2026] [security2:error] [pid 255769:tid 255913] [client 20.226.60.151:23122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/aaa.php"] [unique_id "al9MhbxMYwyVGnfuwsKrygAAA7E"]
[Tue Jul 21 07:40:05.780026 2026] [security2:error] [pid 255769:tid 255922] [client 4.204.201.85:3539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/a.php"] [unique_id "al9MhbxMYwyVGnfuwsKrzAAAA7o"]
[Tue Jul 21 07:40:05.901494 2026] [security2:error] [pid 255769:tid 255921] [client 175.45.70.82:53774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhbxMYwyVGnfuwsKr0AAAA7k"]
[Tue Jul 21 07:40:05.901587 2026] [security2:error] [pid 255769:tid 255921] [client 175.45.70.82:53774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhbxMYwyVGnfuwsKr0AAAA7k"]
[Tue Jul 21 07:40:06.168486 2026] [security2:error] [pid 255769:tid 255949] [client 4.204.201.85:7450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/edit.php"] [unique_id "al9MhrxMYwyVGnfuwsKsEAAAA9U"]
[Tue Jul 21 07:40:06.184122 2026] [security2:error] [pid 255769:tid 255989] [client 103.106.20.201:60505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhrxMYwyVGnfuwsKsEQAAA_0"]
[Tue Jul 21 07:40:06.184295 2026] [security2:error] [pid 255769:tid 255989] [client 103.106.20.201:60505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhrxMYwyVGnfuwsKsEQAAA_0"]
[Tue Jul 21 07:40:06.257105 2026] [security2:error] [pid 255769:tid 256027] [client 154.192.233.199:60032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhrxMYwyVGnfuwsKsEwAABCE"]
[Tue Jul 21 07:40:06.257232 2026] [security2:error] [pid 255769:tid 256027] [client 154.192.233.199:60032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MhrxMYwyVGnfuwsKsEwAABCE"]
[Tue Jul 21 07:40:06.299762 2026] [security2:error] [pid 255769:tid 255988] [client 20.151.10.161:55236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9MhrxMYwyVGnfuwsKsFQAAA_w"]
[Tue Jul 21 07:40:06.300254 2026] [security2:error] [pid 254995:tid 255259] [client 122.162.144.145:31630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mhv7v0rlcEGmVraFNRwAAA4k"]
[Tue Jul 21 07:40:06.300363 2026] [security2:error] [pid 254995:tid 255259] [client 122.162.144.145:31630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mhv7v0rlcEGmVraFNRwAAA4k"]
[Tue Jul 21 07:40:06.311319 2026] [security2:error] [pid 255769:tid 255983] [client 20.226.60.151:23167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/file5.php"] [unique_id "al9MhrxMYwyVGnfuwsKsFgAAA_c"]
[Tue Jul 21 07:40:06.680068 2026] [security2:error] [pid 254995:tid 255216] [client 103.86.117.203:61956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mhv7v0rlcEGmVraFNTQAAA3g"]
[Tue Jul 21 07:40:06.680210 2026] [security2:error] [pid 254995:tid 255216] [client 103.86.117.203:61956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mhv7v0rlcEGmVraFNTQAAA3g"]
[Tue Jul 21 07:40:06.779047 2026] [security2:error] [pid 255769:tid 255912] [client 184.75.223.211:35394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MhrxMYwyVGnfuwsKsHQAAA7A"]
[Tue Jul 21 07:40:06.779166 2026] [security2:error] [pid 255769:tid 255912] [client 184.75.223.211:35394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MhrxMYwyVGnfuwsKsHQAAA7A"]
[Tue Jul 21 07:40:07.041351 2026] [security2:error] [pid 255769:tid 255967] [client 20.151.10.161:55247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/footer.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsJgAAA-c"]
[Tue Jul 21 07:40:07.108108 2026] [security2:error] [pid 255769:tid 255927] [client 152.59.154.239:64422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsJwAAA78"]
[Tue Jul 21 07:40:07.108208 2026] [security2:error] [pid 255769:tid 255927] [client 152.59.154.239:64422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsJwAAA78"]
[Tue Jul 21 07:40:07.109589 2026] [security2:error] [pid 254995:tid 255254] [client 4.204.201.85:3542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/hosty.php"] [unique_id "al9Mh_7v0rlcEGmVraFNVQAAA4Q"]
[Tue Jul 21 07:40:07.164725 2026] [security2:error] [pid 255769:tid 255986] [client 20.226.60.151:56316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/qqqa.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsKAAAA_o"]
[Tue Jul 21 07:40:07.671732 2026] [security2:error] [pid 254995:tid 255161] [client 20.151.10.161:55234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/index.php"] [unique_id "al9Mh_7v0rlcEGmVraFNXAAAA0I"]
[Tue Jul 21 07:40:07.712984 2026] [security2:error] [pid 255769:tid 255998] [client 4.204.201.85:3524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/k.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsMQAABAQ"]
[Tue Jul 21 07:40:07.910539 2026] [security2:error] [pid 255769:tid 255977] [client 122.164.127.47:63153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsNQAAA_E"]
[Tue Jul 21 07:40:07.910677 2026] [security2:error] [pid 255769:tid 255977] [client 122.164.127.47:63153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsNQAAA_E"]
[Tue Jul 21 07:40:07.943327 2026] [security2:error] [pid 255769:tid 255929] [client 20.226.60.151:22930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/222.php"] [unique_id "al9Mh7xMYwyVGnfuwsKsNgAAA8E"]
[Tue Jul 21 07:40:08.042062 2026] [security2:error] [pid 255769:tid 256009] [client 20.151.10.161:45950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file.php"] [unique_id "al9MiLxMYwyVGnfuwsKsOgAABA8"]
[Tue Jul 21 07:40:08.063822 2026] [security2:error] [pid 255769:tid 256005] [client 20.220.225.223:34210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/dr.php"] [unique_id "al9MiLxMYwyVGnfuwsKsOwAABAs"]
[Tue Jul 21 07:40:08.072217 2026] [security2:error] [pid 254995:tid 255197] [client 193.36.225.73:23425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MiP7v0rlcEGmVraFNYwAAA2Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:08.135747 2026] [security2:error] [pid 254995:tid 255229] [client 20.151.10.161:55239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/zoro.php"] [unique_id "al9MiP7v0rlcEGmVraFNZAAAA4I"]
[Tue Jul 21 07:40:08.198931 2026] [security2:error] [pid 255769:tid 255923] [client 59.96.220.140:50537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MiLxMYwyVGnfuwsKsPwAAA7s"]
[Tue Jul 21 07:40:08.199608 2026] [security2:error] [pid 255769:tid 255923] [client 59.96.220.140:50537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MiLxMYwyVGnfuwsKsPwAAA7s"]
[Tue Jul 21 07:40:08.577361 2026] [security2:error] [pid 255769:tid 255914] [client 4.204.201.85:3540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/aaa.php"] [unique_id "al9MiLxMYwyVGnfuwsKsRQAAA7I"]
[Tue Jul 21 07:40:08.616837 2026] [security2:error] [pid 254995:tid 255199] [client 62.102.148.187:44202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MiP7v0rlcEGmVraFNbQAAA2g"]
[Tue Jul 21 07:40:08.616931 2026] [security2:error] [pid 254995:tid 255199] [client 62.102.148.187:44202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MiP7v0rlcEGmVraFNbQAAA2g"]
[Tue Jul 21 07:40:08.642355 2026] [security2:error] [pid 254995:tid 255185] [client 20.151.10.161:53611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/admin.php"] [unique_id "al9MiP7v0rlcEGmVraFNbgAAA1o"]
[Tue Jul 21 07:40:08.689062 2026] [security2:error] [pid 254995:tid 255198] [client 20.151.10.161:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/cfile.php"] [unique_id "al9MiP7v0rlcEGmVraFNcAAAA2c"]
[Tue Jul 21 07:40:08.856085 2026] [security2:error] [pid 254995:tid 255203] [client 103.174.34.15:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MiP7v0rlcEGmVraFNdAAAA2w"]
[Tue Jul 21 07:40:08.856231 2026] [security2:error] [pid 254995:tid 255203] [client 103.174.34.15:49848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MiP7v0rlcEGmVraFNdAAAA2w"]
[Tue Jul 21 07:40:08.961253 2026] [security2:error] [pid 254995:tid 255087] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MiP7v0rlcEGmVraFNeAADfFs"]
[Tue Jul 21 07:40:08.961435 2026] [security2:error] [pid 254995:tid 255220] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MiP7v0rlcEGmVraFNeAADfFs"]
[Tue Jul 21 07:40:09.235570 2026] [security2:error] [pid 255769:tid 256003] [client 20.151.10.161:53597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/greap.php"] [unique_id "al9MibxMYwyVGnfuwsKsUAAABAk"]
[Tue Jul 21 07:40:09.461397 2026] [security2:error] [pid 255769:tid 255918] [client 117.217.38.194:59369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MibxMYwyVGnfuwsKsUwAAA7Y"]
[Tue Jul 21 07:40:09.461516 2026] [security2:error] [pid 255769:tid 255918] [client 117.217.38.194:59369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MibxMYwyVGnfuwsKsUwAAA7Y"]
[Tue Jul 21 07:40:09.544342 2026] [security2:error] [pid 255769:tid 255798] [remote 217.181.92.1:54319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.92.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9MibxMYwyVGnfuwsKsVwAD1xw"]
[Tue Jul 21 07:40:09.660139 2026] [security2:error] [pid 255769:tid 256028] [client 141.11.107.74:61584] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.rinettoar.com.br"] [uri "/"] [unique_id "al9MibxMYwyVGnfuwsKsWgAABCI"]
[Tue Jul 21 07:40:09.668671 2026] [security2:error] [pid 254995:tid 255173] [client 141.11.107.74:61587] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.rinettoar.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9Mif7v0rlcEGmVraFNfgAAA04"]
[Tue Jul 21 07:40:09.674898 2026] [security2:error] [pid 255769:tid 256010] [client 141.11.107.74:61590] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.rinettoar.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9MibxMYwyVGnfuwsKsWwAABBA"]
[Tue Jul 21 07:40:09.676768 2026] [security2:error] [pid 255769:tid 255978] [client 141.11.107.74:61592] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.rinettoar.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9MibxMYwyVGnfuwsKsXAAAA_I"]
[Tue Jul 21 07:40:09.677555 2026] [security2:error] [pid 255769:tid 255907] [client 141.11.107.74:61589] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.rinettoar.com.br"] [uri "/"] [unique_id "al9MibxMYwyVGnfuwsKsXQAAA6s"]
[Tue Jul 21 07:40:09.678437 2026] [security2:error] [pid 255769:tid 255900] [client 141.11.107.74:61593] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "rinettoar.com.br"] [uri "/"] [unique_id "al9MibxMYwyVGnfuwsKsXgAAA6Q"]
[Tue Jul 21 07:40:09.686706 2026] [security2:error] [pid 254995:tid 255166] [client 141.11.107.74:61595] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.rinettoar.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9Mif7v0rlcEGmVraFNfwAAA0c"]
[Tue Jul 21 07:40:09.690833 2026] [security2:error] [pid 254995:tid 255187] [client 141.11.107.74:61597] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.rinettoar.com.br"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "al9Mif7v0rlcEGmVraFNgAAAA1w"]
[Tue Jul 21 07:40:09.723042 2026] [security2:error] [pid 255769:tid 255934] [client 20.151.10.161:12078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/177.php"] [unique_id "al9MibxMYwyVGnfuwsKsXwAAA8Y"]
[Tue Jul 21 07:40:09.742538 2026] [security2:error] [pid 255769:tid 255939] [client 122.179.91.63:21028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MibxMYwyVGnfuwsKsYAAAA8s"]
[Tue Jul 21 07:40:09.742639 2026] [security2:error] [pid 255769:tid 255939] [client 122.179.91.63:21028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MibxMYwyVGnfuwsKsYAAAA8s"]
[Tue Jul 21 07:40:09.821948 2026] [security2:error] [pid 255769:tid 255937] [client 4.204.201.85:7472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/file5.php"] [unique_id "al9MibxMYwyVGnfuwsKsYgAAA8k"]
[Tue Jul 21 07:40:09.838282 2026] [security2:error] [pid 255769:tid 256018] [client 20.151.10.161:45972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/class-wp.php"] [unique_id "al9MibxMYwyVGnfuwsKsYwAABBg"]
[Tue Jul 21 07:40:10.462147 2026] [security2:error] [pid 255769:tid 256021] [client 139.167.225.182:57205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MirxMYwyVGnfuwsKscAAABBs"]
[Tue Jul 21 07:40:10.462243 2026] [security2:error] [pid 255769:tid 256021] [client 139.167.225.182:57205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MirxMYwyVGnfuwsKscAAABBs"]
[Tue Jul 21 07:40:10.492304 2026] [security2:error] [pid 254995:tid 255196] [client 20.226.60.151:56248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/aunmc.php"] [unique_id "al9Miv7v0rlcEGmVraFNjAAAA2U"]
[Tue Jul 21 07:40:10.501181 2026] [security2:error] [pid 254995:tid 255140] [client 20.151.10.161:55249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/199.php"] [unique_id "al9Miv7v0rlcEGmVraFNjQAAAy0"]
[Tue Jul 21 07:40:10.590545 2026] [security2:error] [pid 254995:tid 255262] [client 4.204.201.85:7464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/222.php"] [unique_id "al9Miv7v0rlcEGmVraFNkAAAA4w"]
[Tue Jul 21 07:40:10.601580 2026] [autoindex:error] [pid 254995:tid 255274] [client 34.76.247.13:58355] AH01276: Cannot serve directory /home2/werley42/impactoensino.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:10.640961 2026] [security2:error] [pid 254995:tid 255271] [client 20.151.10.161:45996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/admin.php"] [unique_id "al9Miv7v0rlcEGmVraFNkgAAA5U"]
[Tue Jul 21 07:40:11.092277 2026] [security2:error] [pid 254995:tid 255254] [client 4.204.201.85:7441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/test.php"] [unique_id "al9Mi_7v0rlcEGmVraFNlgAAA4Q"]
[Tue Jul 21 07:40:11.156440 2026] [security2:error] [pid 254995:tid 255174] [client 20.220.225.223:34212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/2x.php"] [unique_id "al9Mi_7v0rlcEGmVraFNmQAAA08"]
[Tue Jul 21 07:40:11.366157 2026] [security2:error] [pid 254995:tid 255146] [client 94.23.188.192:15744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.prismaseg.com"] [uri "/robots.txt"] [unique_id "al9Mi_7v0rlcEGmVraFNnQAAAzM"]
[Tue Jul 21 07:40:11.366305 2026] [security2:error] [pid 254995:tid 255146] [client 94.23.188.192:15744] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.prismaseg.com"] [uri "/robots.txt"] [unique_id "al9Mi_7v0rlcEGmVraFNnQAAAzM"]
[Tue Jul 21 07:40:11.469499 2026] [security2:error] [pid 254995:tid 255189] [client 20.220.225.223:22493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/la.php"] [unique_id "al9Mi_7v0rlcEGmVraFNnwAAA14"]
[Tue Jul 21 07:40:11.545009 2026] [security2:error] [pid 254995:tid 255184] [client 4.204.201.85:7443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/aaa.php"] [unique_id "al9Mi_7v0rlcEGmVraFNogAAA1k"]
[Tue Jul 21 07:40:11.576970 2026] [security2:error] [pid 255769:tid 255945] [client 20.151.10.161:45933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/aa2.php"] [unique_id "al9Mi7xMYwyVGnfuwsKseQAAA9E"]
[Tue Jul 21 07:40:11.692684 2026] [security2:error] [pid 254995:tid 255269] [client 173.24.185.52:63962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNqgAAA5M"]
[Tue Jul 21 07:40:11.692839 2026] [security2:error] [pid 254995:tid 255269] [client 173.24.185.52:63962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNqgAAA5M"]
[Tue Jul 21 07:40:11.694334 2026] [security2:error] [pid 254995:tid 255199] [client 20.151.10.161:55291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file52.php"] [unique_id "al9Mi_7v0rlcEGmVraFNqwAAA2g"]
[Tue Jul 21 07:40:11.734252 2026] [security2:error] [pid 254995:tid 255185] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Mi_7v0rlcEGmVraFNrAAAA1o"]
[Tue Jul 21 07:40:11.777462 2026] [security2:error] [pid 254995:tid 255015] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNrQADdxM"]
[Tue Jul 21 07:40:11.777665 2026] [security2:error] [pid 254995:tid 255215] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNrQADdxM"]
[Tue Jul 21 07:40:11.831571 2026] [security2:error] [pid 254995:tid 255162] [client 62.102.148.187:44206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNrgAAA0M"]
[Tue Jul 21 07:40:11.831657 2026] [security2:error] [pid 254995:tid 255162] [client 62.102.148.187:44206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNrgAAA0M"]
[Tue Jul 21 07:40:11.932360 2026] [security2:error] [pid 254995:tid 255177] [client 20.226.60.151:51234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/uoocf.php"] [unique_id "al9Mi_7v0rlcEGmVraFNrwAAA1I"]
[Tue Jul 21 07:40:11.933340 2026] [security2:error] [pid 255769:tid 255849] [remote 66.249.79.137:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sejabarbara.com.br"] [uri "/wp-content/uploads/2018/11/xan-griffin-419098-unsplash-1200x675.jpg"] [unique_id "al9Mi7xMYwyVGnfuwsKsewADrk8"]
[Tue Jul 21 07:40:11.958052 2026] [security2:error] [pid 254995:tid 255203] [client 128.127.105.184:38870] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNsAAAA2w"]
[Tue Jul 21 07:40:11.958136 2026] [security2:error] [pid 254995:tid 255203] [client 128.127.105.184:38870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Mi_7v0rlcEGmVraFNsAAAA2w"]
[Tue Jul 21 07:40:12.040447 2026] [security2:error] [pid 255769:tid 256013] [client 106.215.181.8:27734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MjLxMYwyVGnfuwsKsfwAABBM"]
[Tue Jul 21 07:40:12.040587 2026] [security2:error] [pid 255769:tid 256013] [client 106.215.181.8:27734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MjLxMYwyVGnfuwsKsfwAABBM"]
[Tue Jul 21 07:40:12.045688 2026] [security2:error] [pid 255769:tid 255901] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MjLxMYwyVGnfuwsKsgAAAA6U"]
[Tue Jul 21 07:40:12.077685 2026] [security2:error] [pid 255769:tid 255896] [remote 66.249.79.137:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sejabarbara.com.br"] [uri "/robots.txt"] [unique_id "al9MjLxMYwyVGnfuwsKsgQADtn4"]
[Tue Jul 21 07:40:12.318922 2026] [security2:error] [pid 255769:tid 255924] [client 62.102.148.187:44214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9MjLxMYwyVGnfuwsKshAAAA7w"]
[Tue Jul 21 07:40:12.319058 2026] [security2:error] [pid 255769:tid 255924] [client 62.102.148.187:44214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9MjLxMYwyVGnfuwsKshAAAA7w"]
[Tue Jul 21 07:40:12.351530 2026] [security2:error] [pid 254995:tid 255175] [client 20.151.10.161:45901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/ccou.php"] [unique_id "al9MjP7v0rlcEGmVraFNuAAAA1A"]
[Tue Jul 21 07:40:12.451966 2026] [security2:error] [pid 255769:tid 255908] [client 4.204.201.85:7459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/11.php"] [unique_id "al9MjLxMYwyVGnfuwsKsigAAA6w"]
[Tue Jul 21 07:40:12.494546 2026] [security2:error] [pid 255769:tid 255919] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9MjLxMYwyVGnfuwsKsjAAAA7c"]
[Tue Jul 21 07:40:12.610435 2026] [security2:error] [pid 255769:tid 255935] [client 4.204.201.85:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MjLxMYwyVGnfuwsKskQAAA8c"]
[Tue Jul 21 07:40:12.777513 2026] [security2:error] [pid 255769:tid 255964] [client 51.222.168.222:34930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.prismaseg.com"] [uri "/"] [unique_id "al9MjLxMYwyVGnfuwsKskwAAA-Q"]
[Tue Jul 21 07:40:12.777618 2026] [security2:error] [pid 255769:tid 255964] [client 51.222.168.222:34930] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.prismaseg.com"] [uri "/"] [unique_id "al9MjLxMYwyVGnfuwsKskwAAA-Q"]
[Tue Jul 21 07:40:12.804386 2026] [security2:error] [pid 254995:tid 255157] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9MjP7v0rlcEGmVraFNvgAAAz4"]
[Tue Jul 21 07:40:12.886146 2026] [security2:error] [pid 254995:tid 255263] [client 4.204.201.85:59962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MjP7v0rlcEGmVraFNwAAAA40"]
[Tue Jul 21 07:40:13.050605 2026] [security2:error] [pid 255769:tid 255952] [client 4.204.201.85:7428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/mac.php"] [unique_id "al9MjbxMYwyVGnfuwsKslQAAA9g"]
[Tue Jul 21 07:40:13.088602 2026] [security2:error] [pid 254995:tid 255273] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Mjf7v0rlcEGmVraFNxAAAA5c"]
[Tue Jul 21 07:40:13.163328 2026] [security2:error] [pid 254995:tid 255211] [client 4.204.201.85:57441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/x.php"] [unique_id "al9Mjf7v0rlcEGmVraFNyAAAA3M"]
[Tue Jul 21 07:40:13.178054 2026] [security2:error] [pid 255769:tid 255833] [remote 65.111.28.178:49289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9MjbxMYwyVGnfuwsKsmgAD_T8"]
[Tue Jul 21 07:40:13.191332 2026] [security2:error] [pid 255769:tid 255994] [client 20.151.10.161:53603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/122.php"] [unique_id "al9MjbxMYwyVGnfuwsKsmwAABAE"]
[Tue Jul 21 07:40:13.202853 2026] [security2:error] [pid 255769:tid 255990] [client 20.151.10.161:45994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/dr.php"] [unique_id "al9MjbxMYwyVGnfuwsKsnAAAA_4"]
[Tue Jul 21 07:40:13.256955 2026] [security2:error] [pid 254995:tid 255158] [client 193.36.225.151:37565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mjf7v0rlcEGmVraFNygAAAz8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:13.372844 2026] [security2:error] [pid 255769:tid 256015] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9MjbxMYwyVGnfuwsKsnwAABBU"]
[Tue Jul 21 07:40:13.376965 2026] [security2:error] [pid 254995:tid 255262] [client 136.144.33.98:35653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Mjf7v0rlcEGmVraFNywAAA4w"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:13.444150 2026] [security2:error] [pid 255769:tid 255931] [client 4.204.201.85:59941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/mgrr.php"] [unique_id "al9MjbxMYwyVGnfuwsKsoQAAA8M"]
[Tue Jul 21 07:40:13.494584 2026] [security2:error] [pid 254995:tid 255012] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mjf7v0rlcEGmVraFNzgADfxA"]
[Tue Jul 21 07:40:13.494736 2026] [security2:error] [pid 254995:tid 255223] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mjf7v0rlcEGmVraFNzgADfxA"]
[Tue Jul 21 07:40:13.583424 2026] [security2:error] [pid 254995:tid 255258] [client 20.226.60.151:56245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/iywwi.php"] [unique_id "al9Mjf7v0rlcEGmVraFNzwAAA4g"]
[Tue Jul 21 07:40:13.658992 2026] [security2:error] [pid 254995:tid 255210] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Mjf7v0rlcEGmVraFN0QAAA3I"]
[Tue Jul 21 07:40:13.713113 2026] [security2:error] [pid 255769:tid 255987] [client 122.186.204.214:65451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MjbxMYwyVGnfuwsKspAAAA_s"]
[Tue Jul 21 07:40:13.713230 2026] [security2:error] [pid 255769:tid 255987] [client 122.186.204.214:65451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MjbxMYwyVGnfuwsKspAAAA_s"]
[Tue Jul 21 07:40:13.721665 2026] [security2:error] [pid 254995:tid 255130] [client 4.204.201.85:57432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/stdin.php"] [unique_id "al9Mjf7v0rlcEGmVraFN1wAAAyM"]
[Tue Jul 21 07:40:13.855544 2026] [security2:error] [pid 255769:tid 255957] [client 117.251.86.144:41424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MjbxMYwyVGnfuwsKspgAAA90"]
[Tue Jul 21 07:40:13.855675 2026] [security2:error] [pid 255769:tid 255957] [client 117.251.86.144:41424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MjbxMYwyVGnfuwsKspgAAA90"]
[Tue Jul 21 07:40:13.890988 2026] [security2:error] [pid 255769:tid 255965] [client 167.235.143.113:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9MjbxMYwyVGnfuwsKspwAD5QE"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:40:13.943081 2026] [security2:error] [pid 254995:tid 255161] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9Mjf7v0rlcEGmVraFN2wAAA0I"]
[Tue Jul 21 07:40:14.003310 2026] [security2:error] [pid 255769:tid 256012] [client 4.204.201.85:59917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/BDKR28.php"] [unique_id "al9MjrxMYwyVGnfuwsKsqQAABBI"]
[Tue Jul 21 07:40:14.019481 2026] [security2:error] [pid 255769:tid 255945] [client 4.204.201.85:7481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/chosen.php"] [unique_id "al9MjrxMYwyVGnfuwsKsqgAAA9E"]
[Tue Jul 21 07:40:14.204638 2026] [security2:error] [pid 255769:tid 255844] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MjrxMYwyVGnfuwsKssAAD-ko"]
[Tue Jul 21 07:40:14.204806 2026] [security2:error] [pid 255769:tid 255986] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MjrxMYwyVGnfuwsKssAAD-ko"]
[Tue Jul 21 07:40:14.233801 2026] [security2:error] [pid 255769:tid 255968] [client 13.59.248.181:36252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "gradiente.com"] [uri "/robots.txt"] [unique_id "al9MjrxMYwyVGnfuwsKssQAAA-g"]
[Tue Jul 21 07:40:14.236849 2026] [security2:error] [pid 255769:tid 255940] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9MjrxMYwyVGnfuwsKssgAAA8w"]
[Tue Jul 21 07:40:14.265508 2026] [security2:error] [pid 255769:tid 255943] [client 13.59.248.181:36246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "gradiente.com"] [uri "/"] [unique_id "al9MjrxMYwyVGnfuwsKsswAAA88"]
[Tue Jul 21 07:40:14.273484 2026] [security2:error] [pid 255769:tid 255981] [client 13.59.248.181:36260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "gradiente.com"] [uri "/robots.txt"] [unique_id "al9MjrxMYwyVGnfuwsKstAAAA_U"]
[Tue Jul 21 07:40:14.282349 2026] [security2:error] [pid 255769:tid 255961] [client 4.204.201.85:57445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/001.php"] [unique_id "al9MjrxMYwyVGnfuwsKstQAAA-E"]
[Tue Jul 21 07:40:14.445856 2026] [security2:error] [pid 255769:tid 255925] [client 167.235.143.113:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9MjrxMYwyVGnfuwsKstwADvUE"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:40:14.463956 2026] [security2:error] [pid 254995:tid 255137] [client 4.204.201.85:3522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/cream1.php"] [unique_id "al9Mjv7v0rlcEGmVraFN4gAAAyo"]
[Tue Jul 21 07:40:14.486026 2026] [security2:error] [pid 254995:tid 255044] [remote 173.252.95.10:56570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Mjv7v0rlcEGmVraFN4wADkzA"]
[Tue Jul 21 07:40:14.511015 2026] [security2:error] [pid 254995:tid 255199] [client 20.226.60.151:62242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Mjv7v0rlcEGmVraFN5AAAA2g"]
[Tue Jul 21 07:40:14.526209 2026] [security2:error] [pid 255769:tid 255939] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9MjrxMYwyVGnfuwsKsuAAAA8s"]
[Tue Jul 21 07:40:14.558722 2026] [security2:error] [pid 255769:tid 256026] [client 4.204.201.85:61067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/dZ3wP5.php"] [unique_id "al9MjrxMYwyVGnfuwsKsuQAABCA"]
[Tue Jul 21 07:40:14.661680 2026] [security2:error] [pid 255769:tid 255921] [client 20.226.60.151:22928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/test.php"] [unique_id "al9MjrxMYwyVGnfuwsKsugAAA7k"]
[Tue Jul 21 07:40:14.697774 2026] [security2:error] [pid 255769:tid 255916] [client 13.59.248.181:36266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "gradiente.com"] [uri "/ads.txt"] [unique_id "al9MjrxMYwyVGnfuwsKsvgAAA7Q"]
[Tue Jul 21 07:40:14.780327 2026] [security2:error] [pid 255769:tid 255904] [client 13.59.248.181:36284] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.gradiente.com"] [uri "/"] [unique_id "al9MjrxMYwyVGnfuwsKsvwAAA6g"]
[Tue Jul 21 07:40:14.811617 2026] [security2:error] [pid 254995:tid 255178] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Mjv7v0rlcEGmVraFN6wAAA1M"]
[Tue Jul 21 07:40:14.838015 2026] [security2:error] [pid 255769:tid 255988] [client 4.204.201.85:59914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/yup.php"] [unique_id "al9MjrxMYwyVGnfuwsKswgAAA_w"]
[Tue Jul 21 07:40:14.955196 2026] [security2:error] [pid 255769:tid 255947] [client 20.151.10.161:45906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xamp.php"] [unique_id "al9MjrxMYwyVGnfuwsKsxgAAA9M"]
[Tue Jul 21 07:40:15.044040 2026] [security2:error] [pid 255769:tid 255932] [client 20.151.10.161:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/green1.php"] [unique_id "al9Mj7xMYwyVGnfuwsKsygAAA8Q"]
[Tue Jul 21 07:40:15.095650 2026] [security2:error] [pid 255769:tid 255965] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Mj7xMYwyVGnfuwsKszgAAA-U"]
[Tue Jul 21 07:40:15.124028 2026] [security2:error] [pid 255769:tid 255941] [client 4.204.201.85:57464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/X.php"] [unique_id "al9Mj7xMYwyVGnfuwsKs0AAAA80"]
[Tue Jul 21 07:40:15.165746 2026] [security2:error] [pid 255769:tid 255825] [remote 51.158.61.221:38834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Mj7xMYwyVGnfuwsKs0QAD1Dc"]
[Tue Jul 21 07:40:15.192440 2026] [proxy:error] [pid 255769:tid 255982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.192499 2026] [proxy_http:error] [pid 255769:tid 255982] [client 2a03:b0c0:3:d0::d1a:1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.193187 2026] [proxy:error] [pid 255769:tid 255982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.193227 2026] [proxy_http:error] [pid 255769:tid 255982] [client 2a03:b0c0:3:d0::d1a:1:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.303868 2026] [proxy:error] [pid 255769:tid 255974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.303936 2026] [proxy_http:error] [pid 255769:tid 255974] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.304398 2026] [proxy:error] [pid 255769:tid 255974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.304427 2026] [proxy_http:error] [pid 255769:tid 255974] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.311450 2026] [security2:error] [pid 255769:tid 255922] [client 20.220.225.223:19272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/pn.php"] [unique_id "al9Mj7xMYwyVGnfuwsKs3wAAA7o"]
[Tue Jul 21 07:40:15.389698 2026] [security2:error] [pid 255769:tid 255924] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Mj7xMYwyVGnfuwsKs5AAAA7w"]
[Tue Jul 21 07:40:15.400942 2026] [security2:error] [pid 255769:tid 255970] [client 4.204.201.85:57416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/1polka.php"] [unique_id "al9Mj7xMYwyVGnfuwsKs5wAAA-o"]
[Tue Jul 21 07:40:15.403757 2026] [proxy:error] [pid 255769:tid 256010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.403839 2026] [proxy_http:error] [pid 255769:tid 256010] [client 2604:a880:cad:d0::d9d:e001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.404398 2026] [proxy:error] [pid 255769:tid 256010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.404427 2026] [proxy_http:error] [pid 255769:tid 256010] [client 2604:a880:cad:d0::d9d:e001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.413171 2026] [security2:error] [pid 255769:tid 255946] [client 69.171.230.42:64710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Mj7xMYwyVGnfuwsKs3QAAA9I"]
[Tue Jul 21 07:40:15.484882 2026] [security2:error] [pid 255769:tid 255811] [remote 47.128.50.211:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hauptmann.com.br"] [uri "/"] [unique_id "al9Mj7xMYwyVGnfuwsKs7wAD4Ck"]
[Tue Jul 21 07:40:15.545277 2026] [security2:error] [pid 255769:tid 255945] [client 69.171.230.3:61662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Mj7xMYwyVGnfuwsKs4wAAA9E"]
[Tue Jul 21 07:40:15.567169 2026] [security2:error] [pid 254995:tid 255138] [client 20.226.60.151:56267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/gqgsa.php"] [unique_id "al9Mj_7v0rlcEGmVraFN-gAAAys"]
[Tue Jul 21 07:40:15.675470 2026] [security2:error] [pid 255769:tid 256011] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9Mj7xMYwyVGnfuwsKs8wAABBE"]
[Tue Jul 21 07:40:15.678432 2026] [security2:error] [pid 255769:tid 255915] [client 4.204.201.85:57460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/gec.php"] [unique_id "al9Mj7xMYwyVGnfuwsKs9AAAA7M"]
[Tue Jul 21 07:40:15.860548 2026] [proxy:error] [pid 255769:tid 255942] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.860633 2026] [proxy_http:error] [pid 255769:tid 255942] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.861370 2026] [proxy:error] [pid 255769:tid 255942] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:15.861421 2026] [proxy_http:error] [pid 255769:tid 255942] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:15.869304 2026] [security2:error] [pid 254995:tid 255000] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mj_7v0rlcEGmVraFOBAADPgQ"]
[Tue Jul 21 07:40:15.869471 2026] [security2:error] [pid 254995:tid 255157] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mj_7v0rlcEGmVraFOBAADPgQ"]
[Tue Jul 21 07:40:15.878841 2026] [security2:error] [pid 254995:tid 255150] [client 154.192.233.199:60220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mj_7v0rlcEGmVraFOBQAAAzc"]
[Tue Jul 21 07:40:15.878930 2026] [security2:error] [pid 254995:tid 255150] [client 154.192.233.199:60220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mj_7v0rlcEGmVraFOBQAAAzc"]
[Tue Jul 21 07:40:15.942608 2026] [security2:error] [pid 254995:tid 255220] [client 122.164.127.47:63702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mj_7v0rlcEGmVraFOBgAAA3w"]
[Tue Jul 21 07:40:15.944558 2026] [security2:error] [pid 254995:tid 255220] [client 122.164.127.47:63702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mj_7v0rlcEGmVraFOBgAAA3w"]
[Tue Jul 21 07:40:15.954664 2026] [security2:error] [pid 255769:tid 255962] [client 4.204.201.85:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/sky.php"] [unique_id "al9Mj7xMYwyVGnfuwsKtAQAAA-I"]
[Tue Jul 21 07:40:15.959608 2026] [security2:error] [pid 255769:tid 255955] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9Mj7xMYwyVGnfuwsKtAgAAA9s"]
[Tue Jul 21 07:40:16.000830 2026] [proxy:error] [pid 255769:tid 255975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.000885 2026] [proxy_http:error] [pid 255769:tid 255975] [client 2a03:b0c0:3:d0::fef:2001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.001469 2026] [proxy:error] [pid 255769:tid 255975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.001490 2026] [proxy_http:error] [pid 255769:tid 255975] [client 2a03:b0c0:3:d0::fef:2001:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.015707 2026] [security2:error] [pid 255769:tid 256015] [client 173.252.95.12:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9MkLxMYwyVGnfuwsKtBAAABBU"]
[Tue Jul 21 07:40:16.050739 2026] [security2:error] [pid 255769:tid 255932] [client 20.226.60.151:62280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MkLxMYwyVGnfuwsKtBQAAA8Q"]
[Tue Jul 21 07:40:16.201130 2026] [security2:error] [pid 255769:tid 255774] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtBwAEHQQ"]
[Tue Jul 21 07:40:16.201311 2026] [security2:error] [pid 255769:tid 256023] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtBwAEHQQ"]
[Tue Jul 21 07:40:16.236494 2026] [security2:error] [pid 255769:tid 255996] [client 4.204.201.85:46030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/dr.php"] [unique_id "al9MkLxMYwyVGnfuwsKtCQAABAI"]
[Tue Jul 21 07:40:16.244907 2026] [security2:error] [pid 254995:tid 255204] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9MkP7v0rlcEGmVraFOCwAAA20"]
[Tue Jul 21 07:40:16.247311 2026] [security2:error] [pid 255769:tid 256014] [client 4.204.201.85:57412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/fffm.php"] [unique_id "al9MkLxMYwyVGnfuwsKtCgAABBQ"]
[Tue Jul 21 07:40:16.313496 2026] [security2:error] [pid 255769:tid 255911] [client 20.151.10.161:12080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/biufile.php"] [unique_id "al9MkLxMYwyVGnfuwsKtDgAAA68"]
[Tue Jul 21 07:40:16.320112 2026] [security2:error] [pid 254995:tid 255213] [client 20.226.60.151:23111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/aaa.php"] [unique_id "al9MkP7v0rlcEGmVraFOEAAAA3U"]
[Tue Jul 21 07:40:16.398494 2026] [security2:error] [pid 255769:tid 255961] [client 20.220.225.223:19276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9MkLxMYwyVGnfuwsKtEgAAA-E"]
[Tue Jul 21 07:40:16.410259 2026] [proxy:error] [pid 254995:tid 255256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.410324 2026] [proxy_http:error] [pid 254995:tid 255256] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.410948 2026] [proxy:error] [pid 254995:tid 255256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.410986 2026] [proxy_http:error] [pid 254995:tid 255256] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.428787 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.428855 2026] [proxy_http:error] [pid 254995:tid 255147] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.429312 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.429339 2026] [proxy_http:error] [pid 254995:tid 255147] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.494165 2026] [proxy:error] [pid 255769:tid 255900] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.494232 2026] [proxy_http:error] [pid 255769:tid 255900] [client 2604:a880:4:1d0::36c:6000:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.494670 2026] [proxy:error] [pid 255769:tid 255900] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.494706 2026] [proxy_http:error] [pid 255769:tid 255900] [client 2604:a880:4:1d0::36c:6000:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.531701 2026] [security2:error] [pid 254995:tid 255127] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9MkP7v0rlcEGmVraFOFgAAAyA"]
[Tue Jul 21 07:40:16.556334 2026] [security2:error] [pid 255769:tid 256026] [client 4.204.201.85:61077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/sixxis.php"] [unique_id "al9MkLxMYwyVGnfuwsKtGgAABCA"]
[Tue Jul 21 07:40:16.588505 2026] [security2:error] [pid 254995:tid 255128] [client 20.226.60.151:56273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/elbzl.php"] [unique_id "al9MkP7v0rlcEGmVraFOFwAAAyE"]
[Tue Jul 21 07:40:16.589138 2026] [security2:error] [pid 255769:tid 256021] [client 175.45.70.82:54285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtGwAABBs"]
[Tue Jul 21 07:40:16.589255 2026] [security2:error] [pid 255769:tid 256021] [client 175.45.70.82:54285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtGwAABBs"]
[Tue Jul 21 07:40:16.723713 2026] [security2:error] [pid 255769:tid 255795] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtHQAEBBk"]
[Tue Jul 21 07:40:16.723888 2026] [security2:error] [pid 255769:tid 255998] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtHQAEBBk"]
[Tue Jul 21 07:40:16.755519 2026] [proxy:error] [pid 254995:tid 255161] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.755574 2026] [proxy_http:error] [pid 254995:tid 255161] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.756151 2026] [proxy:error] [pid 254995:tid 255161] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.756176 2026] [proxy_http:error] [pid 254995:tid 255161] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.822362 2026] [security2:error] [pid 254995:tid 255205] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9MkP7v0rlcEGmVraFOKgAAA24"]
[Tue Jul 21 07:40:16.836063 2026] [security2:error] [pid 255769:tid 256011] [client 4.204.201.85:57429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/yj09.php"] [unique_id "al9MkLxMYwyVGnfuwsKtIQAABBE"]
[Tue Jul 21 07:40:16.883563 2026] [security2:error] [pid 255769:tid 256001] [client 20.151.10.161:45882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/bless.php"] [unique_id "al9MkLxMYwyVGnfuwsKtIwAABAc"]
[Tue Jul 21 07:40:16.911498 2026] [security2:error] [pid 255769:tid 255948] [client 202.143.127.214:61529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtHgAAA9Q"]
[Tue Jul 21 07:40:16.911637 2026] [security2:error] [pid 255769:tid 255948] [client 202.143.127.214:61529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtHgAAA9Q"]
[Tue Jul 21 07:40:16.936100 2026] [security2:error] [pid 255769:tid 255983] [client 20.197.195.24:13163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/inputs.php"] [unique_id "al9MkLxMYwyVGnfuwsKtJgAAA_c"]
[Tue Jul 21 07:40:16.945067 2026] [security2:error] [pid 255769:tid 256012] [client 122.162.144.145:5766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtJwAABBI"]
[Tue Jul 21 07:40:16.945142 2026] [security2:error] [pid 255769:tid 256012] [client 122.162.144.145:5766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtJwAABBI"]
[Tue Jul 21 07:40:16.980876 2026] [security2:error] [pid 255769:tid 255918] [client 103.106.20.201:61096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtKAAAA7Y"]
[Tue Jul 21 07:40:16.980964 2026] [security2:error] [pid 255769:tid 255918] [client 103.106.20.201:61096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MkLxMYwyVGnfuwsKtKAAAA7Y"]
[Tue Jul 21 07:40:16.990192 2026] [security2:error] [pid 255769:tid 255988] [client 4.204.201.85:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/x.php"] [unique_id "al9MkLxMYwyVGnfuwsKtKQAAA_w"]
[Tue Jul 21 07:40:16.996483 2026] [proxy:error] [pid 255769:tid 255972] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.996531 2026] [proxy_http:error] [pid 255769:tid 255972] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:16.996966 2026] [proxy:error] [pid 255769:tid 255972] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:16.996988 2026] [proxy_http:error] [pid 255769:tid 255972] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.142545 2026] [security2:error] [pid 255769:tid 255947] [client 4.204.201.85:57467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/f900.php"] [unique_id "al9MkbxMYwyVGnfuwsKtMAAAA9M"]
[Tue Jul 21 07:40:17.156799 2026] [security2:error] [pid 255769:tid 255978] [client 103.86.117.203:62487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MkbxMYwyVGnfuwsKtMgAAA_I"]
[Tue Jul 21 07:40:17.156941 2026] [security2:error] [pid 255769:tid 255978] [client 103.86.117.203:62487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MkbxMYwyVGnfuwsKtMgAAA_I"]
[Tue Jul 21 07:40:17.301595 2026] [proxy:error] [pid 254995:tid 255225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.301659 2026] [proxy_http:error] [pid 254995:tid 255225] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.302206 2026] [proxy:error] [pid 254995:tid 255225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.302241 2026] [proxy_http:error] [pid 254995:tid 255225] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.382420 2026] [proxy:error] [pid 255769:tid 255911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.382496 2026] [proxy_http:error] [pid 255769:tid 255911] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.383184 2026] [proxy:error] [pid 255769:tid 255911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.383214 2026] [proxy_http:error] [pid 255769:tid 255911] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.412200 2026] [security2:error] [pid 255769:tid 255961] [client 20.226.60.151:62289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/xyn.php"] [unique_id "al9MkbxMYwyVGnfuwsKtQgAAA-E"]
[Tue Jul 21 07:40:17.418684 2026] [security2:error] [pid 255769:tid 255981] [client 4.204.201.85:61063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ups.php"] [unique_id "al9MkbxMYwyVGnfuwsKtQwAAA_U"]
[Tue Jul 21 07:40:17.481862 2026] [proxy:error] [pid 254995:tid 255162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.481913 2026] [proxy_http:error] [pid 254995:tid 255162] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.482571 2026] [proxy:error] [pid 254995:tid 255162] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.482595 2026] [proxy_http:error] [pid 254995:tid 255162] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.535724 2026] [security2:error] [pid 255769:tid 256026] [client 4.204.201.85:3533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/155.php"] [unique_id "al9MkbxMYwyVGnfuwsKtRgAABCA"]
[Tue Jul 21 07:40:17.650257 2026] [security2:error] [pid 255769:tid 255968] [client 49.13.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9MkbxMYwyVGnfuwsKtSAAD6FQ"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:40:17.652890 2026] [security2:error] [pid 254995:tid 255222] [client 20.151.10.161:46023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file46.php"] [unique_id "al9Mkf7v0rlcEGmVraFOPAAAA34"]
[Tue Jul 21 07:40:17.693435 2026] [security2:error] [pid 254995:tid 255177] [client 27.34.72.65:29601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.72.34.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "heyidiomas.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mkf7v0rlcEGmVraFOPQAAA1I"]
[Tue Jul 21 07:40:17.693553 2026] [security2:error] [pid 254995:tid 255177] [client 27.34.72.65:29601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "heyidiomas.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mkf7v0rlcEGmVraFOPQAAA1I"]
[Tue Jul 21 07:40:17.693833 2026] [security2:error] [pid 255769:tid 255903] [client 4.204.201.85:57469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/k.php"] [unique_id "al9MkbxMYwyVGnfuwsKtSgAAA6c"]
[Tue Jul 21 07:40:17.726296 2026] [security2:error] [pid 255769:tid 255935] [client 20.226.60.151:56243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/adjig.php"] [unique_id "al9MkbxMYwyVGnfuwsKtUwAAA8c"]
[Tue Jul 21 07:40:17.907531 2026] [proxy:error] [pid 255769:tid 255999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.907606 2026] [proxy_http:error] [pid 255769:tid 255999] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.908362 2026] [proxy:error] [pid 255769:tid 255999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:17.908404 2026] [proxy_http:error] [pid 255769:tid 255999] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:17.911163 2026] [security2:error] [pid 255769:tid 255989] [client 62.102.148.187:46980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MkbxMYwyVGnfuwsKtXQAAA_0"]
[Tue Jul 21 07:40:17.911269 2026] [security2:error] [pid 255769:tid 255989] [client 62.102.148.187:46980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9MkbxMYwyVGnfuwsKtXQAAA_0"]
[Tue Jul 21 07:40:17.976285 2026] [security2:error] [pid 254995:tid 255158] [client 4.204.201.85:61072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/k2.php"] [unique_id "al9Mkf7v0rlcEGmVraFOUQAAAz8"]
[Tue Jul 21 07:40:17.984824 2026] [security2:error] [pid 254995:tid 255261] [client 182.8.255.181:21225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mkf7v0rlcEGmVraFOSgAAA4s"]
[Tue Jul 21 07:40:17.984973 2026] [security2:error] [pid 254995:tid 255261] [client 182.8.255.181:21225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mkf7v0rlcEGmVraFOSgAAA4s"]
[Tue Jul 21 07:40:18.193169 2026] [security2:error] [pid 255769:tid 255978] [client 49.13.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9MkrxMYwyVGnfuwsKtZAAD8kI"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:40:18.245923 2026] [access_compat:error] [pid 254995:tid 255118] [remote 206.189.95.232:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:18.255486 2026] [security2:error] [pid 254995:tid 255183] [client 4.204.201.85:59948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/w.php"] [unique_id "al9Mkv7v0rlcEGmVraFOWAAAA1g"]
[Tue Jul 21 07:40:18.284028 2026] [security2:error] [pid 254995:tid 255206] [client 20.151.10.161:45856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/eee.php"] [unique_id "al9Mkv7v0rlcEGmVraFOWgAAA28"]
[Tue Jul 21 07:40:18.336729 2026] [security2:error] [pid 254995:tid 255260] [client 152.59.154.239:64910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mkv7v0rlcEGmVraFOXAAAA4o"]
[Tue Jul 21 07:40:18.336824 2026] [security2:error] [pid 254995:tid 255260] [client 152.59.154.239:64910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mkv7v0rlcEGmVraFOXAAAA4o"]
[Tue Jul 21 07:40:18.381124 2026] [security2:error] [pid 254995:tid 255264] [client 167.99.210.137:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcalendars.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/server-status"] [unique_id "al9Mkv7v0rlcEGmVraFOXgAAA44"]
[Tue Jul 21 07:40:18.382516 2026] [access_compat:error] [pid 255769:tid 255967] [client 165.227.39.235:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:18.398584 2026] [security2:error] [pid 255769:tid 255986] [client 167.99.181.249:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webmail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/server-status"] [unique_id "al9MkrxMYwyVGnfuwsKtagAAA_o"]
[Tue Jul 21 07:40:18.404098 2026] [security2:error] [pid 255769:tid 255946] [client 165.227.39.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webmail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/server-status"] [unique_id "al9MkrxMYwyVGnfuwsKtawAAA9I"]
[Tue Jul 21 07:40:18.430347 2026] [proxy:error] [pid 255769:tid 255951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:18.430404 2026] [proxy_http:error] [pid 255769:tid 255951] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:18.430869 2026] [proxy:error] [pid 255769:tid 255951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:18.430902 2026] [proxy_http:error] [pid 255769:tid 255951] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:18.533938 2026] [security2:error] [pid 255769:tid 256028] [client 4.204.201.85:57431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/fpwch.php"] [unique_id "al9MkrxMYwyVGnfuwsKtcQAABCI"]
[Tue Jul 21 07:40:18.604301 2026] [access_compat:error] [pid 255769:tid 255936] [client 157.245.113.227:0] AH01797: client denied by server configuration: proxy:http://127.0.0.1/cgi-sys/autodiscover.cgi
[Tue Jul 21 07:40:18.609783 2026] [security2:error] [pid 255769:tid 255938] [client 20.226.60.151:23156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/11.php"] [unique_id "al9MkrxMYwyVGnfuwsKtdwAAA8o"]
[Tue Jul 21 07:40:18.634194 2026] [security2:error] [pid 255769:tid 255943] [client 20.151.10.161:53578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wpconf.php"] [unique_id "al9MkrxMYwyVGnfuwsKteQAAA88"]
[Tue Jul 21 07:40:18.704605 2026] [access_compat:error] [pid 255769:tid 255970] [client 64.225.75.246:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:18.706096 2026] [security2:error] [pid 255769:tid 255915] [client 4.204.201.85:3549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ops.php"] [unique_id "al9MkrxMYwyVGnfuwsKtewAAA7M"]
[Tue Jul 21 07:40:18.807051 2026] [proxy:error] [pid 254995:tid 255188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:18.807107 2026] [proxy_http:error] [pid 254995:tid 255188] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:18.807762 2026] [proxy:error] [pid 254995:tid 255188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:18.807793 2026] [proxy_http:error] [pid 254995:tid 255188] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:18.810040 2026] [security2:error] [pid 254995:tid 255270] [client 4.204.201.85:59925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/w2025.php"] [unique_id "al9Mkv7v0rlcEGmVraFOZQAAA5Q"]
[Tue Jul 21 07:40:18.827593 2026] [security2:error] [pid 254995:tid 255154] [client 20.226.60.151:59516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Mkv7v0rlcEGmVraFOZgAAAzs"]
[Tue Jul 21 07:40:18.832645 2026] [access_compat:error] [pid 255769:tid 256026] [client 167.99.181.249:0] AH01797: client denied by server configuration: proxy:http://127.0.0.1/cgi-sys/autodiscover.cgi
[Tue Jul 21 07:40:18.912806 2026] [autoindex:error] [pid 255769:tid 255964] [client 136.107.11.182:57070] AH01276: Cannot serve directory /home4/arcoll06/y.arcoll.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:18.978083 2026] [security2:error] [pid 255769:tid 255997] [client 136.144.33.99:44421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MkbxMYwyVGnfuwsKtVAAABAM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:18.999687 2026] [access_compat:error] [pid 254995:tid 255163] [client 147.182.200.94:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:19.000435 2026] [security2:error] [pid 254995:tid 255157] [client 139.59.143.102:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcontacts.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/server-status"] [unique_id "al9Mkv7v0rlcEGmVraFObQAAAz4"]
[Tue Jul 21 07:40:19.040973 2026] [security2:error] [pid 254995:tid 255266] [client 20.151.10.161:45920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file25.php"] [unique_id "al9Mk_7v0rlcEGmVraFObwAAA5A"]
[Tue Jul 21 07:40:19.090406 2026] [security2:error] [pid 255769:tid 255923] [client 206.81.12.187:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpanel.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/server-status"] [unique_id "al9Mk7xMYwyVGnfuwsKtggAAA7s"]
[Tue Jul 21 07:40:19.091574 2026] [security2:error] [pid 255769:tid 255904] [client 4.204.201.85:57440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/FWAZ.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtgwAAA6g"]
[Tue Jul 21 07:40:19.116736 2026] [access_compat:error] [pid 255769:tid 255810] [remote 167.172.158.128:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:19.142595 2026] [security2:error] [pid 254995:tid 255186] [client 172.245.102.32:34117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MkP7v0rlcEGmVraFOLwAAA1s"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:19.151066 2026] [security2:error] [pid 254995:tid 255211] [client 209.97.180.8:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webdisk.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/server-status"] [unique_id "al9Mk_7v0rlcEGmVraFOcgAAA3M"]
[Tue Jul 21 07:40:19.228742 2026] [access_compat:error] [pid 254995:tid 255191] [client 207.154.197.113:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:19.314753 2026] [security2:error] [pid 255769:tid 255900] [client 59.96.220.140:51072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtiAAAA6Q"]
[Tue Jul 21 07:40:19.315381 2026] [security2:error] [pid 255769:tid 255900] [client 59.96.220.140:51072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtiAAAA6Q"]
[Tue Jul 21 07:40:19.356896 2026] [security2:error] [pid 254995:tid 255158] [client 20.220.225.223:34253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/kq1.php"] [unique_id "al9Mk_7v0rlcEGmVraFOcwAAAz8"]
[Tue Jul 21 07:40:19.367217 2026] [security2:error] [pid 254995:tid 255196] [client 142.93.129.190:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcalendars.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/server-status"] [unique_id "al9Mk_7v0rlcEGmVraFOdAAAA2U"]
[Tue Jul 21 07:40:19.379771 2026] [security2:error] [pid 255769:tid 255989] [client 4.204.201.85:57456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/qterm.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtiQAAA_0"]
[Tue Jul 21 07:40:19.400621 2026] [security2:error] [pid 255769:tid 255990] [client 136.107.11.182:57070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.11.107.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "y.arcoll.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtigAAA_4"]
[Tue Jul 21 07:40:19.464316 2026] [security2:error] [pid 254995:tid 255213] [client 209.38.208.202:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpcontacts.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/server-status"] [unique_id "al9Mk_7v0rlcEGmVraFOfAAAA3U"]
[Tue Jul 21 07:40:19.538649 2026] [security2:error] [pid 255769:tid 255980] [client 20.151.10.161:45825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file48.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtkQAAA_Q"]
[Tue Jul 21 07:40:19.667215 2026] [security2:error] [pid 255769:tid 255979] [client 4.204.201.85:57471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/blurbs.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtlAAAA_M"]
[Tue Jul 21 07:40:19.672867 2026] [security2:error] [pid 255769:tid 255899] [client 20.226.60.151:62210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/patie.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtlgAAA6M"]
[Tue Jul 21 07:40:19.694461 2026] [security2:error] [pid 255769:tid 255928] [client 103.174.34.15:50327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtlwAAA8A"]
[Tue Jul 21 07:40:19.694641 2026] [security2:error] [pid 255769:tid 255928] [client 103.174.34.15:50327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtlwAAA8A"]
[Tue Jul 21 07:40:19.738340 2026] [access_compat:error] [pid 254995:tid 255256] [client 142.93.143.8:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:19.757497 2026] [security2:error] [pid 255769:tid 255791] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtmgAEFRU"]
[Tue Jul 21 07:40:19.757684 2026] [security2:error] [pid 255769:tid 256015] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtmgAEFRU"]
[Tue Jul 21 07:40:19.793987 2026] [security2:error] [pid 254995:tid 255272] [client 20.151.10.161:12063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/mosty.php"] [unique_id "al9Mk_7v0rlcEGmVraFOhQAAA5Y"]
[Tue Jul 21 07:40:19.797303 2026] [security2:error] [pid 255769:tid 255867] [remote 20.153.140.50:60524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/wp-login.php"] [unique_id "al9Mk7xMYwyVGnfuwsKtmwAEG2E"]
[Tue Jul 21 07:40:19.938200 2026] [security2:error] [pid 254995:tid 255149] [client 117.217.38.194:59839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mk_7v0rlcEGmVraFOjwAAAzY"]
[Tue Jul 21 07:40:19.938340 2026] [security2:error] [pid 254995:tid 255149] [client 117.217.38.194:59839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mk_7v0rlcEGmVraFOjwAAAzY"]
[Tue Jul 21 07:40:19.944263 2026] [security2:error] [pid 254995:tid 255171] [client 4.204.201.85:59921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/v543.php"] [unique_id "al9Mk_7v0rlcEGmVraFOkAAAA0w"]
[Tue Jul 21 07:40:19.972867 2026] [security2:error] [pid 254995:tid 255274] [client 20.151.10.161:45893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file6.php"] [unique_id "al9Mk_7v0rlcEGmVraFOkgAAA5g"]
[Tue Jul 21 07:40:20.034270 2026] [security2:error] [pid 255769:tid 255919] [client 164.92.244.132:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "cpanel.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/server-status"] [unique_id "al9MlLxMYwyVGnfuwsKtnwAAA7c"]
[Tue Jul 21 07:40:20.224232 2026] [security2:error] [pid 255769:tid 255968] [client 4.204.201.85:59943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/w3lls.php"] [unique_id "al9MlLxMYwyVGnfuwsKtowAAA-g"]
[Tue Jul 21 07:40:20.254598 2026] [security2:error] [pid 255769:tid 256016] [client 20.226.60.151:59487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MlLxMYwyVGnfuwsKtpQAABBY"]
[Tue Jul 21 07:40:20.318800 2026] [security2:error] [pid 254995:tid 255136] [client 20.151.10.161:45918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/a2.php"] [unique_id "al9MlP7v0rlcEGmVraFOmQAAAyk"]
[Tue Jul 21 07:40:20.320430 2026] [proxy:error] [pid 255769:tid 255934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:20.320496 2026] [proxy_http:error] [pid 255769:tid 255934] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:20.320984 2026] [proxy:error] [pid 255769:tid 255934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:20.321024 2026] [proxy_http:error] [pid 255769:tid 255934] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:20.340037 2026] [security2:error] [pid 255769:tid 255996] [client 20.151.10.161:55237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/dejavu.php"] [unique_id "al9MlLxMYwyVGnfuwsKtrQAABAI"]
[Tue Jul 21 07:40:20.362368 2026] [security2:error] [pid 255769:tid 256010] [client 20.104.96.117:14340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MlLxMYwyVGnfuwsKtrgAABBA"]
[Tue Jul 21 07:40:20.396262 2026] [security2:error] [pid 255769:tid 255904] [client 20.226.60.151:23114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/mac.php"] [unique_id "al9MlLxMYwyVGnfuwsKtsAAAA6g"]
[Tue Jul 21 07:40:20.422349 2026] [security2:error] [pid 255769:tid 255911] [client 122.179.91.63:23299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MlLxMYwyVGnfuwsKttQAAA68"]
[Tue Jul 21 07:40:20.422477 2026] [security2:error] [pid 255769:tid 255911] [client 122.179.91.63:23299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MlLxMYwyVGnfuwsKttQAAA68"]
[Tue Jul 21 07:40:20.501888 2026] [security2:error] [pid 255769:tid 256009] [client 4.204.201.85:59956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-ws68.php"] [unique_id "al9MlLxMYwyVGnfuwsKtuQAABA8"]
[Tue Jul 21 07:40:20.578184 2026] [security2:error] [pid 255769:tid 256018] [client 4.204.201.85:46039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/file31.php"] [unique_id "al9MlLxMYwyVGnfuwsKtvQAABBg"]
[Tue Jul 21 07:40:20.614738 2026] [security2:error] [pid 255769:tid 255980] [client 20.226.60.151:62238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/aa.php"] [unique_id "al9MlLxMYwyVGnfuwsKtvwAAA_Q"]
[Tue Jul 21 07:40:20.624694 2026] [security2:error] [pid 255769:tid 255914] [client 139.167.225.182:57857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MlLxMYwyVGnfuwsKtwAAAA7I"]
[Tue Jul 21 07:40:20.624851 2026] [security2:error] [pid 255769:tid 255914] [client 139.167.225.182:57857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MlLxMYwyVGnfuwsKtwAAAA7I"]
[Tue Jul 21 07:40:20.664164 2026] [security2:error] [pid 255769:tid 256003] [client 20.104.96.117:14608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9MlLxMYwyVGnfuwsKtwwAABAk"]
[Tue Jul 21 07:40:20.694660 2026] [security2:error] [pid 255769:tid 255942] [client 20.151.10.161:45944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/file15.php"] [unique_id "al9MlLxMYwyVGnfuwsKtxAAAA84"]
[Tue Jul 21 07:40:20.743785 2026] [security2:error] [pid 255769:tid 256015] [client 207.154.212.47:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "webdisk.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/server-status"] [unique_id "al9MlLxMYwyVGnfuwsKtxQAABBU"]
[Tue Jul 21 07:40:20.781942 2026] [security2:error] [pid 255769:tid 256021] [client 4.204.201.85:57413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/xyn.php"] [unique_id "al9MlLxMYwyVGnfuwsKtxgAABBs"]
[Tue Jul 21 07:40:20.792278 2026] [security2:error] [pid 255769:tid 255958] [client 20.151.10.161:12055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/aaf.php"] [unique_id "al9MlLxMYwyVGnfuwsKtyQAAA94"]
[Tue Jul 21 07:40:20.894184 2026] [proxy:error] [pid 255769:tid 255933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:20.894255 2026] [proxy_http:error] [pid 255769:tid 255933] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:20.894723 2026] [proxy:error] [pid 255769:tid 255933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:20.894764 2026] [proxy_http:error] [pid 255769:tid 255933] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:20.970343 2026] [security2:error] [pid 254995:tid 255218] [client 20.104.96.117:14372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/media.php"] [unique_id "al9MlP7v0rlcEGmVraFOrAAAA3o"]
[Tue Jul 21 07:40:21.068255 2026] [security2:error] [pid 255769:tid 255921] [client 20.226.60.151:59459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/xyn.php"] [unique_id "al9MlbxMYwyVGnfuwsKt0QAAA7k"]
[Tue Jul 21 07:40:21.069187 2026] [security2:error] [pid 255769:tid 255925] [client 4.204.201.85:59928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/green3.php"] [unique_id "al9MlbxMYwyVGnfuwsKt0gAAA70"]
[Tue Jul 21 07:40:21.184459 2026] [security2:error] [pid 255769:tid 255913] [client 20.151.10.161:45930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/jp.php"] [unique_id "al9MlbxMYwyVGnfuwsKt1AAAA7E"]
[Tue Jul 21 07:40:21.205286 2026] [security2:error] [pid 255769:tid 255998] [client 20.151.10.161:55290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/term.php"] [unique_id "al9MlbxMYwyVGnfuwsKt1QAABAQ"]
[Tue Jul 21 07:40:21.292095 2026] [security2:error] [pid 255769:tid 255905] [client 20.104.96.117:14610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/images.php"] [unique_id "al9MlbxMYwyVGnfuwsKt3QAAA6k"]
[Tue Jul 21 07:40:21.343413 2026] [security2:error] [pid 255769:tid 255926] [client 4.204.201.85:57410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ccc.php"] [unique_id "al9MlbxMYwyVGnfuwsKt3gAAA74"]
[Tue Jul 21 07:40:21.361166 2026] [proxy:error] [pid 254995:tid 255158] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:21.361228 2026] [proxy_http:error] [pid 254995:tid 255158] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:21.361845 2026] [proxy:error] [pid 254995:tid 255158] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:21.361872 2026] [proxy_http:error] [pid 254995:tid 255158] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:21.418494 2026] [security2:error] [pid 255769:tid 255918] [client 20.226.60.151:62224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/xwpg.php"] [unique_id "al9MlbxMYwyVGnfuwsKt4QAAA7Y"]
[Tue Jul 21 07:40:21.439383 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:21.439445 2026] [proxy_http:error] [pid 254995:tid 255184] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:21.440055 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:21.440082 2026] [proxy_http:error] [pid 254995:tid 255184] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:21.495192 2026] [security2:error] [pid 255769:tid 255932] [client 4.204.201.85:7457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/file6.php"] [unique_id "al9MlbxMYwyVGnfuwsKt6AAAA8Q"]
[Tue Jul 21 07:40:21.512820 2026] [proxy:error] [pid 255769:tid 255980] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:21.512880 2026] [proxy_http:error] [pid 255769:tid 255980] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:21.513414 2026] [proxy:error] [pid 255769:tid 255980] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:21.513446 2026] [proxy_http:error] [pid 255769:tid 255980] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:21.671617 2026] [security2:error] [pid 255769:tid 256013] [client 4.204.201.85:57430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/get.php"] [unique_id "al9MlbxMYwyVGnfuwsKt7wAABBM"]
[Tue Jul 21 07:40:21.696905 2026] [security2:error] [pid 255769:tid 256015] [client 20.104.96.117:14347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/gecko.php"] [unique_id "al9MlbxMYwyVGnfuwsKt8QAABBU"]
[Tue Jul 21 07:40:21.768232 2026] [security2:error] [pid 255769:tid 255967] [client 20.226.60.151:59464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/patie.php"] [unique_id "al9MlbxMYwyVGnfuwsKt9AAAA-c"]
[Tue Jul 21 07:40:21.797402 2026] [security2:error] [pid 254995:tid 255159] [client 20.151.10.161:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/f35.php"] [unique_id "al9Mlf7v0rlcEGmVraFOvQAAA0A"]
[Tue Jul 21 07:40:21.849865 2026] [security2:error] [pid 254995:tid 255255] [client 20.151.10.161:12035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ha.php"] [unique_id "al9Mlf7v0rlcEGmVraFOvwAAA4U"]
[Tue Jul 21 07:40:21.850756 2026] [security2:error] [pid 255769:tid 256028] [client 20.226.60.151:23116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/chosen.php"] [unique_id "al9MlbxMYwyVGnfuwsKt-gAABCI"]
[Tue Jul 21 07:40:21.949253 2026] [security2:error] [pid 255769:tid 255945] [client 4.204.201.85:59906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/images.php"] [unique_id "al9MlbxMYwyVGnfuwsKuAQAAA9E"]
[Tue Jul 21 07:40:21.982439 2026] [access_compat:error] [pid 255769:tid 255919] [client 128.199.182.152:0] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:40:21.983703 2026] [security2:error] [pid 255769:tid 255970] [client 20.104.96.117:14365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/82.php"] [unique_id "al9MlbxMYwyVGnfuwsKuBAAAA-o"]
[Tue Jul 21 07:40:22.026142 2026] [security2:error] [pid 255769:tid 255916] [client 20.226.60.151:59470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/aa.php"] [unique_id "al9MlrxMYwyVGnfuwsKuBQAAA7Q"]
[Tue Jul 21 07:40:22.028992 2026] [security2:error] [pid 255769:tid 256010] [client 20.226.60.151:56317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/byp.php"] [unique_id "al9MlrxMYwyVGnfuwsKuBgAABBA"]
[Tue Jul 21 07:40:22.116288 2026] [security2:error] [pid 255769:tid 255996] [client 20.220.225.223:34208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/zzz.php"] [unique_id "al9MlrxMYwyVGnfuwsKuCAAABAI"]
[Tue Jul 21 07:40:22.212945 2026] [proxy:error] [pid 255769:tid 255987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.213022 2026] [proxy_http:error] [pid 255769:tid 255987] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.213557 2026] [proxy:error] [pid 255769:tid 255987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.213580 2026] [proxy_http:error] [pid 255769:tid 255987] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.225191 2026] [security2:error] [pid 254995:tid 255149] [client 4.204.201.85:59963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/alls.php"] [unique_id "al9Mlv7v0rlcEGmVraFOxwAAAzY"]
[Tue Jul 21 07:40:22.260219 2026] [security2:error] [pid 255769:tid 255936] [client 173.24.185.52:64542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MlrxMYwyVGnfuwsKuEgAAA8g"]
[Tue Jul 21 07:40:22.260357 2026] [security2:error] [pid 255769:tid 255936] [client 173.24.185.52:64542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MlrxMYwyVGnfuwsKuEgAAA8g"]
[Tue Jul 21 07:40:22.295357 2026] [security2:error] [pid 255769:tid 255900] [client 20.104.96.117:14386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/admin.php"] [unique_id "al9MlrxMYwyVGnfuwsKuFAAAA6Q"]
[Tue Jul 21 07:40:22.347896 2026] [proxy:error] [pid 254995:tid 255192] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.347969 2026] [proxy_http:error] [pid 254995:tid 255192] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.348718 2026] [proxy:error] [pid 254995:tid 255192] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.348760 2026] [proxy_http:error] [pid 254995:tid 255192] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.385096 2026] [proxy:error] [pid 255769:tid 255965] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.385188 2026] [proxy_http:error] [pid 255769:tid 255965] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.386376 2026] [proxy:error] [pid 255769:tid 255965] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.386422 2026] [proxy_http:error] [pid 255769:tid 255965] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.440523 2026] [security2:error] [pid 255769:tid 255796] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MlrxMYwyVGnfuwsKuGQAEHBo"]
[Tue Jul 21 07:40:22.440673 2026] [security2:error] [pid 255769:tid 256022] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MlrxMYwyVGnfuwsKuGQAEHBo"]
[Tue Jul 21 07:40:22.500583 2026] [security2:error] [pid 254995:tid 255269] [client 4.204.201.85:61057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/coffexium.php"] [unique_id "al9Mlv7v0rlcEGmVraFOzAAAA5M"]
[Tue Jul 21 07:40:22.515599 2026] [security2:error] [pid 255769:tid 255978] [client 20.151.10.161:46034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-load.php"] [unique_id "al9MlrxMYwyVGnfuwsKuIAAAA_I"]
[Tue Jul 21 07:40:22.549628 2026] [core:error] [pid 255769:tid 255910] [client 205.210.31.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:22.549651 2026] [core:error] [pid 255769:tid 255910] [client 205.210.31.172:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:22.632008 2026] [proxy:error] [pid 254995:tid 255133] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.632063 2026] [proxy_http:error] [pid 254995:tid 255133] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.632727 2026] [proxy:error] [pid 254995:tid 255133] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.632753 2026] [proxy_http:error] [pid 254995:tid 255133] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.632973 2026] [security2:error] [pid 255769:tid 256024] [client 20.104.96.117:14346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/adminner.php"] [unique_id "al9MlrxMYwyVGnfuwsKuKQAABB4"]
[Tue Jul 21 07:40:22.753779 2026] [proxy:error] [pid 255769:tid 255940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.753859 2026] [proxy_http:error] [pid 255769:tid 255940] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.754354 2026] [proxy:error] [pid 255769:tid 255940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.754386 2026] [proxy_http:error] [pid 255769:tid 255940] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.754868 2026] [security2:error] [pid 255769:tid 255934] [client 106.215.181.8:29964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MlrxMYwyVGnfuwsKuMQAAA8Y"]
[Tue Jul 21 07:40:22.754989 2026] [security2:error] [pid 255769:tid 255934] [client 106.215.181.8:29964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MlrxMYwyVGnfuwsKuMQAAA8Y"]
[Tue Jul 21 07:40:22.766161 2026] [security2:error] [pid 255769:tid 255943] [client 20.226.60.151:59435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/xwpg.php"] [unique_id "al9MlrxMYwyVGnfuwsKuMgAAA88"]
[Tue Jul 21 07:40:22.781591 2026] [security2:error] [pid 254995:tid 255162] [client 4.204.201.85:59961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/red.php"] [unique_id "al9Mlv7v0rlcEGmVraFO1AAAA0M"]
[Tue Jul 21 07:40:22.812881 2026] [security2:error] [pid 255769:tid 255979] [client 172.245.102.46:59041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MlrxMYwyVGnfuwsKuNgAAA_M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:22.943605 2026] [proxy:error] [pid 255769:tid 255904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.943689 2026] [proxy_http:error] [pid 255769:tid 255904] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.944825 2026] [proxy:error] [pid 255769:tid 255904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:22.944880 2026] [proxy_http:error] [pid 255769:tid 255904] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:22.947068 2026] [security2:error] [pid 255769:tid 255983] [client 20.226.60.151:23117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/cream1.php"] [unique_id "al9MlrxMYwyVGnfuwsKuOQAAA_c"]
[Tue Jul 21 07:40:23.071275 2026] [security2:error] [pid 254995:tid 255181] [client 20.104.96.117:14366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/admin.php"] [unique_id "al9Ml_7v0rlcEGmVraFO3AAAA1Y"]
[Tue Jul 21 07:40:23.076297 2026] [autoindex:error] [pid 254995:tid 255177] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:23.153074 2026] [security2:error] [pid 255769:tid 256026] [client 20.226.60.151:62276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ops.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuRwAABCA"]
[Tue Jul 21 07:40:23.230536 2026] [security2:error] [pid 254995:tid 255214] [client 20.151.10.161:53594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/hur.php"] [unique_id "al9Ml_7v0rlcEGmVraFO3wAAA3Y"]
[Tue Jul 21 07:40:23.347137 2026] [security2:error] [pid 255769:tid 255978] [client 20.151.10.161:45908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xwpg.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuTAAAA_I"]
[Tue Jul 21 07:40:23.350117 2026] [security2:error] [pid 254995:tid 255212] [client 4.204.201.85:57453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9Ml_7v0rlcEGmVraFO4wAAA3Q"]
[Tue Jul 21 07:40:23.404303 2026] [security2:error] [pid 255769:tid 256021] [client 20.104.96.117:14368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/k.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuUQAABBs"]
[Tue Jul 21 07:40:23.419594 2026] [security2:error] [pid 255769:tid 255967] [client 128.127.105.184:43618] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuUgAAA-c"]
[Tue Jul 21 07:40:23.419671 2026] [security2:error] [pid 255769:tid 255967] [client 128.127.105.184:43618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuUgAAA-c"]
[Tue Jul 21 07:40:23.466051 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.466116 2026] [proxy_http:error] [pid 254995:tid 255176] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.466661 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.466684 2026] [proxy_http:error] [pid 254995:tid 255176] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.588475 2026] [proxy:error] [pid 255769:tid 255946] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.588532 2026] [proxy_http:error] [pid 255769:tid 255946] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.588947 2026] [proxy:error] [pid 255769:tid 255946] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.588974 2026] [proxy_http:error] [pid 255769:tid 255946] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.649874 2026] [autoindex:error] [pid 254995:tid 255129] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:23.685133 2026] [security2:error] [pid 255769:tid 256028] [client 20.104.96.117:14359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/blurbs.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuYQAABCI"]
[Tue Jul 21 07:40:23.705489 2026] [security2:error] [pid 255769:tid 255970] [client 20.220.225.223:31742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuYgAAA-o"]
[Tue Jul 21 07:40:23.733425 2026] [proxy:error] [pid 254995:tid 255213] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.733499 2026] [proxy_http:error] [pid 254995:tid 255213] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.734493 2026] [proxy:error] [pid 254995:tid 255213] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.734535 2026] [proxy_http:error] [pid 254995:tid 255213] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.865109 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.865169 2026] [proxy_http:error] [pid 255769:tid 255964] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.865612 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.865636 2026] [proxy_http:error] [pid 255769:tid 255964] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.884640 2026] [security2:error] [pid 255769:tid 255949] [client 20.226.60.151:56237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9Ml7xMYwyVGnfuwsKuZwAAA9U"]
[Tue Jul 21 07:40:23.936124 2026] [autoindex:error] [pid 255769:tid 256012] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:23.969835 2026] [proxy:error] [pid 255769:tid 255989] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.969896 2026] [proxy_http:error] [pid 255769:tid 255989] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:23.970332 2026] [proxy:error] [pid 255769:tid 255989] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:23.970358 2026] [proxy_http:error] [pid 255769:tid 255989] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.007772 2026] [security2:error] [pid 254995:tid 255008] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmP7v0rlcEGmVraFO9wADMAw"]
[Tue Jul 21 07:40:24.007909 2026] [security2:error] [pid 254995:tid 255143] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmP7v0rlcEGmVraFO9wADMAw"]
[Tue Jul 21 07:40:24.011271 2026] [security2:error] [pid 255769:tid 255924] [client 20.104.96.117:14397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/bajah.php"] [unique_id "al9MmLxMYwyVGnfuwsKucAAAA7w"]
[Tue Jul 21 07:40:24.076548 2026] [security2:error] [pid 255769:tid 255988] [client 4.204.201.85:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-content/index.php"] [unique_id "al9MmLxMYwyVGnfuwsKucgAAA_w"]
[Tue Jul 21 07:40:24.093278 2026] [proxy:error] [pid 255769:tid 255900] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.093344 2026] [proxy_http:error] [pid 255769:tid 255900] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.093953 2026] [proxy:error] [pid 255769:tid 255900] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.093980 2026] [proxy_http:error] [pid 255769:tid 255900] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.189250 2026] [security2:error] [pid 255769:tid 255972] [client 4.204.201.85:3551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/adminfuns.php"] [unique_id "al9MmLxMYwyVGnfuwsKudwAAA-w"]
[Tue Jul 21 07:40:24.289581 2026] [autoindex:error] [pid 255769:tid 255947] [client 20.226.60.151:23113] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:24.291727 2026] [security2:error] [pid 255769:tid 256003] [client 20.104.96.117:14602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/a.php"] [unique_id "al9MmLxMYwyVGnfuwsKufAAABAk"]
[Tue Jul 21 07:40:24.301750 2026] [security2:error] [pid 255769:tid 255975] [client 165.227.39.235:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al9MmLxMYwyVGnfuwsKufgAAA-8"]
[Tue Jul 21 07:40:24.344708 2026] [proxy:error] [pid 255769:tid 255901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.344786 2026] [proxy_http:error] [pid 255769:tid 255901] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.345738 2026] [proxy:error] [pid 255769:tid 255901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.345775 2026] [proxy_http:error] [pid 255769:tid 255901] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.351878 2026] [security2:error] [pid 255769:tid 256015] [client 4.204.201.85:59912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/admin.php"] [unique_id "al9MmLxMYwyVGnfuwsKuhwAABBU"]
[Tue Jul 21 07:40:24.353359 2026] [autoindex:error] [pid 255769:tid 255974] [client 20.226.60.151:23113] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:24.358607 2026] [security2:error] [pid 255769:tid 256021] [client 20.226.60.151:23113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/dr.php"] [unique_id "al9MmLxMYwyVGnfuwsKuiAAABBs"]
[Tue Jul 21 07:40:24.408827 2026] [security2:error] [pid 255769:tid 255986] [client 167.99.181.249:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al9MmLxMYwyVGnfuwsKujQAAA_o"]
[Tue Jul 21 07:40:24.412488 2026] [security2:error] [pid 254995:tid 255223] [client 122.186.204.214:49602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MmP7v0rlcEGmVraFPAAAAA38"]
[Tue Jul 21 07:40:24.412677 2026] [security2:error] [pid 254995:tid 255223] [client 122.186.204.214:49602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MmP7v0rlcEGmVraFPAAAAA38"]
[Tue Jul 21 07:40:24.444872 2026] [proxy:error] [pid 255769:tid 255951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.444946 2026] [proxy_http:error] [pid 255769:tid 255951] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.445616 2026] [proxy:error] [pid 255769:tid 255951] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.445654 2026] [proxy_http:error] [pid 255769:tid 255951] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.479903 2026] [security2:error] [pid 255769:tid 256016] [client 117.251.86.144:41610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MmLxMYwyVGnfuwsKukAAABBY"]
[Tue Jul 21 07:40:24.480024 2026] [security2:error] [pid 255769:tid 256016] [client 117.251.86.144:41610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MmLxMYwyVGnfuwsKukAAABBY"]
[Tue Jul 21 07:40:24.558924 2026] [security2:error] [pid 255769:tid 255919] [client 4.204.201.85:7473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/goods.php"] [unique_id "al9MmLxMYwyVGnfuwsKuoAAAA7c"]
[Tue Jul 21 07:40:24.626954 2026] [security2:error] [pid 255769:tid 255998] [client 4.204.201.85:59946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/177.php"] [unique_id "al9MmLxMYwyVGnfuwsKutQAABAQ"]
[Tue Jul 21 07:40:24.641865 2026] [security2:error] [pid 255769:tid 255923] [client 20.151.10.161:45907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/waf.php"] [unique_id "al9MmLxMYwyVGnfuwsKuuwAAA7s"]
[Tue Jul 21 07:40:24.656926 2026] [security2:error] [pid 255769:tid 255938] [client 20.104.96.117:14615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/edit.php"] [unique_id "al9MmLxMYwyVGnfuwsKuvAAAA8o"]
[Tue Jul 21 07:40:24.677415 2026] [security2:error] [pid 254995:tid 255206] [client 165.227.39.235:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MmP7v0rlcEGmVraFPAwAAA28"]
[Tue Jul 21 07:40:24.697661 2026] [proxy:error] [pid 254995:tid 255263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.697717 2026] [proxy_http:error] [pid 254995:tid 255263] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.698199 2026] [proxy:error] [pid 254995:tid 255263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.698225 2026] [proxy_http:error] [pid 254995:tid 255263] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.744268 2026] [proxy:error] [pid 254995:tid 255141] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.744326 2026] [proxy_http:error] [pid 254995:tid 255141] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.744754 2026] [proxy:error] [pid 254995:tid 255141] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:24.744785 2026] [proxy_http:error] [pid 254995:tid 255141] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:24.858937 2026] [security2:error] [pid 255769:tid 255831] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmLxMYwyVGnfuwsKuxQAEIj0"]
[Tue Jul 21 07:40:24.859093 2026] [security2:error] [pid 255769:tid 256028] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmLxMYwyVGnfuwsKuxQAEIj0"]
[Tue Jul 21 07:40:24.904667 2026] [security2:error] [pid 255769:tid 255935] [client 20.226.60.151:62334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/mac.php"] [unique_id "al9MmLxMYwyVGnfuwsKuxgAAA8c"]
[Tue Jul 21 07:40:24.905393 2026] [security2:error] [pid 255769:tid 255918] [client 4.204.201.85:57457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/199.php"] [unique_id "al9MmLxMYwyVGnfuwsKuxwAAA7Y"]
[Tue Jul 21 07:40:24.978246 2026] [security2:error] [pid 255769:tid 255924] [client 20.104.96.117:14620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/hosty.php"] [unique_id "al9MmLxMYwyVGnfuwsKu0gAAA7w"]
[Tue Jul 21 07:40:25.009073 2026] [security2:error] [pid 255769:tid 255988] [client 4.204.201.85:7463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/100.php"] [unique_id "al9MmbxMYwyVGnfuwsKu1AAAA_w"]
[Tue Jul 21 07:40:25.055074 2026] [proxy:error] [pid 255769:tid 255976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.055138 2026] [proxy_http:error] [pid 255769:tid 255976] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.055577 2026] [proxy:error] [pid 255769:tid 255976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.055599 2026] [proxy_http:error] [pid 255769:tid 255976] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.077379 2026] [security2:error] [pid 255769:tid 256019] [client 20.226.60.151:59396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ops.php"] [unique_id "al9MmbxMYwyVGnfuwsKu2gAABBk"]
[Tue Jul 21 07:40:25.174389 2026] [security2:error] [pid 254995:tid 255156] [client 74.7.244.15:55996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "memoriabalaiodaoxum.com.br"] [uri "/robots.txt"] [unique_id "al9Mmf7v0rlcEGmVraFPFwADPQE"]
[Tue Jul 21 07:40:25.185864 2026] [security2:error] [pid 255769:tid 255942] [client 4.204.201.85:57444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/file52.php"] [unique_id "al9MmbxMYwyVGnfuwsKu3gAAA84"]
[Tue Jul 21 07:40:25.195013 2026] [security2:error] [pid 254995:tid 255177] [client 69.171.230.116:55282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Mmf7v0rlcEGmVraFPFQAAA1I"]
[Tue Jul 21 07:40:25.249746 2026] [proxy:error] [pid 254995:tid 255168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.249838 2026] [proxy_http:error] [pid 254995:tid 255168] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.250510 2026] [proxy:error] [pid 254995:tid 255168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.250548 2026] [proxy_http:error] [pid 254995:tid 255168] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.275768 2026] [proxy:error] [pid 255769:tid 256014] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.275854 2026] [proxy_http:error] [pid 255769:tid 256014] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.276515 2026] [proxy:error] [pid 255769:tid 256014] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.276540 2026] [proxy_http:error] [pid 255769:tid 256014] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.317185 2026] [security2:error] [pid 254995:tid 255211] [client 20.104.96.117:14342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/k.php"] [unique_id "al9Mmf7v0rlcEGmVraFPIQAAA3M"]
[Tue Jul 21 07:40:25.320595 2026] [security2:error] [pid 255769:tid 255836] [remote 212.80.9.235:38622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "trconsultcontabilidade.com"] [uri "/wp-login.php"] [unique_id "al9MmbxMYwyVGnfuwsKu5gAEB0I"]
[Tue Jul 21 07:40:25.340407 2026] [security2:error] [pid 255769:tid 255978] [client 157.245.113.227:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MmbxMYwyVGnfuwsKu5wAAA_I"]
[Tue Jul 21 07:40:25.362919 2026] [security2:error] [pid 255769:tid 255910] [client 167.99.181.249:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MmbxMYwyVGnfuwsKu6AAAA64"]
[Tue Jul 21 07:40:25.402684 2026] [security2:error] [pid 255769:tid 255946] [client 20.151.10.161:46061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/xstelth.php"] [unique_id "al9MmbxMYwyVGnfuwsKu6gAAA9I"]
[Tue Jul 21 07:40:25.462163 2026] [security2:error] [pid 255769:tid 255908] [client 4.204.201.85:57436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/geck.php"] [unique_id "al9MmbxMYwyVGnfuwsKu7QAAA6w"]
[Tue Jul 21 07:40:25.530587 2026] [security2:error] [pid 254995:tid 255258] [client 128.127.105.184:43634] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mmf7v0rlcEGmVraFPIwAAA4g"]
[Tue Jul 21 07:40:25.530686 2026] [security2:error] [pid 254995:tid 255258] [client 128.127.105.184:43634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mmf7v0rlcEGmVraFPIwAAA4g"]
[Tue Jul 21 07:40:25.567782 2026] [security2:error] [pid 255769:tid 255927] [client 4.204.201.85:3529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/about.php"] [unique_id "al9MmbxMYwyVGnfuwsKu9QAAA78"]
[Tue Jul 21 07:40:25.638242 2026] [security2:error] [pid 254995:tid 255164] [client 20.104.96.117:14345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/aaa.php"] [unique_id "al9Mmf7v0rlcEGmVraFPJQAAA0U"]
[Tue Jul 21 07:40:25.694621 2026] [security2:error] [pid 254995:tid 255122] [remote 104.207.59.203:57855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.59.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9Mmf7v0rlcEGmVraFPJgADIn4"]
[Tue Jul 21 07:40:25.713141 2026] [proxy:error] [pid 255769:tid 256010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.713206 2026] [proxy_http:error] [pid 255769:tid 256010] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.713804 2026] [proxy:error] [pid 255769:tid 256010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:25.713838 2026] [proxy_http:error] [pid 255769:tid 256010] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:25.716969 2026] [security2:error] [pid 255769:tid 255799] [remote 167.172.158.128:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MmbxMYwyVGnfuwsKu_wADpx0"]
[Tue Jul 21 07:40:25.727714 2026] [security2:error] [pid 255769:tid 255938] [client 64.225.75.246:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MmbxMYwyVGnfuwsKvAQAAA8o"]
[Tue Jul 21 07:40:25.737570 2026] [security2:error] [pid 255769:tid 255997] [client 4.204.201.85:57458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/biufile.php"] [unique_id "al9MmbxMYwyVGnfuwsKvAgAABAM"]
[Tue Jul 21 07:40:25.857294 2026] [security2:error] [pid 255769:tid 255928] [client 20.151.10.161:55262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/h02ugyh.php"] [unique_id "al9MmbxMYwyVGnfuwsKvCwAAA8A"]
[Tue Jul 21 07:40:25.972670 2026] [security2:error] [pid 255769:tid 255924] [client 20.104.96.117:14621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/file5.php"] [unique_id "al9MmbxMYwyVGnfuwsKvEQAAA7w"]
[Tue Jul 21 07:40:25.991881 2026] [security2:error] [pid 255769:tid 255990] [client 209.97.180.8:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al9MmbxMYwyVGnfuwsKvEgAAA_4"]
[Tue Jul 21 07:40:26.007314 2026] [security2:error] [pid 255769:tid 255900] [client 20.151.10.161:46008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-links.php"] [unique_id "al9MmrxMYwyVGnfuwsKvEwAAA6Q"]
[Tue Jul 21 07:40:26.013535 2026] [security2:error] [pid 255769:tid 256009] [client 4.204.201.85:61062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/mosty.php"] [unique_id "al9MmrxMYwyVGnfuwsKvFAAABA8"]
[Tue Jul 21 07:40:26.027769 2026] [security2:error] [pid 255769:tid 255977] [client 147.182.200.94:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MmrxMYwyVGnfuwsKvFQAAA_E"]
[Tue Jul 21 07:40:26.037596 2026] [security2:error] [pid 255769:tid 255999] [client 20.226.60.151:23120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/x.php"] [unique_id "al9MmrxMYwyVGnfuwsKvGQAABAU"]
[Tue Jul 21 07:40:26.051971 2026] [proxy:error] [pid 254995:tid 255209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:26.052042 2026] [proxy_http:error] [pid 254995:tid 255209] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:26.052493 2026] [proxy:error] [pid 254995:tid 255209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:26.052514 2026] [proxy_http:error] [pid 254995:tid 255209] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:26.065431 2026] [proxy:error] [pid 255769:tid 256019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:26.065517 2026] [proxy_http:error] [pid 255769:tid 256019] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:26.066259 2026] [proxy:error] [pid 255769:tid 256019] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:26.066312 2026] [proxy_http:error] [pid 255769:tid 256019] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:26.119149 2026] [security2:error] [pid 255769:tid 255966] [client 167.99.210.137:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9MmrxMYwyVGnfuwsKvHAAAA-Y"]
[Tue Jul 21 07:40:26.159027 2026] [security2:error] [pid 255769:tid 255975] [client 4.204.201.85:7438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/about.php"] [unique_id "al9MmrxMYwyVGnfuwsKvIgAAA-8"]
[Tue Jul 21 07:40:26.287773 2026] [security2:error] [pid 254995:tid 255201] [client 4.204.201.85:59958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/dejavu.php"] [unique_id "al9Mmv7v0rlcEGmVraFPNQAAA2o"]
[Tue Jul 21 07:40:26.292255 2026] [security2:error] [pid 255769:tid 255940] [client 202.143.127.214:61980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvKAAAA8w"]
[Tue Jul 21 07:40:26.292368 2026] [security2:error] [pid 255769:tid 255940] [client 202.143.127.214:61980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvKAAAA8w"]
[Tue Jul 21 07:40:26.350328 2026] [security2:error] [pid 254995:tid 255266] [client 20.104.96.117:14349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/222.php"] [unique_id "al9Mmv7v0rlcEGmVraFPNwAAA5A"]
[Tue Jul 21 07:40:26.384158 2026] [security2:error] [pid 255769:tid 255804] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvLwAEHiI"]
[Tue Jul 21 07:40:26.384320 2026] [security2:error] [pid 255769:tid 256024] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvLwAEHiI"]
[Tue Jul 21 07:40:26.546059 2026] [security2:error] [pid 255769:tid 255970] [client 207.154.197.113:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MmrxMYwyVGnfuwsKvOAAAA-o"]
[Tue Jul 21 07:40:26.559559 2026] [security2:error] [pid 255769:tid 256012] [client 154.192.233.199:58837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvOgAABBI"]
[Tue Jul 21 07:40:26.559642 2026] [security2:error] [pid 255769:tid 256012] [client 154.192.233.199:58837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvOgAABBI"]
[Tue Jul 21 07:40:26.567652 2026] [security2:error] [pid 255769:tid 255903] [client 4.204.201.85:61075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/aaf.php"] [unique_id "al9MmrxMYwyVGnfuwsKvPAAAA6c"]
[Tue Jul 21 07:40:26.652819 2026] [security2:error] [pid 255769:tid 255934] [client 20.104.96.117:14363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/test.php"] [unique_id "al9MmrxMYwyVGnfuwsKvPwAAA8Y"]
[Tue Jul 21 07:40:26.711603 2026] [security2:error] [pid 255769:tid 255809] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvQgADyic"]
[Tue Jul 21 07:40:26.711773 2026] [security2:error] [pid 255769:tid 255938] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvQgADyic"]
[Tue Jul 21 07:40:26.716202 2026] [security2:error] [pid 255769:tid 255952] [client 142.93.129.190:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9MmrxMYwyVGnfuwsKvQwAAA9g"]
[Tue Jul 21 07:40:26.764865 2026] [security2:error] [pid 255769:tid 255841] [remote 74.7.241.42:47696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MmrxMYwyVGnfuwsKvPQAD1kc"], referer: https://app.institutocrismonteiro.com.br/2023/05/31/enfrentrando-o-desafio-de-um-marido-preguicoso/
[Tue Jul 21 07:40:26.768008 2026] [security2:error] [pid 255769:tid 255905] [client 4.204.201.85:7470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/admin.php"] [unique_id "al9MmrxMYwyVGnfuwsKvSgAAA6k"]
[Tue Jul 21 07:40:26.848858 2026] [security2:error] [pid 254995:tid 255272] [client 4.204.201.85:59964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ha.php"] [unique_id "al9Mmv7v0rlcEGmVraFPPwAAA5Y"]
[Tue Jul 21 07:40:26.985194 2026] [security2:error] [pid 254995:tid 255188] [client 20.104.96.117:14536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/aaa.php"] [unique_id "al9Mmv7v0rlcEGmVraFPQgAAA10"]
[Tue Jul 21 07:40:27.124883 2026] [security2:error] [pid 254995:tid 255203] [client 4.204.201.85:61089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/hur.php"] [unique_id "al9Mm_7v0rlcEGmVraFPQwAAA2w"]
[Tue Jul 21 07:40:27.147250 2026] [security2:error] [pid 255769:tid 255796] [remote 57.141.18.61:25178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-sitemap-taxonomies-category-1.xml"] [unique_id "al9MmrxMYwyVGnfuwsKvHgAD_Bo"]
[Tue Jul 21 07:40:27.188462 2026] [security2:error] [pid 254995:tid 255214] [client 139.59.143.102:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al9Mm_7v0rlcEGmVraFPRQAAA3Y"]
[Tue Jul 21 07:40:27.206609 2026] [security2:error] [pid 255769:tid 255978] [client 20.226.60.151:62330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/mg.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvVAAAA_I"]
[Tue Jul 21 07:40:27.212743 2026] [security2:error] [pid 255769:tid 255910] [client 20.151.10.161:46027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvVQAAA64"]
[Tue Jul 21 07:40:27.224608 2026] [security2:error] [pid 254995:tid 255166] [client 20.226.60.151:59419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/mac.php"] [unique_id "al9Mm_7v0rlcEGmVraFPRgAAA0c"]
[Tue Jul 21 07:40:27.303505 2026] [security2:error] [pid 255769:tid 255946] [client 20.104.96.117:14622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/11.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvVgAAA9I"]
[Tue Jul 21 07:40:27.393430 2026] [security2:error] [pid 255769:tid 255979] [client 175.45.70.82:54797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvXgAAA_M"]
[Tue Jul 21 07:40:27.393593 2026] [security2:error] [pid 255769:tid 255979] [client 175.45.70.82:54797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvXgAAA_M"]
[Tue Jul 21 07:40:27.400251 2026] [security2:error] [pid 255769:tid 256012] [client 4.204.201.85:59942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/h02ugyh.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvXwAABBI"]
[Tue Jul 21 07:40:27.416065 2026] [security2:error] [pid 255769:tid 255918] [client 122.164.127.47:64243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvYAAAA7Y"]
[Tue Jul 21 07:40:27.416274 2026] [security2:error] [pid 255769:tid 255918] [client 122.164.127.47:64243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvYAAAA7Y"]
[Tue Jul 21 07:40:27.503848 2026] [security2:error] [pid 255769:tid 255974] [client 173.252.95.25:63062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9MmrxMYwyVGnfuwsKvKwAAA-4"]
[Tue Jul 21 07:40:27.541391 2026] [security2:error] [pid 254995:tid 255193] [client 182.8.255.181:17586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPUAAAA2I"]
[Tue Jul 21 07:40:27.541930 2026] [security2:error] [pid 254995:tid 255193] [client 182.8.255.181:17586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPUAAAA2I"]
[Tue Jul 21 07:40:27.566190 2026] [security2:error] [pid 254995:tid 255220] [client 4.204.201.85:7440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/admin.php"] [unique_id "al9Mm_7v0rlcEGmVraFPUgAAA3w"]
[Tue Jul 21 07:40:27.576437 2026] [security2:error] [pid 254995:tid 255092] [remote 206.189.95.232:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9Mm_7v0rlcEGmVraFPUwADNWA"]
[Tue Jul 21 07:40:27.594105 2026] [security2:error] [pid 255769:tid 255935] [client 207.154.212.47:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al9Mm7xMYwyVGnfuwsKvZgAAA8c"]
[Tue Jul 21 07:40:27.648434 2026] [security2:error] [pid 254995:tid 255128] [client 103.86.117.203:63017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPVAAAAyE"]
[Tue Jul 21 07:40:27.648600 2026] [security2:error] [pid 254995:tid 255128] [client 103.86.117.203:63017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPVAAAAyE"]
[Tue Jul 21 07:40:27.678363 2026] [security2:error] [pid 255769:tid 255912] [client 4.204.201.85:61068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/155.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvaAAAA7A"]
[Tue Jul 21 07:40:27.687307 2026] [security2:error] [pid 254995:tid 255276] [client 20.104.96.117:14338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/mac.php"] [unique_id "al9Mm_7v0rlcEGmVraFPVgAAA5o"]
[Tue Jul 21 07:40:27.709853 2026] [security2:error] [pid 254995:tid 255211] [client 142.93.143.8:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9Mm_7v0rlcEGmVraFPVwAAA3M"]
[Tue Jul 21 07:40:27.712345 2026] [security2:error] [pid 255769:tid 255924] [client 206.81.12.187:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9Mm7xMYwyVGnfuwsKvagAAA7w"]
[Tue Jul 21 07:40:27.716675 2026] [security2:error] [pid 254995:tid 255155] [client 103.106.20.201:61678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPWAAAAzw"]
[Tue Jul 21 07:40:27.716791 2026] [security2:error] [pid 254995:tid 255155] [client 103.106.20.201:61678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPWAAAAzw"]
[Tue Jul 21 07:40:27.720647 2026] [security2:error] [pid 255769:tid 255896] [remote 38.242.157.30:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-login.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvawADwH4"]
[Tue Jul 21 07:40:27.722184 2026] [security2:error] [pid 254995:tid 255190] [client 122.162.144.145:4482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPWgAAA18"]
[Tue Jul 21 07:40:27.722270 2026] [security2:error] [pid 254995:tid 255190] [client 122.162.144.145:4482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mm_7v0rlcEGmVraFPWgAAA18"]
[Tue Jul 21 07:40:27.759284 2026] [security2:error] [pid 255769:tid 255906] [client 136.144.33.103:64397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvbQAAA6o"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:27.876500 2026] [security2:error] [pid 255769:tid 255966] [client 20.220.225.223:31904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/inso.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvdAAAA-Y"]
[Tue Jul 21 07:40:27.882078 2026] [security2:error] [pid 255769:tid 255842] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Mm7xMYwyVGnfuwsKvdQAD00g"]
[Tue Jul 21 07:40:27.917625 2026] [security2:error] [pid 255769:tid 255902] [client 74.7.241.153:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "entrepaginasepratos.com.br"] [uri "/index.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvaQAAA6Y"]
[Tue Jul 21 07:40:27.918456 2026] [security2:error] [pid 255769:tid 255915] [client 74.7.241.153:56780] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "entrepaginasepratos.com.br"] [uri "/robots.txt"] [unique_id "al9Mm7xMYwyVGnfuwsKvZwADs2s"]
[Tue Jul 21 07:40:27.955066 2026] [security2:error] [pid 255769:tid 256026] [client 4.204.201.85:57437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/pp.php"] [unique_id "al9Mm7xMYwyVGnfuwsKvewAABCA"]
[Tue Jul 21 07:40:27.974038 2026] [proxy:error] [pid 255769:tid 255967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:27.974089 2026] [proxy_http:error] [pid 255769:tid 255967] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:27.974538 2026] [proxy:error] [pid 255769:tid 255967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:27.974561 2026] [proxy_http:error] [pid 255769:tid 255967] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:28.044653 2026] [security2:error] [pid 254995:tid 255216] [client 20.151.10.161:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "prospecta.agendaclique.com.br"] [uri "/aaa.php"] [unique_id "al9MnP7v0rlcEGmVraFPXwAAA3g"]
[Tue Jul 21 07:40:28.059602 2026] [security2:error] [pid 254995:tid 255125] [client 20.104.96.117:14369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/chosen.php"] [unique_id "al9MnP7v0rlcEGmVraFPYAAAAx4"]
[Tue Jul 21 07:40:28.144569 2026] [core:error] [pid 254995:tid 255063] [remote 52.167.144.162:43271] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:28.144595 2026] [core:error] [pid 254995:tid 255063] [remote 52.167.144.162:43271] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:28.195485 2026] [proxy:error] [pid 254995:tid 255165] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:28.195554 2026] [proxy_http:error] [pid 254995:tid 255165] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:28.196112 2026] [proxy:error] [pid 254995:tid 255165] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:28.196141 2026] [proxy_http:error] [pid 254995:tid 255165] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:28.245374 2026] [security2:error] [pid 255769:tid 255945] [client 4.204.201.85:59927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ops.php"] [unique_id "al9MnLxMYwyVGnfuwsKvggAAA9E"]
[Tue Jul 21 07:40:28.282009 2026] [security2:error] [pid 255769:tid 255887] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9MnLxMYwyVGnfuwsKvgwAEAnU"]
[Tue Jul 21 07:40:28.373652 2026] [security2:error] [pid 254995:tid 255131] [client 20.104.96.117:14351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/cream1.php"] [unique_id "al9MnP7v0rlcEGmVraFPaQAAAyQ"]
[Tue Jul 21 07:40:28.440663 2026] [security2:error] [pid 255769:tid 256027] [client 4.204.201.85:7471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/themes.php"] [unique_id "al9MnLxMYwyVGnfuwsKvhwAABCE"]
[Tue Jul 21 07:40:28.480792 2026] [security2:error] [pid 255769:tid 255794] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnLxMYwyVGnfuwsKviQAEFhg"]
[Tue Jul 21 07:40:28.480946 2026] [security2:error] [pid 255769:tid 256016] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnLxMYwyVGnfuwsKviQAEFhg"]
[Tue Jul 21 07:40:28.524162 2026] [security2:error] [pid 255769:tid 255912] [client 4.204.201.85:59904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ingfo.php"] [unique_id "al9MnLxMYwyVGnfuwsKvigAAA7A"]
[Tue Jul 21 07:40:28.621809 2026] [security2:error] [pid 255769:tid 255990] [client 209.38.208.202:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al9MnLxMYwyVGnfuwsKvjAAAA_4"]
[Tue Jul 21 07:40:28.658552 2026] [security2:error] [pid 255769:tid 256028] [client 164.92.244.132:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9MnLxMYwyVGnfuwsKvjQAABCI"]
[Tue Jul 21 07:40:28.674351 2026] [security2:error] [pid 255769:tid 255771] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9MnLxMYwyVGnfuwsKvjwADqQE"]
[Tue Jul 21 07:40:28.675079 2026] [security2:error] [pid 254995:tid 255136] [client 35.185.62.194:64634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.62.185.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sweetrip.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnP7v0rlcEGmVraFPdAAAAyk"]
[Tue Jul 21 07:40:28.707510 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:28.707561 2026] [proxy_http:error] [pid 255769:tid 255960] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:28.707992 2026] [proxy:error] [pid 255769:tid 255960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:28.708027 2026] [proxy_http:error] [pid 255769:tid 255960] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:28.803903 2026] [security2:error] [pid 255769:tid 255980] [client 4.204.201.85:57449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/error_log.php"] [unique_id "al9MnLxMYwyVGnfuwsKvmAAAA_Q"]
[Tue Jul 21 07:40:28.811757 2026] [proxy:error] [pid 255769:tid 256011] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:28.811852 2026] [proxy_http:error] [pid 255769:tid 256011] [client 20.104.96.117:14619] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:28.812458 2026] [proxy:error] [pid 255769:tid 256011] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:28.812483 2026] [proxy_http:error] [pid 255769:tid 256011] [client 20.104.96.117:14619] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:28.864600 2026] [security2:error] [pid 255769:tid 256004] [client 20.226.60.151:62235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-post-data.php"] [unique_id "al9MnLxMYwyVGnfuwsKvmgAABAo"]
[Tue Jul 21 07:40:28.984200 2026] [security2:error] [pid 255769:tid 255926] [client 20.226.60.151:59475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/mg.php"] [unique_id "al9MnLxMYwyVGnfuwsKvoAAAA74"]
[Tue Jul 21 07:40:29.080104 2026] [security2:error] [pid 255769:tid 255951] [client 4.204.201.85:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/test10.php"] [unique_id "al9MnbxMYwyVGnfuwsKvoQAAA9c"]
[Tue Jul 21 07:40:29.088157 2026] [security2:error] [pid 255769:tid 255987] [client 35.185.62.194:51846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9MnbxMYwyVGnfuwsKvogAAA_s"]
[Tue Jul 21 07:40:29.160109 2026] [proxy:error] [pid 255769:tid 255940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:29.160182 2026] [proxy_http:error] [pid 255769:tid 255940] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:29.160631 2026] [proxy:error] [pid 255769:tid 255940] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:29.160652 2026] [proxy_http:error] [pid 255769:tid 255940] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:29.184714 2026] [security2:error] [pid 255769:tid 255773] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9MnbxMYwyVGnfuwsKvqAAEGwM"]
[Tue Jul 21 07:40:29.186369 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:29.186426 2026] [proxy_http:error] [pid 255769:tid 256017] [client 20.104.96.117:14592] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:29.186939 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:29.186967 2026] [proxy_http:error] [pid 255769:tid 256017] [client 20.104.96.117:14592] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:29.364314 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:57446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/koala.php"] [unique_id "al9Mnf7v0rlcEGmVraFPfQAAA0o"]
[Tue Jul 21 07:40:29.384829 2026] [security2:error] [pid 255769:tid 255943] [client 20.226.60.151:23152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/155.php"] [unique_id "al9MnbxMYwyVGnfuwsKvrwAAA88"]
[Tue Jul 21 07:40:29.385076 2026] [security2:error] [pid 255769:tid 255903] [client 35.185.62.194:63539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9MnbxMYwyVGnfuwsKvsAAAA6c"]
[Tue Jul 21 07:40:29.388406 2026] [security2:error] [pid 255769:tid 255949] [client 20.220.225.223:19666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/dr.php"] [unique_id "al9MnbxMYwyVGnfuwsKvsQAAA9U"]
[Tue Jul 21 07:40:29.423590 2026] [security2:error] [pid 255769:tid 255934] [client 128.199.182.152:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9MnbxMYwyVGnfuwsKvtgAAA8Y"]
[Tue Jul 21 07:40:29.502540 2026] [security2:error] [pid 255769:tid 255938] [client 152.59.154.239:65398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnbxMYwyVGnfuwsKvugAAA8o"]
[Tue Jul 21 07:40:29.507204 2026] [security2:error] [pid 255769:tid 255938] [client 152.59.154.239:65398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnbxMYwyVGnfuwsKvugAAA8o"]
[Tue Jul 21 07:40:29.579551 2026] [security2:error] [pid 254995:tid 255177] [client 20.104.96.117:14374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/dr.php"] [unique_id "al9Mnf7v0rlcEGmVraFPhAAAA1I"]
[Tue Jul 21 07:40:29.594568 2026] [security2:error] [pid 255769:tid 255851] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9MnbxMYwyVGnfuwsKvuwAD4FE"]
[Tue Jul 21 07:40:29.610782 2026] [security2:error] [pid 254995:tid 255156] [client 20.226.60.151:56318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Mnf7v0rlcEGmVraFPhgAAAz0"]
[Tue Jul 21 07:40:29.639655 2026] [security2:error] [pid 254995:tid 255193] [client 4.204.201.85:57463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/mac.php"] [unique_id "al9Mnf7v0rlcEGmVraFPhwAAA2I"]
[Tue Jul 21 07:40:29.673736 2026] [security2:error] [pid 254995:tid 255150] [client 35.185.62.194:58708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Mnf7v0rlcEGmVraFPiAAAAzc"]
[Tue Jul 21 07:40:29.680718 2026] [security2:error] [pid 255769:tid 255975] [client 59.96.220.140:51597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MnbxMYwyVGnfuwsKvwAAAA-8"]
[Tue Jul 21 07:40:29.681316 2026] [security2:error] [pid 255769:tid 255975] [client 59.96.220.140:51597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MnbxMYwyVGnfuwsKvwAAAA-8"]
[Tue Jul 21 07:40:29.872182 2026] [security2:error] [pid 255769:tid 255956] [client 20.226.60.151:59434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-post-data.php"] [unique_id "al9MnbxMYwyVGnfuwsKvxwAAA9w"]
[Tue Jul 21 07:40:29.875645 2026] [security2:error] [pid 255769:tid 255908] [client 20.104.96.117:14382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/x.php"] [unique_id "al9MnbxMYwyVGnfuwsKvyAAAA6w"]
[Tue Jul 21 07:40:29.924712 2026] [security2:error] [pid 255769:tid 255958] [client 4.204.201.85:57465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wefile.php"] [unique_id "al9MnbxMYwyVGnfuwsKvygAAA94"]
[Tue Jul 21 07:40:30.090664 2026] [security2:error] [pid 254995:tid 255138] [client 35.185.62.194:63334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Mnv7v0rlcEGmVraFPlAAAAys"]
[Tue Jul 21 07:40:30.101328 2026] [security2:error] [pid 255769:tid 255986] [client 194.99.104.35:34976] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv0QAAA_o"]
[Tue Jul 21 07:40:30.101425 2026] [security2:error] [pid 255769:tid 255986] [client 194.99.104.35:34976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv0QAAA_o"]
[Tue Jul 21 07:40:30.103172 2026] [security2:error] [pid 255769:tid 255927] [client 62.102.148.187:49200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv0wAAA78"]
[Tue Jul 21 07:40:30.103279 2026] [security2:error] [pid 255769:tid 255927] [client 62.102.148.187:49200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv0wAAA78"]
[Tue Jul 21 07:40:30.178014 2026] [security2:error] [pid 255769:tid 255853] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9MnrxMYwyVGnfuwsKv1wAEElM"]
[Tue Jul 21 07:40:30.213268 2026] [proxy:error] [pid 255769:tid 255919] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:30.213361 2026] [proxy_http:error] [pid 255769:tid 255919] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:30.213860 2026] [proxy:error] [pid 255769:tid 255919] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:30.213901 2026] [proxy_http:error] [pid 255769:tid 255919] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:30.221800 2026] [autoindex:error] [pid 254995:tid 255205] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:30.285637 2026] [security2:error] [pid 255769:tid 255953] [client 20.220.225.223:32294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wpx.php"] [unique_id "al9MnrxMYwyVGnfuwsKv2wAAA9k"]
[Tue Jul 21 07:40:30.319322 2026] [security2:error] [pid 254995:tid 255196] [client 20.104.96.117:14380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/155.php"] [unique_id "al9Mnv7v0rlcEGmVraFPlwAAA2U"]
[Tue Jul 21 07:40:30.322275 2026] [security2:error] [pid 254995:tid 255148] [client 103.174.34.15:50808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mnv7v0rlcEGmVraFPmAAAAzU"]
[Tue Jul 21 07:40:30.322374 2026] [security2:error] [pid 254995:tid 255148] [client 103.174.34.15:50808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mnv7v0rlcEGmVraFPmAAAAzU"]
[Tue Jul 21 07:40:30.343071 2026] [security2:error] [pid 255769:tid 255875] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9MnrxMYwyVGnfuwsKv3QADq2k"]
[Tue Jul 21 07:40:30.416037 2026] [security2:error] [pid 255769:tid 255944] [client 117.217.38.194:60321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv4AAAA9A"]
[Tue Jul 21 07:40:30.416160 2026] [security2:error] [pid 255769:tid 255944] [client 117.217.38.194:60321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv4AAAA9A"]
[Tue Jul 21 07:40:30.455967 2026] [security2:error] [pid 254995:tid 255161] [client 35.185.62.194:56510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Mnv7v0rlcEGmVraFPngAAA0I"]
[Tue Jul 21 07:40:30.471725 2026] [security2:error] [pid 254995:tid 255033] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mnv7v0rlcEGmVraFPoAADeiU"]
[Tue Jul 21 07:40:30.471852 2026] [security2:error] [pid 254995:tid 255218] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mnv7v0rlcEGmVraFPoAADeiU"]
[Tue Jul 21 07:40:30.543778 2026] [autoindex:error] [pid 255769:tid 255938] [client 4.204.201.85:61061] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:30.567275 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:30.567345 2026] [proxy_http:error] [pid 255769:tid 256028] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:30.567970 2026] [proxy:error] [pid 255769:tid 256028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:30.567991 2026] [proxy_http:error] [pid 255769:tid 256028] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:30.617768 2026] [security2:error] [pid 255769:tid 256022] [client 20.104.96.117:14396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ops.php"] [unique_id "al9MnrxMYwyVGnfuwsKv6AAABBw"]
[Tue Jul 21 07:40:30.662487 2026] [security2:error] [pid 255769:tid 255982] [client 20.226.60.151:59453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/pucci.php"] [unique_id "al9MnrxMYwyVGnfuwsKv6QAAA_Y"]
[Tue Jul 21 07:40:30.681839 2026] [security2:error] [pid 255769:tid 255947] [client 4.204.201.85:61061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/makeasmtp.php"] [unique_id "al9MnrxMYwyVGnfuwsKv6wAAA9M"]
[Tue Jul 21 07:40:30.705619 2026] [proxy:error] [pid 254995:tid 255174] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:30.705694 2026] [proxy_http:error] [pid 254995:tid 255174] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:30.706256 2026] [proxy:error] [pid 254995:tid 255174] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:30.706284 2026] [proxy_http:error] [pid 254995:tid 255174] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:30.797607 2026] [security2:error] [pid 255769:tid 255940] [client 139.167.225.182:58509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv7QAAA8w"]
[Tue Jul 21 07:40:30.797712 2026] [security2:error] [pid 255769:tid 255940] [client 139.167.225.182:58509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MnrxMYwyVGnfuwsKv7QAAA8w"]
[Tue Jul 21 07:40:30.814648 2026] [security2:error] [pid 254995:tid 255126] [client 35.185.62.194:65285] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Mnv7v0rlcEGmVraFPqwAAAx8"]
[Tue Jul 21 07:40:30.879831 2026] [security2:error] [pid 255769:tid 255805] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9MnrxMYwyVGnfuwsKv8AAD_CM"]
[Tue Jul 21 07:40:30.946235 2026] [security2:error] [pid 254995:tid 255144] [client 20.104.96.117:14618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/file31.php"] [unique_id "al9Mnv7v0rlcEGmVraFPrQAAAzE"]
[Tue Jul 21 07:40:30.958062 2026] [security2:error] [pid 254995:tid 255266] [client 4.204.201.85:61078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/2P.php"] [unique_id "al9Mnv7v0rlcEGmVraFPrgAAA5A"]
[Tue Jul 21 07:40:31.009979 2026] [security2:error] [pid 255769:tid 255943] [client 122.179.91.63:23721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mn7xMYwyVGnfuwsKv8QAAA88"]
[Tue Jul 21 07:40:31.010106 2026] [security2:error] [pid 255769:tid 255943] [client 122.179.91.63:23721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mn7xMYwyVGnfuwsKv8QAAA88"]
[Tue Jul 21 07:40:31.064762 2026] [security2:error] [pid 255769:tid 255890] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Mn7xMYwyVGnfuwsKv9gAEIHg"]
[Tue Jul 21 07:40:31.088524 2026] [proxy:error] [pid 254995:tid 255160] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.088572 2026] [proxy_http:error] [pid 254995:tid 255160] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.089081 2026] [proxy:error] [pid 254995:tid 255160] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.089107 2026] [proxy_http:error] [pid 254995:tid 255160] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.195655 2026] [security2:error] [pid 255769:tid 255986] [client 35.185.62.194:59638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Mn7xMYwyVGnfuwsKv_QAAA_o"]
[Tue Jul 21 07:40:31.234380 2026] [security2:error] [pid 255769:tid 255900] [client 4.204.201.85:59953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/.well-known/about.php"] [unique_id "al9Mn7xMYwyVGnfuwsKv_gAAA6Q"]
[Tue Jul 21 07:40:31.261314 2026] [proxy:error] [pid 254995:tid 255225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.261376 2026] [proxy_http:error] [pid 254995:tid 255225] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.262046 2026] [proxy:error] [pid 254995:tid 255225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.262075 2026] [proxy_http:error] [pid 254995:tid 255225] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.265114 2026] [security2:error] [pid 254995:tid 255166] [client 20.104.96.117:14388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/file6.php"] [unique_id "al9Mn_7v0rlcEGmVraFPvwAAA0c"]
[Tue Jul 21 07:40:31.282092 2026] [security2:error] [pid 254995:tid 255260] [client 20.151.10.161:55241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/seiso.php"] [unique_id "al9Mn_7v0rlcEGmVraFPwAAAA4o"]
[Tue Jul 21 07:40:31.323969 2026] [security2:error] [pid 254995:tid 255194] [client 20.226.60.151:62307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/pucci.php"] [unique_id "al9Mn_7v0rlcEGmVraFPwQAAA2M"]
[Tue Jul 21 07:40:31.374799 2026] [security2:error] [pid 255769:tid 255847] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Mn7xMYwyVGnfuwsKwAAADxU0"]
[Tue Jul 21 07:40:31.484292 2026] [security2:error] [pid 255769:tid 255907] [client 35.185.62.194:62827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Mn7xMYwyVGnfuwsKwBQAAA6s"]
[Tue Jul 21 07:40:31.512653 2026] [security2:error] [pid 254995:tid 255150] [client 4.204.201.85:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Mn_7v0rlcEGmVraFPxAAAAzc"]
[Tue Jul 21 07:40:31.549809 2026] [proxy:error] [pid 255769:tid 256027] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.549906 2026] [proxy_http:error] [pid 255769:tid 256027] [client 20.104.96.117:14367] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.550467 2026] [proxy:error] [pid 255769:tid 256027] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.550506 2026] [proxy_http:error] [pid 255769:tid 256027] [client 20.104.96.117:14367] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.559126 2026] [security2:error] [pid 255769:tid 255934] [client 20.226.60.151:62331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/black.php"] [unique_id "al9Mn7xMYwyVGnfuwsKwDQAAA8Y"]
[Tue Jul 21 07:40:31.582216 2026] [security2:error] [pid 255769:tid 255916] [client 193.36.225.64:39519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Mn7xMYwyVGnfuwsKwAgAAA7Q"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:31.630215 2026] [proxy:error] [pid 254995:tid 255190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.630276 2026] [proxy_http:error] [pid 254995:tid 255190] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.630739 2026] [proxy:error] [pid 254995:tid 255190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.630768 2026] [proxy_http:error] [pid 254995:tid 255190] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.699919 2026] [proxy:error] [pid 255769:tid 255999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.699978 2026] [proxy_http:error] [pid 255769:tid 255999] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.700435 2026] [proxy:error] [pid 255769:tid 255999] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.700732 2026] [security2:error] [pid 255769:tid 255774] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Mn7xMYwyVGnfuwsKwGAAEHAQ"]
[Tue Jul 21 07:40:31.701089 2026] [proxy_http:error] [pid 255769:tid 255999] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.713899 2026] [security2:error] [pid 255769:tid 255850] [remote 77.90.2.3:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.2.90.77.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9Mn7xMYwyVGnfuwsKwGQADrVA"]
[Tue Jul 21 07:40:31.789780 2026] [security2:error] [pid 255769:tid 255911] [client 4.204.201.85:57454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/system_log.php"] [unique_id "al9Mn7xMYwyVGnfuwsKwHQAAA68"]
[Tue Jul 21 07:40:31.848726 2026] [security2:error] [pid 254995:tid 255222] [client 20.220.225.223:19668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/2x.php"] [unique_id "al9Mn_7v0rlcEGmVraFP1wAAA34"]
[Tue Jul 21 07:40:31.859309 2026] [security2:error] [pid 254995:tid 255271] [client 35.185.62.194:64653] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Mn_7v0rlcEGmVraFP2gAAA5U"]
[Tue Jul 21 07:40:31.899487 2026] [security2:error] [pid 255769:tid 256013] [client 20.104.96.117:14648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/adminfuns.php"] [unique_id "al9Mn7xMYwyVGnfuwsKwIAAABBM"]
[Tue Jul 21 07:40:31.939143 2026] [security2:error] [pid 255769:tid 255891] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.dees.ind.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Mn7xMYwyVGnfuwsKwIwAEGXk"]
[Tue Jul 21 07:40:31.988546 2026] [proxy:error] [pid 255769:tid 255977] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.988608 2026] [proxy_http:error] [pid 255769:tid 255977] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:31.989217 2026] [proxy:error] [pid 255769:tid 255977] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:31.989244 2026] [proxy_http:error] [pid 255769:tid 255977] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.056119 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.056186 2026] [proxy_http:error] [pid 255769:tid 256017] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.056752 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.056775 2026] [proxy_http:error] [pid 255769:tid 256017] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.065793 2026] [security2:error] [pid 254995:tid 255209] [client 20.151.10.161:55233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/155.php"] [unique_id "al9MoP7v0rlcEGmVraFP4gAAA3E"]
[Tue Jul 21 07:40:32.125150 2026] [autoindex:error] [pid 254995:tid 255140] [client 4.204.201.85:57424] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:32.153074 2026] [proxy:error] [pid 255769:tid 255996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.153146 2026] [proxy_http:error] [pid 255769:tid 255996] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.154007 2026] [proxy:error] [pid 255769:tid 255996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.154038 2026] [proxy_http:error] [pid 255769:tid 255996] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.259505 2026] [security2:error] [pid 255769:tid 255933] [client 20.104.96.117:14373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/goods.php"] [unique_id "al9MoLxMYwyVGnfuwsKwNQAAA8U"]
[Tue Jul 21 07:40:32.320389 2026] [security2:error] [pid 255769:tid 255953] [client 4.204.201.85:7486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/.well-known/about.php"] [unique_id "al9MoLxMYwyVGnfuwsKwNwAAA9k"]
[Tue Jul 21 07:40:32.329537 2026] [security2:error] [pid 255769:tid 255974] [client 35.185.62.194:65406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sweetrip.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9MoLxMYwyVGnfuwsKwOAAAA-4"]
[Tue Jul 21 07:40:32.342346 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.342415 2026] [proxy_http:error] [pid 255769:tid 255964] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.343015 2026] [proxy:error] [pid 255769:tid 255964] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.343042 2026] [proxy_http:error] [pid 255769:tid 255964] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.407631 2026] [proxy:error] [pid 255769:tid 255907] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.407701 2026] [proxy_http:error] [pid 255769:tid 255907] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.408337 2026] [proxy:error] [pid 255769:tid 255907] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.408376 2026] [proxy_http:error] [pid 255769:tid 255907] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.459834 2026] [autoindex:error] [pid 254995:tid 255174] [client 4.204.201.85:57424] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:32.586969 2026] [security2:error] [pid 254995:tid 255144] [client 20.104.96.117:14390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/100.php"] [unique_id "al9MoP7v0rlcEGmVraFP7QAAAzE"]
[Tue Jul 21 07:40:32.598208 2026] [security2:error] [pid 254995:tid 255266] [client 4.204.201.85:57424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/crgio.php"] [unique_id "al9MoP7v0rlcEGmVraFP7gAAA5A"]
[Tue Jul 21 07:40:32.609633 2026] [proxy:error] [pid 255769:tid 255913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.609704 2026] [proxy_http:error] [pid 255769:tid 255913] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.610357 2026] [proxy:error] [pid 255769:tid 255913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.610394 2026] [proxy_http:error] [pid 255769:tid 255913] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.630658 2026] [security2:error] [pid 255769:tid 255916] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9MoLxMYwyVGnfuwsKwQwAAA7Q"]
[Tue Jul 21 07:40:32.644520 2026] [security2:error] [pid 254995:tid 255192] [client 184.75.223.211:40134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9MoP7v0rlcEGmVraFP9AAAA2E"]
[Tue Jul 21 07:40:32.644649 2026] [security2:error] [pid 254995:tid 255192] [client 184.75.223.211:40134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9MoP7v0rlcEGmVraFP9AAAA2E"]
[Tue Jul 21 07:40:32.657743 2026] [security2:error] [pid 255769:tid 255990] [client 20.226.60.151:56253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/root.php"] [unique_id "al9MoLxMYwyVGnfuwsKwRAAAA_4"]
[Tue Jul 21 07:40:32.667014 2026] [security2:error] [pid 255769:tid 256010] [client 20.151.10.161:55263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ppp.php"] [unique_id "al9MoLxMYwyVGnfuwsKwRQAABBA"]
[Tue Jul 21 07:40:32.706728 2026] [proxy:error] [pid 254995:tid 255160] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.706793 2026] [proxy_http:error] [pid 254995:tid 255160] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.707417 2026] [proxy:error] [pid 254995:tid 255160] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.707444 2026] [proxy_http:error] [pid 254995:tid 255160] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.710469 2026] [proxy:error] [pid 255769:tid 255906] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.710532 2026] [proxy_http:error] [pid 255769:tid 255906] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.711138 2026] [proxy:error] [pid 255769:tid 255906] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.711166 2026] [proxy_http:error] [pid 255769:tid 255906] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.769539 2026] [proxy:error] [pid 255769:tid 255920] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.769604 2026] [proxy_http:error] [pid 255769:tid 255920] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.770183 2026] [proxy:error] [pid 255769:tid 255920] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:32.770209 2026] [proxy_http:error] [pid 255769:tid 255920] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:32.816028 2026] [security2:error] [pid 255769:tid 255936] [client 20.226.60.151:23159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ops.php"] [unique_id "al9MoLxMYwyVGnfuwsKwSgAAA8g"]
[Tue Jul 21 07:40:32.874257 2026] [security2:error] [pid 255769:tid 255966] [client 4.204.201.85:56542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/pucci.php"] [unique_id "al9MoLxMYwyVGnfuwsKwTAAAA-Y"]
[Tue Jul 21 07:40:32.875635 2026] [security2:error] [pid 254995:tid 255131] [client 173.24.185.52:65240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MoP7v0rlcEGmVraFP-gAAAyQ"]
[Tue Jul 21 07:40:32.875800 2026] [security2:error] [pid 254995:tid 255131] [client 173.24.185.52:65240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MoP7v0rlcEGmVraFP-gAAAyQ"]
[Tue Jul 21 07:40:32.918259 2026] [security2:error] [pid 255769:tid 256003] [client 20.220.225.223:19273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/kq1.php"] [unique_id "al9MoLxMYwyVGnfuwsKwTgAABAk"]
[Tue Jul 21 07:40:32.945942 2026] [security2:error] [pid 255769:tid 255940] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9MoLxMYwyVGnfuwsKwUAAAA8w"]
[Tue Jul 21 07:40:32.981935 2026] [security2:error] [pid 255769:tid 255927] [client 20.104.96.117:14533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/about.php"] [unique_id "al9MoLxMYwyVGnfuwsKwUQAAA78"]
[Tue Jul 21 07:40:33.038856 2026] [security2:error] [pid 254995:tid 255113] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mof7v0rlcEGmVraFP_gADJnU"]
[Tue Jul 21 07:40:33.039048 2026] [security2:error] [pid 254995:tid 255133] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mof7v0rlcEGmVraFP_gADJnU"]
[Tue Jul 21 07:40:33.091125 2026] [proxy:error] [pid 255769:tid 255970] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.091191 2026] [proxy_http:error] [pid 255769:tid 255970] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.091840 2026] [proxy:error] [pid 255769:tid 255970] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.091865 2026] [proxy_http:error] [pid 255769:tid 255970] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.147471 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.147548 2026] [proxy_http:error] [pid 255769:tid 256017] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.148206 2026] [proxy:error] [pid 255769:tid 256017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.148238 2026] [proxy_http:error] [pid 255769:tid 256017] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.167449 2026] [autoindex:error] [pid 255769:tid 256021] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:33.204516 2026] [security2:error] [pid 255769:tid 255955] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9MobxMYwyVGnfuwsKwXwAAA9s"]
[Tue Jul 21 07:40:33.279903 2026] [security2:error] [pid 255769:tid 256015] [client 20.104.96.117:14638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/about.php"] [unique_id "al9MobxMYwyVGnfuwsKwYQAABBU"]
[Tue Jul 21 07:40:33.358598 2026] [security2:error] [pid 255769:tid 256027] [client 20.226.60.151:62218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/zlece.php"] [unique_id "al9MobxMYwyVGnfuwsKwYwAABCE"]
[Tue Jul 21 07:40:33.389185 2026] [proxy:error] [pid 254995:tid 255186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.389264 2026] [proxy_http:error] [pid 254995:tid 255186] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.389898 2026] [proxy:error] [pid 254995:tid 255186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.389938 2026] [proxy_http:error] [pid 254995:tid 255186] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.410363 2026] [security2:error] [pid 255769:tid 255932] [client 167.99.181.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.181.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MobxMYwyVGnfuwsKwZAAAA8Q"]
[Tue Jul 21 07:40:33.455287 2026] [autoindex:error] [pid 255769:tid 255912] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:33.464446 2026] [security2:error] [pid 255769:tid 255934] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9MobxMYwyVGnfuwsKwaAAAA8Y"]
[Tue Jul 21 07:40:33.476284 2026] [security2:error] [pid 255769:tid 256018] [client 20.151.10.161:53620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/201.php"] [unique_id "al9MobxMYwyVGnfuwsKwaQAABBg"]
[Tue Jul 21 07:40:33.500253 2026] [security2:error] [pid 254995:tid 255179] [client 4.204.201.85:7461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Mof7v0rlcEGmVraFQDAAAA1Q"]
[Tue Jul 21 07:40:33.508829 2026] [proxy:error] [pid 254995:tid 255158] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.508924 2026] [proxy_http:error] [pid 254995:tid 255158] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.510013 2026] [proxy:error] [pid 254995:tid 255158] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.510061 2026] [proxy_http:error] [pid 254995:tid 255158] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.513213 2026] [security2:error] [pid 255769:tid 256016] [client 106.215.181.8:4635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MobxMYwyVGnfuwsKwawAABBY"]
[Tue Jul 21 07:40:33.517897 2026] [security2:error] [pid 255769:tid 256016] [client 106.215.181.8:4635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MobxMYwyVGnfuwsKwawAABBY"]
[Tue Jul 21 07:40:33.523240 2026] [proxy:error] [pid 255769:tid 255913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.523298 2026] [proxy_http:error] [pid 255769:tid 255913] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.524101 2026] [proxy:error] [pid 255769:tid 255913] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.524138 2026] [proxy_http:error] [pid 255769:tid 255913] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.594539 2026] [security2:error] [pid 255769:tid 255998] [client 4.204.201.85:59951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-temp.php"] [unique_id "al9MobxMYwyVGnfuwsKwcQAABAQ"]
[Tue Jul 21 07:40:33.607873 2026] [security2:error] [pid 255769:tid 256028] [client 20.104.96.117:14375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/admin.php"] [unique_id "al9MobxMYwyVGnfuwsKwcwAABCI"]
[Tue Jul 21 07:40:33.626050 2026] [security2:error] [pid 255769:tid 256022] [client 165.227.39.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.39.227.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MobxMYwyVGnfuwsKwdAAABBw"]
[Tue Jul 21 07:40:33.685738 2026] [security2:error] [pid 254995:tid 255125] [client 128.127.105.184:52566] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mof7v0rlcEGmVraFQEwAAAx4"]
[Tue Jul 21 07:40:33.685905 2026] [security2:error] [pid 254995:tid 255125] [client 128.127.105.184:52566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mof7v0rlcEGmVraFQEwAAAx4"]
[Tue Jul 21 07:40:33.704675 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:59504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/black.php"] [unique_id "al9Mof7v0rlcEGmVraFQFQAAA5k"]
[Tue Jul 21 07:40:33.745364 2026] [proxy:error] [pid 254995:tid 255209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.745431 2026] [proxy_http:error] [pid 254995:tid 255209] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.746506 2026] [proxy:error] [pid 254995:tid 255209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.746539 2026] [proxy_http:error] [pid 254995:tid 255209] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.757519 2026] [security2:error] [pid 254995:tid 255255] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Mof7v0rlcEGmVraFQGgAAA4U"]
[Tue Jul 21 07:40:33.806691 2026] [security2:error] [pid 254995:tid 255140] [client 184.75.223.211:39590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Mof7v0rlcEGmVraFQHQAAAy0"]
[Tue Jul 21 07:40:33.806846 2026] [security2:error] [pid 254995:tid 255140] [client 184.75.223.211:39590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Mof7v0rlcEGmVraFQHQAAAy0"]
[Tue Jul 21 07:40:33.871915 2026] [security2:error] [pid 254995:tid 255180] [client 4.204.201.85:57427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-admin/js/index.php"] [unique_id "al9Mof7v0rlcEGmVraFQIwAAA1U"]
[Tue Jul 21 07:40:33.881895 2026] [proxy:error] [pid 254995:tid 255174] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.881964 2026] [proxy_http:error] [pid 254995:tid 255174] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.882646 2026] [proxy:error] [pid 254995:tid 255174] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:33.882692 2026] [proxy_http:error] [pid 254995:tid 255174] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:33.923237 2026] [security2:error] [pid 254995:tid 255149] [client 20.104.96.117:14634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/admin.php"] [unique_id "al9Mof7v0rlcEGmVraFQJwAAAzY"]
[Tue Jul 21 07:40:34.039168 2026] [security2:error] [pid 254995:tid 255146] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Mov7v0rlcEGmVraFQKwAAAzM"]
[Tue Jul 21 07:40:34.077967 2026] [proxy:error] [pid 254995:tid 255277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.078035 2026] [proxy_http:error] [pid 254995:tid 255277] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.078476 2026] [proxy:error] [pid 254995:tid 255277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.078502 2026] [proxy_http:error] [pid 254995:tid 255277] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.108847 2026] [proxy:error] [pid 254995:tid 255272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.108911 2026] [proxy_http:error] [pid 254995:tid 255272] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.109540 2026] [proxy:error] [pid 254995:tid 255272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.109585 2026] [proxy_http:error] [pid 254995:tid 255272] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.149296 2026] [security2:error] [pid 254995:tid 255154] [client 4.204.201.85:59957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/puc.php"] [unique_id "al9Mov7v0rlcEGmVraFQNAAAAzs"]
[Tue Jul 21 07:40:34.159886 2026] [security2:error] [pid 254995:tid 255267] [client 62.102.148.187:49224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Mov7v0rlcEGmVraFQNgAAA5E"]
[Tue Jul 21 07:40:34.159964 2026] [security2:error] [pid 254995:tid 255267] [client 62.102.148.187:49224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Mov7v0rlcEGmVraFQNgAAA5E"]
[Tue Jul 21 07:40:34.286695 2026] [security2:error] [pid 254995:tid 255199] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Mov7v0rlcEGmVraFQPwAAA2g"]
[Tue Jul 21 07:40:34.296746 2026] [security2:error] [pid 254995:tid 255252] [client 216.244.66.237:44408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dharmanet.com.br"] [uri "/khyentse/ocidente.htm"] [unique_id "al9Mov7v0rlcEGmVraFQQAAAA4M"]
[Tue Jul 21 07:40:34.296829 2026] [security2:error] [pid 254995:tid 255252] [client 216.244.66.237:44408] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.dharmanet.com.br"] [uri "/khyentse/ocidente.htm"] [unique_id "al9Mov7v0rlcEGmVraFQQAAAA4M"]
[Tue Jul 21 07:40:34.397372 2026] [proxy:error] [pid 254995:tid 255156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.397437 2026] [proxy_http:error] [pid 254995:tid 255156] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.398004 2026] [proxy:error] [pid 254995:tid 255156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.398027 2026] [proxy_http:error] [pid 254995:tid 255156] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.420512 2026] [security2:error] [pid 254995:tid 255186] [client 20.104.96.117:14339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/themes.php"] [unique_id "al9Mov7v0rlcEGmVraFQQwAAA1s"]
[Tue Jul 21 07:40:34.433129 2026] [security2:error] [pid 254995:tid 255221] [client 4.204.201.85:57435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/dx.php"] [unique_id "al9Mov7v0rlcEGmVraFQRAAAA30"]
[Tue Jul 21 07:40:34.487789 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.487862 2026] [proxy_http:error] [pid 254995:tid 255184] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.488468 2026] [proxy:error] [pid 254995:tid 255184] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.488493 2026] [proxy_http:error] [pid 254995:tid 255184] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.502651 2026] [proxy:error] [pid 254995:tid 255257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.502714 2026] [proxy_http:error] [pid 254995:tid 255257] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.503188 2026] [proxy:error] [pid 254995:tid 255257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.503218 2026] [proxy_http:error] [pid 254995:tid 255257] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.520935 2026] [security2:error] [pid 254995:tid 255048] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mov7v0rlcEGmVraFQSAADazQ"]
[Tue Jul 21 07:40:34.521088 2026] [security2:error] [pid 254995:tid 255202] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mov7v0rlcEGmVraFQSAADazQ"]
[Tue Jul 21 07:40:34.566987 2026] [security2:error] [pid 254995:tid 255259] [client 20.226.60.151:62266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/vssrs.php"] [unique_id "al9Mov7v0rlcEGmVraFQTQAAA4k"]
[Tue Jul 21 07:40:34.594729 2026] [security2:error] [pid 254995:tid 255216] [client 20.226.60.151:22345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/file31.php"] [unique_id "al9Mov7v0rlcEGmVraFQTwAAA3g"]
[Tue Jul 21 07:40:34.719664 2026] [security2:error] [pid 254995:tid 255164] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Mov7v0rlcEGmVraFQWgAAA0U"]
[Tue Jul 21 07:40:34.737302 2026] [proxy:error] [pid 254995:tid 255126] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.737402 2026] [proxy_http:error] [pid 254995:tid 255126] [client 20.104.96.117:14395] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.738025 2026] [proxy:error] [pid 254995:tid 255126] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.738061 2026] [proxy_http:error] [pid 254995:tid 255126] [client 20.104.96.117:14395] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.748558 2026] [autoindex:error] [pid 254995:tid 255144] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:34.771500 2026] [proxy:error] [pid 254995:tid 255165] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.771567 2026] [proxy_http:error] [pid 254995:tid 255165] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.772232 2026] [proxy:error] [pid 254995:tid 255165] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:34.772272 2026] [proxy_http:error] [pid 254995:tid 255165] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:34.854569 2026] [security2:error] [pid 254995:tid 255277] [client 20.151.10.161:12037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ops.php"] [unique_id "al9Mov7v0rlcEGmVraFQZAAAA5s"]
[Tue Jul 21 07:40:34.882940 2026] [security2:error] [pid 254995:tid 255162] [client 4.204.201.85:7478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wefile.php"] [unique_id "al9Mov7v0rlcEGmVraFQZQAAA0M"]
[Tue Jul 21 07:40:35.022573 2026] [security2:error] [pid 254995:tid 255181] [client 4.204.201.85:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/bthil.php"] [unique_id "al9Mo_7v0rlcEGmVraFQawAAA1Y"]
[Tue Jul 21 07:40:35.040137 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.040215 2026] [proxy_http:error] [pid 254995:tid 255176] [client 20.104.96.117:14557] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.040723 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.040749 2026] [proxy_http:error] [pid 254995:tid 255176] [client 20.104.96.117:14557] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.042919 2026] [security2:error] [pid 254995:tid 255183] [client 165.227.39.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.39.227.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mo_7v0rlcEGmVraFQbQAAA1g"]
[Tue Jul 21 07:40:35.050829 2026] [security2:error] [pid 254995:tid 255163] [client 167.99.181.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.181.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mo_7v0rlcEGmVraFQbwAAA0Q"]
[Tue Jul 21 07:40:35.075309 2026] [security2:error] [pid 254995:tid 255193] [client 117.251.86.144:60786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mo_7v0rlcEGmVraFQcAAAA2I"]
[Tue Jul 21 07:40:35.075390 2026] [security2:error] [pid 254995:tid 255193] [client 117.251.86.144:60786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mo_7v0rlcEGmVraFQcAAAA2I"]
[Tue Jul 21 07:40:35.097011 2026] [security2:error] [pid 254995:tid 255194] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Mo_7v0rlcEGmVraFQcgAAA2M"]
[Tue Jul 21 07:40:35.135942 2026] [proxy:error] [pid 254995:tid 255252] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.135992 2026] [proxy_http:error] [pid 254995:tid 255252] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.136434 2026] [proxy:error] [pid 254995:tid 255252] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.136458 2026] [proxy_http:error] [pid 254995:tid 255252] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.299339 2026] [security2:error] [pid 254995:tid 255275] [client 4.204.201.85:59949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/7.php"] [unique_id "al9Mo_7v0rlcEGmVraFQhgAAA5k"]
[Tue Jul 21 07:40:35.319331 2026] [security2:error] [pid 254995:tid 255125] [client 20.104.96.117:14544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Mo_7v0rlcEGmVraFQhwAAAx4"]
[Tue Jul 21 07:40:35.394393 2026] [security2:error] [pid 254995:tid 255078] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mo_7v0rlcEGmVraFQjgADKFI"]
[Tue Jul 21 07:40:35.394555 2026] [security2:error] [pid 254995:tid 255135] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mo_7v0rlcEGmVraFQjgADKFI"]
[Tue Jul 21 07:40:35.406637 2026] [security2:error] [pid 254995:tid 255127] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Mo_7v0rlcEGmVraFQjwAAAyA"]
[Tue Jul 21 07:40:35.468770 2026] [proxy:error] [pid 254995:tid 255126] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.468866 2026] [proxy_http:error] [pid 254995:tid 255126] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.469935 2026] [proxy:error] [pid 254995:tid 255126] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.469990 2026] [proxy_http:error] [pid 254995:tid 255126] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.500428 2026] [security2:error] [pid 254995:tid 255161] [client 157.245.113.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.113.245.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mo_7v0rlcEGmVraFQiQAAA0I"]
[Tue Jul 21 07:40:35.511934 2026] [proxy:error] [pid 254995:tid 255144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.512011 2026] [proxy_http:error] [pid 254995:tid 255144] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.512606 2026] [proxy:error] [pid 254995:tid 255144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:35.512636 2026] [proxy_http:error] [pid 254995:tid 255144] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:35.552550 2026] [security2:error] [pid 254995:tid 255146] [client 20.226.60.151:56295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/sym403.php"] [unique_id "al9Mo_7v0rlcEGmVraFQlgAAAzM"]
[Tue Jul 21 07:40:35.574053 2026] [security2:error] [pid 254995:tid 255157] [client 4.204.201.85:60357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/8.php"] [unique_id "al9Mo_7v0rlcEGmVraFQlwAAAz4"]
[Tue Jul 21 07:40:35.607688 2026] [security2:error] [pid 254995:tid 255277] [client 20.104.96.117:14614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Mo_7v0rlcEGmVraFQmQAAA5s"]
[Tue Jul 21 07:40:35.677260 2026] [security2:error] [pid 254995:tid 255141] [client 147.182.200.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.200.182.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mo_7v0rlcEGmVraFQoQAAAy4"]
[Tue Jul 21 07:40:35.847461 2026] [security2:error] [pid 254995:tid 255177] [client 128.127.105.184:52574] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mo_7v0rlcEGmVraFQrQAAA1I"]
[Tue Jul 21 07:40:35.847563 2026] [security2:error] [pid 254995:tid 255177] [client 128.127.105.184:52574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mo_7v0rlcEGmVraFQrQAAA1I"]
[Tue Jul 21 07:40:35.849257 2026] [security2:error] [pid 254995:tid 255150] [client 4.204.201.85:57422] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.wellnesstrade.shop"] [uri "/1.php"] [unique_id "al9Mo_7v0rlcEGmVraFQrgAAAzc"]
[Tue Jul 21 07:40:35.849353 2026] [security2:error] [pid 254995:tid 255150] [client 4.204.201.85:57422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/1.php"] [unique_id "al9Mo_7v0rlcEGmVraFQrgAAAzc"]
[Tue Jul 21 07:40:35.934411 2026] [security2:error] [pid 254995:tid 255072] [remote 167.172.158.128:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.158.172.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mo_7v0rlcEGmVraFQsQADTEw"]
[Tue Jul 21 07:40:35.939318 2026] [security2:error] [pid 254995:tid 255190] [client 20.104.96.117:14546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wefile.php"] [unique_id "al9Mo_7v0rlcEGmVraFQswAAA18"]
[Tue Jul 21 07:40:36.000148 2026] [security2:error] [pid 254995:tid 255202] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Mo_7v0rlcEGmVraFQtwAAA2s"]
[Tue Jul 21 07:40:36.078369 2026] [proxy:error] [pid 254995:tid 255205] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.078434 2026] [proxy_http:error] [pid 254995:tid 255205] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.078954 2026] [proxy:error] [pid 254995:tid 255205] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.078989 2026] [proxy_http:error] [pid 254995:tid 255205] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.125388 2026] [security2:error] [pid 254995:tid 255216] [client 4.204.201.85:59954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/100.php"] [unique_id "al9MpP7v0rlcEGmVraFQuwAAA3g"]
[Tue Jul 21 07:40:36.164744 2026] [security2:error] [pid 254995:tid 255196] [client 20.151.10.161:12094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ingfo.php"] [unique_id "al9MpP7v0rlcEGmVraFQvQAAA2U"]
[Tue Jul 21 07:40:36.273650 2026] [security2:error] [pid 254995:tid 255137] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9MpP7v0rlcEGmVraFQyQAAAyo"]
[Tue Jul 21 07:40:36.321718 2026] [security2:error] [pid 254995:tid 255182] [client 136.144.33.112:48099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9MpP7v0rlcEGmVraFQzwAAA1c"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:36.365961 2026] [security2:error] [pid 254995:tid 255271] [client 20.226.60.151:59482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/zlece.php"] [unique_id "al9MpP7v0rlcEGmVraFQ0wAAA5U"]
[Tue Jul 21 07:40:36.369372 2026] [security2:error] [pid 254995:tid 255229] [client 209.97.180.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.97.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MpP7v0rlcEGmVraFQwwAAA4I"]
[Tue Jul 21 07:40:36.390426 2026] [security2:error] [pid 254995:tid 255200] [client 4.204.201.85:3538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9MpP7v0rlcEGmVraFQ1AAAA2k"]
[Tue Jul 21 07:40:36.405983 2026] [security2:error] [pid 254995:tid 255154] [client 4.204.201.85:59960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/about.php"] [unique_id "al9MpP7v0rlcEGmVraFQ1QAAAzs"]
[Tue Jul 21 07:40:36.427734 2026] [security2:error] [pid 254995:tid 255266] [client 167.99.210.137:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.210.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MpP7v0rlcEGmVraFQ1gAAA5A"]
[Tue Jul 21 07:40:36.501180 2026] [proxy:error] [pid 254995:tid 255175] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.501244 2026] [proxy_http:error] [pid 254995:tid 255175] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.501768 2026] [proxy:error] [pid 254995:tid 255175] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.501803 2026] [proxy_http:error] [pid 254995:tid 255175] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.504365 2026] [proxy:error] [pid 254995:tid 255258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.504428 2026] [proxy_http:error] [pid 254995:tid 255258] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.505061 2026] [proxy:error] [pid 254995:tid 255258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.505088 2026] [proxy_http:error] [pid 254995:tid 255258] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.515832 2026] [security2:error] [pid 254995:tid 255176] [client 20.104.96.117:14653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9MpP7v0rlcEGmVraFQ2wAAA1E"]
[Tue Jul 21 07:40:36.638826 2026] [security2:error] [pid 254995:tid 255162] [client 64.225.75.246:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.75.225.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mo_7v0rlcEGmVraFQmwAAA0M"]
[Tue Jul 21 07:40:36.682720 2026] [security2:error] [pid 254995:tid 255276] [client 4.204.201.85:60389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/admin.php"] [unique_id "al9MpP7v0rlcEGmVraFQ4AAAA5o"]
[Tue Jul 21 07:40:36.695473 2026] [security2:error] [pid 254995:tid 255143] [client 122.186.204.214:50150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MpP7v0rlcEGmVraFQ4QAAAzA"]
[Tue Jul 21 07:40:36.695592 2026] [security2:error] [pid 254995:tid 255143] [client 122.186.204.214:50150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MpP7v0rlcEGmVraFQ4QAAAzA"]
[Tue Jul 21 07:40:36.734682 2026] [security2:error] [pid 254995:tid 255188] [client 20.226.60.151:62312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wicked.php"] [unique_id "al9MpP7v0rlcEGmVraFQ5gAAA10"]
[Tue Jul 21 07:40:36.843311 2026] [proxy:error] [pid 254995:tid 255259] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.843392 2026] [proxy_http:error] [pid 254995:tid 255259] [client 20.104.96.117:14593] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.843905 2026] [proxy:error] [pid 254995:tid 255259] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:36.843938 2026] [proxy_http:error] [pid 254995:tid 255259] [client 20.104.96.117:14593] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:36.857969 2026] [security2:error] [pid 254995:tid 255148] [client 142.93.129.190:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.129.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MpP7v0rlcEGmVraFQ7QAAAzU"]
[Tue Jul 21 07:40:36.859540 2026] [security2:error] [pid 254995:tid 255275] [client 20.151.10.161:55294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/error_log.php"] [unique_id "al9MpP7v0rlcEGmVraFQ7gAAA5k"]
[Tue Jul 21 07:40:36.913719 2026] [security2:error] [pid 254995:tid 255026] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MpP7v0rlcEGmVraFQ8QADVB4"]
[Tue Jul 21 07:40:36.913846 2026] [security2:error] [pid 254995:tid 255179] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9MpP7v0rlcEGmVraFQ8QADVB4"]
[Tue Jul 21 07:40:36.958774 2026] [security2:error] [pid 254995:tid 255145] [client 4.204.201.85:61076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/edit.php"] [unique_id "al9MpP7v0rlcEGmVraFQ8wAAAzI"]
[Tue Jul 21 07:40:36.979294 2026] [security2:error] [pid 254995:tid 255218] [client 122.164.127.47:64812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MpP7v0rlcEGmVraFQ9AAAA3o"]
[Tue Jul 21 07:40:36.979386 2026] [security2:error] [pid 254995:tid 255218] [client 122.164.127.47:64812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MpP7v0rlcEGmVraFQ9AAAA3o"]
[Tue Jul 21 07:40:37.040758 2026] [security2:error] [pid 254995:tid 255141] [client 202.143.127.214:62606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpf7v0rlcEGmVraFQ9gAAAy4"]
[Tue Jul 21 07:40:37.041475 2026] [security2:error] [pid 254995:tid 255141] [client 202.143.127.214:62606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpf7v0rlcEGmVraFQ9gAAAy4"]
[Tue Jul 21 07:40:37.179142 2026] [proxy:error] [pid 254995:tid 255277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.179201 2026] [proxy_http:error] [pid 254995:tid 255277] [client 20.104.96.117:14358] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.179847 2026] [proxy:error] [pid 254995:tid 255277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.179875 2026] [proxy_http:error] [pid 254995:tid 255277] [client 20.104.96.117:14358] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.184660 2026] [security2:error] [pid 254995:tid 255274] [client 46.105.39.50:16715] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "leoamaraldev.com.br"] [uri "/robots.txt"] [unique_id "al9Mpf7v0rlcEGmVraFQ_QAAA5g"]
[Tue Jul 21 07:40:37.184742 2026] [security2:error] [pid 254995:tid 255274] [client 46.105.39.50:16715] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "leoamaraldev.com.br"] [uri "/robots.txt"] [unique_id "al9Mpf7v0rlcEGmVraFQ_QAAA5g"]
[Tue Jul 21 07:40:37.239148 2026] [security2:error] [pid 254995:tid 255199] [client 4.204.201.85:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-content/admin.php"] [unique_id "al9Mpf7v0rlcEGmVraFRAQAAA2g"]
[Tue Jul 21 07:40:37.284708 2026] [autoindex:error] [pid 254995:tid 255097] [remote 185.12.149.40:0] AH01276: Cannot serve directory /home1/bastar15/lacorsini.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://lacorsini.com.br/
[Tue Jul 21 07:40:37.310077 2026] [security2:error] [pid 254995:tid 255138] [client 154.192.233.199:60004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpf7v0rlcEGmVraFRCgAAAys"]
[Tue Jul 21 07:40:37.310264 2026] [security2:error] [pid 254995:tid 255138] [client 154.192.233.199:60004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpf7v0rlcEGmVraFRCgAAAys"]
[Tue Jul 21 07:40:37.393849 2026] [security2:error] [pid 254995:tid 255118] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpf7v0rlcEGmVraFREAADcHo"]
[Tue Jul 21 07:40:37.394073 2026] [security2:error] [pid 254995:tid 255208] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpf7v0rlcEGmVraFREAADcHo"]
[Tue Jul 21 07:40:37.444805 2026] [proxy:error] [pid 254995:tid 255191] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.444878 2026] [proxy_http:error] [pid 254995:tid 255191] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.445484 2026] [proxy:error] [pid 254995:tid 255191] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.445517 2026] [proxy_http:error] [pid 254995:tid 255191] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.461077 2026] [security2:error] [pid 254995:tid 255256] [client 20.104.96.117:14531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Mpf7v0rlcEGmVraFREwAAA4Y"]
[Tue Jul 21 07:40:37.477656 2026] [security2:error] [pid 254995:tid 255143] [client 207.154.197.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.197.154.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mpf7v0rlcEGmVraFRFQAAAzA"]
[Tue Jul 21 07:40:37.485757 2026] [proxy:error] [pid 254995:tid 255279] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.485935 2026] [proxy_http:error] [pid 254995:tid 255279] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.486381 2026] [proxy:error] [pid 254995:tid 255279] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.486403 2026] [proxy_http:error] [pid 254995:tid 255279] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.517797 2026] [security2:error] [pid 254995:tid 255190] [client 4.204.201.85:57417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ss.php"] [unique_id "al9Mpf7v0rlcEGmVraFRGAAAA18"]
[Tue Jul 21 07:40:37.649305 2026] [security2:error] [pid 254995:tid 255133] [client 20.226.60.151:59494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/vssrs.php"] [unique_id "al9Mpf7v0rlcEGmVraFRHAAAAyY"]
[Tue Jul 21 07:40:37.763310 2026] [security2:error] [pid 254995:tid 255172] [client 20.151.10.161:12051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xenon1337.php"] [unique_id "al9Mpf7v0rlcEGmVraFRIgAAA00"]
[Tue Jul 21 07:40:37.792850 2026] [security2:error] [pid 254995:tid 255252] [client 4.204.201.85:61060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/inputs.php"] [unique_id "al9Mpf7v0rlcEGmVraFRJQAAA4M"]
[Tue Jul 21 07:40:37.836573 2026] [security2:error] [pid 254995:tid 255262] [client 20.104.96.117:14594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/8.php"] [unique_id "al9Mpf7v0rlcEGmVraFRKgAAA4w"]
[Tue Jul 21 07:40:37.855994 2026] [security2:error] [pid 254995:tid 255174] [client 139.59.143.102:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.143.59.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mpf7v0rlcEGmVraFRLAAAA08"]
[Tue Jul 21 07:40:37.859546 2026] [proxy:error] [pid 254995:tid 255263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.859598 2026] [proxy_http:error] [pid 254995:tid 255263] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.860070 2026] [proxy:error] [pid 254995:tid 255263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:37.860095 2026] [proxy_http:error] [pid 254995:tid 255263] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:37.894724 2026] [security2:error] [pid 254995:tid 255259] [client 207.154.212.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.212.154.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mpf7v0rlcEGmVraFRHwAAA4k"]
[Tue Jul 21 07:40:38.011671 2026] [security2:error] [pid 254995:tid 255266] [client 182.8.255.181:21223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRNAAAA5A"]
[Tue Jul 21 07:40:38.011844 2026] [security2:error] [pid 254995:tid 255266] [client 182.8.255.181:21223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRNAAAA5A"]
[Tue Jul 21 07:40:38.053766 2026] [security2:error] [pid 254995:tid 255199] [client 20.226.60.151:62246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/24.php"] [unique_id "al9Mpv7v0rlcEGmVraFRNgAAA2g"]
[Tue Jul 21 07:40:38.068856 2026] [security2:error] [pid 254995:tid 255181] [client 4.204.201.85:57450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/av.php"] [unique_id "al9Mpv7v0rlcEGmVraFROAAAA1Y"]
[Tue Jul 21 07:40:38.132879 2026] [security2:error] [pid 254995:tid 255187] [client 103.86.117.203:63550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFROgAAA1w"]
[Tue Jul 21 07:40:38.133018 2026] [security2:error] [pid 254995:tid 255187] [client 103.86.117.203:63550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFROgAAA1w"]
[Tue Jul 21 07:40:38.156065 2026] [security2:error] [pid 254995:tid 255212] [client 175.45.70.82:55317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFROwAAA3Q"]
[Tue Jul 21 07:40:38.156176 2026] [security2:error] [pid 254995:tid 255212] [client 175.45.70.82:55317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFROwAAA3Q"]
[Tue Jul 21 07:40:38.194864 2026] [security2:error] [pid 254995:tid 255146] [client 20.104.96.117:14616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Mpv7v0rlcEGmVraFRPQAAAzM"]
[Tue Jul 21 07:40:38.197028 2026] [security2:error] [pid 254995:tid 255169] [client 194.99.104.35:35018] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRPgAAA0o"]
[Tue Jul 21 07:40:38.197086 2026] [security2:error] [pid 254995:tid 255169] [client 194.99.104.35:35018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRPgAAA0o"]
[Tue Jul 21 07:40:38.346132 2026] [security2:error] [pid 254995:tid 255190] [client 4.204.201.85:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/classwithtostring.php"] [unique_id "al9Mpv7v0rlcEGmVraFRSwAAA18"]
[Tue Jul 21 07:40:38.375891 2026] [security2:error] [pid 254995:tid 255267] [client 103.106.20.201:62260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRTQAAA5E"]
[Tue Jul 21 07:40:38.375983 2026] [security2:error] [pid 254995:tid 255267] [client 103.106.20.201:62260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRTQAAA5E"]
[Tue Jul 21 07:40:38.431957 2026] [security2:error] [pid 254995:tid 255196] [client 142.93.143.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.143.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mpv7v0rlcEGmVraFRUgAAA2U"]
[Tue Jul 21 07:40:38.433512 2026] [proxy:error] [pid 254995:tid 255205] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.433581 2026] [proxy_http:error] [pid 254995:tid 255205] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.434158 2026] [proxy:error] [pid 254995:tid 255205] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.434189 2026] [proxy_http:error] [pid 254995:tid 255205] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.502500 2026] [security2:error] [pid 254995:tid 255252] [client 20.226.60.151:23143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/file6.php"] [unique_id "al9Mpv7v0rlcEGmVraFRVgAAA4M"]
[Tue Jul 21 07:40:38.505485 2026] [proxy:error] [pid 254995:tid 255197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.505543 2026] [proxy_http:error] [pid 254995:tid 255197] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.506212 2026] [proxy:error] [pid 254995:tid 255197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.506245 2026] [proxy_http:error] [pid 254995:tid 255197] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.522267 2026] [security2:error] [pid 254995:tid 255222] [client 122.162.144.145:20232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRWAAAA34"]
[Tue Jul 21 07:40:38.522430 2026] [security2:error] [pid 254995:tid 255222] [client 122.162.144.145:20232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRWAAAA34"]
[Tue Jul 21 07:40:38.612119 2026] [security2:error] [pid 254995:tid 255164] [client 20.104.96.117:14590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/f6.php"] [unique_id "al9Mpv7v0rlcEGmVraFRWQAAA0U"]
[Tue Jul 21 07:40:38.627711 2026] [security2:error] [pid 254995:tid 255159] [client 4.204.201.85:57462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-content/themes/index.php"] [unique_id "al9Mpv7v0rlcEGmVraFRWwAAA0A"]
[Tue Jul 21 07:40:38.659268 2026] [security2:error] [pid 254995:tid 255214] [client 20.151.10.161:12066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/test11.php"] [unique_id "al9Mpv7v0rlcEGmVraFRXgAAA3Y"]
[Tue Jul 21 07:40:38.771574 2026] [security2:error] [pid 254995:tid 255155] [client 164.92.244.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.244.92.164.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mpv7v0rlcEGmVraFRYgAAAzw"]
[Tue Jul 21 07:40:38.860278 2026] [proxy:error] [pid 254995:tid 255154] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.860339 2026] [proxy_http:error] [pid 254995:tid 255154] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.860929 2026] [proxy:error] [pid 254995:tid 255154] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.860956 2026] [proxy_http:error] [pid 254995:tid 255154] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.868668 2026] [proxy:error] [pid 254995:tid 255273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.868715 2026] [proxy_http:error] [pid 254995:tid 255273] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.869156 2026] [proxy:error] [pid 254995:tid 255273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:38.869178 2026] [proxy_http:error] [pid 254995:tid 255273] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:38.870037 2026] [security2:error] [pid 254995:tid 255181] [client 194.99.104.35:59806] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRbwAAA1Y"]
[Tue Jul 21 07:40:38.870102 2026] [security2:error] [pid 254995:tid 255181] [client 194.99.104.35:59806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mpv7v0rlcEGmVraFRbwAAA1Y"]
[Tue Jul 21 07:40:38.904014 2026] [security2:error] [pid 254995:tid 255187] [client 20.104.96.117:14538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/inputs.php"] [unique_id "al9Mpv7v0rlcEGmVraFRcgAAA1w"]
[Tue Jul 21 07:40:38.905529 2026] [security2:error] [pid 254995:tid 255212] [client 4.204.201.85:61073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-blog.php"] [unique_id "al9Mpv7v0rlcEGmVraFRcwAAA3Q"]
[Tue Jul 21 07:40:39.015339 2026] [security2:error] [pid 254995:tid 255271] [client 20.226.60.151:62323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/xacs.php"] [unique_id "al9Mp_7v0rlcEGmVraFReQAAA5U"]
[Tue Jul 21 07:40:39.110753 2026] [security2:error] [pid 254995:tid 255129] [client 54.39.0.186:26248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "premiercservices.com"] [uri "/robots.txt"] [unique_id "al9Mp_7v0rlcEGmVraFRgAAAAyI"]
[Tue Jul 21 07:40:39.110865 2026] [security2:error] [pid 254995:tid 255129] [client 54.39.0.186:26248] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "premiercservices.com"] [uri "/robots.txt"] [unique_id "al9Mp_7v0rlcEGmVraFRgAAAAyI"]
[Tue Jul 21 07:40:39.174615 2026] [security2:error] [pid 254995:tid 255215] [client 206.81.12.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.12.81.206.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mpf7v0rlcEGmVraFQ-gAAA3c"]
[Tue Jul 21 07:40:39.207503 2026] [autoindex:error] [pid 254995:tid 255257] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:39.236284 2026] [security2:error] [pid 254995:tid 255131] [client 4.204.201.85:7474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Mp_7v0rlcEGmVraFRhwAAAyQ"]
[Tue Jul 21 07:40:39.261120 2026] [security2:error] [pid 254995:tid 255252] [client 20.104.96.117:14343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/inputs.php"] [unique_id "al9Mp_7v0rlcEGmVraFRiAAAA4M"]
[Tue Jul 21 07:40:39.433130 2026] [proxy:error] [pid 254995:tid 255157] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:39.433199 2026] [proxy_http:error] [pid 254995:tid 255157] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:39.434513 2026] [proxy:error] [pid 254995:tid 255157] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:39.434555 2026] [proxy_http:error] [pid 254995:tid 255157] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:39.482276 2026] [security2:error] [pid 254995:tid 255274] [client 4.204.201.85:57461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-content/admin.php"] [unique_id "al9Mp_7v0rlcEGmVraFRlQAAA5g"]
[Tue Jul 21 07:40:39.526401 2026] [security2:error] [pid 254995:tid 255045] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mp_7v0rlcEGmVraFRlgADTjE"]
[Tue Jul 21 07:40:39.526582 2026] [security2:error] [pid 254995:tid 255173] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mp_7v0rlcEGmVraFRlgADTjE"]
[Tue Jul 21 07:40:39.584034 2026] [security2:error] [pid 254995:tid 255132] [client 20.104.96.117:14628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Mp_7v0rlcEGmVraFRmwAAAyU"]
[Tue Jul 21 07:40:39.761508 2026] [security2:error] [pid 254995:tid 255166] [client 4.204.201.85:57423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/adminfuns.php"] [unique_id "al9Mp_7v0rlcEGmVraFRpAAAA0c"]
[Tue Jul 21 07:40:39.855273 2026] [proxy:error] [pid 254995:tid 255225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:39.855354 2026] [proxy_http:error] [pid 254995:tid 255225] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:39.855944 2026] [proxy:error] [pid 254995:tid 255225] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:39.855978 2026] [proxy_http:error] [pid 254995:tid 255225] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:39.859100 2026] [proxy:error] [pid 254995:tid 255143] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:39.859143 2026] [proxy_http:error] [pid 254995:tid 255143] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:39.859563 2026] [proxy:error] [pid 254995:tid 255143] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:39.859582 2026] [proxy_http:error] [pid 254995:tid 255143] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:39.863238 2026] [security2:error] [pid 254995:tid 255175] [client 209.38.208.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.208.38.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mpv7v0rlcEGmVraFRagAAA1A"]
[Tue Jul 21 07:40:39.888116 2026] [security2:error] [pid 254995:tid 255171] [client 20.104.96.117:14348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9Mp_7v0rlcEGmVraFRrgAAA0w"]
[Tue Jul 21 07:40:39.951505 2026] [security2:error] [pid 254995:tid 255257] [client 4.204.201.85:7435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/8.php"] [unique_id "al9Mp_7v0rlcEGmVraFRsQAAA4c"]
[Tue Jul 21 07:40:40.036420 2026] [security2:error] [pid 254995:tid 255176] [client 59.96.220.140:52125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MqP7v0rlcEGmVraFRuAAAA1E"]
[Tue Jul 21 07:40:40.036512 2026] [security2:error] [pid 254995:tid 255176] [client 59.96.220.140:52125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MqP7v0rlcEGmVraFRuAAAA1E"]
[Tue Jul 21 07:40:40.042515 2026] [security2:error] [pid 254995:tid 255161] [client 172.245.102.32:53481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MqP7v0rlcEGmVraFRugAAA0I"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:40.056658 2026] [security2:error] [pid 254995:tid 255172] [client 4.204.201.85:60379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/goods.php"] [unique_id "al9MqP7v0rlcEGmVraFRvAAAA00"]
[Tue Jul 21 07:40:40.139527 2026] [security2:error] [pid 254995:tid 255141] [client 20.226.60.151:56308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/v543.php"] [unique_id "al9MqP7v0rlcEGmVraFRwQAAAy4"]
[Tue Jul 21 07:40:40.214123 2026] [security2:error] [pid 254995:tid 255142] [client 20.226.60.151:62281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/zildan.php"] [unique_id "al9MqP7v0rlcEGmVraFRwgAAAy8"]
[Tue Jul 21 07:40:40.217499 2026] [proxy:error] [pid 254995:tid 255150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.217582 2026] [proxy_http:error] [pid 254995:tid 255150] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.218054 2026] [proxy:error] [pid 254995:tid 255150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.218091 2026] [proxy_http:error] [pid 254995:tid 255150] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.272629 2026] [security2:error] [pid 254995:tid 255158] [client 20.104.96.117:14605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-blog.php"] [unique_id "al9MqP7v0rlcEGmVraFRxwAAAz8"]
[Tue Jul 21 07:40:40.333244 2026] [security2:error] [pid 254995:tid 255200] [client 4.204.201.85:59935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ms-edit.php"] [unique_id "al9MqP7v0rlcEGmVraFRzAAAA2k"]
[Tue Jul 21 07:40:40.438164 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.438227 2026] [proxy_http:error] [pid 254995:tid 255268] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.438934 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.438969 2026] [proxy_http:error] [pid 254995:tid 255268] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.456014 2026] [autoindex:error] [pid 254995:tid 255208] [client 20.226.60.151:23144] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:40.467097 2026] [security2:error] [pid 254995:tid 255186] [client 20.226.60.151:23144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/adminfuns.php"] [unique_id "al9MqP7v0rlcEGmVraFR2QAAA1s"]
[Tue Jul 21 07:40:40.573517 2026] [security2:error] [pid 254995:tid 255198] [client 4.204.201.85:7447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-content/admin.php"] [unique_id "al9MqP7v0rlcEGmVraFR4gAAA2c"]
[Tue Jul 21 07:40:40.592495 2026] [proxy:error] [pid 254995:tid 255275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.592553 2026] [proxy_http:error] [pid 254995:tid 255275] [client 20.104.96.117:14624] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.593125 2026] [proxy:error] [pid 254995:tid 255275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.593149 2026] [proxy_http:error] [pid 254995:tid 255275] [client 20.104.96.117:14624] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.605688 2026] [security2:error] [pid 254995:tid 255196] [client 4.204.201.85:61083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/222.php"] [unique_id "al9MqP7v0rlcEGmVraFR5AAAA2U"]
[Tue Jul 21 07:40:40.631133 2026] [security2:error] [pid 254995:tid 255252] [client 20.151.10.161:55257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/koala.php"] [unique_id "al9MqP7v0rlcEGmVraFR5gAAA4M"]
[Tue Jul 21 07:40:40.717803 2026] [security2:error] [pid 254995:tid 255276] [client 54.39.89.96:50416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "premiercservices.com"] [uri "/"] [unique_id "al9MqP7v0rlcEGmVraFR6QAAA5o"]
[Tue Jul 21 07:40:40.717890 2026] [security2:error] [pid 254995:tid 255276] [client 54.39.89.96:50416] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "premiercservices.com"] [uri "/"] [unique_id "al9MqP7v0rlcEGmVraFR6QAAA5o"]
[Tue Jul 21 07:40:40.760266 2026] [security2:error] [pid 254995:tid 255169] [client 152.59.154.239:49522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MqP7v0rlcEGmVraFR6wAAA0o"]
[Tue Jul 21 07:40:40.760391 2026] [security2:error] [pid 254995:tid 255169] [client 152.59.154.239:49522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MqP7v0rlcEGmVraFR6wAAA0o"]
[Tue Jul 21 07:40:40.816962 2026] [security2:error] [pid 254995:tid 255141] [client 20.226.60.151:62256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/csa.php"] [unique_id "al9MqP7v0rlcEGmVraFR7gAAAy4"]
[Tue Jul 21 07:40:40.854982 2026] [proxy:error] [pid 254995:tid 255185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.855057 2026] [proxy_http:error] [pid 254995:tid 255185] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.855510 2026] [proxy:error] [pid 254995:tid 255185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.855535 2026] [proxy_http:error] [pid 254995:tid 255185] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.858581 2026] [proxy:error] [pid 254995:tid 255180] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.858641 2026] [proxy_http:error] [pid 254995:tid 255180] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.859230 2026] [proxy:error] [pid 254995:tid 255180] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:40.859255 2026] [proxy_http:error] [pid 254995:tid 255180] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:40.881486 2026] [security2:error] [pid 254995:tid 255150] [client 4.204.201.85:59924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/cgi-bin/index.php"] [unique_id "al9MqP7v0rlcEGmVraFR8wAAAzc"]
[Tue Jul 21 07:40:40.920846 2026] [security2:error] [pid 254995:tid 255147] [client 20.104.96.117:14603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MqP7v0rlcEGmVraFR-QAAAzQ"]
[Tue Jul 21 07:40:40.956954 2026] [security2:error] [pid 254995:tid 255197] [client 117.217.38.194:60801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MqP7v0rlcEGmVraFR_QAAA2Y"]
[Tue Jul 21 07:40:40.957155 2026] [security2:error] [pid 254995:tid 255197] [client 117.217.38.194:60801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MqP7v0rlcEGmVraFR_QAAA2Y"]
[Tue Jul 21 07:40:41.031034 2026] [security2:error] [pid 254995:tid 255100] [remote 206.189.95.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.95.189.206.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9MqP7v0rlcEGmVraFR8gADbmg"]
[Tue Jul 21 07:40:41.132573 2026] [security2:error] [pid 254995:tid 255191] [client 103.174.34.15:51287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSBQAAA2A"]
[Tue Jul 21 07:40:41.134626 2026] [security2:error] [pid 254995:tid 255191] [client 103.174.34.15:51287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSBQAAA2A"]
[Tue Jul 21 07:40:41.182832 2026] [autoindex:error] [pid 254995:tid 255279] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:41.218292 2026] [security2:error] [pid 254995:tid 255261] [client 184.75.223.211:53092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSDAAAA4s"]
[Tue Jul 21 07:40:41.218385 2026] [security2:error] [pid 254995:tid 255261] [client 184.75.223.211:53092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSDAAAA4s"]
[Tue Jul 21 07:40:41.219433 2026] [proxy:error] [pid 254995:tid 255182] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.219496 2026] [proxy_http:error] [pid 254995:tid 255182] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.220041 2026] [proxy:error] [pid 254995:tid 255182] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.220066 2026] [proxy_http:error] [pid 254995:tid 255182] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.230642 2026] [security2:error] [pid 254995:tid 255114] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSDQADJXY"]
[Tue Jul 21 07:40:41.230755 2026] [security2:error] [pid 254995:tid 255132] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSDQADJXY"]
[Tue Jul 21 07:40:41.291546 2026] [security2:error] [pid 254995:tid 255257] [client 4.204.201.85:7482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/f6.php"] [unique_id "al9Mqf7v0rlcEGmVraFSEAAAA4c"]
[Tue Jul 21 07:40:41.330829 2026] [security2:error] [pid 254995:tid 255196] [client 20.104.96.117:14612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ms-edit.php"] [unique_id "al9Mqf7v0rlcEGmVraFSEQAAA2U"]
[Tue Jul 21 07:40:41.437320 2026] [proxy:error] [pid 254995:tid 255164] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.437386 2026] [proxy_http:error] [pid 254995:tid 255164] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.438050 2026] [proxy:error] [pid 254995:tid 255164] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.438088 2026] [proxy_http:error] [pid 254995:tid 255164] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.457220 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:59950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/BDKR28WP.php"] [unique_id "al9Mqf7v0rlcEGmVraFSGwAAA0o"]
[Tue Jul 21 07:40:41.458363 2026] [security2:error] [pid 254995:tid 255163] [client 193.36.225.57:21725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MqP7v0rlcEGmVraFRyAAAA0Q"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:41.511240 2026] [security2:error] [pid 254995:tid 255222] [client 139.167.225.182:59161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSJAAAA34"]
[Tue Jul 21 07:40:41.513084 2026] [security2:error] [pid 254995:tid 255222] [client 139.167.225.182:59161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSJAAAA34"]
[Tue Jul 21 07:40:41.558463 2026] [security2:error] [pid 254995:tid 255214] [client 5.69.251.235:59610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.251.69.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mp_7v0rlcEGmVraFRmAAAA3Y"]
[Tue Jul 21 07:40:41.558593 2026] [security2:error] [pid 254995:tid 255214] [client 5.69.251.235:59610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mp_7v0rlcEGmVraFRmAAAA3Y"]
[Tue Jul 21 07:40:41.746877 2026] [security2:error] [pid 254995:tid 255175] [client 20.104.96.117:14370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Mqf7v0rlcEGmVraFSMgAAA1A"]
[Tue Jul 21 07:40:41.747056 2026] [autoindex:error] [pid 254995:tid 255140] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:41.759148 2026] [security2:error] [pid 254995:tid 255146] [client 4.204.201.85:3528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/inputs.php"] [unique_id "al9Mqf7v0rlcEGmVraFSNgAAAzM"]
[Tue Jul 21 07:40:41.822983 2026] [security2:error] [pid 254995:tid 255229] [client 20.151.10.161:55271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/mac.php"] [unique_id "al9Mqf7v0rlcEGmVraFSOAAAA4I"]
[Tue Jul 21 07:40:41.857488 2026] [proxy:error] [pid 254995:tid 255166] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.857593 2026] [proxy_http:error] [pid 254995:tid 255166] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.858178 2026] [proxy:error] [pid 254995:tid 255166] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.858204 2026] [proxy_http:error] [pid 254995:tid 255166] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.873110 2026] [proxy:error] [pid 254995:tid 255258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.873178 2026] [proxy_http:error] [pid 254995:tid 255258] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.873749 2026] [proxy:error] [pid 254995:tid 255258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:41.873776 2026] [proxy_http:error] [pid 254995:tid 255258] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:41.930050 2026] [security2:error] [pid 254995:tid 255190] [client 122.179.91.63:3280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSPAAAA18"]
[Tue Jul 21 07:40:41.930166 2026] [security2:error] [pid 254995:tid 255190] [client 122.179.91.63:3280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mqf7v0rlcEGmVraFSPAAAA18"]
[Tue Jul 21 07:40:42.032982 2026] [proxy:error] [pid 254995:tid 255161] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.033044 2026] [proxy_http:error] [pid 254995:tid 255161] [client 20.104.96.117:14545] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.033460 2026] [proxy:error] [pid 254995:tid 255161] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.033486 2026] [proxy_http:error] [pid 254995:tid 255161] [client 20.104.96.117:14545] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.035840 2026] [autoindex:error] [pid 254995:tid 255256] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:42.084909 2026] [security2:error] [pid 254995:tid 255163] [client 20.226.60.151:62301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/w3llscc.php"] [unique_id "al9Mqv7v0rlcEGmVraFSUgAAA0Q"]
[Tue Jul 21 07:40:42.139714 2026] [security2:error] [pid 254995:tid 255266] [client 193.36.225.150:48885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mqf7v0rlcEGmVraFSPwAAA5A"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:42.174332 2026] [security2:error] [pid 254995:tid 255150] [client 4.204.201.85:61082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp.php"] [unique_id "al9Mqv7v0rlcEGmVraFSVQAAAzc"]
[Tue Jul 21 07:40:42.221760 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.221835 2026] [proxy_http:error] [pid 254995:tid 255147] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.222458 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.222488 2026] [proxy_http:error] [pid 254995:tid 255147] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.240496 2026] [security2:error] [pid 254995:tid 255174] [client 20.226.60.151:59496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wicked.php"] [unique_id "al9Mqv7v0rlcEGmVraFSWQAAA08"]
[Tue Jul 21 07:40:42.338341 2026] [security2:error] [pid 254995:tid 255145] [client 20.104.96.117:14385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Mqv7v0rlcEGmVraFSWgAAAzI"]
[Tue Jul 21 07:40:42.426459 2026] [security2:error] [pid 254995:tid 255272] [client 4.204.201.85:3520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/inputs.php"] [unique_id "al9Mqv7v0rlcEGmVraFSXgAAA5Y"]
[Tue Jul 21 07:40:42.436485 2026] [proxy:error] [pid 254995:tid 255138] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.436545 2026] [proxy_http:error] [pid 254995:tid 255138] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.437044 2026] [proxy:error] [pid 254995:tid 255138] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.437072 2026] [proxy_http:error] [pid 254995:tid 255138] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.454476 2026] [security2:error] [pid 254995:tid 255273] [client 4.204.201.85:56529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/abcd.php"] [unique_id "al9Mqv7v0rlcEGmVraFSZAAAA5c"]
[Tue Jul 21 07:40:42.652244 2026] [proxy:error] [pid 254995:tid 255216] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.652319 2026] [proxy_http:error] [pid 254995:tid 255216] [client 20.104.96.117:14651] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.652886 2026] [proxy:error] [pid 254995:tid 255216] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.652914 2026] [proxy_http:error] [pid 254995:tid 255216] [client 20.104.96.117:14651] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.742794 2026] [security2:error] [pid 254995:tid 255131] [client 4.204.201.85:59966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/a1.php"] [unique_id "al9Mqv7v0rlcEGmVraFSdQAAAyQ"]
[Tue Jul 21 07:40:42.858063 2026] [proxy:error] [pid 254995:tid 255202] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.858133 2026] [proxy_http:error] [pid 254995:tid 255202] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.858675 2026] [proxy:error] [pid 254995:tid 255202] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.858699 2026] [proxy_http:error] [pid 254995:tid 255202] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.860151 2026] [proxy:error] [pid 254995:tid 255187] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.860234 2026] [proxy_http:error] [pid 254995:tid 255187] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.860861 2026] [proxy:error] [pid 254995:tid 255187] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.860888 2026] [proxy_http:error] [pid 254995:tid 255187] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.980058 2026] [proxy:error] [pid 254995:tid 255137] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.980150 2026] [proxy_http:error] [pid 254995:tid 255137] [client 20.104.96.117:14549] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:42.980828 2026] [proxy:error] [pid 254995:tid 255137] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:42.980861 2026] [proxy_http:error] [pid 254995:tid 255137] [client 20.104.96.117:14549] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.018271 2026] [security2:error] [pid 254995:tid 255180] [client 4.204.201.85:60367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9Mq_7v0rlcEGmVraFShAAAA1U"]
[Tue Jul 21 07:40:43.132690 2026] [security2:error] [pid 254995:tid 255272] [client 4.204.201.85:3526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/classwithtostring.php"] [unique_id "al9Mq_7v0rlcEGmVraFSjgAAA5Y"]
[Tue Jul 21 07:40:43.133067 2026] [security2:error] [pid 254995:tid 255154] [client 20.226.60.151:22942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/goods.php"] [unique_id "al9Mq_7v0rlcEGmVraFSjwAAAzs"]
[Tue Jul 21 07:40:43.234559 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.234613 2026] [proxy_http:error] [pid 254995:tid 255268] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.235186 2026] [proxy:error] [pid 254995:tid 255268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.235212 2026] [proxy_http:error] [pid 254995:tid 255268] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.271192 2026] [security2:error] [pid 254995:tid 255186] [client 20.104.96.117:14391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/abcd.php"] [unique_id "al9Mq_7v0rlcEGmVraFSmAAAA1s"]
[Tue Jul 21 07:40:43.308937 2026] [security2:error] [pid 254995:tid 255166] [client 4.204.201.85:61059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/cgi-bin/admin.php"] [unique_id "al9Mq_7v0rlcEGmVraFSmQAAA0c"]
[Tue Jul 21 07:40:43.434806 2026] [proxy:error] [pid 254995:tid 255149] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.434880 2026] [proxy_http:error] [pid 254995:tid 255149] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.435370 2026] [proxy:error] [pid 254995:tid 255149] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.435398 2026] [proxy_http:error] [pid 254995:tid 255149] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.449488 2026] [security2:error] [pid 254995:tid 255277] [client 173.24.185.52:49416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Mq_7v0rlcEGmVraFSoAAAA5s"]
[Tue Jul 21 07:40:43.454090 2026] [security2:error] [pid 254995:tid 255277] [client 173.24.185.52:49416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Mq_7v0rlcEGmVraFSoAAAA5s"]
[Tue Jul 21 07:40:43.584508 2026] [security2:error] [pid 254995:tid 255128] [client 4.204.201.85:57447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/gettest.php"] [unique_id "al9Mq_7v0rlcEGmVraFSpgAAAyE"]
[Tue Jul 21 07:40:43.594877 2026] [security2:error] [pid 254995:tid 255125] [client 128.199.182.152:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.182.199.128.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marcelafernandasanto1782482982343.0721679.meusitehostgator.com.br"] [uri "/info.php"] [unique_id "al9Mqf7v0rlcEGmVraFSGAAAAx4"]
[Tue Jul 21 07:40:43.660091 2026] [security2:error] [pid 254995:tid 255164] [client 20.104.96.117:14647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/file15.php"] [unique_id "al9Mq_7v0rlcEGmVraFSqQAAA0U"]
[Tue Jul 21 07:40:43.691868 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:62288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wpx.php"] [unique_id "al9Mq_7v0rlcEGmVraFSrQAAA3w"]
[Tue Jul 21 07:40:43.739807 2026] [security2:error] [pid 254995:tid 255168] [client 20.226.60.151:23155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/100.php"] [unique_id "al9Mq_7v0rlcEGmVraFSsAAAA0k"]
[Tue Jul 21 07:40:43.822893 2026] [security2:error] [pid 254995:tid 255127] [client 4.204.201.85:7451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9Mq_7v0rlcEGmVraFSswAAAyA"]
[Tue Jul 21 07:40:43.859678 2026] [proxy:error] [pid 254995:tid 255214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.859738 2026] [proxy_http:error] [pid 254995:tid 255214] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.860199 2026] [proxy:error] [pid 254995:tid 255214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.860223 2026] [proxy_http:error] [pid 254995:tid 255214] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.861877 2026] [proxy:error] [pid 254995:tid 255211] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.861928 2026] [proxy_http:error] [pid 254995:tid 255211] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.862358 2026] [proxy:error] [pid 254995:tid 255211] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:43.862402 2026] [proxy_http:error] [pid 254995:tid 255211] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:43.980966 2026] [security2:error] [pid 254995:tid 255154] [client 20.151.10.161:53596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9Mq_7v0rlcEGmVraFSvgAAAzs"]
[Tue Jul 21 07:40:43.983810 2026] [security2:error] [pid 254995:tid 255181] [client 20.104.96.117:14336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/jp.php"] [unique_id "al9Mq_7v0rlcEGmVraFSwAAAA1Y"]
[Tue Jul 21 07:40:44.214775 2026] [proxy:error] [pid 254995:tid 255149] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.214857 2026] [proxy_http:error] [pid 254995:tid 255149] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.215461 2026] [proxy:error] [pid 254995:tid 255149] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.215504 2026] [proxy_http:error] [pid 254995:tid 255149] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.249889 2026] [security2:error] [pid 254995:tid 255087] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MrP7v0rlcEGmVraFS1gADXls"]
[Tue Jul 21 07:40:44.250079 2026] [security2:error] [pid 254995:tid 255189] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9MrP7v0rlcEGmVraFS1gADXls"]
[Tue Jul 21 07:40:44.284055 2026] [security2:error] [pid 254995:tid 255267] [client 20.104.96.117:14572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/f35.php"] [unique_id "al9MrP7v0rlcEGmVraFS2AAAA5E"]
[Tue Jul 21 07:40:44.324736 2026] [security2:error] [pid 254995:tid 255255] [client 106.215.181.8:6642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MrP7v0rlcEGmVraFS2gAAA4U"]
[Tue Jul 21 07:40:44.329974 2026] [security2:error] [pid 254995:tid 255255] [client 106.215.181.8:6642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MrP7v0rlcEGmVraFS2gAAA4U"]
[Tue Jul 21 07:40:44.449523 2026] [proxy:error] [pid 254995:tid 255168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.449590 2026] [proxy_http:error] [pid 254995:tid 255168] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.450281 2026] [proxy:error] [pid 254995:tid 255168] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.450315 2026] [proxy_http:error] [pid 254995:tid 255168] [client 167.99.210.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.489521 2026] [security2:error] [pid 254995:tid 255133] [client 20.226.60.151:23124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/about.php"] [unique_id "al9MrP7v0rlcEGmVraFS4wAAAyY"]
[Tue Jul 21 07:40:44.515268 2026] [security2:error] [pid 254995:tid 255163] [client 4.204.201.85:3582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-blog.php"] [unique_id "al9MrP7v0rlcEGmVraFS5AAAA0Q"]
[Tue Jul 21 07:40:44.531415 2026] [security2:error] [pid 254995:tid 255263] [client 4.204.201.85:56515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/simple.php"] [unique_id "al9MrP7v0rlcEGmVraFS5QAAA40"]
[Tue Jul 21 07:40:44.694211 2026] [security2:error] [pid 254995:tid 255140] [client 20.104.96.117:14606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-load.php"] [unique_id "al9MrP7v0rlcEGmVraFS8QAAAy0"]
[Tue Jul 21 07:40:44.756284 2026] [security2:error] [pid 254995:tid 255279] [client 20.226.60.151:62321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-css.php"] [unique_id "al9MrP7v0rlcEGmVraFS9QAAA50"]
[Tue Jul 21 07:40:44.807021 2026] [security2:error] [pid 254995:tid 255143] [client 4.204.201.85:57426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/xxx.php"] [unique_id "al9MrP7v0rlcEGmVraFS9gAAAzA"]
[Tue Jul 21 07:40:44.865096 2026] [proxy:error] [pid 254995:tid 255257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.865161 2026] [proxy_http:error] [pid 254995:tid 255257] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.865713 2026] [proxy:error] [pid 254995:tid 255257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.865737 2026] [proxy_http:error] [pid 254995:tid 255257] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.868075 2026] [proxy:error] [pid 254995:tid 255260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.868165 2026] [proxy_http:error] [pid 254995:tid 255260] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.869316 2026] [proxy:error] [pid 254995:tid 255260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:44.869381 2026] [proxy_http:error] [pid 254995:tid 255260] [client 142.93.129.190:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:44.962616 2026] [security2:error] [pid 254995:tid 255189] [client 20.226.60.151:56234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/sixxis.php"] [unique_id "al9MrP7v0rlcEGmVraFS-wAAA14"]
[Tue Jul 21 07:40:44.988736 2026] [security2:error] [pid 254995:tid 255131] [client 20.104.96.117:14597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/xyn.php"] [unique_id "al9MrP7v0rlcEGmVraFS_QAAAyQ"]
[Tue Jul 21 07:40:45.044990 2026] [security2:error] [pid 254995:tid 255021] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mrf7v0rlcEGmVraFS_wADkRk"]
[Tue Jul 21 07:40:45.045140 2026] [security2:error] [pid 254995:tid 255267] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mrf7v0rlcEGmVraFS_wADkRk"]
[Tue Jul 21 07:40:45.082892 2026] [security2:error] [pid 254995:tid 255255] [client 4.204.201.85:61058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/hypo.php"] [unique_id "al9Mrf7v0rlcEGmVraFTAAAAA4U"]
[Tue Jul 21 07:40:45.215057 2026] [proxy:error] [pid 254995:tid 255199] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.215124 2026] [proxy_http:error] [pid 254995:tid 255199] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.215685 2026] [proxy:error] [pid 254995:tid 255199] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.215709 2026] [proxy_http:error] [pid 254995:tid 255199] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.267555 2026] [security2:error] [pid 254995:tid 255266] [client 20.226.60.151:22936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/about.php"] [unique_id "al9Mrf7v0rlcEGmVraFTDAAAA5A"]
[Tue Jul 21 07:40:45.318401 2026] [security2:error] [pid 254995:tid 255141] [client 20.226.60.151:59477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/24.php"] [unique_id "al9Mrf7v0rlcEGmVraFTDwAAAy4"]
[Tue Jul 21 07:40:45.410035 2026] [autoindex:error] [pid 254995:tid 255273] [client 4.204.201.85:59934] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:45.449065 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.449606 2026] [proxy_http:error] [pid 254995:tid 255147] [client 20.104.96.117:14613] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.450334 2026] [proxy:error] [pid 254995:tid 255147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.450377 2026] [proxy_http:error] [pid 254995:tid 255147] [client 20.104.96.117:14613] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.454395 2026] [security2:error] [pid 254995:tid 255140] [client 20.151.10.161:53580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wefile.php"] [unique_id "al9Mrf7v0rlcEGmVraFTEwAAAy0"]
[Tue Jul 21 07:40:45.505837 2026] [security2:error] [pid 254995:tid 255192] [client 20.226.60.151:62326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ho.php"] [unique_id "al9Mrf7v0rlcEGmVraFTFQAAA2E"]
[Tue Jul 21 07:40:45.531149 2026] [security2:error] [pid 254995:tid 255279] [client 20.226.60.151:23158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/admin.php"] [unique_id "al9Mrf7v0rlcEGmVraFTFgAAA50"]
[Tue Jul 21 07:40:45.684904 2026] [security2:error] [pid 254995:tid 255197] [client 4.204.201.85:59934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/chosen.php"] [unique_id "al9Mrf7v0rlcEGmVraFTIAAAA2Y"]
[Tue Jul 21 07:40:45.798364 2026] [security2:error] [pid 254995:tid 255144] [client 20.226.60.151:23165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/admin.php"] [unique_id "al9Mrf7v0rlcEGmVraFTLAAAAzE"]
[Tue Jul 21 07:40:45.799486 2026] [security2:error] [pid 254995:tid 255271] [client 117.251.86.144:55190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mrf7v0rlcEGmVraFTLQAAA5U"]
[Tue Jul 21 07:40:45.799572 2026] [security2:error] [pid 254995:tid 255271] [client 117.251.86.144:55190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mrf7v0rlcEGmVraFTLQAAA5U"]
[Tue Jul 21 07:40:45.809333 2026] [security2:error] [pid 254995:tid 255157] [client 193.36.225.69:34387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Mrf7v0rlcEGmVraFTLwAAAz4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:45.842638 2026] [proxy:error] [pid 254995:tid 255276] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.842711 2026] [proxy_http:error] [pid 254995:tid 255276] [client 20.104.96.117:14377] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.843444 2026] [proxy:error] [pid 254995:tid 255276] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.843474 2026] [proxy_http:error] [pid 254995:tid 255276] [client 20.104.96.117:14377] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.870196 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.870268 2026] [proxy_http:error] [pid 254995:tid 255176] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.870931 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:45.870975 2026] [proxy_http:error] [pid 254995:tid 255176] [client 139.59.143.102:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:45.933660 2026] [security2:error] [pid 254995:tid 255199] [client 4.204.201.85:7460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-content/admin.php"] [unique_id "al9Mrf7v0rlcEGmVraFTNQAAA2g"]
[Tue Jul 21 07:40:45.977206 2026] [autoindex:error] [pid 254995:tid 255163] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:46.007545 2026] [security2:error] [pid 254995:tid 255224] [client 20.226.60.151:62270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/xy.php"] [unique_id "al9Mrv7v0rlcEGmVraFTPAAAA4A"]
[Tue Jul 21 07:40:46.017299 2026] [security2:error] [pid 254995:tid 255058] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mrv7v0rlcEGmVraFTPQADHj4"]
[Tue Jul 21 07:40:46.017458 2026] [security2:error] [pid 254995:tid 255125] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mrv7v0rlcEGmVraFTPQADHj4"]
[Tue Jul 21 07:40:46.024727 2026] [security2:error] [pid 254995:tid 255219] [client 20.226.60.151:56306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ip.php"] [unique_id "al9Mrv7v0rlcEGmVraFTPgAAA3s"]
[Tue Jul 21 07:40:46.087637 2026] [security2:error] [pid 254995:tid 255127] [client 196.251.121.187:57312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "fit4me.store"] [uri "/wp-json/batch/v1"] [unique_id "al9Mrv7v0rlcEGmVraFTQAAAAyA"]
[Tue Jul 21 07:40:46.127412 2026] [security2:error] [pid 254995:tid 255272] [client 122.186.204.214:50680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mrv7v0rlcEGmVraFTQQAAA5Y"]
[Tue Jul 21 07:40:46.127575 2026] [security2:error] [pid 254995:tid 255272] [client 122.186.204.214:50680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mrv7v0rlcEGmVraFTQQAAA5Y"]
[Tue Jul 21 07:40:46.163693 2026] [security2:error] [pid 254995:tid 255150] [client 20.104.96.117:14652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ccc.php"] [unique_id "al9Mrv7v0rlcEGmVraFTQwAAAzc"]
[Tue Jul 21 07:40:46.189282 2026] [security2:error] [pid 254995:tid 255138] [client 20.226.60.151:62244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/loader.php"] [unique_id "al9Mrv7v0rlcEGmVraFTRAAAAys"]
[Tue Jul 21 07:40:46.231380 2026] [proxy:error] [pid 254995:tid 255260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:46.231442 2026] [proxy_http:error] [pid 254995:tid 255260] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:46.232119 2026] [proxy:error] [pid 254995:tid 255260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:46.232148 2026] [proxy_http:error] [pid 254995:tid 255260] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:46.263390 2026] [security2:error] [pid 254995:tid 255211] [client 4.204.201.85:61086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/als.php"] [unique_id "al9Mrv7v0rlcEGmVraFTTQAAA3M"]
[Tue Jul 21 07:40:46.290897 2026] [security2:error] [pid 254995:tid 255190] [client 20.226.60.151:62221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/spadex.php"] [unique_id "al9Mrv7v0rlcEGmVraFTTwAAA18"]
[Tue Jul 21 07:40:46.452739 2026] [security2:error] [pid 254995:tid 255202] [client 20.226.60.151:23146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/themes.php"] [unique_id "al9Mrv7v0rlcEGmVraFTVwAAA2s"]
[Tue Jul 21 07:40:46.519217 2026] [security2:error] [pid 254995:tid 255159] [client 4.204.201.85:3530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ms-edit.php"] [unique_id "al9Mrv7v0rlcEGmVraFTWQAAA0A"]
[Tue Jul 21 07:40:46.528183 2026] [security2:error] [pid 254995:tid 255274] [client 20.104.96.117:14626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/w.php"] [unique_id "al9Mrv7v0rlcEGmVraFTWgAAA5g"]
[Tue Jul 21 07:40:46.540629 2026] [security2:error] [pid 254995:tid 255215] [client 4.204.201.85:59910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/pol.php"] [unique_id "al9Mrv7v0rlcEGmVraFTWwAAA3c"]
[Tue Jul 21 07:40:46.576985 2026] [security2:error] [pid 254995:tid 255168] [client 20.220.225.223:5271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Mrv7v0rlcEGmVraFTXQAAA0k"]
[Tue Jul 21 07:40:46.599938 2026] [security2:error] [pid 254995:tid 255199] [client 20.226.60.151:62320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/2x.php"] [unique_id "al9Mrv7v0rlcEGmVraFTXgAAA2g"]
[Tue Jul 21 07:40:46.721939 2026] [security2:error] [pid 254995:tid 255042] [remote 185.27.20.235:44234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.20.27.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/wp-login.php"] [unique_id "al9Mrv7v0rlcEGmVraFTYwADMS4"]
[Tue Jul 21 07:40:46.799237 2026] [autoindex:error] [pid 254995:tid 255175] [client 20.226.60.151:22916] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:46.816144 2026] [security2:error] [pid 254995:tid 255260] [client 4.204.201.85:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/file5.php"] [unique_id "al9Mrv7v0rlcEGmVraFTbAAAA4o"]
[Tue Jul 21 07:40:46.933656 2026] [security2:error] [pid 254995:tid 255136] [client 20.104.96.117:14630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Mrv7v0rlcEGmVraFTbgAAAyk"]
[Tue Jul 21 07:40:46.951690 2026] [security2:error] [pid 254995:tid 255223] [client 4.204.201.85:7465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/cgi-bin/index.php"] [unique_id "al9Mrv7v0rlcEGmVraFTbwAAA38"]
[Tue Jul 21 07:40:47.014116 2026] [security2:error] [pid 254995:tid 255012] [remote 154.61.75.100:33410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-login.php"] [unique_id "al9Mr_7v0rlcEGmVraFTcAADkxA"]
[Tue Jul 21 07:40:47.085917 2026] [core:error] [pid 254995:tid 255256] [client 137.184.93.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:47.085933 2026] [core:error] [pid 254995:tid 255256] [client 137.184.93.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:47.092955 2026] [security2:error] [pid 254995:tid 255202] [client 4.204.201.85:61095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/file.php"] [unique_id "al9Mr_7v0rlcEGmVraFTewAAA2s"]
[Tue Jul 21 07:40:47.224969 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:47.225051 2026] [proxy_http:error] [pid 254995:tid 255176] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:47.225553 2026] [proxy:error] [pid 254995:tid 255176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:47.225579 2026] [proxy_http:error] [pid 254995:tid 255176] [client 209.38.208.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:47.238037 2026] [security2:error] [pid 254995:tid 255163] [client 20.104.96.117:14535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/FWAZ.php"] [unique_id "al9Mr_7v0rlcEGmVraFTggAAA0Q"]
[Tue Jul 21 07:40:47.338567 2026] [security2:error] [pid 254995:tid 255219] [client 20.220.225.223:5266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Mr_7v0rlcEGmVraFTqgAAA3s"]
[Tue Jul 21 07:40:47.393881 2026] [security2:error] [pid 254995:tid 255213] [client 4.204.201.85:61111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/cfile.php"] [unique_id "al9Mr_7v0rlcEGmVraFTrQAAA3U"]
[Tue Jul 21 07:40:47.427850 2026] [security2:error] [pid 254995:tid 255065] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mr_7v0rlcEGmVraFTrgADOUU"]
[Tue Jul 21 07:40:47.428062 2026] [security2:error] [pid 254995:tid 255152] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mr_7v0rlcEGmVraFTrgADOUU"]
[Tue Jul 21 07:40:47.456043 2026] [security2:error] [pid 254995:tid 255029] [remote 152.53.111.131:52330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Mr_7v0rlcEGmVraFTsAADPCE"]
[Tue Jul 21 07:40:47.510685 2026] [security2:error] [pid 254995:tid 255169] [client 122.164.127.47:65375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mr_7v0rlcEGmVraFTtQAAA0o"]
[Tue Jul 21 07:40:47.510778 2026] [security2:error] [pid 254995:tid 255169] [client 122.164.127.47:65375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mr_7v0rlcEGmVraFTtQAAA0o"]
[Tue Jul 21 07:40:47.546108 2026] [security2:error] [pid 254995:tid 255177] [client 20.104.96.117:14530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/miru1.php"] [unique_id "al9Mr_7v0rlcEGmVraFTtwAAA1I"]
[Tue Jul 21 07:40:47.562664 2026] [core:error] [pid 254995:tid 254998] [remote 5.255.231.176:52976] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:47.562685 2026] [core:error] [pid 254995:tid 254998] [remote 5.255.231.176:52976] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:40:47.687913 2026] [security2:error] [pid 254995:tid 255197] [client 4.204.201.85:59938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/admin.php"] [unique_id "al9Mr_7v0rlcEGmVraFTvQAAA2Y"]
[Tue Jul 21 07:40:47.794675 2026] [security2:error] [pid 254995:tid 255269] [client 20.226.60.151:59424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/xacs.php"] [unique_id "al9Mr_7v0rlcEGmVraFTwgAAA5M"]
[Tue Jul 21 07:40:47.858557 2026] [security2:error] [pid 254995:tid 255159] [client 20.104.96.117:14640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/aa.php"] [unique_id "al9Mr_7v0rlcEGmVraFTzAAAA0A"]
[Tue Jul 21 07:40:47.912243 2026] [security2:error] [pid 254995:tid 255196] [client 154.192.233.199:60322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mr_7v0rlcEGmVraFTzwAAA2U"]
[Tue Jul 21 07:40:47.912414 2026] [security2:error] [pid 254995:tid 255196] [client 154.192.233.199:60322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mr_7v0rlcEGmVraFTzwAAA2U"]
[Tue Jul 21 07:40:47.963626 2026] [security2:error] [pid 254995:tid 255173] [client 4.204.201.85:57418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/aa2.php"] [unique_id "al9Mr_7v0rlcEGmVraFT0QAAA04"]
[Tue Jul 21 07:40:47.974810 2026] [security2:error] [pid 254995:tid 255125] [client 4.204.201.85:7439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/BDKR28WP.php"] [unique_id "al9Mr_7v0rlcEGmVraFT0gAAAx4"]
[Tue Jul 21 07:40:48.060283 2026] [security2:error] [pid 254995:tid 255151] [client 20.226.60.151:62211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ctex1.php"] [unique_id "al9MsP7v0rlcEGmVraFT1QAAAzg"]
[Tue Jul 21 07:40:48.062908 2026] [security2:error] [pid 254995:tid 255213] [client 20.226.60.151:22916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/.well-known/about.php"] [unique_id "al9MsP7v0rlcEGmVraFT1gAAA3U"]
[Tue Jul 21 07:40:48.101069 2026] [security2:error] [pid 254995:tid 255120] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT2AADiXw"]
[Tue Jul 21 07:40:48.101216 2026] [security2:error] [pid 254995:tid 255259] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT2AADiXw"]
[Tue Jul 21 07:40:48.106597 2026] [security2:error] [pid 254995:tid 255143] [client 202.143.127.214:63026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT2QAAAzA"]
[Tue Jul 21 07:40:48.106720 2026] [security2:error] [pid 254995:tid 255143] [client 202.143.127.214:63026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT2QAAAzA"]
[Tue Jul 21 07:40:48.145650 2026] [security2:error] [pid 254995:tid 255191] [client 20.104.96.117:14604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/122.php"] [unique_id "al9MsP7v0rlcEGmVraFT2gAAA2A"]
[Tue Jul 21 07:40:48.247945 2026] [security2:error] [pid 254995:tid 255177] [client 4.204.201.85:57420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ccou.php"] [unique_id "al9MsP7v0rlcEGmVraFT3QAAA1I"]
[Tue Jul 21 07:40:48.384736 2026] [security2:error] [pid 254995:tid 255225] [client 182.8.255.181:17596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT6AAAA4E"]
[Tue Jul 21 07:40:48.384854 2026] [security2:error] [pid 254995:tid 255225] [client 182.8.255.181:17596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT6AAAA4E"]
[Tue Jul 21 07:40:48.444700 2026] [security2:error] [pid 254995:tid 255159] [client 20.104.96.117:13069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/get.php"] [unique_id "al9MsP7v0rlcEGmVraFT7QAAA0A"]
[Tue Jul 21 07:40:48.452288 2026] [security2:error] [pid 254995:tid 255171] [client 185.198.240.105:49497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "voweltravel.com.br"] [uri "/wp-login.php"] [unique_id "al9Mr_7v0rlcEGmVraFTrwAAA0w"]
[Tue Jul 21 07:40:48.532466 2026] [security2:error] [pid 254995:tid 255163] [client 4.204.201.85:59915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/dr.php"] [unique_id "al9MsP7v0rlcEGmVraFT7wAAA0Q"]
[Tue Jul 21 07:40:48.605417 2026] [security2:error] [pid 254995:tid 255275] [client 103.86.117.203:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT8QAAA5k"]
[Tue Jul 21 07:40:48.605553 2026] [security2:error] [pid 254995:tid 255275] [client 103.86.117.203:64075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT8QAAA5k"]
[Tue Jul 21 07:40:48.637580 2026] [security2:error] [pid 254995:tid 255176] [client 209.141.34.121:55850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "ericksheik.com.br"] [uri "/"] [unique_id "al9MsP7v0rlcEGmVraFT8gAAA1E"]
[Tue Jul 21 07:40:48.681799 2026] [security2:error] [pid 254995:tid 255219] [client 62.102.148.187:59500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT9wAAA3s"]
[Tue Jul 21 07:40:48.681944 2026] [security2:error] [pid 254995:tid 255219] [client 62.102.148.187:59500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT9wAAA3s"]
[Tue Jul 21 07:40:48.690679 2026] [security2:error] [pid 254995:tid 255148] [client 20.226.60.151:23137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9MsP7v0rlcEGmVraFT-AAAAzU"]
[Tue Jul 21 07:40:48.750011 2026] [security2:error] [pid 254995:tid 255155] [client 20.104.96.117:14595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/as.php"] [unique_id "al9MsP7v0rlcEGmVraFT-QAAAzw"]
[Tue Jul 21 07:40:48.785405 2026] [security2:error] [pid 254995:tid 255152] [client 175.45.70.82:55828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT_gAAAzk"]
[Tue Jul 21 07:40:48.785504 2026] [security2:error] [pid 254995:tid 255152] [client 175.45.70.82:55828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFT_gAAAzk"]
[Tue Jul 21 07:40:48.807881 2026] [security2:error] [pid 254995:tid 255279] [client 4.204.201.85:60368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/xamp.php"] [unique_id "al9MsP7v0rlcEGmVraFUAAAAA50"]
[Tue Jul 21 07:40:48.876986 2026] [security2:error] [pid 254995:tid 255263] [client 194.99.104.35:34454] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFUAgAAA40"]
[Tue Jul 21 07:40:48.877069 2026] [security2:error] [pid 254995:tid 255263] [client 194.99.104.35:34454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9MsP7v0rlcEGmVraFUAgAAA40"]
[Tue Jul 21 07:40:48.920069 2026] [security2:error] [pid 254995:tid 255222] [client 4.204.201.85:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/abcd.php"] [unique_id "al9MsP7v0rlcEGmVraFUCAAAA34"]
[Tue Jul 21 07:40:48.973733 2026] [security2:error] [pid 254995:tid 255267] [client 20.226.60.151:62222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/edorxrr.php"] [unique_id "al9MsP7v0rlcEGmVraFUCgAAA5E"]
[Tue Jul 21 07:40:49.081224 2026] [security2:error] [pid 254995:tid 255193] [client 20.104.96.117:14556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ccou.php"] [unique_id "al9Msf7v0rlcEGmVraFUDQAAA2I"]
[Tue Jul 21 07:40:49.084161 2026] [security2:error] [pid 254995:tid 255229] [client 4.204.201.85:59933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/bless.php"] [unique_id "al9Msf7v0rlcEGmVraFUDgAAA4I"]
[Tue Jul 21 07:40:49.142781 2026] [security2:error] [pid 254995:tid 255196] [client 103.106.20.201:62849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Msf7v0rlcEGmVraFUDwAAA2U"]
[Tue Jul 21 07:40:49.142897 2026] [security2:error] [pid 254995:tid 255196] [client 103.106.20.201:62849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Msf7v0rlcEGmVraFUDwAAA2U"]
[Tue Jul 21 07:40:49.151311 2026] [security2:error] [pid 254995:tid 255269] [client 209.141.34.121:55876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "ericksheik.com.br"] [uri "/"] [unique_id "al9Msf7v0rlcEGmVraFUEAAAA5M"]
[Tue Jul 21 07:40:49.164324 2026] [security2:error] [pid 254995:tid 255216] [client 20.226.60.151:22924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wefile.php"] [unique_id "al9Msf7v0rlcEGmVraFUEQAAA3g"]
[Tue Jul 21 07:40:49.233382 2026] [security2:error] [pid 254995:tid 255215] [client 122.162.144.145:20041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Msf7v0rlcEGmVraFUFwAAA3c"]
[Tue Jul 21 07:40:49.233510 2026] [security2:error] [pid 254995:tid 255215] [client 122.162.144.145:20041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Msf7v0rlcEGmVraFUFwAAA3c"]
[Tue Jul 21 07:40:49.278114 2026] [security2:error] [pid 254995:tid 255176] [client 4.204.201.85:3583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/file15.php"] [unique_id "al9Msf7v0rlcEGmVraFUGgAAA1E"]
[Tue Jul 21 07:40:49.370119 2026] [security2:error] [pid 254995:tid 255197] [client 4.204.201.85:56540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/file25.php"] [unique_id "al9Msf7v0rlcEGmVraFUIgAAA2Y"]
[Tue Jul 21 07:40:49.391789 2026] [security2:error] [pid 254995:tid 255155] [client 20.104.96.117:14599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/w3lls.php"] [unique_id "al9Msf7v0rlcEGmVraFUIwAAAzw"]
[Tue Jul 21 07:40:49.646159 2026] [security2:error] [pid 254995:tid 255257] [client 4.204.201.85:3547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/jp.php"] [unique_id "al9Msf7v0rlcEGmVraFULwAAA4c"]
[Tue Jul 21 07:40:49.647415 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/file6.php"] [unique_id "al9Msf7v0rlcEGmVraFUMAAAA0o"]
[Tue Jul 21 07:40:49.683856 2026] [security2:error] [pid 254995:tid 255193] [client 20.104.96.117:14655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/test1.php"] [unique_id "al9Msf7v0rlcEGmVraFUMQAAA2I"]
[Tue Jul 21 07:40:49.718080 2026] [security2:error] [pid 254995:tid 255271] [client 20.220.225.223:5270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/dp.php"] [unique_id "al9Msf7v0rlcEGmVraFUMgAAA5U"]
[Tue Jul 21 07:40:49.726488 2026] [security2:error] [pid 254995:tid 255196] [client 20.226.60.151:59422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/zildan.php"] [unique_id "al9Msf7v0rlcEGmVraFUMwAAA2U"]
[Tue Jul 21 07:40:49.863579 2026] [security2:error] [pid 254995:tid 255173] [client 20.226.60.151:56272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/kq1.php"] [unique_id "al9Msf7v0rlcEGmVraFUNwAAA04"]
[Tue Jul 21 07:40:49.870695 2026] [security2:error] [pid 254995:tid 255160] [client 20.226.60.151:22918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9Msf7v0rlcEGmVraFUOAAAA0E"]
[Tue Jul 21 07:40:49.924909 2026] [security2:error] [pid 254995:tid 255275] [client 4.204.201.85:59930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/a2.php"] [unique_id "al9Msf7v0rlcEGmVraFUOwAAA5k"]
[Tue Jul 21 07:40:49.986864 2026] [security2:error] [pid 254995:tid 255132] [client 20.104.96.117:14387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/database.php"] [unique_id "al9Msf7v0rlcEGmVraFUQAAAAyU"]
[Tue Jul 21 07:40:50.200158 2026] [security2:error] [pid 254995:tid 255127] [client 4.204.201.85:61069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/file15.php"] [unique_id "al9Msv7v0rlcEGmVraFUSwAAAyA"]
[Tue Jul 21 07:40:50.296664 2026] [security2:error] [pid 254995:tid 255042] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Msv7v0rlcEGmVraFUTQADUy4"]
[Tue Jul 21 07:40:50.296786 2026] [security2:error] [pid 254995:tid 255178] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Msv7v0rlcEGmVraFUTQADUy4"]
[Tue Jul 21 07:40:50.335250 2026] [security2:error] [pid 254995:tid 255151] [client 20.151.10.161:11719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Msv7v0rlcEGmVraFUUgAAAzg"]
[Tue Jul 21 07:40:50.335276 2026] [security2:error] [pid 254995:tid 255267] [client 20.104.96.117:14609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/file.php"] [unique_id "al9Msv7v0rlcEGmVraFUUwAAA5E"]
[Tue Jul 21 07:40:50.410361 2026] [security2:error] [pid 254995:tid 255083] [remote 68.178.165.65:49048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9Msv7v0rlcEGmVraFUWAADS1c"]
[Tue Jul 21 07:40:50.475003 2026] [security2:error] [pid 254995:tid 255125] [client 4.204.201.85:57408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/f35.php"] [unique_id "al9Msv7v0rlcEGmVraFUXQAAAx4"]
[Tue Jul 21 07:40:50.577292 2026] [security2:error] [pid 254995:tid 255275] [client 4.204.201.85:7479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/f35.php"] [unique_id "al9Msv7v0rlcEGmVraFUYAAAA5k"]
[Tue Jul 21 07:40:50.659358 2026] [security2:error] [pid 254995:tid 255205] [client 20.104.96.117:13060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/file.php"] [unique_id "al9Msv7v0rlcEGmVraFUYgAAA24"]
[Tue Jul 21 07:40:50.725883 2026] [autoindex:error] [pid 254995:tid 255148] [client 20.226.60.151:22922] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:50.771599 2026] [security2:error] [pid 254995:tid 255175] [client 4.204.201.85:56530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-load.php"] [unique_id "al9Msv7v0rlcEGmVraFUZQAAA1A"]
[Tue Jul 21 07:40:50.953950 2026] [security2:error] [pid 254995:tid 255278] [client 193.36.225.66:24621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Msv7v0rlcEGmVraFUZgAAA5w"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:50.959337 2026] [security2:error] [pid 254995:tid 255224] [client 20.104.96.117:14623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/777.php"] [unique_id "al9Msv7v0rlcEGmVraFUbwAAA4A"]
[Tue Jul 21 07:40:51.018720 2026] [autoindex:error] [pid 254995:tid 255166] [client 20.226.60.151:22922] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:51.024144 2026] [security2:error] [pid 254995:tid 255140] [client 20.226.60.151:22922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Ms_7v0rlcEGmVraFUdAAAAy0"]
[Tue Jul 21 07:40:51.037043 2026] [security2:error] [pid 254995:tid 255267] [client 4.204.201.85:3544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-load.php"] [unique_id "al9Ms_7v0rlcEGmVraFUdQAAA5E"]
[Tue Jul 21 07:40:51.047637 2026] [security2:error] [pid 254995:tid 255150] [client 4.204.201.85:61104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/xwpg.php"] [unique_id "al9Ms_7v0rlcEGmVraFUdgAAAzc"]
[Tue Jul 21 07:40:51.278076 2026] [security2:error] [pid 254995:tid 255218] [client 20.226.60.151:22340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/8.php"] [unique_id "al9Ms_7v0rlcEGmVraFUfAAAA3o"]
[Tue Jul 21 07:40:51.320696 2026] [security2:error] [pid 254995:tid 255199] [client 20.104.96.117:14378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ssixta.php"] [unique_id "al9Ms_7v0rlcEGmVraFUfQAAA2g"]
[Tue Jul 21 07:40:51.337369 2026] [autoindex:error] [pid 254995:tid 255125] [client 4.204.201.85:0] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:51.415466 2026] [security2:error] [pid 254995:tid 255205] [client 4.204.201.85:46018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/xyn.php"] [unique_id "al9Ms_7v0rlcEGmVraFUhwAAA24"]
[Tue Jul 21 07:40:51.425410 2026] [security2:error] [pid 254995:tid 255182] [client 117.217.38.194:61285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUiwAAA1c"]
[Tue Jul 21 07:40:51.425524 2026] [security2:error] [pid 254995:tid 255182] [client 117.217.38.194:61285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUiwAAA1c"]
[Tue Jul 21 07:40:51.430565 2026] [core:error] [pid 254995:tid 255219] [client 137.184.93.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.portalerotes.com.br/
[Tue Jul 21 07:40:51.430579 2026] [core:error] [pid 254995:tid 255219] [client 137.184.93.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.portalerotes.com.br/
[Tue Jul 21 07:40:51.440742 2026] [security2:error] [pid 254995:tid 255192] [client 20.226.60.151:22950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Ms_7v0rlcEGmVraFUjQAAA2E"]
[Tue Jul 21 07:40:51.457239 2026] [security2:error] [pid 254995:tid 255043] [remote 130.51.180.8:53158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9Msf7v0rlcEGmVraFUKQADQC8"]
[Tue Jul 21 07:40:51.603292 2026] [security2:error] [pid 254995:tid 255198] [client 20.226.60.151:23140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/f6.php"] [unique_id "al9Ms_7v0rlcEGmVraFUlAAAA2c"]
[Tue Jul 21 07:40:51.605772 2026] [security2:error] [pid 254995:tid 255221] [client 20.220.225.223:5289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/old.php"] [unique_id "al9Ms_7v0rlcEGmVraFUlQAAA30"]
[Tue Jul 21 07:40:51.650690 2026] [security2:error] [pid 254995:tid 255150] [client 20.104.96.117:14585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/1c.php"] [unique_id "al9Ms_7v0rlcEGmVraFUmAAAAzc"]
[Tue Jul 21 07:40:51.659990 2026] [autoindex:error] [pid 254995:tid 255190] [client 4.204.201.85:59922] AH01276: Cannot serve directory /home1/ofic8899/wellnesstrade.shop/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:51.796778 2026] [security2:error] [pid 254995:tid 255136] [client 4.204.201.85:59922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/xstelth.php"] [unique_id "al9Ms_7v0rlcEGmVraFUmgAAAyk"]
[Tue Jul 21 07:40:51.810140 2026] [security2:error] [pid 254995:tid 255208] [client 103.174.34.15:51765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUmwAAA3A"]
[Tue Jul 21 07:40:51.810270 2026] [security2:error] [pid 254995:tid 255208] [client 103.174.34.15:51765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUmwAAA3A"]
[Tue Jul 21 07:40:51.817480 2026] [security2:error] [pid 254995:tid 255255] [client 20.151.10.161:11734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/2P.php"] [unique_id "al9Ms_7v0rlcEGmVraFUnAAAA4U"]
[Tue Jul 21 07:40:51.835469 2026] [security2:error] [pid 254995:tid 255131] [client 194.99.104.35:48608] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUnQAAAyQ"]
[Tue Jul 21 07:40:51.835569 2026] [security2:error] [pid 254995:tid 255131] [client 194.99.104.35:48608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUnQAAAyQ"]
[Tue Jul 21 07:40:51.866665 2026] [security2:error] [pid 254995:tid 255170] [client 20.226.60.151:22921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/inputs.php"] [unique_id "al9Ms_7v0rlcEGmVraFUnwAAA0s"]
[Tue Jul 21 07:40:51.893010 2026] [security2:error] [pid 254995:tid 255196] [client 20.220.225.223:31732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/billur.php"] [unique_id "al9Ms_7v0rlcEGmVraFUoAAAA2U"]
[Tue Jul 21 07:40:51.934283 2026] [security2:error] [pid 254995:tid 255005] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUogADmwk"]
[Tue Jul 21 07:40:51.934439 2026] [security2:error] [pid 254995:tid 255277] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUogADmwk"]
[Tue Jul 21 07:40:51.938331 2026] [security2:error] [pid 254995:tid 255154] [client 152.59.154.239:50013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUoQAAAzs"]
[Tue Jul 21 07:40:51.938575 2026] [security2:error] [pid 254995:tid 255154] [client 152.59.154.239:50013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ms_7v0rlcEGmVraFUoQAAAzs"]
[Tue Jul 21 07:40:51.975051 2026] [security2:error] [pid 254995:tid 255141] [client 20.104.96.117:14356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/test2.php"] [unique_id "al9Ms_7v0rlcEGmVraFUowAAAy4"]
[Tue Jul 21 07:40:52.020558 2026] [security2:error] [pid 254995:tid 255199] [client 20.226.60.151:56259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9MtP7v0rlcEGmVraFUpgAAA2g"]
[Tue Jul 21 07:40:52.066984 2026] [security2:error] [pid 254995:tid 255155] [client 20.226.60.151:22938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/inputs.php"] [unique_id "al9MtP7v0rlcEGmVraFUrAAAAzw"]
[Tue Jul 21 07:40:52.071844 2026] [security2:error] [pid 254995:tid 255211] [client 4.204.201.85:59959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9MtP7v0rlcEGmVraFUrQAAA3M"]
[Tue Jul 21 07:40:52.081762 2026] [security2:error] [pid 254995:tid 255161] [client 139.167.225.182:59811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFUrgAAA0I"]
[Tue Jul 21 07:40:52.081888 2026] [security2:error] [pid 254995:tid 255161] [client 139.167.225.182:59811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFUrgAAA0I"]
[Tue Jul 21 07:40:52.175165 2026] [core:alert] [pid 254995:tid 255184] [client 57.141.18.113:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:40:52.247503 2026] [security2:error] [pid 254995:tid 255279] [client 20.226.60.151:22926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/classwithtostring.php"] [unique_id "al9MtP7v0rlcEGmVraFUuAAAA50"]
[Tue Jul 21 07:40:52.261793 2026] [security2:error] [pid 254995:tid 255187] [client 122.179.91.63:13190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFUuQAAA1w"]
[Tue Jul 21 07:40:52.262108 2026] [security2:error] [pid 254995:tid 255187] [client 122.179.91.63:13190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFUuQAAA1w"]
[Tue Jul 21 07:40:52.265672 2026] [security2:error] [pid 254995:tid 255268] [client 20.104.96.117:14625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/buy.php"] [unique_id "al9MtP7v0rlcEGmVraFUugAAA5I"]
[Tue Jul 21 07:40:52.336977 2026] [security2:error] [pid 254995:tid 255216] [client 37.140.223.154:43725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Msv7v0rlcEGmVraFUSAAAA3g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:52.356401 2026] [security2:error] [pid 254995:tid 255178] [client 4.204.201.85:60413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/aaa.php"] [unique_id "al9MtP7v0rlcEGmVraFUvAAAA1M"]
[Tue Jul 21 07:40:52.383911 2026] [security2:error] [pid 254995:tid 255140] [client 20.226.60.151:22954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9MtP7v0rlcEGmVraFUvQAAAy0"]
[Tue Jul 21 07:40:52.450488 2026] [security2:error] [pid 254995:tid 255267] [client 20.226.60.151:23164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-blog.php"] [unique_id "al9MtP7v0rlcEGmVraFUvgAAA5E"]
[Tue Jul 21 07:40:52.450962 2026] [security2:error] [pid 254995:tid 255128] [client 4.204.201.85:46038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ccc.php"] [unique_id "al9MtP7v0rlcEGmVraFUvwAAAyE"]
[Tue Jul 21 07:40:52.580501 2026] [security2:error] [pid 254995:tid 255223] [client 20.104.96.117:14575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ssend.php"] [unique_id "al9MtP7v0rlcEGmVraFUyAAAA38"]
[Tue Jul 21 07:40:52.603273 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:56307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/h02ugyh.php"] [unique_id "al9MtP7v0rlcEGmVraFUzAAAAx4"]
[Tue Jul 21 07:40:52.640343 2026] [security2:error] [pid 254995:tid 255173] [client 4.204.201.85:57415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/gecko.php"] [unique_id "al9MtP7v0rlcEGmVraFUzgAAA04"]
[Tue Jul 21 07:40:52.663311 2026] [security2:error] [pid 254995:tid 255025] [remote 202.73.26.211:43686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.26.73.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Ms_7v0rlcEGmVraFUmQADhh0"]
[Tue Jul 21 07:40:52.715612 2026] [autoindex:error] [pid 254995:tid 255211] [client 20.226.60.151:23145] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:52.724634 2026] [security2:error] [pid 254995:tid 255152] [client 20.226.60.151:23145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9MtP7v0rlcEGmVraFU1AAAAzk"]
[Tue Jul 21 07:40:52.748400 2026] [security2:error] [pid 254995:tid 255214] [client 20.220.225.223:11591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/ms-new.php"] [unique_id "al9MtP7v0rlcEGmVraFU1wAAA3Y"]
[Tue Jul 21 07:40:52.832030 2026] [security2:error] [pid 254995:tid 255144] [client 20.226.60.151:62249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/miru1.php"] [unique_id "al9MtP7v0rlcEGmVraFU2AAAAzE"]
[Tue Jul 21 07:40:52.857613 2026] [security2:error] [pid 254995:tid 255200] [client 20.104.96.117:14629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/item.php"] [unique_id "al9MtP7v0rlcEGmVraFU2QAAA2k"]
[Tue Jul 21 07:40:52.880387 2026] [security2:error] [pid 254995:tid 255197] [client 59.96.220.140:52662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFU2gAAA2Y"]
[Tue Jul 21 07:40:52.880511 2026] [security2:error] [pid 254995:tid 255197] [client 59.96.220.140:52662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFU2gAAA2Y"]
[Tue Jul 21 07:40:52.894712 2026] [security2:error] [pid 254995:tid 255260] [client 4.204.201.85:46025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/w.php"] [unique_id "al9MtP7v0rlcEGmVraFU3AAAA4o"]
[Tue Jul 21 07:40:52.906203 2026] [security2:error] [pid 254995:tid 255263] [client 184.75.223.211:37630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFU3QAAA40"]
[Tue Jul 21 07:40:52.906282 2026] [security2:error] [pid 254995:tid 255263] [client 184.75.223.211:37630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9MtP7v0rlcEGmVraFU3QAAA40"]
[Tue Jul 21 07:40:52.915361 2026] [security2:error] [pid 254995:tid 255279] [client 4.204.201.85:61102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/sh3ll.php"] [unique_id "al9MtP7v0rlcEGmVraFU3gAAA50"]
[Tue Jul 21 07:40:53.179855 2026] [security2:error] [pid 254995:tid 255202] [client 20.104.96.117:14558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ss.php"] [unique_id "al9Mtf7v0rlcEGmVraFU6AAAA2s"]
[Tue Jul 21 07:40:53.205092 2026] [security2:error] [pid 254995:tid 255191] [client 4.204.201.85:57414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/pbck.php"] [unique_id "al9Mtf7v0rlcEGmVraFU6wAAA2A"]
[Tue Jul 21 07:40:53.294636 2026] [security2:error] [pid 254995:tid 255164] [client 20.226.60.151:23147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ms-edit.php"] [unique_id "al9Mtf7v0rlcEGmVraFU8AAAA0U"]
[Tue Jul 21 07:40:53.308428 2026] [access_compat:error] [pid 254995:tid 255269] [client 162.241.63.68:33316] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:40:53.328973 2026] [security2:error] [pid 254995:tid 255193] [client 20.226.60.151:56210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-temp.php"] [unique_id "al9Mtf7v0rlcEGmVraFU8wAAA2I"]
[Tue Jul 21 07:40:53.360804 2026] [security2:error] [pid 254995:tid 255225] [client 20.226.60.151:62284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/sump1.php"] [unique_id "al9Mtf7v0rlcEGmVraFU9QAAA4E"]
[Tue Jul 21 07:40:53.428167 2026] [security2:error] [pid 254995:tid 255141] [client 128.127.105.184:60548] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mtf7v0rlcEGmVraFU9gAAAy4"]
[Tue Jul 21 07:40:53.428271 2026] [security2:error] [pid 254995:tid 255141] [client 128.127.105.184:60548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Mtf7v0rlcEGmVraFU9gAAAy4"]
[Tue Jul 21 07:40:53.445011 2026] [security2:error] [pid 254995:tid 255148] [client 4.204.201.85:3554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Mtf7v0rlcEGmVraFU9wAAAzU"]
[Tue Jul 21 07:40:53.495503 2026] [security2:error] [pid 254995:tid 255155] [client 4.204.201.85:59947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/xiugai.php"] [unique_id "al9Mtf7v0rlcEGmVraFU-AAAAzw"]
[Tue Jul 21 07:40:53.538168 2026] [security2:error] [pid 254995:tid 255158] [client 20.104.96.117:14381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/hypo.php"] [unique_id "al9Mtf7v0rlcEGmVraFU_QAAAz8"]
[Tue Jul 21 07:40:53.777484 2026] [security2:error] [pid 254995:tid 255274] [client 4.204.201.85:57451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/e.php"] [unique_id "al9Mtf7v0rlcEGmVraFVBwAAA5g"]
[Tue Jul 21 07:40:53.799668 2026] [security2:error] [pid 254995:tid 255266] [client 20.151.10.161:53589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Mtf7v0rlcEGmVraFVCwAAA5A"]
[Tue Jul 21 07:40:53.827469 2026] [security2:error] [pid 254995:tid 255221] [client 20.104.96.117:14528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/users.php"] [unique_id "al9Mtf7v0rlcEGmVraFVDQAAA30"]
[Tue Jul 21 07:40:53.834796 2026] [security2:error] [pid 254995:tid 255258] [client 20.220.225.223:31704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/mimpi.php"] [unique_id "al9Mtf7v0rlcEGmVraFVDgAAA4g"]
[Tue Jul 21 07:40:53.929504 2026] [security2:error] [pid 254995:tid 255202] [client 4.204.201.85:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/FWAZ.php"] [unique_id "al9Mtf7v0rlcEGmVraFVEAAAA2s"]
[Tue Jul 21 07:40:53.949381 2026] [security2:error] [pid 254995:tid 255146] [client 20.226.60.151:22917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Mtf7v0rlcEGmVraFVEQAAAzM"]
[Tue Jul 21 07:40:54.051267 2026] [security2:error] [pid 254995:tid 255218] [client 4.204.201.85:60355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/for.php"] [unique_id "al9Mtv7v0rlcEGmVraFVGgAAA3o"]
[Tue Jul 21 07:40:54.119036 2026] [security2:error] [pid 254995:tid 255169] [client 173.24.185.52:50764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Mtv7v0rlcEGmVraFVHwAAA0o"]
[Tue Jul 21 07:40:54.119186 2026] [security2:error] [pid 254995:tid 255169] [client 173.24.185.52:50764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Mtv7v0rlcEGmVraFVHwAAA0o"]
[Tue Jul 21 07:40:54.132739 2026] [autoindex:error] [pid 254995:tid 255225] [client 198.235.24.158:59892] AH01276: Cannot serve directory /home1/guiiaz25/eduardolustosa.guiiaz.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:54.173407 2026] [security2:error] [pid 254995:tid 255215] [client 20.104.96.117:13095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/177.php"] [unique_id "al9Mtv7v0rlcEGmVraFVIQAAA3c"]
[Tue Jul 21 07:40:54.257310 2026] [security2:error] [pid 254995:tid 255158] [client 20.226.60.151:56278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9Mtv7v0rlcEGmVraFVJwAAAz8"]
[Tue Jul 21 07:40:54.328491 2026] [security2:error] [pid 254995:tid 255152] [client 4.204.201.85:61101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ssh3ll.php"] [unique_id "al9Mtv7v0rlcEGmVraFVKQAAAzk"]
[Tue Jul 21 07:40:54.349916 2026] [security2:error] [pid 254995:tid 255211] [client 4.204.201.85:46053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/miru1.php"] [unique_id "al9Mtv7v0rlcEGmVraFVKwAAA3M"]
[Tue Jul 21 07:40:54.381144 2026] [security2:error] [pid 254995:tid 255145] [client 20.226.60.151:62278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/file5.php"] [unique_id "al9Mtv7v0rlcEGmVraFVLAAAAzI"]
[Tue Jul 21 07:40:54.441034 2026] [security2:error] [pid 254995:tid 255200] [client 62.102.148.187:59502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Mtv7v0rlcEGmVraFVLQAAA2k"]
[Tue Jul 21 07:40:54.441156 2026] [security2:error] [pid 254995:tid 255200] [client 62.102.148.187:59502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Mtv7v0rlcEGmVraFVLQAAA2k"]
[Tue Jul 21 07:40:54.450693 2026] [security2:error] [pid 254995:tid 255136] [client 20.104.96.117:14631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/config.php"] [unique_id "al9Mtv7v0rlcEGmVraFVLwAAAyk"]
[Tue Jul 21 07:40:54.509450 2026] [security2:error] [pid 254995:tid 255132] [client 20.226.60.151:59461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/csa.php"] [unique_id "al9Mtv7v0rlcEGmVraFVMQAAAyU"]
[Tue Jul 21 07:40:54.604777 2026] [security2:error] [pid 254995:tid 255224] [client 4.204.201.85:57438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/adminner.php"] [unique_id "al9Mtv7v0rlcEGmVraFVNQAAA4A"]
[Tue Jul 21 07:40:54.606374 2026] [security2:error] [pid 254995:tid 255278] [client 173.239.214.235:30275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.214.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mbarcondicionados.com.br"] [uri "/wp-login.php"] [unique_id "al9Mtf7v0rlcEGmVraFVAgAAA5w"]
[Tue Jul 21 07:40:54.731872 2026] [security2:error] [pid 254995:tid 255153] [client 136.144.33.53:22547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Mtv7v0rlcEGmVraFVOQAAAzo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:54.747168 2026] [security2:error] [pid 254995:tid 255229] [client 20.104.96.117:14561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/gettest.php"] [unique_id "al9Mtv7v0rlcEGmVraFVOgAAA4I"]
[Tue Jul 21 07:40:54.796911 2026] [security2:error] [pid 254995:tid 255131] [client 4.204.201.85:3543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/aa.php"] [unique_id "al9Mtv7v0rlcEGmVraFVPAAAAyQ"]
[Tue Jul 21 07:40:54.880878 2026] [security2:error] [pid 254995:tid 255267] [client 4.204.201.85:61094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/82.php"] [unique_id "al9Mtv7v0rlcEGmVraFVPgAAA5E"]
[Tue Jul 21 07:40:54.982274 2026] [security2:error] [pid 254995:tid 255162] [client 106.215.181.8:11890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mtv7v0rlcEGmVraFVPwAAA0M"]
[Tue Jul 21 07:40:54.982389 2026] [security2:error] [pid 254995:tid 255162] [client 106.215.181.8:11890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mtv7v0rlcEGmVraFVPwAAA0M"]
[Tue Jul 21 07:40:55.026957 2026] [security2:error] [pid 254995:tid 255021] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mt_7v0rlcEGmVraFVQAADiBk"]
[Tue Jul 21 07:40:55.027158 2026] [security2:error] [pid 254995:tid 255258] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mt_7v0rlcEGmVraFVQAADiBk"]
[Tue Jul 21 07:40:55.038205 2026] [autoindex:error] [pid 254995:tid 255215] [client 20.226.60.151:22913] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:55.098141 2026] [security2:error] [pid 254995:tid 255155] [client 20.226.60.151:22913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Mt_7v0rlcEGmVraFVRAAAAzw"]
[Tue Jul 21 07:40:55.098772 2026] [security2:error] [pid 254995:tid 255148] [client 20.104.96.117:14383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/min.php"] [unique_id "al9Mt_7v0rlcEGmVraFVRQAAAzU"]
[Tue Jul 21 07:40:55.156641 2026] [security2:error] [pid 254995:tid 255261] [client 4.204.201.85:60394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/kir.php"] [unique_id "al9Mt_7v0rlcEGmVraFVSQAAA4s"]
[Tue Jul 21 07:40:55.168779 2026] [security2:error] [pid 254995:tid 255214] [client 4.204.201.85:7426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/122.php"] [unique_id "al9Mt_7v0rlcEGmVraFVTAAAA3Y"]
[Tue Jul 21 07:40:55.405102 2026] [security2:error] [pid 254995:tid 255257] [client 20.104.96.117:14636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/dvjul.php"] [unique_id "al9Mt_7v0rlcEGmVraFVVgAAA4c"]
[Tue Jul 21 07:40:55.429645 2026] [security2:error] [pid 254995:tid 255263] [client 4.204.201.85:56563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/up4.php"] [unique_id "al9Mt_7v0rlcEGmVraFVWAAAA40"]
[Tue Jul 21 07:40:55.550339 2026] [security2:error] [pid 254995:tid 255057] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mt_7v0rlcEGmVraFVWwADXj0"]
[Tue Jul 21 07:40:55.550497 2026] [security2:error] [pid 254995:tid 255189] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mt_7v0rlcEGmVraFVWwADXj0"]
[Tue Jul 21 07:40:55.555911 2026] [security2:error] [pid 254995:tid 255143] [client 20.151.10.161:12036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Mt_7v0rlcEGmVraFVXAAAAzA"]
[Tue Jul 21 07:40:55.575439 2026] [security2:error] [pid 254995:tid 255273] [client 4.204.201.85:3571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/get.php"] [unique_id "al9Mt_7v0rlcEGmVraFVXQAAA5c"]
[Tue Jul 21 07:40:55.654525 2026] [autoindex:error] [pid 254995:tid 255179] [client 20.226.60.151:23106] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:55.701349 2026] [security2:error] [pid 254995:tid 255140] [client 20.104.96.117:13088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/biufile.php"] [unique_id "al9Mt_7v0rlcEGmVraFVYgAAAy0"]
[Tue Jul 21 07:40:55.706636 2026] [security2:error] [pid 254995:tid 255276] [client 4.204.201.85:59952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/xhar.php"] [unique_id "al9Mt_7v0rlcEGmVraFVZQAAA5o"]
[Tue Jul 21 07:40:55.719240 2026] [autoindex:error] [pid 254995:tid 255221] [client 20.226.60.151:23106] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:55.723791 2026] [security2:error] [pid 254995:tid 255168] [client 20.226.60.151:33480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/0xD.php"] [unique_id "al9Mt_7v0rlcEGmVraFVaQAAA0k"]
[Tue Jul 21 07:40:55.910209 2026] [security2:error] [pid 254995:tid 255192] [client 20.226.60.151:23106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/abcd.php"] [unique_id "al9Mt_7v0rlcEGmVraFVcgAAA2E"]
[Tue Jul 21 07:40:55.978218 2026] [security2:error] [pid 254995:tid 255211] [client 20.104.96.117:14550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/av.php"] [unique_id "al9Mt_7v0rlcEGmVraFVdAAAA3M"]
[Tue Jul 21 07:40:55.980228 2026] [security2:error] [pid 254995:tid 255144] [client 4.204.201.85:56455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/file1221.php"] [unique_id "al9Mt_7v0rlcEGmVraFVdQAAAzE"]
[Tue Jul 21 07:40:56.101338 2026] [security2:error] [pid 254995:tid 255159] [client 20.151.10.161:55261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/bob.php"] [unique_id "al9MuP7v0rlcEGmVraFVegAAA0A"]
[Tue Jul 21 07:40:56.239978 2026] [security2:error] [pid 254995:tid 255268] [client 4.204.201.85:45977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/as.php"] [unique_id "al9MuP7v0rlcEGmVraFVfQAAA5I"]
[Tue Jul 21 07:40:56.256151 2026] [security2:error] [pid 254995:tid 255149] [client 4.204.201.85:56473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/inx.php"] [unique_id "al9MuP7v0rlcEGmVraFVgAAAAzY"]
[Tue Jul 21 07:40:56.269219 2026] [security2:error] [pid 254995:tid 255279] [client 20.104.96.117:14353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/coffexium.php"] [unique_id "al9MuP7v0rlcEGmVraFVggAAA50"]
[Tue Jul 21 07:40:56.312355 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:62234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/fnstall.php"] [unique_id "al9MuP7v0rlcEGmVraFVgwAAA5k"]
[Tue Jul 21 07:40:56.533604 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:57468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/qqqa.php"] [unique_id "al9MuP7v0rlcEGmVraFVkgAAA0o"]
[Tue Jul 21 07:40:56.556841 2026] [security2:error] [pid 254995:tid 255077] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVlAADnFE"]
[Tue Jul 21 07:40:56.557018 2026] [security2:error] [pid 254995:tid 255278] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVlAADnFE"]
[Tue Jul 21 07:40:56.567800 2026] [security2:error] [pid 254995:tid 255141] [client 117.251.86.144:38242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVlgAAAy4"]
[Tue Jul 21 07:40:56.567928 2026] [security2:error] [pid 254995:tid 255141] [client 117.251.86.144:38242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVlgAAAy4"]
[Tue Jul 21 07:40:56.592856 2026] [security2:error] [pid 254995:tid 255199] [client 20.104.96.117:14352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/core.php"] [unique_id "al9MuP7v0rlcEGmVraFVmAAAA2g"]
[Tue Jul 21 07:40:56.608291 2026] [security2:error] [pid 254995:tid 255208] [client 20.226.60.151:59480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/w3llscc.php"] [unique_id "al9MuP7v0rlcEGmVraFVmQAAA3A"]
[Tue Jul 21 07:40:56.653844 2026] [security2:error] [pid 254995:tid 255220] [client 20.220.225.223:5278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/track.php"] [unique_id "al9MuP7v0rlcEGmVraFVmgAAA3w"]
[Tue Jul 21 07:40:56.684473 2026] [security2:error] [pid 254995:tid 255269] [client 4.204.201.85:46045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ccou.php"] [unique_id "al9MuP7v0rlcEGmVraFVmwAAA5M"]
[Tue Jul 21 07:40:56.808740 2026] [security2:error] [pid 254995:tid 255214] [client 4.204.201.85:56458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/ffffile.php"] [unique_id "al9MuP7v0rlcEGmVraFVoQAAA3Y"]
[Tue Jul 21 07:40:56.876947 2026] [security2:error] [pid 254995:tid 255175] [client 122.186.204.214:51212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVpgAAA1A"]
[Tue Jul 21 07:40:56.877069 2026] [security2:error] [pid 254995:tid 255175] [client 122.186.204.214:51212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVpgAAA1A"]
[Tue Jul 21 07:40:56.908168 2026] [security2:error] [pid 254995:tid 255256] [client 20.104.96.117:14587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/als.php"] [unique_id "al9MuP7v0rlcEGmVraFVpwAAA4Y"]
[Tue Jul 21 07:40:56.950567 2026] [security2:error] [pid 254995:tid 255223] [client 62.102.148.187:59510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVqwAAA38"]
[Tue Jul 21 07:40:56.950731 2026] [security2:error] [pid 254995:tid 255223] [client 62.102.148.187:59510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9MuP7v0rlcEGmVraFVqwAAA38"]
[Tue Jul 21 07:40:56.976893 2026] [security2:error] [pid 254995:tid 255145] [client 20.226.60.151:22943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/file15.php"] [unique_id "al9MuP7v0rlcEGmVraFVrAAAAzI"]
[Tue Jul 21 07:40:57.085092 2026] [security2:error] [pid 254995:tid 255268] [client 4.204.201.85:56535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/wp-firewall.php"] [unique_id "al9Muf7v0rlcEGmVraFVrgAAA5I"]
[Tue Jul 21 07:40:57.175951 2026] [security2:error] [pid 254995:tid 255136] [client 20.226.60.151:62333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/acp.php"] [unique_id "al9Muf7v0rlcEGmVraFVtAAAAyk"]
[Tue Jul 21 07:40:57.185470 2026] [security2:error] [pid 254995:tid 255275] [client 20.104.96.117:13072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/simple.php"] [unique_id "al9Muf7v0rlcEGmVraFVtQAAA5k"]
[Tue Jul 21 07:40:57.256756 2026] [security2:error] [pid 254995:tid 255178] [client 20.220.225.223:11193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/2352356666.php"] [unique_id "al9Muf7v0rlcEGmVraFVtwAAA1M"]
[Tue Jul 21 07:40:57.360361 2026] [security2:error] [pid 254995:tid 255177] [client 4.204.201.85:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wellnesstrade.shop"] [uri "/reviall.php"] [unique_id "al9Muf7v0rlcEGmVraFVvgAAA1I"]
[Tue Jul 21 07:40:57.461986 2026] [security2:error] [pid 254995:tid 255184] [client 20.151.10.161:55268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/crgio.php"] [unique_id "al9Muf7v0rlcEGmVraFVwgAAA1k"]
[Tue Jul 21 07:40:57.508354 2026] [security2:error] [pid 254995:tid 255155] [client 20.226.60.151:62328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/mosty.php"] [unique_id "al9Muf7v0rlcEGmVraFVwwAAAzw"]
[Tue Jul 21 07:40:57.521448 2026] [security2:error] [pid 254995:tid 255161] [client 20.104.96.117:14596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/init.php"] [unique_id "al9Muf7v0rlcEGmVraFVxAAAA0I"]
[Tue Jul 21 07:40:57.551175 2026] [security2:error] [pid 254995:tid 255170] [client 20.226.60.151:23105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/jp.php"] [unique_id "al9Muf7v0rlcEGmVraFVxQAAA0s"]
[Tue Jul 21 07:40:57.801636 2026] [security2:error] [pid 254995:tid 255267] [client 37.140.223.152:43671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MuP7v0rlcEGmVraFVjAAAA5E"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:40:57.807828 2026] [security2:error] [pid 254995:tid 255197] [client 20.104.96.117:14573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/fpwch.php"] [unique_id "al9Muf7v0rlcEGmVraFVyQAAA2Y"]
[Tue Jul 21 07:40:57.889250 2026] [security2:error] [pid 254995:tid 255192] [client 4.204.201.85:7446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/w3lls.php"] [unique_id "al9Muf7v0rlcEGmVraFVzgAAA2E"]
[Tue Jul 21 07:40:58.005840 2026] [security2:error] [pid 254995:tid 255219] [client 20.151.10.161:12060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/pucci.php"] [unique_id "al9Muv7v0rlcEGmVraFV0wAAA3s"]
[Tue Jul 21 07:40:58.089769 2026] [security2:error] [pid 254995:tid 255216] [client 20.104.96.117:14632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/domvf.php"] [unique_id "al9Muv7v0rlcEGmVraFV1QAAA3g"]
[Tue Jul 21 07:40:58.162288 2026] [security2:error] [pid 254995:tid 255150] [client 20.226.60.151:23121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/f35.php"] [unique_id "al9Muv7v0rlcEGmVraFV1gAAAzc"]
[Tue Jul 21 07:40:58.168987 2026] [security2:error] [pid 254995:tid 255218] [client 122.164.127.47:49562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV1wAAA3o"]
[Tue Jul 21 07:40:58.169113 2026] [security2:error] [pid 254995:tid 255218] [client 122.164.127.47:49562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV1wAAA3o"]
[Tue Jul 21 07:40:58.192254 2026] [security2:error] [pid 254995:tid 255154] [client 20.220.225.223:19302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wicked.php"] [unique_id "al9Muv7v0rlcEGmVraFV2gAAAzs"]
[Tue Jul 21 07:40:58.308898 2026] [security2:error] [pid 254995:tid 255255] [client 20.226.60.151:62283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/6.php"] [unique_id "al9Muv7v0rlcEGmVraFV3AAAA4U"]
[Tue Jul 21 07:40:58.389890 2026] [security2:error] [pid 254995:tid 255184] [client 20.226.60.151:22955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-load.php"] [unique_id "al9Muv7v0rlcEGmVraFV4QAAA1k"]
[Tue Jul 21 07:40:58.503588 2026] [security2:error] [pid 254995:tid 255144] [client 20.226.60.151:22915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/xyn.php"] [unique_id "al9Muv7v0rlcEGmVraFV5wAAAzE"]
[Tue Jul 21 07:40:58.550979 2026] [security2:error] [pid 254995:tid 255176] [client 20.104.96.117:14627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp.php"] [unique_id "al9Muv7v0rlcEGmVraFV6AAAA1E"]
[Tue Jul 21 07:40:58.609065 2026] [security2:error] [pid 254995:tid 255213] [client 154.192.233.199:59829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV6QAAA3U"]
[Tue Jul 21 07:40:58.609195 2026] [security2:error] [pid 254995:tid 255213] [client 154.192.233.199:59829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV6QAAA3U"]
[Tue Jul 21 07:40:58.619434 2026] [security2:error] [pid 254995:tid 254997] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV6wADcwE"]
[Tue Jul 21 07:40:58.619576 2026] [security2:error] [pid 254995:tid 255211] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV6wADcwE"]
[Tue Jul 21 07:40:58.673763 2026] [security2:error] [pid 254995:tid 255037] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV7AADgSk"]
[Tue Jul 21 07:40:58.673921 2026] [security2:error] [pid 254995:tid 255225] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV7AADgSk"]
[Tue Jul 21 07:40:58.716861 2026] [autoindex:error] [pid 254995:tid 255222] [client 20.226.60.151:22961] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:58.774176 2026] [security2:error] [pid 254995:tid 255192] [client 20.226.60.151:56280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9Muv7v0rlcEGmVraFV7wAAA2E"]
[Tue Jul 21 07:40:58.805967 2026] [autoindex:error] [pid 254995:tid 255193] [client 20.226.60.151:22961] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:40:58.811056 2026] [security2:error] [pid 254995:tid 255156] [client 20.226.60.151:22961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ccc.php"] [unique_id "al9Muv7v0rlcEGmVraFV9AAAAz0"]
[Tue Jul 21 07:40:58.868511 2026] [security2:error] [pid 254995:tid 255263] [client 20.104.96.117:14392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/class.php"] [unique_id "al9Muv7v0rlcEGmVraFV9wAAA40"]
[Tue Jul 21 07:40:58.876594 2026] [security2:error] [pid 254995:tid 255202] [client 182.8.255.181:17691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV-AAAA2s"]
[Tue Jul 21 07:40:58.876716 2026] [security2:error] [pid 254995:tid 255202] [client 182.8.255.181:17691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Muv7v0rlcEGmVraFV-AAAA2s"]
[Tue Jul 21 07:40:59.098346 2026] [security2:error] [pid 254995:tid 255278] [client 20.226.60.151:59418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wpx.php"] [unique_id "al9Mu_7v0rlcEGmVraFWBAAAA5w"]
[Tue Jul 21 07:40:59.102210 2026] [security2:error] [pid 254995:tid 255258] [client 103.86.117.203:64603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWBQAAA4g"]
[Tue Jul 21 07:40:59.102360 2026] [security2:error] [pid 254995:tid 255258] [client 103.86.117.203:64603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWBQAAA4g"]
[Tue Jul 21 07:40:59.214342 2026] [security2:error] [pid 254995:tid 255220] [client 20.104.96.117:14571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/echkm.php"] [unique_id "al9Mu_7v0rlcEGmVraFWBgAAA3w"]
[Tue Jul 21 07:40:59.336621 2026] [security2:error] [pid 254995:tid 255179] [client 20.226.60.151:33485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9Mu_7v0rlcEGmVraFWCgAAA1Q"]
[Tue Jul 21 07:40:59.437607 2026] [proxy:error] [pid 254995:tid 255158] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:59.437674 2026] [proxy_http:error] [pid 254995:tid 255158] [client 84.37.204.163:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:59.438298 2026] [proxy:error] [pid 254995:tid 255158] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:40:59.438331 2026] [proxy_http:error] [pid 254995:tid 255158] [client 84.37.204.163:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:40:59.504909 2026] [security2:error] [pid 254995:tid 255159] [client 20.104.96.117:14532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/lib.php"] [unique_id "al9Mu_7v0rlcEGmVraFWGAAAA0A"]
[Tue Jul 21 07:40:59.505319 2026] [security2:error] [pid 254995:tid 255195] [client 175.45.70.82:56344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWGQAAA2Q"]
[Tue Jul 21 07:40:59.505473 2026] [security2:error] [pid 254995:tid 255195] [client 175.45.70.82:56344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWGQAAA2Q"]
[Tue Jul 21 07:40:59.536839 2026] [security2:error] [pid 254995:tid 255279] [client 202.143.127.214:63435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWGgAAA50"]
[Tue Jul 21 07:40:59.536976 2026] [security2:error] [pid 254995:tid 255279] [client 202.143.127.214:63435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWGgAAA50"]
[Tue Jul 21 07:40:59.568719 2026] [security2:error] [pid 254995:tid 255145] [client 4.204.201.85:7430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/test1.php"] [unique_id "al9Mu_7v0rlcEGmVraFWHQAAAzI"]
[Tue Jul 21 07:40:59.750634 2026] [security2:error] [pid 254995:tid 255260] [client 136.144.33.215:21831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Mu_7v0rlcEGmVraFWHgAAA4o"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:40:59.859362 2026] [security2:error] [pid 254995:tid 255182] [client 20.104.96.117:14547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/login.php"] [unique_id "al9Mu_7v0rlcEGmVraFWHwAAA1c"]
[Tue Jul 21 07:40:59.930516 2026] [security2:error] [pid 254995:tid 255216] [client 20.226.60.151:23127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/w.php"] [unique_id "al9Mu_7v0rlcEGmVraFWIAAAA3g"]
[Tue Jul 21 07:40:59.971853 2026] [security2:error] [pid 254995:tid 255205] [client 103.106.20.201:63446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWIgAAA24"]
[Tue Jul 21 07:40:59.971961 2026] [security2:error] [pid 254995:tid 255205] [client 103.106.20.201:63446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mu_7v0rlcEGmVraFWIgAAA24"]
[Tue Jul 21 07:41:00.016563 2026] [security2:error] [pid 254995:tid 255276] [client 122.162.144.145:31789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MvP7v0rlcEGmVraFWKQAAA5o"]
[Tue Jul 21 07:41:00.016646 2026] [security2:error] [pid 254995:tid 255276] [client 122.162.144.145:31789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9MvP7v0rlcEGmVraFWKQAAA5o"]
[Tue Jul 21 07:41:00.157364 2026] [security2:error] [pid 254995:tid 255208] [client 20.104.96.117:14570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/a2.php"] [unique_id "al9MvP7v0rlcEGmVraFWLQAAA3A"]
[Tue Jul 21 07:41:00.451881 2026] [security2:error] [pid 254995:tid 255140] [client 20.104.96.117:14598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/d61.php"] [unique_id "al9MvP7v0rlcEGmVraFWMQAAAy0"]
[Tue Jul 21 07:41:00.669607 2026] [security2:error] [pid 254995:tid 255159] [client 20.151.10.161:53623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-temp.php"] [unique_id "al9MvP7v0rlcEGmVraFWOgAAA0A"]
[Tue Jul 21 07:41:00.758908 2026] [security2:error] [pid 254995:tid 255279] [client 20.104.96.117:14635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/info.php"] [unique_id "al9MvP7v0rlcEGmVraFWPAAAA50"]
[Tue Jul 21 07:41:00.766884 2026] [security2:error] [pid 254995:tid 255097] [remote 216.73.160.190:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-login.php"] [unique_id "al9MvP7v0rlcEGmVraFWPQADfmU"]
[Tue Jul 21 07:41:00.912905 2026] [security2:error] [pid 254995:tid 255260] [client 20.226.60.151:62212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/qqqa.php"] [unique_id "al9MvP7v0rlcEGmVraFWQgAAA4o"]
[Tue Jul 21 07:41:00.918138 2026] [autoindex:error] [pid 254995:tid 255189] [client 172.252.180.7:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:41:01.096530 2026] [security2:error] [pid 254995:tid 255157] [client 20.226.60.151:59395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-css.php"] [unique_id "al9Mvf7v0rlcEGmVraFWSgAAAz4"]
[Tue Jul 21 07:41:01.097050 2026] [security2:error] [pid 254995:tid 255154] [client 20.104.96.117:14607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/11.php"] [unique_id "al9Mvf7v0rlcEGmVraFWSwAAAzs"]
[Tue Jul 21 07:41:01.251963 2026] [security2:error] [pid 254995:tid 255196] [client 59.96.220.140:53180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Mvf7v0rlcEGmVraFWTgAAA2U"]
[Tue Jul 21 07:41:01.255211 2026] [security2:error] [pid 254995:tid 255196] [client 59.96.220.140:53180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Mvf7v0rlcEGmVraFWTgAAA2U"]
[Tue Jul 21 07:41:01.288711 2026] [security2:error] [pid 254995:tid 255278] [client 51.68.107.159:30823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "avermetais.com.br"] [uri "/robots.txt"] [unique_id "al9Mvf7v0rlcEGmVraFWUAAAA5w"]
[Tue Jul 21 07:41:01.288920 2026] [security2:error] [pid 254995:tid 255278] [client 51.68.107.159:30823] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "avermetais.com.br"] [uri "/robots.txt"] [unique_id "al9Mvf7v0rlcEGmVraFWUAAAA5w"]
[Tue Jul 21 07:41:01.397969 2026] [security2:error] [pid 254995:tid 255179] [client 20.104.96.117:14569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/v2.php"] [unique_id "al9Mvf7v0rlcEGmVraFWVgAAA1Q"]
[Tue Jul 21 07:41:01.413153 2026] [security2:error] [pid 254995:tid 255197] [client 20.220.225.223:5301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/pn.php"] [unique_id "al9Mvf7v0rlcEGmVraFWVwAAA2Y"]
[Tue Jul 21 07:41:01.427342 2026] [security2:error] [pid 254995:tid 255170] [client 4.204.201.85:7487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/database.php"] [unique_id "al9Mvf7v0rlcEGmVraFWWAAAA0s"]
[Tue Jul 21 07:41:01.435885 2026] [security2:error] [pid 254995:tid 255014] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvf7v0rlcEGmVraFWWQADJBI"]
[Tue Jul 21 07:41:01.436077 2026] [security2:error] [pid 254995:tid 255131] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvf7v0rlcEGmVraFWWQADJBI"]
[Tue Jul 21 07:41:01.515103 2026] [security2:error] [pid 254995:tid 255275] [client 37.140.223.191:46697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mvf7v0rlcEGmVraFWVQAAA5k"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:01.585626 2026] [security2:error] [pid 254995:tid 255191] [client 20.226.60.151:56197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/jj.php"] [unique_id "al9Mvf7v0rlcEGmVraFWYQAAA2A"]
[Tue Jul 21 07:41:01.670243 2026] [security2:error] [pid 254995:tid 255184] [client 20.226.60.151:23123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Mvf7v0rlcEGmVraFWZAAAA1k"]
[Tue Jul 21 07:41:01.689410 2026] [security2:error] [pid 254995:tid 255185] [client 20.104.96.117:14542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/panel.php"] [unique_id "al9Mvf7v0rlcEGmVraFWZQAAA1o"]
[Tue Jul 21 07:41:01.749354 2026] [security2:error] [pid 254995:tid 255192] [client 20.197.195.24:13573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/classwithtostring.php"] [unique_id "al9Mvf7v0rlcEGmVraFWaAAAA2E"]
[Tue Jul 21 07:41:01.811921 2026] [security2:error] [pid 254995:tid 255187] [client 20.220.225.223:34256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/edit.php"] [unique_id "al9Mvf7v0rlcEGmVraFWagAAA1w"]
[Tue Jul 21 07:41:01.882966 2026] [security2:error] [pid 254995:tid 255166] [client 117.217.38.194:61766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvf7v0rlcEGmVraFWbQAAA0c"]
[Tue Jul 21 07:41:01.883150 2026] [security2:error] [pid 254995:tid 255166] [client 117.217.38.194:61766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvf7v0rlcEGmVraFWbQAAA0c"]
[Tue Jul 21 07:41:01.889054 2026] [security2:error] [pid 254995:tid 255216] [client 20.151.10.161:53573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9Mvf7v0rlcEGmVraFWbgAAA3g"]
[Tue Jul 21 07:41:01.990476 2026] [security2:error] [pid 254995:tid 255224] [client 20.104.96.117:14399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/dex.php"] [unique_id "al9Mvf7v0rlcEGmVraFWcQAAA4A"]
[Tue Jul 21 07:41:02.341020 2026] [security2:error] [pid 254995:tid 255225] [client 20.104.96.117:13078] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/1.php"] [unique_id "al9Mvv7v0rlcEGmVraFWgwAAA4E"]
[Tue Jul 21 07:41:02.341123 2026] [security2:error] [pid 254995:tid 255225] [client 20.104.96.117:13078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/1.php"] [unique_id "al9Mvv7v0rlcEGmVraFWgwAAA4E"]
[Tue Jul 21 07:41:02.521672 2026] [security2:error] [pid 254995:tid 255129] [client 4.204.201.85:7427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/file.php"] [unique_id "al9Mvv7v0rlcEGmVraFWhQAAAyI"]
[Tue Jul 21 07:41:02.592663 2026] [security2:error] [pid 254995:tid 255190] [client 103.174.34.15:52244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWjAAAA18"]
[Tue Jul 21 07:41:02.593124 2026] [security2:error] [pid 254995:tid 255190] [client 103.174.34.15:52244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWjAAAA18"]
[Tue Jul 21 07:41:02.596933 2026] [security2:error] [pid 254995:tid 255040] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWjQADPyw"]
[Tue Jul 21 07:41:02.597098 2026] [security2:error] [pid 254995:tid 255158] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWjQADPyw"]
[Tue Jul 21 07:41:02.656646 2026] [security2:error] [pid 254995:tid 255182] [client 139.167.225.182:60464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWkgAAA1c"]
[Tue Jul 21 07:41:02.656784 2026] [security2:error] [pid 254995:tid 255182] [client 139.167.225.182:60464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWkgAAA1c"]
[Tue Jul 21 07:41:02.699456 2026] [security2:error] [pid 254995:tid 255154] [client 20.104.96.117:14654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/ms.php"] [unique_id "al9Mvv7v0rlcEGmVraFWlgAAAzs"]
[Tue Jul 21 07:41:02.705018 2026] [security2:error] [pid 254995:tid 255157] [client 20.226.60.151:62322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/aunmc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWmAAAAz4"]
[Tue Jul 21 07:41:02.838456 2026] [security2:error] [pid 254995:tid 255278] [client 122.179.91.63:10547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWoAAAA5w"]
[Tue Jul 21 07:41:02.838559 2026] [security2:error] [pid 254995:tid 255278] [client 122.179.91.63:10547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Mvv7v0rlcEGmVraFWoAAAA5w"]
[Tue Jul 21 07:41:02.997079 2026] [proxy:error] [pid 254995:tid 255275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:02.997155 2026] [proxy_http:error] [pid 254995:tid 255275] [client 20.104.96.117:14529] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:02.997768 2026] [proxy:error] [pid 254995:tid 255275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:02.997795 2026] [proxy_http:error] [pid 254995:tid 255275] [client 20.104.96.117:14529] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:03.195336 2026] [security2:error] [pid 254995:tid 255164] [client 152.59.154.239:64170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mv_7v0rlcEGmVraFWqwAAA0U"]
[Tue Jul 21 07:41:03.195452 2026] [security2:error] [pid 254995:tid 255164] [client 152.59.154.239:64170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mv_7v0rlcEGmVraFWqwAAA0U"]
[Tue Jul 21 07:41:03.267140 2026] [security2:error] [pid 254995:tid 255222] [client 20.226.60.151:62209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/uoocf.php"] [unique_id "al9Mv_7v0rlcEGmVraFWsAAAA34"]
[Tue Jul 21 07:41:03.366036 2026] [security2:error] [pid 254995:tid 255208] [client 20.104.96.117:13068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/memberfuns.php"] [unique_id "al9Mv_7v0rlcEGmVraFWtQAAA3A"]
[Tue Jul 21 07:41:03.443583 2026] [security2:error] [pid 254995:tid 255156] [client 4.204.201.85:3525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/file.php"] [unique_id "al9Mv_7v0rlcEGmVraFWtwAAAz0"]
[Tue Jul 21 07:41:03.528364 2026] [security2:error] [pid 254995:tid 255193] [client 20.220.225.223:19324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/edit.php"] [unique_id "al9Mv_7v0rlcEGmVraFWuAAAA2I"]
[Tue Jul 21 07:41:03.597245 2026] [security2:error] [pid 254995:tid 255190] [client 20.226.60.151:23157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/FWAZ.php"] [unique_id "al9Mv_7v0rlcEGmVraFWugAAA18"]
[Tue Jul 21 07:41:03.643563 2026] [security2:error] [pid 254995:tid 255256] [client 20.226.60.151:59414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ho.php"] [unique_id "al9Mv_7v0rlcEGmVraFWvgAAA4Y"]
[Tue Jul 21 07:41:03.681381 2026] [security2:error] [pid 254995:tid 255178] [client 20.104.96.117:14645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/0.php"] [unique_id "al9Mv_7v0rlcEGmVraFWvwAAA1M"]
[Tue Jul 21 07:41:03.738005 2026] [security2:error] [pid 254995:tid 255004] [remote 193.36.225.189:41107] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9Mv_7v0rlcEGmVraFWwQADeAg"], referer: http://tabelionatopraiadebelas.com.br/
[Tue Jul 21 07:41:03.895911 2026] [security2:error] [pid 254995:tid 255275] [client 20.151.10.161:53629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/puc.php"] [unique_id "al9Mv_7v0rlcEGmVraFWygAAA5k"]
[Tue Jul 21 07:41:04.015843 2026] [security2:error] [pid 254995:tid 255192] [client 172.245.102.30:53203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mv_7v0rlcEGmVraFWxgAAA2E"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:04.031921 2026] [security2:error] [pid 254995:tid 255214] [client 20.104.96.117:14376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/BDKR28.php"] [unique_id "al9MwP7v0rlcEGmVraFWzAAAA3Y"]
[Tue Jul 21 07:41:04.246859 2026] [security2:error] [pid 254995:tid 255023] [remote 193.36.225.189:41107] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/wp-includes/css/buttons.css"] [unique_id "al9MwP7v0rlcEGmVraFW0wADThs"], referer: http://tabelionatopraiadebelas.com.br/wp-includes/css/buttons.css
[Tue Jul 21 07:41:04.324614 2026] [security2:error] [pid 254995:tid 255229] [client 20.104.96.117:13083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/green1.php"] [unique_id "al9MwP7v0rlcEGmVraFW2gAAA4I"]
[Tue Jul 21 07:41:04.470681 2026] [proxy:error] [pid 254995:tid 255274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:04.470749 2026] [proxy_http:error] [pid 254995:tid 255274] [client 23.230.121.85:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:04.471379 2026] [proxy:error] [pid 254995:tid 255274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:04.471407 2026] [proxy_http:error] [pid 254995:tid 255274] [client 23.230.121.85:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:04.578040 2026] [security2:error] [pid 254995:tid 255187] [client 20.226.60.151:33476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/iywwi.php"] [unique_id "al9MwP7v0rlcEGmVraFW4wAAA1w"]
[Tue Jul 21 07:41:04.609093 2026] [security2:error] [pid 254995:tid 255200] [client 20.226.60.151:22970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/miru1.php"] [unique_id "al9MwP7v0rlcEGmVraFW5AAAA2k"]
[Tue Jul 21 07:41:04.626475 2026] [security2:error] [pid 254995:tid 255199] [client 20.104.96.117:13087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/nc4.php"] [unique_id "al9MwP7v0rlcEGmVraFW5gAAA2g"]
[Tue Jul 21 07:41:04.696412 2026] [security2:error] [pid 254995:tid 255175] [client 128.127.105.184:53030] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9MwP7v0rlcEGmVraFW8AAAA1A"]
[Tue Jul 21 07:41:04.696502 2026] [security2:error] [pid 254995:tid 255175] [client 128.127.105.184:53030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9MwP7v0rlcEGmVraFW8AAAA1A"]
[Tue Jul 21 07:41:04.743897 2026] [security2:error] [pid 254995:tid 255174] [client 173.24.185.52:51240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MwP7v0rlcEGmVraFXBwAAA08"]
[Tue Jul 21 07:41:04.748404 2026] [security2:error] [pid 254995:tid 255174] [client 173.24.185.52:51240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9MwP7v0rlcEGmVraFXBwAAA08"]
[Tue Jul 21 07:41:04.787443 2026] [security2:error] [pid 255769:tid 255797] [remote 74.7.228.9:54626] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arielson.com.br"] [uri "/index.php"] [unique_id "al9MobxMYwyVGnfuwsKwcgAD0hs"]
[Tue Jul 21 07:41:04.847920 2026] [security2:error] [pid 254995:tid 255189] [client 4.204.201.85:46029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/777.php"] [unique_id "al9MwP7v0rlcEGmVraFXDgAAA14"]
[Tue Jul 21 07:41:04.943071 2026] [security2:error] [pid 254995:tid 255263] [client 20.226.60.151:56215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9MwP7v0rlcEGmVraFXEAAAA40"]
[Tue Jul 21 07:41:04.954076 2026] [security2:error] [pid 254995:tid 255026] [remote 193.36.225.189:41107] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/media/system/js/core.js"] [unique_id "al9MwP7v0rlcEGmVraFXEQADlB4"], referer: http://tabelionatopraiadebelas.com.br/media/system/js/core.js
[Tue Jul 21 07:41:04.974366 2026] [security2:error] [pid 254995:tid 255184] [client 20.104.96.117:14577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/a1.php"] [unique_id "al9MwP7v0rlcEGmVraFXEgAAA1k"]
[Tue Jul 21 07:41:05.427103 2026] [security2:error] [pid 254995:tid 255269] [client 20.104.96.117:14642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/eee.php"] [unique_id "al9Mwf7v0rlcEGmVraFXHwAAA5M"]
[Tue Jul 21 07:41:05.639560 2026] [security2:error] [pid 254995:tid 255168] [client 106.215.181.8:24340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mwf7v0rlcEGmVraFXJgAAA0k"]
[Tue Jul 21 07:41:05.639701 2026] [security2:error] [pid 254995:tid 255168] [client 106.215.181.8:24340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mwf7v0rlcEGmVraFXJgAAA0k"]
[Tue Jul 21 07:41:05.694028 2026] [security2:error] [pid 254995:tid 255131] [client 20.151.10.161:12050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/themes.php"] [unique_id "al9Mwf7v0rlcEGmVraFXJwAAAyQ"]
[Tue Jul 21 07:41:05.744498 2026] [security2:error] [pid 254995:tid 255200] [client 20.104.96.117:13109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/wp-aothait.php"] [unique_id "al9Mwf7v0rlcEGmVraFXLgAAA2k"]
[Tue Jul 21 07:41:05.816852 2026] [security2:error] [pid 254995:tid 255213] [client 136.144.33.107:44507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9MwP7v0rlcEGmVraFW5wAAA3U"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:05.913858 2026] [security2:error] [pid 254995:tid 255110] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mwf7v0rlcEGmVraFXNwADLXI"]
[Tue Jul 21 07:41:05.914074 2026] [security2:error] [pid 254995:tid 255140] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mwf7v0rlcEGmVraFXNwADLXI"]
[Tue Jul 21 07:41:06.047787 2026] [security2:error] [pid 254995:tid 255272] [client 20.226.60.151:62233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/gqgsa.php"] [unique_id "al9Mwv7v0rlcEGmVraFXOgAAA5Y"]
[Tue Jul 21 07:41:06.061537 2026] [security2:error] [pid 254995:tid 255033] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mwv7v0rlcEGmVraFXOwADLiU"]
[Tue Jul 21 07:41:06.061722 2026] [security2:error] [pid 254995:tid 255141] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mwv7v0rlcEGmVraFXOwADLiU"]
[Tue Jul 21 07:41:06.123556 2026] [security2:error] [pid 254995:tid 255225] [client 20.104.96.117:14560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/config.json.php"] [unique_id "al9Mwv7v0rlcEGmVraFXPAAAA4E"]
[Tue Jul 21 07:41:06.696060 2026] [security2:error] [pid 254995:tid 255168] [client 20.104.96.117:14578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9Mwv7v0rlcEGmVraFXSwAAA0k"]
[Tue Jul 21 07:41:06.722726 2026] [security2:error] [pid 254995:tid 255265] [client 20.226.60.151:62305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/elbzl.php"] [unique_id "al9Mwv7v0rlcEGmVraFXTAAAA48"]
[Tue Jul 21 07:41:06.962328 2026] [security2:error] [pid 254995:tid 255278] [client 20.151.10.161:53614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/dx.php"] [unique_id "al9Mwv7v0rlcEGmVraFXVgAAA5w"]
[Tue Jul 21 07:41:07.074008 2026] [security2:error] [pid 254995:tid 255202] [client 20.226.60.151:62227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/adjig.php"] [unique_id "al9Mw_7v0rlcEGmVraFXWAAAA2s"]
[Tue Jul 21 07:41:07.190505 2026] [security2:error] [pid 254995:tid 255164] [client 20.104.96.117:13117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/k2.php"] [unique_id "al9Mw_7v0rlcEGmVraFXXQAAA0U"]
[Tue Jul 21 07:41:07.262095 2026] [security2:error] [pid 254995:tid 255269] [client 117.251.86.144:38446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mw_7v0rlcEGmVraFXXgAAA5M"]
[Tue Jul 21 07:41:07.262217 2026] [security2:error] [pid 254995:tid 255269] [client 117.251.86.144:38446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mw_7v0rlcEGmVraFXXgAAA5M"]
[Tue Jul 21 07:41:07.300920 2026] [security2:error] [pid 254995:tid 255034] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mw_7v0rlcEGmVraFXXwADTyY"]
[Tue Jul 21 07:41:07.301061 2026] [security2:error] [pid 254995:tid 255174] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mw_7v0rlcEGmVraFXXwADTyY"]
[Tue Jul 21 07:41:07.302207 2026] [security2:error] [pid 254995:tid 255225] [client 20.226.60.151:59420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/xy.php"] [unique_id "al9Mw_7v0rlcEGmVraFXYAAAA4E"]
[Tue Jul 21 07:41:07.476522 2026] [security2:error] [pid 254995:tid 255197] [client 20.104.96.117:14641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9Mw_7v0rlcEGmVraFXaQAAA2Y"]
[Tue Jul 21 07:41:07.579445 2026] [security2:error] [pid 254995:tid 255131] [client 37.140.223.154:54661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mw_7v0rlcEGmVraFXagAAAyQ"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:07.631680 2026] [security2:error] [pid 254995:tid 255191] [client 20.220.225.223:11160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9Mw_7v0rlcEGmVraFXawAAA2A"]
[Tue Jul 21 07:41:07.651775 2026] [security2:error] [pid 254995:tid 255175] [client 122.186.204.214:51748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mw_7v0rlcEGmVraFXbQAAA1A"]
[Tue Jul 21 07:41:07.651928 2026] [security2:error] [pid 254995:tid 255175] [client 122.186.204.214:51748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mw_7v0rlcEGmVraFXbQAAA1A"]
[Tue Jul 21 07:41:07.752407 2026] [security2:error] [pid 254995:tid 255273] [client 20.104.96.117:14563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9Mw_7v0rlcEGmVraFXcAAAA5c"]
[Tue Jul 21 07:41:07.753246 2026] [core:error] [pid 254995:tid 255042] [remote 52.167.144.232:10707] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:07.753271 2026] [core:error] [pid 254995:tid 255042] [remote 52.167.144.232:10707] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:07.807600 2026] [security2:error] [pid 254995:tid 255198] [client 20.226.60.151:59499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/loader.php"] [unique_id "al9Mw_7v0rlcEGmVraFXcgAAA2c"]
[Tue Jul 21 07:41:07.990129 2026] [security2:error] [pid 254995:tid 255149] [client 4.204.201.85:46021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ssixta.php"] [unique_id "al9Mw_7v0rlcEGmVraFXegAAAzY"]
[Tue Jul 21 07:41:08.059008 2026] [security2:error] [pid 254995:tid 255266] [client 20.226.60.151:62247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/byp.php"] [unique_id "al9MxP7v0rlcEGmVraFXfAAAA5A"]
[Tue Jul 21 07:41:08.098258 2026] [security2:error] [pid 254995:tid 255278] [client 20.104.96.117:14580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9MxP7v0rlcEGmVraFXfQAAA5w"]
[Tue Jul 21 07:41:08.409672 2026] [security2:error] [pid 254995:tid 255269] [client 20.104.96.117:14564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/for.php"] [unique_id "al9MxP7v0rlcEGmVraFXhgAAA5M"]
[Tue Jul 21 07:41:08.651309 2026] [security2:error] [pid 254995:tid 255152] [client 122.164.127.47:50132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MxP7v0rlcEGmVraFXjAAAAzk"]
[Tue Jul 21 07:41:08.651441 2026] [security2:error] [pid 254995:tid 255152] [client 122.164.127.47:50132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9MxP7v0rlcEGmVraFXjAAAAzk"]
[Tue Jul 21 07:41:08.807146 2026] [security2:error] [pid 254995:tid 255197] [client 20.226.60.151:33526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9MxP7v0rlcEGmVraFXjwAAA2Y"]
[Tue Jul 21 07:41:08.883371 2026] [security2:error] [pid 254995:tid 255254] [client 20.104.96.117:14337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.fisiopelvicafloripa.com.br"] [uri "/raw.php"] [unique_id "al9MxP7v0rlcEGmVraFXlAAAA4Q"]
[Tue Jul 21 07:41:08.956314 2026] [security2:error] [pid 254995:tid 255267] [client 20.226.60.151:23154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/aa.php"] [unique_id "al9MxP7v0rlcEGmVraFXmAAAA5E"]
[Tue Jul 21 07:41:09.013822 2026] [security2:error] [pid 254995:tid 255219] [client 20.220.225.223:11185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/dr.php"] [unique_id "al9Mxf7v0rlcEGmVraFXmwAAA3s"]
[Tue Jul 21 07:41:09.026782 2026] [security2:error] [pid 254995:tid 255201] [client 20.151.10.161:55266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/p.php"] [unique_id "al9Mxf7v0rlcEGmVraFXnQAAA2o"]
[Tue Jul 21 07:41:09.245635 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:59410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/spadex.php"] [unique_id "al9Mxf7v0rlcEGmVraFXqwAAA3w"]
[Tue Jul 21 07:41:09.335975 2026] [security2:error] [pid 254995:tid 255132] [client 182.8.255.181:17597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXrAAAAyU"]
[Tue Jul 21 07:41:09.336129 2026] [security2:error] [pid 254995:tid 255132] [client 182.8.255.181:17597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXrAAAAyU"]
[Tue Jul 21 07:41:09.385055 2026] [security2:error] [pid 254995:tid 255141] [client 4.204.201.85:3565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/1c.php"] [unique_id "al9Mxf7v0rlcEGmVraFXrQAAAy4"]
[Tue Jul 21 07:41:09.589934 2026] [security2:error] [pid 254995:tid 255171] [client 103.86.117.203:65137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXvAAAA0w"]
[Tue Jul 21 07:41:09.590082 2026] [security2:error] [pid 254995:tid 255171] [client 103.86.117.203:65137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXvAAAA0w"]
[Tue Jul 21 07:41:09.716422 2026] [security2:error] [pid 254995:tid 255258] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Mxf7v0rlcEGmVraFXwAAAA4g"]
[Tue Jul 21 07:41:09.735207 2026] [security2:error] [pid 254995:tid 255131] [client 20.226.60.151:33533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Mxf7v0rlcEGmVraFXwQAAAyQ"]
[Tue Jul 21 07:41:09.837309 2026] [security2:error] [pid 254995:tid 255107] [remote 113.160.142.119:39926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carrosselbuique.com.br"] [uri "/wp-login.php"] [unique_id "al9Mxf7v0rlcEGmVraFXwgADkG8"]
[Tue Jul 21 07:41:09.841742 2026] [security2:error] [pid 254995:tid 255164] [client 193.36.225.71:45735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Mxf7v0rlcEGmVraFXwwAAA0U"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:09.928306 2026] [security2:error] [pid 254995:tid 255068] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXxQADYEg"]
[Tue Jul 21 07:41:09.928437 2026] [security2:error] [pid 254995:tid 255191] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXxQADYEg"]
[Tue Jul 21 07:41:09.946987 2026] [security2:error] [pid 254995:tid 255146] [client 194.99.104.35:39020] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXxgAAAzM"]
[Tue Jul 21 07:41:09.947100 2026] [security2:error] [pid 254995:tid 255146] [client 194.99.104.35:39020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Mxf7v0rlcEGmVraFXxgAAAzM"]
[Tue Jul 21 07:41:09.955652 2026] [security2:error] [pid 254995:tid 255144] [client 4.204.201.85:7433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/test2.php"] [unique_id "al9Mxf7v0rlcEGmVraFXxwAAAzE"]
[Tue Jul 21 07:41:10.010249 2026] [security2:error] [pid 254995:tid 255213] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Mxv7v0rlcEGmVraFXzgAAA3U"]
[Tue Jul 21 07:41:10.242263 2026] [security2:error] [pid 254995:tid 255274] [client 37.140.223.156:54887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mxv7v0rlcEGmVraFX0AAAA5g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:10.290979 2026] [security2:error] [pid 254995:tid 255145] [client 154.192.233.199:59267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX3wAAAzI"]
[Tue Jul 21 07:41:10.291115 2026] [security2:error] [pid 254995:tid 255145] [client 154.192.233.199:59267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX3wAAAzI"]
[Tue Jul 21 07:41:10.323899 2026] [security2:error] [pid 254995:tid 255177] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/wp.php"] [unique_id "al9Mxv7v0rlcEGmVraFX4gAAA1I"]
[Tue Jul 21 07:41:10.327975 2026] [security2:error] [pid 254995:tid 255154] [client 175.45.70.82:56860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX4wAAAzs"]
[Tue Jul 21 07:41:10.328089 2026] [security2:error] [pid 254995:tid 255154] [client 175.45.70.82:56860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX4wAAAzs"]
[Tue Jul 21 07:41:10.369345 2026] [security2:error] [pid 254995:tid 255256] [client 4.204.201.85:7436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/buy.php"] [unique_id "al9Mxv7v0rlcEGmVraFX5AAAA4Y"]
[Tue Jul 21 07:41:10.380891 2026] [security2:error] [pid 254995:tid 255197] [client 20.226.60.151:59466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/2x.php"] [unique_id "al9Mxv7v0rlcEGmVraFX5QAAA2Y"]
[Tue Jul 21 07:41:10.603337 2026] [security2:error] [pid 254995:tid 255150] [client 20.220.225.223:5299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/2x.php"] [unique_id "al9Mxv7v0rlcEGmVraFX7AAAAzc"]
[Tue Jul 21 07:41:10.606747 2026] [security2:error] [pid 254995:tid 255191] [client 20.226.60.151:56287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/txets.php"] [unique_id "al9Mxv7v0rlcEGmVraFX7QAAA2A"]
[Tue Jul 21 07:41:10.652128 2026] [security2:error] [pid 254995:tid 255265] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/new.php"] [unique_id "al9Mxv7v0rlcEGmVraFX8wAAA48"]
[Tue Jul 21 07:41:10.693884 2026] [security2:error] [pid 254995:tid 255223] [client 4.204.201.85:46056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ssend.php"] [unique_id "al9Mxv7v0rlcEGmVraFX9AAAA38"]
[Tue Jul 21 07:41:10.694311 2026] [security2:error] [pid 254995:tid 255278] [client 20.226.60.151:62310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/root.php"] [unique_id "al9Mxv7v0rlcEGmVraFX9QAAA5w"]
[Tue Jul 21 07:41:10.708323 2026] [security2:error] [pid 254995:tid 255157] [client 103.106.20.201:64020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX9gAAAz4"]
[Tue Jul 21 07:41:10.708417 2026] [security2:error] [pid 254995:tid 255157] [client 103.106.20.201:64020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX9gAAAz4"]
[Tue Jul 21 07:41:10.750168 2026] [security2:error] [pid 254995:tid 255211] [client 202.143.127.214:63840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX-QAAA3M"]
[Tue Jul 21 07:41:10.750285 2026] [security2:error] [pid 254995:tid 255211] [client 202.143.127.214:63840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX-QAAA3M"]
[Tue Jul 21 07:41:10.777244 2026] [security2:error] [pid 254995:tid 255189] [client 128.127.105.184:33096] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX-gAAA14"]
[Tue Jul 21 07:41:10.777392 2026] [security2:error] [pid 254995:tid 255189] [client 128.127.105.184:33096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX-gAAA14"]
[Tue Jul 21 07:41:10.813856 2026] [security2:error] [pid 254995:tid 255220] [client 122.162.144.145:29832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX-wAAA3w"]
[Tue Jul 21 07:41:10.813986 2026] [security2:error] [pid 254995:tid 255220] [client 122.162.144.145:29832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX-wAAA3w"]
[Tue Jul 21 07:41:10.865058 2026] [security2:error] [pid 254995:tid 255070] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX_AADbko"]
[Tue Jul 21 07:41:10.865213 2026] [security2:error] [pid 254995:tid 255205] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Mxv7v0rlcEGmVraFX_AADbko"]
[Tue Jul 21 07:41:10.985654 2026] [security2:error] [pid 254995:tid 255272] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/class-t.api.php"] [unique_id "al9Mxv7v0rlcEGmVraFX_wAAA5Y"]
[Tue Jul 21 07:41:11.259450 2026] [security2:error] [pid 254995:tid 255178] [client 4.204.201.85:46048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/item.php"] [unique_id "al9Mx_7v0rlcEGmVraFYEgAAA1M"]
[Tue Jul 21 07:41:11.299627 2026] [security2:error] [pid 254995:tid 255206] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/plugins.php"] [unique_id "al9Mx_7v0rlcEGmVraFYEwAAA28"]
[Tue Jul 21 07:41:11.592310 2026] [security2:error] [pid 254995:tid 255269] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/jp.php"] [unique_id "al9Mx_7v0rlcEGmVraFYHwAAA5M"]
[Tue Jul 21 07:41:11.593794 2026] [security2:error] [pid 254995:tid 255033] [remote 192.241.143.148:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nutrawidenews.com"] [uri "/wp-login.php"] [unique_id "al9Mx_7v0rlcEGmVraFYIAADMCU"]
[Tue Jul 21 07:41:11.709961 2026] [security2:error] [pid 254995:tid 255225] [client 20.226.60.151:22336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/122.php"] [unique_id "al9Mx_7v0rlcEGmVraFYKQAAA4E"]
[Tue Jul 21 07:41:11.832146 2026] [security2:error] [pid 254995:tid 255140] [client 4.204.201.85:3574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ss.php"] [unique_id "al9Mx_7v0rlcEGmVraFYKgAAAy0"]
[Tue Jul 21 07:41:11.846061 2026] [security2:error] [pid 254995:tid 255176] [client 20.151.10.161:12088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/bthil.php"] [unique_id "al9Mx_7v0rlcEGmVraFYKwAAA1E"]
[Tue Jul 21 07:41:11.904342 2026] [security2:error] [pid 254995:tid 255188] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/error.php"] [unique_id "al9Mx_7v0rlcEGmVraFYLAAAA10"]
[Tue Jul 21 07:41:12.140683 2026] [security2:error] [pid 254995:tid 255256] [client 4.204.201.85:3535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/hypo.php"] [unique_id "al9MyP7v0rlcEGmVraFYNwAAA4Y"]
[Tue Jul 21 07:41:12.220584 2026] [security2:error] [pid 254995:tid 255200] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/classwithtostring.php"] [unique_id "al9MyP7v0rlcEGmVraFYPQAAA2k"]
[Tue Jul 21 07:41:12.257886 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:62267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/sym403.php"] [unique_id "al9MyP7v0rlcEGmVraFYPgAAA5c"]
[Tue Jul 21 07:41:12.309635 2026] [core:error] [pid 254995:tid 255114] [remote 52.167.144.206:64029] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:12.309662 2026] [core:error] [pid 254995:tid 255114] [remote 52.167.144.206:64029] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:12.344723 2026] [security2:error] [pid 254995:tid 255019] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MyP7v0rlcEGmVraFYQQADXxc"]
[Tue Jul 21 07:41:12.344870 2026] [security2:error] [pid 254995:tid 255190] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MyP7v0rlcEGmVraFYQQADXxc"]
[Tue Jul 21 07:41:12.425463 2026] [security2:error] [pid 254995:tid 255168] [client 117.217.38.194:62257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MyP7v0rlcEGmVraFYRwAAA0k"]
[Tue Jul 21 07:41:12.425571 2026] [security2:error] [pid 254995:tid 255168] [client 117.217.38.194:62257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MyP7v0rlcEGmVraFYRwAAA0k"]
[Tue Jul 21 07:41:12.494403 2026] [security2:error] [pid 254995:tid 255199] [client 4.204.201.85:3550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/users.php"] [unique_id "al9MyP7v0rlcEGmVraFYSwAAA2g"]
[Tue Jul 21 07:41:12.494778 2026] [security2:error] [pid 254995:tid 255160] [client 128.127.105.184:47600] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9MyP7v0rlcEGmVraFYTAAAA0E"]
[Tue Jul 21 07:41:12.494853 2026] [security2:error] [pid 254995:tid 255160] [client 128.127.105.184:47600] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9MyP7v0rlcEGmVraFYTAAAA0E"]
[Tue Jul 21 07:41:12.494874 2026] [security2:error] [pid 254995:tid 255160] [client 128.127.105.184:47600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9MyP7v0rlcEGmVraFYTAAAA0E"]
[Tue Jul 21 07:41:12.535686 2026] [security2:error] [pid 254995:tid 255143] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/bless.php"] [unique_id "al9MyP7v0rlcEGmVraFYTQAAAzA"]
[Tue Jul 21 07:41:12.550299 2026] [security2:error] [pid 254995:tid 255219] [client 20.226.60.151:59486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ctex1.php"] [unique_id "al9MyP7v0rlcEGmVraFYTgAAA3s"]
[Tue Jul 21 07:41:12.648035 2026] [security2:error] [pid 254995:tid 255161] [client 20.226.60.151:33492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/v543.php"] [unique_id "al9MyP7v0rlcEGmVraFYVwAAA0I"]
[Tue Jul 21 07:41:12.794791 2026] [security2:error] [pid 254995:tid 255200] [client 20.220.225.223:5281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/kq1.php"] [unique_id "al9MyP7v0rlcEGmVraFYXwAAA2k"]
[Tue Jul 21 07:41:12.851918 2026] [security2:error] [pid 254995:tid 255273] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/storage/index.php"] [unique_id "al9MyP7v0rlcEGmVraFYYQAAA5c"]
[Tue Jul 21 07:41:12.913201 2026] [security2:error] [pid 254995:tid 255258] [client 4.204.201.85:3559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/177.php"] [unique_id "al9MyP7v0rlcEGmVraFYYgAAA4g"]
[Tue Jul 21 07:41:12.928062 2026] [security2:error] [pid 254995:tid 255190] [client 20.151.10.161:53579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/7.php"] [unique_id "al9MyP7v0rlcEGmVraFYYwAAA18"]
[Tue Jul 21 07:41:13.008125 2026] [security2:error] [pid 254995:tid 255186] [client 20.226.60.151:59493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/edorxrr.php"] [unique_id "al9Myf7v0rlcEGmVraFYZAAAA1s"]
[Tue Jul 21 07:41:13.032179 2026] [security2:error] [pid 254995:tid 255160] [client 20.226.60.151:59403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/miru1.php"] [unique_id "al9Myf7v0rlcEGmVraFYZQAAA0E"]
[Tue Jul 21 07:41:13.103276 2026] [security2:error] [pid 254995:tid 255208] [client 20.226.60.151:59425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/sump1.php"] [unique_id "al9Myf7v0rlcEGmVraFYaQAAA3A"]
[Tue Jul 21 07:41:13.161453 2026] [security2:error] [pid 254995:tid 255225] [client 20.226.60.151:59392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/file5.php"] [unique_id "al9Myf7v0rlcEGmVraFYawAAA4E"]
[Tue Jul 21 07:41:13.175568 2026] [security2:error] [pid 254995:tid 255198] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/g.php"] [unique_id "al9Myf7v0rlcEGmVraFYbAAAA2c"]
[Tue Jul 21 07:41:13.234854 2026] [security2:error] [pid 254995:tid 255013] [remote 45.150.79.142:55682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9Myf7v0rlcEGmVraFYcQADhhE"]
[Tue Jul 21 07:41:13.300103 2026] [security2:error] [pid 254995:tid 255000] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYegADMAQ"]
[Tue Jul 21 07:41:13.300257 2026] [security2:error] [pid 254995:tid 255143] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYegADMAQ"]
[Tue Jul 21 07:41:13.400499 2026] [security2:error] [pid 254995:tid 255278] [client 20.226.60.151:59490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/0xD.php"] [unique_id "al9Myf7v0rlcEGmVraFYfwAAA5w"]
[Tue Jul 21 07:41:13.483944 2026] [security2:error] [pid 254995:tid 255141] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/nf.php"] [unique_id "al9Myf7v0rlcEGmVraFYggAAAy4"]
[Tue Jul 21 07:41:13.486300 2026] [security2:error] [pid 254995:tid 255222] [client 59.96.220.140:53660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYgwAAA34"]
[Tue Jul 21 07:41:13.486855 2026] [security2:error] [pid 254995:tid 255222] [client 59.96.220.140:53660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYgwAAA34"]
[Tue Jul 21 07:41:13.529129 2026] [security2:error] [pid 254995:tid 255206] [client 4.204.201.85:46044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/config.php"] [unique_id "al9Myf7v0rlcEGmVraFYhAAAA28"]
[Tue Jul 21 07:41:13.539869 2026] [security2:error] [pid 254995:tid 255195] [client 122.179.91.63:14443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYhQAAA2Q"]
[Tue Jul 21 07:41:13.539968 2026] [security2:error] [pid 254995:tid 255195] [client 122.179.91.63:14443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYhQAAA2Q"]
[Tue Jul 21 07:41:13.542572 2026] [security2:error] [pid 254995:tid 255157] [client 103.174.34.15:52735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYhgAAAz4"]
[Tue Jul 21 07:41:13.542694 2026] [security2:error] [pid 254995:tid 255157] [client 103.174.34.15:52735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYhgAAAz4"]
[Tue Jul 21 07:41:13.544726 2026] [security2:error] [pid 254995:tid 255149] [client 139.167.225.182:61114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYhwAAAzY"]
[Tue Jul 21 07:41:13.544779 2026] [security2:error] [pid 254995:tid 255149] [client 139.167.225.182:61114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Myf7v0rlcEGmVraFYhwAAAzY"]
[Tue Jul 21 07:41:13.810588 2026] [security2:error] [pid 254995:tid 255152] [client 20.226.60.151:50932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/fnstall.php"] [unique_id "al9Myf7v0rlcEGmVraFYkQAAAzk"]
[Tue Jul 21 07:41:13.839544 2026] [security2:error] [pid 254995:tid 255145] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/xda.php"] [unique_id "al9Myf7v0rlcEGmVraFYlAAAAzI"]
[Tue Jul 21 07:41:13.942021 2026] [security2:error] [pid 254995:tid 255024] [remote 57.141.18.7:54442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemape.xml"] [unique_id "al9Myf7v0rlcEGmVraFYjwADThw"]
[Tue Jul 21 07:41:14.148716 2026] [security2:error] [pid 254995:tid 255216] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/shell.php"] [unique_id "al9Myv7v0rlcEGmVraFYoQAAA3g"]
[Tue Jul 21 07:41:14.267600 2026] [security2:error] [pid 254995:tid 255146] [client 4.204.201.85:7448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/gettest.php"] [unique_id "al9Myv7v0rlcEGmVraFYpAAAAzM"]
[Tue Jul 21 07:41:14.268018 2026] [security2:error] [pid 254995:tid 255265] [client 20.226.60.151:22359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/get.php"] [unique_id "al9Myv7v0rlcEGmVraFYpQAAA48"]
[Tue Jul 21 07:41:14.450286 2026] [security2:error] [pid 254995:tid 255224] [client 20.226.60.151:59502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/acp.php"] [unique_id "al9Myv7v0rlcEGmVraFYrAAAA4A"]
[Tue Jul 21 07:41:14.453950 2026] [security2:error] [pid 254995:tid 255178] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/3.php"] [unique_id "al9Myv7v0rlcEGmVraFYrQAAA1M"]
[Tue Jul 21 07:41:14.505720 2026] [security2:error] [pid 254995:tid 255168] [client 152.59.154.239:56545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Myv7v0rlcEGmVraFYrwAAA0k"]
[Tue Jul 21 07:41:14.505881 2026] [security2:error] [pid 254995:tid 255168] [client 152.59.154.239:56545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Myv7v0rlcEGmVraFYrwAAA0k"]
[Tue Jul 21 07:41:14.653224 2026] [security2:error] [pid 254995:tid 255192] [client 4.204.201.85:3578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/min.php"] [unique_id "al9Myv7v0rlcEGmVraFYtgAAA2E"]
[Tue Jul 21 07:41:14.775700 2026] [security2:error] [pid 254995:tid 255158] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/mds.php"] [unique_id "al9Myv7v0rlcEGmVraFYuwAAAz8"]
[Tue Jul 21 07:41:14.989245 2026] [security2:error] [pid 254995:tid 255134] [client 4.204.201.85:7462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/dvjul.php"] [unique_id "al9Myv7v0rlcEGmVraFYwQAAAyc"]
[Tue Jul 21 07:41:15.060007 2026] [security2:error] [pid 254995:tid 255200] [client 20.226.60.151:59404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/mosty.php"] [unique_id "al9My_7v0rlcEGmVraFYxAAAA2k"]
[Tue Jul 21 07:41:15.079113 2026] [security2:error] [pid 254995:tid 255153] [client 62.102.148.187:40074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9My_7v0rlcEGmVraFYxQAAAzo"]
[Tue Jul 21 07:41:15.079280 2026] [security2:error] [pid 254995:tid 255153] [client 62.102.148.187:40074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9My_7v0rlcEGmVraFYxQAAAzo"]
[Tue Jul 21 07:41:15.081685 2026] [security2:error] [pid 254995:tid 255265] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/archive.php"] [unique_id "al9My_7v0rlcEGmVraFYxwAAA48"]
[Tue Jul 21 07:41:15.152097 2026] [security2:error] [pid 254995:tid 255179] [client 20.226.60.151:62250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/sixxis.php"] [unique_id "al9My_7v0rlcEGmVraFYyAAAA1Q"]
[Tue Jul 21 07:41:15.302326 2026] [security2:error] [pid 254995:tid 255218] [client 173.24.185.52:51713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9My_7v0rlcEGmVraFYzwAAA3o"]
[Tue Jul 21 07:41:15.302414 2026] [security2:error] [pid 254995:tid 255218] [client 173.24.185.52:51713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9My_7v0rlcEGmVraFYzwAAA3o"]
[Tue Jul 21 07:41:15.329772 2026] [security2:error] [pid 254995:tid 255160] [client 4.204.201.85:45968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/biufile.php"] [unique_id "al9My_7v0rlcEGmVraFY0QAAA0E"]
[Tue Jul 21 07:41:15.383753 2026] [security2:error] [pid 254995:tid 255141] [client 20.226.60.151:22357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/as.php"] [unique_id "al9My_7v0rlcEGmVraFY0wAAAy4"]
[Tue Jul 21 07:41:15.435482 2026] [security2:error] [pid 254995:tid 255208] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/amax.php"] [unique_id "al9My_7v0rlcEGmVraFY1QAAA3A"]
[Tue Jul 21 07:41:15.653152 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:59491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/6.php"] [unique_id "al9My_7v0rlcEGmVraFY3AAAA5k"]
[Tue Jul 21 07:41:15.744335 2026] [security2:error] [pid 254995:tid 255190] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/moon.php"] [unique_id "al9My_7v0rlcEGmVraFY4QAAA18"]
[Tue Jul 21 07:41:15.973245 2026] [security2:error] [pid 254995:tid 255216] [client 4.204.201.85:3521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/av.php"] [unique_id "al9My_7v0rlcEGmVraFY6gAAA3g"]
[Tue Jul 21 07:41:15.996583 2026] [security2:error] [pid 254995:tid 255214] [client 136.144.33.106:37565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Myf7v0rlcEGmVraFYkwAAA3Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:16.027426 2026] [security2:error] [pid 254995:tid 255213] [client 20.226.60.151:62223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ip.php"] [unique_id "al9MzP7v0rlcEGmVraFY6wAAA3U"]
[Tue Jul 21 07:41:16.041207 2026] [security2:error] [pid 254995:tid 255155] [client 136.144.42.179:23431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MzP7v0rlcEGmVraFY7AAAAzw"]
[Tue Jul 21 07:41:16.051541 2026] [security2:error] [pid 254995:tid 255223] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/ws83.php"] [unique_id "al9MzP7v0rlcEGmVraFY7wAAA38"]
[Tue Jul 21 07:41:16.054236 2026] [security2:error] [pid 254995:tid 255205] [client 20.226.60.151:59474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/32e17094cfindex.php"] [unique_id "al9MzP7v0rlcEGmVraFY8AAAA24"]
[Tue Jul 21 07:41:16.056010 2026] [security2:error] [pid 254995:tid 255203] [client 20.151.10.161:12039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/8.php"] [unique_id "al9MzP7v0rlcEGmVraFY8QAAA2w"]
[Tue Jul 21 07:41:16.351878 2026] [security2:error] [pid 254995:tid 255274] [client 106.215.181.8:16565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MzP7v0rlcEGmVraFY_gAAA5g"]
[Tue Jul 21 07:41:16.351982 2026] [security2:error] [pid 254995:tid 255274] [client 106.215.181.8:16565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MzP7v0rlcEGmVraFY_gAAA5g"]
[Tue Jul 21 07:41:16.384481 2026] [security2:error] [pid 254995:tid 255146] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/CDX1.php"] [unique_id "al9MzP7v0rlcEGmVraFZAgAAAzM"]
[Tue Jul 21 07:41:16.410660 2026] [security2:error] [pid 254995:tid 255195] [client 4.204.201.85:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/coffexium.php"] [unique_id "al9MzP7v0rlcEGmVraFZBAAAA2Q"]
[Tue Jul 21 07:41:16.602209 2026] [security2:error] [pid 254995:tid 255022] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MzP7v0rlcEGmVraFZBwADeRo"]
[Tue Jul 21 07:41:16.602353 2026] [security2:error] [pid 254995:tid 255217] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9MzP7v0rlcEGmVraFZBwADeRo"]
[Tue Jul 21 07:41:16.638615 2026] [security2:error] [pid 254995:tid 255142] [client 20.104.96.117:30424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9MzP7v0rlcEGmVraFZCAAAAy8"]
[Tue Jul 21 07:41:16.712554 2026] [security2:error] [pid 254995:tid 255193] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/inputs.php"] [unique_id "al9MzP7v0rlcEGmVraFZDAAAA2I"]
[Tue Jul 21 07:41:16.822035 2026] [security2:error] [pid 254995:tid 255148] [client 20.226.60.151:59514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/qqqa.php"] [unique_id "al9MzP7v0rlcEGmVraFZEAAAAzU"]
[Tue Jul 21 07:41:16.870893 2026] [security2:error] [pid 254995:tid 255033] [remote 45.117.83.212:45148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9MzP7v0rlcEGmVraFZEgADVyU"]
[Tue Jul 21 07:41:16.925349 2026] [security2:error] [pid 254995:tid 255200] [client 4.204.201.85:46033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/core.php"] [unique_id "al9MzP7v0rlcEGmVraFZFgAAA2k"]
[Tue Jul 21 07:41:16.974653 2026] [security2:error] [pid 254995:tid 255216] [client 20.226.60.151:62324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/kq1.php"] [unique_id "al9MzP7v0rlcEGmVraFZGAAAA3g"]
[Tue Jul 21 07:41:17.041504 2026] [security2:error] [pid 254995:tid 255155] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/ms-edit.php"] [unique_id "al9Mzf7v0rlcEGmVraFZGgAAAzw"]
[Tue Jul 21 07:41:17.153690 2026] [security2:error] [pid 254995:tid 255063] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mzf7v0rlcEGmVraFZHQADakM"]
[Tue Jul 21 07:41:17.153859 2026] [security2:error] [pid 254995:tid 255201] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Mzf7v0rlcEGmVraFZHQADakM"]
[Tue Jul 21 07:41:17.419432 2026] [security2:error] [pid 254995:tid 255131] [client 20.226.60.151:59427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/aunmc.php"] [unique_id "al9Mzf7v0rlcEGmVraFZIgAAAyQ"]
[Tue Jul 21 07:41:17.432457 2026] [security2:error] [pid 254995:tid 255220] [client 4.204.201.85:7480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/als.php"] [unique_id "al9Mzf7v0rlcEGmVraFZJgAAA3w"]
[Tue Jul 21 07:41:17.625939 2026] [security2:error] [pid 254995:tid 255149] [client 20.151.10.161:53601] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.jandel.com.br"] [uri "/1.php"] [unique_id "al9Mzf7v0rlcEGmVraFZKQAAAzY"]
[Tue Jul 21 07:41:17.626072 2026] [security2:error] [pid 254995:tid 255149] [client 20.151.10.161:53601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/1.php"] [unique_id "al9Mzf7v0rlcEGmVraFZKQAAAzY"]
[Tue Jul 21 07:41:17.831209 2026] [security2:error] [pid 254995:tid 255142] [client 4.204.201.85:3564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/simple.php"] [unique_id "al9Mzf7v0rlcEGmVraFZLgAAAy8"]
[Tue Jul 21 07:41:17.854283 2026] [security2:error] [pid 254995:tid 255172] [client 20.226.60.151:56242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/dex.php"] [unique_id "al9Mzf7v0rlcEGmVraFZMAAAA00"]
[Tue Jul 21 07:41:17.863695 2026] [security2:error] [pid 254995:tid 255016] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mzf7v0rlcEGmVraFZMQADmBQ"]
[Tue Jul 21 07:41:17.863856 2026] [security2:error] [pid 254995:tid 255274] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mzf7v0rlcEGmVraFZMQADmBQ"]
[Tue Jul 21 07:41:17.884432 2026] [security2:error] [pid 254995:tid 255164] [client 20.226.60.151:22939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ccou.php"] [unique_id "al9Mzf7v0rlcEGmVraFZMwAAA0U"]
[Tue Jul 21 07:41:17.907516 2026] [security2:error] [pid 254995:tid 255192] [client 185.251.19.64:34669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9MzP7v0rlcEGmVraFY7QAAA2E"]
[Tue Jul 21 07:41:17.911393 2026] [security2:error] [pid 254995:tid 255141] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/simple.php"] [unique_id "al9Mzf7v0rlcEGmVraFZNQAAAy4"]
[Tue Jul 21 07:41:18.026332 2026] [security2:error] [pid 254995:tid 255262] [client 20.226.60.151:33473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9Mzv7v0rlcEGmVraFZOQAAA4w"]
[Tue Jul 21 07:41:18.230650 2026] [security2:error] [pid 254995:tid 255201] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/404.php"] [unique_id "al9Mzv7v0rlcEGmVraFZPAAAA2o"]
[Tue Jul 21 07:41:18.325435 2026] [security2:error] [pid 254995:tid 255195] [client 122.186.204.214:52278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mzv7v0rlcEGmVraFZQgAAA2Q"]
[Tue Jul 21 07:41:18.325551 2026] [security2:error] [pid 254995:tid 255195] [client 122.186.204.214:52278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Mzv7v0rlcEGmVraFZQgAAA2Q"]
[Tue Jul 21 07:41:18.343600 2026] [security2:error] [pid 254995:tid 255222] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Mzv7v0rlcEGmVraFZQwAAA34"]
[Tue Jul 21 07:41:18.352317 2026] [security2:error] [pid 254995:tid 255265] [client 4.204.201.85:3541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/init.php"] [unique_id "al9Mzv7v0rlcEGmVraFZRAAAA48"]
[Tue Jul 21 07:41:18.476061 2026] [security2:error] [pid 254995:tid 255258] [client 20.226.60.151:50911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/uoocf.php"] [unique_id "al9Mzv7v0rlcEGmVraFZSgAAA4g"]
[Tue Jul 21 07:41:18.561473 2026] [security2:error] [pid 254995:tid 255157] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/file3.php"] [unique_id "al9Mzv7v0rlcEGmVraFZSwAAAz4"]
[Tue Jul 21 07:41:18.596586 2026] [security2:error] [pid 254995:tid 255149] [client 159.65.243.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.243.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mzv7v0rlcEGmVraFZTQAAAzY"]
[Tue Jul 21 07:41:18.770231 2026] [security2:error] [pid 254995:tid 255273] [client 173.239.211.121:50935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9Mzv7v0rlcEGmVraFZTwAAA5c"]
[Tue Jul 21 07:41:18.778518 2026] [security2:error] [pid 254995:tid 255256] [client 173.239.211.144:38777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9Mzv7v0rlcEGmVraFZUAAAA4Y"]
[Tue Jul 21 07:41:18.901819 2026] [security2:error] [pid 254995:tid 255175] [client 4.204.201.85:7477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/fpwch.php"] [unique_id "al9Mzv7v0rlcEGmVraFZVwAAA1A"]
[Tue Jul 21 07:41:18.928020 2026] [security2:error] [pid 254995:tid 255216] [client 216.73.161.169:20449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9Mzv7v0rlcEGmVraFZTgAAA3g"]
[Tue Jul 21 07:41:18.965526 2026] [security2:error] [pid 254995:tid 255132] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Mzv7v0rlcEGmVraFZXAAAAyU"]
[Tue Jul 21 07:41:19.013828 2026] [security2:error] [pid 254995:tid 255214] [client 117.251.86.144:54942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZXQAAA3Y"]
[Tue Jul 21 07:41:19.013963 2026] [security2:error] [pid 254995:tid 255214] [client 117.251.86.144:54942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZXQAAA3Y"]
[Tue Jul 21 07:41:19.187050 2026] [security2:error] [pid 254995:tid 255268] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/wp-mail.php"] [unique_id "al9Mz_7v0rlcEGmVraFZXwAAA5I"]
[Tue Jul 21 07:41:19.203887 2026] [security2:error] [pid 254995:tid 255143] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Mz_7v0rlcEGmVraFZYAAAAzA"]
[Tue Jul 21 07:41:19.223519 2026] [security2:error] [pid 254995:tid 255179] [client 122.164.127.47:50694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZYQAAA1Q"]
[Tue Jul 21 07:41:19.225109 2026] [security2:error] [pid 254995:tid 255179] [client 122.164.127.47:50694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZYQAAA1Q"]
[Tue Jul 21 07:41:19.264934 2026] [security2:error] [pid 254995:tid 255182] [client 20.151.10.161:12070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/100.php"] [unique_id "al9Mz_7v0rlcEGmVraFZYwAAA1c"]
[Tue Jul 21 07:41:19.437512 2026] [security2:error] [pid 254995:tid 255195] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Mz_7v0rlcEGmVraFZawAAA2Q"]
[Tue Jul 21 07:41:19.501257 2026] [security2:error] [pid 254995:tid 255259] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/about.php"] [unique_id "al9Mz_7v0rlcEGmVraFZbgAAA4k"]
[Tue Jul 21 07:41:19.633832 2026] [security2:error] [pid 254995:tid 255186] [client 4.204.201.85:3523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/domvf.php"] [unique_id "al9Mz_7v0rlcEGmVraFZdgAAA1s"]
[Tue Jul 21 07:41:19.678241 2026] [security2:error] [pid 254995:tid 255272] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9Mz_7v0rlcEGmVraFZdwAAA5Y"]
[Tue Jul 21 07:41:19.699525 2026] [security2:error] [pid 254995:tid 255229] [client 182.8.255.181:21115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZeAAAA4I"]
[Tue Jul 21 07:41:19.699649 2026] [security2:error] [pid 254995:tid 255229] [client 182.8.255.181:21115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZeAAAA4I"]
[Tue Jul 21 07:41:19.806822 2026] [security2:error] [pid 254995:tid 255203] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/adminfuns.php"] [unique_id "al9Mz_7v0rlcEGmVraFZeQAAA2w"]
[Tue Jul 21 07:41:19.840929 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:62229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/h02ugyh.php"] [unique_id "al9Mz_7v0rlcEGmVraFZegAAAx4"]
[Tue Jul 21 07:41:19.920598 2026] [security2:error] [pid 254995:tid 255217] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Mz_7v0rlcEGmVraFZgQAAA3k"]
[Tue Jul 21 07:41:19.928806 2026] [security2:error] [pid 254995:tid 255134] [client 154.192.233.199:59570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZggAAAyc"]
[Tue Jul 21 07:41:19.928902 2026] [security2:error] [pid 254995:tid 255134] [client 154.192.233.199:59570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Mz_7v0rlcEGmVraFZggAAAyc"]
[Tue Jul 21 07:41:20.069395 2026] [security2:error] [pid 254995:tid 255278] [client 103.86.117.203:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M0P7v0rlcEGmVraFZhwAAA5w"]
[Tue Jul 21 07:41:20.069543 2026] [security2:error] [pid 254995:tid 255278] [client 103.86.117.203:49282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M0P7v0rlcEGmVraFZhwAAA5w"]
[Tue Jul 21 07:41:20.080908 2026] [security2:error] [pid 254995:tid 255181] [client 172.245.102.46:50549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9M0P7v0rlcEGmVraFZiQAAA1Y"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:20.104056 2026] [security2:error] [pid 254995:tid 255171] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/php8.php"] [unique_id "al9M0P7v0rlcEGmVraFZjQAAA0w"]
[Tue Jul 21 07:41:20.153658 2026] [security2:error] [pid 254995:tid 255168] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9M0P7v0rlcEGmVraFZjgAAA0k"]
[Tue Jul 21 07:41:20.393414 2026] [security2:error] [pid 254995:tid 255152] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9M0P7v0rlcEGmVraFZjwAAAzk"]
[Tue Jul 21 07:41:20.432512 2026] [security2:error] [pid 254995:tid 255254] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/info.php"] [unique_id "al9M0P7v0rlcEGmVraFZkwAAA4Q"]
[Tue Jul 21 07:41:20.630546 2026] [security2:error] [pid 254995:tid 255274] [client 193.36.225.118:62605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Mz_7v0rlcEGmVraFZbQAAA5g"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:20.640182 2026] [security2:error] [pid 254995:tid 255258] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9M0P7v0rlcEGmVraFZnQAAA4g"]
[Tue Jul 21 07:41:20.653453 2026] [security2:error] [pid 254995:tid 255272] [client 20.220.225.223:55498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/bootstrap.php"] [unique_id "al9M0P7v0rlcEGmVraFZngAAA5Y"]
[Tue Jul 21 07:41:20.655162 2026] [security2:error] [pid 254995:tid 255039] [remote 136.232.157.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.157.232.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9M0P7v0rlcEGmVraFZnwADJCs"]
[Tue Jul 21 07:41:20.655257 2026] [security2:error] [pid 254995:tid 255131] [client 136.232.157.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9M0P7v0rlcEGmVraFZnwADJCs"]
[Tue Jul 21 07:41:20.734282 2026] [security2:error] [pid 254995:tid 255140] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/edit.php"] [unique_id "al9M0P7v0rlcEGmVraFZoQAAAy0"]
[Tue Jul 21 07:41:20.743071 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:33509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-temp.php"] [unique_id "al9M0P7v0rlcEGmVraFZogAAAx4"]
[Tue Jul 21 07:41:20.745631 2026] [security2:error] [pid 254995:tid 255189] [client 20.226.60.151:59408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/iywwi.php"] [unique_id "al9M0P7v0rlcEGmVraFZowAAA14"]
[Tue Jul 21 07:41:20.766100 2026] [security2:error] [pid 254995:tid 255183] [client 20.226.60.151:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/xpwer1.php"] [unique_id "al9M0P7v0rlcEGmVraFZpAAAA1g"]
[Tue Jul 21 07:41:20.887125 2026] [security2:error] [pid 254995:tid 255149] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9M0P7v0rlcEGmVraFZqQAAAzY"]
[Tue Jul 21 07:41:20.914450 2026] [security2:error] [pid 254995:tid 255172] [client 20.226.60.151:23166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/w3lls.php"] [unique_id "al9M0P7v0rlcEGmVraFZqgAAA00"]
[Tue Jul 21 07:41:21.028737 2026] [security2:error] [pid 254995:tid 255182] [client 175.45.70.82:57581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZsAAAA1c"]
[Tue Jul 21 07:41:21.028855 2026] [security2:error] [pid 254995:tid 255182] [client 175.45.70.82:57581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZsAAAA1c"]
[Tue Jul 21 07:41:21.029597 2026] [security2:error] [pid 254995:tid 255214] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/166.php"] [unique_id "al9M0f7v0rlcEGmVraFZsQAAA3Y"]
[Tue Jul 21 07:41:21.135194 2026] [security2:error] [pid 254995:tid 255148] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9M0f7v0rlcEGmVraFZsgAAAzU"]
[Tue Jul 21 07:41:21.324563 2026] [security2:error] [pid 254995:tid 255179] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/8.php"] [unique_id "al9M0f7v0rlcEGmVraFZtwAAA1Q"]
[Tue Jul 21 07:41:21.375585 2026] [security2:error] [pid 254995:tid 255142] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9M0f7v0rlcEGmVraFZuAAAAy8"]
[Tue Jul 21 07:41:21.397421 2026] [security2:error] [pid 254995:tid 255133] [client 20.226.60.151:59397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/gqgsa.php"] [unique_id "al9M0f7v0rlcEGmVraFZuQAAAyY"]
[Tue Jul 21 07:41:21.403026 2026] [security2:error] [pid 254995:tid 255037] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZugADOSk"]
[Tue Jul 21 07:41:21.403128 2026] [security2:error] [pid 254995:tid 255152] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZugADOSk"]
[Tue Jul 21 07:41:21.443853 2026] [security2:error] [pid 254995:tid 255188] [client 103.106.20.201:64603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZvQAAA10"]
[Tue Jul 21 07:41:21.443933 2026] [security2:error] [pid 254995:tid 255188] [client 103.106.20.201:64603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZvQAAA10"]
[Tue Jul 21 07:41:21.587739 2026] [security2:error] [pid 254995:tid 255275] [client 122.162.144.145:32979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZwwAAA5k"]
[Tue Jul 21 07:41:21.587870 2026] [security2:error] [pid 254995:tid 255275] [client 122.162.144.145:32979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZwwAAA5k"]
[Tue Jul 21 07:41:21.604947 2026] [security2:error] [pid 254995:tid 255266] [client 62.102.148.187:57574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZxAAAA5A"]
[Tue Jul 21 07:41:21.605028 2026] [security2:error] [pid 254995:tid 255266] [client 62.102.148.187:57574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9M0f7v0rlcEGmVraFZxAAAA5A"]
[Tue Jul 21 07:41:21.612282 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:62300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9M0f7v0rlcEGmVraFZxQAAA3w"]
[Tue Jul 21 07:41:21.615625 2026] [security2:error] [pid 254995:tid 255160] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9M0f7v0rlcEGmVraFZxgAAA0E"]
[Tue Jul 21 07:41:21.642105 2026] [security2:error] [pid 254995:tid 255218] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/ws38.php"] [unique_id "al9M0f7v0rlcEGmVraFZxwAAA3o"]
[Tue Jul 21 07:41:21.867857 2026] [security2:error] [pid 254995:tid 255225] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9M0f7v0rlcEGmVraFZzAAAA4E"]
[Tue Jul 21 07:41:22.009137 2026] [security2:error] [pid 254995:tid 255149] [client 20.151.10.161:53615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/about.php"] [unique_id "al9M0v7v0rlcEGmVraFZ0gAAAzY"]
[Tue Jul 21 07:41:22.116652 2026] [security2:error] [pid 254995:tid 255192] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9M0v7v0rlcEGmVraFZ1QAAA2E"]
[Tue Jul 21 07:41:22.256155 2026] [security2:error] [pid 254995:tid 255168] [client 20.226.60.151:22948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/test1.php"] [unique_id "al9M0v7v0rlcEGmVraFZ2QAAA0k"]
[Tue Jul 21 07:41:22.327551 2026] [security2:error] [pid 254995:tid 255174] [client 20.104.96.117:30455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9M0v7v0rlcEGmVraFZ2gAAA08"]
[Tue Jul 21 07:41:22.364363 2026] [security2:error] [pid 254995:tid 255173] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9M0v7v0rlcEGmVraFZ2wAAA04"]
[Tue Jul 21 07:41:22.412263 2026] [security2:error] [pid 254995:tid 255147] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/a7.php"] [unique_id "al9M0v7v0rlcEGmVraFZ3AAAAzQ"]
[Tue Jul 21 07:41:22.594366 2026] [security2:error] [pid 254995:tid 255179] [client 20.10.88.201:27841] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arthromdcanada.online"] [uri "/robots.txt"] [unique_id "al9M0v7v0rlcEGmVraFZ4wAAA1Q"]
[Tue Jul 21 07:41:22.607363 2026] [security2:error] [pid 254995:tid 255208] [client 159.65.243.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9M0v7v0rlcEGmVraFZ5QAAA3A"]
[Tue Jul 21 07:41:22.685246 2026] [security2:error] [pid 254995:tid 255177] [client 4.204.201.85:46072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp.php"] [unique_id "al9M0v7v0rlcEGmVraFZ5wAAA1I"]
[Tue Jul 21 07:41:22.695213 2026] [proxy:error] [pid 254995:tid 255223] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:22.695279 2026] [proxy_http:error] [pid 254995:tid 255223] [client 20.226.60.151:62252] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:22.695862 2026] [proxy:error] [pid 254995:tid 255223] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:22.695886 2026] [proxy_http:error] [pid 254995:tid 255223] [client 20.226.60.151:62252] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:22.699848 2026] [security2:error] [pid 254995:tid 255190] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/classsmtps.php"] [unique_id "al9M0v7v0rlcEGmVraFZ6QAAA18"]
[Tue Jul 21 07:41:22.899086 2026] [security2:error] [pid 254995:tid 255278] [client 202.143.127.214:64277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0v7v0rlcEGmVraFZ7gAAA5w"]
[Tue Jul 21 07:41:22.899220 2026] [security2:error] [pid 254995:tid 255278] [client 202.143.127.214:64277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0v7v0rlcEGmVraFZ7gAAA5w"]
[Tue Jul 21 07:41:22.902655 2026] [security2:error] [pid 254995:tid 255209] [client 117.217.38.194:62733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0v7v0rlcEGmVraFZ7wAAA3E"]
[Tue Jul 21 07:41:22.903088 2026] [security2:error] [pid 254995:tid 255209] [client 117.217.38.194:62733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0v7v0rlcEGmVraFZ7wAAA3E"]
[Tue Jul 21 07:41:23.004595 2026] [security2:error] [pid 254995:tid 255157] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/rip.php"] [unique_id "al9M0_7v0rlcEGmVraFZ9AAAAz4"]
[Tue Jul 21 07:41:23.110860 2026] [security2:error] [pid 254995:tid 255187] [client 62.102.148.187:57590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFZ9gAAA1w"]
[Tue Jul 21 07:41:23.110962 2026] [security2:error] [pid 254995:tid 255187] [client 62.102.148.187:57590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFZ9gAAA1w"]
[Tue Jul 21 07:41:23.327226 2026] [security2:error] [pid 254995:tid 255213] [client 74.249.245.134:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/1.php"] [unique_id "al9M0_7v0rlcEGmVraFZ_wAAA3U"]
[Tue Jul 21 07:41:23.327311 2026] [security2:error] [pid 254995:tid 255213] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/1.php"] [unique_id "al9M0_7v0rlcEGmVraFZ_wAAA3U"]
[Tue Jul 21 07:41:23.489578 2026] [security2:error] [pid 254995:tid 255262] [client 59.96.220.140:54205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFaAQAAA4w"]
[Tue Jul 21 07:41:23.489711 2026] [security2:error] [pid 254995:tid 255262] [client 59.96.220.140:54205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFaAQAAA4w"]
[Tue Jul 21 07:41:23.522225 2026] [security2:error] [pid 254995:tid 255087] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFaAgADSVs"]
[Tue Jul 21 07:41:23.522369 2026] [security2:error] [pid 254995:tid 255168] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFaAgADSVs"]
[Tue Jul 21 07:41:23.635996 2026] [security2:error] [pid 254995:tid 255224] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/chosen.php"] [unique_id "al9M0_7v0rlcEGmVraFaCgAAA4A"]
[Tue Jul 21 07:41:23.961952 2026] [security2:error] [pid 254995:tid 255033] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFaEQADKCU"]
[Tue Jul 21 07:41:23.962083 2026] [security2:error] [pid 254995:tid 255135] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M0_7v0rlcEGmVraFaEQADKCU"]
[Tue Jul 21 07:41:24.003685 2026] [security2:error] [pid 254995:tid 255212] [client 139.167.225.182:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaEgAAA3Q"]
[Tue Jul 21 07:41:24.003782 2026] [security2:error] [pid 254995:tid 255212] [client 139.167.225.182:61763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaEgAAA3Q"]
[Tue Jul 21 07:41:24.008900 2026] [security2:error] [pid 254995:tid 255178] [client 20.226.60.151:59400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/elbzl.php"] [unique_id "al9M1P7v0rlcEGmVraFaEwAAA1M"]
[Tue Jul 21 07:41:24.101436 2026] [security2:error] [pid 254995:tid 255210] [client 193.36.225.107:64731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M0v7v0rlcEGmVraFZ8AAAA3I"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:24.263835 2026] [security2:error] [pid 254995:tid 255143] [client 20.226.60.151:23131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/database.php"] [unique_id "al9M1P7v0rlcEGmVraFaGgAAAzA"]
[Tue Jul 21 07:41:24.275879 2026] [security2:error] [pid 254995:tid 255173] [client 122.179.91.63:10997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaGwAAA04"]
[Tue Jul 21 07:41:24.276027 2026] [security2:error] [pid 254995:tid 255173] [client 122.179.91.63:10997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaGwAAA04"]
[Tue Jul 21 07:41:24.516132 2026] [security2:error] [pid 254995:tid 255181] [client 20.151.10.161:53598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/admin.php"] [unique_id "al9M1P7v0rlcEGmVraFaKAAAA1Y"]
[Tue Jul 21 07:41:24.548280 2026] [security2:error] [pid 254995:tid 255192] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/css.php"] [unique_id "al9M1P7v0rlcEGmVraFaKQAAA2E"]
[Tue Jul 21 07:41:24.648579 2026] [security2:error] [pid 254995:tid 255268] [client 184.75.223.211:56194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaLwAAA5I"]
[Tue Jul 21 07:41:24.648678 2026] [security2:error] [pid 254995:tid 255268] [client 184.75.223.211:56194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaLwAAA5I"]
[Tue Jul 21 07:41:24.661425 2026] [security2:error] [pid 254995:tid 255164] [client 20.104.96.117:30900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/xyn.php"] [unique_id "al9M1P7v0rlcEGmVraFaMQAAA0U"]
[Tue Jul 21 07:41:24.693114 2026] [security2:error] [pid 254995:tid 255224] [client 20.226.60.151:62306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9M1P7v0rlcEGmVraFaMgAAA4A"]
[Tue Jul 21 07:41:24.775341 2026] [security2:error] [pid 254995:tid 255190] [client 103.174.34.15:53219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaNAAAA18"]
[Tue Jul 21 07:41:24.775483 2026] [security2:error] [pid 254995:tid 255190] [client 103.174.34.15:53219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1P7v0rlcEGmVraFaNAAAA18"]
[Tue Jul 21 07:41:24.854291 2026] [security2:error] [pid 254995:tid 255163] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/php.php"] [unique_id "al9M1P7v0rlcEGmVraFaOQAAA0Q"]
[Tue Jul 21 07:41:25.071132 2026] [security2:error] [pid 254995:tid 255093] [remote 20.75.217.73:3382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "precisosolucao.com.br"] [uri "/wp-login.php"] [unique_id "al9M1f7v0rlcEGmVraFaQQADOWE"]
[Tue Jul 21 07:41:25.151654 2026] [security2:error] [pid 254995:tid 255143] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/aa.php"] [unique_id "al9M1f7v0rlcEGmVraFaRAAAAzA"]
[Tue Jul 21 07:41:25.161654 2026] [core:error] [pid 254995:tid 255047] [remote 35.221.29.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:25.161673 2026] [core:error] [pid 254995:tid 255047] [remote 35.221.29.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:25.196541 2026] [security2:error] [pid 254995:tid 255160] [client 193.36.225.64:20653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9M1f7v0rlcEGmVraFaSAAAA0E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:25.203211 2026] [security2:error] [pid 254995:tid 255173] [client 20.226.60.151:62274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/jj.php"] [unique_id "al9M1f7v0rlcEGmVraFaSgAAA04"]
[Tue Jul 21 07:41:25.214125 2026] [security2:error] [pid 254995:tid 255183] [client 20.226.60.151:50954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/flox.php"] [unique_id "al9M1f7v0rlcEGmVraFaSwAAA1g"]
[Tue Jul 21 07:41:25.434870 2026] [security2:error] [pid 254995:tid 255213] [client 20.220.225.223:11190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/zzz.php"] [unique_id "al9M1f7v0rlcEGmVraFaTwAAA3U"]
[Tue Jul 21 07:41:25.483628 2026] [security2:error] [pid 254995:tid 255181] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/bolt.php"] [unique_id "al9M1f7v0rlcEGmVraFaUQAAA1Y"]
[Tue Jul 21 07:41:25.606787 2026] [security2:error] [pid 254995:tid 255158] [client 152.59.154.239:51467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1f7v0rlcEGmVraFaVQAAAz8"]
[Tue Jul 21 07:41:25.606911 2026] [security2:error] [pid 254995:tid 255158] [client 152.59.154.239:51467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1f7v0rlcEGmVraFaVQAAAz8"]
[Tue Jul 21 07:41:25.613929 2026] [security2:error] [pid 254995:tid 255042] [remote 148.113.128.149:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "luminabeauty.com.br"] [uri "/robots.txt"] [unique_id "al9M1f7v0rlcEGmVraFaVgADVy4"]
[Tue Jul 21 07:41:25.614093 2026] [security2:error] [pid 254995:tid 255182] [client 148.113.128.149:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "luminabeauty.com.br"] [uri "/robots.txt"] [unique_id "al9M1f7v0rlcEGmVraFaVgADVy4"]
[Tue Jul 21 07:41:25.676616 2026] [security2:error] [pid 254995:tid 255147] [client 20.104.96.117:30409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/patie.php"] [unique_id "al9M1f7v0rlcEGmVraFaWAAAAzQ"]
[Tue Jul 21 07:41:25.691410 2026] [security2:error] [pid 254995:tid 255155] [client 20.197.195.24:13586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-blog.php"] [unique_id "al9M1f7v0rlcEGmVraFaWQAAAzw"]
[Tue Jul 21 07:41:25.733289 2026] [security2:error] [pid 254995:tid 255176] [client 4.204.201.85:46059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/class.php"] [unique_id "al9M1f7v0rlcEGmVraFaWwAAA1E"]
[Tue Jul 21 07:41:25.810083 2026] [security2:error] [pid 254995:tid 255224] [client 128.127.105.184:59826] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9M1f7v0rlcEGmVraFaXgAAA4A"]
[Tue Jul 21 07:41:25.810191 2026] [security2:error] [pid 254995:tid 255224] [client 128.127.105.184:59826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9M1f7v0rlcEGmVraFaXgAAA4A"]
[Tue Jul 21 07:41:25.941722 2026] [security2:error] [pid 254995:tid 255164] [client 173.24.185.52:52193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M1f7v0rlcEGmVraFaYgAAA0U"]
[Tue Jul 21 07:41:25.941837 2026] [security2:error] [pid 254995:tid 255164] [client 173.24.185.52:52193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M1f7v0rlcEGmVraFaYgAAA0U"]
[Tue Jul 21 07:41:25.961379 2026] [security2:error] [pid 254995:tid 255252] [client 20.226.60.151:22925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/file.php"] [unique_id "al9M1f7v0rlcEGmVraFaYwAAA4M"]
[Tue Jul 21 07:41:26.018650 2026] [security2:error] [pid 254995:tid 255179] [client 20.226.60.151:62236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9M1v7v0rlcEGmVraFaZgAAA1Q"]
[Tue Jul 21 07:41:26.367785 2026] [security2:error] [pid 254995:tid 255272] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/x.php"] [unique_id "al9M1v7v0rlcEGmVraFacwAAA5Y"]
[Tue Jul 21 07:41:26.563229 2026] [security2:error] [pid 254995:tid 255141] [client 20.226.60.151:56230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/popo.php"] [unique_id "al9M1v7v0rlcEGmVraFafQAAAy4"]
[Tue Jul 21 07:41:26.636368 2026] [security2:error] [pid 254995:tid 255192] [client 20.220.225.223:11584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/wicked.php"] [unique_id "al9M1v7v0rlcEGmVraFagQAAA2E"]
[Tue Jul 21 07:41:26.910952 2026] [security2:error] [pid 254995:tid 255132] [client 20.220.225.223:19309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/ez.php"] [unique_id "al9M1v7v0rlcEGmVraFaiwAAAyU"]
[Tue Jul 21 07:41:26.921701 2026] [security2:error] [pid 254995:tid 255151] [client 106.215.181.8:20448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1v7v0rlcEGmVraFajAAAAzg"]
[Tue Jul 21 07:41:26.921850 2026] [security2:error] [pid 254995:tid 255151] [client 106.215.181.8:20448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1v7v0rlcEGmVraFajAAAAzg"]
[Tue Jul 21 07:41:26.925205 2026] [core:error] [pid 254995:tid 255018] [remote 35.221.29.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:26.925222 2026] [core:error] [pid 254995:tid 255018] [remote 35.221.29.111:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:26.933199 2026] [security2:error] [pid 254995:tid 255224] [client 4.204.201.85:7434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/echkm.php"] [unique_id "al9M1v7v0rlcEGmVraFajQAAA4A"]
[Tue Jul 21 07:41:26.965701 2026] [security2:error] [pid 254995:tid 255126] [client 20.104.96.117:30853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/aa.php"] [unique_id "al9M1v7v0rlcEGmVraFajgAAAx8"]
[Tue Jul 21 07:41:27.108964 2026] [security2:error] [pid 254995:tid 255012] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1_7v0rlcEGmVraFakAADNRA"]
[Tue Jul 21 07:41:27.109120 2026] [security2:error] [pid 254995:tid 255148] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M1_7v0rlcEGmVraFakAADNRA"]
[Tue Jul 21 07:41:27.138518 2026] [security2:error] [pid 254995:tid 255163] [client 20.226.60.151:59500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/adjig.php"] [unique_id "al9M1_7v0rlcEGmVraFakQAAA0Q"]
[Tue Jul 21 07:41:27.207550 2026] [security2:error] [pid 254995:tid 255088] [remote 15.235.98.228:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "luminabeauty.com.br"] [uri "/"] [unique_id "al9M1_7v0rlcEGmVraFalQADaVw"]
[Tue Jul 21 07:41:27.207736 2026] [security2:error] [pid 254995:tid 255200] [client 15.235.98.228:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "luminabeauty.com.br"] [uri "/"] [unique_id "al9M1_7v0rlcEGmVraFalQADaVw"]
[Tue Jul 21 07:41:27.281100 2026] [security2:error] [pid 254995:tid 255179] [client 194.99.104.35:39394] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9M1_7v0rlcEGmVraFalwAAA1Q"]
[Tue Jul 21 07:41:27.281185 2026] [security2:error] [pid 254995:tid 255179] [client 194.99.104.35:39394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9M1_7v0rlcEGmVraFalwAAA1Q"]
[Tue Jul 21 07:41:27.348073 2026] [security2:error] [pid 254995:tid 255276] [client 20.226.60.151:22945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/file.php"] [unique_id "al9M1_7v0rlcEGmVraFamAAAA5o"]
[Tue Jul 21 07:41:27.417464 2026] [security2:error] [pid 254995:tid 255172] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/jga.php"] [unique_id "al9M1_7v0rlcEGmVraFamgAAA00"]
[Tue Jul 21 07:41:27.455352 2026] [security2:error] [pid 254995:tid 255218] [client 20.226.60.151:62253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/txets.php"] [unique_id "al9M1_7v0rlcEGmVraFanwAAA3o"]
[Tue Jul 21 07:41:27.700856 2026] [security2:error] [pid 254995:tid 255161] [client 20.151.10.161:53569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/edit.php"] [unique_id "al9M1_7v0rlcEGmVraFaowAAA0I"]
[Tue Jul 21 07:41:27.740064 2026] [security2:error] [pid 254995:tid 255189] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/k.php"] [unique_id "al9M1_7v0rlcEGmVraFapwAAA14"]
[Tue Jul 21 07:41:27.778187 2026] [security2:error] [pid 254995:tid 255071] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9M1_7v0rlcEGmVraFaqQADK0s"]
[Tue Jul 21 07:41:27.971422 2026] [security2:error] [pid 254995:tid 255068] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M1_7v0rlcEGmVraFargADWEg"]
[Tue Jul 21 07:41:27.971576 2026] [security2:error] [pid 254995:tid 255183] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M1_7v0rlcEGmVraFargADWEg"]
[Tue Jul 21 07:41:28.051059 2026] [security2:error] [pid 254995:tid 255168] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/vx.php"] [unique_id "al9M2P7v0rlcEGmVraFasAAAA0k"]
[Tue Jul 21 07:41:28.075494 2026] [security2:error] [pid 254995:tid 255177] [client 193.36.225.121:54967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M2P7v0rlcEGmVraFasQAAA1I"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:28.103723 2026] [security2:error] [pid 254995:tid 254999] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9M2P7v0rlcEGmVraFasgADLwM"]
[Tue Jul 21 07:41:28.349091 2026] [security2:error] [pid 254995:tid 255082] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sarareginadosreis1782388162420.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9M2P7v0rlcEGmVraFauAADNFY"]
[Tue Jul 21 07:41:28.363100 2026] [security2:error] [pid 254995:tid 255153] [client 20.104.96.117:30446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/xwpg.php"] [unique_id "al9M2P7v0rlcEGmVraFauQAAAzo"]
[Tue Jul 21 07:41:28.437426 2026] [security2:error] [pid 254995:tid 255020] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9M2P7v0rlcEGmVraFavAADfxg"]
[Tue Jul 21 07:41:28.453851 2026] [security2:error] [pid 254995:tid 255055] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M2P7v0rlcEGmVraFavQADczs"]
[Tue Jul 21 07:41:28.453981 2026] [security2:error] [pid 254995:tid 255211] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M2P7v0rlcEGmVraFavQADczs"]
[Tue Jul 21 07:41:28.482459 2026] [security2:error] [pid 254995:tid 255135] [client 20.226.60.151:51211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/yas.php"] [unique_id "al9M2P7v0rlcEGmVraFawAAAAyg"]
[Tue Jul 21 07:41:28.589234 2026] [security2:error] [pid 254995:tid 255276] [client 20.226.60.151:22923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/777.php"] [unique_id "al9M2P7v0rlcEGmVraFawgAAA5o"]
[Tue Jul 21 07:41:28.594382 2026] [security2:error] [pid 254995:tid 255131] [client 117.251.86.144:37802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M2P7v0rlcEGmVraFawwAAAyQ"]
[Tue Jul 21 07:41:28.594506 2026] [security2:error] [pid 254995:tid 255131] [client 117.251.86.144:37802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M2P7v0rlcEGmVraFawwAAAyQ"]
[Tue Jul 21 07:41:28.661606 2026] [security2:error] [pid 254995:tid 255059] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9M2P7v0rlcEGmVraFayQADjT8"]
[Tue Jul 21 07:41:28.748847 2026] [security2:error] [pid 254995:tid 255160] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/ws77.php"] [unique_id "al9M2P7v0rlcEGmVraFazAAAA0E"]
[Tue Jul 21 07:41:28.963306 2026] [security2:error] [pid 254995:tid 255225] [client 20.220.225.223:19657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/fz.php"] [unique_id "al9M2P7v0rlcEGmVraFa1gAAA4E"]
[Tue Jul 21 07:41:29.012996 2026] [security2:error] [pid 254995:tid 255046] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9M2f7v0rlcEGmVraFa2QADjDI"]
[Tue Jul 21 07:41:29.012987 2026] [security2:error] [pid 254995:tid 255192] [client 4.204.201.85:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/lib.php"] [unique_id "al9M2f7v0rlcEGmVraFa2AAAA2E"]
[Tue Jul 21 07:41:29.019653 2026] [security2:error] [pid 254995:tid 255171] [client 20.226.60.151:59401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/byp.php"] [unique_id "al9M2f7v0rlcEGmVraFa2gAAA0w"]
[Tue Jul 21 07:41:29.021144 2026] [security2:error] [pid 254995:tid 255201] [client 122.186.204.214:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa2wAAA2o"]
[Tue Jul 21 07:41:29.040070 2026] [security2:error] [pid 254995:tid 255158] [client 194.99.104.35:54052] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa3AAAAz8"]
[Tue Jul 21 07:41:29.040164 2026] [security2:error] [pid 254995:tid 255158] [client 194.99.104.35:54052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa3AAAAz8"]
[Tue Jul 21 07:41:29.040168 2026] [security2:error] [pid 254995:tid 255201] [client 122.186.204.214:52812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa2wAAA2o"]
[Tue Jul 21 07:41:29.064567 2026] [security2:error] [pid 254995:tid 255183] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/2.php"] [unique_id "al9M2f7v0rlcEGmVraFa4AAAA1g"]
[Tue Jul 21 07:41:29.217384 2026] [security2:error] [pid 254995:tid 255176] [client 20.226.60.151:62309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/dex.php"] [unique_id "al9M2f7v0rlcEGmVraFa4gAAA1E"]
[Tue Jul 21 07:41:29.226678 2026] [security2:error] [pid 254995:tid 255206] [client 20.226.60.151:22932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ssixta.php"] [unique_id "al9M2f7v0rlcEGmVraFa5AAAA28"]
[Tue Jul 21 07:41:29.298201 2026] [security2:error] [pid 254995:tid 255151] [client 20.104.96.117:30406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/ops.php"] [unique_id "al9M2f7v0rlcEGmVraFa5QAAAzg"]
[Tue Jul 21 07:41:29.342336 2026] [security2:error] [pid 254995:tid 255095] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9M2f7v0rlcEGmVraFa6gADMmM"]
[Tue Jul 21 07:41:29.387273 2026] [security2:error] [pid 254995:tid 255127] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/asd.php"] [unique_id "al9M2f7v0rlcEGmVraFa6wAAAyA"]
[Tue Jul 21 07:41:29.569074 2026] [security2:error] [pid 254995:tid 255276] [client 20.220.225.223:5277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/edit.php"] [unique_id "al9M2f7v0rlcEGmVraFa8AAAA5o"]
[Tue Jul 21 07:41:29.622280 2026] [security2:error] [pid 254995:tid 255022] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9M2f7v0rlcEGmVraFa8gADcho"]
[Tue Jul 21 07:41:29.711101 2026] [security2:error] [pid 254995:tid 255275] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/default.php"] [unique_id "al9M2f7v0rlcEGmVraFa9AAAA5k"]
[Tue Jul 21 07:41:29.804063 2026] [security2:error] [pid 254995:tid 255219] [client 20.104.96.117:30863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/mac.php"] [unique_id "al9M2f7v0rlcEGmVraFa9QAAA3s"]
[Tue Jul 21 07:41:29.805111 2026] [security2:error] [pid 254995:tid 255014] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9M2f7v0rlcEGmVraFa9gADQRI"]
[Tue Jul 21 07:41:29.820914 2026] [security2:error] [pid 254995:tid 255268] [client 122.164.127.47:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa9wAAA5I"]
[Tue Jul 21 07:41:29.821068 2026] [security2:error] [pid 254995:tid 255268] [client 122.164.127.47:51256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa9wAAA5I"]
[Tue Jul 21 07:41:29.902355 2026] [security2:error] [pid 254995:tid 255258] [client 62.102.148.187:36712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa_AAAA4g"]
[Tue Jul 21 07:41:29.902450 2026] [security2:error] [pid 254995:tid 255258] [client 62.102.148.187:36712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9M2f7v0rlcEGmVraFa_AAAA4g"]
[Tue Jul 21 07:41:30.023058 2026] [security2:error] [pid 254995:tid 255146] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/gettest.php"] [unique_id "al9M2v7v0rlcEGmVraFbBQAAAzM"]
[Tue Jul 21 07:41:30.172722 2026] [security2:error] [pid 254995:tid 255255] [client 182.8.255.181:21218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M2v7v0rlcEGmVraFbCgAAA4U"]
[Tue Jul 21 07:41:30.172860 2026] [security2:error] [pid 254995:tid 255255] [client 182.8.255.181:21218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M2v7v0rlcEGmVraFbCgAAA4U"]
[Tue Jul 21 07:41:30.191644 2026] [security2:error] [pid 254995:tid 255049] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9M2v7v0rlcEGmVraFbCwADJTU"]
[Tue Jul 21 07:41:30.213321 2026] [security2:error] [pid 254995:tid 255260] [client 4.204.201.85:3553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/login.php"] [unique_id "al9M2v7v0rlcEGmVraFbDQAAA4o"]
[Tue Jul 21 07:41:30.284117 2026] [security2:error] [pid 254995:tid 255163] [client 20.220.225.223:22505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-editor.php"] [unique_id "al9M2v7v0rlcEGmVraFbEAAAA0Q"]
[Tue Jul 21 07:41:30.530092 2026] [security2:error] [pid 254995:tid 255047] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9M2v7v0rlcEGmVraFbHgADVzM"]
[Tue Jul 21 07:41:30.553089 2026] [security2:error] [pid 254995:tid 255199] [client 103.86.117.203:49820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M2v7v0rlcEGmVraFbHwAAA2g"]
[Tue Jul 21 07:41:30.553212 2026] [security2:error] [pid 254995:tid 255199] [client 103.86.117.203:49820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M2v7v0rlcEGmVraFbHwAAA2g"]
[Tue Jul 21 07:41:30.593300 2026] [security2:error] [pid 254995:tid 255203] [client 20.151.10.161:53593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9M2v7v0rlcEGmVraFbIAAAA2w"]
[Tue Jul 21 07:41:30.660950 2026] [security2:error] [pid 254995:tid 255189] [client 20.104.96.117:30430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/mg.php"] [unique_id "al9M2v7v0rlcEGmVraFbJQAAA14"]
[Tue Jul 21 07:41:30.676620 2026] [security2:error] [pid 254995:tid 255188] [client 20.226.60.151:59513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ortasekerli1.php"] [unique_id "al9M2v7v0rlcEGmVraFbJgAAA10"]
[Tue Jul 21 07:41:30.770965 2026] [security2:error] [pid 254995:tid 255157] [client 193.36.225.72:47893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9M2f7v0rlcEGmVraFa8QAAAz4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:30.861780 2026] [security2:error] [pid 254995:tid 255042] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9M2v7v0rlcEGmVraFbLQADjC4"]
[Tue Jul 21 07:41:30.915429 2026] [security2:error] [pid 254995:tid 255278] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sarareginadosreis1782388162420.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9M2v7v0rlcEGmVraFbMQAAA5w"]
[Tue Jul 21 07:41:30.922360 2026] [security2:error] [pid 254995:tid 255201] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/tfm.php"] [unique_id "al9M2v7v0rlcEGmVraFbMwAAA2o"]
[Tue Jul 21 07:41:31.072473 2026] [security2:error] [pid 254995:tid 255004] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.conquisteemcasa.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9M2_7v0rlcEGmVraFbOAADQAg"]
[Tue Jul 21 07:41:31.083590 2026] [security2:error] [pid 254995:tid 255143] [client 154.192.233.199:59997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M2_7v0rlcEGmVraFbOQAAAzA"]
[Tue Jul 21 07:41:31.083712 2026] [security2:error] [pid 254995:tid 255143] [client 154.192.233.199:59997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M2_7v0rlcEGmVraFbOQAAAzA"]
[Tue Jul 21 07:41:31.102276 2026] [security2:error] [pid 254995:tid 255163] [client 20.220.225.223:11174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/kua.php"] [unique_id "al9M2_7v0rlcEGmVraFbPgAAA0Q"]
[Tue Jul 21 07:41:31.241370 2026] [security2:error] [pid 254995:tid 255212] [client 20.226.60.151:62298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/xpwer1.php"] [unique_id "al9M2_7v0rlcEGmVraFbQgAAA3Q"]
[Tue Jul 21 07:41:31.267098 2026] [security2:error] [pid 254995:tid 255179] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/ws81.php"] [unique_id "al9M2_7v0rlcEGmVraFbRQAAA1Q"]
[Tue Jul 21 07:41:31.321277 2026] [security2:error] [pid 254995:tid 255184] [client 20.226.60.151:22656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/1c.php"] [unique_id "al9M2_7v0rlcEGmVraFbRgAAA1k"]
[Tue Jul 21 07:41:31.433335 2026] [security2:error] [pid 254995:tid 255211] [client 193.36.225.153:50303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M2_7v0rlcEGmVraFbRAAAA3M"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:31.593402 2026] [security2:error] [pid 254995:tid 255256] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/222.php"] [unique_id "al9M2_7v0rlcEGmVraFbTwAAA4Y"]
[Tue Jul 21 07:41:31.605769 2026] [security2:error] [pid 254995:tid 255170] [client 4.204.201.85:3560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/a2.php"] [unique_id "al9M2_7v0rlcEGmVraFbUgAAA0s"]
[Tue Jul 21 07:41:31.761739 2026] [security2:error] [pid 254995:tid 255220] [client 175.45.70.82:58326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M2_7v0rlcEGmVraFbVQAAA3w"]
[Tue Jul 21 07:41:31.761938 2026] [security2:error] [pid 254995:tid 255220] [client 175.45.70.82:58326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M2_7v0rlcEGmVraFbVQAAA3w"]
[Tue Jul 21 07:41:31.869361 2026] [security2:error] [pid 254995:tid 255206] [client 20.151.10.161:55248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/f6.php"] [unique_id "al9M2_7v0rlcEGmVraFbVwAAA28"]
[Tue Jul 21 07:41:31.900694 2026] [security2:error] [pid 254995:tid 255117] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M2_7v0rlcEGmVraFbWAADdnk"]
[Tue Jul 21 07:41:31.900831 2026] [security2:error] [pid 254995:tid 255214] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M2_7v0rlcEGmVraFbWAADdnk"]
[Tue Jul 21 07:41:31.930246 2026] [security2:error] [pid 254995:tid 255255] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/t.php"] [unique_id "al9M2_7v0rlcEGmVraFbWwAAA4U"]
[Tue Jul 21 07:41:31.942266 2026] [security2:error] [pid 254995:tid 255192] [client 20.226.60.151:33475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/flox.php"] [unique_id "al9M2_7v0rlcEGmVraFbXQAAA2E"]
[Tue Jul 21 07:41:32.048069 2026] [security2:error] [pid 254995:tid 255143] [client 20.226.60.151:22377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/test2.php"] [unique_id "al9M3P7v0rlcEGmVraFbYQAAAzA"]
[Tue Jul 21 07:41:32.217623 2026] [security2:error] [pid 254995:tid 255167] [client 103.106.20.201:65215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3P7v0rlcEGmVraFbZwAAA0g"]
[Tue Jul 21 07:41:32.217760 2026] [security2:error] [pid 254995:tid 255167] [client 103.106.20.201:65215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3P7v0rlcEGmVraFbZwAAA0g"]
[Tue Jul 21 07:41:32.253098 2026] [security2:error] [pid 254995:tid 255252] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/a.php"] [unique_id "al9M3P7v0rlcEGmVraFbaAAAA4M"]
[Tue Jul 21 07:41:32.354726 2026] [security2:error] [pid 254995:tid 255274] [client 122.162.144.145:15052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M3P7v0rlcEGmVraFbagAAA5g"]
[Tue Jul 21 07:41:32.354838 2026] [security2:error] [pid 254995:tid 255274] [client 122.162.144.145:15052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M3P7v0rlcEGmVraFbagAAA5g"]
[Tue Jul 21 07:41:32.540163 2026] [security2:error] [pid 254995:tid 255069] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sarasantosdasilva1782312779991.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9M3P7v0rlcEGmVraFbcAADmUk"]
[Tue Jul 21 07:41:32.542757 2026] [security2:error] [pid 254995:tid 255273] [client 125.164.233.50:31734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9M3P7v0rlcEGmVraFbcQAAA5c"]
[Tue Jul 21 07:41:32.594804 2026] [security2:error] [pid 254995:tid 255189] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/a1.php"] [unique_id "al9M3P7v0rlcEGmVraFbcwAAA14"]
[Tue Jul 21 07:41:32.738831 2026] [security2:error] [pid 254995:tid 255209] [client 20.226.60.151:62290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/popo.php"] [unique_id "al9M3P7v0rlcEGmVraFbeQAAA3E"]
[Tue Jul 21 07:41:32.759480 2026] [security2:error] [pid 254995:tid 255125] [client 20.104.96.117:30451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-post-data.php"] [unique_id "al9M3P7v0rlcEGmVraFbegAAAx4"]
[Tue Jul 21 07:41:32.921364 2026] [security2:error] [pid 254995:tid 255202] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/w.php"] [unique_id "al9M3P7v0rlcEGmVraFbfQAAA2s"]
[Tue Jul 21 07:41:32.948049 2026] [security2:error] [pid 254995:tid 255147] [client 20.226.60.151:59407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/classwithtostring.php"] [unique_id "al9M3P7v0rlcEGmVraFbfgAAAzQ"]
[Tue Jul 21 07:41:32.967451 2026] [security2:error] [pid 254995:tid 255132] [client 4.204.201.85:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/d61.php"] [unique_id "al9M3P7v0rlcEGmVraFbfwAAAyU"]
[Tue Jul 21 07:41:33.120841 2026] [security2:error] [pid 254995:tid 255153] [client 20.226.60.151:33528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/yas.php"] [unique_id "al9M3f7v0rlcEGmVraFbhQAAAzo"]
[Tue Jul 21 07:41:33.125699 2026] [security2:error] [pid 254995:tid 255224] [client 20.226.60.151:56233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/file61.php"] [unique_id "al9M3f7v0rlcEGmVraFbhgAAA4A"]
[Tue Jul 21 07:41:33.236961 2026] [security2:error] [pid 254995:tid 255182] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/wp-good.php"] [unique_id "al9M3f7v0rlcEGmVraFbjwAAA1c"]
[Tue Jul 21 07:41:33.245927 2026] [security2:error] [pid 254995:tid 255141] [client 37.140.223.191:33579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M3f7v0rlcEGmVraFbkAAAAy4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:33.356015 2026] [security2:error] [pid 254995:tid 255199] [client 20.151.10.161:53570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/inputs.php"] [unique_id "al9M3f7v0rlcEGmVraFbkgAAA2g"]
[Tue Jul 21 07:41:33.375389 2026] [security2:error] [pid 254995:tid 255171] [client 117.217.38.194:63244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3f7v0rlcEGmVraFbkwAAA0w"]
[Tue Jul 21 07:41:33.375509 2026] [security2:error] [pid 254995:tid 255171] [client 117.217.38.194:63244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3f7v0rlcEGmVraFbkwAAA0w"]
[Tue Jul 21 07:41:33.407356 2026] [security2:error] [pid 254995:tid 255172] [client 20.226.60.151:22941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/buy.php"] [unique_id "al9M3f7v0rlcEGmVraFblAAAA00"]
[Tue Jul 21 07:41:33.728285 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:62239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/file61.php"] [unique_id "al9M3f7v0rlcEGmVraFbnwAAAx4"]
[Tue Jul 21 07:41:33.822506 2026] [security2:error] [pid 254995:tid 255201] [client 20.104.96.117:30458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/pucci.php"] [unique_id "al9M3f7v0rlcEGmVraFboQAAA2o"]
[Tue Jul 21 07:41:33.825669 2026] [security2:error] [pid 254995:tid 255192] [client 4.204.201.85:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/info.php"] [unique_id "al9M3f7v0rlcEGmVraFbogAAA2E"]
[Tue Jul 21 07:41:33.835026 2026] [security2:error] [pid 254995:tid 255161] [client 20.226.60.151:62303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/water.php"] [unique_id "al9M3f7v0rlcEGmVraFbowAAA0I"]
[Tue Jul 21 07:41:33.993864 2026] [security2:error] [pid 254995:tid 255213] [client 74.249.245.134:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/.info.php"] [unique_id "al9M3f7v0rlcEGmVraFbpAAAA3U"]
[Tue Jul 21 07:41:34.034949 2026] [security2:error] [pid 254995:tid 255163] [client 20.226.60.151:22937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ssend.php"] [unique_id "al9M3v7v0rlcEGmVraFbpgAAA0Q"]
[Tue Jul 21 07:41:34.122687 2026] [security2:error] [pid 254995:tid 255153] [client 20.226.60.151:62225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/nano.php"] [unique_id "al9M3v7v0rlcEGmVraFbqgAAAzo"]
[Tue Jul 21 07:41:34.152246 2026] [security2:error] [pid 254995:tid 255260] [client 20.226.60.151:59509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/root.php"] [unique_id "al9M3v7v0rlcEGmVraFbrAAAA4o"]
[Tue Jul 21 07:41:34.297412 2026] [security2:error] [pid 254995:tid 255151] [client 59.96.220.140:54701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbswAAAzg"]
[Tue Jul 21 07:41:34.298130 2026] [security2:error] [pid 254995:tid 255151] [client 59.96.220.140:54701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbswAAAzg"]
[Tue Jul 21 07:41:34.309632 2026] [security2:error] [pid 254995:tid 255274] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/item.php"] [unique_id "al9M3v7v0rlcEGmVraFbtQAAA5g"]
[Tue Jul 21 07:41:34.379840 2026] [security2:error] [pid 254995:tid 255109] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbtgADJHE"]
[Tue Jul 21 07:41:34.380027 2026] [security2:error] [pid 254995:tid 255131] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbtgADJHE"]
[Tue Jul 21 07:41:34.438261 2026] [security2:error] [pid 254995:tid 255214] [client 20.226.60.151:62216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/moon.php"] [unique_id "al9M3v7v0rlcEGmVraFbtwAAA3Y"]
[Tue Jul 21 07:41:34.489426 2026] [security2:error] [pid 254995:tid 255180] [client 139.167.225.182:62419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbuAAAA1U"]
[Tue Jul 21 07:41:34.489540 2026] [security2:error] [pid 254995:tid 255180] [client 139.167.225.182:62419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbuAAAA1U"]
[Tue Jul 21 07:41:34.599335 2026] [security2:error] [pid 254995:tid 255128] [client 136.144.33.102:26277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9M3v7v0rlcEGmVraFbugAAAyE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:34.615353 2026] [security2:error] [pid 254995:tid 255258] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/albin.php"] [unique_id "al9M3v7v0rlcEGmVraFbvgAAA4g"]
[Tue Jul 21 07:41:34.665353 2026] [security2:error] [pid 254995:tid 255026] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbwgADmh4"]
[Tue Jul 21 07:41:34.665477 2026] [security2:error] [pid 254995:tid 255276] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbwgADmh4"]
[Tue Jul 21 07:41:34.772901 2026] [security2:error] [pid 254995:tid 255154] [client 4.204.201.85:45975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/11.php"] [unique_id "al9M3v7v0rlcEGmVraFbyAAAAzs"]
[Tue Jul 21 07:41:34.780098 2026] [security2:error] [pid 254995:tid 255041] [remote 198.244.240.123:51508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.moveisrafael.com.br"] [uri "/robots.txt"] [unique_id "al9M3v7v0rlcEGmVraFbyQADly0"]
[Tue Jul 21 07:41:34.780211 2026] [security2:error] [pid 254995:tid 255273] [client 198.244.240.123:51508] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.moveisrafael.com.br"] [uri "/robots.txt"] [unique_id "al9M3v7v0rlcEGmVraFbyQADly0"]
[Tue Jul 21 07:41:34.900098 2026] [security2:error] [pid 254995:tid 255212] [client 122.179.91.63:13817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbygAAA3Q"]
[Tue Jul 21 07:41:34.900211 2026] [security2:error] [pid 254995:tid 255212] [client 122.179.91.63:13817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbygAAA3Q"]
[Tue Jul 21 07:41:34.919256 2026] [security2:error] [pid 254995:tid 255142] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/alfa.php"] [unique_id "al9M3v7v0rlcEGmVraFbywAAAy8"]
[Tue Jul 21 07:41:34.939201 2026] [security2:error] [pid 254995:tid 255184] [client 202.143.127.214:64726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbzQAAA1k"]
[Tue Jul 21 07:41:34.939285 2026] [security2:error] [pid 254995:tid 255184] [client 202.143.127.214:64726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M3v7v0rlcEGmVraFbzQAAA1k"]
[Tue Jul 21 07:41:35.036342 2026] [security2:error] [pid 254995:tid 255161] [client 20.226.60.151:56251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/water.php"] [unique_id "al9M3_7v0rlcEGmVraFbzwAAA0I"]
[Tue Jul 21 07:41:35.071798 2026] [security2:error] [pid 254995:tid 255163] [client 20.226.60.151:23139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/item.php"] [unique_id "al9M3_7v0rlcEGmVraFb0QAAA0Q"]
[Tue Jul 21 07:41:35.076631 2026] [security2:error] [pid 254995:tid 255218] [client 20.226.60.151:62217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-info.php"] [unique_id "al9M3_7v0rlcEGmVraFb0gAAA3o"]
[Tue Jul 21 07:41:35.128597 2026] [security2:error] [pid 254995:tid 255254] [client 20.104.96.117:30404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/black.php"] [unique_id "al9M3_7v0rlcEGmVraFb2AAAA4Q"]
[Tue Jul 21 07:41:35.219045 2026] [security2:error] [pid 254995:tid 255263] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/autoload_classmap.php"] [unique_id "al9M3_7v0rlcEGmVraFb3AAAA40"]
[Tue Jul 21 07:41:35.236909 2026] [security2:error] [pid 254995:tid 255027] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sarareginadosreis1782388162420.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9M3_7v0rlcEGmVraFb3QADSh8"]
[Tue Jul 21 07:41:35.411834 2026] [security2:error] [pid 254995:tid 255038] [remote 57.141.18.71:45650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9M3_7v0rlcEGmVraFb4wADmCo"]
[Tue Jul 21 07:41:35.478262 2026] [security2:error] [pid 254995:tid 255211] [client 4.204.201.85:3534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/v2.php"] [unique_id "al9M3_7v0rlcEGmVraFb5QAAA3M"]
[Tue Jul 21 07:41:35.547047 2026] [security2:error] [pid 254995:tid 255200] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/av.php"] [unique_id "al9M3_7v0rlcEGmVraFb5wAAA2k"]
[Tue Jul 21 07:41:35.565166 2026] [security2:error] [pid 254995:tid 255189] [client 20.226.60.151:34050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/2000.php"] [unique_id "al9M3_7v0rlcEGmVraFb6AAAA14"]
[Tue Jul 21 07:41:35.574801 2026] [security2:error] [pid 254995:tid 255276] [client 20.226.60.151:22350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ss.php"] [unique_id "al9M3_7v0rlcEGmVraFb6QAAA5o"]
[Tue Jul 21 07:41:35.709239 2026] [security2:error] [pid 254995:tid 255154] [client 20.226.60.151:59515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/sym403.php"] [unique_id "al9M3_7v0rlcEGmVraFb8QAAAzs"]
[Tue Jul 21 07:41:35.780999 2026] [security2:error] [pid 254995:tid 255142] [client 20.151.10.161:12044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/av.php"] [unique_id "al9M3_7v0rlcEGmVraFb9gAAAy8"]
[Tue Jul 21 07:41:35.860748 2026] [security2:error] [pid 254995:tid 255257] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/gg.php"] [unique_id "al9M3_7v0rlcEGmVraFb-gAAA4c"]
[Tue Jul 21 07:41:35.921701 2026] [autoindex:error] [pid 254995:tid 255179] [client 43.135.145.117:44252] AH01276: Cannot serve directory /home2/luc15241/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:41:35.997251 2026] [security2:error] [pid 254995:tid 255196] [client 20.104.96.117:30456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/zlece.php"] [unique_id "al9M3_7v0rlcEGmVraFb_gAAA2U"]
[Tue Jul 21 07:41:36.158560 2026] [security2:error] [pid 254995:tid 255215] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/sql.php"] [unique_id "al9M4P7v0rlcEGmVraFcBAAAA3c"]
[Tue Jul 21 07:41:36.250254 2026] [security2:error] [pid 254995:tid 255266] [client 20.226.60.151:62319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/122.php"] [unique_id "al9M4P7v0rlcEGmVraFcCwAAA5A"]
[Tue Jul 21 07:41:36.306215 2026] [security2:error] [pid 254995:tid 255057] [remote 15.235.27.175:31886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.moveisrafael.com.br"] [uri "/"] [unique_id "al9M4P7v0rlcEGmVraFcDwADSD0"]
[Tue Jul 21 07:41:36.306356 2026] [security2:error] [pid 254995:tid 255167] [client 15.235.27.175:31886] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.moveisrafael.com.br"] [uri "/"] [unique_id "al9M4P7v0rlcEGmVraFcDwADSD0"]
[Tue Jul 21 07:41:36.461391 2026] [security2:error] [pid 254995:tid 255125] [client 103.174.34.15:53718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4P7v0rlcEGmVraFcFQAAAx4"]
[Tue Jul 21 07:41:36.461724 2026] [security2:error] [pid 254995:tid 255125] [client 103.174.34.15:53718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4P7v0rlcEGmVraFcFQAAAx4"]
[Tue Jul 21 07:41:36.470633 2026] [security2:error] [pid 254995:tid 255273] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/up.php"] [unique_id "al9M4P7v0rlcEGmVraFcFgAAA5c"]
[Tue Jul 21 07:41:36.537762 2026] [security2:error] [pid 254995:tid 255220] [client 4.204.201.85:3537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/panel.php"] [unique_id "al9M4P7v0rlcEGmVraFcGQAAA3w"]
[Tue Jul 21 07:41:36.550711 2026] [security2:error] [pid 254995:tid 255200] [client 173.24.185.52:52670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M4P7v0rlcEGmVraFcGwAAA2k"]
[Tue Jul 21 07:41:36.550805 2026] [security2:error] [pid 254995:tid 255200] [client 173.24.185.52:52670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M4P7v0rlcEGmVraFcGwAAA2k"]
[Tue Jul 21 07:41:36.613207 2026] [security2:error] [pid 254995:tid 255112] [remote 162.19.86.63:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produto-express.com"] [uri "/wp-login.php"] [unique_id "al9M4P7v0rlcEGmVraFcHAADbHQ"]
[Tue Jul 21 07:41:36.641768 2026] [security2:error] [pid 254995:tid 255257] [client 20.226.60.151:22675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/hypo.php"] [unique_id "al9M4P7v0rlcEGmVraFcHQAAA4c"]
[Tue Jul 21 07:41:36.670291 2026] [security2:error] [pid 254995:tid 255196] [client 20.226.60.151:34024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/mds.php"] [unique_id "al9M4P7v0rlcEGmVraFcIAAAA2U"]
[Tue Jul 21 07:41:36.740322 2026] [security2:error] [pid 254995:tid 255135] [client 20.104.96.117:30463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/vssrs.php"] [unique_id "al9M4P7v0rlcEGmVraFcKAAAAyg"]
[Tue Jul 21 07:41:36.788587 2026] [security2:error] [pid 254995:tid 255148] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/66.php"] [unique_id "al9M4P7v0rlcEGmVraFcKQAAAzU"]
[Tue Jul 21 07:41:36.832281 2026] [security2:error] [pid 254995:tid 255268] [client 152.59.154.239:51973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4P7v0rlcEGmVraFcKgAAA5I"]
[Tue Jul 21 07:41:36.832385 2026] [security2:error] [pid 254995:tid 255268] [client 152.59.154.239:51973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4P7v0rlcEGmVraFcKgAAA5I"]
[Tue Jul 21 07:41:36.890537 2026] [security2:error] [pid 254995:tid 255181] [client 20.226.60.151:62316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-blink.php"] [unique_id "al9M4P7v0rlcEGmVraFcLgAAA1Y"]
[Tue Jul 21 07:41:37.088290 2026] [security2:error] [pid 254995:tid 255132] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/666.php"] [unique_id "al9M4f7v0rlcEGmVraFcNQAAAyU"]
[Tue Jul 21 07:41:37.250838 2026] [security2:error] [pid 254995:tid 255146] [client 4.204.201.85:7449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/dex.php"] [unique_id "al9M4f7v0rlcEGmVraFcOwAAAzM"]
[Tue Jul 21 07:41:37.322241 2026] [security2:error] [pid 254995:tid 255162] [client 20.226.60.151:33489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/zc-208.php"] [unique_id "al9M4f7v0rlcEGmVraFcPQAAA0M"]
[Tue Jul 21 07:41:37.442987 2026] [security2:error] [pid 254995:tid 255159] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/byp.php"] [unique_id "al9M4f7v0rlcEGmVraFcRgAAA0A"]
[Tue Jul 21 07:41:37.451426 2026] [security2:error] [pid 254995:tid 255213] [client 20.226.60.151:51204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/nano.php"] [unique_id "al9M4f7v0rlcEGmVraFcRwAAA3U"]
[Tue Jul 21 07:41:37.462918 2026] [security2:error] [pid 254995:tid 255212] [client 20.226.60.151:23162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/users.php"] [unique_id "al9M4f7v0rlcEGmVraFcSAAAA3Q"]
[Tue Jul 21 07:41:37.469776 2026] [security2:error] [pid 254995:tid 255156] [client 20.104.96.117:30412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wicked.php"] [unique_id "al9M4f7v0rlcEGmVraFcSQAAAz0"]
[Tue Jul 21 07:41:37.475695 2026] [security2:error] [pid 254995:tid 255140] [client 20.226.60.151:62228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/sid4.php"] [unique_id "al9M4f7v0rlcEGmVraFcSgAAAy0"]
[Tue Jul 21 07:41:37.536248 2026] [security2:error] [pid 254995:tid 255125] [client 193.36.225.123:51893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M4f7v0rlcEGmVraFcQQAAAx4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:37.571738 2026] [security2:error] [pid 254995:tid 255145] [client 106.215.181.8:26264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4f7v0rlcEGmVraFcSwAAAzI"]
[Tue Jul 21 07:41:37.581310 2026] [security2:error] [pid 254995:tid 255145] [client 106.215.181.8:26264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4f7v0rlcEGmVraFcSwAAAzI"]
[Tue Jul 21 07:41:37.651867 2026] [security2:error] [pid 254995:tid 255104] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4f7v0rlcEGmVraFcTQADemw"]
[Tue Jul 21 07:41:37.652003 2026] [security2:error] [pid 254995:tid 255218] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4f7v0rlcEGmVraFcTQADemw"]
[Tue Jul 21 07:41:37.716702 2026] [security2:error] [pid 254995:tid 255263] [client 4.204.201.85:46016] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "futurelogistica.com"] [uri "/1.php"] [unique_id "al9M4f7v0rlcEGmVraFcUAAAA40"]
[Tue Jul 21 07:41:37.716837 2026] [security2:error] [pid 254995:tid 255263] [client 4.204.201.85:46016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/1.php"] [unique_id "al9M4f7v0rlcEGmVraFcUAAAA40"]
[Tue Jul 21 07:41:37.746632 2026] [security2:error] [pid 254995:tid 255131] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/date.php"] [unique_id "al9M4f7v0rlcEGmVraFcUQAAAyQ"]
[Tue Jul 21 07:41:37.761393 2026] [security2:error] [pid 254995:tid 255215] [client 20.226.60.151:59460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/v543.php"] [unique_id "al9M4f7v0rlcEGmVraFcUgAAA3c"]
[Tue Jul 21 07:41:38.037737 2026] [security2:error] [pid 254995:tid 255223] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/pomo.php"] [unique_id "al9M4v7v0rlcEGmVraFcWwAAA38"]
[Tue Jul 21 07:41:38.119959 2026] [security2:error] [pid 254995:tid 255190] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sarareginadosreis1782388162420.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9M4v7v0rlcEGmVraFcXAAAA18"]
[Tue Jul 21 07:41:38.231129 2026] [security2:error] [pid 254995:tid 255146] [client 20.104.96.117:30413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/24.php"] [unique_id "al9M4v7v0rlcEGmVraFcYAAAAzM"]
[Tue Jul 21 07:41:38.232955 2026] [proxy:error] [pid 254995:tid 255278] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:38.233032 2026] [proxy_http:error] [pid 254995:tid 255278] [client 20.226.60.151:62297] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:38.233661 2026] [proxy:error] [pid 254995:tid 255278] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:38.233693 2026] [proxy_http:error] [pid 254995:tid 255278] [client 20.226.60.151:62297] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:38.276479 2026] [security2:error] [pid 254995:tid 255174] [client 4.204.201.85:3562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/ms.php"] [unique_id "al9M4v7v0rlcEGmVraFcYgAAA08"]
[Tue Jul 21 07:41:38.329670 2026] [security2:error] [pid 254995:tid 255143] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/test1.php"] [unique_id "al9M4v7v0rlcEGmVraFcZAAAAzA"]
[Tue Jul 21 07:41:38.352588 2026] [security2:error] [pid 254995:tid 255170] [client 20.226.60.151:22344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/177.php"] [unique_id "al9M4v7v0rlcEGmVraFcZwAAA0s"]
[Tue Jul 21 07:41:38.647466 2026] [security2:error] [pid 254995:tid 255145] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/fw.php"] [unique_id "al9M4v7v0rlcEGmVraFccQAAAzI"]
[Tue Jul 21 07:41:38.650076 2026] [security2:error] [pid 254995:tid 255260] [client 20.226.60.151:62332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wmore1.php"] [unique_id "al9M4v7v0rlcEGmVraFccgAAA4o"]
[Tue Jul 21 07:41:38.799010 2026] [security2:error] [pid 254995:tid 255084] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M4v7v0rlcEGmVraFcdQADVFg"]
[Tue Jul 21 07:41:38.799160 2026] [security2:error] [pid 254995:tid 255179] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M4v7v0rlcEGmVraFcdQADVFg"]
[Tue Jul 21 07:41:38.852612 2026] [security2:error] [pid 254995:tid 255221] [client 136.144.33.107:58249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9M4v7v0rlcEGmVraFceQAAA30"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:38.978735 2026] [security2:error] [pid 254995:tid 255169] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/fm.php"] [unique_id "al9M4v7v0rlcEGmVraFcfgAAA0o"]
[Tue Jul 21 07:41:39.139475 2026] [security2:error] [pid 254995:tid 255082] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFchgADSFY"]
[Tue Jul 21 07:41:39.139892 2026] [security2:error] [pid 254995:tid 255167] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFchgADSFY"]
[Tue Jul 21 07:41:39.229110 2026] [security2:error] [pid 254995:tid 255219] [client 20.226.60.151:62325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/solo1.php"] [unique_id "al9M4_7v0rlcEGmVraFcigAAA3s"]
[Tue Jul 21 07:41:39.242100 2026] [security2:error] [pid 254995:tid 255213] [client 117.251.86.144:46930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFciwAAA3U"]
[Tue Jul 21 07:41:39.242206 2026] [security2:error] [pid 254995:tid 255213] [client 117.251.86.144:46930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFciwAAA3U"]
[Tue Jul 21 07:41:39.291860 2026] [security2:error] [pid 254995:tid 255220] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/ini.php"] [unique_id "al9M4_7v0rlcEGmVraFcjQAAA3w"]
[Tue Jul 21 07:41:39.420590 2026] [security2:error] [pid 254995:tid 255188] [client 20.226.60.151:22947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/config.php"] [unique_id "al9M4_7v0rlcEGmVraFckwAAA10"]
[Tue Jul 21 07:41:39.473965 2026] [security2:error] [pid 254995:tid 255201] [client 20.104.96.117:30448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/xacs.php"] [unique_id "al9M4_7v0rlcEGmVraFclAAAA2o"]
[Tue Jul 21 07:41:39.543734 2026] [security2:error] [pid 254995:tid 255210] [client 4.204.201.85:3555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/memberfuns.php"] [unique_id "al9M4_7v0rlcEGmVraFcmAAAA3I"]
[Tue Jul 21 07:41:39.613510 2026] [security2:error] [pid 254995:tid 255145] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/themes.php"] [unique_id "al9M4_7v0rlcEGmVraFcmwAAAzI"]
[Tue Jul 21 07:41:39.659503 2026] [security2:error] [pid 254995:tid 255164] [client 62.102.148.187:39998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFcnAAAA0U"]
[Tue Jul 21 07:41:39.659645 2026] [security2:error] [pid 254995:tid 255164] [client 62.102.148.187:39998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFcnAAAA0U"]
[Tue Jul 21 07:41:39.665493 2026] [security2:error] [pid 254995:tid 255211] [client 122.186.204.214:53620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFcnQAAA3M"]
[Tue Jul 21 07:41:39.665603 2026] [security2:error] [pid 254995:tid 255211] [client 122.186.204.214:53620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M4_7v0rlcEGmVraFcnQAAA3M"]
[Tue Jul 21 07:41:39.942132 2026] [security2:error] [pid 254995:tid 255258] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/dropdown.php"] [unique_id "al9M4_7v0rlcEGmVraFcowAAA4g"]
[Tue Jul 21 07:41:39.954485 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:59463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/sixxis.php"] [unique_id "al9M4_7v0rlcEGmVraFcpAAAA5k"]
[Tue Jul 21 07:41:40.152327 2026] [security2:error] [pid 254995:tid 255278] [client 20.104.96.117:30457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/zildan.php"] [unique_id "al9M5P7v0rlcEGmVraFcrQAAA5w"]
[Tue Jul 21 07:41:40.153376 2026] [proxy:error] [pid 254995:tid 255209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:40.153458 2026] [proxy_http:error] [pid 254995:tid 255209] [client 20.226.60.151:62226] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:40.154073 2026] [proxy:error] [pid 254995:tid 255209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:40.154106 2026] [proxy_http:error] [pid 254995:tid 255209] [client 20.226.60.151:62226] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:40.245677 2026] [security2:error] [pid 254995:tid 255200] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/wp-links.php"] [unique_id "al9M5P7v0rlcEGmVraFcrwAAA2k"]
[Tue Jul 21 07:41:40.420007 2026] [security2:error] [pid 254995:tid 255128] [client 194.99.104.35:59876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9M5P7v0rlcEGmVraFctQAAAyE"]
[Tue Jul 21 07:41:40.420111 2026] [security2:error] [pid 254995:tid 255128] [client 194.99.104.35:59876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9M5P7v0rlcEGmVraFctQAAAyE"]
[Tue Jul 21 07:41:40.435699 2026] [security2:error] [pid 254995:tid 255218] [client 122.164.127.47:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M5P7v0rlcEGmVraFcugAAA3o"]
[Tue Jul 21 07:41:40.435808 2026] [security2:error] [pid 254995:tid 255218] [client 122.164.127.47:51814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M5P7v0rlcEGmVraFcugAAA3o"]
[Tue Jul 21 07:41:40.580028 2026] [security2:error] [pid 254995:tid 255254] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/xmrlpc.php"] [unique_id "al9M5P7v0rlcEGmVraFcwgAAA4Q"]
[Tue Jul 21 07:41:40.670581 2026] [security2:error] [pid 254995:tid 255169] [client 182.8.255.181:21216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M5P7v0rlcEGmVraFcyAAAA0o"]
[Tue Jul 21 07:41:40.670754 2026] [security2:error] [pid 254995:tid 255169] [client 182.8.255.181:21216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M5P7v0rlcEGmVraFcyAAAA0o"]
[Tue Jul 21 07:41:40.726182 2026] [autoindex:error] [pid 254995:tid 255256] [client 20.197.195.24:13664] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:41:40.752111 2026] [security2:error] [pid 254995:tid 255177] [client 20.197.195.24:13664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-content/admin.php"] [unique_id "al9M5P7v0rlcEGmVraFczAAAA1I"]
[Tue Jul 21 07:41:40.762640 2026] [security2:error] [pid 254995:tid 255132] [client 4.204.201.85:46071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/0.php"] [unique_id "al9M5P7v0rlcEGmVraFczQAAAyU"]
[Tue Jul 21 07:41:40.890192 2026] [security2:error] [pid 254995:tid 255197] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/htaccess.php"] [unique_id "al9M5P7v0rlcEGmVraFc0AAAA2Y"]
[Tue Jul 21 07:41:41.033425 2026] [security2:error] [pid 254995:tid 255223] [client 103.86.117.203:50358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M5f7v0rlcEGmVraFc1wAAA38"]
[Tue Jul 21 07:41:41.033542 2026] [security2:error] [pid 254995:tid 255223] [client 103.86.117.203:50358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M5f7v0rlcEGmVraFc1wAAA38"]
[Tue Jul 21 07:41:41.086022 2026] [security2:error] [pid 254995:tid 255128] [client 20.104.96.117:30859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/csa.php"] [unique_id "al9M5f7v0rlcEGmVraFc2wAAAyE"]
[Tue Jul 21 07:41:41.208843 2026] [security2:error] [pid 254995:tid 255218] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/readme.php"] [unique_id "al9M5f7v0rlcEGmVraFc3AAAA3o"]
[Tue Jul 21 07:41:41.248603 2026] [security2:error] [pid 254995:tid 255189] [client 154.192.233.199:60423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5f7v0rlcEGmVraFc3QAAA14"]
[Tue Jul 21 07:41:41.248894 2026] [security2:error] [pid 254995:tid 255189] [client 154.192.233.199:60423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5f7v0rlcEGmVraFc3QAAA14"]
[Tue Jul 21 07:41:41.398076 2026] [security2:error] [pid 254995:tid 255254] [client 20.226.60.151:56293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/moon.php"] [unique_id "al9M5f7v0rlcEGmVraFc4wAAA4Q"]
[Tue Jul 21 07:41:41.448894 2026] [security2:error] [pid 254995:tid 255135] [client 20.226.60.151:22949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/gettest.php"] [unique_id "al9M5f7v0rlcEGmVraFc5gAAAyg"]
[Tue Jul 21 07:41:41.622060 2026] [security2:error] [pid 254995:tid 255147] [client 20.226.60.151:59428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ip.php"] [unique_id "al9M5f7v0rlcEGmVraFc9AAAAzQ"]
[Tue Jul 21 07:41:41.661102 2026] [security2:error] [pid 254995:tid 255278] [client 194.99.104.35:59882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9M5f7v0rlcEGmVraFc9QAAA5w"]
[Tue Jul 21 07:41:41.661198 2026] [security2:error] [pid 254995:tid 255278] [client 194.99.104.35:59882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9M5f7v0rlcEGmVraFc9QAAA5w"]
[Tue Jul 21 07:41:41.670693 2026] [security2:error] [pid 254995:tid 255181] [client 4.204.201.85:7431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/BDKR28.php"] [unique_id "al9M5f7v0rlcEGmVraFc9gAAA1Y"]
[Tue Jul 21 07:41:41.743982 2026] [security2:error] [pid 254995:tid 255269] [client 20.226.60.151:33479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/cong.php"] [unique_id "al9M5f7v0rlcEGmVraFc-wAAA5M"]
[Tue Jul 21 07:41:41.858738 2026] [security2:error] [pid 254995:tid 255218] [client 20.104.96.117:30435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/w3llscc.php"] [unique_id "al9M5f7v0rlcEGmVraFc_gAAA3o"]
[Tue Jul 21 07:41:42.027299 2026] [security2:error] [pid 254995:tid 255161] [client 20.151.10.161:12034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/classwithtostring.php"] [unique_id "al9M5v7v0rlcEGmVraFdBAAAA0I"]
[Tue Jul 21 07:41:42.077922 2026] [security2:error] [pid 254995:tid 255211] [client 20.220.225.223:19281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/la.php"] [unique_id "al9M5v7v0rlcEGmVraFdBgAAA3M"]
[Tue Jul 21 07:41:42.192713 2026] [security2:error] [pid 254995:tid 255258] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/403.php"] [unique_id "al9M5v7v0rlcEGmVraFdDQAAA4g"]
[Tue Jul 21 07:41:42.240283 2026] [security2:error] [pid 254995:tid 255184] [client 4.204.201.85:46040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/green1.php"] [unique_id "al9M5v7v0rlcEGmVraFdDgAAA1k"]
[Tue Jul 21 07:41:42.406603 2026] [security2:error] [pid 254995:tid 255028] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M5v7v0rlcEGmVraFdEAADciA"]
[Tue Jul 21 07:41:42.406758 2026] [security2:error] [pid 254995:tid 255210] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M5v7v0rlcEGmVraFdEAADciA"]
[Tue Jul 21 07:41:42.506008 2026] [security2:error] [pid 254995:tid 255194] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/max.php"] [unique_id "al9M5v7v0rlcEGmVraFdFQAAA2M"]
[Tue Jul 21 07:41:42.530081 2026] [security2:error] [pid 254995:tid 255166] [client 175.45.70.82:58841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5v7v0rlcEGmVraFdGQAAA0c"]
[Tue Jul 21 07:41:42.530221 2026] [security2:error] [pid 254995:tid 255166] [client 175.45.70.82:58841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5v7v0rlcEGmVraFdGQAAA0c"]
[Tue Jul 21 07:41:42.544690 2026] [security2:error] [pid 254995:tid 255103] [remote 47.128.50.197:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hauptmann.com.br"] [uri "/"] [unique_id "al9M5v7v0rlcEGmVraFdGwADTWs"]
[Tue Jul 21 07:41:42.715888 2026] [security2:error] [pid 254995:tid 255268] [client 136.144.33.215:56491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9M5v7v0rlcEGmVraFdGgAAA5I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:42.811688 2026] [security2:error] [pid 254995:tid 255197] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/m.php"] [unique_id "al9M5v7v0rlcEGmVraFdJgAAA2Y"]
[Tue Jul 21 07:41:42.862714 2026] [security2:error] [pid 254995:tid 255144] [client 4.204.201.85:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/nc4.php"] [unique_id "al9M5v7v0rlcEGmVraFdJwAAAzE"]
[Tue Jul 21 07:41:43.047251 2026] [security2:error] [pid 254995:tid 255183] [client 103.106.20.201:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdMAAAA1g"]
[Tue Jul 21 07:41:43.047358 2026] [security2:error] [pid 254995:tid 255183] [client 103.106.20.201:49678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdMAAAA1g"]
[Tue Jul 21 07:41:43.121240 2026] [security2:error] [pid 254995:tid 255184] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/click.php"] [unique_id "al9M5_7v0rlcEGmVraFdMQAAA1k"]
[Tue Jul 21 07:41:43.161485 2026] [security2:error] [pid 254995:tid 255181] [client 122.162.144.145:15965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdMgAAA1Y"]
[Tue Jul 21 07:41:43.161616 2026] [security2:error] [pid 254995:tid 255181] [client 122.162.144.145:15965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdMgAAA1Y"]
[Tue Jul 21 07:41:43.317779 2026] [security2:error] [pid 254995:tid 255182] [client 20.226.60.151:22360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/min.php"] [unique_id "al9M5_7v0rlcEGmVraFdNwAAA1c"]
[Tue Jul 21 07:41:43.333201 2026] [security2:error] [pid 254995:tid 255271] [client 20.226.60.151:56255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-info.php"] [unique_id "al9M5_7v0rlcEGmVraFdOAAAA5U"]
[Tue Jul 21 07:41:43.438432 2026] [proxy:error] [pid 254995:tid 255194] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:43.438520 2026] [proxy_http:error] [pid 254995:tid 255194] [client 23.137.105.99:40496] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:43.439097 2026] [proxy:error] [pid 254995:tid 255194] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:43.439125 2026] [proxy_http:error] [pid 254995:tid 255194] [client 23.137.105.99:40496] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:43.445735 2026] [security2:error] [pid 254995:tid 255209] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/lv.php"] [unique_id "al9M5_7v0rlcEGmVraFdOgAAA3E"]
[Tue Jul 21 07:41:43.604172 2026] [security2:error] [pid 254995:tid 255175] [client 20.220.225.223:5251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/ez.php"] [unique_id "al9M5_7v0rlcEGmVraFdQQAAA1A"]
[Tue Jul 21 07:41:43.729538 2026] [security2:error] [pid 254995:tid 255165] [client 4.204.201.85:7485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/a1.php"] [unique_id "al9M5_7v0rlcEGmVraFdRwAAA0Y"]
[Tue Jul 21 07:41:43.768960 2026] [security2:error] [pid 254995:tid 255128] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/cong.php"] [unique_id "al9M5_7v0rlcEGmVraFdSAAAAyE"]
[Tue Jul 21 07:41:43.841700 2026] [security2:error] [pid 254995:tid 255254] [client 20.104.96.117:30850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wpx.php"] [unique_id "al9M5_7v0rlcEGmVraFdSgAAA4Q"]
[Tue Jul 21 07:41:43.860359 2026] [security2:error] [pid 254995:tid 255215] [client 117.217.38.194:63719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdSwAAA3c"]
[Tue Jul 21 07:41:43.860460 2026] [security2:error] [pid 254995:tid 255215] [client 117.217.38.194:63719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdSwAAA3c"]
[Tue Jul 21 07:41:43.879267 2026] [security2:error] [pid 254995:tid 255188] [client 59.96.220.140:55235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdTAAAA10"]
[Tue Jul 21 07:41:43.880000 2026] [security2:error] [pid 254995:tid 255188] [client 59.96.220.140:55235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M5_7v0rlcEGmVraFdTAAAA10"]
[Tue Jul 21 07:41:43.919647 2026] [core:error] [pid 254995:tid 255274] [client 23.137.105.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:43.919667 2026] [core:error] [pid 254995:tid 255274] [client 23.137.105.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:44.092128 2026] [security2:error] [pid 254995:tid 255271] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/brand.php"] [unique_id "al9M6P7v0rlcEGmVraFdWQAAA5U"]
[Tue Jul 21 07:41:44.097634 2026] [security2:error] [pid 254995:tid 255179] [client 20.226.60.151:59416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/kq1.php"] [unique_id "al9M6P7v0rlcEGmVraFdWgAAA1Q"]
[Tue Jul 21 07:41:44.400546 2026] [security2:error] [pid 254995:tid 255270] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/atomlib.php"] [unique_id "al9M6P7v0rlcEGmVraFdaQAAA5Q"]
[Tue Jul 21 07:41:44.432033 2026] [core:error] [pid 254995:tid 255188] [client 23.137.105.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:44.432060 2026] [core:error] [pid 254995:tid 255188] [client 23.137.105.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:44.433317 2026] [core:error] [pid 254995:tid 255143] [client 23.137.105.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:44.433334 2026] [core:error] [pid 254995:tid 255143] [client 23.137.105.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:44.600737 2026] [security2:error] [pid 254995:tid 255213] [client 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sarasantosdasilva1782312779991.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9M6P7v0rlcEGmVraFdegAAA3U"]
[Tue Jul 21 07:41:44.721253 2026] [security2:error] [pid 254995:tid 255166] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/0x.php"] [unique_id "al9M6P7v0rlcEGmVraFdfgAAA0c"]
[Tue Jul 21 07:41:44.803402 2026] [security2:error] [pid 254995:tid 255158] [client 20.226.60.151:54329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9M6P7v0rlcEGmVraFdggAAAz8"]
[Tue Jul 21 07:41:44.840637 2026] [security2:error] [pid 254995:tid 255263] [client 37.140.223.191:24915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M6P7v0rlcEGmVraFdgwAAA40"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:44.841630 2026] [security2:error] [pid 254995:tid 255260] [client 4.204.201.85:3566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/eee.php"] [unique_id "al9M6P7v0rlcEGmVraFdhAAAA4o"]
[Tue Jul 21 07:41:44.898608 2026] [security2:error] [pid 254995:tid 255200] [client 20.226.60.151:22951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/dvjul.php"] [unique_id "al9M6P7v0rlcEGmVraFdhwAAA2k"]
[Tue Jul 21 07:41:44.956363 2026] [security2:error] [pid 254995:tid 255071] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6P7v0rlcEGmVraFdiAADnEs"]
[Tue Jul 21 07:41:44.956525 2026] [security2:error] [pid 254995:tid 255278] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6P7v0rlcEGmVraFdiAADnEs"]
[Tue Jul 21 07:41:45.063410 2026] [security2:error] [pid 254995:tid 255187] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/buy.php"] [unique_id "al9M6f7v0rlcEGmVraFdjgAAA1w"]
[Tue Jul 21 07:41:45.069793 2026] [proxy:error] [pid 254995:tid 255255] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:45.069865 2026] [proxy_http:error] [pid 254995:tid 255255] [client 20.226.60.151:62313] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:45.070317 2026] [proxy:error] [pid 254995:tid 255255] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:45.070340 2026] [proxy_http:error] [pid 254995:tid 255255] [client 20.226.60.151:62313] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:45.192901 2026] [security2:error] [pid 254995:tid 255224] [client 139.167.225.182:63066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6f7v0rlcEGmVraFdkgAAA4A"]
[Tue Jul 21 07:41:45.193054 2026] [security2:error] [pid 254995:tid 255224] [client 139.167.225.182:63066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6f7v0rlcEGmVraFdkgAAA4A"]
[Tue Jul 21 07:41:45.210252 2026] [security2:error] [pid 254995:tid 255141] [client 20.220.225.223:34188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/ez.php"] [unique_id "al9M6f7v0rlcEGmVraFdlAAAAy4"]
[Tue Jul 21 07:41:45.265983 2026] [security2:error] [pid 254995:tid 255102] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M6f7v0rlcEGmVraFdmgADOmo"]
[Tue Jul 21 07:41:45.266178 2026] [security2:error] [pid 254995:tid 255153] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M6f7v0rlcEGmVraFdmgADOmo"]
[Tue Jul 21 07:41:45.397542 2026] [security2:error] [pid 254995:tid 255177] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/sx.php"] [unique_id "al9M6f7v0rlcEGmVraFdngAAA1I"]
[Tue Jul 21 07:41:45.472822 2026] [security2:error] [pid 254995:tid 255139] [client 122.179.91.63:1797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M6f7v0rlcEGmVraFdnwAAAyw"]
[Tue Jul 21 07:41:45.472954 2026] [security2:error] [pid 254995:tid 255139] [client 122.179.91.63:1797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M6f7v0rlcEGmVraFdnwAAAyw"]
[Tue Jul 21 07:41:45.737399 2026] [security2:error] [pid 254995:tid 255175] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/article.php"] [unique_id "al9M6f7v0rlcEGmVraFdqAAAA1A"]
[Tue Jul 21 07:41:45.810123 2026] [security2:error] [pid 254995:tid 255273] [client 4.204.201.85:7458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/wp-aothait.php"] [unique_id "al9M6f7v0rlcEGmVraFdrQAAA5c"]
[Tue Jul 21 07:41:45.872668 2026] [security2:error] [pid 254995:tid 255178] [client 20.226.60.151:51206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/2000.php"] [unique_id "al9M6f7v0rlcEGmVraFdrwAAA1M"]
[Tue Jul 21 07:41:45.891350 2026] [security2:error] [pid 254995:tid 255181] [client 20.226.60.151:59506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/fw/faiyy.php"] [unique_id "al9M6f7v0rlcEGmVraFdsAAAA1Y"]
[Tue Jul 21 07:41:45.999340 2026] [security2:error] [pid 254995:tid 255215] [client 20.226.60.151:23128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/biufile.php"] [unique_id "al9M6f7v0rlcEGmVraFdswAAA3c"]
[Tue Jul 21 07:41:46.037942 2026] [security2:error] [pid 254995:tid 255143] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/bootstrap.php"] [unique_id "al9M6v7v0rlcEGmVraFdtAAAAzA"]
[Tue Jul 21 07:41:46.127669 2026] [security2:error] [pid 254995:tid 255271] [client 202.143.127.214:65189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6v7v0rlcEGmVraFdtgAAA5U"]
[Tue Jul 21 07:41:46.128430 2026] [security2:error] [pid 254995:tid 255271] [client 202.143.127.214:65189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6v7v0rlcEGmVraFdtgAAA5U"]
[Tue Jul 21 07:41:46.363579 2026] [core:error] [pid 254995:tid 255095] [remote 40.77.167.77:18325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:46.363604 2026] [core:error] [pid 254995:tid 255095] [remote 40.77.167.77:18325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:46.381428 2026] [security2:error] [pid 254995:tid 255266] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/config-backup.php"] [unique_id "al9M6v7v0rlcEGmVraFdwAAAA5A"]
[Tue Jul 21 07:41:46.438010 2026] [security2:error] [pid 254995:tid 255144] [client 20.226.60.151:62230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/public/css.php"] [unique_id "al9M6v7v0rlcEGmVraFdwQAAAzE"]
[Tue Jul 21 07:41:46.547942 2026] [core:error] [pid 254995:tid 255122] [remote 40.77.167.77:18325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:46.547962 2026] [core:error] [pid 254995:tid 255122] [remote 40.77.167.77:18325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:46.672258 2026] [core:error] [pid 254995:tid 255027] [remote 40.77.167.77:18325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:46.672283 2026] [core:error] [pid 254995:tid 255027] [remote 40.77.167.77:18325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:46.685975 2026] [security2:error] [pid 254995:tid 255175] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/goods.php"] [unique_id "al9M6v7v0rlcEGmVraFdywAAA1A"]
[Tue Jul 21 07:41:46.997078 2026] [security2:error] [pid 254995:tid 255165] [client 20.226.60.151:59455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/h02ugyh.php"] [unique_id "al9M6v7v0rlcEGmVraFd2AAAA0Y"]
[Tue Jul 21 07:41:47.003575 2026] [security2:error] [pid 254995:tid 255143] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/init.php"] [unique_id "al9M6_7v0rlcEGmVraFd2wAAAzA"]
[Tue Jul 21 07:41:47.085612 2026] [security2:error] [pid 254995:tid 255271] [client 20.226.60.151:54320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9M6_7v0rlcEGmVraFd3QAAA5U"]
[Tue Jul 21 07:41:47.107316 2026] [security2:error] [pid 254995:tid 255178] [client 173.24.185.52:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M6_7v0rlcEGmVraFd3gAAA1M"]
[Tue Jul 21 07:41:47.107422 2026] [security2:error] [pid 254995:tid 255178] [client 173.24.185.52:53150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M6_7v0rlcEGmVraFd3gAAA1M"]
[Tue Jul 21 07:41:47.138387 2026] [security2:error] [pid 254995:tid 255159] [client 4.204.201.85:7483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/config.json.php"] [unique_id "al9M6_7v0rlcEGmVraFd4AAAA0A"]
[Tue Jul 21 07:41:47.218059 2026] [security2:error] [pid 254995:tid 255136] [client 20.104.96.117:30852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-css.php"] [unique_id "al9M6_7v0rlcEGmVraFd4wAAAyk"]
[Tue Jul 21 07:41:47.301448 2026] [security2:error] [pid 254995:tid 255166] [client 103.174.34.15:54202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6_7v0rlcEGmVraFd7AAAA0c"]
[Tue Jul 21 07:41:47.301573 2026] [security2:error] [pid 254995:tid 255166] [client 103.174.34.15:54202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M6_7v0rlcEGmVraFd7AAAA0c"]
[Tue Jul 21 07:41:47.388146 2026] [security2:error] [pid 254995:tid 255173] [client 20.220.225.223:11197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/fz.php"] [unique_id "al9M6_7v0rlcEGmVraFd8QAAA04"]
[Tue Jul 21 07:41:47.470961 2026] [security2:error] [pid 254995:tid 255263] [client 20.151.10.161:53575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9M6_7v0rlcEGmVraFd9gAAA40"]
[Tue Jul 21 07:41:47.545046 2026] [authz_core:error] [pid 254995:tid 255273] [client 74.249.245.134:0] AH01630: client denied by server configuration: /home4/inhous92/fortenegociosimobiliarios/php.ini
[Tue Jul 21 07:41:47.686016 2026] [security2:error] [pid 254995:tid 255268] [client 194.99.104.35:43662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9M6_7v0rlcEGmVraFd-gAAA5I"]
[Tue Jul 21 07:41:47.686139 2026] [security2:error] [pid 254995:tid 255268] [client 194.99.104.35:43662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9M6_7v0rlcEGmVraFd-gAAA5I"]
[Tue Jul 21 07:41:47.719724 2026] [security2:error] [pid 254995:tid 255162] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/settings.php"] [unique_id "al9M6_7v0rlcEGmVraFd_gAAA0M"]
[Tue Jul 21 07:41:47.754761 2026] [security2:error] [pid 254995:tid 255179] [client 172.245.102.45:38799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9M6_7v0rlcEGmVraFeAAAAA1Q"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:48.078737 2026] [security2:error] [pid 254995:tid 255125] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/g.php"] [unique_id "al9M7P7v0rlcEGmVraFeCwAAAx4"]
[Tue Jul 21 07:41:48.106783 2026] [security2:error] [pid 254995:tid 255169] [client 152.59.154.239:52453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7P7v0rlcEGmVraFeDAAAA0o"]
[Tue Jul 21 07:41:48.106905 2026] [security2:error] [pid 254995:tid 255169] [client 152.59.154.239:52453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7P7v0rlcEGmVraFeDAAAA0o"]
[Tue Jul 21 07:41:48.170032 2026] [security2:error] [pid 254995:tid 255047] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7P7v0rlcEGmVraFeDQADXjM"]
[Tue Jul 21 07:41:48.170202 2026] [security2:error] [pid 254995:tid 255189] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7P7v0rlcEGmVraFeDQADXjM"]
[Tue Jul 21 07:41:48.264627 2026] [security2:error] [pid 254995:tid 255180] [client 106.215.181.8:6648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7P7v0rlcEGmVraFeEQAAA1U"]
[Tue Jul 21 07:41:48.264743 2026] [security2:error] [pid 254995:tid 255180] [client 106.215.181.8:6648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7P7v0rlcEGmVraFeEQAAA1U"]
[Tue Jul 21 07:41:48.412046 2026] [security2:error] [pid 254995:tid 255223] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/403.php"] [unique_id "al9M7P7v0rlcEGmVraFeEwAAA38"]
[Tue Jul 21 07:41:48.541286 2026] [security2:error] [pid 254995:tid 255175] [client 20.226.60.151:23133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/av.php"] [unique_id "al9M7P7v0rlcEGmVraFeGQAAA1A"]
[Tue Jul 21 07:41:48.677009 2026] [security2:error] [pid 254995:tid 255270] [client 20.104.96.117:30460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/ho.php"] [unique_id "al9M7P7v0rlcEGmVraFeHgAAA5Q"]
[Tue Jul 21 07:41:48.705309 2026] [security2:error] [pid 254995:tid 255162] [client 20.226.60.151:56275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/122.php"] [unique_id "al9M7P7v0rlcEGmVraFeIQAAA0M"]
[Tue Jul 21 07:41:48.735889 2026] [security2:error] [pid 254995:tid 255221] [client 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fortenegociosimobiliarios.net.br"] [uri "/api.php"] [unique_id "al9M7P7v0rlcEGmVraFeIgAAA30"]
[Tue Jul 21 07:41:48.933230 2026] [security2:error] [pid 254995:tid 255279] [client 20.226.60.151:23161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/coffexium.php"] [unique_id "al9M7P7v0rlcEGmVraFeKQAAA50"]
[Tue Jul 21 07:41:48.965739 2026] [security2:error] [pid 254995:tid 255256] [client 20.226.60.151:59394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-temp.php"] [unique_id "al9M7P7v0rlcEGmVraFeLQAAA4Y"]
[Tue Jul 21 07:41:49.052271 2026] [security2:error] [pid 254995:tid 255156] [client 4.204.201.85:46057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9M7f7v0rlcEGmVraFeMAAAAz0"]
[Tue Jul 21 07:41:49.114182 2026] [security2:error] [pid 254995:tid 255146] [client 20.104.96.117:30875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/xy.php"] [unique_id "al9M7f7v0rlcEGmVraFeMgAAAzM"]
[Tue Jul 21 07:41:49.342496 2026] [security2:error] [pid 254995:tid 255265] [client 20.226.60.151:22342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/core.php"] [unique_id "al9M7f7v0rlcEGmVraFePQAAA48"]
[Tue Jul 21 07:41:49.343500 2026] [security2:error] [pid 254995:tid 255252] [client 193.36.225.102:24127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M6_7v0rlcEGmVraFd4QAAA4M"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:41:49.668785 2026] [security2:error] [pid 254995:tid 255108] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M7f7v0rlcEGmVraFeRQADf3A"]
[Tue Jul 21 07:41:49.669048 2026] [security2:error] [pid 254995:tid 255223] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M7f7v0rlcEGmVraFeRQADf3A"]
[Tue Jul 21 07:41:49.741645 2026] [security2:error] [pid 254995:tid 255106] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7f7v0rlcEGmVraFeRgADh24"]
[Tue Jul 21 07:41:49.741831 2026] [security2:error] [pid 254995:tid 255257] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M7f7v0rlcEGmVraFeRgADh24"]
[Tue Jul 21 07:41:49.921403 2026] [security2:error] [pid 254995:tid 255182] [client 117.251.86.144:47158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M7f7v0rlcEGmVraFeTQAAA1c"]
[Tue Jul 21 07:41:49.921521 2026] [security2:error] [pid 254995:tid 255182] [client 117.251.86.144:47158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M7f7v0rlcEGmVraFeTQAAA1c"]
[Tue Jul 21 07:41:49.942893 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:23148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/als.php"] [unique_id "al9M7f7v0rlcEGmVraFeTgAAA3w"]
[Tue Jul 21 07:41:49.969922 2026] [security2:error] [pid 254995:tid 255179] [client 34.1.17.177:52186] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bastarecomecar.com.br"] [uri "/index.php"] [unique_id "al9M7P7v0rlcEGmVraFeJgAAA1Q"]
[Tue Jul 21 07:41:49.974963 2026] [security2:error] [pid 254995:tid 255166] [client 34.1.17.177:38612] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bastarecomecar.com.br"] [uri "/index.php"] [unique_id "al9M7f7v0rlcEGmVraFeQQAAA0c"]
[Tue Jul 21 07:41:50.043311 2026] [security2:error] [pid 254995:tid 255224] [client 20.226.60.151:54317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/media.php"] [unique_id "al9M7v7v0rlcEGmVraFeVgAAA4A"]
[Tue Jul 21 07:41:50.228741 2026] [security2:error] [pid 254995:tid 255169] [client 4.204.201.85:46051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/k2.php"] [unique_id "al9M7v7v0rlcEGmVraFeXAAAA0o"]
[Tue Jul 21 07:41:50.288688 2026] [security2:error] [pid 254995:tid 255139] [client 34.1.17.177:52198] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bastarecomecar.com.br"] [uri "/index.php"] [unique_id "al9M7v7v0rlcEGmVraFeWwAAAyw"]
[Tue Jul 21 07:41:50.300329 2026] [security2:error] [pid 254995:tid 255218] [client 20.226.60.151:22370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/simple.php"] [unique_id "al9M7v7v0rlcEGmVraFeXQAAA3o"]
[Tue Jul 21 07:41:50.308515 2026] [security2:error] [pid 254995:tid 255269] [client 122.186.204.214:54259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M7v7v0rlcEGmVraFeXgAAA5M"]
[Tue Jul 21 07:41:50.308639 2026] [security2:error] [pid 254995:tid 255269] [client 122.186.204.214:54259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M7v7v0rlcEGmVraFeXgAAA5M"]
[Tue Jul 21 07:41:50.346280 2026] [security2:error] [pid 254995:tid 255189] [client 20.226.60.151:62237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/output.php"] [unique_id "al9M7v7v0rlcEGmVraFeYgAAA14"]
[Tue Jul 21 07:41:50.369043 2026] [security2:error] [pid 254995:tid 255131] [client 20.226.60.151:59519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-content/cong.php"] [unique_id "al9M7v7v0rlcEGmVraFeZAAAAyQ"]
[Tue Jul 21 07:41:50.393514 2026] [security2:error] [pid 254995:tid 255252] [client 20.226.60.151:56264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/mds.php"] [unique_id "al9M7v7v0rlcEGmVraFeZgAAA4M"]
[Tue Jul 21 07:41:50.562264 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:23129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/init.php"] [unique_id "al9M7v7v0rlcEGmVraFebQAAA5c"]
[Tue Jul 21 07:41:50.627035 2026] [security2:error] [pid 254995:tid 255260] [client 20.226.60.151:22380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/fpwch.php"] [unique_id "al9M7v7v0rlcEGmVraFecQAAA4o"]
[Tue Jul 21 07:41:50.646430 2026] [core:error] [pid 254995:tid 254997] [remote 52.167.144.206:52545] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:50.646455 2026] [core:error] [pid 254995:tid 254997] [remote 52.167.144.206:52545] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:50.762609 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:23135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/domvf.php"] [unique_id "al9M7v7v0rlcEGmVraFedAAAA3w"]
[Tue Jul 21 07:41:50.775093 2026] [core:error] [pid 254995:tid 255024] [remote 52.167.144.206:52545] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:50.775125 2026] [core:error] [pid 254995:tid 255024] [remote 52.167.144.206:52545] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:50.854395 2026] [security2:error] [pid 254995:tid 255268] [client 34.1.17.177:38628] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bastarecomecar.com.br"] [uri "/index.php"] [unique_id "al9M7v7v0rlcEGmVraFedwAAA5I"]
[Tue Jul 21 07:41:50.902522 2026] [core:error] [pid 254995:tid 255018] [remote 52.167.144.206:52545] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:50.902548 2026] [core:error] [pid 254995:tid 255018] [remote 52.167.144.206:52545] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:41:50.940938 2026] [security2:error] [pid 254995:tid 255270] [client 20.220.225.223:55503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/cron-tab.php"] [unique_id "al9M7v7v0rlcEGmVraFefgAAA5Q"]
[Tue Jul 21 07:41:50.961472 2026] [security2:error] [pid 254995:tid 255125] [client 122.164.127.47:52374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M7v7v0rlcEGmVraFegAAAAx4"]
[Tue Jul 21 07:41:50.961598 2026] [security2:error] [pid 254995:tid 255125] [client 122.164.127.47:52374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M7v7v0rlcEGmVraFegAAAAx4"]
[Tue Jul 21 07:41:51.069074 2026] [security2:error] [pid 254995:tid 255229] [client 20.104.96.117:30861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/loader.php"] [unique_id "al9M7_7v0rlcEGmVraFehQAAA4I"]
[Tue Jul 21 07:41:51.086657 2026] [security2:error] [pid 254995:tid 255198] [client 20.220.225.223:5292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/la.php"] [unique_id "al9M7_7v0rlcEGmVraFeiAAAA2c"]
[Tue Jul 21 07:41:51.116017 2026] [security2:error] [pid 254995:tid 255173] [client 182.8.255.181:17183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M7_7v0rlcEGmVraFeigAAA04"]
[Tue Jul 21 07:41:51.116139 2026] [security2:error] [pid 254995:tid 255173] [client 182.8.255.181:17183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M7_7v0rlcEGmVraFeigAAA04"]
[Tue Jul 21 07:41:51.397948 2026] [security2:error] [pid 254995:tid 255181] [client 20.151.10.161:12057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-blog.php"] [unique_id "al9M7_7v0rlcEGmVraFekQAAA1Y"]
[Tue Jul 21 07:41:51.448334 2026] [security2:error] [pid 254995:tid 255275] [client 20.226.60.151:23104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp.php"] [unique_id "al9M7_7v0rlcEGmVraFekgAAA5k"]
[Tue Jul 21 07:41:51.448597 2026] [security2:error] [pid 254995:tid 255183] [client 4.204.201.85:3572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/uiuvs58l.php"] [unique_id "al9M7_7v0rlcEGmVraFekwAAA1g"]
[Tue Jul 21 07:41:51.523241 2026] [security2:error] [pid 254995:tid 255147] [client 103.86.117.203:51156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M7_7v0rlcEGmVraFelQAAAzQ"]
[Tue Jul 21 07:41:51.523430 2026] [security2:error] [pid 254995:tid 255147] [client 103.86.117.203:51156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M7_7v0rlcEGmVraFelQAAAzQ"]
[Tue Jul 21 07:41:51.718745 2026] [security2:error] [pid 254995:tid 255202] [client 20.197.195.24:13644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ms-edit.php"] [unique_id "al9M7_7v0rlcEGmVraFemwAAA2s"]
[Tue Jul 21 07:41:51.856246 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:62302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-file-120.php"] [unique_id "al9M7_7v0rlcEGmVraFenwAAAx4"]
[Tue Jul 21 07:41:51.989844 2026] [security2:error] [pid 254995:tid 255131] [client 20.226.60.151:22914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/class.php"] [unique_id "al9M7_7v0rlcEGmVraFeqgAAAyQ"]
[Tue Jul 21 07:41:52.144385 2026] [security2:error] [pid 254995:tid 255222] [client 20.226.60.151:22337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/echkm.php"] [unique_id "al9M8P7v0rlcEGmVraFesgAAA34"]
[Tue Jul 21 07:41:52.362493 2026] [security2:error] [pid 254995:tid 255182] [client 20.220.225.223:34203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/fz.php"] [unique_id "al9M8P7v0rlcEGmVraFetgAAA1c"]
[Tue Jul 21 07:41:52.433581 2026] [security2:error] [pid 254995:tid 255146] [client 194.99.104.35:47274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9M8P7v0rlcEGmVraFeuAAAAzM"]
[Tue Jul 21 07:41:52.433693 2026] [security2:error] [pid 254995:tid 255146] [client 194.99.104.35:47274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9M8P7v0rlcEGmVraFeuAAAAzM"]
[Tue Jul 21 07:41:52.481584 2026] [security2:error] [pid 254995:tid 255212] [client 4.204.201.85:3561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/40p9ixjd.php"] [unique_id "al9M8P7v0rlcEGmVraFeuwAAA3Q"]
[Tue Jul 21 07:41:52.682167 2026] [proxy:error] [pid 254995:tid 255270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:52.682260 2026] [proxy_http:error] [pid 254995:tid 255270] [client 20.226.60.151:59462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:52.682869 2026] [proxy:error] [pid 254995:tid 255270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:41:52.684070 2026] [proxy_http:error] [pid 254995:tid 255270] [client 20.226.60.151:59462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:41:52.877683 2026] [security2:error] [pid 254995:tid 255183] [client 154.192.233.199:60229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8P7v0rlcEGmVraFexQAAA1g"]
[Tue Jul 21 07:41:52.877829 2026] [security2:error] [pid 254995:tid 255183] [client 154.192.233.199:60229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8P7v0rlcEGmVraFexQAAA1g"]
[Tue Jul 21 07:41:52.891870 2026] [security2:error] [pid 254995:tid 255122] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M8P7v0rlcEGmVraFeyAADP34"]
[Tue Jul 21 07:41:52.892029 2026] [security2:error] [pid 254995:tid 255158] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M8P7v0rlcEGmVraFeyAADP34"]
[Tue Jul 21 07:41:52.925370 2026] [security2:error] [pid 254995:tid 255140] [client 20.226.60.151:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/images.php"] [unique_id "al9M8P7v0rlcEGmVraFeyQAAAy0"]
[Tue Jul 21 07:41:53.050068 2026] [security2:error] [pid 254995:tid 255167] [client 20.220.225.223:32285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/koiy.php"] [unique_id "al9M8f7v0rlcEGmVraFe0AAAA0g"]
[Tue Jul 21 07:41:53.105070 2026] [security2:error] [pid 254995:tid 255175] [client 20.226.60.151:22919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/lib.php"] [unique_id "al9M8f7v0rlcEGmVraFe1QAAA1A"]
[Tue Jul 21 07:41:53.135112 2026] [security2:error] [pid 254995:tid 255153] [client 20.226.60.151:54300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/gecko.php"] [unique_id "al9M8f7v0rlcEGmVraFe1wAAAzo"]
[Tue Jul 21 07:41:53.251554 2026] [security2:error] [pid 254995:tid 255182] [client 20.226.60.151:54315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/82.php"] [unique_id "al9M8f7v0rlcEGmVraFe2gAAA1c"]
[Tue Jul 21 07:41:53.308307 2026] [security2:error] [pid 254995:tid 255156] [client 175.45.70.82:59163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.70.45.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8f7v0rlcEGmVraFe2wAAAz0"]
[Tue Jul 21 07:41:53.308442 2026] [security2:error] [pid 254995:tid 255156] [client 175.45.70.82:59163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "filtrokangen.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8f7v0rlcEGmVraFe2wAAAz0"]
[Tue Jul 21 07:41:53.311604 2026] [security2:error] [pid 254995:tid 255147] [client 20.226.60.151:54372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/admin.php"] [unique_id "al9M8f7v0rlcEGmVraFe3AAAAzQ"]
[Tue Jul 21 07:41:53.352521 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:33486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/special.php"] [unique_id "al9M8f7v0rlcEGmVraFe3QAAA3w"]
[Tue Jul 21 07:41:53.417030 2026] [security2:error] [pid 254995:tid 255194] [client 193.36.225.63:59749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9M8P7v0rlcEGmVraFetAAAA2M"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:53.491618 2026] [security2:error] [pid 254995:tid 255174] [client 20.226.60.151:22940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/login.php"] [unique_id "al9M8f7v0rlcEGmVraFe5AAAA08"]
[Tue Jul 21 07:41:53.505322 2026] [security2:error] [pid 254995:tid 255202] [client 20.226.60.151:54399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/adminner.php"] [unique_id "al9M8f7v0rlcEGmVraFe5QAAA2s"]
[Tue Jul 21 07:41:53.726485 2026] [access_compat:error] [pid 254995:tid 255189] [client 162.241.63.68:15446] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:41:53.792285 2026] [security2:error] [pid 254995:tid 255129] [client 103.106.20.201:50257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8f7v0rlcEGmVraFe8QAAAyI"]
[Tue Jul 21 07:41:53.792419 2026] [security2:error] [pid 254995:tid 255129] [client 103.106.20.201:50257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8f7v0rlcEGmVraFe8QAAAyI"]
[Tue Jul 21 07:41:53.805525 2026] [security2:error] [pid 254995:tid 255279] [client 20.151.10.161:55275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9M8f7v0rlcEGmVraFe8wAAA50"]
[Tue Jul 21 07:41:53.865440 2026] [security2:error] [pid 254995:tid 255142] [client 4.204.201.85:46061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9M8f7v0rlcEGmVraFe9gAAAy8"]
[Tue Jul 21 07:41:53.886856 2026] [security2:error] [pid 254995:tid 255132] [client 122.162.144.145:10195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M8f7v0rlcEGmVraFe9wAAAyU"]
[Tue Jul 21 07:41:53.887016 2026] [security2:error] [pid 254995:tid 255132] [client 122.162.144.145:10195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M8f7v0rlcEGmVraFe9wAAAyU"]
[Tue Jul 21 07:41:54.205755 2026] [security2:error] [pid 254995:tid 255179] [client 20.226.60.151:56284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-blink.php"] [unique_id "al9M8v7v0rlcEGmVraFfBQAAA1Q"]
[Tue Jul 21 07:41:54.270654 2026] [security2:error] [pid 254995:tid 255224] [client 20.226.60.151:59423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-includes/css/index.php"] [unique_id "al9M8v7v0rlcEGmVraFfCwAAA4A"]
[Tue Jul 21 07:41:54.270668 2026] [security2:error] [pid 254995:tid 255136] [client 20.104.96.117:30425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/spadex.php"] [unique_id "al9M8v7v0rlcEGmVraFfDAAAAyk"]
[Tue Jul 21 07:41:54.332947 2026] [security2:error] [pid 254995:tid 255174] [client 20.226.60.151:33518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/as.php"] [unique_id "al9M8v7v0rlcEGmVraFfDQAAA08"]
[Tue Jul 21 07:41:54.341060 2026] [security2:error] [pid 254995:tid 255131] [client 117.217.38.194:64207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8v7v0rlcEGmVraFfDgAAAyQ"]
[Tue Jul 21 07:41:54.341171 2026] [security2:error] [pid 254995:tid 255131] [client 117.217.38.194:64207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8v7v0rlcEGmVraFfDgAAAyQ"]
[Tue Jul 21 07:41:54.456551 2026] [security2:error] [pid 254995:tid 255218] [client 59.96.220.140:55797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M8v7v0rlcEGmVraFfFQAAA3o"]
[Tue Jul 21 07:41:54.456679 2026] [security2:error] [pid 254995:tid 255218] [client 59.96.220.140:55797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M8v7v0rlcEGmVraFfFQAAA3o"]
[Tue Jul 21 07:41:54.612543 2026] [security2:error] [pid 254995:tid 255177] [client 4.204.201.85:45959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/for.php"] [unique_id "al9M8v7v0rlcEGmVraFfGgAAA1I"]
[Tue Jul 21 07:41:55.048867 2026] [security2:error] [pid 254995:tid 255147] [client 20.226.60.151:54345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/admin.php"] [unique_id "al9M8_7v0rlcEGmVraFfJwAAAzQ"]
[Tue Jul 21 07:41:55.100891 2026] [security2:error] [pid 254995:tid 255212] [client 4.204.201.85:46054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "futurelogistica.com"] [uri "/raw.php"] [unique_id "al9M8_7v0rlcEGmVraFfKQAAA3Q"]
[Tue Jul 21 07:41:55.186627 2026] [security2:error] [pid 254995:tid 255194] [client 20.226.60.151:22378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/a2.php"] [unique_id "al9M8_7v0rlcEGmVraFfLgAAA2M"]
[Tue Jul 21 07:41:55.240333 2026] [security2:error] [pid 254995:tid 255174] [client 20.220.225.223:22485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/hp2.php"] [unique_id "al9M8_7v0rlcEGmVraFfMgAAA08"]
[Tue Jul 21 07:41:55.300046 2026] [security2:error] [pid 254995:tid 255196] [client 20.220.225.223:19278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9M8_7v0rlcEGmVraFfNgAAA2U"]
[Tue Jul 21 07:41:55.543277 2026] [security2:error] [pid 254995:tid 255198] [client 20.104.96.117:30867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/2x.php"] [unique_id "al9M8_7v0rlcEGmVraFfPAAAA2c"]
[Tue Jul 21 07:41:55.571530 2026] [security2:error] [pid 254995:tid 255152] [client 139.167.225.182:63714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfPQAAAzk"]
[Tue Jul 21 07:41:55.573435 2026] [security2:error] [pid 254995:tid 255152] [client 139.167.225.182:63714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfPQAAAzk"]
[Tue Jul 21 07:41:55.653265 2026] [security2:error] [pid 254995:tid 255195] [client 194.99.104.35:54226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfQQAAA2Q"]
[Tue Jul 21 07:41:55.653404 2026] [security2:error] [pid 254995:tid 255195] [client 194.99.104.35:54226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfQQAAA2Q"]
[Tue Jul 21 07:41:55.658240 2026] [security2:error] [pid 254995:tid 255273] [client 20.220.225.223:32273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/hp3.php"] [unique_id "al9M8_7v0rlcEGmVraFfQwAAA5c"]
[Tue Jul 21 07:41:55.818376 2026] [security2:error] [pid 254995:tid 255012] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfUQADmBA"]
[Tue Jul 21 07:41:55.818563 2026] [security2:error] [pid 254995:tid 255274] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfUQADmBA"]
[Tue Jul 21 07:41:55.823433 2026] [security2:error] [pid 254995:tid 255194] [client 20.220.225.223:11164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9M8_7v0rlcEGmVraFfUgAAA2M"]
[Tue Jul 21 07:41:55.869881 2026] [security2:error] [pid 254995:tid 255224] [client 20.226.60.151:33529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9M8_7v0rlcEGmVraFfUwAAA4A"]
[Tue Jul 21 07:41:55.976999 2026] [security2:error] [pid 254995:tid 255017] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfVAADVxU"]
[Tue Jul 21 07:41:55.977124 2026] [security2:error] [pid 254995:tid 255182] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M8_7v0rlcEGmVraFfVAADVxU"]
[Tue Jul 21 07:41:56.150440 2026] [security2:error] [pid 254995:tid 255258] [client 20.226.60.151:22935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/d61.php"] [unique_id "al9M9P7v0rlcEGmVraFfWwAAA4g"]
[Tue Jul 21 07:41:56.560823 2026] [security2:error] [pid 254995:tid 255084] [remote 45.79.123.44:58958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "voweltravel.com.br"] [uri "/wp-login.php"] [unique_id "al9M9P7v0rlcEGmVraFfYwADHlg"]
[Tue Jul 21 07:41:57.010120 2026] [security2:error] [pid 254995:tid 255221] [client 20.226.60.151:54363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/k.php"] [unique_id "al9M9f7v0rlcEGmVraFfdAAAA30"]
[Tue Jul 21 07:41:57.142840 2026] [security2:error] [pid 254995:tid 255178] [client 122.179.91.63:6880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFfeAAAA1M"]
[Tue Jul 21 07:41:57.142976 2026] [security2:error] [pid 254995:tid 255178] [client 122.179.91.63:6880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFfeAAAA1M"]
[Tue Jul 21 07:41:57.284514 2026] [security2:error] [pid 254995:tid 255259] [client 74.7.228.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.lunarium.tec.br"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "al9M9f7v0rlcEGmVraFffwADiTs"]
[Tue Jul 21 07:41:57.354180 2026] [security2:error] [pid 254995:tid 255181] [client 202.143.127.214:49241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFfhgAAA1Y"]
[Tue Jul 21 07:41:57.354297 2026] [security2:error] [pid 254995:tid 255181] [client 202.143.127.214:49241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFfhgAAA1Y"]
[Tue Jul 21 07:41:57.374835 2026] [security2:error] [pid 254995:tid 255142] [client 20.151.10.161:53626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/adminfuns.php"] [unique_id "al9M9f7v0rlcEGmVraFfiQAAAy8"]
[Tue Jul 21 07:41:57.648769 2026] [security2:error] [pid 254995:tid 255270] [client 20.226.60.151:59443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/jj.php"] [unique_id "al9M9f7v0rlcEGmVraFfjAAAA5Q"]
[Tue Jul 21 07:41:57.668568 2026] [security2:error] [pid 254995:tid 255215] [client 173.24.185.52:53627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFfjQAAA3c"]
[Tue Jul 21 07:41:57.668710 2026] [security2:error] [pid 254995:tid 255215] [client 173.24.185.52:53627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFfjQAAA3c"]
[Tue Jul 21 07:41:57.699842 2026] [security2:error] [pid 254995:tid 255204] [client 20.226.60.151:62219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/w1px.php"] [unique_id "al9M9f7v0rlcEGmVraFfjgAAA20"]
[Tue Jul 21 07:41:57.914878 2026] [security2:error] [pid 254995:tid 255131] [client 103.174.34.15:54689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFflQAAAyQ"]
[Tue Jul 21 07:41:57.915031 2026] [security2:error] [pid 254995:tid 255131] [client 103.174.34.15:54689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9f7v0rlcEGmVraFflQAAAyQ"]
[Tue Jul 21 07:41:57.927957 2026] [security2:error] [pid 254995:tid 255169] [client 20.220.225.223:32298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/aa1.php"] [unique_id "al9M9f7v0rlcEGmVraFfmQAAA0o"]
[Tue Jul 21 07:41:58.077528 2026] [security2:error] [pid 254995:tid 255130] [client 20.226.60.151:62255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/yawa.php"] [unique_id "al9M9v7v0rlcEGmVraFfnwAAAyM"]
[Tue Jul 21 07:41:58.112420 2026] [security2:error] [pid 254995:tid 255146] [client 20.226.60.151:33498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/js.php"] [unique_id "al9M9v7v0rlcEGmVraFfoAAAAzM"]
[Tue Jul 21 07:41:58.149220 2026] [security2:error] [pid 254995:tid 255267] [client 172.245.102.46:45589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9M9v7v0rlcEGmVraFfogAAA5E"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:41:58.167475 2026] [security2:error] [pid 254995:tid 255125] [client 45.8.19.184:28273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9M9v7v0rlcEGmVraFfpAAAAx4"]
[Tue Jul 21 07:41:58.168151 2026] [security2:error] [pid 254995:tid 255202] [client 45.8.19.190:53169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9M9v7v0rlcEGmVraFfowAAA2s"]
[Tue Jul 21 07:41:58.263104 2026] [security2:error] [pid 254995:tid 255188] [client 20.226.60.151:51235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/zc-208.php"] [unique_id "al9M9v7v0rlcEGmVraFfrAAAA10"]
[Tue Jul 21 07:41:58.284767 2026] [security2:error] [pid 254995:tid 255222] [client 20.220.225.223:34242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9M9v7v0rlcEGmVraFfsQAAA34"]
[Tue Jul 21 07:41:58.512952 2026] [security2:error] [pid 254995:tid 255162] [client 20.226.60.151:61952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/blurbs.php"] [unique_id "al9M9v7v0rlcEGmVraFfuwAAA0M"]
[Tue Jul 21 07:41:58.620289 2026] [security2:error] [pid 254995:tid 255174] [client 20.226.60.151:62299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/core.php"] [unique_id "al9M9v7v0rlcEGmVraFfwgAAA08"]
[Tue Jul 21 07:41:58.703370 2026] [security2:error] [pid 254995:tid 255183] [client 20.226.60.151:22969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/info.php"] [unique_id "al9M9v7v0rlcEGmVraFfxwAAA1g"]
[Tue Jul 21 07:41:58.969534 2026] [security2:error] [pid 254995:tid 255189] [client 20.220.225.223:19297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/inso.php"] [unique_id "al9M9v7v0rlcEGmVraFf0gAAA14"]
[Tue Jul 21 07:41:59.066599 2026] [core:alert] [pid 254995:tid 255193] [client 57.141.18.42:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:41:59.080696 2026] [security2:error] [pid 254995:tid 255209] [client 106.215.181.8:28639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9_7v0rlcEGmVraFf2QAAA3E"]
[Tue Jul 21 07:41:59.080782 2026] [security2:error] [pid 254995:tid 255209] [client 106.215.181.8:28639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9_7v0rlcEGmVraFf2QAAA3E"]
[Tue Jul 21 07:41:59.154112 2026] [security2:error] [pid 254995:tid 255217] [client 152.59.154.239:52941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9_7v0rlcEGmVraFf3QAAA3k"]
[Tue Jul 21 07:41:59.154246 2026] [security2:error] [pid 254995:tid 255217] [client 152.59.154.239:52941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M9_7v0rlcEGmVraFf3QAAA3k"]
[Tue Jul 21 07:41:59.223119 2026] [security2:error] [pid 254995:tid 255204] [client 20.104.96.117:30864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/ctex1.php"] [unique_id "al9M9_7v0rlcEGmVraFf3wAAA20"]
[Tue Jul 21 07:41:59.380717 2026] [security2:error] [pid 254995:tid 255273] [client 20.226.60.151:54339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/bajah.php"] [unique_id "al9M9_7v0rlcEGmVraFf6AAAA5c"]
[Tue Jul 21 07:42:00.120876 2026] [core:crit] [pid 254995:tid 255058] (13)Permission denied: [remote 146.70.194.220:0] AH00529: /home1/deesmo24/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home1/deesmo24/public_html/cgi-bin/' is executable
[Tue Jul 21 07:42:00.319427 2026] [security2:error] [pid 254995:tid 255016] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgBAADSBQ"]
[Tue Jul 21 07:42:00.319878 2026] [security2:error] [pid 254995:tid 255167] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgBAADSBQ"]
[Tue Jul 21 07:42:00.373582 2026] [security2:error] [pid 254995:tid 255088] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-P7v0rlcEGmVraFgCAADUFw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:00.380609 2026] [security2:error] [pid 254995:tid 255108] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-P7v0rlcEGmVraFgCQADInA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:00.385579 2026] [security2:error] [pid 254995:tid 255100] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-P7v0rlcEGmVraFgCgADI2g"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:00.392810 2026] [security2:error] [pid 254995:tid 255257] [client 20.151.10.161:53610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/goods.php"] [unique_id "al9M-P7v0rlcEGmVraFgCwAAA4c"]
[Tue Jul 21 07:42:00.485583 2026] [security2:error] [pid 254995:tid 255006] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgEgADNAo"]
[Tue Jul 21 07:42:00.485728 2026] [security2:error] [pid 254995:tid 255147] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgEgADNAo"]
[Tue Jul 21 07:42:00.718097 2026] [security2:error] [pid 254995:tid 254997] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-P7v0rlcEGmVraFgGwADeQE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:00.721696 2026] [security2:error] [pid 254995:tid 255229] [client 117.251.86.144:42586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgHAAAA4I"]
[Tue Jul 21 07:42:00.721831 2026] [security2:error] [pid 254995:tid 255229] [client 117.251.86.144:42586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgHAAAA4I"]
[Tue Jul 21 07:42:00.745248 2026] [security2:error] [pid 254995:tid 255092] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-P7v0rlcEGmVraFgHQADUmA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:00.752097 2026] [security2:error] [pid 254995:tid 255084] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-P7v0rlcEGmVraFgHgADk1g"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:00.806982 2026] [security2:error] [pid 254995:tid 255212] [client 20.226.60.151:54285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/a.php"] [unique_id "al9M-P7v0rlcEGmVraFgIAAAA3Q"]
[Tue Jul 21 07:42:00.866648 2026] [security2:error] [pid 254995:tid 255211] [client 20.226.60.151:59436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al9M-P7v0rlcEGmVraFgJQAAA3M"]
[Tue Jul 21 07:42:00.952582 2026] [security2:error] [pid 254995:tid 255224] [client 122.186.204.214:54788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgKQAAA4A"]
[Tue Jul 21 07:42:00.952727 2026] [security2:error] [pid 254995:tid 255224] [client 122.186.204.214:54788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M-P7v0rlcEGmVraFgKQAAA4A"]
[Tue Jul 21 07:42:01.104488 2026] [security2:error] [pid 254995:tid 255071] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-f7v0rlcEGmVraFgLwADWUs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:01.108314 2026] [security2:error] [pid 254995:tid 255082] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-f7v0rlcEGmVraFgMAADhFY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:01.371796 2026] [security2:error] [pid 254995:tid 255012] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-P7v0rlcEGmVraFgBwADKRA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:01.456255 2026] [security2:error] [pid 254995:tid 255089] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-f7v0rlcEGmVraFgOwADZF0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:01.524462 2026] [security2:error] [pid 254995:tid 255205] [client 122.164.127.47:52938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M-f7v0rlcEGmVraFgPwAAA24"]
[Tue Jul 21 07:42:01.524561 2026] [security2:error] [pid 254995:tid 255205] [client 122.164.127.47:52938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9M-f7v0rlcEGmVraFgPwAAA24"]
[Tue Jul 21 07:42:01.543627 2026] [security2:error] [pid 254995:tid 255215] [client 20.220.225.223:5295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/inso.php"] [unique_id "al9M-f7v0rlcEGmVraFgQAAAA3c"]
[Tue Jul 21 07:42:01.605037 2026] [security2:error] [pid 254995:tid 255156] [client 182.8.255.181:21085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M-f7v0rlcEGmVraFgQgAAAz0"]
[Tue Jul 21 07:42:01.605160 2026] [security2:error] [pid 254995:tid 255156] [client 182.8.255.181:21085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9M-f7v0rlcEGmVraFgQgAAAz0"]
[Tue Jul 21 07:42:01.707182 2026] [security2:error] [pid 254995:tid 255081] [remote 188.166.248.216:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.248.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9M-f7v0rlcEGmVraFgRQADlFU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:42:01.730415 2026] [security2:error] [pid 254995:tid 255167] [client 20.226.60.151:62314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/19.php"] [unique_id "al9M-f7v0rlcEGmVraFgRgAAA0g"]
[Tue Jul 21 07:42:01.747277 2026] [security2:error] [pid 254995:tid 255194] [client 20.197.195.24:44699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/cgi-bin/index.php"] [unique_id "al9M-f7v0rlcEGmVraFgSAAAA2M"]
[Tue Jul 21 07:42:02.003408 2026] [security2:error] [pid 254995:tid 255273] [client 103.86.117.203:51852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M-v7v0rlcEGmVraFgegAAA5c"]
[Tue Jul 21 07:42:02.003603 2026] [security2:error] [pid 254995:tid 255273] [client 103.86.117.203:51852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9M-v7v0rlcEGmVraFgegAAA5c"]
[Tue Jul 21 07:42:02.141863 2026] [security2:error] [pid 254995:tid 255193] [client 20.104.96.117:30462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/edorxrr.php"] [unique_id "al9M-v7v0rlcEGmVraFgfwAAA2I"]
[Tue Jul 21 07:42:02.187972 2026] [security2:error] [pid 254995:tid 255189] [client 194.99.104.35:56454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9M-v7v0rlcEGmVraFggQAAA14"]
[Tue Jul 21 07:42:02.188133 2026] [security2:error] [pid 254995:tid 255189] [client 194.99.104.35:56454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9M-v7v0rlcEGmVraFggQAAA14"]
[Tue Jul 21 07:42:02.205141 2026] [security2:error] [pid 254995:tid 255143] [client 20.220.225.223:31714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/acew67.php"] [unique_id "al9M-v7v0rlcEGmVraFgggAAAzA"]
[Tue Jul 21 07:42:02.430428 2026] [security2:error] [pid 254995:tid 255160] [client 154.192.233.199:60443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M-v7v0rlcEGmVraFghQAAA0E"]
[Tue Jul 21 07:42:02.430535 2026] [security2:error] [pid 254995:tid 255160] [client 154.192.233.199:60443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M-v7v0rlcEGmVraFghQAAA0E"]
[Tue Jul 21 07:42:02.454069 2026] [security2:error] [pid 254995:tid 255219] [client 20.151.10.161:12059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ms-edit.php"] [unique_id "al9M-v7v0rlcEGmVraFgiAAAA3s"]
[Tue Jul 21 07:42:02.723614 2026] [security2:error] [pid 254995:tid 255268] [client 172.245.102.42:42811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9M-v7v0rlcEGmVraFgjgAAA5I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:02.725369 2026] [security2:error] [pid 254995:tid 255277] [client 20.226.60.151:59415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/txets.php"] [unique_id "al9M-v7v0rlcEGmVraFglQAAA5s"]
[Tue Jul 21 07:42:03.017027 2026] [security2:error] [pid 254995:tid 255197] [client 20.226.60.151:22395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/11.php"] [unique_id "al9M-_7v0rlcEGmVraFgpAAAA2Y"]
[Tue Jul 21 07:42:03.051706 2026] [security2:error] [pid 254995:tid 255214] [client 74.7.244.30:54476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "porondeeuestive.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9M-_7v0rlcEGmVraFgqAADdhw"]
[Tue Jul 21 07:42:03.063435 2026] [security2:error] [pid 254995:tid 255222] [client 37.140.223.156:24713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M-_7v0rlcEGmVraFgqgAAA34"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:03.088623 2026] [security2:error] [pid 254995:tid 255173] [client 114.119.152.161:45375] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "insp1.com.br"] [uri "/irma-benigna/"] [unique_id "al9M-_7v0rlcEGmVraFgrAAAA04"], referer: https://www.insp1.com.br/robotica-1?lightbox=dataItem-jxz3k2ys
[Tue Jul 21 07:42:03.208994 2026] [security2:error] [pid 254995:tid 255204] [client 65.21.232.200:14243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.232.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-comments-post.php"] [unique_id "al9M-f7v0rlcEGmVraFgMQAAA20"], referer: https://valloratoodo.com/hello-world/#comment-7855
[Tue Jul 21 07:42:03.209159 2026] [security2:error] [pid 254995:tid 255204] [client 65.21.232.200:14243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "valloratoodo.com"] [uri "/wp-comments-post.php"] [unique_id "al9M-f7v0rlcEGmVraFgMQAAA20"], referer: https://valloratoodo.com/hello-world/#comment-7855
[Tue Jul 21 07:42:03.224591 2026] [security2:error] [pid 254995:tid 255185] [client 20.151.10.161:55274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/222.php"] [unique_id "al9M-_7v0rlcEGmVraFgsQAAA1o"]
[Tue Jul 21 07:42:03.420793 2026] [security2:error] [pid 254995:tid 255257] [client 20.220.225.223:22482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/bscclapb.php"] [unique_id "al9M-_7v0rlcEGmVraFgtwAAA4c"]
[Tue Jul 21 07:42:03.434122 2026] [security2:error] [pid 254995:tid 255018] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M-_7v0rlcEGmVraFgugADYRY"]
[Tue Jul 21 07:42:03.434249 2026] [security2:error] [pid 254995:tid 255192] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9M-_7v0rlcEGmVraFgugADYRY"]
[Tue Jul 21 07:42:03.435505 2026] [core:alert] [pid 254995:tid 255130] [client 35.196.36.160:0] /home1/ofic8899/quietum-plus.tryhealth.shop/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:42:03.447712 2026] [security2:error] [pid 254995:tid 255196] [client 20.226.60.151:54370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/edit.php"] [unique_id "al9M-_7v0rlcEGmVraFgvAAAA2U"]
[Tue Jul 21 07:42:03.459909 2026] [security2:error] [pid 254995:tid 255268] [client 20.226.60.151:62240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/inc.php"] [unique_id "al9M-_7v0rlcEGmVraFgvQAAA5I"]
[Tue Jul 21 07:42:03.860225 2026] [core:alert] [pid 254995:tid 255222] [client 35.196.36.160:0] /home1/ofic8899/quietum-plus.tryhealth.shop/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:42:04.196017 2026] [security2:error] [pid 254995:tid 255260] [client 190.92.174.183:58542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg2wAAA4o"]
[Tue Jul 21 07:42:04.196117 2026] [security2:error] [pid 254995:tid 255260] [client 190.92.174.183:58542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg2wAAA4o"]
[Tue Jul 21 07:42:04.287184 2026] [core:alert] [pid 254995:tid 255266] [client 35.196.36.160:0] /home1/ofic8899/quietum-plus.tryhealth.shop/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:42:04.569487 2026] [security2:error] [pid 254995:tid 255229] [client 103.106.20.201:50836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg6QAAA4I"]
[Tue Jul 21 07:42:04.569613 2026] [security2:error] [pid 254995:tid 255229] [client 103.106.20.201:50836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg6QAAA4I"]
[Tue Jul 21 07:42:04.691825 2026] [security2:error] [pid 254995:tid 255134] [client 35.196.36.160:58380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.36.196.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "quietum-plus.tryhealth.shop"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg7gAAAyc"]
[Tue Jul 21 07:42:04.715783 2026] [security2:error] [pid 254995:tid 255193] [client 20.226.60.151:54390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/hosty.php"] [unique_id "al9M_P7v0rlcEGmVraFg8AAAA2I"]
[Tue Jul 21 07:42:04.719097 2026] [security2:error] [pid 254995:tid 255217] [client 122.162.144.145:21954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg8QAAA3k"]
[Tue Jul 21 07:42:04.719220 2026] [security2:error] [pid 254995:tid 255217] [client 122.162.144.145:21954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg8QAAA3k"]
[Tue Jul 21 07:42:04.822675 2026] [security2:error] [pid 254995:tid 255224] [client 117.217.38.194:64690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg9gAAA4A"]
[Tue Jul 21 07:42:04.822827 2026] [security2:error] [pid 254995:tid 255224] [client 117.217.38.194:64690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg9gAAA4A"]
[Tue Jul 21 07:42:04.847558 2026] [security2:error] [pid 254995:tid 255212] [client 184.75.223.211:34920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg9wAAA3Q"]
[Tue Jul 21 07:42:04.847679 2026] [security2:error] [pid 254995:tid 255212] [client 184.75.223.211:34920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9M_P7v0rlcEGmVraFg9wAAA3Q"]
[Tue Jul 21 07:42:04.952014 2026] [security2:error] [pid 254995:tid 255162] [client 35.196.36.160:64347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9M_P7v0rlcEGmVraFg-QAAA0M"]
[Tue Jul 21 07:42:05.048749 2026] [security2:error] [pid 254995:tid 255252] [client 20.151.10.161:55277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9M_f7v0rlcEGmVraFg-wAAA4M"]
[Tue Jul 21 07:42:05.164619 2026] [security2:error] [pid 254995:tid 255222] [client 190.92.174.183:58544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_f7v0rlcEGmVraFhAwAAA34"]
[Tue Jul 21 07:42:05.164770 2026] [security2:error] [pid 254995:tid 255222] [client 190.92.174.183:58544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_f7v0rlcEGmVraFhAwAAA34"]
[Tue Jul 21 07:42:05.205133 2026] [security2:error] [pid 254995:tid 255257] [client 35.196.36.160:54319] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9M_f7v0rlcEGmVraFhBQAAA4c"]
[Tue Jul 21 07:42:05.370193 2026] [security2:error] [pid 254995:tid 255270] [client 20.220.225.223:11162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/wpx.php"] [unique_id "al9M_f7v0rlcEGmVraFhCAAAA5Q"]
[Tue Jul 21 07:42:05.381808 2026] [security2:error] [pid 254995:tid 255254] [client 20.226.60.151:62296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9M_f7v0rlcEGmVraFhCQAAA4Q"]
[Tue Jul 21 07:42:05.428052 2026] [security2:error] [pid 254995:tid 255142] [client 20.226.60.151:56239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/sid4.php"] [unique_id "al9M_f7v0rlcEGmVraFhCgAAAy8"]
[Tue Jul 21 07:42:05.484898 2026] [security2:error] [pid 254995:tid 255181] [client 20.226.60.151:59495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/dex.php"] [unique_id "al9M_f7v0rlcEGmVraFhDAAAA1Y"]
[Tue Jul 21 07:42:05.514366 2026] [security2:error] [pid 254995:tid 255166] [client 35.196.36.160:49223] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9M_f7v0rlcEGmVraFhDQAAA0c"]
[Tue Jul 21 07:42:05.785013 2026] [security2:error] [pid 254995:tid 255202] [client 35.196.36.160:61752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9M_f7v0rlcEGmVraFhGQAAA2s"]
[Tue Jul 21 07:42:06.043660 2026] [security2:error] [pid 254995:tid 255142] [client 35.196.36.160:64192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9M_v7v0rlcEGmVraFhIwAAAy8"]
[Tue Jul 21 07:42:06.064910 2026] [security2:error] [pid 254995:tid 255184] [client 20.226.60.151:54397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/k.php"] [unique_id "al9M_v7v0rlcEGmVraFhJAAAA1k"]
[Tue Jul 21 07:42:06.103559 2026] [security2:error] [pid 254995:tid 255229] [client 20.226.60.151:22659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/v2.php"] [unique_id "al9M_v7v0rlcEGmVraFhJQAAA4I"]
[Tue Jul 21 07:42:06.320846 2026] [security2:error] [pid 254995:tid 255147] [client 139.167.225.182:64358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhNgAAAzQ"]
[Tue Jul 21 07:42:06.320942 2026] [security2:error] [pid 254995:tid 255147] [client 139.167.225.182:64358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhNgAAAzQ"]
[Tue Jul 21 07:42:06.411976 2026] [security2:error] [pid 254995:tid 255138] [client 35.196.36.160:51087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9M_v7v0rlcEGmVraFhOwAAAys"]
[Tue Jul 21 07:42:06.446108 2026] [security2:error] [pid 254995:tid 255188] [client 136.144.33.111:43109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9M_v7v0rlcEGmVraFhPAAAA10"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:06.615440 2026] [security2:error] [pid 254995:tid 255075] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhPgADa08"]
[Tue Jul 21 07:42:06.615625 2026] [security2:error] [pid 254995:tid 255202] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhPgADa08"]
[Tue Jul 21 07:42:06.654648 2026] [security2:error] [pid 254995:tid 255033] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhPwADYSU"]
[Tue Jul 21 07:42:06.654780 2026] [security2:error] [pid 254995:tid 255192] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhPwADYSU"]
[Tue Jul 21 07:42:06.655306 2026] [security2:error] [pid 254995:tid 255209] [client 20.226.60.151:62262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9M_v7v0rlcEGmVraFhQAAAA3E"]
[Tue Jul 21 07:42:06.662879 2026] [security2:error] [pid 254995:tid 255125] [client 59.96.220.140:56296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhQgAAAx4"]
[Tue Jul 21 07:42:06.662960 2026] [security2:error] [pid 254995:tid 255125] [client 59.96.220.140:56296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhQgAAAx4"]
[Tue Jul 21 07:42:06.698455 2026] [security2:error] [pid 254995:tid 255181] [client 35.196.36.160:55733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9M_v7v0rlcEGmVraFhRwAAA1Y"]
[Tue Jul 21 07:42:06.808575 2026] [security2:error] [pid 254995:tid 255126] [client 190.92.174.183:58558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhUgAAAx8"]
[Tue Jul 21 07:42:06.808668 2026] [security2:error] [pid 254995:tid 255126] [client 190.92.174.183:58558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9M_v7v0rlcEGmVraFhUgAAAx8"]
[Tue Jul 21 07:42:07.006722 2026] [security2:error] [pid 254995:tid 255154] [client 35.196.36.160:49307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9M__7v0rlcEGmVraFhWwAAAzs"]
[Tue Jul 21 07:42:07.264866 2026] [security2:error] [pid 254995:tid 255279] [client 35.196.36.160:63065] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9M__7v0rlcEGmVraFhaAAAA50"]
[Tue Jul 21 07:42:07.353936 2026] [security2:error] [pid 254995:tid 255127] [client 20.151.10.161:53584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9M__7v0rlcEGmVraFhawAAAyA"]
[Tue Jul 21 07:42:07.460053 2026] [security2:error] [pid 254995:tid 255166] [client 20.226.60.151:54385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/aaa.php"] [unique_id "al9M__7v0rlcEGmVraFhbgAAA0c"]
[Tue Jul 21 07:42:07.508677 2026] [security2:error] [pid 254995:tid 255169] [client 20.104.96.117:30417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/miru1.php"] [unique_id "al9M__7v0rlcEGmVraFhcAAAA0o"]
[Tue Jul 21 07:42:07.511787 2026] [security2:error] [pid 254995:tid 255152] [client 35.196.36.160:53347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9M__7v0rlcEGmVraFhcQAAAzk"]
[Tue Jul 21 07:42:07.765165 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:22960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/panel.php"] [unique_id "al9M__7v0rlcEGmVraFhgAAAA3w"]
[Tue Jul 21 07:42:07.802946 2026] [security2:error] [pid 254995:tid 255194] [client 35.196.36.160:63296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "quietum-plus.tryhealth.shop"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9M__7v0rlcEGmVraFhgwAAA2M"]
[Tue Jul 21 07:42:07.966724 2026] [security2:error] [pid 254995:tid 255199] [client 190.92.174.183:58566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9M__7v0rlcEGmVraFhiAAAA2g"]
[Tue Jul 21 07:42:07.966833 2026] [security2:error] [pid 254995:tid 255199] [client 190.92.174.183:58566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9M__7v0rlcEGmVraFhiAAAA2g"]
[Tue Jul 21 07:42:07.982088 2026] [security2:error] [pid 254995:tid 255156] [client 122.179.91.63:27808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M__7v0rlcEGmVraFhiQAAAz0"]
[Tue Jul 21 07:42:07.982299 2026] [security2:error] [pid 254995:tid 255156] [client 122.179.91.63:27808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9M__7v0rlcEGmVraFhiQAAAz0"]
[Tue Jul 21 07:42:08.272559 2026] [security2:error] [pid 254995:tid 255192] [client 173.24.185.52:54100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NAP7v0rlcEGmVraFhvAAAA2E"]
[Tue Jul 21 07:42:08.272675 2026] [security2:error] [pid 254995:tid 255192] [client 173.24.185.52:54100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NAP7v0rlcEGmVraFhvAAAA2E"]
[Tue Jul 21 07:42:08.401877 2026] [security2:error] [pid 254995:tid 255220] [client 20.226.60.151:62279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ss.php"] [unique_id "al9NAP7v0rlcEGmVraFh0AAAA3w"]
[Tue Jul 21 07:42:08.478318 2026] [security2:error] [pid 254995:tid 255229] [client 37.140.223.118:60221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9M__7v0rlcEGmVraFhbwAAA4I"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:08.597426 2026] [security2:error] [pid 254995:tid 255140] [client 202.143.127.214:49679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAP7v0rlcEGmVraFh1gAAAy0"]
[Tue Jul 21 07:42:08.597570 2026] [security2:error] [pid 254995:tid 255140] [client 202.143.127.214:49679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAP7v0rlcEGmVraFh1gAAAy0"]
[Tue Jul 21 07:42:08.665837 2026] [autoindex:error] [pid 254995:tid 255129] [client 20.197.195.24:44709] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:08.675443 2026] [security2:error] [pid 254995:tid 255274] [client 20.197.195.24:44709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/BDKR28WP.php"] [unique_id "al9NAP7v0rlcEGmVraFh2AAAA5g"]
[Tue Jul 21 07:42:08.807141 2026] [security2:error] [pid 254995:tid 255200] [client 103.174.34.15:55174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAP7v0rlcEGmVraFh4gAAA2k"]
[Tue Jul 21 07:42:08.807253 2026] [security2:error] [pid 254995:tid 255200] [client 103.174.34.15:55174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAP7v0rlcEGmVraFh4gAAA2k"]
[Tue Jul 21 07:42:09.076994 2026] [security2:error] [pid 254995:tid 255153] [client 190.92.174.183:58576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "al9NAf7v0rlcEGmVraFh6gAAAzo"]
[Tue Jul 21 07:42:09.077110 2026] [security2:error] [pid 254995:tid 255153] [client 190.92.174.183:58576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "al9NAf7v0rlcEGmVraFh6gAAAzo"]
[Tue Jul 21 07:42:09.115491 2026] [security2:error] [pid 254995:tid 255183] [client 20.226.60.151:59508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/xpwer1.php"] [unique_id "al9NAf7v0rlcEGmVraFh7QAAA1g"]
[Tue Jul 21 07:42:09.126968 2026] [autoindex:error] [pid 254995:tid 255277] [client 20.226.60.151:0] AH01276: Cannot serve directory /home3/vivia357/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:09.137319 2026] [security2:error] [pid 254995:tid 255143] [client 20.226.60.151:56299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wmore1.php"] [unique_id "al9NAf7v0rlcEGmVraFh8AAAAzA"]
[Tue Jul 21 07:42:09.412745 2026] [security2:error] [pid 254995:tid 255146] [client 20.226.60.151:22352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/dex.php"] [unique_id "al9NAf7v0rlcEGmVraFh_gAAAzM"]
[Tue Jul 21 07:42:09.659868 2026] [security2:error] [pid 254995:tid 255129] [client 20.226.60.151:54318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file5.php"] [unique_id "al9NAf7v0rlcEGmVraFiAQAAAyI"]
[Tue Jul 21 07:42:09.751252 2026] [autoindex:error] [pid 254995:tid 255202] [client 172.252.54.73:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:09.796422 2026] [security2:error] [pid 254995:tid 255192] [client 106.215.181.8:5840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAf7v0rlcEGmVraFiDwAAA2E"]
[Tue Jul 21 07:42:09.796530 2026] [security2:error] [pid 254995:tid 255192] [client 106.215.181.8:5840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAf7v0rlcEGmVraFiDwAAA2E"]
[Tue Jul 21 07:42:10.021425 2026] [security2:error] [pid 254995:tid 255199] [client 190.92.174.183:58586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiGgAAA2g"]
[Tue Jul 21 07:42:10.021525 2026] [security2:error] [pid 254995:tid 255199] [client 190.92.174.183:58586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiGgAAA2g"]
[Tue Jul 21 07:42:10.289567 2026] [security2:error] [pid 254995:tid 255179] [client 20.151.10.161:11721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp.php"] [unique_id "al9NAv7v0rlcEGmVraFiHQAAA1Q"]
[Tue Jul 21 07:42:10.298572 2026] [security2:error] [pid 254995:tid 255252] [client 152.59.154.239:53422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiHgAAA4M"]
[Tue Jul 21 07:42:10.298691 2026] [security2:error] [pid 254995:tid 255252] [client 152.59.154.239:53422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiHgAAA4M"]
[Tue Jul 21 07:42:10.384857 2026] [security2:error] [pid 254995:tid 255042] [remote 5.252.52.249:52402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aprendizadosemlimites.store"] [uri "/wp-login.php"] [unique_id "al9NAv7v0rlcEGmVraFiKAADPC4"]
[Tue Jul 21 07:42:10.566827 2026] [autoindex:error] [pid 254995:tid 255139] [client 20.197.195.24:44711] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:10.584685 2026] [authz_core:error] [pid 254995:tid 255156] [client 20.197.195.24:44711] AH01630: client denied by server configuration: /home2/ren85318/public_html/wp-content/uploads/index.php
[Tue Jul 21 07:42:10.593475 2026] [security2:error] [pid 254995:tid 255222] [client 20.197.195.24:44711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/abcd.php"] [unique_id "al9NAv7v0rlcEGmVraFiOwAAA34"]
[Tue Jul 21 07:42:10.825091 2026] [security2:error] [pid 254995:tid 255162] [client 20.226.60.151:62254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/min.php"] [unique_id "al9NAv7v0rlcEGmVraFiQgAAA0M"]
[Tue Jul 21 07:42:10.862659 2026] [security2:error] [pid 254995:tid 255211] [client 20.226.60.151:56212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/solo1.php"] [unique_id "al9NAv7v0rlcEGmVraFiRAAAA3M"]
[Tue Jul 21 07:42:10.883248 2026] [security2:error] [pid 254995:tid 255164] [client 74.7.228.51:53206] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "guiapleno.com"] [uri "/robots.txt"] [unique_id "al9NAv7v0rlcEGmVraFiRQADRXQ"]
[Tue Jul 21 07:42:10.918764 2026] [security2:error] [pid 254995:tid 255277] [client 128.127.105.184:47210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9NAf7v0rlcEGmVraFiFgAAA5s"]
[Tue Jul 21 07:42:10.918872 2026] [security2:error] [pid 254995:tid 255277] [client 128.127.105.184:47210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9NAf7v0rlcEGmVraFiFgAAA5s"]
[Tue Jul 21 07:42:10.937543 2026] [security2:error] [pid 254995:tid 255117] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiTAADZHk"]
[Tue Jul 21 07:42:10.937693 2026] [security2:error] [pid 254995:tid 255195] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiTAADZHk"]
[Tue Jul 21 07:42:10.984741 2026] [security2:error] [pid 254995:tid 255202] [client 62.102.148.187:35308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiUAAAA2s"]
[Tue Jul 21 07:42:10.984839 2026] [security2:error] [pid 254995:tid 255202] [client 62.102.148.187:35308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NAv7v0rlcEGmVraFiUAAAA2s"]
[Tue Jul 21 07:42:11.048539 2026] [security2:error] [pid 254995:tid 255104] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFiUwADaGw"]
[Tue Jul 21 07:42:11.048719 2026] [security2:error] [pid 254995:tid 255199] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFiUwADaGw"]
[Tue Jul 21 07:42:11.054609 2026] [security2:error] [pid 254995:tid 255171] [client 74.7.228.51:53206] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "guiapleno.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al9NA_7v0rlcEGmVraFiUgADTF0"], referer: https://guiapleno.com/robots.txt
[Tue Jul 21 07:42:11.108394 2026] [security2:error] [pid 254995:tid 255149] [client 45.146.55.214:22203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lumerah.com.br"] [uri "/wp-login.php"] [unique_id "al9NA_7v0rlcEGmVraFiVgAAAzY"]
[Tue Jul 21 07:42:11.114010 2026] [security2:error] [pid 254995:tid 255143] [client 190.92.174.183:58590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFiVwAAAzA"]
[Tue Jul 21 07:42:11.114122 2026] [security2:error] [pid 254995:tid 255143] [client 190.92.174.183:58590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFiVwAAAzA"]
[Tue Jul 21 07:42:11.160946 2026] [security2:error] [pid 254995:tid 255260] [client 20.226.60.151:22391] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cavilhaslufra.com.br"] [uri "/1.php"] [unique_id "al9NA_7v0rlcEGmVraFiWQAAA4o"]
[Tue Jul 21 07:42:11.161055 2026] [security2:error] [pid 254995:tid 255260] [client 20.226.60.151:22391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/1.php"] [unique_id "al9NA_7v0rlcEGmVraFiWQAAA4o"]
[Tue Jul 21 07:42:11.307080 2026] [security2:error] [pid 254995:tid 255131] [client 20.104.96.117:30461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/sump1.php"] [unique_id "al9NA_7v0rlcEGmVraFiXAAAAyQ"]
[Tue Jul 21 07:42:11.330839 2026] [security2:error] [pid 254995:tid 255200] [client 136.144.33.111:40471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NA_7v0rlcEGmVraFiXQAAA2k"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:11.384267 2026] [security2:error] [pid 254995:tid 255142] [client 20.226.60.151:54380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/222.php"] [unique_id "al9NA_7v0rlcEGmVraFiYAAAAy8"]
[Tue Jul 21 07:42:11.475231 2026] [security2:error] [pid 254995:tid 255275] [client 117.251.86.144:49054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFiawAAA5k"]
[Tue Jul 21 07:42:11.475324 2026] [security2:error] [pid 254995:tid 255275] [client 117.251.86.144:49054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFiawAAA5k"]
[Tue Jul 21 07:42:11.620539 2026] [security2:error] [pid 254995:tid 255229] [client 20.151.10.161:12095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/abcd.php"] [unique_id "al9NA_7v0rlcEGmVraFicAAAA4I"]
[Tue Jul 21 07:42:11.621822 2026] [security2:error] [pid 254995:tid 255184] [client 122.186.204.214:55320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFicQAAA1k"]
[Tue Jul 21 07:42:11.621939 2026] [security2:error] [pid 254995:tid 255184] [client 122.186.204.214:55320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NA_7v0rlcEGmVraFicQAAA1k"]
[Tue Jul 21 07:42:12.011617 2026] [security2:error] [pid 254995:tid 255214] [client 182.8.255.181:21220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFigAAAA3Y"]
[Tue Jul 21 07:42:12.011718 2026] [security2:error] [pid 254995:tid 255214] [client 182.8.255.181:21220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFigAAAA3Y"]
[Tue Jul 21 07:42:12.061955 2026] [security2:error] [pid 254995:tid 255252] [client 190.92.174.183:58594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/main/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFigwAAA4M"]
[Tue Jul 21 07:42:12.062061 2026] [security2:error] [pid 254995:tid 255252] [client 190.92.174.183:58594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/main/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFigwAAA4M"]
[Tue Jul 21 07:42:12.098178 2026] [security2:error] [pid 254995:tid 255258] [client 122.164.127.47:53497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFihgAAA4g"]
[Tue Jul 21 07:42:12.098293 2026] [security2:error] [pid 254995:tid 255258] [client 122.164.127.47:53497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFihgAAA4g"]
[Tue Jul 21 07:42:12.159900 2026] [security2:error] [pid 254995:tid 255162] [client 20.226.60.151:50917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/flox.php"] [unique_id "al9NBP7v0rlcEGmVraFihwAAA0M"]
[Tue Jul 21 07:42:12.197972 2026] [security2:error] [pid 254995:tid 255218] [client 74.7.175.148:45646] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.resultados.liranesuliano.com.br"] [uri "/index.php"] [unique_id "al9NA_7v0rlcEGmVraFicwADenw"]
[Tue Jul 21 07:42:12.253227 2026] [security2:error] [pid 254995:tid 255129] [client 20.197.195.24:44720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/file15.php"] [unique_id "al9NBP7v0rlcEGmVraFiiwAAAyI"]
[Tue Jul 21 07:42:12.494201 2026] [security2:error] [pid 254995:tid 255199] [client 103.86.117.203:52388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFilgAAA2g"]
[Tue Jul 21 07:42:12.494375 2026] [security2:error] [pid 254995:tid 255199] [client 103.86.117.203:52388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NBP7v0rlcEGmVraFilgAAA2g"]
[Tue Jul 21 07:42:12.582382 2026] [security2:error] [pid 254995:tid 255200] [client 20.226.60.151:62220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9NBP7v0rlcEGmVraFinQAAA2k"]
[Tue Jul 21 07:42:12.699382 2026] [security2:error] [pid 254995:tid 255138] [client 20.220.225.223:34249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NBP7v0rlcEGmVraFioAAAAys"]
[Tue Jul 21 07:42:12.704422 2026] [security2:error] [pid 254995:tid 255222] [client 20.220.225.223:11169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/berlin.php"] [unique_id "al9NBP7v0rlcEGmVraFioQAAA34"]
[Tue Jul 21 07:42:12.845829 2026] [security2:error] [pid 254995:tid 255162] [client 20.104.96.117:30459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/file5.php"] [unique_id "al9NBP7v0rlcEGmVraFipQAAA0M"]
[Tue Jul 21 07:42:12.859021 2026] [security2:error] [pid 254995:tid 255272] [client 74.7.175.148:45662] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "resultados.liranesuliano.com.br"] [uri "/index.php"] [unique_id "al9NBP7v0rlcEGmVraFiogADlgU"], referer: https://www.resultados.liranesuliano.com.br/robots.txt
[Tue Jul 21 07:42:12.910999 2026] [security2:error] [pid 254995:tid 255277] [client 20.226.60.151:54287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/test.php"] [unique_id "al9NBP7v0rlcEGmVraFiqwAAA5s"]
[Tue Jul 21 07:42:13.031819 2026] [autoindex:error] [pid 254995:tid 255205] [client 20.226.60.151:0] AH01276: Cannot serve directory /home3/vivia357/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:13.035655 2026] [security2:error] [pid 254995:tid 255163] [client 74.7.244.14:58852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "resultados.liranesuliano.com.br"] [uri "/index.php"] [unique_id "al9NBP7v0rlcEGmVraFirQADRG8"]
[Tue Jul 21 07:42:13.054159 2026] [security2:error] [pid 254995:tid 255212] [client 20.226.60.151:51217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/cong.php"] [unique_id "al9NBf7v0rlcEGmVraFisQAAA3Q"]
[Tue Jul 21 07:42:13.155532 2026] [security2:error] [pid 254995:tid 255131] [client 190.92.174.183:42548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9NBf7v0rlcEGmVraFitQAAAyQ"]
[Tue Jul 21 07:42:13.155625 2026] [security2:error] [pid 254995:tid 255131] [client 190.92.174.183:42548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9NBf7v0rlcEGmVraFitQAAAyQ"]
[Tue Jul 21 07:42:13.198852 2026] [security2:error] [pid 254995:tid 255169] [client 74.7.230.0:40388] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.visagismo2.0.oficialwebsite.com.br"] [uri "/index.php"] [unique_id "al9NBP7v0rlcEGmVraFiowADSiw"]
[Tue Jul 21 07:42:13.199027 2026] [security2:error] [pid 254995:tid 255149] [client 154.192.233.199:59611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NBf7v0rlcEGmVraFiuAAAAzY"]
[Tue Jul 21 07:42:13.199121 2026] [security2:error] [pid 254995:tid 255149] [client 154.192.233.199:59611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NBf7v0rlcEGmVraFiuAAAAzY"]
[Tue Jul 21 07:42:13.212252 2026] [security2:error] [pid 254995:tid 255199] [client 20.220.225.223:19675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wpx.php"] [unique_id "al9NBf7v0rlcEGmVraFiuQAAA2g"]
[Tue Jul 21 07:42:13.317243 2026] [security2:error] [pid 254995:tid 255257] [client 20.226.60.151:22946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/ms.php"] [unique_id "al9NBf7v0rlcEGmVraFiwgAAA4c"]
[Tue Jul 21 07:42:13.423720 2026] [security2:error] [pid 254995:tid 255171] [client 20.151.10.161:12076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/a1.php"] [unique_id "al9NBf7v0rlcEGmVraFixwAAA0w"]
[Tue Jul 21 07:42:13.660032 2026] [security2:error] [pid 254995:tid 255156] [client 74.7.230.32:46332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "visagismo2.0.oficialwebsite.com.br"] [uri "/index.php"] [unique_id "al9NBf7v0rlcEGmVraFiuwADPSM"]
[Tue Jul 21 07:42:13.927956 2026] [security2:error] [pid 254995:tid 255110] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NBf7v0rlcEGmVraFi2QADgnI"]
[Tue Jul 21 07:42:13.928111 2026] [security2:error] [pid 254995:tid 255229] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NBf7v0rlcEGmVraFi2QADgnI"]
[Tue Jul 21 07:42:14.153659 2026] [security2:error] [pid 254995:tid 255197] [client 20.197.195.24:44766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/jp.php"] [unique_id "al9NBv7v0rlcEGmVraFi4QAAA2Y"]
[Tue Jul 21 07:42:14.199994 2026] [security2:error] [pid 254995:tid 255174] [client 20.220.225.223:22499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/else1.php"] [unique_id "al9NBv7v0rlcEGmVraFi4gAAA08"]
[Tue Jul 21 07:42:14.255256 2026] [security2:error] [pid 254995:tid 255157] [client 190.92.174.183:42574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9NBv7v0rlcEGmVraFi5AAAAz4"]
[Tue Jul 21 07:42:14.255392 2026] [security2:error] [pid 254995:tid 255157] [client 190.92.174.183:42574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9NBv7v0rlcEGmVraFi5AAAAz4"]
[Tue Jul 21 07:42:14.292526 2026] [security2:error] [pid 254995:tid 255127] [client 74.7.230.0:40402] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "visagismo2.0.oficialwebsite.com.br"] [uri "/index.php"] [unique_id "al9NBf7v0rlcEGmVraFi2gADIEE"], referer: https://www.visagismo2.0.oficialwebsite.com.br/robots.txt
[Tue Jul 21 07:42:14.521289 2026] [security2:error] [pid 254995:tid 255130] [client 20.104.96.117:30426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/0xD.php"] [unique_id "al9NBv7v0rlcEGmVraFi7QAAAyM"]
[Tue Jul 21 07:42:14.760603 2026] [security2:error] [pid 254995:tid 255218] [client 20.151.10.161:53613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9NBv7v0rlcEGmVraFi9gAAA3o"]
[Tue Jul 21 07:42:14.793781 2026] [security2:error] [pid 254995:tid 255203] [client 20.226.60.151:33523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9NBv7v0rlcEGmVraFi9wAAA2w"]
[Tue Jul 21 07:42:15.020317 2026] [security2:error] [pid 254995:tid 255133] [client 128.127.105.184:47212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjBAAAAyY"]
[Tue Jul 21 07:42:15.020415 2026] [security2:error] [pid 254995:tid 255133] [client 128.127.105.184:47212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjBAAAAyY"]
[Tue Jul 21 07:42:15.279425 2026] [security2:error] [pid 254995:tid 255143] [client 117.217.38.194:65167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjDwAAAzA"]
[Tue Jul 21 07:42:15.279550 2026] [security2:error] [pid 254995:tid 255143] [client 117.217.38.194:65167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjDwAAAzA"]
[Tue Jul 21 07:42:15.282672 2026] [security2:error] [pid 254995:tid 255162] [client 103.106.20.201:51413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjEAAAA0M"]
[Tue Jul 21 07:42:15.282776 2026] [security2:error] [pid 254995:tid 255162] [client 103.106.20.201:51413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjEAAAA0M"]
[Tue Jul 21 07:42:15.349492 2026] [security2:error] [pid 254995:tid 255229] [client 190.92.174.183:42576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjEwAAA4I"]
[Tue Jul 21 07:42:15.349588 2026] [security2:error] [pid 254995:tid 255229] [client 190.92.174.183:42576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjEwAAA4I"]
[Tue Jul 21 07:42:15.455275 2026] [security2:error] [pid 254995:tid 255257] [client 194.99.104.35:40758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjFAAAA4c"]
[Tue Jul 21 07:42:15.455372 2026] [security2:error] [pid 254995:tid 255257] [client 194.99.104.35:40758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjFAAAA4c"]
[Tue Jul 21 07:42:15.627074 2026] [security2:error] [pid 254995:tid 255166] [client 59.96.220.140:56791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjHgAAA0c"]
[Tue Jul 21 07:42:15.627199 2026] [security2:error] [pid 254995:tid 255166] [client 59.96.220.140:56791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjHgAAA0c"]
[Tue Jul 21 07:42:15.645652 2026] [security2:error] [pid 254995:tid 255275] [client 122.162.144.145:18499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjHwAAA5k"]
[Tue Jul 21 07:42:15.645830 2026] [security2:error] [pid 254995:tid 255275] [client 122.162.144.145:18499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NB_7v0rlcEGmVraFjHwAAA5k"]
[Tue Jul 21 07:42:15.683805 2026] [security2:error] [pid 254995:tid 255266] [client 136.144.33.103:28621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NB_7v0rlcEGmVraFjFwAAA5A"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:15.696933 2026] [http2:info] [pid 296703:tid 296703] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 07:42:15.771911 2026] [security2:error] [pid 254995:tid 255164] [client 20.220.225.223:31720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/tkikikoko.php"] [unique_id "al9NB_7v0rlcEGmVraFjJQAAA0U"]
[Tue Jul 21 07:42:15.773489 2026] [security2:error] [pid 254995:tid 255213] [client 20.151.10.161:12056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9NB_7v0rlcEGmVraFjJgAAA3U"]
[Tue Jul 21 07:42:15.953882 2026] [security2:error] [pid 254995:tid 255179] [client 20.197.195.24:44789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/f35.php"] [unique_id "al9NB_7v0rlcEGmVraFjKgAAA1Q"]
[Tue Jul 21 07:42:16.286653 2026] [security2:error] [pid 254995:tid 255088] [remote 74.7.242.41:34054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "visagismo2.0.oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NCP7v0rlcEGmVraFjLQADPlw"], referer: https://visagismo2.0.oficialwebsite.com.br/
[Tue Jul 21 07:42:16.297347 2026] [security2:error] [pid 254995:tid 255197] [client 190.92.174.183:42578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/new/xmlrpc.php"] [unique_id "al9NCP7v0rlcEGmVraFjNQAAA2Y"]
[Tue Jul 21 07:42:16.297453 2026] [security2:error] [pid 254995:tid 255197] [client 190.92.174.183:42578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "br1102.hostgator.com.br"] [uri "/new/xmlrpc.php"] [unique_id "al9NCP7v0rlcEGmVraFjNQAAA2Y"]
[Tue Jul 21 07:42:16.334130 2026] [security2:error] [pid 296703:tid 296837] [client 198.204.224.34:52612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-includes/adc37af5/edit.php"] [unique_id "al9NCCn25uliftkV1n75yQAAAAQ"], referer: https://aumentodevendas.factorial.studio/wp-includes/adc37af5/edit.php
[Tue Jul 21 07:42:16.339050 2026] [security2:error] [pid 296703:tid 296840] [client 20.226.60.151:54396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/aaa.php"] [unique_id "al9NCCn25uliftkV1n75ygAAAAc"]
[Tue Jul 21 07:42:16.448959 2026] [security2:error] [pid 296703:tid 296842] [client 194.99.104.35:56946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NCCn25uliftkV1n75zAAAAAk"]
[Tue Jul 21 07:42:16.449089 2026] [security2:error] [pid 296703:tid 296842] [client 194.99.104.35:56946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NCCn25uliftkV1n75zAAAAAk"]
[Tue Jul 21 07:42:16.459848 2026] [security2:error] [pid 254995:tid 255277] [client 20.226.60.151:59454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/popo.php"] [unique_id "al9NCP7v0rlcEGmVraFjOQAAA5s"]
[Tue Jul 21 07:42:16.561626 2026] [autoindex:error] [pid 296703:tid 296848] [client 20.226.60.151:0] AH01276: Cannot serve directory /home3/vivia357/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:16.594276 2026] [security2:error] [pid 296703:tid 296852] [client 20.226.60.151:51216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/public/css.php"] [unique_id "al9NCCn25uliftkV1n750AAAABM"]
[Tue Jul 21 07:42:16.598478 2026] [security2:error] [pid 296703:tid 296853] [client 20.151.10.161:11758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/gettest.php"] [unique_id "al9NCCn25uliftkV1n750QAAABQ"]
[Tue Jul 21 07:42:16.723697 2026] [security2:error] [pid 254995:tid 255152] [client 20.104.96.117:30862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/fnstall.php"] [unique_id "al9NCP7v0rlcEGmVraFjRQAAAzk"]
[Tue Jul 21 07:42:17.016698 2026] [security2:error] [pid 296703:tid 296866] [client 20.197.195.24:44767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-load.php"] [unique_id "al9NCSn25uliftkV1n754AAAACE"]
[Tue Jul 21 07:42:17.099612 2026] [security2:error] [pid 296703:tid 296870] [client 20.220.225.223:34294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9NCSn25uliftkV1n754QAAACU"]
[Tue Jul 21 07:42:17.123297 2026] [security2:error] [pid 254995:tid 255074] [remote 217.182.128.41:48986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9NCf7v0rlcEGmVraFjTAADJU4"]
[Tue Jul 21 07:42:17.293623 2026] [security2:error] [pid 296703:tid 296715] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NCSn25uliftkV1n755QAAIAs"]
[Tue Jul 21 07:42:17.293824 2026] [security2:error] [pid 296703:tid 296865] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NCSn25uliftkV1n755QAAIAs"]
[Tue Jul 21 07:42:17.308049 2026] [security2:error] [pid 296703:tid 296880] [client 20.151.10.161:55295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/simple.php"] [unique_id "al9NCSn25uliftkV1n755wAAAC8"]
[Tue Jul 21 07:42:17.383895 2026] [security2:error] [pid 254995:tid 255120] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NCf7v0rlcEGmVraFjVgADO3w"]
[Tue Jul 21 07:42:17.384086 2026] [security2:error] [pid 254995:tid 255154] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NCf7v0rlcEGmVraFjVgADO3w"]
[Tue Jul 21 07:42:17.396195 2026] [security2:error] [pid 296703:tid 296883] [client 20.220.225.223:11152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/billur.php"] [unique_id "al9NCSn25uliftkV1n757AAAADI"]
[Tue Jul 21 07:42:17.448574 2026] [security2:error] [pid 254995:tid 255153] [client 20.226.60.151:33481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9NCf7v0rlcEGmVraFjWAAAAzo"]
[Tue Jul 21 07:42:17.509006 2026] [security2:error] [pid 296703:tid 296845] [client 139.167.225.182:65008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NCSn25uliftkV1n757gAAAAw"]
[Tue Jul 21 07:42:17.509118 2026] [security2:error] [pid 296703:tid 296845] [client 139.167.225.182:65008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NCSn25uliftkV1n757gAAAAw"]
[Tue Jul 21 07:42:17.894230 2026] [security2:error] [pid 296703:tid 296899] [client 20.197.195.24:44721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/xyn.php"] [unique_id "al9NCSn25uliftkV1n759AAAAEI"]
[Tue Jul 21 07:42:18.014232 2026] [security2:error] [pid 254995:tid 255209] [client 20.151.10.161:53582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xxx.php"] [unique_id "al9NCv7v0rlcEGmVraFjZQAAA3E"]
[Tue Jul 21 07:42:18.372288 2026] [security2:error] [pid 254995:tid 255064] [remote 42.200.84.61:56968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cezadvogados.com"] [uri "/wp-login.php"] [unique_id "al9NCv7v0rlcEGmVraFjbwADc0Q"]
[Tue Jul 21 07:42:18.373918 2026] [security2:error] [pid 296703:tid 296916] [client 20.104.96.117:30419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/acp.php"] [unique_id "al9NCin25uliftkV1n75-wAAAFM"]
[Tue Jul 21 07:42:18.382107 2026] [security2:error] [pid 296703:tid 296917] [client 20.220.225.223:34241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/inso.php"] [unique_id "al9NCin25uliftkV1n75_AAAAFQ"]
[Tue Jul 21 07:42:18.524868 2026] [security2:error] [pid 296703:tid 296921] [client 20.226.60.151:56240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/output.php"] [unique_id "al9NCin25uliftkV1n75_QAAAFg"]
[Tue Jul 21 07:42:18.542290 2026] [autoindex:error] [pid 296703:tid 296922] [client 20.197.195.24:44787] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:18.749372 2026] [security2:error] [pid 254995:tid 255163] [client 190.92.174.183:42592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "br1102.hostgator.com.br"] [uri "/wp-login.php"] [unique_id "al9NCf7v0rlcEGmVraFjYAAAA0Q"]
[Tue Jul 21 07:42:18.801167 2026] [security2:error] [pid 254995:tid 255149] [client 173.24.185.52:54574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NCv7v0rlcEGmVraFjeAAAAzY"]
[Tue Jul 21 07:42:18.801298 2026] [security2:error] [pid 254995:tid 255149] [client 173.24.185.52:54574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NCv7v0rlcEGmVraFjeAAAAzY"]
[Tue Jul 21 07:42:18.921050 2026] [security2:error] [pid 296703:tid 296913] [client 122.179.91.63:26448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NCin25uliftkV1n76BAAAAFA"]
[Tue Jul 21 07:42:18.921414 2026] [security2:error] [pid 296703:tid 296913] [client 122.179.91.63:26448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NCin25uliftkV1n76BAAAAFA"]
[Tue Jul 21 07:42:18.930727 2026] [autoindex:error] [pid 296703:tid 296928] [client 20.197.195.24:44787] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:18.939007 2026] [security2:error] [pid 296703:tid 296931] [client 20.197.195.24:44787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ccc.php"] [unique_id "al9NCin25uliftkV1n76BQAAAGI"]
[Tue Jul 21 07:42:18.995137 2026] [security2:error] [pid 296703:tid 296877] [client 62.102.148.187:35320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9NCin25uliftkV1n76BgAAACw"]
[Tue Jul 21 07:42:18.995242 2026] [security2:error] [pid 296703:tid 296877] [client 62.102.148.187:35320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9NCin25uliftkV1n76BgAAACw"]
[Tue Jul 21 07:42:19.101321 2026] [security2:error] [pid 296703:tid 296933] [client 74.249.245.134:54371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NCyn25uliftkV1n76BwAAAGQ"]
[Tue Jul 21 07:42:19.229648 2026] [security2:error] [pid 296703:tid 296937] [client 20.226.60.151:59505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/yas.php"] [unique_id "al9NCyn25uliftkV1n76CgAAAGg"]
[Tue Jul 21 07:42:19.252393 2026] [security2:error] [pid 296703:tid 296939] [client 20.151.10.161:12048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/hypo.php"] [unique_id "al9NCyn25uliftkV1n76CwAAAGo"]
[Tue Jul 21 07:42:19.447362 2026] [security2:error] [pid 296703:tid 296912] [client 136.144.33.97:40605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NCyn25uliftkV1n76DQAAAE8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:19.521905 2026] [security2:error] [pid 296703:tid 296929] [client 103.174.34.15:55663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NCyn25uliftkV1n76DgAAAGA"]
[Tue Jul 21 07:42:19.522052 2026] [security2:error] [pid 296703:tid 296929] [client 103.174.34.15:55663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NCyn25uliftkV1n76DgAAAGA"]
[Tue Jul 21 07:42:19.540423 2026] [security2:error] [pid 254995:tid 255009] [remote 97.74.93.24:55682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrsolar.org.br"] [uri "/wp-login.php"] [unique_id "al9NC_7v0rlcEGmVraFjhgADPw0"]
[Tue Jul 21 07:42:19.655005 2026] [security2:error] [pid 296703:tid 296947] [client 20.197.195.24:44713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/w.php"] [unique_id "al9NCyn25uliftkV1n76DwAAAHI"]
[Tue Jul 21 07:42:19.662860 2026] [security2:error] [pid 254995:tid 255190] [client 20.226.60.151:54275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/11.php"] [unique_id "al9NC_7v0rlcEGmVraFjhwAAA18"]
[Tue Jul 21 07:42:19.699510 2026] [security2:error] [pid 254995:tid 255184] [client 202.143.127.214:50105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NC_7v0rlcEGmVraFjiQAAA1k"]
[Tue Jul 21 07:42:19.699637 2026] [security2:error] [pid 254995:tid 255184] [client 202.143.127.214:50105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NC_7v0rlcEGmVraFjiQAAA1k"]
[Tue Jul 21 07:42:19.788164 2026] [security2:error] [pid 254995:tid 255203] [client 20.104.96.117:30427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/mosty.php"] [unique_id "al9NC_7v0rlcEGmVraFjiwAAA2w"]
[Tue Jul 21 07:42:19.805575 2026] [security2:error] [pid 296703:tid 296955] [client 20.220.225.223:19280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/berlin.php"] [unique_id "al9NCyn25uliftkV1n76EgAAAHo"]
[Tue Jul 21 07:42:19.849877 2026] [security2:error] [pid 296703:tid 296958] [client 20.226.60.151:62287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9NCyn25uliftkV1n76FAAAAH0"]
[Tue Jul 21 07:42:19.966000 2026] [security2:error] [pid 254995:tid 255127] [client 193.36.225.105:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NC_7v0rlcEGmVraFjkwAAAyA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:20.152357 2026] [security2:error] [pid 254995:tid 255152] [client 20.220.225.223:5269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/mimpi.php"] [unique_id "al9NDP7v0rlcEGmVraFjlgAAAzk"]
[Tue Jul 21 07:42:20.265584 2026] [security2:error] [pid 296703:tid 296847] [client 20.151.10.161:12038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/chosen.php"] [unique_id "al9NDCn25uliftkV1n76HAAAAA4"]
[Tue Jul 21 07:42:20.358210 2026] [security2:error] [pid 254995:tid 255132] [client 20.197.195.24:44727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9NDP7v0rlcEGmVraFjnAAAAyU"]
[Tue Jul 21 07:42:20.429041 2026] [security2:error] [pid 254995:tid 255191] [client 106.215.181.8:26953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDP7v0rlcEGmVraFjogAAA2A"]
[Tue Jul 21 07:42:20.429168 2026] [security2:error] [pid 254995:tid 255191] [client 106.215.181.8:26953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDP7v0rlcEGmVraFjogAAA2A"]
[Tue Jul 21 07:42:20.871165 2026] [security2:error] [pid 254995:tid 255120] [remote 144.217.254.10:37800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.254.217.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrsolar.org.br"] [uri "/wp-login.php"] [unique_id "al9NDP7v0rlcEGmVraFj3AADQHw"]
[Tue Jul 21 07:42:20.887297 2026] [security2:error] [pid 254995:tid 255164] [client 20.197.195.24:44691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/FWAZ.php"] [unique_id "al9NDP7v0rlcEGmVraFj3QAAA0U"]
[Tue Jul 21 07:42:20.910434 2026] [security2:error] [pid 254995:tid 255151] [client 20.104.96.117:30408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/6.php"] [unique_id "al9NDP7v0rlcEGmVraFj3wAAAzg"]
[Tue Jul 21 07:42:21.056862 2026] [security2:error] [pid 254995:tid 255269] [client 20.226.60.151:51247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-file-120.php"] [unique_id "al9NDf7v0rlcEGmVraFj4gAAA5M"]
[Tue Jul 21 07:42:21.177905 2026] [security2:error] [pid 296703:tid 296841] [client 20.197.195.24:44675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/miru1.php"] [unique_id "al9NDSn25uliftkV1n76KwAAAAg"]
[Tue Jul 21 07:42:21.198683 2026] [security2:error] [pid 296703:tid 296880] [client 20.226.60.151:59448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/file61.php"] [unique_id "al9NDSn25uliftkV1n76LAAAAC8"]
[Tue Jul 21 07:42:21.209620 2026] [security2:error] [pid 254995:tid 255200] [client 20.151.10.161:55284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/als.php"] [unique_id "al9NDf7v0rlcEGmVraFj5AAAA2k"]
[Tue Jul 21 07:42:21.213908 2026] [security2:error] [pid 254995:tid 255127] [client 184.75.223.211:37090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9NDf7v0rlcEGmVraFj5QAAAyA"]
[Tue Jul 21 07:42:21.214006 2026] [security2:error] [pid 254995:tid 255127] [client 184.75.223.211:37090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9NDf7v0rlcEGmVraFj5QAAAyA"]
[Tue Jul 21 07:42:21.305093 2026] [security2:error] [pid 296703:tid 296884] [client 20.220.225.223:22491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9NDSn25uliftkV1n76LgAAADM"]
[Tue Jul 21 07:42:21.463768 2026] [security2:error] [pid 254995:tid 255252] [client 20.197.195.24:44743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/aa.php"] [unique_id "al9NDf7v0rlcEGmVraFj9QAAA4M"]
[Tue Jul 21 07:42:21.541902 2026] [security2:error] [pid 296703:tid 296736] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDSn25uliftkV1n76MAAAMiA"]
[Tue Jul 21 07:42:21.542044 2026] [security2:error] [pid 296703:tid 296883] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDSn25uliftkV1n76MAAAMiA"]
[Tue Jul 21 07:42:21.591597 2026] [security2:error] [pid 254995:tid 255010] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NDf7v0rlcEGmVraFj-gADMw4"]
[Tue Jul 21 07:42:21.591830 2026] [security2:error] [pid 254995:tid 255146] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NDf7v0rlcEGmVraFj-gADMw4"]
[Tue Jul 21 07:42:21.618087 2026] [security2:error] [pid 296703:tid 296882] [client 20.197.195.24:44757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/122.php"] [unique_id "al9NDSn25uliftkV1n76MgAAADE"]
[Tue Jul 21 07:42:21.645654 2026] [security2:error] [pid 296703:tid 296897] [client 20.151.10.161:11718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/pol.php"] [unique_id "al9NDSn25uliftkV1n76MwAAAEA"]
[Tue Jul 21 07:42:21.713769 2026] [security2:error] [pid 296703:tid 296902] [client 20.220.225.223:27980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/dp.php"] [unique_id "al9NDSn25uliftkV1n76NAAAAEU"]
[Tue Jul 21 07:42:21.816598 2026] [security2:error] [pid 254995:tid 255166] [client 152.59.154.239:30414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDf7v0rlcEGmVraFkAAAAA0c"]
[Tue Jul 21 07:42:21.816684 2026] [security2:error] [pid 254995:tid 255166] [client 152.59.154.239:30414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDf7v0rlcEGmVraFkAAAAA0c"]
[Tue Jul 21 07:42:21.838035 2026] [security2:error] [pid 254995:tid 255190] [client 20.197.195.24:44768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/get.php"] [unique_id "al9NDf7v0rlcEGmVraFkAgAAA18"]
[Tue Jul 21 07:42:21.942062 2026] [security2:error] [pid 254995:tid 255128] [client 20.197.195.24:44742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/as.php"] [unique_id "al9NDf7v0rlcEGmVraFkBgAAAyE"]
[Tue Jul 21 07:42:21.949729 2026] [security2:error] [pid 296703:tid 296872] [client 47.128.99.162:10984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "precisosolucao.com.br"] [uri "/robots.txt"] [unique_id "al9NDSn25uliftkV1n76NgAAACc"]
[Tue Jul 21 07:42:21.958428 2026] [security2:error] [pid 254995:tid 255129] [client 20.226.60.151:50838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/water.php"] [unique_id "al9NDf7v0rlcEGmVraFkCgAAAyI"]
[Tue Jul 21 07:42:22.129124 2026] [security2:error] [pid 296703:tid 296914] [client 20.151.10.161:55289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file5.php"] [unique_id "al9NDin25uliftkV1n76OQAAAFE"]
[Tue Jul 21 07:42:22.151704 2026] [security2:error] [pid 254995:tid 255163] [client 117.251.86.144:58072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkDgAAA0Q"]
[Tue Jul 21 07:42:22.151838 2026] [security2:error] [pid 254995:tid 255163] [client 117.251.86.144:58072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkDgAAA0Q"]
[Tue Jul 21 07:42:22.159533 2026] [security2:error] [pid 254995:tid 255209] [client 20.197.195.24:44722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ccou.php"] [unique_id "al9NDv7v0rlcEGmVraFkDwAAA3E"]
[Tue Jul 21 07:42:22.254102 2026] [security2:error] [pid 296703:tid 296907] [client 45.3.46.170:33377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.46.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDin25uliftkV1n76OAAAAEo"]
[Tue Jul 21 07:42:22.254286 2026] [security2:error] [pid 296703:tid 296907] [client 45.3.46.170:33377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3d-surgery.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NDin25uliftkV1n76OAAAAEo"]
[Tue Jul 21 07:42:22.265562 2026] [security2:error] [pid 254995:tid 255131] [client 20.197.195.24:44755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/w3lls.php"] [unique_id "al9NDv7v0rlcEGmVraFkEwAAAyQ"]
[Tue Jul 21 07:42:22.295941 2026] [security2:error] [pid 296703:tid 296919] [client 20.226.60.151:33987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/albin.php"] [unique_id "al9NDin25uliftkV1n76OgAAAFY"]
[Tue Jul 21 07:42:22.311968 2026] [security2:error] [pid 296703:tid 296899] [client 122.186.204.214:55855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NDin25uliftkV1n76OwAAAEI"]
[Tue Jul 21 07:42:22.312129 2026] [security2:error] [pid 296703:tid 296899] [client 122.186.204.214:55855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NDin25uliftkV1n76OwAAAEI"]
[Tue Jul 21 07:42:22.357596 2026] [security2:error] [pid 254995:tid 255169] [client 20.197.195.24:44778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/test1.php"] [unique_id "al9NDv7v0rlcEGmVraFkFQAAA0o"]
[Tue Jul 21 07:42:22.454937 2026] [security2:error] [pid 254995:tid 255155] [client 20.226.60.151:54335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/mac.php"] [unique_id "al9NDv7v0rlcEGmVraFkGAAAAzw"]
[Tue Jul 21 07:42:22.507452 2026] [security2:error] [pid 254995:tid 255142] [client 182.8.255.181:21227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkHgAAAy8"]
[Tue Jul 21 07:42:22.507563 2026] [security2:error] [pid 254995:tid 255142] [client 182.8.255.181:21227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkHgAAAy8"]
[Tue Jul 21 07:42:22.518386 2026] [security2:error] [pid 254995:tid 255216] [client 20.197.195.24:13642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/database.php"] [unique_id "al9NDv7v0rlcEGmVraFkHwAAA3g"]
[Tue Jul 21 07:42:22.581515 2026] [autoindex:error] [pid 296703:tid 296931] [client 20.226.60.151:22933] AH01276: Cannot serve directory /home4/cavilh06/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:22.594316 2026] [security2:error] [pid 254995:tid 255268] [client 74.249.245.134:5536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NDv7v0rlcEGmVraFkJAAAA5I"]
[Tue Jul 21 07:42:22.615796 2026] [security2:error] [pid 296703:tid 296933] [client 20.226.60.151:22933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/memberfuns.php"] [unique_id "al9NDin25uliftkV1n76QwAAAGQ"]
[Tue Jul 21 07:42:22.630170 2026] [security2:error] [pid 254995:tid 255164] [client 122.164.127.47:54061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkJgAAA0U"]
[Tue Jul 21 07:42:22.630296 2026] [security2:error] [pid 254995:tid 255164] [client 122.164.127.47:54061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkJgAAA0U"]
[Tue Jul 21 07:42:22.812752 2026] [security2:error] [pid 254995:tid 255063] [remote 5.252.52.249:60588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9NDv7v0rlcEGmVraFkKgADIEM"]
[Tue Jul 21 07:42:22.854544 2026] [security2:error] [pid 296703:tid 296938] [client 20.151.10.161:55252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9NDin25uliftkV1n76RQAAAGk"]
[Tue Jul 21 07:42:22.970762 2026] [security2:error] [pid 296703:tid 296944] [client 20.220.225.223:5268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/bootstrap.php"] [unique_id "al9NDin25uliftkV1n76RwAAAG8"]
[Tue Jul 21 07:42:22.983037 2026] [security2:error] [pid 254995:tid 255125] [client 103.86.117.203:52927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkLgAAAx4"]
[Tue Jul 21 07:42:22.983141 2026] [security2:error] [pid 254995:tid 255125] [client 103.86.117.203:52927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NDv7v0rlcEGmVraFkLgAAAx4"]
[Tue Jul 21 07:42:23.138666 2026] [security2:error] [pid 254995:tid 255168] [client 20.226.60.151:59430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/nano.php"] [unique_id "al9ND_7v0rlcEGmVraFkNAAAA0k"]
[Tue Jul 21 07:42:23.145492 2026] [security2:error] [pid 254995:tid 255220] [client 193.36.225.153:23249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9ND_7v0rlcEGmVraFkNQAAA3w"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:23.365351 2026] [security2:error] [pid 254995:tid 255151] [client 104.207.63.247:35791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.63.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9ND_7v0rlcEGmVraFkNgAAAzg"]
[Tue Jul 21 07:42:23.385486 2026] [security2:error] [pid 254995:tid 255128] [client 45.3.54.172:24623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9ND_7v0rlcEGmVraFkNwAAAyE"]
[Tue Jul 21 07:42:23.423364 2026] [security2:error] [pid 296703:tid 296838] [client 20.197.192.193:23527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NDyn25uliftkV1n76UAAAAAU"]
[Tue Jul 21 07:42:23.424351 2026] [security2:error] [pid 296703:tid 296952] [client 45.3.48.133:25087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.48.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76TgAAAHc"]
[Tue Jul 21 07:42:23.490858 2026] [security2:error] [pid 254995:tid 255197] [client 195.63.31.255:12237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9ND_7v0rlcEGmVraFkOgAAA2Y"]
[Tue Jul 21 07:42:23.493756 2026] [security2:error] [pid 296703:tid 296929] [client 104.207.54.10:29895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.54.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76SQAAAGA"]
[Tue Jul 21 07:42:23.502293 2026] [security2:error] [pid 296703:tid 296848] [client 20.197.195.24:44773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/file.php"] [unique_id "al9NDyn25uliftkV1n76UgAAAA8"]
[Tue Jul 21 07:42:23.556163 2026] [security2:error] [pid 296703:tid 296930] [client 20.226.60.151:51243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/special.php"] [unique_id "al9NDyn25uliftkV1n76VgAAAGE"]
[Tue Jul 21 07:42:23.590287 2026] [security2:error] [pid 296703:tid 296951] [client 104.207.42.121:27069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.42.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76TwAAAHY"]
[Tue Jul 21 07:42:23.640171 2026] [security2:error] [pid 296703:tid 296833] [client 65.111.8.38:25619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76WQAAAAA"]
[Tue Jul 21 07:42:23.669092 2026] [security2:error] [pid 254995:tid 255149] [client 20.151.10.161:12047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file.php"] [unique_id "al9ND_7v0rlcEGmVraFkSQAAAzY"]
[Tue Jul 21 07:42:23.679482 2026] [security2:error] [pid 296703:tid 296843] [client 20.197.192.193:23520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NDyn25uliftkV1n76XAAAAAo"]
[Tue Jul 21 07:42:23.700008 2026] [security2:error] [pid 296703:tid 296862] [client 20.104.96.117:30443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9NDyn25uliftkV1n76XQAAAB0"]
[Tue Jul 21 07:42:23.714449 2026] [security2:error] [pid 254995:tid 255274] [client 74.7.175.175:46816] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.a06.arcoll.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9ND_7v0rlcEGmVraFkSgADmAg"]
[Tue Jul 21 07:42:23.744049 2026] [security2:error] [pid 296703:tid 296864] [client 20.197.192.193:23491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/dp.php"] [unique_id "al9NDyn25uliftkV1n76XwAAAB8"]
[Tue Jul 21 07:42:23.765289 2026] [security2:error] [pid 254995:tid 255153] [client 20.197.192.193:24450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/old.php"] [unique_id "al9ND_7v0rlcEGmVraFkTAAAAzo"]
[Tue Jul 21 07:42:23.766588 2026] [security2:error] [pid 296703:tid 296955] [client 182.8.226.25:25671] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "darsenavogamarine.com"] [uri "/wp-json/batch/v1"] [unique_id "al9NDyn25uliftkV1n76WwAAAHo"]
[Tue Jul 21 07:42:23.789674 2026] [security2:error] [pid 296703:tid 296871] [client 20.197.192.193:23534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/ms-new.php"] [unique_id "al9NDyn25uliftkV1n76YAAAACY"]
[Tue Jul 21 07:42:23.859562 2026] [security2:error] [pid 254995:tid 255266] [client 20.197.192.193:23536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/track.php"] [unique_id "al9ND_7v0rlcEGmVraFkTQAAA5A"]
[Tue Jul 21 07:42:23.924609 2026] [security2:error] [pid 296703:tid 296860] [client 20.197.192.193:24449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/2352356666.php"] [unique_id "al9NDyn25uliftkV1n76YQAAABs"]
[Tue Jul 21 07:42:23.938722 2026] [security2:error] [pid 296703:tid 296849] [client 20.220.225.223:34277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/dp.php"] [unique_id "al9NDyn25uliftkV1n76YgAAABA"]
[Tue Jul 21 07:42:24.000323 2026] [security2:error] [pid 296703:tid 296958] [client 154.192.233.199:58927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NECn25uliftkV1n76ZgAAAH0"]
[Tue Jul 21 07:42:24.000464 2026] [security2:error] [pid 296703:tid 296958] [client 154.192.233.199:58927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NECn25uliftkV1n76ZgAAAH0"]
[Tue Jul 21 07:42:24.001644 2026] [security2:error] [pid 296703:tid 296880] [client 20.197.192.193:23489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/pn.php"] [unique_id "al9NECn25uliftkV1n76ZwAAAC8"]
[Tue Jul 21 07:42:24.031920 2026] [security2:error] [pid 296703:tid 296884] [client 20.226.60.151:54272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/chosen.php"] [unique_id "al9NECn25uliftkV1n76aAAAADM"]
[Tue Jul 21 07:42:24.132430 2026] [security2:error] [pid 254995:tid 255158] [client 184.75.223.211:37104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NEP7v0rlcEGmVraFkVgAAAz8"]
[Tue Jul 21 07:42:24.132590 2026] [security2:error] [pid 254995:tid 255158] [client 184.75.223.211:37104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NEP7v0rlcEGmVraFkVgAAAz8"]
[Tue Jul 21 07:42:24.146597 2026] [security2:error] [pid 296703:tid 296868] [client 151.123.176.212:15037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.176.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76ZAAAACM"]
[Tue Jul 21 07:42:24.161279 2026] [security2:error] [pid 296703:tid 296869] [client 65.111.30.122:29173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.30.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76ZQAAACQ"]
[Tue Jul 21 07:42:24.243914 2026] [security2:error] [pid 254995:tid 255133] [client 193.36.225.60:31601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NEP7v0rlcEGmVraFkWAAAAyY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:24.282182 2026] [security2:error] [pid 296703:tid 296856] [client 20.197.192.193:24466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wp-wpbak.php"] [unique_id "al9NECn25uliftkV1n76awAAABc"]
[Tue Jul 21 07:42:24.365682 2026] [security2:error] [pid 296703:tid 296878] [client 104.207.57.141:53959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NECn25uliftkV1n76agAAAC0"]
[Tue Jul 21 07:42:24.433409 2026] [security2:error] [pid 254995:tid 255022] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NEP7v0rlcEGmVraFkXQADeRo"]
[Tue Jul 21 07:42:24.433550 2026] [security2:error] [pid 254995:tid 255217] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NEP7v0rlcEGmVraFkXQADeRo"]
[Tue Jul 21 07:42:24.465253 2026] [security2:error] [pid 296703:tid 296882] [client 74.249.245.134:5540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/wp.php"] [unique_id "al9NECn25uliftkV1n76cAAAADE"]
[Tue Jul 21 07:42:24.484838 2026] [security2:error] [pid 296703:tid 296886] [client 104.207.39.249:44233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.39.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NECn25uliftkV1n76bAAAADU"]
[Tue Jul 21 07:42:24.510718 2026] [security2:error] [pid 296703:tid 296900] [client 20.197.192.193:23522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/dr.php"] [unique_id "al9NECn25uliftkV1n76cQAAAEM"]
[Tue Jul 21 07:42:24.516970 2026] [security2:error] [pid 296703:tid 296901] [client 20.151.10.161:53607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/cfile.php"] [unique_id "al9NECn25uliftkV1n76cgAAAEQ"]
[Tue Jul 21 07:42:24.539412 2026] [security2:error] [pid 296703:tid 296909] [client 20.197.192.193:23518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/2x.php"] [unique_id "al9NECn25uliftkV1n76cwAAAEw"]
[Tue Jul 21 07:42:24.554762 2026] [security2:error] [pid 254995:tid 255202] [client 20.197.192.193:23538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/kq1.php"] [unique_id "al9NEP7v0rlcEGmVraFkYAAAA2s"]
[Tue Jul 21 07:42:24.574962 2026] [security2:error] [pid 296703:tid 296947] [client 65.111.11.9:57839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.11.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76TAAAAHI"]
[Tue Jul 21 07:42:24.586210 2026] [security2:error] [pid 296703:tid 296950] [client 65.111.13.109:52345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.13.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76TQAAAHU"]
[Tue Jul 21 07:42:24.586468 2026] [security2:error] [pid 296703:tid 296890] [client 45.3.52.120:52627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NECn25uliftkV1n76bQAAADk"]
[Tue Jul 21 07:42:24.616658 2026] [security2:error] [pid 296703:tid 296911] [client 20.197.195.24:44776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/file.php"] [unique_id "al9NECn25uliftkV1n76dAAAAE4"]
[Tue Jul 21 07:42:24.620030 2026] [security2:error] [pid 296703:tid 296914] [client 20.197.192.193:23502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/zzz.php"] [unique_id "al9NECn25uliftkV1n76dQAAAFE"]
[Tue Jul 21 07:42:24.701605 2026] [security2:error] [pid 254995:tid 255255] [client 45.3.36.121:30439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.36.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9ND_7v0rlcEGmVraFkQQAAA4U"]
[Tue Jul 21 07:42:24.702603 2026] [security2:error] [pid 296703:tid 296920] [client 20.197.192.193:24452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wicked.php"] [unique_id "al9NECn25uliftkV1n76egAAAFc"]
[Tue Jul 21 07:42:24.777715 2026] [security2:error] [pid 254995:tid 255183] [client 20.197.192.193:23540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/edit.php"] [unique_id "al9NEP7v0rlcEGmVraFkZwAAA1g"]
[Tue Jul 21 07:42:24.809288 2026] [security2:error] [pid 254995:tid 255218] [client 65.111.7.220:40873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.7.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9ND_7v0rlcEGmVraFkRwAAA3o"]
[Tue Jul 21 07:42:24.866831 2026] [security2:error] [pid 296703:tid 296928] [client 20.197.192.193:23513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/kua.php"] [unique_id "al9NECn25uliftkV1n76fAAAAF8"]
[Tue Jul 21 07:42:24.936565 2026] [security2:error] [pid 254995:tid 255169] [client 20.226.60.151:50914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/moon.php"] [unique_id "al9NEP7v0rlcEGmVraFkawAAA0o"]
[Tue Jul 21 07:42:24.986990 2026] [security2:error] [pid 254995:tid 255157] [client 20.197.192.193:23530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/ez.php"] [unique_id "al9NEP7v0rlcEGmVraFkbwAAAz4"]
[Tue Jul 21 07:42:25.004017 2026] [security2:error] [pid 296703:tid 296927] [client 20.226.60.151:62268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/cilus.php"] [unique_id "al9NESn25uliftkV1n76fQAAAF4"]
[Tue Jul 21 07:42:25.121723 2026] [security2:error] [pid 296703:tid 296921] [client 182.8.226.25:23659] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "darsenavogamarine.com"] [uri "/wp-json/batch/v1"] [unique_id "al9NESn25uliftkV1n76fgAAAFg"]
[Tue Jul 21 07:42:25.181668 2026] [security2:error] [pid 254995:tid 255260] [client 20.197.192.193:24453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/fz.php"] [unique_id "al9NEf7v0rlcEGmVraFkdAAAA4o"]
[Tue Jul 21 07:42:25.278006 2026] [security2:error] [pid 296703:tid 296945] [client 20.197.192.193:23510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/la.php"] [unique_id "al9NESn25uliftkV1n76hQAAAHA"]
[Tue Jul 21 07:42:25.287092 2026] [security2:error] [pid 296703:tid 296960] [client 20.226.60.151:54377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/cream1.php"] [unique_id "al9NESn25uliftkV1n76hwAAAH8"]
[Tue Jul 21 07:42:25.305344 2026] [security2:error] [pid 296703:tid 296932] [client 104.207.49.97:9701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.49.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NESn25uliftkV1n76gAAAAGM"]
[Tue Jul 21 07:42:25.376446 2026] [security2:error] [pid 296703:tid 296836] [client 20.151.10.161:55276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/class-wp.php"] [unique_id "al9NESn25uliftkV1n76iwAAAAM"]
[Tue Jul 21 07:42:25.401342 2026] [security2:error] [pid 296703:tid 296842] [client 20.197.192.193:23503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/nhvoanpl.php"] [unique_id "al9NESn25uliftkV1n76jAAAAAk"]
[Tue Jul 21 07:42:25.484616 2026] [security2:error] [pid 296703:tid 296935] [client 45.3.51.209:14995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.51.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NESn25uliftkV1n76igAAAGY"]
[Tue Jul 21 07:42:25.519671 2026] [security2:error] [pid 296703:tid 296852] [client 20.197.192.193:23532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/inso.php"] [unique_id "al9NESn25uliftkV1n76jgAAABM"]
[Tue Jul 21 07:42:25.557615 2026] [security2:error] [pid 254995:tid 255252] [client 104.207.52.81:59483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEf7v0rlcEGmVraFkdgAAA4M"]
[Tue Jul 21 07:42:25.573602 2026] [security2:error] [pid 254995:tid 255270] [client 151.123.177.142:50635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEf7v0rlcEGmVraFkdwAAA5Q"]
[Tue Jul 21 07:42:25.603248 2026] [security2:error] [pid 254995:tid 255268] [client 20.197.192.193:23493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wpx.php"] [unique_id "al9NEf7v0rlcEGmVraFkfQAAA5I"]
[Tue Jul 21 07:42:25.668663 2026] [security2:error] [pid 254995:tid 255273] [client 20.197.192.193:24507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/berlin.php"] [unique_id "al9NEf7v0rlcEGmVraFkgAAAA5c"]
[Tue Jul 21 07:42:25.679288 2026] [security2:error] [pid 254995:tid 255190] [client 20.197.195.24:44760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/777.php"] [unique_id "al9NEf7v0rlcEGmVraFkgQAAA18"]
[Tue Jul 21 07:42:25.706042 2026] [security2:error] [pid 254995:tid 255164] [client 104.207.35.18:35481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.35.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEf7v0rlcEGmVraFkewAAA0U"]
[Tue Jul 21 07:42:25.720501 2026] [security2:error] [pid 254995:tid 255135] [client 20.197.192.193:24453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/billur.php"] [unique_id "al9NEf7v0rlcEGmVraFkhAAAAyg"]
[Tue Jul 21 07:42:25.763516 2026] [security2:error] [pid 254995:tid 255153] [client 45.3.40.34:47797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.40.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEf7v0rlcEGmVraFkfAAAAzo"]
[Tue Jul 21 07:42:25.771529 2026] [security2:error] [pid 254995:tid 255217] [client 20.197.192.193:23488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/mimpi.php"] [unique_id "al9NEf7v0rlcEGmVraFkhwAAA3k"]
[Tue Jul 21 07:42:25.789171 2026] [security2:error] [pid 296703:tid 296849] [client 20.197.192.193:24479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/dp.php"] [unique_id "al9NESn25uliftkV1n76lAAAABA"]
[Tue Jul 21 07:42:25.806349 2026] [security2:error] [pid 296703:tid 296948] [client 65.111.5.248:27789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.5.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NDyn25uliftkV1n76WgAAAHM"]
[Tue Jul 21 07:42:25.817649 2026] [security2:error] [pid 296703:tid 296940] [client 117.217.38.194:49256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NESn25uliftkV1n76lQAAAGs"]
[Tue Jul 21 07:42:25.817756 2026] [security2:error] [pid 296703:tid 296940] [client 117.217.38.194:49256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NESn25uliftkV1n76lQAAAGs"]
[Tue Jul 21 07:42:25.841400 2026] [security2:error] [pid 296703:tid 296958] [client 20.197.192.193:23509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/bootstrap.php"] [unique_id "al9NESn25uliftkV1n76lgAAAH0"]
[Tue Jul 21 07:42:25.894421 2026] [security2:error] [pid 296703:tid 296854] [client 20.197.192.193:23550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wp-editor.php"] [unique_id "al9NESn25uliftkV1n76lwAAABU"]
[Tue Jul 21 07:42:25.937288 2026] [security2:error] [pid 296703:tid 296888] [client 20.197.192.193:24467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/cro.php"] [unique_id "al9NESn25uliftkV1n76mAAAADc"]
[Tue Jul 21 07:42:25.960029 2026] [security2:error] [pid 254995:tid 255209] [client 20.197.192.193:24481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/cron-tab.php"] [unique_id "al9NEf7v0rlcEGmVraFkiwAAA3E"]
[Tue Jul 21 07:42:25.962733 2026] [security2:error] [pid 296703:tid 296838] [client 103.106.20.201:51992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NESn25uliftkV1n76mQAAAAU"]
[Tue Jul 21 07:42:25.962936 2026] [security2:error] [pid 296703:tid 296838] [client 103.106.20.201:51992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NESn25uliftkV1n76mQAAAAU"]
[Tue Jul 21 07:42:26.029174 2026] [security2:error] [pid 254995:tid 255145] [client 20.197.192.193:24465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/koiy.php"] [unique_id "al9NEv7v0rlcEGmVraFkjgAAAzI"]
[Tue Jul 21 07:42:26.078170 2026] [security2:error] [pid 296703:tid 296869] [client 20.151.10.161:55287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/admin.php"] [unique_id "al9NEin25uliftkV1n76mwAAACQ"]
[Tue Jul 21 07:42:26.086378 2026] [security2:error] [pid 254995:tid 255218] [client 20.197.192.193:23545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/hp2.php"] [unique_id "al9NEv7v0rlcEGmVraFkkQAAA3o"]
[Tue Jul 21 07:42:26.110146 2026] [security2:error] [pid 254995:tid 255189] [client 20.197.192.193:23546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/hp3.php"] [unique_id "al9NEv7v0rlcEGmVraFklAAAA14"]
[Tue Jul 21 07:42:26.155322 2026] [security2:error] [pid 254995:tid 255180] [client 20.197.192.193:23533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/aa1.php"] [unique_id "al9NEv7v0rlcEGmVraFklwAAA1U"]
[Tue Jul 21 07:42:26.190007 2026] [security2:error] [pid 296703:tid 296856] [client 20.197.192.193:23496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/acew67.php"] [unique_id "al9NEin25uliftkV1n76nAAAABc"]
[Tue Jul 21 07:42:26.201307 2026] [security2:error] [pid 296703:tid 296837] [client 20.226.60.151:51215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/as.php"] [unique_id "al9NEin25uliftkV1n76ngAAAAQ"]
[Tue Jul 21 07:42:26.224902 2026] [security2:error] [pid 296703:tid 296878] [client 20.197.192.193:23515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/bscclapb.php"] [unique_id "al9NEin25uliftkV1n76oAAAAC0"]
[Tue Jul 21 07:42:26.311672 2026] [security2:error] [pid 296703:tid 296901] [client 20.197.192.193:24462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/else1.php"] [unique_id "al9NEin25uliftkV1n76pAAAAEQ"]
[Tue Jul 21 07:42:26.403732 2026] [security2:error] [pid 296703:tid 296959] [client 20.197.192.193:24042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/tkikikoko.php"] [unique_id "al9NEin25uliftkV1n76pQAAAH4"]
[Tue Jul 21 07:42:26.479457 2026] [security2:error] [pid 296703:tid 296909] [client 20.197.192.193:23549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wp-Blogs.php"] [unique_id "al9NEin25uliftkV1n76pwAAAEw"]
[Tue Jul 21 07:42:26.494369 2026] [security2:error] [pid 254995:tid 255222] [client 217.181.91.227:65451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.91.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEv7v0rlcEGmVraFkowAAA34"]
[Tue Jul 21 07:42:26.519647 2026] [security2:error] [pid 296703:tid 296860] [client 122.162.144.145:15093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NEin25uliftkV1n76qQAAABs"]
[Tue Jul 21 07:42:26.519785 2026] [security2:error] [pid 296703:tid 296860] [client 122.162.144.145:15093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NEin25uliftkV1n76qQAAABs"]
[Tue Jul 21 07:42:26.546637 2026] [security2:error] [pid 296703:tid 296947] [client 20.220.225.223:34276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/wpx.php"] [unique_id "al9NEin25uliftkV1n76qgAAAHI"]
[Tue Jul 21 07:42:26.549259 2026] [security2:error] [pid 296703:tid 296872] [client 20.197.192.193:24497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wp-css.php"] [unique_id "al9NEin25uliftkV1n76qwAAACc"]
[Tue Jul 21 07:42:26.665176 2026] [security2:error] [pid 254995:tid 255147] [client 20.197.192.193:23516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/wp-explorer.php"] [unique_id "al9NEv7v0rlcEGmVraFktwAAAzQ"]
[Tue Jul 21 07:42:26.683363 2026] [security2:error] [pid 296703:tid 296917] [client 20.151.10.161:12041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/aa2.php"] [unique_id "al9NEin25uliftkV1n76rQAAAFQ"]
[Tue Jul 21 07:42:26.729893 2026] [security2:error] [pid 254995:tid 255252] [client 184.75.223.211:37118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9NEv7v0rlcEGmVraFkuwAAA4M"]
[Tue Jul 21 07:42:26.729991 2026] [security2:error] [pid 254995:tid 255252] [client 184.75.223.211:37118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9NEv7v0rlcEGmVraFkuwAAA4M"]
[Tue Jul 21 07:42:26.849536 2026] [security2:error] [pid 296703:tid 296943] [client 20.197.192.193:23507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/akismet.php"] [unique_id "al9NEin25uliftkV1n76swAAAG4"]
[Tue Jul 21 07:42:26.909193 2026] [security2:error] [pid 254995:tid 255149] [client 45.3.37.145:57521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.37.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEv7v0rlcEGmVraFkvAAAAzY"]
[Tue Jul 21 07:42:26.961876 2026] [autoindex:error] [pid 296703:tid 296912] [client 20.226.60.151:54277] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:26.988024 2026] [autoindex:error] [pid 296703:tid 296952] [client 20.226.60.151:54277] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:26.994007 2026] [security2:error] [pid 296703:tid 296932] [client 20.226.60.151:54277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/dr.php"] [unique_id "al9NEin25uliftkV1n76twAAAGM"]
[Tue Jul 21 07:42:27.029802 2026] [security2:error] [pid 296703:tid 296836] [client 20.197.192.193:23539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/ace2.php"] [unique_id "al9NEyn25uliftkV1n76uAAAAAM"]
[Tue Jul 21 07:42:27.078869 2026] [security2:error] [pid 296703:tid 296842] [client 20.220.225.223:34192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/old.php"] [unique_id "al9NEyn25uliftkV1n76uwAAAAk"]
[Tue Jul 21 07:42:27.128672 2026] [security2:error] [pid 296703:tid 296951] [client 20.197.192.193:24482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.overkotz.com"] [uri "/ms.php"] [unique_id "al9NEyn25uliftkV1n76vQAAAHY"]
[Tue Jul 21 07:42:27.142523 2026] [security2:error] [pid 296703:tid 296899] [client 20.226.60.151:59492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-info.php"] [unique_id "al9NEyn25uliftkV1n76vgAAAEI"]
[Tue Jul 21 07:42:27.226717 2026] [security2:error] [pid 296703:tid 296866] [client 74.249.245.134:5549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/new.php"] [unique_id "al9NEyn25uliftkV1n76wAAAACE"]
[Tue Jul 21 07:42:27.242475 2026] [security2:error] [pid 254995:tid 255121] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NE_7v0rlcEGmVraFkwwADQH0"]
[Tue Jul 21 07:42:27.263278 2026] [security2:error] [pid 254995:tid 255125] [client 20.226.60.151:62304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/gptsh.php"] [unique_id "al9NE_7v0rlcEGmVraFkxQAAAx4"]
[Tue Jul 21 07:42:27.292889 2026] [security2:error] [pid 254995:tid 255217] [client 20.151.10.161:53574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/ccou.php"] [unique_id "al9NE_7v0rlcEGmVraFkyAAAA3k"]
[Tue Jul 21 07:42:27.421202 2026] [security2:error] [pid 254995:tid 255205] [client 193.56.28.44:61287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.28.56.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEf7v0rlcEGmVraFkeAAAA24"]
[Tue Jul 21 07:42:27.497249 2026] [security2:error] [pid 254995:tid 255178] [client 104.207.55.155:20929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.55.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEv7v0rlcEGmVraFkswAAA1M"]
[Tue Jul 21 07:42:27.568233 2026] [security2:error] [pid 296703:tid 296750] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9NEyn25uliftkV1n76yQAAfS4"]
[Tue Jul 21 07:42:27.648038 2026] [security2:error] [pid 296703:tid 296897] [client 104.207.59.45:22221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.59.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEin25uliftkV1n76pgAAAEA"]
[Tue Jul 21 07:42:27.690925 2026] [security2:error] [pid 254995:tid 255030] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NE_7v0rlcEGmVraFk0QADMCI"]
[Tue Jul 21 07:42:27.788934 2026] [security2:error] [pid 296703:tid 296960] [client 139.167.225.182:49287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NEyn25uliftkV1n76ywAAAH8"]
[Tue Jul 21 07:42:27.789114 2026] [security2:error] [pid 296703:tid 296960] [client 139.167.225.182:49287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NEyn25uliftkV1n76ywAAAH8"]
[Tue Jul 21 07:42:27.828193 2026] [security2:error] [pid 296703:tid 296751] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NEyn25uliftkV1n76zAAANy8"]
[Tue Jul 21 07:42:27.941247 2026] [security2:error] [pid 296703:tid 296838] [client 20.151.10.161:11715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/dr.php"] [unique_id "al9NEyn25uliftkV1n76zQAAAAU"]
[Tue Jul 21 07:42:27.970325 2026] [security2:error] [pid 254995:tid 255049] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9NE_7v0rlcEGmVraFk2QADTzU"]
[Tue Jul 21 07:42:28.068137 2026] [security2:error] [pid 296703:tid 296856] [client 20.220.225.223:34296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/ms-new.php"] [unique_id "al9NFCn25uliftkV1n76zgAAABc"]
[Tue Jul 21 07:42:28.106405 2026] [security2:error] [pid 254995:tid 255090] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NFP7v0rlcEGmVraFk2wADPl4"]
[Tue Jul 21 07:42:28.106530 2026] [security2:error] [pid 254995:tid 255157] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NFP7v0rlcEGmVraFk2wADPl4"]
[Tue Jul 21 07:42:28.107774 2026] [security2:error] [pid 296703:tid 296752] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NFCn25uliftkV1n760AAAATA"]
[Tue Jul 21 07:42:28.115947 2026] [security2:error] [pid 254995:tid 255162] [client 20.226.60.151:50880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/2000.php"] [unique_id "al9NFP7v0rlcEGmVraFk3AAAA0M"]
[Tue Jul 21 07:42:28.181192 2026] [security2:error] [pid 254995:tid 255179] [client 59.96.220.140:57297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NFP7v0rlcEGmVraFk3gAAA1Q"]
[Tue Jul 21 07:42:28.186904 2026] [security2:error] [pid 254995:tid 255179] [client 59.96.220.140:57297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NFP7v0rlcEGmVraFk3gAAA1Q"]
[Tue Jul 21 07:42:28.222638 2026] [security2:error] [pid 296703:tid 296901] [client 20.104.96.117:62940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NFCn25uliftkV1n760wAAAEQ"]
[Tue Jul 21 07:42:28.226003 2026] [security2:error] [pid 296703:tid 296857] [client 20.220.225.223:11150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/wp-editor.php"] [unique_id "al9NFCn25uliftkV1n761AAAABg"]
[Tue Jul 21 07:42:28.232103 2026] [security2:error] [pid 254995:tid 255114] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9NFP7v0rlcEGmVraFk4AADL3Y"]
[Tue Jul 21 07:42:28.237622 2026] [security2:error] [pid 296703:tid 296754] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFCn25uliftkV1n761QAAJDI"]
[Tue Jul 21 07:42:28.237764 2026] [security2:error] [pid 296703:tid 296869] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFCn25uliftkV1n761QAAJDI"]
[Tue Jul 21 07:42:28.292108 2026] [security2:error] [pid 254995:tid 255140] [client 122.179.91.63:30657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NFP7v0rlcEGmVraFk5AAAAy0"]
[Tue Jul 21 07:42:28.292471 2026] [security2:error] [pid 254995:tid 255140] [client 122.179.91.63:30657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NFP7v0rlcEGmVraFk5AAAAy0"]
[Tue Jul 21 07:42:28.366094 2026] [security2:error] [pid 296703:tid 296755] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NFCn25uliftkV1n762AAATjM"]
[Tue Jul 21 07:42:28.404692 2026] [security2:error] [pid 296703:tid 296868] [client 104.207.33.57:40343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NEin25uliftkV1n76ogAAACM"]
[Tue Jul 21 07:42:28.451067 2026] [security2:error] [pid 296703:tid 296910] [client 20.104.96.117:30403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/qqqa.php"] [unique_id "al9NFCn25uliftkV1n763AAAAE0"]
[Tue Jul 21 07:42:28.459335 2026] [security2:error] [pid 254995:tid 255146] [client 20.151.10.161:11728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xamp.php"] [unique_id "al9NFP7v0rlcEGmVraFk5gAAAzM"]
[Tue Jul 21 07:42:28.477323 2026] [security2:error] [pid 296703:tid 296896] [client 20.197.195.24:44769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ssixta.php"] [unique_id "al9NFCn25uliftkV1n763QAAAD8"]
[Tue Jul 21 07:42:28.486936 2026] [security2:error] [pid 254995:tid 255076] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NFP7v0rlcEGmVraFk5wADQlA"]
[Tue Jul 21 07:42:28.793973 2026] [security2:error] [pid 296703:tid 296895] [client 20.104.96.117:64010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NFCn25uliftkV1n764gAAAD4"]
[Tue Jul 21 07:42:28.809445 2026] [security2:error] [pid 296703:tid 296928] [client 20.226.60.151:61970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/x.php"] [unique_id "al9NFCn25uliftkV1n764wAAAF8"]
[Tue Jul 21 07:42:28.926613 2026] [security2:error] [pid 296703:tid 296759] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NFCn25uliftkV1n765QAAZTc"]
[Tue Jul 21 07:42:28.998854 2026] [security2:error] [pid 254995:tid 255127] [client 45.3.37.80:62865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.37.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9NE_7v0rlcEGmVraFk1wAAAyA"]
[Tue Jul 21 07:42:29.021520 2026] [security2:error] [pid 254995:tid 255159] [client 20.226.60.151:33497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/rithin.php"] [unique_id "al9NFf7v0rlcEGmVraFk8QAAA0A"]
[Tue Jul 21 07:42:29.052077 2026] [security2:error] [pid 254995:tid 255117] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NFf7v0rlcEGmVraFk8wADOnk"]
[Tue Jul 21 07:42:29.186744 2026] [security2:error] [pid 296703:tid 296761] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.elpcons.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NFSn25uliftkV1n765wAAaDk"]
[Tue Jul 21 07:42:29.375085 2026] [security2:error] [pid 254995:tid 255194] [client 173.24.185.52:55050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NFf7v0rlcEGmVraFk_QAAA2M"]
[Tue Jul 21 07:42:29.375207 2026] [security2:error] [pid 254995:tid 255194] [client 173.24.185.52:55050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NFf7v0rlcEGmVraFk_QAAA2M"]
[Tue Jul 21 07:42:29.433200 2026] [security2:error] [pid 254995:tid 255158] [client 193.36.225.121:56893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NFf7v0rlcEGmVraFk_gAAAz8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:29.448533 2026] [security2:error] [pid 254995:tid 255131] [client 74.249.245.134:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/class-t.api.php"] [unique_id "al9NFf7v0rlcEGmVraFk_wAAAyQ"]
[Tue Jul 21 07:42:29.453556 2026] [security2:error] [pid 254995:tid 255268] [client 136.144.33.97:30397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NFP7v0rlcEGmVraFk4gAAA5I"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:29.558836 2026] [security2:error] [pid 296703:tid 296894] [client 20.104.96.117:64031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/media.php"] [unique_id "al9NFSn25uliftkV1n767AAAAD0"]
[Tue Jul 21 07:42:29.757285 2026] [security2:error] [pid 296703:tid 296852] [client 20.220.225.223:34300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/berlin.php"] [unique_id "al9NFSn25uliftkV1n767wAAABM"]
[Tue Jul 21 07:42:29.782408 2026] [security2:error] [pid 254995:tid 255002] [remote 195.26.244.42:39116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "escoladaseguranca.com.br"] [uri "/wp-login.php"] [unique_id "al9NFf7v0rlcEGmVraFlBQADXwY"]
[Tue Jul 21 07:42:29.918910 2026] [security2:error] [pid 254995:tid 255174] [client 20.104.96.117:62929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/images.php"] [unique_id "al9NFf7v0rlcEGmVraFlCgAAA08"]
[Tue Jul 21 07:42:29.966145 2026] [security2:error] [pid 296703:tid 296764] [remote 13.41.15.21:48212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.15.41.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9NFSn25uliftkV1n769QAAEjw"]
[Tue Jul 21 07:42:30.057430 2026] [security2:error] [pid 296703:tid 296841] [client 20.226.60.151:56312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9NFin25uliftkV1n76-QAAAAg"]
[Tue Jul 21 07:42:30.154537 2026] [security2:error] [pid 296703:tid 296940] [client 20.151.10.161:12058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/bless.php"] [unique_id "al9NFin25uliftkV1n76_AAAAGs"]
[Tue Jul 21 07:42:30.211415 2026] [security2:error] [pid 296703:tid 296848] [client 103.174.34.15:56135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFin25uliftkV1n76_gAAAA8"]
[Tue Jul 21 07:42:30.211533 2026] [security2:error] [pid 296703:tid 296848] [client 103.174.34.15:56135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFin25uliftkV1n76_gAAAA8"]
[Tue Jul 21 07:42:30.286882 2026] [security2:error] [pid 296703:tid 296887] [client 20.104.96.117:62944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/gecko.php"] [unique_id "al9NFin25uliftkV1n77AAAAADY"]
[Tue Jul 21 07:42:30.298824 2026] [security2:error] [pid 296703:tid 296888] [client 20.226.60.151:62318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/fffm.php"] [unique_id "al9NFin25uliftkV1n77AQAAADc"]
[Tue Jul 21 07:42:30.609571 2026] [security2:error] [pid 254995:tid 255146] [client 20.104.96.117:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/82.php"] [unique_id "al9NFv7v0rlcEGmVraFlFwAAAzM"]
[Tue Jul 21 07:42:30.671070 2026] [security2:error] [pid 254995:tid 255266] [client 20.220.225.223:5249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/cro.php"] [unique_id "al9NFv7v0rlcEGmVraFlGQAAA5A"]
[Tue Jul 21 07:42:30.673475 2026] [security2:error] [pid 296703:tid 296902] [client 20.197.195.24:44692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/1c.php"] [unique_id "al9NFin25uliftkV1n77CAAAAEU"]
[Tue Jul 21 07:42:30.748445 2026] [security2:error] [pid 296703:tid 296875] [client 20.226.60.151:50919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/122.php"] [unique_id "al9NFin25uliftkV1n77CwAAACo"]
[Tue Jul 21 07:42:30.790294 2026] [security2:error] [pid 296703:tid 296769] [remote 38.242.157.30:34070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "liranesuliano.acupunturaebemestar.com.br"] [uri "/wp-login.php"] [unique_id "al9NFin25uliftkV1n77DQAAQUE"]
[Tue Jul 21 07:42:30.804248 2026] [security2:error] [pid 254995:tid 255162] [client 202.143.127.214:50536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFv7v0rlcEGmVraFlGwAAA0M"]
[Tue Jul 21 07:42:30.804372 2026] [security2:error] [pid 254995:tid 255162] [client 202.143.127.214:50536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFv7v0rlcEGmVraFlGwAAA0M"]
[Tue Jul 21 07:42:30.916201 2026] [security2:error] [pid 296703:tid 296860] [client 20.104.96.117:64014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/admin.php"] [unique_id "al9NFin25uliftkV1n77DwAAABs"]
[Tue Jul 21 07:42:31.196625 2026] [security2:error] [pid 296703:tid 296878] [client 106.215.181.8:3222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFyn25uliftkV1n77EAAAAC0"]
[Tue Jul 21 07:42:31.196773 2026] [security2:error] [pid 296703:tid 296878] [client 106.215.181.8:3222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NFyn25uliftkV1n77EAAAAC0"]
[Tue Jul 21 07:42:31.210023 2026] [security2:error] [pid 254995:tid 255217] [client 74.249.245.134:5544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/plugins.php"] [unique_id "al9NF_7v0rlcEGmVraFlJQAAA3k"]
[Tue Jul 21 07:42:31.254589 2026] [security2:error] [pid 296703:tid 296896] [client 20.104.96.117:62923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/adminner.php"] [unique_id "al9NFyn25uliftkV1n77EwAAAD8"]
[Tue Jul 21 07:42:31.264338 2026] [security2:error] [pid 254995:tid 255153] [client 20.226.60.151:33506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/dfre.php"] [unique_id "al9NF_7v0rlcEGmVraFlJwAAAzo"]
[Tue Jul 21 07:42:31.592315 2026] [security2:error] [pid 296703:tid 296913] [client 20.104.96.117:62948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/admin.php"] [unique_id "al9NFyn25uliftkV1n77GQAAAFA"]
[Tue Jul 21 07:42:31.603556 2026] [security2:error] [pid 254995:tid 255158] [client 20.226.60.151:54355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/155.php"] [unique_id "al9NF_7v0rlcEGmVraFlMQAAAz8"]
[Tue Jul 21 07:42:31.738975 2026] [security2:error] [pid 296703:tid 296931] [client 62.102.148.187:35008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9NFyn25uliftkV1n77GwAAAGI"]
[Tue Jul 21 07:42:31.739069 2026] [security2:error] [pid 296703:tid 296931] [client 62.102.148.187:35008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9NFyn25uliftkV1n77GwAAAGI"]
[Tue Jul 21 07:42:31.740298 2026] [security2:error] [pid 296703:tid 296927] [client 20.197.195.24:44751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/test2.php"] [unique_id "al9NFyn25uliftkV1n77HAAAAF4"]
[Tue Jul 21 07:42:31.741501 2026] [security2:error] [pid 296703:tid 296844] [client 74.249.245.134:54339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/jp.php"] [unique_id "al9NFyn25uliftkV1n77HQAAAAs"]
[Tue Jul 21 07:42:31.899953 2026] [security2:error] [pid 254995:tid 255189] [client 20.226.60.151:50908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/mds.php"] [unique_id "al9NF_7v0rlcEGmVraFlNwAAA14"]
[Tue Jul 21 07:42:31.917061 2026] [security2:error] [pid 296703:tid 296845] [client 20.104.96.117:62922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/k.php"] [unique_id "al9NFyn25uliftkV1n77HwAAAAw"]
[Tue Jul 21 07:42:32.063277 2026] [autoindex:error] [pid 254995:tid 255196] [client 205.210.31.250:62288] AH01276: Cannot serve directory /home1/bastar15/mirth.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:32.117137 2026] [security2:error] [pid 296703:tid 296772] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NGCn25uliftkV1n77IgAAZEQ"]
[Tue Jul 21 07:42:32.117314 2026] [security2:error] [pid 296703:tid 296933] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NGCn25uliftkV1n77IgAAZEQ"]
[Tue Jul 21 07:42:32.229644 2026] [security2:error] [pid 296703:tid 296932] [client 20.104.96.117:62939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/blurbs.php"] [unique_id "al9NGCn25uliftkV1n77IwAAAGM"]
[Tue Jul 21 07:42:32.277575 2026] [security2:error] [pid 296703:tid 296773] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NGCn25uliftkV1n77JQAAcEU"]
[Tue Jul 21 07:42:32.277692 2026] [security2:error] [pid 296703:tid 296945] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NGCn25uliftkV1n77JQAAcEU"]
[Tue Jul 21 07:42:32.393825 2026] [security2:error] [pid 296703:tid 296852] [client 20.151.10.161:12040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file46.php"] [unique_id "al9NGCn25uliftkV1n77KAAAABM"]
[Tue Jul 21 07:42:32.489712 2026] [security2:error] [pid 254995:tid 255216] [client 20.220.225.223:19326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/billur.php"] [unique_id "al9NGP7v0rlcEGmVraFlQAAAA3g"]
[Tue Jul 21 07:42:32.527419 2026] [security2:error] [pid 254995:tid 255266] [client 20.104.96.117:64021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/bajah.php"] [unique_id "al9NGP7v0rlcEGmVraFlRwAAA5A"]
[Tue Jul 21 07:42:32.651462 2026] [security2:error] [pid 254995:tid 255156] [client 20.220.225.223:34477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/billur.php"] [unique_id "al9NGP7v0rlcEGmVraFlSAAAAz0"]
[Tue Jul 21 07:42:32.831289 2026] [security2:error] [pid 296703:tid 296876] [client 20.226.60.151:54272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ops.php"] [unique_id "al9NGCn25uliftkV1n77KwAAACs"]
[Tue Jul 21 07:42:32.865962 2026] [security2:error] [pid 296703:tid 296957] [client 182.8.255.181:21082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NGCn25uliftkV1n77LAAAAHw"]
[Tue Jul 21 07:42:32.866131 2026] [security2:error] [pid 296703:tid 296957] [client 182.8.255.181:21082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NGCn25uliftkV1n77LAAAAHw"]
[Tue Jul 21 07:42:32.881161 2026] [security2:error] [pid 254995:tid 255157] [client 117.251.86.144:41398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NGP7v0rlcEGmVraFlSQAAAz4"]
[Tue Jul 21 07:42:32.881285 2026] [security2:error] [pid 254995:tid 255157] [client 117.251.86.144:41398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NGP7v0rlcEGmVraFlSQAAAz4"]
[Tue Jul 21 07:42:32.892911 2026] [security2:error] [pid 254995:tid 255191] [client 20.104.96.117:62945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/a.php"] [unique_id "al9NGP7v0rlcEGmVraFlSgAAA2A"]
[Tue Jul 21 07:42:32.946384 2026] [security2:error] [pid 254995:tid 255139] [client 74.249.245.134:54358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/error.php"] [unique_id "al9NGP7v0rlcEGmVraFlTQAAAyw"]
[Tue Jul 21 07:42:32.976708 2026] [security2:error] [pid 254995:tid 255133] [client 20.226.60.151:62294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/wp-happy.php"] [unique_id "al9NGP7v0rlcEGmVraFlTwAAAyY"]
[Tue Jul 21 07:42:33.031582 2026] [security2:error] [pid 296703:tid 296842] [client 122.186.204.214:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NGSn25uliftkV1n77MAAAAAk"]
[Tue Jul 21 07:42:33.031699 2026] [security2:error] [pid 296703:tid 296842] [client 122.186.204.214:56394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NGSn25uliftkV1n77MAAAAAk"]
[Tue Jul 21 07:42:33.057457 2026] [security2:error] [pid 254995:tid 255141] [client 136.144.33.241:20301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NGf7v0rlcEGmVraFlUgAAAy4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:33.190623 2026] [security2:error] [pid 296703:tid 296897] [client 20.104.96.117:64042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/edit.php"] [unique_id "al9NGSn25uliftkV1n77MgAAAEA"]
[Tue Jul 21 07:42:33.195131 2026] [security2:error] [pid 296703:tid 296881] [client 122.164.127.47:54630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NGSn25uliftkV1n77NAAAADA"]
[Tue Jul 21 07:42:33.200117 2026] [security2:error] [pid 296703:tid 296881] [client 122.164.127.47:54630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NGSn25uliftkV1n77NAAAADA"]
[Tue Jul 21 07:42:33.338438 2026] [security2:error] [pid 296703:tid 296834] [client 20.197.195.24:44679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/buy.php"] [unique_id "al9NGSn25uliftkV1n77NwAAAAE"]
[Tue Jul 21 07:42:33.462878 2026] [security2:error] [pid 296703:tid 296867] [client 103.86.117.203:53464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NGSn25uliftkV1n77PgAAACI"]
[Tue Jul 21 07:42:33.463040 2026] [security2:error] [pid 296703:tid 296867] [client 103.86.117.203:53464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NGSn25uliftkV1n77PgAAACI"]
[Tue Jul 21 07:42:33.489409 2026] [security2:error] [pid 254995:tid 255170] [client 20.104.96.117:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/hosty.php"] [unique_id "al9NGf7v0rlcEGmVraFlVgAAA0s"]
[Tue Jul 21 07:42:33.757700 2026] [security2:error] [pid 254995:tid 255128] [client 20.220.225.223:34288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/mimpi.php"] [unique_id "al9NGf7v0rlcEGmVraFlYQAAAyE"]
[Tue Jul 21 07:42:33.788114 2026] [security2:error] [pid 254995:tid 255143] [client 74.249.245.134:5512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/classwithtostring.php"] [unique_id "al9NGf7v0rlcEGmVraFlYgAAAzA"]
[Tue Jul 21 07:42:33.808452 2026] [security2:error] [pid 254995:tid 255189] [client 20.226.60.151:56269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/w1px.php"] [unique_id "al9NGf7v0rlcEGmVraFlYwAAA14"]
[Tue Jul 21 07:42:34.033992 2026] [security2:error] [pid 254995:tid 255196] [client 20.104.96.117:62953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/k.php"] [unique_id "al9NGv7v0rlcEGmVraFlaAAAA2U"]
[Tue Jul 21 07:42:34.204463 2026] [security2:error] [pid 296703:tid 296781] [remote 54.39.210.143:47202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.odontoclinicms.com.br"] [uri "/robots.txt"] [unique_id "al9NGin25uliftkV1n77SAAAUk0"]
[Tue Jul 21 07:42:34.204679 2026] [security2:error] [pid 296703:tid 296915] [client 54.39.210.143:47202] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.odontoclinicms.com.br"] [uri "/robots.txt"] [unique_id "al9NGin25uliftkV1n77SAAAUk0"]
[Tue Jul 21 07:42:34.251367 2026] [security2:error] [pid 296703:tid 296913] [client 20.226.60.151:59405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-blink.php"] [unique_id "al9NGin25uliftkV1n77SgAAAFA"]
[Tue Jul 21 07:42:34.401217 2026] [security2:error] [pid 296703:tid 296914] [client 20.104.96.117:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/aaa.php"] [unique_id "al9NGin25uliftkV1n77TQAAAFE"]
[Tue Jul 21 07:42:34.427624 2026] [security2:error] [pid 296703:tid 296836] [client 37.140.223.157:44717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NGCn25uliftkV1n77JAAAAAM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:34.562222 2026] [security2:error] [pid 296703:tid 296942] [client 20.226.60.151:54359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file31.php"] [unique_id "al9NGin25uliftkV1n77TwAAAG0"]
[Tue Jul 21 07:42:34.595190 2026] [security2:error] [pid 254995:tid 255157] [client 20.226.60.151:33483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/fpr4.php"] [unique_id "al9NGv7v0rlcEGmVraFleQAAAz4"]
[Tue Jul 21 07:42:34.597268 2026] [security2:error] [pid 296703:tid 296909] [client 154.192.233.199:59657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NGin25uliftkV1n77UAAAAEw"]
[Tue Jul 21 07:42:34.597422 2026] [security2:error] [pid 296703:tid 296909] [client 154.192.233.199:59657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NGin25uliftkV1n77UAAAAEw"]
[Tue Jul 21 07:42:34.795699 2026] [security2:error] [pid 254995:tid 255258] [client 20.104.96.117:62921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/file5.php"] [unique_id "al9NGv7v0rlcEGmVraFlfQAAA4g"]
[Tue Jul 21 07:42:34.838483 2026] [security2:error] [pid 254995:tid 255141] [client 62.102.148.187:35022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9NGv7v0rlcEGmVraFlfwAAAy4"]
[Tue Jul 21 07:42:34.838595 2026] [security2:error] [pid 254995:tid 255141] [client 62.102.148.187:35022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9NGv7v0rlcEGmVraFlfwAAAy4"]
[Tue Jul 21 07:42:34.980643 2026] [security2:error] [pid 254995:tid 255028] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NGv7v0rlcEGmVraFlgAADNyA"]
[Tue Jul 21 07:42:34.980835 2026] [security2:error] [pid 254995:tid 255150] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NGv7v0rlcEGmVraFlgAADNyA"]
[Tue Jul 21 07:42:35.031230 2026] [security2:error] [pid 296703:tid 296883] [client 20.197.195.24:44678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ssend.php"] [unique_id "al9NGyn25uliftkV1n77WAAAADI"]
[Tue Jul 21 07:42:35.184114 2026] [security2:error] [pid 296703:tid 296865] [client 20.104.96.117:64002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/222.php"] [unique_id "al9NGyn25uliftkV1n77XAAAACA"]
[Tue Jul 21 07:42:35.238683 2026] [security2:error] [pid 296703:tid 296842] [client 20.104.96.117:30871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/aunmc.php"] [unique_id "al9NGyn25uliftkV1n77XgAAAAk"]
[Tue Jul 21 07:42:35.278850 2026] [security2:error] [pid 296703:tid 296951] [client 114.119.133.30:43211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hometohomelondon.com"] [uri "/en/servico/corporate-services"] [unique_id "al9NGyn25uliftkV1n77XwAAAHY"], referer: https://hometohomelondon.com/en/services
[Tue Jul 21 07:42:35.465090 2026] [security2:error] [pid 296703:tid 296837] [client 20.104.96.117:5071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/test.php"] [unique_id "al9NGyn25uliftkV1n77ZQAAAAQ"]
[Tue Jul 21 07:42:35.737365 2026] [security2:error] [pid 296703:tid 296790] [remote 167.114.139.77:18858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.odontoclinicms.com.br"] [uri "/"] [unique_id "al9NGyn25uliftkV1n77awAARlY"]
[Tue Jul 21 07:42:35.737545 2026] [security2:error] [pid 296703:tid 296903] [client 167.114.139.77:18858] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.odontoclinicms.com.br"] [uri "/"] [unique_id "al9NGyn25uliftkV1n77awAARlY"]
[Tue Jul 21 07:42:35.763381 2026] [security2:error] [pid 296703:tid 296905] [client 74.249.245.134:5538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/bless.php"] [unique_id "al9NGyn25uliftkV1n77bAAAAEg"]
[Tue Jul 21 07:42:35.767171 2026] [security2:error] [pid 296703:tid 296898] [client 20.104.96.117:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/aaa.php"] [unique_id "al9NGyn25uliftkV1n77bQAAAEE"]
[Tue Jul 21 07:42:35.870866 2026] [security2:error] [pid 296703:tid 296879] [client 20.151.10.161:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/eee.php"] [unique_id "al9NGyn25uliftkV1n77bgAAAC4"]
[Tue Jul 21 07:42:35.923675 2026] [security2:error] [pid 296703:tid 296855] [client 20.226.60.151:33484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/file88.php"] [unique_id "al9NGyn25uliftkV1n77bwAAABY"]
[Tue Jul 21 07:42:36.099395 2026] [security2:error] [pid 296703:tid 296955] [client 20.104.96.117:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/11.php"] [unique_id "al9NHCn25uliftkV1n77cgAAAHo"]
[Tue Jul 21 07:42:36.111360 2026] [security2:error] [pid 254995:tid 255087] [remote 116.179.33.17:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.33.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9NHP7v0rlcEGmVraFlkgADWFs"], referer: https://androapkmod.com/luna-re-dimensional-watcher-apk-mod/
[Tue Jul 21 07:42:36.293868 2026] [security2:error] [pid 296703:tid 296867] [client 117.217.38.194:49744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHCn25uliftkV1n77dAAAACI"]
[Tue Jul 21 07:42:36.293962 2026] [security2:error] [pid 296703:tid 296867] [client 117.217.38.194:49744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHCn25uliftkV1n77dAAAACI"]
[Tue Jul 21 07:42:36.414338 2026] [security2:error] [pid 296703:tid 296952] [client 20.104.96.117:5068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/mac.php"] [unique_id "al9NHCn25uliftkV1n77fwAAAHc"]
[Tue Jul 21 07:42:36.477539 2026] [security2:error] [pid 296703:tid 296909] [client 20.226.60.151:54393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file6.php"] [unique_id "al9NHCn25uliftkV1n77hQAAAEw"]
[Tue Jul 21 07:42:36.513503 2026] [security2:error] [pid 296703:tid 296956] [client 20.220.225.223:34285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/dp.php"] [unique_id "al9NHCn25uliftkV1n77hgAAAHs"]
[Tue Jul 21 07:42:36.595907 2026] [security2:error] [pid 254995:tid 255158] [client 152.59.154.239:54453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHP7v0rlcEGmVraFlkwAAAz8"]
[Tue Jul 21 07:42:36.610493 2026] [security2:error] [pid 254995:tid 255158] [client 152.59.154.239:54453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHP7v0rlcEGmVraFlkwAAAz8"]
[Tue Jul 21 07:42:36.732397 2026] [security2:error] [pid 296703:tid 296856] [client 103.106.20.201:52577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHCn25uliftkV1n77lgAAABc"]
[Tue Jul 21 07:42:36.732499 2026] [security2:error] [pid 296703:tid 296861] [client 20.104.96.117:62946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/chosen.php"] [unique_id "al9NHCn25uliftkV1n77lQAAABw"]
[Tue Jul 21 07:42:36.732526 2026] [security2:error] [pid 296703:tid 296856] [client 103.106.20.201:52577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHCn25uliftkV1n77lgAAABc"]
[Tue Jul 21 07:42:36.732973 2026] [security2:error] [pid 296703:tid 296960] [client 20.197.195.24:13639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/item.php"] [unique_id "al9NHCn25uliftkV1n77lwAAAH8"]
[Tue Jul 21 07:42:36.748663 2026] [security2:error] [pid 296703:tid 296846] [client 20.226.60.151:22346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/0.php"] [unique_id "al9NHCn25uliftkV1n77mQAAAA0"]
[Tue Jul 21 07:42:36.765732 2026] [security2:error] [pid 296703:tid 296897] [client 136.144.33.29:65447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NHCn25uliftkV1n77mgAAAEA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:36.981187 2026] [security2:error] [pid 296703:tid 296888] [client 74.249.245.134:5562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/storage/index.php"] [unique_id "al9NHCn25uliftkV1n77nAAAADc"]
[Tue Jul 21 07:42:37.072962 2026] [autoindex:error] [pid 296703:tid 296875] [client 20.226.60.151:54282] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:37.088063 2026] [security2:error] [pid 296703:tid 296907] [client 20.104.96.117:62914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/cream1.php"] [unique_id "al9NHSn25uliftkV1n77oAAAAEo"]
[Tue Jul 21 07:42:37.299866 2026] [security2:error] [pid 296703:tid 296858] [client 122.162.144.145:3405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NHSn25uliftkV1n77rQAAABk"]
[Tue Jul 21 07:42:37.300006 2026] [security2:error] [pid 296703:tid 296858] [client 122.162.144.145:3405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NHSn25uliftkV1n77rQAAABk"]
[Tue Jul 21 07:42:37.443031 2026] [security2:error] [pid 296703:tid 296923] [client 20.226.60.151:54282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/adminfuns.php"] [unique_id "al9NHSn25uliftkV1n77tAAAAFo"]
[Tue Jul 21 07:42:37.461045 2026] [security2:error] [pid 296703:tid 296836] [client 20.226.60.151:33490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ccc.php"] [unique_id "al9NHSn25uliftkV1n77tQAAAAM"]
[Tue Jul 21 07:42:37.621421 2026] [security2:error] [pid 296703:tid 296852] [client 20.220.225.223:34187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/bootstrap.php"] [unique_id "al9NHSn25uliftkV1n77vwAAABM"]
[Tue Jul 21 07:42:37.673173 2026] [security2:error] [pid 296703:tid 296833] [client 20.220.225.223:34276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/track.php"] [unique_id "al9NHSn25uliftkV1n77wwAAAAA"]
[Tue Jul 21 07:42:37.953318 2026] [security2:error] [pid 296703:tid 296870] [client 128.127.105.184:51054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9NHSn25uliftkV1n77zwAAACU"]
[Tue Jul 21 07:42:37.953420 2026] [security2:error] [pid 296703:tid 296870] [client 128.127.105.184:51054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9NHSn25uliftkV1n77zwAAACU"]
[Tue Jul 21 07:42:38.011352 2026] [security2:error] [pid 296703:tid 296926] [client 20.226.60.151:54391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/goods.php"] [unique_id "al9NHin25uliftkV1n770QAAAF0"]
[Tue Jul 21 07:42:38.056904 2026] [security2:error] [pid 296703:tid 296857] [client 20.226.60.151:59442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/zc-208.php"] [unique_id "al9NHin25uliftkV1n770wAAABg"]
[Tue Jul 21 07:42:38.093439 2026] [security2:error] [pid 296703:tid 296886] [client 20.104.96.117:64039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/dr.php"] [unique_id "al9NHin25uliftkV1n771AAAADU"]
[Tue Jul 21 07:42:38.111787 2026] [security2:error] [pid 296703:tid 296913] [client 139.167.225.182:49945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHin25uliftkV1n771QAAAFA"]
[Tue Jul 21 07:42:38.111923 2026] [security2:error] [pid 296703:tid 296913] [client 139.167.225.182:49945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHin25uliftkV1n771QAAAFA"]
[Tue Jul 21 07:42:38.311523 2026] [security2:error] [pid 296703:tid 296936] [client 59.96.220.140:57808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NHin25uliftkV1n774AAAAGc"]
[Tue Jul 21 07:42:38.311640 2026] [security2:error] [pid 296703:tid 296936] [client 59.96.220.140:57808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NHin25uliftkV1n774AAAAGc"]
[Tue Jul 21 07:42:38.321144 2026] [security2:error] [pid 296703:tid 296887] [client 20.151.10.161:11746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file25.php"] [unique_id "al9NHin25uliftkV1n774QAAADY"]
[Tue Jul 21 07:42:38.432722 2026] [security2:error] [pid 296703:tid 296858] [client 20.104.96.117:64051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/x.php"] [unique_id "al9NHin25uliftkV1n774wAAABk"]
[Tue Jul 21 07:42:38.552765 2026] [security2:error] [pid 296703:tid 296860] [client 172.202.118.31:55476] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.69"] [uri "/index.cgi"] [unique_id "al9NHin25uliftkV1n776wAAABs"]
[Tue Jul 21 07:42:38.613957 2026] [security2:error] [pid 296703:tid 296894] [client 20.226.60.151:56313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/yawa.php"] [unique_id "al9NHin25uliftkV1n777QAAAD0"]
[Tue Jul 21 07:42:38.619465 2026] [security2:error] [pid 296703:tid 296912] [client 37.140.223.152:38659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NHin25uliftkV1n775gAAAE8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:38.728660 2026] [security2:error] [pid 296703:tid 296851] [client 20.104.96.117:64057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/155.php"] [unique_id "al9NHin25uliftkV1n778QAAABI"]
[Tue Jul 21 07:42:38.930141 2026] [security2:error] [pid 296703:tid 296907] [client 122.179.91.63:18992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NHin25uliftkV1n77_gAAAEo"]
[Tue Jul 21 07:42:38.930279 2026] [security2:error] [pid 296703:tid 296907] [client 122.179.91.63:18992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NHin25uliftkV1n77_gAAAEo"]
[Tue Jul 21 07:42:39.017400 2026] [security2:error] [pid 296703:tid 296717] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHyn25uliftkV1n78AAAAEw0"]
[Tue Jul 21 07:42:39.017582 2026] [security2:error] [pid 296703:tid 296852] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NHyn25uliftkV1n78AAAAEw0"]
[Tue Jul 21 07:42:39.072788 2026] [security2:error] [pid 296703:tid 296960] [client 20.104.96.117:64023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ops.php"] [unique_id "al9NHyn25uliftkV1n78AgAAAH8"]
[Tue Jul 21 07:42:39.120391 2026] [security2:error] [pid 296703:tid 296722] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NHyn25uliftkV1n78AwAACRI"]
[Tue Jul 21 07:42:39.120589 2026] [security2:error] [pid 296703:tid 296842] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NHyn25uliftkV1n78AwAACRI"]
[Tue Jul 21 07:42:39.218747 2026] [security2:error] [pid 296703:tid 296926] [client 74.249.245.134:5528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/g.php"] [unique_id "al9NHyn25uliftkV1n78BwAAAF0"]
[Tue Jul 21 07:42:39.427481 2026] [security2:error] [pid 296703:tid 296879] [client 20.226.60.151:54383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/100.php"] [unique_id "al9NHyn25uliftkV1n78EQAAAC4"]
[Tue Jul 21 07:42:39.547600 2026] [security2:error] [pid 296703:tid 296937] [client 20.104.96.117:64058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/file31.php"] [unique_id "al9NHyn25uliftkV1n78FwAAAGg"]
[Tue Jul 21 07:42:39.678505 2026] [autoindex:error] [pid 296703:tid 296730] [remote 74.7.227.20:38772] AH01276: Cannot serve directory /home2/bavosc49/gratech.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:39.741514 2026] [security2:error] [pid 296703:tid 296858] [client 74.7.228.22:41110] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "gratech.bavos.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9NHyn25uliftkV1n78GwAAGSM"]
[Tue Jul 21 07:42:39.812989 2026] [security2:error] [pid 296703:tid 296930] [client 20.197.195.24:44737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ss.php"] [unique_id "al9NHyn25uliftkV1n78IgAAAGE"]
[Tue Jul 21 07:42:39.821055 2026] [security2:error] [pid 296703:tid 296851] [client 20.220.225.223:19672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/mimpi.php"] [unique_id "al9NHyn25uliftkV1n78JQAAABI"]
[Tue Jul 21 07:42:39.884506 2026] [security2:error] [pid 296703:tid 296878] [client 20.104.96.117:64055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/file6.php"] [unique_id "al9NHyn25uliftkV1n78KQAAAC0"]
[Tue Jul 21 07:42:39.885062 2026] [security2:error] [pid 296703:tid 296876] [client 20.226.60.151:62248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/777.php"] [unique_id "al9NHyn25uliftkV1n78KgAAACs"]
[Tue Jul 21 07:42:39.954194 2026] [security2:error] [pid 296703:tid 296938] [client 173.24.185.52:55525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NHyn25uliftkV1n78KwAAAGk"]
[Tue Jul 21 07:42:39.954314 2026] [security2:error] [pid 296703:tid 296938] [client 173.24.185.52:55525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NHyn25uliftkV1n78KwAAAGk"]
[Tue Jul 21 07:42:40.346391 2026] [security2:error] [pid 296703:tid 296844] [client 103.166.103.129:8421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NICn25uliftkV1n78MgAAAAs"]
[Tue Jul 21 07:42:40.353005 2026] [security2:error] [pid 296703:tid 296844] [client 103.166.103.129:8421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NICn25uliftkV1n78MgAAAAs"]
[Tue Jul 21 07:42:40.569594 2026] [security2:error] [pid 296703:tid 296906] [client 20.151.10.161:55279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file48.php"] [unique_id "al9NICn25uliftkV1n78PAAAAEk"]
[Tue Jul 21 07:42:40.596045 2026] [security2:error] [pid 296703:tid 296913] [client 20.104.96.117:64013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/adminfuns.php"] [unique_id "al9NICn25uliftkV1n78PgAAAFA"]
[Tue Jul 21 07:42:40.677439 2026] [security2:error] [pid 296703:tid 296951] [client 172.245.102.34:35355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NICn25uliftkV1n78QQAAAHY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:40.785214 2026] [security2:error] [pid 296703:tid 296905] [client 20.226.60.151:59472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/sid4.php"] [unique_id "al9NICn25uliftkV1n78RQAAAEg"]
[Tue Jul 21 07:42:40.820248 2026] [security2:error] [pid 296703:tid 296887] [client 20.226.60.151:54330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/about.php"] [unique_id "al9NICn25uliftkV1n78SgAAADY"]
[Tue Jul 21 07:42:40.858925 2026] [security2:error] [pid 296703:tid 296942] [client 20.104.96.117:30849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/uoocf.php"] [unique_id "al9NICn25uliftkV1n78TwAAAG0"]
[Tue Jul 21 07:42:40.991377 2026] [security2:error] [pid 296703:tid 296920] [client 103.174.34.15:56614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NICn25uliftkV1n78WgAAAFc"]
[Tue Jul 21 07:42:40.991554 2026] [security2:error] [pid 296703:tid 296920] [client 103.174.34.15:56614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NICn25uliftkV1n78WgAAAFc"]
[Tue Jul 21 07:42:40.994147 2026] [security2:error] [pid 296703:tid 296929] [client 74.249.245.134:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/nf.php"] [unique_id "al9NICn25uliftkV1n78WwAAAGA"]
[Tue Jul 21 07:42:41.117645 2026] [security2:error] [pid 296703:tid 296871] [client 20.220.225.223:34230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/wp-editor.php"] [unique_id "al9NISn25uliftkV1n78YwAAACY"]
[Tue Jul 21 07:42:41.181913 2026] [security2:error] [pid 296703:tid 296928] [client 20.104.96.117:64053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/goods.php"] [unique_id "al9NISn25uliftkV1n78ZAAAAF8"]
[Tue Jul 21 07:42:41.405739 2026] [security2:error] [pid 296703:tid 296834] [client 20.226.60.151:54305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/about.php"] [unique_id "al9NISn25uliftkV1n78bAAAAAE"]
[Tue Jul 21 07:42:41.425551 2026] [security2:error] [pid 296703:tid 296943] [client 37.140.223.68:55275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NISn25uliftkV1n78bwAAAG4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:41.446675 2026] [security2:error] [pid 296703:tid 296857] [client 20.197.195.24:44726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/hypo.php"] [unique_id "al9NISn25uliftkV1n78cAAAABg"]
[Tue Jul 21 07:42:41.471514 2026] [security2:error] [pid 296703:tid 296945] [client 2.57.168.7:58193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.168.57.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9NISn25uliftkV1n78cQAAAHA"]
[Tue Jul 21 07:42:41.513729 2026] [security2:error] [pid 296703:tid 296884] [client 20.104.96.117:62942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/100.php"] [unique_id "al9NISn25uliftkV1n78cwAAADM"]
[Tue Jul 21 07:42:41.726671 2026] [security2:error] [pid 296703:tid 296858] [client 74.7.175.173:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solucaomodular.com.br"] [uri "/index.php"] [unique_id "al9NICn25uliftkV1n78UgAAABk"]
[Tue Jul 21 07:42:41.727575 2026] [security2:error] [pid 296703:tid 296879] [client 74.7.175.173:44524] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solucaomodular.com.br"] [uri "/robots.txt"] [unique_id "al9NICn25uliftkV1n78TQAALjU"]
[Tue Jul 21 07:42:41.765475 2026] [security2:error] [pid 296703:tid 296891] [client 20.220.225.223:32259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-explorer.php"] [unique_id "al9NISn25uliftkV1n78eAAAADo"]
[Tue Jul 21 07:42:41.791261 2026] [proxy:error] [pid 296703:tid 296927] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:41.791310 2026] [proxy_http:error] [pid 296703:tid 296927] [client 20.226.60.151:59429] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:41.792208 2026] [proxy:error] [pid 296703:tid 296927] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:41.792245 2026] [proxy_http:error] [pid 296703:tid 296927] [client 20.226.60.151:59429] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:41.825377 2026] [security2:error] [pid 296703:tid 296893] [client 20.104.96.117:64018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/about.php"] [unique_id "al9NISn25uliftkV1n78fAAAADw"]
[Tue Jul 21 07:42:41.870073 2026] [security2:error] [pid 296703:tid 296767] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NISn25uliftkV1n78dQAAfz8"]
[Tue Jul 21 07:42:41.870335 2026] [security2:error] [pid 296703:tid 296960] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NISn25uliftkV1n78dQAAfz8"]
[Tue Jul 21 07:42:41.876643 2026] [security2:error] [pid 296703:tid 296847] [client 106.215.181.8:19843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NISn25uliftkV1n78fQAAAA4"]
[Tue Jul 21 07:42:41.876731 2026] [security2:error] [pid 296703:tid 296847] [client 106.215.181.8:19843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NISn25uliftkV1n78fQAAAA4"]
[Tue Jul 21 07:42:42.020000 2026] [security2:error] [pid 296703:tid 296939] [client 20.151.10.161:53599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file6.php"] [unique_id "al9NIin25uliftkV1n78iAAAAGo"]
[Tue Jul 21 07:42:42.308765 2026] [security2:error] [pid 296703:tid 296895] [client 20.104.96.117:5099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/about.php"] [unique_id "al9NIin25uliftkV1n78jgAAAD4"]
[Tue Jul 21 07:42:42.399382 2026] [security2:error] [pid 296703:tid 296917] [client 202.143.127.214:50981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NIin25uliftkV1n78kAAAAFQ"]
[Tue Jul 21 07:42:42.399538 2026] [security2:error] [pid 296703:tid 296917] [client 202.143.127.214:50981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NIin25uliftkV1n78kAAAAFQ"]
[Tue Jul 21 07:42:42.610531 2026] [security2:error] [pid 296703:tid 296856] [client 20.104.96.117:62932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/admin.php"] [unique_id "al9NIin25uliftkV1n78mgAAABc"]
[Tue Jul 21 07:42:42.745195 2026] [security2:error] [pid 296703:tid 296956] [client 20.197.195.24:13648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/users.php"] [unique_id "al9NIin25uliftkV1n78mwAAAHs"]
[Tue Jul 21 07:42:42.770426 2026] [security2:error] [pid 296703:tid 296785] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NIin25uliftkV1n78nQAAS1E"]
[Tue Jul 21 07:42:42.770581 2026] [security2:error] [pid 296703:tid 296908] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NIin25uliftkV1n78nQAAS1E"]
[Tue Jul 21 07:42:42.776616 2026] [security2:error] [pid 296703:tid 296884] [client 74.249.245.134:54376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/xda.php"] [unique_id "al9NIin25uliftkV1n78ngAAADM"]
[Tue Jul 21 07:42:42.867681 2026] [security2:error] [pid 296703:tid 296789] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NIin25uliftkV1n78owAAB1U"]
[Tue Jul 21 07:42:42.867831 2026] [security2:error] [pid 296703:tid 296840] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NIin25uliftkV1n78owAAB1U"]
[Tue Jul 21 07:42:42.918638 2026] [security2:error] [pid 296703:tid 296841] [client 20.104.96.117:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/admin.php"] [unique_id "al9NIin25uliftkV1n78pQAAAAg"]
[Tue Jul 21 07:42:43.089847 2026] [security2:error] [pid 296703:tid 296894] [client 20.197.195.24:44759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/177.php"] [unique_id "al9NIyn25uliftkV1n78sQAAAD0"]
[Tue Jul 21 07:42:43.193025 2026] [security2:error] [pid 296703:tid 296919] [client 20.104.96.117:30429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/iywwi.php"] [unique_id "al9NIyn25uliftkV1n78tAAAAFY"]
[Tue Jul 21 07:42:43.207941 2026] [security2:error] [pid 296703:tid 296863] [client 20.104.96.117:64045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/themes.php"] [unique_id "al9NIyn25uliftkV1n78tQAAAB4"]
[Tue Jul 21 07:42:43.243523 2026] [security2:error] [pid 296703:tid 296902] [client 20.226.60.151:56196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/js.php"] [unique_id "al9NIyn25uliftkV1n78tgAAAEU"]
[Tue Jul 21 07:42:43.245986 2026] [security2:error] [pid 296703:tid 296939] [client 20.197.195.24:44712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/config.php"] [unique_id "al9NIyn25uliftkV1n78twAAAGo"]
[Tue Jul 21 07:42:43.310834 2026] [security2:error] [pid 296703:tid 296903] [client 182.8.255.181:17557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n78uAAAAEY"]
[Tue Jul 21 07:42:43.310935 2026] [security2:error] [pid 296703:tid 296903] [client 182.8.255.181:17557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n78uAAAAEY"]
[Tue Jul 21 07:42:43.545307 2026] [security2:error] [pid 296703:tid 296834] [client 20.226.60.151:59413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wmore1.php"] [unique_id "al9NIyn25uliftkV1n78vwAAAAE"]
[Tue Jul 21 07:42:43.662088 2026] [core:error] [pid 296703:tid 296857] [client 143.198.156.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:42:43.662108 2026] [core:error] [pid 296703:tid 296857] [client 143.198.156.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:42:43.663438 2026] [security2:error] [pid 296703:tid 296855] [client 117.251.86.144:46712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n78yQAAABY"]
[Tue Jul 21 07:42:43.663573 2026] [security2:error] [pid 296703:tid 296855] [client 117.251.86.144:46712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n78yQAAABY"]
[Tue Jul 21 07:42:43.708282 2026] [security2:error] [pid 296703:tid 296877] [client 20.197.195.24:44758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/gettest.php"] [unique_id "al9NIyn25uliftkV1n78zAAAACw"]
[Tue Jul 21 07:42:43.725833 2026] [security2:error] [pid 296703:tid 296960] [client 122.186.204.214:56925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n78zQAAAH8"]
[Tue Jul 21 07:42:43.725941 2026] [security2:error] [pid 296703:tid 296960] [client 122.186.204.214:56925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n78zQAAAH8"]
[Tue Jul 21 07:42:43.940091 2026] [security2:error] [pid 296703:tid 296876] [client 103.86.117.203:54011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n781AAAACs"]
[Tue Jul 21 07:42:43.940181 2026] [security2:error] [pid 296703:tid 296876] [client 103.86.117.203:54011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NIyn25uliftkV1n781AAAACs"]
[Tue Jul 21 07:42:44.006075 2026] [security2:error] [pid 296703:tid 296940] [client 20.220.225.223:32296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/akismet.php"] [unique_id "al9NJCn25uliftkV1n781gAAAGs"]
[Tue Jul 21 07:42:44.023556 2026] [security2:error] [pid 296703:tid 296806] [remote 192.241.143.148:38058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "links.principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9NJCn25uliftkV1n782wAAEGY"]
[Tue Jul 21 07:42:44.035062 2026] [security2:error] [pid 296703:tid 296922] [client 122.164.127.47:55207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NJCn25uliftkV1n783QAAAFk"]
[Tue Jul 21 07:42:44.035166 2026] [security2:error] [pid 296703:tid 296922] [client 122.164.127.47:55207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NJCn25uliftkV1n783QAAAFk"]
[Tue Jul 21 07:42:44.135755 2026] [security2:error] [pid 296703:tid 296915] [client 20.220.225.223:34266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/cro.php"] [unique_id "al9NJCn25uliftkV1n785gAAAFI"]
[Tue Jul 21 07:42:44.215315 2026] [security2:error] [pid 296703:tid 296846] [client 20.197.195.24:13782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NJCn25uliftkV1n786gAAAA0"]
[Tue Jul 21 07:42:44.268321 2026] [security2:error] [pid 296703:tid 296842] [client 20.104.96.117:64052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/.well-known/about.php"] [unique_id "al9NJCn25uliftkV1n787wAAAAk"]
[Tue Jul 21 07:42:44.399090 2026] [security2:error] [pid 296703:tid 296837] [client 20.226.60.151:62000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/admin.php"] [unique_id "al9NJCn25uliftkV1n789QAAAAQ"]
[Tue Jul 21 07:42:44.464728 2026] [security2:error] [pid 296703:tid 296812] [remote 119.155.20.197:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.20.155.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJCn25uliftkV1n788gAAXGw"]
[Tue Jul 21 07:42:44.464995 2026] [security2:error] [pid 296703:tid 296925] [client 119.155.20.197:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hauptmann.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJCn25uliftkV1n788gAAXGw"]
[Tue Jul 21 07:42:44.631262 2026] [security2:error] [pid 296703:tid 296940] [client 20.104.96.117:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9NJCn25uliftkV1n79AQAAAGs"]
[Tue Jul 21 07:42:44.667286 2026] [security2:error] [pid 296703:tid 296920] [client 20.226.60.151:56214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/core.php"] [unique_id "al9NJCn25uliftkV1n79BQAAAFc"]
[Tue Jul 21 07:42:45.029770 2026] [security2:error] [pid 296703:tid 296846] [client 74.249.245.134:54380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/shell.php"] [unique_id "al9NJSn25uliftkV1n79DAAAAA0"]
[Tue Jul 21 07:42:45.038103 2026] [security2:error] [pid 296703:tid 296854] [client 20.197.195.24:13683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/min.php"] [unique_id "al9NJSn25uliftkV1n79DgAAABU"]
[Tue Jul 21 07:42:45.057470 2026] [security2:error] [pid 296703:tid 296844] [client 20.104.96.117:62974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wefile.php"] [unique_id "al9NJSn25uliftkV1n79DwAAAAs"]
[Tue Jul 21 07:42:45.187714 2026] [security2:error] [pid 296703:tid 296870] [client 20.226.60.151:50897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/solo1.php"] [unique_id "al9NJSn25uliftkV1n79GAAAACU"]
[Tue Jul 21 07:42:45.286059 2026] [security2:error] [pid 296703:tid 296942] [client 20.226.60.151:62245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/for.php"] [unique_id "al9NJSn25uliftkV1n79HAAAAG0"]
[Tue Jul 21 07:42:45.313059 2026] [security2:error] [pid 296703:tid 296849] [client 154.192.233.199:59142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJSn25uliftkV1n79HgAAABA"]
[Tue Jul 21 07:42:45.313518 2026] [security2:error] [pid 296703:tid 296849] [client 154.192.233.199:59142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJSn25uliftkV1n79HgAAABA"]
[Tue Jul 21 07:42:45.405703 2026] [security2:error] [pid 296703:tid 296948] [client 20.104.96.117:62950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9NJSn25uliftkV1n79HwAAAHM"]
[Tue Jul 21 07:42:45.537429 2026] [security2:error] [pid 296703:tid 296830] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NJSn25uliftkV1n79IQAAM34"]
[Tue Jul 21 07:42:45.537608 2026] [security2:error] [pid 296703:tid 296884] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NJSn25uliftkV1n79IQAAM34"]
[Tue Jul 21 07:42:45.613173 2026] [security2:error] [pid 296703:tid 296879] [client 20.226.60.151:56241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/19.php"] [unique_id "al9NJSn25uliftkV1n79JAAAAC4"]
[Tue Jul 21 07:42:45.774696 2026] [security2:error] [pid 296703:tid 296909] [client 20.104.96.117:30856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/gqgsa.php"] [unique_id "al9NJSn25uliftkV1n79KgAAAEw"]
[Tue Jul 21 07:42:46.051402 2026] [security2:error] [pid 296703:tid 296834] [client 20.151.10.161:53581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/a2.php"] [unique_id "al9NJin25uliftkV1n79MQAAAAE"]
[Tue Jul 21 07:42:46.355937 2026] [proxy:error] [pid 296703:tid 296849] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:46.356027 2026] [proxy_http:error] [pid 296703:tid 296849] [client 20.226.60.151:50939] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:46.356486 2026] [proxy:error] [pid 296703:tid 296849] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:46.356508 2026] [proxy_http:error] [pid 296703:tid 296849] [client 20.226.60.151:50939] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:46.417297 2026] [security2:error] [pid 296703:tid 296926] [client 20.226.60.151:61979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/admin.php"] [unique_id "al9NJin25uliftkV1n79QwAAAF0"]
[Tue Jul 21 07:42:46.479519 2026] [security2:error] [pid 296703:tid 296898] [client 136.144.33.102:20187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NJin25uliftkV1n79RAAAAEE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:46.489008 2026] [security2:error] [pid 296703:tid 296871] [client 20.197.195.24:44719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/dvjul.php"] [unique_id "al9NJin25uliftkV1n79RQAAACY"]
[Tue Jul 21 07:42:46.499674 2026] [security2:error] [pid 296703:tid 296724] [remote 41.76.214.143:46598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/wp-login.php"] [unique_id "al9NJin25uliftkV1n79RgAAWhQ"]
[Tue Jul 21 07:42:46.500039 2026] [security2:error] [pid 296703:tid 296905] [client 20.104.96.117:64050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-admin/css/colour.php"] [unique_id "al9NJin25uliftkV1n79RwAAAEg"]
[Tue Jul 21 07:42:46.741259 2026] [security2:error] [pid 296703:tid 296960] [client 20.197.195.24:13714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NJin25uliftkV1n79UQAAAH8"]
[Tue Jul 21 07:42:46.787939 2026] [security2:error] [pid 296703:tid 296899] [client 117.217.38.194:50435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJin25uliftkV1n79VQAAAEI"]
[Tue Jul 21 07:42:46.788060 2026] [security2:error] [pid 296703:tid 296899] [client 117.217.38.194:50435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJin25uliftkV1n79VQAAAEI"]
[Tue Jul 21 07:42:46.842130 2026] [security2:error] [pid 296703:tid 296957] [client 20.104.96.117:64058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/8.php"] [unique_id "al9NJin25uliftkV1n79VgAAAHw"]
[Tue Jul 21 07:42:47.039675 2026] [security2:error] [pid 296703:tid 296873] [client 62.102.148.187:36238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79WQAAACg"]
[Tue Jul 21 07:42:47.039762 2026] [security2:error] [pid 296703:tid 296873] [client 62.102.148.187:36238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79WQAAACg"]
[Tue Jul 21 07:42:47.162088 2026] [security2:error] [pid 296703:tid 296841] [client 20.104.96.117:62955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-content/admin.php"] [unique_id "al9NJyn25uliftkV1n79XQAAAAg"]
[Tue Jul 21 07:42:47.306851 2026] [security2:error] [pid 296703:tid 296891] [client 20.226.60.151:50820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/cong.php"] [unique_id "al9NJyn25uliftkV1n79aQAAADo"]
[Tue Jul 21 07:42:47.440408 2026] [security2:error] [pid 296703:tid 296870] [client 20.104.96.117:62937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/f6.php"] [unique_id "al9NJyn25uliftkV1n79awAAACU"]
[Tue Jul 21 07:42:47.549055 2026] [security2:error] [pid 296703:tid 296922] [client 59.96.220.140:58324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79bQAAAFk"]
[Tue Jul 21 07:42:47.549170 2026] [security2:error] [pid 296703:tid 296922] [client 59.96.220.140:58324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79bQAAAFk"]
[Tue Jul 21 07:42:47.551653 2026] [security2:error] [pid 296703:tid 296911] [client 103.106.20.201:53164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79bAAAAE4"]
[Tue Jul 21 07:42:47.551784 2026] [security2:error] [pid 296703:tid 296911] [client 103.106.20.201:53164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79bAAAAE4"]
[Tue Jul 21 07:42:47.572365 2026] [security2:error] [pid 296703:tid 296948] [client 20.197.195.24:44725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/biufile.php"] [unique_id "al9NJyn25uliftkV1n79bgAAAHM"]
[Tue Jul 21 07:42:47.586376 2026] [security2:error] [pid 296703:tid 296923] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NJyn25uliftkV1n79bwAAAFo"]
[Tue Jul 21 07:42:47.591287 2026] [security2:error] [pid 296703:tid 296905] [client 74.249.245.134:54343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/3.php"] [unique_id "al9NJyn25uliftkV1n79cAAAAEg"]
[Tue Jul 21 07:42:47.722559 2026] [security2:error] [pid 296703:tid 296893] [client 20.151.10.161:11774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/file15.php"] [unique_id "al9NJyn25uliftkV1n79eAAAADw"]
[Tue Jul 21 07:42:47.728760 2026] [security2:error] [pid 296703:tid 296848] [client 20.104.96.117:62963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/inputs.php"] [unique_id "al9NJyn25uliftkV1n79eQAAAA8"]
[Tue Jul 21 07:42:47.826959 2026] [security2:error] [pid 296703:tid 296867] [client 20.220.225.223:34245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/2352356666.php"] [unique_id "al9NJyn25uliftkV1n79gQAAACI"]
[Tue Jul 21 07:42:47.858140 2026] [security2:error] [pid 296703:tid 296909] [client 20.226.60.151:56228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/inc.php"] [unique_id "al9NJyn25uliftkV1n79ggAAAEw"]
[Tue Jul 21 07:42:47.861095 2026] [security2:error] [pid 296703:tid 296957] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NJyn25uliftkV1n79gwAAAHw"]
[Tue Jul 21 07:42:47.897473 2026] [security2:error] [pid 296703:tid 296874] [client 152.59.154.239:54970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79hAAAACk"]
[Tue Jul 21 07:42:47.897592 2026] [security2:error] [pid 296703:tid 296874] [client 152.59.154.239:54970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NJyn25uliftkV1n79hAAAACk"]
[Tue Jul 21 07:42:47.983938 2026] [core:error] [pid 296703:tid 296842] [client 143.198.156.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.newpostapp.com/
[Tue Jul 21 07:42:47.983967 2026] [core:error] [pid 296703:tid 296842] [client 143.198.156.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.newpostapp.com/
[Tue Jul 21 07:42:48.038589 2026] [security2:error] [pid 296703:tid 296895] [client 20.104.96.117:62975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/inputs.php"] [unique_id "al9NKCn25uliftkV1n79jAAAAD4"]
[Tue Jul 21 07:42:48.108179 2026] [security2:error] [pid 296703:tid 296849] [client 122.162.144.145:4564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NKCn25uliftkV1n79jgAAABA"]
[Tue Jul 21 07:42:48.108298 2026] [security2:error] [pid 296703:tid 296849] [client 122.162.144.145:4564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NKCn25uliftkV1n79jgAAABA"]
[Tue Jul 21 07:42:48.225473 2026] [security2:error] [pid 296703:tid 296836] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/media.php"] [unique_id "al9NKCn25uliftkV1n79kAAAAAM"]
[Tue Jul 21 07:42:48.347918 2026] [security2:error] [pid 296703:tid 296929] [client 20.104.96.117:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/classwithtostring.php"] [unique_id "al9NKCn25uliftkV1n79lQAAAGA"]
[Tue Jul 21 07:42:48.378072 2026] [autoindex:error] [pid 296703:tid 296917] [client 44.220.233.148:20350] AH01276: Cannot serve directory /home2/acupu265/public_html/lp.liranesuliano.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:48.426163 2026] [autoindex:error] [pid 296703:tid 296901] [client 34.78.230.243:0] AH01276: Cannot serve directory /home1/hostag18/seiac.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:48.512471 2026] [proxy:error] [pid 296703:tid 296860] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:48.512543 2026] [proxy_http:error] [pid 296703:tid 296860] [client 20.226.60.151:59468] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:48.513152 2026] [proxy:error] [pid 296703:tid 296860] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:48.513182 2026] [proxy_http:error] [pid 296703:tid 296860] [client 20.226.60.151:59468] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:48.532818 2026] [security2:error] [pid 296703:tid 296920] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/images.php"] [unique_id "al9NKCn25uliftkV1n79ogAAAFc"]
[Tue Jul 21 07:42:48.646534 2026] [security2:error] [pid 296703:tid 296884] [client 20.197.195.24:13757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/media.php"] [unique_id "al9NKCn25uliftkV1n79pAAAADM"]
[Tue Jul 21 07:42:48.770796 2026] [security2:error] [pid 296703:tid 296912] [client 20.104.96.117:5060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-content/themes/index.php"] [unique_id "al9NKCn25uliftkV1n79qgAAAE8"]
[Tue Jul 21 07:42:48.815426 2026] [security2:error] [pid 296703:tid 296873] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/gecko.php"] [unique_id "al9NKCn25uliftkV1n79rAAAACg"]
[Tue Jul 21 07:42:48.979741 2026] [security2:error] [pid 296703:tid 296834] [client 20.226.60.151:34001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/ssla.php"] [unique_id "al9NKCn25uliftkV1n79sQAAAAE"]
[Tue Jul 21 07:42:49.039974 2026] [security2:error] [pid 296703:tid 296938] [client 20.197.195.24:44723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/av.php"] [unique_id "al9NKSn25uliftkV1n79sgAAAGk"]
[Tue Jul 21 07:42:49.060123 2026] [security2:error] [pid 296703:tid 296889] [client 62.102.148.187:33118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n79swAAADg"]
[Tue Jul 21 07:42:49.060223 2026] [security2:error] [pid 296703:tid 296889] [client 62.102.148.187:33118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n79swAAADg"]
[Tue Jul 21 07:42:49.067087 2026] [core:error] [pid 296703:tid 296763] [remote 205.210.31.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:42:49.067103 2026] [core:error] [pid 296703:tid 296763] [remote 205.210.31.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:42:49.106675 2026] [security2:error] [pid 296703:tid 296906] [client 139.167.225.182:50590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n79tgAAAEk"]
[Tue Jul 21 07:42:49.106782 2026] [security2:error] [pid 296703:tid 296906] [client 139.167.225.182:50590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n79tgAAAEk"]
[Tue Jul 21 07:42:49.183390 2026] [security2:error] [pid 296703:tid 296869] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/82.php"] [unique_id "al9NKSn25uliftkV1n79uQAAACQ"]
[Tue Jul 21 07:42:49.187762 2026] [security2:error] [pid 296703:tid 296770] [remote 207.180.241.245:35468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n79ugAAGUI"]
[Tue Jul 21 07:42:49.187951 2026] [security2:error] [pid 296703:tid 296858] [client 207.180.241.245:35468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rlvmultiofertas.com"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n79ugAAGUI"]
[Tue Jul 21 07:42:49.319723 2026] [security2:error] [pid 296703:tid 296934] [client 20.151.10.161:55283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/jp.php"] [unique_id "al9NKSn25uliftkV1n79wQAAAGU"]
[Tue Jul 21 07:42:49.410873 2026] [security2:error] [pid 296703:tid 296948] [client 20.226.60.151:50882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/public/css.php"] [unique_id "al9NKSn25uliftkV1n79xgAAAHM"]
[Tue Jul 21 07:42:49.480467 2026] [security2:error] [pid 296703:tid 296936] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/admin.php"] [unique_id "al9NKSn25uliftkV1n79yAAAAGc"]
[Tue Jul 21 07:42:49.495108 2026] [security2:error] [pid 296703:tid 296848] [client 20.104.96.117:30445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/elbzl.php"] [unique_id "al9NKSn25uliftkV1n79ywAAAA8"]
[Tue Jul 21 07:42:49.603612 2026] [security2:error] [pid 296703:tid 296920] [client 20.104.96.117:64026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-blog.php"] [unique_id "al9NKSn25uliftkV1n79zQAAAFc"]
[Tue Jul 21 07:42:49.640458 2026] [security2:error] [pid 296703:tid 296884] [client 20.226.60.151:54301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/themes.php"] [unique_id "al9NKSn25uliftkV1n79zgAAADM"]
[Tue Jul 21 07:42:49.759123 2026] [security2:error] [pid 296703:tid 296912] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/adminner.php"] [unique_id "al9NKSn25uliftkV1n790gAAAE8"]
[Tue Jul 21 07:42:49.759419 2026] [security2:error] [pid 296703:tid 296953] [client 20.197.195.24:13775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/images.php"] [unique_id "al9NKSn25uliftkV1n790wAAAHg"]
[Tue Jul 21 07:42:49.817390 2026] [security2:error] [pid 296703:tid 296914] [client 20.226.60.151:50940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/output.php"] [unique_id "al9NKSn25uliftkV1n791wAAAFE"]
[Tue Jul 21 07:42:49.882012 2026] [security2:error] [pid 296703:tid 296928] [client 20.197.195.24:13575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/coffexium.php"] [unique_id "al9NKSn25uliftkV1n792wAAAF8"]
[Tue Jul 21 07:42:49.920872 2026] [security2:error] [pid 296703:tid 296785] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n793gAAPVE"]
[Tue Jul 21 07:42:49.921031 2026] [security2:error] [pid 296703:tid 296894] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NKSn25uliftkV1n793gAAPVE"]
[Tue Jul 21 07:42:50.036231 2026] [security2:error] [pid 296703:tid 296849] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/admin.php"] [unique_id "al9NKin25uliftkV1n794wAAABA"]
[Tue Jul 21 07:42:50.207568 2026] [security2:error] [pid 296703:tid 296855] [client 74.249.245.134:54382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/mds.php"] [unique_id "al9NKin25uliftkV1n796gAAABY"]
[Tue Jul 21 07:42:50.317136 2026] [security2:error] [pid 296703:tid 296922] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/k.php"] [unique_id "al9NKin25uliftkV1n797gAAAFk"]
[Tue Jul 21 07:42:50.323631 2026] [security2:error] [pid 296703:tid 296847] [client 103.166.103.129:8857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n798AAAAA4"]
[Tue Jul 21 07:42:50.324039 2026] [security2:error] [pid 296703:tid 296847] [client 103.166.103.129:8857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n798AAAAA4"]
[Tue Jul 21 07:42:50.359113 2026] [security2:error] [pid 296703:tid 296883] [client 62.102.148.187:33128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n798QAAADI"]
[Tue Jul 21 07:42:50.359198 2026] [security2:error] [pid 296703:tid 296883] [client 62.102.148.187:33128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n798QAAADI"]
[Tue Jul 21 07:42:50.517674 2026] [security2:error] [pid 296703:tid 296929] [client 173.24.185.52:55995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n79-wAAAGA"]
[Tue Jul 21 07:42:50.517775 2026] [security2:error] [pid 296703:tid 296929] [client 173.24.185.52:55995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n79-wAAAGA"]
[Tue Jul 21 07:42:50.521901 2026] [security2:error] [pid 296703:tid 296887] [client 20.197.195.24:44686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/core.php"] [unique_id "al9NKin25uliftkV1n79_AAAADY"]
[Tue Jul 21 07:42:50.583698 2026] [security2:error] [pid 296703:tid 296806] [remote 43.157.224.197:54546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.224.157.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roseoliveirarose.com.br"] [uri "/wp-login.php"] [unique_id "al9NKin25uliftkV1n79_gAAGWY"]
[Tue Jul 21 07:42:50.617560 2026] [security2:error] [pid 296703:tid 296892] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/blurbs.php"] [unique_id "al9NKin25uliftkV1n79_wAAADs"]
[Tue Jul 21 07:42:50.699155 2026] [security2:error] [pid 296703:tid 296906] [client 122.179.91.63:26407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n7-AQAAAEk"]
[Tue Jul 21 07:42:50.699371 2026] [security2:error] [pid 296703:tid 296906] [client 122.179.91.63:26407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NKin25uliftkV1n7-AQAAAEk"]
[Tue Jul 21 07:42:50.871882 2026] [security2:error] [pid 296703:tid 296947] [client 20.226.60.151:22667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/BDKR28.php"] [unique_id "al9NKin25uliftkV1n7-CAAAAHI"]
[Tue Jul 21 07:42:50.892126 2026] [security2:error] [pid 296703:tid 296841] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/bajah.php"] [unique_id "al9NKin25uliftkV1n7-CQAAAAg"]
[Tue Jul 21 07:42:51.102638 2026] [autoindex:error] [pid 296703:tid 296934] [client 198.235.24.151:61966] AH01276: Cannot serve directory /home2/bavosc49/finance.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:51.107418 2026] [security2:error] [pid 296703:tid 296891] [client 20.226.60.151:50904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-file-120.php"] [unique_id "al9NKyn25uliftkV1n7-EgAAADo"]
[Tue Jul 21 07:42:51.129373 2026] [security2:error] [pid 296703:tid 296942] [client 20.104.96.117:64030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-content/admin.php"] [unique_id "al9NKyn25uliftkV1n7-EwAAAG0"]
[Tue Jul 21 07:42:51.200533 2026] [security2:error] [pid 296703:tid 296854] [client 136.144.33.107:33893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NKyn25uliftkV1n7-GAAAABU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:51.231635 2026] [security2:error] [pid 296703:tid 296870] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/a.php"] [unique_id "al9NKyn25uliftkV1n7-GQAAACU"]
[Tue Jul 21 07:42:51.266491 2026] [security2:error] [pid 296703:tid 296943] [client 20.104.96.117:30433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/adjig.php"] [unique_id "al9NKyn25uliftkV1n7-GgAAAG4"]
[Tue Jul 21 07:42:51.515053 2026] [security2:error] [pid 296703:tid 296876] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/edit.php"] [unique_id "al9NKyn25uliftkV1n7-KwAAACs"]
[Tue Jul 21 07:42:51.581501 2026] [security2:error] [pid 296703:tid 296872] [client 20.197.195.24:13759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/gecko.php"] [unique_id "al9NKyn25uliftkV1n7-LQAAACc"]
[Tue Jul 21 07:42:51.592024 2026] [security2:error] [pid 296703:tid 296905] [client 20.104.96.117:62965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ms-edit.php"] [unique_id "al9NKyn25uliftkV1n7-LwAAAEg"]
[Tue Jul 21 07:42:51.615941 2026] [security2:error] [pid 296703:tid 296932] [client 20.197.195.24:13668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/als.php"] [unique_id "al9NKyn25uliftkV1n7-MAAAAGM"]
[Tue Jul 21 07:42:51.769186 2026] [security2:error] [pid 296703:tid 296933] [client 20.226.60.151:50941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/special.php"] [unique_id "al9NKyn25uliftkV1n7-NAAAAGQ"]
[Tue Jul 21 07:42:51.801777 2026] [security2:error] [pid 296703:tid 296834] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/hosty.php"] [unique_id "al9NKyn25uliftkV1n7-NQAAAAE"]
[Tue Jul 21 07:42:51.895299 2026] [security2:error] [pid 296703:tid 296871] [client 103.174.34.15:57105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NKyn25uliftkV1n7-OAAAACY"]
[Tue Jul 21 07:42:51.895433 2026] [security2:error] [pid 296703:tid 296871] [client 103.174.34.15:57105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NKyn25uliftkV1n7-OAAAACY"]
[Tue Jul 21 07:42:52.030728 2026] [security2:error] [pid 296703:tid 296712] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NLCn25uliftkV1n7-QQAAAwg"]
[Tue Jul 21 07:42:52.030908 2026] [security2:error] [pid 296703:tid 296836] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NLCn25uliftkV1n7-QQAAAwg"]
[Tue Jul 21 07:42:52.054347 2026] [autoindex:error] [pid 296703:tid 296869] [client 20.226.60.151:54356] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:52.083627 2026] [security2:error] [pid 296703:tid 296956] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/k.php"] [unique_id "al9NLCn25uliftkV1n7-RAAAAHs"]
[Tue Jul 21 07:42:52.114666 2026] [security2:error] [pid 296703:tid 296707] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NLCn25uliftkV1n7-RQAAaQM"]
[Tue Jul 21 07:42:52.114787 2026] [security2:error] [pid 296703:tid 296938] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NLCn25uliftkV1n7-RQAAaQM"]
[Tue Jul 21 07:42:52.176280 2026] [security2:error] [pid 296703:tid 296917] [client 20.226.60.151:50913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/as.php"] [unique_id "al9NLCn25uliftkV1n7-RgAAAFQ"]
[Tue Jul 21 07:42:52.236645 2026] [autoindex:error] [pid 296703:tid 296840] [client 205.210.31.142:59266] AH01276: Cannot serve directory /home4/fabi0417/admin.powerflats.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:52.376102 2026] [security2:error] [pid 296703:tid 296912] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/aaa.php"] [unique_id "al9NLCn25uliftkV1n7-SwAAAE8"]
[Tue Jul 21 07:42:52.400559 2026] [security2:error] [pid 296703:tid 296863] [client 20.226.60.151:56277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9NLCn25uliftkV1n7-TAAAAB4"]
[Tue Jul 21 07:42:52.618465 2026] [security2:error] [pid 296703:tid 296845] [client 20.104.96.117:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/cgi-bin/index.php"] [unique_id "al9NLCn25uliftkV1n7-XQAAAAw"]
[Tue Jul 21 07:42:52.640833 2026] [security2:error] [pid 296703:tid 296884] [client 20.197.195.24:49863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/82.php"] [unique_id "al9NLCn25uliftkV1n7-XwAAADM"]
[Tue Jul 21 07:42:52.651286 2026] [security2:error] [pid 296703:tid 296908] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/file5.php"] [unique_id "al9NLCn25uliftkV1n7-YAAAAEs"]
[Tue Jul 21 07:42:52.712915 2026] [security2:error] [pid 296703:tid 296837] [client 20.151.10.161:55269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/f35.php"] [unique_id "al9NLCn25uliftkV1n7-YQAAAAQ"]
[Tue Jul 21 07:42:52.713910 2026] [security2:error] [pid 296703:tid 296877] [client 20.197.195.24:44762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/simple.php"] [unique_id "al9NLCn25uliftkV1n7-YgAAACw"]
[Tue Jul 21 07:42:52.771826 2026] [security2:error] [pid 296703:tid 296945] [client 106.215.181.8:32620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLCn25uliftkV1n7-ZQAAAHA"]
[Tue Jul 21 07:42:52.771952 2026] [security2:error] [pid 296703:tid 296945] [client 106.215.181.8:32620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLCn25uliftkV1n7-ZQAAAHA"]
[Tue Jul 21 07:42:52.783308 2026] [security2:error] [pid 296703:tid 296947] [client 74.249.245.134:5529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/archive.php"] [unique_id "al9NLCn25uliftkV1n7-ZgAAAHI"]
[Tue Jul 21 07:42:52.826801 2026] [security2:error] [pid 296703:tid 296836] [client 20.220.225.223:11170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/koiy.php"] [unique_id "al9NLCn25uliftkV1n7-ZwAAAAM"]
[Tue Jul 21 07:42:52.867046 2026] [security2:error] [pid 296703:tid 296911] [client 20.226.60.151:59471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/cgi-bin/index.php"] [unique_id "al9NLCn25uliftkV1n7-aAAAAE4"]
[Tue Jul 21 07:42:52.966776 2026] [security2:error] [pid 296703:tid 296898] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/222.php"] [unique_id "al9NLCn25uliftkV1n7-awAAAEE"]
[Tue Jul 21 07:42:53.039871 2026] [security2:error] [pid 296703:tid 296917] [client 20.220.225.223:19320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/dp.php"] [unique_id "al9NLSn25uliftkV1n7-cQAAAFQ"]
[Tue Jul 21 07:42:53.280882 2026] [security2:error] [pid 296703:tid 296923] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/test.php"] [unique_id "al9NLSn25uliftkV1n7-eAAAAFo"]
[Tue Jul 21 07:42:53.390690 2026] [security2:error] [pid 296703:tid 296960] [client 20.220.225.223:34202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/cron-tab.php"] [unique_id "al9NLSn25uliftkV1n7-ewAAAH8"]
[Tue Jul 21 07:42:53.408089 2026] [security2:error] [pid 296703:tid 296842] [client 20.226.60.151:50922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/w1px.php"] [unique_id "al9NLSn25uliftkV1n7-fgAAAAk"]
[Tue Jul 21 07:42:53.433452 2026] [security2:error] [pid 296703:tid 296733] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-gQAAIx0"]
[Tue Jul 21 07:42:53.433647 2026] [security2:error] [pid 296703:tid 296868] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-gQAAIx0"]
[Tue Jul 21 07:42:53.437362 2026] [security2:error] [pid 296703:tid 296933] [client 20.104.96.117:30854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/byp.php"] [unique_id "al9NLSn25uliftkV1n7-ggAAAGQ"]
[Tue Jul 21 07:42:53.445066 2026] [security2:error] [pid 296703:tid 296834] [client 20.104.96.117:64054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/BDKR28WP.php"] [unique_id "al9NLSn25uliftkV1n7-gwAAAAE"]
[Tue Jul 21 07:42:53.448868 2026] [security2:error] [pid 296703:tid 296881] [client 194.99.104.35:47300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-hAAAADA"]
[Tue Jul 21 07:42:53.448955 2026] [security2:error] [pid 296703:tid 296881] [client 194.99.104.35:47300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-hAAAADA"]
[Tue Jul 21 07:42:53.491021 2026] [security2:error] [pid 296703:tid 296899] [client 20.197.195.24:44702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/init.php"] [unique_id "al9NLSn25uliftkV1n7-hwAAAEI"]
[Tue Jul 21 07:42:53.563702 2026] [security2:error] [pid 296703:tid 296877] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/aaa.php"] [unique_id "al9NLSn25uliftkV1n7-jQAAACw"]
[Tue Jul 21 07:42:53.722078 2026] [security2:error] [pid 296703:tid 296925] [client 182.8.255.181:17591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-lAAAAFw"]
[Tue Jul 21 07:42:53.722201 2026] [security2:error] [pid 296703:tid 296925] [client 182.8.255.181:17591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-lAAAAFw"]
[Tue Jul 21 07:42:53.848084 2026] [security2:error] [pid 296703:tid 296838] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/11.php"] [unique_id "al9NLSn25uliftkV1n7-mQAAAAU"]
[Tue Jul 21 07:42:53.900549 2026] [security2:error] [pid 296703:tid 296737] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-ngAATyE"]
[Tue Jul 21 07:42:53.900707 2026] [security2:error] [pid 296703:tid 296912] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-ngAATyE"]
[Tue Jul 21 07:42:53.922779 2026] [security2:error] [pid 296703:tid 296863] [client 20.220.225.223:5258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/hp2.php"] [unique_id "al9NLSn25uliftkV1n7-oQAAAB4"]
[Tue Jul 21 07:42:53.947763 2026] [security2:error] [pid 296703:tid 296939] [client 202.143.127.214:51420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-owAAAGo"]
[Tue Jul 21 07:42:53.947887 2026] [security2:error] [pid 296703:tid 296939] [client 202.143.127.214:51420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLSn25uliftkV1n7-owAAAGo"]
[Tue Jul 21 07:42:54.130808 2026] [security2:error] [pid 296703:tid 296868] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/mac.php"] [unique_id "al9NLin25uliftkV1n7-qgAAACM"]
[Tue Jul 21 07:42:54.165914 2026] [access_compat:error] [pid 296703:tid 296881] [client 162.241.63.68:58052] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:42:54.238829 2026] [security2:error] [pid 296703:tid 296877] [client 20.197.195.24:13804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/admin.php"] [unique_id "al9NLin25uliftkV1n7-sgAAACw"]
[Tue Jul 21 07:42:54.244265 2026] [security2:error] [pid 296703:tid 296891] [client 20.226.60.151:56221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9NLin25uliftkV1n7-swAAADo"]
[Tue Jul 21 07:42:54.361322 2026] [security2:error] [pid 296703:tid 296837] [client 20.226.60.151:59444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/yawa.php"] [unique_id "al9NLin25uliftkV1n7-tAAAAAQ"]
[Tue Jul 21 07:42:54.381494 2026] [security2:error] [pid 296703:tid 296922] [client 20.197.195.24:44697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/fpwch.php"] [unique_id "al9NLin25uliftkV1n7-tQAAAFk"]
[Tue Jul 21 07:42:54.413852 2026] [security2:error] [pid 296703:tid 296911] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/chosen.php"] [unique_id "al9NLin25uliftkV1n7-tgAAAE4"]
[Tue Jul 21 07:42:54.416521 2026] [security2:error] [pid 296703:tid 296846] [client 122.186.204.214:57460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-twAAAA0"]
[Tue Jul 21 07:42:54.416617 2026] [security2:error] [pid 296703:tid 296846] [client 122.186.204.214:57460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-twAAAA0"]
[Tue Jul 21 07:42:54.432800 2026] [security2:error] [pid 296703:tid 296870] [client 103.86.117.203:54553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-uQAAACU"]
[Tue Jul 21 07:42:54.432908 2026] [security2:error] [pid 296703:tid 296870] [client 103.86.117.203:54553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-uQAAACU"]
[Tue Jul 21 07:42:54.437045 2026] [security2:error] [pid 296703:tid 296893] [client 20.104.96.117:64015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/abcd.php"] [unique_id "al9NLin25uliftkV1n7-ugAAADw"]
[Tue Jul 21 07:42:54.438976 2026] [security2:error] [pid 296703:tid 296901] [client 20.220.225.223:5257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/hp3.php"] [unique_id "al9NLin25uliftkV1n7-uwAAAEQ"]
[Tue Jul 21 07:42:54.514490 2026] [security2:error] [pid 296703:tid 296855] [client 20.197.195.24:44777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/domvf.php"] [unique_id "al9NLin25uliftkV1n7-wQAAABY"]
[Tue Jul 21 07:42:54.664304 2026] [security2:error] [pid 296703:tid 296839] [client 20.197.195.24:13638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp.php"] [unique_id "al9NLin25uliftkV1n7-zAAAAAY"]
[Tue Jul 21 07:42:54.673966 2026] [security2:error] [pid 296703:tid 296873] [client 122.164.127.47:55780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-zgAAACg"]
[Tue Jul 21 07:42:54.674132 2026] [security2:error] [pid 296703:tid 296873] [client 122.164.127.47:55780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-zgAAACg"]
[Tue Jul 21 07:42:54.720656 2026] [security2:error] [pid 296703:tid 296918] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/cream1.php"] [unique_id "al9NLin25uliftkV1n7-0gAAAFU"]
[Tue Jul 21 07:42:54.774057 2026] [security2:error] [pid 296703:tid 296844] [client 20.104.96.117:5113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/file15.php"] [unique_id "al9NLin25uliftkV1n7-1QAAAAs"]
[Tue Jul 21 07:42:54.892246 2026] [security2:error] [pid 296703:tid 296837] [client 20.197.195.24:44738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/class.php"] [unique_id "al9NLin25uliftkV1n7-2QAAAAQ"]
[Tue Jul 21 07:42:54.912222 2026] [security2:error] [pid 296703:tid 296911] [client 20.220.225.223:5260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/aa1.php"] [unique_id "al9NLin25uliftkV1n7-3AAAAE4"]
[Tue Jul 21 07:42:54.915054 2026] [security2:error] [pid 296703:tid 296762] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-2wAAMDo"]
[Tue Jul 21 07:42:54.915231 2026] [security2:error] [pid 296703:tid 296881] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLin25uliftkV1n7-2wAAMDo"]
[Tue Jul 21 07:42:55.014268 2026] [autoindex:error] [pid 296703:tid 296952] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:55.026313 2026] [security2:error] [pid 296703:tid 296901] [client 20.151.10.161:12093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-load.php"] [unique_id "al9NLyn25uliftkV1n7-4AAAAEQ"]
[Tue Jul 21 07:42:55.062923 2026] [security2:error] [pid 296703:tid 296889] [client 37.140.223.118:49387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NLyn25uliftkV1n7-4wAAADg"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:55.092514 2026] [security2:error] [pid 296703:tid 296835] [client 20.104.96.117:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/jp.php"] [unique_id "al9NLyn25uliftkV1n7-5gAAAAI"]
[Tue Jul 21 07:42:55.119092 2026] [security2:error] [pid 296703:tid 296887] [client 20.226.60.151:59497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/js.php"] [unique_id "al9NLyn25uliftkV1n7-6AAAADY"]
[Tue Jul 21 07:42:55.160567 2026] [security2:error] [pid 296703:tid 296953] [client 20.226.60.151:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/.well-known/about.php"] [unique_id "al9NLyn25uliftkV1n7-6QAAAHg"]
[Tue Jul 21 07:42:55.183374 2026] [autoindex:error] [pid 296703:tid 296951] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:55.225402 2026] [security2:error] [pid 296703:tid 296899] [client 20.197.195.24:44730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/echkm.php"] [unique_id "al9NLyn25uliftkV1n7-8AAAAEI"]
[Tue Jul 21 07:42:55.349649 2026] [security2:error] [pid 296703:tid 296885] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/dr.php"] [unique_id "al9NLyn25uliftkV1n7-8gAAADQ"]
[Tue Jul 21 07:42:55.369274 2026] [security2:error] [pid 296703:tid 296935] [client 20.197.195.24:13689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/lib.php"] [unique_id "al9NLyn25uliftkV1n7-8wAAAGY"]
[Tue Jul 21 07:42:55.428773 2026] [security2:error] [pid 296703:tid 296945] [client 20.197.195.24:13577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/login.php"] [unique_id "al9NLyn25uliftkV1n7-9QAAAHA"]
[Tue Jul 21 07:42:55.437739 2026] [proxy:error] [pid 296703:tid 296774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:55.437785 2026] [proxy_http:error] [pid 296703:tid 296774] [remote 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:55.438392 2026] [proxy:error] [pid 296703:tid 296774] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:55.438424 2026] [proxy_http:error] [pid 296703:tid 296774] [remote 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:55.443822 2026] [security2:error] [pid 296703:tid 296867] [client 20.104.96.117:5058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/f35.php"] [unique_id "al9NLyn25uliftkV1n7--AAAACI"]
[Tue Jul 21 07:42:55.491176 2026] [security2:error] [pid 296703:tid 296848] [client 20.197.195.24:44744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/a2.php"] [unique_id "al9NLyn25uliftkV1n7--QAAAA8"]
[Tue Jul 21 07:42:55.558472 2026] [security2:error] [pid 296703:tid 296888] [client 143.244.57.90:44282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "links.principiamatematica.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9NLyn25uliftkV1n7-_AAAADc"]
[Tue Jul 21 07:42:55.569855 2026] [security2:error] [pid 296703:tid 296908] [client 20.197.195.24:44731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/d61.php"] [unique_id "al9NLyn25uliftkV1n7-_gAAAEs"]
[Tue Jul 21 07:42:55.647552 2026] [security2:error] [pid 296703:tid 296929] [client 20.197.195.24:44765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/info.php"] [unique_id "al9NLyn25uliftkV1n7_BAAAAGA"]
[Tue Jul 21 07:42:55.752418 2026] [security2:error] [pid 296703:tid 296830] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9NLyn25uliftkV1n7_LwAAQn4"]
[Tue Jul 21 07:42:55.768369 2026] [security2:error] [pid 296703:tid 296845] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/x.php"] [unique_id "al9NLyn25uliftkV1n7_MgAAAAw"]
[Tue Jul 21 07:42:55.776036 2026] [security2:error] [pid 296703:tid 296935] [client 20.104.96.117:62919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-load.php"] [unique_id "al9NLyn25uliftkV1n7_NAAAAGY"]
[Tue Jul 21 07:42:55.888259 2026] [security2:error] [pid 296703:tid 296861] [client 20.220.225.223:5256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/acew67.php"] [unique_id "al9NLyn25uliftkV1n7_PAAAABw"]
[Tue Jul 21 07:42:56.007424 2026] [security2:error] [pid 296703:tid 296847] [client 20.226.60.151:59409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/core.php"] [unique_id "al9NMCn25uliftkV1n7_PwAAAA4"]
[Tue Jul 21 07:42:56.043493 2026] [security2:error] [pid 296703:tid 296705] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_QgAATgE"]
[Tue Jul 21 07:42:56.043664 2026] [security2:error] [pid 296703:tid 296911] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_QgAATgE"]
[Tue Jul 21 07:42:56.054073 2026] [security2:error] [pid 296703:tid 296870] [client 20.197.195.24:44764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/11.php"] [unique_id "al9NMCn25uliftkV1n7_RQAAACU"]
[Tue Jul 21 07:42:56.064630 2026] [security2:error] [pid 296703:tid 296949] [client 154.192.233.199:60039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_RwAAAHQ"]
[Tue Jul 21 07:42:56.064735 2026] [security2:error] [pid 296703:tid 296949] [client 154.192.233.199:60039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_RwAAAHQ"]
[Tue Jul 21 07:42:56.136262 2026] [security2:error] [pid 296703:tid 296917] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/155.php"] [unique_id "al9NMCn25uliftkV1n7_SwAAAFQ"]
[Tue Jul 21 07:42:56.138363 2026] [security2:error] [pid 296703:tid 296938] [client 20.226.60.151:54343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9NMCn25uliftkV1n7_TAAAAGk"]
[Tue Jul 21 07:42:56.205091 2026] [security2:error] [pid 296703:tid 296943] [client 20.104.96.117:64005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/xyn.php"] [unique_id "al9NMCn25uliftkV1n7_TQAAAG4"]
[Tue Jul 21 07:42:56.209417 2026] [security2:error] [pid 296703:tid 296936] [client 136.144.33.100:28699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NMCn25uliftkV1n7_QwAAAGc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:42:56.215860 2026] [security2:error] [pid 296703:tid 296912] [client 117.247.80.59:30314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLyn25uliftkV1n7-7wAAAE8"]
[Tue Jul 21 07:42:56.215968 2026] [security2:error] [pid 296703:tid 296912] [client 117.247.80.59:30314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NLyn25uliftkV1n7-7wAAAE8"]
[Tue Jul 21 07:42:56.290933 2026] [security2:error] [pid 296703:tid 296855] [client 194.99.104.35:47312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_UgAAABY"]
[Tue Jul 21 07:42:56.291008 2026] [security2:error] [pid 296703:tid 296855] [client 194.99.104.35:47312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_UgAAABY"]
[Tue Jul 21 07:42:56.317051 2026] [security2:error] [pid 296703:tid 296871] [client 20.197.195.24:44782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/v2.php"] [unique_id "al9NMCn25uliftkV1n7_UwAAACY"]
[Tue Jul 21 07:42:56.338163 2026] [security2:error] [pid 296703:tid 296920] [client 20.104.96.117:30432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9NMCn25uliftkV1n7_VAAAAFc"]
[Tue Jul 21 07:42:56.387878 2026] [security2:error] [pid 296703:tid 296837] [client 143.244.57.90:44298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "links.principiamatematica.com"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_VQAAAAQ"]
[Tue Jul 21 07:42:56.420907 2026] [security2:error] [pid 296703:tid 296923] [client 20.197.195.24:13661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/panel.php"] [unique_id "al9NMCn25uliftkV1n7_VwAAAFo"]
[Tue Jul 21 07:42:56.438818 2026] [security2:error] [pid 296703:tid 296910] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ops.php"] [unique_id "al9NMCn25uliftkV1n7_WAAAAE0"]
[Tue Jul 21 07:42:56.672068 2026] [security2:error] [pid 296703:tid 296728] [remote 159.223.41.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMCn25uliftkV1n7_YAAAXxg"]
[Tue Jul 21 07:42:56.738299 2026] [security2:error] [pid 296703:tid 296903] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/file31.php"] [unique_id "al9NMCn25uliftkV1n7_ZgAAAEY"]
[Tue Jul 21 07:42:56.742068 2026] [security2:error] [pid 296703:tid 296867] [client 20.197.195.24:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/dex.php"] [unique_id "al9NMCn25uliftkV1n7_aQAAACI"]
[Tue Jul 21 07:42:56.755870 2026] [security2:error] [pid 296703:tid 296934] [client 20.197.195.24:13747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/adminner.php"] [unique_id "al9NMCn25uliftkV1n7_bAAAAGU"]
[Tue Jul 21 07:42:56.939237 2026] [security2:error] [pid 296703:tid 296838] [client 20.226.60.151:33512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.samavidistribuicao.com.br"] [uri "/zc-131.php"] [unique_id "al9NMCn25uliftkV1n7_dQAAAAU"]
[Tue Jul 21 07:42:56.979823 2026] [proxy:error] [pid 296703:tid 296746] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:56.979886 2026] [proxy_http:error] [pid 296703:tid 296746] [remote 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:56.980328 2026] [proxy:error] [pid 296703:tid 296746] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:42:56.980354 2026] [proxy_http:error] [pid 296703:tid 296746] [remote 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:42:57.020934 2026] [security2:error] [pid 296703:tid 296886] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/file6.php"] [unique_id "al9NMSn25uliftkV1n7_egAAADU"]
[Tue Jul 21 07:42:57.110223 2026] [security2:error] [pid 296703:tid 296837] [client 20.197.195.24:44694] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "nrfilmes.com"] [uri "/1.php"] [unique_id "al9NMSn25uliftkV1n7_hAAAAAQ"]
[Tue Jul 21 07:42:57.110361 2026] [security2:error] [pid 296703:tid 296837] [client 20.197.195.24:44694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/1.php"] [unique_id "al9NMSn25uliftkV1n7_hAAAAAQ"]
[Tue Jul 21 07:42:57.260409 2026] [security2:error] [pid 296703:tid 296845] [client 117.217.38.194:51057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMSn25uliftkV1n7_mgAAAAw"]
[Tue Jul 21 07:42:57.260517 2026] [security2:error] [pid 296703:tid 296845] [client 117.217.38.194:51057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMSn25uliftkV1n7_mgAAAAw"]
[Tue Jul 21 07:42:57.292572 2026] [security2:error] [pid 296703:tid 296793] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NMSn25uliftkV1n7_rAAAUVk"]
[Tue Jul 21 07:42:57.313086 2026] [security2:error] [pid 296703:tid 296902] [client 74.249.245.134:5539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/amax.php"] [unique_id "al9NMSn25uliftkV1n7_sAAAAEU"]
[Tue Jul 21 07:42:57.313950 2026] [autoindex:error] [pid 296703:tid 296834] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:57.434611 2026] [security2:error] [pid 296703:tid 296925] [client 20.220.225.223:5304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/bscclapb.php"] [unique_id "al9NMSn25uliftkV1n7_uQAAAFw"]
[Tue Jul 21 07:42:57.465918 2026] [security2:error] [pid 296703:tid 296848] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/adminfuns.php"] [unique_id "al9NMSn25uliftkV1n7_ugAAAA8"]
[Tue Jul 21 07:42:57.468347 2026] [security2:error] [pid 296703:tid 296839] [client 20.197.195.24:44795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/ms.php"] [unique_id "al9NMSn25uliftkV1n7_uwAAAAY"]
[Tue Jul 21 07:42:57.507875 2026] [security2:error] [pid 296703:tid 296861] [client 20.226.60.151:59483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/19.php"] [unique_id "al9NMSn25uliftkV1n7_vQAAABw"]
[Tue Jul 21 07:42:57.562293 2026] [security2:error] [pid 296703:tid 296938] [client 20.104.96.117:4180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ccc.php"] [unique_id "al9NMSn25uliftkV1n7_wwAAAGk"]
[Tue Jul 21 07:42:57.602182 2026] [security2:error] [pid 296703:tid 296791] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9NMSn25uliftkV1n7_xQAAblc"]
[Tue Jul 21 07:42:57.748122 2026] [security2:error] [pid 296703:tid 296874] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/goods.php"] [unique_id "al9NMSn25uliftkV1n7_ywAAACk"]
[Tue Jul 21 07:42:57.855709 2026] [autoindex:error] [pid 296703:tid 296960] [client 20.197.195.24:44685] AH01276: Cannot serve directory /home2/ren85318/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:57.880238 2026] [security2:error] [pid 296703:tid 296889] [client 20.197.195.24:44685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/memberfuns.php"] [unique_id "al9NMSn25uliftkV1n7_1AAAADg"]
[Tue Jul 21 07:42:57.913490 2026] [security2:error] [pid 296703:tid 296816] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NMSn25uliftkV1n7_1wAAZHA"]
[Tue Jul 21 07:42:58.021732 2026] [security2:error] [pid 296703:tid 296867] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/100.php"] [unique_id "al9NMin25uliftkV1n7_2wAAACI"]
[Tue Jul 21 07:42:58.071018 2026] [security2:error] [pid 296703:tid 296862] [client 20.226.60.151:50910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/inc.php"] [unique_id "al9NMin25uliftkV1n7_3QAAAB0"]
[Tue Jul 21 07:42:58.112765 2026] [security2:error] [pid 296703:tid 296729] [remote 182.77.62.24:39230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moratoadvogado.com"] [uri "/wp-login.php"] [unique_id "al9NMin25uliftkV1n7_4wAALRk"]
[Tue Jul 21 07:42:58.136429 2026] [security2:error] [pid 296703:tid 296952] [client 20.197.195.24:44748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/0.php"] [unique_id "al9NMin25uliftkV1n7_5gAAAHc"]
[Tue Jul 21 07:42:58.180710 2026] [security2:error] [pid 296703:tid 296939] [client 59.96.220.140:59016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NMin25uliftkV1n7_7QAAAGo"]
[Tue Jul 21 07:42:58.180824 2026] [security2:error] [pid 296703:tid 296939] [client 59.96.220.140:59016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NMin25uliftkV1n7_7QAAAGo"]
[Tue Jul 21 07:42:58.197984 2026] [security2:error] [pid 296703:tid 296847] [client 136.144.33.25:26499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NMin25uliftkV1n7_3AAAAA4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:42:58.220745 2026] [security2:error] [pid 296703:tid 296792] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9NMin25uliftkV1n7_7gAABVg"]
[Tue Jul 21 07:42:58.251535 2026] [security2:error] [pid 296703:tid 296896] [client 20.104.96.117:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/w.php"] [unique_id "al9NMin25uliftkV1n7_8QAAAD8"]
[Tue Jul 21 07:42:58.301516 2026] [security2:error] [pid 296703:tid 296912] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/about.php"] [unique_id "al9NMin25uliftkV1n7_8wAAAE8"]
[Tue Jul 21 07:42:58.309175 2026] [security2:error] [pid 296703:tid 296835] [client 103.106.20.201:53746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMin25uliftkV1n7_9AAAAAI"]
[Tue Jul 21 07:42:58.309286 2026] [security2:error] [pid 296703:tid 296835] [client 103.106.20.201:53746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMin25uliftkV1n7_9AAAAAI"]
[Tue Jul 21 07:42:58.309862 2026] [security2:error] [pid 296703:tid 296886] [client 20.197.195.24:44677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/BDKR28.php"] [unique_id "al9NMin25uliftkV1n7_9QAAADU"]
[Tue Jul 21 07:42:58.535306 2026] [security2:error] [pid 296703:tid 296748] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NMin25uliftkV1n4AFwAAcCw"]
[Tue Jul 21 07:42:58.599575 2026] [security2:error] [pid 296703:tid 296862] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/about.php"] [unique_id "al9NMin25uliftkV1n4AHwAAAB0"]
[Tue Jul 21 07:42:58.643194 2026] [security2:error] [pid 296703:tid 296911] [client 20.197.195.24:44746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/green1.php"] [unique_id "al9NMin25uliftkV1n4AJwAAAE4"]
[Tue Jul 21 07:42:58.700892 2026] [security2:error] [pid 296703:tid 296847] [client 20.226.60.151:59467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-ppoxua4.php"] [unique_id "al9NMin25uliftkV1n4ALAAAAA4"]
[Tue Jul 21 07:42:58.773104 2026] [security2:error] [pid 296703:tid 296912] [client 20.226.60.151:54337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wefile.php"] [unique_id "al9NMin25uliftkV1n4ANgAAAE8"]
[Tue Jul 21 07:42:58.797044 2026] [security2:error] [pid 296703:tid 296868] [client 122.162.144.145:1645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NMin25uliftkV1n4ANwAAACM"]
[Tue Jul 21 07:42:58.797143 2026] [security2:error] [pid 296703:tid 296868] [client 122.162.144.145:1645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NMin25uliftkV1n4ANwAAACM"]
[Tue Jul 21 07:42:58.824179 2026] [security2:error] [pid 296703:tid 296860] [client 20.104.96.117:64044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9NMin25uliftkV1n4AOQAAABs"]
[Tue Jul 21 07:42:58.842538 2026] [security2:error] [pid 296703:tid 296757] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9NMin25uliftkV1n4AOgAAPjU"]
[Tue Jul 21 07:42:58.874673 2026] [security2:error] [pid 296703:tid 296932] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/admin.php"] [unique_id "al9NMin25uliftkV1n4AOwAAAGM"]
[Tue Jul 21 07:42:58.974001 2026] [security2:error] [pid 296703:tid 296940] [client 20.197.195.24:13812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/admin.php"] [unique_id "al9NMin25uliftkV1n4AQAAAAGs"]
[Tue Jul 21 07:42:59.148364 2026] [security2:error] [pid 296703:tid 296835] [client 154.92.130.87:44333] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://:"] [hostname "www.startonesite.com.br"] [uri "/"] [unique_id "al9NMyn25uliftkV1n4ASQAAAAI"]
[Tue Jul 21 07:42:59.154577 2026] [security2:error] [pid 296703:tid 296809] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9NMyn25uliftkV1n4ASgAAJ2k"]
[Tue Jul 21 07:42:59.166332 2026] [security2:error] [pid 296703:tid 296903] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/admin.php"] [unique_id "al9NMyn25uliftkV1n4ATAAAAEY"]
[Tue Jul 21 07:42:59.209305 2026] [security2:error] [pid 296703:tid 296866] [client 20.104.96.117:64029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/FWAZ.php"] [unique_id "al9NMyn25uliftkV1n4ATQAAACE"]
[Tue Jul 21 07:42:59.305412 2026] [security2:error] [pid 296703:tid 296843] [client 152.59.154.239:5394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMyn25uliftkV1n4AVAAAAAo"]
[Tue Jul 21 07:42:59.309851 2026] [security2:error] [pid 296703:tid 296843] [client 152.59.154.239:5394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMyn25uliftkV1n4AVAAAAAo"]
[Tue Jul 21 07:42:59.350954 2026] [security2:error] [pid 296703:tid 296914] [client 20.197.195.24:13589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/nc4.php"] [unique_id "al9NMyn25uliftkV1n4AVgAAAFE"]
[Tue Jul 21 07:42:59.409472 2026] [security2:error] [pid 296703:tid 296861] [client 20.226.60.151:59450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-u3nxbvx.php"] [unique_id "al9NMyn25uliftkV1n4AWAAAABw"]
[Tue Jul 21 07:42:59.448592 2026] [security2:error] [pid 296703:tid 296950] [client 139.167.225.182:51236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMyn25uliftkV1n4AWQAAAHU"]
[Tue Jul 21 07:42:59.450163 2026] [security2:error] [pid 296703:tid 296950] [client 139.167.225.182:51236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NMyn25uliftkV1n4AWQAAAHU"]
[Tue Jul 21 07:42:59.475564 2026] [security2:error] [pid 296703:tid 296789] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NMyn25uliftkV1n4AXQAARFU"]
[Tue Jul 21 07:42:59.542024 2026] [security2:error] [pid 296703:tid 296923] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/themes.php"] [unique_id "al9NMyn25uliftkV1n4AYAAAAFo"]
[Tue Jul 21 07:42:59.639294 2026] [security2:error] [pid 296703:tid 296851] [client 20.104.96.117:5089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/miru1.php"] [unique_id "al9NMyn25uliftkV1n4AYwAAABI"]
[Tue Jul 21 07:42:59.777370 2026] [security2:error] [pid 296703:tid 296947] [client 20.226.60.151:56301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ss.php"] [unique_id "al9NMyn25uliftkV1n4AawAAAHI"]
[Tue Jul 21 07:42:59.787488 2026] [security2:error] [pid 296703:tid 296731] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NMyn25uliftkV1n4AbAAAShs"]
[Tue Jul 21 07:42:59.815497 2026] [security2:error] [pid 296703:tid 296866] [client 20.197.195.24:13660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/a1.php"] [unique_id "al9NMyn25uliftkV1n4AbQAAACE"]
[Tue Jul 21 07:42:59.852667 2026] [autoindex:error] [pid 296703:tid 296945] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:42:59.883161 2026] [security2:error] [pid 296703:tid 296834] [client 20.226.60.151:22964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/green1.php"] [unique_id "al9NMyn25uliftkV1n4AcAAAAAE"]
[Tue Jul 21 07:43:00.025146 2026] [autoindex:error] [pid 296703:tid 296801] [remote 74.7.227.60:58968] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/conhecaonordeste.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:00.045615 2026] [security2:error] [pid 296703:tid 296869] [client 74.7.228.57:47238] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "conhecaonordeste.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9NNCn25uliftkV1n4AeAAAJGA"]
[Tue Jul 21 07:43:00.046221 2026] [security2:error] [pid 296703:tid 296838] [client 20.104.96.117:5098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/aa.php"] [unique_id "al9NNCn25uliftkV1n4AeQAAAAU"]
[Tue Jul 21 07:43:00.093677 2026] [security2:error] [pid 296703:tid 296791] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NNCn25uliftkV1n4AfAAAUVc"]
[Tue Jul 21 07:43:00.112220 2026] [security2:error] [pid 296703:tid 296876] [client 20.151.10.161:11656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xwpg.php"] [unique_id "al9NNCn25uliftkV1n4AfQAAACs"]
[Tue Jul 21 07:43:00.127591 2026] [security2:error] [pid 296703:tid 296902] [client 20.197.195.24:44681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/eee.php"] [unique_id "al9NNCn25uliftkV1n4AfgAAAEU"]
[Tue Jul 21 07:43:00.166696 2026] [security2:error] [pid 296703:tid 296861] [client 20.226.60.151:50821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ss.php"] [unique_id "al9NNCn25uliftkV1n4AgAAAABw"]
[Tue Jul 21 07:43:00.296843 2026] [security2:error] [pid 296703:tid 296860] [client 20.226.60.151:51230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/min.php"] [unique_id "al9NNCn25uliftkV1n4AiAAAABs"]
[Tue Jul 21 07:43:00.366221 2026] [security2:error] [pid 296703:tid 296887] [client 20.104.96.117:5117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/122.php"] [unique_id "al9NNCn25uliftkV1n4AigAAADY"]
[Tue Jul 21 07:43:00.375668 2026] [security2:error] [pid 296703:tid 296960] [client 20.197.195.24:44745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/wp-aothait.php"] [unique_id "al9NNCn25uliftkV1n4AiwAAAH8"]
[Tue Jul 21 07:43:00.406098 2026] [security2:error] [pid 296703:tid 296797] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NNCn25uliftkV1n4AjAAAEl0"]
[Tue Jul 21 07:43:00.431136 2026] [security2:error] [pid 296703:tid 296928] [client 20.226.60.151:54326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9NNCn25uliftkV1n4AjQAAAF8"]
[Tue Jul 21 07:43:00.468380 2026] [security2:error] [pid 296703:tid 296855] [client 20.226.60.151:56246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9NNCn25uliftkV1n4AjwAAABY"]
[Tue Jul 21 07:43:00.524888 2026] [security2:error] [pid 296703:tid 296885] [client 20.226.60.151:59431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/min.php"] [unique_id "al9NNCn25uliftkV1n4AlgAAADQ"]
[Tue Jul 21 07:43:00.538930 2026] [security2:error] [pid 296703:tid 296849] [client 20.226.60.151:56311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9NNCn25uliftkV1n4AlwAAABA"]
[Tue Jul 21 07:43:00.565335 2026] [security2:error] [pid 296703:tid 296945] [client 20.197.195.24:13607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/config.json.php"] [unique_id "al9NNCn25uliftkV1n4AmAAAAHA"]
[Tue Jul 21 07:43:00.566602 2026] [security2:error] [pid 296703:tid 296751] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NNCn25uliftkV1n4AmQAAbi8"]
[Tue Jul 21 07:43:00.566740 2026] [security2:error] [pid 296703:tid 296943] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NNCn25uliftkV1n4AmQAAbi8"]
[Tue Jul 21 07:43:00.590373 2026] [security2:error] [pid 296703:tid 296952] [client 20.220.225.223:11159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/else1.php"] [unique_id "al9NNCn25uliftkV1n4AmgAAAHc"]
[Tue Jul 21 07:43:00.626593 2026] [security2:error] [pid 296703:tid 296922] [client 20.197.195.24:44707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9NNCn25uliftkV1n4AmwAAAFk"]
[Tue Jul 21 07:43:00.644599 2026] [security2:error] [pid 296703:tid 296958] [client 143.244.57.90:44328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "links.principiamatematica.com"] [uri "/xmlrpc.php"] [unique_id "al9NNCn25uliftkV1n4AnAAAAH0"]
[Tue Jul 21 07:43:00.644698 2026] [security2:error] [pid 296703:tid 296958] [client 143.244.57.90:44328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "links.principiamatematica.com"] [uri "/xmlrpc.php"] [unique_id "al9NNCn25uliftkV1n4AnAAAAH0"]
[Tue Jul 21 07:43:00.656114 2026] [security2:error] [pid 296703:tid 296920] [client 20.226.60.151:51258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9NNCn25uliftkV1n4AnQAAAFc"]
[Tue Jul 21 07:43:00.686833 2026] [security2:error] [pid 296703:tid 296884] [client 20.104.96.117:5082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/get.php"] [unique_id "al9NNCn25uliftkV1n4AoAAAADM"]
[Tue Jul 21 07:43:00.713920 2026] [security2:error] [pid 296703:tid 296712] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9NNCn25uliftkV1n4AowAALgg"]
[Tue Jul 21 07:43:00.790637 2026] [security2:error] [pid 296703:tid 296954] [client 20.197.195.24:44754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/k2.php"] [unique_id "al9NNCn25uliftkV1n4ApwAAAHk"]
[Tue Jul 21 07:43:00.888466 2026] [security2:error] [pid 296703:tid 296894] [client 193.36.225.60:61979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NNCn25uliftkV1n4ArgAAAD0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:00.910059 2026] [security2:error] [pid 296703:tid 296858] [client 74.249.245.134:5525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/moon.php"] [unique_id "al9NNCn25uliftkV1n4ArwAAABk"]
[Tue Jul 21 07:43:01.026228 2026] [security2:error] [pid 296703:tid 296822] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9NNSn25uliftkV1n4AswAAC3Y"]
[Tue Jul 21 07:43:01.034928 2026] [security2:error] [pid 296703:tid 296837] [client 103.166.103.129:58692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4AtAAAAAQ"]
[Tue Jul 21 07:43:01.035033 2026] [security2:error] [pid 296703:tid 296837] [client 103.166.103.129:58692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4AtAAAAAQ"]
[Tue Jul 21 07:43:01.122202 2026] [security2:error] [pid 296703:tid 296935] [client 173.24.185.52:56465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4AuAAAAGY"]
[Tue Jul 21 07:43:01.122316 2026] [security2:error] [pid 296703:tid 296935] [client 173.24.185.52:56465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4AuAAAAGY"]
[Tue Jul 21 07:43:01.144039 2026] [security2:error] [pid 296703:tid 296903] [client 20.104.96.117:5059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/as.php"] [unique_id "al9NNSn25uliftkV1n4AuQAAAEY"]
[Tue Jul 21 07:43:01.170743 2026] [security2:error] [pid 296703:tid 296885] [client 20.220.225.223:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/bootstrap.php"] [unique_id "al9NNSn25uliftkV1n4AugAAADQ"]
[Tue Jul 21 07:43:01.218056 2026] [security2:error] [pid 296703:tid 296947] [client 122.179.91.63:2593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4AvgAAAHI"]
[Tue Jul 21 07:43:01.218218 2026] [security2:error] [pid 296703:tid 296947] [client 122.179.91.63:2593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4AvgAAAHI"]
[Tue Jul 21 07:43:01.318996 2026] [security2:error] [pid 296703:tid 296864] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/.well-known/about.php"] [unique_id "al9NNSn25uliftkV1n4AxAAAAB8"]
[Tue Jul 21 07:43:01.334263 2026] [security2:error] [pid 296703:tid 296721] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NNSn25uliftkV1n4AxwAAARE"]
[Tue Jul 21 07:43:01.530019 2026] [security2:error] [pid 296703:tid 296906] [client 20.104.96.117:5079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ccou.php"] [unique_id "al9NNSn25uliftkV1n4AzgAAAEk"]
[Tue Jul 21 07:43:01.542063 2026] [autoindex:error] [pid 296703:tid 296876] [client 20.226.60.151:54348] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:01.553095 2026] [security2:error] [pid 296703:tid 296938] [client 20.226.60.151:50943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9NNSn25uliftkV1n4A0AAAAGk"]
[Tue Jul 21 07:43:01.617114 2026] [security2:error] [pid 296703:tid 296923] [client 20.197.195.24:44689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/uiuvs58l.php"] [unique_id "al9NNSn25uliftkV1n4A1QAAAFo"]
[Tue Jul 21 07:43:01.620203 2026] [autoindex:error] [pid 296703:tid 296861] [client 20.226.60.151:54348] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:01.625654 2026] [security2:error] [pid 296703:tid 296839] [client 20.226.60.151:54348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9NNSn25uliftkV1n4A1wAAAAY"]
[Tue Jul 21 07:43:01.646351 2026] [security2:error] [pid 296703:tid 296738] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NNSn25uliftkV1n4A2gAAMCI"]
[Tue Jul 21 07:43:01.818747 2026] [security2:error] [pid 296703:tid 296947] [client 20.104.96.117:30627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/classwithtostring.php"] [unique_id "al9NNSn25uliftkV1n4A4AAAAHI"]
[Tue Jul 21 07:43:01.818948 2026] [security2:error] [pid 296703:tid 296888] [client 37.140.223.190:26681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NNSn25uliftkV1n4A2wAAADc"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:01.819319 2026] [security2:error] [pid 296703:tid 296907] [client 74.249.245.134:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/ws83.php"] [unique_id "al9NNSn25uliftkV1n4A4QAAAEo"]
[Tue Jul 21 07:43:01.825466 2026] [security2:error] [pid 296703:tid 296951] [client 194.99.104.35:46230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4A4gAAAHY"]
[Tue Jul 21 07:43:01.825527 2026] [security2:error] [pid 296703:tid 296951] [client 194.99.104.35:46230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4A4gAAAHY"]
[Tue Jul 21 07:43:01.835064 2026] [security2:error] [pid 296703:tid 296710] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4A4wAAJwY"]
[Tue Jul 21 07:43:01.835227 2026] [security2:error] [pid 296703:tid 296872] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NNSn25uliftkV1n4A4wAAJwY"]
[Tue Jul 21 07:43:01.857760 2026] [security2:error] [pid 296703:tid 296908] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9NNSn25uliftkV1n4A5gAAAEs"]
[Tue Jul 21 07:43:01.912464 2026] [security2:error] [pid 296703:tid 296945] [client 20.197.195.24:13147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/40p9ixjd.php"] [unique_id "al9NNSn25uliftkV1n4A6AAAAHA"]
[Tue Jul 21 07:43:01.953075 2026] [security2:error] [pid 296703:tid 296717] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.raphaelicarolicitacoes.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9NNSn25uliftkV1n4A6gAABw0"]
[Tue Jul 21 07:43:01.983220 2026] [security2:error] [pid 296703:tid 296866] [client 20.104.96.117:64011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/w3lls.php"] [unique_id "al9NNSn25uliftkV1n4A6wAAACE"]
[Tue Jul 21 07:43:02.063293 2026] [security2:error] [pid 296703:tid 296848] [client 20.226.60.151:51260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9NNin25uliftkV1n4A7QAAAA8"]
[Tue Jul 21 07:43:02.140655 2026] [security2:error] [pid 296703:tid 296876] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wefile.php"] [unique_id "al9NNin25uliftkV1n4A8QAAACs"]
[Tue Jul 21 07:43:02.277742 2026] [security2:error] [pid 296703:tid 296869] [client 20.197.195.24:13616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9NNin25uliftkV1n4A9AAAACQ"]
[Tue Jul 21 07:43:02.302356 2026] [security2:error] [pid 296703:tid 296910] [client 20.104.96.117:5096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/test1.php"] [unique_id "al9NNin25uliftkV1n4A9QAAAE0"]
[Tue Jul 21 07:43:02.419058 2026] [security2:error] [pid 296703:tid 296837] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9NNin25uliftkV1n4A-gAAAAQ"]
[Tue Jul 21 07:43:02.580751 2026] [security2:error] [pid 296703:tid 296947] [client 20.197.195.24:13580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/for.php"] [unique_id "al9NNin25uliftkV1n4A_gAAAHI"]
[Tue Jul 21 07:43:02.581809 2026] [security2:error] [pid 296703:tid 296888] [client 20.226.60.151:54292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/8.php"] [unique_id "al9NNin25uliftkV1n4A_wAAADc"]
[Tue Jul 21 07:43:02.685013 2026] [security2:error] [pid 296703:tid 296954] [client 20.104.96.117:62943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/database.php"] [unique_id "al9NNin25uliftkV1n4BAwAAAHk"]
[Tue Jul 21 07:43:02.706365 2026] [autoindex:error] [pid 296703:tid 296834] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:02.727128 2026] [security2:error] [pid 296703:tid 296917] [client 20.197.195.24:44797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/raw.php"] [unique_id "al9NNin25uliftkV1n4BBQAAAFQ"]
[Tue Jul 21 07:43:02.819169 2026] [security2:error] [pid 296703:tid 296716] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NNin25uliftkV1n4BDQAAMgw"]
[Tue Jul 21 07:43:02.819341 2026] [security2:error] [pid 296703:tid 296883] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NNin25uliftkV1n4BDQAAMgw"]
[Tue Jul 21 07:43:02.862806 2026] [security2:error] [pid 296703:tid 296867] [client 20.226.60.151:51253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/albin.php"] [unique_id "al9NNin25uliftkV1n4BDwAAACI"]
[Tue Jul 21 07:43:02.899739 2026] [security2:error] [pid 296703:tid 296762] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NNin25uliftkV1n4BFAAABTo"]
[Tue Jul 21 07:43:02.899933 2026] [security2:error] [pid 296703:tid 296838] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NNin25uliftkV1n4BFAAABTo"]
[Tue Jul 21 07:43:02.902711 2026] [autoindex:error] [pid 296703:tid 296870] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:02.952901 2026] [security2:error] [pid 296703:tid 296952] [client 20.220.225.223:19303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wp-editor.php"] [unique_id "al9NNin25uliftkV1n4BFQAAAHc"]
[Tue Jul 21 07:43:02.978904 2026] [security2:error] [pid 296703:tid 296876] [client 20.104.96.117:62912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/file.php"] [unique_id "al9NNin25uliftkV1n4BFwAAACs"]
[Tue Jul 21 07:43:03.047607 2026] [security2:error] [pid 296703:tid 296896] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9NNyn25uliftkV1n4BGQAAAD8"]
[Tue Jul 21 07:43:03.124180 2026] [security2:error] [pid 296703:tid 296869] [client 20.220.225.223:5285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/tkikikoko.php"] [unique_id "al9NNyn25uliftkV1n4BGwAAACQ"]
[Tue Jul 21 07:43:03.162318 2026] [security2:error] [pid 296703:tid 296910] [client 20.197.195.24:13787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/k.php"] [unique_id "al9NNyn25uliftkV1n4BHgAAAE0"]
[Tue Jul 21 07:43:03.243471 2026] [security2:error] [pid 296703:tid 296918] [client 20.226.60.151:54325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9NNyn25uliftkV1n4BIAAAAFU"]
[Tue Jul 21 07:43:03.278210 2026] [security2:error] [pid 296703:tid 296936] [client 20.104.96.117:5088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/file.php"] [unique_id "al9NNyn25uliftkV1n4BIgAAAGc"]
[Tue Jul 21 07:43:03.402199 2026] [security2:error] [pid 296703:tid 296919] [client 106.215.181.8:9549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NNyn25uliftkV1n4BJAAAAFY"]
[Tue Jul 21 07:43:03.402305 2026] [security2:error] [pid 296703:tid 296919] [client 106.215.181.8:9549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NNyn25uliftkV1n4BJAAAAFY"]
[Tue Jul 21 07:43:03.573879 2026] [security2:error] [pid 296703:tid 296880] [client 20.104.96.117:62952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/777.php"] [unique_id "al9NNyn25uliftkV1n4BLQAAAC8"]
[Tue Jul 21 07:43:03.636909 2026] [security2:error] [pid 296703:tid 296841] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/8.php"] [unique_id "al9NNyn25uliftkV1n4BLgAAAAg"]
[Tue Jul 21 07:43:03.826573 2026] [security2:error] [pid 296703:tid 296952] [client 74.249.245.134:5518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/CDX1.php"] [unique_id "al9NNyn25uliftkV1n4BNgAAAHc"]
[Tue Jul 21 07:43:03.859846 2026] [security2:error] [pid 296703:tid 296924] [client 20.226.60.151:54331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/f6.php"] [unique_id "al9NNyn25uliftkV1n4BNwAAAFs"]
[Tue Jul 21 07:43:03.911525 2026] [security2:error] [pid 296703:tid 296863] [client 20.104.96.117:5102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ssixta.php"] [unique_id "al9NNyn25uliftkV1n4BOAAAAB4"]
[Tue Jul 21 07:43:03.915348 2026] [security2:error] [pid 296703:tid 296896] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9NNyn25uliftkV1n4BOQAAAD8"]
[Tue Jul 21 07:43:04.024748 2026] [security2:error] [pid 296703:tid 296765] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BQAAAKT0"]
[Tue Jul 21 07:43:04.024920 2026] [security2:error] [pid 296703:tid 296874] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BQAAAKT0"]
[Tue Jul 21 07:43:04.186166 2026] [security2:error] [pid 296703:tid 296953] [client 182.8.255.181:17482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BRgAAAHg"]
[Tue Jul 21 07:43:04.186267 2026] [security2:error] [pid 296703:tid 296953] [client 182.8.255.181:17482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BRgAAAHg"]
[Tue Jul 21 07:43:04.189408 2026] [security2:error] [pid 296703:tid 296846] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/f6.php"] [unique_id "al9NOCn25uliftkV1n4BRwAAAA0"]
[Tue Jul 21 07:43:04.216230 2026] [security2:error] [pid 296703:tid 296918] [client 20.104.96.117:5072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/1c.php"] [unique_id "al9NOCn25uliftkV1n4BSQAAAFU"]
[Tue Jul 21 07:43:04.234304 2026] [security2:error] [pid 296703:tid 296938] [client 20.226.60.151:51237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/cilus.php"] [unique_id "al9NOCn25uliftkV1n4BTAAAAGk"]
[Tue Jul 21 07:43:04.324844 2026] [security2:error] [pid 296703:tid 296778] [remote 199.189.225.40:45059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9NOCn25uliftkV1n4BTgAAYEo"]
[Tue Jul 21 07:43:04.370552 2026] [security2:error] [pid 296703:tid 296950] [client 20.220.225.223:34206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wp-wpbak.php"] [unique_id "al9NOCn25uliftkV1n4BUAAAAHU"]
[Tue Jul 21 07:43:04.429046 2026] [security2:error] [pid 296703:tid 296845] [client 103.174.34.15:57586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BUgAAAAw"]
[Tue Jul 21 07:43:04.429166 2026] [security2:error] [pid 296703:tid 296845] [client 103.174.34.15:57586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BUgAAAAw"]
[Tue Jul 21 07:43:04.503991 2026] [security2:error] [pid 296703:tid 296862] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/inputs.php"] [unique_id "al9NOCn25uliftkV1n4BVAAAAB0"]
[Tue Jul 21 07:43:04.517425 2026] [security2:error] [pid 296703:tid 296917] [client 20.104.96.117:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/test2.php"] [unique_id "al9NOCn25uliftkV1n4BVQAAAFQ"]
[Tue Jul 21 07:43:04.544459 2026] [security2:error] [pid 296703:tid 296871] [client 62.102.148.187:51348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BVgAAACY"]
[Tue Jul 21 07:43:04.544533 2026] [security2:error] [pid 296703:tid 296871] [client 62.102.148.187:51348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BVgAAACY"]
[Tue Jul 21 07:43:04.709699 2026] [security2:error] [pid 296703:tid 296763] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BYQAAFjs"]
[Tue Jul 21 07:43:04.709839 2026] [security2:error] [pid 296703:tid 296855] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BYQAAFjs"]
[Tue Jul 21 07:43:04.821544 2026] [security2:error] [pid 296703:tid 296861] [client 20.104.96.117:62973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/buy.php"] [unique_id "al9NOCn25uliftkV1n4BagAAABw"]
[Tue Jul 21 07:43:04.893832 2026] [security2:error] [pid 296703:tid 296935] [client 193.36.225.61:56869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NOCn25uliftkV1n4BYgAAAGY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:04.902650 2026] [security2:error] [pid 296703:tid 296864] [client 20.226.60.151:63578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/autoload_classmap.php"] [unique_id "al9NOCn25uliftkV1n4BcgAAAB8"]
[Tue Jul 21 07:43:04.909130 2026] [security2:error] [pid 296703:tid 296881] [client 103.86.117.203:55093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BcwAAADA"]
[Tue Jul 21 07:43:04.909242 2026] [security2:error] [pid 296703:tid 296881] [client 103.86.117.203:55093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NOCn25uliftkV1n4BcwAAADA"]
[Tue Jul 21 07:43:04.938051 2026] [security2:error] [pid 296703:tid 296837] [client 20.226.60.151:50974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/gptsh.php"] [unique_id "al9NOCn25uliftkV1n4BdwAAAAQ"]
[Tue Jul 21 07:43:05.061112 2026] [security2:error] [pid 296703:tid 296950] [client 20.226.60.151:61994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/inputs.php"] [unique_id "al9NOSn25uliftkV1n4BfQAAAHU"]
[Tue Jul 21 07:43:05.116593 2026] [security2:error] [pid 296703:tid 296859] [client 20.104.96.117:5067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ssend.php"] [unique_id "al9NOSn25uliftkV1n4BfgAAABo"]
[Tue Jul 21 07:43:05.124407 2026] [security2:error] [pid 296703:tid 296847] [client 122.186.204.214:57996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BfwAAAA4"]
[Tue Jul 21 07:43:05.124574 2026] [security2:error] [pid 296703:tid 296847] [client 122.186.204.214:57996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BfwAAAA4"]
[Tue Jul 21 07:43:05.188967 2026] [security2:error] [pid 296703:tid 296960] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/inputs.php"] [unique_id "al9NOSn25uliftkV1n4BgQAAAH8"]
[Tue Jul 21 07:43:05.195184 2026] [security2:error] [pid 296703:tid 296873] [client 117.247.80.59:20206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BggAAACg"]
[Tue Jul 21 07:43:05.195289 2026] [security2:error] [pid 296703:tid 296873] [client 117.247.80.59:20206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BggAAACg"]
[Tue Jul 21 07:43:05.195667 2026] [security2:error] [pid 296703:tid 296884] [client 202.143.127.214:51852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BgwAAADM"]
[Tue Jul 21 07:43:05.196581 2026] [security2:error] [pid 296703:tid 296884] [client 202.143.127.214:51852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BgwAAADM"]
[Tue Jul 21 07:43:05.257767 2026] [security2:error] [pid 296703:tid 296954] [client 20.226.60.151:50970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/rithin.php"] [unique_id "al9NOSn25uliftkV1n4BiAAAAHk"]
[Tue Jul 21 07:43:05.311791 2026] [security2:error] [pid 296703:tid 296867] [client 122.164.127.47:56356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BiQAAACI"]
[Tue Jul 21 07:43:05.313098 2026] [security2:error] [pid 296703:tid 296867] [client 122.164.127.47:56356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NOSn25uliftkV1n4BiQAAACI"]
[Tue Jul 21 07:43:05.421620 2026] [security2:error] [pid 296703:tid 296933] [client 20.104.96.117:64048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/item.php"] [unique_id "al9NOSn25uliftkV1n4BjAAAAGQ"]
[Tue Jul 21 07:43:05.471292 2026] [security2:error] [pid 296703:tid 296860] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/classwithtostring.php"] [unique_id "al9NOSn25uliftkV1n4BjQAAABs"]
[Tue Jul 21 07:43:05.688573 2026] [security2:error] [pid 296703:tid 296820] [remote 202.51.202.242:56044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "legadoengenhariaam.com.br"] [uri "/wp-login.php"] [unique_id "al9NOSn25uliftkV1n4BlAAAY3Q"]
[Tue Jul 21 07:43:05.689080 2026] [security2:error] [pid 296703:tid 296903] [client 15.235.27.119:16214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aronimoveis.com.br"] [uri "/robots.txt"] [unique_id "al9NOSn25uliftkV1n4BlQAAAEY"]
[Tue Jul 21 07:43:05.689162 2026] [security2:error] [pid 296703:tid 296903] [client 15.235.27.119:16214] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aronimoveis.com.br"] [uri "/robots.txt"] [unique_id "al9NOSn25uliftkV1n4BlQAAAEY"]
[Tue Jul 21 07:43:05.759949 2026] [core:alert] [pid 296703:tid 296872] [client 57.141.18.65:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:43:05.785482 2026] [security2:error] [pid 296703:tid 296845] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9NOSn25uliftkV1n4BngAAAAw"]
[Tue Jul 21 07:43:05.789734 2026] [security2:error] [pid 296703:tid 296859] [client 20.104.96.117:62926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ss.php"] [unique_id "al9NOSn25uliftkV1n4BnwAAABo"]
[Tue Jul 21 07:43:06.016756 2026] [security2:error] [pid 296703:tid 296943] [client 20.197.195.24:49859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/blurbs.php"] [unique_id "al9NOin25uliftkV1n4BqAAAAG4"]
[Tue Jul 21 07:43:06.067863 2026] [security2:error] [pid 296703:tid 296841] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-blog.php"] [unique_id "al9NOin25uliftkV1n4BqgAAAAg"]
[Tue Jul 21 07:43:06.179850 2026] [security2:error] [pid 296703:tid 296906] [client 20.226.60.151:56274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/fffm.php"] [unique_id "al9NOin25uliftkV1n4BrwAAAEk"]
[Tue Jul 21 07:43:06.336616 2026] [security2:error] [pid 296703:tid 296870] [client 130.195.241.7:39949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.241.195.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bellascleaningsolutionsllc.com"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BtAAAACU"]
[Tue Jul 21 07:43:06.336735 2026] [security2:error] [pid 296703:tid 296870] [client 130.195.241.7:39949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bellascleaningsolutionsllc.com"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BtAAAACU"]
[Tue Jul 21 07:43:06.343251 2026] [security2:error] [pid 296703:tid 296861] [client 20.104.96.117:64009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/hypo.php"] [unique_id "al9NOin25uliftkV1n4BtQAAABw"]
[Tue Jul 21 07:43:06.401850 2026] [security2:error] [pid 296703:tid 296921] [client 20.220.225.223:19264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/cro.php"] [unique_id "al9NOin25uliftkV1n4BtgAAAFg"]
[Tue Jul 21 07:43:06.445315 2026] [autoindex:error] [pid 296703:tid 296938] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:06.512564 2026] [security2:error] [pid 296703:tid 296821] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BugAAW3U"]
[Tue Jul 21 07:43:06.512686 2026] [security2:error] [pid 296703:tid 296924] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BugAAW3U"]
[Tue Jul 21 07:43:06.602902 2026] [security2:error] [pid 296703:tid 296911] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9NOin25uliftkV1n4BvwAAAE4"]
[Tue Jul 21 07:43:06.619101 2026] [security2:error] [pid 296703:tid 296907] [client 74.249.245.134:5515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/inputs.php"] [unique_id "al9NOin25uliftkV1n4BwAAAAEo"]
[Tue Jul 21 07:43:06.677043 2026] [security2:error] [pid 296703:tid 296853] [client 20.104.96.117:64020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/users.php"] [unique_id "al9NOin25uliftkV1n4BwgAAABQ"]
[Tue Jul 21 07:43:06.729304 2026] [security2:error] [pid 296703:tid 296879] [client 154.192.233.199:58639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BwwAAAC4"]
[Tue Jul 21 07:43:06.729424 2026] [security2:error] [pid 296703:tid 296879] [client 154.192.233.199:58639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BwwAAAC4"]
[Tue Jul 21 07:43:06.883857 2026] [security2:error] [pid 296703:tid 296862] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ms-edit.php"] [unique_id "al9NOin25uliftkV1n4ByQAAAB0"]
[Tue Jul 21 07:43:06.941783 2026] [security2:error] [pid 296703:tid 296885] [client 20.226.60.151:54284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/inputs.php"] [unique_id "al9NOin25uliftkV1n4BywAAADQ"]
[Tue Jul 21 07:43:06.988837 2026] [security2:error] [pid 296703:tid 296884] [client 20.104.96.117:64000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/177.php"] [unique_id "al9NOin25uliftkV1n4BzAAAADM"]
[Tue Jul 21 07:43:06.998521 2026] [security2:error] [pid 296703:tid 296834] [client 184.75.223.211:43286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BzQAAAAE"]
[Tue Jul 21 07:43:06.998634 2026] [security2:error] [pid 296703:tid 296834] [client 184.75.223.211:43286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9NOin25uliftkV1n4BzQAAAAE"]
[Tue Jul 21 07:43:07.015028 2026] [security2:error] [pid 296703:tid 296918] [client 37.140.223.134:27823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NOCn25uliftkV1n4BbgAAAFU"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:07.123509 2026] [security2:error] [pid 296703:tid 296920] [client 54.39.210.168:37260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "aronimoveis.com.br"] [uri "/"] [unique_id "al9NOyn25uliftkV1n4B0wAAAFc"]
[Tue Jul 21 07:43:07.123633 2026] [security2:error] [pid 296703:tid 296920] [client 54.39.210.168:37260] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aronimoveis.com.br"] [uri "/"] [unique_id "al9NOyn25uliftkV1n4B0wAAAFc"]
[Tue Jul 21 07:43:07.159158 2026] [security2:error] [pid 296703:tid 296896] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9NOyn25uliftkV1n4B1AAAAD8"]
[Tue Jul 21 07:43:07.327037 2026] [security2:error] [pid 296703:tid 296870] [client 20.197.195.24:13717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/bajah.php"] [unique_id "al9NOyn25uliftkV1n4B2QAAACU"]
[Tue Jul 21 07:43:07.451429 2026] [security2:error] [pid 296703:tid 296928] [client 20.104.96.117:5118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/config.php"] [unique_id "al9NOyn25uliftkV1n4B4AAAAF8"]
[Tue Jul 21 07:43:07.480543 2026] [autoindex:error] [pid 296703:tid 296924] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:07.540931 2026] [security2:error] [pid 296703:tid 296932] [client 20.220.225.223:19971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/cron-tab.php"] [unique_id "al9NOyn25uliftkV1n4B4gAAAGM"]
[Tue Jul 21 07:43:07.557657 2026] [security2:error] [pid 296703:tid 296891] [client 194.99.104.35:46236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9NOyn25uliftkV1n4B4wAAADo"]
[Tue Jul 21 07:43:07.557732 2026] [security2:error] [pid 296703:tid 296891] [client 194.99.104.35:46236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9NOyn25uliftkV1n4B4wAAADo"]
[Tue Jul 21 07:43:07.625827 2026] [security2:error] [pid 296703:tid 296851] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9NOyn25uliftkV1n4B5gAAABI"]
[Tue Jul 21 07:43:07.791198 2026] [security2:error] [pid 296703:tid 296882] [client 117.217.38.194:51594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOyn25uliftkV1n4B7AAAADE"]
[Tue Jul 21 07:43:07.791305 2026] [security2:error] [pid 296703:tid 296882] [client 117.217.38.194:51594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NOyn25uliftkV1n4B7AAAADE"]
[Tue Jul 21 07:43:07.827831 2026] [security2:error] [pid 296703:tid 296922] [client 20.104.96.117:5056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/gettest.php"] [unique_id "al9NOyn25uliftkV1n4B7QAAAFk"]
[Tue Jul 21 07:43:07.913389 2026] [security2:error] [pid 296703:tid 296878] [client 20.226.60.151:59433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-link-zorm.php"] [unique_id "al9NOyn25uliftkV1n4B8gAAAC0"]
[Tue Jul 21 07:43:07.934459 2026] [autoindex:error] [pid 296703:tid 296849] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:08.117754 2026] [autoindex:error] [pid 296703:tid 296896] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:08.205663 2026] [security2:error] [pid 296703:tid 296860] [client 20.226.60.151:22339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/nc4.php"] [unique_id "al9NPCn25uliftkV1n4CAAAAABs"]
[Tue Jul 21 07:43:08.262782 2026] [security2:error] [pid 296703:tid 296871] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/abcd.php"] [unique_id "al9NPCn25uliftkV1n4CAQAAACY"]
[Tue Jul 21 07:43:08.452723 2026] [security2:error] [pid 296703:tid 296887] [client 20.226.60.151:60158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9NPCn25uliftkV1n4CBwAAADY"]
[Tue Jul 21 07:43:08.470104 2026] [security2:error] [pid 296703:tid 296880] [client 74.249.245.134:54337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/ms-edit.php"] [unique_id "al9NPCn25uliftkV1n4CCAAAAC8"]
[Tue Jul 21 07:43:08.488942 2026] [security2:error] [pid 296703:tid 296907] [client 20.226.60.151:56225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/dfre.php"] [unique_id "al9NPCn25uliftkV1n4CCQAAAEo"]
[Tue Jul 21 07:43:08.522242 2026] [security2:error] [pid 296703:tid 296919] [client 20.104.96.117:5073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/min.php"] [unique_id "al9NPCn25uliftkV1n4CDQAAAFY"]
[Tue Jul 21 07:43:08.548602 2026] [security2:error] [pid 296703:tid 296872] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/file15.php"] [unique_id "al9NPCn25uliftkV1n4CDwAAACc"]
[Tue Jul 21 07:43:08.648258 2026] [security2:error] [pid 296703:tid 296917] [client 20.197.195.24:13732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/a.php"] [unique_id "al9NPCn25uliftkV1n4CEQAAAFQ"]
[Tue Jul 21 07:43:08.815411 2026] [security2:error] [pid 296703:tid 296884] [client 59.96.220.140:59689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NPCn25uliftkV1n4CFgAAADM"]
[Tue Jul 21 07:43:08.815554 2026] [security2:error] [pid 296703:tid 296884] [client 59.96.220.140:59689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NPCn25uliftkV1n4CFgAAADM"]
[Tue Jul 21 07:43:08.830068 2026] [security2:error] [pid 296703:tid 296840] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/jp.php"] [unique_id "al9NPCn25uliftkV1n4CFwAAAAc"]
[Tue Jul 21 07:43:09.033804 2026] [security2:error] [pid 296703:tid 296924] [client 103.106.20.201:54354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPSn25uliftkV1n4CHgAAAFs"]
[Tue Jul 21 07:43:09.033937 2026] [security2:error] [pid 296703:tid 296924] [client 103.106.20.201:54354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPSn25uliftkV1n4CHgAAAFs"]
[Tue Jul 21 07:43:09.121569 2026] [security2:error] [pid 296703:tid 296886] [client 20.104.96.117:62936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/dvjul.php"] [unique_id "al9NPSn25uliftkV1n4CIwAAADU"]
[Tue Jul 21 07:43:09.145651 2026] [security2:error] [pid 296703:tid 296870] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/f35.php"] [unique_id "al9NPSn25uliftkV1n4CJAAAACU"]
[Tue Jul 21 07:43:09.210672 2026] [security2:error] [pid 296703:tid 296861] [client 20.226.60.151:51219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/wp-happy.php"] [unique_id "al9NPSn25uliftkV1n4CJgAAABw"]
[Tue Jul 21 07:43:09.434616 2026] [security2:error] [pid 296703:tid 296880] [client 20.104.96.117:62971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/biufile.php"] [unique_id "al9NPSn25uliftkV1n4CMQAAAC8"]
[Tue Jul 21 07:43:09.452547 2026] [security2:error] [pid 296703:tid 296879] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-load.php"] [unique_id "al9NPSn25uliftkV1n4CMwAAAC4"]
[Tue Jul 21 07:43:09.522016 2026] [security2:error] [pid 296703:tid 296911] [client 74.249.245.134:17459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/simple.php"] [unique_id "al9NPSn25uliftkV1n4CNwAAAE4"]
[Tue Jul 21 07:43:09.560092 2026] [security2:error] [pid 296703:tid 296883] [client 122.162.144.145:20134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NPSn25uliftkV1n4COQAAADI"]
[Tue Jul 21 07:43:09.560202 2026] [security2:error] [pid 296703:tid 296883] [client 122.162.144.145:20134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NPSn25uliftkV1n4COQAAADI"]
[Tue Jul 21 07:43:09.657178 2026] [security2:error] [pid 296703:tid 296933] [client 20.226.60.151:61953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9NPSn25uliftkV1n4COgAAAGQ"]
[Tue Jul 21 07:43:09.753379 2026] [security2:error] [pid 296703:tid 296923] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/xyn.php"] [unique_id "al9NPSn25uliftkV1n4CPwAAAFo"]
[Tue Jul 21 07:43:09.832859 2026] [security2:error] [pid 296703:tid 296958] [client 20.104.96.117:4186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/av.php"] [unique_id "al9NPSn25uliftkV1n4CRQAAAH0"]
[Tue Jul 21 07:43:09.848018 2026] [security2:error] [pid 296703:tid 296873] [client 193.36.225.65:32873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NPSn25uliftkV1n4CSAAAACg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:09.957141 2026] [security2:error] [pid 296703:tid 296876] [client 20.197.195.24:13697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/edit.php"] [unique_id "al9NPSn25uliftkV1n4CTQAAACs"]
[Tue Jul 21 07:43:09.985446 2026] [security2:error] [pid 296703:tid 296868] [client 152.59.154.239:55938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPSn25uliftkV1n4CUAAAACM"]
[Tue Jul 21 07:43:09.985528 2026] [security2:error] [pid 296703:tid 296868] [client 152.59.154.239:55938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPSn25uliftkV1n4CUAAAACM"]
[Tue Jul 21 07:43:10.040197 2026] [autoindex:error] [pid 296703:tid 296928] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:10.077250 2026] [security2:error] [pid 296703:tid 296855] [client 20.104.96.117:30860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/root.php"] [unique_id "al9NPin25uliftkV1n4CVAAAABY"]
[Tue Jul 21 07:43:10.109458 2026] [security2:error] [pid 296703:tid 296850] [client 139.167.225.182:51886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPin25uliftkV1n4CVgAAABE"]
[Tue Jul 21 07:43:10.109641 2026] [security2:error] [pid 296703:tid 296850] [client 139.167.225.182:51886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPin25uliftkV1n4CVgAAABE"]
[Tue Jul 21 07:43:10.160685 2026] [security2:error] [pid 296703:tid 296919] [client 20.104.96.117:62915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/coffexium.php"] [unique_id "al9NPin25uliftkV1n4CWAAAAFY"]
[Tue Jul 21 07:43:10.232097 2026] [autoindex:error] [pid 296703:tid 296835] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:10.370863 2026] [security2:error] [pid 296703:tid 296877] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ccc.php"] [unique_id "al9NPin25uliftkV1n4CYwAAACw"]
[Tue Jul 21 07:43:10.464503 2026] [security2:error] [pid 296703:tid 296904] [client 20.104.96.117:5097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/core.php"] [unique_id "al9NPin25uliftkV1n4CZgAAAEc"]
[Tue Jul 21 07:43:10.681732 2026] [security2:error] [pid 296703:tid 296924] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/w.php"] [unique_id "al9NPin25uliftkV1n4CagAAAFs"]
[Tue Jul 21 07:43:10.704009 2026] [security2:error] [pid 296703:tid 296838] [client 20.226.60.151:59421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-link-szoppm.php"] [unique_id "al9NPin25uliftkV1n4CawAAAAU"]
[Tue Jul 21 07:43:10.751202 2026] [security2:error] [pid 296703:tid 296840] [client 20.104.96.117:5080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/als.php"] [unique_id "al9NPin25uliftkV1n4CbAAAAAc"]
[Tue Jul 21 07:43:10.856848 2026] [security2:error] [pid 296703:tid 296952] [client 74.249.245.134:5505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/404.php"] [unique_id "al9NPin25uliftkV1n4CcgAAAHc"]
[Tue Jul 21 07:43:10.898059 2026] [security2:error] [pid 296703:tid 296896] [client 54.238.249.23:60176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://user@:80"] [hostname "academycont.com"] [uri "/wp-json/batch/v1"] [unique_id "al9NPin25uliftkV1n4CdAAAAD8"]
[Tue Jul 21 07:43:10.996227 2026] [security2:error] [pid 296703:tid 296841] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9NPin25uliftkV1n4CeAAAAAg"]
[Tue Jul 21 07:43:11.039004 2026] [security2:error] [pid 296703:tid 296850] [client 20.197.195.24:13803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/hosty.php"] [unique_id "al9NPyn25uliftkV1n4CfAAAABE"]
[Tue Jul 21 07:43:11.074920 2026] [security2:error] [pid 296703:tid 296906] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NPyn25uliftkV1n4CfQAAAEk"]
[Tue Jul 21 07:43:11.096663 2026] [security2:error] [pid 296703:tid 296929] [client 20.104.96.117:62918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/simple.php"] [unique_id "al9NPyn25uliftkV1n4CfgAAAGA"]
[Tue Jul 21 07:43:11.279626 2026] [security2:error] [pid 296703:tid 296879] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/FWAZ.php"] [unique_id "al9NPyn25uliftkV1n4CfwAAAC4"]
[Tue Jul 21 07:43:11.305794 2026] [security2:error] [pid 296703:tid 296888] [client 20.226.60.151:54347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-blog.php"] [unique_id "al9NPyn25uliftkV1n4CggAAADc"]
[Tue Jul 21 07:43:11.317136 2026] [security2:error] [pid 296703:tid 296931] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9NPyn25uliftkV1n4ChAAAAGI"]
[Tue Jul 21 07:43:11.494281 2026] [security2:error] [pid 296703:tid 296930] [client 20.104.96.117:64004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/init.php"] [unique_id "al9NPyn25uliftkV1n4CigAAAGE"]
[Tue Jul 21 07:43:11.561319 2026] [security2:error] [pid 296703:tid 296868] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/miru1.php"] [unique_id "al9NPyn25uliftkV1n4ClAAAACM"]
[Tue Jul 21 07:43:11.604838 2026] [security2:error] [pid 296703:tid 296839] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NPyn25uliftkV1n4ClgAAAAY"]
[Tue Jul 21 07:43:11.644684 2026] [security2:error] [pid 296703:tid 296796] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CmAAAUlw"]
[Tue Jul 21 07:43:11.644798 2026] [security2:error] [pid 296703:tid 296915] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CmAAAUlw"]
[Tue Jul 21 07:43:11.677327 2026] [security2:error] [pid 296703:tid 296952] [client 20.151.10.161:55292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/waf.php"] [unique_id "al9NPyn25uliftkV1n4CmQAAAHc"]
[Tue Jul 21 07:43:11.723628 2026] [security2:error] [pid 296703:tid 296902] [client 20.197.195.24:13706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/k.php"] [unique_id "al9NPyn25uliftkV1n4CmwAAAEU"]
[Tue Jul 21 07:43:11.755581 2026] [security2:error] [pid 296703:tid 296940] [client 173.24.185.52:56940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CnwAAAGs"]
[Tue Jul 21 07:43:11.755742 2026] [security2:error] [pid 296703:tid 296940] [client 173.24.185.52:56940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CnwAAAGs"]
[Tue Jul 21 07:43:11.773253 2026] [security2:error] [pid 296703:tid 296950] [client 20.226.60.151:56238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/fpr4.php"] [unique_id "al9NPyn25uliftkV1n4CoAAAAHU"]
[Tue Jul 21 07:43:11.804372 2026] [security2:error] [pid 296703:tid 296887] [client 20.104.96.117:5104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/fpwch.php"] [unique_id "al9NPyn25uliftkV1n4CoQAAADY"]
[Tue Jul 21 07:43:11.827079 2026] [security2:error] [pid 296703:tid 296835] [client 103.166.103.129:59278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CpAAAAAI"]
[Tue Jul 21 07:43:11.827277 2026] [security2:error] [pid 296703:tid 296835] [client 103.166.103.129:59278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CpAAAAAI"]
[Tue Jul 21 07:43:11.838158 2026] [security2:error] [pid 296703:tid 296861] [client 54.238.249.23:33758] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://user@:80"] [hostname "academycont.com"] [uri "/"] [unique_id "al9NPyn25uliftkV1n4CpwAAABw"]
[Tue Jul 21 07:43:11.843477 2026] [security2:error] [pid 296703:tid 296883] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/aa.php"] [unique_id "al9NPyn25uliftkV1n4CqgAAADI"]
[Tue Jul 21 07:43:11.893757 2026] [security2:error] [pid 296703:tid 296882] [client 20.220.225.223:19266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/koiy.php"] [unique_id "al9NPyn25uliftkV1n4CrAAAADE"]
[Tue Jul 21 07:43:11.968486 2026] [security2:error] [pid 296703:tid 296888] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NPyn25uliftkV1n4CrQAAADc"]
[Tue Jul 21 07:43:11.975855 2026] [security2:error] [pid 296703:tid 296939] [client 122.179.91.63:29355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CrgAAAGo"]
[Tue Jul 21 07:43:11.975946 2026] [security2:error] [pid 296703:tid 296939] [client 122.179.91.63:29355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NPyn25uliftkV1n4CrgAAAGo"]
[Tue Jul 21 07:43:12.125285 2026] [security2:error] [pid 296703:tid 296913] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/122.php"] [unique_id "al9NQCn25uliftkV1n4CtAAAAFA"]
[Tue Jul 21 07:43:12.141450 2026] [security2:error] [pid 296703:tid 296930] [client 20.104.96.117:4229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/domvf.php"] [unique_id "al9NQCn25uliftkV1n4CtQAAAGE"]
[Tue Jul 21 07:43:12.219715 2026] [security2:error] [pid 296703:tid 296908] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9NQCn25uliftkV1n4CugAAAEs"]
[Tue Jul 21 07:43:12.227180 2026] [security2:error] [pid 296703:tid 296848] [client 74.249.245.134:5567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/file3.php"] [unique_id "al9NQCn25uliftkV1n4CuwAAAA8"]
[Tue Jul 21 07:43:12.351594 2026] [security2:error] [pid 296703:tid 296817] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQCn25uliftkV1n4CvgAAJXE"]
[Tue Jul 21 07:43:12.351736 2026] [security2:error] [pid 296703:tid 296870] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQCn25uliftkV1n4CvgAAJXE"]
[Tue Jul 21 07:43:12.431137 2026] [security2:error] [pid 296703:tid 296807] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NQCn25uliftkV1n4CwgAAX2c"]
[Tue Jul 21 07:43:12.442804 2026] [security2:error] [pid 296703:tid 296853] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/get.php"] [unique_id "al9NQCn25uliftkV1n4CwwAAABQ"]
[Tue Jul 21 07:43:12.503679 2026] [security2:error] [pid 296703:tid 296781] [remote 45.3.45.241:34879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NQCn25uliftkV1n4CvQAAOk0"]
[Tue Jul 21 07:43:12.520885 2026] [security2:error] [pid 296703:tid 296950] [client 20.104.96.117:62917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp.php"] [unique_id "al9NQCn25uliftkV1n4CxAAAAHU"]
[Tue Jul 21 07:43:12.581013 2026] [security2:error] [pid 296703:tid 296731] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9NQCn25uliftkV1n4CxgAANhs"]
[Tue Jul 21 07:43:12.641466 2026] [security2:error] [pid 296703:tid 296947] [client 20.197.195.24:13752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/aaa.php"] [unique_id "al9NQCn25uliftkV1n4CywAAAHI"]
[Tue Jul 21 07:43:12.648220 2026] [security2:error] [pid 296703:tid 296938] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NQCn25uliftkV1n4CzAAAAGk"]
[Tue Jul 21 07:43:12.785742 2026] [security2:error] [pid 296703:tid 296811] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NQCn25uliftkV1n4C0AAALWs"]
[Tue Jul 21 07:43:12.822400 2026] [security2:error] [pid 296703:tid 296931] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/as.php"] [unique_id "al9NQCn25uliftkV1n4C0QAAAGI"]
[Tue Jul 21 07:43:12.840320 2026] [security2:error] [pid 296703:tid 296845] [client 20.104.96.117:5084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/class.php"] [unique_id "al9NQCn25uliftkV1n4C0gAAAAw"]
[Tue Jul 21 07:43:12.905737 2026] [security2:error] [pid 296703:tid 296847] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9NQCn25uliftkV1n4C1wAAAA4"]
[Tue Jul 21 07:43:12.925278 2026] [security2:error] [pid 296703:tid 296822] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NQCn25uliftkV1n4C2AAAWnY"]
[Tue Jul 21 07:43:13.104515 2026] [security2:error] [pid 296703:tid 296920] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ccou.php"] [unique_id "al9NQSn25uliftkV1n4C3gAAAFc"]
[Tue Jul 21 07:43:13.137925 2026] [security2:error] [pid 296703:tid 296839] [client 20.104.96.117:4173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/echkm.php"] [unique_id "al9NQSn25uliftkV1n4C4AAAAAY"]
[Tue Jul 21 07:43:13.154058 2026] [security2:error] [pid 296703:tid 296706] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4C4QAAKwI"]
[Tue Jul 21 07:43:13.155973 2026] [security2:error] [pid 296703:tid 296915] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4C4gAAAFI"]
[Tue Jul 21 07:43:13.219611 2026] [security2:error] [pid 296703:tid 296960] [client 20.226.60.151:56258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/file88.php"] [unique_id "al9NQSn25uliftkV1n4C4wAAAH8"]
[Tue Jul 21 07:43:13.242272 2026] [security2:error] [pid 296703:tid 296863] [client 103.174.34.15:58072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4C5AAAAB4"]
[Tue Jul 21 07:43:13.242698 2026] [security2:error] [pid 296703:tid 296863] [client 103.174.34.15:58072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4C5AAAAB4"]
[Tue Jul 21 07:43:13.333961 2026] [security2:error] [pid 296703:tid 296850] [client 62.102.148.187:34684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4C5gAAABE"]
[Tue Jul 21 07:43:13.334120 2026] [security2:error] [pid 296703:tid 296850] [client 62.102.148.187:34684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4C5gAAABE"]
[Tue Jul 21 07:43:13.348776 2026] [security2:error] [pid 296703:tid 296853] [client 20.197.195.24:13818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/file5.php"] [unique_id "al9NQSn25uliftkV1n4C5wAAABQ"]
[Tue Jul 21 07:43:13.365520 2026] [security2:error] [pid 296703:tid 296767] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4C6AAAFj8"]
[Tue Jul 21 07:43:13.388064 2026] [security2:error] [pid 296703:tid 296935] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/w3lls.php"] [unique_id "al9NQSn25uliftkV1n4C6gAAAGY"]
[Tue Jul 21 07:43:13.461833 2026] [security2:error] [pid 296703:tid 296862] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4C7gAAAB0"]
[Tue Jul 21 07:43:13.462847 2026] [security2:error] [pid 296703:tid 296718] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4C7wAAHA4"]
[Tue Jul 21 07:43:13.462969 2026] [security2:error] [pid 296703:tid 296861] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4C7wAAHA4"]
[Tue Jul 21 07:43:13.567893 2026] [security2:error] [pid 296703:tid 296881] [client 20.104.96.117:64062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/lib.php"] [unique_id "al9NQSn25uliftkV1n4C8gAAADA"]
[Tue Jul 21 07:43:13.612765 2026] [security2:error] [pid 296703:tid 296829] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4C9AAASn0"]
[Tue Jul 21 07:43:13.690930 2026] [security2:error] [pid 296703:tid 296922] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/test1.php"] [unique_id "al9NQSn25uliftkV1n4C-AAAAFk"]
[Tue Jul 21 07:43:13.714101 2026] [security2:error] [pid 296703:tid 296884] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4C-gAAADM"]
[Tue Jul 21 07:43:13.760971 2026] [security2:error] [pid 296703:tid 296904] [client 20.197.195.24:13723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/222.php"] [unique_id "al9NQSn25uliftkV1n4C-wAAAEc"]
[Tue Jul 21 07:43:13.879537 2026] [security2:error] [pid 296703:tid 296738] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4C_AAAGiI"]
[Tue Jul 21 07:43:13.919627 2026] [security2:error] [pid 296703:tid 296918] [client 20.104.96.117:4196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/login.php"] [unique_id "al9NQSn25uliftkV1n4C_QAAAFU"]
[Tue Jul 21 07:43:13.942115 2026] [security2:error] [pid 296703:tid 296897] [client 106.215.181.8:3523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4DAgAAAEA"]
[Tue Jul 21 07:43:13.942244 2026] [security2:error] [pid 296703:tid 296897] [client 106.215.181.8:3523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQSn25uliftkV1n4DAgAAAEA"]
[Tue Jul 21 07:43:13.949718 2026] [security2:error] [pid 296703:tid 296953] [client 31.14.72.5:49156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4DAwAAAHg"]
[Tue Jul 21 07:43:13.956728 2026] [security2:error] [pid 296703:tid 296886] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NQSn25uliftkV1n4DBAAAADU"]
[Tue Jul 21 07:43:13.966544 2026] [security2:error] [pid 296703:tid 296888] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/database.php"] [unique_id "al9NQSn25uliftkV1n4DBQAAADc"]
[Tue Jul 21 07:43:14.011248 2026] [security2:error] [pid 296703:tid 296719] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NQin25uliftkV1n4DBgAARA8"]
[Tue Jul 21 07:43:14.093578 2026] [security2:error] [pid 296703:tid 296742] [remote 47.128.54.230:48604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.serbetoadv.com"] [uri "/siemens-iq300-sn63ex15be-k.html"] [unique_id "al9NQin25uliftkV1n4DCwAAJiY"]
[Tue Jul 21 07:43:14.123319 2026] [security2:error] [pid 296703:tid 296960] [client 20.197.195.24:13771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/test.php"] [unique_id "al9NQin25uliftkV1n4DDAAAAH8"]
[Tue Jul 21 07:43:14.144867 2026] [security2:error] [pid 296703:tid 296776] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NQin25uliftkV1n4DDQAACEg"]
[Tue Jul 21 07:43:14.176357 2026] [security2:error] [pid 296703:tid 296930] [client 20.151.10.161:12072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/xstelth.php"] [unique_id "al9NQin25uliftkV1n4DEAAAAGE"]
[Tue Jul 21 07:43:14.234717 2026] [security2:error] [pid 296703:tid 296928] [client 20.104.96.117:62957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/a2.php"] [unique_id "al9NQin25uliftkV1n4DEgAAAF8"]
[Tue Jul 21 07:43:14.251809 2026] [security2:error] [pid 296703:tid 296927] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/file.php"] [unique_id "al9NQin25uliftkV1n4DEwAAAF4"]
[Tue Jul 21 07:43:14.268606 2026] [security2:error] [pid 296703:tid 296853] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NQin25uliftkV1n4DFAAAABQ"]
[Tue Jul 21 07:43:14.454760 2026] [security2:error] [pid 296703:tid 296722] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NQin25uliftkV1n4DHAAAERI"]
[Tue Jul 21 07:43:14.454937 2026] [security2:error] [pid 296703:tid 296850] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NQin25uliftkV1n4DHAAAERI"]
[Tue Jul 21 07:43:14.482886 2026] [security2:error] [pid 296703:tid 296736] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NQin25uliftkV1n4DHQAAASA"]
[Tue Jul 21 07:43:14.535286 2026] [security2:error] [pid 296703:tid 296931] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/file.php"] [unique_id "al9NQin25uliftkV1n4DIAAAAGI"]
[Tue Jul 21 07:43:14.663910 2026] [security2:error] [pid 296703:tid 296730] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.expertemrecheios.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NQin25uliftkV1n4DKAAADho"]
[Tue Jul 21 07:43:14.674519 2026] [security2:error] [pid 296703:tid 296913] [client 182.8.255.181:17341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NQin25uliftkV1n4DKQAAAFA"]
[Tue Jul 21 07:43:14.674717 2026] [security2:error] [pid 296703:tid 296913] [client 182.8.255.181:17341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NQin25uliftkV1n4DKQAAAFA"]
[Tue Jul 21 07:43:14.683434 2026] [security2:error] [pid 296703:tid 296752] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQin25uliftkV1n4DKwAAbjA"]
[Tue Jul 21 07:43:14.683565 2026] [security2:error] [pid 296703:tid 296943] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQin25uliftkV1n4DKwAAbjA"]
[Tue Jul 21 07:43:14.708729 2026] [security2:error] [pid 296703:tid 296838] [client 20.104.96.117:5103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/d61.php"] [unique_id "al9NQin25uliftkV1n4DLgAAAAU"]
[Tue Jul 21 07:43:14.719325 2026] [autoindex:error] [pid 296703:tid 296953] [client 20.226.60.151:61971] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:14.741504 2026] [security2:error] [pid 296703:tid 296888] [client 20.226.60.151:61971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9NQin25uliftkV1n4DMgAAADc"]
[Tue Jul 21 07:43:14.842916 2026] [security2:error] [pid 296703:tid 296902] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/777.php"] [unique_id "al9NQin25uliftkV1n4DNQAAAEU"]
[Tue Jul 21 07:43:14.866695 2026] [security2:error] [pid 296703:tid 296870] [client 20.226.60.151:51239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ccc.php"] [unique_id "al9NQin25uliftkV1n4DNgAAACU"]
[Tue Jul 21 07:43:14.974756 2026] [security2:error] [pid 296703:tid 296889] [client 31.14.72.5:49906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NQin25uliftkV1n4DPAAAADg"]
[Tue Jul 21 07:43:15.063886 2026] [security2:error] [pid 296703:tid 296861] [client 20.104.96.117:4189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/info.php"] [unique_id "al9NQyn25uliftkV1n4DQQAAABw"]
[Tue Jul 21 07:43:15.085735 2026] [security2:error] [pid 296703:tid 296880] [client 136.144.33.54:49667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NQin25uliftkV1n4DNwAAAC8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:15.132668 2026] [security2:error] [pid 296703:tid 296876] [client 20.197.195.24:13731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/aaa.php"] [unique_id "al9NQyn25uliftkV1n4DQgAAACs"]
[Tue Jul 21 07:43:15.167507 2026] [security2:error] [pid 296703:tid 296890] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ssixta.php"] [unique_id "al9NQyn25uliftkV1n4DQwAAADk"]
[Tue Jul 21 07:43:15.280630 2026] [security2:error] [pid 296703:tid 296937] [client 20.151.10.161:12046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-links.php"] [unique_id "al9NQyn25uliftkV1n4DTAAAAGg"]
[Tue Jul 21 07:43:15.305555 2026] [security2:error] [pid 296703:tid 296847] [client 74.249.245.134:5543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/wp-mail.php"] [unique_id "al9NQyn25uliftkV1n4DTgAAAA4"]
[Tue Jul 21 07:43:15.347309 2026] [security2:error] [pid 296703:tid 296859] [client 20.226.60.151:63577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/albin.php"] [unique_id "al9NQyn25uliftkV1n4DTwAAABo"]
[Tue Jul 21 07:43:15.395730 2026] [security2:error] [pid 296703:tid 296848] [client 103.86.117.203:55637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DUAAAAA8"]
[Tue Jul 21 07:43:15.395896 2026] [security2:error] [pid 296703:tid 296848] [client 103.86.117.203:55637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DUAAAAA8"]
[Tue Jul 21 07:43:15.430084 2026] [security2:error] [pid 296703:tid 296838] [client 20.104.96.117:5091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/11.php"] [unique_id "al9NQyn25uliftkV1n4DUQAAAAU"]
[Tue Jul 21 07:43:15.442469 2026] [security2:error] [pid 296703:tid 296885] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/1c.php"] [unique_id "al9NQyn25uliftkV1n4DUgAAADQ"]
[Tue Jul 21 07:43:15.637229 2026] [security2:error] [pid 296703:tid 296853] [client 31.14.72.5:50431] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NQyn25uliftkV1n4DWgAAABQ"]
[Tue Jul 21 07:43:15.660855 2026] [security2:error] [pid 296703:tid 296841] [client 117.251.86.144:60910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DXAAAAAg"]
[Tue Jul 21 07:43:15.660961 2026] [security2:error] [pid 296703:tid 296841] [client 117.251.86.144:60910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DXAAAAAg"]
[Tue Jul 21 07:43:15.732497 2026] [security2:error] [pid 296703:tid 296862] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/test2.php"] [unique_id "al9NQyn25uliftkV1n4DYgAAAB0"]
[Tue Jul 21 07:43:15.791990 2026] [security2:error] [pid 296703:tid 296947] [client 122.186.204.214:58532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DZAAAAHI"]
[Tue Jul 21 07:43:15.811867 2026] [security2:error] [pid 296703:tid 296947] [client 122.186.204.214:58532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DZAAAAHI"]
[Tue Jul 21 07:43:15.830332 2026] [security2:error] [pid 296703:tid 296856] [client 20.104.96.117:62959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/v2.php"] [unique_id "al9NQyn25uliftkV1n4DZQAAABc"]
[Tue Jul 21 07:43:15.850323 2026] [security2:error] [pid 296703:tid 296935] [client 122.164.127.47:56924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DZgAAAGY"]
[Tue Jul 21 07:43:15.850438 2026] [security2:error] [pid 296703:tid 296935] [client 122.164.127.47:56924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DZgAAAGY"]
[Tue Jul 21 07:43:15.908557 2026] [security2:error] [pid 296703:tid 296775] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DZwAAOEc"]
[Tue Jul 21 07:43:15.908698 2026] [security2:error] [pid 296703:tid 296889] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DZwAAOEc"]
[Tue Jul 21 07:43:15.932707 2026] [security2:error] [pid 296703:tid 296884] [client 117.247.80.59:31032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DaQAAADM"]
[Tue Jul 21 07:43:15.932832 2026] [security2:error] [pid 296703:tid 296884] [client 117.247.80.59:31032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NQyn25uliftkV1n4DaQAAADM"]
[Tue Jul 21 07:43:15.993185 2026] [security2:error] [pid 296703:tid 296929] [client 20.226.60.151:54327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ms-edit.php"] [unique_id "al9NQyn25uliftkV1n4DagAAAGA"]
[Tue Jul 21 07:43:16.089087 2026] [security2:error] [pid 296703:tid 296937] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/buy.php"] [unique_id "al9NRCn25uliftkV1n4DbwAAAGg"]
[Tue Jul 21 07:43:16.098859 2026] [security2:error] [pid 296703:tid 296955] [client 20.226.60.151:50918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/cilus.php"] [unique_id "al9NRCn25uliftkV1n4DcAAAAHo"]
[Tue Jul 21 07:43:16.133289 2026] [security2:error] [pid 296703:tid 296945] [client 20.104.96.117:4236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/panel.php"] [unique_id "al9NRCn25uliftkV1n4DcQAAAHA"]
[Tue Jul 21 07:43:16.336337 2026] [security2:error] [pid 296703:tid 296930] [client 31.14.72.5:50732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9NRCn25uliftkV1n4DeQAAAGE"]
[Tue Jul 21 07:43:16.371535 2026] [security2:error] [pid 296703:tid 296933] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ssend.php"] [unique_id "al9NRCn25uliftkV1n4DegAAAGQ"]
[Tue Jul 21 07:43:16.394993 2026] [security2:error] [pid 296703:tid 296850] [client 202.143.127.214:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRCn25uliftkV1n4DewAAABE"]
[Tue Jul 21 07:43:16.395220 2026] [security2:error] [pid 296703:tid 296850] [client 202.143.127.214:52286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRCn25uliftkV1n4DewAAABE"]
[Tue Jul 21 07:43:16.404961 2026] [security2:error] [pid 296703:tid 296917] [client 20.151.10.161:53621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9NRCn25uliftkV1n4DfAAAAFQ"]
[Tue Jul 21 07:43:16.436720 2026] [security2:error] [pid 296703:tid 296887] [client 20.104.96.117:5094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/dex.php"] [unique_id "al9NRCn25uliftkV1n4DfgAAADY"]
[Tue Jul 21 07:43:16.647367 2026] [security2:error] [pid 296703:tid 296876] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/item.php"] [unique_id "al9NRCn25uliftkV1n4DhAAAACs"]
[Tue Jul 21 07:43:16.717721 2026] [security2:error] [pid 296703:tid 296856] [client 20.226.60.151:59426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/gptsh.php"] [unique_id "al9NRCn25uliftkV1n4DhQAAABc"]
[Tue Jul 21 07:43:16.725566 2026] [security2:error] [pid 296703:tid 296935] [client 20.104.96.117:5081] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "fit4me.online"] [uri "/1.php"] [unique_id "al9NRCn25uliftkV1n4DhwAAAGY"]
[Tue Jul 21 07:43:16.725689 2026] [security2:error] [pid 296703:tid 296935] [client 20.104.96.117:5081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/1.php"] [unique_id "al9NRCn25uliftkV1n4DhwAAAGY"]
[Tue Jul 21 07:43:16.939687 2026] [security2:error] [pid 296703:tid 296926] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ss.php"] [unique_id "al9NRCn25uliftkV1n4DjQAAAF0"]
[Tue Jul 21 07:43:17.002060 2026] [security2:error] [pid 296703:tid 296845] [client 31.14.72.5:51059] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NRSn25uliftkV1n4DjgAAAAw"]
[Tue Jul 21 07:43:17.036364 2026] [security2:error] [pid 296703:tid 296847] [client 20.226.60.151:54312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9NRSn25uliftkV1n4DjwAAAA4"]
[Tue Jul 21 07:43:17.051580 2026] [security2:error] [pid 296703:tid 296938] [client 20.197.195.24:13733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/11.php"] [unique_id "al9NRSn25uliftkV1n4DkAAAAGk"]
[Tue Jul 21 07:43:17.062032 2026] [security2:error] [pid 296703:tid 296793] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NRSn25uliftkV1n4DkQAAGlk"]
[Tue Jul 21 07:43:17.062207 2026] [security2:error] [pid 296703:tid 296859] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NRSn25uliftkV1n4DkQAAGlk"]
[Tue Jul 21 07:43:17.107472 2026] [security2:error] [pid 296703:tid 296953] [client 20.104.96.117:30400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/sym403.php"] [unique_id "al9NRSn25uliftkV1n4DlQAAAHg"]
[Tue Jul 21 07:43:17.121461 2026] [security2:error] [pid 296703:tid 296950] [client 20.104.96.117:5061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/ms.php"] [unique_id "al9NRSn25uliftkV1n4DmQAAAHU"]
[Tue Jul 21 07:43:17.218643 2026] [security2:error] [pid 296703:tid 296869] [client 74.249.245.134:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/about.php"] [unique_id "al9NRSn25uliftkV1n4DnAAAACQ"]
[Tue Jul 21 07:43:17.257662 2026] [security2:error] [pid 296703:tid 296885] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/hypo.php"] [unique_id "al9NRSn25uliftkV1n4DngAAADQ"]
[Tue Jul 21 07:43:17.323275 2026] [security2:error] [pid 296703:tid 296917] [client 20.226.60.151:51236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/777.php"] [unique_id "al9NRSn25uliftkV1n4DoAAAAFQ"]
[Tue Jul 21 07:43:17.356995 2026] [security2:error] [pid 296703:tid 296928] [client 20.197.195.24:13822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/mac.php"] [unique_id "al9NRSn25uliftkV1n4DoQAAAF8"]
[Tue Jul 21 07:43:17.401509 2026] [security2:error] [pid 296703:tid 296911] [client 20.197.195.24:13820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/chosen.php"] [unique_id "al9NRSn25uliftkV1n4DpQAAAE4"]
[Tue Jul 21 07:43:17.543862 2026] [security2:error] [pid 296703:tid 296931] [client 154.192.233.199:59921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRSn25uliftkV1n4DpwAAAGI"]
[Tue Jul 21 07:43:17.544030 2026] [security2:error] [pid 296703:tid 296931] [client 154.192.233.199:59921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRSn25uliftkV1n4DpwAAAGI"]
[Tue Jul 21 07:43:17.575732 2026] [security2:error] [pid 296703:tid 296924] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/users.php"] [unique_id "al9NRSn25uliftkV1n4DqQAAAFs"]
[Tue Jul 21 07:43:17.600731 2026] [security2:error] [pid 296703:tid 296939] [client 20.151.10.161:12056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.jandel.com.br"] [uri "/aaa.php"] [unique_id "al9NRSn25uliftkV1n4DqwAAAGo"]
[Tue Jul 21 07:43:17.623501 2026] [security2:error] [pid 296703:tid 296884] [client 20.197.195.24:13711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/cream1.php"] [unique_id "al9NRSn25uliftkV1n4DrgAAADM"]
[Tue Jul 21 07:43:17.692467 2026] [security2:error] [pid 296703:tid 296878] [client 31.14.72.5:51350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9NRSn25uliftkV1n4DswAAAC0"]
[Tue Jul 21 07:43:17.747641 2026] [security2:error] [pid 296703:tid 296955] [client 20.104.96.117:4190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/memberfuns.php"] [unique_id "al9NRSn25uliftkV1n4DtQAAAHo"]
[Tue Jul 21 07:43:18.001781 2026] [security2:error] [pid 296703:tid 296838] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/177.php"] [unique_id "al9NRin25uliftkV1n4DvAAAAAU"]
[Tue Jul 21 07:43:18.018638 2026] [autoindex:error] [pid 296703:tid 296953] [client 20.226.60.151:61963] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:18.029123 2026] [security2:error] [pid 296703:tid 296900] [client 20.226.60.151:61963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9NRin25uliftkV1n4DvwAAAEM"]
[Tue Jul 21 07:43:18.065257 2026] [security2:error] [pid 296703:tid 296904] [client 20.104.96.117:4237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/0.php"] [unique_id "al9NRin25uliftkV1n4DwAAAAEc"]
[Tue Jul 21 07:43:18.252902 2026] [security2:error] [pid 296703:tid 296881] [client 117.217.38.194:52096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRin25uliftkV1n4DxgAAADA"]
[Tue Jul 21 07:43:18.253092 2026] [security2:error] [pid 296703:tid 296881] [client 117.217.38.194:52096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRin25uliftkV1n4DxgAAADA"]
[Tue Jul 21 07:43:18.284050 2026] [security2:error] [pid 296703:tid 296863] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/config.php"] [unique_id "al9NRin25uliftkV1n4DxwAAAB4"]
[Tue Jul 21 07:43:18.365902 2026] [security2:error] [pid 296703:tid 296951] [client 31.14.72.5:51636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9NRin25uliftkV1n4DzQAAAHY"]
[Tue Jul 21 07:43:18.368724 2026] [security2:error] [pid 296703:tid 296919] [client 20.104.96.117:5090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/BDKR28.php"] [unique_id "al9NRin25uliftkV1n4DzgAAAFY"]
[Tue Jul 21 07:43:18.379512 2026] [security2:error] [pid 296703:tid 296872] [client 128.140.106.114:18234] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9NRin25uliftkV1n4DzwAAACc"], referer: https://artetoner.com.br
[Tue Jul 21 07:43:18.457280 2026] [autoindex:error] [pid 296703:tid 296939] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:18.489023 2026] [autoindex:error] [pid 296703:tid 296889] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:18.498327 2026] [security2:error] [pid 296703:tid 296862] [client 20.197.195.24:49904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/dr.php"] [unique_id "al9NRin25uliftkV1n4D1wAAAB0"]
[Tue Jul 21 07:43:18.594963 2026] [security2:error] [pid 296703:tid 296926] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/gettest.php"] [unique_id "al9NRin25uliftkV1n4D2gAAAF0"]
[Tue Jul 21 07:43:18.642624 2026] [security2:error] [pid 296703:tid 296909] [client 74.249.245.134:17417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/adminfuns.php"] [unique_id "al9NRin25uliftkV1n4D3gAAAEw"]
[Tue Jul 21 07:43:18.707003 2026] [security2:error] [pid 296703:tid 296890] [client 20.104.96.117:64012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/green1.php"] [unique_id "al9NRin25uliftkV1n4D3wAAADk"]
[Tue Jul 21 07:43:18.747272 2026] [security2:error] [pid 296703:tid 296934] [client 136.144.33.97:45073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NRin25uliftkV1n4D5AAAAGU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:18.876179 2026] [security2:error] [pid 296703:tid 296871] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/min.php"] [unique_id "al9NRin25uliftkV1n4D7AAAACY"]
[Tue Jul 21 07:43:19.001368 2026] [security2:error] [pid 296703:tid 296891] [client 20.104.96.117:62913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/nc4.php"] [unique_id "al9NRyn25uliftkV1n4D8AAAADo"]
[Tue Jul 21 07:43:19.033860 2026] [security2:error] [pid 296703:tid 296853] [client 31.14.72.5:51899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NRyn25uliftkV1n4D8gAAABQ"]
[Tue Jul 21 07:43:19.042051 2026] [autoindex:error] [pid 296703:tid 296952] [client 20.226.60.151:54307] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:19.062320 2026] [autoindex:error] [pid 296703:tid 296897] [client 20.226.60.151:54307] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:19.067353 2026] [security2:error] [pid 296703:tid 296894] [client 20.226.60.151:54307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/abcd.php"] [unique_id "al9NRyn25uliftkV1n4D9QAAAD0"]
[Tue Jul 21 07:43:19.110835 2026] [security2:error] [pid 296703:tid 296951] [client 20.226.60.151:56213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/for.php"] [unique_id "al9NRyn25uliftkV1n4D-AAAAHY"]
[Tue Jul 21 07:43:19.126516 2026] [security2:error] [pid 296703:tid 296919] [client 62.102.148.187:37294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9NRyn25uliftkV1n4D-QAAAFY"]
[Tue Jul 21 07:43:19.126630 2026] [security2:error] [pid 296703:tid 296919] [client 62.102.148.187:37294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9NRyn25uliftkV1n4D-QAAAFY"]
[Tue Jul 21 07:43:19.177404 2026] [security2:error] [pid 296703:tid 296837] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/dvjul.php"] [unique_id "al9NRyn25uliftkV1n4D-wAAAAQ"]
[Tue Jul 21 07:43:19.288549 2026] [security2:error] [pid 296703:tid 296878] [client 20.104.96.117:62933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/a1.php"] [unique_id "al9NRyn25uliftkV1n4EAAAAAC0"]
[Tue Jul 21 07:43:19.315956 2026] [security2:error] [pid 296703:tid 296926] [client 20.197.195.24:13734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/x.php"] [unique_id "al9NRyn25uliftkV1n4EAQAAAF0"]
[Tue Jul 21 07:43:19.459131 2026] [security2:error] [pid 296703:tid 296876] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/biufile.php"] [unique_id "al9NRyn25uliftkV1n4EBwAAACs"]
[Tue Jul 21 07:43:19.645896 2026] [security2:error] [pid 296703:tid 296915] [client 20.104.96.117:5085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/eee.php"] [unique_id "al9NRyn25uliftkV1n4ECQAAAFI"]
[Tue Jul 21 07:43:19.702214 2026] [core:error] [pid 296703:tid 296771] [remote 2600:1f16:743:ac02:233c:ec46:b0a2:6f83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://webdisk.dralulmabhering.com.br/
[Tue Jul 21 07:43:19.702232 2026] [core:error] [pid 296703:tid 296771] [remote 2600:1f16:743:ac02:233c:ec46:b0a2:6f83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://webdisk.dralulmabhering.com.br/
[Tue Jul 21 07:43:19.708694 2026] [security2:error] [pid 296703:tid 296902] [client 31.14.72.5:52246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NRyn25uliftkV1n4EDAAAAEU"]
[Tue Jul 21 07:43:19.749917 2026] [security2:error] [pid 296703:tid 296848] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/av.php"] [unique_id "al9NRyn25uliftkV1n4EEAAAAA8"]
[Tue Jul 21 07:43:19.853836 2026] [security2:error] [pid 296703:tid 296924] [client 103.106.20.201:54942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRyn25uliftkV1n4EEQAAAFs"]
[Tue Jul 21 07:43:19.854558 2026] [security2:error] [pid 296703:tid 296924] [client 103.106.20.201:54942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NRyn25uliftkV1n4EEQAAAFs"]
[Tue Jul 21 07:43:19.984393 2026] [security2:error] [pid 296703:tid 296874] [client 20.104.96.117:62947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-aothait.php"] [unique_id "al9NRyn25uliftkV1n4EFgAAACk"]
[Tue Jul 21 07:43:20.049356 2026] [security2:error] [pid 296703:tid 296861] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/coffexium.php"] [unique_id "al9NSCn25uliftkV1n4EGAAAABw"]
[Tue Jul 21 07:43:20.135193 2026] [security2:error] [pid 296703:tid 296884] [client 47.128.22.36:14740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fisioevida.com"] [uri "/robots.txt"] [unique_id "al9NSCn25uliftkV1n4EGgAAADM"]
[Tue Jul 21 07:43:20.149620 2026] [security2:error] [pid 296703:tid 296944] [client 74.249.245.134:5519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/php8.php"] [unique_id "al9NSCn25uliftkV1n4EHAAAAG8"]
[Tue Jul 21 07:43:20.154041 2026] [security2:error] [pid 296703:tid 296837] [client 20.197.195.24:49856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/155.php"] [unique_id "al9NSCn25uliftkV1n4EHQAAAAQ"]
[Tue Jul 21 07:43:20.274119 2026] [security2:error] [pid 296703:tid 296907] [client 20.104.96.117:62928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/config.json.php"] [unique_id "al9NSCn25uliftkV1n4EIAAAAEo"]
[Tue Jul 21 07:43:20.311824 2026] [security2:error] [pid 296703:tid 296862] [client 20.226.60.151:54289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file15.php"] [unique_id "al9NSCn25uliftkV1n4EIwAAAB0"]
[Tue Jul 21 07:43:20.331942 2026] [security2:error] [pid 296703:tid 296834] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/core.php"] [unique_id "al9NSCn25uliftkV1n4EJAAAAAE"]
[Tue Jul 21 07:43:20.334706 2026] [security2:error] [pid 296703:tid 296844] [client 122.162.144.145:11400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NSCn25uliftkV1n4EJQAAAAs"]
[Tue Jul 21 07:43:20.334797 2026] [security2:error] [pid 296703:tid 296844] [client 122.162.144.145:11400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NSCn25uliftkV1n4EJQAAAAs"]
[Tue Jul 21 07:43:20.387722 2026] [security2:error] [pid 296703:tid 296958] [client 31.14.72.5:52579] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9NSCn25uliftkV1n4EJwAAAH0"]
[Tue Jul 21 07:43:20.478662 2026] [security2:error] [pid 296703:tid 296953] [client 20.226.60.151:54278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/jp.php"] [unique_id "al9NSCn25uliftkV1n4ELAAAAHg"]
[Tue Jul 21 07:43:20.501318 2026] [security2:error] [pid 296703:tid 296869] [client 59.96.220.140:60208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NSCn25uliftkV1n4ELQAAACQ"]
[Tue Jul 21 07:43:20.501416 2026] [security2:error] [pid 296703:tid 296869] [client 59.96.220.140:60208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NSCn25uliftkV1n4ELQAAACQ"]
[Tue Jul 21 07:43:20.602393 2026] [security2:error] [pid 296703:tid 296879] [client 20.104.96.117:64056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9NSCn25uliftkV1n4ELgAAAC4"]
[Tue Jul 21 07:43:20.616994 2026] [security2:error] [pid 296703:tid 296950] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/als.php"] [unique_id "al9NSCn25uliftkV1n4ELwAAAHU"]
[Tue Jul 21 07:43:20.640661 2026] [security2:error] [pid 296703:tid 296920] [client 20.226.60.151:60136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/f35.php"] [unique_id "al9NSCn25uliftkV1n4EMAAAAFc"]
[Tue Jul 21 07:43:20.899362 2026] [security2:error] [pid 296703:tid 296881] [client 20.104.96.117:4212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/k2.php"] [unique_id "al9NSCn25uliftkV1n4ENgAAADA"]
[Tue Jul 21 07:43:20.919997 2026] [security2:error] [pid 296703:tid 296894] [client 152.59.154.239:56420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSCn25uliftkV1n4ENwAAAD0"]
[Tue Jul 21 07:43:20.922032 2026] [security2:error] [pid 296703:tid 296894] [client 152.59.154.239:56420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSCn25uliftkV1n4ENwAAAD0"]
[Tue Jul 21 07:43:21.073269 2026] [security2:error] [pid 296703:tid 296908] [client 31.14.72.5:53081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9NSSn25uliftkV1n4EPQAAAEs"]
[Tue Jul 21 07:43:21.191817 2026] [security2:error] [pid 296703:tid 296909] [client 139.167.225.182:52541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSSn25uliftkV1n4EQAAAAEw"]
[Tue Jul 21 07:43:21.191972 2026] [security2:error] [pid 296703:tid 296909] [client 139.167.225.182:52541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSSn25uliftkV1n4EQAAAAEw"]
[Tue Jul 21 07:43:21.232322 2026] [security2:error] [pid 296703:tid 296931] [client 20.104.96.117:64059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/uiuvs58l.php"] [unique_id "al9NSSn25uliftkV1n4EQQAAAGI"]
[Tue Jul 21 07:43:21.250247 2026] [security2:error] [pid 296703:tid 296861] [client 20.226.60.151:54314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-load.php"] [unique_id "al9NSSn25uliftkV1n4EQgAAABw"]
[Tue Jul 21 07:43:21.271827 2026] [security2:error] [pid 296703:tid 296884] [client 20.226.60.151:56209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/ssla.php"] [unique_id "al9NSSn25uliftkV1n4ERAAAADM"]
[Tue Jul 21 07:43:21.342960 2026] [security2:error] [pid 296703:tid 296837] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/simple.php"] [unique_id "al9NSSn25uliftkV1n4ERQAAAAQ"]
[Tue Jul 21 07:43:21.387309 2026] [security2:error] [pid 296703:tid 296957] [client 74.249.245.134:5530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/info.php"] [unique_id "al9NSSn25uliftkV1n4ESQAAAHw"]
[Tue Jul 21 07:43:21.420784 2026] [security2:error] [pid 296703:tid 296935] [client 20.220.225.223:5261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/wp-css.php"] [unique_id "al9NSSn25uliftkV1n4ESgAAAGY"]
[Tue Jul 21 07:43:21.542051 2026] [security2:error] [pid 296703:tid 296844] [client 20.226.60.151:61965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xyn.php"] [unique_id "al9NSSn25uliftkV1n4ETgAAAAs"]
[Tue Jul 21 07:43:21.551952 2026] [security2:error] [pid 296703:tid 296955] [client 20.104.96.117:4169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/40p9ixjd.php"] [unique_id "al9NSSn25uliftkV1n4EUAAAAHo"]
[Tue Jul 21 07:43:21.627172 2026] [security2:error] [pid 296703:tid 296937] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/init.php"] [unique_id "al9NSSn25uliftkV1n4EUgAAAGg"]
[Tue Jul 21 07:43:21.720841 2026] [autoindex:error] [pid 296703:tid 296838] [client 20.226.60.151:54332] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:21.744477 2026] [security2:error] [pid 296703:tid 296924] [client 122.179.91.63:19931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NSSn25uliftkV1n4EVgAAAFs"]
[Tue Jul 21 07:43:21.747347 2026] [security2:error] [pid 296703:tid 296924] [client 122.179.91.63:19931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NSSn25uliftkV1n4EVgAAAFs"]
[Tue Jul 21 07:43:21.748337 2026] [security2:error] [pid 296703:tid 296879] [client 31.14.72.5:53469] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NSSn25uliftkV1n4EVwAAAC4"]
[Tue Jul 21 07:43:21.815262 2026] [security2:error] [pid 296703:tid 296960] [client 20.220.225.223:34194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/2x.php"] [unique_id "al9NSSn25uliftkV1n4EWwAAAH8"]
[Tue Jul 21 07:43:21.902060 2026] [security2:error] [pid 296703:tid 296891] [client 20.104.96.117:64017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/uiuvs58l.update.php"] [unique_id "al9NSSn25uliftkV1n4EYgAAADo"]
[Tue Jul 21 07:43:21.929969 2026] [security2:error] [pid 296703:tid 296928] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/fpwch.php"] [unique_id "al9NSSn25uliftkV1n4EYwAAAF8"]
[Tue Jul 21 07:43:21.946527 2026] [security2:error] [pid 296703:tid 296932] [client 20.197.195.24:13785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/ops.php"] [unique_id "al9NSSn25uliftkV1n4EZAAAAGM"]
[Tue Jul 21 07:43:22.167971 2026] [autoindex:error] [pid 296703:tid 296944] [client 20.226.60.151:54332] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:22.188247 2026] [security2:error] [pid 296703:tid 296957] [client 20.226.60.151:54332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ccc.php"] [unique_id "al9NSin25uliftkV1n4EbQAAAHw"]
[Tue Jul 21 07:43:22.188747 2026] [security2:error] [pid 296703:tid 296865] [client 20.220.225.223:19714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/hp2.php"] [unique_id "al9NSin25uliftkV1n4EbgAAACA"]
[Tue Jul 21 07:43:22.216560 2026] [security2:error] [pid 296703:tid 296951] [client 20.104.96.117:5057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/for.php"] [unique_id "al9NSin25uliftkV1n4EbwAAAHY"]
[Tue Jul 21 07:43:22.288676 2026] [security2:error] [pid 296703:tid 296853] [client 173.24.185.52:57412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EcQAAABQ"]
[Tue Jul 21 07:43:22.288763 2026] [security2:error] [pid 296703:tid 296853] [client 173.24.185.52:57412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EcQAAABQ"]
[Tue Jul 21 07:43:22.346637 2026] [security2:error] [pid 296703:tid 296716] [remote 5.39.1.236:39046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "brasilmotoeletrica.com"] [uri "/robots.txt"] [unique_id "al9NSin25uliftkV1n4EcwAAOAw"]
[Tue Jul 21 07:43:22.346782 2026] [security2:error] [pid 296703:tid 296889] [client 5.39.1.236:39046] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "brasilmotoeletrica.com"] [uri "/robots.txt"] [unique_id "al9NSin25uliftkV1n4EcwAAOAw"]
[Tue Jul 21 07:43:22.363030 2026] [security2:error] [pid 296703:tid 296743] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EdAAALSc"]
[Tue Jul 21 07:43:22.363142 2026] [security2:error] [pid 296703:tid 296878] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EdAAALSc"]
[Tue Jul 21 07:43:22.404045 2026] [security2:error] [pid 296703:tid 296834] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/domvf.php"] [unique_id "al9NSin25uliftkV1n4EeAAAAAE"]
[Tue Jul 21 07:43:22.436046 2026] [security2:error] [pid 296703:tid 296890] [client 31.14.72.5:53897] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NSin25uliftkV1n4EegAAADk"]
[Tue Jul 21 07:43:22.534940 2026] [security2:error] [pid 296703:tid 296923] [client 74.249.245.134:54351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/edit.php"] [unique_id "al9NSin25uliftkV1n4EfgAAAFo"]
[Tue Jul 21 07:43:22.540949 2026] [security2:error] [pid 296703:tid 296937] [client 20.104.96.117:5063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fit4me.online"] [uri "/raw.php"] [unique_id "al9NSin25uliftkV1n4EfwAAAGg"]
[Tue Jul 21 07:43:22.604969 2026] [security2:error] [pid 296703:tid 296950] [client 20.226.60.151:56224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vivianelages.com.br"] [uri "/zc-131.php"] [unique_id "al9NSin25uliftkV1n4EgwAAAHU"]
[Tue Jul 21 07:43:22.659625 2026] [security2:error] [pid 296703:tid 296940] [client 103.166.103.129:10761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EhAAAAGs"]
[Tue Jul 21 07:43:22.659714 2026] [security2:error] [pid 296703:tid 296940] [client 103.166.103.129:10761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EhAAAAGs"]
[Tue Jul 21 07:43:22.711792 2026] [security2:error] [pid 296703:tid 296848] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp.php"] [unique_id "al9NSin25uliftkV1n4EhQAAAA8"]
[Tue Jul 21 07:43:22.866142 2026] [security2:error] [pid 296703:tid 296917] [client 20.220.225.223:11188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/wp-explorer.php"] [unique_id "al9NSin25uliftkV1n4EigAAAFQ"]
[Tue Jul 21 07:43:22.873879 2026] [security2:error] [pid 296703:tid 296775] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EjAAAc0c"]
[Tue Jul 21 07:43:22.873992 2026] [security2:error] [pid 296703:tid 296948] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NSin25uliftkV1n4EjAAAc0c"]
[Tue Jul 21 07:43:22.996599 2026] [security2:error] [pid 296703:tid 296863] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/class.php"] [unique_id "al9NSin25uliftkV1n4EjQAAAB4"]
[Tue Jul 21 07:43:23.039678 2026] [security2:error] [pid 296703:tid 296892] [client 20.220.225.223:19664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/hp3.php"] [unique_id "al9NSyn25uliftkV1n4EjgAAADs"]
[Tue Jul 21 07:43:23.107128 2026] [security2:error] [pid 296703:tid 296872] [client 31.14.72.5:54257] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raqueldacosta.online"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9NSyn25uliftkV1n4EkAAAACc"]
[Tue Jul 21 07:43:23.191599 2026] [security2:error] [pid 296703:tid 296907] [client 47.128.49.54:50460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.andrelageorthobolics.com.br"] [uri "/robots.txt"] [unique_id "al9NSyn25uliftkV1n4ElgAAAEo"]
[Tue Jul 21 07:43:23.223893 2026] [security2:error] [pid 296703:tid 296865] [client 20.226.60.151:60128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/w.php"] [unique_id "al9NSyn25uliftkV1n4ElwAAACA"]
[Tue Jul 21 07:43:23.375245 2026] [security2:error] [pid 296703:tid 296878] [client 20.226.60.151:59441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/rithin.php"] [unique_id "al9NSyn25uliftkV1n4EnAAAAC0"]
[Tue Jul 21 07:43:23.499248 2026] [security2:error] [pid 296703:tid 296927] [client 37.140.223.191:54249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NSyn25uliftkV1n4EmAAAAF4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:23.530127 2026] [security2:error] [pid 296703:tid 296876] [client 37.140.223.68:59105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NSyn25uliftkV1n4EoAAAACs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:23.561132 2026] [security2:error] [pid 296703:tid 296880] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/echkm.php"] [unique_id "al9NSyn25uliftkV1n4EogAAAC8"]
[Tue Jul 21 07:43:23.578483 2026] [security2:error] [pid 296703:tid 296859] [client 20.197.195.24:49864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/file31.php"] [unique_id "al9NSyn25uliftkV1n4EowAAABo"]
[Tue Jul 21 07:43:23.654037 2026] [security2:error] [pid 296703:tid 296879] [client 74.249.245.134:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/166.php"] [unique_id "al9NSyn25uliftkV1n4EqAAAAC4"]
[Tue Jul 21 07:43:23.654650 2026] [security2:error] [pid 296703:tid 296938] [client 20.220.225.223:19653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/aa1.php"] [unique_id "al9NSyn25uliftkV1n4EqQAAAGk"]
[Tue Jul 21 07:43:23.711361 2026] [security2:error] [pid 296703:tid 296940] [client 20.226.60.151:22351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/a1.php"] [unique_id "al9NSyn25uliftkV1n4EqgAAAGs"]
[Tue Jul 21 07:43:23.798794 2026] [security2:error] [pid 296703:tid 296945] [client 20.226.60.151:61990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9NSyn25uliftkV1n4EqwAAAHA"]
[Tue Jul 21 07:43:23.997312 2026] [security2:error] [pid 296703:tid 296909] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/lib.php"] [unique_id "al9NSyn25uliftkV1n4EswAAAEw"]
[Tue Jul 21 07:43:24.037537 2026] [security2:error] [pid 296703:tid 296929] [client 103.174.34.15:58554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4EtQAAAGA"]
[Tue Jul 21 07:43:24.037995 2026] [security2:error] [pid 296703:tid 296929] [client 103.174.34.15:58554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4EtQAAAGA"]
[Tue Jul 21 07:43:24.059923 2026] [security2:error] [pid 296703:tid 296784] [remote 142.44.233.164:46878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "brasilmotoeletrica.com"] [uri "/"] [unique_id "al9NTCn25uliftkV1n4EtgAADlA"]
[Tue Jul 21 07:43:24.060121 2026] [security2:error] [pid 296703:tid 296847] [client 142.44.233.164:46878] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "brasilmotoeletrica.com"] [uri "/"] [unique_id "al9NTCn25uliftkV1n4EtgAADlA"]
[Tue Jul 21 07:43:24.272034 2026] [security2:error] [pid 296703:tid 296793] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4EvAAAOFk"]
[Tue Jul 21 07:43:24.272187 2026] [security2:error] [pid 296703:tid 296889] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4EvAAAOFk"]
[Tue Jul 21 07:43:24.274277 2026] [security2:error] [pid 296703:tid 296878] [client 20.220.225.223:19267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/acew67.php"] [unique_id "al9NTCn25uliftkV1n4EvQAAAC0"]
[Tue Jul 21 07:43:24.285123 2026] [security2:error] [pid 296703:tid 296943] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/login.php"] [unique_id "al9NTCn25uliftkV1n4EvgAAAG4"]
[Tue Jul 21 07:43:24.604757 2026] [security2:error] [pid 296703:tid 296894] [client 106.215.181.8:19875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4ExQAAAD0"]
[Tue Jul 21 07:43:24.604908 2026] [security2:error] [pid 296703:tid 296894] [client 106.215.181.8:19875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4ExQAAAD0"]
[Tue Jul 21 07:43:24.622399 2026] [security2:error] [pid 296703:tid 296934] [client 20.226.60.151:54336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/FWAZ.php"] [unique_id "al9NTCn25uliftkV1n4ExwAAAGU"]
[Tue Jul 21 07:43:24.625213 2026] [security2:error] [pid 296703:tid 296922] [client 74.249.245.134:5556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/8.php"] [unique_id "al9NTCn25uliftkV1n4EyAAAAFk"]
[Tue Jul 21 07:43:24.784809 2026] [security2:error] [pid 296703:tid 296940] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/a2.php"] [unique_id "al9NTCn25uliftkV1n4EzwAAAGs"]
[Tue Jul 21 07:43:24.826986 2026] [security2:error] [pid 296703:tid 296900] [client 184.75.223.211:58596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4E0AAAAEM"]
[Tue Jul 21 07:43:24.827106 2026] [security2:error] [pid 296703:tid 296900] [client 184.75.223.211:58596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NTCn25uliftkV1n4E0AAAAEM"]
[Tue Jul 21 07:43:25.015563 2026] [security2:error] [pid 296703:tid 296834] [client 182.8.255.181:10169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E1QAAAAE"]
[Tue Jul 21 07:43:25.015694 2026] [security2:error] [pid 296703:tid 296834] [client 182.8.255.181:10169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E1QAAAAE"]
[Tue Jul 21 07:43:25.062147 2026] [security2:error] [pid 296703:tid 296872] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/d61.php"] [unique_id "al9NTSn25uliftkV1n4E1wAAACc"]
[Tue Jul 21 07:43:25.110129 2026] [security2:error] [pid 296703:tid 296810] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E2wAAFWo"]
[Tue Jul 21 07:43:25.110278 2026] [security2:error] [pid 296703:tid 296854] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E2wAAFWo"]
[Tue Jul 21 07:43:25.128571 2026] [security2:error] [pid 296703:tid 296929] [client 5.161.69.178:39250] ModSecurity: Access denied with code 406 (phase 1). Match of "rx (^/administrator/)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "63"] [id "331216"] [rev "2"] [msg "Atomicorp.com WAF Rules: Wordpress DOS Attack Dropped"] [severity "CRITICAL"] [hostname "cotidianorural.com.br"] [uri "/wp-load.php"] [unique_id "al9NTSn25uliftkV1n4E3AAAAGA"]
[Tue Jul 21 07:43:25.210593 2026] [security2:error] [pid 296703:tid 296931] [client 20.226.60.151:54290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/miru1.php"] [unique_id "al9NTSn25uliftkV1n4E4wAAAGI"]
[Tue Jul 21 07:43:25.292379 2026] [security2:error] [pid 296703:tid 296712] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E5AAAVAg"]
[Tue Jul 21 07:43:25.292619 2026] [security2:error] [pid 296703:tid 296917] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E5AAAVAg"]
[Tue Jul 21 07:43:25.339692 2026] [security2:error] [pid 296703:tid 296889] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/info.php"] [unique_id "al9NTSn25uliftkV1n4E5gAAADg"]
[Tue Jul 21 07:43:25.352277 2026] [security2:error] [pid 296703:tid 296935] [client 74.249.245.134:54352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/ws38.php"] [unique_id "al9NTSn25uliftkV1n4E6AAAAGY"]
[Tue Jul 21 07:43:25.452306 2026] [security2:error] [pid 296703:tid 296861] [client 37.140.223.152:31403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NTSn25uliftkV1n4E7AAAABw"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:25.530366 2026] [security2:error] [pid 296703:tid 296807] [remote 182.77.62.24:43960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zooparquevet.com.br"] [uri "/wp-login.php"] [unique_id "al9NTSn25uliftkV1n4E8gAALmc"]
[Tue Jul 21 07:43:25.563247 2026] [security2:error] [pid 296703:tid 296842] [client 20.197.195.24:13741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/file6.php"] [unique_id "al9NTSn25uliftkV1n4E9QAAAAk"]
[Tue Jul 21 07:43:25.616329 2026] [security2:error] [pid 296703:tid 296900] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/11.php"] [unique_id "al9NTSn25uliftkV1n4E9gAAAEM"]
[Tue Jul 21 07:43:25.891288 2026] [security2:error] [pid 296703:tid 296841] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/v2.php"] [unique_id "al9NTSn25uliftkV1n4E_gAAAAg"]
[Tue Jul 21 07:43:25.891789 2026] [security2:error] [pid 296703:tid 296911] [client 103.86.117.203:56180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E_wAAAE4"]
[Tue Jul 21 07:43:25.891945 2026] [security2:error] [pid 296703:tid 296911] [client 103.86.117.203:56180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E_wAAAE4"]
[Tue Jul 21 07:43:25.991557 2026] [security2:error] [pid 296703:tid 296928] [client 20.226.60.151:54280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/aa.php"] [unique_id "al9NTSn25uliftkV1n4FAgAAAF8"]
[Tue Jul 21 07:43:26.094794 2026] [security2:error] [pid 296703:tid 296863] [client 74.249.245.134:17427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/a7.php"] [unique_id "al9NTin25uliftkV1n4FCgAAAB4"]
[Tue Jul 21 07:43:26.097831 2026] [security2:error] [pid 296703:tid 296891] [client 20.63.100.92:2557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NTin25uliftkV1n4FCwAAADo"]
[Tue Jul 21 07:43:26.167492 2026] [security2:error] [pid 296703:tid 296935] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/panel.php"] [unique_id "al9NTin25uliftkV1n4FDgAAAGY"]
[Tue Jul 21 07:43:26.440462 2026] [security2:error] [pid 296703:tid 296888] [client 117.251.86.144:42270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FOgAAADc"]
[Tue Jul 21 07:43:26.440570 2026] [security2:error] [pid 296703:tid 296888] [client 117.251.86.144:42270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FOgAAADc"]
[Tue Jul 21 07:43:26.484382 2026] [security2:error] [pid 296703:tid 296926] [client 122.164.127.47:57490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FOwAAAF0"]
[Tue Jul 21 07:43:26.484499 2026] [security2:error] [pid 296703:tid 296926] [client 122.164.127.47:57490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FOwAAAF0"]
[Tue Jul 21 07:43:26.510184 2026] [security2:error] [pid 296703:tid 296872] [client 122.186.204.214:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FPAAAACc"]
[Tue Jul 21 07:43:26.510290 2026] [security2:error] [pid 296703:tid 296872] [client 122.186.204.214:59074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FPAAAACc"]
[Tue Jul 21 07:43:26.599261 2026] [security2:error] [pid 296703:tid 296940] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/dex.php"] [unique_id "al9NTin25uliftkV1n4FPwAAAGs"]
[Tue Jul 21 07:43:26.649729 2026] [security2:error] [pid 296703:tid 296920] [client 117.247.80.59:31412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FQwAAAFc"]
[Tue Jul 21 07:43:26.649919 2026] [security2:error] [pid 296703:tid 296920] [client 117.247.80.59:31412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FQwAAAFc"]
[Tue Jul 21 07:43:26.668725 2026] [security2:error] [pid 296703:tid 296849] [client 20.220.225.223:5305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/akismet.php"] [unique_id "al9NTin25uliftkV1n4FRAAAABA"]
[Tue Jul 21 07:43:26.686400 2026] [security2:error] [pid 296703:tid 296743] [remote 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FRgAAUCc"]
[Tue Jul 21 07:43:26.686619 2026] [security2:error] [pid 296703:tid 296913] [client 2401:4900:88d1:e59:19d5:3e3b:eedf:b645:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NTin25uliftkV1n4FRgAAUCc"]
[Tue Jul 21 07:43:26.876926 2026] [security2:error] [pid 296703:tid 296908] [client 178.153.91.96:61446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E-wAAAEs"]
[Tue Jul 21 07:43:26.877059 2026] [security2:error] [pid 296703:tid 296908] [client 178.153.91.96:61446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NTSn25uliftkV1n4E-wAAAEs"]
[Tue Jul 21 07:43:26.881534 2026] [security2:error] [pid 296703:tid 296939] [client 74.249.245.134:5521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/classsmtps.php"] [unique_id "al9NTin25uliftkV1n4FUwAAAGo"]
[Tue Jul 21 07:43:26.890645 2026] [security2:error] [pid 296703:tid 296944] [client 4.204.201.85:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "denarios.com.br"] [uri "/1.php"] [unique_id "al9NTin25uliftkV1n4FVAAAAG8"]
[Tue Jul 21 07:43:26.890743 2026] [security2:error] [pid 296703:tid 296944] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/1.php"] [unique_id "al9NTin25uliftkV1n4FVAAAAG8"]
[Tue Jul 21 07:43:26.960349 2026] [security2:error] [pid 296703:tid 296863] [client 20.63.100.92:6187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NTin25uliftkV1n4FWAAAAB4"]
[Tue Jul 21 07:43:26.967562 2026] [autoindex:error] [pid 296703:tid 296917] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:26.978188 2026] [security2:error] [pid 296703:tid 296921] [client 20.197.195.24:13805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/adminfuns.php"] [unique_id "al9NTin25uliftkV1n4FWQAAAFg"]
[Tue Jul 21 07:43:27.197690 2026] [security2:error] [pid 296703:tid 296888] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/ms.php"] [unique_id "al9NTyn25uliftkV1n4FZAAAADc"]
[Tue Jul 21 07:43:27.364278 2026] [security2:error] [pid 296703:tid 296955] [client 136.144.33.215:48943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NTyn25uliftkV1n4FagAAAHo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:27.376590 2026] [security2:error] [pid 296703:tid 296785] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTyn25uliftkV1n4FawAAUFE"]
[Tue Jul 21 07:43:27.376744 2026] [security2:error] [pid 296703:tid 296913] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTyn25uliftkV1n4FawAAUFE"]
[Tue Jul 21 07:43:27.425810 2026] [security2:error] [pid 296703:tid 296881] [client 74.249.245.134:54368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/rip.php"] [unique_id "al9NTyn25uliftkV1n4FbAAAADA"]
[Tue Jul 21 07:43:27.495412 2026] [security2:error] [pid 296703:tid 296947] [client 202.143.127.214:52720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTyn25uliftkV1n4FbwAAAHI"]
[Tue Jul 21 07:43:27.495519 2026] [security2:error] [pid 296703:tid 296947] [client 202.143.127.214:52720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NTyn25uliftkV1n4FbwAAAHI"]
[Tue Jul 21 07:43:27.538447 2026] [autoindex:error] [pid 296703:tid 296834] [client 4.204.201.85:0] AH01276: Cannot serve directory /home2/anap6468/denarios.com.br/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:27.590506 2026] [security2:error] [pid 296703:tid 296758] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NTyn25uliftkV1n4FcAAAJzY"]
[Tue Jul 21 07:43:27.590642 2026] [security2:error] [pid 296703:tid 296872] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NTyn25uliftkV1n4FcAAAJzY"]
[Tue Jul 21 07:43:27.690083 2026] [security2:error] [pid 296703:tid 296938] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/memberfuns.php"] [unique_id "al9NTyn25uliftkV1n4FdQAAAGk"]
[Tue Jul 21 07:43:27.824110 2026] [security2:error] [pid 296703:tid 296869] [client 20.226.60.151:54306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/122.php"] [unique_id "al9NTyn25uliftkV1n4FfAAAACQ"]
[Tue Jul 21 07:43:27.905157 2026] [security2:error] [pid 296703:tid 296871] [client 20.197.195.24:49909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/goods.php"] [unique_id "al9NTyn25uliftkV1n4FfQAAACY"]
[Tue Jul 21 07:43:27.971936 2026] [security2:error] [pid 296703:tid 296943] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/0.php"] [unique_id "al9NTyn25uliftkV1n4FfgAAAG4"]
[Tue Jul 21 07:43:28.187862 2026] [security2:error] [pid 296703:tid 296839] [client 154.192.233.199:58881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUCn25uliftkV1n4FhQAAAAY"]
[Tue Jul 21 07:43:28.188085 2026] [security2:error] [pid 296703:tid 296839] [client 154.192.233.199:58881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUCn25uliftkV1n4FhQAAAAY"]
[Tue Jul 21 07:43:28.217706 2026] [security2:error] [pid 296703:tid 296784] [remote 199.189.225.40:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexandrevitor1781543539748.0711679.meusitehostgator.com.br"] [uri "/wp-login.php"] [unique_id "al9NUCn25uliftkV1n4FhwAABVA"]
[Tue Jul 21 07:43:28.283618 2026] [security2:error] [pid 296703:tid 296950] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/BDKR28.php"] [unique_id "al9NUCn25uliftkV1n4FiQAAAHU"]
[Tue Jul 21 07:43:28.347764 2026] [security2:error] [pid 296703:tid 296859] [client 20.63.100.92:2294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/dp.php"] [unique_id "al9NUCn25uliftkV1n4FjAAAABo"]
[Tue Jul 21 07:43:28.407534 2026] [security2:error] [pid 296703:tid 296873] [client 74.249.245.134:5551] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/1.php"] [unique_id "al9NUCn25uliftkV1n4FjwAAACg"]
[Tue Jul 21 07:43:28.407653 2026] [security2:error] [pid 296703:tid 296873] [client 74.249.245.134:5551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/1.php"] [unique_id "al9NUCn25uliftkV1n4FjwAAACg"]
[Tue Jul 21 07:43:28.454731 2026] [security2:error] [pid 296703:tid 296804] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NUCn25uliftkV1n4FkQAAemQ"]
[Tue Jul 21 07:43:28.677346 2026] [security2:error] [pid 296703:tid 296892] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/green1.php"] [unique_id "al9NUCn25uliftkV1n4FlAAAADs"]
[Tue Jul 21 07:43:28.708431 2026] [security2:error] [pid 296703:tid 296919] [client 117.217.38.194:52572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUCn25uliftkV1n4FmAAAAFY"]
[Tue Jul 21 07:43:28.708889 2026] [security2:error] [pid 296703:tid 296919] [client 117.217.38.194:52572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUCn25uliftkV1n4FmAAAAFY"]
[Tue Jul 21 07:43:28.803079 2026] [security2:error] [pid 296703:tid 296815] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9NUCn25uliftkV1n4FmwAACG8"]
[Tue Jul 21 07:43:28.856318 2026] [security2:error] [pid 296703:tid 296928] [client 20.197.195.24:13739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/100.php"] [unique_id "al9NUCn25uliftkV1n4FngAAAF8"]
[Tue Jul 21 07:43:28.977890 2026] [security2:error] [pid 296703:tid 296931] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/nc4.php"] [unique_id "al9NUCn25uliftkV1n4FoAAAAGI"]
[Tue Jul 21 07:43:29.026493 2026] [security2:error] [pid 296703:tid 296884] [client 20.226.60.151:61966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/get.php"] [unique_id "al9NUSn25uliftkV1n4FogAAADM"]
[Tue Jul 21 07:43:29.120429 2026] [security2:error] [pid 296703:tid 296897] [client 194.99.104.35:58014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NUSn25uliftkV1n4FpwAAAEA"]
[Tue Jul 21 07:43:29.120513 2026] [security2:error] [pid 296703:tid 296897] [client 194.99.104.35:58014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NUSn25uliftkV1n4FpwAAAEA"]
[Tue Jul 21 07:43:29.141798 2026] [security2:error] [pid 296703:tid 296817] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NUSn25uliftkV1n4FqAAAbnE"]
[Tue Jul 21 07:43:29.288690 2026] [security2:error] [pid 296703:tid 296923] [client 20.220.225.223:5309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/ace2.php"] [unique_id "al9NUSn25uliftkV1n4FrwAAAFo"]
[Tue Jul 21 07:43:29.303296 2026] [security2:error] [pid 296703:tid 296868] [client 20.197.195.24:13770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/about.php"] [unique_id "al9NUSn25uliftkV1n4FsAAAACM"]
[Tue Jul 21 07:43:29.310329 2026] [security2:error] [pid 296703:tid 296797] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NUSn25uliftkV1n4FsQAADl0"]
[Tue Jul 21 07:43:29.338556 2026] [security2:error] [pid 296703:tid 296885] [client 20.226.60.151:61982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/as.php"] [unique_id "al9NUSn25uliftkV1n4FsgAAADQ"]
[Tue Jul 21 07:43:29.456421 2026] [security2:error] [pid 296703:tid 296922] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/a1.php"] [unique_id "al9NUSn25uliftkV1n4FtgAAAFk"]
[Tue Jul 21 07:43:29.527203 2026] [security2:error] [pid 296703:tid 296934] [client 74.249.245.134:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/chosen.php"] [unique_id "al9NUSn25uliftkV1n4FuQAAAGU"]
[Tue Jul 21 07:43:29.602025 2026] [security2:error] [pid 296703:tid 296781] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9NUSn25uliftkV1n4FuwAAek0"]
[Tue Jul 21 07:43:29.772301 2026] [security2:error] [pid 296703:tid 296707] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NUSn25uliftkV1n4FxQAADwM"]
[Tue Jul 21 07:43:29.785772 2026] [security2:error] [pid 296703:tid 296727] [remote 124.55.178.99:51676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9NUSn25uliftkV1n4FxgAAaBc"]
[Tue Jul 21 07:43:29.922382 2026] [security2:error] [pid 296703:tid 296854] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/eee.php"] [unique_id "al9NUSn25uliftkV1n4FyQAAABU"]
[Tue Jul 21 07:43:29.964167 2026] [security2:error] [pid 296703:tid 296884] [client 20.226.60.151:54398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ccou.php"] [unique_id "al9NUSn25uliftkV1n4FzgAAADM"]
[Tue Jul 21 07:43:29.985512 2026] [core:error] [pid 296703:tid 296825] [remote 52.167.144.232:64881] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:43:29.985541 2026] [core:error] [pid 296703:tid 296825] [remote 52.167.144.232:64881] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:43:30.032222 2026] [security2:error] [pid 296703:tid 296821] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9NUin25uliftkV1n4F0AAAJHU"]
[Tue Jul 21 07:43:30.140288 2026] [security2:error] [pid 296703:tid 296844] [client 20.197.195.24:49858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/about.php"] [unique_id "al9NUin25uliftkV1n4F0QAAAAs"]
[Tue Jul 21 07:43:30.197090 2026] [security2:error] [pid 296703:tid 296929] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-aothait.php"] [unique_id "al9NUin25uliftkV1n4F0gAAAGA"]
[Tue Jul 21 07:43:30.217293 2026] [security2:error] [pid 296703:tid 296719] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NUin25uliftkV1n4F1AAASg8"]
[Tue Jul 21 07:43:30.247917 2026] [security2:error] [pid 296703:tid 296880] [client 20.226.60.151:54376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/w3lls.php"] [unique_id "al9NUin25uliftkV1n4F1QAAAC8"]
[Tue Jul 21 07:43:30.267026 2026] [security2:error] [pid 296703:tid 296927] [client 59.96.220.140:60701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NUin25uliftkV1n4F1wAAAF4"]
[Tue Jul 21 07:43:30.267145 2026] [security2:error] [pid 296703:tid 296927] [client 59.96.220.140:60701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NUin25uliftkV1n4F1wAAAF4"]
[Tue Jul 21 07:43:30.302478 2026] [security2:error] [pid 296703:tid 296717] [remote 41.186.86.12:21421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9NUin25uliftkV1n4F2AAAEw0"]
[Tue Jul 21 07:43:30.351563 2026] [security2:error] [pid 296703:tid 296734] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NUin25uliftkV1n4F3AAATh4"]
[Tue Jul 21 07:43:30.372481 2026] [security2:error] [pid 296703:tid 296950] [client 20.197.195.24:49799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/admin.php"] [unique_id "al9NUin25uliftkV1n4F3gAAAHU"]
[Tue Jul 21 07:43:30.463203 2026] [security2:error] [pid 296703:tid 296934] [client 20.220.225.223:19279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/bscclapb.php"] [unique_id "al9NUin25uliftkV1n4F4gAAAGU"]
[Tue Jul 21 07:43:30.463234 2026] [security2:error] [pid 296703:tid 296833] [client 20.220.225.223:11154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.agendazap.com.br"] [uri "/ms.php"] [unique_id "al9NUin25uliftkV1n4F4QAAAAA"]
[Tue Jul 21 07:43:30.508058 2026] [security2:error] [pid 296703:tid 296905] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/config.json.php"] [unique_id "al9NUin25uliftkV1n4F5AAAAEg"]
[Tue Jul 21 07:43:30.517452 2026] [security2:error] [pid 296703:tid 296955] [client 20.220.225.223:34193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/kq1.php"] [unique_id "al9NUin25uliftkV1n4F5QAAAHo"]
[Tue Jul 21 07:43:30.529691 2026] [security2:error] [pid 296703:tid 296730] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NUin25uliftkV1n4F5gAACRo"]
[Tue Jul 21 07:43:30.590360 2026] [security2:error] [pid 296703:tid 296874] [client 103.106.20.201:55509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUin25uliftkV1n4F6AAAACk"]
[Tue Jul 21 07:43:30.590501 2026] [security2:error] [pid 296703:tid 296874] [client 103.106.20.201:55509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUin25uliftkV1n4F6AAAACk"]
[Tue Jul 21 07:43:30.661267 2026] [security2:error] [pid 296703:tid 296848] [client 20.197.195.24:13726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/admin.php"] [unique_id "al9NUin25uliftkV1n4F6gAAAA8"]
[Tue Jul 21 07:43:30.666549 2026] [security2:error] [pid 296703:tid 296718] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NUin25uliftkV1n4F6wAAaA4"]
[Tue Jul 21 07:43:30.705560 2026] [security2:error] [pid 296703:tid 296841] [client 20.226.60.151:54310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/test1.php"] [unique_id "al9NUin25uliftkV1n4F7AAAAAg"]
[Tue Jul 21 07:43:30.799151 2026] [security2:error] [pid 296703:tid 296744] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.farmaciafarmula.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NUin25uliftkV1n4F8QAAWyg"]
[Tue Jul 21 07:43:30.847151 2026] [security2:error] [pid 296703:tid 296884] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9NUin25uliftkV1n4F9AAAADM"]
[Tue Jul 21 07:43:30.911580 2026] [security2:error] [pid 296703:tid 296897] [client 20.226.60.151:54276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/database.php"] [unique_id "al9NUin25uliftkV1n4F-QAAAEA"]
[Tue Jul 21 07:43:30.948264 2026] [security2:error] [pid 296703:tid 296956] [client 20.197.195.24:49877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/themes.php"] [unique_id "al9NUin25uliftkV1n4F-wAAAHs"]
[Tue Jul 21 07:43:31.035357 2026] [security2:error] [pid 296703:tid 296900] [client 122.162.144.145:33018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NUyn25uliftkV1n4GAAAAAEM"]
[Tue Jul 21 07:43:31.035472 2026] [security2:error] [pid 296703:tid 296900] [client 122.162.144.145:33018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NUyn25uliftkV1n4GAAAAAEM"]
[Tue Jul 21 07:43:31.130431 2026] [security2:error] [pid 296703:tid 296921] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/k2.php"] [unique_id "al9NUyn25uliftkV1n4GAQAAAFg"]
[Tue Jul 21 07:43:31.167436 2026] [security2:error] [pid 296703:tid 296934] [client 74.249.245.134:5558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/css.php"] [unique_id "al9NUyn25uliftkV1n4GAwAAAGU"]
[Tue Jul 21 07:43:31.208199 2026] [security2:error] [pid 296703:tid 296925] [client 20.104.96.117:30437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/v543.php"] [unique_id "al9NUyn25uliftkV1n4GBAAAAFw"]
[Tue Jul 21 07:43:31.254279 2026] [autoindex:error] [pid 296703:tid 296955] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:31.318547 2026] [security2:error] [pid 296703:tid 296881] [client 139.167.225.182:53185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUyn25uliftkV1n4GDgAAADA"]
[Tue Jul 21 07:43:31.318653 2026] [security2:error] [pid 296703:tid 296881] [client 139.167.225.182:53185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NUyn25uliftkV1n4GDgAAADA"]
[Tue Jul 21 07:43:31.411422 2026] [security2:error] [pid 296703:tid 296902] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9NUyn25uliftkV1n4GEgAAAEU"]
[Tue Jul 21 07:43:31.516186 2026] [security2:error] [pid 296703:tid 296894] [client 136.144.33.108:52603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NUyn25uliftkV1n4GFwAAAD0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:31.623263 2026] [security2:error] [pid 296703:tid 296871] [client 34.74.242.206:1636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.robertaramos.com.br"] [uri "/robots.txt"] [unique_id "al9NUyn25uliftkV1n4GGgAAACY"]
[Tue Jul 21 07:43:31.623348 2026] [security2:error] [pid 296703:tid 296871] [client 34.74.242.206:1636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.robertaramos.com.br"] [uri "/robots.txt"] [unique_id "al9NUyn25uliftkV1n4GGgAAACY"]
[Tue Jul 21 07:43:31.660902 2026] [security2:error] [pid 296703:tid 296892] [client 20.226.60.151:54346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file.php"] [unique_id "al9NUyn25uliftkV1n4GGwAAADs"]
[Tue Jul 21 07:43:31.745735 2026] [security2:error] [pid 296703:tid 296929] [client 20.226.60.151:22393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/eee.php"] [unique_id "al9NUyn25uliftkV1n4GHgAAAGA"]
[Tue Jul 21 07:43:31.773004 2026] [security2:error] [pid 296703:tid 296880] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9NUyn25uliftkV1n4GHwAAAC8"]
[Tue Jul 21 07:43:31.832561 2026] [security2:error] [pid 296703:tid 296951] [client 20.220.225.223:19313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/else1.php"] [unique_id "al9NUyn25uliftkV1n4GIgAAAHY"]
[Tue Jul 21 07:43:31.860637 2026] [security2:error] [pid 296703:tid 296911] [client 34.74.242.206:1654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.robertaramos.com.br"] [uri "/"] [unique_id "al9NUyn25uliftkV1n4GKQAAAE4"]
[Tue Jul 21 07:43:31.860726 2026] [security2:error] [pid 296703:tid 296911] [client 34.74.242.206:1654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.robertaramos.com.br"] [uri "/"] [unique_id "al9NUyn25uliftkV1n4GKQAAAE4"]
[Tue Jul 21 07:43:32.047639 2026] [security2:error] [pid 296703:tid 296888] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9NVCn25uliftkV1n4GMwAAADc"]
[Tue Jul 21 07:43:32.210783 2026] [security2:error] [pid 296703:tid 296834] [client 20.226.60.151:60123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/file.php"] [unique_id "al9NVCn25uliftkV1n4GNwAAAAE"]
[Tue Jul 21 07:43:32.314390 2026] [security2:error] [pid 296703:tid 296884] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/for.php"] [unique_id "al9NVCn25uliftkV1n4GOwAAADM"]
[Tue Jul 21 07:43:32.593624 2026] [security2:error] [pid 296703:tid 296711] [remote 202.51.202.242:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9NVCn25uliftkV1n4GSgAAWQc"]
[Tue Jul 21 07:43:32.614429 2026] [security2:error] [pid 296703:tid 296947] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/raw.php"] [unique_id "al9NVCn25uliftkV1n4GSwAAAHI"]
[Tue Jul 21 07:43:32.634604 2026] [security2:error] [pid 296703:tid 296852] [client 20.226.60.151:54395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/777.php"] [unique_id "al9NVCn25uliftkV1n4GTAAAABM"]
[Tue Jul 21 07:43:32.645284 2026] [security2:error] [pid 296703:tid 296926] [client 193.36.225.123:32285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NUyn25uliftkV1n4GEwAAAF0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:32.899692 2026] [security2:error] [pid 296703:tid 296944] [client 173.24.185.52:57881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NVCn25uliftkV1n4GVAAAAG8"]
[Tue Jul 21 07:43:32.899783 2026] [security2:error] [pid 296703:tid 296944] [client 173.24.185.52:57881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NVCn25uliftkV1n4GVAAAAG8"]
[Tue Jul 21 07:43:33.030659 2026] [security2:error] [pid 296703:tid 296939] [client 20.197.195.24:49857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/.well-known/about.php"] [unique_id "al9NVSn25uliftkV1n4GXAAAAGo"]
[Tue Jul 21 07:43:33.114646 2026] [security2:error] [pid 296703:tid 296899] [client 20.226.60.151:61984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ssixta.php"] [unique_id "al9NVSn25uliftkV1n4GYQAAAEI"]
[Tue Jul 21 07:43:33.203032 2026] [security2:error] [pid 296703:tid 296938] [client 122.179.91.63:30711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GYwAAAGk"]
[Tue Jul 21 07:43:33.203139 2026] [security2:error] [pid 296703:tid 296938] [client 122.179.91.63:30711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GYwAAAGk"]
[Tue Jul 21 07:43:33.269005 2026] [security2:error] [pid 296703:tid 296783] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GZAAAWU8"]
[Tue Jul 21 07:43:33.269154 2026] [security2:error] [pid 296703:tid 296922] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GZAAAWU8"]
[Tue Jul 21 07:43:33.329733 2026] [security2:error] [pid 296703:tid 296926] [client 20.197.195.24:13815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9NVSn25uliftkV1n4GZwAAAF0"]
[Tue Jul 21 07:43:33.392124 2026] [security2:error] [pid 296703:tid 296780] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GawAADkw"]
[Tue Jul 21 07:43:33.392242 2026] [security2:error] [pid 296703:tid 296847] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GawAADkw"]
[Tue Jul 21 07:43:33.429603 2026] [security2:error] [pid 296703:tid 296838] [client 103.166.103.129:11311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GbQAAAAU"]
[Tue Jul 21 07:43:33.429695 2026] [security2:error] [pid 296703:tid 296838] [client 103.166.103.129:11311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GbQAAAAU"]
[Tue Jul 21 07:43:33.490245 2026] [security2:error] [pid 296703:tid 296873] [client 152.59.154.239:56916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GbwAAACg"]
[Tue Jul 21 07:43:33.490590 2026] [security2:error] [pid 296703:tid 296873] [client 152.59.154.239:56916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVSn25uliftkV1n4GbwAAACg"]
[Tue Jul 21 07:43:33.613357 2026] [security2:error] [pid 296703:tid 296909] [client 74.249.245.134:5559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/php.php"] [unique_id "al9NVSn25uliftkV1n4GdgAAAEw"]
[Tue Jul 21 07:43:33.647639 2026] [security2:error] [pid 296703:tid 296949] [client 20.197.195.24:49811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wefile.php"] [unique_id "al9NVSn25uliftkV1n4GeAAAAHQ"]
[Tue Jul 21 07:43:33.808644 2026] [security2:error] [pid 296703:tid 296902] [client 20.220.225.223:19711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/tkikikoko.php"] [unique_id "al9NVSn25uliftkV1n4GewAAAEU"]
[Tue Jul 21 07:43:33.889368 2026] [security2:error] [pid 296703:tid 296841] [client 20.197.195.24:13725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9NVSn25uliftkV1n4GfAAAAAg"]
[Tue Jul 21 07:43:33.934695 2026] [security2:error] [pid 296703:tid 296955] [client 20.226.60.151:60113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/1c.php"] [unique_id "al9NVSn25uliftkV1n4GgQAAAHo"]
[Tue Jul 21 07:43:33.960383 2026] [security2:error] [pid 296703:tid 296951] [client 216.73.160.188:58045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/wp-login.php"] [unique_id "al9NVSn25uliftkV1n4GgwAAAHY"]
[Tue Jul 21 07:43:34.005715 2026] [security2:error] [pid 296703:tid 296899] [client 20.63.100.92:7694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/old.php"] [unique_id "al9NVin25uliftkV1n4GhQAAAEI"]
[Tue Jul 21 07:43:34.194914 2026] [security2:error] [pid 296703:tid 296952] [client 20.104.96.117:30602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/sixxis.php"] [unique_id "al9NVin25uliftkV1n4GiwAAAHc"]
[Tue Jul 21 07:43:34.230450 2026] [security2:error] [pid 296703:tid 296855] [client 103.29.114.44:62139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVin25uliftkV1n4GhgAAABY"]
[Tue Jul 21 07:43:34.230582 2026] [security2:error] [pid 296703:tid 296855] [client 103.29.114.44:62139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVin25uliftkV1n4GhgAAABY"]
[Tue Jul 21 07:43:34.241631 2026] [autoindex:error] [pid 296703:tid 296913] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:34.311190 2026] [autoindex:error] [pid 296703:tid 296937] [client 20.197.195.24:13705] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:34.326627 2026] [security2:error] [pid 296703:tid 296926] [client 20.197.195.24:13705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9NVin25uliftkV1n4GkAAAAF0"]
[Tue Jul 21 07:43:34.473571 2026] [security2:error] [pid 296703:tid 296958] [client 37.140.223.191:32275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NVin25uliftkV1n4GlgAAAH0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:34.628601 2026] [security2:error] [pid 296703:tid 296934] [client 20.197.195.24:13718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/8.php"] [unique_id "al9NVin25uliftkV1n4GnQAAAGU"]
[Tue Jul 21 07:43:34.731413 2026] [security2:error] [pid 296703:tid 296880] [client 103.174.34.15:59032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVin25uliftkV1n4GoAAAAC8"]
[Tue Jul 21 07:43:34.731551 2026] [security2:error] [pid 296703:tid 296880] [client 103.174.34.15:59032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVin25uliftkV1n4GoAAAAC8"]
[Tue Jul 21 07:43:34.783744 2026] [security2:error] [pid 296703:tid 296859] [client 128.127.105.184:44556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9NVin25uliftkV1n4GowAAABo"]
[Tue Jul 21 07:43:34.783913 2026] [security2:error] [pid 296703:tid 296859] [client 128.127.105.184:44556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9NVin25uliftkV1n4GowAAABo"]
[Tue Jul 21 07:43:34.945753 2026] [security2:error] [pid 296703:tid 296915] [client 20.226.60.151:61961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/test2.php"] [unique_id "al9NVin25uliftkV1n4GqAAAAFI"]
[Tue Jul 21 07:43:34.972577 2026] [security2:error] [pid 296703:tid 296921] [client 20.226.60.151:50819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/fffm.php"] [unique_id "al9NVin25uliftkV1n4GqgAAAFg"]
[Tue Jul 21 07:43:35.037480 2026] [security2:error] [pid 296703:tid 296853] [client 20.226.60.151:22971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-aothait.php"] [unique_id "al9NVyn25uliftkV1n4GrQAAABQ"]
[Tue Jul 21 07:43:35.151689 2026] [security2:error] [pid 296703:tid 296808] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GswAATGg"]
[Tue Jul 21 07:43:35.151798 2026] [security2:error] [pid 296703:tid 296909] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GswAATGg"]
[Tue Jul 21 07:43:35.243108 2026] [security2:error] [pid 296703:tid 296847] [client 106.215.181.8:31009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GtwAAAA4"]
[Tue Jul 21 07:43:35.243269 2026] [security2:error] [pid 296703:tid 296847] [client 106.215.181.8:31009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GtwAAAA4"]
[Tue Jul 21 07:43:35.342245 2026] [security2:error] [pid 296703:tid 296888] [client 20.197.195.24:13750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-content/admin.php"] [unique_id "al9NVyn25uliftkV1n4GuAAAADc"]
[Tue Jul 21 07:43:35.441695 2026] [security2:error] [pid 296703:tid 296868] [client 74.249.245.134:54396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/aa.php"] [unique_id "al9NVyn25uliftkV1n4GwgAAACM"]
[Tue Jul 21 07:43:35.523147 2026] [security2:error] [pid 296703:tid 296949] [client 182.8.255.181:17514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GyAAAAHQ"]
[Tue Jul 21 07:43:35.523318 2026] [security2:error] [pid 296703:tid 296949] [client 182.8.255.181:17514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GyAAAAHQ"]
[Tue Jul 21 07:43:35.574339 2026] [security2:error] [pid 296703:tid 296904] [client 20.104.96.117:30420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/ip.php"] [unique_id "al9NVyn25uliftkV1n4GzQAAAEc"]
[Tue Jul 21 07:43:35.577450 2026] [security2:error] [pid 296703:tid 296955] [client 178.153.91.96:62112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GzgAAAHo"]
[Tue Jul 21 07:43:35.577563 2026] [security2:error] [pid 296703:tid 296955] [client 178.153.91.96:62112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4GzgAAAHo"]
[Tue Jul 21 07:43:35.609364 2026] [security2:error] [pid 296703:tid 296874] [client 20.197.195.24:13730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/f6.php"] [unique_id "al9NVyn25uliftkV1n4G0gAAACk"]
[Tue Jul 21 07:43:35.706159 2026] [security2:error] [pid 296703:tid 296921] [client 20.220.225.223:34187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/zzz.php"] [unique_id "al9NVyn25uliftkV1n4G1wAAAFg"]
[Tue Jul 21 07:43:35.720549 2026] [security2:error] [pid 296703:tid 296846] [client 20.220.225.223:19969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9NVyn25uliftkV1n4G2AAAAA0"]
[Tue Jul 21 07:43:35.868955 2026] [security2:error] [pid 296703:tid 296767] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4G3QAAZT8"]
[Tue Jul 21 07:43:35.869113 2026] [security2:error] [pid 296703:tid 296934] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4G3QAAZT8"]
[Tue Jul 21 07:43:35.872784 2026] [security2:error] [pid 296703:tid 296730] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4G3gAAYho"]
[Tue Jul 21 07:43:35.872947 2026] [security2:error] [pid 296703:tid 296931] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NVyn25uliftkV1n4G3gAAYho"]
[Tue Jul 21 07:43:35.924682 2026] [security2:error] [pid 296703:tid 296737] [remote 37.139.53.5:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NVyn25uliftkV1n4G3wAAbyE"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:35.924858 2026] [security2:error] [pid 296703:tid 296944] [client 37.139.53.5:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NVyn25uliftkV1n4G3wAAbyE"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:36.094563 2026] [autoindex:error] [pid 296703:tid 296872] [client 3.219.86.171:27103] AH01276: Cannot serve directory /home3/bilili18/lojasafrodite.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:36.122251 2026] [security2:error] [pid 296703:tid 296929] [client 20.226.60.151:54322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/buy.php"] [unique_id "al9NWCn25uliftkV1n4G6wAAAGA"]
[Tue Jul 21 07:43:36.130503 2026] [security2:error] [pid 296703:tid 296770] [remote 37.139.53.5:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NWCn25uliftkV1n4G7QAAI0I"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:36.130637 2026] [security2:error] [pid 296703:tid 296868] [client 37.139.53.5:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NWCn25uliftkV1n4G7QAAI0I"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:36.188218 2026] [security2:error] [pid 296703:tid 296940] [client 20.197.195.24:13721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/inputs.php"] [unique_id "al9NWCn25uliftkV1n4G8QAAAGs"]
[Tue Jul 21 07:43:36.273286 2026] [security2:error] [pid 296703:tid 296714] [remote 188.95.113.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9NWCn25uliftkV1n4G9AAAXgo"]
[Tue Jul 21 07:43:36.348212 2026] [security2:error] [pid 296703:tid 296932] [client 103.86.117.203:56718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NWCn25uliftkV1n4G-gAAAGM"]
[Tue Jul 21 07:43:36.348342 2026] [security2:error] [pid 296703:tid 296932] [client 103.86.117.203:56718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NWCn25uliftkV1n4G-gAAAGM"]
[Tue Jul 21 07:43:36.860040 2026] [security2:error] [pid 296703:tid 296908] [client 172.245.102.42:61615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NVyn25uliftkV1n4G1gAAAEs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:36.950497 2026] [security2:error] [pid 296703:tid 296833] [client 122.164.127.47:58058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NWCn25uliftkV1n4HCgAAAAA"]
[Tue Jul 21 07:43:36.952302 2026] [security2:error] [pid 296703:tid 296833] [client 122.164.127.47:58058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NWCn25uliftkV1n4HCgAAAAA"]
[Tue Jul 21 07:43:36.982914 2026] [security2:error] [pid 296703:tid 296950] [client 41.68.90.219:62155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWCn25uliftkV1n4HBwAAAHU"]
[Tue Jul 21 07:43:36.983018 2026] [security2:error] [pid 296703:tid 296950] [client 41.68.90.219:62155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWCn25uliftkV1n4HBwAAAHU"]
[Tue Jul 21 07:43:37.033806 2026] [security2:error] [pid 296703:tid 296868] [client 20.197.195.24:13806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/inputs.php"] [unique_id "al9NWSn25uliftkV1n4HDgAAACM"]
[Tue Jul 21 07:43:37.036967 2026] [security2:error] [pid 296703:tid 296874] [client 117.251.86.144:34918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HEQAAACk"]
[Tue Jul 21 07:43:37.037099 2026] [security2:error] [pid 296703:tid 296874] [client 117.251.86.144:34918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HEQAAACk"]
[Tue Jul 21 07:43:37.065629 2026] [security2:error] [pid 296703:tid 296920] [client 20.226.60.151:60097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ssend.php"] [unique_id "al9NWSn25uliftkV1n4HGQAAAFc"]
[Tue Jul 21 07:43:37.156072 2026] [security2:error] [pid 296703:tid 296881] [client 20.220.225.223:34179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wicked.php"] [unique_id "al9NWSn25uliftkV1n4HHwAAADA"]
[Tue Jul 21 07:43:37.175592 2026] [security2:error] [pid 296703:tid 296846] [client 122.186.204.214:59611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HIAAAAA0"]
[Tue Jul 21 07:43:37.175726 2026] [security2:error] [pid 296703:tid 296846] [client 122.186.204.214:59611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HIAAAAA0"]
[Tue Jul 21 07:43:37.187325 2026] [security2:error] [pid 296703:tid 296937] [client 74.249.245.134:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/bolt.php"] [unique_id "al9NWSn25uliftkV1n4HIQAAAGg"]
[Tue Jul 21 07:43:37.231546 2026] [security2:error] [pid 296703:tid 296809] [remote 97.74.93.24:36948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compressoresra.com.br"] [uri "/wp-login.php"] [unique_id "al9NWSn25uliftkV1n4HJQAAM2k"]
[Tue Jul 21 07:43:37.260934 2026] [security2:error] [pid 296703:tid 296759] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HJwAAdDc"]
[Tue Jul 21 07:43:37.261062 2026] [security2:error] [pid 296703:tid 296949] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HJwAAdDc"]
[Tue Jul 21 07:43:37.469148 2026] [security2:error] [pid 296703:tid 296903] [client 117.247.80.59:28758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HLwAAAEY"]
[Tue Jul 21 07:43:37.469270 2026] [security2:error] [pid 296703:tid 296903] [client 117.247.80.59:28758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWSn25uliftkV1n4HLwAAAEY"]
[Tue Jul 21 07:43:37.505129 2026] [security2:error] [pid 296703:tid 296919] [client 20.197.195.24:13777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/classwithtostring.php"] [unique_id "al9NWSn25uliftkV1n4HMAAAAFY"]
[Tue Jul 21 07:43:37.962372 2026] [security2:error] [pid 296703:tid 296765] [remote 173.252.82.1:33652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9NWSn25uliftkV1n4HOwAACT0"]
[Tue Jul 21 07:43:37.975512 2026] [security2:error] [pid 296703:tid 296925] [client 37.140.223.157:59393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NWSn25uliftkV1n4HPgAAAFw"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:38.018909 2026] [security2:error] [pid 296703:tid 296902] [client 20.63.100.92:2534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/ms-new.php"] [unique_id "al9NWin25uliftkV1n4HPwAAAEU"]
[Tue Jul 21 07:43:38.135210 2026] [security2:error] [pid 296703:tid 296866] [client 173.239.214.252:28175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.214.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9NWin25uliftkV1n4HQgAAACE"]
[Tue Jul 21 07:43:38.140175 2026] [security2:error] [pid 296703:tid 296789] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NWin25uliftkV1n4HRAAAWFU"]
[Tue Jul 21 07:43:38.140336 2026] [security2:error] [pid 296703:tid 296921] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NWin25uliftkV1n4HRAAAWFU"]
[Tue Jul 21 07:43:38.203330 2026] [security2:error] [pid 296703:tid 296952] [client 20.197.195.24:13703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9NWin25uliftkV1n4HRwAAAHc"]
[Tue Jul 21 07:43:38.346436 2026] [security2:error] [pid 296703:tid 296869] [client 20.104.96.117:30899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/kq1.php"] [unique_id "al9NWin25uliftkV1n4HTwAAACQ"]
[Tue Jul 21 07:43:38.425833 2026] [security2:error] [pid 296703:tid 296873] [client 202.143.127.214:53145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWin25uliftkV1n4HVAAAACg"]
[Tue Jul 21 07:43:38.425995 2026] [security2:error] [pid 296703:tid 296873] [client 202.143.127.214:53145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWin25uliftkV1n4HVAAAACg"]
[Tue Jul 21 07:43:38.461296 2026] [security2:error] [pid 296703:tid 296879] [client 20.226.60.151:22371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/config.json.php"] [unique_id "al9NWin25uliftkV1n4HVQAAAC4"]
[Tue Jul 21 07:43:38.462927 2026] [security2:error] [pid 296703:tid 296889] [client 185.198.240.204:36991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9NWSn25uliftkV1n4HLgAAADg"]
[Tue Jul 21 07:43:38.548770 2026] [security2:error] [pid 296703:tid 296784] [remote 207.182.27.255:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NWin25uliftkV1n4HSAAAPVA"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:38.836845 2026] [security2:error] [pid 296703:tid 296842] [client 20.197.195.24:49810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-blog.php"] [unique_id "al9NWin25uliftkV1n4HYgAAAAk"]
[Tue Jul 21 07:43:38.991053 2026] [security2:error] [pid 296703:tid 296859] [client 20.226.60.151:60141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/item.php"] [unique_id "al9NWin25uliftkV1n4HZAAAABo"]
[Tue Jul 21 07:43:39.077054 2026] [security2:error] [pid 296703:tid 296955] [client 74.249.245.134:5564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/x.php"] [unique_id "al9NWyn25uliftkV1n4HZQAAAHo"]
[Tue Jul 21 07:43:39.190506 2026] [security2:error] [pid 296703:tid 296874] [client 117.217.38.194:53054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWyn25uliftkV1n4HbwAAACk"]
[Tue Jul 21 07:43:39.190613 2026] [security2:error] [pid 296703:tid 296874] [client 117.217.38.194:53054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWyn25uliftkV1n4HbwAAACk"]
[Tue Jul 21 07:43:39.220555 2026] [security2:error] [pid 296703:tid 296894] [client 207.182.27.255:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NWin25uliftkV1n4HSAAAPVA"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:39.480765 2026] [security2:error] [pid 296703:tid 296811] [remote 65.111.12.194:19395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.12.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NWyn25uliftkV1n4HgAAAO2s"]
[Tue Jul 21 07:43:39.902945 2026] [security2:error] [pid 296703:tid 296944] [client 154.192.233.199:59817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWyn25uliftkV1n4HjgAAAG8"]
[Tue Jul 21 07:43:39.903119 2026] [security2:error] [pid 296703:tid 296944] [client 154.192.233.199:59817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NWyn25uliftkV1n4HjgAAAG8"]
[Tue Jul 21 07:43:39.940085 2026] [security2:error] [pid 296703:tid 296931] [client 20.104.96.117:30442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9NWyn25uliftkV1n4HjwAAAGI"]
[Tue Jul 21 07:43:39.993927 2026] [security2:error] [pid 296703:tid 296856] [client 20.63.100.92:5386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/track.php"] [unique_id "al9NWyn25uliftkV1n4HkQAAABc"]
[Tue Jul 21 07:43:40.003854 2026] [security2:error] [pid 296703:tid 296924] [client 20.197.192.193:58217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NXCn25uliftkV1n4HkgAAAFs"]
[Tue Jul 21 07:43:40.044376 2026] [security2:error] [pid 296703:tid 296912] [client 20.197.192.193:56433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NXCn25uliftkV1n4HnAAAAE8"]
[Tue Jul 21 07:43:40.071605 2026] [security2:error] [pid 296703:tid 296919] [client 20.197.192.193:58198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/dp.php"] [unique_id "al9NXCn25uliftkV1n4HpAAAAFY"]
[Tue Jul 21 07:43:40.092872 2026] [autoindex:error] [pid 296703:tid 296908] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:40.102619 2026] [security2:error] [pid 296703:tid 296914] [client 20.197.195.24:13776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-content/admin.php"] [unique_id "al9NXCn25uliftkV1n4HqQAAAFE"]
[Tue Jul 21 07:43:40.114664 2026] [security2:error] [pid 296703:tid 296940] [client 74.249.245.134:54355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/jga.php"] [unique_id "al9NXCn25uliftkV1n4HqgAAAGs"]
[Tue Jul 21 07:43:40.118825 2026] [security2:error] [pid 296703:tid 296925] [client 20.197.192.193:58432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/old.php"] [unique_id "al9NXCn25uliftkV1n4HqwAAAFw"]
[Tue Jul 21 07:43:40.165761 2026] [security2:error] [pid 296703:tid 296926] [client 20.197.192.193:58195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ms-new.php"] [unique_id "al9NXCn25uliftkV1n4HrAAAAF0"]
[Tue Jul 21 07:43:40.232728 2026] [security2:error] [pid 296703:tid 296922] [client 20.197.192.193:58481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/track.php"] [unique_id "al9NXCn25uliftkV1n4HswAAAFk"]
[Tue Jul 21 07:43:40.263313 2026] [security2:error] [pid 296703:tid 296854] [client 20.197.192.193:58452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/2352356666.php"] [unique_id "al9NXCn25uliftkV1n4HtQAAABU"]
[Tue Jul 21 07:43:40.302544 2026] [security2:error] [pid 296703:tid 296889] [client 20.197.192.193:56430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/pn.php"] [unique_id "al9NXCn25uliftkV1n4HuAAAADg"]
[Tue Jul 21 07:43:40.303117 2026] [security2:error] [pid 296703:tid 296943] [client 20.197.195.24:13701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/ms-edit.php"] [unique_id "al9NXCn25uliftkV1n4HuQAAAG4"]
[Tue Jul 21 07:43:40.333599 2026] [security2:error] [pid 296703:tid 296923] [client 20.197.192.193:56438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-wpbak.php"] [unique_id "al9NXCn25uliftkV1n4HuwAAAFo"]
[Tue Jul 21 07:43:40.371613 2026] [security2:error] [pid 296703:tid 296904] [client 20.197.192.193:40886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/dr.php"] [unique_id "al9NXCn25uliftkV1n4HvwAAAEc"]
[Tue Jul 21 07:43:40.399758 2026] [security2:error] [pid 296703:tid 296893] [client 20.197.192.193:58208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/2x.php"] [unique_id "al9NXCn25uliftkV1n4HwAAAADw"]
[Tue Jul 21 07:43:40.429328 2026] [security2:error] [pid 296703:tid 296940] [client 20.197.192.193:58206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/kq1.php"] [unique_id "al9NXCn25uliftkV1n4HwgAAAGs"]
[Tue Jul 21 07:43:40.460469 2026] [security2:error] [pid 296703:tid 296839] [client 20.197.192.193:58186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/zzz.php"] [unique_id "al9NXCn25uliftkV1n4HwwAAAAY"]
[Tue Jul 21 07:43:40.477253 2026] [security2:error] [pid 296703:tid 296956] [client 20.197.192.193:58437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wicked.php"] [unique_id "al9NXCn25uliftkV1n4HxgAAAHs"]
[Tue Jul 21 07:43:40.506847 2026] [security2:error] [pid 296703:tid 296902] [client 20.197.192.193:58183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/edit.php"] [unique_id "al9NXCn25uliftkV1n4HyAAAAEU"]
[Tue Jul 21 07:43:40.530101 2026] [security2:error] [pid 296703:tid 296942] [client 20.197.192.193:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/kua.php"] [unique_id "al9NXCn25uliftkV1n4HyQAAAG0"]
[Tue Jul 21 07:43:40.556066 2026] [security2:error] [pid 296703:tid 296879] [client 20.197.192.193:58227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ez.php"] [unique_id "al9NXCn25uliftkV1n4HygAAAC4"]
[Tue Jul 21 07:43:40.574309 2026] [security2:error] [pid 296703:tid 296858] [client 20.197.192.193:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/fz.php"] [unique_id "al9NXCn25uliftkV1n4HywAAABk"]
[Tue Jul 21 07:43:40.593332 2026] [security2:error] [pid 296703:tid 296855] [client 20.197.192.193:58194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/la.php"] [unique_id "al9NXCn25uliftkV1n4HzQAAABY"]
[Tue Jul 21 07:43:40.615601 2026] [security2:error] [pid 296703:tid 296934] [client 20.197.192.193:58219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/nhvoanpl.php"] [unique_id "al9NXCn25uliftkV1n4H0QAAAGU"]
[Tue Jul 21 07:43:40.620925 2026] [security2:error] [pid 296703:tid 296911] [client 136.144.33.106:26281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NXCn25uliftkV1n4H0gAAAE4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:40.655892 2026] [security2:error] [pid 296703:tid 296949] [client 20.197.192.193:58197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/inso.php"] [unique_id "al9NXCn25uliftkV1n4H0wAAAHQ"]
[Tue Jul 21 07:43:40.679469 2026] [security2:error] [pid 296703:tid 296874] [client 20.197.192.193:56420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wpx.php"] [unique_id "al9NXCn25uliftkV1n4H1AAAACk"]
[Tue Jul 21 07:43:40.705314 2026] [security2:error] [pid 296703:tid 296833] [client 20.197.192.193:58233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/berlin.php"] [unique_id "al9NXCn25uliftkV1n4H1QAAAAA"]
[Tue Jul 21 07:43:40.768706 2026] [security2:error] [pid 296703:tid 296937] [client 20.197.195.24:13724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/cgi-bin/index.php"] [unique_id "al9NXCn25uliftkV1n4H3AAAAGg"]
[Tue Jul 21 07:43:40.784355 2026] [security2:error] [pid 296703:tid 296904] [client 20.197.192.193:58479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/billur.php"] [unique_id "al9NXCn25uliftkV1n4H3gAAAEc"]
[Tue Jul 21 07:43:40.811116 2026] [security2:error] [pid 296703:tid 296915] [client 20.104.96.117:30597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/h02ugyh.php"] [unique_id "al9NXCn25uliftkV1n4H4AAAAFI"]
[Tue Jul 21 07:43:40.840250 2026] [security2:error] [pid 296703:tid 296793] [remote 167.160.65.170:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NWin25uliftkV1n4HVwAAPVk"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:40.948108 2026] [security2:error] [pid 296703:tid 296944] [client 20.197.192.193:58225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/mimpi.php"] [unique_id "al9NXCn25uliftkV1n4H6QAAAG8"]
[Tue Jul 21 07:43:41.044627 2026] [security2:error] [pid 296703:tid 296924] [client 74.249.245.134:17410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/k.php"] [unique_id "al9NXSn25uliftkV1n4H7wAAAFs"]
[Tue Jul 21 07:43:41.050539 2026] [security2:error] [pid 296703:tid 296856] [client 20.197.192.193:56432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/dp.php"] [unique_id "al9NXSn25uliftkV1n4H8QAAABc"]
[Tue Jul 21 07:43:41.057869 2026] [autoindex:error] [pid 296703:tid 296855] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:41.095030 2026] [security2:error] [pid 296703:tid 296889] [client 20.197.192.193:49563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/bootstrap.php"] [unique_id "al9NXSn25uliftkV1n4H8gAAADg"]
[Tue Jul 21 07:43:41.096208 2026] [security2:error] [pid 296703:tid 296949] [client 20.197.195.24:13735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/BDKR28WP.php"] [unique_id "al9NXSn25uliftkV1n4H8wAAAHQ"]
[Tue Jul 21 07:43:41.120159 2026] [security2:error] [pid 296703:tid 296833] [client 20.197.192.193:56423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-editor.php"] [unique_id "al9NXSn25uliftkV1n4H9QAAAAA"]
[Tue Jul 21 07:43:41.168136 2026] [proxy:error] [pid 296703:tid 296704] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.168180 2026] [proxy_http:error] [pid 296703:tid 296704] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.168710 2026] [proxy:error] [pid 296703:tid 296704] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.168743 2026] [proxy_http:error] [pid 296703:tid 296704] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.169891 2026] [proxy:error] [pid 296703:tid 296741] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.169939 2026] [proxy_http:error] [pid 296703:tid 296741] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.170470 2026] [proxy:error] [pid 296703:tid 296741] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.170497 2026] [proxy_http:error] [pid 296703:tid 296741] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.191001 2026] [security2:error] [pid 296703:tid 296908] [client 20.197.192.193:56446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/cro.php"] [unique_id "al9NXSn25uliftkV1n4IAAAAAEs"]
[Tue Jul 21 07:43:41.217767 2026] [autoindex:error] [pid 296703:tid 296911] [client 66.249.69.224:51925] AH01276: Cannot serve directory /home1/domusc58/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:41.230754 2026] [security2:error] [pid 296703:tid 296914] [client 20.197.192.193:58200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/cron-tab.php"] [unique_id "al9NXSn25uliftkV1n4IAwAAAFE"]
[Tue Jul 21 07:43:41.232555 2026] [security2:error] [pid 296703:tid 296894] [client 167.160.65.170:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9NWin25uliftkV1n4HVwAAPVk"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 07:43:41.263906 2026] [security2:error] [pid 296703:tid 296880] [client 20.226.60.151:50921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/dfre.php"] [unique_id "al9NXSn25uliftkV1n4IBgAAAC8"]
[Tue Jul 21 07:43:41.284865 2026] [security2:error] [pid 296703:tid 296955] [client 20.197.192.193:49584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/koiy.php"] [unique_id "al9NXSn25uliftkV1n4ICwAAAHo"]
[Tue Jul 21 07:43:41.328247 2026] [security2:error] [pid 296703:tid 296861] [client 20.197.192.193:58441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/hp2.php"] [unique_id "al9NXSn25uliftkV1n4IEAAAABw"]
[Tue Jul 21 07:43:41.331673 2026] [security2:error] [pid 296703:tid 296919] [client 193.36.225.102:25191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NXSn25uliftkV1n4H9gAAAFY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:41.352490 2026] [security2:error] [pid 296703:tid 296869] [client 20.197.192.193:58488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/hp3.php"] [unique_id "al9NXSn25uliftkV1n4IEwAAACQ"]
[Tue Jul 21 07:43:41.370442 2026] [security2:error] [pid 296703:tid 296923] [client 103.106.20.201:56182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IFQAAAFo"]
[Tue Jul 21 07:43:41.370610 2026] [security2:error] [pid 296703:tid 296923] [client 103.106.20.201:56182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IFQAAAFo"]
[Tue Jul 21 07:43:41.378162 2026] [security2:error] [pid 296703:tid 296941] [client 20.197.192.193:58464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/aa1.php"] [unique_id "al9NXSn25uliftkV1n4IFwAAAGw"]
[Tue Jul 21 07:43:41.411099 2026] [security2:error] [pid 296703:tid 296845] [client 20.197.192.193:58467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/acew67.php"] [unique_id "al9NXSn25uliftkV1n4IGgAAAAw"]
[Tue Jul 21 07:43:41.449532 2026] [security2:error] [pid 296703:tid 296868] [client 20.197.192.193:56418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/bscclapb.php"] [unique_id "al9NXSn25uliftkV1n4IHQAAACM"]
[Tue Jul 21 07:43:41.474191 2026] [security2:error] [pid 296703:tid 296914] [client 20.197.192.193:58492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/else1.php"] [unique_id "al9NXSn25uliftkV1n4IHgAAAFE"]
[Tue Jul 21 07:43:41.501790 2026] [security2:error] [pid 296703:tid 296847] [client 20.197.192.193:40861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/tkikikoko.php"] [unique_id "al9NXSn25uliftkV1n4IIAAAAA4"]
[Tue Jul 21 07:43:41.516399 2026] [security2:error] [pid 296703:tid 296866] [client 20.197.192.193:58190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-Blogs.php"] [unique_id "al9NXSn25uliftkV1n4IIQAAACE"]
[Tue Jul 21 07:43:41.530965 2026] [security2:error] [pid 296703:tid 296880] [client 20.197.192.193:49569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-css.php"] [unique_id "al9NXSn25uliftkV1n4IIgAAAC8"]
[Tue Jul 21 07:43:41.531867 2026] [security2:error] [pid 296703:tid 296907] [client 62.102.148.187:36512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IIwAAAEo"]
[Tue Jul 21 07:43:41.531929 2026] [security2:error] [pid 296703:tid 296907] [client 62.102.148.187:36512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IIwAAAEo"]
[Tue Jul 21 07:43:41.550557 2026] [security2:error] [pid 296703:tid 296878] [client 20.197.192.193:56412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/wp-explorer.php"] [unique_id "al9NXSn25uliftkV1n4IJAAAAC0"]
[Tue Jul 21 07:43:41.555373 2026] [security2:error] [pid 296703:tid 296844] [client 20.63.100.92:1219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/2352356666.php"] [unique_id "al9NXSn25uliftkV1n4IJQAAAAs"]
[Tue Jul 21 07:43:41.573671 2026] [security2:error] [pid 296703:tid 296855] [client 20.197.192.193:58209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/akismet.php"] [unique_id "al9NXSn25uliftkV1n4IJgAAABY"]
[Tue Jul 21 07:43:41.592396 2026] [security2:error] [pid 296703:tid 296867] [client 20.197.192.193:58177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ace2.php"] [unique_id "al9NXSn25uliftkV1n4IJwAAACI"]
[Tue Jul 21 07:43:41.604996 2026] [security2:error] [pid 296703:tid 296849] [client 20.197.192.193:49586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marcomarafon.techknowledgebr.com"] [uri "/ms.php"] [unique_id "al9NXSn25uliftkV1n4IKAAAABA"]
[Tue Jul 21 07:43:41.720950 2026] [proxy:error] [pid 296703:tid 296762] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.721053 2026] [proxy_http:error] [pid 296703:tid 296762] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.722168 2026] [proxy:error] [pid 296703:tid 296762] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.722218 2026] [proxy_http:error] [pid 296703:tid 296762] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.722437 2026] [proxy:error] [pid 296703:tid 296785] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.722497 2026] [proxy_http:error] [pid 296703:tid 296785] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.723113 2026] [proxy:error] [pid 296703:tid 296785] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.723152 2026] [proxy_http:error] [pid 296703:tid 296785] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.785703 2026] [http2:info] [pid 302018:tid 302018] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 07:43:41.859679 2026] [autoindex:error] [pid 302018:tid 302151] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:41.902426 2026] [proxy:error] [pid 296703:tid 296747] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.902484 2026] [proxy_http:error] [pid 296703:tid 296747] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.903007 2026] [proxy:error] [pid 296703:tid 296747] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.903035 2026] [proxy_http:error] [pid 296703:tid 296747] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.906597 2026] [proxy:error] [pid 296703:tid 296804] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.906637 2026] [proxy_http:error] [pid 296703:tid 296804] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.907145 2026] [proxy:error] [pid 296703:tid 296804] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:41.907170 2026] [proxy_http:error] [pid 296703:tid 296804] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:41.951095 2026] [security2:error] [pid 296703:tid 296915] [client 122.162.144.145:14067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IQQAAAFI"]
[Tue Jul 21 07:43:41.951231 2026] [security2:error] [pid 296703:tid 296915] [client 122.162.144.145:14067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IQQAAAFI"]
[Tue Jul 21 07:43:41.971595 2026] [security2:error] [pid 296703:tid 296937] [client 20.104.96.117:30869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-temp.php"] [unique_id "al9NXSn25uliftkV1n4IRQAAAGg"]
[Tue Jul 21 07:43:41.972367 2026] [security2:error] [pid 296703:tid 296851] [client 139.167.225.182:53836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IRgAAABI"]
[Tue Jul 21 07:43:41.972447 2026] [security2:error] [pid 296703:tid 296851] [client 139.167.225.182:53836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NXSn25uliftkV1n4IRgAAABI"]
[Tue Jul 21 07:43:41.975971 2026] [security2:error] [pid 296703:tid 296904] [client 74.249.245.134:5565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/vx.php"] [unique_id "al9NXSn25uliftkV1n4IRwAAAEc"]
[Tue Jul 21 07:43:42.093457 2026] [security2:error] [pid 296703:tid 296797] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4ISgAAZV0"]
[Tue Jul 21 07:43:42.249889 2026] [security2:error] [pid 296703:tid 296750] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4ISQAAFy4"]
[Tue Jul 21 07:43:42.272887 2026] [security2:error] [pid 296703:tid 296784] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4IUQAALFA"]
[Tue Jul 21 07:43:42.382903 2026] [autoindex:error] [pid 302018:tid 302157] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:42.430470 2026] [security2:error] [pid 296703:tid 296904] [client 20.197.195.24:49862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/abcd.php"] [unique_id "al9NXin25uliftkV1n4IWQAAAEc"]
[Tue Jul 21 07:43:42.432937 2026] [security2:error] [pid 296703:tid 296811] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4IWgAAPWs"]
[Tue Jul 21 07:43:42.443091 2026] [security2:error] [pid 296703:tid 296735] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4IWwAAXB8"]
[Tue Jul 21 07:43:42.618127 2026] [proxy:error] [pid 296703:tid 296779] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:42.618190 2026] [proxy_http:error] [pid 296703:tid 296779] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:42.618613 2026] [proxy:error] [pid 296703:tid 296779] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:42.618633 2026] [proxy_http:error] [pid 296703:tid 296779] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:42.627161 2026] [security2:error] [pid 302018:tid 302023] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXoAs9lPxxVAErz3iywAAlQI"]
[Tue Jul 21 07:43:42.632664 2026] [security2:error] [pid 302018:tid 302024] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXoAs9lPxxVAErz3izAAAmgM"]
[Tue Jul 21 07:43:42.723348 2026] [security2:error] [pid 296703:tid 296926] [client 20.220.225.223:19699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wp-css.php"] [unique_id "al9NXin25uliftkV1n4IYgAAAF0"]
[Tue Jul 21 07:43:42.750099 2026] [autoindex:error] [pid 296703:tid 296817] [remote 74.7.242.34:58126] AH01276: Cannot serve directory /home2/jefe0292/robopsf3.agendaclique.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:42.766052 2026] [security2:error] [pid 302018:tid 302173] [client 20.226.60.151:56016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ss.php"] [unique_id "al9NXoAs9lPxxVAErz3izgAAAJw"]
[Tue Jul 21 07:43:42.805824 2026] [proxy:error] [pid 302018:tid 302025] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:42.805865 2026] [proxy_http:error] [pid 302018:tid 302025] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:42.806481 2026] [proxy:error] [pid 302018:tid 302025] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:43:42.806502 2026] [proxy_http:error] [pid 302018:tid 302025] [remote 130.12.180.39:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:43:42.810351 2026] [security2:error] [pid 296703:tid 296742] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4IZQAAKyY"]
[Tue Jul 21 07:43:42.811400 2026] [security2:error] [pid 302018:tid 302026] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXoAs9lPxxVAErz3i0AAAowU"]
[Tue Jul 21 07:43:42.814641 2026] [security2:error] [pid 296703:tid 296838] [client 103.29.114.44:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NXin25uliftkV1n4IaQAAAAU"]
[Tue Jul 21 07:43:42.820270 2026] [security2:error] [pid 296703:tid 296838] [client 103.29.114.44:54340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NXin25uliftkV1n4IaQAAAAU"]
[Tue Jul 21 07:43:42.931261 2026] [security2:error] [pid 302018:tid 302178] [client 74.7.175.189:55720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.robopsf3.agendaclique.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9NXoAs9lPxxVAErz3i1AAAoQc"]
[Tue Jul 21 07:43:42.963745 2026] [security2:error] [pid 296703:tid 296737] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4IcAAAMSE"]
[Tue Jul 21 07:43:42.993000 2026] [security2:error] [pid 296703:tid 296734] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXin25uliftkV1n4IcQAAbB4"]
[Tue Jul 21 07:43:43.146295 2026] [security2:error] [pid 302018:tid 302030] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NX4As9lPxxVAErz3i2QAAtgk"]
[Tue Jul 21 07:43:43.231136 2026] [security2:error] [pid 296703:tid 296938] [client 128.127.105.184:42070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NXyn25uliftkV1n4IdAAAAGk"]
[Tue Jul 21 07:43:43.231233 2026] [security2:error] [pid 296703:tid 296938] [client 128.127.105.184:42070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9NXyn25uliftkV1n4IdAAAAGk"]
[Tue Jul 21 07:43:43.235677 2026] [security2:error] [pid 296703:tid 296860] [client 20.197.195.24:13774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/file15.php"] [unique_id "al9NXyn25uliftkV1n4IdQAAABs"]
[Tue Jul 21 07:43:43.379746 2026] [security2:error] [pid 296703:tid 296771] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXyn25uliftkV1n4IfQAANEM"]
[Tue Jul 21 07:43:43.437912 2026] [security2:error] [pid 302018:tid 302200] [client 173.24.185.52:58361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NX4As9lPxxVAErz3i4gAAALc"]
[Tue Jul 21 07:43:43.438086 2026] [security2:error] [pid 302018:tid 302200] [client 173.24.185.52:58361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NX4As9lPxxVAErz3i4gAAALc"]
[Tue Jul 21 07:43:43.474311 2026] [security2:error] [pid 296703:tid 296915] [client 20.104.96.117:30895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9NXyn25uliftkV1n4IgQAAAFI"]
[Tue Jul 21 07:43:43.529519 2026] [security2:error] [pid 302018:tid 302222] [client 20.104.96.117:44096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NX4As9lPxxVAErz3i5QAAAM0"]
[Tue Jul 21 07:43:43.563065 2026] [security2:error] [pid 296703:tid 296714] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NXyn25uliftkV1n4IhQAAPQo"]
[Tue Jul 21 07:43:43.563575 2026] [security2:error] [pid 296703:tid 296925] [client 20.226.60.151:50933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/wp-happy.php"] [unique_id "al9NXyn25uliftkV1n4IhwAAAFw"]
[Tue Jul 21 07:43:43.569048 2026] [security2:error] [pid 296703:tid 296937] [client 34.12.245.104:54327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.245.12.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verbodavidachapeco.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NXyn25uliftkV1n4IhgAAAGg"]
[Tue Jul 21 07:43:43.620095 2026] [security2:error] [pid 302018:tid 302230] [client 74.249.245.134:5531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/ws77.php"] [unique_id "al9NX4As9lPxxVAErz3i6AAAANU"]
[Tue Jul 21 07:43:43.692010 2026] [security2:error] [pid 296703:tid 296897] [client 20.220.225.223:34243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/edit.php"] [unique_id "al9NXyn25uliftkV1n4IiwAAAEA"]
[Tue Jul 21 07:43:43.846657 2026] [security2:error] [pid 296703:tid 296959] [client 59.96.220.140:61236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NXyn25uliftkV1n4IkQAAAH4"]
[Tue Jul 21 07:43:43.846764 2026] [security2:error] [pid 296703:tid 296959] [client 59.96.220.140:61236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NXyn25uliftkV1n4IkQAAAH4"]
[Tue Jul 21 07:43:43.888734 2026] [security2:error] [pid 296703:tid 296881] [client 194.99.104.35:50802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9NXyn25uliftkV1n4ImgAAADA"]
[Tue Jul 21 07:43:43.888825 2026] [security2:error] [pid 296703:tid 296881] [client 194.99.104.35:50802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9NXyn25uliftkV1n4ImgAAADA"]
[Tue Jul 21 07:43:43.894191 2026] [security2:error] [pid 302018:tid 302037] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NX4As9lPxxVAErz3i6gAA3hA"]
[Tue Jul 21 07:43:43.894334 2026] [security2:error] [pid 302018:tid 302239] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NX4As9lPxxVAErz3i6gAA3hA"]
[Tue Jul 21 07:43:43.921171 2026] [security2:error] [pid 302018:tid 302038] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NX4As9lPxxVAErz3i6wAA4BE"]
[Tue Jul 21 07:43:43.921319 2026] [security2:error] [pid 302018:tid 302241] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NX4As9lPxxVAErz3i6wAA4BE"]
[Tue Jul 21 07:43:43.999346 2026] [security2:error] [pid 296703:tid 296853] [client 34.12.245.104:64453] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NXyn25uliftkV1n4InQAAABQ"]
[Tue Jul 21 07:43:44.138469 2026] [security2:error] [pid 302018:tid 302245] [client 20.226.60.151:22967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9NYIAs9lPxxVAErz3i7QAAAOQ"]
[Tue Jul 21 07:43:44.207553 2026] [security2:error] [pid 296703:tid 296851] [client 103.166.103.129:60778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NYCn25uliftkV1n4IqgAAABI"]
[Tue Jul 21 07:43:44.208345 2026] [security2:error] [pid 296703:tid 296851] [client 103.166.103.129:60778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NYCn25uliftkV1n4IqgAAABI"]
[Tue Jul 21 07:43:44.412663 2026] [security2:error] [pid 296703:tid 296868] [client 20.63.100.92:7967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/pn.php"] [unique_id "al9NYCn25uliftkV1n4IswAAACM"]
[Tue Jul 21 07:43:44.428774 2026] [security2:error] [pid 296703:tid 296890] [client 34.12.245.104:55795] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NYCn25uliftkV1n4ItAAAADk"]
[Tue Jul 21 07:43:44.863986 2026] [security2:error] [pid 296703:tid 296926] [client 34.12.245.104:64165] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NYCn25uliftkV1n4IvQAAAF0"]
[Tue Jul 21 07:43:44.885020 2026] [security2:error] [pid 302018:tid 302259] [client 74.249.245.134:5560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/2.php"] [unique_id "al9NYIAs9lPxxVAErz3i9gAAAPI"]
[Tue Jul 21 07:43:44.941689 2026] [security2:error] [pid 302018:tid 302261] [client 20.226.60.151:61981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/hypo.php"] [unique_id "al9NYIAs9lPxxVAErz3i9wAAAPQ"]
[Tue Jul 21 07:43:45.122772 2026] [security2:error] [pid 302018:tid 302268] [client 20.197.195.24:13749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/jp.php"] [unique_id "al9NYYAs9lPxxVAErz3i-AAAAPs"]
[Tue Jul 21 07:43:45.200128 2026] [security2:error] [pid 302018:tid 302044] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NYYAs9lPxxVAErz3i-gAA_hc"]
[Tue Jul 21 07:43:45.269687 2026] [security2:error] [pid 296703:tid 296851] [client 20.226.60.151:50927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/fpr4.php"] [unique_id "al9NYSn25uliftkV1n4IygAAABI"]
[Tue Jul 21 07:43:45.297390 2026] [security2:error] [pid 296703:tid 296947] [client 34.12.245.104:61475] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9NYSn25uliftkV1n4IzAAAAHI"]
[Tue Jul 21 07:43:45.302754 2026] [security2:error] [pid 302018:tid 302233] [client 136.144.33.54:22611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NYYAs9lPxxVAErz3i-wAAANg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:45.376711 2026] [security2:error] [pid 296703:tid 296828] [remote 130.12.180.39:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.180.12.130.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.assumaocontrole.com"] [uri "/_internal/api/setup.php"] [unique_id "al9NYSn25uliftkV1n4I0wAAFXw"]
[Tue Jul 21 07:43:45.404708 2026] [security2:error] [pid 296703:tid 296919] [client 193.36.225.143:36171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NYSn25uliftkV1n4IyAAAAFY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:45.535571 2026] [security2:error] [pid 296703:tid 296838] [client 103.174.34.15:59516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYSn25uliftkV1n4I2QAAAAU"]
[Tue Jul 21 07:43:45.535920 2026] [security2:error] [pid 296703:tid 296838] [client 103.174.34.15:59516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYSn25uliftkV1n4I2QAAAAU"]
[Tue Jul 21 07:43:45.600594 2026] [security2:error] [pid 296703:tid 296780] [remote 104.207.45.89:17005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.45.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NYSn25uliftkV1n4I1gAAT0w"]
[Tue Jul 21 07:43:45.730172 2026] [security2:error] [pid 296703:tid 296872] [client 106.215.181.8:18543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYSn25uliftkV1n4I4gAAACc"]
[Tue Jul 21 07:43:45.730276 2026] [security2:error] [pid 296703:tid 296872] [client 106.215.181.8:18543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYSn25uliftkV1n4I4gAAACc"]
[Tue Jul 21 07:43:45.732035 2026] [security2:error] [pid 302018:tid 302157] [client 34.12.245.104:55834] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NYYAs9lPxxVAErz3jAgAAAIw"]
[Tue Jul 21 07:43:45.742104 2026] [security2:error] [pid 302018:tid 302159] [client 20.220.225.223:34281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/kua.php"] [unique_id "al9NYYAs9lPxxVAErz3jAwAAAI4"]
[Tue Jul 21 07:43:45.807130 2026] [security2:error] [pid 296703:tid 296747] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NYSn25uliftkV1n4I5AAABis"]
[Tue Jul 21 07:43:45.807262 2026] [security2:error] [pid 296703:tid 296839] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NYSn25uliftkV1n4I5AAABis"]
[Tue Jul 21 07:43:45.977037 2026] [security2:error] [pid 302018:tid 302167] [client 128.127.105.184:46858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9NYYAs9lPxxVAErz3jBQAAAJY"]
[Tue Jul 21 07:43:45.977142 2026] [security2:error] [pid 302018:tid 302167] [client 128.127.105.184:46858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9NYYAs9lPxxVAErz3jBQAAAJY"]
[Tue Jul 21 07:43:45.999707 2026] [security2:error] [pid 302018:tid 302272] [client 182.8.255.181:17335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NYYAs9lPxxVAErz3jBwAAAP8"]
[Tue Jul 21 07:43:45.999851 2026] [security2:error] [pid 302018:tid 302272] [client 182.8.255.181:17335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NYYAs9lPxxVAErz3jBwAAAP8"]
[Tue Jul 21 07:43:46.086628 2026] [security2:error] [pid 296703:tid 296925] [client 20.226.60.151:60138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/users.php"] [unique_id "al9NYin25uliftkV1n4I7wAAAFw"]
[Tue Jul 21 07:43:46.102856 2026] [security2:error] [pid 302018:tid 302151] [client 178.153.91.96:6614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NYoAs9lPxxVAErz3jCQAAAIY"]
[Tue Jul 21 07:43:46.103028 2026] [security2:error] [pid 302018:tid 302151] [client 178.153.91.96:6614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NYoAs9lPxxVAErz3jCQAAAIY"]
[Tue Jul 21 07:43:46.175896 2026] [security2:error] [pid 296703:tid 296940] [client 34.12.245.104:60519] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9NYin25uliftkV1n4I8gAAAGs"]
[Tue Jul 21 07:43:46.177607 2026] [security2:error] [pid 302018:tid 302170] [client 20.197.195.24:13796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/f35.php"] [unique_id "al9NYoAs9lPxxVAErz3jDwAAAJk"]
[Tue Jul 21 07:43:46.365652 2026] [security2:error] [pid 296703:tid 296907] [client 74.249.245.134:17456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/asd.php"] [unique_id "al9NYin25uliftkV1n4I9wAAAEo"]
[Tue Jul 21 07:43:46.467453 2026] [security2:error] [pid 296703:tid 296901] [client 20.226.60.151:22966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/k2.php"] [unique_id "al9NYin25uliftkV1n4I-QAAAEQ"]
[Tue Jul 21 07:43:46.491140 2026] [security2:error] [pid 296703:tid 296911] [client 20.104.96.117:30879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9NYin25uliftkV1n4I-wAAAE4"]
[Tue Jul 21 07:43:46.587298 2026] [security2:error] [pid 302018:tid 302053] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NYoAs9lPxxVAErz3jGwAAqiA"]
[Tue Jul 21 07:43:46.587431 2026] [security2:error] [pid 302018:tid 302187] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NYoAs9lPxxVAErz3jGwAAqiA"]
[Tue Jul 21 07:43:46.615372 2026] [security2:error] [pid 296703:tid 296952] [client 20.197.195.24:13746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-load.php"] [unique_id "al9NYin25uliftkV1n4I_gAAAHc"]
[Tue Jul 21 07:43:46.648526 2026] [security2:error] [pid 302018:tid 302207] [client 34.12.245.104:60056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NYoAs9lPxxVAErz3jHAAAAL4"]
[Tue Jul 21 07:43:46.654624 2026] [security2:error] [pid 302018:tid 302051] [remote 104.207.48.107:50321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.48.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NYoAs9lPxxVAErz3jFgAAph4"]
[Tue Jul 21 07:43:46.727020 2026] [security2:error] [pid 302018:tid 302054] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYoAs9lPxxVAErz3jHQAAsiE"]
[Tue Jul 21 07:43:46.727180 2026] [security2:error] [pid 302018:tid 302195] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYoAs9lPxxVAErz3jHQAAsiE"]
[Tue Jul 21 07:43:46.833322 2026] [security2:error] [pid 296703:tid 296885] [client 152.59.154.239:48970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYin25uliftkV1n4JAwAAADQ"]
[Tue Jul 21 07:43:46.833490 2026] [security2:error] [pid 296703:tid 296885] [client 152.59.154.239:48970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NYin25uliftkV1n4JAwAAADQ"]
[Tue Jul 21 07:43:46.834999 2026] [security2:error] [pid 296703:tid 296937] [client 103.86.117.203:57258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NYin25uliftkV1n4JBAAAAGg"]
[Tue Jul 21 07:43:46.835166 2026] [security2:error] [pid 296703:tid 296937] [client 103.86.117.203:57258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NYin25uliftkV1n4JBAAAAGg"]
[Tue Jul 21 07:43:46.898769 2026] [security2:error] [pid 302018:tid 302055] [remote 104.207.58.53:55353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NYoAs9lPxxVAErz3jHgAAsyI"]
[Tue Jul 21 07:43:47.135889 2026] [security2:error] [pid 302018:tid 302230] [client 20.226.60.151:59488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/file88.php"] [unique_id "al9NY4As9lPxxVAErz3jIQAAANU"]
[Tue Jul 21 07:43:47.181876 2026] [security2:error] [pid 302018:tid 302237] [client 34.12.245.104:59667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NY4As9lPxxVAErz3jJAAAANw"]
[Tue Jul 21 07:43:47.217582 2026] [security2:error] [pid 302018:tid 302241] [client 20.226.60.151:54374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/177.php"] [unique_id "al9NY4As9lPxxVAErz3jJwAAAOA"]
[Tue Jul 21 07:43:47.312307 2026] [security2:error] [pid 296703:tid 296926] [client 20.197.195.24:13764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/xyn.php"] [unique_id "al9NYyn25uliftkV1n4JDQAAAF0"]
[Tue Jul 21 07:43:47.389466 2026] [security2:error] [pid 302018:tid 302248] [client 74.249.245.134:54338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/default.php"] [unique_id "al9NY4As9lPxxVAErz3jKwAAAOc"]
[Tue Jul 21 07:43:47.419036 2026] [security2:error] [pid 296703:tid 296854] [client 20.104.96.117:44127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NYyn25uliftkV1n4JDgAAABU"]
[Tue Jul 21 07:43:47.491007 2026] [security2:error] [pid 302018:tid 302208] [client 122.164.127.47:58627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NY4As9lPxxVAErz3jLAAAAL8"]
[Tue Jul 21 07:43:47.495691 2026] [security2:error] [pid 302018:tid 302208] [client 122.164.127.47:58627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NY4As9lPxxVAErz3jLAAAAL8"]
[Tue Jul 21 07:43:47.789244 2026] [autoindex:error] [pid 302018:tid 302267] [client 20.197.195.24:0] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:47.844414 2026] [security2:error] [pid 302018:tid 302222] [client 117.251.86.144:41530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NY4As9lPxxVAErz3jNQAAAM0"]
[Tue Jul 21 07:43:47.844583 2026] [security2:error] [pid 302018:tid 302222] [client 117.251.86.144:41530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NY4As9lPxxVAErz3jNQAAAM0"]
[Tue Jul 21 07:43:47.889554 2026] [autoindex:error] [pid 302018:tid 302265] [client 20.197.195.24:13714] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:47.891707 2026] [security2:error] [pid 302018:tid 302242] [client 122.186.204.214:60142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NY4As9lPxxVAErz3jNgAAAOE"]
[Tue Jul 21 07:43:47.891841 2026] [security2:error] [pid 302018:tid 302242] [client 122.186.204.214:60142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NY4As9lPxxVAErz3jNgAAAOE"]
[Tue Jul 21 07:43:47.896400 2026] [security2:error] [pid 302018:tid 302277] [client 20.197.195.24:13714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/ccc.php"] [unique_id "al9NY4As9lPxxVAErz3jNwAAAQQ"]
[Tue Jul 21 07:43:48.107745 2026] [security2:error] [pid 296703:tid 296918] [client 20.197.195.24:13704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/w.php"] [unique_id "al9NZCn25uliftkV1n4JHAAAAFU"]
[Tue Jul 21 07:43:48.108461 2026] [security2:error] [pid 296703:tid 296882] [client 34.12.245.104:54760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NZCn25uliftkV1n4JHQAAADE"]
[Tue Jul 21 07:43:48.126412 2026] [security2:error] [pid 302018:tid 302252] [client 41.68.90.219:62589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZIAs9lPxxVAErz3jOgAAAOs"]
[Tue Jul 21 07:43:48.127505 2026] [security2:error] [pid 302018:tid 302252] [client 41.68.90.219:62589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZIAs9lPxxVAErz3jOgAAAOs"]
[Tue Jul 21 07:43:48.150289 2026] [security2:error] [pid 302018:tid 302272] [client 20.226.60.151:22364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9NZIAs9lPxxVAErz3jOwAAAP8"]
[Tue Jul 21 07:43:48.204354 2026] [security2:error] [pid 296703:tid 296893] [client 117.247.80.59:20989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZCn25uliftkV1n4JIQAAADw"]
[Tue Jul 21 07:43:48.204499 2026] [security2:error] [pid 296703:tid 296893] [client 117.247.80.59:20989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZCn25uliftkV1n4JIQAAADw"]
[Tue Jul 21 07:43:48.251310 2026] [security2:error] [pid 302018:tid 302057] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZIAs9lPxxVAErz3jPQAAjyQ"]
[Tue Jul 21 07:43:48.251448 2026] [security2:error] [pid 302018:tid 302160] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZIAs9lPxxVAErz3jPQAAjyQ"]
[Tue Jul 21 07:43:48.682366 2026] [security2:error] [pid 296703:tid 296805] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NZCn25uliftkV1n4JMgAAImU"]
[Tue Jul 21 07:43:48.682557 2026] [security2:error] [pid 296703:tid 296867] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NZCn25uliftkV1n4JMgAAImU"]
[Tue Jul 21 07:43:48.698874 2026] [security2:error] [pid 296703:tid 296959] [client 20.226.60.151:59412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ccc.php"] [unique_id "al9NZCn25uliftkV1n4JNAAAAH4"]
[Tue Jul 21 07:43:48.870195 2026] [security2:error] [pid 302018:tid 302203] [client 20.197.195.24:13754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9NZIAs9lPxxVAErz3jQAAAALo"]
[Tue Jul 21 07:43:48.913915 2026] [security2:error] [pid 296703:tid 296880] [client 34.12.245.104:50854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NZCn25uliftkV1n4JPwAAAC8"]
[Tue Jul 21 07:43:48.933195 2026] [security2:error] [pid 296703:tid 296937] [client 37.140.223.122:25261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NZCn25uliftkV1n4JQAAAAGg"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:49.177990 2026] [security2:error] [pid 296703:tid 296934] [client 193.36.225.60:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NZSn25uliftkV1n4JQgAAAGU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:49.266128 2026] [security2:error] [pid 302018:tid 302061] [remote 65.111.20.205:19507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NZYAs9lPxxVAErz3jRQAAvCg"]
[Tue Jul 21 07:43:49.294301 2026] [security2:error] [pid 302018:tid 302196] [client 20.226.60.151:22975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9NZYAs9lPxxVAErz3jRwAAALM"]
[Tue Jul 21 07:43:49.433736 2026] [security2:error] [pid 296703:tid 296952] [client 202.143.127.214:53572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZSn25uliftkV1n4JTQAAAHc"]
[Tue Jul 21 07:43:49.434295 2026] [security2:error] [pid 296703:tid 296952] [client 202.143.127.214:53572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZSn25uliftkV1n4JTQAAAHc"]
[Tue Jul 21 07:43:49.617320 2026] [security2:error] [pid 302018:tid 302189] [client 20.63.100.92:1561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9NZYAs9lPxxVAErz3jSQAAAKw"]
[Tue Jul 21 07:43:49.650009 2026] [security2:error] [pid 302018:tid 302204] [client 20.197.195.24:13762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/FWAZ.php"] [unique_id "al9NZYAs9lPxxVAErz3jSwAAALs"]
[Tue Jul 21 07:43:49.678963 2026] [security2:error] [pid 296703:tid 296838] [client 117.217.38.194:53525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZSn25uliftkV1n4JUQAAAAU"]
[Tue Jul 21 07:43:49.679082 2026] [security2:error] [pid 296703:tid 296838] [client 117.217.38.194:53525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZSn25uliftkV1n4JUQAAAAU"]
[Tue Jul 21 07:43:49.790968 2026] [security2:error] [pid 302018:tid 302221] [client 74.249.245.134:5546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/gettest.php"] [unique_id "al9NZYAs9lPxxVAErz3jUQAAAMw"]
[Tue Jul 21 07:43:49.835528 2026] [security2:error] [pid 302018:tid 302249] [client 34.12.245.104:62957] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "verbodavidachapeco.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NZYAs9lPxxVAErz3jUwAAAOg"]
[Tue Jul 21 07:43:49.915091 2026] [security2:error] [pid 302018:tid 302264] [client 20.197.195.24:13767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/miru1.php"] [unique_id "al9NZYAs9lPxxVAErz3jWAAAAPc"]
[Tue Jul 21 07:43:49.991136 2026] [security2:error] [pid 296703:tid 296848] [client 20.104.96.117:30423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/jj.php"] [unique_id "al9NZSn25uliftkV1n4JWAAAAA8"]
[Tue Jul 21 07:43:50.208072 2026] [security2:error] [pid 302018:tid 302265] [client 20.226.60.151:60112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/config.php"] [unique_id "al9NZoAs9lPxxVAErz3jXAAAAPg"]
[Tue Jul 21 07:43:50.535355 2026] [security2:error] [pid 302018:tid 302258] [client 154.192.233.199:58583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZoAs9lPxxVAErz3jXgAAAPE"]
[Tue Jul 21 07:43:50.535805 2026] [security2:error] [pid 302018:tid 302258] [client 154.192.233.199:58583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NZoAs9lPxxVAErz3jXgAAAPE"]
[Tue Jul 21 07:43:50.562992 2026] [security2:error] [pid 296703:tid 296938] [client 20.197.195.24:13769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/aa.php"] [unique_id "al9NZin25uliftkV1n4JbQAAAGk"]
[Tue Jul 21 07:43:50.665895 2026] [security2:error] [pid 296703:tid 296839] [client 20.104.96.117:44229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/media.php"] [unique_id "al9NZin25uliftkV1n4JbwAAAAY"]
[Tue Jul 21 07:43:50.682272 2026] [security2:error] [pid 302018:tid 302156] [client 20.104.96.117:30889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9NZoAs9lPxxVAErz3jXwAAAIs"]
[Tue Jul 21 07:43:50.789499 2026] [security2:error] [pid 302018:tid 302162] [client 20.226.60.151:59518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/777.php"] [unique_id "al9NZoAs9lPxxVAErz3jYwAAAJE"]
[Tue Jul 21 07:43:51.014709 2026] [security2:error] [pid 296703:tid 296954] [client 20.197.195.24:13817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/122.php"] [unique_id "al9NZyn25uliftkV1n4JdwAAAHk"]
[Tue Jul 21 07:43:51.234128 2026] [security2:error] [pid 296703:tid 296866] [client 20.226.60.151:22367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9NZyn25uliftkV1n4JeQAAACE"]
[Tue Jul 21 07:43:51.290119 2026] [security2:error] [pid 302018:tid 302188] [client 20.197.195.24:49871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/get.php"] [unique_id "al9NZ4As9lPxxVAErz3jbgAAAKs"]
[Tue Jul 21 07:43:51.331086 2026] [security2:error] [pid 296703:tid 296890] [client 20.104.96.117:30866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/txets.php"] [unique_id "al9NZyn25uliftkV1n4JegAAADk"]
[Tue Jul 21 07:43:51.661234 2026] [security2:error] [pid 302018:tid 302210] [client 20.226.60.151:54299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/gettest.php"] [unique_id "al9NZ4As9lPxxVAErz3jcAAAAME"]
[Tue Jul 21 07:43:51.724103 2026] [security2:error] [pid 302018:tid 302176] [client 20.220.225.223:34254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/ez.php"] [unique_id "al9NZ4As9lPxxVAErz3jcQAAAJ8"]
[Tue Jul 21 07:43:51.797594 2026] [security2:error] [pid 302018:tid 302184] [client 20.197.195.24:49816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/as.php"] [unique_id "al9NZ4As9lPxxVAErz3jcwAAAKc"]
[Tue Jul 21 07:43:51.813263 2026] [security2:error] [pid 302018:tid 302199] [client 20.104.96.117:30450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/dex.php"] [unique_id "al9NZ4As9lPxxVAErz3jdAAAALY"]
[Tue Jul 21 07:43:51.964880 2026] [security2:error] [pid 296703:tid 296876] [client 193.36.225.143:22429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NZyn25uliftkV1n4JiAAAACs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:52.209881 2026] [security2:error] [pid 296703:tid 296845] [client 103.106.20.201:56849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaCn25uliftkV1n4JigAAAAw"]
[Tue Jul 21 07:43:52.210028 2026] [security2:error] [pid 296703:tid 296845] [client 103.106.20.201:56849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaCn25uliftkV1n4JigAAAAw"]
[Tue Jul 21 07:43:52.228378 2026] [security2:error] [pid 302018:tid 302067] [remote 104.207.52.109:17267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NZoAs9lPxxVAErz3jXQAA-y4"]
[Tue Jul 21 07:43:52.322848 2026] [security2:error] [pid 302018:tid 302231] [client 20.226.60.151:50886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/for.php"] [unique_id "al9NaIAs9lPxxVAErz3jfAAAANY"]
[Tue Jul 21 07:43:52.371142 2026] [security2:error] [pid 302018:tid 302160] [client 47.128.50.191:11106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gfacil.com.br"] [uri "/robots.txt"] [unique_id "al9NaIAs9lPxxVAErz3jfQAAAI8"]
[Tue Jul 21 07:43:52.407589 2026] [security2:error] [pid 302018:tid 302235] [client 74.249.245.134:54381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/tfm.php"] [unique_id "al9NaIAs9lPxxVAErz3jggAAANo"]
[Tue Jul 21 07:43:52.666780 2026] [security2:error] [pid 302018:tid 302183] [client 139.167.225.182:54479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaIAs9lPxxVAErz3jhAAAAKY"]
[Tue Jul 21 07:43:52.666912 2026] [security2:error] [pid 302018:tid 302183] [client 139.167.225.182:54479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaIAs9lPxxVAErz3jhAAAAKY"]
[Tue Jul 21 07:43:52.684801 2026] [security2:error] [pid 302018:tid 302240] [client 20.104.96.117:30406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/xpwer1.php"] [unique_id "al9NaIAs9lPxxVAErz3jhQAAAN8"]
[Tue Jul 21 07:43:52.729708 2026] [security2:error] [pid 302018:tid 302212] [client 122.162.144.145:25266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NaIAs9lPxxVAErz3jiAAAAMM"]
[Tue Jul 21 07:43:52.729802 2026] [security2:error] [pid 302018:tid 302212] [client 122.162.144.145:25266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NaIAs9lPxxVAErz3jiAAAAMM"]
[Tue Jul 21 07:43:52.751677 2026] [security2:error] [pid 302018:tid 302151] [client 59.96.220.140:61730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NaIAs9lPxxVAErz3jiQAAAIY"]
[Tue Jul 21 07:43:52.769495 2026] [security2:error] [pid 302018:tid 302151] [client 59.96.220.140:61730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NaIAs9lPxxVAErz3jiQAAAIY"]
[Tue Jul 21 07:43:52.799086 2026] [security2:error] [pid 302018:tid 302255] [client 20.197.195.24:49795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/ccou.php"] [unique_id "al9NaIAs9lPxxVAErz3jigAAAO4"]
[Tue Jul 21 07:43:52.816313 2026] [security2:error] [pid 302018:tid 302229] [client 20.104.96.117:44129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/images.php"] [unique_id "al9NaIAs9lPxxVAErz3jiwAAANQ"]
[Tue Jul 21 07:43:52.853112 2026] [security2:error] [pid 302018:tid 302261] [client 20.226.60.151:22657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/for.php"] [unique_id "al9NaIAs9lPxxVAErz3jjAAAAPQ"]
[Tue Jul 21 07:43:53.050957 2026] [security2:error] [pid 302018:tid 302274] [client 20.226.60.151:50835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/ssla.php"] [unique_id "al9NaYAs9lPxxVAErz3jkAAAAQE"]
[Tue Jul 21 07:43:53.190917 2026] [security2:error] [pid 302018:tid 302187] [client 136.144.33.102:35951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NaYAs9lPxxVAErz3jkwAAAKo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:43:53.412072 2026] [security2:error] [pid 302018:tid 302239] [client 103.29.114.44:63164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaYAs9lPxxVAErz3jlwAAAN4"]
[Tue Jul 21 07:43:53.412189 2026] [security2:error] [pid 302018:tid 302239] [client 103.29.114.44:63164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaYAs9lPxxVAErz3jlwAAAN4"]
[Tue Jul 21 07:43:53.626644 2026] [security2:error] [pid 302018:tid 302256] [client 122.179.91.63:7999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NaYAs9lPxxVAErz3jmgAAAO8"]
[Tue Jul 21 07:43:53.626841 2026] [security2:error] [pid 302018:tid 302256] [client 122.179.91.63:7999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NaYAs9lPxxVAErz3jmgAAAO8"]
[Tue Jul 21 07:43:54.037900 2026] [security2:error] [pid 302018:tid 302202] [client 20.226.60.151:22962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/raw.php"] [unique_id "al9NaoAs9lPxxVAErz3jpgAAALk"]
[Tue Jul 21 07:43:54.042214 2026] [security2:error] [pid 302018:tid 302169] [client 173.24.185.52:58833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3jpwAAAJg"]
[Tue Jul 21 07:43:54.042373 2026] [security2:error] [pid 302018:tid 302169] [client 173.24.185.52:58833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3jpwAAAJg"]
[Tue Jul 21 07:43:54.145115 2026] [security2:error] [pid 302018:tid 302177] [client 20.197.195.24:13790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/w3lls.php"] [unique_id "al9NaoAs9lPxxVAErz3jqAAAAKA"]
[Tue Jul 21 07:43:54.168726 2026] [security2:error] [pid 302018:tid 302180] [client 193.36.225.143:48915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NaoAs9lPxxVAErz3jqQAAAKM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:43:54.237388 2026] [security2:error] [pid 302018:tid 302215] [client 20.104.96.117:44244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/gecko.php"] [unique_id "al9NaoAs9lPxxVAErz3jqgAAAMY"]
[Tue Jul 21 07:43:54.249259 2026] [security2:error] [pid 296703:tid 296916] [client 20.226.60.151:50881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.piskefotografia.com"] [uri "/zc-131.php"] [unique_id "al9Nain25uliftkV1n4JrgAAAFM"]
[Tue Jul 21 07:43:54.414080 2026] [security2:error] [pid 302018:tid 302086] [remote 132.148.72.88:57622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9NaoAs9lPxxVAErz3jrgAAj0E"]
[Tue Jul 21 07:43:54.437644 2026] [security2:error] [pid 302018:tid 302088] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3jsAAA2kM"]
[Tue Jul 21 07:43:54.437798 2026] [security2:error] [pid 302018:tid 302235] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3jsAAA2kM"]
[Tue Jul 21 07:43:54.472281 2026] [security2:error] [pid 296703:tid 296727] [remote 45.150.79.142:50588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Nain25uliftkV1n4JsQAAIxc"]
[Tue Jul 21 07:43:54.570312 2026] [security2:error] [pid 302018:tid 302150] [client 20.220.225.223:53454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NaoAs9lPxxVAErz3jswAAAIU"]
[Tue Jul 21 07:43:54.630025 2026] [security2:error] [pid 302018:tid 302228] [client 20.104.96.117:44276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/82.php"] [unique_id "al9NaoAs9lPxxVAErz3jtQAAANM"]
[Tue Jul 21 07:43:54.653761 2026] [access_compat:error] [pid 302018:tid 302212] [client 162.241.63.68:31450] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:43:54.815861 2026] [security2:error] [pid 302018:tid 302090] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3jtwAAhkU"]
[Tue Jul 21 07:43:54.816055 2026] [security2:error] [pid 302018:tid 302151] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3jtwAAhkU"]
[Tue Jul 21 07:43:54.830079 2026] [security2:error] [pid 302018:tid 302208] [client 62.102.148.187:50646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3juAAAAL8"]
[Tue Jul 21 07:43:54.830169 2026] [security2:error] [pid 302018:tid 302208] [client 62.102.148.187:50646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NaoAs9lPxxVAErz3juAAAAL8"]
[Tue Jul 21 07:43:54.944735 2026] [security2:error] [pid 296703:tid 296877] [client 103.166.103.129:61278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Nain25uliftkV1n4JuQAAACw"]
[Tue Jul 21 07:43:54.944884 2026] [security2:error] [pid 296703:tid 296877] [client 103.166.103.129:61278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Nain25uliftkV1n4JuQAAACw"]
[Tue Jul 21 07:43:55.005619 2026] [security2:error] [pid 302018:tid 302262] [client 20.104.96.117:44282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/admin.php"] [unique_id "al9Na4As9lPxxVAErz3juwAAAPU"]
[Tue Jul 21 07:43:55.059122 2026] [security2:error] [pid 302018:tid 302271] [client 20.104.96.117:30598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/flox.php"] [unique_id "al9Na4As9lPxxVAErz3jvQAAAP4"]
[Tue Jul 21 07:43:55.067692 2026] [security2:error] [pid 302018:tid 302222] [client 20.197.195.24:13788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/test1.php"] [unique_id "al9Na4As9lPxxVAErz3jvgAAAM0"]
[Tue Jul 21 07:43:55.182110 2026] [security2:error] [pid 302018:tid 302260] [client 20.220.225.223:53471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Na4As9lPxxVAErz3jvwAAAPM"]
[Tue Jul 21 07:43:55.633686 2026] [security2:error] [pid 302018:tid 302239] [client 20.104.96.117:44144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/adminner.php"] [unique_id "al9Na4As9lPxxVAErz3jyQAAAN4"]
[Tue Jul 21 07:43:55.707253 2026] [security2:error] [pid 296703:tid 296873] [client 62.102.148.187:50650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Nayn25uliftkV1n4JxQAAACg"]
[Tue Jul 21 07:43:55.707342 2026] [security2:error] [pid 296703:tid 296873] [client 62.102.148.187:50650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Nayn25uliftkV1n4JxQAAACg"]
[Tue Jul 21 07:43:55.781802 2026] [security2:error] [pid 296703:tid 296887] [client 20.226.60.151:54357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/min.php"] [unique_id "al9Nayn25uliftkV1n4JyQAAADY"]
[Tue Jul 21 07:43:56.170705 2026] [autoindex:error] [pid 302018:tid 302192] [client 43.157.95.131:46224] AH01276: Cannot serve directory /home2/luisur31/unimundoconsultoria.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:43:56.204091 2026] [security2:error] [pid 302018:tid 302191] [client 20.226.60.151:54303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/dvjul.php"] [unique_id "al9NbIAs9lPxxVAErz3j0wAAAK4"]
[Tue Jul 21 07:43:56.276257 2026] [security2:error] [pid 302018:tid 302203] [client 20.104.96.117:44243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/admin.php"] [unique_id "al9NbIAs9lPxxVAErz3j1QAAALo"]
[Tue Jul 21 07:43:56.296336 2026] [security2:error] [pid 302018:tid 302199] [client 20.226.60.151:60118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/biufile.php"] [unique_id "al9NbIAs9lPxxVAErz3j1gAAALY"]
[Tue Jul 21 07:43:56.323059 2026] [security2:error] [pid 302018:tid 302104] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NbIAs9lPxxVAErz3j2QAAvlM"]
[Tue Jul 21 07:43:56.323251 2026] [security2:error] [pid 302018:tid 302207] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NbIAs9lPxxVAErz3j2QAAvlM"]
[Tue Jul 21 07:43:56.363559 2026] [security2:error] [pid 302018:tid 302257] [client 103.174.34.15:60002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NbIAs9lPxxVAErz3j2wAAAPA"]
[Tue Jul 21 07:43:56.363713 2026] [security2:error] [pid 302018:tid 302257] [client 103.174.34.15:60002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NbIAs9lPxxVAErz3j2wAAAPA"]
[Tue Jul 21 07:43:56.533919 2026] [security2:error] [pid 302018:tid 302211] [client 20.226.60.151:61957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/av.php"] [unique_id "al9NbIAs9lPxxVAErz3j3QAAAMI"]
[Tue Jul 21 07:43:56.579432 2026] [security2:error] [pid 302018:tid 302167] [client 182.8.255.181:17197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NbIAs9lPxxVAErz3j4QAAAJY"]
[Tue Jul 21 07:43:56.579601 2026] [security2:error] [pid 302018:tid 302167] [client 182.8.255.181:17197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NbIAs9lPxxVAErz3j4QAAAJY"]
[Tue Jul 21 07:43:56.612041 2026] [security2:error] [pid 296703:tid 296906] [client 106.215.181.8:20166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NbCn25uliftkV1n4J2gAAAEk"]
[Tue Jul 21 07:43:56.612136 2026] [security2:error] [pid 296703:tid 296906] [client 106.215.181.8:20166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NbCn25uliftkV1n4J2gAAAEk"]
[Tue Jul 21 07:43:56.676908 2026] [security2:error] [pid 296703:tid 296947] [client 178.153.91.96:63332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NbCn25uliftkV1n4J3AAAAHI"]
[Tue Jul 21 07:43:56.677053 2026] [security2:error] [pid 296703:tid 296947] [client 178.153.91.96:63332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NbCn25uliftkV1n4J3AAAAHI"]
[Tue Jul 21 07:43:56.753593 2026] [security2:error] [pid 302018:tid 302175] [client 20.197.195.24:13772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/database.php"] [unique_id "al9NbIAs9lPxxVAErz3j4wAAAJ4"]
[Tue Jul 21 07:43:56.862368 2026] [security2:error] [pid 302018:tid 302178] [client 20.104.96.117:44126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/k.php"] [unique_id "al9NbIAs9lPxxVAErz3j5AAAAKE"]
[Tue Jul 21 07:43:56.937754 2026] [security2:error] [pid 302018:tid 302230] [client 20.220.225.223:19667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/wp-explorer.php"] [unique_id "al9NbIAs9lPxxVAErz3j5wAAANU"]
[Tue Jul 21 07:43:57.074716 2026] [security2:error] [pid 302018:tid 302251] [client 20.220.225.223:53478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/wander.php"] [unique_id "al9NbYAs9lPxxVAErz3j6gAAAOo"]
[Tue Jul 21 07:43:57.158474 2026] [security2:error] [pid 302018:tid 302229] [client 20.197.195.24:13751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/file.php"] [unique_id "al9NbYAs9lPxxVAErz3j7gAAANQ"]
[Tue Jul 21 07:43:57.197004 2026] [security2:error] [pid 302018:tid 302253] [client 20.104.96.117:30857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/popo.php"] [unique_id "al9NbYAs9lPxxVAErz3j7wAAAOw"]
[Tue Jul 21 07:43:57.245617 2026] [security2:error] [pid 302018:tid 302109] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NbYAs9lPxxVAErz3j8AAAplg"]
[Tue Jul 21 07:43:57.245741 2026] [security2:error] [pid 302018:tid 302183] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NbYAs9lPxxVAErz3j8AAAplg"]
[Tue Jul 21 07:43:57.266376 2026] [security2:error] [pid 302018:tid 302110] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NbYAs9lPxxVAErz3j8QAA21k"]
[Tue Jul 21 07:43:57.266491 2026] [security2:error] [pid 302018:tid 302236] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NbYAs9lPxxVAErz3j8QAA21k"]
[Tue Jul 21 07:43:57.303666 2026] [security2:error] [pid 302018:tid 302204] [client 103.86.117.203:57800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NbYAs9lPxxVAErz3j8wAAALs"]
[Tue Jul 21 07:43:57.303857 2026] [security2:error] [pid 302018:tid 302204] [client 103.86.117.203:57800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NbYAs9lPxxVAErz3j8wAAALs"]
[Tue Jul 21 07:43:57.635634 2026] [security2:error] [pid 302018:tid 302187] [client 20.226.60.151:60127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/coffexium.php"] [unique_id "al9NbYAs9lPxxVAErz3j-QAAAKo"]
[Tue Jul 21 07:43:57.941712 2026] [security2:error] [pid 296703:tid 296880] [client 20.197.195.24:13761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/file.php"] [unique_id "al9NbSn25uliftkV1n4J7gAAAC8"]
[Tue Jul 21 07:43:57.997458 2026] [security2:error] [pid 296703:tid 296847] [client 74.7.241.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "renatapereiradecarva1751037342486.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9NbSn25uliftkV1n4J8QAADiM"]
[Tue Jul 21 07:43:58.007784 2026] [security2:error] [pid 296703:tid 296884] [client 122.164.127.47:59201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Nbin25uliftkV1n4J8gAAADM"]
[Tue Jul 21 07:43:58.009915 2026] [security2:error] [pid 296703:tid 296884] [client 122.164.127.47:59201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Nbin25uliftkV1n4J8gAAADM"]
[Tue Jul 21 07:43:58.014331 2026] [security2:error] [pid 296703:tid 296938] [client 20.104.96.117:44247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/blurbs.php"] [unique_id "al9Nbin25uliftkV1n4J8wAAAGk"]
[Tue Jul 21 07:43:58.158290 2026] [security2:error] [pid 296703:tid 296746] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9Nbin25uliftkV1n4J9gAAVSo"], referer: www.google.com
[Tue Jul 21 07:43:58.182239 2026] [security2:error] [pid 302018:tid 302117] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9NboAs9lPxxVAErz3kAQABAmA"]
[Tue Jul 21 07:43:58.463371 2026] [security2:error] [pid 296703:tid 296877] [client 117.251.86.144:34574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Nbin25uliftkV1n4J-wAAACw"]
[Tue Jul 21 07:43:58.463480 2026] [security2:error] [pid 296703:tid 296877] [client 117.251.86.144:34574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Nbin25uliftkV1n4J-wAAACw"]
[Tue Jul 21 07:43:58.480667 2026] [security2:error] [pid 302018:tid 302164] [client 122.186.204.214:60667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NboAs9lPxxVAErz3kBwAAAJM"]
[Tue Jul 21 07:43:58.480824 2026] [security2:error] [pid 302018:tid 302164] [client 122.186.204.214:60667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NboAs9lPxxVAErz3kBwAAAJM"]
[Tue Jul 21 07:43:58.814943 2026] [security2:error] [pid 296703:tid 296887] [client 20.220.225.223:53465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/jga.php"] [unique_id "al9Nbin25uliftkV1n4KAQAAADY"]
[Tue Jul 21 07:43:58.817446 2026] [security2:error] [pid 302018:tid 302182] [client 117.247.80.59:32315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NboAs9lPxxVAErz3kEAAAAKU"]
[Tue Jul 21 07:43:58.817537 2026] [security2:error] [pid 302018:tid 302182] [client 117.247.80.59:32315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NboAs9lPxxVAErz3kEAAAAKU"]
[Tue Jul 21 07:43:58.858728 2026] [security2:error] [pid 302018:tid 302209] [client 20.197.195.24:13808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/777.php"] [unique_id "al9NboAs9lPxxVAErz3kEQAAAMA"]
[Tue Jul 21 07:43:59.147224 2026] [security2:error] [pid 302018:tid 302116] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-plain.php"] [unique_id "al9NboAs9lPxxVAErz3kAAAA5F8"], referer: www.google.com
[Tue Jul 21 07:43:59.161691 2026] [security2:error] [pid 296703:tid 296861] [client 20.104.96.117:44101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/bajah.php"] [unique_id "al9Nbyn25uliftkV1n4KCQAAABw"]
[Tue Jul 21 07:43:59.206425 2026] [security2:error] [pid 302018:tid 302127] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Nb4As9lPxxVAErz3kGAAAsmo"]
[Tue Jul 21 07:43:59.206567 2026] [security2:error] [pid 302018:tid 302195] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Nb4As9lPxxVAErz3kGAAAsmo"]
[Tue Jul 21 07:43:59.303903 2026] [security2:error] [pid 296703:tid 296858] [client 20.226.60.151:61967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/core.php"] [unique_id "al9Nbyn25uliftkV1n4KDAAAABk"]
[Tue Jul 21 07:43:59.314360 2026] [security2:error] [pid 296703:tid 296756] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nbyn25uliftkV1n4KDQAAczQ"]
[Tue Jul 21 07:43:59.314564 2026] [security2:error] [pid 296703:tid 296948] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nbyn25uliftkV1n4KDQAAczQ"]
[Tue Jul 21 07:43:59.380874 2026] [security2:error] [pid 302018:tid 302225] [client 20.104.96.117:30407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/yas.php"] [unique_id "al9Nb4As9lPxxVAErz3kHwAAANA"]
[Tue Jul 21 07:43:59.558491 2026] [security2:error] [pid 302018:tid 302129] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/aafsohnc.php"] [unique_id "al9Nb4As9lPxxVAErz3kIAAA_Ww"], referer: www.google.com
[Tue Jul 21 07:43:59.662458 2026] [security2:error] [pid 302018:tid 302263] [client 20.197.195.24:49827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/ssixta.php"] [unique_id "al9Nb4As9lPxxVAErz3kJQAAAPY"]
[Tue Jul 21 07:44:00.070666 2026] [security2:error] [pid 302018:tid 302176] [client 20.104.96.117:44225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/a.php"] [unique_id "al9NcIAs9lPxxVAErz3kKwAAAJ8"]
[Tue Jul 21 07:44:00.156055 2026] [security2:error] [pid 302018:tid 302262] [client 154.192.233.199:58823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NcIAs9lPxxVAErz3kLgAAAPU"]
[Tue Jul 21 07:44:00.156182 2026] [security2:error] [pid 302018:tid 302262] [client 154.192.233.199:58823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NcIAs9lPxxVAErz3kLgAAAPU"]
[Tue Jul 21 07:44:00.203477 2026] [security2:error] [pid 302018:tid 302135] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9NcIAs9lPxxVAErz3kMQAAr3I"], referer: www.google.com
[Tue Jul 21 07:44:00.216588 2026] [security2:error] [pid 302018:tid 302264] [client 117.217.38.194:54019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NcIAs9lPxxVAErz3kMgAAAPc"]
[Tue Jul 21 07:44:00.216715 2026] [security2:error] [pid 302018:tid 302264] [client 117.217.38.194:54019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NcIAs9lPxxVAErz3kMgAAAPc"]
[Tue Jul 21 07:44:00.248782 2026] [security2:error] [pid 302018:tid 302188] [client 136.144.33.28:65397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NboAs9lPxxVAErz3j_AAAAKs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:44:00.464308 2026] [security2:error] [pid 302018:tid 302206] [client 20.220.225.223:19669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/akismet.php"] [unique_id "al9NcIAs9lPxxVAErz3kNQAAAL0"]
[Tue Jul 21 07:44:00.493617 2026] [security2:error] [pid 296703:tid 296856] [client 20.226.60.151:60121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/als.php"] [unique_id "al9NcCn25uliftkV1n4KHwAAABc"]
[Tue Jul 21 07:44:00.514605 2026] [security2:error] [pid 296703:tid 296892] [client 20.220.225.223:53473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/x.php"] [unique_id "al9NcCn25uliftkV1n4KIAAAADs"]
[Tue Jul 21 07:44:00.524999 2026] [security2:error] [pid 302018:tid 302256] [client 202.143.127.214:54009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NcIAs9lPxxVAErz3kNgAAAO8"]
[Tue Jul 21 07:44:00.525085 2026] [security2:error] [pid 302018:tid 302256] [client 202.143.127.214:54009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NcIAs9lPxxVAErz3kNgAAAO8"]
[Tue Jul 21 07:44:00.552172 2026] [security2:error] [pid 296703:tid 296883] [client 41.68.90.219:63073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NcCn25uliftkV1n4KIQAAADI"]
[Tue Jul 21 07:44:00.553254 2026] [security2:error] [pid 296703:tid 296883] [client 41.68.90.219:63073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NcCn25uliftkV1n4KIQAAADI"]
[Tue Jul 21 07:44:00.644060 2026] [security2:error] [pid 296703:tid 296866] [client 74.249.245.134:5523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/ws81.php"] [unique_id "al9NcCn25uliftkV1n4KIgAAACE"]
[Tue Jul 21 07:44:00.755708 2026] [security2:error] [pid 302018:tid 302268] [client 20.104.96.117:44107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/edit.php"] [unique_id "al9NcIAs9lPxxVAErz3kOgAAAPs"]
[Tue Jul 21 07:44:01.153535 2026] [security2:error] [pid 302018:tid 302175] [client 152.59.154.239:57936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NcYAs9lPxxVAErz3kQAAAAJ4"]
[Tue Jul 21 07:44:01.153700 2026] [security2:error] [pid 302018:tid 302175] [client 152.59.154.239:57936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NcYAs9lPxxVAErz3kQAAAAJ4"]
[Tue Jul 21 07:44:01.442215 2026] [core:error] [pid 296703:tid 296723] [remote 159.223.41.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:44:01.442241 2026] [core:error] [pid 296703:tid 296723] [remote 159.223.41.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:44:01.510640 2026] [security2:error] [pid 296703:tid 296885] [client 20.104.96.117:30903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/file61.php"] [unique_id "al9NcSn25uliftkV1n4KOAAAADQ"]
[Tue Jul 21 07:44:01.590134 2026] [security2:error] [pid 302018:tid 302169] [client 20.104.96.117:44109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/hosty.php"] [unique_id "al9NcYAs9lPxxVAErz3kTAAAAJg"]
[Tue Jul 21 07:44:01.613214 2026] [security2:error] [pid 302018:tid 302271] [client 20.226.60.151:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/simple.php"] [unique_id "al9NcYAs9lPxxVAErz3kTQAAAP4"]
[Tue Jul 21 07:44:01.759912 2026] [security2:error] [pid 296703:tid 296804] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9NcSn25uliftkV1n4KPAAAWWQ"]
[Tue Jul 21 07:44:01.802745 2026] [security2:error] [pid 302018:tid 302170] [client 20.197.195.24:13743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/1c.php"] [unique_id "al9NcYAs9lPxxVAErz3kUwAAAJk"]
[Tue Jul 21 07:44:01.959929 2026] [security2:error] [pid 302018:tid 302152] [client 74.249.245.134:5534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/222.php"] [unique_id "al9NcYAs9lPxxVAErz3kWAAAAIc"]
[Tue Jul 21 07:44:02.157429 2026] [security2:error] [pid 296703:tid 296858] [client 20.220.225.223:53497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/tinyfilemanager.php"] [unique_id "al9Ncin25uliftkV1n4KRAAAABk"]
[Tue Jul 21 07:44:02.359873 2026] [security2:error] [pid 296703:tid 296836] [client 59.96.220.140:62223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Ncin25uliftkV1n4KSAAAAAM"]
[Tue Jul 21 07:44:02.360437 2026] [security2:error] [pid 296703:tid 296836] [client 59.96.220.140:62223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Ncin25uliftkV1n4KSAAAAAM"]
[Tue Jul 21 07:44:02.691627 2026] [security2:error] [pid 302018:tid 302148] [remote 159.223.41.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9NcoAs9lPxxVAErz3kYwAAtX8"]
[Tue Jul 21 07:44:02.781968 2026] [security2:error] [pid 302018:tid 302230] [client 20.104.96.117:44105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/k.php"] [unique_id "al9NcoAs9lPxxVAErz3kZAAAANU"]
[Tue Jul 21 07:44:02.817560 2026] [security2:error] [pid 302018:tid 302209] [client 20.197.195.24:49893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/test2.php"] [unique_id "al9NcoAs9lPxxVAErz3kaQAAAMA"]
[Tue Jul 21 07:44:02.954929 2026] [security2:error] [pid 302018:tid 302254] [client 20.226.60.151:61954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/init.php"] [unique_id "al9NcoAs9lPxxVAErz3kagAAAO0"]
[Tue Jul 21 07:44:02.987985 2026] [security2:error] [pid 302018:tid 302208] [client 74.249.245.134:17446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/t.php"] [unique_id "al9NcoAs9lPxxVAErz3kbAAAAL8"]
[Tue Jul 21 07:44:03.012580 2026] [core:error] [pid 302018:tid 302023] [remote 159.223.41.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:44:03.012602 2026] [core:error] [pid 302018:tid 302023] [remote 159.223.41.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:44:03.173418 2026] [security2:error] [pid 302018:tid 302242] [client 139.167.225.182:55299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nc4As9lPxxVAErz3kcQAAAOE"]
[Tue Jul 21 07:44:03.175203 2026] [security2:error] [pid 302018:tid 302242] [client 139.167.225.182:55299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nc4As9lPxxVAErz3kcQAAAOE"]
[Tue Jul 21 07:44:03.207116 2026] [security2:error] [pid 302018:tid 302274] [client 20.220.225.223:19305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/ace2.php"] [unique_id "al9Nc4As9lPxxVAErz3kcgAAAQE"]
[Tue Jul 21 07:44:03.302436 2026] [security2:error] [pid 296703:tid 296856] [client 20.220.225.223:53474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/ee.php"] [unique_id "al9Ncyn25uliftkV1n4KVQAAABc"]
[Tue Jul 21 07:44:03.324710 2026] [security2:error] [pid 302018:tid 302026] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Nc4As9lPxxVAErz3kdAAAtwU"]
[Tue Jul 21 07:44:03.359401 2026] [security2:error] [pid 302018:tid 302267] [client 20.197.195.24:13802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/buy.php"] [unique_id "al9Nc4As9lPxxVAErz3kdQAAAPo"]
[Tue Jul 21 07:44:03.507558 2026] [security2:error] [pid 296703:tid 296868] [client 122.162.144.145:17191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Ncyn25uliftkV1n4KXgAAACM"]
[Tue Jul 21 07:44:03.509683 2026] [security2:error] [pid 296703:tid 296868] [client 122.162.144.145:17191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Ncyn25uliftkV1n4KXgAAACM"]
[Tue Jul 21 07:44:03.607387 2026] [security2:error] [pid 302018:tid 302215] [client 20.220.225.223:34284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/fz.php"] [unique_id "al9Nc4As9lPxxVAErz3kewAAAMY"]
[Tue Jul 21 07:44:03.637901 2026] [security2:error] [pid 302018:tid 302030] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Nc4As9lPxxVAErz3kfQAArwk"]
[Tue Jul 21 07:44:03.891996 2026] [security2:error] [pid 296703:tid 296953] [client 20.197.195.24:49873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/ssend.php"] [unique_id "al9Ncyn25uliftkV1n4KZAAAAHg"]
[Tue Jul 21 07:44:03.952078 2026] [security2:error] [pid 296703:tid 296707] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Ncyn25uliftkV1n4KZQAAagM"]
[Tue Jul 21 07:44:04.054464 2026] [security2:error] [pid 302018:tid 302231] [client 74.249.245.134:54392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/a.php"] [unique_id "al9NdIAs9lPxxVAErz3kigAAANY"]
[Tue Jul 21 07:44:04.292423 2026] [security2:error] [pid 296703:tid 296869] [client 103.29.114.44:5037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NdCn25uliftkV1n4KagAAACQ"]
[Tue Jul 21 07:44:04.292586 2026] [security2:error] [pid 296703:tid 296869] [client 103.29.114.44:5037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NdCn25uliftkV1n4KagAAACQ"]
[Tue Jul 21 07:44:04.299426 2026] [security2:error] [pid 302018:tid 302034] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9NdIAs9lPxxVAErz3kjQAA3A0"]
[Tue Jul 21 07:44:04.342846 2026] [security2:error] [pid 302018:tid 302175] [client 20.104.96.117:44240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/aaa.php"] [unique_id "al9NdIAs9lPxxVAErz3kjwAAAJ4"]
[Tue Jul 21 07:44:04.417548 2026] [security2:error] [pid 296703:tid 296941] [client 128.127.105.184:47950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NdCn25uliftkV1n4KbgAAAGw"]
[Tue Jul 21 07:44:04.417682 2026] [security2:error] [pid 296703:tid 296941] [client 128.127.105.184:47950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9NdCn25uliftkV1n4KbgAAAGw"]
[Tue Jul 21 07:44:04.434456 2026] [security2:error] [pid 302018:tid 302212] [client 20.197.195.24:13781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/item.php"] [unique_id "al9NdIAs9lPxxVAErz3kkAAAAMM"]
[Tue Jul 21 07:44:04.612822 2026] [security2:error] [pid 302018:tid 302036] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NdIAs9lPxxVAErz3klAAAlQ8"]
[Tue Jul 21 07:44:04.649903 2026] [security2:error] [pid 296703:tid 296904] [client 173.24.185.52:59311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NdCn25uliftkV1n4KcwAAAEc"]
[Tue Jul 21 07:44:04.650031 2026] [security2:error] [pid 296703:tid 296904] [client 173.24.185.52:59311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NdCn25uliftkV1n4KcwAAAEc"]
[Tue Jul 21 07:44:04.833683 2026] [security2:error] [pid 296703:tid 296776] [remote 202.51.202.242:45294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NdCn25uliftkV1n4KdQAAFEg"]
[Tue Jul 21 07:44:04.833827 2026] [security2:error] [pid 296703:tid 296853] [client 202.51.202.242:45294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NdCn25uliftkV1n4KdQAAFEg"]
[Tue Jul 21 07:44:04.913161 2026] [security2:error] [pid 302018:tid 302172] [client 172.245.102.33:64805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NdIAs9lPxxVAErz3klQAAAJs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:44:04.926931 2026] [security2:error] [pid 302018:tid 302038] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9NdIAs9lPxxVAErz3kmQAAtxE"]
[Tue Jul 21 07:44:04.959739 2026] [security2:error] [pid 296703:tid 296827] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NdCn25uliftkV1n4KeAAAeXs"]
[Tue Jul 21 07:44:04.959951 2026] [security2:error] [pid 296703:tid 296954] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NdCn25uliftkV1n4KeAAAeXs"]
[Tue Jul 21 07:44:05.040319 2026] [security2:error] [pid 296703:tid 296837] [client 20.197.195.24:14059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NdSn25uliftkV1n4KfgAAAAQ"]
[Tue Jul 21 07:44:05.111724 2026] [security2:error] [pid 296703:tid 296921] [client 20.220.225.223:34240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/la.php"] [unique_id "al9NdSn25uliftkV1n4KggAAAFg"]
[Tue Jul 21 07:44:05.217847 2026] [security2:error] [pid 302018:tid 302173] [client 20.63.100.92:7880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/dr.php"] [unique_id "al9NdYAs9lPxxVAErz3knAAAAJw"]
[Tue Jul 21 07:44:05.243728 2026] [security2:error] [pid 302018:tid 302039] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9NdYAs9lPxxVAErz3knQAA_xI"]
[Tue Jul 21 07:44:05.274660 2026] [security2:error] [pid 302018:tid 302266] [client 20.220.225.223:53460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/blue.php"] [unique_id "al9NdYAs9lPxxVAErz3knwAAAPk"]
[Tue Jul 21 07:44:05.378269 2026] [security2:error] [pid 296703:tid 296854] [client 122.179.91.63:17675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NdSn25uliftkV1n4KhwAAABU"]
[Tue Jul 21 07:44:05.378384 2026] [security2:error] [pid 296703:tid 296854] [client 122.179.91.63:17675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NdSn25uliftkV1n4KhwAAABU"]
[Tue Jul 21 07:44:05.452238 2026] [security2:error] [pid 296703:tid 296889] [client 20.197.195.24:14034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NdSn25uliftkV1n4KiAAAADg"]
[Tue Jul 21 07:44:05.456325 2026] [security2:error] [pid 302018:tid 302162] [client 20.104.96.117:30881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/water.php"] [unique_id "al9NdYAs9lPxxVAErz3kpAAAAJE"]
[Tue Jul 21 07:44:05.467510 2026] [security2:error] [pid 302018:tid 302215] [client 20.226.60.151:54341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/fpwch.php"] [unique_id "al9NdYAs9lPxxVAErz3kpQAAAMY"]
[Tue Jul 21 07:44:05.523220 2026] [security2:error] [pid 296703:tid 296900] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9NdCn25uliftkV1n4KbQAAQx8"]
[Tue Jul 21 07:44:05.562462 2026] [security2:error] [pid 296703:tid 296734] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NdSn25uliftkV1n4KjAAAZh4"]
[Tue Jul 21 07:44:05.566023 2026] [security2:error] [pid 296703:tid 296813] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NdSn25uliftkV1n4KjQAAK20"]
[Tue Jul 21 07:44:05.566147 2026] [security2:error] [pid 296703:tid 296876] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NdSn25uliftkV1n4KjQAAK20"]
[Tue Jul 21 07:44:05.627282 2026] [security2:error] [pid 296703:tid 296916] [client 103.166.103.129:61792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NdSn25uliftkV1n4KkAAAAFM"]
[Tue Jul 21 07:44:05.627410 2026] [security2:error] [pid 296703:tid 296916] [client 103.166.103.129:61792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NdSn25uliftkV1n4KkAAAAFM"]
[Tue Jul 21 07:44:05.874928 2026] [security2:error] [pid 296703:tid 296855] [client 20.197.195.24:49898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/ss.php"] [unique_id "al9NdSn25uliftkV1n4KkwAAABY"]
[Tue Jul 21 07:44:05.883507 2026] [security2:error] [pid 302018:tid 302042] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NdYAs9lPxxVAErz3kqAAA6hU"]
[Tue Jul 21 07:44:05.956359 2026] [security2:error] [pid 302018:tid 302202] [client 20.197.195.24:14027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/media.php"] [unique_id "al9NdYAs9lPxxVAErz3kqgAAALk"]
[Tue Jul 21 07:44:06.044198 2026] [security2:error] [pid 302018:tid 302222] [client 74.249.245.134:54395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/a1.php"] [unique_id "al9NdoAs9lPxxVAErz3krAAAAM0"]
[Tue Jul 21 07:44:06.047154 2026] [security2:error] [pid 302018:tid 302249] [client 37.140.223.68:55729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NdoAs9lPxxVAErz3kqwAAAOg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:44:06.148007 2026] [security2:error] [pid 296703:tid 296790] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Ndin25uliftkV1n4KoQAAVFY"]
[Tue Jul 21 07:44:06.163650 2026] [security2:error] [pid 296703:tid 296714] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Ndin25uliftkV1n4KogAAAQo"]
[Tue Jul 21 07:44:06.187958 2026] [security2:error] [pid 296703:tid 296782] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/dp.php"] [unique_id "al9Ndin25uliftkV1n4KowAAbE4"]
[Tue Jul 21 07:44:06.197143 2026] [security2:error] [pid 302018:tid 302046] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NdoAs9lPxxVAErz3ksQAArRk"]
[Tue Jul 21 07:44:06.205502 2026] [security2:error] [pid 296703:tid 296825] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/old.php"] [unique_id "al9Ndin25uliftkV1n4KpAAAIHk"]
[Tue Jul 21 07:44:06.222585 2026] [security2:error] [pid 296703:tid 296781] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/ms-new.php"] [unique_id "al9Ndin25uliftkV1n4KpQAAa00"]
[Tue Jul 21 07:44:06.252054 2026] [security2:error] [pid 296703:tid 296810] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/track.php"] [unique_id "al9Ndin25uliftkV1n4KpgAAM2o"]
[Tue Jul 21 07:44:06.273753 2026] [security2:error] [pid 296703:tid 296748] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/2352356666.php"] [unique_id "al9Ndin25uliftkV1n4KpwAAdCw"]
[Tue Jul 21 07:44:06.295616 2026] [security2:error] [pid 296703:tid 296706] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/pn.php"] [unique_id "al9Ndin25uliftkV1n4KqAAARwI"]
[Tue Jul 21 07:44:06.319195 2026] [security2:error] [pid 296703:tid 296710] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9Ndin25uliftkV1n4KqgAARAY"]
[Tue Jul 21 07:44:06.338036 2026] [security2:error] [pid 296703:tid 296739] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/dr.php"] [unique_id "al9Ndin25uliftkV1n4KqwAABSM"]
[Tue Jul 21 07:44:06.370883 2026] [security2:error] [pid 296703:tid 296887] [client 20.63.100.92:7888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/2x.php"] [unique_id "al9Ndin25uliftkV1n4KrAAAADY"]
[Tue Jul 21 07:44:06.371102 2026] [security2:error] [pid 296703:tid 296729] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/2x.php"] [unique_id "al9Ndin25uliftkV1n4KrQAAFBk"]
[Tue Jul 21 07:44:06.388096 2026] [security2:error] [pid 296703:tid 296752] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/kq1.php"] [unique_id "al9Ndin25uliftkV1n4KrgAAOTA"]
[Tue Jul 21 07:44:06.407318 2026] [security2:error] [pid 296703:tid 296937] [client 20.197.195.24:14018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/images.php"] [unique_id "al9Ndin25uliftkV1n4KrwAAAGg"]
[Tue Jul 21 07:44:06.407944 2026] [security2:error] [pid 296703:tid 296746] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/zzz.php"] [unique_id "al9Ndin25uliftkV1n4KsAAAJio"]
[Tue Jul 21 07:44:06.410366 2026] [security2:error] [pid 302018:tid 302171] [client 20.220.225.223:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/wp-signup.php"] [unique_id "al9NdoAs9lPxxVAErz3ksgAAAJo"]
[Tue Jul 21 07:44:06.423616 2026] [security2:error] [pid 296703:tid 296792] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/wicked.php"] [unique_id "al9Ndin25uliftkV1n4KsQAAeVg"]
[Tue Jul 21 07:44:06.440343 2026] [security2:error] [pid 296703:tid 296743] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/edit.php"] [unique_id "al9Ndin25uliftkV1n4KsgAARSc"]
[Tue Jul 21 07:44:06.474789 2026] [security2:error] [pid 296703:tid 296799] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/kua.php"] [unique_id "al9Ndin25uliftkV1n4KtAAAHV8"]
[Tue Jul 21 07:44:06.491443 2026] [security2:error] [pid 296703:tid 296741] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/ez.php"] [unique_id "al9Ndin25uliftkV1n4KtQAAByU"]
[Tue Jul 21 07:44:06.508045 2026] [security2:error] [pid 296703:tid 296704] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/fz.php"] [unique_id "al9Ndin25uliftkV1n4KtgAADwA"]
[Tue Jul 21 07:44:06.525636 2026] [security2:error] [pid 296703:tid 296749] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/la.php"] [unique_id "al9Ndin25uliftkV1n4KtwAAWC0"]
[Tue Jul 21 07:44:06.536524 2026] [security2:error] [pid 302018:tid 302045] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NdoAs9lPxxVAErz3ktQAAlBg"]
[Tue Jul 21 07:44:06.542332 2026] [security2:error] [pid 296703:tid 296728] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9Ndin25uliftkV1n4KuAAACRg"]
[Tue Jul 21 07:44:06.560659 2026] [security2:error] [pid 296703:tid 296787] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/inso.php"] [unique_id "al9Ndin25uliftkV1n4KuQAAA1M"]
[Tue Jul 21 07:44:06.574156 2026] [security2:error] [pid 302018:tid 302237] [client 20.104.96.117:44252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/file5.php"] [unique_id "al9NdoAs9lPxxVAErz3ktwAAANw"]
[Tue Jul 21 07:44:06.579710 2026] [security2:error] [pid 296703:tid 296753] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/wpx.php"] [unique_id "al9Ndin25uliftkV1n4KuwAAfzE"]
[Tue Jul 21 07:44:06.604760 2026] [security2:error] [pid 296703:tid 296830] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/berlin.php"] [unique_id "al9Ndin25uliftkV1n4KvAAAc34"]
[Tue Jul 21 07:44:06.629783 2026] [security2:error] [pid 296703:tid 296756] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/billur.php"] [unique_id "al9Ndin25uliftkV1n4KvwAAGTQ"]
[Tue Jul 21 07:44:06.648646 2026] [security2:error] [pid 296703:tid 296766] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/mimpi.php"] [unique_id "al9Ndin25uliftkV1n4KwAAAOD4"]
[Tue Jul 21 07:44:06.655194 2026] [security2:error] [pid 296703:tid 296907] [client 20.197.195.24:14049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/gecko.php"] [unique_id "al9Ndin25uliftkV1n4KwQAAAEo"]
[Tue Jul 21 07:44:06.665666 2026] [security2:error] [pid 296703:tid 296775] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/dp.php"] [unique_id "al9Ndin25uliftkV1n4KwgAAHEc"]
[Tue Jul 21 07:44:06.687183 2026] [security2:error] [pid 296703:tid 296722] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/bootstrap.php"] [unique_id "al9Ndin25uliftkV1n4KxAAAQRI"]
[Tue Jul 21 07:44:06.713619 2026] [security2:error] [pid 296703:tid 296711] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/wp-editor.php"] [unique_id "al9Ndin25uliftkV1n4KxQAAZgc"]
[Tue Jul 21 07:44:06.733274 2026] [security2:error] [pid 296703:tid 296759] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/cro.php"] [unique_id "al9Ndin25uliftkV1n4KxgAAITc"]
[Tue Jul 21 07:44:06.746499 2026] [security2:error] [pid 302018:tid 302150] [client 2602:ffe4:8:1001::4:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bdois.com.br"] [uri "/files/GCS%20CERTIFICATE%202173BR%20-%20SISTEMA%20DE%20GEST%C3%83O%20-%20B2%20-%20ISO%209001.pdf"] [unique_id "al9NdoAs9lPxxVAErz3kuQAAAIU"]
[Tue Jul 21 07:44:06.751231 2026] [security2:error] [pid 296703:tid 296724] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/cron-tab.php"] [unique_id "al9Ndin25uliftkV1n4KxwAAKxQ"]
[Tue Jul 21 07:44:06.769582 2026] [security2:error] [pid 296703:tid 296803] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/koiy.php"] [unique_id "al9Ndin25uliftkV1n4KyAAAU2M"]
[Tue Jul 21 07:44:06.787137 2026] [security2:error] [pid 296703:tid 296788] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/hp2.php"] [unique_id "al9Ndin25uliftkV1n4KyQAAIlQ"]
[Tue Jul 21 07:44:06.806385 2026] [security2:error] [pid 296703:tid 296755] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/hp3.php"] [unique_id "al9Ndin25uliftkV1n4KygAAJzM"]
[Tue Jul 21 07:44:06.824299 2026] [security2:error] [pid 296703:tid 296754] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/aa1.php"] [unique_id "al9Ndin25uliftkV1n4KzAAASDI"]
[Tue Jul 21 07:44:06.837927 2026] [security2:error] [pid 296703:tid 296959] [client 20.197.195.24:13751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/hypo.php"] [unique_id "al9Ndin25uliftkV1n4KzQAAAH4"]
[Tue Jul 21 07:44:06.843078 2026] [security2:error] [pid 296703:tid 296829] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/acew67.php"] [unique_id "al9Ndin25uliftkV1n4KzgAAMX0"]
[Tue Jul 21 07:44:06.849921 2026] [security2:error] [pid 296703:tid 296793] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9Ndin25uliftkV1n4KzwAAI1k"]
[Tue Jul 21 07:44:06.860911 2026] [security2:error] [pid 296703:tid 296809] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/bscclapb.php"] [unique_id "al9Ndin25uliftkV1n4K0AAAG2k"]
[Tue Jul 21 07:44:06.877568 2026] [security2:error] [pid 296703:tid 296713] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/else1.php"] [unique_id "al9Ndin25uliftkV1n4K0QAAFgk"]
[Tue Jul 21 07:44:06.894626 2026] [security2:error] [pid 296703:tid 296831] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/tkikikoko.php"] [unique_id "al9Ndin25uliftkV1n4K0gAAS38"]
[Tue Jul 21 07:44:06.911628 2026] [security2:error] [pid 296703:tid 296794] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9Ndin25uliftkV1n4K0wAAPFo"]
[Tue Jul 21 07:44:06.930992 2026] [security2:error] [pid 296703:tid 296828] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/wp-css.php"] [unique_id "al9Ndin25uliftkV1n4K1AAAd3w"]
[Tue Jul 21 07:44:06.962359 2026] [security2:error] [pid 296703:tid 296765] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/wp-explorer.php"] [unique_id "al9Ndin25uliftkV1n4K1gAAZT0"]
[Tue Jul 21 07:44:06.994212 2026] [security2:error] [pid 296703:tid 296723] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/akismet.php"] [unique_id "al9Ndin25uliftkV1n4K2gAABhM"]
[Tue Jul 21 07:44:07.015948 2026] [security2:error] [pid 296703:tid 296939] [client 20.104.96.117:30880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/nano.php"] [unique_id "al9Ndyn25uliftkV1n4K2wAAAGo"]
[Tue Jul 21 07:44:07.022313 2026] [security2:error] [pid 296703:tid 296783] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/ace2.php"] [unique_id "al9Ndyn25uliftkV1n4K3AAAe08"]
[Tue Jul 21 07:44:07.042634 2026] [security2:error] [pid 296703:tid 296777] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.10db.com.br"] [uri "/ms.php"] [unique_id "al9Ndyn25uliftkV1n4K3QAAaUk"]
[Tue Jul 21 07:44:07.071797 2026] [security2:error] [pid 302018:tid 302201] [client 106.215.181.8:22007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nd4As9lPxxVAErz3kvQAAALg"]
[Tue Jul 21 07:44:07.071981 2026] [security2:error] [pid 302018:tid 302201] [client 106.215.181.8:22007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nd4As9lPxxVAErz3kvQAAALg"]
[Tue Jul 21 07:44:07.105958 2026] [security2:error] [pid 296703:tid 296894] [client 182.8.255.181:17173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Ndyn25uliftkV1n4K3wAAAD0"]
[Tue Jul 21 07:44:07.106142 2026] [security2:error] [pid 296703:tid 296894] [client 182.8.255.181:17173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Ndyn25uliftkV1n4K3wAAAD0"]
[Tue Jul 21 07:44:07.139128 2026] [security2:error] [pid 296703:tid 296768] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Ndyn25uliftkV1n4K4AAAL0A"]
[Tue Jul 21 07:44:07.139264 2026] [security2:error] [pid 296703:tid 296880] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Ndyn25uliftkV1n4K4AAAL0A"]
[Tue Jul 21 07:44:07.166642 2026] [security2:error] [pid 302018:tid 302047] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9Nd4As9lPxxVAErz3kvgAAvxo"]
[Tue Jul 21 07:44:07.199547 2026] [security2:error] [pid 302018:tid 302235] [client 103.174.34.15:60533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nd4As9lPxxVAErz3kwAAAANo"]
[Tue Jul 21 07:44:07.199657 2026] [security2:error] [pid 302018:tid 302235] [client 103.174.34.15:60533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nd4As9lPxxVAErz3kwAAAANo"]
[Tue Jul 21 07:44:07.255451 2026] [security2:error] [pid 302018:tid 302225] [client 20.197.195.24:14026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/82.php"] [unique_id "al9Nd4As9lPxxVAErz3kwQAAANA"]
[Tue Jul 21 07:44:07.266792 2026] [security2:error] [pid 302018:tid 302174] [client 178.153.91.96:63944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Nd4As9lPxxVAErz3kwgAAAJ0"]
[Tue Jul 21 07:44:07.266907 2026] [security2:error] [pid 302018:tid 302174] [client 178.153.91.96:63944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Nd4As9lPxxVAErz3kwgAAAJ0"]
[Tue Jul 21 07:44:07.386662 2026] [security2:error] [pid 296703:tid 296834] [client 193.36.225.139:37327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Ndyn25uliftkV1n4K5AAAAAE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:44:07.459911 2026] [security2:error] [pid 302018:tid 302216] [client 20.104.96.117:44265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/222.php"] [unique_id "al9Nd4As9lPxxVAErz3kxQAAAMc"]
[Tue Jul 21 07:44:07.461469 2026] [security2:error] [pid 302018:tid 302204] [client 20.220.225.223:19741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.roseoliveirarose.com.br"] [uri "/ms.php"] [unique_id "al9Nd4As9lPxxVAErz3kxgAAALs"]
[Tue Jul 21 07:44:07.478315 2026] [security2:error] [pid 302018:tid 302053] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Nd4As9lPxxVAErz3kxwAAviA"]
[Tue Jul 21 07:44:07.626329 2026] [security2:error] [pid 302018:tid 302258] [client 20.197.195.24:14076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/admin.php"] [unique_id "al9Nd4As9lPxxVAErz3kygAAAPE"]
[Tue Jul 21 07:44:07.720948 2026] [security2:error] [pid 302018:tid 302172] [client 74.7.230.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "andersonbarbosarodri1781972754062.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9Nd4As9lPxxVAErz3kzwAAmyE"]
[Tue Jul 21 07:44:07.728033 2026] [security2:error] [pid 302018:tid 302243] [client 74.249.245.134:54353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/w.php"] [unique_id "al9Nd4As9lPxxVAErz3k0AAAAOI"]
[Tue Jul 21 07:44:07.784398 2026] [security2:error] [pid 302018:tid 302210] [client 20.197.195.24:14073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/adminner.php"] [unique_id "al9Nd4As9lPxxVAErz3k0QAAAME"]
[Tue Jul 21 07:44:07.791376 2026] [security2:error] [pid 302018:tid 302055] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Nd4As9lPxxVAErz3k0gAAkSI"]
[Tue Jul 21 07:44:07.803519 2026] [security2:error] [pid 296703:tid 296878] [client 103.86.117.203:58347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ndyn25uliftkV1n4K6gAAAC0"]
[Tue Jul 21 07:44:07.803655 2026] [security2:error] [pid 296703:tid 296878] [client 103.86.117.203:58347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ndyn25uliftkV1n4K6gAAAC0"]
[Tue Jul 21 07:44:07.878642 2026] [security2:error] [pid 302018:tid 302056] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Nd4As9lPxxVAErz3k0wAAtyM"]
[Tue Jul 21 07:44:07.878789 2026] [security2:error] [pid 302018:tid 302200] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Nd4As9lPxxVAErz3k0wAAtyM"]
[Tue Jul 21 07:44:07.935174 2026] [security2:error] [pid 302018:tid 302240] [client 20.197.195.24:14022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/admin.php"] [unique_id "al9Nd4As9lPxxVAErz3k1AAAAN8"]
[Tue Jul 21 07:44:08.051858 2026] [security2:error] [pid 302018:tid 302058] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NeIAs9lPxxVAErz3k1wAAjiU"]
[Tue Jul 21 07:44:08.052032 2026] [security2:error] [pid 302018:tid 302159] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NeIAs9lPxxVAErz3k1wAAjiU"]
[Tue Jul 21 07:44:08.106725 2026] [security2:error] [pid 296703:tid 296785] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.royalbsolutions.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9NeCn25uliftkV1n4K7gAAR1E"]
[Tue Jul 21 07:44:08.186492 2026] [security2:error] [pid 296703:tid 296937] [client 20.197.195.24:14055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/k.php"] [unique_id "al9NeCn25uliftkV1n4K8wAAAGg"]
[Tue Jul 21 07:44:08.226735 2026] [security2:error] [pid 296703:tid 296902] [client 20.104.96.117:30449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/moon.php"] [unique_id "al9NeCn25uliftkV1n4K9AAAAEU"]
[Tue Jul 21 07:44:08.289635 2026] [security2:error] [pid 302018:tid 302179] [client 20.197.195.24:13983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/blurbs.php"] [unique_id "al9NeIAs9lPxxVAErz3k2AAAAKI"]
[Tue Jul 21 07:44:08.413589 2026] [security2:error] [pid 302018:tid 302262] [client 20.226.60.151:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/domvf.php"] [unique_id "al9NeIAs9lPxxVAErz3k2QAAAPU"]
[Tue Jul 21 07:44:08.420872 2026] [security2:error] [pid 302018:tid 302191] [client 20.104.96.117:44267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/test.php"] [unique_id "al9NeIAs9lPxxVAErz3k2gAAAK4"]
[Tue Jul 21 07:44:08.487157 2026] [security2:error] [pid 302018:tid 302177] [client 20.220.225.223:34255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/acew67.php"] [unique_id "al9NeIAs9lPxxVAErz3k2wAAAKA"]
[Tue Jul 21 07:44:08.538435 2026] [security2:error] [pid 302018:tid 302215] [client 122.164.127.47:59771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NeIAs9lPxxVAErz3k3AAAAMY"]
[Tue Jul 21 07:44:08.538567 2026] [security2:error] [pid 302018:tid 302215] [client 122.164.127.47:59771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NeIAs9lPxxVAErz3k3AAAAMY"]
[Tue Jul 21 07:44:08.734287 2026] [security2:error] [pid 302018:tid 302157] [client 20.197.195.24:14048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/bajah.php"] [unique_id "al9NeIAs9lPxxVAErz3k4AAAAIw"]
[Tue Jul 21 07:44:08.787623 2026] [security2:error] [pid 296703:tid 296960] [client 20.197.195.24:49912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/users.php"] [unique_id "al9NeCn25uliftkV1n4K_AAAAH8"]
[Tue Jul 21 07:44:09.032336 2026] [security2:error] [pid 302018:tid 302241] [client 20.197.195.24:13989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/a.php"] [unique_id "al9NeYAs9lPxxVAErz3k6AAAAOA"]
[Tue Jul 21 07:44:09.047776 2026] [security2:error] [pid 302018:tid 302248] [client 20.104.96.117:30870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-info.php"] [unique_id "al9NeYAs9lPxxVAErz3k6QAAAOc"]
[Tue Jul 21 07:44:09.173098 2026] [security2:error] [pid 296703:tid 296947] [client 122.186.204.214:61194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NeSn25uliftkV1n4LBAAAAHI"]
[Tue Jul 21 07:44:09.173237 2026] [security2:error] [pid 296703:tid 296947] [client 122.186.204.214:61194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NeSn25uliftkV1n4LBAAAAHI"]
[Tue Jul 21 07:44:09.218061 2026] [security2:error] [pid 302018:tid 302257] [client 117.251.86.144:52828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NeYAs9lPxxVAErz3k6gAAAPA"]
[Tue Jul 21 07:44:09.218214 2026] [security2:error] [pid 302018:tid 302257] [client 117.251.86.144:52828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NeYAs9lPxxVAErz3k6gAAAPA"]
[Tue Jul 21 07:44:09.364808 2026] [security2:error] [pid 302018:tid 302225] [client 20.197.195.24:14032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/edit.php"] [unique_id "al9NeYAs9lPxxVAErz3k7gAAANA"]
[Tue Jul 21 07:44:09.396489 2026] [security2:error] [pid 302018:tid 302255] [client 20.104.96.117:44259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/aaa.php"] [unique_id "al9NeYAs9lPxxVAErz3k7wAAAO4"]
[Tue Jul 21 07:44:09.437842 2026] [security2:error] [pid 296703:tid 296905] [client 20.220.225.223:55769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/csa.php"] [unique_id "al9NeSn25uliftkV1n4LCgAAAEg"]
[Tue Jul 21 07:44:09.507354 2026] [security2:error] [pid 302018:tid 302166] [client 20.197.195.24:14078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/hosty.php"] [unique_id "al9NeYAs9lPxxVAErz3k8AAAAJU"]
[Tue Jul 21 07:44:09.553856 2026] [security2:error] [pid 302018:tid 302237] [client 117.247.80.59:22500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NeYAs9lPxxVAErz3k8QAAANw"]
[Tue Jul 21 07:44:09.554025 2026] [security2:error] [pid 302018:tid 302237] [client 117.247.80.59:22500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NeYAs9lPxxVAErz3k8QAAANw"]
[Tue Jul 21 07:44:09.581944 2026] [security2:error] [pid 302018:tid 302236] [client 74.249.245.134:54366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/wp-good.php"] [unique_id "al9NeYAs9lPxxVAErz3k8wAAANs"]
[Tue Jul 21 07:44:09.673334 2026] [security2:error] [pid 302018:tid 302059] [remote 119.195.102.159:43778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9NeYAs9lPxxVAErz3k9QAAoyY"]
[Tue Jul 21 07:44:09.742951 2026] [security2:error] [pid 296703:tid 296764] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NeSn25uliftkV1n4LGwAAEjw"]
[Tue Jul 21 07:44:09.743145 2026] [security2:error] [pid 296703:tid 296851] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NeSn25uliftkV1n4LGwAAEjw"]
[Tue Jul 21 07:44:09.870209 2026] [security2:error] [pid 302018:tid 302264] [client 193.36.225.62:21517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NeYAs9lPxxVAErz3k9gAAAPc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:44:09.991016 2026] [security2:error] [pid 302018:tid 302155] [client 20.197.195.24:14053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/k.php"] [unique_id "al9NeYAs9lPxxVAErz3k-wAAAIo"]
[Tue Jul 21 07:44:10.210181 2026] [security2:error] [pid 302018:tid 302252] [client 114.119.136.66:29609] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pacodasrosas.com.br"] [uri "/4gelyphoh.html"] [unique_id "al9NeoAs9lPxxVAErz3k_wAAAOs"], referer: https://pacodasrosas.com.br/4gelyphoh.html
[Tue Jul 21 07:44:10.396692 2026] [security2:error] [pid 296703:tid 296810] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nein25uliftkV1n4LNgAAIGo"]
[Tue Jul 21 07:44:10.396911 2026] [security2:error] [pid 296703:tid 296865] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nein25uliftkV1n4LNgAAIGo"]
[Tue Jul 21 07:44:10.455655 2026] [security2:error] [pid 302018:tid 302234] [client 107.189.14.87:61989] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.northcomm.com.br"] [uri "/"] [unique_id "al9NeoAs9lPxxVAErz3lBAAAANk"]
[Tue Jul 21 07:44:10.524656 2026] [security2:error] [pid 296703:tid 296958] [client 20.104.96.117:30848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/2000.php"] [unique_id "al9Nein25uliftkV1n4LNwAAAH0"]
[Tue Jul 21 07:44:10.531593 2026] [security2:error] [pid 296703:tid 296884] [client 20.197.195.24:13966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/aaa.php"] [unique_id "al9Nein25uliftkV1n4LOQAAADM"]
[Tue Jul 21 07:44:10.556327 2026] [security2:error] [pid 302018:tid 302153] [client 20.220.225.223:60355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/min.php"] [unique_id "al9NeoAs9lPxxVAErz3lBQAAAIg"]
[Tue Jul 21 07:44:10.631319 2026] [security2:error] [pid 296703:tid 296937] [client 20.226.60.151:60108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp.php"] [unique_id "al9Nein25uliftkV1n4LPgAAAGg"]
[Tue Jul 21 07:44:10.673034 2026] [security2:error] [pid 296703:tid 296909] [client 107.189.14.87:62532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.northcomm.com.br"] [uri "/"] [unique_id "al9Nein25uliftkV1n4LPwAAAEw"]
[Tue Jul 21 07:44:10.692640 2026] [security2:error] [pid 302018:tid 302262] [client 20.197.195.24:49869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/177.php"] [unique_id "al9NeoAs9lPxxVAErz3lBgAAAPU"]
[Tue Jul 21 07:44:10.746785 2026] [security2:error] [pid 296703:tid 296847] [client 117.217.38.194:54504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nein25uliftkV1n4LQwAAAA4"]
[Tue Jul 21 07:44:10.746893 2026] [security2:error] [pid 296703:tid 296847] [client 117.217.38.194:54504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nein25uliftkV1n4LQwAAAA4"]
[Tue Jul 21 07:44:10.766193 2026] [security2:error] [pid 302018:tid 302250] [client 154.192.233.199:58981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NeoAs9lPxxVAErz3lCAAAAOk"]
[Tue Jul 21 07:44:10.766313 2026] [security2:error] [pid 302018:tid 302250] [client 154.192.233.199:58981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NeoAs9lPxxVAErz3lCAAAAOk"]
[Tue Jul 21 07:44:10.904113 2026] [security2:error] [pid 296703:tid 296960] [client 20.104.96.117:44284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/11.php"] [unique_id "al9Nein25uliftkV1n4LRwAAAH8"]
[Tue Jul 21 07:44:10.928992 2026] [security2:error] [pid 296703:tid 296840] [client 107.189.14.87:63804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.northcomm.com.br"] [uri "/"] [unique_id "al9Nein25uliftkV1n4LSQAAAAc"]
[Tue Jul 21 07:44:11.275962 2026] [security2:error] [pid 296703:tid 296927] [client 152.59.154.239:58409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Neyn25uliftkV1n4LUAAAAF4"]
[Tue Jul 21 07:44:11.276072 2026] [security2:error] [pid 296703:tid 296927] [client 152.59.154.239:58409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Neyn25uliftkV1n4LUAAAAF4"]
[Tue Jul 21 07:44:11.323025 2026] [security2:error] [pid 302018:tid 302188] [client 202.143.127.214:54428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ne4As9lPxxVAErz3lEQAAAKs"]
[Tue Jul 21 07:44:11.323189 2026] [security2:error] [pid 302018:tid 302188] [client 202.143.127.214:54428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ne4As9lPxxVAErz3lEQAAAKs"]
[Tue Jul 21 07:44:11.375896 2026] [security2:error] [pid 296703:tid 296889] [client 107.189.14.87:64276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.northcomm.com.br"] [uri "/"] [unique_id "al9Neyn25uliftkV1n4LUgAAADg"]
[Tue Jul 21 07:44:11.379116 2026] [security2:error] [pid 296703:tid 296947] [client 74.249.245.134:17433] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/.info.php"] [unique_id "al9Neyn25uliftkV1n4LUwAAAHI"]
[Tue Jul 21 07:44:11.579201 2026] [security2:error] [pid 296703:tid 296872] [client 20.197.195.24:14079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/file5.php"] [unique_id "al9Neyn25uliftkV1n4LWgAAACc"]
[Tue Jul 21 07:44:11.996845 2026] [security2:error] [pid 302018:tid 302229] [client 20.197.195.24:14045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/222.php"] [unique_id "al9Ne4As9lPxxVAErz3lFgAAANQ"]
[Tue Jul 21 07:44:12.180464 2026] [security2:error] [pid 296703:tid 296929] [client 20.197.195.24:13971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/test.php"] [unique_id "al9NfCn25uliftkV1n4LYgAAAGA"]
[Tue Jul 21 07:44:12.255791 2026] [core:alert] [pid 302018:tid 302189] [client 57.141.18.17:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:44:12.366495 2026] [security2:error] [pid 302018:tid 302180] [client 20.220.225.223:53463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/echkm.php"] [unique_id "al9NfIAs9lPxxVAErz3lIQAAAKM"]
[Tue Jul 21 07:44:12.423430 2026] [security2:error] [pid 302018:tid 302196] [client 20.226.60.151:54351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/class.php"] [unique_id "al9NfIAs9lPxxVAErz3lIgAAALM"]
[Tue Jul 21 07:44:12.598831 2026] [security2:error] [pid 302018:tid 302264] [client 20.197.195.24:62672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/aaa.php"] [unique_id "al9NfIAs9lPxxVAErz3lJQAAAPc"]
[Tue Jul 21 07:44:12.911884 2026] [security2:error] [pid 302018:tid 302244] [client 20.104.96.117:44122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/mac.php"] [unique_id "al9NfIAs9lPxxVAErz3lKQAAAOM"]
[Tue Jul 21 07:44:12.963719 2026] [security2:error] [pid 302018:tid 302192] [client 20.197.195.24:13973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/11.php"] [unique_id "al9NfIAs9lPxxVAErz3lKgAAAK8"]
[Tue Jul 21 07:44:13.123519 2026] [security2:error] [pid 296703:tid 296865] [client 20.104.96.117:30904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/122.php"] [unique_id "al9NfSn25uliftkV1n4LcAAAACA"]
[Tue Jul 21 07:44:13.155347 2026] [security2:error] [pid 302018:tid 302249] [client 20.220.225.223:60372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/mac.php"] [unique_id "al9NfYAs9lPxxVAErz3lLQAAAOg"]
[Tue Jul 21 07:44:13.192089 2026] [security2:error] [pid 302018:tid 302078] [remote 104.207.54.116:59913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.54.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NfYAs9lPxxVAErz3lLwABAjk"]
[Tue Jul 21 07:44:13.248876 2026] [security2:error] [pid 302018:tid 302070] [remote 209.42.18.223:56928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NfIAs9lPxxVAErz3lHAAA7TE"]
[Tue Jul 21 07:44:13.517803 2026] [security2:error] [pid 296703:tid 296853] [client 20.197.195.24:14012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/mac.php"] [unique_id "al9NfSn25uliftkV1n4LdgAAABQ"]
[Tue Jul 21 07:44:13.642683 2026] [security2:error] [pid 302018:tid 302263] [client 41.68.90.219:63575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NfYAs9lPxxVAErz3lNAAAAPY"]
[Tue Jul 21 07:44:13.643540 2026] [security2:error] [pid 302018:tid 302263] [client 41.68.90.219:63575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NfYAs9lPxxVAErz3lNAAAAPY"]
[Tue Jul 21 07:44:13.689379 2026] [security2:error] [pid 302018:tid 302081] [remote 104.207.46.86:13157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.46.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NfYAs9lPxxVAErz3lNgAA6Tw"]
[Tue Jul 21 07:44:13.905290 2026] [security2:error] [pid 302018:tid 302229] [client 20.220.225.223:53503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/samll.php"] [unique_id "al9NfYAs9lPxxVAErz3lPQAAANQ"]
[Tue Jul 21 07:44:13.918537 2026] [security2:error] [pid 302018:tid 302183] [client 20.197.195.24:62659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/chosen.php"] [unique_id "al9NfYAs9lPxxVAErz3lPgAAAKY"]
[Tue Jul 21 07:44:14.095012 2026] [security2:error] [pid 302018:tid 302186] [client 20.197.195.24:62668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/cream1.php"] [unique_id "al9NfoAs9lPxxVAErz3lQQAAAKk"]
[Tue Jul 21 07:44:14.209516 2026] [security2:error] [pid 302018:tid 302219] [client 20.226.60.151:54353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/echkm.php"] [unique_id "al9NfoAs9lPxxVAErz3lRgAAAMo"]
[Tue Jul 21 07:44:14.220130 2026] [security2:error] [pid 302018:tid 302276] [client 139.167.225.182:56039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NfoAs9lPxxVAErz3lRwAAAQM"]
[Tue Jul 21 07:44:14.220249 2026] [security2:error] [pid 302018:tid 302276] [client 139.167.225.182:56039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NfoAs9lPxxVAErz3lRwAAAQM"]
[Tue Jul 21 07:44:14.223948 2026] [security2:error] [pid 296703:tid 296890] [client 122.162.144.145:32367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Nfin25uliftkV1n4LgAAAADk"]
[Tue Jul 21 07:44:14.224041 2026] [security2:error] [pid 296703:tid 296890] [client 122.162.144.145:32367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Nfin25uliftkV1n4LgAAAADk"]
[Tue Jul 21 07:44:14.473933 2026] [security2:error] [pid 296703:tid 296835] [client 136.144.33.110:63991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Nfin25uliftkV1n4LhAAAAAI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:44:14.584310 2026] [security2:error] [pid 302018:tid 302169] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9NfoAs9lPxxVAErz3lbAAAmGc"]
[Tue Jul 21 07:44:14.622074 2026] [security2:error] [pid 302018:tid 302151] [client 103.29.114.44:46895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NfoAs9lPxxVAErz3lbQAAAIY"]
[Tue Jul 21 07:44:14.622192 2026] [security2:error] [pid 302018:tid 302151] [client 103.29.114.44:46895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NfoAs9lPxxVAErz3lbQAAAIY"]
[Tue Jul 21 07:44:14.647842 2026] [security2:error] [pid 296703:tid 296913] [client 62.102.148.187:45142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Nfin25uliftkV1n4LiwAAAFA"]
[Tue Jul 21 07:44:14.647956 2026] [security2:error] [pid 296703:tid 296913] [client 62.102.148.187:45142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Nfin25uliftkV1n4LiwAAAFA"]
[Tue Jul 21 07:44:14.731601 2026] [security2:error] [pid 296703:tid 296927] [client 20.104.96.117:44246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/chosen.php"] [unique_id "al9Nfin25uliftkV1n4LjAAAAF4"]
[Tue Jul 21 07:44:14.985328 2026] [security2:error] [pid 302018:tid 302202] [client 20.220.225.223:34275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/nhvoanpl.php"] [unique_id "al9NfoAs9lPxxVAErz3legAAALk"]
[Tue Jul 21 07:44:15.016232 2026] [security2:error] [pid 302018:tid 302138] [remote 4.205.168.44:40760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-login.php"] [unique_id "al9Nf4As9lPxxVAErz3lewAAwHU"]
[Tue Jul 21 07:44:15.022040 2026] [security2:error] [pid 302018:tid 302179] [client 20.197.195.24:13819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/config.php"] [unique_id "al9Nf4As9lPxxVAErz3lfAAAAKI"]
[Tue Jul 21 07:44:15.132491 2026] [security2:error] [pid 302018:tid 302262] [client 74.249.245.134:5516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/item.php"] [unique_id "al9Nf4As9lPxxVAErz3lfgAAAPU"]
[Tue Jul 21 07:44:15.245647 2026] [security2:error] [pid 302018:tid 302270] [client 173.24.185.52:59787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Nf4As9lPxxVAErz3lgQAAAP0"]
[Tue Jul 21 07:44:15.245779 2026] [security2:error] [pid 302018:tid 302270] [client 173.24.185.52:59787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Nf4As9lPxxVAErz3lgQAAAP0"]
[Tue Jul 21 07:44:15.269496 2026] [security2:error] [pid 302018:tid 302154] [client 20.104.96.117:30422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/mds.php"] [unique_id "al9Nf4As9lPxxVAErz3lggAAAIk"]
[Tue Jul 21 07:44:15.296551 2026] [security2:error] [pid 302018:tid 302191] [client 184.75.223.211:41082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Nf4As9lPxxVAErz3lhAAAAK4"]
[Tue Jul 21 07:44:15.296634 2026] [security2:error] [pid 302018:tid 302191] [client 184.75.223.211:41082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Nf4As9lPxxVAErz3lhAAAAK4"]
[Tue Jul 21 07:44:15.357925 2026] [security2:error] [pid 302018:tid 302268] [client 20.197.195.24:14070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/dr.php"] [unique_id "al9Nf4As9lPxxVAErz3lhgAAAPs"]
[Tue Jul 21 07:44:15.468044 2026] [security2:error] [pid 302018:tid 302141] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nf4As9lPxxVAErz3liAAA-Hg"]
[Tue Jul 21 07:44:15.468164 2026] [security2:error] [pid 302018:tid 302265] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nf4As9lPxxVAErz3liAAA-Hg"]
[Tue Jul 21 07:44:15.626615 2026] [security2:error] [pid 296703:tid 296955] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fortenegociosimobiliarios.net.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Nfyn25uliftkV1n4LogAAAHo"]
[Tue Jul 21 07:44:15.700362 2026] [security2:error] [pid 302018:tid 302207] [client 20.197.195.24:62613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/x.php"] [unique_id "al9Nf4As9lPxxVAErz3lkQAAAL4"]
[Tue Jul 21 07:44:15.779831 2026] [security2:error] [pid 302018:tid 302196] [client 20.220.225.223:34209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/inso.php"] [unique_id "al9Nf4As9lPxxVAErz3llAAAALM"]
[Tue Jul 21 07:44:15.792187 2026] [security2:error] [pid 302018:tid 302258] [client 20.197.195.24:14058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/155.php"] [unique_id "al9Nf4As9lPxxVAErz3llQAAAPE"]
[Tue Jul 21 07:44:15.832084 2026] [security2:error] [pid 302018:tid 302161] [client 20.197.195.24:13990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/ops.php"] [unique_id "al9Nf4As9lPxxVAErz3lmAAAAJA"]
[Tue Jul 21 07:44:15.852546 2026] [security2:error] [pid 302018:tid 302211] [client 20.220.225.223:60361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/abcd.php"] [unique_id "al9Nf4As9lPxxVAErz3lmgAAAMI"]
[Tue Jul 21 07:44:15.902544 2026] [security2:error] [pid 296703:tid 296865] [client 20.197.195.24:62705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/file31.php"] [unique_id "al9Nfyn25uliftkV1n4LsAAAACA"]
[Tue Jul 21 07:44:15.943230 2026] [security2:error] [pid 302018:tid 302162] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fortenegociosimobiliarios.net.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Nf4As9lPxxVAErz3lnwAAAJE"]
[Tue Jul 21 07:44:16.046642 2026] [security2:error] [pid 296703:tid 296909] [client 20.197.195.24:13698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/gettest.php"] [unique_id "al9NgCn25uliftkV1n4LtwAAAEw"]
[Tue Jul 21 07:44:16.053874 2026] [security2:error] [pid 296703:tid 296837] [client 20.197.195.24:14067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/file6.php"] [unique_id "al9NgCn25uliftkV1n4LuAAAAAQ"]
[Tue Jul 21 07:44:16.155571 2026] [security2:error] [pid 302018:tid 302184] [client 20.197.195.24:62716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/adminfuns.php"] [unique_id "al9NgIAs9lPxxVAErz3lqgAAAKc"]
[Tue Jul 21 07:44:16.184171 2026] [security2:error] [pid 302018:tid 302179] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fortenegociosimobiliarios.net.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NgIAs9lPxxVAErz3lqwAAAKI"]
[Tue Jul 21 07:44:16.360414 2026] [security2:error] [pid 302018:tid 302181] [client 194.99.104.35:57686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NgIAs9lPxxVAErz3lrQAAAKQ"]
[Tue Jul 21 07:44:16.360506 2026] [security2:error] [pid 302018:tid 302181] [client 194.99.104.35:57686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NgIAs9lPxxVAErz3lrQAAAKQ"]
[Tue Jul 21 07:44:16.377216 2026] [security2:error] [pid 302018:tid 302145] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NgIAs9lPxxVAErz3lrgAAl3w"]
[Tue Jul 21 07:44:16.377338 2026] [security2:error] [pid 302018:tid 302168] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NgIAs9lPxxVAErz3lrgAAl3w"]
[Tue Jul 21 07:44:16.403100 2026] [security2:error] [pid 302018:tid 302270] [client 20.226.60.151:54283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/lib.php"] [unique_id "al9NgIAs9lPxxVAErz3lrwAAAP0"]
[Tue Jul 21 07:44:16.425467 2026] [security2:error] [pid 302018:tid 302277] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fortenegociosimobiliarios.net.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NgIAs9lPxxVAErz3lsAAAAQQ"]
[Tue Jul 21 07:44:16.425551 2026] [security2:error] [pid 302018:tid 302154] [client 20.197.195.24:14016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/goods.php"] [unique_id "al9NgIAs9lPxxVAErz3lsQAAAIk"]
[Tue Jul 21 07:44:16.429365 2026] [security2:error] [pid 302018:tid 302157] [client 103.166.103.129:13433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NgIAs9lPxxVAErz3lsgAAAIw"]
[Tue Jul 21 07:44:16.429443 2026] [security2:error] [pid 302018:tid 302157] [client 103.166.103.129:13433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NgIAs9lPxxVAErz3lsgAAAIw"]
[Tue Jul 21 07:44:16.641221 2026] [security2:error] [pid 302018:tid 302231] [client 74.249.245.134:17429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/albin.php"] [unique_id "al9NgIAs9lPxxVAErz3ltQAAANY"]
[Tue Jul 21 07:44:16.720166 2026] [security2:error] [pid 302018:tid 302215] [client 20.197.195.24:14007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/100.php"] [unique_id "al9NgIAs9lPxxVAErz3lvAAAAMY"]
[Tue Jul 21 07:44:16.731573 2026] [security2:error] [pid 302018:tid 302250] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fortenegociosimobiliarios.net.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9NgIAs9lPxxVAErz3lvQAAAOk"]
[Tue Jul 21 07:44:16.968301 2026] [security2:error] [pid 302018:tid 302207] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fortenegociosimobiliarios.net.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NgIAs9lPxxVAErz3l2QAAAL4"]
[Tue Jul 21 07:44:16.994647 2026] [security2:error] [pid 296703:tid 296858] [client 20.197.195.24:13700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/min.php"] [unique_id "al9NgCn25uliftkV1n4LyQAAABk"]
[Tue Jul 21 07:44:17.083325 2026] [security2:error] [pid 302018:tid 302247] [client 20.197.195.24:62688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/about.php"] [unique_id "al9NgYAs9lPxxVAErz3l2wAAAOY"]
[Tue Jul 21 07:44:17.216966 2026] [security2:error] [pid 302018:tid 302257] [client 20.197.195.24:14001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/about.php"] [unique_id "al9NgYAs9lPxxVAErz3l4wAAAPA"]
[Tue Jul 21 07:44:17.217847 2026] [security2:error] [pid 296703:tid 296866] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fortenegociosimobiliarios.net.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9NgSn25uliftkV1n4LzQAAACE"]
[Tue Jul 21 07:44:17.418372 2026] [security2:error] [pid 302018:tid 302243] [client 20.104.96.117:30891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-blink.php"] [unique_id "al9NgYAs9lPxxVAErz3l5AAAAOI"]
[Tue Jul 21 07:44:17.463764 2026] [security2:error] [pid 302018:tid 302269] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fortenegociosimobiliarios.net.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NgYAs9lPxxVAErz3l5QAAAPw"]
[Tue Jul 21 07:44:17.497902 2026] [security2:error] [pid 296703:tid 296936] [client 193.36.225.141:52323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NgCn25uliftkV1n4LvAAAAGc"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:44:17.550176 2026] [security2:error] [pid 296703:tid 296868] [client 20.104.96.117:44236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/cream1.php"] [unique_id "al9NgSn25uliftkV1n4L0gAAACM"]
[Tue Jul 21 07:44:17.574734 2026] [security2:error] [pid 302018:tid 302248] [client 182.8.255.181:17691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NgYAs9lPxxVAErz3l5gAAAOc"]
[Tue Jul 21 07:44:17.574836 2026] [security2:error] [pid 302018:tid 302248] [client 182.8.255.181:17691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NgYAs9lPxxVAErz3l5gAAAOc"]
[Tue Jul 21 07:44:17.639523 2026] [security2:error] [pid 296703:tid 296893] [client 20.197.195.24:14042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/admin.php"] [unique_id "al9NgSn25uliftkV1n4L1QAAADw"]
[Tue Jul 21 07:44:17.784915 2026] [security2:error] [pid 296703:tid 296889] [client 106.215.181.8:26360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NgSn25uliftkV1n4L2QAAADg"]
[Tue Jul 21 07:44:17.785032 2026] [security2:error] [pid 296703:tid 296889] [client 106.215.181.8:26360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NgSn25uliftkV1n4L2QAAADg"]
[Tue Jul 21 07:44:17.785669 2026] [security2:error] [pid 302018:tid 302242] [client 178.153.91.96:8659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NgYAs9lPxxVAErz3l6AAAAOE"]
[Tue Jul 21 07:44:17.785747 2026] [security2:error] [pid 302018:tid 302242] [client 178.153.91.96:8659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NgYAs9lPxxVAErz3l6AAAAOE"]
[Tue Jul 21 07:44:17.787293 2026] [security2:error] [pid 302018:tid 302242] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fortenegociosimobiliarios.net.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NgYAs9lPxxVAErz3l6QAAAOE"]
[Tue Jul 21 07:44:17.834171 2026] [security2:error] [pid 302018:tid 302052] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NgYAs9lPxxVAErz3l6gAApx8"]
[Tue Jul 21 07:44:17.834316 2026] [security2:error] [pid 302018:tid 302184] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NgYAs9lPxxVAErz3l6gAApx8"]
[Tue Jul 21 07:44:17.889574 2026] [security2:error] [pid 302018:tid 302266] [client 103.174.34.15:61014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NgYAs9lPxxVAErz3l7AAAAPk"]
[Tue Jul 21 07:44:17.889661 2026] [security2:error] [pid 302018:tid 302266] [client 103.174.34.15:61014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NgYAs9lPxxVAErz3l7AAAAPk"]
[Tue Jul 21 07:44:17.892318 2026] [security2:error] [pid 302018:tid 302054] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "al9NgYAs9lPxxVAErz3l7QAAuSE"]
[Tue Jul 21 07:44:18.028292 2026] [security2:error] [pid 296703:tid 296908] [client 20.197.195.24:13976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/admin.php"] [unique_id "al9Ngin25uliftkV1n4L3wAAAEs"]
[Tue Jul 21 07:44:18.029259 2026] [security2:error] [pid 302018:tid 302254] [client 122.179.91.63:6146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NgoAs9lPxxVAErz3l7wAAAO0"]
[Tue Jul 21 07:44:18.029399 2026] [security2:error] [pid 302018:tid 302254] [client 122.179.91.63:6146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NgoAs9lPxxVAErz3l7wAAAO0"]
[Tue Jul 21 07:44:18.120763 2026] [security2:error] [pid 296703:tid 296953] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fortenegociosimobiliarios.net.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Ngin25uliftkV1n4L4AAAAHg"]
[Tue Jul 21 07:44:18.139032 2026] [security2:error] [pid 296703:tid 296863] [client 20.220.225.223:53482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/xyn.php"] [unique_id "al9Ngin25uliftkV1n4L4QAAAB4"]
[Tue Jul 21 07:44:18.256700 2026] [security2:error] [pid 296703:tid 296957] [client 20.197.195.24:49888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/dvjul.php"] [unique_id "al9Ngin25uliftkV1n4L4gAAAHw"]
[Tue Jul 21 07:44:18.280455 2026] [security2:error] [pid 296703:tid 296925] [client 103.86.117.203:58889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ngin25uliftkV1n4L5AAAAFw"]
[Tue Jul 21 07:44:18.280572 2026] [security2:error] [pid 296703:tid 296925] [client 103.86.117.203:58889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ngin25uliftkV1n4L5AAAAFw"]
[Tue Jul 21 07:44:18.294628 2026] [security2:error] [pid 302018:tid 302270] [client 20.197.195.24:13963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/themes.php"] [unique_id "al9NgoAs9lPxxVAErz3l8QAAAP0"]
[Tue Jul 21 07:44:18.401724 2026] [security2:error] [pid 296703:tid 296918] [client 20.197.195.24:62614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/.well-known/about.php"] [unique_id "al9Ngin25uliftkV1n4L7AAAAFU"]
[Tue Jul 21 07:44:18.458563 2026] [security2:error] [pid 302018:tid 302191] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fortenegociosimobiliarios.net.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NgoAs9lPxxVAErz3l9AAAAK4"]
[Tue Jul 21 07:44:18.468601 2026] [security2:error] [pid 302018:tid 302055] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NgoAs9lPxxVAErz3l9QAAlyI"]
[Tue Jul 21 07:44:18.468722 2026] [security2:error] [pid 302018:tid 302168] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NgoAs9lPxxVAErz3l9QAAlyI"]
[Tue Jul 21 07:44:18.651416 2026] [security2:error] [pid 302018:tid 302212] [client 193.36.225.67:35351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NgoAs9lPxxVAErz3l9wAAAMM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:44:18.658704 2026] [security2:error] [pid 302018:tid 302231] [client 20.104.96.117:30428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/zc-208.php"] [unique_id "al9NgoAs9lPxxVAErz3l-AAAANY"]
[Tue Jul 21 07:44:18.671466 2026] [security2:error] [pid 296703:tid 296817] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ngin25uliftkV1n4L8gAAIHE"]
[Tue Jul 21 07:44:18.671655 2026] [security2:error] [pid 296703:tid 296865] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ngin25uliftkV1n4L8gAAIHE"]
[Tue Jul 21 07:44:18.705916 2026] [security2:error] [pid 302018:tid 302263] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fortenegociosimobiliarios.net.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NgoAs9lPxxVAErz3l-QAAAPY"]
[Tue Jul 21 07:44:18.723640 2026] [security2:error] [pid 302018:tid 302188] [client 20.197.195.24:62662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9NgoAs9lPxxVAErz3l-wAAAKs"]
[Tue Jul 21 07:44:19.136615 2026] [security2:error] [pid 296703:tid 296960] [client 20.197.195.24:14036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/wefile.php"] [unique_id "al9Ngyn25uliftkV1n4L_AAAAH8"]
[Tue Jul 21 07:44:19.237767 2026] [security2:error] [pid 296703:tid 296869] [client 122.164.127.47:60342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Ngyn25uliftkV1n4L_QAAACQ"]
[Tue Jul 21 07:44:19.237886 2026] [security2:error] [pid 296703:tid 296869] [client 122.164.127.47:60342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Ngyn25uliftkV1n4L_QAAACQ"]
[Tue Jul 21 07:44:19.330001 2026] [security2:error] [pid 302018:tid 302186] [client 20.197.195.24:13740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/biufile.php"] [unique_id "al9Ng4As9lPxxVAErz3mBQAAAKk"]
[Tue Jul 21 07:44:19.365430 2026] [security2:error] [pid 302018:tid 302247] [client 20.104.96.117:30438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/sid4.php"] [unique_id "al9Ng4As9lPxxVAErz3mBgAAAOY"]
[Tue Jul 21 07:44:19.446360 2026] [security2:error] [pid 302018:tid 302258] [client 74.249.245.134:5553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/alfa.php"] [unique_id "al9Ng4As9lPxxVAErz3mCQAAAPE"]
[Tue Jul 21 07:44:19.477225 2026] [security2:error] [pid 302018:tid 302219] [client 20.226.60.151:54313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/login.php"] [unique_id "al9Ng4As9lPxxVAErz3mCgAAAMo"]
[Tue Jul 21 07:44:19.508782 2026] [autoindex:error] [pid 302018:tid 302161] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/blissf00/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:44:19.707705 2026] [security2:error] [pid 296703:tid 296858] [client 20.220.225.223:60366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/byp8.php"] [unique_id "al9Ngyn25uliftkV1n4MBAAAABk"]
[Tue Jul 21 07:44:19.812647 2026] [security2:error] [pid 296703:tid 296915] [client 122.186.204.214:61727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ngyn25uliftkV1n4MBwAAAFI"]
[Tue Jul 21 07:44:19.812736 2026] [security2:error] [pid 296703:tid 296915] [client 122.186.204.214:61727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ngyn25uliftkV1n4MBwAAAFI"]
[Tue Jul 21 07:44:19.831112 2026] [autoindex:error] [pid 302018:tid 302169] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/blissf00/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:44:19.874634 2026] [security2:error] [pid 302018:tid 302267] [client 20.197.195.24:49874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/av.php"] [unique_id "al9Ng4As9lPxxVAErz3mFgAAAPo"]
[Tue Jul 21 07:44:19.901723 2026] [security2:error] [pid 302018:tid 302192] [client 20.220.225.223:34210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wpx.php"] [unique_id "al9Ng4As9lPxxVAErz3mFwAAAK8"]
[Tue Jul 21 07:44:19.925725 2026] [security2:error] [pid 296703:tid 296866] [client 20.197.195.24:62671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9Ngyn25uliftkV1n4MCAAAACE"]
[Tue Jul 21 07:44:19.985293 2026] [security2:error] [pid 302018:tid 302061] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al9Ng4As9lPxxVAErz3mGQAAnSg"]
[Tue Jul 21 07:44:19.986291 2026] [security2:error] [pid 302018:tid 302184] [client 20.104.96.117:44230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/dr.php"] [unique_id "al9Ng4As9lPxxVAErz3mGgAAAKc"]
[Tue Jul 21 07:44:20.080594 2026] [security2:error] [pid 302018:tid 302160] [client 117.251.86.144:33202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NhIAs9lPxxVAErz3mHgAAAI8"]
[Tue Jul 21 07:44:20.080699 2026] [security2:error] [pid 302018:tid 302160] [client 117.251.86.144:33202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NhIAs9lPxxVAErz3mHgAAAI8"]
[Tue Jul 21 07:44:20.194227 2026] [security2:error] [pid 302018:tid 302155] [client 117.247.80.59:22808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NhIAs9lPxxVAErz3mLAAAAIo"]
[Tue Jul 21 07:44:20.194331 2026] [security2:error] [pid 302018:tid 302155] [client 117.247.80.59:22808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NhIAs9lPxxVAErz3mLAAAAIo"]
[Tue Jul 21 07:44:20.249569 2026] [security2:error] [pid 302018:tid 302168] [client 20.197.195.24:13800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/coffexium.php"] [unique_id "al9NhIAs9lPxxVAErz3mPQAAAJc"]
[Tue Jul 21 07:44:20.297140 2026] [security2:error] [pid 302018:tid 302094] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NhIAs9lPxxVAErz3mPgAA-Uk"]
[Tue Jul 21 07:44:20.297284 2026] [security2:error] [pid 302018:tid 302266] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NhIAs9lPxxVAErz3mPgAA-Uk"]
[Tue Jul 21 07:44:20.430224 2026] [security2:error] [pid 302018:tid 302158] [client 20.104.96.117:30402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wmore1.php"] [unique_id "al9NhIAs9lPxxVAErz3mQAAAAI0"]
[Tue Jul 21 07:44:20.704067 2026] [security2:error] [pid 302018:tid 302265] [client 193.36.225.103:51571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NhIAs9lPxxVAErz3mQgAAAPg"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:44:20.819654 2026] [security2:error] [pid 302018:tid 302170] [client 20.197.195.24:62689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9NhIAs9lPxxVAErz3mTgAAAJk"]
[Tue Jul 21 07:44:20.993153 2026] [security2:error] [pid 296703:tid 296833] [client 20.226.60.151:61972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/a2.php"] [unique_id "al9NhCn25uliftkV1n4MKQAAAAA"]
[Tue Jul 21 07:44:21.028441 2026] [security2:error] [pid 302018:tid 302152] [client 20.197.195.24:49895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/core.php"] [unique_id "al9NhYAs9lPxxVAErz3mVAAAAIc"]
[Tue Jul 21 07:44:21.212443 2026] [security2:error] [pid 302018:tid 302260] [client 117.217.38.194:54993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NhYAs9lPxxVAErz3mWAAAAPM"]
[Tue Jul 21 07:44:21.212774 2026] [security2:error] [pid 302018:tid 302260] [client 117.217.38.194:54993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NhYAs9lPxxVAErz3mWAAAAPM"]
[Tue Jul 21 07:44:21.407613 2026] [security2:error] [pid 302018:tid 302247] [client 154.192.233.199:59795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NhYAs9lPxxVAErz3mYQAAAOY"]
[Tue Jul 21 07:44:21.407804 2026] [security2:error] [pid 302018:tid 302247] [client 154.192.233.199:59795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NhYAs9lPxxVAErz3mYQAAAOY"]
[Tue Jul 21 07:44:21.439699 2026] [security2:error] [pid 302018:tid 302110] [remote 151.123.176.97:59017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.176.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9NhYAs9lPxxVAErz3mYgAAr1k"]
[Tue Jul 21 07:44:21.442479 2026] [security2:error] [pid 296703:tid 296802] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NhSn25uliftkV1n4MXAAAMmI"]
[Tue Jul 21 07:44:21.442639 2026] [security2:error] [pid 296703:tid 296883] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NhSn25uliftkV1n4MXAAAMmI"]
[Tue Jul 21 07:44:21.467474 2026] [security2:error] [pid 296703:tid 296838] [client 20.197.195.24:13967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/8.php"] [unique_id "al9NhSn25uliftkV1n4MXQAAAAU"]
[Tue Jul 21 07:44:21.564224 2026] [security2:error] [pid 302018:tid 302155] [client 20.104.96.117:30896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/solo1.php"] [unique_id "al9NhYAs9lPxxVAErz3mZwAAAIo"]
[Tue Jul 21 07:44:21.575167 2026] [security2:error] [pid 302018:tid 302168] [client 20.197.195.24:13964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/wp-content/admin.php"] [unique_id "al9NhYAs9lPxxVAErz3maAAAAJc"]
[Tue Jul 21 07:44:21.671134 2026] [security2:error] [pid 302018:tid 302214] [client 20.220.225.223:34177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/berlin.php"] [unique_id "al9NhYAs9lPxxVAErz3magAAAMU"]
[Tue Jul 21 07:44:21.777530 2026] [security2:error] [pid 302018:tid 302215] [client 20.197.195.24:62657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/f6.php"] [unique_id "al9NhYAs9lPxxVAErz3mbAAAAMY"]
[Tue Jul 21 07:44:21.790407 2026] [security2:error] [pid 302018:tid 302208] [client 20.104.96.117:44099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/x.php"] [unique_id "al9NhYAs9lPxxVAErz3mbQAAAL8"]
[Tue Jul 21 07:44:21.860826 2026] [security2:error] [pid 296703:tid 296896] [client 20.197.195.24:49820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/als.php"] [unique_id "al9NhSn25uliftkV1n4MYwAAAD8"]
[Tue Jul 21 07:44:21.928726 2026] [security2:error] [pid 302018:tid 302112] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "al9NhYAs9lPxxVAErz3mbgAA11s"]
[Tue Jul 21 07:44:22.084713 2026] [security2:error] [pid 302018:tid 302196] [client 74.249.245.134:54390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/autoload_classmap.php"] [unique_id "al9NhoAs9lPxxVAErz3mcgAAALM"]
[Tue Jul 21 07:44:22.124276 2026] [security2:error] [pid 302018:tid 302106] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "al9NhoAs9lPxxVAErz3mcwAAx1U"]
[Tue Jul 21 07:44:22.140601 2026] [security2:error] [pid 302018:tid 302237] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NhoAs9lPxxVAErz3mdAAAANw"]
[Tue Jul 21 07:44:22.163080 2026] [security2:error] [pid 296703:tid 296853] [client 20.197.195.24:14068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/inputs.php"] [unique_id "al9Nhin25uliftkV1n4MZgAAABQ"]
[Tue Jul 21 07:44:22.353181 2026] [security2:error] [pid 296703:tid 296862] [client 202.143.127.214:54847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nhin25uliftkV1n4MbQAAAB0"]
[Tue Jul 21 07:44:22.353315 2026] [security2:error] [pid 296703:tid 296862] [client 202.143.127.214:54847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nhin25uliftkV1n4MbQAAAB0"]
[Tue Jul 21 07:44:22.419839 2026] [security2:error] [pid 296703:tid 296915] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Nhin25uliftkV1n4McAAAAFI"]
[Tue Jul 21 07:44:22.484025 2026] [security2:error] [pid 302018:tid 302211] [client 20.197.195.24:13980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/inputs.php"] [unique_id "al9NhoAs9lPxxVAErz3mewAAAMI"]
[Tue Jul 21 07:44:22.506264 2026] [security2:error] [pid 296703:tid 296900] [client 20.197.195.24:13791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/simple.php"] [unique_id "al9Nhin25uliftkV1n4MdAAAAEM"]
[Tue Jul 21 07:44:22.547383 2026] [security2:error] [pid 296703:tid 296876] [client 20.220.225.223:27136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/user.php"] [unique_id "al9Nhin25uliftkV1n4MdgAAACs"]
[Tue Jul 21 07:44:22.606850 2026] [security2:error] [pid 296703:tid 296888] [client 20.197.195.24:14013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/classwithtostring.php"] [unique_id "al9Nhin25uliftkV1n4MeAAAADc"]
[Tue Jul 21 07:44:22.654307 2026] [security2:error] [pid 296703:tid 296886] [client 20.220.225.223:34196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/billur.php"] [unique_id "al9Nhin25uliftkV1n4MewAAADU"]
[Tue Jul 21 07:44:22.664361 2026] [security2:error] [pid 302018:tid 302210] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NhoAs9lPxxVAErz3mfgAAAME"]
[Tue Jul 21 07:44:22.748782 2026] [security2:error] [pid 302018:tid 302101] [remote 57.141.18.22:51698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9NhoAs9lPxxVAErz3mgAAAslA"]
[Tue Jul 21 07:44:22.856338 2026] [security2:error] [pid 296703:tid 296870] [client 152.59.154.239:58930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nhin25uliftkV1n4MfgAAACU"]
[Tue Jul 21 07:44:22.856435 2026] [security2:error] [pid 296703:tid 296870] [client 152.59.154.239:58930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nhin25uliftkV1n4MfgAAACU"]
[Tue Jul 21 07:44:22.871624 2026] [security2:error] [pid 296703:tid 296839] [client 20.104.96.117:44287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/155.php"] [unique_id "al9Nhin25uliftkV1n4MfwAAAAY"]
[Tue Jul 21 07:44:22.909923 2026] [security2:error] [pid 296703:tid 296877] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Nhin25uliftkV1n4MggAAACw"]
[Tue Jul 21 07:44:22.929184 2026] [security2:error] [pid 302018:tid 302252] [client 20.197.195.24:62695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9NhoAs9lPxxVAErz3mgQAAAOs"]
[Tue Jul 21 07:44:22.984926 2026] [security2:error] [pid 302018:tid 302164] [client 20.197.195.24:14033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/wp-blog.php"] [unique_id "al9NhoAs9lPxxVAErz3mhAAAAJM"]
[Tue Jul 21 07:44:23.046003 2026] [security2:error] [pid 296703:tid 296912] [client 20.197.195.24:62668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/wp-content/admin.php"] [unique_id "al9Nhyn25uliftkV1n4MhgAAAE8"]
[Tue Jul 21 07:44:23.075171 2026] [security2:error] [pid 302018:tid 302267] [client 20.197.195.24:14040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/ms-edit.php"] [unique_id "al9Nh4As9lPxxVAErz3mhgAAAPo"]
[Tue Jul 21 07:44:23.157991 2026] [security2:error] [pid 302018:tid 302260] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Nh4As9lPxxVAErz3miAAAAPM"]
[Tue Jul 21 07:44:23.179279 2026] [security2:error] [pid 302018:tid 302245] [client 20.220.225.223:34295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/mimpi.php"] [unique_id "al9Nh4As9lPxxVAErz3miQAAAOQ"]
[Tue Jul 21 07:44:23.181841 2026] [security2:error] [pid 302018:tid 302254] [client 20.197.195.24:14075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/cgi-bin/index.php"] [unique_id "al9Nh4As9lPxxVAErz3migAAAO0"]
[Tue Jul 21 07:44:23.211309 2026] [security2:error] [pid 296703:tid 296846] [client 20.104.96.117:30603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/cong.php"] [unique_id "al9Nhyn25uliftkV1n4MiQAAAA0"]
[Tue Jul 21 07:44:23.306998 2026] [security2:error] [pid 302018:tid 302255] [client 20.226.60.151:62012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/d61.php"] [unique_id "al9Nh4As9lPxxVAErz3mjAAAAO4"]
[Tue Jul 21 07:44:23.344294 2026] [security2:error] [pid 296703:tid 296834] [client 20.197.195.24:13956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/BDKR28WP.php"] [unique_id "al9Nhyn25uliftkV1n4MjwAAAAE"]
[Tue Jul 21 07:44:23.477267 2026] [security2:error] [pid 302018:tid 302264] [client 59.96.220.140:63198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Nh4As9lPxxVAErz3mkgAAAPc"]
[Tue Jul 21 07:44:23.477384 2026] [security2:error] [pid 302018:tid 302264] [client 59.96.220.140:63198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Nh4As9lPxxVAErz3mkgAAAPc"]
[Tue Jul 21 07:44:23.480090 2026] [security2:error] [pid 296703:tid 296917] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Nhyn25uliftkV1n4MkQAAAFQ"]
[Tue Jul 21 07:44:23.553930 2026] [security2:error] [pid 302018:tid 302168] [client 20.197.195.24:13957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/abcd.php"] [unique_id "al9Nh4As9lPxxVAErz3mkwAAAJc"]
[Tue Jul 21 07:44:23.826092 2026] [security2:error] [pid 302018:tid 302247] [client 193.36.225.121:26679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Nh4As9lPxxVAErz3mlAAAAOY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:44:23.846632 2026] [security2:error] [pid 302018:tid 302215] [client 20.220.225.223:60352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/ops.php"] [unique_id "al9Nh4As9lPxxVAErz3mnQAAAMY"]
[Tue Jul 21 07:44:23.853607 2026] [security2:error] [pid 302018:tid 302256] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Nh4As9lPxxVAErz3mngAAAO8"]
[Tue Jul 21 07:44:23.882570 2026] [security2:error] [pid 302018:tid 302154] [client 136.144.33.97:28355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NhoAs9lPxxVAErz3mfwAAAIk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:44:23.931013 2026] [security2:error] [pid 296703:tid 296940] [client 20.197.195.24:62631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/file15.php"] [unique_id "al9Nhyn25uliftkV1n4MmgAAAGs"]
[Tue Jul 21 07:44:23.996238 2026] [security2:error] [pid 302018:tid 302207] [client 20.226.60.151:61969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/info.php"] [unique_id "al9Nh4As9lPxxVAErz3mogAAAL4"]
[Tue Jul 21 07:44:24.028554 2026] [security2:error] [pid 302018:tid 302243] [client 20.197.195.24:14074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/jp.php"] [unique_id "al9NiIAs9lPxxVAErz3mowAAAOI"]
[Tue Jul 21 07:44:24.098052 2026] [security2:error] [pid 302018:tid 302258] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NiIAs9lPxxVAErz3mpgAAAPE"]
[Tue Jul 21 07:44:24.232837 2026] [security2:error] [pid 302018:tid 302211] [client 20.197.195.24:14069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/f35.php"] [unique_id "al9NiIAs9lPxxVAErz3mqgAAAMI"]
[Tue Jul 21 07:44:24.274736 2026] [security2:error] [pid 302018:tid 302128] [remote 45.79.123.44:40266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9NiIAs9lPxxVAErz3mqwABAWs"]
[Tue Jul 21 07:44:24.344432 2026] [security2:error] [pid 296703:tid 296914] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9NiCn25uliftkV1n4MpAAAAFE"]
[Tue Jul 21 07:44:24.451214 2026] [security2:error] [pid 302018:tid 302152] [client 20.197.195.24:62661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/wp-load.php"] [unique_id "al9NiIAs9lPxxVAErz3msAAAAIc"]
[Tue Jul 21 07:44:24.474506 2026] [security2:error] [pid 302018:tid 302248] [client 20.104.96.117:44285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/ops.php"] [unique_id "al9NiIAs9lPxxVAErz3msQAAAOc"]
[Tue Jul 21 07:44:24.480615 2026] [security2:error] [pid 302018:tid 302242] [client 20.197.195.24:13797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/init.php"] [unique_id "al9NiIAs9lPxxVAErz3msgAAAOE"]
[Tue Jul 21 07:44:24.513622 2026] [security2:error] [pid 296703:tid 296890] [client 20.104.96.117:30898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/public/css.php"] [unique_id "al9NiCn25uliftkV1n4MpwAAADk"]
[Tue Jul 21 07:44:24.599156 2026] [security2:error] [pid 302018:tid 302254] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9NiIAs9lPxxVAErz3mtwAAAO0"]
[Tue Jul 21 07:44:24.607600 2026] [security2:error] [pid 296703:tid 296865] [client 41.68.90.219:64013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NiCn25uliftkV1n4MqwAAACA"]
[Tue Jul 21 07:44:24.608747 2026] [security2:error] [pid 296703:tid 296865] [client 41.68.90.219:64013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NiCn25uliftkV1n4MqwAAACA"]
[Tue Jul 21 07:44:24.789471 2026] [security2:error] [pid 302018:tid 302277] [client 142.44.233.81:25398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "powertronicseguranca.com"] [uri "/robots.txt"] [unique_id "al9NiIAs9lPxxVAErz3mvAAAAQQ"]
[Tue Jul 21 07:44:24.789582 2026] [security2:error] [pid 302018:tid 302277] [client 142.44.233.81:25398] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "powertronicseguranca.com"] [uri "/robots.txt"] [unique_id "al9NiIAs9lPxxVAErz3mvAAAAQQ"]
[Tue Jul 21 07:44:24.820101 2026] [security2:error] [pid 302018:tid 302194] [client 20.197.195.24:14024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/xyn.php"] [unique_id "al9NiIAs9lPxxVAErz3mvQAAALE"]
[Tue Jul 21 07:44:24.821609 2026] [security2:error] [pid 296703:tid 296840] [client 20.220.225.223:55783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/term.php"] [unique_id "al9NiCn25uliftkV1n4MrgAAAAc"]
[Tue Jul 21 07:44:24.899297 2026] [security2:error] [pid 296703:tid 296951] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9NiCn25uliftkV1n4MsQAAAHY"]
[Tue Jul 21 07:44:24.991856 2026] [security2:error] [pid 302018:tid 302187] [client 122.162.144.145:31989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NiIAs9lPxxVAErz3mvwAAAKo"]
[Tue Jul 21 07:44:24.992005 2026] [security2:error] [pid 302018:tid 302187] [client 122.162.144.145:31989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NiIAs9lPxxVAErz3mvwAAAKo"]
[Tue Jul 21 07:44:25.052124 2026] [security2:error] [pid 296703:tid 296927] [client 184.75.223.211:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9NiSn25uliftkV1n4MswAAAF4"]
[Tue Jul 21 07:44:25.052237 2026] [security2:error] [pid 296703:tid 296927] [client 184.75.223.211:56646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9NiSn25uliftkV1n4MswAAAF4"]
[Tue Jul 21 07:44:25.065304 2026] [security2:error] [pid 296703:tid 296905] [client 74.249.245.134:54369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/av.php"] [unique_id "al9NiSn25uliftkV1n4MtgAAAEg"]
[Tue Jul 21 07:44:25.153162 2026] [security2:error] [pid 302018:tid 302253] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9NiYAs9lPxxVAErz3mwQAAAOw"]
[Tue Jul 21 07:44:25.171914 2026] [security2:error] [pid 302018:tid 302269] [client 139.167.225.182:56706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NiYAs9lPxxVAErz3mwgAAAPw"]
[Tue Jul 21 07:44:25.172023 2026] [security2:error] [pid 302018:tid 302269] [client 139.167.225.182:56706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NiYAs9lPxxVAErz3mwgAAAPw"]
[Tue Jul 21 07:44:25.204582 2026] [security2:error] [pid 302018:tid 302155] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9NiYAs9lPxxVAErz3mwAAAimg"]
[Tue Jul 21 07:44:25.276609 2026] [security2:error] [pid 302018:tid 302158] [client 20.104.96.117:30911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/output.php"] [unique_id "al9NiYAs9lPxxVAErz3mxAAAAI0"]
[Tue Jul 21 07:44:25.288153 2026] [security2:error] [pid 296703:tid 296836] [client 103.29.114.44:64895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NiSn25uliftkV1n4MuwAAAAM"]
[Tue Jul 21 07:44:25.288275 2026] [security2:error] [pid 296703:tid 296836] [client 103.29.114.44:64895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NiSn25uliftkV1n4MuwAAAAM"]
[Tue Jul 21 07:44:25.453843 2026] [security2:error] [pid 296703:tid 296912] [client 20.197.195.24:14064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/ccc.php"] [unique_id "al9NiSn25uliftkV1n4MwwAAAE8"]
[Tue Jul 21 07:44:25.468383 2026] [security2:error] [pid 296703:tid 296846] [client 20.226.60.151:54381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/11.php"] [unique_id "al9NiSn25uliftkV1n4MxQAAAA0"]
[Tue Jul 21 07:44:25.514411 2026] [security2:error] [pid 296703:tid 296863] [client 20.220.225.223:60357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/ah25.php"] [unique_id "al9NiSn25uliftkV1n4MxwAAAB4"]
[Tue Jul 21 07:44:25.790020 2026] [security2:error] [pid 296703:tid 296949] [client 20.197.195.24:62696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/w.php"] [unique_id "al9NiSn25uliftkV1n4MzQAAAHQ"]
[Tue Jul 21 07:44:25.807329 2026] [security2:error] [pid 296703:tid 296833] [client 173.24.185.52:60453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NiSn25uliftkV1n4MzgAAAAA"]
[Tue Jul 21 07:44:25.807452 2026] [security2:error] [pid 296703:tid 296833] [client 173.24.185.52:60453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NiSn25uliftkV1n4MzgAAAAA"]
[Tue Jul 21 07:44:25.974314 2026] [security2:error] [pid 296703:tid 296843] [client 20.197.195.24:62658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9NiSn25uliftkV1n4M0AAAAAo"]
[Tue Jul 21 07:44:25.985074 2026] [security2:error] [pid 296703:tid 296760] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NiSn25uliftkV1n4M0QAAVjg"]
[Tue Jul 21 07:44:25.985233 2026] [security2:error] [pid 296703:tid 296919] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NiSn25uliftkV1n4M0QAAVjg"]
[Tue Jul 21 07:44:26.005555 2026] [security2:error] [pid 302018:tid 302214] [client 122.179.91.63:28402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NioAs9lPxxVAErz3mzwAAAMU"]
[Tue Jul 21 07:44:26.006335 2026] [security2:error] [pid 302018:tid 302214] [client 122.179.91.63:28402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NioAs9lPxxVAErz3mzwAAAMU"]
[Tue Jul 21 07:44:26.045841 2026] [security2:error] [pid 302018:tid 302201] [client 20.197.195.24:13988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/FWAZ.php"] [unique_id "al9NioAs9lPxxVAErz3m0gAAALg"]
[Tue Jul 21 07:44:26.101221 2026] [security2:error] [pid 302018:tid 302227] [client 20.220.225.223:60364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/8.php"] [unique_id "al9NioAs9lPxxVAErz3m0wAAANI"]
[Tue Jul 21 07:44:26.206299 2026] [security2:error] [pid 296703:tid 296911] [client 20.104.96.117:30858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-file-120.php"] [unique_id "al9Niin25uliftkV1n4M1AAAAE4"]
[Tue Jul 21 07:44:26.225921 2026] [security2:error] [pid 302018:tid 302188] [client 54.39.210.74:43456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "powertronicseguranca.com"] [uri "/"] [unique_id "al9NioAs9lPxxVAErz3m1AAAAKs"]
[Tue Jul 21 07:44:26.226076 2026] [security2:error] [pid 302018:tid 302188] [client 54.39.210.74:43456] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "powertronicseguranca.com"] [uri "/"] [unique_id "al9NioAs9lPxxVAErz3m1AAAAKs"]
[Tue Jul 21 07:44:26.564352 2026] [security2:error] [pid 296703:tid 296884] [client 20.197.195.24:13978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/miru1.php"] [unique_id "al9Niin25uliftkV1n4M2wAAADM"]
[Tue Jul 21 07:44:26.580398 2026] [security2:error] [pid 296703:tid 296943] [client 20.104.96.117:44239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/file31.php"] [unique_id "al9Niin25uliftkV1n4M3AAAAG4"]
[Tue Jul 21 07:44:26.630884 2026] [security2:error] [pid 302018:tid 302180] [client 20.226.60.151:62009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/v2.php"] [unique_id "al9NioAs9lPxxVAErz3m2AAAAKM"]
[Tue Jul 21 07:44:26.741004 2026] [security2:error] [pid 302018:tid 302252] [client 20.104.96.117:30643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/special.php"] [unique_id "al9NioAs9lPxxVAErz3m2QAAAOs"]
[Tue Jul 21 07:44:26.810700 2026] [security2:error] [pid 302018:tid 302219] [client 20.197.195.24:62690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/aa.php"] [unique_id "al9NioAs9lPxxVAErz3m3AAAAMo"]
[Tue Jul 21 07:44:26.892899 2026] [security2:error] [pid 302018:tid 302204] [client 20.197.195.24:62612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/122.php"] [unique_id "al9NioAs9lPxxVAErz3m3wAAALs"]
[Tue Jul 21 07:44:27.018475 2026] [security2:error] [pid 302018:tid 302260] [client 20.220.225.223:34220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/dp.php"] [unique_id "al9Ni4As9lPxxVAErz3m4QAAAPM"]
[Tue Jul 21 07:44:27.033731 2026] [security2:error] [pid 296703:tid 296854] [client 20.220.225.223:55756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/red.php"] [unique_id "al9Niyn25uliftkV1n4M4wAAABU"]
[Tue Jul 21 07:44:27.041711 2026] [security2:error] [pid 302018:tid 302195] [client 103.166.103.129:62818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Ni4As9lPxxVAErz3m4gAAALI"]
[Tue Jul 21 07:44:27.041858 2026] [security2:error] [pid 302018:tid 302195] [client 103.166.103.129:62818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Ni4As9lPxxVAErz3m4gAAALI"]
[Tue Jul 21 07:44:27.043540 2026] [security2:error] [pid 302018:tid 302242] [client 136.144.33.24:48383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NioAs9lPxxVAErz3m3gAAAOE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:44:27.081777 2026] [security2:error] [pid 302018:tid 302133] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ni4As9lPxxVAErz3m5QAAnHA"]
[Tue Jul 21 07:44:27.081926 2026] [security2:error] [pid 302018:tid 302173] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ni4As9lPxxVAErz3m5QAAnHA"]
[Tue Jul 21 07:44:27.437440 2026] [security2:error] [pid 302018:tid 302259] [client 20.197.195.24:49830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/fpwch.php"] [unique_id "al9Ni4As9lPxxVAErz3m7QAAAPI"]
[Tue Jul 21 07:44:27.502234 2026] [security2:error] [pid 296703:tid 296894] [client 20.104.96.117:44116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/file6.php"] [unique_id "al9Niyn25uliftkV1n4M6QAAAD0"]
[Tue Jul 21 07:44:27.527597 2026] [security2:error] [pid 296703:tid 296960] [client 20.226.60.151:56025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/panel.php"] [unique_id "al9Niyn25uliftkV1n4M6wAAAH8"]
[Tue Jul 21 07:44:27.535627 2026] [security2:error] [pid 302018:tid 302158] [client 74.249.245.134:54383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/gg.php"] [unique_id "al9Ni4As9lPxxVAErz3m7wAAAI0"]
[Tue Jul 21 07:44:27.758565 2026] [security2:error] [pid 296703:tid 296872] [client 20.104.96.117:30594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/as.php"] [unique_id "al9Niyn25uliftkV1n4M7wAAACc"]
[Tue Jul 21 07:44:27.772571 2026] [core:error] [pid 296703:tid 296876] [client 66.249.66.74:42388] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:44:27.772592 2026] [core:error] [pid 296703:tid 296876] [client 66.249.66.74:42388] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:44:27.893799 2026] [security2:error] [pid 302018:tid 302238] [client 20.197.195.24:13985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/get.php"] [unique_id "al9Ni4As9lPxxVAErz3m8QAAAN0"]
[Tue Jul 21 07:44:28.045415 2026] [security2:error] [pid 302018:tid 302272] [client 182.8.255.181:17167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NjIAs9lPxxVAErz3m9AAAAP8"]
[Tue Jul 21 07:44:28.045525 2026] [security2:error] [pid 302018:tid 302272] [client 182.8.255.181:17167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NjIAs9lPxxVAErz3m9AAAAP8"]
[Tue Jul 21 07:44:28.165931 2026] [security2:error] [pid 296703:tid 296934] [client 20.220.225.223:34243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/else1.php"] [unique_id "al9NjCn25uliftkV1n4M9wAAAGU"]
[Tue Jul 21 07:44:28.265305 2026] [security2:error] [pid 296703:tid 296847] [client 193.36.225.56:41963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NjCn25uliftkV1n4M-wAAAA4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:44:28.347142 2026] [security2:error] [pid 302018:tid 302140] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NjIAs9lPxxVAErz3m-wAAs3c"]
[Tue Jul 21 07:44:28.347376 2026] [security2:error] [pid 302018:tid 302196] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NjIAs9lPxxVAErz3m-wAAs3c"]
[Tue Jul 21 07:44:28.365319 2026] [security2:error] [pid 296703:tid 296905] [client 178.153.91.96:65168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NjCn25uliftkV1n4M_AAAAEg"]
[Tue Jul 21 07:44:28.365454 2026] [security2:error] [pid 296703:tid 296905] [client 178.153.91.96:65168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NjCn25uliftkV1n4M_AAAAEg"]
[Tue Jul 21 07:44:28.509871 2026] [security2:error] [pid 302018:tid 302161] [client 20.104.96.117:30882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9NjIAs9lPxxVAErz3m_QAAAJA"]
[Tue Jul 21 07:44:28.516317 2026] [security2:error] [pid 302018:tid 302141] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjIAs9lPxxVAErz3m_gAA03g"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:28.524864 2026] [security2:error] [pid 296703:tid 296830] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjCn25uliftkV1n4NAQAALH4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:28.537820 2026] [security2:error] [pid 296703:tid 296778] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjCn25uliftkV1n4NAwAAfko"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:28.560739 2026] [security2:error] [pid 302018:tid 302224] [client 20.197.195.24:13962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/as.php"] [unique_id "al9NjIAs9lPxxVAErz3m_wAAAM8"]
[Tue Jul 21 07:44:28.669557 2026] [security2:error] [pid 296703:tid 296715] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjCn25uliftkV1n4NAAAASws"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:28.682170 2026] [security2:error] [pid 302018:tid 302256] [client 106.215.181.8:17447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NjIAs9lPxxVAErz3nAgAAAO8"]
[Tue Jul 21 07:44:28.682289 2026] [security2:error] [pid 302018:tid 302256] [client 106.215.181.8:17447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NjIAs9lPxxVAErz3nAgAAAO8"]
[Tue Jul 21 07:44:28.697549 2026] [security2:error] [pid 302018:tid 302137] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjIAs9lPxxVAErz3nAwAA63Q"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:28.713165 2026] [security2:error] [pid 296703:tid 296875] [client 20.226.60.151:61968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/dex.php"] [unique_id "al9NjCn25uliftkV1n4NCgAAACo"]
[Tue Jul 21 07:44:28.732307 2026] [security2:error] [pid 296703:tid 296766] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjCn25uliftkV1n4NDQAARD4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:28.734243 2026] [autoindex:error] [pid 302018:tid 302248] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/blissf00/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:44:28.770054 2026] [security2:error] [pid 302018:tid 302237] [client 103.86.117.203:59428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NjIAs9lPxxVAErz3nBQAAANw"]
[Tue Jul 21 07:44:28.770199 2026] [security2:error] [pid 302018:tid 302237] [client 103.86.117.203:59428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NjIAs9lPxxVAErz3nBQAAANw"]
[Tue Jul 21 07:44:28.811863 2026] [security2:error] [pid 302018:tid 302222] [client 20.197.195.24:13994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/ccou.php"] [unique_id "al9NjIAs9lPxxVAErz3nBgAAAM0"]
[Tue Jul 21 07:44:28.845394 2026] [security2:error] [pid 296703:tid 296745] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjCn25uliftkV1n4NDgAALSk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:28.863346 2026] [security2:error] [pid 302018:tid 302236] [client 103.174.34.15:61500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NjIAs9lPxxVAErz3nBwAAANs"]
[Tue Jul 21 07:44:28.863759 2026] [security2:error] [pid 302018:tid 302236] [client 103.174.34.15:61500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NjIAs9lPxxVAErz3nBwAAANs"]
[Tue Jul 21 07:44:28.883934 2026] [security2:error] [pid 302018:tid 302144] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjIAs9lPxxVAErz3nCAABAHs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:28.924449 2026] [security2:error] [pid 296703:tid 296775] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjCn25uliftkV1n4NDwAAfUc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:28.948790 2026] [security2:error] [pid 302018:tid 302153] [client 20.197.195.24:22151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/domvf.php"] [unique_id "al9NjIAs9lPxxVAErz3nCQAAAIg"]
[Tue Jul 21 07:44:29.001097 2026] [security2:error] [pid 302018:tid 302139] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjIAs9lPxxVAErz3nCwAA-nY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:29.027041 2026] [security2:error] [pid 296703:tid 296711] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NjSn25uliftkV1n4NFQAAYgc"]
[Tue Jul 21 07:44:29.027168 2026] [security2:error] [pid 296703:tid 296931] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NjSn25uliftkV1n4NFQAAYgc"]
[Tue Jul 21 07:44:29.037240 2026] [security2:error] [pid 296703:tid 296902] [client 20.104.96.117:44268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/adminfuns.php"] [unique_id "al9NjSn25uliftkV1n4NFgAAAEU"]
[Tue Jul 21 07:44:29.044801 2026] [security2:error] [pid 302018:tid 302259] [client 20.220.225.223:34252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/tkikikoko.php"] [unique_id "al9NjYAs9lPxxVAErz3nIAAAAPI"]
[Tue Jul 21 07:44:29.114903 2026] [security2:error] [pid 296703:tid 296740] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjSn25uliftkV1n4NGAAATCQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:29.190098 2026] [security2:error] [pid 296703:tid 296788] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjSn25uliftkV1n4NGgAAeVQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:29.300366 2026] [security2:error] [pid 296703:tid 296724] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjSn25uliftkV1n4NHAAAHxQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:29.317111 2026] [security2:error] [pid 302018:tid 302027] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjYAs9lPxxVAErz3nIwAAtwY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:29.323830 2026] [security2:error] [pid 302018:tid 302029] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NjYAs9lPxxVAErz3nJQAA4gg"]
[Tue Jul 21 07:44:29.323934 2026] [security2:error] [pid 302018:tid 302243] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NjYAs9lPxxVAErz3nJQAA4gg"]
[Tue Jul 21 07:44:29.324787 2026] [security2:error] [pid 302018:tid 302034] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjYAs9lPxxVAErz3nJgAA3Q0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:29.447667 2026] [security2:error] [pid 302018:tid 302036] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9NjYAs9lPxxVAErz3nJwAApw8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:44:29.474877 2026] [security2:error] [pid 302018:tid 302258] [client 20.104.96.117:30439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/w1px.php"] [unique_id "al9NjYAs9lPxxVAErz3nKAAAAPE"]
[Tue Jul 21 07:44:29.547048 2026] [security2:error] [pid 302018:tid 302216] [client 20.104.96.117:44274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/goods.php"] [unique_id "al9NjYAs9lPxxVAErz3nKQAAAMc"]
[Tue Jul 21 07:44:29.565350 2026] [security2:error] [pid 302018:tid 302214] [client 20.197.195.24:62706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/w3lls.php"] [unique_id "al9NjYAs9lPxxVAErz3nKgAAAMU"]
[Tue Jul 21 07:44:29.695577 2026] [security2:error] [pid 302018:tid 302275] [client 20.197.195.24:13814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp.php"] [unique_id "al9NjYAs9lPxxVAErz3nLwAAAQI"]
[Tue Jul 21 07:44:29.750549 2026] [security2:error] [pid 302018:tid 302174] [client 122.164.127.47:60909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NjYAs9lPxxVAErz3nMQAAAJ0"]
[Tue Jul 21 07:44:29.750719 2026] [security2:error] [pid 302018:tid 302174] [client 122.164.127.47:60909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NjYAs9lPxxVAErz3nMQAAAJ0"]
[Tue Jul 21 07:44:29.764295 2026] [security2:error] [pid 302018:tid 302265] [client 34.91.119.153:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "linosguincho.com.br"] [uri "/"] [unique_id "al9NjYAs9lPxxVAErz3nMgAAAPg"]
[Tue Jul 21 07:44:29.764412 2026] [security2:error] [pid 302018:tid 302265] [client 34.91.119.153:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "linosguincho.com.br"] [uri "/"] [unique_id "al9NjYAs9lPxxVAErz3nMgAAAPg"]
[Tue Jul 21 07:44:29.955248 2026] [security2:error] [pid 302018:tid 302031] [remote 39.97.110.217:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.110.97.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samilacalculos.com.br"] [uri "/wp-login.php"] [unique_id "al9NjYAs9lPxxVAErz3nOgAA9Ao"]
[Tue Jul 21 07:44:29.960266 2026] [security2:error] [pid 302018:tid 302245] [client 20.197.195.24:14014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/test1.php"] [unique_id "al9NjYAs9lPxxVAErz3nOwAAAOQ"]
[Tue Jul 21 07:44:29.993718 2026] [security2:error] [pid 302018:tid 302179] [client 20.197.195.24:22149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/class.php"] [unique_id "al9NjYAs9lPxxVAErz3nPAAAAKI"]
[Tue Jul 21 07:44:30.033148 2026] [security2:error] [pid 302018:tid 302157] [client 20.104.96.117:44108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/100.php"] [unique_id "al9NjoAs9lPxxVAErz3nPQAAAIw"]
[Tue Jul 21 07:44:30.127784 2026] [security2:error] [pid 302018:tid 302160] [client 20.104.96.117:30614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/yawa.php"] [unique_id "al9NjoAs9lPxxVAErz3nQAAAAI8"]
[Tue Jul 21 07:44:30.261090 2026] [security2:error] [pid 302018:tid 302259] [client 20.220.225.223:34257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/bootstrap.php"] [unique_id "al9NjoAs9lPxxVAErz3nQwAAAPI"]
[Tue Jul 21 07:44:30.501366 2026] [security2:error] [pid 302018:tid 302215] [client 20.104.96.117:44232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/about.php"] [unique_id "al9NjoAs9lPxxVAErz3nSAAAAMY"]
[Tue Jul 21 07:44:30.609760 2026] [security2:error] [pid 296703:tid 296857] [client 20.197.195.24:13748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/echkm.php"] [unique_id "al9Njin25uliftkV1n4NLQAAABg"]
[Tue Jul 21 07:44:30.739902 2026] [security2:error] [pid 302018:tid 302272] [client 20.226.60.151:54368] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "horiclinicaguarulhos.com.br"] [uri "/1.php"] [unique_id "al9NjoAs9lPxxVAErz3nTQAAAP8"]
[Tue Jul 21 07:44:30.740023 2026] [security2:error] [pid 302018:tid 302272] [client 20.226.60.151:54368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/1.php"] [unique_id "al9NjoAs9lPxxVAErz3nTQAAAP8"]
[Tue Jul 21 07:44:30.753377 2026] [security2:error] [pid 296703:tid 296768] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Njin25uliftkV1n4NMgAAUkA"]
[Tue Jul 21 07:44:30.753527 2026] [security2:error] [pid 296703:tid 296915] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Njin25uliftkV1n4NMgAAUkA"]
[Tue Jul 21 07:44:30.769102 2026] [security2:error] [pid 296703:tid 296906] [client 117.251.86.144:52774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Njin25uliftkV1n4NMwAAAEk"]
[Tue Jul 21 07:44:30.769232 2026] [security2:error] [pid 296703:tid 296906] [client 117.251.86.144:52774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Njin25uliftkV1n4NMwAAAEk"]
[Tue Jul 21 07:44:30.778643 2026] [security2:error] [pid 302018:tid 302197] [client 20.197.195.24:13984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/database.php"] [unique_id "al9NjoAs9lPxxVAErz3nTwAAALQ"]
[Tue Jul 21 07:44:30.890572 2026] [security2:error] [pid 302018:tid 302258] [client 20.104.96.117:44147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/about.php"] [unique_id "al9NjoAs9lPxxVAErz3nUAAAAPE"]
[Tue Jul 21 07:44:30.935644 2026] [security2:error] [pid 302018:tid 302166] [client 117.247.80.59:21158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NjoAs9lPxxVAErz3nUQAAAJU"]
[Tue Jul 21 07:44:30.936281 2026] [security2:error] [pid 302018:tid 302166] [client 117.247.80.59:21158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NjoAs9lPxxVAErz3nUQAAAJU"]
[Tue Jul 21 07:44:31.010435 2026] [security2:error] [pid 302018:tid 302266] [client 122.186.204.214:62263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Nj4As9lPxxVAErz3nUgAAAPk"]
[Tue Jul 21 07:44:31.010578 2026] [security2:error] [pid 302018:tid 302266] [client 122.186.204.214:62263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Nj4As9lPxxVAErz3nUgAAAPk"]
[Tue Jul 21 07:44:31.201869 2026] [security2:error] [pid 302018:tid 302241] [client 20.63.100.92:4418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/zzz.php"] [unique_id "al9Nj4As9lPxxVAErz3nUwAAAOA"]
[Tue Jul 21 07:44:31.226723 2026] [security2:error] [pid 296703:tid 296903] [client 20.104.96.117:44156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/admin.php"] [unique_id "al9Njyn25uliftkV1n4NNwAAAEY"]
[Tue Jul 21 07:44:31.303652 2026] [security2:error] [pid 302018:tid 302211] [client 20.197.195.24:49836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/lib.php"] [unique_id "al9Nj4As9lPxxVAErz3nWQAAAMI"]
[Tue Jul 21 07:44:31.307258 2026] [security2:error] [pid 302018:tid 302170] [client 20.197.195.24:13970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/file.php"] [unique_id "al9Nj4As9lPxxVAErz3nWgAAAJk"]
[Tue Jul 21 07:44:31.357698 2026] [core:error] [pid 302018:tid 302174] [client 66.249.66.75:35277] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:44:31.357718 2026] [core:error] [pid 302018:tid 302174] [client 66.249.66.75:35277] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:44:31.393628 2026] [security2:error] [pid 302018:tid 302222] [client 20.104.96.117:30592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/js.php"] [unique_id "al9Nj4As9lPxxVAErz3nXgAAAM0"]
[Tue Jul 21 07:44:31.412277 2026] [security2:error] [pid 302018:tid 302151] [client 74.249.245.134:54336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/sql.php"] [unique_id "al9Nj4As9lPxxVAErz3nXwAAAIY"]
[Tue Jul 21 07:44:31.563304 2026] [security2:error] [pid 296703:tid 296935] [client 20.197.195.24:13755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/login.php"] [unique_id "al9Njyn25uliftkV1n4NOwAAAGY"]
[Tue Jul 21 07:44:31.678358 2026] [security2:error] [pid 302018:tid 302216] [client 117.217.38.194:55475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nj4As9lPxxVAErz3nYQAAAMc"]
[Tue Jul 21 07:44:31.678501 2026] [security2:error] [pid 302018:tid 302216] [client 117.217.38.194:55475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nj4As9lPxxVAErz3nYQAAAMc"]
[Tue Jul 21 07:44:31.685910 2026] [security2:error] [pid 302018:tid 302161] [client 20.197.195.24:13993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/file.php"] [unique_id "al9Nj4As9lPxxVAErz3nYgAAAJA"]
[Tue Jul 21 07:44:31.713314 2026] [security2:error] [pid 296703:tid 296959] [client 20.104.96.117:44125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/admin.php"] [unique_id "al9Njyn25uliftkV1n4NQAAAAH4"]
[Tue Jul 21 07:44:31.855745 2026] [security2:error] [pid 296703:tid 296880] [client 20.197.195.24:62621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/777.php"] [unique_id "al9Njyn25uliftkV1n4NQwAAAC8"]
[Tue Jul 21 07:44:32.006395 2026] [security2:error] [pid 302018:tid 302209] [client 20.226.60.151:54361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/ms.php"] [unique_id "al9NkIAs9lPxxVAErz3nZwAAAMA"]
[Tue Jul 21 07:44:32.123576 2026] [security2:error] [pid 302018:tid 302177] [client 154.192.233.199:59004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NkIAs9lPxxVAErz3naQAAAKA"]
[Tue Jul 21 07:44:32.123766 2026] [security2:error] [pid 302018:tid 302177] [client 154.192.233.199:59004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NkIAs9lPxxVAErz3naQAAAKA"]
[Tue Jul 21 07:44:32.131292 2026] [security2:error] [pid 302018:tid 302187] [client 20.104.96.117:44148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/themes.php"] [unique_id "al9NkIAs9lPxxVAErz3nagAAAKo"]
[Tue Jul 21 07:44:32.144601 2026] [security2:error] [pid 302018:tid 302160] [client 20.197.195.24:13823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/a2.php"] [unique_id "al9NkIAs9lPxxVAErz3nawAAAI8"]
[Tue Jul 21 07:44:32.337894 2026] [security2:error] [pid 302018:tid 302155] [client 20.197.195.24:13986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/ssixta.php"] [unique_id "al9NkIAs9lPxxVAErz3nbwAAAIo"]
[Tue Jul 21 07:44:32.338626 2026] [security2:error] [pid 302018:tid 302207] [client 136.144.33.107:32001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NkIAs9lPxxVAErz3nbAAAAL4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:44:32.606976 2026] [security2:error] [pid 296703:tid 296721] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NkCn25uliftkV1n4NTAAARBE"]
[Tue Jul 21 07:44:32.607154 2026] [security2:error] [pid 296703:tid 296901] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NkCn25uliftkV1n4NTAAARBE"]
[Tue Jul 21 07:44:32.627989 2026] [autoindex:error] [pid 302018:tid 302159] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/blissf00/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:44:32.804899 2026] [security2:error] [pid 302018:tid 302150] [client 20.197.195.24:49797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/d61.php"] [unique_id "al9NkIAs9lPxxVAErz3ndQAAAIU"]
[Tue Jul 21 07:44:33.100043 2026] [security2:error] [pid 302018:tid 302225] [client 20.197.195.24:13779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/info.php"] [unique_id "al9NkYAs9lPxxVAErz3nfQAAANA"]
[Tue Jul 21 07:44:33.137465 2026] [security2:error] [pid 296703:tid 296824] [remote 182.77.62.24:51472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9NkSn25uliftkV1n4NVQAADHg"]
[Tue Jul 21 07:44:33.137597 2026] [security2:error] [pid 296703:tid 296845] [client 182.77.62.24:51472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9NkSn25uliftkV1n4NVQAADHg"]
[Tue Jul 21 07:44:33.149089 2026] [security2:error] [pid 302018:tid 302242] [client 20.220.225.223:34208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wp-editor.php"] [unique_id "al9NkYAs9lPxxVAErz3nfgAAAOE"]
[Tue Jul 21 07:44:33.206720 2026] [security2:error] [pid 302018:tid 302153] [client 20.197.195.24:62718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/1c.php"] [unique_id "al9NkYAs9lPxxVAErz3nfwAAAIg"]
[Tue Jul 21 07:44:33.233893 2026] [security2:error] [pid 302018:tid 302241] [client 74.249.245.134:17444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/up.php"] [unique_id "al9NkYAs9lPxxVAErz3ngAAAAOA"]
[Tue Jul 21 07:44:33.238975 2026] [security2:error] [pid 302018:tid 302168] [client 202.143.127.214:55266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NkYAs9lPxxVAErz3ngQAAAJc"]
[Tue Jul 21 07:44:33.239123 2026] [security2:error] [pid 302018:tid 302168] [client 202.143.127.214:55266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NkYAs9lPxxVAErz3ngQAAAJc"]
[Tue Jul 21 07:44:33.496441 2026] [security2:error] [pid 302018:tid 302252] [client 20.197.195.24:62664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/test2.php"] [unique_id "al9NkYAs9lPxxVAErz3nhgAAAOs"]
[Tue Jul 21 07:44:33.568150 2026] [security2:error] [pid 302018:tid 302217] [client 20.197.195.24:49838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/11.php"] [unique_id "al9NkYAs9lPxxVAErz3nhwAAAMg"]
[Tue Jul 21 07:44:33.739327 2026] [security2:error] [pid 296703:tid 296869] [client 20.197.195.24:62692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/buy.php"] [unique_id "al9NkSn25uliftkV1n4NYAAAACQ"]
[Tue Jul 21 07:44:33.948303 2026] [security2:error] [pid 302018:tid 302053] [remote 182.77.62.24:44862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9NkYAs9lPxxVAErz3niAAAwiA"]
[Tue Jul 21 07:44:33.966271 2026] [security2:error] [pid 302018:tid 302151] [client 20.197.195.24:62627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/ssend.php"] [unique_id "al9NkYAs9lPxxVAErz3niQAAAIY"]
[Tue Jul 21 07:44:34.103163 2026] [security2:error] [pid 296703:tid 296867] [client 20.197.195.24:22158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/v2.php"] [unique_id "al9Nkin25uliftkV1n4NaQAAACI"]
[Tue Jul 21 07:44:34.179866 2026] [security2:error] [pid 296703:tid 296864] [client 59.96.220.140:63706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Nkin25uliftkV1n4NagAAAB8"]
[Tue Jul 21 07:44:34.180009 2026] [security2:error] [pid 296703:tid 296864] [client 59.96.220.140:63706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Nkin25uliftkV1n4NagAAAB8"]
[Tue Jul 21 07:44:34.230194 2026] [security2:error] [pid 302018:tid 302185] [client 20.220.225.223:34180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9NkoAs9lPxxVAErz3niwAAAKg"]
[Tue Jul 21 07:44:34.285256 2026] [security2:error] [pid 302018:tid 302196] [client 152.59.154.239:59425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NkoAs9lPxxVAErz3njgAAALM"]
[Tue Jul 21 07:44:34.285406 2026] [security2:error] [pid 302018:tid 302196] [client 152.59.154.239:59425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NkoAs9lPxxVAErz3njgAAALM"]
[Tue Jul 21 07:44:34.446642 2026] [autoindex:error] [pid 296703:tid 296932] [client 20.226.60.151:62015] AH01276: Cannot serve directory /home4/horicl01/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:44:34.456093 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.456117 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.456526 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Globo-2.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.468687 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.468695 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.468915 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/IstoE.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.476073 2026] [security2:error] [pid 296703:tid 296893] [client 20.226.60.151:62015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/memberfuns.php"] [unique_id "al9Nkin25uliftkV1n4NcQAAADw"]
[Tue Jul 21 07:44:34.480796 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.480842 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.481023 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Terra.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.496683 2026] [security2:error] [pid 296703:tid 296870] [client 20.197.195.24:14067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/item.php"] [unique_id "al9Nkin25uliftkV1n4NcgAAACU"]
[Tue Jul 21 07:44:34.497426 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.497436 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.497641 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Caras.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.509270 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.509287 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.509463 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Contigo.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.521320 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.521336 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.521527 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Bons-Fluidos.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.533126 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.533139 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.533343 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Boa-Forma.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.544559 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.544583 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.544753 2026] [lsapi:warn] [pid 302018:tid 302044] [remote 191.235.66.17:21441] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Lance.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:44:34.643440 2026] [security2:error] [pid 296703:tid 296905] [client 20.197.195.24:13953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/ss.php"] [unique_id "al9Nkin25uliftkV1n4NdAAAAEg"]
[Tue Jul 21 07:44:34.665468 2026] [security2:error] [pid 302018:tid 302269] [client 20.104.96.117:44124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/.well-known/about.php"] [unique_id "al9NkoAs9lPxxVAErz3nkQAAAPw"]
[Tue Jul 21 07:44:34.688169 2026] [security2:error] [pid 302018:tid 302213] [client 20.104.96.117:30907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/core.php"] [unique_id "al9NkoAs9lPxxVAErz3nkgAAAMQ"]
[Tue Jul 21 07:44:34.766991 2026] [security2:error] [pid 302018:tid 302231] [client 20.63.100.92:2620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/wicked.php"] [unique_id "al9NkoAs9lPxxVAErz3nlAAAANY"]
[Tue Jul 21 07:44:34.791387 2026] [security2:error] [pid 296703:tid 296929] [client 20.197.195.24:49833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/panel.php"] [unique_id "al9Nkin25uliftkV1n4NeAAAAGA"]
[Tue Jul 21 07:44:34.811858 2026] [security2:error] [pid 302018:tid 302215] [client 20.197.195.24:62670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/hypo.php"] [unique_id "al9NkoAs9lPxxVAErz3nlQAAAMY"]
[Tue Jul 21 07:44:34.896188 2026] [security2:error] [pid 296703:tid 296957] [client 20.197.195.24:14066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/users.php"] [unique_id "al9Nkin25uliftkV1n4NewAAAHw"]
[Tue Jul 21 07:44:34.911767 2026] [security2:error] [pid 296703:tid 296891] [client 20.197.195.24:13999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/177.php"] [unique_id "al9Nkin25uliftkV1n4NfAAAADo"]
[Tue Jul 21 07:44:34.986861 2026] [security2:error] [pid 302018:tid 302242] [client 20.197.195.24:62707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/config.php"] [unique_id "al9NkoAs9lPxxVAErz3nmwAAAOE"]
[Tue Jul 21 07:44:34.999391 2026] [security2:error] [pid 296703:tid 296917] [client 20.197.195.24:22204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/dex.php"] [unique_id "al9Nkin25uliftkV1n4NgAAAAFQ"]
[Tue Jul 21 07:44:35.077842 2026] [security2:error] [pid 296703:tid 296899] [client 74.249.245.134:5561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/66.php"] [unique_id "al9Nkyn25uliftkV1n4NgQAAAEI"]
[Tue Jul 21 07:44:35.152227 2026] [security2:error] [pid 302018:tid 302205] [client 20.220.225.223:34200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/cro.php"] [unique_id "al9Nk4As9lPxxVAErz3nngAAALw"]
[Tue Jul 21 07:44:35.197579 2026] [security2:error] [pid 296703:tid 296928] [client 20.197.195.24:14043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/gettest.php"] [unique_id "al9Nkyn25uliftkV1n4NhAAAAF8"]
[Tue Jul 21 07:44:35.254193 2026] [security2:error] [pid 302018:tid 302247] [client 20.197.195.24:13778] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "clubevendasonline.com"] [uri "/1.php"] [unique_id "al9Nk4As9lPxxVAErz3nnwAAAOY"]
[Tue Jul 21 07:44:35.254310 2026] [security2:error] [pid 302018:tid 302247] [client 20.197.195.24:13778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/1.php"] [unique_id "al9Nk4As9lPxxVAErz3nnwAAAOY"]
[Tue Jul 21 07:44:35.330246 2026] [security2:error] [pid 296703:tid 296912] [client 41.68.90.219:64408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nkyn25uliftkV1n4NhwAAAE8"]
[Tue Jul 21 07:44:35.331466 2026] [security2:error] [pid 296703:tid 296912] [client 41.68.90.219:64408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nkyn25uliftkV1n4NhwAAAE8"]
[Tue Jul 21 07:44:35.415650 2026] [security2:error] [pid 302018:tid 302264] [client 139.167.225.182:57363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nk4As9lPxxVAErz3noQAAAPc"]
[Tue Jul 21 07:44:35.415784 2026] [security2:error] [pid 302018:tid 302264] [client 139.167.225.182:57363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nk4As9lPxxVAErz3noQAAAPc"]
[Tue Jul 21 07:44:35.580974 2026] [security2:error] [pid 296703:tid 296941] [client 20.197.195.24:13807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/ms.php"] [unique_id "al9Nkyn25uliftkV1n4NkQAAAGw"]
[Tue Jul 21 07:44:35.658410 2026] [security2:error] [pid 296703:tid 296851] [client 122.162.144.145:5559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Nkyn25uliftkV1n4NkgAAABI"]
[Tue Jul 21 07:44:35.658540 2026] [security2:error] [pid 296703:tid 296851] [client 122.162.144.145:5559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Nkyn25uliftkV1n4NkgAAABI"]
[Tue Jul 21 07:44:35.694788 2026] [security2:error] [pid 296703:tid 296954] [client 20.197.195.24:13974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/min.php"] [unique_id "al9Nkyn25uliftkV1n4NkwAAAHk"]
[Tue Jul 21 07:44:35.815490 2026] [security2:error] [pid 296703:tid 296837] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Nkyn25uliftkV1n4NlQAABDw"]
[Tue Jul 21 07:44:35.929008 2026] [security2:error] [pid 296703:tid 296833] [client 103.29.114.44:55003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nkyn25uliftkV1n4NmAAAAAA"]
[Tue Jul 21 07:44:35.929105 2026] [security2:error] [pid 296703:tid 296833] [client 103.29.114.44:55003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nkyn25uliftkV1n4NmAAAAAA"]
[Tue Jul 21 07:44:35.971831 2026] [autoindex:error] [pid 302018:tid 302232] [client 20.197.195.24:13720] AH01276: Cannot serve directory /home3/klebe893/clubevendasonline.com/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:44:36.003983 2026] [security2:error] [pid 302018:tid 302248] [client 20.197.195.24:13720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/memberfuns.php"] [unique_id "al9NlIAs9lPxxVAErz3npQAAAOc"]
[Tue Jul 21 07:44:36.004454 2026] [security2:error] [pid 296703:tid 296904] [client 20.220.225.223:34182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/cron-tab.php"] [unique_id "al9NlCn25uliftkV1n4NmQAAAEc"]
[Tue Jul 21 07:44:36.060361 2026] [security2:error] [pid 296703:tid 296854] [client 20.197.195.24:13954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/dvjul.php"] [unique_id "al9NlCn25uliftkV1n4NngAAABU"]
[Tue Jul 21 07:44:36.134112 2026] [security2:error] [pid 302018:tid 302226] [client 136.144.33.103:56569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NlIAs9lPxxVAErz3npgAAANE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:44:36.153853 2026] [security2:error] [pid 296703:tid 296953] [client 20.197.195.24:14011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/biufile.php"] [unique_id "al9NlCn25uliftkV1n4NoAAAAHg"]
[Tue Jul 21 07:44:36.170903 2026] [security2:error] [pid 296703:tid 296927] [client 20.197.195.24:62663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/av.php"] [unique_id "al9NlCn25uliftkV1n4NoQAAAF4"]
[Tue Jul 21 07:44:36.196504 2026] [security2:error] [pid 296703:tid 296848] [client 20.197.195.24:14035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/coffexium.php"] [unique_id "al9NlCn25uliftkV1n4NogAAAA8"]
[Tue Jul 21 07:44:36.259308 2026] [security2:error] [pid 296703:tid 296864] [client 20.197.195.24:14002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/core.php"] [unique_id "al9NlCn25uliftkV1n4NowAAAB8"]
[Tue Jul 21 07:44:36.275200 2026] [security2:error] [pid 296703:tid 296920] [client 20.104.96.117:44100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9NlCn25uliftkV1n4NpAAAAFc"]
[Tue Jul 21 07:44:36.342477 2026] [security2:error] [pid 296703:tid 296868] [client 20.197.195.24:13813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/0.php"] [unique_id "al9NlCn25uliftkV1n4NqAAAACM"]
[Tue Jul 21 07:44:36.401145 2026] [security2:error] [pid 296703:tid 296907] [client 20.197.195.24:62666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/als.php"] [unique_id "al9NlCn25uliftkV1n4NrwAAAEo"]
[Tue Jul 21 07:44:36.492257 2026] [security2:error] [pid 296703:tid 296705] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NlCn25uliftkV1n4NsgAAfgE"]
[Tue Jul 21 07:44:36.492388 2026] [security2:error] [pid 296703:tid 296959] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NlCn25uliftkV1n4NsgAAfgE"]
[Tue Jul 21 07:44:36.498177 2026] [security2:error] [pid 302018:tid 302068] [remote 45.79.123.44:53048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "murilomattos.com"] [uri "/wp-login.php"] [unique_id "al9NlIAs9lPxxVAErz3nqgAA7i8"]
[Tue Jul 21 07:44:36.513917 2026] [security2:error] [pid 302018:tid 302057] [remote 119.195.102.159:43720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fisiopelvicafloripa.com.br"] [uri "/wp-login.php"] [unique_id "al9NlIAs9lPxxVAErz3nqwAAyCQ"]
[Tue Jul 21 07:44:36.531192 2026] [security2:error] [pid 302018:tid 302156] [client 20.197.195.24:13968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/simple.php"] [unique_id "al9NlIAs9lPxxVAErz3nrAAAAIs"]
[Tue Jul 21 07:44:36.548670 2026] [security2:error] [pid 302018:tid 302185] [client 20.226.60.151:60115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/0.php"] [unique_id "al9NlIAs9lPxxVAErz3nrQAAAKg"]
[Tue Jul 21 07:44:36.573572 2026] [security2:error] [pid 302018:tid 302197] [client 20.197.195.24:49809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/BDKR28.php"] [unique_id "al9NlIAs9lPxxVAErz3nrgAAALQ"]
[Tue Jul 21 07:44:36.650500 2026] [security2:error] [pid 296703:tid 296957] [client 20.197.195.24:13955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/init.php"] [unique_id "al9NlCn25uliftkV1n4NtgAAAHw"]
[Tue Jul 21 07:44:36.651598 2026] [security2:error] [pid 296703:tid 296761] [remote 67.207.94.191:56674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.94.207.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/wp-login.php"] [unique_id "al9NlCn25uliftkV1n4NtAAAZjk"]
[Tue Jul 21 07:44:36.720889 2026] [security2:error] [pid 296703:tid 296839] [client 173.24.185.52:60940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NlCn25uliftkV1n4NuAAAAAY"]
[Tue Jul 21 07:44:36.720986 2026] [security2:error] [pid 296703:tid 296839] [client 173.24.185.52:60940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NlCn25uliftkV1n4NuAAAAAY"]
[Tue Jul 21 07:44:36.808353 2026] [security2:error] [pid 296703:tid 296846] [client 20.197.195.24:14010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/fpwch.php"] [unique_id "al9NlCn25uliftkV1n4NuQAAAA0"]
[Tue Jul 21 07:44:36.899149 2026] [security2:error] [pid 296703:tid 296947] [client 122.179.91.63:16170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NlCn25uliftkV1n4NugAAAHI"]
[Tue Jul 21 07:44:36.899432 2026] [security2:error] [pid 296703:tid 296947] [client 122.179.91.63:16170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NlCn25uliftkV1n4NugAAAHI"]
[Tue Jul 21 07:44:37.025428 2026] [security2:error] [pid 302018:tid 302267] [client 20.197.195.24:62610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/domvf.php"] [unique_id "al9NlYAs9lPxxVAErz3nsAAAAPo"]
[Tue Jul 21 07:44:37.101278 2026] [security2:error] [pid 296703:tid 296843] [client 20.220.225.223:34287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/koiy.php"] [unique_id "al9NlSn25uliftkV1n4NwwAAAAo"]
[Tue Jul 21 07:44:37.150414 2026] [security2:error] [pid 302018:tid 302246] [client 20.197.195.24:49826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/green1.php"] [unique_id "al9NlYAs9lPxxVAErz3nsgAAAOU"]
[Tue Jul 21 07:44:37.301997 2026] [security2:error] [pid 302018:tid 302262] [client 20.197.195.24:14054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/wp.php"] [unique_id "al9NlYAs9lPxxVAErz3ntAAAAPU"]
[Tue Jul 21 07:44:37.440742 2026] [security2:error] [pid 296703:tid 296892] [client 74.7.175.144:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.gradiente.com"] [uri "/index.php"] [unique_id "al9NlCn25uliftkV1n4NqQAAADs"]
[Tue Jul 21 07:44:37.441551 2026] [security2:error] [pid 296703:tid 296873] [client 74.7.175.144:49892] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.gradiente.com"] [uri "/robots.txt"] [unique_id "al9NlCn25uliftkV1n4NpgAAKAo"]
[Tue Jul 21 07:44:37.648120 2026] [security2:error] [pid 296703:tid 296871] [client 20.104.96.117:44279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wefile.php"] [unique_id "al9NlSn25uliftkV1n4NzgAAACY"]
[Tue Jul 21 07:44:37.744267 2026] [security2:error] [pid 302018:tid 302155] [client 20.197.195.24:62620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/class.php"] [unique_id "al9NlYAs9lPxxVAErz3nuQAAAIo"]
[Tue Jul 21 07:44:37.815415 2026] [security2:error] [pid 302018:tid 302071] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NlYAs9lPxxVAErz3nugAApTI"]
[Tue Jul 21 07:44:37.815553 2026] [security2:error] [pid 302018:tid 302182] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NlYAs9lPxxVAErz3nugAApTI"]
[Tue Jul 21 07:44:37.843948 2026] [security2:error] [pid 302018:tid 302261] [client 103.166.103.129:63328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NlYAs9lPxxVAErz3nvAAAAPQ"]
[Tue Jul 21 07:44:37.844859 2026] [security2:error] [pid 302018:tid 302261] [client 103.166.103.129:63328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NlYAs9lPxxVAErz3nvAAAAPQ"]
[Tue Jul 21 07:44:37.906372 2026] [security2:error] [pid 296703:tid 296869] [client 74.7.175.144:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gradiente.com"] [uri "/index.php"] [unique_id "al9NlSn25uliftkV1n4N0AAAACQ"], referer: https://www.gradiente.com/robots.txt
[Tue Jul 21 07:44:37.907214 2026] [security2:error] [pid 296703:tid 296952] [client 74.7.175.144:49904] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gradiente.com"] [uri "/robots.txt"] [unique_id "al9NlSn25uliftkV1n4NzwAAdwA"], referer: https://www.gradiente.com/robots.txt
[Tue Jul 21 07:44:37.946612 2026] [security2:error] [pid 296703:tid 296927] [client 20.197.195.24:14008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/echkm.php"] [unique_id "al9NlSn25uliftkV1n4N1AAAAF4"]
[Tue Jul 21 07:44:38.014060 2026] [security2:error] [pid 296703:tid 296864] [client 20.197.195.24:62593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/lib.php"] [unique_id "al9Nlin25uliftkV1n4N1gAAAB8"]
[Tue Jul 21 07:44:38.058526 2026] [security2:error] [pid 296703:tid 296920] [client 20.197.195.24:62667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/login.php"] [unique_id "al9Nlin25uliftkV1n4N2AAAAFc"]
[Tue Jul 21 07:44:38.227744 2026] [security2:error] [pid 296703:tid 296835] [client 20.197.195.24:50323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/a2.php"] [unique_id "al9Nlin25uliftkV1n4N3gAAAAI"]
[Tue Jul 21 07:44:38.285515 2026] [security2:error] [pid 296703:tid 296932] [client 20.197.195.24:49847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/nc4.php"] [unique_id "al9Nlin25uliftkV1n4N3wAAAGM"]
[Tue Jul 21 07:44:38.462805 2026] [security2:error] [pid 302018:tid 302272] [client 20.197.195.24:62674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/d61.php"] [unique_id "al9NloAs9lPxxVAErz3nvwAAAP8"]
[Tue Jul 21 07:44:38.466822 2026] [security2:error] [pid 296703:tid 296936] [client 20.226.60.151:54297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/BDKR28.php"] [unique_id "al9Nlin25uliftkV1n4N4gAAAGc"]
[Tue Jul 21 07:44:38.583482 2026] [security2:error] [pid 302018:tid 302231] [client 182.8.255.181:17508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NloAs9lPxxVAErz3nxAAAANY"]
[Tue Jul 21 07:44:38.583614 2026] [security2:error] [pid 302018:tid 302231] [client 182.8.255.181:17508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NloAs9lPxxVAErz3nxAAAANY"]
[Tue Jul 21 07:44:38.664641 2026] [security2:error] [pid 302018:tid 302153] [client 20.197.195.24:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/info.php"] [unique_id "al9NloAs9lPxxVAErz3nxgAAAIg"]
[Tue Jul 21 07:44:38.849473 2026] [security2:error] [pid 302018:tid 302195] [client 74.249.245.134:5548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/666.php"] [unique_id "al9NloAs9lPxxVAErz3nyAAAALI"]
[Tue Jul 21 07:44:38.860624 2026] [security2:error] [pid 296703:tid 296728] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Nlin25uliftkV1n4N6gAALBg"]
[Tue Jul 21 07:44:38.860760 2026] [security2:error] [pid 296703:tid 296877] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Nlin25uliftkV1n4N6gAALBg"]
[Tue Jul 21 07:44:38.947056 2026] [security2:error] [pid 296703:tid 296857] [client 178.153.91.96:49402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Nlin25uliftkV1n4N6wAAABg"]
[Tue Jul 21 07:44:38.947223 2026] [security2:error] [pid 296703:tid 296857] [client 178.153.91.96:49402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Nlin25uliftkV1n4N6wAAABg"]
[Tue Jul 21 07:44:39.088316 2026] [security2:error] [pid 302018:tid 302222] [client 20.197.195.24:14065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/11.php"] [unique_id "al9Nl4As9lPxxVAErz3nygAAAM0"]
[Tue Jul 21 07:44:39.250682 2026] [security2:error] [pid 302018:tid 302275] [client 20.197.195.24:14009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/v2.php"] [unique_id "al9Nl4As9lPxxVAErz3nzAAAAQI"]
[Tue Jul 21 07:44:39.252775 2026] [security2:error] [pid 302018:tid 302158] [client 103.86.117.203:59972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Nl4As9lPxxVAErz3nzQAAAI0"]
[Tue Jul 21 07:44:39.252909 2026] [security2:error] [pid 302018:tid 302158] [client 103.86.117.203:59972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Nl4As9lPxxVAErz3nzQAAAI0"]
[Tue Jul 21 07:44:39.286659 2026] [security2:error] [pid 302018:tid 302243] [client 106.215.181.8:26051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nl4As9lPxxVAErz3n0AAAAOI"]
[Tue Jul 21 07:44:39.286779 2026] [security2:error] [pid 302018:tid 302243] [client 106.215.181.8:26051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nl4As9lPxxVAErz3n0AAAAOI"]
[Tue Jul 21 07:44:39.317146 2026] [security2:error] [pid 302018:tid 302176] [client 20.197.195.24:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/panel.php"] [unique_id "al9Nl4As9lPxxVAErz3n0gAAAJ8"]
[Tue Jul 21 07:44:39.494938 2026] [security2:error] [pid 296703:tid 296843] [client 20.197.195.24:49915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/a1.php"] [unique_id "al9Nlyn25uliftkV1n4N9QAAAAo"]
[Tue Jul 21 07:44:39.548669 2026] [security2:error] [pid 296703:tid 296740] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Nlyn25uliftkV1n4N9gAAeiQ"]
[Tue Jul 21 07:44:39.548790 2026] [security2:error] [pid 296703:tid 296955] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Nlyn25uliftkV1n4N9gAAeiQ"]
[Tue Jul 21 07:44:39.563184 2026] [security2:error] [pid 296703:tid 296845] [client 20.197.195.24:62678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/dex.php"] [unique_id "al9Nlyn25uliftkV1n4N-QAAAAw"]
[Tue Jul 21 07:44:39.691348 2026] [security2:error] [pid 302018:tid 302197] [client 20.104.96.117:44128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9Nl4As9lPxxVAErz3n1QAAALQ"]
[Tue Jul 21 07:44:39.730792 2026] [security2:error] [pid 302018:tid 302264] [client 103.174.34.15:61984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nl4As9lPxxVAErz3n1gAAAPc"]
[Tue Jul 21 07:44:39.730897 2026] [security2:error] [pid 302018:tid 302264] [client 103.174.34.15:61984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nl4As9lPxxVAErz3n1gAAAPc"]
[Tue Jul 21 07:44:39.789290 2026] [security2:error] [pid 302018:tid 302247] [client 117.220.45.16:50674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.45.220.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "overkotz.com"] [uri "/xmlrpc.php"] [unique_id "al9Nl4As9lPxxVAErz3n0wAAAOY"]
[Tue Jul 21 07:44:39.789445 2026] [security2:error] [pid 302018:tid 302247] [client 117.220.45.16:50674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "overkotz.com"] [uri "/xmlrpc.php"] [unique_id "al9Nl4As9lPxxVAErz3n0wAAAOY"]
[Tue Jul 21 07:44:39.861750 2026] [security2:error] [pid 302018:tid 302159] [client 193.36.225.64:46617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Nl4As9lPxxVAErz3n3AAAAI4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:44:39.899691 2026] [core:error] [pid 302018:tid 302073] [remote 198.235.24.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:44:39.899711 2026] [core:error] [pid 302018:tid 302073] [remote 198.235.24.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:44:39.972523 2026] [security2:error] [pid 296703:tid 296793] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nlyn25uliftkV1n4OAwAAK1k"]
[Tue Jul 21 07:44:39.972720 2026] [security2:error] [pid 296703:tid 296876] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nlyn25uliftkV1n4OAwAAK1k"]
[Tue Jul 21 07:44:40.061372 2026] [security2:error] [pid 302018:tid 302246] [client 20.197.195.24:13959] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "sistedu-mec.com"] [uri "/1.php"] [unique_id "al9NmIAs9lPxxVAErz3n4AAAAOU"]
[Tue Jul 21 07:44:40.061491 2026] [security2:error] [pid 302018:tid 302246] [client 20.197.195.24:13959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/1.php"] [unique_id "al9NmIAs9lPxxVAErz3n4AAAAOU"]
[Tue Jul 21 07:44:40.287004 2026] [security2:error] [pid 302018:tid 302207] [client 20.220.225.223:34298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/hp2.php"] [unique_id "al9NmIAs9lPxxVAErz3n5QAAAL4"]
[Tue Jul 21 07:44:40.306581 2026] [security2:error] [pid 296703:tid 296945] [client 122.164.127.47:61487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NmCn25uliftkV1n4ODAAAAHA"]
[Tue Jul 21 07:44:40.306702 2026] [security2:error] [pid 296703:tid 296945] [client 122.164.127.47:61487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NmCn25uliftkV1n4ODAAAAHA"]
[Tue Jul 21 07:44:40.432835 2026] [security2:error] [pid 302018:tid 302224] [client 20.104.96.117:30636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/19.php"] [unique_id "al9NmIAs9lPxxVAErz3n5wAAAM8"]
[Tue Jul 21 07:44:40.453761 2026] [security2:error] [pid 302018:tid 302253] [client 20.197.195.24:49812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/eee.php"] [unique_id "al9NmIAs9lPxxVAErz3n6AAAAOw"]
[Tue Jul 21 07:44:40.667650 2026] [security2:error] [pid 296703:tid 296864] [client 20.197.195.24:62632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/ms.php"] [unique_id "al9NmCn25uliftkV1n4OEQAAAB8"]
[Tue Jul 21 07:44:40.741000 2026] [security2:error] [pid 302018:tid 302169] [client 128.127.105.184:48892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9NmIAs9lPxxVAErz3n8wAAAJg"]
[Tue Jul 21 07:44:40.741111 2026] [security2:error] [pid 302018:tid 302169] [client 128.127.105.184:48892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9NmIAs9lPxxVAErz3n8wAAAJg"]
[Tue Jul 21 07:44:40.747545 2026] [security2:error] [pid 302018:tid 302225] [client 20.226.114.112:1194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "revistareflexopolitico.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9NmIAs9lPxxVAErz3n9AAAANA"]
[Tue Jul 21 07:44:40.829291 2026] [security2:error] [pid 296703:tid 296723] [remote 103.74.123.7:24724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.123.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "darsenavogamarine.com"] [uri "/wp-login.php"] [unique_id "al9NmCn25uliftkV1n4OFQAAFRM"]
[Tue Jul 21 07:44:40.861306 2026] [security2:error] [pid 302018:tid 302208] [client 20.226.114.112:1175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.114.226.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "revistareflexopolitico.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NmIAs9lPxxVAErz3n9gAAAL8"]
[Tue Jul 21 07:44:40.895220 2026] [security2:error] [pid 296703:tid 296890] [client 109.60.28.94:58002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nlin25uliftkV1n4N3AAAADk"]
[Tue Jul 21 07:44:41.080776 2026] [security2:error] [pid 302018:tid 302158] [client 20.220.225.223:34298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/wp-css.php"] [unique_id "al9NmYAs9lPxxVAErz3oAgAAAI0"]
[Tue Jul 21 07:44:41.085743 2026] [security2:error] [pid 296703:tid 296914] [client 74.249.245.134:5555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/byp.php"] [unique_id "al9NmSn25uliftkV1n4OGAAAAFE"]
[Tue Jul 21 07:44:41.131733 2026] [security2:error] [pid 302018:tid 302232] [client 20.63.100.92:7068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/edit.php"] [unique_id "al9NmYAs9lPxxVAErz3oBAAAANc"]
[Tue Jul 21 07:44:41.150059 2026] [security2:error] [pid 302018:tid 302226] [client 20.226.114.112:1191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.114.226.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "revistareflexopolitico.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NmYAs9lPxxVAErz3oBQAAANE"]
[Tue Jul 21 07:44:41.150135 2026] [security2:error] [pid 302018:tid 302226] [client 20.226.114.112:1191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "revistareflexopolitico.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NmYAs9lPxxVAErz3oBQAAANE"]
[Tue Jul 21 07:44:41.306294 2026] [security2:error] [pid 302018:tid 302065] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NmYAs9lPxxVAErz3oCAAAyCw"]
[Tue Jul 21 07:44:41.306455 2026] [security2:error] [pid 302018:tid 302217] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NmYAs9lPxxVAErz3oCAAAyCw"]
[Tue Jul 21 07:44:41.567614 2026] [autoindex:error] [pid 296703:tid 296905] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/blissf00/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:44:41.627975 2026] [security2:error] [pid 296703:tid 296894] [client 117.247.80.59:23918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NmSn25uliftkV1n4OIgAAAD0"]
[Tue Jul 21 07:44:41.628096 2026] [security2:error] [pid 296703:tid 296894] [client 117.247.80.59:23918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NmSn25uliftkV1n4OIgAAAD0"]
[Tue Jul 21 07:44:41.649450 2026] [security2:error] [pid 296703:tid 296835] [client 117.251.86.144:34720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NmSn25uliftkV1n4OJAAAAAI"]
[Tue Jul 21 07:44:41.649550 2026] [security2:error] [pid 296703:tid 296835] [client 117.251.86.144:34720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NmSn25uliftkV1n4OJAAAAAI"]
[Tue Jul 21 07:44:41.668404 2026] [security2:error] [pid 296703:tid 296846] [client 20.226.60.151:60144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/green1.php"] [unique_id "al9NmSn25uliftkV1n4OJQAAAA0"]
[Tue Jul 21 07:44:41.705137 2026] [security2:error] [pid 302018:tid 302252] [client 122.186.204.214:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NmYAs9lPxxVAErz3oEwAAAOs"]
[Tue Jul 21 07:44:41.705236 2026] [security2:error] [pid 302018:tid 302252] [client 122.186.204.214:62789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NmYAs9lPxxVAErz3oEwAAAOs"]
[Tue Jul 21 07:44:41.727415 2026] [security2:error] [pid 302018:tid 302246] [client 20.220.225.223:34178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/hp3.php"] [unique_id "al9NmYAs9lPxxVAErz3oFAAAAOU"]
[Tue Jul 21 07:44:41.745880 2026] [security2:error] [pid 296703:tid 296875] [client 20.197.195.24:49813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/wp-aothait.php"] [unique_id "al9NmSn25uliftkV1n4OKgAAACo"]
[Tue Jul 21 07:44:41.813238 2026] [security2:error] [pid 302018:tid 302273] [client 20.220.225.223:34207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/wp-explorer.php"] [unique_id "al9NmYAs9lPxxVAErz3oFwAAAQA"]
[Tue Jul 21 07:44:41.901904 2026] [autoindex:error] [pid 302018:tid 302171] [client 20.104.96.117:44208] AH01276: Cannot serve directory /home2/blissf00/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:44:41.983145 2026] [security2:error] [pid 296703:tid 296901] [client 20.197.195.24:62606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/memberfuns.php"] [unique_id "al9NmSn25uliftkV1n4OLwAAAEQ"]
[Tue Jul 21 07:44:42.074364 2026] [security2:error] [pid 302018:tid 302259] [client 194.99.104.35:43390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NmoAs9lPxxVAErz3oHAAAAPI"]
[Tue Jul 21 07:44:42.074466 2026] [security2:error] [pid 302018:tid 302259] [client 194.99.104.35:43390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NmoAs9lPxxVAErz3oHAAAAPI"]
[Tue Jul 21 07:44:42.135502 2026] [security2:error] [pid 302018:tid 302165] [client 20.197.195.24:13742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/config.json.php"] [unique_id "al9NmoAs9lPxxVAErz3oHQAAAJQ"]
[Tue Jul 21 07:44:42.172855 2026] [security2:error] [pid 296703:tid 296836] [client 117.217.38.194:55961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nmin25uliftkV1n4OMQAAAAM"]
[Tue Jul 21 07:44:42.172993 2026] [security2:error] [pid 296703:tid 296836] [client 117.217.38.194:55961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nmin25uliftkV1n4OMQAAAAM"]
[Tue Jul 21 07:44:42.234070 2026] [security2:error] [pid 296703:tid 296884] [client 20.197.195.24:13979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/0.php"] [unique_id "al9Nmin25uliftkV1n4ONQAAADM"]
[Tue Jul 21 07:44:42.301061 2026] [security2:error] [pid 302018:tid 302191] [client 20.197.195.24:62684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/BDKR28.php"] [unique_id "al9NmoAs9lPxxVAErz3oIAAAAK4"]
[Tue Jul 21 07:44:42.321129 2026] [security2:error] [pid 302018:tid 302152] [client 20.197.195.24:62642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/green1.php"] [unique_id "al9NmoAs9lPxxVAErz3oIgAAAIc"]
[Tue Jul 21 07:44:42.342244 2026] [security2:error] [pid 302018:tid 302258] [client 20.197.195.24:14021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/nc4.php"] [unique_id "al9NmoAs9lPxxVAErz3oJQAAAPE"]
[Tue Jul 21 07:44:42.386449 2026] [security2:error] [pid 302018:tid 302208] [client 20.197.195.24:14039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/a1.php"] [unique_id "al9NmoAs9lPxxVAErz3oKAAAAL8"]
[Tue Jul 21 07:44:42.409699 2026] [security2:error] [pid 302018:tid 302168] [client 20.197.195.24:13991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/eee.php"] [unique_id "al9NmoAs9lPxxVAErz3oKQAAAJc"]
[Tue Jul 21 07:44:42.515918 2026] [security2:error] [pid 296703:tid 296893] [client 20.197.195.24:62650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/wp-aothait.php"] [unique_id "al9Nmin25uliftkV1n4OOAAAADw"]
[Tue Jul 21 07:44:42.544088 2026] [security2:error] [pid 296703:tid 296838] [client 20.197.195.24:13719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9Nmin25uliftkV1n4OOQAAAAU"]
[Tue Jul 21 07:44:42.607606 2026] [security2:error] [pid 296703:tid 296911] [client 20.197.195.24:14051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/config.json.php"] [unique_id "al9Nmin25uliftkV1n4OOgAAAE4"]
[Tue Jul 21 07:44:42.629182 2026] [security2:error] [pid 302018:tid 302249] [client 20.104.96.117:44208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-admin/css/colour.php"] [unique_id "al9NmoAs9lPxxVAErz3oKwAAAOg"]
[Tue Jul 21 07:44:42.683562 2026] [security2:error] [pid 302018:tid 302157] [client 20.197.195.24:14031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9NmoAs9lPxxVAErz3oLQAAAIw"]
[Tue Jul 21 07:44:42.738911 2026] [security2:error] [pid 296703:tid 296909] [client 20.197.195.24:50311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/k2.php"] [unique_id "al9Nmin25uliftkV1n4OPwAAAEw"]
[Tue Jul 21 07:44:42.817235 2026] [security2:error] [pid 296703:tid 296952] [client 20.197.195.24:50316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/uiuvs58l.php"] [unique_id "al9Nmin25uliftkV1n4OQAAAAHc"]
[Tue Jul 21 07:44:42.856783 2026] [security2:error] [pid 302018:tid 302170] [client 20.197.195.24:62677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/40p9ixjd.php"] [unique_id "al9NmoAs9lPxxVAErz3oMwAAAJk"]
[Tue Jul 21 07:44:42.986834 2026] [security2:error] [pid 302018:tid 302172] [client 154.192.233.199:59871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NmoAs9lPxxVAErz3oNQAAAJs"]
[Tue Jul 21 07:44:42.987939 2026] [security2:error] [pid 302018:tid 302172] [client 154.192.233.199:59871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NmoAs9lPxxVAErz3oNQAAAJs"]
[Tue Jul 21 07:44:43.009488 2026] [security2:error] [pid 302018:tid 302183] [client 216.73.160.193:23463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9Nm4As9lPxxVAErz3oNgAAAKY"]
[Tue Jul 21 07:44:43.025921 2026] [security2:error] [pid 296703:tid 296858] [client 20.197.195.24:62613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9Nmyn25uliftkV1n4ORAAAABk"]
[Tue Jul 21 07:44:43.130690 2026] [security2:error] [pid 296703:tid 296943] [client 20.197.195.24:49887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/k2.php"] [unique_id "al9Nmyn25uliftkV1n4ORgAAAG4"]
[Tue Jul 21 07:44:43.149504 2026] [security2:error] [pid 302018:tid 302217] [client 173.252.95.6:59434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Nm4As9lPxxVAErz3oOAAAAMg"]
[Tue Jul 21 07:44:43.266913 2026] [security2:error] [pid 302018:tid 302264] [client 74.7.241.167:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "vitorrafaeldossantos1743267721255.0711679.myhostgator.site"] [uri "/robots.txt"] [unique_id "al9Nm4As9lPxxVAErz3oPAAA90A"]
[Tue Jul 21 07:44:43.361731 2026] [security2:error] [pid 302018:tid 302151] [client 20.220.225.223:34229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/aa1.php"] [unique_id "al9Nm4As9lPxxVAErz3oPwAAAIY"]
[Tue Jul 21 07:44:43.446462 2026] [security2:error] [pid 302018:tid 302268] [client 216.73.160.41:28339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9Nm4As9lPxxVAErz3oQgAAAPs"]
[Tue Jul 21 07:44:43.527375 2026] [security2:error] [pid 302018:tid 302253] [client 20.197.195.24:62686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/for.php"] [unique_id "al9Nm4As9lPxxVAErz3oRAAAAOw"]
[Tue Jul 21 07:44:43.594265 2026] [security2:error] [pid 302018:tid 302182] [client 20.197.195.24:13969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sistedu-mec.com"] [uri "/raw.php"] [unique_id "al9Nm4As9lPxxVAErz3oRQAAAKU"]
[Tue Jul 21 07:44:43.625687 2026] [security2:error] [pid 302018:tid 302261] [client 20.104.96.117:44286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/8.php"] [unique_id "al9Nm4As9lPxxVAErz3oRgAAAPQ"]
[Tue Jul 21 07:44:43.664477 2026] [security2:error] [pid 302018:tid 302105] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nm4As9lPxxVAErz3oRwAAs1Q"]
[Tue Jul 21 07:44:43.664632 2026] [security2:error] [pid 302018:tid 302196] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nm4As9lPxxVAErz3oRwAAs1Q"]
[Tue Jul 21 07:44:43.682622 2026] [security2:error] [pid 302018:tid 302191] [client 20.197.195.24:13760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/uiuvs58l.php"] [unique_id "al9Nm4As9lPxxVAErz3oSAAAAK4"]
[Tue Jul 21 07:44:43.843259 2026] [security2:error] [pid 302018:tid 302272] [client 20.104.96.117:30612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/inc.php"] [unique_id "al9Nm4As9lPxxVAErz3oTQAAAP8"]
[Tue Jul 21 07:44:44.011100 2026] [security2:error] [pid 296703:tid 296860] [client 20.63.100.92:2630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/kua.php"] [unique_id "al9NnCn25uliftkV1n4OUAAAABs"]
[Tue Jul 21 07:44:44.196540 2026] [security2:error] [pid 302018:tid 302269] [client 202.143.127.214:55687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NnIAs9lPxxVAErz3oUQAAAPw"]
[Tue Jul 21 07:44:44.196682 2026] [security2:error] [pid 302018:tid 302269] [client 202.143.127.214:55687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NnIAs9lPxxVAErz3oUQAAAPw"]
[Tue Jul 21 07:44:44.448625 2026] [security2:error] [pid 302018:tid 302223] [client 216.73.160.40:53631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9Nm4As9lPxxVAErz3oQQAAAM4"]
[Tue Jul 21 07:44:44.461473 2026] [security2:error] [pid 296703:tid 296835] [client 20.104.96.117:44241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-content/admin.php"] [unique_id "al9NnCn25uliftkV1n4OXgAAAAI"]
[Tue Jul 21 07:44:44.507761 2026] [security2:error] [pid 302018:tid 302157] [client 20.197.195.24:13799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/40p9ixjd.php"] [unique_id "al9NnIAs9lPxxVAErz3oVQAAAIw"]
[Tue Jul 21 07:44:44.570298 2026] [security2:error] [pid 296703:tid 296869] [client 136.144.33.104:54677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NnCn25uliftkV1n4OXQAAACQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:44:44.646444 2026] [security2:error] [pid 302018:tid 302234] [client 59.96.220.140:64199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NnIAs9lPxxVAErz3oVwAAANk"]
[Tue Jul 21 07:44:44.647472 2026] [security2:error] [pid 302018:tid 302234] [client 59.96.220.140:64199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NnIAs9lPxxVAErz3oVwAAANk"]
[Tue Jul 21 07:44:44.674003 2026] [security2:error] [pid 302018:tid 302250] [client 20.226.60.151:54323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/nc4.php"] [unique_id "al9NnIAs9lPxxVAErz3oWAAAAOk"]
[Tue Jul 21 07:44:44.906985 2026] [security2:error] [pid 296703:tid 296880] [client 74.249.245.134:62852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/date.php"] [unique_id "al9NnCn25uliftkV1n4OZAAAAC8"]
[Tue Jul 21 07:44:45.046016 2026] [security2:error] [pid 296703:tid 296808] [remote 199.189.225.40:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9NnSn25uliftkV1n4OaQAAQmg"]
[Tue Jul 21 07:44:45.088937 2026] [security2:error] [pid 296703:tid 296836] [client 20.104.96.117:44255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/f6.php"] [unique_id "al9NnSn25uliftkV1n4OawAAAAM"]
[Tue Jul 21 07:44:45.169953 2026] [security2:error] [pid 302018:tid 302200] [client 216.73.160.176:61985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9Nm4As9lPxxVAErz3oNwAAALc"]
[Tue Jul 21 07:44:45.546709 2026] [security2:error] [pid 302018:tid 302276] [client 152.59.154.239:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NnYAs9lPxxVAErz3oZAAAAQM"]
[Tue Jul 21 07:44:45.546833 2026] [security2:error] [pid 302018:tid 302276] [client 152.59.154.239:59907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NnYAs9lPxxVAErz3oZAAAAQM"]
[Tue Jul 21 07:44:45.635876 2026] [security2:error] [pid 302018:tid 302192] [client 20.104.96.117:30444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9NnYAs9lPxxVAErz3oZwAAAK8"]
[Tue Jul 21 07:44:45.704265 2026] [security2:error] [pid 302018:tid 302187] [client 20.104.96.117:44271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/inputs.php"] [unique_id "al9NnYAs9lPxxVAErz3oaAAAAKo"]
[Tue Jul 21 07:44:45.887778 2026] [security2:error] [pid 296703:tid 296838] [client 41.68.90.219:64801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NnSn25uliftkV1n4OeQAAAAU"]
[Tue Jul 21 07:44:45.889059 2026] [security2:error] [pid 296703:tid 296838] [client 41.68.90.219:64801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NnSn25uliftkV1n4OeQAAAAU"]
[Tue Jul 21 07:44:46.021147 2026] [security2:error] [pid 302018:tid 302224] [client 184.75.223.211:51636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9NnoAs9lPxxVAErz3obQAAAM8"]
[Tue Jul 21 07:44:46.021248 2026] [security2:error] [pid 302018:tid 302224] [client 184.75.223.211:51636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9NnoAs9lPxxVAErz3obQAAAM8"]
[Tue Jul 21 07:44:46.025284 2026] [security2:error] [pid 302018:tid 302253] [client 20.197.195.24:49903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9NnoAs9lPxxVAErz3obgAAAOw"]
[Tue Jul 21 07:44:46.088158 2026] [security2:error] [pid 302018:tid 302180] [client 37.140.223.152:45119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NnoAs9lPxxVAErz3ocQAAAKM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:44:46.184372 2026] [security2:error] [pid 302018:tid 302191] [client 20.226.60.151:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/a1.php"] [unique_id "al9NnoAs9lPxxVAErz3ocgAAAK4"]
[Tue Jul 21 07:44:46.264022 2026] [security2:error] [pid 302018:tid 302172] [client 139.167.225.182:58019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NnoAs9lPxxVAErz3ocwAAAJs"]
[Tue Jul 21 07:44:46.264190 2026] [security2:error] [pid 302018:tid 302172] [client 139.167.225.182:58019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NnoAs9lPxxVAErz3ocwAAAJs"]
[Tue Jul 21 07:44:46.273599 2026] [security2:error] [pid 302018:tid 302169] [client 20.104.96.117:44133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/inputs.php"] [unique_id "al9NnoAs9lPxxVAErz3odAAAAJg"]
[Tue Jul 21 07:44:46.388926 2026] [security2:error] [pid 302018:tid 302194] [client 122.162.144.145:19836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NnoAs9lPxxVAErz3odwAAALE"]
[Tue Jul 21 07:44:46.389080 2026] [security2:error] [pid 302018:tid 302194] [client 122.162.144.145:19836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NnoAs9lPxxVAErz3odwAAALE"]
[Tue Jul 21 07:44:46.401052 2026] [security2:error] [pid 302018:tid 302261] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9NnoAs9lPxxVAErz3odQAA9FM"]
[Tue Jul 21 07:44:46.682769 2026] [security2:error] [pid 302018:tid 302155] [client 103.29.114.44:40225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NnoAs9lPxxVAErz3oeQAAAIo"]
[Tue Jul 21 07:44:46.682878 2026] [security2:error] [pid 302018:tid 302155] [client 103.29.114.44:40225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NnoAs9lPxxVAErz3oeQAAAIo"]
[Tue Jul 21 07:44:46.965533 2026] [security2:error] [pid 302018:tid 302226] [client 20.104.96.117:44249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/classwithtostring.php"] [unique_id "al9NnoAs9lPxxVAErz3ohwAAANE"]
[Tue Jul 21 07:44:46.991019 2026] [security2:error] [pid 302018:tid 302107] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NnoAs9lPxxVAErz3oiAAA8FY"]
[Tue Jul 21 07:44:46.991189 2026] [security2:error] [pid 302018:tid 302257] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NnoAs9lPxxVAErz3oiAAA8FY"]
[Tue Jul 21 07:44:47.077887 2026] [security2:error] [pid 302018:tid 302157] [client 173.24.185.52:61448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Nn4As9lPxxVAErz3ojgAAAIw"]
[Tue Jul 21 07:44:47.078016 2026] [security2:error] [pid 302018:tid 302157] [client 173.24.185.52:61448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Nn4As9lPxxVAErz3ojgAAAIw"]
[Tue Jul 21 07:44:47.288024 2026] [security2:error] [pid 302018:tid 302197] [client 20.226.60.151:61986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/eee.php"] [unique_id "al9Nn4As9lPxxVAErz3olgAAALQ"]
[Tue Jul 21 07:44:47.681545 2026] [security2:error] [pid 302018:tid 302165] [client 74.249.245.134:17464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/pomo.php"] [unique_id "al9Nn4As9lPxxVAErz3ooQAAAJQ"]
[Tue Jul 21 07:44:47.849078 2026] [security2:error] [pid 302018:tid 302254] [client 184.75.223.211:51640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Nn4As9lPxxVAErz3oogAAAO0"]
[Tue Jul 21 07:44:47.849198 2026] [security2:error] [pid 302018:tid 302254] [client 184.75.223.211:51640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Nn4As9lPxxVAErz3oogAAAO0"]
[Tue Jul 21 07:44:48.133909 2026] [security2:error] [pid 296703:tid 296923] [client 20.104.96.117:44251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-content/themes/index.php"] [unique_id "al9NoCn25uliftkV1n4OowAAAFo"]
[Tue Jul 21 07:44:48.140101 2026] [security2:error] [pid 296703:tid 296940] [client 20.197.195.24:13736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/for.php"] [unique_id "al9NoCn25uliftkV1n4OpAAAAGs"]
[Tue Jul 21 07:44:48.382037 2026] [security2:error] [pid 296703:tid 296899] [client 20.226.60.151:54324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-aothait.php"] [unique_id "al9NoCn25uliftkV1n4OpwAAAEI"]
[Tue Jul 21 07:44:48.419173 2026] [security2:error] [pid 302018:tid 302242] [client 193.36.225.105:40027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NoIAs9lPxxVAErz3oqAAAAOE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:44:48.554099 2026] [security2:error] [pid 302018:tid 302114] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NoIAs9lPxxVAErz3orAAA310"]
[Tue Jul 21 07:44:48.554267 2026] [security2:error] [pid 302018:tid 302240] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NoIAs9lPxxVAErz3orAAA310"]
[Tue Jul 21 07:44:48.568259 2026] [security2:error] [pid 302018:tid 302180] [client 103.166.103.129:63842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NoIAs9lPxxVAErz3orgAAAKM"]
[Tue Jul 21 07:44:48.568582 2026] [security2:error] [pid 302018:tid 302180] [client 103.166.103.129:63842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NoIAs9lPxxVAErz3orgAAAKM"]
[Tue Jul 21 07:44:48.920230 2026] [security2:error] [pid 302018:tid 302157] [client 20.220.225.223:34287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/akismet.php"] [unique_id "al9NoIAs9lPxxVAErz3oswAAAIw"]
[Tue Jul 21 07:44:48.993539 2026] [security2:error] [pid 302018:tid 302150] [client 182.8.255.181:17196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NoIAs9lPxxVAErz3otAAAAIU"]
[Tue Jul 21 07:44:48.993731 2026] [security2:error] [pid 302018:tid 302150] [client 182.8.255.181:17196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NoIAs9lPxxVAErz3otAAAAIU"]
[Tue Jul 21 07:44:49.123361 2026] [security2:error] [pid 296703:tid 296871] [client 20.226.60.151:54354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/config.json.php"] [unique_id "al9NoSn25uliftkV1n4OtgAAACY"]
[Tue Jul 21 07:44:49.177870 2026] [security2:error] [pid 296703:tid 296881] [client 20.104.96.117:30865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9NoSn25uliftkV1n4OuQAAADA"]
[Tue Jul 21 07:44:49.223181 2026] [security2:error] [pid 296703:tid 296960] [client 20.220.225.223:53449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/ftde.php"] [unique_id "al9NoSn25uliftkV1n4OuwAAAH8"]
[Tue Jul 21 07:44:49.236139 2026] [security2:error] [pid 302018:tid 302185] [client 20.104.96.117:44166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-blog.php"] [unique_id "al9NoYAs9lPxxVAErz3ouQAAAKg"]
[Tue Jul 21 07:44:49.324562 2026] [security2:error] [pid 302018:tid 302275] [client 109.60.28.94:8091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NoYAs9lPxxVAErz3ouAAAAQI"]
[Tue Jul 21 07:44:49.422955 2026] [security2:error] [pid 302018:tid 302214] [client 178.153.91.96:50044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NoYAs9lPxxVAErz3ovgAAAMU"]
[Tue Jul 21 07:44:49.423115 2026] [security2:error] [pid 302018:tid 302214] [client 178.153.91.96:50044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NoYAs9lPxxVAErz3ovgAAAMU"]
[Tue Jul 21 07:44:49.692710 2026] [security2:error] [pid 296703:tid 296888] [client 20.63.100.92:5262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/ez.php"] [unique_id "al9NoSn25uliftkV1n4OwgAAADc"]
[Tue Jul 21 07:44:49.735198 2026] [security2:error] [pid 296703:tid 296911] [client 103.86.117.203:60519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NoSn25uliftkV1n4OxgAAAE4"]
[Tue Jul 21 07:44:49.735312 2026] [security2:error] [pid 296703:tid 296911] [client 103.86.117.203:60519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NoSn25uliftkV1n4OxgAAAE4"]
[Tue Jul 21 07:44:49.768018 2026] [security2:error] [pid 296703:tid 296745] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NoSn25uliftkV1n4OxwAAOSk"]
[Tue Jul 21 07:44:49.768162 2026] [security2:error] [pid 296703:tid 296890] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NoSn25uliftkV1n4OxwAAOSk"]
[Tue Jul 21 07:44:49.837056 2026] [security2:error] [pid 302018:tid 302255] [client 106.215.181.8:3822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NoYAs9lPxxVAErz3owQAAAO4"]
[Tue Jul 21 07:44:49.837172 2026] [security2:error] [pid 302018:tid 302255] [client 106.215.181.8:3822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NoYAs9lPxxVAErz3owQAAAO4"]
[Tue Jul 21 07:44:50.039663 2026] [security2:error] [pid 296703:tid 296956] [client 20.197.195.24:13753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clubevendasonline.com"] [uri "/raw.php"] [unique_id "al9Noin25uliftkV1n4OygAAAHs"]
[Tue Jul 21 07:44:50.060795 2026] [security2:error] [pid 296703:tid 296907] [client 74.249.245.134:54393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/test1.php"] [unique_id "al9Noin25uliftkV1n4OzAAAAEo"]
[Tue Jul 21 07:44:50.169044 2026] [security2:error] [pid 302018:tid 302099] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NooAs9lPxxVAErz3oxQAA604"]
[Tue Jul 21 07:44:50.169196 2026] [security2:error] [pid 302018:tid 302252] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NooAs9lPxxVAErz3oxQAA604"]
[Tue Jul 21 07:44:50.306245 2026] [security2:error] [pid 296703:tid 296914] [client 20.220.225.223:53489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/yup.php"] [unique_id "al9Noin25uliftkV1n4O0gAAAFE"]
[Tue Jul 21 07:44:50.445335 2026] [security2:error] [pid 302018:tid 302165] [client 136.144.33.98:61351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NooAs9lPxxVAErz3oyAAAAJQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:44:50.478565 2026] [security2:error] [pid 302018:tid 302224] [client 20.226.60.151:60103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9NooAs9lPxxVAErz3oyQAAAM8"]
[Tue Jul 21 07:44:50.552416 2026] [security2:error] [pid 296703:tid 296868] [client 103.174.34.15:62478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Noin25uliftkV1n4O1AAAACM"]
[Tue Jul 21 07:44:50.552585 2026] [security2:error] [pid 296703:tid 296868] [client 103.174.34.15:62478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Noin25uliftkV1n4O1AAAACM"]
[Tue Jul 21 07:44:50.567762 2026] [security2:error] [pid 296703:tid 296803] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Noin25uliftkV1n4O1QAAGWM"]
[Tue Jul 21 07:44:50.567909 2026] [security2:error] [pid 296703:tid 296858] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Noin25uliftkV1n4O1QAAGWM"]
[Tue Jul 21 07:44:50.775024 2026] [autoindex:error] [pid 296703:tid 296898] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/blissf00/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:44:51.055705 2026] [security2:error] [pid 296703:tid 296925] [client 20.104.96.117:44273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-content/admin.php"] [unique_id "al9Noyn25uliftkV1n4O4wAAAFw"]
[Tue Jul 21 07:44:51.057896 2026] [security2:error] [pid 302018:tid 302268] [client 122.164.127.47:62068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9No4As9lPxxVAErz3ozgAAAPs"]
[Tue Jul 21 07:44:51.058029 2026] [security2:error] [pid 302018:tid 302268] [client 122.164.127.47:62068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9No4As9lPxxVAErz3ozgAAAPs"]
[Tue Jul 21 07:44:51.354364 2026] [security2:error] [pid 302018:tid 302225] [client 62.102.148.187:51224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9No4As9lPxxVAErz3o1AAAANA"]
[Tue Jul 21 07:44:51.354466 2026] [security2:error] [pid 302018:tid 302225] [client 62.102.148.187:51224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9No4As9lPxxVAErz3o1AAAANA"]
[Tue Jul 21 07:44:51.563201 2026] [security2:error] [pid 302018:tid 302152] [client 74.249.245.134:54374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/fw.php"] [unique_id "al9No4As9lPxxVAErz3o1wAAAIc"]
[Tue Jul 21 07:44:51.599396 2026] [security2:error] [pid 302018:tid 302236] [client 37.140.223.157:42697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9No4As9lPxxVAErz3o1gAAANs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:44:51.647999 2026] [security2:error] [pid 296703:tid 296873] [client 20.220.225.223:34223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/acew67.php"] [unique_id "al9Noyn25uliftkV1n4O7AAAACg"]
[Tue Jul 21 07:44:51.840214 2026] [security2:error] [pid 302018:tid 302130] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9No4As9lPxxVAErz3o2AAA-W0"]
[Tue Jul 21 07:44:51.840348 2026] [security2:error] [pid 302018:tid 302266] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9No4As9lPxxVAErz3o2AAA-W0"]
[Tue Jul 21 07:44:52.386706 2026] [security2:error] [pid 296703:tid 296833] [client 122.186.204.214:63321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NpCn25uliftkV1n4PBAAAAAA"]
[Tue Jul 21 07:44:52.386847 2026] [security2:error] [pid 296703:tid 296833] [client 122.186.204.214:63321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NpCn25uliftkV1n4PBAAAAAA"]
[Tue Jul 21 07:44:52.454411 2026] [security2:error] [pid 302018:tid 302164] [client 184.75.223.211:55952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NpIAs9lPxxVAErz3o6AAAAJM"]
[Tue Jul 21 07:44:52.454511 2026] [security2:error] [pid 302018:tid 302164] [client 184.75.223.211:55952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NpIAs9lPxxVAErz3o6AAAAJM"]
[Tue Jul 21 07:44:52.506033 2026] [security2:error] [pid 302018:tid 302222] [client 20.104.96.117:44115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/ms-edit.php"] [unique_id "al9NpIAs9lPxxVAErz3o6QAAAM0"]
[Tue Jul 21 07:44:52.546373 2026] [security2:error] [pid 296703:tid 296916] [client 117.251.86.144:50026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NpCn25uliftkV1n4PBgAAAFM"]
[Tue Jul 21 07:44:52.546516 2026] [security2:error] [pid 296703:tid 296916] [client 117.251.86.144:50026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NpCn25uliftkV1n4PBgAAAFM"]
[Tue Jul 21 07:44:52.633015 2026] [security2:error] [pid 302018:tid 302174] [client 74.249.245.134:17422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/fm.php"] [unique_id "al9NpIAs9lPxxVAErz3o6wAAAJ0"]
[Tue Jul 21 07:44:52.658683 2026] [security2:error] [pid 296703:tid 296960] [client 117.217.38.194:56448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NpCn25uliftkV1n4PBwAAAH8"]
[Tue Jul 21 07:44:52.658838 2026] [security2:error] [pid 296703:tid 296960] [client 117.217.38.194:56448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NpCn25uliftkV1n4PBwAAAH8"]
[Tue Jul 21 07:44:52.994425 2026] [security2:error] [pid 296703:tid 296850] [client 184.75.223.211:55960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NpCn25uliftkV1n4PDwAAABE"]
[Tue Jul 21 07:44:52.994538 2026] [security2:error] [pid 296703:tid 296850] [client 184.75.223.211:55960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9NpCn25uliftkV1n4PDwAAABE"]
[Tue Jul 21 07:44:53.143211 2026] [security2:error] [pid 296703:tid 296957] [client 20.226.60.151:54375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/k2.php"] [unique_id "al9NpSn25uliftkV1n4PEQAAAHw"]
[Tue Jul 21 07:44:53.303520 2026] [security2:error] [pid 302018:tid 302137] [remote 192.241.143.148:39602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fgengenharia.eng.br"] [uri "/wp-login.php"] [unique_id "al9NpYAs9lPxxVAErz3o8QAA5HQ"]
[Tue Jul 21 07:44:53.318004 2026] [security2:error] [pid 296703:tid 296890] [client 117.247.80.59:23177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NpSn25uliftkV1n4PGQAAADk"]
[Tue Jul 21 07:44:53.318116 2026] [security2:error] [pid 296703:tid 296890] [client 117.247.80.59:23177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NpSn25uliftkV1n4PGQAAADk"]
[Tue Jul 21 07:44:53.569731 2026] [security2:error] [pid 302018:tid 302235] [client 154.192.233.199:59551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NpYAs9lPxxVAErz3o9QAAANo"]
[Tue Jul 21 07:44:53.569863 2026] [security2:error] [pid 302018:tid 302235] [client 154.192.233.199:59551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NpYAs9lPxxVAErz3o9QAAANo"]
[Tue Jul 21 07:44:53.608027 2026] [security2:error] [pid 302018:tid 302252] [client 20.220.225.223:34248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/bscclapb.php"] [unique_id "al9NpYAs9lPxxVAErz3o9wAAAOs"]
[Tue Jul 21 07:44:53.714289 2026] [security2:error] [pid 296703:tid 296797] [remote 37.60.226.168:40660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.226.60.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9NpSn25uliftkV1n4PIwAAFl0"]
[Tue Jul 21 07:44:53.954594 2026] [security2:error] [pid 296703:tid 296928] [client 20.104.96.117:44118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/cgi-bin/index.php"] [unique_id "al9NpSn25uliftkV1n4PJgAAAF8"]
[Tue Jul 21 07:44:54.063934 2026] [security2:error] [pid 296703:tid 296959] [client 136.144.33.100:46497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Npin25uliftkV1n4PKAAAAH4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:44:54.194644 2026] [security2:error] [pid 302018:tid 302179] [client 194.99.104.35:37302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9NpoAs9lPxxVAErz3pBwAAAKI"]
[Tue Jul 21 07:44:54.194727 2026] [security2:error] [pid 302018:tid 302179] [client 194.99.104.35:37302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9NpoAs9lPxxVAErz3pBwAAAKI"]
[Tue Jul 21 07:44:54.200381 2026] [security2:error] [pid 302018:tid 302236] [client 74.249.245.134:54342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/ini.php"] [unique_id "al9NpoAs9lPxxVAErz3pCAAAANs"]
[Tue Jul 21 07:44:54.338436 2026] [security2:error] [pid 296703:tid 296876] [client 62.102.148.187:51248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Npin25uliftkV1n4PLQAAACs"]
[Tue Jul 21 07:44:54.338541 2026] [security2:error] [pid 296703:tid 296876] [client 62.102.148.187:51248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Npin25uliftkV1n4PLQAAACs"]
[Tue Jul 21 07:44:54.759747 2026] [security2:error] [pid 302018:tid 302042] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NpoAs9lPxxVAErz3pFgAApRU"]
[Tue Jul 21 07:44:54.759924 2026] [security2:error] [pid 302018:tid 302182] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NpoAs9lPxxVAErz3pFgAApRU"]
[Tue Jul 21 07:44:54.915468 2026] [security2:error] [pid 302018:tid 302257] [client 20.220.225.223:53495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/jj.php"] [unique_id "al9NpoAs9lPxxVAErz3pGQAAAPA"]
[Tue Jul 21 07:44:55.040442 2026] [access_compat:error] [pid 296703:tid 296933] [client 162.241.63.68:34554] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:44:55.077973 2026] [autoindex:error] [pid 302018:tid 302186] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/blissf00/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:44:55.298639 2026] [security2:error] [pid 302018:tid 302223] [client 202.143.127.214:56109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Np4As9lPxxVAErz3pcQAAAM4"]
[Tue Jul 21 07:44:55.298769 2026] [security2:error] [pid 302018:tid 302223] [client 202.143.127.214:56109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Np4As9lPxxVAErz3pcQAAAM4"]
[Tue Jul 21 07:44:55.552541 2026] [security2:error] [pid 296703:tid 296943] [client 74.249.245.134:54347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/themes.php"] [unique_id "al9Npyn25uliftkV1n4PRgAAAG4"]
[Tue Jul 21 07:44:55.674934 2026] [security2:error] [pid 296703:tid 296923] [client 172.245.102.29:32705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NpSn25uliftkV1n4PHgAAAFo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:44:55.772712 2026] [security2:error] [pid 302018:tid 302211] [client 20.220.225.223:34244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/else1.php"] [unique_id "al9Np4As9lPxxVAErz3pfgAAAMI"]
[Tue Jul 21 07:44:55.797684 2026] [security2:error] [pid 302018:tid 302177] [client 20.104.96.117:44103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/BDKR28WP.php"] [unique_id "al9Np4As9lPxxVAErz3pfwAAAKA"]
[Tue Jul 21 07:44:56.019371 2026] [security2:error] [pid 302018:tid 302261] [client 20.226.60.151:54296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9NqIAs9lPxxVAErz3phQAAAPQ"]
[Tue Jul 21 07:44:56.144892 2026] [security2:error] [pid 302018:tid 302215] [client 62.102.148.187:56548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NqIAs9lPxxVAErz3phwAAAMY"]
[Tue Jul 21 07:44:56.144988 2026] [security2:error] [pid 302018:tid 302215] [client 62.102.148.187:56548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9NqIAs9lPxxVAErz3phwAAAMY"]
[Tue Jul 21 07:44:56.594567 2026] [security2:error] [pid 302018:tid 302255] [client 152.59.154.239:60404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NqIAs9lPxxVAErz3pigAAAO4"]
[Tue Jul 21 07:44:56.594687 2026] [security2:error] [pid 302018:tid 302255] [client 152.59.154.239:60404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NqIAs9lPxxVAErz3pigAAAO4"]
[Tue Jul 21 07:44:56.698541 2026] [security2:error] [pid 302018:tid 302194] [client 41.68.90.219:65199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NqIAs9lPxxVAErz3piwAAALE"]
[Tue Jul 21 07:44:56.698715 2026] [security2:error] [pid 302018:tid 302194] [client 41.68.90.219:65199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NqIAs9lPxxVAErz3piwAAALE"]
[Tue Jul 21 07:44:56.964608 2026] [autoindex:error] [pid 302018:tid 302269] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/blissf00/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:44:57.047985 2026] [security2:error] [pid 302018:tid 302171] [client 139.167.225.182:58677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3pkAAAAJo"]
[Tue Jul 21 07:44:57.049801 2026] [security2:error] [pid 302018:tid 302171] [client 139.167.225.182:58677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3pkAAAAJo"]
[Tue Jul 21 07:44:57.050848 2026] [security2:error] [pid 296703:tid 296935] [client 74.249.245.134:62911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/dropdown.php"] [unique_id "al9NqSn25uliftkV1n4PXQAAAGY"]
[Tue Jul 21 07:44:57.051048 2026] [security2:error] [pid 296703:tid 296934] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9NqCn25uliftkV1n4PWwAAZRY"]
[Tue Jul 21 07:44:57.180129 2026] [security2:error] [pid 302018:tid 302152] [client 103.29.114.44:50286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3plAAAAIc"]
[Tue Jul 21 07:44:57.180281 2026] [security2:error] [pid 302018:tid 302152] [client 103.29.114.44:50286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3plAAAAIc"]
[Tue Jul 21 07:44:57.234880 2026] [security2:error] [pid 302018:tid 302238] [client 122.162.144.145:24160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3plQAAAN0"]
[Tue Jul 21 07:44:57.235082 2026] [security2:error] [pid 302018:tid 302238] [client 122.162.144.145:24160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3plQAAAN0"]
[Tue Jul 21 07:44:57.294451 2026] [autoindex:error] [pid 302018:tid 302257] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/blissf00/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:44:57.433031 2026] [security2:error] [pid 302018:tid 302195] [client 20.104.96.117:30873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/ss.php"] [unique_id "al9NqYAs9lPxxVAErz3pmgAAALI"]
[Tue Jul 21 07:44:57.532188 2026] [security2:error] [pid 302018:tid 302026] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3pnQAAqQU"]
[Tue Jul 21 07:44:57.532331 2026] [security2:error] [pid 302018:tid 302186] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3pnQAAqQU"]
[Tue Jul 21 07:44:57.629162 2026] [security2:error] [pid 302018:tid 302197] [client 128.127.105.184:56802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3poAAAALQ"]
[Tue Jul 21 07:44:57.629274 2026] [security2:error] [pid 302018:tid 302197] [client 128.127.105.184:56802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3poAAAALQ"]
[Tue Jul 21 07:44:57.655888 2026] [security2:error] [pid 302018:tid 302150] [client 173.24.185.52:61930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3poQAAAIU"]
[Tue Jul 21 07:44:57.656004 2026] [security2:error] [pid 302018:tid 302150] [client 173.24.185.52:61930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3poQAAAIU"]
[Tue Jul 21 07:44:57.804767 2026] [security2:error] [pid 302018:tid 302217] [client 20.104.96.117:44130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/abcd.php"] [unique_id "al9NqYAs9lPxxVAErz3pogAAAMg"]
[Tue Jul 21 07:44:57.903616 2026] [security2:error] [pid 302018:tid 302265] [client 128.127.105.184:42902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3powAAAPg"]
[Tue Jul 21 07:44:57.903728 2026] [security2:error] [pid 302018:tid 302265] [client 128.127.105.184:42902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3powAAAPg"]
[Tue Jul 21 07:44:57.974675 2026] [security2:error] [pid 302018:tid 302250] [client 122.179.91.63:22843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3ppAAAAOk"]
[Tue Jul 21 07:44:57.974796 2026] [security2:error] [pid 302018:tid 302250] [client 122.179.91.63:22843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NqYAs9lPxxVAErz3ppAAAAOk"]
[Tue Jul 21 07:44:58.064896 2026] [core:error] [pid 302018:tid 302027] [remote 2600:1f16:743:ac02:233c:ec46:b0a2:6f83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:44:58.064922 2026] [core:error] [pid 302018:tid 302027] [remote 2600:1f16:743:ac02:233c:ec46:b0a2:6f83:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:44:58.122249 2026] [security2:error] [pid 296703:tid 296937] [client 59.96.220.140:64695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Nqin25uliftkV1n4PbQAAAGg"]
[Tue Jul 21 07:44:58.122366 2026] [security2:error] [pid 296703:tid 296937] [client 59.96.220.140:64695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Nqin25uliftkV1n4PbQAAAGg"]
[Tue Jul 21 07:44:58.145366 2026] [security2:error] [pid 296703:tid 296901] [client 4.204.201.85:9357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Nqin25uliftkV1n4PbgAAAEQ"]
[Tue Jul 21 07:44:58.431549 2026] [security2:error] [pid 302018:tid 302212] [client 4.204.201.85:9360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NqoAs9lPxxVAErz3prQAAAMM"]
[Tue Jul 21 07:44:58.485790 2026] [security2:error] [pid 296703:tid 296867] [client 74.249.245.134:54365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/wp-links.php"] [unique_id "al9Nqin25uliftkV1n4PdwAAACI"]
[Tue Jul 21 07:44:58.543920 2026] [security2:error] [pid 296703:tid 296863] [client 20.104.96.117:44145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/file15.php"] [unique_id "al9Nqin25uliftkV1n4PeQAAAB4"]
[Tue Jul 21 07:44:58.552735 2026] [security2:error] [pid 296703:tid 296887] [client 20.220.225.223:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/tkikikoko.php"] [unique_id "al9Nqin25uliftkV1n4PegAAADY"]
[Tue Jul 21 07:44:58.645880 2026] [security2:error] [pid 296703:tid 296843] [client 193.36.225.72:24545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Nqin25uliftkV1n4PdAAAAAo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:44:58.711919 2026] [security2:error] [pid 296703:tid 296911] [client 4.204.201.85:22051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/x.php"] [unique_id "al9Nqin25uliftkV1n4PggAAAE4"]
[Tue Jul 21 07:44:58.777270 2026] [security2:error] [pid 296703:tid 296854] [client 184.75.223.211:42852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Nqin25uliftkV1n4PhAAAABU"]
[Tue Jul 21 07:44:58.777375 2026] [security2:error] [pid 296703:tid 296854] [client 184.75.223.211:42852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Nqin25uliftkV1n4PhAAAABU"]
[Tue Jul 21 07:44:58.953954 2026] [security2:error] [pid 296703:tid 296850] [client 20.220.225.223:34267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bkp.liranesuliano.com.br"] [uri "/ace2.php"] [unique_id "al9Nqin25uliftkV1n4PiQAAABE"]
[Tue Jul 21 07:44:59.047586 2026] [security2:error] [pid 296703:tid 296894] [client 4.204.201.85:22046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/mgrr.php"] [unique_id "al9Nqyn25uliftkV1n4PjQAAAD0"]
[Tue Jul 21 07:44:59.270836 2026] [security2:error] [pid 302018:tid 302162] [client 103.166.103.129:15551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Nq4As9lPxxVAErz3puAAAAJE"]
[Tue Jul 21 07:44:59.270947 2026] [security2:error] [pid 302018:tid 302162] [client 103.166.103.129:15551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Nq4As9lPxxVAErz3puAAAAJE"]
[Tue Jul 21 07:44:59.342391 2026] [security2:error] [pid 302018:tid 302038] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nq4As9lPxxVAErz3puQAAohE"]
[Tue Jul 21 07:44:59.342558 2026] [security2:error] [pid 302018:tid 302179] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nq4As9lPxxVAErz3puQAAohE"]
[Tue Jul 21 07:44:59.378637 2026] [security2:error] [pid 296703:tid 296856] [client 4.204.201.85:9312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/stdin.php"] [unique_id "al9Nqyn25uliftkV1n4PkwAAABc"]
[Tue Jul 21 07:44:59.516063 2026] [security2:error] [pid 296703:tid 296945] [client 182.8.255.181:17568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Nqyn25uliftkV1n4PlwAAAHA"]
[Tue Jul 21 07:44:59.516169 2026] [security2:error] [pid 296703:tid 296945] [client 182.8.255.181:17568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Nqyn25uliftkV1n4PlwAAAHA"]
[Tue Jul 21 07:44:59.686521 2026] [security2:error] [pid 302018:tid 302182] [client 20.226.60.151:60155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9Nq4As9lPxxVAErz3puwAAAKU"]
[Tue Jul 21 07:44:59.687882 2026] [security2:error] [pid 302018:tid 302201] [client 4.204.201.85:22018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/BDKR28.php"] [unique_id "al9Nq4As9lPxxVAErz3pvAAAALg"]
[Tue Jul 21 07:44:59.940155 2026] [security2:error] [pid 302018:tid 302236] [client 109.60.28.94:59022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nq4As9lPxxVAErz3pvgAAANs"]
[Tue Jul 21 07:44:59.976478 2026] [security2:error] [pid 302018:tid 302243] [client 4.204.201.85:22052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/001.php"] [unique_id "al9Nq4As9lPxxVAErz3pwAAAAOI"]
[Tue Jul 21 07:44:59.989564 2026] [security2:error] [pid 302018:tid 302263] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Nq4As9lPxxVAErz3pwQAAAPY"]
[Tue Jul 21 07:45:00.029566 2026] [security2:error] [pid 302018:tid 302171] [client 178.153.91.96:50656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NrIAs9lPxxVAErz3pxQAAAJo"]
[Tue Jul 21 07:45:00.029681 2026] [security2:error] [pid 302018:tid 302171] [client 178.153.91.96:50656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NrIAs9lPxxVAErz3pxQAAAJo"]
[Tue Jul 21 07:45:00.056733 2026] [security2:error] [pid 302018:tid 302184] [client 20.104.96.117:44106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/jp.php"] [unique_id "al9NrIAs9lPxxVAErz3pxgAAAKc"]
[Tue Jul 21 07:45:00.217103 2026] [security2:error] [pid 296703:tid 296914] [client 103.86.117.203:61061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NrCn25uliftkV1n4PowAAAFE"]
[Tue Jul 21 07:45:00.217215 2026] [security2:error] [pid 296703:tid 296914] [client 103.86.117.203:61061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NrCn25uliftkV1n4PowAAAFE"]
[Tue Jul 21 07:45:00.258558 2026] [security2:error] [pid 296703:tid 296959] [client 4.204.201.85:9402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/dZ3wP5.php"] [unique_id "al9NrCn25uliftkV1n4PpgAAAH4"]
[Tue Jul 21 07:45:00.309624 2026] [security2:error] [pid 302018:tid 302183] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NrIAs9lPxxVAErz3pzAAAAKY"]
[Tue Jul 21 07:45:00.323056 2026] [security2:error] [pid 296703:tid 296722] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NrCn25uliftkV1n4PpwAAAxI"]
[Tue Jul 21 07:45:00.323187 2026] [security2:error] [pid 296703:tid 296836] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NrCn25uliftkV1n4PpwAAAxI"]
[Tue Jul 21 07:45:00.381297 2026] [security2:error] [pid 302018:tid 302031] [remote 209.97.182.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "falarmelhor.com.br"] [uri "/wp-login.php"] [unique_id "al9NrIAs9lPxxVAErz3pzQAAqAo"]
[Tue Jul 21 07:45:00.567352 2026] [security2:error] [pid 296703:tid 296839] [client 106.215.181.8:2333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NrCn25uliftkV1n4PrAAAAAY"]
[Tue Jul 21 07:45:00.567457 2026] [security2:error] [pid 296703:tid 296839] [client 106.215.181.8:2333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NrCn25uliftkV1n4PrAAAAAY"]
[Tue Jul 21 07:45:00.576621 2026] [security2:error] [pid 302018:tid 302245] [client 4.204.201.85:22071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/yup.php"] [unique_id "al9NrIAs9lPxxVAErz3pzwAAAOQ"]
[Tue Jul 21 07:45:00.623029 2026] [security2:error] [pid 302018:tid 302180] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/media.php"] [unique_id "al9NrIAs9lPxxVAErz3p0QAAAKM"]
[Tue Jul 21 07:45:00.720039 2026] [security2:error] [pid 296703:tid 296759] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NrCn25uliftkV1n4PsQAACzc"]
[Tue Jul 21 07:45:00.720190 2026] [security2:error] [pid 296703:tid 296844] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NrCn25uliftkV1n4PsQAACzc"]
[Tue Jul 21 07:45:00.866184 2026] [security2:error] [pid 296703:tid 296853] [client 4.204.201.85:22025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/X.php"] [unique_id "al9NrCn25uliftkV1n4PswAAABQ"]
[Tue Jul 21 07:45:00.906133 2026] [security2:error] [pid 302018:tid 302045] [remote 209.42.18.223:52346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/wp-login.php"] [unique_id "al9NrIAs9lPxxVAErz3p1AAAqhg"]
[Tue Jul 21 07:45:00.908821 2026] [security2:error] [pid 302018:tid 302165] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/images.php"] [unique_id "al9NrIAs9lPxxVAErz3p1QAAAJQ"]
[Tue Jul 21 07:45:00.972247 2026] [security2:error] [pid 296703:tid 296837] [client 74.249.245.134:62887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/xmrlpc.php"] [unique_id "al9NrCn25uliftkV1n4PtAAAAAQ"]
[Tue Jul 21 07:45:01.155525 2026] [security2:error] [pid 296703:tid 296866] [client 4.204.201.85:21954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/1polka.php"] [unique_id "al9NrSn25uliftkV1n4PuQAAACE"]
[Tue Jul 21 07:45:01.158147 2026] [security2:error] [pid 296703:tid 296960] [client 20.220.225.223:34203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wp-Blogs.php"] [unique_id "al9NrSn25uliftkV1n4PugAAAH8"]
[Tue Jul 21 07:45:01.173041 2026] [security2:error] [pid 302018:tid 302055] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NrYAs9lPxxVAErz3p1gAA7CI"]
[Tue Jul 21 07:45:01.173167 2026] [security2:error] [pid 302018:tid 302253] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NrYAs9lPxxVAErz3p1gAA7CI"]
[Tue Jul 21 07:45:01.207183 2026] [security2:error] [pid 296703:tid 296878] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/gecko.php"] [unique_id "al9NrSn25uliftkV1n4PvQAAAC0"]
[Tue Jul 21 07:45:01.356522 2026] [security2:error] [pid 296703:tid 296845] [client 122.164.127.47:62941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NrSn25uliftkV1n4PwQAAAAw"]
[Tue Jul 21 07:45:01.356620 2026] [security2:error] [pid 296703:tid 296845] [client 122.164.127.47:62941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NrSn25uliftkV1n4PwQAAAAw"]
[Tue Jul 21 07:45:01.375374 2026] [security2:error] [pid 302018:tid 302192] [client 103.174.34.15:62952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NrYAs9lPxxVAErz3p2QAAAK8"]
[Tue Jul 21 07:45:01.413259 2026] [security2:error] [pid 296703:tid 296882] [client 20.104.96.117:30599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/min.php"] [unique_id "al9NrSn25uliftkV1n4PwgAAADE"]
[Tue Jul 21 07:45:01.436922 2026] [security2:error] [pid 296703:tid 296913] [client 4.204.201.85:9319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/gec.php"] [unique_id "al9NrSn25uliftkV1n4PwwAAAFA"]
[Tue Jul 21 07:45:01.491274 2026] [security2:error] [pid 296703:tid 296848] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/82.php"] [unique_id "al9NrSn25uliftkV1n4PxAAAAA8"]
[Tue Jul 21 07:45:01.587701 2026] [security2:error] [pid 302018:tid 302172] [client 20.104.96.117:44280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/f35.php"] [unique_id "al9NrYAs9lPxxVAErz3p2wAAAJs"]
[Tue Jul 21 07:45:01.726648 2026] [security2:error] [pid 296703:tid 296905] [client 4.204.201.85:9318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/sky.php"] [unique_id "al9NrSn25uliftkV1n4PzgAAAEg"]
[Tue Jul 21 07:45:01.745441 2026] [security2:error] [pid 296703:tid 296880] [client 20.226.60.151:61959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9NrSn25uliftkV1n4PzwAAAC8"]
[Tue Jul 21 07:45:01.778836 2026] [security2:error] [pid 296703:tid 296833] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/admin.php"] [unique_id "al9NrSn25uliftkV1n4P0AAAAAA"]
[Tue Jul 21 07:45:02.004424 2026] [security2:error] [pid 302018:tid 302166] [client 4.204.201.85:9308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/fffm.php"] [unique_id "al9NroAs9lPxxVAErz3p3QAAAJU"]
[Tue Jul 21 07:45:02.079426 2026] [security2:error] [pid 296703:tid 296891] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/adminner.php"] [unique_id "al9Nrin25uliftkV1n4P2QAAADo"]
[Tue Jul 21 07:45:02.289568 2026] [security2:error] [pid 302018:tid 302194] [client 4.204.201.85:22055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/sixxis.php"] [unique_id "al9NroAs9lPxxVAErz3p4gAAALE"]
[Tue Jul 21 07:45:02.348606 2026] [security2:error] [pid 302018:tid 302266] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/admin.php"] [unique_id "al9NroAs9lPxxVAErz3p4wAAAPk"]
[Tue Jul 21 07:45:02.361643 2026] [security2:error] [pid 302018:tid 302189] [client 172.245.102.41:45893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NroAs9lPxxVAErz3p5AAAAKw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:45:02.389856 2026] [security2:error] [pid 296703:tid 296802] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Nrin25uliftkV1n4P4AAAemI"]
[Tue Jul 21 07:45:02.390006 2026] [security2:error] [pid 296703:tid 296955] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Nrin25uliftkV1n4P4AAAemI"]
[Tue Jul 21 07:45:02.418335 2026] [security2:error] [pid 302018:tid 302192] [client 103.174.34.15:62952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NrYAs9lPxxVAErz3p2QAAAK8"]
[Tue Jul 21 07:45:02.577528 2026] [security2:error] [pid 296703:tid 296881] [client 20.104.96.117:44141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-load.php"] [unique_id "al9Nrin25uliftkV1n4P4wAAADA"]
[Tue Jul 21 07:45:02.580067 2026] [security2:error] [pid 296703:tid 296921] [client 4.204.201.85:9347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/yj09.php"] [unique_id "al9Nrin25uliftkV1n4P5AAAAFg"]
[Tue Jul 21 07:45:02.625510 2026] [security2:error] [pid 296703:tid 296926] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/k.php"] [unique_id "al9Nrin25uliftkV1n4P5QAAAF0"]
[Tue Jul 21 07:45:02.809492 2026] [autoindex:error] [pid 296703:tid 296838] [client 98.91.173.173:5355] AH01276: Cannot serve directory /home2/onfiel33/lucaskotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:02.858529 2026] [security2:error] [pid 296703:tid 296837] [client 4.204.201.85:9370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/f900.php"] [unique_id "al9Nrin25uliftkV1n4P7gAAAAQ"]
[Tue Jul 21 07:45:02.943533 2026] [security2:error] [pid 302018:tid 302163] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/blurbs.php"] [unique_id "al9NroAs9lPxxVAErz3p7AAAAJI"]
[Tue Jul 21 07:45:02.958918 2026] [security2:error] [pid 302018:tid 302241] [client 117.247.80.59:24447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NroAs9lPxxVAErz3p7QAAAOA"]
[Tue Jul 21 07:45:02.959079 2026] [security2:error] [pid 302018:tid 302241] [client 117.247.80.59:24447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NroAs9lPxxVAErz3p7QAAAOA"]
[Tue Jul 21 07:45:03.007344 2026] [security2:error] [pid 302018:tid 302071] [remote 130.51.180.8:44580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "platinumcleaningkansas.com"] [uri "/wp-login.php"] [unique_id "al9Nr4As9lPxxVAErz3p7gAApTI"]
[Tue Jul 21 07:45:03.115359 2026] [security2:error] [pid 302018:tid 302215] [client 122.186.204.214:63849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Nr4As9lPxxVAErz3p7wAAAMY"]
[Tue Jul 21 07:45:03.115491 2026] [security2:error] [pid 302018:tid 302215] [client 122.186.204.214:63849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Nr4As9lPxxVAErz3p7wAAAMY"]
[Tue Jul 21 07:45:03.125729 2026] [security2:error] [pid 302018:tid 302220] [client 117.217.38.194:56942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nr4As9lPxxVAErz3p8AAAAMs"]
[Tue Jul 21 07:45:03.125871 2026] [security2:error] [pid 302018:tid 302220] [client 117.217.38.194:56942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nr4As9lPxxVAErz3p8AAAAMs"]
[Tue Jul 21 07:45:03.137001 2026] [security2:error] [pid 296703:tid 296863] [client 4.204.201.85:9297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/ups.php"] [unique_id "al9Nryn25uliftkV1n4P8QAAAB4"]
[Tue Jul 21 07:45:03.261718 2026] [security2:error] [pid 296703:tid 296909] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/bajah.php"] [unique_id "al9Nryn25uliftkV1n4P9wAAAEw"]
[Tue Jul 21 07:45:03.322459 2026] [security2:error] [pid 296703:tid 296942] [client 74.249.245.134:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/htaccess.php"] [unique_id "al9Nryn25uliftkV1n4P-AAAAG0"]
[Tue Jul 21 07:45:03.329663 2026] [security2:error] [pid 296703:tid 296937] [client 65.21.232.200:26428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.232.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-comments-post.php"] [unique_id "al9Nryn25uliftkV1n4P8gAAAGg"], referer: https://valloratoodo.com/hello-world/#comment-6613
[Tue Jul 21 07:45:03.329758 2026] [security2:error] [pid 296703:tid 296937] [client 65.21.232.200:26428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "valloratoodo.com"] [uri "/wp-comments-post.php"] [unique_id "al9Nryn25uliftkV1n4P8gAAAGg"], referer: https://valloratoodo.com/hello-world/#comment-6613
[Tue Jul 21 07:45:03.368484 2026] [security2:error] [pid 296703:tid 296960] [client 20.226.60.151:61980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/for.php"] [unique_id "al9Nryn25uliftkV1n4P-gAAAH8"]
[Tue Jul 21 07:45:03.437784 2026] [security2:error] [pid 302018:tid 302214] [client 4.204.201.85:9326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/k.php"] [unique_id "al9Nr4As9lPxxVAErz3p9gAAAMU"]
[Tue Jul 21 07:45:03.514401 2026] [security2:error] [pid 296703:tid 296901] [client 117.251.86.144:34866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Nryn25uliftkV1n4P_AAAAEQ"]
[Tue Jul 21 07:45:03.514559 2026] [security2:error] [pid 296703:tid 296901] [client 117.251.86.144:34866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Nryn25uliftkV1n4P_AAAAEQ"]
[Tue Jul 21 07:45:03.538429 2026] [security2:error] [pid 302018:tid 302264] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/a.php"] [unique_id "al9Nr4As9lPxxVAErz3p-AAAAPc"]
[Tue Jul 21 07:45:03.576136 2026] [security2:error] [pid 302018:tid 302270] [client 62.102.148.187:46098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Nr4As9lPxxVAErz3p-QAAAP0"]
[Tue Jul 21 07:45:03.576228 2026] [security2:error] [pid 302018:tid 302270] [client 62.102.148.187:46098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Nr4As9lPxxVAErz3p-QAAAP0"]
[Tue Jul 21 07:45:03.722861 2026] [security2:error] [pid 302018:tid 302239] [client 4.204.201.85:22042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/k2.php"] [unique_id "al9Nr4As9lPxxVAErz3p-wAAAN4"]
[Tue Jul 21 07:45:03.815665 2026] [security2:error] [pid 296703:tid 296958] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/edit.php"] [unique_id "al9Nryn25uliftkV1n4QAQAAAH0"]
[Tue Jul 21 07:45:03.819203 2026] [security2:error] [pid 302018:tid 302191] [client 128.127.105.184:40954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Nr4As9lPxxVAErz3qAAAAAK4"]
[Tue Jul 21 07:45:03.819273 2026] [security2:error] [pid 302018:tid 302191] [client 128.127.105.184:40954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Nr4As9lPxxVAErz3qAAAAAK4"]
[Tue Jul 21 07:45:04.002657 2026] [security2:error] [pid 296703:tid 296890] [client 4.204.201.85:9393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/w.php"] [unique_id "al9NsCn25uliftkV1n4QBAAAADk"]
[Tue Jul 21 07:45:04.098811 2026] [security2:error] [pid 302018:tid 302172] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/hosty.php"] [unique_id "al9NsIAs9lPxxVAErz3qAwAAAJs"]
[Tue Jul 21 07:45:04.120515 2026] [security2:error] [pid 302018:tid 302227] [client 74.7.175.154:45014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "teste.inonebrasil.com.br"] [uri "/index.php"] [unique_id "al9NsIAs9lPxxVAErz3qAgAA0h4"]
[Tue Jul 21 07:45:04.149908 2026] [security2:error] [pid 296703:tid 296939] [client 20.104.96.117:44104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xyn.php"] [unique_id "al9NsCn25uliftkV1n4QBwAAAGo"]
[Tue Jul 21 07:45:04.164166 2026] [security2:error] [pid 302018:tid 302245] [client 154.192.233.199:58919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NsIAs9lPxxVAErz3qBAAAAOQ"]
[Tue Jul 21 07:45:04.164309 2026] [security2:error] [pid 302018:tid 302245] [client 154.192.233.199:58919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NsIAs9lPxxVAErz3qBAAAAOQ"]
[Tue Jul 21 07:45:04.304156 2026] [security2:error] [pid 302018:tid 302181] [client 4.204.201.85:9316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/fpwch.php"] [unique_id "al9NsIAs9lPxxVAErz3qBgAAAKQ"]
[Tue Jul 21 07:45:04.390199 2026] [security2:error] [pid 296703:tid 296884] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/k.php"] [unique_id "al9NsCn25uliftkV1n4QDwAAADM"]
[Tue Jul 21 07:45:04.591403 2026] [security2:error] [pid 296703:tid 296959] [client 4.204.201.85:21966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/w2025.php"] [unique_id "al9NsCn25uliftkV1n4QEwAAAH4"]
[Tue Jul 21 07:45:04.626606 2026] [security2:error] [pid 302018:tid 302205] [client 20.104.96.117:30639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9NsIAs9lPxxVAErz3qCAAAALw"]
[Tue Jul 21 07:45:04.713123 2026] [security2:error] [pid 296703:tid 296899] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/aaa.php"] [unique_id "al9NsCn25uliftkV1n4QFQAAAEI"]
[Tue Jul 21 07:45:04.872303 2026] [security2:error] [pid 302018:tid 302189] [client 4.204.201.85:22077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/FWAZ.php"] [unique_id "al9NsIAs9lPxxVAErz3qCgAAAKw"]
[Tue Jul 21 07:45:04.921364 2026] [security2:error] [pid 296703:tid 296786] [remote 13.41.15.21:43508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.15.41.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9NsCn25uliftkV1n4QHgAAUVI"]
[Tue Jul 21 07:45:04.995945 2026] [security2:error] [pid 296703:tid 296926] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/file5.php"] [unique_id "al9NsCn25uliftkV1n4QIAAAAF0"]
[Tue Jul 21 07:45:05.039892 2026] [autoindex:error] [pid 296703:tid 296871] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/blissf00/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:05.092629 2026] [security2:error] [pid 302018:tid 302208] [client 20.220.225.223:60362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/dragonshell.php"] [unique_id "al9NsYAs9lPxxVAErz3qDQAAAL8"]
[Tue Jul 21 07:45:05.159848 2026] [security2:error] [pid 302018:tid 302201] [client 4.204.201.85:9371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/qterm.php"] [unique_id "al9NsYAs9lPxxVAErz3qDgAAALg"]
[Tue Jul 21 07:45:05.254471 2026] [security2:error] [pid 302018:tid 302078] [remote 208.109.9.173:42720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-login.php"] [unique_id "al9NsYAs9lPxxVAErz3qDwAA0Tk"]
[Tue Jul 21 07:45:05.275728 2026] [security2:error] [pid 302018:tid 302171] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/222.php"] [unique_id "al9NsYAs9lPxxVAErz3qEAAAAJo"]
[Tue Jul 21 07:45:05.396893 2026] [autoindex:error] [pid 302018:tid 302200] [client 20.104.96.117:44207] AH01276: Cannot serve directory /home2/blissf00/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:05.458999 2026] [security2:error] [pid 302018:tid 302237] [client 4.204.201.85:9353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/blurbs.php"] [unique_id "al9NsYAs9lPxxVAErz3qFAAAANw"]
[Tue Jul 21 07:45:05.550637 2026] [security2:error] [pid 302018:tid 302267] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/test.php"] [unique_id "al9NsYAs9lPxxVAErz3qGAAAAPo"]
[Tue Jul 21 07:45:05.573896 2026] [security2:error] [pid 302018:tid 302275] [client 20.104.96.117:44207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/ccc.php"] [unique_id "al9NsYAs9lPxxVAErz3qGQAAAQI"]
[Tue Jul 21 07:45:05.756800 2026] [security2:error] [pid 302018:tid 302229] [client 4.204.201.85:22072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/v543.php"] [unique_id "al9NsYAs9lPxxVAErz3qHgAAANQ"]
[Tue Jul 21 07:45:05.847396 2026] [security2:error] [pid 296703:tid 296737] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NsSn25uliftkV1n4QMAAATiE"]
[Tue Jul 21 07:45:05.847537 2026] [security2:error] [pid 296703:tid 296911] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NsSn25uliftkV1n4QMAAATiE"]
[Tue Jul 21 07:45:05.914167 2026] [security2:error] [pid 296703:tid 296901] [client 184.75.223.211:42868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9NsSn25uliftkV1n4QNQAAAEQ"]
[Tue Jul 21 07:45:05.914265 2026] [security2:error] [pid 296703:tid 296901] [client 184.75.223.211:42868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9NsSn25uliftkV1n4QNQAAAEQ"]
[Tue Jul 21 07:45:06.008686 2026] [security2:error] [pid 302018:tid 302235] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/aaa.php"] [unique_id "al9NsoAs9lPxxVAErz3qJAAAANo"]
[Tue Jul 21 07:45:06.030946 2026] [security2:error] [pid 302018:tid 302211] [client 4.204.201.85:22039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/w3lls.php"] [unique_id "al9NsoAs9lPxxVAErz3qJQAAAMI"]
[Tue Jul 21 07:45:06.162192 2026] [security2:error] [pid 302018:tid 302082] [remote 172.98.33.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.33.98.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9NsYAs9lPxxVAErz3qIwAA9z0"]
[Tue Jul 21 07:45:06.284840 2026] [security2:error] [pid 296703:tid 296877] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/11.php"] [unique_id "al9Nsin25uliftkV1n4QOAAAACw"]
[Tue Jul 21 07:45:06.324281 2026] [security2:error] [pid 302018:tid 302187] [client 74.249.245.134:5547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/readme.php"] [unique_id "al9NsoAs9lPxxVAErz3qJwAAAKo"]
[Tue Jul 21 07:45:06.327490 2026] [security2:error] [pid 296703:tid 296948] [client 4.204.201.85:9315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-ws68.php"] [unique_id "al9Nsin25uliftkV1n4QOQAAAHM"]
[Tue Jul 21 07:45:06.495027 2026] [security2:error] [pid 296703:tid 296943] [client 202.143.127.214:56547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nsin25uliftkV1n4QQAAAAG4"]
[Tue Jul 21 07:45:06.495121 2026] [security2:error] [pid 296703:tid 296943] [client 202.143.127.214:56547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nsin25uliftkV1n4QQAAAAG4"]
[Tue Jul 21 07:45:06.557522 2026] [security2:error] [pid 296703:tid 296872] [client 193.36.225.10:27425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Nsin25uliftkV1n4QQgAAACc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:45:06.580157 2026] [security2:error] [pid 302018:tid 302254] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/mac.php"] [unique_id "al9NsoAs9lPxxVAErz3qKgAAAO0"]
[Tue Jul 21 07:45:06.585958 2026] [security2:error] [pid 302018:tid 302277] [client 114.119.128.46:20301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.foreverconfidence.com"] [uri "/careers"] [unique_id "al9NsoAs9lPxxVAErz3qKwAAAQQ"], referer: https://www.foreverconfidence.com/es/careers
[Tue Jul 21 07:45:06.609624 2026] [security2:error] [pid 302018:tid 302261] [client 4.204.201.85:9321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/xyn.php"] [unique_id "al9NsoAs9lPxxVAErz3qLAAAAPQ"]
[Tue Jul 21 07:45:06.660055 2026] [security2:error] [pid 302018:tid 302172] [client 20.220.225.223:55754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/wp-mt.php"] [unique_id "al9NsoAs9lPxxVAErz3qLQAAAJs"]
[Tue Jul 21 07:45:06.849622 2026] [security2:error] [pid 302018:tid 302181] [client 20.226.60.151:54316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/raw.php"] [unique_id "al9NsoAs9lPxxVAErz3qLgAAAKQ"]
[Tue Jul 21 07:45:06.880592 2026] [security2:error] [pid 302018:tid 302255] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/chosen.php"] [unique_id "al9NsoAs9lPxxVAErz3qLwAAAO4"]
[Tue Jul 21 07:45:06.887164 2026] [security2:error] [pid 302018:tid 302169] [client 4.204.201.85:9288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/green3.php"] [unique_id "al9NsoAs9lPxxVAErz3qMQAAAJg"]
[Tue Jul 21 07:45:06.914967 2026] [security2:error] [pid 302018:tid 302242] [client 20.104.96.117:44110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/w.php"] [unique_id "al9NsoAs9lPxxVAErz3qMgAAAOE"]
[Tue Jul 21 07:45:07.039909 2026] [security2:error] [pid 302018:tid 302238] [client 59.96.220.140:65209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Ns4As9lPxxVAErz3qOAAAAN0"]
[Tue Jul 21 07:45:07.040674 2026] [security2:error] [pid 302018:tid 302238] [client 59.96.220.140:65209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Ns4As9lPxxVAErz3qOAAAAN0"]
[Tue Jul 21 07:45:07.163413 2026] [security2:error] [pid 302018:tid 302240] [client 4.204.201.85:9359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/ccc.php"] [unique_id "al9Ns4As9lPxxVAErz3qOgAAAN8"]
[Tue Jul 21 07:45:07.174050 2026] [security2:error] [pid 302018:tid 302276] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/cream1.php"] [unique_id "al9Ns4As9lPxxVAErz3qOwAAAQM"]
[Tue Jul 21 07:45:07.348333 2026] [security2:error] [pid 302018:tid 302274] [client 65.110.40.175:45244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sscoenper.com.br"] [uri "/.env"] [unique_id "al9Ns4As9lPxxVAErz3qPgAAAQE"]
[Tue Jul 21 07:45:07.447058 2026] [security2:error] [pid 296703:tid 296934] [client 4.204.201.85:22075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/get.php"] [unique_id "al9Nsyn25uliftkV1n4QUQAAAGU"]
[Tue Jul 21 07:45:07.479940 2026] [autoindex:error] [pid 302018:tid 302156] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/soluc601/domains/granicap.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:07.520176 2026] [security2:error] [pid 302018:tid 302268] [client 152.59.154.239:60884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ns4As9lPxxVAErz3qRAAAAPs"]
[Tue Jul 21 07:45:07.520281 2026] [security2:error] [pid 302018:tid 302268] [client 152.59.154.239:60884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ns4As9lPxxVAErz3qRAAAAPs"]
[Tue Jul 21 07:45:07.639850 2026] [autoindex:error] [pid 302018:tid 302183] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/soluc601/domains/granicap.com.br/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:07.715795 2026] [security2:error] [pid 302018:tid 302263] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Ns4As9lPxxVAErz3qSAAA9kQ"]
[Tue Jul 21 07:45:07.729792 2026] [security2:error] [pid 296703:tid 296927] [client 4.204.201.85:22057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/images.php"] [unique_id "al9Nsyn25uliftkV1n4QVwAAAF4"]
[Tue Jul 21 07:45:07.796587 2026] [security2:error] [pid 302018:tid 302248] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/dr.php"] [unique_id "al9Ns4As9lPxxVAErz3qSQAAAOc"]
[Tue Jul 21 07:45:07.842558 2026] [security2:error] [pid 302018:tid 302231] [client 103.29.114.44:32431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ns4As9lPxxVAErz3qSwAAANY"]
[Tue Jul 21 07:45:07.842688 2026] [security2:error] [pid 302018:tid 302231] [client 103.29.114.44:32431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ns4As9lPxxVAErz3qSwAAANY"]
[Tue Jul 21 07:45:07.990833 2026] [security2:error] [pid 302018:tid 302201] [client 139.167.225.182:59326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ns4As9lPxxVAErz3qTgAAALg"]
[Tue Jul 21 07:45:07.992602 2026] [security2:error] [pid 302018:tid 302201] [client 139.167.225.182:59326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ns4As9lPxxVAErz3qTgAAALg"]
[Tue Jul 21 07:45:08.004139 2026] [security2:error] [pid 302018:tid 302252] [client 4.204.201.85:9327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/alls.php"] [unique_id "al9NtIAs9lPxxVAErz3qUQAAAOs"]
[Tue Jul 21 07:45:08.041005 2026] [security2:error] [pid 302018:tid 302236] [client 122.162.144.145:30614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NtIAs9lPxxVAErz3qUwAAANs"]
[Tue Jul 21 07:45:08.041142 2026] [security2:error] [pid 302018:tid 302236] [client 122.162.144.145:30614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NtIAs9lPxxVAErz3qUwAAANs"]
[Tue Jul 21 07:45:08.100921 2026] [security2:error] [pid 302018:tid 302092] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NtIAs9lPxxVAErz3qVAAAk0c"]
[Tue Jul 21 07:45:08.101107 2026] [security2:error] [pid 302018:tid 302164] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NtIAs9lPxxVAErz3qVAAAk0c"]
[Tue Jul 21 07:45:08.141885 2026] [security2:error] [pid 302018:tid 302220] [client 37.140.223.150:37227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NsYAs9lPxxVAErz3qIgAAAMs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:45:08.162761 2026] [security2:error] [pid 302018:tid 302196] [client 20.220.225.223:60363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/ww.php"] [unique_id "al9NtIAs9lPxxVAErz3qVQAAALM"]
[Tue Jul 21 07:45:08.207559 2026] [security2:error] [pid 296703:tid 296883] [client 20.104.96.117:44261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9NtCn25uliftkV1n4QXQAAADI"]
[Tue Jul 21 07:45:08.281485 2026] [security2:error] [pid 302018:tid 302258] [client 173.24.185.52:62412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NtIAs9lPxxVAErz3qVgAAAPE"]
[Tue Jul 21 07:45:08.281602 2026] [security2:error] [pid 302018:tid 302258] [client 173.24.185.52:62412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NtIAs9lPxxVAErz3qVgAAAPE"]
[Tue Jul 21 07:45:08.288996 2026] [security2:error] [pid 302018:tid 302254] [client 4.204.201.85:22028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/coffexium.php"] [unique_id "al9NtIAs9lPxxVAErz3qVwAAAO0"]
[Tue Jul 21 07:45:08.326469 2026] [security2:error] [pid 302018:tid 302253] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/x.php"] [unique_id "al9NtIAs9lPxxVAErz3qWAAAAOw"]
[Tue Jul 21 07:45:08.583798 2026] [security2:error] [pid 296703:tid 296853] [client 4.204.201.85:21959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/red.php"] [unique_id "al9NtCn25uliftkV1n4QZAAAABQ"]
[Tue Jul 21 07:45:08.613855 2026] [security2:error] [pid 302018:tid 302192] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/155.php"] [unique_id "al9NtIAs9lPxxVAErz3qXgAAAK8"]
[Tue Jul 21 07:45:08.692911 2026] [security2:error] [pid 302018:tid 302175] [client 41.68.90.219:49256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NtIAs9lPxxVAErz3qXwAAAJ4"]
[Tue Jul 21 07:45:08.693990 2026] [security2:error] [pid 302018:tid 302175] [client 41.68.90.219:49256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NtIAs9lPxxVAErz3qXwAAAJ4"]
[Tue Jul 21 07:45:08.882479 2026] [security2:error] [pid 302018:tid 302076] [remote 41.76.214.143:60604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tryhealthonline.shop"] [uri "/wp-login.php"] [unique_id "al9NtIAs9lPxxVAErz3qYwAAmzc"]
[Tue Jul 21 07:45:09.004921 2026] [security2:error] [pid 302018:tid 302163] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/ops.php"] [unique_id "al9NtYAs9lPxxVAErz3qZQAAAJI"]
[Tue Jul 21 07:45:09.289168 2026] [security2:error] [pid 302018:tid 302167] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/file31.php"] [unique_id "al9NtYAs9lPxxVAErz3qbQAAAJY"]
[Tue Jul 21 07:45:09.398271 2026] [security2:error] [pid 302018:tid 302183] [client 74.249.245.134:17438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/403.php"] [unique_id "al9NtYAs9lPxxVAErz3qbgAAAKY"]
[Tue Jul 21 07:45:09.542202 2026] [security2:error] [pid 302018:tid 302265] [client 20.104.96.117:30885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9NtYAs9lPxxVAErz3qcAAAAPg"]
[Tue Jul 21 07:45:09.696821 2026] [security2:error] [pid 296703:tid 296958] [client 4.204.201.85:9285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9NtSn25uliftkV1n4QdQAAAH0"]
[Tue Jul 21 07:45:09.784989 2026] [security2:error] [pid 302018:tid 302176] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/file6.php"] [unique_id "al9NtYAs9lPxxVAErz3qdAAAAJ8"]
[Tue Jul 21 07:45:09.948033 2026] [security2:error] [pid 302018:tid 302156] [client 182.8.255.181:21092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NtYAs9lPxxVAErz3qdgAAAIs"]
[Tue Jul 21 07:45:09.948192 2026] [security2:error] [pid 302018:tid 302156] [client 182.8.255.181:21092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NtYAs9lPxxVAErz3qdgAAAIs"]
[Tue Jul 21 07:45:09.990316 2026] [security2:error] [pid 296703:tid 296886] [client 103.166.103.129:64878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NtSn25uliftkV1n4QdwAAADU"]
[Tue Jul 21 07:45:09.990439 2026] [security2:error] [pid 296703:tid 296886] [client 103.166.103.129:64878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NtSn25uliftkV1n4QdwAAADU"]
[Tue Jul 21 07:45:10.081147 2026] [autoindex:error] [pid 296703:tid 296932] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/soluc601/domains/granicap.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:10.122004 2026] [security2:error] [pid 302018:tid 302105] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NtoAs9lPxxVAErz3qewAAqlQ"]
[Tue Jul 21 07:45:10.122153 2026] [security2:error] [pid 302018:tid 302187] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NtoAs9lPxxVAErz3qewAAqlQ"]
[Tue Jul 21 07:45:10.249924 2026] [security2:error] [pid 296703:tid 296846] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/adminfuns.php"] [unique_id "al9Ntin25uliftkV1n4QgQAAAA0"]
[Tue Jul 21 07:45:10.309683 2026] [security2:error] [pid 302018:tid 302262] [client 20.220.225.223:53466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/cron.php"] [unique_id "al9NtoAs9lPxxVAErz3qfgAAAPU"]
[Tue Jul 21 07:45:10.377967 2026] [security2:error] [pid 302018:tid 302236] [client 109.60.28.94:59482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NtoAs9lPxxVAErz3qfQAAANs"]
[Tue Jul 21 07:45:10.521800 2026] [security2:error] [pid 302018:tid 302202] [client 193.36.225.11:51141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NtoAs9lPxxVAErz3qfwAAALk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:45:10.570810 2026] [security2:error] [pid 302018:tid 302196] [client 178.153.91.96:12093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NtoAs9lPxxVAErz3qggAAALM"]
[Tue Jul 21 07:45:10.570925 2026] [security2:error] [pid 302018:tid 302196] [client 178.153.91.96:12093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NtoAs9lPxxVAErz3qggAAALM"]
[Tue Jul 21 07:45:10.576391 2026] [security2:error] [pid 302018:tid 302194] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/goods.php"] [unique_id "al9NtoAs9lPxxVAErz3qgwAAALE"]
[Tue Jul 21 07:45:10.706292 2026] [security2:error] [pid 296703:tid 296841] [client 103.86.117.203:61606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ntin25uliftkV1n4QjgAAAAg"]
[Tue Jul 21 07:45:10.706401 2026] [security2:error] [pid 296703:tid 296841] [client 103.86.117.203:61606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ntin25uliftkV1n4QjgAAAAg"]
[Tue Jul 21 07:45:10.732128 2026] [security2:error] [pid 296703:tid 296873] [client 20.104.96.117:44098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/FWAZ.php"] [unique_id "al9Ntin25uliftkV1n4QkQAAACg"]
[Tue Jul 21 07:45:10.791487 2026] [security2:error] [pid 296703:tid 296711] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Ntin25uliftkV1n4QkwAAAgc"]
[Tue Jul 21 07:45:10.791639 2026] [security2:error] [pid 296703:tid 296835] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Ntin25uliftkV1n4QkwAAAgc"]
[Tue Jul 21 07:45:10.861543 2026] [security2:error] [pid 302018:tid 302162] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/100.php"] [unique_id "al9NtoAs9lPxxVAErz3qhQAAAJE"]
[Tue Jul 21 07:45:10.876379 2026] [security2:error] [pid 302018:tid 302240] [client 4.204.201.85:9290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-content/index.php"] [unique_id "al9NtoAs9lPxxVAErz3qhgAAAN8"]
[Tue Jul 21 07:45:10.926174 2026] [security2:error] [pid 302018:tid 302172] [client 74.249.245.134:17431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/max.php"] [unique_id "al9NtoAs9lPxxVAErz3qhwAAAJs"]
[Tue Jul 21 07:45:11.028204 2026] [security2:error] [pid 302018:tid 302177] [client 65.110.40.175:45300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sscoenper.com.br"] [uri "/backend/.env"] [unique_id "al9Nt4As9lPxxVAErz3qiQAAAKA"]
[Tue Jul 21 07:45:11.028237 2026] [security2:error] [pid 302018:tid 302235] [client 65.110.40.175:45318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sscoenper.com.br"] [uri "/api/.env"] [unique_id "al9Nt4As9lPxxVAErz3qiAAAANo"]
[Tue Jul 21 07:45:11.147820 2026] [security2:error] [pid 302018:tid 302200] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/about.php"] [unique_id "al9Nt4As9lPxxVAErz3qkQAAALc"]
[Tue Jul 21 07:45:11.154057 2026] [security2:error] [pid 302018:tid 302158] [client 20.220.225.223:53461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/xxx.php"] [unique_id "al9Nt4As9lPxxVAErz3qkgAAAI0"]
[Tue Jul 21 07:45:11.154385 2026] [security2:error] [pid 302018:tid 302174] [client 4.204.201.85:9363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/admin.php"] [unique_id "al9Nt4As9lPxxVAErz3qkwAAAJ0"]
[Tue Jul 21 07:45:11.170368 2026] [security2:error] [pid 302018:tid 302225] [client 106.215.181.8:12889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nt4As9lPxxVAErz3qlgAAANA"]
[Tue Jul 21 07:45:11.179895 2026] [security2:error] [pid 302018:tid 302225] [client 106.215.181.8:12889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nt4As9lPxxVAErz3qlgAAANA"]
[Tue Jul 21 07:45:11.250079 2026] [security2:error] [pid 296703:tid 296784] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ntyn25uliftkV1n4QnQAAPFA"]
[Tue Jul 21 07:45:11.250258 2026] [security2:error] [pid 296703:tid 296893] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Ntyn25uliftkV1n4QnQAAPFA"]
[Tue Jul 21 07:45:11.432920 2026] [security2:error] [pid 302018:tid 302259] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/about.php"] [unique_id "al9Nt4As9lPxxVAErz3qmgAAAPI"]
[Tue Jul 21 07:45:11.437405 2026] [security2:error] [pid 302018:tid 302183] [client 4.204.201.85:22054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/177.php"] [unique_id "al9Nt4As9lPxxVAErz3qmwAAAKY"]
[Tue Jul 21 07:45:11.501644 2026] [security2:error] [pid 296703:tid 296837] [client 20.104.96.117:44140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/miru1.php"] [unique_id "al9Ntyn25uliftkV1n4QogAAAAQ"]
[Tue Jul 21 07:45:11.697169 2026] [security2:error] [pid 296703:tid 296743] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ntyn25uliftkV1n4QpgAAHCc"]
[Tue Jul 21 07:45:11.697298 2026] [security2:error] [pid 296703:tid 296861] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ntyn25uliftkV1n4QpgAAHCc"]
[Tue Jul 21 07:45:11.699986 2026] [security2:error] [pid 296703:tid 296933] [client 20.104.96.117:30872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9Ntyn25uliftkV1n4QpwAAAGQ"]
[Tue Jul 21 07:45:11.724045 2026] [security2:error] [pid 296703:tid 296853] [client 4.204.201.85:9381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/199.php"] [unique_id "al9Ntyn25uliftkV1n4QqAAAABQ"]
[Tue Jul 21 07:45:11.725430 2026] [security2:error] [pid 302018:tid 302244] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/admin.php"] [unique_id "al9Nt4As9lPxxVAErz3qoQAAAOM"]
[Tue Jul 21 07:45:11.928390 2026] [security2:error] [pid 296703:tid 296887] [client 172.245.102.31:45731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Ntyn25uliftkV1n4QqQAAADY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:45:12.001276 2026] [security2:error] [pid 302018:tid 302176] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/admin.php"] [unique_id "al9NuIAs9lPxxVAErz3qpQAAAJ8"]
[Tue Jul 21 07:45:12.072991 2026] [security2:error] [pid 302018:tid 302156] [client 4.204.201.85:22011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/file52.php"] [unique_id "al9NuIAs9lPxxVAErz3qpgAAAIs"]
[Tue Jul 21 07:45:12.083528 2026] [security2:error] [pid 302018:tid 302170] [client 122.164.127.47:63615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NuIAs9lPxxVAErz3qpwAAAJk"]
[Tue Jul 21 07:45:12.083613 2026] [security2:error] [pid 302018:tid 302170] [client 122.164.127.47:63615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NuIAs9lPxxVAErz3qpwAAAJk"]
[Tue Jul 21 07:45:12.201553 2026] [security2:error] [pid 302018:tid 302187] [client 20.104.96.117:44242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/aa.php"] [unique_id "al9NuIAs9lPxxVAErz3qqwAAAKo"]
[Tue Jul 21 07:45:12.277999 2026] [security2:error] [pid 296703:tid 296920] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/themes.php"] [unique_id "al9NuCn25uliftkV1n4QsgAAAFc"]
[Tue Jul 21 07:45:12.359000 2026] [security2:error] [pid 296703:tid 296924] [client 4.204.201.85:9301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/geck.php"] [unique_id "al9NuCn25uliftkV1n4QswAAAFs"]
[Tue Jul 21 07:45:12.503561 2026] [security2:error] [pid 302018:tid 302194] [client 20.220.225.223:27147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/hunter.php"] [unique_id "al9NuIAs9lPxxVAErz3qrwAAALE"]
[Tue Jul 21 07:45:12.580542 2026] [security2:error] [pid 296703:tid 296956] [client 20.104.96.117:30414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9NuCn25uliftkV1n4QugAAAHs"]
[Tue Jul 21 07:45:12.587822 2026] [autoindex:error] [pid 296703:tid 296877] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/soluc601/domains/granicap.com.br/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:12.645100 2026] [security2:error] [pid 302018:tid 302246] [client 4.204.201.85:9367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/biufile.php"] [unique_id "al9NuIAs9lPxxVAErz3qswAAAOU"]
[Tue Jul 21 07:45:12.693242 2026] [security2:error] [pid 302018:tid 302211] [client 103.174.34.15:63512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NuIAs9lPxxVAErz3qtAAAAMI"]
[Tue Jul 21 07:45:12.693376 2026] [security2:error] [pid 302018:tid 302211] [client 103.174.34.15:63512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NuIAs9lPxxVAErz3qtAAAAMI"]
[Tue Jul 21 07:45:12.927939 2026] [security2:error] [pid 296703:tid 296907] [client 4.204.201.85:22069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/mosty.php"] [unique_id "al9NuCn25uliftkV1n4QwQAAAEo"]
[Tue Jul 21 07:45:12.944872 2026] [security2:error] [pid 296703:tid 296823] [remote 198.244.242.243:20326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "hotelpordosolpolonini.com.br"] [uri "/robots.txt"] [unique_id "al9NuCn25uliftkV1n4QwwAAY3c"]
[Tue Jul 21 07:45:12.945038 2026] [security2:error] [pid 296703:tid 296932] [client 198.244.242.243:20326] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hotelpordosolpolonini.com.br"] [uri "/robots.txt"] [unique_id "al9NuCn25uliftkV1n4QwwAAY3c"]
[Tue Jul 21 07:45:12.956704 2026] [security2:error] [pid 296703:tid 296828] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NuCn25uliftkV1n4QxAAAFnw"]
[Tue Jul 21 07:45:12.956848 2026] [security2:error] [pid 296703:tid 296855] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NuCn25uliftkV1n4QxAAAFnw"]
[Tue Jul 21 07:45:13.212442 2026] [security2:error] [pid 302018:tid 302184] [client 4.204.201.85:22049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/dejavu.php"] [unique_id "al9NuYAs9lPxxVAErz3qvAAAAKc"]
[Tue Jul 21 07:45:13.327544 2026] [security2:error] [pid 302018:tid 302237] [client 20.104.96.117:44254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/122.php"] [unique_id "al9NuYAs9lPxxVAErz3qwAAAANw"]
[Tue Jul 21 07:45:13.541470 2026] [security2:error] [pid 296703:tid 296856] [client 4.204.201.85:65483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/aaf.php"] [unique_id "al9NuSn25uliftkV1n4QzgAAABc"]
[Tue Jul 21 07:45:13.594463 2026] [security2:error] [pid 302018:tid 302201] [client 117.217.38.194:57441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NuYAs9lPxxVAErz3qxAAAALg"]
[Tue Jul 21 07:45:13.594595 2026] [security2:error] [pid 302018:tid 302201] [client 117.217.38.194:57441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NuYAs9lPxxVAErz3qxAAAALg"]
[Tue Jul 21 07:45:13.693597 2026] [security2:error] [pid 302018:tid 302252] [client 117.247.80.59:19786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NuYAs9lPxxVAErz3qxgAAAOs"]
[Tue Jul 21 07:45:13.693703 2026] [security2:error] [pid 302018:tid 302252] [client 117.247.80.59:19786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NuYAs9lPxxVAErz3qxgAAAOs"]
[Tue Jul 21 07:45:13.818296 2026] [security2:error] [pid 296703:tid 296922] [client 4.204.201.85:22023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/ha.php"] [unique_id "al9NuSn25uliftkV1n4Q1wAAAFk"]
[Tue Jul 21 07:45:13.830179 2026] [security2:error] [pid 296703:tid 296919] [client 74.249.245.134:17436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/m.php"] [unique_id "al9NuSn25uliftkV1n4Q2AAAAFY"]
[Tue Jul 21 07:45:13.897338 2026] [security2:error] [pid 302018:tid 302158] [client 122.186.204.214:64388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NuYAs9lPxxVAErz3qywAAAI0"]
[Tue Jul 21 07:45:13.897499 2026] [security2:error] [pid 302018:tid 302158] [client 122.186.204.214:64388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NuYAs9lPxxVAErz3qywAAAI0"]
[Tue Jul 21 07:45:14.105740 2026] [security2:error] [pid 296703:tid 296955] [client 4.204.201.85:9352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/hur.php"] [unique_id "al9Nuin25uliftkV1n4Q2wAAAHo"]
[Tue Jul 21 07:45:14.141314 2026] [security2:error] [pid 296703:tid 296881] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Nuin25uliftkV1n4Q3QAAADA"]
[Tue Jul 21 07:45:14.170363 2026] [security2:error] [pid 302018:tid 302208] [client 117.251.86.144:43616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NuoAs9lPxxVAErz3qzAAAAL8"]
[Tue Jul 21 07:45:14.170518 2026] [security2:error] [pid 302018:tid 302208] [client 117.251.86.144:43616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NuoAs9lPxxVAErz3qzAAAAL8"]
[Tue Jul 21 07:45:14.368974 2026] [security2:error] [pid 296703:tid 296862] [client 74.249.245.134:5535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/click.php"] [unique_id "al9Nuin25uliftkV1n4Q5wAAAB0"]
[Tue Jul 21 07:45:14.391243 2026] [security2:error] [pid 296703:tid 296953] [client 4.204.201.85:9406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/h02ugyh.php"] [unique_id "al9Nuin25uliftkV1n4Q6AAAAHg"]
[Tue Jul 21 07:45:14.417547 2026] [security2:error] [pid 302018:tid 302277] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9NuoAs9lPxxVAErz3qzgAAAQQ"]
[Tue Jul 21 07:45:14.440951 2026] [security2:error] [pid 296703:tid 296844] [client 20.220.225.223:53442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/we.php"] [unique_id "al9Nuin25uliftkV1n4Q6gAAAAs"]
[Tue Jul 21 07:45:14.495441 2026] [security2:error] [pid 296703:tid 296712] [remote 15.235.27.74:30214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "hotelpordosolpolonini.com.br"] [uri "/"] [unique_id "al9Nuin25uliftkV1n4Q6wAAIAg"]
[Tue Jul 21 07:45:14.495554 2026] [security2:error] [pid 296703:tid 296865] [client 15.235.27.74:30214] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hotelpordosolpolonini.com.br"] [uri "/"] [unique_id "al9Nuin25uliftkV1n4Q6wAAIAg"]
[Tue Jul 21 07:45:14.526548 2026] [security2:error] [pid 302018:tid 302165] [client 193.36.225.55:34167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NuoAs9lPxxVAErz3q0AAAAJQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:45:14.679177 2026] [security2:error] [pid 302018:tid 302221] [client 4.204.201.85:9313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/155.php"] [unique_id "al9NuoAs9lPxxVAErz3q1AAAAMw"]
[Tue Jul 21 07:45:14.720631 2026] [security2:error] [pid 302018:tid 302238] [client 20.104.96.117:30874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/albin.php"] [unique_id "al9NuoAs9lPxxVAErz3q1gAAAN0"]
[Tue Jul 21 07:45:14.785391 2026] [security2:error] [pid 296703:tid 296913] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wefile.php"] [unique_id "al9Nuin25uliftkV1n4Q8wAAAFA"]
[Tue Jul 21 07:45:14.957529 2026] [security2:error] [pid 296703:tid 296905] [client 4.204.201.85:9322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/pp.php"] [unique_id "al9Nuin25uliftkV1n4Q-QAAAEg"]
[Tue Jul 21 07:45:15.007110 2026] [security2:error] [pid 302018:tid 302189] [client 193.36.225.143:48221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NuIAs9lPxxVAErz3qtwAAAKw"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:45:15.235659 2026] [security2:error] [pid 296703:tid 296857] [client 4.204.201.85:22016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/ops.php"] [unique_id "al9Nuyn25uliftkV1n4Q_gAAABg"]
[Tue Jul 21 07:45:15.362608 2026] [security2:error] [pid 296703:tid 296879] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9Nuyn25uliftkV1n4RAwAAAC4"]
[Tue Jul 21 07:45:15.478231 2026] [security2:error] [pid 302018:tid 302267] [client 74.249.245.134:5509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/lv.php"] [unique_id "al9Nu4As9lPxxVAErz3q4wAAAPo"]
[Tue Jul 21 07:45:15.514652 2026] [security2:error] [pid 302018:tid 302160] [client 4.204.201.85:3461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/ingfo.php"] [unique_id "al9Nu4As9lPxxVAErz3q5AAAAI8"]
[Tue Jul 21 07:45:15.651711 2026] [autoindex:error] [pid 302018:tid 302229] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/soluc601/domains/granicap.com.br/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:15.800594 2026] [security2:error] [pid 302018:tid 302204] [client 4.204.201.85:9407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/error_log.php"] [unique_id "al9Nu4As9lPxxVAErz3q6QAAALs"]
[Tue Jul 21 07:45:15.893133 2026] [autoindex:error] [pid 302018:tid 302244] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/soluc601/domains/granicap.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:15.935407 2026] [security2:error] [pid 302018:tid 302156] [client 20.104.96.117:44880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/get.php"] [unique_id "al9Nu4As9lPxxVAErz3q7QAAAIs"]
[Tue Jul 21 07:45:16.084760 2026] [security2:error] [pid 296703:tid 296858] [client 4.204.201.85:21985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/test10.php"] [unique_id "al9NvCn25uliftkV1n4REwAAABk"]
[Tue Jul 21 07:45:16.125348 2026] [security2:error] [pid 302018:tid 302173] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9NvIAs9lPxxVAErz3q7gAAAJw"]
[Tue Jul 21 07:45:16.264376 2026] [security2:error] [pid 302018:tid 302202] [client 20.104.96.117:30434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/cilus.php"] [unique_id "al9NvIAs9lPxxVAErz3q9QAAALk"]
[Tue Jul 21 07:45:16.365470 2026] [security2:error] [pid 302018:tid 302196] [client 128.127.105.184:44138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9NvIAs9lPxxVAErz3q_wAAALM"]
[Tue Jul 21 07:45:16.365642 2026] [security2:error] [pid 302018:tid 302196] [client 128.127.105.184:44138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9NvIAs9lPxxVAErz3q_wAAALM"]
[Tue Jul 21 07:45:16.387492 2026] [security2:error] [pid 302018:tid 302271] [client 23.180.120.145:39876] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "prostadine.shop-officialstore.com"] [uri "/"] [unique_id "al9NvIAs9lPxxVAErz3rAQAAAP4"]
[Tue Jul 21 07:45:16.393704 2026] [security2:error] [pid 296703:tid 296839] [client 4.204.201.85:9332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/koala.php"] [unique_id "al9NvCn25uliftkV1n4RHQAAAAY"]
[Tue Jul 21 07:45:16.451339 2026] [security2:error] [pid 296703:tid 296837] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/8.php"] [unique_id "al9NvCn25uliftkV1n4RIAAAAAQ"]
[Tue Jul 21 07:45:16.476828 2026] [security2:error] [pid 302018:tid 302178] [client 59.96.220.140:177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NvIAs9lPxxVAErz3rAgAAAKE"]
[Tue Jul 21 07:45:16.477539 2026] [security2:error] [pid 302018:tid 302178] [client 59.96.220.140:177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9NvIAs9lPxxVAErz3rAgAAAKE"]
[Tue Jul 21 07:45:16.728381 2026] [security2:error] [pid 302018:tid 302205] [client 4.204.201.85:9404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/mac.php"] [unique_id "al9NvIAs9lPxxVAErz3rBwAAALw"]
[Tue Jul 21 07:45:16.739276 2026] [security2:error] [pid 296703:tid 296861] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9NvCn25uliftkV1n4RJAAAABw"]
[Tue Jul 21 07:45:17.036096 2026] [security2:error] [pid 302018:tid 302183] [client 37.140.223.157:26969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9NvYAs9lPxxVAErz3rDgAAAKY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:45:17.058448 2026] [security2:error] [pid 302018:tid 302160] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/f6.php"] [unique_id "al9NvYAs9lPxxVAErz3rDwAAAI8"]
[Tue Jul 21 07:45:17.069132 2026] [security2:error] [pid 302018:tid 302223] [client 4.204.201.85:21965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wefile.php"] [unique_id "al9NvYAs9lPxxVAErz3rEQAAAM4"]
[Tue Jul 21 07:45:17.147578 2026] [security2:error] [pid 302018:tid 302217] [client 74.249.245.134:5552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/cong.php"] [unique_id "al9NvYAs9lPxxVAErz3rFgAAAMg"]
[Tue Jul 21 07:45:17.220542 2026] [security2:error] [pid 302018:tid 302259] [client 23.180.120.145:34540] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "prostadine.shop-officialstore.com"] [uri "/wp-json/batch/v1"] [unique_id "al9NvYAs9lPxxVAErz3rFwAAAPI"]
[Tue Jul 21 07:45:17.255234 2026] [security2:error] [pid 296703:tid 296822] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NvSn25uliftkV1n4RKwAATnY"]
[Tue Jul 21 07:45:17.255412 2026] [security2:error] [pid 296703:tid 296911] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NvSn25uliftkV1n4RKwAATnY"]
[Tue Jul 21 07:45:17.342405 2026] [security2:error] [pid 296703:tid 296896] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/inputs.php"] [unique_id "al9NvSn25uliftkV1n4RLQAAAD8"]
[Tue Jul 21 07:45:17.537932 2026] [security2:error] [pid 296703:tid 296921] [client 184.75.223.211:52124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9NvSn25uliftkV1n4RNQAAAFg"]
[Tue Jul 21 07:45:17.538022 2026] [security2:error] [pid 296703:tid 296921] [client 184.75.223.211:52124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9NvSn25uliftkV1n4RNQAAAFg"]
[Tue Jul 21 07:45:17.538658 2026] [security2:error] [pid 296703:tid 296876] [client 20.104.96.117:30613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/gptsh.php"] [unique_id "al9NvSn25uliftkV1n4RNgAAACs"]
[Tue Jul 21 07:45:17.580381 2026] [security2:error] [pid 302018:tid 302233] [client 202.143.127.214:56984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NvYAs9lPxxVAErz3rNgAAANg"]
[Tue Jul 21 07:45:17.580502 2026] [security2:error] [pid 302018:tid 302233] [client 202.143.127.214:56984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NvYAs9lPxxVAErz3rNgAAANg"]
[Tue Jul 21 07:45:17.630908 2026] [security2:error] [pid 302018:tid 302113] [remote 4.205.168.44:58236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zooparquevet.com.br"] [uri "/wp-login.php"] [unique_id "al9NvIAs9lPxxVAErz3rBgAA7Fw"]
[Tue Jul 21 07:45:17.655631 2026] [security2:error] [pid 296703:tid 296936] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/inputs.php"] [unique_id "al9NvSn25uliftkV1n4ROQAAAGc"]
[Tue Jul 21 07:45:17.660135 2026] [security2:error] [pid 296703:tid 296907] [client 20.104.96.117:44162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/as.php"] [unique_id "al9NvSn25uliftkV1n4ROgAAAEo"]
[Tue Jul 21 07:45:17.820696 2026] [security2:error] [pid 302018:tid 302165] [client 20.220.225.223:55760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/phpinfo.php1"] [unique_id "al9NvYAs9lPxxVAErz3rOQAAAJQ"]
[Tue Jul 21 07:45:17.898709 2026] [security2:error] [pid 302018:tid 302262] [client 74.249.245.134:62861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/brand.php"] [unique_id "al9NvYAs9lPxxVAErz3rOgAAAPU"]
[Tue Jul 21 07:45:17.959836 2026] [security2:error] [pid 302018:tid 302175] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/classwithtostring.php"] [unique_id "al9NvYAs9lPxxVAErz3rQgAAAJ4"]
[Tue Jul 21 07:45:18.244603 2026] [security2:error] [pid 302018:tid 302172] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9NvoAs9lPxxVAErz3rSwAAAJs"]
[Tue Jul 21 07:45:18.340146 2026] [security2:error] [pid 302018:tid 302243] [client 62.102.148.187:41742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9NvoAs9lPxxVAErz3rTgAAAOI"]
[Tue Jul 21 07:45:18.340227 2026] [security2:error] [pid 302018:tid 302243] [client 62.102.148.187:41742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9NvoAs9lPxxVAErz3rTgAAAOI"]
[Tue Jul 21 07:45:18.366718 2026] [security2:error] [pid 302018:tid 302221] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9NvoAs9lPxxVAErz3rTQAAzAY"]
[Tue Jul 21 07:45:18.399986 2026] [security2:error] [pid 296703:tid 296924] [client 152.59.154.239:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nvin25uliftkV1n4RSgAAAFs"]
[Tue Jul 21 07:45:18.400127 2026] [security2:error] [pid 296703:tid 296924] [client 152.59.154.239:61395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nvin25uliftkV1n4RSgAAAFs"]
[Tue Jul 21 07:45:18.477038 2026] [security2:error] [pid 302018:tid 302251] [client 20.104.96.117:30868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/rithin.php"] [unique_id "al9NvoAs9lPxxVAErz3rUgAAAOo"]
[Tue Jul 21 07:45:18.483987 2026] [security2:error] [pid 302018:tid 302173] [client 103.29.114.44:11072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NvoAs9lPxxVAErz3rUwAAAJw"]
[Tue Jul 21 07:45:18.484084 2026] [security2:error] [pid 302018:tid 302173] [client 103.29.114.44:11072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NvoAs9lPxxVAErz3rUwAAAJw"]
[Tue Jul 21 07:45:18.528764 2026] [security2:error] [pid 302018:tid 302236] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wp-blog.php"] [unique_id "al9NvoAs9lPxxVAErz3rVAAAANs"]
[Tue Jul 21 07:45:18.617217 2026] [security2:error] [pid 302018:tid 302030] [remote 209.97.182.179:46590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dentepro.com.br"] [uri "/wp-login.php"] [unique_id "al9NvoAs9lPxxVAErz3rVwAA2gk"]
[Tue Jul 21 07:45:18.629677 2026] [security2:error] [pid 296703:tid 296748] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nvin25uliftkV1n4RUAAAOiw"]
[Tue Jul 21 07:45:18.629859 2026] [security2:error] [pid 296703:tid 296891] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nvin25uliftkV1n4RUAAAOiw"]
[Tue Jul 21 07:45:18.664823 2026] [security2:error] [pid 302018:tid 302255] [client 139.167.225.182:59983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NvoAs9lPxxVAErz3rWAAAAO4"]
[Tue Jul 21 07:45:18.664949 2026] [security2:error] [pid 302018:tid 302255] [client 139.167.225.182:59983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NvoAs9lPxxVAErz3rWAAAAO4"]
[Tue Jul 21 07:45:18.681891 2026] [security2:error] [pid 302018:tid 302227] [client 65.110.40.175:38798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.40.110.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NvIAs9lPxxVAErz3q_QAAANI"]
[Tue Jul 21 07:45:18.702855 2026] [security2:error] [pid 302018:tid 302272] [client 4.204.201.85:21963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/makeasmtp.php"] [unique_id "al9NvoAs9lPxxVAErz3rWQAAAP8"]
[Tue Jul 21 07:45:18.724940 2026] [security2:error] [pid 302018:tid 302029] [remote 54.64.35.240:33760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.35.64.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9NvoAs9lPxxVAErz3rWgAAzwg"]
[Tue Jul 21 07:45:18.818735 2026] [autoindex:error] [pid 302018:tid 302166] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/soluc601/domains/granicap.com.br/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:18.820031 2026] [security2:error] [pid 296703:tid 296836] [client 173.24.185.52:62890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Nvin25uliftkV1n4RVAAAAAM"]
[Tue Jul 21 07:45:18.820165 2026] [security2:error] [pid 296703:tid 296836] [client 173.24.185.52:62890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Nvin25uliftkV1n4RVAAAAAM"]
[Tue Jul 21 07:45:18.904426 2026] [security2:error] [pid 296703:tid 296855] [client 122.162.144.145:5474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Nvin25uliftkV1n4RWAAAABY"]
[Tue Jul 21 07:45:18.904556 2026] [security2:error] [pid 296703:tid 296855] [client 122.162.144.145:5474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Nvin25uliftkV1n4RWAAAABY"]
[Tue Jul 21 07:45:19.002007 2026] [security2:error] [pid 302018:tid 302240] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Nv4As9lPxxVAErz3rXgAAAN8"]
[Tue Jul 21 07:45:19.009258 2026] [security2:error] [pid 302018:tid 302265] [client 4.204.201.85:9354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/2P.php"] [unique_id "al9Nv4As9lPxxVAErz3rXwAAAPg"]
[Tue Jul 21 07:45:19.128624 2026] [security2:error] [pid 296703:tid 296837] [client 20.104.96.117:44152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/ccou.php"] [unique_id "al9Nvyn25uliftkV1n4RXwAAAAQ"]
[Tue Jul 21 07:45:19.296042 2026] [security2:error] [pid 296703:tid 296934] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/ms-edit.php"] [unique_id "al9Nvyn25uliftkV1n4RYgAAAGU"]
[Tue Jul 21 07:45:19.324584 2026] [security2:error] [pid 302018:tid 302180] [client 74.249.245.134:17457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/atomlib.php"] [unique_id "al9Nv4As9lPxxVAErz3rYQAAAKM"]
[Tue Jul 21 07:45:19.341172 2026] [security2:error] [pid 302018:tid 302270] [client 4.204.201.85:9401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Nv4As9lPxxVAErz3rYgAAAP0"]
[Tue Jul 21 07:45:19.444879 2026] [security2:error] [pid 296703:tid 296843] [client 193.36.225.62:40745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Nvyn25uliftkV1n4RYQAAAAo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:45:19.579778 2026] [security2:error] [pid 296703:tid 296866] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Nvyn25uliftkV1n4RbAAAACE"]
[Tue Jul 21 07:45:19.606508 2026] [security2:error] [pid 296703:tid 296896] [client 20.104.96.117:30454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/fffm.php"] [unique_id "al9Nvyn25uliftkV1n4RbQAAAD8"]
[Tue Jul 21 07:45:19.756647 2026] [security2:error] [pid 296703:tid 296877] [client 4.204.201.85:21960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Nvyn25uliftkV1n4RcAAAACw"]
[Tue Jul 21 07:45:19.876172 2026] [autoindex:error] [pid 296703:tid 296904] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/soluc601/domains/granicap.com.br/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:20.047319 2026] [security2:error] [pid 296703:tid 296898] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9NwCn25uliftkV1n4RfgAAAEE"]
[Tue Jul 21 07:45:20.051652 2026] [security2:error] [pid 302018:tid 302194] [client 4.204.201.85:3470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/system_log.php"] [unique_id "al9NwIAs9lPxxVAErz3rbQAAALE"]
[Tue Jul 21 07:45:20.110613 2026] [security2:error] [pid 296703:tid 296897] [client 18.193.252.127:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9NwCn25uliftkV1n4RfwAAQBg"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:45:20.350253 2026] [autoindex:error] [pid 302018:tid 302162] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/soluc601/domains/granicap.com.br/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:20.364056 2026] [security2:error] [pid 302018:tid 302242] [client 41.68.90.219:49684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NwIAs9lPxxVAErz3rdAAAAOE"]
[Tue Jul 21 07:45:20.365034 2026] [security2:error] [pid 302018:tid 302242] [client 41.68.90.219:49684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NwIAs9lPxxVAErz3rdAAAAOE"]
[Tue Jul 21 07:45:20.429840 2026] [security2:error] [pid 296703:tid 296899] [client 20.104.96.117:44260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/w3lls.php"] [unique_id "al9NwCn25uliftkV1n4RhwAAAEI"]
[Tue Jul 21 07:45:20.434116 2026] [security2:error] [pid 296703:tid 296906] [client 182.8.255.181:17512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NwCn25uliftkV1n4RhgAAAEk"]
[Tue Jul 21 07:45:20.434251 2026] [security2:error] [pid 296703:tid 296906] [client 182.8.255.181:17512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NwCn25uliftkV1n4RhgAAAEk"]
[Tue Jul 21 07:45:20.544788 2026] [autoindex:error] [pid 302018:tid 302190] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/soluc601/domains/granicap.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:20.654933 2026] [security2:error] [pid 296703:tid 296847] [client 18.193.252.127:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9NwCn25uliftkV1n4RjwAADn4"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:45:20.661306 2026] [security2:error] [pid 296703:tid 296929] [client 74.249.245.134:62858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/0x.php"] [unique_id "al9NwCn25uliftkV1n4RkAAAAGA"]
[Tue Jul 21 07:45:20.693391 2026] [security2:error] [pid 302018:tid 302210] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/abcd.php"] [unique_id "al9NwIAs9lPxxVAErz3rfgAAAME"]
[Tue Jul 21 07:45:20.715269 2026] [security2:error] [pid 296703:tid 296932] [client 103.166.103.129:65392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NwCn25uliftkV1n4RkwAAAGM"]
[Tue Jul 21 07:45:20.715572 2026] [security2:error] [pid 296703:tid 296932] [client 103.166.103.129:65392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9NwCn25uliftkV1n4RkwAAAGM"]
[Tue Jul 21 07:45:20.834767 2026] [security2:error] [pid 302018:tid 302182] [client 20.104.96.117:30877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/dfre.php"] [unique_id "al9NwIAs9lPxxVAErz3rfwAAAKU"]
[Tue Jul 21 07:45:20.929098 2026] [security2:error] [pid 302018:tid 302043] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NwIAs9lPxxVAErz3rggAAnBY"]
[Tue Jul 21 07:45:20.929254 2026] [security2:error] [pid 302018:tid 302173] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NwIAs9lPxxVAErz3rggAAnBY"]
[Tue Jul 21 07:45:20.976706 2026] [security2:error] [pid 302018:tid 302241] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/file15.php"] [unique_id "al9NwIAs9lPxxVAErz3rhQAAAOA"]
[Tue Jul 21 07:45:21.076050 2026] [security2:error] [pid 296703:tid 296918] [client 178.153.91.96:51894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NwSn25uliftkV1n4RnwAAAFU"]
[Tue Jul 21 07:45:21.076173 2026] [security2:error] [pid 296703:tid 296918] [client 178.153.91.96:51894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9NwSn25uliftkV1n4RnwAAAFU"]
[Tue Jul 21 07:45:21.109461 2026] [security2:error] [pid 296703:tid 296917] [client 122.179.91.63:27174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NwSn25uliftkV1n4RoAAAAFQ"]
[Tue Jul 21 07:45:21.109585 2026] [security2:error] [pid 296703:tid 296917] [client 122.179.91.63:27174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9NwSn25uliftkV1n4RoAAAAFQ"]
[Tue Jul 21 07:45:21.169795 2026] [security2:error] [pid 302018:tid 302153] [client 109.60.28.94:59848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NwYAs9lPxxVAErz3riQAAAIg"]
[Tue Jul 21 07:45:21.197489 2026] [security2:error] [pid 296703:tid 296919] [client 103.86.117.203:62153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NwSn25uliftkV1n4RoQAAAFY"]
[Tue Jul 21 07:45:21.197622 2026] [security2:error] [pid 296703:tid 296919] [client 103.86.117.203:62153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NwSn25uliftkV1n4RoQAAAFY"]
[Tue Jul 21 07:45:21.244257 2026] [security2:error] [pid 296703:tid 296875] [client 4.204.201.85:22066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/crgio.php"] [unique_id "al9NwSn25uliftkV1n4RogAAACo"]
[Tue Jul 21 07:45:21.266501 2026] [security2:error] [pid 302018:tid 302201] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/jp.php"] [unique_id "al9NwYAs9lPxxVAErz3rjAAAALg"]
[Tue Jul 21 07:45:21.465347 2026] [security2:error] [pid 302018:tid 302038] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NwYAs9lPxxVAErz3rjgAA3RE"]
[Tue Jul 21 07:45:21.465509 2026] [security2:error] [pid 302018:tid 302238] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NwYAs9lPxxVAErz3rjgAA3RE"]
[Tue Jul 21 07:45:21.472509 2026] [autoindex:error] [pid 302018:tid 302265] [client 205.210.31.177:64008] AH01276: Cannot serve directory /home1/hostag18/app.fastpedidos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:21.533794 2026] [security2:error] [pid 302018:tid 302270] [client 20.104.96.117:30909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/wp-happy.php"] [unique_id "al9NwYAs9lPxxVAErz3rkAAAAP0"]
[Tue Jul 21 07:45:21.543856 2026] [security2:error] [pid 296703:tid 296911] [client 4.204.201.85:9295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/pucci.php"] [unique_id "al9NwSn25uliftkV1n4RqAAAAE4"]
[Tue Jul 21 07:45:21.545351 2026] [security2:error] [pid 296703:tid 296937] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/f35.php"] [unique_id "al9NwSn25uliftkV1n4RqQAAAGg"]
[Tue Jul 21 07:45:21.718131 2026] [security2:error] [pid 296703:tid 296901] [client 74.249.245.134:17409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/buy.php"] [unique_id "al9NwSn25uliftkV1n4RrQAAAEQ"]
[Tue Jul 21 07:45:21.779948 2026] [security2:error] [pid 302018:tid 302200] [client 106.215.181.8:22365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NwYAs9lPxxVAErz3rkgAAALc"]
[Tue Jul 21 07:45:21.780086 2026] [security2:error] [pid 302018:tid 302200] [client 106.215.181.8:22365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NwYAs9lPxxVAErz3rkgAAALc"]
[Tue Jul 21 07:45:21.831618 2026] [security2:error] [pid 296703:tid 296913] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wp-load.php"] [unique_id "al9NwSn25uliftkV1n4RrwAAAFA"]
[Tue Jul 21 07:45:21.889242 2026] [security2:error] [pid 296703:tid 296780] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NwSn25uliftkV1n4RtAAAJUw"]
[Tue Jul 21 07:45:21.889388 2026] [security2:error] [pid 296703:tid 296870] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NwSn25uliftkV1n4RtAAAJUw"]
[Tue Jul 21 07:45:22.116281 2026] [security2:error] [pid 296703:tid 296879] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xyn.php"] [unique_id "al9Nwin25uliftkV1n4RuQAAAC4"]
[Tue Jul 21 07:45:22.142858 2026] [security2:error] [pid 302018:tid 302165] [client 20.104.96.117:44275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/test1.php"] [unique_id "al9NwoAs9lPxxVAErz3rmgAAAJQ"]
[Tue Jul 21 07:45:22.155361 2026] [security2:error] [pid 302018:tid 302245] [client 20.104.96.117:30890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/fpr4.php"] [unique_id "al9NwoAs9lPxxVAErz3rmwAAAOQ"]
[Tue Jul 21 07:45:22.226183 2026] [security2:error] [pid 296703:tid 296762] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nwin25uliftkV1n4RvAAADTo"]
[Tue Jul 21 07:45:22.226357 2026] [security2:error] [pid 296703:tid 296846] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nwin25uliftkV1n4RvAAADTo"]
[Tue Jul 21 07:45:22.276542 2026] [security2:error] [pid 296703:tid 296897] [client 159.223.41.76:61095] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bracksimoveis.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Nwin25uliftkV1n4RvQAAAEA"]
[Tue Jul 21 07:45:22.412611 2026] [autoindex:error] [pid 302018:tid 302276] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/soluc601/domains/granicap.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:22.510861 2026] [security2:error] [pid 302018:tid 302181] [client 20.220.225.223:34268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wp-explorer.php"] [unique_id "al9NwoAs9lPxxVAErz3rpAAAAKQ"]
[Tue Jul 21 07:45:22.563666 2026] [security2:error] [pid 302018:tid 302178] [client 51.68.111.203:14673] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "benti.com.br"] [uri "/robots.txt"] [unique_id "al9NwoAs9lPxxVAErz3rqAAAAKE"]
[Tue Jul 21 07:45:22.563758 2026] [security2:error] [pid 302018:tid 302178] [client 51.68.111.203:14673] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "benti.com.br"] [uri "/robots.txt"] [unique_id "al9NwoAs9lPxxVAErz3rqAAAAKE"]
[Tue Jul 21 07:45:22.610100 2026] [security2:error] [pid 302018:tid 302216] [client 122.164.127.47:64198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NwoAs9lPxxVAErz3rrAAAAMc"]
[Tue Jul 21 07:45:22.610211 2026] [security2:error] [pid 302018:tid 302216] [client 122.164.127.47:64198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NwoAs9lPxxVAErz3rrAAAAMc"]
[Tue Jul 21 07:45:22.613600 2026] [autoindex:error] [pid 302018:tid 302246] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/soluc601/domains/granicap.com.br/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:22.754434 2026] [security2:error] [pid 302018:tid 302224] [client 4.204.201.85:9342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-temp.php"] [unique_id "al9NwoAs9lPxxVAErz3rsQAAAM8"]
[Tue Jul 21 07:45:22.811341 2026] [security2:error] [pid 302018:tid 302237] [client 20.104.96.117:30638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/file88.php"] [unique_id "al9NwoAs9lPxxVAErz3rsgAAANw"]
[Tue Jul 21 07:45:23.028088 2026] [security2:error] [pid 302018:tid 302240] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/ccc.php"] [unique_id "al9Nw4As9lPxxVAErz3rtgAAAN8"]
[Tue Jul 21 07:45:23.036207 2026] [security2:error] [pid 302018:tid 302217] [client 4.204.201.85:9291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9Nw4As9lPxxVAErz3rtwAAAMg"]
[Tue Jul 21 07:45:23.046330 2026] [security2:error] [pid 302018:tid 302167] [client 78.46.190.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9Nw4As9lPxxVAErz3ruAAAlhg"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:45:23.091032 2026] [security2:error] [pid 296703:tid 296944] [client 20.104.96.117:44161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/database.php"] [unique_id "al9Nwyn25uliftkV1n4RxgAAAG8"]
[Tue Jul 21 07:45:23.144549 2026] [security2:error] [pid 296703:tid 296885] [client 74.249.245.134:17451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/sx.php"] [unique_id "al9Nwyn25uliftkV1n4RyQAAADQ"]
[Tue Jul 21 07:45:23.250038 2026] [security2:error] [pid 302018:tid 302244] [client 78.46.190.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9Nw4As9lPxxVAErz3rvQAA4xc"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:45:23.279540 2026] [security2:error] [pid 302018:tid 302254] [client 136.144.33.107:47741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Nw4As9lPxxVAErz3rvgAAAO0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:45:23.314043 2026] [security2:error] [pid 302018:tid 302253] [client 4.204.201.85:9368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/puc.php"] [unique_id "al9Nw4As9lPxxVAErz3rvwAAAOw"]
[Tue Jul 21 07:45:23.315217 2026] [security2:error] [pid 302018:tid 302165] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/w.php"] [unique_id "al9Nw4As9lPxxVAErz3rwAAAAJQ"]
[Tue Jul 21 07:45:23.488918 2026] [security2:error] [pid 302018:tid 302073] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Nw4As9lPxxVAErz3rxQAA3jQ"]
[Tue Jul 21 07:45:23.489135 2026] [security2:error] [pid 302018:tid 302239] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Nw4As9lPxxVAErz3rxQAA3jQ"]
[Tue Jul 21 07:45:23.590356 2026] [security2:error] [pid 302018:tid 302250] [client 4.204.201.85:9335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/dx.php"] [unique_id "al9Nw4As9lPxxVAErz3rxgAAAOk"]
[Tue Jul 21 07:45:23.624050 2026] [security2:error] [pid 302018:tid 302192] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Nw4As9lPxxVAErz3rxwAAAK8"]
[Tue Jul 21 07:45:23.631165 2026] [security2:error] [pid 302018:tid 302201] [client 159.223.41.76:51247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bracksimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nw4As9lPxxVAErz3ryAAAALg"]
[Tue Jul 21 07:45:23.713939 2026] [security2:error] [pid 302018:tid 302269] [client 20.104.96.117:30431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/ccc.php"] [unique_id "al9Nw4As9lPxxVAErz3rywAAAPw"]
[Tue Jul 21 07:45:23.718268 2026] [security2:error] [pid 302018:tid 302170] [client 20.220.225.223:34185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/akismet.php"] [unique_id "al9Nw4As9lPxxVAErz3rzAAAAJk"]
[Tue Jul 21 07:45:23.775196 2026] [security2:error] [pid 296703:tid 296837] [client 103.174.34.15:64171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nwyn25uliftkV1n4SBwAAAAQ"]
[Tue Jul 21 07:45:23.775334 2026] [security2:error] [pid 296703:tid 296837] [client 103.174.34.15:64171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nwyn25uliftkV1n4SBwAAAAQ"]
[Tue Jul 21 07:45:24.004602 2026] [security2:error] [pid 296703:tid 296888] [client 74.249.245.134:17414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/article.php"] [unique_id "al9NxCn25uliftkV1n4SDQAAADc"]
[Tue Jul 21 07:45:24.060262 2026] [security2:error] [pid 296703:tid 296956] [client 20.63.100.92:5179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/la.php"] [unique_id "al9NxCn25uliftkV1n4SDwAAAHs"]
[Tue Jul 21 07:45:24.074354 2026] [security2:error] [pid 296703:tid 296908] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/FWAZ.php"] [unique_id "al9NxCn25uliftkV1n4SEAAAAEs"]
[Tue Jul 21 07:45:24.084362 2026] [security2:error] [pid 302018:tid 302198] [client 117.217.38.194:57935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NxIAs9lPxxVAErz3r0AAAALU"]
[Tue Jul 21 07:45:24.084498 2026] [security2:error] [pid 302018:tid 302198] [client 117.217.38.194:57935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NxIAs9lPxxVAErz3r0AAAALU"]
[Tue Jul 21 07:45:24.127101 2026] [security2:error] [pid 296703:tid 296782] [remote 195.26.244.42:46706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-login.php"] [unique_id "al9NxCn25uliftkV1n4SEgAAGk4"]
[Tue Jul 21 07:45:24.198858 2026] [security2:error] [pid 296703:tid 296889] [client 20.206.105.145:56656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9NxCn25uliftkV1n4SFQAAADg"]
[Tue Jul 21 07:45:24.217108 2026] [security2:error] [pid 302018:tid 302251] [client 20.104.96.117:30905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/777.php"] [unique_id "al9NxIAs9lPxxVAErz3r0wAAAOo"]
[Tue Jul 21 07:45:24.219077 2026] [security2:error] [pid 302018:tid 302210] [client 20.104.96.117:44258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/file.php"] [unique_id "al9NxIAs9lPxxVAErz3r1AAAAME"]
[Tue Jul 21 07:45:24.310066 2026] [security2:error] [pid 296703:tid 296898] [client 4.204.201.85:22017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/bthil.php"] [unique_id "al9NxCn25uliftkV1n4SGAAAAEE"]
[Tue Jul 21 07:45:24.357228 2026] [security2:error] [pid 302018:tid 302224] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/miru1.php"] [unique_id "al9NxIAs9lPxxVAErz3r2wAAAM8"]
[Tue Jul 21 07:45:24.386573 2026] [security2:error] [pid 302018:tid 302276] [client 117.247.80.59:25263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NxIAs9lPxxVAErz3r3AAAAQM"]
[Tue Jul 21 07:45:24.386674 2026] [security2:error] [pid 302018:tid 302276] [client 117.247.80.59:25263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NxIAs9lPxxVAErz3r3AAAAQM"]
[Tue Jul 21 07:45:24.503328 2026] [security2:error] [pid 302018:tid 302196] [client 162.241.63.68:52578] ModSecurity: Warning. Matched phrase "fq" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thiagomartins.com"] [uri "/wp-cron.php"] [unique_id "al9NxIAs9lPxxVAErz3r3QAAALM"]
[Tue Jul 21 07:45:24.576989 2026] [security2:error] [pid 296703:tid 296863] [client 122.186.204.214:64923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NxCn25uliftkV1n4SGwAAAB4"]
[Tue Jul 21 07:45:24.587810 2026] [security2:error] [pid 296703:tid 296860] [client 4.204.201.85:9296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/7.php"] [unique_id "al9NxCn25uliftkV1n4SHAAAABs"]
[Tue Jul 21 07:45:24.591739 2026] [security2:error] [pid 296703:tid 296863] [client 122.186.204.214:64923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9NxCn25uliftkV1n4SGwAAAB4"]
[Tue Jul 21 07:45:24.653107 2026] [security2:error] [pid 302018:tid 302223] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/aa.php"] [unique_id "al9NxIAs9lPxxVAErz3r3gAAAM4"]
[Tue Jul 21 07:45:24.870792 2026] [security2:error] [pid 296703:tid 296706] [remote 192.241.143.148:41446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9NxCn25uliftkV1n4SJwAAFQI"]
[Tue Jul 21 07:45:24.888225 2026] [security2:error] [pid 302018:tid 302258] [client 4.204.201.85:9351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/8.php"] [unique_id "al9NxIAs9lPxxVAErz3r5gAAAPE"]
[Tue Jul 21 07:45:24.904729 2026] [security2:error] [pid 296703:tid 296901] [client 117.251.86.144:39056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NxCn25uliftkV1n4SKAAAAEQ"]
[Tue Jul 21 07:45:24.904829 2026] [security2:error] [pid 296703:tid 296901] [client 117.251.86.144:39056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9NxCn25uliftkV1n4SKAAAAEQ"]
[Tue Jul 21 07:45:24.968307 2026] [security2:error] [pid 296703:tid 296855] [client 74.249.245.134:54379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/bootstrap.php"] [unique_id "al9NxCn25uliftkV1n4SKQAAABY"]
[Tue Jul 21 07:45:25.053313 2026] [security2:error] [pid 302018:tid 302256] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/122.php"] [unique_id "al9NxYAs9lPxxVAErz3r6QAAAO8"]
[Tue Jul 21 07:45:25.074954 2026] [security2:error] [pid 302018:tid 302059] [remote 212.80.9.235:34126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9NxYAs9lPxxVAErz3r6gAA3yY"]
[Tue Jul 21 07:45:25.126373 2026] [security2:error] [pid 302018:tid 302260] [client 20.104.96.117:44177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/file.php"] [unique_id "al9NxYAs9lPxxVAErz3r7AAAAPM"]
[Tue Jul 21 07:45:25.170980 2026] [security2:error] [pid 296703:tid 296960] [client 4.204.201.85:22067] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ppsiqueira.com.br"] [uri "/1.php"] [unique_id "al9NxSn25uliftkV1n4SLgAAAH8"]
[Tue Jul 21 07:45:25.171102 2026] [security2:error] [pid 296703:tid 296960] [client 4.204.201.85:22067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/1.php"] [unique_id "al9NxSn25uliftkV1n4SLgAAAH8"]
[Tue Jul 21 07:45:25.324754 2026] [core:alert] [pid 302018:tid 302262] [client 57.141.18.86:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:45:25.336673 2026] [security2:error] [pid 302018:tid 302202] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/get.php"] [unique_id "al9NxYAs9lPxxVAErz3r8wAAALk"]
[Tue Jul 21 07:45:25.440955 2026] [security2:error] [pid 302018:tid 302208] [client 223.236.153.128:5908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9NxIAs9lPxxVAErz3r1wAAAL8"]
[Tue Jul 21 07:45:25.441094 2026] [security2:error] [pid 302018:tid 302208] [client 223.236.153.128:5908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9NxIAs9lPxxVAErz3r1wAAAL8"]
[Tue Jul 21 07:45:25.447781 2026] [security2:error] [pid 302018:tid 302239] [client 4.204.201.85:3510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/100.php"] [unique_id "al9NxYAs9lPxxVAErz3r9AAAAN4"]
[Tue Jul 21 07:45:25.725464 2026] [security2:error] [pid 302018:tid 302187] [client 4.204.201.85:65497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/about.php"] [unique_id "al9NxYAs9lPxxVAErz3r-QAAAKo"]
[Tue Jul 21 07:45:25.788712 2026] [security2:error] [pid 302018:tid 302243] [client 20.104.96.117:30410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/for.php"] [unique_id "al9NxYAs9lPxxVAErz3r_AAAAOI"]
[Tue Jul 21 07:45:25.818716 2026] [security2:error] [pid 302018:tid 302198] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/as.php"] [unique_id "al9NxYAs9lPxxVAErz3r_gAAALU"]
[Tue Jul 21 07:45:25.932179 2026] [security2:error] [pid 296703:tid 296937] [client 20.104.96.117:44165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/777.php"] [unique_id "al9NxSn25uliftkV1n4SRAAAAGg"]
[Tue Jul 21 07:45:26.008686 2026] [security2:error] [pid 296703:tid 296882] [client 4.204.201.85:9389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/admin.php"] [unique_id "al9Nxin25uliftkV1n4SRwAAADE"]
[Tue Jul 21 07:45:26.117026 2026] [security2:error] [pid 296703:tid 296888] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/ccou.php"] [unique_id "al9Nxin25uliftkV1n4SSAAAADc"]
[Tue Jul 21 07:45:26.154143 2026] [security2:error] [pid 302018:tid 302264] [client 20.206.105.145:56598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9NxoAs9lPxxVAErz3sAgAAAPc"]
[Tue Jul 21 07:45:26.188067 2026] [security2:error] [pid 296703:tid 296908] [client 74.249.245.134:5508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/config-backup.php"] [unique_id "al9Nxin25uliftkV1n4SSQAAAEs"]
[Tue Jul 21 07:45:26.284863 2026] [security2:error] [pid 296703:tid 296859] [client 4.204.201.85:22047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/edit.php"] [unique_id "al9Nxin25uliftkV1n4SSgAAABo"]
[Tue Jul 21 07:45:26.400147 2026] [security2:error] [pid 296703:tid 296928] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/w3lls.php"] [unique_id "al9Nxin25uliftkV1n4SVwAAAF8"]
[Tue Jul 21 07:45:26.472896 2026] [security2:error] [pid 302018:tid 302153] [client 20.104.96.117:44270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/ssixta.php"] [unique_id "al9NxoAs9lPxxVAErz3sBgAAAIg"]
[Tue Jul 21 07:45:26.565647 2026] [security2:error] [pid 296703:tid 296858] [client 4.204.201.85:22030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Nxin25uliftkV1n4SWQAAABk"]
[Tue Jul 21 07:45:26.677832 2026] [security2:error] [pid 302018:tid 302167] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/test1.php"] [unique_id "al9NxoAs9lPxxVAErz3sEAAAAJY"]
[Tue Jul 21 07:45:26.758317 2026] [security2:error] [pid 296703:tid 296837] [client 47.128.30.22:21098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "localizavistorias.com"] [uri "/robots.txt"] [unique_id "al9Nxin25uliftkV1n4SYgAAAAQ"]
[Tue Jul 21 07:45:26.844678 2026] [security2:error] [pid 296703:tid 296891] [client 4.204.201.85:3466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/ss.php"] [unique_id "al9Nxin25uliftkV1n4SZQAAADo"]
[Tue Jul 21 07:45:26.949625 2026] [security2:error] [pid 302018:tid 302180] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/database.php"] [unique_id "al9NxoAs9lPxxVAErz3sEwAAAKM"]
[Tue Jul 21 07:45:27.088510 2026] [security2:error] [pid 302018:tid 302240] [client 20.63.100.92:1727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9Nx4As9lPxxVAErz3sFAAAAN8"]
[Tue Jul 21 07:45:27.098114 2026] [security2:error] [pid 296703:tid 296940] [client 59.96.220.140:49625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Nxyn25uliftkV1n4SawAAAGs"]
[Tue Jul 21 07:45:27.098235 2026] [security2:error] [pid 296703:tid 296940] [client 59.96.220.140:49625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Nxyn25uliftkV1n4SawAAAGs"]
[Tue Jul 21 07:45:27.115070 2026] [security2:error] [pid 302018:tid 302048] [remote 45.90.123.233:47178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "escoladaseguranca.com.br"] [uri "/wp-login.php"] [unique_id "al9Nx4As9lPxxVAErz3sFQAA_Rs"]
[Tue Jul 21 07:45:27.136285 2026] [security2:error] [pid 302018:tid 302254] [client 4.204.201.85:65479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/inputs.php"] [unique_id "al9Nx4As9lPxxVAErz3sFwAAAO0"]
[Tue Jul 21 07:45:27.227376 2026] [security2:error] [pid 302018:tid 302253] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/file.php"] [unique_id "al9Nx4As9lPxxVAErz3sGAAAAOw"]
[Tue Jul 21 07:45:27.340281 2026] [security2:error] [pid 302018:tid 302190] [client 20.104.96.117:30452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/ssla.php"] [unique_id "al9Nx4As9lPxxVAErz3sGgAAAK0"]
[Tue Jul 21 07:45:27.412068 2026] [security2:error] [pid 302018:tid 302239] [client 4.204.201.85:9289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/av.php"] [unique_id "al9Nx4As9lPxxVAErz3sHAAAAN4"]
[Tue Jul 21 07:45:27.572829 2026] [security2:error] [pid 296703:tid 296918] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/file.php"] [unique_id "al9Nxyn25uliftkV1n4SdAAAAFU"]
[Tue Jul 21 07:45:27.639523 2026] [security2:error] [pid 302018:tid 302170] [client 20.104.96.117:44192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/1c.php"] [unique_id "al9Nx4As9lPxxVAErz3sJQAAAJk"]
[Tue Jul 21 07:45:27.693346 2026] [security2:error] [pid 296703:tid 296873] [client 4.204.201.85:22004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Nxyn25uliftkV1n4SdgAAACg"]
[Tue Jul 21 07:45:27.864588 2026] [security2:error] [pid 296703:tid 296905] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/777.php"] [unique_id "al9Nxyn25uliftkV1n4SgQAAAEg"]
[Tue Jul 21 07:45:27.969144 2026] [security2:error] [pid 296703:tid 296845] [client 4.204.201.85:9304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9Nxyn25uliftkV1n4ShQAAAAw"]
[Tue Jul 21 07:45:28.056083 2026] [security2:error] [pid 302018:tid 302236] [client 74.249.245.134:62853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/goods.php"] [unique_id "al9NyIAs9lPxxVAErz3sKwAAANs"]
[Tue Jul 21 07:45:28.057396 2026] [security2:error] [pid 302018:tid 302232] [client 20.104.96.117:30534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "solucoesdeti.com.br"] [uri "/zc-131.php"] [unique_id "al9NyIAs9lPxxVAErz3sLAAAANc"]
[Tue Jul 21 07:45:28.141051 2026] [security2:error] [pid 296703:tid 296865] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/ssixta.php"] [unique_id "al9NyCn25uliftkV1n4SjQAAACA"]
[Tue Jul 21 07:45:28.173486 2026] [security2:error] [pid 302018:tid 302264] [client 20.206.105.145:29649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/media.php"] [unique_id "al9NyIAs9lPxxVAErz3sMgAAAPc"]
[Tue Jul 21 07:45:28.246653 2026] [security2:error] [pid 302018:tid 302224] [client 4.204.201.85:9349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-blog.php"] [unique_id "al9NyIAs9lPxxVAErz3sMwAAAM8"]
[Tue Jul 21 07:45:28.320682 2026] [security2:error] [pid 302018:tid 302040] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NyIAs9lPxxVAErz3sNAAA-hM"]
[Tue Jul 21 07:45:28.320843 2026] [security2:error] [pid 302018:tid 302267] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NyIAs9lPxxVAErz3sNAAA-hM"]
[Tue Jul 21 07:45:28.331046 2026] [security2:error] [pid 302018:tid 302237] [client 20.104.96.117:44213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/test2.php"] [unique_id "al9NyIAs9lPxxVAErz3sNQAAANw"]
[Tue Jul 21 07:45:28.335733 2026] [security2:error] [pid 302018:tid 302160] [client 136.144.33.29:39185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9NyIAs9lPxxVAErz3sMQAAAI8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:45:28.424122 2026] [security2:error] [pid 302018:tid 302214] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/1c.php"] [unique_id "al9NyIAs9lPxxVAErz3sNwAAAMU"]
[Tue Jul 21 07:45:28.547914 2026] [security2:error] [pid 296703:tid 296836] [client 165.227.32.93:51481] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9NyCn25uliftkV1n4SlAAAAAM"]
[Tue Jul 21 07:45:28.570363 2026] [security2:error] [pid 302018:tid 302243] [client 154.192.233.199:59964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NyIAs9lPxxVAErz3sPgAAAOI"]
[Tue Jul 21 07:45:28.570485 2026] [security2:error] [pid 302018:tid 302243] [client 154.192.233.199:59964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NyIAs9lPxxVAErz3sPgAAAOI"]
[Tue Jul 21 07:45:28.596183 2026] [security2:error] [pid 302018:tid 302200] [client 20.63.100.92:9821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/inso.php"] [unique_id "al9NyIAs9lPxxVAErz3sPwAAALc"]
[Tue Jul 21 07:45:28.698281 2026] [security2:error] [pid 302018:tid 302165] [client 165.227.32.93:51785] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9NyIAs9lPxxVAErz3sQwAAAJQ"]
[Tue Jul 21 07:45:28.719537 2026] [security2:error] [pid 302018:tid 302181] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/test2.php"] [unique_id "al9NyIAs9lPxxVAErz3sRAAAAKQ"]
[Tue Jul 21 07:45:28.748041 2026] [security2:error] [pid 302018:tid 302157] [client 202.143.127.214:57415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NyIAs9lPxxVAErz3sRgAAAIw"]
[Tue Jul 21 07:45:28.748993 2026] [security2:error] [pid 302018:tid 302157] [client 202.143.127.214:57415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NyIAs9lPxxVAErz3sRgAAAIw"]
[Tue Jul 21 07:45:28.959001 2026] [security2:error] [pid 302018:tid 302192] [client 4.204.201.85:9375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9NyIAs9lPxxVAErz3sTAAAAK8"]
[Tue Jul 21 07:45:28.961751 2026] [security2:error] [pid 302018:tid 302065] [remote 198.244.240.151:23010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.powerflats.com.br"] [uri "/robots.txt"] [unique_id "al9NyIAs9lPxxVAErz3sTgAA7Cw"]
[Tue Jul 21 07:45:28.961914 2026] [security2:error] [pid 302018:tid 302253] [client 198.244.240.151:23010] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.powerflats.com.br"] [uri "/robots.txt"] [unique_id "al9NyIAs9lPxxVAErz3sTgAA7Cw"]
[Tue Jul 21 07:45:28.963627 2026] [security2:error] [pid 302018:tid 302194] [client 20.104.96.117:44272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/buy.php"] [unique_id "al9NyIAs9lPxxVAErz3sTwAAALE"]
[Tue Jul 21 07:45:29.113281 2026] [security2:error] [pid 296703:tid 296863] [client 165.227.32.93:54153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.32.227.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aron.adv.br"] [uri "/xmlrpc.php"] [unique_id "al9NySn25uliftkV1n4SnQAAAB4"]
[Tue Jul 21 07:45:29.129516 2026] [security2:error] [pid 302018:tid 302080] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NyYAs9lPxxVAErz3sVAAAoDs"]
[Tue Jul 21 07:45:29.130003 2026] [security2:error] [pid 302018:tid 302177] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NyYAs9lPxxVAErz3sVAAAoDs"]
[Tue Jul 21 07:45:29.138668 2026] [security2:error] [pid 302018:tid 302150] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/buy.php"] [unique_id "al9NyYAs9lPxxVAErz3sVQAAAIU"]
[Tue Jul 21 07:45:29.152643 2026] [security2:error] [pid 302018:tid 302156] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9NyYAs9lPxxVAErz3sUgAAiwQ"]
[Tue Jul 21 07:45:29.164874 2026] [security2:error] [pid 302018:tid 302232] [client 74.249.245.134:17412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/init.php"] [unique_id "al9NyYAs9lPxxVAErz3sVgAAANc"]
[Tue Jul 21 07:45:29.176795 2026] [security2:error] [pid 302018:tid 302186] [client 103.29.114.44:26187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NyYAs9lPxxVAErz3sVwAAAKk"]
[Tue Jul 21 07:45:29.176976 2026] [security2:error] [pid 302018:tid 302186] [client 103.29.114.44:26187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NyYAs9lPxxVAErz3sVwAAAKk"]
[Tue Jul 21 07:45:29.247468 2026] [security2:error] [pid 302018:tid 302235] [client 4.204.201.85:9394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/adminfuns.php"] [unique_id "al9NyYAs9lPxxVAErz3sWAAAANo"]
[Tue Jul 21 07:45:29.250621 2026] [security2:error] [pid 302018:tid 302241] [client 165.227.32.93:54418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.32.227.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/xmlrpc.php"] [unique_id "al9NyYAs9lPxxVAErz3sWQAAAOA"]
[Tue Jul 21 07:45:29.341969 2026] [security2:error] [pid 302018:tid 302221] [client 152.59.154.239:8680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NyYAs9lPxxVAErz3sWwAAAMw"]
[Tue Jul 21 07:45:29.342108 2026] [security2:error] [pid 302018:tid 302221] [client 152.59.154.239:8680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NyYAs9lPxxVAErz3sWwAAAMw"]
[Tue Jul 21 07:45:29.357099 2026] [security2:error] [pid 296703:tid 296943] [client 139.167.225.182:60640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NySn25uliftkV1n4SpAAAAG4"]
[Tue Jul 21 07:45:29.357183 2026] [security2:error] [pid 296703:tid 296943] [client 139.167.225.182:60640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NySn25uliftkV1n4SpAAAAG4"]
[Tue Jul 21 07:45:29.416261 2026] [security2:error] [pid 302018:tid 302189] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/ssend.php"] [unique_id "al9NyYAs9lPxxVAErz3sXAAAAKw"]
[Tue Jul 21 07:45:29.418284 2026] [security2:error] [pid 296703:tid 296901] [client 165.227.32.93:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9NySn25uliftkV1n4SqAAAAEQ"]
[Tue Jul 21 07:45:29.420408 2026] [security2:error] [pid 302018:tid 302267] [client 20.206.105.145:56594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/images.php"] [unique_id "al9NyYAs9lPxxVAErz3sXQAAAPo"]
[Tue Jul 21 07:45:29.424244 2026] [security2:error] [pid 302018:tid 302216] [client 173.24.185.52:63362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NyYAs9lPxxVAErz3sXgAAAMc"]
[Tue Jul 21 07:45:29.424369 2026] [security2:error] [pid 302018:tid 302216] [client 173.24.185.52:63362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9NyYAs9lPxxVAErz3sXgAAAMc"]
[Tue Jul 21 07:45:29.547523 2026] [security2:error] [pid 302018:tid 302209] [client 4.204.201.85:22045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/goods.php"] [unique_id "al9NyYAs9lPxxVAErz3sYQAAAMA"]
[Tue Jul 21 07:45:29.658701 2026] [security2:error] [pid 302018:tid 302082] [remote 132.148.72.88:54060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9NyIAs9lPxxVAErz3sQQAApT0"]
[Tue Jul 21 07:45:29.690575 2026] [security2:error] [pid 296703:tid 296959] [client 122.162.144.145:9732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NySn25uliftkV1n4SrAAAAH4"]
[Tue Jul 21 07:45:29.690662 2026] [security2:error] [pid 296703:tid 296959] [client 122.162.144.145:9732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9NySn25uliftkV1n4SrAAAAH4"]
[Tue Jul 21 07:45:29.706301 2026] [security2:error] [pid 296703:tid 296952] [client 20.104.96.117:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/ssend.php"] [unique_id "al9NySn25uliftkV1n4SrQAAAHc"]
[Tue Jul 21 07:45:29.718486 2026] [security2:error] [pid 302018:tid 302259] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/item.php"] [unique_id "al9NyYAs9lPxxVAErz3sZwAAAPI"]
[Tue Jul 21 07:45:29.751519 2026] [security2:error] [pid 302018:tid 302258] [client 165.227.32.93:54135] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9NyYAs9lPxxVAErz3saAAAAPE"]
[Tue Jul 21 07:45:29.837742 2026] [security2:error] [pid 296703:tid 296960] [client 4.204.201.85:22073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/ms-edit.php"] [unique_id "al9NySn25uliftkV1n4SrwAAAH8"]
[Tue Jul 21 07:45:29.970324 2026] [security2:error] [pid 302018:tid 302229] [client 165.227.32.93:55916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.32.227.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/xmlrpc.php"] [unique_id "al9NyYAs9lPxxVAErz3sbAAAANQ"]
[Tue Jul 21 07:45:30.039012 2026] [security2:error] [pid 302018:tid 302245] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/ss.php"] [unique_id "al9NyoAs9lPxxVAErz3sbwAAAOQ"]
[Tue Jul 21 07:45:30.108324 2026] [security2:error] [pid 296703:tid 296768] [remote 182.77.62.24:38440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Nyin25uliftkV1n4StAAAXUA"]
[Tue Jul 21 07:45:30.116504 2026] [security2:error] [pid 302018:tid 302277] [client 4.204.201.85:9376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/222.php"] [unique_id "al9NyoAs9lPxxVAErz3scQAAAQQ"]
[Tue Jul 21 07:45:30.217243 2026] [security2:error] [pid 302018:tid 302210] [client 165.227.32.93:55247] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NyoAs9lPxxVAErz3scgAAAME"]
[Tue Jul 21 07:45:30.330172 2026] [security2:error] [pid 296703:tid 296918] [client 165.227.32.93:56647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.32.227.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aronconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9Nyin25uliftkV1n4SuQAAAFU"]
[Tue Jul 21 07:45:30.350325 2026] [security2:error] [pid 302018:tid 302266] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/hypo.php"] [unique_id "al9NyoAs9lPxxVAErz3sdQAAAPk"]
[Tue Jul 21 07:45:30.378576 2026] [security2:error] [pid 302018:tid 302231] [client 165.227.32.93:55519] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NyoAs9lPxxVAErz3seAAAANY"]
[Tue Jul 21 07:45:30.415061 2026] [security2:error] [pid 296703:tid 296851] [client 4.204.201.85:22035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Nyin25uliftkV1n4SuwAAABI"]
[Tue Jul 21 07:45:30.508555 2026] [security2:error] [pid 302018:tid 302089] [remote 54.39.0.8:40454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.powerflats.com.br"] [uri "/"] [unique_id "al9NyoAs9lPxxVAErz3sewAAm0Q"]
[Tue Jul 21 07:45:30.508706 2026] [security2:error] [pid 302018:tid 302172] [client 54.39.0.8:40454] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.powerflats.com.br"] [uri "/"] [unique_id "al9NyoAs9lPxxVAErz3sewAAm0Q"]
[Tue Jul 21 07:45:30.545200 2026] [security2:error] [pid 302018:tid 302156] [client 20.104.96.117:44168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/item.php"] [unique_id "al9NyoAs9lPxxVAErz3sfQAAAIs"]
[Tue Jul 21 07:45:30.690981 2026] [security2:error] [pid 302018:tid 302174] [client 165.227.32.93:57012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9NyoAs9lPxxVAErz3sgQAAAJ0"]
[Tue Jul 21 07:45:30.769779 2026] [security2:error] [pid 302018:tid 302276] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/users.php"] [unique_id "al9NyoAs9lPxxVAErz3sgwAAAQM"]
[Tue Jul 21 07:45:30.782494 2026] [security2:error] [pid 302018:tid 302150] [client 165.227.32.93:57505] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9NyoAs9lPxxVAErz3shAAAAIU"]
[Tue Jul 21 07:45:30.901498 2026] [security2:error] [pid 302018:tid 302208] [client 182.8.255.181:17330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NyoAs9lPxxVAErz3siwAAAL8"]
[Tue Jul 21 07:45:30.901638 2026] [security2:error] [pid 302018:tid 302208] [client 182.8.255.181:17330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9NyoAs9lPxxVAErz3siwAAAL8"]
[Tue Jul 21 07:45:30.936078 2026] [security2:error] [pid 302018:tid 302167] [client 20.104.96.117:44228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/ss.php"] [unique_id "al9NyoAs9lPxxVAErz3sjwAAAJY"]
[Tue Jul 21 07:45:30.971199 2026] [security2:error] [pid 302018:tid 302155] [client 165.227.32.93:57862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9NyoAs9lPxxVAErz3skQAAAIo"]
[Tue Jul 21 07:45:31.040140 2026] [security2:error] [pid 302018:tid 302275] [client 165.227.32.93:57708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Ny4As9lPxxVAErz3slQAAAQI"]
[Tue Jul 21 07:45:31.074925 2026] [security2:error] [pid 296703:tid 296911] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/177.php"] [unique_id "al9Nyyn25uliftkV1n4SxAAAAE4"]
[Tue Jul 21 07:45:31.143916 2026] [security2:error] [pid 302018:tid 302200] [client 4.204.201.85:9283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Ny4As9lPxxVAErz3smAAAALc"]
[Tue Jul 21 07:45:31.247770 2026] [security2:error] [pid 302018:tid 302264] [client 41.68.90.219:50100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ny4As9lPxxVAErz3smgAAAPc"]
[Tue Jul 21 07:45:31.249014 2026] [security2:error] [pid 302018:tid 302264] [client 41.68.90.219:50100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ny4As9lPxxVAErz3smgAAAPc"]
[Tue Jul 21 07:45:31.252071 2026] [security2:error] [pid 302018:tid 302258] [client 165.227.32.93:58535] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Ny4As9lPxxVAErz3smwAAAPE"]
[Tue Jul 21 07:45:31.291949 2026] [security2:error] [pid 296703:tid 296897] [client 154.208.47.43:65173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Nyyn25uliftkV1n4SyAAAAEA"]
[Tue Jul 21 07:45:31.292120 2026] [security2:error] [pid 296703:tid 296897] [client 154.208.47.43:65173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Nyyn25uliftkV1n4SyAAAAEA"]
[Tue Jul 21 07:45:31.349193 2026] [security2:error] [pid 302018:tid 302180] [client 165.227.32.93:58758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Ny4As9lPxxVAErz3snQAAAKM"]
[Tue Jul 21 07:45:31.389660 2026] [security2:error] [pid 296703:tid 296908] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/config.php"] [unique_id "al9Nyyn25uliftkV1n4SygAAAEs"]
[Tue Jul 21 07:45:31.394216 2026] [security2:error] [pid 302018:tid 302176] [client 20.104.96.117:44120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/hypo.php"] [unique_id "al9Ny4As9lPxxVAErz3snwAAAJ8"]
[Tue Jul 21 07:45:31.427903 2026] [security2:error] [pid 302018:tid 302210] [client 20.206.105.145:56671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/adminner.php"] [unique_id "al9Ny4As9lPxxVAErz3soQAAAME"]
[Tue Jul 21 07:45:31.435337 2026] [security2:error] [pid 302018:tid 302224] [client 103.166.103.129:17109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Ny4As9lPxxVAErz3sogAAAM8"]
[Tue Jul 21 07:45:31.435428 2026] [security2:error] [pid 302018:tid 302224] [client 103.166.103.129:17109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Ny4As9lPxxVAErz3sogAAAM8"]
[Tue Jul 21 07:45:31.531863 2026] [security2:error] [pid 302018:tid 302245] [client 165.227.32.93:59076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Ny4As9lPxxVAErz3spQAAAOQ"]
[Tue Jul 21 07:45:31.550526 2026] [security2:error] [pid 302018:tid 302188] [client 178.153.91.96:52532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ny4As9lPxxVAErz3spgAAAKs"]
[Tue Jul 21 07:45:31.550651 2026] [security2:error] [pid 302018:tid 302188] [client 178.153.91.96:52532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ny4As9lPxxVAErz3spgAAAKs"]
[Tue Jul 21 07:45:31.597404 2026] [security2:error] [pid 296703:tid 296848] [client 165.227.32.93:59221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Nyyn25uliftkV1n4SzwAAAA8"]
[Tue Jul 21 07:45:31.657796 2026] [security2:error] [pid 302018:tid 302151] [client 20.63.100.92:9847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/wpx.php"] [unique_id "al9Ny4As9lPxxVAErz3sqwAAAIY"]
[Tue Jul 21 07:45:31.658836 2026] [authz_core:error] [pid 302018:tid 302177] [client 74.249.245.134:54375] AH01630: client denied by server configuration: /home1/ofic8899/viaciaxx.shop-officialstore.com/php.ini
[Tue Jul 21 07:45:31.665566 2026] [security2:error] [pid 296703:tid 296849] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/gettest.php"] [unique_id "al9Nyyn25uliftkV1n4S0gAAABA"]
[Tue Jul 21 07:45:31.674347 2026] [security2:error] [pid 296703:tid 296907] [client 103.86.117.203:62703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Nyyn25uliftkV1n4S0wAAAEo"]
[Tue Jul 21 07:45:31.674499 2026] [security2:error] [pid 296703:tid 296907] [client 103.86.117.203:62703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Nyyn25uliftkV1n4S0wAAAEo"]
[Tue Jul 21 07:45:31.778720 2026] [security2:error] [pid 302018:tid 302085] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ny4As9lPxxVAErz3srQAAvkA"]
[Tue Jul 21 07:45:31.778883 2026] [security2:error] [pid 302018:tid 302207] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ny4As9lPxxVAErz3srQAAvkA"]
[Tue Jul 21 07:45:31.800029 2026] [security2:error] [pid 302018:tid 302174] [client 74.249.245.134:54375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/settings.php"] [unique_id "al9Ny4As9lPxxVAErz3ssAAAAJ0"]
[Tue Jul 21 07:45:31.815559 2026] [security2:error] [pid 302018:tid 302170] [client 165.227.32.93:59606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Ny4As9lPxxVAErz3ssQAAAJk"]
[Tue Jul 21 07:45:31.910603 2026] [security2:error] [pid 296703:tid 296913] [client 165.227.32.93:59786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9Nyyn25uliftkV1n4S1wAAAFA"]
[Tue Jul 21 07:45:31.951408 2026] [security2:error] [pid 302018:tid 302195] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/min.php"] [unique_id "al9Ny4As9lPxxVAErz3sswAAALI"]
[Tue Jul 21 07:45:31.972798 2026] [security2:error] [pid 296703:tid 296898] [client 20.104.96.117:44890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/users.php"] [unique_id "al9Nyyn25uliftkV1n4S2QAAAEE"]
[Tue Jul 21 07:45:32.101151 2026] [security2:error] [pid 296703:tid 296924] [client 165.227.32.93:60159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9NzCn25uliftkV1n4S3QAAAFs"]
[Tue Jul 21 07:45:32.103793 2026] [security2:error] [pid 302018:tid 302190] [client 20.206.105.145:56687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/admin.php"] [unique_id "al9NzIAs9lPxxVAErz3suAAAAK0"]
[Tue Jul 21 07:45:32.156906 2026] [security2:error] [pid 302018:tid 302150] [client 165.227.32.93:60265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9NzIAs9lPxxVAErz3suwAAAIU"]
[Tue Jul 21 07:45:32.257030 2026] [security2:error] [pid 302018:tid 302211] [client 159.223.41.76:49782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bracksimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NzIAs9lPxxVAErz3svgAAAMI"]
[Tue Jul 21 07:45:32.257119 2026] [security2:error] [pid 302018:tid 302211] [client 159.223.41.76:49782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bracksimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NzIAs9lPxxVAErz3svgAAAMI"]
[Tue Jul 21 07:45:32.280939 2026] [security2:error] [pid 302018:tid 302105] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NzIAs9lPxxVAErz3svwAA3FQ"]
[Tue Jul 21 07:45:32.281100 2026] [security2:error] [pid 302018:tid 302237] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9NzIAs9lPxxVAErz3svwAA3FQ"]
[Tue Jul 21 07:45:32.374982 2026] [security2:error] [pid 302018:tid 302265] [client 165.227.32.93:60638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9NzIAs9lPxxVAErz3swQAAAPg"]
[Tue Jul 21 07:45:32.377367 2026] [security2:error] [pid 302018:tid 302165] [client 4.204.201.85:3495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp.php"] [unique_id "al9NzIAs9lPxxVAErz3swgAAAJQ"]
[Tue Jul 21 07:45:32.405135 2026] [security2:error] [pid 296703:tid 296915] [client 106.215.181.8:15024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NzCn25uliftkV1n4S4gAAAFI"]
[Tue Jul 21 07:45:32.405248 2026] [security2:error] [pid 296703:tid 296915] [client 106.215.181.8:15024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NzCn25uliftkV1n4S4gAAAFI"]
[Tue Jul 21 07:45:32.462847 2026] [security2:error] [pid 302018:tid 302062] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NzIAs9lPxxVAErz3sxAABAik"]
[Tue Jul 21 07:45:32.462990 2026] [security2:error] [pid 302018:tid 302275] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9NzIAs9lPxxVAErz3sxAABAik"]
[Tue Jul 21 07:45:32.465186 2026] [security2:error] [pid 296703:tid 296874] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/dvjul.php"] [unique_id "al9NzCn25uliftkV1n4S4wAAACk"]
[Tue Jul 21 07:45:32.469136 2026] [security2:error] [pid 302018:tid 302259] [client 165.227.32.93:60832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NzIAs9lPxxVAErz3sxQAAAPI"]
[Tue Jul 21 07:45:32.575805 2026] [security2:error] [pid 296703:tid 296945] [client 20.104.96.117:44135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/177.php"] [unique_id "al9NzCn25uliftkV1n4S5gAAAHA"]
[Tue Jul 21 07:45:32.626525 2026] [autoindex:error] [pid 302018:tid 302192] [client 85.204.70.114:0] AH01276: Cannot serve directory /home3/rapha354/espaconeuroascensao.com.br/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:32.656356 2026] [security2:error] [pid 302018:tid 302245] [client 4.204.201.85:22064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/abcd.php"] [unique_id "al9NzIAs9lPxxVAErz3s0AAAAOQ"]
[Tue Jul 21 07:45:32.659044 2026] [security2:error] [pid 302018:tid 302254] [client 165.227.32.93:61237] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NzIAs9lPxxVAErz3s0QAAAO0"]
[Tue Jul 21 07:45:32.718972 2026] [security2:error] [pid 296703:tid 296847] [client 165.227.32.93:61343] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9NzCn25uliftkV1n4S6AAAAA4"]
[Tue Jul 21 07:45:32.759203 2026] [security2:error] [pid 302018:tid 302100] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NzIAs9lPxxVAErz3s0gAA1E8"]
[Tue Jul 21 07:45:32.759328 2026] [security2:error] [pid 302018:tid 302229] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NzIAs9lPxxVAErz3s0gAA1E8"]
[Tue Jul 21 07:45:32.783926 2026] [security2:error] [pid 302018:tid 302172] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/biufile.php"] [unique_id "al9NzIAs9lPxxVAErz3s0wAAAJs"]
[Tue Jul 21 07:45:32.933615 2026] [security2:error] [pid 302018:tid 302241] [client 4.204.201.85:22068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/a1.php"] [unique_id "al9NzIAs9lPxxVAErz3s1AAAAOA"]
[Tue Jul 21 07:45:32.936968 2026] [security2:error] [pid 302018:tid 302188] [client 165.227.32.93:61869] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NzIAs9lPxxVAErz3s1QAAAKs"]
[Tue Jul 21 07:45:32.973586 2026] [security2:error] [pid 302018:tid 302235] [client 20.206.105.145:29644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/k.php"] [unique_id "al9NzIAs9lPxxVAErz3s1gAAANo"]
[Tue Jul 21 07:45:32.988057 2026] [security2:error] [pid 296703:tid 296867] [client 20.104.96.117:44266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/config.php"] [unique_id "al9NzCn25uliftkV1n4S7QAAACI"]
[Tue Jul 21 07:45:33.030006 2026] [security2:error] [pid 302018:tid 302177] [client 165.227.32.93:62083] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9NzYAs9lPxxVAErz3s2AAAAKA"]
[Tue Jul 21 07:45:33.070351 2026] [security2:error] [pid 302018:tid 302221] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/av.php"] [unique_id "al9NzYAs9lPxxVAErz3s2QAAAMw"]
[Tue Jul 21 07:45:33.220600 2026] [security2:error] [pid 302018:tid 302247] [client 4.204.201.85:21969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9NzYAs9lPxxVAErz3s3gAAAOY"]
[Tue Jul 21 07:45:33.224230 2026] [security2:error] [pid 302018:tid 302260] [client 165.227.32.93:62608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9NzYAs9lPxxVAErz3s3wAAAPM"]
[Tue Jul 21 07:45:33.285348 2026] [security2:error] [pid 302018:tid 302204] [client 165.227.32.93:62735] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9NzYAs9lPxxVAErz3s4QAAALs"]
[Tue Jul 21 07:45:33.327159 2026] [security2:error] [pid 302018:tid 302150] [client 20.206.105.145:56580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/x.php"] [unique_id "al9NzYAs9lPxxVAErz3s4gAAAIU"]
[Tue Jul 21 07:45:33.338596 2026] [security2:error] [pid 302018:tid 302095] [remote 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amandamorau.adv.br"] [uri "/wp-login.php"] [unique_id "al9NzYAs9lPxxVAErz3s4wAA20o"]
[Tue Jul 21 07:45:33.366614 2026] [security2:error] [pid 302018:tid 302211] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/coffexium.php"] [unique_id "al9NzYAs9lPxxVAErz3s5AAAAMI"]
[Tue Jul 21 07:45:33.378654 2026] [security2:error] [pid 296703:tid 296819] [remote 68.178.165.65:48608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "premiercservices.com"] [uri "/wp-login.php"] [unique_id "al9NzSn25uliftkV1n4S8QAAd3M"]
[Tue Jul 21 07:45:33.400821 2026] [security2:error] [pid 296703:tid 296929] [client 122.164.127.47:64776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NzSn25uliftkV1n4S8wAAAGA"]
[Tue Jul 21 07:45:33.400953 2026] [security2:error] [pid 296703:tid 296929] [client 122.164.127.47:64776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9NzSn25uliftkV1n4S8wAAAGA"]
[Tue Jul 21 07:45:33.411173 2026] [security2:error] [pid 302018:tid 302243] [client 20.220.225.223:34291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/ace2.php"] [unique_id "al9NzYAs9lPxxVAErz3s5QAAAOI"]
[Tue Jul 21 07:45:33.451671 2026] [security2:error] [pid 302018:tid 302182] [client 136.144.33.104:64235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9NzYAs9lPxxVAErz3s5gAAAKU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:45:33.504380 2026] [security2:error] [pid 302018:tid 302190] [client 165.227.32.93:63140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9NzYAs9lPxxVAErz3s6QAAAK0"]
[Tue Jul 21 07:45:33.547731 2026] [security2:error] [pid 302018:tid 302206] [client 4.204.201.85:9366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9NzYAs9lPxxVAErz3s7AAAAL0"]
[Tue Jul 21 07:45:33.608966 2026] [security2:error] [pid 296703:tid 296885] [client 165.227.32.93:63450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9NzSn25uliftkV1n4S9gAAADQ"]
[Tue Jul 21 07:45:33.684302 2026] [security2:error] [pid 302018:tid 302224] [client 20.104.96.117:44155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/gettest.php"] [unique_id "al9NzYAs9lPxxVAErz3s7gAAAM8"]
[Tue Jul 21 07:45:33.753321 2026] [security2:error] [pid 302018:tid 302276] [client 103.174.34.15:64696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NzYAs9lPxxVAErz3s8gAAAQM"]
[Tue Jul 21 07:45:33.753485 2026] [security2:error] [pid 302018:tid 302276] [client 103.174.34.15:64696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NzYAs9lPxxVAErz3s8gAAAQM"]
[Tue Jul 21 07:45:33.782311 2026] [security2:error] [pid 302018:tid 302265] [client 165.227.32.93:63808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9NzYAs9lPxxVAErz3s8wAAAPg"]
[Tue Jul 21 07:45:33.828650 2026] [security2:error] [pid 302018:tid 302187] [client 4.204.201.85:9331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/gettest.php"] [unique_id "al9NzYAs9lPxxVAErz3s9QAAAKo"]
[Tue Jul 21 07:45:33.849472 2026] [security2:error] [pid 302018:tid 302185] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/core.php"] [unique_id "al9NzYAs9lPxxVAErz3s9wAAAKg"]
[Tue Jul 21 07:45:33.866832 2026] [security2:error] [pid 302018:tid 302196] [client 109.60.28.94:60246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NzYAs9lPxxVAErz3s7wAAALM"]
[Tue Jul 21 07:45:33.874713 2026] [security2:error] [pid 302018:tid 302202] [client 165.227.32.93:63945] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9NzYAs9lPxxVAErz3s-QAAALk"]
[Tue Jul 21 07:45:33.973030 2026] [security2:error] [pid 302018:tid 302143] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NzYAs9lPxxVAErz3s-gAA4Ho"]
[Tue Jul 21 07:45:33.973153 2026] [security2:error] [pid 302018:tid 302241] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9NzYAs9lPxxVAErz3s-gAA4Ho"]
[Tue Jul 21 07:45:34.063099 2026] [security2:error] [pid 302018:tid 302205] [client 165.227.32.93:64369] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9NzoAs9lPxxVAErz3s-wAAALw"]
[Tue Jul 21 07:45:34.119131 2026] [security2:error] [pid 302018:tid 302272] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/als.php"] [unique_id "al9NzoAs9lPxxVAErz3s_wAAAP8"]
[Tue Jul 21 07:45:34.156136 2026] [security2:error] [pid 296703:tid 296932] [client 122.179.91.63:25437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Nzin25uliftkV1n4S_gAAAGM"]
[Tue Jul 21 07:45:34.156269 2026] [security2:error] [pid 296703:tid 296932] [client 122.179.91.63:25437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Nzin25uliftkV1n4S_gAAAGM"]
[Tue Jul 21 07:45:34.177148 2026] [security2:error] [pid 296703:tid 296862] [client 165.227.32.93:64631] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Nzin25uliftkV1n4TAAAAAB0"]
[Tue Jul 21 07:45:34.242152 2026] [security2:error] [pid 296703:tid 296937] [client 20.206.105.145:56700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wss.php"] [unique_id "al9Nzin25uliftkV1n4TAQAAAGg"]
[Tue Jul 21 07:45:34.344965 2026] [security2:error] [pid 302018:tid 302207] [client 165.227.32.93:65041] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NzoAs9lPxxVAErz3tAQAAAL4"]
[Tue Jul 21 07:45:34.372079 2026] [security2:error] [pid 302018:tid 302150] [client 20.104.96.117:44238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/min.php"] [unique_id "al9NzoAs9lPxxVAErz3tAwAAAIU"]
[Tue Jul 21 07:45:34.396502 2026] [security2:error] [pid 302018:tid 302263] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/simple.php"] [unique_id "al9NzoAs9lPxxVAErz3tBQAAAPY"]
[Tue Jul 21 07:45:34.436914 2026] [security2:error] [pid 302018:tid 302267] [client 165.227.32.93:65194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9NzoAs9lPxxVAErz3tBgAAAPo"]
[Tue Jul 21 07:45:34.509246 2026] [security2:error] [pid 302018:tid 302231] [client 223.236.153.128:1889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9NzoAs9lPxxVAErz3tCQAAANY"]
[Tue Jul 21 07:45:34.509389 2026] [security2:error] [pid 302018:tid 302231] [client 223.236.153.128:1889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9NzoAs9lPxxVAErz3tCQAAANY"]
[Tue Jul 21 07:45:34.552598 2026] [security2:error] [pid 302018:tid 302222] [client 4.204.201.85:22043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/simple.php"] [unique_id "al9NzoAs9lPxxVAErz3tCwAAAM0"]
[Tue Jul 21 07:45:34.567055 2026] [security2:error] [pid 302018:tid 302198] [client 117.217.38.194:58425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NzoAs9lPxxVAErz3tDAAAALU"]
[Tue Jul 21 07:45:34.567143 2026] [security2:error] [pid 302018:tid 302198] [client 117.217.38.194:58425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9NzoAs9lPxxVAErz3tDAAAALU"]
[Tue Jul 21 07:45:34.625684 2026] [security2:error] [pid 302018:tid 302204] [client 165.227.32.93:49189] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NzoAs9lPxxVAErz3tDQAAALs"]
[Tue Jul 21 07:45:34.735511 2026] [security2:error] [pid 302018:tid 302237] [client 165.227.32.93:49439] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NzoAs9lPxxVAErz3tDwAAANw"]
[Tue Jul 21 07:45:34.846242 2026] [security2:error] [pid 302018:tid 302239] [client 4.204.201.85:9373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/xxx.php"] [unique_id "al9NzoAs9lPxxVAErz3tEgAAAN4"]
[Tue Jul 21 07:45:34.847339 2026] [security2:error] [pid 296703:tid 296925] [client 20.104.96.117:44157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/dvjul.php"] [unique_id "al9Nzin25uliftkV1n4TDQAAAFw"]
[Tue Jul 21 07:45:34.908878 2026] [security2:error] [pid 302018:tid 302157] [client 165.227.32.93:49819] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9NzoAs9lPxxVAErz3tEwAAAIw"]
[Tue Jul 21 07:45:34.927510 2026] [security2:error] [pid 302018:tid 302187] [client 74.249.245.134:54370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/g.php"] [unique_id "al9NzoAs9lPxxVAErz3tFgAAAKo"]
[Tue Jul 21 07:45:34.981360 2026] [security2:error] [pid 296703:tid 296906] [client 20.104.96.117:46662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Nzin25uliftkV1n4TEQAAAEk"]
[Tue Jul 21 07:45:34.993382 2026] [security2:error] [pid 302018:tid 302156] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/init.php"] [unique_id "al9NzoAs9lPxxVAErz3tGAAAAIs"]
[Tue Jul 21 07:45:34.999992 2026] [security2:error] [pid 302018:tid 302203] [client 165.227.32.93:50032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9NzoAs9lPxxVAErz3tGQAAALo"]
[Tue Jul 21 07:45:35.130946 2026] [security2:error] [pid 302018:tid 302221] [client 4.204.201.85:3480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/hypo.php"] [unique_id "al9Nz4As9lPxxVAErz3tHQAAAMw"]
[Tue Jul 21 07:45:35.153178 2026] [security2:error] [pid 302018:tid 302270] [client 117.247.80.59:25613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nz4As9lPxxVAErz3tHgAAAP0"]
[Tue Jul 21 07:45:35.153299 2026] [security2:error] [pid 302018:tid 302270] [client 117.247.80.59:25613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Nz4As9lPxxVAErz3tHgAAAP0"]
[Tue Jul 21 07:45:35.188702 2026] [security2:error] [pid 302018:tid 302265] [client 165.227.32.93:50389] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Nz4As9lPxxVAErz3tHwAAAPg"]
[Tue Jul 21 07:45:35.279010 2026] [security2:error] [pid 302018:tid 302247] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/fpwch.php"] [unique_id "al9Nz4As9lPxxVAErz3tIAAAAOY"]
[Tue Jul 21 07:45:35.282553 2026] [security2:error] [pid 302018:tid 302259] [client 122.186.204.214:65459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Nz4As9lPxxVAErz3tIQAAAPI"]
[Tue Jul 21 07:45:35.282750 2026] [security2:error] [pid 302018:tid 302259] [client 122.186.204.214:65459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Nz4As9lPxxVAErz3tIQAAAPI"]
[Tue Jul 21 07:45:35.295204 2026] [security2:error] [pid 302018:tid 302233] [client 165.227.32.93:50620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Nz4As9lPxxVAErz3tIgAAANg"]
[Tue Jul 21 07:45:35.320160 2026] [security2:error] [pid 302018:tid 302223] [client 20.206.105.145:56670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/ty.php"] [unique_id "al9Nz4As9lPxxVAErz3tJQAAAM4"]
[Tue Jul 21 07:45:35.467836 2026] [security2:error] [pid 302018:tid 302272] [client 165.227.32.93:50945] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Nz4As9lPxxVAErz3tKAAAAP8"]
[Tue Jul 21 07:45:35.561845 2026] [security2:error] [pid 296703:tid 296891] [client 165.227.32.93:51119] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Nzyn25uliftkV1n4TGQAAADo"]
[Tue Jul 21 07:45:35.573568 2026] [security2:error] [pid 296703:tid 296901] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/domvf.php"] [unique_id "al9Nzyn25uliftkV1n4TGgAAAEQ"]
[Tue Jul 21 07:45:35.660240 2026] [security2:error] [pid 302018:tid 302206] [client 20.104.96.117:44269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/biufile.php"] [unique_id "al9Nz4As9lPxxVAErz3tLAAAAL0"]
[Tue Jul 21 07:45:35.725262 2026] [security2:error] [pid 302018:tid 302273] [client 20.206.105.145:56684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/155.php"] [unique_id "al9Nz4As9lPxxVAErz3tLgAAAQA"]
[Tue Jul 21 07:45:35.738439 2026] [security2:error] [pid 296703:tid 296924] [client 117.251.86.144:55380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Nzyn25uliftkV1n4THQAAAFs"]
[Tue Jul 21 07:45:35.738569 2026] [security2:error] [pid 296703:tid 296924] [client 117.251.86.144:55380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Nzyn25uliftkV1n4THQAAAFs"]
[Tue Jul 21 07:45:35.754634 2026] [security2:error] [pid 302018:tid 302222] [client 165.227.32.93:51551] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Nz4As9lPxxVAErz3tLwAAAM0"]
[Tue Jul 21 07:45:35.858521 2026] [security2:error] [pid 296703:tid 296960] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wp.php"] [unique_id "al9Nzyn25uliftkV1n4THwAAAH8"]
[Tue Jul 21 07:45:35.858766 2026] [security2:error] [pid 302018:tid 302276] [client 4.204.201.85:21982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/chosen.php"] [unique_id "al9Nz4As9lPxxVAErz3tMAAAAQM"]
[Tue Jul 21 07:45:35.865314 2026] [security2:error] [pid 296703:tid 296847] [client 165.227.32.93:51831] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Nzyn25uliftkV1n4TIAAAAA4"]
[Tue Jul 21 07:45:36.033117 2026] [security2:error] [pid 302018:tid 302277] [client 165.227.32.93:52232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9N0IAs9lPxxVAErz3tNAAAAQQ"]
[Tue Jul 21 07:45:36.066553 2026] [security2:error] [pid 302018:tid 302119] [remote 117.0.21.154:33046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9N0IAs9lPxxVAErz3tNwAAj2I"]
[Tue Jul 21 07:45:36.127302 2026] [security2:error] [pid 302018:tid 302224] [client 165.227.32.93:52428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9N0IAs9lPxxVAErz3tPAAAAM8"]
[Tue Jul 21 07:45:36.141223 2026] [security2:error] [pid 296703:tid 296836] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/class.php"] [unique_id "al9N0Cn25uliftkV1n4TJgAAAAM"]
[Tue Jul 21 07:45:36.313624 2026] [security2:error] [pid 296703:tid 296869] [client 165.227.32.93:52795] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9N0Cn25uliftkV1n4TKAAAACQ"]
[Tue Jul 21 07:45:36.427433 2026] [security2:error] [pid 302018:tid 302235] [client 165.227.32.93:53065] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9N0IAs9lPxxVAErz3tQwAAANo"]
[Tue Jul 21 07:45:36.457291 2026] [security2:error] [pid 296703:tid 296879] [client 37.140.223.50:25121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Nzyn25uliftkV1n4TGAAAAC4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:45:36.473789 2026] [security2:error] [pid 296703:tid 296851] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/echkm.php"] [unique_id "al9N0Cn25uliftkV1n4TLAAAABI"]
[Tue Jul 21 07:45:36.482406 2026] [security2:error] [pid 302018:tid 302162] [client 20.104.96.117:44197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/av.php"] [unique_id "al9N0IAs9lPxxVAErz3tRAAAAJE"]
[Tue Jul 21 07:45:36.573999 2026] [security2:error] [pid 302018:tid 302259] [client 4.204.201.85:22024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/als.php"] [unique_id "al9N0IAs9lPxxVAErz3tRQAAAPI"]
[Tue Jul 21 07:45:36.597435 2026] [security2:error] [pid 302018:tid 302219] [client 165.227.32.93:53561] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9N0IAs9lPxxVAErz3tRgAAAMo"]
[Tue Jul 21 07:45:36.658628 2026] [security2:error] [pid 302018:tid 302216] [client 20.206.105.145:56686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/ops.php"] [unique_id "al9N0IAs9lPxxVAErz3tRwAAAMc"]
[Tue Jul 21 07:45:36.690010 2026] [security2:error] [pid 296703:tid 296902] [client 165.227.32.93:53786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9N0Cn25uliftkV1n4TLwAAAEU"]
[Tue Jul 21 07:45:36.756837 2026] [security2:error] [pid 302018:tid 302267] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/lib.php"] [unique_id "al9N0IAs9lPxxVAErz3tSgAAAPo"]
[Tue Jul 21 07:45:36.854631 2026] [security2:error] [pid 302018:tid 302240] [client 4.204.201.85:3513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/pol.php"] [unique_id "al9N0IAs9lPxxVAErz3tTAAAAN8"]
[Tue Jul 21 07:45:36.881423 2026] [security2:error] [pid 302018:tid 302233] [client 165.227.32.93:54159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9N0IAs9lPxxVAErz3tTQAAANg"]
[Tue Jul 21 07:45:36.887294 2026] [security2:error] [pid 296703:tid 296909] [client 20.104.96.117:44171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/coffexium.php"] [unique_id "al9N0Cn25uliftkV1n4TNAAAAEw"]
[Tue Jul 21 07:45:36.982998 2026] [security2:error] [pid 302018:tid 302228] [client 165.227.32.93:54350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9N0IAs9lPxxVAErz3tTgAAANM"]
[Tue Jul 21 07:45:37.040470 2026] [security2:error] [pid 302018:tid 302165] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/login.php"] [unique_id "al9N0YAs9lPxxVAErz3tTwAAAJQ"]
[Tue Jul 21 07:45:37.130926 2026] [security2:error] [pid 302018:tid 302222] [client 4.204.201.85:9348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/file5.php"] [unique_id "al9N0YAs9lPxxVAErz3tUwAAAM0"]
[Tue Jul 21 07:45:37.155189 2026] [security2:error] [pid 302018:tid 302182] [client 165.227.32.93:54745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9N0YAs9lPxxVAErz3tVQAAAKU"]
[Tue Jul 21 07:45:37.158889 2026] [security2:error] [pid 296703:tid 296954] [client 154.192.233.199:59591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N0Sn25uliftkV1n4TOAAAAHk"]
[Tue Jul 21 07:45:37.158995 2026] [security2:error] [pid 296703:tid 296954] [client 154.192.233.199:59591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N0Sn25uliftkV1n4TOAAAAHk"]
[Tue Jul 21 07:45:37.251587 2026] [security2:error] [pid 302018:tid 302234] [client 165.227.32.93:54926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9N0YAs9lPxxVAErz3tWAAAANk"]
[Tue Jul 21 07:45:37.322874 2026] [security2:error] [pid 296703:tid 296893] [client 193.36.225.70:32191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9N0Sn25uliftkV1n4TNgAAADw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:45:37.329338 2026] [security2:error] [pid 296703:tid 296897] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/a2.php"] [unique_id "al9N0Sn25uliftkV1n4TOgAAAEA"]
[Tue Jul 21 07:45:37.414310 2026] [security2:error] [pid 302018:tid 302269] [client 4.204.201.85:9395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/file.php"] [unique_id "al9N0YAs9lPxxVAErz3tWQAAAPw"]
[Tue Jul 21 07:45:37.435894 2026] [security2:error] [pid 302018:tid 302249] [client 165.227.32.93:55247] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9N0YAs9lPxxVAErz3tXQAAAOg"]
[Tue Jul 21 07:45:37.444285 2026] [security2:error] [pid 302018:tid 302271] [client 20.104.96.117:44137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/core.php"] [unique_id "al9N0YAs9lPxxVAErz3tXgAAAP4"]
[Tue Jul 21 07:45:37.546837 2026] [security2:error] [pid 296703:tid 296908] [client 165.227.32.93:55444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9N0Sn25uliftkV1n4TPgAAAEs"]
[Tue Jul 21 07:45:37.642903 2026] [security2:error] [pid 302018:tid 302205] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/d61.php"] [unique_id "al9N0YAs9lPxxVAErz3tXwAAALw"]
[Tue Jul 21 07:45:37.687005 2026] [security2:error] [pid 296703:tid 296913] [client 62.102.148.187:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9N0Sn25uliftkV1n4TQAAAAFA"]
[Tue Jul 21 07:45:37.687095 2026] [security2:error] [pid 296703:tid 296913] [client 62.102.148.187:51954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9N0Sn25uliftkV1n4TQAAAAFA"]
[Tue Jul 21 07:45:37.712898 2026] [security2:error] [pid 302018:tid 302221] [client 4.204.201.85:22053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/cfile.php"] [unique_id "al9N0YAs9lPxxVAErz3tYQAAAMw"]
[Tue Jul 21 07:45:37.722882 2026] [security2:error] [pid 302018:tid 302196] [client 165.227.32.93:55864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9N0YAs9lPxxVAErz3tYgAAALM"]
[Tue Jul 21 07:45:37.818374 2026] [security2:error] [pid 296703:tid 296907] [client 165.227.32.93:55987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9N0Sn25uliftkV1n4TRAAAAEo"]
[Tue Jul 21 07:45:37.862664 2026] [security2:error] [pid 302018:tid 302247] [client 20.206.105.145:56591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/ingfo.php"] [unique_id "al9N0YAs9lPxxVAErz3tZgAAAOY"]
[Tue Jul 21 07:45:37.951340 2026] [security2:error] [pid 296703:tid 296957] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/info.php"] [unique_id "al9N0Sn25uliftkV1n4TSAAAAHw"]
[Tue Jul 21 07:45:37.990089 2026] [security2:error] [pid 302018:tid 302152] [client 4.204.201.85:65525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/admin.php"] [unique_id "al9N0YAs9lPxxVAErz3tagAAAIc"]
[Tue Jul 21 07:45:38.015569 2026] [security2:error] [pid 296703:tid 296894] [client 165.227.32.93:56375] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9N0in25uliftkV1n4TSQAAAD0"]
[Tue Jul 21 07:45:38.025564 2026] [security2:error] [pid 302018:tid 302227] [client 185.213.175.37:38896] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "archrender.com.br"] [uri "/feed/"] [unique_id "al9N0oAs9lPxxVAErz3tawAAANI"]
[Tue Jul 21 07:45:38.115533 2026] [security2:error] [pid 302018:tid 302265] [client 165.227.32.93:56564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9N0oAs9lPxxVAErz3tbAAAAPg"]
[Tue Jul 21 07:45:38.235841 2026] [security2:error] [pid 302018:tid 302182] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/11.php"] [unique_id "al9N0oAs9lPxxVAErz3tcAAAAKU"]
[Tue Jul 21 07:45:38.266480 2026] [security2:error] [pid 302018:tid 302262] [client 4.204.201.85:9340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/aa2.php"] [unique_id "al9N0oAs9lPxxVAErz3tcgAAAPU"]
[Tue Jul 21 07:45:38.289912 2026] [security2:error] [pid 302018:tid 302207] [client 165.227.32.93:56909] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9N0oAs9lPxxVAErz3tcwAAAL4"]
[Tue Jul 21 07:45:38.306090 2026] [security2:error] [pid 302018:tid 302151] [client 20.104.96.117:44186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/als.php"] [unique_id "al9N0oAs9lPxxVAErz3tdAAAAIY"]
[Tue Jul 21 07:45:38.375295 2026] [security2:error] [pid 296703:tid 296939] [client 165.227.32.93:57037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9N0in25uliftkV1n4TTgAAAGo"]
[Tue Jul 21 07:45:38.470456 2026] [security2:error] [pid 302018:tid 302203] [client 20.206.105.145:56701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/error_log.php"] [unique_id "al9N0oAs9lPxxVAErz3tdQAAALo"]
[Tue Jul 21 07:45:38.520365 2026] [security2:error] [pid 302018:tid 302264] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/v2.php"] [unique_id "al9N0oAs9lPxxVAErz3tdgAAAPc"]
[Tue Jul 21 07:45:38.565781 2026] [security2:error] [pid 302018:tid 302215] [client 4.204.201.85:22008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/ccou.php"] [unique_id "al9N0oAs9lPxxVAErz3teQAAAMY"]
[Tue Jul 21 07:45:38.578616 2026] [security2:error] [pid 302018:tid 302253] [client 165.227.32.93:57443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9N0oAs9lPxxVAErz3tewAAAOw"]
[Tue Jul 21 07:45:38.673383 2026] [security2:error] [pid 302018:tid 302246] [client 165.227.32.93:57672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9N0oAs9lPxxVAErz3tfgAAAOU"]
[Tue Jul 21 07:45:38.832216 2026] [security2:error] [pid 302018:tid 302150] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/panel.php"] [unique_id "al9N0oAs9lPxxVAErz3tgQAAAIU"]
[Tue Jul 21 07:45:38.844582 2026] [security2:error] [pid 302018:tid 302263] [client 4.204.201.85:21962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/dr.php"] [unique_id "al9N0oAs9lPxxVAErz3tggAAAPY"]
[Tue Jul 21 07:45:38.849972 2026] [security2:error] [pid 296703:tid 296861] [client 165.227.32.93:58075] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9N0in25uliftkV1n4TVAAAABw"]
[Tue Jul 21 07:45:38.924767 2026] [security2:error] [pid 302018:tid 302261] [client 20.206.105.145:56650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/ok.php"] [unique_id "al9N0oAs9lPxxVAErz3tgwAAAPQ"]
[Tue Jul 21 07:45:38.937242 2026] [security2:error] [pid 302018:tid 302270] [client 165.227.32.93:58319] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9N0oAs9lPxxVAErz3thQAAAP0"]
[Tue Jul 21 07:45:39.023549 2026] [security2:error] [pid 302018:tid 302087] [remote 104.207.48.198:50749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.48.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9N04As9lPxxVAErz3tiQAAs0I"]
[Tue Jul 21 07:45:39.120224 2026] [security2:error] [pid 296703:tid 296914] [client 4.204.201.85:22031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/xamp.php"] [unique_id "al9N0yn25uliftkV1n4TWQAAAFE"]
[Tue Jul 21 07:45:39.124910 2026] [security2:error] [pid 302018:tid 302258] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/dex.php"] [unique_id "al9N04As9lPxxVAErz3tigAAAPE"]
[Tue Jul 21 07:45:39.140165 2026] [security2:error] [pid 302018:tid 302211] [client 165.227.32.93:58846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9N04As9lPxxVAErz3tiwAAAMI"]
[Tue Jul 21 07:45:39.170569 2026] [security2:error] [pid 296703:tid 296960] [client 20.206.105.145:56605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/mac.php"] [unique_id "al9N0yn25uliftkV1n4TWgAAAH8"]
[Tue Jul 21 07:45:39.264522 2026] [security2:error] [pid 302018:tid 302190] [client 59.96.220.140:50159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9N04As9lPxxVAErz3tjAAAAK0"]
[Tue Jul 21 07:45:39.264614 2026] [security2:error] [pid 302018:tid 302190] [client 59.96.220.140:50159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9N04As9lPxxVAErz3tjAAAAK0"]
[Tue Jul 21 07:45:39.278249 2026] [security2:error] [pid 302018:tid 302115] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N04As9lPxxVAErz3tjQAAuV4"]
[Tue Jul 21 07:45:39.278387 2026] [security2:error] [pid 302018:tid 302202] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N04As9lPxxVAErz3tjQAAuV4"]
[Tue Jul 21 07:45:39.405518 2026] [security2:error] [pid 302018:tid 302186] [client 4.204.201.85:9300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/bless.php"] [unique_id "al9N04As9lPxxVAErz3tkQAAAKk"]
[Tue Jul 21 07:45:39.431617 2026] [security2:error] [pid 302018:tid 302215] [client 20.104.96.117:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "granicap.com.br"] [uri "/1.php"] [unique_id "al9N04As9lPxxVAErz3tkgAAAMY"]
[Tue Jul 21 07:45:39.431736 2026] [security2:error] [pid 302018:tid 302215] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/1.php"] [unique_id "al9N04As9lPxxVAErz3tkgAAAMY"]
[Tue Jul 21 07:45:39.508720 2026] [security2:error] [pid 302018:tid 302229] [client 165.227.32.93:59589] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "aronconsultoria.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9N04As9lPxxVAErz3tkwAAANQ"]
[Tue Jul 21 07:45:39.543275 2026] [security2:error] [pid 302018:tid 302221] [client 20.104.96.117:44151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/simple.php"] [unique_id "al9N04As9lPxxVAErz3tlgAAAMw"]
[Tue Jul 21 07:45:39.604375 2026] [security2:error] [pid 302018:tid 302182] [client 202.143.127.214:57853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N04As9lPxxVAErz3tlwAAAKU"]
[Tue Jul 21 07:45:39.605064 2026] [security2:error] [pid 302018:tid 302182] [client 202.143.127.214:57853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N04As9lPxxVAErz3tlwAAAKU"]
[Tue Jul 21 07:45:39.660852 2026] [security2:error] [pid 302018:tid 302128] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N04As9lPxxVAErz3tmAAA82s"]
[Tue Jul 21 07:45:39.661006 2026] [security2:error] [pid 302018:tid 302260] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N04As9lPxxVAErz3tmAAA82s"]
[Tue Jul 21 07:45:39.681607 2026] [security2:error] [pid 302018:tid 302257] [client 4.204.201.85:9310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/file25.php"] [unique_id "al9N04As9lPxxVAErz3tmgAAAPA"]
[Tue Jul 21 07:45:39.756274 2026] [security2:error] [pid 302018:tid 302263] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/ms.php"] [unique_id "al9N04As9lPxxVAErz3tmwAAAPY"]
[Tue Jul 21 07:45:39.797928 2026] [security2:error] [pid 302018:tid 302276] [client 103.29.114.44:52677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N04As9lPxxVAErz3tnAAAAQM"]
[Tue Jul 21 07:45:39.798038 2026] [security2:error] [pid 302018:tid 302276] [client 103.29.114.44:52677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N04As9lPxxVAErz3tnAAAAQM"]
[Tue Jul 21 07:45:39.926693 2026] [security2:error] [pid 302018:tid 302247] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9N04As9lPxxVAErz3tngAA5nA"]
[Tue Jul 21 07:45:39.935418 2026] [security2:error] [pid 296703:tid 296926] [client 37.140.223.158:22993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9N0yn25uliftkV1n4TZAAAAF0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:45:39.955282 2026] [security2:error] [pid 302018:tid 302196] [client 4.204.201.85:21983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/file6.php"] [unique_id "al9N04As9lPxxVAErz3trgAAALM"]
[Tue Jul 21 07:45:40.026504 2026] [security2:error] [pid 302018:tid 302227] [client 173.24.185.52:63833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9N1IAs9lPxxVAErz3trwAAANI"]
[Tue Jul 21 07:45:40.026728 2026] [security2:error] [pid 302018:tid 302227] [client 173.24.185.52:63833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9N1IAs9lPxxVAErz3trwAAANI"]
[Tue Jul 21 07:45:40.075102 2026] [security2:error] [pid 302018:tid 302271] [client 139.167.225.182:61297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N1IAs9lPxxVAErz3tuQAAAP4"]
[Tue Jul 21 07:45:40.075242 2026] [security2:error] [pid 302018:tid 302271] [client 139.167.225.182:61297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N1IAs9lPxxVAErz3tuQAAAP4"]
[Tue Jul 21 07:45:40.092594 2026] [security2:error] [pid 302018:tid 302151] [client 152.59.154.239:62372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N1IAs9lPxxVAErz3tugAAAIY"]
[Tue Jul 21 07:45:40.092748 2026] [security2:error] [pid 302018:tid 302151] [client 152.59.154.239:62372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N1IAs9lPxxVAErz3tugAAAIY"]
[Tue Jul 21 07:45:40.106074 2026] [autoindex:error] [pid 302018:tid 302258] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/soluc601/domains/granicap.com.br/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:40.232433 2026] [security2:error] [pid 296703:tid 296869] [client 4.204.201.85:21967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/a2.php"] [unique_id "al9N1Cn25uliftkV1n4TaQAAACQ"]
[Tue Jul 21 07:45:40.270218 2026] [security2:error] [pid 302018:tid 302172] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/memberfuns.php"] [unique_id "al9N1IAs9lPxxVAErz3tuwAAAJs"]
[Tue Jul 21 07:45:40.299633 2026] [security2:error] [pid 302018:tid 302249] [client 20.206.105.145:56604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wefile.php"] [unique_id "al9N1IAs9lPxxVAErz3tvAAAAOg"]
[Tue Jul 21 07:45:40.509206 2026] [security2:error] [pid 302018:tid 302183] [client 4.204.201.85:21968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/file15.php"] [unique_id "al9N1IAs9lPxxVAErz3twwAAAKY"]
[Tue Jul 21 07:45:40.539216 2026] [security2:error] [pid 302018:tid 302177] [client 20.104.96.117:44183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/init.php"] [unique_id "al9N1IAs9lPxxVAErz3txAAAAKA"]
[Tue Jul 21 07:45:40.590726 2026] [security2:error] [pid 302018:tid 302205] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/0.php"] [unique_id "al9N1IAs9lPxxVAErz3txwAAALw"]
[Tue Jul 21 07:45:40.793026 2026] [security2:error] [pid 302018:tid 302204] [client 4.204.201.85:3486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/f35.php"] [unique_id "al9N1IAs9lPxxVAErz3tzAAAALs"]
[Tue Jul 21 07:45:40.945074 2026] [security2:error] [pid 296703:tid 296850] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/BDKR28.php"] [unique_id "al9N1Cn25uliftkV1n4TcwAAABE"]
[Tue Jul 21 07:45:41.067576 2026] [security2:error] [pid 296703:tid 296902] [client 4.204.201.85:9356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-load.php"] [unique_id "al9N1Sn25uliftkV1n4TeAAAAEU"]
[Tue Jul 21 07:45:41.222824 2026] [security2:error] [pid 302018:tid 302243] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/green1.php"] [unique_id "al9N1YAs9lPxxVAErz3t2AAAAOI"]
[Tue Jul 21 07:45:41.338999 2026] [security2:error] [pid 302018:tid 302206] [client 20.104.96.117:44117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/fpwch.php"] [unique_id "al9N1YAs9lPxxVAErz3t2gAAAL0"]
[Tue Jul 21 07:45:41.343302 2026] [security2:error] [pid 302018:tid 302220] [client 182.8.255.181:17665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9N1YAs9lPxxVAErz3t3AAAAMs"]
[Tue Jul 21 07:45:41.343373 2026] [security2:error] [pid 302018:tid 302271] [client 4.204.201.85:22056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/xwpg.php"] [unique_id "al9N1YAs9lPxxVAErz3t2wAAAP4"]
[Tue Jul 21 07:45:41.343404 2026] [security2:error] [pid 302018:tid 302220] [client 182.8.255.181:17665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9N1YAs9lPxxVAErz3t3AAAAMs"]
[Tue Jul 21 07:45:41.441744 2026] [security2:error] [pid 296703:tid 296955] [client 20.206.105.145:56692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9N1Sn25uliftkV1n4TfwAAAHo"]
[Tue Jul 21 07:45:41.470747 2026] [security2:error] [pid 302018:tid 302223] [client 154.208.47.43:49233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9N1YAs9lPxxVAErz3t3wAAAM4"]
[Tue Jul 21 07:45:41.470873 2026] [security2:error] [pid 302018:tid 302223] [client 154.208.47.43:49233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9N1YAs9lPxxVAErz3t3wAAAM4"]
[Tue Jul 21 07:45:41.500450 2026] [security2:error] [pid 302018:tid 302244] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/nc4.php"] [unique_id "al9N1YAs9lPxxVAErz3t4AAAAOM"]
[Tue Jul 21 07:45:41.606097 2026] [security2:error] [pid 296703:tid 296709] [remote 45.3.53.205:37051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.53.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9N1Sn25uliftkV1n4TggAARwU"]
[Tue Jul 21 07:45:41.776187 2026] [security2:error] [pid 296703:tid 296936] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/a1.php"] [unique_id "al9N1Sn25uliftkV1n4TiAAAAGc"]
[Tue Jul 21 07:45:41.868264 2026] [security2:error] [pid 302018:tid 302259] [client 122.162.144.145:11483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9N1YAs9lPxxVAErz3t5gAAAPI"]
[Tue Jul 21 07:45:41.868463 2026] [security2:error] [pid 302018:tid 302259] [client 122.162.144.145:11483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9N1YAs9lPxxVAErz3t5gAAAPI"]
[Tue Jul 21 07:45:41.984294 2026] [security2:error] [pid 302018:tid 302224] [client 142.93.74.209:50784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9N1YAs9lPxxVAErz3t6AAAAM8"]
[Tue Jul 21 07:45:41.992586 2026] [security2:error] [pid 302018:tid 302192] [client 74.249.245.134:54394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/403.php"] [unique_id "al9N1YAs9lPxxVAErz3t6QAAAK8"]
[Tue Jul 21 07:45:42.028384 2026] [security2:error] [pid 302018:tid 302265] [client 136.144.33.53:63739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9N1oAs9lPxxVAErz3t6gAAAPg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:45:42.037121 2026] [security2:error] [pid 296703:tid 296877] [client 41.68.90.219:50507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N1in25uliftkV1n4TiwAAACw"]
[Tue Jul 21 07:45:42.038377 2026] [security2:error] [pid 296703:tid 296877] [client 41.68.90.219:50507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N1in25uliftkV1n4TiwAAACw"]
[Tue Jul 21 07:45:42.052228 2026] [security2:error] [pid 302018:tid 302193] [client 178.153.91.96:14193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9N1oAs9lPxxVAErz3t7AAAALA"]
[Tue Jul 21 07:45:42.052375 2026] [security2:error] [pid 302018:tid 302193] [client 178.153.91.96:14193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9N1oAs9lPxxVAErz3t7AAAALA"]
[Tue Jul 21 07:45:42.103268 2026] [security2:error] [pid 302018:tid 302221] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/eee.php"] [unique_id "al9N1oAs9lPxxVAErz3t7QAAAMw"]
[Tue Jul 21 07:45:42.122973 2026] [security2:error] [pid 302018:tid 302187] [client 103.166.103.129:17643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9N1oAs9lPxxVAErz3t7gAAAKo"]
[Tue Jul 21 07:45:42.124270 2026] [security2:error] [pid 302018:tid 302187] [client 103.166.103.129:17643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9N1oAs9lPxxVAErz3t7gAAAKo"]
[Tue Jul 21 07:45:42.152693 2026] [security2:error] [pid 296703:tid 296865] [client 103.86.117.203:63251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N1in25uliftkV1n4TjgAAACA"]
[Tue Jul 21 07:45:42.152805 2026] [security2:error] [pid 296703:tid 296865] [client 103.86.117.203:63251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N1in25uliftkV1n4TjgAAACA"]
[Tue Jul 21 07:45:42.231873 2026] [security2:error] [pid 302018:tid 302252] [client 142.93.74.209:52045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.74.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adsul.focsmart.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N1oAs9lPxxVAErz3t7wAAAOs"]
[Tue Jul 21 07:45:42.370453 2026] [security2:error] [pid 296703:tid 296837] [client 20.104.96.117:44222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/domvf.php"] [unique_id "al9N1in25uliftkV1n4TlwAAAAQ"]
[Tue Jul 21 07:45:42.399126 2026] [security2:error] [pid 302018:tid 302253] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wp-aothait.php"] [unique_id "al9N1oAs9lPxxVAErz3t8AAAAOw"]
[Tue Jul 21 07:45:42.700485 2026] [security2:error] [pid 296703:tid 296916] [client 142.93.74.209:52667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9N1in25uliftkV1n4TnwAAAFM"]
[Tue Jul 21 07:45:42.790193 2026] [security2:error] [pid 296703:tid 296960] [client 4.204.201.85:9300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/xstelth.php"] [unique_id "al9N1in25uliftkV1n4TowAAAH8"]
[Tue Jul 21 07:45:42.808922 2026] [security2:error] [pid 302018:tid 302247] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/config.json.php"] [unique_id "al9N1oAs9lPxxVAErz3t-AAAAOY"]
[Tue Jul 21 07:45:42.824651 2026] [security2:error] [pid 302018:tid 302137] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N1oAs9lPxxVAErz3t-QAAlHQ"]
[Tue Jul 21 07:45:42.824788 2026] [security2:error] [pid 302018:tid 302165] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N1oAs9lPxxVAErz3t-QAAlHQ"]
[Tue Jul 21 07:45:42.903995 2026] [security2:error] [pid 302018:tid 302144] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9N1oAs9lPxxVAErz3t-gAAnns"]
[Tue Jul 21 07:45:42.904184 2026] [security2:error] [pid 302018:tid 302175] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9N1oAs9lPxxVAErz3t-gAAnns"]
[Tue Jul 21 07:45:42.948082 2026] [security2:error] [pid 302018:tid 302166] [client 142.93.74.209:53810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9N1oAs9lPxxVAErz3t-wAAAJU"]
[Tue Jul 21 07:45:43.066021 2026] [security2:error] [pid 296703:tid 296883] [client 4.204.201.85:65472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9N1yn25uliftkV1n4TqQAAADI"]
[Tue Jul 21 07:45:43.068175 2026] [security2:error] [pid 296703:tid 296741] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9N1yn25uliftkV1n4TqgAADiU"]
[Tue Jul 21 07:45:43.068323 2026] [security2:error] [pid 296703:tid 296847] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9N1yn25uliftkV1n4TqgAADiU"]
[Tue Jul 21 07:45:43.103588 2026] [security2:error] [pid 302018:tid 302173] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9N14As9lPxxVAErz3t_gAAAJw"]
[Tue Jul 21 07:45:43.138483 2026] [security2:error] [pid 302018:tid 302260] [client 106.215.181.8:5436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N14As9lPxxVAErz3t_wAAAPM"]
[Tue Jul 21 07:45:43.138639 2026] [security2:error] [pid 302018:tid 302260] [client 106.215.181.8:5436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N14As9lPxxVAErz3t_wAAAPM"]
[Tue Jul 21 07:45:43.175721 2026] [security2:error] [pid 302018:tid 302176] [client 20.104.96.117:44253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp.php"] [unique_id "al9N14As9lPxxVAErz3uAAAAAJ8"]
[Tue Jul 21 07:45:43.190984 2026] [security2:error] [pid 302018:tid 302155] [client 142.93.74.209:54319] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9N14As9lPxxVAErz3uAgAAAIo"]
[Tue Jul 21 07:45:43.218986 2026] [security2:error] [pid 296703:tid 296751] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.elpcons.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9N1yn25uliftkV1n4TrAAAMy8"]
[Tue Jul 21 07:45:43.234222 2026] [security2:error] [pid 302018:tid 302138] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N14As9lPxxVAErz3uBAAA4nU"]
[Tue Jul 21 07:45:43.234334 2026] [security2:error] [pid 302018:tid 302243] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N14As9lPxxVAErz3uBAAA4nU"]
[Tue Jul 21 07:45:43.342600 2026] [security2:error] [pid 302018:tid 302274] [client 4.204.201.85:22079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/aaa.php"] [unique_id "al9N14As9lPxxVAErz3uCgAAAQE"]
[Tue Jul 21 07:45:43.351522 2026] [security2:error] [pid 296703:tid 296708] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.elpcons.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9N1yn25uliftkV1n4TsAAAXgQ"]
[Tue Jul 21 07:45:43.380845 2026] [security2:error] [pid 302018:tid 302153] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/k2.php"] [unique_id "al9N14As9lPxxVAErz3uCwAAAIg"]
[Tue Jul 21 07:45:43.422218 2026] [security2:error] [pid 302018:tid 302123] [remote 57.141.18.33:61940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9N14As9lPxxVAErz3uBgAA8WY"]
[Tue Jul 21 07:45:43.427051 2026] [security2:error] [pid 302018:tid 302195] [client 142.93.74.209:54656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9N14As9lPxxVAErz3uDAAAALI"]
[Tue Jul 21 07:45:43.479243 2026] [security2:error] [pid 296703:tid 296707] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.elpcons.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9N1yn25uliftkV1n4TsgAAJAM"]
[Tue Jul 21 07:45:43.531971 2026] [security2:error] [pid 302018:tid 302083] [remote 45.146.55.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mecanicanogueira.com.br"] [uri "/wp-login.php"] [unique_id "al9N14As9lPxxVAErz3uDgABAz4"]
[Tue Jul 21 07:45:43.620792 2026] [security2:error] [pid 302018:tid 302193] [client 4.204.201.85:9286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/gecko.php"] [unique_id "al9N14As9lPxxVAErz3uEAAAALA"]
[Tue Jul 21 07:45:43.659098 2026] [security2:error] [pid 302018:tid 302221] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9N14As9lPxxVAErz3uEgAAAMw"]
[Tue Jul 21 07:45:43.659500 2026] [security2:error] [pid 296703:tid 296840] [client 142.93.74.209:55151] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9N1yn25uliftkV1n4TtgAAAAc"]
[Tue Jul 21 07:45:43.676675 2026] [security2:error] [pid 296703:tid 296826] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.elpcons.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9N1yn25uliftkV1n4TtwAAKHo"]
[Tue Jul 21 07:45:43.687424 2026] [security2:error] [pid 302018:tid 302187] [client 194.99.104.35:36408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9N14As9lPxxVAErz3uFAAAAKo"]
[Tue Jul 21 07:45:43.687541 2026] [security2:error] [pid 302018:tid 302187] [client 194.99.104.35:36408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9N14As9lPxxVAErz3uFAAAAKo"]
[Tue Jul 21 07:45:43.784326 2026] [security2:error] [pid 302018:tid 302203] [client 185.213.175.37:5924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcoll.com.br"] [uri "/public/modstore.php"] [unique_id "al9N14As9lPxxVAErz3uGgAAALo"]
[Tue Jul 21 07:45:43.838553 2026] [security2:error] [pid 296703:tid 296824] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.elpcons.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9N1yn25uliftkV1n4TugAAFHg"]
[Tue Jul 21 07:45:43.894484 2026] [security2:error] [pid 302018:tid 302261] [client 4.204.201.85:2216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/sh3ll.php"] [unique_id "al9N14As9lPxxVAErz3uGwAAAPQ"]
[Tue Jul 21 07:45:43.895077 2026] [security2:error] [pid 296703:tid 296851] [client 142.93.74.209:55722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9N1yn25uliftkV1n4TvAAAABI"]
[Tue Jul 21 07:45:44.005304 2026] [security2:error] [pid 302018:tid 302183] [client 185.213.175.37:5956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arcoll.com.br"] [uri "/public/index.php"] [unique_id "al9N2IAs9lPxxVAErz3uIwAAAKY"]
[Tue Jul 21 07:45:44.020670 2026] [security2:error] [pid 296703:tid 296801] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.elpcons.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9N2Cn25uliftkV1n4TvgAATmE"]
[Tue Jul 21 07:45:44.037192 2026] [security2:error] [pid 302018:tid 302198] [client 20.220.225.223:34207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/ms.php"] [unique_id "al9N2IAs9lPxxVAErz3uJAAAALU"]
[Tue Jul 21 07:45:44.071116 2026] [security2:error] [pid 302018:tid 302220] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9N2IAs9lPxxVAErz3uJgAAAMs"]
[Tue Jul 21 07:45:44.128932 2026] [security2:error] [pid 302018:tid 302185] [client 142.93.74.209:56099] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9N2IAs9lPxxVAErz3uKAAAAKg"]
[Tue Jul 21 07:45:44.139128 2026] [security2:error] [pid 302018:tid 302249] [client 122.164.127.47:65351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9N2IAs9lPxxVAErz3uKQAAAOg"]
[Tue Jul 21 07:45:44.139249 2026] [security2:error] [pid 302018:tid 302249] [client 122.164.127.47:65351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9N2IAs9lPxxVAErz3uKQAAAOg"]
[Tue Jul 21 07:45:44.171742 2026] [security2:error] [pid 302018:tid 302173] [client 4.204.201.85:3467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/pbck.php"] [unique_id "al9N2IAs9lPxxVAErz3uKgAAAJw"]
[Tue Jul 21 07:45:44.177647 2026] [security2:error] [pid 296703:tid 296726] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.elpcons.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9N2Cn25uliftkV1n4TwgAAcxY"]
[Tue Jul 21 07:45:44.343845 2026] [security2:error] [pid 302018:tid 302153] [client 20.104.96.117:44111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/class.php"] [unique_id "al9N2IAs9lPxxVAErz3uMgAAAIg"]
[Tue Jul 21 07:45:44.363276 2026] [security2:error] [pid 302018:tid 302207] [client 142.93.74.209:56530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9N2IAs9lPxxVAErz3uMwAAAL4"]
[Tue Jul 21 07:45:44.369036 2026] [security2:error] [pid 296703:tid 296758] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.elpcons.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9N2Cn25uliftkV1n4TyAAAYzY"]
[Tue Jul 21 07:45:44.406533 2026] [security2:error] [pid 302018:tid 302228] [client 20.206.105.145:56584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-admin/css/colour.php"] [unique_id "al9N2IAs9lPxxVAErz3uNAAAANM"]
[Tue Jul 21 07:45:44.422467 2026] [security2:error] [pid 302018:tid 302253] [client 103.174.34.15:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N2IAs9lPxxVAErz3uNQAAAOw"]
[Tue Jul 21 07:45:44.422559 2026] [security2:error] [pid 302018:tid 302253] [client 103.174.34.15:65190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N2IAs9lPxxVAErz3uNQAAAOw"]
[Tue Jul 21 07:45:44.448030 2026] [security2:error] [pid 302018:tid 302202] [client 4.204.201.85:21994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/xiugai.php"] [unique_id "al9N2IAs9lPxxVAErz3uNgAAALk"]
[Tue Jul 21 07:45:44.498976 2026] [security2:error] [pid 302018:tid 302145] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9N2IAs9lPxxVAErz3uNwABA3w"]
[Tue Jul 21 07:45:44.499148 2026] [security2:error] [pid 302018:tid 302276] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9N2IAs9lPxxVAErz3uNwABA3w"]
[Tue Jul 21 07:45:44.520681 2026] [security2:error] [pid 296703:tid 296859] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9N2Cn25uliftkV1n4TzAAAABo"]
[Tue Jul 21 07:45:44.565984 2026] [security2:error] [pid 296703:tid 296764] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.elpcons.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9N2Cn25uliftkV1n4TzQAACDw"]
[Tue Jul 21 07:45:44.597445 2026] [security2:error] [pid 302018:tid 302177] [client 142.93.74.209:56952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9N2IAs9lPxxVAErz3uOwAAAKA"]
[Tue Jul 21 07:45:44.723415 2026] [security2:error] [pid 302018:tid 302174] [client 4.204.201.85:9305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/e.php"] [unique_id "al9N2IAs9lPxxVAErz3uPQAAAJ0"]
[Tue Jul 21 07:45:44.759699 2026] [security2:error] [pid 296703:tid 296734] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.elpcons.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9N2Cn25uliftkV1n4T0gAAfB4"]
[Tue Jul 21 07:45:44.812885 2026] [security2:error] [pid 302018:tid 302270] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/for.php"] [unique_id "al9N2IAs9lPxxVAErz3uPgAAAP0"]
[Tue Jul 21 07:45:44.833342 2026] [security2:error] [pid 302018:tid 302263] [client 142.93.74.209:57378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9N2IAs9lPxxVAErz3uPwAAAPY"]
[Tue Jul 21 07:45:44.917236 2026] [security2:error] [pid 302018:tid 302229] [client 34.182.235.64:62874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gradiente.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9N2IAs9lPxxVAErz3uQwAAANQ"]
[Tue Jul 21 07:45:44.976613 2026] [security2:error] [pid 296703:tid 296747] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.elpcons.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9N2Cn25uliftkV1n4T1gAAGSs"]
[Tue Jul 21 07:45:44.999306 2026] [security2:error] [pid 302018:tid 302254] [client 4.204.201.85:9385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/for.php"] [unique_id "al9N2IAs9lPxxVAErz3uRQAAAO0"]
[Tue Jul 21 07:45:45.036022 2026] [security2:error] [pid 302018:tid 302195] [client 117.217.38.194:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N2YAs9lPxxVAErz3uRgAAALI"]
[Tue Jul 21 07:45:45.036123 2026] [security2:error] [pid 302018:tid 302195] [client 117.217.38.194:58922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N2YAs9lPxxVAErz3uRgAAALI"]
[Tue Jul 21 07:45:45.067123 2026] [security2:error] [pid 296703:tid 296868] [client 142.93.74.209:57848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9N2Sn25uliftkV1n4T2AAAACM"]
[Tue Jul 21 07:45:45.104257 2026] [security2:error] [pid 302018:tid 302180] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/raw.php"] [unique_id "al9N2YAs9lPxxVAErz3uRwAAAKM"]
[Tue Jul 21 07:45:45.110136 2026] [security2:error] [pid 296703:tid 296763] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.elpcons.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9N2Sn25uliftkV1n4T2QAAVzs"]
[Tue Jul 21 07:45:45.127933 2026] [security2:error] [pid 302018:tid 302277] [client 20.104.96.117:44199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/echkm.php"] [unique_id "al9N2YAs9lPxxVAErz3uSAAAAQQ"]
[Tue Jul 21 07:45:45.137253 2026] [security2:error] [pid 302018:tid 302258] [client 223.236.153.128:5537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9N2YAs9lPxxVAErz3uSQAAAPE"]
[Tue Jul 21 07:45:45.137355 2026] [security2:error] [pid 302018:tid 302258] [client 223.236.153.128:5537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9N2YAs9lPxxVAErz3uSQAAAPE"]
[Tue Jul 21 07:45:45.234461 2026] [security2:error] [pid 296703:tid 296945] [client 20.206.105.145:56679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/like.php"] [unique_id "al9N2Sn25uliftkV1n4T4AAAAHA"]
[Tue Jul 21 07:45:45.276872 2026] [security2:error] [pid 302018:tid 302240] [client 4.204.201.85:9305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/ssh3ll.php"] [unique_id "al9N2YAs9lPxxVAErz3uWAAAAN8"]
[Tue Jul 21 07:45:45.308049 2026] [security2:error] [pid 302018:tid 302172] [client 142.93.74.209:58259] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9N2YAs9lPxxVAErz3uWQAAAJs"]
[Tue Jul 21 07:45:45.358617 2026] [security2:error] [pid 296703:tid 296946] [client 194.99.104.35:36420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9N2Sn25uliftkV1n4T4gAAAHE"]
[Tue Jul 21 07:45:45.358706 2026] [security2:error] [pid 296703:tid 296946] [client 194.99.104.35:36420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9N2Sn25uliftkV1n4T4gAAAHE"]
[Tue Jul 21 07:45:45.551683 2026] [security2:error] [pid 302018:tid 302186] [client 142.93.74.209:58815] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9N2YAs9lPxxVAErz3uXgAAAKk"]
[Tue Jul 21 07:45:45.552560 2026] [security2:error] [pid 296703:tid 296938] [client 4.204.201.85:9396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/adminner.php"] [unique_id "al9N2Sn25uliftkV1n4T5gAAAGk"]
[Tue Jul 21 07:45:45.559810 2026] [security2:error] [pid 296703:tid 296872] [client 109.60.28.94:10373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N2Sn25uliftkV1n4T5AAAACc"]
[Tue Jul 21 07:45:45.589304 2026] [security2:error] [pid 302018:tid 302150] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9N2YAs9lPxxVAErz3uYQAAAIU"]
[Tue Jul 21 07:45:45.724077 2026] [security2:error] [pid 302018:tid 302152] [client 20.104.96.117:46707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9N2YAs9lPxxVAErz3uZAAAAIc"]
[Tue Jul 21 07:45:45.736980 2026] [security2:error] [pid 296703:tid 296838] [client 20.104.96.117:44123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/lib.php"] [unique_id "al9N2Sn25uliftkV1n4T6gAAAAU"]
[Tue Jul 21 07:45:45.755862 2026] [security2:error] [pid 296703:tid 296867] [client 20.197.192.193:65167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9N2Sn25uliftkV1n4T7AAAACI"]
[Tue Jul 21 07:45:45.785270 2026] [security2:error] [pid 296703:tid 296947] [client 142.93.74.209:59420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9N2Sn25uliftkV1n4T7QAAAHI"]
[Tue Jul 21 07:45:45.831147 2026] [security2:error] [pid 302018:tid 302178] [client 4.204.201.85:9383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/82.php"] [unique_id "al9N2YAs9lPxxVAErz3uZgAAAKE"]
[Tue Jul 21 07:45:45.919558 2026] [security2:error] [pid 296703:tid 296748] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9N2Sn25uliftkV1n4T8AAAbyw"]
[Tue Jul 21 07:45:45.975093 2026] [security2:error] [pid 302018:tid 302273] [client 122.186.204.214:49607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N2YAs9lPxxVAErz3uaQAAAQA"]
[Tue Jul 21 07:45:45.975252 2026] [security2:error] [pid 302018:tid 302273] [client 122.186.204.214:49607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N2YAs9lPxxVAErz3uaQAAAQA"]
[Tue Jul 21 07:45:45.997422 2026] [security2:error] [pid 302018:tid 302153] [client 117.247.80.59:25879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N2YAs9lPxxVAErz3uagAAAIg"]
[Tue Jul 21 07:45:45.997550 2026] [security2:error] [pid 302018:tid 302153] [client 117.247.80.59:25879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N2YAs9lPxxVAErz3uagAAAIg"]
[Tue Jul 21 07:45:46.054281 2026] [security2:error] [pid 302018:tid 302206] [client 142.93.74.209:60240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9N2oAs9lPxxVAErz3uawAAAL0"]
[Tue Jul 21 07:45:46.107381 2026] [security2:error] [pid 302018:tid 302220] [client 4.204.201.85:22012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/kir.php"] [unique_id "al9N2oAs9lPxxVAErz3ubAAAAMs"]
[Tue Jul 21 07:45:46.226676 2026] [security2:error] [pid 302018:tid 302249] [client 74.249.245.134:62880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viaciaxx.shop-officialstore.com"] [uri "/api.php"] [unique_id "al9N2oAs9lPxxVAErz3ubgAAAOg"]
[Tue Jul 21 07:45:46.245588 2026] [security2:error] [pid 302018:tid 302166] [client 34.182.235.64:51962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gradiente.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9N2oAs9lPxxVAErz3ubwAAAJU"]
[Tue Jul 21 07:45:46.260569 2026] [security2:error] [pid 296703:tid 296863] [client 20.104.96.117:44256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/login.php"] [unique_id "al9N2in25uliftkV1n4T9QAAAB4"]
[Tue Jul 21 07:45:46.284331 2026] [security2:error] [pid 302018:tid 302151] [client 142.93.74.209:60925] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adsul.focsmart.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9N2oAs9lPxxVAErz3ucgAAAIY"]
[Tue Jul 21 07:45:46.363448 2026] [security2:error] [pid 296703:tid 296814] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9N2in25uliftkV1n4T-AAAJG4"]
[Tue Jul 21 07:45:46.371828 2026] [security2:error] [pid 302018:tid 302258] [client 51.68.107.144:29959] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.betoperroygrill.com.br"] [uri "/robots.txt"] [unique_id "al9N2oAs9lPxxVAErz3ucwAAAPE"]
[Tue Jul 21 07:45:46.371907 2026] [security2:error] [pid 302018:tid 302258] [client 51.68.107.144:29959] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.betoperroygrill.com.br"] [uri "/robots.txt"] [unique_id "al9N2oAs9lPxxVAErz3ucwAAAPE"]
[Tue Jul 21 07:45:46.404181 2026] [security2:error] [pid 296703:tid 296943] [client 20.206.105.145:56647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/.well-known/about.php"] [unique_id "al9N2in25uliftkV1n4T-gAAAG4"]
[Tue Jul 21 07:45:46.421093 2026] [security2:error] [pid 296703:tid 296844] [client 4.204.201.85:9307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/up4.php"] [unique_id "al9N2in25uliftkV1n4T-wAAAAs"]
[Tue Jul 21 07:45:46.516886 2026] [security2:error] [pid 296703:tid 296715] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/wander.php"] [unique_id "al9N2in25uliftkV1n4T_QAAdQs"]
[Tue Jul 21 07:45:46.520529 2026] [security2:error] [pid 296703:tid 296916] [client 117.251.86.144:44990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9N2in25uliftkV1n4T_gAAAFM"]
[Tue Jul 21 07:45:46.520601 2026] [security2:error] [pid 296703:tid 296916] [client 117.251.86.144:44990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9N2in25uliftkV1n4T_gAAAFM"]
[Tue Jul 21 07:45:46.670926 2026] [security2:error] [pid 296703:tid 296725] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/jga.php"] [unique_id "al9N2in25uliftkV1n4UAAAAQxU"]
[Tue Jul 21 07:45:46.699431 2026] [security2:error] [pid 296703:tid 296909] [client 4.204.201.85:22026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/xhar.php"] [unique_id "al9N2in25uliftkV1n4UAgAAAEw"]
[Tue Jul 21 07:45:46.842808 2026] [security2:error] [pid 296703:tid 296706] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/x.php"] [unique_id "al9N2in25uliftkV1n4UBwAAPwI"]
[Tue Jul 21 07:45:46.878776 2026] [security2:error] [pid 296703:tid 296833] [client 20.104.96.117:44170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/a2.php"] [unique_id "al9N2in25uliftkV1n4UCAAAAAA"]
[Tue Jul 21 07:45:46.880652 2026] [security2:error] [pid 302018:tid 302246] [client 143.244.57.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N2YAs9lPxxVAErz3uZwAAAOU"]
[Tue Jul 21 07:45:46.884194 2026] [security2:error] [pid 296703:tid 296904] [client 193.36.225.72:55511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9N2in25uliftkV1n4UCQAAAEc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:45:46.917587 2026] [security2:error] [pid 302018:tid 302198] [client 154.192.233.199:59994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N2oAs9lPxxVAErz3ueAAAALU"]
[Tue Jul 21 07:45:46.917719 2026] [security2:error] [pid 302018:tid 302198] [client 154.192.233.199:59994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N2oAs9lPxxVAErz3ueAAAALU"]
[Tue Jul 21 07:45:46.921723 2026] [security2:error] [pid 296703:tid 296843] [client 34.182.235.64:52271] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gradiente.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9N2in25uliftkV1n4UCwAAAAo"]
[Tue Jul 21 07:45:46.975980 2026] [security2:error] [pid 296703:tid 296893] [client 4.204.201.85:9330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/file1221.php"] [unique_id "al9N2in25uliftkV1n4UDQAAADw"]
[Tue Jul 21 07:45:47.027054 2026] [security2:error] [pid 296703:tid 296756] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9N2yn25uliftkV1n4UEAAACDQ"]
[Tue Jul 21 07:45:47.177168 2026] [security2:error] [pid 296703:tid 296728] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/ee.php"] [unique_id "al9N2yn25uliftkV1n4UEwAAXxg"]
[Tue Jul 21 07:45:47.252575 2026] [security2:error] [pid 302018:tid 302191] [client 4.204.201.85:9400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/inx.php"] [unique_id "al9N24As9lPxxVAErz3ugAAAAK4"]
[Tue Jul 21 07:45:47.253301 2026] [security2:error] [pid 302018:tid 302263] [client 20.197.192.193:65206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9N24As9lPxxVAErz3ufwAAAPY"]
[Tue Jul 21 07:45:47.319316 2026] [security2:error] [pid 302018:tid 302257] [client 143.244.57.118:44308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9N24As9lPxxVAErz3ugQAAAPA"]
[Tue Jul 21 07:45:47.332884 2026] [security2:error] [pid 296703:tid 296907] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9N2yn25uliftkV1n4UFwAAAEo"]
[Tue Jul 21 07:45:47.349366 2026] [security2:error] [pid 296703:tid 296711] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/blue.php"] [unique_id "al9N2yn25uliftkV1n4UGQAAHwc"]
[Tue Jul 21 07:45:47.411157 2026] [security2:error] [pid 302018:tid 302254] [client 20.206.105.145:56689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9N24As9lPxxVAErz3uhAAAAO0"]
[Tue Jul 21 07:45:47.485203 2026] [security2:error] [pid 296703:tid 296868] [client 20.104.96.117:44112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/d61.php"] [unique_id "al9N2yn25uliftkV1n4UHAAAACM"]
[Tue Jul 21 07:45:47.501630 2026] [security2:error] [pid 296703:tid 296803] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/wp-signup.php"] [unique_id "al9N2yn25uliftkV1n4UHQAAV2M"]
[Tue Jul 21 07:45:47.530438 2026] [security2:error] [pid 302018:tid 302222] [client 34.182.235.64:49477] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gradiente.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9N24As9lPxxVAErz3uhgAAAM0"]
[Tue Jul 21 07:45:47.534380 2026] [security2:error] [pid 296703:tid 296925] [client 4.204.201.85:9287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/qqqa.php"] [unique_id "al9N2yn25uliftkV1n4UHgAAAFw"]
[Tue Jul 21 07:45:47.618681 2026] [security2:error] [pid 302018:tid 302210] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9N24As9lPxxVAErz3uigAAAME"]
[Tue Jul 21 07:45:47.651536 2026] [security2:error] [pid 302018:tid 302183] [client 184.75.223.211:43338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9N24As9lPxxVAErz3uiwAAAKY"]
[Tue Jul 21 07:45:47.651649 2026] [security2:error] [pid 302018:tid 302183] [client 184.75.223.211:43338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9N24As9lPxxVAErz3uiwAAAKY"]
[Tue Jul 21 07:45:47.681594 2026] [security2:error] [pid 296703:tid 296743] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/csa.php"] [unique_id "al9N2yn25uliftkV1n4UJQAAaic"]
[Tue Jul 21 07:45:47.816449 2026] [security2:error] [pid 302018:tid 302155] [client 4.204.201.85:21990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/ffffile.php"] [unique_id "al9N24As9lPxxVAErz3ulQAAAIo"]
[Tue Jul 21 07:45:47.838004 2026] [security2:error] [pid 296703:tid 296754] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/min.php"] [unique_id "al9N2yn25uliftkV1n4ULAAAcjI"]
[Tue Jul 21 07:45:47.898899 2026] [security2:error] [pid 302018:tid 302260] [client 20.197.192.193:65195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/wander.php"] [unique_id "al9N24As9lPxxVAErz3ulwAAAPM"]
[Tue Jul 21 07:45:47.905137 2026] [security2:error] [pid 302018:tid 302272] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9N24As9lPxxVAErz3umAAAAP8"]
[Tue Jul 21 07:45:48.011856 2026] [security2:error] [pid 296703:tid 296724] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/echkm.php"] [unique_id "al9N3Cn25uliftkV1n4UMAAADhQ"]
[Tue Jul 21 07:45:48.092413 2026] [security2:error] [pid 302018:tid 302161] [client 4.204.201.85:9343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/wp-firewall.php"] [unique_id "al9N3IAs9lPxxVAErz3umgAAAJA"]
[Tue Jul 21 07:45:48.182514 2026] [security2:error] [pid 296703:tid 296793] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/mac.php"] [unique_id "al9N3Cn25uliftkV1n4UNQAAXVk"]
[Tue Jul 21 07:45:48.193929 2026] [security2:error] [pid 296703:tid 296861] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9N3Cn25uliftkV1n4UNgAAABw"]
[Tue Jul 21 07:45:48.267564 2026] [security2:error] [pid 302018:tid 302233] [client 20.104.96.117:44114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/info.php"] [unique_id "al9N3IAs9lPxxVAErz3umwAAANg"]
[Tue Jul 21 07:45:48.295337 2026] [security2:error] [pid 296703:tid 296794] [remote 57.141.18.94:51196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-sitemap-users-1.xml"] [unique_id "al9N3Cn25uliftkV1n4UOQAAT1o"]
[Tue Jul 21 07:45:48.317427 2026] [security2:error] [pid 296703:tid 296929] [client 34.182.235.64:63819] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gradiente.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9N3Cn25uliftkV1n4UOgAAAGA"]
[Tue Jul 21 07:45:48.338199 2026] [security2:error] [pid 296703:tid 296723] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/samll.php"] [unique_id "al9N3Cn25uliftkV1n4UPQAAAxM"]
[Tue Jul 21 07:45:48.372480 2026] [security2:error] [pid 296703:tid 296844] [client 4.204.201.85:22070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ppsiqueira.com.br"] [uri "/reviall.php"] [unique_id "al9N3Cn25uliftkV1n4UQAAAAAs"]
[Tue Jul 21 07:45:48.486240 2026] [security2:error] [pid 302018:tid 302198] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9N3IAs9lPxxVAErz3unAAAALU"]
[Tue Jul 21 07:45:48.516737 2026] [security2:error] [pid 296703:tid 296823] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/abcd.php"] [unique_id "al9N3Cn25uliftkV1n4UQQAAFHc"]
[Tue Jul 21 07:45:48.565931 2026] [security2:error] [pid 302018:tid 302274] [client 176.88.23.26:47870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.23.88.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilly.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N24As9lPxxVAErz3ugwAAAQE"]
[Tue Jul 21 07:45:48.566045 2026] [security2:error] [pid 302018:tid 302274] [client 176.88.23.26:47870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hilly.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N24As9lPxxVAErz3ugwAAAQE"]
[Tue Jul 21 07:45:48.652374 2026] [security2:error] [pid 296703:tid 296919] [client 34.182.235.64:60338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gradiente.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9N3Cn25uliftkV1n4URgAAAFY"]
[Tue Jul 21 07:45:48.666924 2026] [security2:error] [pid 296703:tid 296710] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/xyn.php"] [unique_id "al9N3Cn25uliftkV1n4URwAAcwY"]
[Tue Jul 21 07:45:48.776420 2026] [security2:error] [pid 296703:tid 296932] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9N3Cn25uliftkV1n4UTAAAAGM"]
[Tue Jul 21 07:45:48.805733 2026] [security2:error] [pid 302018:tid 302193] [client 184.75.223.211:35184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9N3IAs9lPxxVAErz3ungAAALA"]
[Tue Jul 21 07:45:48.805823 2026] [security2:error] [pid 302018:tid 302193] [client 184.75.223.211:35184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9N3IAs9lPxxVAErz3ungAAALA"]
[Tue Jul 21 07:45:48.832623 2026] [security2:error] [pid 296703:tid 296716] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/byp8.php"] [unique_id "al9N3Cn25uliftkV1n4UTQAADQw"]
[Tue Jul 21 07:45:48.995865 2026] [security2:error] [pid 296703:tid 296773] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/user.php"] [unique_id "al9N3Cn25uliftkV1n4UUQAACEU"]
[Tue Jul 21 07:45:49.003540 2026] [security2:error] [pid 296703:tid 296956] [client 20.104.96.117:44914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/11.php"] [unique_id "al9N3Sn25uliftkV1n4UUgAAAHs"]
[Tue Jul 21 07:45:49.037689 2026] [security2:error] [pid 302018:tid 302160] [client 20.197.192.193:65164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/jga.php"] [unique_id "al9N3YAs9lPxxVAErz3uogAAAI8"]
[Tue Jul 21 07:45:49.065704 2026] [security2:error] [pid 302018:tid 302267] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9N3YAs9lPxxVAErz3upAAAAPo"]
[Tue Jul 21 07:45:49.079128 2026] [security2:error] [pid 302018:tid 302162] [client 20.197.192.193:43802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/x.php"] [unique_id "al9N3YAs9lPxxVAErz3upQAAAJE"]
[Tue Jul 21 07:45:49.150453 2026] [security2:error] [pid 296703:tid 296812] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/ops.php"] [unique_id "al9N3Sn25uliftkV1n4UVQAAX2w"]
[Tue Jul 21 07:45:49.188153 2026] [security2:error] [pid 302018:tid 302247] [client 194.99.104.35:48856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9N3YAs9lPxxVAErz3uqAAAAOY"]
[Tue Jul 21 07:45:49.188218 2026] [security2:error] [pid 302018:tid 302247] [client 194.99.104.35:48856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9N3YAs9lPxxVAErz3uqAAAAOY"]
[Tue Jul 21 07:45:49.245657 2026] [security2:error] [pid 302018:tid 302194] [client 20.206.105.145:56693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/pucci.php"] [unique_id "al9N3YAs9lPxxVAErz3uqwAAALE"]
[Tue Jul 21 07:45:49.319772 2026] [security2:error] [pid 302018:tid 302206] [client 20.197.192.193:65155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9N3YAs9lPxxVAErz3urAAAAL0"]
[Tue Jul 21 07:45:49.330043 2026] [security2:error] [pid 302018:tid 302246] [client 59.96.220.140:50682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9N3YAs9lPxxVAErz3urQAAAOU"]
[Tue Jul 21 07:45:49.330140 2026] [security2:error] [pid 302018:tid 302246] [client 59.96.220.140:50682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9N3YAs9lPxxVAErz3urQAAAOU"]
[Tue Jul 21 07:45:49.356792 2026] [security2:error] [pid 302018:tid 302166] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9N3YAs9lPxxVAErz3urgAAAJU"]
[Tue Jul 21 07:45:49.435943 2026] [security2:error] [pid 302018:tid 302178] [client 20.197.192.193:43782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/ee.php"] [unique_id "al9N3YAs9lPxxVAErz3usAAAAKE"]
[Tue Jul 21 07:45:49.498983 2026] [security2:error] [pid 296703:tid 296777] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/term.php"] [unique_id "al9N3Sn25uliftkV1n4UWQAAaEk"]
[Tue Jul 21 07:45:49.557513 2026] [security2:error] [pid 296703:tid 296864] [client 34.182.235.64:53005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gradiente.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9N3Sn25uliftkV1n4UWgAAAB8"]
[Tue Jul 21 07:45:49.592393 2026] [security2:error] [pid 296703:tid 296905] [client 20.104.96.117:44257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/v2.php"] [unique_id "al9N3Sn25uliftkV1n4UWwAAAEg"]
[Tue Jul 21 07:45:49.629489 2026] [security2:error] [pid 296703:tid 296866] [client 20.197.192.193:43785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/blue.php"] [unique_id "al9N3Sn25uliftkV1n4UXQAAACE"]
[Tue Jul 21 07:45:49.652356 2026] [security2:error] [pid 296703:tid 296868] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9N3Sn25uliftkV1n4UXwAAACM"]
[Tue Jul 21 07:45:49.657487 2026] [security2:error] [pid 296703:tid 296737] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/ah25.php"] [unique_id "al9N3Sn25uliftkV1n4UYAAAVyE"]
[Tue Jul 21 07:45:49.747739 2026] [security2:error] [pid 302018:tid 302220] [client 143.244.57.118:44312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "milhasexpresso.com"] [uri "/xmlrpc.php"] [unique_id "al9N24As9lPxxVAErz3ukAAAAMs"]
[Tue Jul 21 07:45:49.818022 2026] [security2:error] [pid 296703:tid 296755] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/8.php"] [unique_id "al9N3Sn25uliftkV1n4UZAAAdDM"]
[Tue Jul 21 07:45:49.877770 2026] [security2:error] [pid 302018:tid 302228] [client 20.197.192.193:65175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/wp-signup.php"] [unique_id "al9N3YAs9lPxxVAErz3utgAAANM"]
[Tue Jul 21 07:45:49.907387 2026] [security2:error] [pid 302018:tid 302202] [client 20.197.192.193:43792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/csa.php"] [unique_id "al9N3YAs9lPxxVAErz3utwAAALk"]
[Tue Jul 21 07:45:49.942765 2026] [security2:error] [pid 302018:tid 302276] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9N3YAs9lPxxVAErz3uuQAAAQM"]
[Tue Jul 21 07:45:49.966774 2026] [security2:error] [pid 296703:tid 296806] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/red.php"] [unique_id "al9N3Sn25uliftkV1n4UZwAAFmY"]
[Tue Jul 21 07:45:49.998147 2026] [security2:error] [pid 296703:tid 296867] [client 34.182.235.64:52055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gradiente.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9N3Sn25uliftkV1n4UaAAAACI"]
[Tue Jul 21 07:45:50.126869 2026] [security2:error] [pid 296703:tid 296796] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/fffm.php"] [unique_id "al9N3in25uliftkV1n4UagAAAlw"]
[Tue Jul 21 07:45:50.148529 2026] [security2:error] [pid 302018:tid 302182] [client 20.197.192.193:43805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/min.php"] [unique_id "al9N3oAs9lPxxVAErz3uvgAAAKU"]
[Tue Jul 21 07:45:50.169741 2026] [security2:error] [pid 296703:tid 296808] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N3in25uliftkV1n4UbAAAIGg"]
[Tue Jul 21 07:45:50.169992 2026] [security2:error] [pid 296703:tid 296865] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N3in25uliftkV1n4UbAAAIGg"]
[Tue Jul 21 07:45:50.232402 2026] [security2:error] [pid 302018:tid 302204] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9N3oAs9lPxxVAErz3uvwAAALs"]
[Tue Jul 21 07:45:50.250048 2026] [security2:error] [pid 296703:tid 296791] [remote 57.141.18.40:53466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9N3in25uliftkV1n4UcAAAM1c"]
[Tue Jul 21 07:45:50.278969 2026] [security2:error] [pid 302018:tid 302030] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N3oAs9lPxxVAErz3uwQAAkQk"]
[Tue Jul 21 07:45:50.279094 2026] [security2:error] [pid 302018:tid 302162] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N3oAs9lPxxVAErz3uwQAAkQk"]
[Tue Jul 21 07:45:50.303506 2026] [security2:error] [pid 296703:tid 296712] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/ftde.php"] [unique_id "al9N3in25uliftkV1n4UcQAAZgg"]
[Tue Jul 21 07:45:50.315163 2026] [security2:error] [pid 302018:tid 302152] [client 20.104.96.117:44164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/panel.php"] [unique_id "al9N3oAs9lPxxVAErz3uwgAAAIc"]
[Tue Jul 21 07:45:50.385082 2026] [security2:error] [pid 302018:tid 302195] [client 20.206.105.145:56668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-temp.php"] [unique_id "al9N3oAs9lPxxVAErz3uxQAAALI"]
[Tue Jul 21 07:45:50.441508 2026] [security2:error] [pid 302018:tid 302221] [client 136.144.33.24:42049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9N3oAs9lPxxVAErz3uwAAAAMw"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:45:50.463085 2026] [security2:error] [pid 296703:tid 296767] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/yup.php"] [unique_id "al9N3in25uliftkV1n4UdAAATz8"]
[Tue Jul 21 07:45:50.488685 2026] [security2:error] [pid 296703:tid 296942] [client 103.29.114.44:32620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N3in25uliftkV1n4UdwAAAG0"]
[Tue Jul 21 07:45:50.488755 2026] [security2:error] [pid 296703:tid 296942] [client 103.29.114.44:32620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N3in25uliftkV1n4UdwAAAG0"]
[Tue Jul 21 07:45:50.509161 2026] [security2:error] [pid 302018:tid 302203] [client 136.144.33.29:48449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9N3oAs9lPxxVAErz3uyAAAALo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:45:50.520923 2026] [security2:error] [pid 302018:tid 302153] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9N3oAs9lPxxVAErz3uyQAAAIg"]
[Tue Jul 21 07:45:50.527427 2026] [security2:error] [pid 302018:tid 302206] [client 34.182.235.64:57270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gradiente.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9N3oAs9lPxxVAErz3uygAAAL0"]
[Tue Jul 21 07:45:50.635763 2026] [security2:error] [pid 296703:tid 296816] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/jj.php"] [unique_id "al9N3in25uliftkV1n4UegAAbnA"]
[Tue Jul 21 07:45:50.648313 2026] [security2:error] [pid 302018:tid 302229] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9N3oAs9lPxxVAErz3uywAA1H8"]
[Tue Jul 21 07:45:50.669231 2026] [security2:error] [pid 296703:tid 296959] [client 202.143.127.214:58277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N3in25uliftkV1n4UfAAAAH4"]
[Tue Jul 21 07:45:50.669335 2026] [security2:error] [pid 296703:tid 296959] [client 202.143.127.214:58277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N3in25uliftkV1n4UfAAAAH4"]
[Tue Jul 21 07:45:50.672616 2026] [security2:error] [pid 296703:tid 296886] [client 173.24.185.52:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9N3in25uliftkV1n4UfQAAADU"]
[Tue Jul 21 07:45:50.672692 2026] [security2:error] [pid 296703:tid 296886] [client 173.24.185.52:64329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9N3in25uliftkV1n4UfQAAADU"]
[Tue Jul 21 07:45:50.772119 2026] [security2:error] [pid 302018:tid 302259] [client 139.167.225.182:61952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N3oAs9lPxxVAErz3uzAAAAPI"]
[Tue Jul 21 07:45:50.772276 2026] [security2:error] [pid 302018:tid 302259] [client 139.167.225.182:61952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N3oAs9lPxxVAErz3uzAAAAPI"]
[Tue Jul 21 07:45:50.804753 2026] [security2:error] [pid 296703:tid 296741] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/dragonshell.php"] [unique_id "al9N3in25uliftkV1n4UgQAAUSU"]
[Tue Jul 21 07:45:50.810474 2026] [security2:error] [pid 302018:tid 302151] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9N3oAs9lPxxVAErz3uzgAAAIY"]
[Tue Jul 21 07:45:50.844516 2026] [security2:error] [pid 302018:tid 302264] [client 152.59.154.239:62948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N3oAs9lPxxVAErz3uzwAAAPc"]
[Tue Jul 21 07:45:50.844633 2026] [security2:error] [pid 302018:tid 302264] [client 152.59.154.239:62948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N3oAs9lPxxVAErz3uzwAAAPc"]
[Tue Jul 21 07:45:50.976096 2026] [security2:error] [pid 296703:tid 296751] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/wp-mt.php"] [unique_id "al9N3in25uliftkV1n4UhAAAdS8"]
[Tue Jul 21 07:45:50.985718 2026] [security2:error] [pid 302018:tid 302220] [client 20.197.192.193:43810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/echkm.php"] [unique_id "al9N3oAs9lPxxVAErz3u1QAAAMs"]
[Tue Jul 21 07:45:51.077122 2026] [security2:error] [pid 302018:tid 302209] [client 122.162.144.145:27286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9N34As9lPxxVAErz3u2AAAAMA"]
[Tue Jul 21 07:45:51.077234 2026] [security2:error] [pid 302018:tid 302209] [client 122.162.144.145:27286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9N34As9lPxxVAErz3u2AAAAMA"]
[Tue Jul 21 07:45:51.101057 2026] [security2:error] [pid 302018:tid 302241] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9N34As9lPxxVAErz3u2QAAAOA"]
[Tue Jul 21 07:45:51.118321 2026] [security2:error] [pid 296703:tid 296909] [client 34.182.235.64:51021] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gradiente.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9N3yn25uliftkV1n4UiAAAAEw"]
[Tue Jul 21 07:45:51.151486 2026] [security2:error] [pid 296703:tid 296708] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/ww.php"] [unique_id "al9N3yn25uliftkV1n4UiQAANgQ"]
[Tue Jul 21 07:45:51.174633 2026] [security2:error] [pid 296703:tid 296927] [client 122.179.91.63:19446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9N3yn25uliftkV1n4UiwAAAF4"]
[Tue Jul 21 07:45:51.174722 2026] [security2:error] [pid 296703:tid 296927] [client 122.179.91.63:19446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9N3yn25uliftkV1n4UiwAAAF4"]
[Tue Jul 21 07:45:51.241205 2026] [security2:error] [pid 296703:tid 296843] [client 143.244.57.118:52290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9N3yn25uliftkV1n4UjgAAAAo"]
[Tue Jul 21 07:45:51.302444 2026] [security2:error] [pid 296703:tid 296707] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/cron.php"] [unique_id "al9N3yn25uliftkV1n4UjwAAQAM"]
[Tue Jul 21 07:45:51.328204 2026] [security2:error] [pid 296703:tid 296849] [client 184.75.223.211:35188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9N3yn25uliftkV1n4UkQAAABA"]
[Tue Jul 21 07:45:51.328304 2026] [security2:error] [pid 296703:tid 296849] [client 184.75.223.211:35188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9N3yn25uliftkV1n4UkQAAABA"]
[Tue Jul 21 07:45:51.392501 2026] [security2:error] [pid 296703:tid 296936] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9N3yn25uliftkV1n4UkwAAAGc"]
[Tue Jul 21 07:45:51.413475 2026] [security2:error] [pid 296703:tid 296913] [client 20.104.96.117:44283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/dex.php"] [unique_id "al9N3yn25uliftkV1n4UlAAAAFA"]
[Tue Jul 21 07:45:51.453488 2026] [security2:error] [pid 296703:tid 296826] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/xxx.php"] [unique_id "al9N3yn25uliftkV1n4UlQAAX3o"]
[Tue Jul 21 07:45:51.587991 2026] [security2:error] [pid 302018:tid 302175] [client 216.73.160.188:60803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9N34As9lPxxVAErz3u5AAAAJ4"]
[Tue Jul 21 07:45:51.604015 2026] [security2:error] [pid 296703:tid 296824] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/hunter.php"] [unique_id "al9N3yn25uliftkV1n4UmwAASXg"]
[Tue Jul 21 07:45:51.640599 2026] [security2:error] [pid 302018:tid 302246] [client 34.182.235.64:62984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gradiente.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9N34As9lPxxVAErz3u5QAAAOU"]
[Tue Jul 21 07:45:51.681277 2026] [security2:error] [pid 302018:tid 302259] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9N34As9lPxxVAErz3u5gAAAPI"]
[Tue Jul 21 07:45:51.713549 2026] [security2:error] [pid 302018:tid 302151] [client 143.244.57.118:52296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9N34As9lPxxVAErz3u5wAAAIY"]
[Tue Jul 21 07:45:51.796603 2026] [security2:error] [pid 302018:tid 302193] [client 182.8.255.181:17161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9N34As9lPxxVAErz3u6AAAALA"]
[Tue Jul 21 07:45:51.796756 2026] [security2:error] [pid 302018:tid 302193] [client 182.8.255.181:17161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9N34As9lPxxVAErz3u6AAAALA"]
[Tue Jul 21 07:45:51.815454 2026] [security2:error] [pid 296703:tid 296845] [client 154.208.47.43:49916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9N3yn25uliftkV1n4UnwAAAAw"]
[Tue Jul 21 07:45:51.816129 2026] [security2:error] [pid 296703:tid 296845] [client 154.208.47.43:49916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9N3yn25uliftkV1n4UnwAAAAw"]
[Tue Jul 21 07:45:51.865897 2026] [security2:error] [pid 296703:tid 296819] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/we.php"] [unique_id "al9N3yn25uliftkV1n4UoQAAcXM"]
[Tue Jul 21 07:45:51.895879 2026] [security2:error] [pid 296703:tid 296945] [client 20.197.192.193:65187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/mac.php"] [unique_id "al9N3yn25uliftkV1n4UogAAAHA"]
[Tue Jul 21 07:45:51.929728 2026] [security2:error] [pid 296703:tid 296872] [client 34.182.235.64:56142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gradiente.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9N3yn25uliftkV1n4UowAAACc"]
[Tue Jul 21 07:45:52.031492 2026] [security2:error] [pid 296703:tid 296798] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "conquisteemcasa.com.br"] [uri "/phpinfo.php1"] [unique_id "al9N4Cn25uliftkV1n4UpgAAAl4"]
[Tue Jul 21 07:45:52.138730 2026] [security2:error] [pid 302018:tid 302168] [client 143.244.57.118:52298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9N4IAs9lPxxVAErz3u6gAAAJc"]
[Tue Jul 21 07:45:52.278132 2026] [security2:error] [pid 296703:tid 296847] [client 194.99.104.35:48860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9N4Cn25uliftkV1n4UqgAAAA4"]
[Tue Jul 21 07:45:52.278218 2026] [security2:error] [pid 296703:tid 296847] [client 194.99.104.35:48860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9N4Cn25uliftkV1n4UqgAAAA4"]
[Tue Jul 21 07:45:52.396168 2026] [security2:error] [pid 296703:tid 296935] [client 20.104.96.117:44892] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "blissfullcleaning.net"] [uri "/1.php"] [unique_id "al9N4Cn25uliftkV1n4UrAAAAGY"]
[Tue Jul 21 07:45:52.396282 2026] [security2:error] [pid 296703:tid 296935] [client 20.104.96.117:44892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/1.php"] [unique_id "al9N4Cn25uliftkV1n4UrAAAAGY"]
[Tue Jul 21 07:45:52.552488 2026] [security2:error] [pid 302018:tid 302209] [client 143.244.57.118:52304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9N4IAs9lPxxVAErz3u8QAAAMA"]
[Tue Jul 21 07:45:52.553379 2026] [security2:error] [pid 302018:tid 302258] [client 178.153.91.96:53774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9N4IAs9lPxxVAErz3u8AAAAPE"]
[Tue Jul 21 07:45:52.553449 2026] [security2:error] [pid 302018:tid 302258] [client 178.153.91.96:53774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9N4IAs9lPxxVAErz3u8AAAAPE"]
[Tue Jul 21 07:45:52.659940 2026] [security2:error] [pid 302018:tid 302205] [client 20.197.192.193:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/samll.php"] [unique_id "al9N4IAs9lPxxVAErz3u8gAAALw"]
[Tue Jul 21 07:45:52.669703 2026] [security2:error] [pid 302018:tid 302275] [client 103.86.117.203:63799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N4IAs9lPxxVAErz3u8wAAAQI"]
[Tue Jul 21 07:45:52.669841 2026] [security2:error] [pid 302018:tid 302275] [client 103.86.117.203:63799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N4IAs9lPxxVAErz3u8wAAAQI"]
[Tue Jul 21 07:45:52.709877 2026] [security2:error] [pid 302018:tid 302174] [client 20.206.105.145:56696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/xmu.php"] [unique_id "al9N4IAs9lPxxVAErz3u9AAAAJ0"]
[Tue Jul 21 07:45:52.848046 2026] [security2:error] [pid 302018:tid 302189] [client 103.166.103.129:18177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9N4IAs9lPxxVAErz3u-wAAAKw"]
[Tue Jul 21 07:45:52.848123 2026] [security2:error] [pid 302018:tid 302189] [client 103.166.103.129:18177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9N4IAs9lPxxVAErz3u-wAAAKw"]
[Tue Jul 21 07:45:52.913800 2026] [security2:error] [pid 302018:tid 302046] [remote 192.241.143.148:44346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "overkotz.com"] [uri "/wp-login.php"] [unique_id "al9N4IAs9lPxxVAErz3u_AAAyhk"]
[Tue Jul 21 07:45:52.970056 2026] [security2:error] [pid 302018:tid 302152] [client 20.104.96.117:44195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/ms.php"] [unique_id "al9N4IAs9lPxxVAErz3u_QAAAIc"]
[Tue Jul 21 07:45:52.971331 2026] [security2:error] [pid 302018:tid 302222] [client 143.244.57.118:52314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9N4IAs9lPxxVAErz3u_gAAAM0"]
[Tue Jul 21 07:45:53.135188 2026] [core:error] [pid 302018:tid 302206] [client 64.23.170.109:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:45:53.135214 2026] [core:error] [pid 302018:tid 302206] [client 64.23.170.109:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:45:53.394192 2026] [security2:error] [pid 296703:tid 296950] [client 143.244.57.118:52324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9N4Sn25uliftkV1n4UvQAAAHU"]
[Tue Jul 21 07:45:53.418282 2026] [security2:error] [pid 302018:tid 302260] [client 20.197.192.193:65170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/abcd.php"] [unique_id "al9N4YAs9lPxxVAErz3vBwAAAPM"]
[Tue Jul 21 07:45:53.609019 2026] [security2:error] [pid 302018:tid 302136] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N4YAs9lPxxVAErz3vCgAAlHM"]
[Tue Jul 21 07:45:53.609162 2026] [security2:error] [pid 302018:tid 302165] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N4YAs9lPxxVAErz3vCgAAlHM"]
[Tue Jul 21 07:45:53.649357 2026] [security2:error] [pid 296703:tid 296765] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9N4Sn25uliftkV1n4UwQAACz0"]
[Tue Jul 21 07:45:53.649494 2026] [security2:error] [pid 296703:tid 296844] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9N4Sn25uliftkV1n4UwQAACz0"]
[Tue Jul 21 07:45:53.699926 2026] [security2:error] [pid 296703:tid 296953] [client 106.215.181.8:31609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N4Sn25uliftkV1n4UwgAAAHg"]
[Tue Jul 21 07:45:53.700077 2026] [security2:error] [pid 296703:tid 296953] [client 106.215.181.8:31609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N4Sn25uliftkV1n4UwgAAAHg"]
[Tue Jul 21 07:45:53.709388 2026] [core:error] [pid 302018:tid 302177] [client 66.249.66.68:59283] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:45:53.709414 2026] [core:error] [pid 302018:tid 302177] [client 66.249.66.68:59283] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:45:53.725729 2026] [security2:error] [pid 302018:tid 302042] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9N4YAs9lPxxVAErz3vDAAA7hU"]
[Tue Jul 21 07:45:53.725855 2026] [security2:error] [pid 302018:tid 302255] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9N4YAs9lPxxVAErz3vDAAA7hU"]
[Tue Jul 21 07:45:53.753788 2026] [security2:error] [pid 302018:tid 302139] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N4YAs9lPxxVAErz3vDQABA3Y"]
[Tue Jul 21 07:45:53.753910 2026] [security2:error] [pid 302018:tid 302276] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N4YAs9lPxxVAErz3vDQABA3Y"]
[Tue Jul 21 07:45:53.818524 2026] [security2:error] [pid 302018:tid 302215] [client 143.244.57.118:52336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9N4YAs9lPxxVAErz3vDwAAAMY"]
[Tue Jul 21 07:45:53.838103 2026] [security2:error] [pid 302018:tid 302068] [remote 45.3.48.204:35577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.48.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9N4YAs9lPxxVAErz3vEAAAyy8"]
[Tue Jul 21 07:45:54.157871 2026] [security2:error] [pid 302018:tid 302045] [remote 45.79.123.44:38540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rosisestefanoadvocacia.guiiaz.com.br"] [uri "/wp-login.php"] [unique_id "al9N4oAs9lPxxVAErz3vFgAApxg"]
[Tue Jul 21 07:45:54.239278 2026] [security2:error] [pid 302018:tid 302192] [client 143.244.57.118:52344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9N4oAs9lPxxVAErz3vFwAAAK8"]
[Tue Jul 21 07:45:54.441441 2026] [security2:error] [pid 302018:tid 302196] [client 20.197.192.193:65207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/xyn.php"] [unique_id "al9N4oAs9lPxxVAErz3vGgAAALM"]
[Tue Jul 21 07:45:54.637449 2026] [security2:error] [pid 296703:tid 296954] [client 62.102.148.187:34996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9N4in25uliftkV1n4U1gAAAHk"]
[Tue Jul 21 07:45:54.637526 2026] [security2:error] [pid 296703:tid 296954] [client 62.102.148.187:34996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9N4in25uliftkV1n4U1gAAAHk"]
[Tue Jul 21 07:45:54.660629 2026] [security2:error] [pid 302018:tid 302265] [client 143.244.57.118:52360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9N4oAs9lPxxVAErz3vHQAAAPg"]
[Tue Jul 21 07:45:54.746595 2026] [security2:error] [pid 302018:tid 302271] [client 20.206.105.145:56702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-admin/js/index.php"] [unique_id "al9N4oAs9lPxxVAErz3vHwAAAP4"]
[Tue Jul 21 07:45:54.805778 2026] [security2:error] [pid 296703:tid 296893] [client 122.164.127.47:49549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9N4in25uliftkV1n4U2AAAADw"]
[Tue Jul 21 07:45:54.805929 2026] [security2:error] [pid 296703:tid 296893] [client 122.164.127.47:49549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9N4in25uliftkV1n4U2AAAADw"]
[Tue Jul 21 07:45:55.029295 2026] [security2:error] [pid 302018:tid 302073] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9N44As9lPxxVAErz3vJAAA0jQ"]
[Tue Jul 21 07:45:55.029456 2026] [security2:error] [pid 302018:tid 302227] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9N44As9lPxxVAErz3vJAAA0jQ"]
[Tue Jul 21 07:45:55.060892 2026] [autoindex:error] [pid 302018:tid 302260] [client 20.104.96.117:44196] AH01276: Cannot serve directory /home2/blissf00/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:45:55.089628 2026] [security2:error] [pid 302018:tid 302175] [client 136.144.33.102:61621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9N44As9lPxxVAErz3vJgAAAJ4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:45:55.124886 2026] [security2:error] [pid 302018:tid 302253] [client 143.244.57.118:52368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9N44As9lPxxVAErz3vKAAAAOw"]
[Tue Jul 21 07:45:55.130797 2026] [access_compat:error] [pid 302018:tid 302240] [client 162.241.63.68:38912] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:45:55.258232 2026] [security2:error] [pid 302018:tid 302277] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9N44As9lPxxVAErz3vLAAAAQQ"]
[Tue Jul 21 07:45:55.349252 2026] [security2:error] [pid 296703:tid 296850] [client 37.140.223.122:58845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9N4Sn25uliftkV1n4UuwAAABE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:45:55.359983 2026] [security2:error] [pid 296703:tid 296866] [client 103.174.34.15:49328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N4yn25uliftkV1n4U6QAAACE"]
[Tue Jul 21 07:45:55.360078 2026] [security2:error] [pid 296703:tid 296866] [client 103.174.34.15:49328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N4yn25uliftkV1n4U6QAAACE"]
[Tue Jul 21 07:45:55.367428 2026] [security2:error] [pid 302018:tid 302205] [client 20.104.96.117:44196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/memberfuns.php"] [unique_id "al9N44As9lPxxVAErz3vLQAAALw"]
[Tue Jul 21 07:45:55.400340 2026] [security2:error] [pid 296703:tid 296915] [client 41.68.90.219:50938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N4yn25uliftkV1n4U6wAAAFI"]
[Tue Jul 21 07:45:55.401553 2026] [security2:error] [pid 296703:tid 296915] [client 41.68.90.219:50938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N4yn25uliftkV1n4U6wAAAFI"]
[Tue Jul 21 07:45:55.454523 2026] [security2:error] [pid 296703:tid 296942] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9N4yn25uliftkV1n4U7QAAAG0"]
[Tue Jul 21 07:45:55.508026 2026] [security2:error] [pid 296703:tid 296957] [client 117.217.38.194:59407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N4yn25uliftkV1n4U7gAAAHw"]
[Tue Jul 21 07:45:55.508207 2026] [security2:error] [pid 296703:tid 296957] [client 117.217.38.194:59407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N4yn25uliftkV1n4U7gAAAHw"]
[Tue Jul 21 07:45:55.551536 2026] [security2:error] [pid 302018:tid 302191] [client 143.244.57.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N44As9lPxxVAErz3vMQAAAK4"]
[Tue Jul 21 07:45:55.636551 2026] [security2:error] [pid 296703:tid 296929] [client 143.244.57.118:52374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9N4yn25uliftkV1n4U8QAAAGA"]
[Tue Jul 21 07:45:55.737018 2026] [security2:error] [pid 302018:tid 302192] [client 143.244.57.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N44As9lPxxVAErz3vMgAAAK8"]
[Tue Jul 21 07:45:55.740914 2026] [security2:error] [pid 302018:tid 302257] [client 20.206.105.145:56637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/puc.php"] [unique_id "al9N44As9lPxxVAErz3vMwAAAPA"]
[Tue Jul 21 07:45:55.761221 2026] [security2:error] [pid 302018:tid 302272] [client 223.236.153.128:5556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9N44As9lPxxVAErz3vNAAAAP8"]
[Tue Jul 21 07:45:55.771073 2026] [security2:error] [pid 302018:tid 302272] [client 223.236.153.128:5556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9N44As9lPxxVAErz3vNAAAAP8"]
[Tue Jul 21 07:45:55.988087 2026] [core:error] [pid 302018:tid 302162] [client 66.249.66.67:38615] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:45:55.988105 2026] [core:error] [pid 302018:tid 302162] [client 66.249.66.67:38615] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:45:55.996401 2026] [security2:error] [pid 296703:tid 296841] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9N4yn25uliftkV1n4U-gAAAAg"]
[Tue Jul 21 07:45:56.048546 2026] [security2:error] [pid 302018:tid 302203] [client 143.244.57.118:52380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9N5IAs9lPxxVAErz3vOQAAALo"]
[Tue Jul 21 07:45:56.094045 2026] [security2:error] [pid 302018:tid 302206] [client 20.197.192.193:65186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/byp8.php"] [unique_id "al9N5IAs9lPxxVAErz3vOgAAAL0"]
[Tue Jul 21 07:45:56.105772 2026] [security2:error] [pid 302018:tid 302273] [client 20.104.96.117:46697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/xyn.php"] [unique_id "al9N5IAs9lPxxVAErz3vOwAAAQA"]
[Tue Jul 21 07:45:56.185740 2026] [security2:error] [pid 296703:tid 296941] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9N5Cn25uliftkV1n4U_gAAAGw"]
[Tue Jul 21 07:45:56.306396 2026] [security2:error] [pid 302018:tid 302260] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9N5IAs9lPxxVAErz3vPgAAAPM"]
[Tue Jul 21 07:45:56.327427 2026] [security2:error] [pid 302018:tid 302231] [client 20.104.96.117:44262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/0.php"] [unique_id "al9N5IAs9lPxxVAErz3vPwAAANY"]
[Tue Jul 21 07:45:56.336728 2026] [security2:error] [pid 302018:tid 302240] [client 20.197.192.193:65185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/user.php"] [unique_id "al9N5IAs9lPxxVAErz3vQAAAAN8"]
[Tue Jul 21 07:45:56.471266 2026] [security2:error] [pid 302018:tid 302177] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9N5IAs9lPxxVAErz3vQQAAAKA"]
[Tue Jul 21 07:45:56.526551 2026] [security2:error] [pid 302018:tid 302173] [client 194.99.104.35:48864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9N5IAs9lPxxVAErz3vQwAAAJw"]
[Tue Jul 21 07:45:56.526643 2026] [security2:error] [pid 302018:tid 302173] [client 194.99.104.35:48864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9N5IAs9lPxxVAErz3vQwAAAJw"]
[Tue Jul 21 07:45:56.531022 2026] [security2:error] [pid 296703:tid 296860] [client 143.244.57.118:52396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9N5Cn25uliftkV1n4VBAAAABs"]
[Tue Jul 21 07:45:56.558138 2026] [security2:error] [pid 302018:tid 302205] [client 20.197.192.193:65177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/ops.php"] [unique_id "al9N5IAs9lPxxVAErz3vRQAAALw"]
[Tue Jul 21 07:45:56.599102 2026] [security2:error] [pid 302018:tid 302252] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9N5IAs9lPxxVAErz3vRgAAAOs"]
[Tue Jul 21 07:45:56.621747 2026] [security2:error] [pid 296703:tid 296833] [client 122.186.204.214:50148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N5Cn25uliftkV1n4VBgAAAAA"]
[Tue Jul 21 07:45:56.621891 2026] [security2:error] [pid 296703:tid 296833] [client 122.186.204.214:50148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N5Cn25uliftkV1n4VBgAAAAA"]
[Tue Jul 21 07:45:56.721171 2026] [security2:error] [pid 296703:tid 296956] [client 117.247.80.59:23790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N5Cn25uliftkV1n4VCQAAAHs"]
[Tue Jul 21 07:45:56.721279 2026] [security2:error] [pid 296703:tid 296956] [client 117.247.80.59:23790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N5Cn25uliftkV1n4VCQAAAHs"]
[Tue Jul 21 07:45:56.753996 2026] [security2:error] [pid 296703:tid 296845] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9N5Cn25uliftkV1n4VDAAAAAw"]
[Tue Jul 21 07:45:56.802367 2026] [security2:error] [pid 302018:tid 302160] [client 20.206.105.145:56589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/themes.php"] [unique_id "al9N5IAs9lPxxVAErz3vSQAAAI8"]
[Tue Jul 21 07:45:56.868512 2026] [security2:error] [pid 302018:tid 302189] [client 20.197.192.193:65158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/term.php"] [unique_id "al9N5IAs9lPxxVAErz3vSgAAAKw"]
[Tue Jul 21 07:45:56.891374 2026] [security2:error] [pid 296703:tid 296888] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9N5Cn25uliftkV1n4VDQAAADc"]
[Tue Jul 21 07:45:56.989065 2026] [security2:error] [pid 302018:tid 302196] [client 20.197.192.193:65194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/ah25.php"] [unique_id "al9N5IAs9lPxxVAErz3vTAAAALM"]
[Tue Jul 21 07:45:57.009642 2026] [security2:error] [pid 296703:tid 296835] [client 143.244.57.118:52406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9N5Sn25uliftkV1n4VEAAAAAI"]
[Tue Jul 21 07:45:57.043588 2026] [security2:error] [pid 302018:tid 302222] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9N5YAs9lPxxVAErz3vTQAAAM0"]
[Tue Jul 21 07:45:57.138461 2026] [security2:error] [pid 296703:tid 296947] [client 20.63.100.92:8056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/billur.php"] [unique_id "al9N5Sn25uliftkV1n4VFAAAAHI"]
[Tue Jul 21 07:45:57.139903 2026] [security2:error] [pid 296703:tid 296924] [client 20.197.192.193:43811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/8.php"] [unique_id "al9N5Sn25uliftkV1n4VFQAAAFs"]
[Tue Jul 21 07:45:57.183937 2026] [security2:error] [pid 302018:tid 302247] [client 20.197.192.193:43803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/red.php"] [unique_id "al9N5YAs9lPxxVAErz3vWQAAAOY"]
[Tue Jul 21 07:45:57.185173 2026] [security2:error] [pid 302018:tid 302233] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9N5YAs9lPxxVAErz3vWgAAANg"]
[Tue Jul 21 07:45:57.265552 2026] [security2:error] [pid 302018:tid 302271] [client 20.206.105.145:56673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/8.php"] [unique_id "al9N5YAs9lPxxVAErz3vXQAAAP4"]
[Tue Jul 21 07:45:57.296695 2026] [security2:error] [pid 302018:tid 302238] [client 117.251.86.144:53818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9N5YAs9lPxxVAErz3vXgAAAN0"]
[Tue Jul 21 07:45:57.296786 2026] [security2:error] [pid 302018:tid 302238] [client 117.251.86.144:53818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9N5YAs9lPxxVAErz3vXgAAAN0"]
[Tue Jul 21 07:45:57.330677 2026] [security2:error] [pid 302018:tid 302246] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9N5YAs9lPxxVAErz3vXwAAAOU"]
[Tue Jul 21 07:45:57.388079 2026] [security2:error] [pid 302018:tid 302193] [client 20.197.192.193:43799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/fffm.php"] [unique_id "al9N5YAs9lPxxVAErz3vYQAAALA"]
[Tue Jul 21 07:45:57.402400 2026] [security2:error] [pid 302018:tid 302183] [client 20.104.96.117:44154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/BDKR28.php"] [unique_id "al9N5YAs9lPxxVAErz3vYwAAAKY"]
[Tue Jul 21 07:45:57.446013 2026] [security2:error] [pid 302018:tid 302260] [client 20.197.192.193:43784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/ftde.php"] [unique_id "al9N5YAs9lPxxVAErz3vZAAAAPM"]
[Tue Jul 21 07:45:57.446624 2026] [security2:error] [pid 296703:tid 296866] [client 143.244.57.118:52422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9N5Sn25uliftkV1n4VGQAAACE"]
[Tue Jul 21 07:45:57.479762 2026] [security2:error] [pid 302018:tid 302165] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9N5YAs9lPxxVAErz3vZQAAAJQ"]
[Tue Jul 21 07:45:57.572578 2026] [core:error] [pid 302018:tid 302205] [client 64.23.170.109:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.cezadvogados.com/
[Tue Jul 21 07:45:57.572603 2026] [core:error] [pid 302018:tid 302205] [client 64.23.170.109:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.cezadvogados.com/
[Tue Jul 21 07:45:57.614521 2026] [security2:error] [pid 302018:tid 302186] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9N5YAs9lPxxVAErz3vawAAAKk"]
[Tue Jul 21 07:45:57.738775 2026] [security2:error] [pid 302018:tid 302270] [client 20.197.192.193:43788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/yup.php"] [unique_id "al9N5YAs9lPxxVAErz3vbQAAAP0"]
[Tue Jul 21 07:45:57.773047 2026] [security2:error] [pid 302018:tid 302189] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9N5YAs9lPxxVAErz3vcAAAAKw"]
[Tue Jul 21 07:45:57.858517 2026] [security2:error] [pid 302018:tid 302222] [client 143.244.57.118:55216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "milhasexpresso.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9N5YAs9lPxxVAErz3vcwAAAM0"]
[Tue Jul 21 07:45:57.899556 2026] [security2:error] [pid 302018:tid 302178] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9N5YAs9lPxxVAErz3vdAAAAKE"]
[Tue Jul 21 07:45:57.976294 2026] [security2:error] [pid 302018:tid 302166] [client 20.197.192.193:43790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/jj.php"] [unique_id "al9N5YAs9lPxxVAErz3vdQAAAJU"]
[Tue Jul 21 07:45:58.055696 2026] [security2:error] [pid 302018:tid 302261] [client 20.197.192.193:65182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/dragonshell.php"] [unique_id "al9N5oAs9lPxxVAErz3veAAAAPQ"]
[Tue Jul 21 07:45:58.067271 2026] [core:error] [pid 302018:tid 302244] [client 66.249.66.196:38438] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:45:58.067295 2026] [core:error] [pid 302018:tid 302244] [client 66.249.66.196:38438] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:45:58.090977 2026] [security2:error] [pid 302018:tid 302273] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9N5oAs9lPxxVAErz3vewAAAQA"]
[Tue Jul 21 07:45:58.184514 2026] [security2:error] [pid 302018:tid 302151] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9N5oAs9lPxxVAErz3vfAAAAIY"]
[Tue Jul 21 07:45:58.261881 2026] [security2:error] [pid 296703:tid 296948] [client 20.197.192.193:48330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/wp-mt.php"] [unique_id "al9N5in25uliftkV1n4VJAAAAHM"]
[Tue Jul 21 07:45:58.387721 2026] [security2:error] [pid 302018:tid 302177] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9N5oAs9lPxxVAErz3vfgAAAKA"]
[Tue Jul 21 07:45:58.399051 2026] [security2:error] [pid 302018:tid 302255] [client 20.206.105.145:29653] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "aumentodevendas.factorial.studio"] [uri "/1.php"] [unique_id "al9N5oAs9lPxxVAErz3vfwAAAO4"]
[Tue Jul 21 07:45:58.399153 2026] [security2:error] [pid 302018:tid 302255] [client 20.206.105.145:29653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/1.php"] [unique_id "al9N5oAs9lPxxVAErz3vfwAAAO4"]
[Tue Jul 21 07:45:58.470335 2026] [security2:error] [pid 302018:tid 302240] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9N5oAs9lPxxVAErz3vgAAAAN8"]
[Tue Jul 21 07:45:58.544386 2026] [security2:error] [pid 302018:tid 302252] [client 20.197.192.193:43789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/ww.php"] [unique_id "al9N5oAs9lPxxVAErz3viwAAAOs"]
[Tue Jul 21 07:45:58.596857 2026] [security2:error] [pid 302018:tid 302243] [client 185.213.175.37:2588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "armazemraizesdaserra.com.br"] [uri "/wp-json/oembed/1.0/embed"] [unique_id "al9N5oAs9lPxxVAErz3vjQAAAOI"]
[Tue Jul 21 07:45:58.596982 2026] [security2:error] [pid 302018:tid 302243] [client 185.213.175.37:2588] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "armazemraizesdaserra.com.br"] [uri "/wp-json/oembed/1.0/embed"] [unique_id "al9N5oAs9lPxxVAErz3vjQAAAOI"]
[Tue Jul 21 07:45:58.678405 2026] [security2:error] [pid 302018:tid 302263] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9N5oAs9lPxxVAErz3vkAAAAPY"]
[Tue Jul 21 07:45:58.738756 2026] [security2:error] [pid 302018:tid 302152] [client 20.197.192.193:43794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/cron.php"] [unique_id "al9N5oAs9lPxxVAErz3vkgAAAIc"]
[Tue Jul 21 07:45:58.753582 2026] [security2:error] [pid 302018:tid 302222] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9N5oAs9lPxxVAErz3vkwAAAM0"]
[Tue Jul 21 07:45:58.824991 2026] [security2:error] [pid 302018:tid 302224] [client 193.36.225.72:34665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9N5oAs9lPxxVAErz3vlgAAAM8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:45:58.836983 2026] [security2:error] [pid 302018:tid 302261] [client 20.104.96.117:44227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/green1.php"] [unique_id "al9N5oAs9lPxxVAErz3vlwAAAPQ"]
[Tue Jul 21 07:45:58.893681 2026] [security2:error] [pid 302018:tid 302265] [client 20.197.192.193:48336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/xxx.php"] [unique_id "al9N5oAs9lPxxVAErz3vmAAAAPg"]
[Tue Jul 21 07:45:58.916692 2026] [security2:error] [pid 296703:tid 296913] [client 20.197.195.24:18497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9N5in25uliftkV1n4VMAAAAFA"]
[Tue Jul 21 07:45:58.985441 2026] [security2:error] [pid 296703:tid 296919] [client 59.96.220.140:51210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9N5in25uliftkV1n4VMQAAAFY"]
[Tue Jul 21 07:45:58.986059 2026] [security2:error] [pid 296703:tid 296919] [client 59.96.220.140:51210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9N5in25uliftkV1n4VMQAAAFY"]
[Tue Jul 21 07:45:59.018071 2026] [security2:error] [pid 302018:tid 302184] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9N54As9lPxxVAErz3vmwAAAKc"]
[Tue Jul 21 07:45:59.042596 2026] [security2:error] [pid 302018:tid 302246] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9N54As9lPxxVAErz3vnAAAAOU"]
[Tue Jul 21 07:45:59.126520 2026] [security2:error] [pid 302018:tid 302177] [client 20.197.192.193:65204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/hunter.php"] [unique_id "al9N54As9lPxxVAErz3voAAAAKA"]
[Tue Jul 21 07:45:59.128011 2026] [security2:error] [pid 302018:tid 302255] [client 20.206.105.145:56601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/100.php"] [unique_id "al9N54As9lPxxVAErz3voQAAAO4"]
[Tue Jul 21 07:45:59.315490 2026] [security2:error] [pid 302018:tid 302205] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9N54As9lPxxVAErz3vpgAAALw"]
[Tue Jul 21 07:45:59.329886 2026] [security2:error] [pid 302018:tid 302198] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9N54As9lPxxVAErz3vpwAAALU"]
[Tue Jul 21 07:45:59.490894 2026] [security2:error] [pid 296703:tid 296960] [client 128.127.105.184:51286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9N5yn25uliftkV1n4VNwAAAH8"]
[Tue Jul 21 07:45:59.490999 2026] [security2:error] [pid 296703:tid 296960] [client 128.127.105.184:51286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9N5yn25uliftkV1n4VNwAAAH8"]
[Tue Jul 21 07:45:59.606463 2026] [security2:error] [pid 302018:tid 302257] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9N54As9lPxxVAErz3vsQAAAPA"]
[Tue Jul 21 07:45:59.616295 2026] [security2:error] [pid 296703:tid 296896] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9N5yn25uliftkV1n4VOgAAAD8"]
[Tue Jul 21 07:45:59.692922 2026] [security2:error] [pid 302018:tid 302263] [client 20.197.192.193:65157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/we.php"] [unique_id "al9N54As9lPxxVAErz3vsgAAAPY"]
[Tue Jul 21 07:45:59.826675 2026] [security2:error] [pid 302018:tid 302259] [client 20.197.195.24:16154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9N54As9lPxxVAErz3vtAAAAPI"]
[Tue Jul 21 07:45:59.880992 2026] [security2:error] [pid 302018:tid 302178] [client 20.63.100.92:6430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/mimpi.php"] [unique_id "al9N54As9lPxxVAErz3vtgAAAKE"]
[Tue Jul 21 07:45:59.899478 2026] [security2:error] [pid 296703:tid 296945] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9N5yn25uliftkV1n4VPgAAAHA"]
[Tue Jul 21 07:45:59.900218 2026] [security2:error] [pid 296703:tid 296906] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9N5yn25uliftkV1n4VPwAAAEk"]
[Tue Jul 21 07:45:59.916416 2026] [security2:error] [pid 296703:tid 296925] [client 20.197.192.193:65159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/phpinfo.php1"] [unique_id "al9N5yn25uliftkV1n4VQAAAAFw"]
[Tue Jul 21 07:45:59.929829 2026] [core:error] [pid 296703:tid 296845] [client 66.249.66.38:60842] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:45:59.929848 2026] [core:error] [pid 296703:tid 296845] [client 66.249.66.38:60842] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:46:00.157557 2026] [security2:error] [pid 302018:tid 302271] [client 20.104.96.117:44134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/nc4.php"] [unique_id "al9N6IAs9lPxxVAErz3vuwAAAP4"]
[Tue Jul 21 07:46:00.185409 2026] [security2:error] [pid 296703:tid 296935] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9N6Cn25uliftkV1n4VRgAAAGY"]
[Tue Jul 21 07:46:00.200155 2026] [security2:error] [pid 302018:tid 302229] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9N6IAs9lPxxVAErz3vvAAAANQ"]
[Tue Jul 21 07:46:00.470173 2026] [security2:error] [pid 296703:tid 296875] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9N6Cn25uliftkV1n4VSwAAACo"]
[Tue Jul 21 07:46:00.507872 2026] [security2:error] [pid 302018:tid 302183] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mulher-de-valor.online.elvissousabrandao1781989696466.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9N6IAs9lPxxVAErz3vwwAAAKY"]
[Tue Jul 21 07:46:00.572646 2026] [security2:error] [pid 302018:tid 302186] [client 20.197.195.24:16181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/media.php"] [unique_id "al9N6IAs9lPxxVAErz3vxQAAAKk"]
[Tue Jul 21 07:46:00.587294 2026] [security2:error] [pid 296703:tid 296934] [client 20.206.105.145:56597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/about.php"] [unique_id "al9N6Cn25uliftkV1n4VTgAAAGU"]
[Tue Jul 21 07:46:00.697093 2026] [security2:error] [pid 296703:tid 296791] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N6Cn25uliftkV1n4VUgAAEFc"]
[Tue Jul 21 07:46:00.697221 2026] [security2:error] [pid 296703:tid 296849] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N6Cn25uliftkV1n4VUgAAEFc"]
[Tue Jul 21 07:46:01.046844 2026] [security2:error] [pid 302018:tid 302221] [client 103.29.114.44:34700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N6YAs9lPxxVAErz3vzgAAAMw"]
[Tue Jul 21 07:46:01.047022 2026] [security2:error] [pid 302018:tid 302221] [client 103.29.114.44:34700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N6YAs9lPxxVAErz3vzgAAAMw"]
[Tue Jul 21 07:46:01.083128 2026] [security2:error] [pid 296703:tid 296844] [client 20.63.100.92:8041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/dp.php"] [unique_id "al9N6Sn25uliftkV1n4VWgAAAAs"]
[Tue Jul 21 07:46:01.121374 2026] [security2:error] [pid 302018:tid 302272] [client 216.73.161.159:57051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giovanoniadv.com.br"] [uri "/wp-login.php"] [unique_id "al9N6IAs9lPxxVAErz3vuQAAAP8"]
[Tue Jul 21 07:46:01.246715 2026] [security2:error] [pid 302018:tid 302067] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9N6YAs9lPxxVAErz3v0gAA8C4"]
[Tue Jul 21 07:46:01.246903 2026] [security2:error] [pid 302018:tid 302257] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9N6YAs9lPxxVAErz3v0gAA8C4"]
[Tue Jul 21 07:46:01.249508 2026] [security2:error] [pid 296703:tid 296840] [client 20.197.195.24:18505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/images.php"] [unique_id "al9N6Sn25uliftkV1n4VXgAAAAc"]
[Tue Jul 21 07:46:01.251700 2026] [security2:error] [pid 296703:tid 296900] [client 173.24.185.52:65028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9N6Sn25uliftkV1n4VXwAAAEM"]
[Tue Jul 21 07:46:01.251792 2026] [security2:error] [pid 296703:tid 296900] [client 173.24.185.52:65028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9N6Sn25uliftkV1n4VXwAAAEM"]
[Tue Jul 21 07:46:01.259903 2026] [security2:error] [pid 296703:tid 296915] [client 139.167.225.182:62614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N6Sn25uliftkV1n4VYAAAAFI"]
[Tue Jul 21 07:46:01.260065 2026] [security2:error] [pid 296703:tid 296915] [client 139.167.225.182:62614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N6Sn25uliftkV1n4VYAAAAFI"]
[Tue Jul 21 07:46:01.327781 2026] [security2:error] [pid 302018:tid 302080] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N6YAs9lPxxVAErz3v1QAAzzs"]
[Tue Jul 21 07:46:01.327981 2026] [security2:error] [pid 302018:tid 302224] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N6YAs9lPxxVAErz3v1QAAzzs"]
[Tue Jul 21 07:46:01.644964 2026] [security2:error] [pid 302018:tid 302230] [client 185.251.19.60:30911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/wp-login.php"] [unique_id "al9N6YAs9lPxxVAErz3v3AAAANU"]
[Tue Jul 21 07:46:01.707887 2026] [security2:error] [pid 302018:tid 302152] [client 202.143.127.214:58716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N6YAs9lPxxVAErz3v3QAAAIc"]
[Tue Jul 21 07:46:01.708061 2026] [security2:error] [pid 302018:tid 302152] [client 202.143.127.214:58716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N6YAs9lPxxVAErz3v3QAAAIc"]
[Tue Jul 21 07:46:01.850743 2026] [security2:error] [pid 302018:tid 302263] [client 122.162.144.145:19123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9N6YAs9lPxxVAErz3v3wAAAPY"]
[Tue Jul 21 07:46:01.850898 2026] [security2:error] [pid 302018:tid 302263] [client 122.162.144.145:19123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9N6YAs9lPxxVAErz3v3wAAAPY"]
[Tue Jul 21 07:46:01.908028 2026] [security2:error] [pid 302018:tid 302174] [client 20.197.195.24:16177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/gecko.php"] [unique_id "al9N6YAs9lPxxVAErz3v4AAAAJ0"]
[Tue Jul 21 07:46:02.008161 2026] [security2:error] [pid 296703:tid 296946] [client 20.206.105.145:56644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/about.php"] [unique_id "al9N6in25uliftkV1n4VbgAAAHE"]
[Tue Jul 21 07:46:02.073387 2026] [security2:error] [pid 302018:tid 302202] [client 20.197.195.24:18545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/82.php"] [unique_id "al9N6oAs9lPxxVAErz3v4gAAALk"]
[Tue Jul 21 07:46:02.227001 2026] [security2:error] [pid 302018:tid 302204] [client 182.8.255.181:17703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9N6oAs9lPxxVAErz3v4wAAALs"]
[Tue Jul 21 07:46:02.227121 2026] [security2:error] [pid 302018:tid 302204] [client 182.8.255.181:17703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9N6oAs9lPxxVAErz3v4wAAALs"]
[Tue Jul 21 07:46:02.243719 2026] [security2:error] [pid 296703:tid 296956] [client 185.213.175.37:2600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aronimoveis.com.br"] [uri "/var/assets/img/images/cropped-favicon-192x192.png"] [unique_id "al9N6in25uliftkV1n4VcgAAAHs"]
[Tue Jul 21 07:46:02.243825 2026] [security2:error] [pid 296703:tid 296956] [client 185.213.175.37:2600] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aronimoveis.com.br"] [uri "/var/assets/img/images/cropped-favicon-192x192.png"] [unique_id "al9N6in25uliftkV1n4VcgAAAHs"]
[Tue Jul 21 07:46:02.346902 2026] [security2:error] [pid 296703:tid 296944] [client 20.104.96.117:44146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/a1.php"] [unique_id "al9N6in25uliftkV1n4VdQAAAG8"]
[Tue Jul 21 07:46:02.410060 2026] [security2:error] [pid 296703:tid 296874] [client 154.208.47.43:50400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9N6in25uliftkV1n4VdgAAACk"]
[Tue Jul 21 07:46:02.410216 2026] [security2:error] [pid 296703:tid 296874] [client 154.208.47.43:50400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9N6in25uliftkV1n4VdgAAACk"]
[Tue Jul 21 07:46:02.631119 2026] [security2:error] [pid 302018:tid 302177] [client 152.59.154.239:63491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N6oAs9lPxxVAErz3v6wAAAKA"]
[Tue Jul 21 07:46:02.631240 2026] [security2:error] [pid 302018:tid 302177] [client 152.59.154.239:63491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N6oAs9lPxxVAErz3v6wAAAKA"]
[Tue Jul 21 07:46:02.997909 2026] [security2:error] [pid 296703:tid 296955] [client 20.197.195.24:16188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/admin.php"] [unique_id "al9N6in25uliftkV1n4VhQAAAHo"]
[Tue Jul 21 07:46:03.076474 2026] [security2:error] [pid 296703:tid 296856] [client 20.206.105.145:56621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/admin.php"] [unique_id "al9N6yn25uliftkV1n4VhgAAABc"]
[Tue Jul 21 07:46:03.120542 2026] [security2:error] [pid 296703:tid 296854] [client 178.153.91.96:15667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9N6yn25uliftkV1n4VhwAAABU"]
[Tue Jul 21 07:46:03.120668 2026] [security2:error] [pid 296703:tid 296854] [client 178.153.91.96:15667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9N6yn25uliftkV1n4VhwAAABU"]
[Tue Jul 21 07:46:03.207421 2026] [security2:error] [pid 302018:tid 302176] [client 103.86.117.203:64351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N64As9lPxxVAErz3v8QAAAJ8"]
[Tue Jul 21 07:46:03.207543 2026] [security2:error] [pid 302018:tid 302176] [client 103.86.117.203:64351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N64As9lPxxVAErz3v8QAAAJ8"]
[Tue Jul 21 07:46:03.232312 2026] [security2:error] [pid 302018:tid 302194] [client 136.144.33.213:27835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9N64As9lPxxVAErz3v8AAAALE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:46:03.629313 2026] [security2:error] [pid 302018:tid 302166] [client 103.166.103.129:18715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9N64As9lPxxVAErz3v-QAAAJU"]
[Tue Jul 21 07:46:03.629507 2026] [security2:error] [pid 302018:tid 302166] [client 103.166.103.129:18715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9N64As9lPxxVAErz3v-QAAAJU"]
[Tue Jul 21 07:46:03.683251 2026] [security2:error] [pid 296703:tid 296900] [client 20.104.96.117:44218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/eee.php"] [unique_id "al9N6yn25uliftkV1n4VjgAAAEM"]
[Tue Jul 21 07:46:03.837945 2026] [security2:error] [pid 302018:tid 302183] [client 184.75.223.211:41854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9N64As9lPxxVAErz3v-wAAAKY"]
[Tue Jul 21 07:46:03.838053 2026] [security2:error] [pid 302018:tid 302183] [client 184.75.223.211:41854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9N64As9lPxxVAErz3v-wAAAKY"]
[Tue Jul 21 07:46:03.907083 2026] [core:error] [pid 296703:tid 296760] [remote 74.7.175.180:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:46:03.907102 2026] [core:error] [pid 296703:tid 296760] [remote 74.7.175.180:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:46:03.907297 2026] [security2:error] [pid 296703:tid 296882] [client 74.7.175.180:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.luminabeauty.com.br"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "al9N6yn25uliftkV1n4VkQAAMTg"]
[Tue Jul 21 07:46:04.112632 2026] [security2:error] [pid 302018:tid 302204] [client 20.197.195.24:16168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/adminner.php"] [unique_id "al9N7IAs9lPxxVAErz3wAAAAALs"]
[Tue Jul 21 07:46:04.127890 2026] [security2:error] [pid 296703:tid 296860] [client 62.102.148.187:43968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9N7Cn25uliftkV1n4VlwAAABs"]
[Tue Jul 21 07:46:04.127996 2026] [security2:error] [pid 296703:tid 296860] [client 62.102.148.187:43968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9N7Cn25uliftkV1n4VlwAAABs"]
[Tue Jul 21 07:46:04.206747 2026] [security2:error] [pid 296703:tid 296836] [client 106.215.181.8:18923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N7Cn25uliftkV1n4VmAAAAAM"]
[Tue Jul 21 07:46:04.206882 2026] [security2:error] [pid 296703:tid 296836] [client 106.215.181.8:18923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N7Cn25uliftkV1n4VmAAAAAM"]
[Tue Jul 21 07:46:04.257652 2026] [security2:error] [pid 302018:tid 302070] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9N7IAs9lPxxVAErz3wAwAArzE"]
[Tue Jul 21 07:46:04.257788 2026] [security2:error] [pid 302018:tid 302192] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9N7IAs9lPxxVAErz3wAwAArzE"]
[Tue Jul 21 07:46:04.265084 2026] [security2:error] [pid 302018:tid 302033] [remote 65.111.15.6:38893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9N7IAs9lPxxVAErz3v_wAA9gw"]
[Tue Jul 21 07:46:04.287651 2026] [security2:error] [pid 296703:tid 296765] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9N7Cn25uliftkV1n4VmwAAPD0"]
[Tue Jul 21 07:46:04.287766 2026] [security2:error] [pid 296703:tid 296893] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9N7Cn25uliftkV1n4VmwAAPD0"]
[Tue Jul 21 07:46:04.309217 2026] [security2:error] [pid 296703:tid 296747] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N7Cn25uliftkV1n4VngAALis"]
[Tue Jul 21 07:46:04.309387 2026] [security2:error] [pid 296703:tid 296879] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N7Cn25uliftkV1n4VngAALis"]
[Tue Jul 21 07:46:04.423926 2026] [security2:error] [pid 302018:tid 302218] [client 20.197.195.24:16189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/admin.php"] [unique_id "al9N7IAs9lPxxVAErz3wBgAAAMk"]
[Tue Jul 21 07:46:04.471923 2026] [security2:error] [pid 296703:tid 296705] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N7Cn25uliftkV1n4VnwAADAE"]
[Tue Jul 21 07:46:04.472090 2026] [security2:error] [pid 296703:tid 296845] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N7Cn25uliftkV1n4VnwAADAE"]
[Tue Jul 21 07:46:04.530188 2026] [security2:error] [pid 302018:tid 302228] [client 20.197.195.24:16236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/k.php"] [unique_id "al9N7IAs9lPxxVAErz3wCwAAANM"]
[Tue Jul 21 07:46:04.731512 2026] [security2:error] [pid 302018:tid 302267] [client 20.197.195.24:16246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/blurbs.php"] [unique_id "al9N7IAs9lPxxVAErz3wDwAAAPo"]
[Tue Jul 21 07:46:04.749340 2026] [security2:error] [pid 302018:tid 302176] [client 20.63.100.92:8002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/bootstrap.php"] [unique_id "al9N7IAs9lPxxVAErz3wEAAAAJ8"]
[Tue Jul 21 07:46:04.988126 2026] [security2:error] [pid 296703:tid 296846] [client 20.104.96.117:44167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-aothait.php"] [unique_id "al9N7Cn25uliftkV1n4VqwAAAA0"]
[Tue Jul 21 07:46:05.174848 2026] [security2:error] [pid 302018:tid 302184] [client 20.197.195.24:16155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/bajah.php"] [unique_id "al9N7YAs9lPxxVAErz3wFQAAAKc"]
[Tue Jul 21 07:46:05.352508 2026] [security2:error] [pid 302018:tid 302234] [client 20.104.96.117:46602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/patie.php"] [unique_id "al9N7YAs9lPxxVAErz3wFwAAANk"]
[Tue Jul 21 07:46:05.548693 2026] [security2:error] [pid 296703:tid 296874] [client 122.164.127.47:50134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9N7Sn25uliftkV1n4VugAAACk"]
[Tue Jul 21 07:46:05.552643 2026] [security2:error] [pid 296703:tid 296874] [client 122.164.127.47:50134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9N7Sn25uliftkV1n4VugAAACk"]
[Tue Jul 21 07:46:05.563888 2026] [security2:error] [pid 302018:tid 302056] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9N7YAs9lPxxVAErz3wGQAA3yM"]
[Tue Jul 21 07:46:05.564047 2026] [security2:error] [pid 302018:tid 302240] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9N7YAs9lPxxVAErz3wGQAA3yM"]
[Tue Jul 21 07:46:05.614795 2026] [security2:error] [pid 302018:tid 302183] [client 20.206.105.145:56607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/admin.php"] [unique_id "al9N7YAs9lPxxVAErz3wGgAAAKY"]
[Tue Jul 21 07:46:05.668832 2026] [security2:error] [pid 302018:tid 302182] [client 122.179.91.63:13983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9N7YAs9lPxxVAErz3wGwAAAKU"]
[Tue Jul 21 07:46:05.669056 2026] [security2:error] [pid 302018:tid 302182] [client 122.179.91.63:13983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9N7YAs9lPxxVAErz3wGwAAAKU"]
[Tue Jul 21 07:46:05.795545 2026] [security2:error] [pid 296703:tid 296859] [client 20.197.195.24:16166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/a.php"] [unique_id "al9N7Sn25uliftkV1n4VuwAAABo"]
[Tue Jul 21 07:46:05.805313 2026] [security2:error] [pid 296703:tid 296920] [client 193.36.225.54:26067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9N6yn25uliftkV1n4VjQAAAFc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:46:05.916248 2026] [security2:error] [pid 302018:tid 302246] [client 103.174.34.15:49834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N7YAs9lPxxVAErz3wHwAAAOU"]
[Tue Jul 21 07:46:05.916344 2026] [security2:error] [pid 302018:tid 302246] [client 103.174.34.15:49834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N7YAs9lPxxVAErz3wHwAAAOU"]
[Tue Jul 21 07:46:05.977620 2026] [security2:error] [pid 296703:tid 296834] [client 117.217.38.194:59899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N7Sn25uliftkV1n4VwAAAAAE"]
[Tue Jul 21 07:46:05.977712 2026] [security2:error] [pid 296703:tid 296834] [client 117.217.38.194:59899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N7Sn25uliftkV1n4VwAAAAAE"]
[Tue Jul 21 07:46:05.995840 2026] [security2:error] [pid 296703:tid 296955] [client 41.68.90.219:51370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N7Sn25uliftkV1n4VwQAAAHo"]
[Tue Jul 21 07:46:05.995927 2026] [security2:error] [pid 296703:tid 296955] [client 41.68.90.219:51370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N7Sn25uliftkV1n4VwQAAAHo"]
[Tue Jul 21 07:46:06.041851 2026] [security2:error] [pid 302018:tid 302189] [client 128.127.105.184:51312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9N7oAs9lPxxVAErz3wIAAAAKw"]
[Tue Jul 21 07:46:06.041929 2026] [security2:error] [pid 302018:tid 302189] [client 128.127.105.184:51312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9N7oAs9lPxxVAErz3wIAAAAKw"]
[Tue Jul 21 07:46:06.112426 2026] [security2:error] [pid 296703:tid 296953] [client 172.245.102.32:20277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9N7Sn25uliftkV1n4VvwAAAHg"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:46:06.238731 2026] [security2:error] [pid 302018:tid 302172] [client 20.197.195.24:16216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/edit.php"] [unique_id "al9N7oAs9lPxxVAErz3wIwAAAJs"]
[Tue Jul 21 07:46:06.258862 2026] [security2:error] [pid 296703:tid 296880] [client 20.206.105.145:56653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/edit.php"] [unique_id "al9N7in25uliftkV1n4VxAAAAC8"]
[Tue Jul 21 07:46:06.290505 2026] [security2:error] [pid 296703:tid 296952] [client 47.128.56.180:49084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "liranesuliano.com.br"] [uri "/robots.txt"] [unique_id "al9N7in25uliftkV1n4VxQAAAHc"]
[Tue Jul 21 07:46:06.566367 2026] [security2:error] [pid 296703:tid 296841] [client 223.236.153.128:1889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9N7in25uliftkV1n4VygAAAAg"]
[Tue Jul 21 07:46:06.568912 2026] [security2:error] [pid 296703:tid 296841] [client 223.236.153.128:1889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9N7in25uliftkV1n4VygAAAAg"]
[Tue Jul 21 07:46:06.781127 2026] [security2:error] [pid 302018:tid 302165] [client 20.104.96.117:44178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/config.json.php"] [unique_id "al9N7oAs9lPxxVAErz3wKAAAAJQ"]
[Tue Jul 21 07:46:06.811006 2026] [security2:error] [pid 302018:tid 302226] [client 20.197.195.24:16232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/hosty.php"] [unique_id "al9N7oAs9lPxxVAErz3wKQAAANE"]
[Tue Jul 21 07:46:07.371706 2026] [security2:error] [pid 302018:tid 302272] [client 122.186.204.214:50680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N74As9lPxxVAErz3wLAAAAP8"]
[Tue Jul 21 07:46:07.371856 2026] [security2:error] [pid 302018:tid 302272] [client 122.186.204.214:50680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N74As9lPxxVAErz3wLAAAAP8"]
[Tue Jul 21 07:46:07.380438 2026] [security2:error] [pid 302018:tid 302231] [client 117.247.80.59:32940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N74As9lPxxVAErz3wLQAAANY"]
[Tue Jul 21 07:46:07.380761 2026] [security2:error] [pid 302018:tid 302231] [client 117.247.80.59:32940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N74As9lPxxVAErz3wLQAAANY"]
[Tue Jul 21 07:46:07.581798 2026] [security2:error] [pid 302018:tid 302277] [client 20.104.96.117:44163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9N74As9lPxxVAErz3wMAAAAQQ"]
[Tue Jul 21 07:46:07.992427 2026] [security2:error] [pid 296703:tid 296918] [client 20.197.192.193:47219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9N7yn25uliftkV1n4V3gAAAFU"]
[Tue Jul 21 07:46:08.019059 2026] [security2:error] [pid 296703:tid 296873] [client 20.197.192.193:32538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9N8Cn25uliftkV1n4V4AAAACg"]
[Tue Jul 21 07:46:08.023359 2026] [security2:error] [pid 296703:tid 296894] [client 117.251.86.144:34096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9N8Cn25uliftkV1n4V4QAAAD0"]
[Tue Jul 21 07:46:08.023449 2026] [security2:error] [pid 296703:tid 296894] [client 117.251.86.144:34096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9N8Cn25uliftkV1n4V4QAAAD0"]
[Tue Jul 21 07:46:08.052122 2026] [security2:error] [pid 296703:tid 296934] [client 20.197.192.193:32561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/dp.php"] [unique_id "al9N8Cn25uliftkV1n4V4gAAAGU"]
[Tue Jul 21 07:46:08.061592 2026] [security2:error] [pid 296703:tid 296917] [client 20.197.195.24:18501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/k.php"] [unique_id "al9N8Cn25uliftkV1n4V4wAAAFQ"]
[Tue Jul 21 07:46:08.073575 2026] [security2:error] [pid 296703:tid 296926] [client 20.197.192.193:32530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/old.php"] [unique_id "al9N8Cn25uliftkV1n4V5AAAAF0"]
[Tue Jul 21 07:46:08.096021 2026] [security2:error] [pid 296703:tid 296959] [client 20.197.192.193:32542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ms-new.php"] [unique_id "al9N8Cn25uliftkV1n4V5wAAAH4"]
[Tue Jul 21 07:46:08.126692 2026] [security2:error] [pid 302018:tid 302186] [client 20.197.192.193:32532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/track.php"] [unique_id "al9N8IAs9lPxxVAErz3wOAAAAKk"]
[Tue Jul 21 07:46:08.148795 2026] [security2:error] [pid 302018:tid 302260] [client 193.37.33.173:36757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tofaseg.com.br"] [uri "/wp-login.php"] [unique_id "al9N74As9lPxxVAErz3wNQAAAPM"]
[Tue Jul 21 07:46:08.160366 2026] [security2:error] [pid 302018:tid 302166] [client 154.192.233.199:60345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N8IAs9lPxxVAErz3wOQAAAJU"]
[Tue Jul 21 07:46:08.160469 2026] [security2:error] [pid 302018:tid 302166] [client 154.192.233.199:60345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N8IAs9lPxxVAErz3wOQAAAJU"]
[Tue Jul 21 07:46:08.170341 2026] [security2:error] [pid 302018:tid 302197] [client 20.197.192.193:47222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/2352356666.php"] [unique_id "al9N8IAs9lPxxVAErz3wOgAAALQ"]
[Tue Jul 21 07:46:08.194272 2026] [core:error] [pid 302018:tid 302210] [client 66.249.66.73:50823] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:46:08.194295 2026] [core:error] [pid 302018:tid 302210] [client 66.249.66.73:50823] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:46:08.195774 2026] [security2:error] [pid 302018:tid 302228] [client 20.197.192.193:32543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/pn.php"] [unique_id "al9N8IAs9lPxxVAErz3wPQAAANM"]
[Tue Jul 21 07:46:08.277674 2026] [security2:error] [pid 302018:tid 302173] [client 20.197.192.193:47224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9N8IAs9lPxxVAErz3wPgAAAJw"]
[Tue Jul 21 07:46:08.317265 2026] [security2:error] [pid 302018:tid 302215] [client 20.197.192.193:47179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/dr.php"] [unique_id "al9N8IAs9lPxxVAErz3wPwAAAMY"]
[Tue Jul 21 07:46:08.409559 2026] [security2:error] [pid 296703:tid 296920] [client 20.104.96.117:44132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/k2.php"] [unique_id "al9N8Cn25uliftkV1n4V6wAAAFc"]
[Tue Jul 21 07:46:08.429948 2026] [security2:error] [pid 302018:tid 302274] [client 20.197.192.193:47168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/2x.php"] [unique_id "al9N8IAs9lPxxVAErz3wQQAAAQE"]
[Tue Jul 21 07:46:08.464430 2026] [security2:error] [pid 302018:tid 302229] [client 20.197.192.193:47175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/kq1.php"] [unique_id "al9N8IAs9lPxxVAErz3wQwAAANQ"]
[Tue Jul 21 07:46:08.502210 2026] [security2:error] [pid 296703:tid 296881] [client 20.197.192.193:32570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/zzz.php"] [unique_id "al9N8Cn25uliftkV1n4V7AAAADA"]
[Tue Jul 21 07:46:08.524415 2026] [security2:error] [pid 296703:tid 296913] [client 20.197.192.193:47203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wicked.php"] [unique_id "al9N8Cn25uliftkV1n4V7gAAAFA"]
[Tue Jul 21 07:46:08.549533 2026] [security2:error] [pid 296703:tid 296902] [client 20.197.192.193:47223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/edit.php"] [unique_id "al9N8Cn25uliftkV1n4V7wAAAEU"]
[Tue Jul 21 07:46:08.569907 2026] [security2:error] [pid 302018:tid 302223] [client 20.197.192.193:32549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/kua.php"] [unique_id "al9N8IAs9lPxxVAErz3wRgAAAM4"]
[Tue Jul 21 07:46:08.586513 2026] [security2:error] [pid 296703:tid 296955] [client 20.197.192.193:32537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ez.php"] [unique_id "al9N8Cn25uliftkV1n4V8QAAAHo"]
[Tue Jul 21 07:46:08.603246 2026] [security2:error] [pid 302018:tid 302161] [client 20.197.192.193:32533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/fz.php"] [unique_id "al9N8IAs9lPxxVAErz3wRwAAAJA"]
[Tue Jul 21 07:46:08.632663 2026] [security2:error] [pid 302018:tid 302151] [client 20.197.192.193:47184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/la.php"] [unique_id "al9N8IAs9lPxxVAErz3wSAAAAIY"]
[Tue Jul 21 07:46:08.657018 2026] [security2:error] [pid 302018:tid 302231] [client 20.197.192.193:32515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9N8IAs9lPxxVAErz3wSQAAANY"]
[Tue Jul 21 07:46:08.677334 2026] [security2:error] [pid 302018:tid 302261] [client 20.197.192.193:32531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/inso.php"] [unique_id "al9N8IAs9lPxxVAErz3wSgAAAPQ"]
[Tue Jul 21 07:46:08.695889 2026] [security2:error] [pid 302018:tid 302258] [client 20.197.192.193:32534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wpx.php"] [unique_id "al9N8IAs9lPxxVAErz3wTAAAAPE"]
[Tue Jul 21 07:46:08.721259 2026] [security2:error] [pid 302018:tid 302252] [client 20.206.105.145:56576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-content/admin.php"] [unique_id "al9N8IAs9lPxxVAErz3wTgAAAOs"]
[Tue Jul 21 07:46:08.725107 2026] [security2:error] [pid 296703:tid 296953] [client 20.197.192.193:32519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/berlin.php"] [unique_id "al9N8Cn25uliftkV1n4V8wAAAHg"]
[Tue Jul 21 07:46:08.747627 2026] [security2:error] [pid 296703:tid 296836] [client 20.197.192.193:47209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/billur.php"] [unique_id "al9N8Cn25uliftkV1n4V9AAAAAM"]
[Tue Jul 21 07:46:08.780863 2026] [security2:error] [pid 302018:tid 302202] [client 20.197.192.193:47195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/mimpi.php"] [unique_id "al9N8IAs9lPxxVAErz3wUAAAALk"]
[Tue Jul 21 07:46:08.814366 2026] [security2:error] [pid 302018:tid 302192] [client 20.197.192.193:33188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/dp.php"] [unique_id "al9N8IAs9lPxxVAErz3wUwAAAK8"]
[Tue Jul 21 07:46:08.842301 2026] [security2:error] [pid 302018:tid 302221] [client 20.197.192.193:47229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/bootstrap.php"] [unique_id "al9N8IAs9lPxxVAErz3wVAAAAMw"]
[Tue Jul 21 07:46:08.895041 2026] [security2:error] [pid 302018:tid 302181] [client 20.197.192.193:32520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-editor.php"] [unique_id "al9N8IAs9lPxxVAErz3wVQAAAKQ"]
[Tue Jul 21 07:46:08.943768 2026] [security2:error] [pid 302018:tid 302260] [client 20.197.192.193:33211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/cro.php"] [unique_id "al9N8IAs9lPxxVAErz3wVwAAAPM"]
[Tue Jul 21 07:46:08.983564 2026] [security2:error] [pid 302018:tid 302166] [client 20.197.192.193:47185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/cron-tab.php"] [unique_id "al9N8IAs9lPxxVAErz3wWAAAAJU"]
[Tue Jul 21 07:46:09.017873 2026] [security2:error] [pid 302018:tid 302172] [client 20.197.192.193:47196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/koiy.php"] [unique_id "al9N8YAs9lPxxVAErz3wWgAAAJs"]
[Tue Jul 21 07:46:09.057908 2026] [security2:error] [pid 296703:tid 296857] [client 20.197.195.24:16153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/aaa.php"] [unique_id "al9N8Sn25uliftkV1n4V-gAAABg"]
[Tue Jul 21 07:46:09.063090 2026] [security2:error] [pid 296703:tid 296954] [client 20.197.192.193:47198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/hp2.php"] [unique_id "al9N8Sn25uliftkV1n4V-wAAAHk"]
[Tue Jul 21 07:46:09.117562 2026] [security2:error] [pid 296703:tid 296781] [remote 20.84.23.218:6940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.23.84.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "revistareflexopolitico.com.br"] [uri "/wp-login.php"] [unique_id "al9N8Sn25uliftkV1n4V_AAAX00"]
[Tue Jul 21 07:46:09.119616 2026] [security2:error] [pid 302018:tid 302210] [client 20.197.192.193:32539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/hp3.php"] [unique_id "al9N8YAs9lPxxVAErz3wXAAAAME"]
[Tue Jul 21 07:46:09.130981 2026] [security2:error] [pid 302018:tid 302264] [client 20.104.96.117:44219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/uiuvs58l.php"] [unique_id "al9N8YAs9lPxxVAErz3wXQAAAPc"]
[Tue Jul 21 07:46:09.151981 2026] [security2:error] [pid 296703:tid 296855] [client 20.197.192.193:32551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/aa1.php"] [unique_id "al9N8Sn25uliftkV1n4V_QAAABY"]
[Tue Jul 21 07:46:09.218831 2026] [security2:error] [pid 296703:tid 296947] [client 20.197.192.193:32557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/acew67.php"] [unique_id "al9N8Sn25uliftkV1n4WAwAAAHI"]
[Tue Jul 21 07:46:09.267292 2026] [security2:error] [pid 302018:tid 302173] [client 20.197.192.193:33204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/bscclapb.php"] [unique_id "al9N8YAs9lPxxVAErz3wXgAAAJw"]
[Tue Jul 21 07:46:09.284176 2026] [security2:error] [pid 302018:tid 302215] [client 20.63.100.92:2480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/wp-editor.php"] [unique_id "al9N8YAs9lPxxVAErz3wXwAAAMY"]
[Tue Jul 21 07:46:09.298485 2026] [security2:error] [pid 302018:tid 302267] [client 20.197.192.193:33193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/else1.php"] [unique_id "al9N8YAs9lPxxVAErz3wYAAAAPo"]
[Tue Jul 21 07:46:09.312593 2026] [security2:error] [pid 302018:tid 302274] [client 20.197.192.193:32544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/tkikikoko.php"] [unique_id "al9N8YAs9lPxxVAErz3wYQAAAQE"]
[Tue Jul 21 07:46:09.337798 2026] [security2:error] [pid 302018:tid 302229] [client 20.197.192.193:32527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9N8YAs9lPxxVAErz3wYgAAANQ"]
[Tue Jul 21 07:46:09.382609 2026] [security2:error] [pid 296703:tid 296885] [client 20.197.192.193:33195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-css.php"] [unique_id "al9N8Sn25uliftkV1n4WBgAAADQ"]
[Tue Jul 21 07:46:09.424682 2026] [security2:error] [pid 296703:tid 296886] [client 20.206.105.145:29671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/f6.php"] [unique_id "al9N8Sn25uliftkV1n4WBwAAADU"]
[Tue Jul 21 07:46:09.428248 2026] [security2:error] [pid 296703:tid 296949] [client 20.197.192.193:47201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-explorer.php"] [unique_id "al9N8Sn25uliftkV1n4WCAAAAHQ"]
[Tue Jul 21 07:46:09.444241 2026] [security2:error] [pid 296703:tid 296849] [client 20.197.192.193:32529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/akismet.php"] [unique_id "al9N8Sn25uliftkV1n4WCQAAABA"]
[Tue Jul 21 07:46:09.467787 2026] [security2:error] [pid 296703:tid 296873] [client 20.197.192.193:47204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ace2.php"] [unique_id "al9N8Sn25uliftkV1n4WCgAAACg"]
[Tue Jul 21 07:46:09.516586 2026] [security2:error] [pid 302018:tid 302206] [client 20.197.192.193:32528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ms.php"] [unique_id "al9N8YAs9lPxxVAErz3wZQAAAL0"]
[Tue Jul 21 07:46:09.560979 2026] [security2:error] [pid 296703:tid 296851] [client 20.206.105.145:56690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/inputs.php"] [unique_id "al9N8Sn25uliftkV1n4WDAAAABI"]
[Tue Jul 21 07:46:09.636393 2026] [security2:error] [pid 302018:tid 302241] [client 136.144.33.101:23261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9N8YAs9lPxxVAErz3wZwAAAOA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:46:09.645918 2026] [security2:error] [pid 296703:tid 296950] [client 20.197.195.24:16245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/file5.php"] [unique_id "al9N8Sn25uliftkV1n4WDwAAAHU"]
[Tue Jul 21 07:46:09.880453 2026] [security2:error] [pid 302018:tid 302181] [client 20.104.96.117:44287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/40p9ixjd.php"] [unique_id "al9N8YAs9lPxxVAErz3wdgAAAKQ"]
[Tue Jul 21 07:46:10.010311 2026] [security2:error] [pid 302018:tid 302197] [client 20.197.195.24:16181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/222.php"] [unique_id "al9N8oAs9lPxxVAErz3weQAAALQ"]
[Tue Jul 21 07:46:10.038647 2026] [security2:error] [pid 302018:tid 302210] [client 20.104.96.117:46696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/aa.php"] [unique_id "al9N8oAs9lPxxVAErz3wegAAAME"]
[Tue Jul 21 07:46:10.044976 2026] [security2:error] [pid 296703:tid 296942] [client 131.226.101.54:39628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.101.226.131.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guilhermeverissimo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N8in25uliftkV1n4WHQAAAG0"]
[Tue Jul 21 07:46:10.045150 2026] [security2:error] [pid 296703:tid 296942] [client 131.226.101.54:39628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "guilhermeverissimo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N8in25uliftkV1n4WHQAAAG0"]
[Tue Jul 21 07:46:10.457909 2026] [security2:error] [pid 296703:tid 296944] [client 20.197.195.24:16196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/test.php"] [unique_id "al9N8in25uliftkV1n4WJQAAAG8"]
[Tue Jul 21 07:46:10.537243 2026] [security2:error] [pid 302018:tid 302274] [client 20.151.10.161:44013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9N8oAs9lPxxVAErz3wfgAAAQE"]
[Tue Jul 21 07:46:10.686520 2026] [security2:error] [pid 302018:tid 302206] [client 20.206.105.145:56648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/inputs.php"] [unique_id "al9N8oAs9lPxxVAErz3wgwAAAL0"]
[Tue Jul 21 07:46:10.923346 2026] [security2:error] [pid 302018:tid 302272] [client 20.63.100.92:2141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/cro.php"] [unique_id "al9N8oAs9lPxxVAErz3wiQAAAP8"]
[Tue Jul 21 07:46:11.103070 2026] [security2:error] [pid 302018:tid 302234] [client 59.96.220.140:51737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9N84As9lPxxVAErz3wjwAAANk"]
[Tue Jul 21 07:46:11.103773 2026] [security2:error] [pid 302018:tid 302234] [client 59.96.220.140:51737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9N84As9lPxxVAErz3wjwAAANk"]
[Tue Jul 21 07:46:11.201407 2026] [access_compat:error] [pid 302018:tid 302184] [client 45.76.80.124:44475] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-admin/admin-ajax.php, referer: https://swingcuiaba.com.br/
[Tue Jul 21 07:46:11.212068 2026] [security2:error] [pid 302018:tid 302137] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N84As9lPxxVAErz3wkgAA4HQ"]
[Tue Jul 21 07:46:11.212191 2026] [security2:error] [pid 302018:tid 302241] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N84As9lPxxVAErz3wkgAA4HQ"]
[Tue Jul 21 07:46:11.320770 2026] [security2:error] [pid 302018:tid 302277] [client 20.104.96.117:44113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/uiuvs58l.update.php"] [unique_id "al9N84As9lPxxVAErz3wlgAAAQQ"]
[Tue Jul 21 07:46:11.545776 2026] [security2:error] [pid 302018:tid 302186] [client 20.197.195.24:16233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/aaa.php"] [unique_id "al9N84As9lPxxVAErz3wmgAAAKk"]
[Tue Jul 21 07:46:11.557772 2026] [security2:error] [pid 302018:tid 302164] [client 20.151.10.161:44021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9N84As9lPxxVAErz3wmwAAAJM"]
[Tue Jul 21 07:46:11.696063 2026] [security2:error] [pid 296703:tid 296864] [client 103.29.114.44:50821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N8yn25uliftkV1n4WNQAAAB8"]
[Tue Jul 21 07:46:11.696229 2026] [security2:error] [pid 296703:tid 296864] [client 103.29.114.44:50821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N8yn25uliftkV1n4WNQAAAB8"]
[Tue Jul 21 07:46:11.733314 2026] [security2:error] [pid 302018:tid 302264] [client 141.11.107.74:54955] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.sejabarbara.com.br"] [uri "/"] [unique_id "al9N84As9lPxxVAErz3woAAAAPc"]
[Tue Jul 21 07:46:11.835398 2026] [security2:error] [pid 302018:tid 302221] [client 173.24.185.52:49256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9N84As9lPxxVAErz3wowAAAMw"]
[Tue Jul 21 07:46:11.835499 2026] [security2:error] [pid 302018:tid 302221] [client 173.24.185.52:49256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9N84As9lPxxVAErz3wowAAAMw"]
[Tue Jul 21 07:46:11.836181 2026] [security2:error] [pid 302018:tid 302121] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9N84As9lPxxVAErz3wogAAz2Q"]
[Tue Jul 21 07:46:11.836346 2026] [security2:error] [pid 302018:tid 302224] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9N84As9lPxxVAErz3wogAAz2Q"]
[Tue Jul 21 07:46:11.858379 2026] [security2:error] [pid 302018:tid 302113] [remote 141.11.107.74:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.sejabarbara.com.br"] [uri "/"] [unique_id "al9N84As9lPxxVAErz3wpwAAwFw"], referer: http://autodiscover.sejabarbara.com.br
[Tue Jul 21 07:46:11.879298 2026] [security2:error] [pid 302018:tid 302129] [remote 141.11.107.74:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.sejabarbara.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9N84As9lPxxVAErz3wqAAAsWw"], referer: http://webdisk.sejabarbara.com.br
[Tue Jul 21 07:46:11.915834 2026] [security2:error] [pid 296703:tid 296708] [remote 141.11.107.74:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "sejabarbara.com.br"] [uri "/"] [unique_id "al9N8yn25uliftkV1n4WOgAAKAQ"], referer: http://sejabarbara.com.br
[Tue Jul 21 07:46:11.925102 2026] [security2:error] [pid 302018:tid 302222] [client 139.167.225.182:63261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N84As9lPxxVAErz3wqQAAAM0"]
[Tue Jul 21 07:46:11.925244 2026] [security2:error] [pid 302018:tid 302222] [client 139.167.225.182:63261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N84As9lPxxVAErz3wqQAAAM0"]
[Tue Jul 21 07:46:11.926797 2026] [security2:error] [pid 302018:tid 302093] [remote 65.111.14.197:51403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.14.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9N84As9lPxxVAErz3woQAArEg"]
[Tue Jul 21 07:46:11.951306 2026] [security2:error] [pid 302018:tid 302248] [client 20.104.96.117:44873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/for.php"] [unique_id "al9N84As9lPxxVAErz3wrQAAAOc"]
[Tue Jul 21 07:46:11.964077 2026] [security2:error] [pid 296703:tid 296779] [remote 141.11.107.74:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.sejabarbara.com.br"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "al9N8yn25uliftkV1n4WOwAAPUs"], referer: http://cpcalendars.sejabarbara.com.br
[Tue Jul 21 07:46:11.982630 2026] [security2:error] [pid 302018:tid 302032] [remote 141.11.107.74:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.sejabarbara.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9N84As9lPxxVAErz3wrgAAsgs"], referer: http://cpcontacts.sejabarbara.com.br
[Tue Jul 21 07:46:11.991153 2026] [security2:error] [pid 302018:tid 302145] [remote 141.11.107.74:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.sejabarbara.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9N84As9lPxxVAErz3wrwAAxnw"], referer: http://cpanel.sejabarbara.com.br
[Tue Jul 21 07:46:12.053256 2026] [security2:error] [pid 302018:tid 302030] [remote 141.11.107.74:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.sejabarbara.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9N9IAs9lPxxVAErz3wsQAAogk"], referer: http://webmail.sejabarbara.com.br
[Tue Jul 21 07:46:12.109134 2026] [security2:error] [pid 302018:tid 302234] [client 20.206.105.145:56666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/av.php"] [unique_id "al9N9IAs9lPxxVAErz3wswAAANk"]
[Tue Jul 21 07:46:12.303861 2026] [security2:error] [pid 302018:tid 302034] [remote 142.93.10.93:44436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9N9IAs9lPxxVAErz3wtQAAoA0"]
[Tue Jul 21 07:46:12.304054 2026] [security2:error] [pid 302018:tid 302177] [client 142.93.10.93:44436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9N9IAs9lPxxVAErz3wtQAAoA0"]
[Tue Jul 21 07:46:12.318758 2026] [security2:error] [pid 302018:tid 302241] [client 20.151.10.161:44000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/x.php"] [unique_id "al9N9IAs9lPxxVAErz3wtgAAAOA"]
[Tue Jul 21 07:46:12.383190 2026] [security2:error] [pid 302018:tid 302125] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N9IAs9lPxxVAErz3wuQAA9mg"]
[Tue Jul 21 07:46:12.383392 2026] [security2:error] [pid 302018:tid 302263] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N9IAs9lPxxVAErz3wuQAA9mg"]
[Tue Jul 21 07:46:12.400431 2026] [security2:error] [pid 302018:tid 302246] [client 152.59.154.239:63987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N9IAs9lPxxVAErz3wugAAAOU"]
[Tue Jul 21 07:46:12.400524 2026] [security2:error] [pid 302018:tid 302246] [client 152.59.154.239:63987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N9IAs9lPxxVAErz3wugAAAOU"]
[Tue Jul 21 07:46:12.593962 2026] [security2:error] [pid 296703:tid 296849] [client 122.179.91.63:27985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9N9Cn25uliftkV1n4WQgAAABA"]
[Tue Jul 21 07:46:12.594454 2026] [security2:error] [pid 296703:tid 296849] [client 122.179.91.63:27985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9N9Cn25uliftkV1n4WQgAAABA"]
[Tue Jul 21 07:46:12.601583 2026] [security2:error] [pid 302018:tid 302255] [client 20.104.96.117:44097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/raw.php"] [unique_id "al9N9IAs9lPxxVAErz3wvwAAAO4"]
[Tue Jul 21 07:46:12.708416 2026] [security2:error] [pid 296703:tid 296854] [client 122.162.144.145:18339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9N9Cn25uliftkV1n4WRwAAABU"]
[Tue Jul 21 07:46:12.708596 2026] [security2:error] [pid 296703:tid 296854] [client 122.162.144.145:18339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9N9Cn25uliftkV1n4WRwAAABU"]
[Tue Jul 21 07:46:12.842217 2026] [security2:error] [pid 302018:tid 302212] [client 154.208.47.43:50847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9N9IAs9lPxxVAErz3wxAAAAMM"]
[Tue Jul 21 07:46:12.842355 2026] [security2:error] [pid 302018:tid 302212] [client 154.208.47.43:50847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9N9IAs9lPxxVAErz3wxAAAAMM"]
[Tue Jul 21 07:46:13.034615 2026] [security2:error] [pid 296703:tid 296913] [client 20.151.10.161:43973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/j260624_13.php"] [unique_id "al9N9Sn25uliftkV1n4WTAAAAFA"]
[Tue Jul 21 07:46:13.054987 2026] [security2:error] [pid 302018:tid 302252] [client 202.143.127.214:59157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N9YAs9lPxxVAErz3wxwAAAOs"]
[Tue Jul 21 07:46:13.055150 2026] [security2:error] [pid 302018:tid 302252] [client 202.143.127.214:59157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N9YAs9lPxxVAErz3wxwAAAOs"]
[Tue Jul 21 07:46:13.280555 2026] [security2:error] [pid 302018:tid 302161] [client 193.36.225.63:40057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9N9YAs9lPxxVAErz3wyQAAAJA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:46:13.578353 2026] [security2:error] [pid 302018:tid 302226] [client 20.206.105.145:56614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/classwithtostring.php"] [unique_id "al9N9YAs9lPxxVAErz3wzQAAANE"]
[Tue Jul 21 07:46:13.588323 2026] [security2:error] [pid 302018:tid 302259] [client 178.153.91.96:55006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9N9YAs9lPxxVAErz3wzgAAAPI"]
[Tue Jul 21 07:46:13.588481 2026] [security2:error] [pid 302018:tid 302259] [client 178.153.91.96:55006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9N9YAs9lPxxVAErz3wzgAAAPI"]
[Tue Jul 21 07:46:13.653350 2026] [security2:error] [pid 296703:tid 296881] [client 182.8.255.181:17665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9N9Sn25uliftkV1n4WVgAAADA"]
[Tue Jul 21 07:46:13.653494 2026] [security2:error] [pid 296703:tid 296881] [client 182.8.255.181:17665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9N9Sn25uliftkV1n4WVgAAADA"]
[Tue Jul 21 07:46:13.690411 2026] [security2:error] [pid 302018:tid 302209] [client 103.86.117.203:64900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N9YAs9lPxxVAErz3w0AAAAMA"]
[Tue Jul 21 07:46:13.690540 2026] [security2:error] [pid 302018:tid 302209] [client 103.86.117.203:64900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N9YAs9lPxxVAErz3w0AAAAMA"]
[Tue Jul 21 07:46:13.992858 2026] [security2:error] [pid 296703:tid 296954] [client 20.151.10.161:44022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/d62.php"] [unique_id "al9N9Sn25uliftkV1n4WXQAAAHk"]
[Tue Jul 21 07:46:14.076919 2026] [autoindex:error] [pid 302018:tid 302277] [client 198.235.24.135:60666] AH01276: Cannot serve directory /home2/reser379/megaroteiros.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:46:14.333445 2026] [security2:error] [pid 296703:tid 296879] [client 103.166.103.129:51584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9N9in25uliftkV1n4WYAAAAC4"]
[Tue Jul 21 07:46:14.333567 2026] [security2:error] [pid 296703:tid 296879] [client 103.166.103.129:51584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9N9in25uliftkV1n4WYAAAAC4"]
[Tue Jul 21 07:46:14.609017 2026] [security2:error] [pid 302018:tid 302238] [client 20.206.105.145:56661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-content/themes/index.php"] [unique_id "al9N9oAs9lPxxVAErz3w4wAAAN0"]
[Tue Jul 21 07:46:14.824667 2026] [security2:error] [pid 302018:tid 302241] [client 106.215.181.8:25690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N9oAs9lPxxVAErz3w6AAAAOA"]
[Tue Jul 21 07:46:14.824776 2026] [security2:error] [pid 302018:tid 302241] [client 106.215.181.8:25690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N9oAs9lPxxVAErz3w6AAAAOA"]
[Tue Jul 21 07:46:14.859515 2026] [security2:error] [pid 302018:tid 302071] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9N9oAs9lPxxVAErz3w6gAAmzI"]
[Tue Jul 21 07:46:14.859640 2026] [security2:error] [pid 302018:tid 302172] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9N9oAs9lPxxVAErz3w6gAAmzI"]
[Tue Jul 21 07:46:14.893177 2026] [security2:error] [pid 296703:tid 296747] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N9in25uliftkV1n4WZwAAcCs"]
[Tue Jul 21 07:46:14.893319 2026] [security2:error] [pid 296703:tid 296945] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N9in25uliftkV1n4WZwAAcCs"]
[Tue Jul 21 07:46:14.937435 2026] [security2:error] [pid 302018:tid 302223] [client 20.151.10.161:43947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/ups.php"] [unique_id "al9N9oAs9lPxxVAErz3w7AAAAM4"]
[Tue Jul 21 07:46:15.048635 2026] [security2:error] [pid 296703:tid 296736] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9N9yn25uliftkV1n4WagAAHiA"]
[Tue Jul 21 07:46:15.048780 2026] [security2:error] [pid 296703:tid 296863] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9N9yn25uliftkV1n4WagAAHiA"]
[Tue Jul 21 07:46:15.136480 2026] [security2:error] [pid 302018:tid 302059] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N94As9lPxxVAErz3w8QAAoCY"]
[Tue Jul 21 07:46:15.136604 2026] [security2:error] [pid 302018:tid 302177] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N94As9lPxxVAErz3w8QAAoCY"]
[Tue Jul 21 07:46:15.437448 2026] [security2:error] [pid 302018:tid 302247] [client 20.206.105.145:56579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-blog.php"] [unique_id "al9N94As9lPxxVAErz3w9gAAAOY"]
[Tue Jul 21 07:46:15.484776 2026] [security2:error] [pid 296703:tid 296869] [client 37.140.223.163:65251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9N9yn25uliftkV1n4WbwAAACQ"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:46:15.772547 2026] [security2:error] [pid 302018:tid 302191] [client 20.151.10.161:44015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/k.php"] [unique_id "al9N94As9lPxxVAErz3w-wAAAK4"]
[Tue Jul 21 07:46:16.032939 2026] [security2:error] [pid 296703:tid 296859] [client 20.197.195.24:16130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/11.php"] [unique_id "al9N-Cn25uliftkV1n4WfQAAABo"]
[Tue Jul 21 07:46:16.090068 2026] [security2:error] [pid 296703:tid 296814] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9N-Cn25uliftkV1n4WgQAAem4"]
[Tue Jul 21 07:46:16.090243 2026] [security2:error] [pid 296703:tid 296955] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9N-Cn25uliftkV1n4WgQAAem4"]
[Tue Jul 21 07:46:16.188425 2026] [security2:error] [pid 296703:tid 296926] [client 122.164.127.47:50709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9N-Cn25uliftkV1n4WggAAAF0"]
[Tue Jul 21 07:46:16.189114 2026] [security2:error] [pid 296703:tid 296926] [client 122.164.127.47:50709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9N-Cn25uliftkV1n4WggAAAF0"]
[Tue Jul 21 07:46:16.504010 2026] [security2:error] [pid 302018:tid 302222] [client 41.68.90.219:51780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N-IAs9lPxxVAErz3xAwAAAM0"]
[Tue Jul 21 07:46:16.504404 2026] [security2:error] [pid 302018:tid 302221] [client 117.217.38.194:60394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N-IAs9lPxxVAErz3xBAAAAMw"]
[Tue Jul 21 07:46:16.504517 2026] [security2:error] [pid 302018:tid 302221] [client 117.217.38.194:60394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N-IAs9lPxxVAErz3xBAAAAMw"]
[Tue Jul 21 07:46:16.505119 2026] [security2:error] [pid 302018:tid 302222] [client 41.68.90.219:51780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N-IAs9lPxxVAErz3xAwAAAM0"]
[Tue Jul 21 07:46:16.633699 2026] [security2:error] [pid 302018:tid 302189] [client 103.174.34.15:50336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N-IAs9lPxxVAErz3xBwAAAKw"]
[Tue Jul 21 07:46:16.633836 2026] [security2:error] [pid 302018:tid 302189] [client 103.174.34.15:50336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N-IAs9lPxxVAErz3xBwAAAKw"]
[Tue Jul 21 07:46:16.807884 2026] [security2:error] [pid 302018:tid 302165] [client 20.151.10.161:43981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/k2.php"] [unique_id "al9N-IAs9lPxxVAErz3xCQAAAJQ"]
[Tue Jul 21 07:46:17.117160 2026] [security2:error] [pid 296703:tid 296925] [client 20.206.105.145:56697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-content/admin.php"] [unique_id "al9N-Sn25uliftkV1n4WlAAAAFw"]
[Tue Jul 21 07:46:17.169070 2026] [security2:error] [pid 302018:tid 302248] [client 223.236.153.128:4836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9N-YAs9lPxxVAErz3xDwAAAOc"]
[Tue Jul 21 07:46:17.169182 2026] [security2:error] [pid 302018:tid 302248] [client 223.236.153.128:4836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9N-YAs9lPxxVAErz3xDwAAAOc"]
[Tue Jul 21 07:46:17.242783 2026] [security2:error] [pid 302018:tid 302081] [remote 20.153.140.50:39814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rqracademy.com"] [uri "/wp-login.php"] [unique_id "al9N-YAs9lPxxVAErz3xEAAA0jw"]
[Tue Jul 21 07:46:17.301032 2026] [security2:error] [pid 302018:tid 302163] [client 74.7.241.156:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "leandronogueiramarti1753727208000.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9N-YAs9lPxxVAErz3xEgAAkhM"]
[Tue Jul 21 07:46:17.405963 2026] [security2:error] [pid 302018:tid 302194] [client 20.206.105.145:56658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/adminfuns.php"] [unique_id "al9N-YAs9lPxxVAErz3xEwAAALE"]
[Tue Jul 21 07:46:17.516554 2026] [security2:error] [pid 302018:tid 302172] [client 20.104.96.117:46715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/xwpg.php"] [unique_id "al9N-YAs9lPxxVAErz3xFgAAAJs"]
[Tue Jul 21 07:46:17.636034 2026] [security2:error] [pid 302018:tid 302067] [remote 207.46.13.7:48653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertinhoimoveis.com.br"] [uri "/video.php/card991/jogo-hoje-ao-vivo/"] [unique_id "al9N-YAs9lPxxVAErz3xFQAA-y4"]
[Tue Jul 21 07:46:17.650063 2026] [security2:error] [pid 296703:tid 296899] [client 20.151.10.161:43986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/k3.php"] [unique_id "al9N-Sn25uliftkV1n4WmwAAAEI"]
[Tue Jul 21 07:46:17.733597 2026] [security2:error] [pid 302018:tid 302161] [client 136.144.33.239:36875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9N-YAs9lPxxVAErz3xFwAAAJA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:46:17.909657 2026] [security2:error] [pid 296703:tid 296837] [client 172.245.102.42:29093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9N-Sn25uliftkV1n4WnQAAAAQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:46:17.974210 2026] [security2:error] [pid 302018:tid 302184] [client 20.206.105.145:56685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/goods.php"] [unique_id "al9N-YAs9lPxxVAErz3xIQAAAKc"]
[Tue Jul 21 07:46:18.036611 2026] [security2:error] [pid 302018:tid 302267] [client 122.186.204.214:51220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N-oAs9lPxxVAErz3xIgAAAPo"]
[Tue Jul 21 07:46:18.040768 2026] [security2:error] [pid 302018:tid 302267] [client 122.186.204.214:51220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9N-oAs9lPxxVAErz3xIgAAAPo"]
[Tue Jul 21 07:46:18.057426 2026] [security2:error] [pid 296703:tid 296864] [client 117.247.80.59:27053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N-in25uliftkV1n4WogAAAB8"]
[Tue Jul 21 07:46:18.057551 2026] [security2:error] [pid 296703:tid 296864] [client 117.247.80.59:27053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N-in25uliftkV1n4WogAAAB8"]
[Tue Jul 21 07:46:18.750760 2026] [security2:error] [pid 302018:tid 302171] [client 117.251.86.144:37916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9N-oAs9lPxxVAErz3xLwAAAJo"]
[Tue Jul 21 07:46:18.750940 2026] [security2:error] [pid 302018:tid 302171] [client 117.251.86.144:37916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9N-oAs9lPxxVAErz3xLwAAAJo"]
[Tue Jul 21 07:46:18.869337 2026] [security2:error] [pid 302018:tid 302214] [client 154.192.233.199:60065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N-oAs9lPxxVAErz3xMAAAAMU"]
[Tue Jul 21 07:46:18.869458 2026] [security2:error] [pid 302018:tid 302214] [client 154.192.233.199:60065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N-oAs9lPxxVAErz3xMAAAAMU"]
[Tue Jul 21 07:46:19.139097 2026] [security2:error] [pid 296703:tid 296827] [remote 41.76.214.143:40152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9N-yn25uliftkV1n4WsgAAbns"]
[Tue Jul 21 07:46:19.415318 2026] [security2:error] [pid 296703:tid 296859] [client 20.206.105.145:56624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/ms-edit.php"] [unique_id "al9N-yn25uliftkV1n4WtAAAABo"]
[Tue Jul 21 07:46:19.482045 2026] [security2:error] [pid 296703:tid 296893] [client 20.151.10.161:43990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/k4.php"] [unique_id "al9N-yn25uliftkV1n4WtgAAADw"]
[Tue Jul 21 07:46:19.527438 2026] [core:error] [pid 302018:tid 302075] [remote 40.77.167.10:40900] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:46:19.527470 2026] [core:error] [pid 302018:tid 302075] [remote 40.77.167.10:40900] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:46:19.766557 2026] [security2:error] [pid 302018:tid 302221] [client 20.197.195.24:16171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/mac.php"] [unique_id "al9N-4As9lPxxVAErz3xNgAAAMw"]
[Tue Jul 21 07:46:20.030077 2026] [security2:error] [pid 302018:tid 302194] [client 59.96.220.140:52264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9N_IAs9lPxxVAErz3xOwAAALE"]
[Tue Jul 21 07:46:20.030205 2026] [security2:error] [pid 302018:tid 302194] [client 59.96.220.140:52264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9N_IAs9lPxxVAErz3xOwAAALE"]
[Tue Jul 21 07:46:20.356049 2026] [security2:error] [pid 302018:tid 302234] [client 20.104.96.117:46610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/ops.php"] [unique_id "al9N_IAs9lPxxVAErz3xQAAAANk"]
[Tue Jul 21 07:46:20.531522 2026] [security2:error] [pid 302018:tid 302223] [client 20.206.105.145:56593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/222.php"] [unique_id "al9N_IAs9lPxxVAErz3xQQAAAM4"]
[Tue Jul 21 07:46:20.886272 2026] [security2:error] [pid 296703:tid 296838] [client 184.75.223.211:43030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9N_Cn25uliftkV1n4WzgAAAAU"]
[Tue Jul 21 07:46:20.886406 2026] [security2:error] [pid 296703:tid 296838] [client 184.75.223.211:43030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9N_Cn25uliftkV1n4WzgAAAAU"]
[Tue Jul 21 07:46:21.158505 2026] [security2:error] [pid 302018:tid 302193] [client 20.206.105.145:56615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/cgi-bin/index.php"] [unique_id "al9N_YAs9lPxxVAErz3xSgAAALA"]
[Tue Jul 21 07:46:21.184472 2026] [security2:error] [pid 302018:tid 302210] [client 45.8.19.158:63587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeireirapiske.com.br"] [uri "/wp-login.php"] [unique_id "al9N_YAs9lPxxVAErz3xTAAAAME"]
[Tue Jul 21 07:46:21.547039 2026] [security2:error] [pid 296703:tid 296935] [client 136.144.33.109:47057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9N_Sn25uliftkV1n4W2AAAAGY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:46:21.747984 2026] [security2:error] [pid 296703:tid 296808] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N_Sn25uliftkV1n4W3wAAAWg"]
[Tue Jul 21 07:46:21.748145 2026] [security2:error] [pid 296703:tid 296834] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N_Sn25uliftkV1n4W3wAAAWg"]
[Tue Jul 21 07:46:21.922650 2026] [security2:error] [pid 296703:tid 296881] [client 128.127.105.184:36654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9N_Sn25uliftkV1n4W5AAAADA"]
[Tue Jul 21 07:46:21.922757 2026] [security2:error] [pid 296703:tid 296881] [client 128.127.105.184:36654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9N_Sn25uliftkV1n4W5AAAADA"]
[Tue Jul 21 07:46:21.951716 2026] [security2:error] [pid 302018:tid 302226] [client 20.197.195.24:16178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/chosen.php"] [unique_id "al9N_YAs9lPxxVAErz3xYgAAANE"]
[Tue Jul 21 07:46:22.380703 2026] [security2:error] [pid 302018:tid 302176] [client 103.29.114.44:46004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N_oAs9lPxxVAErz3xaQAAAJ8"]
[Tue Jul 21 07:46:22.380836 2026] [security2:error] [pid 302018:tid 302176] [client 103.29.114.44:46004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N_oAs9lPxxVAErz3xaQAAAJ8"]
[Tue Jul 21 07:46:22.407415 2026] [security2:error] [pid 296703:tid 296941] [client 20.151.10.161:44004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/k5.php"] [unique_id "al9N_in25uliftkV1n4W6wAAAGw"]
[Tue Jul 21 07:46:22.438624 2026] [security2:error] [pid 302018:tid 302223] [client 173.24.185.52:64956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9N_oAs9lPxxVAErz3xagAAAM4"]
[Tue Jul 21 07:46:22.438717 2026] [security2:error] [pid 302018:tid 302223] [client 173.24.185.52:64956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9N_oAs9lPxxVAErz3xagAAAM4"]
[Tue Jul 21 07:46:22.477884 2026] [security2:error] [pid 302018:tid 302095] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9N_oAs9lPxxVAErz3xbAAAvEo"]
[Tue Jul 21 07:46:22.478083 2026] [security2:error] [pid 302018:tid 302205] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9N_oAs9lPxxVAErz3xbAAAvEo"]
[Tue Jul 21 07:46:22.483631 2026] [security2:error] [pid 296703:tid 296844] [client 139.167.225.182:63906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N_in25uliftkV1n4W7QAAAAs"]
[Tue Jul 21 07:46:22.483716 2026] [security2:error] [pid 296703:tid 296844] [client 139.167.225.182:63906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N_in25uliftkV1n4W7QAAAAs"]
[Tue Jul 21 07:46:22.561208 2026] [security2:error] [pid 302018:tid 302164] [client 20.104.96.117:46617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/mac.php"] [unique_id "al9N_oAs9lPxxVAErz3xbwAAAJM"]
[Tue Jul 21 07:46:22.634526 2026] [security2:error] [pid 296703:tid 296818] [remote 51.75.236.139:36860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dscbrasil.com.br"] [uri "/robots.txt"] [unique_id "al9N_in25uliftkV1n4W8AAATXI"]
[Tue Jul 21 07:46:22.634783 2026] [security2:error] [pid 296703:tid 296910] [client 51.75.236.139:36860] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dscbrasil.com.br"] [uri "/robots.txt"] [unique_id "al9N_in25uliftkV1n4W8AAATXI"]
[Tue Jul 21 07:46:22.886402 2026] [security2:error] [pid 302018:tid 302197] [client 20.206.105.145:56603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/BDKR28WP.php"] [unique_id "al9N_oAs9lPxxVAErz3xcwAAALQ"]
[Tue Jul 21 07:46:22.891713 2026] [security2:error] [pid 296703:tid 296906] [client 20.197.195.24:16151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/cream1.php"] [unique_id "al9N_in25uliftkV1n4W-AAAAEk"]
[Tue Jul 21 07:46:22.962649 2026] [security2:error] [pid 296703:tid 296833] [client 20.63.100.92:6022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/cron-tab.php"] [unique_id "al9N_in25uliftkV1n4W-gAAAAA"]
[Tue Jul 21 07:46:23.016236 2026] [security2:error] [pid 302018:tid 302169] [client 74.7.244.22:41114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "professoraclaudiaaguiar.com.br"] [uri "/index.php"] [unique_id "al9N_oAs9lPxxVAErz3xawAAmHo"]
[Tue Jul 21 07:46:23.148358 2026] [security2:error] [pid 302018:tid 302189] [client 152.59.154.239:64485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N_4As9lPxxVAErz3xeAAAAKw"]
[Tue Jul 21 07:46:23.148485 2026] [security2:error] [pid 302018:tid 302189] [client 152.59.154.239:64485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N_4As9lPxxVAErz3xeAAAAKw"]
[Tue Jul 21 07:46:23.155610 2026] [security2:error] [pid 296703:tid 296954] [client 182.8.255.181:2903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9N_yn25uliftkV1n4W-wAAAHk"]
[Tue Jul 21 07:46:23.155885 2026] [security2:error] [pid 296703:tid 296954] [client 182.8.255.181:2903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9N_yn25uliftkV1n4W-wAAAHk"]
[Tue Jul 21 07:46:23.295777 2026] [security2:error] [pid 302018:tid 302154] [client 154.208.47.43:51298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9N_4As9lPxxVAErz3xfAAAAIk"]
[Tue Jul 21 07:46:23.295917 2026] [security2:error] [pid 302018:tid 302154] [client 154.208.47.43:51298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9N_4As9lPxxVAErz3xfAAAAIk"]
[Tue Jul 21 07:46:23.318531 2026] [security2:error] [pid 302018:tid 302172] [client 20.104.96.117:46674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/mg.php"] [unique_id "al9N_4As9lPxxVAErz3xfwAAAJs"]
[Tue Jul 21 07:46:23.393699 2026] [security2:error] [pid 302018:tid 302124] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N_4As9lPxxVAErz3xgAAA1Gc"]
[Tue Jul 21 07:46:23.393881 2026] [security2:error] [pid 302018:tid 302229] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9N_4As9lPxxVAErz3xgAAA1Gc"]
[Tue Jul 21 07:46:23.444385 2026] [security2:error] [pid 302018:tid 302183] [client 193.36.225.140:28559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9N_YAs9lPxxVAErz3xUgAAAKY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:46:23.544098 2026] [security2:error] [pid 296703:tid 296871] [client 122.162.144.145:32287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9N_yn25uliftkV1n4XAwAAACY"]
[Tue Jul 21 07:46:23.544240 2026] [security2:error] [pid 296703:tid 296871] [client 122.162.144.145:32287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9N_yn25uliftkV1n4XAwAAACY"]
[Tue Jul 21 07:46:23.550014 2026] [security2:error] [pid 296703:tid 296949] [client 20.206.105.145:29673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/raw.php"] [unique_id "al9N_yn25uliftkV1n4XBAAAAHQ"]
[Tue Jul 21 07:46:23.856789 2026] [security2:error] [pid 296703:tid 296894] [client 20.63.100.92:2771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/koiy.php"] [unique_id "al9N_yn25uliftkV1n4XCQAAAD0"]
[Tue Jul 21 07:46:24.130264 2026] [security2:error] [pid 296703:tid 296847] [client 178.153.91.96:55560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OACn25uliftkV1n4XDAAAAA4"]
[Tue Jul 21 07:46:24.130428 2026] [security2:error] [pid 296703:tid 296847] [client 178.153.91.96:55560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OACn25uliftkV1n4XDAAAAA4"]
[Tue Jul 21 07:46:24.175805 2026] [security2:error] [pid 296703:tid 296868] [client 103.86.117.203:65444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OACn25uliftkV1n4XDQAAACM"]
[Tue Jul 21 07:46:24.175985 2026] [security2:error] [pid 296703:tid 296868] [client 103.86.117.203:65444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OACn25uliftkV1n4XDQAAACM"]
[Tue Jul 21 07:46:24.176603 2026] [security2:error] [pid 296703:tid 296903] [client 89.124.113.107:49598] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.113.107" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "ullissessabinooficial.com"] [uri "/wp-comments-post.php"] [unique_id "al9OACn25uliftkV1n4XDgAAAEY"], referer: https://ullissessabinooficial.com/hello-world/
[Tue Jul 21 07:46:24.176687 2026] [security2:error] [pid 296703:tid 296903] [client 89.124.113.107:49598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "ullissessabinooficial.com"] [uri "/wp-comments-post.php"] [unique_id "al9OACn25uliftkV1n4XDgAAAEY"], referer: https://ullissessabinooficial.com/hello-world/
[Tue Jul 21 07:46:24.211131 2026] [fcgid:warn] [pid 296703:tid 296953] (70014)End of file found: [client 66.132.195.108:61164] mod_fcgid: can't get data from http client
[Tue Jul 21 07:46:24.226764 2026] [security2:error] [pid 302018:tid 302118] [remote 54.39.0.165:63680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dscbrasil.com.br"] [uri "/products"] [unique_id "al9OAIAs9lPxxVAErz3xjQAAnGE"]
[Tue Jul 21 07:46:24.226948 2026] [security2:error] [pid 302018:tid 302173] [client 54.39.0.165:63680] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dscbrasil.com.br"] [uri "/products"] [unique_id "al9OAIAs9lPxxVAErz3xjQAAnGE"]
[Tue Jul 21 07:46:24.278763 2026] [security2:error] [pid 302018:tid 302165] [client 202.143.127.214:59590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OAIAs9lPxxVAErz3xjgAAAJQ"]
[Tue Jul 21 07:46:24.278876 2026] [security2:error] [pid 302018:tid 302165] [client 202.143.127.214:59590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OAIAs9lPxxVAErz3xjgAAAJQ"]
[Tue Jul 21 07:46:24.440621 2026] [security2:error] [pid 296703:tid 296955] [client 20.104.96.117:46689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-post-data.php"] [unique_id "al9OACn25uliftkV1n4XGAAAAHo"]
[Tue Jul 21 07:46:25.023840 2026] [security2:error] [pid 302018:tid 302252] [client 194.99.104.35:45952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9OAYAs9lPxxVAErz3xmAAAAOs"]
[Tue Jul 21 07:46:25.023937 2026] [security2:error] [pid 302018:tid 302252] [client 194.99.104.35:45952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9OAYAs9lPxxVAErz3xmAAAAOs"]
[Tue Jul 21 07:46:25.335262 2026] [security2:error] [pid 302018:tid 302230] [client 20.197.195.24:18533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/dr.php"] [unique_id "al9OAYAs9lPxxVAErz3xnAAAANU"]
[Tue Jul 21 07:46:25.381648 2026] [security2:error] [pid 302018:tid 302273] [client 106.215.181.8:31100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OAYAs9lPxxVAErz3xnQAAAQA"]
[Tue Jul 21 07:46:25.381778 2026] [security2:error] [pid 302018:tid 302273] [client 106.215.181.8:31100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OAYAs9lPxxVAErz3xnQAAAQA"]
[Tue Jul 21 07:46:25.393475 2026] [security2:error] [pid 302018:tid 302159] [client 20.206.105.145:56611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/abcd.php"] [unique_id "al9OAYAs9lPxxVAErz3xngAAAI4"]
[Tue Jul 21 07:46:25.421870 2026] [security2:error] [pid 296703:tid 296947] [client 62.102.148.187:41130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9OASn25uliftkV1n4XJgAAAHI"]
[Tue Jul 21 07:46:25.421972 2026] [security2:error] [pid 296703:tid 296947] [client 62.102.148.187:41130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9OASn25uliftkV1n4XJgAAAHI"]
[Tue Jul 21 07:46:25.452110 2026] [security2:error] [pid 302018:tid 302052] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OAYAs9lPxxVAErz3xowAA4h8"]
[Tue Jul 21 07:46:25.452243 2026] [security2:error] [pid 302018:tid 302243] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OAYAs9lPxxVAErz3xowAA4h8"]
[Tue Jul 21 07:46:25.479167 2026] [security2:error] [pid 296703:tid 296765] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OASn25uliftkV1n4XLAAAdj0"]
[Tue Jul 21 07:46:25.479317 2026] [security2:error] [pid 296703:tid 296951] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OASn25uliftkV1n4XLAAAdj0"]
[Tue Jul 21 07:46:25.603642 2026] [security2:error] [pid 296703:tid 296747] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OASn25uliftkV1n4XLgAAFis"]
[Tue Jul 21 07:46:25.603863 2026] [security2:error] [pid 296703:tid 296855] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OASn25uliftkV1n4XLgAAFis"]
[Tue Jul 21 07:46:25.634092 2026] [security2:error] [pid 302018:tid 302210] [client 103.166.103.129:19823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OAYAs9lPxxVAErz3xpQAAAME"]
[Tue Jul 21 07:46:25.634238 2026] [security2:error] [pid 302018:tid 302210] [client 103.166.103.129:19823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OAYAs9lPxxVAErz3xpQAAAME"]
[Tue Jul 21 07:46:25.793623 2026] [security2:error] [pid 302018:tid 302151] [client 20.104.96.117:46688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/pucci.php"] [unique_id "al9OAYAs9lPxxVAErz3xpwAAAIY"]
[Tue Jul 21 07:46:25.989435 2026] [security2:error] [pid 302018:tid 302223] [client 128.127.105.184:38336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9OAYAs9lPxxVAErz3xqwAAAM4"]
[Tue Jul 21 07:46:25.989556 2026] [security2:error] [pid 302018:tid 302223] [client 128.127.105.184:38336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9OAYAs9lPxxVAErz3xqwAAAM4"]
[Tue Jul 21 07:46:26.058346 2026] [security2:error] [pid 302018:tid 302135] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OAoAs9lPxxVAErz3xrQAA0HI"]
[Tue Jul 21 07:46:26.058511 2026] [security2:error] [pid 302018:tid 302225] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OAoAs9lPxxVAErz3xrQAA0HI"]
[Tue Jul 21 07:46:26.119356 2026] [security2:error] [pid 302018:tid 302270] [client 20.63.100.92:2192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/hp2.php"] [unique_id "al9OAoAs9lPxxVAErz3xsQAAAP0"]
[Tue Jul 21 07:46:26.233929 2026] [security2:error] [pid 296703:tid 296871] [client 20.197.195.24:16144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/x.php"] [unique_id "al9OAin25uliftkV1n4XNgAAACY"]
[Tue Jul 21 07:46:26.379675 2026] [security2:error] [pid 296703:tid 296942] [client 193.36.225.10:37927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OAin25uliftkV1n4XNQAAAG0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:46:26.440688 2026] [security2:error] [pid 296703:tid 296902] [client 20.206.105.145:56632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/a1.php"] [unique_id "al9OAin25uliftkV1n4XPwAAAEU"]
[Tue Jul 21 07:46:26.506067 2026] [security2:error] [pid 302018:tid 302152] [client 20.197.195.24:16148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/155.php"] [unique_id "al9OAoAs9lPxxVAErz3xtAAAAIc"]
[Tue Jul 21 07:46:26.514796 2026] [security2:error] [pid 302018:tid 302178] [client 184.75.223.211:34474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OAoAs9lPxxVAErz3xtQAAAKE"]
[Tue Jul 21 07:46:26.514911 2026] [security2:error] [pid 302018:tid 302178] [client 184.75.223.211:34474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OAoAs9lPxxVAErz3xtQAAAKE"]
[Tue Jul 21 07:46:26.567182 2026] [security2:error] [pid 302018:tid 302144] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OAoAs9lPxxVAErz3xtwAAuXs"]
[Tue Jul 21 07:46:26.567316 2026] [security2:error] [pid 302018:tid 302202] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OAoAs9lPxxVAErz3xtwAAuXs"]
[Tue Jul 21 07:46:26.703998 2026] [core:alert] [pid 302018:tid 302174] [client 57.141.18.25:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:46:26.828277 2026] [security2:error] [pid 302018:tid 302150] [client 20.151.10.161:44014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/w.php"] [unique_id "al9OAoAs9lPxxVAErz3xvAAAAIU"]
[Tue Jul 21 07:46:26.922357 2026] [security2:error] [pid 296703:tid 296837] [client 122.164.127.47:51287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OAin25uliftkV1n4XRQAAAAQ"]
[Tue Jul 21 07:46:26.922465 2026] [security2:error] [pid 296703:tid 296837] [client 122.164.127.47:51287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OAin25uliftkV1n4XRQAAAAQ"]
[Tue Jul 21 07:46:27.024491 2026] [security2:error] [pid 296703:tid 296862] [client 122.179.91.63:27360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OAyn25uliftkV1n4XSAAAAB0"]
[Tue Jul 21 07:46:27.024661 2026] [security2:error] [pid 296703:tid 296862] [client 122.179.91.63:27360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OAyn25uliftkV1n4XSAAAAB0"]
[Tue Jul 21 07:46:27.046915 2026] [security2:error] [pid 302018:tid 302172] [client 20.197.195.24:18500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/ops.php"] [unique_id "al9OA4As9lPxxVAErz3xvwAAAJs"]
[Tue Jul 21 07:46:27.047354 2026] [security2:error] [pid 296703:tid 296927] [client 117.217.38.194:60878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OAyn25uliftkV1n4XSwAAAF4"]
[Tue Jul 21 07:46:27.047453 2026] [security2:error] [pid 296703:tid 296927] [client 117.217.38.194:60878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OAyn25uliftkV1n4XSwAAAF4"]
[Tue Jul 21 07:46:27.159877 2026] [security2:error] [pid 302018:tid 302234] [client 20.104.96.117:46690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/black.php"] [unique_id "al9OA4As9lPxxVAErz3xwQAAANk"]
[Tue Jul 21 07:46:27.196742 2026] [security2:error] [pid 302018:tid 302263] [client 41.68.90.219:52191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OA4As9lPxxVAErz3xwwAAAPY"]
[Tue Jul 21 07:46:27.197827 2026] [security2:error] [pid 302018:tid 302263] [client 41.68.90.219:52191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OA4As9lPxxVAErz3xwwAAAPY"]
[Tue Jul 21 07:46:27.288160 2026] [security2:error] [pid 302018:tid 302277] [client 62.102.148.187:47284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9OA4As9lPxxVAErz3xxQAAAQQ"]
[Tue Jul 21 07:46:27.288260 2026] [security2:error] [pid 302018:tid 302277] [client 62.102.148.187:47284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9OA4As9lPxxVAErz3xxQAAAQQ"]
[Tue Jul 21 07:46:27.344732 2026] [security2:error] [pid 296703:tid 296946] [client 193.36.225.107:54477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OAyn25uliftkV1n4XTQAAAHE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:46:27.417236 2026] [autoindex:error] [pid 302018:tid 302226] [client 198.235.24.174:60330] AH01276: Cannot serve directory /home4/ciclod61/bahinternet.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:46:27.573978 2026] [security2:error] [pid 302018:tid 302169] [client 103.174.34.15:50842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OA4As9lPxxVAErz3xzAAAAJg"]
[Tue Jul 21 07:46:27.574164 2026] [security2:error] [pid 302018:tid 302169] [client 103.174.34.15:50842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OA4As9lPxxVAErz3xzAAAAJg"]
[Tue Jul 21 07:46:27.743457 2026] [security2:error] [pid 302018:tid 302265] [client 51.195.215.11:41896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.girassollimpeza.com.br"] [uri "/robots.txt"] [unique_id "al9OA4As9lPxxVAErz3xzgAAAPg"]
[Tue Jul 21 07:46:27.743570 2026] [security2:error] [pid 302018:tid 302265] [client 51.195.215.11:41896] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.girassollimpeza.com.br"] [uri "/robots.txt"] [unique_id "al9OA4As9lPxxVAErz3xzgAAAPg"]
[Tue Jul 21 07:46:28.162759 2026] [security2:error] [pid 296703:tid 296941] [client 223.236.153.128:7270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OBCn25uliftkV1n4XWgAAAGw"]
[Tue Jul 21 07:46:28.167411 2026] [security2:error] [pid 296703:tid 296941] [client 223.236.153.128:7270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OBCn25uliftkV1n4XWgAAAGw"]
[Tue Jul 21 07:46:28.407518 2026] [security2:error] [pid 302018:tid 302207] [client 20.197.195.24:16187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/file31.php"] [unique_id "al9OBIAs9lPxxVAErz3x1gAAAL4"]
[Tue Jul 21 07:46:28.642499 2026] [security2:error] [pid 302018:tid 302252] [client 20.104.96.117:46683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/zlece.php"] [unique_id "al9OBIAs9lPxxVAErz3x2wAAAOs"]
[Tue Jul 21 07:46:28.766708 2026] [security2:error] [pid 302018:tid 302258] [client 117.247.80.59:25264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OBIAs9lPxxVAErz3x3QAAAPE"]
[Tue Jul 21 07:46:28.766854 2026] [security2:error] [pid 302018:tid 302258] [client 117.247.80.59:25264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OBIAs9lPxxVAErz3x3QAAAPE"]
[Tue Jul 21 07:46:28.821503 2026] [security2:error] [pid 302018:tid 302264] [client 122.186.204.214:51759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OBIAs9lPxxVAErz3x3gAAAPc"]
[Tue Jul 21 07:46:28.821634 2026] [security2:error] [pid 302018:tid 302264] [client 122.186.204.214:51759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OBIAs9lPxxVAErz3x3gAAAPc"]
[Tue Jul 21 07:46:29.018343 2026] [security2:error] [pid 302018:tid 302161] [client 194.99.104.35:49444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9OBYAs9lPxxVAErz3x4AAAAJA"]
[Tue Jul 21 07:46:29.018442 2026] [security2:error] [pid 302018:tid 302161] [client 194.99.104.35:49444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9OBYAs9lPxxVAErz3x4AAAAJA"]
[Tue Jul 21 07:46:29.053961 2026] [autoindex:error] [pid 296703:tid 296949] [client 148.113.192.228:50750] AH01276: Cannot serve directory /home2/andr9968/artemcamadas.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:46:29.156484 2026] [security2:error] [pid 296703:tid 296953] [client 142.44.228.208:17994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.girassollimpeza.com.br"] [uri "/"] [unique_id "al9OBSn25uliftkV1n4XcgAAAHg"]
[Tue Jul 21 07:46:29.157183 2026] [security2:error] [pid 296703:tid 296953] [client 142.44.228.208:17994] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.girassollimpeza.com.br"] [uri "/"] [unique_id "al9OBSn25uliftkV1n4XcgAAAHg"]
[Tue Jul 21 07:46:29.236358 2026] [security2:error] [pid 302018:tid 302256] [client 20.197.195.24:16241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/file6.php"] [unique_id "al9OBYAs9lPxxVAErz3x4gAAAO8"]
[Tue Jul 21 07:46:29.248596 2026] [security2:error] [pid 302018:tid 302234] [client 20.206.105.145:56662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9OBYAs9lPxxVAErz3x4wAAANk"]
[Tue Jul 21 07:46:29.463565 2026] [security2:error] [pid 296703:tid 296871] [client 117.251.86.144:55620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OBSn25uliftkV1n4XdgAAACY"]
[Tue Jul 21 07:46:29.463665 2026] [security2:error] [pid 296703:tid 296871] [client 117.251.86.144:55620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OBSn25uliftkV1n4XdgAAACY"]
[Tue Jul 21 07:46:29.504306 2026] [security2:error] [pid 296703:tid 296959] [client 154.192.233.199:59661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OBSn25uliftkV1n4XdwAAAH4"]
[Tue Jul 21 07:46:29.504459 2026] [security2:error] [pid 296703:tid 296959] [client 154.192.233.199:59661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OBSn25uliftkV1n4XdwAAAH4"]
[Tue Jul 21 07:46:29.513651 2026] [security2:error] [pid 296703:tid 296880] [client 20.151.10.161:43998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/fpwch.php"] [unique_id "al9OBSn25uliftkV1n4XeAAAAC8"]
[Tue Jul 21 07:46:29.865100 2026] [security2:error] [pid 302018:tid 302206] [client 47.128.17.129:38764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "avermetais.com.br"] [uri "/robots.txt"] [unique_id "al9OBYAs9lPxxVAErz3x6AAAAL0"]
[Tue Jul 21 07:46:29.902400 2026] [security2:error] [pid 296703:tid 296946] [client 20.197.195.24:16162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/adminfuns.php"] [unique_id "al9OBSn25uliftkV1n4XfwAAAHE"]
[Tue Jul 21 07:46:30.683578 2026] [security2:error] [pid 296703:tid 296850] [client 20.104.96.117:46681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/vssrs.php"] [unique_id "al9OBin25uliftkV1n4XiQAAABE"]
[Tue Jul 21 07:46:31.033015 2026] [security2:error] [pid 296703:tid 296846] [client 20.151.10.161:43909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/w2025.php"] [unique_id "al9OByn25uliftkV1n4XjgAAAA0"]
[Tue Jul 21 07:46:31.327066 2026] [security2:error] [pid 296703:tid 296894] [client 193.36.225.60:30177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OByn25uliftkV1n4XlAAAAD0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:46:31.366212 2026] [security2:error] [pid 302018:tid 302224] [client 20.197.195.24:16131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/goods.php"] [unique_id "al9OB4As9lPxxVAErz3x9AAAAM8"]
[Tue Jul 21 07:46:31.532447 2026] [security2:error] [pid 302018:tid 302261] [client 62.102.148.187:45728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9OB4As9lPxxVAErz3x9QAAAPQ"]
[Tue Jul 21 07:46:31.532556 2026] [security2:error] [pid 302018:tid 302261] [client 62.102.148.187:45728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9OB4As9lPxxVAErz3x9QAAAPQ"]
[Tue Jul 21 07:46:32.054989 2026] [security2:error] [pid 296703:tid 296843] [client 59.96.220.140:52803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OCCn25uliftkV1n4XnwAAAAo"]
[Tue Jul 21 07:46:32.055734 2026] [security2:error] [pid 296703:tid 296843] [client 59.96.220.140:52803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OCCn25uliftkV1n4XnwAAAAo"]
[Tue Jul 21 07:46:32.122340 2026] [security2:error] [pid 302018:tid 302172] [client 20.226.60.151:61576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9OCIAs9lPxxVAErz3x_gAAAJs"]
[Tue Jul 21 07:46:32.239294 2026] [security2:error] [pid 302018:tid 302230] [client 20.206.105.145:56585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/cgi-bin/admin.php"] [unique_id "al9OCIAs9lPxxVAErz3x_wAAANU"]
[Tue Jul 21 07:46:32.278653 2026] [security2:error] [pid 302018:tid 302038] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OCIAs9lPxxVAErz3yAAAAmhE"]
[Tue Jul 21 07:46:32.278787 2026] [security2:error] [pid 302018:tid 302171] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OCIAs9lPxxVAErz3yAAAAmhE"]
[Tue Jul 21 07:46:32.425237 2026] [security2:error] [pid 302018:tid 302274] [client 20.197.195.24:11309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/100.php"] [unique_id "al9OCIAs9lPxxVAErz3yBgAAAQE"]
[Tue Jul 21 07:46:33.013767 2026] [security2:error] [pid 296703:tid 296870] [client 103.29.114.44:47076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OCSn25uliftkV1n4XrAAAACU"]
[Tue Jul 21 07:46:33.013895 2026] [security2:error] [pid 296703:tid 296870] [client 103.29.114.44:47076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OCSn25uliftkV1n4XrAAAACU"]
[Tue Jul 21 07:46:33.057011 2026] [security2:error] [pid 302018:tid 302183] [client 139.167.225.182:64557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OCYAs9lPxxVAErz3yDQAAAKY"]
[Tue Jul 21 07:46:33.057104 2026] [security2:error] [pid 302018:tid 302183] [client 139.167.225.182:64557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OCYAs9lPxxVAErz3yDQAAAKY"]
[Tue Jul 21 07:46:33.084512 2026] [security2:error] [pid 296703:tid 296893] [client 173.24.185.52:49271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OCSn25uliftkV1n4XrQAAADw"]
[Tue Jul 21 07:46:33.084618 2026] [security2:error] [pid 296703:tid 296893] [client 173.24.185.52:49271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OCSn25uliftkV1n4XrQAAADw"]
[Tue Jul 21 07:46:33.112484 2026] [security2:error] [pid 302018:tid 302055] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OCYAs9lPxxVAErz3yDgAA1yI"]
[Tue Jul 21 07:46:33.112631 2026] [security2:error] [pid 302018:tid 302232] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OCYAs9lPxxVAErz3yDgAA1yI"]
[Tue Jul 21 07:46:33.150549 2026] [security2:error] [pid 302018:tid 302236] [client 20.151.10.161:43969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/scxy.php"] [unique_id "al9OCYAs9lPxxVAErz3yDwAAANs"]
[Tue Jul 21 07:46:33.671015 2026] [security2:error] [pid 296703:tid 296919] [client 182.8.255.181:17332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OCSn25uliftkV1n4XswAAAFY"]
[Tue Jul 21 07:46:33.671151 2026] [security2:error] [pid 296703:tid 296919] [client 182.8.255.181:17332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OCSn25uliftkV1n4XswAAAFY"]
[Tue Jul 21 07:46:33.767170 2026] [security2:error] [pid 302018:tid 302276] [client 154.208.47.43:51743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OCYAs9lPxxVAErz3yFwAAAQM"]
[Tue Jul 21 07:46:33.767298 2026] [security2:error] [pid 302018:tid 302276] [client 154.208.47.43:51743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OCYAs9lPxxVAErz3yFwAAAQM"]
[Tue Jul 21 07:46:33.785309 2026] [security2:error] [pid 302018:tid 302233] [client 20.206.105.145:29634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-content/BypassBest.php"] [unique_id "al9OCYAs9lPxxVAErz3yGAAAANg"]
[Tue Jul 21 07:46:33.836152 2026] [security2:error] [pid 302018:tid 302261] [client 20.104.96.117:46608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wicked.php"] [unique_id "al9OCYAs9lPxxVAErz3yGQAAAPQ"]
[Tue Jul 21 07:46:33.890062 2026] [security2:error] [pid 296703:tid 296859] [client 152.59.154.239:64972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OCSn25uliftkV1n4XtQAAABo"]
[Tue Jul 21 07:46:33.890214 2026] [security2:error] [pid 296703:tid 296859] [client 152.59.154.239:64972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OCSn25uliftkV1n4XtQAAABo"]
[Tue Jul 21 07:46:33.931096 2026] [security2:error] [pid 302018:tid 302150] [client 20.226.60.151:61594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9OCYAs9lPxxVAErz3yHAAAAIU"]
[Tue Jul 21 07:46:34.009245 2026] [security2:error] [pid 302018:tid 302178] [client 122.179.91.63:24474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OCoAs9lPxxVAErz3yHwAAAKE"]
[Tue Jul 21 07:46:34.009349 2026] [security2:error] [pid 302018:tid 302178] [client 122.179.91.63:24474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OCoAs9lPxxVAErz3yHwAAAKE"]
[Tue Jul 21 07:46:34.113900 2026] [security2:error] [pid 302018:tid 302194] [client 20.63.100.92:8742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/hp3.php"] [unique_id "al9OCoAs9lPxxVAErz3yIAAAALE"]
[Tue Jul 21 07:46:34.262150 2026] [security2:error] [pid 296703:tid 296945] [client 20.197.195.24:16195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/about.php"] [unique_id "al9OCin25uliftkV1n4XugAAAHA"]
[Tue Jul 21 07:46:34.335528 2026] [security2:error] [pid 302018:tid 302192] [client 122.162.144.145:14117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OCoAs9lPxxVAErz3yIQAAAK8"]
[Tue Jul 21 07:46:34.337969 2026] [security2:error] [pid 302018:tid 302192] [client 122.162.144.145:14117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OCoAs9lPxxVAErz3yIQAAAK8"]
[Tue Jul 21 07:46:34.364734 2026] [security2:error] [pid 302018:tid 302031] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OCoAs9lPxxVAErz3yIgAA8Qo"]
[Tue Jul 21 07:46:34.364878 2026] [security2:error] [pid 302018:tid 302258] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OCoAs9lPxxVAErz3yIgAA8Qo"]
[Tue Jul 21 07:46:34.667010 2026] [security2:error] [pid 296703:tid 296879] [client 103.86.117.203:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OCin25uliftkV1n4XwQAAAC4"]
[Tue Jul 21 07:46:34.667151 2026] [security2:error] [pid 296703:tid 296879] [client 103.86.117.203:49614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OCin25uliftkV1n4XwQAAAC4"]
[Tue Jul 21 07:46:34.737120 2026] [security2:error] [pid 296703:tid 296944] [client 178.153.91.96:17737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OCin25uliftkV1n4XwgAAAG8"]
[Tue Jul 21 07:46:34.737339 2026] [security2:error] [pid 296703:tid 296944] [client 178.153.91.96:17737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OCin25uliftkV1n4XwgAAAG8"]
[Tue Jul 21 07:46:34.848501 2026] [security2:error] [pid 302018:tid 302208] [client 20.151.10.161:44029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/FWAZ.php"] [unique_id "al9OCoAs9lPxxVAErz3yKAAAAL8"]
[Tue Jul 21 07:46:34.995738 2026] [security2:error] [pid 302018:tid 302210] [client 20.104.96.117:46648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/24.php"] [unique_id "al9OCoAs9lPxxVAErz3yKgAAAME"]
[Tue Jul 21 07:46:35.002209 2026] [security2:error] [pid 302018:tid 302224] [client 136.144.33.109:45145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OC4As9lPxxVAErz3yKwAAAM8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:46:35.073501 2026] [security2:error] [pid 302018:tid 302259] [client 20.206.105.145:56660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/simple.php"] [unique_id "al9OC4As9lPxxVAErz3yLAAAAPI"]
[Tue Jul 21 07:46:35.365178 2026] [security2:error] [pid 296703:tid 296861] [client 202.143.127.214:60041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OCyn25uliftkV1n4XywAAABw"]
[Tue Jul 21 07:46:35.365367 2026] [security2:error] [pid 296703:tid 296861] [client 202.143.127.214:60041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OCyn25uliftkV1n4XywAAABw"]
[Tue Jul 21 07:46:35.889360 2026] [security2:error] [pid 302018:tid 302277] [client 103.166.103.129:20395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OC4As9lPxxVAErz3yNwAAAQQ"]
[Tue Jul 21 07:46:35.889514 2026] [security2:error] [pid 302018:tid 302277] [client 103.166.103.129:20395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OC4As9lPxxVAErz3yNwAAAQQ"]
[Tue Jul 21 07:46:35.958486 2026] [security2:error] [pid 302018:tid 302270] [client 20.197.195.24:16222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/about.php"] [unique_id "al9OC4As9lPxxVAErz3yOAAAAP0"]
[Tue Jul 21 07:46:35.997980 2026] [security2:error] [pid 302018:tid 302225] [client 109.60.28.94:62668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OCYAs9lPxxVAErz3yFgAAANA"]
[Tue Jul 21 07:46:36.007966 2026] [security2:error] [pid 302018:tid 302193] [client 20.206.105.145:29666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/xxx.php"] [unique_id "al9ODIAs9lPxxVAErz3yOgAAALA"]
[Tue Jul 21 07:46:36.017372 2026] [security2:error] [pid 296703:tid 296804] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9ODCn25uliftkV1n4X1wAAAmQ"]
[Tue Jul 21 07:46:36.017507 2026] [security2:error] [pid 296703:tid 296835] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9ODCn25uliftkV1n4X1wAAAmQ"]
[Tue Jul 21 07:46:36.101464 2026] [security2:error] [pid 296703:tid 296847] [client 106.215.181.8:16453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ODCn25uliftkV1n4X2gAAAA4"]
[Tue Jul 21 07:46:36.101568 2026] [security2:error] [pid 296703:tid 296847] [client 106.215.181.8:16453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ODCn25uliftkV1n4X2gAAAA4"]
[Tue Jul 21 07:46:36.170731 2026] [security2:error] [pid 296703:tid 296917] [client 20.151.10.161:43991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/qterm.php"] [unique_id "al9ODCn25uliftkV1n4X2wAAAFQ"]
[Tue Jul 21 07:46:36.266049 2026] [security2:error] [pid 302018:tid 302059] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9ODIAs9lPxxVAErz3yPwAA2CY"]
[Tue Jul 21 07:46:36.266178 2026] [security2:error] [pid 302018:tid 302233] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9ODIAs9lPxxVAErz3yPwAA2CY"]
[Tue Jul 21 07:46:36.278102 2026] [security2:error] [pid 296703:tid 296758] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ODCn25uliftkV1n4X3AAAXjY"]
[Tue Jul 21 07:46:36.278197 2026] [security2:error] [pid 296703:tid 296927] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ODCn25uliftkV1n4X3AAAXjY"]
[Tue Jul 21 07:46:36.699656 2026] [security2:error] [pid 302018:tid 302173] [client 20.104.96.117:46719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/xacs.php"] [unique_id "al9ODIAs9lPxxVAErz3yQwAAAJw"]
[Tue Jul 21 07:46:36.841222 2026] [security2:error] [pid 302018:tid 302251] [client 20.151.10.161:43923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/blurbs.php"] [unique_id "al9ODIAs9lPxxVAErz3yRAAAAOo"]
[Tue Jul 21 07:46:37.012965 2026] [security2:error] [pid 296703:tid 296760] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ODSn25uliftkV1n4X5QAAVjg"]
[Tue Jul 21 07:46:37.013093 2026] [security2:error] [pid 296703:tid 296919] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ODSn25uliftkV1n4X5QAAVjg"]
[Tue Jul 21 07:46:37.103046 2026] [security2:error] [pid 302018:tid 302051] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ODYAs9lPxxVAErz3yRgAA6R4"]
[Tue Jul 21 07:46:37.103222 2026] [security2:error] [pid 302018:tid 302250] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ODYAs9lPxxVAErz3yRgAA6R4"]
[Tue Jul 21 07:46:37.507238 2026] [security2:error] [pid 302018:tid 302258] [client 20.197.195.24:53157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/admin.php"] [unique_id "al9ODYAs9lPxxVAErz3ySQAAAPE"]
[Tue Jul 21 07:46:37.527867 2026] [security2:error] [pid 302018:tid 302186] [client 117.217.38.194:61362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ODYAs9lPxxVAErz3ySgAAAKk"]
[Tue Jul 21 07:46:37.528010 2026] [security2:error] [pid 302018:tid 302186] [client 117.217.38.194:61362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ODYAs9lPxxVAErz3ySgAAAKk"]
[Tue Jul 21 07:46:37.553340 2026] [security2:error] [pid 296703:tid 296933] [client 122.164.127.47:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9ODSn25uliftkV1n4X7AAAAGQ"]
[Tue Jul 21 07:46:37.553452 2026] [security2:error] [pid 296703:tid 296933] [client 122.164.127.47:51866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9ODSn25uliftkV1n4X7AAAAGQ"]
[Tue Jul 21 07:46:37.740671 2026] [security2:error] [pid 302018:tid 302262] [client 20.151.10.161:44005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/v543.php"] [unique_id "al9ODYAs9lPxxVAErz3yTAAAAPU"]
[Tue Jul 21 07:46:37.935713 2026] [security2:error] [pid 296703:tid 296899] [client 20.206.105.145:56623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/hypo.php"] [unique_id "al9ODSn25uliftkV1n4X9gAAAEI"]
[Tue Jul 21 07:46:38.089623 2026] [security2:error] [pid 302018:tid 302237] [client 20.151.10.161:43997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/w3lls.php"] [unique_id "al9ODoAs9lPxxVAErz3yTQAAANw"]
[Tue Jul 21 07:46:38.447184 2026] [security2:error] [pid 296703:tid 296944] [client 103.174.34.15:51353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ODin25uliftkV1n4X_gAAAG8"]
[Tue Jul 21 07:46:38.447305 2026] [security2:error] [pid 296703:tid 296944] [client 103.174.34.15:51353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ODin25uliftkV1n4X_gAAAG8"]
[Tue Jul 21 07:46:38.452022 2026] [security2:error] [pid 296703:tid 296929] [client 20.104.96.117:46705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/zildan.php"] [unique_id "al9ODin25uliftkV1n4X_wAAAGA"]
[Tue Jul 21 07:46:38.509555 2026] [security2:error] [pid 296703:tid 296951] [client 223.236.153.128:5938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9ODin25uliftkV1n4YAAAAAHY"]
[Tue Jul 21 07:46:38.509697 2026] [security2:error] [pid 296703:tid 296951] [client 223.236.153.128:5938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9ODin25uliftkV1n4YAAAAAHY"]
[Tue Jul 21 07:46:38.584484 2026] [security2:error] [pid 302018:tid 302057] [remote 14.128.14.9:33822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.14.128.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ellosemijoias.com.br"] [uri "/wp-login.php"] [unique_id "al9ODIAs9lPxxVAErz3yQQAAlSQ"]
[Tue Jul 21 07:46:38.597663 2026] [security2:error] [pid 296703:tid 296921] [client 20.197.195.24:18544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/admin.php"] [unique_id "al9ODin25uliftkV1n4YAQAAAFg"]
[Tue Jul 21 07:46:38.669570 2026] [security2:error] [pid 302018:tid 302243] [client 41.68.90.219:52624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ODoAs9lPxxVAErz3yUgAAAOI"]
[Tue Jul 21 07:46:38.670744 2026] [security2:error] [pid 302018:tid 302243] [client 41.68.90.219:52624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ODoAs9lPxxVAErz3yUgAAAOI"]
[Tue Jul 21 07:46:39.038888 2026] [security2:error] [pid 302018:tid 302211] [client 20.151.10.161:44006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-ws68.php"] [unique_id "al9OD4As9lPxxVAErz3yWQAAAMI"]
[Tue Jul 21 07:46:39.493787 2026] [security2:error] [pid 302018:tid 302277] [client 117.247.80.59:19380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OD4As9lPxxVAErz3yXwAAAQQ"]
[Tue Jul 21 07:46:39.493964 2026] [security2:error] [pid 302018:tid 302277] [client 117.247.80.59:19380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OD4As9lPxxVAErz3yXwAAAQQ"]
[Tue Jul 21 07:46:39.617006 2026] [security2:error] [pid 302018:tid 302270] [client 122.186.204.214:52313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OD4As9lPxxVAErz3yYAAAAP0"]
[Tue Jul 21 07:46:39.617136 2026] [security2:error] [pid 302018:tid 302270] [client 122.186.204.214:52313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OD4As9lPxxVAErz3yYAAAAP0"]
[Tue Jul 21 07:46:39.621134 2026] [security2:error] [pid 302018:tid 302173] [client 20.197.195.24:16252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/themes.php"] [unique_id "al9OD4As9lPxxVAErz3yYQAAAJw"]
[Tue Jul 21 07:46:39.667540 2026] [security2:error] [pid 302018:tid 302180] [client 136.144.33.28:42915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OD4As9lPxxVAErz3yYgAAAKM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:46:39.775436 2026] [security2:error] [pid 302018:tid 302242] [client 20.206.105.145:56613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/chosen.php"] [unique_id "al9OD4As9lPxxVAErz3yZAAAAOE"]
[Tue Jul 21 07:46:39.823542 2026] [security2:error] [pid 302018:tid 302194] [client 20.104.96.117:46616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/csa.php"] [unique_id "al9OD4As9lPxxVAErz3yagAAALE"]
[Tue Jul 21 07:46:40.094567 2026] [security2:error] [pid 302018:tid 302172] [client 20.63.100.92:8706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/aa1.php"] [unique_id "al9OEIAs9lPxxVAErz3ybAAAAJs"]
[Tue Jul 21 07:46:40.106703 2026] [security2:error] [pid 296703:tid 296847] [client 154.192.233.199:60513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OECn25uliftkV1n4YFwAAAA4"]
[Tue Jul 21 07:46:40.106844 2026] [security2:error] [pid 296703:tid 296847] [client 154.192.233.199:60513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OECn25uliftkV1n4YFwAAAA4"]
[Tue Jul 21 07:46:40.352420 2026] [security2:error] [pid 302018:tid 302198] [client 117.251.86.144:44888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OEIAs9lPxxVAErz3ycQAAALU"]
[Tue Jul 21 07:46:40.352535 2026] [security2:error] [pid 302018:tid 302198] [client 117.251.86.144:44888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OEIAs9lPxxVAErz3ycQAAALU"]
[Tue Jul 21 07:46:40.417315 2026] [security2:error] [pid 302018:tid 302224] [client 20.151.10.161:43982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/xyn.php"] [unique_id "al9OEIAs9lPxxVAErz3ycgAAAM8"]
[Tue Jul 21 07:46:40.756911 2026] [security2:error] [pid 302018:tid 302243] [client 62.102.148.187:56628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9OEIAs9lPxxVAErz3ydgAAAOI"]
[Tue Jul 21 07:46:40.757023 2026] [security2:error] [pid 302018:tid 302243] [client 62.102.148.187:56628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9OEIAs9lPxxVAErz3ydgAAAOI"]
[Tue Jul 21 07:46:40.982568 2026] [autoindex:error] [pid 296703:tid 296945] [client 173.252.95.54:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:46:41.120018 2026] [security2:error] [pid 302018:tid 302190] [client 20.104.96.117:46692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/w3llscc.php"] [unique_id "al9OEYAs9lPxxVAErz3yewAAAK0"]
[Tue Jul 21 07:46:41.410908 2026] [autoindex:error] [pid 302018:tid 302066] [remote 74.7.227.173:45370] AH01276: Cannot serve directory /home2/bavosc49/davinci.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:46:41.599146 2026] [security2:error] [pid 302018:tid 302211] [client 74.7.228.24:56684] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.davinci.bavos.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9OEYAs9lPxxVAErz3ygwAAwiw"]
[Tue Jul 21 07:46:41.697278 2026] [security2:error] [pid 296703:tid 296930] [client 20.197.195.24:16156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/.well-known/about.php"] [unique_id "al9OESn25uliftkV1n4YNgAAAGE"]
[Tue Jul 21 07:46:41.898847 2026] [security2:error] [pid 302018:tid 302157] [client 20.104.96.117:46672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wpx.php"] [unique_id "al9OEYAs9lPxxVAErz3yhgAAAIw"]
[Tue Jul 21 07:46:42.734228 2026] [security2:error] [pid 302018:tid 302221] [client 20.206.105.145:56622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/file5.php"] [unique_id "al9OEoAs9lPxxVAErz3ykQAAAMw"]
[Tue Jul 21 07:46:42.812514 2026] [security2:error] [pid 296703:tid 296771] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OEin25uliftkV1n4YTAAADkM"]
[Tue Jul 21 07:46:42.812693 2026] [security2:error] [pid 296703:tid 296847] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OEin25uliftkV1n4YTAAADkM"]
[Tue Jul 21 07:46:42.855809 2026] [security2:error] [pid 296703:tid 296934] [client 20.63.100.92:2701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/acew67.php"] [unique_id "al9OEin25uliftkV1n4YTgAAAGU"]
[Tue Jul 21 07:46:42.926296 2026] [security2:error] [pid 302018:tid 302236] [client 193.36.225.106:52501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OEoAs9lPxxVAErz3ykgAAANs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:46:42.963930 2026] [security2:error] [pid 302018:tid 302252] [client 20.197.195.24:16190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9OEoAs9lPxxVAErz3ylgAAAOs"]
[Tue Jul 21 07:46:43.199161 2026] [security2:error] [pid 302018:tid 302171] [client 20.151.10.161:44027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/green3.php"] [unique_id "al9OE4As9lPxxVAErz3ylwAAAJo"]
[Tue Jul 21 07:46:43.239042 2026] [security2:error] [pid 302018:tid 302276] [client 136.144.33.110:48419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OE4As9lPxxVAErz3ymQAAAQM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:46:43.412617 2026] [proxy:error] [pid 296703:tid 296817] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:46:43.412650 2026] [proxy_http:error] [pid 296703:tid 296817] [remote 74.7.228.55:59252] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:46:43.413083 2026] [proxy:error] [pid 296703:tid 296817] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:46:43.413103 2026] [proxy_http:error] [pid 296703:tid 296817] [remote 74.7.228.55:59252] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:46:43.551276 2026] [security2:error] [pid 302018:tid 302192] [client 139.167.225.182:65204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OE4As9lPxxVAErz3yngAAAK8"]
[Tue Jul 21 07:46:43.551369 2026] [security2:error] [pid 302018:tid 302192] [client 139.167.225.182:65204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OE4As9lPxxVAErz3yngAAAK8"]
[Tue Jul 21 07:46:43.586359 2026] [security2:error] [pid 302018:tid 302243] [client 74.7.230.0:45382] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "novo.mannucarvalho.com"] [uri "/robots.txt"] [unique_id "al9OE4As9lPxxVAErz3yoAAA4kc"]
[Tue Jul 21 07:46:43.616376 2026] [security2:error] [pid 296703:tid 296916] [client 173.24.185.52:50232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OEyn25uliftkV1n4YXAAAAFM"]
[Tue Jul 21 07:46:43.626251 2026] [security2:error] [pid 296703:tid 296916] [client 173.24.185.52:50232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OEyn25uliftkV1n4YXAAAAFM"]
[Tue Jul 21 07:46:43.734902 2026] [security2:error] [pid 302018:tid 302170] [client 20.197.195.24:16247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/wefile.php"] [unique_id "al9OE4As9lPxxVAErz3ypAAAAJk"]
[Tue Jul 21 07:46:43.754941 2026] [security2:error] [pid 302018:tid 302190] [client 74.7.230.0:45382] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "novo.mannucarvalho.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al9OE4As9lPxxVAErz3yowAArTc"], referer: https://novo.mannucarvalho.com/robots.txt
[Tue Jul 21 07:46:43.821104 2026] [security2:error] [pid 302018:tid 302107] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OE4As9lPxxVAErz3ypwAA0VY"]
[Tue Jul 21 07:46:43.821239 2026] [security2:error] [pid 302018:tid 302226] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OE4As9lPxxVAErz3ypwAA0VY"]
[Tue Jul 21 07:46:43.869414 2026] [security2:error] [pid 302018:tid 302225] [client 20.104.96.117:46678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-css.php"] [unique_id "al9OE4As9lPxxVAErz3yqAAAANA"]
[Tue Jul 21 07:46:44.016891 2026] [security2:error] [pid 302018:tid 302222] [client 103.29.114.44:56272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OFIAs9lPxxVAErz3yrAAAAM0"]
[Tue Jul 21 07:46:44.017015 2026] [security2:error] [pid 302018:tid 302222] [client 103.29.114.44:56272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OFIAs9lPxxVAErz3yrAAAAM0"]
[Tue Jul 21 07:46:44.123321 2026] [security2:error] [pid 302018:tid 302208] [client 59.96.220.140:53304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OFIAs9lPxxVAErz3yrgAAAL8"]
[Tue Jul 21 07:46:44.124183 2026] [security2:error] [pid 302018:tid 302208] [client 59.96.220.140:53304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OFIAs9lPxxVAErz3yrgAAAL8"]
[Tue Jul 21 07:46:44.135282 2026] [security2:error] [pid 302018:tid 302184] [client 20.226.60.151:61607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/xyn.php"] [unique_id "al9OFIAs9lPxxVAErz3yrwAAAKc"]
[Tue Jul 21 07:46:44.186121 2026] [security2:error] [pid 296703:tid 296929] [client 20.197.195.24:16146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9OFCn25uliftkV1n4YYwAAAGA"]
[Tue Jul 21 07:46:44.218838 2026] [security2:error] [pid 296703:tid 296863] [client 182.8.255.181:17585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OFCn25uliftkV1n4YZAAAAB4"]
[Tue Jul 21 07:46:44.219016 2026] [security2:error] [pid 296703:tid 296863] [client 182.8.255.181:17585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OFCn25uliftkV1n4YZAAAAB4"]
[Tue Jul 21 07:46:44.309865 2026] [security2:error] [pid 302018:tid 302206] [client 154.208.47.43:52196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OFIAs9lPxxVAErz3ytQAAAL0"]
[Tue Jul 21 07:46:44.310076 2026] [security2:error] [pid 302018:tid 302206] [client 154.208.47.43:52196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OFIAs9lPxxVAErz3ytQAAAL0"]
[Tue Jul 21 07:46:44.631742 2026] [security2:error] [pid 296703:tid 296950] [client 20.197.195.24:18496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9OFCn25uliftkV1n4YbQAAAHU"]
[Tue Jul 21 07:46:44.668860 2026] [security2:error] [pid 302018:tid 302242] [client 20.206.105.145:29680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/file.php"] [unique_id "al9OFIAs9lPxxVAErz3yvQAAAOE"]
[Tue Jul 21 07:46:44.688017 2026] [security2:error] [pid 302018:tid 302159] [client 152.59.154.239:65458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OFIAs9lPxxVAErz3yvgAAAI4"]
[Tue Jul 21 07:46:44.688128 2026] [security2:error] [pid 302018:tid 302159] [client 152.59.154.239:65458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OFIAs9lPxxVAErz3yvgAAAI4"]
[Tue Jul 21 07:46:44.720932 2026] [autoindex:error] [pid 302018:tid 302189] [client 170.106.180.246:46516] AH01276: Cannot serve directory /home1/domusc58/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:46:44.784149 2026] [security2:error] [pid 296703:tid 296846] [client 144.76.32.114:58284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.32.76.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.alperembalagens.com.br"] [uri "/faleconosco.php"] [unique_id "al9OEin25uliftkV1n4YSgAAAA0"]
[Tue Jul 21 07:46:44.786215 2026] [security2:error] [pid 302018:tid 302262] [client 20.63.100.92:8735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/bscclapb.php"] [unique_id "al9OFIAs9lPxxVAErz3ywgAAAPU"]
[Tue Jul 21 07:46:44.808138 2026] [security2:error] [pid 302018:tid 302276] [client 20.197.195.24:16164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/8.php"] [unique_id "al9OFIAs9lPxxVAErz3ywwAAAQM"]
[Tue Jul 21 07:46:45.020760 2026] [security2:error] [pid 302018:tid 302170] [client 20.197.195.24:16176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/wp-content/admin.php"] [unique_id "al9OFYAs9lPxxVAErz3yyQAAAJk"]
[Tue Jul 21 07:46:45.079035 2026] [security2:error] [pid 302018:tid 302226] [client 20.104.96.117:46621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/ho.php"] [unique_id "al9OFYAs9lPxxVAErz3yygAAANE"]
[Tue Jul 21 07:46:45.147332 2026] [security2:error] [pid 302018:tid 302194] [client 103.86.117.203:50174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OFYAs9lPxxVAErz3yzQAAALE"]
[Tue Jul 21 07:46:45.147515 2026] [security2:error] [pid 302018:tid 302194] [client 103.86.117.203:50174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OFYAs9lPxxVAErz3yzQAAALE"]
[Tue Jul 21 07:46:45.199594 2026] [security2:error] [pid 302018:tid 302216] [client 122.162.144.145:13829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OFYAs9lPxxVAErz3yzgAAAMc"]
[Tue Jul 21 07:46:45.202547 2026] [security2:error] [pid 302018:tid 302216] [client 122.162.144.145:13829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OFYAs9lPxxVAErz3yzgAAAMc"]
[Tue Jul 21 07:46:45.234026 2026] [security2:error] [pid 302018:tid 302161] [client 178.153.91.96:18407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OFYAs9lPxxVAErz3y0gAAAJA"]
[Tue Jul 21 07:46:45.234123 2026] [security2:error] [pid 302018:tid 302161] [client 178.153.91.96:18407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OFYAs9lPxxVAErz3y0gAAAJA"]
[Tue Jul 21 07:46:45.367472 2026] [security2:error] [pid 302018:tid 302069] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OFYAs9lPxxVAErz3y1AAAizA"]
[Tue Jul 21 07:46:45.367597 2026] [security2:error] [pid 302018:tid 302156] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OFYAs9lPxxVAErz3y1AAAizA"]
[Tue Jul 21 07:46:45.534429 2026] [security2:error] [pid 302018:tid 302103] [remote 182.77.62.24:38640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/wp-login.php"] [unique_id "al9OFYAs9lPxxVAErz3y3AAAk1I"]
[Tue Jul 21 07:46:45.723101 2026] [security2:error] [pid 302018:tid 302227] [client 193.36.225.104:46841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OFYAs9lPxxVAErz3y3QAAANI"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:46:45.762489 2026] [security2:error] [pid 302018:tid 302214] [client 109.60.28.94:63154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OFYAs9lPxxVAErz3y3wAAAMU"]
[Tue Jul 21 07:46:46.006168 2026] [security2:error] [pid 296703:tid 296847] [client 20.197.195.24:16180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/f6.php"] [unique_id "al9OFin25uliftkV1n4YgAAAAA4"]
[Tue Jul 21 07:46:46.135704 2026] [security2:error] [pid 302018:tid 302256] [client 20.206.105.145:29663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/aa2.php"] [unique_id "al9OFoAs9lPxxVAErz3y5AAAAO8"]
[Tue Jul 21 07:46:46.366743 2026] [security2:error] [pid 302018:tid 302271] [client 20.197.195.24:16209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/inputs.php"] [unique_id "al9OFoAs9lPxxVAErz3y5wAAAP4"]
[Tue Jul 21 07:46:46.465826 2026] [security2:error] [pid 302018:tid 302242] [client 202.143.127.214:60474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OFoAs9lPxxVAErz3y6AAAAOE"]
[Tue Jul 21 07:46:46.465943 2026] [security2:error] [pid 302018:tid 302242] [client 202.143.127.214:60474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OFoAs9lPxxVAErz3y6AAAAOE"]
[Tue Jul 21 07:46:46.610746 2026] [security2:error] [pid 302018:tid 302094] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OFoAs9lPxxVAErz3y6QAA8kk"]
[Tue Jul 21 07:46:46.610906 2026] [security2:error] [pid 302018:tid 302259] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OFoAs9lPxxVAErz3y6QAA8kk"]
[Tue Jul 21 07:46:46.692688 2026] [security2:error] [pid 296703:tid 296917] [client 106.215.181.8:4938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OFin25uliftkV1n4YjwAAAFQ"]
[Tue Jul 21 07:46:46.692821 2026] [security2:error] [pid 296703:tid 296917] [client 106.215.181.8:4938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OFin25uliftkV1n4YjwAAAFQ"]
[Tue Jul 21 07:46:46.704821 2026] [security2:error] [pid 296703:tid 296934] [client 103.166.103.129:20940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OFin25uliftkV1n4YkAAAAGU"]
[Tue Jul 21 07:46:46.705279 2026] [security2:error] [pid 296703:tid 296934] [client 103.166.103.129:20940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OFin25uliftkV1n4YkAAAAGU"]
[Tue Jul 21 07:46:46.709810 2026] [security2:error] [pid 296703:tid 296910] [client 20.197.195.24:16169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/inputs.php"] [unique_id "al9OFin25uliftkV1n4YkQAAAE0"]
[Tue Jul 21 07:46:46.724880 2026] [security2:error] [pid 296703:tid 296876] [client 51.68.236.73:27011] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cursosonlinesiteoficial.com"] [uri "/robots.txt"] [unique_id "al9OFin25uliftkV1n4YkgAAACs"]
[Tue Jul 21 07:46:46.724968 2026] [security2:error] [pid 296703:tid 296876] [client 51.68.236.73:27011] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.cursosonlinesiteoficial.com"] [uri "/robots.txt"] [unique_id "al9OFin25uliftkV1n4YkgAAACs"]
[Tue Jul 21 07:46:46.810576 2026] [security2:error] [pid 302018:tid 302204] [client 20.197.195.24:16244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/classwithtostring.php"] [unique_id "al9OFoAs9lPxxVAErz3y6wAAALs"]
[Tue Jul 21 07:46:46.812411 2026] [security2:error] [pid 296703:tid 296733] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OFin25uliftkV1n4YlQAAUx0"]
[Tue Jul 21 07:46:46.812575 2026] [security2:error] [pid 296703:tid 296916] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OFin25uliftkV1n4YlQAAUx0"]
[Tue Jul 21 07:46:46.910762 2026] [security2:error] [pid 302018:tid 302124] [remote 69.171.234.23:63762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9OFoAs9lPxxVAErz3y6gAA9mc"]
[Tue Jul 21 07:46:47.001272 2026] [security2:error] [pid 296703:tid 296869] [client 62.102.148.187:50630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9OFyn25uliftkV1n4YmgAAACQ"]
[Tue Jul 21 07:46:47.001350 2026] [security2:error] [pid 296703:tid 296869] [client 62.102.148.187:50630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9OFyn25uliftkV1n4YmgAAACQ"]
[Tue Jul 21 07:46:47.027840 2026] [security2:error] [pid 302018:tid 302196] [client 20.197.195.24:16194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9OF4As9lPxxVAErz3y7gAAALM"]
[Tue Jul 21 07:46:47.047381 2026] [security2:error] [pid 296703:tid 296785] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OFyn25uliftkV1n4YnAAAclE"]
[Tue Jul 21 07:46:47.047555 2026] [security2:error] [pid 296703:tid 296947] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OFyn25uliftkV1n4YnAAAclE"]
[Tue Jul 21 07:46:47.161974 2026] [security2:error] [pid 296703:tid 296932] [client 20.63.100.92:9055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/else1.php"] [unique_id "al9OFyn25uliftkV1n4YoAAAAGM"]
[Tue Jul 21 07:46:47.197374 2026] [security2:error] [pid 296703:tid 296854] [client 20.197.195.24:16201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/wp-blog.php"] [unique_id "al9OFyn25uliftkV1n4YowAAABU"]
[Tue Jul 21 07:46:47.291193 2026] [security2:error] [pid 296703:tid 296843] [client 20.104.96.117:46667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/xy.php"] [unique_id "al9OFyn25uliftkV1n4YpAAAAAo"]
[Tue Jul 21 07:46:47.354798 2026] [security2:error] [pid 302018:tid 302265] [client 20.197.195.24:16142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/wp-content/admin.php"] [unique_id "al9OF4As9lPxxVAErz3y8gAAAPg"]
[Tue Jul 21 07:46:47.356288 2026] [security2:error] [pid 296703:tid 296765] [remote 173.252.69.7:35806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.69.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9OFyn25uliftkV1n4YogAAHj0"]
[Tue Jul 21 07:46:47.379159 2026] [security2:error] [pid 302018:tid 302106] [remote 54.39.136.10:19974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bcsenepol.com.br"] [uri "/tag/swimming/"] [unique_id "al9OF4As9lPxxVAErz3y8wAAsVU"]
[Tue Jul 21 07:46:47.379341 2026] [security2:error] [pid 302018:tid 302194] [client 54.39.136.10:19974] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bcsenepol.com.br"] [uri "/tag/swimming/"] [unique_id "al9OF4As9lPxxVAErz3y8wAAsVU"]
[Tue Jul 21 07:46:47.460279 2026] [security2:error] [pid 302018:tid 302158] [client 74.7.241.148:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "romuloalexssandro1766405717000.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9OF4As9lPxxVAErz3y9AAAjUI"]
[Tue Jul 21 07:46:47.577440 2026] [security2:error] [pid 302018:tid 302180] [client 20.226.60.151:61504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/patie.php"] [unique_id "al9OF4As9lPxxVAErz3y-AAAAKM"]
[Tue Jul 21 07:46:47.641193 2026] [security2:error] [pid 302018:tid 302091] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OF4As9lPxxVAErz3y-gAAx0Y"]
[Tue Jul 21 07:46:47.641347 2026] [security2:error] [pid 302018:tid 302216] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OF4As9lPxxVAErz3y-gAAx0Y"]
[Tue Jul 21 07:46:47.696422 2026] [security2:error] [pid 296703:tid 296835] [client 20.197.195.24:16237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/ms-edit.php"] [unique_id "al9OFyn25uliftkV1n4YqwAAAAI"]
[Tue Jul 21 07:46:47.754557 2026] [security2:error] [pid 296703:tid 296852] [client 193.36.225.58:62865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OFyn25uliftkV1n4YrAAAABM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:46:48.051088 2026] [security2:error] [pid 296703:tid 296949] [client 117.217.38.194:61853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OGCn25uliftkV1n4YsQAAAHQ"]
[Tue Jul 21 07:46:48.051194 2026] [security2:error] [pid 296703:tid 296949] [client 117.217.38.194:61853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OGCn25uliftkV1n4YsQAAAHQ"]
[Tue Jul 21 07:46:48.056579 2026] [security2:error] [pid 296703:tid 296881] [client 20.151.10.161:43992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/ccs.php"] [unique_id "al9OGCn25uliftkV1n4YsgAAADA"]
[Tue Jul 21 07:46:48.131562 2026] [security2:error] [pid 302018:tid 302219] [client 131.226.101.54:43849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.101.226.131.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guilhermeverissimo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OGIAs9lPxxVAErz3y_QAAAMo"]
[Tue Jul 21 07:46:48.131673 2026] [security2:error] [pid 302018:tid 302219] [client 131.226.101.54:43849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "guilhermeverissimo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OGIAs9lPxxVAErz3y_QAAAMo"]
[Tue Jul 21 07:46:48.170579 2026] [security2:error] [pid 296703:tid 296880] [client 20.206.105.145:56695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/ccou.php"] [unique_id "al9OGCn25uliftkV1n4YtwAAAC8"]
[Tue Jul 21 07:46:48.213246 2026] [security2:error] [pid 296703:tid 296958] [client 122.164.127.47:52446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OGCn25uliftkV1n4YuAAAAH0"]
[Tue Jul 21 07:46:48.213367 2026] [security2:error] [pid 296703:tid 296958] [client 122.164.127.47:52446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OGCn25uliftkV1n4YuAAAAH0"]
[Tue Jul 21 07:46:48.221807 2026] [security2:error] [pid 302018:tid 302118] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OGIAs9lPxxVAErz3y_wAAhWE"]
[Tue Jul 21 07:46:48.221985 2026] [security2:error] [pid 302018:tid 302150] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OGIAs9lPxxVAErz3y_wAAhWE"]
[Tue Jul 21 07:46:48.255432 2026] [security2:error] [pid 302018:tid 302270] [client 20.197.195.24:16183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/cgi-bin/index.php"] [unique_id "al9OGIAs9lPxxVAErz3zAAAAAP0"]
[Tue Jul 21 07:46:48.508365 2026] [security2:error] [pid 302018:tid 302154] [client 20.197.195.24:11296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/BDKR28WP.php"] [unique_id "al9OGIAs9lPxxVAErz3zBAAAAIk"]
[Tue Jul 21 07:46:48.614454 2026] [security2:error] [pid 296703:tid 296904] [client 144.76.23.116:40850] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "drapatriciavarella.com.br"] [uri "/index.php"] [unique_id "al9OGCn25uliftkV1n4YuQAAAEc"]
[Tue Jul 21 07:46:48.707900 2026] [security2:error] [pid 302018:tid 302229] [client 20.197.195.24:18504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/abcd.php"] [unique_id "al9OGIAs9lPxxVAErz3zCQAAANQ"]
[Tue Jul 21 07:46:48.908751 2026] [security2:error] [pid 302018:tid 302259] [client 20.197.195.24:16152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/file15.php"] [unique_id "al9OGIAs9lPxxVAErz3zCwAAAPI"]
[Tue Jul 21 07:46:49.133511 2026] [security2:error] [pid 296703:tid 296752] [remote 132.148.72.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-login.php"] [unique_id "al9OGSn25uliftkV1n4YwwAAUzA"]
[Tue Jul 21 07:46:49.152797 2026] [security2:error] [pid 296703:tid 296842] [client 20.151.10.161:43911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/ccc.php"] [unique_id "al9OGSn25uliftkV1n4YxAAAAAk"]
[Tue Jul 21 07:46:49.155630 2026] [security2:error] [pid 296703:tid 296838] [client 20.197.195.24:16206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/jp.php"] [unique_id "al9OGSn25uliftkV1n4YxQAAAAU"]
[Tue Jul 21 07:46:49.257657 2026] [security2:error] [pid 302018:tid 302172] [client 223.236.153.128:4595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OGYAs9lPxxVAErz3zEwAAAJs"]
[Tue Jul 21 07:46:49.257775 2026] [security2:error] [pid 302018:tid 302172] [client 223.236.153.128:4595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OGYAs9lPxxVAErz3zEwAAAJs"]
[Tue Jul 21 07:46:49.329014 2026] [security2:error] [pid 302018:tid 302235] [client 20.104.96.117:46633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/loader.php"] [unique_id "al9OGYAs9lPxxVAErz3zFgAAANo"]
[Tue Jul 21 07:46:49.353162 2026] [security2:error] [pid 302018:tid 302223] [client 20.197.195.24:16197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/f35.php"] [unique_id "al9OGYAs9lPxxVAErz3zFwAAAM4"]
[Tue Jul 21 07:46:49.530578 2026] [security2:error] [pid 302018:tid 302157] [client 20.197.195.24:18547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/wp-load.php"] [unique_id "al9OGYAs9lPxxVAErz3zGwAAAIw"]
[Tue Jul 21 07:46:49.540561 2026] [security2:error] [pid 302018:tid 302268] [client 41.68.90.219:53043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OGYAs9lPxxVAErz3zHAAAAPs"]
[Tue Jul 21 07:46:49.543539 2026] [security2:error] [pid 302018:tid 302268] [client 41.68.90.219:53043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OGYAs9lPxxVAErz3zHAAAAPs"]
[Tue Jul 21 07:46:49.616887 2026] [security2:error] [pid 296703:tid 296932] [client 20.197.195.24:18507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/xyn.php"] [unique_id "al9OGSn25uliftkV1n4YzQAAAGM"]
[Tue Jul 21 07:46:49.865048 2026] [security2:error] [pid 302018:tid 302226] [client 144.76.23.116:40860] ModSecurity: Warning. Matched phrase "Trendiction" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "drapatriciavarella.com.br"] [uri "/index.php"] [unique_id "al9OGYAs9lPxxVAErz3zHQAAANE"]
[Tue Jul 21 07:46:49.885833 2026] [security2:error] [pid 302018:tid 302154] [client 20.197.195.24:16182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/ccc.php"] [unique_id "al9OGYAs9lPxxVAErz3zKAAAAIk"]
[Tue Jul 21 07:46:50.073585 2026] [security2:error] [pid 302018:tid 302159] [client 20.197.195.24:16204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/w.php"] [unique_id "al9OGoAs9lPxxVAErz3zKQAAAI4"]
[Tue Jul 21 07:46:50.129538 2026] [security2:error] [pid 302018:tid 302189] [client 20.197.195.24:11268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9OGoAs9lPxxVAErz3zKgAAAKw"]
[Tue Jul 21 07:46:50.261254 2026] [security2:error] [pid 296703:tid 296935] [client 117.247.80.59:33000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OGin25uliftkV1n4Y2QAAAGY"]
[Tue Jul 21 07:46:50.261364 2026] [security2:error] [pid 296703:tid 296935] [client 117.247.80.59:33000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OGin25uliftkV1n4Y2QAAAGY"]
[Tue Jul 21 07:46:50.276402 2026] [security2:error] [pid 302018:tid 302205] [client 122.186.204.214:52863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OGoAs9lPxxVAErz3zLQAAALw"]
[Tue Jul 21 07:46:50.276562 2026] [security2:error] [pid 302018:tid 302205] [client 122.186.204.214:52863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OGoAs9lPxxVAErz3zLQAAALw"]
[Tue Jul 21 07:46:50.326882 2026] [security2:error] [pid 302018:tid 302210] [client 20.197.195.24:16224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/FWAZ.php"] [unique_id "al9OGoAs9lPxxVAErz3zLgAAAME"]
[Tue Jul 21 07:46:50.489215 2026] [security2:error] [pid 296703:tid 296943] [client 20.197.195.24:16147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/miru1.php"] [unique_id "al9OGin25uliftkV1n4Y2wAAAG4"]
[Tue Jul 21 07:46:50.573572 2026] [security2:error] [pid 302018:tid 302242] [client 20.197.195.24:18543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/aa.php"] [unique_id "al9OGoAs9lPxxVAErz3zMAAAAOE"]
[Tue Jul 21 07:46:50.684943 2026] [security2:error] [pid 296703:tid 296862] [client 20.104.96.117:46615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/spadex.php"] [unique_id "al9OGin25uliftkV1n4Y3QAAAB0"]
[Tue Jul 21 07:46:50.751530 2026] [security2:error] [pid 302018:tid 302144] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.expertemrecheios.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9OGoAs9lPxxVAErz3zMgABAXs"]
[Tue Jul 21 07:46:50.797396 2026] [security2:error] [pid 296703:tid 296843] [client 154.192.233.199:59954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OGin25uliftkV1n4Y4QAAAAo"]
[Tue Jul 21 07:46:50.797580 2026] [security2:error] [pid 296703:tid 296843] [client 154.192.233.199:59954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OGin25uliftkV1n4Y4QAAAAo"]
[Tue Jul 21 07:46:50.927611 2026] [security2:error] [pid 302018:tid 302247] [client 20.206.105.145:56663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/dr.php"] [unique_id "al9OGoAs9lPxxVAErz3zNgAAAOY"]
[Tue Jul 21 07:46:50.962553 2026] [security2:error] [pid 302018:tid 302203] [client 62.102.148.187:41692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OGoAs9lPxxVAErz3zNwAAALo"]
[Tue Jul 21 07:46:50.962642 2026] [security2:error] [pid 302018:tid 302203] [client 62.102.148.187:41692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OGoAs9lPxxVAErz3zNwAAALo"]
[Tue Jul 21 07:46:51.118453 2026] [security2:error] [pid 302018:tid 302206] [client 103.174.34.15:51854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OG4As9lPxxVAErz3zPAAAAL0"]
[Tue Jul 21 07:46:51.118564 2026] [security2:error] [pid 302018:tid 302206] [client 103.174.34.15:51854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OG4As9lPxxVAErz3zPAAAAL0"]
[Tue Jul 21 07:46:51.161128 2026] [security2:error] [pid 296703:tid 296864] [client 117.251.86.144:37614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OGyn25uliftkV1n4Y5QAAAB8"]
[Tue Jul 21 07:46:51.161265 2026] [security2:error] [pid 296703:tid 296864] [client 117.251.86.144:37614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OGyn25uliftkV1n4Y5QAAAB8"]
[Tue Jul 21 07:46:51.229306 2026] [security2:error] [pid 296703:tid 296754] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.expertemrecheios.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9OGyn25uliftkV1n4Y5gAAXjI"]
[Tue Jul 21 07:46:51.269266 2026] [security2:error] [pid 302018:tid 302211] [client 20.197.195.24:11264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/122.php"] [unique_id "al9OG4As9lPxxVAErz3zPgAAAMI"]
[Tue Jul 21 07:46:51.523975 2026] [security2:error] [pid 296703:tid 296958] [client 20.197.195.24:16159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/get.php"] [unique_id "al9OGyn25uliftkV1n4Y6wAAAH0"]
[Tue Jul 21 07:46:51.605838 2026] [security2:error] [pid 296703:tid 296859] [client 20.197.195.24:16235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/as.php"] [unique_id "al9OGyn25uliftkV1n4Y7gAAABo"]
[Tue Jul 21 07:46:51.766084 2026] [security2:error] [pid 302018:tid 302173] [client 20.197.195.24:18557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/ccou.php"] [unique_id "al9OG4As9lPxxVAErz3zfgAAAJw"]
[Tue Jul 21 07:46:51.893581 2026] [security2:error] [pid 302018:tid 302079] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.expertemrecheios.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9OG4As9lPxxVAErz3zjQAA1Do"]
[Tue Jul 21 07:46:51.896097 2026] [security2:error] [pid 296703:tid 296857] [client 59.96.220.140:53825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OGyn25uliftkV1n4Y9QAAABg"]
[Tue Jul 21 07:46:51.896203 2026] [security2:error] [pid 296703:tid 296857] [client 59.96.220.140:53825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OGyn25uliftkV1n4Y9QAAABg"]
[Tue Jul 21 07:46:51.901691 2026] [security2:error] [pid 302018:tid 302256] [client 20.197.195.24:16193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/w3lls.php"] [unique_id "al9OG4As9lPxxVAErz3zkAAAAO8"]
[Tue Jul 21 07:46:52.081212 2026] [security2:error] [pid 302018:tid 302276] [client 20.197.195.24:16234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/test1.php"] [unique_id "al9OHIAs9lPxxVAErz3zlAAAAQM"]
[Tue Jul 21 07:46:52.362874 2026] [security2:error] [pid 296703:tid 296732] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.expertemrecheios.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9OHCn25uliftkV1n4Y_QAACRw"]
[Tue Jul 21 07:46:52.506523 2026] [security2:error] [pid 302018:tid 302192] [client 20.197.195.24:16208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/database.php"] [unique_id "al9OHIAs9lPxxVAErz3zmQAAAK8"]
[Tue Jul 21 07:46:52.538089 2026] [security2:error] [pid 302018:tid 302069] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.expertemrecheios.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9OHIAs9lPxxVAErz3zmwAAuzA"]
[Tue Jul 21 07:46:52.560107 2026] [security2:error] [pid 302018:tid 302259] [client 193.36.225.69:23217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OHIAs9lPxxVAErz3zmAAAAPI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:46:52.908084 2026] [security2:error] [pid 302018:tid 302203] [client 20.206.105.145:56677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/file31.php"] [unique_id "al9OHIAs9lPxxVAErz3zoAAAALo"]
[Tue Jul 21 07:46:52.927691 2026] [security2:error] [pid 302018:tid 302184] [client 20.104.96.117:46710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/2x.php"] [unique_id "al9OHIAs9lPxxVAErz3zogAAAKc"]
[Tue Jul 21 07:46:53.252444 2026] [security2:error] [pid 296703:tid 296795] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.expertemrecheios.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9OHSn25uliftkV1n4ZAgAASVs"]
[Tue Jul 21 07:46:53.345250 2026] [security2:error] [pid 302018:tid 302142] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OHYAs9lPxxVAErz3zpgAAiHk"]
[Tue Jul 21 07:46:53.345397 2026] [security2:error] [pid 302018:tid 302153] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OHYAs9lPxxVAErz3zpgAAiHk"]
[Tue Jul 21 07:46:53.569226 2026] [security2:error] [pid 302018:tid 302039] [remote 182.77.62.24:54440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9OHYAs9lPxxVAErz3zrAAAzhI"]
[Tue Jul 21 07:46:53.604421 2026] [security2:error] [pid 302018:tid 302094] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.expertemrecheios.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9OHYAs9lPxxVAErz3zrQAAnEk"]
[Tue Jul 21 07:46:53.912065 2026] [security2:error] [pid 296703:tid 296943] [client 20.63.100.92:6715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/tkikikoko.php"] [unique_id "al9OHSn25uliftkV1n4ZDQAAAG4"]
[Tue Jul 21 07:46:54.012769 2026] [security2:error] [pid 302018:tid 302195] [client 20.197.195.24:11315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/file.php"] [unique_id "al9OHoAs9lPxxVAErz3ztwAAALI"]
[Tue Jul 21 07:46:54.099537 2026] [security2:error] [pid 296703:tid 296846] [client 74.7.241.161:47478] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "psicologo.guiiaz.com.br"] [uri "/index.php"] [unique_id "al9OHSn25uliftkV1n4ZEQAADQU"]
[Tue Jul 21 07:46:54.109497 2026] [security2:error] [pid 302018:tid 302258] [client 173.24.185.52:51094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OHoAs9lPxxVAErz3zugAAAPE"]
[Tue Jul 21 07:46:54.109633 2026] [security2:error] [pid 302018:tid 302258] [client 173.24.185.52:51094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OHoAs9lPxxVAErz3zugAAAPE"]
[Tue Jul 21 07:46:54.134847 2026] [security2:error] [pid 302018:tid 302180] [client 139.167.225.182:49472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OHoAs9lPxxVAErz3zuwAAAKM"]
[Tue Jul 21 07:46:54.134990 2026] [security2:error] [pid 302018:tid 302180] [client 139.167.225.182:49472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OHoAs9lPxxVAErz3zuwAAAKM"]
[Tue Jul 21 07:46:54.253793 2026] [security2:error] [pid 302018:tid 302236] [client 103.29.114.44:56114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OHoAs9lPxxVAErz3zvAAAANs"]
[Tue Jul 21 07:46:54.253935 2026] [security2:error] [pid 302018:tid 302236] [client 103.29.114.44:56114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OHoAs9lPxxVAErz3zvAAAANs"]
[Tue Jul 21 07:46:54.278142 2026] [security2:error] [pid 302018:tid 302166] [client 20.206.105.145:29693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/file6.php"] [unique_id "al9OHoAs9lPxxVAErz3zvQAAAJU"]
[Tue Jul 21 07:46:54.467655 2026] [security2:error] [pid 302018:tid 302118] [remote 165.227.132.137:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.132.227.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OHoAs9lPxxVAErz3zwwAA8mE"], referer: http://assumaocontrole.com/
[Tue Jul 21 07:46:54.470475 2026] [security2:error] [pid 296703:tid 296786] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.expertemrecheios.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9OHin25uliftkV1n4ZFwAAIlI"]
[Tue Jul 21 07:46:54.565482 2026] [security2:error] [pid 302018:tid 302238] [client 122.179.91.63:30423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OHoAs9lPxxVAErz3zxwAAAN0"]
[Tue Jul 21 07:46:54.565613 2026] [security2:error] [pid 302018:tid 302238] [client 122.179.91.63:30423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OHoAs9lPxxVAErz3zxwAAAN0"]
[Tue Jul 21 07:46:54.593744 2026] [security2:error] [pid 296703:tid 296953] [client 182.8.255.181:17511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OHin25uliftkV1n4ZGwAAAHg"]
[Tue Jul 21 07:46:54.593847 2026] [security2:error] [pid 296703:tid 296953] [client 182.8.255.181:17511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OHin25uliftkV1n4ZGwAAAHg"]
[Tue Jul 21 07:46:54.615043 2026] [security2:error] [pid 296703:tid 296712] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OHin25uliftkV1n4ZHAAAAgg"]
[Tue Jul 21 07:46:54.615180 2026] [security2:error] [pid 296703:tid 296835] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OHin25uliftkV1n4ZHAAAAgg"]
[Tue Jul 21 07:46:54.678252 2026] [security2:error] [pid 302018:tid 302251] [client 37.140.223.190:53235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OHYAs9lPxxVAErz3zrgAAAOo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:46:54.777941 2026] [security2:error] [pid 302018:tid 302210] [client 154.208.47.43:52657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OHoAs9lPxxVAErz3z7QAAAME"]
[Tue Jul 21 07:46:54.778095 2026] [security2:error] [pid 302018:tid 302210] [client 154.208.47.43:52657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OHoAs9lPxxVAErz3z7QAAAME"]
[Tue Jul 21 07:46:54.904245 2026] [security2:error] [pid 302018:tid 302099] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.expertemrecheios.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9OHoAs9lPxxVAErz3z7wAAk04"]
[Tue Jul 21 07:46:54.973703 2026] [security2:error] [pid 302018:tid 302216] [client 20.226.60.151:61530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/aa.php"] [unique_id "al9OHoAs9lPxxVAErz3z8AAAAMc"]
[Tue Jul 21 07:46:55.080536 2026] [security2:error] [pid 296703:tid 296837] [client 20.215.50.93:63158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pousadanaturalis.com.br"] [uri "/.env"] [unique_id "al9OHyn25uliftkV1n4ZJAAAAAQ"]
[Tue Jul 21 07:46:55.130081 2026] [security2:error] [pid 302018:tid 302153] [client 192.129.247.173:49562] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "gradiente.com"] [uri "/"] [unique_id "al9OH4As9lPxxVAErz3z9AAAAIg"]
[Tue Jul 21 07:46:55.186088 2026] [security2:error] [pid 296703:tid 296818] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.expertemrecheios.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9OHyn25uliftkV1n4ZJQAASHI"]
[Tue Jul 21 07:46:55.358175 2026] [security2:error] [pid 296703:tid 296925] [client 20.197.195.24:11327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/file.php"] [unique_id "al9OHyn25uliftkV1n4ZKQAAAFw"]
[Tue Jul 21 07:46:55.406502 2026] [security2:error] [pid 302018:tid 302249] [client 194.99.104.35:39582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9OH4As9lPxxVAErz3z9wAAAOg"]
[Tue Jul 21 07:46:55.406619 2026] [security2:error] [pid 302018:tid 302249] [client 194.99.104.35:39582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9OH4As9lPxxVAErz3z9wAAAOg"]
[Tue Jul 21 07:46:55.438059 2026] [access_compat:error] [pid 302018:tid 302152] [client 162.241.63.68:41466] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:46:55.446435 2026] [security2:error] [pid 296703:tid 296864] [client 152.59.154.239:49565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OHyn25uliftkV1n4ZLgAAAB8"]
[Tue Jul 21 07:46:55.446521 2026] [security2:error] [pid 296703:tid 296864] [client 152.59.154.239:49565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OHyn25uliftkV1n4ZLgAAAB8"]
[Tue Jul 21 07:46:55.475802 2026] [security2:error] [pid 302018:tid 302074] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.expertemrecheios.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9OH4As9lPxxVAErz3z-QAAnDU"]
[Tue Jul 21 07:46:55.591680 2026] [security2:error] [pid 296703:tid 296716] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9OHyn25uliftkV1n4ZMAAAXww"]
[Tue Jul 21 07:46:55.620306 2026] [security2:error] [pid 302018:tid 302243] [client 103.86.117.203:50886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OH4As9lPxxVAErz30GAAAAOI"]
[Tue Jul 21 07:46:55.620448 2026] [security2:error] [pid 302018:tid 302243] [client 103.86.117.203:50886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OH4As9lPxxVAErz30GAAAAOI"]
[Tue Jul 21 07:46:55.733793 2026] [security2:error] [pid 296703:tid 296721] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.expertemrecheios.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9OHyn25uliftkV1n4ZMwAAPRE"]
[Tue Jul 21 07:46:55.808841 2026] [security2:error] [pid 302018:tid 302219] [client 178.153.91.96:19097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OH4As9lPxxVAErz30LgAAAMo"]
[Tue Jul 21 07:46:55.808964 2026] [security2:error] [pid 302018:tid 302219] [client 178.153.91.96:19097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OH4As9lPxxVAErz30LgAAAMo"]
[Tue Jul 21 07:46:55.891347 2026] [security2:error] [pid 296703:tid 296944] [client 20.104.96.117:46706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/ctex1.php"] [unique_id "al9OHyn25uliftkV1n4ZNQAAAG8"]
[Tue Jul 21 07:46:56.019001 2026] [security2:error] [pid 302018:tid 302208] [client 122.162.144.145:7700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OIIAs9lPxxVAErz30MAAAAL8"]
[Tue Jul 21 07:46:56.019122 2026] [security2:error] [pid 302018:tid 302208] [client 122.162.144.145:7700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OIIAs9lPxxVAErz30MAAAAL8"]
[Tue Jul 21 07:46:56.057869 2026] [security2:error] [pid 302018:tid 302095] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9OIIAs9lPxxVAErz30MQAA70o"]
[Tue Jul 21 07:46:56.071015 2026] [security2:error] [pid 302018:tid 302231] [client 172.245.102.45:65251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OIIAs9lPxxVAErz30NAAAANY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:46:56.134649 2026] [security2:error] [pid 302018:tid 302191] [client 34.0.61.43:33640] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artix.locaiestetica.com.br"] [uri "/index.html"] [unique_id "al9OIIAs9lPxxVAErz30NQAAAK4"]
[Tue Jul 21 07:46:56.225022 2026] [security2:error] [pid 302018:tid 302141] [remote 195.26.244.42:59190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9OIIAs9lPxxVAErz30OQAAoHg"]
[Tue Jul 21 07:46:56.233852 2026] [security2:error] [pid 296703:tid 296792] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/media.php"] [unique_id "al9OICn25uliftkV1n4ZPAAAbVg"]
[Tue Jul 21 07:46:56.335220 2026] [security2:error] [pid 302018:tid 302259] [client 20.206.105.145:29685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/file15.php"] [unique_id "al9OIIAs9lPxxVAErz30PQAAAPI"]
[Tue Jul 21 07:46:56.384696 2026] [security2:error] [pid 302018:tid 302086] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/images.php"] [unique_id "al9OIIAs9lPxxVAErz30QAAAs0E"]
[Tue Jul 21 07:46:56.472074 2026] [security2:error] [pid 296703:tid 296733] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OICn25uliftkV1n4ZQQAAZh0"]
[Tue Jul 21 07:46:56.472211 2026] [security2:error] [pid 296703:tid 296935] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OICn25uliftkV1n4ZQQAAZh0"]
[Tue Jul 21 07:46:56.536756 2026] [security2:error] [pid 296703:tid 296764] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/gecko.php"] [unique_id "al9OICn25uliftkV1n4ZRAAAbjw"]
[Tue Jul 21 07:46:56.726980 2026] [security2:error] [pid 296703:tid 296785] [remote 159.223.116.62:37960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.116.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/wp-login.php"] [unique_id "al9OICn25uliftkV1n4ZRwAAQlE"]
[Tue Jul 21 07:46:56.827531 2026] [security2:error] [pid 302018:tid 302118] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/82.php"] [unique_id "al9OIIAs9lPxxVAErz30RQAAzWE"]
[Tue Jul 21 07:46:56.943517 2026] [security2:error] [pid 302018:tid 302251] [client 37.140.223.119:34987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OIIAs9lPxxVAErz30RAAAAOo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:46:57.006963 2026] [security2:error] [pid 296703:tid 296758] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/admin.php"] [unique_id "al9OISn25uliftkV1n4ZTAAACjY"]
[Tue Jul 21 07:46:57.167296 2026] [security2:error] [pid 302018:tid 302178] [client 20.197.195.24:11280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/777.php"] [unique_id "al9OIYAs9lPxxVAErz30TgAAAKE"]
[Tue Jul 21 07:46:57.221219 2026] [security2:error] [pid 302018:tid 302088] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/adminner.php"] [unique_id "al9OIYAs9lPxxVAErz30TwAAxkM"]
[Tue Jul 21 07:46:57.250836 2026] [security2:error] [pid 302018:tid 302075] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OIYAs9lPxxVAErz30UAAAjTY"]
[Tue Jul 21 07:46:57.250995 2026] [security2:error] [pid 302018:tid 302158] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OIYAs9lPxxVAErz30UAAAjTY"]
[Tue Jul 21 07:46:57.297420 2026] [security2:error] [pid 296703:tid 296919] [client 20.215.50.93:63158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "pousadanaturalis.com.br"] [uri "/.env.backup"] [unique_id "al9OISn25uliftkV1n4ZUQAAAFY"]
[Tue Jul 21 07:46:57.352894 2026] [security2:error] [pid 302018:tid 302132] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OIYAs9lPxxVAErz30WwAA8G8"]
[Tue Jul 21 07:46:57.353025 2026] [security2:error] [pid 302018:tid 302257] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OIYAs9lPxxVAErz30WwAA8G8"]
[Tue Jul 21 07:46:57.378051 2026] [security2:error] [pid 296703:tid 296901] [client 106.215.181.8:3581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OISn25uliftkV1n4ZUgAAAEQ"]
[Tue Jul 21 07:46:57.385447 2026] [security2:error] [pid 302018:tid 302266] [client 20.206.105.145:29667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/jp.php"] [unique_id "al9OIYAs9lPxxVAErz30XAAAAPk"]
[Tue Jul 21 07:46:57.387728 2026] [security2:error] [pid 296703:tid 296901] [client 106.215.181.8:3581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OISn25uliftkV1n4ZUgAAAEQ"]
[Tue Jul 21 07:46:57.399644 2026] [security2:error] [pid 296703:tid 296776] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/admin.php"] [unique_id "al9OISn25uliftkV1n4ZUwAAV0g"]
[Tue Jul 21 07:46:57.426727 2026] [security2:error] [pid 296703:tid 296913] [client 103.166.103.129:21501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OISn25uliftkV1n4ZVAAAAFA"]
[Tue Jul 21 07:46:57.427451 2026] [security2:error] [pid 296703:tid 296913] [client 103.166.103.129:21501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OISn25uliftkV1n4ZVAAAAFA"]
[Tue Jul 21 07:46:57.598471 2026] [security2:error] [pid 302018:tid 302163] [client 202.143.127.214:60956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OIYAs9lPxxVAErz30XwAAAJI"]
[Tue Jul 21 07:46:57.598573 2026] [security2:error] [pid 302018:tid 302163] [client 202.143.127.214:60956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OIYAs9lPxxVAErz30XwAAAJI"]
[Tue Jul 21 07:46:57.621964 2026] [security2:error] [pid 302018:tid 302078] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/k.php"] [unique_id "al9OIYAs9lPxxVAErz30YAAAzDk"]
[Tue Jul 21 07:46:57.710104 2026] [security2:error] [pid 302018:tid 302208] [client 20.104.96.117:46620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/edorxrr.php"] [unique_id "al9OIYAs9lPxxVAErz30ZAAAAL8"]
[Tue Jul 21 07:46:57.769744 2026] [security2:error] [pid 296703:tid 296822] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/blurbs.php"] [unique_id "al9OISn25uliftkV1n4ZWQAABnY"]
[Tue Jul 21 07:46:57.923104 2026] [security2:error] [pid 302018:tid 302051] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OIYAs9lPxxVAErz30aQAAoB4"]
[Tue Jul 21 07:46:57.923274 2026] [security2:error] [pid 302018:tid 302177] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OIYAs9lPxxVAErz30aQAAoB4"]
[Tue Jul 21 07:46:58.080117 2026] [security2:error] [pid 302018:tid 302024] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/bajah.php"] [unique_id "al9OIoAs9lPxxVAErz30bAAAmQM"]
[Tue Jul 21 07:46:58.191396 2026] [security2:error] [pid 302018:tid 302120] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OIoAs9lPxxVAErz30bQAAo2M"]
[Tue Jul 21 07:46:58.191528 2026] [security2:error] [pid 302018:tid 302180] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OIoAs9lPxxVAErz30bQAAo2M"]
[Tue Jul 21 07:46:58.255356 2026] [security2:error] [pid 296703:tid 296805] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/a.php"] [unique_id "al9OIin25uliftkV1n4ZXwAATWU"]
[Tue Jul 21 07:46:58.265087 2026] [security2:error] [pid 296703:tid 296917] [client 20.215.50.93:63158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "pousadanaturalis.com.br"] [uri "/.env.old"] [unique_id "al9OIin25uliftkV1n4ZYAAAAFQ"]
[Tue Jul 21 07:46:58.285632 2026] [security2:error] [pid 302018:tid 302275] [client 20.206.105.145:56642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/f35.php"] [unique_id "al9OIoAs9lPxxVAErz30cQAAAQI"]
[Tue Jul 21 07:46:58.379566 2026] [security2:error] [pid 296703:tid 296841] [client 185.213.175.37:64866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "areademembros.paginadoproduto-oficial.com.br"] [uri "/wp-content/plugins/tutor-pro/assets/css/front.css"] [unique_id "al9OIin25uliftkV1n4ZZAAAAAg"]
[Tue Jul 21 07:46:58.379649 2026] [security2:error] [pid 296703:tid 296841] [client 185.213.175.37:64866] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "areademembros.paginadoproduto-oficial.com.br"] [uri "/wp-content/plugins/tutor-pro/assets/css/front.css"] [unique_id "al9OIin25uliftkV1n4ZZAAAAAg"]
[Tue Jul 21 07:46:58.453968 2026] [security2:error] [pid 302018:tid 302129] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/edit.php"] [unique_id "al9OIoAs9lPxxVAErz30egAAkGw"]
[Tue Jul 21 07:46:58.537114 2026] [security2:error] [pid 302018:tid 302230] [client 117.217.38.194:62340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OIoAs9lPxxVAErz30fAAAANU"]
[Tue Jul 21 07:46:58.537238 2026] [security2:error] [pid 302018:tid 302230] [client 117.217.38.194:62340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OIoAs9lPxxVAErz30fAAAANU"]
[Tue Jul 21 07:46:58.616110 2026] [security2:error] [pid 296703:tid 296752] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/hosty.php"] [unique_id "al9OIin25uliftkV1n4ZawAABTA"]
[Tue Jul 21 07:46:58.685337 2026] [security2:error] [pid 302018:tid 302138] [remote 95.108.213.119:44050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.213.108.95.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "professoraclaudiaaguiar.com.br"] [uri "/"] [unique_id "al9OIYAs9lPxxVAErz30YgAA0nU"]
[Tue Jul 21 07:46:58.810802 2026] [security2:error] [pid 302018:tid 302052] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/k.php"] [unique_id "al9OIoAs9lPxxVAErz30fwAAjR8"]
[Tue Jul 21 07:46:58.822485 2026] [security2:error] [pid 296703:tid 296893] [client 122.164.127.47:53021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OIin25uliftkV1n4ZcQAAADw"]
[Tue Jul 21 07:46:58.822614 2026] [security2:error] [pid 296703:tid 296893] [client 122.164.127.47:53021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OIin25uliftkV1n4ZcQAAADw"]
[Tue Jul 21 07:46:58.915015 2026] [security2:error] [pid 302018:tid 302257] [client 20.197.195.24:16199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/ssixta.php"] [unique_id "al9OIoAs9lPxxVAErz30gAAAAPA"]
[Tue Jul 21 07:46:58.958978 2026] [security2:error] [pid 296703:tid 296810] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/aaa.php"] [unique_id "al9OIin25uliftkV1n4ZcwAAdmo"]
[Tue Jul 21 07:46:58.992922 2026] [security2:error] [pid 296703:tid 296813] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OIin25uliftkV1n4ZdAAAP20"]
[Tue Jul 21 07:46:58.993085 2026] [security2:error] [pid 296703:tid 296896] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OIin25uliftkV1n4ZdAAAP20"]
[Tue Jul 21 07:46:59.053639 2026] [security2:error] [pid 302018:tid 302189] [client 20.206.105.145:56617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-load.php"] [unique_id "al9OI4As9lPxxVAErz30ggAAAKw"]
[Tue Jul 21 07:46:59.169277 2026] [security2:error] [pid 302018:tid 302133] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/file5.php"] [unique_id "al9OI4As9lPxxVAErz30hwAA1HA"]
[Tue Jul 21 07:46:59.329380 2026] [security2:error] [pid 302018:tid 302196] [client 20.104.96.117:46656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/miru1.php"] [unique_id "al9OI4As9lPxxVAErz30jQAAALM"]
[Tue Jul 21 07:46:59.347610 2026] [security2:error] [pid 296703:tid 296738] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/222.php"] [unique_id "al9OIyn25uliftkV1n4ZeQAAZiI"]
[Tue Jul 21 07:46:59.563131 2026] [security2:error] [pid 302018:tid 302073] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/test.php"] [unique_id "al9OI4As9lPxxVAErz30kgAA8jQ"]
[Tue Jul 21 07:46:59.642941 2026] [security2:error] [pid 302018:tid 302185] [client 1.39.117.130:23000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OIoAs9lPxxVAErz30cwAAAKg"]
[Tue Jul 21 07:46:59.734350 2026] [security2:error] [pid 296703:tid 296756] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/aaa.php"] [unique_id "al9OIyn25uliftkV1n4ZggAAKDQ"]
[Tue Jul 21 07:46:59.860170 2026] [security2:error] [pid 302018:tid 302158] [client 20.63.100.92:4549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9OI4As9lPxxVAErz30nAAAAI0"]
[Tue Jul 21 07:46:59.888219 2026] [security2:error] [pid 296703:tid 296931] [client 223.236.153.128:2956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OIyn25uliftkV1n4ZgwAAAGI"]
[Tue Jul 21 07:46:59.890917 2026] [security2:error] [pid 296703:tid 296931] [client 223.236.153.128:2956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OIyn25uliftkV1n4ZgwAAAGI"]
[Tue Jul 21 07:46:59.907151 2026] [security2:error] [pid 302018:tid 302204] [client 103.174.34.15:52356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OI4As9lPxxVAErz30ngAAALs"]
[Tue Jul 21 07:46:59.907230 2026] [security2:error] [pid 302018:tid 302204] [client 103.174.34.15:52356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OI4As9lPxxVAErz30ngAAALs"]
[Tue Jul 21 07:47:00.019072 2026] [security2:error] [pid 296703:tid 296939] [client 193.36.225.103:21141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OIin25uliftkV1n4ZcgAAAGo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:47:00.037191 2026] [security2:error] [pid 302018:tid 302208] [client 20.226.60.151:61547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/xwpg.php"] [unique_id "al9OJIAs9lPxxVAErz30ogAAAL8"]
[Tue Jul 21 07:47:00.163687 2026] [security2:error] [pid 302018:tid 302036] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/11.php"] [unique_id "al9OJIAs9lPxxVAErz30pQAA3A8"]
[Tue Jul 21 07:47:00.328358 2026] [security2:error] [pid 302018:tid 302093] [remote 61.28.226.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.226.28.61.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OJIAs9lPxxVAErz30rAAAmEg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:47:00.331605 2026] [security2:error] [pid 296703:tid 296807] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/mac.php"] [unique_id "al9OJCn25uliftkV1n4ZiAAAeGc"]
[Tue Jul 21 07:47:00.342692 2026] [security2:error] [pid 302018:tid 302074] [remote 61.28.226.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.226.28.61.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OJIAs9lPxxVAErz30rgAApzU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:47:00.383060 2026] [security2:error] [pid 296703:tid 296895] [client 41.68.90.219:53445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OJCn25uliftkV1n4ZigAAAD4"]
[Tue Jul 21 07:47:00.384114 2026] [security2:error] [pid 296703:tid 296895] [client 41.68.90.219:53445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OJCn25uliftkV1n4ZigAAAD4"]
[Tue Jul 21 07:47:00.505329 2026] [security2:error] [pid 296703:tid 296878] [client 20.197.195.24:16198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/1c.php"] [unique_id "al9OJCn25uliftkV1n4ZiwAAAC0"]
[Tue Jul 21 07:47:00.542660 2026] [security2:error] [pid 296703:tid 296722] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/chosen.php"] [unique_id "al9OJCn25uliftkV1n4ZjAAAVhI"]
[Tue Jul 21 07:47:00.634996 2026] [security2:error] [pid 302018:tid 302153] [client 20.206.105.145:56643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9OJIAs9lPxxVAErz30tAAAAIg"]
[Tue Jul 21 07:47:00.723368 2026] [security2:error] [pid 302018:tid 302027] [remote 61.28.226.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.226.28.61.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OJIAs9lPxxVAErz30tgAA6AY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:47:00.733654 2026] [security2:error] [pid 296703:tid 296740] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/cream1.php"] [unique_id "al9OJCn25uliftkV1n4ZkQAAXSQ"]
[Tue Jul 21 07:47:00.741555 2026] [security2:error] [pid 302018:tid 302098] [remote 61.28.226.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.226.28.61.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OJIAs9lPxxVAErz30uAAAlU0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:47:00.844348 2026] [security2:error] [pid 296703:tid 296911] [client 117.247.80.59:28216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OJCn25uliftkV1n4ZlAAAAE4"]
[Tue Jul 21 07:47:00.844474 2026] [security2:error] [pid 296703:tid 296911] [client 117.247.80.59:28216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OJCn25uliftkV1n4ZlAAAAE4"]
[Tue Jul 21 07:47:00.986696 2026] [security2:error] [pid 302018:tid 302196] [client 122.186.204.214:53668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OJIAs9lPxxVAErz30zwAAALM"]
[Tue Jul 21 07:47:00.986778 2026] [security2:error] [pid 302018:tid 302196] [client 122.186.204.214:53668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OJIAs9lPxxVAErz30zwAAALM"]
[Tue Jul 21 07:47:01.116236 2026] [security2:error] [pid 302018:tid 302061] [remote 61.28.226.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.226.28.61.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OJYAs9lPxxVAErz300AAAuyg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:47:01.435413 2026] [security2:error] [pid 296703:tid 296893] [client 20.206.105.145:56599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-links.php"] [unique_id "al9OJSn25uliftkV1n4ZowAAADw"]
[Tue Jul 21 07:47:01.440633 2026] [security2:error] [pid 296703:tid 296842] [client 20.215.50.93:63158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "pousadanaturalis.com.br"] [uri "/.env.bak"] [unique_id "al9OJSn25uliftkV1n4ZpAAAAAk"]
[Tue Jul 21 07:47:01.462535 2026] [security2:error] [pid 302018:tid 302042] [remote 61.28.226.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.226.28.61.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OJIAs9lPxxVAErz30qAAA9BU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:47:01.466355 2026] [security2:error] [pid 302018:tid 302257] [client 154.192.233.199:59597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OJYAs9lPxxVAErz302QAAAPA"]
[Tue Jul 21 07:47:01.466491 2026] [security2:error] [pid 302018:tid 302257] [client 154.192.233.199:59597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OJYAs9lPxxVAErz302QAAAPA"]
[Tue Jul 21 07:47:01.516415 2026] [security2:error] [pid 302018:tid 302143] [remote 61.28.226.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.226.28.61.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OJYAs9lPxxVAErz303gAApHo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:47:01.573158 2026] [security2:error] [pid 302018:tid 302163] [client 172.245.102.43:41801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.245.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OJYAs9lPxxVAErz303wAAAJI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:47:01.732159 2026] [security2:error] [pid 296703:tid 296794] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/dr.php"] [unique_id "al9OJSn25uliftkV1n4ZqgAAGVo"]
[Tue Jul 21 07:47:01.772716 2026] [security2:error] [pid 296703:tid 296864] [client 117.251.86.144:48178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OJSn25uliftkV1n4ZrQAAAB8"]
[Tue Jul 21 07:47:01.773126 2026] [security2:error] [pid 296703:tid 296864] [client 117.251.86.144:48178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OJSn25uliftkV1n4ZrQAAAB8"]
[Tue Jul 21 07:47:01.843393 2026] [security2:error] [pid 302018:tid 302079] [remote 61.28.226.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.226.28.61.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OJYAs9lPxxVAErz306QAAqDo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:47:01.905136 2026] [security2:error] [pid 302018:tid 302096] [remote 61.28.226.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.226.28.61.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OJYAs9lPxxVAErz307AAA0Us"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:47:01.921597 2026] [security2:error] [pid 296703:tid 296750] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/x.php"] [unique_id "al9OJSn25uliftkV1n4ZsAAAYS4"]
[Tue Jul 21 07:47:02.032232 2026] [security2:error] [pid 296703:tid 296863] [client 20.197.195.24:16191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/test2.php"] [unique_id "al9OJin25uliftkV1n4ZswAAAB4"]
[Tue Jul 21 07:47:02.070417 2026] [security2:error] [pid 296703:tid 296771] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/155.php"] [unique_id "al9OJin25uliftkV1n4ZtAAAYEM"]
[Tue Jul 21 07:47:02.160731 2026] [security2:error] [pid 296703:tid 296943] [client 20.104.96.117:27110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/sump1.php"] [unique_id "al9OJin25uliftkV1n4ZtgAAAG4"]
[Tue Jul 21 07:47:02.218857 2026] [security2:error] [pid 296703:tid 296773] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/ops.php"] [unique_id "al9OJin25uliftkV1n4ZuAAAG0U"]
[Tue Jul 21 07:47:02.218906 2026] [security2:error] [pid 302018:tid 302131] [remote 61.28.226.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.226.28.61.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OJoAs9lPxxVAErz308QAA_24"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:47:02.331466 2026] [security2:error] [pid 302018:tid 302062] [remote 61.28.226.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.226.28.61.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OJIAs9lPxxVAErz30rQAAlSk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:47:02.349071 2026] [security2:error] [pid 302018:tid 302095] [remote 61.28.226.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.226.28.61.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OJoAs9lPxxVAErz309gAAiko"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:47:02.431175 2026] [security2:error] [pid 296703:tid 296769] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/file31.php"] [unique_id "al9OJin25uliftkV1n4ZvAAAYkE"]
[Tue Jul 21 07:47:02.518124 2026] [security2:error] [pid 302018:tid 302033] [remote 61.28.226.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.226.28.61.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OJoAs9lPxxVAErz30-gAA4gw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:47:02.597328 2026] [security2:error] [pid 302018:tid 302086] [remote 61.28.226.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.226.28.61.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OJoAs9lPxxVAErz30_AAAxkE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:47:02.713839 2026] [security2:error] [pid 302018:tid 302152] [client 20.206.105.145:29675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/solo1.php"] [unique_id "al9OJoAs9lPxxVAErz30_gAAAIc"]
[Tue Jul 21 07:47:02.723389 2026] [security2:error] [pid 296703:tid 296709] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/file6.php"] [unique_id "al9OJin25uliftkV1n4ZwAAAHQU"]
[Tue Jul 21 07:47:03.375062 2026] [security2:error] [pid 296703:tid 296763] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/adminfuns.php"] [unique_id "al9OJyn25uliftkV1n4ZzwAAAjs"]
[Tue Jul 21 07:47:03.402773 2026] [security2:error] [pid 302018:tid 302153] [client 20.206.105.145:29648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/sixxis.php"] [unique_id "al9OJ4As9lPxxVAErz31CwAAAIg"]
[Tue Jul 21 07:47:03.501728 2026] [security2:error] [pid 302018:tid 302173] [client 59.96.220.140:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OJ4As9lPxxVAErz31DQAAAJw"]
[Tue Jul 21 07:47:03.502526 2026] [security2:error] [pid 302018:tid 302173] [client 59.96.220.140:54340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OJ4As9lPxxVAErz31DQAAAJw"]
[Tue Jul 21 07:47:03.510934 2026] [security2:error] [pid 296703:tid 296911] [client 20.226.60.151:61514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/ops.php"] [unique_id "al9OJyn25uliftkV1n4Z0QAAAE4"]
[Tue Jul 21 07:47:03.566738 2026] [security2:error] [pid 296703:tid 296790] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/goods.php"] [unique_id "al9OJyn25uliftkV1n4Z0wAAfFY"]
[Tue Jul 21 07:47:03.586528 2026] [security2:error] [pid 296703:tid 296857] [client 20.197.195.24:16248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/buy.php"] [unique_id "al9OJyn25uliftkV1n4Z1AAAABg"]
[Tue Jul 21 07:47:03.868435 2026] [security2:error] [pid 296703:tid 296708] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OJyn25uliftkV1n4Z2QAADwQ"]
[Tue Jul 21 07:47:03.868555 2026] [security2:error] [pid 296703:tid 296848] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OJyn25uliftkV1n4Z2QAADwQ"]
[Tue Jul 21 07:47:03.890726 2026] [security2:error] [pid 296703:tid 296894] [client 20.104.96.117:46712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/file5.php"] [unique_id "al9OJyn25uliftkV1n4Z2gAAAD0"]
[Tue Jul 21 07:47:04.068076 2026] [security2:error] [pid 296703:tid 296767] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/100.php"] [unique_id "al9OKCn25uliftkV1n4Z4AAAHz8"]
[Tue Jul 21 07:47:04.174694 2026] [security2:error] [pid 302018:tid 302053] [remote 132.148.72.88:52962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/wp-login.php"] [unique_id "al9OKIAs9lPxxVAErz31FQAAryA"]
[Tue Jul 21 07:47:04.259182 2026] [security2:error] [pid 296703:tid 296821] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/about.php"] [unique_id "al9OKCn25uliftkV1n4Z5AAASnU"]
[Tue Jul 21 07:47:04.426251 2026] [security2:error] [pid 296703:tid 296714] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/about.php"] [unique_id "al9OKCn25uliftkV1n4Z6AAAdQo"]
[Tue Jul 21 07:47:04.447079 2026] [security2:error] [pid 296703:tid 296943] [client 20.197.195.24:16255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/ssend.php"] [unique_id "al9OKCn25uliftkV1n4Z6QAAAG4"]
[Tue Jul 21 07:47:04.535304 2026] [security2:error] [pid 296703:tid 296912] [client 37.140.223.201:58413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OJin25uliftkV1n4ZuwAAAE8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:47:04.559872 2026] [security2:error] [pid 296703:tid 296935] [client 20.206.105.145:56600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/2P.update.php"] [unique_id "al9OKCn25uliftkV1n4Z7QAAAGY"]
[Tue Jul 21 07:47:04.573697 2026] [security2:error] [pid 296703:tid 296733] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/admin.php"] [unique_id "al9OKCn25uliftkV1n4Z7gAAah0"]
[Tue Jul 21 07:47:04.724046 2026] [security2:error] [pid 296703:tid 296774] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/admin.php"] [unique_id "al9OKCn25uliftkV1n4Z8QAAIkY"]
[Tue Jul 21 07:47:04.801213 2026] [security2:error] [pid 302018:tid 302216] [client 173.24.185.52:51578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OKIAs9lPxxVAErz31KAAAAMc"]
[Tue Jul 21 07:47:04.801330 2026] [security2:error] [pid 302018:tid 302216] [client 173.24.185.52:51578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OKIAs9lPxxVAErz31KAAAAMc"]
[Tue Jul 21 07:47:04.871241 2026] [security2:error] [pid 296703:tid 296785] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/themes.php"] [unique_id "al9OKCn25uliftkV1n4Z9gAAUlE"]
[Tue Jul 21 07:47:04.914641 2026] [security2:error] [pid 302018:tid 302203] [client 20.104.96.117:46622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/0xD.php"] [unique_id "al9OKIAs9lPxxVAErz31KgAAALo"]
[Tue Jul 21 07:47:05.043871 2026] [security2:error] [pid 302018:tid 302252] [client 139.167.225.182:50132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OKYAs9lPxxVAErz31KwAAAOs"]
[Tue Jul 21 07:47:05.044020 2026] [security2:error] [pid 302018:tid 302252] [client 139.167.225.182:50132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OKYAs9lPxxVAErz31KwAAAOs"]
[Tue Jul 21 07:47:05.055365 2026] [security2:error] [pid 302018:tid 302168] [client 182.8.255.181:17487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OKYAs9lPxxVAErz31LAAAAJc"]
[Tue Jul 21 07:47:05.055474 2026] [security2:error] [pid 302018:tid 302168] [client 182.8.255.181:17487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OKYAs9lPxxVAErz31LAAAAJc"]
[Tue Jul 21 07:47:05.120174 2026] [security2:error] [pid 302018:tid 302222] [client 20.197.195.24:18499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/item.php"] [unique_id "al9OKYAs9lPxxVAErz31LwAAAM0"]
[Tue Jul 21 07:47:05.183934 2026] [security2:error] [pid 296703:tid 296834] [client 122.179.91.63:24088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OKSn25uliftkV1n4Z_gAAAAE"]
[Tue Jul 21 07:47:05.184066 2026] [security2:error] [pid 296703:tid 296834] [client 122.179.91.63:24088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OKSn25uliftkV1n4Z_gAAAAE"]
[Tue Jul 21 07:47:05.287859 2026] [security2:error] [pid 302018:tid 302144] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OKYAs9lPxxVAErz31MAAAzns"]
[Tue Jul 21 07:47:05.288109 2026] [security2:error] [pid 302018:tid 302223] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OKYAs9lPxxVAErz31MAAAzns"]
[Tue Jul 21 07:47:05.322552 2026] [security2:error] [pid 296703:tid 296843] [client 154.208.47.43:53123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OKSn25uliftkV1n4aAgAAAAo"]
[Tue Jul 21 07:47:05.322697 2026] [security2:error] [pid 296703:tid 296843] [client 154.208.47.43:53123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OKSn25uliftkV1n4aAgAAAAo"]
[Tue Jul 21 07:47:05.357812 2026] [security2:error] [pid 302018:tid 302191] [client 20.63.100.92:7033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/wp-css.php"] [unique_id "al9OKYAs9lPxxVAErz31NQAAAK4"]
[Tue Jul 21 07:47:05.754398 2026] [security2:error] [pid 296703:tid 296916] [client 20.197.195.24:16253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/ss.php"] [unique_id "al9OKSn25uliftkV1n4aCgAAAFM"]
[Tue Jul 21 07:47:05.850017 2026] [security2:error] [pid 302018:tid 302213] [client 20.104.96.117:46717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/fnstall.php"] [unique_id "al9OKYAs9lPxxVAErz31QwAAAMQ"]
[Tue Jul 21 07:47:05.874037 2026] [security2:error] [pid 296703:tid 296705] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/.well-known/about.php"] [unique_id "al9OKSn25uliftkV1n4aDAAADwE"]
[Tue Jul 21 07:47:05.940245 2026] [security2:error] [pid 302018:tid 302205] [client 194.99.104.35:51824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OKYAs9lPxxVAErz31SAAAALw"]
[Tue Jul 21 07:47:05.940331 2026] [security2:error] [pid 302018:tid 302205] [client 194.99.104.35:51824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OKYAs9lPxxVAErz31SAAAALw"]
[Tue Jul 21 07:47:05.970979 2026] [security2:error] [pid 302018:tid 302230] [client 74.249.245.134:24768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9OKYAs9lPxxVAErz31SQAAANU"]
[Tue Jul 21 07:47:06.056030 2026] [security2:error] [pid 296703:tid 296744] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9OKin25uliftkV1n4aEAAAXyg"]
[Tue Jul 21 07:47:06.064406 2026] [security2:error] [pid 302018:tid 302235] [client 20.206.105.145:56649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/a.php"] [unique_id "al9OKoAs9lPxxVAErz31SgAAANo"]
[Tue Jul 21 07:47:06.205460 2026] [security2:error] [pid 296703:tid 296736] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/wefile.php"] [unique_id "al9OKin25uliftkV1n4aFQAAGSA"]
[Tue Jul 21 07:47:06.226378 2026] [security2:error] [pid 302018:tid 302229] [client 103.86.117.203:51631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OKoAs9lPxxVAErz31TAAAANQ"]
[Tue Jul 21 07:47:06.226478 2026] [security2:error] [pid 302018:tid 302229] [client 103.86.117.203:51631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OKoAs9lPxxVAErz31TAAAANQ"]
[Tue Jul 21 07:47:06.344777 2026] [core:error] [pid 296703:tid 296752] [remote 202.78.167.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.royalbsolutions.com/
[Tue Jul 21 07:47:06.344800 2026] [core:error] [pid 296703:tid 296752] [remote 202.78.167.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.royalbsolutions.com/
[Tue Jul 21 07:47:06.404354 2026] [core:error] [pid 302018:tid 302024] [remote 202.78.167.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.royalbsolutions.com/
[Tue Jul 21 07:47:06.404379 2026] [core:error] [pid 302018:tid 302024] [remote 202.78.167.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.royalbsolutions.com/
[Tue Jul 21 07:47:06.405484 2026] [security2:error] [pid 302018:tid 302166] [client 173.252.95.33:53016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9OKoAs9lPxxVAErz31TQAAAJU"]
[Tue Jul 21 07:47:06.423602 2026] [security2:error] [pid 302018:tid 302162] [client 152.59.154.239:41328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OKoAs9lPxxVAErz31VQAAAJE"]
[Tue Jul 21 07:47:06.423720 2026] [security2:error] [pid 302018:tid 302162] [client 152.59.154.239:41328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OKoAs9lPxxVAErz31VQAAAJE"]
[Tue Jul 21 07:47:06.454996 2026] [security2:error] [pid 296703:tid 296746] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9OKin25uliftkV1n4aHQAAHCo"]
[Tue Jul 21 07:47:06.469882 2026] [security2:error] [pid 302018:tid 302156] [client 178.153.91.96:58044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OKoAs9lPxxVAErz31WAAAAIs"]
[Tue Jul 21 07:47:06.470013 2026] [security2:error] [pid 302018:tid 302156] [client 178.153.91.96:58044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OKoAs9lPxxVAErz31WAAAAIs"]
[Tue Jul 21 07:47:06.474598 2026] [core:error] [pid 302018:tid 302129] [remote 202.78.167.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcontacts.royalbsolutions.com/
[Tue Jul 21 07:47:06.474612 2026] [core:error] [pid 302018:tid 302129] [remote 202.78.167.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcontacts.royalbsolutions.com/
[Tue Jul 21 07:47:06.546942 2026] [core:error] [pid 302018:tid 302052] [remote 202.78.167.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.royalbsolutions.com/
[Tue Jul 21 07:47:06.546980 2026] [core:error] [pid 302018:tid 302052] [remote 202.78.167.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.royalbsolutions.com/
[Tue Jul 21 07:47:06.601953 2026] [core:error] [pid 302018:tid 302119] [remote 202.78.167.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.royalbsolutions.com/
[Tue Jul 21 07:47:06.601975 2026] [core:error] [pid 302018:tid 302119] [remote 202.78.167.117:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webmail.royalbsolutions.com/
[Tue Jul 21 07:47:06.636981 2026] [security2:error] [pid 296703:tid 296907] [client 20.104.96.117:46709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/acp.php"] [unique_id "al9OKin25uliftkV1n4aIQAAAEo"]
[Tue Jul 21 07:47:06.810212 2026] [security2:error] [pid 302018:tid 302268] [client 122.162.144.145:28707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OKoAs9lPxxVAErz31aQAAAPs"]
[Tue Jul 21 07:47:06.810293 2026] [security2:error] [pid 302018:tid 302268] [client 122.162.144.145:28707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OKoAs9lPxxVAErz31aQAAAPs"]
[Tue Jul 21 07:47:07.092680 2026] [security2:error] [pid 302018:tid 302272] [client 20.197.195.24:16150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/hypo.php"] [unique_id "al9OK4As9lPxxVAErz31awAAAP8"]
[Tue Jul 21 07:47:07.178310 2026] [security2:error] [pid 296703:tid 296748] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9OKyn25uliftkV1n4aLwAAMCw"]
[Tue Jul 21 07:47:07.227008 2026] [security2:error] [pid 296703:tid 296879] [client 103.29.114.44:8685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OKyn25uliftkV1n4aMAAAAC4"]
[Tue Jul 21 07:47:07.227130 2026] [security2:error] [pid 296703:tid 296879] [client 103.29.114.44:8685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OKyn25uliftkV1n4aMAAAAC4"]
[Tue Jul 21 07:47:07.325568 2026] [security2:error] [pid 302018:tid 302236] [client 20.104.96.117:46671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/mosty.php"] [unique_id "al9OK4As9lPxxVAErz31bgAAANs"]
[Tue Jul 21 07:47:07.326774 2026] [security2:error] [pid 296703:tid 296737] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/8.php"] [unique_id "al9OKyn25uliftkV1n4aMQAAJSE"]
[Tue Jul 21 07:47:07.385621 2026] [security2:error] [pid 302018:tid 302198] [client 20.206.105.145:29654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/k.php"] [unique_id "al9OK4As9lPxxVAErz31cAAAALU"]
[Tue Jul 21 07:47:07.436899 2026] [security2:error] [pid 296703:tid 296897] [client 128.127.105.184:35488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9OKyn25uliftkV1n4aMgAAAEA"]
[Tue Jul 21 07:47:07.436987 2026] [security2:error] [pid 296703:tid 296897] [client 128.127.105.184:35488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9OKyn25uliftkV1n4aMgAAAEA"]
[Tue Jul 21 07:47:07.488191 2026] [security2:error] [pid 296703:tid 296719] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9OKyn25uliftkV1n4aMwAAXg8"]
[Tue Jul 21 07:47:07.620960 2026] [security2:error] [pid 302018:tid 302050] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OK4As9lPxxVAErz31cwAA7x0"]
[Tue Jul 21 07:47:07.621088 2026] [security2:error] [pid 302018:tid 302256] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OK4As9lPxxVAErz31cwAA7x0"]
[Tue Jul 21 07:47:07.656472 2026] [security2:error] [pid 302018:tid 302155] [client 128.127.105.184:43044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9OK4As9lPxxVAErz31dQAAAIo"]
[Tue Jul 21 07:47:07.656548 2026] [security2:error] [pid 302018:tid 302155] [client 128.127.105.184:43044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9OK4As9lPxxVAErz31dQAAAIo"]
[Tue Jul 21 07:47:07.735095 2026] [security2:error] [pid 302018:tid 302208] [client 20.197.195.24:16157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/users.php"] [unique_id "al9OK4As9lPxxVAErz31dwAAAL8"]
[Tue Jul 21 07:47:07.816310 2026] [security2:error] [pid 302018:tid 302045] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OK4As9lPxxVAErz31eQAAqxg"]
[Tue Jul 21 07:47:07.816457 2026] [security2:error] [pid 302018:tid 302188] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OK4As9lPxxVAErz31eQAAqxg"]
[Tue Jul 21 07:47:07.864390 2026] [security2:error] [pid 302018:tid 302157] [client 20.104.96.117:46713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/6.php"] [unique_id "al9OK4As9lPxxVAErz31egAAAIw"]
[Tue Jul 21 07:47:07.880449 2026] [security2:error] [pid 302018:tid 302274] [client 106.215.181.8:15286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OK4As9lPxxVAErz31ewAAAQE"]
[Tue Jul 21 07:47:07.880621 2026] [security2:error] [pid 302018:tid 302274] [client 106.215.181.8:15286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OK4As9lPxxVAErz31ewAAAQE"]
[Tue Jul 21 07:47:07.964533 2026] [security2:error] [pid 302018:tid 302036] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OK4As9lPxxVAErz31fAAArA8"]
[Tue Jul 21 07:47:07.964665 2026] [security2:error] [pid 302018:tid 302189] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OK4As9lPxxVAErz31fAAArA8"]
[Tue Jul 21 07:47:08.017846 2026] [security2:error] [pid 296703:tid 296720] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/f6.php"] [unique_id "al9OLCn25uliftkV1n4aPQAALxA"]
[Tue Jul 21 07:47:08.040805 2026] [security2:error] [pid 302018:tid 302275] [client 20.63.100.92:1874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/wp-explorer.php"] [unique_id "al9OLIAs9lPxxVAErz31gAAAAQI"]
[Tue Jul 21 07:47:08.151684 2026] [security2:error] [pid 302018:tid 302252] [client 103.166.103.129:54182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OLIAs9lPxxVAErz31ggAAAOs"]
[Tue Jul 21 07:47:08.152650 2026] [security2:error] [pid 302018:tid 302252] [client 103.166.103.129:54182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OLIAs9lPxxVAErz31ggAAAOs"]
[Tue Jul 21 07:47:08.165251 2026] [security2:error] [pid 296703:tid 296754] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/inputs.php"] [unique_id "al9OLCn25uliftkV1n4aQQAAWTI"]
[Tue Jul 21 07:47:08.212927 2026] [security2:error] [pid 296703:tid 296883] [client 193.36.225.73:41963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OKin25uliftkV1n4aDwAAADI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:47:08.334217 2026] [security2:error] [pid 302018:tid 302272] [client 20.226.60.151:61545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/mac.php"] [unique_id "al9OLIAs9lPxxVAErz31hwAAAP8"]
[Tue Jul 21 07:47:08.357922 2026] [security2:error] [pid 296703:tid 296791] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/inputs.php"] [unique_id "al9OLCn25uliftkV1n4aQwAAV1c"]
[Tue Jul 21 07:47:08.461804 2026] [security2:error] [pid 296703:tid 296911] [client 20.104.96.117:46603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/32e17094cfindex.php"] [unique_id "al9OLCn25uliftkV1n4aRAAAAE4"]
[Tue Jul 21 07:47:08.523629 2026] [security2:error] [pid 302018:tid 302178] [client 20.206.105.145:29573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/w.php"] [unique_id "al9OLIAs9lPxxVAErz31iAAAAKE"]
[Tue Jul 21 07:47:08.529556 2026] [security2:error] [pid 302018:tid 302219] [client 202.143.127.214:61400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OLIAs9lPxxVAErz31iQAAAMo"]
[Tue Jul 21 07:47:08.529699 2026] [security2:error] [pid 302018:tid 302219] [client 202.143.127.214:61400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OLIAs9lPxxVAErz31iQAAAMo"]
[Tue Jul 21 07:47:08.613114 2026] [security2:error] [pid 302018:tid 302164] [client 20.197.195.24:16249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/177.php"] [unique_id "al9OLIAs9lPxxVAErz31iwAAAJM"]
[Tue Jul 21 07:47:08.711893 2026] [security2:error] [pid 296703:tid 296827] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OLCn25uliftkV1n4aSQAAAHs"]
[Tue Jul 21 07:47:08.712042 2026] [security2:error] [pid 296703:tid 296833] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OLCn25uliftkV1n4aSQAAAHs"]
[Tue Jul 21 07:47:08.880269 2026] [security2:error] [pid 302018:tid 302098] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OLIAs9lPxxVAErz31jwAAzU0"]
[Tue Jul 21 07:47:08.880449 2026] [security2:error] [pid 302018:tid 302222] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OLIAs9lPxxVAErz31jwAAzU0"]
[Tue Jul 21 07:47:08.895651 2026] [security2:error] [pid 302018:tid 302166] [client 20.104.96.117:46716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/qqqa.php"] [unique_id "al9OLIAs9lPxxVAErz31kAAAAJU"]
[Tue Jul 21 07:47:08.984772 2026] [security2:error] [pid 296703:tid 296809] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/classwithtostring.php"] [unique_id "al9OLCn25uliftkV1n4aTQAAJ2k"]
[Tue Jul 21 07:47:09.039541 2026] [security2:error] [pid 302018:tid 302153] [client 117.217.38.194:62832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OLYAs9lPxxVAErz31kgAAAIg"]
[Tue Jul 21 07:47:09.039659 2026] [security2:error] [pid 302018:tid 302153] [client 117.217.38.194:62832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OLYAs9lPxxVAErz31kgAAAIg"]
[Tue Jul 21 07:47:09.185154 2026] [security2:error] [pid 296703:tid 296794] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9OLSn25uliftkV1n4aUwAAWlo"]
[Tue Jul 21 07:47:09.245213 2026] [security2:error] [pid 302018:tid 302186] [client 62.102.148.187:43176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9OLYAs9lPxxVAErz31lQAAAKk"]
[Tue Jul 21 07:47:09.245294 2026] [security2:error] [pid 302018:tid 302186] [client 62.102.148.187:43176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9OLYAs9lPxxVAErz31lQAAAKk"]
[Tue Jul 21 07:47:09.314544 2026] [security2:error] [pid 296703:tid 296956] [client 20.206.105.145:29674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/insc.php"] [unique_id "al9OLSn25uliftkV1n4aVQAAAHs"]
[Tue Jul 21 07:47:09.450499 2026] [security2:error] [pid 302018:tid 302157] [client 20.104.96.117:46626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/aunmc.php"] [unique_id "al9OLYAs9lPxxVAErz31mAAAAIw"]
[Tue Jul 21 07:47:09.477835 2026] [security2:error] [pid 302018:tid 302191] [client 20.197.195.24:16160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/config.php"] [unique_id "al9OLYAs9lPxxVAErz31mQAAAK4"]
[Tue Jul 21 07:47:09.497793 2026] [security2:error] [pid 302018:tid 302198] [client 122.164.127.47:53603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OLYAs9lPxxVAErz31mgAAALU"]
[Tue Jul 21 07:47:09.497905 2026] [security2:error] [pid 302018:tid 302198] [client 122.164.127.47:53603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OLYAs9lPxxVAErz31mgAAALU"]
[Tue Jul 21 07:47:09.776981 2026] [security2:error] [pid 302018:tid 302028] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OLYAs9lPxxVAErz31nQAAzAc"]
[Tue Jul 21 07:47:09.777122 2026] [security2:error] [pid 302018:tid 302221] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OLYAs9lPxxVAErz31nQAAzAc"]
[Tue Jul 21 07:47:10.031507 2026] [security2:error] [pid 302018:tid 302160] [client 20.104.96.117:46702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/uoocf.php"] [unique_id "al9OLoAs9lPxxVAErz31oAAAAI8"]
[Tue Jul 21 07:47:10.065400 2026] [security2:error] [pid 296703:tid 296773] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/wp-blog.php"] [unique_id "al9OLin25uliftkV1n4aXwAAdUU"]
[Tue Jul 21 07:47:10.106098 2026] [security2:error] [pid 296703:tid 296902] [client 20.206.105.145:56703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9OLin25uliftkV1n4aYgAAAEU"]
[Tue Jul 21 07:47:10.360276 2026] [security2:error] [pid 296703:tid 296881] [client 20.215.50.93:63158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pousadanaturalis.com.br"] [uri "/config/.env"] [unique_id "al9OLin25uliftkV1n4aZwAAADA"]
[Tue Jul 21 07:47:10.524097 2026] [security2:error] [pid 302018:tid 302216] [client 74.249.245.134:64105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9OLoAs9lPxxVAErz31qQAAAMc"]
[Tue Jul 21 07:47:10.532449 2026] [security2:error] [pid 296703:tid 296879] [client 20.104.96.117:46704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/iywwi.php"] [unique_id "al9OLin25uliftkV1n4aaQAAAC4"]
[Tue Jul 21 07:47:10.550505 2026] [security2:error] [pid 302018:tid 302268] [client 103.174.34.15:52854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OLoAs9lPxxVAErz31qgAAAPs"]
[Tue Jul 21 07:47:10.550609 2026] [security2:error] [pid 302018:tid 302268] [client 103.174.34.15:52854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OLoAs9lPxxVAErz31qgAAAPs"]
[Tue Jul 21 07:47:10.632022 2026] [security2:error] [pid 296703:tid 296935] [client 20.197.195.24:11265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/gettest.php"] [unique_id "al9OLin25uliftkV1n4abAAAAGY"]
[Tue Jul 21 07:47:10.656994 2026] [security2:error] [pid 302018:tid 302247] [client 223.236.153.128:5890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OLoAs9lPxxVAErz31rQAAAOY"]
[Tue Jul 21 07:47:10.657070 2026] [security2:error] [pid 302018:tid 302247] [client 223.236.153.128:5890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OLoAs9lPxxVAErz31rQAAAOY"]
[Tue Jul 21 07:47:11.230720 2026] [security2:error] [pid 302018:tid 302196] [client 20.63.100.92:6114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/akismet.php"] [unique_id "al9OL4As9lPxxVAErz31swAAALM"]
[Tue Jul 21 07:47:11.262265 2026] [security2:error] [pid 296703:tid 296839] [client 20.215.50.93:63158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pousadanaturalis.com.br"] [uri "/app/.env"] [unique_id "al9OLyn25uliftkV1n4aewAAAAY"]
[Tue Jul 21 07:47:11.264988 2026] [security2:error] [pid 302018:tid 302152] [client 20.226.60.151:61505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/mg.php"] [unique_id "al9OL4As9lPxxVAErz31tAAAAIc"]
[Tue Jul 21 07:47:11.292263 2026] [security2:error] [pid 296703:tid 296883] [client 20.104.96.117:46607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/gqgsa.php"] [unique_id "al9OLyn25uliftkV1n4afAAAADI"]
[Tue Jul 21 07:47:11.477677 2026] [security2:error] [pid 296703:tid 296920] [client 20.197.195.24:16161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/min.php"] [unique_id "al9OLyn25uliftkV1n4afQAAAFc"]
[Tue Jul 21 07:47:11.479189 2026] [security2:error] [pid 302018:tid 302204] [client 20.206.105.145:56606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/u.php"] [unique_id "al9OL4As9lPxxVAErz31twAAALs"]
[Tue Jul 21 07:47:11.627766 2026] [security2:error] [pid 296703:tid 296953] [client 117.247.80.59:28250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OLyn25uliftkV1n4afgAAAHg"]
[Tue Jul 21 07:47:11.627902 2026] [security2:error] [pid 296703:tid 296953] [client 117.247.80.59:28250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OLyn25uliftkV1n4afgAAAHg"]
[Tue Jul 21 07:47:11.846333 2026] [security2:error] [pid 296703:tid 296784] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9OLyn25uliftkV1n4ahAAAXVA"]
[Tue Jul 21 07:47:11.993749 2026] [security2:error] [pid 296703:tid 296790] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/ms-edit.php"] [unique_id "al9OLyn25uliftkV1n4ahgAAK1Y"]
[Tue Jul 21 07:47:12.139738 2026] [security2:error] [pid 302018:tid 302160] [client 20.104.96.117:46668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/elbzl.php"] [unique_id "al9OMIAs9lPxxVAErz31vQAAAI8"]
[Tue Jul 21 07:47:12.179306 2026] [security2:error] [pid 296703:tid 296749] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9OMCn25uliftkV1n4ahwAAJi0"]
[Tue Jul 21 07:47:12.365671 2026] [core:error] [pid 296703:tid 296845] [client 20.215.50.93:63158] AH10244: invalid URI path (/../.env)
[Tue Jul 21 07:47:12.501533 2026] [security2:error] [pid 302018:tid 302191] [client 117.251.86.144:41798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OMIAs9lPxxVAErz31wwAAAK4"]
[Tue Jul 21 07:47:12.501685 2026] [security2:error] [pid 302018:tid 302191] [client 117.251.86.144:41798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OMIAs9lPxxVAErz31wwAAAK4"]
[Tue Jul 21 07:47:12.682966 2026] [security2:error] [pid 302018:tid 302235] [client 20.197.195.24:16139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/dvjul.php"] [unique_id "al9OMIAs9lPxxVAErz31xgAAANo"]
[Tue Jul 21 07:47:12.751753 2026] [security2:error] [pid 302018:tid 302225] [client 74.249.245.134:64073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp.php"] [unique_id "al9OMIAs9lPxxVAErz31yAAAANA"]
[Tue Jul 21 07:47:12.862971 2026] [security2:error] [pid 296703:tid 296938] [client 136.144.33.100:34931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OMCn25uliftkV1n4amgAAAGk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:47:12.868831 2026] [security2:error] [pid 302018:tid 302177] [client 41.68.90.219:53872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OMIAs9lPxxVAErz31ygAAAKA"]
[Tue Jul 21 07:47:12.870176 2026] [security2:error] [pid 302018:tid 302177] [client 41.68.90.219:53872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OMIAs9lPxxVAErz31ygAAAKA"]
[Tue Jul 21 07:47:12.930138 2026] [security2:error] [pid 302018:tid 302254] [client 20.206.105.145:56669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/sss.php"] [unique_id "al9OMIAs9lPxxVAErz31ywAAAO0"]
[Tue Jul 21 07:47:12.958309 2026] [security2:error] [pid 296703:tid 296929] [client 20.104.96.117:46638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/adjig.php"] [unique_id "al9OMCn25uliftkV1n4amwAAAGA"]
[Tue Jul 21 07:47:13.021772 2026] [security2:error] [pid 296703:tid 296917] [client 37.140.223.152:38073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OLyn25uliftkV1n4ahQAAAFQ"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:47:13.143446 2026] [security2:error] [pid 302018:tid 302168] [client 20.197.195.24:16170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/biufile.php"] [unique_id "al9OMYAs9lPxxVAErz31zAAAAJc"]
[Tue Jul 21 07:47:13.156568 2026] [security2:error] [pid 296703:tid 296924] [client 154.192.233.199:58626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OMSn25uliftkV1n4anQAAAFs"]
[Tue Jul 21 07:47:13.156707 2026] [security2:error] [pid 296703:tid 296924] [client 154.192.233.199:58626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OMSn25uliftkV1n4anQAAAFs"]
[Tue Jul 21 07:47:13.158591 2026] [security2:error] [pid 302018:tid 302227] [client 122.186.204.214:54296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OMYAs9lPxxVAErz31zQAAANI"]
[Tue Jul 21 07:47:13.158694 2026] [security2:error] [pid 302018:tid 302227] [client 122.186.204.214:54296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OMYAs9lPxxVAErz31zQAAANI"]
[Tue Jul 21 07:47:13.385105 2026] [security2:error] [pid 296703:tid 296774] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9OMSn25uliftkV1n4apgAAMEY"]
[Tue Jul 21 07:47:13.658845 2026] [security2:error] [pid 296703:tid 296870] [client 20.197.195.24:18529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/av.php"] [unique_id "al9OMSn25uliftkV1n4aqgAAACU"]
[Tue Jul 21 07:47:13.839568 2026] [security2:error] [pid 302018:tid 302218] [client 20.206.105.145:56577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/sss.php"] [unique_id "al9OMYAs9lPxxVAErz311gAAAMk"]
[Tue Jul 21 07:47:14.153884 2026] [security2:error] [pid 302018:tid 302231] [client 20.206.105.145:56675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/c.php"] [unique_id "al9OMoAs9lPxxVAErz313QAAANY"]
[Tue Jul 21 07:47:14.156137 2026] [access_compat:error] [pid 302018:tid 302213] [client 186.202.163.107:0] AH01797: client denied by server configuration: /home4/fabi0417/powerflats.com.br/index.php4
[Tue Jul 21 07:47:14.203627 2026] [security2:error] [pid 302018:tid 302269] [client 59.96.220.140:54857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OMoAs9lPxxVAErz313gAAAPw"]
[Tue Jul 21 07:47:14.204384 2026] [security2:error] [pid 302018:tid 302269] [client 59.96.220.140:54857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OMoAs9lPxxVAErz313gAAAPw"]
[Tue Jul 21 07:47:14.231289 2026] [security2:error] [pid 302018:tid 302030] [remote 41.76.214.143:46264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9OMoAs9lPxxVAErz313wAAqAk"]
[Tue Jul 21 07:47:14.264871 2026] [security2:error] [pid 302018:tid 302191] [client 20.104.96.117:46684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/byp.php"] [unique_id "al9OMoAs9lPxxVAErz314QAAAK4"]
[Tue Jul 21 07:47:14.400644 2026] [security2:error] [pid 302018:tid 302032] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OMoAs9lPxxVAErz315AAA_ws"]
[Tue Jul 21 07:47:14.400772 2026] [security2:error] [pid 302018:tid 302272] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OMoAs9lPxxVAErz315AAA_ws"]
[Tue Jul 21 07:47:14.844469 2026] [security2:error] [pid 296703:tid 296837] [client 193.36.225.139:33795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OMin25uliftkV1n4atwAAAAQ"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:47:14.849079 2026] [core:error] [pid 296703:tid 296747] [remote 1.192.195.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.baidu.com/
[Tue Jul 21 07:47:14.849106 2026] [core:error] [pid 296703:tid 296747] [remote 1.192.195.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://www.baidu.com/
[Tue Jul 21 07:47:15.116225 2026] [security2:error] [pid 296703:tid 296925] [client 62.102.148.187:50718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OMyn25uliftkV1n4awAAAAFw"]
[Tue Jul 21 07:47:15.116371 2026] [security2:error] [pid 296703:tid 296925] [client 62.102.148.187:50718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OMyn25uliftkV1n4awAAAAFw"]
[Tue Jul 21 07:47:15.229017 2026] [security2:error] [pid 296703:tid 296926] [client 20.206.105.145:56582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/aa.php"] [unique_id "al9OMyn25uliftkV1n4awgAAAF0"]
[Tue Jul 21 07:47:15.245071 2026] [security2:error] [pid 296703:tid 296833] [client 20.63.100.92:4947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/ace2.php"] [unique_id "al9OMyn25uliftkV1n4awwAAAAA"]
[Tue Jul 21 07:47:15.331410 2026] [security2:error] [pid 296703:tid 296847] [client 139.167.225.182:50781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OMyn25uliftkV1n4axQAAAA4"]
[Tue Jul 21 07:47:15.331549 2026] [security2:error] [pid 296703:tid 296847] [client 139.167.225.182:50781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OMyn25uliftkV1n4axQAAAA4"]
[Tue Jul 21 07:47:15.417083 2026] [security2:error] [pid 296703:tid 296928] [client 20.197.195.24:18559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/coffexium.php"] [unique_id "al9OMyn25uliftkV1n4ayQAAAF8"]
[Tue Jul 21 07:47:15.435392 2026] [security2:error] [pid 296703:tid 296841] [client 173.24.185.52:52048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OMyn25uliftkV1n4aywAAAAg"]
[Tue Jul 21 07:47:15.435485 2026] [security2:error] [pid 296703:tid 296841] [client 173.24.185.52:52048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OMyn25uliftkV1n4aywAAAAg"]
[Tue Jul 21 07:47:15.502027 2026] [security2:error] [pid 302018:tid 302266] [client 184.75.223.211:53478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9OM4As9lPxxVAErz319AAAAPk"]
[Tue Jul 21 07:47:15.502120 2026] [security2:error] [pid 302018:tid 302266] [client 184.75.223.211:53478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9OM4As9lPxxVAErz319AAAAPk"]
[Tue Jul 21 07:47:15.558464 2026] [security2:error] [pid 296703:tid 296752] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/abcd.php"] [unique_id "al9OMyn25uliftkV1n4azQAAWjA"]
[Tue Jul 21 07:47:15.606378 2026] [security2:error] [pid 296703:tid 296880] [client 182.8.255.181:17689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OMyn25uliftkV1n4azgAAAC8"]
[Tue Jul 21 07:47:15.606537 2026] [security2:error] [pid 296703:tid 296880] [client 182.8.255.181:17689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OMyn25uliftkV1n4azgAAAC8"]
[Tue Jul 21 07:47:15.613155 2026] [security2:error] [pid 302018:tid 302092] [remote 65.111.15.57:24343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9OM4As9lPxxVAErz319wAAnkc"]
[Tue Jul 21 07:47:15.613939 2026] [security2:error] [pid 302018:tid 302189] [client 74.7.244.5:41984] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.quattrotech.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9OM4As9lPxxVAErz31-AAArFo"]
[Tue Jul 21 07:47:15.648652 2026] [security2:error] [pid 302018:tid 302225] [client 204.12.208.18:57338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.arcoll.com.br"] [uri "/wp-includes/admin.php"] [unique_id "al9OMoAs9lPxxVAErz316gAAANA"], referer: https://ia.arcoll.com.br/wp-includes/admin.php
[Tue Jul 21 07:47:15.755329 2026] [security2:error] [pid 296703:tid 296775] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/file15.php"] [unique_id "al9OMyn25uliftkV1n4azwAAHEc"]
[Tue Jul 21 07:47:15.783407 2026] [security2:error] [pid 302018:tid 302166] [client 103.29.114.44:36972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OM4As9lPxxVAErz31-gAAAJU"]
[Tue Jul 21 07:47:15.783545 2026] [security2:error] [pid 302018:tid 302166] [client 103.29.114.44:36972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OM4As9lPxxVAErz31-gAAAJU"]
[Tue Jul 21 07:47:15.784977 2026] [security2:error] [pid 302018:tid 302268] [client 109.60.28.94:64572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OM4As9lPxxVAErz31-QAAAPs"]
[Tue Jul 21 07:47:15.864639 2026] [security2:error] [pid 296703:tid 296842] [client 20.104.96.117:46595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/ortasekerli1.php"] [unique_id "al9OMyn25uliftkV1n4a0gAAAAk"]
[Tue Jul 21 07:47:15.875540 2026] [security2:error] [pid 302018:tid 302206] [client 122.179.91.63:30707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OM4As9lPxxVAErz31-wAAAL0"]
[Tue Jul 21 07:47:15.875910 2026] [security2:error] [pid 302018:tid 302206] [client 122.179.91.63:30707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OM4As9lPxxVAErz31-wAAAL0"]
[Tue Jul 21 07:47:15.894260 2026] [security2:error] [pid 302018:tid 302208] [client 154.208.47.43:53589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OM4As9lPxxVAErz31_AAAAL8"]
[Tue Jul 21 07:47:15.894374 2026] [security2:error] [pid 302018:tid 302208] [client 154.208.47.43:53589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OM4As9lPxxVAErz31_AAAAL8"]
[Tue Jul 21 07:47:15.903978 2026] [security2:error] [pid 296703:tid 296746] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/jp.php"] [unique_id "al9OMyn25uliftkV1n4a0wAAHyo"]
[Tue Jul 21 07:47:16.005593 2026] [security2:error] [pid 296703:tid 296810] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9ONCn25uliftkV1n4a3QAAe2o"]
[Tue Jul 21 07:47:16.005749 2026] [security2:error] [pid 296703:tid 296956] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9ONCn25uliftkV1n4a3QAAe2o"]
[Tue Jul 21 07:47:16.038680 2026] [security2:error] [pid 296703:tid 296877] [client 74.249.245.134:24821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/new.php"] [unique_id "al9ONCn25uliftkV1n4a3gAAACw"]
[Tue Jul 21 07:47:16.059175 2026] [security2:error] [pid 296703:tid 296814] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/f35.php"] [unique_id "al9ONCn25uliftkV1n4a3wAAQm4"]
[Tue Jul 21 07:47:16.207959 2026] [security2:error] [pid 302018:tid 302269] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "produto-express.com"] [uri "/index.php"] [unique_id "al9ONIAs9lPxxVAErz32BAAA_BU"]
[Tue Jul 21 07:47:16.209349 2026] [security2:error] [pid 296703:tid 296831] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/wp-load.php"] [unique_id "al9ONCn25uliftkV1n4a5QAAZn8"]
[Tue Jul 21 07:47:16.231077 2026] [security2:error] [pid 296703:tid 296856] [client 20.197.195.24:16141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/core.php"] [unique_id "al9ONCn25uliftkV1n4a5gAAABc"]
[Tue Jul 21 07:47:16.289475 2026] [security2:error] [pid 296703:tid 296943] [client 204.12.208.18:57357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.arcoll.com.br"] [uri "/wp-includes/admin.php"] [unique_id "al9ONCn25uliftkV1n4a5wAAAG4"], referer: https://ia.arcoll.com.br/wp-includes/admin.php
[Tue Jul 21 07:47:16.378176 2026] [security2:error] [pid 296703:tid 296893] [client 20.206.105.145:56691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/100.php"] [unique_id "al9ONCn25uliftkV1n4a6wAAADw"]
[Tue Jul 21 07:47:16.380565 2026] [security2:error] [pid 296703:tid 296748] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/xyn.php"] [unique_id "al9ONCn25uliftkV1n4a7AAANCw"]
[Tue Jul 21 07:47:16.418747 2026] [security2:error] [pid 296703:tid 296901] [client 194.99.104.35:33484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9ONCn25uliftkV1n4a7gAAAEQ"]
[Tue Jul 21 07:47:16.418878 2026] [security2:error] [pid 296703:tid 296901] [client 194.99.104.35:33484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9ONCn25uliftkV1n4a7gAAAEQ"]
[Tue Jul 21 07:47:16.706793 2026] [security2:error] [pid 302018:tid 302260] [client 103.86.117.203:52214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9ONIAs9lPxxVAErz32EAAAAPM"]
[Tue Jul 21 07:47:16.706932 2026] [security2:error] [pid 302018:tid 302260] [client 103.86.117.203:52214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9ONIAs9lPxxVAErz32EAAAAPM"]
[Tue Jul 21 07:47:16.820350 2026] [security2:error] [pid 296703:tid 296849] [client 20.104.96.117:27111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/classwithtostring.php"] [unique_id "al9ONCn25uliftkV1n4a-AAAABA"]
[Tue Jul 21 07:47:16.844412 2026] [security2:error] [pid 302018:tid 302188] [client 204.12.208.18:57364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.arcoll.com.br"] [uri "/wp-includes/admin.php"] [unique_id "al9ONIAs9lPxxVAErz32EgAAAKs"], referer: https://ia.arcoll.com.br/wp-includes/admin.php
[Tue Jul 21 07:47:16.934368 2026] [security2:error] [pid 302018:tid 302198] [client 20.197.195.24:18508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/als.php"] [unique_id "al9ONIAs9lPxxVAErz32FgAAALU"]
[Tue Jul 21 07:47:17.036524 2026] [security2:error] [pid 302018:tid 302177] [client 152.59.154.239:10831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ONYAs9lPxxVAErz32GQAAAKA"]
[Tue Jul 21 07:47:17.036637 2026] [security2:error] [pid 302018:tid 302177] [client 152.59.154.239:10831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ONYAs9lPxxVAErz32GQAAAKA"]
[Tue Jul 21 07:47:17.089354 2026] [security2:error] [pid 302018:tid 302176] [client 178.153.91.96:20545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ONYAs9lPxxVAErz32GgAAAJ8"]
[Tue Jul 21 07:47:17.089541 2026] [security2:error] [pid 302018:tid 302176] [client 178.153.91.96:20545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ONYAs9lPxxVAErz32GgAAAJ8"]
[Tue Jul 21 07:47:17.218680 2026] [security2:error] [pid 302018:tid 302179] [client 136.144.33.215:26939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9ONYAs9lPxxVAErz32GwAAAKI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:47:17.492730 2026] [security2:error] [pid 302018:tid 302192] [client 20.104.96.117:46660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/root.php"] [unique_id "al9ONYAs9lPxxVAErz32IAAAAK8"]
[Tue Jul 21 07:47:17.674416 2026] [security2:error] [pid 302018:tid 302237] [client 122.162.144.145:32983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9ONYAs9lPxxVAErz32IwAAANw"]
[Tue Jul 21 07:47:17.676780 2026] [security2:error] [pid 302018:tid 302237] [client 122.162.144.145:32983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9ONYAs9lPxxVAErz32IwAAANw"]
[Tue Jul 21 07:47:17.863062 2026] [security2:error] [pid 302018:tid 302247] [client 20.197.195.24:16210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/simple.php"] [unique_id "al9ONYAs9lPxxVAErz32JwAAAOY"]
[Tue Jul 21 07:47:18.018725 2026] [security2:error] [pid 296703:tid 296890] [client 20.206.105.145:56667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/footer.php"] [unique_id "al9ONin25uliftkV1n4bEwAAADk"]
[Tue Jul 21 07:47:18.125768 2026] [security2:error] [pid 296703:tid 296713] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/ccc.php"] [unique_id "al9ONin25uliftkV1n4bGQAAYgk"]
[Tue Jul 21 07:47:18.137473 2026] [security2:error] [pid 296703:tid 296899] [client 74.249.245.134:65148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/class-t.api.php"] [unique_id "al9ONin25uliftkV1n4bGwAAAEI"]
[Tue Jul 21 07:47:18.316717 2026] [security2:error] [pid 296703:tid 296800] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/w.php"] [unique_id "al9ONin25uliftkV1n4bHQAAMGA"]
[Tue Jul 21 07:47:18.417401 2026] [security2:error] [pid 302018:tid 302033] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9ONoAs9lPxxVAErz32NQAAqAw"]
[Tue Jul 21 07:47:18.417583 2026] [security2:error] [pid 302018:tid 302185] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9ONoAs9lPxxVAErz32NQAAqAw"]
[Tue Jul 21 07:47:18.418863 2026] [security2:error] [pid 302018:tid 302226] [client 106.215.181.8:26919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ONoAs9lPxxVAErz32NAAAANE"]
[Tue Jul 21 07:47:18.423438 2026] [security2:error] [pid 302018:tid 302226] [client 106.215.181.8:26919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ONoAs9lPxxVAErz32NAAAANE"]
[Tue Jul 21 07:47:18.463704 2026] [security2:error] [pid 296703:tid 296846] [client 20.104.96.117:46606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/sym403.php"] [unique_id "al9ONin25uliftkV1n4bIAAAAA0"]
[Tue Jul 21 07:47:18.538120 2026] [security2:error] [pid 296703:tid 296812] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9ONin25uliftkV1n4bIgAAQGw"]
[Tue Jul 21 07:47:18.558138 2026] [security2:error] [pid 296703:tid 296885] [client 20.197.195.24:16228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/init.php"] [unique_id "al9ONin25uliftkV1n4bJwAAADQ"]
[Tue Jul 21 07:47:18.565729 2026] [security2:error] [pid 302018:tid 302084] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ONoAs9lPxxVAErz32OQAA3T8"]
[Tue Jul 21 07:47:18.565870 2026] [security2:error] [pid 302018:tid 302238] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ONoAs9lPxxVAErz32OQAA3T8"]
[Tue Jul 21 07:47:18.612662 2026] [security2:error] [pid 302018:tid 302038] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ONoAs9lPxxVAErz32OwAA_xE"]
[Tue Jul 21 07:47:18.612794 2026] [security2:error] [pid 302018:tid 302272] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ONoAs9lPxxVAErz32OwAA_xE"]
[Tue Jul 21 07:47:18.688040 2026] [security2:error] [pid 296703:tid 296777] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/FWAZ.php"] [unique_id "al9ONin25uliftkV1n4bKgAARUk"]
[Tue Jul 21 07:47:18.751769 2026] [security2:error] [pid 296703:tid 296853] [client 20.197.195.24:16133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/fpwch.php"] [unique_id "al9ONin25uliftkV1n4bKwAAABQ"]
[Tue Jul 21 07:47:18.865895 2026] [security2:error] [pid 296703:tid 296771] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/miru1.php"] [unique_id "al9ONin25uliftkV1n4bLAAAUEM"]
[Tue Jul 21 07:47:18.959423 2026] [security2:error] [pid 296703:tid 296919] [client 20.197.195.24:18510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/domvf.php"] [unique_id "al9ONin25uliftkV1n4bLQAAAFY"]
[Tue Jul 21 07:47:18.969114 2026] [security2:error] [pid 296703:tid 296949] [client 103.166.103.129:54704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ONin25uliftkV1n4bLgAAAHQ"]
[Tue Jul 21 07:47:18.969233 2026] [security2:error] [pid 296703:tid 296949] [client 103.166.103.129:54704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ONin25uliftkV1n4bLgAAAHQ"]
[Tue Jul 21 07:47:19.029081 2026] [security2:error] [pid 296703:tid 296718] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/aa.php"] [unique_id "al9ONyn25uliftkV1n4bMAAACw4"]
[Tue Jul 21 07:47:19.107837 2026] [security2:error] [pid 296703:tid 296835] [client 20.104.96.117:46700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/v543.php"] [unique_id "al9ONyn25uliftkV1n4bNQAAAAI"]
[Tue Jul 21 07:47:19.228209 2026] [security2:error] [pid 302018:tid 302240] [client 20.197.195.24:16143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/wp.php"] [unique_id "al9ON4As9lPxxVAErz32QgAAAN8"]
[Tue Jul 21 07:47:19.266463 2026] [security2:error] [pid 296703:tid 296815] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ONyn25uliftkV1n4bNwAAPm8"]
[Tue Jul 21 07:47:19.266595 2026] [security2:error] [pid 296703:tid 296895] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ONyn25uliftkV1n4bNwAAPm8"]
[Tue Jul 21 07:47:19.362292 2026] [security2:error] [pid 296703:tid 296833] [client 128.127.105.184:35118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9ONyn25uliftkV1n4bOQAAAAA"]
[Tue Jul 21 07:47:19.362386 2026] [security2:error] [pid 296703:tid 296833] [client 128.127.105.184:35118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9ONyn25uliftkV1n4bOQAAAAA"]
[Tue Jul 21 07:47:19.503801 2026] [security2:error] [pid 296703:tid 296888] [client 117.217.38.194:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ONyn25uliftkV1n4bOgAAADc"]
[Tue Jul 21 07:47:19.503924 2026] [security2:error] [pid 296703:tid 296888] [client 117.217.38.194:63325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ONyn25uliftkV1n4bOgAAADc"]
[Tue Jul 21 07:47:19.586762 2026] [security2:error] [pid 302018:tid 302216] [client 20.197.195.24:16173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/class.php"] [unique_id "al9ON4As9lPxxVAErz32SgAAAMc"]
[Tue Jul 21 07:47:19.670283 2026] [security2:error] [pid 296703:tid 296839] [client 202.143.127.214:62115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ONyn25uliftkV1n4bQQAAAAY"]
[Tue Jul 21 07:47:19.670376 2026] [security2:error] [pid 296703:tid 296839] [client 202.143.127.214:62115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ONyn25uliftkV1n4bQQAAAAY"]
[Tue Jul 21 07:47:19.738035 2026] [security2:error] [pid 296703:tid 296808] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9ONyn25uliftkV1n4bQgAAOGg"]
[Tue Jul 21 07:47:19.738177 2026] [security2:error] [pid 296703:tid 296889] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9ONyn25uliftkV1n4bQgAAOGg"]
[Tue Jul 21 07:47:19.816022 2026] [security2:error] [pid 296703:tid 296817] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/122.php"] [unique_id "al9ONyn25uliftkV1n4bRAAAL3E"]
[Tue Jul 21 07:47:19.888154 2026] [security2:error] [pid 302018:tid 302191] [client 74.249.245.134:64434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/plugins.php"] [unique_id "al9ON4As9lPxxVAErz32UgAAAK4"]
[Tue Jul 21 07:47:19.897791 2026] [security2:error] [pid 302018:tid 302255] [client 20.197.195.24:11291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/echkm.php"] [unique_id "al9ON4As9lPxxVAErz32UwAAAO4"]
[Tue Jul 21 07:47:19.983998 2026] [security2:error] [pid 302018:tid 302203] [client 20.226.60.151:61527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wp-post-data.php"] [unique_id "al9ON4As9lPxxVAErz32VAAAALo"]
[Tue Jul 21 07:47:19.992997 2026] [security2:error] [pid 296703:tid 296947] [client 20.104.96.117:46673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/sixxis.php"] [unique_id "al9ONyn25uliftkV1n4bRQAAAHI"]
[Tue Jul 21 07:47:19.998634 2026] [security2:error] [pid 296703:tid 296796] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/get.php"] [unique_id "al9ONyn25uliftkV1n4bRgAAR1w"]
[Tue Jul 21 07:47:20.159408 2026] [security2:error] [pid 302018:tid 302210] [client 122.164.127.47:54178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OOIAs9lPxxVAErz32WAAAAME"]
[Tue Jul 21 07:47:20.159505 2026] [security2:error] [pid 302018:tid 302210] [client 122.164.127.47:54178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OOIAs9lPxxVAErz32WAAAAME"]
[Tue Jul 21 07:47:20.373935 2026] [security2:error] [pid 296703:tid 296768] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/as.php"] [unique_id "al9OOCn25uliftkV1n4bSwAAdUA"]
[Tue Jul 21 07:47:20.420308 2026] [security2:error] [pid 296703:tid 296929] [client 20.206.105.145:56595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/users.php"] [unique_id "al9OOCn25uliftkV1n4bTQAAAGA"]
[Tue Jul 21 07:47:20.496774 2026] [security2:error] [pid 296703:tid 296790] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OOCn25uliftkV1n4bTwAAYVY"]
[Tue Jul 21 07:47:20.496973 2026] [security2:error] [pid 296703:tid 296930] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OOCn25uliftkV1n4bTwAAYVY"]
[Tue Jul 21 07:47:20.524440 2026] [security2:error] [pid 296703:tid 296749] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/ccou.php"] [unique_id "al9OOCn25uliftkV1n4bUAAAVC0"]
[Tue Jul 21 07:47:20.648010 2026] [security2:error] [pid 296703:tid 296877] [client 184.75.223.211:49438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OOCn25uliftkV1n4bVgAAACw"]
[Tue Jul 21 07:47:20.648106 2026] [security2:error] [pid 296703:tid 296877] [client 184.75.223.211:49438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OOCn25uliftkV1n4bVgAAACw"]
[Tue Jul 21 07:47:21.059509 2026] [security2:error] [pid 296703:tid 296767] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/w3lls.php"] [unique_id "al9OOSn25uliftkV1n4bYQAAeD8"]
[Tue Jul 21 07:47:21.230175 2026] [security2:error] [pid 296703:tid 296788] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/test1.php"] [unique_id "al9OOSn25uliftkV1n4bZgAAKlQ"]
[Tue Jul 21 07:47:21.355167 2026] [security2:error] [pid 302018:tid 302184] [client 223.236.153.128:5480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OOYAs9lPxxVAErz32ZQAAAKc"]
[Tue Jul 21 07:47:21.355279 2026] [security2:error] [pid 302018:tid 302184] [client 223.236.153.128:5480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OOYAs9lPxxVAErz32ZQAAAKc"]
[Tue Jul 21 07:47:21.433127 2026] [security2:error] [pid 302018:tid 302235] [client 103.174.34.15:53354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OOYAs9lPxxVAErz32ZgAAANo"]
[Tue Jul 21 07:47:21.433279 2026] [security2:error] [pid 302018:tid 302235] [client 103.174.34.15:53354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OOYAs9lPxxVAErz32ZgAAANo"]
[Tue Jul 21 07:47:21.539992 2026] [security2:error] [pid 296703:tid 296910] [client 74.249.245.134:65111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/jp.php"] [unique_id "al9OOSn25uliftkV1n4baQAAAE0"]
[Tue Jul 21 07:47:21.662495 2026] [security2:error] [pid 296703:tid 296714] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/database.php"] [unique_id "al9OOSn25uliftkV1n4bbgAAfAo"]
[Tue Jul 21 07:47:21.686950 2026] [security2:error] [pid 302018:tid 302256] [client 20.206.105.145:56698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/177.php"] [unique_id "al9OOYAs9lPxxVAErz32agAAAO8"]
[Tue Jul 21 07:47:21.728197 2026] [security2:error] [pid 296703:tid 296926] [client 20.206.105.145:29639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/config.php"] [unique_id "al9OOSn25uliftkV1n4bcAAAAF0"]
[Tue Jul 21 07:47:21.992119 2026] [security2:error] [pid 296703:tid 296858] [client 193.36.225.64:56205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OOSn25uliftkV1n4bcgAAABk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:47:22.030589 2026] [security2:error] [pid 302018:tid 302170] [client 20.206.105.145:56608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/gettest.php"] [unique_id "al9OOoAs9lPxxVAErz32cQAAAJk"]
[Tue Jul 21 07:47:22.122994 2026] [security2:error] [pid 296703:tid 296787] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/file.php"] [unique_id "al9OOin25uliftkV1n4bdAAAJlM"]
[Tue Jul 21 07:47:22.240115 2026] [security2:error] [pid 296703:tid 296928] [client 20.104.96.117:46634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/ip.php"] [unique_id "al9OOin25uliftkV1n4beAAAAF8"]
[Tue Jul 21 07:47:22.337457 2026] [security2:error] [pid 296703:tid 296776] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/file.php"] [unique_id "al9OOin25uliftkV1n4begAAEUg"]
[Tue Jul 21 07:47:22.337595 2026] [security2:error] [pid 302018:tid 302177] [client 128.127.105.184:45396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9OOoAs9lPxxVAErz32dQAAAKA"]
[Tue Jul 21 07:47:22.337673 2026] [security2:error] [pid 302018:tid 302177] [client 128.127.105.184:45396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9OOoAs9lPxxVAErz32dQAAAKA"]
[Tue Jul 21 07:47:22.342856 2026] [security2:error] [pid 302018:tid 302174] [client 117.247.80.59:19850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OOoAs9lPxxVAErz32dgAAAJ0"]
[Tue Jul 21 07:47:22.342932 2026] [security2:error] [pid 302018:tid 302174] [client 117.247.80.59:19850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OOoAs9lPxxVAErz32dgAAAJ0"]
[Tue Jul 21 07:47:22.347692 2026] [security2:error] [pid 296703:tid 296833] [client 122.186.204.214:54833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OOin25uliftkV1n4bewAAAAA"]
[Tue Jul 21 07:47:22.351824 2026] [security2:error] [pid 296703:tid 296833] [client 122.186.204.214:54833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OOin25uliftkV1n4bewAAAAA"]
[Tue Jul 21 07:47:22.376801 2026] [security2:error] [pid 302018:tid 302175] [client 20.197.195.24:16174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/lib.php"] [unique_id "al9OOoAs9lPxxVAErz32eAAAAJ4"]
[Tue Jul 21 07:47:22.407030 2026] [security2:error] [pid 296703:tid 296880] [client 20.197.195.24:16251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/login.php"] [unique_id "al9OOin25uliftkV1n4bfAAAAC8"]
[Tue Jul 21 07:47:22.435461 2026] [security2:error] [pid 302018:tid 302058] [remote 154.61.75.100:43800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9OOoAs9lPxxVAErz32eQAA0CU"]
[Tue Jul 21 07:47:22.659516 2026] [security2:error] [pid 296703:tid 296734] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/777.php"] [unique_id "al9OOin25uliftkV1n4bgAAAdh4"]
[Tue Jul 21 07:47:22.791695 2026] [security2:error] [pid 296703:tid 296960] [client 154.192.233.199:59299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OOin25uliftkV1n4biQAAAH8"]
[Tue Jul 21 07:47:22.791800 2026] [security2:error] [pid 296703:tid 296960] [client 154.192.233.199:59299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OOin25uliftkV1n4biQAAAH8"]
[Tue Jul 21 07:47:22.807442 2026] [security2:error] [pid 296703:tid 296782] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/ssixta.php"] [unique_id "al9OOin25uliftkV1n4biwAAME4"]
[Tue Jul 21 07:47:23.039253 2026] [security2:error] [pid 296703:tid 296846] [client 20.197.195.24:18517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/a2.php"] [unique_id "al9OOyn25uliftkV1n4bjQAAAA0"]
[Tue Jul 21 07:47:23.053857 2026] [security2:error] [pid 302018:tid 302273] [client 20.206.105.145:56682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/min.php"] [unique_id "al9OO4As9lPxxVAErz32ewAAAQA"]
[Tue Jul 21 07:47:23.088841 2026] [security2:error] [pid 296703:tid 296879] [client 20.226.60.151:61598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/pucci.php"] [unique_id "al9OOyn25uliftkV1n4bjgAAAC4"]
[Tue Jul 21 07:47:23.189549 2026] [security2:error] [pid 296703:tid 296830] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/1c.php"] [unique_id "al9OOyn25uliftkV1n4bjwAAPH4"]
[Tue Jul 21 07:47:23.215933 2026] [security2:error] [pid 302018:tid 302176] [client 20.197.195.24:18518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/d61.php"] [unique_id "al9OO4As9lPxxVAErz32fAAAAJ8"]
[Tue Jul 21 07:47:23.224565 2026] [security2:error] [pid 296703:tid 296861] [client 117.251.86.144:43000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OOyn25uliftkV1n4bkQAAABw"]
[Tue Jul 21 07:47:23.224670 2026] [security2:error] [pid 296703:tid 296861] [client 117.251.86.144:43000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OOyn25uliftkV1n4bkQAAABw"]
[Tue Jul 21 07:47:23.305049 2026] [security2:error] [pid 302018:tid 302252] [client 74.249.245.134:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/error.php"] [unique_id "al9OO4As9lPxxVAErz32ggAAAOs"]
[Tue Jul 21 07:47:23.357764 2026] [security2:error] [pid 296703:tid 296744] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/test2.php"] [unique_id "al9OOyn25uliftkV1n4blgAARSg"]
[Tue Jul 21 07:47:23.473114 2026] [security2:error] [pid 296703:tid 296913] [client 20.197.195.24:18555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/info.php"] [unique_id "al9OOyn25uliftkV1n4bmAAAAFA"]
[Tue Jul 21 07:47:23.505950 2026] [security2:error] [pid 296703:tid 296752] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/buy.php"] [unique_id "al9OOyn25uliftkV1n4bmQAAOjA"]
[Tue Jul 21 07:47:23.557212 2026] [security2:error] [pid 296703:tid 296927] [client 20.206.105.145:56688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/edorxrr.php"] [unique_id "al9OOyn25uliftkV1n4bmgAAAF4"]
[Tue Jul 21 07:47:23.680381 2026] [security2:error] [pid 296703:tid 296775] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/ssend.php"] [unique_id "al9OOyn25uliftkV1n4bmwAAZ0c"]
[Tue Jul 21 07:47:23.849194 2026] [security2:error] [pid 296703:tid 296805] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/item.php"] [unique_id "al9OOyn25uliftkV1n4bnwAAdGU"]
[Tue Jul 21 07:47:23.852873 2026] [security2:error] [pid 296703:tid 296952] [client 47.128.54.152:54676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.serbetoadv.com"] [uri "/robots.txt"] [unique_id "al9OOyn25uliftkV1n4boAAAAHc"]
[Tue Jul 21 07:47:23.856276 2026] [security2:error] [pid 296703:tid 296859] [client 59.96.220.140:55405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OOyn25uliftkV1n4boQAAABo"]
[Tue Jul 21 07:47:23.857047 2026] [security2:error] [pid 296703:tid 296859] [client 59.96.220.140:55405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OOyn25uliftkV1n4boQAAABo"]
[Tue Jul 21 07:47:23.859524 2026] [security2:error] [pid 296703:tid 296892] [client 20.197.195.24:16149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/11.php"] [unique_id "al9OOyn25uliftkV1n4bogAAADs"]
[Tue Jul 21 07:47:24.021552 2026] [security2:error] [pid 296703:tid 296813] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/ss.php"] [unique_id "al9OPCn25uliftkV1n4bpQAACm0"]
[Tue Jul 21 07:47:24.169886 2026] [security2:error] [pid 296703:tid 296831] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/hypo.php"] [unique_id "al9OPCn25uliftkV1n4bqAAANH8"]
[Tue Jul 21 07:47:24.322861 2026] [security2:error] [pid 296703:tid 296756] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/users.php"] [unique_id "al9OPCn25uliftkV1n4brAAAbTQ"]
[Tue Jul 21 07:47:24.324388 2026] [security2:error] [pid 296703:tid 296876] [client 20.197.195.24:16137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/v2.php"] [unique_id "al9OPCn25uliftkV1n4brQAAACs"]
[Tue Jul 21 07:47:24.471963 2026] [security2:error] [pid 296703:tid 296727] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/177.php"] [unique_id "al9OPCn25uliftkV1n4brwAAPRc"]
[Tue Jul 21 07:47:24.515115 2026] [security2:error] [pid 302018:tid 302214] [client 20.197.195.24:18522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/panel.php"] [unique_id "al9OPIAs9lPxxVAErz32kAAAAMU"]
[Tue Jul 21 07:47:24.534762 2026] [security2:error] [pid 302018:tid 302237] [client 41.68.90.219:54339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OPIAs9lPxxVAErz32kQAAANw"]
[Tue Jul 21 07:47:24.534893 2026] [security2:error] [pid 302018:tid 302237] [client 41.68.90.219:54339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OPIAs9lPxxVAErz32kQAAANw"]
[Tue Jul 21 07:47:24.575188 2026] [security2:error] [pid 302018:tid 302218] [client 20.197.195.24:16220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/dex.php"] [unique_id "al9OPIAs9lPxxVAErz32kgAAAMk"]
[Tue Jul 21 07:47:24.621529 2026] [security2:error] [pid 296703:tid 296725] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/config.php"] [unique_id "al9OPCn25uliftkV1n4bsAAABhU"]
[Tue Jul 21 07:47:24.745417 2026] [security2:error] [pid 302018:tid 302258] [client 20.104.96.117:27121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/kq1.php"] [unique_id "al9OPIAs9lPxxVAErz32kwAAAPE"]
[Tue Jul 21 07:47:24.763434 2026] [security2:error] [pid 302018:tid 302266] [client 20.197.195.24:18513] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ciclododinheiro.com"] [uri "/1.php"] [unique_id "al9OPIAs9lPxxVAErz32lAAAAPk"]
[Tue Jul 21 07:47:24.763558 2026] [security2:error] [pid 302018:tid 302266] [client 20.197.195.24:18513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/1.php"] [unique_id "al9OPIAs9lPxxVAErz32lAAAAPk"]
[Tue Jul 21 07:47:24.824884 2026] [security2:error] [pid 302018:tid 302272] [client 20.197.195.24:16136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/ms.php"] [unique_id "al9OPIAs9lPxxVAErz32mAAAAP8"]
[Tue Jul 21 07:47:24.827448 2026] [security2:error] [pid 296703:tid 296807] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/gettest.php"] [unique_id "al9OPCn25uliftkV1n4btgAAOGc"]
[Tue Jul 21 07:47:24.854757 2026] [security2:error] [pid 302018:tid 302273] [client 74.249.245.134:24776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/classwithtostring.php"] [unique_id "al9OPIAs9lPxxVAErz32mgAAAQA"]
[Tue Jul 21 07:47:24.941794 2026] [security2:error] [pid 296703:tid 296730] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OPCn25uliftkV1n4btwAADxo"]
[Tue Jul 21 07:47:24.941993 2026] [security2:error] [pid 296703:tid 296848] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OPCn25uliftkV1n4btwAADxo"]
[Tue Jul 21 07:47:24.998449 2026] [security2:error] [pid 302018:tid 302193] [client 20.197.195.24:16175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/memberfuns.php"] [unique_id "al9OPIAs9lPxxVAErz32nQAAALA"]
[Tue Jul 21 07:47:25.044425 2026] [security2:error] [pid 302018:tid 302192] [client 20.197.195.24:18525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/0.php"] [unique_id "al9OPYAs9lPxxVAErz32ngAAAK8"]
[Tue Jul 21 07:47:25.066331 2026] [security2:error] [pid 296703:tid 296720] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/min.php"] [unique_id "al9OPSn25uliftkV1n4buAAAcBA"]
[Tue Jul 21 07:47:25.071446 2026] [security2:error] [pid 296703:tid 296845] [client 184.75.223.211:49444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9OPSn25uliftkV1n4buQAAAAw"]
[Tue Jul 21 07:47:25.071538 2026] [security2:error] [pid 296703:tid 296845] [client 184.75.223.211:49444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9OPSn25uliftkV1n4buQAAAAw"]
[Tue Jul 21 07:47:25.073172 2026] [security2:error] [pid 302018:tid 302241] [client 20.197.195.24:11279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/BDKR28.php"] [unique_id "al9OPYAs9lPxxVAErz32nwAAAOA"]
[Tue Jul 21 07:47:25.136266 2026] [security2:error] [pid 302018:tid 302216] [client 20.197.195.24:16225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/green1.php"] [unique_id "al9OPYAs9lPxxVAErz32oQAAAMc"]
[Tue Jul 21 07:47:25.190555 2026] [security2:error] [pid 302018:tid 302213] [client 20.197.195.24:52591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/nc4.php"] [unique_id "al9OPYAs9lPxxVAErz32ogAAAMQ"]
[Tue Jul 21 07:47:25.227384 2026] [security2:error] [pid 296703:tid 296706] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/dvjul.php"] [unique_id "al9OPSn25uliftkV1n4bugAARwI"]
[Tue Jul 21 07:47:25.318443 2026] [security2:error] [pid 296703:tid 296925] [client 20.197.195.24:18515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/a1.php"] [unique_id "al9OPSn25uliftkV1n4bvAAAAFw"]
[Tue Jul 21 07:47:25.375892 2026] [security2:error] [pid 296703:tid 296791] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/biufile.php"] [unique_id "al9OPSn25uliftkV1n4bvwAAdlc"]
[Tue Jul 21 07:47:25.489151 2026] [security2:error] [pid 302018:tid 302267] [client 20.206.105.145:56678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/hur.php"] [unique_id "al9OPYAs9lPxxVAErz32pQAAAPo"]
[Tue Jul 21 07:47:25.527308 2026] [security2:error] [pid 296703:tid 296766] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/av.php"] [unique_id "al9OPSn25uliftkV1n4bxgAAYD4"]
[Tue Jul 21 07:47:25.561704 2026] [security2:error] [pid 296703:tid 296840] [client 20.197.195.24:18539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/eee.php"] [unique_id "al9OPSn25uliftkV1n4bxwAAAAc"]
[Tue Jul 21 07:47:25.675876 2026] [security2:error] [pid 296703:tid 296743] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/coffexium.php"] [unique_id "al9OPSn25uliftkV1n4byAAASic"]
[Tue Jul 21 07:47:25.780826 2026] [security2:error] [pid 302018:tid 302256] [client 194.147.58.101:57196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/backup.sql"] [unique_id "al9OPYAs9lPxxVAErz32qgAAAO8"]
[Tue Jul 21 07:47:25.824439 2026] [security2:error] [pid 296703:tid 296759] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/core.php"] [unique_id "al9OPSn25uliftkV1n4byQAAOTc"]
[Tue Jul 21 07:47:25.872577 2026] [security2:error] [pid 296703:tid 296879] [client 20.197.195.24:18556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/wp-aothait.php"] [unique_id "al9OPSn25uliftkV1n4bygAAAC4"]
[Tue Jul 21 07:47:25.925167 2026] [security2:error] [pid 302018:tid 302159] [client 139.167.225.182:51424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OPYAs9lPxxVAErz32rQAAAI4"]
[Tue Jul 21 07:47:25.925283 2026] [security2:error] [pid 302018:tid 302159] [client 139.167.225.182:51424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OPYAs9lPxxVAErz32rQAAAI4"]
[Tue Jul 21 07:47:25.994094 2026] [security2:error] [pid 302018:tid 302269] [client 173.24.185.52:52516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OPYAs9lPxxVAErz32rgAAAPw"]
[Tue Jul 21 07:47:25.994199 2026] [security2:error] [pid 302018:tid 302269] [client 173.24.185.52:52516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OPYAs9lPxxVAErz32rgAAAPw"]
[Tue Jul 21 07:47:26.001480 2026] [security2:error] [pid 296703:tid 296783] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/als.php"] [unique_id "al9OPin25uliftkV1n4b0QAAUk8"]
[Tue Jul 21 07:47:26.075462 2026] [security2:error] [pid 296703:tid 296923] [client 182.8.255.181:17502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OPin25uliftkV1n4b1AAAAFo"]
[Tue Jul 21 07:47:26.075572 2026] [security2:error] [pid 296703:tid 296923] [client 182.8.255.181:17502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OPin25uliftkV1n4b1AAAAFo"]
[Tue Jul 21 07:47:26.079215 2026] [security2:error] [pid 296703:tid 296865] [client 103.29.114.44:56731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OPin25uliftkV1n4b1QAAACA"]
[Tue Jul 21 07:47:26.079334 2026] [security2:error] [pid 296703:tid 296865] [client 103.29.114.44:56731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OPin25uliftkV1n4b1QAAACA"]
[Tue Jul 21 07:47:26.080196 2026] [security2:error] [pid 302018:tid 302188] [client 74.249.245.134:64398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/bless.php"] [unique_id "al9OPoAs9lPxxVAErz32sQAAAKs"]
[Tue Jul 21 07:47:26.247955 2026] [security2:error] [pid 302018:tid 302226] [client 20.197.195.24:16179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/config.json.php"] [unique_id "al9OPoAs9lPxxVAErz32swAAANE"]
[Tue Jul 21 07:47:26.256488 2026] [security2:error] [pid 296703:tid 296827] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/simple.php"] [unique_id "al9OPin25uliftkV1n4b1wAAQ3s"]
[Tue Jul 21 07:47:26.370311 2026] [security2:error] [pid 302018:tid 302168] [client 216.244.66.201:52878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.combolog.com.br"] [uri "/robots.txt"] [unique_id "al9OPoAs9lPxxVAErz32tQAAAJc"]
[Tue Jul 21 07:47:26.370463 2026] [security2:error] [pid 302018:tid 302168] [client 216.244.66.201:52878] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.combolog.com.br"] [uri "/robots.txt"] [unique_id "al9OPoAs9lPxxVAErz32tQAAAJc"]
[Tue Jul 21 07:47:26.436153 2026] [security2:error] [pid 296703:tid 296795] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/init.php"] [unique_id "al9OPin25uliftkV1n4b3QAAVls"]
[Tue Jul 21 07:47:26.459184 2026] [security2:error] [pid 302018:tid 302150] [client 122.179.91.63:6377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OPoAs9lPxxVAErz32uAAAAIU"]
[Tue Jul 21 07:47:26.459294 2026] [security2:error] [pid 302018:tid 302150] [client 122.179.91.63:6377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OPoAs9lPxxVAErz32uAAAAIU"]
[Tue Jul 21 07:47:26.464642 2026] [security2:error] [pid 302018:tid 302156] [client 154.208.47.43:54055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OPoAs9lPxxVAErz32uQAAAIs"]
[Tue Jul 21 07:47:26.464723 2026] [security2:error] [pid 302018:tid 302156] [client 154.208.47.43:54055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OPoAs9lPxxVAErz32uQAAAIs"]
[Tue Jul 21 07:47:26.599466 2026] [security2:error] [pid 296703:tid 296777] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/fpwch.php"] [unique_id "al9OPin25uliftkV1n4b3gAAO0k"]
[Tue Jul 21 07:47:26.748894 2026] [security2:error] [pid 296703:tid 296771] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/domvf.php"] [unique_id "al9OPin25uliftkV1n4b4QAACkM"]
[Tue Jul 21 07:47:26.777692 2026] [security2:error] [pid 302018:tid 302261] [client 194.147.58.101:57240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wp-content/database.sql"] [unique_id "al9OPoAs9lPxxVAErz32wgAAAPQ"]
[Tue Jul 21 07:47:26.777849 2026] [security2:error] [pid 302018:tid 302190] [client 194.147.58.101:57246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wp-content/uploads/br1102.hostgator.com.br.sql"] [unique_id "al9OPoAs9lPxxVAErz32wAAAAK0"]
[Tue Jul 21 07:47:26.777966 2026] [security2:error] [pid 302018:tid 302241] [client 194.147.58.101:57212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/database.sql"] [unique_id "al9OPoAs9lPxxVAErz32wQAAAOA"]
[Tue Jul 21 07:47:26.778093 2026] [security2:error] [pid 302018:tid 302219] [client 194.147.58.101:57266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/mysql.sql"] [unique_id "al9OPoAs9lPxxVAErz32wwAAAMo"]
[Tue Jul 21 07:47:26.779110 2026] [security2:error] [pid 296703:tid 296859] [client 194.147.58.101:57276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wp-content/uploads/backup.sql"] [unique_id "al9OPin25uliftkV1n4b4gAAABo"]
[Tue Jul 21 07:47:26.780088 2026] [security2:error] [pid 302018:tid 302216] [client 194.147.58.101:57222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/backups/database.sql"] [unique_id "al9OPoAs9lPxxVAErz32xAAAAMc"]
[Tue Jul 21 07:47:26.782916 2026] [security2:error] [pid 302018:tid 302184] [client 194.147.58.101:57226] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/db.sql"] [unique_id "al9OPoAs9lPxxVAErz32xQAAAKc"]
[Tue Jul 21 07:47:26.783270 2026] [security2:error] [pid 302018:tid 302185] [client 193.36.225.63:51455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OPoAs9lPxxVAErz32xwAAAKg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:47:26.783587 2026] [security2:error] [pid 302018:tid 302164] [client 194.147.58.101:57290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/br1102.hostgator.com.br.sql"] [unique_id "al9OPoAs9lPxxVAErz32xgAAAJM"]
[Tue Jul 21 07:47:26.787406 2026] [security2:error] [pid 302018:tid 302248] [client 194.147.58.101:57250] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/dump.sql"] [unique_id "al9OPoAs9lPxxVAErz32yQAAAOc"]
[Tue Jul 21 07:47:26.788404 2026] [security2:error] [pid 302018:tid 302244] [client 194.147.58.101:57298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wp-content/uploads/database.sql"] [unique_id "al9OPoAs9lPxxVAErz32ygAAAOM"]
[Tue Jul 21 07:47:26.788404 2026] [security2:error] [pid 302018:tid 302157] [client 194.147.58.101:57300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/wp-content/uploads/dump.sql"] [unique_id "al9OPoAs9lPxxVAErz32ywAAAIw"]
[Tue Jul 21 07:47:26.791434 2026] [security2:error] [pid 302018:tid 302048] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OPoAs9lPxxVAErz32zAAA6xs"]
[Tue Jul 21 07:47:26.791537 2026] [security2:error] [pid 302018:tid 302252] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OPoAs9lPxxVAErz32zAAA6xs"]
[Tue Jul 21 07:47:26.880859 2026] [security2:error] [pid 296703:tid 296885] [client 20.197.195.24:18528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9OPin25uliftkV1n4b5QAAADQ"]
[Tue Jul 21 07:47:26.898317 2026] [security2:error] [pid 296703:tid 296781] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/wp.php"] [unique_id "al9OPin25uliftkV1n4b5gAAeE0"]
[Tue Jul 21 07:47:27.047856 2026] [security2:error] [pid 296703:tid 296815] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/class.php"] [unique_id "al9OPyn25uliftkV1n4b8AAAPW8"]
[Tue Jul 21 07:47:27.194529 2026] [security2:error] [pid 296703:tid 296952] [client 103.86.117.203:52759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OPyn25uliftkV1n4b8QAAAHc"]
[Tue Jul 21 07:47:27.194663 2026] [security2:error] [pid 296703:tid 296952] [client 103.86.117.203:52759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OPyn25uliftkV1n4b8QAAAHc"]
[Tue Jul 21 07:47:27.385755 2026] [security2:error] [pid 296703:tid 296833] [client 20.197.195.24:16135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/k2.php"] [unique_id "al9OPyn25uliftkV1n4b9gAAAAA"]
[Tue Jul 21 07:47:27.439535 2026] [security2:error] [pid 296703:tid 296922] [client 193.36.225.143:24209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OPyn25uliftkV1n4b8gAAAFk"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:47:27.614209 2026] [security2:error] [pid 302018:tid 302203] [client 178.153.91.96:21197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OP4As9lPxxVAErz320AAAALo"]
[Tue Jul 21 07:47:27.614331 2026] [security2:error] [pid 302018:tid 302203] [client 178.153.91.96:21197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OP4As9lPxxVAErz320AAAALo"]
[Tue Jul 21 07:47:27.664097 2026] [security2:error] [pid 296703:tid 296797] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/echkm.php"] [unique_id "al9OPyn25uliftkV1n4b_gAAA10"]
[Tue Jul 21 07:47:27.718078 2026] [security2:error] [pid 302018:tid 302275] [client 185.198.240.6:43601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dener.design"] [uri "/wp-login.php"] [unique_id "al9OP4As9lPxxVAErz320QAAAQI"]
[Tue Jul 21 07:47:27.718947 2026] [security2:error] [pid 296703:tid 296870] [client 152.59.154.239:51033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OPyn25uliftkV1n4b_wAAACU"]
[Tue Jul 21 07:47:27.719038 2026] [security2:error] [pid 296703:tid 296870] [client 152.59.154.239:51033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OPyn25uliftkV1n4b_wAAACU"]
[Tue Jul 21 07:47:27.740284 2026] [security2:error] [pid 302018:tid 302176] [client 20.206.105.145:29659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/zoro.php"] [unique_id "al9OP4As9lPxxVAErz320gAAAJ8"]
[Tue Jul 21 07:47:27.838870 2026] [security2:error] [pid 296703:tid 296808] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/lib.php"] [unique_id "al9OPyn25uliftkV1n4cAAAAf2g"]
[Tue Jul 21 07:47:27.988949 2026] [security2:error] [pid 296703:tid 296741] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/login.php"] [unique_id "al9OPyn25uliftkV1n4cBgAAOSU"]
[Tue Jul 21 07:47:28.162740 2026] [security2:error] [pid 296703:tid 296790] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/a2.php"] [unique_id "al9OQCn25uliftkV1n4cCgAANVY"]
[Tue Jul 21 07:47:28.381991 2026] [security2:error] [pid 296703:tid 296958] [client 122.162.144.145:15633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OQCn25uliftkV1n4cCwAAAH0"]
[Tue Jul 21 07:47:28.384531 2026] [security2:error] [pid 296703:tid 296958] [client 122.162.144.145:15633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OQCn25uliftkV1n4cCwAAAH0"]
[Tue Jul 21 07:47:28.511607 2026] [security2:error] [pid 302018:tid 302164] [client 20.151.10.161:43915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/images.php"] [unique_id "al9OQIAs9lPxxVAErz322gAAAJM"]
[Tue Jul 21 07:47:28.537269 2026] [security2:error] [pid 296703:tid 296910] [client 20.197.195.24:16223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/uiuvs58l.php"] [unique_id "al9OQCn25uliftkV1n4cEQAAAE0"]
[Tue Jul 21 07:47:28.583698 2026] [security2:error] [pid 296703:tid 296712] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/d61.php"] [unique_id "al9OQCn25uliftkV1n4cFAAAOgg"]
[Tue Jul 21 07:47:28.731563 2026] [security2:error] [pid 296703:tid 296816] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/info.php"] [unique_id "al9OQCn25uliftkV1n4cFgAAFnA"]
[Tue Jul 21 07:47:28.934894 2026] [security2:error] [pid 296703:tid 296763] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/11.php"] [unique_id "al9OQCn25uliftkV1n4cFwAAVjs"]
[Tue Jul 21 07:47:28.991246 2026] [security2:error] [pid 296703:tid 296821] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OQCn25uliftkV1n4cGQAALXU"]
[Tue Jul 21 07:47:28.991377 2026] [security2:error] [pid 296703:tid 296878] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OQCn25uliftkV1n4cGQAALXU"]
[Tue Jul 21 07:47:29.016475 2026] [security2:error] [pid 302018:tid 302223] [client 20.197.195.24:11283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/40p9ixjd.php"] [unique_id "al9OQYAs9lPxxVAErz324gAAAM4"]
[Tue Jul 21 07:47:29.102187 2026] [security2:error] [pid 302018:tid 302052] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OQYAs9lPxxVAErz325QAAlR8"]
[Tue Jul 21 07:47:29.102360 2026] [security2:error] [pid 302018:tid 302166] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OQYAs9lPxxVAErz325QAAlR8"]
[Tue Jul 21 07:47:29.131661 2026] [security2:error] [pid 302018:tid 302219] [client 106.215.181.8:18879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OQYAs9lPxxVAErz325gAAAMo"]
[Tue Jul 21 07:47:29.131772 2026] [security2:error] [pid 302018:tid 302219] [client 106.215.181.8:18879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OQYAs9lPxxVAErz325gAAAMo"]
[Tue Jul 21 07:47:29.155780 2026] [security2:error] [pid 302018:tid 302161] [client 74.249.245.134:64115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/storage/index.php"] [unique_id "al9OQYAs9lPxxVAErz325wAAAJA"]
[Tue Jul 21 07:47:29.194986 2026] [security2:error] [pid 296703:tid 296751] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/v2.php"] [unique_id "al9OQSn25uliftkV1n4cHwAATi8"]
[Tue Jul 21 07:47:29.296468 2026] [security2:error] [pid 302018:tid 302155] [client 20.206.105.145:56588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/coffexium.php"] [unique_id "al9OQYAs9lPxxVAErz326wAAAIo"]
[Tue Jul 21 07:47:29.301963 2026] [security2:error] [pid 302018:tid 302249] [client 20.197.195.24:16254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9OQYAs9lPxxVAErz327AAAAOg"]
[Tue Jul 21 07:47:29.347187 2026] [security2:error] [pid 302018:tid 302225] [client 20.151.10.161:64146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9OQYAs9lPxxVAErz327gAAANA"]
[Tue Jul 21 07:47:29.423841 2026] [security2:error] [pid 296703:tid 296721] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/panel.php"] [unique_id "al9OQSn25uliftkV1n4cIgAAXRE"]
[Tue Jul 21 07:47:29.559587 2026] [security2:error] [pid 302018:tid 302213] [client 20.197.195.24:16202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/for.php"] [unique_id "al9OQYAs9lPxxVAErz329gAAAMQ"]
[Tue Jul 21 07:47:29.617307 2026] [security2:error] [pid 296703:tid 296826] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OQSn25uliftkV1n4cJgAAbXo"]
[Tue Jul 21 07:47:29.617426 2026] [security2:error] [pid 296703:tid 296942] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OQSn25uliftkV1n4cJgAAbXo"]
[Tue Jul 21 07:47:29.650671 2026] [security2:error] [pid 296703:tid 296888] [client 20.104.96.117:27098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/fw/faiyy.php"] [unique_id "al9OQSn25uliftkV1n4cJwAAADc"]
[Tue Jul 21 07:47:29.745365 2026] [security2:error] [pid 302018:tid 302237] [client 103.166.103.129:23171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OQYAs9lPxxVAErz33CQAAANw"]
[Tue Jul 21 07:47:29.745450 2026] [security2:error] [pid 302018:tid 302237] [client 103.166.103.129:23171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OQYAs9lPxxVAErz33CQAAANw"]
[Tue Jul 21 07:47:29.782629 2026] [security2:error] [pid 296703:tid 296774] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/dex.php"] [unique_id "al9OQSn25uliftkV1n4cKAAAfkY"]
[Tue Jul 21 07:47:29.804506 2026] [security2:error] [pid 302018:tid 302026] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OQYAs9lPxxVAErz33DQAAmQU"]
[Tue Jul 21 07:47:29.804594 2026] [security2:error] [pid 302018:tid 302170] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OQYAs9lPxxVAErz33DQAAmQU"]
[Tue Jul 21 07:47:29.915639 2026] [security2:error] [pid 296703:tid 296860] [client 20.197.195.24:11312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ciclododinheiro.com"] [uri "/raw.php"] [unique_id "al9OQSn25uliftkV1n4cKwAAABs"]
[Tue Jul 21 07:47:29.960155 2026] [security2:error] [pid 296703:tid 296764] [remote 4.204.201.85:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "albegaoficial.com.br"] [uri "/1.php"] [unique_id "al9OQSn25uliftkV1n4cLAAAATw"]
[Tue Jul 21 07:47:29.960242 2026] [security2:error] [pid 296703:tid 296764] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/1.php"] [unique_id "al9OQSn25uliftkV1n4cLAAAATw"]
[Tue Jul 21 07:47:29.970743 2026] [security2:error] [pid 302018:tid 302168] [client 117.217.38.194:63811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OQYAs9lPxxVAErz33OgAAAJc"]
[Tue Jul 21 07:47:29.970848 2026] [security2:error] [pid 302018:tid 302168] [client 117.217.38.194:63811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OQYAs9lPxxVAErz33OgAAAJc"]
[Tue Jul 21 07:47:30.129930 2026] [security2:error] [pid 296703:tid 296735] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/ms.php"] [unique_id "al9OQin25uliftkV1n4cLwAABh8"]
[Tue Jul 21 07:47:30.387433 2026] [security2:error] [pid 302018:tid 302052] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OQoAs9lPxxVAErz33ZQAAmB8"]
[Tue Jul 21 07:47:30.387563 2026] [security2:error] [pid 302018:tid 302169] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OQoAs9lPxxVAErz33ZQAAmB8"]
[Tue Jul 21 07:47:30.468421 2026] [autoindex:error] [pid 302018:tid 302230] [client 198.235.24.145:61680] AH01276: Cannot serve directory /home1/taina869/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:47:30.642141 2026] [security2:error] [pid 296703:tid 296705] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/memberfuns.php"] [unique_id "al9OQin25uliftkV1n4cPQAAVAE"]
[Tue Jul 21 07:47:30.722265 2026] [security2:error] [pid 302018:tid 302256] [client 122.164.127.47:54755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OQoAs9lPxxVAErz330AAAAO8"]
[Tue Jul 21 07:47:30.722408 2026] [security2:error] [pid 302018:tid 302256] [client 122.164.127.47:54755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OQoAs9lPxxVAErz330AAAAO8"]
[Tue Jul 21 07:47:30.790825 2026] [security2:error] [pid 296703:tid 296830] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/0.php"] [unique_id "al9OQin25uliftkV1n4cPwAAX34"]
[Tue Jul 21 07:47:30.895431 2026] [security2:error] [pid 302018:tid 302223] [client 20.206.105.145:29576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/app.php"] [unique_id "al9OQoAs9lPxxVAErz331AAAAM4"]
[Tue Jul 21 07:47:30.928620 2026] [security2:error] [pid 302018:tid 302248] [client 202.143.127.214:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OQoAs9lPxxVAErz332QAAAOc"]
[Tue Jul 21 07:47:30.928718 2026] [security2:error] [pid 302018:tid 302248] [client 202.143.127.214:62708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OQoAs9lPxxVAErz332QAAAOc"]
[Tue Jul 21 07:47:30.944012 2026] [security2:error] [pid 296703:tid 296822] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/BDKR28.php"] [unique_id "al9OQin25uliftkV1n4cQAAAQHY"]
[Tue Jul 21 07:47:31.138128 2026] [security2:error] [pid 296703:tid 296760] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/green1.php"] [unique_id "al9OQyn25uliftkV1n4cSAAAQjg"]
[Tue Jul 21 07:47:31.248114 2026] [security2:error] [pid 296703:tid 296893] [client 74.249.245.134:64099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/g.php"] [unique_id "al9OQyn25uliftkV1n4cSwAAADw"]
[Tue Jul 21 07:47:31.300568 2026] [security2:error] [pid 302018:tid 302175] [client 193.36.225.68:29389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OQ4As9lPxxVAErz334QAAAJ4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:47:31.364841 2026] [security2:error] [pid 296703:tid 296736] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/nc4.php"] [unique_id "al9OQyn25uliftkV1n4cTQAARCA"]
[Tue Jul 21 07:47:31.384061 2026] [security2:error] [pid 302018:tid 302129] [remote 154.0.166.254:35222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nocaminhodafe.com.br"] [uri "/wp-login.php"] [unique_id "al9OQ4As9lPxxVAErz335AAA4mw"]
[Tue Jul 21 07:47:31.513845 2026] [security2:error] [pid 296703:tid 296704] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/a1.php"] [unique_id "al9OQyn25uliftkV1n4cTgAAbgA"]
[Tue Jul 21 07:47:31.536880 2026] [security2:error] [pid 296703:tid 296739] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OQyn25uliftkV1n4cTwAAYyM"]
[Tue Jul 21 07:47:31.536976 2026] [security2:error] [pid 296703:tid 296932] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OQyn25uliftkV1n4cTwAAYyM"]
[Tue Jul 21 07:47:31.662302 2026] [security2:error] [pid 296703:tid 296810] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/eee.php"] [unique_id "al9OQyn25uliftkV1n4cUgAARWo"]
[Tue Jul 21 07:47:31.834576 2026] [security2:error] [pid 296703:tid 296831] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/wp-aothait.php"] [unique_id "al9OQyn25uliftkV1n4cVQAAQ38"]
[Tue Jul 21 07:47:31.839000 2026] [security2:error] [pid 302018:tid 302244] [client 136.144.33.213:56455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OQoAs9lPxxVAErz33zwAAAOM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:47:32.016069 2026] [security2:error] [pid 296703:tid 296941] [client 109.60.28.94:14955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OQyn25uliftkV1n4cVgAAAGw"]
[Tue Jul 21 07:47:32.031390 2026] [security2:error] [pid 302018:tid 302247] [client 20.151.10.161:64253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9ORIAs9lPxxVAErz337wAAAOY"]
[Tue Jul 21 07:47:32.094470 2026] [security2:error] [pid 296703:tid 296748] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/config.json.php"] [unique_id "al9ORCn25uliftkV1n4cWAAAeSw"]
[Tue Jul 21 07:47:32.106827 2026] [autoindex:error] [pid 302018:tid 302222] [client 184.154.139.52:60830] AH01276: Cannot serve directory /home1/imperd48/sabino-tracker.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.google.com/url?url=sabino-tracker.com&yahoo.com
[Tue Jul 21 07:47:32.157192 2026] [security2:error] [pid 296703:tid 296883] [client 223.236.153.128:5489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9ORCn25uliftkV1n4cWwAAADI"]
[Tue Jul 21 07:47:32.157284 2026] [security2:error] [pid 296703:tid 296883] [client 223.236.153.128:5489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9ORCn25uliftkV1n4cWwAAADI"]
[Tue Jul 21 07:47:32.163878 2026] [security2:error] [pid 296703:tid 296919] [client 20.104.96.117:46661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/h02ugyh.php"] [unique_id "al9ORCn25uliftkV1n4cXQAAAFY"]
[Tue Jul 21 07:47:32.282834 2026] [security2:error] [pid 296703:tid 296727] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9ORCn25uliftkV1n4cYAAAOxc"]
[Tue Jul 21 07:47:32.379663 2026] [security2:error] [pid 302018:tid 302184] [client 103.174.34.15:53855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ORIAs9lPxxVAErz33-QAAAKc"]
[Tue Jul 21 07:47:32.380705 2026] [security2:error] [pid 302018:tid 302184] [client 103.174.34.15:53855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ORIAs9lPxxVAErz33-QAAAKc"]
[Tue Jul 21 07:47:32.471130 2026] [security2:error] [pid 296703:tid 296753] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/k2.php"] [unique_id "al9ORCn25uliftkV1n4cYgAAKjE"]
[Tue Jul 21 07:47:32.629678 2026] [security2:error] [pid 296703:tid 296807] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9ORCn25uliftkV1n4cZAAAGmc"]
[Tue Jul 21 07:47:32.785274 2026] [security2:error] [pid 296703:tid 296737] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9ORCn25uliftkV1n4caAAAGSE"]
[Tue Jul 21 07:47:32.823220 2026] [core:alert] [pid 296703:tid 296868] [client 57.141.18.5:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:47:32.887015 2026] [security2:error] [pid 296703:tid 296953] [client 184.154.139.52:33012] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "sabino-tracker.com"] [uri "/cgi-sys/404.html"] [unique_id "al9ORCn25uliftkV1n4cawAAAHg"]
[Tue Jul 21 07:47:32.933265 2026] [security2:error] [pid 296703:tid 296706] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9ORCn25uliftkV1n4cbQAAKwI"]
[Tue Jul 21 07:47:33.080254 2026] [security2:error] [pid 302018:tid 302156] [client 122.186.204.214:55365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9ORYAs9lPxxVAErz34BAAAAIs"]
[Tue Jul 21 07:47:33.080387 2026] [security2:error] [pid 302018:tid 302156] [client 122.186.204.214:55365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9ORYAs9lPxxVAErz34BAAAAIs"]
[Tue Jul 21 07:47:33.121222 2026] [security2:error] [pid 302018:tid 302200] [client 20.151.10.161:64217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/media.php"] [unique_id "al9ORYAs9lPxxVAErz34BQAAALc"]
[Tue Jul 21 07:47:33.187342 2026] [security2:error] [pid 296703:tid 296731] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/for.php"] [unique_id "al9ORSn25uliftkV1n4ccQAAARs"]
[Tue Jul 21 07:47:33.258580 2026] [security2:error] [pid 302018:tid 302238] [client 20.104.96.117:46677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-temp.php"] [unique_id "al9ORYAs9lPxxVAErz34DQAAAN0"]
[Tue Jul 21 07:47:33.375380 2026] [security2:error] [pid 296703:tid 296793] [remote 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "albegaoficial.com.br"] [uri "/raw.php"] [unique_id "al9ORSn25uliftkV1n4cdQAAWVk"]
[Tue Jul 21 07:47:33.473352 2026] [security2:error] [pid 302018:tid 302227] [client 184.154.139.52:33288] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sabino-tracker.com"] [uri "/cgi-sys/css/bootstrap.min.css"] [unique_id "al9ORYAs9lPxxVAErz34EAAAANI"]
[Tue Jul 21 07:47:33.527374 2026] [security2:error] [pid 296703:tid 296942] [client 154.192.233.199:59607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ORSn25uliftkV1n4ceAAAAG0"]
[Tue Jul 21 07:47:33.527703 2026] [security2:error] [pid 296703:tid 296942] [client 154.192.233.199:59607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ORSn25uliftkV1n4ceAAAAG0"]
[Tue Jul 21 07:47:33.612113 2026] [security2:error] [pid 296703:tid 296895] [client 128.127.105.184:46720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9ORSn25uliftkV1n4ceQAAAD4"]
[Tue Jul 21 07:47:33.612219 2026] [security2:error] [pid 296703:tid 296895] [client 128.127.105.184:46720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9ORSn25uliftkV1n4ceQAAAD4"]
[Tue Jul 21 07:47:33.673048 2026] [security2:error] [pid 296703:tid 296925] [client 20.206.105.145:29662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/core.php"] [unique_id "al9ORSn25uliftkV1n4cegAAAFw"]
[Tue Jul 21 07:47:33.686888 2026] [security2:error] [pid 296703:tid 296872] [client 20.226.60.151:53963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/black.php"] [unique_id "al9ORSn25uliftkV1n4cfAAAACc"]
[Tue Jul 21 07:47:33.772953 2026] [security2:error] [pid 302018:tid 302164] [client 184.154.139.52:33450] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sabino-tracker.com"] [uri "/cgi-sys/css/fonts.css"] [unique_id "al9ORYAs9lPxxVAErz34FQAAAJM"]
[Tue Jul 21 07:47:33.809018 2026] [security2:error] [pid 302018:tid 302226] [client 34.14.85.22:49467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.85.14.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senseriopreto.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ORYAs9lPxxVAErz34FgAAANE"]
[Tue Jul 21 07:47:33.905591 2026] [security2:error] [pid 296703:tid 296934] [client 20.104.96.117:46630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-content/cong.php"] [unique_id "al9ORSn25uliftkV1n4cgQAAAGU"]
[Tue Jul 21 07:47:33.978507 2026] [security2:error] [pid 302018:tid 302165] [client 117.251.86.144:36086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9ORYAs9lPxxVAErz34FwAAAJQ"]
[Tue Jul 21 07:47:33.978620 2026] [security2:error] [pid 302018:tid 302165] [client 117.251.86.144:36086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9ORYAs9lPxxVAErz34FwAAAJQ"]
[Tue Jul 21 07:47:34.120122 2026] [security2:error] [pid 302018:tid 302271] [client 117.247.80.59:33582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ORoAs9lPxxVAErz34GQAAAP4"]
[Tue Jul 21 07:47:34.120271 2026] [security2:error] [pid 302018:tid 302271] [client 117.247.80.59:33582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ORoAs9lPxxVAErz34GQAAAP4"]
[Tue Jul 21 07:47:34.484615 2026] [security2:error] [pid 296703:tid 296874] [client 59.96.220.140:55911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9ORin25uliftkV1n4ciwAAACk"]
[Tue Jul 21 07:47:34.485350 2026] [security2:error] [pid 296703:tid 296874] [client 59.96.220.140:55911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9ORin25uliftkV1n4ciwAAACk"]
[Tue Jul 21 07:47:34.723351 2026] [security2:error] [pid 302018:tid 302160] [client 34.14.85.22:52548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "senseriopreto.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9ORoAs9lPxxVAErz34TQAAAI8"]
[Tue Jul 21 07:47:34.922906 2026] [security2:error] [pid 302018:tid 302158] [client 20.151.10.161:43945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/alls.php"] [unique_id "al9ORoAs9lPxxVAErz34UQAAAI0"]
[Tue Jul 21 07:47:34.966547 2026] [autoindex:error] [pid 302018:tid 302256] [client 184.154.139.52:34036] AH01276: Cannot serve directory /home1/imperd48/sabino-tracker.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:47:34.967068 2026] [security2:error] [pid 302018:tid 302256] [client 184.154.139.52:34036] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "sabino-tracker.com"] [uri "/cgi-sys/403.html"] [unique_id "al9ORoAs9lPxxVAErz34UgAAAO8"]
[Tue Jul 21 07:47:35.197832 2026] [security2:error] [pid 302018:tid 302264] [client 41.68.90.219:54743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OR4As9lPxxVAErz34VAAAAPc"]
[Tue Jul 21 07:47:35.198946 2026] [security2:error] [pid 302018:tid 302264] [client 41.68.90.219:54743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OR4As9lPxxVAErz34VAAAAPc"]
[Tue Jul 21 07:47:35.384783 2026] [security2:error] [pid 302018:tid 302225] [client 20.151.10.161:64252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/images.php"] [unique_id "al9OR4As9lPxxVAErz34XgAAANA"]
[Tue Jul 21 07:47:35.392979 2026] [security2:error] [pid 302018:tid 302170] [client 74.249.245.134:65122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/nf.php"] [unique_id "al9OR4As9lPxxVAErz34XwAAAJk"]
[Tue Jul 21 07:47:35.467388 2026] [security2:error] [pid 302018:tid 302177] [client 184.154.139.52:34370] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "sabino-tracker.com"] [uri "/cgi-sys/404.html"] [unique_id "al9OR4As9lPxxVAErz34YQAAAKA"]
[Tue Jul 21 07:47:35.475199 2026] [security2:error] [pid 296703:tid 296781] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ORyn25uliftkV1n4clwAAQ00"]
[Tue Jul 21 07:47:35.475298 2026] [security2:error] [pid 296703:tid 296900] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ORyn25uliftkV1n4clwAAQ00"]
[Tue Jul 21 07:47:35.541611 2026] [security2:error] [pid 302018:tid 302226] [client 34.14.85.22:53690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "senseriopreto.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9OR4As9lPxxVAErz34YwAAANE"]
[Tue Jul 21 07:47:35.587479 2026] [security2:error] [pid 302018:tid 302161] [client 20.206.105.145:29678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/main.php"] [unique_id "al9OR4As9lPxxVAErz34ZwAAAJA"]
[Tue Jul 21 07:47:35.810399 2026] [security2:error] [pid 302018:tid 302238] [client 20.206.105.145:56641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/init.php"] [unique_id "al9OR4As9lPxxVAErz34dgAAAN0"]
[Tue Jul 21 07:47:35.926800 2026] [security2:error] [pid 302018:tid 302271] [client 20.104.96.117:46601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-includes/css/index.php"] [unique_id "al9OR4As9lPxxVAErz34fAAAAP4"]
[Tue Jul 21 07:47:35.948998 2026] [security2:error] [pid 302018:tid 302235] [client 20.206.105.145:56645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/prekel.php"] [unique_id "al9OR4As9lPxxVAErz34fgAAANo"]
[Tue Jul 21 07:47:36.071766 2026] [security2:error] [pid 302018:tid 302226] [client 20.151.10.161:43937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/yyu.php"] [unique_id "al9OSIAs9lPxxVAErz34hwAAANE"]
[Tue Jul 21 07:47:36.107659 2026] [security2:error] [pid 302018:tid 302203] [client 20.206.105.145:56634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/0.php"] [unique_id "al9OSIAs9lPxxVAErz34iAAAALo"]
[Tue Jul 21 07:47:36.252877 2026] [security2:error] [pid 302018:tid 302246] [client 20.206.105.145:29637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/BDKR28.php"] [unique_id "al9OSIAs9lPxxVAErz34iwAAAOU"]
[Tue Jul 21 07:47:36.328422 2026] [security2:error] [pid 302018:tid 302221] [client 193.36.225.72:49463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OSIAs9lPxxVAErz34kAAAAMw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:47:36.492539 2026] [security2:error] [pid 302018:tid 302166] [client 34.14.85.22:62286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "senseriopreto.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9OSIAs9lPxxVAErz34owAAAJU"]
[Tue Jul 21 07:47:36.623297 2026] [security2:error] [pid 302018:tid 302156] [client 173.24.185.52:52991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OSIAs9lPxxVAErz34qAAAAIs"]
[Tue Jul 21 07:47:36.623380 2026] [security2:error] [pid 302018:tid 302156] [client 173.24.185.52:52991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OSIAs9lPxxVAErz34qAAAAIs"]
[Tue Jul 21 07:47:36.630442 2026] [security2:error] [pid 296703:tid 296888] [client 20.206.105.145:29633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/f35.update.php"] [unique_id "al9OSCn25uliftkV1n4crgAAADc"]
[Tue Jul 21 07:47:36.632618 2026] [security2:error] [pid 302018:tid 302191] [client 182.8.255.181:17280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OSIAs9lPxxVAErz34qQAAAK4"]
[Tue Jul 21 07:47:36.632899 2026] [security2:error] [pid 302018:tid 302191] [client 182.8.255.181:17280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OSIAs9lPxxVAErz34qQAAAK4"]
[Tue Jul 21 07:47:36.677044 2026] [security2:error] [pid 302018:tid 302276] [client 103.29.114.44:6889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OSIAs9lPxxVAErz34rAAAAQM"]
[Tue Jul 21 07:47:36.677135 2026] [security2:error] [pid 302018:tid 302276] [client 103.29.114.44:6889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OSIAs9lPxxVAErz34rAAAAQM"]
[Tue Jul 21 07:47:36.684267 2026] [security2:error] [pid 302018:tid 302249] [client 139.167.225.182:52067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OSIAs9lPxxVAErz34rQAAAOg"]
[Tue Jul 21 07:47:36.686232 2026] [security2:error] [pid 302018:tid 302249] [client 139.167.225.182:52067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OSIAs9lPxxVAErz34rQAAAOg"]
[Tue Jul 21 07:47:36.700009 2026] [security2:error] [pid 296703:tid 296922] [client 20.206.105.145:29601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/f900.php"] [unique_id "al9OSCn25uliftkV1n4crwAAAFk"]
[Tue Jul 21 07:47:36.727119 2026] [security2:error] [pid 296703:tid 296942] [client 20.104.96.117:46597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/jj.php"] [unique_id "al9OSCn25uliftkV1n4csAAAAG0"]
[Tue Jul 21 07:47:36.907339 2026] [security2:error] [pid 302018:tid 302229] [client 20.206.105.145:29695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/xmrl.php"] [unique_id "al9OSIAs9lPxxVAErz34sgAAANQ"]
[Tue Jul 21 07:47:37.061149 2026] [security2:error] [pid 302018:tid 302166] [client 20.151.10.161:64179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/adminner.php"] [unique_id "al9OSYAs9lPxxVAErz34tgAAAJU"]
[Tue Jul 21 07:47:37.089136 2026] [security2:error] [pid 302018:tid 302222] [client 122.179.91.63:2457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OSYAs9lPxxVAErz34twAAAM0"]
[Tue Jul 21 07:47:37.089243 2026] [security2:error] [pid 302018:tid 302222] [client 122.179.91.63:2457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OSYAs9lPxxVAErz34twAAAM0"]
[Tue Jul 21 07:47:37.120279 2026] [security2:error] [pid 302018:tid 302251] [client 154.208.47.43:54523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OSYAs9lPxxVAErz34uAAAAOo"]
[Tue Jul 21 07:47:37.120385 2026] [security2:error] [pid 302018:tid 302251] [client 154.208.47.43:54523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OSYAs9lPxxVAErz34uAAAAOo"]
[Tue Jul 21 07:47:37.132344 2026] [security2:error] [pid 302018:tid 302223] [client 20.206.105.145:29656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/memberfuns.php"] [unique_id "al9OSYAs9lPxxVAErz34uQAAAM4"]
[Tue Jul 21 07:47:37.258253 2026] [security2:error] [pid 296703:tid 296841] [client 20.151.10.161:43904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/by.php"] [unique_id "al9OSSn25uliftkV1n4ctQAAAAg"]
[Tue Jul 21 07:47:37.301108 2026] [security2:error] [pid 302018:tid 302165] [client 173.252.95.1:36584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9OSYAs9lPxxVAErz34ugAAAJQ"]
[Tue Jul 21 07:47:37.382718 2026] [security2:error] [pid 302018:tid 302271] [client 34.14.85.22:60379] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "senseriopreto.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9OSYAs9lPxxVAErz34vQAAAP4"]
[Tue Jul 21 07:47:37.443183 2026] [security2:error] [pid 296703:tid 296938] [client 20.206.105.145:29568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/ms.php"] [unique_id "al9OSSn25uliftkV1n4cugAAAGk"]
[Tue Jul 21 07:47:37.475900 2026] [security2:error] [pid 302018:tid 302078] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OSYAs9lPxxVAErz34wgAAmTk"]
[Tue Jul 21 07:47:37.476043 2026] [security2:error] [pid 302018:tid 302170] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OSYAs9lPxxVAErz34wgAAmTk"]
[Tue Jul 21 07:47:37.519850 2026] [security2:error] [pid 302018:tid 302210] [client 20.104.96.117:27090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al9OSYAs9lPxxVAErz34wwAAAME"]
[Tue Jul 21 07:47:37.661495 2026] [security2:error] [pid 296703:tid 296951] [client 103.86.117.203:53307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OSSn25uliftkV1n4cvAAAAHY"]
[Tue Jul 21 07:47:37.661607 2026] [security2:error] [pid 296703:tid 296951] [client 103.86.117.203:53307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OSSn25uliftkV1n4cvAAAAHY"]
[Tue Jul 21 07:47:37.689668 2026] [security2:error] [pid 302018:tid 302199] [client 45.8.19.170:45319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luanaarruda.com"] [uri "/wp-login.php"] [unique_id "al9OSYAs9lPxxVAErz34xAAAALY"]
[Tue Jul 21 07:47:37.769552 2026] [security2:error] [pid 296703:tid 296897] [client 74.249.245.134:65121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/xda.php"] [unique_id "al9OSSn25uliftkV1n4cvgAAAEA"]
[Tue Jul 21 07:47:37.799399 2026] [security2:error] [pid 302018:tid 302246] [client 20.206.105.145:56596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/zz.php"] [unique_id "al9OSYAs9lPxxVAErz34xQAAAOU"]
[Tue Jul 21 07:47:38.015535 2026] [security2:error] [pid 296703:tid 296939] [client 173.252.95.5:33394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9OSin25uliftkV1n4cwgAAAGo"]
[Tue Jul 21 07:47:38.049383 2026] [security2:error] [pid 302018:tid 302188] [client 20.206.105.145:56628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/for.php"] [unique_id "al9OSoAs9lPxxVAErz340QAAAKs"]
[Tue Jul 21 07:47:38.094631 2026] [security2:error] [pid 302018:tid 302249] [client 178.153.91.96:21887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OSoAs9lPxxVAErz340wAAAOg"]
[Tue Jul 21 07:47:38.094784 2026] [security2:error] [pid 302018:tid 302249] [client 178.153.91.96:21887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OSoAs9lPxxVAErz340wAAAOg"]
[Tue Jul 21 07:47:38.212001 2026] [security2:error] [pid 296703:tid 296870] [client 20.206.105.145:29591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/yup.php"] [unique_id "al9OSin25uliftkV1n4cxAAAACU"]
[Tue Jul 21 07:47:38.229372 2026] [security2:error] [pid 296703:tid 296929] [client 20.104.96.117:46594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/txets.php"] [unique_id "al9OSin25uliftkV1n4cxQAAAGA"]
[Tue Jul 21 07:47:38.279943 2026] [security2:error] [pid 296703:tid 296944] [client 34.14.85.22:51488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "senseriopreto.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9OSin25uliftkV1n4cxgAAAG8"]
[Tue Jul 21 07:47:38.345190 2026] [security2:error] [pid 302018:tid 302223] [client 20.206.105.145:29652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wpxml.php"] [unique_id "al9OSoAs9lPxxVAErz341AAAAM4"]
[Tue Jul 21 07:47:38.385656 2026] [security2:error] [pid 302018:tid 302276] [client 152.59.154.239:51531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OSoAs9lPxxVAErz341gAAAQM"]
[Tue Jul 21 07:47:38.385776 2026] [security2:error] [pid 302018:tid 302276] [client 152.59.154.239:51531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OSoAs9lPxxVAErz341gAAAQM"]
[Tue Jul 21 07:47:38.416297 2026] [security2:error] [pid 296703:tid 296943] [client 20.206.105.145:29622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/fffm.php"] [unique_id "al9OSin25uliftkV1n4cyAAAAG4"]
[Tue Jul 21 07:47:38.602062 2026] [security2:error] [pid 296703:tid 296941] [client 20.206.105.145:29579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/gecko.php"] [unique_id "al9OSin25uliftkV1n4c0AAAAGw"]
[Tue Jul 21 07:47:38.722864 2026] [security2:error] [pid 296703:tid 296910] [client 20.206.105.145:56581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/a1.php"] [unique_id "al9OSin25uliftkV1n4c0QAAAE0"]
[Tue Jul 21 07:47:38.728579 2026] [security2:error] [pid 296703:tid 296816] [remote 198.244.183.69:34734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9OSin25uliftkV1n4c0gAAWnA"]
[Tue Jul 21 07:47:38.728705 2026] [security2:error] [pid 296703:tid 296923] [client 198.244.183.69:34734] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9OSin25uliftkV1n4c0gAAWnA"]
[Tue Jul 21 07:47:38.903420 2026] [security2:error] [pid 296703:tid 296919] [client 20.104.96.117:46691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/dex.php"] [unique_id "al9OSin25uliftkV1n4c0wAAAFY"]
[Tue Jul 21 07:47:38.921998 2026] [security2:error] [pid 302018:tid 302190] [client 20.151.10.161:43850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/FAQ.php"] [unique_id "al9OSoAs9lPxxVAErz343AAAAK0"]
[Tue Jul 21 07:47:39.139873 2026] [security2:error] [pid 302018:tid 302227] [client 20.151.10.161:63431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/admin.php"] [unique_id "al9OS4As9lPxxVAErz344wAAANI"]
[Tue Jul 21 07:47:39.146440 2026] [security2:error] [pid 302018:tid 302151] [client 34.14.85.22:58966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "senseriopreto.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9OS4As9lPxxVAErz345AAAAIY"]
[Tue Jul 21 07:47:39.164860 2026] [security2:error] [pid 302018:tid 302234] [client 20.206.105.145:56610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/k2.php"] [unique_id "al9OS4As9lPxxVAErz345gAAANk"]
[Tue Jul 21 07:47:39.231806 2026] [security2:error] [pid 302018:tid 302165] [client 122.162.144.145:8877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OS4As9lPxxVAErz345wAAAJQ"]
[Tue Jul 21 07:47:39.231950 2026] [security2:error] [pid 302018:tid 302165] [client 122.162.144.145:8877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OS4As9lPxxVAErz345wAAAJQ"]
[Tue Jul 21 07:47:39.269674 2026] [security2:error] [pid 302018:tid 302150] [client 173.252.95.20:35188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9OS4As9lPxxVAErz346AAAAIU"]
[Tue Jul 21 07:47:39.393802 2026] [security2:error] [pid 296703:tid 296911] [client 129.154.254.191:60866] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "limaradiologiadigital.com.br"] [uri "/"] [unique_id "al9OSyn25uliftkV1n4c2wAAAE4"]
[Tue Jul 21 07:47:39.471978 2026] [security2:error] [pid 296703:tid 296851] [client 20.206.105.145:56699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/82.php"] [unique_id "al9OSyn25uliftkV1n4c3AAAABI"]
[Tue Jul 21 07:47:39.605718 2026] [security2:error] [pid 296703:tid 296844] [client 106.215.181.8:10529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OSyn25uliftkV1n4c4QAAAAs"]
[Tue Jul 21 07:47:39.605880 2026] [security2:error] [pid 296703:tid 296844] [client 106.215.181.8:10529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OSyn25uliftkV1n4c4QAAAAs"]
[Tue Jul 21 07:47:39.614194 2026] [security2:error] [pid 302018:tid 302129] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OS4As9lPxxVAErz347gAAzGw"]
[Tue Jul 21 07:47:39.614350 2026] [security2:error] [pid 302018:tid 302221] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OS4As9lPxxVAErz347gAAzGw"]
[Tue Jul 21 07:47:39.622364 2026] [security2:error] [pid 296703:tid 296721] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OSyn25uliftkV1n4c4gAAAhE"]
[Tue Jul 21 07:47:39.622465 2026] [security2:error] [pid 296703:tid 296835] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OSyn25uliftkV1n4c4gAAAhE"]
[Tue Jul 21 07:47:39.642597 2026] [security2:error] [pid 302018:tid 302166] [client 20.206.105.145:29647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/config.json.php"] [unique_id "al9OS4As9lPxxVAErz347wAAAJU"]
[Tue Jul 21 07:47:39.687037 2026] [security2:error] [pid 302018:tid 302216] [client 20.206.105.145:56590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/fpwch.php"] [unique_id "al9OS4As9lPxxVAErz348AAAAMc"]
[Tue Jul 21 07:47:39.912245 2026] [security2:error] [pid 296703:tid 296956] [client 20.151.10.161:44002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/coffexium.php"] [unique_id "al9OSyn25uliftkV1n4c5QAAAHs"]
[Tue Jul 21 07:47:39.999188 2026] [security2:error] [pid 302018:tid 302233] [client 34.14.85.22:55974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "senseriopreto.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9OS4As9lPxxVAErz348QAAANg"]
[Tue Jul 21 07:47:40.097598 2026] [security2:error] [pid 302018:tid 302195] [client 136.144.33.96:52299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OTIAs9lPxxVAErz349QAAALI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:47:40.248631 2026] [security2:error] [pid 296703:tid 296940] [client 20.104.96.117:46618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/xpwer1.php"] [unique_id "al9OTCn25uliftkV1n4c8gAAAGs"]
[Tue Jul 21 07:47:40.255684 2026] [security2:error] [pid 296703:tid 296785] [remote 142.44.233.1:56288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.transitoaberto.com.br"] [uri "/"] [unique_id "al9OTCn25uliftkV1n4c8wAADFE"]
[Tue Jul 21 07:47:40.255790 2026] [security2:error] [pid 296703:tid 296845] [client 142.44.233.1:56288] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.transitoaberto.com.br"] [uri "/"] [unique_id "al9OTCn25uliftkV1n4c8wAADFE"]
[Tue Jul 21 07:47:40.318707 2026] [security2:error] [pid 302018:tid 302191] [client 74.249.245.134:64124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/shell.php"] [unique_id "al9OTIAs9lPxxVAErz34-AAAAK4"]
[Tue Jul 21 07:47:40.355290 2026] [security2:error] [pid 302018:tid 302147] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OTIAs9lPxxVAErz34-QAAln4"]
[Tue Jul 21 07:47:40.355449 2026] [security2:error] [pid 302018:tid 302167] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OTIAs9lPxxVAErz34-QAAln4"]
[Tue Jul 21 07:47:40.448527 2026] [security2:error] [pid 296703:tid 296889] [client 117.217.38.194:64303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OTCn25uliftkV1n4c9QAAADg"]
[Tue Jul 21 07:47:40.448704 2026] [security2:error] [pid 296703:tid 296889] [client 117.217.38.194:64303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OTCn25uliftkV1n4c9QAAADg"]
[Tue Jul 21 07:47:40.473643 2026] [security2:error] [pid 302018:tid 302210] [client 74.7.228.56:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpcontacts.psicologafernandaguedes.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/404.html"] [unique_id "al9OTIAs9lPxxVAErz34_AAAAME"]
[Tue Jul 21 07:47:40.476050 2026] [security2:error] [pid 302018:tid 302215] [client 74.7.228.56:47910] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpcontacts.psicologafernandaguedes.com"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "al9OTIAs9lPxxVAErz34-gAAxh8"]
[Tue Jul 21 07:47:40.599776 2026] [security2:error] [pid 302018:tid 302222] [client 103.166.103.129:23747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OTIAs9lPxxVAErz35AQAAAM0"]
[Tue Jul 21 07:47:40.599927 2026] [security2:error] [pid 302018:tid 302222] [client 103.166.103.129:23747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OTIAs9lPxxVAErz35AQAAAM0"]
[Tue Jul 21 07:47:40.601915 2026] [security2:error] [pid 302018:tid 302219] [client 20.151.10.161:43845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/red.php"] [unique_id "al9OTIAs9lPxxVAErz35AgAAAMo"]
[Tue Jul 21 07:47:40.605400 2026] [proxy:error] [pid 302018:tid 302255] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:47:40.605443 2026] [proxy_http:error] [pid 302018:tid 302255] [client 174.138.52.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:47:40.606102 2026] [proxy:error] [pid 302018:tid 302255] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:47:40.606136 2026] [proxy_http:error] [pid 302018:tid 302255] [client 174.138.52.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:47:40.634844 2026] [security2:error] [pid 296703:tid 296870] [client 20.151.10.161:64192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/k.php"] [unique_id "al9OTCn25uliftkV1n4c_AAAACU"]
[Tue Jul 21 07:47:40.718481 2026] [security2:error] [pid 302018:tid 302073] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OTIAs9lPxxVAErz35BwAAsDQ"]
[Tue Jul 21 07:47:40.718645 2026] [security2:error] [pid 302018:tid 302193] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OTIAs9lPxxVAErz35BwAAsDQ"]
[Tue Jul 21 07:47:40.818424 2026] [security2:error] [pid 296703:tid 296836] [client 51.68.111.199:21155] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gradiente.com.br"] [uri "/robots.txt"] [unique_id "al9OTCn25uliftkV1n4c_gAAAAM"]
[Tue Jul 21 07:47:40.818532 2026] [security2:error] [pid 296703:tid 296836] [client 51.68.111.199:21155] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.gradiente.com.br"] [uri "/robots.txt"] [unique_id "al9OTCn25uliftkV1n4c_gAAAAM"]
[Tue Jul 21 07:47:40.829059 2026] [security2:error] [pid 302018:tid 302232] [client 184.75.223.211:34882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9OTIAs9lPxxVAErz35CAAAANc"]
[Tue Jul 21 07:47:40.829141 2026] [security2:error] [pid 302018:tid 302232] [client 184.75.223.211:34882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9OTIAs9lPxxVAErz35CAAAANc"]
[Tue Jul 21 07:47:40.867342 2026] [proxy:error] [pid 302018:tid 302264] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:47:40.867412 2026] [proxy_http:error] [pid 302018:tid 302264] [client 174.138.52.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.rubenscoelhonascimen1781537878645.0721679.meusitehostgator.com.br/
[Tue Jul 21 07:47:40.867991 2026] [proxy:error] [pid 302018:tid 302264] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:47:40.868016 2026] [proxy_http:error] [pid 302018:tid 302264] [client 174.138.52.8:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.rubenscoelhonascimen1781537878645.0721679.meusitehostgator.com.br/
[Tue Jul 21 07:47:40.957759 2026] [security2:error] [pid 302018:tid 302238] [client 74.7.241.179:55144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.novo.mannucarvalho.com"] [uri "/robots.txt"] [unique_id "al9OTIAs9lPxxVAErz35DQAA3Uw"]
[Tue Jul 21 07:47:40.992976 2026] [security2:error] [pid 296703:tid 296939] [client 34.14.85.22:64236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "senseriopreto.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9OTCn25uliftkV1n4dAQAAAGo"]
[Tue Jul 21 07:47:41.022605 2026] [security2:error] [pid 296703:tid 296798] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OTSn25uliftkV1n4dAgAAf14"]
[Tue Jul 21 07:47:41.022777 2026] [security2:error] [pid 296703:tid 296960] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OTSn25uliftkV1n4dAgAAf14"]
[Tue Jul 21 07:47:41.129260 2026] [security2:error] [pid 302018:tid 302200] [client 74.7.241.179:55144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.novo.mannucarvalho.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al9OTYAs9lPxxVAErz35EwAAtw8"], referer: https://www.novo.mannucarvalho.com/robots.txt
[Tue Jul 21 07:47:41.228761 2026] [security2:error] [pid 302018:tid 302240] [client 20.104.96.117:27085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/flox.php"] [unique_id "al9OTYAs9lPxxVAErz35FQAAAN8"]
[Tue Jul 21 07:47:41.341495 2026] [security2:error] [pid 302018:tid 302194] [client 122.164.127.47:55335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OTYAs9lPxxVAErz35FgAAALE"]
[Tue Jul 21 07:47:41.341615 2026] [security2:error] [pid 302018:tid 302194] [client 122.164.127.47:55335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OTYAs9lPxxVAErz35FgAAALE"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:47:41.602499 2026] [security2:error] [pid 302018:tid 302244] [client 20.151.10.161:64250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/x.php"] [unique_id "al9OTYAs9lPxxVAErz35HAAAAOM"]
[Tue Jul 21 07:47:41.680460 2026] [security2:error] [pid 296703:tid 296920] [client 20.151.10.161:43907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9OTSn25uliftkV1n4dEwAAAFc"]
[Tue Jul 21 07:47:41.924254 2026] [security2:error] [pid 302018:tid 302184] [client 109.60.28.94:15367] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OTYAs9lPxxVAErz35IAAAAKc"]
[Tue Jul 21 07:47:41.924403 2026] [security2:error] [pid 302018:tid 302184] [client 109.60.28.94:15367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OTYAs9lPxxVAErz35IAAAAKc"]
[Tue Jul 21 07:47:42.026928 2026] [security2:error] [pid 296703:tid 296868] [client 34.14.85.22:55140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "senseriopreto.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9OTin25uliftkV1n4dFgAAACM"]
[Tue Jul 21 07:47:42.122300 2026] [security2:error] [pid 302018:tid 302050] [remote 51.89.129.25:39536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "insp1.com.br"] [uri "/robots.txt"] [unique_id "al9OToAs9lPxxVAErz35IwABAh0"]
[Tue Jul 21 07:47:42.122497 2026] [security2:error] [pid 302018:tid 302275] [client 51.89.129.25:39536] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "insp1.com.br"] [uri "/robots.txt"] [unique_id "al9OToAs9lPxxVAErz35IwABAh0"]
[Tue Jul 21 07:47:42.132449 2026] [security2:error] [pid 296703:tid 296843] [client 202.143.127.214:63181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OTin25uliftkV1n4dGwAAAAo"]
[Tue Jul 21 07:47:42.132531 2026] [security2:error] [pid 296703:tid 296843] [client 202.143.127.214:63181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OTin25uliftkV1n4dGwAAAAo"]
[Tue Jul 21 07:47:42.240135 2026] [security2:error] [pid 302018:tid 302087] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OToAs9lPxxVAErz35JQAArEI"]
[Tue Jul 21 07:47:42.240286 2026] [security2:error] [pid 302018:tid 302189] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OToAs9lPxxVAErz35JQAArEI"]
[Tue Jul 21 07:47:42.422741 2026] [security2:error] [pid 296703:tid 296904] [client 20.151.10.161:63392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wss.php"] [unique_id "al9OTin25uliftkV1n4dIgAAAEc"]
[Tue Jul 21 07:47:42.539040 2026] [security2:error] [pid 296703:tid 296909] [client 20.104.96.117:46694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/popo.php"] [unique_id "al9OTin25uliftkV1n4dJQAAAEw"]
[Tue Jul 21 07:47:42.668074 2026] [security2:error] [pid 302018:tid 302243] [client 223.236.153.128:5114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OToAs9lPxxVAErz35KwAAAOI"]
[Tue Jul 21 07:47:42.668196 2026] [security2:error] [pid 302018:tid 302243] [client 223.236.153.128:5114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OToAs9lPxxVAErz35KwAAAOI"]
[Tue Jul 21 07:47:42.735403 2026] [security2:error] [pid 302018:tid 302188] [client 173.252.95.114:50606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9OToAs9lPxxVAErz35KAAAAKs"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:47:42.905574 2026] [security2:error] [pid 302018:tid 302202] [client 20.151.10.161:43988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/footer.php"] [unique_id "al9OToAs9lPxxVAErz35LgAAALk"]
[Tue Jul 21 07:47:43.041328 2026] [security2:error] [pid 302018:tid 302260] [client 34.14.85.22:61891] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "senseriopreto.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9OT4As9lPxxVAErz35LwAAAPM"]
[Tue Jul 21 07:47:43.208928 2026] [security2:error] [pid 296703:tid 296876] [client 103.174.34.15:54371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OTyn25uliftkV1n4dMgAAACs"]
[Tue Jul 21 07:47:43.209054 2026] [security2:error] [pid 296703:tid 296876] [client 103.174.34.15:54371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OTyn25uliftkV1n4dMgAAACs"]
[Tue Jul 21 07:47:43.425130 2026] [security2:error] [pid 302018:tid 302167] [client 20.151.10.161:63412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/ty.php"] [unique_id "al9OT4As9lPxxVAErz35NgAAAJY"]
[Tue Jul 21 07:47:43.472980 2026] [security2:error] [pid 302018:tid 302250] [client 62.102.148.187:55646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9OT4As9lPxxVAErz35NwAAAOk"]
[Tue Jul 21 07:47:43.473072 2026] [security2:error] [pid 302018:tid 302250] [client 62.102.148.187:55646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9OT4As9lPxxVAErz35NwAAAOk"]
[Tue Jul 21 07:47:43.669721 2026] [security2:error] [pid 302018:tid 302059] [remote 142.44.220.131:21782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "insp1.com.br"] [uri "/a-arte-pode-ensinar-ciencias/"] [unique_id "al9OT4As9lPxxVAErz35PAAAnyY"]
[Tue Jul 21 07:47:43.669896 2026] [security2:error] [pid 302018:tid 302176] [client 142.44.220.131:21782] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "insp1.com.br"] [uri "/a-arte-pode-ensinar-ciencias/"] [unique_id "al9OT4As9lPxxVAErz35PAAAnyY"]
[Tue Jul 21 07:47:43.852564 2026] [security2:error] [pid 302018:tid 302156] [client 122.186.204.214:55908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OT4As9lPxxVAErz35QAAAAIs"]
[Tue Jul 21 07:47:43.852704 2026] [security2:error] [pid 302018:tid 302156] [client 122.186.204.214:55908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OT4As9lPxxVAErz35QAAAAIs"]
[Tue Jul 21 07:47:43.874103 2026] [security2:error] [pid 296703:tid 296837] [client 117.247.80.59:25952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OTyn25uliftkV1n4dOwAAAAQ"]
[Tue Jul 21 07:47:43.874204 2026] [security2:error] [pid 296703:tid 296837] [client 117.247.80.59:25952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OTyn25uliftkV1n4dOwAAAAQ"]
[Tue Jul 21 07:47:43.885685 2026] [security2:error] [pid 302018:tid 302261] [client 34.14.85.22:59709] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "senseriopreto.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9OT4As9lPxxVAErz35QQAAAPQ"]
[Tue Jul 21 07:47:44.109410 2026] [security2:error] [pid 302018:tid 302240] [client 47.128.113.237:65012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bubaby.com.br"] [uri "/robots.txt"] [unique_id "al9OUIAs9lPxxVAErz35QgAAAN8"]
[Tue Jul 21 07:47:44.170600 2026] [security2:error] [pid 296703:tid 296706] [remote 159.223.116.62:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.116.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powertronicseguranca.com"] [uri "/wp-login.php"] [unique_id "al9OUCn25uliftkV1n4dQAAAUAI"]
[Tue Jul 21 07:47:44.188860 2026] [security2:error] [pid 296703:tid 296958] [client 154.192.233.199:60344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OUCn25uliftkV1n4dQgAAAH0"]
[Tue Jul 21 07:47:44.188975 2026] [security2:error] [pid 296703:tid 296958] [client 154.192.233.199:60344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OUCn25uliftkV1n4dQgAAAH0"]
[Tue Jul 21 07:47:44.359428 2026] [security2:error] [pid 302018:tid 302161] [client 20.151.10.161:64217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/155.php"] [unique_id "al9OUIAs9lPxxVAErz35TQAAAJA"]
[Tue Jul 21 07:47:44.734682 2026] [security2:error] [pid 296703:tid 296924] [client 193.36.225.64:32909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OUCn25uliftkV1n4dTAAAAFs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:47:44.770990 2026] [security2:error] [pid 302018:tid 302251] [client 117.251.86.144:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OUIAs9lPxxVAErz35TwAAAOo"]
[Tue Jul 21 07:47:44.771162 2026] [security2:error] [pid 302018:tid 302251] [client 117.251.86.144:55240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OUIAs9lPxxVAErz35TwAAAOo"]
[Tue Jul 21 07:47:44.830246 2026] [security2:error] [pid 302018:tid 302178] [client 194.99.104.35:33698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9OUIAs9lPxxVAErz35UAAAAKE"]
[Tue Jul 21 07:47:44.830317 2026] [security2:error] [pid 302018:tid 302178] [client 194.99.104.35:33698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9OUIAs9lPxxVAErz35UAAAAKE"]
[Tue Jul 21 07:47:44.852960 2026] [security2:error] [pid 296703:tid 296926] [client 20.104.96.117:27091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/yas.php"] [unique_id "al9OUCn25uliftkV1n4dUAAAAF0"]
[Tue Jul 21 07:47:45.110251 2026] [security2:error] [pid 296703:tid 296954] [client 59.96.220.140:56405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OUSn25uliftkV1n4dVQAAAHk"]
[Tue Jul 21 07:47:45.110840 2026] [security2:error] [pid 296703:tid 296954] [client 59.96.220.140:56405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OUSn25uliftkV1n4dVQAAAHk"]
[Tue Jul 21 07:47:45.739587 2026] [security2:error] [pid 302018:tid 302183] [client 20.226.60.151:61524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/zlece.php"] [unique_id "al9OUYAs9lPxxVAErz35WgAAAKY"]
[Tue Jul 21 07:47:45.886605 2026] [security2:error] [pid 296703:tid 296870] [client 74.249.245.134:24779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/3.php"] [unique_id "al9OUSn25uliftkV1n4dZgAAACU"]
[Tue Jul 21 07:47:45.947601 2026] [security2:error] [pid 302018:tid 302136] [remote 130.185.118.215:36148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9OUYAs9lPxxVAErz35YAAAnnM"]
[Tue Jul 21 07:47:46.002165 2026] [security2:error] [pid 296703:tid 296934] [client 41.68.90.219:55160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OUin25uliftkV1n4daAAAAGU"]
[Tue Jul 21 07:47:46.004191 2026] [security2:error] [pid 296703:tid 296934] [client 41.68.90.219:55160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OUin25uliftkV1n4daAAAAGU"]
[Tue Jul 21 07:47:46.011689 2026] [security2:error] [pid 302018:tid 302025] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OUoAs9lPxxVAErz35ZAAArAQ"]
[Tue Jul 21 07:47:46.011797 2026] [security2:error] [pid 302018:tid 302189] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OUoAs9lPxxVAErz35ZAAArAQ"]
[Tue Jul 21 07:47:46.154405 2026] [security2:error] [pid 296703:tid 296837] [client 20.104.96.117:46611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/file61.php"] [unique_id "al9OUin25uliftkV1n4dbwAAAAQ"]
[Tue Jul 21 07:47:46.350853 2026] [security2:error] [pid 302018:tid 302126] [remote 114.34.90.9:35962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9OUoAs9lPxxVAErz35aQAA4Wk"]
[Tue Jul 21 07:47:46.351009 2026] [security2:error] [pid 302018:tid 302242] [client 114.34.90.9:35962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9OUoAs9lPxxVAErz35aQAA4Wk"]
[Tue Jul 21 07:47:46.491415 2026] [security2:error] [pid 296703:tid 296881] [client 20.151.10.161:63426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/ops.php"] [unique_id "al9OUin25uliftkV1n4dfQAAADA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:47:46.790433 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.790477 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.791013 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Globo-2.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.803946 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.803970 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.804246 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/IstoE.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.817735 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.817768 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.818160 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Terra.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.831621 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.831654 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.832093 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Caras.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.836924 2026] [security2:error] [pid 296703:tid 296904] [client 20.151.10.161:44028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-content/index.php"] [unique_id "al9OUin25uliftkV1n4djwAAAEc"]
[Tue Jul 21 07:47:46.843897 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.843915 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.844132 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Contigo.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.855326 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.855346 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.855558 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Bons-Fluidos.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.868796 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.868822 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.869674 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Boa-Forma.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.880757 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.880779 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.881069 2026] [lsapi:warn] [pid 296703:tid 296771] [remote 34.24.57.82:55874] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Lance.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n, referer: http://liranesuliano.com.br
[Tue Jul 21 07:47:46.929158 2026] [security2:error] [pid 296703:tid 296914] [client 139.167.225.182:52711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OUin25uliftkV1n4dlgAAAFE"]
[Tue Jul 21 07:47:46.929262 2026] [security2:error] [pid 296703:tid 296914] [client 139.167.225.182:52711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OUin25uliftkV1n4dlgAAAFE"]
[Tue Jul 21 07:47:47.158707 2026] [security2:error] [pid 296703:tid 296883] [client 182.8.255.181:17495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OUyn25uliftkV1n4d0AAAADI"]
[Tue Jul 21 07:47:47.158824 2026] [security2:error] [pid 296703:tid 296883] [client 182.8.255.181:17495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OUyn25uliftkV1n4d0AAAADI"]
[Tue Jul 21 07:47:47.272978 2026] [security2:error] [pid 302018:tid 302171] [client 173.24.185.52:53462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OU4As9lPxxVAErz35dQAAAJo"]
[Tue Jul 21 07:47:47.273105 2026] [security2:error] [pid 302018:tid 302171] [client 173.24.185.52:53462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OU4As9lPxxVAErz35dQAAAJo"]
[Tue Jul 21 07:47:47.316556 2026] [security2:error] [pid 296703:tid 296896] [client 103.29.114.44:37057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OUyn25uliftkV1n4d0gAAAD8"]
[Tue Jul 21 07:47:47.316677 2026] [security2:error] [pid 296703:tid 296896] [client 103.29.114.44:37057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OUyn25uliftkV1n4d0gAAAD8"]
[Tue Jul 21 07:47:47.361253 2026] [security2:error] [pid 302018:tid 302234] [client 20.104.96.117:46614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/water.php"] [unique_id "al9OU4As9lPxxVAErz35dwAAANk"]
[Tue Jul 21 07:47:47.646837 2026] [security2:error] [pid 302018:tid 302244] [client 122.179.91.63:24583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OU4As9lPxxVAErz35ewAAAOM"]
[Tue Jul 21 07:47:47.646986 2026] [security2:error] [pid 302018:tid 302244] [client 122.179.91.63:24583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OU4As9lPxxVAErz35ewAAAOM"]
[Tue Jul 21 07:47:47.779271 2026] [security2:error] [pid 302018:tid 302224] [client 154.208.47.43:54998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OU4As9lPxxVAErz35fQAAAM8"]
[Tue Jul 21 07:47:47.779396 2026] [security2:error] [pid 302018:tid 302224] [client 154.208.47.43:54998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OU4As9lPxxVAErz35fQAAAM8"]
[Tue Jul 21 07:47:47.814618 2026] [security2:error] [pid 296703:tid 296730] [remote 51.195.215.203:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "annaguimaraes.com.br"] [uri "/robots.txt"] [unique_id "al9OUyn25uliftkV1n4d4wAAWxo"]
[Tue Jul 21 07:47:47.814772 2026] [security2:error] [pid 296703:tid 296924] [client 51.195.215.203:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "annaguimaraes.com.br"] [uri "/robots.txt"] [unique_id "al9OUyn25uliftkV1n4d4wAAWxo"]
[Tue Jul 21 07:47:47.879212 2026] [security2:error] [pid 302018:tid 302150] [client 20.104.96.117:46651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/nano.php"] [unique_id "al9OU4As9lPxxVAErz35fgAAAIU"]
[Tue Jul 21 07:47:48.022066 2026] [security2:error] [pid 296703:tid 296724] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iducali.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9OVCn25uliftkV1n4eEgAADBQ"]
[Tue Jul 21 07:47:48.149667 2026] [security2:error] [pid 296703:tid 296881] [client 103.86.117.203:53851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OVCn25uliftkV1n4eFQAAADA"]
[Tue Jul 21 07:47:48.149797 2026] [security2:error] [pid 296703:tid 296881] [client 103.86.117.203:53851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OVCn25uliftkV1n4eFQAAADA"]
[Tue Jul 21 07:47:48.168015 2026] [security2:error] [pid 296703:tid 296820] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iducali.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9OVCn25uliftkV1n4eFgAAf3Q"]
[Tue Jul 21 07:47:48.204729 2026] [security2:error] [pid 302018:tid 302077] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OVIAs9lPxxVAErz35igAAnjg"]
[Tue Jul 21 07:47:48.204875 2026] [security2:error] [pid 302018:tid 302175] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OVIAs9lPxxVAErz35igAAnjg"]
[Tue Jul 21 07:47:48.381294 2026] [security2:error] [pid 296703:tid 296768] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iducali.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9OVCn25uliftkV1n4eGgAAVEA"]
[Tue Jul 21 07:47:48.422706 2026] [security2:error] [pid 296703:tid 296935] [client 193.36.225.142:64537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OVCn25uliftkV1n4eGAAAAGY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:47:48.510476 2026] [security2:error] [pid 296703:tid 296815] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iducali.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9OVCn25uliftkV1n4eIwAAL28"]
[Tue Jul 21 07:47:48.615557 2026] [security2:error] [pid 302018:tid 302187] [client 178.153.91.96:22557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OVIAs9lPxxVAErz35jQAAAKo"]
[Tue Jul 21 07:47:48.615674 2026] [security2:error] [pid 302018:tid 302187] [client 178.153.91.96:22557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OVIAs9lPxxVAErz35jQAAAKo"]
[Tue Jul 21 07:47:48.634988 2026] [security2:error] [pid 296703:tid 296785] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iducali.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9OVCn25uliftkV1n4eJQAAaFE"]
[Tue Jul 21 07:47:48.663578 2026] [security2:error] [pid 302018:tid 302243] [client 20.151.10.161:64130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/ingfo.php"] [unique_id "al9OVIAs9lPxxVAErz35jgAAAOI"]
[Tue Jul 21 07:47:48.712783 2026] [security2:error] [pid 302018:tid 302227] [client 136.144.33.104:21971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OVIAs9lPxxVAErz35jwAAANI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:47:48.786682 2026] [security2:error] [pid 296703:tid 296763] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iducali.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9OVCn25uliftkV1n4eKQAAHTs"]
[Tue Jul 21 07:47:48.812853 2026] [security2:error] [pid 296703:tid 296946] [client 20.151.10.161:43936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/zoro.php"] [unique_id "al9OVCn25uliftkV1n4eNAAAAHE"]
[Tue Jul 21 07:47:48.860774 2026] [security2:error] [pid 302018:tid 302212] [client 20.104.96.117:27078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/moon.php"] [unique_id "al9OVIAs9lPxxVAErz35lAAAAMM"]
[Tue Jul 21 07:47:48.910498 2026] [security2:error] [pid 296703:tid 296821] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iducali.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9OVCn25uliftkV1n4eNQAAM3U"]
[Tue Jul 21 07:47:49.118097 2026] [security2:error] [pid 296703:tid 296913] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "digital-universo.com"] [uri "/index.php"] [unique_id "al9OVSn25uliftkV1n4eOwAAUEI"]
[Tue Jul 21 07:47:49.242466 2026] [security2:error] [pid 302018:tid 302242] [client 152.59.154.239:52043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OVYAs9lPxxVAErz35mwAAAOE"]
[Tue Jul 21 07:47:49.242617 2026] [security2:error] [pid 302018:tid 302242] [client 152.59.154.239:52043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OVYAs9lPxxVAErz35mwAAAOE"]
[Tue Jul 21 07:47:49.330612 2026] [security2:error] [pid 296703:tid 296779] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iducali.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9OVSn25uliftkV1n4eRAAAeEs"]
[Tue Jul 21 07:47:49.436345 2026] [security2:error] [pid 302018:tid 302084] [remote 51.161.37.107:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "annaguimaraes.com.br"] [uri "/"] [unique_id "al9OVYAs9lPxxVAErz35ngAA_D8"]
[Tue Jul 21 07:47:49.436566 2026] [security2:error] [pid 302018:tid 302269] [client 51.161.37.107:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "annaguimaraes.com.br"] [uri "/"] [unique_id "al9OVYAs9lPxxVAErz35ngAA_D8"]
[Tue Jul 21 07:47:49.504351 2026] [security2:error] [pid 302018:tid 302248] [client 74.249.245.134:64390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/mds.php"] [unique_id "al9OVYAs9lPxxVAErz35ogAAAOc"]
[Tue Jul 21 07:47:49.507145 2026] [security2:error] [pid 296703:tid 296704] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iducali.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9OVSn25uliftkV1n4eSgAAPQA"]
[Tue Jul 21 07:47:49.683163 2026] [security2:error] [pid 296703:tid 296729] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iducali.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9OVSn25uliftkV1n4eTwAANxk"]
[Tue Jul 21 07:47:49.820669 2026] [security2:error] [pid 296703:tid 296787] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iducali.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9OVSn25uliftkV1n4eUwAAS1M"]
[Tue Jul 21 07:47:49.949540 2026] [security2:error] [pid 296703:tid 296830] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iducali.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9OVSn25uliftkV1n4eVQAAC34"]
[Tue Jul 21 07:47:49.962892 2026] [security2:error] [pid 302018:tid 302038] [remote 45.117.83.212:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9OVYAs9lPxxVAErz35vwAA7hE"]
[Tue Jul 21 07:47:49.988398 2026] [security2:error] [pid 302018:tid 302168] [client 122.162.144.145:2063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OVYAs9lPxxVAErz35wAAAAJc"]
[Tue Jul 21 07:47:49.988501 2026] [security2:error] [pid 302018:tid 302168] [client 122.162.144.145:2063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OVYAs9lPxxVAErz35wAAAAJc"]
[Tue Jul 21 07:47:50.116868 2026] [security2:error] [pid 302018:tid 302060] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OVoAs9lPxxVAErz35xQAA2ic"]
[Tue Jul 21 07:47:50.116997 2026] [security2:error] [pid 302018:tid 302235] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OVoAs9lPxxVAErz35xQAA2ic"]
[Tue Jul 21 07:47:50.164634 2026] [security2:error] [pid 296703:tid 296705] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OVin25uliftkV1n4eXQAAVwE"]
[Tue Jul 21 07:47:50.164751 2026] [security2:error] [pid 296703:tid 296920] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OVin25uliftkV1n4eXQAAVwE"]
[Tue Jul 21 07:47:50.175778 2026] [security2:error] [pid 296703:tid 296931] [client 20.151.10.161:64246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/error_log.php"] [unique_id "al9OVin25uliftkV1n4eXwAAAGI"]
[Tue Jul 21 07:47:50.221367 2026] [security2:error] [pid 302018:tid 302244] [client 106.215.181.8:4355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OVoAs9lPxxVAErz35xwAAAOM"]
[Tue Jul 21 07:47:50.221478 2026] [security2:error] [pid 302018:tid 302244] [client 106.215.181.8:4355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OVoAs9lPxxVAErz35xwAAAOM"]
[Tue Jul 21 07:47:50.316080 2026] [security2:error] [pid 302018:tid 302260] [client 20.104.96.117:46619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-info.php"] [unique_id "al9OVoAs9lPxxVAErz35ygAAAPM"]
[Tue Jul 21 07:47:50.735951 2026] [security2:error] [pid 302018:tid 302258] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9OVoAs9lPxxVAErz353QAAAPE"]
[Tue Jul 21 07:47:50.757315 2026] [security2:error] [pid 302018:tid 302262] [client 62.102.148.187:49604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9OVoAs9lPxxVAErz353gAAAPU"]
[Tue Jul 21 07:47:50.757423 2026] [security2:error] [pid 302018:tid 302262] [client 62.102.148.187:49604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9OVoAs9lPxxVAErz353gAAAPU"]
[Tue Jul 21 07:47:50.797019 2026] [security2:error] [pid 302018:tid 302150] [client 20.151.10.161:43914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/admin.php"] [unique_id "al9OVoAs9lPxxVAErz354AAAAIU"]
[Tue Jul 21 07:47:50.897123 2026] [security2:error] [pid 302018:tid 302061] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OVoAs9lPxxVAErz354gAAnSg"]
[Tue Jul 21 07:47:50.897339 2026] [security2:error] [pid 302018:tid 302174] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OVoAs9lPxxVAErz354gAAnSg"]
[Tue Jul 21 07:47:50.960591 2026] [security2:error] [pid 296703:tid 296942] [client 20.104.96.117:46679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/2000.php"] [unique_id "al9OVin25uliftkV1n4eawAAAG0"]
[Tue Jul 21 07:47:50.972957 2026] [security2:error] [pid 296703:tid 296956] [client 20.151.10.161:64237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/ok.php"] [unique_id "al9OVin25uliftkV1n4ebAAAAHs"]
[Tue Jul 21 07:47:50.974286 2026] [security2:error] [pid 302018:tid 302275] [client 117.217.38.194:64804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OVoAs9lPxxVAErz355AAAAQI"]
[Tue Jul 21 07:47:50.974395 2026] [security2:error] [pid 302018:tid 302275] [client 117.217.38.194:64804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OVoAs9lPxxVAErz355AAAAQI"]
[Tue Jul 21 07:47:51.027439 2026] [security2:error] [pid 302018:tid 302166] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OV4As9lPxxVAErz355QAAAJU"]
[Tue Jul 21 07:47:51.133288 2026] [security2:error] [pid 296703:tid 296862] [client 62.102.148.187:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OVyn25uliftkV1n4ecQAAAB0"]
[Tue Jul 21 07:47:51.133375 2026] [security2:error] [pid 296703:tid 296862] [client 62.102.148.187:49614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OVyn25uliftkV1n4ecQAAAB0"]
[Tue Jul 21 07:47:51.263793 2026] [security2:error] [pid 302018:tid 302273] [client 103.166.103.129:56252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OV4As9lPxxVAErz356wAAAQA"]
[Tue Jul 21 07:47:51.263950 2026] [security2:error] [pid 302018:tid 302273] [client 103.166.103.129:56252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OV4As9lPxxVAErz356wAAAQA"]
[Tue Jul 21 07:47:51.506828 2026] [security2:error] [pid 296703:tid 296919] [client 20.151.10.161:44019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/greap.php"] [unique_id "al9OVyn25uliftkV1n4efQAAAFY"]
[Tue Jul 21 07:47:51.509747 2026] [security2:error] [pid 302018:tid 302260] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9OV4As9lPxxVAErz358gAAAPM"]
[Tue Jul 21 07:47:51.576134 2026] [security2:error] [pid 302018:tid 302175] [client 20.104.96.117:46718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/122.php"] [unique_id "al9OV4As9lPxxVAErz359AAAAJ4"]
[Tue Jul 21 07:47:51.614328 2026] [security2:error] [pid 296703:tid 296829] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OVyn25uliftkV1n4epAAAI30"]
[Tue Jul 21 07:47:51.614475 2026] [security2:error] [pid 296703:tid 296868] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OVyn25uliftkV1n4epAAAI30"]
[Tue Jul 21 07:47:51.750543 2026] [security2:error] [pid 302018:tid 302064] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OV4As9lPxxVAErz35_AAAqis"]
[Tue Jul 21 07:47:51.750726 2026] [security2:error] [pid 302018:tid 302187] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OV4As9lPxxVAErz35_AAAqis"]
[Tue Jul 21 07:47:51.797346 2026] [security2:error] [pid 302018:tid 302224] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9OV4As9lPxxVAErz35_gAAAM8"]
[Tue Jul 21 07:47:51.815964 2026] [security2:error] [pid 302018:tid 302202] [client 128.127.105.184:60304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9OV4As9lPxxVAErz35_wAAALk"]
[Tue Jul 21 07:47:51.816058 2026] [security2:error] [pid 302018:tid 302202] [client 128.127.105.184:60304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9OV4As9lPxxVAErz35_wAAALk"]
[Tue Jul 21 07:47:51.907994 2026] [security2:error] [pid 296703:tid 296946] [client 122.164.127.47:55906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OVyn25uliftkV1n4eqgAAAHE"]
[Tue Jul 21 07:47:51.908125 2026] [security2:error] [pid 296703:tid 296946] [client 122.164.127.47:55906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OVyn25uliftkV1n4eqgAAAHE"]
[Tue Jul 21 07:47:51.922123 2026] [security2:error] [pid 302018:tid 302250] [client 20.151.10.161:63481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/mac.php"] [unique_id "al9OV4As9lPxxVAErz36AgAAAOk"]
[Tue Jul 21 07:47:52.003301 2026] [security2:error] [pid 296703:tid 296852] [client 20.104.96.117:46627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/mds.php"] [unique_id "al9OWCn25uliftkV1n4eqwAAABM"]
[Tue Jul 21 07:47:52.108914 2026] [security2:error] [pid 296703:tid 296865] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9OWCn25uliftkV1n4erQAAACA"]
[Tue Jul 21 07:47:52.376127 2026] [security2:error] [pid 302018:tid 302277] [client 136.144.33.96:65043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OWIAs9lPxxVAErz36CgAAAQQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:47:52.397537 2026] [security2:error] [pid 296703:tid 296895] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9OWCn25uliftkV1n4etwAAAD4"]
[Tue Jul 21 07:47:52.419467 2026] [security2:error] [pid 302018:tid 302254] [client 20.226.60.151:61601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/vssrs.php"] [unique_id "al9OWIAs9lPxxVAErz36CwAAAO0"]
[Tue Jul 21 07:47:52.509099 2026] [security2:error] [pid 296703:tid 296935] [client 194.99.104.35:40382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9OWCn25uliftkV1n4eugAAAGY"]
[Tue Jul 21 07:47:52.509200 2026] [security2:error] [pid 296703:tid 296935] [client 194.99.104.35:40382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9OWCn25uliftkV1n4eugAAAGY"]
[Tue Jul 21 07:47:52.575039 2026] [security2:error] [pid 302018:tid 302039] [remote 5.252.52.249:43156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9OWIAs9lPxxVAErz36EAAA4BI"]
[Tue Jul 21 07:47:52.658870 2026] [security2:error] [pid 302018:tid 302243] [client 20.104.96.117:27075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-blink.php"] [unique_id "al9OWIAs9lPxxVAErz36EQAAAOI"]
[Tue Jul 21 07:47:52.683721 2026] [security2:error] [pid 302018:tid 302276] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9OWIAs9lPxxVAErz36EgAAAQM"]
[Tue Jul 21 07:47:52.854645 2026] [security2:error] [pid 302018:tid 302160] [client 20.226.60.151:61586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wicked.php"] [unique_id "al9OWIAs9lPxxVAErz36FwAAAI8"]
[Tue Jul 21 07:47:52.905081 2026] [security2:error] [pid 296703:tid 296823] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OWCn25uliftkV1n4ewgAALnc"]
[Tue Jul 21 07:47:52.905269 2026] [security2:error] [pid 296703:tid 296879] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OWCn25uliftkV1n4ewgAALnc"]
[Tue Jul 21 07:47:52.912130 2026] [security2:error] [pid 296703:tid 296944] [client 193.36.225.122:32003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OVyn25uliftkV1n4epwAAAG8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:47:52.969236 2026] [security2:error] [pid 302018:tid 302212] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9OWIAs9lPxxVAErz36GAAAAMM"]
[Tue Jul 21 07:47:53.086978 2026] [security2:error] [pid 296703:tid 296942] [client 20.226.60.151:61537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/24.php"] [unique_id "al9OWSn25uliftkV1n4exAAAAG0"]
[Tue Jul 21 07:47:53.113086 2026] [security2:error] [pid 302018:tid 302219] [client 20.104.96.117:46605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/zc-208.php"] [unique_id "al9OWYAs9lPxxVAErz36GgAAAMo"]
[Tue Jul 21 07:47:53.254314 2026] [security2:error] [pid 296703:tid 296933] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9OWSn25uliftkV1n4exgAAAGQ"]
[Tue Jul 21 07:47:53.270827 2026] [security2:error] [pid 302018:tid 302227] [client 202.143.127.214:63643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OWYAs9lPxxVAErz36HQAAANI"]
[Tue Jul 21 07:47:53.270982 2026] [security2:error] [pid 302018:tid 302227] [client 202.143.127.214:63643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OWYAs9lPxxVAErz36HQAAANI"]
[Tue Jul 21 07:47:53.391392 2026] [security2:error] [pid 296703:tid 296833] [client 223.236.153.128:2469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OWSn25uliftkV1n4eygAAAAA"]
[Tue Jul 21 07:47:53.391539 2026] [security2:error] [pid 296703:tid 296833] [client 223.236.153.128:2469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OWSn25uliftkV1n4eygAAAAA"]
[Tue Jul 21 07:47:53.406313 2026] [security2:error] [pid 302018:tid 302150] [client 20.151.10.161:43908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/177.php"] [unique_id "al9OWYAs9lPxxVAErz36IAAAAIU"]
[Tue Jul 21 07:47:53.428530 2026] [security2:error] [pid 302018:tid 302215] [client 20.226.60.151:61589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/xacs.php"] [unique_id "al9OWYAs9lPxxVAErz36IQAAAMY"]
[Tue Jul 21 07:47:53.540365 2026] [security2:error] [pid 302018:tid 302206] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9OWYAs9lPxxVAErz36JAAAAL0"]
[Tue Jul 21 07:47:53.631621 2026] [security2:error] [pid 296703:tid 296896] [client 20.104.96.117:46612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/sid4.php"] [unique_id "al9OWSn25uliftkV1n4ezgAAAD8"]
[Tue Jul 21 07:47:53.730388 2026] [security2:error] [pid 302018:tid 302254] [client 20.151.10.161:64239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wefile.php"] [unique_id "al9OWYAs9lPxxVAErz36TAAAAO0"]
[Tue Jul 21 07:47:53.825204 2026] [security2:error] [pid 302018:tid 302241] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9OWYAs9lPxxVAErz36TgAAAOA"]
[Tue Jul 21 07:47:54.005064 2026] [security2:error] [pid 302018:tid 302194] [client 103.174.34.15:54882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OWoAs9lPxxVAErz36YQAAALE"]
[Tue Jul 21 07:47:54.005210 2026] [security2:error] [pid 302018:tid 302194] [client 103.174.34.15:54882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OWoAs9lPxxVAErz36YQAAALE"]
[Tue Jul 21 07:47:54.114091 2026] [security2:error] [pid 302018:tid 302156] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9OWoAs9lPxxVAErz36dQAAAIs"]
[Tue Jul 21 07:47:54.401545 2026] [security2:error] [pid 302018:tid 302206] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9OWoAs9lPxxVAErz36hAAAAL0"]
[Tue Jul 21 07:47:54.462856 2026] [security2:error] [pid 296703:tid 296864] [client 20.151.10.161:63398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9OWin25uliftkV1n4e4AAAAB8"]
[Tue Jul 21 07:47:54.551279 2026] [security2:error] [pid 296703:tid 296782] [remote 5.252.52.249:47296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carrosselbuique.com.br"] [uri "/wp-login.php"] [unique_id "al9OWin25uliftkV1n4e4gAAIk4"]
[Tue Jul 21 07:47:54.586971 2026] [security2:error] [pid 302018:tid 302155] [client 20.104.96.117:46680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wmore1.php"] [unique_id "al9OWoAs9lPxxVAErz36iAAAAIo"]
[Tue Jul 21 07:47:54.628270 2026] [security2:error] [pid 302018:tid 302244] [client 117.247.80.59:29113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OWoAs9lPxxVAErz36iwAAAOM"]
[Tue Jul 21 07:47:54.628424 2026] [security2:error] [pid 302018:tid 302244] [client 117.247.80.59:29113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OWoAs9lPxxVAErz36iwAAAOM"]
[Tue Jul 21 07:47:54.657108 2026] [security2:error] [pid 302018:tid 302167] [client 122.186.204.214:56446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OWoAs9lPxxVAErz36jgAAAJY"]
[Tue Jul 21 07:47:54.657222 2026] [security2:error] [pid 302018:tid 302167] [client 122.186.204.214:56446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OWoAs9lPxxVAErz36jgAAAJY"]
[Tue Jul 21 07:47:54.686445 2026] [security2:error] [pid 296703:tid 296835] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9OWin25uliftkV1n4e5wAAAAI"]
[Tue Jul 21 07:47:54.861682 2026] [security2:error] [pid 302018:tid 302038] [remote 142.44.233.4:59506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "limetteodontologia.com.br"] [uri "/odontologia-digital-como-o-escaneamento-3d-revoluciona-os-tratamentos/"] [unique_id "al9OWoAs9lPxxVAErz36kQAA6BE"]
[Tue Jul 21 07:47:54.861851 2026] [security2:error] [pid 302018:tid 302249] [client 142.44.233.4:59506] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "limetteodontologia.com.br"] [uri "/odontologia-digital-como-o-escaneamento-3d-revoluciona-os-tratamentos/"] [unique_id "al9OWoAs9lPxxVAErz36kQAA6BE"]
[Tue Jul 21 07:47:54.914125 2026] [security2:error] [pid 296703:tid 296946] [client 154.192.233.199:59062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OWin25uliftkV1n4e6wAAAHE"]
[Tue Jul 21 07:47:54.914263 2026] [security2:error] [pid 296703:tid 296946] [client 154.192.233.199:59062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OWin25uliftkV1n4e6wAAAHE"]
[Tue Jul 21 07:47:54.972231 2026] [security2:error] [pid 296703:tid 296850] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9OWin25uliftkV1n4e7QAAABE"]
[Tue Jul 21 07:47:55.000572 2026] [security2:error] [pid 302018:tid 302212] [client 20.151.10.161:43977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/199.php"] [unique_id "al9OWoAs9lPxxVAErz36mAAAAMM"]
[Tue Jul 21 07:47:55.257140 2026] [security2:error] [pid 296703:tid 296834] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9OWyn25uliftkV1n4e8QAAAAE"]
[Tue Jul 21 07:47:55.391521 2026] [security2:error] [pid 302018:tid 302060] [remote 185.242.3.159:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "naturofarma.com.br"] [uri "/"] [unique_id "al9OW4As9lPxxVAErz36oQAAqic"]
[Tue Jul 21 07:47:55.433443 2026] [security2:error] [pid 296703:tid 296844] [client 117.251.86.144:60832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OWyn25uliftkV1n4e8wAAAAs"]
[Tue Jul 21 07:47:55.433559 2026] [security2:error] [pid 296703:tid 296844] [client 117.251.86.144:60832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OWyn25uliftkV1n4e8wAAAAs"]
[Tue Jul 21 07:47:55.439604 2026] [security2:error] [pid 296703:tid 296942] [client 20.104.96.117:46599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/solo1.php"] [unique_id "al9OWyn25uliftkV1n4e9QAAAG0"]
[Tue Jul 21 07:47:55.543165 2026] [security2:error] [pid 296703:tid 296948] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9OWyn25uliftkV1n4e-gAAAHM"]
[Tue Jul 21 07:47:55.563952 2026] [security2:error] [pid 302018:tid 302216] [client 194.99.104.35:40394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9OW4As9lPxxVAErz36pQAAAMc"]
[Tue Jul 21 07:47:55.564070 2026] [security2:error] [pid 302018:tid 302216] [client 194.99.104.35:40394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9OW4As9lPxxVAErz36pQAAAMc"]
[Tue Jul 21 07:47:55.590615 2026] [access_compat:error] [pid 296703:tid 296906] [client 162.241.63.68:41036] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:47:55.676839 2026] [security2:error] [pid 296703:tid 296889] [client 59.96.220.140:56909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OWyn25uliftkV1n4e_gAAADg"]
[Tue Jul 21 07:47:55.676953 2026] [security2:error] [pid 296703:tid 296889] [client 59.96.220.140:56909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OWyn25uliftkV1n4e_gAAADg"]
[Tue Jul 21 07:47:55.827904 2026] [security2:error] [pid 302018:tid 302161] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.marielamartinscruz1782866921729.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9OW4As9lPxxVAErz36qwAAAJA"]
[Tue Jul 21 07:47:56.109067 2026] [security2:error] [pid 296703:tid 296951] [client 74.249.245.134:8775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/archive.php"] [unique_id "al9OXCn25uliftkV1n4fCQAAAHY"]
[Tue Jul 21 07:47:56.195760 2026] [security2:error] [pid 302018:tid 302241] [client 20.104.96.117:46685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/cong.php"] [unique_id "al9OXIAs9lPxxVAErz36twAAAOA"]
[Tue Jul 21 07:47:56.212035 2026] [security2:error] [pid 302018:tid 302194] [client 62.102.148.187:49628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9OXIAs9lPxxVAErz36uQAAALE"]
[Tue Jul 21 07:47:56.212897 2026] [security2:error] [pid 302018:tid 302194] [client 62.102.148.187:49628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9OXIAs9lPxxVAErz36uQAAALE"]
[Tue Jul 21 07:47:56.225106 2026] [security2:error] [pid 302018:tid 302191] [client 62.102.148.187:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OXIAs9lPxxVAErz36ugAAAK4"]
[Tue Jul 21 07:47:56.225184 2026] [security2:error] [pid 302018:tid 302191] [client 62.102.148.187:49640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OXIAs9lPxxVAErz36ugAAAK4"]
[Tue Jul 21 07:47:56.534181 2026] [security2:error] [pid 296703:tid 296799] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OXCn25uliftkV1n4fEAAAPV8"]
[Tue Jul 21 07:47:56.534316 2026] [security2:error] [pid 296703:tid 296894] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OXCn25uliftkV1n4fEAAAPV8"]
[Tue Jul 21 07:47:56.607121 2026] [security2:error] [pid 302018:tid 302256] [client 41.68.90.219:55560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OXIAs9lPxxVAErz36vQAAAO8"]
[Tue Jul 21 07:47:56.608215 2026] [security2:error] [pid 302018:tid 302256] [client 41.68.90.219:55560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OXIAs9lPxxVAErz36vQAAAO8"]
[Tue Jul 21 07:47:56.750146 2026] [security2:error] [pid 296703:tid 296869] [client 20.151.10.161:43861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/file52.php"] [unique_id "al9OXCn25uliftkV1n4fFAAAACQ"]
[Tue Jul 21 07:47:56.966047 2026] [security2:error] [pid 296703:tid 296734] [remote 185.242.3.159:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "naturofarma.com.br"] [uri "/_profiler/empty/search/results"] [unique_id "al9OXCn25uliftkV1n4fGwAAQh4"]
[Tue Jul 21 07:47:57.044193 2026] [proxy:error] [pid 302018:tid 302185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:47:57.044248 2026] [proxy_http:error] [pid 302018:tid 302185] [client 198.235.24.144:57970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:47:57.044724 2026] [proxy:error] [pid 302018:tid 302185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:47:57.044750 2026] [proxy_http:error] [pid 302018:tid 302185] [client 198.235.24.144:57970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:47:57.142286 2026] [security2:error] [pid 296703:tid 296960] [client 20.104.96.117:27086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/public/css.php"] [unique_id "al9OXSn25uliftkV1n4fJAAAAH8"]
[Tue Jul 21 07:47:57.222423 2026] [security2:error] [pid 302018:tid 302219] [client 136.144.33.100:37421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OXYAs9lPxxVAErz36vwAAAMo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:47:57.444589 2026] [security2:error] [pid 296703:tid 296930] [client 185.213.175.37:20284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "armazemraizesdaserra.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OXSn25uliftkV1n4fKQAAAGE"]
[Tue Jul 21 07:47:57.529173 2026] [security2:error] [pid 296703:tid 296885] [client 139.167.225.182:53357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OXSn25uliftkV1n4fLgAAADQ"]
[Tue Jul 21 07:47:57.529331 2026] [security2:error] [pid 296703:tid 296885] [client 139.167.225.182:53357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OXSn25uliftkV1n4fLgAAADQ"]
[Tue Jul 21 07:47:57.576731 2026] [security2:error] [pid 302018:tid 302176] [client 20.104.96.117:46663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/output.php"] [unique_id "al9OXYAs9lPxxVAErz360gAAAJ8"]
[Tue Jul 21 07:47:57.577881 2026] [security2:error] [pid 296703:tid 296730] [remote 180.153.236.122:31577] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9OXSn25uliftkV1n4fMAAAKho"], referer: https://tabelionatoportoalegre.com.br/
[Tue Jul 21 07:47:57.578072 2026] [security2:error] [pid 296703:tid 296875] [client 180.153.236.122:31577] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9OXSn25uliftkV1n4fMAAAKho"], referer: https://tabelionatoportoalegre.com.br/
[Tue Jul 21 07:47:57.640720 2026] [security2:error] [pid 302018:tid 302222] [client 182.8.255.181:17549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OXYAs9lPxxVAErz361wAAAM0"]
[Tue Jul 21 07:47:57.640841 2026] [security2:error] [pid 302018:tid 302222] [client 182.8.255.181:17549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OXYAs9lPxxVAErz361wAAAM0"]
[Tue Jul 21 07:47:57.656649 2026] [security2:error] [pid 296703:tid 296834] [client 34.141.254.56:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.msc.oscrias.com.br"] [uri "/"] [unique_id "al9OXSn25uliftkV1n4fNgAAAAE"]
[Tue Jul 21 07:47:57.656727 2026] [security2:error] [pid 296703:tid 296834] [client 34.141.254.56:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.msc.oscrias.com.br"] [uri "/"] [unique_id "al9OXSn25uliftkV1n4fNgAAAAE"]
[Tue Jul 21 07:47:57.897338 2026] [security2:error] [pid 302018:tid 302181] [client 173.24.185.52:53927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OXYAs9lPxxVAErz364AAAAKQ"]
[Tue Jul 21 07:47:57.897452 2026] [security2:error] [pid 302018:tid 302181] [client 173.24.185.52:53927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OXYAs9lPxxVAErz364AAAAKQ"]
[Tue Jul 21 07:47:58.039685 2026] [security2:error] [pid 302018:tid 302262] [client 20.104.96.117:27102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-file-120.php"] [unique_id "al9OXoAs9lPxxVAErz365AAAAPU"]
[Tue Jul 21 07:47:58.144811 2026] [security2:error] [pid 302018:tid 302155] [client 154.208.47.43:55474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OXoAs9lPxxVAErz365wAAAIo"]
[Tue Jul 21 07:47:58.147153 2026] [security2:error] [pid 302018:tid 302155] [client 154.208.47.43:55474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OXoAs9lPxxVAErz365wAAAIo"]
[Tue Jul 21 07:47:58.225687 2026] [security2:error] [pid 302018:tid 302241] [client 136.144.33.25:37793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OXoAs9lPxxVAErz365QAAAOA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:47:58.328412 2026] [security2:error] [pid 296703:tid 296948] [client 122.179.91.63:25926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OXin25uliftkV1n4fUQAAAHM"]
[Tue Jul 21 07:47:58.328587 2026] [security2:error] [pid 296703:tid 296948] [client 122.179.91.63:25926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OXin25uliftkV1n4fUQAAAHM"]
[Tue Jul 21 07:47:58.454418 2026] [security2:error] [pid 296703:tid 296906] [client 103.29.114.44:54706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OXin25uliftkV1n4fVwAAAEk"]
[Tue Jul 21 07:47:58.454522 2026] [security2:error] [pid 296703:tid 296906] [client 103.29.114.44:54706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OXin25uliftkV1n4fVwAAAEk"]
[Tue Jul 21 07:47:58.621489 2026] [security2:error] [pid 296703:tid 296860] [client 103.86.117.203:54399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OXin25uliftkV1n4fWwAAABs"]
[Tue Jul 21 07:47:58.621714 2026] [security2:error] [pid 296703:tid 296860] [client 103.86.117.203:54399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OXin25uliftkV1n4fWwAAABs"]
[Tue Jul 21 07:47:58.653088 2026] [security2:error] [pid 296703:tid 296937] [client 20.104.96.117:46695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/special.php"] [unique_id "al9OXin25uliftkV1n4fXgAAAGg"]
[Tue Jul 21 07:47:58.965766 2026] [security2:error] [pid 296703:tid 296811] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OXin25uliftkV1n4fZgAAHWs"]
[Tue Jul 21 07:47:58.965899 2026] [security2:error] [pid 296703:tid 296862] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OXin25uliftkV1n4fZgAAHWs"]
[Tue Jul 21 07:47:59.015835 2026] [security2:error] [pid 296703:tid 296837] [client 62.102.148.187:52208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9OXyn25uliftkV1n4fZwAAAAQ"]
[Tue Jul 21 07:47:59.015937 2026] [security2:error] [pid 296703:tid 296837] [client 62.102.148.187:52208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9OXyn25uliftkV1n4fZwAAAAQ"]
[Tue Jul 21 07:47:59.115495 2026] [security2:error] [pid 302018:tid 302171] [client 20.151.10.161:64131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9OX4As9lPxxVAErz37LwAAAJo"]
[Tue Jul 21 07:47:59.128772 2026] [security2:error] [pid 302018:tid 302229] [client 20.104.96.117:46708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/as.php"] [unique_id "al9OX4As9lPxxVAErz37MAAAANQ"]
[Tue Jul 21 07:47:59.161879 2026] [security2:error] [pid 302018:tid 302160] [client 178.153.91.96:61284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OX4As9lPxxVAErz37MgAAAI8"]
[Tue Jul 21 07:47:59.162086 2026] [security2:error] [pid 302018:tid 302160] [client 178.153.91.96:61284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OX4As9lPxxVAErz37MgAAAI8"]
[Tue Jul 21 07:47:59.356341 2026] [security2:error] [pid 302018:tid 302263] [client 20.151.10.161:43984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/122.php"] [unique_id "al9OX4As9lPxxVAErz37OQAAAPY"]
[Tue Jul 21 07:47:59.399038 2026] [security2:error] [pid 302018:tid 302252] [client 74.249.245.134:24819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/amax.php"] [unique_id "al9OX4As9lPxxVAErz37OgAAAOs"]
[Tue Jul 21 07:47:59.745504 2026] [security2:error] [pid 302018:tid 302256] [client 20.104.96.117:27093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/cgi-bin/index.php"] [unique_id "al9OX4As9lPxxVAErz37SQAAAO8"]
[Tue Jul 21 07:47:59.977592 2026] [security2:error] [pid 302018:tid 302224] [client 152.59.154.239:52533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OX4As9lPxxVAErz37TwAAAM8"]
[Tue Jul 21 07:47:59.982541 2026] [security2:error] [pid 302018:tid 302224] [client 152.59.154.239:52533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OX4As9lPxxVAErz37TwAAAM8"]
[Tue Jul 21 07:48:00.089887 2026] [security2:error] [pid 296703:tid 296914] [client 20.104.96.117:46669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/w1px.php"] [unique_id "al9OYCn25uliftkV1n4ffQAAAFE"]
[Tue Jul 21 07:48:00.605270 2026] [security2:error] [pid 302018:tid 302190] [client 20.151.10.161:19412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9OYIAs9lPxxVAErz37XAAAAK0"]
[Tue Jul 21 07:48:00.637532 2026] [security2:error] [pid 296703:tid 296768] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OYCn25uliftkV1n4fiwAAKEA"]
[Tue Jul 21 07:48:00.637731 2026] [security2:error] [pid 296703:tid 296873] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OYCn25uliftkV1n4fiwAAKEA"]
[Tue Jul 21 07:48:00.768952 2026] [security2:error] [pid 302018:tid 302219] [client 122.162.144.145:2319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OYIAs9lPxxVAErz37cgAAAMo"]
[Tue Jul 21 07:48:00.769048 2026] [security2:error] [pid 302018:tid 302219] [client 122.162.144.145:2319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OYIAs9lPxxVAErz37cgAAAMo"]
[Tue Jul 21 07:48:00.789949 2026] [security2:error] [pid 302018:tid 302275] [client 20.104.96.117:46687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/yawa.php"] [unique_id "al9OYIAs9lPxxVAErz37cwAAAQI"]
[Tue Jul 21 07:48:00.828442 2026] [security2:error] [pid 302018:tid 302093] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OYIAs9lPxxVAErz37dQAA10g"]
[Tue Jul 21 07:48:00.828557 2026] [security2:error] [pid 302018:tid 302232] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OYIAs9lPxxVAErz37dQAA10g"]
[Tue Jul 21 07:48:00.850146 2026] [security2:error] [pid 296703:tid 296883] [client 106.215.181.8:14197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OYCn25uliftkV1n4flwAAADI"]
[Tue Jul 21 07:48:00.850227 2026] [security2:error] [pid 296703:tid 296883] [client 106.215.181.8:14197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OYCn25uliftkV1n4flwAAADI"]
[Tue Jul 21 07:48:00.882042 2026] [security2:error] [pid 302018:tid 302191] [client 136.144.33.112:44215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OYIAs9lPxxVAErz37dwAAAK4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:00.960900 2026] [security2:error] [pid 302018:tid 302269] [client 20.151.10.161:19428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9OYIAs9lPxxVAErz37hQAAAPw"]
[Tue Jul 21 07:48:01.285641 2026] [security2:error] [pid 302018:tid 302266] [client 20.151.10.161:19427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/media.php"] [unique_id "al9OYYAs9lPxxVAErz37jgAAAPk"]
[Tue Jul 21 07:48:01.443575 2026] [security2:error] [pid 302018:tid 302151] [client 193.36.225.142:43125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OYYAs9lPxxVAErz37lAAAAIY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:48:01.447586 2026] [security2:error] [pid 302018:tid 302244] [client 117.217.38.194:65300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OYYAs9lPxxVAErz37lQAAAOM"]
[Tue Jul 21 07:48:01.447681 2026] [security2:error] [pid 302018:tid 302244] [client 117.217.38.194:65300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OYYAs9lPxxVAErz37lQAAAOM"]
[Tue Jul 21 07:48:01.451772 2026] [security2:error] [pid 302018:tid 302075] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OYYAs9lPxxVAErz37lgAAtzY"]
[Tue Jul 21 07:48:01.451875 2026] [security2:error] [pid 302018:tid 302200] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OYYAs9lPxxVAErz37lgAAtzY"]
[Tue Jul 21 07:48:01.493077 2026] [security2:error] [pid 302018:tid 302243] [client 20.104.96.117:46682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/js.php"] [unique_id "al9OYYAs9lPxxVAErz37lwAAAOI"]
[Tue Jul 21 07:48:01.594552 2026] [security2:error] [pid 302018:tid 302186] [client 20.151.10.161:19402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/images.php"] [unique_id "al9OYYAs9lPxxVAErz37pQAAAKk"]
[Tue Jul 21 07:48:01.980622 2026] [security2:error] [pid 302018:tid 302244] [client 20.151.10.161:19392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/adminner.php"] [unique_id "al9OYYAs9lPxxVAErz37sgAAAOM"]
[Tue Jul 21 07:48:02.009509 2026] [security2:error] [pid 302018:tid 302233] [client 103.166.103.129:24861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OYoAs9lPxxVAErz37swAAANg"]
[Tue Jul 21 07:48:02.009978 2026] [security2:error] [pid 302018:tid 302233] [client 103.166.103.129:24861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OYoAs9lPxxVAErz37swAAANg"]
[Tue Jul 21 07:48:02.307392 2026] [security2:error] [pid 302018:tid 302091] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OYoAs9lPxxVAErz37wwAAqUY"]
[Tue Jul 21 07:48:02.307498 2026] [security2:error] [pid 302018:tid 302186] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OYoAs9lPxxVAErz37wwAAqUY"]
[Tue Jul 21 07:48:02.334684 2026] [security2:error] [pid 302018:tid 302259] [client 20.151.10.161:19404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/admin.php"] [unique_id "al9OYoAs9lPxxVAErz37xAAAAPI"]
[Tue Jul 21 07:48:02.349681 2026] [security2:error] [pid 302018:tid 302171] [client 20.104.96.117:46675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/core.php"] [unique_id "al9OYoAs9lPxxVAErz37xQAAAJo"]
[Tue Jul 21 07:48:02.717601 2026] [security2:error] [pid 296703:tid 296918] [client 20.151.10.161:19441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/k.php"] [unique_id "al9OYin25uliftkV1n4fvQAAAFU"]
[Tue Jul 21 07:48:02.797832 2026] [security2:error] [pid 302018:tid 302097] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OYoAs9lPxxVAErz370QAA00w"]
[Tue Jul 21 07:48:02.798000 2026] [security2:error] [pid 302018:tid 302228] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OYoAs9lPxxVAErz370QAA00w"]
[Tue Jul 21 07:48:02.961878 2026] [qos:error] [pid 302018:tid 302147] [remote 69.63.189.36:54866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=69.63.189.36, id=al9OYoAs9lPxxVAErz373QAA2n4
[Tue Jul 21 07:48:02.987178 2026] [qos:error] [pid 296703:tid 296704] [remote 173.252.69.16:48060] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=173.252.69.16, id=al9OYin25uliftkV1n4fwgAAUAA
[Tue Jul 21 07:48:03.280125 2026] [security2:error] [pid 302018:tid 302261] [client 20.151.10.161:19450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/x.php"] [unique_id "al9OY4As9lPxxVAErz378QAAAPQ"]
[Tue Jul 21 07:48:03.301731 2026] [qos:error] [pid 302018:tid 302127] [remote 173.252.69.15:62416] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=173.252.69.15, id=al9OY4As9lPxxVAErz378gAAnGo
[Tue Jul 21 07:48:03.410581 2026] [security2:error] [pid 302018:tid 302243] [client 184.75.223.211:41424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OY4As9lPxxVAErz37-AAAAOI"]
[Tue Jul 21 07:48:03.410685 2026] [security2:error] [pid 302018:tid 302243] [client 184.75.223.211:41424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OY4As9lPxxVAErz37-AAAAOI"]
[Tue Jul 21 07:48:03.498844 2026] [security2:error] [pid 302018:tid 302228] [client 20.104.96.117:27392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/19.php"] [unique_id "al9OY4As9lPxxVAErz37-wAAANM"]
[Tue Jul 21 07:48:03.581745 2026] [security2:error] [pid 302018:tid 302192] [client 180.153.236.96:14351] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9OY4As9lPxxVAErz38AQAAAK8"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 07:48:03.581956 2026] [security2:error] [pid 302018:tid 302192] [client 180.153.236.96:14351] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9OY4As9lPxxVAErz38AQAAAK8"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 07:48:03.603033 2026] [security2:error] [pid 296703:tid 296926] [client 62.60.130.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "patriciarodriguesterapia.com.br.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/"] [unique_id "al9OYyn25uliftkV1n4f0AAAAF0"]
[Tue Jul 21 07:48:03.616860 2026] [qos:error] [pid 302018:tid 302070] [remote 57.141.18.103:42358] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.103, id=al9OY4As9lPxxVAErz38AwAA8zE
[Tue Jul 21 07:48:03.620768 2026] [security2:error] [pid 296703:tid 296845] [client 74.249.245.134:64078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/moon.php"] [unique_id "al9OYyn25uliftkV1n4f0QAAAAw"]
[Tue Jul 21 07:48:03.651446 2026] [security2:error] [pid 296703:tid 296822] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OYyn25uliftkV1n4f1QAAY3Y"]
[Tue Jul 21 07:48:03.651641 2026] [security2:error] [pid 296703:tid 296932] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OYyn25uliftkV1n4f1QAAY3Y"]
[Tue Jul 21 07:48:03.661195 2026] [qos:error] [pid 296703:tid 296733] [remote 57.141.18.18:54512] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.18, id=al9OYyn25uliftkV1n4f1wAAAB0
[Tue Jul 21 07:48:03.708923 2026] [security2:error] [pid 296703:tid 296876] [client 20.151.10.161:19354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wss.php"] [unique_id "al9OYyn25uliftkV1n4f3gAAACs"]
[Tue Jul 21 07:48:03.721859 2026] [security2:error] [pid 296703:tid 296936] [client 20.151.10.161:63452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/like.php"] [unique_id "al9OYyn25uliftkV1n4f3wAAAGc"]
[Tue Jul 21 07:48:03.737662 2026] [qos:error] [pid 302018:tid 302023] [remote 69.63.189.45:33846] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=69.63.189.45, id=al9OY4As9lPxxVAErz38DQAA9QI
[Tue Jul 21 07:48:03.765572 2026] [security2:error] [pid 302018:tid 302161] [client 122.164.127.47:56485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OY4As9lPxxVAErz38DgAAAJA"]
[Tue Jul 21 07:48:03.765700 2026] [security2:error] [pid 302018:tid 302161] [client 122.164.127.47:56485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OY4As9lPxxVAErz38DgAAAJA"]
[Tue Jul 21 07:48:03.846310 2026] [security2:error] [pid 296703:tid 296873] [client 62.60.130.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "patriciarodriguesterapia.com.br.danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9OYyn25uliftkV1n4f4QAAACg"]
[Tue Jul 21 07:48:03.930162 2026] [qos:error] [pid 296703:tid 296728] [remote 57.141.18.94:34948] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.94, id=al9OYyn25uliftkV1n4f5AAAHhg
[Tue Jul 21 07:48:03.963193 2026] [security2:error] [pid 302018:tid 302236] [client 20.151.10.161:43928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/green1.php"] [unique_id "al9OY4As9lPxxVAErz38EQAAANs"]
[Tue Jul 21 07:48:04.057371 2026] [autoindex:error] [pid 296703:tid 296837] [client 140.99.164.34:0] AH01276: Cannot serve directory /home2/eloisa13/tourcampos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:48:04.062349 2026] [security2:error] [pid 302018:tid 302275] [client 20.151.10.161:19408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/ty.php"] [unique_id "al9OZIAs9lPxxVAErz38EgAAAQI"]
[Tue Jul 21 07:48:04.070385 2026] [security2:error] [pid 302018:tid 302238] [client 223.236.153.128:5281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OZIAs9lPxxVAErz38EwAAAN0"]
[Tue Jul 21 07:48:04.070465 2026] [security2:error] [pid 302018:tid 302238] [client 223.236.153.128:5281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OZIAs9lPxxVAErz38EwAAAN0"]
[Tue Jul 21 07:48:04.181465 2026] [security2:error] [pid 296703:tid 296946] [client 37.140.223.119:35357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OZCn25uliftkV1n4f7AAAAHE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:48:04.349531 2026] [qos:error] [pid 296703:tid 296757] [remote 69.63.184.17:39706] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=69.63.184.17, id=al9OZCn25uliftkV1n4f9QAAEzU
[Tue Jul 21 07:48:04.399572 2026] [http2:info] [pid 296703:tid 296833] [client 185.219.83.53:42064] AH10180: h2_stream(296703-1003-1,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:48:04.406575 2026] [security2:error] [pid 296703:tid 296893] [client 202.143.127.214:64098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OZCn25uliftkV1n4f9wAAADw"]
[Tue Jul 21 07:48:04.407110 2026] [security2:error] [pid 296703:tid 296893] [client 202.143.127.214:64098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OZCn25uliftkV1n4f9wAAADw"]
[Tue Jul 21 07:48:04.425382 2026] [security2:error] [pid 296703:tid 296914] [client 20.151.10.161:19330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/155.php"] [unique_id "al9OZCn25uliftkV1n4f-gAAAFE"]
[Tue Jul 21 07:48:04.553096 2026] [qos:error] [pid 296703:tid 296753] [remote 57.141.18.52:41524] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.52, id=al9OZCn25uliftkV1n4f_QAAJTE
[Tue Jul 21 07:48:04.577572 2026] [qos:error] [pid 302018:tid 302075] [remote 173.252.82.3:47716] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=173.252.82.3, id=al9OZIAs9lPxxVAErz38GQAArTY
[Tue Jul 21 07:48:04.727705 2026] [security2:error] [pid 302018:tid 302266] [client 103.174.34.15:55382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OZIAs9lPxxVAErz38GgAAAPk"]
[Tue Jul 21 07:48:04.728112 2026] [security2:error] [pid 302018:tid 302266] [client 103.174.34.15:55382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OZIAs9lPxxVAErz38GgAAAPk"]
[Tue Jul 21 07:48:04.735434 2026] [qos:error] [pid 296703:tid 296765] [remote 69.63.184.2:65136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=69.63.184.2, id=al9OZCn25uliftkV1n4gAAAAcz0
[Tue Jul 21 07:48:04.763404 2026] [security2:error] [pid 302018:tid 302161] [client 20.151.10.161:19341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/ops.php"] [unique_id "al9OZIAs9lPxxVAErz38HQAAAJA"]
[Tue Jul 21 07:48:04.941100 2026] [security2:error] [pid 302018:tid 302181] [client 20.104.96.117:27073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/inc.php"] [unique_id "al9OZIAs9lPxxVAErz38HgAAAKQ"]
[Tue Jul 21 07:48:05.105715 2026] [security2:error] [pid 302018:tid 302238] [client 20.151.10.161:19454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/ingfo.php"] [unique_id "al9OZYAs9lPxxVAErz38IQAAAN0"]
[Tue Jul 21 07:48:05.377837 2026] [security2:error] [pid 302018:tid 302260] [client 117.247.80.59:20052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OZYAs9lPxxVAErz38JAAAAPM"]
[Tue Jul 21 07:48:05.377971 2026] [security2:error] [pid 302018:tid 302260] [client 117.247.80.59:20052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OZYAs9lPxxVAErz38JAAAAPM"]
[Tue Jul 21 07:48:05.389583 2026] [security2:error] [pid 296703:tid 296917] [client 122.186.204.214:56989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OZSn25uliftkV1n4gDQAAAFQ"]
[Tue Jul 21 07:48:05.389695 2026] [security2:error] [pid 296703:tid 296917] [client 122.186.204.214:56989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OZSn25uliftkV1n4gDQAAAFQ"]
[Tue Jul 21 07:48:05.610102 2026] [security2:error] [pid 302018:tid 302232] [client 20.104.96.117:46714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-ppoxua4.php"] [unique_id "al9OZYAs9lPxxVAErz38KAAAANc"]
[Tue Jul 21 07:48:05.640972 2026] [http2:info] [pid 296703:tid 296957] [client 185.219.83.53:42066] AH10180: h2_stream(296703-1010-1,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:48:05.657540 2026] [security2:error] [pid 296703:tid 296956] [client 136.144.33.54:49319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OZSn25uliftkV1n4gEQAAAHs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:05.754046 2026] [security2:error] [pid 302018:tid 302224] [client 20.151.10.161:19414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/error_log.php"] [unique_id "al9OZYAs9lPxxVAErz38KgAAAM8"]
[Tue Jul 21 07:48:05.852688 2026] [autoindex:error] [pid 302018:tid 302159] [client 209.38.125.40:0] AH01276: Cannot serve directory /home2/eloisa13/tourcampos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:48:05.881869 2026] [qos:error] [pid 296703:tid 296719] [remote 69.171.230.1:63266] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=69.171.230.1, id=al9OZSn25uliftkV1n4gGwAAEQ8
[Tue Jul 21 07:48:06.043429 2026] [security2:error] [pid 296703:tid 296929] [client 20.151.10.161:63437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/.well-known/about.php"] [unique_id "al9OZin25uliftkV1n4gIQAAAGA"]
[Tue Jul 21 07:48:06.049704 2026] [security2:error] [pid 296703:tid 296958] [client 20.151.10.161:19403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/ok.php"] [unique_id "al9OZin25uliftkV1n4gIgAAAH0"]
[Tue Jul 21 07:48:06.073060 2026] [qos:error] [pid 302018:tid 302096] [remote 173.252.107.26:64870] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=173.252.107.26, id=al9OZoAs9lPxxVAErz38MQAA1Es
[Tue Jul 21 07:48:06.221478 2026] [security2:error] [pid 302018:tid 302252] [client 117.251.86.144:57520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OZoAs9lPxxVAErz38NQAAAOs"]
[Tue Jul 21 07:48:06.221596 2026] [security2:error] [pid 302018:tid 302252] [client 117.251.86.144:57520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OZoAs9lPxxVAErz38NQAAAOs"]
[Tue Jul 21 07:48:06.244400 2026] [qos:error] [pid 296703:tid 296715] [remote 173.252.87.112:42558] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=173.252.87.112, id=al9OZin25uliftkV1n4gKAAAMgs
[Tue Jul 21 07:48:06.377275 2026] [security2:error] [pid 302018:tid 302244] [client 37.140.223.201:48487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OZoAs9lPxxVAErz38PQAAAOM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:48:06.432957 2026] [qos:error] [pid 296703:tid 296811] [remote 69.171.230.6:55532] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=69.171.230.6, id=al9OZin25uliftkV1n4gRwAAX2s
[Tue Jul 21 07:48:06.480566 2026] [security2:error] [pid 302018:tid 302211] [client 20.151.10.161:19401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/mac.php"] [unique_id "al9OZoAs9lPxxVAErz38kwAAAMI"]
[Tue Jul 21 07:48:06.535835 2026] [qos:error] [pid 296703:tid 296732] [remote 173.252.70.28:45866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=173.252.70.28, id=al9OZin25uliftkV1n4gSwAAMBw
[Tue Jul 21 07:48:06.662694 2026] [qos:error] [pid 296703:tid 296717] [remote 173.252.87.36:43778] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=173.252.87.36, id=al9OZin25uliftkV1n4gTgAABA0
[Tue Jul 21 07:48:06.708647 2026] [security2:error] [pid 296703:tid 296948] [client 154.192.233.199:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OZin25uliftkV1n4gTwAAAHM"]
[Tue Jul 21 07:48:06.708817 2026] [security2:error] [pid 296703:tid 296948] [client 154.192.233.199:60374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OZin25uliftkV1n4gTwAAAHM"]
[Tue Jul 21 07:48:06.827841 2026] [security2:error] [pid 296703:tid 296926] [client 20.151.10.161:19398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wefile.php"] [unique_id "al9OZin25uliftkV1n4gVQAAAF0"]
[Tue Jul 21 07:48:07.104568 2026] [security2:error] [pid 296703:tid 296797] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OZyn25uliftkV1n4gXQAAU10"]
[Tue Jul 21 07:48:07.104682 2026] [security2:error] [pid 296703:tid 296916] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OZyn25uliftkV1n4gXQAAU10"]
[Tue Jul 21 07:48:07.183968 2026] [security2:error] [pid 296703:tid 296960] [client 128.127.105.184:52678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9OZyn25uliftkV1n4gXgAAAH8"]
[Tue Jul 21 07:48:07.184077 2026] [security2:error] [pid 296703:tid 296960] [client 128.127.105.184:52678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9OZyn25uliftkV1n4gXgAAAH8"]
[Tue Jul 21 07:48:07.279332 2026] [qos:error] [pid 302018:tid 302052] [remote 57.141.18.7:46022] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.7, id=al9OZ4As9lPxxVAErz38mwAAkh8
[Tue Jul 21 07:48:07.292605 2026] [security2:error] [pid 302018:tid 302184] [client 74.249.245.134:65130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ws83.php"] [unique_id "al9OZ4As9lPxxVAErz38nQAAAKc"]
[Tue Jul 21 07:48:07.307958 2026] [security2:error] [pid 302018:tid 302220] [client 20.151.10.161:19432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9OZ4As9lPxxVAErz38ngAAAMs"]
[Tue Jul 21 07:48:07.350720 2026] [security2:error] [pid 302018:tid 302252] [client 20.104.96.117:27104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-u3nxbvx.php"] [unique_id "al9OZ4As9lPxxVAErz38nwAAAOs"]
[Tue Jul 21 07:48:07.358328 2026] [qos:error] [pid 302018:tid 302063] [remote 57.141.18.72:21578] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.72, id=al9OZ4As9lPxxVAErz38oAAAmio
[Tue Jul 21 07:48:07.381863 2026] [qos:error] [pid 296703:tid 296725] [remote 173.252.83.8:47556] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=173.252.83.8, id=al9OZyn25uliftkV1n4gYwAAKxU
[Tue Jul 21 07:48:07.591012 2026] [security2:error] [pid 302018:tid 302230] [client 184.75.223.211:41430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OZ4As9lPxxVAErz38ogAAANU"]
[Tue Jul 21 07:48:07.591128 2026] [security2:error] [pid 302018:tid 302230] [client 184.75.223.211:41430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OZ4As9lPxxVAErz38ogAAANU"]
[Tue Jul 21 07:48:07.609984 2026] [security2:error] [pid 296703:tid 296905] [client 20.151.10.161:64189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9OZyn25uliftkV1n4gZwAAAEg"]
[Tue Jul 21 07:48:07.710341 2026] [security2:error] [pid 296703:tid 296901] [client 41.68.90.219:55995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OZyn25uliftkV1n4gaQAAAEQ"]
[Tue Jul 21 07:48:07.711695 2026] [security2:error] [pid 296703:tid 296901] [client 41.68.90.219:55995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OZyn25uliftkV1n4gaQAAAEQ"]
[Tue Jul 21 07:48:07.902775 2026] [security2:error] [pid 296703:tid 296834] [client 59.96.220.140:57197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OZyn25uliftkV1n4gbwAAAAE"]
[Tue Jul 21 07:48:07.902976 2026] [security2:error] [pid 296703:tid 296834] [client 59.96.220.140:57197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OZyn25uliftkV1n4gbwAAAAE"]
[Tue Jul 21 07:48:07.993932 2026] [security2:error] [pid 302018:tid 302224] [client 20.151.10.161:19435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9OZ4As9lPxxVAErz38qAAAAM8"]
[Tue Jul 21 07:48:08.040863 2026] [security2:error] [pid 296703:tid 296875] [client 182.8.255.181:17478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OaCn25uliftkV1n4gcQAAACo"]
[Tue Jul 21 07:48:08.041022 2026] [security2:error] [pid 296703:tid 296875] [client 182.8.255.181:17478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OaCn25uliftkV1n4gcQAAACo"]
[Tue Jul 21 07:48:08.083581 2026] [security2:error] [pid 296703:tid 296785] [remote 68.178.160.25:42492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deals-ecomm.shop"] [uri "/wp-login.php"] [unique_id "al9OaCn25uliftkV1n4gdAAAYFE"]
[Tue Jul 21 07:48:08.306917 2026] [security2:error] [pid 302018:tid 302236] [client 139.167.225.182:53999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OaIAs9lPxxVAErz38qgAAANs"]
[Tue Jul 21 07:48:08.307073 2026] [security2:error] [pid 302018:tid 302236] [client 139.167.225.182:53999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OaIAs9lPxxVAErz38qgAAANs"]
[Tue Jul 21 07:48:08.467479 2026] [security2:error] [pid 302018:tid 302270] [client 173.24.185.52:54389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OaIAs9lPxxVAErz38qwAAAP0"]
[Tue Jul 21 07:48:08.467584 2026] [security2:error] [pid 302018:tid 302270] [client 173.24.185.52:54389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OaIAs9lPxxVAErz38qwAAAP0"]
[Tue Jul 21 07:48:08.468508 2026] [qos:error] [pid 296703:tid 296804] [remote 69.171.249.116:64588] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=69.171.249.116, id=al9OaCn25uliftkV1n4ghwAAYmQ
[Tue Jul 21 07:48:08.539397 2026] [security2:error] [pid 296703:tid 296868] [client 154.208.47.43:55948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OaCn25uliftkV1n4giAAAACM"]
[Tue Jul 21 07:48:08.539547 2026] [security2:error] [pid 296703:tid 296868] [client 154.208.47.43:55948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9OaCn25uliftkV1n4giAAAACM"]
[Tue Jul 21 07:48:08.630311 2026] [security2:error] [pid 302018:tid 302215] [client 20.151.10.161:19338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/like.php"] [unique_id "al9OaIAs9lPxxVAErz38rQAAAMY"]
[Tue Jul 21 07:48:08.686596 2026] [security2:error] [pid 296703:tid 296913] [client 103.29.114.44:61053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OaCn25uliftkV1n4gjwAAAFA"]
[Tue Jul 21 07:48:08.686698 2026] [security2:error] [pid 296703:tid 296913] [client 103.29.114.44:61053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OaCn25uliftkV1n4gjwAAAFA"]
[Tue Jul 21 07:48:08.932016 2026] [security2:error] [pid 302018:tid 302180] [client 20.151.10.161:19436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/.well-known/about.php"] [unique_id "al9OaIAs9lPxxVAErz38swAAAKM"]
[Tue Jul 21 07:48:09.026258 2026] [security2:error] [pid 296703:tid 296957] [client 122.179.91.63:14928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OaSn25uliftkV1n4gkwAAAHw"]
[Tue Jul 21 07:48:09.026365 2026] [security2:error] [pid 296703:tid 296957] [client 122.179.91.63:14928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OaSn25uliftkV1n4gkwAAAHw"]
[Tue Jul 21 07:48:09.081330 2026] [security2:error] [pid 296703:tid 296955] [client 103.86.117.203:54942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OaSn25uliftkV1n4glwAAAHo"]
[Tue Jul 21 07:48:09.081489 2026] [security2:error] [pid 296703:tid 296955] [client 103.86.117.203:54942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OaSn25uliftkV1n4glwAAAHo"]
[Tue Jul 21 07:48:09.291669 2026] [security2:error] [pid 302018:tid 302222] [client 20.151.10.161:19426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9OaYAs9lPxxVAErz38vwAAAM0"]
[Tue Jul 21 07:48:09.352375 2026] [qos:error] [pid 296703:tid 296733] [remote 57.141.18.32:65382] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.32, id=al9OaSn25uliftkV1n4gngAAWh0
[Tue Jul 21 07:48:09.378474 2026] [qos:error] [pid 302018:tid 311327] [remote 57.141.18.25:58534] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.25, id=al9OaYAs9lPxxVAErz38xAAAz4E
[Tue Jul 21 07:48:09.387151 2026] [security2:error] [pid 296703:tid 296878] [client 20.104.96.117:27113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/ss.php"] [unique_id "al9OaSn25uliftkV1n4gnwAAAC0"]
[Tue Jul 21 07:48:09.462148 2026] [security2:error] [pid 296703:tid 296901] [client 128.127.105.184:58762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OaSn25uliftkV1n4gsAAAAEQ"]
[Tue Jul 21 07:48:09.462256 2026] [security2:error] [pid 296703:tid 296901] [client 128.127.105.184:58762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OaSn25uliftkV1n4gsAAAAEQ"]
[Tue Jul 21 07:48:09.598127 2026] [security2:error] [pid 302018:tid 302227] [client 178.153.91.96:61976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OaYAs9lPxxVAErz38xgAAANI"]
[Tue Jul 21 07:48:09.598252 2026] [security2:error] [pid 302018:tid 302227] [client 178.153.91.96:61976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OaYAs9lPxxVAErz38xgAAANI"]
[Tue Jul 21 07:48:09.628795 2026] [security2:error] [pid 302018:tid 311331] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OaYAs9lPxxVAErz38xwAA1IU"]
[Tue Jul 21 07:48:09.629042 2026] [security2:error] [pid 302018:tid 302229] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OaYAs9lPxxVAErz38xwAA1IU"]
[Tue Jul 21 07:48:09.703574 2026] [security2:error] [pid 302018:tid 302190] [client 136.144.33.108:35489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OaYAs9lPxxVAErz38yQAAAK0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:09.747424 2026] [security2:error] [pid 296703:tid 296866] [client 20.226.60.151:61521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/zildan.php"] [unique_id "al9OaSn25uliftkV1n4guAAAACE"]
[Tue Jul 21 07:48:09.890701 2026] [security2:error] [pid 296703:tid 296835] [client 194.99.104.35:59284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9OaSn25uliftkV1n4gxwAAAAI"]
[Tue Jul 21 07:48:09.890786 2026] [security2:error] [pid 296703:tid 296835] [client 194.99.104.35:59284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9OaSn25uliftkV1n4gxwAAAAI"]
[Tue Jul 21 07:48:09.892420 2026] [security2:error] [pid 296703:tid 296957] [client 20.151.10.161:19350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/pucci.php"] [unique_id "al9OaSn25uliftkV1n4gyAAAAHw"]
[Tue Jul 21 07:48:10.032985 2026] [security2:error] [pid 302018:tid 302166] [client 128.127.105.184:58758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9OaoAs9lPxxVAErz380AAAAJU"]
[Tue Jul 21 07:48:10.033077 2026] [security2:error] [pid 302018:tid 302166] [client 128.127.105.184:58758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9OaoAs9lPxxVAErz380AAAAJU"]
[Tue Jul 21 07:48:10.249862 2026] [security2:error] [pid 302018:tid 302160] [client 62.102.148.187:60112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OaoAs9lPxxVAErz380QAAAI8"]
[Tue Jul 21 07:48:10.249966 2026] [security2:error] [pid 302018:tid 302160] [client 62.102.148.187:60112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OaoAs9lPxxVAErz380QAAAI8"]
[Tue Jul 21 07:48:10.748385 2026] [security2:error] [pid 296703:tid 296833] [client 152.59.154.239:53013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oain25uliftkV1n4g3QAAAAA"]
[Tue Jul 21 07:48:10.748521 2026] [security2:error] [pid 296703:tid 296833] [client 152.59.154.239:53013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oain25uliftkV1n4g3QAAAAA"]
[Tue Jul 21 07:48:10.761760 2026] [security2:error] [pid 302018:tid 302184] [client 20.151.10.161:19377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wp-temp.php"] [unique_id "al9OaoAs9lPxxVAErz383gAAAKc"]
[Tue Jul 21 07:48:10.886431 2026] [security2:error] [pid 302018:tid 302262] [client 65.111.24.135:15973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9OaoAs9lPxxVAErz384QAAAPU"]
[Tue Jul 21 07:48:11.006341 2026] [security2:error] [pid 296703:tid 296913] [client 20.151.10.161:43970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/biufile.php"] [unique_id "al9Oayn25uliftkV1n4g6AAAAFA"]
[Tue Jul 21 07:48:11.101566 2026] [security2:error] [pid 302018:tid 302135] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oa4As9lPxxVAErz386AAA1HI"]
[Tue Jul 21 07:48:11.101729 2026] [security2:error] [pid 302018:tid 302229] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oa4As9lPxxVAErz386AAA1HI"]
[Tue Jul 21 07:48:11.236862 2026] [security2:error] [pid 296703:tid 296930] [client 74.249.245.134:64085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/CDX1.php"] [unique_id "al9Oayn25uliftkV1n4g6QAAAGE"]
[Tue Jul 21 07:48:11.471734 2026] [security2:error] [pid 302018:tid 302263] [client 106.215.181.8:18296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oa4As9lPxxVAErz386wAAAPY"]
[Tue Jul 21 07:48:11.471847 2026] [security2:error] [pid 302018:tid 302263] [client 106.215.181.8:18296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oa4As9lPxxVAErz386wAAAPY"]
[Tue Jul 21 07:48:11.476603 2026] [qos:error] [pid 296703:tid 296722] [remote 57.141.18.116:45450] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.116, id=al9Oayn25uliftkV1n4g9AAAUxI
[Tue Jul 21 07:48:11.560966 2026] [security2:error] [pid 302018:tid 302227] [client 122.162.144.145:30463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Oa4As9lPxxVAErz387gAAANI"]
[Tue Jul 21 07:48:11.561108 2026] [security2:error] [pid 302018:tid 302227] [client 122.162.144.145:30463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Oa4As9lPxxVAErz387gAAANI"]
[Tue Jul 21 07:48:11.574646 2026] [qos:error] [pid 296703:tid 296738] [remote 57.141.18.25:52328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.25, id=al9Oayn25uliftkV1n4g9gAAVSI
[Tue Jul 21 07:48:11.769671 2026] [security2:error] [pid 302018:tid 302240] [client 20.104.96.117:46699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/min.php"] [unique_id "al9Oa4As9lPxxVAErz388QAAAN8"]
[Tue Jul 21 07:48:11.804390 2026] [security2:error] [pid 296703:tid 296878] [client 45.146.54.52:20539] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "uaudistribuidora.com.br"] [uri "/.env"] [unique_id "al9Oayn25uliftkV1n4g-gAAAC0"]
[Tue Jul 21 07:48:11.824759 2026] [security2:error] [pid 302018:tid 302224] [client 20.151.10.161:19337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/xmu.php"] [unique_id "al9Oa4As9lPxxVAErz388gAAAM8"]
[Tue Jul 21 07:48:11.918193 2026] [security2:error] [pid 296703:tid 296956] [client 117.217.38.194:49407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oayn25uliftkV1n4g_AAAAHs"]
[Tue Jul 21 07:48:11.918542 2026] [security2:error] [pid 296703:tid 296956] [client 117.217.38.194:49407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oayn25uliftkV1n4g_AAAAHs"]
[Tue Jul 21 07:48:11.989825 2026] [security2:error] [pid 302018:tid 302046] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Oa4As9lPxxVAErz38-AAArRk"]
[Tue Jul 21 07:48:11.989993 2026] [security2:error] [pid 302018:tid 302190] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Oa4As9lPxxVAErz38-AAArRk"]
[Tue Jul 21 07:48:12.200764 2026] [security2:error] [pid 296703:tid 296725] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9ObCn25uliftkV1n4hAQAAFxU"]
[Tue Jul 21 07:48:12.200880 2026] [security2:error] [pid 296703:tid 296856] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9ObCn25uliftkV1n4hAQAAFxU"]
[Tue Jul 21 07:48:12.316033 2026] [security2:error] [pid 302018:tid 302194] [client 74.249.245.134:65112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/inputs.php"] [unique_id "al9ObIAs9lPxxVAErz39AAAAALE"]
[Tue Jul 21 07:48:12.758227 2026] [security2:error] [pid 302018:tid 302275] [client 103.166.103.129:25395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ObIAs9lPxxVAErz39BQAAAQI"]
[Tue Jul 21 07:48:12.758690 2026] [security2:error] [pid 302018:tid 302275] [client 103.166.103.129:25395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ObIAs9lPxxVAErz39BQAAAQI"]
[Tue Jul 21 07:48:12.798962 2026] [security2:error] [pid 302018:tid 302198] [client 20.151.10.161:63413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/pucci.php"] [unique_id "al9ObIAs9lPxxVAErz39BwAAALU"]
[Tue Jul 21 07:48:12.881791 2026] [security2:error] [pid 302018:tid 302271] [client 20.151.10.161:19349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9ObIAs9lPxxVAErz39CAAAAP4"]
[Tue Jul 21 07:48:13.110259 2026] [security2:error] [pid 296703:tid 296763] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9ObSn25uliftkV1n4hEQAAMjs"]
[Tue Jul 21 07:48:13.110431 2026] [security2:error] [pid 296703:tid 296883] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9ObSn25uliftkV1n4hEQAAMjs"]
[Tue Jul 21 07:48:13.157444 2026] [security2:error] [pid 302018:tid 302186] [client 74.249.245.134:64392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ms-edit.php"] [unique_id "al9ObYAs9lPxxVAErz39CwAAAKk"]
[Tue Jul 21 07:48:13.316089 2026] [security2:error] [pid 302018:tid 302274] [client 20.104.96.117:27101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9ObYAs9lPxxVAErz39DwAAAQE"]
[Tue Jul 21 07:48:13.598290 2026] [security2:error] [pid 296703:tid 296843] [client 122.164.127.47:57067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9ObSn25uliftkV1n4hHAAAAAo"]
[Tue Jul 21 07:48:13.598440 2026] [security2:error] [pid 296703:tid 296843] [client 122.164.127.47:57067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9ObSn25uliftkV1n4hHAAAAAo"]
[Tue Jul 21 07:48:13.648317 2026] [security2:error] [pid 302018:tid 302230] [client 20.151.10.161:44009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wpconf.php"] [unique_id "al9ObYAs9lPxxVAErz39HQAAANU"]
[Tue Jul 21 07:48:13.677164 2026] [security2:error] [pid 302018:tid 302177] [client 136.144.33.108:46997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9ObYAs9lPxxVAErz39HgAAAKA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:13.845421 2026] [security2:error] [pid 296703:tid 296845] [client 20.151.10.161:19413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/puc.php"] [unique_id "al9ObSn25uliftkV1n4hIQAAAAw"]
[Tue Jul 21 07:48:13.852683 2026] [qos:error] [pid 296703:tid 296781] [remote 57.141.18.88:22808] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.88, id=al9ObSn25uliftkV1n4hIgAAck0
[Tue Jul 21 07:48:13.894476 2026] [security2:error] [pid 296703:tid 296804] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ObSn25uliftkV1n4hJAAAYGQ"]
[Tue Jul 21 07:48:13.894629 2026] [security2:error] [pid 296703:tid 296929] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ObSn25uliftkV1n4hJAAAYGQ"]
[Tue Jul 21 07:48:14.480065 2026] [security2:error] [pid 302018:tid 302111] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OboAs9lPxxVAErz39IwABAlo"]
[Tue Jul 21 07:48:14.480241 2026] [security2:error] [pid 302018:tid 302275] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OboAs9lPxxVAErz39IwABAlo"]
[Tue Jul 21 07:48:14.654543 2026] [security2:error] [pid 302018:tid 302153] [client 20.104.96.117:46640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/autoload_classmap.php"] [unique_id "al9OboAs9lPxxVAErz39JQAAAIg"]
[Tue Jul 21 07:48:14.753251 2026] [security2:error] [pid 296703:tid 296956] [client 223.236.153.128:5450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Obin25uliftkV1n4hNgAAAHs"]
[Tue Jul 21 07:48:14.753407 2026] [security2:error] [pid 296703:tid 296956] [client 223.236.153.128:5450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Obin25uliftkV1n4hNgAAAHs"]
[Tue Jul 21 07:48:15.093128 2026] [security2:error] [pid 296703:tid 296813] [remote 132.148.72.88:35520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Obyn25uliftkV1n4hPQAAPG0"]
[Tue Jul 21 07:48:15.104953 2026] [security2:error] [pid 296703:tid 296859] [client 20.151.10.161:19434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/themes.php"] [unique_id "al9Obyn25uliftkV1n4hPwAAABo"]
[Tue Jul 21 07:48:15.483542 2026] [security2:error] [pid 302018:tid 302227] [client 103.174.34.15:55893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.34.174.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ob4As9lPxxVAErz39OgAAANI"]
[Tue Jul 21 07:48:15.483686 2026] [security2:error] [pid 302018:tid 302227] [client 103.174.34.15:55893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ob4As9lPxxVAErz39OgAAANI"]
[Tue Jul 21 07:48:15.488044 2026] [security2:error] [pid 302018:tid 302266] [client 20.151.10.161:43840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/mosty.php"] [unique_id "al9Ob4As9lPxxVAErz39OwAAAPk"]
[Tue Jul 21 07:48:15.536396 2026] [security2:error] [pid 296703:tid 296847] [client 202.143.127.214:64549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Obyn25uliftkV1n4hSQAAAA4"]
[Tue Jul 21 07:48:15.536988 2026] [security2:error] [pid 296703:tid 296847] [client 202.143.127.214:64549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Obyn25uliftkV1n4hSQAAAA4"]
[Tue Jul 21 07:48:15.562382 2026] [security2:error] [pid 302018:tid 302166] [client 74.249.245.134:24774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/simple.php"] [unique_id "al9Ob4As9lPxxVAErz39PAAAAJU"]
[Tue Jul 21 07:48:15.568491 2026] [security2:error] [pid 296703:tid 296834] [client 191.101.114.168:48270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9Oain25uliftkV1n4gygAAAAE"], referer: https://drjoaoguedes.com/wp-login.php
[Tue Jul 21 07:48:15.823847 2026] [security2:error] [pid 302018:tid 302168] [client 20.151.10.161:64186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wp-temp.php"] [unique_id "al9Ob4As9lPxxVAErz39QAAAAJc"]
[Tue Jul 21 07:48:16.064856 2026] [security2:error] [pid 302018:tid 302230] [client 122.186.204.214:57533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OcIAs9lPxxVAErz39RQAAANU"]
[Tue Jul 21 07:48:16.065046 2026] [security2:error] [pid 302018:tid 302230] [client 122.186.204.214:57533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OcIAs9lPxxVAErz39RQAAANU"]
[Tue Jul 21 07:48:16.107064 2026] [security2:error] [pid 296703:tid 296878] [client 117.247.80.59:30576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OcCn25uliftkV1n4hUwAAAC0"]
[Tue Jul 21 07:48:16.107627 2026] [security2:error] [pid 296703:tid 296878] [client 117.247.80.59:30576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OcCn25uliftkV1n4hUwAAAC0"]
[Tue Jul 21 07:48:16.230029 2026] [security2:error] [pid 302018:tid 302243] [client 154.192.233.199:60367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OcIAs9lPxxVAErz39SQAAAOI"]
[Tue Jul 21 07:48:16.230139 2026] [security2:error] [pid 302018:tid 302243] [client 154.192.233.199:60367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OcIAs9lPxxVAErz39SQAAAOI"]
[Tue Jul 21 07:48:16.352987 2026] [security2:error] [pid 302018:tid 302192] [client 20.151.10.161:43938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/dejavu.php"] [unique_id "al9OcIAs9lPxxVAErz39SgAAAK8"]
[Tue Jul 21 07:48:16.518318 2026] [security2:error] [pid 302018:tid 302191] [client 20.104.96.117:27133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-link-zorm.php"] [unique_id "al9OcIAs9lPxxVAErz39TAAAAK4"]
[Tue Jul 21 07:48:16.983491 2026] [security2:error] [pid 302018:tid 302234] [client 20.151.10.161:19393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/8.php"] [unique_id "al9OcIAs9lPxxVAErz39TwAAANk"]
[Tue Jul 21 07:48:17.027194 2026] [security2:error] [pid 302018:tid 302235] [client 117.251.86.144:37956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OcYAs9lPxxVAErz39UwAAANo"]
[Tue Jul 21 07:48:17.027331 2026] [security2:error] [pid 302018:tid 302235] [client 117.251.86.144:37956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OcYAs9lPxxVAErz39UwAAANo"]
[Tue Jul 21 07:48:17.085117 2026] [security2:error] [pid 302018:tid 302263] [client 74.249.245.134:24769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/404.php"] [unique_id "al9OcYAs9lPxxVAErz39VAAAAPY"]
[Tue Jul 21 07:48:17.336913 2026] [security2:error] [pid 302018:tid 302172] [client 20.151.10.161:19328] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "clickedbought.com"] [uri "/1.php"] [unique_id "al9OcYAs9lPxxVAErz39WgAAAJs"]
[Tue Jul 21 07:48:17.337505 2026] [security2:error] [pid 302018:tid 302172] [client 20.151.10.161:19328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/1.php"] [unique_id "al9OcYAs9lPxxVAErz39WgAAAJs"]
[Tue Jul 21 07:48:17.623767 2026] [security2:error] [pid 302018:tid 302058] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OcYAs9lPxxVAErz39WwAA1CU"]
[Tue Jul 21 07:48:17.623983 2026] [security2:error] [pid 302018:tid 302229] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OcYAs9lPxxVAErz39WwAA1CU"]
[Tue Jul 21 07:48:17.689357 2026] [security2:error] [pid 296703:tid 296926] [client 193.36.225.70:30441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OcSn25uliftkV1n4haQAAAF0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:17.708581 2026] [security2:error] [pid 302018:tid 302240] [client 20.151.10.161:19438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/100.php"] [unique_id "al9OcYAs9lPxxVAErz39XwAAAN8"]
[Tue Jul 21 07:48:18.005990 2026] [security2:error] [pid 302018:tid 302269] [client 59.96.220.140:57734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OcoAs9lPxxVAErz39ZwAAAPw"]
[Tue Jul 21 07:48:18.006135 2026] [security2:error] [pid 302018:tid 302269] [client 59.96.220.140:57734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OcoAs9lPxxVAErz39ZwAAAPw"]
[Tue Jul 21 07:48:18.367909 2026] [security2:error] [pid 302018:tid 302253] [client 128.127.105.184:39344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9OcoAs9lPxxVAErz39bQAAAOw"]
[Tue Jul 21 07:48:18.367993 2026] [security2:error] [pid 302018:tid 302253] [client 128.127.105.184:39344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9OcoAs9lPxxVAErz39bQAAAOw"]
[Tue Jul 21 07:48:18.416901 2026] [security2:error] [pid 302018:tid 302179] [client 182.8.255.181:17565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OcoAs9lPxxVAErz39bgAAAKI"]
[Tue Jul 21 07:48:18.417050 2026] [security2:error] [pid 302018:tid 302179] [client 182.8.255.181:17565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OcoAs9lPxxVAErz39bgAAAKI"]
[Tue Jul 21 07:48:18.433219 2026] [security2:error] [pid 302018:tid 302259] [client 41.68.90.219:56416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OcoAs9lPxxVAErz39bwAAAPI"]
[Tue Jul 21 07:48:18.434226 2026] [security2:error] [pid 302018:tid 302259] [client 41.68.90.219:56416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OcoAs9lPxxVAErz39bwAAAPI"]
[Tue Jul 21 07:48:18.441429 2026] [security2:error] [pid 302018:tid 302162] [client 20.151.10.161:63387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/xmu.php"] [unique_id "al9OcoAs9lPxxVAErz39cAAAAJE"]
[Tue Jul 21 07:48:18.444381 2026] [security2:error] [pid 302018:tid 302275] [client 20.151.10.161:19446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/about.php"] [unique_id "al9OcoAs9lPxxVAErz39cQAAAQI"]
[Tue Jul 21 07:48:18.444567 2026] [security2:error] [pid 302018:tid 302166] [client 74.249.245.134:64400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/file3.php"] [unique_id "al9OcoAs9lPxxVAErz39cgAAAJU"]
[Tue Jul 21 07:48:18.565682 2026] [security2:error] [pid 302018:tid 302260] [client 20.104.96.117:46628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-link-szoppm.php"] [unique_id "al9OcoAs9lPxxVAErz39dgAAAPM"]
[Tue Jul 21 07:48:18.662186 2026] [security2:error] [pid 302018:tid 302252] [client 20.151.10.161:43922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/aaf.php"] [unique_id "al9OcoAs9lPxxVAErz39dwAAAOs"]
[Tue Jul 21 07:48:18.836875 2026] [security2:error] [pid 302018:tid 302227] [client 113.160.132.26:13881] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 26.132.160.113.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9OcYAs9lPxxVAErz39XgAAANI"]
[Tue Jul 21 07:48:18.837011 2026] [security2:error] [pid 302018:tid 302227] [client 113.160.132.26:13881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "efrelectronics.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9OcYAs9lPxxVAErz39XgAAANI"]
[Tue Jul 21 07:48:18.845376 2026] [security2:error] [pid 302018:tid 302161] [client 139.167.225.182:54668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OcoAs9lPxxVAErz39eQAAAJA"]
[Tue Jul 21 07:48:18.845481 2026] [security2:error] [pid 302018:tid 302161] [client 139.167.225.182:54668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OcoAs9lPxxVAErz39eQAAAJA"]
[Tue Jul 21 07:48:19.095857 2026] [security2:error] [pid 302018:tid 302209] [client 173.24.185.52:54857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Oc4As9lPxxVAErz39fgAAAMA"]
[Tue Jul 21 07:48:19.095961 2026] [security2:error] [pid 302018:tid 302209] [client 173.24.185.52:54857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Oc4As9lPxxVAErz39fgAAAMA"]
[Tue Jul 21 07:48:19.157527 2026] [security2:error] [pid 302018:tid 302194] [client 154.208.47.43:56404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Oc4As9lPxxVAErz39gAAAALE"]
[Tue Jul 21 07:48:19.157620 2026] [security2:error] [pid 302018:tid 302194] [client 154.208.47.43:56404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Oc4As9lPxxVAErz39gAAAALE"]
[Tue Jul 21 07:48:19.205174 2026] [security2:error] [pid 296703:tid 296951] [client 20.151.10.161:19335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/about.php"] [unique_id "al9Ocyn25uliftkV1n4hhQAAAHY"]
[Tue Jul 21 07:48:19.466138 2026] [security2:error] [pid 296703:tid 296850] [client 103.29.114.44:41168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ocyn25uliftkV1n4hiAAAABE"]
[Tue Jul 21 07:48:19.466278 2026] [security2:error] [pid 296703:tid 296850] [client 103.29.114.44:41168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ocyn25uliftkV1n4hiAAAABE"]
[Tue Jul 21 07:48:19.543661 2026] [security2:error] [pid 302018:tid 302258] [client 103.86.117.203:55489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Oc4As9lPxxVAErz39ggAAAPE"]
[Tue Jul 21 07:48:19.543764 2026] [security2:error] [pid 302018:tid 302258] [client 103.86.117.203:55489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Oc4As9lPxxVAErz39ggAAAPE"]
[Tue Jul 21 07:48:19.682811 2026] [security2:error] [pid 302018:tid 302224] [client 122.179.91.63:27006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Oc4As9lPxxVAErz39hQAAAM8"]
[Tue Jul 21 07:48:19.683026 2026] [security2:error] [pid 302018:tid 302224] [client 122.179.91.63:27006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Oc4As9lPxxVAErz39hQAAAM8"]
[Tue Jul 21 07:48:19.923616 2026] [security2:error] [pid 302018:tid 302263] [client 20.151.10.161:43851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/term.php"] [unique_id "al9Oc4As9lPxxVAErz39iAAAAPY"]
[Tue Jul 21 07:48:20.097331 2026] [security2:error] [pid 302018:tid 302218] [client 20.104.96.117:27115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/albin.php"] [unique_id "al9OdIAs9lPxxVAErz39iQAAAMk"]
[Tue Jul 21 07:48:20.155252 2026] [security2:error] [pid 296703:tid 296946] [client 178.153.91.96:62582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OdCn25uliftkV1n4hmQAAAHE"]
[Tue Jul 21 07:48:20.155381 2026] [security2:error] [pid 296703:tid 296946] [client 178.153.91.96:62582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OdCn25uliftkV1n4hmQAAAHE"]
[Tue Jul 21 07:48:20.311499 2026] [security2:error] [pid 302018:tid 302244] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9OdIAs9lPxxVAErz39igAA41A"]
[Tue Jul 21 07:48:20.331570 2026] [security2:error] [pid 296703:tid 296806] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OdCn25uliftkV1n4hogAAYGY"]
[Tue Jul 21 07:48:20.331675 2026] [security2:error] [pid 296703:tid 296929] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OdCn25uliftkV1n4hogAAYGY"]
[Tue Jul 21 07:48:20.336400 2026] [security2:error] [pid 296703:tid 296934] [client 20.151.10.161:19400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/admin.php"] [unique_id "al9OdCn25uliftkV1n4hpAAAAGU"]
[Tue Jul 21 07:48:20.783148 2026] [security2:error] [pid 302018:tid 302168] [client 20.151.10.161:43972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/ha.php"] [unique_id "al9OdIAs9lPxxVAErz39kwAAAJc"]
[Tue Jul 21 07:48:20.849549 2026] [security2:error] [pid 302018:tid 302255] [client 74.249.245.134:24818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-mail.php"] [unique_id "al9OdIAs9lPxxVAErz39lQAAAO4"]
[Tue Jul 21 07:48:20.900729 2026] [security2:error] [pid 302018:tid 302209] [client 20.151.10.161:63447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9OdIAs9lPxxVAErz39lwAAAMA"]
[Tue Jul 21 07:48:21.021560 2026] [autoindex:error] [pid 302018:tid 302236] [client 185.243.76.40:0] AH01276: Cannot serve directory /home2/eloisa13/tourcampos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:48:21.105804 2026] [security2:error] [pid 296703:tid 296749] [remote 72.167.132.114:39420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9OdSn25uliftkV1n4hrgAAEC0"]
[Tue Jul 21 07:48:21.357566 2026] [security2:error] [pid 296703:tid 296840] [client 193.36.225.68:24065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OdSn25uliftkV1n4h0QAAAAc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:21.369265 2026] [security2:error] [pid 302018:tid 302179] [client 20.151.10.161:19425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/admin.php"] [unique_id "al9OdYAs9lPxxVAErz39swAAAKI"]
[Tue Jul 21 07:48:21.407776 2026] [security2:error] [pid 302018:tid 302191] [client 20.151.10.161:63444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/puc.php"] [unique_id "al9OdYAs9lPxxVAErz39tAAAAK4"]
[Tue Jul 21 07:48:21.495392 2026] [security2:error] [pid 296703:tid 296960] [client 65.111.6.254:38949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.6.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9OdSn25uliftkV1n4h0gAAAH8"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:48:21.499110 2026] [security2:error] [pid 302018:tid 302235] [client 20.104.96.117:27088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/cilus.php"] [unique_id "al9OdYAs9lPxxVAErz39tQAAANo"]
[Tue Jul 21 07:48:21.631142 2026] [security2:error] [pid 296703:tid 296931] [client 152.59.154.239:13051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OdSn25uliftkV1n4h1AAAAGI"]
[Tue Jul 21 07:48:21.631348 2026] [security2:error] [pid 296703:tid 296931] [client 152.59.154.239:13051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OdSn25uliftkV1n4h1AAAAGI"]
[Tue Jul 21 07:48:21.637615 2026] [security2:error] [pid 302018:tid 311335] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OdYAs9lPxxVAErz39twAA9Yk"]
[Tue Jul 21 07:48:21.637755 2026] [security2:error] [pid 302018:tid 302262] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OdYAs9lPxxVAErz39twAA9Yk"]
[Tue Jul 21 07:48:22.185140 2026] [security2:error] [pid 296703:tid 296844] [client 106.215.181.8:30185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Odin25uliftkV1n4h2gAAAAs"]
[Tue Jul 21 07:48:22.185284 2026] [security2:error] [pid 296703:tid 296844] [client 106.215.181.8:30185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Odin25uliftkV1n4h2gAAAAs"]
[Tue Jul 21 07:48:22.233404 2026] [security2:error] [pid 302018:tid 302161] [client 20.151.10.161:19449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/edit.php"] [unique_id "al9OdoAs9lPxxVAErz39wAAAAJA"]
[Tue Jul 21 07:48:22.289548 2026] [security2:error] [pid 302018:tid 302187] [client 122.162.144.145:32746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OdoAs9lPxxVAErz39wwAAAKo"]
[Tue Jul 21 07:48:22.289668 2026] [security2:error] [pid 302018:tid 302187] [client 122.162.144.145:32746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OdoAs9lPxxVAErz39wwAAAKo"]
[Tue Jul 21 07:48:22.459467 2026] [security2:error] [pid 296703:tid 296858] [client 20.151.10.161:63406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/themes.php"] [unique_id "al9Odin25uliftkV1n4h4QAAABk"]
[Tue Jul 21 07:48:22.473498 2026] [security2:error] [pid 302018:tid 302184] [client 117.217.38.194:50010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OdoAs9lPxxVAErz39xgAAAKc"]
[Tue Jul 21 07:48:22.473639 2026] [security2:error] [pid 302018:tid 302184] [client 117.217.38.194:50010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OdoAs9lPxxVAErz39xgAAAKc"]
[Tue Jul 21 07:48:22.513735 2026] [security2:error] [pid 302018:tid 302138] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OdoAs9lPxxVAErz39xwAA4nU"]
[Tue Jul 21 07:48:22.513969 2026] [security2:error] [pid 302018:tid 302243] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OdoAs9lPxxVAErz39xwAA4nU"]
[Tue Jul 21 07:48:22.798585 2026] [security2:error] [pid 296703:tid 296757] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Odin25uliftkV1n4h5gAAADU"]
[Tue Jul 21 07:48:22.798719 2026] [security2:error] [pid 296703:tid 296833] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Odin25uliftkV1n4h5gAAADU"]
[Tue Jul 21 07:48:22.924277 2026] [security2:error] [pid 302018:tid 302258] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9OdoAs9lPxxVAErz391wAAAPE"]
[Tue Jul 21 07:48:22.935412 2026] [security2:error] [pid 302018:tid 302181] [client 20.104.96.117:46657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/gptsh.php"] [unique_id "al9OdoAs9lPxxVAErz392AAAAKQ"]
[Tue Jul 21 07:48:22.972560 2026] [security2:error] [pid 302018:tid 302192] [client 20.151.10.161:43965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/hur.php"] [unique_id "al9OdoAs9lPxxVAErz392QAAAK8"]
[Tue Jul 21 07:48:23.106443 2026] [security2:error] [pid 302018:tid 302255] [client 20.151.10.161:19365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wp-content/admin.php"] [unique_id "al9Od4As9lPxxVAErz392gAAAO4"]
[Tue Jul 21 07:48:23.310044 2026] [security2:error] [pid 302018:tid 302163] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Od4As9lPxxVAErz393QAAAJI"]
[Tue Jul 21 07:48:23.458266 2026] [security2:error] [pid 302018:tid 302224] [client 103.166.103.129:25959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Od4As9lPxxVAErz394AAAAM8"]
[Tue Jul 21 07:48:23.458431 2026] [security2:error] [pid 302018:tid 302224] [client 103.166.103.129:25959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Od4As9lPxxVAErz394AAAAM8"]
[Tue Jul 21 07:48:23.558261 2026] [security2:error] [pid 302018:tid 302182] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Od4As9lPxxVAErz394QAAAKU"]
[Tue Jul 21 07:48:23.759370 2026] [security2:error] [pid 302018:tid 302109] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Od4As9lPxxVAErz395QAAsVg"]
[Tue Jul 21 07:48:23.759561 2026] [security2:error] [pid 302018:tid 302194] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Od4As9lPxxVAErz395QAAsVg"]
[Tue Jul 21 07:48:23.804385 2026] [security2:error] [pid 302018:tid 302267] [client 74.249.245.134:24826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/about.php"] [unique_id "al9Od4As9lPxxVAErz395wAAAPo"]
[Tue Jul 21 07:48:23.939791 2026] [security2:error] [pid 302018:tid 302196] [client 20.151.10.161:19342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/f6.php"] [unique_id "al9Od4As9lPxxVAErz396QAAALM"]
[Tue Jul 21 07:48:23.940540 2026] [security2:error] [pid 296703:tid 296847] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Odyn25uliftkV1n4h9wAAAA4"]
[Tue Jul 21 07:48:23.947027 2026] [security2:error] [pid 296703:tid 296927] [client 49.13.164.148:33796] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9Odyn25uliftkV1n4h-AAAAF4"], referer: https://artetoner.com.br
[Tue Jul 21 07:48:24.049285 2026] [security2:error] [pid 302018:tid 302209] [client 122.164.127.47:57638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OeIAs9lPxxVAErz396wAAAMA"]
[Tue Jul 21 07:48:24.051621 2026] [security2:error] [pid 302018:tid 302209] [client 122.164.127.47:57638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OeIAs9lPxxVAErz396wAAAMA"]
[Tue Jul 21 07:48:24.188562 2026] [security2:error] [pid 296703:tid 296926] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9OeCn25uliftkV1n4h-gAAAF0"]
[Tue Jul 21 07:48:24.390908 2026] [security2:error] [pid 302018:tid 302254] [client 20.151.10.161:19442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/inputs.php"] [unique_id "al9OeIAs9lPxxVAErz399wAAAO0"]
[Tue Jul 21 07:48:24.456593 2026] [security2:error] [pid 302018:tid 302252] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9OeIAs9lPxxVAErz39-QAAAOs"]
[Tue Jul 21 07:48:24.515017 2026] [security2:error] [pid 302018:tid 302271] [client 20.104.96.117:46592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/rithin.php"] [unique_id "al9OeIAs9lPxxVAErz39_QAAAP4"]
[Tue Jul 21 07:48:24.685594 2026] [security2:error] [pid 302018:tid 302234] [client 20.151.10.161:19399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/inputs.php"] [unique_id "al9OeIAs9lPxxVAErz39_gAAANk"]
[Tue Jul 21 07:48:24.754423 2026] [security2:error] [pid 302018:tid 302218] [client 20.151.10.161:44017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/h02ugyh.php"] [unique_id "al9OeIAs9lPxxVAErz39_wAAAMk"]
[Tue Jul 21 07:48:24.790313 2026] [security2:error] [pid 302018:tid 302180] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9OeIAs9lPxxVAErz3-AQAAAKM"]
[Tue Jul 21 07:48:24.999449 2026] [security2:error] [pid 296703:tid 296938] [client 20.151.10.161:19357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/av.php"] [unique_id "al9OeCn25uliftkV1n4iCwAAAGk"]
[Tue Jul 21 07:48:25.010214 2026] [security2:error] [pid 302018:tid 302145] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OeYAs9lPxxVAErz3-BAAA7Hw"]
[Tue Jul 21 07:48:25.010360 2026] [security2:error] [pid 302018:tid 302253] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OeYAs9lPxxVAErz3-BAAA7Hw"]
[Tue Jul 21 07:48:25.207788 2026] [security2:error] [pid 296703:tid 296720] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OeSn25uliftkV1n4iEQAARRA"]
[Tue Jul 21 07:48:25.208100 2026] [security2:error] [pid 296703:tid 296902] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OeSn25uliftkV1n4iEQAARRA"]
[Tue Jul 21 07:48:25.307610 2026] [security2:error] [pid 296703:tid 296956] [client 20.151.10.161:19443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/classwithtostring.php"] [unique_id "al9OeSn25uliftkV1n4iFAAAAHs"]
[Tue Jul 21 07:48:25.321366 2026] [security2:error] [pid 296703:tid 296853] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9OeSn25uliftkV1n4iGQAAABQ"]
[Tue Jul 21 07:48:25.410294 2026] [security2:error] [pid 302018:tid 302194] [client 223.236.153.128:5166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OeYAs9lPxxVAErz3-DAAAALE"]
[Tue Jul 21 07:48:25.410415 2026] [security2:error] [pid 302018:tid 302194] [client 223.236.153.128:5166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OeYAs9lPxxVAErz3-DAAAALE"]
[Tue Jul 21 07:48:25.509706 2026] [security2:error] [pid 296703:tid 296891] [client 74.249.245.134:64107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/adminfuns.php"] [unique_id "al9OeSn25uliftkV1n4iHgAAADo"]
[Tue Jul 21 07:48:25.682632 2026] [security2:error] [pid 302018:tid 302244] [client 20.151.10.161:19451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9OeYAs9lPxxVAErz3-DgAAAOM"]
[Tue Jul 21 07:48:25.734751 2026] [security2:error] [pid 296703:tid 296946] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9OeSn25uliftkV1n4iIgAAAHE"]
[Tue Jul 21 07:48:25.889003 2026] [security2:error] [pid 296703:tid 296923] [client 20.151.10.161:44010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/seiso.php"] [unique_id "al9OeSn25uliftkV1n4iKQAAAFo"]
[Tue Jul 21 07:48:26.017535 2026] [security2:error] [pid 296703:tid 296877] [client 20.151.10.161:19280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wp-blog.php"] [unique_id "al9Oein25uliftkV1n4iLgAAACw"]
[Tue Jul 21 07:48:26.173237 2026] [security2:error] [pid 302018:tid 302224] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9OeoAs9lPxxVAErz3-EwAAAM8"]
[Tue Jul 21 07:48:26.306612 2026] [security2:error] [pid 302018:tid 302160] [client 136.144.33.54:63491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OeoAs9lPxxVAErz3-FAAAAI8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:26.322068 2026] [security2:error] [pid 302018:tid 302191] [client 20.104.96.117:46650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/fffm.php"] [unique_id "al9OeoAs9lPxxVAErz3-FwAAAK4"]
[Tue Jul 21 07:48:26.322474 2026] [core:alert] [pid 302018:tid 302182] [client 66.249.66.202:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:48:26.520791 2026] [security2:error] [pid 302018:tid 302235] [client 20.151.10.161:19356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wp-content/admin.php"] [unique_id "al9OeoAs9lPxxVAErz3-IgAAANo"]
[Tue Jul 21 07:48:26.615140 2026] [security2:error] [pid 302018:tid 302258] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9OeoAs9lPxxVAErz3-JgAAAPE"]
[Tue Jul 21 07:48:26.657071 2026] [security2:error] [pid 302018:tid 302194] [client 74.249.245.134:65141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/php8.php"] [unique_id "al9OeoAs9lPxxVAErz3-JwAAALE"]
[Tue Jul 21 07:48:26.744487 2026] [security2:error] [pid 296703:tid 296878] [client 202.143.127.214:65016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oein25uliftkV1n4iNgAAAC0"]
[Tue Jul 21 07:48:26.744633 2026] [security2:error] [pid 296703:tid 296878] [client 202.143.127.214:65016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oein25uliftkV1n4iNgAAAC0"]
[Tue Jul 21 07:48:26.815125 2026] [security2:error] [pid 296703:tid 296857] [client 20.151.10.161:19447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/adminfuns.php"] [unique_id "al9Oein25uliftkV1n4iNwAAABg"]
[Tue Jul 21 07:48:26.851701 2026] [security2:error] [pid 302018:tid 302274] [client 122.186.204.214:58081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OeoAs9lPxxVAErz3-KAAAAQE"]
[Tue Jul 21 07:48:26.856128 2026] [security2:error] [pid 302018:tid 302274] [client 122.186.204.214:58081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OeoAs9lPxxVAErz3-KAAAAQE"]
[Tue Jul 21 07:48:26.865769 2026] [security2:error] [pid 302018:tid 302231] [client 117.247.80.59:30818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OeoAs9lPxxVAErz3-KQAAANY"]
[Tue Jul 21 07:48:26.865884 2026] [security2:error] [pid 302018:tid 302231] [client 117.247.80.59:30818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OeoAs9lPxxVAErz3-KQAAANY"]
[Tue Jul 21 07:48:26.882989 2026] [security2:error] [pid 302018:tid 302198] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9OeoAs9lPxxVAErz3-KgAAALU"]
[Tue Jul 21 07:48:26.892270 2026] [security2:error] [pid 302018:tid 302153] [client 20.151.10.161:64168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/8.php"] [unique_id "al9OeoAs9lPxxVAErz3-KwAAAIg"]
[Tue Jul 21 07:48:26.902695 2026] [security2:error] [pid 296703:tid 296902] [client 62.102.148.187:58662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Oein25uliftkV1n4iOQAAAEU"]
[Tue Jul 21 07:48:26.902788 2026] [security2:error] [pid 296703:tid 296902] [client 62.102.148.187:58662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Oein25uliftkV1n4iOQAAAEU"]
[Tue Jul 21 07:48:27.069823 2026] [security2:error] [pid 302018:tid 302267] [client 154.192.233.199:59724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oe4As9lPxxVAErz3-NAAAAPo"]
[Tue Jul 21 07:48:27.069964 2026] [security2:error] [pid 302018:tid 302267] [client 154.192.233.199:59724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oe4As9lPxxVAErz3-NAAAAPo"]
[Tue Jul 21 07:48:27.185759 2026] [security2:error] [pid 302018:tid 302271] [client 20.151.10.161:19444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/goods.php"] [unique_id "al9Oe4As9lPxxVAErz3-NQAAAP4"]
[Tue Jul 21 07:48:27.357205 2026] [security2:error] [pid 302018:tid 302125] [remote 85.208.96.210:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "androapkmod.com"] [uri "/contato-dmca/"] [unique_id "al9Oe4As9lPxxVAErz3-NgAAp2g"]
[Tue Jul 21 07:48:27.357362 2026] [security2:error] [pid 302018:tid 302184] [client 85.208.96.210:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "androapkmod.com"] [uri "/contato-dmca/"] [unique_id "al9Oe4As9lPxxVAErz3-NgAAp2g"]
[Tue Jul 21 07:48:27.414062 2026] [security2:error] [pid 302018:tid 302252] [client 20.151.10.161:64140] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "techknowledgebr.com"] [uri "/1.php"] [unique_id "al9Oe4As9lPxxVAErz3-NwAAAOs"]
[Tue Jul 21 07:48:27.414206 2026] [security2:error] [pid 302018:tid 302252] [client 20.151.10.161:64140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/1.php"] [unique_id "al9Oe4As9lPxxVAErz3-NwAAAOs"]
[Tue Jul 21 07:48:27.455168 2026] [security2:error] [pid 302018:tid 302192] [client 59.96.220.140:58200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Oe4As9lPxxVAErz3-OQAAAK8"]
[Tue Jul 21 07:48:27.455275 2026] [security2:error] [pid 302018:tid 302192] [client 59.96.220.140:58200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Oe4As9lPxxVAErz3-OQAAAK8"]
[Tue Jul 21 07:48:27.464997 2026] [security2:error] [pid 296703:tid 296836] [client 20.104.96.117:27087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/dfre.php"] [unique_id "al9Oeyn25uliftkV1n4iPgAAAAM"]
[Tue Jul 21 07:48:27.510321 2026] [security2:error] [pid 302018:tid 302240] [client 20.151.10.161:19424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/ms-edit.php"] [unique_id "al9Oe4As9lPxxVAErz3-OwAAAN8"]
[Tue Jul 21 07:48:27.741667 2026] [security2:error] [pid 296703:tid 296852] [client 117.251.86.144:42574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Oeyn25uliftkV1n4iQgAAABM"]
[Tue Jul 21 07:48:27.741803 2026] [security2:error] [pid 296703:tid 296852] [client 117.251.86.144:42574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Oeyn25uliftkV1n4iQgAAABM"]
[Tue Jul 21 07:48:27.912053 2026] [security2:error] [pid 302018:tid 302258] [client 20.151.10.161:19440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/222.php"] [unique_id "al9Oe4As9lPxxVAErz3-QAAAAPE"]
[Tue Jul 21 07:48:28.096852 2026] [security2:error] [pid 302018:tid 302268] [client 103.76.88.37:7390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "azusacorretora.com.br"] [uri "/.env"] [unique_id "al9OfIAs9lPxxVAErz3-QwAAAPs"]
[Tue Jul 21 07:48:28.140346 2026] [security2:error] [pid 296703:tid 296713] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OfCn25uliftkV1n4iTQAAXAk"]
[Tue Jul 21 07:48:28.140470 2026] [security2:error] [pid 296703:tid 296925] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OfCn25uliftkV1n4iTQAAXAk"]
[Tue Jul 21 07:48:28.199085 2026] [security2:error] [pid 296703:tid 296955] [client 20.104.96.117:46693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/wp-happy.php"] [unique_id "al9OfCn25uliftkV1n4iTgAAAHo"]
[Tue Jul 21 07:48:28.204395 2026] [security2:error] [pid 296703:tid 296861] [client 20.151.10.161:62913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/100.php"] [unique_id "al9OfCn25uliftkV1n4iTwAAABw"]
[Tue Jul 21 07:48:28.209367 2026] [security2:error] [pid 302018:tid 302186] [client 20.151.10.161:19286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/cgi-bin/index.php"] [unique_id "al9OfIAs9lPxxVAErz3-RwAAAKk"]
[Tue Jul 21 07:48:28.224447 2026] [security2:error] [pid 296703:tid 296940] [client 194.99.104.35:52624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OfCn25uliftkV1n4iUAAAAGs"]
[Tue Jul 21 07:48:28.224547 2026] [security2:error] [pid 296703:tid 296940] [client 194.99.104.35:52624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OfCn25uliftkV1n4iUAAAAGs"]
[Tue Jul 21 07:48:28.286769 2026] [security2:error] [pid 302018:tid 302211] [client 74.249.245.134:64081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/info.php"] [unique_id "al9OfIAs9lPxxVAErz3-SAAAAMI"]
[Tue Jul 21 07:48:28.390339 2026] [security2:error] [pid 296703:tid 296903] [client 191.101.114.168:41940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9Odin25uliftkV1n4h6wAAAEY"], referer: https://drjoaoguedes.com/xmlrpc.php
[Tue Jul 21 07:48:28.538713 2026] [security2:error] [pid 302018:tid 302271] [client 20.151.10.161:63435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/about.php"] [unique_id "al9OfIAs9lPxxVAErz3-TQAAAP4"]
[Tue Jul 21 07:48:28.637444 2026] [security2:error] [pid 302018:tid 302182] [client 20.151.10.161:19406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/BDKR28WP.php"] [unique_id "al9OfIAs9lPxxVAErz3-TgAAAKU"]
[Tue Jul 21 07:48:28.690307 2026] [security2:error] [pid 302018:tid 302252] [client 20.151.10.161:43919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/155.php"] [unique_id "al9OfIAs9lPxxVAErz3-UAAAAOs"]
[Tue Jul 21 07:48:28.846153 2026] [security2:error] [pid 302018:tid 302234] [client 20.151.10.161:63458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/about.php"] [unique_id "al9OfIAs9lPxxVAErz3-UQAAANk"]
[Tue Jul 21 07:48:28.987601 2026] [security2:error] [pid 296703:tid 296926] [client 182.8.255.181:17704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OfCn25uliftkV1n4iWgAAAF0"]
[Tue Jul 21 07:48:28.987731 2026] [security2:error] [pid 296703:tid 296926] [client 182.8.255.181:17704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OfCn25uliftkV1n4iWgAAAF0"]
[Tue Jul 21 07:48:29.280429 2026] [security2:error] [pid 302018:tid 302270] [client 20.104.96.117:46598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/fpr4.php"] [unique_id "al9OfYAs9lPxxVAErz3-WQAAAP0"]
[Tue Jul 21 07:48:29.407514 2026] [security2:error] [pid 302018:tid 302236] [client 20.151.10.161:19371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/raw.php"] [unique_id "al9OfYAs9lPxxVAErz3-WwAAANs"]
[Tue Jul 21 07:48:29.478622 2026] [security2:error] [pid 296703:tid 296936] [client 20.151.10.161:63436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/admin.php"] [unique_id "al9OfSn25uliftkV1n4iYAAAAGc"]
[Tue Jul 21 07:48:29.478655 2026] [security2:error] [pid 302018:tid 302180] [client 139.167.225.182:55502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OfYAs9lPxxVAErz3-XAAAAKM"]
[Tue Jul 21 07:48:29.478765 2026] [security2:error] [pid 302018:tid 302180] [client 139.167.225.182:55502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OfYAs9lPxxVAErz3-XAAAAKM"]
[Tue Jul 21 07:48:29.604305 2026] [security2:error] [pid 296703:tid 296920] [client 41.68.90.219:56842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OfSn25uliftkV1n4iZAAAAFc"]
[Tue Jul 21 07:48:29.605667 2026] [security2:error] [pid 296703:tid 296920] [client 41.68.90.219:56842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OfSn25uliftkV1n4iZAAAAFc"]
[Tue Jul 21 07:48:29.696538 2026] [security2:error] [pid 302018:tid 302247] [client 20.151.10.161:19277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/abcd.php"] [unique_id "al9OfYAs9lPxxVAErz3-YAAAAOY"]
[Tue Jul 21 07:48:29.736518 2026] [security2:error] [pid 302018:tid 302179] [client 136.144.33.108:43635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OfYAs9lPxxVAErz3-YQAAAKI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:29.825846 2026] [security2:error] [pid 302018:tid 302152] [client 173.24.185.52:55328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OfYAs9lPxxVAErz3-YgAAAIc"]
[Tue Jul 21 07:48:29.825994 2026] [security2:error] [pid 302018:tid 302152] [client 173.24.185.52:55328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OfYAs9lPxxVAErz3-YgAAAIc"]
[Tue Jul 21 07:48:30.026893 2026] [security2:error] [pid 296703:tid 296847] [client 103.86.117.203:56036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ofin25uliftkV1n4ibgAAAA4"]
[Tue Jul 21 07:48:30.027012 2026] [security2:error] [pid 296703:tid 296847] [client 103.86.117.203:56036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ofin25uliftkV1n4ibgAAAA4"]
[Tue Jul 21 07:48:30.038432 2026] [security2:error] [pid 296703:tid 296858] [client 103.29.114.44:43223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ofin25uliftkV1n4ibwAAABk"]
[Tue Jul 21 07:48:30.038521 2026] [security2:error] [pid 296703:tid 296858] [client 103.29.114.44:43223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ofin25uliftkV1n4ibwAAABk"]
[Tue Jul 21 07:48:30.077378 2026] [security2:error] [pid 296703:tid 296917] [client 20.151.10.161:19355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/a1.php"] [unique_id "al9Ofin25uliftkV1n4icQAAAFQ"]
[Tue Jul 21 07:48:30.202064 2026] [security2:error] [pid 296703:tid 296859] [client 20.104.96.117:46654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/file88.php"] [unique_id "al9Ofin25uliftkV1n4idQAAABo"]
[Tue Jul 21 07:48:30.249116 2026] [security2:error] [pid 302018:tid 302184] [client 20.151.10.161:63428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/admin.php"] [unique_id "al9OfoAs9lPxxVAErz3-aQAAAKc"]
[Tue Jul 21 07:48:30.341256 2026] [security2:error] [pid 296703:tid 296874] [client 20.151.10.161:43935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/ppp.php"] [unique_id "al9Ofin25uliftkV1n4ifAAAACk"]
[Tue Jul 21 07:48:30.413111 2026] [security2:error] [pid 302018:tid 302234] [client 20.151.10.161:19336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9OfoAs9lPxxVAErz3-agAAANk"]
[Tue Jul 21 07:48:30.502263 2026] [security2:error] [pid 302018:tid 302274] [client 122.179.91.63:27287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OfoAs9lPxxVAErz3-awAAAQE"]
[Tue Jul 21 07:48:30.502477 2026] [security2:error] [pid 302018:tid 302274] [client 122.179.91.63:27287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OfoAs9lPxxVAErz3-awAAAQE"]
[Tue Jul 21 07:48:30.519838 2026] [security2:error] [pid 302018:tid 302253] [client 74.249.245.134:8782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/edit.php"] [unique_id "al9OfoAs9lPxxVAErz3-bAAAAOw"]
[Tue Jul 21 07:48:30.590167 2026] [security2:error] [pid 296703:tid 296762] [remote 52.167.144.213:9193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/"] [unique_id "al9OfSn25uliftkV1n4iYwAAATo"]
[Tue Jul 21 07:48:30.614218 2026] [security2:error] [pid 302018:tid 302266] [client 194.99.104.35:33670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9OfoAs9lPxxVAErz3-cgAAAPk"]
[Tue Jul 21 07:48:30.614327 2026] [security2:error] [pid 302018:tid 302266] [client 194.99.104.35:33670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9OfoAs9lPxxVAErz3-cgAAAPk"]
[Tue Jul 21 07:48:30.665352 2026] [security2:error] [pid 302018:tid 302264] [client 178.153.91.96:63186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OfoAs9lPxxVAErz3-dQAAAPc"]
[Tue Jul 21 07:48:30.665472 2026] [security2:error] [pid 302018:tid 302264] [client 178.153.91.96:63186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OfoAs9lPxxVAErz3-dQAAAPc"]
[Tue Jul 21 07:48:30.734054 2026] [security2:error] [pid 296703:tid 296927] [client 20.151.10.161:63480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/edit.php"] [unique_id "al9Ofin25uliftkV1n4iggAAAF4"]
[Tue Jul 21 07:48:30.787497 2026] [security2:error] [pid 296703:tid 296877] [client 20.151.10.161:19453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9Ofin25uliftkV1n4igwAAACw"]
[Tue Jul 21 07:48:30.894496 2026] [security2:error] [pid 302018:tid 302220] [client 173.252.95.37:45690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9OfoAs9lPxxVAErz3-eAAAAMs"]
[Tue Jul 21 07:48:31.013774 2026] [security2:error] [pid 302018:tid 302211] [client 20.151.10.161:43959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/201.php"] [unique_id "al9Of4As9lPxxVAErz3-fQAAAMI"]
[Tue Jul 21 07:48:31.048137 2026] [security2:error] [pid 302018:tid 302024] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Of4As9lPxxVAErz3-fgAApAM"]
[Tue Jul 21 07:48:31.048282 2026] [security2:error] [pid 302018:tid 302181] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Of4As9lPxxVAErz3-fgAApAM"]
[Tue Jul 21 07:48:31.069588 2026] [security2:error] [pid 302018:tid 302233] [client 20.104.96.117:46670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/ccc.php"] [unique_id "al9Of4As9lPxxVAErz3-fwAAANg"]
[Tue Jul 21 07:48:31.078190 2026] [security2:error] [pid 302018:tid 302228] [client 20.151.10.161:19452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wp-content/BypassBest.php"] [unique_id "al9Of4As9lPxxVAErz3-gAAAANM"]
[Tue Jul 21 07:48:31.084051 2026] [security2:error] [pid 302018:tid 302275] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9OfoAs9lPxxVAErz3-fAABAiI"]
[Tue Jul 21 07:48:31.113406 2026] [security2:error] [pid 302018:tid 302225] [client 20.151.10.161:63403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wp-content/admin.php"] [unique_id "al9Of4As9lPxxVAErz3-gQAAANA"]
[Tue Jul 21 07:48:31.490548 2026] [security2:error] [pid 302018:tid 302215] [client 20.151.10.161:63432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/f6.php"] [unique_id "al9Of4As9lPxxVAErz3-iAAAAMY"]
[Tue Jul 21 07:48:31.646874 2026] [security2:error] [pid 296703:tid 296910] [client 20.151.10.161:19362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/simple.php"] [unique_id "al9Ofyn25uliftkV1n4ilAAAAE0"]
[Tue Jul 21 07:48:31.704258 2026] [security2:error] [pid 302018:tid 302235] [client 89.124.113.107:55544] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.113.107" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "tryhealthonline.shop"] [uri "/wp-comments-post.php"] [unique_id "al9Of4As9lPxxVAErz3-iQAAANo"], referer: https://tryhealthonline.shop/hello-world/
[Tue Jul 21 07:48:31.704384 2026] [security2:error] [pid 302018:tid 302235] [client 89.124.113.107:55544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "tryhealthonline.shop"] [uri "/wp-comments-post.php"] [unique_id "al9Of4As9lPxxVAErz3-iQAAANo"], referer: https://tryhealthonline.shop/hello-world/
[Tue Jul 21 07:48:31.858605 2026] [security2:error] [pid 302018:tid 302272] [client 74.249.245.134:64196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/166.php"] [unique_id "al9Of4As9lPxxVAErz3-igAAAP8"]
[Tue Jul 21 07:48:31.863905 2026] [security2:error] [pid 302018:tid 302227] [client 20.104.96.117:27399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/777.php"] [unique_id "al9Of4As9lPxxVAErz3-iwAAANI"]
[Tue Jul 21 07:48:32.130736 2026] [security2:error] [pid 302018:tid 302230] [client 20.151.10.161:19343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/xxx.php"] [unique_id "al9OgIAs9lPxxVAErz3-jAAAANU"]
[Tue Jul 21 07:48:32.169421 2026] [security2:error] [pid 296703:tid 296835] [client 194.99.104.35:33682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OgCn25uliftkV1n4imwAAAAI"]
[Tue Jul 21 07:48:32.169527 2026] [security2:error] [pid 296703:tid 296835] [client 194.99.104.35:33682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OgCn25uliftkV1n4imwAAAAI"]
[Tue Jul 21 07:48:32.186307 2026] [security2:error] [pid 296703:tid 296757] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OgCn25uliftkV1n4ingAALTU"]
[Tue Jul 21 07:48:32.186448 2026] [security2:error] [pid 296703:tid 296878] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OgCn25uliftkV1n4ingAALTU"]
[Tue Jul 21 07:48:32.289957 2026] [security2:error] [pid 296703:tid 296880] [client 20.151.10.161:64244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/inputs.php"] [unique_id "al9OgCn25uliftkV1n4ioAAAAC8"]
[Tue Jul 21 07:48:32.347434 2026] [security2:error] [pid 302018:tid 302260] [client 178.128.61.43:62378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.61.128.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitaclick.com"] [uri "/wp-login.php"] [unique_id "al9OfYAs9lPxxVAErz3-VgAAAPM"], referer: https://t.co/
[Tue Jul 21 07:48:32.356942 2026] [security2:error] [pid 296703:tid 296938] [client 152.59.154.239:54034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OgCn25uliftkV1n4iogAAAGk"]
[Tue Jul 21 07:48:32.357048 2026] [security2:error] [pid 296703:tid 296938] [client 152.59.154.239:54034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OgCn25uliftkV1n4iogAAAGk"]
[Tue Jul 21 07:48:32.399572 2026] [security2:error] [pid 302018:tid 302220] [client 20.151.10.161:43968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/ops.php"] [unique_id "al9OgIAs9lPxxVAErz3-kAAAAMs"]
[Tue Jul 21 07:48:32.534050 2026] [security2:error] [pid 302018:tid 302243] [client 20.151.10.161:19407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/hypo.php"] [unique_id "al9OgIAs9lPxxVAErz3-kQAAAOI"]
[Tue Jul 21 07:48:32.569069 2026] [security2:error] [pid 302018:tid 302254] [client 184.75.223.211:52838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9OgIAs9lPxxVAErz3-kgAAAO0"]
[Tue Jul 21 07:48:32.569182 2026] [security2:error] [pid 302018:tid 302254] [client 184.75.223.211:52838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9OgIAs9lPxxVAErz3-kgAAAO0"]
[Tue Jul 21 07:48:32.576050 2026] [security2:error] [pid 302018:tid 302267] [client 184.75.223.211:52846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9OgIAs9lPxxVAErz3-kwAAAPo"]
[Tue Jul 21 07:48:32.576142 2026] [security2:error] [pid 302018:tid 302267] [client 184.75.223.211:52846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9OgIAs9lPxxVAErz3-kwAAAPo"]
[Tue Jul 21 07:48:32.718943 2026] [security2:error] [pid 302018:tid 302275] [client 20.104.96.117:46629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/for.php"] [unique_id "al9OgIAs9lPxxVAErz3-lwAAAQI"]
[Tue Jul 21 07:48:32.746739 2026] [security2:error] [pid 302018:tid 302225] [client 184.75.223.211:37906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9OgIAs9lPxxVAErz3-mAAAANA"]
[Tue Jul 21 07:48:32.746846 2026] [security2:error] [pid 302018:tid 302225] [client 184.75.223.211:37906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9OgIAs9lPxxVAErz3-mAAAANA"]
[Tue Jul 21 07:48:32.806828 2026] [security2:error] [pid 296703:tid 296946] [client 37.140.223.200:23243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OgCn25uliftkV1n4iowAAAHE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:48:32.813141 2026] [security2:error] [pid 302018:tid 302194] [client 106.215.181.8:32275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OgIAs9lPxxVAErz3-mQAAALE"]
[Tue Jul 21 07:48:32.819594 2026] [security2:error] [pid 302018:tid 302194] [client 106.215.181.8:32275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OgIAs9lPxxVAErz3-mQAAALE"]
[Tue Jul 21 07:48:32.955369 2026] [security2:error] [pid 302018:tid 302153] [client 117.217.38.194:50641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OgIAs9lPxxVAErz3-nwAAAIg"]
[Tue Jul 21 07:48:32.955472 2026] [security2:error] [pid 302018:tid 302153] [client 117.217.38.194:50641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OgIAs9lPxxVAErz3-nwAAAIg"]
[Tue Jul 21 07:48:33.057070 2026] [security2:error] [pid 302018:tid 302050] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OgYAs9lPxxVAErz3-owAArh0"]
[Tue Jul 21 07:48:33.057231 2026] [security2:error] [pid 302018:tid 302191] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OgYAs9lPxxVAErz3-owAArh0"]
[Tue Jul 21 07:48:33.071936 2026] [security2:error] [pid 302018:tid 302215] [client 20.151.10.161:19415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/chosen.php"] [unique_id "al9OgYAs9lPxxVAErz3-pAAAAMY"]
[Tue Jul 21 07:48:33.120200 2026] [security2:error] [pid 302018:tid 302255] [client 122.162.144.145:3196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OgYAs9lPxxVAErz3-pQAAAO4"]
[Tue Jul 21 07:48:33.120316 2026] [security2:error] [pid 302018:tid 302255] [client 122.162.144.145:3196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OgYAs9lPxxVAErz3-pQAAAO4"]
[Tue Jul 21 07:48:33.327163 2026] [security2:error] [pid 302018:tid 302198] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "dentitox.tryhealth.shop"] [uri "/index.php"] [unique_id "al9OgYAs9lPxxVAErz3-rgAAALU"]
[Tue Jul 21 07:48:33.327703 2026] [security2:error] [pid 302018:tid 302218] [client 20.10.88.227:22912] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "dentitox.tryhealth.shop"] [uri "/robots.txt"] [unique_id "al9OgYAs9lPxxVAErz3-rAAAAMk"]
[Tue Jul 21 07:48:33.362080 2026] [security2:error] [pid 296703:tid 296731] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OgSn25uliftkV1n4itAAAARs"]
[Tue Jul 21 07:48:33.362208 2026] [security2:error] [pid 296703:tid 296834] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OgSn25uliftkV1n4itAAAARs"]
[Tue Jul 21 07:48:33.531292 2026] [security2:error] [pid 302018:tid 302275] [client 20.151.10.161:19409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/file5.php"] [unique_id "al9OgYAs9lPxxVAErz3-swAAAQI"]
[Tue Jul 21 07:48:33.581402 2026] [security2:error] [pid 302018:tid 302225] [client 184.75.223.211:37920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9OgYAs9lPxxVAErz3-tAAAANA"]
[Tue Jul 21 07:48:33.581566 2026] [security2:error] [pid 302018:tid 302225] [client 184.75.223.211:37920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9OgYAs9lPxxVAErz3-tAAAANA"]
[Tue Jul 21 07:48:33.808206 2026] [security2:error] [pid 302018:tid 302184] [client 20.151.10.161:64184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/inputs.php"] [unique_id "al9OgYAs9lPxxVAErz3-twAAAKc"]
[Tue Jul 21 07:48:33.939604 2026] [security2:error] [pid 302018:tid 302200] [client 20.104.96.117:46647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/ssla.php"] [unique_id "al9OgYAs9lPxxVAErz3-uwAAALc"]
[Tue Jul 21 07:48:34.016386 2026] [security2:error] [pid 296703:tid 296931] [client 20.151.10.161:19417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/file.php"] [unique_id "al9Ogin25uliftkV1n4ivwAAAGI"]
[Tue Jul 21 07:48:34.248618 2026] [security2:error] [pid 296703:tid 296958] [client 103.166.103.129:58742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Ogin25uliftkV1n4ixgAAAH0"]
[Tue Jul 21 07:48:34.249187 2026] [security2:error] [pid 296703:tid 296958] [client 103.166.103.129:58742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Ogin25uliftkV1n4ixgAAAH0"]
[Tue Jul 21 07:48:34.256296 2026] [security2:error] [pid 296703:tid 296905] [client 20.151.10.161:43939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/ingfo.php"] [unique_id "al9Ogin25uliftkV1n4iyAAAAEg"]
[Tue Jul 21 07:48:34.319879 2026] [security2:error] [pid 302018:tid 302222] [client 20.104.96.117:27404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.mannucarvalho.com"] [uri "/zc-131.php"] [unique_id "al9OgoAs9lPxxVAErz3-xAAAAM0"]
[Tue Jul 21 07:48:34.352084 2026] [security2:error] [pid 302018:tid 302247] [client 20.151.10.161:19361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/aa2.php"] [unique_id "al9OgoAs9lPxxVAErz3-xgAAAOY"]
[Tue Jul 21 07:48:34.365494 2026] [security2:error] [pid 302018:tid 302229] [client 136.144.33.109:24171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OgoAs9lPxxVAErz3-yAAAANQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:34.391255 2026] [security2:error] [pid 302018:tid 311329] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OgoAs9lPxxVAErz3-yQAAxIM"]
[Tue Jul 21 07:48:34.391427 2026] [security2:error] [pid 302018:tid 302213] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OgoAs9lPxxVAErz3-yQAAxIM"]
[Tue Jul 21 07:48:34.518211 2026] [security2:error] [pid 302018:tid 302218] [client 74.249.245.134:64437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/8.php"] [unique_id "al9OgoAs9lPxxVAErz3-zgAAAMk"]
[Tue Jul 21 07:48:34.700323 2026] [security2:error] [pid 302018:tid 302234] [client 122.164.127.47:58207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OgoAs9lPxxVAErz3-0AAAANk"]
[Tue Jul 21 07:48:34.700423 2026] [security2:error] [pid 302018:tid 302234] [client 122.164.127.47:58207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OgoAs9lPxxVAErz3-0AAAANk"]
[Tue Jul 21 07:48:34.802691 2026] [security2:error] [pid 302018:tid 302266] [client 20.151.10.161:44003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/error_log.php"] [unique_id "al9OgoAs9lPxxVAErz3-0wAAAPk"]
[Tue Jul 21 07:48:34.839604 2026] [security2:error] [pid 302018:tid 302265] [client 191.101.114.168:59640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9OfYAs9lPxxVAErz3-WgAAAPg"], referer: https://drjoaoguedes.com/xmlrpc.php
[Tue Jul 21 07:48:34.887103 2026] [security2:error] [pid 302018:tid 302172] [client 20.151.10.161:19360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/ccou.php"] [unique_id "al9OgoAs9lPxxVAErz3-1QAAAJs"]
[Tue Jul 21 07:48:35.011768 2026] [security2:error] [pid 302018:tid 302170] [client 20.151.10.161:64138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/av.php"] [unique_id "al9Og4As9lPxxVAErz3-2gAAAJk"]
[Tue Jul 21 07:48:35.198575 2026] [security2:error] [pid 302018:tid 302152] [client 20.151.10.161:19391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/dr.php"] [unique_id "al9Og4As9lPxxVAErz3-3AAAAIc"]
[Tue Jul 21 07:48:35.822584 2026] [security2:error] [pid 296703:tid 296903] [client 20.151.10.161:43975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/xenon1337.php"] [unique_id "al9Ogyn25uliftkV1n4i3wAAAEY"]
[Tue Jul 21 07:48:35.943031 2026] [security2:error] [pid 302018:tid 302132] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Og4As9lPxxVAErz3-4wABAW8"]
[Tue Jul 21 07:48:35.943220 2026] [security2:error] [pid 302018:tid 302274] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Og4As9lPxxVAErz3-4wABAW8"]
[Tue Jul 21 07:48:36.020253 2026] [security2:error] [pid 302018:tid 302263] [client 172.235.138.70:8538] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "br1102.hostgator.com.br"] [uri "/"] [unique_id "al9OhIAs9lPxxVAErz3-5QAAAPY"]
[Tue Jul 21 07:48:36.040925 2026] [security2:error] [pid 296703:tid 296840] [client 223.236.153.128:7512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OhCn25uliftkV1n4i5QAAAAc"]
[Tue Jul 21 07:48:36.041042 2026] [security2:error] [pid 296703:tid 296840] [client 223.236.153.128:7512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OhCn25uliftkV1n4i5QAAAAc"]
[Tue Jul 21 07:48:36.059242 2026] [security2:error] [pid 302018:tid 302135] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OhIAs9lPxxVAErz3-5gAAknI"]
[Tue Jul 21 07:48:36.059398 2026] [security2:error] [pid 302018:tid 302163] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OhIAs9lPxxVAErz3-5gAAknI"]
[Tue Jul 21 07:48:36.128953 2026] [security2:error] [pid 302018:tid 302271] [client 178.128.61.43:64422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.61.128.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitaclick.com"] [uri "/wp-login.php"] [unique_id "al9OhIAs9lPxxVAErz3-5wAAAP4"]
[Tue Jul 21 07:48:36.158415 2026] [security2:error] [pid 296703:tid 296913] [client 20.151.10.161:19455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/file31.php"] [unique_id "al9OhCn25uliftkV1n4i5gAAAFA"]
[Tue Jul 21 07:48:36.225242 2026] [security2:error] [pid 302018:tid 302196] [client 193.36.225.96:41587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Og4As9lPxxVAErz3-2wAAALM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:48:37.033675 2026] [security2:error] [pid 302018:tid 302186] [client 20.151.10.161:19363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/file6.php"] [unique_id "al9OhYAs9lPxxVAErz3-8AAAAKk"]
[Tue Jul 21 07:48:37.370210 2026] [security2:error] [pid 296703:tid 296901] [client 20.151.10.161:43844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/test11.php"] [unique_id "al9OhSn25uliftkV1n4i-wAAAEQ"]
[Tue Jul 21 07:48:37.375400 2026] [security2:error] [pid 296703:tid 296905] [client 74.249.245.134:64415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ws38.php"] [unique_id "al9OhSn25uliftkV1n4i_AAAAEg"]
[Tue Jul 21 07:48:37.497234 2026] [security2:error] [pid 296703:tid 296883] [client 20.151.10.161:19359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/file15.php"] [unique_id "al9OhSn25uliftkV1n4i_wAAADI"]
[Tue Jul 21 07:48:37.557530 2026] [security2:error] [pid 296703:tid 296944] [client 117.247.80.59:31047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OhSn25uliftkV1n4jAAAAAG8"]
[Tue Jul 21 07:48:37.557623 2026] [security2:error] [pid 296703:tid 296944] [client 117.247.80.59:31047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OhSn25uliftkV1n4jAAAAAG8"]
[Tue Jul 21 07:48:37.590347 2026] [security2:error] [pid 302018:tid 302152] [client 122.186.204.214:58622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OhYAs9lPxxVAErz3--QAAAIc"]
[Tue Jul 21 07:48:37.590446 2026] [security2:error] [pid 302018:tid 302152] [client 122.186.204.214:58622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OhYAs9lPxxVAErz3--QAAAIc"]
[Tue Jul 21 07:48:37.830730 2026] [security2:error] [pid 296703:tid 296880] [client 20.220.225.223:24215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9OhSn25uliftkV1n4jBQAAAC8"]
[Tue Jul 21 07:48:37.833052 2026] [security2:error] [pid 302018:tid 302187] [client 154.192.233.199:58970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OhYAs9lPxxVAErz3_AwAAAKo"]
[Tue Jul 21 07:48:37.833170 2026] [security2:error] [pid 302018:tid 302187] [client 154.192.233.199:58970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OhYAs9lPxxVAErz3_AwAAAKo"]
[Tue Jul 21 07:48:37.850186 2026] [security2:error] [pid 302018:tid 302196] [client 20.151.10.161:19388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/jp.php"] [unique_id "al9OhYAs9lPxxVAErz3_BAAAALM"]
[Tue Jul 21 07:48:38.097784 2026] [security2:error] [pid 302018:tid 302211] [client 202.143.127.214:65481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OhoAs9lPxxVAErz3_BgAAAMI"]
[Tue Jul 21 07:48:38.097954 2026] [security2:error] [pid 302018:tid 302211] [client 202.143.127.214:65481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OhoAs9lPxxVAErz3_BgAAAMI"]
[Tue Jul 21 07:48:38.138455 2026] [security2:error] [pid 302018:tid 302231] [client 136.144.33.99:57257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OhoAs9lPxxVAErz3_BwAAANY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:38.157810 2026] [security2:error] [pid 296703:tid 296955] [client 20.151.10.161:19264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/f35.php"] [unique_id "al9Ohin25uliftkV1n4jDAAAAHo"]
[Tue Jul 21 07:48:38.406516 2026] [security2:error] [pid 302018:tid 302170] [client 20.220.225.223:24243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9OhoAs9lPxxVAErz3_CgAAAJk"]
[Tue Jul 21 07:48:38.569219 2026] [security2:error] [pid 302018:tid 302230] [client 117.251.86.144:60606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OhoAs9lPxxVAErz3_CwAAANU"]
[Tue Jul 21 07:48:38.569394 2026] [security2:error] [pid 302018:tid 302230] [client 117.251.86.144:60606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OhoAs9lPxxVAErz3_CwAAANU"]
[Tue Jul 21 07:48:38.598794 2026] [security2:error] [pid 302018:tid 302268] [client 20.151.10.161:19385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wp-load.php"] [unique_id "al9OhoAs9lPxxVAErz3_DAAAAPs"]
[Tue Jul 21 07:48:38.704945 2026] [core:error] [pid 296703:tid 296763] [remote 40.77.167.28:44217] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:48:38.704962 2026] [core:error] [pid 296703:tid 296763] [remote 40.77.167.28:44217] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:48:38.712858 2026] [security2:error] [pid 296703:tid 296772] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ohin25uliftkV1n4jFQAAGkQ"]
[Tue Jul 21 07:48:38.712986 2026] [security2:error] [pid 296703:tid 296859] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ohin25uliftkV1n4jFQAAGkQ"]
[Tue Jul 21 07:48:38.945343 2026] [security2:error] [pid 302018:tid 302254] [client 20.151.10.161:43944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/koala.php"] [unique_id "al9OhoAs9lPxxVAErz3_DwAAAO0"]
[Tue Jul 21 07:48:39.158733 2026] [core:alert] [pid 302018:tid 302184] [client 57.141.18.73:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:48:39.163757 2026] [proxy:error] [pid 296703:tid 296877] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:48:39.163832 2026] [proxy_http:error] [pid 296703:tid 296877] [client 137.184.181.86:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:48:39.164389 2026] [proxy:error] [pid 296703:tid 296877] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:48:39.164412 2026] [proxy_http:error] [pid 296703:tid 296877] [client 137.184.181.86:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:48:39.275016 2026] [security2:error] [pid 302018:tid 302153] [client 20.151.10.161:19298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9Oh4As9lPxxVAErz3_GAAAAIg"]
[Tue Jul 21 07:48:39.308604 2026] [security2:error] [pid 302018:tid 302271] [client 20.220.225.223:24245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/wander.php"] [unique_id "al9Oh4As9lPxxVAErz3_GQAAAP4"]
[Tue Jul 21 07:48:39.317770 2026] [security2:error] [pid 296703:tid 296950] [client 59.96.220.140:59122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Ohyn25uliftkV1n4jHAAAAHU"]
[Tue Jul 21 07:48:39.317929 2026] [security2:error] [pid 296703:tid 296950] [client 59.96.220.140:59122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9Ohyn25uliftkV1n4jHAAAAHU"]
[Tue Jul 21 07:48:39.447144 2026] [security2:error] [pid 296703:tid 296845] [client 182.8.255.181:17479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Ohyn25uliftkV1n4jHQAAAAw"]
[Tue Jul 21 07:48:39.447272 2026] [security2:error] [pid 296703:tid 296845] [client 182.8.255.181:17479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Ohyn25uliftkV1n4jHQAAAAw"]
[Tue Jul 21 07:48:39.477014 2026] [security2:error] [pid 302018:tid 302191] [client 20.151.10.161:63404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/classwithtostring.php"] [unique_id "al9Oh4As9lPxxVAErz3_HAAAAK4"]
[Tue Jul 21 07:48:39.514155 2026] [proxy:error] [pid 296703:tid 296863] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:48:39.514203 2026] [proxy_http:error] [pid 296703:tid 296863] [client 137.184.181.86:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.brendoww.srodrigues1748183999701.0711679.meusitehostgator.com.br/
[Tue Jul 21 07:48:39.514621 2026] [proxy:error] [pid 296703:tid 296863] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:48:39.514642 2026] [proxy_http:error] [pid 296703:tid 296863] [client 137.184.181.86:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.brendoww.srodrigues1748183999701.0711679.meusitehostgator.com.br/
[Tue Jul 21 07:48:39.719583 2026] [security2:error] [pid 302018:tid 302170] [client 20.151.10.161:19353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wp-links.php"] [unique_id "al9Oh4As9lPxxVAErz3_IgAAAJk"]
[Tue Jul 21 07:48:39.805450 2026] [autoindex:error] [pid 296703:tid 296960] [client 100.50.152.193:36471] AH01276: Cannot serve directory /home4/saojor65/madmoholding/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:48:39.988837 2026] [security2:error] [pid 296703:tid 296849] [client 20.220.225.223:24221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/jga.php"] [unique_id "al9Ohyn25uliftkV1n4jJwAAABA"]
[Tue Jul 21 07:48:40.303858 2026] [security2:error] [pid 296703:tid 296941] [client 173.24.185.52:55785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OiCn25uliftkV1n4jLQAAAGw"]
[Tue Jul 21 07:48:40.304000 2026] [security2:error] [pid 296703:tid 296941] [client 173.24.185.52:55785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OiCn25uliftkV1n4jLQAAAGw"]
[Tue Jul 21 07:48:40.307153 2026] [security2:error] [pid 296703:tid 296931] [client 139.167.225.182:56195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OiCn25uliftkV1n4jLgAAAGI"]
[Tue Jul 21 07:48:40.307226 2026] [security2:error] [pid 296703:tid 296931] [client 139.167.225.182:56195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OiCn25uliftkV1n4jLgAAAGI"]
[Tue Jul 21 07:48:40.467075 2026] [security2:error] [pid 302018:tid 302220] [client 20.151.10.161:19405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/solo1.php"] [unique_id "al9OiIAs9lPxxVAErz3_KwAAAMs"]
[Tue Jul 21 07:48:40.522571 2026] [security2:error] [pid 302018:tid 302162] [client 103.86.117.203:56590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OiIAs9lPxxVAErz3_LAAAAJE"]
[Tue Jul 21 07:48:40.522697 2026] [security2:error] [pid 302018:tid 302162] [client 103.86.117.203:56590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OiIAs9lPxxVAErz3_LAAAAJE"]
[Tue Jul 21 07:48:40.792106 2026] [security2:error] [pid 296703:tid 296779] [remote 124.55.178.99:56370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojadedoces.com"] [uri "/wp-login.php"] [unique_id "al9OiCn25uliftkV1n4jNwAAL0s"]
[Tue Jul 21 07:48:40.944549 2026] [security2:error] [pid 302018:tid 302211] [client 20.151.10.161:19344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/sixxis.php"] [unique_id "al9OiIAs9lPxxVAErz3_MAAAAMI"]
[Tue Jul 21 07:48:41.267944 2026] [security2:error] [pid 302018:tid 302170] [client 20.151.10.161:43920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/mac.php"] [unique_id "al9OiYAs9lPxxVAErz3_MwAAAJk"]
[Tue Jul 21 07:48:41.271843 2026] [security2:error] [pid 302018:tid 302152] [client 122.179.91.63:16726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OiYAs9lPxxVAErz3_NAAAAIc"]
[Tue Jul 21 07:48:41.271942 2026] [security2:error] [pid 302018:tid 302152] [client 122.179.91.63:16726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OiYAs9lPxxVAErz3_NAAAAIc"]
[Tue Jul 21 07:48:41.305290 2026] [security2:error] [pid 302018:tid 302247] [client 74.249.245.134:64384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/a7.php"] [unique_id "al9OiYAs9lPxxVAErz3_NQAAAOY"]
[Tue Jul 21 07:48:41.323442 2026] [security2:error] [pid 296703:tid 296840] [client 20.151.10.161:19273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/2P.update.php"] [unique_id "al9OiSn25uliftkV1n4jPAAAAAc"]
[Tue Jul 21 07:48:41.465990 2026] [security2:error] [pid 302018:tid 302172] [client 41.68.90.219:57300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OiYAs9lPxxVAErz3_OAAAAJs"]
[Tue Jul 21 07:48:41.466185 2026] [security2:error] [pid 302018:tid 302172] [client 41.68.90.219:57300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OiYAs9lPxxVAErz3_OAAAAJs"]
[Tue Jul 21 07:48:41.712935 2026] [security2:error] [pid 302018:tid 302209] [client 184.75.223.211:47306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9OiYAs9lPxxVAErz3_OgAAAMA"]
[Tue Jul 21 07:48:41.713041 2026] [security2:error] [pid 302018:tid 302209] [client 184.75.223.211:47306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9OiYAs9lPxxVAErz3_OgAAAMA"]
[Tue Jul 21 07:48:41.750622 2026] [security2:error] [pid 302018:tid 302026] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OiYAs9lPxxVAErz3_OwAAyQU"]
[Tue Jul 21 07:48:41.750839 2026] [security2:error] [pid 302018:tid 302218] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OiYAs9lPxxVAErz3_OwAAyQU"]
[Tue Jul 21 07:48:41.801341 2026] [security2:error] [pid 302018:tid 302266] [client 193.36.225.10:43617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OiYAs9lPxxVAErz3_PAAAAPk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:41.803551 2026] [security2:error] [pid 302018:tid 302204] [client 20.220.225.223:24194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/x.php"] [unique_id "al9OiYAs9lPxxVAErz3_PQAAALs"]
[Tue Jul 21 07:48:41.823982 2026] [security2:error] [pid 296703:tid 296841] [client 20.151.10.161:63384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9OiSn25uliftkV1n4jRAAAAAg"]
[Tue Jul 21 07:48:41.935297 2026] [security2:error] [pid 302018:tid 302225] [client 20.151.10.161:19347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/a.php"] [unique_id "al9OiYAs9lPxxVAErz3_PwAAANA"]
[Tue Jul 21 07:48:42.125673 2026] [security2:error] [pid 302018:tid 302183] [client 193.36.225.143:44005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OiYAs9lPxxVAErz3_QQAAAKY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:48:42.132793 2026] [security2:error] [pid 302018:tid 302186] [client 178.153.91.96:26019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OioAs9lPxxVAErz3_RAAAAKk"]
[Tue Jul 21 07:48:42.132936 2026] [security2:error] [pid 302018:tid 302186] [client 178.153.91.96:26019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OioAs9lPxxVAErz3_RAAAAKk"]
[Tue Jul 21 07:48:42.161964 2026] [security2:error] [pid 296703:tid 296877] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Oiin25uliftkV1n4jSQAALG0"]
[Tue Jul 21 07:48:42.560535 2026] [security2:error] [pid 296703:tid 296922] [client 20.151.10.161:19348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/k.php"] [unique_id "al9Oiin25uliftkV1n4jUQAAAFk"]
[Tue Jul 21 07:48:42.752080 2026] [security2:error] [pid 296703:tid 296822] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oiin25uliftkV1n4jVQAAfXY"]
[Tue Jul 21 07:48:42.752265 2026] [security2:error] [pid 296703:tid 296958] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oiin25uliftkV1n4jVQAAfXY"]
[Tue Jul 21 07:48:42.800486 2026] [core:error] [pid 296703:tid 296798] [remote 52.167.144.206:64040] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:48:42.800518 2026] [core:error] [pid 296703:tid 296798] [remote 52.167.144.206:64040] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:48:43.157338 2026] [security2:error] [pid 302018:tid 302191] [client 152.59.154.239:54543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oi4As9lPxxVAErz3_TQAAAK4"]
[Tue Jul 21 07:48:43.157440 2026] [security2:error] [pid 302018:tid 302191] [client 152.59.154.239:54543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oi4As9lPxxVAErz3_TQAAAK4"]
[Tue Jul 21 07:48:43.214549 2026] [security2:error] [pid 302018:tid 302172] [client 20.151.10.161:43852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9Oi4As9lPxxVAErz3_TgAAAJs"]
[Tue Jul 21 07:48:43.245315 2026] [security2:error] [pid 302018:tid 302179] [client 20.151.10.161:19374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/w.php"] [unique_id "al9Oi4As9lPxxVAErz3_TwAAAKI"]
[Tue Jul 21 07:48:43.455308 2026] [security2:error] [pid 302018:tid 302244] [client 117.217.38.194:51236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oi4As9lPxxVAErz3_UgAAAOM"]
[Tue Jul 21 07:48:43.455431 2026] [security2:error] [pid 302018:tid 302244] [client 117.217.38.194:51236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oi4As9lPxxVAErz3_UgAAAOM"]
[Tue Jul 21 07:48:43.490180 2026] [security2:error] [pid 296703:tid 296876] [client 106.215.181.8:30778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oiyn25uliftkV1n4jYwAAACs"]
[Tue Jul 21 07:48:43.490308 2026] [security2:error] [pid 296703:tid 296876] [client 106.215.181.8:30778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oiyn25uliftkV1n4jYwAAACs"]
[Tue Jul 21 07:48:43.576637 2026] [security2:error] [pid 296703:tid 296731] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Oiyn25uliftkV1n4jZAAAHxs"]
[Tue Jul 21 07:48:43.576839 2026] [security2:error] [pid 296703:tid 296864] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Oiyn25uliftkV1n4jZAAAHxs"]
[Tue Jul 21 07:48:43.660130 2026] [security2:error] [pid 302018:tid 302208] [client 178.128.61.43:65397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.61.128.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitaclick.com"] [uri "/wp-login.php"] [unique_id "al9Oi4As9lPxxVAErz3_UwAAAL8"], referer: https://wordpress.org/
[Tue Jul 21 07:48:43.702513 2026] [security2:error] [pid 302018:tid 302220] [client 20.151.10.161:64215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wp-blog.php"] [unique_id "al9Oi4As9lPxxVAErz3_VwAAAMs"]
[Tue Jul 21 07:48:43.844970 2026] [security2:error] [pid 296703:tid 296878] [client 122.162.144.145:3950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Oiyn25uliftkV1n4jaAAAAC0"]
[Tue Jul 21 07:48:43.845103 2026] [security2:error] [pid 296703:tid 296878] [client 122.162.144.145:3950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Oiyn25uliftkV1n4jaAAAAC0"]
[Tue Jul 21 07:48:43.877973 2026] [security2:error] [pid 296703:tid 296750] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Oiyn25uliftkV1n4jagAAei4"]
[Tue Jul 21 07:48:43.878116 2026] [security2:error] [pid 296703:tid 296955] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Oiyn25uliftkV1n4jagAAei4"]
[Tue Jul 21 07:48:44.011848 2026] [security2:error] [pid 302018:tid 302271] [client 20.151.10.161:19448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/insc.php"] [unique_id "al9OjIAs9lPxxVAErz3_XAAAAP4"]
[Tue Jul 21 07:48:44.369697 2026] [security2:error] [pid 302018:tid 302268] [client 20.220.225.223:24240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9OjIAs9lPxxVAErz3_ZwAAAPs"]
[Tue Jul 21 07:48:44.486830 2026] [security2:error] [pid 296703:tid 296842] [client 20.151.10.161:19339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9OjCn25uliftkV1n4jeQAAAAk"]
[Tue Jul 21 07:48:44.844868 2026] [security2:error] [pid 302018:tid 302179] [client 193.36.225.123:42997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OjIAs9lPxxVAErz3_bQAAAKI"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:48:44.966612 2026] [security2:error] [pid 302018:tid 302060] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OjIAs9lPxxVAErz3_dgAAyyc"]
[Tue Jul 21 07:48:44.966764 2026] [security2:error] [pid 302018:tid 302220] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OjIAs9lPxxVAErz3_dgAAyyc"]
[Tue Jul 21 07:48:45.018844 2026] [security2:error] [pid 296703:tid 296960] [client 20.151.10.161:19283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/u.php"] [unique_id "al9OjSn25uliftkV1n4jhQAAAH8"]
[Tue Jul 21 07:48:45.107896 2026] [security2:error] [pid 302018:tid 302186] [client 74.249.245.134:24769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/classsmtps.php"] [unique_id "al9OjYAs9lPxxVAErz3_egAAAKk"]
[Tue Jul 21 07:48:45.122570 2026] [security2:error] [pid 302018:tid 302264] [client 194.99.104.35:46298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OjYAs9lPxxVAErz3_ewAAAPc"]
[Tue Jul 21 07:48:45.122641 2026] [security2:error] [pid 302018:tid 302264] [client 194.99.104.35:46298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OjYAs9lPxxVAErz3_ewAAAPc"]
[Tue Jul 21 07:48:45.129082 2026] [security2:error] [pid 296703:tid 296873] [client 103.166.103.129:27063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OjSn25uliftkV1n4jhwAAACg"]
[Tue Jul 21 07:48:45.129208 2026] [security2:error] [pid 296703:tid 296873] [client 103.166.103.129:27063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OjSn25uliftkV1n4jhwAAACg"]
[Tue Jul 21 07:48:45.278864 2026] [security2:error] [pid 296703:tid 296862] [client 122.164.127.47:58789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OjSn25uliftkV1n4jiQAAAB0"]
[Tue Jul 21 07:48:45.280406 2026] [security2:error] [pid 296703:tid 296862] [client 122.164.127.47:58789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OjSn25uliftkV1n4jiQAAAB0"]
[Tue Jul 21 07:48:45.321704 2026] [security2:error] [pid 296703:tid 296932] [client 20.220.225.223:24210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/ee.php"] [unique_id "al9OjSn25uliftkV1n4jiwAAAGM"]
[Tue Jul 21 07:48:45.353841 2026] [security2:error] [pid 302018:tid 302099] [remote 199.189.225.40:28011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medoraldracena.com.br"] [uri "/wp-login.php"] [unique_id "al9OjYAs9lPxxVAErz3_fQAA7E4"]
[Tue Jul 21 07:48:45.367853 2026] [security2:error] [pid 302018:tid 302231] [client 20.226.60.151:61611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/w3llscc.php"] [unique_id "al9OjYAs9lPxxVAErz3_fgAAANY"]
[Tue Jul 21 07:48:45.569953 2026] [security2:error] [pid 302018:tid 302170] [client 20.151.10.161:19376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/sss.php"] [unique_id "al9OjYAs9lPxxVAErz3_gAAAAJk"]
[Tue Jul 21 07:48:45.617213 2026] [security2:error] [pid 302018:tid 302196] [client 136.144.33.215:55245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OjYAs9lPxxVAErz3_gwAAALM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:45.672651 2026] [security2:error] [pid 302018:tid 302194] [client 20.220.225.223:24252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/blue.php"] [unique_id "al9OjYAs9lPxxVAErz3_hAAAALE"]
[Tue Jul 21 07:48:45.817472 2026] [security2:error] [pid 302018:tid 302258] [client 20.151.10.161:43912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wefile.php"] [unique_id "al9OjYAs9lPxxVAErz3_iAAAAPE"]
[Tue Jul 21 07:48:46.146342 2026] [security2:error] [pid 296703:tid 296890] [client 20.151.10.161:19370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/sss.php"] [unique_id "al9Ojin25uliftkV1n4jmgAAADk"]
[Tue Jul 21 07:48:46.247803 2026] [security2:error] [pid 296703:tid 296955] [client 20.220.225.223:24275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/wp-signup.php"] [unique_id "al9Ojin25uliftkV1n4jnQAAAHo"]
[Tue Jul 21 07:48:46.364956 2026] [security2:error] [pid 302018:tid 302187] [client 20.151.10.161:64221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wp-content/admin.php"] [unique_id "al9OjoAs9lPxxVAErz3_kwAAAKo"]
[Tue Jul 21 07:48:46.366178 2026] [security2:error] [pid 296703:tid 296940] [client 37.140.223.200:50461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Ojin25uliftkV1n4jnwAAAGs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:48:46.510249 2026] [security2:error] [pid 296703:tid 296878] [client 114.119.157.112:20129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.compressoresra.com.br"] [uri "/phpmailer/SECURITY.md"] [unique_id "al9Ojin25uliftkV1n4jogAAAC0"], referer: https://www.compressoresra.com.br/phpmailer/SECURITY.md
[Tue Jul 21 07:48:46.693874 2026] [security2:error] [pid 302018:tid 302090] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OjoAs9lPxxVAErz3_lQAA_0U"]
[Tue Jul 21 07:48:46.694086 2026] [security2:error] [pid 302018:tid 302272] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OjoAs9lPxxVAErz3_lQAA_0U"]
[Tue Jul 21 07:48:46.751123 2026] [security2:error] [pid 302018:tid 302194] [client 20.151.10.161:19389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/c.php"] [unique_id "al9OjoAs9lPxxVAErz3_mAAAALE"]
[Tue Jul 21 07:48:46.770299 2026] [security2:error] [pid 302018:tid 302179] [client 223.236.153.128:5990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OjoAs9lPxxVAErz3_mwAAAKI"]
[Tue Jul 21 07:48:46.770404 2026] [security2:error] [pid 302018:tid 302179] [client 223.236.153.128:5990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OjoAs9lPxxVAErz3_mwAAAKI"]
[Tue Jul 21 07:48:46.951961 2026] [security2:error] [pid 302018:tid 302058] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OjoAs9lPxxVAErz3_oQAA7SU"]
[Tue Jul 21 07:48:46.952194 2026] [security2:error] [pid 302018:tid 302254] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OjoAs9lPxxVAErz3_oQAA7SU"]
[Tue Jul 21 07:48:47.246600 2026] [security2:error] [pid 296703:tid 296930] [client 20.151.10.161:63445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/adminfuns.php"] [unique_id "al9Ojyn25uliftkV1n4jqgAAAGE"]
[Tue Jul 21 07:48:47.283890 2026] [security2:error] [pid 296703:tid 296950] [client 20.151.10.161:19275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/aa.php"] [unique_id "al9Ojyn25uliftkV1n4jqwAAAHU"]
[Tue Jul 21 07:48:47.490503 2026] [security2:error] [pid 296703:tid 296912] [client 20.220.225.223:24282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/csa.php"] [unique_id "al9Ojyn25uliftkV1n4jrwAAAE8"]
[Tue Jul 21 07:48:47.699925 2026] [security2:error] [pid 296703:tid 296877] [client 20.151.10.161:19352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/100.php"] [unique_id "al9Ojyn25uliftkV1n4jtQAAACw"]
[Tue Jul 21 07:48:47.905582 2026] [security2:error] [pid 296703:tid 296883] [client 4.204.201.85:51293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Ojyn25uliftkV1n4jugAAADI"]
[Tue Jul 21 07:48:48.058038 2026] [security2:error] [pid 296703:tid 296897] [client 20.151.10.161:63374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/goods.php"] [unique_id "al9OkCn25uliftkV1n4juwAAAEA"]
[Tue Jul 21 07:48:48.312391 2026] [security2:error] [pid 302018:tid 302272] [client 194.99.104.35:47900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9OkIAs9lPxxVAErz3_zwAAAP8"]
[Tue Jul 21 07:48:48.312490 2026] [security2:error] [pid 302018:tid 302272] [client 194.99.104.35:47900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9OkIAs9lPxxVAErz3_zwAAAP8"]
[Tue Jul 21 07:48:48.375395 2026] [security2:error] [pid 302018:tid 302253] [client 74.249.245.134:65145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/rip.php"] [unique_id "al9OkIAs9lPxxVAErz3_0AAAAOw"]
[Tue Jul 21 07:48:48.384964 2026] [security2:error] [pid 296703:tid 296873] [client 122.186.204.214:59170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OkCn25uliftkV1n4jxAAAACg"]
[Tue Jul 21 07:48:48.385102 2026] [security2:error] [pid 296703:tid 296873] [client 122.186.204.214:59170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OkCn25uliftkV1n4jxAAAACg"]
[Tue Jul 21 07:48:48.386403 2026] [security2:error] [pid 302018:tid 302186] [client 117.247.80.59:20876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OkIAs9lPxxVAErz3_0QAAAKk"]
[Tue Jul 21 07:48:48.386622 2026] [security2:error] [pid 302018:tid 302186] [client 117.247.80.59:20876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OkIAs9lPxxVAErz3_0QAAAKk"]
[Tue Jul 21 07:48:48.494142 2026] [security2:error] [pid 296703:tid 296946] [client 20.151.10.161:19295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/footer.php"] [unique_id "al9OkCn25uliftkV1n4jyAAAAHE"]
[Tue Jul 21 07:48:48.661499 2026] [security2:error] [pid 302018:tid 302211] [client 59.96.220.140:59799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OkIAs9lPxxVAErz3_1QAAAMI"]
[Tue Jul 21 07:48:48.661634 2026] [security2:error] [pid 302018:tid 302211] [client 59.96.220.140:59799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OkIAs9lPxxVAErz3_1QAAAMI"]
[Tue Jul 21 07:48:48.725228 2026] [security2:error] [pid 302018:tid 302163] [client 154.192.233.199:58827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OkIAs9lPxxVAErz3_1wAAAJI"]
[Tue Jul 21 07:48:48.725322 2026] [security2:error] [pid 302018:tid 302163] [client 154.192.233.199:58827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OkIAs9lPxxVAErz3_1wAAAJI"]
[Tue Jul 21 07:48:48.974519 2026] [security2:error] [pid 302018:tid 302203] [client 20.220.225.223:24249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/min.php"] [unique_id "al9OkIAs9lPxxVAErz3_2gAAALo"]
[Tue Jul 21 07:48:49.077219 2026] [security2:error] [pid 302018:tid 302215] [client 20.151.10.161:63362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/ms-edit.php"] [unique_id "al9OkYAs9lPxxVAErz3_2wAAAMY"]
[Tue Jul 21 07:48:49.198091 2026] [security2:error] [pid 296703:tid 296794] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OkSn25uliftkV1n4j0wAAQlo"]
[Tue Jul 21 07:48:49.198250 2026] [security2:error] [pid 296703:tid 296899] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OkSn25uliftkV1n4j0wAAQlo"]
[Tue Jul 21 07:48:49.254380 2026] [security2:error] [pid 296703:tid 296941] [client 193.36.225.72:52927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OkSn25uliftkV1n4j1QAAAGw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:49.267134 2026] [security2:error] [pid 302018:tid 302217] [client 20.151.10.161:19421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/users.php"] [unique_id "al9OkYAs9lPxxVAErz3_3wAAAMg"]
[Tue Jul 21 07:48:49.286061 2026] [security2:error] [pid 302018:tid 302179] [client 202.143.127.214:49559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OkYAs9lPxxVAErz3_4AAAAKI"]
[Tue Jul 21 07:48:49.286193 2026] [security2:error] [pid 302018:tid 302179] [client 202.143.127.214:49559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OkYAs9lPxxVAErz3_4AAAAKI"]
[Tue Jul 21 07:48:49.331873 2026] [security2:error] [pid 302018:tid 302198] [client 4.204.201.85:57741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9OkYAs9lPxxVAErz3_4QAAALU"]
[Tue Jul 21 07:48:49.384892 2026] [security2:error] [pid 302018:tid 302194] [client 117.251.86.144:60672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OkYAs9lPxxVAErz3_4gAAALE"]
[Tue Jul 21 07:48:49.385024 2026] [security2:error] [pid 302018:tid 302194] [client 117.251.86.144:60672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OkYAs9lPxxVAErz3_4gAAALE"]
[Tue Jul 21 07:48:49.825261 2026] [security2:error] [pid 296703:tid 296836] [client 20.151.10.161:19303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/177.php"] [unique_id "al9OkSn25uliftkV1n4j2wAAAAM"]
[Tue Jul 21 07:48:49.893486 2026] [core:error] [pid 296703:tid 296815] [remote 52.167.144.206:52553] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:48:49.893506 2026] [core:error] [pid 296703:tid 296815] [remote 52.167.144.206:52553] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:48:50.007559 2026] [security2:error] [pid 302018:tid 302196] [client 74.7.244.48:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albuquerqueeharo.com"] [uri "/index.php"] [unique_id "al9OkYAs9lPxxVAErz3_7wAAALM"]
[Tue Jul 21 07:48:50.008377 2026] [security2:error] [pid 302018:tid 302209] [client 74.7.244.48:55772] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albuquerqueeharo.com"] [uri "/robots.txt"] [unique_id "al9OkYAs9lPxxVAErz3_6wAAwIU"]
[Tue Jul 21 07:48:50.019473 2026] [security2:error] [pid 302018:tid 302240] [client 182.8.255.181:17666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OkoAs9lPxxVAErz3_8gAAAN8"]
[Tue Jul 21 07:48:50.019565 2026] [security2:error] [pid 302018:tid 302240] [client 182.8.255.181:17666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OkoAs9lPxxVAErz3_8gAAAN8"]
[Tue Jul 21 07:48:50.242849 2026] [security2:error] [pid 302018:tid 302215] [client 20.151.10.161:63484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/222.php"] [unique_id "al9OkoAs9lPxxVAErz3_9gAAAMY"]
[Tue Jul 21 07:48:50.389992 2026] [security2:error] [pid 302018:tid 302264] [client 20.151.10.161:19346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/config.php"] [unique_id "al9OkoAs9lPxxVAErz0AAAAAAPc"]
[Tue Jul 21 07:48:50.403014 2026] [core:error] [pid 296703:tid 296707] [remote 185.242.3.90:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:48:50.403030 2026] [core:error] [pid 296703:tid 296707] [remote 185.242.3.90:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:48:50.403290 2026] [security2:error] [pid 296703:tid 296902] [client 4.204.201.85:51287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/media.php"] [unique_id "al9Okin25uliftkV1n4j5AAAAEU"]
[Tue Jul 21 07:48:50.480617 2026] [security2:error] [pid 302018:tid 302187] [client 139.167.225.182:56851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OkoAs9lPxxVAErz0ABgAAAKo"]
[Tue Jul 21 07:48:50.482476 2026] [security2:error] [pid 302018:tid 302187] [client 139.167.225.182:56851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OkoAs9lPxxVAErz0ABgAAAKo"]
[Tue Jul 21 07:48:50.513092 2026] [security2:error] [pid 302018:tid 302091] [remote 185.242.3.90:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.dralulmabhering.com.br"] [uri "/"] [unique_id "al9OkoAs9lPxxVAErz0ACAABAUY"]
[Tue Jul 21 07:48:50.516782 2026] [core:error] [pid 302018:tid 311332] [remote 185.242.3.90:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:48:50.516805 2026] [core:error] [pid 302018:tid 311332] [remote 185.242.3.90:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:48:50.579489 2026] [security2:error] [pid 302018:tid 302231] [client 20.220.225.223:24195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/echkm.php"] [unique_id "al9OkoAs9lPxxVAErz0AEgAAANY"]
[Tue Jul 21 07:48:50.656797 2026] [security2:error] [pid 302018:tid 302086] [remote 198.244.240.10:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.naturofarma.com.br"] [uri "/robots.txt"] [unique_id "al9OkoAs9lPxxVAErz0AGgAA40E"]
[Tue Jul 21 07:48:50.657041 2026] [security2:error] [pid 302018:tid 302244] [client 198.244.240.10:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.naturofarma.com.br"] [uri "/robots.txt"] [unique_id "al9OkoAs9lPxxVAErz0AGgAA40E"]
[Tue Jul 21 07:48:50.862579 2026] [security2:error] [pid 302018:tid 302240] [client 20.151.10.161:19411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/gettest.php"] [unique_id "al9OkoAs9lPxxVAErz0AKQAAAN8"]
[Tue Jul 21 07:48:50.873001 2026] [security2:error] [pid 302018:tid 302190] [client 173.24.185.52:56245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OkoAs9lPxxVAErz0AKgAAAK0"]
[Tue Jul 21 07:48:50.873105 2026] [security2:error] [pid 302018:tid 302190] [client 173.24.185.52:56245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OkoAs9lPxxVAErz0AKgAAAK0"]
[Tue Jul 21 07:48:51.003559 2026] [security2:error] [pid 296703:tid 296897] [client 103.86.117.203:57137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Okyn25uliftkV1n4j9wAAAEA"]
[Tue Jul 21 07:48:51.003708 2026] [security2:error] [pid 296703:tid 296897] [client 103.86.117.203:57137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Okyn25uliftkV1n4j9wAAAEA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:48:51.351527 2026] [security2:error] [pid 296703:tid 296925] [client 103.29.114.44:63830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Okyn25uliftkV1n4j-gAAAFw"]
[Tue Jul 21 07:48:51.351636 2026] [security2:error] [pid 296703:tid 296925] [client 103.29.114.44:63830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Okyn25uliftkV1n4j-gAAAFw"]
[Tue Jul 21 07:48:51.363532 2026] [security2:error] [pid 302018:tid 302092] [remote 185.242.3.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dralulmabhering.com.br"] [uri "/wp-admin/install.php"] [unique_id "al9Ok4As9lPxxVAErz0AMgAA4kc"]
[Tue Jul 21 07:48:51.422271 2026] [security2:error] [pid 302018:tid 302261] [client 4.204.201.85:51271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/images.php"] [unique_id "al9Ok4As9lPxxVAErz0ANAAAAPQ"]
[Tue Jul 21 07:48:51.562206 2026] [security2:error] [pid 302018:tid 302186] [client 20.151.10.161:64190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/cgi-bin/index.php"] [unique_id "al9Ok4As9lPxxVAErz0AOQAAAKk"]
[Tue Jul 21 07:48:51.563940 2026] [security2:error] [pid 302018:tid 302090] [remote 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp-login.php"] [unique_id "al9Ok4As9lPxxVAErz0AOAAAwkU"]
[Tue Jul 21 07:48:51.641449 2026] [security2:error] [pid 302018:tid 302164] [client 178.153.91.96:26619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ok4As9lPxxVAErz0AOgAAAJM"]
[Tue Jul 21 07:48:51.641551 2026] [security2:error] [pid 302018:tid 302164] [client 178.153.91.96:26619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ok4As9lPxxVAErz0AOgAAAJM"]
[Tue Jul 21 07:48:51.765971 2026] [security2:error] [pid 302018:tid 302190] [client 20.151.10.161:19268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/min.php"] [unique_id "al9Ok4As9lPxxVAErz0APAAAAK0"]
[Tue Jul 21 07:48:51.852734 2026] [security2:error] [pid 302018:tid 302180] [client 122.179.91.63:2058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Ok4As9lPxxVAErz0AQAAAAKM"]
[Tue Jul 21 07:48:51.852853 2026] [security2:error] [pid 302018:tid 302180] [client 122.179.91.63:2058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Ok4As9lPxxVAErz0AQAAAAKM"]
[Tue Jul 21 07:48:51.899483 2026] [security2:error] [pid 296703:tid 296733] [remote 185.242.3.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dralulmabhering.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9Okyn25uliftkV1n4kAQAARh0"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:48:52.192118 2026] [security2:error] [pid 302018:tid 302153] [client 4.204.201.85:57763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/gecko.php"] [unique_id "al9OlIAs9lPxxVAErz0ASgAAAIg"]
[Tue Jul 21 07:48:52.219039 2026] [security2:error] [pid 302018:tid 302268] [client 41.68.90.219:57728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OlIAs9lPxxVAErz0ATAAAAPs"]
[Tue Jul 21 07:48:52.220131 2026] [security2:error] [pid 302018:tid 302268] [client 41.68.90.219:57728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OlIAs9lPxxVAErz0ATAAAAPs"]
[Tue Jul 21 07:48:52.247599 2026] [security2:error] [pid 302018:tid 302227] [client 20.151.10.161:44025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9OlIAs9lPxxVAErz0ATQAAANI"]
[Tue Jul 21 07:48:52.262457 2026] [security2:error] [pid 296703:tid 296810] [remote 54.39.210.224:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.naturofarma.com.br"] [uri "/"] [unique_id "al9OlCn25uliftkV1n4kCQAAYWo"]
[Tue Jul 21 07:48:52.262642 2026] [security2:error] [pid 296703:tid 296930] [client 54.39.210.224:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.naturofarma.com.br"] [uri "/"] [unique_id "al9OlCn25uliftkV1n4kCQAAYWo"]
[Tue Jul 21 07:48:52.432975 2026] [security2:error] [pid 302018:tid 302259] [client 193.36.225.105:57921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OkoAs9lPxxVAErz3_9wAAAPI"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:48:52.443536 2026] [security2:error] [pid 296703:tid 296736] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OlCn25uliftkV1n4kDAAAdSA"]
[Tue Jul 21 07:48:52.443722 2026] [security2:error] [pid 296703:tid 296950] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OlCn25uliftkV1n4kDAAAdSA"]
[Tue Jul 21 07:48:52.702282 2026] [security2:error] [pid 302018:tid 302254] [client 20.220.225.223:24247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/mac.php"] [unique_id "al9OlIAs9lPxxVAErz0AVwAAAO0"]
[Tue Jul 21 07:48:52.794273 2026] [security2:error] [pid 296703:tid 296877] [client 20.151.10.161:19214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/edorxrr.php"] [unique_id "al9OlCn25uliftkV1n4kEwAAACw"]
[Tue Jul 21 07:48:52.873077 2026] [security2:error] [pid 296703:tid 296924] [client 4.204.201.85:57826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/82.php"] [unique_id "al9OlCn25uliftkV1n4kFgAAAFs"]
[Tue Jul 21 07:48:52.951521 2026] [security2:error] [pid 302018:tid 302187] [client 74.249.245.134:64418] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "andrelageorthobolics.com.br"] [uri "/1.php"] [unique_id "al9OlIAs9lPxxVAErz0AXAAAAKo"]
[Tue Jul 21 07:48:52.951658 2026] [security2:error] [pid 302018:tid 302187] [client 74.249.245.134:64418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/1.php"] [unique_id "al9OlIAs9lPxxVAErz0AXAAAAKo"]
[Tue Jul 21 07:48:53.078701 2026] [security2:error] [pid 296703:tid 296842] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9OlCn25uliftkV1n4kGwAACUg"]
[Tue Jul 21 07:48:53.308344 2026] [security2:error] [pid 302018:tid 302075] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OlYAs9lPxxVAErz0AYAAA-TY"]
[Tue Jul 21 07:48:53.308482 2026] [security2:error] [pid 302018:tid 302266] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OlYAs9lPxxVAErz0AYAAA-TY"]
[Tue Jul 21 07:48:53.313509 2026] [security2:error] [pid 302018:tid 302260] [client 74.7.230.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cevicheria.com.br.bomexito.com.br"] [uri "/index.php"] [unique_id "al9OlYAs9lPxxVAErz0AXwAAAPM"]
[Tue Jul 21 07:48:53.314404 2026] [security2:error] [pid 302018:tid 302217] [client 74.7.230.63:55902] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cevicheria.com.br.bomexito.com.br"] [uri "/robots.txt"] [unique_id "al9OlYAs9lPxxVAErz0AXgAAyE8"]
[Tue Jul 21 07:48:53.492831 2026] [security2:error] [pid 296703:tid 296946] [client 4.204.201.85:57774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/admin.php"] [unique_id "al9OlSn25uliftkV1n4kKgAAAHE"]
[Tue Jul 21 07:48:53.603720 2026] [security2:error] [pid 302018:tid 302268] [client 20.220.225.223:24274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/samll.php"] [unique_id "al9OlYAs9lPxxVAErz0AYgAAAPs"]
[Tue Jul 21 07:48:53.634469 2026] [security2:error] [pid 296703:tid 296914] [client 20.151.10.161:19299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/hur.php"] [unique_id "al9OlSn25uliftkV1n4kLgAAAFE"]
[Tue Jul 21 07:48:53.727463 2026] [security2:error] [pid 302018:tid 302162] [client 193.36.225.70:52171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OlYAs9lPxxVAErz0AYQAAAJE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:53.766289 2026] [security2:error] [pid 302018:tid 302261] [client 20.151.10.161:43905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/2P.php"] [unique_id "al9OlYAs9lPxxVAErz0AZgAAAPQ"]
[Tue Jul 21 07:48:53.902244 2026] [security2:error] [pid 296703:tid 296841] [client 117.217.38.194:51758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OlSn25uliftkV1n4kMgAAAAg"]
[Tue Jul 21 07:48:53.902427 2026] [security2:error] [pid 296703:tid 296841] [client 117.217.38.194:51758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OlSn25uliftkV1n4kMgAAAAg"]
[Tue Jul 21 07:48:53.940470 2026] [security2:error] [pid 302018:tid 302242] [client 152.59.154.239:55041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OlYAs9lPxxVAErz0AagAAAOE"]
[Tue Jul 21 07:48:53.940578 2026] [security2:error] [pid 302018:tid 302242] [client 152.59.154.239:55041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OlYAs9lPxxVAErz0AagAAAOE"]
[Tue Jul 21 07:48:54.116735 2026] [security2:error] [pid 302018:tid 302228] [client 106.215.181.8:29049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OloAs9lPxxVAErz0AawAAANM"]
[Tue Jul 21 07:48:54.116887 2026] [security2:error] [pid 302018:tid 302228] [client 106.215.181.8:29049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OloAs9lPxxVAErz0AawAAANM"]
[Tue Jul 21 07:48:54.122296 2026] [security2:error] [pid 296703:tid 296793] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Olin25uliftkV1n4kOgAAa1k"]
[Tue Jul 21 07:48:54.122487 2026] [security2:error] [pid 296703:tid 296940] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Olin25uliftkV1n4kOgAAa1k"]
[Tue Jul 21 07:48:54.307568 2026] [security2:error] [pid 302018:tid 302203] [client 4.204.201.85:57776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/adminner.php"] [unique_id "al9OloAs9lPxxVAErz0AbQAAALo"]
[Tue Jul 21 07:48:54.471527 2026] [security2:error] [pid 296703:tid 296856] [client 20.151.10.161:62887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/BDKR28WP.php"] [unique_id "al9Olin25uliftkV1n4kPgAAABc"]
[Tue Jul 21 07:48:54.479078 2026] [security2:error] [pid 302018:tid 302267] [client 20.220.225.223:24276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/abcd.php"] [unique_id "al9OloAs9lPxxVAErz0AcAAAAPo"]
[Tue Jul 21 07:48:54.537667 2026] [security2:error] [pid 302018:tid 302180] [client 20.151.10.161:19334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/zoro.php"] [unique_id "al9OloAs9lPxxVAErz0AcwAAAKM"]
[Tue Jul 21 07:48:54.558214 2026] [security2:error] [pid 302018:tid 302141] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OloAs9lPxxVAErz0AdAAAk3g"]
[Tue Jul 21 07:48:54.558366 2026] [security2:error] [pid 302018:tid 302164] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OloAs9lPxxVAErz0AdAAAk3g"]
[Tue Jul 21 07:48:54.599195 2026] [security2:error] [pid 302018:tid 302258] [client 122.162.144.145:9840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OloAs9lPxxVAErz0AdgAAAPE"]
[Tue Jul 21 07:48:54.599327 2026] [security2:error] [pid 302018:tid 302258] [client 122.162.144.145:9840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OloAs9lPxxVAErz0AdgAAAPE"]
[Tue Jul 21 07:48:54.759069 2026] [security2:error] [pid 302018:tid 302178] [client 4.204.201.85:57771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/admin.php"] [unique_id "al9OloAs9lPxxVAErz0AegAAAKE"]
[Tue Jul 21 07:48:54.979245 2026] [fcgid:warn] [pid 302018:tid 302233] (70014)End of file found: [client 66.132.195.92:17944] mod_fcgid: can't get data from http client
[Tue Jul 21 07:48:55.250309 2026] [security2:error] [pid 296703:tid 296862] [client 20.220.225.223:24205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/xyn.php"] [unique_id "al9Olyn25uliftkV1n4kSQAAAB0"]
[Tue Jul 21 07:48:55.283708 2026] [security2:error] [pid 302018:tid 302268] [client 173.252.95.41:58642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Ol4As9lPxxVAErz0AfwAAAPs"]
[Tue Jul 21 07:48:55.291131 2026] [security2:error] [pid 302018:tid 302208] [client 4.204.201.85:57735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/k.php"] [unique_id "al9Ol4As9lPxxVAErz0AggAAAL8"]
[Tue Jul 21 07:48:55.599114 2026] [access_compat:error] [pid 302018:tid 302230] [client 162.241.63.68:52116] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:48:55.651574 2026] [security2:error] [pid 302018:tid 302144] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Ol4As9lPxxVAErz0AiAAA-Hs"]
[Tue Jul 21 07:48:55.651733 2026] [security2:error] [pid 302018:tid 302265] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Ol4As9lPxxVAErz0AiAAA-Hs"]
[Tue Jul 21 07:48:55.761799 2026] [security2:error] [pid 302018:tid 302178] [client 20.151.10.161:19310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/coffexium.php"] [unique_id "al9Ol4As9lPxxVAErz0AiwAAAKE"]
[Tue Jul 21 07:48:55.762171 2026] [security2:error] [pid 296703:tid 296917] [client 74.249.245.134:64247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/chosen.php"] [unique_id "al9Olyn25uliftkV1n4kUgAAAFQ"]
[Tue Jul 21 07:48:55.973609 2026] [security2:error] [pid 302018:tid 302242] [client 122.164.127.47:59367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Ol4As9lPxxVAErz0AkAAAAOE"]
[Tue Jul 21 07:48:55.973748 2026] [security2:error] [pid 302018:tid 302242] [client 122.164.127.47:59367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Ol4As9lPxxVAErz0AkAAAAOE"]
[Tue Jul 21 07:48:55.984617 2026] [security2:error] [pid 296703:tid 296849] [client 103.166.103.129:59834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Olyn25uliftkV1n4kWAAAABA"]
[Tue Jul 21 07:48:55.984765 2026] [security2:error] [pid 296703:tid 296849] [client 103.166.103.129:59834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Olyn25uliftkV1n4kWAAAABA"]
[Tue Jul 21 07:48:56.198010 2026] [security2:error] [pid 302018:tid 302196] [client 4.204.201.85:51299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/blurbs.php"] [unique_id "al9OmIAs9lPxxVAErz0AlAAAALM"]
[Tue Jul 21 07:48:56.273997 2026] [security2:error] [pid 302018:tid 302189] [client 20.151.10.161:19368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/app.php"] [unique_id "al9OmIAs9lPxxVAErz0AlgAAAKw"]
[Tue Jul 21 07:48:56.671393 2026] [security2:error] [pid 302018:tid 302254] [client 20.220.225.223:24264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/byp8.php"] [unique_id "al9OmIAs9lPxxVAErz0AngAAAO0"]
[Tue Jul 21 07:48:56.681603 2026] [security2:error] [pid 296703:tid 296870] [client 20.151.10.161:63368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/raw.php"] [unique_id "al9OmCn25uliftkV1n4kbQAAACU"]
[Tue Jul 21 07:48:56.766299 2026] [security2:error] [pid 296703:tid 296874] [client 4.204.201.85:51278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/bajah.php"] [unique_id "al9OmCn25uliftkV1n4kbwAAACk"]
[Tue Jul 21 07:48:57.091786 2026] [security2:error] [pid 302018:tid 302229] [client 4.204.201.85:51274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/a.php"] [unique_id "al9OmYAs9lPxxVAErz0ApAAAANQ"]
[Tue Jul 21 07:48:57.109878 2026] [security2:error] [pid 302018:tid 302184] [client 20.151.10.161:43916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/.well-known/about.php"] [unique_id "al9OmYAs9lPxxVAErz0ApQAAAKc"]
[Tue Jul 21 07:48:57.185683 2026] [security2:error] [pid 302018:tid 302196] [client 20.151.10.161:19281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/core.php"] [unique_id "al9OmYAs9lPxxVAErz0AqQAAALM"]
[Tue Jul 21 07:48:57.196961 2026] [security2:error] [pid 296703:tid 296946] [client 193.36.225.10:54573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OmSn25uliftkV1n4kdgAAAHE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:48:57.459007 2026] [security2:error] [pid 302018:tid 302194] [client 223.236.153.128:7270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OmYAs9lPxxVAErz0AsQAAALE"]
[Tue Jul 21 07:48:57.461699 2026] [security2:error] [pid 302018:tid 302194] [client 223.236.153.128:7270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OmYAs9lPxxVAErz0AsQAAALE"]
[Tue Jul 21 07:48:57.484035 2026] [security2:error] [pid 302018:tid 302059] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OmYAs9lPxxVAErz0AsgABBCY"]
[Tue Jul 21 07:48:57.484280 2026] [security2:error] [pid 302018:tid 302277] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OmYAs9lPxxVAErz0AsgABBCY"]
[Tue Jul 21 07:48:57.588412 2026] [security2:error] [pid 302018:tid 302265] [client 20.220.225.223:24193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/user.php"] [unique_id "al9OmYAs9lPxxVAErz0AswAAAPg"]
[Tue Jul 21 07:48:57.607242 2026] [security2:error] [pid 302018:tid 302215] [client 4.204.201.85:57775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/edit.php"] [unique_id "al9OmYAs9lPxxVAErz0AtQAAAMY"]
[Tue Jul 21 07:48:57.918693 2026] [security2:error] [pid 302018:tid 302137] [remote 156.59.198.135:12370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carrosselbuique.com.br"] [uri "/wp-content/uploads/2026/02/Conteudos-para-estudo-av-1-I-bimestre.pdf"] [unique_id "al9OmYAs9lPxxVAErz0AvgAA83Q"]
[Tue Jul 21 07:48:57.924927 2026] [security2:error] [pid 302018:tid 302181] [client 20.151.10.161:63466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/abcd.php"] [unique_id "al9OmYAs9lPxxVAErz0AvwAAAKQ"]
[Tue Jul 21 07:48:57.964596 2026] [security2:error] [pid 302018:tid 302209] [client 20.151.10.161:19312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/main.php"] [unique_id "al9OmYAs9lPxxVAErz0AwQAAAMA"]
[Tue Jul 21 07:48:58.032558 2026] [security2:error] [pid 296703:tid 296815] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Omin25uliftkV1n4kgwAAPG8"]
[Tue Jul 21 07:48:58.032691 2026] [security2:error] [pid 296703:tid 296893] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Omin25uliftkV1n4kgwAAPG8"]
[Tue Jul 21 07:48:58.063632 2026] [core:error] [pid 296703:tid 296781] [remote 40.77.167.28:44190] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:48:58.063650 2026] [core:error] [pid 296703:tid 296781] [remote 40.77.167.28:44190] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:48:58.140339 2026] [security2:error] [pid 302018:tid 302184] [client 4.204.201.85:57819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/hosty.php"] [unique_id "al9OmoAs9lPxxVAErz0AwwAAAKc"]
[Tue Jul 21 07:48:58.292585 2026] [security2:error] [pid 302018:tid 302211] [client 20.151.10.161:19270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/init.php"] [unique_id "al9OmoAs9lPxxVAErz0AxQAAAMI"]
[Tue Jul 21 07:48:58.331316 2026] [http2:warn] [pid 302018:tid 302202] [client 69.63.184.30:51652] h2_stream(302018-911-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:48:58.424688 2026] [http2:warn] [pid 302018:tid 302226] [client 69.63.184.8:51364] h2_stream(302018-913-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:48:58.472880 2026] [security2:error] [pid 302018:tid 302265] [client 20.151.10.161:43927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9OmoAs9lPxxVAErz0AygAAAPg"]
[Tue Jul 21 07:48:58.527806 2026] [security2:error] [pid 302018:tid 302215] [client 20.220.225.223:24199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/ops.php"] [unique_id "al9OmoAs9lPxxVAErz0AzQAAAMY"]
[Tue Jul 21 07:48:58.621254 2026] [http2:warn] [pid 296703:tid 296851] [client 69.171.230.47:50132] h2_stream(296703-979-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:48:58.625950 2026] [security2:error] [pid 302018:tid 302218] [client 20.151.10.161:19384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/prekel.php"] [unique_id "al9OmoAs9lPxxVAErz0AzwAAAMk"]
[Tue Jul 21 07:48:58.651671 2026] [http2:warn] [pid 302018:tid 302216] [client 69.63.184.33:58860] h2_stream(302018-912-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:48:58.662677 2026] [http2:warn] [pid 302018:tid 302199] [client 173.252.87.10:37718] h2_stream(302018-914-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:48:58.795667 2026] [security2:error] [pid 302018:tid 302264] [client 20.151.10.161:63451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/a1.php"] [unique_id "al9OmoAs9lPxxVAErz0A0QAAAPc"]
[Tue Jul 21 07:48:58.817016 2026] [security2:error] [pid 296703:tid 296928] [client 4.204.201.85:57816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/k.php"] [unique_id "al9Omin25uliftkV1n4kjwAAAF8"]
[Tue Jul 21 07:48:58.818398 2026] [security2:error] [pid 296703:tid 296926] [client 20.220.225.223:24223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/term.php"] [unique_id "al9Omin25uliftkV1n4kkAAAAF0"]
[Tue Jul 21 07:48:58.856677 2026] [http2:warn] [pid 302018:tid 302273] [client 69.171.249.115:54970] h2_stream(302018-915-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:48:58.914477 2026] [security2:error] [pid 302018:tid 302181] [client 20.151.10.161:19351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/0.php"] [unique_id "al9OmoAs9lPxxVAErz0A1AAAAKQ"]
[Tue Jul 21 07:48:58.962456 2026] [http2:warn] [pid 302018:tid 302175] [client 69.63.184.114:47988] h2_stream(302018-917-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:48:59.136590 2026] [security2:error] [pid 302018:tid 302227] [client 122.186.204.214:59706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Om4As9lPxxVAErz0A2AAAANI"]
[Tue Jul 21 07:48:59.136717 2026] [security2:error] [pid 302018:tid 302227] [client 122.186.204.214:59706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Om4As9lPxxVAErz0A2AAAANI"]
[Tue Jul 21 07:48:59.229261 2026] [security2:error] [pid 302018:tid 302271] [client 4.204.201.85:57751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/aaa.php"] [unique_id "al9Om4As9lPxxVAErz0A2wAAAP4"]
[Tue Jul 21 07:48:59.234664 2026] [security2:error] [pid 302018:tid 302153] [client 117.247.80.59:32072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Om4As9lPxxVAErz0A3AAAAIg"]
[Tue Jul 21 07:48:59.234757 2026] [security2:error] [pid 302018:tid 302153] [client 117.247.80.59:32072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Om4As9lPxxVAErz0A3AAAAIg"]
[Tue Jul 21 07:48:59.288846 2026] [security2:error] [pid 302018:tid 302179] [client 20.151.10.161:19285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/BDKR28.php"] [unique_id "al9Om4As9lPxxVAErz0A3wAAAKI"]
[Tue Jul 21 07:48:59.303965 2026] [security2:error] [pid 302018:tid 302189] [client 20.220.225.223:25413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/ah25.php"] [unique_id "al9Om4As9lPxxVAErz0A4AAAAKw"]
[Tue Jul 21 07:48:59.334548 2026] [security2:error] [pid 302018:tid 302244] [client 74.249.245.134:64399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/css.php"] [unique_id "al9Om4As9lPxxVAErz0A4QAAAOM"]
[Tue Jul 21 07:48:59.346559 2026] [security2:error] [pid 302018:tid 302253] [client 74.7.230.36:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "celsohideofukuda1781706464289.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9Om4As9lPxxVAErz0A4gAA7B0"]
[Tue Jul 21 07:48:59.376164 2026] [security2:error] [pid 296703:tid 296858] [client 37.140.223.158:48303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Omin25uliftkV1n4kigAAABk"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:48:59.467894 2026] [http2:warn] [pid 302018:tid 302193] [client 173.252.87.43:52870] h2_stream(302018-919-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:48:59.502107 2026] [security2:error] [pid 296703:tid 296841] [client 154.192.233.199:60216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Omyn25uliftkV1n4kmgAAAAg"]
[Tue Jul 21 07:48:59.502231 2026] [security2:error] [pid 296703:tid 296841] [client 154.192.233.199:60216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Omyn25uliftkV1n4kmgAAAAg"]
[Tue Jul 21 07:48:59.606056 2026] [security2:error] [pid 302018:tid 302277] [client 20.151.10.161:64231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9Om4As9lPxxVAErz0A5gAAAQQ"]
[Tue Jul 21 07:48:59.606990 2026] [security2:error] [pid 302018:tid 302234] [client 175.156.77.210:56696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.77.156.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hiveel.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OmoAs9lPxxVAErz0AzgAAANk"]
[Tue Jul 21 07:48:59.607198 2026] [security2:error] [pid 302018:tid 302234] [client 175.156.77.210:56696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hiveel.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OmoAs9lPxxVAErz0AzgAAANk"]
[Tue Jul 21 07:48:59.665191 2026] [http2:warn] [pid 302018:tid 302237] [client 173.252.95.30:33348] h2_stream(302018-922-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:48:59.734406 2026] [security2:error] [pid 296703:tid 296813] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Omyn25uliftkV1n4knAAAOm0"]
[Tue Jul 21 07:48:59.734572 2026] [security2:error] [pid 296703:tid 296891] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Omyn25uliftkV1n4knAAAOm0"]
[Tue Jul 21 07:48:59.737875 2026] [security2:error] [pid 296703:tid 296870] [client 62.102.148.187:33578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Omyn25uliftkV1n4knQAAACU"]
[Tue Jul 21 07:48:59.737968 2026] [security2:error] [pid 296703:tid 296870] [client 62.102.148.187:33578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Omyn25uliftkV1n4knQAAACU"]
[Tue Jul 21 07:48:59.747635 2026] [http2:warn] [pid 302018:tid 302174] [client 173.252.87.6:38066] h2_stream(302018-921-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:48:59.786796 2026] [security2:error] [pid 302018:tid 302204] [client 20.151.10.161:19305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/f35.update.php"] [unique_id "al9Om4As9lPxxVAErz0A6QAAALs"]
[Tue Jul 21 07:48:59.794056 2026] [security2:error] [pid 302018:tid 302178] [client 4.204.201.85:57788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/file5.php"] [unique_id "al9Om4As9lPxxVAErz0A6gAAAKE"]
[Tue Jul 21 07:48:59.819435 2026] [security2:error] [pid 302018:tid 302203] [client 20.220.225.223:24201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/8.php"] [unique_id "al9Om4As9lPxxVAErz0A6wAAALo"]
[Tue Jul 21 07:48:59.928979 2026] [http2:warn] [pid 302018:tid 302246] [client 173.252.95.1:53018] h2_stream(302018-924-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:48:59.932382 2026] [http2:warn] [pid 302018:tid 302169] [client 69.63.184.18:44548] h2_stream(302018-923-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:48:59.993636 2026] [security2:error] [pid 296703:tid 296930] [client 20.151.10.161:44030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/bob.php"] [unique_id "al9Omyn25uliftkV1n4koAAAAGE"]
[Tue Jul 21 07:49:00.083715 2026] [core:error] [pid 302018:tid 302118] [remote 52.167.144.206:64024] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:49:00.083740 2026] [core:error] [pid 302018:tid 302118] [remote 52.167.144.206:64024] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:49:00.085740 2026] [security2:error] [pid 302018:tid 302179] [client 20.151.10.161:19416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/f900.php"] [unique_id "al9OnIAs9lPxxVAErz0A8QAAAKI"]
[Tue Jul 21 07:49:00.144954 2026] [security2:error] [pid 302018:tid 302152] [client 117.251.86.144:56882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OnIAs9lPxxVAErz0A8gAAAIc"]
[Tue Jul 21 07:49:00.145089 2026] [security2:error] [pid 302018:tid 302152] [client 117.251.86.144:56882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OnIAs9lPxxVAErz0A8gAAAIc"]
[Tue Jul 21 07:49:00.244253 2026] [security2:error] [pid 296703:tid 296822] [remote 68.178.160.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/wp-login.php"] [unique_id "al9OnCn25uliftkV1n4kpAAABnY"]
[Tue Jul 21 07:49:00.300964 2026] [http2:warn] [pid 302018:tid 302155] [client 69.63.184.27:54038] h2_stream(302018-928-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:00.321680 2026] [security2:error] [pid 302018:tid 302158] [client 4.204.201.85:51326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/222.php"] [unique_id "al9OnIAs9lPxxVAErz0A9QAAAI0"]
[Tue Jul 21 07:49:00.357088 2026] [security2:error] [pid 296703:tid 296733] [remote 159.65.81.207:58744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9OnCn25uliftkV1n4kqQAAVR0"]
[Tue Jul 21 07:49:00.376859 2026] [security2:error] [pid 302018:tid 302250] [client 59.96.220.140:60331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OnIAs9lPxxVAErz0A9wAAAOk"]
[Tue Jul 21 07:49:00.376958 2026] [security2:error] [pid 302018:tid 302250] [client 59.96.220.140:60331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OnIAs9lPxxVAErz0A9wAAAOk"]
[Tue Jul 21 07:49:00.416722 2026] [security2:error] [pid 302018:tid 302190] [client 20.151.10.161:19227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/xmrl.php"] [unique_id "al9OnIAs9lPxxVAErz0A-AAAAK0"]
[Tue Jul 21 07:49:00.424588 2026] [security2:error] [pid 302018:tid 302164] [client 182.8.255.181:10130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OnIAs9lPxxVAErz0A-QAAAJM"]
[Tue Jul 21 07:49:00.424695 2026] [security2:error] [pid 302018:tid 302164] [client 182.8.255.181:10130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OnIAs9lPxxVAErz0A-QAAAJM"]
[Tue Jul 21 07:49:00.606810 2026] [security2:error] [pid 302018:tid 302263] [client 202.143.127.214:50035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OnIAs9lPxxVAErz0BAwAAAPY"]
[Tue Jul 21 07:49:00.607422 2026] [security2:error] [pid 302018:tid 302263] [client 202.143.127.214:50035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OnIAs9lPxxVAErz0BAwAAAPY"]
[Tue Jul 21 07:49:00.612008 2026] [http2:warn] [pid 296703:tid 296894] [client 69.63.184.24:46704] h2_stream(296703-985-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:00.742707 2026] [security2:error] [pid 302018:tid 302223] [client 20.151.10.161:19314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/memberfuns.php"] [unique_id "al9OnIAs9lPxxVAErz0BBAAAAM4"]
[Tue Jul 21 07:49:00.830366 2026] [security2:error] [pid 302018:tid 302166] [client 194.99.104.35:37518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9OnIAs9lPxxVAErz0BBQAAAJU"]
[Tue Jul 21 07:49:00.830465 2026] [security2:error] [pid 302018:tid 302166] [client 194.99.104.35:37518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9OnIAs9lPxxVAErz0BBQAAAJU"]
[Tue Jul 21 07:49:00.906099 2026] [http2:warn] [pid 302018:tid 302251] [client 69.171.230.8:34302] h2_stream(302018-930-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:00.966642 2026] [security2:error] [pid 302018:tid 302134] [remote 192.241.143.148:33280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9OnIAs9lPxxVAErz0BCAAAkXE"]
[Tue Jul 21 07:49:00.977030 2026] [security2:error] [pid 302018:tid 302264] [client 20.220.225.223:24216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/red.php"] [unique_id "al9OnIAs9lPxxVAErz0BCQAAAPc"]
[Tue Jul 21 07:49:00.989307 2026] [security2:error] [pid 296703:tid 296880] [client 139.167.225.182:57500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OnCn25uliftkV1n4ktQAAAC8"]
[Tue Jul 21 07:49:00.989388 2026] [security2:error] [pid 296703:tid 296880] [client 139.167.225.182:57500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OnCn25uliftkV1n4ktQAAAC8"]
[Tue Jul 21 07:49:01.022242 2026] [http2:warn] [pid 302018:tid 302195] [client 173.252.87.42:52686] h2_stream(302018-931-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:01.044480 2026] [security2:error] [pid 302018:tid 302275] [client 20.151.10.161:19364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/ms.php"] [unique_id "al9OnYAs9lPxxVAErz0BDgAAAQI"]
[Tue Jul 21 07:49:01.114812 2026] [security2:error] [pid 302018:tid 302183] [client 4.204.201.85:51266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/test.php"] [unique_id "al9OnYAs9lPxxVAErz0BEgAAAKY"]
[Tue Jul 21 07:49:01.181728 2026] [http2:warn] [pid 296703:tid 296906] [client 173.252.95.38:56958] h2_stream(296703-989-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:01.292481 2026] [http2:warn] [pid 296703:tid 296935] [client 173.252.87.112:42550] h2_stream(296703-987-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:01.368044 2026] [security2:error] [pid 302018:tid 302164] [client 20.151.10.161:19379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/zz.php"] [unique_id "al9OnYAs9lPxxVAErz0BFgAAAJM"]
[Tue Jul 21 07:49:01.435564 2026] [http2:warn] [pid 302018:tid 302188] [client 173.252.95.4:58774] h2_stream(302018-934-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:01.454547 2026] [http2:warn] [pid 296703:tid 296885] [client 173.252.82.53:40148] h2_stream(296703-991-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:01.493120 2026] [security2:error] [pid 296703:tid 296920] [client 103.86.117.203:57685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OnSn25uliftkV1n4kvQAAAFc"]
[Tue Jul 21 07:49:01.493249 2026] [security2:error] [pid 296703:tid 296920] [client 103.86.117.203:57685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OnSn25uliftkV1n4kvQAAAFc"]
[Tue Jul 21 07:49:01.537614 2026] [security2:error] [pid 296703:tid 296899] [client 136.144.33.215:59055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OnSn25uliftkV1n4kvgAAAEI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:49:01.552687 2026] [security2:error] [pid 296703:tid 296849] [client 173.24.185.52:56702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OnSn25uliftkV1n4kvwAAABA"]
[Tue Jul 21 07:49:01.552806 2026] [security2:error] [pid 296703:tid 296849] [client 173.24.185.52:56702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OnSn25uliftkV1n4kvwAAABA"]
[Tue Jul 21 07:49:01.712971 2026] [security2:error] [pid 296703:tid 296933] [client 4.204.201.85:57824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/aaa.php"] [unique_id "al9OnSn25uliftkV1n4kwgAAAGQ"]
[Tue Jul 21 07:49:01.788659 2026] [http2:warn] [pid 296703:tid 296937] [client 173.252.83.6:50724] h2_stream(296703-992-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:01.808454 2026] [security2:error] [pid 302018:tid 302216] [client 20.151.10.161:19293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/for.php"] [unique_id "al9OnYAs9lPxxVAErz0BHQAAAMc"]
[Tue Jul 21 07:49:01.960205 2026] [security2:error] [pid 296703:tid 296912] [client 20.151.10.161:63364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9OnSn25uliftkV1n4kyAAAAE8"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:49:02.071028 2026] [security2:error] [pid 296703:tid 296918] [client 20.220.225.223:24198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/fffm.php"] [unique_id "al9Onin25uliftkV1n4kzAAAAFU"]
[Tue Jul 21 07:49:02.073518 2026] [security2:error] [pid 296703:tid 296928] [client 178.153.91.96:27273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Onin25uliftkV1n4kzQAAAF8"]
[Tue Jul 21 07:49:02.073618 2026] [security2:error] [pid 296703:tid 296928] [client 178.153.91.96:27273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Onin25uliftkV1n4kzQAAAF8"]
[Tue Jul 21 07:49:02.113067 2026] [security2:error] [pid 302018:tid 302264] [client 20.151.10.161:19205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/yup.php"] [unique_id "al9OnoAs9lPxxVAErz0BHwAAAPc"]
[Tue Jul 21 07:49:02.248852 2026] [rewrite:warn] [pid 302018:tid 302099] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:02.256143 2026] [autoindex:error] [pid 296703:tid 296862] [client 186.202.163.107:0] AH01276: Cannot serve directory /home4/conte946/produtosnapromo.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:02.267643 2026] [security2:error] [pid 302018:tid 302259] [client 103.29.114.44:17723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OnoAs9lPxxVAErz0BIwAAAPI"]
[Tue Jul 21 07:49:02.267763 2026] [security2:error] [pid 302018:tid 302259] [client 103.29.114.44:17723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OnoAs9lPxxVAErz0BIwAAAPI"]
[Tue Jul 21 07:49:02.279937 2026] [security2:error] [pid 302018:tid 302260] [client 4.204.201.85:57778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/11.php"] [unique_id "al9OnoAs9lPxxVAErz0BJAAAAPM"]
[Tue Jul 21 07:49:02.327425 2026] [rewrite:warn] [pid 302018:tid 302092] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:02.331937 2026] [http2:warn] [pid 302018:tid 302154] [client 173.252.87.9:52724] h2_stream(302018-936-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:02.360646 2026] [rewrite:warn] [pid 302018:tid 302090] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:02.361359 2026] [rewrite:warn] [pid 302018:tid 302119] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:02.367564 2026] [rewrite:warn] [pid 302018:tid 302111] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:02.399065 2026] [rewrite:warn] [pid 302018:tid 302087] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:02.414656 2026] [http2:warn] [pid 302018:tid 302206] [client 69.171.230.48:55748] h2_stream(302018-937-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:49:02.460014 2026] [core:error] [pid 302018:tid 302103] [remote 40.77.167.152:62075] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:49:02.460037 2026] [core:error] [pid 302018:tid 302103] [remote 40.77.167.152:62075] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:49:02.462936 2026] [rewrite:warn] [pid 302018:tid 302061] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:02.497295 2026] [security2:error] [pid 302018:tid 302189] [client 20.151.10.161:19390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/wpxml.php"] [unique_id "al9OnoAs9lPxxVAErz0BMAAAAKw"]
[Tue Jul 21 07:49:02.580767 2026] [security2:error] [pid 296703:tid 296853] [client 20.151.10.161:43976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/crgio.php"] [unique_id "al9Onin25uliftkV1n4k3AAAABQ"]
[Tue Jul 21 07:49:02.584344 2026] [core:error] [pid 302018:tid 302124] [remote 40.77.167.152:62075] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:49:02.584368 2026] [core:error] [pid 302018:tid 302124] [remote 40.77.167.152:62075] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:49:02.709142 2026] [security2:error] [pid 296703:tid 296892] [client 122.179.91.63:23816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Onin25uliftkV1n4k4gAAADs"]
[Tue Jul 21 07:49:02.709277 2026] [security2:error] [pid 296703:tid 296892] [client 122.179.91.63:23816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Onin25uliftkV1n4k4gAAADs"]
[Tue Jul 21 07:49:02.757158 2026] [http2:warn] [pid 296703:tid 296888] [client 173.252.83.17:38130] h2_stream(296703-996-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:02.768323 2026] [security2:error] [pid 296703:tid 296947] [client 4.204.201.85:57832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/mac.php"] [unique_id "al9Onin25uliftkV1n4k5QAAAHI"]
[Tue Jul 21 07:49:02.895622 2026] [security2:error] [pid 302018:tid 302274] [client 20.151.10.161:19292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/fffm.php"] [unique_id "al9OnoAs9lPxxVAErz0BPQAAAQE"]
[Tue Jul 21 07:49:02.937985 2026] [security2:error] [pid 296703:tid 296952] [client 172.245.102.33:53023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Onin25uliftkV1n4k5gAAAHc"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:49:03.010778 2026] [http2:warn] [pid 302018:tid 302151] [client 173.252.82.53:40158] h2_stream(302018-943-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:03.117388 2026] [security2:error] [pid 302018:tid 302075] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9On4As9lPxxVAErz0BQwAAuzY"]
[Tue Jul 21 07:49:03.117551 2026] [security2:error] [pid 302018:tid 302204] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9On4As9lPxxVAErz0BQwAAuzY"]
[Tue Jul 21 07:49:03.129166 2026] [security2:error] [pid 302018:tid 302196] [client 4.204.201.85:57732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/chosen.php"] [unique_id "al9On4As9lPxxVAErz0BRAAAALM"]
[Tue Jul 21 07:49:03.198956 2026] [security2:error] [pid 302018:tid 302229] [client 20.220.225.223:24284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/ftde.php"] [unique_id "al9On4As9lPxxVAErz0BRwAAANQ"]
[Tue Jul 21 07:49:03.232538 2026] [security2:error] [pid 302018:tid 302211] [client 20.151.10.161:19410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/gecko.php"] [unique_id "al9On4As9lPxxVAErz0BSAAAAMI"]
[Tue Jul 21 07:49:03.295980 2026] [http2:warn] [pid 302018:tid 302257] [client 173.252.83.14:38904] h2_stream(302018-942-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:03.336171 2026] [rewrite:warn] [pid 302018:tid 302100] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:03.574365 2026] [security2:error] [pid 302018:tid 302271] [client 41.68.90.219:58154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9On4As9lPxxVAErz0BTQAAAP4"]
[Tue Jul 21 07:49:03.575561 2026] [security2:error] [pid 302018:tid 302271] [client 41.68.90.219:58154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9On4As9lPxxVAErz0BTQAAAP4"]
[Tue Jul 21 07:49:03.596827 2026] [security2:error] [pid 302018:tid 302226] [client 20.151.10.161:19331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/a1.php"] [unique_id "al9On4As9lPxxVAErz0BTwAAANE"]
[Tue Jul 21 07:49:03.652174 2026] [security2:error] [pid 296703:tid 296904] [client 128.127.105.184:46386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Onyn25uliftkV1n4k8wAAAEc"]
[Tue Jul 21 07:49:03.652272 2026] [security2:error] [pid 296703:tid 296904] [client 128.127.105.184:46386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Onyn25uliftkV1n4k8wAAAEc"]
[Tue Jul 21 07:49:03.693222 2026] [security2:error] [pid 302018:tid 302263] [client 4.204.201.85:57737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/cream1.php"] [unique_id "al9On4As9lPxxVAErz0BUwAAAPY"]
[Tue Jul 21 07:49:03.694087 2026] [security2:error] [pid 302018:tid 302186] [client 20.151.10.161:64223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wp-content/BypassBest.php"] [unique_id "al9On4As9lPxxVAErz0BVAAAAKk"]
[Tue Jul 21 07:49:03.840038 2026] [http2:warn] [pid 302018:tid 302219] [client 173.252.87.25:63496] h2_stream(302018-946-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:03.908229 2026] [security2:error] [pid 296703:tid 296836] [client 20.151.10.161:19323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/k2.php"] [unique_id "al9Onyn25uliftkV1n4k-wAAAAM"]
[Tue Jul 21 07:49:03.913604 2026] [security2:error] [pid 302018:tid 302264] [client 20.151.10.161:44011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/pucci.php"] [unique_id "al9On4As9lPxxVAErz0BVgAAAPc"]
[Tue Jul 21 07:49:03.922982 2026] [security2:error] [pid 296703:tid 296856] [client 20.220.225.223:24242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/yup.php"] [unique_id "al9Onyn25uliftkV1n4k_AAAABc"]
[Tue Jul 21 07:49:03.950530 2026] [security2:error] [pid 296703:tid 296759] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Onyn25uliftkV1n4k_QAAKTc"]
[Tue Jul 21 07:49:03.950658 2026] [security2:error] [pid 296703:tid 296874] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Onyn25uliftkV1n4k_QAAKTc"]
[Tue Jul 21 07:49:04.082439 2026] [security2:error] [pid 296703:tid 296927] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Onyn25uliftkV1n4k_gAAXhI"]
[Tue Jul 21 07:49:04.202946 2026] [security2:error] [pid 302018:tid 302209] [client 20.151.10.161:19423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/82.php"] [unique_id "al9OoIAs9lPxxVAErz0BWgAAAMA"]
[Tue Jul 21 07:49:04.251073 2026] [autoindex:error] [pid 302018:tid 302183] [client 4.204.201.85:57854] AH01276: Cannot serve directory /home4/solar369/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:04.263145 2026] [http2:warn] [pid 296703:tid 296911] [client 173.252.83.11:40358] h2_stream(296703-999-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:04.320455 2026] [autoindex:error] [pid 302018:tid 302196] [client 54.209.8.187:0] AH01276: Cannot serve directory /home2/eloisa13/tourcampos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:04.379372 2026] [security2:error] [pid 296703:tid 296928] [client 117.217.38.194:52257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OoCn25uliftkV1n4lBQAAAF8"]
[Tue Jul 21 07:49:04.379519 2026] [security2:error] [pid 296703:tid 296928] [client 117.217.38.194:52257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OoCn25uliftkV1n4lBQAAAF8"]
[Tue Jul 21 07:49:04.449478 2026] [autoindex:error] [pid 296703:tid 296958] [client 54.209.8.187:0] AH01276: Cannot serve directory /home2/eloisa13/tourcampos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:04.523940 2026] [rewrite:warn] [pid 302018:tid 302052] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.536468 2026] [security2:error] [pid 302018:tid 302172] [client 20.151.10.161:19319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/config.json.php"] [unique_id "al9OoIAs9lPxxVAErz0BZwAAAJs"]
[Tue Jul 21 07:49:04.554368 2026] [autoindex:error] [pid 302018:tid 302263] [client 4.204.201.85:57854] AH01276: Cannot serve directory /home4/solar369/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:04.599051 2026] [rewrite:warn] [pid 302018:tid 302138] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.633763 2026] [rewrite:warn] [pid 302018:tid 302123] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.635902 2026] [rewrite:warn] [pid 302018:tid 302147] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.637077 2026] [rewrite:warn] [pid 302018:tid 302129] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.637542 2026] [rewrite:warn] [pid 302018:tid 302125] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.684591 2026] [security2:error] [pid 296703:tid 296947] [client 20.220.225.223:24286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/jj.php"] [unique_id "al9OoCn25uliftkV1n4lCgAAAHI"]
[Tue Jul 21 07:49:04.687611 2026] [rewrite:warn] [pid 302018:tid 302036] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.691546 2026] [security2:error] [pid 302018:tid 302266] [client 4.204.201.85:57854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/dr.php"] [unique_id "al9OoIAs9lPxxVAErz0BdgAAAPk"]
[Tue Jul 21 07:49:04.691663 2026] [rewrite:warn] [pid 302018:tid 302109] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.692226 2026] [rewrite:warn] [pid 302018:tid 302098] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.692409 2026] [rewrite:warn] [pid 302018:tid 302059] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.692410 2026] [rewrite:warn] [pid 302018:tid 302120] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.708306 2026] [rewrite:warn] [pid 302018:tid 311335] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.726114 2026] [rewrite:warn] [pid 302018:tid 302056] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.726114 2026] [rewrite:warn] [pid 302018:tid 302121] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.728050 2026] [rewrite:warn] [pid 302018:tid 302048] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:04.747723 2026] [security2:error] [pid 296703:tid 296732] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OoCn25uliftkV1n4lDAAAJBw"]
[Tue Jul 21 07:49:04.747855 2026] [security2:error] [pid 296703:tid 296869] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OoCn25uliftkV1n4lDAAAJBw"]
[Tue Jul 21 07:49:04.811753 2026] [security2:error] [pid 296703:tid 296905] [client 106.215.181.8:30425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OoCn25uliftkV1n4lDQAAAEg"]
[Tue Jul 21 07:49:04.811872 2026] [security2:error] [pid 296703:tid 296905] [client 106.215.181.8:30425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OoCn25uliftkV1n4lDQAAAEg"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:49:04.859300 2026] [security2:error] [pid 302018:tid 302179] [client 20.151.10.161:19308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clickedbought.com"] [uri "/fpwch.php"] [unique_id "al9OoIAs9lPxxVAErz0BgAAAAKI"]
[Tue Jul 21 07:49:04.950639 2026] [security2:error] [pid 302018:tid 302035] [remote 82.112.255.5:39100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.255.112.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9OoIAs9lPxxVAErz0BgwAA4Q4"]
[Tue Jul 21 07:49:05.161376 2026] [security2:error] [pid 302018:tid 302192] [client 4.204.201.85:21914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/x.php"] [unique_id "al9OoYAs9lPxxVAErz0BigAAAK8"]
[Tue Jul 21 07:49:05.164792 2026] [security2:error] [pid 302018:tid 302062] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OoYAs9lPxxVAErz0BiwAAvyk"]
[Tue Jul 21 07:49:05.164958 2026] [security2:error] [pid 302018:tid 302208] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OoYAs9lPxxVAErz0BiwAAvyk"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:49:05.326377 2026] [security2:error] [pid 302018:tid 302216] [client 20.151.10.161:43848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-temp.php"] [unique_id "al9OoYAs9lPxxVAErz0BjQAAAMc"]
[Tue Jul 21 07:49:05.333852 2026] [security2:error] [pid 302018:tid 302268] [client 122.162.144.145:32954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OoYAs9lPxxVAErz0BjgAAAPs"]
[Tue Jul 21 07:49:05.333945 2026] [security2:error] [pid 302018:tid 302268] [client 122.162.144.145:32954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OoYAs9lPxxVAErz0BjgAAAPs"]
[Tue Jul 21 07:49:05.489466 2026] [http2:warn] [pid 296703:tid 296886] [client 173.252.87.20:57794] h2_stream(296703-1004-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:05.502990 2026] [security2:error] [pid 302018:tid 302275] [client 4.204.201.85:57747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/155.php"] [unique_id "al9OoYAs9lPxxVAErz0BkAAAAQI"]
[Tue Jul 21 07:49:05.704504 2026] [security2:error] [pid 302018:tid 302153] [client 128.127.105.184:39296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9OoYAs9lPxxVAErz0BlgAAAIg"]
[Tue Jul 21 07:49:05.704573 2026] [security2:error] [pid 302018:tid 302153] [client 128.127.105.184:39296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9OoYAs9lPxxVAErz0BlgAAAIg"]
[Tue Jul 21 07:49:05.835976 2026] [security2:error] [pid 302018:tid 302181] [client 193.36.225.72:36891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OoYAs9lPxxVAErz0BkgAAAKQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:49:05.945391 2026] [security2:error] [pid 296703:tid 296845] [client 4.204.201.85:51282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/ops.php"] [unique_id "al9OoSn25uliftkV1n4lJAAAAAw"]
[Tue Jul 21 07:49:05.971671 2026] [security2:error] [pid 302018:tid 302229] [client 20.220.225.223:24267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/dragonshell.php"] [unique_id "al9OoYAs9lPxxVAErz0BmwAAANQ"]
[Tue Jul 21 07:49:06.083684 2026] [security2:error] [pid 296703:tid 296891] [client 20.226.60.151:61587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wp-css.php"] [unique_id "al9Ooin25uliftkV1n4lKAAAADo"]
[Tue Jul 21 07:49:06.279602 2026] [security2:error] [pid 296703:tid 296772] [remote 207.180.241.245:49624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9Ooin25uliftkV1n4lLQAABUQ"]
[Tue Jul 21 07:49:06.279820 2026] [security2:error] [pid 296703:tid 296838] [client 207.180.241.245:49624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9Ooin25uliftkV1n4lLQAABUQ"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:49:06.390640 2026] [security2:error] [pid 302018:tid 302136] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OooAs9lPxxVAErz0BogAA2XM"]
[Tue Jul 21 07:49:06.390805 2026] [security2:error] [pid 302018:tid 302234] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OooAs9lPxxVAErz0BogAA2XM"]
[Tue Jul 21 07:49:06.398384 2026] [security2:error] [pid 302018:tid 302258] [client 122.164.127.47:59946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OooAs9lPxxVAErz0BowAAAPE"]
[Tue Jul 21 07:49:06.398530 2026] [security2:error] [pid 302018:tid 302258] [client 122.164.127.47:59946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OooAs9lPxxVAErz0BowAAAPE"]
[Tue Jul 21 07:49:06.455158 2026] [security2:error] [pid 302018:tid 302272] [client 74.249.245.134:64447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/php.php"] [unique_id "al9OooAs9lPxxVAErz0BpAAAAP8"]
[Tue Jul 21 07:49:06.518799 2026] [security2:error] [pid 296703:tid 296903] [client 103.166.103.129:60354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Ooin25uliftkV1n4lNAAAAEY"]
[Tue Jul 21 07:49:06.518956 2026] [security2:error] [pid 296703:tid 296903] [client 103.166.103.129:60354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Ooin25uliftkV1n4lNAAAAEY"]
[Tue Jul 21 07:49:06.542718 2026] [security2:error] [pid 296703:tid 296864] [client 20.151.10.161:43857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9Ooin25uliftkV1n4lNQAAAB8"]
[Tue Jul 21 07:49:06.689064 2026] [security2:error] [pid 302018:tid 302180] [client 4.204.201.85:57849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/file31.php"] [unique_id "al9OooAs9lPxxVAErz0BpgAAAKM"]
[Tue Jul 21 07:49:07.027030 2026] [http2:warn] [pid 302018:tid 302212] [client 173.252.87.40:51700] h2_stream(302018-960-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:07.044225 2026] [security2:error] [pid 302018:tid 302215] [client 74.7.241.181:48600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "teste.verbodavidachapeco.com.br"] [uri "/index.php"] [unique_id "al9OooAs9lPxxVAErz0BpQAAxho"]
[Tue Jul 21 07:49:07.143167 2026] [security2:error] [pid 302018:tid 302172] [client 193.36.225.150:25785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OooAs9lPxxVAErz0BrgAAAJs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:49:07.168037 2026] [security2:error] [pid 302018:tid 302190] [client 4.204.201.85:57821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/file6.php"] [unique_id "al9Oo4As9lPxxVAErz0BtgAAAK0"]
[Tue Jul 21 07:49:07.218053 2026] [security2:error] [pid 302018:tid 302236] [client 20.151.10.161:43921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/puc.php"] [unique_id "al9Oo4As9lPxxVAErz0BuAAAANs"]
[Tue Jul 21 07:49:07.564663 2026] [autoindex:error] [pid 296703:tid 296849] [client 4.204.201.85:51285] AH01276: Cannot serve directory /home4/solar369/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:07.633429 2026] [security2:error] [pid 302018:tid 302117] [remote 150.95.80.135:37280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.80.95.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Oo4As9lPxxVAErz0BxwAAuWA"]
[Tue Jul 21 07:49:07.648110 2026] [security2:error] [pid 296703:tid 296846] [client 74.249.245.134:64386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Ooyn25uliftkV1n4lRwAAAA0"]
[Tue Jul 21 07:49:07.818682 2026] [security2:error] [pid 296703:tid 296878] [client 20.151.10.161:43917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/themes.php"] [unique_id "al9Ooyn25uliftkV1n4lSgAAAC0"]
[Tue Jul 21 07:49:07.896880 2026] [security2:error] [pid 296703:tid 296949] [client 4.204.201.85:51285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/adminfuns.php"] [unique_id "al9Ooyn25uliftkV1n4lTgAAAHQ"]
[Tue Jul 21 07:49:08.069692 2026] [security2:error] [pid 296703:tid 296901] [client 223.236.153.128:7049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OpCn25uliftkV1n4lVQAAAEQ"]
[Tue Jul 21 07:49:08.069807 2026] [security2:error] [pid 296703:tid 296901] [client 223.236.153.128:7049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OpCn25uliftkV1n4lVQAAAEQ"]
[Tue Jul 21 07:49:08.226482 2026] [security2:error] [pid 296703:tid 296829] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OpCn25uliftkV1n4lVwAAYH0"]
[Tue Jul 21 07:49:08.226660 2026] [security2:error] [pid 296703:tid 296929] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OpCn25uliftkV1n4lVwAAYH0"]
[Tue Jul 21 07:49:08.261495 2026] [security2:error] [pid 302018:tid 302198] [client 4.204.201.85:57742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/goods.php"] [unique_id "al9OpIAs9lPxxVAErz0BzgAAALU"]
[Tue Jul 21 07:49:08.354421 2026] [security2:error] [pid 302018:tid 302260] [client 20.220.225.223:24263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/wp-mt.php"] [unique_id "al9OpIAs9lPxxVAErz0B0gAAAPM"]
[Tue Jul 21 07:49:08.428546 2026] [security2:error] [pid 302018:tid 302213] [client 20.151.10.161:43933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/dx.php"] [unique_id "al9OpIAs9lPxxVAErz0B1gAAAMQ"]
[Tue Jul 21 07:49:08.838384 2026] [security2:error] [pid 302018:tid 302242] [client 4.204.201.85:57800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/100.php"] [unique_id "al9OpIAs9lPxxVAErz0B3AAAAOE"]
[Tue Jul 21 07:49:08.942113 2026] [security2:error] [pid 296703:tid 296704] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OpCn25uliftkV1n4lYAAAbwA"]
[Tue Jul 21 07:49:08.942286 2026] [security2:error] [pid 296703:tid 296944] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OpCn25uliftkV1n4lYAAAbwA"]
[Tue Jul 21 07:49:09.061036 2026] [http2:warn] [pid 302018:tid 302241] [client 173.252.83.11:40370] h2_stream(302018-966-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:09.176933 2026] [security2:error] [pid 302018:tid 302265] [client 20.220.225.223:24220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/ww.php"] [unique_id "al9OpYAs9lPxxVAErz0B5QAAAPg"]
[Tue Jul 21 07:49:09.418086 2026] [security2:error] [pid 302018:tid 302218] [client 4.204.201.85:57810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/about.php"] [unique_id "al9OpYAs9lPxxVAErz0B6AAAAMk"]
[Tue Jul 21 07:49:09.540766 2026] [security2:error] [pid 302018:tid 302156] [client 136.144.33.54:27929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OpYAs9lPxxVAErz0B6gAAAIs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:49:09.669689 2026] [http2:warn] [pid 302018:tid 302165] [client 173.252.95.37:45904] h2_stream(302018-933-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:09.675705 2026] [http2:warn] [pid 296703:tid 296879] [client 69.63.189.36:43504] h2_stream(296703-990-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:09.806643 2026] [security2:error] [pid 302018:tid 302162] [client 4.204.201.85:57825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/about.php"] [unique_id "al9OpYAs9lPxxVAErz0B7AAAAJE"]
[Tue Jul 21 07:49:09.951293 2026] [security2:error] [pid 302018:tid 302266] [client 122.186.204.214:60239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OpYAs9lPxxVAErz0B8AAAAPk"]
[Tue Jul 21 07:49:09.951403 2026] [security2:error] [pid 302018:tid 302266] [client 122.186.204.214:60239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OpYAs9lPxxVAErz0B8AAAAPk"]
[Tue Jul 21 07:49:09.964265 2026] [security2:error] [pid 302018:tid 302026] [remote 20.75.217.64:9888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9OpYAs9lPxxVAErz0B8QAAzwU"]
[Tue Jul 21 07:49:10.023253 2026] [security2:error] [pid 302018:tid 302234] [client 37.140.223.190:55407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OpYAs9lPxxVAErz0B7QAAANk"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:49:10.100613 2026] [http2:warn] [pid 302018:tid 302171] [client 69.171.249.7:61836] h2_stream(302018-969-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:10.133250 2026] [security2:error] [pid 296703:tid 296843] [client 154.192.233.199:59968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Opin25uliftkV1n4ldQAAAAo"]
[Tue Jul 21 07:49:10.133376 2026] [security2:error] [pid 296703:tid 296843] [client 154.192.233.199:59968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Opin25uliftkV1n4ldQAAAAo"]
[Tue Jul 21 07:49:10.199097 2026] [security2:error] [pid 296703:tid 296848] [client 4.204.201.85:57759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/admin.php"] [unique_id "al9Opin25uliftkV1n4ldgAAAA8"]
[Tue Jul 21 07:49:10.213106 2026] [security2:error] [pid 296703:tid 296947] [client 117.247.80.59:32086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Opin25uliftkV1n4ldwAAAHI"]
[Tue Jul 21 07:49:10.213213 2026] [security2:error] [pid 296703:tid 296947] [client 117.247.80.59:32086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Opin25uliftkV1n4ldwAAAHI"]
[Tue Jul 21 07:49:10.452928 2026] [security2:error] [pid 302018:tid 302174] [client 20.220.225.223:24288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/cron.php"] [unique_id "al9OpoAs9lPxxVAErz0CBgAAAJ0"]
[Tue Jul 21 07:49:10.456198 2026] [security2:error] [pid 302018:tid 302209] [client 45.3.54.215:61141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9OpoAs9lPxxVAErz0CBQAAAMA"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:49:10.513893 2026] [security2:error] [pid 302018:tid 302162] [client 20.226.60.151:53971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/ho.php"] [unique_id "al9OpoAs9lPxxVAErz0CBwAAAJE"]
[Tue Jul 21 07:49:10.875595 2026] [security2:error] [pid 302018:tid 302180] [client 182.8.255.181:17726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OpoAs9lPxxVAErz0CCwAAAKM"]
[Tue Jul 21 07:49:10.875769 2026] [security2:error] [pid 302018:tid 302180] [client 182.8.255.181:17726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OpoAs9lPxxVAErz0CCwAAAKM"]
[Tue Jul 21 07:49:10.880834 2026] [security2:error] [pid 302018:tid 302208] [client 20.151.10.161:43958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/p.php"] [unique_id "al9OpoAs9lPxxVAErz0CDAAAAL8"]
[Tue Jul 21 07:49:10.880960 2026] [security2:error] [pid 302018:tid 302265] [client 4.204.201.85:57814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/admin.php"] [unique_id "al9OpoAs9lPxxVAErz0CDQAAAPg"]
[Tue Jul 21 07:49:10.885581 2026] [security2:error] [pid 296703:tid 296849] [client 117.251.86.144:37460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Opin25uliftkV1n4lhQAAABA"]
[Tue Jul 21 07:49:10.885671 2026] [security2:error] [pid 296703:tid 296849] [client 117.251.86.144:37460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9Opin25uliftkV1n4lhQAAABA"]
[Tue Jul 21 07:49:11.660695 2026] [security2:error] [pid 296703:tid 296845] [client 139.167.225.182:58152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Opyn25uliftkV1n4llQAAAAw"]
[Tue Jul 21 07:49:11.660799 2026] [security2:error] [pid 296703:tid 296845] [client 139.167.225.182:58152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Opyn25uliftkV1n4llQAAAAw"]
[Tue Jul 21 07:49:11.728860 2026] [security2:error] [pid 296703:tid 296838] [client 202.143.127.214:50497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Opyn25uliftkV1n4llwAAAAU"]
[Tue Jul 21 07:49:11.729023 2026] [security2:error] [pid 296703:tid 296838] [client 202.143.127.214:50497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Opyn25uliftkV1n4llwAAAAU"]
[Tue Jul 21 07:49:11.862757 2026] [security2:error] [pid 302018:tid 302186] [client 4.204.201.85:57834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/themes.php"] [unique_id "al9Op4As9lPxxVAErz0CHQAAAKk"]
[Tue Jul 21 07:49:11.975110 2026] [security2:error] [pid 296703:tid 296864] [client 103.86.117.203:58225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Opyn25uliftkV1n4lmwAAAB8"]
[Tue Jul 21 07:49:11.975240 2026] [security2:error] [pid 296703:tid 296864] [client 103.86.117.203:58225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Opyn25uliftkV1n4lmwAAAB8"]
[Tue Jul 21 07:49:12.081694 2026] [security2:error] [pid 302018:tid 302272] [client 20.220.225.223:24253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/xxx.php"] [unique_id "al9OqIAs9lPxxVAErz0CIgAAAP8"]
[Tue Jul 21 07:49:12.152038 2026] [security2:error] [pid 302018:tid 302158] [client 173.24.185.52:57173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OqIAs9lPxxVAErz0CIwAAAI0"]
[Tue Jul 21 07:49:12.152175 2026] [security2:error] [pid 302018:tid 302158] [client 173.24.185.52:57173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OqIAs9lPxxVAErz0CIwAAAI0"]
[Tue Jul 21 07:49:12.219972 2026] [http2:warn] [pid 302018:tid 302256] [client 173.252.69.19:54490] h2_stream(302018-945-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:49:12.381117 2026] [http2:warn] [pid 302018:tid 302232] [client 173.252.95.33:50346] h2_stream(302018-982-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:12.438810 2026] [security2:error] [pid 302018:tid 302189] [client 59.96.220.140:60825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OqIAs9lPxxVAErz0CKQAAAKw"]
[Tue Jul 21 07:49:12.438970 2026] [security2:error] [pid 302018:tid 302189] [client 59.96.220.140:60825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OqIAs9lPxxVAErz0CKQAAAKw"]
[Tue Jul 21 07:49:12.454385 2026] [security2:error] [pid 302018:tid 302193] [client 20.151.10.161:43843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/bthil.php"] [unique_id "al9OqIAs9lPxxVAErz0CKgAAALA"]
[Tue Jul 21 07:49:12.606899 2026] [security2:error] [pid 296703:tid 296954] [client 103.29.114.44:3580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OqCn25uliftkV1n4lqgAAAHk"]
[Tue Jul 21 07:49:12.606988 2026] [security2:error] [pid 296703:tid 296954] [client 103.29.114.44:3580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OqCn25uliftkV1n4lqgAAAHk"]
[Tue Jul 21 07:49:12.712029 2026] [security2:error] [pid 302018:tid 302216] [client 178.153.91.96:27939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OqIAs9lPxxVAErz0CMAAAAMc"]
[Tue Jul 21 07:49:12.712156 2026] [security2:error] [pid 302018:tid 302216] [client 178.153.91.96:27939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OqIAs9lPxxVAErz0CMAAAAMc"]
[Tue Jul 21 07:49:12.811057 2026] [security2:error] [pid 296703:tid 296898] [client 62.102.148.187:39220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OqCn25uliftkV1n4lrQAAAEE"]
[Tue Jul 21 07:49:12.811144 2026] [security2:error] [pid 296703:tid 296898] [client 62.102.148.187:39220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OqCn25uliftkV1n4lrQAAAEE"]
[Tue Jul 21 07:49:12.851290 2026] [autoindex:error] [pid 296703:tid 296941] [client 4.204.201.85:57845] AH01276: Cannot serve directory /home4/solar369/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:12.876807 2026] [security2:error] [pid 302018:tid 302204] [client 20.220.225.223:24229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/hunter.php"] [unique_id "al9OqIAs9lPxxVAErz0CNgAAALs"]
[Tue Jul 21 07:49:13.103416 2026] [security2:error] [pid 302018:tid 302258] [client 20.226.60.151:61546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/xy.php"] [unique_id "al9OqYAs9lPxxVAErz0CPQAAAPE"]
[Tue Jul 21 07:49:13.269947 2026] [security2:error] [pid 302018:tid 302266] [client 20.220.225.223:24218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/we.php"] [unique_id "al9OqYAs9lPxxVAErz0CQwAAAPk"]
[Tue Jul 21 07:49:13.271371 2026] [security2:error] [pid 302018:tid 302172] [client 74.7.175.132:40532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "gradiente.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9OqYAs9lPxxVAErz0CQgAAm1I"]
[Tue Jul 21 07:49:13.312687 2026] [security2:error] [pid 302018:tid 302180] [client 173.252.95.57:52984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9OqYAs9lPxxVAErz0CRQAAAKM"]
[Tue Jul 21 07:49:13.350315 2026] [security2:error] [pid 302018:tid 302236] [client 122.179.91.63:23990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OqYAs9lPxxVAErz0CSAAAANs"]
[Tue Jul 21 07:49:13.350672 2026] [security2:error] [pid 302018:tid 302236] [client 122.179.91.63:23990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OqYAs9lPxxVAErz0CSAAAANs"]
[Tue Jul 21 07:49:13.573049 2026] [security2:error] [pid 302018:tid 302153] [client 20.220.225.223:24254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "claretimoveis.com.br"] [uri "/phpinfo.php1"] [unique_id "al9OqYAs9lPxxVAErz0CSwAAAIg"]
[Tue Jul 21 07:49:13.638914 2026] [security2:error] [pid 302018:tid 302243] [client 74.249.245.134:24785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/aa.php"] [unique_id "al9OqYAs9lPxxVAErz0CTgAAAOI"]
[Tue Jul 21 07:49:13.644594 2026] [security2:error] [pid 302018:tid 302260] [client 74.249.245.134:64092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9OqYAs9lPxxVAErz0CTwAAAPM"]
[Tue Jul 21 07:49:13.675153 2026] [security2:error] [pid 302018:tid 302218] [client 20.151.10.161:43995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/7.php"] [unique_id "al9OqYAs9lPxxVAErz0CUQAAAMk"]
[Tue Jul 21 07:49:13.791668 2026] [security2:error] [pid 296703:tid 296780] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OqSn25uliftkV1n4lwAAAP0w"]
[Tue Jul 21 07:49:13.791827 2026] [security2:error] [pid 296703:tid 296896] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OqSn25uliftkV1n4lwAAAP0w"]
[Tue Jul 21 07:49:13.862338 2026] [security2:error] [pid 302018:tid 302216] [client 128.127.105.184:37936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9OqYAs9lPxxVAErz0CUgAAAMc"]
[Tue Jul 21 07:49:13.862430 2026] [security2:error] [pid 302018:tid 302216] [client 128.127.105.184:37936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9OqYAs9lPxxVAErz0CUgAAAMc"]
[Tue Jul 21 07:49:13.919545 2026] [http2:warn] [pid 296703:tid 296919] [client 173.252.95.58:37408] h2_stream(296703-1052-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:14.235429 2026] [security2:error] [pid 296703:tid 296856] [client 20.151.10.161:44031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/8.php"] [unique_id "al9Oqin25uliftkV1n4lyAAAABc"]
[Tue Jul 21 07:49:14.507735 2026] [security2:error] [pid 296703:tid 296808] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oqin25uliftkV1n4lzAAAZ2g"]
[Tue Jul 21 07:49:14.507936 2026] [security2:error] [pid 296703:tid 296936] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oqin25uliftkV1n4lzAAAZ2g"]
[Tue Jul 21 07:49:14.593608 2026] [security2:error] [pid 296703:tid 296864] [client 4.204.201.85:57845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Oqin25uliftkV1n4lzwAAAB8"]
[Tue Jul 21 07:49:14.681730 2026] [security2:error] [pid 302018:tid 302246] [client 41.68.90.219:58604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OqoAs9lPxxVAErz0CZAAAAOU"]
[Tue Jul 21 07:49:14.682713 2026] [security2:error] [pid 302018:tid 302246] [client 41.68.90.219:58604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OqoAs9lPxxVAErz0CZAAAAOU"]
[Tue Jul 21 07:49:14.837878 2026] [security2:error] [pid 296703:tid 296939] [client 117.217.38.194:52748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oqin25uliftkV1n4l0gAAAGo"]
[Tue Jul 21 07:49:14.838028 2026] [security2:error] [pid 296703:tid 296939] [client 117.217.38.194:52748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oqin25uliftkV1n4l0gAAAGo"]
[Tue Jul 21 07:49:15.043889 2026] [security2:error] [pid 302018:tid 302258] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9OqoAs9lPxxVAErz0CZwAA8Yg"]
[Tue Jul 21 07:49:15.181139 2026] [security2:error] [pid 302018:tid 302196] [client 4.204.201.85:51249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Oq4As9lPxxVAErz0CawAAALM"]
[Tue Jul 21 07:49:15.244453 2026] [security2:error] [pid 302018:tid 302161] [client 152.59.154.239:55997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oq4As9lPxxVAErz0CbQAAAJA"]
[Tue Jul 21 07:49:15.244602 2026] [security2:error] [pid 302018:tid 302161] [client 152.59.154.239:55997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oq4As9lPxxVAErz0CbQAAAJA"]
[Tue Jul 21 07:49:15.286011 2026] [security2:error] [pid 296703:tid 296717] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Oqyn25uliftkV1n4l2gAAcA0"]
[Tue Jul 21 07:49:15.286153 2026] [security2:error] [pid 296703:tid 296945] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Oqyn25uliftkV1n4l2gAAcA0"]
[Tue Jul 21 07:49:15.435574 2026] [security2:error] [pid 302018:tid 302265] [client 20.151.10.161:43925] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.olimposolar.com.br"] [uri "/1.php"] [unique_id "al9Oq4As9lPxxVAErz0CcAAAAPg"]
[Tue Jul 21 07:49:15.435675 2026] [security2:error] [pid 302018:tid 302265] [client 20.151.10.161:43925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/1.php"] [unique_id "al9Oq4As9lPxxVAErz0CcAAAAPg"]
[Tue Jul 21 07:49:15.450077 2026] [security2:error] [pid 302018:tid 302185] [client 106.215.181.8:27007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oq4As9lPxxVAErz0CcQAAAKg"]
[Tue Jul 21 07:49:15.450188 2026] [security2:error] [pid 302018:tid 302185] [client 106.215.181.8:27007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oq4As9lPxxVAErz0CcQAAAKg"]
[Tue Jul 21 07:49:15.541381 2026] [security2:error] [pid 302018:tid 302192] [client 193.36.225.57:26091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OqYAs9lPxxVAErz0CSQAAAK8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:49:15.577476 2026] [security2:error] [pid 296703:tid 296904] [client 4.204.201.85:57739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/wefile.php"] [unique_id "al9Oqyn25uliftkV1n4l4QAAAEc"]
[Tue Jul 21 07:49:15.793855 2026] [security2:error] [pid 302018:tid 302075] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Oq4As9lPxxVAErz0CdwAArDY"]
[Tue Jul 21 07:49:15.793983 2026] [security2:error] [pid 302018:tid 302189] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Oq4As9lPxxVAErz0CdwAArDY"]
[Tue Jul 21 07:49:15.902781 2026] [security2:error] [pid 296703:tid 296874] [client 4.204.201.85:57803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9Oqyn25uliftkV1n4l6gAAACk"]
[Tue Jul 21 07:49:16.170356 2026] [security2:error] [pid 302018:tid 302167] [client 122.162.144.145:23837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OrIAs9lPxxVAErz0CfQAAAJY"]
[Tue Jul 21 07:49:16.172797 2026] [security2:error] [pid 302018:tid 302167] [client 122.162.144.145:23837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OrIAs9lPxxVAErz0CfQAAAJY"]
[Tue Jul 21 07:49:16.242506 2026] [autoindex:error] [pid 296703:tid 296909] [client 4.204.201.85:57813] AH01276: Cannot serve directory /home4/solar369/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:16.425991 2026] [security2:error] [pid 296703:tid 296865] [client 20.151.10.161:44023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/100.php"] [unique_id "al9OrCn25uliftkV1n4l8QAAACA"]
[Tue Jul 21 07:49:16.564421 2026] [autoindex:error] [pid 296703:tid 296903] [client 4.204.201.85:57813] AH01276: Cannot serve directory /home4/solar369/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:16.737235 2026] [security2:error] [pid 296703:tid 296931] [client 4.204.201.85:57813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9OrCn25uliftkV1n4l-AAAAGI"]
[Tue Jul 21 07:49:16.851649 2026] [security2:error] [pid 302018:tid 302263] [client 37.140.223.117:22391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Oq4As9lPxxVAErz0CeAAAAPY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:49:16.911766 2026] [security2:error] [pid 296703:tid 296948] [client 20.151.10.161:43962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/about.php"] [unique_id "al9OrCn25uliftkV1n4l_QAAAHM"]
[Tue Jul 21 07:49:17.072637 2026] [security2:error] [pid 302018:tid 302141] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OrYAs9lPxxVAErz0CiAAAxng"]
[Tue Jul 21 07:49:17.072833 2026] [security2:error] [pid 302018:tid 302215] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OrYAs9lPxxVAErz0CiAAAxng"]
[Tue Jul 21 07:49:17.134407 2026] [security2:error] [pid 302018:tid 302264] [client 20.226.60.151:61569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/loader.php"] [unique_id "al9OrYAs9lPxxVAErz0CiQAAAPc"]
[Tue Jul 21 07:49:17.136167 2026] [security2:error] [pid 302018:tid 302178] [client 122.164.127.47:60520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OrYAs9lPxxVAErz0CigAAAKE"]
[Tue Jul 21 07:49:17.136312 2026] [security2:error] [pid 302018:tid 302178] [client 122.164.127.47:60520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OrYAs9lPxxVAErz0CigAAAKE"]
[Tue Jul 21 07:49:17.244144 2026] [security2:error] [pid 296703:tid 296841] [client 4.204.201.85:51238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/8.php"] [unique_id "al9OrSn25uliftkV1n4mAQAAAAg"]
[Tue Jul 21 07:49:17.275923 2026] [security2:error] [pid 296703:tid 296893] [client 103.166.103.129:28709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OrSn25uliftkV1n4mAgAAADw"]
[Tue Jul 21 07:49:17.276058 2026] [security2:error] [pid 296703:tid 296893] [client 103.166.103.129:28709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OrSn25uliftkV1n4mAgAAADw"]
[Tue Jul 21 07:49:17.459338 2026] [security2:error] [pid 302018:tid 302246] [client 20.151.10.161:43860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/admin.php"] [unique_id "al9OrYAs9lPxxVAErz0CjwAAAOU"]
[Tue Jul 21 07:49:17.666515 2026] [security2:error] [pid 296703:tid 296947] [client 4.204.201.85:57782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9OrSn25uliftkV1n4mCAAAAHI"]
[Tue Jul 21 07:49:17.926068 2026] [security2:error] [pid 302018:tid 302274] [client 20.151.10.161:43946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/edit.php"] [unique_id "al9OrYAs9lPxxVAErz0CkwAAAQE"]
[Tue Jul 21 07:49:18.131341 2026] [security2:error] [pid 296703:tid 296946] [client 4.204.201.85:57755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/f6.php"] [unique_id "al9Orin25uliftkV1n4mEwAAAHE"]
[Tue Jul 21 07:49:18.580400 2026] [security2:error] [pid 302018:tid 302153] [client 4.204.201.85:51279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/inputs.php"] [unique_id "al9OroAs9lPxxVAErz0CnQAAAIg"]
[Tue Jul 21 07:49:18.624779 2026] [security2:error] [pid 302018:tid 302258] [client 223.236.153.128:5912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OroAs9lPxxVAErz0CngAAAPE"]
[Tue Jul 21 07:49:18.627577 2026] [security2:error] [pid 302018:tid 302258] [client 223.236.153.128:5912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OroAs9lPxxVAErz0CngAAAPE"]
[Tue Jul 21 07:49:18.671036 2026] [http2:warn] [pid 302018:tid 302245] [client 173.252.95.57:48072] h2_stream(302018-995-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:19.033580 2026] [security2:error] [pid 302018:tid 302264] [client 193.36.225.104:22211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OroAs9lPxxVAErz0CowAAAPc"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:49:19.088257 2026] [security2:error] [pid 302018:tid 302265] [client 4.204.201.85:51313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/inputs.php"] [unique_id "al9Or4As9lPxxVAErz0CpQAAAPg"]
[Tue Jul 21 07:49:19.143978 2026] [security2:error] [pid 302018:tid 302052] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Or4As9lPxxVAErz0CpwAA2B8"]
[Tue Jul 21 07:49:19.144133 2026] [security2:error] [pid 302018:tid 302233] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Or4As9lPxxVAErz0CpwAA2B8"]
[Tue Jul 21 07:49:19.682616 2026] [security2:error] [pid 302018:tid 302225] [client 4.204.201.85:57743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Or4As9lPxxVAErz0CrgAAANA"]
[Tue Jul 21 07:49:19.804303 2026] [security2:error] [pid 296703:tid 296853] [client 20.226.60.151:61506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/spadex.php"] [unique_id "al9Oryn25uliftkV1n4mKwAAABQ"]
[Tue Jul 21 07:49:19.965107 2026] [security2:error] [pid 296703:tid 296733] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oryn25uliftkV1n4mMAAAKh0"]
[Tue Jul 21 07:49:19.965250 2026] [security2:error] [pid 296703:tid 296875] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oryn25uliftkV1n4mMAAAKh0"]
[Tue Jul 21 07:49:20.112715 2026] [security2:error] [pid 296703:tid 296840] [client 20.151.10.161:43964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9OsCn25uliftkV1n4mMgAAAAc"]
[Tue Jul 21 07:49:20.138892 2026] [security2:error] [pid 302018:tid 302204] [client 4.204.201.85:57855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9OsIAs9lPxxVAErz0CtQAAALs"]
[Tue Jul 21 07:49:20.221524 2026] [http2:warn] [pid 296703:tid 296882] [client 173.252.95.39:58314] h2_stream(296703-1064-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:20.472427 2026] [security2:error] [pid 302018:tid 302215] [client 74.7.175.192:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cristinapessanhamary1748551922313.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9OsIAs9lPxxVAErz0CvQAAxns"]
[Tue Jul 21 07:49:20.488710 2026] [security2:error] [pid 302018:tid 302264] [client 4.204.201.85:57730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/wp-blog.php"] [unique_id "al9OsIAs9lPxxVAErz0CvgAAAPc"]
[Tue Jul 21 07:49:20.551170 2026] [security2:error] [pid 302018:tid 302265] [client 20.151.10.161:64188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/simple.php"] [unique_id "al9OsIAs9lPxxVAErz0CwAAAAPg"]
[Tue Jul 21 07:49:20.628297 2026] [security2:error] [pid 296703:tid 296898] [client 20.151.10.161:43913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/f6.php"] [unique_id "al9OsCn25uliftkV1n4mOwAAAEE"]
[Tue Jul 21 07:49:20.678604 2026] [security2:error] [pid 296703:tid 296841] [client 59.96.220.140:61357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OsCn25uliftkV1n4mPQAAAAg"]
[Tue Jul 21 07:49:20.678752 2026] [security2:error] [pid 296703:tid 296841] [client 59.96.220.140:61357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OsCn25uliftkV1n4mPQAAAAg"]
[Tue Jul 21 07:49:20.743840 2026] [security2:error] [pid 296703:tid 296946] [client 184.75.223.211:45448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9OsCn25uliftkV1n4mQAAAAHE"]
[Tue Jul 21 07:49:20.743944 2026] [security2:error] [pid 296703:tid 296946] [client 184.75.223.211:45448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9OsCn25uliftkV1n4mQAAAAHE"]
[Tue Jul 21 07:49:20.745991 2026] [security2:error] [pid 296703:tid 296895] [client 154.192.233.199:58899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OsCn25uliftkV1n4mPwAAAD4"]
[Tue Jul 21 07:49:20.746148 2026] [security2:error] [pid 296703:tid 296895] [client 154.192.233.199:58899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OsCn25uliftkV1n4mPwAAAD4"]
[Tue Jul 21 07:49:20.779244 2026] [security2:error] [pid 296703:tid 296869] [client 122.186.204.214:60780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OsCn25uliftkV1n4mQQAAACQ"]
[Tue Jul 21 07:49:20.779415 2026] [security2:error] [pid 296703:tid 296869] [client 122.186.204.214:60780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OsCn25uliftkV1n4mQQAAACQ"]
[Tue Jul 21 07:49:20.968207 2026] [security2:error] [pid 302018:tid 302195] [client 117.247.80.59:22312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OsIAs9lPxxVAErz0CxgAAALI"]
[Tue Jul 21 07:49:20.968288 2026] [security2:error] [pid 302018:tid 302195] [client 117.247.80.59:22312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OsIAs9lPxxVAErz0CxgAAALI"]
[Tue Jul 21 07:49:21.009624 2026] [autoindex:error] [pid 296703:tid 296857] [client 4.204.201.85:57770] AH01276: Cannot serve directory /home4/solar369/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:21.012294 2026] [security2:error] [pid 302018:tid 302179] [client 194.99.104.35:43330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9OsYAs9lPxxVAErz0CxwAAAKI"]
[Tue Jul 21 07:49:21.012364 2026] [security2:error] [pid 302018:tid 302179] [client 194.99.104.35:43330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9OsYAs9lPxxVAErz0CxwAAAKI"]
[Tue Jul 21 07:49:21.013928 2026] [security2:error] [pid 296703:tid 296851] [client 193.36.225.118:64343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OsCn25uliftkV1n4mQwAAABI"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:49:21.348009 2026] [security2:error] [pid 302018:tid 302184] [client 182.8.255.181:17714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OsYAs9lPxxVAErz0CyQAAAKc"]
[Tue Jul 21 07:49:21.348165 2026] [security2:error] [pid 302018:tid 302184] [client 182.8.255.181:17714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OsYAs9lPxxVAErz0CyQAAAKc"]
[Tue Jul 21 07:49:21.349646 2026] [security2:error] [pid 296703:tid 296927] [client 4.204.201.85:57770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9OsSn25uliftkV1n4mTAAAAF4"]
[Tue Jul 21 07:49:21.502621 2026] [security2:error] [pid 296703:tid 296941] [client 117.251.86.144:36812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.86.251.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OsSn25uliftkV1n4mUQAAAGw"]
[Tue Jul 21 07:49:21.502762 2026] [security2:error] [pid 296703:tid 296941] [client 117.251.86.144:36812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9OsSn25uliftkV1n4mUQAAAGw"]
[Tue Jul 21 07:49:21.882430 2026] [security2:error] [pid 302018:tid 302186] [client 74.249.245.134:65137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/bolt.php"] [unique_id "al9OsYAs9lPxxVAErz0C0QAAAKk"]
[Tue Jul 21 07:49:21.882531 2026] [security2:error] [pid 302018:tid 302165] [client 74.249.245.134:8812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp.php"] [unique_id "al9OsYAs9lPxxVAErz0C0gAAAJQ"]
[Tue Jul 21 07:49:21.914783 2026] [security2:error] [pid 296703:tid 296838] [client 172.245.102.43:45445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.245.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OsSn25uliftkV1n4mVwAAAAU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:49:21.975769 2026] [security2:error] [pid 296703:tid 296936] [client 4.204.201.85:51305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/ms-edit.php"] [unique_id "al9OsSn25uliftkV1n4mWQAAAGc"]
[Tue Jul 21 07:49:22.329714 2026] [security2:error] [pid 302018:tid 302192] [client 20.220.225.223:38679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9OsoAs9lPxxVAErz0C2AAAAK8"]
[Tue Jul 21 07:49:22.332340 2026] [security2:error] [pid 302018:tid 302172] [client 20.151.10.161:43869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/inputs.php"] [unique_id "al9OsoAs9lPxxVAErz0C2QAAAJs"]
[Tue Jul 21 07:49:22.369061 2026] [security2:error] [pid 296703:tid 296924] [client 139.167.225.182:58796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Osin25uliftkV1n4mXgAAAFs"]
[Tue Jul 21 07:49:22.370278 2026] [security2:error] [pid 296703:tid 296924] [client 139.167.225.182:58796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Osin25uliftkV1n4mXgAAAFs"]
[Tue Jul 21 07:49:22.456615 2026] [security2:error] [pid 302018:tid 302209] [client 103.86.117.203:58774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OsoAs9lPxxVAErz0C2gAAAMA"]
[Tue Jul 21 07:49:22.456719 2026] [security2:error] [pid 302018:tid 302209] [client 103.86.117.203:58774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OsoAs9lPxxVAErz0C2gAAAMA"]
[Tue Jul 21 07:49:22.511742 2026] [security2:error] [pid 296703:tid 296767] [remote 147.50.252.213:33296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "digitaclick.com"] [uri "/wp-login.php"] [unique_id "al9Osin25uliftkV1n4mYwAACT8"]
[Tue Jul 21 07:49:22.627155 2026] [security2:error] [pid 302018:tid 302179] [client 20.197.195.24:10742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9OsoAs9lPxxVAErz0C3QAAAKI"]
[Tue Jul 21 07:49:22.653957 2026] [security2:error] [pid 302018:tid 302193] [client 4.204.201.85:51268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9OsoAs9lPxxVAErz0C3gAAALA"]
[Tue Jul 21 07:49:22.684640 2026] [security2:error] [pid 302018:tid 302059] [remote 81.173.115.7:40426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9OsoAs9lPxxVAErz0C4QAA0SY"]
[Tue Jul 21 07:49:22.821629 2026] [security2:error] [pid 302018:tid 302236] [client 173.24.185.52:57639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OsoAs9lPxxVAErz0C4wAAANs"]
[Tue Jul 21 07:49:22.821832 2026] [security2:error] [pid 302018:tid 302236] [client 173.24.185.52:57639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OsoAs9lPxxVAErz0C4wAAANs"]
[Tue Jul 21 07:49:22.986720 2026] [security2:error] [pid 296703:tid 296956] [client 202.143.127.214:50960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Osin25uliftkV1n4mbgAAAHs"]
[Tue Jul 21 07:49:22.986858 2026] [security2:error] [pid 296703:tid 296956] [client 202.143.127.214:50960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Osin25uliftkV1n4mbgAAAHs"]
[Tue Jul 21 07:49:23.048781 2026] [security2:error] [pid 302018:tid 302224] [client 194.99.104.35:43340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Os4As9lPxxVAErz0C5wAAAM8"]
[Tue Jul 21 07:49:23.048897 2026] [security2:error] [pid 302018:tid 302224] [client 194.99.104.35:43340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Os4As9lPxxVAErz0C5wAAAM8"]
[Tue Jul 21 07:49:23.068403 2026] [security2:error] [pid 302018:tid 302180] [client 104.207.57.134:18047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9OsoAs9lPxxVAErz0C5QAAAKM"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:49:23.137866 2026] [security2:error] [pid 302018:tid 302178] [client 185.213.175.37:50866] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "asl.erpcondominios.com.br"] [uri "/"] [unique_id "al9Os4As9lPxxVAErz0C6gAAAKE"]
[Tue Jul 21 07:49:23.252183 2026] [security2:error] [pid 302018:tid 302202] [client 103.29.114.44:60221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Os4As9lPxxVAErz0C7QAAALk"]
[Tue Jul 21 07:49:23.252350 2026] [security2:error] [pid 302018:tid 302202] [client 103.29.114.44:60221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Os4As9lPxxVAErz0C7QAAALk"]
[Tue Jul 21 07:49:23.258139 2026] [security2:error] [pid 296703:tid 296920] [client 20.151.10.161:43895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/av.php"] [unique_id "al9Osyn25uliftkV1n4mcgAAAFc"]
[Tue Jul 21 07:49:23.295744 2026] [security2:error] [pid 302018:tid 302274] [client 178.153.91.96:28625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Os4As9lPxxVAErz0C7wAAAQE"]
[Tue Jul 21 07:49:23.295883 2026] [security2:error] [pid 302018:tid 302274] [client 178.153.91.96:28625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Os4As9lPxxVAErz0C7wAAAQE"]
[Tue Jul 21 07:49:23.446892 2026] [autoindex:error] [pid 302018:tid 302152] [client 4.204.201.85:51304] AH01276: Cannot serve directory /home4/solar369/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:23.662926 2026] [security2:error] [pid 296703:tid 296877] [client 37.140.223.200:61321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Osyn25uliftkV1n4mdgAAACw"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:49:23.752148 2026] [security2:error] [pid 302018:tid 302246] [client 4.204.201.85:51304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Os4As9lPxxVAErz0C9wAAAOU"]
[Tue Jul 21 07:49:23.867528 2026] [security2:error] [pid 302018:tid 302195] [client 20.197.195.24:10735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Os4As9lPxxVAErz0C-QAAALI"]
[Tue Jul 21 07:49:23.924428 2026] [security2:error] [pid 302018:tid 302153] [client 122.179.91.63:3987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Os4As9lPxxVAErz0C-gAAAIg"]
[Tue Jul 21 07:49:23.924574 2026] [security2:error] [pid 302018:tid 302153] [client 122.179.91.63:3987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Os4As9lPxxVAErz0C-gAAAIg"]
[Tue Jul 21 07:49:24.264952 2026] [security2:error] [pid 302018:tid 302243] [client 104.207.46.174:17777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.46.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9OtIAs9lPxxVAErz0C_AAAAOI"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:49:24.305542 2026] [security2:error] [pid 296703:tid 296847] [client 20.151.10.161:63407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/xxx.php"] [unique_id "al9OtCn25uliftkV1n4mfwAAAA4"]
[Tue Jul 21 07:49:24.321890 2026] [autoindex:error] [pid 302018:tid 302183] [client 4.204.201.85:57769] AH01276: Cannot serve directory /home4/solar369/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:24.467450 2026] [security2:error] [pid 296703:tid 296722] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OtCn25uliftkV1n4mhwAAKxI"]
[Tue Jul 21 07:49:24.467685 2026] [security2:error] [pid 296703:tid 296876] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OtCn25uliftkV1n4mhwAAKxI"]
[Tue Jul 21 07:49:24.553738 2026] [security2:error] [pid 302018:tid 302196] [client 20.220.225.223:38696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9OtIAs9lPxxVAErz0DAwAAALM"]
[Tue Jul 21 07:49:24.576415 2026] [security2:error] [pid 296703:tid 296839] [client 20.197.195.24:10632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/media.php"] [unique_id "al9OtCn25uliftkV1n4miQAAAAY"]
[Tue Jul 21 07:49:24.611619 2026] [autoindex:error] [pid 302018:tid 302234] [client 4.204.201.85:57769] AH01276: Cannot serve directory /home4/solar369/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:24.752004 2026] [security2:error] [pid 302018:tid 302204] [client 4.204.201.85:57769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/abcd.php"] [unique_id "al9OtIAs9lPxxVAErz0DCQAAALs"]
[Tue Jul 21 07:49:25.026306 2026] [security2:error] [pid 302018:tid 302137] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OtYAs9lPxxVAErz0DDAAAi3Q"]
[Tue Jul 21 07:49:25.026443 2026] [security2:error] [pid 302018:tid 302156] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OtYAs9lPxxVAErz0DDAAAi3Q"]
[Tue Jul 21 07:49:25.044501 2026] [security2:error] [pid 296703:tid 296957] [client 20.151.10.161:63372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/hypo.php"] [unique_id "al9OtSn25uliftkV1n4mkQAAAHw"]
[Tue Jul 21 07:49:25.195615 2026] [security2:error] [pid 296703:tid 296932] [client 20.151.10.161:43784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/classwithtostring.php"] [unique_id "al9OtSn25uliftkV1n4mlQAAAGM"]
[Tue Jul 21 07:49:25.217498 2026] [security2:error] [pid 302018:tid 302174] [client 4.204.201.85:57841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/file15.php"] [unique_id "al9OtYAs9lPxxVAErz0DEgAAAJ0"]
[Tue Jul 21 07:49:25.260189 2026] [security2:error] [pid 302018:tid 302179] [client 20.197.195.24:16781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/images.php"] [unique_id "al9OtYAs9lPxxVAErz0DEwAAAKI"]
[Tue Jul 21 07:49:25.313821 2026] [security2:error] [pid 302018:tid 302271] [client 117.217.38.194:53247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OtYAs9lPxxVAErz0DFgAAAP4"]
[Tue Jul 21 07:49:25.313960 2026] [security2:error] [pid 302018:tid 302271] [client 117.217.38.194:53247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OtYAs9lPxxVAErz0DFgAAAP4"]
[Tue Jul 21 07:49:25.432281 2026] [security2:error] [pid 296703:tid 296878] [client 20.197.195.24:10721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/gecko.php"] [unique_id "al9OtSn25uliftkV1n4mmgAAAC0"]
[Tue Jul 21 07:49:25.483364 2026] [security2:error] [pid 302018:tid 302199] [client 41.68.90.219:59032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OtYAs9lPxxVAErz0DFwAAALY"]
[Tue Jul 21 07:49:25.484504 2026] [security2:error] [pid 302018:tid 302199] [client 41.68.90.219:59032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OtYAs9lPxxVAErz0DFwAAALY"]
[Tue Jul 21 07:49:25.552859 2026] [security2:error] [pid 296703:tid 296907] [client 193.36.225.10:33199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OtSn25uliftkV1n4mmwAAAEo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:49:25.575199 2026] [security2:error] [pid 302018:tid 302208] [client 4.204.201.85:51314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/jp.php"] [unique_id "al9OtYAs9lPxxVAErz0DHQAAAL8"]
[Tue Jul 21 07:49:25.607797 2026] [security2:error] [pid 302018:tid 302267] [client 20.220.225.223:38713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wander.php"] [unique_id "al9OtYAs9lPxxVAErz0DHwAAAPo"]
[Tue Jul 21 07:49:25.634821 2026] [security2:error] [pid 302018:tid 302265] [client 20.197.195.24:16784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/82.php"] [unique_id "al9OtYAs9lPxxVAErz0DIAAAAPg"]
[Tue Jul 21 07:49:25.726689 2026] [security2:error] [pid 302018:tid 302225] [client 74.249.245.134:64104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/x.php"] [unique_id "al9OtYAs9lPxxVAErz0DIQAAANA"]
[Tue Jul 21 07:49:25.737023 2026] [security2:error] [pid 296703:tid 296727] [remote 57.141.18.52:55880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/wp-login.php"] [unique_id "al9OtCn25uliftkV1n4miAAARhc"]
[Tue Jul 21 07:49:25.823591 2026] [security2:error] [pid 296703:tid 296732] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OtSn25uliftkV1n4moQAAahw"]
[Tue Jul 21 07:49:25.823790 2026] [security2:error] [pid 296703:tid 296939] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OtSn25uliftkV1n4moQAAahw"]
[Tue Jul 21 07:49:25.925041 2026] [security2:error] [pid 302018:tid 302209] [client 106.215.181.8:22424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OtYAs9lPxxVAErz0DJAAAAMA"]
[Tue Jul 21 07:49:25.925164 2026] [security2:error] [pid 302018:tid 302209] [client 106.215.181.8:22424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OtYAs9lPxxVAErz0DJAAAAMA"]
[Tue Jul 21 07:49:25.938489 2026] [security2:error] [pid 296703:tid 296858] [client 4.204.201.85:57808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/f35.php"] [unique_id "al9OtSn25uliftkV1n4mogAAABk"]
[Tue Jul 21 07:49:25.967491 2026] [security2:error] [pid 302018:tid 302266] [client 20.197.195.24:10681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/admin.php"] [unique_id "al9OtYAs9lPxxVAErz0DJgAAAPk"]
[Tue Jul 21 07:49:26.028604 2026] [security2:error] [pid 296703:tid 296914] [client 152.59.154.239:53348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Otin25uliftkV1n4mpAAAAFE"]
[Tue Jul 21 07:49:26.028779 2026] [security2:error] [pid 296703:tid 296914] [client 152.59.154.239:53348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Otin25uliftkV1n4mpAAAAFE"]
[Tue Jul 21 07:49:26.095706 2026] [security2:error] [pid 302018:tid 302183] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9OtYAs9lPxxVAErz0DJwAApkA"]
[Tue Jul 21 07:49:26.228789 2026] [http2:warn] [pid 296703:tid 296934] [client 173.252.95.16:51424] h2_stream(296703-1078-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:26.344430 2026] [security2:error] [pid 296703:tid 296849] [client 20.197.195.24:10646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/adminner.php"] [unique_id "al9Otin25uliftkV1n4mqwAAABA"]
[Tue Jul 21 07:49:26.376647 2026] [http2:warn] [pid 302018:tid 302248] [client 57.141.18.77:58206] h2_stream(302018-941-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:26.387958 2026] [security2:error] [pid 302018:tid 302128] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OtoAs9lPxxVAErz0DKwAAqGs"]
[Tue Jul 21 07:49:26.388104 2026] [security2:error] [pid 302018:tid 302185] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OtoAs9lPxxVAErz0DKwAAqGs"]
[Tue Jul 21 07:49:26.421549 2026] [security2:error] [pid 302018:tid 302153] [client 4.204.201.85:51291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/wp-load.php"] [unique_id "al9OtoAs9lPxxVAErz0DLAAAAIg"]
[Tue Jul 21 07:49:26.543099 2026] [security2:error] [pid 302018:tid 302273] [client 20.151.10.161:63427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/chosen.php"] [unique_id "al9OtoAs9lPxxVAErz0DLQAAAQA"]
[Tue Jul 21 07:49:26.696334 2026] [security2:error] [pid 302018:tid 302208] [client 20.151.10.161:44020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9OtoAs9lPxxVAErz0DMQAAAL8"]
[Tue Jul 21 07:49:26.794357 2026] [security2:error] [pid 302018:tid 302213] [client 4.204.201.85:57750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/xyn.php"] [unique_id "al9OtoAs9lPxxVAErz0DNgAAAMQ"]
[Tue Jul 21 07:49:26.854524 2026] [security2:error] [pid 302018:tid 302192] [client 122.162.144.145:8885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OtoAs9lPxxVAErz0DOAAAAK8"]
[Tue Jul 21 07:49:26.854652 2026] [security2:error] [pid 302018:tid 302192] [client 122.162.144.145:8885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OtoAs9lPxxVAErz0DOAAAAK8"]
[Tue Jul 21 07:49:27.061367 2026] [security2:error] [pid 302018:tid 302152] [client 20.197.195.24:10625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/admin.php"] [unique_id "al9Ot4As9lPxxVAErz0DPAAAAIc"]
[Tue Jul 21 07:49:27.201174 2026] [security2:error] [pid 302018:tid 302234] [client 65.111.29.63:47425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.29.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9OtoAs9lPxxVAErz0DKAAAANk"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:49:27.238278 2026] [security2:error] [pid 302018:tid 302156] [client 20.197.195.24:10648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/k.php"] [unique_id "al9Ot4As9lPxxVAErz0DQAAAAIs"]
[Tue Jul 21 07:49:27.422462 2026] [http2:warn] [pid 302018:tid 302176] [client 57.141.18.89:55996] h2_stream(302018-948-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:27.499101 2026] [autoindex:error] [pid 302018:tid 302174] [client 4.204.201.85:51289] AH01276: Cannot serve directory /home4/solar369/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:27.505549 2026] [security2:error] [pid 302018:tid 302158] [client 20.151.10.161:63396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/file5.php"] [unique_id "al9Ot4As9lPxxVAErz0DRAAAAI0"]
[Tue Jul 21 07:49:27.548034 2026] [security2:error] [pid 302018:tid 302246] [client 20.197.195.24:16750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/blurbs.php"] [unique_id "al9Ot4As9lPxxVAErz0DRQAAAOU"]
[Tue Jul 21 07:49:27.555105 2026] [security2:error] [pid 302018:tid 302216] [client 20.226.60.151:61579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/2x.php"] [unique_id "al9Ot4As9lPxxVAErz0DRgAAAMc"]
[Tue Jul 21 07:49:27.563115 2026] [security2:error] [pid 302018:tid 302179] [client 74.249.245.134:64065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/new.php"] [unique_id "al9Ot4As9lPxxVAErz0DRwAAAKI"]
[Tue Jul 21 07:49:27.646238 2026] [security2:error] [pid 302018:tid 302131] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Ot4As9lPxxVAErz0DSQAA_m4"]
[Tue Jul 21 07:49:27.646382 2026] [security2:error] [pid 302018:tid 302271] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Ot4As9lPxxVAErz0DSQAA_m4"]
[Tue Jul 21 07:49:27.724886 2026] [security2:error] [pid 302018:tid 302233] [client 20.220.225.223:38684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/jga.php"] [unique_id "al9Ot4As9lPxxVAErz0DSgAAANg"]
[Tue Jul 21 07:49:27.733223 2026] [http2:warn] [pid 302018:tid 302262] [client 173.252.95.19:37480] h2_stream(302018-1018-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:27.943678 2026] [autoindex:error] [pid 302018:tid 302243] [client 4.204.201.85:51289] AH01276: Cannot serve directory /home4/solar369/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:49:28.081271 2026] [security2:error] [pid 302018:tid 302228] [client 4.204.201.85:51289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/ccc.php"] [unique_id "al9OuIAs9lPxxVAErz0DTwAAANM"]
[Tue Jul 21 07:49:28.096059 2026] [security2:error] [pid 302018:tid 302175] [client 103.166.103.129:61400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OuIAs9lPxxVAErz0DUAAAAJ4"]
[Tue Jul 21 07:49:28.096187 2026] [security2:error] [pid 302018:tid 302175] [client 103.166.103.129:61400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OuIAs9lPxxVAErz0DUAAAAJ4"]
[Tue Jul 21 07:49:28.197128 2026] [http2:warn] [pid 302018:tid 302157] [client 173.252.95.57:34648] h2_stream(302018-1019-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:28.365449 2026] [security2:error] [pid 296703:tid 296865] [client 20.151.10.161:63448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/file.php"] [unique_id "al9OuCn25uliftkV1n4myAAAACA"]
[Tue Jul 21 07:49:28.575786 2026] [security2:error] [pid 296703:tid 296953] [client 20.220.225.223:38693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/x.php"] [unique_id "al9OuCn25uliftkV1n4m0QAAAHg"]
[Tue Jul 21 07:49:28.705141 2026] [security2:error] [pid 296703:tid 296896] [client 74.249.245.134:64197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/jga.php"] [unique_id "al9OuCn25uliftkV1n4m1AAAAD8"]
[Tue Jul 21 07:49:28.717192 2026] [security2:error] [pid 302018:tid 302172] [client 20.151.10.161:43963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-blog.php"] [unique_id "al9OuIAs9lPxxVAErz0DWwAAAJs"]
[Tue Jul 21 07:49:28.771330 2026] [security2:error] [pid 296703:tid 296903] [client 20.197.195.24:10703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/bajah.php"] [unique_id "al9OuCn25uliftkV1n4m1wAAAEY"]
[Tue Jul 21 07:49:28.852525 2026] [security2:error] [pid 302018:tid 302277] [client 122.164.127.47:61096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OuIAs9lPxxVAErz0DXgAAAQQ"]
[Tue Jul 21 07:49:28.859157 2026] [security2:error] [pid 302018:tid 302277] [client 122.164.127.47:61096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OuIAs9lPxxVAErz0DXgAAAQQ"]
[Tue Jul 21 07:49:28.888239 2026] [security2:error] [pid 302018:tid 302174] [client 4.204.201.85:57732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/w.php"] [unique_id "al9OuIAs9lPxxVAErz0DYAAAAJ0"]
[Tue Jul 21 07:49:29.236391 2026] [security2:error] [pid 296703:tid 296924] [client 223.236.153.128:16051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OuSn25uliftkV1n4m3wAAAFs"]
[Tue Jul 21 07:49:29.236516 2026] [security2:error] [pid 296703:tid 296924] [client 223.236.153.128:16051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OuSn25uliftkV1n4m3wAAAFs"]
[Tue Jul 21 07:49:29.267112 2026] [security2:error] [pid 296703:tid 296781] [remote 192.241.143.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.hauptmann.com.br"] [uri "/wp-login.php"] [unique_id "al9OuSn25uliftkV1n4m4gAAPk0"]
[Tue Jul 21 07:49:29.296344 2026] [security2:error] [pid 302018:tid 302126] [remote 103.28.36.106:37062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "knconteudo.com"] [uri "/wp-login.php"] [unique_id "al9OuYAs9lPxxVAErz0DZgAAi2k"]
[Tue Jul 21 07:49:29.335864 2026] [security2:error] [pid 302018:tid 302184] [client 4.204.201.85:57737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9OuYAs9lPxxVAErz0DZwAAAKc"]
[Tue Jul 21 07:49:29.474131 2026] [security2:error] [pid 302018:tid 302196] [client 20.151.10.161:64232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/aa2.php"] [unique_id "al9OuYAs9lPxxVAErz0DawAAALM"]
[Tue Jul 21 07:49:29.487558 2026] [security2:error] [pid 302018:tid 302118] [remote 114.34.90.9:44842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9OuYAs9lPxxVAErz0DbAAA1GE"]
[Tue Jul 21 07:49:29.487730 2026] [security2:error] [pid 302018:tid 302229] [client 114.34.90.9:44842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9OuYAs9lPxxVAErz0DbAAA1GE"]
[Tue Jul 21 07:49:29.523790 2026] [security2:error] [pid 296703:tid 296920] [client 194.99.104.35:44178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9OuSn25uliftkV1n4m5QAAAFc"]
[Tue Jul 21 07:49:29.523920 2026] [security2:error] [pid 296703:tid 296920] [client 194.99.104.35:44178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9OuSn25uliftkV1n4m5QAAAFc"]
[Tue Jul 21 07:49:29.536440 2026] [security2:error] [pid 302018:tid 302091] [remote 74.208.9.170:41142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.9.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9OuYAs9lPxxVAErz0DbwAA50Y"]
[Tue Jul 21 07:49:29.676312 2026] [security2:error] [pid 302018:tid 302264] [client 4.204.201.85:51295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/FWAZ.php"] [unique_id "al9OuYAs9lPxxVAErz0DcAAAAPc"]
[Tue Jul 21 07:49:29.712006 2026] [security2:error] [pid 296703:tid 296905] [client 193.36.225.73:29623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OuSn25uliftkV1n4m5gAAAEg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:49:29.749425 2026] [http2:warn] [pid 296703:tid 296923] [client 173.252.95.7:34726] h2_stream(296703-1086-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:29.985227 2026] [security2:error] [pid 302018:tid 302046] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OuYAs9lPxxVAErz0DeAAAsBk"]
[Tue Jul 21 07:49:29.985374 2026] [security2:error] [pid 302018:tid 302193] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OuYAs9lPxxVAErz0DeAAAsBk"]
[Tue Jul 21 07:49:30.052614 2026] [security2:error] [pid 296703:tid 296952] [client 4.204.201.85:57766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/miru1.php"] [unique_id "al9Ouin25uliftkV1n4m7QAAAHc"]
[Tue Jul 21 07:49:30.184448 2026] [http2:warn] [pid 296703:tid 296908] [client 57.141.18.93:31082] h2_stream(296703-1011-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:30.451304 2026] [security2:error] [pid 296703:tid 296873] [client 4.204.201.85:21900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/aa.php"] [unique_id "al9Ouin25uliftkV1n4m8wAAACg"]
[Tue Jul 21 07:49:30.643935 2026] [security2:error] [pid 302018:tid 302233] [client 20.197.195.24:10650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/a.php"] [unique_id "al9OuoAs9lPxxVAErz0DfwAAANg"]
[Tue Jul 21 07:49:30.716925 2026] [security2:error] [pid 302018:tid 302114] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OuoAs9lPxxVAErz0DfAAAkF0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:49:30.744882 2026] [security2:error] [pid 302018:tid 302151] [client 20.151.10.161:63443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/ccou.php"] [unique_id "al9OuoAs9lPxxVAErz0DgAAAAIY"]
[Tue Jul 21 07:49:30.753033 2026] [security2:error] [pid 296703:tid 296744] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Ouin25uliftkV1n4m9gAALig"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:49:30.765191 2026] [security2:error] [pid 302018:tid 302086] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OuoAs9lPxxVAErz0DfQAAwEE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:49:30.772098 2026] [security2:error] [pid 302018:tid 302078] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OuoAs9lPxxVAErz0DfgAAkjk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:49:30.829081 2026] [security2:error] [pid 302018:tid 302263] [client 62.102.148.187:39372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9OuoAs9lPxxVAErz0DgQAAAPY"]
[Tue Jul 21 07:49:30.829152 2026] [security2:error] [pid 302018:tid 302263] [client 62.102.148.187:39372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9OuoAs9lPxxVAErz0DgQAAAPY"]
[Tue Jul 21 07:49:30.864235 2026] [security2:error] [pid 302018:tid 302199] [client 4.204.201.85:51325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/122.php"] [unique_id "al9OuoAs9lPxxVAErz0DggAAALY"]
[Tue Jul 21 07:49:30.920007 2026] [security2:error] [pid 296703:tid 296775] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Ouin25uliftkV1n4m_wAAIEc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:49:30.946192 2026] [security2:error] [pid 302018:tid 302122] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9OuoAs9lPxxVAErz0DhAAAo2U"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:49:30.958283 2026] [security2:error] [pid 296703:tid 296955] [client 20.151.10.161:43930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Ouin25uliftkV1n4nAAAAAHo"]
[Tue Jul 21 07:49:31.022477 2026] [security2:error] [pid 302018:tid 302026] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ou4As9lPxxVAErz0DhwAAiwU"]
[Tue Jul 21 07:49:31.022635 2026] [security2:error] [pid 302018:tid 302156] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ou4As9lPxxVAErz0DhwAAiwU"]
[Tue Jul 21 07:49:31.048748 2026] [security2:error] [pid 296703:tid 296885] [client 20.226.60.151:61525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/ctex1.php"] [unique_id "al9Ouyn25uliftkV1n4nBAAAADQ"]
[Tue Jul 21 07:49:31.134819 2026] [security2:error] [pid 302018:tid 302148] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Ou4As9lPxxVAErz0DiAAA1H8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:49:31.192882 2026] [security2:error] [pid 296703:tid 296856] [client 74.249.245.134:18458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/k.php"] [unique_id "al9Ouyn25uliftkV1n4nBgAAABc"]
[Tue Jul 21 07:49:31.200390 2026] [security2:error] [pid 302018:tid 302039] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Ou4As9lPxxVAErz0DigAAoRI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:49:31.204671 2026] [security2:error] [pid 302018:tid 302237] [client 74.249.245.134:64401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/class-t.api.php"] [unique_id "al9Ou4As9lPxxVAErz0DiwAAANw"]
[Tue Jul 21 07:49:31.254963 2026] [security2:error] [pid 296703:tid 296953] [client 4.204.201.85:57784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/get.php"] [unique_id "al9Ouyn25uliftkV1n4nBwAAAHg"]
[Tue Jul 21 07:49:31.298885 2026] [security2:error] [pid 302018:tid 302143] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Ou4As9lPxxVAErz0DjAAA93o"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:49:31.327774 2026] [security2:error] [pid 302018:tid 302112] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Ou4As9lPxxVAErz0DjgAAnFs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:49:31.375089 2026] [security2:error] [pid 302018:tid 302106] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Ou4As9lPxxVAErz0DjwAA21U"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:49:31.420310 2026] [security2:error] [pid 302018:tid 302276] [client 122.186.204.214:61313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ou4As9lPxxVAErz0DkQAAAQM"]
[Tue Jul 21 07:49:31.420468 2026] [security2:error] [pid 302018:tid 302276] [client 122.186.204.214:61313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ou4As9lPxxVAErz0DkQAAAQM"]
[Tue Jul 21 07:49:31.426825 2026] [core:error] [pid 302018:tid 302083] [remote 52.167.144.206:52554] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:49:31.426843 2026] [core:error] [pid 302018:tid 302083] [remote 52.167.144.206:52554] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:49:31.427944 2026] [security2:error] [pid 296703:tid 296927] [client 154.192.233.199:58856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ouyn25uliftkV1n4nCwAAAF4"]
[Tue Jul 21 07:49:31.428039 2026] [security2:error] [pid 296703:tid 296927] [client 154.192.233.199:58856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ouyn25uliftkV1n4nCwAAAF4"]
[Tue Jul 21 07:49:31.677572 2026] [security2:error] [pid 296703:tid 296898] [client 4.204.201.85:51292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/as.php"] [unique_id "al9Ouyn25uliftkV1n4nDwAAAEE"]
[Tue Jul 21 07:49:31.707186 2026] [security2:error] [pid 302018:tid 302215] [client 117.247.80.59:21929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ou4As9lPxxVAErz0DlQAAAMY"]
[Tue Jul 21 07:49:31.707301 2026] [security2:error] [pid 302018:tid 302215] [client 117.247.80.59:21929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ou4As9lPxxVAErz0DlQAAAMY"]
[Tue Jul 21 07:49:31.736429 2026] [http2:warn] [pid 296703:tid 296860] [client 57.141.18.20:21158] h2_stream(296703-1018-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:31.808570 2026] [security2:error] [pid 296703:tid 296899] [client 182.8.255.181:2931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Ouyn25uliftkV1n4nEAAAAEI"]
[Tue Jul 21 07:49:31.808682 2026] [security2:error] [pid 296703:tid 296899] [client 182.8.255.181:2931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Ouyn25uliftkV1n4nEAAAAEI"]
[Tue Jul 21 07:49:31.895542 2026] [security2:error] [pid 302018:tid 302183] [client 20.220.225.223:38662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/tinyfilemanager.php"] [unique_id "al9Ou4As9lPxxVAErz0DmgAAAKY"]
[Tue Jul 21 07:49:31.967273 2026] [security2:error] [pid 302018:tid 302271] [client 20.197.195.24:10684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/edit.php"] [unique_id "al9Ou4As9lPxxVAErz0DnQAAAP4"]
[Tue Jul 21 07:49:32.175502 2026] [security2:error] [pid 302018:tid 302263] [client 4.204.201.85:57815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/ccou.php"] [unique_id "al9OvIAs9lPxxVAErz0DpAAAAPY"]
[Tue Jul 21 07:49:32.414931 2026] [security2:error] [pid 302018:tid 302196] [client 20.151.10.161:63405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/dr.php"] [unique_id "al9OvIAs9lPxxVAErz0DqQAAALM"]
[Tue Jul 21 07:49:32.804582 2026] [security2:error] [pid 296703:tid 296910] [client 4.204.201.85:57736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/w3lls.php"] [unique_id "al9OvCn25uliftkV1n4nIAAAAE0"]
[Tue Jul 21 07:49:32.807572 2026] [security2:error] [pid 296703:tid 296888] [client 20.220.225.223:31185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/ee.php"] [unique_id "al9OvCn25uliftkV1n4nIQAAADc"]
[Tue Jul 21 07:49:32.911258 2026] [security2:error] [pid 302018:tid 302228] [client 136.144.42.186:27985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiferreira.com.br"] [uri "/wp-login.php"] [unique_id "al9OvIAs9lPxxVAErz0DrwAAANM"]
[Tue Jul 21 07:49:32.946848 2026] [security2:error] [pid 302018:tid 302243] [client 103.86.117.203:59319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OvIAs9lPxxVAErz0DsAAAAOI"]
[Tue Jul 21 07:49:32.947002 2026] [security2:error] [pid 302018:tid 302243] [client 103.86.117.203:59319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OvIAs9lPxxVAErz0DsAAAAOI"]
[Tue Jul 21 07:49:32.990299 2026] [security2:error] [pid 302018:tid 302162] [client 139.167.225.182:59443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OvIAs9lPxxVAErz0DsQAAAJE"]
[Tue Jul 21 07:49:32.990420 2026] [security2:error] [pid 302018:tid 302162] [client 139.167.225.182:59443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OvIAs9lPxxVAErz0DsQAAAJE"]
[Tue Jul 21 07:49:33.186397 2026] [security2:error] [pid 302018:tid 302218] [client 4.204.201.85:57746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/test1.php"] [unique_id "al9OvYAs9lPxxVAErz0DswAAAMk"]
[Tue Jul 21 07:49:33.287483 2026] [security2:error] [pid 296703:tid 296838] [client 128.127.105.184:34430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9OvSn25uliftkV1n4nKwAAAAU"]
[Tue Jul 21 07:49:33.287582 2026] [security2:error] [pid 296703:tid 296838] [client 128.127.105.184:34430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9OvSn25uliftkV1n4nKwAAAAU"]
[Tue Jul 21 07:49:33.357682 2026] [security2:error] [pid 296703:tid 296862] [client 74.249.245.134:8779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/plugins.php"] [unique_id "al9OvSn25uliftkV1n4nLQAAAB0"]
[Tue Jul 21 07:49:33.400349 2026] [security2:error] [pid 296703:tid 296873] [client 173.24.185.52:58106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OvSn25uliftkV1n4nLgAAACg"]
[Tue Jul 21 07:49:33.400477 2026] [security2:error] [pid 296703:tid 296873] [client 173.24.185.52:58106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9OvSn25uliftkV1n4nLgAAACg"]
[Tue Jul 21 07:49:33.604909 2026] [security2:error] [pid 296703:tid 296843] [client 59.96.220.140:61858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OvSn25uliftkV1n4nNAAAAAo"]
[Tue Jul 21 07:49:33.605628 2026] [security2:error] [pid 296703:tid 296843] [client 59.96.220.140:61858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OvSn25uliftkV1n4nNAAAAAo"]
[Tue Jul 21 07:49:33.675829 2026] [security2:error] [pid 296703:tid 296836] [client 193.36.225.11:22659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9OvSn25uliftkV1n4nNgAAAAM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:49:33.784042 2026] [security2:error] [pid 296703:tid 296875] [client 20.151.10.161:64173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/file31.php"] [unique_id "al9OvSn25uliftkV1n4nOQAAACo"]
[Tue Jul 21 07:49:33.795194 2026] [security2:error] [pid 296703:tid 296876] [client 103.29.114.44:35951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OvSn25uliftkV1n4nOgAAACs"]
[Tue Jul 21 07:49:33.795293 2026] [security2:error] [pid 296703:tid 296876] [client 103.29.114.44:35951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OvSn25uliftkV1n4nOgAAACs"]
[Tue Jul 21 07:49:33.879849 2026] [security2:error] [pid 296703:tid 296948] [client 178.153.91.96:50516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OvSn25uliftkV1n4nOwAAAHM"]
[Tue Jul 21 07:49:33.879959 2026] [security2:error] [pid 296703:tid 296948] [client 178.153.91.96:50516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OvSn25uliftkV1n4nOwAAAHM"]
[Tue Jul 21 07:49:33.880885 2026] [security2:error] [pid 302018:tid 302230] [client 20.197.195.24:10736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/hosty.php"] [unique_id "al9OvYAs9lPxxVAErz0DugAAANU"]
[Tue Jul 21 07:49:33.973207 2026] [security2:error] [pid 302018:tid 302175] [client 202.143.127.214:51420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OvYAs9lPxxVAErz0DvAAAAJ4"]
[Tue Jul 21 07:49:33.973345 2026] [security2:error] [pid 302018:tid 302175] [client 202.143.127.214:51420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OvYAs9lPxxVAErz0DvAAAAJ4"]
[Tue Jul 21 07:49:34.027568 2026] [security2:error] [pid 296703:tid 296926] [client 4.204.201.85:57785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/database.php"] [unique_id "al9Ovin25uliftkV1n4nPwAAAF0"]
[Tue Jul 21 07:49:34.421371 2026] [security2:error] [pid 296703:tid 296872] [client 74.249.245.134:64439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/vx.php"] [unique_id "al9Ovin25uliftkV1n4nQgAAACc"]
[Tue Jul 21 07:49:34.447090 2026] [security2:error] [pid 302018:tid 302178] [client 20.151.10.161:63410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/file6.php"] [unique_id "al9OvoAs9lPxxVAErz0DxQAAAKE"]
[Tue Jul 21 07:49:34.479513 2026] [http2:warn] [pid 296703:tid 296889] [client 57.141.18.100:26474] h2_stream(296703-1036-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:34.574917 2026] [security2:error] [pid 296703:tid 296844] [client 4.204.201.85:57780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/file.php"] [unique_id "al9Ovin25uliftkV1n4nRwAAAAs"]
[Tue Jul 21 07:49:34.616353 2026] [security2:error] [pid 302018:tid 302271] [client 122.179.91.63:6653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OvoAs9lPxxVAErz0DyAAAAP4"]
[Tue Jul 21 07:49:34.616445 2026] [security2:error] [pid 302018:tid 302271] [client 122.179.91.63:6653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OvoAs9lPxxVAErz0DyAAAAP4"]
[Tue Jul 21 07:49:34.939667 2026] [security2:error] [pid 302018:tid 302226] [client 47.128.97.42:15840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "woma.com.br"] [uri "/robots.txt"] [unique_id "al9OvoAs9lPxxVAErz0DzQAAANE"]
[Tue Jul 21 07:49:35.105429 2026] [security2:error] [pid 296703:tid 296910] [client 20.226.60.151:61535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/edorxrr.php"] [unique_id "al9Ovyn25uliftkV1n4nUAAAAE0"]
[Tue Jul 21 07:49:35.181746 2026] [security2:error] [pid 302018:tid 302119] [remote 68.178.160.25:57302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "revistareflexopolitico.com.br"] [uri "/wp-login.php"] [unique_id "al9Ov4As9lPxxVAErz0D0QAAyWI"]
[Tue Jul 21 07:49:35.208455 2026] [http2:warn] [pid 302018:tid 302159] [client 57.141.18.24:63744] h2_stream(302018-979-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:35.240347 2026] [security2:error] [pid 302018:tid 302230] [client 20.151.10.161:64243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/file15.php"] [unique_id "al9Ov4As9lPxxVAErz0D0wAAANU"]
[Tue Jul 21 07:49:35.269247 2026] [security2:error] [pid 302018:tid 302111] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Ov4As9lPxxVAErz0D1gAAxlo"]
[Tue Jul 21 07:49:35.269403 2026] [security2:error] [pid 302018:tid 302215] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Ov4As9lPxxVAErz0D1gAAxlo"]
[Tue Jul 21 07:49:35.414371 2026] [security2:error] [pid 296703:tid 296852] [client 74.249.245.134:65107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ws77.php"] [unique_id "al9Ovyn25uliftkV1n4nVQAAABM"]
[Tue Jul 21 07:49:35.603994 2026] [security2:error] [pid 302018:tid 302029] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ov4As9lPxxVAErz0D2QAAnwg"]
[Tue Jul 21 07:49:35.604166 2026] [security2:error] [pid 302018:tid 302176] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ov4As9lPxxVAErz0D2QAAnwg"]
[Tue Jul 21 07:49:35.821801 2026] [security2:error] [pid 302018:tid 302156] [client 4.204.201.85:57833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/file.php"] [unique_id "al9Ov4As9lPxxVAErz0D3wAAAIs"]
[Tue Jul 21 07:49:35.845661 2026] [security2:error] [pid 296703:tid 296864] [client 117.217.38.194:53734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ovyn25uliftkV1n4nYgAAAB8"]
[Tue Jul 21 07:49:35.845763 2026] [security2:error] [pid 296703:tid 296864] [client 117.217.38.194:53734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ovyn25uliftkV1n4nYgAAAB8"]
[Tue Jul 21 07:49:35.951541 2026] [security2:error] [pid 302018:tid 302229] [client 20.151.10.161:64143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/jp.php"] [unique_id "al9Ov4As9lPxxVAErz0D4AAAANQ"]
[Tue Jul 21 07:49:36.350251 2026] [security2:error] [pid 302018:tid 302061] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OwIAs9lPxxVAErz0D5QAAtSg"]
[Tue Jul 21 07:49:36.350401 2026] [security2:error] [pid 302018:tid 302198] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OwIAs9lPxxVAErz0D5QAAtSg"]
[Tue Jul 21 07:49:36.571606 2026] [security2:error] [pid 302018:tid 302192] [client 106.215.181.8:6039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OwIAs9lPxxVAErz0D5wAAAK8"]
[Tue Jul 21 07:49:36.571700 2026] [security2:error] [pid 302018:tid 302192] [client 106.215.181.8:6039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OwIAs9lPxxVAErz0D5wAAAK8"]
[Tue Jul 21 07:49:36.722551 2026] [security2:error] [pid 302018:tid 302258] [client 20.151.10.161:63454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/f35.php"] [unique_id "al9OwIAs9lPxxVAErz0D6wAAAPE"]
[Tue Jul 21 07:49:36.809277 2026] [security2:error] [pid 302018:tid 302263] [client 20.197.195.24:16770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/k.php"] [unique_id "al9OwIAs9lPxxVAErz0D7wAAAPY"]
[Tue Jul 21 07:49:36.932681 2026] [security2:error] [pid 302018:tid 302173] [client 152.59.154.239:57030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OwIAs9lPxxVAErz0D8QAAAJw"]
[Tue Jul 21 07:49:36.932806 2026] [security2:error] [pid 302018:tid 302173] [client 152.59.154.239:57030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OwIAs9lPxxVAErz0D8QAAAJw"]
[Tue Jul 21 07:49:36.937603 2026] [security2:error] [pid 302018:tid 302124] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OwIAs9lPxxVAErz0D8gAAkGc"]
[Tue Jul 21 07:49:36.937743 2026] [security2:error] [pid 302018:tid 302161] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9OwIAs9lPxxVAErz0D8gAAkGc"]
[Tue Jul 21 07:49:37.041936 2026] [security2:error] [pid 296703:tid 296896] [client 20.151.10.161:63463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wp-load.php"] [unique_id "al9OwSn25uliftkV1n4ncAAAAD8"]
[Tue Jul 21 07:49:37.091798 2026] [security2:error] [pid 302018:tid 302178] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9OwIAs9lPxxVAErz0D8wAAoRU"]
[Tue Jul 21 07:49:37.268358 2026] [security2:error] [pid 302018:tid 302162] [client 194.99.104.35:44184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OwYAs9lPxxVAErz0D9gAAAJE"]
[Tue Jul 21 07:49:37.268471 2026] [security2:error] [pid 302018:tid 302162] [client 194.99.104.35:44184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OwYAs9lPxxVAErz0D9gAAAJE"]
[Tue Jul 21 07:49:37.318324 2026] [security2:error] [pid 302018:tid 302176] [client 41.68.90.219:59465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OwYAs9lPxxVAErz0D9wAAAJ8"]
[Tue Jul 21 07:49:37.319331 2026] [security2:error] [pid 302018:tid 302176] [client 41.68.90.219:59465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OwYAs9lPxxVAErz0D9wAAAJ8"]
[Tue Jul 21 07:49:37.602136 2026] [rewrite:warn] [pid 302018:tid 302022] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:37.609345 2026] [security2:error] [pid 302018:tid 302212] [client 20.151.10.161:43892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/adminfuns.php"] [unique_id "al9OwYAs9lPxxVAErz0D_gAAAMM"]
[Tue Jul 21 07:49:37.666403 2026] [security2:error] [pid 302018:tid 302040] [remote 199.189.225.40:43337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roha.life"] [uri "/wp-login.php"] [unique_id "al9OwYAs9lPxxVAErz0D_wAA2xM"]
[Tue Jul 21 07:49:37.681941 2026] [security2:error] [pid 302018:tid 302251] [client 122.162.144.145:8786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OwYAs9lPxxVAErz0EAAAAAOo"]
[Tue Jul 21 07:49:37.682043 2026] [security2:error] [pid 302018:tid 302251] [client 122.162.144.145:8786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OwYAs9lPxxVAErz0EAAAAAOo"]
[Tue Jul 21 07:49:37.707132 2026] [security2:error] [pid 296703:tid 296893] [client 20.226.60.151:61561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/miru1.php"] [unique_id "al9OwSn25uliftkV1n4negAAADw"]
[Tue Jul 21 07:49:37.719407 2026] [rewrite:warn] [pid 302018:tid 302113] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:37.725344 2026] [rewrite:warn] [pid 302018:tid 302102] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:37.782909 2026] [security2:error] [pid 302018:tid 302233] [client 4.204.201.85:21890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/777.php"] [unique_id "al9OwYAs9lPxxVAErz0EBgAAANg"]
[Tue Jul 21 07:49:37.793546 2026] [rewrite:warn] [pid 302018:tid 311334] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:37.814179 2026] [rewrite:warn] [pid 302018:tid 302097] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:37.892545 2026] [rewrite:warn] [pid 302018:tid 302075] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:37.926341 2026] [security2:error] [pid 302018:tid 302216] [client 74.249.245.134:64080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/jp.php"] [unique_id "al9OwYAs9lPxxVAErz0ECgAAAMc"]
[Tue Jul 21 07:49:37.927965 2026] [http2:warn] [pid 302018:tid 302222] [client 173.252.95.9:42610] h2_stream(302018-1042-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:37.954007 2026] [rewrite:warn] [pid 302018:tid 302025] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:38.022260 2026] [security2:error] [pid 302018:tid 302209] [client 20.197.195.24:16776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/aaa.php"] [unique_id "al9OwoAs9lPxxVAErz0EDAAAAMA"]
[Tue Jul 21 07:49:38.279059 2026] [security2:error] [pid 302018:tid 302189] [client 122.164.127.47:61668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OwoAs9lPxxVAErz0EEwAAAKw"]
[Tue Jul 21 07:49:38.279785 2026] [security2:error] [pid 302018:tid 302189] [client 122.164.127.47:61668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OwoAs9lPxxVAErz0EEwAAAKw"]
[Tue Jul 21 07:49:38.437384 2026] [http2:warn] [pid 296703:tid 296916] [client 57.141.18.75:32254] h2_stream(296703-1053-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:38.485206 2026] [security2:error] [pid 302018:tid 302043] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OwoAs9lPxxVAErz0EFwAA3hY"]
[Tue Jul 21 07:49:38.485337 2026] [security2:error] [pid 302018:tid 302239] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OwoAs9lPxxVAErz0EFwAA3hY"]
[Tue Jul 21 07:49:38.704291 2026] [security2:error] [pid 296703:tid 296852] [client 194.99.104.35:55978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Owin25uliftkV1n4nkAAAABM"]
[Tue Jul 21 07:49:38.704387 2026] [security2:error] [pid 296703:tid 296852] [client 194.99.104.35:55978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Owin25uliftkV1n4nkAAAABM"]
[Tue Jul 21 07:49:38.838108 2026] [http2:warn] [pid 302018:tid 302200] [client 173.252.95.28:50184] h2_stream(302018-1045-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:38.910164 2026] [security2:error] [pid 296703:tid 296947] [client 103.166.103.129:29795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Owin25uliftkV1n4nlwAAAHI"]
[Tue Jul 21 07:49:38.910301 2026] [security2:error] [pid 296703:tid 296947] [client 103.166.103.129:29795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Owin25uliftkV1n4nlwAAAHI"]
[Tue Jul 21 07:49:39.264021 2026] [security2:error] [pid 302018:tid 302211] [client 136.144.33.101:48859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9OwoAs9lPxxVAErz0EDwAAAMI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:49:39.341891 2026] [rewrite:warn] [pid 302018:tid 302141] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:39.351705 2026] [rewrite:warn] [pid 302018:tid 302073] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:39.442415 2026] [security2:error] [pid 302018:tid 302175] [client 74.249.245.134:8776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/2.php"] [unique_id "al9Ow4As9lPxxVAErz0EIgAAAJ4"]
[Tue Jul 21 07:49:39.483310 2026] [http2:warn] [pid 296703:tid 296951] [client 173.252.95.16:33648] h2_stream(296703-1099-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:39.772064 2026] [rewrite:warn] [pid 302018:tid 311330] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:49:39.873607 2026] [security2:error] [pid 302018:tid 302276] [client 20.197.195.24:10690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/file5.php"] [unique_id "al9Ow4As9lPxxVAErz0EJgAAAQM"]
[Tue Jul 21 07:49:39.966044 2026] [security2:error] [pid 296703:tid 296958] [client 223.236.153.128:5911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Owyn25uliftkV1n4nqAAAAH0"]
[Tue Jul 21 07:49:39.973614 2026] [security2:error] [pid 296703:tid 296958] [client 223.236.153.128:5911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Owyn25uliftkV1n4nqAAAAH0"]
[Tue Jul 21 07:49:40.177947 2026] [security2:error] [pid 296703:tid 296834] [client 4.204.201.85:57783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/ssixta.php"] [unique_id "al9OxCn25uliftkV1n4nqgAAAAE"]
[Tue Jul 21 07:49:40.322709 2026] [security2:error] [pid 296703:tid 296904] [client 20.151.10.161:64199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9OxCn25uliftkV1n4nqwAAAEc"]
[Tue Jul 21 07:49:40.337669 2026] [http2:warn] [pid 302018:tid 302270] [client 173.252.95.10:52482] h2_stream(302018-1047-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:40.609959 2026] [security2:error] [pid 296703:tid 296704] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OxCn25uliftkV1n4nswAACAA"]
[Tue Jul 21 07:49:40.610080 2026] [security2:error] [pid 296703:tid 296841] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OxCn25uliftkV1n4nswAACAA"]
[Tue Jul 21 07:49:40.732329 2026] [security2:error] [pid 302018:tid 302244] [client 128.127.105.184:43554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9OxIAs9lPxxVAErz0ELgAAAOM"]
[Tue Jul 21 07:49:40.732423 2026] [security2:error] [pid 302018:tid 302244] [client 128.127.105.184:43554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9OxIAs9lPxxVAErz0ELgAAAOM"]
[Tue Jul 21 07:49:40.943502 2026] [security2:error] [pid 302018:tid 302176] [client 20.151.10.161:63371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wp-links.php"] [unique_id "al9OxIAs9lPxxVAErz0EMgAAAJ8"]
[Tue Jul 21 07:49:41.218855 2026] [security2:error] [pid 302018:tid 302225] [client 4.204.201.85:50990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/1c.php"] [unique_id "al9OxYAs9lPxxVAErz0ENAAAANA"]
[Tue Jul 21 07:49:41.244323 2026] [http2:warn] [pid 296703:tid 296837] [client 57.141.18.54:54464] h2_stream(296703-1058-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:41.264052 2026] [security2:error] [pid 302018:tid 302162] [client 20.151.10.161:43891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/goods.php"] [unique_id "al9OxYAs9lPxxVAErz0ENgAAAJE"]
[Tue Jul 21 07:49:41.473837 2026] [security2:error] [pid 296703:tid 296854] [client 62.102.148.187:57556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9OxSn25uliftkV1n4nugAAABU"]
[Tue Jul 21 07:49:41.473934 2026] [security2:error] [pid 296703:tid 296854] [client 62.102.148.187:57556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9OxSn25uliftkV1n4nugAAABU"]
[Tue Jul 21 07:49:41.646051 2026] [security2:error] [pid 302018:tid 302266] [client 20.151.10.161:63363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/solo1.php"] [unique_id "al9OxYAs9lPxxVAErz0EOwAAAPk"]
[Tue Jul 21 07:49:41.855132 2026] [security2:error] [pid 302018:tid 302164] [client 74.7.244.58:57500] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "webmail.radiantus.online"] [uri "/___proxy_subdomain_webmail/robots.txt"] [unique_id "al9OxYAs9lPxxVAErz0EPAAAAJM"]
[Tue Jul 21 07:49:41.889824 2026] [http2:warn] [pid 302018:tid 302238] [client 57.141.18.35:30806] h2_stream(302018-992-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:41.897083 2026] [security2:error] [pid 302018:tid 302192] [client 20.197.195.24:10694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/222.php"] [unique_id "al9OxYAs9lPxxVAErz0EPQAAAK8"]
[Tue Jul 21 07:49:41.958611 2026] [security2:error] [pid 296703:tid 296798] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OxSn25uliftkV1n4nvwAATV4"]
[Tue Jul 21 07:49:41.958746 2026] [security2:error] [pid 296703:tid 296910] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OxSn25uliftkV1n4nvwAATV4"]
[Tue Jul 21 07:49:41.995405 2026] [security2:error] [pid 296703:tid 296888] [client 20.151.10.161:62851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/sixxis.php"] [unique_id "al9OxSn25uliftkV1n4nwQAAADc"]
[Tue Jul 21 07:49:42.072058 2026] [security2:error] [pid 302018:tid 302215] [client 4.204.201.85:51043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/test2.php"] [unique_id "al9OxoAs9lPxxVAErz0EQAAAAMY"]
[Tue Jul 21 07:49:42.196399 2026] [security2:error] [pid 302018:tid 302212] [client 122.186.204.214:61851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OxoAs9lPxxVAErz0EQQAAAMM"]
[Tue Jul 21 07:49:42.215741 2026] [security2:error] [pid 302018:tid 302212] [client 122.186.204.214:61851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9OxoAs9lPxxVAErz0EQQAAAMM"]
[Tue Jul 21 07:49:42.239068 2026] [security2:error] [pid 302018:tid 302236] [client 154.192.233.199:59046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OxoAs9lPxxVAErz0ERAAAANs"]
[Tue Jul 21 07:49:42.239186 2026] [security2:error] [pid 302018:tid 302236] [client 154.192.233.199:59046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OxoAs9lPxxVAErz0ERAAAANs"]
[Tue Jul 21 07:49:42.299236 2026] [security2:error] [pid 302018:tid 302251] [client 182.8.255.181:17175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OxoAs9lPxxVAErz0ERQAAAOo"]
[Tue Jul 21 07:49:42.299343 2026] [security2:error] [pid 302018:tid 302251] [client 182.8.255.181:17175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9OxoAs9lPxxVAErz0ERQAAAOo"]
[Tue Jul 21 07:49:42.376129 2026] [security2:error] [pid 302018:tid 302144] [remote 38.242.157.30:50082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9OxoAs9lPxxVAErz0ESwAAnns"]
[Tue Jul 21 07:49:42.454361 2026] [security2:error] [pid 302018:tid 302159] [client 117.247.80.59:34296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OxoAs9lPxxVAErz0ETgAAAI4"]
[Tue Jul 21 07:49:42.454463 2026] [security2:error] [pid 302018:tid 302159] [client 117.247.80.59:34296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OxoAs9lPxxVAErz0ETgAAAI4"]
[Tue Jul 21 07:49:42.624214 2026] [security2:error] [pid 302018:tid 302228] [client 20.197.192.193:8376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9OxoAs9lPxxVAErz0EVQAAANM"]
[Tue Jul 21 07:49:42.809570 2026] [security2:error] [pid 302018:tid 302173] [client 20.151.10.161:63369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/2P.update.php"] [unique_id "al9OxoAs9lPxxVAErz0EVwAAAJw"]
[Tue Jul 21 07:49:43.017649 2026] [security2:error] [pid 296703:tid 296873] [client 74.249.245.134:24794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/asd.php"] [unique_id "al9Oxyn25uliftkV1n4nzwAAACg"]
[Tue Jul 21 07:49:43.292782 2026] [security2:error] [pid 302018:tid 302186] [client 136.144.33.112:25653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Ox4As9lPxxVAErz0EXQAAAKk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:49:43.419075 2026] [security2:error] [pid 302018:tid 302155] [client 103.86.117.203:59864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ox4As9lPxxVAErz0EXgAAAIo"]
[Tue Jul 21 07:49:43.419198 2026] [security2:error] [pid 302018:tid 302155] [client 103.86.117.203:59864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ox4As9lPxxVAErz0EXgAAAIo"]
[Tue Jul 21 07:49:43.550638 2026] [security2:error] [pid 296703:tid 296840] [client 20.151.10.161:63468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/a.php"] [unique_id "al9Oxyn25uliftkV1n4n1gAAAAc"]
[Tue Jul 21 07:49:43.704326 2026] [security2:error] [pid 296703:tid 296960] [client 184.75.223.211:56280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Oxyn25uliftkV1n4n2AAAAH8"]
[Tue Jul 21 07:49:43.704443 2026] [security2:error] [pid 296703:tid 296960] [client 184.75.223.211:56280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Oxyn25uliftkV1n4n2AAAAH8"]
[Tue Jul 21 07:49:43.738215 2026] [security2:error] [pid 302018:tid 302230] [client 139.167.225.182:60084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ox4As9lPxxVAErz0EYAAAANU"]
[Tue Jul 21 07:49:43.738355 2026] [security2:error] [pid 302018:tid 302230] [client 139.167.225.182:60084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ox4As9lPxxVAErz0EYAAAANU"]
[Tue Jul 21 07:49:43.758129 2026] [security2:error] [pid 296703:tid 296865] [client 74.249.245.134:64436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/error.php"] [unique_id "al9Oxyn25uliftkV1n4n2wAAACA"]
[Tue Jul 21 07:49:43.852102 2026] [security2:error] [pid 302018:tid 302158] [client 20.197.195.24:10641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/test.php"] [unique_id "al9Ox4As9lPxxVAErz0EYQAAAI0"]
[Tue Jul 21 07:49:43.998097 2026] [security2:error] [pid 296703:tid 296858] [client 173.24.185.52:58576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Oxyn25uliftkV1n4n4gAAABk"]
[Tue Jul 21 07:49:43.998201 2026] [security2:error] [pid 296703:tid 296858] [client 173.24.185.52:58576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Oxyn25uliftkV1n4n4gAAABk"]
[Tue Jul 21 07:49:44.060770 2026] [security2:error] [pid 296703:tid 296906] [client 20.151.10.161:62938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/k.php"] [unique_id "al9OyCn25uliftkV1n4n5AAAAEk"]
[Tue Jul 21 07:49:44.121638 2026] [security2:error] [pid 302018:tid 302244] [client 20.197.195.24:16771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/aaa.php"] [unique_id "al9OyIAs9lPxxVAErz0EZAAAAOM"]
[Tue Jul 21 07:49:44.346660 2026] [security2:error] [pid 296703:tid 296847] [client 178.153.91.96:51130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OyCn25uliftkV1n4n6QAAAA4"]
[Tue Jul 21 07:49:44.346875 2026] [security2:error] [pid 296703:tid 296847] [client 178.153.91.96:51130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9OyCn25uliftkV1n4n6QAAAA4"]
[Tue Jul 21 07:49:44.357274 2026] [security2:error] [pid 296703:tid 296842] [client 4.204.201.85:51046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/buy.php"] [unique_id "al9OyCn25uliftkV1n4n6gAAAAk"]
[Tue Jul 21 07:49:44.383137 2026] [security2:error] [pid 296703:tid 296893] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/index.php"] [unique_id "al9OyCn25uliftkV1n4n6AAAADw"]
[Tue Jul 21 07:49:44.383827 2026] [security2:error] [pid 302018:tid 302237] [client 20.10.88.227:2306] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/robots.txt"] [unique_id "al9OyIAs9lPxxVAErz0EaQAAANw"]
[Tue Jul 21 07:49:44.446987 2026] [security2:error] [pid 296703:tid 296932] [client 103.29.114.44:19442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OyCn25uliftkV1n4n7AAAAGM"]
[Tue Jul 21 07:49:44.447142 2026] [security2:error] [pid 296703:tid 296932] [client 103.29.114.44:19442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OyCn25uliftkV1n4n7AAAAGM"]
[Tue Jul 21 07:49:44.675242 2026] [security2:error] [pid 296703:tid 296928] [client 59.96.220.140:62359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OyCn25uliftkV1n4n8gAAAF8"]
[Tue Jul 21 07:49:44.675364 2026] [security2:error] [pid 296703:tid 296928] [client 59.96.220.140:62359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9OyCn25uliftkV1n4n8gAAAF8"]
[Tue Jul 21 07:49:44.693975 2026] [security2:error] [pid 302018:tid 302173] [client 20.151.10.161:63402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/w.php"] [unique_id "al9OyIAs9lPxxVAErz0EbQAAAJw"]
[Tue Jul 21 07:49:44.867247 2026] [security2:error] [pid 296703:tid 296907] [client 194.99.104.35:55996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OyCn25uliftkV1n4n9AAAAEo"]
[Tue Jul 21 07:49:44.867344 2026] [security2:error] [pid 296703:tid 296907] [client 194.99.104.35:55996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9OyCn25uliftkV1n4n9AAAAEo"]
[Tue Jul 21 07:49:44.875166 2026] [security2:error] [pid 302018:tid 302176] [client 193.36.225.105:20017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9OyIAs9lPxxVAErz0EbgAAAJ8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:49:44.901975 2026] [security2:error] [pid 296703:tid 296854] [client 20.151.10.161:43782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/ms-edit.php"] [unique_id "al9OyCn25uliftkV1n4n9QAAABU"]
[Tue Jul 21 07:49:44.931953 2026] [security2:error] [pid 302018:tid 302172] [client 20.197.195.24:10724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/11.php"] [unique_id "al9OyIAs9lPxxVAErz0EcAAAAJs"]
[Tue Jul 21 07:49:45.068095 2026] [security2:error] [pid 302018:tid 302229] [client 202.143.127.214:51889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OyYAs9lPxxVAErz0EcQAAANQ"]
[Tue Jul 21 07:49:45.068264 2026] [security2:error] [pid 302018:tid 302229] [client 202.143.127.214:51889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OyYAs9lPxxVAErz0EcQAAANQ"]
[Tue Jul 21 07:49:45.071083 2026] [security2:error] [pid 296703:tid 296849] [client 20.226.60.151:61584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/sump1.php"] [unique_id "al9OySn25uliftkV1n4n9wAAABA"]
[Tue Jul 21 07:49:45.412291 2026] [security2:error] [pid 302018:tid 302268] [client 122.179.91.63:25549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OyYAs9lPxxVAErz0EdQAAAPs"]
[Tue Jul 21 07:49:45.412415 2026] [security2:error] [pid 302018:tid 302268] [client 122.179.91.63:25549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9OyYAs9lPxxVAErz0EdQAAAPs"]
[Tue Jul 21 07:49:45.435039 2026] [http2:warn] [pid 302018:tid 302177] [client 57.141.18.63:47140] h2_stream(302018-1002-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:45.557988 2026] [security2:error] [pid 302018:tid 302227] [client 20.151.10.161:64255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/insc.php"] [unique_id "al9OyYAs9lPxxVAErz0EdgAAANI"]
[Tue Jul 21 07:49:45.663154 2026] [security2:error] [pid 296703:tid 296870] [client 184.75.223.211:59230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9OySn25uliftkV1n4oBQAAACU"]
[Tue Jul 21 07:49:45.663237 2026] [security2:error] [pid 296703:tid 296870] [client 184.75.223.211:59230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9OySn25uliftkV1n4oBQAAACU"]
[Tue Jul 21 07:49:45.908099 2026] [core:alert] [pid 296703:tid 296950] [client 57.141.18.71:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:49:45.925086 2026] [security2:error] [pid 296703:tid 296912] [client 20.197.195.24:10668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/mac.php"] [unique_id "al9OySn25uliftkV1n4oEQAAAE8"]
[Tue Jul 21 07:49:45.966694 2026] [security2:error] [pid 302018:tid 302035] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OyYAs9lPxxVAErz0EeAAAig4"]
[Tue Jul 21 07:49:45.966858 2026] [security2:error] [pid 302018:tid 302155] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9OyYAs9lPxxVAErz0EeAAAig4"]
[Tue Jul 21 07:49:46.155736 2026] [security2:error] [pid 302018:tid 302137] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OyoAs9lPxxVAErz0EeQAAz3Q"]
[Tue Jul 21 07:49:46.155935 2026] [security2:error] [pid 302018:tid 302224] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OyoAs9lPxxVAErz0EeQAAz3Q"]
[Tue Jul 21 07:49:46.190932 2026] [security2:error] [pid 296703:tid 296948] [client 20.197.195.24:16779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/chosen.php"] [unique_id "al9Oyin25uliftkV1n4oGAAAAHM"]
[Tue Jul 21 07:49:46.252686 2026] [security2:error] [pid 296703:tid 296939] [client 74.249.245.134:24813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Oyin25uliftkV1n4oGwAAAGo"]
[Tue Jul 21 07:49:46.322662 2026] [security2:error] [pid 302018:tid 302246] [client 117.217.38.194:54226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OyoAs9lPxxVAErz0EfQAAAOU"]
[Tue Jul 21 07:49:46.322786 2026] [security2:error] [pid 302018:tid 302246] [client 117.217.38.194:54226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OyoAs9lPxxVAErz0EfQAAAOU"]
[Tue Jul 21 07:49:46.408677 2026] [security2:error] [pid 296703:tid 296927] [client 20.197.195.24:10696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/cream1.php"] [unique_id "al9Oyin25uliftkV1n4oHAAAAF4"]
[Tue Jul 21 07:49:46.626687 2026] [security2:error] [pid 302018:tid 302219] [client 20.151.10.161:64167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9OyoAs9lPxxVAErz0EgAAAAMo"]
[Tue Jul 21 07:49:46.673662 2026] [security2:error] [pid 302018:tid 302276] [client 4.204.201.85:57809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/ssend.php"] [unique_id "al9OyoAs9lPxxVAErz0EhAAAAQM"]
[Tue Jul 21 07:49:46.836349 2026] [security2:error] [pid 302018:tid 302062] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OyoAs9lPxxVAErz0EiAAA2Sk"]
[Tue Jul 21 07:49:46.836490 2026] [security2:error] [pid 302018:tid 302234] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9OyoAs9lPxxVAErz0EiAAA2Sk"]
[Tue Jul 21 07:49:46.972240 2026] [security2:error] [pid 302018:tid 302188] [client 20.151.10.161:43816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/222.php"] [unique_id "al9OyoAs9lPxxVAErz0EjwAAAKs"]
[Tue Jul 21 07:49:47.057874 2026] [security2:error] [pid 302018:tid 302192] [client 20.197.195.24:10716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/dr.php"] [unique_id "al9Oy4As9lPxxVAErz0ElgAAAK8"]
[Tue Jul 21 07:49:47.185295 2026] [security2:error] [pid 296703:tid 296949] [client 20.151.10.161:62919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/u.php"] [unique_id "al9Oyyn25uliftkV1n4oLAAAAHQ"]
[Tue Jul 21 07:49:47.195528 2026] [security2:error] [pid 302018:tid 302165] [client 106.215.181.8:21407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oy4As9lPxxVAErz0EmAAAAJQ"]
[Tue Jul 21 07:49:47.201309 2026] [security2:error] [pid 302018:tid 302165] [client 106.215.181.8:21407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oy4As9lPxxVAErz0EmAAAAJQ"]
[Tue Jul 21 07:49:47.333158 2026] [security2:error] [pid 296703:tid 296920] [client 136.144.33.239:63435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Oyyn25uliftkV1n4oKwAAAFc"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:49:47.386275 2026] [security2:error] [pid 302018:tid 302228] [client 20.197.195.24:10645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/x.php"] [unique_id "al9Oy4As9lPxxVAErz0EnQAAANM"]
[Tue Jul 21 07:49:47.400397 2026] [security2:error] [pid 302018:tid 302260] [client 104.207.42.103:58319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.42.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9Oy4As9lPxxVAErz0EmQAAAPM"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:49:47.543249 2026] [security2:error] [pid 302018:tid 302054] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Oy4As9lPxxVAErz0EpQABASE"]
[Tue Jul 21 07:49:47.543402 2026] [security2:error] [pid 302018:tid 302274] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Oy4As9lPxxVAErz0EpQABASE"]
[Tue Jul 21 07:49:47.668803 2026] [security2:error] [pid 302018:tid 302215] [client 20.197.195.24:10741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/155.php"] [unique_id "al9Oy4As9lPxxVAErz0EqAAAAMY"]
[Tue Jul 21 07:49:47.799349 2026] [security2:error] [pid 302018:tid 302225] [client 152.59.154.239:2148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oy4As9lPxxVAErz0EqwAAANA"]
[Tue Jul 21 07:49:47.799462 2026] [security2:error] [pid 302018:tid 302225] [client 152.59.154.239:2148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oy4As9lPxxVAErz0EqwAAANA"]
[Tue Jul 21 07:49:47.826721 2026] [security2:error] [pid 296703:tid 296901] [client 74.249.245.134:64391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/bless.php"] [unique_id "al9Oyyn25uliftkV1n4oOQAAAEQ"]
[Tue Jul 21 07:49:47.913755 2026] [security2:error] [pid 296703:tid 296843] [client 20.197.195.24:16798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/ops.php"] [unique_id "al9Oyyn25uliftkV1n4oOwAAAAo"]
[Tue Jul 21 07:49:47.950129 2026] [security2:error] [pid 296703:tid 296850] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Oyyn25uliftkV1n4oPgAAABE"]
[Tue Jul 21 07:49:47.964220 2026] [security2:error] [pid 296703:tid 296952] [client 193.36.225.60:64827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Oyyn25uliftkV1n4oPwAAAHc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:49:47.990804 2026] [security2:error] [pid 302018:tid 302177] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Oy4As9lPxxVAErz0ErAAAoIY"]
[Tue Jul 21 07:49:48.014434 2026] [security2:error] [pid 296703:tid 296954] [client 194.99.104.35:56012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OzCn25uliftkV1n4oQAAAAHk"]
[Tue Jul 21 07:49:48.014542 2026] [security2:error] [pid 296703:tid 296954] [client 194.99.104.35:56012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9OzCn25uliftkV1n4oQAAAAHk"]
[Tue Jul 21 07:49:48.047227 2026] [security2:error] [pid 302018:tid 302178] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9OzIAs9lPxxVAErz0ErQAAAKE"]
[Tue Jul 21 07:49:48.047310 2026] [security2:error] [pid 302018:tid 302178] [client 34.182.235.64:0] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "webdisk.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9OzIAs9lPxxVAErz0ErQAAAKE"]
[Tue Jul 21 07:49:48.055588 2026] [security2:error] [pid 302018:tid 302238] [client 41.68.90.219:59905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OzIAs9lPxxVAErz0ErgAAAN0"]
[Tue Jul 21 07:49:48.055699 2026] [security2:error] [pid 302018:tid 302238] [client 41.68.90.219:59905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9OzIAs9lPxxVAErz0ErgAAAN0"]
[Tue Jul 21 07:49:48.170856 2026] [security2:error] [pid 302018:tid 302234] [client 20.197.195.24:13766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/file31.php"] [unique_id "al9OzIAs9lPxxVAErz0EsQAAANk"]
[Tue Jul 21 07:49:48.304724 2026] [security2:error] [pid 302018:tid 302162] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9OzIAs9lPxxVAErz0EsgAAAJE"]
[Tue Jul 21 07:49:48.325338 2026] [security2:error] [pid 296703:tid 296904] [client 20.197.195.24:16793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/file6.php"] [unique_id "al9OzCn25uliftkV1n4oTQAAAEc"]
[Tue Jul 21 07:49:48.387988 2026] [security2:error] [pid 296703:tid 296893] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9OzCn25uliftkV1n4oUwAAADw"]
[Tue Jul 21 07:49:48.404644 2026] [security2:error] [pid 302018:tid 302226] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9OzIAs9lPxxVAErz0EtAAAANE"]
[Tue Jul 21 07:49:48.492450 2026] [security2:error] [pid 302018:tid 302267] [client 122.162.144.145:19633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OzIAs9lPxxVAErz0EtQAAAPo"]
[Tue Jul 21 07:49:48.492645 2026] [security2:error] [pid 302018:tid 302267] [client 122.162.144.145:19633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9OzIAs9lPxxVAErz0EtQAAAPo"]
[Tue Jul 21 07:49:48.516629 2026] [security2:error] [pid 296703:tid 296917] [client 20.220.225.223:31710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9OzCn25uliftkV1n4oVQAAAFQ"]
[Tue Jul 21 07:49:48.657864 2026] [security2:error] [pid 296703:tid 296844] [client 74.249.245.134:64116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/storage/index.php"] [unique_id "al9OzCn25uliftkV1n4oVwAAAAs"]
[Tue Jul 21 07:49:48.688090 2026] [security2:error] [pid 296703:tid 296915] [client 20.151.10.161:63391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/sss.php"] [unique_id "al9OzCn25uliftkV1n4oWQAAAFI"]
[Tue Jul 21 07:49:48.691467 2026] [security2:error] [pid 296703:tid 296863] [client 122.164.127.47:62294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OzCn25uliftkV1n4oWgAAAB4"]
[Tue Jul 21 07:49:48.692032 2026] [security2:error] [pid 296703:tid 296863] [client 122.164.127.47:62294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9OzCn25uliftkV1n4oWgAAAB4"]
[Tue Jul 21 07:49:48.865696 2026] [security2:error] [pid 302018:tid 302277] [client 20.197.195.24:16782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/adminfuns.php"] [unique_id "al9OzIAs9lPxxVAErz0EyQAAAQQ"]
[Tue Jul 21 07:49:48.925569 2026] [security2:error] [pid 296703:tid 296956] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9OzCn25uliftkV1n4oZQAAAHs"]
[Tue Jul 21 07:49:48.989909 2026] [security2:error] [pid 302018:tid 302163] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9OzIAs9lPxxVAErz0EzwAAAJI"]
[Tue Jul 21 07:49:49.036530 2026] [security2:error] [pid 296703:tid 296856] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9OzSn25uliftkV1n4oZwAAABc"]
[Tue Jul 21 07:49:49.143679 2026] [security2:error] [pid 302018:tid 311331] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OzYAs9lPxxVAErz0E0wAAp4U"]
[Tue Jul 21 07:49:49.143801 2026] [security2:error] [pid 302018:tid 302184] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9OzYAs9lPxxVAErz0E0wAAp4U"]
[Tue Jul 21 07:49:49.173843 2026] [security2:error] [pid 302018:tid 302166] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9OzYAs9lPxxVAErz0E1gAAAJU"]
[Tue Jul 21 07:49:49.396428 2026] [security2:error] [pid 302018:tid 302243] [client 20.197.195.24:10653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/goods.php"] [unique_id "al9OzYAs9lPxxVAErz0E2wAAAOI"]
[Tue Jul 21 07:49:49.581931 2026] [security2:error] [pid 302018:tid 302215] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9OzYAs9lPxxVAErz0E4gAAAMY"]
[Tue Jul 21 07:49:49.590565 2026] [security2:error] [pid 296703:tid 296944] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9OzSn25uliftkV1n4obgAAAG8"]
[Tue Jul 21 07:49:49.624557 2026] [security2:error] [pid 296703:tid 296868] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9OzSn25uliftkV1n4ocAAAACM"]
[Tue Jul 21 07:49:49.670577 2026] [security2:error] [pid 302018:tid 302236] [client 20.151.10.161:63483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/sss.php"] [unique_id "al9OzYAs9lPxxVAErz0E4wAAANs"]
[Tue Jul 21 07:49:49.686719 2026] [security2:error] [pid 302018:tid 302028] [remote 217.182.128.41:43438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9OzYAs9lPxxVAErz0E5AAAswc"]
[Tue Jul 21 07:49:49.694007 2026] [security2:error] [pid 302018:tid 302155] [client 103.166.103.129:62456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OzYAs9lPxxVAErz0E5QAAAIo"]
[Tue Jul 21 07:49:49.694127 2026] [security2:error] [pid 302018:tid 302155] [client 103.166.103.129:62456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9OzYAs9lPxxVAErz0E5QAAAIo"]
[Tue Jul 21 07:49:49.726061 2026] [security2:error] [pid 296703:tid 296943] [client 20.197.195.24:10722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/100.php"] [unique_id "al9OzSn25uliftkV1n4ocgAAAG4"]
[Tue Jul 21 07:49:49.936125 2026] [security2:error] [pid 302018:tid 302249] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9OzYAs9lPxxVAErz0E7AAAAOg"]
[Tue Jul 21 07:49:50.010455 2026] [security2:error] [pid 302018:tid 302163] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9OzoAs9lPxxVAErz0E7gAAAJI"]
[Tue Jul 21 07:49:50.059533 2026] [security2:error] [pid 296703:tid 296857] [client 20.197.195.24:10693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/about.php"] [unique_id "al9Ozin25uliftkV1n4odgAAABg"]
[Tue Jul 21 07:49:50.107207 2026] [security2:error] [pid 296703:tid 296850] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Ozin25uliftkV1n4oeAAAABE"]
[Tue Jul 21 07:49:50.129630 2026] [security2:error] [pid 302018:tid 302157] [client 20.197.195.24:10655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/about.php"] [unique_id "al9OzoAs9lPxxVAErz0E8AAAAIw"]
[Tue Jul 21 07:49:50.226671 2026] [security2:error] [pid 296703:tid 296891] [client 20.197.195.24:10686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/admin.php"] [unique_id "al9Ozin25uliftkV1n4oegAAADo"]
[Tue Jul 21 07:49:50.358867 2026] [security2:error] [pid 296703:tid 296879] [client 20.197.195.24:16708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/admin.php"] [unique_id "al9Ozin25uliftkV1n4oewAAAC4"]
[Tue Jul 21 07:49:50.362112 2026] [security2:error] [pid 302018:tid 302264] [client 74.249.245.134:64103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/g.php"] [unique_id "al9OzoAs9lPxxVAErz0E9gAAAPc"]
[Tue Jul 21 07:49:50.471992 2026] [security2:error] [pid 302018:tid 302262] [client 20.197.195.24:10728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/themes.php"] [unique_id "al9OzoAs9lPxxVAErz0E-QAAAPU"]
[Tue Jul 21 07:49:50.503003 2026] [security2:error] [pid 296703:tid 296836] [client 4.204.201.85:51024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/item.php"] [unique_id "al9Ozin25uliftkV1n4ofgAAAAM"]
[Tue Jul 21 07:49:50.539253 2026] [security2:error] [pid 302018:tid 302258] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9OzoAs9lPxxVAErz0E_QAAAPE"]
[Tue Jul 21 07:49:50.552142 2026] [security2:error] [pid 302018:tid 302164] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9OzoAs9lPxxVAErz0E_gAAAJM"]
[Tue Jul 21 07:49:50.617765 2026] [security2:error] [pid 302018:tid 302199] [client 223.236.153.128:16036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OzoAs9lPxxVAErz0FBAAAALY"]
[Tue Jul 21 07:49:50.617870 2026] [security2:error] [pid 302018:tid 302199] [client 223.236.153.128:16036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9OzoAs9lPxxVAErz0FBAAAALY"]
[Tue Jul 21 07:49:50.621385 2026] [security2:error] [pid 302018:tid 302165] [client 20.197.195.24:10672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/.well-known/about.php"] [unique_id "al9OzoAs9lPxxVAErz0FBQAAAJQ"]
[Tue Jul 21 07:49:50.627376 2026] [security2:error] [pid 302018:tid 302265] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9OzoAs9lPxxVAErz0FBgAAAPg"]
[Tue Jul 21 07:49:50.673781 2026] [security2:error] [pid 302018:tid 302260] [client 20.197.195.24:10733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9OzoAs9lPxxVAErz0FBwAAAPM"]
[Tue Jul 21 07:49:50.735010 2026] [security2:error] [pid 302018:tid 302228] [client 20.197.195.24:16752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wefile.php"] [unique_id "al9OzoAs9lPxxVAErz0FCAAAANM"]
[Tue Jul 21 07:49:50.784983 2026] [security2:error] [pid 302018:tid 302209] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9OzoAs9lPxxVAErz0FCQAAAMA"]
[Tue Jul 21 07:49:50.788595 2026] [security2:error] [pid 302018:tid 302150] [client 20.197.195.24:10730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9OzoAs9lPxxVAErz0FCgAAAIU"]
[Tue Jul 21 07:49:50.886835 2026] [security2:error] [pid 296703:tid 296917] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Ozin25uliftkV1n4ohQAAAFQ"]
[Tue Jul 21 07:49:50.891743 2026] [security2:error] [pid 296703:tid 296932] [client 173.239.218.204:22609] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://"] [hostname "agrocibus.com.br"] [uri "/"] [unique_id "al9Ozin25uliftkV1n4ohgAAAGM"]
[Tue Jul 21 07:49:51.001791 2026] [security2:error] [pid 296703:tid 296871] [client 20.151.10.161:63397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/c.php"] [unique_id "al9Ozyn25uliftkV1n4oiQAAACY"]
[Tue Jul 21 07:49:51.011384 2026] [security2:error] [pid 296703:tid 296844] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Ozyn25uliftkV1n4oigAAAAs"]
[Tue Jul 21 07:49:51.039725 2026] [security2:error] [pid 296703:tid 296915] [client 74.249.245.134:64122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/nf.php"] [unique_id "al9Ozyn25uliftkV1n4ojAAAAFI"]
[Tue Jul 21 07:49:51.048941 2026] [security2:error] [pid 302018:tid 302172] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Oz4As9lPxxVAErz0FDQAAAJs"]
[Tue Jul 21 07:49:51.192611 2026] [security2:error] [pid 296703:tid 296854] [client 62.102.148.187:47028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Ozyn25uliftkV1n4ojgAAABU"]
[Tue Jul 21 07:49:51.192716 2026] [security2:error] [pid 296703:tid 296854] [client 62.102.148.187:47028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Ozyn25uliftkV1n4ojgAAABU"]
[Tue Jul 21 07:49:51.194909 2026] [security2:error] [pid 296703:tid 296906] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Ozyn25uliftkV1n4ojwAAAEk"]
[Tue Jul 21 07:49:51.255704 2026] [security2:error] [pid 296703:tid 296841] [client 20.197.192.193:8381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Ozyn25uliftkV1n4okAAAAAg"]
[Tue Jul 21 07:49:51.277546 2026] [security2:error] [pid 296703:tid 296882] [client 194.99.104.35:49066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Ozyn25uliftkV1n4okQAAADE"]
[Tue Jul 21 07:49:51.277611 2026] [security2:error] [pid 296703:tid 296882] [client 194.99.104.35:49066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Ozyn25uliftkV1n4okQAAADE"]
[Tue Jul 21 07:49:51.278764 2026] [security2:error] [pid 302018:tid 302159] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Oz4As9lPxxVAErz0FFQAAAI4"]
[Tue Jul 21 07:49:51.289503 2026] [security2:error] [pid 296703:tid 296925] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Ozyn25uliftkV1n4okgAAAFw"]
[Tue Jul 21 07:49:51.321664 2026] [security2:error] [pid 302018:tid 302263] [client 20.197.195.24:10670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Oz4As9lPxxVAErz0FFgAAAPY"]
[Tue Jul 21 07:49:51.349254 2026] [security2:error] [pid 302018:tid 302151] [client 20.151.10.161:43961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Oz4As9lPxxVAErz0FFwAAAIY"]
[Tue Jul 21 07:49:51.396370 2026] [security2:error] [pid 302018:tid 302185] [client 20.220.225.223:55518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Oz4As9lPxxVAErz0FGAAAAKg"]
[Tue Jul 21 07:49:51.403047 2026] [security2:error] [pid 302018:tid 302091] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oz4As9lPxxVAErz0FGQAAp0Y"]
[Tue Jul 21 07:49:51.403172 2026] [security2:error] [pid 302018:tid 302184] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Oz4As9lPxxVAErz0FGQAAp0Y"]
[Tue Jul 21 07:49:51.450581 2026] [security2:error] [pid 302018:tid 302171] [client 98.159.37.154:58099] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://"] [hostname "agrocibus.com.br"] [uri "/"] [unique_id "al9Oz4As9lPxxVAErz0FHAAAAJo"]
[Tue Jul 21 07:49:51.536974 2026] [security2:error] [pid 302018:tid 302162] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Oz4As9lPxxVAErz0FHgAAAJE"]
[Tue Jul 21 07:49:51.601045 2026] [security2:error] [pid 302018:tid 302188] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Oz4As9lPxxVAErz0FHwAAAKs"]
[Tue Jul 21 07:49:51.605982 2026] [security2:error] [pid 302018:tid 302156] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Oz4As9lPxxVAErz0FIAAAAIs"]
[Tue Jul 21 07:49:51.622778 2026] [http2:warn] [pid 302018:tid 302269] [client 173.252.95.38:53960] h2_stream(302018-1075-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:51.693303 2026] [security2:error] [pid 296703:tid 296955] [client 193.36.225.71:50189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Ozyn25uliftkV1n4omQAAAHo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:49:51.742372 2026] [security2:error] [pid 302018:tid 302195] [client 20.197.195.24:10732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/8.php"] [unique_id "al9Oz4As9lPxxVAErz0FIwAAALI"]
[Tue Jul 21 07:49:51.853264 2026] [security2:error] [pid 296703:tid 296936] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Ozyn25uliftkV1n4ooAAAAGc"]
[Tue Jul 21 07:49:51.863211 2026] [security2:error] [pid 296703:tid 296862] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Ozyn25uliftkV1n4ooQAAAB0"]
[Tue Jul 21 07:49:52.023334 2026] [security2:error] [pid 296703:tid 296944] [client 20.197.195.24:16828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9O0Cn25uliftkV1n4opAAAAG8"]
[Tue Jul 21 07:49:52.114694 2026] [security2:error] [pid 302018:tid 302265] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9O0IAs9lPxxVAErz0FJgAAAPg"]
[Tue Jul 21 07:49:52.125603 2026] [security2:error] [pid 296703:tid 296870] [client 20.151.10.161:64176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/aa.php"] [unique_id "al9O0Cn25uliftkV1n4oqAAAACU"]
[Tue Jul 21 07:49:52.162476 2026] [security2:error] [pid 302018:tid 302268] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9O0IAs9lPxxVAErz0FKAAAAPs"]
[Tue Jul 21 07:49:52.169553 2026] [security2:error] [pid 296703:tid 296886] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9O0Cn25uliftkV1n4orAAAADU"]
[Tue Jul 21 07:49:52.285580 2026] [security2:error] [pid 302018:tid 302212] [client 4.204.201.85:50980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/ss.php"] [unique_id "al9O0IAs9lPxxVAErz0FKQAAAMM"]
[Tue Jul 21 07:49:52.443245 2026] [security2:error] [pid 296703:tid 296877] [client 59.96.220.140:62888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9O0Cn25uliftkV1n4orQAAACw"]
[Tue Jul 21 07:49:52.443359 2026] [security2:error] [pid 296703:tid 296877] [client 59.96.220.140:62888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9O0Cn25uliftkV1n4orQAAACw"]
[Tue Jul 21 07:49:52.455245 2026] [security2:error] [pid 302018:tid 302211] [client 74.249.245.134:64444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/xda.php"] [unique_id "al9O0IAs9lPxxVAErz0FKwAAAMI"]
[Tue Jul 21 07:49:52.601185 2026] [security2:error] [pid 302018:tid 302208] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9O0IAs9lPxxVAErz0FMAAAAL8"]
[Tue Jul 21 07:49:52.607844 2026] [security2:error] [pid 302018:tid 302174] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9O0IAs9lPxxVAErz0FMQAAAJ0"]
[Tue Jul 21 07:49:52.618322 2026] [security2:error] [pid 302018:tid 302230] [client 74.249.245.134:64411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/gettest.php"] [unique_id "al9O0IAs9lPxxVAErz0FMwAAANU"]
[Tue Jul 21 07:49:52.774709 2026] [security2:error] [pid 302018:tid 302199] [client 182.8.255.181:17676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9O0IAs9lPxxVAErz0FOAAAALY"]
[Tue Jul 21 07:49:52.775278 2026] [security2:error] [pid 302018:tid 302199] [client 182.8.255.181:17676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9O0IAs9lPxxVAErz0FOAAAALY"]
[Tue Jul 21 07:49:52.856426 2026] [security2:error] [pid 296703:tid 296942] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9O0Cn25uliftkV1n4otAAAAG0"]
[Tue Jul 21 07:49:52.871054 2026] [security2:error] [pid 302018:tid 302233] [client 122.186.204.214:62388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O0IAs9lPxxVAErz0FOwAAANg"]
[Tue Jul 21 07:49:52.871149 2026] [security2:error] [pid 302018:tid 302233] [client 122.186.204.214:62388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O0IAs9lPxxVAErz0FOwAAANg"]
[Tue Jul 21 07:49:52.918319 2026] [security2:error] [pid 302018:tid 302264] [client 20.197.195.24:10723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/f6.php"] [unique_id "al9O0IAs9lPxxVAErz0FPAAAAPc"]
[Tue Jul 21 07:49:52.979225 2026] [security2:error] [pid 302018:tid 302051] [remote 13.41.15.21:45066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.15.41.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9O0IAs9lPxxVAErz0FPQAAoR4"]
[Tue Jul 21 07:49:53.009729 2026] [security2:error] [pid 296703:tid 296708] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O0Sn25uliftkV1n4otwAADwQ"]
[Tue Jul 21 07:49:53.009861 2026] [security2:error] [pid 296703:tid 296848] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O0Sn25uliftkV1n4otwAADwQ"]
[Tue Jul 21 07:49:53.066482 2026] [security2:error] [pid 302018:tid 302239] [client 128.127.105.184:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9O0YAs9lPxxVAErz0FQAAAAN4"]
[Tue Jul 21 07:49:53.066567 2026] [security2:error] [pid 302018:tid 302239] [client 128.127.105.184:54384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9O0YAs9lPxxVAErz0FQAAAAN4"]
[Tue Jul 21 07:49:53.148926 2026] [http2:warn] [pid 302018:tid 302168] [client 173.252.95.37:41404] h2_stream(302018-1090-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:49:53.151142 2026] [security2:error] [pid 302018:tid 302274] [client 117.247.80.59:23691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O0YAs9lPxxVAErz0FQQAAAQE"]
[Tue Jul 21 07:49:53.151253 2026] [security2:error] [pid 302018:tid 302274] [client 117.247.80.59:23691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O0YAs9lPxxVAErz0FQQAAAQE"]
[Tue Jul 21 07:49:53.369158 2026] [security2:error] [pid 302018:tid 302224] [client 4.204.201.85:57799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/hypo.php"] [unique_id "al9O0YAs9lPxxVAErz0FRAAAAM8"]
[Tue Jul 21 07:49:53.608583 2026] [security2:error] [pid 302018:tid 302246] [client 20.151.10.161:64229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/100.php"] [unique_id "al9O0YAs9lPxxVAErz0FSAAAAOU"]
[Tue Jul 21 07:49:53.896548 2026] [security2:error] [pid 302018:tid 302268] [client 103.86.117.203:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O0YAs9lPxxVAErz0FTAAAAPs"]
[Tue Jul 21 07:49:53.896671 2026] [security2:error] [pid 302018:tid 302268] [client 103.86.117.203:60412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O0YAs9lPxxVAErz0FTAAAAPs"]
[Tue Jul 21 07:49:53.901728 2026] [security2:error] [pid 296703:tid 296928] [client 74.249.245.134:64445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/tfm.php"] [unique_id "al9O0Sn25uliftkV1n4owgAAAF8"]
[Tue Jul 21 07:49:53.916675 2026] [security2:error] [pid 296703:tid 296894] [client 4.204.201.85:51005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/users.php"] [unique_id "al9O0Sn25uliftkV1n4owwAAAD0"]
[Tue Jul 21 07:49:54.172554 2026] [security2:error] [pid 296703:tid 296925] [client 20.197.195.24:10675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/inputs.php"] [unique_id "al9O0in25uliftkV1n4oygAAAFw"]
[Tue Jul 21 07:49:54.219316 2026] [security2:error] [pid 296703:tid 296939] [client 74.249.245.134:64406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/shell.php"] [unique_id "al9O0in25uliftkV1n4oywAAAGo"]
[Tue Jul 21 07:49:54.293091 2026] [security2:error] [pid 296703:tid 296899] [client 139.167.225.182:60731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O0in25uliftkV1n4ozQAAAEI"]
[Tue Jul 21 07:49:54.293217 2026] [security2:error] [pid 296703:tid 296899] [client 139.167.225.182:60731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O0in25uliftkV1n4ozQAAAEI"]
[Tue Jul 21 07:49:54.329845 2026] [security2:error] [pid 302018:tid 302204] [client 128.127.105.184:54388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9O0oAs9lPxxVAErz0FUgAAALs"]
[Tue Jul 21 07:49:54.330011 2026] [security2:error] [pid 302018:tid 302204] [client 128.127.105.184:54388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9O0oAs9lPxxVAErz0FUgAAALs"]
[Tue Jul 21 07:49:54.410202 2026] [security2:error] [pid 296703:tid 296930] [client 20.220.225.223:19310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9O0in25uliftkV1n4ozgAAAGE"]
[Tue Jul 21 07:49:54.526747 2026] [security2:error] [pid 296703:tid 296895] [client 4.204.201.85:51064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/177.php"] [unique_id "al9O0in25uliftkV1n4ozwAAAD4"]
[Tue Jul 21 07:49:54.603633 2026] [security2:error] [pid 302018:tid 302187] [client 173.24.185.52:59095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9O0oAs9lPxxVAErz0FUwAAAKo"]
[Tue Jul 21 07:49:54.603736 2026] [security2:error] [pid 302018:tid 302187] [client 173.24.185.52:59095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9O0oAs9lPxxVAErz0FUwAAAKo"]
[Tue Jul 21 07:49:54.676013 2026] [security2:error] [pid 302018:tid 302167] [client 20.197.195.24:16802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/inputs.php"] [unique_id "al9O0oAs9lPxxVAErz0FVgAAAJY"]
[Tue Jul 21 07:49:54.812561 2026] [security2:error] [pid 296703:tid 296933] [client 178.153.91.96:30743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9O0in25uliftkV1n4o1wAAAGQ"]
[Tue Jul 21 07:49:54.812669 2026] [security2:error] [pid 296703:tid 296933] [client 178.153.91.96:30743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9O0in25uliftkV1n4o1wAAAGQ"]
[Tue Jul 21 07:49:54.875591 2026] [security2:error] [pid 302018:tid 302228] [client 20.197.195.24:10697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/classwithtostring.php"] [unique_id "al9O0oAs9lPxxVAErz0FWwAAANM"]
[Tue Jul 21 07:49:54.933504 2026] [security2:error] [pid 302018:tid 302236] [client 4.204.201.85:50971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/config.php"] [unique_id "al9O0oAs9lPxxVAErz0FXQAAANs"]
[Tue Jul 21 07:49:55.088245 2026] [security2:error] [pid 302018:tid 302213] [client 20.197.195.24:13797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9O04As9lPxxVAErz0FYQAAAMQ"]
[Tue Jul 21 07:49:55.313646 2026] [security2:error] [pid 296703:tid 296829] [remote 65.111.20.186:44075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9O0Sn25uliftkV1n4ougAAIH0"]
[Tue Jul 21 07:49:55.415919 2026] [security2:error] [pid 302018:tid 302180] [client 4.204.201.85:57842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/gettest.php"] [unique_id "al9O04As9lPxxVAErz0FZgAAAKM"]
[Tue Jul 21 07:49:55.650438 2026] [security2:error] [pid 302018:tid 302151] [client 20.151.10.161:64139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/footer.php"] [unique_id "al9O04As9lPxxVAErz0FZwAAAIY"]
[Tue Jul 21 07:49:55.738211 2026] [security2:error] [pid 302018:tid 302153] [client 103.29.114.44:23012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O04As9lPxxVAErz0FagAAAIg"]
[Tue Jul 21 07:49:55.738329 2026] [security2:error] [pid 302018:tid 302153] [client 103.29.114.44:23012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O04As9lPxxVAErz0FagAAAIg"]
[Tue Jul 21 07:49:55.758794 2026] [security2:error] [pid 302018:tid 302233] [client 62.102.148.187:47036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9O04As9lPxxVAErz0FawAAANg"]
[Tue Jul 21 07:49:55.758942 2026] [security2:error] [pid 302018:tid 302233] [client 62.102.148.187:47036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9O04As9lPxxVAErz0FawAAANg"]
[Tue Jul 21 07:49:55.770466 2026] [access_compat:error] [pid 302018:tid 302226] [client 162.241.63.68:33806] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:49:55.879278 2026] [security2:error] [pid 302018:tid 302174] [client 122.179.91.63:13422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9O04As9lPxxVAErz0FbwAAAJ0"]
[Tue Jul 21 07:49:55.879375 2026] [security2:error] [pid 302018:tid 302174] [client 122.179.91.63:13422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9O04As9lPxxVAErz0FbwAAAJ0"]
[Tue Jul 21 07:49:55.926806 2026] [security2:error] [pid 302018:tid 302276] [client 202.143.127.214:52352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O04As9lPxxVAErz0FcAAAAQM"]
[Tue Jul 21 07:49:55.926974 2026] [security2:error] [pid 302018:tid 302276] [client 202.143.127.214:52352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O04As9lPxxVAErz0FcAAAAQM"]
[Tue Jul 21 07:49:55.981043 2026] [security2:error] [pid 302018:tid 302195] [client 20.197.195.24:16785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wp-blog.php"] [unique_id "al9O04As9lPxxVAErz0FcQAAALI"]
[Tue Jul 21 07:49:56.183101 2026] [security2:error] [pid 302018:tid 302164] [client 193.36.225.56:49863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9O1IAs9lPxxVAErz0FcwAAAJM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:49:56.244428 2026] [security2:error] [pid 302018:tid 302266] [client 4.204.201.85:50946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/min.php"] [unique_id "al9O1IAs9lPxxVAErz0FdgAAAPk"]
[Tue Jul 21 07:49:56.641761 2026] [security2:error] [pid 302018:tid 302108] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O1IAs9lPxxVAErz0FfQAA11c"]
[Tue Jul 21 07:49:56.641920 2026] [security2:error] [pid 302018:tid 302232] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O1IAs9lPxxVAErz0FfQAA11c"]
[Tue Jul 21 07:49:56.732440 2026] [security2:error] [pid 302018:tid 302032] [remote 57.141.18.115:46098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9O1IAs9lPxxVAErz0FfAAAwws"]
[Tue Jul 21 07:49:56.736396 2026] [security2:error] [pid 302018:tid 302215] [client 20.220.225.223:32293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/dp.php"] [unique_id "al9O1IAs9lPxxVAErz0FfwAAAMY"]
[Tue Jul 21 07:49:56.743614 2026] [security2:error] [pid 302018:tid 302053] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9O1IAs9lPxxVAErz0FgAAAsyA"]
[Tue Jul 21 07:49:56.743720 2026] [security2:error] [pid 302018:tid 302196] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9O1IAs9lPxxVAErz0FgAAAsyA"]
[Tue Jul 21 07:49:56.756483 2026] [security2:error] [pid 296703:tid 296954] [client 20.197.195.24:10689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9O1Cn25uliftkV1n4o8QAAAHk"]
[Tue Jul 21 07:49:56.807002 2026] [security2:error] [pid 302018:tid 302165] [client 117.217.38.194:54718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O1IAs9lPxxVAErz0FgQAAAJQ"]
[Tue Jul 21 07:49:56.807134 2026] [security2:error] [pid 302018:tid 302165] [client 117.217.38.194:54718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O1IAs9lPxxVAErz0FgQAAAJQ"]
[Tue Jul 21 07:49:56.908146 2026] [security2:error] [pid 296703:tid 296731] [remote 97.74.93.24:46968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9O1Cn25uliftkV1n4o9wAAexs"]
[Tue Jul 21 07:49:56.994510 2026] [security2:error] [pid 302018:tid 302158] [client 4.204.201.85:57829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/dvjul.php"] [unique_id "al9O1IAs9lPxxVAErz0FhQAAAI0"]
[Tue Jul 21 07:49:57.051887 2026] [security2:error] [pid 302018:tid 302180] [client 74.249.245.134:8809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/3.php"] [unique_id "al9O1YAs9lPxxVAErz0FiAAAAKM"]
[Tue Jul 21 07:49:57.054608 2026] [security2:error] [pid 302018:tid 302256] [client 74.249.245.134:64110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ws81.php"] [unique_id "al9O1YAs9lPxxVAErz0FiQAAAO8"]
[Tue Jul 21 07:49:57.312262 2026] [security2:error] [pid 302018:tid 302174] [client 4.204.201.85:57731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/biufile.php"] [unique_id "al9O1YAs9lPxxVAErz0FkQAAAJ0"]
[Tue Jul 21 07:49:57.379375 2026] [security2:error] [pid 296703:tid 296816] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9O1Sn25uliftkV1n4o_AAADXA"]
[Tue Jul 21 07:49:57.379536 2026] [security2:error] [pid 296703:tid 296846] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9O1Sn25uliftkV1n4o_AAADXA"]
[Tue Jul 21 07:49:57.496470 2026] [security2:error] [pid 296703:tid 296841] [client 20.220.225.223:35037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/old.php"] [unique_id "al9O1Sn25uliftkV1n4pAAAAAAg"]
[Tue Jul 21 07:49:57.528691 2026] [security2:error] [pid 296703:tid 296919] [client 20.197.195.24:10683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/ms-edit.php"] [unique_id "al9O1Sn25uliftkV1n4pAQAAAFY"]
[Tue Jul 21 07:49:57.630025 2026] [security2:error] [pid 302018:tid 302178] [client 20.151.10.161:64151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/users.php"] [unique_id "al9O1YAs9lPxxVAErz0FkgAAAKE"]
[Tue Jul 21 07:49:57.732587 2026] [security2:error] [pid 302018:tid 302192] [client 193.36.225.120:56397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9O1IAs9lPxxVAErz0FewAAAK8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:49:57.889994 2026] [security2:error] [pid 302018:tid 302204] [client 106.215.181.8:30248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O1YAs9lPxxVAErz0FlAAAALs"]
[Tue Jul 21 07:49:57.899765 2026] [security2:error] [pid 302018:tid 302204] [client 106.215.181.8:30248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O1YAs9lPxxVAErz0FlAAAALs"]
[Tue Jul 21 07:49:57.904597 2026] [security2:error] [pid 302018:tid 302265] [client 4.204.201.85:50975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/av.php"] [unique_id "al9O1YAs9lPxxVAErz0FlQAAAPg"]
[Tue Jul 21 07:49:57.936499 2026] [security2:error] [pid 302018:tid 302257] [client 20.197.195.24:10715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9O1YAs9lPxxVAErz0FmAAAAPA"]
[Tue Jul 21 07:49:58.163101 2026] [security2:error] [pid 302018:tid 302061] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9O1oAs9lPxxVAErz0FmgAAnyg"]
[Tue Jul 21 07:49:58.163285 2026] [security2:error] [pid 302018:tid 302176] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9O1oAs9lPxxVAErz0FmgAAnyg"]
[Tue Jul 21 07:49:58.274922 2026] [security2:error] [pid 302018:tid 302241] [client 20.197.195.24:10667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9O1oAs9lPxxVAErz0FoAAAAOA"]
[Tue Jul 21 07:49:58.408671 2026] [security2:error] [pid 296703:tid 296900] [client 74.249.245.134:24775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/222.php"] [unique_id "al9O1in25uliftkV1n4pDgAAAEM"]
[Tue Jul 21 07:49:58.420638 2026] [security2:error] [pid 302018:tid 302213] [client 74.249.245.134:65147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/mds.php"] [unique_id "al9O1oAs9lPxxVAErz0FogAAAMQ"]
[Tue Jul 21 07:49:58.511532 2026] [security2:error] [pid 296703:tid 296892] [client 74.7.230.32:38082] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "erp.orixmed.com"] [uri "/public/index.php"] [unique_id "al9O1in25uliftkV1n4pEQAAO0o"]
[Tue Jul 21 07:49:58.594871 2026] [security2:error] [pid 302018:tid 302183] [client 4.204.201.85:57767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/coffexium.php"] [unique_id "al9O1oAs9lPxxVAErz0FrwAAAKY"]
[Tue Jul 21 07:49:58.606802 2026] [security2:error] [pid 302018:tid 302249] [client 20.197.195.24:10709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/abcd.php"] [unique_id "al9O1oAs9lPxxVAErz0FsgAAAOg"]
[Tue Jul 21 07:49:58.639071 2026] [security2:error] [pid 296703:tid 296955] [client 20.151.10.161:62972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/177.php"] [unique_id "al9O1in25uliftkV1n4pFgAAAHo"]
[Tue Jul 21 07:49:58.648187 2026] [security2:error] [pid 302018:tid 302228] [client 41.68.90.219:60323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O1oAs9lPxxVAErz0FswAAANM"]
[Tue Jul 21 07:49:58.649259 2026] [security2:error] [pid 302018:tid 302228] [client 41.68.90.219:60323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O1oAs9lPxxVAErz0FswAAANM"]
[Tue Jul 21 07:49:58.815938 2026] [security2:error] [pid 296703:tid 296886] [client 20.220.225.223:38673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-signup.php"] [unique_id "al9O1in25uliftkV1n4pGQAAADU"]
[Tue Jul 21 07:49:58.970244 2026] [security2:error] [pid 296703:tid 296957] [client 45.3.39.64:16757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.39.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9O1Sn25uliftkV1n4pCAAAAHw"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:49:58.994349 2026] [security2:error] [pid 296703:tid 296840] [client 20.197.195.24:16796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/file15.php"] [unique_id "al9O1in25uliftkV1n4pJgAAAAc"]
[Tue Jul 21 07:49:59.018908 2026] [security2:error] [pid 302018:tid 302230] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9O1oAs9lPxxVAErz0FtgAA1RU"]
[Tue Jul 21 07:49:59.251154 2026] [security2:error] [pid 302018:tid 302156] [client 20.151.10.161:62912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/config.php"] [unique_id "al9O14As9lPxxVAErz0FtwAAAIs"]
[Tue Jul 21 07:49:59.257359 2026] [security2:error] [pid 302018:tid 302246] [client 122.162.144.145:11562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9O14As9lPxxVAErz0FuAAAAOU"]
[Tue Jul 21 07:49:59.257503 2026] [security2:error] [pid 302018:tid 302246] [client 122.162.144.145:11562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9O14As9lPxxVAErz0FuAAAAOU"]
[Tue Jul 21 07:49:59.351172 2026] [security2:error] [pid 296703:tid 296897] [client 122.164.127.47:63161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9O1yn25uliftkV1n4pKgAAAEA"]
[Tue Jul 21 07:49:59.351291 2026] [security2:error] [pid 296703:tid 296897] [client 122.164.127.47:63161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9O1yn25uliftkV1n4pKgAAAEA"]
[Tue Jul 21 07:49:59.408620 2026] [security2:error] [pid 296703:tid 296836] [client 20.197.195.24:10660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/jp.php"] [unique_id "al9O1yn25uliftkV1n4pMgAAAAM"]
[Tue Jul 21 07:49:59.571644 2026] [security2:error] [pid 302018:tid 302196] [client 136.144.33.101:29875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9O14As9lPxxVAErz0FvgAAALM"], referer: https://moldurasbrilhante.com.br/wp-login.php
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:49:59.658928 2026] [security2:error] [pid 302018:tid 302260] [client 20.197.195.24:16790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/f35.php"] [unique_id "al9O14As9lPxxVAErz0FvwAAAPM"]
[Tue Jul 21 07:49:59.743622 2026] [security2:error] [pid 302018:tid 302176] [client 20.151.10.161:43856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9O14As9lPxxVAErz0FwAAAAJ8"]
[Tue Jul 21 07:49:59.747285 2026] [security2:error] [pid 302018:tid 302258] [client 4.204.201.85:57793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/core.php"] [unique_id "al9O14As9lPxxVAErz0FwQAAAPE"]
[Tue Jul 21 07:49:59.796260 2026] [security2:error] [pid 302018:tid 302251] [client 20.197.195.24:10636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wp-load.php"] [unique_id "al9O14As9lPxxVAErz0FxAAAAOo"]
[Tue Jul 21 07:49:59.838906 2026] [security2:error] [pid 302018:tid 302022] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9O14As9lPxxVAErz0FxQAAwAE"]
[Tue Jul 21 07:49:59.839073 2026] [security2:error] [pid 302018:tid 302209] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9O14As9lPxxVAErz0FxQAAwAE"]
[Tue Jul 21 07:49:59.974082 2026] [security2:error] [pid 302018:tid 302208] [client 20.197.195.24:10720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/xyn.php"] [unique_id "al9O14As9lPxxVAErz0FyAAAAL8"]
[Tue Jul 21 07:49:59.986971 2026] [security2:error] [pid 302018:tid 302252] [client 20.151.10.161:64198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/gettest.php"] [unique_id "al9O14As9lPxxVAErz0FyQAAAOs"]
[Tue Jul 21 07:50:00.068972 2026] [security2:error] [pid 302018:tid 302245] [client 20.197.192.193:9464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/wander.php"] [unique_id "al9O2IAs9lPxxVAErz0FzQAAAOQ"]
[Tue Jul 21 07:50:00.166990 2026] [security2:error] [pid 302018:tid 302153] [client 20.197.195.24:16831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/ccc.php"] [unique_id "al9O2IAs9lPxxVAErz0F1QAAAIg"]
[Tue Jul 21 07:50:00.282427 2026] [security2:error] [pid 302018:tid 302238] [client 194.99.104.35:37312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9O2IAs9lPxxVAErz0F1gAAAN0"]
[Tue Jul 21 07:50:00.282544 2026] [security2:error] [pid 302018:tid 302238] [client 194.99.104.35:37312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9O2IAs9lPxxVAErz0F1gAAAN0"]
[Tue Jul 21 07:50:00.301269 2026] [security2:error] [pid 302018:tid 302182] [client 20.197.195.24:16783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/w.php"] [unique_id "al9O2IAs9lPxxVAErz0F1wAAAKU"]
[Tue Jul 21 07:50:00.323924 2026] [security2:error] [pid 302018:tid 302264] [client 20.220.225.223:19296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9O2IAs9lPxxVAErz0F2AAAAPc"]
[Tue Jul 21 07:50:00.539582 2026] [security2:error] [pid 296703:tid 296844] [client 103.166.103.129:62982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9O2Cn25uliftkV1n4pRAAAAAs"]
[Tue Jul 21 07:50:00.539944 2026] [security2:error] [pid 296703:tid 296844] [client 103.166.103.129:62982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9O2Cn25uliftkV1n4pRAAAAAs"]
[Tue Jul 21 07:50:00.618281 2026] [security2:error] [pid 296703:tid 296930] [client 20.197.195.24:10721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9O2Cn25uliftkV1n4pRwAAAGE"]
[Tue Jul 21 07:50:00.619018 2026] [security2:error] [pid 302018:tid 302163] [client 104.207.52.134:57071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9O2IAs9lPxxVAErz0F2QAAAJI"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:50:00.644973 2026] [security2:error] [pid 296703:tid 296818] [remote 81.173.115.7:40236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "manosorvetes.com.br"] [uri "/wp-login.php"] [unique_id "al9O2Cn25uliftkV1n4pSAAAaHI"]
[Tue Jul 21 07:50:00.647071 2026] [security2:error] [pid 302018:tid 302263] [client 152.59.154.239:58033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O2IAs9lPxxVAErz0F3AAAAPY"]
[Tue Jul 21 07:50:00.647213 2026] [security2:error] [pid 302018:tid 302263] [client 152.59.154.239:58033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O2IAs9lPxxVAErz0F3AAAAPY"]
[Tue Jul 21 07:50:00.754827 2026] [security2:error] [pid 302018:tid 302195] [client 74.249.245.134:65095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/archive.php"] [unique_id "al9O2IAs9lPxxVAErz0F3wAAALI"]
[Tue Jul 21 07:50:00.794444 2026] [security2:error] [pid 302018:tid 302262] [client 20.151.10.161:63479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/min.php"] [unique_id "al9O2IAs9lPxxVAErz0F4AAAAPU"]
[Tue Jul 21 07:50:00.847031 2026] [security2:error] [pid 302018:tid 302265] [client 20.197.195.24:10718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/FWAZ.php"] [unique_id "al9O2IAs9lPxxVAErz0F4wAAAPg"]
[Tue Jul 21 07:50:00.886516 2026] [security2:error] [pid 302018:tid 302257] [client 4.204.201.85:50972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/als.php"] [unique_id "al9O2IAs9lPxxVAErz0F5QAAAPA"]
[Tue Jul 21 07:50:00.910113 2026] [security2:error] [pid 302018:tid 302239] [client 184.75.223.211:60972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9O2IAs9lPxxVAErz0F5gAAAN4"]
[Tue Jul 21 07:50:00.910276 2026] [security2:error] [pid 302018:tid 302239] [client 184.75.223.211:60972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9O2IAs9lPxxVAErz0F5gAAAN4"]
[Tue Jul 21 07:50:00.935260 2026] [security2:error] [pid 302018:tid 302176] [client 20.197.195.24:10628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/miru1.php"] [unique_id "al9O2IAs9lPxxVAErz0F6AAAAJ8"]
[Tue Jul 21 07:50:00.979301 2026] [security2:error] [pid 302018:tid 302200] [client 74.249.245.134:64212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/t.php"] [unique_id "al9O2IAs9lPxxVAErz0F7QAAALc"]
[Tue Jul 21 07:50:00.990988 2026] [security2:error] [pid 302018:tid 302212] [client 20.197.195.24:10663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/aa.php"] [unique_id "al9O2IAs9lPxxVAErz0F7gAAAMM"]
[Tue Jul 21 07:50:01.108788 2026] [security2:error] [pid 296703:tid 296887] [client 37.140.223.153:24679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9O1yn25uliftkV1n4pOgAAADY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:50:01.125516 2026] [security2:error] [pid 302018:tid 302268] [client 20.197.195.24:16772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/122.php"] [unique_id "al9O2YAs9lPxxVAErz0F9QAAAPs"]
[Tue Jul 21 07:50:01.209447 2026] [security2:error] [pid 302018:tid 302072] [remote 103.187.169.251:38078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agencia.aede.com.br"] [uri "/wp-login.php"] [unique_id "al9O2YAs9lPxxVAErz0F-AABAzM"]
[Tue Jul 21 07:50:01.222483 2026] [security2:error] [pid 302018:tid 302233] [client 223.236.153.128:1913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9O2YAs9lPxxVAErz0F-gAAANg"]
[Tue Jul 21 07:50:01.222625 2026] [security2:error] [pid 302018:tid 302233] [client 223.236.153.128:1913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9O2YAs9lPxxVAErz0F-gAAANg"]
[Tue Jul 21 07:50:01.423125 2026] [security2:error] [pid 302018:tid 302198] [client 20.197.195.24:10744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/get.php"] [unique_id "al9O2YAs9lPxxVAErz0GAQAAALU"]
[Tue Jul 21 07:50:01.611556 2026] [security2:error] [pid 296703:tid 296901] [client 20.197.195.24:10647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/as.php"] [unique_id "al9O2Sn25uliftkV1n4pVgAAAEQ"]
[Tue Jul 21 07:50:01.852748 2026] [security2:error] [pid 296703:tid 296857] [client 20.197.195.24:10702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/ccou.php"] [unique_id "al9O2Sn25uliftkV1n4pWgAAABg"]
[Tue Jul 21 07:50:01.867209 2026] [security2:error] [pid 302018:tid 302260] [client 20.151.10.161:64148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/edorxrr.php"] [unique_id "al9O2YAs9lPxxVAErz0GCwAAAPM"]
[Tue Jul 21 07:50:01.887346 2026] [security2:error] [pid 302018:tid 302176] [client 4.204.201.85:57837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/simple.php"] [unique_id "al9O2YAs9lPxxVAErz0GDQAAAJ8"]
[Tue Jul 21 07:50:02.169711 2026] [security2:error] [pid 302018:tid 302277] [client 20.197.195.24:10701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/w3lls.php"] [unique_id "al9O2oAs9lPxxVAErz0GFgAAAQQ"]
[Tue Jul 21 07:50:02.195619 2026] [security2:error] [pid 302018:tid 302023] [remote 173.252.87.4:39186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9O2oAs9lPxxVAErz0GEwAA2wI"]
[Tue Jul 21 07:50:02.268413 2026] [security2:error] [pid 302018:tid 302105] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O2oAs9lPxxVAErz0GGAAAo1Q"]
[Tue Jul 21 07:50:02.268654 2026] [security2:error] [pid 302018:tid 302180] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O2oAs9lPxxVAErz0GGAAAo1Q"]
[Tue Jul 21 07:50:02.334333 2026] [security2:error] [pid 302018:tid 302264] [client 62.102.148.187:49502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9O2oAs9lPxxVAErz0GGgAAAPc"]
[Tue Jul 21 07:50:02.334465 2026] [security2:error] [pid 302018:tid 302264] [client 62.102.148.187:49502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9O2oAs9lPxxVAErz0GGgAAAPc"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:50:02.519569 2026] [security2:error] [pid 302018:tid 302247] [client 20.197.195.24:16824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/test1.php"] [unique_id "al9O2oAs9lPxxVAErz0GHgAAAOY"]
[Tue Jul 21 07:50:02.573987 2026] [security2:error] [pid 302018:tid 302260] [client 20.197.195.24:10695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/database.php"] [unique_id "al9O2oAs9lPxxVAErz0GIAAAAPM"]
[Tue Jul 21 07:50:02.812473 2026] [security2:error] [pid 296703:tid 296959] [client 20.197.195.24:10674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/file.php"] [unique_id "al9O2in25uliftkV1n4pZgAAAH4"]
[Tue Jul 21 07:50:02.892644 2026] [security2:error] [pid 296703:tid 296946] [client 20.151.10.161:63416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/hur.php"] [unique_id "al9O2in25uliftkV1n4pZwAAAHE"]
[Tue Jul 21 07:50:02.922037 2026] [security2:error] [pid 302018:tid 302161] [client 20.197.195.24:13763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/file.php"] [unique_id "al9O2oAs9lPxxVAErz0GLgAAAJA"]
[Tue Jul 21 07:50:02.935427 2026] [security2:error] [pid 302018:tid 302252] [client 20.220.225.223:22488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/ms-new.php"] [unique_id "al9O2oAs9lPxxVAErz0GLwAAAOs"]
[Tue Jul 21 07:50:03.062105 2026] [security2:error] [pid 302018:tid 302248] [client 20.197.195.24:16787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/777.php"] [unique_id "al9O24As9lPxxVAErz0GMwAAAOc"]
[Tue Jul 21 07:50:03.109599 2026] [security2:error] [pid 302018:tid 302175] [client 59.96.220.140:63395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9O24As9lPxxVAErz0GNAAAAJ4"]
[Tue Jul 21 07:50:03.110314 2026] [security2:error] [pid 302018:tid 302175] [client 59.96.220.140:63395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9O24As9lPxxVAErz0GNAAAAJ4"]
[Tue Jul 21 07:50:03.123931 2026] [security2:error] [pid 302018:tid 302276] [client 4.204.201.85:57838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/init.php"] [unique_id "al9O24As9lPxxVAErz0GNwAAAQM"]
[Tue Jul 21 07:50:03.141228 2026] [security2:error] [pid 302018:tid 302251] [client 74.249.245.134:64111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/a.php"] [unique_id "al9O24As9lPxxVAErz0GOAAAAOo"]
[Tue Jul 21 07:50:03.195423 2026] [core:error] [pid 296703:tid 296785] [remote 87.236.176.242:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpcalendars.ginecologistadrcelsofukuda.com.br:8880
[Tue Jul 21 07:50:03.195451 2026] [core:error] [pid 296703:tid 296785] [remote 87.236.176.242:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpcalendars.ginecologistadrcelsofukuda.com.br:8880
[Tue Jul 21 07:50:03.266234 2026] [security2:error] [pid 296703:tid 296865] [client 182.8.255.181:17583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9O2yn25uliftkV1n4pbwAAACA"]
[Tue Jul 21 07:50:03.266398 2026] [security2:error] [pid 296703:tid 296865] [client 182.8.255.181:17583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9O2yn25uliftkV1n4pbwAAACA"]
[Tue Jul 21 07:50:03.272002 2026] [security2:error] [pid 302018:tid 302219] [client 20.197.195.24:10644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/ssixta.php"] [unique_id "al9O24As9lPxxVAErz0GOgAAAMo"]
[Tue Jul 21 07:50:03.503223 2026] [security2:error] [pid 296703:tid 296952] [client 20.197.195.24:13794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/1c.php"] [unique_id "al9O2yn25uliftkV1n4pcwAAAHc"]
[Tue Jul 21 07:50:03.599445 2026] [security2:error] [pid 296703:tid 296851] [client 122.186.204.214:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O2yn25uliftkV1n4peAAAABI"]
[Tue Jul 21 07:50:03.599567 2026] [security2:error] [pid 296703:tid 296851] [client 122.186.204.214:62916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O2yn25uliftkV1n4peAAAABI"]
[Tue Jul 21 07:50:03.657418 2026] [security2:error] [pid 296703:tid 296866] [client 20.151.10.161:64155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/zoro.php"] [unique_id "al9O2yn25uliftkV1n4peQAAACE"]
[Tue Jul 21 07:50:03.671773 2026] [security2:error] [pid 296703:tid 296839] [client 154.192.233.199:59889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O2yn25uliftkV1n4pfAAAAAY"]
[Tue Jul 21 07:50:03.671901 2026] [security2:error] [pid 296703:tid 296839] [client 154.192.233.199:59889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O2yn25uliftkV1n4pfAAAAAY"]
[Tue Jul 21 07:50:03.715339 2026] [security2:error] [pid 296703:tid 296925] [client 74.249.245.134:65135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/amax.php"] [unique_id "al9O2yn25uliftkV1n4pfgAAAFw"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:50:03.749570 2026] [security2:error] [pid 296703:tid 296953] [client 20.197.195.24:16738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/test2.php"] [unique_id "al9O2yn25uliftkV1n4pgAAAAHg"]
[Tue Jul 21 07:50:03.759754 2026] [security2:error] [pid 302018:tid 302150] [client 109.60.28.94:57956] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O2YAs9lPxxVAErz0GAgAAAIU"]
[Tue Jul 21 07:50:03.759870 2026] [security2:error] [pid 302018:tid 302150] [client 109.60.28.94:57956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O2YAs9lPxxVAErz0GAgAAAIU"]
[Tue Jul 21 07:50:03.838498 2026] [security2:error] [pid 296703:tid 296899] [client 20.220.225.223:19656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/dp.php"] [unique_id "al9O2yn25uliftkV1n4pgQAAAEI"]
[Tue Jul 21 07:50:03.865081 2026] [security2:error] [pid 296703:tid 296932] [client 20.197.195.24:16786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/buy.php"] [unique_id "al9O2yn25uliftkV1n4pggAAAGM"]
[Tue Jul 21 07:50:03.891583 2026] [security2:error] [pid 302018:tid 302225] [client 117.247.80.59:23683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O24As9lPxxVAErz0GTgAAANA"]
[Tue Jul 21 07:50:03.891719 2026] [security2:error] [pid 302018:tid 302225] [client 117.247.80.59:23683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O24As9lPxxVAErz0GTgAAANA"]
[Tue Jul 21 07:50:03.966320 2026] [security2:error] [pid 296703:tid 296888] [client 20.197.195.24:13776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/ssend.php"] [unique_id "al9O2yn25uliftkV1n4phAAAADc"]
[Tue Jul 21 07:50:04.132612 2026] [security2:error] [pid 302018:tid 302174] [client 20.220.225.223:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9O3IAs9lPxxVAErz0GTwAAAJ0"]
[Tue Jul 21 07:50:04.135113 2026] [security2:error] [pid 296703:tid 296892] [client 62.102.148.187:59574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9O3Cn25uliftkV1n4piQAAADs"]
[Tue Jul 21 07:50:04.135180 2026] [security2:error] [pid 296703:tid 296892] [client 62.102.148.187:59574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9O3Cn25uliftkV1n4piQAAADs"]
[Tue Jul 21 07:50:04.150677 2026] [security2:error] [pid 296703:tid 296773] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O3Cn25uliftkV1n4pigAAc0U"]
[Tue Jul 21 07:50:04.150778 2026] [security2:error] [pid 296703:tid 296948] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O3Cn25uliftkV1n4pigAAc0U"]
[Tue Jul 21 07:50:04.269284 2026] [security2:error] [pid 296703:tid 296804] [remote 45.3.34.196:20045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.34.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9O3Cn25uliftkV1n4pjwAAXmQ"]
[Tue Jul 21 07:50:04.292002 2026] [security2:error] [pid 302018:tid 302240] [client 20.197.195.24:10678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/item.php"] [unique_id "al9O3IAs9lPxxVAErz0GUgAAAN8"]
[Tue Jul 21 07:50:04.308481 2026] [security2:error] [pid 302018:tid 302262] [client 136.144.33.101:25097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9O3IAs9lPxxVAErz0GUwAAAPU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:50:04.316194 2026] [security2:error] [pid 296703:tid 296920] [client 4.204.201.85:50993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/fpwch.php"] [unique_id "al9O3Cn25uliftkV1n4pkAAAAFc"]
[Tue Jul 21 07:50:04.378845 2026] [security2:error] [pid 296703:tid 296841] [client 103.86.117.203:60953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O3Cn25uliftkV1n4pkQAAAAg"]
[Tue Jul 21 07:50:04.379031 2026] [security2:error] [pid 296703:tid 296841] [client 103.86.117.203:60953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O3Cn25uliftkV1n4pkQAAAAg"]
[Tue Jul 21 07:50:04.464367 2026] [security2:error] [pid 302018:tid 302256] [client 20.220.225.223:38692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/csa.php"] [unique_id "al9O3IAs9lPxxVAErz0GVAAAAO8"]
[Tue Jul 21 07:50:04.478306 2026] [security2:error] [pid 302018:tid 302265] [client 20.151.10.161:43885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp.php"] [unique_id "al9O3IAs9lPxxVAErz0GVQAAAPg"]
[Tue Jul 21 07:50:04.537797 2026] [security2:error] [pid 296703:tid 296944] [client 20.220.225.223:38244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/track.php"] [unique_id "al9O3Cn25uliftkV1n4pkgAAAG8"]
[Tue Jul 21 07:50:04.678332 2026] [security2:error] [pid 296703:tid 296843] [client 20.197.195.24:10708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/ss.php"] [unique_id "al9O3Cn25uliftkV1n4plwAAAAo"]
[Tue Jul 21 07:50:04.804329 2026] [security2:error] [pid 302018:tid 302192] [client 20.197.195.24:16768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/hypo.php"] [unique_id "al9O3IAs9lPxxVAErz0GXQAAAK8"]
[Tue Jul 21 07:50:04.863206 2026] [security2:error] [pid 302018:tid 302267] [client 4.204.201.85:51038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/domvf.php"] [unique_id "al9O3IAs9lPxxVAErz0GXgAAAPo"]
[Tue Jul 21 07:50:04.941374 2026] [security2:error] [pid 302018:tid 302165] [client 20.197.195.24:16709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/users.php"] [unique_id "al9O3IAs9lPxxVAErz0GXwAAAJQ"]
[Tue Jul 21 07:50:04.975418 2026] [security2:error] [pid 302018:tid 302172] [client 20.226.60.151:53901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/0xD.php"] [unique_id "al9O3IAs9lPxxVAErz0GYAAAAJs"]
[Tue Jul 21 07:50:04.978182 2026] [security2:error] [pid 296703:tid 296936] [client 139.167.225.182:61387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O3Cn25uliftkV1n4pngAAAGc"]
[Tue Jul 21 07:50:04.978312 2026] [security2:error] [pid 296703:tid 296936] [client 139.167.225.182:61387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O3Cn25uliftkV1n4pngAAAGc"]
[Tue Jul 21 07:50:05.103086 2026] [security2:error] [pid 302018:tid 302212] [client 20.197.195.24:10657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/177.php"] [unique_id "al9O3YAs9lPxxVAErz0GYQAAAMM"]
[Tue Jul 21 07:50:05.131537 2026] [security2:error] [pid 302018:tid 302268] [client 74.249.245.134:64194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/moon.php"] [unique_id "al9O3YAs9lPxxVAErz0GYgAAAPs"]
[Tue Jul 21 07:50:05.182768 2026] [security2:error] [pid 302018:tid 302215] [client 173.24.185.52:59569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9O3YAs9lPxxVAErz0GZQAAAMY"]
[Tue Jul 21 07:50:05.182969 2026] [security2:error] [pid 302018:tid 302215] [client 173.24.185.52:59569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9O3YAs9lPxxVAErz0GZQAAAMY"]
[Tue Jul 21 07:50:05.186782 2026] [security2:error] [pid 296703:tid 296946] [client 20.197.195.24:10629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/config.php"] [unique_id "al9O3Sn25uliftkV1n4powAAAHE"]
[Tue Jul 21 07:50:05.278109 2026] [security2:error] [pid 302018:tid 302153] [client 20.197.195.24:10714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/gettest.php"] [unique_id "al9O3YAs9lPxxVAErz0GbAAAAIg"]
[Tue Jul 21 07:50:05.365506 2026] [security2:error] [pid 302018:tid 302232] [client 178.153.91.96:31391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9O3YAs9lPxxVAErz0GbgAAANc"]
[Tue Jul 21 07:50:05.365624 2026] [security2:error] [pid 302018:tid 302232] [client 178.153.91.96:31391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9O3YAs9lPxxVAErz0GbgAAANc"]
[Tue Jul 21 07:50:05.366172 2026] [security2:error] [pid 302018:tid 302229] [client 20.220.225.223:31176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/min.php"] [unique_id "al9O3YAs9lPxxVAErz0GbwAAANQ"]
[Tue Jul 21 07:50:05.445199 2026] [security2:error] [pid 302018:tid 302184] [client 20.197.195.24:16797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/min.php"] [unique_id "al9O3YAs9lPxxVAErz0GcAAAAKc"]
[Tue Jul 21 07:50:05.486020 2026] [security2:error] [pid 302018:tid 302182] [client 20.151.10.161:43989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/abcd.php"] [unique_id "al9O3YAs9lPxxVAErz0GcQAAAKU"]
[Tue Jul 21 07:50:05.501097 2026] [security2:error] [pid 302018:tid 302156] [client 4.204.201.85:51056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/wp.php"] [unique_id "al9O3YAs9lPxxVAErz0GcgAAAIs"]
[Tue Jul 21 07:50:05.562969 2026] [security2:error] [pid 296703:tid 296914] [client 74.249.245.134:65128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/a1.php"] [unique_id "al9O3Sn25uliftkV1n4ppgAAAFE"]
[Tue Jul 21 07:50:05.638821 2026] [security2:error] [pid 296703:tid 296842] [client 103.29.114.44:64178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O3Sn25uliftkV1n4ppwAAAAk"]
[Tue Jul 21 07:50:05.638986 2026] [security2:error] [pid 296703:tid 296842] [client 103.29.114.44:64178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O3Sn25uliftkV1n4ppwAAAAk"]
[Tue Jul 21 07:50:05.660140 2026] [security2:error] [pid 302018:tid 302163] [client 20.197.195.24:10652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/dvjul.php"] [unique_id "al9O3YAs9lPxxVAErz0GeAAAAJI"]
[Tue Jul 21 07:50:05.851302 2026] [security2:error] [pid 302018:tid 302265] [client 20.197.195.24:16813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/biufile.php"] [unique_id "al9O3YAs9lPxxVAErz0GewAAAPg"]
[Tue Jul 21 07:50:05.975117 2026] [security2:error] [pid 302018:tid 302196] [client 20.197.195.24:10642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/av.php"] [unique_id "al9O3YAs9lPxxVAErz0GfwAAALM"]
[Tue Jul 21 07:50:06.006644 2026] [security2:error] [pid 302018:tid 302185] [client 20.197.195.24:13795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/coffexium.php"] [unique_id "al9O3oAs9lPxxVAErz0GgAAAAKg"]
[Tue Jul 21 07:50:06.109359 2026] [security2:error] [pid 302018:tid 302257] [client 20.197.195.24:16821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/core.php"] [unique_id "al9O3oAs9lPxxVAErz0GgwAAAPA"]
[Tue Jul 21 07:50:06.227035 2026] [security2:error] [pid 296703:tid 296894] [client 20.197.195.24:16799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/als.php"] [unique_id "al9O3in25uliftkV1n4psgAAAD0"]
[Tue Jul 21 07:50:06.286072 2026] [security2:error] [pid 302018:tid 302210] [client 180.93.252.125:47406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "10db.com.br"] [uri "/"] [unique_id "al9O3oAs9lPxxVAErz0GhgAAAME"]
[Tue Jul 21 07:50:06.320256 2026] [security2:error] [pid 302018:tid 302224] [client 20.197.195.24:10637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/simple.php"] [unique_id "al9O3oAs9lPxxVAErz0GigAAAM8"]
[Tue Jul 21 07:50:06.345903 2026] [security2:error] [pid 302018:tid 302208] [client 20.151.10.161:64136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/coffexium.php"] [unique_id "al9O3oAs9lPxxVAErz0GjgAAAL8"]
[Tue Jul 21 07:50:06.349463 2026] [security2:error] [pid 302018:tid 302177] [client 20.220.225.223:38248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/2352356666.php"] [unique_id "al9O3oAs9lPxxVAErz0GjwAAAKA"]
[Tue Jul 21 07:50:06.539588 2026] [security2:error] [pid 302018:tid 302234] [client 122.179.91.63:18100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9O3oAs9lPxxVAErz0GlAAAANk"]
[Tue Jul 21 07:50:06.539723 2026] [security2:error] [pid 302018:tid 302234] [client 122.179.91.63:18100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9O3oAs9lPxxVAErz0GlAAAANk"]
[Tue Jul 21 07:50:06.560780 2026] [http2:warn] [pid 296703:tid 296938] [client 173.252.95.59:52612] h2_stream(296703-1161-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:50:06.669102 2026] [security2:error] [pid 302018:tid 302167] [client 20.197.195.24:16766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/init.php"] [unique_id "al9O3oAs9lPxxVAErz0GlgAAAJY"]
[Tue Jul 21 07:50:06.849635 2026] [security2:error] [pid 302018:tid 302243] [client 4.204.201.85:57804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/class.php"] [unique_id "al9O3oAs9lPxxVAErz0GmgAAAOI"]
[Tue Jul 21 07:50:06.877622 2026] [security2:error] [pid 302018:tid 302268] [client 202.143.127.214:52817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O3oAs9lPxxVAErz0GmwAAAPs"]
[Tue Jul 21 07:50:06.877720 2026] [security2:error] [pid 302018:tid 302268] [client 202.143.127.214:52817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O3oAs9lPxxVAErz0GmwAAAPs"]
[Tue Jul 21 07:50:06.948079 2026] [security2:error] [pid 296703:tid 296872] [client 184.75.223.211:60418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9O3in25uliftkV1n4pvgAAACc"]
[Tue Jul 21 07:50:06.948168 2026] [security2:error] [pid 296703:tid 296872] [client 184.75.223.211:60418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9O3in25uliftkV1n4pvgAAACc"]
[Tue Jul 21 07:50:07.130199 2026] [security2:error] [pid 296703:tid 296900] [client 20.197.195.24:16791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/fpwch.php"] [unique_id "al9O3yn25uliftkV1n4pvwAAAEM"]
[Tue Jul 21 07:50:07.198464 2026] [security2:error] [pid 296703:tid 296798] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O3yn25uliftkV1n4pwAAAYV4"]
[Tue Jul 21 07:50:07.198622 2026] [security2:error] [pid 296703:tid 296930] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O3yn25uliftkV1n4pwAAAYV4"]
[Tue Jul 21 07:50:07.352702 2026] [security2:error] [pid 296703:tid 296932] [client 117.217.38.194:55214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O3yn25uliftkV1n4pyAAAAGM"]
[Tue Jul 21 07:50:07.352841 2026] [security2:error] [pid 296703:tid 296932] [client 117.217.38.194:55214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O3yn25uliftkV1n4pyAAAAGM"]
[Tue Jul 21 07:50:07.421416 2026] [security2:error] [pid 296703:tid 296737] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9O3yn25uliftkV1n4pygAATSE"]
[Tue Jul 21 07:50:07.421562 2026] [security2:error] [pid 296703:tid 296910] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9O3yn25uliftkV1n4pygAATSE"]
[Tue Jul 21 07:50:07.426572 2026] [security2:error] [pid 296703:tid 296841] [client 20.151.10.161:43870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/a1.php"] [unique_id "al9O3yn25uliftkV1n4pywAAAAg"]
[Tue Jul 21 07:50:07.481374 2026] [security2:error] [pid 296703:tid 296864] [client 20.197.195.24:10682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/domvf.php"] [unique_id "al9O3yn25uliftkV1n4pzwAAAB8"]
[Tue Jul 21 07:50:07.497876 2026] [security2:error] [pid 296703:tid 296731] [remote 5.252.52.249:35864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-login.php"] [unique_id "al9O3yn25uliftkV1n4p0AAAcxs"]
[Tue Jul 21 07:50:07.692833 2026] [security2:error] [pid 296703:tid 296877] [client 20.197.192.193:8365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/jga.php"] [unique_id "al9O3yn25uliftkV1n4p0QAAACw"]
[Tue Jul 21 07:50:07.924446 2026] [security2:error] [pid 296703:tid 296816] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9O3yn25uliftkV1n4p1wAATnA"]
[Tue Jul 21 07:50:07.924583 2026] [security2:error] [pid 296703:tid 296911] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9O3yn25uliftkV1n4p1wAATnA"]
[Tue Jul 21 07:50:07.936845 2026] [security2:error] [pid 302018:tid 302251] [client 4.204.201.85:57823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/echkm.php"] [unique_id "al9O34As9lPxxVAErz0GqgAAAOo"]
[Tue Jul 21 07:50:07.993838 2026] [security2:error] [pid 296703:tid 296954] [client 20.220.225.223:31223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/echkm.php"] [unique_id "al9O3yn25uliftkV1n4p2wAAAHk"]
[Tue Jul 21 07:50:08.001989 2026] [security2:error] [pid 302018:tid 302227] [client 20.197.195.24:10626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wp.php"] [unique_id "al9O4IAs9lPxxVAErz0GqwAAANI"]
[Tue Jul 21 07:50:08.066829 2026] [http2:warn] [pid 302018:tid 302217] [client 173.252.95.11:42262] h2_stream(302018-1186-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Tue Jul 21 07:50:08.115553 2026] [security2:error] [pid 296703:tid 296880] [client 136.144.33.241:32925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9O4Cn25uliftkV1n4p3QAAAC8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:50:08.116830 2026] [security2:error] [pid 296703:tid 296891] [client 20.151.10.161:43955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9O4Cn25uliftkV1n4p3gAAADo"]
[Tue Jul 21 07:50:08.139282 2026] [security2:error] [pid 296703:tid 296873] [client 37.140.223.137:25435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9O3yn25uliftkV1n4p2gAAACg"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:50:08.250090 2026] [security2:error] [pid 296703:tid 296942] [client 20.220.225.223:19676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/old.php"] [unique_id "al9O4Cn25uliftkV1n4p3wAAAG0"]
[Tue Jul 21 07:50:08.359398 2026] [security2:error] [pid 296703:tid 296917] [client 74.249.245.134:65116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/w.php"] [unique_id "al9O4Cn25uliftkV1n4p5AAAAFQ"]
[Tue Jul 21 07:50:08.711708 2026] [security2:error] [pid 302018:tid 302184] [client 4.204.201.85:51032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/lib.php"] [unique_id "al9O4IAs9lPxxVAErz0GtAAAAKc"]
[Tue Jul 21 07:50:08.725020 2026] [security2:error] [pid 302018:tid 302161] [client 106.215.181.8:22864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O4IAs9lPxxVAErz0GtQAAAJA"]
[Tue Jul 21 07:50:08.725118 2026] [security2:error] [pid 302018:tid 302161] [client 106.215.181.8:22864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O4IAs9lPxxVAErz0GtQAAAJA"]
[Tue Jul 21 07:50:08.781600 2026] [security2:error] [pid 296703:tid 296750] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9O4Cn25uliftkV1n4p6gAARi4"]
[Tue Jul 21 07:50:08.781758 2026] [security2:error] [pid 296703:tid 296903] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9O4Cn25uliftkV1n4p6gAARi4"]
[Tue Jul 21 07:50:09.020499 2026] [security2:error] [pid 296703:tid 296839] [client 20.220.225.223:31195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/mac.php"] [unique_id "al9O4Sn25uliftkV1n4p8QAAAAY"]
[Tue Jul 21 07:50:09.068147 2026] [security2:error] [pid 296703:tid 296953] [client 20.197.195.24:10658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/class.php"] [unique_id "al9O4Sn25uliftkV1n4p8wAAAHg"]
[Tue Jul 21 07:50:09.218005 2026] [security2:error] [pid 296703:tid 296897] [client 152.59.154.239:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O4Sn25uliftkV1n4p9gAAAEA"]
[Tue Jul 21 07:50:09.218140 2026] [security2:error] [pid 296703:tid 296897] [client 152.59.154.239:58444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O4Sn25uliftkV1n4p9gAAAEA"]
[Tue Jul 21 07:50:09.246630 2026] [security2:error] [pid 296703:tid 296896] [client 4.204.201.85:51041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/login.php"] [unique_id "al9O4Sn25uliftkV1n4p9wAAAD8"]
[Tue Jul 21 07:50:09.597010 2026] [security2:error] [pid 296703:tid 296909] [client 41.68.90.219:60745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O4Sn25uliftkV1n4p_wAAAEw"]
[Tue Jul 21 07:50:09.598176 2026] [security2:error] [pid 296703:tid 296909] [client 41.68.90.219:60745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O4Sn25uliftkV1n4p_wAAAEw"]
[Tue Jul 21 07:50:09.806513 2026] [security2:error] [pid 302018:tid 302183] [client 20.220.225.223:6086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9O4YAs9lPxxVAErz0GxQAAAKY"]
[Tue Jul 21 07:50:09.870791 2026] [security2:error] [pid 302018:tid 302150] [client 122.164.127.47:63770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9O4YAs9lPxxVAErz0GxwAAAIU"]
[Tue Jul 21 07:50:09.870927 2026] [security2:error] [pid 302018:tid 302150] [client 122.164.127.47:63770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9O4YAs9lPxxVAErz0GxwAAAIU"]
[Tue Jul 21 07:50:09.930403 2026] [security2:error] [pid 302018:tid 302246] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9O4YAs9lPxxVAErz0GxgAA5T8"]
[Tue Jul 21 07:50:09.985308 2026] [security2:error] [pid 302018:tid 302236] [client 20.197.195.24:10676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/echkm.php"] [unique_id "al9O4YAs9lPxxVAErz0GywAAANs"]
[Tue Jul 21 07:50:10.085902 2026] [security2:error] [pid 302018:tid 302174] [client 122.162.144.145:20206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9O4oAs9lPxxVAErz0GzgAAAJ0"]
[Tue Jul 21 07:50:10.086032 2026] [security2:error] [pid 302018:tid 302174] [client 122.162.144.145:20206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9O4oAs9lPxxVAErz0GzgAAAJ0"]
[Tue Jul 21 07:50:10.164171 2026] [security2:error] [pid 302018:tid 302212] [client 4.204.201.85:51014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/a2.php"] [unique_id "al9O4oAs9lPxxVAErz0G0AAAAMM"]
[Tue Jul 21 07:50:10.175502 2026] [security2:error] [pid 296703:tid 296886] [client 20.197.195.24:10643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/lib.php"] [unique_id "al9O4in25uliftkV1n4qBwAAADU"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:50:10.350145 2026] [security2:error] [pid 302018:tid 302164] [client 74.249.245.134:64093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-good.php"] [unique_id "al9O4oAs9lPxxVAErz0G0wAAAJM"]
[Tue Jul 21 07:50:10.388558 2026] [security2:error] [pid 302018:tid 302173] [client 20.220.225.223:38706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/samll.php"] [unique_id "al9O4oAs9lPxxVAErz0G1AAAAJw"]
[Tue Jul 21 07:50:10.527513 2026] [security2:error] [pid 296703:tid 296807] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9O4in25uliftkV1n4qDAAAdGc"]
[Tue Jul 21 07:50:10.527662 2026] [security2:error] [pid 296703:tid 296949] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9O4in25uliftkV1n4qDAAAdGc"]
[Tue Jul 21 07:50:10.558974 2026] [security2:error] [pid 302018:tid 302229] [client 4.204.201.85:50963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/d61.php"] [unique_id "al9O4oAs9lPxxVAErz0G2wAAANQ"]
[Tue Jul 21 07:50:10.581991 2026] [security2:error] [pid 302018:tid 302234] [client 20.197.195.24:10740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/login.php"] [unique_id "al9O4oAs9lPxxVAErz0G3gAAANk"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:50:10.948049 2026] [security2:error] [pid 302018:tid 302262] [client 20.197.192.193:8355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/x.php"] [unique_id "al9O4oAs9lPxxVAErz0G5gAAAPU"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:50:11.001533 2026] [security2:error] [pid 296703:tid 296860] [client 4.204.201.85:57798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/info.php"] [unique_id "al9O4yn25uliftkV1n4qFgAAABs"]
[Tue Jul 21 07:50:11.043507 2026] [security2:error] [pid 302018:tid 302163] [client 20.220.225.223:35052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/pn.php"] [unique_id "al9O44As9lPxxVAErz0G6AAAAJI"]
[Tue Jul 21 07:50:11.246439 2026] [security2:error] [pid 302018:tid 302153] [client 20.197.195.24:16711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/a2.php"] [unique_id "al9O44As9lPxxVAErz0G7AAAAIg"]
[Tue Jul 21 07:50:11.277061 2026] [security2:error] [pid 302018:tid 302182] [client 103.166.103.129:63520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9O44As9lPxxVAErz0G7QAAAKU"]
[Tue Jul 21 07:50:11.277152 2026] [security2:error] [pid 302018:tid 302182] [client 103.166.103.129:63520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9O44As9lPxxVAErz0G7QAAAKU"]
[Tue Jul 21 07:50:11.329297 2026] [security2:error] [pid 302018:tid 302171] [client 20.220.225.223:38697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/abcd.php"] [unique_id "al9O44As9lPxxVAErz0G7wAAAJo"]
[Tue Jul 21 07:50:11.662909 2026] [security2:error] [pid 302018:tid 302172] [client 35.221.29.111:53964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gradiente.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9O44As9lPxxVAErz0G-wAAAJs"]
[Tue Jul 21 07:50:11.670016 2026] [security2:error] [pid 302018:tid 302211] [client 4.204.201.85:57792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/11.php"] [unique_id "al9O44As9lPxxVAErz0G_AAAAMI"]
[Tue Jul 21 07:50:11.726764 2026] [security2:error] [pid 296703:tid 296889] [client 87.199.199.98:50197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madeireirapiske.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9O4in25uliftkV1n4qDwAAADg"], referer: https://madeireirapiske.com.br/2013/04/02/new-post-for-clever-people/
[Tue Jul 21 07:50:11.726940 2026] [security2:error] [pid 296703:tid 296889] [client 87.199.199.98:50197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "madeireirapiske.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9O4in25uliftkV1n4qDwAAADg"], referer: https://madeireirapiske.com.br/2013/04/02/new-post-for-clever-people/
[Tue Jul 21 07:50:11.807027 2026] [security2:error] [pid 302018:tid 302200] [client 193.36.225.62:61153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9O44As9lPxxVAErz0G-QAAALc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:50:11.889842 2026] [security2:error] [pid 302018:tid 302199] [client 20.151.10.161:64142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/app.php"] [unique_id "al9O44As9lPxxVAErz0G_QAAALY"]
[Tue Jul 21 07:50:12.004173 2026] [security2:error] [pid 302018:tid 302245] [client 35.221.29.111:50335] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gradiente.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9O5IAs9lPxxVAErz0G_wAAAOQ"]
[Tue Jul 21 07:50:12.009515 2026] [security2:error] [pid 296703:tid 296849] [client 223.236.153.128:7047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9O5Cn25uliftkV1n4qIgAAABA"]
[Tue Jul 21 07:50:12.009641 2026] [security2:error] [pid 296703:tid 296849] [client 223.236.153.128:7047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9O5Cn25uliftkV1n4qIgAAABA"]
[Tue Jul 21 07:50:12.010107 2026] [security2:error] [pid 296703:tid 296952] [client 4.204.201.85:51015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/v2.php"] [unique_id "al9O5Cn25uliftkV1n4qIwAAAHc"]
[Tue Jul 21 07:50:12.067993 2026] [security2:error] [pid 296703:tid 296836] [client 20.151.10.161:43878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9O5Cn25uliftkV1n4qJQAAAAM"]
[Tue Jul 21 07:50:12.275113 2026] [security2:error] [pid 296703:tid 296866] [client 184.75.223.211:37434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9O5Cn25uliftkV1n4qJwAAACE"]
[Tue Jul 21 07:50:12.275262 2026] [security2:error] [pid 296703:tid 296866] [client 184.75.223.211:37434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9O5Cn25uliftkV1n4qJwAAACE"]
[Tue Jul 21 07:50:12.276680 2026] [security2:error] [pid 302018:tid 302151] [client 20.220.225.223:23426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/dp.php"] [unique_id "al9O5IAs9lPxxVAErz0HAgAAAIY"]
[Tue Jul 21 07:50:12.295399 2026] [security2:error] [pid 296703:tid 296878] [client 20.197.195.24:10671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/d61.php"] [unique_id "al9O5Cn25uliftkV1n4qKAAAAC0"]
[Tue Jul 21 07:50:12.365831 2026] [security2:error] [pid 302018:tid 302226] [client 109.60.28.94:25397] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O5IAs9lPxxVAErz0HBQAAANE"]
[Tue Jul 21 07:50:12.365988 2026] [security2:error] [pid 302018:tid 302226] [client 109.60.28.94:25397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O5IAs9lPxxVAErz0HBQAAANE"]
[Tue Jul 21 07:50:12.383697 2026] [security2:error] [pid 296703:tid 296896] [client 4.204.201.85:51323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/panel.php"] [unique_id "al9O5Cn25uliftkV1n4qKgAAAD8"]
[Tue Jul 21 07:50:12.435619 2026] [security2:error] [pid 296703:tid 296914] [client 35.221.29.111:59711] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gradiente.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9O5Cn25uliftkV1n4qKwAAAFE"]
[Tue Jul 21 07:50:12.743563 2026] [security2:error] [pid 302018:tid 302153] [client 193.36.225.150:57653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9O5IAs9lPxxVAErz0HDgAAAIg"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:50:12.774127 2026] [security2:error] [pid 296703:tid 296867] [client 20.220.225.223:31227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xyn.php"] [unique_id "al9O5Cn25uliftkV1n4qNwAAACI"]
[Tue Jul 21 07:50:12.798569 2026] [security2:error] [pid 302018:tid 302183] [client 4.204.201.85:51047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/dex.php"] [unique_id "al9O5IAs9lPxxVAErz0HDwAAAKY"]
[Tue Jul 21 07:50:12.876151 2026] [security2:error] [pid 296703:tid 296882] [client 74.7.175.154:40968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "teste.inonebrasil.com.br"] [uri "/index.php"] [unique_id "al9O5Cn25uliftkV1n4qKQAAADE"]
[Tue Jul 21 07:50:13.010284 2026] [security2:error] [pid 296703:tid 296758] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O5Sn25uliftkV1n4qOQAAYTY"]
[Tue Jul 21 07:50:13.010435 2026] [security2:error] [pid 296703:tid 296930] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O5Sn25uliftkV1n4qOQAAYTY"]
[Tue Jul 21 07:50:13.172987 2026] [security2:error] [pid 302018:tid 302236] [client 4.204.201.85:51307] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "seth-quiro.com.br"] [uri "/1.php"] [unique_id "al9O5YAs9lPxxVAErz0HFAAAANs"]
[Tue Jul 21 07:50:13.173133 2026] [security2:error] [pid 302018:tid 302236] [client 4.204.201.85:51307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/1.php"] [unique_id "al9O5YAs9lPxxVAErz0HFAAAANs"]
[Tue Jul 21 07:50:13.206050 2026] [security2:error] [pid 296703:tid 296797] [remote 97.74.93.24:55324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9O5Sn25uliftkV1n4qPwAAHF0"]
[Tue Jul 21 07:50:13.213479 2026] [security2:error] [pid 302018:tid 302166] [client 35.221.29.111:52421] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gradiente.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9O5YAs9lPxxVAErz0HFQAAAJU"]
[Tue Jul 21 07:50:13.278155 2026] [proxy:error] [pid 296703:tid 296845] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:50:13.278249 2026] [proxy_http:error] [pid 296703:tid 296845] [client 164.92.68.146:53790] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:50:13.279358 2026] [proxy:error] [pid 296703:tid 296845] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:50:13.279417 2026] [proxy_http:error] [pid 296703:tid 296845] [client 164.92.68.146:53790] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:50:13.591964 2026] [security2:error] [pid 296703:tid 296870] [client 4.204.201.85:50962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/ms.php"] [unique_id "al9O5Sn25uliftkV1n4qQQAAACU"]
[Tue Jul 21 07:50:13.618164 2026] [security2:error] [pid 296703:tid 296960] [client 59.96.220.140:63908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9O5Sn25uliftkV1n4qQwAAAH8"]
[Tue Jul 21 07:50:13.618872 2026] [security2:error] [pid 296703:tid 296960] [client 59.96.220.140:63908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9O5Sn25uliftkV1n4qQwAAAH8"]
[Tue Jul 21 07:50:13.624934 2026] [security2:error] [pid 296703:tid 296795] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O5Sn25uliftkV1n4qRAAACls"]
[Tue Jul 21 07:50:13.625103 2026] [security2:error] [pid 296703:tid 296843] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O5Sn25uliftkV1n4qRAAACls"]
[Tue Jul 21 07:50:13.708564 2026] [security2:error] [pid 302018:tid 302176] [client 182.8.255.181:17702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9O5YAs9lPxxVAErz0HHwAAAJ8"]
[Tue Jul 21 07:50:13.708683 2026] [security2:error] [pid 302018:tid 302176] [client 182.8.255.181:17702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9O5YAs9lPxxVAErz0HHwAAAJ8"]
[Tue Jul 21 07:50:13.783312 2026] [security2:error] [pid 302018:tid 302159] [client 20.197.195.24:10639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/info.php"] [unique_id "al9O5YAs9lPxxVAErz0HIQAAAI4"]
[Tue Jul 21 07:50:13.786071 2026] [proxy:error] [pid 296703:tid 296949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:50:13.786141 2026] [proxy_http:error] [pid 296703:tid 296949] [client 164.92.68.146:53792] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.juliagoncalvesestetica.com/
[Tue Jul 21 07:50:13.786619 2026] [proxy:error] [pid 296703:tid 296949] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:50:13.786648 2026] [proxy_http:error] [pid 296703:tid 296949] [client 164.92.68.146:53792] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.juliagoncalvesestetica.com/
[Tue Jul 21 07:50:13.806148 2026] [security2:error] [pid 302018:tid 302227] [client 35.221.29.111:59314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gradiente.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9O5YAs9lPxxVAErz0HIwAAANI"]
[Tue Jul 21 07:50:13.893945 2026] [security2:error] [pid 302018:tid 302277] [client 20.197.192.193:9422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9O5YAs9lPxxVAErz0HJAAAAQQ"]
[Tue Jul 21 07:50:14.111131 2026] [security2:error] [pid 296703:tid 296954] [client 74.249.245.134:65132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "andrelageorthobolics.com.br"] [uri "/.info.php"] [unique_id "al9O5in25uliftkV1n4qTAAAAHk"]
[Tue Jul 21 07:50:14.112007 2026] [security2:error] [pid 302018:tid 302156] [client 74.249.245.134:24781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ws83.php"] [unique_id "al9O5oAs9lPxxVAErz0HJQAAAIs"]
[Tue Jul 21 07:50:14.336471 2026] [security2:error] [pid 302018:tid 302223] [client 122.186.204.214:63456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O5oAs9lPxxVAErz0HKQAAAM4"]
[Tue Jul 21 07:50:14.336597 2026] [security2:error] [pid 302018:tid 302223] [client 122.186.204.214:63456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O5oAs9lPxxVAErz0HKQAAAM4"]
[Tue Jul 21 07:50:14.426901 2026] [autoindex:error] [pid 302018:tid 302226] [client 4.204.201.85:51067] AH01276: Cannot serve directory /home4/solar369/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:50:14.495043 2026] [security2:error] [pid 302018:tid 302212] [client 74.249.245.134:65150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/CDX1.php"] [unique_id "al9O5oAs9lPxxVAErz0HKwAAAMM"]
[Tue Jul 21 07:50:14.503009 2026] [security2:error] [pid 302018:tid 302262] [client 74.249.245.134:8785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/item.php"] [unique_id "al9O5oAs9lPxxVAErz0HLAAAAPU"]
[Tue Jul 21 07:50:14.559587 2026] [security2:error] [pid 296703:tid 296902] [client 117.247.80.59:22548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O5in25uliftkV1n4qUgAAAEU"]
[Tue Jul 21 07:50:14.559698 2026] [security2:error] [pid 296703:tid 296902] [client 117.247.80.59:22548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O5in25uliftkV1n4qUgAAAEU"]
[Tue Jul 21 07:50:14.645824 2026] [security2:error] [pid 302018:tid 302082] [remote 167.71.132.111:42214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.132.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9O5oAs9lPxxVAErz0HLQAAtT0"]
[Tue Jul 21 07:50:14.653147 2026] [security2:error] [pid 302018:tid 302269] [client 35.221.29.111:65256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gradiente.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9O5oAs9lPxxVAErz0HLgAAAPw"]
[Tue Jul 21 07:50:14.689076 2026] [proxy:error] [pid 302018:tid 302230] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:50:14.689111 2026] [proxy_http:error] [pid 302018:tid 302230] [client 164.92.68.146:33308] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:50:14.689546 2026] [proxy:error] [pid 302018:tid 302230] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:50:14.689567 2026] [proxy_http:error] [pid 302018:tid 302230] [client 164.92.68.146:33308] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:50:14.725362 2026] [security2:error] [pid 302018:tid 302257] [client 4.204.201.85:51067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/memberfuns.php"] [unique_id "al9O5oAs9lPxxVAErz0HNwAAAPA"]
[Tue Jul 21 07:50:14.779507 2026] [security2:error] [pid 302018:tid 302254] [client 20.220.225.223:6116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/old.php"] [unique_id "al9O5oAs9lPxxVAErz0HOAAAAO0"]
[Tue Jul 21 07:50:14.858385 2026] [security2:error] [pid 302018:tid 302167] [client 103.86.117.203:61505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O5oAs9lPxxVAErz0HOgAAAJY"]
[Tue Jul 21 07:50:14.858506 2026] [security2:error] [pid 302018:tid 302167] [client 103.86.117.203:61505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O5oAs9lPxxVAErz0HOgAAAJY"]
[Tue Jul 21 07:50:15.094526 2026] [security2:error] [pid 296703:tid 296833] [client 35.221.29.111:55212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gradiente.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9O5yn25uliftkV1n4qWQAAAAA"]
[Tue Jul 21 07:50:15.160202 2026] [security2:error] [pid 302018:tid 302266] [client 20.151.10.161:64141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/core.php"] [unique_id "al9O54As9lPxxVAErz0HPAAAAPk"]
[Tue Jul 21 07:50:15.170023 2026] [security2:error] [pid 302018:tid 302174] [client 20.226.60.151:53962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/fnstall.php"] [unique_id "al9O54As9lPxxVAErz0HPQAAAJ0"]
[Tue Jul 21 07:50:15.194760 2026] [security2:error] [pid 302018:tid 302102] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O54As9lPxxVAErz0HPwAAj1E"]
[Tue Jul 21 07:50:15.195013 2026] [security2:error] [pid 302018:tid 302160] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O54As9lPxxVAErz0HPwAAj1E"]
[Tue Jul 21 07:50:15.276117 2026] [security2:error] [pid 302018:tid 302224] [client 20.197.195.24:13775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/11.php"] [unique_id "al9O54As9lPxxVAErz0HQQAAAM8"]
[Tue Jul 21 07:50:15.312371 2026] [security2:error] [pid 296703:tid 296866] [client 184.75.223.211:37448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9O5yn25uliftkV1n4qYAAAACE"]
[Tue Jul 21 07:50:15.312468 2026] [security2:error] [pid 296703:tid 296866] [client 184.75.223.211:37448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9O5yn25uliftkV1n4qYAAAACE"]
[Tue Jul 21 07:50:15.356643 2026] [security2:error] [pid 302018:tid 302215] [client 20.151.10.161:44018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/gettest.php"] [unique_id "al9O54As9lPxxVAErz0HQgAAAMY"]
[Tue Jul 21 07:50:15.581534 2026] [security2:error] [pid 302018:tid 302277] [client 4.204.201.85:51039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/0.php"] [unique_id "al9O54As9lPxxVAErz0HRgAAAQQ"]
[Tue Jul 21 07:50:15.622079 2026] [security2:error] [pid 302018:tid 302168] [client 139.167.225.182:62041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O54As9lPxxVAErz0HRwAAAJc"]
[Tue Jul 21 07:50:15.622180 2026] [security2:error] [pid 302018:tid 302168] [client 139.167.225.182:62041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O54As9lPxxVAErz0HRwAAAJc"]
[Tue Jul 21 07:50:15.631241 2026] [security2:error] [pid 296703:tid 296834] [client 35.221.29.111:61503] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gradiente.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9O5yn25uliftkV1n4qYwAAAAE"]
[Tue Jul 21 07:50:15.781628 2026] [security2:error] [pid 296703:tid 296896] [client 173.24.185.52:60236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9O5yn25uliftkV1n4qawAAAD8"]
[Tue Jul 21 07:50:15.781710 2026] [security2:error] [pid 296703:tid 296896] [client 173.24.185.52:60236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9O5yn25uliftkV1n4qawAAAD8"]
[Tue Jul 21 07:50:15.918373 2026] [security2:error] [pid 296703:tid 296878] [client 178.153.91.96:52968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9O5yn25uliftkV1n4qbQAAAC0"]
[Tue Jul 21 07:50:15.918519 2026] [security2:error] [pid 296703:tid 296878] [client 178.153.91.96:52968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9O5yn25uliftkV1n4qbQAAAC0"]
[Tue Jul 21 07:50:16.059769 2026] [security2:error] [pid 302018:tid 302156] [client 35.221.29.111:51577] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gradiente.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9O6IAs9lPxxVAErz0HSQAAAIs"]
[Tue Jul 21 07:50:16.227610 2026] [security2:error] [pid 302018:tid 302175] [client 103.29.114.44:11248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O6IAs9lPxxVAErz0HTQAAAJ4"]
[Tue Jul 21 07:50:16.227752 2026] [security2:error] [pid 302018:tid 302175] [client 103.29.114.44:11248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O6IAs9lPxxVAErz0HTQAAAJ4"]
[Tue Jul 21 07:50:16.368808 2026] [security2:error] [pid 296703:tid 296938] [client 4.204.201.85:50992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/BDKR28.php"] [unique_id "al9O6Cn25uliftkV1n4qeAAAAGk"]
[Tue Jul 21 07:50:16.392447 2026] [security2:error] [pid 296703:tid 296960] [client 35.221.29.111:58874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gradiente.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9O6Cn25uliftkV1n4qegAAAH8"]
[Tue Jul 21 07:50:16.443419 2026] [security2:error] [pid 302018:tid 302151] [client 20.197.195.24:16775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/v2.php"] [unique_id "al9O6IAs9lPxxVAErz0HTwAAAIY"]
[Tue Jul 21 07:50:16.522251 2026] [security2:error] [pid 296703:tid 296815] [remote 68.178.160.25:44834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9O6Cn25uliftkV1n4qfAAAXW8"]
[Tue Jul 21 07:50:16.639648 2026] [security2:error] [pid 302018:tid 302185] [client 193.36.225.58:50763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9O6IAs9lPxxVAErz0HUQAAAKg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:50:16.782911 2026] [security2:error] [pid 302018:tid 302274] [client 20.104.96.117:64375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9O6IAs9lPxxVAErz0HUgAAAQE"]
[Tue Jul 21 07:50:16.904148 2026] [security2:error] [pid 296703:tid 296947] [client 35.221.29.111:61322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gradiente.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9O6Cn25uliftkV1n4qgwAAAHI"]
[Tue Jul 21 07:50:16.943141 2026] [security2:error] [pid 302018:tid 302272] [client 74.7.230.54:48688] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.valorizeadistribuidora.provendasatacado.com.br"] [uri "/index.html"] [unique_id "al9O6IAs9lPxxVAErz0HVwAA_wQ"]
[Tue Jul 21 07:50:17.110174 2026] [security2:error] [pid 296703:tid 296939] [client 20.197.195.24:16722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/panel.php"] [unique_id "al9O6Sn25uliftkV1n4qiQAAAGo"]
[Tue Jul 21 07:50:17.220183 2026] [security2:error] [pid 296703:tid 296842] [client 35.221.29.111:61973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gradiente.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9O6Sn25uliftkV1n4qiwAAAAk"]
[Tue Jul 21 07:50:17.310527 2026] [security2:error] [pid 302018:tid 302214] [client 20.197.192.193:8364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/ee.php"] [unique_id "al9O6YAs9lPxxVAErz0HYAAAAMU"]
[Tue Jul 21 07:50:17.474265 2026] [security2:error] [pid 296703:tid 296839] [client 20.151.10.161:63380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/main.php"] [unique_id "al9O6Sn25uliftkV1n4qkQAAAAY"]
[Tue Jul 21 07:50:17.509731 2026] [security2:error] [pid 296703:tid 296859] [client 122.179.91.63:3739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9O6Sn25uliftkV1n4qkwAAABo"]
[Tue Jul 21 07:50:17.509810 2026] [security2:error] [pid 296703:tid 296859] [client 122.179.91.63:3739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9O6Sn25uliftkV1n4qkwAAABo"]
[Tue Jul 21 07:50:17.535206 2026] [security2:error] [pid 296703:tid 296951] [client 4.204.201.85:57811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/green1.php"] [unique_id "al9O6Sn25uliftkV1n4qlwAAAHY"]
[Tue Jul 21 07:50:17.593872 2026] [security2:error] [pid 302018:tid 302164] [client 74.249.245.134:65154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/inputs.php"] [unique_id "al9O6YAs9lPxxVAErz0HZgAAAJM"]
[Tue Jul 21 07:50:17.600672 2026] [security2:error] [pid 296703:tid 296854] [client 74.249.245.134:8830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/albin.php"] [unique_id "al9O6Sn25uliftkV1n4qmAAAABU"]
[Tue Jul 21 07:50:17.677737 2026] [security2:error] [pid 302018:tid 302220] [client 20.104.96.117:59742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9O6YAs9lPxxVAErz0HZwAAAMs"]
[Tue Jul 21 07:50:17.711836 2026] [security2:error] [pid 302018:tid 302101] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O6YAs9lPxxVAErz0HaAAAxlA"]
[Tue Jul 21 07:50:17.711961 2026] [security2:error] [pid 302018:tid 302215] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O6YAs9lPxxVAErz0HaAAAxlA"]
[Tue Jul 21 07:50:17.813487 2026] [security2:error] [pid 296703:tid 296873] [client 202.143.127.214:53283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O6Sn25uliftkV1n4qmQAAACg"]
[Tue Jul 21 07:50:17.813597 2026] [security2:error] [pid 296703:tid 296873] [client 202.143.127.214:53283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O6Sn25uliftkV1n4qmQAAACg"]
[Tue Jul 21 07:50:17.821200 2026] [security2:error] [pid 302018:tid 302174] [client 117.217.38.194:55712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O6YAs9lPxxVAErz0HawAAAJ0"]
[Tue Jul 21 07:50:17.821278 2026] [security2:error] [pid 302018:tid 302174] [client 117.217.38.194:55712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O6YAs9lPxxVAErz0HawAAAJ0"]
[Tue Jul 21 07:50:18.042293 2026] [security2:error] [pid 302018:tid 302105] [remote 162.19.246.208:50508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "selleto.com.br"] [uri "/wp-login.php"] [unique_id "al9O6oAs9lPxxVAErz0HcgAAwlQ"]
[Tue Jul 21 07:50:18.195091 2026] [security2:error] [pid 302018:tid 302052] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9O6oAs9lPxxVAErz0HdAAAtx8"]
[Tue Jul 21 07:50:18.195239 2026] [security2:error] [pid 302018:tid 302200] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9O6oAs9lPxxVAErz0HdAAAtx8"]
[Tue Jul 21 07:50:18.237483 2026] [core:error] [pid 302018:tid 302141] [remote 40.77.167.28:44161] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:18.237509 2026] [core:error] [pid 302018:tid 302141] [remote 40.77.167.28:44161] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:18.258559 2026] [security2:error] [pid 302018:tid 302212] [client 20.197.195.24:13803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/dex.php"] [unique_id "al9O6oAs9lPxxVAErz0HdgAAAMM"]
[Tue Jul 21 07:50:18.360788 2026] [core:error] [pid 302018:tid 302144] [remote 40.77.167.28:44161] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:18.360808 2026] [core:error] [pid 302018:tid 302144] [remote 40.77.167.28:44161] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:18.367879 2026] [core:error] [pid 302018:tid 302129] [remote 205.210.31.33:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:18.367899 2026] [core:error] [pid 302018:tid 302129] [remote 205.210.31.33:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:18.376057 2026] [security2:error] [pid 302018:tid 302170] [client 20.151.10.161:64207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/init.php"] [unique_id "al9O6oAs9lPxxVAErz0HfAAAAJk"]
[Tue Jul 21 07:50:18.439988 2026] [security2:error] [pid 296703:tid 296827] [remote 122.176.107.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9O6in25uliftkV1n4qpAAAO3s"]
[Tue Jul 21 07:50:18.440196 2026] [security2:error] [pid 296703:tid 296892] [client 122.176.107.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9O6in25uliftkV1n4qpAAAO3s"]
[Tue Jul 21 07:50:18.442971 2026] [security2:error] [pid 296703:tid 296852] [client 4.204.201.85:57822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/nc4.php"] [unique_id "al9O6in25uliftkV1n4qpQAAABM"]
[Tue Jul 21 07:50:18.485781 2026] [core:error] [pid 302018:tid 302125] [remote 40.77.167.28:44161] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:18.485809 2026] [core:error] [pid 302018:tid 302125] [remote 40.77.167.28:44161] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:18.609631 2026] [core:error] [pid 302018:tid 302038] [remote 40.77.167.28:44161] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:18.609654 2026] [core:error] [pid 302018:tid 302038] [remote 40.77.167.28:44161] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:50:18.876080 2026] [security2:error] [pid 296703:tid 296924] [client 20.151.10.161:43960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/simple.php"] [unique_id "al9O6in25uliftkV1n4qrgAAAFs"]
[Tue Jul 21 07:50:18.952546 2026] [security2:error] [pid 296703:tid 296960] [client 20.151.10.161:62923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/prekel.php"] [unique_id "al9O6in25uliftkV1n4qsAAAAH8"]
[Tue Jul 21 07:50:19.020862 2026] [security2:error] [pid 296703:tid 296908] [client 74.7.228.20:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.suora.com.br"] [uri "/index.php"] [unique_id "al9O6in25uliftkV1n4qogAAAEs"]
[Tue Jul 21 07:50:19.021919 2026] [security2:error] [pid 302018:tid 302185] [client 74.7.228.20:43438] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.suora.com.br"] [uri "/robots.txt"] [unique_id "al9O6oAs9lPxxVAErz0HfQAAqFg"]
[Tue Jul 21 07:50:19.302093 2026] [security2:error] [pid 302018:tid 302256] [client 106.215.181.8:14553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O64As9lPxxVAErz0HiQAAAO8"]
[Tue Jul 21 07:50:19.302213 2026] [security2:error] [pid 302018:tid 302256] [client 106.215.181.8:14553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O64As9lPxxVAErz0HiQAAAO8"]
[Tue Jul 21 07:50:19.368530 2026] [security2:error] [pid 302018:tid 311335] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9O64As9lPxxVAErz0HiwAAz4k"]
[Tue Jul 21 07:50:19.368693 2026] [security2:error] [pid 302018:tid 302224] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9O64As9lPxxVAErz0HiwAAz4k"]
[Tue Jul 21 07:50:19.435522 2026] [security2:error] [pid 302018:tid 302173] [client 128.127.105.184:39976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9O64As9lPxxVAErz0HjAAAAJw"]
[Tue Jul 21 07:50:19.435619 2026] [security2:error] [pid 302018:tid 302173] [client 128.127.105.184:39976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9O64As9lPxxVAErz0HjAAAAJw"]
[Tue Jul 21 07:50:19.535238 2026] [proxy:error] [pid 302018:tid 302189] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:50:19.535313 2026] [proxy_http:error] [pid 302018:tid 302189] [client 164.92.68.146:33384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.juliagoncalvesestetica.com/
[Tue Jul 21 07:50:19.535857 2026] [proxy:error] [pid 302018:tid 302189] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:50:19.535906 2026] [proxy_http:error] [pid 302018:tid 302189] [client 164.92.68.146:33384] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.juliagoncalvesestetica.com/
[Tue Jul 21 07:50:19.584246 2026] [security2:error] [pid 302018:tid 302168] [client 20.197.192.193:8332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/blue.php"] [unique_id "al9O64As9lPxxVAErz0HlAAAAJc"]
[Tue Jul 21 07:50:19.633045 2026] [security2:error] [pid 296703:tid 296918] [client 20.151.10.161:64134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/0.php"] [unique_id "al9O6yn25uliftkV1n4qvQAAAFU"]
[Tue Jul 21 07:50:19.803551 2026] [security2:error] [pid 296703:tid 296938] [client 152.59.154.239:58621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O6yn25uliftkV1n4qvwAAAGk"]
[Tue Jul 21 07:50:19.803648 2026] [security2:error] [pid 296703:tid 296938] [client 152.59.154.239:58621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O6yn25uliftkV1n4qvwAAAGk"]
[Tue Jul 21 07:50:19.839256 2026] [security2:error] [pid 296703:tid 296917] [client 20.197.195.24:10688] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "runnezy.com.br"] [uri "/1.php"] [unique_id "al9O6yn25uliftkV1n4qwAAAAFQ"]
[Tue Jul 21 07:50:19.839362 2026] [security2:error] [pid 296703:tid 296917] [client 20.197.195.24:10688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/1.php"] [unique_id "al9O6yn25uliftkV1n4qwAAAAFQ"]
[Tue Jul 21 07:50:19.857516 2026] [security2:error] [pid 302018:tid 302252] [client 4.204.201.85:50960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/a1.php"] [unique_id "al9O64As9lPxxVAErz0HlwAAAOs"]
[Tue Jul 21 07:50:19.878895 2026] [security2:error] [pid 302018:tid 302177] [client 20.220.225.223:22515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9O64As9lPxxVAErz0HmQAAAKA"]
[Tue Jul 21 07:50:20.149691 2026] [security2:error] [pid 296703:tid 296833] [client 20.151.10.161:43994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/xxx.php"] [unique_id "al9O7Cn25uliftkV1n4qxwAAAAA"]
[Tue Jul 21 07:50:20.204097 2026] [security2:error] [pid 302018:tid 302262] [client 20.226.60.151:61570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/acp.php"] [unique_id "al9O7IAs9lPxxVAErz0HmgAAAPU"]
[Tue Jul 21 07:50:20.216623 2026] [core:error] [pid 302018:tid 302035] [remote 52.167.144.206:52583] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:20.216645 2026] [core:error] [pid 302018:tid 302035] [remote 52.167.144.206:52583] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:20.233749 2026] [security2:error] [pid 296703:tid 296894] [client 20.151.10.161:64200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/BDKR28.php"] [unique_id "al9O7Cn25uliftkV1n4qyAAAAD0"]
[Tue Jul 21 07:50:20.300803 2026] [security2:error] [pid 302018:tid 302277] [client 122.164.127.47:64356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9O7IAs9lPxxVAErz0HnAAAAQQ"]
[Tue Jul 21 07:50:20.300989 2026] [security2:error] [pid 302018:tid 302277] [client 122.164.127.47:64356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9O7IAs9lPxxVAErz0HnAAAAQQ"]
[Tue Jul 21 07:50:20.504874 2026] [security2:error] [pid 302018:tid 302176] [client 136.144.33.108:52131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9O7IAs9lPxxVAErz0HoQAAAJ8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:50:20.518650 2026] [security2:error] [pid 296703:tid 296949] [client 104.207.33.88:48235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9O7Cn25uliftkV1n4qyQAAAHQ"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:50:20.655587 2026] [security2:error] [pid 302018:tid 302137] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9O7IAs9lPxxVAErz0HpAAAznQ"]
[Tue Jul 21 07:50:20.655743 2026] [security2:error] [pid 302018:tid 302223] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9O7IAs9lPxxVAErz0HpAAAznQ"]
[Tue Jul 21 07:50:20.688581 2026] [security2:error] [pid 302018:tid 302266] [client 20.220.225.223:38661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/byp8.php"] [unique_id "al9O7IAs9lPxxVAErz0HqAAAAPk"]
[Tue Jul 21 07:50:20.828793 2026] [security2:error] [pid 296703:tid 296899] [client 20.151.10.161:63399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/f35.update.php"] [unique_id "al9O7Cn25uliftkV1n4q0QAAAEI"]
[Tue Jul 21 07:50:20.891129 2026] [security2:error] [pid 302018:tid 302230] [client 41.68.90.219:61175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O7IAs9lPxxVAErz0HrAAAANU"]
[Tue Jul 21 07:50:20.892533 2026] [security2:error] [pid 302018:tid 302230] [client 41.68.90.219:61175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O7IAs9lPxxVAErz0HrAAAANU"]
[Tue Jul 21 07:50:20.904484 2026] [security2:error] [pid 302018:tid 302192] [client 122.162.144.145:4815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9O7IAs9lPxxVAErz0HrQAAAK8"]
[Tue Jul 21 07:50:20.904635 2026] [security2:error] [pid 302018:tid 302192] [client 122.162.144.145:4815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9O7IAs9lPxxVAErz0HrQAAAK8"]
[Tue Jul 21 07:50:21.191109 2026] [security2:error] [pid 296703:tid 296805] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9O7Sn25uliftkV1n4q1wAAaGU"]
[Tue Jul 21 07:50:21.191289 2026] [security2:error] [pid 296703:tid 296937] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9O7Sn25uliftkV1n4q1wAAaGU"]
[Tue Jul 21 07:50:21.203802 2026] [security2:error] [pid 296703:tid 296878] [client 20.151.10.161:62579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/f900.php"] [unique_id "al9O7Sn25uliftkV1n4q2AAAAC0"]
[Tue Jul 21 07:50:21.245445 2026] [security2:error] [pid 296703:tid 296867] [client 20.151.10.161:43932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/hypo.php"] [unique_id "al9O7Sn25uliftkV1n4q2QAAACI"]
[Tue Jul 21 07:50:21.390387 2026] [security2:error] [pid 296703:tid 296838] [client 4.204.201.85:57830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/eee.php"] [unique_id "al9O7Sn25uliftkV1n4q4gAAAAU"]
[Tue Jul 21 07:50:21.419060 2026] [security2:error] [pid 296703:tid 296886] [client 62.102.148.187:33452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9O7Sn25uliftkV1n4q4wAAADU"]
[Tue Jul 21 07:50:21.419144 2026] [security2:error] [pid 296703:tid 296886] [client 62.102.148.187:33452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9O7Sn25uliftkV1n4q4wAAADU"]
[Tue Jul 21 07:50:21.758209 2026] [security2:error] [pid 296703:tid 296840] [client 20.151.10.161:63455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/xmrl.php"] [unique_id "al9O7Sn25uliftkV1n4q7wAAAAc"]
[Tue Jul 21 07:50:21.815292 2026] [security2:error] [pid 296703:tid 296858] [client 20.197.192.193:8321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/wp-signup.php"] [unique_id "al9O7Sn25uliftkV1n4q8QAAABk"]
[Tue Jul 21 07:50:21.843733 2026] [security2:error] [pid 296703:tid 296891] [client 20.104.96.117:59764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/xyn.php"] [unique_id "al9O7Sn25uliftkV1n4q8gAAADo"]
[Tue Jul 21 07:50:21.977420 2026] [security2:error] [pid 302018:tid 302168] [client 20.151.10.161:2749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roupasatacado44.com.br.factorial.studio"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9O7YAs9lPxxVAErz0HrwAAAJc"]
[Tue Jul 21 07:50:22.178746 2026] [security2:error] [pid 302018:tid 302208] [client 20.151.10.161:62963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/memberfuns.php"] [unique_id "al9O7oAs9lPxxVAErz0HsgAAAL8"]
[Tue Jul 21 07:50:22.273117 2026] [security2:error] [pid 302018:tid 302175] [client 20.151.10.161:2750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roupasatacado44.com.br.factorial.studio"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9O7oAs9lPxxVAErz0HtgAAAJ4"]
[Tue Jul 21 07:50:22.289665 2026] [security2:error] [pid 296703:tid 296956] [client 4.204.201.85:51004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/wp-aothait.php"] [unique_id "al9O7in25uliftkV1n4q_AAAAHs"]
[Tue Jul 21 07:50:22.341451 2026] [security2:error] [pid 296703:tid 296852] [client 103.166.103.129:31966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9O7in25uliftkV1n4q_gAAABM"]
[Tue Jul 21 07:50:22.341567 2026] [security2:error] [pid 296703:tid 296852] [client 103.166.103.129:31966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9O7in25uliftkV1n4q_gAAABM"]
[Tue Jul 21 07:50:22.369153 2026] [security2:error] [pid 296703:tid 296911] [client 104.207.58.210:45083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9O7in25uliftkV1n4q-AAAAE4"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:50:22.549736 2026] [security2:error] [pid 302018:tid 302275] [client 20.151.10.161:2952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roupasatacado44.com.br.factorial.studio"] [uri "/images.php"] [unique_id "al9O7oAs9lPxxVAErz0HuQAAAQI"]
[Tue Jul 21 07:50:22.570050 2026] [security2:error] [pid 302018:tid 302151] [client 20.197.192.193:9420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/csa.php"] [unique_id "al9O7oAs9lPxxVAErz0HugAAAIY"]
[Tue Jul 21 07:50:22.656749 2026] [security2:error] [pid 302018:tid 302262] [client 20.151.10.161:64196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/ms.php"] [unique_id "al9O7oAs9lPxxVAErz0HvAAAAPU"]
[Tue Jul 21 07:50:22.812631 2026] [security2:error] [pid 302018:tid 302277] [client 4.204.201.85:51006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/config.json.php"] [unique_id "al9O7oAs9lPxxVAErz0HvwAAAQQ"]
[Tue Jul 21 07:50:22.832109 2026] [security2:error] [pid 296703:tid 296919] [client 20.151.10.161:2730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roupasatacado44.com.br.factorial.studio"] [uri "/for.php"] [unique_id "al9O7in25uliftkV1n4rCAAAAFY"]
[Tue Jul 21 07:50:22.977455 2026] [core:error] [pid 302018:tid 302054] [remote 40.77.167.152:62053] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:22.977484 2026] [core:error] [pid 302018:tid 302054] [remote 40.77.167.152:62053] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:23.010347 2026] [security2:error] [pid 302018:tid 302176] [client 20.151.10.161:63478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/zz.php"] [unique_id "al9O74As9lPxxVAErz0HwQAAAJ8"]
[Tue Jul 21 07:50:23.083691 2026] [security2:error] [pid 302018:tid 302212] [client 109.60.28.94:25813] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O74As9lPxxVAErz0HwgAAAMM"]
[Tue Jul 21 07:50:23.083800 2026] [security2:error] [pid 302018:tid 302212] [client 109.60.28.94:25813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O74As9lPxxVAErz0HwgAAAMM"]
[Tue Jul 21 07:50:23.105932 2026] [core:error] [pid 302018:tid 302071] [remote 40.77.167.152:62053] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:23.105948 2026] [core:error] [pid 302018:tid 302071] [remote 40.77.167.152:62053] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:23.109677 2026] [security2:error] [pid 302018:tid 302153] [client 20.151.10.161:2715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roupasatacado44.com.br.factorial.studio"] [uri "/2larp.php"] [unique_id "al9O74As9lPxxVAErz0HxAAAAIg"]
[Tue Jul 21 07:50:23.395243 2026] [security2:error] [pid 302018:tid 302266] [client 20.220.225.223:32308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/dr.php"] [unique_id "al9O74As9lPxxVAErz0HxwAAAPk"]
[Tue Jul 21 07:50:23.399015 2026] [security2:error] [pid 296703:tid 296882] [client 20.151.10.161:2985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roupasatacado44.com.br.factorial.studio"] [uri "/adminner.php"] [unique_id "al9O7yn25uliftkV1n4rEAAAADE"]
[Tue Jul 21 07:50:23.421918 2026] [security2:error] [pid 302018:tid 302225] [client 4.204.201.85:51007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9O74As9lPxxVAErz0HyAAAANA"]
[Tue Jul 21 07:50:23.468660 2026] [security2:error] [pid 296703:tid 296892] [client 20.197.195.24:10719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/ms.php"] [unique_id "al9O7yn25uliftkV1n4rEQAAADs"]
[Tue Jul 21 07:50:23.583577 2026] [security2:error] [pid 302018:tid 302214] [client 194.99.104.35:60222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9O74As9lPxxVAErz0HygAAAMU"]
[Tue Jul 21 07:50:23.583698 2026] [security2:error] [pid 302018:tid 302214] [client 194.99.104.35:60222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9O74As9lPxxVAErz0HygAAAMU"]
[Tue Jul 21 07:50:23.678912 2026] [security2:error] [pid 302018:tid 302178] [client 20.151.10.161:2976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roupasatacado44.com.br.factorial.studio"] [uri "/82.php"] [unique_id "al9O74As9lPxxVAErz0HzAAAAKE"]
[Tue Jul 21 07:50:23.686941 2026] [security2:error] [pid 296703:tid 296924] [client 20.151.10.161:63388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/for.php"] [unique_id "al9O7yn25uliftkV1n4rFgAAAFs"]
[Tue Jul 21 07:50:23.731583 2026] [security2:error] [pid 296703:tid 296834] [client 20.220.225.223:38671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/user.php"] [unique_id "al9O7yn25uliftkV1n4rFwAAAAE"]
[Tue Jul 21 07:50:23.851628 2026] [security2:error] [pid 296703:tid 296760] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O7yn25uliftkV1n4rGgAARjg"]
[Tue Jul 21 07:50:23.851746 2026] [security2:error] [pid 296703:tid 296903] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O7yn25uliftkV1n4rGgAARjg"]
[Tue Jul 21 07:50:23.948669 2026] [core:error] [pid 302018:tid 302136] [remote 40.77.167.152:62053] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:23.948693 2026] [core:error] [pid 302018:tid 302136] [remote 40.77.167.152:62053] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:23.957044 2026] [security2:error] [pid 296703:tid 296908] [client 20.151.10.161:2988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roupasatacado44.com.br.factorial.studio"] [uri "/kir.php"] [unique_id "al9O7yn25uliftkV1n4rHQAAAEs"]
[Tue Jul 21 07:50:24.051202 2026] [security2:error] [pid 302018:tid 302275] [client 65.21.113.253:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mindsetinfluencer.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9O8IAs9lPxxVAErz0H2AAAAQI"]
[Tue Jul 21 07:50:24.051666 2026] [security2:error] [pid 302018:tid 302194] [client 65.21.113.253:50430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mindsetinfluencer.com.br"] [uri "/robots.txt"] [unique_id "al9O8IAs9lPxxVAErz0H1gAAALE"]
[Tue Jul 21 07:50:24.092432 2026] [security2:error] [pid 296703:tid 296940] [client 182.8.255.181:17343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9O8Cn25uliftkV1n4rHwAAAGs"]
[Tue Jul 21 07:50:24.092537 2026] [security2:error] [pid 296703:tid 296940] [client 182.8.255.181:17343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9O8Cn25uliftkV1n4rHwAAAGs"]
[Tue Jul 21 07:50:24.103224 2026] [security2:error] [pid 296703:tid 296883] [client 136.144.33.110:30969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9O8Cn25uliftkV1n4rIQAAADI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:50:24.116500 2026] [security2:error] [pid 302018:tid 302131] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O8IAs9lPxxVAErz0H2gAAxG4"]
[Tue Jul 21 07:50:24.116618 2026] [security2:error] [pid 302018:tid 302213] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O8IAs9lPxxVAErz0H2gAAxG4"]
[Tue Jul 21 07:50:24.120682 2026] [security2:error] [pid 302018:tid 302269] [client 20.104.96.117:59774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/patie.php"] [unique_id "al9O8IAs9lPxxVAErz0H2wAAAPw"]
[Tue Jul 21 07:50:24.340767 2026] [security2:error] [pid 302018:tid 302207] [client 59.96.220.140:64435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9O8IAs9lPxxVAErz0H3QAAAL4"]
[Tue Jul 21 07:50:24.340897 2026] [security2:error] [pid 302018:tid 302207] [client 59.96.220.140:64435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9O8IAs9lPxxVAErz0H3QAAAL4"]
[Tue Jul 21 07:50:24.373762 2026] [security2:error] [pid 302018:tid 302176] [client 4.204.201.85:51267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/k2.php"] [unique_id "al9O8IAs9lPxxVAErz0H4QAAAJ8"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:50:24.503378 2026] [security2:error] [pid 302018:tid 302242] [client 74.249.245.134:64084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ms-edit.php"] [unique_id "al9O8IAs9lPxxVAErz0H5QAAAOE"]
[Tue Jul 21 07:50:24.503407 2026] [security2:error] [pid 302018:tid 302204] [client 74.249.245.134:65109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/alfa.php"] [unique_id "al9O8IAs9lPxxVAErz0H5AAAALs"]
[Tue Jul 21 07:50:24.586117 2026] [security2:error] [pid 296703:tid 296918] [client 20.151.10.161:43865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/chosen.php"] [unique_id "al9O8Cn25uliftkV1n4rKgAAAFU"]
[Tue Jul 21 07:50:24.618292 2026] [security2:error] [pid 302018:tid 302166] [client 20.151.10.161:63474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/yup.php"] [unique_id "al9O8IAs9lPxxVAErz0H5gAAAJU"]
[Tue Jul 21 07:50:24.924066 2026] [security2:error] [pid 302018:tid 302277] [client 154.192.233.199:59578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O8IAs9lPxxVAErz0H7QAAAQQ"]
[Tue Jul 21 07:50:24.924176 2026] [security2:error] [pid 302018:tid 302277] [client 154.192.233.199:59578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O8IAs9lPxxVAErz0H7QAAAQQ"]
[Tue Jul 21 07:50:24.931777 2026] [security2:error] [pid 302018:tid 302178] [client 4.204.201.85:21889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9O8IAs9lPxxVAErz0H7gAAAKE"]
[Tue Jul 21 07:50:24.999791 2026] [security2:error] [pid 296703:tid 296902] [client 65.21.113.253:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mindsetinfluencer.com.br"] [uri "/index.html"] [unique_id "al9O8Cn25uliftkV1n4rMgAAAEU"]
[Tue Jul 21 07:50:25.000725 2026] [security2:error] [pid 302018:tid 302158] [client 65.21.113.253:50446] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mindsetinfluencer.com.br"] [uri "/"] [unique_id "al9O8IAs9lPxxVAErz0H8AAAAI0"]
[Tue Jul 21 07:50:25.074533 2026] [security2:error] [pid 302018:tid 302181] [client 122.186.204.214:63992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O8YAs9lPxxVAErz0H8QAAAKQ"]
[Tue Jul 21 07:50:25.074686 2026] [security2:error] [pid 302018:tid 302181] [client 122.186.204.214:63992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O8YAs9lPxxVAErz0H8QAAAKQ"]
[Tue Jul 21 07:50:25.227417 2026] [security2:error] [pid 302018:tid 302189] [client 62.102.148.187:37804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9O8YAs9lPxxVAErz0H8wAAAKw"]
[Tue Jul 21 07:50:25.227517 2026] [security2:error] [pid 302018:tid 302189] [client 62.102.148.187:37804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9O8YAs9lPxxVAErz0H8wAAAKw"]
[Tue Jul 21 07:50:25.299610 2026] [security2:error] [pid 302018:tid 302186] [client 20.151.10.161:64150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/wpxml.php"] [unique_id "al9O8YAs9lPxxVAErz0H9AAAAKk"]
[Tue Jul 21 07:50:25.324346 2026] [security2:error] [pid 302018:tid 302192] [client 117.247.80.59:34457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O8YAs9lPxxVAErz0H9QAAAK8"]
[Tue Jul 21 07:50:25.324495 2026] [security2:error] [pid 302018:tid 302192] [client 117.247.80.59:34457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O8YAs9lPxxVAErz0H9QAAAK8"]
[Tue Jul 21 07:50:25.353314 2026] [security2:error] [pid 296703:tid 296847] [client 103.86.117.203:62057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O8Sn25uliftkV1n4rNgAAAA4"]
[Tue Jul 21 07:50:25.353475 2026] [security2:error] [pid 296703:tid 296847] [client 103.86.117.203:62057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O8Sn25uliftkV1n4rNgAAAA4"]
[Tue Jul 21 07:50:25.616502 2026] [security2:error] [pid 296703:tid 296848] [client 20.197.192.193:9429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/min.php"] [unique_id "al9O8Sn25uliftkV1n4rPAAAAA8"]
[Tue Jul 21 07:50:25.645315 2026] [security2:error] [pid 296703:tid 296889] [client 128.140.41.193:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9O8Sn25uliftkV1n4rPQAAOEE"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:50:25.656740 2026] [security2:error] [pid 296703:tid 296844] [client 20.197.195.24:20329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/memberfuns.php"] [unique_id "al9O8Sn25uliftkV1n4rQQAAAAs"]
[Tue Jul 21 07:50:25.720912 2026] [security2:error] [pid 296703:tid 296912] [client 20.151.10.161:63469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/fffm.php"] [unique_id "al9O8Sn25uliftkV1n4rQwAAAE8"]
[Tue Jul 21 07:50:25.748378 2026] [security2:error] [pid 302018:tid 302151] [client 4.204.201.85:57773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9O8YAs9lPxxVAErz0H-gAAAIY"]
[Tue Jul 21 07:50:26.198833 2026] [security2:error] [pid 302018:tid 302269] [client 128.140.41.193:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9O8oAs9lPxxVAErz0IAAAA_EA"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:50:26.299669 2026] [security2:error] [pid 296703:tid 296885] [client 4.204.201.85:50998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9O8in25uliftkV1n4rUQAAADQ"]
[Tue Jul 21 07:50:26.305033 2026] [security2:error] [pid 296703:tid 296910] [client 139.167.225.182:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O8in25uliftkV1n4rUgAAAE0"]
[Tue Jul 21 07:50:26.305206 2026] [security2:error] [pid 296703:tid 296910] [client 139.167.225.182:62709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O8in25uliftkV1n4rUgAAAE0"]
[Tue Jul 21 07:50:26.319252 2026] [security2:error] [pid 296703:tid 296896] [client 173.24.185.52:60695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9O8in25uliftkV1n4rUwAAAD8"]
[Tue Jul 21 07:50:26.319372 2026] [security2:error] [pid 296703:tid 296896] [client 173.24.185.52:60695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9O8in25uliftkV1n4rUwAAAD8"]
[Tue Jul 21 07:50:26.331417 2026] [security2:error] [pid 302018:tid 311331] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O8oAs9lPxxVAErz0IAQAA_4U"]
[Tue Jul 21 07:50:26.331540 2026] [security2:error] [pid 302018:tid 302272] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O8oAs9lPxxVAErz0IAQAA_4U"]
[Tue Jul 21 07:50:26.357807 2026] [security2:error] [pid 296703:tid 296834] [client 20.151.10.161:62857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/gecko.php"] [unique_id "al9O8in25uliftkV1n4rVAAAAAE"]
[Tue Jul 21 07:50:26.374579 2026] [security2:error] [pid 302018:tid 302227] [client 20.220.225.223:19288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/track.php"] [unique_id "al9O8oAs9lPxxVAErz0IAgAAANI"]
[Tue Jul 21 07:50:26.463064 2026] [security2:error] [pid 296703:tid 296862] [client 20.104.96.117:59755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/aa.php"] [unique_id "al9O8in25uliftkV1n4rVgAAAB0"]
[Tue Jul 21 07:50:26.505288 2026] [security2:error] [pid 302018:tid 302194] [client 178.153.91.96:32729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9O8oAs9lPxxVAErz0IBAAAALE"]
[Tue Jul 21 07:50:26.505398 2026] [security2:error] [pid 302018:tid 302194] [client 178.153.91.96:32729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9O8oAs9lPxxVAErz0IBAAAALE"]
[Tue Jul 21 07:50:26.862985 2026] [security2:error] [pid 296703:tid 296891] [client 20.151.10.161:62918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/a1.php"] [unique_id "al9O8in25uliftkV1n4rYAAAADo"]
[Tue Jul 21 07:50:27.012310 2026] [security2:error] [pid 296703:tid 296892] [client 103.29.114.44:53346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O8yn25uliftkV1n4rZwAAADs"]
[Tue Jul 21 07:50:27.012461 2026] [security2:error] [pid 296703:tid 296892] [client 103.29.114.44:53346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O8yn25uliftkV1n4rZwAAADs"]
[Tue Jul 21 07:50:27.332366 2026] [security2:error] [pid 302018:tid 302267] [client 20.151.10.161:64133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/k2.php"] [unique_id "al9O84As9lPxxVAErz0ICwAAAPo"]
[Tue Jul 21 07:50:27.361303 2026] [security2:error] [pid 302018:tid 302224] [client 20.220.225.223:38682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/ops.php"] [unique_id "al9O84As9lPxxVAErz0IDAAAAM8"]
[Tue Jul 21 07:50:27.510385 2026] [security2:error] [pid 302018:tid 302277] [client 4.204.201.85:50953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/for.php"] [unique_id "al9O84As9lPxxVAErz0IFQAAAQQ"]
[Tue Jul 21 07:50:27.528071 2026] [security2:error] [pid 302018:tid 302234] [client 193.36.225.151:30521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9O84As9lPxxVAErz0IDQAAANk"], referer: https://efrelectronics.com.br/wp-admin/
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:50:27.804760 2026] [security2:error] [pid 302018:tid 302203] [client 20.151.10.161:43949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/als.php"] [unique_id "al9O84As9lPxxVAErz0IHAAAALo"]
[Tue Jul 21 07:50:27.909898 2026] [security2:error] [pid 302018:tid 302252] [client 20.151.10.161:64152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/82.php"] [unique_id "al9O84As9lPxxVAErz0IHgAAAOs"]
[Tue Jul 21 07:50:27.939113 2026] [security2:error] [pid 302018:tid 302219] [client 20.104.96.117:59763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/xwpg.php"] [unique_id "al9O84As9lPxxVAErz0IIAAAAMo"]
[Tue Jul 21 07:50:27.969200 2026] [security2:error] [pid 302018:tid 302211] [client 4.204.201.85:51002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seth-quiro.com.br"] [uri "/raw.php"] [unique_id "al9O84As9lPxxVAErz0IIgAAAMI"]
[Tue Jul 21 07:50:27.987065 2026] [security2:error] [pid 302018:tid 302185] [client 122.179.91.63:28084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9O84As9lPxxVAErz0IIwAAAKg"]
[Tue Jul 21 07:50:27.987152 2026] [security2:error] [pid 302018:tid 302185] [client 122.179.91.63:28084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9O84As9lPxxVAErz0IIwAAAKg"]
[Tue Jul 21 07:50:28.127381 2026] [security2:error] [pid 296703:tid 296756] [remote 130.185.118.215:49502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/wp-login.php"] [unique_id "al9O9Cn25uliftkV1n4reAAAUzQ"]
[Tue Jul 21 07:50:28.246674 2026] [security2:error] [pid 296703:tid 296819] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O9Cn25uliftkV1n4reQAAN3M"]
[Tue Jul 21 07:50:28.246857 2026] [security2:error] [pid 296703:tid 296888] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O9Cn25uliftkV1n4reQAAN3M"]
[Tue Jul 21 07:50:28.343968 2026] [security2:error] [pid 302018:tid 302192] [client 117.217.38.194:56214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O9IAs9lPxxVAErz0IJAAAAK8"]
[Tue Jul 21 07:50:28.344058 2026] [security2:error] [pid 302018:tid 302192] [client 117.217.38.194:56214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O9IAs9lPxxVAErz0IJAAAAK8"]
[Tue Jul 21 07:50:28.633852 2026] [security2:error] [pid 296703:tid 296834] [client 20.151.10.161:63464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/config.json.php"] [unique_id "al9O9Cn25uliftkV1n4rhAAAAAE"]
[Tue Jul 21 07:50:28.703152 2026] [security2:error] [pid 302018:tid 302227] [client 20.197.192.193:9423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/echkm.php"] [unique_id "al9O9IAs9lPxxVAErz0IKQAAANI"]
[Tue Jul 21 07:50:28.761773 2026] [security2:error] [pid 302018:tid 302176] [client 20.197.195.24:10729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/0.php"] [unique_id "al9O9IAs9lPxxVAErz0IKgAAAJ8"]
[Tue Jul 21 07:50:28.874230 2026] [security2:error] [pid 302018:tid 302242] [client 20.220.225.223:19314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/2352356666.php"] [unique_id "al9O9IAs9lPxxVAErz0ILQAAAOE"]
[Tue Jul 21 07:50:28.891071 2026] [security2:error] [pid 302018:tid 302250] [client 20.197.192.193:8356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/mac.php"] [unique_id "al9O9IAs9lPxxVAErz0ILgAAAOk"]
[Tue Jul 21 07:50:28.891699 2026] [security2:error] [pid 296703:tid 296876] [client 202.143.127.214:53758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O9Cn25uliftkV1n4rhwAAACs"]
[Tue Jul 21 07:50:28.891770 2026] [security2:error] [pid 296703:tid 296876] [client 202.143.127.214:53758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O9Cn25uliftkV1n4rhwAAACs"]
[Tue Jul 21 07:50:28.959537 2026] [security2:error] [pid 302018:tid 302118] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9O9IAs9lPxxVAErz0ILwABA2E"]
[Tue Jul 21 07:50:28.959728 2026] [security2:error] [pid 302018:tid 302276] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9O9IAs9lPxxVAErz0ILwABA2E"]
[Tue Jul 21 07:50:28.982446 2026] [security2:error] [pid 302018:tid 302194] [client 3.79.134.69:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9O9IAs9lPxxVAErz0IMAAAsXk"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:50:29.179229 2026] [security2:error] [pid 302018:tid 302266] [client 3.79.134.69:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9O9YAs9lPxxVAErz0IMwAA-R0"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:50:29.195354 2026] [security2:error] [pid 302018:tid 302183] [client 20.220.225.223:38690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/term.php"] [unique_id "al9O9YAs9lPxxVAErz0INQAAAKY"]
[Tue Jul 21 07:50:29.342800 2026] [security2:error] [pid 302018:tid 302224] [client 20.151.10.161:62904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "techknowledgebr.com"] [uri "/fpwch.php"] [unique_id "al9O9YAs9lPxxVAErz0INgAAAM8"]
[Tue Jul 21 07:50:29.469935 2026] [security2:error] [pid 296703:tid 296922] [client 20.220.225.223:23432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/ms-new.php"] [unique_id "al9O9Sn25uliftkV1n4rjgAAAFk"]
[Tue Jul 21 07:50:29.481687 2026] [security2:error] [pid 296703:tid 296879] [client 20.151.10.161:43859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/pol.php"] [unique_id "al9O9Sn25uliftkV1n4rjwAAAC4"]
[Tue Jul 21 07:50:29.827289 2026] [security2:error] [pid 302018:tid 302159] [client 180.211.113.210:56573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.113.211.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hostserv.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O9YAs9lPxxVAErz0IOwAAAI4"]
[Tue Jul 21 07:50:29.827524 2026] [security2:error] [pid 302018:tid 302159] [client 180.211.113.210:56573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hostserv.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O9YAs9lPxxVAErz0IOwAAAI4"]
[Tue Jul 21 07:50:29.860917 2026] [security2:error] [pid 302018:tid 302228] [client 37.140.223.154:37283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9O9YAs9lPxxVAErz0IPAAAANM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:50:29.866409 2026] [security2:error] [pid 302018:tid 302153] [client 172.245.102.41:54135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9O9IAs9lPxxVAErz0IKAAAAIg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:50:29.930024 2026] [security2:error] [pid 296703:tid 296960] [client 106.215.181.8:31111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O9Sn25uliftkV1n4rlwAAAH8"]
[Tue Jul 21 07:50:29.939286 2026] [security2:error] [pid 296703:tid 296960] [client 106.215.181.8:31111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O9Sn25uliftkV1n4rlwAAAH8"]
[Tue Jul 21 07:50:29.948934 2026] [security2:error] [pid 296703:tid 296761] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9O9Sn25uliftkV1n4rmAAAbDk"]
[Tue Jul 21 07:50:29.949079 2026] [security2:error] [pid 296703:tid 296941] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9O9Sn25uliftkV1n4rmAAAbDk"]
[Tue Jul 21 07:50:30.144700 2026] [security2:error] [pid 296703:tid 296954] [client 20.104.96.117:64326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/ops.php"] [unique_id "al9O9in25uliftkV1n4rnAAAAHk"]
[Tue Jul 21 07:50:30.325004 2026] [security2:error] [pid 302018:tid 302197] [client 152.59.154.239:58710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.154.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O9oAs9lPxxVAErz0IPwAAALQ"]
[Tue Jul 21 07:50:30.325099 2026] [security2:error] [pid 302018:tid 302197] [client 152.59.154.239:58710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O9oAs9lPxxVAErz0IPwAAALQ"]
[Tue Jul 21 07:50:30.383322 2026] [core:error] [pid 302018:tid 302077] [remote 52.167.144.206:64011] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:30.383348 2026] [core:error] [pid 302018:tid 302077] [remote 52.167.144.206:64011] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:30.447933 2026] [security2:error] [pid 296703:tid 296842] [client 20.151.10.161:43979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/file5.php"] [unique_id "al9O9in25uliftkV1n4roAAAAAk"]
[Tue Jul 21 07:50:30.585895 2026] [security2:error] [pid 296703:tid 296862] [client 47.128.18.188:52018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/robots.txt"] [unique_id "al9O9in25uliftkV1n4roQAAAB0"]
[Tue Jul 21 07:50:30.913360 2026] [security2:error] [pid 302018:tid 302220] [client 20.220.225.223:38710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/ah25.php"] [unique_id "al9O9oAs9lPxxVAErz0ISQAAAMs"]
[Tue Jul 21 07:50:31.031164 2026] [security2:error] [pid 296703:tid 296870] [client 122.164.127.47:64947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9O9yn25uliftkV1n4rqQAAACU"]
[Tue Jul 21 07:50:31.033451 2026] [security2:error] [pid 296703:tid 296870] [client 122.164.127.47:64947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9O9yn25uliftkV1n4rqQAAACU"]
[Tue Jul 21 07:50:31.365447 2026] [security2:error] [pid 296703:tid 296878] [client 34.148.166.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.166.148.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marianapiazentincorr1782084969421.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O9yn25uliftkV1n4rrwAAAC0"]
[Tue Jul 21 07:50:31.513575 2026] [security2:error] [pid 302018:tid 302117] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9O94As9lPxxVAErz0IUAAA0mA"]
[Tue Jul 21 07:50:31.513705 2026] [security2:error] [pid 302018:tid 302227] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9O94As9lPxxVAErz0IUAAA0mA"]
[Tue Jul 21 07:50:31.667335 2026] [security2:error] [pid 302018:tid 302182] [client 41.68.90.219:61616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O94As9lPxxVAErz0IUwAAAKU"]
[Tue Jul 21 07:50:31.668989 2026] [security2:error] [pid 302018:tid 302182] [client 41.68.90.219:61616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O94As9lPxxVAErz0IUwAAAKU"]
[Tue Jul 21 07:50:31.670004 2026] [security2:error] [pid 296703:tid 296854] [client 122.162.144.145:20894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9O9yn25uliftkV1n4rswAAABU"]
[Tue Jul 21 07:50:31.672321 2026] [security2:error] [pid 296703:tid 296854] [client 122.162.144.145:20894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9O9yn25uliftkV1n4rswAAABU"]
[Tue Jul 21 07:50:31.696886 2026] [security2:error] [pid 302018:tid 302254] [client 34.148.166.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marianapiazentincorr1782084969421.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9O94As9lPxxVAErz0IVAAAAO0"]
[Tue Jul 21 07:50:31.793008 2026] [security2:error] [pid 296703:tid 296810] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9O9yn25uliftkV1n4rtgAAaGo"]
[Tue Jul 21 07:50:31.793175 2026] [security2:error] [pid 296703:tid 296937] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9O9yn25uliftkV1n4rtgAAaGo"]
[Tue Jul 21 07:50:31.864253 2026] [security2:error] [pid 302018:tid 302221] [client 20.151.10.161:43797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9O94As9lPxxVAErz0IVwAAAMw"]
[Tue Jul 21 07:50:31.960552 2026] [security2:error] [pid 296703:tid 296910] [client 34.148.166.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marianapiazentincorr1782084969421.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9O9yn25uliftkV1n4rtwAAAE0"]
[Tue Jul 21 07:50:32.036700 2026] [security2:error] [pid 302018:tid 302153] [client 20.197.195.24:20334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/BDKR28.php"] [unique_id "al9O-IAs9lPxxVAErz0IXAAAAIg"]
[Tue Jul 21 07:50:32.225308 2026] [security2:error] [pid 296703:tid 296948] [client 34.148.166.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marianapiazentincorr1782084969421.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9O-Cn25uliftkV1n4rvAAAAHM"]
[Tue Jul 21 07:50:32.304979 2026] [security2:error] [pid 302018:tid 302243] [client 114.119.138.183:58569] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.betoperroy.com.br"] [uri "/image/saladas-fogao.jpg"] [unique_id "al9O-IAs9lPxxVAErz0IXwAAAOI"], referer: http://www.betoperroy.com.br/image/saladas-fogao.jpg
[Tue Jul 21 07:50:32.509327 2026] [security2:error] [pid 296703:tid 296883] [client 34.148.166.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marianapiazentincorr1782084969421.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9O-Cn25uliftkV1n4rwAAAADI"]
[Tue Jul 21 07:50:32.535718 2026] [security2:error] [pid 302018:tid 302178] [client 37.140.223.134:61119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9O-IAs9lPxxVAErz0IYQAAAKE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:50:32.634565 2026] [security2:error] [pid 296703:tid 296932] [client 20.197.192.193:9424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/samll.php"] [unique_id "al9O-Cn25uliftkV1n4rwwAAAGM"]
[Tue Jul 21 07:50:32.721670 2026] [security2:error] [pid 302018:tid 302256] [client 103.166.103.129:64568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9O-IAs9lPxxVAErz0IbAAAAO8"]
[Tue Jul 21 07:50:32.722173 2026] [security2:error] [pid 302018:tid 302256] [client 103.166.103.129:64568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9O-IAs9lPxxVAErz0IbAAAAO8"]
[Tue Jul 21 07:50:32.725398 2026] [security2:error] [pid 296703:tid 296849] [client 20.104.96.117:59752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/mac.php"] [unique_id "al9O-Cn25uliftkV1n4ryAAAABA"]
[Tue Jul 21 07:50:32.768475 2026] [security2:error] [pid 296703:tid 296939] [client 34.148.166.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marianapiazentincorr1782084969421.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9O-Cn25uliftkV1n4rygAAAGo"]
[Tue Jul 21 07:50:32.814805 2026] [security2:error] [pid 296703:tid 296805] [remote 97.74.93.24:48038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "health-24.shop"] [uri "/wp-login.php"] [unique_id "al9O-Cn25uliftkV1n4rywAAK2U"]
[Tue Jul 21 07:50:32.870461 2026] [security2:error] [pid 302018:tid 302202] [client 20.220.225.223:38717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/8.php"] [unique_id "al9O-IAs9lPxxVAErz0IbQAAALk"]
[Tue Jul 21 07:50:32.951412 2026] [security2:error] [pid 302018:tid 302114] [remote 97.74.93.24:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9O-IAs9lPxxVAErz0IbwAA1F0"]
[Tue Jul 21 07:50:33.052928 2026] [security2:error] [pid 302018:tid 302245] [client 34.148.166.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marianapiazentincorr1782084969421.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9O-YAs9lPxxVAErz0IcQAAAOQ"]
[Tue Jul 21 07:50:33.238061 2026] [security2:error] [pid 302018:tid 302070] [remote 216.73.160.31:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-login.php"] [unique_id "al9O-YAs9lPxxVAErz0IcgAAkDE"]
[Tue Jul 21 07:50:33.317788 2026] [security2:error] [pid 302018:tid 302250] [client 34.148.166.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marianapiazentincorr1782084969421.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9O-YAs9lPxxVAErz0IcwAAAOk"]
[Tue Jul 21 07:50:33.454651 2026] [security2:error] [pid 302018:tid 302262] [client 20.151.10.161:44001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/file.php"] [unique_id "al9O-YAs9lPxxVAErz0IdAAAAPU"]
[Tue Jul 21 07:50:33.581117 2026] [security2:error] [pid 296703:tid 296842] [client 34.148.166.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marianapiazentincorr1782084969421.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9O-Sn25uliftkV1n4r2AAAAAk"]
[Tue Jul 21 07:50:33.584352 2026] [security2:error] [pid 296703:tid 296908] [client 193.36.225.56:41991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9O-Sn25uliftkV1n4r2QAAAEs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:50:33.609382 2026] [security2:error] [pid 302018:tid 302230] [client 74.249.245.134:8787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/simple.php"] [unique_id "al9O-YAs9lPxxVAErz0IfAAAANU"]
[Tue Jul 21 07:50:33.712263 2026] [security2:error] [pid 302018:tid 302234] [client 20.197.195.24:20341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/green1.php"] [unique_id "al9O-YAs9lPxxVAErz0IfQAAANk"]
[Tue Jul 21 07:50:33.841030 2026] [security2:error] [pid 296703:tid 296911] [client 34.148.166.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marianapiazentincorr1782084969421.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9O-Sn25uliftkV1n4r3QAAAE4"]
[Tue Jul 21 07:50:33.961170 2026] [security2:error] [pid 302018:tid 302172] [client 20.197.192.193:8348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/abcd.php"] [unique_id "al9O-YAs9lPxxVAErz0IfwAAAJs"]
[Tue Jul 21 07:50:33.984520 2026] [security2:error] [pid 302018:tid 302249] [client 20.104.96.117:59758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/mg.php"] [unique_id "al9O-YAs9lPxxVAErz0IgQAAAOg"]
[Tue Jul 21 07:50:34.014404 2026] [security2:error] [pid 302018:tid 302179] [client 109.60.28.94:26239] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O-oAs9lPxxVAErz0IggAAAKI"]
[Tue Jul 21 07:50:34.014529 2026] [security2:error] [pid 302018:tid 302179] [client 109.60.28.94:26239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O-oAs9lPxxVAErz0IggAAAKI"]
[Tue Jul 21 07:50:34.104917 2026] [security2:error] [pid 302018:tid 302246] [client 34.148.166.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marianapiazentincorr1782084969421.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9O-oAs9lPxxVAErz0IhAAAAOU"]
[Tue Jul 21 07:50:34.364298 2026] [security2:error] [pid 302018:tid 302174] [client 34.148.166.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marianapiazentincorr1782084969421.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9O-oAs9lPxxVAErz0IiQAAAJ0"]
[Tue Jul 21 07:50:34.433358 2026] [security2:error] [pid 296703:tid 296873] [client 20.226.60.151:53986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/mosty.php"] [unique_id "al9O-in25uliftkV1n4r4wAAACg"]
[Tue Jul 21 07:50:34.463217 2026] [security2:error] [pid 302018:tid 302251] [client 182.8.255.181:17529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9O-oAs9lPxxVAErz0IigAAAOo"]
[Tue Jul 21 07:50:34.463428 2026] [security2:error] [pid 302018:tid 302251] [client 182.8.255.181:17529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9O-oAs9lPxxVAErz0IigAAAOo"]
[Tue Jul 21 07:50:34.616031 2026] [security2:error] [pid 302018:tid 302148] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O-oAs9lPxxVAErz0IjAAAxn8"]
[Tue Jul 21 07:50:34.616176 2026] [security2:error] [pid 302018:tid 302215] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O-oAs9lPxxVAErz0IjAAAxn8"]
[Tue Jul 21 07:50:34.622982 2026] [security2:error] [pid 302018:tid 302213] [client 34.148.166.21:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "marianapiazentincorr1782084969421.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9O-oAs9lPxxVAErz0IjQAAAMQ"]
[Tue Jul 21 07:50:34.798458 2026] [security2:error] [pid 302018:tid 302024] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O-oAs9lPxxVAErz0IkAABAgM"]
[Tue Jul 21 07:50:34.798608 2026] [security2:error] [pid 302018:tid 302275] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O-oAs9lPxxVAErz0IkAABAgM"]
[Tue Jul 21 07:50:34.878458 2026] [security2:error] [pid 296703:tid 296871] [client 20.197.192.193:8337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/xyn.php"] [unique_id "al9O-in25uliftkV1n4r7AAAACY"]
[Tue Jul 21 07:50:35.032047 2026] [security2:error] [pid 302018:tid 302199] [client 20.197.195.24:20252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/nc4.php"] [unique_id "al9O-4As9lPxxVAErz0IlAAAALY"]
[Tue Jul 21 07:50:35.100013 2026] [security2:error] [pid 302018:tid 302176] [client 20.104.96.117:64334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-post-data.php"] [unique_id "al9O-4As9lPxxVAErz0IlgAAAJ8"]
[Tue Jul 21 07:50:35.590252 2026] [security2:error] [pid 302018:tid 302269] [client 59.96.220.140:64990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9O-4As9lPxxVAErz0ImQAAAPw"]
[Tue Jul 21 07:50:35.590390 2026] [security2:error] [pid 302018:tid 302269] [client 59.96.220.140:64990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9O-4As9lPxxVAErz0ImQAAAPw"]
[Tue Jul 21 07:50:35.622084 2026] [security2:error] [pid 296703:tid 296947] [client 74.249.245.134:65156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9O-yn25uliftkV1n4r-AAAAHI"]
[Tue Jul 21 07:50:35.624874 2026] [security2:error] [pid 302018:tid 302241] [client 20.226.60.151:61533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/6.php"] [unique_id "al9O-4As9lPxxVAErz0ImwAAAOA"]
[Tue Jul 21 07:50:35.794706 2026] [security2:error] [pid 296703:tid 296937] [client 122.186.204.214:64532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O-yn25uliftkV1n4r-QAAAGg"]
[Tue Jul 21 07:50:35.794930 2026] [security2:error] [pid 296703:tid 296937] [client 122.186.204.214:64532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O-yn25uliftkV1n4r-QAAAGg"]
[Tue Jul 21 07:50:35.824860 2026] [security2:error] [pid 302018:tid 302245] [client 103.86.117.203:62601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O-4As9lPxxVAErz0IngAAAOQ"]
[Tue Jul 21 07:50:35.824992 2026] [security2:error] [pid 302018:tid 302245] [client 103.86.117.203:62601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9O-4As9lPxxVAErz0IngAAAOQ"]
[Tue Jul 21 07:50:35.940462 2026] [security2:error] [pid 302018:tid 302173] [client 20.104.96.117:64333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/pucci.php"] [unique_id "al9O-4As9lPxxVAErz0InwAAAJw"]
[Tue Jul 21 07:50:35.994204 2026] [security2:error] [pid 296703:tid 296866] [client 117.247.80.59:25138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O-yn25uliftkV1n4r_QAAACE"]
[Tue Jul 21 07:50:35.994346 2026] [security2:error] [pid 296703:tid 296866] [client 117.247.80.59:25138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O-yn25uliftkV1n4r_QAAACE"]
[Tue Jul 21 07:50:36.600827 2026] [proxy:error] [pid 302018:tid 302244] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:50:36.600923 2026] [proxy_http:error] [pid 302018:tid 302244] [client 64.227.103.192:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:50:36.601543 2026] [proxy:error] [pid 302018:tid 302244] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:50:36.601576 2026] [proxy_http:error] [pid 302018:tid 302244] [client 64.227.103.192:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:50:36.838827 2026] [security2:error] [pid 302018:tid 302276] [client 154.192.233.199:59608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O_IAs9lPxxVAErz0IrgAAAQM"]
[Tue Jul 21 07:50:36.838966 2026] [security2:error] [pid 302018:tid 302276] [client 154.192.233.199:59608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O_IAs9lPxxVAErz0IrgAAAQM"]
[Tue Jul 21 07:50:36.855149 2026] [security2:error] [pid 302018:tid 302234] [client 139.167.225.182:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O_IAs9lPxxVAErz0IsAAAANk"]
[Tue Jul 21 07:50:36.855242 2026] [security2:error] [pid 302018:tid 302234] [client 139.167.225.182:63355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O_IAs9lPxxVAErz0IsAAAANk"]
[Tue Jul 21 07:50:36.949421 2026] [security2:error] [pid 302018:tid 302197] [client 173.24.185.52:61159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9O_IAs9lPxxVAErz0IsQAAALQ"]
[Tue Jul 21 07:50:36.949563 2026] [security2:error] [pid 302018:tid 302197] [client 173.24.185.52:61159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9O_IAs9lPxxVAErz0IsQAAALQ"]
[Tue Jul 21 07:50:36.956193 2026] [security2:error] [pid 302018:tid 302215] [client 20.151.10.161:43941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/cfile.php"] [unique_id "al9O_IAs9lPxxVAErz0IsgAAAMY"]
[Tue Jul 21 07:50:37.006590 2026] [security2:error] [pid 296703:tid 296876] [client 178.153.91.96:54190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9O_Sn25uliftkV1n4sCwAAACs"]
[Tue Jul 21 07:50:37.006706 2026] [security2:error] [pid 296703:tid 296876] [client 178.153.91.96:54190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9O_Sn25uliftkV1n4sCwAAACs"]
[Tue Jul 21 07:50:37.011977 2026] [proxy:error] [pid 302018:tid 302213] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:50:37.012042 2026] [proxy_http:error] [pid 302018:tid 302213] [client 64.227.103.192:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.josevictormacedomene1751221063252.0711679.meusitehostgator.com.br/
[Tue Jul 21 07:50:37.012600 2026] [proxy:error] [pid 302018:tid 302213] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:50:37.012623 2026] [proxy_http:error] [pid 302018:tid 302213] [client 64.227.103.192:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.josevictormacedomene1751221063252.0711679.meusitehostgator.com.br/
[Tue Jul 21 07:50:37.209196 2026] [security2:error] [pid 296703:tid 296842] [client 20.104.96.117:59766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/black.php"] [unique_id "al9O_Sn25uliftkV1n4sDgAAAAk"]
[Tue Jul 21 07:50:37.264160 2026] [security2:error] [pid 302018:tid 302021] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O_YAs9lPxxVAErz0IuAAAwAA"]
[Tue Jul 21 07:50:37.264298 2026] [security2:error] [pid 302018:tid 302209] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O_YAs9lPxxVAErz0IuAAAwAA"]
[Tue Jul 21 07:50:37.705321 2026] [security2:error] [pid 296703:tid 296868] [client 20.226.60.151:53904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9O_Sn25uliftkV1n4sFgAAACM"]
[Tue Jul 21 07:50:37.812776 2026] [security2:error] [pid 302018:tid 302156] [client 103.29.114.44:53969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O_YAs9lPxxVAErz0IvAAAAIs"]
[Tue Jul 21 07:50:37.812899 2026] [security2:error] [pid 302018:tid 302156] [client 103.29.114.44:53969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O_YAs9lPxxVAErz0IvAAAAIs"]
[Tue Jul 21 07:50:37.989931 2026] [security2:error] [pid 302018:tid 302269] [client 20.197.195.24:20308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/a1.php"] [unique_id "al9O_YAs9lPxxVAErz0IvgAAAPw"]
[Tue Jul 21 07:50:38.013225 2026] [security2:error] [pid 302018:tid 302185] [client 37.140.223.163:58885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9O_IAs9lPxxVAErz0IrwAAAKg"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:50:38.113355 2026] [security2:error] [pid 302018:tid 302195] [client 193.36.225.64:20935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9O_oAs9lPxxVAErz0IwAAAALI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:50:38.601376 2026] [security2:error] [pid 296703:tid 296882] [client 20.197.192.193:8324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/byp8.php"] [unique_id "al9O_in25uliftkV1n4sJQAAADE"]
[Tue Jul 21 07:50:38.624972 2026] [security2:error] [pid 302018:tid 302183] [client 20.220.225.223:23456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/track.php"] [unique_id "al9O_oAs9lPxxVAErz0IyAAAAKY"]
[Tue Jul 21 07:50:38.718962 2026] [security2:error] [pid 302018:tid 302178] [client 20.197.195.24:20351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/eee.php"] [unique_id "al9O_oAs9lPxxVAErz0IygAAAKE"]
[Tue Jul 21 07:50:38.727606 2026] [security2:error] [pid 296703:tid 296830] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O_in25uliftkV1n4sJwAAPX4"]
[Tue Jul 21 07:50:38.727749 2026] [security2:error] [pid 296703:tid 296894] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O_in25uliftkV1n4sJwAAPX4"]
[Tue Jul 21 07:50:38.727873 2026] [security2:error] [pid 302018:tid 302223] [client 122.179.91.63:11895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9O_oAs9lPxxVAErz0IywAAAM4"]
[Tue Jul 21 07:50:38.727973 2026] [security2:error] [pid 302018:tid 302223] [client 122.179.91.63:11895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9O_oAs9lPxxVAErz0IywAAAM4"]
[Tue Jul 21 07:50:38.821224 2026] [security2:error] [pid 296703:tid 296870] [client 117.217.38.194:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O_in25uliftkV1n4sKgAAACU"]
[Tue Jul 21 07:50:38.821373 2026] [security2:error] [pid 296703:tid 296870] [client 117.217.38.194:56716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9O_in25uliftkV1n4sKgAAACU"]
[Tue Jul 21 07:50:38.898733 2026] [security2:error] [pid 302018:tid 302174] [client 74.249.245.134:24797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/av.php"] [unique_id "al9O_oAs9lPxxVAErz0IzQAAAJ0"]
[Tue Jul 21 07:50:39.180451 2026] [security2:error] [pid 302018:tid 302188] [client 20.151.10.161:43863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/class-wp.php"] [unique_id "al9O_4As9lPxxVAErz0I0gAAAKs"]
[Tue Jul 21 07:50:39.329226 2026] [security2:error] [pid 302018:tid 302170] [client 20.197.195.24:20311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wp-aothait.php"] [unique_id "al9O_4As9lPxxVAErz0I1QAAAJk"]
[Tue Jul 21 07:50:39.399050 2026] [security2:error] [pid 302018:tid 302272] [client 20.197.192.193:8338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/user.php"] [unique_id "al9O_4As9lPxxVAErz0I1gAAAP8"]
[Tue Jul 21 07:50:39.400124 2026] [security2:error] [pid 302018:tid 302229] [client 20.104.96.117:59756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/zlece.php"] [unique_id "al9O_4As9lPxxVAErz0I1wAAANQ"]
[Tue Jul 21 07:50:39.495274 2026] [security2:error] [pid 302018:tid 302207] [client 20.197.195.24:20296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/config.json.php"] [unique_id "al9O_4As9lPxxVAErz0I2wAAAL4"]
[Tue Jul 21 07:50:39.705713 2026] [security2:error] [pid 296703:tid 296756] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9O_yn25uliftkV1n4sOgAAEjQ"]
[Tue Jul 21 07:50:39.705903 2026] [security2:error] [pid 296703:tid 296851] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9O_yn25uliftkV1n4sOgAAEjQ"]
[Tue Jul 21 07:50:39.924216 2026] [security2:error] [pid 302018:tid 302161] [client 20.197.192.193:9450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/ops.php"] [unique_id "al9O_4As9lPxxVAErz0I3wAAAJA"]
[Tue Jul 21 07:50:40.070580 2026] [security2:error] [pid 296703:tid 296864] [client 20.151.10.161:43943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/admin.php"] [unique_id "al9PACn25uliftkV1n4sQgAAAB8"]
[Tue Jul 21 07:50:40.238205 2026] [security2:error] [pid 302018:tid 302225] [client 20.220.225.223:38707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/red.php"] [unique_id "al9PAIAs9lPxxVAErz0I6AAAANA"]
[Tue Jul 21 07:50:40.467218 2026] [security2:error] [pid 302018:tid 302168] [client 20.220.225.223:19275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/pn.php"] [unique_id "al9PAIAs9lPxxVAErz0I7gAAAJc"]
[Tue Jul 21 07:50:40.468780 2026] [security2:error] [pid 302018:tid 302237] [client 202.143.127.214:54236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PAIAs9lPxxVAErz0I7wAAANw"]
[Tue Jul 21 07:50:40.468901 2026] [security2:error] [pid 302018:tid 302237] [client 202.143.127.214:54236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PAIAs9lPxxVAErz0I7wAAANw"]
[Tue Jul 21 07:50:40.480977 2026] [security2:error] [pid 296703:tid 296930] [client 20.197.195.24:20333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9PACn25uliftkV1n4sSAAAAGE"]
[Tue Jul 21 07:50:40.521830 2026] [security2:error] [pid 302018:tid 302218] [client 106.215.181.8:26558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PAIAs9lPxxVAErz0I8gAAAMk"]
[Tue Jul 21 07:50:40.521959 2026] [security2:error] [pid 302018:tid 302218] [client 106.215.181.8:26558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PAIAs9lPxxVAErz0I8gAAAMk"]
[Tue Jul 21 07:50:40.581459 2026] [security2:error] [pid 302018:tid 302053] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PAIAs9lPxxVAErz0I8wAAnCA"]
[Tue Jul 21 07:50:40.581591 2026] [security2:error] [pid 302018:tid 302173] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PAIAs9lPxxVAErz0I8wAAnCA"]
[Tue Jul 21 07:50:40.836577 2026] [security2:error] [pid 302018:tid 302234] [client 20.104.96.117:64364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/vssrs.php"] [unique_id "al9PAIAs9lPxxVAErz0I9gAAANk"]
[Tue Jul 21 07:50:40.917355 2026] [security2:error] [pid 302018:tid 302193] [client 193.36.225.103:23409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PAIAs9lPxxVAErz0I9QAAALA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:50:41.173415 2026] [security2:error] [pid 302018:tid 302255] [client 20.220.225.223:38685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/fffm.php"] [unique_id "al9PAYAs9lPxxVAErz0JAAAAAO4"]
[Tue Jul 21 07:50:41.337821 2026] [security2:error] [pid 302018:tid 302219] [client 128.127.105.184:46388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9PAYAs9lPxxVAErz0JAQAAAMo"]
[Tue Jul 21 07:50:41.337927 2026] [security2:error] [pid 302018:tid 302219] [client 128.127.105.184:46388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9PAYAs9lPxxVAErz0JAQAAAMo"]
[Tue Jul 21 07:50:41.354912 2026] [security2:error] [pid 302018:tid 302176] [client 20.197.195.24:20266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/k2.php"] [unique_id "al9PAYAs9lPxxVAErz0JAgAAAJ8"]
[Tue Jul 21 07:50:41.463891 2026] [security2:error] [pid 296703:tid 296857] [client 20.220.225.223:23487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/2352356666.php"] [unique_id "al9PASn25uliftkV1n4sYQAAABg"]
[Tue Jul 21 07:50:41.564317 2026] [security2:error] [pid 302018:tid 302240] [client 20.197.195.24:20338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9PAYAs9lPxxVAErz0JBwAAAN8"]
[Tue Jul 21 07:50:41.585842 2026] [security2:error] [pid 296703:tid 296918] [client 20.104.96.117:64276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wicked.php"] [unique_id "al9PASn25uliftkV1n4sZgAAAFU"]
[Tue Jul 21 07:50:41.617611 2026] [security2:error] [pid 296703:tid 296904] [client 20.226.60.151:53984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/qqqa.php"] [unique_id "al9PASn25uliftkV1n4sZwAAAEc"]
[Tue Jul 21 07:50:41.658000 2026] [security2:error] [pid 302018:tid 302241] [client 20.197.195.24:20256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9PAYAs9lPxxVAErz0JCAAAAOA"]
[Tue Jul 21 07:50:41.836987 2026] [security2:error] [pid 302018:tid 302182] [client 122.164.127.47:49156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PAYAs9lPxxVAErz0JDQAAAKU"]
[Tue Jul 21 07:50:41.837142 2026] [security2:error] [pid 302018:tid 302182] [client 122.164.127.47:49156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PAYAs9lPxxVAErz0JDQAAAKU"]
[Tue Jul 21 07:50:42.237756 2026] [security2:error] [pid 296703:tid 296875] [client 41.68.90.219:62054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PAin25uliftkV1n4scgAAACo"]
[Tue Jul 21 07:50:42.239294 2026] [security2:error] [pid 296703:tid 296875] [client 41.68.90.219:62054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PAin25uliftkV1n4scgAAACo"]
[Tue Jul 21 07:50:42.261258 2026] [security2:error] [pid 302018:tid 302277] [client 20.197.195.24:20314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9PAoAs9lPxxVAErz0JEwAAAQQ"]
[Tue Jul 21 07:50:42.324668 2026] [security2:error] [pid 302018:tid 302153] [client 20.220.225.223:38676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/ftde.php"] [unique_id "al9PAoAs9lPxxVAErz0JFgAAAIg"]
[Tue Jul 21 07:50:42.384709 2026] [security2:error] [pid 296703:tid 296744] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PAin25uliftkV1n4sdQAAKCg"]
[Tue Jul 21 07:50:42.384856 2026] [security2:error] [pid 296703:tid 296873] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PAin25uliftkV1n4sdQAAKCg"]
[Tue Jul 21 07:50:42.407557 2026] [security2:error] [pid 296703:tid 296905] [client 122.162.144.145:27544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PAin25uliftkV1n4sdgAAAEg"]
[Tue Jul 21 07:50:42.407660 2026] [security2:error] [pid 296703:tid 296905] [client 122.162.144.145:27544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PAin25uliftkV1n4sdgAAAEg"]
[Tue Jul 21 07:50:42.437063 2026] [security2:error] [pid 296703:tid 296777] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PAin25uliftkV1n4sdwAAUkk"]
[Tue Jul 21 07:50:42.437186 2026] [security2:error] [pid 296703:tid 296915] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PAin25uliftkV1n4sdwAAUkk"]
[Tue Jul 21 07:50:42.562795 2026] [security2:error] [pid 296703:tid 296888] [client 20.104.96.117:59749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/24.php"] [unique_id "al9PAin25uliftkV1n4sfQAAADc"]
[Tue Jul 21 07:50:42.649914 2026] [security2:error] [pid 302018:tid 302262] [client 65.111.21.60:13031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.21.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PAoAs9lPxxVAErz0JGgAAAPU"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:50:42.892890 2026] [security2:error] [pid 296703:tid 296910] [client 20.226.60.151:61778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/aunmc.php"] [unique_id "al9PAin25uliftkV1n4sfwAAAE0"]
[Tue Jul 21 07:50:42.940211 2026] [security2:error] [pid 302018:tid 302237] [client 74.249.245.134:65128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/404.php"] [unique_id "al9PAoAs9lPxxVAErz0JHAAAANw"]
[Tue Jul 21 07:50:43.124333 2026] [security2:error] [pid 296703:tid 296923] [client 20.104.96.117:64338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/xacs.php"] [unique_id "al9PAyn25uliftkV1n4shgAAAFo"]
[Tue Jul 21 07:50:43.364827 2026] [security2:error] [pid 296703:tid 296937] [client 20.197.195.24:20263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/for.php"] [unique_id "al9PAyn25uliftkV1n4sigAAAGg"]
[Tue Jul 21 07:50:43.445493 2026] [security2:error] [pid 296703:tid 296951] [client 103.166.103.129:65102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PAyn25uliftkV1n4slwAAAHY"]
[Tue Jul 21 07:50:43.446053 2026] [security2:error] [pid 296703:tid 296951] [client 103.166.103.129:65102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PAyn25uliftkV1n4slwAAAHY"]
[Tue Jul 21 07:50:43.494600 2026] [security2:error] [pid 302018:tid 302173] [client 20.220.225.223:22470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/kq1.php"] [unique_id "al9PA4As9lPxxVAErz0JHgAAAJw"]
[Tue Jul 21 07:50:43.557937 2026] [security2:error] [pid 302018:tid 302178] [client 74.249.245.134:64097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/gg.php"] [unique_id "al9PA4As9lPxxVAErz0JHwAAAKE"]
[Tue Jul 21 07:50:43.858572 2026] [security2:error] [pid 302018:tid 302244] [client 20.104.96.117:59741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/zildan.php"] [unique_id "al9PA4As9lPxxVAErz0JIQAAAOM"]
[Tue Jul 21 07:50:43.876803 2026] [authz_core:error] [pid 302018:tid 302187] [client 162.241.63.68:0] AH01630: client denied by server configuration: /home1/bastar15/mltlaw.com.br/.user.ini
[Tue Jul 21 07:50:43.918206 2026] [security2:error] [pid 302018:tid 302273] [client 20.151.10.161:44021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/aa2.php"] [unique_id "al9PA4As9lPxxVAErz0JJQAAAQA"]
[Tue Jul 21 07:50:43.985222 2026] [security2:error] [pid 302018:tid 302197] [client 20.197.195.24:20301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/raw.php"] [unique_id "al9PA4As9lPxxVAErz0JJgAAALQ"]
[Tue Jul 21 07:50:44.137122 2026] [security2:error] [pid 296703:tid 296918] [client 193.36.225.120:45399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PBCn25uliftkV1n4srQAAAFU"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:50:44.433464 2026] [autoindex:error] [pid 302018:tid 302272] [client 54.251.12.30:41546] AH01276: Cannot serve directory /home2/tropi058/loja.tropicaliaeyewear.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:50:44.452870 2026] [security2:error] [pid 302018:tid 302203] [client 172.245.102.42:24101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PAoAs9lPxxVAErz0JFAAAALo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:50:44.475637 2026] [security2:error] [pid 302018:tid 302188] [client 20.197.192.193:51598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9PBIAs9lPxxVAErz0JLgAAAKs"]
[Tue Jul 21 07:50:44.572583 2026] [security2:error] [pid 302018:tid 302220] [client 128.127.105.184:57596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PBIAs9lPxxVAErz0JMQAAAMs"]
[Tue Jul 21 07:50:44.572650 2026] [security2:error] [pid 302018:tid 302220] [client 128.127.105.184:57596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PBIAs9lPxxVAErz0JMQAAAMs"]
[Tue Jul 21 07:50:44.691800 2026] [security2:error] [pid 296703:tid 296880] [client 20.104.96.117:64285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/csa.php"] [unique_id "al9PBCn25uliftkV1n4suAAAAC8"]
[Tue Jul 21 07:50:44.695422 2026] [security2:error] [pid 296703:tid 296908] [client 184.75.223.211:57980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PBCn25uliftkV1n4suQAAAEs"]
[Tue Jul 21 07:50:44.695518 2026] [security2:error] [pid 296703:tid 296908] [client 184.75.223.211:57980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PBCn25uliftkV1n4suQAAAEs"]
[Tue Jul 21 07:50:44.726798 2026] [security2:error] [pid 302018:tid 302212] [client 20.197.192.193:58742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9PBIAs9lPxxVAErz0JMwAAAMM"]
[Tue Jul 21 07:50:44.832670 2026] [security2:error] [pid 296703:tid 296860] [client 182.8.255.181:17517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PBCn25uliftkV1n4svAAAABs"]
[Tue Jul 21 07:50:44.832802 2026] [security2:error] [pid 296703:tid 296860] [client 182.8.255.181:17517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PBCn25uliftkV1n4svAAAABs"]
[Tue Jul 21 07:50:45.047353 2026] [security2:error] [pid 302018:tid 302266] [client 20.197.192.193:64066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/dp.php"] [unique_id "al9PBYAs9lPxxVAErz0JNwAAAPk"]
[Tue Jul 21 07:50:45.162404 2026] [security2:error] [pid 296703:tid 296710] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PBSn25uliftkV1n4swQAAUgY"]
[Tue Jul 21 07:50:45.162513 2026] [security2:error] [pid 296703:tid 296915] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PBSn25uliftkV1n4swQAAUgY"]
[Tue Jul 21 07:50:45.387821 2026] [security2:error] [pid 296703:tid 296887] [client 20.197.192.193:58727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/old.php"] [unique_id "al9PBSn25uliftkV1n4swwAAADY"]
[Tue Jul 21 07:50:45.665894 2026] [security2:error] [pid 296703:tid 296885] [client 20.104.96.117:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/w3llscc.php"] [unique_id "al9PBSn25uliftkV1n4syQAAADQ"]
[Tue Jul 21 07:50:45.778293 2026] [security2:error] [pid 302018:tid 302159] [client 20.197.192.193:50794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/ms-new.php"] [unique_id "al9PBYAs9lPxxVAErz0JRwAAAI4"]
[Tue Jul 21 07:50:45.787686 2026] [security2:error] [pid 296703:tid 296746] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PBSn25uliftkV1n4sywAAfio"]
[Tue Jul 21 07:50:45.787834 2026] [security2:error] [pid 296703:tid 296959] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PBSn25uliftkV1n4sywAAfio"]
[Tue Jul 21 07:50:45.938115 2026] [security2:error] [pid 302018:tid 302276] [client 20.220.225.223:19315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9PBYAs9lPxxVAErz0JSwAAAQM"]
[Tue Jul 21 07:50:46.089801 2026] [security2:error] [pid 302018:tid 302174] [client 74.249.245.134:64095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/sql.php"] [unique_id "al9PBoAs9lPxxVAErz0JTAAAAJ0"]
[Tue Jul 21 07:50:46.118259 2026] [security2:error] [pid 296703:tid 296896] [client 109.60.28.94:60154] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PBin25uliftkV1n4szQAAAD8"]
[Tue Jul 21 07:50:46.118407 2026] [security2:error] [pid 296703:tid 296896] [client 109.60.28.94:60154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PBin25uliftkV1n4szQAAAD8"]
[Tue Jul 21 07:50:46.132790 2026] [security2:error] [pid 302018:tid 302171] [client 59.96.220.140:65530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9PBoAs9lPxxVAErz0JUAAAAJo"]
[Tue Jul 21 07:50:46.133464 2026] [security2:error] [pid 302018:tid 302171] [client 59.96.220.140:65530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9PBoAs9lPxxVAErz0JUAAAAJo"]
[Tue Jul 21 07:50:46.294509 2026] [security2:error] [pid 302018:tid 302203] [client 20.151.10.161:43910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/ccou.php"] [unique_id "al9PBoAs9lPxxVAErz0JVAAAALo"]
[Tue Jul 21 07:50:46.298070 2026] [security2:error] [pid 302018:tid 302237] [client 103.86.117.203:63146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PBoAs9lPxxVAErz0JVQAAANw"]
[Tue Jul 21 07:50:46.298176 2026] [security2:error] [pid 302018:tid 302237] [client 103.86.117.203:63146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PBoAs9lPxxVAErz0JVQAAANw"]
[Tue Jul 21 07:50:46.360527 2026] [security2:error] [pid 296703:tid 296927] [client 65.111.22.92:9697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PBCn25uliftkV1n4ssAAAAF4"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:50:46.416898 2026] [security2:error] [pid 302018:tid 302261] [client 20.220.225.223:19318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/dr.php"] [unique_id "al9PBoAs9lPxxVAErz0JWQAAAPQ"]
[Tue Jul 21 07:50:46.508930 2026] [security2:error] [pid 302018:tid 302190] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/.env"] [unique_id "al9PBoAs9lPxxVAErz0JXAAAAK0"]
[Tue Jul 21 07:50:46.546168 2026] [security2:error] [pid 302018:tid 302244] [client 154.192.233.199:60094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PBoAs9lPxxVAErz0JXQAAAOM"]
[Tue Jul 21 07:50:46.546315 2026] [security2:error] [pid 302018:tid 302244] [client 154.192.233.199:60094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PBoAs9lPxxVAErz0JXQAAAOM"]
[Tue Jul 21 07:50:46.619619 2026] [security2:error] [pid 296703:tid 296851] [client 122.186.204.214:65069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PBin25uliftkV1n4s1gAAABI"]
[Tue Jul 21 07:50:46.619753 2026] [security2:error] [pid 296703:tid 296851] [client 122.186.204.214:65069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PBin25uliftkV1n4s1gAAABI"]
[Tue Jul 21 07:50:46.723104 2026] [security2:error] [pid 302018:tid 302193] [client 117.247.80.59:25282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PBoAs9lPxxVAErz0JXwAAALA"]
[Tue Jul 21 07:50:46.723209 2026] [security2:error] [pid 302018:tid 302193] [client 117.247.80.59:25282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PBoAs9lPxxVAErz0JXwAAALA"]
[Tue Jul 21 07:50:46.755019 2026] [security2:error] [pid 302018:tid 302033] [remote 20.153.140.50:55750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9PBoAs9lPxxVAErz0JYQAA5Aw"]
[Tue Jul 21 07:50:46.880310 2026] [security2:error] [pid 302018:tid 302205] [client 20.226.60.151:61568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/uoocf.php"] [unique_id "al9PBoAs9lPxxVAErz0JZAAAALw"]
[Tue Jul 21 07:50:46.883146 2026] [security2:error] [pid 302018:tid 302269] [client 74.7.230.27:57440] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "kotovicz.com"] [uri "/cgi-sys/404.html"] [unique_id "al9PBoAs9lPxxVAErz0JYwAA_G0"]
[Tue Jul 21 07:50:46.995996 2026] [security2:error] [pid 302018:tid 302179] [client 20.220.225.223:19277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/2x.php"] [unique_id "al9PBoAs9lPxxVAErz0JZQAAAKI"]
[Tue Jul 21 07:50:47.080049 2026] [security2:error] [pid 302018:tid 302228] [client 20.197.192.193:50814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/track.php"] [unique_id "al9PB4As9lPxxVAErz0JZgAAANM"]
[Tue Jul 21 07:50:47.174155 2026] [security2:error] [pid 302018:tid 302218] [client 20.104.96.117:64321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wpx.php"] [unique_id "al9PB4As9lPxxVAErz0JZwAAAMk"]
[Tue Jul 21 07:50:47.447582 2026] [security2:error] [pid 302018:tid 302175] [client 139.167.225.182:64006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PB4As9lPxxVAErz0JbgAAAJ4"]
[Tue Jul 21 07:50:47.447732 2026] [security2:error] [pid 302018:tid 302175] [client 139.167.225.182:64006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PB4As9lPxxVAErz0JbgAAAJ4"]
[Tue Jul 21 07:50:47.535422 2026] [autoindex:error] [pid 296703:tid 296926] [client 185.213.175.37:31390] AH01276: Cannot serve directory /home1/monte290/atendimento.monteirosantosesilva.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:50:47.557944 2026] [security2:error] [pid 302018:tid 302262] [client 178.153.91.96:54802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PB4As9lPxxVAErz0JcQAAAPU"]
[Tue Jul 21 07:50:47.558063 2026] [security2:error] [pid 302018:tid 302262] [client 178.153.91.96:54802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PB4As9lPxxVAErz0JcQAAAPU"]
[Tue Jul 21 07:50:47.574204 2026] [security2:error] [pid 296703:tid 296889] [client 173.24.185.52:61626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PByn25uliftkV1n4s4gAAADg"]
[Tue Jul 21 07:50:47.574346 2026] [security2:error] [pid 296703:tid 296889] [client 173.24.185.52:61626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PByn25uliftkV1n4s4gAAADg"]
[Tue Jul 21 07:50:47.678764 2026] [security2:error] [pid 302018:tid 302274] [client 20.197.192.193:58745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/2352356666.php"] [unique_id "al9PB4As9lPxxVAErz0JdAAAAQE"]
[Tue Jul 21 07:50:47.988115 2026] [security2:error] [pid 302018:tid 302197] [client 104.207.61.46:60481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PB4As9lPxxVAErz0JeAAAALQ"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:50:48.272575 2026] [security2:error] [pid 302018:tid 302219] [client 20.197.192.193:64124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/pn.php"] [unique_id "al9PCIAs9lPxxVAErz0JfwAAAMo"]
[Tue Jul 21 07:50:48.369990 2026] [security2:error] [pid 302018:tid 302171] [client 103.29.114.44:12647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PCIAs9lPxxVAErz0JgwAAAJo"]
[Tue Jul 21 07:50:48.370121 2026] [security2:error] [pid 302018:tid 302171] [client 103.29.114.44:12647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PCIAs9lPxxVAErz0JgwAAAJo"]
[Tue Jul 21 07:50:48.392540 2026] [security2:error] [pid 302018:tid 302082] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PCIAs9lPxxVAErz0JhAAAyz0"]
[Tue Jul 21 07:50:48.392671 2026] [security2:error] [pid 302018:tid 302220] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PCIAs9lPxxVAErz0JhAAAyz0"]
[Tue Jul 21 07:50:48.404201 2026] [security2:error] [pid 302018:tid 302224] [client 20.220.225.223:31175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/yup.php"] [unique_id "al9PCIAs9lPxxVAErz0JhQAAAM8"]
[Tue Jul 21 07:50:48.509851 2026] [security2:error] [pid 296703:tid 296936] [client 20.197.192.193:58711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9PCCn25uliftkV1n4s8QAAAGc"]
[Tue Jul 21 07:50:48.760215 2026] [security2:error] [pid 296703:tid 296944] [client 20.197.192.193:58726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/dr.php"] [unique_id "al9PCCn25uliftkV1n4s9gAAAG8"]
[Tue Jul 21 07:50:48.905698 2026] [security2:error] [pid 302018:tid 302200] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/.env.bak"] [unique_id "al9PCIAs9lPxxVAErz0JjgAAALc"]
[Tue Jul 21 07:50:48.907907 2026] [security2:error] [pid 302018:tid 302267] [client 20.197.192.193:50796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/2x.php"] [unique_id "al9PCIAs9lPxxVAErz0JjwAAAPo"]
[Tue Jul 21 07:50:48.936006 2026] [security2:error] [pid 302018:tid 302157] [client 136.144.33.53:20719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PCIAs9lPxxVAErz0JkAAAAIw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:50:48.991074 2026] [security2:error] [pid 296703:tid 296956] [client 194.99.104.35:46754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PCCn25uliftkV1n4s-wAAAHs"]
[Tue Jul 21 07:50:48.991173 2026] [security2:error] [pid 296703:tid 296956] [client 194.99.104.35:46754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PCCn25uliftkV1n4s-wAAAHs"]
[Tue Jul 21 07:50:49.062131 2026] [security2:error] [pid 296703:tid 296954] [client 20.104.96.117:64260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-css.php"] [unique_id "al9PCSn25uliftkV1n4s_AAAAHk"]
[Tue Jul 21 07:50:49.081998 2026] [security2:error] [pid 302018:tid 302277] [client 20.220.225.223:32291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/zzz.php"] [unique_id "al9PCYAs9lPxxVAErz0JkgAAAQQ"]
[Tue Jul 21 07:50:49.119785 2026] [security2:error] [pid 296703:tid 296844] [client 20.197.192.193:50811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/kq1.php"] [unique_id "al9PCSn25uliftkV1n4s_QAAAAs"]
[Tue Jul 21 07:50:49.246180 2026] [security2:error] [pid 302018:tid 302191] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/.env.backup"] [unique_id "al9PCYAs9lPxxVAErz0JkwAAAK4"]
[Tue Jul 21 07:50:49.248750 2026] [security2:error] [pid 296703:tid 296933] [client 122.179.91.63:32004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PCSn25uliftkV1n4s_wAAAGQ"]
[Tue Jul 21 07:50:49.249275 2026] [security2:error] [pid 302018:tid 302102] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PCYAs9lPxxVAErz0JlAAA9lE"]
[Tue Jul 21 07:50:49.249318 2026] [security2:error] [pid 296703:tid 296933] [client 122.179.91.63:32004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PCSn25uliftkV1n4s_wAAAGQ"]
[Tue Jul 21 07:50:49.249417 2026] [security2:error] [pid 302018:tid 302263] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PCYAs9lPxxVAErz0JlAAA9lE"]
[Tue Jul 21 07:50:49.292130 2026] [security2:error] [pid 302018:tid 302156] [client 117.217.38.194:57210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PCYAs9lPxxVAErz0JlgAAAIs"]
[Tue Jul 21 07:50:49.292230 2026] [security2:error] [pid 302018:tid 302156] [client 117.217.38.194:57210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PCYAs9lPxxVAErz0JlgAAAIs"]
[Tue Jul 21 07:50:49.438691 2026] [security2:error] [pid 302018:tid 302218] [client 20.197.192.193:64121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/zzz.php"] [unique_id "al9PCYAs9lPxxVAErz0JmQAAAMk"]
[Tue Jul 21 07:50:49.485332 2026] [security2:error] [pid 302018:tid 302178] [client 20.220.225.223:38709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/jj.php"] [unique_id "al9PCYAs9lPxxVAErz0JngAAAKE"]
[Tue Jul 21 07:50:49.824526 2026] [security2:error] [pid 302018:tid 302226] [client 20.197.192.193:64083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/wicked.php"] [unique_id "al9PCYAs9lPxxVAErz0JpAAAANE"]
[Tue Jul 21 07:50:49.906869 2026] [security2:error] [pid 302018:tid 302257] [client 52.139.36.144:30582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9PCIAs9lPxxVAErz0JjQAAAPA"]
[Tue Jul 21 07:50:49.928120 2026] [security2:error] [pid 302018:tid 302259] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/.env.old"] [unique_id "al9PCYAs9lPxxVAErz0JpwAAAPI"]
[Tue Jul 21 07:50:49.982029 2026] [security2:error] [pid 302018:tid 302199] [client 20.104.96.117:59747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/ho.php"] [unique_id "al9PCYAs9lPxxVAErz0JqQAAALY"]
[Tue Jul 21 07:50:49.984226 2026] [security2:error] [pid 296703:tid 296880] [client 65.111.20.249:61143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PCCn25uliftkV1n4s-gAAAC8"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:50:50.126561 2026] [security2:error] [pid 296703:tid 296959] [client 20.197.192.193:58700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/edit.php"] [unique_id "al9PCin25uliftkV1n4tCAAAAH4"]
[Tue Jul 21 07:50:50.219230 2026] [security2:error] [pid 296703:tid 296919] [client 20.151.10.161:43792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/dr.php"] [unique_id "al9PCin25uliftkV1n4tCgAAAFY"]
[Tue Jul 21 07:50:50.293923 2026] [security2:error] [pid 296703:tid 296897] [client 52.139.36.144:30560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9PCin25uliftkV1n4tDAAAAEA"]
[Tue Jul 21 07:50:50.376975 2026] [security2:error] [pid 296703:tid 296781] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PCin25uliftkV1n4tDwAABE0"]
[Tue Jul 21 07:50:50.377128 2026] [security2:error] [pid 296703:tid 296837] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PCin25uliftkV1n4tDwAABE0"]
[Tue Jul 21 07:50:50.504415 2026] [security2:error] [pid 296703:tid 296864] [client 20.197.192.193:64096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/kua.php"] [unique_id "al9PCin25uliftkV1n4tEQAAAB8"]
[Tue Jul 21 07:50:50.562320 2026] [security2:error] [pid 302018:tid 302219] [client 128.127.105.184:37450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9PCoAs9lPxxVAErz0JrwAAAMo"]
[Tue Jul 21 07:50:50.562395 2026] [security2:error] [pid 302018:tid 302219] [client 128.127.105.184:37450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9PCoAs9lPxxVAErz0JrwAAAMo"]
[Tue Jul 21 07:50:50.647945 2026] [security2:error] [pid 296703:tid 296951] [client 20.220.225.223:38670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/dragonshell.php"] [unique_id "al9PCin25uliftkV1n4tEwAAAHY"]
[Tue Jul 21 07:50:50.733804 2026] [security2:error] [pid 302018:tid 302270] [client 20.197.192.193:64084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/ez.php"] [unique_id "al9PCoAs9lPxxVAErz0JsgAAAP0"]
[Tue Jul 21 07:50:50.739770 2026] [security2:error] [pid 302018:tid 302190] [client 52.139.36.144:33032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/sql.php"] [unique_id "al9PCoAs9lPxxVAErz0JswAAAK0"]
[Tue Jul 21 07:50:50.747472 2026] [security2:error] [pid 302018:tid 302187] [client 20.104.96.117:59748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/xy.php"] [unique_id "al9PCoAs9lPxxVAErz0JtAAAAKo"]
[Tue Jul 21 07:50:50.967334 2026] [security2:error] [pid 302018:tid 302254] [client 20.197.192.193:50771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/fz.php"] [unique_id "al9PCoAs9lPxxVAErz0JvQAAAO0"]
[Tue Jul 21 07:50:51.036106 2026] [security2:error] [pid 302018:tid 302241] [client 52.139.36.144:1167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/1index.php"] [unique_id "al9PC4As9lPxxVAErz0JvwAAAOA"]
[Tue Jul 21 07:50:51.106713 2026] [security2:error] [pid 296703:tid 296845] [client 106.215.181.8:18329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PCyn25uliftkV1n4tGAAAAAw"]
[Tue Jul 21 07:50:51.106897 2026] [security2:error] [pid 296703:tid 296845] [client 106.215.181.8:18329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PCyn25uliftkV1n4tGAAAAAw"]
[Tue Jul 21 07:50:51.114215 2026] [security2:error] [pid 296703:tid 296931] [client 20.197.192.193:50778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/la.php"] [unique_id "al9PCyn25uliftkV1n4tGQAAAGI"]
[Tue Jul 21 07:50:51.117283 2026] [security2:error] [pid 302018:tid 302176] [client 65.111.1.51:15361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.1.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PCoAs9lPxxVAErz0JuQAAAJ8"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:50:51.150681 2026] [security2:error] [pid 302018:tid 302195] [client 20.151.10.161:43924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/xamp.php"] [unique_id "al9PC4As9lPxxVAErz0JwAAAALI"]
[Tue Jul 21 07:50:51.159436 2026] [security2:error] [pid 302018:tid 302097] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PC4As9lPxxVAErz0JwQAAsUw"]
[Tue Jul 21 07:50:51.159566 2026] [security2:error] [pid 302018:tid 302194] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PC4As9lPxxVAErz0JwQAAsUw"]
[Tue Jul 21 07:50:51.182215 2026] [security2:error] [pid 302018:tid 302204] [client 20.197.192.193:51592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9PC4As9lPxxVAErz0JwgAAALs"]
[Tue Jul 21 07:50:51.226743 2026] [security2:error] [pid 296703:tid 296953] [client 20.197.192.193:58696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/inso.php"] [unique_id "al9PCyn25uliftkV1n4tGwAAAHg"]
[Tue Jul 21 07:50:51.294644 2026] [security2:error] [pid 296703:tid 296889] [client 20.197.192.193:51611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/wpx.php"] [unique_id "al9PCyn25uliftkV1n4tHQAAADg"]
[Tue Jul 21 07:50:51.354659 2026] [security2:error] [pid 296703:tid 296866] [client 20.220.225.223:55496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wicked.php"] [unique_id "al9PCyn25uliftkV1n4tIAAAACE"]
[Tue Jul 21 07:50:51.355589 2026] [security2:error] [pid 302018:tid 302247] [client 20.197.192.193:51624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/berlin.php"] [unique_id "al9PC4As9lPxxVAErz0JzAAAAOY"]
[Tue Jul 21 07:50:51.381901 2026] [security2:error] [pid 302018:tid 302268] [client 52.139.36.144:1153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/reop1.php"] [unique_id "al9PC4As9lPxxVAErz0JzgAAAPs"]
[Tue Jul 21 07:50:51.430431 2026] [security2:error] [pid 302018:tid 302075] [remote 41.186.86.12:36303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bestsellerdigital.com.br"] [uri "/wp-login.php"] [unique_id "al9PC4As9lPxxVAErz0JzwAAlTY"]
[Tue Jul 21 07:50:51.432352 2026] [security2:error] [pid 302018:tid 302226] [client 128.127.105.184:37466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PC4As9lPxxVAErz0J0AAAANE"]
[Tue Jul 21 07:50:51.432466 2026] [security2:error] [pid 302018:tid 302226] [client 128.127.105.184:37466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PC4As9lPxxVAErz0J0AAAANE"]
[Tue Jul 21 07:50:51.435717 2026] [security2:error] [pid 296703:tid 296858] [client 20.197.192.193:58743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/billur.php"] [unique_id "al9PCyn25uliftkV1n4tIgAAABk"]
[Tue Jul 21 07:50:51.493016 2026] [security2:error] [pid 296703:tid 296869] [client 20.197.192.193:58689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/mimpi.php"] [unique_id "al9PCyn25uliftkV1n4tJAAAACQ"]
[Tue Jul 21 07:50:51.534095 2026] [security2:error] [pid 302018:tid 302202] [client 20.197.192.193:8336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/term.php"] [unique_id "al9PC4As9lPxxVAErz0J0wAAALk"]
[Tue Jul 21 07:50:51.599284 2026] [security2:error] [pid 302018:tid 302162] [client 20.197.192.193:51594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/dp.php"] [unique_id "al9PC4As9lPxxVAErz0J1gAAAJE"]
[Tue Jul 21 07:50:51.666937 2026] [security2:error] [pid 296703:tid 296946] [client 202.143.127.214:54709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PCyn25uliftkV1n4tJgAAAHE"]
[Tue Jul 21 07:50:51.667530 2026] [security2:error] [pid 296703:tid 296946] [client 202.143.127.214:54709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PCyn25uliftkV1n4tJgAAAHE"]
[Tue Jul 21 07:50:51.708829 2026] [security2:error] [pid 302018:tid 302203] [client 52.139.36.144:30464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/trusj18.php"] [unique_id "al9PC4As9lPxxVAErz0J2QAAALo"]
[Tue Jul 21 07:50:51.777304 2026] [security2:error] [pid 302018:tid 302261] [client 20.197.192.193:64099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/bootstrap.php"] [unique_id "al9PC4As9lPxxVAErz0J3AAAAPQ"]
[Tue Jul 21 07:50:51.802609 2026] [security2:error] [pid 302018:tid 302215] [client 20.220.225.223:6107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/pn.php"] [unique_id "al9PC4As9lPxxVAErz0J3QAAAMY"]
[Tue Jul 21 07:50:51.805700 2026] [security2:error] [pid 296703:tid 296862] [client 20.104.96.117:59729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/loader.php"] [unique_id "al9PCyn25uliftkV1n4tKAAAAB0"]
[Tue Jul 21 07:50:51.815960 2026] [security2:error] [pid 302018:tid 302212] [client 20.197.192.193:64069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/wp-editor.php"] [unique_id "al9PC4As9lPxxVAErz0J3gAAAMM"]
[Tue Jul 21 07:50:51.835845 2026] [security2:error] [pid 302018:tid 302273] [client 185.213.175.37:7642] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "atercbrasil.com.br"] [uri "/"] [unique_id "al9PC4As9lPxxVAErz0J3wAAAQA"]
[Tue Jul 21 07:50:51.909481 2026] [security2:error] [pid 296703:tid 296904] [client 20.197.192.193:50754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/cro.php"] [unique_id "al9PCyn25uliftkV1n4tKgAAAEc"]
[Tue Jul 21 07:50:51.946612 2026] [security2:error] [pid 302018:tid 302187] [client 20.197.192.193:58712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/cron-tab.php"] [unique_id "al9PC4As9lPxxVAErz0J4QAAAKo"]
[Tue Jul 21 07:50:52.070218 2026] [security2:error] [pid 302018:tid 302242] [client 20.197.192.193:58714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/koiy.php"] [unique_id "al9PDIAs9lPxxVAErz0J5QAAAOE"]
[Tue Jul 21 07:50:52.153448 2026] [security2:error] [pid 302018:tid 302233] [client 52.139.36.144:33076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/trusj15.php"] [unique_id "al9PDIAs9lPxxVAErz0J5gAAANg"]
[Tue Jul 21 07:50:52.186739 2026] [security2:error] [pid 296703:tid 296860] [client 74.249.245.134:24789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/file3.php"] [unique_id "al9PDCn25uliftkV1n4tMAAAABs"]
[Tue Jul 21 07:50:52.285594 2026] [security2:error] [pid 302018:tid 302245] [client 20.197.192.193:58740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/hp2.php"] [unique_id "al9PDIAs9lPxxVAErz0J6QAAAOQ"]
[Tue Jul 21 07:50:52.353953 2026] [security2:error] [pid 302018:tid 302255] [client 20.104.96.117:64299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/spadex.php"] [unique_id "al9PDIAs9lPxxVAErz0J6wAAAO4"]
[Tue Jul 21 07:50:52.420633 2026] [security2:error] [pid 302018:tid 302195] [client 20.151.10.161:43947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/bless.php"] [unique_id "al9PDIAs9lPxxVAErz0J7wAAALI"]
[Tue Jul 21 07:50:52.457030 2026] [security2:error] [pid 302018:tid 302191] [client 20.220.225.223:32265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/edit.php"] [unique_id "al9PDIAs9lPxxVAErz0J8QAAAK4"]
[Tue Jul 21 07:50:52.478650 2026] [security2:error] [pid 302018:tid 302158] [client 52.139.36.144:33101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/rft8.php"] [unique_id "al9PDIAs9lPxxVAErz0J8gAAAI0"]
[Tue Jul 21 07:50:52.484541 2026] [security2:error] [pid 302018:tid 302168] [client 122.164.127.47:49742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PDIAs9lPxxVAErz0J8wAAAJc"]
[Tue Jul 21 07:50:52.484631 2026] [security2:error] [pid 302018:tid 302168] [client 122.164.127.47:49742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PDIAs9lPxxVAErz0J8wAAAJc"]
[Tue Jul 21 07:50:52.497345 2026] [security2:error] [pid 302018:tid 302156] [client 20.197.192.193:50802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/hp3.php"] [unique_id "al9PDIAs9lPxxVAErz0J9AAAAIs"]
[Tue Jul 21 07:50:52.636115 2026] [security2:error] [pid 302018:tid 302207] [client 20.197.192.193:58710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/aa1.php"] [unique_id "al9PDIAs9lPxxVAErz0J9wAAAL4"]
[Tue Jul 21 07:50:52.716259 2026] [security2:error] [pid 302018:tid 302276] [client 20.197.192.193:50792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/acew67.php"] [unique_id "al9PDIAs9lPxxVAErz0J-QAAAQM"]
[Tue Jul 21 07:50:52.719620 2026] [security2:error] [pid 302018:tid 302159] [client 62.102.148.187:36592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9PDIAs9lPxxVAErz0J-gAAAI4"]
[Tue Jul 21 07:50:52.719694 2026] [security2:error] [pid 302018:tid 302159] [client 62.102.148.187:36592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9PDIAs9lPxxVAErz0J-gAAAI4"]
[Tue Jul 21 07:50:52.828422 2026] [security2:error] [pid 302018:tid 302257] [client 20.197.192.193:50781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/bscclapb.php"] [unique_id "al9PDIAs9lPxxVAErz0J_wAAAPA"]
[Tue Jul 21 07:50:52.875627 2026] [security2:error] [pid 296703:tid 296852] [client 52.139.36.144:33105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/ai.php"] [unique_id "al9PDCn25uliftkV1n4tNwAAABM"]
[Tue Jul 21 07:50:52.876420 2026] [security2:error] [pid 302018:tid 302225] [client 41.68.90.219:62730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PDIAs9lPxxVAErz0KAAAAANA"]
[Tue Jul 21 07:50:52.879179 2026] [security2:error] [pid 302018:tid 302225] [client 41.68.90.219:62730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PDIAs9lPxxVAErz0KAAAAANA"]
[Tue Jul 21 07:50:52.898388 2026] [security2:error] [pid 296703:tid 296888] [client 20.197.192.193:51630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/else1.php"] [unique_id "al9PDCn25uliftkV1n4tOQAAADc"]
[Tue Jul 21 07:50:52.960403 2026] [security2:error] [pid 296703:tid 296875] [client 122.162.144.145:14241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PDCn25uliftkV1n4tOwAAACo"]
[Tue Jul 21 07:50:52.960533 2026] [security2:error] [pid 296703:tid 296875] [client 122.162.144.145:14241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PDCn25uliftkV1n4tOwAAACo"]
[Tue Jul 21 07:50:53.022040 2026] [security2:error] [pid 302018:tid 302073] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PDYAs9lPxxVAErz0KAgAA6DQ"]
[Tue Jul 21 07:50:53.022306 2026] [security2:error] [pid 302018:tid 302249] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PDYAs9lPxxVAErz0KAgAA6DQ"]
[Tue Jul 21 07:50:53.031022 2026] [security2:error] [pid 296703:tid 296880] [client 20.197.192.193:51631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/tkikikoko.php"] [unique_id "al9PDSn25uliftkV1n4tPgAAAC8"]
[Tue Jul 21 07:50:53.070534 2026] [security2:error] [pid 302018:tid 302237] [client 20.197.192.193:58736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9PDYAs9lPxxVAErz0KBAAAANw"]
[Tue Jul 21 07:50:53.075573 2026] [security2:error] [pid 302018:tid 302214] [client 20.104.96.117:64378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/2x.php"] [unique_id "al9PDYAs9lPxxVAErz0KBQAAAMU"]
[Tue Jul 21 07:50:53.103339 2026] [security2:error] [pid 296703:tid 296870] [client 20.197.192.193:64122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/wp-css.php"] [unique_id "al9PDSn25uliftkV1n4tQQAAACU"]
[Tue Jul 21 07:50:53.191887 2026] [security2:error] [pid 302018:tid 302273] [client 20.197.192.193:64070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/wp-explorer.php"] [unique_id "al9PDYAs9lPxxVAErz0KBwAAAQA"]
[Tue Jul 21 07:50:53.193621 2026] [core:alert] [pid 302018:tid 302256] [client 57.141.18.28:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:50:53.270003 2026] [security2:error] [pid 302018:tid 302105] [remote 182.77.62.24:55958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-login.php"] [unique_id "al9PDYAs9lPxxVAErz0KCQAA2VQ"]
[Tue Jul 21 07:50:53.296733 2026] [security2:error] [pid 296703:tid 296867] [client 52.139.36.144:1169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/fx.php"] [unique_id "al9PDSn25uliftkV1n4tRAAAACI"]
[Tue Jul 21 07:50:53.385854 2026] [security2:error] [pid 296703:tid 296851] [client 20.197.192.193:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/akismet.php"] [unique_id "al9PDSn25uliftkV1n4tSAAAABI"]
[Tue Jul 21 07:50:53.446880 2026] [security2:error] [pid 302018:tid 302138] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PDYAs9lPxxVAErz0KEAAA1HU"]
[Tue Jul 21 07:50:53.447025 2026] [security2:error] [pid 302018:tid 302229] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PDYAs9lPxxVAErz0KEAAA1HU"]
[Tue Jul 21 07:50:53.489225 2026] [security2:error] [pid 296703:tid 296841] [client 20.104.96.117:59743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/ctex1.php"] [unique_id "al9PDSn25uliftkV1n4tTAAAAAg"]
[Tue Jul 21 07:50:53.705225 2026] [security2:error] [pid 296703:tid 296879] [client 20.197.192.193:51619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/ace2.php"] [unique_id "al9PDSn25uliftkV1n4tUAAAAC4"]
[Tue Jul 21 07:50:53.720999 2026] [security2:error] [pid 302018:tid 302182] [client 65.111.29.250:44799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.29.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PDIAs9lPxxVAErz0J9gAAAKU"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:50:53.756482 2026] [security2:error] [pid 296703:tid 296855] [client 52.139.36.144:1214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/xxx.php"] [unique_id "al9PDSn25uliftkV1n4tUQAAABY"]
[Tue Jul 21 07:50:53.875542 2026] [security2:error] [pid 302018:tid 302193] [client 20.197.192.193:58695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.x45consultoria.com.br"] [uri "/ms.php"] [unique_id "al9PDYAs9lPxxVAErz0KGAAAALA"]
[Tue Jul 21 07:50:53.902448 2026] [security2:error] [pid 296703:tid 296929] [client 20.197.192.193:8334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/ah25.php"] [unique_id "al9PDSn25uliftkV1n4tVAAAAGA"]
[Tue Jul 21 07:50:53.971137 2026] [security2:error] [pid 296703:tid 296816] [remote 20.75.217.73:3491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9PDSn25uliftkV1n4tVwAAOnA"]
[Tue Jul 21 07:50:53.986531 2026] [security2:error] [pid 296703:tid 296941] [client 20.151.10.161:43810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/file46.php"] [unique_id "al9PDSn25uliftkV1n4tWAAAAGw"]
[Tue Jul 21 07:50:54.031573 2026] [security2:error] [pid 302018:tid 302248] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/.env.swp"] [unique_id "al9PDoAs9lPxxVAErz0KGgAAAOc"]
[Tue Jul 21 07:50:54.072303 2026] [security2:error] [pid 296703:tid 296945] [client 52.139.36.144:1192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/dropdown.php"] [unique_id "al9PDin25uliftkV1n4tXQAAAHA"]
[Tue Jul 21 07:50:54.212576 2026] [security2:error] [pid 302018:tid 302221] [client 20.104.96.117:64347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/edorxrr.php"] [unique_id "al9PDoAs9lPxxVAErz0KHQAAAMw"]
[Tue Jul 21 07:50:54.240777 2026] [security2:error] [pid 302018:tid 302200] [client 103.166.103.129:33567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PDoAs9lPxxVAErz0KHwAAALc"]
[Tue Jul 21 07:50:54.241673 2026] [security2:error] [pid 302018:tid 302200] [client 103.166.103.129:33567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PDoAs9lPxxVAErz0KHwAAALc"]
[Tue Jul 21 07:50:54.372767 2026] [security2:error] [pid 302018:tid 302260] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/.env~"] [unique_id "al9PDoAs9lPxxVAErz0KIAAAAPM"]
[Tue Jul 21 07:50:54.427915 2026] [security2:error] [pid 296703:tid 296918] [client 74.249.245.134:24809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-mail.php"] [unique_id "al9PDin25uliftkV1n4tYAAAAFU"]
[Tue Jul 21 07:50:54.479402 2026] [security2:error] [pid 296703:tid 296904] [client 184.75.223.211:54046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9PDin25uliftkV1n4tYQAAAEc"]
[Tue Jul 21 07:50:54.479503 2026] [security2:error] [pid 296703:tid 296904] [client 184.75.223.211:54046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9PDin25uliftkV1n4tYQAAAEc"]
[Tue Jul 21 07:50:54.501303 2026] [security2:error] [pid 296703:tid 296925] [client 52.139.36.144:1248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/file11.php"] [unique_id "al9PDin25uliftkV1n4tYwAAAFw"]
[Tue Jul 21 07:50:54.596525 2026] [security2:error] [pid 302018:tid 302264] [client 136.144.33.97:27269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PDYAs9lPxxVAErz0KDwAAAPc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:50:55.061118 2026] [security2:error] [pid 302018:tid 302172] [client 223.236.153.128:4546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PD4As9lPxxVAErz0KJwAAAJs"]
[Tue Jul 21 07:50:55.061254 2026] [security2:error] [pid 302018:tid 302172] [client 223.236.153.128:4546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PD4As9lPxxVAErz0KJwAAAJs"]
[Tue Jul 21 07:50:55.061945 2026] [security2:error] [pid 302018:tid 302163] [client 20.220.225.223:19674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/kq1.php"] [unique_id "al9PD4As9lPxxVAErz0KKQAAAJI"]
[Tue Jul 21 07:50:55.131812 2026] [security2:error] [pid 302018:tid 302151] [client 52.139.36.144:1230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/png.php"] [unique_id "al9PD4As9lPxxVAErz0KKwAAAIY"]
[Tue Jul 21 07:50:55.266334 2026] [security2:error] [pid 296703:tid 296840] [client 182.8.255.181:2881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PDyn25uliftkV1n4tcwAAAAc"]
[Tue Jul 21 07:50:55.266470 2026] [security2:error] [pid 296703:tid 296840] [client 182.8.255.181:2881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PDyn25uliftkV1n4tcwAAAAc"]
[Tue Jul 21 07:50:55.460573 2026] [security2:error] [pid 302018:tid 302164] [client 20.104.96.117:59770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/miru1.php"] [unique_id "al9PD4As9lPxxVAErz0KLwAAAJM"]
[Tue Jul 21 07:50:55.543487 2026] [security2:error] [pid 302018:tid 302272] [client 52.139.36.144:33085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-slss.php"] [unique_id "al9PD4As9lPxxVAErz0KMAAAAP8"]
[Tue Jul 21 07:50:55.620235 2026] [security2:error] [pid 302018:tid 302234] [client 20.151.10.161:43866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/eee.php"] [unique_id "al9PD4As9lPxxVAErz0KMgAAANk"]
[Tue Jul 21 07:50:55.689573 2026] [security2:error] [pid 302018:tid 302038] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PD4As9lPxxVAErz0KOgAA_RE"]
[Tue Jul 21 07:50:55.689695 2026] [security2:error] [pid 302018:tid 302270] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PD4As9lPxxVAErz0KOgAA_RE"]
[Tue Jul 21 07:50:55.891008 2026] [security2:error] [pid 302018:tid 302171] [client 20.197.192.193:27186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9PD4As9lPxxVAErz0KPwAAAJo"]
[Tue Jul 21 07:50:55.930908 2026] [security2:error] [pid 302018:tid 302186] [client 52.139.36.144:33123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/ah25.php"] [unique_id "al9PD4As9lPxxVAErz0KQAAAAKk"]
[Tue Jul 21 07:50:55.940382 2026] [security2:error] [pid 302018:tid 302203] [client 136.144.33.213:21957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PD4As9lPxxVAErz0KPgAAALo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:50:56.068450 2026] [access_compat:error] [pid 302018:tid 302193] [client 162.241.63.68:36880] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:50:56.390646 2026] [core:error] [pid 296703:tid 296790] [remote 198.235.24.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:56.390665 2026] [core:error] [pid 296703:tid 296790] [remote 198.235.24.164:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:50:56.393646 2026] [security2:error] [pid 302018:tid 302260] [client 52.139.36.144:33139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/ccou.php"] [unique_id "al9PEIAs9lPxxVAErz0KRwAAAPM"]
[Tue Jul 21 07:50:56.412053 2026] [security2:error] [pid 302018:tid 302207] [client 20.104.96.117:64328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/sump1.php"] [unique_id "al9PEIAs9lPxxVAErz0KSAAAAL4"]
[Tue Jul 21 07:50:56.462477 2026] [security2:error] [pid 302018:tid 302176] [client 114.119.146.126:55145] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "benattiodontologia.com.br"] [uri "/depoimento/daniel/"] [unique_id "al9PEIAs9lPxxVAErz0KSgAAAJ8"], referer: https://benattiodontologia.com.br/depoimento/daniel/
[Tue Jul 21 07:50:56.498322 2026] [security2:error] [pid 296703:tid 296793] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PECn25uliftkV1n4tgAAAOVk"]
[Tue Jul 21 07:50:56.498511 2026] [security2:error] [pid 296703:tid 296890] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PECn25uliftkV1n4tgAAAOVk"]
[Tue Jul 21 07:50:56.512513 2026] [security2:error] [pid 302018:tid 302255] [client 59.96.220.140:49432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9PEIAs9lPxxVAErz0KSwAAAO4"]
[Tue Jul 21 07:50:56.512638 2026] [security2:error] [pid 302018:tid 302255] [client 59.96.220.140:49432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9PEIAs9lPxxVAErz0KSwAAAO4"]
[Tue Jul 21 07:50:56.542854 2026] [security2:error] [pid 302018:tid 302036] [remote 185.236.20.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9PEIAs9lPxxVAErz0KTAAAog8"]
[Tue Jul 21 07:50:56.551220 2026] [security2:error] [pid 296703:tid 296927] [client 74.249.245.134:24784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/up.php"] [unique_id "al9PECn25uliftkV1n4tggAAAF4"]
[Tue Jul 21 07:50:56.587040 2026] [security2:error] [pid 302018:tid 302227] [client 194.99.104.35:46774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PEIAs9lPxxVAErz0KTQAAANI"]
[Tue Jul 21 07:50:56.587126 2026] [security2:error] [pid 302018:tid 302227] [client 194.99.104.35:46774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PEIAs9lPxxVAErz0KTQAAANI"]
[Tue Jul 21 07:50:56.755647 2026] [security2:error] [pid 296703:tid 296851] [client 52.139.36.144:33027] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.arthromdcanada.online"] [uri "/1.php"] [unique_id "al9PECn25uliftkV1n4thgAAABI"]
[Tue Jul 21 07:50:56.755756 2026] [security2:error] [pid 296703:tid 296851] [client 52.139.36.144:33027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/1.php"] [unique_id "al9PECn25uliftkV1n4thgAAABI"]
[Tue Jul 21 07:50:56.776646 2026] [security2:error] [pid 302018:tid 302191] [client 103.86.117.203:63689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PEIAs9lPxxVAErz0KVAAAAK4"]
[Tue Jul 21 07:50:56.776765 2026] [security2:error] [pid 302018:tid 302191] [client 103.86.117.203:63689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PEIAs9lPxxVAErz0KVAAAAK4"]
[Tue Jul 21 07:50:56.862592 2026] [security2:error] [pid 302018:tid 302247] [client 109.60.28.94:60568] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PEIAs9lPxxVAErz0KVwAAAOY"]
[Tue Jul 21 07:50:56.862747 2026] [security2:error] [pid 302018:tid 302247] [client 109.60.28.94:60568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PEIAs9lPxxVAErz0KVwAAAOY"]
[Tue Jul 21 07:50:56.943518 2026] [security2:error] [pid 302018:tid 302199] [client 74.249.245.134:8828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/about.php"] [unique_id "al9PEIAs9lPxxVAErz0KXAAAALY"]
[Tue Jul 21 07:50:57.105357 2026] [security2:error] [pid 302018:tid 302161] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/app/.env"] [unique_id "al9PEYAs9lPxxVAErz0KXwAAAJA"]
[Tue Jul 21 07:50:57.162056 2026] [security2:error] [pid 302018:tid 311333] [remote 185.236.20.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9PEYAs9lPxxVAErz0KYQAAz4c"], referer: http://hauptmann.com.br/wp-admin/admin-ajax.php
[Tue Jul 21 07:50:57.217923 2026] [security2:error] [pid 296703:tid 296898] [client 20.104.96.117:59715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/file5.php"] [unique_id "al9PESn25uliftkV1n4tiwAAAEE"]
[Tue Jul 21 07:50:57.246069 2026] [security2:error] [pid 302018:tid 302268] [client 154.192.233.199:58754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PEYAs9lPxxVAErz0KagAAAPs"]
[Tue Jul 21 07:50:57.246193 2026] [security2:error] [pid 302018:tid 302268] [client 154.192.233.199:58754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PEYAs9lPxxVAErz0KagAAAPs"]
[Tue Jul 21 07:50:57.303321 2026] [security2:error] [pid 302018:tid 302241] [client 52.139.36.144:33039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/900.php"] [unique_id "al9PEYAs9lPxxVAErz0KawAAAOA"]
[Tue Jul 21 07:50:57.314532 2026] [security2:error] [pid 302018:tid 302226] [client 122.186.204.214:49220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PEYAs9lPxxVAErz0KbAAAANE"]
[Tue Jul 21 07:50:57.314666 2026] [security2:error] [pid 302018:tid 302226] [client 122.186.204.214:49220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PEYAs9lPxxVAErz0KbAAAANE"]
[Tue Jul 21 07:50:57.376424 2026] [security2:error] [pid 302018:tid 302177] [client 20.151.10.161:43923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/file25.php"] [unique_id "al9PEYAs9lPxxVAErz0KbQAAAKA"]
[Tue Jul 21 07:50:57.445398 2026] [security2:error] [pid 302018:tid 302182] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/apps/.env"] [unique_id "al9PEYAs9lPxxVAErz0KbgAAAKU"]
[Tue Jul 21 07:50:57.472424 2026] [security2:error] [pid 302018:tid 302215] [client 117.247.80.59:23608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PEYAs9lPxxVAErz0KbwAAAMY"]
[Tue Jul 21 07:50:57.472541 2026] [security2:error] [pid 302018:tid 302215] [client 117.247.80.59:23608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PEYAs9lPxxVAErz0KbwAAAMY"]
[Tue Jul 21 07:50:57.589062 2026] [security2:error] [pid 302018:tid 302205] [client 20.197.192.193:9565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/8.php"] [unique_id "al9PEYAs9lPxxVAErz0KcQAAALw"]
[Tue Jul 21 07:50:57.689668 2026] [security2:error] [pid 302018:tid 302200] [client 52.139.36.144:24953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/file59.php"] [unique_id "al9PEYAs9lPxxVAErz0KdAAAALc"]
[Tue Jul 21 07:50:57.710326 2026] [security2:error] [pid 302018:tid 302120] [remote 185.236.20.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hauptmann.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9PEYAs9lPxxVAErz0KdQAAu2M"]
[Tue Jul 21 07:50:57.785178 2026] [security2:error] [pid 302018:tid 302218] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/api/.env"] [unique_id "al9PEYAs9lPxxVAErz0KeAAAAMk"]
[Tue Jul 21 07:50:57.814213 2026] [security2:error] [pid 302018:tid 302110] [remote 116.179.37.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9PEYAs9lPxxVAErz0KcwAAjFk"], referer: https://androapkmod.com/hacker/
[Tue Jul 21 07:50:58.047592 2026] [security2:error] [pid 302018:tid 302277] [client 178.153.91.96:55416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PEoAs9lPxxVAErz0KfgAAAQQ"]
[Tue Jul 21 07:50:58.047735 2026] [security2:error] [pid 302018:tid 302277] [client 178.153.91.96:55416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PEoAs9lPxxVAErz0KfgAAAQQ"]
[Tue Jul 21 07:50:58.101675 2026] [security2:error] [pid 302018:tid 302162] [client 52.139.36.144:30545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/amxloxxr.php"] [unique_id "al9PEoAs9lPxxVAErz0KfwAAAJE"]
[Tue Jul 21 07:50:58.126161 2026] [security2:error] [pid 302018:tid 302249] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/web/.env"] [unique_id "al9PEoAs9lPxxVAErz0KgAAAAOg"]
[Tue Jul 21 07:50:58.158692 2026] [security2:error] [pid 302018:tid 302211] [client 104.207.49.238:37437] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "cezaretto.com.br"] [uri "/"] [unique_id "al9PEoAs9lPxxVAErz0KgQAAAMI"]
[Tue Jul 21 07:50:58.213510 2026] [security2:error] [pid 302018:tid 302227] [client 173.24.185.52:62101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PEoAs9lPxxVAErz0KggAAANI"]
[Tue Jul 21 07:50:58.213609 2026] [security2:error] [pid 302018:tid 302227] [client 173.24.185.52:62101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PEoAs9lPxxVAErz0KggAAANI"]
[Tue Jul 21 07:50:58.270595 2026] [security2:error] [pid 296703:tid 296796] [remote 185.236.20.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9PEin25uliftkV1n4tlgAAV1w"]
[Tue Jul 21 07:50:58.307933 2026] [security2:error] [pid 302018:tid 302195] [client 139.167.225.182:64662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PEoAs9lPxxVAErz0KhAAAALI"]
[Tue Jul 21 07:50:58.308034 2026] [security2:error] [pid 302018:tid 302195] [client 139.167.225.182:64662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PEoAs9lPxxVAErz0KhAAAALI"]
[Tue Jul 21 07:50:58.427582 2026] [security2:error] [pid 296703:tid 296857] [client 20.197.192.193:8330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/red.php"] [unique_id "al9PEin25uliftkV1n4tmwAAABg"]
[Tue Jul 21 07:50:58.428305 2026] [security2:error] [pid 302018:tid 302272] [client 104.207.49.238:37437] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "cezaretto.com.br"] [uri "/"] [unique_id "al9PEoAs9lPxxVAErz0KhQAAAP8"]
[Tue Jul 21 07:50:58.430683 2026] [security2:error] [pid 302018:tid 302172] [client 52.139.36.144:33025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/aboutc.php"] [unique_id "al9PEoAs9lPxxVAErz0KhgAAAJs"]
[Tue Jul 21 07:50:58.466119 2026] [security2:error] [pid 302018:tid 302164] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/site/.env"] [unique_id "al9PEoAs9lPxxVAErz0KiQAAAJM"]
[Tue Jul 21 07:50:58.522891 2026] [security2:error] [pid 296703:tid 296902] [client 20.104.96.117:59713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/0xD.php"] [unique_id "al9PEin25uliftkV1n4tngAAAEU"]
[Tue Jul 21 07:50:58.572054 2026] [security2:error] [pid 302018:tid 302188] [client 20.220.225.223:31683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/kua.php"] [unique_id "al9PEoAs9lPxxVAErz0KiwAAAKs"]
[Tue Jul 21 07:50:58.645944 2026] [security2:error] [pid 302018:tid 302071] [remote 130.51.180.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp-login.php"] [unique_id "al9PEoAs9lPxxVAErz0KjgAA3TI"]
[Tue Jul 21 07:50:58.652694 2026] [security2:error] [pid 302018:tid 302270] [client 20.220.225.223:52179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9PEoAs9lPxxVAErz0KjwAAAP0"]
[Tue Jul 21 07:50:58.718283 2026] [security2:error] [pid 302018:tid 302170] [client 104.207.49.238:37437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9PEoAs9lPxxVAErz0KkAAAAJk"]
[Tue Jul 21 07:50:58.761054 2026] [security2:error] [pid 296703:tid 296946] [client 52.139.36.144:33042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/bless18.php"] [unique_id "al9PEin25uliftkV1n4toAAAAHE"]
[Tue Jul 21 07:50:58.806249 2026] [security2:error] [pid 302018:tid 302185] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/public/.env"] [unique_id "al9PEoAs9lPxxVAErz0KkQAAAKg"]
[Tue Jul 21 07:50:58.917673 2026] [security2:error] [pid 296703:tid 296853] [client 20.151.10.161:44013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/file48.php"] [unique_id "al9PEin25uliftkV1n4tpQAAABQ"]
[Tue Jul 21 07:50:58.932321 2026] [security2:error] [pid 296703:tid 296758] [remote 185.236.20.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9PEin25uliftkV1n4tpgAAdTY"], referer: http://hauptmann.com.br/wp-admin/admin-ajax.php
[Tue Jul 21 07:50:59.039836 2026] [security2:error] [pid 296703:tid 296944] [client 20.104.96.117:64379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/fnstall.php"] [unique_id "al9PEyn25uliftkV1n4tqQAAAG8"]
[Tue Jul 21 07:50:59.086382 2026] [security2:error] [pid 302018:tid 302202] [client 103.29.114.44:5284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PE4As9lPxxVAErz0KmQAAALk"]
[Tue Jul 21 07:50:59.086501 2026] [security2:error] [pid 302018:tid 302202] [client 103.29.114.44:5284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PE4As9lPxxVAErz0KmQAAALk"]
[Tue Jul 21 07:50:59.132217 2026] [security2:error] [pid 302018:tid 302171] [client 172.245.102.31:59845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PEoAs9lPxxVAErz0KmAAAAJo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:50:59.193919 2026] [security2:error] [pid 296703:tid 296868] [client 52.139.36.144:33094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/crgio.php"] [unique_id "al9PEyn25uliftkV1n4trAAAACM"]
[Tue Jul 21 07:50:59.453264 2026] [security2:error] [pid 302018:tid 302058] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PE4As9lPxxVAErz0KnQAAjiU"]
[Tue Jul 21 07:50:59.453399 2026] [security2:error] [pid 302018:tid 302159] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PE4As9lPxxVAErz0KnQAAjiU"]
[Tue Jul 21 07:50:59.488105 2026] [security2:error] [pid 302018:tid 302178] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/backend/.env"] [unique_id "al9PE4As9lPxxVAErz0KngAAAKE"]
[Tue Jul 21 07:50:59.493928 2026] [security2:error] [pid 302018:tid 302136] [remote 185.236.20.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.hauptmann.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9PE4As9lPxxVAErz0KoAAA7nM"]
[Tue Jul 21 07:50:59.571841 2026] [security2:error] [pid 296703:tid 296888] [client 52.139.36.144:33084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-act.php"] [unique_id "al9PEyn25uliftkV1n4ttAAAADc"]
[Tue Jul 21 07:50:59.576975 2026] [security2:error] [pid 296703:tid 296871] [client 74.249.245.134:8777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/adminfuns.php"] [unique_id "al9PEyn25uliftkV1n4ttQAAACY"]
[Tue Jul 21 07:50:59.615372 2026] [security2:error] [pid 296703:tid 296873] [client 104.207.49.238:38635] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "cezaretto.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PEyn25uliftkV1n4trgAAACg"]
[Tue Jul 21 07:50:59.640840 2026] [security2:error] [pid 296703:tid 296894] [client 20.220.225.223:32386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/dr.php"] [unique_id "al9PEyn25uliftkV1n4ttgAAAD0"]
[Tue Jul 21 07:50:59.754846 2026] [security2:error] [pid 296703:tid 296955] [client 117.217.38.194:57715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PEyn25uliftkV1n4tuAAAAHo"]
[Tue Jul 21 07:50:59.754983 2026] [security2:error] [pid 296703:tid 296955] [client 117.217.38.194:57715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PEyn25uliftkV1n4tuAAAAHo"]
[Tue Jul 21 07:50:59.756776 2026] [security2:error] [pid 302018:tid 302128] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PE4As9lPxxVAErz0KpAAAjGs"]
[Tue Jul 21 07:50:59.756950 2026] [security2:error] [pid 302018:tid 302157] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PE4As9lPxxVAErz0KpAAAjGs"]
[Tue Jul 21 07:50:59.828536 2026] [security2:error] [pid 302018:tid 302163] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/server/.env"] [unique_id "al9PE4As9lPxxVAErz0KpQAAAJI"]
[Tue Jul 21 07:50:59.882648 2026] [security2:error] [pid 302018:tid 302151] [client 20.197.192.193:27103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9PE4As9lPxxVAErz0KpwAAAIY"]
[Tue Jul 21 07:50:59.884493 2026] [security2:error] [pid 296703:tid 296907] [client 104.207.49.238:38635] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "cezaretto.com.br"] [uri "/"] [unique_id "al9PEyn25uliftkV1n4tuwAAAEo"]
[Tue Jul 21 07:51:00.010679 2026] [security2:error] [pid 302018:tid 302174] [client 52.139.36.144:1200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/new4.php"] [unique_id "al9PFIAs9lPxxVAErz0KrwAAAJ0"]
[Tue Jul 21 07:51:00.045140 2026] [security2:error] [pid 302018:tid 302248] [client 122.179.91.63:3541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PFIAs9lPxxVAErz0KsgAAAOc"]
[Tue Jul 21 07:51:00.045241 2026] [security2:error] [pid 302018:tid 302248] [client 122.179.91.63:3541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PFIAs9lPxxVAErz0KsgAAAOc"]
[Tue Jul 21 07:51:00.046948 2026] [security2:error] [pid 302018:tid 302256] [client 37.140.223.68:65281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PFIAs9lPxxVAErz0KsQAAAO8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:00.048590 2026] [security2:error] [pid 302018:tid 311327] [remote 185.236.20.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "hauptmann.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9PFIAs9lPxxVAErz0KswABBIE"]
[Tue Jul 21 07:51:00.153083 2026] [security2:error] [pid 296703:tid 296935] [client 104.207.49.238:38635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9PFCn25uliftkV1n4tvwAAAGY"]
[Tue Jul 21 07:51:00.168336 2026] [security2:error] [pid 302018:tid 302234] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/frontend/.env"] [unique_id "al9PFIAs9lPxxVAErz0KtAAAANk"]
[Tue Jul 21 07:51:00.180844 2026] [security2:error] [pid 302018:tid 302273] [client 20.151.10.161:43996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/file6.php"] [unique_id "al9PFIAs9lPxxVAErz0KtQAAAQA"]
[Tue Jul 21 07:51:00.312589 2026] [security2:error] [pid 296703:tid 296890] [client 20.220.225.223:6117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/2x.php"] [unique_id "al9PFCn25uliftkV1n4twgAAADk"]
[Tue Jul 21 07:51:00.413120 2026] [security2:error] [pid 302018:tid 302229] [client 20.220.225.223:19659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/zzz.php"] [unique_id "al9PFIAs9lPxxVAErz0KuQAAANQ"]
[Tue Jul 21 07:51:00.509042 2026] [security2:error] [pid 302018:tid 302233] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/src/.env"] [unique_id "al9PFIAs9lPxxVAErz0KvwAAANg"]
[Tue Jul 21 07:51:00.525661 2026] [security2:error] [pid 302018:tid 302241] [client 20.220.225.223:31222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-mt.php"] [unique_id "al9PFIAs9lPxxVAErz0KwAAAAOA"]
[Tue Jul 21 07:51:00.618934 2026] [security2:error] [pid 296703:tid 296867] [client 52.139.36.144:30588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-the.php"] [unique_id "al9PFCn25uliftkV1n4txgAAACI"]
[Tue Jul 21 07:51:00.706049 2026] [security2:error] [pid 302018:tid 302158] [client 104.207.49.238:17973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9PFIAs9lPxxVAErz0KxAAAAI0"]
[Tue Jul 21 07:51:00.723182 2026] [security2:error] [pid 302018:tid 302028] [remote 185.236.20.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "hauptmann.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9PFIAs9lPxxVAErz0KxQAA0Qc"], referer: http://hauptmann.com.br/wp-content/plugins/super-forms/readme.txt
[Tue Jul 21 07:51:00.839243 2026] [security2:error] [pid 302018:tid 302218] [client 20.104.96.117:59734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/acp.php"] [unique_id "al9PFIAs9lPxxVAErz0KyAAAAMk"]
[Tue Jul 21 07:51:00.849023 2026] [security2:error] [pid 302018:tid 302186] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/core/.env"] [unique_id "al9PFIAs9lPxxVAErz0KyQAAAKk"]
[Tue Jul 21 07:51:00.874190 2026] [security2:error] [pid 302018:tid 302048] [remote 51.89.129.6:38870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dsoler.com.br"] [uri "/robots.txt"] [unique_id "al9PFIAs9lPxxVAErz0KygAAyBs"]
[Tue Jul 21 07:51:00.874379 2026] [security2:error] [pid 302018:tid 302217] [client 51.89.129.6:38870] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dsoler.com.br"] [uri "/robots.txt"] [unique_id "al9PFIAs9lPxxVAErz0KygAAyBs"]
[Tue Jul 21 07:51:01.080781 2026] [security2:error] [pid 302018:tid 302175] [client 52.139.36.144:30570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/atkno.php"] [unique_id "al9PFYAs9lPxxVAErz0KzgAAAJ4"]
[Tue Jul 21 07:51:01.083738 2026] [security2:error] [pid 302018:tid 302142] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PFYAs9lPxxVAErz0KzwAAu3k"]
[Tue Jul 21 07:51:01.083884 2026] [security2:error] [pid 302018:tid 302204] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PFYAs9lPxxVAErz0KzwAAu3k"]
[Tue Jul 21 07:51:01.106977 2026] [security2:error] [pid 302018:tid 302179] [client 20.220.225.223:55498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/ez.php"] [unique_id "al9PFYAs9lPxxVAErz0K0AAAAKI"]
[Tue Jul 21 07:51:01.189175 2026] [security2:error] [pid 302018:tid 302263] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/core/app/.env"] [unique_id "al9PFYAs9lPxxVAErz0K0QAAAPY"]
[Tue Jul 21 07:51:01.247865 2026] [security2:error] [pid 302018:tid 302237] [client 104.207.49.238:19053] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9PFYAs9lPxxVAErz0K0gAAANw"]
[Tue Jul 21 07:51:01.267722 2026] [security2:error] [pid 296703:tid 296953] [client 20.197.192.193:8371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/fffm.php"] [unique_id "al9PFSn25uliftkV1n4t4AAAAHg"]
[Tue Jul 21 07:51:01.280653 2026] [security2:error] [pid 302018:tid 302050] [remote 185.236.20.134:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.hauptmann.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9PFYAs9lPxxVAErz0K0wAAix0"]
[Tue Jul 21 07:51:01.370308 2026] [security2:error] [pid 302018:tid 302046] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/.git/config"] [unique_id "al9PFYAs9lPxxVAErz0K2QABAxk"]
[Tue Jul 21 07:51:01.370308 2026] [security2:error] [pid 302018:tid 302114] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/.aws/config"] [unique_id "al9PFYAs9lPxxVAErz0K2wABA10"]
[Tue Jul 21 07:51:01.510297 2026] [security2:error] [pid 302018:tid 302195] [client 52.139.36.144:33074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/mass.php"] [unique_id "al9PFYAs9lPxxVAErz0K5AAAALI"]
[Tue Jul 21 07:51:01.530292 2026] [security2:error] [pid 302018:tid 302234] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/config/.env"] [unique_id "al9PFYAs9lPxxVAErz0K5QAAANk"]
[Tue Jul 21 07:51:01.688345 2026] [security2:error] [pid 296703:tid 296762] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PFSn25uliftkV1n4t8AAAZTo"]
[Tue Jul 21 07:51:01.688474 2026] [security2:error] [pid 296703:tid 296934] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PFSn25uliftkV1n4t8AAAZTo"]
[Tue Jul 21 07:51:01.810292 2026] [security2:error] [pid 302018:tid 302160] [client 104.207.49.238:19721] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9PFYAs9lPxxVAErz0K9AAAAI8"]
[Tue Jul 21 07:51:01.816840 2026] [security2:error] [pid 302018:tid 302080] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "portal.gradiente.com"] [uri "/graphql"] [unique_id "al9PFYAs9lPxxVAErz0K9QABAzs"]
[Tue Jul 21 07:51:01.870054 2026] [security2:error] [pid 302018:tid 302223] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/private/.env"] [unique_id "al9PFYAs9lPxxVAErz0K-gAAAM4"]
[Tue Jul 21 07:51:01.873674 2026] [security2:error] [pid 302018:tid 311329] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/.env"] [unique_id "al9PFYAs9lPxxVAErz0K-wABA4M"]
[Tue Jul 21 07:51:01.919216 2026] [security2:error] [pid 296703:tid 296945] [client 52.139.36.144:30535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wefile.php"] [unique_id "al9PFSn25uliftkV1n4t8wAAAHA"]
[Tue Jul 21 07:51:01.921488 2026] [security2:error] [pid 296703:tid 296909] [client 106.215.181.8:23877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PFSn25uliftkV1n4t8gAAAEw"]
[Tue Jul 21 07:51:01.921617 2026] [security2:error] [pid 296703:tid 296909] [client 106.215.181.8:23877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PFSn25uliftkV1n4t8gAAAEw"]
[Tue Jul 21 07:51:02.006832 2026] [security2:error] [pid 296703:tid 296929] [client 20.220.225.223:31181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/ww.php"] [unique_id "al9PFin25uliftkV1n4t9AAAAGA"]
[Tue Jul 21 07:51:02.157346 2026] [security2:error] [pid 302018:tid 302090] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "portal.gradiente.com"] [uri "/api/graphql"] [unique_id "al9PFoAs9lPxxVAErz0LBAABA0U"]
[Tue Jul 21 07:51:02.160609 2026] [security2:error] [pid 302018:tid 302065] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/.env.backup"] [unique_id "al9PFoAs9lPxxVAErz0LBQABAyw"]
[Tue Jul 21 07:51:02.161519 2026] [security2:error] [pid 302018:tid 302134] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "portal.gradiente.com"] [uri "/.env.local"] [unique_id "al9PFoAs9lPxxVAErz0LBgABA3E"]
[Tue Jul 21 07:51:02.163930 2026] [security2:error] [pid 302018:tid 302029] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/.env.bak"] [unique_id "al9PFoAs9lPxxVAErz0LBwABAwg"]
[Tue Jul 21 07:51:02.210065 2026] [security2:error] [pid 302018:tid 302171] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/application/.env"] [unique_id "al9PFoAs9lPxxVAErz0LDQAAAJo"]
[Tue Jul 21 07:51:02.257248 2026] [security2:error] [pid 302018:tid 302042] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/.env.old"] [unique_id "al9PFoAs9lPxxVAErz0LDgABAxU"]
[Tue Jul 21 07:51:02.322415 2026] [security2:error] [pid 302018:tid 302107] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/api/.env"] [unique_id "al9PFoAs9lPxxVAErz0LDwABA1Y"]
[Tue Jul 21 07:51:02.326358 2026] [security2:error] [pid 302018:tid 302124] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/backend/.env"] [unique_id "al9PFoAs9lPxxVAErz0LEAABA2c"]
[Tue Jul 21 07:51:02.329047 2026] [security2:error] [pid 302018:tid 302198] [client 52.139.36.144:30586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/min.php"] [unique_id "al9PFoAs9lPxxVAErz0LEgAAALU"]
[Tue Jul 21 07:51:02.360215 2026] [security2:error] [pid 296703:tid 296917] [client 20.104.96.117:59720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/mosty.php"] [unique_id "al9PFin25uliftkV1n4t-wAAAFQ"]
[Tue Jul 21 07:51:02.371851 2026] [security2:error] [pid 302018:tid 302203] [client 104.207.49.238:64551] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9PFoAs9lPxxVAErz0LFQAAALo"]
[Tue Jul 21 07:51:02.388402 2026] [security2:error] [pid 302018:tid 302127] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "portal.gradiente.com"] [uri "/v1/graphql"] [unique_id "al9PFoAs9lPxxVAErz0LFgABA2o"]
[Tue Jul 21 07:51:02.433179 2026] [security2:error] [pid 302018:tid 302088] [remote 54.39.203.231:36806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dsoler.com.br"] [uri "/"] [unique_id "al9PFoAs9lPxxVAErz0LFwAAl0M"]
[Tue Jul 21 07:51:02.433359 2026] [security2:error] [pid 302018:tid 302168] [client 54.39.203.231:36806] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dsoler.com.br"] [uri "/"] [unique_id "al9PFoAs9lPxxVAErz0LFwAAl0M"]
[Tue Jul 21 07:51:02.451577 2026] [security2:error] [pid 302018:tid 302102] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/config/.env"] [unique_id "al9PFoAs9lPxxVAErz0LGAABA1E"]
[Tue Jul 21 07:51:02.550881 2026] [security2:error] [pid 302018:tid 302217] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/bootstrap/.env"] [unique_id "al9PFoAs9lPxxVAErz0LIAAAAMg"]
[Tue Jul 21 07:51:02.625183 2026] [security2:error] [pid 296703:tid 296857] [client 193.36.225.152:32955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PFin25uliftkV1n4t_AAAABg"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:51:02.644944 2026] [security2:error] [pid 296703:tid 296956] [client 74.249.245.134:64118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/php8.php"] [unique_id "al9PFin25uliftkV1n4uAQAAAHs"]
[Tue Jul 21 07:51:02.665797 2026] [security2:error] [pid 302018:tid 302173] [client 20.220.225.223:6120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/kq1.php"] [unique_id "al9PFoAs9lPxxVAErz0LKQAAAJw"]
[Tue Jul 21 07:51:02.728621 2026] [security2:error] [pid 302018:tid 302176] [client 52.139.36.144:33106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/sid3.php"] [unique_id "al9PFoAs9lPxxVAErz0LLQAAAJ8"]
[Tue Jul 21 07:51:02.820611 2026] [security2:error] [pid 302018:tid 302235] [client 202.143.127.214:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PFoAs9lPxxVAErz0LMwAAANo"]
[Tue Jul 21 07:51:02.821391 2026] [security2:error] [pid 302018:tid 302235] [client 202.143.127.214:55188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PFoAs9lPxxVAErz0LMwAAANo"]
[Tue Jul 21 07:51:02.883966 2026] [security2:error] [pid 302018:tid 302156] [client 20.220.225.223:38665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/cron.php"] [unique_id "al9PFoAs9lPxxVAErz0LOAAAAIs"]
[Tue Jul 21 07:51:02.885367 2026] [security2:error] [pid 302018:tid 302138] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "portal.gradiente.com"] [uri "/.npmrc"] [unique_id "al9PFoAs9lPxxVAErz0LNgAAknU"]
[Tue Jul 21 07:51:02.890930 2026] [security2:error] [pid 302018:tid 302249] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/database/.env"] [unique_id "al9PFoAs9lPxxVAErz0LOQAAAOg"]
[Tue Jul 21 07:51:02.924171 2026] [security2:error] [pid 302018:tid 302144] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/.svn/entries"] [unique_id "al9PFoAs9lPxxVAErz0LOgAA0ns"]
[Tue Jul 21 07:51:02.927346 2026] [authz_core:error] [pid 302018:tid 302100] [remote 34.17.160.209:55390] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Tue Jul 21 07:51:02.935509 2026] [security2:error] [pid 302018:tid 302214] [client 104.207.49.238:49077] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9PFoAs9lPxxVAErz0LPAAAAMU"]
[Tue Jul 21 07:51:02.984801 2026] [security2:error] [pid 302018:tid 302158] [client 122.164.127.47:50328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PFoAs9lPxxVAErz0LPQAAAI0"]
[Tue Jul 21 07:51:02.984958 2026] [security2:error] [pid 302018:tid 302158] [client 122.164.127.47:50328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PFoAs9lPxxVAErz0LPQAAAI0"]
[Tue Jul 21 07:51:02.987582 2026] [security2:error] [pid 302018:tid 302174] [client 20.151.10.161:43806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/a2.php"] [unique_id "al9PFoAs9lPxxVAErz0LPgAAAJ0"]
[Tue Jul 21 07:51:03.060297 2026] [security2:error] [pid 302018:tid 311326] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/.ssh/id_rsa"] [unique_id "al9PF4As9lPxxVAErz0LRAAAy4A"]
[Tue Jul 21 07:51:03.100188 2026] [security2:error] [pid 296703:tid 296905] [client 20.197.192.193:27190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/dp.php"] [unique_id "al9PFyn25uliftkV1n4uBwAAAEg"]
[Tue Jul 21 07:51:03.154799 2026] [security2:error] [pid 302018:tid 302238] [client 52.139.36.144:33037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/fileas.php"] [unique_id "al9PF4As9lPxxVAErz0LSwAAAN0"]
[Tue Jul 21 07:51:03.167445 2026] [security2:error] [pid 302018:tid 302126] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "portal.gradiente.com"] [uri "/.ssh/authorized_keys"] [unique_id "al9PF4As9lPxxVAErz0LTAAAmWk"]
[Tue Jul 21 07:51:03.190153 2026] [security2:error] [pid 302018:tid 311333] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/.ssh/id_dsa"] [unique_id "al9PF4As9lPxxVAErz0LTQAA6Yc"]
[Tue Jul 21 07:51:03.230920 2026] [security2:error] [pid 302018:tid 302210] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/storage/.env"] [unique_id "al9PF4As9lPxxVAErz0LTwAAAME"]
[Tue Jul 21 07:51:03.231904 2026] [security2:error] [pid 302018:tid 302067] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/.ssh/config"] [unique_id "al9PF4As9lPxxVAErz0LUAAA-y4"]
[Tue Jul 21 07:51:03.232028 2026] [security2:error] [pid 302018:tid 302268] [client 34.17.160.209:55390] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "portal.gradiente.com"] [uri "/.ssh/config"] [unique_id "al9PF4As9lPxxVAErz0LUAAA-y4"]
[Tue Jul 21 07:51:03.315879 2026] [security2:error] [pid 302018:tid 302096] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/id_rsa"] [unique_id "al9PF4As9lPxxVAErz0LWAAAmks"]
[Tue Jul 21 07:51:03.361233 2026] [security2:error] [pid 302018:tid 302133] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/id_dsa"] [unique_id "al9PF4As9lPxxVAErz0LWwAA0XA"]
[Tue Jul 21 07:51:03.371739 2026] [security2:error] [pid 302018:tid 302198] [client 20.220.225.223:23471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/zzz.php"] [unique_id "al9PF4As9lPxxVAErz0LXAAAALU"]
[Tue Jul 21 07:51:03.436897 2026] [security2:error] [pid 302018:tid 302192] [client 41.68.90.219:63275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PF4As9lPxxVAErz0LXQAAAK8"]
[Tue Jul 21 07:51:03.437039 2026] [security2:error] [pid 302018:tid 302192] [client 41.68.90.219:63275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PF4As9lPxxVAErz0LXQAAAK8"]
[Tue Jul 21 07:51:03.473331 2026] [security2:error] [pid 302018:tid 302276] [client 104.207.49.238:41295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9PF4As9lPxxVAErz0LYAAAAQM"]
[Tue Jul 21 07:51:03.491316 2026] [security2:error] [pid 302018:tid 302128] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/privatekey.key"] [unique_id "al9PF4As9lPxxVAErz0LYgAAvms"]
[Tue Jul 21 07:51:03.491525 2026] [security2:error] [pid 302018:tid 302086] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/key.pem"] [unique_id "al9PF4As9lPxxVAErz0LYQAAvkE"]
[Tue Jul 21 07:51:03.571020 2026] [security2:error] [pid 302018:tid 302228] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/var/www/.env"] [unique_id "al9PF4As9lPxxVAErz0LZwAAANM"]
[Tue Jul 21 07:51:03.612800 2026] [security2:error] [pid 302018:tid 302064] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PF4As9lPxxVAErz0LagAAlis"]
[Tue Jul 21 07:51:03.612959 2026] [security2:error] [pid 302018:tid 302167] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PF4As9lPxxVAErz0LagAAlis"]
[Tue Jul 21 07:51:03.613052 2026] [security2:error] [pid 302018:tid 302047] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/ssl/server.key"] [unique_id "al9PF4As9lPxxVAErz0LawAAkxo"]
[Tue Jul 21 07:51:03.692457 2026] [security2:error] [pid 302018:tid 302213] [client 74.249.245.134:64387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/info.php"] [unique_id "al9PF4As9lPxxVAErz0LcAAAAMQ"]
[Tue Jul 21 07:51:03.794727 2026] [security2:error] [pid 296703:tid 296884] [client 122.162.144.145:6861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PFyn25uliftkV1n4uEQAAADM"]
[Tue Jul 21 07:51:03.794852 2026] [security2:error] [pid 296703:tid 296884] [client 122.162.144.145:6861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PFyn25uliftkV1n4uEQAAADM"]
[Tue Jul 21 07:51:03.797973 2026] [security2:error] [pid 302018:tid 302142] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9PF4As9lPxxVAErz0LdwABAXk"]
[Tue Jul 21 07:51:03.814680 2026] [security2:error] [pid 302018:tid 302156] [client 20.220.225.223:31173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xxx.php"] [unique_id "al9PF4As9lPxxVAErz0LegAAAIs"]
[Tue Jul 21 07:51:03.910727 2026] [security2:error] [pid 302018:tid 302214] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/var/www/html/.env"] [unique_id "al9PF4As9lPxxVAErz0LgQAAAMU"]
[Tue Jul 21 07:51:03.962942 2026] [security2:error] [pid 302018:tid 302049] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/.hermes/.env"] [unique_id "al9PF4As9lPxxVAErz0LhwAA7xw"]
[Tue Jul 21 07:51:03.979423 2026] [security2:error] [pid 302018:tid 302272] [client 52.139.36.144:1168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/bless24.php"] [unique_id "al9PF4As9lPxxVAErz0LiQAAAP8"]
[Tue Jul 21 07:51:04.022352 2026] [security2:error] [pid 302018:tid 302161] [client 104.207.49.238:64353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9PGIAs9lPxxVAErz0LkAAAAJA"]
[Tue Jul 21 07:51:04.102308 2026] [security2:error] [pid 302018:tid 302108] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "portal.gradiente.com"] [uri "/.bashrc"] [unique_id "al9PGIAs9lPxxVAErz0LlgAA_Vc"]
[Tue Jul 21 07:51:04.250938 2026] [security2:error] [pid 302018:tid 302210] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/current/.env"] [unique_id "al9PGIAs9lPxxVAErz0LngAAAME"]
[Tue Jul 21 07:51:04.255806 2026] [security2:error] [pid 302018:tid 302135] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PGIAs9lPxxVAErz0LnwAAknI"]
[Tue Jul 21 07:51:04.255982 2026] [security2:error] [pid 302018:tid 302163] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PGIAs9lPxxVAErz0LnwAAknI"]
[Tue Jul 21 07:51:04.316235 2026] [security2:error] [pid 302018:tid 302143] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "portal.gradiente.com"] [uri "/wp-config.php.old"] [unique_id "al9PGIAs9lPxxVAErz0LowAAqHo"]
[Tue Jul 21 07:51:04.332861 2026] [security2:error] [pid 302018:tid 302090] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "portal.gradiente.com"] [uri "/wp-config.php.bak"] [unique_id "al9PGIAs9lPxxVAErz0LpQAAtkU"]
[Tue Jul 21 07:51:04.426446 2026] [security2:error] [pid 302018:tid 302241] [client 52.139.36.144:1215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/fun.php"] [unique_id "al9PGIAs9lPxxVAErz0LqAAAAOA"]
[Tue Jul 21 07:51:04.440802 2026] [security2:error] [pid 302018:tid 302034] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "portal.gradiente.com"] [uri "/config/.env.php"] [unique_id "al9PGIAs9lPxxVAErz0LqgAApQ0"]
[Tue Jul 21 07:51:04.442028 2026] [security2:error] [pid 302018:tid 302029] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/laravel/.env"] [unique_id "al9PGIAs9lPxxVAErz0LqQAApQg"]
[Tue Jul 21 07:51:04.491572 2026] [security2:error] [pid 302018:tid 302119] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portal.gradiente.com"] [uri "/.env.php.bak"] [unique_id "al9PGIAs9lPxxVAErz0LrAAA_GI"]
[Tue Jul 21 07:51:04.536465 2026] [security2:error] [pid 302018:tid 302099] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/core/.env"] [unique_id "al9PGIAs9lPxxVAErz0LrgAAr04"]
[Tue Jul 21 07:51:04.548928 2026] [security2:error] [pid 302018:tid 302042] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "portal.gradiente.com"] [uri "/configuration.php.bak"] [unique_id "al9PGIAs9lPxxVAErz0LrwAAuhU"]
[Tue Jul 21 07:51:04.563635 2026] [security2:error] [pid 302018:tid 302260] [client 20.220.225.223:31172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/hunter.php"] [unique_id "al9PGIAs9lPxxVAErz0LsQAAAPM"]
[Tue Jul 21 07:51:04.567949 2026] [security2:error] [pid 302018:tid 302124] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/.env.dev"] [unique_id "al9PGIAs9lPxxVAErz0LsgABA2c"]
[Tue Jul 21 07:51:04.578130 2026] [security2:error] [pid 302018:tid 302221] [client 104.207.49.238:61543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9PGIAs9lPxxVAErz0LswAAAMw"]
[Tue Jul 21 07:51:04.590696 2026] [security2:error] [pid 302018:tid 302267] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/release/.env"] [unique_id "al9PGIAs9lPxxVAErz0LtQAAAPo"]
[Tue Jul 21 07:51:04.636336 2026] [security2:error] [pid 302018:tid 302078] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portal.gradiente.com"] [uri "/config.php.bak"] [unique_id "al9PGIAs9lPxxVAErz0LtgAA6jk"]
[Tue Jul 21 07:51:04.722206 2026] [security2:error] [pid 302018:tid 302091] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/.env.swp"] [unique_id "al9PGIAs9lPxxVAErz0LuwAAyEY"]
[Tue Jul 21 07:51:04.725603 2026] [security2:error] [pid 302018:tid 302127] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/web/.env"] [unique_id "al9PGIAs9lPxxVAErz0LvAAAyGo"]
[Tue Jul 21 07:51:04.726274 2026] [security2:error] [pid 302018:tid 302088] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/public/.env"] [unique_id "al9PGIAs9lPxxVAErz0LvQAAyEM"]
[Tue Jul 21 07:51:04.737398 2026] [security2:error] [pid 296703:tid 296837] [client 52.139.36.144:1249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/drykl.php"] [unique_id "al9PGCn25uliftkV1n4uIQAAAAQ"]
[Tue Jul 21 07:51:04.760164 2026] [security2:error] [pid 302018:tid 302040] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/config/application.properties"] [unique_id "al9PGIAs9lPxxVAErz0LvwAAxBM"]
[Tue Jul 21 07:51:04.777498 2026] [security2:error] [pid 296703:tid 296892] [client 20.197.192.193:8362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/ftde.php"] [unique_id "al9PGCn25uliftkV1n4uIwAAADs"]
[Tue Jul 21 07:51:04.797934 2026] [security2:error] [pid 302018:tid 302022] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/bootstrap.properties"] [unique_id "al9PGIAs9lPxxVAErz0LwgAA2wE"]
[Tue Jul 21 07:51:04.857559 2026] [security2:error] [pid 302018:tid 302041] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "portal.gradiente.com"] [uri "/actuator/env"] [unique_id "al9PGIAs9lPxxVAErz0LxwAA9hQ"]
[Tue Jul 21 07:51:04.888134 2026] [security2:error] [pid 296703:tid 296833] [client 194.99.104.35:55798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PGCn25uliftkV1n4uJQAAAAA"]
[Tue Jul 21 07:51:04.888232 2026] [security2:error] [pid 296703:tid 296833] [client 194.99.104.35:55798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PGCn25uliftkV1n4uJQAAAAA"]
[Tue Jul 21 07:51:04.905077 2026] [security2:error] [pid 302018:tid 302072] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "portal.gradiente.com"] [uri "/gradle.properties"] [unique_id "al9PGIAs9lPxxVAErz0LyAABATM"]
[Tue Jul 21 07:51:04.930661 2026] [security2:error] [pid 302018:tid 302156] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/releases/.env"] [unique_id "al9PGIAs9lPxxVAErz0LyQAAAIs"]
[Tue Jul 21 07:51:04.969103 2026] [security2:error] [pid 302018:tid 302123] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "portal.gradiente.com"] [uri "/.gradle/gradle.properties"] [unique_id "al9PGIAs9lPxxVAErz0L0AAAtGY"]
[Tue Jul 21 07:51:05.009399 2026] [security2:error] [pid 302018:tid 302195] [client 193.36.225.69:21219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PGIAs9lPxxVAErz0LxgAAALI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:05.025359 2026] [security2:error] [pid 302018:tid 302175] [client 20.220.225.223:32289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/fz.php"] [unique_id "al9PGYAs9lPxxVAErz0L1AAAAJ4"]
[Tue Jul 21 07:51:05.029121 2026] [security2:error] [pid 302018:tid 302151] [client 103.166.103.129:34126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PGYAs9lPxxVAErz0L1gAAAIY"]
[Tue Jul 21 07:51:05.029270 2026] [security2:error] [pid 302018:tid 302151] [client 103.166.103.129:34126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PGYAs9lPxxVAErz0L1gAAAIY"]
[Tue Jul 21 07:51:05.080595 2026] [security2:error] [pid 302018:tid 302052] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/web.config"] [unique_id "al9PGYAs9lPxxVAErz0L2gAA5h8"]
[Tue Jul 21 07:51:05.085469 2026] [security2:error] [pid 302018:tid 302204] [client 193.36.225.121:31855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PGYAs9lPxxVAErz0L2AAAALs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:51:05.149819 2026] [security2:error] [pid 302018:tid 302272] [client 104.207.49.238:15151] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9PGYAs9lPxxVAErz0L3AAAAP8"]
[Tue Jul 21 07:51:05.156312 2026] [security2:error] [pid 302018:tid 302150] [client 52.139.36.144:1156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al9PGYAs9lPxxVAErz0L3QAAAIU"]
[Tue Jul 21 07:51:05.270268 2026] [security2:error] [pid 302018:tid 302240] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/shared/.env"] [unique_id "al9PGYAs9lPxxVAErz0L5wAAAN8"]
[Tue Jul 21 07:51:05.405310 2026] [security2:error] [pid 302018:tid 302056] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "portal.gradiente.com"] [uri "/.env.staging"] [unique_id "al9PGYAs9lPxxVAErz0L7gAA4iM"]
[Tue Jul 21 07:51:05.533722 2026] [security2:error] [pid 302018:tid 302168] [client 52.139.36.144:24306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/mifta.php"] [unique_id "al9PGYAs9lPxxVAErz0L-AAAAJc"]
[Tue Jul 21 07:51:05.574641 2026] [security2:error] [pid 302018:tid 302207] [client 20.226.60.151:53890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/iywwi.php"] [unique_id "al9PGYAs9lPxxVAErz0L-wAAAL4"]
[Tue Jul 21 07:51:05.595026 2026] [security2:error] [pid 302018:tid 302133] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/app/.env"] [unique_id "al9PGYAs9lPxxVAErz0L_AAA-nA"]
[Tue Jul 21 07:51:05.609217 2026] [security2:error] [pid 302018:tid 302251] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/deploy/.env"] [unique_id "al9PGYAs9lPxxVAErz0L_gAAAOo"]
[Tue Jul 21 07:51:05.653267 2026] [security2:error] [pid 296703:tid 296936] [client 20.197.192.193:27141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/old.php"] [unique_id "al9PGSn25uliftkV1n4uLQAAAGc"]
[Tue Jul 21 07:51:05.655538 2026] [security2:error] [pid 302018:tid 302058] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "portal.gradiente.com"] [uri "/frontend/.env"] [unique_id "al9PGYAs9lPxxVAErz0L_wAAliU"]
[Tue Jul 21 07:51:05.657729 2026] [security2:error] [pid 302018:tid 302071] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/src/.env"] [unique_id "al9PGYAs9lPxxVAErz0MAAAAljI"]
[Tue Jul 21 07:51:05.671572 2026] [security2:error] [pid 302018:tid 302235] [client 223.236.153.128:5509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PGYAs9lPxxVAErz0MAgAAANo"]
[Tue Jul 21 07:51:05.672037 2026] [security2:error] [pid 302018:tid 302136] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/server/.env"] [unique_id "al9PGYAs9lPxxVAErz0MAQAAwHM"]
[Tue Jul 21 07:51:05.672490 2026] [security2:error] [pid 302018:tid 302128] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/production/.env"] [unique_id "al9PGYAs9lPxxVAErz0MAwAAwGs"]
[Tue Jul 21 07:51:05.674401 2026] [security2:error] [pid 302018:tid 302235] [client 223.236.153.128:5509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PGYAs9lPxxVAErz0MAgAAANo"]
[Tue Jul 21 07:51:05.688717 2026] [security2:error] [pid 302018:tid 302205] [client 104.207.49.238:13421] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9PGYAs9lPxxVAErz0MBAAAALw"]
[Tue Jul 21 07:51:05.698811 2026] [security2:error] [pid 302018:tid 302237] [client 182.8.255.181:17695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PGYAs9lPxxVAErz0MBwAAANw"]
[Tue Jul 21 07:51:05.698979 2026] [security2:error] [pid 302018:tid 302237] [client 182.8.255.181:17695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PGYAs9lPxxVAErz0MBwAAANw"]
[Tue Jul 21 07:51:05.703145 2026] [security2:error] [pid 302018:tid 302079] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/dev/.env"] [unique_id "al9PGYAs9lPxxVAErz0MCAAA7jo"]
[Tue Jul 21 07:51:05.790284 2026] [security2:error] [pid 302018:tid 302093] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/staging/.env"] [unique_id "al9PGYAs9lPxxVAErz0MDgAAi0g"]
[Tue Jul 21 07:51:05.915315 2026] [security2:error] [pid 302018:tid 302158] [client 20.104.96.117:64277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/6.php"] [unique_id "al9PGYAs9lPxxVAErz0MEAAAAI0"]
[Tue Jul 21 07:51:05.948687 2026] [security2:error] [pid 302018:tid 302157] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/build/.env"] [unique_id "al9PGYAs9lPxxVAErz0MEgAAAIw"]
[Tue Jul 21 07:51:05.968940 2026] [security2:error] [pid 302018:tid 302027] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "portal.gradiente.com"] [uri "/sa.json"] [unique_id "al9PGYAs9lPxxVAErz0MEwAAhgY"]
[Tue Jul 21 07:51:05.980153 2026] [security2:error] [pid 302018:tid 311327] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/docker/.env"] [unique_id "al9PGYAs9lPxxVAErz0MFQAAnYE"]
[Tue Jul 21 07:51:05.980630 2026] [security2:error] [pid 302018:tid 302064] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/.env.production.bak"] [unique_id "al9PGYAs9lPxxVAErz0MFAAAnSs"]
[Tue Jul 21 07:51:05.986181 2026] [security2:error] [pid 302018:tid 302047] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/google-credentials.json"] [unique_id "al9PGYAs9lPxxVAErz0MFgAAoho"]
[Tue Jul 21 07:51:05.986292 2026] [security2:error] [pid 302018:tid 302179] [client 34.17.160.209:55390] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "portal.gradiente.com"] [uri "/google-credentials.json"] [unique_id "al9PGYAs9lPxxVAErz0MFgAAoho"]
[Tue Jul 21 07:51:05.990548 2026] [security2:error] [pid 302018:tid 302028] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/.env.prod.bak"] [unique_id "al9PGYAs9lPxxVAErz0MGAAAogc"]
[Tue Jul 21 07:51:05.995501 2026] [security2:error] [pid 302018:tid 311332] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/@fs/root/.env"] [unique_id "al9PGYAs9lPxxVAErz0MGQAAooY"]
[Tue Jul 21 07:51:05.997224 2026] [security2:error] [pid 302018:tid 302048] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "portal.gradiente.com"] [uri "/@fs/.env"] [unique_id "al9PGYAs9lPxxVAErz0MGgAAyhs"]
[Tue Jul 21 07:51:05.997592 2026] [security2:error] [pid 302018:tid 302085] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/gcp-credentials.json"] [unique_id "al9PGYAs9lPxxVAErz0MGwAAykA"]
[Tue Jul 21 07:51:05.997708 2026] [security2:error] [pid 302018:tid 302219] [client 34.17.160.209:55390] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "portal.gradiente.com"] [uri "/gcp-credentials.json"] [unique_id "al9PGYAs9lPxxVAErz0MGwAAykA"]
[Tue Jul 21 07:51:06.007959 2026] [security2:error] [pid 302018:tid 302045] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/@fs/proc/self/environ"] [unique_id "al9PGoAs9lPxxVAErz0MHAAAuxg"]
[Tue Jul 21 07:51:06.015064 2026] [security2:error] [pid 302018:tid 302273] [client 52.139.36.144:1163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/class-t.api.php"] [unique_id "al9PGoAs9lPxxVAErz0MHQAAAQA"]
[Tue Jul 21 07:51:06.139273 2026] [security2:error] [pid 302018:tid 302161] [client 20.220.225.223:32280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/la.php"] [unique_id "al9PGoAs9lPxxVAErz0MIAAAAJA"]
[Tue Jul 21 07:51:06.147280 2026] [security2:error] [pid 302018:tid 302188] [client 20.220.225.223:31186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/we.php"] [unique_id "al9PGoAs9lPxxVAErz0MIQAAAKs"]
[Tue Jul 21 07:51:06.202716 2026] [security2:error] [pid 302018:tid 302050] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PGoAs9lPxxVAErz0MIgAA5h0"]
[Tue Jul 21 07:51:06.202863 2026] [security2:error] [pid 302018:tid 302247] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PGoAs9lPxxVAErz0MIgAA5h0"]
[Tue Jul 21 07:51:06.215779 2026] [security2:error] [pid 302018:tid 302095] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "portal.gradiente.com"] [uri "/config/gcp-credentials.json"] [unique_id "al9PGoAs9lPxxVAErz0MJgAA9Eo"]
[Tue Jul 21 07:51:06.223947 2026] [security2:error] [pid 302018:tid 302208] [client 104.207.49.238:60833] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9PGoAs9lPxxVAErz0MJwAAAL8"]
[Tue Jul 21 07:51:06.288312 2026] [security2:error] [pid 302018:tid 302238] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/dist/.env"] [unique_id "al9PGoAs9lPxxVAErz0MMgAAAN0"]
[Tue Jul 21 07:51:06.397105 2026] [security2:error] [pid 302018:tid 302055] [remote 97.74.93.24:38326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moneyclass.com.br"] [uri "/wp-login.php"] [unique_id "al9PGoAs9lPxxVAErz0MNgAA8CI"]
[Tue Jul 21 07:51:06.403360 2026] [security2:error] [pid 302018:tid 302233] [client 52.139.36.144:1262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/vgtyu.php"] [unique_id "al9PGoAs9lPxxVAErz0MNwAAANg"]
[Tue Jul 21 07:51:06.500489 2026] [security2:error] [pid 302018:tid 302193] [client 74.249.245.134:64252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/edit.php"] [unique_id "al9PGoAs9lPxxVAErz0MPgAAALA"]
[Tue Jul 21 07:51:06.628338 2026] [security2:error] [pid 302018:tid 302221] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/public_html/.env"] [unique_id "al9PGoAs9lPxxVAErz0MRQAAAMw"]
[Tue Jul 21 07:51:06.675419 2026] [security2:error] [pid 302018:tid 302267] [client 74.249.245.134:65104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/666.php"] [unique_id "al9PGoAs9lPxxVAErz0MSAAAAPo"]
[Tue Jul 21 07:51:06.683455 2026] [security2:error] [pid 302018:tid 302143] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/api/v2/config"] [unique_id "al9PGoAs9lPxxVAErz0MSgAA03o"]
[Tue Jul 21 07:51:06.748163 2026] [security2:error] [pid 302018:tid 302034] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "portal.gradiente.com"] [uri "/api/v2/settings"] [unique_id "al9PGoAs9lPxxVAErz0MUAAAwA0"]
[Tue Jul 21 07:51:06.786598 2026] [security2:error] [pid 302018:tid 302205] [client 104.207.49.238:46513] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9PGoAs9lPxxVAErz0MUwAAALw"]
[Tue Jul 21 07:51:06.816862 2026] [security2:error] [pid 302018:tid 302236] [client 52.139.36.144:30558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/atomlib.php"] [unique_id "al9PGoAs9lPxxVAErz0MVgAAANs"]
[Tue Jul 21 07:51:06.968110 2026] [security2:error] [pid 302018:tid 302262] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/htdocs/.env"] [unique_id "al9PGoAs9lPxxVAErz0MVwAAAPU"]
[Tue Jul 21 07:51:07.183180 2026] [security2:error] [pid 302018:tid 302163] [client 59.96.220.140:50000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9PG4As9lPxxVAErz0MZQAAAJI"]
[Tue Jul 21 07:51:07.183997 2026] [security2:error] [pid 302018:tid 302163] [client 59.96.220.140:50000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9PG4As9lPxxVAErz0MZQAAAJI"]
[Tue Jul 21 07:51:07.257641 2026] [security2:error] [pid 302018:tid 302260] [client 103.86.117.203:64232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PG4As9lPxxVAErz0MZgAAAPM"]
[Tue Jul 21 07:51:07.257808 2026] [security2:error] [pid 302018:tid 302260] [client 103.86.117.203:64232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PG4As9lPxxVAErz0MZgAAAPM"]
[Tue Jul 21 07:51:07.270284 2026] [security2:error] [pid 302018:tid 302145] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PG4As9lPxxVAErz0MbgAAn3w"]
[Tue Jul 21 07:51:07.270456 2026] [security2:error] [pid 302018:tid 302176] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PG4As9lPxxVAErz0MbgAAn3w"]
[Tue Jul 21 07:51:07.284954 2026] [security2:error] [pid 302018:tid 302204] [client 20.220.225.223:22526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9PG4As9lPxxVAErz0MdAAAALs"]
[Tue Jul 21 07:51:07.307710 2026] [security2:error] [pid 302018:tid 302248] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/www/.env"] [unique_id "al9PG4As9lPxxVAErz0MdQAAAOc"]
[Tue Jul 21 07:51:07.340753 2026] [security2:error] [pid 296703:tid 296908] [client 52.139.36.144:30552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-access.php"] [unique_id "al9PGyn25uliftkV1n4uRgAAAEs"]
[Tue Jul 21 07:51:07.479506 2026] [security2:error] [pid 296703:tid 296853] [client 20.151.10.161:43880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/file15.php"] [unique_id "al9PGyn25uliftkV1n4uSAAAABQ"]
[Tue Jul 21 07:51:07.497189 2026] [security2:error] [pid 302018:tid 302023] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/api/graphql"] [unique_id "al9PG4As9lPxxVAErz0MfAAAvwI"]
[Tue Jul 21 07:51:07.497340 2026] [security2:error] [pid 302018:tid 302208] [client 34.17.160.209:55390] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "portal.gradiente.com"] [uri "/api/graphql"] [unique_id "al9PG4As9lPxxVAErz0MfAAAvwI"]
[Tue Jul 21 07:51:07.506398 2026] [security2:error] [pid 296703:tid 296946] [client 109.60.28.94:27551] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PGyn25uliftkV1n4uSQAAAHE"]
[Tue Jul 21 07:51:07.506539 2026] [security2:error] [pid 296703:tid 296946] [client 109.60.28.94:27551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PGyn25uliftkV1n4uSQAAAHE"]
[Tue Jul 21 07:51:07.523046 2026] [security2:error] [pid 302018:tid 302100] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/actuator"] [unique_id "al9PG4As9lPxxVAErz0MgwAA-E8"]
[Tue Jul 21 07:51:07.523232 2026] [security2:error] [pid 302018:tid 302265] [client 34.17.160.209:55390] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "portal.gradiente.com"] [uri "/actuator"] [unique_id "al9PG4As9lPxxVAErz0MgwAA-E8"]
[Tue Jul 21 07:51:07.554657 2026] [security2:error] [pid 302018:tid 302063] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "portal.gradiente.com"] [uri "/actuator/mappings"] [unique_id "al9PG4As9lPxxVAErz0MhAAA1Co"]
[Tue Jul 21 07:51:07.648220 2026] [security2:error] [pid 302018:tid 302238] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/html/.env"] [unique_id "al9PG4As9lPxxVAErz0MhgAAAN0"]
[Tue Jul 21 07:51:07.712493 2026] [security2:error] [pid 296703:tid 296848] [client 52.139.36.144:33026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-update.php"] [unique_id "al9PGyn25uliftkV1n4uSwAAAA8"]
[Tue Jul 21 07:51:07.722472 2026] [security2:error] [pid 302018:tid 302038] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portal.gradiente.com"] [uri "/phpinfo.php"] [unique_id "al9PG4As9lPxxVAErz0MiAAA0hE"]
[Tue Jul 21 07:51:07.732736 2026] [security2:error] [pid 302018:tid 311326] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portal.gradiente.com"] [uri "/info.php"] [unique_id "al9PG4As9lPxxVAErz0MiwAArYA"]
[Tue Jul 21 07:51:07.752062 2026] [security2:error] [pid 302018:tid 302056] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portal.gradiente.com"] [uri "/i.php"] [unique_id "al9PG4As9lPxxVAErz0MjgAA8CM"]
[Tue Jul 21 07:51:07.752862 2026] [security2:error] [pid 302018:tid 302126] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portal.gradiente.com"] [uri "/test.php"] [unique_id "al9PG4As9lPxxVAErz0MjwAA2Gk"]
[Tue Jul 21 07:51:07.771099 2026] [security2:error] [pid 302018:tid 302067] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/pi.php"] [unique_id "al9PG4As9lPxxVAErz0MkQAAti4"]
[Tue Jul 21 07:51:07.771216 2026] [security2:error] [pid 302018:tid 302199] [client 34.17.160.209:55390] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "portal.gradiente.com"] [uri "/pi.php"] [unique_id "al9PG4As9lPxxVAErz0MkQAAti4"]
[Tue Jul 21 07:51:07.798554 2026] [security2:error] [pid 296703:tid 296905] [client 20.104.96.117:64372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9PGyn25uliftkV1n4uTAAAAEg"]
[Tue Jul 21 07:51:07.942343 2026] [security2:error] [pid 302018:tid 302137] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portal.gradiente.com"] [uri "/app_dev.php"] [unique_id "al9PG4As9lPxxVAErz0MkwAA4HQ"]
[Tue Jul 21 07:51:07.944054 2026] [security2:error] [pid 302018:tid 302057] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "portal.gradiente.com"] [uri "/_ignition/health-check"] [unique_id "al9PG4As9lPxxVAErz0MlAAA4CQ"]
[Tue Jul 21 07:51:07.963363 2026] [security2:error] [pid 302018:tid 302110] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portal.gradiente.com"] [uri "/app_dev.php/_profiler"] [unique_id "al9PG4As9lPxxVAErz0MlwAApVk"]
[Tue Jul 21 07:51:07.987536 2026] [security2:error] [pid 302018:tid 302171] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/live/.env"] [unique_id "al9PG4As9lPxxVAErz0MmwAAAJo"]
[Tue Jul 21 07:51:08.003450 2026] [security2:error] [pid 302018:tid 302071] [remote 34.17.160.209:55390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portal.gradiente.com"] [uri "/server-info"] [unique_id "al9PHIAs9lPxxVAErz0MngAApTI"]
[Tue Jul 21 07:51:08.003606 2026] [security2:error] [pid 302018:tid 302182] [client 34.17.160.209:55390] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "portal.gradiente.com"] [uri "/server-info"] [unique_id "al9PHIAs9lPxxVAErz0MngAApTI"]
[Tue Jul 21 07:51:08.017257 2026] [security2:error] [pid 296703:tid 296959] [client 52.139.36.144:1154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/erty.php"] [unique_id "al9PHCn25uliftkV1n4uVwAAAH4"]
[Tue Jul 21 07:51:08.025860 2026] [access_compat:error] [pid 302018:tid 302044] [remote 34.17.160.209:55390] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 07:51:08.034639 2026] [security2:error] [pid 302018:tid 302277] [client 122.186.204.214:49767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PHIAs9lPxxVAErz0MoAAAAQQ"]
[Tue Jul 21 07:51:08.034732 2026] [security2:error] [pid 302018:tid 302277] [client 122.186.204.214:49767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PHIAs9lPxxVAErz0MoAAAAQQ"]
[Tue Jul 21 07:51:08.311784 2026] [security2:error] [pid 302018:tid 302221] [client 52.139.36.144:30551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al9PHIAs9lPxxVAErz0MogAAAMw"]
[Tue Jul 21 07:51:08.327064 2026] [security2:error] [pid 302018:tid 302200] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/prod/.env"] [unique_id "al9PHIAs9lPxxVAErz0MpwAAALc"]
[Tue Jul 21 07:51:08.453191 2026] [security2:error] [pid 296703:tid 296844] [client 178.153.91.96:56060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PHCn25uliftkV1n4uYgAAAAs"]
[Tue Jul 21 07:51:08.453307 2026] [security2:error] [pid 296703:tid 296844] [client 178.153.91.96:56060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PHCn25uliftkV1n4uYgAAAAs"]
[Tue Jul 21 07:51:08.542059 2026] [security2:error] [pid 302018:tid 302259] [client 139.167.225.182:65303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PHIAs9lPxxVAErz0MswAAAPI"]
[Tue Jul 21 07:51:08.542149 2026] [security2:error] [pid 302018:tid 302259] [client 139.167.225.182:65303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PHIAs9lPxxVAErz0MswAAAPI"]
[Tue Jul 21 07:51:08.664900 2026] [security2:error] [pid 302018:tid 302192] [client 20.220.225.223:52182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/wicked.php"] [unique_id "al9PHIAs9lPxxVAErz0MtQAAAK8"]
[Tue Jul 21 07:51:08.667477 2026] [security2:error] [pid 302018:tid 302178] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/dev/.env"] [unique_id "al9PHIAs9lPxxVAErz0MtgAAAKE"]
[Tue Jul 21 07:51:08.680009 2026] [security2:error] [pid 302018:tid 302235] [client 52.139.36.144:33140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/like.php"] [unique_id "al9PHIAs9lPxxVAErz0MtwAAANo"]
[Tue Jul 21 07:51:08.806419 2026] [security2:error] [pid 296703:tid 296864] [client 173.24.185.52:62570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PHCn25uliftkV1n4uaQAAAB8"]
[Tue Jul 21 07:51:08.806561 2026] [security2:error] [pid 296703:tid 296864] [client 173.24.185.52:62570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PHCn25uliftkV1n4uaQAAAB8"]
[Tue Jul 21 07:51:08.818053 2026] [security2:error] [pid 302018:tid 302236] [client 20.197.192.193:8352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/yup.php"] [unique_id "al9PHIAs9lPxxVAErz0MvQAAANs"]
[Tue Jul 21 07:51:08.934680 2026] [security2:error] [pid 302018:tid 302276] [client 117.247.80.59:32719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PHIAs9lPxxVAErz0MwAAAAQM"]
[Tue Jul 21 07:51:08.934820 2026] [security2:error] [pid 302018:tid 302276] [client 117.247.80.59:32719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PHIAs9lPxxVAErz0MwAAAAQM"]
[Tue Jul 21 07:51:09.007265 2026] [security2:error] [pid 302018:tid 302156] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/staging/.env"] [unique_id "al9PHYAs9lPxxVAErz0MxQAAAIs"]
[Tue Jul 21 07:51:09.073261 2026] [security2:error] [pid 302018:tid 302175] [client 52.139.36.144:30466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/bless5.php"] [unique_id "al9PHYAs9lPxxVAErz0MyAAAAJ4"]
[Tue Jul 21 07:51:09.090437 2026] [security2:error] [pid 302018:tid 302174] [client 20.151.10.161:43969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/jp.php"] [unique_id "al9PHYAs9lPxxVAErz0MyQAAAJ0"]
[Tue Jul 21 07:51:09.237725 2026] [security2:error] [pid 302018:tid 302176] [client 20.197.192.193:26923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/ms-new.php"] [unique_id "al9PHYAs9lPxxVAErz0MzgAAAJ8"]
[Tue Jul 21 07:51:09.346906 2026] [security2:error] [pid 302018:tid 302195] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/opt/.env"] [unique_id "al9PHYAs9lPxxVAErz0M0AAAALI"]
[Tue Jul 21 07:51:09.475741 2026] [security2:error] [pid 302018:tid 302209] [client 103.29.114.44:55835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PHYAs9lPxxVAErz0M0gAAAMA"]
[Tue Jul 21 07:51:09.475886 2026] [security2:error] [pid 302018:tid 302209] [client 103.29.114.44:55835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PHYAs9lPxxVAErz0M0gAAAMA"]
[Tue Jul 21 07:51:09.502619 2026] [security2:error] [pid 302018:tid 302264] [client 154.192.233.199:59876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PHYAs9lPxxVAErz0M0wAAAPc"]
[Tue Jul 21 07:51:09.502753 2026] [security2:error] [pid 302018:tid 302264] [client 154.192.233.199:59876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PHYAs9lPxxVAErz0M0wAAAPc"]
[Tue Jul 21 07:51:09.514609 2026] [security2:error] [pid 296703:tid 296920] [client 52.139.36.144:33038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/t.php"] [unique_id "al9PHSn25uliftkV1n4udAAAAFc"]
[Tue Jul 21 07:51:09.665694 2026] [security2:error] [pid 296703:tid 296954] [client 136.144.33.54:22621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PHSn25uliftkV1n4uegAAAHk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:09.686842 2026] [security2:error] [pid 302018:tid 302188] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/laravel/.env"] [unique_id "al9PHYAs9lPxxVAErz0M1wAAAKs"]
[Tue Jul 21 07:51:09.847654 2026] [security2:error] [pid 296703:tid 296917] [client 52.139.36.144:30533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/xoot.php"] [unique_id "al9PHSn25uliftkV1n4ufwAAAFQ"]
[Tue Jul 21 07:51:09.933198 2026] [security2:error] [pid 296703:tid 296944] [client 20.220.225.223:38680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/phpinfo.php1"] [unique_id "al9PHSn25uliftkV1n4uggAAAG8"]
[Tue Jul 21 07:51:10.026349 2026] [security2:error] [pid 302018:tid 302265] [client 54.251.12.30:41546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/symfony/.env"] [unique_id "al9PHoAs9lPxxVAErz0M4gAAAPg"]
[Tue Jul 21 07:51:10.030612 2026] [security2:error] [pid 302018:tid 302229] [client 20.104.96.117:59732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/qqqa.php"] [unique_id "al9PHoAs9lPxxVAErz0M4wAAANQ"]
[Tue Jul 21 07:51:10.071195 2026] [security2:error] [pid 296703:tid 296792] [remote 173.252.87.4:46832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9PHin25uliftkV1n4uhgAAJ1g"]
[Tue Jul 21 07:51:10.146288 2026] [security2:error] [pid 296703:tid 296905] [client 52.139.36.144:33138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/xqq.php"] [unique_id "al9PHin25uliftkV1n4uiAAAAEg"]
[Tue Jul 21 07:51:10.255830 2026] [security2:error] [pid 296703:tid 296929] [client 117.217.38.194:58210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PHin25uliftkV1n4uiQAAAGA"]
[Tue Jul 21 07:51:10.255960 2026] [security2:error] [pid 296703:tid 296929] [client 117.217.38.194:58210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PHin25uliftkV1n4uiQAAAGA"]
[Tue Jul 21 07:51:10.276084 2026] [security2:error] [pid 296703:tid 296745] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PHin25uliftkV1n4uiwAAGik"]
[Tue Jul 21 07:51:10.276214 2026] [security2:error] [pid 296703:tid 296859] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PHin25uliftkV1n4uiwAAGik"]
[Tue Jul 21 07:51:10.469240 2026] [security2:error] [pid 302018:tid 302190] [client 52.139.36.144:1240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-load.php"] [unique_id "al9PHoAs9lPxxVAErz0M5wAAAK0"]
[Tue Jul 21 07:51:10.614721 2026] [security2:error] [pid 302018:tid 302261] [client 122.179.91.63:17797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PHoAs9lPxxVAErz0M6gAAAPQ"]
[Tue Jul 21 07:51:10.614971 2026] [security2:error] [pid 302018:tid 302261] [client 122.179.91.63:17797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PHoAs9lPxxVAErz0M6gAAAPQ"]
[Tue Jul 21 07:51:10.814553 2026] [security2:error] [pid 296703:tid 296870] [client 20.151.10.161:43929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/f35.php"] [unique_id "al9PHin25uliftkV1n4ulwAAACU"]
[Tue Jul 21 07:51:10.894944 2026] [security2:error] [pid 302018:tid 302277] [client 52.139.36.144:33150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/x.php"] [unique_id "al9PHoAs9lPxxVAErz0M7AAAAQQ"]
[Tue Jul 21 07:51:10.974635 2026] [security2:error] [pid 302018:tid 302037] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PHoAs9lPxxVAErz0M7QAAsBA"]
[Tue Jul 21 07:51:10.974790 2026] [security2:error] [pid 302018:tid 302193] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PHoAs9lPxxVAErz0M7QAAsBA"]
[Tue Jul 21 07:51:11.066415 2026] [security2:error] [pid 296703:tid 296838] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/wordpress/.env"] [unique_id "al9PHyn25uliftkV1n4uoQAAAAU"]
[Tue Jul 21 07:51:11.284913 2026] [security2:error] [pid 302018:tid 302200] [client 128.127.105.184:39340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PH4As9lPxxVAErz0M8AAAALc"]
[Tue Jul 21 07:51:11.285022 2026] [security2:error] [pid 302018:tid 302200] [client 128.127.105.184:39340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PH4As9lPxxVAErz0M8AAAALc"]
[Tue Jul 21 07:51:11.416639 2026] [security2:error] [pid 296703:tid 296943] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/wp/.env"] [unique_id "al9PHyn25uliftkV1n4uowAAAG4"]
[Tue Jul 21 07:51:11.561724 2026] [security2:error] [pid 302018:tid 302178] [client 20.220.225.223:19266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/wicked.php"] [unique_id "al9PH4As9lPxxVAErz0M8wAAAKE"]
[Tue Jul 21 07:51:11.686105 2026] [security2:error] [pid 302018:tid 302217] [client 52.139.36.144:33111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/i.php"] [unique_id "al9PH4As9lPxxVAErz0M9gAAAMg"]
[Tue Jul 21 07:51:11.767650 2026] [security2:error] [pid 296703:tid 296841] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/cms/.env"] [unique_id "al9PHyn25uliftkV1n4uqgAAAAg"]
[Tue Jul 21 07:51:11.774714 2026] [security2:error] [pid 302018:tid 302143] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PH4As9lPxxVAErz0M9wAA6no"]
[Tue Jul 21 07:51:11.774923 2026] [security2:error] [pid 302018:tid 302251] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PH4As9lPxxVAErz0M9wAA6no"]
[Tue Jul 21 07:51:11.822935 2026] [security2:error] [pid 296703:tid 296854] [client 20.197.192.193:27098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/track.php"] [unique_id "al9PHyn25uliftkV1n4urAAAABU"]
[Tue Jul 21 07:51:12.117246 2026] [security2:error] [pid 296703:tid 296845] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/drupal/.env"] [unique_id "al9PICn25uliftkV1n4uswAAAAw"]
[Tue Jul 21 07:51:12.166780 2026] [security2:error] [pid 296703:tid 296895] [client 74.249.245.134:65090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/byp.php"] [unique_id "al9PICn25uliftkV1n4uuQAAAD4"]
[Tue Jul 21 07:51:12.232514 2026] [security2:error] [pid 296703:tid 296937] [client 52.139.36.144:26125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/ms-edit.php"] [unique_id "al9PICn25uliftkV1n4uuwAAAGg"]
[Tue Jul 21 07:51:12.357391 2026] [security2:error] [pid 302018:tid 302134] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PIIAs9lPxxVAErz0NDgAAhnE"]
[Tue Jul 21 07:51:12.357604 2026] [security2:error] [pid 302018:tid 302151] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PIIAs9lPxxVAErz0NDgAAhnE"]
[Tue Jul 21 07:51:12.468685 2026] [security2:error] [pid 296703:tid 296889] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/joomla/.env"] [unique_id "al9PICn25uliftkV1n4uxwAAADg"]
[Tue Jul 21 07:51:12.576684 2026] [security2:error] [pid 302018:tid 302263] [client 106.215.181.8:32211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PIIAs9lPxxVAErz0NFgAAAPY"]
[Tue Jul 21 07:51:12.576807 2026] [security2:error] [pid 302018:tid 302263] [client 106.215.181.8:32211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PIIAs9lPxxVAErz0NFgAAAPY"]
[Tue Jul 21 07:51:12.586836 2026] [security2:error] [pid 302018:tid 302238] [client 52.139.36.144:1213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/v2.php"] [unique_id "al9PIIAs9lPxxVAErz0NFwAAAN0"]
[Tue Jul 21 07:51:12.615636 2026] [security2:error] [pid 296703:tid 296759] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env"] [unique_id "al9PICn25uliftkV1n4uzAAAWTc"]
[Tue Jul 21 07:51:12.818982 2026] [security2:error] [pid 296703:tid 296956] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/magento/.env"] [unique_id "al9PICn25uliftkV1n4uzwAAAHs"]
[Tue Jul 21 07:51:12.942619 2026] [security2:error] [pid 302018:tid 302245] [client 20.220.225.223:23430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/edit.php"] [unique_id "al9PIIAs9lPxxVAErz0NIAAAAOQ"]
[Tue Jul 21 07:51:12.959942 2026] [security2:error] [pid 296703:tid 296781] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "gradiente.com"] [uri "/graphql"] [unique_id "al9PICn25uliftkV1n4u0gAASE0"]
[Tue Jul 21 07:51:12.961160 2026] [security2:error] [pid 296703:tid 296827] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.old"] [unique_id "al9PICn25uliftkV1n4u1gAASHs"]
[Tue Jul 21 07:51:12.961165 2026] [security2:error] [pid 296703:tid 296820] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.backup"] [unique_id "al9PICn25uliftkV1n4u1AAASHQ"]
[Tue Jul 21 07:51:12.962434 2026] [security2:error] [pid 296703:tid 296791] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.bak"] [unique_id "al9PICn25uliftkV1n4u1wAASFc"]
[Tue Jul 21 07:51:13.082973 2026] [security2:error] [pid 296703:tid 296754] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/api/.env"] [unique_id "al9PISn25uliftkV1n4u3QAASDI"]
[Tue Jul 21 07:51:13.082973 2026] [security2:error] [pid 296703:tid 296788] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/config/.env"] [unique_id "al9PISn25uliftkV1n4u3gAASFQ"]
[Tue Jul 21 07:51:13.083550 2026] [security2:error] [pid 296703:tid 296813] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/backend/.env"] [unique_id "al9PISn25uliftkV1n4u4AAASG0"]
[Tue Jul 21 07:51:13.118788 2026] [security2:error] [pid 302018:tid 302276] [client 20.104.96.117:64361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/aunmc.php"] [unique_id "al9PIYAs9lPxxVAErz0NKAAAAQM"]
[Tue Jul 21 07:51:13.169409 2026] [security2:error] [pid 296703:tid 296893] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/shopify/.env"] [unique_id "al9PISn25uliftkV1n4u4gAAADw"]
[Tue Jul 21 07:51:13.216220 2026] [security2:error] [pid 302018:tid 302214] [client 136.144.33.29:64229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PIYAs9lPxxVAErz0NKwAAAMU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:13.249124 2026] [security2:error] [pid 296703:tid 296825] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "gradiente.com"] [uri "/api/graphql"] [unique_id "al9PISn25uliftkV1n4u4wAAJXk"]
[Tue Jul 21 07:51:13.295763 2026] [security2:error] [pid 302018:tid 302268] [client 52.139.36.144:26154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/new.php"] [unique_id "al9PIYAs9lPxxVAErz0NLgAAAPs"]
[Tue Jul 21 07:51:13.346954 2026] [security2:error] [pid 296703:tid 296713] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.docker/config.json"] [unique_id "al9PISn25uliftkV1n4u7QAAKgk"]
[Tue Jul 21 07:51:13.347153 2026] [security2:error] [pid 296703:tid 296875] [client 34.17.160.209:51564] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/.docker/config.json"] [unique_id "al9PISn25uliftkV1n4u7QAAKgk"]
[Tue Jul 21 07:51:13.356888 2026] [security2:error] [pid 296703:tid 296896] [client 184.75.223.211:52366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PISn25uliftkV1n4u7wAAAD8"]
[Tue Jul 21 07:51:13.357006 2026] [security2:error] [pid 296703:tid 296896] [client 184.75.223.211:52366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PISn25uliftkV1n4u7wAAAD8"]
[Tue Jul 21 07:51:13.447232 2026] [security2:error] [pid 302018:tid 302151] [client 20.197.192.193:8325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/jj.php"] [unique_id "al9PIYAs9lPxxVAErz0NMgAAAIY"]
[Tue Jul 21 07:51:13.465095 2026] [security2:error] [pid 296703:tid 296846] [client 193.36.225.152:31517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PISn25uliftkV1n4u8QAAAA0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:51:13.480628 2026] [security2:error] [pid 296703:tid 296821] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "gradiente.com"] [uri "/v1/graphql"] [unique_id "al9PISn25uliftkV1n4u8wAAKnU"]
[Tue Jul 21 07:51:13.511270 2026] [security2:error] [pid 296703:tid 296777] [remote 91.142.222.105:51444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9PISn25uliftkV1n4u9gAAPUk"]
[Tue Jul 21 07:51:13.518520 2026] [security2:error] [pid 296703:tid 296880] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/prestashop/.env"] [unique_id "al9PISn25uliftkV1n4u-QAAAC8"]
[Tue Jul 21 07:51:13.534961 2026] [authz_core:error] [pid 302018:tid 302265] [client 34.17.160.209:0] AH01630: client denied by server configuration: /home2/rica0429/public_html/.htpasswd
[Tue Jul 21 07:51:13.539934 2026] [security2:error] [pid 302018:tid 302234] [client 20.151.10.161:43985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-load.php"] [unique_id "al9PIYAs9lPxxVAErz0NNwAAANk"]
[Tue Jul 21 07:51:13.550716 2026] [security2:error] [pid 302018:tid 302230] [client 20.197.192.193:27172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/2352356666.php"] [unique_id "al9PIYAs9lPxxVAErz0NOQAAANU"]
[Tue Jul 21 07:51:13.665293 2026] [security2:error] [pid 296703:tid 296776] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.ssh/id_rsa"] [unique_id "al9PISn25uliftkV1n4vAgAANkg"]
[Tue Jul 21 07:51:13.685558 2026] [security2:error] [pid 302018:tid 302212] [client 122.164.127.47:50913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PIYAs9lPxxVAErz0NQQAAAMM"]
[Tue Jul 21 07:51:13.685646 2026] [security2:error] [pid 302018:tid 302212] [client 122.164.127.47:50913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PIYAs9lPxxVAErz0NQQAAAMM"]
[Tue Jul 21 07:51:13.721961 2026] [security2:error] [pid 296703:tid 296805] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.ssh/id_dsa"] [unique_id "al9PISn25uliftkV1n4vBwAANmU"]
[Tue Jul 21 07:51:13.764240 2026] [security2:error] [pid 296703:tid 296766] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9PISn25uliftkV1n4vDAAACz4"]
[Tue Jul 21 07:51:13.775777 2026] [security2:error] [pid 302018:tid 302193] [client 52.139.36.144:33113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-admin/network/edit.php"] [unique_id "al9PIYAs9lPxxVAErz0NRwAAALA"]
[Tue Jul 21 07:51:13.868735 2026] [security2:error] [pid 296703:tid 296895] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/codeigniter/.env"] [unique_id "al9PISn25uliftkV1n4vDgAAAD4"]
[Tue Jul 21 07:51:13.877569 2026] [security2:error] [pid 296703:tid 296850] [client 202.143.127.214:55668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PISn25uliftkV1n4vDwAAABE"]
[Tue Jul 21 07:51:13.877717 2026] [security2:error] [pid 296703:tid 296850] [client 202.143.127.214:55668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PISn25uliftkV1n4vDwAAABE"]
[Tue Jul 21 07:51:13.943419 2026] [security2:error] [pid 296703:tid 296719] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9PISn25uliftkV1n4vEAAAQg8"]
[Tue Jul 21 07:51:13.959583 2026] [security2:error] [pid 296703:tid 296786] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/id_ecdsa"] [unique_id "al9PISn25uliftkV1n4vEgAANlI"]
[Tue Jul 21 07:51:13.991060 2026] [security2:error] [pid 296703:tid 296716] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/id_rsa"] [unique_id "al9PISn25uliftkV1n4vFAAANgw"]
[Tue Jul 21 07:51:14.004359 2026] [security2:error] [pid 296703:tid 296715] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/id_dsa"] [unique_id "al9PIin25uliftkV1n4vFgAANgs"]
[Tue Jul 21 07:51:14.004407 2026] [security2:error] [pid 296703:tid 296720] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/server.key"] [unique_id "al9PIin25uliftkV1n4vFwAANhA"]
[Tue Jul 21 07:51:14.029361 2026] [security2:error] [pid 302018:tid 302179] [client 41.68.90.219:63794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PIoAs9lPxxVAErz0NTwAAAKI"]
[Tue Jul 21 07:51:14.030563 2026] [security2:error] [pid 302018:tid 302179] [client 41.68.90.219:63794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PIoAs9lPxxVAErz0NTwAAAKI"]
[Tue Jul 21 07:51:14.064805 2026] [security2:error] [pid 296703:tid 296741] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/key.pem"] [unique_id "al9PIin25uliftkV1n4vGAAANiU"]
[Tue Jul 21 07:51:14.075380 2026] [security2:error] [pid 296703:tid 296753] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/privatekey.key"] [unique_id "al9PIin25uliftkV1n4vGQAANjE"]
[Tue Jul 21 07:51:14.159525 2026] [security2:error] [pid 296703:tid 296778] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp.php"] [unique_id "al9PIin25uliftkV1n4vHQAAako"]
[Tue Jul 21 07:51:14.218916 2026] [security2:error] [pid 296703:tid 296920] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/cakephp/.env"] [unique_id "al9PIin25uliftkV1n4vIQAAAFc"]
[Tue Jul 21 07:51:14.359244 2026] [security2:error] [pid 296703:tid 296709] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/new.php"] [unique_id "al9PIin25uliftkV1n4vMgAAAgU"]
[Tue Jul 21 07:51:14.421980 2026] [security2:error] [pid 302018:tid 302262] [client 52.139.36.144:26097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/pouhg.php"] [unique_id "al9PIoAs9lPxxVAErz0NUgAAAPU"]
[Tue Jul 21 07:51:14.474947 2026] [security2:error] [pid 296703:tid 296714] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PIin25uliftkV1n4vMwAAbAo"]
[Tue Jul 21 07:51:14.475074 2026] [security2:error] [pid 296703:tid 296941] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PIin25uliftkV1n4vMwAAbAo"]
[Tue Jul 21 07:51:14.486803 2026] [security2:error] [pid 296703:tid 296718] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9PIin25uliftkV1n4vNAAACQ4"]
[Tue Jul 21 07:51:14.486931 2026] [security2:error] [pid 296703:tid 296842] [client 34.17.160.209:51564] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9PIin25uliftkV1n4vNAAACQ4"]
[Tue Jul 21 07:51:14.548779 2026] [security2:error] [pid 296703:tid 296796] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/class-t.api.php"] [unique_id "al9PIin25uliftkV1n4vNgAAB1w"]
[Tue Jul 21 07:51:14.569162 2026] [security2:error] [pid 296703:tid 296901] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/zend/.env"] [unique_id "al9PIin25uliftkV1n4vNwAAAEQ"]
[Tue Jul 21 07:51:14.629253 2026] [security2:error] [pid 302018:tid 302243] [client 122.162.144.145:2453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PIoAs9lPxxVAErz0NVgAAAOI"]
[Tue Jul 21 07:51:14.629376 2026] [security2:error] [pid 302018:tid 302243] [client 122.162.144.145:2453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PIoAs9lPxxVAErz0NVgAAAOI"]
[Tue Jul 21 07:51:14.720463 2026] [security2:error] [pid 296703:tid 296758] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.hermes/auth.json"] [unique_id "al9PIin25uliftkV1n4vQwAAJjY"]
[Tue Jul 21 07:51:14.720685 2026] [security2:error] [pid 296703:tid 296871] [client 34.17.160.209:51564] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/.hermes/auth.json"] [unique_id "al9PIin25uliftkV1n4vQwAAJjY"]
[Tue Jul 21 07:51:14.722257 2026] [security2:error] [pid 296703:tid 296811] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.hermes/.env"] [unique_id "al9PIin25uliftkV1n4vRAAAJms"]
[Tue Jul 21 07:51:14.731767 2026] [security2:error] [pid 296703:tid 296780] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/plugins.php"] [unique_id "al9PIin25uliftkV1n4vRgAAaUw"]
[Tue Jul 21 07:51:14.775852 2026] [security2:error] [pid 296703:tid 296745] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.mcp.json"] [unique_id "al9PIin25uliftkV1n4vSwAAJik"]
[Tue Jul 21 07:51:14.776004 2026] [security2:error] [pid 296703:tid 296871] [client 34.17.160.209:51564] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/.mcp.json"] [unique_id "al9PIin25uliftkV1n4vSwAAJik"]
[Tue Jul 21 07:51:14.919383 2026] [security2:error] [pid 296703:tid 296896] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/yii/.env"] [unique_id "al9PIin25uliftkV1n4vTQAAAD8"]
[Tue Jul 21 07:51:14.979576 2026] [security2:error] [pid 296703:tid 296710] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "gradiente.com"] [uri "/wp-config.php.bak"] [unique_id "al9PIin25uliftkV1n4vUQAAJgY"]
[Tue Jul 21 07:51:14.981062 2026] [security2:error] [pid 296703:tid 296712] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/jp.php"] [unique_id "al9PIin25uliftkV1n4vUwAAFwg"]
[Tue Jul 21 07:51:14.997377 2026] [security2:error] [pid 296703:tid 296746] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "gradiente.com"] [uri "/wp-config.php.old"] [unique_id "al9PIin25uliftkV1n4vVwAAJio"]
[Tue Jul 21 07:51:15.004600 2026] [security2:error] [pid 296703:tid 296732] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/laravel/.env"] [unique_id "al9PIyn25uliftkV1n4vWAAAJhw"]
[Tue Jul 21 07:51:15.022144 2026] [security2:error] [pid 296703:tid 296752] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/config/.env.php"] [unique_id "al9PIyn25uliftkV1n4vWwAAJjA"]
[Tue Jul 21 07:51:15.042619 2026] [security2:error] [pid 296703:tid 296880] [client 62.102.148.187:41620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9PIyn25uliftkV1n4vXAAAAC8"]
[Tue Jul 21 07:51:15.042736 2026] [security2:error] [pid 296703:tid 296880] [client 62.102.148.187:41620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9PIyn25uliftkV1n4vXAAAAC8"]
[Tue Jul 21 07:51:15.145681 2026] [security2:error] [pid 302018:tid 302273] [client 52.139.36.144:1204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/cilus.php"] [unique_id "al9PI4As9lPxxVAErz0NYQAAAQA"]
[Tue Jul 21 07:51:15.155105 2026] [security2:error] [pid 302018:tid 302078] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PI4As9lPxxVAErz0NYgAAxTk"]
[Tue Jul 21 07:51:15.155291 2026] [security2:error] [pid 302018:tid 302214] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PI4As9lPxxVAErz0NYgAAxTk"]
[Tue Jul 21 07:51:15.278743 2026] [security2:error] [pid 296703:tid 296957] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/laravel5/.env"] [unique_id "al9PIyn25uliftkV1n4vYgAAAHw"]
[Tue Jul 21 07:51:15.320890 2026] [security2:error] [pid 296703:tid 296717] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/.env.php.bak"] [unique_id "al9PIyn25uliftkV1n4vZQAAJg0"]
[Tue Jul 21 07:51:15.348028 2026] [security2:error] [pid 296703:tid 296764] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/config.php.bak"] [unique_id "al9PIyn25uliftkV1n4vaAAAJjw"]
[Tue Jul 21 07:51:15.348122 2026] [security2:error] [pid 296703:tid 296773] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/core/.env"] [unique_id "al9PIyn25uliftkV1n4vZwAAJkU"]
[Tue Jul 21 07:51:15.390958 2026] [security2:error] [pid 296703:tid 296738] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/error.php"] [unique_id "al9PIyn25uliftkV1n4vagAAHyI"]
[Tue Jul 21 07:51:15.582843 2026] [security2:error] [pid 296703:tid 296806] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/configuration.php.bak"] [unique_id "al9PIyn25uliftkV1n4vcAAAOGY"]
[Tue Jul 21 07:51:15.584115 2026] [security2:error] [pid 296703:tid 296755] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.swp"] [unique_id "al9PIyn25uliftkV1n4vbwAAODM"]
[Tue Jul 21 07:51:15.606115 2026] [security2:error] [pid 296703:tid 296774] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/public/.env"] [unique_id "al9PIyn25uliftkV1n4vcgAAOEY"]
[Tue Jul 21 07:51:15.628755 2026] [security2:error] [pid 296703:tid 296923] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/v1/.env"] [unique_id "al9PIyn25uliftkV1n4vdQAAAFo"]
[Tue Jul 21 07:51:15.629026 2026] [security2:error] [pid 296703:tid 296829] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/web/.env"] [unique_id "al9PIyn25uliftkV1n4vdgAAOH0"]
[Tue Jul 21 07:51:15.721396 2026] [security2:error] [pid 296703:tid 296837] [client 52.139.36.144:26152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/file4.php"] [unique_id "al9PIyn25uliftkV1n4vhQAAAAQ"]
[Tue Jul 21 07:51:15.723405 2026] [security2:error] [pid 302018:tid 302040] [remote 182.77.62.24:55858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9PI4As9lPxxVAErz0NawAAlRM"]
[Tue Jul 21 07:51:15.723597 2026] [security2:error] [pid 302018:tid 302166] [client 182.77.62.24:55858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9PI4As9lPxxVAErz0NawAAlRM"]
[Tue Jul 21 07:51:15.735967 2026] [security2:error] [pid 296703:tid 296739] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/classwithtostring.php"] [unique_id "al9PIyn25uliftkV1n4vhgAARyM"]
[Tue Jul 21 07:51:15.802473 2026] [security2:error] [pid 296703:tid 296835] [client 20.104.96.117:59773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/uoocf.php"] [unique_id "al9PIyn25uliftkV1n4vhwAAAAI"]
[Tue Jul 21 07:51:15.815796 2026] [security2:error] [pid 296703:tid 296925] [client 103.166.103.129:34731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PIyn25uliftkV1n4viAAAAFw"]
[Tue Jul 21 07:51:15.815928 2026] [security2:error] [pid 296703:tid 296925] [client 103.166.103.129:34731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PIyn25uliftkV1n4viAAAAFw"]
[Tue Jul 21 07:51:15.877252 2026] [security2:error] [pid 296703:tid 296781] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/env.json"] [unique_id "al9PIyn25uliftkV1n4vkgAAOE0"]
[Tue Jul 21 07:51:15.979030 2026] [security2:error] [pid 296703:tid 296941] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/v2/.env"] [unique_id "al9PIyn25uliftkV1n4vkwAAAGw"]
[Tue Jul 21 07:51:16.085038 2026] [security2:error] [pid 296703:tid 296813] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/bless.php"] [unique_id "al9PJCn25uliftkV1n4voQAAB20"]
[Tue Jul 21 07:51:16.118023 2026] [security2:error] [pid 296703:tid 296867] [client 182.8.255.181:17301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PJCn25uliftkV1n4vpAAAACI"]
[Tue Jul 21 07:51:16.118141 2026] [security2:error] [pid 296703:tid 296867] [client 182.8.255.181:17301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PJCn25uliftkV1n4vpAAAACI"]
[Tue Jul 21 07:51:16.250932 2026] [security2:error] [pid 296703:tid 296888] [client 20.197.192.193:27140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/pn.php"] [unique_id "al9PJCn25uliftkV1n4vsQAAADc"]
[Tue Jul 21 07:51:16.255847 2026] [security2:error] [pid 296703:tid 296952] [client 20.197.192.193:8374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/dragonshell.php"] [unique_id "al9PJCn25uliftkV1n4vsgAAAHc"]
[Tue Jul 21 07:51:16.268659 2026] [security2:error] [pid 296703:tid 296825] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/storage/index.php"] [unique_id "al9PJCn25uliftkV1n4vswAAP3k"]
[Tue Jul 21 07:51:16.270608 2026] [security2:error] [pid 296703:tid 296876] [client 122.167.114.195:6578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.114.167.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hctreinamentos.net"] [uri "/xmlrpc.php"] [unique_id "al9PIyn25uliftkV1n4vXQAAACs"]
[Tue Jul 21 07:51:16.270846 2026] [security2:error] [pid 296703:tid 296876] [client 122.167.114.195:6578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hctreinamentos.net"] [uri "/xmlrpc.php"] [unique_id "al9PIyn25uliftkV1n4vXQAAACs"]
[Tue Jul 21 07:51:16.331216 2026] [security2:error] [pid 296703:tid 296924] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/v3/.env"] [unique_id "al9PJCn25uliftkV1n4vugAAAFs"]
[Tue Jul 21 07:51:16.368897 2026] [security2:error] [pid 296703:tid 296877] [client 223.236.153.128:5024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PJCn25uliftkV1n4vuwAAACw"]
[Tue Jul 21 07:51:16.370478 2026] [security2:error] [pid 296703:tid 296877] [client 223.236.153.128:5024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PJCn25uliftkV1n4vuwAAACw"]
[Tue Jul 21 07:51:16.373167 2026] [security2:error] [pid 302018:tid 302178] [client 52.139.36.144:26165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/samll.php"] [unique_id "al9PJIAs9lPxxVAErz0NeQAAAKE"]
[Tue Jul 21 07:51:16.451885 2026] [security2:error] [pid 296703:tid 296713] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/g.php"] [unique_id "al9PJCn25uliftkV1n4vvgAAZgk"]
[Tue Jul 21 07:51:16.629211 2026] [security2:error] [pid 296703:tid 296705] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/nf.php"] [unique_id "al9PJCn25uliftkV1n4vxQAAaAE"]
[Tue Jul 21 07:51:16.682037 2026] [security2:error] [pid 296703:tid 296855] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/api/v1/.env"] [unique_id "al9PJCn25uliftkV1n4v0QAAABY"]
[Tue Jul 21 07:51:16.732766 2026] [security2:error] [pid 296703:tid 296747] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/graphql"] [unique_id "al9PJCn25uliftkV1n4v1QAADCs"]
[Tue Jul 21 07:51:16.732773 2026] [security2:error] [pid 296703:tid 296775] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/swagger.json"] [unique_id "al9PJCn25uliftkV1n4v1gAADEc"]
[Tue Jul 21 07:51:16.732923 2026] [security2:error] [pid 296703:tid 296845] [client 34.17.160.209:51564] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/graphql"] [unique_id "al9PJCn25uliftkV1n4v1QAADCs"]
[Tue Jul 21 07:51:16.765175 2026] [security2:error] [pid 302018:tid 302139] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PJIAs9lPxxVAErz0NhQAAvHY"]
[Tue Jul 21 07:51:16.765292 2026] [security2:error] [pid 302018:tid 302205] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PJIAs9lPxxVAErz0NhQAAvHY"]
[Tue Jul 21 07:51:16.813831 2026] [security2:error] [pid 296703:tid 296805] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xda.php"] [unique_id "al9PJCn25uliftkV1n4v3AAABGU"]
[Tue Jul 21 07:51:16.934479 2026] [security2:error] [pid 302018:tid 302158] [client 20.151.10.161:44015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/xwpg.php"] [unique_id "al9PJIAs9lPxxVAErz0NigAAAI0"]
[Tue Jul 21 07:51:16.944022 2026] [security2:error] [pid 302018:tid 302151] [client 52.139.36.144:26146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/Okxob.php"] [unique_id "al9PJIAs9lPxxVAErz0NiwAAAIY"]
[Tue Jul 21 07:51:17.010336 2026] [security2:error] [pid 296703:tid 296711] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/shell.php"] [unique_id "al9PJSn25uliftkV1n4v4AAALQc"]
[Tue Jul 21 07:51:17.031288 2026] [security2:error] [pid 296703:tid 296851] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/api/v2/.env"] [unique_id "al9PJSn25uliftkV1n4v5AAAABI"]
[Tue Jul 21 07:51:17.145124 2026] [security2:error] [pid 302018:tid 302082] [remote 20.75.217.72:4937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9PJYAs9lPxxVAErz0NjwAA0j0"]
[Tue Jul 21 07:51:17.362367 2026] [security2:error] [pid 296703:tid 296816] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/3.php"] [unique_id "al9PJSn25uliftkV1n4v7QAAcHA"]
[Tue Jul 21 07:51:17.382257 2026] [security2:error] [pid 296703:tid 296891] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/rest/.env"] [unique_id "al9PJSn25uliftkV1n4v7gAAADo"]
[Tue Jul 21 07:51:17.392381 2026] [security2:error] [pid 296703:tid 296909] [client 20.197.192.193:27180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/wp-wpbak.php"] [unique_id "al9PJSn25uliftkV1n4v8AAAAEw"]
[Tue Jul 21 07:51:17.624835 2026] [security2:error] [pid 302018:tid 302244] [client 52.139.36.144:26127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/ok.php"] [unique_id "al9PJYAs9lPxxVAErz0NmAAAAOM"]
[Tue Jul 21 07:51:17.646689 2026] [security2:error] [pid 296703:tid 296715] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/mds.php"] [unique_id "al9PJSn25uliftkV1n4v8gAAEws"]
[Tue Jul 21 07:51:17.705520 2026] [security2:error] [pid 296703:tid 296734] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/app_dev.php"] [unique_id "al9PJSn25uliftkV1n4v9QAAPx4"]
[Tue Jul 21 07:51:17.705678 2026] [security2:error] [pid 296703:tid 296896] [client 34.17.160.209:51564] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/app_dev.php"] [unique_id "al9PJSn25uliftkV1n4v9QAAPx4"]
[Tue Jul 21 07:51:17.724491 2026] [security2:error] [pid 296703:tid 296753] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/app_dev.php/_profiler"] [unique_id "al9PJSn25uliftkV1n4v-AAAPzE"]
[Tue Jul 21 07:51:17.731947 2026] [security2:error] [pid 296703:tid 296838] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/graphql/.env"] [unique_id "al9PJSn25uliftkV1n4v-gAAAAU"]
[Tue Jul 21 07:51:17.739773 2026] [security2:error] [pid 302018:tid 302261] [client 172.245.102.29:23619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PJIAs9lPxxVAErz0NegAAAPQ"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:51:17.744737 2026] [security2:error] [pid 296703:tid 296787] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/i.php"] [unique_id "al9PJSn25uliftkV1n4wAAAAP1M"]
[Tue Jul 21 07:51:17.744762 2026] [security2:error] [pid 296703:tid 296765] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/test.php"] [unique_id "al9PJSn25uliftkV1n4v_gAAPz0"]
[Tue Jul 21 07:51:17.744791 2026] [security2:error] [pid 296703:tid 296750] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/phpinfo.php"] [unique_id "al9PJSn25uliftkV1n4wAQAAPy4"]
[Tue Jul 21 07:51:17.745331 2026] [security2:error] [pid 296703:tid 296709] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/info.php"] [unique_id "al9PJSn25uliftkV1n4wBAAAPwU"]
[Tue Jul 21 07:51:17.762841 2026] [security2:error] [pid 302018:tid 302229] [client 103.86.117.203:64781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PJYAs9lPxxVAErz0NnAAAANQ"]
[Tue Jul 21 07:51:17.763031 2026] [security2:error] [pid 302018:tid 302229] [client 103.86.117.203:64781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PJYAs9lPxxVAErz0NnAAAANQ"]
[Tue Jul 21 07:51:17.767082 2026] [security2:error] [pid 296703:tid 296943] [client 74.249.245.134:24831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/date.php"] [unique_id "al9PJSn25uliftkV1n4wCAAAAG4"]
[Tue Jul 21 07:51:17.784177 2026] [security2:error] [pid 296703:tid 296803] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/pi.php"] [unique_id "al9PJSn25uliftkV1n4wCQAAP2M"]
[Tue Jul 21 07:51:17.841756 2026] [security2:error] [pid 296703:tid 296810] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/archive.php"] [unique_id "al9PJSn25uliftkV1n4wDQAAXmo"]
[Tue Jul 21 07:51:17.948708 2026] [security2:error] [pid 296703:tid 296844] [client 52.139.36.144:33116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wuasr.php"] [unique_id "al9PJSn25uliftkV1n4wDwAAAAs"]
[Tue Jul 21 07:51:18.013212 2026] [access_compat:error] [pid 296703:tid 296782] [remote 34.17.160.209:51564] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Tue Jul 21 07:51:18.020928 2026] [security2:error] [pid 296703:tid 296793] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/amax.php"] [unique_id "al9PJin25uliftkV1n4wGQAAH1k"]
[Tue Jul 21 07:51:18.050843 2026] [security2:error] [pid 302018:tid 302097] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PJoAs9lPxxVAErz0NqwABBEw"]
[Tue Jul 21 07:51:18.050912 2026] [security2:error] [pid 296703:tid 296824] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/trace.axd"] [unique_id "al9PJin25uliftkV1n4wGgAAMXg"]
[Tue Jul 21 07:51:18.051018 2026] [security2:error] [pid 302018:tid 302277] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PJoAs9lPxxVAErz0NqwABBEw"]
[Tue Jul 21 07:51:18.082300 2026] [security2:error] [pid 296703:tid 296906] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/gateway/.env"] [unique_id "al9PJin25uliftkV1n4wGwAAAEk"]
[Tue Jul 21 07:51:18.103650 2026] [security2:error] [pid 296703:tid 296758] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/server-info"] [unique_id "al9PJin25uliftkV1n4wHAAAMTY"]
[Tue Jul 21 07:51:18.119106 2026] [security2:error] [pid 302018:tid 302158] [client 74.249.245.134:65212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/166.php"] [unique_id "al9PJoAs9lPxxVAErz0NrgAAAI0"]
[Tue Jul 21 07:51:18.199253 2026] [security2:error] [pid 296703:tid 296751] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/moon.php"] [unique_id "al9PJin25uliftkV1n4wIQAAFi8"]
[Tue Jul 21 07:51:18.324762 2026] [security2:error] [pid 302018:tid 302227] [client 20.104.96.117:64362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/iywwi.php"] [unique_id "al9PJoAs9lPxxVAErz0NtQAAANI"]
[Tue Jul 21 07:51:18.376936 2026] [security2:error] [pid 302018:tid 302237] [client 93.108.115.148:64583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.115.108.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homemsedutoronline.com"] [uri "/xmlrpc.php"] [unique_id "al9PJYAs9lPxxVAErz0NkAAAANw"]
[Tue Jul 21 07:51:18.377142 2026] [security2:error] [pid 302018:tid 302237] [client 93.108.115.148:64583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "homemsedutoronline.com"] [uri "/xmlrpc.php"] [unique_id "al9PJYAs9lPxxVAErz0NkAAAANw"]
[Tue Jul 21 07:51:18.380867 2026] [security2:error] [pid 296703:tid 296746] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ws83.php"] [unique_id "al9PJin25uliftkV1n4wKQAAeSo"]
[Tue Jul 21 07:51:18.389824 2026] [security2:error] [pid 296703:tid 296872] [client 136.144.33.111:55835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PJSn25uliftkV1n4v6AAAACc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:18.432712 2026] [security2:error] [pid 296703:tid 296904] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/microservice/.env"] [unique_id "al9PJin25uliftkV1n4wKgAAAEc"]
[Tue Jul 21 07:51:18.533808 2026] [security2:error] [pid 296703:tid 296851] [client 52.139.36.144:26115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/bless11.php"] [unique_id "al9PJin25uliftkV1n4wKwAAABI"]
[Tue Jul 21 07:51:18.560670 2026] [security2:error] [pid 296703:tid 296732] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/CDX1.php"] [unique_id "al9PJin25uliftkV1n4wLAAABhw"]
[Tue Jul 21 07:51:18.742647 2026] [security2:error] [pid 296703:tid 296789] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/inputs.php"] [unique_id "al9PJin25uliftkV1n4wNAAAUFU"]
[Tue Jul 21 07:51:18.776495 2026] [security2:error] [pid 302018:tid 302189] [client 122.186.204.214:50307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PJoAs9lPxxVAErz0NvQAAAKw"]
[Tue Jul 21 07:51:18.776634 2026] [security2:error] [pid 302018:tid 302189] [client 122.186.204.214:50307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PJoAs9lPxxVAErz0NvQAAAKw"]
[Tue Jul 21 07:51:18.782991 2026] [security2:error] [pid 296703:tid 296861] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/service/.env"] [unique_id "al9PJin25uliftkV1n4wNgAAABw"]
[Tue Jul 21 07:51:18.893390 2026] [security2:error] [pid 302018:tid 302214] [client 109.60.28.94:61372] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PJoAs9lPxxVAErz0NvAAAAMU"]
[Tue Jul 21 07:51:18.893560 2026] [security2:error] [pid 302018:tid 302214] [client 109.60.28.94:61372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PJoAs9lPxxVAErz0NvAAAAMU"]
[Tue Jul 21 07:51:18.921443 2026] [security2:error] [pid 296703:tid 296808] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ms-edit.php"] [unique_id "al9PJin25uliftkV1n4wPAAAdmg"]
[Tue Jul 21 07:51:18.983187 2026] [security2:error] [pid 302018:tid 302186] [client 178.153.91.96:36921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PJoAs9lPxxVAErz0NwgAAAKk"]
[Tue Jul 21 07:51:18.983307 2026] [security2:error] [pid 302018:tid 302186] [client 178.153.91.96:36921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PJoAs9lPxxVAErz0NwgAAAKk"]
[Tue Jul 21 07:51:19.024459 2026] [security2:error] [pid 302018:tid 302230] [client 59.96.220.140:50546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9PJ4As9lPxxVAErz0NwwAAANU"]
[Tue Jul 21 07:51:19.026182 2026] [security2:error] [pid 302018:tid 302230] [client 59.96.220.140:50546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9PJ4As9lPxxVAErz0NwwAAANU"]
[Tue Jul 21 07:51:19.055123 2026] [security2:error] [pid 302018:tid 302244] [client 52.139.36.144:26166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-block.php"] [unique_id "al9PJ4As9lPxxVAErz0NxAAAAOM"]
[Tue Jul 21 07:51:19.133342 2026] [security2:error] [pid 296703:tid 296887] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/api/v3/.env"] [unique_id "al9PJyn25uliftkV1n4wPQAAADY"]
[Tue Jul 21 07:51:19.139598 2026] [security2:error] [pid 302018:tid 302174] [client 139.167.225.182:49574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PJ4As9lPxxVAErz0NxQAAAJ0"]
[Tue Jul 21 07:51:19.139687 2026] [security2:error] [pid 302018:tid 302174] [client 139.167.225.182:49574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PJ4As9lPxxVAErz0NxQAAAJ0"]
[Tue Jul 21 07:51:19.173175 2026] [security2:error] [pid 296703:tid 296946] [client 20.197.192.193:27084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/dr.php"] [unique_id "al9PJyn25uliftkV1n4wPwAAAHE"]
[Tue Jul 21 07:51:19.291566 2026] [security2:error] [pid 296703:tid 296725] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/simple.php"] [unique_id "al9PJyn25uliftkV1n4wQQAAIhU"]
[Tue Jul 21 07:51:19.378219 2026] [security2:error] [pid 302018:tid 302212] [client 173.24.185.52:63047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PJ4As9lPxxVAErz0NyAAAAMM"]
[Tue Jul 21 07:51:19.378309 2026] [security2:error] [pid 302018:tid 302212] [client 173.24.185.52:63047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PJ4As9lPxxVAErz0NyAAAAMM"]
[Tue Jul 21 07:51:19.421571 2026] [security2:error] [pid 302018:tid 302208] [client 117.247.80.59:26752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PJ4As9lPxxVAErz0NygAAAL8"]
[Tue Jul 21 07:51:19.421673 2026] [security2:error] [pid 302018:tid 302208] [client 117.247.80.59:26752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PJ4As9lPxxVAErz0NygAAAL8"]
[Tue Jul 21 07:51:19.468347 2026] [security2:error] [pid 296703:tid 296806] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/404.php"] [unique_id "al9PJyn25uliftkV1n4wSgAAUWY"]
[Tue Jul 21 07:51:19.486829 2026] [security2:error] [pid 296703:tid 296838] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/api/dev/.env"] [unique_id "al9PJyn25uliftkV1n4wSwAAAAU"]
[Tue Jul 21 07:51:19.522951 2026] [security2:error] [pid 296703:tid 296929] [client 52.139.36.144:1178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/aevly.php"] [unique_id "al9PJyn25uliftkV1n4wTAAAAGA"]
[Tue Jul 21 07:51:19.804151 2026] [security2:error] [pid 296703:tid 296915] [client 20.220.225.223:19291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/edit.php"] [unique_id "al9PJyn25uliftkV1n4wVQAAAFI"]
[Tue Jul 21 07:51:19.837098 2026] [security2:error] [pid 296703:tid 296935] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/api/staging/.env"] [unique_id "al9PJyn25uliftkV1n4wVgAAAGY"]
[Tue Jul 21 07:51:19.950528 2026] [security2:error] [pid 296703:tid 296890] [client 20.104.96.117:59736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/gqgsa.php"] [unique_id "al9PJyn25uliftkV1n4wXwAAADk"]
[Tue Jul 21 07:51:20.015967 2026] [security2:error] [pid 296703:tid 296889] [client 185.213.175.37:33296] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "artix.locaiestetica.com.br"] [uri "/favicon.png"] [unique_id "al9PKCn25uliftkV1n4wYgAAADg"]
[Tue Jul 21 07:51:20.059601 2026] [security2:error] [pid 296703:tid 296882] [client 52.139.36.144:26062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/hello.php"] [unique_id "al9PKCn25uliftkV1n4wZAAAADE"]
[Tue Jul 21 07:51:20.066062 2026] [security2:error] [pid 296703:tid 296817] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/file3.php"] [unique_id "al9PKCn25uliftkV1n4wZQAAL3E"]
[Tue Jul 21 07:51:20.186724 2026] [security2:error] [pid 296703:tid 296849] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/vendor/.env"] [unique_id "al9PKCn25uliftkV1n4wZwAAABA"]
[Tue Jul 21 07:51:20.243109 2026] [security2:error] [pid 296703:tid 296742] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp-mail.php"] [unique_id "al9PKCn25uliftkV1n4wbQAAWiY"]
[Tue Jul 21 07:51:20.434949 2026] [security2:error] [pid 302018:tid 302277] [client 20.220.225.223:38210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/inso.php"] [unique_id "al9PKIAs9lPxxVAErz0N1wAAAQQ"]
[Tue Jul 21 07:51:20.469448 2026] [security2:error] [pid 296703:tid 296791] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/about.php"] [unique_id "al9PKCn25uliftkV1n4wcwAASFc"]
[Tue Jul 21 07:51:20.506019 2026] [security2:error] [pid 302018:tid 302270] [client 74.249.245.134:64117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/8.php"] [unique_id "al9PKIAs9lPxxVAErz0N2wAAAP0"]
[Tue Jul 21 07:51:20.535888 2026] [security2:error] [pid 296703:tid 296936] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/lib/.env"] [unique_id "al9PKCn25uliftkV1n4wdgAAAGc"]
[Tue Jul 21 07:51:20.599997 2026] [security2:error] [pid 302018:tid 302187] [client 52.139.36.144:1243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-links-opml.php"] [unique_id "al9PKIAs9lPxxVAErz0N3QAAAKo"]
[Tue Jul 21 07:51:20.630710 2026] [security2:error] [pid 296703:tid 296847] [client 103.29.114.44:45811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PKCn25uliftkV1n4wdwAAAA4"]
[Tue Jul 21 07:51:20.630864 2026] [security2:error] [pid 296703:tid 296847] [client 103.29.114.44:45811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PKCn25uliftkV1n4wdwAAAA4"]
[Tue Jul 21 07:51:20.677344 2026] [security2:error] [pid 296703:tid 296704] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/adminfuns.php"] [unique_id "al9PKCn25uliftkV1n4weQAATgA"]
[Tue Jul 21 07:51:20.724700 2026] [security2:error] [pid 296703:tid 296851] [client 117.217.38.194:58714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PKCn25uliftkV1n4wegAAABI"]
[Tue Jul 21 07:51:20.725151 2026] [security2:error] [pid 296703:tid 296851] [client 117.217.38.194:58714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PKCn25uliftkV1n4wegAAABI"]
[Tue Jul 21 07:51:20.740470 2026] [security2:error] [pid 302018:tid 302074] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PKIAs9lPxxVAErz0N4AAA9zU"]
[Tue Jul 21 07:51:20.740639 2026] [security2:error] [pid 302018:tid 302264] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PKIAs9lPxxVAErz0N4AAA9zU"]
[Tue Jul 21 07:51:20.856328 2026] [security2:error] [pid 296703:tid 296740] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/php8.php"] [unique_id "al9PKCn25uliftkV1n4wfAAAeiQ"]
[Tue Jul 21 07:51:20.887183 2026] [security2:error] [pid 296703:tid 296908] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/resources/.env"] [unique_id "al9PKCn25uliftkV1n4wfQAAAEs"]
[Tue Jul 21 07:51:21.091381 2026] [security2:error] [pid 302018:tid 302165] [client 52.139.36.144:33044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/forbidals.php"] [unique_id "al9PKYAs9lPxxVAErz0N6AAAAJQ"]
[Tue Jul 21 07:51:21.237263 2026] [security2:error] [pid 296703:tid 296840] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/assets/.env"] [unique_id "al9PKSn25uliftkV1n4whgAAAAc"]
[Tue Jul 21 07:51:21.290364 2026] [security2:error] [pid 302018:tid 302272] [client 122.179.91.63:10634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PKYAs9lPxxVAErz0N6QAAAP8"]
[Tue Jul 21 07:51:21.290502 2026] [security2:error] [pid 302018:tid 302272] [client 122.179.91.63:10634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PKYAs9lPxxVAErz0N6QAAAP8"]
[Tue Jul 21 07:51:21.583652 2026] [security2:error] [pid 296703:tid 296711] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PKSn25uliftkV1n4wjQAAUwc"]
[Tue Jul 21 07:51:21.583759 2026] [security2:error] [pid 296703:tid 296916] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PKSn25uliftkV1n4wjQAAUwc"]
[Tue Jul 21 07:51:21.587806 2026] [security2:error] [pid 296703:tid 296960] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/uploads/.env"] [unique_id "al9PKSn25uliftkV1n4wjgAAAH8"]
[Tue Jul 21 07:51:21.674556 2026] [security2:error] [pid 296703:tid 296906] [client 20.104.96.117:59750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/elbzl.php"] [unique_id "al9PKSn25uliftkV1n4wkAAAAEk"]
[Tue Jul 21 07:51:21.723694 2026] [security2:error] [pid 296703:tid 296767] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/info.php"] [unique_id "al9PKSn25uliftkV1n4wkQAAaD8"]
[Tue Jul 21 07:51:21.806458 2026] [security2:error] [pid 302018:tid 302275] [client 52.139.36.144:33121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/file30.php"] [unique_id "al9PKYAs9lPxxVAErz0N8QAAAQI"]
[Tue Jul 21 07:51:21.882651 2026] [security2:error] [pid 302018:tid 302100] [remote 47.128.54.188:47210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.serbetoadv.com"] [uri "/siemens-iq300-sn63ex15be-k.html"] [unique_id "al9PKYAs9lPxxVAErz0N8wAA9E8"]
[Tue Jul 21 07:51:21.898426 2026] [security2:error] [pid 302018:tid 302229] [client 128.127.105.184:57088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9PKYAs9lPxxVAErz0N9AAAANQ"]
[Tue Jul 21 07:51:21.898539 2026] [security2:error] [pid 302018:tid 302229] [client 128.127.105.184:57088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9PKYAs9lPxxVAErz0N9AAAANQ"]
[Tue Jul 21 07:51:21.930441 2026] [security2:error] [pid 296703:tid 296737] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/edit.php"] [unique_id "al9PKSn25uliftkV1n4wkwAAASE"]
[Tue Jul 21 07:51:21.936759 2026] [security2:error] [pid 296703:tid 296940] [client 20.197.192.193:27154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/2x.php"] [unique_id "al9PKSn25uliftkV1n4wlgAAAGs"]
[Tue Jul 21 07:51:21.937221 2026] [security2:error] [pid 296703:tid 296872] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/internal/.env"] [unique_id "al9PKSn25uliftkV1n4wlQAAACc"]
[Tue Jul 21 07:51:22.152233 2026] [security2:error] [pid 296703:tid 296723] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/166.php"] [unique_id "al9PKin25uliftkV1n4wngAAPhM"]
[Tue Jul 21 07:51:22.287216 2026] [security2:error] [pid 296703:tid 296945] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/tools/.env"] [unique_id "al9PKin25uliftkV1n4woAAAAHA"]
[Tue Jul 21 07:51:22.393302 2026] [security2:error] [pid 302018:tid 302182] [client 52.139.36.144:1209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/xda.php"] [unique_id "al9PKoAs9lPxxVAErz0N_QAAAKU"]
[Tue Jul 21 07:51:22.437362 2026] [security2:error] [pid 296703:tid 296947] [client 184.75.223.211:58410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9PKin25uliftkV1n4wpQAAAHI"]
[Tue Jul 21 07:51:22.437448 2026] [security2:error] [pid 296703:tid 296947] [client 184.75.223.211:58410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9PKin25uliftkV1n4wpQAAAHI"]
[Tue Jul 21 07:51:22.467794 2026] [security2:error] [pid 296703:tid 296777] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PKin25uliftkV1n4wpgAAG0k"]
[Tue Jul 21 07:51:22.467997 2026] [security2:error] [pid 296703:tid 296860] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PKin25uliftkV1n4wpgAAG0k"]
[Tue Jul 21 07:51:22.591706 2026] [security2:error] [pid 296703:tid 296951] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9PKin25uliftkV1n4wrgAAAHY"]
[Tue Jul 21 07:51:22.637265 2026] [security2:error] [pid 296703:tid 296887] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/scripts/.env"] [unique_id "al9PKin25uliftkV1n4wrwAAADY"]
[Tue Jul 21 07:51:22.794983 2026] [security2:error] [pid 302018:tid 302063] [remote 173.252.95.40:33486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9PKoAs9lPxxVAErz0OAQAA4io"]
[Tue Jul 21 07:51:22.845499 2026] [security2:error] [pid 296703:tid 296715] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/8.php"] [unique_id "al9PKin25uliftkV1n4wswAANAs"]
[Tue Jul 21 07:51:22.877091 2026] [security2:error] [pid 302018:tid 302180] [client 52.139.36.144:30523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/z.php"] [unique_id "al9PKoAs9lPxxVAErz0OAwAAAKM"]
[Tue Jul 21 07:51:22.878281 2026] [security2:error] [pid 296703:tid 296952] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PKin25uliftkV1n4wtAAAAHc"]
[Tue Jul 21 07:51:22.927416 2026] [security2:error] [pid 296703:tid 296716] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PKin25uliftkV1n4wtQAAcQw"]
[Tue Jul 21 07:51:22.927566 2026] [security2:error] [pid 296703:tid 296946] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PKin25uliftkV1n4wtQAAcQw"]
[Tue Jul 21 07:51:22.958946 2026] [security2:error] [pid 302018:tid 302219] [client 20.104.96.117:64378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/adjig.php"] [unique_id "al9PKoAs9lPxxVAErz0OBQAAAMo"]
[Tue Jul 21 07:51:22.988279 2026] [security2:error] [pid 296703:tid 296893] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/bin/.env"] [unique_id "al9PKin25uliftkV1n4wtgAAADw"]
[Tue Jul 21 07:51:23.026887 2026] [security2:error] [pid 302018:tid 302237] [client 62.102.148.187:55950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9PK4As9lPxxVAErz0OBwAAANw"]
[Tue Jul 21 07:51:23.026965 2026] [security2:error] [pid 302018:tid 302237] [client 62.102.148.187:55950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9PK4As9lPxxVAErz0OBwAAANw"]
[Tue Jul 21 07:51:23.032799 2026] [security2:error] [pid 296703:tid 296852] [client 193.36.225.56:43719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PKyn25uliftkV1n4wuAAAABM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:23.235479 2026] [security2:error] [pid 302018:tid 302171] [client 106.215.181.8:7487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PK4As9lPxxVAErz0OEwAAAJo"]
[Tue Jul 21 07:51:23.235676 2026] [security2:error] [pid 302018:tid 302171] [client 106.215.181.8:7487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PK4As9lPxxVAErz0OEwAAAJo"]
[Tue Jul 21 07:51:23.245925 2026] [security2:error] [pid 296703:tid 296765] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ws38.php"] [unique_id "al9PKyn25uliftkV1n4wvQAAWz0"]
[Tue Jul 21 07:51:23.262041 2026] [security2:error] [pid 302018:tid 302195] [client 52.139.36.144:26063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/b.php"] [unique_id "al9PK4As9lPxxVAErz0OFAAAALI"]
[Tue Jul 21 07:51:23.323001 2026] [security2:error] [pid 302018:tid 302189] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9PK4As9lPxxVAErz0OFwAAAKw"]
[Tue Jul 21 07:51:23.333312 2026] [security2:error] [pid 302018:tid 302172] [client 74.7.228.21:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "buyonlinetodayatadiscount.net.imperdivelbestpromotionofthedaytodayonly.com"] [uri "/cgi-sys/404.html"] [unique_id "al9PK4As9lPxxVAErz0OGAAAAJs"]
[Tue Jul 21 07:51:23.334796 2026] [security2:error] [pid 302018:tid 302198] [client 74.7.228.21:50612] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "buyonlinetodayatadiscount.net.imperdivelbestpromotionofthedaytodayonly.com"] [uri "/robots.txt"] [unique_id "al9PK4As9lPxxVAErz0OFQAAtQ8"]
[Tue Jul 21 07:51:23.337929 2026] [security2:error] [pid 296703:tid 296956] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/sbin/.env"] [unique_id "al9PKyn25uliftkV1n4wvwAAAHs"]
[Tue Jul 21 07:51:23.422830 2026] [security2:error] [pid 296703:tid 296709] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/a7.php"] [unique_id "al9PKyn25uliftkV1n4wwAAAZgU"]
[Tue Jul 21 07:51:23.601138 2026] [security2:error] [pid 296703:tid 296749] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/classsmtps.php"] [unique_id "al9PKyn25uliftkV1n4wzwAAHy0"]
[Tue Jul 21 07:51:23.607653 2026] [security2:error] [pid 302018:tid 302155] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9PK4As9lPxxVAErz0OKAAAAIo"]
[Tue Jul 21 07:51:23.688879 2026] [security2:error] [pid 296703:tid 296870] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/local/.env"] [unique_id "al9PKyn25uliftkV1n4w0QAAACU"]
[Tue Jul 21 07:51:23.789645 2026] [security2:error] [pid 296703:tid 296793] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/rip.php"] [unique_id "al9PKyn25uliftkV1n4w1AAAFlk"]
[Tue Jul 21 07:51:23.887257 2026] [security2:error] [pid 296703:tid 296919] [client 52.139.36.144:1170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/edit.php"] [unique_id "al9PKyn25uliftkV1n4w2AAAAFY"]
[Tue Jul 21 07:51:23.889712 2026] [security2:error] [pid 302018:tid 302203] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9PK4As9lPxxVAErz0OLgAAALo"]
[Tue Jul 21 07:51:23.969823 2026] [security2:error] [pid 296703:tid 296751] [remote 74.249.245.134:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "luminabeauty.com.br"] [uri "/1.php"] [unique_id "al9PKyn25uliftkV1n4w2QAAOy8"]
[Tue Jul 21 07:51:23.969949 2026] [security2:error] [pid 296703:tid 296751] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/1.php"] [unique_id "al9PKyn25uliftkV1n4w2QAAOy8"]
[Tue Jul 21 07:51:24.039070 2026] [security2:error] [pid 296703:tid 296872] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/portal/.env"] [unique_id "al9PLCn25uliftkV1n4w2wAAACc"]
[Tue Jul 21 07:51:24.062138 2026] [security2:error] [pid 302018:tid 302183] [client 20.220.225.223:22480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wpx.php"] [unique_id "al9PLIAs9lPxxVAErz0OMgAAAKY"]
[Tue Jul 21 07:51:24.067625 2026] [security2:error] [pid 302018:tid 302180] [client 20.220.225.223:23431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/kua.php"] [unique_id "al9PLIAs9lPxxVAErz0OMwAAAKM"]
[Tue Jul 21 07:51:24.098733 2026] [security2:error] [pid 302018:tid 302245] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "buyonlinetodayatadiscount.net"] [uri "/cgi-sys/404.html"] [unique_id "al9PLIAs9lPxxVAErz0OOAAAAOQ"]
[Tue Jul 21 07:51:24.100041 2026] [security2:error] [pid 296703:tid 296834] [client 74.7.230.1:47928] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "buyonlinetodayatadiscount.net"] [uri "/robots.txt"] [unique_id "al9PLCn25uliftkV1n4w3gAAAQY"]
[Tue Jul 21 07:51:24.172146 2026] [security2:error] [pid 296703:tid 296784] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/chosen.php"] [unique_id "al9PLCn25uliftkV1n4w3wAAOVA"]
[Tue Jul 21 07:51:24.173478 2026] [security2:error] [pid 296703:tid 296904] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9PLCn25uliftkV1n4w4AAAAEc"]
[Tue Jul 21 07:51:24.263241 2026] [proxy:error] [pid 302018:tid 302171] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:51:24.263316 2026] [proxy_http:error] [pid 302018:tid 302171] [client 193.160.32.97:64500] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:51:24.263916 2026] [proxy:error] [pid 302018:tid 302171] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:51:24.263944 2026] [proxy_http:error] [pid 302018:tid 302171] [client 193.160.32.97:64500] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:51:24.265173 2026] [security2:error] [pid 302018:tid 302273] [client 20.197.192.193:27179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/kq1.php"] [unique_id "al9PLIAs9lPxxVAErz0OPQAAAQA"]
[Tue Jul 21 07:51:24.350099 2026] [security2:error] [pid 296703:tid 296780] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/css.php"] [unique_id "al9PLCn25uliftkV1n4w5QAAMUw"]
[Tue Jul 21 07:51:24.389866 2026] [security2:error] [pid 296703:tid 296879] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/dashboard/.env"] [unique_id "al9PLCn25uliftkV1n4w5gAAAC4"]
[Tue Jul 21 07:51:24.429553 2026] [security2:error] [pid 296703:tid 296807] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/wp-login.php"] [unique_id "al9PLCn25uliftkV1n4w4gAAWWc"], referer: https://gradiente.com/wp-admin/
[Tue Jul 21 07:51:24.453488 2026] [core:error] [pid 302018:tid 302213] [client 193.160.32.97:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:51:24.453506 2026] [core:error] [pid 302018:tid 302213] [client 193.160.32.97:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:51:24.458855 2026] [security2:error] [pid 302018:tid 302191] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9PLIAs9lPxxVAErz0OQQAAAK4"]
[Tue Jul 21 07:51:24.494040 2026] [security2:error] [pid 296703:tid 296880] [client 52.139.36.144:26067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/app.php"] [unique_id "al9PLCn25uliftkV1n4w5wAAAC8"]
[Tue Jul 21 07:51:24.739887 2026] [security2:error] [pid 296703:tid 296899] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/panel/.env"] [unique_id "al9PLCn25uliftkV1n4w6wAAAEI"]
[Tue Jul 21 07:51:24.743022 2026] [security2:error] [pid 302018:tid 302177] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9PLIAs9lPxxVAErz0ORgAAAKA"]
[Tue Jul 21 07:51:24.798786 2026] [security2:error] [pid 302018:tid 302186] [client 20.104.96.117:59726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/byp.php"] [unique_id "al9PLIAs9lPxxVAErz0OSQAAAKk"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:51:24.943889 2026] [security2:error] [pid 302018:tid 302256] [client 41.68.90.219:64239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PLIAs9lPxxVAErz0OSgAAAO8"]
[Tue Jul 21 07:51:24.945389 2026] [security2:error] [pid 302018:tid 302256] [client 41.68.90.219:64239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PLIAs9lPxxVAErz0OSgAAAO8"]
[Tue Jul 21 07:51:24.959333 2026] [security2:error] [pid 296703:tid 296942] [client 202.143.127.214:56148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PLCn25uliftkV1n4w8AAAAG0"]
[Tue Jul 21 07:51:24.959464 2026] [security2:error] [pid 296703:tid 296942] [client 202.143.127.214:56148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PLCn25uliftkV1n4w8AAAAG0"]
[Tue Jul 21 07:51:24.985744 2026] [security2:error] [pid 296703:tid 296782] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/wp-login.php"] [unique_id "al9PKyn25uliftkV1n4w1QAAWU4"], referer: https://gradiente.com/login
[Tue Jul 21 07:51:24.991663 2026] [security2:error] [pid 302018:tid 302263] [client 52.139.36.144:26103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-png.php"] [unique_id "al9PLIAs9lPxxVAErz0OTAAAAPY"]
[Tue Jul 21 07:51:25.026232 2026] [security2:error] [pid 296703:tid 296947] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9PLSn25uliftkV1n4w8gAAAHI"]
[Tue Jul 21 07:51:25.078039 2026] [core:error] [pid 302018:tid 302208] [client 193.160.32.97:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:51:25.078071 2026] [core:error] [pid 302018:tid 302208] [client 193.160.32.97:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:51:25.084367 2026] [security2:error] [pid 296703:tid 296745] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/php.php"] [unique_id "al9PLSn25uliftkV1n4w9AAACyk"]
[Tue Jul 21 07:51:25.086591 2026] [core:error] [pid 302018:tid 302192] [client 193.160.32.97:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:51:25.086610 2026] [core:error] [pid 302018:tid 302192] [client 193.160.32.97:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:51:25.089742 2026] [security2:error] [pid 296703:tid 296860] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/crm/.env"] [unique_id "al9PLSn25uliftkV1n4w9QAAABs"]
[Tue Jul 21 07:51:25.132474 2026] [security2:error] [pid 302018:tid 302193] [client 20.220.225.223:55533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/berlin.php"] [unique_id "al9PLYAs9lPxxVAErz0OVwAAALA"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 07:51:25.277314 2026] [security2:error] [pid 296703:tid 296732] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/aa.php"] [unique_id "al9PLSn25uliftkV1n4w9wAAZRw"]
[Tue Jul 21 07:51:25.311320 2026] [security2:error] [pid 296703:tid 296869] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9PLSn25uliftkV1n4w-QAAACQ"]
[Tue Jul 21 07:51:25.321958 2026] [security2:error] [pid 302018:tid 302236] [client 20.151.10.161:43887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/waf.php"] [unique_id "al9PLYAs9lPxxVAErz0OWQAAANs"]
[Tue Jul 21 07:51:25.372129 2026] [security2:error] [pid 296703:tid 296957] [client 122.164.127.47:51500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PLSn25uliftkV1n4w_AAAAHw"]
[Tue Jul 21 07:51:25.374402 2026] [security2:error] [pid 296703:tid 296957] [client 122.164.127.47:51500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PLSn25uliftkV1n4w_AAAAHw"]
[Tue Jul 21 07:51:25.415348 2026] [security2:error] [pid 302018:tid 302071] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PLYAs9lPxxVAErz0OXgAA3zI"]
[Tue Jul 21 07:51:25.415570 2026] [security2:error] [pid 302018:tid 302240] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PLYAs9lPxxVAErz0OXgAA3zI"]
[Tue Jul 21 07:51:25.423068 2026] [security2:error] [pid 302018:tid 302220] [client 52.139.36.144:26071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/lib.php"] [unique_id "al9PLYAs9lPxxVAErz0OYAAAAMs"]
[Tue Jul 21 07:51:25.430275 2026] [security2:error] [pid 296703:tid 296811] [remote 34.17.160.209:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/wp-login.php"] [unique_id "al9PLCn25uliftkV1n4w4wAAWWs"], referer: https://gradiente.com/wp-admin/
[Tue Jul 21 07:51:25.439547 2026] [security2:error] [pid 296703:tid 296867] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/erp/.env"] [unique_id "al9PLSn25uliftkV1n4w_QAAACI"]
[Tue Jul 21 07:51:25.442097 2026] [security2:error] [pid 302018:tid 302198] [client 122.162.144.145:12154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PLYAs9lPxxVAErz0OYQAAALU"]
[Tue Jul 21 07:51:25.442211 2026] [security2:error] [pid 302018:tid 302198] [client 122.162.144.145:12154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PLYAs9lPxxVAErz0OYQAAALU"]
[Tue Jul 21 07:51:25.456256 2026] [security2:error] [pid 296703:tid 296717] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/bolt.php"] [unique_id "al9PLSn25uliftkV1n4w_gAAbA0"]
[Tue Jul 21 07:51:25.460859 2026] [security2:error] [pid 302018:tid 302274] [client 62.102.148.187:55964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9PLYAs9lPxxVAErz0OYgAAAQE"]
[Tue Jul 21 07:51:25.460936 2026] [security2:error] [pid 302018:tid 302274] [client 62.102.148.187:55964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9PLYAs9lPxxVAErz0OYgAAAQE"]
[Tue Jul 21 07:51:25.594230 2026] [security2:error] [pid 302018:tid 302168] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9PLYAs9lPxxVAErz0OZAAAAJc"]
[Tue Jul 21 07:51:25.652305 2026] [security2:error] [pid 296703:tid 296808] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/x.php"] [unique_id "al9PLSn25uliftkV1n4xAgAATmg"]
[Tue Jul 21 07:51:25.789099 2026] [security2:error] [pid 296703:tid 296952] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/shop/.env"] [unique_id "al9PLSn25uliftkV1n4xCAAAAHc"]
[Tue Jul 21 07:51:25.833830 2026] [security2:error] [pid 296703:tid 296772] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/jga.php"] [unique_id "al9PLSn25uliftkV1n4xCQAAE0Q"]
[Tue Jul 21 07:51:25.877762 2026] [security2:error] [pid 296703:tid 296933] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9PLSn25uliftkV1n4xCgAAAGQ"]
[Tue Jul 21 07:51:25.911710 2026] [security2:error] [pid 302018:tid 302173] [client 52.139.36.144:26080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/sys.php"] [unique_id "al9PLYAs9lPxxVAErz0OZwAAAJw"]
[Tue Jul 21 07:51:26.017127 2026] [security2:error] [pid 296703:tid 296769] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/k.php"] [unique_id "al9PLin25uliftkV1n4xDAAAK0E"]
[Tue Jul 21 07:51:26.045407 2026] [security2:error] [pid 302018:tid 302235] [client 128.127.105.184:33386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9PLoAs9lPxxVAErz0OaQAAANo"]
[Tue Jul 21 07:51:26.045483 2026] [security2:error] [pid 302018:tid 302235] [client 128.127.105.184:33386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9PLoAs9lPxxVAErz0OaQAAANo"]
[Tue Jul 21 07:51:26.051504 2026] [security2:error] [pid 302018:tid 302044] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PLoAs9lPxxVAErz0OagAAyhc"]
[Tue Jul 21 07:51:26.051650 2026] [security2:error] [pid 302018:tid 302219] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PLoAs9lPxxVAErz0OagAAyhc"]
[Tue Jul 21 07:51:26.064840 2026] [security2:error] [pid 302018:tid 302271] [client 20.197.192.193:27078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/zzz.php"] [unique_id "al9PLoAs9lPxxVAErz0OawAAAP4"]
[Tue Jul 21 07:51:26.139247 2026] [security2:error] [pid 296703:tid 296842] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/store/.env"] [unique_id "al9PLin25uliftkV1n4xDgAAAAk"]
[Tue Jul 21 07:51:26.160838 2026] [security2:error] [pid 296703:tid 296840] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9PLin25uliftkV1n4xEgAAAAc"]
[Tue Jul 21 07:51:26.233464 2026] [security2:error] [pid 296703:tid 296743] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/vx.php"] [unique_id "al9PLin25uliftkV1n4xFAAAKCc"]
[Tue Jul 21 07:51:26.325164 2026] [security2:error] [pid 302018:tid 302191] [client 20.104.96.117:59733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9PLoAs9lPxxVAErz0OcAAAAK4"]
[Tue Jul 21 07:51:26.444121 2026] [security2:error] [pid 302018:tid 302200] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9PLoAs9lPxxVAErz0OcQAAALc"]
[Tue Jul 21 07:51:26.444937 2026] [security2:error] [pid 296703:tid 296794] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ws77.php"] [unique_id "al9PLin25uliftkV1n4xGgAAaFo"]
[Tue Jul 21 07:51:26.489366 2026] [security2:error] [pid 296703:tid 296919] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/saas/.env"] [unique_id "al9PLin25uliftkV1n4xGwAAAFY"]
[Tue Jul 21 07:51:26.524588 2026] [security2:error] [pid 296703:tid 296841] [client 136.144.33.111:25173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PLin25uliftkV1n4xHAAAAAg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:26.539550 2026] [security2:error] [pid 296703:tid 296946] [client 182.8.255.181:10166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PLin25uliftkV1n4xHgAAAHE"]
[Tue Jul 21 07:51:26.539665 2026] [security2:error] [pid 296703:tid 296946] [client 182.8.255.181:10166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PLin25uliftkV1n4xHgAAAHE"]
[Tue Jul 21 07:51:26.593643 2026] [security2:error] [pid 302018:tid 302264] [client 103.166.103.129:50844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PLoAs9lPxxVAErz0OcwAAAPc"]
[Tue Jul 21 07:51:26.593745 2026] [security2:error] [pid 302018:tid 302264] [client 103.166.103.129:50844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PLoAs9lPxxVAErz0OcwAAAPc"]
[Tue Jul 21 07:51:26.623252 2026] [security2:error] [pid 296703:tid 296770] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/2.php"] [unique_id "al9PLin25uliftkV1n4xIAAAQEI"]
[Tue Jul 21 07:51:26.696958 2026] [security2:error] [pid 296703:tid 296889] [client 52.139.36.144:1254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/la.php"] [unique_id "al9PLin25uliftkV1n4xIwAAADg"]
[Tue Jul 21 07:51:26.727370 2026] [security2:error] [pid 302018:tid 302244] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9PLoAs9lPxxVAErz0OdwAAAOM"]
[Tue Jul 21 07:51:26.739951 2026] [security2:error] [pid 302018:tid 302197] [client 194.99.104.35:39516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PLoAs9lPxxVAErz0OeAAAALQ"]
[Tue Jul 21 07:51:26.740024 2026] [security2:error] [pid 302018:tid 302197] [client 194.99.104.35:39516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PLoAs9lPxxVAErz0OeAAAALQ"]
[Tue Jul 21 07:51:26.820912 2026] [security2:error] [pid 296703:tid 296756] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/asd.php"] [unique_id "al9PLin25uliftkV1n4xJAAAYzQ"]
[Tue Jul 21 07:51:26.835356 2026] [security2:error] [pid 302018:tid 302215] [client 20.220.225.223:52176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/ez.php"] [unique_id "al9PLoAs9lPxxVAErz0OfAAAAMY"]
[Tue Jul 21 07:51:26.838924 2026] [security2:error] [pid 296703:tid 296882] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/client/.env"] [unique_id "al9PLin25uliftkV1n4xJgAAADE"]
[Tue Jul 21 07:51:26.874096 2026] [security2:error] [pid 302018:tid 302223] [client 20.197.192.193:27136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/wicked.php"] [unique_id "al9PLoAs9lPxxVAErz0OfwAAAM4"]
[Tue Jul 21 07:51:26.998700 2026] [security2:error] [pid 296703:tid 296826] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/default.php"] [unique_id "al9PLin25uliftkV1n4xLAAAdHo"]
[Tue Jul 21 07:51:27.011506 2026] [security2:error] [pid 302018:tid 302178] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9PL4As9lPxxVAErz0OgwAAAKE"]
[Tue Jul 21 07:51:27.068587 2026] [security2:error] [pid 302018:tid 302213] [client 223.236.153.128:5503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PL4As9lPxxVAErz0OhAAAAMQ"]
[Tue Jul 21 07:51:27.081217 2026] [security2:error] [pid 302018:tid 302213] [client 223.236.153.128:5503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PL4As9lPxxVAErz0OhAAAAMQ"]
[Tue Jul 21 07:51:27.177526 2026] [security2:error] [pid 296703:tid 296774] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/gettest.php"] [unique_id "al9PLyn25uliftkV1n4xLgAAckY"]
[Tue Jul 21 07:51:27.190398 2026] [security2:error] [pid 296703:tid 296844] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/project/.env"] [unique_id "al9PLyn25uliftkV1n4xLwAAAAs"]
[Tue Jul 21 07:51:27.290926 2026] [security2:error] [pid 302018:tid 302086] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PL4As9lPxxVAErz0OiQAA0UE"]
[Tue Jul 21 07:51:27.291065 2026] [security2:error] [pid 302018:tid 302226] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PL4As9lPxxVAErz0OiQAA0UE"]
[Tue Jul 21 07:51:27.298178 2026] [security2:error] [pid 296703:tid 296886] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9PLyn25uliftkV1n4xMgAAADU"]
[Tue Jul 21 07:51:27.369184 2026] [security2:error] [pid 296703:tid 296869] [client 52.139.36.144:1267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/tires.php"] [unique_id "al9PLyn25uliftkV1n4xNwAAACQ"]
[Tue Jul 21 07:51:27.370871 2026] [security2:error] [pid 296703:tid 296804] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/tfm.php"] [unique_id "al9PLyn25uliftkV1n4xOAAANmQ"]
[Tue Jul 21 07:51:27.541986 2026] [security2:error] [pid 296703:tid 296867] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/admin-panel/.env"] [unique_id "al9PLyn25uliftkV1n4xPQAAACI"]
[Tue Jul 21 07:51:27.571468 2026] [security2:error] [pid 296703:tid 296815] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ws81.php"] [unique_id "al9PLyn25uliftkV1n4xQAAADm8"]
[Tue Jul 21 07:51:27.582489 2026] [security2:error] [pid 296703:tid 296911] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.kaiodasilvapenhagil1782856930060.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9PLyn25uliftkV1n4xQQAAAE4"]
[Tue Jul 21 07:51:27.758236 2026] [security2:error] [pid 296703:tid 296735] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/222.php"] [unique_id "al9PLyn25uliftkV1n4xRgAASx8"]
[Tue Jul 21 07:51:27.796081 2026] [security2:error] [pid 302018:tid 302217] [client 20.104.96.117:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/classwithtostring.php"] [unique_id "al9PL4As9lPxxVAErz0OlQAAAMg"]
[Tue Jul 21 07:51:27.892331 2026] [security2:error] [pid 296703:tid 296885] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/control-panel/.env"] [unique_id "al9PLyn25uliftkV1n4xRwAAADQ"]
[Tue Jul 21 07:51:27.965752 2026] [security2:error] [pid 302018:tid 302238] [client 52.139.36.144:26064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/lv.php"] [unique_id "al9PL4As9lPxxVAErz0OmAAAAN0"]
[Tue Jul 21 07:51:28.100185 2026] [security2:error] [pid 296703:tid 296817] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/t.php"] [unique_id "al9PMCn25uliftkV1n4xSgAACXE"]
[Tue Jul 21 07:51:28.225889 2026] [security2:error] [pid 302018:tid 302237] [client 103.86.117.203:65328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PMIAs9lPxxVAErz0OnAAAANw"]
[Tue Jul 21 07:51:28.226040 2026] [security2:error] [pid 302018:tid 302237] [client 103.86.117.203:65328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PMIAs9lPxxVAErz0OnAAAANw"]
[Tue Jul 21 07:51:28.243364 2026] [security2:error] [pid 296703:tid 296935] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/user-panel/.env"] [unique_id "al9PMCn25uliftkV1n4xTgAAAGY"]
[Tue Jul 21 07:51:28.288260 2026] [security2:error] [pid 296703:tid 296759] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/a.php"] [unique_id "al9PMCn25uliftkV1n4xUAAAGjc"]
[Tue Jul 21 07:51:28.418241 2026] [security2:error] [pid 302018:tid 302186] [client 20.197.192.193:8383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/wp-mt.php"] [unique_id "al9PMIAs9lPxxVAErz0OowAAAKk"]
[Tue Jul 21 07:51:28.426734 2026] [security2:error] [pid 302018:tid 302166] [client 52.139.36.144:33148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/myfile.php"] [unique_id "al9PMIAs9lPxxVAErz0OpAAAAJU"]
[Tue Jul 21 07:51:28.467876 2026] [security2:error] [pid 296703:tid 296742] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/a1.php"] [unique_id "al9PMCn25uliftkV1n4xUwAAYCY"]
[Tue Jul 21 07:51:28.594409 2026] [security2:error] [pid 296703:tid 296864] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/node/.env"] [unique_id "al9PMCn25uliftkV1n4xVgAAAB8"]
[Tue Jul 21 07:51:28.595605 2026] [security2:error] [pid 302018:tid 302207] [client 59.96.220.140:51097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9PMIAs9lPxxVAErz0OpgAAAL4"]
[Tue Jul 21 07:51:28.595980 2026] [security2:error] [pid 302018:tid 302207] [client 59.96.220.140:51097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9PMIAs9lPxxVAErz0OpgAAAL4"]
[Tue Jul 21 07:51:28.611375 2026] [security2:error] [pid 302018:tid 302167] [client 20.197.192.193:8359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/ww.php"] [unique_id "al9PMIAs9lPxxVAErz0OpwAAAJY"]
[Tue Jul 21 07:51:28.646747 2026] [security2:error] [pid 296703:tid 296762] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/w.php"] [unique_id "al9PMCn25uliftkV1n4xVwAATzo"]
[Tue Jul 21 07:51:28.726228 2026] [security2:error] [pid 302018:tid 302164] [client 20.197.192.193:27177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/edit.php"] [unique_id "al9PMIAs9lPxxVAErz0OqAAAAJM"]
[Tue Jul 21 07:51:28.832684 2026] [security2:error] [pid 296703:tid 296892] [client 52.139.36.144:1186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/06.php"] [unique_id "al9PMCn25uliftkV1n4xXQAAADs"]
[Tue Jul 21 07:51:28.877524 2026] [security2:error] [pid 302018:tid 302048] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PMIAs9lPxxVAErz0OqQAAihs"]
[Tue Jul 21 07:51:28.877727 2026] [security2:error] [pid 302018:tid 302155] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PMIAs9lPxxVAErz0OqQAAihs"]
[Tue Jul 21 07:51:28.943918 2026] [security2:error] [pid 296703:tid 296833] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/express/.env"] [unique_id "al9PMCn25uliftkV1n4xXwAAAAA"]
[Tue Jul 21 07:51:28.970244 2026] [security2:error] [pid 296703:tid 296827] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp-good.php"] [unique_id "al9PMCn25uliftkV1n4xYQAAQHs"]
[Tue Jul 21 07:51:29.003948 2026] [autoindex:error] [pid 302018:tid 302241] [client 185.193.167.42:23399] AH01276: Cannot serve directory /home3/sabri472/evolvaa.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:51:29.072631 2026] [security2:error] [pid 296703:tid 296924] [client 103.147.32.194:58335] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "albuquerqueeharo.com"] [uri "/"] [unique_id "al9PMSn25uliftkV1n4xYgAAAFs"]
[Tue Jul 21 07:51:29.209571 2026] [security2:error] [pid 296703:tid 296740] [remote 74.249.245.134:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "luminabeauty.com.br"] [uri "/.info.php"] [unique_id "al9PMSn25uliftkV1n4xYwAAayQ"]
[Tue Jul 21 07:51:29.273056 2026] [security2:error] [pid 302018:tid 302243] [client 194.99.104.35:45416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PMYAs9lPxxVAErz0OrQAAAOI"]
[Tue Jul 21 07:51:29.273165 2026] [security2:error] [pid 302018:tid 302243] [client 194.99.104.35:45416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PMYAs9lPxxVAErz0OrQAAAOI"]
[Tue Jul 21 07:51:29.283900 2026] [security2:error] [pid 296703:tid 296904] [client 52.139.36.144:1266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/fs.php"] [unique_id "al9PMSn25uliftkV1n4xZAAAAEc"]
[Tue Jul 21 07:51:29.293034 2026] [security2:error] [pid 296703:tid 296900] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/next/.env"] [unique_id "al9PMSn25uliftkV1n4xZgAAAEM"]
[Tue Jul 21 07:51:29.332954 2026] [security2:error] [pid 296703:tid 296882] [client 20.104.96.117:64341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/root.php"] [unique_id "al9PMSn25uliftkV1n4xaAAAADE"]
[Tue Jul 21 07:51:29.397955 2026] [security2:error] [pid 296703:tid 296788] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/item.php"] [unique_id "al9PMSn25uliftkV1n4xagAALlQ"]
[Tue Jul 21 07:51:29.444730 2026] [security2:error] [pid 296703:tid 296916] [client 122.186.204.214:50844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PMSn25uliftkV1n4xbAAAAFM"]
[Tue Jul 21 07:51:29.444864 2026] [security2:error] [pid 296703:tid 296916] [client 122.186.204.214:50844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PMSn25uliftkV1n4xbAAAAFM"]
[Tue Jul 21 07:51:29.517880 2026] [security2:error] [pid 296703:tid 296931] [client 178.153.91.96:57320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PMSn25uliftkV1n4xbQAAAGI"]
[Tue Jul 21 07:51:29.518039 2026] [security2:error] [pid 296703:tid 296931] [client 178.153.91.96:57320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PMSn25uliftkV1n4xbQAAAGI"]
[Tue Jul 21 07:51:29.556629 2026] [security2:error] [pid 302018:tid 302190] [client 109.60.28.94:28375] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PMYAs9lPxxVAErz0OtAAAAK0"]
[Tue Jul 21 07:51:29.556762 2026] [security2:error] [pid 302018:tid 302190] [client 109.60.28.94:28375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PMYAs9lPxxVAErz0OtAAAAK0"]
[Tue Jul 21 07:51:29.587512 2026] [security2:error] [pid 296703:tid 296775] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/albin.php"] [unique_id "al9PMSn25uliftkV1n4xcgAAOkc"]
[Tue Jul 21 07:51:29.643284 2026] [security2:error] [pid 296703:tid 296942] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/nuxt/.env"] [unique_id "al9PMSn25uliftkV1n4xdAAAAG0"]
[Tue Jul 21 07:51:29.712983 2026] [security2:error] [pid 302018:tid 302265] [client 52.139.36.144:1218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/asasx.php"] [unique_id "al9PMYAs9lPxxVAErz0OtgAAAPg"]
[Tue Jul 21 07:51:29.777747 2026] [security2:error] [pid 296703:tid 296814] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/alfa.php"] [unique_id "al9PMSn25uliftkV1n4xdQAAAm4"]
[Tue Jul 21 07:51:29.830479 2026] [security2:error] [pid 296703:tid 296857] [client 20.220.225.223:23463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/fz.php"] [unique_id "al9PMSn25uliftkV1n4xeQAAABg"]
[Tue Jul 21 07:51:29.922731 2026] [security2:error] [pid 296703:tid 296872] [client 139.167.225.182:50234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PMSn25uliftkV1n4xewAAACc"]
[Tue Jul 21 07:51:29.922867 2026] [security2:error] [pid 296703:tid 296872] [client 139.167.225.182:50234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PMSn25uliftkV1n4xewAAACc"]
[Tue Jul 21 07:51:29.924921 2026] [security2:error] [pid 296703:tid 296928] [client 20.197.192.193:8328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/cron.php"] [unique_id "al9PMSn25uliftkV1n4xfAAAAF8"]
[Tue Jul 21 07:51:29.945076 2026] [security2:error] [pid 302018:tid 302173] [client 173.24.185.52:63512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PMYAs9lPxxVAErz0O9AAAAJw"]
[Tue Jul 21 07:51:29.945162 2026] [security2:error] [pid 302018:tid 302173] [client 173.24.185.52:63512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PMYAs9lPxxVAErz0O9AAAAJw"]
[Tue Jul 21 07:51:29.955550 2026] [security2:error] [pid 296703:tid 296711] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9PMSn25uliftkV1n4xfQAAWQc"]
[Tue Jul 21 07:51:29.993551 2026] [security2:error] [pid 296703:tid 296941] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/nest/.env"] [unique_id "al9PMSn25uliftkV1n4xfgAAAGw"]
[Tue Jul 21 07:51:30.128968 2026] [security2:error] [pid 302018:tid 302157] [client 45.227.253.15:39244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.253.227.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perfex.bavos.com.br"] [uri "/index.php/jk"] [unique_id "al9PMoAs9lPxxVAErz0O_wAAAIw"]
[Tue Jul 21 07:51:30.166768 2026] [security2:error] [pid 296703:tid 296744] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/av.php"] [unique_id "al9PMin25uliftkV1n4xggAAIyg"]
[Tue Jul 21 07:51:30.257477 2026] [security2:error] [pid 302018:tid 302275] [client 117.247.80.59:26587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PMoAs9lPxxVAErz0PFgAAAQI"]
[Tue Jul 21 07:51:30.257577 2026] [security2:error] [pid 302018:tid 302275] [client 117.247.80.59:26587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PMoAs9lPxxVAErz0PFgAAAQI"]
[Tue Jul 21 07:51:30.288200 2026] [security2:error] [pid 302018:tid 302241] [client 52.139.36.144:1188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-kd4xalrg7m.php"] [unique_id "al9PMoAs9lPxxVAErz0PFwAAAOA"]
[Tue Jul 21 07:51:30.343791 2026] [security2:error] [pid 296703:tid 296888] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/react/.env"] [unique_id "al9PMin25uliftkV1n4xiwAAADc"]
[Tue Jul 21 07:51:30.421303 2026] [security2:error] [pid 296703:tid 296728] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/gg.php"] [unique_id "al9PMin25uliftkV1n4xkgAAZhg"]
[Tue Jul 21 07:51:30.440999 2026] [security2:error] [pid 296703:tid 296884] [client 103.147.32.194:58544] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "albuquerqueeharo.com"] [uri "/wp-json/batch/v1"] [unique_id "al9PMin25uliftkV1n4xkwAAADM"]
[Tue Jul 21 07:51:30.600698 2026] [security2:error] [pid 296703:tid 296799] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/sql.php"] [unique_id "al9PMin25uliftkV1n4xmAAAKF8"]
[Tue Jul 21 07:51:30.693272 2026] [security2:error] [pid 296703:tid 296839] [client 193.36.225.65:22307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PMin25uliftkV1n4xlAAAAAY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:30.693536 2026] [security2:error] [pid 296703:tid 296917] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/vue/.env"] [unique_id "al9PMin25uliftkV1n4xmQAAAFQ"]
[Tue Jul 21 07:51:30.767896 2026] [security2:error] [pid 302018:tid 302262] [client 74.249.245.134:8795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ws38.php"] [unique_id "al9PMoAs9lPxxVAErz0PQQAAAPU"]
[Tue Jul 21 07:51:30.779009 2026] [security2:error] [pid 296703:tid 296777] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/up.php"] [unique_id "al9PMin25uliftkV1n4xnAAACkk"]
[Tue Jul 21 07:51:30.854049 2026] [security2:error] [pid 296703:tid 296915] [client 52.139.36.144:33095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-good.php"] [unique_id "al9PMin25uliftkV1n4xngAAAFI"]
[Tue Jul 21 07:51:30.897760 2026] [security2:error] [pid 302018:tid 302260] [client 103.29.114.44:57105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PMoAs9lPxxVAErz0PTwAAAPM"]
[Tue Jul 21 07:51:30.897903 2026] [security2:error] [pid 302018:tid 302260] [client 103.29.114.44:57105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PMoAs9lPxxVAErz0PTwAAAPM"]
[Tue Jul 21 07:51:30.946708 2026] [security2:error] [pid 302018:tid 302194] [client 20.197.192.193:27081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/kua.php"] [unique_id "al9PMoAs9lPxxVAErz0PUAAAALE"]
[Tue Jul 21 07:51:31.044491 2026] [security2:error] [pid 296703:tid 296875] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/angular/.env"] [unique_id "al9PMyn25uliftkV1n4xoQAAACo"]
[Tue Jul 21 07:51:31.057403 2026] [security2:error] [pid 296703:tid 296841] [client 20.104.96.117:64256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/sym403.php"] [unique_id "al9PMyn25uliftkV1n4xpAAAAAg"]
[Tue Jul 21 07:51:31.195584 2026] [security2:error] [pid 296703:tid 296854] [client 117.217.38.194:59209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PMyn25uliftkV1n4xpQAAABU"]
[Tue Jul 21 07:51:31.195710 2026] [security2:error] [pid 296703:tid 296854] [client 117.217.38.194:59209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PMyn25uliftkV1n4xpQAAABU"]
[Tue Jul 21 07:51:31.268445 2026] [security2:error] [pid 296703:tid 296920] [client 52.139.36.144:33077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/scxy.php"] [unique_id "al9PMyn25uliftkV1n4xpwAAAFc"]
[Tue Jul 21 07:51:31.277284 2026] [security2:error] [pid 302018:tid 302131] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PM4As9lPxxVAErz0PUgAAm24"]
[Tue Jul 21 07:51:31.277416 2026] [security2:error] [pid 302018:tid 302172] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PM4As9lPxxVAErz0PUgAAm24"]
[Tue Jul 21 07:51:31.296970 2026] [security2:error] [pid 296703:tid 296906] [client 74.249.245.134:24823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/pomo.php"] [unique_id "al9PMyn25uliftkV1n4xqAAAAEk"]
[Tue Jul 21 07:51:31.340520 2026] [security2:error] [pid 296703:tid 296900] [client 194.99.104.35:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9PMyn25uliftkV1n4xqgAAAEM"]
[Tue Jul 21 07:51:31.340666 2026] [security2:error] [pid 296703:tid 296900] [client 194.99.104.35:45426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9PMyn25uliftkV1n4xqgAAAEM"]
[Tue Jul 21 07:51:31.394546 2026] [security2:error] [pid 296703:tid 296948] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/svelte/.env"] [unique_id "al9PMyn25uliftkV1n4xqwAAAHM"]
[Tue Jul 21 07:51:31.409553 2026] [security2:error] [pid 296703:tid 296715] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/66.php"] [unique_id "al9PMyn25uliftkV1n4xrgAALgs"]
[Tue Jul 21 07:51:31.586788 2026] [security2:error] [pid 296703:tid 296753] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/666.php"] [unique_id "al9PMyn25uliftkV1n4xtgAAGzE"]
[Tue Jul 21 07:51:31.720051 2026] [security2:error] [pid 296703:tid 296939] [client 185.213.175.37:12460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "asholdings.com.br"] [uri "/logo.png"] [unique_id "al9PMyn25uliftkV1n4xtwAAAGo"]
[Tue Jul 21 07:51:31.720150 2026] [security2:error] [pid 296703:tid 296939] [client 185.213.175.37:12460] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "asholdings.com.br"] [uri "/logo.png"] [unique_id "al9PMyn25uliftkV1n4xtwAAAGo"]
[Tue Jul 21 07:51:31.745145 2026] [security2:error] [pid 296703:tid 296930] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/vite/.env"] [unique_id "al9PMyn25uliftkV1n4xuAAAAGE"]
[Tue Jul 21 07:51:31.768922 2026] [security2:error] [pid 302018:tid 302210] [client 185.213.175.37:12486] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "asholdings.com.br"] [uri "/script.js"] [unique_id "al9PM4As9lPxxVAErz0PaAAAAME"]
[Tue Jul 21 07:51:31.775637 2026] [security2:error] [pid 302018:tid 302230] [client 52.139.36.144:26161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wmore1.php"] [unique_id "al9PM4As9lPxxVAErz0PaQAAANU"]
[Tue Jul 21 07:51:31.917877 2026] [security2:error] [pid 302018:tid 302233] [client 122.179.91.63:3326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PM4As9lPxxVAErz0PcwAAANg"]
[Tue Jul 21 07:51:31.917973 2026] [security2:error] [pid 302018:tid 302233] [client 122.179.91.63:3326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PM4As9lPxxVAErz0PcwAAANg"]
[Tue Jul 21 07:51:31.955295 2026] [security2:error] [pid 296703:tid 296709] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/byp.php"] [unique_id "al9PMyn25uliftkV1n4xwQAAIgU"]
[Tue Jul 21 07:51:32.095372 2026] [security2:error] [pid 296703:tid 296901] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/backup/.env"] [unique_id "al9PNCn25uliftkV1n4xxgAAAEQ"]
[Tue Jul 21 07:51:32.146713 2026] [security2:error] [pid 296703:tid 296812] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/date.php"] [unique_id "al9PNCn25uliftkV1n4xyAAAS2w"]
[Tue Jul 21 07:51:32.349116 2026] [security2:error] [pid 296703:tid 296803] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/pomo.php"] [unique_id "al9PNCn25uliftkV1n4xyQAAWmM"]
[Tue Jul 21 07:51:32.446013 2026] [security2:error] [pid 296703:tid 296902] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/backups/.env"] [unique_id "al9PNCn25uliftkV1n4xzwAAAEU"]
[Tue Jul 21 07:51:32.497038 2026] [security2:error] [pid 302018:tid 302252] [client 185.213.175.37:30064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "asimd.ongsolution.com.br"] [uri "/css/style.css"] [unique_id "al9PNIAs9lPxxVAErz0PigAAAOs"]
[Tue Jul 21 07:51:32.497117 2026] [security2:error] [pid 302018:tid 302252] [client 185.213.175.37:30064] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "asimd.ongsolution.com.br"] [uri "/css/style.css"] [unique_id "al9PNIAs9lPxxVAErz0PigAAAOs"]
[Tue Jul 21 07:51:32.548724 2026] [security2:error] [pid 296703:tid 296933] [client 20.104.96.117:64325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/v543.php"] [unique_id "al9PNCn25uliftkV1n4x0AAAAGQ"]
[Tue Jul 21 07:51:32.651520 2026] [security2:error] [pid 302018:tid 302106] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PNIAs9lPxxVAErz0PjgAA_VU"]
[Tue Jul 21 07:51:32.651702 2026] [security2:error] [pid 302018:tid 302270] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PNIAs9lPxxVAErz0PjgAA_VU"]
[Tue Jul 21 07:51:32.709727 2026] [security2:error] [pid 302018:tid 302217] [client 52.139.36.144:33024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/like.php"] [unique_id "al9PNIAs9lPxxVAErz0PjwAAAMg"]
[Tue Jul 21 07:51:32.796863 2026] [security2:error] [pid 296703:tid 296935] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/old/.env"] [unique_id "al9PNCn25uliftkV1n4x1AAAAGY"]
[Tue Jul 21 07:51:32.819022 2026] [security2:error] [pid 296703:tid 296783] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/test1.php"] [unique_id "al9PNCn25uliftkV1n4x1QAAe08"]
[Tue Jul 21 07:51:33.002029 2026] [security2:error] [pid 296703:tid 296796] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/fw.php"] [unique_id "al9PNSn25uliftkV1n4x2gAAYFw"]
[Tue Jul 21 07:51:33.099375 2026] [security2:error] [pid 296703:tid 296758] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PNSn25uliftkV1n4x3AAAVDY"]
[Tue Jul 21 07:51:33.099512 2026] [security2:error] [pid 296703:tid 296917] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PNSn25uliftkV1n4x3AAAVDY"]
[Tue Jul 21 07:51:33.146504 2026] [security2:error] [pid 296703:tid 296896] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/tmp/.env"] [unique_id "al9PNSn25uliftkV1n4x3wAAAD8"]
[Tue Jul 21 07:51:33.237981 2026] [security2:error] [pid 302018:tid 302172] [client 20.197.192.193:27073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/ez.php"] [unique_id "al9PNYAs9lPxxVAErz0PowAAAJs"]
[Tue Jul 21 07:51:33.475485 2026] [security2:error] [pid 296703:tid 296730] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/fm.php"] [unique_id "al9PNSn25uliftkV1n4x5AAAIRo"]
[Tue Jul 21 07:51:33.496052 2026] [security2:error] [pid 296703:tid 296892] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/temp/.env"] [unique_id "al9PNSn25uliftkV1n4x5wAAADs"]
[Tue Jul 21 07:51:33.506009 2026] [security2:error] [pid 302018:tid 302040] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PNYAs9lPxxVAErz0PpAAA9xM"]
[Tue Jul 21 07:51:33.506167 2026] [security2:error] [pid 302018:tid 302264] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PNYAs9lPxxVAErz0PpAAA9xM"]
[Tue Jul 21 07:51:33.637317 2026] [security2:error] [pid 296703:tid 296940] [client 20.197.192.193:8366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/xxx.php"] [unique_id "al9PNSn25uliftkV1n4x7QAAAGs"]
[Tue Jul 21 07:51:33.653885 2026] [security2:error] [pid 296703:tid 296784] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/ini.php"] [unique_id "al9PNSn25uliftkV1n4x7gAALlA"]
[Tue Jul 21 07:51:33.689905 2026] [security2:error] [pid 302018:tid 302221] [client 106.215.181.8:12734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PNYAs9lPxxVAErz0PqgAAAMw"]
[Tue Jul 21 07:51:33.690028 2026] [security2:error] [pid 302018:tid 302221] [client 106.215.181.8:12734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PNYAs9lPxxVAErz0PqgAAAMw"]
[Tue Jul 21 07:51:33.780779 2026] [security2:error] [pid 302018:tid 302210] [client 20.104.96.117:59725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/sixxis.php"] [unique_id "al9PNYAs9lPxxVAErz0PrQAAAME"]
[Tue Jul 21 07:51:33.832967 2026] [security2:error] [pid 296703:tid 296746] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/themes.php"] [unique_id "al9PNSn25uliftkV1n4x8AAAMSo"]
[Tue Jul 21 07:51:33.846231 2026] [security2:error] [pid 296703:tid 296954] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/lab/.env"] [unique_id "al9PNSn25uliftkV1n4x8gAAAHk"]
[Tue Jul 21 07:51:34.023299 2026] [security2:error] [pid 296703:tid 296726] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/dropdown.php"] [unique_id "al9PNin25uliftkV1n4x9QAAABY"]
[Tue Jul 21 07:51:34.074501 2026] [security2:error] [pid 302018:tid 302173] [client 193.36.225.72:47233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PNoAs9lPxxVAErz0PtgAAAJw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:34.196688 2026] [security2:error] [pid 296703:tid 296916] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/cronlab/.env"] [unique_id "al9PNin25uliftkV1n4x9gAAAFM"]
[Tue Jul 21 07:51:34.318714 2026] [security2:error] [pid 296703:tid 296818] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/wp-links.php"] [unique_id "al9PNin25uliftkV1n4x-AAAOnI"]
[Tue Jul 21 07:51:34.509027 2026] [security2:error] [pid 296703:tid 296745] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmrlpc.php"] [unique_id "al9PNin25uliftkV1n4x-gAAcik"]
[Tue Jul 21 07:51:34.547141 2026] [security2:error] [pid 296703:tid 296949] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/cron/.env"] [unique_id "al9PNin25uliftkV1n4x_gAAAHQ"]
[Tue Jul 21 07:51:34.626763 2026] [security2:error] [pid 296703:tid 296939] [client 20.197.192.193:27195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/fz.php"] [unique_id "al9PNin25uliftkV1n4yAAAAAGo"]
[Tue Jul 21 07:51:34.780511 2026] [security2:error] [pid 296703:tid 296732] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/htaccess.php"] [unique_id "al9PNin25uliftkV1n4yAgAAdhw"]
[Tue Jul 21 07:51:34.864776 2026] [security2:error] [pid 302018:tid 302171] [client 20.104.96.117:64357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/ip.php"] [unique_id "al9PNoAs9lPxxVAErz0P7AAAAJo"]
[Tue Jul 21 07:51:34.897105 2026] [security2:error] [pid 296703:tid 296861] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/en/.env"] [unique_id "al9PNin25uliftkV1n4yBQAAABw"]
[Tue Jul 21 07:51:34.958015 2026] [security2:error] [pid 296703:tid 296789] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/readme.php"] [unique_id "al9PNin25uliftkV1n4yBgAAIlU"]
[Tue Jul 21 07:51:35.025297 2026] [security2:error] [pid 296703:tid 296941] [client 52.139.36.144:26175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/x.php"] [unique_id "al9PNyn25uliftkV1n4yDQAAAGw"]
[Tue Jul 21 07:51:35.046194 2026] [security2:error] [pid 302018:tid 302236] [client 122.164.127.47:52087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PN4As9lPxxVAErz0P9gAAANs"]
[Tue Jul 21 07:51:35.046363 2026] [security2:error] [pid 302018:tid 302236] [client 122.164.127.47:52087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PN4As9lPxxVAErz0P9gAAANs"]
[Tue Jul 21 07:51:35.049543 2026] [security2:error] [pid 302018:tid 302175] [client 128.127.105.184:42826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PN4As9lPxxVAErz0P9wAAAJ4"]
[Tue Jul 21 07:51:35.049655 2026] [security2:error] [pid 302018:tid 302175] [client 128.127.105.184:42826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PN4As9lPxxVAErz0P9wAAAJ4"]
[Tue Jul 21 07:51:35.137078 2026] [security2:error] [pid 296703:tid 296772] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/403.php"] [unique_id "al9PNyn25uliftkV1n4yDwAAaUQ"]
[Tue Jul 21 07:51:35.253067 2026] [security2:error] [pid 296703:tid 296923] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/administrator/.env"] [unique_id "al9PNyn25uliftkV1n4yEQAAAFo"]
[Tue Jul 21 07:51:35.435128 2026] [security2:error] [pid 296703:tid 296706] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/max.php"] [unique_id "al9PNyn25uliftkV1n4yFAAAegI"]
[Tue Jul 21 07:51:35.493490 2026] [security2:error] [pid 302018:tid 302207] [client 52.139.36.144:1263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/xa.php"] [unique_id "al9PN4As9lPxxVAErz0QAQAAAL4"]
[Tue Jul 21 07:51:35.603466 2026] [security2:error] [pid 296703:tid 296959] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/psnlink/.env"] [unique_id "al9PNyn25uliftkV1n4yGgAAAH4"]
[Tue Jul 21 07:51:35.613570 2026] [security2:error] [pid 296703:tid 296738] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/m.php"] [unique_id "al9PNyn25uliftkV1n4yGwAAZCI"]
[Tue Jul 21 07:51:35.769102 2026] [security2:error] [pid 302018:tid 302215] [client 74.249.245.134:64249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/a7.php"] [unique_id "al9PN4As9lPxxVAErz0QBgAAAMY"]
[Tue Jul 21 07:51:35.774077 2026] [security2:error] [pid 302018:tid 302167] [client 74.249.245.134:64113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/test1.php"] [unique_id "al9PN4As9lPxxVAErz0QBwAAAJY"]
[Tue Jul 21 07:51:35.792309 2026] [security2:error] [pid 296703:tid 296792] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/click.php"] [unique_id "al9PNyn25uliftkV1n4yHQAAK1g"]
[Tue Jul 21 07:51:35.816738 2026] [security2:error] [pid 296703:tid 296853] [client 41.68.90.219:64678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PNyn25uliftkV1n4yHgAAABQ"]
[Tue Jul 21 07:51:35.816887 2026] [security2:error] [pid 296703:tid 296853] [client 41.68.90.219:64678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PNyn25uliftkV1n4yHgAAABQ"]
[Tue Jul 21 07:51:35.907015 2026] [security2:error] [pid 302018:tid 302250] [client 20.197.192.193:27183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/la.php"] [unique_id "al9PN4As9lPxxVAErz0QCwAAAOk"]
[Tue Jul 21 07:51:35.953662 2026] [security2:error] [pid 296703:tid 296925] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/exapi/.env"] [unique_id "al9PNyn25uliftkV1n4yIAAAAFw"]
[Tue Jul 21 07:51:35.976054 2026] [security2:error] [pid 302018:tid 302267] [client 202.143.127.214:56618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PN4As9lPxxVAErz0QDAAAAPo"]
[Tue Jul 21 07:51:35.976194 2026] [security2:error] [pid 302018:tid 302267] [client 202.143.127.214:56618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PN4As9lPxxVAErz0QDAAAAPo"]
[Tue Jul 21 07:51:36.040255 2026] [security2:error] [pid 296703:tid 296795] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/lv.php"] [unique_id "al9POCn25uliftkV1n4yJQAAYFs"]
[Tue Jul 21 07:51:36.047495 2026] [security2:error] [pid 296703:tid 296859] [client 52.139.36.144:1158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/kolda.php"] [unique_id "al9POCn25uliftkV1n4yJgAAABo"]
[Tue Jul 21 07:51:36.220717 2026] [security2:error] [pid 296703:tid 296830] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/cong.php"] [unique_id "al9POCn25uliftkV1n4yKAAACn4"]
[Tue Jul 21 07:51:36.232896 2026] [security2:error] [pid 302018:tid 302263] [client 122.162.144.145:21136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9POIAs9lPxxVAErz0QDwAAAPY"]
[Tue Jul 21 07:51:36.233001 2026] [security2:error] [pid 302018:tid 302263] [client 122.162.144.145:21136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9POIAs9lPxxVAErz0QDwAAAPY"]
[Tue Jul 21 07:51:36.256115 2026] [security2:error] [pid 302018:tid 302109] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9POIAs9lPxxVAErz0QEAAA5Vg"]
[Tue Jul 21 07:51:36.256308 2026] [security2:error] [pid 302018:tid 302246] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9POIAs9lPxxVAErz0QEAAA5Vg"]
[Tue Jul 21 07:51:36.303481 2026] [security2:error] [pid 296703:tid 296926] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/sitemaps/.env"] [unique_id "al9POCn25uliftkV1n4yKgAAAF0"]
[Tue Jul 21 07:51:36.405555 2026] [security2:error] [pid 296703:tid 296826] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/brand.php"] [unique_id "al9POCn25uliftkV1n4yKwAABno"]
[Tue Jul 21 07:51:36.498285 2026] [security2:error] [pid 296703:tid 296919] [client 20.197.192.193:27163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/nhvoanpl.php"] [unique_id "al9POCn25uliftkV1n4yLgAAAFY"]
[Tue Jul 21 07:51:36.550490 2026] [security2:error] [pid 302018:tid 302198] [client 52.139.36.144:1185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-aothait.php"] [unique_id "al9POIAs9lPxxVAErz0QFQAAALU"]
[Tue Jul 21 07:51:36.559955 2026] [security2:error] [pid 296703:tid 296850] [client 20.104.96.117:59737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/kq1.php"] [unique_id "al9POCn25uliftkV1n4yMAAAABE"]
[Tue Jul 21 07:51:36.583407 2026] [security2:error] [pid 296703:tid 296707] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/atomlib.php"] [unique_id "al9POCn25uliftkV1n4yNAAAFQM"]
[Tue Jul 21 07:51:36.656541 2026] [security2:error] [pid 296703:tid 296894] [client 20.220.225.223:52189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/la.php"] [unique_id "al9POCn25uliftkV1n4yOgAAAD0"]
[Tue Jul 21 07:51:36.761660 2026] [security2:error] [pid 296703:tid 296721] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/0x.php"] [unique_id "al9POCn25uliftkV1n4yPAAAaxE"]
[Tue Jul 21 07:51:36.849951 2026] [security2:error] [pid 296703:tid 296960] [client 182.8.255.181:17334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9POCn25uliftkV1n4yQQAAAH8"]
[Tue Jul 21 07:51:36.850079 2026] [security2:error] [pid 296703:tid 296960] [client 182.8.255.181:17334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9POCn25uliftkV1n4yQQAAAH8"]
[Tue Jul 21 07:51:36.952216 2026] [security2:error] [pid 296703:tid 296880] [client 52.139.36.144:33117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/ftde.php"] [unique_id "al9POCn25uliftkV1n4yQwAAAC8"]
[Tue Jul 21 07:51:36.960037 2026] [security2:error] [pid 296703:tid 296781] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/buy.php"] [unique_id "al9POCn25uliftkV1n4yRAAATE0"]
[Tue Jul 21 07:51:37.003941 2026] [security2:error] [pid 302018:tid 311333] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9POYAs9lPxxVAErz0QHQAA0Yc"]
[Tue Jul 21 07:51:37.004075 2026] [security2:error] [pid 302018:tid 302226] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9POYAs9lPxxVAErz0QHQAA0Yc"]
[Tue Jul 21 07:51:37.153127 2026] [security2:error] [pid 296703:tid 296768] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/sx.php"] [unique_id "al9POSn25uliftkV1n4yTAAAZUA"]
[Tue Jul 21 07:51:37.305975 2026] [security2:error] [pid 302018:tid 302255] [client 20.220.225.223:35031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/billur.php"] [unique_id "al9POYAs9lPxxVAErz0QHgAAAO4"]
[Tue Jul 21 07:51:37.332680 2026] [security2:error] [pid 296703:tid 296831] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/article.php"] [unique_id "al9POSn25uliftkV1n4yTwAAX38"]
[Tue Jul 21 07:51:37.353392 2026] [security2:error] [pid 302018:tid 302235] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9POYAs9lPxxVAErz0QIAAAANo"]
[Tue Jul 21 07:51:37.358057 2026] [security2:error] [pid 296703:tid 296837] [client 54.251.12.30:45934] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/logs/.env"] [unique_id "al9POSn25uliftkV1n4yUAAAAAQ"]
[Tue Jul 21 07:51:37.473037 2026] [security2:error] [pid 302018:tid 302171] [client 184.75.223.211:41476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9POYAs9lPxxVAErz0QIwAAAJo"]
[Tue Jul 21 07:51:37.473144 2026] [security2:error] [pid 302018:tid 302171] [client 184.75.223.211:41476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9POYAs9lPxxVAErz0QIwAAAJo"]
[Tue Jul 21 07:51:37.476203 2026] [security2:error] [pid 302018:tid 302194] [client 185.251.19.78:54685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9PN4As9lPxxVAErz0QBAAAALE"]
[Tue Jul 21 07:51:37.476496 2026] [security2:error] [pid 302018:tid 302266] [client 45.132.227.208:24177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9PN4As9lPxxVAErz0QBQAAAPk"]
[Tue Jul 21 07:51:37.485950 2026] [security2:error] [pid 302018:tid 302165] [client 185.251.19.70:36953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9PN4As9lPxxVAErz0QAwAAAJQ"]
[Tue Jul 21 07:51:37.513658 2026] [security2:error] [pid 296703:tid 296813] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/bootstrap.php"] [unique_id "al9POSn25uliftkV1n4yUgAAdW0"]
[Tue Jul 21 07:51:37.518429 2026] [security2:error] [pid 296703:tid 296863] [client 103.166.103.129:35857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9POSn25uliftkV1n4yUwAAAB4"]
[Tue Jul 21 07:51:37.518524 2026] [security2:error] [pid 296703:tid 296863] [client 103.166.103.129:35857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9POSn25uliftkV1n4yUwAAAB4"]
[Tue Jul 21 07:51:37.584391 2026] [security2:error] [pid 296703:tid 296829] [remote 46.105.28.235:54416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9POCn25uliftkV1n4yMwAAA30"]
[Tue Jul 21 07:51:37.631627 2026] [security2:error] [pid 302018:tid 302259] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9POYAs9lPxxVAErz0QJAAAAPI"]
[Tue Jul 21 07:51:37.663635 2026] [security2:error] [pid 302018:tid 302254] [client 52.139.36.144:1268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/vx.php"] [unique_id "al9POYAs9lPxxVAErz0QKAAAAO0"]
[Tue Jul 21 07:51:37.700734 2026] [security2:error] [pid 296703:tid 296791] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/config-backup.php"] [unique_id "al9POSn25uliftkV1n4yVwAANlc"]
[Tue Jul 21 07:51:37.796496 2026] [security2:error] [pid 296703:tid 296916] [client 223.236.153.128:5484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9POSn25uliftkV1n4yWQAAAFM"]
[Tue Jul 21 07:51:37.796617 2026] [security2:error] [pid 296703:tid 296916] [client 223.236.153.128:5484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9POSn25uliftkV1n4yWQAAAFM"]
[Tue Jul 21 07:51:37.857673 2026] [security2:error] [pid 302018:tid 302057] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9POYAs9lPxxVAErz0QLQAAkSQ"]
[Tue Jul 21 07:51:37.857807 2026] [security2:error] [pid 302018:tid 302162] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9POYAs9lPxxVAErz0QLQAAkSQ"]
[Tue Jul 21 07:51:37.918195 2026] [security2:error] [pid 302018:tid 302264] [client 20.220.225.223:6094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9POYAs9lPxxVAErz0QLgAAAPc"]
[Tue Jul 21 07:51:37.960171 2026] [security2:error] [pid 302018:tid 302195] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9POYAs9lPxxVAErz0QLwAAALI"]
[Tue Jul 21 07:51:37.960329 2026] [security2:error] [pid 302018:tid 302221] [client 20.104.96.117:59722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9POYAs9lPxxVAErz0QMAAAAMw"]
[Tue Jul 21 07:51:38.163351 2026] [security2:error] [pid 302018:tid 302178] [client 52.139.36.144:1238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/a5.php"] [unique_id "al9POoAs9lPxxVAErz0QMgAAAKE"]
[Tue Jul 21 07:51:38.239124 2026] [security2:error] [pid 296703:tid 296955] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9POin25uliftkV1n4yXgAAAHo"]
[Tue Jul 21 07:51:38.318322 2026] [security2:error] [pid 296703:tid 296819] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/goods.php"] [unique_id "al9POin25uliftkV1n4yYAAANHM"]
[Tue Jul 21 07:51:38.442988 2026] [security2:error] [pid 296703:tid 296856] [client 136.144.33.101:56047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9POin25uliftkV1n4yYwAAABc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:38.574172 2026] [security2:error] [pid 296703:tid 296925] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9POin25uliftkV1n4yZQAAAFw"]
[Tue Jul 21 07:51:38.581209 2026] [security2:error] [pid 302018:tid 302173] [client 20.197.192.193:27083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/inso.php"] [unique_id "al9POoAs9lPxxVAErz0QNwAAAJw"]
[Tue Jul 21 07:51:38.686969 2026] [security2:error] [pid 302018:tid 302240] [client 52.139.36.144:1191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-sing.php"] [unique_id "al9POoAs9lPxxVAErz0QOgAAAN8"]
[Tue Jul 21 07:51:38.717296 2026] [security2:error] [pid 296703:tid 296936] [client 103.86.117.203:49492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9POin25uliftkV1n4yZwAAAGc"]
[Tue Jul 21 07:51:38.717454 2026] [security2:error] [pid 296703:tid 296936] [client 103.86.117.203:49492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9POin25uliftkV1n4yZwAAAGc"]
[Tue Jul 21 07:51:38.754297 2026] [security2:error] [pid 296703:tid 296959] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/cache/.env"] [unique_id "al9POin25uliftkV1n4yaQAAAH4"]
[Tue Jul 21 07:51:38.891631 2026] [security2:error] [pid 296703:tid 296814] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/init.php"] [unique_id "al9POin25uliftkV1n4ybAAAGm4"]
[Tue Jul 21 07:51:38.938399 2026] [proxy:error] [pid 302018:tid 302187] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:51:38.938480 2026] [proxy_http:error] [pid 302018:tid 302187] [client 64.23.171.245:60512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:51:38.939055 2026] [proxy:error] [pid 302018:tid 302187] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:51:38.939082 2026] [proxy_http:error] [pid 302018:tid 302187] [client 64.23.171.245:60512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:51:39.051916 2026] [security2:error] [pid 302018:tid 302261] [client 20.104.96.117:64370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/h02ugyh.php"] [unique_id "al9PO4As9lPxxVAErz0QPwAAAPQ"]
[Tue Jul 21 07:51:39.103514 2026] [security2:error] [pid 296703:tid 296843] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/mailer/.env"] [unique_id "al9POyn25uliftkV1n4ybwAAAAo"]
[Tue Jul 21 07:51:39.137048 2026] [security2:error] [pid 302018:tid 302212] [client 20.197.192.193:9443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/hunter.php"] [unique_id "al9PO4As9lPxxVAErz0QQAAAAMM"]
[Tue Jul 21 07:51:39.164293 2026] [security2:error] [pid 302018:tid 302177] [client 52.139.36.144:28692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/database.php"] [unique_id "al9PO4As9lPxxVAErz0QQQAAAKA"]
[Tue Jul 21 07:51:39.264523 2026] [security2:error] [pid 302018:tid 302276] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9PO4As9lPxxVAErz0QRwAAAQM"]
[Tue Jul 21 07:51:39.284477 2026] [authz_core:error] [pid 296703:tid 296767] [remote 74.249.245.134:0] AH01630: client denied by server configuration: /home1/deesmo24/luminabeauty.com.br/php.ini
[Tue Jul 21 07:51:39.315349 2026] [proxy:error] [pid 296703:tid 296919] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:51:39.315439 2026] [proxy_http:error] [pid 296703:tid 296919] [client 64.23.171.245:60526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.despensanatural.com.br/
[Tue Jul 21 07:51:39.316397 2026] [proxy:error] [pid 296703:tid 296919] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:51:39.316447 2026] [proxy_http:error] [pid 296703:tid 296919] [client 64.23.171.245:60526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.despensanatural.com.br/
[Tue Jul 21 07:51:39.452979 2026] [security2:error] [pid 296703:tid 296946] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/mail/.env"] [unique_id "al9POyn25uliftkV1n4ydgAAAHE"]
[Tue Jul 21 07:51:39.462151 2026] [core:error] [pid 296703:tid 296736] [remote 52.167.144.184:62104] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:51:39.462181 2026] [core:error] [pid 296703:tid 296736] [remote 52.167.144.184:62104] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:51:39.475643 2026] [security2:error] [pid 296703:tid 296816] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/settings.php"] [unique_id "al9POyn25uliftkV1n4yeAAAQHA"]
[Tue Jul 21 07:51:39.519242 2026] [security2:error] [pid 302018:tid 302209] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9PO4As9lPxxVAErz0QSgAAAMA"]
[Tue Jul 21 07:51:39.522886 2026] [security2:error] [pid 302018:tid 302262] [client 20.104.96.117:59759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-temp.php"] [unique_id "al9PO4As9lPxxVAErz0QSwAAAPU"]
[Tue Jul 21 07:51:39.680948 2026] [security2:error] [pid 296703:tid 296821] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/g.php"] [unique_id "al9POyn25uliftkV1n4yewAAIXU"]
[Tue Jul 21 07:51:39.778057 2026] [security2:error] [pid 296703:tid 296731] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9POyn25uliftkV1n4yfgAAJRs"]
[Tue Jul 21 07:51:39.778220 2026] [security2:error] [pid 296703:tid 296870] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9POyn25uliftkV1n4yfgAAJRs"]
[Tue Jul 21 07:51:39.789761 2026] [security2:error] [pid 302018:tid 302165] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9PO4As9lPxxVAErz0QTQAAAJQ"]
[Tue Jul 21 07:51:39.801205 2026] [security2:error] [pid 296703:tid 296909] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/email/.env"] [unique_id "al9POyn25uliftkV1n4ygAAAAEw"]
[Tue Jul 21 07:51:39.822605 2026] [security2:error] [pid 302018:tid 302159] [client 52.139.36.144:1183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/explorer/index_.php"] [unique_id "al9PO4As9lPxxVAErz0QTwAAAI4"]
[Tue Jul 21 07:51:39.860356 2026] [security2:error] [pid 296703:tid 296757] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/403.php"] [unique_id "al9POyn25uliftkV1n4yggAAQjU"]
[Tue Jul 21 07:51:40.007276 2026] [security2:error] [pid 302018:tid 302157] [client 20.104.96.117:60724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9PPIAs9lPxxVAErz0QUwAAAIw"]
[Tue Jul 21 07:51:40.037013 2026] [proxy:error] [pid 302018:tid 302191] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:51:40.037046 2026] [proxy_http:error] [pid 302018:tid 302191] [client 64.23.171.245:59244] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:51:40.037479 2026] [proxy:error] [pid 302018:tid 302191] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:51:40.037498 2026] [proxy_http:error] [pid 302018:tid 302191] [client 64.23.171.245:59244] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:51:40.060158 2026] [security2:error] [pid 296703:tid 296802] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/api.php"] [unique_id "al9PPCn25uliftkV1n4yhwAAG2I"]
[Tue Jul 21 07:51:40.067190 2026] [security2:error] [pid 296703:tid 296845] [client 20.220.225.223:35030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/mimpi.php"] [unique_id "al9PPCn25uliftkV1n4yiAAAAAw"]
[Tue Jul 21 07:51:40.115327 2026] [security2:error] [pid 302018:tid 302188] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9PPIAs9lPxxVAErz0QWAAAAKs"]
[Tue Jul 21 07:51:40.116044 2026] [security2:error] [pid 302018:tid 302217] [client 178.153.91.96:38813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PPIAs9lPxxVAErz0QWQAAAMg"]
[Tue Jul 21 07:51:40.116164 2026] [security2:error] [pid 302018:tid 302217] [client 178.153.91.96:38813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PPIAs9lPxxVAErz0QWQAAAMg"]
[Tue Jul 21 07:51:40.150110 2026] [security2:error] [pid 296703:tid 296934] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/smtp/.env"] [unique_id "al9PPCn25uliftkV1n4yiQAAAGU"]
[Tue Jul 21 07:51:40.171592 2026] [security2:error] [pid 296703:tid 296924] [client 122.186.204.214:51384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PPCn25uliftkV1n4yjAAAAFs"]
[Tue Jul 21 07:51:40.171715 2026] [security2:error] [pid 296703:tid 296924] [client 122.186.204.214:51384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PPCn25uliftkV1n4yjAAAAFs"]
[Tue Jul 21 07:51:40.214749 2026] [security2:error] [pid 296703:tid 296879] [client 109.60.28.94:28811] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PPCn25uliftkV1n4yjQAAAC4"]
[Tue Jul 21 07:51:40.214911 2026] [security2:error] [pid 296703:tid 296879] [client 109.60.28.94:28811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PPCn25uliftkV1n4yjQAAAC4"]
[Tue Jul 21 07:51:40.303581 2026] [security2:error] [pid 296703:tid 296894] [client 59.96.220.140:51640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9PPCn25uliftkV1n4ykwAAAD0"]
[Tue Jul 21 07:51:40.304224 2026] [security2:error] [pid 296703:tid 296894] [client 59.96.220.140:51640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9PPCn25uliftkV1n4ykwAAAD0"]
[Tue Jul 21 07:51:40.355615 2026] [security2:error] [pid 296703:tid 296922] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9PPCn25uliftkV1n4ymQAAAFk"]
[Tue Jul 21 07:51:40.364591 2026] [security2:error] [pid 302018:tid 302193] [client 139.167.225.182:50887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PPIAs9lPxxVAErz0QWgAAALA"]
[Tue Jul 21 07:51:40.364690 2026] [security2:error] [pid 302018:tid 302193] [client 139.167.225.182:50887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PPIAs9lPxxVAErz0QWgAAALA"]
[Tue Jul 21 07:51:40.380930 2026] [security2:error] [pid 296703:tid 296887] [client 52.139.36.144:26049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-at.php"] [unique_id "al9PPCn25uliftkV1n4ymwAAADY"]
[Tue Jul 21 07:51:40.500134 2026] [security2:error] [pid 296703:tid 296938] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/mailing/.env"] [unique_id "al9PPCn25uliftkV1n4ynwAAAGk"]
[Tue Jul 21 07:51:40.589746 2026] [security2:error] [pid 296703:tid 296912] [client 173.24.185.52:63986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PPCn25uliftkV1n4ypAAAAE8"]
[Tue Jul 21 07:51:40.589902 2026] [security2:error] [pid 296703:tid 296912] [client 173.24.185.52:63986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PPCn25uliftkV1n4ypAAAAE8"]
[Tue Jul 21 07:51:40.605892 2026] [security2:error] [pid 296703:tid 296885] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9PPCn25uliftkV1n4ypgAAADQ"]
[Tue Jul 21 07:51:40.776726 2026] [security2:error] [pid 296703:tid 296925] [client 20.104.96.117:59767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9PPCn25uliftkV1n4yqQAAAFw"]
[Tue Jul 21 07:51:40.788427 2026] [security2:error] [pid 302018:tid 302162] [client 117.247.80.59:26745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PPIAs9lPxxVAErz0QXAAAAJE"]
[Tue Jul 21 07:51:40.788530 2026] [security2:error] [pid 302018:tid 302162] [client 117.247.80.59:26745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PPIAs9lPxxVAErz0QXAAAAJE"]
[Tue Jul 21 07:51:40.848233 2026] [security2:error] [pid 296703:tid 296959] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/notifications/.env"] [unique_id "al9PPCn25uliftkV1n4yrwAAAH4"]
[Tue Jul 21 07:51:40.904641 2026] [security2:error] [pid 296703:tid 296859] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9PPCn25uliftkV1n4ysgAAABo"]
[Tue Jul 21 07:51:41.122956 2026] [security2:error] [pid 296703:tid 296957] [client 52.139.36.144:33133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-wz.php"] [unique_id "al9PPSn25uliftkV1n4ytwAAAHw"]
[Tue Jul 21 07:51:41.140886 2026] [security2:error] [pid 296703:tid 296840] [client 74.249.245.134:24791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/fw.php"] [unique_id "al9PPSn25uliftkV1n4yuAAAAAc"]
[Tue Jul 21 07:51:41.147476 2026] [security2:error] [pid 302018:tid 302263] [client 74.249.245.134:24807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/classsmtps.php"] [unique_id "al9PPYAs9lPxxVAErz0QXQAAAPY"]
[Tue Jul 21 07:51:41.197033 2026] [security2:error] [pid 296703:tid 296946] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/notify/.env"] [unique_id "al9PPSn25uliftkV1n4yuQAAAHE"]
[Tue Jul 21 07:51:41.218594 2026] [autoindex:error] [pid 302018:tid 302155] [client 34.78.230.243:55125] AH01276: Cannot serve directory /home2/marior90/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:51:41.507820 2026] [security2:error] [pid 302018:tid 302269] [client 20.226.60.151:61527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/elbzl.php"] [unique_id "al9PPYAs9lPxxVAErz0QZAAAAPw"]
[Tue Jul 21 07:51:41.537707 2026] [security2:error] [pid 296703:tid 296909] [client 52.139.36.144:1152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-ver.php"] [unique_id "al9PPSn25uliftkV1n4ywQAAAEw"]
[Tue Jul 21 07:51:41.545649 2026] [security2:error] [pid 296703:tid 296899] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/sender/.env"] [unique_id "al9PPSn25uliftkV1n4ywgAAAEI"]
[Tue Jul 21 07:51:41.630426 2026] [security2:error] [pid 302018:tid 302173] [client 104.207.35.235:35549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.35.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PPYAs9lPxxVAErz0QZQAAAJw"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:51:41.663661 2026] [security2:error] [pid 296703:tid 296839] [client 117.217.38.194:59705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PPSn25uliftkV1n4ywwAAAAY"]
[Tue Jul 21 07:51:41.663759 2026] [security2:error] [pid 296703:tid 296839] [client 117.217.38.194:59705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PPSn25uliftkV1n4ywwAAAAY"]
[Tue Jul 21 07:51:41.773215 2026] [security2:error] [pid 302018:tid 302125] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PPYAs9lPxxVAErz0QZgAA32g"]
[Tue Jul 21 07:51:41.773364 2026] [security2:error] [pid 302018:tid 302240] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PPYAs9lPxxVAErz0QZgAA32g"]
[Tue Jul 21 07:51:41.861403 2026] [security2:error] [pid 302018:tid 302176] [client 52.139.36.144:1244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp5.php"] [unique_id "al9PPYAs9lPxxVAErz0QbAAAAJ8"]
[Tue Jul 21 07:51:41.897895 2026] [security2:error] [pid 296703:tid 296942] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/campaign/.env"] [unique_id "al9PPSn25uliftkV1n4yxQAAAG0"]
[Tue Jul 21 07:51:42.108323 2026] [security2:error] [pid 296703:tid 296876] [client 172.245.102.45:46917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PPin25uliftkV1n4yyQAAACs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:42.229053 2026] [security2:error] [pid 302018:tid 302265] [client 20.197.192.193:27181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/wpx.php"] [unique_id "al9PPoAs9lPxxVAErz0QcQAAAPg"]
[Tue Jul 21 07:51:42.247487 2026] [security2:error] [pid 296703:tid 296871] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/newsletter/.env"] [unique_id "al9PPin25uliftkV1n4yygAAACY"]
[Tue Jul 21 07:51:42.298688 2026] [security2:error] [pid 302018:tid 302226] [client 128.127.105.184:47556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9PPoAs9lPxxVAErz0QcgAAANE"]
[Tue Jul 21 07:51:42.298794 2026] [security2:error] [pid 302018:tid 302226] [client 128.127.105.184:47556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9PPoAs9lPxxVAErz0QcgAAANE"]
[Tue Jul 21 07:51:42.370328 2026] [security2:error] [pid 302018:tid 302255] [client 52.139.36.144:1222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-pp.php"] [unique_id "al9PPoAs9lPxxVAErz0QdAAAAO4"]
[Tue Jul 21 07:51:42.539427 2026] [security2:error] [pid 302018:tid 302187] [client 122.179.91.63:14631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PPoAs9lPxxVAErz0QdgAAAKo"]
[Tue Jul 21 07:51:42.539565 2026] [security2:error] [pid 302018:tid 302187] [client 122.179.91.63:14631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PPoAs9lPxxVAErz0QdgAAAKo"]
[Tue Jul 21 07:51:42.548237 2026] [security2:error] [pid 302018:tid 302171] [client 20.104.96.117:64259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/jj.php"] [unique_id "al9PPoAs9lPxxVAErz0QdwAAAJo"]
[Tue Jul 21 07:51:42.595832 2026] [security2:error] [pid 296703:tid 296837] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/ses/.env"] [unique_id "al9PPin25uliftkV1n4y1gAAAAQ"]
[Tue Jul 21 07:51:42.727857 2026] [security2:error] [pid 302018:tid 302237] [client 52.139.36.144:1164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/w3lls.php"] [unique_id "al9PPoAs9lPxxVAErz0QeAAAANw"]
[Tue Jul 21 07:51:42.943916 2026] [security2:error] [pid 296703:tid 296847] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/sendgrid/.env"] [unique_id "al9PPin25uliftkV1n4y2gAAAA4"]
[Tue Jul 21 07:51:43.007327 2026] [security2:error] [pid 296703:tid 296849] [client 103.29.114.44:36792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PPyn25uliftkV1n4y2wAAABA"]
[Tue Jul 21 07:51:43.007514 2026] [security2:error] [pid 296703:tid 296849] [client 103.29.114.44:36792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PPyn25uliftkV1n4y2wAAABA"]
[Tue Jul 21 07:51:43.200845 2026] [security2:error] [pid 302018:tid 302181] [client 52.139.36.144:1159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/sbhu.php"] [unique_id "al9PP4As9lPxxVAErz0QfgAAAKQ"]
[Tue Jul 21 07:51:43.292613 2026] [security2:error] [pid 296703:tid 296941] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/sparkpost/.env"] [unique_id "al9PPyn25uliftkV1n4y3QAAAGw"]
[Tue Jul 21 07:51:43.447577 2026] [security2:error] [pid 302018:tid 302275] [client 20.104.96.117:64257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9PP4As9lPxxVAErz0QggAAAQI"]
[Tue Jul 21 07:51:43.537915 2026] [security2:error] [pid 296703:tid 296953] [client 74.249.245.134:64394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/fm.php"] [unique_id "al9PPyn25uliftkV1n4y5AAAAHg"]
[Tue Jul 21 07:51:43.642362 2026] [security2:error] [pid 296703:tid 296907] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/postmark/.env"] [unique_id "al9PPyn25uliftkV1n4y5gAAAEo"]
[Tue Jul 21 07:51:43.645505 2026] [security2:error] [pid 302018:tid 302263] [client 20.220.225.223:19668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/ez.php"] [unique_id "al9PP4As9lPxxVAErz0QhAAAAPY"]
[Tue Jul 21 07:51:43.673204 2026] [security2:error] [pid 302018:tid 302029] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PP4As9lPxxVAErz0QhQAApQg"]
[Tue Jul 21 07:51:43.673410 2026] [security2:error] [pid 302018:tid 302182] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PP4As9lPxxVAErz0QhQAApQg"]
[Tue Jul 21 07:51:43.702226 2026] [security2:error] [pid 296703:tid 296925] [client 52.139.36.144:33124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-content/uploads/admin.php"] [unique_id "al9PPyn25uliftkV1n4y6gAAAFw"]
[Tue Jul 21 07:51:43.782015 2026] [security2:error] [pid 302018:tid 302087] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PP4As9lPxxVAErz0QiAAA2EI"]
[Tue Jul 21 07:51:43.782185 2026] [security2:error] [pid 302018:tid 302233] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PP4As9lPxxVAErz0QiAAA2EI"]
[Tue Jul 21 07:51:43.963159 2026] [security2:error] [pid 302018:tid 302212] [client 194.99.104.35:53892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9PP4As9lPxxVAErz0QjAAAAMM"]
[Tue Jul 21 07:51:43.963250 2026] [security2:error] [pid 302018:tid 302212] [client 194.99.104.35:53892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9PP4As9lPxxVAErz0QjAAAAMM"]
[Tue Jul 21 07:51:43.991656 2026] [security2:error] [pid 296703:tid 296910] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/mailgun/.env"] [unique_id "al9PPyn25uliftkV1n4y7gAAAE0"]
[Tue Jul 21 07:51:44.146751 2026] [security2:error] [pid 302018:tid 311327] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PQIAs9lPxxVAErz0QjQAA34E"]
[Tue Jul 21 07:51:44.146913 2026] [security2:error] [pid 302018:tid 302240] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PQIAs9lPxxVAErz0QjQAA34E"]
[Tue Jul 21 07:51:44.159617 2026] [security2:error] [pid 296703:tid 296929] [client 52.139.36.144:26130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/favicon.php"] [unique_id "al9PQCn25uliftkV1n4y8wAAAGA"]
[Tue Jul 21 07:51:44.166546 2026] [security2:error] [pid 296703:tid 296883] [client 74.249.245.134:64446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/rip.php"] [unique_id "al9PQCn25uliftkV1n4y9AAAADI"]
[Tue Jul 21 07:51:44.184422 2026] [security2:error] [pid 296703:tid 296927] [client 20.197.192.193:27176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/berlin.php"] [unique_id "al9PQCn25uliftkV1n4y9gAAAF4"]
[Tue Jul 21 07:51:44.261592 2026] [security2:error] [pid 296703:tid 296912] [client 106.215.181.8:23361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PQCn25uliftkV1n4y_QAAAE8"]
[Tue Jul 21 07:51:44.261727 2026] [security2:error] [pid 296703:tid 296912] [client 106.215.181.8:23361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PQCn25uliftkV1n4y_QAAAE8"]
[Tue Jul 21 07:51:44.339218 2026] [proxy:error] [pid 296703:tid 296956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:51:44.339256 2026] [proxy_http:error] [pid 296703:tid 296956] [client 64.23.171.245:59360] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.despensanatural.com.br/
[Tue Jul 21 07:51:44.339555 2026] [security2:error] [pid 296703:tid 296840] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/mandrill/.env"] [unique_id "al9PQCn25uliftkV1n4y_wAAAAc"]
[Tue Jul 21 07:51:44.339805 2026] [proxy:error] [pid 296703:tid 296956] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:51:44.339845 2026] [proxy_http:error] [pid 296703:tid 296956] [client 64.23.171.245:59360] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.despensanatural.com.br/
[Tue Jul 21 07:51:44.676862 2026] [security2:error] [pid 296703:tid 296909] [client 52.139.36.144:26140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/txets.php"] [unique_id "al9PQCn25uliftkV1n4zCQAAAEw"]
[Tue Jul 21 07:51:44.687434 2026] [security2:error] [pid 296703:tid 296899] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/mailjet/.env"] [unique_id "al9PQCn25uliftkV1n4zCgAAAEI"]
[Tue Jul 21 07:51:44.743683 2026] [security2:error] [pid 296703:tid 296845] [client 194.99.104.35:53902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PQCn25uliftkV1n4zDAAAAAw"]
[Tue Jul 21 07:51:44.743785 2026] [security2:error] [pid 296703:tid 296845] [client 194.99.104.35:53902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PQCn25uliftkV1n4zDAAAAAw"]
[Tue Jul 21 07:51:44.748724 2026] [security2:error] [pid 296703:tid 296835] [client 20.104.96.117:59761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/txets.php"] [unique_id "al9PQCn25uliftkV1n4zDQAAAAI"]
[Tue Jul 21 07:51:44.975616 2026] [security2:error] [pid 296703:tid 296879] [client 74.249.245.134:65151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ini.php"] [unique_id "al9PQCn25uliftkV1n4zDwAAAC4"]
[Tue Jul 21 07:51:45.005664 2026] [security2:error] [pid 296703:tid 296950] [client 20.220.225.223:38226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/dp.php"] [unique_id "al9PQSn25uliftkV1n4zFAAAAHU"]
[Tue Jul 21 07:51:45.035973 2026] [security2:error] [pid 296703:tid 296947] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/brevo/.env"] [unique_id "al9PQSn25uliftkV1n4zFQAAAHI"]
[Tue Jul 21 07:51:45.082256 2026] [security2:error] [pid 296703:tid 296836] [client 74.249.245.134:65190] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "andrelageorthobolics.com.br"] [uri "/1.php"] [unique_id "al9PQSn25uliftkV1n4zFgAAAAM"]
[Tue Jul 21 07:51:45.082369 2026] [security2:error] [pid 296703:tid 296836] [client 74.249.245.134:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/1.php"] [unique_id "al9PQSn25uliftkV1n4zFgAAAAM"]
[Tue Jul 21 07:51:45.153644 2026] [security2:error] [pid 302018:tid 302168] [client 52.139.36.144:1216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-su.php"] [unique_id "al9PQYAs9lPxxVAErz0QkgAAAJc"]
[Tue Jul 21 07:51:45.375606 2026] [security2:error] [pid 302018:tid 302252] [client 20.220.225.223:19650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/fz.php"] [unique_id "al9PQYAs9lPxxVAErz0QlAAAAOs"]
[Tue Jul 21 07:51:45.384714 2026] [security2:error] [pid 296703:tid 296923] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/transactional/.env"] [unique_id "al9PQSn25uliftkV1n4zGwAAAFo"]
[Tue Jul 21 07:51:45.593083 2026] [security2:error] [pid 296703:tid 296888] [client 52.139.36.144:33102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/ff.php"] [unique_id "al9PQSn25uliftkV1n4zIAAAADc"]
[Tue Jul 21 07:51:45.674908 2026] [security2:error] [pid 296703:tid 296876] [client 122.164.127.47:52674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PQSn25uliftkV1n4zIQAAACs"]
[Tue Jul 21 07:51:45.675001 2026] [security2:error] [pid 296703:tid 296876] [client 122.164.127.47:52674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PQSn25uliftkV1n4zIQAAACs"]
[Tue Jul 21 07:51:45.690542 2026] [security2:error] [pid 302018:tid 302235] [client 20.197.192.193:9417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/we.php"] [unique_id "al9PQYAs9lPxxVAErz0QlQAAANo"]
[Tue Jul 21 07:51:45.733210 2026] [security2:error] [pid 296703:tid 296925] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/bulk/.env"] [unique_id "al9PQSn25uliftkV1n4zIgAAAFw"]
[Tue Jul 21 07:51:45.953135 2026] [security2:error] [pid 296703:tid 296764] [remote 8.217.108.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9PQCn25uliftkV1n4zDgAAGDw"], referer: http://assumaocontrole.com/
[Tue Jul 21 07:51:46.052213 2026] [security2:error] [pid 302018:tid 302273] [client 74.249.245.134:24828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/chosen.php"] [unique_id "al9PQoAs9lPxxVAErz0QnAAAAQA"]
[Tue Jul 21 07:51:46.081846 2026] [security2:error] [pid 296703:tid 296896] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/aws/.env"] [unique_id "al9PQin25uliftkV1n4zLQAAAD8"]
[Tue Jul 21 07:51:46.130239 2026] [security2:error] [pid 302018:tid 302159] [client 52.139.36.144:1160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/reze.php"] [unique_id "al9PQoAs9lPxxVAErz0QnwAAAI4"]
[Tue Jul 21 07:51:46.136165 2026] [security2:error] [pid 302018:tid 302156] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "buyonlinetodayatadiscount.net"] [uri "/cgi-sys/404.html"] [unique_id "al9PQoAs9lPxxVAErz0QoAAAAIs"]
[Tue Jul 21 07:51:46.136842 2026] [security2:error] [pid 302018:tid 302234] [client 74.7.230.1:45126] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "buyonlinetodayatadiscount.net"] [uri "/robots.txt"] [unique_id "al9PQoAs9lPxxVAErz0QnQAAANk"]
[Tue Jul 21 07:51:46.183806 2026] [security2:error] [pid 302018:tid 302259] [client 20.197.192.193:60650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9PQoAs9lPxxVAErz0QpAAAAPI"]
[Tue Jul 21 07:51:46.251378 2026] [security2:error] [pid 302018:tid 302237] [client 20.197.192.193:60619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9PQoAs9lPxxVAErz0QpQAAANw"]
[Tue Jul 21 07:51:46.324041 2026] [security2:error] [pid 302018:tid 302191] [client 20.197.192.193:60646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/dp.php"] [unique_id "al9PQoAs9lPxxVAErz0QpwAAAK4"]
[Tue Jul 21 07:51:46.368248 2026] [security2:error] [pid 302018:tid 302262] [client 41.68.90.219:65111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PQoAs9lPxxVAErz0QqQAAAPU"]
[Tue Jul 21 07:51:46.369456 2026] [security2:error] [pid 302018:tid 302262] [client 41.68.90.219:65111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PQoAs9lPxxVAErz0QqQAAAPU"]
[Tue Jul 21 07:51:46.412375 2026] [security2:error] [pid 296703:tid 296954] [client 193.36.225.62:54973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PQin25uliftkV1n4zMwAAAHk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:46.429873 2026] [security2:error] [pid 296703:tid 296877] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/azure/.env"] [unique_id "al9PQin25uliftkV1n4zNAAAACw"]
[Tue Jul 21 07:51:46.435044 2026] [security2:error] [pid 302018:tid 302272] [client 20.197.192.193:60611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/old.php"] [unique_id "al9PQoAs9lPxxVAErz0QrQAAAP8"]
[Tue Jul 21 07:51:46.475616 2026] [security2:error] [pid 296703:tid 296854] [client 20.104.96.117:64382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/dex.php"] [unique_id "al9PQin25uliftkV1n4zNgAAABU"]
[Tue Jul 21 07:51:46.563285 2026] [security2:error] [pid 302018:tid 302229] [client 20.197.192.193:38960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/ms-new.php"] [unique_id "al9PQoAs9lPxxVAErz0QtQAAANQ"]
[Tue Jul 21 07:51:46.649736 2026] [security2:error] [pid 302018:tid 302164] [client 52.139.36.144:28700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/666.php"] [unique_id "al9PQoAs9lPxxVAErz0QuQAAAJM"]
[Tue Jul 21 07:51:46.777910 2026] [security2:error] [pid 296703:tid 296860] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/gcp/.env"] [unique_id "al9PQin25uliftkV1n4zQwAAABs"]
[Tue Jul 21 07:51:46.834405 2026] [security2:error] [pid 302018:tid 302192] [client 20.197.192.193:60664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/track.php"] [unique_id "al9PQoAs9lPxxVAErz0QxAAAAK8"]
[Tue Jul 21 07:51:46.984067 2026] [security2:error] [pid 302018:tid 302274] [client 20.197.192.193:60667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/2352356666.php"] [unique_id "al9PQoAs9lPxxVAErz0QxwAAAQE"]
[Tue Jul 21 07:51:47.010955 2026] [security2:error] [pid 302018:tid 302045] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PQ4As9lPxxVAErz0QyQAAxBg"]
[Tue Jul 21 07:51:47.011125 2026] [security2:error] [pid 302018:tid 302213] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PQ4As9lPxxVAErz0QyQAAxBg"]
[Tue Jul 21 07:51:47.011736 2026] [security2:error] [pid 302018:tid 302150] [client 20.226.60.151:56793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9PQ4As9lPxxVAErz0QygAAAIU"]
[Tue Jul 21 07:51:47.013401 2026] [security2:error] [pid 302018:tid 302245] [client 20.197.192.193:60654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/pn.php"] [unique_id "al9PQ4As9lPxxVAErz0QywAAAOQ"]
[Tue Jul 21 07:51:47.037175 2026] [security2:error] [pid 302018:tid 302268] [client 20.197.192.193:60633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9PQ4As9lPxxVAErz0QzAAAAPs"]
[Tue Jul 21 07:51:47.040810 2026] [security2:error] [pid 302018:tid 302166] [client 202.143.127.214:57100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PQ4As9lPxxVAErz0QzQAAAJU"]
[Tue Jul 21 07:51:47.040893 2026] [security2:error] [pid 302018:tid 302166] [client 202.143.127.214:57100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PQ4As9lPxxVAErz0QzQAAAJU"]
[Tue Jul 21 07:51:47.075725 2026] [security2:error] [pid 302018:tid 302276] [client 20.197.192.193:35863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/dr.php"] [unique_id "al9PQ4As9lPxxVAErz0QzwAAAQM"]
[Tue Jul 21 07:51:47.104043 2026] [security2:error] [pid 302018:tid 302188] [client 122.162.144.145:11626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PQ4As9lPxxVAErz0Q0QAAAKs"]
[Tue Jul 21 07:51:47.104209 2026] [security2:error] [pid 302018:tid 302188] [client 122.162.144.145:11626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PQ4As9lPxxVAErz0Q0QAAAKs"]
[Tue Jul 21 07:51:47.106054 2026] [security2:error] [pid 302018:tid 302218] [client 20.197.192.193:60657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/2x.php"] [unique_id "al9PQ4As9lPxxVAErz0Q0gAAAMk"]
[Tue Jul 21 07:51:47.126659 2026] [security2:error] [pid 296703:tid 296905] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/cloud/.env"] [unique_id "al9PQyn25uliftkV1n4zRgAAAEg"]
[Tue Jul 21 07:51:47.176731 2026] [security2:error] [pid 302018:tid 302227] [client 52.139.36.144:26112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wehrman.php"] [unique_id "al9PQ4As9lPxxVAErz0Q1AAAANI"]
[Tue Jul 21 07:51:47.182363 2026] [security2:error] [pid 302018:tid 302255] [client 20.197.192.193:60610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/kq1.php"] [unique_id "al9PQ4As9lPxxVAErz0Q1QAAAO4"]
[Tue Jul 21 07:51:47.240078 2026] [security2:error] [pid 302018:tid 302171] [client 20.197.192.193:38970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/zzz.php"] [unique_id "al9PQ4As9lPxxVAErz0Q1wAAAJo"]
[Tue Jul 21 07:51:47.245164 2026] [security2:error] [pid 302018:tid 302179] [client 20.220.225.223:31688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/bootstrap.php"] [unique_id "al9PQ4As9lPxxVAErz0Q2AAAAKI"]
[Tue Jul 21 07:51:47.262947 2026] [security2:error] [pid 302018:tid 302207] [client 182.8.255.181:17292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PQ4As9lPxxVAErz0Q2gAAAL4"]
[Tue Jul 21 07:51:47.263080 2026] [security2:error] [pid 302018:tid 302207] [client 182.8.255.181:17292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PQ4As9lPxxVAErz0Q2gAAAL4"]
[Tue Jul 21 07:51:47.306030 2026] [security2:error] [pid 302018:tid 302203] [client 193.36.225.96:63019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PQ4As9lPxxVAErz0Q0wAAALo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:51:47.314991 2026] [security2:error] [pid 302018:tid 302160] [client 20.197.192.193:38948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/wicked.php"] [unique_id "al9PQ4As9lPxxVAErz0Q4gAAAI8"]
[Tue Jul 21 07:51:47.425344 2026] [security2:error] [pid 302018:tid 302181] [client 74.249.245.134:64216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/css.php"] [unique_id "al9PQ4As9lPxxVAErz0Q5gAAAKQ"]
[Tue Jul 21 07:51:47.475791 2026] [security2:error] [pid 296703:tid 296894] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/infrastructure/.env"] [unique_id "al9PQyn25uliftkV1n4zSwAAAD0"]
[Tue Jul 21 07:51:47.576829 2026] [security2:error] [pid 296703:tid 296863] [client 20.197.192.193:60627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/edit.php"] [unique_id "al9PQyn25uliftkV1n4zTAAAAB4"]
[Tue Jul 21 07:51:47.639738 2026] [security2:error] [pid 302018:tid 302263] [client 20.197.192.193:60638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/kua.php"] [unique_id "al9PQ4As9lPxxVAErz0Q7AAAAPY"]
[Tue Jul 21 07:51:47.657250 2026] [security2:error] [pid 296703:tid 296906] [client 194.99.104.35:53908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9PQyn25uliftkV1n4zUAAAAEk"]
[Tue Jul 21 07:51:47.657367 2026] [security2:error] [pid 296703:tid 296906] [client 194.99.104.35:53908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9PQyn25uliftkV1n4zUAAAAEk"]
[Tue Jul 21 07:51:47.687053 2026] [security2:error] [pid 302018:tid 302220] [client 20.197.192.193:60636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/ez.php"] [unique_id "al9PQ4As9lPxxVAErz0Q7QAAAMs"]
[Tue Jul 21 07:51:47.701845 2026] [security2:error] [pid 302018:tid 302192] [client 20.220.225.223:22703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-editor.php"] [unique_id "al9PQ4As9lPxxVAErz0Q7gAAAK8"]
[Tue Jul 21 07:51:47.716919 2026] [security2:error] [pid 302018:tid 302247] [client 20.197.192.193:60615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/fz.php"] [unique_id "al9PQ4As9lPxxVAErz0Q7wAAAOY"]
[Tue Jul 21 07:51:47.764425 2026] [security2:error] [pid 302018:tid 302150] [client 20.197.192.193:60641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/la.php"] [unique_id "al9PQ4As9lPxxVAErz0Q8gAAAIU"]
[Tue Jul 21 07:51:47.825128 2026] [security2:error] [pid 296703:tid 296849] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/docker/.env"] [unique_id "al9PQyn25uliftkV1n4zUwAAABA"]
[Tue Jul 21 07:51:47.844819 2026] [security2:error] [pid 302018:tid 302266] [client 52.139.36.144:1258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-conflg.php"] [unique_id "al9PQ4As9lPxxVAErz0Q9QAAAPk"]
[Tue Jul 21 07:51:47.914878 2026] [security2:error] [pid 296703:tid 296846] [client 20.197.192.193:38947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9PQyn25uliftkV1n4zVQAAAA0"]
[Tue Jul 21 07:51:47.996255 2026] [security2:error] [pid 296703:tid 296908] [client 20.197.192.193:38956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/inso.php"] [unique_id "al9PQyn25uliftkV1n4zVwAAAEs"]
[Tue Jul 21 07:51:48.029515 2026] [security2:error] [pid 302018:tid 302030] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PRIAs9lPxxVAErz0Q-AAAwQk"]
[Tue Jul 21 07:51:48.029686 2026] [security2:error] [pid 302018:tid 302210] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PRIAs9lPxxVAErz0Q-AAAwQk"]
[Tue Jul 21 07:51:48.058354 2026] [security2:error] [pid 302018:tid 302276] [client 20.104.96.117:60687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/xpwer1.php"] [unique_id "al9PRIAs9lPxxVAErz0Q-QAAAQM"]
[Tue Jul 21 07:51:48.064440 2026] [security2:error] [pid 302018:tid 302252] [client 20.220.225.223:6082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/inso.php"] [unique_id "al9PRIAs9lPxxVAErz0Q-gAAAOs"]
[Tue Jul 21 07:51:48.106323 2026] [security2:error] [pid 296703:tid 296850] [client 20.197.192.193:60660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/wpx.php"] [unique_id "al9PRCn25uliftkV1n4zWAAAABE"]
[Tue Jul 21 07:51:48.162149 2026] [security2:error] [pid 296703:tid 296955] [client 20.197.192.193:60625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/berlin.php"] [unique_id "al9PRCn25uliftkV1n4zWwAAAHo"]
[Tue Jul 21 07:51:48.173153 2026] [security2:error] [pid 296703:tid 296933] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/k8s/.env"] [unique_id "al9PRCn25uliftkV1n4zXAAAAGQ"]
[Tue Jul 21 07:51:48.188993 2026] [security2:error] [pid 302018:tid 302218] [client 20.197.192.193:35881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/billur.php"] [unique_id "al9PRIAs9lPxxVAErz0Q_AAAAMk"]
[Tue Jul 21 07:51:48.227525 2026] [security2:error] [pid 302018:tid 302194] [client 20.197.192.193:38940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/mimpi.php"] [unique_id "al9PRIAs9lPxxVAErz0Q_QAAALE"]
[Tue Jul 21 07:51:48.276384 2026] [security2:error] [pid 302018:tid 302221] [client 103.166.103.129:36409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PRIAs9lPxxVAErz0Q_wAAAMw"]
[Tue Jul 21 07:51:48.276532 2026] [security2:error] [pid 302018:tid 302221] [client 103.166.103.129:36409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PRIAs9lPxxVAErz0Q_wAAAMw"]
[Tue Jul 21 07:51:48.311120 2026] [security2:error] [pid 302018:tid 302148] [remote 45.150.79.142:45630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wp-login.php"] [unique_id "al9PRIAs9lPxxVAErz0RAQAA-H8"]
[Tue Jul 21 07:51:48.323433 2026] [security2:error] [pid 302018:tid 302163] [client 52.139.36.144:33059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/ff1.php"] [unique_id "al9PRIAs9lPxxVAErz0RAgAAAJI"]
[Tue Jul 21 07:51:48.355522 2026] [security2:error] [pid 302018:tid 302267] [client 74.7.228.5:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tiagorochaamorim1781889826254.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9PRIAs9lPxxVAErz0RBAAA-hI"]
[Tue Jul 21 07:51:48.361629 2026] [security2:error] [pid 296703:tid 296759] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PRCn25uliftkV1n4zXwAAIjc"]
[Tue Jul 21 07:51:48.361810 2026] [security2:error] [pid 296703:tid 296867] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PRCn25uliftkV1n4zXwAAIjc"]
[Tue Jul 21 07:51:48.390856 2026] [security2:error] [pid 302018:tid 302269] [client 223.236.153.128:7095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PRIAs9lPxxVAErz0RBQAAAPw"]
[Tue Jul 21 07:51:48.395411 2026] [security2:error] [pid 302018:tid 302269] [client 223.236.153.128:7095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PRIAs9lPxxVAErz0RBQAAAPw"]
[Tue Jul 21 07:51:48.523593 2026] [security2:error] [pid 296703:tid 296910] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/kubernetes/.env"] [unique_id "al9PRCn25uliftkV1n4zYwAAAE0"]
[Tue Jul 21 07:51:48.532923 2026] [security2:error] [pid 302018:tid 302186] [client 20.197.192.193:60658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/dp.php"] [unique_id "al9PRIAs9lPxxVAErz0RBgAAAKk"]
[Tue Jul 21 07:51:48.541737 2026] [security2:error] [pid 296703:tid 296857] [client 162.241.63.68:16718] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-cron.php"] [unique_id "al9PRCn25uliftkV1n4zZAAAABg"]
[Tue Jul 21 07:51:48.553254 2026] [security2:error] [pid 302018:tid 302236] [client 20.104.96.117:64353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/flox.php"] [unique_id "al9PRIAs9lPxxVAErz0RBwAAANs"]
[Tue Jul 21 07:51:48.721686 2026] [security2:error] [pid 302018:tid 302205] [client 74.249.245.134:64248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/php.php"] [unique_id "al9PRIAs9lPxxVAErz0RDgAAALw"]
[Tue Jul 21 07:51:48.730672 2026] [security2:error] [pid 302018:tid 302217] [client 20.197.192.193:60631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/bootstrap.php"] [unique_id "al9PRIAs9lPxxVAErz0RDwAAAMg"]
[Tue Jul 21 07:51:48.807400 2026] [security2:error] [pid 296703:tid 296927] [client 52.139.36.144:1202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/fff.php"] [unique_id "al9PRCn25uliftkV1n4zawAAAF4"]
[Tue Jul 21 07:51:48.834209 2026] [security2:error] [pid 302018:tid 302193] [client 20.220.225.223:31740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/cro.php"] [unique_id "al9PRIAs9lPxxVAErz0REQAAALA"]
[Tue Jul 21 07:51:48.871760 2026] [security2:error] [pid 296703:tid 296853] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/terraform/.env"] [unique_id "al9PRCn25uliftkV1n4zbQAAABQ"]
[Tue Jul 21 07:51:48.931379 2026] [security2:error] [pid 296703:tid 296864] [client 20.197.192.193:38961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/wp-editor.php"] [unique_id "al9PRCn25uliftkV1n4zcQAAAB8"]
[Tue Jul 21 07:51:49.029863 2026] [security2:error] [pid 302018:tid 302214] [client 20.104.96.117:64336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/popo.php"] [unique_id "al9PRYAs9lPxxVAErz0RFAAAAMU"]
[Tue Jul 21 07:51:49.054325 2026] [security2:error] [pid 296703:tid 296917] [client 20.197.192.193:38935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/cro.php"] [unique_id "al9PRSn25uliftkV1n4zdAAAAFQ"]
[Tue Jul 21 07:51:49.126651 2026] [security2:error] [pid 296703:tid 296854] [client 20.197.192.193:60637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/cron-tab.php"] [unique_id "al9PRSn25uliftkV1n4zdgAAABU"]
[Tue Jul 21 07:51:49.206227 2026] [security2:error] [pid 296703:tid 296916] [client 103.86.117.203:50046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PRSn25uliftkV1n4zdwAAAFM"]
[Tue Jul 21 07:51:49.206380 2026] [security2:error] [pid 296703:tid 296916] [client 103.86.117.203:50046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PRSn25uliftkV1n4zdwAAAFM"]
[Tue Jul 21 07:51:49.220395 2026] [security2:error] [pid 296703:tid 296946] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/ansible/.env"] [unique_id "al9PRSn25uliftkV1n4zeAAAAHE"]
[Tue Jul 21 07:51:49.250300 2026] [security2:error] [pid 296703:tid 296870] [client 20.197.192.193:60652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/koiy.php"] [unique_id "al9PRSn25uliftkV1n4zfAAAACU"]
[Tue Jul 21 07:51:49.295999 2026] [security2:error] [pid 302018:tid 302173] [client 20.197.192.193:35880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/hp2.php"] [unique_id "al9PRYAs9lPxxVAErz0RGwAAAJw"]
[Tue Jul 21 07:51:49.322801 2026] [security2:error] [pid 302018:tid 302274] [client 20.197.192.193:38945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/hp3.php"] [unique_id "al9PRYAs9lPxxVAErz0RHwAAAQE"]
[Tue Jul 21 07:51:49.362242 2026] [security2:error] [pid 302018:tid 302196] [client 52.139.36.144:30516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/amax.php"] [unique_id "al9PRYAs9lPxxVAErz0RIAAAALM"]
[Tue Jul 21 07:51:49.447183 2026] [security2:error] [pid 302018:tid 302210] [client 20.197.192.193:60635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/aa1.php"] [unique_id "al9PRYAs9lPxxVAErz0RIgAAAME"]
[Tue Jul 21 07:51:49.568929 2026] [security2:error] [pid 296703:tid 296956] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/.git/.env"] [unique_id "al9PRSn25uliftkV1n4zgQAAAHs"]
[Tue Jul 21 07:51:49.585836 2026] [security2:error] [pid 296703:tid 296835] [client 20.220.225.223:6096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/wpx.php"] [unique_id "al9PRSn25uliftkV1n4zggAAAAI"]
[Tue Jul 21 07:51:49.601470 2026] [security2:error] [pid 302018:tid 302188] [client 20.197.192.193:35871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/acew67.php"] [unique_id "al9PRYAs9lPxxVAErz0RIwAAAKs"]
[Tue Jul 21 07:51:49.751139 2026] [security2:error] [pid 296703:tid 296905] [client 20.197.192.193:60634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/bscclapb.php"] [unique_id "al9PRSn25uliftkV1n4zhgAAAEg"]
[Tue Jul 21 07:51:49.807684 2026] [security2:error] [pid 302018:tid 302219] [client 20.197.192.193:60624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/else1.php"] [unique_id "al9PRYAs9lPxxVAErz0RKwAAAMo"]
[Tue Jul 21 07:51:49.876798 2026] [security2:error] [pid 302018:tid 302179] [client 52.139.36.144:33054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-firewall.php"] [unique_id "al9PRYAs9lPxxVAErz0RLAAAAKI"]
[Tue Jul 21 07:51:49.884028 2026] [security2:error] [pid 302018:tid 302159] [client 20.197.192.193:60614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/tkikikoko.php"] [unique_id "al9PRYAs9lPxxVAErz0RLQAAAI4"]
[Tue Jul 21 07:51:49.917296 2026] [security2:error] [pid 296703:tid 296934] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/ci/.env"] [unique_id "al9PRSn25uliftkV1n4zigAAAGU"]
[Tue Jul 21 07:51:49.957805 2026] [security2:error] [pid 302018:tid 302186] [client 20.197.192.193:27082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/billur.php"] [unique_id "al9PRYAs9lPxxVAErz0RLgAAAKk"]
[Tue Jul 21 07:51:49.968930 2026] [security2:error] [pid 302018:tid 302175] [client 20.197.192.193:35869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9PRYAs9lPxxVAErz0RLwAAAJ4"]
[Tue Jul 21 07:51:50.077319 2026] [security2:error] [pid 302018:tid 302248] [client 20.197.192.193:38930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/wp-css.php"] [unique_id "al9PRoAs9lPxxVAErz0RMgAAAOc"]
[Tue Jul 21 07:51:50.139706 2026] [security2:error] [pid 302018:tid 302160] [client 20.220.225.223:6119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/berlin.php"] [unique_id "al9PRoAs9lPxxVAErz0RMwAAAI8"]
[Tue Jul 21 07:51:50.211996 2026] [security2:error] [pid 302018:tid 302191] [client 20.197.192.193:38924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/wp-explorer.php"] [unique_id "al9PRoAs9lPxxVAErz0RNAAAAK4"]
[Tue Jul 21 07:51:50.265552 2026] [security2:error] [pid 296703:tid 296947] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/cd/.env"] [unique_id "al9PRin25uliftkV1n4zjwAAAHI"]
[Tue Jul 21 07:51:50.284771 2026] [security2:error] [pid 302018:tid 302151] [client 20.197.192.193:60620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/akismet.php"] [unique_id "al9PRoAs9lPxxVAErz0RNwAAAIY"]
[Tue Jul 21 07:51:50.297185 2026] [security2:error] [pid 302018:tid 302217] [client 52.139.36.144:1270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/appt.php"] [unique_id "al9PRoAs9lPxxVAErz0ROAAAAMg"]
[Tue Jul 21 07:51:50.377894 2026] [security2:error] [pid 302018:tid 302187] [client 20.104.96.117:64351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/yas.php"] [unique_id "al9PRoAs9lPxxVAErz0ROwAAAKo"]
[Tue Jul 21 07:51:50.405918 2026] [security2:error] [pid 302018:tid 302230] [client 20.197.192.193:60668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/ace2.php"] [unique_id "al9PRoAs9lPxxVAErz0RPgAAANU"]
[Tue Jul 21 07:51:50.546705 2026] [security2:error] [pid 302018:tid 302220] [client 20.197.192.193:38926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gruposafiramt.com.br"] [uri "/ms.php"] [unique_id "al9PRoAs9lPxxVAErz0RQwAAAMs"]
[Tue Jul 21 07:51:50.559727 2026] [security2:error] [pid 302018:tid 302076] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PRoAs9lPxxVAErz0RRAAAuzc"]
[Tue Jul 21 07:51:50.559844 2026] [security2:error] [pid 302018:tid 302204] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PRoAs9lPxxVAErz0RRAAAuzc"]
[Tue Jul 21 07:51:50.618288 2026] [security2:error] [pid 296703:tid 296847] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/jenkins/.env"] [unique_id "al9PRin25uliftkV1n4zkwAAAA4"]
[Tue Jul 21 07:51:50.674008 2026] [security2:error] [pid 302018:tid 302261] [client 52.139.36.144:1155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-thi.php"] [unique_id "al9PRoAs9lPxxVAErz0RRQAAAPQ"]
[Tue Jul 21 07:51:50.679974 2026] [security2:error] [pid 296703:tid 296890] [client 178.153.91.96:58574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PRin25uliftkV1n4zlAAAADk"]
[Tue Jul 21 07:51:50.680067 2026] [security2:error] [pid 296703:tid 296890] [client 178.153.91.96:58574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PRin25uliftkV1n4zlAAAADk"]
[Tue Jul 21 07:51:50.835483 2026] [security2:error] [pid 302018:tid 302211] [client 109.60.28.94:62574] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PRoAs9lPxxVAErz0RSwAAAMI"]
[Tue Jul 21 07:51:50.835667 2026] [security2:error] [pid 302018:tid 302211] [client 109.60.28.94:62574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PRoAs9lPxxVAErz0RSwAAAMI"]
[Tue Jul 21 07:51:50.848662 2026] [security2:error] [pid 302018:tid 302259] [client 122.186.204.214:51917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PRoAs9lPxxVAErz0RTQAAAPI"]
[Tue Jul 21 07:51:50.848867 2026] [security2:error] [pid 302018:tid 302259] [client 122.186.204.214:51917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PRoAs9lPxxVAErz0RTQAAAPI"]
[Tue Jul 21 07:51:50.889233 2026] [security2:error] [pid 296703:tid 296868] [client 20.220.225.223:6124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/billur.php"] [unique_id "al9PRin25uliftkV1n4zmAAAACM"]
[Tue Jul 21 07:51:50.951433 2026] [security2:error] [pid 302018:tid 302203] [client 139.167.225.182:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PRoAs9lPxxVAErz0RTwAAALo"]
[Tue Jul 21 07:51:50.951560 2026] [security2:error] [pid 302018:tid 302203] [client 139.167.225.182:51540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PRoAs9lPxxVAErz0RTwAAALo"]
[Tue Jul 21 07:51:50.967392 2026] [security2:error] [pid 296703:tid 296930] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/gitlab/.env"] [unique_id "al9PRin25uliftkV1n4znAAAAGE"]
[Tue Jul 21 07:51:51.182718 2026] [security2:error] [pid 302018:tid 302221] [client 52.139.36.144:1199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/jj.php"] [unique_id "al9PR4As9lPxxVAErz0RWAAAAMw"]
[Tue Jul 21 07:51:51.197500 2026] [security2:error] [pid 302018:tid 302258] [client 173.24.185.52:64530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PR4As9lPxxVAErz0RWQAAAPE"]
[Tue Jul 21 07:51:51.197667 2026] [security2:error] [pid 302018:tid 302258] [client 173.24.185.52:64530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PR4As9lPxxVAErz0RWQAAAPE"]
[Tue Jul 21 07:51:51.263631 2026] [security2:error] [pid 296703:tid 296897] [client 193.36.225.54:22161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PRyn25uliftkV1n4znQAAAEA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:51.316188 2026] [security2:error] [pid 296703:tid 296844] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/github/.env"] [unique_id "al9PRyn25uliftkV1n4znwAAAAs"]
[Tue Jul 21 07:51:51.374119 2026] [security2:error] [pid 302018:tid 302233] [client 59.96.220.140:52081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.220.96.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9PR4As9lPxxVAErz0RWgAAANg"]
[Tue Jul 21 07:51:51.374249 2026] [security2:error] [pid 302018:tid 302233] [client 59.96.220.140:52081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gmtruckms.com"] [uri "/xmlrpc.php"] [unique_id "al9PR4As9lPxxVAErz0RWgAAANg"]
[Tue Jul 21 07:51:51.376086 2026] [security2:error] [pid 296703:tid 296876] [client 20.104.96.117:64360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/file61.php"] [unique_id "al9PRyn25uliftkV1n4zpAAAACs"]
[Tue Jul 21 07:51:51.525927 2026] [security2:error] [pid 302018:tid 302194] [client 52.139.36.144:26151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/333.php"] [unique_id "al9PR4As9lPxxVAErz0RYQAAALE"]
[Tue Jul 21 07:51:51.531413 2026] [security2:error] [pid 302018:tid 302248] [client 20.220.225.223:55546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/cron-tab.php"] [unique_id "al9PR4As9lPxxVAErz0RYgAAAOc"]
[Tue Jul 21 07:51:51.586956 2026] [security2:error] [pid 302018:tid 302089] [remote 46.105.28.235:44090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9PR4As9lPxxVAErz0RYwABAEQ"]
[Tue Jul 21 07:51:51.664994 2026] [security2:error] [pid 296703:tid 296873] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/actions/.env"] [unique_id "al9PRyn25uliftkV1n4zpwAAACg"]
[Tue Jul 21 07:51:51.796960 2026] [security2:error] [pid 302018:tid 302250] [client 74.249.245.134:64405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/aa.php"] [unique_id "al9PR4As9lPxxVAErz0RaAAAAOk"]
[Tue Jul 21 07:51:51.864181 2026] [security2:error] [pid 302018:tid 302178] [client 65.111.1.220:43733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.1.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PR4As9lPxxVAErz0RawAAAKE"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:51:51.935060 2026] [security2:error] [pid 302018:tid 302246] [client 52.139.36.144:1161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/albin.php"] [unique_id "al9PR4As9lPxxVAErz0RbQAAAOU"]
[Tue Jul 21 07:51:52.013515 2026] [security2:error] [pid 296703:tid 296914] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/circleci/.env"] [unique_id "al9PSCn25uliftkV1n4zrgAAAFE"]
[Tue Jul 21 07:51:52.155401 2026] [security2:error] [pid 302018:tid 302251] [client 20.220.225.223:19670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/la.php"] [unique_id "al9PSIAs9lPxxVAErz0RcQAAAOo"]
[Tue Jul 21 07:51:52.157797 2026] [security2:error] [pid 296703:tid 296885] [client 103.29.114.44:18691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PSCn25uliftkV1n4zswAAADQ"]
[Tue Jul 21 07:51:52.157936 2026] [security2:error] [pid 296703:tid 296885] [client 103.29.114.44:18691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PSCn25uliftkV1n4zswAAADQ"]
[Tue Jul 21 07:51:52.191469 2026] [security2:error] [pid 302018:tid 302157] [client 117.217.38.194:60201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PSIAs9lPxxVAErz0RcgAAAIw"]
[Tue Jul 21 07:51:52.191603 2026] [security2:error] [pid 302018:tid 302157] [client 117.217.38.194:60201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PSIAs9lPxxVAErz0RcgAAAIw"]
[Tue Jul 21 07:51:52.288907 2026] [security2:error] [pid 296703:tid 296842] [client 52.139.36.144:33120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/66.php"] [unique_id "al9PSCn25uliftkV1n4ztgAAAAk"]
[Tue Jul 21 07:51:52.299459 2026] [security2:error] [pid 302018:tid 302205] [client 117.247.80.59:34841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PSIAs9lPxxVAErz0RcwAAALw"]
[Tue Jul 21 07:51:52.299592 2026] [security2:error] [pid 302018:tid 302205] [client 117.247.80.59:34841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PSIAs9lPxxVAErz0RcwAAALw"]
[Tue Jul 21 07:51:52.300012 2026] [security2:error] [pid 302018:tid 302091] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PSIAs9lPxxVAErz0RdAAA0UY"]
[Tue Jul 21 07:51:52.300212 2026] [security2:error] [pid 302018:tid 302226] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PSIAs9lPxxVAErz0RdAAA0UY"]
[Tue Jul 21 07:51:52.362264 2026] [security2:error] [pid 296703:tid 296954] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/travis/.env"] [unique_id "al9PSCn25uliftkV1n4ztwAAAHk"]
[Tue Jul 21 07:51:52.504474 2026] [security2:error] [pid 302018:tid 302276] [client 20.104.96.117:64270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/water.php"] [unique_id "al9PSIAs9lPxxVAErz0ReAAAAQM"]
[Tue Jul 21 07:51:52.571857 2026] [security2:error] [pid 296703:tid 296949] [client 184.75.223.211:38904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9PSCn25uliftkV1n4zwwAAAHQ"]
[Tue Jul 21 07:51:52.571975 2026] [security2:error] [pid 296703:tid 296949] [client 184.75.223.211:38904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9PSCn25uliftkV1n4zwwAAAHQ"]
[Tue Jul 21 07:51:52.711457 2026] [security2:error] [pid 302018:tid 302227] [client 52.139.36.144:26169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/motu.php"] [unique_id "al9PSIAs9lPxxVAErz0RegAAANI"]
[Tue Jul 21 07:51:52.711896 2026] [security2:error] [pid 296703:tid 296956] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/buildkite/.env"] [unique_id "al9PSCn25uliftkV1n4zxQAAAHs"]
[Tue Jul 21 07:51:53.002151 2026] [security2:error] [pid 302018:tid 302195] [client 52.139.36.144:1259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/kj.php"] [unique_id "al9PSYAs9lPxxVAErz0RfQAAALI"]
[Tue Jul 21 07:51:53.062483 2026] [security2:error] [pid 296703:tid 296871] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/mysql/.env"] [unique_id "al9PSSn25uliftkV1n4zygAAACY"]
[Tue Jul 21 07:51:53.296948 2026] [security2:error] [pid 302018:tid 302241] [client 20.220.225.223:23464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/mimpi.php"] [unique_id "al9PSYAs9lPxxVAErz0RggAAAOA"]
[Tue Jul 21 07:51:53.324469 2026] [security2:error] [pid 302018:tid 302243] [client 65.111.27.39:59893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PSYAs9lPxxVAErz0RgwAAAOI"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:51:53.334805 2026] [security2:error] [pid 302018:tid 302255] [client 172.245.102.32:51101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PR4As9lPxxVAErz0RVwAAAO4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:51:53.390454 2026] [security2:error] [pid 302018:tid 302173] [client 52.139.36.144:26110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp4.php"] [unique_id "al9PSYAs9lPxxVAErz0RhAAAAJw"]
[Tue Jul 21 07:51:53.411325 2026] [security2:error] [pid 296703:tid 296928] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/postgres/.env"] [unique_id "al9PSSn25uliftkV1n4zzgAAAF8"]
[Tue Jul 21 07:51:53.485637 2026] [autoindex:error] [pid 296703:tid 296884] [client 85.204.70.114:0] AH01276: Cannot serve directory /home3/rapha354/espaconeuroascensao.com.br/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:51:53.492443 2026] [security2:error] [pid 296703:tid 296835] [client 122.179.91.63:28511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PSSn25uliftkV1n4z4QAAAAI"]
[Tue Jul 21 07:51:53.492605 2026] [security2:error] [pid 296703:tid 296835] [client 122.179.91.63:28511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PSSn25uliftkV1n4z4QAAAAI"]
[Tue Jul 21 07:51:53.625146 2026] [security2:error] [pid 302018:tid 302168] [client 162.241.63.68:0] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "buyonlinetodayatadiscount.net"] [uri "/index.php"] [unique_id "al9PSYAs9lPxxVAErz0RjQAAAJc"]
[Tue Jul 21 07:51:53.625780 2026] [security2:error] [pid 296703:tid 296908] [client 162.241.63.68:43262] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "buyonlinetodayatadiscount.net"] [uri "/"] [unique_id "al9PSSn25uliftkV1n4z9QAAAEs"]
[Tue Jul 21 07:51:53.631959 2026] [security2:error] [pid 302018:tid 302252] [client 128.127.105.184:57308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PSYAs9lPxxVAErz0RkQAAAOs"]
[Tue Jul 21 07:51:53.632028 2026] [security2:error] [pid 302018:tid 302252] [client 128.127.105.184:57308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PSYAs9lPxxVAErz0RkQAAAOs"]
[Tue Jul 21 07:51:53.759896 2026] [security2:error] [pid 296703:tid 296844] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/mongodb/.env"] [unique_id "al9PSSn25uliftkV1n4z_QAAAAs"]
[Tue Jul 21 07:51:53.766207 2026] [security2:error] [pid 296703:tid 296953] [client 20.226.60.151:61520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/adjig.php"] [unique_id "al9PSSn25uliftkV1n4z_gAAAHg"]
[Tue Jul 21 07:51:53.884793 2026] [security2:error] [pid 296703:tid 296935] [client 52.139.36.144:30502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/file61.php"] [unique_id "al9PSSn25uliftkV1n40AwAAAGY"]
[Tue Jul 21 07:51:54.108660 2026] [security2:error] [pid 296703:tid 296914] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/redis/.env"] [unique_id "al9PSin25uliftkV1n40DAAAAFE"]
[Tue Jul 21 07:51:54.263090 2026] [security2:error] [pid 302018:tid 302194] [client 52.139.36.144:33062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp.php"] [unique_id "al9PSoAs9lPxxVAErz0RnAAAALE"]
[Tue Jul 21 07:51:54.412635 2026] [security2:error] [pid 302018:tid 302258] [client 185.198.240.6:52129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mbarcondicionados.com.br"] [uri "/wp-login.php"] [unique_id "al9PSoAs9lPxxVAErz0RngAAAPE"]
[Tue Jul 21 07:51:54.458204 2026] [security2:error] [pid 296703:tid 296920] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/elasticsearch/.env"] [unique_id "al9PSin25uliftkV1n40FwAAAFc"]
[Tue Jul 21 07:51:54.482693 2026] [security2:error] [pid 302018:tid 302134] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PSoAs9lPxxVAErz0RnwAA23E"]
[Tue Jul 21 07:51:54.482913 2026] [security2:error] [pid 302018:tid 302236] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PSoAs9lPxxVAErz0RnwAA23E"]
[Tue Jul 21 07:51:54.526271 2026] [security2:error] [pid 296703:tid 296929] [client 45.3.34.197:18393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.34.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PSin25uliftkV1n40EQAAAGA"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:51:54.710945 2026] [security2:error] [pid 302018:tid 302095] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PSoAs9lPxxVAErz0RpwAAj0o"]
[Tue Jul 21 07:51:54.711077 2026] [security2:error] [pid 302018:tid 302160] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PSoAs9lPxxVAErz0RpwAAj0o"]
[Tue Jul 21 07:51:54.745089 2026] [security2:error] [pid 302018:tid 302159] [client 106.215.181.8:28054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PSoAs9lPxxVAErz0RqQAAAI4"]
[Tue Jul 21 07:51:54.745261 2026] [security2:error] [pid 302018:tid 302159] [client 106.215.181.8:28054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PSoAs9lPxxVAErz0RqQAAAI4"]
[Tue Jul 21 07:51:54.761098 2026] [security2:error] [pid 296703:tid 296755] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PSin25uliftkV1n40JQAAczM"]
[Tue Jul 21 07:51:54.761239 2026] [security2:error] [pid 296703:tid 296948] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PSin25uliftkV1n40JQAAczM"]
[Tue Jul 21 07:51:54.779628 2026] [security2:error] [pid 296703:tid 296891] [client 20.104.96.117:64345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/nano.php"] [unique_id "al9PSin25uliftkV1n40JgAAADo"]
[Tue Jul 21 07:51:54.807122 2026] [security2:error] [pid 296703:tid 296879] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/rabbitmq/.env"] [unique_id "al9PSin25uliftkV1n40KAAAAC4"]
[Tue Jul 21 07:51:54.959947 2026] [security2:error] [pid 296703:tid 296947] [client 52.139.36.144:26070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-trackback.php"] [unique_id "al9PSin25uliftkV1n40KwAAAHI"]
[Tue Jul 21 07:51:55.155046 2026] [security2:error] [pid 296703:tid 296837] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/kafka/.env"] [unique_id "al9PSyn25uliftkV1n40MwAAAAQ"]
[Tue Jul 21 07:51:55.260754 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.260805 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.261579 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Globo-2.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.272840 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.272866 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.273147 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/IstoE.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.285966 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.285989 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.286192 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Terra.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.297933 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.297963 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.298174 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Caras.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.310680 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.310708 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.310908 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Contigo.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.322285 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.322305 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.322492 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Bons-Fluidos.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.334061 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.334081 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.334260 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Boa-Forma.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.346271 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.346289 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.346586 2026] [lsapi:warn] [pid 302018:tid 302250] [client 205.210.31.169:58628] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Lance.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 07:51:55.408743 2026] [security2:error] [pid 296703:tid 296916] [client 103.156.176.166:43836] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lojadedoces.com"] [uri "/wp-comments-post.php"] [unique_id "al9PSyn25uliftkV1n40MAAAAFM"]
[Tue Jul 21 07:51:55.409486 2026] [security2:error] [pid 302018:tid 302212] [client 20.220.225.223:32260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/koiy.php"] [unique_id "al9PS4As9lPxxVAErz0RsgAAAMM"]
[Tue Jul 21 07:51:55.503386 2026] [security2:error] [pid 296703:tid 296847] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/queue/.env"] [unique_id "al9PSyn25uliftkV1n40NQAAAA4"]
[Tue Jul 21 07:51:55.576005 2026] [security2:error] [pid 296703:tid 296916] [client 103.156.176.166:43836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "lojadedoces.com"] [uri "/wp-comments-post.php"] [unique_id "al9PSyn25uliftkV1n40MAAAAFM"]
[Tue Jul 21 07:51:55.853106 2026] [security2:error] [pid 296703:tid 296856] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/worker/.env"] [unique_id "al9PSyn25uliftkV1n40RwAAABc"]
[Tue Jul 21 07:51:55.882670 2026] [security2:error] [pid 296703:tid 296896] [client 103.253.27.198:57828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.27.253.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9PSin25uliftkV1n40JAAAAD8"]
[Tue Jul 21 07:51:55.911955 2026] [security2:error] [pid 296703:tid 296913] [client 193.36.225.62:21471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PSyn25uliftkV1n40SAAAAFA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:56.084445 2026] [access_compat:error] [pid 302018:tid 302162] [client 162.241.63.68:43278] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:51:56.105784 2026] [security2:error] [pid 302018:tid 302257] [client 20.197.192.193:9438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/phpinfo.php1"] [unique_id "al9PTIAs9lPxxVAErz0RwQAAAPA"]
[Tue Jul 21 07:51:56.196447 2026] [security2:error] [pid 296703:tid 296915] [client 20.104.96.117:64331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/moon.php"] [unique_id "al9PTCn25uliftkV1n40VgAAAFI"]
[Tue Jul 21 07:51:56.201741 2026] [security2:error] [pid 296703:tid 296937] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/job/.env"] [unique_id "al9PTCn25uliftkV1n40VwAAAGg"]
[Tue Jul 21 07:51:56.221823 2026] [security2:error] [pid 296703:tid 296862] [client 52.139.36.144:33043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/db.php"] [unique_id "al9PTCn25uliftkV1n40WAAAAB0"]
[Tue Jul 21 07:51:56.347007 2026] [security2:error] [pid 302018:tid 302260] [client 74.249.245.134:64393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/dropdown.php"] [unique_id "al9PTIAs9lPxxVAErz0RxQAAAPM"]
[Tue Jul 21 07:51:56.491248 2026] [security2:error] [pid 302018:tid 302193] [client 122.164.127.47:53257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PTIAs9lPxxVAErz0RxwAAALA"]
[Tue Jul 21 07:51:56.491365 2026] [security2:error] [pid 302018:tid 302193] [client 122.164.127.47:53257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PTIAs9lPxxVAErz0RxwAAALA"]
[Tue Jul 21 07:51:56.550148 2026] [security2:error] [pid 296703:tid 296942] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/test/.env"] [unique_id "al9PTCn25uliftkV1n40awAAAG0"]
[Tue Jul 21 07:51:56.898902 2026] [security2:error] [pid 296703:tid 296870] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/qa/.env"] [unique_id "al9PTCn25uliftkV1n40fwAAACU"]
[Tue Jul 21 07:51:56.905012 2026] [security2:error] [pid 302018:tid 302182] [client 41.68.90.219:49169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PTIAs9lPxxVAErz0RygAAAKU"]
[Tue Jul 21 07:51:56.906114 2026] [security2:error] [pid 302018:tid 302182] [client 41.68.90.219:49169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PTIAs9lPxxVAErz0RygAAAKU"]
[Tue Jul 21 07:51:56.967355 2026] [security2:error] [pid 302018:tid 302192] [client 20.197.192.193:27157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/mimpi.php"] [unique_id "al9PTIAs9lPxxVAErz0RywAAAK8"]
[Tue Jul 21 07:51:57.089612 2026] [security2:error] [pid 296703:tid 296836] [client 20.220.225.223:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9PTSn25uliftkV1n40hQAAAAM"]
[Tue Jul 21 07:51:57.248093 2026] [security2:error] [pid 296703:tid 296945] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/preview/.env"] [unique_id "al9PTSn25uliftkV1n40iwAAAHA"]
[Tue Jul 21 07:51:57.267965 2026] [security2:error] [pid 296703:tid 296897] [client 52.139.36.144:1269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/NewFile.php"] [unique_id "al9PTSn25uliftkV1n40kAAAAEA"]
[Tue Jul 21 07:51:57.597893 2026] [security2:error] [pid 296703:tid 296910] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/beta/.env"] [unique_id "al9PTSn25uliftkV1n40lgAAAE0"]
[Tue Jul 21 07:51:57.635191 2026] [security2:error] [pid 302018:tid 302245] [client 182.8.255.181:17675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PTYAs9lPxxVAErz0R0gAAAOQ"]
[Tue Jul 21 07:51:57.635601 2026] [security2:error] [pid 302018:tid 302245] [client 182.8.255.181:17675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PTYAs9lPxxVAErz0R0gAAAOQ"]
[Tue Jul 21 07:51:57.701760 2026] [security2:error] [pid 296703:tid 296783] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PTSn25uliftkV1n40mQAAZ08"]
[Tue Jul 21 07:51:57.701953 2026] [security2:error] [pid 296703:tid 296936] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PTSn25uliftkV1n40mQAAZ08"]
[Tue Jul 21 07:51:57.878854 2026] [security2:error] [pid 302018:tid 302151] [client 122.162.144.145:32435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PTYAs9lPxxVAErz0R1QAAAIY"]
[Tue Jul 21 07:51:57.878988 2026] [security2:error] [pid 302018:tid 302151] [client 122.162.144.145:32435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PTYAs9lPxxVAErz0R1QAAAIY"]
[Tue Jul 21 07:51:57.946909 2026] [security2:error] [pid 296703:tid 296915] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/uat/.env"] [unique_id "al9PTSn25uliftkV1n40nwAAAFI"]
[Tue Jul 21 07:51:57.970027 2026] [security2:error] [pid 302018:tid 302252] [client 20.226.60.151:56829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9PTYAs9lPxxVAErz0R2gAAAOs"]
[Tue Jul 21 07:51:57.977152 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977257 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977366 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977408 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977443 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977550 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977622 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977659 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977710 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977753 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977788 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977852 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977886 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977921 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977955 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.977991 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978025 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978060 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978095 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978129 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978163 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978198 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978232 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978266 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978300 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978335 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978369 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978404 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978487 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978523 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978557 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978591 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978626 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978660 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978694 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978736 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978771 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978807 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978862 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978896 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978945 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.978985 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979024 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979069 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979107 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979142 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979176 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979211 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979259 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979294 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979330 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979363 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979397 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979431 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979465 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979500 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979536 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979572 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979607 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979642 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979680 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979719 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979757 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979806 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979852 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979922 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.979975 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980013 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980047 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980085 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980123 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980162 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980202 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980236 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980270 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980305 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980339 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980373 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980407 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980442 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980477 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980512 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980546 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980580 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980614 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980649 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980684 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980725 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980760 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980795 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980840 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980886 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980947 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.980999 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.981043 2026] [lsapi:warn] [pid 302018:tid 302178] [client 52.45.9.143:5731] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 07:51:57.991506 2026] [security2:error] [pid 296703:tid 296937] [client 52.139.36.144:33141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/xxx.php"] [unique_id "al9PTSn25uliftkV1n40oQAAAGg"]
[Tue Jul 21 07:51:58.134347 2026] [security2:error] [pid 296703:tid 296838] [client 20.104.96.117:59746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-info.php"] [unique_id "al9PTin25uliftkV1n40pAAAAAU"]
[Tue Jul 21 07:51:58.218319 2026] [security2:error] [pid 302018:tid 302259] [client 202.143.127.214:57575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PToAs9lPxxVAErz0R5QAAAPI"]
[Tue Jul 21 07:51:58.218480 2026] [security2:error] [pid 302018:tid 302259] [client 202.143.127.214:57575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PToAs9lPxxVAErz0R5QAAAPI"]
[Tue Jul 21 07:51:58.295626 2026] [security2:error] [pid 296703:tid 296927] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/stage/.env"] [unique_id "al9PTin25uliftkV1n40qgAAAF4"]
[Tue Jul 21 07:51:58.387295 2026] [security2:error] [pid 296703:tid 296733] [remote 41.186.86.12:63921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tryhealth.shop"] [uri "/wp-login.php"] [unique_id "al9PTin25uliftkV1n40rgAAFB0"]
[Tue Jul 21 07:51:58.659881 2026] [security2:error] [pid 296703:tid 296839] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/development/.env"] [unique_id "al9PTin25uliftkV1n40sQAAAAY"]
[Tue Jul 21 07:51:58.853537 2026] [core:alert] [pid 296703:tid 296879] [client 57.141.18.122:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:51:58.911387 2026] [security2:error] [pid 296703:tid 296909] [client 103.166.103.129:36965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PTin25uliftkV1n40uAAAAEw"]
[Tue Jul 21 07:51:58.912412 2026] [security2:error] [pid 296703:tid 296909] [client 103.166.103.129:36965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PTin25uliftkV1n40uAAAAEw"]
[Tue Jul 21 07:51:58.913748 2026] [security2:error] [pid 302018:tid 302181] [client 52.139.36.144:1242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/ms.php"] [unique_id "al9PToAs9lPxxVAErz0R7gAAAKQ"]
[Tue Jul 21 07:51:58.941593 2026] [security2:error] [pid 302018:tid 302103] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PToAs9lPxxVAErz0R8AAAplI"]
[Tue Jul 21 07:51:58.941807 2026] [security2:error] [pid 302018:tid 302183] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PToAs9lPxxVAErz0R8AAAplI"]
[Tue Jul 21 07:51:58.952647 2026] [security2:error] [pid 302018:tid 302220] [client 20.226.60.151:61592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/byp.php"] [unique_id "al9PToAs9lPxxVAErz0R8QAAAMs"]
[Tue Jul 21 07:51:59.009827 2026] [security2:error] [pid 296703:tid 296887] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/production/.env"] [unique_id "al9PTyn25uliftkV1n40vQAAADY"]
[Tue Jul 21 07:51:59.258610 2026] [security2:error] [pid 302018:tid 302160] [client 223.236.153.128:3764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PT4As9lPxxVAErz0R-gAAAI8"]
[Tue Jul 21 07:51:59.261379 2026] [security2:error] [pid 302018:tid 302160] [client 223.236.153.128:3764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PT4As9lPxxVAErz0R-gAAAI8"]
[Tue Jul 21 07:51:59.359201 2026] [security2:error] [pid 296703:tid 296955] [client 54.251.12.30:35722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/config/app/.env"] [unique_id "al9PTyn25uliftkV1n40wwAAAHo"]
[Tue Jul 21 07:51:59.435415 2026] [security2:error] [pid 296703:tid 296906] [client 20.104.96.117:64303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/2000.php"] [unique_id "al9PTyn25uliftkV1n40xAAAAEk"]
[Tue Jul 21 07:51:59.451936 2026] [security2:error] [pid 302018:tid 302237] [client 193.36.225.69:42085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PT4As9lPxxVAErz0SCgAAANw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:51:59.553622 2026] [security2:error] [pid 302018:tid 302217] [client 128.127.105.184:34072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9PT4As9lPxxVAErz0SCwAAAMg"]
[Tue Jul 21 07:51:59.553745 2026] [security2:error] [pid 302018:tid 302217] [client 128.127.105.184:34072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9PT4As9lPxxVAErz0SCwAAAMg"]
[Tue Jul 21 07:51:59.684924 2026] [security2:error] [pid 296703:tid 296884] [client 103.86.117.203:50681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PTyn25uliftkV1n40xgAAADM"]
[Tue Jul 21 07:51:59.685111 2026] [security2:error] [pid 296703:tid 296884] [client 103.86.117.203:50681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PTyn25uliftkV1n40xgAAADM"]
[Tue Jul 21 07:51:59.710346 2026] [security2:error] [pid 296703:tid 296916] [client 54.251.12.30:35722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/phpinfo.php"] [unique_id "al9PTyn25uliftkV1n40xwAAAFM"]
[Tue Jul 21 07:51:59.835752 2026] [security2:error] [pid 302018:tid 302166] [client 20.226.60.151:56762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xyn.php"] [unique_id "al9PT4As9lPxxVAErz0SDAAAAJU"]
[Tue Jul 21 07:51:59.936983 2026] [security2:error] [pid 302018:tid 302200] [client 20.151.10.161:43982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/wp-links.php"] [unique_id "al9PT4As9lPxxVAErz0SDgAAALc"]
[Tue Jul 21 07:52:00.158922 2026] [security2:error] [pid 296703:tid 296843] [client 194.99.104.35:50658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9PUCn25uliftkV1n400wAAAAo"]
[Tue Jul 21 07:52:00.159044 2026] [security2:error] [pid 296703:tid 296843] [client 194.99.104.35:50658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9PUCn25uliftkV1n400wAAAAo"]
[Tue Jul 21 07:52:00.321000 2026] [security2:error] [pid 302018:tid 302179] [client 52.139.36.144:33137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/mini.php"] [unique_id "al9PUIAs9lPxxVAErz0SEwAAAKI"]
[Tue Jul 21 07:52:00.637848 2026] [security2:error] [pid 296703:tid 296937] [client 128.127.105.184:44216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9PUCn25uliftkV1n402QAAAGg"]
[Tue Jul 21 07:52:00.637954 2026] [security2:error] [pid 296703:tid 296937] [client 128.127.105.184:44216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9PUCn25uliftkV1n402QAAAGg"]
[Tue Jul 21 07:52:00.765620 2026] [security2:error] [pid 302018:tid 302229] [client 114.119.146.29:62369] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "avermetais.com.br"] [uri "/produto/florence/"] [unique_id "al9PUIAs9lPxxVAErz0SGwAAANQ"], referer: http://avermetais.com.br/produto/florence/
[Tue Jul 21 07:52:00.771747 2026] [security2:error] [pid 302018:tid 302193] [client 54.251.12.30:40610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/info.php"] [unique_id "al9PUIAs9lPxxVAErz0SHAAAALA"]
[Tue Jul 21 07:52:01.019245 2026] [security2:error] [pid 296703:tid 296926] [client 52.139.36.144:26095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/first.php"] [unique_id "al9PUSn25uliftkV1n403wAAAF0"]
[Tue Jul 21 07:52:01.220070 2026] [security2:error] [pid 302018:tid 302248] [client 178.153.91.96:40661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PUYAs9lPxxVAErz0SKQAAAOc"]
[Tue Jul 21 07:52:01.220216 2026] [security2:error] [pid 302018:tid 302248] [client 178.153.91.96:40661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PUYAs9lPxxVAErz0SKQAAAOc"]
[Tue Jul 21 07:52:01.265327 2026] [security2:error] [pid 296703:tid 296885] [client 20.220.225.223:23450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/dp.php"] [unique_id "al9PUSn25uliftkV1n404AAAADQ"]
[Tue Jul 21 07:52:01.296935 2026] [security2:error] [pid 302018:tid 302223] [client 74.249.245.134:24800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/bolt.php"] [unique_id "al9PUYAs9lPxxVAErz0SKwAAAM4"]
[Tue Jul 21 07:52:01.329563 2026] [security2:error] [pid 302018:tid 302151] [client 20.104.96.117:64272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/122.php"] [unique_id "al9PUYAs9lPxxVAErz0SLAAAAIY"]
[Tue Jul 21 07:52:01.452211 2026] [core:error] [pid 296703:tid 296811] [remote 43.228.157.40:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://webdisk.naldoinvest.com.br/
[Tue Jul 21 07:52:01.452238 2026] [core:error] [pid 296703:tid 296811] [remote 43.228.157.40:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://webdisk.naldoinvest.com.br/
[Tue Jul 21 07:52:01.479808 2026] [security2:error] [pid 302018:tid 302207] [client 109.60.28.94:62974] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PUYAs9lPxxVAErz0SMgAAAL4"]
[Tue Jul 21 07:52:01.480014 2026] [security2:error] [pid 302018:tid 302207] [client 109.60.28.94:62974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PUYAs9lPxxVAErz0SMgAAAL4"]
[Tue Jul 21 07:52:01.519397 2026] [security2:error] [pid 302018:tid 302209] [client 139.167.225.182:52187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PUYAs9lPxxVAErz0SMwAAAMA"]
[Tue Jul 21 07:52:01.519537 2026] [security2:error] [pid 302018:tid 302209] [client 139.167.225.182:52187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PUYAs9lPxxVAErz0SMwAAAMA"]
[Tue Jul 21 07:52:01.619264 2026] [security2:error] [pid 296703:tid 296911] [client 20.220.225.223:19297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/inso.php"] [unique_id "al9PUSn25uliftkV1n407AAAAE4"]
[Tue Jul 21 07:52:01.634467 2026] [security2:error] [pid 302018:tid 302263] [client 122.186.204.214:52460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PUYAs9lPxxVAErz0SNQAAAPY"]
[Tue Jul 21 07:52:01.634602 2026] [security2:error] [pid 302018:tid 302263] [client 122.186.204.214:52460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PUYAs9lPxxVAErz0SNQAAAPY"]
[Tue Jul 21 07:52:01.667393 2026] [security2:error] [pid 302018:tid 302074] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PUYAs9lPxxVAErz0SNwAA_zU"]
[Tue Jul 21 07:52:01.667557 2026] [security2:error] [pid 302018:tid 302272] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PUYAs9lPxxVAErz0SNwAA_zU"]
[Tue Jul 21 07:52:01.738007 2026] [security2:error] [pid 296703:tid 296909] [client 52.139.36.144:26090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/0okj.php"] [unique_id "al9PUSn25uliftkV1n407QAAAEw"]
[Tue Jul 21 07:52:01.777908 2026] [security2:error] [pid 302018:tid 302163] [client 173.24.185.52:65204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PUYAs9lPxxVAErz0SOQAAAJI"]
[Tue Jul 21 07:52:01.778060 2026] [security2:error] [pid 302018:tid 302163] [client 173.24.185.52:65204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PUYAs9lPxxVAErz0SOQAAAJI"]
[Tue Jul 21 07:52:01.797518 2026] [security2:error] [pid 302018:tid 302217] [client 54.251.12.30:40622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/php.php"] [unique_id "al9PUYAs9lPxxVAErz0SOgAAAMg"]
[Tue Jul 21 07:52:01.885933 2026] [security2:error] [pid 296703:tid 296862] [client 117.247.80.59:32171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PUSn25uliftkV1n407wAAAB0"]
[Tue Jul 21 07:52:01.886076 2026] [security2:error] [pid 296703:tid 296862] [client 117.247.80.59:32171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PUSn25uliftkV1n407wAAAB0"]
[Tue Jul 21 07:52:02.436184 2026] [security2:error] [pid 296703:tid 296908] [client 20.220.225.223:6092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/bootstrap.php"] [unique_id "al9PUin25uliftkV1n409gAAAEs"]
[Tue Jul 21 07:52:02.460618 2026] [security2:error] [pid 296703:tid 296725] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PUin25uliftkV1n409wAADBU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:02.503283 2026] [security2:error] [pid 296703:tid 296792] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PUin25uliftkV1n40-QAAQFg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:02.671049 2026] [security2:error] [pid 302018:tid 302165] [client 52.139.36.144:30576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/grsiuk.php"] [unique_id "al9PUoAs9lPxxVAErz0SbgAAAJQ"]
[Tue Jul 21 07:52:02.679911 2026] [security2:error] [pid 296703:tid 296928] [client 117.217.38.194:60696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PUin25uliftkV1n40_gAAAF8"]
[Tue Jul 21 07:52:02.680050 2026] [security2:error] [pid 296703:tid 296928] [client 117.217.38.194:60696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PUin25uliftkV1n40_gAAAF8"]
[Tue Jul 21 07:52:02.710737 2026] [security2:error] [pid 302018:tid 302045] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PUoAs9lPxxVAErz0ScQAA-Rg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:02.744992 2026] [security2:error] [pid 302018:tid 302199] [client 103.29.114.44:58997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PUoAs9lPxxVAErz0ScwAAALY"]
[Tue Jul 21 07:52:02.745108 2026] [security2:error] [pid 302018:tid 302199] [client 103.29.114.44:58997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PUoAs9lPxxVAErz0ScwAAALY"]
[Tue Jul 21 07:52:02.794677 2026] [security2:error] [pid 296703:tid 296795] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PUin25uliftkV1n41AQAADls"]
[Tue Jul 21 07:52:02.795011 2026] [security2:error] [pid 296703:tid 296847] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PUin25uliftkV1n41AQAADls"]
[Tue Jul 21 07:52:02.811558 2026] [security2:error] [pid 296703:tid 296837] [client 54.251.12.30:40626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/i.php"] [unique_id "al9PUin25uliftkV1n41AgAAAAQ"]
[Tue Jul 21 07:52:03.130411 2026] [security2:error] [pid 302018:tid 302115] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PU4As9lPxxVAErz0SeQAAy14"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:03.286824 2026] [security2:error] [pid 302018:tid 302213] [client 52.139.36.144:1278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/shell20211028.php"] [unique_id "al9PU4As9lPxxVAErz0SegAAAMQ"]
[Tue Jul 21 07:52:03.425884 2026] [security2:error] [pid 302018:tid 302085] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PUoAs9lPxxVAErz0SZwAA8EA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:03.452367 2026] [security2:error] [pid 302018:tid 302270] [client 20.104.96.117:64271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/mds.php"] [unique_id "al9PU4As9lPxxVAErz0SewAAAP0"]
[Tue Jul 21 07:52:03.481320 2026] [security2:error] [pid 296703:tid 296755] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PUyn25uliftkV1n41DQAADTM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:03.485294 2026] [security2:error] [pid 302018:tid 302249] [client 47.128.44.35:8870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "benattiodontologia.com.br"] [uri "/robots.txt"] [unique_id "al9PU4As9lPxxVAErz0SfAAAAOg"]
[Tue Jul 21 07:52:03.542312 2026] [security2:error] [pid 302018:tid 302124] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PU4As9lPxxVAErz0SfQAAzmc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:03.560581 2026] [security2:error] [pid 302018:tid 302170] [client 20.197.192.193:27171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/dp.php"] [unique_id "al9PU4As9lPxxVAErz0SfgAAAJk"]
[Tue Jul 21 07:52:03.572303 2026] [security2:error] [pid 296703:tid 296771] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PUyn25uliftkV1n41EgAAPkM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:03.737674 2026] [security2:error] [pid 302018:tid 302162] [client 20.226.60.151:56830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/patie.php"] [unique_id "al9PU4As9lPxxVAErz0ShQAAAJE"]
[Tue Jul 21 07:52:03.865653 2026] [security2:error] [pid 302018:tid 302264] [client 54.251.12.30:40642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/pi.php"] [unique_id "al9PU4As9lPxxVAErz0ShwAAAPc"]
[Tue Jul 21 07:52:03.953392 2026] [security2:error] [pid 302018:tid 302148] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PU4As9lPxxVAErz0SiAAAzH8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:03.974052 2026] [security2:error] [pid 296703:tid 296770] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PUyn25uliftkV1n41FwAAYEI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:03.978798 2026] [security2:error] [pid 296703:tid 296763] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PUyn25uliftkV1n41GAAAOzs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:04.015310 2026] [security2:error] [pid 302018:tid 302039] [remote 195.26.244.42:52558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9PVIAs9lPxxVAErz0SiQAA-BI"]
[Tue Jul 21 07:52:04.117298 2026] [security2:error] [pid 302018:tid 302156] [client 193.36.225.10:64811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PVIAs9lPxxVAErz0SjQAAAIs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:52:04.236307 2026] [security2:error] [pid 302018:tid 302209] [client 172.245.102.34:46171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PVIAs9lPxxVAErz0SigAAAMA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:52:04.282769 2026] [security2:error] [pid 302018:tid 302274] [client 74.249.245.134:64121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-links.php"] [unique_id "al9PVIAs9lPxxVAErz0SlAAAAQE"]
[Tue Jul 21 07:52:04.288733 2026] [security2:error] [pid 302018:tid 302233] [client 20.220.225.223:23434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/wp-editor.php"] [unique_id "al9PVIAs9lPxxVAErz0SlQAAANg"]
[Tue Jul 21 07:52:04.337803 2026] [autoindex:error] [pid 302018:tid 302234] [client 100.50.152.193:45407] AH01276: Cannot serve directory /home2/techkn33/marcomarafon.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:52:04.357469 2026] [security2:error] [pid 302018:tid 302027] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PVIAs9lPxxVAErz0SnQAArgY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:04.385997 2026] [security2:error] [pid 296703:tid 296779] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PVCn25uliftkV1n41HAAAcUs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:04.448276 2026] [security2:error] [pid 296703:tid 296759] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PVCn25uliftkV1n41HgAANDc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:04.459754 2026] [security2:error] [pid 296703:tid 296960] [client 52.139.36.144:33064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/revealability.php"] [unique_id "al9PVCn25uliftkV1n41HwAAAH8"]
[Tue Jul 21 07:52:04.520218 2026] [security2:error] [pid 302018:tid 311334] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PVIAs9lPxxVAErz0SnwAA04g"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:04.649307 2026] [security2:error] [pid 302018:tid 302266] [client 184.75.223.211:47666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9PVIAs9lPxxVAErz0SqAAAAPk"]
[Tue Jul 21 07:52:04.649412 2026] [security2:error] [pid 302018:tid 302266] [client 184.75.223.211:47666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9PVIAs9lPxxVAErz0SqAAAAPk"]
[Tue Jul 21 07:52:04.763476 2026] [security2:error] [pid 296703:tid 296919] [client 20.226.60.151:61607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9PVCn25uliftkV1n41IwAAAFY"]
[Tue Jul 21 07:52:04.764043 2026] [security2:error] [pid 302018:tid 302106] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PVIAs9lPxxVAErz0SqwAAnFU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:04.849592 2026] [security2:error] [pid 296703:tid 296829] [remote 103.170.123.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.123.170.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9PVCn25uliftkV1n41JAAAE30"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:52:04.891058 2026] [security2:error] [pid 302018:tid 302230] [client 54.251.12.30:40656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/pinfo.php"] [unique_id "al9PVIAs9lPxxVAErz0SswAAANU"]
[Tue Jul 21 07:52:05.141903 2026] [security2:error] [pid 302018:tid 302108] [remote 209.97.182.179:44940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "links.principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9PVYAs9lPxxVAErz0StQAAy1c"]
[Tue Jul 21 07:52:05.174184 2026] [security2:error] [pid 302018:tid 302223] [client 52.139.36.144:28728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/btx25.php"] [unique_id "al9PVYAs9lPxxVAErz0SuAAAAM4"]
[Tue Jul 21 07:52:05.208535 2026] [security2:error] [pid 296703:tid 296813] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PVSn25uliftkV1n41KQAAe20"]
[Tue Jul 21 07:52:05.208706 2026] [security2:error] [pid 296703:tid 296956] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PVSn25uliftkV1n41KQAAe20"]
[Tue Jul 21 07:52:05.211485 2026] [security2:error] [pid 302018:tid 302244] [client 106.215.181.8:29511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PVYAs9lPxxVAErz0SugAAAOM"]
[Tue Jul 21 07:52:05.211583 2026] [security2:error] [pid 302018:tid 302244] [client 106.215.181.8:29511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PVYAs9lPxxVAErz0SugAAAOM"]
[Tue Jul 21 07:52:05.233092 2026] [security2:error] [pid 302018:tid 302151] [client 20.104.96.117:64340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-blink.php"] [unique_id "al9PVYAs9lPxxVAErz0SuwAAAIY"]
[Tue Jul 21 07:52:05.338561 2026] [security2:error] [pid 296703:tid 296827] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PVSn25uliftkV1n41LgAATns"]
[Tue Jul 21 07:52:05.338742 2026] [security2:error] [pid 296703:tid 296911] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PVSn25uliftkV1n41LgAATns"]
[Tue Jul 21 07:52:05.799619 2026] [security2:error] [pid 302018:tid 302217] [client 74.249.245.134:18446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/x.php"] [unique_id "al9PVYAs9lPxxVAErz0SygAAAMg"]
[Tue Jul 21 07:52:05.811366 2026] [security2:error] [pid 296703:tid 296788] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PVSn25uliftkV1n41MwAAAlQ"]
[Tue Jul 21 07:52:05.811522 2026] [security2:error] [pid 296703:tid 296835] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PVSn25uliftkV1n41MwAAAlQ"]
[Tue Jul 21 07:52:05.817167 2026] [security2:error] [pid 302018:tid 302219] [client 20.220.225.223:23483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/cro.php"] [unique_id "al9PVYAs9lPxxVAErz0SywAAAMo"]
[Tue Jul 21 07:52:05.869154 2026] [security2:error] [pid 302018:tid 302274] [client 52.139.36.144:26137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/bthil.php"] [unique_id "al9PVYAs9lPxxVAErz0SzQAAAQE"]
[Tue Jul 21 07:52:05.949238 2026] [security2:error] [pid 296703:tid 296842] [client 54.251.12.30:51226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/test.php"] [unique_id "al9PVSn25uliftkV1n41NgAAAAk"]
[Tue Jul 21 07:52:06.026707 2026] [security2:error] [pid 302018:tid 302240] [client 20.104.96.117:64324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/zc-208.php"] [unique_id "al9PVoAs9lPxxVAErz0S0AAAAN8"]
[Tue Jul 21 07:52:06.427507 2026] [security2:error] [pid 302018:tid 302160] [client 65.111.24.141:62849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PVYAs9lPxxVAErz0SvAAAAI8"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:52:06.535494 2026] [security2:error] [pid 302018:tid 302165] [client 52.139.36.144:30554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/hplfuns.php"] [unique_id "al9PVoAs9lPxxVAErz0S2AAAAJQ"]
[Tue Jul 21 07:52:06.571093 2026] [security2:error] [pid 302018:tid 302266] [client 20.197.192.193:27095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/bootstrap.php"] [unique_id "al9PVoAs9lPxxVAErz0S2gAAAPk"]
[Tue Jul 21 07:52:06.620449 2026] [security2:error] [pid 302018:tid 302262] [client 185.213.175.37:58486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "astrosyasmin.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PVYAs9lPxxVAErz0SwAAAAPU"]
[Tue Jul 21 07:52:06.656582 2026] [security2:error] [pid 302018:tid 302241] [client 20.220.225.223:31719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/hp2.php"] [unique_id "al9PVoAs9lPxxVAErz0S3AAAAOA"]
[Tue Jul 21 07:52:06.759909 2026] [security2:error] [pid 302018:tid 302181] [client 20.104.96.117:64262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/sid4.php"] [unique_id "al9PVoAs9lPxxVAErz0S4wAAAKQ"]
[Tue Jul 21 07:52:06.895275 2026] [security2:error] [pid 302018:tid 302222] [client 193.36.225.120:64761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PVoAs9lPxxVAErz0S4QAAAM0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:52:06.987412 2026] [security2:error] [pid 296703:tid 296887] [client 122.164.127.47:53834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PVin25uliftkV1n41QQAAADY"]
[Tue Jul 21 07:52:06.987565 2026] [security2:error] [pid 296703:tid 296887] [client 122.164.127.47:53834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PVin25uliftkV1n41QQAAADY"]
[Tue Jul 21 07:52:07.175623 2026] [security2:error] [pid 296703:tid 296902] [client 52.139.36.144:1208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/error.php"] [unique_id "al9PVyn25uliftkV1n41QwAAAEU"]
[Tue Jul 21 07:52:07.347139 2026] [security2:error] [pid 302018:tid 302176] [client 54.251.12.30:51242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/p.php"] [unique_id "al9PV4As9lPxxVAErz0S7QAAAJ8"]
[Tue Jul 21 07:52:07.509542 2026] [security2:error] [pid 296703:tid 296925] [client 45.3.48.75:35965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.48.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PVyn25uliftkV1n41TAAAAFw"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:52:07.529739 2026] [security2:error] [pid 296703:tid 296837] [client 41.68.90.219:49618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PVyn25uliftkV1n41TQAAAAQ"]
[Tue Jul 21 07:52:07.530738 2026] [security2:error] [pid 296703:tid 296837] [client 41.68.90.219:49618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PVyn25uliftkV1n41TQAAAAQ"]
[Tue Jul 21 07:52:07.546343 2026] [security2:error] [pid 302018:tid 302192] [client 193.36.225.66:20325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PV4As9lPxxVAErz0S_wAAAK8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:52:07.632754 2026] [security2:error] [pid 302018:tid 302225] [client 74.249.245.134:64112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/jga.php"] [unique_id "al9PV4As9lPxxVAErz0TAAAAANA"]
[Tue Jul 21 07:52:07.901883 2026] [security2:error] [pid 296703:tid 296843] [client 20.104.96.117:64288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wmore1.php"] [unique_id "al9PVyn25uliftkV1n41UgAAAAo"]
[Tue Jul 21 07:52:07.905067 2026] [security2:error] [pid 296703:tid 296864] [client 52.139.36.144:26111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/edit.php"] [unique_id "al9PVyn25uliftkV1n41UwAAAB8"]
[Tue Jul 21 07:52:08.067754 2026] [security2:error] [pid 302018:tid 302150] [client 182.8.255.181:17582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PWIAs9lPxxVAErz0TDAAAAIU"]
[Tue Jul 21 07:52:08.067955 2026] [security2:error] [pid 302018:tid 302150] [client 182.8.255.181:17582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PWIAs9lPxxVAErz0TDAAAAIU"]
[Tue Jul 21 07:52:08.223213 2026] [security2:error] [pid 302018:tid 302168] [client 52.139.36.144:24930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/pass4.php"] [unique_id "al9PWIAs9lPxxVAErz0TDgAAAJc"]
[Tue Jul 21 07:52:08.384584 2026] [security2:error] [pid 302018:tid 302079] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PWIAs9lPxxVAErz0TEwAA1To"]
[Tue Jul 21 07:52:08.384770 2026] [security2:error] [pid 302018:tid 302230] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PWIAs9lPxxVAErz0TEwAA1To"]
[Tue Jul 21 07:52:08.406617 2026] [security2:error] [pid 296703:tid 296929] [client 54.251.12.30:51250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/debug.php"] [unique_id "al9PWCn25uliftkV1n41YAAAAGA"]
[Tue Jul 21 07:52:08.643798 2026] [security2:error] [pid 296703:tid 296851] [client 20.104.96.117:60686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/solo1.php"] [unique_id "al9PWCn25uliftkV1n41YgAAABI"]
[Tue Jul 21 07:52:08.719091 2026] [security2:error] [pid 302018:tid 302266] [client 122.162.144.145:6039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PWIAs9lPxxVAErz0TFQAAAPk"]
[Tue Jul 21 07:52:08.719233 2026] [security2:error] [pid 302018:tid 302266] [client 122.162.144.145:6039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PWIAs9lPxxVAErz0TFQAAAPk"]
[Tue Jul 21 07:52:08.790533 2026] [security2:error] [pid 296703:tid 296891] [client 20.220.225.223:59810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/hp3.php"] [unique_id "al9PWCn25uliftkV1n41ZQAAADo"]
[Tue Jul 21 07:52:08.793889 2026] [security2:error] [pid 296703:tid 296956] [client 52.139.36.144:33127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/sadcut1.php"] [unique_id "al9PWCn25uliftkV1n41ZgAAAHs"]
[Tue Jul 21 07:52:08.979943 2026] [security2:error] [pid 302018:tid 302195] [client 104.207.55.26:49191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.55.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PWIAs9lPxxVAErz0THAAAALI"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:52:09.012883 2026] [security2:error] [pid 296703:tid 296833] [client 20.220.225.223:52202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/cron-tab.php"] [unique_id "al9PWSn25uliftkV1n41bQAAAAA"]
[Tue Jul 21 07:52:09.162207 2026] [security2:error] [pid 302018:tid 302159] [client 20.197.192.193:27198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/wp-editor.php"] [unique_id "al9PWYAs9lPxxVAErz0THQAAAI4"]
[Tue Jul 21 07:52:09.300705 2026] [security2:error] [pid 296703:tid 296955] [client 74.249.245.134:24787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/k.php"] [unique_id "al9PWSn25uliftkV1n41cQAAAHo"]
[Tue Jul 21 07:52:09.302582 2026] [security2:error] [pid 296703:tid 296917] [client 202.143.127.214:58068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PWSn25uliftkV1n41cgAAAFQ"]
[Tue Jul 21 07:52:09.303213 2026] [security2:error] [pid 296703:tid 296917] [client 202.143.127.214:58068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PWSn25uliftkV1n41cgAAAFQ"]
[Tue Jul 21 07:52:09.366934 2026] [security2:error] [pid 302018:tid 302179] [client 52.139.36.144:26171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/bgymj.php"] [unique_id "al9PWYAs9lPxxVAErz0TJAAAAKI"]
[Tue Jul 21 07:52:09.410721 2026] [security2:error] [pid 302018:tid 302264] [client 202.137.142.173:57171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.142.137.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homemsedutoronline.com"] [uri "/xmlrpc.php"] [unique_id "al9PWYAs9lPxxVAErz0TKAAAAPc"]
[Tue Jul 21 07:52:09.410869 2026] [security2:error] [pid 302018:tid 302264] [client 202.137.142.173:57171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "homemsedutoronline.com"] [uri "/xmlrpc.php"] [unique_id "al9PWYAs9lPxxVAErz0TKAAAAPc"]
[Tue Jul 21 07:52:09.451691 2026] [security2:error] [pid 302018:tid 302265] [client 54.251.12.30:51262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/admin/phpinfo.php"] [unique_id "al9PWYAs9lPxxVAErz0TKQAAAPg"]
[Tue Jul 21 07:52:09.658073 2026] [core:error] [pid 302018:tid 302028] [remote 87.250.224.211:58606] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:52:09.658097 2026] [core:error] [pid 302018:tid 302028] [remote 87.250.224.211:58606] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:52:09.679788 2026] [security2:error] [pid 296703:tid 296728] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PWSn25uliftkV1n41eQAAZRg"]
[Tue Jul 21 07:52:09.680096 2026] [security2:error] [pid 296703:tid 296934] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PWSn25uliftkV1n41eQAAZRg"]
[Tue Jul 21 07:52:09.708664 2026] [security2:error] [pid 302018:tid 302221] [client 103.166.103.129:37573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PWYAs9lPxxVAErz0TKwAAAMw"]
[Tue Jul 21 07:52:09.708843 2026] [security2:error] [pid 302018:tid 302221] [client 103.166.103.129:37573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PWYAs9lPxxVAErz0TKwAAAMw"]
[Tue Jul 21 07:52:09.860426 2026] [security2:error] [pid 302018:tid 302229] [client 52.139.36.144:24906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/yas.php"] [unique_id "al9PWYAs9lPxxVAErz0TLwAAANQ"]
[Tue Jul 21 07:52:09.872667 2026] [security2:error] [pid 302018:tid 302172] [client 223.236.153.128:16045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PWYAs9lPxxVAErz0TMAAAAJs"]
[Tue Jul 21 07:52:09.872809 2026] [security2:error] [pid 302018:tid 302172] [client 223.236.153.128:16045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PWYAs9lPxxVAErz0TMAAAAJs"]
[Tue Jul 21 07:52:10.167646 2026] [security2:error] [pid 302018:tid 302248] [client 62.102.148.187:37112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9PWoAs9lPxxVAErz0TOQAAAOc"]
[Tue Jul 21 07:52:10.167777 2026] [security2:error] [pid 302018:tid 302248] [client 62.102.148.187:37112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9PWoAs9lPxxVAErz0TOQAAAOc"]
[Tue Jul 21 07:52:10.180617 2026] [security2:error] [pid 296703:tid 296872] [client 103.86.117.203:51448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PWin25uliftkV1n41gAAAACc"]
[Tue Jul 21 07:52:10.180838 2026] [security2:error] [pid 296703:tid 296872] [client 103.86.117.203:51448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PWin25uliftkV1n41gAAAACc"]
[Tue Jul 21 07:52:10.400980 2026] [security2:error] [pid 302018:tid 302266] [client 52.139.36.144:33103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/dx.php"] [unique_id "al9PWoAs9lPxxVAErz0TPQAAAPk"]
[Tue Jul 21 07:52:10.488460 2026] [security2:error] [pid 302018:tid 302243] [client 54.251.12.30:51264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/test/phpinfo.php"] [unique_id "al9PWoAs9lPxxVAErz0TPgAAAOI"]
[Tue Jul 21 07:52:10.919629 2026] [security2:error] [pid 302018:tid 302200] [client 52.139.36.144:26126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/yellow.php"] [unique_id "al9PWoAs9lPxxVAErz0TRAAAALc"]
[Tue Jul 21 07:52:10.928765 2026] [security2:error] [pid 302018:tid 302263] [client 184.75.223.211:52320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9PWoAs9lPxxVAErz0TRQAAAPY"]
[Tue Jul 21 07:52:10.928847 2026] [security2:error] [pid 302018:tid 302263] [client 184.75.223.211:52320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9PWoAs9lPxxVAErz0TRQAAAPY"]
[Tue Jul 21 07:52:10.966008 2026] [security2:error] [pid 302018:tid 302179] [client 20.104.96.117:60675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/cong.php"] [unique_id "al9PWoAs9lPxxVAErz0TSwAAAKI"]
[Tue Jul 21 07:52:10.993081 2026] [proxy:error] [pid 302018:tid 302192] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:10.993164 2026] [proxy_http:error] [pid 302018:tid 302192] [client 205.210.31.24:62194] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:52:10.994514 2026] [proxy:error] [pid 302018:tid 302192] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:10.994575 2026] [proxy_http:error] [pid 302018:tid 302192] [client 205.210.31.24:62194] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:52:11.195386 2026] [security2:error] [pid 302018:tid 302197] [client 74.249.245.134:24817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/vx.php"] [unique_id "al9PW4As9lPxxVAErz0TUQAAALQ"]
[Tue Jul 21 07:52:11.341493 2026] [security2:error] [pid 296703:tid 296929] [client 20.197.192.193:27089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/cro.php"] [unique_id "al9PWyn25uliftkV1n41kQAAAGA"]
[Tue Jul 21 07:52:11.441983 2026] [security2:error] [pid 302018:tid 302187] [client 52.139.36.144:28699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/wp-der.php"] [unique_id "al9PW4As9lPxxVAErz0TVwAAAKo"]
[Tue Jul 21 07:52:11.507023 2026] [security2:error] [pid 302018:tid 302265] [client 54.251.12.30:51276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/dev/phpinfo.php"] [unique_id "al9PW4As9lPxxVAErz0TWwAAAPg"]
[Tue Jul 21 07:52:11.594369 2026] [security2:error] [pid 302018:tid 302260] [client 74.249.245.134:64441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/xmrlpc.php"] [unique_id "al9PW4As9lPxxVAErz0TXAAAAPM"]
[Tue Jul 21 07:52:11.754891 2026] [security2:error] [pid 302018:tid 302234] [client 20.104.96.117:64369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/public/css.php"] [unique_id "al9PW4As9lPxxVAErz0TXgAAANk"]
[Tue Jul 21 07:52:11.815360 2026] [security2:error] [pid 302018:tid 302264] [client 178.153.91.96:59810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PW4As9lPxxVAErz0TYAAAAPc"]
[Tue Jul 21 07:52:11.815487 2026] [security2:error] [pid 302018:tid 302264] [client 178.153.91.96:59810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PW4As9lPxxVAErz0TYAAAAPc"]
[Tue Jul 21 07:52:11.864042 2026] [security2:error] [pid 302018:tid 302129] [remote 85.204.70.94:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "naldoinvest.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9PW4As9lPxxVAErz0TYQAA9Ww"]
[Tue Jul 21 07:52:11.949106 2026] [security2:error] [pid 302018:tid 302199] [client 52.139.36.144:26068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/lala.php"] [unique_id "al9PW4As9lPxxVAErz0TYgAAALY"]
[Tue Jul 21 07:52:11.978036 2026] [security2:error] [pid 302018:tid 302213] [client 20.220.225.223:56079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/aa1.php"] [unique_id "al9PW4As9lPxxVAErz0TYwAAAMQ"]
[Tue Jul 21 07:52:12.007625 2026] [security2:error] [pid 302018:tid 302097] [remote 85.204.70.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naldoinvest.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXIAs9lPxxVAErz0TZgAAqEw"]
[Tue Jul 21 07:52:12.108118 2026] [security2:error] [pid 302018:tid 302221] [client 139.167.225.182:52840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXIAs9lPxxVAErz0TawAAAMw"]
[Tue Jul 21 07:52:12.108230 2026] [security2:error] [pid 302018:tid 302221] [client 139.167.225.182:52840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXIAs9lPxxVAErz0TawAAAMw"]
[Tue Jul 21 07:52:12.180681 2026] [security2:error] [pid 302018:tid 302150] [client 109.60.28.94:63376] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXIAs9lPxxVAErz0TbwAAAIU"]
[Tue Jul 21 07:52:12.180857 2026] [security2:error] [pid 302018:tid 302150] [client 109.60.28.94:63376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXIAs9lPxxVAErz0TbwAAAIU"]
[Tue Jul 21 07:52:12.252473 2026] [security2:error] [pid 302018:tid 302218] [client 127.0.0.1:46058] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al9PXIAs9lPxxVAErz0TcAAAAMk"]
[Tue Jul 21 07:52:12.252544 2026] [security2:error] [pid 296703:tid 296833] [client 74.7.244.48:42508] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.goldentrips40.com"] [uri "/robots.txt"] [unique_id "al9PXCn25uliftkV1n41ngAAADY"]
[Tue Jul 21 07:52:12.370373 2026] [security2:error] [pid 296703:tid 296839] [client 117.247.80.59:28041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXCn25uliftkV1n41oAAAAAY"]
[Tue Jul 21 07:52:12.370508 2026] [security2:error] [pid 296703:tid 296839] [client 117.247.80.59:28041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXCn25uliftkV1n41oAAAAAY"]
[Tue Jul 21 07:52:12.379081 2026] [security2:error] [pid 302018:tid 302168] [client 122.186.204.214:53093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PXIAs9lPxxVAErz0TcgAAAJc"]
[Tue Jul 21 07:52:12.379232 2026] [security2:error] [pid 302018:tid 302168] [client 122.186.204.214:53093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PXIAs9lPxxVAErz0TcgAAAJc"]
[Tue Jul 21 07:52:12.392015 2026] [security2:error] [pid 302018:tid 302170] [client 173.24.185.52:49372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PXIAs9lPxxVAErz0TdgAAAJk"]
[Tue Jul 21 07:52:12.392165 2026] [security2:error] [pid 302018:tid 302170] [client 173.24.185.52:49372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PXIAs9lPxxVAErz0TdgAAAJk"]
[Tue Jul 21 07:52:12.460880 2026] [security2:error] [pid 302018:tid 302203] [client 20.104.96.117:64377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/output.php"] [unique_id "al9PXIAs9lPxxVAErz0TewAAALo"]
[Tue Jul 21 07:52:12.519641 2026] [security2:error] [pid 296703:tid 296955] [client 52.139.36.144:26066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.36.139.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.arthromdcanada.online"] [uri "/aa.php"] [unique_id "al9PXCn25uliftkV1n41pQAAAHo"]
[Tue Jul 21 07:52:12.534901 2026] [security2:error] [pid 302018:tid 302207] [client 54.251.12.30:51292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/old/phpinfo.php"] [unique_id "al9PXIAs9lPxxVAErz0TfAAAAL4"]
[Tue Jul 21 07:52:12.538513 2026] [security2:error] [pid 302018:tid 302142] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXIAs9lPxxVAErz0TfQAAoXk"]
[Tue Jul 21 07:52:12.538644 2026] [security2:error] [pid 302018:tid 302178] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXIAs9lPxxVAErz0TfQAAoXk"]
[Tue Jul 21 07:52:12.561459 2026] [security2:error] [pid 296703:tid 296868] [client 20.226.60.151:56722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/aa.php"] [unique_id "al9PXCn25uliftkV1n41qAAAACM"]
[Tue Jul 21 07:52:12.978917 2026] [security2:error] [pid 296703:tid 296859] [client 193.36.225.62:27045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PWyn25uliftkV1n41mAAAABo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:52:13.055268 2026] [security2:error] [pid 302018:tid 302155] [client 193.36.225.104:25285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PXYAs9lPxxVAErz0TjgAAAIo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:52:13.222053 2026] [security2:error] [pid 302018:tid 302233] [client 117.217.38.194:61195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXYAs9lPxxVAErz0TkgAAANg"]
[Tue Jul 21 07:52:13.222247 2026] [security2:error] [pid 302018:tid 302233] [client 117.217.38.194:61195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXYAs9lPxxVAErz0TkgAAANg"]
[Tue Jul 21 07:52:13.315026 2026] [security2:error] [pid 302018:tid 302138] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXYAs9lPxxVAErz0TlgAA5XU"]
[Tue Jul 21 07:52:13.315146 2026] [security2:error] [pid 302018:tid 302246] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXYAs9lPxxVAErz0TlgAA5XU"]
[Tue Jul 21 07:52:13.434352 2026] [security2:error] [pid 302018:tid 302235] [client 128.127.105.184:37200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PXYAs9lPxxVAErz0TlwAAANo"]
[Tue Jul 21 07:52:13.434463 2026] [security2:error] [pid 302018:tid 302235] [client 128.127.105.184:37200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PXYAs9lPxxVAErz0TlwAAANo"]
[Tue Jul 21 07:52:13.439395 2026] [security2:error] [pid 302018:tid 302196] [client 103.29.114.44:6559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXYAs9lPxxVAErz0TmQAAALM"]
[Tue Jul 21 07:52:13.439525 2026] [security2:error] [pid 302018:tid 302196] [client 103.29.114.44:6559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXYAs9lPxxVAErz0TmQAAALM"]
[Tue Jul 21 07:52:13.444087 2026] [security2:error] [pid 302018:tid 302271] [client 20.197.192.193:27150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/cron-tab.php"] [unique_id "al9PXYAs9lPxxVAErz0TmgAAAP4"]
[Tue Jul 21 07:52:13.524465 2026] [proxy:error] [pid 302018:tid 302223] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:13.524539 2026] [proxy_http:error] [pid 302018:tid 302223] [client 147.182.225.118:51446] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:52:13.525083 2026] [proxy:error] [pid 302018:tid 302223] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:13.525113 2026] [proxy_http:error] [pid 302018:tid 302223] [client 147.182.225.118:51446] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:52:13.557288 2026] [security2:error] [pid 302018:tid 302245] [client 54.251.12.30:51298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/tmp/phpinfo.php"] [unique_id "al9PXYAs9lPxxVAErz0TnwAAAOQ"]
[Tue Jul 21 07:52:13.604857 2026] [security2:error] [pid 302018:tid 302074] [remote 45.3.46.64:29497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9PXYAs9lPxxVAErz0TmAAAkDU"]
[Tue Jul 21 07:52:13.628453 2026] [security2:error] [pid 302018:tid 302208] [client 20.104.96.117:59757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-file-120.php"] [unique_id "al9PXYAs9lPxxVAErz0ToQAAAL8"]
[Tue Jul 21 07:52:13.649495 2026] [security2:error] [pid 302018:tid 302268] [client 20.220.225.223:31732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/acew67.php"] [unique_id "al9PXYAs9lPxxVAErz0TogAAAPs"]
[Tue Jul 21 07:52:13.711801 2026] [security2:error] [pid 302018:tid 302063] [remote 85.204.70.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naldoinvest.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXYAs9lPxxVAErz0TowAAlyo"]
[Tue Jul 21 07:52:13.712014 2026] [security2:error] [pid 302018:tid 302168] [client 85.204.70.94:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "naldoinvest.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PXYAs9lPxxVAErz0TowAAlyo"]
[Tue Jul 21 07:52:13.901888 2026] [proxy:error] [pid 302018:tid 302156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:13.901979 2026] [proxy_http:error] [pid 302018:tid 302156] [client 147.182.225.118:51450] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.memoriabalaiodaoxum.com.br/
[Tue Jul 21 07:52:13.903163 2026] [proxy:error] [pid 302018:tid 302156] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:13.903230 2026] [proxy_http:error] [pid 302018:tid 302156] [client 147.182.225.118:51450] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.memoriabalaiodaoxum.com.br/
[Tue Jul 21 07:52:14.332691 2026] [security2:error] [pid 296703:tid 296925] [client 74.249.245.134:64412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/htaccess.php"] [unique_id "al9PXin25uliftkV1n41vgAAAFw"]
[Tue Jul 21 07:52:14.467267 2026] [security2:error] [pid 302018:tid 302170] [client 122.179.91.63:26131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PXoAs9lPxxVAErz0TrAAAAJk"]
[Tue Jul 21 07:52:14.467375 2026] [security2:error] [pid 302018:tid 302170] [client 122.179.91.63:26131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PXoAs9lPxxVAErz0TrAAAAJk"]
[Tue Jul 21 07:52:14.549473 2026] [security2:error] [pid 302018:tid 302189] [client 184.75.223.211:53964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.223.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9PXoAs9lPxxVAErz0TrwAAAKw"]
[Tue Jul 21 07:52:14.549583 2026] [security2:error] [pid 302018:tid 302189] [client 184.75.223.211:53964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9PXoAs9lPxxVAErz0TrwAAAKw"]
[Tue Jul 21 07:52:14.589237 2026] [security2:error] [pid 302018:tid 302229] [client 20.104.96.117:59735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/special.php"] [unique_id "al9PXoAs9lPxxVAErz0TsQAAANQ"]
[Tue Jul 21 07:52:14.601455 2026] [security2:error] [pid 302018:tid 302178] [client 54.251.12.30:51300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/public/phpinfo.php"] [unique_id "al9PXoAs9lPxxVAErz0TsgAAAKE"]
[Tue Jul 21 07:52:14.645351 2026] [core:error] [pid 296703:tid 296898] [client 147.182.225.118:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:52:14.645370 2026] [core:error] [pid 296703:tid 296898] [client 147.182.225.118:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:52:14.682284 2026] [security2:error] [pid 296703:tid 296876] [client 20.197.192.193:27101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/koiy.php"] [unique_id "al9PXin25uliftkV1n41yAAAACs"]
[Tue Jul 21 07:52:15.725180 2026] [security2:error] [pid 302018:tid 302255] [client 106.215.181.8:13966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PX4As9lPxxVAErz0TxgAAAO4"]
[Tue Jul 21 07:52:15.725339 2026] [security2:error] [pid 302018:tid 302255] [client 106.215.181.8:13966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PX4As9lPxxVAErz0TxgAAAO4"]
[Tue Jul 21 07:52:15.749325 2026] [security2:error] [pid 296703:tid 296900] [client 20.151.10.161:43978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.olimposolar.com.br"] [uri "/aaa.php"] [unique_id "al9PXyn25uliftkV1n412QAAAEM"]
[Tue Jul 21 07:52:15.797891 2026] [security2:error] [pid 296703:tid 296947] [client 20.197.192.193:27137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/hp2.php"] [unique_id "al9PXyn25uliftkV1n412wAAAHI"]
[Tue Jul 21 07:52:15.921177 2026] [security2:error] [pid 296703:tid 296795] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PXyn25uliftkV1n413wAAMls"]
[Tue Jul 21 07:52:15.921334 2026] [security2:error] [pid 296703:tid 296883] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PXyn25uliftkV1n413wAAMls"]
[Tue Jul 21 07:52:15.962715 2026] [security2:error] [pid 296703:tid 296833] [client 54.251.12.30:51308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/php-info.php"] [unique_id "al9PXyn25uliftkV1n414QAAAAA"]
[Tue Jul 21 07:52:16.002614 2026] [security2:error] [pid 296703:tid 296794] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PYCn25uliftkV1n415gAAOlo"]
[Tue Jul 21 07:52:16.002832 2026] [security2:error] [pid 296703:tid 296891] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PYCn25uliftkV1n415gAAOlo"]
[Tue Jul 21 07:52:16.040039 2026] [security2:error] [pid 302018:tid 302176] [client 20.226.60.151:61548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/classwithtostring.php"] [unique_id "al9PYIAs9lPxxVAErz0TygAAAJ8"]
[Tue Jul 21 07:52:16.129257 2026] [security2:error] [pid 296703:tid 296845] [client 20.220.225.223:23452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/koiy.php"] [unique_id "al9PYCn25uliftkV1n417QAAAAw"]
[Tue Jul 21 07:52:16.154273 2026] [security2:error] [pid 302018:tid 302150] [client 20.197.192.193:27076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/hp3.php"] [unique_id "al9PYIAs9lPxxVAErz0TzwAAAIU"]
[Tue Jul 21 07:52:16.215915 2026] [autoindex:error] [pid 302018:tid 302168] [client 44.223.102.150:63337] AH01276: Cannot serve directory /home1/imperd48/sabino-tracker.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.google.com/
[Tue Jul 21 07:52:16.251810 2026] [security2:error] [pid 302018:tid 302267] [client 20.197.192.193:27175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/aa1.php"] [unique_id "al9PYIAs9lPxxVAErz0T1wAAAPo"]
[Tue Jul 21 07:52:16.361885 2026] [security2:error] [pid 302018:tid 302219] [client 20.104.96.117:64367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/as.php"] [unique_id "al9PYIAs9lPxxVAErz0T3gAAAMo"]
[Tue Jul 21 07:52:16.423720 2026] [security2:error] [pid 296703:tid 296887] [client 20.226.60.151:56708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xwpg.php"] [unique_id "al9PYCn25uliftkV1n418wAAADY"]
[Tue Jul 21 07:52:16.454671 2026] [security2:error] [pid 302018:tid 302191] [client 194.99.104.35:57680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9PYIAs9lPxxVAErz0T4gAAAK4"]
[Tue Jul 21 07:52:16.454781 2026] [security2:error] [pid 302018:tid 302191] [client 194.99.104.35:57680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9PYIAs9lPxxVAErz0T4gAAAK4"]
[Tue Jul 21 07:52:16.477495 2026] [security2:error] [pid 296703:tid 296952] [client 20.197.192.193:27173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/acew67.php"] [unique_id "al9PYCn25uliftkV1n419gAAAHc"]
[Tue Jul 21 07:52:16.764981 2026] [security2:error] [pid 302018:tid 302199] [client 20.197.192.193:27153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/bscclapb.php"] [unique_id "al9PYIAs9lPxxVAErz0T9AAAALY"]
[Tue Jul 21 07:52:16.866987 2026] [security2:error] [pid 302018:tid 302235] [client 20.197.192.193:27187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/else1.php"] [unique_id "al9PYIAs9lPxxVAErz0T-gAAANo"]
[Tue Jul 21 07:52:16.879078 2026] [security2:error] [pid 296703:tid 296826] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PYCn25uliftkV1n42AAAARno"]
[Tue Jul 21 07:52:16.879346 2026] [security2:error] [pid 296703:tid 296903] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PYCn25uliftkV1n42AAAARno"]
[Tue Jul 21 07:52:16.993372 2026] [security2:error] [pid 296703:tid 296872] [client 54.251.12.30:51832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/phpversion.php"] [unique_id "al9PYCn25uliftkV1n42BgAAACc"]
[Tue Jul 21 07:52:17.030352 2026] [security2:error] [pid 296703:tid 296898] [client 20.197.192.193:26918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/tkikikoko.php"] [unique_id "al9PYSn25uliftkV1n42CAAAAEE"]
[Tue Jul 21 07:52:17.065174 2026] [security2:error] [pid 296703:tid 296721] [remote 14.128.14.9:43200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.14.128.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9PYSn25uliftkV1n42CgAARRE"]
[Tue Jul 21 07:52:17.273525 2026] [security2:error] [pid 302018:tid 302160] [client 193.36.225.107:22779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PX4As9lPxxVAErz0TwQAAAI8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:52:17.335594 2026] [security2:error] [pid 296703:tid 296946] [client 20.197.192.193:27110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/wp-Blogs.php"] [unique_id "al9PYSn25uliftkV1n42GAAAAHE"]
[Tue Jul 21 07:52:17.665793 2026] [security2:error] [pid 302018:tid 302233] [client 122.164.127.47:54422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PYYAs9lPxxVAErz0UGQAAANg"]
[Tue Jul 21 07:52:17.665944 2026] [security2:error] [pid 302018:tid 302233] [client 122.164.127.47:54422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PYYAs9lPxxVAErz0UGQAAANg"]
[Tue Jul 21 07:52:17.928401 2026] [security2:error] [pid 302018:tid 302163] [client 20.104.96.117:64264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9PYYAs9lPxxVAErz0UKAAAAJI"]
[Tue Jul 21 07:52:17.935981 2026] [security2:error] [pid 296703:tid 296822] [remote 182.77.62.24:44444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9PYSn25uliftkV1n42KgAAOHY"]
[Tue Jul 21 07:52:17.949802 2026] [security2:error] [pid 302018:tid 302246] [client 136.144.33.215:50527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PYYAs9lPxxVAErz0UKQAAAOU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:52:18.019086 2026] [security2:error] [pid 302018:tid 302223] [client 54.251.12.30:51844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/_phpinfo.php"] [unique_id "al9PYoAs9lPxxVAErz0UKgAAAM4"]
[Tue Jul 21 07:52:18.046022 2026] [security2:error] [pid 302018:tid 302259] [client 41.68.90.219:50064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PYoAs9lPxxVAErz0ULgAAAPI"]
[Tue Jul 21 07:52:18.046199 2026] [security2:error] [pid 302018:tid 302259] [client 41.68.90.219:50064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PYoAs9lPxxVAErz0ULgAAAPI"]
[Tue Jul 21 07:52:18.092252 2026] [security2:error] [pid 302018:tid 302187] [client 74.249.245.134:65111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/readme.php"] [unique_id "al9PYoAs9lPxxVAErz0UMAAAAKo"]
[Tue Jul 21 07:52:18.288805 2026] [security2:error] [pid 296703:tid 296903] [client 74.249.245.134:24806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ws77.php"] [unique_id "al9PYin25uliftkV1n42PgAAAEY"]
[Tue Jul 21 07:52:18.333152 2026] [security2:error] [pid 302018:tid 302257] [client 20.197.192.193:27184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/wp-css.php"] [unique_id "al9PYoAs9lPxxVAErz0URAAAAPA"]
[Tue Jul 21 07:52:18.338762 2026] [autoindex:error] [pid 302018:tid 302245] [client 44.223.102.150:58562] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.google.com/
[Tue Jul 21 07:52:18.485939 2026] [security2:error] [pid 302018:tid 302190] [client 182.8.255.181:2928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PYoAs9lPxxVAErz0UTQAAAK0"]
[Tue Jul 21 07:52:18.486139 2026] [security2:error] [pid 302018:tid 302190] [client 182.8.255.181:2928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PYoAs9lPxxVAErz0UTQAAAK0"]
[Tue Jul 21 07:52:18.625495 2026] [security2:error] [pid 296703:tid 296935] [client 20.104.96.117:60229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/w1px.php"] [unique_id "al9PYin25uliftkV1n42SQAAAGY"]
[Tue Jul 21 07:52:19.011277 2026] [security2:error] [pid 296703:tid 296736] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PYyn25uliftkV1n42VAAAcSA"]
[Tue Jul 21 07:52:19.011563 2026] [security2:error] [pid 296703:tid 296946] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PYyn25uliftkV1n42VAAAcSA"]
[Tue Jul 21 07:52:19.062746 2026] [security2:error] [pid 302018:tid 302236] [client 54.251.12.30:51848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/old_phpinfo.php"] [unique_id "al9PY4As9lPxxVAErz0UbwAAANs"]
[Tue Jul 21 07:52:19.074727 2026] [security2:error] [pid 302018:tid 302206] [client 20.226.60.151:56737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/ops.php"] [unique_id "al9PY4As9lPxxVAErz0UcAAAAL0"]
[Tue Jul 21 07:52:19.197797 2026] [core:error] [pid 302018:tid 302190] [client 147.182.225.118:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.memoriabalaiodaoxum.com.br/
[Tue Jul 21 07:52:19.197828 2026] [core:error] [pid 302018:tid 302190] [client 147.182.225.118:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.memoriabalaiodaoxum.com.br/
[Tue Jul 21 07:52:19.518888 2026] [security2:error] [pid 302018:tid 302191] [client 122.162.144.145:21682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PY4As9lPxxVAErz0UgAAAAK4"]
[Tue Jul 21 07:52:19.519046 2026] [security2:error] [pid 302018:tid 302191] [client 122.162.144.145:21682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PY4As9lPxxVAErz0UgAAAAK4"]
[Tue Jul 21 07:52:19.550047 2026] [security2:error] [pid 296703:tid 296767] [remote 217.182.128.41:32788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/wp-login.php"] [unique_id "al9PYyn25uliftkV1n42YAAAEj8"]
[Tue Jul 21 07:52:19.628514 2026] [security2:error] [pid 302018:tid 302231] [client 20.197.192.193:27156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/wp-explorer.php"] [unique_id "al9PY4As9lPxxVAErz0UggAAANY"]
[Tue Jul 21 07:52:19.684273 2026] [security2:error] [pid 302018:tid 302031] [remote 84.247.172.23:49632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9PY4As9lPxxVAErz0UgwAAvgo"]
[Tue Jul 21 07:52:19.710969 2026] [security2:error] [pid 302018:tid 302166] [client 20.220.225.223:23482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/hp2.php"] [unique_id "al9PY4As9lPxxVAErz0UhgAAAJU"]
[Tue Jul 21 07:52:19.982306 2026] [security2:error] [pid 296703:tid 296856] [client 74.249.245.134:65097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/2.php"] [unique_id "al9PYyn25uliftkV1n42ZQAAABc"]
[Tue Jul 21 07:52:20.051467 2026] [security2:error] [pid 302018:tid 302265] [client 20.104.96.117:59765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/yawa.php"] [unique_id "al9PZIAs9lPxxVAErz0UkgAAAPg"]
[Tue Jul 21 07:52:20.115423 2026] [security2:error] [pid 296703:tid 296936] [client 54.251.12.30:51854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/server-info.php"] [unique_id "al9PZCn25uliftkV1n42ZwAAAGc"]
[Tue Jul 21 07:52:20.396943 2026] [security2:error] [pid 302018:tid 302171] [client 103.166.103.129:38129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PZIAs9lPxxVAErz0UlwAAAJo"]
[Tue Jul 21 07:52:20.397405 2026] [security2:error] [pid 302018:tid 302171] [client 103.166.103.129:38129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PZIAs9lPxxVAErz0UlwAAAJo"]
[Tue Jul 21 07:52:20.466735 2026] [security2:error] [pid 296703:tid 296945] [client 202.143.127.214:58571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZCn25uliftkV1n42bwAAAHA"]
[Tue Jul 21 07:52:20.466888 2026] [security2:error] [pid 296703:tid 296945] [client 202.143.127.214:58571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZCn25uliftkV1n42bwAAAHA"]
[Tue Jul 21 07:52:20.478494 2026] [autoindex:error] [pid 296703:tid 296877] [client 43.153.74.75:52242] AH01276: Cannot serve directory /home2/rodr9255/mrragrorepresentacoes.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:52:20.612092 2026] [security2:error] [pid 302018:tid 302200] [client 223.236.153.128:7177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PZIAs9lPxxVAErz0UmgAAALc"]
[Tue Jul 21 07:52:20.612240 2026] [security2:error] [pid 302018:tid 302200] [client 223.236.153.128:7177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PZIAs9lPxxVAErz0UmgAAALc"]
[Tue Jul 21 07:52:20.653020 2026] [security2:error] [pid 296703:tid 296907] [client 103.86.117.203:52060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PZCn25uliftkV1n42cQAAAEo"]
[Tue Jul 21 07:52:20.653487 2026] [security2:error] [pid 296703:tid 296907] [client 103.86.117.203:52060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PZCn25uliftkV1n42cQAAAEo"]
[Tue Jul 21 07:52:20.725958 2026] [security2:error] [pid 302018:tid 302093] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PZIAs9lPxxVAErz0UmwAA50g"]
[Tue Jul 21 07:52:20.726096 2026] [security2:error] [pid 302018:tid 302248] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PZIAs9lPxxVAErz0UmwAA50g"]
[Tue Jul 21 07:52:20.933603 2026] [security2:error] [pid 296703:tid 296876] [client 20.197.192.193:27194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/akismet.php"] [unique_id "al9PZCn25uliftkV1n42ewAAACs"]
[Tue Jul 21 07:52:21.016743 2026] [security2:error] [pid 296703:tid 296799] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZSn25uliftkV1n42gAAAP18"]
[Tue Jul 21 07:52:21.017404 2026] [security2:error] [pid 296703:tid 296896] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZSn25uliftkV1n42gAAAP18"]
[Tue Jul 21 07:52:21.078661 2026] [security2:error] [pid 296703:tid 296908] [client 20.104.96.117:64363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/js.php"] [unique_id "al9PZSn25uliftkV1n42gQAAAEs"]
[Tue Jul 21 07:52:21.154568 2026] [security2:error] [pid 296703:tid 296878] [client 54.251.12.30:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/server-status.php"] [unique_id "al9PZSn25uliftkV1n42ggAAAC0"]
[Tue Jul 21 07:52:21.489015 2026] [security2:error] [pid 296703:tid 296862] [client 20.226.60.151:56815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/mac.php"] [unique_id "al9PZSn25uliftkV1n42mQAAAB0"]
[Tue Jul 21 07:52:21.536763 2026] [security2:error] [pid 302018:tid 302250] [client 136.144.33.241:44269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PZYAs9lPxxVAErz0UnAAAAOk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:52:21.682077 2026] [security2:error] [pid 296703:tid 296863] [client 20.104.96.117:64290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/core.php"] [unique_id "al9PZSn25uliftkV1n42oAAAAB4"]
[Tue Jul 21 07:52:21.773915 2026] [security2:error] [pid 296703:tid 296936] [client 194.99.104.35:59358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9PZSn25uliftkV1n42oQAAAGc"]
[Tue Jul 21 07:52:21.774035 2026] [security2:error] [pid 296703:tid 296936] [client 194.99.104.35:59358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9PZSn25uliftkV1n42oQAAAGc"]
[Tue Jul 21 07:52:21.823182 2026] [security2:error] [pid 296703:tid 296845] [client 66.249.66.34:35457] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "gpcom.com.br"] [uri "/robots.txt"] [unique_id "al9PZSn25uliftkV1n42owAAAAw"]
[Tue Jul 21 07:52:22.052459 2026] [security2:error] [pid 296703:tid 296871] [client 20.197.192.193:27149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/ace2.php"] [unique_id "al9PZin25uliftkV1n42rgAAACY"]
[Tue Jul 21 07:52:22.244351 2026] [security2:error] [pid 296703:tid 296951] [client 114.119.145.194:23415] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carrosselbuique.com.br"] [uri "/sp_revisao-de-portugues-simulado-de-dezembro-2020-4"] [unique_id "al9PZin25uliftkV1n42tQAAAHY"], referer: https://carrosselbuique.com.br/category/6ano
[Tue Jul 21 07:52:22.253207 2026] [security2:error] [pid 296703:tid 296850] [client 178.153.91.96:60436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PZin25uliftkV1n42tgAAABE"]
[Tue Jul 21 07:52:22.253362 2026] [security2:error] [pid 296703:tid 296850] [client 178.153.91.96:60436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PZin25uliftkV1n42tgAAABE"]
[Tue Jul 21 07:52:22.420201 2026] [security2:error] [pid 296703:tid 296857] [client 62.102.148.187:34872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9PZin25uliftkV1n42vwAAABg"]
[Tue Jul 21 07:52:22.420332 2026] [security2:error] [pid 296703:tid 296857] [client 62.102.148.187:34872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9PZin25uliftkV1n42vwAAABg"]
[Tue Jul 21 07:52:22.488124 2026] [autoindex:error] [pid 296703:tid 296896] [client 202.78.167.207:36502] AH01276: Cannot serve directory /home2/tamoio74/engeconconstrucoes.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.engeconconstrucoes.com.br.tamoiomix.com.br/
[Tue Jul 21 07:52:22.522370 2026] [autoindex:error] [pid 296703:tid 296911] [client 202.78.167.207:36518] AH01276: Cannot serve directory /home2/tamoio74/engeconconstrucoes.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://engeconconstrucoes.com.br.tamoiomix.com.br/
[Tue Jul 21 07:52:22.546271 2026] [security2:error] [pid 296703:tid 296835] [client 74.249.245.134:64421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/asd.php"] [unique_id "al9PZin25uliftkV1n42yAAAAAI"]
[Tue Jul 21 07:52:22.643447 2026] [security2:error] [pid 296703:tid 296916] [client 139.167.225.182:53489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZin25uliftkV1n42yQAAAFM"]
[Tue Jul 21 07:52:22.645308 2026] [security2:error] [pid 296703:tid 296916] [client 139.167.225.182:53489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZin25uliftkV1n42yQAAAFM"]
[Tue Jul 21 07:52:22.760481 2026] [security2:error] [pid 296703:tid 296948] [client 20.104.96.117:64309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/19.php"] [unique_id "al9PZin25uliftkV1n42ywAAAHM"]
[Tue Jul 21 07:52:22.875883 2026] [security2:error] [pid 296703:tid 296954] [client 54.251.12.30:51868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/webroot/index.php/_environment"] [unique_id "al9PZin25uliftkV1n420wAAAHk"]
[Tue Jul 21 07:52:22.894342 2026] [autoindex:error] [pid 296703:tid 296950] [client 202.78.167.207:36526] AH01276: Cannot serve directory /home2/tamoio74/engeconconstrucoes.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://engeconconstrucoes.com.br/
[Tue Jul 21 07:52:22.929618 2026] [security2:error] [pid 296703:tid 296926] [client 117.247.80.59:22732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZin25uliftkV1n422gAAAF0"]
[Tue Jul 21 07:52:22.929733 2026] [security2:error] [pid 296703:tid 296926] [client 117.247.80.59:22732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZin25uliftkV1n422gAAAF0"]
[Tue Jul 21 07:52:22.957515 2026] [security2:error] [pid 296703:tid 296856] [client 2.57.168.21:44303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.168.57.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9PZin25uliftkV1n422wAAABc"]
[Tue Jul 21 07:52:22.991167 2026] [security2:error] [pid 296703:tid 296942] [client 173.24.185.52:50702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PZin25uliftkV1n423gAAAG0"]
[Tue Jul 21 07:52:22.991259 2026] [security2:error] [pid 296703:tid 296942] [client 173.24.185.52:50702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PZin25uliftkV1n423gAAAG0"]
[Tue Jul 21 07:52:23.078905 2026] [security2:error] [pid 296703:tid 296879] [client 109.60.28.94:63784] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZyn25uliftkV1n425AAAAC4"]
[Tue Jul 21 07:52:23.079034 2026] [security2:error] [pid 296703:tid 296879] [client 109.60.28.94:63784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZyn25uliftkV1n425AAAAC4"]
[Tue Jul 21 07:52:23.099235 2026] [security2:error] [pid 296703:tid 296882] [client 122.186.204.214:53834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PZyn25uliftkV1n425gAAADE"]
[Tue Jul 21 07:52:23.099404 2026] [security2:error] [pid 296703:tid 296882] [client 122.186.204.214:53834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PZyn25uliftkV1n425gAAADE"]
[Tue Jul 21 07:52:23.201430 2026] [security2:error] [pid 296703:tid 296906] [client 20.220.225.223:19971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/berlin.php"] [unique_id "al9PZyn25uliftkV1n425wAAAEk"]
[Tue Jul 21 07:52:23.473300 2026] [security2:error] [pid 296703:tid 296710] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZyn25uliftkV1n42-gAAJQY"]
[Tue Jul 21 07:52:23.473449 2026] [security2:error] [pid 296703:tid 296870] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZyn25uliftkV1n42-gAAJQY"]
[Tue Jul 21 07:52:23.654757 2026] [security2:error] [pid 296703:tid 296890] [client 20.104.96.117:64282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/inc.php"] [unique_id "al9PZyn25uliftkV1n43CAAAADk"]
[Tue Jul 21 07:52:23.684496 2026] [security2:error] [pid 296703:tid 296929] [client 117.217.38.194:61693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZyn25uliftkV1n43CQAAAGA"]
[Tue Jul 21 07:52:23.684651 2026] [security2:error] [pid 296703:tid 296929] [client 117.217.38.194:61693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZyn25uliftkV1n43CQAAAGA"]
[Tue Jul 21 07:52:23.758783 2026] [security2:error] [pid 296703:tid 296936] [client 20.226.60.151:61602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/root.php"] [unique_id "al9PZyn25uliftkV1n43DgAAAGc"]
[Tue Jul 21 07:52:23.853566 2026] [security2:error] [pid 296703:tid 296782] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZyn25uliftkV1n43DwAAH04"]
[Tue Jul 21 07:52:23.853721 2026] [security2:error] [pid 296703:tid 296864] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PZyn25uliftkV1n43DwAAH04"]
[Tue Jul 21 07:52:23.897840 2026] [security2:error] [pid 296703:tid 296948] [client 54.251.12.30:51882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/mail/phpinfo.php"] [unique_id "al9PZyn25uliftkV1n43EAAAAHM"]
[Tue Jul 21 07:52:24.018122 2026] [security2:error] [pid 296703:tid 296913] [client 74.249.245.134:24820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/default.php"] [unique_id "al9PaCn25uliftkV1n43GAAAAFA"]
[Tue Jul 21 07:52:24.174897 2026] [security2:error] [pid 296703:tid 296938] [client 20.226.60.151:56831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/mg.php"] [unique_id "al9PaCn25uliftkV1n43HQAAAGk"]
[Tue Jul 21 07:52:24.328246 2026] [security2:error] [pid 302018:tid 302120] [remote 103.112.62.59:36580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9PaIAs9lPxxVAErz0UnQAA62M"]
[Tue Jul 21 07:52:24.339910 2026] [security2:error] [pid 296703:tid 296937] [client 103.29.114.44:60255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PaCn25uliftkV1n43IAAAAGg"]
[Tue Jul 21 07:52:24.340023 2026] [security2:error] [pid 296703:tid 296937] [client 103.29.114.44:60255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PaCn25uliftkV1n43IAAAAGg"]
[Tue Jul 21 07:52:24.476454 2026] [security2:error] [pid 296703:tid 296888] [client 20.197.192.193:27148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atacadomaster.com"] [uri "/ms.php"] [unique_id "al9PaCn25uliftkV1n43JgAAADc"]
[Tue Jul 21 07:52:24.533808 2026] [security2:error] [pid 296703:tid 296717] [remote 134.209.147.209:50450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.147.209.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-login.php"] [unique_id "al9PaCn25uliftkV1n43KgAAIQ0"]
[Tue Jul 21 07:52:24.608406 2026] [security2:error] [pid 296703:tid 296949] [client 20.104.96.117:59731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9PaCn25uliftkV1n43LwAAAHQ"]
[Tue Jul 21 07:52:24.927939 2026] [security2:error] [pid 296703:tid 296941] [client 54.251.12.30:51888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/cpanel/phpinfo.php"] [unique_id "al9PaCn25uliftkV1n43OQAAAGw"]
[Tue Jul 21 07:52:25.205766 2026] [security2:error] [pid 296703:tid 296957] [client 122.179.91.63:8836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PaSn25uliftkV1n43SQAAAHw"]
[Tue Jul 21 07:52:25.205957 2026] [security2:error] [pid 296703:tid 296957] [client 122.179.91.63:8836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PaSn25uliftkV1n43SQAAAHw"]
[Tue Jul 21 07:52:25.307630 2026] [security2:error] [pid 296703:tid 296931] [client 20.104.96.117:64350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9PaSn25uliftkV1n43TQAAAGI"]
[Tue Jul 21 07:52:25.746962 2026] [security2:error] [pid 296703:tid 296903] [client 20.104.96.117:64279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/ss.php"] [unique_id "al9PaSn25uliftkV1n43XgAAAEY"]
[Tue Jul 21 07:52:25.969975 2026] [security2:error] [pid 296703:tid 296935] [client 54.251.12.30:35176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/hosting/phpinfo.php"] [unique_id "al9PaSn25uliftkV1n43YAAAAGY"]
[Tue Jul 21 07:52:26.194319 2026] [security2:error] [pid 296703:tid 296913] [client 106.215.181.8:28264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pain25uliftkV1n43bgAAAFA"]
[Tue Jul 21 07:52:26.194492 2026] [security2:error] [pid 296703:tid 296913] [client 106.215.181.8:28264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pain25uliftkV1n43bgAAAFA"]
[Tue Jul 21 07:52:26.297222 2026] [security2:error] [pid 296703:tid 296771] [remote 104.207.58.39:34409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9Pain25uliftkV1n43ZwAAREM"]
[Tue Jul 21 07:52:26.418050 2026] [security2:error] [pid 296703:tid 296785] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Pain25uliftkV1n43dAAAT1E"]
[Tue Jul 21 07:52:26.418231 2026] [security2:error] [pid 296703:tid 296912] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Pain25uliftkV1n43dAAAT1E"]
[Tue Jul 21 07:52:26.602895 2026] [security2:error] [pid 296703:tid 296779] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Pain25uliftkV1n43eQAAOEs"]
[Tue Jul 21 07:52:26.603099 2026] [security2:error] [pid 296703:tid 296889] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Pain25uliftkV1n43eQAAOEs"]
[Tue Jul 21 07:52:26.643074 2026] [security2:error] [pid 296703:tid 296862] [client 20.104.96.117:64306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/min.php"] [unique_id "al9Pain25uliftkV1n43egAAAB0"]
[Tue Jul 21 07:52:26.859471 2026] [security2:error] [pid 296703:tid 296942] [client 20.220.225.223:23444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/hp3.php"] [unique_id "al9Pain25uliftkV1n43gwAAAG0"]
[Tue Jul 21 07:52:26.991726 2026] [security2:error] [pid 296703:tid 296919] [client 54.251.12.30:35178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/webmail/phpinfo.php"] [unique_id "al9Pain25uliftkV1n43hwAAAFY"]
[Tue Jul 21 07:52:27.403224 2026] [security2:error] [pid 296703:tid 296880] [client 172.245.102.42:55085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Pain25uliftkV1n43cwAAAC8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:52:27.539670 2026] [security2:error] [pid 296703:tid 296934] [client 20.104.96.117:64314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9Payn25uliftkV1n43nAAAAGU"]
[Tue Jul 21 07:52:27.974911 2026] [security2:error] [pid 296703:tid 296909] [client 20.104.96.117:60700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9Payn25uliftkV1n43sQAAAEw"]
[Tue Jul 21 07:52:28.016913 2026] [security2:error] [pid 296703:tid 296960] [client 54.251.12.30:35186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/smtp/phpinfo.php"] [unique_id "al9PbCn25uliftkV1n43sgAAAH8"]
[Tue Jul 21 07:52:28.054978 2026] [security2:error] [pid 296703:tid 296799] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PbCn25uliftkV1n43tgAAHV8"]
[Tue Jul 21 07:52:28.055135 2026] [security2:error] [pid 296703:tid 296862] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PbCn25uliftkV1n43tgAAHV8"]
[Tue Jul 21 07:52:28.074926 2026] [security2:error] [pid 296703:tid 296841] [client 20.220.225.223:52191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/aa1.php"] [unique_id "al9PbCn25uliftkV1n43twAAAAg"]
[Tue Jul 21 07:52:28.213794 2026] [security2:error] [pid 296703:tid 296905] [client 122.164.127.47:55002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PbCn25uliftkV1n43wAAAAEg"]
[Tue Jul 21 07:52:28.221025 2026] [security2:error] [pid 296703:tid 296905] [client 122.164.127.47:55002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PbCn25uliftkV1n43wAAAAEg"]
[Tue Jul 21 07:52:28.252005 2026] [security2:error] [pid 296703:tid 296924] [client 74.249.245.134:24819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/gettest.php"] [unique_id "al9PbCn25uliftkV1n43wgAAAFs"]
[Tue Jul 21 07:52:28.402094 2026] [security2:error] [pid 296703:tid 296876] [client 62.102.148.187:34878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9PbCn25uliftkV1n43zgAAACs"]
[Tue Jul 21 07:52:28.403755 2026] [security2:error] [pid 296703:tid 296876] [client 62.102.148.187:34878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9PbCn25uliftkV1n43zgAAACs"]
[Tue Jul 21 07:52:28.714246 2026] [security2:error] [pid 296703:tid 296934] [client 20.104.96.117:64300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9PbCn25uliftkV1n432QAAAGU"]
[Tue Jul 21 07:52:28.744780 2026] [security2:error] [pid 296703:tid 296835] [client 20.220.225.223:22331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/bscclapb.php"] [unique_id "al9PbCn25uliftkV1n432wAAAAI"]
[Tue Jul 21 07:52:28.745723 2026] [security2:error] [pid 296703:tid 296838] [client 20.104.96.117:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9PbCn25uliftkV1n433AAAAAU"]
[Tue Jul 21 07:52:28.861642 2026] [security2:error] [pid 296703:tid 296902] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9PbCn25uliftkV1n435wAAAEU"]
[Tue Jul 21 07:52:28.879835 2026] [security2:error] [pid 296703:tid 296948] [client 182.8.255.181:17521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PbCn25uliftkV1n436QAAAHM"]
[Tue Jul 21 07:52:28.879958 2026] [security2:error] [pid 296703:tid 296948] [client 182.8.255.181:17521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PbCn25uliftkV1n436QAAAHM"]
[Tue Jul 21 07:52:28.882151 2026] [security2:error] [pid 296703:tid 296947] [client 41.68.90.219:50510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PbCn25uliftkV1n436gAAAHI"]
[Tue Jul 21 07:52:28.883279 2026] [security2:error] [pid 296703:tid 296947] [client 41.68.90.219:50510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PbCn25uliftkV1n436gAAAHI"]
[Tue Jul 21 07:52:29.044791 2026] [security2:error] [pid 296703:tid 296866] [client 54.251.12.30:35192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/phpinfo.php.bak"] [unique_id "al9PbSn25uliftkV1n437AAAACE"]
[Tue Jul 21 07:52:29.072006 2026] [security2:error] [pid 296703:tid 296796] [remote 49.13.1.223:57638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nocaminhodafe.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PbSn25uliftkV1n437QAAelw"]
[Tue Jul 21 07:52:29.072189 2026] [security2:error] [pid 296703:tid 296955] [client 49.13.1.223:57638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nocaminhodafe.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PbSn25uliftkV1n437QAAelw"]
[Tue Jul 21 07:52:29.182554 2026] [security2:error] [pid 296703:tid 296841] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9PbSn25uliftkV1n438AAAAAg"]
[Tue Jul 21 07:52:29.198064 2026] [security2:error] [pid 296703:tid 296887] [client 20.104.96.117:64352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9PbSn25uliftkV1n438wAAADY"]
[Tue Jul 21 07:52:29.418788 2026] [security2:error] [pid 296703:tid 296912] [client 37.140.223.119:37173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PbSn25uliftkV1n439wAAAE8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:52:29.458013 2026] [security2:error] [pid 296703:tid 296931] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9PbSn25uliftkV1n44AQAAAGI"]
[Tue Jul 21 07:52:29.494760 2026] [security2:error] [pid 296703:tid 296935] [client 20.220.225.223:6100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/acew67.php"] [unique_id "al9PbSn25uliftkV1n44BAAAAGY"]
[Tue Jul 21 07:52:29.716599 2026] [security2:error] [pid 296703:tid 296870] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9PbSn25uliftkV1n44CQAAACU"]
[Tue Jul 21 07:52:29.775832 2026] [security2:error] [pid 296703:tid 296780] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PbSn25uliftkV1n44CwAATkw"]
[Tue Jul 21 07:52:29.775963 2026] [security2:error] [pid 296703:tid 296911] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PbSn25uliftkV1n44CwAATkw"]
[Tue Jul 21 07:52:29.777648 2026] [security2:error] [pid 296703:tid 296838] [client 20.104.96.117:64354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/albin.php"] [unique_id "al9PbSn25uliftkV1n44DAAAAAU"]
[Tue Jul 21 07:52:29.918802 2026] [security2:error] [pid 296703:tid 296902] [client 74.249.245.134:8771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/tfm.php"] [unique_id "al9PbSn25uliftkV1n44EQAAAEU"]
[Tue Jul 21 07:52:29.962551 2026] [security2:error] [pid 296703:tid 296863] [client 20.220.225.223:19691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/billur.php"] [unique_id "al9PbSn25uliftkV1n44EwAAAB4"]
[Tue Jul 21 07:52:29.963410 2026] [security2:error] [pid 296703:tid 296947] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9PbSn25uliftkV1n44FAAAAHI"]
[Tue Jul 21 07:52:30.044571 2026] [security2:error] [pid 296703:tid 296954] [client 20.220.225.223:35071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/else1.php"] [unique_id "al9Pbin25uliftkV1n44FgAAAHk"]
[Tue Jul 21 07:52:30.100381 2026] [security2:error] [pid 296703:tid 296934] [client 54.251.12.30:35198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/phpinfo.php.old"] [unique_id "al9Pbin25uliftkV1n44FwAAAGU"]
[Tue Jul 21 07:52:30.203662 2026] [security2:error] [pid 296703:tid 296845] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Pbin25uliftkV1n44GwAAAAw"]
[Tue Jul 21 07:52:30.306570 2026] [security2:error] [pid 296703:tid 296861] [client 20.220.225.223:52192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/bscclapb.php"] [unique_id "al9Pbin25uliftkV1n44HgAAABw"]
[Tue Jul 21 07:52:30.380511 2026] [security2:error] [pid 296703:tid 296854] [client 122.162.144.145:20397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Pbin25uliftkV1n44IAAAABU"]
[Tue Jul 21 07:52:30.380627 2026] [security2:error] [pid 296703:tid 296854] [client 122.162.144.145:20397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Pbin25uliftkV1n44IAAAABU"]
[Tue Jul 21 07:52:30.457487 2026] [security2:error] [pid 296703:tid 296883] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Pbin25uliftkV1n44JAAAADI"]
[Tue Jul 21 07:52:30.718129 2026] [security2:error] [pid 296703:tid 296722] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pbin25uliftkV1n44LQAAPRI"]
[Tue Jul 21 07:52:30.718325 2026] [security2:error] [pid 296703:tid 296894] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pbin25uliftkV1n44LQAAPRI"]
[Tue Jul 21 07:52:30.776273 2026] [security2:error] [pid 296703:tid 296837] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Pbin25uliftkV1n44LgAAAAQ"]
[Tue Jul 21 07:52:31.024554 2026] [security2:error] [pid 296703:tid 296911] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Pbyn25uliftkV1n44NgAAAE4"]
[Tue Jul 21 07:52:31.055578 2026] [security2:error] [pid 296703:tid 296891] [client 20.104.96.117:64313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/cilus.php"] [unique_id "al9Pbyn25uliftkV1n44OAAAADo"]
[Tue Jul 21 07:52:31.144190 2026] [security2:error] [pid 296703:tid 296935] [client 54.251.12.30:35212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/phpinfo.php~"] [unique_id "al9Pbyn25uliftkV1n44PAAAAGY"]
[Tue Jul 21 07:52:31.145098 2026] [security2:error] [pid 296703:tid 296957] [client 103.86.117.203:52604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Pbyn25uliftkV1n44PQAAAHw"]
[Tue Jul 21 07:52:31.145180 2026] [security2:error] [pid 296703:tid 296957] [client 103.86.117.203:52604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Pbyn25uliftkV1n44PQAAAHw"]
[Tue Jul 21 07:52:31.204575 2026] [security2:error] [pid 296703:tid 296893] [client 20.226.60.151:56790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-post-data.php"] [unique_id "al9Pbyn25uliftkV1n44PgAAADw"]
[Tue Jul 21 07:52:31.261485 2026] [security2:error] [pid 296703:tid 296919] [client 103.166.103.129:54056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Pbyn25uliftkV1n44QgAAAFY"]
[Tue Jul 21 07:52:31.261845 2026] [security2:error] [pid 296703:tid 296919] [client 103.166.103.129:54056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Pbyn25uliftkV1n44QgAAAFY"]
[Tue Jul 21 07:52:31.277664 2026] [security2:error] [pid 296703:tid 296955] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Pbyn25uliftkV1n44QwAAAHo"]
[Tue Jul 21 07:52:31.419161 2026] [security2:error] [pid 296703:tid 296907] [client 180.153.236.46:19173] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.guterperfumes.com.br"] [uri "/"] [unique_id "al9Pbyn25uliftkV1n44SwAAAEo"], referer: http://www.guterperfumes.com.br/
[Tue Jul 21 07:52:31.419312 2026] [security2:error] [pid 296703:tid 296907] [client 180.153.236.46:19173] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.guterperfumes.com.br"] [uri "/"] [unique_id "al9Pbyn25uliftkV1n44SwAAAEo"], referer: http://www.guterperfumes.com.br/
[Tue Jul 21 07:52:31.535520 2026] [security2:error] [pid 296703:tid 296842] [client 20.220.225.223:6113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/else1.php"] [unique_id "al9Pbyn25uliftkV1n44UAAAAAk"]
[Tue Jul 21 07:52:31.559680 2026] [security2:error] [pid 296703:tid 296850] [client 202.143.127.214:59047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pbyn25uliftkV1n44UQAAABE"]
[Tue Jul 21 07:52:31.559904 2026] [security2:error] [pid 296703:tid 296850] [client 202.143.127.214:59047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pbyn25uliftkV1n44UQAAABE"]
[Tue Jul 21 07:52:31.603110 2026] [security2:error] [pid 296703:tid 296846] [client 20.197.192.193:3473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Pbyn25uliftkV1n44UgAAAA0"]
[Tue Jul 21 07:52:31.698604 2026] [security2:error] [pid 296703:tid 296797] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Pbyn25uliftkV1n44UwAAU10"]
[Tue Jul 21 07:52:31.698789 2026] [security2:error] [pid 296703:tid 296916] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Pbyn25uliftkV1n44UwAAU10"]
[Tue Jul 21 07:52:31.768083 2026] [security2:error] [pid 296703:tid 296912] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Pbyn25uliftkV1n44WAAAAE8"]
[Tue Jul 21 07:52:31.836860 2026] [security2:error] [pid 296703:tid 296922] [client 47.128.56.175:21600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bkp.liranesuliano.com.br"] [uri "/robots.txt"] [unique_id "al9Pbyn25uliftkV1n44XgAAAFk"]
[Tue Jul 21 07:52:31.882732 2026] [security2:error] [pid 296703:tid 296942] [client 172.245.102.44:40635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Pbyn25uliftkV1n44XwAAAG0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:52:32.058022 2026] [security2:error] [pid 296703:tid 296948] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9PcCn25uliftkV1n44bAAAAHM"]
[Tue Jul 21 07:52:32.175433 2026] [security2:error] [pid 296703:tid 296956] [client 54.251.12.30:35222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/info.php.bak"] [unique_id "al9PcCn25uliftkV1n44cQAAAHs"]
[Tue Jul 21 07:52:32.278336 2026] [security2:error] [pid 296703:tid 296879] [client 223.236.153.128:3764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PcCn25uliftkV1n44cgAAAC4"]
[Tue Jul 21 07:52:32.282940 2026] [security2:error] [pid 296703:tid 296879] [client 223.236.153.128:3764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PcCn25uliftkV1n44cgAAAC4"]
[Tue Jul 21 07:52:32.451503 2026] [security2:error] [pid 296703:tid 296924] [client 20.226.60.151:61544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/sym403.php"] [unique_id "al9PcCn25uliftkV1n44egAAAFs"]
[Tue Jul 21 07:52:32.470975 2026] [security2:error] [pid 296703:tid 296869] [client 20.104.96.117:59760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/gptsh.php"] [unique_id "al9PcCn25uliftkV1n44fgAAACQ"]
[Tue Jul 21 07:52:32.639068 2026] [security2:error] [pid 296703:tid 296925] [client 47.128.58.157:30228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dracrislaineoliveira.com.br"] [uri "/robots.txt"] [unique_id "al9PcCn25uliftkV1n44ugAAAFw"]
[Tue Jul 21 07:52:32.765272 2026] [security2:error] [pid 296703:tid 296836] [client 178.153.91.96:61232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PcCn25uliftkV1n44zQAAAAM"]
[Tue Jul 21 07:52:32.765456 2026] [security2:error] [pid 296703:tid 296836] [client 178.153.91.96:61232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PcCn25uliftkV1n44zQAAAAM"]
[Tue Jul 21 07:52:32.805440 2026] [security2:error] [pid 296703:tid 296899] [client 20.104.96.117:54926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9PcCn25uliftkV1n44zwAAAEI"]
[Tue Jul 21 07:52:33.103390 2026] [security2:error] [pid 296703:tid 296907] [client 139.167.225.182:54134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PcSn25uliftkV1n44-AAAAEo"]
[Tue Jul 21 07:52:33.103571 2026] [security2:error] [pid 296703:tid 296907] [client 139.167.225.182:54134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PcSn25uliftkV1n44-AAAAEo"]
[Tue Jul 21 07:52:33.183742 2026] [security2:error] [pid 296703:tid 296797] [remote 18.61.192.253:54486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9PcSn25uliftkV1n44-QAAX10"]
[Tue Jul 21 07:52:33.190697 2026] [security2:error] [pid 296703:tid 296953] [client 54.251.12.30:35236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/phpinfo.php.save"] [unique_id "al9PcSn25uliftkV1n44-gAAAHg"]
[Tue Jul 21 07:52:33.397905 2026] [security2:error] [pid 296703:tid 296940] [client 37.140.223.157:40127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PcSn25uliftkV1n44_AAAAGs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:52:33.442654 2026] [security2:error] [pid 296703:tid 296857] [client 117.247.80.59:35043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PcSn25uliftkV1n45TQAAABg"]
[Tue Jul 21 07:52:33.442766 2026] [security2:error] [pid 296703:tid 296857] [client 117.247.80.59:35043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PcSn25uliftkV1n45TQAAABg"]
[Tue Jul 21 07:52:33.466881 2026] [security2:error] [pid 296703:tid 296956] [client 74.249.245.134:65101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ws81.php"] [unique_id "al9PcSn25uliftkV1n45TwAAAHs"]
[Tue Jul 21 07:52:33.515913 2026] [security2:error] [pid 296703:tid 296905] [client 173.24.185.52:51180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PcSn25uliftkV1n45UAAAAEg"]
[Tue Jul 21 07:52:33.516020 2026] [security2:error] [pid 296703:tid 296905] [client 173.24.185.52:51180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PcSn25uliftkV1n45UAAAAEg"]
[Tue Jul 21 07:52:33.792872 2026] [security2:error] [pid 296703:tid 296942] [client 20.104.96.117:54912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/xyn.php"] [unique_id "al9PcSn25uliftkV1n45WQAAAG0"]
[Tue Jul 21 07:52:33.889093 2026] [security2:error] [pid 296703:tid 296949] [client 20.104.96.117:64339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/rithin.php"] [unique_id "al9PcSn25uliftkV1n45XgAAAHQ"]
[Tue Jul 21 07:52:33.969294 2026] [security2:error] [pid 296703:tid 296896] [client 20.226.60.151:56824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/pucci.php"] [unique_id "al9PcSn25uliftkV1n45YAAAAD8"]
[Tue Jul 21 07:52:34.022034 2026] [security2:error] [pid 296703:tid 296869] [client 122.186.204.214:54422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Pcin25uliftkV1n45YgAAACQ"]
[Tue Jul 21 07:52:34.022193 2026] [security2:error] [pid 296703:tid 296869] [client 122.186.204.214:54422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Pcin25uliftkV1n45YgAAACQ"]
[Tue Jul 21 07:52:34.096776 2026] [security2:error] [pid 296703:tid 296908] [client 74.249.245.134:64108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/max.php"] [unique_id "al9Pcin25uliftkV1n45ZgAAAEs"]
[Tue Jul 21 07:52:34.181725 2026] [security2:error] [pid 296703:tid 296880] [client 117.217.38.194:62194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pcin25uliftkV1n45aAAAAC8"]
[Tue Jul 21 07:52:34.181966 2026] [security2:error] [pid 296703:tid 296880] [client 117.217.38.194:62194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pcin25uliftkV1n45aAAAAC8"]
[Tue Jul 21 07:52:34.226454 2026] [security2:error] [pid 296703:tid 296941] [client 54.251.12.30:35238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/staging/phpinfo.php"] [unique_id "al9Pcin25uliftkV1n45awAAAGw"]
[Tue Jul 21 07:52:34.387658 2026] [security2:error] [pid 296703:tid 296764] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pcin25uliftkV1n45cQAAYTw"]
[Tue Jul 21 07:52:34.387838 2026] [security2:error] [pid 296703:tid 296930] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pcin25uliftkV1n45cQAAYTw"]
[Tue Jul 21 07:52:34.435269 2026] [security2:error] [pid 296703:tid 296796] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pcin25uliftkV1n45dAAAeVw"]
[Tue Jul 21 07:52:34.435415 2026] [security2:error] [pid 296703:tid 296954] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pcin25uliftkV1n45dAAAeVw"]
[Tue Jul 21 07:52:34.746494 2026] [security2:error] [pid 296703:tid 296778] [remote 43.165.170.119:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.170.165.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.expovilhena.com"] [uri "/login.php"] [unique_id "al9Pcin25uliftkV1n45dwAABko"], referer: https://www.expovilhena.com/
[Tue Jul 21 07:52:34.830791 2026] [security2:error] [pid 296703:tid 296906] [client 103.29.114.44:60884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pcin25uliftkV1n45ogAAAEk"]
[Tue Jul 21 07:52:34.831099 2026] [security2:error] [pid 296703:tid 296906] [client 103.29.114.44:60884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pcin25uliftkV1n45ogAAAEk"]
[Tue Jul 21 07:52:34.886996 2026] [security2:error] [pid 296703:tid 296924] [client 109.60.28.94:64194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PcSn25uliftkV1n45VwAAAFs"]
[Tue Jul 21 07:52:34.887213 2026] [security2:error] [pid 296703:tid 296924] [client 109.60.28.94:64194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PcSn25uliftkV1n45VwAAAFs"]
[Tue Jul 21 07:52:35.176562 2026] [security2:error] [pid 296703:tid 296903] [client 20.104.96.117:54915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/patie.php"] [unique_id "al9Pcyn25uliftkV1n45twAAAEY"]
[Tue Jul 21 07:52:35.260073 2026] [security2:error] [pid 296703:tid 296913] [client 54.251.12.30:35254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/beta/phpinfo.php"] [unique_id "al9Pcyn25uliftkV1n45uQAAAFA"]
[Tue Jul 21 07:52:35.292131 2026] [security2:error] [pid 296703:tid 296849] [client 34.182.235.64:54543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.lylow.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Pcyn25uliftkV1n45ugAAABA"]
[Tue Jul 21 07:52:35.791661 2026] [security2:error] [pid 296703:tid 296921] [client 122.179.91.63:29803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Pcyn25uliftkV1n450AAAAFg"]
[Tue Jul 21 07:52:35.791769 2026] [security2:error] [pid 296703:tid 296921] [client 122.179.91.63:29803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Pcyn25uliftkV1n450AAAAFg"]
[Tue Jul 21 07:52:35.853996 2026] [security2:error] [pid 296703:tid 296905] [client 34.182.235.64:53292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.lylow.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Pcyn25uliftkV1n450gAAAEg"]
[Tue Jul 21 07:52:35.861453 2026] [security2:error] [pid 296703:tid 296929] [client 74.7.241.153:38874] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "diskvidros.com.br"] [uri "/index.php"] [unique_id "al9PcSn25uliftkV1n45WgAAYHU"]
[Tue Jul 21 07:52:35.946697 2026] [security2:error] [pid 296703:tid 296857] [client 185.198.240.91:20197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-login.php"] [unique_id "al9Pcin25uliftkV1n45qAAAABg"]
[Tue Jul 21 07:52:36.090172 2026] [security2:error] [pid 296703:tid 296838] [client 193.36.225.67:47819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PdCn25uliftkV1n453AAAAAU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:52:36.141283 2026] [core:error] [pid 296703:tid 296934] [client 66.249.66.69:63680] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:52:36.141309 2026] [core:error] [pid 296703:tid 296934] [client 66.249.66.69:63680] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:52:36.142576 2026] [core:error] [pid 296703:tid 296940] [client 66.249.66.68:41398] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:52:36.142599 2026] [core:error] [pid 296703:tid 296940] [client 66.249.66.68:41398] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:52:36.201881 2026] [security2:error] [pid 296703:tid 296886] [client 20.104.96.117:64346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/fffm.php"] [unique_id "al9PdCn25uliftkV1n455AAAADU"]
[Tue Jul 21 07:52:36.297066 2026] [security2:error] [pid 296703:tid 296839] [client 54.251.12.30:38672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/uat/phpinfo.php"] [unique_id "al9PdCn25uliftkV1n455gAAAAY"]
[Tue Jul 21 07:52:36.314692 2026] [security2:error] [pid 296703:tid 296845] [client 34.182.235.64:55089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.lylow.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9PdCn25uliftkV1n455wAAAAw"]
[Tue Jul 21 07:52:36.338608 2026] [security2:error] [pid 296703:tid 296924] [client 20.220.225.223:19305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/mimpi.php"] [unique_id "al9PdCn25uliftkV1n456AAAAFs"]
[Tue Jul 21 07:52:36.457187 2026] [security2:error] [pid 296703:tid 296915] [client 74.7.230.58:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rafaelzolet1751388309362.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9PdCn25uliftkV1n456wAAUio"]
[Tue Jul 21 07:52:36.542734 2026] [security2:error] [pid 296703:tid 296887] [client 20.104.96.117:54918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/aa.php"] [unique_id "al9PdCn25uliftkV1n457wAAADY"]
[Tue Jul 21 07:52:36.772152 2026] [security2:error] [pid 296703:tid 296861] [client 106.215.181.8:28770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PdCn25uliftkV1n459gAAABw"]
[Tue Jul 21 07:52:36.776212 2026] [security2:error] [pid 296703:tid 296861] [client 106.215.181.8:28770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PdCn25uliftkV1n459gAAABw"]
[Tue Jul 21 07:52:36.830745 2026] [security2:error] [pid 296703:tid 296889] [client 20.226.60.151:56794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/black.php"] [unique_id "al9PdCn25uliftkV1n45-gAAADg"]
[Tue Jul 21 07:52:36.874138 2026] [security2:error] [pid 296703:tid 296914] [client 34.182.235.64:50240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.lylow.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9PdCn25uliftkV1n45-wAAAFE"]
[Tue Jul 21 07:52:37.030190 2026] [security2:error] [pid 296703:tid 296786] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PdSn25uliftkV1n45_gAAIVI"]
[Tue Jul 21 07:52:37.030336 2026] [security2:error] [pid 296703:tid 296866] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PdSn25uliftkV1n45_gAAIVI"]
[Tue Jul 21 07:52:37.095973 2026] [security2:error] [pid 296703:tid 296876] [client 141.11.107.74:64453] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.10db.com.br"] [uri "/"] [unique_id "al9PdSn25uliftkV1n46AgAAACs"]
[Tue Jul 21 07:52:37.124577 2026] [security2:error] [pid 296703:tid 296918] [client 37.140.223.50:39797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Pcyn25uliftkV1n450wAAAFU"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:52:37.124639 2026] [security2:error] [pid 296703:tid 296892] [client 141.11.107.74:64487] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "10db.com.br"] [uri "/"] [unique_id "al9PdSn25uliftkV1n46AwAAADs"]
[Tue Jul 21 07:52:37.306034 2026] [security2:error] [pid 296703:tid 296804] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PdSn25uliftkV1n46CQAAXmQ"]
[Tue Jul 21 07:52:37.306203 2026] [security2:error] [pid 296703:tid 296927] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PdSn25uliftkV1n46CQAAXmQ"]
[Tue Jul 21 07:52:37.313789 2026] [security2:error] [pid 296703:tid 296905] [client 54.251.12.30:38684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/qa/phpinfo.php"] [unique_id "al9PdSn25uliftkV1n46CgAAAEg"]
[Tue Jul 21 07:52:37.367673 2026] [proxy:error] [pid 296703:tid 296736] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:37.367739 2026] [proxy_http:error] [pid 296703:tid 296736] [remote 141.11.107.74:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.10db.com.br
[Tue Jul 21 07:52:37.368897 2026] [proxy:error] [pid 296703:tid 296736] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:37.368947 2026] [proxy_http:error] [pid 296703:tid 296736] [remote 141.11.107.74:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.10db.com.br
[Tue Jul 21 07:52:37.421070 2026] [security2:error] [pid 296703:tid 296922] [client 20.104.96.117:59751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/dfre.php"] [unique_id "al9PdSn25uliftkV1n46EAAAAFk"]
[Tue Jul 21 07:52:37.437191 2026] [security2:error] [pid 296703:tid 296822] [remote 141.11.107.74:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.10db.com.br"] [uri "/"] [unique_id "al9PdSn25uliftkV1n46EQAAbXY"], referer: http://autodiscover.10db.com.br
[Tue Jul 21 07:52:37.624040 2026] [security2:error] [pid 296703:tid 296853] [client 20.104.96.117:54973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/xwpg.php"] [unique_id "al9PdSn25uliftkV1n46GwAAABQ"]
[Tue Jul 21 07:52:37.831774 2026] [security2:error] [pid 296703:tid 296929] [client 74.249.245.134:65129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/222.php"] [unique_id "al9PdSn25uliftkV1n46JQAAAGA"]
[Tue Jul 21 07:52:37.940550 2026] [security2:error] [pid 296703:tid 296918] [client 34.182.235.64:50881] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.lylow.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9PdSn25uliftkV1n46KQAAAFU"]
[Tue Jul 21 07:52:38.178891 2026] [security2:error] [pid 296703:tid 296771] [remote 124.55.178.99:49828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "santotchay.com"] [uri "/wp-login.php"] [unique_id "al9Pdin25uliftkV1n46MgAADUM"]
[Tue Jul 21 07:52:38.228491 2026] [security2:error] [pid 296703:tid 296893] [client 74.249.245.134:65106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/m.php"] [unique_id "al9Pdin25uliftkV1n46NAAAADw"]
[Tue Jul 21 07:52:38.351311 2026] [security2:error] [pid 296703:tid 296843] [client 20.104.96.117:60239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/wp-happy.php"] [unique_id "al9Pdin25uliftkV1n46OgAAAAo"]
[Tue Jul 21 07:52:38.359944 2026] [security2:error] [pid 296703:tid 296913] [client 54.251.12.30:38690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/preview/phpinfo.php"] [unique_id "al9Pdin25uliftkV1n46OwAAAFA"]
[Tue Jul 21 07:52:38.363648 2026] [security2:error] [pid 296703:tid 296947] [client 20.104.96.117:55007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/ops.php"] [unique_id "al9Pdin25uliftkV1n46PAAAAHI"]
[Tue Jul 21 07:52:38.500978 2026] [security2:error] [pid 296703:tid 296879] [client 8.212.162.181:36022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mateusdespachante.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9Pdin25uliftkV1n46PwAAAC4"], referer: https://mateusdespachante.com.br
[Tue Jul 21 07:52:38.501091 2026] [security2:error] [pid 296703:tid 296879] [client 8.212.162.181:36022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "mateusdespachante.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9Pdin25uliftkV1n46PwAAAC4"], referer: https://mateusdespachante.com.br
[Tue Jul 21 07:52:38.675554 2026] [security2:error] [pid 296703:tid 296864] [client 20.226.60.151:61575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/v543.php"] [unique_id "al9Pdin25uliftkV1n46SwAAAB8"]
[Tue Jul 21 07:52:38.709518 2026] [security2:error] [pid 296703:tid 296891] [client 20.220.225.223:6143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/tkikikoko.php"] [unique_id "al9Pdin25uliftkV1n46TQAAADo"]
[Tue Jul 21 07:52:38.724051 2026] [security2:error] [pid 296703:tid 296837] [client 20.197.192.193:3305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Pdin25uliftkV1n46TgAAAAQ"]
[Tue Jul 21 07:52:38.788267 2026] [security2:error] [pid 296703:tid 296838] [client 122.164.127.47:55582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Pdin25uliftkV1n46UgAAAAU"]
[Tue Jul 21 07:52:38.788366 2026] [security2:error] [pid 296703:tid 296838] [client 122.164.127.47:55582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Pdin25uliftkV1n46UgAAAAU"]
[Tue Jul 21 07:52:38.805685 2026] [security2:error] [pid 296703:tid 296931] [client 34.182.235.64:57497] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.lylow.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Pdin25uliftkV1n46UwAAAGI"]
[Tue Jul 21 07:52:38.840022 2026] [security2:error] [pid 296703:tid 296819] [remote 65.111.20.143:48691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.20.111.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9Pdin25uliftkV1n46SgAAYXM"]
[Tue Jul 21 07:52:39.002200 2026] [security2:error] [pid 296703:tid 296922] [client 20.104.96.117:59775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/fpr4.php"] [unique_id "al9Pdyn25uliftkV1n46VgAAAFk"]
[Tue Jul 21 07:52:39.011642 2026] [core:error] [pid 296703:tid 296747] [remote 198.235.24.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:52:39.011669 2026] [core:error] [pid 296703:tid 296747] [remote 198.235.24.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:52:39.132822 2026] [security2:error] [pid 296703:tid 296741] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pdyn25uliftkV1n46bgAALyU"]
[Tue Jul 21 07:52:39.133004 2026] [security2:error] [pid 296703:tid 296880] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pdyn25uliftkV1n46bgAALyU"]
[Tue Jul 21 07:52:39.203755 2026] [security2:error] [pid 296703:tid 296953] [client 20.104.96.117:54956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/mac.php"] [unique_id "al9Pdyn25uliftkV1n46hgAAAHg"]
[Tue Jul 21 07:52:39.246990 2026] [security2:error] [pid 296703:tid 296921] [client 182.8.255.181:17167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Pdyn25uliftkV1n46hwAAAFg"]
[Tue Jul 21 07:52:39.247184 2026] [security2:error] [pid 296703:tid 296921] [client 182.8.255.181:17167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Pdyn25uliftkV1n46hwAAAFg"]
[Tue Jul 21 07:52:39.274831 2026] [security2:error] [pid 296703:tid 296879] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Pdyn25uliftkV1n46igAAAC4"]
[Tue Jul 21 07:52:39.382778 2026] [security2:error] [pid 296703:tid 296916] [client 54.251.12.30:38702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/www/phpinfo.php"] [unique_id "al9Pdyn25uliftkV1n46kAAAAFM"]
[Tue Jul 21 07:52:39.383402 2026] [security2:error] [pid 296703:tid 296940] [client 41.68.90.219:50958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pdyn25uliftkV1n46kQAAAGs"]
[Tue Jul 21 07:52:39.384589 2026] [security2:error] [pid 296703:tid 296940] [client 41.68.90.219:50958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pdyn25uliftkV1n46kQAAAGs"]
[Tue Jul 21 07:52:39.516496 2026] [security2:error] [pid 296703:tid 296934] [client 45.3.45.140:60015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9Pdin25uliftkV1n46QAAAAGU"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:52:39.552816 2026] [security2:error] [pid 296703:tid 296876] [client 85.204.70.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pdyn25uliftkV1n46lQAAACs"]
[Tue Jul 21 07:52:39.588465 2026] [security2:error] [pid 296703:tid 296935] [client 20.226.60.151:56799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/zlece.php"] [unique_id "al9Pdyn25uliftkV1n46lgAAAGY"]
[Tue Jul 21 07:52:39.815110 2026] [security2:error] [pid 296703:tid 296959] [client 20.104.96.117:64291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/file88.php"] [unique_id "al9Pdyn25uliftkV1n46oAAAAH4"]
[Tue Jul 21 07:52:39.978053 2026] [security2:error] [pid 296703:tid 296927] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Pdyn25uliftkV1n46pQAAAF4"]
[Tue Jul 21 07:52:40.115045 2026] [security2:error] [pid 296703:tid 296821] [remote 97.74.93.24:60220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "combolog.com.br"] [uri "/wp-login.php"] [unique_id "al9PeCn25uliftkV1n46qgAAM3U"]
[Tue Jul 21 07:52:40.254272 2026] [security2:error] [pid 296703:tid 296953] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9PeCn25uliftkV1n46rwAAAHg"]
[Tue Jul 21 07:52:40.402392 2026] [security2:error] [pid 296703:tid 296869] [client 54.251.12.30:38714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/htdocs/phpinfo.php"] [unique_id "al9PeCn25uliftkV1n46tAAAACQ"]
[Tue Jul 21 07:52:40.438526 2026] [security2:error] [pid 296703:tid 296797] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PeCn25uliftkV1n46tQAARF0"]
[Tue Jul 21 07:52:40.438735 2026] [security2:error] [pid 296703:tid 296901] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PeCn25uliftkV1n46tQAARF0"]
[Tue Jul 21 07:52:40.490995 2026] [security2:error] [pid 296703:tid 296954] [client 20.226.60.151:56817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/vssrs.php"] [unique_id "al9PeCn25uliftkV1n46tgAAAHk"]
[Tue Jul 21 07:52:40.519641 2026] [security2:error] [pid 296703:tid 296866] [client 20.104.96.117:64289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/ccc.php"] [unique_id "al9PeCn25uliftkV1n46twAAACE"]
[Tue Jul 21 07:52:40.530436 2026] [security2:error] [pid 296703:tid 296910] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9PeCn25uliftkV1n46uAAAAE0"]
[Tue Jul 21 07:52:40.731992 2026] [security2:error] [pid 296703:tid 296841] [client 20.104.96.117:54962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/mg.php"] [unique_id "al9PeCn25uliftkV1n46vwAAAAg"]
[Tue Jul 21 07:52:40.805188 2026] [security2:error] [pid 296703:tid 296859] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9PeCn25uliftkV1n46wAAAABo"]
[Tue Jul 21 07:52:40.839922 2026] [security2:error] [pid 296703:tid 296846] [client 193.36.225.105:55265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Pdyn25uliftkV1n46ogAAAA0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:52:40.841829 2026] [security2:error] [pid 296703:tid 296915] [client 193.36.225.64:20517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PeCn25uliftkV1n46wQAAAFI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:52:40.882601 2026] [security2:error] [pid 296703:tid 296870] [client 92.119.178.3:60782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9PeCn25uliftkV1n46wgAAACU"]
[Tue Jul 21 07:52:40.882682 2026] [security2:error] [pid 296703:tid 296870] [client 92.119.178.3:60782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9PeCn25uliftkV1n46wgAAACU"]
[Tue Jul 21 07:52:40.989876 2026] [security2:error] [pid 296703:tid 296932] [client 34.182.235.64:61064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.lylow.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9PeCn25uliftkV1n46yAAAAGM"]
[Tue Jul 21 07:52:41.063087 2026] [security2:error] [pid 296703:tid 296879] [client 122.162.144.145:31251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PeSn25uliftkV1n46ygAAAC4"]
[Tue Jul 21 07:52:41.063223 2026] [security2:error] [pid 296703:tid 296879] [client 122.162.144.145:31251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PeSn25uliftkV1n46ygAAAC4"]
[Tue Jul 21 07:52:41.081221 2026] [security2:error] [pid 296703:tid 296892] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9PeSn25uliftkV1n46ywAAADs"]
[Tue Jul 21 07:52:41.289642 2026] [security2:error] [pid 296703:tid 296731] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PeSn25uliftkV1n461AAAbRs"]
[Tue Jul 21 07:52:41.289895 2026] [security2:error] [pid 296703:tid 296942] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PeSn25uliftkV1n461AAAbRs"]
[Tue Jul 21 07:52:41.290027 2026] [ssl:error] [pid 296703:tid 296908] [client 185.247.137.141:52095] AH02032: Hostname www.tofaseg.levesdigital.com.br provided via SNI and hostname tofaseg.com.br provided via HTTP have no compatible SSL setup for policy 'secure', referer: https://www.tofaseg.levesdigital.com.br
[Tue Jul 21 07:52:41.356663 2026] [security2:error] [pid 296703:tid 296849] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9PeSn25uliftkV1n461gAAABA"]
[Tue Jul 21 07:52:41.440078 2026] [security2:error] [pid 296703:tid 296875] [client 54.251.12.30:38728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/public_html/phpinfo.php"] [unique_id "al9PeSn25uliftkV1n462wAAACo"]
[Tue Jul 21 07:52:41.630944 2026] [security2:error] [pid 296703:tid 296854] [client 103.86.117.203:53151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PeSn25uliftkV1n463gAAABU"]
[Tue Jul 21 07:52:41.631162 2026] [security2:error] [pid 296703:tid 296854] [client 103.86.117.203:53151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PeSn25uliftkV1n463gAAABU"]
[Tue Jul 21 07:52:41.651766 2026] [security2:error] [pid 296703:tid 296910] [client 20.104.96.117:60672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/777.php"] [unique_id "al9PeSn25uliftkV1n463wAAAE0"]
[Tue Jul 21 07:52:41.658622 2026] [security2:error] [pid 296703:tid 296844] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9PeSn25uliftkV1n464AAAAAs"]
[Tue Jul 21 07:52:41.864315 2026] [security2:error] [pid 296703:tid 296880] [client 103.166.103.129:54588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PeSn25uliftkV1n466wAAAC8"]
[Tue Jul 21 07:52:41.864402 2026] [security2:error] [pid 296703:tid 296880] [client 103.166.103.129:54588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PeSn25uliftkV1n466wAAAC8"]
[Tue Jul 21 07:52:41.937161 2026] [security2:error] [pid 296703:tid 296860] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9PeSn25uliftkV1n469AAAABs"]
[Tue Jul 21 07:52:42.008962 2026] [security2:error] [pid 296703:tid 296924] [client 223.236.153.128:5155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Pein25uliftkV1n469gAAAFs"]
[Tue Jul 21 07:52:42.009106 2026] [security2:error] [pid 296703:tid 296924] [client 223.236.153.128:5155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Pein25uliftkV1n469gAAAFs"]
[Tue Jul 21 07:52:42.213297 2026] [security2:error] [pid 296703:tid 296839] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Pein25uliftkV1n46_gAAAAY"]
[Tue Jul 21 07:52:42.333307 2026] [security2:error] [pid 296703:tid 296875] [client 20.104.96.117:64327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/for.php"] [unique_id "al9Pein25uliftkV1n47BAAAACo"]
[Tue Jul 21 07:52:42.446581 2026] [security2:error] [pid 296703:tid 296910] [client 34.182.235.64:50930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.lylow.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Pein25uliftkV1n47DAAAAE0"]
[Tue Jul 21 07:52:42.457466 2026] [security2:error] [pid 296703:tid 296915] [client 202.143.127.214:59500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pein25uliftkV1n47DgAAAFI"]
[Tue Jul 21 07:52:42.457594 2026] [security2:error] [pid 296703:tid 296915] [client 202.143.127.214:59500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pein25uliftkV1n47DgAAAFI"]
[Tue Jul 21 07:52:42.477400 2026] [security2:error] [pid 296703:tid 296906] [client 54.251.12.30:38738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/site/phpinfo.php"] [unique_id "al9Pein25uliftkV1n47DwAAAEk"]
[Tue Jul 21 07:52:42.490247 2026] [security2:error] [pid 296703:tid 296876] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Pein25uliftkV1n47EAAAACs"]
[Tue Jul 21 07:52:42.523317 2026] [security2:error] [pid 296703:tid 296888] [client 20.226.60.151:56781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wicked.php"] [unique_id "al9Pein25uliftkV1n47EQAAADc"]
[Tue Jul 21 07:52:42.592292 2026] [security2:error] [pid 296703:tid 296939] [client 74.249.245.134:64414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/click.php"] [unique_id "al9Pein25uliftkV1n47EwAAAGo"]
[Tue Jul 21 07:52:42.708419 2026] [security2:error] [pid 296703:tid 296817] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Pein25uliftkV1n47FAAADHE"]
[Tue Jul 21 07:52:42.708612 2026] [security2:error] [pid 296703:tid 296845] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Pein25uliftkV1n47FAAADHE"]
[Tue Jul 21 07:52:42.766695 2026] [security2:error] [pid 296703:tid 296930] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Pein25uliftkV1n47FwAAAGE"]
[Tue Jul 21 07:52:42.926078 2026] [security2:error] [pid 296703:tid 296864] [client 20.104.96.117:64349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/ssla.php"] [unique_id "al9Pein25uliftkV1n47HgAAAB8"]
[Tue Jul 21 07:52:43.040293 2026] [security2:error] [pid 296703:tid 296849] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9Peyn25uliftkV1n47IgAAABA"]
[Tue Jul 21 07:52:43.316460 2026] [security2:error] [pid 296703:tid 296854] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9Peyn25uliftkV1n47KQAAABU"]
[Tue Jul 21 07:52:43.333408 2026] [security2:error] [pid 296703:tid 296929] [client 193.36.225.142:23967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Peyn25uliftkV1n47JAAAAGA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:52:43.389116 2026] [security2:error] [pid 296703:tid 296842] [client 178.153.91.96:61942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Peyn25uliftkV1n47LgAAAAk"]
[Tue Jul 21 07:52:43.389271 2026] [security2:error] [pid 296703:tid 296842] [client 178.153.91.96:61942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Peyn25uliftkV1n47LgAAAAk"]
[Tue Jul 21 07:52:43.449520 2026] [security2:error] [pid 296703:tid 296883] [client 34.182.235.64:50930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.lylow.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Peyn25uliftkV1n47LwAAADI"]
[Tue Jul 21 07:52:43.479208 2026] [security2:error] [pid 296703:tid 296747] [remote 37.139.53.5:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9Peyn25uliftkV1n47MQAAGis"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:52:43.479374 2026] [security2:error] [pid 296703:tid 296859] [client 37.139.53.5:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9Peyn25uliftkV1n47MQAAGis"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:52:43.492089 2026] [proxy:error] [pid 296703:tid 296939] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:43.492160 2026] [proxy_http:error] [pid 296703:tid 296939] [client 161.35.142.61:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:52:43.492879 2026] [proxy:error] [pid 296703:tid 296939] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:43.492919 2026] [proxy_http:error] [pid 296703:tid 296939] [client 161.35.142.61:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:52:43.502802 2026] [security2:error] [pid 296703:tid 296913] [client 54.251.12.30:38742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/docs/phpinfo.php"] [unique_id "al9Peyn25uliftkV1n47NgAAAFA"]
[Tue Jul 21 07:52:43.591187 2026] [security2:error] [pid 296703:tid 296905] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Peyn25uliftkV1n47OQAAAEg"]
[Tue Jul 21 07:52:43.653739 2026] [security2:error] [pid 296703:tid 296843] [client 139.167.225.182:54857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Peyn25uliftkV1n47OgAAAAo"]
[Tue Jul 21 07:52:43.653880 2026] [security2:error] [pid 296703:tid 296843] [client 139.167.225.182:54857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Peyn25uliftkV1n47OgAAAAo"]
[Tue Jul 21 07:52:43.719989 2026] [security2:error] [pid 296703:tid 296802] [remote 37.139.53.5:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9Peyn25uliftkV1n47PAAAc2I"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:52:43.720186 2026] [security2:error] [pid 296703:tid 296948] [client 37.139.53.5:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9Peyn25uliftkV1n47PAAAc2I"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:52:43.764594 2026] [proxy:error] [pid 296703:tid 296887] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:43.764662 2026] [proxy_http:error] [pid 296703:tid 296887] [client 161.35.142.61:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.julianasantosdutra1782388096435.0711679.meusitehostgator.com.br/
[Tue Jul 21 07:52:43.765271 2026] [proxy:error] [pid 296703:tid 296887] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:43.765298 2026] [proxy_http:error] [pid 296703:tid 296887] [client 161.35.142.61:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.julianasantosdutra1782388096435.0711679.meusitehostgator.com.br/
[Tue Jul 21 07:52:43.864767 2026] [security2:error] [pid 296703:tid 296882] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Peyn25uliftkV1n47QAAAADE"]
[Tue Jul 21 07:52:43.896899 2026] [security2:error] [pid 296703:tid 296924] [client 20.104.96.117:59714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sideli.com.br"] [uri "/zc-131.php"] [unique_id "al9Peyn25uliftkV1n47QwAAAFs"]
[Tue Jul 21 07:52:43.965262 2026] [security2:error] [pid 296703:tid 296861] [client 117.247.80.59:29357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Peyn25uliftkV1n47RwAAABw"]
[Tue Jul 21 07:52:43.965355 2026] [security2:error] [pid 296703:tid 296861] [client 117.247.80.59:29357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Peyn25uliftkV1n47RwAAABw"]
[Tue Jul 21 07:52:44.060968 2026] [security2:error] [pid 296703:tid 296855] [client 20.226.60.151:56805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/24.php"] [unique_id "al9PfCn25uliftkV1n47TAAAABY"]
[Tue Jul 21 07:52:44.139510 2026] [security2:error] [pid 296703:tid 296914] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.carolinaborges1782162049177.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9PfCn25uliftkV1n47UQAAAFE"]
[Tue Jul 21 07:52:44.159458 2026] [security2:error] [pid 296703:tid 296837] [client 173.24.185.52:51681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PfCn25uliftkV1n47UgAAAAQ"]
[Tue Jul 21 07:52:44.159599 2026] [security2:error] [pid 296703:tid 296837] [client 173.24.185.52:51681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PfCn25uliftkV1n47UgAAAAQ"]
[Tue Jul 21 07:52:44.235955 2026] [security2:error] [pid 296703:tid 296920] [client 34.182.235.64:61634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.lylow.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9PfCn25uliftkV1n47VwAAAFc"]
[Tue Jul 21 07:52:44.476978 2026] [security2:error] [pid 296703:tid 296960] [client 193.36.225.55:36477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PfCn25uliftkV1n47XgAAAH8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:52:44.518988 2026] [security2:error] [pid 296703:tid 296875] [client 109.60.28.94:31317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PfCn25uliftkV1n47YAAAACo"]
[Tue Jul 21 07:52:44.519131 2026] [security2:error] [pid 296703:tid 296875] [client 109.60.28.94:31317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PfCn25uliftkV1n47YAAAACo"]
[Tue Jul 21 07:52:44.562121 2026] [security2:error] [pid 296703:tid 296866] [client 54.251.12.30:38752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/wp-admin/phpinfo.php"] [unique_id "al9PfCn25uliftkV1n47YgAAACE"]
[Tue Jul 21 07:52:44.644304 2026] [security2:error] [pid 296703:tid 296907] [client 117.217.38.194:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PfCn25uliftkV1n47ZgAAAEo"]
[Tue Jul 21 07:52:44.644462 2026] [security2:error] [pid 296703:tid 296907] [client 117.217.38.194:62693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PfCn25uliftkV1n47ZgAAAEo"]
[Tue Jul 21 07:52:44.725094 2026] [security2:error] [pid 296703:tid 296850] [client 122.186.204.214:54954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PfCn25uliftkV1n47ZwAAABE"]
[Tue Jul 21 07:52:44.725260 2026] [security2:error] [pid 296703:tid 296850] [client 122.186.204.214:54954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PfCn25uliftkV1n47ZwAAABE"]
[Tue Jul 21 07:52:44.921955 2026] [security2:error] [pid 296703:tid 296790] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PfCn25uliftkV1n47bwAAPFY"]
[Tue Jul 21 07:52:44.922180 2026] [security2:error] [pid 296703:tid 296893] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PfCn25uliftkV1n47bwAAPFY"]
[Tue Jul 21 07:52:44.971152 2026] [security2:error] [pid 296703:tid 296921] [client 34.182.235.64:59810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.lylow.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9PfCn25uliftkV1n47cwAAAFg"]
[Tue Jul 21 07:52:45.017313 2026] [security2:error] [pid 296703:tid 296836] [client 34.141.229.34:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.barcob.com"] [uri "/"] [unique_id "al9PfSn25uliftkV1n47dgAAAAM"]
[Tue Jul 21 07:52:45.017417 2026] [security2:error] [pid 296703:tid 296836] [client 34.141.229.34:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.barcob.com"] [uri "/"] [unique_id "al9PfSn25uliftkV1n47dgAAAAM"]
[Tue Jul 21 07:52:45.091567 2026] [security2:error] [pid 296703:tid 296869] [client 103.78.200.11:59472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PfCn25uliftkV1n47cAAAACQ"]
[Tue Jul 21 07:52:45.091750 2026] [security2:error] [pid 296703:tid 296869] [client 103.78.200.11:59472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PfCn25uliftkV1n47cAAAACQ"]
[Tue Jul 21 07:52:45.114273 2026] [security2:error] [pid 296703:tid 296824] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PfSn25uliftkV1n47eQAAGXg"]
[Tue Jul 21 07:52:45.114437 2026] [security2:error] [pid 296703:tid 296858] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PfSn25uliftkV1n47eQAAGXg"]
[Tue Jul 21 07:52:45.218716 2026] [security2:error] [pid 296703:tid 296910] [client 74.249.245.134:8799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/t.php"] [unique_id "al9PfSn25uliftkV1n47fQAAAE0"]
[Tue Jul 21 07:52:45.311124 2026] [security2:error] [pid 296703:tid 296936] [client 20.104.96.117:54980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-post-data.php"] [unique_id "al9PfSn25uliftkV1n47gwAAAGc"]
[Tue Jul 21 07:52:45.399447 2026] [security2:error] [pid 296703:tid 296888] [client 103.29.114.44:61518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PfSn25uliftkV1n47hwAAADc"]
[Tue Jul 21 07:52:45.399594 2026] [security2:error] [pid 296703:tid 296888] [client 103.29.114.44:61518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PfSn25uliftkV1n47hwAAADc"]
[Tue Jul 21 07:52:45.431558 2026] [security2:error] [pid 296703:tid 296782] [remote 217.154.211.247:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.211.154.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cromobelo.com.br"] [uri "/wp-login.php"] [unique_id "al9PfSn25uliftkV1n47iAAAPU4"]
[Tue Jul 21 07:52:45.593959 2026] [security2:error] [pid 296703:tid 296856] [client 54.251.12.30:38760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/administrator/phpinfo.php"] [unique_id "al9PfSn25uliftkV1n47kAAAABc"]
[Tue Jul 21 07:52:45.713147 2026] [security2:error] [pid 296703:tid 296934] [client 74.249.245.134:64428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/lv.php"] [unique_id "al9PfSn25uliftkV1n47lQAAAGU"]
[Tue Jul 21 07:52:45.956103 2026] [security2:error] [pid 296703:tid 296952] [client 20.104.96.117:12867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9PfSn25uliftkV1n47nAAAAHc"]
[Tue Jul 21 07:52:46.085680 2026] [security2:error] [pid 296703:tid 296706] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PfSn25uliftkV1n47mwAAHwI"]
[Tue Jul 21 07:52:46.085959 2026] [security2:error] [pid 296703:tid 296864] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PfSn25uliftkV1n47mwAAHwI"]
[Tue Jul 21 07:52:46.389383 2026] [security2:error] [pid 296703:tid 296893] [client 122.179.91.63:13289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Pfin25uliftkV1n47pwAAADw"]
[Tue Jul 21 07:52:46.389510 2026] [security2:error] [pid 296703:tid 296893] [client 122.179.91.63:13289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Pfin25uliftkV1n47pwAAADw"]
[Tue Jul 21 07:52:46.582028 2026] [security2:error] [pid 296703:tid 296714] [remote 167.160.77.30:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9PfSn25uliftkV1n47fwAAFgo"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:52:46.602455 2026] [security2:error] [pid 296703:tid 296927] [client 20.104.96.117:12879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Pfin25uliftkV1n47rgAAAF4"]
[Tue Jul 21 07:52:46.631092 2026] [security2:error] [pid 296703:tid 296863] [client 54.251.12.30:49576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/core/phpinfo.php"] [unique_id "al9Pfin25uliftkV1n47rwAAAB4"]
[Tue Jul 21 07:52:46.679238 2026] [security2:error] [pid 296703:tid 296855] [client 167.160.77.30:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9PfSn25uliftkV1n47fwAAFgo"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:52:46.808214 2026] [security2:error] [pid 296703:tid 296794] [remote 144.217.254.10:59502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.254.217.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-login.php"] [unique_id "al9Pfin25uliftkV1n47tQAAdFo"]
[Tue Jul 21 07:52:47.083020 2026] [security2:error] [pid 296703:tid 296858] [client 20.104.96.117:12614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/media.php"] [unique_id "al9Pfyn25uliftkV1n47uwAAABk"]
[Tue Jul 21 07:52:47.251463 2026] [security2:error] [pid 296703:tid 296722] [remote 147.92.53.93:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9PfCn25uliftkV1n47bgAAVRI"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:52:47.269382 2026] [security2:error] [pid 296703:tid 296906] [client 172.245.102.32:48545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Pfyn25uliftkV1n47xgAAAEk"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:52:47.319496 2026] [security2:error] [pid 296703:tid 296930] [client 106.215.181.8:24433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pfyn25uliftkV1n47xwAAAGE"]
[Tue Jul 21 07:52:47.319611 2026] [security2:error] [pid 296703:tid 296930] [client 106.215.181.8:24433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pfyn25uliftkV1n47xwAAAGE"]
[Tue Jul 21 07:52:47.333392 2026] [security2:error] [pid 296703:tid 296918] [client 147.92.53.93:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "cromobelo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9PfCn25uliftkV1n47bgAAVRI"], referer: https://cromobelo.com.br/2020/08/06/metalizacao-em-cromo/?unapproved=6547&moderation-hash=39b53877f6b6894645ed3235b1178b4c
[Tue Jul 21 07:52:47.554372 2026] [security2:error] [pid 296703:tid 296951] [client 20.226.60.151:56746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xacs.php"] [unique_id "al9Pfyn25uliftkV1n47zAAAAHY"]
[Tue Jul 21 07:52:47.625485 2026] [security2:error] [pid 296703:tid 296786] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Pfyn25uliftkV1n47zwAAP1I"]
[Tue Jul 21 07:52:47.625620 2026] [security2:error] [pid 296703:tid 296896] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Pfyn25uliftkV1n47zwAAP1I"]
[Tue Jul 21 07:52:47.645084 2026] [security2:error] [pid 296703:tid 296905] [client 20.104.96.117:12864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/images.php"] [unique_id "al9Pfyn25uliftkV1n470QAAAEg"]
[Tue Jul 21 07:52:47.696331 2026] [security2:error] [pid 296703:tid 296846] [client 54.251.12.30:49592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.12.251.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/includes/phpinfo.php"] [unique_id "al9Pfyn25uliftkV1n471QAAAA0"]
[Tue Jul 21 07:52:47.798607 2026] [security2:error] [pid 296703:tid 296769] [remote 5.202.15.246:48980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.15.202.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pomotionjustforyou.com"] [uri "/wp-login.php"] [unique_id "al9Pfin25uliftkV1n47tAAAf0E"]
[Tue Jul 21 07:52:47.983332 2026] [security2:error] [pid 296703:tid 296850] [client 20.104.96.117:12866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/gecko.php"] [unique_id "al9Pfyn25uliftkV1n472wAAABE"]
[Tue Jul 21 07:52:48.026793 2026] [security2:error] [pid 296703:tid 296739] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PgCn25uliftkV1n473QAAQiM"]
[Tue Jul 21 07:52:48.027020 2026] [security2:error] [pid 296703:tid 296899] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PgCn25uliftkV1n473QAAQiM"]
[Tue Jul 21 07:52:48.353282 2026] [security2:error] [pid 296703:tid 296952] [client 136.144.33.112:45213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PgCn25uliftkV1n47_gAAAHc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:52:48.377689 2026] [security2:error] [pid 296703:tid 296890] [client 198.54.128.138:59512] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Pfyn25uliftkV1n47xQAAADk"]
[Tue Jul 21 07:52:48.377794 2026] [security2:error] [pid 296703:tid 296890] [client 198.54.128.138:59512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Pfyn25uliftkV1n47xQAAADk"]
[Tue Jul 21 07:52:48.431052 2026] [security2:error] [pid 296703:tid 296892] [client 20.104.96.117:12656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/82.php"] [unique_id "al9PgCn25uliftkV1n48BwAAADs"]
[Tue Jul 21 07:52:48.452137 2026] [security2:error] [pid 296703:tid 296953] [client 74.249.245.134:24773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/a.php"] [unique_id "al9PgCn25uliftkV1n48CAAAAHg"]
[Tue Jul 21 07:52:48.483027 2026] [security2:error] [pid 296703:tid 296859] [client 74.249.245.134:64435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/cong.php"] [unique_id "al9PgCn25uliftkV1n48CQAAABo"]
[Tue Jul 21 07:52:48.982751 2026] [security2:error] [pid 296703:tid 296899] [client 20.104.96.117:12883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/admin.php"] [unique_id "al9PgCn25uliftkV1n48FwAAAEI"]
[Tue Jul 21 07:52:49.328758 2026] [security2:error] [pid 296703:tid 296940] [client 20.104.96.117:12874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/adminner.php"] [unique_id "al9PgSn25uliftkV1n48KAAAAGs"]
[Tue Jul 21 07:52:49.475746 2026] [security2:error] [pid 296703:tid 296844] [client 122.164.127.47:56164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PgSn25uliftkV1n48KQAAAAs"]
[Tue Jul 21 07:52:49.475886 2026] [security2:error] [pid 296703:tid 296844] [client 122.164.127.47:56164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PgSn25uliftkV1n48KQAAAAs"]
[Tue Jul 21 07:52:49.593045 2026] [security2:error] [pid 296703:tid 296855] [client 182.8.255.181:17506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PgSn25uliftkV1n48KwAAABY"]
[Tue Jul 21 07:52:49.593158 2026] [security2:error] [pid 296703:tid 296855] [client 182.8.255.181:17506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PgSn25uliftkV1n48KwAAABY"]
[Tue Jul 21 07:52:49.640601 2026] [security2:error] [pid 296703:tid 296876] [client 20.104.96.117:12635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/admin.php"] [unique_id "al9PgSn25uliftkV1n48LAAAACs"]
[Tue Jul 21 07:52:49.783001 2026] [autoindex:error] [pid 296703:tid 296846] [client 40.223.166.124:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:52:49.914547 2026] [security2:error] [pid 296703:tid 296906] [client 20.104.96.117:57440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/pucci.php"] [unique_id "al9PgSn25uliftkV1n48PgAAAEk"]
[Tue Jul 21 07:52:50.040942 2026] [security2:error] [pid 296703:tid 296953] [client 37.140.223.200:23421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PgSn25uliftkV1n48OgAAAHg"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:52:50.085615 2026] [security2:error] [pid 296703:tid 296911] [client 20.104.96.117:12628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/k.php"] [unique_id "al9Pgin25uliftkV1n48QgAAAE4"]
[Tue Jul 21 07:52:50.284091 2026] [security2:error] [pid 296703:tid 296864] [client 102.206.115.33:59602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Pgin25uliftkV1n48QwAAAB8"]
[Tue Jul 21 07:52:50.284311 2026] [security2:error] [pid 296703:tid 296864] [client 102.206.115.33:59602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Pgin25uliftkV1n48QwAAAB8"]
[Tue Jul 21 07:52:50.298031 2026] [security2:error] [pid 296703:tid 296762] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pgin25uliftkV1n48TQAAOzo"]
[Tue Jul 21 07:52:50.298134 2026] [security2:error] [pid 296703:tid 296892] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pgin25uliftkV1n48TQAAOzo"]
[Tue Jul 21 07:52:50.425576 2026] [security2:error] [pid 296703:tid 296883] [client 41.68.90.219:51406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pgin25uliftkV1n48UwAAADI"]
[Tue Jul 21 07:52:50.426808 2026] [security2:error] [pid 296703:tid 296883] [client 41.68.90.219:51406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pgin25uliftkV1n48UwAAADI"]
[Tue Jul 21 07:52:50.590149 2026] [security2:error] [pid 296703:tid 296866] [client 20.104.96.117:12912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/blurbs.php"] [unique_id "al9Pgin25uliftkV1n48WQAAACE"]
[Tue Jul 21 07:52:50.990321 2026] [security2:error] [pid 296703:tid 296727] [remote 192.241.143.148:59170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alcovaperiodico.com"] [uri "/wp-login.php"] [unique_id "al9Pgin25uliftkV1n48jQAAFhc"]
[Tue Jul 21 07:52:51.094007 2026] [security2:error] [pid 296703:tid 296870] [client 20.104.96.117:12616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/bajah.php"] [unique_id "al9Pgyn25uliftkV1n48jwAAACU"]
[Tue Jul 21 07:52:51.150606 2026] [security2:error] [pid 296703:tid 296706] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Pgyn25uliftkV1n48kAAAUAI"]
[Tue Jul 21 07:52:51.150808 2026] [security2:error] [pid 296703:tid 296913] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Pgyn25uliftkV1n48kAAAUAI"]
[Tue Jul 21 07:52:51.455344 2026] [security2:error] [pid 296703:tid 296907] [client 20.104.96.117:12891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/a.php"] [unique_id "al9Pgyn25uliftkV1n48owAAAEo"]
[Tue Jul 21 07:52:51.787529 2026] [security2:error] [pid 296703:tid 296940] [client 20.104.96.117:12642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/edit.php"] [unique_id "al9Pgyn25uliftkV1n48rwAAAGs"]
[Tue Jul 21 07:52:51.827932 2026] [security2:error] [pid 296703:tid 296839] [client 122.162.144.145:24812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Pgyn25uliftkV1n48sQAAAAY"]
[Tue Jul 21 07:52:51.828032 2026] [security2:error] [pid 296703:tid 296839] [client 122.162.144.145:24812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Pgyn25uliftkV1n48sQAAAAY"]
[Tue Jul 21 07:52:51.835117 2026] [security2:error] [pid 296703:tid 296712] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pgyn25uliftkV1n48sgAANwg"]
[Tue Jul 21 07:52:51.835213 2026] [security2:error] [pid 296703:tid 296888] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Pgyn25uliftkV1n48sgAANwg"]
[Tue Jul 21 07:52:51.953654 2026] [security2:error] [pid 296703:tid 296838] [client 20.220.225.223:23484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9Pgyn25uliftkV1n48tgAAAAU"]
[Tue Jul 21 07:52:52.110518 2026] [security2:error] [pid 296703:tid 296960] [client 103.86.117.203:53696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PhCn25uliftkV1n48vQAAAH8"]
[Tue Jul 21 07:52:52.110681 2026] [security2:error] [pid 296703:tid 296960] [client 103.86.117.203:53696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PhCn25uliftkV1n48vQAAAH8"]
[Tue Jul 21 07:52:52.238589 2026] [security2:error] [pid 296703:tid 296880] [client 20.104.96.117:12618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/hosty.php"] [unique_id "al9PhCn25uliftkV1n48xAAAAC8"]
[Tue Jul 21 07:52:52.580203 2026] [security2:error] [pid 296703:tid 296921] [client 103.166.103.129:39881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PhCn25uliftkV1n480AAAAFg"]
[Tue Jul 21 07:52:52.580337 2026] [security2:error] [pid 296703:tid 296921] [client 103.166.103.129:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PhCn25uliftkV1n480AAAAFg"]
[Tue Jul 21 07:52:52.582102 2026] [security2:error] [pid 296703:tid 296883] [client 20.104.96.117:12484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/k.php"] [unique_id "al9PhCn25uliftkV1n480QAAADI"]
[Tue Jul 21 07:52:52.632776 2026] [security2:error] [pid 296703:tid 296844] [client 20.104.96.117:54918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/black.php"] [unique_id "al9PhCn25uliftkV1n480gAAAAs"]
[Tue Jul 21 07:52:52.727775 2026] [security2:error] [pid 296703:tid 296896] [client 223.236.153.128:5163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PhCn25uliftkV1n481AAAAD8"]
[Tue Jul 21 07:52:52.732543 2026] [security2:error] [pid 296703:tid 296896] [client 223.236.153.128:5163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PhCn25uliftkV1n481AAAAD8"]
[Tue Jul 21 07:52:53.088496 2026] [security2:error] [pid 296703:tid 296837] [client 20.104.96.117:12873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/aaa.php"] [unique_id "al9PhSn25uliftkV1n49BwAAAAQ"]
[Tue Jul 21 07:52:53.284735 2026] [security2:error] [pid 296703:tid 296883] [client 20.226.60.151:61601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/sixxis.php"] [unique_id "al9PhSn25uliftkV1n49HAAAADI"]
[Tue Jul 21 07:52:53.436186 2026] [security2:error] [pid 296703:tid 296913] [client 20.220.225.223:23485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/wp-css.php"] [unique_id "al9PhSn25uliftkV1n49IgAAAFA"]
[Tue Jul 21 07:52:53.441526 2026] [security2:error] [pid 296703:tid 296898] [client 74.249.245.134:24818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/brand.php"] [unique_id "al9PhSn25uliftkV1n49IwAAAEE"]
[Tue Jul 21 07:52:53.445049 2026] [security2:error] [pid 296703:tid 296914] [client 74.249.245.134:64438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/a1.php"] [unique_id "al9PhSn25uliftkV1n49JAAAAFE"]
[Tue Jul 21 07:52:53.592111 2026] [security2:error] [pid 296703:tid 296841] [client 136.144.33.107:24141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PhCn25uliftkV1n48zAAAAAg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:52:53.598849 2026] [security2:error] [pid 296703:tid 296906] [client 20.104.96.117:12647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/file5.php"] [unique_id "al9PhSn25uliftkV1n49LQAAAEk"]
[Tue Jul 21 07:52:53.750339 2026] [security2:error] [pid 296703:tid 296875] [client 202.143.127.214:59980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PhSn25uliftkV1n49SwAAACo"]
[Tue Jul 21 07:52:53.750501 2026] [security2:error] [pid 296703:tid 296875] [client 202.143.127.214:59980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PhSn25uliftkV1n49SwAAACo"]
[Tue Jul 21 07:52:53.754477 2026] [security2:error] [pid 296703:tid 296818] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PhSn25uliftkV1n49TAAAC3I"]
[Tue Jul 21 07:52:53.754638 2026] [security2:error] [pid 296703:tid 296844] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PhSn25uliftkV1n49TAAAC3I"]
[Tue Jul 21 07:52:53.892291 2026] [security2:error] [pid 296703:tid 296921] [client 178.153.91.96:45113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PhSn25uliftkV1n49XgAAAFg"]
[Tue Jul 21 07:52:53.892518 2026] [security2:error] [pid 296703:tid 296921] [client 178.153.91.96:45113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PhSn25uliftkV1n49XgAAAFg"]
[Tue Jul 21 07:52:53.938822 2026] [security2:error] [pid 296703:tid 296898] [client 20.104.96.117:12646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/222.php"] [unique_id "al9PhSn25uliftkV1n49cQAAAEE"]
[Tue Jul 21 07:52:54.202161 2026] [security2:error] [pid 296703:tid 296869] [client 139.167.225.182:55665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Phin25uliftkV1n49fAAAACQ"]
[Tue Jul 21 07:52:54.202273 2026] [security2:error] [pid 296703:tid 296869] [client 139.167.225.182:55665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Phin25uliftkV1n49fAAAACQ"]
[Tue Jul 21 07:52:54.217107 2026] [security2:error] [pid 296703:tid 296939] [client 20.104.96.117:12636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/test.php"] [unique_id "al9Phin25uliftkV1n49fwAAAGo"]
[Tue Jul 21 07:52:54.527589 2026] [security2:error] [pid 296703:tid 296876] [client 117.247.80.59:29311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Phin25uliftkV1n49pQAAACs"]
[Tue Jul 21 07:52:54.527689 2026] [security2:error] [pid 296703:tid 296876] [client 117.247.80.59:29311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Phin25uliftkV1n49pQAAACs"]
[Tue Jul 21 07:52:54.533284 2026] [security2:error] [pid 296703:tid 296930] [client 193.36.225.139:34061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Phin25uliftkV1n49hwAAAGE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:52:54.575215 2026] [security2:error] [pid 296703:tid 296946] [client 20.104.96.117:12664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/aaa.php"] [unique_id "al9Phin25uliftkV1n49tQAAAHE"]
[Tue Jul 21 07:52:54.687866 2026] [security2:error] [pid 296703:tid 296905] [client 173.24.185.52:52161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Phin25uliftkV1n49vQAAAEg"]
[Tue Jul 21 07:52:54.687982 2026] [security2:error] [pid 296703:tid 296905] [client 173.24.185.52:52161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9Phin25uliftkV1n49vQAAAEg"]
[Tue Jul 21 07:52:54.700509 2026] [security2:error] [pid 296703:tid 296896] [client 103.78.200.11:60059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Phin25uliftkV1n49vwAAAD8"]
[Tue Jul 21 07:52:54.700596 2026] [security2:error] [pid 296703:tid 296896] [client 103.78.200.11:60059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Phin25uliftkV1n49vwAAAD8"]
[Tue Jul 21 07:52:54.793410 2026] [security2:error] [pid 296703:tid 296816] [remote 100.42.189.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onkosclinica.com"] [uri "/wp-login.php"] [unique_id "al9Phin25uliftkV1n49wwAAPnA"]
[Tue Jul 21 07:52:54.938518 2026] [security2:error] [pid 296703:tid 296872] [client 20.104.96.117:12650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/11.php"] [unique_id "al9Phin25uliftkV1n49yAAAACc"]
[Tue Jul 21 07:52:55.118249 2026] [security2:error] [pid 296703:tid 296846] [client 117.217.38.194:63186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Phyn25uliftkV1n491gAAAA0"]
[Tue Jul 21 07:52:55.118356 2026] [security2:error] [pid 296703:tid 296846] [client 117.217.38.194:63186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Phyn25uliftkV1n491gAAAA0"]
[Tue Jul 21 07:52:55.183193 2026] [security2:error] [pid 296703:tid 296854] [client 20.104.96.117:55005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/zlece.php"] [unique_id "al9Phyn25uliftkV1n491wAAABU"]
[Tue Jul 21 07:52:55.401213 2026] [security2:error] [pid 296703:tid 296885] [client 122.186.204.214:55494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Phyn25uliftkV1n493AAAADQ"]
[Tue Jul 21 07:52:55.401344 2026] [security2:error] [pid 296703:tid 296885] [client 122.186.204.214:55494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Phyn25uliftkV1n493AAAADQ"]
[Tue Jul 21 07:52:55.442177 2026] [security2:error] [pid 296703:tid 296856] [client 109.60.28.94:65022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Phyn25uliftkV1n493QAAABc"]
[Tue Jul 21 07:52:55.442934 2026] [security2:error] [pid 296703:tid 296856] [client 109.60.28.94:65022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Phyn25uliftkV1n493QAAABc"]
[Tue Jul 21 07:52:55.448252 2026] [security2:error] [pid 296703:tid 296905] [client 20.104.96.117:12669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/mac.php"] [unique_id "al9Phyn25uliftkV1n493gAAAEg"]
[Tue Jul 21 07:52:55.457489 2026] [security2:error] [pid 296703:tid 296740] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Phyn25uliftkV1n493wAAXiQ"]
[Tue Jul 21 07:52:55.457709 2026] [security2:error] [pid 296703:tid 296927] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Phyn25uliftkV1n493wAAXiQ"]
[Tue Jul 21 07:52:55.483080 2026] [security2:error] [pid 296703:tid 296825] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Phyn25uliftkV1n494wAAYHk"]
[Tue Jul 21 07:52:55.483212 2026] [security2:error] [pid 296703:tid 296929] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Phyn25uliftkV1n494wAAYHk"]
[Tue Jul 21 07:52:55.606661 2026] [autoindex:error] [pid 296703:tid 296906] [client 43.157.95.239:50190] AH01276: Cannot serve directory /home2/silv4569/silviolevada.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:52:55.794662 2026] [security2:error] [pid 296703:tid 296889] [client 20.104.96.117:12902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/chosen.php"] [unique_id "al9Phyn25uliftkV1n499gAAADg"]
[Tue Jul 21 07:52:56.124727 2026] [security2:error] [pid 296703:tid 296934] [client 20.104.96.117:12885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/cream1.php"] [unique_id "al9PiCn25uliftkV1n4-CwAAAGU"]
[Tue Jul 21 07:52:56.203179 2026] [security2:error] [pid 296703:tid 296952] [client 20.220.225.223:6095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/wp-explorer.php"] [unique_id "al9PiCn25uliftkV1n4-DgAAAHc"]
[Tue Jul 21 07:52:56.237121 2026] [security2:error] [pid 296703:tid 296774] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PiCn25uliftkV1n4-EQAAJEY"]
[Tue Jul 21 07:52:56.237347 2026] [security2:error] [pid 296703:tid 296869] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PiCn25uliftkV1n4-EQAAJEY"]
[Tue Jul 21 07:52:56.238088 2026] [proxy:error] [pid 296703:tid 296935] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:56.238134 2026] [proxy_http:error] [pid 296703:tid 296935] [client 159.65.187.103:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:52:56.238806 2026] [proxy:error] [pid 296703:tid 296935] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:56.238836 2026] [proxy_http:error] [pid 296703:tid 296935] [client 159.65.187.103:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:52:56.244709 2026] [security2:error] [pid 296703:tid 296877] [client 20.197.192.193:62033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9PiCn25uliftkV1n4-FAAAACw"]
[Tue Jul 21 07:52:56.246235 2026] [security2:error] [pid 296703:tid 296947] [client 103.29.114.44:18973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PiCn25uliftkV1n4-FQAAAHI"]
[Tue Jul 21 07:52:56.246326 2026] [security2:error] [pid 296703:tid 296947] [client 103.29.114.44:18973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PiCn25uliftkV1n4-FQAAAHI"]
[Tue Jul 21 07:52:56.364448 2026] [security2:error] [pid 296703:tid 296844] [client 20.197.192.193:61178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9PiCn25uliftkV1n4-GAAAAAs"]
[Tue Jul 21 07:52:56.385280 2026] [access_compat:error] [pid 296703:tid 296957] [client 162.241.63.68:39936] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:52:56.528539 2026] [proxy:error] [pid 296703:tid 296959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:56.528592 2026] [proxy_http:error] [pid 296703:tid 296959] [client 159.65.187.103:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.caetanodemoraeszanga1751206926735.0711679.meusitehostgator.com.br/
[Tue Jul 21 07:52:56.529158 2026] [proxy:error] [pid 296703:tid 296959] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:52:56.529183 2026] [proxy_http:error] [pid 296703:tid 296959] [client 159.65.187.103:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.caetanodemoraeszanga1751206926735.0711679.meusitehostgator.com.br/
[Tue Jul 21 07:52:56.568478 2026] [security2:error] [pid 296703:tid 296872] [client 20.104.96.117:55019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/vssrs.php"] [unique_id "al9PiCn25uliftkV1n4-IQAAACc"]
[Tue Jul 21 07:52:56.610768 2026] [security2:error] [pid 296703:tid 296896] [client 20.197.192.193:50925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/dp.php"] [unique_id "al9PiCn25uliftkV1n4-JwAAAD8"]
[Tue Jul 21 07:52:56.877222 2026] [security2:error] [pid 296703:tid 296842] [client 20.104.96.117:12622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/dr.php"] [unique_id "al9PiCn25uliftkV1n4-KgAAAAk"]
[Tue Jul 21 07:52:57.058448 2026] [security2:error] [pid 296703:tid 296869] [client 20.197.192.193:62044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/old.php"] [unique_id "al9PiSn25uliftkV1n4-LQAAACQ"]
[Tue Jul 21 07:52:57.206632 2026] [security2:error] [pid 296703:tid 296946] [client 20.220.225.223:6118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/akismet.php"] [unique_id "al9PiSn25uliftkV1n4-OQAAAHE"]
[Tue Jul 21 07:52:57.316738 2026] [autoindex:error] [pid 296703:tid 296910] [client 45.55.216.128:0] AH01276: Cannot serve directory /home2/gus15895/clinicapastanaeabreu.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:52:57.461183 2026] [security2:error] [pid 296703:tid 296856] [client 20.104.96.117:54970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wicked.php"] [unique_id "al9PiSn25uliftkV1n4-QAAAABc"]
[Tue Jul 21 07:52:57.501032 2026] [security2:error] [pid 296703:tid 296866] [client 122.179.91.63:30275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PiSn25uliftkV1n4-QQAAACE"]
[Tue Jul 21 07:52:57.501383 2026] [security2:error] [pid 296703:tid 296866] [client 122.179.91.63:30275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PiSn25uliftkV1n4-QQAAACE"]
[Tue Jul 21 07:52:57.527240 2026] [security2:error] [pid 296703:tid 296925] [client 20.197.192.193:29786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/ms-new.php"] [unique_id "al9PiSn25uliftkV1n4-QwAAAFw"]
[Tue Jul 21 07:52:57.543491 2026] [security2:error] [pid 296703:tid 296960] [client 20.104.96.117:12908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/x.php"] [unique_id "al9PiSn25uliftkV1n4-RAAAAH8"]
[Tue Jul 21 07:52:57.671327 2026] [security2:error] [pid 296703:tid 296842] [client 20.220.225.223:19278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/bootstrap.php"] [unique_id "al9PiSn25uliftkV1n4-UgAAAAk"]
[Tue Jul 21 07:52:57.779740 2026] [security2:error] [pid 296703:tid 296952] [client 106.215.181.8:2947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PiSn25uliftkV1n4-VwAAAHc"]
[Tue Jul 21 07:52:57.779841 2026] [security2:error] [pid 296703:tid 296952] [client 106.215.181.8:2947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PiSn25uliftkV1n4-VwAAAHc"]
[Tue Jul 21 07:52:57.783549 2026] [security2:error] [pid 296703:tid 296914] [client 74.249.245.134:64119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/w.php"] [unique_id "al9PiSn25uliftkV1n4-WAAAAFE"]
[Tue Jul 21 07:52:57.784318 2026] [security2:error] [pid 296703:tid 296837] [client 74.249.245.134:65152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/atomlib.php"] [unique_id "al9PiSn25uliftkV1n4-WQAAAAQ"]
[Tue Jul 21 07:52:57.825004 2026] [security2:error] [pid 296703:tid 296954] [client 20.197.192.193:61136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/track.php"] [unique_id "al9PiSn25uliftkV1n4-WgAAAHk"]
[Tue Jul 21 07:52:58.239111 2026] [security2:error] [pid 296703:tid 296794] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Piin25uliftkV1n4-ZwAAL1o"]
[Tue Jul 21 07:52:58.239411 2026] [security2:error] [pid 296703:tid 296880] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9Piin25uliftkV1n4-ZwAAL1o"]
[Tue Jul 21 07:52:58.338390 2026] [http2:info] [pid 341679:tid 341679] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 07:52:58.360179 2026] [security2:error] [pid 341679:tid 341818] [client 20.104.96.117:12614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/155.php"] [unique_id "al9PigWat-noHLkDuAhjTgAAARM"]
[Tue Jul 21 07:52:58.360206 2026] [security2:error] [pid 341679:tid 341809] [client 20.220.225.223:23467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madmoholding.com.br"] [uri "/ace2.php"] [unique_id "al9PigWat-noHLkDuAhjSwAAAQo"]
[Tue Jul 21 07:52:58.360272 2026] [security2:error] [pid 341679:tid 341815] [client 20.197.192.193:50903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/2352356666.php"] [unique_id "al9PigWat-noHLkDuAhjTQAAARA"]
[Tue Jul 21 07:52:58.364600 2026] [security2:error] [pid 341679:tid 341812] [client 204.8.98.45:42880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PigWat-noHLkDuAhjTAAAAQ0"]
[Tue Jul 21 07:52:58.364761 2026] [security2:error] [pid 341679:tid 341812] [client 204.8.98.45:42880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PigWat-noHLkDuAhjTAAAAQ0"]
[Tue Jul 21 07:52:58.679038 2026] [security2:error] [pid 341679:tid 341892] [client 20.197.192.193:61148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/pn.php"] [unique_id "al9PigWat-noHLkDuAhjjgAAAV0"]
[Tue Jul 21 07:52:58.745679 2026] [security2:error] [pid 341679:tid 341688] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PigWat-noHLkDuAhjlAABZwg"]
[Tue Jul 21 07:52:58.745829 2026] [security2:error] [pid 341679:tid 341902] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PigWat-noHLkDuAhjlAABZwg"]
[Tue Jul 21 07:52:58.912935 2026] [security2:error] [pid 341679:tid 341818] [client 20.104.96.117:12872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/ops.php"] [unique_id "al9PigWat-noHLkDuAhjlwAAARM"]
[Tue Jul 21 07:52:58.965149 2026] [security2:error] [pid 341679:tid 341815] [client 204.8.98.45:42874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PigWat-noHLkDuAhjmQAAARA"]
[Tue Jul 21 07:52:58.965274 2026] [security2:error] [pid 341679:tid 341815] [client 204.8.98.45:42874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PigWat-noHLkDuAhjmQAAARA"]
[Tue Jul 21 07:52:59.077101 2026] [security2:error] [pid 341679:tid 341877] [client 20.197.192.193:50888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9PiwWat-noHLkDuAhjmwAAAU4"]
[Tue Jul 21 07:52:59.087775 2026] [security2:error] [pid 341679:tid 341872] [client 20.104.96.117:55002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/24.php"] [unique_id "al9PiwWat-noHLkDuAhjnAAAAUk"]
[Tue Jul 21 07:52:59.154075 2026] [security2:error] [pid 341679:tid 341880] [client 20.226.60.151:56725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/zildan.php"] [unique_id "al9PiwWat-noHLkDuAhjnQAAAVE"]
[Tue Jul 21 07:52:59.256222 2026] [security2:error] [pid 341679:tid 341819] [client 20.197.192.193:61139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/dr.php"] [unique_id "al9PiwWat-noHLkDuAhjngAAARQ"]
[Tue Jul 21 07:52:59.311674 2026] [security2:error] [pid 341679:tid 341849] [client 20.104.96.117:12652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/file31.php"] [unique_id "al9PiwWat-noHLkDuAhjpQAAATI"]
[Tue Jul 21 07:52:59.795828 2026] [security2:error] [pid 341679:tid 341836] [client 20.197.192.193:62023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/2x.php"] [unique_id "al9PiwWat-noHLkDuAhjtQAAASU"]
[Tue Jul 21 07:52:59.859206 2026] [security2:error] [pid 341679:tid 341885] [client 20.104.96.117:12665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/file6.php"] [unique_id "al9PiwWat-noHLkDuAhjtwAAAVY"]
[Tue Jul 21 07:52:59.926078 2026] [security2:error] [pid 341679:tid 341881] [client 182.8.255.181:17156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PiwWat-noHLkDuAhjuAAAAVI"]
[Tue Jul 21 07:52:59.926224 2026] [security2:error] [pid 341679:tid 341881] [client 182.8.255.181:17156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PiwWat-noHLkDuAhjuAAAAVI"]
[Tue Jul 21 07:53:00.129292 2026] [security2:error] [pid 341679:tid 341888] [client 20.197.192.193:61180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/kq1.php"] [unique_id "al9PjAWat-noHLkDuAhjwgAAAVk"]
[Tue Jul 21 07:53:00.167612 2026] [security2:error] [pid 341679:tid 341827] [client 102.206.115.33:57978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9PjAWat-noHLkDuAhjxQAAARw"]
[Tue Jul 21 07:53:00.167762 2026] [security2:error] [pid 341679:tid 341827] [client 102.206.115.33:57978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9PjAWat-noHLkDuAhjxQAAARw"]
[Tue Jul 21 07:53:00.244492 2026] [security2:error] [pid 341679:tid 341848] [client 122.164.127.47:56747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PjAWat-noHLkDuAhjxgAAATE"]
[Tue Jul 21 07:53:00.244638 2026] [security2:error] [pid 341679:tid 341848] [client 122.164.127.47:56747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PjAWat-noHLkDuAhjxgAAATE"]
[Tue Jul 21 07:53:00.279808 2026] [security2:error] [pid 341679:tid 341905] [client 20.104.96.117:54953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/xacs.php"] [unique_id "al9PjAWat-noHLkDuAhjzAAAAWo"]
[Tue Jul 21 07:53:00.342664 2026] [security2:error] [pid 341679:tid 341916] [client 20.197.192.193:29102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/zzz.php"] [unique_id "al9PjAWat-noHLkDuAhj1AAAAXU"]
[Tue Jul 21 07:53:00.404660 2026] [security2:error] [pid 341679:tid 341930] [client 20.197.192.193:62035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wicked.php"] [unique_id "al9PjAWat-noHLkDuAhj1wAAAYM"]
[Tue Jul 21 07:53:00.482743 2026] [security2:error] [pid 341679:tid 341933] [client 20.104.96.117:12882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/adminfuns.php"] [unique_id "al9PjAWat-noHLkDuAhj2QAAAYY"]
[Tue Jul 21 07:53:00.546902 2026] [security2:error] [pid 341679:tid 341936] [client 20.226.60.151:61528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/ip.php"] [unique_id "al9PjAWat-noHLkDuAhj2wAAAYk"]
[Tue Jul 21 07:53:00.573482 2026] [security2:error] [pid 341679:tid 341815] [client 20.197.192.193:29809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/edit.php"] [unique_id "al9PjAWat-noHLkDuAhj3AAAARA"]
[Tue Jul 21 07:53:00.610765 2026] [security2:error] [pid 341679:tid 341820] [client 184.75.221.3:41922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9PjAWat-noHLkDuAhj4gAAARU"]
[Tue Jul 21 07:53:00.610875 2026] [security2:error] [pid 341679:tid 341820] [client 184.75.221.3:41922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9PjAWat-noHLkDuAhj4gAAARU"]
[Tue Jul 21 07:53:00.755399 2026] [security2:error] [pid 341679:tid 341872] [client 20.197.192.193:29803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/kua.php"] [unique_id "al9PjAWat-noHLkDuAhj4wAAAUk"]
[Tue Jul 21 07:53:00.851557 2026] [security2:error] [pid 341679:tid 341838] [client 20.197.192.193:29820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/ez.php"] [unique_id "al9PjAWat-noHLkDuAhkDgAAASc"]
[Tue Jul 21 07:53:00.996942 2026] [security2:error] [pid 341679:tid 341828] [client 20.197.192.193:50934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/fz.php"] [unique_id "al9PjAWat-noHLkDuAhkKAAAAR0"]
[Tue Jul 21 07:53:01.134759 2026] [security2:error] [pid 341679:tid 341870] [client 41.68.90.219:51867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PjQWat-noHLkDuAhkSAAAAUc"]
[Tue Jul 21 07:53:01.136135 2026] [security2:error] [pid 341679:tid 341870] [client 41.68.90.219:51867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PjQWat-noHLkDuAhkSAAAAUc"]
[Tue Jul 21 07:53:01.226169 2026] [security2:error] [pid 341679:tid 341834] [client 20.197.192.193:61146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/la.php"] [unique_id "al9PjQWat-noHLkDuAhkSgAAASM"]
[Tue Jul 21 07:53:01.286780 2026] [security2:error] [pid 341679:tid 341850] [client 20.197.192.193:29765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9PjQWat-noHLkDuAhkSwAAATM"]
[Tue Jul 21 07:53:01.341926 2026] [security2:error] [pid 341679:tid 341684] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PjQWat-noHLkDuAhkTgABOgQ"]
[Tue Jul 21 07:53:01.342075 2026] [security2:error] [pid 341679:tid 341857] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PjQWat-noHLkDuAhkTgABOgQ"]
[Tue Jul 21 07:53:01.362864 2026] [security2:error] [pid 341679:tid 341825] [client 20.197.192.193:29805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/inso.php"] [unique_id "al9PjQWat-noHLkDuAhkTwAAARo"]
[Tue Jul 21 07:53:01.450116 2026] [security2:error] [pid 341679:tid 341891] [client 20.104.96.117:12890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/goods.php"] [unique_id "al9PjQWat-noHLkDuAhkWAAAAVw"]
[Tue Jul 21 07:53:01.513906 2026] [security2:error] [pid 341679:tid 341862] [client 20.197.192.193:61168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wpx.php"] [unique_id "al9PjQWat-noHLkDuAhkWwAAAT8"]
[Tue Jul 21 07:53:01.619978 2026] [security2:error] [pid 341679:tid 341897] [client 20.197.192.193:29811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/berlin.php"] [unique_id "al9PjQWat-noHLkDuAhkcgAAAWI"]
[Tue Jul 21 07:53:01.711804 2026] [security2:error] [pid 341679:tid 341899] [client 20.197.192.193:50935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/billur.php"] [unique_id "al9PjQWat-noHLkDuAhkjwAAAWQ"]
[Tue Jul 21 07:53:01.771665 2026] [security2:error] [pid 341679:tid 341745] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PjQWat-noHLkDuAhknQABe0E"]
[Tue Jul 21 07:53:01.771801 2026] [security2:error] [pid 341679:tid 341922] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PjQWat-noHLkDuAhknQABe0E"]
[Tue Jul 21 07:53:01.845315 2026] [security2:error] [pid 341679:tid 341746] [remote 178.20.101.93:42328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.101.20.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goldentrips40.com"] [uri "/wp-login.php"] [unique_id "al9PjQWat-noHLkDuAhkjgABHkI"]
[Tue Jul 21 07:53:01.951651 2026] [security2:error] [pid 341679:tid 341878] [client 136.144.33.97:40953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PjQWat-noHLkDuAhktwAAAU8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:53:02.066251 2026] [security2:error] [pid 341679:tid 341841] [client 20.197.192.193:61182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/mimpi.php"] [unique_id "al9PjgWat-noHLkDuAhkvQAAASo"]
[Tue Jul 21 07:53:02.078797 2026] [security2:error] [pid 341679:tid 341873] [client 20.104.96.117:54979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/zildan.php"] [unique_id "al9PjgWat-noHLkDuAhkvwAAAUo"]
[Tue Jul 21 07:53:02.235704 2026] [security2:error] [pid 341679:tid 341813] [client 20.197.192.193:50940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/dp.php"] [unique_id "al9PjgWat-noHLkDuAhkxwAAAQ4"]
[Tue Jul 21 07:53:02.279655 2026] [security2:error] [pid 341679:tid 341680] [remote 18.61.192.253:57434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9PjgWat-noHLkDuAhkyQABbgA"]
[Tue Jul 21 07:53:02.340676 2026] [security2:error] [pid 341679:tid 341934] [client 37.140.223.156:52527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PjgWat-noHLkDuAhkxAAAAYc"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:53:02.369479 2026] [security2:error] [pid 341679:tid 341782] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PjgWat-noHLkDuAhkywABR2Y"]
[Tue Jul 21 07:53:02.369616 2026] [security2:error] [pid 341679:tid 341870] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PjgWat-noHLkDuAhkywABR2Y"]
[Tue Jul 21 07:53:02.500983 2026] [security2:error] [pid 341679:tid 341866] [client 20.197.192.193:50934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/bootstrap.php"] [unique_id "al9PjgWat-noHLkDuAhk0wAAAUM"]
[Tue Jul 21 07:53:02.567542 2026] [security2:error] [pid 341679:tid 341936] [client 122.162.144.145:6876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PjgWat-noHLkDuAhk1AAAAYk"]
[Tue Jul 21 07:53:02.567712 2026] [security2:error] [pid 341679:tid 341936] [client 122.162.144.145:6876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PjgWat-noHLkDuAhk1AAAAYk"]
[Tue Jul 21 07:53:02.572196 2026] [security2:error] [pid 341679:tid 341890] [client 92.119.178.3:35494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9PjgWat-noHLkDuAhk1QAAAVs"]
[Tue Jul 21 07:53:02.572315 2026] [security2:error] [pid 341679:tid 341890] [client 92.119.178.3:35494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9PjgWat-noHLkDuAhk1QAAAVs"]
[Tue Jul 21 07:53:02.597366 2026] [security2:error] [pid 341679:tid 341907] [client 103.86.117.203:54245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PjgWat-noHLkDuAhk1wAAAWw"]
[Tue Jul 21 07:53:02.597497 2026] [security2:error] [pid 341679:tid 341907] [client 103.86.117.203:54245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PjgWat-noHLkDuAhk1wAAAWw"]
[Tue Jul 21 07:53:02.753519 2026] [security2:error] [pid 341679:tid 341827] [client 20.197.192.193:62072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wp-editor.php"] [unique_id "al9PjgWat-noHLkDuAhk2QAAARw"]
[Tue Jul 21 07:53:02.852959 2026] [security2:error] [pid 341679:tid 341900] [client 20.104.96.117:12655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/100.php"] [unique_id "al9PjgWat-noHLkDuAhk3QAAAWU"]
[Tue Jul 21 07:53:03.064955 2026] [security2:error] [pid 341679:tid 341883] [client 20.197.192.193:29770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/cro.php"] [unique_id "al9PjwWat-noHLkDuAhk5QAAAVQ"]
[Tue Jul 21 07:53:03.170199 2026] [security2:error] [pid 341679:tid 341789] [remote 207.180.241.245:56666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limaradiologiadigital.com.br"] [uri "/wp-login.php"] [unique_id "al9PjwWat-noHLkDuAhk5wABP20"]
[Tue Jul 21 07:53:03.300014 2026] [security2:error] [pid 341679:tid 341933] [client 20.197.192.193:50914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/cron-tab.php"] [unique_id "al9PjwWat-noHLkDuAhk7gAAAYY"]
[Tue Jul 21 07:53:03.352326 2026] [security2:error] [pid 341679:tid 341778] [remote 45.117.83.212:42212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9PjwWat-noHLkDuAhk8gABCmI"]
[Tue Jul 21 07:53:03.379086 2026] [security2:error] [pid 341679:tid 341811] [client 20.104.96.117:12626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/about.php"] [unique_id "al9PjwWat-noHLkDuAhk8wAAAQw"]
[Tue Jul 21 07:53:03.432045 2026] [security2:error] [pid 341679:tid 341885] [client 223.236.153.128:5454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PjwWat-noHLkDuAhk9gAAAVY"]
[Tue Jul 21 07:53:03.436501 2026] [security2:error] [pid 341679:tid 341885] [client 223.236.153.128:5454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PjwWat-noHLkDuAhk9gAAAVY"]
[Tue Jul 21 07:53:03.456862 2026] [security2:error] [pid 341679:tid 341892] [client 20.197.192.193:50896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/koiy.php"] [unique_id "al9PjwWat-noHLkDuAhk9wAAAV0"]
[Tue Jul 21 07:53:03.507190 2026] [security2:error] [pid 341679:tid 341902] [client 103.166.103.129:40477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PjwWat-noHLkDuAhlAAAAAWc"]
[Tue Jul 21 07:53:03.507349 2026] [security2:error] [pid 341679:tid 341902] [client 103.166.103.129:40477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PjwWat-noHLkDuAhlAAAAAWc"]
[Tue Jul 21 07:53:03.610583 2026] [security2:error] [pid 341679:tid 341841] [client 20.197.192.193:62028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/hp2.php"] [unique_id "al9PjwWat-noHLkDuAhlAwAAASo"]
[Tue Jul 21 07:53:03.977397 2026] [security2:error] [pid 341679:tid 341863] [client 20.197.192.193:50912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/hp3.php"] [unique_id "al9PjwWat-noHLkDuAhlEgAAAUA"]
[Tue Jul 21 07:53:03.995041 2026] [autoindex:error] [pid 341679:tid 341859] [client 43.157.38.131:41414] AH01276: Cannot serve directory /home1/asse7722/comecx.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:53:04.176048 2026] [security2:error] [pid 341679:tid 341894] [client 74.249.245.134:64206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/0x.php"] [unique_id "al9PkAWat-noHLkDuAhlGwAAAV8"]
[Tue Jul 21 07:53:04.223178 2026] [security2:error] [pid 341679:tid 341906] [client 20.104.96.117:12625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/about.php"] [unique_id "al9PkAWat-noHLkDuAhlHQAAAWs"]
[Tue Jul 21 07:53:04.268415 2026] [security2:error] [pid 341679:tid 341914] [client 20.104.96.117:54977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/csa.php"] [unique_id "al9PkAWat-noHLkDuAhlHgAAAXM"]
[Tue Jul 21 07:53:04.394515 2026] [security2:error] [pid 341679:tid 341843] [client 178.153.91.96:45991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PkAWat-noHLkDuAhlIwAAASw"]
[Tue Jul 21 07:53:04.394628 2026] [security2:error] [pid 341679:tid 341843] [client 178.153.91.96:45991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PkAWat-noHLkDuAhlIwAAASw"]
[Tue Jul 21 07:53:04.537544 2026] [security2:error] [pid 341679:tid 341921] [client 37.140.223.156:37053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PkAWat-noHLkDuAhlLwAAAXo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:53:04.650446 2026] [security2:error] [pid 341679:tid 341923] [client 20.197.192.193:29772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/aa1.php"] [unique_id "al9PkAWat-noHLkDuAhlNgAAAXw"]
[Tue Jul 21 07:53:04.710174 2026] [security2:error] [pid 341679:tid 341734] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PkAWat-noHLkDuAhlPAABbTY"]
[Tue Jul 21 07:53:04.710343 2026] [security2:error] [pid 341679:tid 341908] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PkAWat-noHLkDuAhlPAABbTY"]
[Tue Jul 21 07:53:04.726533 2026] [proxy:error] [pid 341679:tid 341735] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:53:04.726593 2026] [proxy_http:error] [pid 341679:tid 341735] [remote 74.7.241.138:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:53:04.727885 2026] [proxy:error] [pid 341679:tid 341735] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:53:04.727933 2026] [proxy_http:error] [pid 341679:tid 341735] [remote 74.7.241.138:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:53:04.728097 2026] [security2:error] [pid 341679:tid 341874] [client 74.7.241.138:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.githec.com"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "al9PkAWat-noHLkDuAhlPgABSzc"]
[Tue Jul 21 07:53:04.743311 2026] [security2:error] [pid 341679:tid 341884] [client 20.104.96.117:12901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/admin.php"] [unique_id "al9PkAWat-noHLkDuAhlQAAAAVU"]
[Tue Jul 21 07:53:04.755288 2026] [security2:error] [pid 341679:tid 341844] [client 20.226.60.151:56707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/csa.php"] [unique_id "al9PkAWat-noHLkDuAhlQgAAAS0"]
[Tue Jul 21 07:53:04.873403 2026] [security2:error] [pid 341679:tid 341881] [client 202.143.127.214:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkAWat-noHLkDuAhlRQAAAVI"]
[Tue Jul 21 07:53:04.873532 2026] [security2:error] [pid 341679:tid 341881] [client 202.143.127.214:60452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkAWat-noHLkDuAhlRQAAAVI"]
[Tue Jul 21 07:53:05.006007 2026] [security2:error] [pid 341679:tid 341910] [client 139.167.225.182:56345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkQWat-noHLkDuAhlTQAAAW8"]
[Tue Jul 21 07:53:05.006142 2026] [security2:error] [pid 341679:tid 341910] [client 139.167.225.182:56345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkQWat-noHLkDuAhlTQAAAW8"]
[Tue Jul 21 07:53:05.010345 2026] [security2:error] [pid 341679:tid 341911] [client 117.247.80.59:20387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkQWat-noHLkDuAhlTwAAAXA"]
[Tue Jul 21 07:53:05.010449 2026] [security2:error] [pid 341679:tid 341911] [client 117.247.80.59:20387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkQWat-noHLkDuAhlTwAAAXA"]
[Tue Jul 21 07:53:05.119539 2026] [security2:error] [pid 341679:tid 341852] [client 20.104.96.117:12662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/admin.php"] [unique_id "al9PkQWat-noHLkDuAhlUgAAATU"]
[Tue Jul 21 07:53:05.178507 2026] [security2:error] [pid 341679:tid 341731] [remote 5.252.52.249:52306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9PkQWat-noHLkDuAhlVQABLzM"]
[Tue Jul 21 07:53:05.264862 2026] [security2:error] [pid 341679:tid 341840] [client 173.24.185.52:52647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PkQWat-noHLkDuAhlWAAAASk"]
[Tue Jul 21 07:53:05.264980 2026] [security2:error] [pid 341679:tid 341840] [client 173.24.185.52:52647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PkQWat-noHLkDuAhlWAAAASk"]
[Tue Jul 21 07:53:05.266870 2026] [security2:error] [pid 341679:tid 341863] [client 20.197.192.193:62026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/acew67.php"] [unique_id "al9PkQWat-noHLkDuAhlWQAAAUA"]
[Tue Jul 21 07:53:05.416148 2026] [security2:error] [pid 341679:tid 341927] [client 103.78.200.11:60572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkQWat-noHLkDuAhlXQAAAYA"]
[Tue Jul 21 07:53:05.416262 2026] [security2:error] [pid 341679:tid 341927] [client 103.78.200.11:60572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkQWat-noHLkDuAhlXQAAAYA"]
[Tue Jul 21 07:53:05.450610 2026] [security2:error] [pid 341679:tid 341904] [client 47.128.43.195:49898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carrosselbuique.com.br"] [uri "/robots.txt"] [unique_id "al9PkQWat-noHLkDuAhlXgAAAWk"]
[Tue Jul 21 07:53:05.587596 2026] [security2:error] [pid 341679:tid 341869] [client 20.104.96.117:12617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/themes.php"] [unique_id "al9PkQWat-noHLkDuAhlYwAAAUY"]
[Tue Jul 21 07:53:05.588332 2026] [security2:error] [pid 341679:tid 341830] [client 117.217.38.194:63678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkQWat-noHLkDuAhlZAAAAR8"]
[Tue Jul 21 07:53:05.588442 2026] [security2:error] [pid 341679:tid 341830] [client 117.217.38.194:63678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkQWat-noHLkDuAhlZAAAAR8"]
[Tue Jul 21 07:53:05.916785 2026] [security2:error] [pid 341679:tid 341877] [client 20.197.192.193:50916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/bscclapb.php"] [unique_id "al9PkQWat-noHLkDuAhlcAAAAU4"]
[Tue Jul 21 07:53:05.942685 2026] [security2:error] [pid 341679:tid 341823] [client 173.239.211.122:24413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9PkQWat-noHLkDuAhlcgAAARg"]
[Tue Jul 21 07:53:05.947642 2026] [security2:error] [pid 341679:tid 341853] [client 216.73.161.161:50069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9PkQWat-noHLkDuAhlcwAAATY"]
[Tue Jul 21 07:53:05.949185 2026] [security2:error] [pid 341679:tid 341810] [client 216.73.161.172:44863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9PkQWat-noHLkDuAhlcQAAAQs"]
[Tue Jul 21 07:53:05.997519 2026] [autoindex:error] [pid 341679:tid 341915] [client 3.219.86.171:13205] AH01276: Cannot serve directory /home2/reser379/megaroteiros.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:53:06.005661 2026] [security2:error] [pid 341679:tid 341751] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkgWat-noHLkDuAhleQABY0c"]
[Tue Jul 21 07:53:06.005825 2026] [security2:error] [pid 341679:tid 341898] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkgWat-noHLkDuAhleQABY0c"]
[Tue Jul 21 07:53:06.017020 2026] [security2:error] [pid 341679:tid 341753] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkgWat-noHLkDuAhlegABiEk"]
[Tue Jul 21 07:53:06.017212 2026] [security2:error] [pid 341679:tid 341935] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkgWat-noHLkDuAhlegABiEk"]
[Tue Jul 21 07:53:06.098210 2026] [security2:error] [pid 341679:tid 341906] [client 122.186.204.214:56029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PkgWat-noHLkDuAhlgwAAAWs"]
[Tue Jul 21 07:53:06.098337 2026] [security2:error] [pid 341679:tid 341906] [client 122.186.204.214:56029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PkgWat-noHLkDuAhlgwAAAWs"]
[Tue Jul 21 07:53:06.152725 2026] [security2:error] [pid 341679:tid 341809] [client 109.60.28.94:65434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkgWat-noHLkDuAhlhgAAAQo"]
[Tue Jul 21 07:53:06.153453 2026] [security2:error] [pid 341679:tid 341809] [client 109.60.28.94:65434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkgWat-noHLkDuAhlhgAAAQo"]
[Tue Jul 21 07:53:06.210421 2026] [core:alert] [pid 341679:tid 341825] [client 57.141.18.7:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:53:06.275779 2026] [autoindex:error] [pid 341679:tid 341864] [client 3.219.86.171:38111] AH01276: Cannot serve directory /home2/reser379/megaroteiros.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:53:06.355473 2026] [security2:error] [pid 341679:tid 341927] [client 20.104.96.117:12640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/.well-known/about.php"] [unique_id "al9PkgWat-noHLkDuAhllgAAAYA"]
[Tue Jul 21 07:53:06.420224 2026] [security2:error] [pid 341679:tid 341843] [client 20.226.60.151:61510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/kq1.php"] [unique_id "al9PkgWat-noHLkDuAhlmgAAASw"]
[Tue Jul 21 07:53:06.588765 2026] [security2:error] [pid 341679:tid 341924] [client 20.197.192.193:29774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/else1.php"] [unique_id "al9PkgWat-noHLkDuAhlnwAAAX0"]
[Tue Jul 21 07:53:06.623796 2026] [security2:error] [pid 341679:tid 341685] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkgWat-noHLkDuAhlpAABdwU"]
[Tue Jul 21 07:53:06.623915 2026] [security2:error] [pid 341679:tid 341918] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkgWat-noHLkDuAhlpAABdwU"]
[Tue Jul 21 07:53:06.640212 2026] [security2:error] [pid 341679:tid 341820] [client 20.197.192.193:29816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/tkikikoko.php"] [unique_id "al9PkgWat-noHLkDuAhlpwAAARU"]
[Tue Jul 21 07:53:06.678574 2026] [security2:error] [pid 341679:tid 341823] [client 20.104.96.117:12870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9PkgWat-noHLkDuAhlqgAAARg"]
[Tue Jul 21 07:53:06.717167 2026] [security2:error] [pid 341679:tid 341810] [client 20.197.192.193:50931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9PkgWat-noHLkDuAhlrAAAAQs"]
[Tue Jul 21 07:53:06.744737 2026] [security2:error] [pid 341679:tid 341909] [client 103.29.114.44:58511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkgWat-noHLkDuAhlrgAAAW4"]
[Tue Jul 21 07:53:06.744878 2026] [security2:error] [pid 341679:tid 341909] [client 103.29.114.44:58511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PkgWat-noHLkDuAhlrgAAAW4"]
[Tue Jul 21 07:53:06.793872 2026] [security2:error] [pid 341679:tid 341923] [client 20.197.192.193:29810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wp-css.php"] [unique_id "al9PkgWat-noHLkDuAhlrwAAAXw"]
[Tue Jul 21 07:53:06.874107 2026] [security2:error] [pid 341679:tid 341935] [client 20.197.192.193:29817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wp-explorer.php"] [unique_id "al9PkgWat-noHLkDuAhlswAAAYg"]
[Tue Jul 21 07:53:06.911587 2026] [security2:error] [pid 341679:tid 341902] [client 20.226.60.151:56733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/w3llscc.php"] [unique_id "al9PkgWat-noHLkDuAhltwAAAWc"]
[Tue Jul 21 07:53:06.971300 2026] [security2:error] [pid 341679:tid 341817] [client 20.104.96.117:12613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/wefile.php"] [unique_id "al9PkgWat-noHLkDuAhluAAAARI"]
[Tue Jul 21 07:53:07.038063 2026] [security2:error] [pid 341679:tid 341895] [client 193.36.225.65:20325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PkgWat-noHLkDuAhlsgAAAWA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:53:07.049246 2026] [security2:error] [pid 341679:tid 341934] [client 216.73.160.190:55433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/wp-login.php"] [unique_id "al9PkwWat-noHLkDuAhluQAAAYc"]
[Tue Jul 21 07:53:07.070366 2026] [security2:error] [pid 341679:tid 341828] [client 20.197.192.193:61130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/akismet.php"] [unique_id "al9PkwWat-noHLkDuAhlugAAAR0"]
[Tue Jul 21 07:53:07.135092 2026] [security2:error] [pid 341679:tid 341852] [client 20.197.192.193:29808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/ace2.php"] [unique_id "al9PkwWat-noHLkDuAhlvwAAATU"]
[Tue Jul 21 07:53:07.212300 2026] [security2:error] [pid 341679:tid 341838] [client 20.197.192.193:29767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/ms.php"] [unique_id "al9PkwWat-noHLkDuAhlwwAAASc"]
[Tue Jul 21 07:53:07.278164 2026] [security2:error] [pid 341679:tid 341863] [client 74.7.175.152:48988] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "ewfmontagens.com.br"] [uri "/robots.txt"] [unique_id "al9PkwWat-noHLkDuAhlxgAAAUA"]
[Tue Jul 21 07:53:07.311110 2026] [security2:error] [pid 341679:tid 341890] [client 20.104.96.117:12881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9PkwWat-noHLkDuAhlyAAAAVs"]
[Tue Jul 21 07:53:07.494676 2026] [security2:error] [pid 341679:tid 341821] [client 74.7.175.152:56376] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ewfmontagens.com.br"] [uri "/robots.txt"] [unique_id "al9PkwWat-noHLkDuAhl0gABFmQ"], referer: http://ewfmontagens.com.br/robots.txt
[Tue Jul 21 07:53:07.495223 2026] [security2:error] [pid 341679:tid 341821] [client 74.7.175.152:56376] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ewfmontagens.com.br"] [uri "/robots.txt"] [unique_id "al9PkwWat-noHLkDuAhl0QABFgA"]
[Tue Jul 21 07:53:07.570140 2026] [security2:error] [pid 341679:tid 341876] [client 122.179.91.63:12391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PkwWat-noHLkDuAhl2AAAAU0"]
[Tue Jul 21 07:53:07.570282 2026] [security2:error] [pid 341679:tid 341876] [client 122.179.91.63:12391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PkwWat-noHLkDuAhl2AAAAU0"]
[Tue Jul 21 07:53:07.935771 2026] [security2:error] [pid 341679:tid 341877] [client 20.104.96.117:12918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9PkwWat-noHLkDuAhl5gAAAU4"]
[Tue Jul 21 07:53:08.242206 2026] [security2:error] [pid 341679:tid 341867] [client 20.104.96.117:12619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/8.php"] [unique_id "al9PlAWat-noHLkDuAhl9wAAAUQ"]
[Tue Jul 21 07:53:08.293042 2026] [security2:error] [pid 341679:tid 341878] [client 106.215.181.8:5957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PlAWat-noHLkDuAhl-AAAAU8"]
[Tue Jul 21 07:53:08.293172 2026] [security2:error] [pid 341679:tid 341878] [client 106.215.181.8:5957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PlAWat-noHLkDuAhl-AAAAU8"]
[Tue Jul 21 07:53:08.593763 2026] [security2:error] [pid 341679:tid 341882] [client 20.104.96.117:12514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9PlAWat-noHLkDuAhl-wAAAVM"]
[Tue Jul 21 07:53:08.880595 2026] [security2:error] [pid 341679:tid 341683] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PlAWat-noHLkDuAhmBgABTAM"]
[Tue Jul 21 07:53:08.880727 2026] [security2:error] [pid 341679:tid 341875] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PlAWat-noHLkDuAhmBgABTAM"]
[Tue Jul 21 07:53:08.903740 2026] [security2:error] [pid 341679:tid 341851] [client 20.104.96.117:12889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/f6.php"] [unique_id "al9PlAWat-noHLkDuAhmBwAAATQ"]
[Tue Jul 21 07:53:09.228528 2026] [security2:error] [pid 341679:tid 341893] [client 20.104.96.117:12886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/inputs.php"] [unique_id "al9PlQWat-noHLkDuAhmFwAAAV4"]
[Tue Jul 21 07:53:09.459811 2026] [security2:error] [pid 341679:tid 341710] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PlQWat-noHLkDuAhmIwABgB4"]
[Tue Jul 21 07:53:09.459960 2026] [security2:error] [pid 341679:tid 341927] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PlQWat-noHLkDuAhmIwABgB4"]
[Tue Jul 21 07:53:09.555149 2026] [security2:error] [pid 341679:tid 341884] [client 20.226.60.151:61576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9PlQWat-noHLkDuAhmJQAAAVU"]
[Tue Jul 21 07:53:09.720729 2026] [security2:error] [pid 341679:tid 341847] [client 198.54.128.138:49384] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9PlQWat-noHLkDuAhmKQAAATA"]
[Tue Jul 21 07:53:09.720862 2026] [security2:error] [pid 341679:tid 341847] [client 198.54.128.138:49384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9PlQWat-noHLkDuAhmKQAAATA"]
[Tue Jul 21 07:53:09.850672 2026] [security2:error] [pid 341679:tid 341846] [client 20.104.96.117:12871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/inputs.php"] [unique_id "al9PlQWat-noHLkDuAhmNAAAAS8"]
[Tue Jul 21 07:53:09.936005 2026] [security2:error] [pid 341679:tid 341834] [client 20.226.60.151:56768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wpx.php"] [unique_id "al9PlQWat-noHLkDuAhmNgAAASM"]
[Tue Jul 21 07:53:10.359437 2026] [security2:error] [pid 341679:tid 341888] [client 20.104.96.117:12632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9PlgWat-noHLkDuAhmPAAAAVk"]
[Tue Jul 21 07:53:10.466415 2026] [security2:error] [pid 341679:tid 341910] [client 182.8.255.181:21071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PlgWat-noHLkDuAhmRQAAAW8"]
[Tue Jul 21 07:53:10.466552 2026] [security2:error] [pid 341679:tid 341910] [client 182.8.255.181:21071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PlgWat-noHLkDuAhmRQAAAW8"]
[Tue Jul 21 07:53:10.679663 2026] [security2:error] [pid 341679:tid 341916] [client 102.206.115.33:60159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9PlgWat-noHLkDuAhmSAAAAXU"]
[Tue Jul 21 07:53:10.679976 2026] [security2:error] [pid 341679:tid 341916] [client 102.206.115.33:60159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9PlgWat-noHLkDuAhmSAAAAXU"]
[Tue Jul 21 07:53:10.742873 2026] [security2:error] [pid 341679:tid 341860] [client 136.144.33.97:38965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PlgWat-noHLkDuAhmSgAAAT0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:53:10.782466 2026] [security2:error] [pid 341679:tid 341831] [client 122.164.127.47:57328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PlgWat-noHLkDuAhmSwAAASA"]
[Tue Jul 21 07:53:10.785861 2026] [security2:error] [pid 341679:tid 341891] [client 20.104.96.117:12663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9PlgWat-noHLkDuAhmTQAAAVw"]
[Tue Jul 21 07:53:10.789313 2026] [security2:error] [pid 341679:tid 341831] [client 122.164.127.47:57328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PlgWat-noHLkDuAhmSwAAASA"]
[Tue Jul 21 07:53:10.842510 2026] [security2:error] [pid 341679:tid 341716] [remote 95.108.213.170:56882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.213.108.95.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "professoraclaudiaaguiar.com.br"] [uri "/"] [unique_id "al9PlgWat-noHLkDuAhmRwABQyQ"]
[Tue Jul 21 07:53:10.885622 2026] [security2:error] [pid 341679:tid 341839] [client 65.111.12.162:9995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.12.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PlAWat-noHLkDuAhmAAAAASg"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:53:11.083744 2026] [security2:error] [pid 341679:tid 341881] [client 20.104.96.117:12630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/wp-blog.php"] [unique_id "al9PlwWat-noHLkDuAhmWgAAAVI"]
[Tue Jul 21 07:53:11.094974 2026] [security2:error] [pid 341679:tid 341841] [client 184.75.221.3:43096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PlwWat-noHLkDuAhmWwAAASo"]
[Tue Jul 21 07:53:11.095073 2026] [security2:error] [pid 341679:tid 341841] [client 184.75.221.3:43096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PlwWat-noHLkDuAhmWwAAASo"]
[Tue Jul 21 07:53:11.143697 2026] [security2:error] [pid 341679:tid 341849] [client 204.8.98.45:45558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9PlwWat-noHLkDuAhmXAAAATI"]
[Tue Jul 21 07:53:11.143809 2026] [security2:error] [pid 341679:tid 341849] [client 204.8.98.45:45558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9PlwWat-noHLkDuAhmXAAAATI"]
[Tue Jul 21 07:53:11.247666 2026] [security2:error] [pid 341679:tid 341724] [remote 57.141.18.27:63282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "camilajung.com.br"] [uri "/wp-content/plugins/litespeed-cache/guest.vary.php"] [unique_id "al9PlwWat-noHLkDuAhmXgABESw"], referer: https://camilajung.com.br/ferramenta/
[Tue Jul 21 07:53:11.312725 2026] [security2:error] [pid 341679:tid 341852] [client 20.226.60.151:61619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/h02ugyh.php"] [unique_id "al9PlwWat-noHLkDuAhmZAAAATU"]
[Tue Jul 21 07:53:11.598451 2026] [security2:error] [pid 341679:tid 341863] [client 20.104.96.117:12645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9PlwWat-noHLkDuAhmbgAAAUA"]
[Tue Jul 21 07:53:11.954234 2026] [security2:error] [pid 341679:tid 341924] [client 20.104.96.117:12876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/ms-edit.php"] [unique_id "al9PlwWat-noHLkDuAhmeQAAAX0"]
[Tue Jul 21 07:53:12.011702 2026] [security2:error] [pid 341679:tid 341851] [client 89.124.113.107:50279] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.113.107" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "tryhealth.shop"] [uri "/wp-comments-post.php"] [unique_id "al9PmAWat-noHLkDuAhmfQAAATQ"], referer: https://tryhealth.shop/how-to-effectively-respond-to-customer-complaints/
[Tue Jul 21 07:53:12.011788 2026] [security2:error] [pid 341679:tid 341851] [client 89.124.113.107:50279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "tryhealth.shop"] [uri "/wp-comments-post.php"] [unique_id "al9PmAWat-noHLkDuAhmfQAAATQ"], referer: https://tryhealth.shop/how-to-effectively-respond-to-customer-complaints/
[Tue Jul 21 07:53:12.257309 2026] [security2:error] [pid 341679:tid 341719] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PmAWat-noHLkDuAhmhAABUSc"]
[Tue Jul 21 07:53:12.257473 2026] [security2:error] [pid 341679:tid 341880] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PmAWat-noHLkDuAhmhAABUSc"]
[Tue Jul 21 07:53:12.277664 2026] [security2:error] [pid 341679:tid 341865] [client 20.104.96.117:12641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9PmAWat-noHLkDuAhmhQAAAUI"]
[Tue Jul 21 07:53:12.345749 2026] [security2:error] [pid 341679:tid 341743] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PmAWat-noHLkDuAhmiQABVD8"]
[Tue Jul 21 07:53:12.345886 2026] [security2:error] [pid 341679:tid 341883] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PmAWat-noHLkDuAhmiQABVD8"]
[Tue Jul 21 07:53:12.808640 2026] [security2:error] [pid 341679:tid 341898] [client 20.104.96.117:12894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9PmAWat-noHLkDuAhmlwAAAWM"]
[Tue Jul 21 07:53:12.945894 2026] [security2:error] [pid 341679:tid 341763] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PmAWat-noHLkDuAhmoAABU1M"]
[Tue Jul 21 07:53:12.946078 2026] [security2:error] [pid 341679:tid 341882] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PmAWat-noHLkDuAhmoAABU1M"]
[Tue Jul 21 07:53:12.982753 2026] [security2:error] [pid 341679:tid 341854] [client 20.104.96.117:54974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/w3llscc.php"] [unique_id "al9PmAWat-noHLkDuAhmoQAAATc"]
[Tue Jul 21 07:53:13.082438 2026] [security2:error] [pid 341679:tid 341840] [client 103.86.117.203:54793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PmQWat-noHLkDuAhmpwAAASk"]
[Tue Jul 21 07:53:13.082533 2026] [security2:error] [pid 341679:tid 341840] [client 103.86.117.203:54793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PmQWat-noHLkDuAhmpwAAASk"]
[Tue Jul 21 07:53:13.235729 2026] [security2:error] [pid 341679:tid 341904] [client 41.68.90.219:52344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PmQWat-noHLkDuAhmrQAAAWk"]
[Tue Jul 21 07:53:13.236837 2026] [security2:error] [pid 341679:tid 341904] [client 41.68.90.219:52344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PmQWat-noHLkDuAhmrQAAAWk"]
[Tue Jul 21 07:53:13.270455 2026] [security2:error] [pid 341679:tid 341871] [client 122.162.144.145:22675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PmQWat-noHLkDuAhmrgAAAUg"]
[Tue Jul 21 07:53:13.272614 2026] [security2:error] [pid 341679:tid 341871] [client 122.162.144.145:22675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PmQWat-noHLkDuAhmrgAAAUg"]
[Tue Jul 21 07:53:13.590122 2026] [security2:error] [pid 341679:tid 341892] [client 20.104.96.117:12670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/abcd.php"] [unique_id "al9PmQWat-noHLkDuAhmvAAAAV0"]
[Tue Jul 21 07:53:14.140315 2026] [security2:error] [pid 341679:tid 341905] [client 223.236.153.128:7098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PmgWat-noHLkDuAhmzQAAAWo"]
[Tue Jul 21 07:53:14.140404 2026] [security2:error] [pid 341679:tid 341905] [client 223.236.153.128:7098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PmgWat-noHLkDuAhmzQAAAWo"]
[Tue Jul 21 07:53:14.281903 2026] [security2:error] [pid 341679:tid 341856] [client 103.166.103.129:41097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PmgWat-noHLkDuAhm0gAAATk"]
[Tue Jul 21 07:53:14.282057 2026] [security2:error] [pid 341679:tid 341856] [client 103.166.103.129:41097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PmgWat-noHLkDuAhm0gAAATk"]
[Tue Jul 21 07:53:14.572345 2026] [security2:error] [pid 341679:tid 341854] [client 20.226.60.151:61600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wp-temp.php"] [unique_id "al9PmgWat-noHLkDuAhm2wAAATc"]
[Tue Jul 21 07:53:14.948800 2026] [security2:error] [pid 341679:tid 341842] [client 178.153.91.96:46999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PmgWat-noHLkDuAhm5QAAASs"]
[Tue Jul 21 07:53:14.948923 2026] [security2:error] [pid 341679:tid 341842] [client 178.153.91.96:46999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PmgWat-noHLkDuAhm5QAAASs"]
[Tue Jul 21 07:53:15.069401 2026] [security2:error] [pid 341679:tid 341869] [client 20.104.96.117:12900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/file15.php"] [unique_id "al9PmwWat-noHLkDuAhm6QAAAUY"]
[Tue Jul 21 07:53:15.231378 2026] [security2:error] [pid 341679:tid 341882] [client 139.167.225.182:57010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PmwWat-noHLkDuAhnEgAAAVM"]
[Tue Jul 21 07:53:15.231504 2026] [security2:error] [pid 341679:tid 341882] [client 139.167.225.182:57010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PmwWat-noHLkDuAhnEgAAAVM"]
[Tue Jul 21 07:53:15.340676 2026] [security2:error] [pid 341679:tid 341897] [client 136.144.33.111:27437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PmwWat-noHLkDuAhnFQAAAWI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:53:15.382332 2026] [security2:error] [pid 341679:tid 341873] [client 20.104.96.117:54930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wpx.php"] [unique_id "al9PmwWat-noHLkDuAhnGAAAAUo"]
[Tue Jul 21 07:53:15.521028 2026] [security2:error] [pid 341679:tid 341925] [client 20.226.60.151:56827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-css.php"] [unique_id "al9PmwWat-noHLkDuAhnIgAAAX4"]
[Tue Jul 21 07:53:15.585586 2026] [security2:error] [pid 341679:tid 341846] [client 20.104.96.117:12667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/jp.php"] [unique_id "al9PmwWat-noHLkDuAhnJAAAAS8"]
[Tue Jul 21 07:53:15.588398 2026] [security2:error] [pid 341679:tid 341830] [client 117.247.80.59:35534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PmwWat-noHLkDuAhnJQAAAR8"]
[Tue Jul 21 07:53:15.588485 2026] [security2:error] [pid 341679:tid 341830] [client 117.247.80.59:35534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PmwWat-noHLkDuAhnJQAAAR8"]
[Tue Jul 21 07:53:15.628172 2026] [security2:error] [pid 341679:tid 341712] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PmwWat-noHLkDuAhnKAABLSA"]
[Tue Jul 21 07:53:15.628319 2026] [security2:error] [pid 341679:tid 341844] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PmwWat-noHLkDuAhnKAABLSA"]
[Tue Jul 21 07:53:15.682405 2026] [security2:error] [pid 341679:tid 341878] [client 184.75.221.3:43098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9PmwWat-noHLkDuAhnKgAAAU8"]
[Tue Jul 21 07:53:15.682520 2026] [security2:error] [pid 341679:tid 341878] [client 184.75.221.3:43098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9PmwWat-noHLkDuAhnKgAAAU8"]
[Tue Jul 21 07:53:15.881580 2026] [security2:error] [pid 341679:tid 341926] [client 103.78.200.11:61028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PmwWat-noHLkDuAhnLgAAAX8"]
[Tue Jul 21 07:53:15.881732 2026] [security2:error] [pid 341679:tid 341926] [client 103.78.200.11:61028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PmwWat-noHLkDuAhnLgAAAX8"]
[Tue Jul 21 07:53:15.890989 2026] [security2:error] [pid 341679:tid 341916] [client 173.24.185.52:53125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PmwWat-noHLkDuAhnMAAAAXU"]
[Tue Jul 21 07:53:15.891086 2026] [security2:error] [pid 341679:tid 341916] [client 173.24.185.52:53125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PmwWat-noHLkDuAhnMAAAAXU"]
[Tue Jul 21 07:53:15.901291 2026] [security2:error] [pid 341679:tid 341849] [client 202.143.127.214:60931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PmwWat-noHLkDuAhnMQAAATI"]
[Tue Jul 21 07:53:15.901383 2026] [security2:error] [pid 341679:tid 341849] [client 202.143.127.214:60931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PmwWat-noHLkDuAhnMQAAATI"]
[Tue Jul 21 07:53:16.068069 2026] [security2:error] [pid 341679:tid 341908] [client 117.217.38.194:64176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PnAWat-noHLkDuAhnOQAAAW0"]
[Tue Jul 21 07:53:16.068156 2026] [security2:error] [pid 341679:tid 341908] [client 117.217.38.194:64176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PnAWat-noHLkDuAhnOQAAAW0"]
[Tue Jul 21 07:53:16.182895 2026] [security2:error] [pid 341679:tid 341891] [client 20.104.96.117:12633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/f35.php"] [unique_id "al9PnAWat-noHLkDuAhnQQAAAVw"]
[Tue Jul 21 07:53:16.306190 2026] [security2:error] [pid 341679:tid 341890] [client 37.140.223.134:52717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PnAWat-noHLkDuAhnQAAAAVs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:53:16.545527 2026] [security2:error] [pid 341679:tid 341728] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PnAWat-noHLkDuAhnTQABKjA"]
[Tue Jul 21 07:53:16.545699 2026] [security2:error] [pid 341679:tid 341841] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PnAWat-noHLkDuAhnTQABKjA"]
[Tue Jul 21 07:53:16.566889 2026] [security2:error] [pid 341679:tid 341741] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PnAWat-noHLkDuAhnTwABQz0"]
[Tue Jul 21 07:53:16.567030 2026] [security2:error] [pid 341679:tid 341866] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PnAWat-noHLkDuAhnTwABQz0"]
[Tue Jul 21 07:53:16.577612 2026] [security2:error] [pid 341679:tid 341719] [remote 150.95.80.135:34584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.80.95.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carlosmangajr.com"] [uri "/wp-login.php"] [unique_id "al9PnAWat-noHLkDuAhnUAABOCc"]
[Tue Jul 21 07:53:16.591757 2026] [security2:error] [pid 341679:tid 341905] [client 20.104.96.117:12494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/wp-load.php"] [unique_id "al9PnAWat-noHLkDuAhnUgAAAWo"]
[Tue Jul 21 07:53:16.745919 2026] [security2:error] [pid 341679:tid 341875] [client 20.197.192.193:46046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/ms-new.php"] [unique_id "al9PnAWat-noHLkDuAhnWQAAAUw"]
[Tue Jul 21 07:53:16.790833 2026] [security2:error] [pid 341679:tid 341865] [client 122.186.204.214:56567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PnAWat-noHLkDuAhnWgAAAUI"]
[Tue Jul 21 07:53:16.790959 2026] [security2:error] [pid 341679:tid 341865] [client 122.186.204.214:56567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PnAWat-noHLkDuAhnWgAAAUI"]
[Tue Jul 21 07:53:16.974707 2026] [security2:error] [pid 341679:tid 341895] [client 20.104.96.117:12892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/xyn.php"] [unique_id "al9PnAWat-noHLkDuAhnXQAAAWA"]
[Tue Jul 21 07:53:16.980548 2026] [security2:error] [pid 341679:tid 341815] [client 109.60.28.94:49468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PnAWat-noHLkDuAhnXgAAARA"]
[Tue Jul 21 07:53:16.980632 2026] [security2:error] [pid 341679:tid 341815] [client 109.60.28.94:49468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PnAWat-noHLkDuAhnXgAAARA"]
[Tue Jul 21 07:53:17.348397 2026] [security2:error] [pid 341679:tid 341756] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PnQWat-noHLkDuAhnbQABcUw"]
[Tue Jul 21 07:53:17.348580 2026] [security2:error] [pid 341679:tid 341912] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PnQWat-noHLkDuAhnbQABcUw"]
[Tue Jul 21 07:53:17.525515 2026] [security2:error] [pid 341679:tid 341837] [client 103.29.114.44:6522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PnQWat-noHLkDuAhncgAAASY"]
[Tue Jul 21 07:53:17.525629 2026] [security2:error] [pid 341679:tid 341837] [client 103.29.114.44:6522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PnQWat-noHLkDuAhncgAAASY"]
[Tue Jul 21 07:53:17.653997 2026] [security2:error] [pid 341679:tid 341909] [client 20.104.96.117:12865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/ccc.php"] [unique_id "al9PnQWat-noHLkDuAhneAAAAW4"]
[Tue Jul 21 07:53:17.882638 2026] [security2:error] [pid 341679:tid 341923] [client 168.144.32.27:62301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.32.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.brwmarcas.com.br"] [uri "/gestaolancamentos/wp-login.php"] [unique_id "al9PnQWat-noHLkDuAhnfwAAAXw"], referer: http://www.brwmarcas.com.br/gestaolancamentos/wp-admin/
[Tue Jul 21 07:53:18.018930 2026] [security2:error] [pid 341679:tid 341821] [client 20.104.96.117:12623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/w.php"] [unique_id "al9PngWat-noHLkDuAhngwAAARY"]
[Tue Jul 21 07:53:18.077139 2026] [security2:error] [pid 341679:tid 341902] [client 20.226.60.151:56732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/ho.php"] [unique_id "al9PngWat-noHLkDuAhnigAAAWc"]
[Tue Jul 21 07:53:18.213481 2026] [security2:error] [pid 341679:tid 341864] [client 74.249.245.134:64399] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "andrelageorthobolics.com.br"] [uri "/.info.php"] [unique_id "al9PngWat-noHLkDuAhnjgAAAUE"]
[Tue Jul 21 07:53:18.214428 2026] [security2:error] [pid 341679:tid 341883] [client 122.179.91.63:1591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PngWat-noHLkDuAhnjwAAAVQ"]
[Tue Jul 21 07:53:18.214725 2026] [security2:error] [pid 341679:tid 341883] [client 122.179.91.63:1591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PngWat-noHLkDuAhnjwAAAVQ"]
[Tue Jul 21 07:53:18.417722 2026] [security2:error] [pid 341679:tid 341921] [client 20.104.96.117:12907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9PngWat-noHLkDuAhnlQAAAXo"]
[Tue Jul 21 07:53:18.573897 2026] [security2:error] [pid 341679:tid 341858] [client 20.226.60.151:61516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9PngWat-noHLkDuAhnmQAAATs"]
[Tue Jul 21 07:53:18.704414 2026] [security2:error] [pid 341679:tid 341855] [client 106.215.181.8:19739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PngWat-noHLkDuAhnpAAAATg"]
[Tue Jul 21 07:53:18.704520 2026] [security2:error] [pid 341679:tid 341855] [client 106.215.181.8:19739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PngWat-noHLkDuAhnpAAAATg"]
[Tue Jul 21 07:53:18.732649 2026] [security2:error] [pid 341679:tid 341930] [client 193.36.225.123:65039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PngWat-noHLkDuAhnmAAAAYM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:53:18.821166 2026] [security2:error] [pid 341679:tid 341838] [client 20.104.96.117:12501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/FWAZ.php"] [unique_id "al9PngWat-noHLkDuAhnqgAAASc"]
[Tue Jul 21 07:53:19.054539 2026] [security2:error] [pid 341679:tid 341907] [client 92.119.178.3:48498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9PnwWat-noHLkDuAhnswAAAWw"]
[Tue Jul 21 07:53:19.054626 2026] [security2:error] [pid 341679:tid 341907] [client 92.119.178.3:48498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9PnwWat-noHLkDuAhnswAAAWw"]
[Tue Jul 21 07:53:19.379989 2026] [security2:error] [pid 341679:tid 341874] [client 20.226.60.151:56727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xy.php"] [unique_id "al9PnwWat-noHLkDuAhnvwAAAUs"]
[Tue Jul 21 07:53:19.401715 2026] [security2:error] [pid 341679:tid 341791] [remote 103.187.169.251:51870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9PnwWat-noHLkDuAhnwAABcm8"]
[Tue Jul 21 07:53:19.412274 2026] [security2:error] [pid 341679:tid 341875] [client 20.104.96.117:12611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/miru1.php"] [unique_id "al9PnwWat-noHLkDuAhnwQAAAUw"]
[Tue Jul 21 07:53:19.452788 2026] [security2:error] [pid 341679:tid 341788] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PnwWat-noHLkDuAhnxAABDmw"]
[Tue Jul 21 07:53:19.452986 2026] [security2:error] [pid 341679:tid 341813] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PnwWat-noHLkDuAhnxAABDmw"]
[Tue Jul 21 07:53:19.763103 2026] [security2:error] [pid 341679:tid 341881] [client 20.226.60.151:50637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/loader.php"] [unique_id "al9PnwWat-noHLkDuAhnzgAAAVI"]
[Tue Jul 21 07:53:20.121436 2026] [security2:error] [pid 341679:tid 341702] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PoAWat-noHLkDuAhn2wABaBY"]
[Tue Jul 21 07:53:20.121574 2026] [security2:error] [pid 341679:tid 341903] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PoAWat-noHLkDuAhn2wABaBY"]
[Tue Jul 21 07:53:20.275666 2026] [security2:error] [pid 341679:tid 341869] [client 20.104.96.117:12913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/aa.php"] [unique_id "al9PoAWat-noHLkDuAhn4AAAAUY"]
[Tue Jul 21 07:53:20.545028 2026] [security2:error] [pid 341679:tid 341877] [client 20.104.96.117:54942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-css.php"] [unique_id "al9PoAWat-noHLkDuAhn7wAAAU4"]
[Tue Jul 21 07:53:20.651398 2026] [security2:error] [pid 341679:tid 341874] [client 74.249.245.134:65099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/item.php"] [unique_id "al9PoAWat-noHLkDuAhn9AAAAUs"]
[Tue Jul 21 07:53:20.827768 2026] [security2:error] [pid 341679:tid 341912] [client 182.8.255.181:21071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PoAWat-noHLkDuAhn-QAAAXE"]
[Tue Jul 21 07:53:20.827912 2026] [security2:error] [pid 341679:tid 341912] [client 182.8.255.181:21071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PoAWat-noHLkDuAhn-QAAAXE"]
[Tue Jul 21 07:53:20.834416 2026] [security2:error] [pid 341679:tid 341866] [client 185.213.175.37:61844] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "astrosyasmin.com.br"] [uri "/wp-content/themes/flatsome/assets/js/%url%"] [unique_id "al9PoAWat-noHLkDuAhn-gAAAUM"]
[Tue Jul 21 07:53:20.953106 2026] [security2:error] [pid 341679:tid 341815] [client 20.104.96.117:12895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/122.php"] [unique_id "al9PoAWat-noHLkDuAhoAwAAARA"]
[Tue Jul 21 07:53:21.311050 2026] [security2:error] [pid 341679:tid 341890] [client 102.206.115.33:64881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9PoQWat-noHLkDuAhoGQAAAVs"]
[Tue Jul 21 07:53:21.311198 2026] [security2:error] [pid 341679:tid 341890] [client 102.206.115.33:64881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9PoQWat-noHLkDuAhoGQAAAVs"]
[Tue Jul 21 07:53:21.311598 2026] [security2:error] [pid 341679:tid 341825] [client 104.207.49.50:25601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.49.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PoQWat-noHLkDuAhoDwAAARo"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:53:21.346597 2026] [security2:error] [pid 341679:tid 341935] [client 122.164.127.47:57907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PoQWat-noHLkDuAhoGgAAAYg"]
[Tue Jul 21 07:53:21.346731 2026] [security2:error] [pid 341679:tid 341935] [client 122.164.127.47:57907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PoQWat-noHLkDuAhoGgAAAYg"]
[Tue Jul 21 07:53:21.462876 2026] [autoindex:error] [pid 341679:tid 341863] [client 186.202.163.107:44679] AH01276: Cannot serve directory /home2/cla35313/protetordegraxa.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:53:21.741681 2026] [security2:error] [pid 341679:tid 341902] [client 20.104.96.117:12919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/get.php"] [unique_id "al9PoQWat-noHLkDuAhoUgAAAWc"]
[Tue Jul 21 07:53:21.967307 2026] [security2:error] [pid 341679:tid 341856] [client 72.13.46.9:0] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.sublimeassis.com"] [uri "/index.php"] [unique_id "al9PoAWat-noHLkDuAhoAAAAATk"]
[Tue Jul 21 07:53:21.967821 2026] [security2:error] [pid 341679:tid 341823] [client 72.13.46.9:39942] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.sublimeassis.com"] [uri "/robots.txt"] [unique_id "al9PoAWat-noHLkDuAhn_gAAARg"]
[Tue Jul 21 07:53:22.070280 2026] [security2:error] [pid 341679:tid 341773] [remote 100.42.189.89:55620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinicius-schneider.com"] [uri "/wp-login.php"] [unique_id "al9PogWat-noHLkDuAhoYAABcl0"]
[Tue Jul 21 07:53:22.287759 2026] [security2:error] [pid 341679:tid 341812] [client 20.104.96.117:12868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/as.php"] [unique_id "al9PogWat-noHLkDuAhobQAAAQ0"]
[Tue Jul 21 07:53:22.599553 2026] [security2:error] [pid 341679:tid 341863] [client 20.226.60.151:61534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9PogWat-noHLkDuAhohQAAAUA"]
[Tue Jul 21 07:53:22.717558 2026] [security2:error] [pid 341679:tid 341892] [client 92.119.178.3:39918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9PogWat-noHLkDuAhoiAAAAV0"]
[Tue Jul 21 07:53:22.717675 2026] [security2:error] [pid 341679:tid 341892] [client 92.119.178.3:39918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9PogWat-noHLkDuAhoiAAAAV0"]
[Tue Jul 21 07:53:22.752522 2026] [security2:error] [pid 341679:tid 341840] [client 20.104.96.117:12488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/ccou.php"] [unique_id "al9PogWat-noHLkDuAhoiwAAASk"]
[Tue Jul 21 07:53:22.913889 2026] [security2:error] [pid 341679:tid 341820] [client 65.111.22.62:51423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PogWat-noHLkDuAhoiQAAARU"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:53:22.947080 2026] [security2:error] [pid 341679:tid 341703] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PogWat-noHLkDuAhokwABJBc"]
[Tue Jul 21 07:53:22.947218 2026] [security2:error] [pid 341679:tid 341835] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PogWat-noHLkDuAhokwABJBc"]
[Tue Jul 21 07:53:23.042715 2026] [security2:error] [pid 341679:tid 341875] [client 20.104.96.117:55009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/ho.php"] [unique_id "al9PowWat-noHLkDuAholwAAAUw"]
[Tue Jul 21 07:53:23.147844 2026] [security2:error] [pid 341679:tid 341856] [client 72.13.46.9:0] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.sublimeassis.com"] [uri "/index.php"] [unique_id "al9PowWat-noHLkDuAhonQAAATk"]
[Tue Jul 21 07:53:23.148454 2026] [security2:error] [pid 341679:tid 341912] [client 72.13.46.9:39942] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.sublimeassis.com"] [uri "/"] [unique_id "al9PowWat-noHLkDuAhomgAAAXE"]
[Tue Jul 21 07:53:23.382897 2026] [security2:error] [pid 341679:tid 341924] [client 20.104.96.117:12621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/w3lls.php"] [unique_id "al9PowWat-noHLkDuAhopgAAAX0"]
[Tue Jul 21 07:53:23.404008 2026] [security2:error] [pid 341679:tid 341807] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PowWat-noHLkDuAhoqQABJ38"]
[Tue Jul 21 07:53:23.404186 2026] [security2:error] [pid 341679:tid 341838] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PowWat-noHLkDuAhoqQABJ38"]
[Tue Jul 21 07:53:23.445167 2026] [security2:error] [pid 341679:tid 341812] [client 72.13.46.9:0] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sublimeassis.com"] [uri "/index.php"] [unique_id "al9PowWat-noHLkDuAhoqAAAAQ0"]
[Tue Jul 21 07:53:23.445562 2026] [security2:error] [pid 341679:tid 341870] [client 72.13.46.9:39942] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sublimeassis.com"] [uri "/robots.txt"] [unique_id "al9PowWat-noHLkDuAhopQAAAUc"]
[Tue Jul 21 07:53:23.505611 2026] [security2:error] [pid 341679:tid 341695] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PowWat-noHLkDuAhorQABOw8"]
[Tue Jul 21 07:53:23.505768 2026] [security2:error] [pid 341679:tid 341858] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PowWat-noHLkDuAhorQABOw8"]
[Tue Jul 21 07:53:23.559462 2026] [security2:error] [pid 341679:tid 341897] [client 103.86.117.203:55331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PowWat-noHLkDuAhorwAAAWI"]
[Tue Jul 21 07:53:23.559592 2026] [security2:error] [pid 341679:tid 341897] [client 103.86.117.203:55331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PowWat-noHLkDuAhorwAAAWI"]
[Tue Jul 21 07:53:23.676507 2026] [security2:error] [pid 341679:tid 341869] [client 204.8.98.45:45204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9PowWat-noHLkDuAhotAAAAUY"]
[Tue Jul 21 07:53:23.676610 2026] [security2:error] [pid 341679:tid 341869] [client 204.8.98.45:45204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9PowWat-noHLkDuAhotAAAAUY"]
[Tue Jul 21 07:53:23.942514 2026] [security2:error] [pid 341679:tid 341876] [client 20.226.60.151:56718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/spadex.php"] [unique_id "al9PowWat-noHLkDuAhovQAAAU0"]
[Tue Jul 21 07:53:24.004047 2026] [security2:error] [pid 341679:tid 341843] [client 41.68.90.219:52800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpAWat-noHLkDuAhovwAAASw"]
[Tue Jul 21 07:53:24.005385 2026] [security2:error] [pid 341679:tid 341843] [client 41.68.90.219:52800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpAWat-noHLkDuAhovwAAASw"]
[Tue Jul 21 07:53:24.033639 2026] [security2:error] [pid 341679:tid 341864] [client 122.162.144.145:6657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PpAWat-noHLkDuAhowAAAAUE"]
[Tue Jul 21 07:53:24.033789 2026] [security2:error] [pid 341679:tid 341864] [client 122.162.144.145:6657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PpAWat-noHLkDuAhowAAAAUE"]
[Tue Jul 21 07:53:24.200422 2026] [security2:error] [pid 341679:tid 341875] [client 20.104.96.117:12531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/test1.php"] [unique_id "al9PpAWat-noHLkDuAhoxQAAAUw"]
[Tue Jul 21 07:53:24.283034 2026] [security2:error] [pid 341679:tid 341895] [client 74.249.245.134:24814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/albin.php"] [unique_id "al9PpAWat-noHLkDuAhoyAAAAWA"]
[Tue Jul 21 07:53:24.482366 2026] [security2:error] [pid 341679:tid 341788] [remote 60.205.8.163:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.8.205.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9PogWat-noHLkDuAhoeAABfmw"]
[Tue Jul 21 07:53:24.603704 2026] [security2:error] [pid 341679:tid 341866] [client 74.249.245.134:8781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/alfa.php"] [unique_id "al9PpAWat-noHLkDuAho0AAAAUM"]
[Tue Jul 21 07:53:24.758756 2026] [security2:error] [pid 341679:tid 341812] [client 168.144.32.27:62334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.32.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.brwmarcas.com.br"] [uri "/gestaolancamentos/wp-login.php"] [unique_id "al9PpAWat-noHLkDuAho1QAAAQ0"], referer: www.google.com
[Tue Jul 21 07:53:24.794541 2026] [security2:error] [pid 341679:tid 341898] [client 72.13.46.9:0] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sublimeassis.com"] [uri "/index.php"] [unique_id "al9PpAWat-noHLkDuAhozwAAAWM"]
[Tue Jul 21 07:53:24.795274 2026] [security2:error] [pid 341679:tid 341872] [client 72.13.46.9:39942] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sublimeassis.com"] [uri "/"] [unique_id "al9PpAWat-noHLkDuAhozQAAAUk"]
[Tue Jul 21 07:53:24.854785 2026] [security2:error] [pid 341679:tid 341902] [client 223.236.153.128:4559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PpAWat-noHLkDuAho1wAAAWc"]
[Tue Jul 21 07:53:24.854946 2026] [security2:error] [pid 341679:tid 341902] [client 223.236.153.128:4559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PpAWat-noHLkDuAho1wAAAWc"]
[Tue Jul 21 07:53:24.952840 2026] [security2:error] [pid 341679:tid 341848] [client 65.111.0.213:25787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.0.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PowWat-noHLkDuAhovgAAATE"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:53:24.975459 2026] [security2:error] [pid 341679:tid 341833] [client 103.166.103.129:56740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PpAWat-noHLkDuAho2wAAASI"]
[Tue Jul 21 07:53:24.976562 2026] [security2:error] [pid 341679:tid 341833] [client 103.166.103.129:56740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PpAWat-noHLkDuAho2wAAASI"]
[Tue Jul 21 07:53:25.244794 2026] [security2:error] [pid 341679:tid 341903] [client 20.220.225.223:19972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/cro.php"] [unique_id "al9PpQWat-noHLkDuAho4QAAAWg"]
[Tue Jul 21 07:53:25.331441 2026] [security2:error] [pid 341679:tid 341936] [client 20.104.96.117:12661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/database.php"] [unique_id "al9PpQWat-noHLkDuAho4wAAAYk"]
[Tue Jul 21 07:53:25.457560 2026] [security2:error] [pid 341679:tid 341849] [client 178.153.91.96:64418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PpQWat-noHLkDuAho6QAAATI"]
[Tue Jul 21 07:53:25.457714 2026] [security2:error] [pid 341679:tid 341849] [client 178.153.91.96:64418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PpQWat-noHLkDuAho6QAAATI"]
[Tue Jul 21 07:53:25.668369 2026] [security2:error] [pid 341679:tid 341864] [client 20.226.60.151:61593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/jj.php"] [unique_id "al9PpQWat-noHLkDuAho6gAAAUE"]
[Tue Jul 21 07:53:25.763950 2026] [security2:error] [pid 341679:tid 341914] [client 139.167.225.182:57669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpQWat-noHLkDuAho7wAAAXM"]
[Tue Jul 21 07:53:25.764147 2026] [security2:error] [pid 341679:tid 341914] [client 139.167.225.182:57669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpQWat-noHLkDuAho7wAAAXM"]
[Tue Jul 21 07:53:25.879431 2026] [security2:error] [pid 341679:tid 341814] [client 20.226.60.151:56755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/2x.php"] [unique_id "al9PpQWat-noHLkDuAho8gAAAQ8"]
[Tue Jul 21 07:53:26.049092 2026] [security2:error] [pid 341679:tid 341836] [client 20.104.96.117:12924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/file.php"] [unique_id "al9PpgWat-noHLkDuAho-QAAASU"]
[Tue Jul 21 07:53:26.059379 2026] [security2:error] [pid 341679:tid 341884] [client 117.247.80.59:30404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpgWat-noHLkDuAho-gAAAVU"]
[Tue Jul 21 07:53:26.059502 2026] [security2:error] [pid 341679:tid 341884] [client 117.247.80.59:30404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpgWat-noHLkDuAho-gAAAVU"]
[Tue Jul 21 07:53:26.151418 2026] [ssl:error] [pid 341679:tid 341911] [client 72.13.46.9:56673] AH02032: Hostname br1102.hostgator.com.br (default host as no SNI was provided) and hostname sublimeassis.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue Jul 21 07:53:26.151545 2026] [security2:error] [pid 341679:tid 341911] [client 72.13.46.9:56673] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "421"] [hostname "sublimeassis.com"] [uri "/"] [unique_id "al9PpgWat-noHLkDuAho-wAAAXA"]
[Tue Jul 21 07:53:26.424634 2026] [security2:error] [pid 341679:tid 341925] [client 173.24.185.52:53595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PpgWat-noHLkDuAhpDAAAAX4"]
[Tue Jul 21 07:53:26.424746 2026] [security2:error] [pid 341679:tid 341925] [client 173.24.185.52:53595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PpgWat-noHLkDuAhpDAAAAX4"]
[Tue Jul 21 07:53:26.508581 2026] [security2:error] [pid 341679:tid 341935] [client 20.104.96.117:12896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/file.php"] [unique_id "al9PpgWat-noHLkDuAhpDgAAAYg"]
[Tue Jul 21 07:53:26.542005 2026] [security2:error] [pid 341679:tid 341927] [client 117.217.38.194:64670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpgWat-noHLkDuAhpDwAAAYA"]
[Tue Jul 21 07:53:26.542140 2026] [security2:error] [pid 341679:tid 341927] [client 117.217.38.194:64670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpgWat-noHLkDuAhpDwAAAYA"]
[Tue Jul 21 07:53:26.604496 2026] [security2:error] [pid 341679:tid 341713] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PpgWat-noHLkDuAhpEgABaiE"]
[Tue Jul 21 07:53:26.604716 2026] [security2:error] [pid 341679:tid 341905] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PpgWat-noHLkDuAhpEgABaiE"]
[Tue Jul 21 07:53:26.816352 2026] [security2:error] [pid 341679:tid 341739] [remote 209.97.182.179:38478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/wp-login.php"] [unique_id "al9PpgWat-noHLkDuAhpHQABbzs"]
[Tue Jul 21 07:53:26.910384 2026] [security2:error] [pid 341679:tid 341814] [client 20.104.96.117:12624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/777.php"] [unique_id "al9PpgWat-noHLkDuAhpIgAAAQ8"]
[Tue Jul 21 07:53:27.106965 2026] [security2:error] [pid 341679:tid 341745] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpwWat-noHLkDuAhpKAABOkE"]
[Tue Jul 21 07:53:27.107114 2026] [security2:error] [pid 341679:tid 341857] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpwWat-noHLkDuAhpKAABOkE"]
[Tue Jul 21 07:53:27.111104 2026] [security2:error] [pid 341679:tid 341753] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpwWat-noHLkDuAhpKQABQUk"]
[Tue Jul 21 07:53:27.111220 2026] [security2:error] [pid 341679:tid 341864] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpwWat-noHLkDuAhpKQABQUk"]
[Tue Jul 21 07:53:27.196085 2026] [security2:error] [pid 341679:tid 341844] [client 20.226.60.151:56759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/ctex1.php"] [unique_id "al9PpwWat-noHLkDuAhpKwAAAS0"]
[Tue Jul 21 07:53:27.238971 2026] [security2:error] [pid 341679:tid 341863] [client 202.143.127.214:61420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpwWat-noHLkDuAhpLAAAAUA"]
[Tue Jul 21 07:53:27.239535 2026] [security2:error] [pid 341679:tid 341863] [client 202.143.127.214:61420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpwWat-noHLkDuAhpLAAAAUA"]
[Tue Jul 21 07:53:27.304111 2026] [security2:error] [pid 341679:tid 341812] [client 20.104.96.117:12508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/ssixta.php"] [unique_id "al9PpwWat-noHLkDuAhpLQAAAQ0"]
[Tue Jul 21 07:53:27.470432 2026] [security2:error] [pid 341679:tid 341850] [client 20.226.60.151:53974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9PpwWat-noHLkDuAhpNgAAATM"]
[Tue Jul 21 07:53:27.503916 2026] [ssl:error] [pid 341679:tid 341925] [client 72.13.46.9:41117] AH02032: Hostname br1102.hostgator.com.br (default host as no SNI was provided) and hostname sublimeassis.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue Jul 21 07:53:27.504058 2026] [security2:error] [pid 341679:tid 341925] [client 72.13.46.9:41117] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "421"] [hostname "sublimeassis.com"] [uri "/hello-world/"] [unique_id "al9PpwWat-noHLkDuAhpOAAAAX4"]
[Tue Jul 21 07:53:27.531718 2026] [security2:error] [pid 341679:tid 341842] [client 122.186.204.214:57101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PpwWat-noHLkDuAhpOQAAASs"]
[Tue Jul 21 07:53:27.531853 2026] [security2:error] [pid 341679:tid 341842] [client 122.186.204.214:57101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PpwWat-noHLkDuAhpOQAAASs"]
[Tue Jul 21 07:53:27.668295 2026] [security2:error] [pid 341679:tid 341737] [remote 104.207.49.44:61907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.49.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9PpwWat-noHLkDuAhpNwABGTk"]
[Tue Jul 21 07:53:27.710329 2026] [security2:error] [pid 341679:tid 341834] [client 20.104.96.117:12909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/1c.php"] [unique_id "al9PpwWat-noHLkDuAhpQAAAASM"]
[Tue Jul 21 07:53:27.741401 2026] [security2:error] [pid 341679:tid 341846] [client 20.220.225.223:19693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/cron-tab.php"] [unique_id "al9PpwWat-noHLkDuAhpQgAAAS8"]
[Tue Jul 21 07:53:27.760001 2026] [security2:error] [pid 341679:tid 341835] [client 20.104.96.117:55027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/xy.php"] [unique_id "al9PpwWat-noHLkDuAhpRQAAASQ"]
[Tue Jul 21 07:53:27.917846 2026] [security2:error] [pid 341679:tid 341869] [client 109.60.28.94:33055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpwWat-noHLkDuAhpSgAAAUY"]
[Tue Jul 21 07:53:27.917958 2026] [security2:error] [pid 341679:tid 341869] [client 109.60.28.94:33055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PpwWat-noHLkDuAhpSgAAAUY"]
[Tue Jul 21 07:53:28.053278 2026] [security2:error] [pid 341679:tid 341740] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PqAWat-noHLkDuAhpTgABSjw"]
[Tue Jul 21 07:53:28.053460 2026] [security2:error] [pid 341679:tid 341873] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PqAWat-noHLkDuAhpTgABSjw"]
[Tue Jul 21 07:53:28.060236 2026] [security2:error] [pid 341679:tid 341870] [client 103.29.114.44:64216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PqAWat-noHLkDuAhpTwAAAUc"]
[Tue Jul 21 07:53:28.060348 2026] [security2:error] [pid 341679:tid 341870] [client 103.29.114.44:64216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PqAWat-noHLkDuAhpTwAAAUc"]
[Tue Jul 21 07:53:28.113895 2026] [security2:error] [pid 341679:tid 341815] [client 103.78.200.11:61477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PqAWat-noHLkDuAhpUAAAARA"]
[Tue Jul 21 07:53:28.115720 2026] [security2:error] [pid 341679:tid 341815] [client 103.78.200.11:61477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PqAWat-noHLkDuAhpUAAAARA"]
[Tue Jul 21 07:53:28.124138 2026] [security2:error] [pid 341679:tid 341813] [client 20.104.96.117:12887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/test2.php"] [unique_id "al9PqAWat-noHLkDuAhpUQAAAQ4"]
[Tue Jul 21 07:53:28.131774 2026] [security2:error] [pid 341679:tid 341913] [client 20.226.60.151:61504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/txets.php"] [unique_id "al9PqAWat-noHLkDuAhpUgAAAXI"]
[Tue Jul 21 07:53:28.258248 2026] [security2:error] [pid 341679:tid 341911] [client 20.226.60.151:61623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/dex.php"] [unique_id "al9PqAWat-noHLkDuAhpVAAAAXA"]
[Tue Jul 21 07:53:28.389465 2026] [security2:error] [pid 341679:tid 341822] [client 20.226.60.151:61513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/xpwer1.php"] [unique_id "al9PqAWat-noHLkDuAhpWgAAARc"]
[Tue Jul 21 07:53:28.434724 2026] [security2:error] [pid 341679:tid 341811] [client 20.104.96.117:54931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/loader.php"] [unique_id "al9PqAWat-noHLkDuAhpWwAAAQw"]
[Tue Jul 21 07:53:28.459977 2026] [security2:error] [pid 341679:tid 341872] [client 20.104.96.117:12666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/buy.php"] [unique_id "al9PqAWat-noHLkDuAhpXQAAAUk"]
[Tue Jul 21 07:53:28.523869 2026] [security2:error] [pid 341679:tid 341897] [client 20.226.60.151:61571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/flox.php"] [unique_id "al9PqAWat-noHLkDuAhpXwAAAWI"]
[Tue Jul 21 07:53:28.717855 2026] [security2:error] [pid 341679:tid 341925] [client 20.197.192.193:3503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/track.php"] [unique_id "al9PqAWat-noHLkDuAhpZgAAAX4"]
[Tue Jul 21 07:53:28.751466 2026] [security2:error] [pid 341679:tid 341901] [client 20.226.60.151:61565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/popo.php"] [unique_id "al9PqAWat-noHLkDuAhpaAAAAWY"]
[Tue Jul 21 07:53:28.828106 2026] [security2:error] [pid 341679:tid 341933] [client 20.226.60.151:56745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/edorxrr.php"] [unique_id "al9PqAWat-noHLkDuAhpaQAAAYY"]
[Tue Jul 21 07:53:28.868576 2026] [security2:error] [pid 341679:tid 341905] [client 20.104.96.117:12643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/ssend.php"] [unique_id "al9PqAWat-noHLkDuAhpbQAAAWo"]
[Tue Jul 21 07:53:28.879547 2026] [security2:error] [pid 341679:tid 341832] [client 122.179.91.63:29695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PqAWat-noHLkDuAhpbgAAASE"]
[Tue Jul 21 07:53:28.879671 2026] [security2:error] [pid 341679:tid 341832] [client 122.179.91.63:29695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PqAWat-noHLkDuAhpbgAAASE"]
[Tue Jul 21 07:53:28.961747 2026] [security2:error] [pid 341679:tid 341874] [client 20.226.60.151:61596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/yas.php"] [unique_id "al9PqAWat-noHLkDuAhpcgAAAUs"]
[Tue Jul 21 07:53:29.053335 2026] [security2:error] [pid 341679:tid 341882] [client 20.226.60.151:61552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/file61.php"] [unique_id "al9PqQWat-noHLkDuAhpdwAAAVM"]
[Tue Jul 21 07:53:29.294861 2026] [security2:error] [pid 341679:tid 341930] [client 106.215.181.8:19718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PqQWat-noHLkDuAhpfAAAAYM"]
[Tue Jul 21 07:53:29.299517 2026] [security2:error] [pid 341679:tid 341930] [client 106.215.181.8:19718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PqQWat-noHLkDuAhpfAAAAYM"]
[Tue Jul 21 07:53:29.386589 2026] [security2:error] [pid 341679:tid 341809] [client 20.104.96.117:12487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/item.php"] [unique_id "al9PqQWat-noHLkDuAhpgAAAAQo"]
[Tue Jul 21 07:53:29.512640 2026] [security2:error] [pid 341679:tid 341904] [client 4.204.201.85:63184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9PqQWat-noHLkDuAhpgwAAAWk"]
[Tue Jul 21 07:53:29.769666 2026] [security2:error] [pid 341679:tid 341878] [client 20.104.96.117:12495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/ss.php"] [unique_id "al9PqQWat-noHLkDuAhpigAAAU8"]
[Tue Jul 21 07:53:29.951915 2026] [security2:error] [pid 341679:tid 341855] [client 4.204.201.85:63222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9PqQWat-noHLkDuAhpkgAAATg"]
[Tue Jul 21 07:53:30.081358 2026] [security2:error] [pid 341679:tid 341936] [client 20.104.96.117:12637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/hypo.php"] [unique_id "al9PqgWat-noHLkDuAhpmgAAAYk"]
[Tue Jul 21 07:53:30.133637 2026] [security2:error] [pid 341679:tid 341778] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PqgWat-noHLkDuAhpnAABamI"]
[Tue Jul 21 07:53:30.133798 2026] [security2:error] [pid 341679:tid 341905] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PqgWat-noHLkDuAhpnAABamI"]
[Tue Jul 21 07:53:30.285921 2026] [security2:error] [pid 341679:tid 341876] [client 78.46.190.63:41666] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9PqgWat-noHLkDuAhpnwAAAU0"], referer: https://artetoner.com.br
[Tue Jul 21 07:53:30.301103 2026] [security2:error] [pid 341679:tid 341835] [client 4.204.201.85:63104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/media.php"] [unique_id "al9PqgWat-noHLkDuAhpoQAAASQ"]
[Tue Jul 21 07:53:30.448961 2026] [security2:error] [pid 341679:tid 341868] [client 20.104.96.117:12500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/users.php"] [unique_id "al9PqgWat-noHLkDuAhppgAAAUU"]
[Tue Jul 21 07:53:30.569159 2026] [security2:error] [pid 341679:tid 341892] [client 20.104.96.117:54941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/spadex.php"] [unique_id "al9PqgWat-noHLkDuAhpqQAAAV0"]
[Tue Jul 21 07:53:30.623846 2026] [security2:error] [pid 341679:tid 341814] [client 4.204.201.85:63231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/images.php"] [unique_id "al9PqgWat-noHLkDuAhpqgAAAQ8"]
[Tue Jul 21 07:53:30.787875 2026] [security2:error] [pid 341679:tid 341796] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PqgWat-noHLkDuAhprwABO3Q"]
[Tue Jul 21 07:53:30.788027 2026] [security2:error] [pid 341679:tid 341858] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PqgWat-noHLkDuAhprwABO3Q"]
[Tue Jul 21 07:53:30.813652 2026] [security2:error] [pid 341679:tid 341816] [client 20.104.96.117:12654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/177.php"] [unique_id "al9PqgWat-noHLkDuAhpsgAAARE"]
[Tue Jul 21 07:53:30.961389 2026] [security2:error] [pid 341679:tid 341809] [client 74.249.245.134:24790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/sx.php"] [unique_id "al9PqgWat-noHLkDuAhptwAAAQo"]
[Tue Jul 21 07:53:30.962268 2026] [security2:error] [pid 341679:tid 341828] [client 74.249.245.134:24811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9PqgWat-noHLkDuAhpuAAAAR0"]
[Tue Jul 21 07:53:31.061536 2026] [security2:error] [pid 341679:tid 341852] [client 4.204.201.85:63213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/gecko.php"] [unique_id "al9PqwWat-noHLkDuAhpvAAAATU"]
[Tue Jul 21 07:53:31.146349 2026] [security2:error] [pid 341679:tid 341934] [client 136.144.33.29:53145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PqgWat-noHLkDuAhpuQAAAYc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:53:31.260787 2026] [security2:error] [pid 341679:tid 341922] [client 182.8.255.181:10146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PqwWat-noHLkDuAhpwAAAAXs"]
[Tue Jul 21 07:53:31.260931 2026] [security2:error] [pid 341679:tid 341922] [client 182.8.255.181:10146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PqwWat-noHLkDuAhpwAAAAXs"]
[Tue Jul 21 07:53:31.312607 2026] [security2:error] [pid 341679:tid 341897] [client 37.140.223.190:29239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PqgWat-noHLkDuAhpnQAAAWI"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:53:31.361145 2026] [security2:error] [pid 341679:tid 341862] [client 4.204.201.85:63169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/82.php"] [unique_id "al9PqwWat-noHLkDuAhpwQAAAT8"]
[Tue Jul 21 07:53:31.379940 2026] [security2:error] [pid 341679:tid 341825] [client 20.104.96.117:12493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/config.php"] [unique_id "al9PqwWat-noHLkDuAhpwgAAARo"]
[Tue Jul 21 07:53:31.501641 2026] [security2:error] [pid 341679:tid 341857] [client 173.252.95.15:45012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9PqwWat-noHLkDuAhpxgAAATo"]
[Tue Jul 21 07:53:31.690071 2026] [security2:error] [pid 341679:tid 341812] [client 204.8.98.45:59136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9PqwWat-noHLkDuAhp0AAAAQ0"]
[Tue Jul 21 07:53:31.690183 2026] [security2:error] [pid 341679:tid 341812] [client 204.8.98.45:59136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9PqwWat-noHLkDuAhp0AAAAQ0"]
[Tue Jul 21 07:53:31.801917 2026] [security2:error] [pid 341679:tid 341844] [client 102.206.115.33:59122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9PqwWat-noHLkDuAhp0QAAAS0"]
[Tue Jul 21 07:53:31.802034 2026] [security2:error] [pid 341679:tid 341844] [client 102.206.115.33:59122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9PqwWat-noHLkDuAhp0QAAAS0"]
[Tue Jul 21 07:53:31.813126 2026] [security2:error] [pid 341679:tid 341882] [client 4.204.201.85:63110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/admin.php"] [unique_id "al9PqwWat-noHLkDuAhp0gAAAVM"]
[Tue Jul 21 07:53:31.921401 2026] [security2:error] [pid 341679:tid 341846] [client 20.220.225.223:19666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/koiy.php"] [unique_id "al9PqwWat-noHLkDuAhp1AAAAS8"]
[Tue Jul 21 07:53:31.977216 2026] [security2:error] [pid 341679:tid 341856] [client 20.104.96.117:12649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/gettest.php"] [unique_id "al9PqwWat-noHLkDuAhp1wAAATk"]
[Tue Jul 21 07:53:32.064324 2026] [security2:error] [pid 341679:tid 341866] [client 122.164.127.47:58488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PrAWat-noHLkDuAhp2QAAAUM"]
[Tue Jul 21 07:53:32.066127 2026] [security2:error] [pid 341679:tid 341866] [client 122.164.127.47:58488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PrAWat-noHLkDuAhp2QAAAUM"]
[Tue Jul 21 07:53:32.325491 2026] [security2:error] [pid 341679:tid 341902] [client 4.204.201.85:63170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/adminner.php"] [unique_id "al9PrAWat-noHLkDuAhp3AAAAWc"]
[Tue Jul 21 07:53:32.365173 2026] [security2:error] [pid 341679:tid 341893] [client 20.226.60.151:56785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/miru1.php"] [unique_id "al9PrAWat-noHLkDuAhp4AAAAV4"]
[Tue Jul 21 07:53:32.414774 2026] [security2:error] [pid 341679:tid 341863] [client 20.104.96.117:12507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/min.php"] [unique_id "al9PrAWat-noHLkDuAhp4QAAAUA"]
[Tue Jul 21 07:53:32.613513 2026] [security2:error] [pid 341679:tid 341906] [client 173.252.95.40:60068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9PrAWat-noHLkDuAhp5gAAAWs"]
[Tue Jul 21 07:53:32.760671 2026] [security2:error] [pid 341679:tid 341850] [client 20.104.96.117:12483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/dvjul.php"] [unique_id "al9PrAWat-noHLkDuAhp5wAAATM"]
[Tue Jul 21 07:53:32.771659 2026] [security2:error] [pid 341679:tid 341918] [client 185.213.175.37:27544] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "atendimento.monteirosantosesilva.com.br"] [uri "/cgi-sys/images/favicons/favicon.ico"] [unique_id "al9PrAWat-noHLkDuAhp6QAAAXc"]
[Tue Jul 21 07:53:32.875988 2026] [security2:error] [pid 341679:tid 341830] [client 185.213.175.37:27578] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "atendimento.monteirosantosesilva.com.br"] [uri "/cgi-sys/images/favicons/favicon-32.png"] [unique_id "al9PrAWat-noHLkDuAhp8QAAAR8"]
[Tue Jul 21 07:53:32.876070 2026] [security2:error] [pid 341679:tid 341830] [client 185.213.175.37:27578] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "atendimento.monteirosantosesilva.com.br"] [uri "/cgi-sys/images/favicons/favicon-32.png"] [unique_id "al9PrAWat-noHLkDuAhp8QAAAR8"]
[Tue Jul 21 07:53:32.906128 2026] [security2:error] [pid 341679:tid 341933] [client 185.213.175.37:27600] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "atendimento.monteirosantosesilva.com.br"] [uri "/cgi-sys/images/favicons/favicon-128.png"] [unique_id "al9PrAWat-noHLkDuAhp8wAAAYY"]
[Tue Jul 21 07:53:32.953931 2026] [security2:error] [pid 341679:tid 341903] [client 4.204.201.85:63181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/admin.php"] [unique_id "al9PrAWat-noHLkDuAhp9QAAAWg"]
[Tue Jul 21 07:53:32.985511 2026] [security2:error] [pid 341679:tid 341846] [client 184.75.221.3:40320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9PrAWat-noHLkDuAhp-QAAAS8"]
[Tue Jul 21 07:53:32.985587 2026] [security2:error] [pid 341679:tid 341846] [client 184.75.221.3:40320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9PrAWat-noHLkDuAhp-QAAAS8"]
[Tue Jul 21 07:53:33.190433 2026] [security2:error] [pid 341679:tid 341930] [client 20.104.96.117:12875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/biufile.php"] [unique_id "al9PrQWat-noHLkDuAhqBAAAAYM"]
[Tue Jul 21 07:53:33.253353 2026] [security2:error] [pid 341679:tid 341815] [client 20.220.225.223:35070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-css.php"] [unique_id "al9PrQWat-noHLkDuAhqBgAAARA"]
[Tue Jul 21 07:53:33.356149 2026] [security2:error] [pid 341679:tid 341836] [client 20.197.192.193:3469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/2352356666.php"] [unique_id "al9PrQWat-noHLkDuAhqCwAAASU"]
[Tue Jul 21 07:53:33.523540 2026] [security2:error] [pid 341679:tid 341889] [client 20.104.96.117:12534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/av.php"] [unique_id "al9PrQWat-noHLkDuAhqEAAAAVo"]
[Tue Jul 21 07:53:33.565722 2026] [security2:error] [pid 341679:tid 341794] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PrQWat-noHLkDuAhqGAABYnI"]
[Tue Jul 21 07:53:33.565857 2026] [security2:error] [pid 341679:tid 341897] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PrQWat-noHLkDuAhqGAABYnI"]
[Tue Jul 21 07:53:33.601961 2026] [security2:error] [pid 341679:tid 341871] [client 4.204.201.85:63133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/k.php"] [unique_id "al9PrQWat-noHLkDuAhqGwAAAUg"]
[Tue Jul 21 07:53:33.824625 2026] [security2:error] [pid 341679:tid 341851] [client 20.226.60.151:61539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/water.php"] [unique_id "al9PrQWat-noHLkDuAhqHgAAATQ"]
[Tue Jul 21 07:53:33.874293 2026] [security2:error] [pid 341679:tid 341918] [client 20.104.96.117:54965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/2x.php"] [unique_id "al9PrQWat-noHLkDuAhqIQAAAXc"]
[Tue Jul 21 07:53:33.896513 2026] [security2:error] [pid 341679:tid 341855] [client 20.104.96.117:12657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/coffexium.php"] [unique_id "al9PrQWat-noHLkDuAhqIwAAATg"]
[Tue Jul 21 07:53:34.043853 2026] [security2:error] [pid 341679:tid 341817] [client 103.86.117.203:55878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PrgWat-noHLkDuAhqKQAAARI"]
[Tue Jul 21 07:53:34.043961 2026] [security2:error] [pid 341679:tid 341817] [client 103.86.117.203:55878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PrgWat-noHLkDuAhqKQAAARI"]
[Tue Jul 21 07:53:34.210210 2026] [security2:error] [pid 341679:tid 341818] [client 20.104.96.117:12741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/core.php"] [unique_id "al9PrgWat-noHLkDuAhqLQAAARM"]
[Tue Jul 21 07:53:34.235594 2026] [security2:error] [pid 341679:tid 341856] [client 173.252.95.40:60072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9PrgWat-noHLkDuAhqLgAAATk"]
[Tue Jul 21 07:53:34.367551 2026] [security2:error] [pid 341679:tid 341716] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PrgWat-noHLkDuAhqNAABTCQ"]
[Tue Jul 21 07:53:34.367729 2026] [security2:error] [pid 341679:tid 341875] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PrgWat-noHLkDuAhqNAABTCQ"]
[Tue Jul 21 07:53:34.388104 2026] [security2:error] [pid 341679:tid 341815] [client 4.204.201.85:63105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/blurbs.php"] [unique_id "al9PrgWat-noHLkDuAhqNgAAARA"]
[Tue Jul 21 07:53:34.451867 2026] [security2:error] [pid 341679:tid 341722] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PrgWat-noHLkDuAhqPAABfCo"]
[Tue Jul 21 07:53:34.452004 2026] [security2:error] [pid 341679:tid 341923] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PrgWat-noHLkDuAhqPAABfCo"]
[Tue Jul 21 07:53:34.561958 2026] [security2:error] [pid 341679:tid 341896] [client 173.252.95.16:56508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9PrgWat-noHLkDuAhqPgAAAWE"]
[Tue Jul 21 07:53:34.622282 2026] [security2:error] [pid 341679:tid 341869] [client 20.104.96.117:12739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/als.php"] [unique_id "al9PrgWat-noHLkDuAhqRQAAAUY"]
[Tue Jul 21 07:53:34.654029 2026] [security2:error] [pid 341679:tid 341893] [client 20.226.60.151:56735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/sump1.php"] [unique_id "al9PrgWat-noHLkDuAhqRgAAAV4"]
[Tue Jul 21 07:53:34.692825 2026] [security2:error] [pid 341679:tid 341882] [client 122.162.144.145:19843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PrgWat-noHLkDuAhqSQAAAVM"]
[Tue Jul 21 07:53:34.692925 2026] [security2:error] [pid 341679:tid 341882] [client 122.162.144.145:19843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PrgWat-noHLkDuAhqSQAAAVM"]
[Tue Jul 21 07:53:34.816576 2026] [security2:error] [pid 341679:tid 341858] [client 41.68.90.219:53268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PrgWat-noHLkDuAhqTgAAATs"]
[Tue Jul 21 07:53:34.816722 2026] [security2:error] [pid 341679:tid 341858] [client 41.68.90.219:53268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PrgWat-noHLkDuAhqTgAAATs"]
[Tue Jul 21 07:53:34.848576 2026] [security2:error] [pid 341679:tid 341898] [client 4.204.201.85:63227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/bajah.php"] [unique_id "al9PrgWat-noHLkDuAhqTwAAAWM"]
[Tue Jul 21 07:53:34.918751 2026] [security2:error] [pid 341679:tid 341863] [client 20.104.96.117:12893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/simple.php"] [unique_id "al9PrgWat-noHLkDuAhqUQAAAUA"]
[Tue Jul 21 07:53:34.941706 2026] [security2:error] [pid 341679:tid 341887] [client 74.249.245.134:24793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/av.php"] [unique_id "al9PrgWat-noHLkDuAhqVAAAAVg"]
[Tue Jul 21 07:53:34.946837 2026] [security2:error] [pid 341679:tid 341878] [client 74.249.245.134:8807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/article.php"] [unique_id "al9PrgWat-noHLkDuAhqVgAAAU8"]
[Tue Jul 21 07:53:35.218665 2026] [security2:error] [pid 341679:tid 341890] [client 4.204.201.85:63193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/a.php"] [unique_id "al9PrwWat-noHLkDuAhqXAAAAVs"]
[Tue Jul 21 07:53:35.265201 2026] [security2:error] [pid 341679:tid 341817] [client 20.104.96.117:12914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/init.php"] [unique_id "al9PrwWat-noHLkDuAhqXgAAARI"]
[Tue Jul 21 07:53:35.290843 2026] [security2:error] [pid 341679:tid 341906] [client 69.171.230.16:34014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9PrwWat-noHLkDuAhqWgAAAWs"]
[Tue Jul 21 07:53:35.416396 2026] [security2:error] [pid 341679:tid 341924] [client 104.207.46.40:13345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.46.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PrwWat-noHLkDuAhqXQAAAX0"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:53:35.506350 2026] [security2:error] [pid 341679:tid 341866] [client 4.204.201.85:63179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/edit.php"] [unique_id "al9PrwWat-noHLkDuAhqaQAAAUM"]
[Tue Jul 21 07:53:35.562426 2026] [security2:error] [pid 341679:tid 341934] [client 223.236.153.128:5675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PrwWat-noHLkDuAhqagAAAYc"]
[Tue Jul 21 07:53:35.562608 2026] [security2:error] [pid 341679:tid 341934] [client 223.236.153.128:5675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PrwWat-noHLkDuAhqagAAAYc"]
[Tue Jul 21 07:53:35.597409 2026] [security2:error] [pid 341679:tid 341809] [client 20.104.96.117:12543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/fpwch.php"] [unique_id "al9PrwWat-noHLkDuAhqawAAAQo"]
[Tue Jul 21 07:53:35.663095 2026] [security2:error] [pid 341679:tid 341926] [client 20.220.225.223:35023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/wp-explorer.php"] [unique_id "al9PrwWat-noHLkDuAhqcAAAAX8"]
[Tue Jul 21 07:53:35.743483 2026] [security2:error] [pid 341679:tid 341907] [client 103.166.103.129:42255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PrwWat-noHLkDuAhqcgAAAWw"]
[Tue Jul 21 07:53:35.743673 2026] [security2:error] [pid 341679:tid 341907] [client 103.166.103.129:42255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PrwWat-noHLkDuAhqcgAAAWw"]
[Tue Jul 21 07:53:35.763580 2026] [security2:error] [pid 341679:tid 341915] [client 204.8.98.45:42666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9PrwWat-noHLkDuAhqcwAAAXQ"]
[Tue Jul 21 07:53:35.763666 2026] [security2:error] [pid 341679:tid 341915] [client 204.8.98.45:42666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9PrwWat-noHLkDuAhqcwAAAXQ"]
[Tue Jul 21 07:53:35.772513 2026] [security2:error] [pid 341679:tid 341893] [client 37.140.223.157:28423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PrwWat-noHLkDuAhqdAAAAV4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:53:35.800513 2026] [security2:error] [pid 341679:tid 341812] [client 136.144.33.54:60283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PrwWat-noHLkDuAhqdQAAAQ0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:53:35.941903 2026] [security2:error] [pid 341679:tid 341914] [client 20.104.96.117:12898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/domvf.php"] [unique_id "al9PrwWat-noHLkDuAhqeAAAAXM"]
[Tue Jul 21 07:53:35.963369 2026] [security2:error] [pid 341679:tid 341891] [client 20.104.96.117:55000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/ctex1.php"] [unique_id "al9PrwWat-noHLkDuAhqeQAAAVw"]
[Tue Jul 21 07:53:35.972918 2026] [security2:error] [pid 341679:tid 341904] [client 4.204.201.85:63140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/hosty.php"] [unique_id "al9PrwWat-noHLkDuAhqegAAAWk"]
[Tue Jul 21 07:53:35.973037 2026] [security2:error] [pid 341679:tid 341818] [client 178.153.91.96:48795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PrwWat-noHLkDuAhqewAAARM"]
[Tue Jul 21 07:53:35.973157 2026] [security2:error] [pid 341679:tid 341818] [client 178.153.91.96:48795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PrwWat-noHLkDuAhqewAAARM"]
[Tue Jul 21 07:53:36.166389 2026] [security2:error] [pid 341679:tid 341922] [client 69.171.230.41:37762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9PsAWat-noHLkDuAhqiAAAAXs"]
[Tue Jul 21 07:53:36.386385 2026] [security2:error] [pid 341679:tid 341912] [client 4.204.201.85:63125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/k.php"] [unique_id "al9PsAWat-noHLkDuAhqjAAAAXE"]
[Tue Jul 21 07:53:36.445956 2026] [security2:error] [pid 341679:tid 341846] [client 20.206.105.145:55927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9PsAWat-noHLkDuAhqjQAAAS8"]
[Tue Jul 21 07:53:36.588838 2026] [security2:error] [pid 341679:tid 341932] [client 20.104.96.117:12541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/wp.php"] [unique_id "al9PsAWat-noHLkDuAhqlAAAAYU"]
[Tue Jul 21 07:53:36.600836 2026] [security2:error] [pid 341679:tid 341884] [client 117.247.80.59:29611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsAWat-noHLkDuAhqlQAAAVU"]
[Tue Jul 21 07:53:36.600939 2026] [security2:error] [pid 341679:tid 341884] [client 117.247.80.59:29611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsAWat-noHLkDuAhqlQAAAVU"]
[Tue Jul 21 07:53:36.607207 2026] [security2:error] [pid 341679:tid 341892] [client 114.119.150.86:48293] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "madeireirapiske.com.br"] [uri "/catalogo/p1/"] [unique_id "al9PsAWat-noHLkDuAhqlgAAAV0"], referer: https://madeireirapiske.com.br/wp-sitemap-posts-us_portfolio-1.xml
[Tue Jul 21 07:53:36.644111 2026] [security2:error] [pid 341679:tid 341842] [client 20.220.225.223:19675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/hp2.php"] [unique_id "al9PsAWat-noHLkDuAhqmwAAASs"]
[Tue Jul 21 07:53:36.726255 2026] [security2:error] [pid 341679:tid 341858] [client 139.167.225.182:58318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsAWat-noHLkDuAhqngAAATs"]
[Tue Jul 21 07:53:36.726392 2026] [security2:error] [pid 341679:tid 341858] [client 139.167.225.182:58318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsAWat-noHLkDuAhqngAAATs"]
[Tue Jul 21 07:53:36.783552 2026] [security2:error] [pid 341679:tid 341921] [client 4.204.201.85:63122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/aaa.php"] [unique_id "al9PsAWat-noHLkDuAhqoQAAAXo"]
[Tue Jul 21 07:53:37.012673 2026] [security2:error] [pid 341679:tid 341837] [client 173.24.185.52:54071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PsQWat-noHLkDuAhqogAAASY"]
[Tue Jul 21 07:53:37.012810 2026] [security2:error] [pid 341679:tid 341837] [client 173.24.185.52:54071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PsQWat-noHLkDuAhqogAAASY"]
[Tue Jul 21 07:53:37.028554 2026] [security2:error] [pid 341679:tid 341883] [client 117.217.38.194:65160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsQWat-noHLkDuAhqpAAAAVQ"]
[Tue Jul 21 07:53:37.028651 2026] [security2:error] [pid 341679:tid 341883] [client 117.217.38.194:65160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsQWat-noHLkDuAhqpAAAAVQ"]
[Tue Jul 21 07:53:37.056262 2026] [security2:error] [pid 341679:tid 341699] [remote 167.71.240.77:43456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.240.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/wp-login.php"] [unique_id "al9PsQWat-noHLkDuAhqpwABbBM"]
[Tue Jul 21 07:53:37.117332 2026] [security2:error] [pid 341679:tid 341891] [client 20.104.96.117:12757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/class.php"] [unique_id "al9PsQWat-noHLkDuAhqqAAAAVw"]
[Tue Jul 21 07:53:37.187177 2026] [security2:error] [pid 341679:tid 341935] [client 74.249.245.134:64402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/bootstrap.php"] [unique_id "al9PsQWat-noHLkDuAhqrAAAAYg"]
[Tue Jul 21 07:53:37.258473 2026] [security2:error] [pid 341679:tid 341847] [client 103.78.200.11:61921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsQWat-noHLkDuAhqrgAAATA"]
[Tue Jul 21 07:53:37.260134 2026] [security2:error] [pid 341679:tid 341847] [client 103.78.200.11:61921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsQWat-noHLkDuAhqrgAAATA"]
[Tue Jul 21 07:53:37.402166 2026] [security2:error] [pid 341679:tid 341864] [client 20.104.96.117:12877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/echkm.php"] [unique_id "al9PsQWat-noHLkDuAhqsAAAAUE"]
[Tue Jul 21 07:53:37.554054 2026] [security2:error] [pid 341679:tid 341737] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PsQWat-noHLkDuAhqtgABDDk"]
[Tue Jul 21 07:53:37.554330 2026] [security2:error] [pid 341679:tid 341811] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PsQWat-noHLkDuAhqtgABDDk"]
[Tue Jul 21 07:53:37.636489 2026] [security2:error] [pid 341679:tid 341846] [client 20.226.60.151:56811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/file5.php"] [unique_id "al9PsQWat-noHLkDuAhqvQAAAS8"]
[Tue Jul 21 07:53:37.655835 2026] [security2:error] [pid 341679:tid 341744] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsQWat-noHLkDuAhqwAABh0A"]
[Tue Jul 21 07:53:37.655973 2026] [security2:error] [pid 341679:tid 341934] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsQWat-noHLkDuAhqwAABh0A"]
[Tue Jul 21 07:53:37.676771 2026] [security2:error] [pid 341679:tid 341740] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsQWat-noHLkDuAhqwgABUTw"]
[Tue Jul 21 07:53:37.676903 2026] [security2:error] [pid 341679:tid 341880] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsQWat-noHLkDuAhqwgABUTw"]
[Tue Jul 21 07:53:37.716515 2026] [security2:error] [pid 341679:tid 341923] [client 74.249.245.134:64201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/config-backup.php"] [unique_id "al9PsQWat-noHLkDuAhqwwAAAXw"]
[Tue Jul 21 07:53:37.725449 2026] [autoindex:error] [pid 341679:tid 341879] [client 147.185.132.159:64816] AH01276: Cannot serve directory /home2/jefe0292/robopsf3.agendaclique.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:53:37.781426 2026] [security2:error] [pid 341679:tid 341859] [client 4.204.201.85:63230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/file5.php"] [unique_id "al9PsQWat-noHLkDuAhqygAAATw"]
[Tue Jul 21 07:53:37.839976 2026] [security2:error] [pid 341679:tid 341837] [client 20.104.96.117:12777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/lib.php"] [unique_id "al9PsQWat-noHLkDuAhqzgAAASY"]
[Tue Jul 21 07:53:38.259289 2026] [security2:error] [pid 341679:tid 341898] [client 20.104.96.117:12513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/login.php"] [unique_id "al9PsgWat-noHLkDuAhq3AAAAWM"]
[Tue Jul 21 07:53:38.260767 2026] [security2:error] [pid 341679:tid 341856] [client 122.186.204.214:57635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PsgWat-noHLkDuAhq3QAAATk"]
[Tue Jul 21 07:53:38.260909 2026] [security2:error] [pid 341679:tid 341856] [client 122.186.204.214:57635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PsgWat-noHLkDuAhq3QAAATk"]
[Tue Jul 21 07:53:38.373123 2026] [security2:error] [pid 341679:tid 341845] [client 202.143.127.214:62149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsgWat-noHLkDuAhq4AAAAS4"]
[Tue Jul 21 07:53:38.373654 2026] [security2:error] [pid 341679:tid 341845] [client 202.143.127.214:62149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsgWat-noHLkDuAhq4AAAAS4"]
[Tue Jul 21 07:53:38.438835 2026] [security2:error] [pid 341679:tid 341892] [client 114.119.138.155:56297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tempex.com.br"] [uri "/nossos-parceiros"] [unique_id "al9PsgWat-noHLkDuAhq4gAAAV0"], referer: https://www.tempex.com.br/sobre-nos
[Tue Jul 21 07:53:38.590239 2026] [security2:error] [pid 341679:tid 341840] [client 20.206.105.145:55874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9PsgWat-noHLkDuAhq5QAAASk"]
[Tue Jul 21 07:53:38.682809 2026] [security2:error] [pid 341679:tid 341883] [client 103.29.114.44:37965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsgWat-noHLkDuAhq6QAAAVQ"]
[Tue Jul 21 07:53:38.682938 2026] [security2:error] [pid 341679:tid 341883] [client 103.29.114.44:37965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsgWat-noHLkDuAhq6QAAAVQ"]
[Tue Jul 21 07:53:38.724849 2026] [security2:error] [pid 341679:tid 341735] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsgWat-noHLkDuAhq6wABGjc"]
[Tue Jul 21 07:53:38.725044 2026] [security2:error] [pid 341679:tid 341825] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsgWat-noHLkDuAhq6wABGjc"]
[Tue Jul 21 07:53:38.749218 2026] [security2:error] [pid 341679:tid 341862] [client 20.104.96.117:12769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/a2.php"] [unique_id "al9PsgWat-noHLkDuAhq7wAAAT8"]
[Tue Jul 21 07:53:38.850641 2026] [security2:error] [pid 341679:tid 341765] [remote 34.86.195.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.195.86.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsgWat-noHLkDuAhq8AABFFU"]
[Tue Jul 21 07:53:38.866100 2026] [security2:error] [pid 341679:tid 341906] [client 20.226.60.151:56772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/0xD.php"] [unique_id "al9PsgWat-noHLkDuAhq8QAAAWs"]
[Tue Jul 21 07:53:38.888476 2026] [security2:error] [pid 341679:tid 341831] [client 109.60.28.94:50314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsgWat-noHLkDuAhq8gAAASA"]
[Tue Jul 21 07:53:38.888626 2026] [security2:error] [pid 341679:tid 341831] [client 109.60.28.94:50314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PsgWat-noHLkDuAhq8gAAASA"]
[Tue Jul 21 07:53:39.005796 2026] [security2:error] [pid 341679:tid 341835] [client 4.204.201.85:63120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/222.php"] [unique_id "al9PswWat-noHLkDuAhq9QAAASQ"]
[Tue Jul 21 07:53:39.006032 2026] [security2:error] [pid 341679:tid 341786] [remote 34.86.195.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wendelleite.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9PswWat-noHLkDuAhq9gABKmo"]
[Tue Jul 21 07:53:39.118455 2026] [security2:error] [pid 341679:tid 341927] [client 20.104.96.117:12754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/d61.php"] [unique_id "al9PswWat-noHLkDuAhq-gAAAYA"]
[Tue Jul 21 07:53:39.152390 2026] [security2:error] [pid 341679:tid 341780] [remote 34.86.195.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wendelleite.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9PswWat-noHLkDuAhq-wABb2Q"]
[Tue Jul 21 07:53:39.279233 2026] [security2:error] [pid 341679:tid 341782] [remote 34.86.195.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wendelleite.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9PswWat-noHLkDuAhq_QABYGY"]
[Tue Jul 21 07:53:39.405734 2026] [security2:error] [pid 341679:tid 341877] [client 20.220.225.223:32296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/akismet.php"] [unique_id "al9PswWat-noHLkDuAhrAwAAAU4"]
[Tue Jul 21 07:53:39.421397 2026] [security2:error] [pid 341679:tid 341778] [remote 34.86.195.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wendelleite.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9PswWat-noHLkDuAhrBwABT2I"]
[Tue Jul 21 07:53:39.497359 2026] [security2:error] [pid 341679:tid 341911] [client 20.226.60.151:61532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/nano.php"] [unique_id "al9PswWat-noHLkDuAhrCAAAAXA"]
[Tue Jul 21 07:53:39.514585 2026] [security2:error] [pid 341679:tid 341898] [client 20.104.96.117:12897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/info.php"] [unique_id "al9PswWat-noHLkDuAhrCwAAAWM"]
[Tue Jul 21 07:53:39.586034 2026] [security2:error] [pid 341679:tid 341836] [client 122.179.91.63:1187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PswWat-noHLkDuAhrDQAAASU"]
[Tue Jul 21 07:53:39.586177 2026] [security2:error] [pid 341679:tid 341836] [client 122.179.91.63:1187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PswWat-noHLkDuAhrDQAAASU"]
[Tue Jul 21 07:53:39.672751 2026] [security2:error] [pid 341679:tid 341810] [client 37.140.223.69:37175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PswWat-noHLkDuAhrCgAAAQs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:53:39.722253 2026] [security2:error] [pid 341679:tid 341809] [client 4.204.201.85:63214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/test.php"] [unique_id "al9PswWat-noHLkDuAhrEgAAAQo"]
[Tue Jul 21 07:53:39.722537 2026] [security2:error] [pid 341679:tid 341791] [remote 34.86.195.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wendelleite.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9PswWat-noHLkDuAhrEwABhW8"]
[Tue Jul 21 07:53:39.793897 2026] [security2:error] [pid 341679:tid 341821] [client 106.215.181.8:17909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PswWat-noHLkDuAhrGAAAARY"]
[Tue Jul 21 07:53:39.794008 2026] [security2:error] [pid 341679:tid 341821] [client 106.215.181.8:17909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PswWat-noHLkDuAhrGAAAARY"]
[Tue Jul 21 07:53:39.832095 2026] [security2:error] [pid 341679:tid 341842] [client 20.104.96.117:12671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/11.php"] [unique_id "al9PswWat-noHLkDuAhrGgAAASs"]
[Tue Jul 21 07:53:39.885947 2026] [security2:error] [pid 341679:tid 341723] [remote 34.86.195.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wendelleite.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9PswWat-noHLkDuAhrGwABfys"]
[Tue Jul 21 07:53:40.089967 2026] [security2:error] [pid 341679:tid 341710] [remote 34.86.195.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wendelleite.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9PtAWat-noHLkDuAhrHQABRh4"]
[Tue Jul 21 07:53:40.156552 2026] [security2:error] [pid 341679:tid 341837] [client 20.104.96.117:12631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/v2.php"] [unique_id "al9PtAWat-noHLkDuAhrIQAAASY"]
[Tue Jul 21 07:53:40.227024 2026] [security2:error] [pid 341679:tid 341784] [remote 34.86.195.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wendelleite.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9PtAWat-noHLkDuAhrIwABFGg"]
[Tue Jul 21 07:53:40.333433 2026] [security2:error] [pid 341679:tid 341870] [client 20.206.105.145:55834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/media.php"] [unique_id "al9PtAWat-noHLkDuAhrKAAAAUc"]
[Tue Jul 21 07:53:40.420315 2026] [security2:error] [pid 341679:tid 341776] [remote 34.86.195.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wendelleite.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9PtAWat-noHLkDuAhrKgABQGA"]
[Tue Jul 21 07:53:40.461625 2026] [security2:error] [pid 341679:tid 341852] [client 20.104.96.117:12540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/panel.php"] [unique_id "al9PtAWat-noHLkDuAhrKwAAATU"]
[Tue Jul 21 07:53:40.553909 2026] [security2:error] [pid 341679:tid 341904] [client 198.54.128.138:58338] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9PtAWat-noHLkDuAhrLQAAAWk"]
[Tue Jul 21 07:53:40.554019 2026] [security2:error] [pid 341679:tid 341904] [client 198.54.128.138:58338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9PtAWat-noHLkDuAhrLQAAAWk"]
[Tue Jul 21 07:53:40.583908 2026] [security2:error] [pid 341679:tid 341698] [remote 34.86.195.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wendelleite.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9PtAWat-noHLkDuAhrLgABbxI"]
[Tue Jul 21 07:53:40.624639 2026] [security2:error] [pid 341679:tid 341925] [client 74.249.245.134:64088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/gg.php"] [unique_id "al9PtAWat-noHLkDuAhrLwAAAX4"]
[Tue Jul 21 07:53:40.766959 2026] [security2:error] [pid 341679:tid 341702] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PtAWat-noHLkDuAhrMwABgBY"]
[Tue Jul 21 07:53:40.767115 2026] [security2:error] [pid 341679:tid 341927] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PtAWat-noHLkDuAhrMwABgBY"]
[Tue Jul 21 07:53:40.775246 2026] [security2:error] [pid 341679:tid 341871] [client 20.104.96.117:12884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/dex.php"] [unique_id "al9PtAWat-noHLkDuAhrNAAAAUg"]
[Tue Jul 21 07:53:40.862249 2026] [security2:error] [pid 341679:tid 341890] [client 20.220.225.223:19655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/hp3.php"] [unique_id "al9PtAWat-noHLkDuAhrOQAAAVs"]
[Tue Jul 21 07:53:40.889399 2026] [security2:error] [pid 341679:tid 341706] [remote 34.86.195.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wendelleite.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9PtAWat-noHLkDuAhrSwABOho"]
[Tue Jul 21 07:53:40.964469 2026] [security2:error] [pid 341679:tid 341814] [client 20.226.60.151:56731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/fnstall.php"] [unique_id "al9PtAWat-noHLkDuAhrWgAAAQ8"]
[Tue Jul 21 07:53:41.019400 2026] [security2:error] [pid 341679:tid 341730] [remote 34.86.195.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "wendelleite.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9PtQWat-noHLkDuAhrXAABOTI"]
[Tue Jul 21 07:53:41.108435 2026] [security2:error] [pid 341679:tid 341913] [client 4.204.201.85:63176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/aaa.php"] [unique_id "al9PtQWat-noHLkDuAhrYAAAAXI"]
[Tue Jul 21 07:53:41.119582 2026] [security2:error] [pid 341679:tid 341828] [client 20.104.96.117:12526] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "exclusivaeventos.com.br"] [uri "/1.php"] [unique_id "al9PtQWat-noHLkDuAhrbQAAAR0"]
[Tue Jul 21 07:53:41.119699 2026] [security2:error] [pid 341679:tid 341828] [client 20.104.96.117:12526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/1.php"] [unique_id "al9PtQWat-noHLkDuAhrbQAAAR0"]
[Tue Jul 21 07:53:41.296005 2026] [security2:error] [pid 341679:tid 341858] [client 20.226.60.151:53952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/moon.php"] [unique_id "al9PtQWat-noHLkDuAhrfgAAATs"]
[Tue Jul 21 07:53:41.457785 2026] [security2:error] [pid 341679:tid 341837] [client 20.104.96.117:12511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/ms.php"] [unique_id "al9PtQWat-noHLkDuAhrhAAAASY"]
[Tue Jul 21 07:53:41.467614 2026] [security2:error] [pid 341679:tid 341777] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PtQWat-noHLkDuAhrhQABC2E"]
[Tue Jul 21 07:53:41.467820 2026] [security2:error] [pid 341679:tid 341810] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PtQWat-noHLkDuAhrhQABC2E"]
[Tue Jul 21 07:53:41.592236 2026] [security2:error] [pid 341679:tid 341875] [client 182.8.255.181:2940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PtQWat-noHLkDuAhrhgAAAUw"]
[Tue Jul 21 07:53:41.592367 2026] [security2:error] [pid 341679:tid 341875] [client 182.8.255.181:2940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PtQWat-noHLkDuAhrhgAAAUw"]
[Tue Jul 21 07:53:41.828930 2026] [security2:error] [pid 341679:tid 341872] [client 4.204.201.85:63218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/11.php"] [unique_id "al9PtQWat-noHLkDuAhrkgAAAUk"]
[Tue Jul 21 07:53:41.996340 2026] [security2:error] [pid 341679:tid 341750] [remote 178.18.124.148:26430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.124.18.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/wp-login.php"] [unique_id "al9PtQWat-noHLkDuAhrngABZ0Y"]
[Tue Jul 21 07:53:42.001698 2026] [security2:error] [pid 341679:tid 341924] [client 20.104.96.117:12627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/memberfuns.php"] [unique_id "al9PtgWat-noHLkDuAhrnwAAAX0"]
[Tue Jul 21 07:53:42.013316 2026] [security2:error] [pid 341679:tid 341817] [client 74.249.245.134:64073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/sql.php"] [unique_id "al9PtgWat-noHLkDuAhroAAAARI"]
[Tue Jul 21 07:53:42.022124 2026] [security2:error] [pid 341679:tid 341890] [client 74.249.245.134:64390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/goods.php"] [unique_id "al9PtgWat-noHLkDuAhroQAAAVs"]
[Tue Jul 21 07:53:42.312570 2026] [security2:error] [pid 341679:tid 341898] [client 4.204.201.85:63141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/mac.php"] [unique_id "al9PtgWat-noHLkDuAhrqwAAAWM"]
[Tue Jul 21 07:53:42.384104 2026] [security2:error] [pid 341679:tid 341931] [client 102.206.115.33:57832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9PtgWat-noHLkDuAhrrwAAAYQ"]
[Tue Jul 21 07:53:42.384237 2026] [security2:error] [pid 341679:tid 341931] [client 102.206.115.33:57832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9PtgWat-noHLkDuAhrrwAAAYQ"]
[Tue Jul 21 07:53:42.446932 2026] [security2:error] [pid 341679:tid 341809] [client 20.104.96.117:12535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/0.php"] [unique_id "al9PtgWat-noHLkDuAhrswAAAQo"]
[Tue Jul 21 07:53:42.524029 2026] [security2:error] [pid 341679:tid 341880] [client 20.197.192.193:3484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/pn.php"] [unique_id "al9PtgWat-noHLkDuAhrtQAAAVE"]
[Tue Jul 21 07:53:42.633529 2026] [security2:error] [pid 341679:tid 341850] [client 4.204.201.85:63183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/chosen.php"] [unique_id "al9PtgWat-noHLkDuAhrvQAAATM"]
[Tue Jul 21 07:53:42.899765 2026] [security2:error] [pid 341679:tid 341841] [client 20.104.96.117:12644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/BDKR28.php"] [unique_id "al9PtgWat-noHLkDuAhrzwAAASo"]
[Tue Jul 21 07:53:42.912921 2026] [security2:error] [pid 341679:tid 341866] [client 193.36.225.152:24049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PtgWat-noHLkDuAhrwgAAAUM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:53:42.969017 2026] [security2:error] [pid 341679:tid 341872] [client 20.206.105.145:55929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/images.php"] [unique_id "al9PtgWat-noHLkDuAhr1AAAAUk"]
[Tue Jul 21 07:53:42.979241 2026] [security2:error] [pid 341679:tid 341812] [client 4.204.201.85:63171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/cream1.php"] [unique_id "al9PtgWat-noHLkDuAhr1gAAAQ0"]
[Tue Jul 21 07:53:43.203983 2026] [security2:error] [pid 341679:tid 341902] [client 20.104.96.117:12497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/green1.php"] [unique_id "al9PtwWat-noHLkDuAhr2gAAAWc"]
[Tue Jul 21 07:53:43.237353 2026] [security2:error] [pid 341679:tid 341909] [client 173.252.95.26:55724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9PtwWat-noHLkDuAhr2wAAAW4"]
[Tue Jul 21 07:53:43.247907 2026] [security2:error] [pid 341679:tid 341906] [client 172.245.102.46:43703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PtwWat-noHLkDuAhr3AAAAWs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:53:43.432449 2026] [security2:error] [pid 341679:tid 341843] [client 20.226.60.151:56784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/acp.php"] [unique_id "al9PtwWat-noHLkDuAhr9wAAASw"]
[Tue Jul 21 07:53:43.552613 2026] [autoindex:error] [pid 341679:tid 341921] [client 43.130.110.130:42264] AH01276: Cannot serve directory /home2/ric83751/sanovitta.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:53:43.564768 2026] [security2:error] [pid 341679:tid 341897] [client 20.104.96.117:12749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/nc4.php"] [unique_id "al9PtwWat-noHLkDuAhsGwAAAWI"]
[Tue Jul 21 07:53:43.655117 2026] [security2:error] [pid 341679:tid 341837] [client 204.8.98.45:38832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9PtwWat-noHLkDuAhsHgAAASY"]
[Tue Jul 21 07:53:43.655207 2026] [security2:error] [pid 341679:tid 341837] [client 204.8.98.45:38832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9PtwWat-noHLkDuAhsHgAAASY"]
[Tue Jul 21 07:53:43.709576 2026] [security2:error] [pid 341679:tid 341821] [client 4.204.201.85:63201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/dr.php"] [unique_id "al9PtwWat-noHLkDuAhsIwAAARY"]
[Tue Jul 21 07:53:43.862357 2026] [security2:error] [pid 341679:tid 341862] [client 20.104.96.117:54996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/edorxrr.php"] [unique_id "al9PtwWat-noHLkDuAhsLQAAAT8"]
[Tue Jul 21 07:53:43.973195 2026] [security2:error] [pid 341679:tid 341877] [client 20.104.96.117:12648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/a1.php"] [unique_id "al9PtwWat-noHLkDuAhsNAAAAU4"]
[Tue Jul 21 07:53:44.241852 2026] [security2:error] [pid 341679:tid 341898] [client 4.204.201.85:48072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/x.php"] [unique_id "al9PuAWat-noHLkDuAhsUQAAAWM"]
[Tue Jul 21 07:53:44.265234 2026] [security2:error] [pid 341679:tid 341741] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PuAWat-noHLkDuAhsXQABhz0"]
[Tue Jul 21 07:53:44.265361 2026] [security2:error] [pid 341679:tid 341934] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PuAWat-noHLkDuAhsXQABhz0"]
[Tue Jul 21 07:53:44.278702 2026] [security2:error] [pid 341679:tid 341932] [client 20.104.96.117:12880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/eee.php"] [unique_id "al9PuAWat-noHLkDuAhsXwAAAYU"]
[Tue Jul 21 07:53:44.538776 2026] [security2:error] [pid 341679:tid 341885] [client 103.86.117.203:56424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PuAWat-noHLkDuAhsaQAAAVY"]
[Tue Jul 21 07:53:44.538894 2026] [security2:error] [pid 341679:tid 341885] [client 103.86.117.203:56424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PuAWat-noHLkDuAhsaQAAAVY"]
[Tue Jul 21 07:53:44.693175 2026] [security2:error] [pid 341679:tid 341850] [client 20.104.96.117:12752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/wp-aothait.php"] [unique_id "al9PuAWat-noHLkDuAhsdAAAATM"]
[Tue Jul 21 07:53:44.711427 2026] [security2:error] [pid 341679:tid 341854] [client 74.249.245.134:24776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/init.php"] [unique_id "al9PuAWat-noHLkDuAhsegAAATc"]
[Tue Jul 21 07:53:44.894133 2026] [security2:error] [pid 341679:tid 341759] [remote 167.71.218.184:56852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/xmlrpc.php"] [unique_id "al9PuAWat-noHLkDuAhsgQABNE8"]
[Tue Jul 21 07:53:44.894319 2026] [security2:error] [pid 341679:tid 341851] [client 167.71.218.184:56852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "supremaservices.net"] [uri "/xmlrpc.php"] [unique_id "al9PuAWat-noHLkDuAhsgQABNE8"]
[Tue Jul 21 07:53:45.028959 2026] [security2:error] [pid 341679:tid 341878] [client 4.204.201.85:63225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/155.php"] [unique_id "al9PuQWat-noHLkDuAhsjgAAAU8"]
[Tue Jul 21 07:53:45.042905 2026] [security2:error] [pid 341679:tid 341869] [client 20.104.96.117:12612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/config.json.php"] [unique_id "al9PuQWat-noHLkDuAhskAAAAUY"]
[Tue Jul 21 07:53:45.064903 2026] [security2:error] [pid 341679:tid 341781] [remote 97.74.93.24:46488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wp-login.php"] [unique_id "al9PuQWat-noHLkDuAhskgABg2U"]
[Tue Jul 21 07:53:45.144845 2026] [security2:error] [pid 341679:tid 341817] [client 204.8.98.45:35060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9PuQWat-noHLkDuAhskwAAARI"]
[Tue Jul 21 07:53:45.144963 2026] [security2:error] [pid 341679:tid 341817] [client 204.8.98.45:35060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9PuQWat-noHLkDuAhskwAAARI"]
[Tue Jul 21 07:53:45.227648 2026] [security2:error] [pid 341679:tid 341922] [client 122.164.127.47:59079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PuQWat-noHLkDuAhslAAAAXs"]
[Tue Jul 21 07:53:45.229879 2026] [security2:error] [pid 341679:tid 341922] [client 122.164.127.47:59079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PuQWat-noHLkDuAhslAAAAXs"]
[Tue Jul 21 07:53:45.255910 2026] [security2:error] [pid 341679:tid 341914] [client 20.206.105.145:55917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/adminner.php"] [unique_id "al9PuQWat-noHLkDuAhsmgAAAXM"]
[Tue Jul 21 07:53:45.341770 2026] [security2:error] [pid 341679:tid 341832] [client 4.204.201.85:63134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/ops.php"] [unique_id "al9PuQWat-noHLkDuAhsnQAAASE"]
[Tue Jul 21 07:53:45.360250 2026] [security2:error] [pid 341679:tid 341934] [client 20.104.96.117:12485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9PuQWat-noHLkDuAhsngAAAYc"]
[Tue Jul 21 07:53:45.375132 2026] [security2:error] [pid 341679:tid 341703] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PuQWat-noHLkDuAhsoQABiBc"]
[Tue Jul 21 07:53:45.375280 2026] [security2:error] [pid 341679:tid 341935] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PuQWat-noHLkDuAhsoQABiBc"]
[Tue Jul 21 07:53:45.381590 2026] [security2:error] [pid 341679:tid 341822] [client 41.68.90.219:53716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PuQWat-noHLkDuAhsowAAARc"]
[Tue Jul 21 07:53:45.382025 2026] [security2:error] [pid 341679:tid 341822] [client 41.68.90.219:53716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PuQWat-noHLkDuAhsowAAARc"]
[Tue Jul 21 07:53:45.412502 2026] [security2:error] [pid 341679:tid 341857] [client 37.140.223.150:47695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PuQWat-noHLkDuAhslQAAATo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:53:45.451877 2026] [security2:error] [pid 341679:tid 341896] [client 20.226.60.151:56757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/mosty.php"] [unique_id "al9PuQWat-noHLkDuAhsqAAAAWE"]
[Tue Jul 21 07:53:45.459641 2026] [security2:error] [pid 341679:tid 341802] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PuQWat-noHLkDuAhsqgABLno"]
[Tue Jul 21 07:53:45.459739 2026] [security2:error] [pid 341679:tid 341845] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PuQWat-noHLkDuAhsqgABLno"]
[Tue Jul 21 07:53:45.553847 2026] [security2:error] [pid 341679:tid 341841] [client 122.162.144.145:27053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PuQWat-noHLkDuAhsrQAAASo"]
[Tue Jul 21 07:53:45.553957 2026] [security2:error] [pid 341679:tid 341841] [client 122.162.144.145:27053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PuQWat-noHLkDuAhsrQAAASo"]
[Tue Jul 21 07:53:45.677074 2026] [security2:error] [pid 341679:tid 341880] [client 4.204.201.85:63175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/file31.php"] [unique_id "al9PuQWat-noHLkDuAhssgAAAVE"]
[Tue Jul 21 07:53:45.802318 2026] [security2:error] [pid 341679:tid 341842] [client 34.74.242.206:1701] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.premiumgrupo.com.br"] [uri "/robots.txt"] [unique_id "al9PuQWat-noHLkDuAhstQAAASs"]
[Tue Jul 21 07:53:45.802466 2026] [security2:error] [pid 341679:tid 341842] [client 34.74.242.206:1701] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.premiumgrupo.com.br"] [uri "/robots.txt"] [unique_id "al9PuQWat-noHLkDuAhstQAAASs"]
[Tue Jul 21 07:53:45.844740 2026] [security2:error] [pid 341679:tid 341818] [client 20.104.96.117:12536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/k2.php"] [unique_id "al9PuQWat-noHLkDuAhstgAAARM"]
[Tue Jul 21 07:53:45.849910 2026] [security2:error] [pid 341679:tid 341931] [client 65.111.20.214:57065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PuQWat-noHLkDuAhsswAAAYQ"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:53:45.856934 2026] [security2:error] [pid 341679:tid 341901] [client 173.252.95.21:58010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9PuQWat-noHLkDuAhstwAAAWY"]
[Tue Jul 21 07:53:46.039927 2026] [security2:error] [pid 341679:tid 341871] [client 34.74.242.206:1700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.premiumgrupo.com.br"] [uri "/"] [unique_id "al9PugWat-noHLkDuAhsvgAAAUg"]
[Tue Jul 21 07:53:46.040011 2026] [security2:error] [pid 341679:tid 341871] [client 34.74.242.206:1700] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.premiumgrupo.com.br"] [uri "/"] [unique_id "al9PugWat-noHLkDuAhsvgAAAUg"]
[Tue Jul 21 07:53:46.273509 2026] [security2:error] [pid 341679:tid 341859] [client 223.236.153.128:7410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PugWat-noHLkDuAhswwAAATw"]
[Tue Jul 21 07:53:46.273641 2026] [security2:error] [pid 341679:tid 341859] [client 223.236.153.128:7410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PugWat-noHLkDuAhswwAAATw"]
[Tue Jul 21 07:53:46.351253 2026] [security2:error] [pid 341679:tid 341924] [client 4.204.201.85:63167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/file6.php"] [unique_id "al9PugWat-noHLkDuAhsxAAAAX0"]
[Tue Jul 21 07:53:46.370181 2026] [security2:error] [pid 341679:tid 341909] [client 20.104.96.117:12738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9PugWat-noHLkDuAhsxQAAAW4"]
[Tue Jul 21 07:53:46.416828 2026] [security2:error] [pid 341679:tid 341686] [remote 103.187.169.251:43484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limaradiologiadigital.com.br"] [uri "/wp-login.php"] [unique_id "al9PugWat-noHLkDuAhsxgABMwY"]
[Tue Jul 21 07:53:46.495616 2026] [security2:error] [pid 341679:tid 341893] [client 178.153.91.96:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PugWat-noHLkDuAhsxwAAAV4"]
[Tue Jul 21 07:53:46.495771 2026] [security2:error] [pid 341679:tid 341893] [client 178.153.91.96:49282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PugWat-noHLkDuAhsxwAAAV4"]
[Tue Jul 21 07:53:46.549106 2026] [security2:error] [pid 341679:tid 341854] [client 103.166.103.129:42849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PugWat-noHLkDuAhszgAAATc"]
[Tue Jul 21 07:53:46.549610 2026] [security2:error] [pid 341679:tid 341854] [client 103.166.103.129:42849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PugWat-noHLkDuAhszgAAATc"]
[Tue Jul 21 07:53:46.789758 2026] [security2:error] [pid 341679:tid 341896] [client 20.104.96.117:12629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9PugWat-noHLkDuAhs0gAAAWE"]
[Tue Jul 21 07:53:46.814612 2026] [security2:error] [pid 341679:tid 341872] [client 20.226.60.151:53954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wp-info.php"] [unique_id "al9PugWat-noHLkDuAhs1AAAAUk"]
[Tue Jul 21 07:53:46.820946 2026] [security2:error] [pid 341679:tid 341903] [client 139.167.225.182:58970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PugWat-noHLkDuAhs1QAAAWg"]
[Tue Jul 21 07:53:46.821087 2026] [security2:error] [pid 341679:tid 341903] [client 139.167.225.182:58970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PugWat-noHLkDuAhs1QAAAWg"]
[Tue Jul 21 07:53:46.960852 2026] [security2:error] [pid 341679:tid 341820] [client 4.204.201.85:63189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/adminfuns.php"] [unique_id "al9PugWat-noHLkDuAhs2QAAARU"]
[Tue Jul 21 07:53:46.988312 2026] [security2:error] [pid 341679:tid 341841] [client 114.119.154.242:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.imobiliariasobrado.com.br"] [uri "/index.php/imovel/sobrado-geminado-3-quartos-com-garagem-17500m2-venda-boa-vista-joinville-sc-sr093"] [unique_id "al9PugWat-noHLkDuAhs2gAAASo"], referer: https://www.imobiliariasobrado.com.br/index.php/imovel/sobrado-geminado-3-quartos-com-garagem-17500m2-venda-boa-vista-joinville-sc-sr093?opcao=SR093&cd_empresa=8
[Tue Jul 21 07:53:47.045940 2026] [security2:error] [pid 341679:tid 341892] [client 20.206.105.145:55921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/admin.php"] [unique_id "al9PuwWat-noHLkDuAhs4wAAAV0"]
[Tue Jul 21 07:53:47.134791 2026] [security2:error] [pid 341679:tid 341838] [client 20.104.96.117:12504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9PuwWat-noHLkDuAhs5wAAASc"]
[Tue Jul 21 07:53:47.210071 2026] [security2:error] [pid 341679:tid 341832] [client 117.247.80.59:36038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PuwWat-noHLkDuAhs6AAAASE"]
[Tue Jul 21 07:53:47.210174 2026] [security2:error] [pid 341679:tid 341832] [client 117.247.80.59:36038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PuwWat-noHLkDuAhs6AAAASE"]
[Tue Jul 21 07:53:47.451115 2026] [authz_core:error] [pid 341679:tid 341882] [client 74.249.245.134:0] AH01630: client denied by server configuration: /home2/andr8586/public_html/php.ini
[Tue Jul 21 07:53:47.482955 2026] [autoindex:error] [pid 341679:tid 341869] [client 34.76.2.141:58032] AH01276: Cannot serve directory /home2/tropi058/loja.tropicaliaeyewear.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:53:47.492164 2026] [security2:error] [pid 341679:tid 341830] [client 117.217.38.194:49269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PuwWat-noHLkDuAhs9gAAAR8"]
[Tue Jul 21 07:53:47.492850 2026] [security2:error] [pid 341679:tid 341830] [client 117.217.38.194:49269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PuwWat-noHLkDuAhs9gAAAR8"]
[Tue Jul 21 07:53:47.552288 2026] [security2:error] [pid 341679:tid 341813] [client 173.24.185.52:54549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PuwWat-noHLkDuAhs-gAAAQ4"]
[Tue Jul 21 07:53:47.552391 2026] [security2:error] [pid 341679:tid 341813] [client 173.24.185.52:54549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PuwWat-noHLkDuAhs-gAAAQ4"]
[Tue Jul 21 07:53:47.562304 2026] [security2:error] [pid 341679:tid 341817] [client 20.104.96.117:12888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/for.php"] [unique_id "al9PuwWat-noHLkDuAhs-wAAARI"]
[Tue Jul 21 07:53:47.605894 2026] [security2:error] [pid 341679:tid 341922] [client 74.249.245.134:8791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/settings.php"] [unique_id "al9PuwWat-noHLkDuAhs_wAAAXs"]
[Tue Jul 21 07:53:47.648259 2026] [security2:error] [pid 341679:tid 341898] [client 20.226.60.151:50657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/6.php"] [unique_id "al9PuwWat-noHLkDuAhtAQAAAWM"]
[Tue Jul 21 07:53:47.759563 2026] [security2:error] [pid 341679:tid 341849] [client 103.78.200.11:62373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PuwWat-noHLkDuAhtAwAAATI"]
[Tue Jul 21 07:53:47.759746 2026] [security2:error] [pid 341679:tid 341849] [client 103.78.200.11:62373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PuwWat-noHLkDuAhtAwAAATI"]
[Tue Jul 21 07:53:47.797889 2026] [security2:error] [pid 341679:tid 341860] [client 4.204.201.85:63144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/goods.php"] [unique_id "al9PuwWat-noHLkDuAhtBAAAAT0"]
[Tue Jul 21 07:53:47.847013 2026] [security2:error] [pid 341679:tid 341863] [client 193.36.225.57:35133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PuwWat-noHLkDuAhtDAAAAUA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:53:47.930526 2026] [security2:error] [pid 341679:tid 341809] [client 20.104.96.117:12521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "exclusivaeventos.com.br"] [uri "/raw.php"] [unique_id "al9PuwWat-noHLkDuAhtDwAAAQo"]
[Tue Jul 21 07:53:47.991306 2026] [security2:error] [pid 341679:tid 341912] [client 20.220.225.223:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/ace2.php"] [unique_id "al9PuwWat-noHLkDuAhtEQAAAXE"]
[Tue Jul 21 07:53:48.129966 2026] [security2:error] [pid 341679:tid 341794] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PvAWat-noHLkDuAhtGAABHHI"]
[Tue Jul 21 07:53:48.130128 2026] [security2:error] [pid 341679:tid 341827] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PvAWat-noHLkDuAhtGAABHHI"]
[Tue Jul 21 07:53:48.236750 2026] [security2:error] [pid 341679:tid 341804] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PvAWat-noHLkDuAhtGQABUnw"]
[Tue Jul 21 07:53:48.236896 2026] [security2:error] [pid 341679:tid 341881] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PvAWat-noHLkDuAhtGQABUnw"]
[Tue Jul 21 07:53:48.251029 2026] [autoindex:error] [pid 341679:tid 341862] [client 43.130.72.177:60124] AH01276: Cannot serve directory /home2/lari0640/lararmstore.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:53:48.295487 2026] [security2:error] [pid 341679:tid 341894] [client 185.242.177.19:34146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "barcob.com"] [uri "/"] [unique_id "al9PvAWat-noHLkDuAhtHAAAAV8"]
[Tue Jul 21 07:53:48.467107 2026] [security2:error] [pid 341679:tid 341832] [client 4.204.201.85:63131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/100.php"] [unique_id "al9PvAWat-noHLkDuAhtHQAAASE"]
[Tue Jul 21 07:53:48.529537 2026] [security2:error] [pid 341679:tid 341716] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PvAWat-noHLkDuAhtIAABLyQ"]
[Tue Jul 21 07:53:48.529709 2026] [security2:error] [pid 341679:tid 341846] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PvAWat-noHLkDuAhtIAABLyQ"]
[Tue Jul 21 07:53:48.826176 2026] [security2:error] [pid 341679:tid 341922] [client 74.249.245.134:65124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/up.php"] [unique_id "al9PvAWat-noHLkDuAhtLQAAAXs"]
[Tue Jul 21 07:53:48.839323 2026] [security2:error] [pid 341679:tid 341898] [client 92.119.178.3:58518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9PvAWat-noHLkDuAhtLgAAAWM"]
[Tue Jul 21 07:53:48.839410 2026] [security2:error] [pid 341679:tid 341898] [client 92.119.178.3:58518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9PvAWat-noHLkDuAhtLgAAAWM"]
[Tue Jul 21 07:53:48.885635 2026] [security2:error] [pid 341679:tid 341915] [client 114.119.157.4:41173] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "startonesite.com.br"] [uri "/9613txoids-23wx75241"] [unique_id "al9PvAWat-noHLkDuAhtMQAAAXQ"], referer: https://startonesite.com.br/9613txoids-23wx75241
[Tue Jul 21 07:53:48.902752 2026] [security2:error] [pid 341679:tid 341838] [client 122.186.204.214:58184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PvAWat-noHLkDuAhtMgAAASc"]
[Tue Jul 21 07:53:48.902882 2026] [security2:error] [pid 341679:tid 341838] [client 122.186.204.214:58184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PvAWat-noHLkDuAhtMgAAASc"]
[Tue Jul 21 07:53:49.276102 2026] [security2:error] [pid 341679:tid 341912] [client 20.226.60.151:61536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/2000.php"] [unique_id "al9PvQWat-noHLkDuAhtPgAAAXE"]
[Tue Jul 21 07:53:49.308242 2026] [security2:error] [pid 341679:tid 341931] [client 20.226.60.151:56778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/32e17094cfindex.php"] [unique_id "al9PvQWat-noHLkDuAhtQAAAAYQ"]
[Tue Jul 21 07:53:49.346574 2026] [security2:error] [pid 341679:tid 341831] [client 4.204.201.85:63108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/about.php"] [unique_id "al9PvQWat-noHLkDuAhtQQAAASA"]
[Tue Jul 21 07:53:49.394156 2026] [security2:error] [pid 341679:tid 341713] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PvQWat-noHLkDuAhtQgABWiE"]
[Tue Jul 21 07:53:49.394336 2026] [security2:error] [pid 341679:tid 341889] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PvQWat-noHLkDuAhtQgABWiE"]
[Tue Jul 21 07:53:49.408283 2026] [security2:error] [pid 341679:tid 341895] [client 103.29.114.44:41062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PvQWat-noHLkDuAhtQwAAAWA"]
[Tue Jul 21 07:53:49.408419 2026] [security2:error] [pid 341679:tid 341895] [client 103.29.114.44:41062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PvQWat-noHLkDuAhtQwAAAWA"]
[Tue Jul 21 07:53:49.466727 2026] [security2:error] [pid 341679:tid 341726] [remote 182.77.62.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/wp-login.php"] [unique_id "al9PvQWat-noHLkDuAhtRAABMS4"]
[Tue Jul 21 07:53:49.536383 2026] [security2:error] [pid 341679:tid 341852] [client 202.143.127.214:62744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PvQWat-noHLkDuAhtRgAAATU"]
[Tue Jul 21 07:53:49.536531 2026] [security2:error] [pid 341679:tid 341852] [client 202.143.127.214:62744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PvQWat-noHLkDuAhtRgAAATU"]
[Tue Jul 21 07:53:49.644980 2026] [security2:error] [pid 341679:tid 341905] [client 109.60.28.94:33911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PvQWat-noHLkDuAhtRwAAAWo"]
[Tue Jul 21 07:53:49.645097 2026] [security2:error] [pid 341679:tid 341905] [client 109.60.28.94:33911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PvQWat-noHLkDuAhtRwAAAWo"]
[Tue Jul 21 07:53:49.676660 2026] [security2:error] [pid 341679:tid 341739] [remote 62.60.130.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "onlinebuyerwebsite.com"] [uri "/"] [unique_id "al9PvQWat-noHLkDuAhtSgABVjs"]
[Tue Jul 21 07:53:49.838669 2026] [security2:error] [pid 341679:tid 341856] [client 114.119.147.181:21039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "northcomm.com.br"] [uri "/wp-includes/css/dist/list-reusable-blocks/style-rtl.css"] [unique_id "al9PvQWat-noHLkDuAhtVAAAATk"], referer: https://northcomm.com.br/wp-includes/css/dist/list-reusable-blocks/
[Tue Jul 21 07:53:49.872431 2026] [security2:error] [pid 341679:tid 341908] [client 4.204.201.85:63209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/about.php"] [unique_id "al9PvQWat-noHLkDuAhtVgAAAW0"]
[Tue Jul 21 07:53:49.952476 2026] [security2:error] [pid 341679:tid 341727] [remote 62.60.130.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "onlinebuyerwebsite.com"] [uri "/wp-json/batch/v1"] [unique_id "al9PvQWat-noHLkDuAhtWQABIy8"]
[Tue Jul 21 07:53:50.095257 2026] [security2:error] [pid 341679:tid 341691] [remote 104.207.32.53:56751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.32.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9PvQWat-noHLkDuAhtWAABWAs"]
[Tue Jul 21 07:53:50.240720 2026] [security2:error] [pid 341679:tid 341844] [client 4.204.201.85:63212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/admin.php"] [unique_id "al9PvgWat-noHLkDuAhtZAAAAS0"]
[Tue Jul 21 07:53:50.279786 2026] [security2:error] [pid 341679:tid 341883] [client 106.215.181.8:15978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PvgWat-noHLkDuAhtZwAAAVQ"]
[Tue Jul 21 07:53:50.279896 2026] [security2:error] [pid 341679:tid 341883] [client 106.215.181.8:15978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PvgWat-noHLkDuAhtZwAAAVQ"]
[Tue Jul 21 07:53:50.435648 2026] [security2:error] [pid 341679:tid 341842] [client 20.206.105.145:55918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/k.php"] [unique_id "al9PvgWat-noHLkDuAhtagAAASs"]
[Tue Jul 21 07:53:50.515955 2026] [security2:error] [pid 341679:tid 341821] [client 74.249.245.134:65127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/66.php"] [unique_id "al9PvgWat-noHLkDuAhtawAAARY"]
[Tue Jul 21 07:53:50.741149 2026] [security2:error] [pid 341679:tid 341862] [client 4.204.201.85:63118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/admin.php"] [unique_id "al9PvgWat-noHLkDuAhtdQAAAT8"]
[Tue Jul 21 07:53:50.867865 2026] [security2:error] [pid 341679:tid 341812] [client 92.119.178.3:58536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PvgWat-noHLkDuAhtfwAAAQ0"]
[Tue Jul 21 07:53:50.867966 2026] [security2:error] [pid 341679:tid 341812] [client 92.119.178.3:58536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9PvgWat-noHLkDuAhtfwAAAQ0"]
[Tue Jul 21 07:53:51.040718 2026] [security2:error] [pid 341679:tid 341856] [client 20.226.60.151:56751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/qqqa.php"] [unique_id "al9PvwWat-noHLkDuAhtgQAAATk"]
[Tue Jul 21 07:53:51.120003 2026] [security2:error] [pid 341679:tid 341908] [client 4.204.201.85:63130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/themes.php"] [unique_id "al9PvwWat-noHLkDuAhtgwAAAW0"]
[Tue Jul 21 07:53:51.246232 2026] [security2:error] [pid 341679:tid 341827] [client 20.220.225.223:19662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/aa1.php"] [unique_id "al9PvwWat-noHLkDuAhthgAAARw"]
[Tue Jul 21 07:53:51.317295 2026] [security2:error] [pid 341679:tid 341766] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PvwWat-noHLkDuAhtjQABL1Y"]
[Tue Jul 21 07:53:51.317488 2026] [security2:error] [pid 341679:tid 341846] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PvwWat-noHLkDuAhtjQABL1Y"]
[Tue Jul 21 07:53:51.612655 2026] [security2:error] [pid 341679:tid 341838] [client 91.92.47.101:42258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/config.php"] [unique_id "al9PvwWat-noHLkDuAhtlAAAASc"], referer: http://sigmas.app.br/
[Tue Jul 21 07:53:51.805317 2026] [security2:error] [pid 341679:tid 341845] [client 4.204.201.85:63135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/.well-known/about.php"] [unique_id "al9PvwWat-noHLkDuAhtnAAAAS4"]
[Tue Jul 21 07:53:51.861446 2026] [security2:error] [pid 341679:tid 341913] [client 91.92.47.101:42272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/info.php"] [unique_id "al9PvwWat-noHLkDuAhtoQAAAXI"], referer: http://sigmas.app.br/
[Tue Jul 21 07:53:51.874114 2026] [security2:error] [pid 341679:tid 341912] [client 91.92.47.101:42284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sigmas.app.br"] [uri "/.env"] [unique_id "al9PvwWat-noHLkDuAhtogAAAXE"], referer: http://sigmas.app.br/
[Tue Jul 21 07:53:51.948879 2026] [security2:error] [pid 341679:tid 341866] [client 182.8.255.181:17338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PvwWat-noHLkDuAhtpAAAAUM"]
[Tue Jul 21 07:53:51.949029 2026] [security2:error] [pid 341679:tid 341866] [client 182.8.255.181:17338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PvwWat-noHLkDuAhtpAAAAUM"]
[Tue Jul 21 07:53:51.951811 2026] [security2:error] [pid 341679:tid 341853] [client 91.92.47.101:42314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/wp-config.php"] [unique_id "al9PvwWat-noHLkDuAhtpQAAATY"], referer: http://sigmas.app.br/
[Tue Jul 21 07:53:51.952894 2026] [security2:error] [pid 341679:tid 341842] [client 91.92.47.101:42306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/phpinfo.php"] [unique_id "al9PvwWat-noHLkDuAhtpwAAASs"], referer: http://sigmas.app.br/
[Tue Jul 21 07:53:52.024762 2026] [security2:error] [pid 341679:tid 341926] [client 20.104.96.117:55028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/miru1.php"] [unique_id "al9PwAWat-noHLkDuAhtqQAAAX8"]
[Tue Jul 21 07:53:52.067218 2026] [security2:error] [pid 341679:tid 341797] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PwAWat-noHLkDuAhtqwABOnU"]
[Tue Jul 21 07:53:52.067402 2026] [security2:error] [pid 341679:tid 341857] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PwAWat-noHLkDuAhtqwABOnU"]
[Tue Jul 21 07:53:52.123493 2026] [security2:error] [pid 341679:tid 341848] [client 4.204.201.85:63143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9PwAWat-noHLkDuAhtrQAAATE"]
[Tue Jul 21 07:53:52.394040 2026] [security2:error] [pid 341679:tid 341935] [client 136.144.33.109:34195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PwAWat-noHLkDuAhtsgAAAYg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:53:52.426965 2026] [security2:error] [pid 341679:tid 341908] [client 4.204.201.85:63146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wefile.php"] [unique_id "al9PwAWat-noHLkDuAhtuwAAAW0"]
[Tue Jul 21 07:53:52.670414 2026] [security2:error] [pid 341679:tid 341897] [client 20.226.60.151:61543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/122.php"] [unique_id "al9PwAWat-noHLkDuAhtvQAAAWI"]
[Tue Jul 21 07:53:52.732905 2026] [security2:error] [pid 341679:tid 341894] [client 74.249.245.134:64192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/666.php"] [unique_id "al9PwAWat-noHLkDuAhtvgAAAV8"]
[Tue Jul 21 07:53:52.745154 2026] [security2:error] [pid 341679:tid 341887] [client 4.204.201.85:63199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9PwAWat-noHLkDuAhtvwAAAVg"]
[Tue Jul 21 07:53:52.922931 2026] [security2:error] [pid 341679:tid 341850] [client 20.226.60.151:61508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/mds.php"] [unique_id "al9PwAWat-noHLkDuAhtxwAAATM"]
[Tue Jul 21 07:53:52.956091 2026] [security2:error] [pid 341679:tid 341879] [client 102.206.115.33:65520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9PwAWat-noHLkDuAhtyAAAAVA"]
[Tue Jul 21 07:53:52.956246 2026] [security2:error] [pid 341679:tid 341879] [client 102.206.115.33:65520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9PwAWat-noHLkDuAhtyAAAAVA"]
[Tue Jul 21 07:53:53.063274 2026] [security2:error] [pid 341679:tid 341876] [client 74.249.245.134:64424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/g.php"] [unique_id "al9PwQWat-noHLkDuAhtygAAAU0"]
[Tue Jul 21 07:53:53.129854 2026] [security2:error] [pid 341679:tid 341841] [client 122.179.91.63:6852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PwQWat-noHLkDuAhtzQAAASo"]
[Tue Jul 21 07:53:53.129974 2026] [security2:error] [pid 341679:tid 341841] [client 122.179.91.63:6852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PwQWat-noHLkDuAhtzQAAASo"]
[Tue Jul 21 07:53:53.171609 2026] [security2:error] [pid 341679:tid 341845] [client 20.226.60.151:56713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/aunmc.php"] [unique_id "al9PwQWat-noHLkDuAhtzgAAAS4"]
[Tue Jul 21 07:53:53.346775 2026] [security2:error] [pid 341679:tid 341930] [client 122.164.127.47:59659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PwQWat-noHLkDuAht0gAAAYM"]
[Tue Jul 21 07:53:53.346917 2026] [security2:error] [pid 341679:tid 341930] [client 122.164.127.47:59659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PwQWat-noHLkDuAht0gAAAYM"]
[Tue Jul 21 07:53:53.575781 2026] [security2:error] [pid 341679:tid 341842] [client 20.220.225.223:19311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/acew67.php"] [unique_id "al9PwQWat-noHLkDuAht2AAAASs"]
[Tue Jul 21 07:53:53.595108 2026] [security2:error] [pid 341679:tid 341902] [client 20.226.60.151:61604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wp-blink.php"] [unique_id "al9PwQWat-noHLkDuAht2gAAAWc"]
[Tue Jul 21 07:53:53.709014 2026] [security2:error] [pid 341679:tid 341933] [client 74.7.230.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rogeriomenezessoares1749232133269.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9PwQWat-noHLkDuAht3wABhmg"]
[Tue Jul 21 07:53:53.782183 2026] [security2:error] [pid 341679:tid 341819] [client 4.204.201.85:63164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9PwQWat-noHLkDuAht4AAAARQ"]
[Tue Jul 21 07:53:54.630983 2026] [security2:error] [pid 341679:tid 341910] [client 4.204.201.85:63113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/8.php"] [unique_id "al9PwgWat-noHLkDuAht-gAAAW8"]
[Tue Jul 21 07:53:54.800669 2026] [security2:error] [pid 341679:tid 341711] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PwgWat-noHLkDuAhuAAABKh8"]
[Tue Jul 21 07:53:54.800879 2026] [security2:error] [pid 341679:tid 341841] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PwgWat-noHLkDuAhuAAABKh8"]
[Tue Jul 21 07:53:55.014537 2026] [security2:error] [pid 341679:tid 341834] [client 103.86.117.203:56975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PwwWat-noHLkDuAhuCgAAASM"]
[Tue Jul 21 07:53:55.014686 2026] [security2:error] [pid 341679:tid 341834] [client 103.86.117.203:56975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PwwWat-noHLkDuAhuCgAAASM"]
[Tue Jul 21 07:53:55.036196 2026] [security2:error] [pid 341679:tid 341898] [client 4.204.201.85:63204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9PwwWat-noHLkDuAhuDAAAAWM"]
[Tue Jul 21 07:53:55.435000 2026] [security2:error] [pid 341679:tid 341923] [client 20.206.105.145:55900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/x.php"] [unique_id "al9PwwWat-noHLkDuAhuGwAAAXw"]
[Tue Jul 21 07:53:55.523144 2026] [security2:error] [pid 341679:tid 341871] [client 4.204.201.85:63194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/f6.php"] [unique_id "al9PwwWat-noHLkDuAhuIgAAAUg"]
[Tue Jul 21 07:53:55.571469 2026] [security2:error] [pid 341679:tid 341814] [client 74.249.245.134:24785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/byp.php"] [unique_id "al9PwwWat-noHLkDuAhuKAAAAQ8"]
[Tue Jul 21 07:53:55.687284 2026] [security2:error] [pid 341679:tid 341850] [client 74.249.245.134:64413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/403.php"] [unique_id "al9PwwWat-noHLkDuAhuLAAAATM"]
[Tue Jul 21 07:53:55.852588 2026] [security2:error] [pid 341679:tid 341811] [client 4.204.201.85:63106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/inputs.php"] [unique_id "al9PwwWat-noHLkDuAhuMAAAAQw"]
[Tue Jul 21 07:53:55.915077 2026] [security2:error] [pid 341679:tid 341708] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PwwWat-noHLkDuAhuNQABWRw"]
[Tue Jul 21 07:53:55.915263 2026] [security2:error] [pid 341679:tid 341888] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PwwWat-noHLkDuAhuNQABWRw"]
[Tue Jul 21 07:53:55.920586 2026] [security2:error] [pid 341679:tid 341833] [client 20.206.105.145:55837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wss.php"] [unique_id "al9PwwWat-noHLkDuAhuOgAAASI"]
[Tue Jul 21 07:53:55.947445 2026] [security2:error] [pid 341679:tid 341854] [client 114.119.133.146:52347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oticapersona.com.br"] [uri "/produto/oculos-platini-8065/"] [unique_id "al9PwwWat-noHLkDuAhuPAAAATc"], referer: https://oticapersona.com.br/produtos/page/5/
[Tue Jul 21 07:53:56.051140 2026] [security2:error] [pid 341679:tid 341816] [client 193.36.225.64:21967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PxAWat-noHLkDuAhuPwAAARE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:53:56.179686 2026] [security2:error] [pid 341679:tid 341882] [client 41.68.90.219:54167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxAWat-noHLkDuAhuSwAAAVM"]
[Tue Jul 21 07:53:56.180970 2026] [security2:error] [pid 341679:tid 341882] [client 41.68.90.219:54167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxAWat-noHLkDuAhuSwAAAVM"]
[Tue Jul 21 07:53:56.337206 2026] [security2:error] [pid 341679:tid 341910] [client 122.162.144.145:29937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PxAWat-noHLkDuAhuTwAAAW8"]
[Tue Jul 21 07:53:56.337333 2026] [security2:error] [pid 341679:tid 341910] [client 122.162.144.145:29937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PxAWat-noHLkDuAhuTwAAAW8"]
[Tue Jul 21 07:53:56.383288 2026] [security2:error] [pid 341679:tid 341923] [client 4.204.201.85:63136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/inputs.php"] [unique_id "al9PxAWat-noHLkDuAhuUgAAAXw"]
[Tue Jul 21 07:53:56.493060 2026] [security2:error] [pid 341679:tid 341747] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxAWat-noHLkDuAhuVgABbUM"]
[Tue Jul 21 07:53:56.493230 2026] [security2:error] [pid 341679:tid 341908] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxAWat-noHLkDuAhuVgABbUM"]
[Tue Jul 21 07:53:56.600942 2026] [security2:error] [pid 341679:tid 341814] [client 20.220.225.223:31740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.limaradiologiadigital.com.br"] [uri "/ms.php"] [unique_id "al9PxAWat-noHLkDuAhuXAAAAQ8"]
[Tue Jul 21 07:53:56.811035 2026] [security2:error] [pid 341679:tid 341930] [client 4.204.201.85:63129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/classwithtostring.php"] [unique_id "al9PxAWat-noHLkDuAhuZAAAAYM"]
[Tue Jul 21 07:53:56.884232 2026] [security2:error] [pid 341679:tid 341912] [client 20.226.60.151:56720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/uoocf.php"] [unique_id "al9PxAWat-noHLkDuAhubgAAAXE"]
[Tue Jul 21 07:53:56.890913 2026] [access_compat:error] [pid 341679:tid 341858] [client 162.241.63.68:45348] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:53:56.969551 2026] [security2:error] [pid 341679:tid 341699] [remote 132.148.72.88:57150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PxAWat-noHLkDuAhucwABfRM"]
[Tue Jul 21 07:53:56.973523 2026] [security2:error] [pid 341679:tid 341921] [client 223.236.153.128:7086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PxAWat-noHLkDuAhudgAAAXo"]
[Tue Jul 21 07:53:56.973612 2026] [security2:error] [pid 341679:tid 341921] [client 223.236.153.128:7086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PxAWat-noHLkDuAhudgAAAXo"]
[Tue Jul 21 07:53:57.123418 2026] [security2:error] [pid 341679:tid 341897] [client 178.153.91.96:50991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PxQWat-noHLkDuAhuggAAAWI"]
[Tue Jul 21 07:53:57.123579 2026] [security2:error] [pid 341679:tid 341897] [client 178.153.91.96:50991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PxQWat-noHLkDuAhuggAAAWI"]
[Tue Jul 21 07:53:57.281140 2026] [security2:error] [pid 341679:tid 341845] [client 20.226.60.151:50677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/iywwi.php"] [unique_id "al9PxQWat-noHLkDuAhuhwAAAS4"]
[Tue Jul 21 07:53:57.315910 2026] [security2:error] [pid 341679:tid 341817] [client 103.166.103.129:43415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PxQWat-noHLkDuAhuiAAAARI"]
[Tue Jul 21 07:53:57.316105 2026] [security2:error] [pid 341679:tid 341817] [client 103.166.103.129:43415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9PxQWat-noHLkDuAhuiAAAARI"]
[Tue Jul 21 07:53:57.348950 2026] [security2:error] [pid 341679:tid 341871] [client 4.204.201.85:63138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9PxQWat-noHLkDuAhuiwAAAUg"]
[Tue Jul 21 07:53:57.383670 2026] [security2:error] [pid 341679:tid 341763] [remote 45.117.83.212:59988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9PxQWat-noHLkDuAhujAABVFM"]
[Tue Jul 21 07:53:57.389026 2026] [security2:error] [pid 341679:tid 341685] [remote 74.208.58.20:43388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.58.208.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9PxQWat-noHLkDuAhuhQABSwU"]
[Tue Jul 21 07:53:57.411806 2026] [security2:error] [pid 341679:tid 341814] [client 20.226.60.151:56754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/gqgsa.php"] [unique_id "al9PxQWat-noHLkDuAhujgAAAQ8"]
[Tue Jul 21 07:53:57.444455 2026] [security2:error] [pid 341679:tid 341851] [client 139.167.225.182:59625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxQWat-noHLkDuAhukgAAATQ"]
[Tue Jul 21 07:53:57.444551 2026] [security2:error] [pid 341679:tid 341851] [client 139.167.225.182:59625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxQWat-noHLkDuAhukgAAATQ"]
[Tue Jul 21 07:53:57.455085 2026] [security2:error] [pid 341679:tid 341831] [client 104.207.34.237:50767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.34.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PxAWat-noHLkDuAhuTAAAASA"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:53:57.544007 2026] [security2:error] [pid 341679:tid 341913] [client 20.226.60.151:56729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/elbzl.php"] [unique_id "al9PxQWat-noHLkDuAhulwAAAXI"]
[Tue Jul 21 07:53:57.702028 2026] [security2:error] [pid 341679:tid 341833] [client 20.226.60.151:56742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/adjig.php"] [unique_id "al9PxQWat-noHLkDuAhunQAAASI"]
[Tue Jul 21 07:53:57.728585 2026] [security2:error] [pid 341679:tid 341931] [client 117.247.80.59:1139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxQWat-noHLkDuAhungAAAYQ"]
[Tue Jul 21 07:53:57.728687 2026] [security2:error] [pid 341679:tid 341931] [client 117.247.80.59:1139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxQWat-noHLkDuAhungAAAYQ"]
[Tue Jul 21 07:53:57.777242 2026] [security2:error] [pid 341679:tid 341924] [client 4.204.201.85:48111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wp-blog.php"] [unique_id "al9PxQWat-noHLkDuAhunwAAAX0"]
[Tue Jul 21 07:53:57.989099 2026] [security2:error] [pid 341679:tid 341862] [client 117.217.38.194:49798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxQWat-noHLkDuAhupgAAAT8"]
[Tue Jul 21 07:53:57.989386 2026] [security2:error] [pid 341679:tid 341862] [client 117.217.38.194:49798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxQWat-noHLkDuAhupgAAAT8"]
[Tue Jul 21 07:53:58.186700 2026] [security2:error] [pid 341679:tid 341859] [client 173.24.185.52:55030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PxgWat-noHLkDuAhurgAAATw"]
[Tue Jul 21 07:53:58.186830 2026] [security2:error] [pid 341679:tid 341859] [client 173.24.185.52:55030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9PxgWat-noHLkDuAhurgAAATw"]
[Tue Jul 21 07:53:58.532987 2026] [security2:error] [pid 341679:tid 341821] [client 103.78.200.11:62827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxgWat-noHLkDuAhuxQAAARY"]
[Tue Jul 21 07:53:58.533073 2026] [security2:error] [pid 341679:tid 341821] [client 103.78.200.11:62827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxgWat-noHLkDuAhuxQAAARY"]
[Tue Jul 21 07:53:58.606531 2026] [security2:error] [pid 341679:tid 341782] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxgWat-noHLkDuAhuyAABWmY"]
[Tue Jul 21 07:53:58.606663 2026] [security2:error] [pid 341679:tid 341889] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxgWat-noHLkDuAhuyAABWmY"]
[Tue Jul 21 07:53:58.640502 2026] [security2:error] [pid 341679:tid 341880] [client 4.204.201.85:48004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9PxgWat-noHLkDuAhuygAAAVE"]
[Tue Jul 21 07:53:58.704646 2026] [security2:error] [pid 341679:tid 341811] [client 74.249.245.134:64389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/api.php"] [unique_id "al9PxgWat-noHLkDuAhu0QAAAQw"]
[Tue Jul 21 07:53:58.755401 2026] [security2:error] [pid 341679:tid 341784] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxgWat-noHLkDuAhu0wABcmg"]
[Tue Jul 21 07:53:58.755507 2026] [security2:error] [pid 341679:tid 341913] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxgWat-noHLkDuAhu0wABcmg"]
[Tue Jul 21 07:53:58.932698 2026] [security2:error] [pid 341679:tid 341836] [client 4.204.201.85:63177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/ms-edit.php"] [unique_id "al9PxgWat-noHLkDuAhu1wAAASU"]
[Tue Jul 21 07:53:59.066121 2026] [security2:error] [pid 341679:tid 341876] [client 104.207.57.89:28083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9PxgWat-noHLkDuAhu1gAAAU0"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:53:59.085988 2026] [security2:error] [pid 341679:tid 341852] [client 114.119.131.181:31347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gradiente.com"] [uri "/site/produtos/view.asp"] [unique_id "al9PxwWat-noHLkDuAhu4QAAATU"], referer: https://www.videohelp.com/dvdplayers/gradiente-d-204/8701
[Tue Jul 21 07:53:59.223749 2026] [security2:error] [pid 341679:tid 341777] [remote 17.246.19.228:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.19.246.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "liranesuliano.com.br"] [uri "/wp-content/plugins/litespeed-cache/guest.vary.php"] [unique_id "al9PxQWat-noHLkDuAhufgABb2E"], referer: https://liranesuliano.com.br/o-que-e-auriculoterapia-neurofisiologica/
[Tue Jul 21 07:53:59.226837 2026] [security2:error] [pid 341679:tid 341698] [remote 209.97.182.179:51396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/wp-login.php"] [unique_id "al9PxwWat-noHLkDuAhu8gABdRI"]
[Tue Jul 21 07:53:59.369440 2026] [security2:error] [pid 341679:tid 341868] [client 4.204.201.85:63219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9PxwWat-noHLkDuAhu9gAAAUU"]
[Tue Jul 21 07:53:59.605845 2026] [security2:error] [pid 341679:tid 341853] [client 122.186.204.214:58718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PxwWat-noHLkDuAhu_wAAATY"]
[Tue Jul 21 07:53:59.605937 2026] [security2:error] [pid 341679:tid 341853] [client 122.186.204.214:58718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PxwWat-noHLkDuAhu_wAAATY"]
[Tue Jul 21 07:53:59.656448 2026] [security2:error] [pid 341679:tid 341704] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PxwWat-noHLkDuAhvCwABMxg"]
[Tue Jul 21 07:53:59.656582 2026] [security2:error] [pid 341679:tid 341850] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9PxwWat-noHLkDuAhvCwABMxg"]
[Tue Jul 21 07:53:59.897638 2026] [security2:error] [pid 341679:tid 341888] [client 4.204.201.85:63188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9PxwWat-noHLkDuAhvFwAAAVk"]
[Tue Jul 21 07:53:59.901766 2026] [security2:error] [pid 341679:tid 341903] [client 114.119.148.60:41275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jandel.com.br"] [uri "/ldwy6t6/warriors-ownership-percentages"] [unique_id "al9PxwWat-noHLkDuAhvGAAAAWg"], referer: https://jandel.com.br/ldwy6t6/warriors-ownership-percentages
[Tue Jul 21 07:53:59.990024 2026] [security2:error] [pid 341679:tid 341901] [client 103.29.114.44:13939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxwWat-noHLkDuAhvGwAAAWY"]
[Tue Jul 21 07:53:59.990135 2026] [security2:error] [pid 341679:tid 341901] [client 103.29.114.44:13939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PxwWat-noHLkDuAhvGwAAAWY"]
[Tue Jul 21 07:54:00.487402 2026] [security2:error] [pid 341679:tid 341911] [client 202.143.127.214:63229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PyAWat-noHLkDuAhvKgAAAXA"]
[Tue Jul 21 07:54:00.487534 2026] [security2:error] [pid 341679:tid 341911] [client 202.143.127.214:63229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PyAWat-noHLkDuAhvKgAAAXA"]
[Tue Jul 21 07:54:00.583008 2026] [security2:error] [pid 341679:tid 341812] [client 4.204.201.85:63190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/abcd.php"] [unique_id "al9PyAWat-noHLkDuAhvLAAAAQ0"]
[Tue Jul 21 07:54:00.621278 2026] [security2:error] [pid 341679:tid 341849] [client 109.60.28.94:34361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PyAWat-noHLkDuAhvLQAAATI"]
[Tue Jul 21 07:54:00.621420 2026] [security2:error] [pid 341679:tid 341849] [client 109.60.28.94:34361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PyAWat-noHLkDuAhvLQAAATI"]
[Tue Jul 21 07:54:00.671588 2026] [security2:error] [pid 341679:tid 341916] [client 20.104.96.117:57782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/sump1.php"] [unique_id "al9PyAWat-noHLkDuAhvMQAAAXU"]
[Tue Jul 21 07:54:00.677569 2026] [security2:error] [pid 341679:tid 341779] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PyAWat-noHLkDuAhvMgABX2M"]
[Tue Jul 21 07:54:00.677750 2026] [security2:error] [pid 341679:tid 341894] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PyAWat-noHLkDuAhvMgABX2M"]
[Tue Jul 21 07:54:00.721527 2026] [security2:error] [pid 341679:tid 341858] [client 106.215.181.8:8654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PyAWat-noHLkDuAhvNgAAATs"]
[Tue Jul 21 07:54:00.721666 2026] [security2:error] [pid 341679:tid 341858] [client 106.215.181.8:8654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PyAWat-noHLkDuAhvNgAAATs"]
[Tue Jul 21 07:54:00.965971 2026] [security2:error] [pid 341679:tid 341832] [client 92.119.178.3:58548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9PyAWat-noHLkDuAhvPQAAASE"]
[Tue Jul 21 07:54:00.966050 2026] [security2:error] [pid 341679:tid 341832] [client 92.119.178.3:58548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9PyAWat-noHLkDuAhvPQAAASE"]
[Tue Jul 21 07:54:01.058138 2026] [security2:error] [pid 341679:tid 341853] [client 204.8.98.45:39790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PyQWat-noHLkDuAhvPgAAATY"]
[Tue Jul 21 07:54:01.058215 2026] [security2:error] [pid 341679:tid 341853] [client 204.8.98.45:39790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9PyQWat-noHLkDuAhvPgAAATY"]
[Tue Jul 21 07:54:01.151723 2026] [security2:error] [pid 341679:tid 341912] [client 136.144.33.53:40341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9PxwWat-noHLkDuAhvGgAAAXE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:01.162613 2026] [security2:error] [pid 341679:tid 341850] [client 198.54.128.138:49362] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9PyQWat-noHLkDuAhvQAAAATM"]
[Tue Jul 21 07:54:01.162701 2026] [security2:error] [pid 341679:tid 341850] [client 198.54.128.138:49362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9PyQWat-noHLkDuAhvQAAAATM"]
[Tue Jul 21 07:54:01.234709 2026] [security2:error] [pid 341679:tid 341874] [client 4.204.201.85:63196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/file15.php"] [unique_id "al9PyQWat-noHLkDuAhvRAAAAUs"]
[Tue Jul 21 07:54:01.660124 2026] [security2:error] [pid 341679:tid 341847] [client 20.226.60.151:50686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/byp.php"] [unique_id "al9PyQWat-noHLkDuAhvTAAAATA"]
[Tue Jul 21 07:54:01.703252 2026] [security2:error] [pid 341679:tid 341902] [client 4.204.201.85:63149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/jp.php"] [unique_id "al9PyQWat-noHLkDuAhvUAAAAWc"]
[Tue Jul 21 07:54:01.912466 2026] [security2:error] [pid 341679:tid 341743] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PyQWat-noHLkDuAhvVgABej8"]
[Tue Jul 21 07:54:01.912591 2026] [security2:error] [pid 341679:tid 341921] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9PyQWat-noHLkDuAhvVgABej8"]
[Tue Jul 21 07:54:02.040798 2026] [security2:error] [pid 341679:tid 341893] [client 122.179.91.63:30697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PygWat-noHLkDuAhvWQAAAV4"]
[Tue Jul 21 07:54:02.040993 2026] [security2:error] [pid 341679:tid 341893] [client 122.179.91.63:30697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9PygWat-noHLkDuAhvWQAAAV4"]
[Tue Jul 21 07:54:02.344174 2026] [security2:error] [pid 341679:tid 341819] [client 4.204.201.85:63200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/f35.php"] [unique_id "al9PygWat-noHLkDuAhvcgAAARQ"]
[Tue Jul 21 07:54:02.373406 2026] [security2:error] [pid 341679:tid 341896] [client 182.8.255.181:17532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PygWat-noHLkDuAhvdQAAAWE"]
[Tue Jul 21 07:54:02.373521 2026] [security2:error] [pid 341679:tid 341896] [client 182.8.255.181:17532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9PygWat-noHLkDuAhvdQAAAWE"]
[Tue Jul 21 07:54:02.544107 2026] [security2:error] [pid 341679:tid 341917] [client 20.206.105.145:55924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/ty.php"] [unique_id "al9PygWat-noHLkDuAhvegAAAXY"]
[Tue Jul 21 07:54:02.550427 2026] [core:error] [pid 341679:tid 341863] [client 66.249.66.169:62087] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:54:02.550449 2026] [core:error] [pid 341679:tid 341863] [client 66.249.66.169:62087] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:54:02.741870 2026] [security2:error] [pid 341679:tid 341770] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PygWat-noHLkDuAhvfwABLFo"]
[Tue Jul 21 07:54:02.742097 2026] [security2:error] [pid 341679:tid 341843] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9PygWat-noHLkDuAhvfwABLFo"]
[Tue Jul 21 07:54:02.897336 2026] [security2:error] [pid 341679:tid 341867] [client 198.54.128.138:49364] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9PygWat-noHLkDuAhvhQAAAUQ"]
[Tue Jul 21 07:54:02.897430 2026] [security2:error] [pid 341679:tid 341867] [client 198.54.128.138:49364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9PygWat-noHLkDuAhvhQAAAUQ"]
[Tue Jul 21 07:54:02.906856 2026] [security2:error] [pid 341679:tid 341847] [client 4.204.201.85:63173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wp-load.php"] [unique_id "al9PygWat-noHLkDuAhviQAAATA"]
[Tue Jul 21 07:54:03.117239 2026] [autoindex:error] [pid 341679:tid 341865] [client 43.136.167.197:48438] AH01276: Cannot serve directory /home2/lari0640/lararmstore.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:54:03.238922 2026] [security2:error] [pid 341679:tid 341831] [client 4.204.201.85:63112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/xyn.php"] [unique_id "al9PywWat-noHLkDuAhvkwAAASA"]
[Tue Jul 21 07:54:03.452239 2026] [security2:error] [pid 341679:tid 341883] [client 102.206.115.33:60094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9PywWat-noHLkDuAhvmQAAAVQ"]
[Tue Jul 21 07:54:03.452345 2026] [security2:error] [pid 341679:tid 341883] [client 102.206.115.33:60094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9PywWat-noHLkDuAhvmQAAAVQ"]
[Tue Jul 21 07:54:03.733325 2026] [security2:error] [pid 341679:tid 341927] [client 20.104.96.117:54937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/file5.php"] [unique_id "al9PywWat-noHLkDuAhvnQAAAYA"]
[Tue Jul 21 07:54:03.762620 2026] [security2:error] [pid 341679:tid 341906] [client 114.119.131.189:28553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gfacil.com.br"] [uri "/201-6182005/promercado-consultoria-e-marketing/detalhe.html"] [unique_id "al9PywWat-noHLkDuAhvnwAAAWs"], referer: https://pages24.com.br/rio-de-janeiro-rj/promercado-consultoria-participacoes-e-marketing-aXyHXp.html
[Tue Jul 21 07:54:03.867744 2026] [security2:error] [pid 341679:tid 341872] [client 122.164.127.47:60244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PywWat-noHLkDuAhvpQAAAUk"]
[Tue Jul 21 07:54:03.867875 2026] [security2:error] [pid 341679:tid 341872] [client 122.164.127.47:60244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9PywWat-noHLkDuAhvpQAAAUk"]
[Tue Jul 21 07:54:03.951811 2026] [security2:error] [pid 341679:tid 341838] [client 4.204.201.85:48069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/ccc.php"] [unique_id "al9PywWat-noHLkDuAhvpgAAASc"]
[Tue Jul 21 07:54:03.999212 2026] [security2:error] [pid 341679:tid 341915] [client 74.249.245.134:65108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/date.php"] [unique_id "al9PywWat-noHLkDuAhvqgAAAXQ"]
[Tue Jul 21 07:54:04.145682 2026] [security2:error] [pid 341679:tid 341898] [client 74.249.245.134:64104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/pomo.php"] [unique_id "al9PzAWat-noHLkDuAhvrAAAAWM"]
[Tue Jul 21 07:54:04.333015 2026] [security2:error] [pid 341679:tid 341834] [client 4.204.201.85:48071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/w.php"] [unique_id "al9PzAWat-noHLkDuAhvsAAAASM"]
[Tue Jul 21 07:54:04.437715 2026] [security2:error] [pid 341679:tid 341840] [client 185.213.175.37:9570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "astrosyasmin.com.br"] [uri "/wp-content/plugins/complianz-gdpr/assets/css/cookieblocker.min.css"] [unique_id "al9PzAWat-noHLkDuAhvtQAAASk"]
[Tue Jul 21 07:54:04.437799 2026] [security2:error] [pid 341679:tid 341840] [client 185.213.175.37:9570] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "astrosyasmin.com.br"] [uri "/wp-content/plugins/complianz-gdpr/assets/css/cookieblocker.min.css"] [unique_id "al9PzAWat-noHLkDuAhvtQAAASk"]
[Tue Jul 21 07:54:04.711134 2026] [security2:error] [pid 341679:tid 341809] [client 4.204.201.85:48078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9PzAWat-noHLkDuAhvugAAAQo"]
[Tue Jul 21 07:54:05.061920 2026] [security2:error] [pid 341679:tid 341853] [client 4.204.201.85:63142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/FWAZ.php"] [unique_id "al9PzQWat-noHLkDuAhvwwAAATY"]
[Tue Jul 21 07:54:05.194450 2026] [security2:error] [pid 341679:tid 341771] [remote 103.187.169.251:39092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/wp-login.php"] [unique_id "al9PzQWat-noHLkDuAhvxwABQls"]
[Tue Jul 21 07:54:05.247008 2026] [security2:error] [pid 341679:tid 341914] [client 74.249.245.134:64236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/test1.php"] [unique_id "al9PzQWat-noHLkDuAhvyQAAAXM"]
[Tue Jul 21 07:54:05.300790 2026] [security2:error] [pid 341679:tid 341768] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PzQWat-noHLkDuAhvywABN1g"]
[Tue Jul 21 07:54:05.300961 2026] [security2:error] [pid 341679:tid 341854] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9PzQWat-noHLkDuAhvywABN1g"]
[Tue Jul 21 07:54:05.464403 2026] [security2:error] [pid 341679:tid 341822] [client 4.204.201.85:63205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/miru1.php"] [unique_id "al9PzQWat-noHLkDuAhv0AAAARc"]
[Tue Jul 21 07:54:05.494551 2026] [security2:error] [pid 341679:tid 341862] [client 103.86.117.203:57529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PzQWat-noHLkDuAhv0QAAAT8"]
[Tue Jul 21 07:54:05.494661 2026] [security2:error] [pid 341679:tid 341862] [client 103.86.117.203:57529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9PzQWat-noHLkDuAhv0QAAAT8"]
[Tue Jul 21 07:54:05.704531 2026] [security2:error] [pid 341679:tid 341901] [client 20.197.192.193:57808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/dr.php"] [unique_id "al9PzQWat-noHLkDuAhv1gAAAWY"]
[Tue Jul 21 07:54:05.761612 2026] [security2:error] [pid 341679:tid 341851] [client 4.204.201.85:63192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/aa.php"] [unique_id "al9PzQWat-noHLkDuAhv2AAAATQ"]
[Tue Jul 21 07:54:05.883645 2026] [security2:error] [pid 341679:tid 341847] [client 198.54.128.138:49524] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9PzQWat-noHLkDuAhv2gAAATA"]
[Tue Jul 21 07:54:05.883748 2026] [security2:error] [pid 341679:tid 341847] [client 198.54.128.138:49524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9PzQWat-noHLkDuAhv2gAAATA"]
[Tue Jul 21 07:54:05.994034 2026] [security2:error] [pid 341679:tid 341903] [client 193.36.225.11:55559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9PzQWat-noHLkDuAhv4gAAAWg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:06.208572 2026] [security2:error] [pid 341679:tid 341868] [client 4.204.201.85:48077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/122.php"] [unique_id "al9PzgWat-noHLkDuAhv5gAAAUU"]
[Tue Jul 21 07:54:06.281746 2026] [security2:error] [pid 341679:tid 341871] [client 114.119.136.64:28565] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.vivaconcierge.com.br"] [uri "/wp-content/uploads/2018/08/WhatsApp-Image-2019-08-28-at-22.52.05.jpeg"] [unique_id "al9PzgWat-noHLkDuAhv6QAAAUg"], referer: https://www.vivaconcierge.com.br/wp-content/uploads/2018/08/WhatsApp-Image-2019-08-28-at-22.52.05.jpeg
[Tue Jul 21 07:54:06.503162 2026] [security2:error] [pid 341679:tid 341926] [client 4.204.201.85:48075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/get.php"] [unique_id "al9PzgWat-noHLkDuAhv7wAAAX8"]
[Tue Jul 21 07:54:06.730390 2026] [security2:error] [pid 341679:tid 341821] [client 136.144.33.213:20805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9PzgWat-noHLkDuAhv8AAAARY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:54:06.804860 2026] [security2:error] [pid 341679:tid 341914] [client 74.249.245.134:18478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/fw.php"] [unique_id "al9PzgWat-noHLkDuAhv-AAAAXM"]
[Tue Jul 21 07:54:06.810074 2026] [security2:error] [pid 341679:tid 341790] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PzgWat-noHLkDuAhv-QABam4"]
[Tue Jul 21 07:54:06.810190 2026] [security2:error] [pid 341679:tid 341905] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PzgWat-noHLkDuAhv-QABam4"]
[Tue Jul 21 07:54:06.823382 2026] [security2:error] [pid 341679:tid 341838] [client 4.204.201.85:63163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/as.php"] [unique_id "al9PzgWat-noHLkDuAhv-gAAASc"]
[Tue Jul 21 07:54:06.902357 2026] [security2:error] [pid 341679:tid 341864] [client 41.68.90.219:54623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PzgWat-noHLkDuAhv_QAAAUE"]
[Tue Jul 21 07:54:06.903493 2026] [security2:error] [pid 341679:tid 341864] [client 41.68.90.219:54623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PzgWat-noHLkDuAhv_QAAAUE"]
[Tue Jul 21 07:54:06.982622 2026] [security2:error] [pid 341679:tid 341892] [client 185.198.240.214:44369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9PzgWat-noHLkDuAhwAQAAAV0"]
[Tue Jul 21 07:54:06.985289 2026] [security2:error] [pid 341679:tid 341922] [client 185.198.240.230:61477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9PzgWat-noHLkDuAhwAgAAAXs"]
[Tue Jul 21 07:54:07.064423 2026] [security2:error] [pid 341679:tid 341890] [client 122.162.144.145:4396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PzwWat-noHLkDuAhwAwAAAVs"]
[Tue Jul 21 07:54:07.064549 2026] [security2:error] [pid 341679:tid 341890] [client 122.162.144.145:4396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9PzwWat-noHLkDuAhwAwAAAVs"]
[Tue Jul 21 07:54:07.120931 2026] [security2:error] [pid 341679:tid 341836] [client 4.204.201.85:48117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/ccou.php"] [unique_id "al9PzwWat-noHLkDuAhwBQAAASU"]
[Tue Jul 21 07:54:07.421139 2026] [security2:error] [pid 341679:tid 341815] [client 4.204.201.85:48120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/w3lls.php"] [unique_id "al9PzwWat-noHLkDuAhwDQAAARA"]
[Tue Jul 21 07:54:07.421139 2026] [security2:error] [pid 341679:tid 341723] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PzwWat-noHLkDuAhwDgABTSs"]
[Tue Jul 21 07:54:07.421255 2026] [security2:error] [pid 341679:tid 341876] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9PzwWat-noHLkDuAhwDgABTSs"]
[Tue Jul 21 07:54:07.515189 2026] [security2:error] [pid 341679:tid 341863] [client 178.153.91.96:52138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PzwWat-noHLkDuAhwEwAAAUA"]
[Tue Jul 21 07:54:07.515294 2026] [security2:error] [pid 341679:tid 341863] [client 178.153.91.96:52138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9PzwWat-noHLkDuAhwEwAAAUA"]
[Tue Jul 21 07:54:07.675290 2026] [security2:error] [pid 341679:tid 341811] [client 223.236.153.128:7070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PzwWat-noHLkDuAhwFAAAAQw"]
[Tue Jul 21 07:54:07.675414 2026] [security2:error] [pid 341679:tid 341811] [client 223.236.153.128:7070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9PzwWat-noHLkDuAhwFAAAAQw"]
[Tue Jul 21 07:54:07.741441 2026] [security2:error] [pid 341679:tid 341903] [client 74.7.175.159:56406] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.rota40.autoq.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9PzwWat-noHLkDuAhwFgABaH8"]
[Tue Jul 21 07:54:07.956602 2026] [security2:error] [pid 341679:tid 341882] [client 4.204.201.85:48010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/test1.php"] [unique_id "al9PzwWat-noHLkDuAhwHAAAAVM"]
[Tue Jul 21 07:54:08.074488 2026] [security2:error] [pid 341679:tid 341867] [client 103.166.103.129:44003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9P0AWat-noHLkDuAhwIAAAAUQ"]
[Tue Jul 21 07:54:08.074618 2026] [security2:error] [pid 341679:tid 341867] [client 103.166.103.129:44003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9P0AWat-noHLkDuAhwIAAAAUQ"]
[Tue Jul 21 07:54:08.236179 2026] [security2:error] [pid 341679:tid 341872] [client 204.8.98.45:57868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9P0AWat-noHLkDuAhwIgAAAUk"]
[Tue Jul 21 07:54:08.236278 2026] [security2:error] [pid 341679:tid 341872] [client 204.8.98.45:57868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9P0AWat-noHLkDuAhwIgAAAUk"]
[Tue Jul 21 07:54:08.263293 2026] [security2:error] [pid 341679:tid 341850] [client 20.104.96.117:57747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/0xD.php"] [unique_id "al9P0AWat-noHLkDuAhwJAAAATM"]
[Tue Jul 21 07:54:08.273811 2026] [security2:error] [pid 341679:tid 341910] [client 117.247.80.59:1706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0AWat-noHLkDuAhwKAAAAW8"]
[Tue Jul 21 07:54:08.273938 2026] [security2:error] [pid 341679:tid 341910] [client 117.247.80.59:1706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0AWat-noHLkDuAhwKAAAAW8"]
[Tue Jul 21 07:54:08.274834 2026] [autoindex:error] [pid 341679:tid 341680] [remote 74.7.242.29:43748] AH01276: Cannot serve directory /home2/italom32/rota40.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:54:08.277729 2026] [security2:error] [pid 341679:tid 341914] [client 4.204.201.85:63203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/database.php"] [unique_id "al9P0AWat-noHLkDuAhwKgAAAXM"]
[Tue Jul 21 07:54:08.378511 2026] [security2:error] [pid 341679:tid 341913] [client 74.249.245.134:64070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/fm.php"] [unique_id "al9P0AWat-noHLkDuAhwKwAAAXI"]
[Tue Jul 21 07:54:08.450874 2026] [security2:error] [pid 341679:tid 341859] [client 117.217.38.194:50462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0AWat-noHLkDuAhwLgAAATw"]
[Tue Jul 21 07:54:08.451023 2026] [security2:error] [pid 341679:tid 341859] [client 117.217.38.194:50462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0AWat-noHLkDuAhwLgAAATw"]
[Tue Jul 21 07:54:08.611083 2026] [security2:error] [pid 341679:tid 341809] [client 139.167.225.182:60285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0AWat-noHLkDuAhwNQAAAQo"]
[Tue Jul 21 07:54:08.611180 2026] [security2:error] [pid 341679:tid 341809] [client 139.167.225.182:60285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0AWat-noHLkDuAhwNQAAAQo"]
[Tue Jul 21 07:54:08.635051 2026] [security2:error] [pid 341679:tid 341898] [client 4.204.201.85:63207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/file.php"] [unique_id "al9P0AWat-noHLkDuAhwNgAAAWM"]
[Tue Jul 21 07:54:08.726162 2026] [security2:error] [pid 341679:tid 341707] [remote 45.90.123.233:55684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fgengenharia.eng.br"] [uri "/wp-login.php"] [unique_id "al9P0AWat-noHLkDuAhwNwABexs"]
[Tue Jul 21 07:54:08.745541 2026] [security2:error] [pid 341679:tid 341892] [client 173.24.185.52:55507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9P0AWat-noHLkDuAhwOAAAAV0"]
[Tue Jul 21 07:54:08.745634 2026] [security2:error] [pid 341679:tid 341892] [client 173.24.185.52:55507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9P0AWat-noHLkDuAhwOAAAAV0"]
[Tue Jul 21 07:54:08.907925 2026] [security2:error] [pid 341679:tid 341715] [remote 114.119.151.93:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aud-7.com"] [uri "/good.php"] [unique_id "al9P0AWat-noHLkDuAhwPQABMSM"], referer: https://aud-7.com/good.php?rcnfn/p217600.html
[Tue Jul 21 07:54:08.978750 2026] [security2:error] [pid 341679:tid 341830] [client 4.204.201.85:63147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/file.php"] [unique_id "al9P0AWat-noHLkDuAhwQAAAAR8"]
[Tue Jul 21 07:54:09.117335 2026] [security2:error] [pid 341679:tid 341758] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0QWat-noHLkDuAhwRQABh04"]
[Tue Jul 21 07:54:09.117468 2026] [security2:error] [pid 341679:tid 341934] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0QWat-noHLkDuAhwRQABh04"]
[Tue Jul 21 07:54:09.190303 2026] [security2:error] [pid 341679:tid 341832] [client 103.78.200.11:63283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0QWat-noHLkDuAhwSQAAASE"]
[Tue Jul 21 07:54:09.191218 2026] [security2:error] [pid 341679:tid 341832] [client 103.78.200.11:63283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0QWat-noHLkDuAhwSQAAASE"]
[Tue Jul 21 07:54:09.326459 2026] [security2:error] [pid 341679:tid 341705] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0QWat-noHLkDuAhwTQABLRk"]
[Tue Jul 21 07:54:09.326641 2026] [security2:error] [pid 341679:tid 341844] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0QWat-noHLkDuAhwTQABLRk"]
[Tue Jul 21 07:54:09.354309 2026] [security2:error] [pid 341679:tid 341869] [client 4.204.201.85:48030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/777.php"] [unique_id "al9P0QWat-noHLkDuAhwTwAAAUY"]
[Tue Jul 21 07:54:09.424030 2026] [security2:error] [pid 341679:tid 341853] [client 92.119.178.3:42426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9P0QWat-noHLkDuAhwUgAAATY"]
[Tue Jul 21 07:54:09.424130 2026] [security2:error] [pid 341679:tid 341853] [client 92.119.178.3:42426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9P0QWat-noHLkDuAhwUgAAATY"]
[Tue Jul 21 07:54:09.621714 2026] [autoindex:error] [pid 341679:tid 341701] [remote 74.7.243.203:46992] AH01276: Cannot serve directory /home2/onfiel33/kotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.wallpapers.pro
[Tue Jul 21 07:54:09.699435 2026] [security2:error] [pid 341679:tid 341908] [client 4.204.201.85:63132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/ssixta.php"] [unique_id "al9P0QWat-noHLkDuAhwWgAAAW0"]
[Tue Jul 21 07:54:09.743642 2026] [autoindex:error] [pid 341679:tid 341694] [remote 74.7.243.200:48554] AH01276: Cannot serve directory /home2/marc8022/frederichpart.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:54:09.835994 2026] [security2:error] [pid 341679:tid 341816] [client 20.226.60.151:56813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/ortasekerli1.php"] [unique_id "al9P0QWat-noHLkDuAhwYwAAARE"]
[Tue Jul 21 07:54:09.839302 2026] [security2:error] [pid 341679:tid 341814] [client 74.7.175.158:41440] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "frederichpart.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9P0QWat-noHLkDuAhwZAABD2M"]
[Tue Jul 21 07:54:10.169945 2026] [security2:error] [pid 341679:tid 341883] [client 4.204.201.85:63165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/1c.php"] [unique_id "al9P0gWat-noHLkDuAhwbgAAAVQ"]
[Tue Jul 21 07:54:10.385770 2026] [security2:error] [pid 341679:tid 341930] [client 122.186.204.214:59270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P0gWat-noHLkDuAhwcgAAAYM"]
[Tue Jul 21 07:54:10.385899 2026] [security2:error] [pid 341679:tid 341930] [client 122.186.204.214:59270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P0gWat-noHLkDuAhwcgAAAYM"]
[Tue Jul 21 07:54:10.509207 2026] [security2:error] [pid 341679:tid 341716] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9P0gWat-noHLkDuAhwdQABECQ"]
[Tue Jul 21 07:54:10.509386 2026] [security2:error] [pid 341679:tid 341815] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9P0gWat-noHLkDuAhwdQABECQ"]
[Tue Jul 21 07:54:10.704874 2026] [security2:error] [pid 341679:tid 341901] [client 103.29.114.44:11621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0gWat-noHLkDuAhwhQAAAWY"]
[Tue Jul 21 07:54:10.705000 2026] [security2:error] [pid 341679:tid 341901] [client 103.29.114.44:11621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0gWat-noHLkDuAhwhQAAAWY"]
[Tue Jul 21 07:54:10.728536 2026] [security2:error] [pid 341679:tid 341916] [client 4.204.201.85:63123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/test2.php"] [unique_id "al9P0gWat-noHLkDuAhwhgAAAXU"]
[Tue Jul 21 07:54:10.837403 2026] [security2:error] [pid 341679:tid 341917] [client 193.36.225.70:49813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9P0gWat-noHLkDuAhwhAAAAXY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:10.920403 2026] [security2:error] [pid 341679:tid 341741] [remote 124.55.178.99:39686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rqracademy.com"] [uri "/wp-login.php"] [unique_id "al9P0gWat-noHLkDuAhwiwABIj0"]
[Tue Jul 21 07:54:10.971909 2026] [security2:error] [pid 341679:tid 341691] [remote 114.119.144.36:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "androapkmod.com"] [uri "/rfs-real-flight-simulator/download/"] [unique_id "al9P0gWat-noHLkDuAhwjQABLQs"], referer: https://androapkmod.com/rfs-real-flight-simulator/
[Tue Jul 21 07:54:11.033482 2026] [security2:error] [pid 341679:tid 341819] [client 136.144.33.213:63977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9P0wWat-noHLkDuAhwjwAAARQ"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:54:11.129562 2026] [security2:error] [pid 341679:tid 341880] [client 4.204.201.85:48103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/buy.php"] [unique_id "al9P0wWat-noHLkDuAhwkAAAAVE"]
[Tue Jul 21 07:54:11.205140 2026] [security2:error] [pid 341679:tid 341813] [client 106.215.181.8:5880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0wWat-noHLkDuAhwlAAAAQ4"]
[Tue Jul 21 07:54:11.205225 2026] [security2:error] [pid 341679:tid 341813] [client 106.215.181.8:5880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0wWat-noHLkDuAhwlAAAAQ4"]
[Tue Jul 21 07:54:11.294473 2026] [security2:error] [pid 341679:tid 341906] [client 20.197.192.193:57839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/2x.php"] [unique_id "al9P0wWat-noHLkDuAhwlQAAAWs"]
[Tue Jul 21 07:54:11.382952 2026] [security2:error] [pid 341679:tid 341910] [client 109.60.28.94:51570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0wWat-noHLkDuAhwmAAAAW8"]
[Tue Jul 21 07:54:11.383797 2026] [security2:error] [pid 341679:tid 341910] [client 109.60.28.94:51570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0wWat-noHLkDuAhwmAAAAW8"]
[Tue Jul 21 07:54:11.420856 2026] [security2:error] [pid 341679:tid 341685] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0wWat-noHLkDuAhwnAABbQU"]
[Tue Jul 21 07:54:11.421067 2026] [security2:error] [pid 341679:tid 341908] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0wWat-noHLkDuAhwnAABbQU"]
[Tue Jul 21 07:54:11.443130 2026] [security2:error] [pid 341679:tid 341881] [client 4.204.201.85:63198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/ssend.php"] [unique_id "al9P0wWat-noHLkDuAhwoAAAAVI"]
[Tue Jul 21 07:54:11.447041 2026] [security2:error] [pid 341679:tid 341827] [client 202.143.127.214:63697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0wWat-noHLkDuAhwnwAAARw"]
[Tue Jul 21 07:54:11.447174 2026] [security2:error] [pid 341679:tid 341827] [client 202.143.127.214:63697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P0wWat-noHLkDuAhwnwAAARw"]
[Tue Jul 21 07:54:11.752987 2026] [security2:error] [pid 341679:tid 341930] [client 4.204.201.85:63217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/item.php"] [unique_id "al9P0wWat-noHLkDuAhwpgAAAYM"]
[Tue Jul 21 07:54:11.848608 2026] [security2:error] [pid 341679:tid 341863] [client 20.226.60.151:50676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/classwithtostring.php"] [unique_id "al9P0wWat-noHLkDuAhwpwAAAUA"]
[Tue Jul 21 07:54:12.188472 2026] [security2:error] [pid 341679:tid 341869] [client 4.204.201.85:48074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/ss.php"] [unique_id "al9P1AWat-noHLkDuAhwtAAAAUY"]
[Tue Jul 21 07:54:12.299755 2026] [security2:error] [pid 341679:tid 341876] [client 122.179.91.63:16011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9P1AWat-noHLkDuAhwtgAAAU0"]
[Tue Jul 21 07:54:12.299883 2026] [security2:error] [pid 341679:tid 341876] [client 122.179.91.63:16011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9P1AWat-noHLkDuAhwtgAAAU0"]
[Tue Jul 21 07:54:12.478900 2026] [security2:error] [pid 341679:tid 341868] [client 114.119.150.186:37497] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "essenceclinicadesaude.com.br"] [uri "/blog/page/1/"] [unique_id "al9P1AWat-noHLkDuAhwvAAAAUU"], referer: https://essenceclinicadesaude.com.br/blog/page/4
[Tue Jul 21 07:54:12.485928 2026] [security2:error] [pid 341679:tid 341753] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9P1AWat-noHLkDuAhwvQABOEk"]
[Tue Jul 21 07:54:12.486051 2026] [security2:error] [pid 341679:tid 341855] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9P1AWat-noHLkDuAhwvQABOEk"]
[Tue Jul 21 07:54:12.519711 2026] [core:alert] [pid 341679:tid 341880] [client 57.141.18.104:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:54:12.564090 2026] [security2:error] [pid 341679:tid 341822] [client 4.204.201.85:63228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/hypo.php"] [unique_id "al9P1AWat-noHLkDuAhwwgAAARc"]
[Tue Jul 21 07:54:12.684110 2026] [security2:error] [pid 341679:tid 341814] [client 20.104.96.117:54994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/fnstall.php"] [unique_id "al9P1AWat-noHLkDuAhwwwAAAQ8"]
[Tue Jul 21 07:54:12.794085 2026] [security2:error] [pid 341679:tid 341870] [client 182.8.255.181:17505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9P1AWat-noHLkDuAhwywAAAUc"]
[Tue Jul 21 07:54:12.794212 2026] [security2:error] [pid 341679:tid 341870] [client 182.8.255.181:17505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9P1AWat-noHLkDuAhwywAAAUc"]
[Tue Jul 21 07:54:12.922881 2026] [security2:error] [pid 341679:tid 341824] [client 4.204.201.85:48119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/users.php"] [unique_id "al9P1AWat-noHLkDuAhwzgAAARk"]
[Tue Jul 21 07:54:13.041311 2026] [security2:error] [pid 341679:tid 341867] [client 216.73.160.23:59987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9P1QWat-noHLkDuAhw0wAAAUQ"]
[Tue Jul 21 07:54:13.063178 2026] [security2:error] [pid 341679:tid 341833] [client 216.73.160.191:26513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9P1QWat-noHLkDuAhw1QAAASI"]
[Tue Jul 21 07:54:13.074058 2026] [security2:error] [pid 341679:tid 341889] [client 216.73.160.189:32725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9P1QWat-noHLkDuAhw1gAAAVo"]
[Tue Jul 21 07:54:13.204458 2026] [security2:error] [pid 341679:tid 341884] [client 216.73.160.25:60791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9P1QWat-noHLkDuAhw1AAAAVU"]
[Tue Jul 21 07:54:13.316895 2026] [security2:error] [pid 341679:tid 341811] [client 4.204.201.85:63216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/177.php"] [unique_id "al9P1QWat-noHLkDuAhw2AAAAQw"]
[Tue Jul 21 07:54:13.326854 2026] [security2:error] [pid 341679:tid 341736] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9P1QWat-noHLkDuAhw2gABIDg"]
[Tue Jul 21 07:54:13.326969 2026] [security2:error] [pid 341679:tid 341831] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9P1QWat-noHLkDuAhw2gABIDg"]
[Tue Jul 21 07:54:13.569866 2026] [security2:error] [pid 341679:tid 341865] [client 114.119.132.122:57635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.simleite.com.br"] [uri "/album/211"] [unique_id "al9P1QWat-noHLkDuAhw5AAAAUI"], referer: https://www.simleite.com.br/album/210
[Tue Jul 21 07:54:13.626211 2026] [autoindex:error] [pid 341679:tid 341893] [client 43.166.238.12:43442] AH01276: Cannot serve directory /home2/lylowc82/conquisteemcasa.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:54:13.659400 2026] [security2:error] [pid 341679:tid 341876] [client 4.204.201.85:63223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/config.php"] [unique_id "al9P1QWat-noHLkDuAhw6AAAAU0"]
[Tue Jul 21 07:54:13.786668 2026] [security2:error] [pid 341679:tid 341821] [client 198.54.128.138:53646] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9P1QWat-noHLkDuAhw7QAAARY"]
[Tue Jul 21 07:54:13.786780 2026] [security2:error] [pid 341679:tid 341821] [client 198.54.128.138:53646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9P1QWat-noHLkDuAhw7QAAARY"]
[Tue Jul 21 07:54:13.815240 2026] [security2:error] [pid 341679:tid 341868] [client 20.206.105.145:55828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/155.php"] [unique_id "al9P1QWat-noHLkDuAhw7wAAAUU"]
[Tue Jul 21 07:54:13.972628 2026] [security2:error] [pid 341679:tid 341769] [remote 198.244.242.138:27478] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.dantonio.com.br"] [uri "/robots.txt"] [unique_id "al9P1QWat-noHLkDuAhw8AABN1k"]
[Tue Jul 21 07:54:13.972850 2026] [security2:error] [pid 341679:tid 341854] [client 198.244.242.138:27478] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.dantonio.com.br"] [uri "/robots.txt"] [unique_id "al9P1QWat-noHLkDuAhw8AABN1k"]
[Tue Jul 21 07:54:14.000407 2026] [security2:error] [pid 341679:tid 341864] [client 102.206.115.33:59785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9P1QWat-noHLkDuAhw8QAAAUE"]
[Tue Jul 21 07:54:14.000876 2026] [security2:error] [pid 341679:tid 341864] [client 102.206.115.33:59785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9P1QWat-noHLkDuAhw8QAAAUE"]
[Tue Jul 21 07:54:14.068766 2026] [security2:error] [pid 341679:tid 341918] [client 4.204.201.85:48122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/gettest.php"] [unique_id "al9P1gWat-noHLkDuAhw9AAAAXc"]
[Tue Jul 21 07:54:14.410018 2026] [security2:error] [pid 341679:tid 341936] [client 4.204.201.85:63111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/min.php"] [unique_id "al9P1gWat-noHLkDuAhw_wAAAYk"]
[Tue Jul 21 07:54:14.633221 2026] [security2:error] [pid 341679:tid 341863] [client 172.245.102.45:43347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9P1gWat-noHLkDuAhxBQAAAUA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:14.674200 2026] [security2:error] [pid 341679:tid 341901] [client 122.164.127.47:60821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9P1gWat-noHLkDuAhxCAAAAWY"]
[Tue Jul 21 07:54:14.674310 2026] [security2:error] [pid 341679:tid 341901] [client 122.164.127.47:60821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9P1gWat-noHLkDuAhxCAAAAWY"]
[Tue Jul 21 07:54:14.814134 2026] [security2:error] [pid 341679:tid 341921] [client 114.119.157.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.imobiliariasobrado.net.br"] [uri "/imovel/terreno-venda-costa-e-silva-joinville-sc-v-3681"] [unique_id "al9P1gWat-noHLkDuAhxCwAAAXo"], referer: https://www.imobiliariasobrado.net.br/imovel/terreno-venda-costa-e-silva-joinville-sc-v-3681?opcao=V-3681&cd_empresa=5
[Tue Jul 21 07:54:14.827033 2026] [security2:error] [pid 341679:tid 341930] [client 4.204.201.85:63151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/dvjul.php"] [unique_id "al9P1gWat-noHLkDuAhxDgAAAYM"]
[Tue Jul 21 07:54:15.135498 2026] [security2:error] [pid 341679:tid 341842] [client 4.204.201.85:63180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/biufile.php"] [unique_id "al9P1wWat-noHLkDuAhxEQAAASs"]
[Tue Jul 21 07:54:15.200872 2026] [security2:error] [pid 341679:tid 341856] [client 20.197.192.193:3098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/kq1.php"] [unique_id "al9P1wWat-noHLkDuAhxGAAAATk"]
[Tue Jul 21 07:54:15.503547 2026] [security2:error] [pid 341679:tid 341778] [remote 15.235.27.174:16322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.dantonio.com.br"] [uri "/"] [unique_id "al9P1wWat-noHLkDuAhxHwABQWI"]
[Tue Jul 21 07:54:15.503723 2026] [security2:error] [pid 341679:tid 341864] [client 15.235.27.174:16322] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.dantonio.com.br"] [uri "/"] [unique_id "al9P1wWat-noHLkDuAhxHwABQWI"]
[Tue Jul 21 07:54:15.536939 2026] [security2:error] [pid 341679:tid 341860] [client 4.204.201.85:63226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/av.php"] [unique_id "al9P1wWat-noHLkDuAhxIAAAAT0"]
[Tue Jul 21 07:54:15.832376 2026] [security2:error] [pid 341679:tid 341915] [client 193.36.225.105:52277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9P1gWat-noHLkDuAhxBwAAAXQ"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:54:15.959630 2026] [security2:error] [pid 341679:tid 341796] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9P1wWat-noHLkDuAhxKwABEnQ"]
[Tue Jul 21 07:54:15.959808 2026] [security2:error] [pid 341679:tid 341817] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9P1wWat-noHLkDuAhxKwABEnQ"]
[Tue Jul 21 07:54:15.981554 2026] [security2:error] [pid 341679:tid 341825] [client 103.86.117.203:58072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P1wWat-noHLkDuAhxLgAAARo"]
[Tue Jul 21 07:54:15.981688 2026] [security2:error] [pid 341679:tid 341825] [client 103.86.117.203:58072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P1wWat-noHLkDuAhxLgAAARo"]
[Tue Jul 21 07:54:16.029470 2026] [security2:error] [pid 341679:tid 341867] [client 4.204.201.85:63202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/coffexium.php"] [unique_id "al9P2AWat-noHLkDuAhxMQAAAUQ"]
[Tue Jul 21 07:54:16.061683 2026] [security2:error] [pid 341679:tid 341812] [client 20.104.96.117:54972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/acp.php"] [unique_id "al9P2AWat-noHLkDuAhxNAAAAQ0"]
[Tue Jul 21 07:54:16.077244 2026] [security2:error] [pid 341679:tid 341790] [remote 182.77.62.24:60974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ellosemijoias.com.br"] [uri "/wp-login.php"] [unique_id "al9P1wWat-noHLkDuAhxEAABHW4"]
[Tue Jul 21 07:54:16.667832 2026] [security2:error] [pid 341679:tid 341865] [client 4.204.201.85:48084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/core.php"] [unique_id "al9P2AWat-noHLkDuAhxQQAAAUI"]
[Tue Jul 21 07:54:17.379807 2026] [security2:error] [pid 341679:tid 341851] [client 4.204.201.85:48041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/als.php"] [unique_id "al9P2QWat-noHLkDuAhxUQAAATQ"]
[Tue Jul 21 07:54:17.694180 2026] [security2:error] [pid 341679:tid 341902] [client 74.249.245.134:65168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ini.php"] [unique_id "al9P2QWat-noHLkDuAhxWwAAAWc"]
[Tue Jul 21 07:54:17.699245 2026] [security2:error] [pid 341679:tid 341700] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P2QWat-noHLkDuAhxXAABZhQ"]
[Tue Jul 21 07:54:17.699381 2026] [security2:error] [pid 341679:tid 341901] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P2QWat-noHLkDuAhxXAABZhQ"]
[Tue Jul 21 07:54:17.848152 2026] [security2:error] [pid 341679:tid 341854] [client 122.162.144.145:17921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9P2QWat-noHLkDuAhxYgAAATc"]
[Tue Jul 21 07:54:17.848238 2026] [security2:error] [pid 341679:tid 341854] [client 122.162.144.145:17921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9P2QWat-noHLkDuAhxYgAAATc"]
[Tue Jul 21 07:54:17.970058 2026] [security2:error] [pid 341679:tid 341815] [client 4.204.201.85:63116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/simple.php"] [unique_id "al9P2QWat-noHLkDuAhxZgAAARA"]
[Tue Jul 21 07:54:18.126317 2026] [security2:error] [pid 341679:tid 341827] [client 178.153.91.96:51146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9P2gWat-noHLkDuAhxaQAAARw"]
[Tue Jul 21 07:54:18.126454 2026] [security2:error] [pid 341679:tid 341827] [client 178.153.91.96:51146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9P2gWat-noHLkDuAhxaQAAARw"]
[Tue Jul 21 07:54:18.160278 2026] [security2:error] [pid 341679:tid 341819] [client 223.236.153.128:14218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9P2gWat-noHLkDuAhxagAAARQ"]
[Tue Jul 21 07:54:18.164975 2026] [security2:error] [pid 341679:tid 341819] [client 223.236.153.128:14218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9P2gWat-noHLkDuAhxagAAARQ"]
[Tue Jul 21 07:54:18.301932 2026] [security2:error] [pid 341679:tid 341810] [client 20.226.60.151:50624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/root.php"] [unique_id "al9P2gWat-noHLkDuAhxbAAAAQs"]
[Tue Jul 21 07:54:18.522665 2026] [security2:error] [pid 341679:tid 341690] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P2gWat-noHLkDuAhxeAABdQo"]
[Tue Jul 21 07:54:18.522938 2026] [security2:error] [pid 341679:tid 341916] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P2gWat-noHLkDuAhxeAABdQo"]
[Tue Jul 21 07:54:18.800194 2026] [security2:error] [pid 341679:tid 341903] [client 139.167.225.182:60943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P2gWat-noHLkDuAhxhQAAAWg"]
[Tue Jul 21 07:54:18.800306 2026] [security2:error] [pid 341679:tid 341903] [client 139.167.225.182:60943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P2gWat-noHLkDuAhxhQAAAWg"]
[Tue Jul 21 07:54:18.822619 2026] [security2:error] [pid 341679:tid 341897] [client 117.247.80.59:12285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P2gWat-noHLkDuAhxhwAAAWI"]
[Tue Jul 21 07:54:18.822750 2026] [security2:error] [pid 341679:tid 341897] [client 117.247.80.59:12285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P2gWat-noHLkDuAhxhwAAAWI"]
[Tue Jul 21 07:54:18.921356 2026] [security2:error] [pid 341679:tid 341843] [client 117.217.38.194:51080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P2gWat-noHLkDuAhxjAAAASw"]
[Tue Jul 21 07:54:18.921726 2026] [security2:error] [pid 341679:tid 341843] [client 117.217.38.194:51080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P2gWat-noHLkDuAhxjAAAASw"]
[Tue Jul 21 07:54:18.952459 2026] [security2:error] [pid 341679:tid 341842] [client 103.166.103.129:59822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9P2gWat-noHLkDuAhxjgAAASs"]
[Tue Jul 21 07:54:18.952645 2026] [security2:error] [pid 341679:tid 341842] [client 103.166.103.129:59822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9P2gWat-noHLkDuAhxjgAAASs"]
[Tue Jul 21 07:54:19.023014 2026] [security2:error] [pid 341679:tid 341905] [client 20.197.192.193:57811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/zzz.php"] [unique_id "al9P2wWat-noHLkDuAhxkgAAAWo"]
[Tue Jul 21 07:54:19.146417 2026] [security2:error] [pid 341679:tid 341936] [client 114.119.153.106:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sobradoimoveis.com.br"] [uri "/imovel/apartamento-com-3-quartos-54m2-com-garagem-a-venda-joao-costa-joinville-sc-v-10258"] [unique_id "al9P2wWat-noHLkDuAhxlAAAAYk"], referer: https://www.sobradoimoveis.com.br/imovel/apartamento-com-3-quartos-54m2-com-garagem-a-venda-joao-costa-joinville-sc-v-10258?cd_empresa=5&opcao=V-10258
[Tue Jul 21 07:54:19.160301 2026] [security2:error] [pid 341679:tid 341863] [client 4.204.201.85:48073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/init.php"] [unique_id "al9P2wWat-noHLkDuAhxlQAAAUA"]
[Tue Jul 21 07:54:19.374736 2026] [security2:error] [pid 341679:tid 341841] [client 173.24.185.52:55985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9P2wWat-noHLkDuAhxmQAAASo"]
[Tue Jul 21 07:54:19.374880 2026] [security2:error] [pid 341679:tid 341841] [client 173.24.185.52:55985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9P2wWat-noHLkDuAhxmQAAASo"]
[Tue Jul 21 07:54:19.584110 2026] [security2:error] [pid 341679:tid 341691] [remote 209.97.182.179:48044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/wp-login.php"] [unique_id "al9P2wWat-noHLkDuAhxnwABMAs"]
[Tue Jul 21 07:54:19.598940 2026] [security2:error] [pid 341679:tid 341895] [client 172.245.102.44:21999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9P2wWat-noHLkDuAhxoAAAAWA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:19.623149 2026] [security2:error] [pid 341679:tid 341896] [client 184.75.221.3:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9P2wWat-noHLkDuAhxowAAAWE"]
[Tue Jul 21 07:54:19.623231 2026] [security2:error] [pid 341679:tid 341896] [client 184.75.221.3:57466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9P2wWat-noHLkDuAhxowAAAWE"]
[Tue Jul 21 07:54:19.624153 2026] [security2:error] [pid 341679:tid 341717] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P2wWat-noHLkDuAhxpQABgiU"]
[Tue Jul 21 07:54:19.624240 2026] [security2:error] [pid 341679:tid 341929] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P2wWat-noHLkDuAhxpQABgiU"]
[Tue Jul 21 07:54:19.930910 2026] [security2:error] [pid 341679:tid 341752] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P2wWat-noHLkDuAhxqwABFEg"]
[Tue Jul 21 07:54:19.931026 2026] [security2:error] [pid 341679:tid 341819] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P2wWat-noHLkDuAhxqwABFEg"]
[Tue Jul 21 07:54:20.038039 2026] [security2:error] [pid 341679:tid 341906] [client 37.140.223.156:23021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9P2gWat-noHLkDuAhxiAAAAWs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:54:20.122149 2026] [security2:error] [pid 341679:tid 341891] [client 41.68.90.219:55103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P3AWat-noHLkDuAhxswAAAVw"]
[Tue Jul 21 07:54:20.123183 2026] [security2:error] [pid 341679:tid 341891] [client 41.68.90.219:55103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P3AWat-noHLkDuAhxswAAAVw"]
[Tue Jul 21 07:54:20.308894 2026] [security2:error] [pid 341679:tid 341888] [client 92.119.178.3:43138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9P3AWat-noHLkDuAhxtQAAAVk"]
[Tue Jul 21 07:54:20.308992 2026] [security2:error] [pid 341679:tid 341888] [client 92.119.178.3:43138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9P3AWat-noHLkDuAhxtQAAAVk"]
[Tue Jul 21 07:54:20.422460 2026] [security2:error] [pid 341679:tid 341859] [client 4.204.201.85:63117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/fpwch.php"] [unique_id "al9P3AWat-noHLkDuAhxtwAAATw"]
[Tue Jul 21 07:54:20.727631 2026] [security2:error] [pid 341679:tid 341833] [client 114.119.165.5:24083] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bcsenepol.com.br"] [uri "/home/fundo-gramado-fazenda-novo-novo/"] [unique_id "al9P3AWat-noHLkDuAhxwQAAASI"], referer: https://bcsenepol.com.br/attachment-sitemap.xml
[Tue Jul 21 07:54:20.915382 2026] [security2:error] [pid 341679:tid 341892] [client 103.78.200.11:63743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P3AWat-noHLkDuAhxwwAAAV0"]
[Tue Jul 21 07:54:20.918614 2026] [security2:error] [pid 341679:tid 341892] [client 103.78.200.11:63743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P3AWat-noHLkDuAhxwwAAAV0"]
[Tue Jul 21 07:54:21.056821 2026] [security2:error] [pid 341679:tid 341825] [client 122.186.204.214:59806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P3QWat-noHLkDuAhxyAAAARo"]
[Tue Jul 21 07:54:21.056908 2026] [security2:error] [pid 341679:tid 341825] [client 122.186.204.214:59806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P3QWat-noHLkDuAhxyAAAARo"]
[Tue Jul 21 07:54:21.139132 2026] [security2:error] [pid 341679:tid 341883] [client 4.204.201.85:48030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/domvf.php"] [unique_id "al9P3QWat-noHLkDuAhxzQAAAVQ"]
[Tue Jul 21 07:54:21.225444 2026] [security2:error] [pid 341679:tid 341824] [client 103.29.114.44:57362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P3QWat-noHLkDuAhxzgAAARk"]
[Tue Jul 21 07:54:21.225596 2026] [security2:error] [pid 341679:tid 341824] [client 103.29.114.44:57362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P3QWat-noHLkDuAhxzgAAARk"]
[Tue Jul 21 07:54:21.371683 2026] [security2:error] [pid 341679:tid 341840] [client 114.119.155.42:21415] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dharmanet.com.br"] [uri "/home/"] [unique_id "al9P3QWat-noHLkDuAhx0AAAASk"], referer: http://futurenow.dw.com/pt-br/aulas-de-budismo-em-escolas-de-berlim/a-1071057
[Tue Jul 21 07:54:21.477042 2026] [security2:error] [pid 341679:tid 341732] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9P3QWat-noHLkDuAhx0gABZzQ"]
[Tue Jul 21 07:54:21.477313 2026] [security2:error] [pid 341679:tid 341902] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9P3QWat-noHLkDuAhx0gABZzQ"]
[Tue Jul 21 07:54:21.551407 2026] [autoindex:error] [pid 341679:tid 341729] [remote 40.160.16.154:27412] AH01276: Cannot serve directory /home2/pris2861/nuacruaefree.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:54:21.701786 2026] [security2:error] [pid 341679:tid 341813] [client 106.215.181.8:3013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P3QWat-noHLkDuAhx2wAAAQ4"]
[Tue Jul 21 07:54:21.701922 2026] [security2:error] [pid 341679:tid 341813] [client 106.215.181.8:3013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P3QWat-noHLkDuAhx2wAAAQ4"]
[Tue Jul 21 07:54:21.778035 2026] [security2:error] [pid 341679:tid 341719] [remote 192.241.143.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/wp-login.php"] [unique_id "al9P3QWat-noHLkDuAhx3AABLic"]
[Tue Jul 21 07:54:21.884050 2026] [security2:error] [pid 341679:tid 341855] [client 4.204.201.85:63116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wp.php"] [unique_id "al9P3QWat-noHLkDuAhx3QAAATg"]
[Tue Jul 21 07:54:22.115997 2026] [security2:error] [pid 341679:tid 341859] [client 20.220.225.223:19272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/else1.php"] [unique_id "al9P3gWat-noHLkDuAhx5AAAATw"]
[Tue Jul 21 07:54:22.146968 2026] [security2:error] [pid 341679:tid 341761] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P3gWat-noHLkDuAhx5wABQFE"]
[Tue Jul 21 07:54:22.147099 2026] [security2:error] [pid 341679:tid 341863] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P3gWat-noHLkDuAhx5wABQFE"]
[Tue Jul 21 07:54:22.312458 2026] [security2:error] [pid 341679:tid 341918] [client 109.60.28.94:51998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P3gWat-noHLkDuAhx6QAAAXc"]
[Tue Jul 21 07:54:22.313241 2026] [security2:error] [pid 341679:tid 341918] [client 109.60.28.94:51998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P3gWat-noHLkDuAhx6QAAAXc"]
[Tue Jul 21 07:54:22.536438 2026] [security2:error] [pid 341679:tid 341814] [client 202.143.127.214:64176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P3gWat-noHLkDuAhx7QAAAQ8"]
[Tue Jul 21 07:54:22.536559 2026] [security2:error] [pid 341679:tid 341814] [client 202.143.127.214:64176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P3gWat-noHLkDuAhx7QAAAQ8"]
[Tue Jul 21 07:54:22.662881 2026] [security2:error] [pid 341679:tid 341857] [client 114.119.140.169:42619] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tragaseushow.com.br"] [uri "/projeto/1-vitor-ramil-foi-no-mes-que-vem"] [unique_id "al9P3gWat-noHLkDuAhx8gAAATo"], referer: http://dbpedia.org/resource/Vitor_Ramil
[Tue Jul 21 07:54:22.766899 2026] [security2:error] [pid 341679:tid 341848] [client 20.226.60.151:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/sym403.php"] [unique_id "al9P3gWat-noHLkDuAhx9AAAATE"]
[Tue Jul 21 07:54:22.943076 2026] [security2:error] [pid 341679:tid 341822] [client 122.179.91.63:19709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9P3gWat-noHLkDuAhx-wAAARc"]
[Tue Jul 21 07:54:22.943189 2026] [security2:error] [pid 341679:tid 341822] [client 122.179.91.63:19709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9P3gWat-noHLkDuAhx-wAAARc"]
[Tue Jul 21 07:54:23.038841 2026] [security2:error] [pid 341679:tid 341865] [client 4.204.201.85:63215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/class.php"] [unique_id "al9P3wWat-noHLkDuAhx_QAAAUI"]
[Tue Jul 21 07:54:23.102040 2026] [security2:error] [pid 341679:tid 341871] [client 184.75.221.3:40024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9P3wWat-noHLkDuAhyAAAAAUg"]
[Tue Jul 21 07:54:23.102115 2026] [security2:error] [pid 341679:tid 341871] [client 184.75.221.3:40024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9P3wWat-noHLkDuAhyAAAAAUg"]
[Tue Jul 21 07:54:23.105286 2026] [security2:error] [pid 341679:tid 341873] [client 193.36.225.62:31759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9P3gWat-noHLkDuAhx-gAAAUo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:23.122539 2026] [security2:error] [pid 341679:tid 341769] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9P3wWat-noHLkDuAhyAgABiFk"]
[Tue Jul 21 07:54:23.122657 2026] [security2:error] [pid 341679:tid 341935] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9P3wWat-noHLkDuAhyAgABiFk"]
[Tue Jul 21 07:54:23.257985 2026] [security2:error] [pid 341679:tid 341930] [client 182.8.255.181:17327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9P3wWat-noHLkDuAhyBQAAAYM"]
[Tue Jul 21 07:54:23.258317 2026] [security2:error] [pid 341679:tid 341930] [client 182.8.255.181:17327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9P3wWat-noHLkDuAhyBQAAAYM"]
[Tue Jul 21 07:54:23.532309 2026] [security2:error] [pid 341679:tid 341809] [client 20.197.192.193:3088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/wicked.php"] [unique_id "al9P3wWat-noHLkDuAhyFQAAAQo"]
[Tue Jul 21 07:54:23.578949 2026] [security2:error] [pid 341679:tid 341863] [client 20.206.105.145:55818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/ops.php"] [unique_id "al9P3wWat-noHLkDuAhyFgAAAUA"]
[Tue Jul 21 07:54:23.702128 2026] [security2:error] [pid 341679:tid 341782] [remote 20.153.140.50:43084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9P3wWat-noHLkDuAhyGgABdmY"]
[Tue Jul 21 07:54:23.753660 2026] [security2:error] [pid 341679:tid 341838] [client 114.119.144.17:27809] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ellosemijoias.com.br"] [uri "/product-category/pulseiras/pulseiras-semi-joia/"] [unique_id "al9P3wWat-noHLkDuAhyGwAAASc"], referer: https://www.ellosemijoias.com.br/product-category/pulseiras/pulseiras-semi-joia/?orderby=menu_order
[Tue Jul 21 07:54:24.005593 2026] [security2:error] [pid 341679:tid 341910] [client 114.119.134.148:38545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/index.php/wishlist/index/add/product/53/form_key/gH4NcZGWQUlxlLWU"] [unique_id "al9P4AWat-noHLkDuAhyIQAAAW8"], referer: http://www.ceramicasantoaugusto.com.br/index.php/produtos.html?dir=asc&order=position
[Tue Jul 21 07:54:24.076678 2026] [security2:error] [pid 341679:tid 341784] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9P4AWat-noHLkDuAhyIwABR2g"]
[Tue Jul 21 07:54:24.076805 2026] [security2:error] [pid 341679:tid 341870] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9P4AWat-noHLkDuAhyIwABR2g"]
[Tue Jul 21 07:54:24.157624 2026] [security2:error] [pid 341679:tid 341814] [client 20.220.225.223:19736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/tkikikoko.php"] [unique_id "al9P4AWat-noHLkDuAhyJwAAAQ8"]
[Tue Jul 21 07:54:24.309207 2026] [security2:error] [pid 341679:tid 341897] [client 114.119.146.141:35443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/page/93/"] [unique_id "al9P4AWat-noHLkDuAhyKgAAAWI"], referer: https://powerflats.com.br/page/92/
[Tue Jul 21 07:54:24.506615 2026] [security2:error] [pid 341679:tid 341918] [client 102.206.115.33:58641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9P4AWat-noHLkDuAhyLgAAAXc"]
[Tue Jul 21 07:54:24.506749 2026] [security2:error] [pid 341679:tid 341918] [client 102.206.115.33:58641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9P4AWat-noHLkDuAhyLgAAAXc"]
[Tue Jul 21 07:54:24.753334 2026] [security2:error] [pid 341679:tid 341815] [client 92.119.178.3:51974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9P4AWat-noHLkDuAhyNgAAARA"]
[Tue Jul 21 07:54:24.753435 2026] [security2:error] [pid 341679:tid 341815] [client 92.119.178.3:51974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9P4AWat-noHLkDuAhyNgAAARA"]
[Tue Jul 21 07:54:24.966717 2026] [security2:error] [pid 341679:tid 341813] [client 4.204.201.85:63158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/echkm.php"] [unique_id "al9P4AWat-noHLkDuAhyOwAAAQ4"]
[Tue Jul 21 07:54:24.973731 2026] [security2:error] [pid 341679:tid 341884] [client 122.164.127.47:61397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9P4AWat-noHLkDuAhyPAAAAVU"]
[Tue Jul 21 07:54:24.973853 2026] [security2:error] [pid 341679:tid 341884] [client 122.164.127.47:61397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9P4AWat-noHLkDuAhyPAAAAVU"]
[Tue Jul 21 07:54:25.386124 2026] [security2:error] [pid 341679:tid 341915] [client 20.104.96.117:54917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/mosty.php"] [unique_id "al9P4QWat-noHLkDuAhyRwAAAXQ"]
[Tue Jul 21 07:54:25.757179 2026] [security2:error] [pid 341679:tid 341814] [client 74.249.245.134:65120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/themes.php"] [unique_id "al9P4QWat-noHLkDuAhyXAAAAQ8"]
[Tue Jul 21 07:54:26.159872 2026] [security2:error] [pid 341679:tid 341847] [client 20.226.60.151:56764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/v543.php"] [unique_id "al9P4gWat-noHLkDuAhyZwAAATA"]
[Tue Jul 21 07:54:26.463266 2026] [security2:error] [pid 341679:tid 341879] [client 103.86.117.203:58615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P4gWat-noHLkDuAhybwAAAVA"]
[Tue Jul 21 07:54:26.463380 2026] [security2:error] [pid 341679:tid 341879] [client 103.86.117.203:58615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P4gWat-noHLkDuAhybwAAAVA"]
[Tue Jul 21 07:54:26.504384 2026] [security2:error] [pid 341679:tid 341696] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9P4gWat-noHLkDuAhycgABRBA"]
[Tue Jul 21 07:54:26.504518 2026] [security2:error] [pid 341679:tid 341867] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9P4gWat-noHLkDuAhycgABRBA"]
[Tue Jul 21 07:54:26.805751 2026] [security2:error] [pid 341679:tid 341701] [remote 173.239.254.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.254.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amandamorau.adv.br"] [uri "/wp-login.php"] [unique_id "al9P4gWat-noHLkDuAhydAABVRU"]
[Tue Jul 21 07:54:26.809908 2026] [security2:error] [pid 341679:tid 341844] [client 136.144.33.101:60179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9P4gWat-noHLkDuAhyewAAAS0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:26.848486 2026] [security2:error] [pid 341679:tid 341894] [client 20.104.96.117:55038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/6.php"] [unique_id "al9P4gWat-noHLkDuAhyfwAAAV8"]
[Tue Jul 21 07:54:26.939237 2026] [security2:error] [pid 341679:tid 341832] [client 4.204.201.85:48105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/lib.php"] [unique_id "al9P4gWat-noHLkDuAhyhQAAASE"]
[Tue Jul 21 07:54:27.733739 2026] [security2:error] [pid 341679:tid 341914] [client 20.104.96.117:55014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9P4wWat-noHLkDuAhymQAAAXM"]
[Tue Jul 21 07:54:27.851286 2026] [security2:error] [pid 341679:tid 341889] [client 4.204.201.85:63178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/login.php"] [unique_id "al9P4wWat-noHLkDuAhyqAAAAVo"]
[Tue Jul 21 07:54:28.040274 2026] [security2:error] [pid 341679:tid 341813] [client 172.245.102.29:35223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9P4gWat-noHLkDuAhygAAAAQ4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:54:28.512082 2026] [security2:error] [pid 341679:tid 341859] [client 114.119.157.43:35461] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.politicabrasil.com.br"] [uri "/post/prefeito-de-barbalha-denuncia-d%C3%ADvida-de-energia-de-mais-de-r-3-milh%C3%B5es-deixada-pelo-seu-antecessor"] [unique_id "al9P5AWat-noHLkDuAhyzwAAATw"], referer: https://www.politicabrasil.com.br/blogentrelinhas/tags/prefeito-de-barbalha
[Tue Jul 21 07:54:28.562727 2026] [security2:error] [pid 341679:tid 341836] [client 114.119.144.105:31085] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ssvistorias.com.br"] [uri "/zgkb.php"] [unique_id "al9P5AWat-noHLkDuAhy0AAAASU"], referer: http://www.ssvistorias.com.br/zgkb.php?educate/monthly_setfnnuurm-19/pgid=23373
[Tue Jul 21 07:54:28.591023 2026] [security2:error] [pid 341679:tid 341884] [client 122.162.144.145:21612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9P5AWat-noHLkDuAhy0QAAAVU"]
[Tue Jul 21 07:54:28.591126 2026] [security2:error] [pid 341679:tid 341884] [client 122.162.144.145:21612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9P5AWat-noHLkDuAhy0QAAAVU"]
[Tue Jul 21 07:54:28.626151 2026] [security2:error] [pid 341679:tid 341682] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5AWat-noHLkDuAhy0gABJAI"]
[Tue Jul 21 07:54:28.626304 2026] [security2:error] [pid 341679:tid 341835] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5AWat-noHLkDuAhy0gABJAI"]
[Tue Jul 21 07:54:28.628617 2026] [security2:error] [pid 341679:tid 341914] [client 4.204.201.85:48095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/a2.php"] [unique_id "al9P5AWat-noHLkDuAhy0wAAAXM"]
[Tue Jul 21 07:54:28.665313 2026] [security2:error] [pid 341679:tid 341936] [client 178.153.91.96:54428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9P5AWat-noHLkDuAhy1QAAAYk"]
[Tue Jul 21 07:54:28.665447 2026] [security2:error] [pid 341679:tid 341936] [client 178.153.91.96:54428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9P5AWat-noHLkDuAhy1QAAAYk"]
[Tue Jul 21 07:54:28.939351 2026] [security2:error] [pid 341679:tid 341868] [client 20.206.105.145:55810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/ingfo.php"] [unique_id "al9P5AWat-noHLkDuAhy3QAAAUU"]
[Tue Jul 21 07:54:28.972082 2026] [security2:error] [pid 341679:tid 341821] [client 223.236.153.128:7085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9P5AWat-noHLkDuAhy3gAAARY"]
[Tue Jul 21 07:54:28.972203 2026] [security2:error] [pid 341679:tid 341821] [client 223.236.153.128:7085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9P5AWat-noHLkDuAhy3gAAARY"]
[Tue Jul 21 07:54:29.018794 2026] [security2:error] [pid 341679:tid 341842] [client 20.104.96.117:55017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/qqqa.php"] [unique_id "al9P5QWat-noHLkDuAhy4gAAASs"]
[Tue Jul 21 07:54:29.046019 2026] [security2:error] [pid 341679:tid 341882] [client 20.226.60.151:50679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/sixxis.php"] [unique_id "al9P5QWat-noHLkDuAhy4wAAAVM"]
[Tue Jul 21 07:54:29.292764 2026] [security2:error] [pid 341679:tid 341849] [client 4.204.201.85:63210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/d61.php"] [unique_id "al9P5QWat-noHLkDuAhy6gAAATI"]
[Tue Jul 21 07:54:29.307022 2026] [security2:error] [pid 341679:tid 341846] [client 117.247.80.59:12818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5QWat-noHLkDuAhy7AAAAS8"]
[Tue Jul 21 07:54:29.307138 2026] [security2:error] [pid 341679:tid 341846] [client 117.247.80.59:12818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5QWat-noHLkDuAhy7AAAAS8"]
[Tue Jul 21 07:54:29.362481 2026] [security2:error] [pid 341679:tid 341918] [client 139.167.225.182:61601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5QWat-noHLkDuAhy8QAAAXc"]
[Tue Jul 21 07:54:29.362571 2026] [security2:error] [pid 341679:tid 341918] [client 139.167.225.182:61601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5QWat-noHLkDuAhy8QAAAXc"]
[Tue Jul 21 07:54:29.422080 2026] [security2:error] [pid 341679:tid 341935] [client 117.217.38.194:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5QWat-noHLkDuAhy8wAAAYg"]
[Tue Jul 21 07:54:29.422206 2026] [security2:error] [pid 341679:tid 341935] [client 117.217.38.194:51620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5QWat-noHLkDuAhy8wAAAYg"]
[Tue Jul 21 07:54:29.551053 2026] [security2:error] [pid 341679:tid 341724] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5QWat-noHLkDuAhy-gABKiw"]
[Tue Jul 21 07:54:29.551176 2026] [security2:error] [pid 341679:tid 341841] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5QWat-noHLkDuAhy-gABKiw"]
[Tue Jul 21 07:54:29.612050 2026] [security2:error] [pid 341679:tid 341830] [client 20.197.192.193:62021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9P5QWat-noHLkDuAhy_AAAAR8"]
[Tue Jul 21 07:54:29.731970 2026] [security2:error] [pid 341679:tid 341929] [client 103.166.103.129:45159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9P5QWat-noHLkDuAhy_wAAAYI"]
[Tue Jul 21 07:54:29.732119 2026] [security2:error] [pid 341679:tid 341929] [client 103.166.103.129:45159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9P5QWat-noHLkDuAhy_wAAAYI"]
[Tue Jul 21 07:54:29.930628 2026] [security2:error] [pid 341679:tid 341902] [client 20.197.192.193:61127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9P5QWat-noHLkDuAhzBgAAAWc"]
[Tue Jul 21 07:54:29.956562 2026] [security2:error] [pid 341679:tid 341814] [client 4.204.201.85:63121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/info.php"] [unique_id "al9P5QWat-noHLkDuAhzBwAAAQ8"]
[Tue Jul 21 07:54:29.969997 2026] [security2:error] [pid 341679:tid 341847] [client 173.24.185.52:56465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9P5QWat-noHLkDuAhzCAAAATA"]
[Tue Jul 21 07:54:29.970094 2026] [security2:error] [pid 341679:tid 341847] [client 173.24.185.52:56465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9P5QWat-noHLkDuAhzCAAAATA"]
[Tue Jul 21 07:54:30.116528 2026] [security2:error] [pid 341679:tid 341860] [client 20.104.96.117:57432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/aunmc.php"] [unique_id "al9P5gWat-noHLkDuAhzDAAAAT0"]
[Tue Jul 21 07:54:30.117581 2026] [security2:error] [pid 341679:tid 341699] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5gWat-noHLkDuAhzDgABUBM"]
[Tue Jul 21 07:54:30.117717 2026] [security2:error] [pid 341679:tid 341879] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5gWat-noHLkDuAhzDgABUBM"]
[Tue Jul 21 07:54:30.245186 2026] [security2:error] [pid 341679:tid 341689] [remote 114.119.155.228:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.naturofarma.com.br"] [uri "/imagem.php"] [unique_id "al9P5gWat-noHLkDuAhzGgABSgk"], referer: https://www.naturofarma.com.br/imagem.php?tipo=8&cod_img=176258
[Tue Jul 21 07:54:30.311737 2026] [security2:error] [pid 341679:tid 341898] [client 4.204.201.85:48081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/11.php"] [unique_id "al9P5gWat-noHLkDuAhzHgAAAWM"]
[Tue Jul 21 07:54:30.316154 2026] [security2:error] [pid 341679:tid 341849] [client 20.197.192.193:50881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/dp.php"] [unique_id "al9P5gWat-noHLkDuAhzHwAAATI"]
[Tue Jul 21 07:54:30.443104 2026] [security2:error] [pid 341679:tid 341792] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5gWat-noHLkDuAhzJwABSHA"]
[Tue Jul 21 07:54:30.443226 2026] [security2:error] [pid 341679:tid 341871] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5gWat-noHLkDuAhzJwABSHA"]
[Tue Jul 21 07:54:30.481282 2026] [security2:error] [pid 341679:tid 341895] [client 103.78.200.11:64204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5gWat-noHLkDuAhzKAAAAWA"]
[Tue Jul 21 07:54:30.481458 2026] [security2:error] [pid 341679:tid 341895] [client 103.78.200.11:64204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5gWat-noHLkDuAhzKAAAAWA"]
[Tue Jul 21 07:54:30.581429 2026] [security2:error] [pid 341679:tid 341827] [client 136.144.33.53:45595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9P5gWat-noHLkDuAhzKgAAARw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:30.632061 2026] [security2:error] [pid 341679:tid 341916] [client 20.197.192.193:62064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/old.php"] [unique_id "al9P5gWat-noHLkDuAhzLwAAAXU"]
[Tue Jul 21 07:54:30.679985 2026] [security2:error] [pid 341679:tid 341921] [client 4.204.201.85:48059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/v2.php"] [unique_id "al9P5gWat-noHLkDuAhzMAAAAXo"]
[Tue Jul 21 07:54:30.990147 2026] [security2:error] [pid 341679:tid 341856] [client 20.197.192.193:50906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/ms-new.php"] [unique_id "al9P5gWat-noHLkDuAhzPQAAATk"]
[Tue Jul 21 07:54:31.095412 2026] [security2:error] [pid 341679:tid 341864] [client 149.18.81.114:33405] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 114.81.18.149.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9P5gWat-noHLkDuAhzOgAAAUE"]
[Tue Jul 21 07:54:31.095550 2026] [security2:error] [pid 341679:tid 341864] [client 149.18.81.114:33405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "klvviagens.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9P5gWat-noHLkDuAhzOgAAAUE"]
[Tue Jul 21 07:54:31.221053 2026] [security2:error] [pid 341679:tid 341830] [client 41.68.90.219:55579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5wWat-noHLkDuAhzRAAAAR8"]
[Tue Jul 21 07:54:31.222183 2026] [security2:error] [pid 341679:tid 341830] [client 41.68.90.219:55579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P5wWat-noHLkDuAhzRAAAAR8"]
[Tue Jul 21 07:54:31.268174 2026] [security2:error] [pid 341679:tid 341840] [client 4.204.201.85:63166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/panel.php"] [unique_id "al9P5wWat-noHLkDuAhzRgAAASk"]
[Tue Jul 21 07:54:31.305968 2026] [security2:error] [pid 341679:tid 341873] [client 20.197.192.193:29821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/track.php"] [unique_id "al9P5wWat-noHLkDuAhzRwAAAUo"]
[Tue Jul 21 07:54:31.646746 2026] [security2:error] [pid 341679:tid 341871] [client 20.197.192.193:61169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/2352356666.php"] [unique_id "al9P5wWat-noHLkDuAhzUQAAAUg"]
[Tue Jul 21 07:54:31.699606 2026] [security2:error] [pid 341679:tid 341848] [client 122.186.204.214:60341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P5wWat-noHLkDuAhzVAAAATE"]
[Tue Jul 21 07:54:31.699746 2026] [security2:error] [pid 341679:tid 341848] [client 122.186.204.214:60341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P5wWat-noHLkDuAhzVAAAATE"]
[Tue Jul 21 07:54:31.711792 2026] [security2:error] [pid 341679:tid 341817] [client 20.197.192.193:29760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/pn.php"] [unique_id "al9P5wWat-noHLkDuAhzVgAAARI"]
[Tue Jul 21 07:54:31.866246 2026] [security2:error] [pid 341679:tid 341820] [client 4.204.201.85:63161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/dex.php"] [unique_id "al9P5wWat-noHLkDuAhzWgAAARU"]
[Tue Jul 21 07:54:31.945147 2026] [security2:error] [pid 341679:tid 341916] [client 20.197.192.193:29990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9P5wWat-noHLkDuAhzXAAAAXU"]
[Tue Jul 21 07:54:31.963390 2026] [security2:error] [pid 341679:tid 341903] [client 114.119.131.248:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sobradoimoveis.com"] [uri "/imovel/terreno-venda-gloria-joinville-sc-v79774"] [unique_id "al9P5wWat-noHLkDuAhzXQAAAWg"], referer: https://sobradoimoveis.com
[Tue Jul 21 07:54:32.075188 2026] [security2:error] [pid 341679:tid 341885] [client 20.226.60.151:61559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/sid4.php"] [unique_id "al9P6AWat-noHLkDuAhzZAAAAVY"]
[Tue Jul 21 07:54:32.144969 2026] [security2:error] [pid 341679:tid 341898] [client 106.215.181.8:25959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P6AWat-noHLkDuAhzaAAAAWM"]
[Tue Jul 21 07:54:32.149647 2026] [security2:error] [pid 341679:tid 341898] [client 106.215.181.8:25959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P6AWat-noHLkDuAhzaAAAAWM"]
[Tue Jul 21 07:54:32.196086 2026] [security2:error] [pid 341679:tid 341924] [client 20.104.96.117:55003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/uoocf.php"] [unique_id "al9P6AWat-noHLkDuAhzagAAAX0"]
[Tue Jul 21 07:54:32.355867 2026] [security2:error] [pid 341679:tid 341936] [client 20.197.192.193:62040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/dr.php"] [unique_id "al9P6AWat-noHLkDuAhzawAAAYk"]
[Tue Jul 21 07:54:32.473802 2026] [security2:error] [pid 341679:tid 341802] [remote 144.217.254.10:52716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.254.217.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fgengenharia.eng.br"] [uri "/wp-login.php"] [unique_id "al9P6AWat-noHLkDuAhzbgABZ3o"]
[Tue Jul 21 07:54:32.478149 2026] [security2:error] [pid 341679:tid 341805] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9P6AWat-noHLkDuAhzbwABcX0"]
[Tue Jul 21 07:54:32.478284 2026] [security2:error] [pid 341679:tid 341912] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9P6AWat-noHLkDuAhzbwABcX0"]
[Tue Jul 21 07:54:32.518968 2026] [security2:error] [pid 341679:tid 341869] [client 20.197.192.193:29788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/2x.php"] [unique_id "al9P6AWat-noHLkDuAhzcgAAAUY"]
[Tue Jul 21 07:54:32.618726 2026] [security2:error] [pid 341679:tid 341889] [client 20.197.192.193:62060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/kq1.php"] [unique_id "al9P6AWat-noHLkDuAhzdQAAAVo"]
[Tue Jul 21 07:54:32.670717 2026] [security2:error] [pid 341679:tid 341842] [client 20.197.192.193:29782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/zzz.php"] [unique_id "al9P6AWat-noHLkDuAhzdwAAASs"]
[Tue Jul 21 07:54:32.703315 2026] [security2:error] [pid 341679:tid 341824] [client 4.204.201.85:63124] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "folegofinanceiro.com.br"] [uri "/1.php"] [unique_id "al9P6AWat-noHLkDuAhzeAAAARk"]
[Tue Jul 21 07:54:32.703443 2026] [security2:error] [pid 341679:tid 341824] [client 4.204.201.85:63124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/1.php"] [unique_id "al9P6AWat-noHLkDuAhzeAAAARk"]
[Tue Jul 21 07:54:32.719014 2026] [security2:error] [pid 341679:tid 341860] [client 20.197.192.193:50943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wicked.php"] [unique_id "al9P6AWat-noHLkDuAhzegAAAT0"]
[Tue Jul 21 07:54:32.742803 2026] [security2:error] [pid 341679:tid 341778] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P6AWat-noHLkDuAhzewABT2I"]
[Tue Jul 21 07:54:32.742952 2026] [security2:error] [pid 341679:tid 341878] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P6AWat-noHLkDuAhzewABT2I"]
[Tue Jul 21 07:54:32.797611 2026] [security2:error] [pid 341679:tid 341813] [client 20.220.225.223:19299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9P6AWat-noHLkDuAhzfwAAAQ4"]
[Tue Jul 21 07:54:32.806730 2026] [security2:error] [pid 341679:tid 341809] [client 20.197.192.193:62077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/edit.php"] [unique_id "al9P6AWat-noHLkDuAhzgAAAAQo"]
[Tue Jul 21 07:54:32.883685 2026] [security2:error] [pid 341679:tid 341934] [client 20.197.192.193:29797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/kua.php"] [unique_id "al9P6AWat-noHLkDuAhzgQAAAYc"]
[Tue Jul 21 07:54:33.190801 2026] [security2:error] [pid 341679:tid 341851] [client 20.197.192.193:29804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/ez.php"] [unique_id "al9P6QWat-noHLkDuAhziwAAATQ"]
[Tue Jul 21 07:54:33.267962 2026] [security2:error] [pid 341679:tid 341703] [remote 161.35.232.153:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.232.35.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9P6QWat-noHLkDuAhzjAABDBc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:54:33.299305 2026] [security2:error] [pid 341679:tid 341825] [client 20.197.192.193:62068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/fz.php"] [unique_id "al9P6QWat-noHLkDuAhzkgAAARo"]
[Tue Jul 21 07:54:33.306056 2026] [security2:error] [pid 341679:tid 341796] [remote 161.35.232.153:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.232.35.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9P6QWat-noHLkDuAhzhwABdXQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:54:33.307005 2026] [security2:error] [pid 341679:tid 341681] [remote 161.35.232.153:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.232.35.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9P6QWat-noHLkDuAhziAABYAE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:54:33.316330 2026] [security2:error] [pid 341679:tid 341710] [remote 161.35.232.153:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.232.35.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9P6QWat-noHLkDuAhziQABbx4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:54:33.328518 2026] [security2:error] [pid 341679:tid 341871] [client 109.60.28.94:52434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P6QWat-noHLkDuAhzkwAAAUg"]
[Tue Jul 21 07:54:33.329326 2026] [security2:error] [pid 341679:tid 341871] [client 109.60.28.94:52434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P6QWat-noHLkDuAhzkwAAAUg"]
[Tue Jul 21 07:54:33.405318 2026] [security2:error] [pid 341679:tid 341892] [client 4.204.201.85:48068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/ms.php"] [unique_id "al9P6QWat-noHLkDuAhzlAAAAV0"]
[Tue Jul 21 07:54:33.413541 2026] [security2:error] [pid 341679:tid 341914] [client 20.197.192.193:50920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/la.php"] [unique_id "al9P6QWat-noHLkDuAhzlQAAAXM"]
[Tue Jul 21 07:54:33.440831 2026] [security2:error] [pid 341679:tid 341814] [client 20.206.105.145:55832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/error_log.php"] [unique_id "al9P6QWat-noHLkDuAhzlwAAAQ8"]
[Tue Jul 21 07:54:33.476256 2026] [security2:error] [pid 341679:tid 341869] [client 20.197.192.193:62070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9P6QWat-noHLkDuAhzmAAAAUY"]
[Tue Jul 21 07:54:33.500958 2026] [security2:error] [pid 341679:tid 341923] [client 193.36.225.151:62085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9P5wWat-noHLkDuAhzSQAAAXw"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:54:33.517967 2026] [security2:error] [pid 341679:tid 341683] [remote 161.35.232.153:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.232.35.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9P6QWat-noHLkDuAhzmQABUQM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:54:33.535841 2026] [security2:error] [pid 341679:tid 341827] [client 202.143.127.214:64647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P6QWat-noHLkDuAhzmgAAARw"]
[Tue Jul 21 07:54:33.535943 2026] [security2:error] [pid 341679:tid 341827] [client 202.143.127.214:64647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P6QWat-noHLkDuAhzmgAAARw"]
[Tue Jul 21 07:54:33.552229 2026] [security2:error] [pid 341679:tid 341760] [remote 161.35.232.153:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.232.35.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9P6QWat-noHLkDuAhzmwABC1A"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:54:33.563844 2026] [security2:error] [pid 341679:tid 341889] [client 20.197.192.193:61161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/inso.php"] [unique_id "al9P6QWat-noHLkDuAhznwAAAVo"]
[Tue Jul 21 07:54:33.577242 2026] [security2:error] [pid 341679:tid 341807] [remote 161.35.232.153:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.232.35.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9P6QWat-noHLkDuAhzoAABEH8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:54:33.597521 2026] [security2:error] [pid 341679:tid 341906] [client 114.119.154.67:56947] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acaiofficial.com.br"] [uri "/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/"] [unique_id "al9P6QWat-noHLkDuAhzogAAAWs"], referer: https://acaiofficial.com.br/wp-includes/sodium_compat/src/Core32/Curve25519/Ge/?SD
[Tue Jul 21 07:54:33.601581 2026] [security2:error] [pid 341679:tid 341927] [client 182.8.255.181:21101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9P6QWat-noHLkDuAhzowAAAYA"]
[Tue Jul 21 07:54:33.601681 2026] [security2:error] [pid 341679:tid 341927] [client 182.8.255.181:21101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9P6QWat-noHLkDuAhzowAAAYA"]
[Tue Jul 21 07:54:33.647630 2026] [security2:error] [pid 341679:tid 341878] [client 20.197.192.193:61143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wpx.php"] [unique_id "al9P6QWat-noHLkDuAhzpAAAAU8"]
[Tue Jul 21 07:54:33.700137 2026] [security2:error] [pid 341679:tid 341777] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9P6QWat-noHLkDuAhzpQABZ2E"]
[Tue Jul 21 07:54:33.700256 2026] [security2:error] [pid 341679:tid 341902] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9P6QWat-noHLkDuAhzpQABZ2E"]
[Tue Jul 21 07:54:33.766384 2026] [security2:error] [pid 341679:tid 341714] [remote 161.35.232.153:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.232.35.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9P6QWat-noHLkDuAhzrQABdiI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:54:33.802043 2026] [security2:error] [pid 341679:tid 341852] [client 103.29.114.44:51822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P6QWat-noHLkDuAhzrgAAATU"]
[Tue Jul 21 07:54:33.802129 2026] [security2:error] [pid 341679:tid 341852] [client 103.29.114.44:51822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P6QWat-noHLkDuAhzrgAAATU"]
[Tue Jul 21 07:54:33.855830 2026] [security2:error] [pid 341679:tid 341858] [client 20.197.192.193:29954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/berlin.php"] [unique_id "al9P6QWat-noHLkDuAhzsAAAATs"]
[Tue Jul 21 07:54:33.947466 2026] [security2:error] [pid 341679:tid 341709] [remote 161.35.232.153:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.232.35.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9P6QWat-noHLkDuAhztgABNh0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:54:34.050065 2026] [security2:error] [pid 341679:tid 341881] [client 20.226.60.151:56773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/ip.php"] [unique_id "al9P6gWat-noHLkDuAhzvQAAAVI"]
[Tue Jul 21 07:54:34.068238 2026] [security2:error] [pid 341679:tid 341870] [client 4.204.201.85:63126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/memberfuns.php"] [unique_id "al9P6gWat-noHLkDuAhzwAAAAUc"]
[Tue Jul 21 07:54:34.102894 2026] [security2:error] [pid 341679:tid 341929] [client 122.179.91.63:11523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9P6gWat-noHLkDuAhzwwAAAYI"]
[Tue Jul 21 07:54:34.102994 2026] [security2:error] [pid 341679:tid 341929] [client 122.179.91.63:11523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9P6gWat-noHLkDuAhzwwAAAYI"]
[Tue Jul 21 07:54:34.194624 2026] [security2:error] [pid 341679:tid 341722] [remote 161.35.232.153:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.232.35.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9P6gWat-noHLkDuAhzyQABKio"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:54:34.292474 2026] [security2:error] [pid 341679:tid 341818] [client 20.197.192.193:29991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/billur.php"] [unique_id "al9P6gWat-noHLkDuAhzzwAAARM"]
[Tue Jul 21 07:54:34.329036 2026] [security2:error] [pid 341679:tid 341705] [remote 65.111.20.10:60531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9P6gWat-noHLkDuAhzyAABTBk"]
[Tue Jul 21 07:54:34.460319 2026] [security2:error] [pid 341679:tid 341905] [client 193.36.225.68:54647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9P6gWat-noHLkDuAhzzQAAAWo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:34.647384 2026] [security2:error] [pid 341679:tid 341889] [client 20.197.192.193:29957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/mimpi.php"] [unique_id "al9P6gWat-noHLkDuAhz1wAAAVo"]
[Tue Jul 21 07:54:34.835193 2026] [security2:error] [pid 341679:tid 341716] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9P6gWat-noHLkDuAhz3QABESQ"]
[Tue Jul 21 07:54:34.835344 2026] [security2:error] [pid 341679:tid 341816] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9P6gWat-noHLkDuAhz3QABESQ"]
[Tue Jul 21 07:54:34.933128 2026] [security2:error] [pid 341679:tid 341872] [client 20.197.192.193:64466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/edit.php"] [unique_id "al9P6gWat-noHLkDuAhz3gAAAUk"]
[Tue Jul 21 07:54:35.057007 2026] [security2:error] [pid 341679:tid 341914] [client 102.206.115.33:59896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9P6wWat-noHLkDuAhz4AAAAXM"]
[Tue Jul 21 07:54:35.057114 2026] [security2:error] [pid 341679:tid 341914] [client 102.206.115.33:59896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9P6wWat-noHLkDuAhz4AAAAXM"]
[Tue Jul 21 07:54:35.107044 2026] [security2:error] [pid 341679:tid 341830] [client 20.197.192.193:61181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/dp.php"] [unique_id "al9P6wWat-noHLkDuAhz4QAAAR8"]
[Tue Jul 21 07:54:35.180738 2026] [security2:error] [pid 341679:tid 341934] [client 4.204.201.85:63186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/0.php"] [unique_id "al9P6wWat-noHLkDuAhz5gAAAYc"]
[Tue Jul 21 07:54:35.322746 2026] [security2:error] [pid 341679:tid 341893] [client 20.197.192.193:29113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/bootstrap.php"] [unique_id "al9P6wWat-noHLkDuAhz6AAAAV4"]
[Tue Jul 21 07:54:35.349652 2026] [security2:error] [pid 341679:tid 341877] [client 20.197.192.193:50909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wp-editor.php"] [unique_id "al9P6wWat-noHLkDuAhz7QAAAU4"]
[Tue Jul 21 07:54:35.384555 2026] [security2:error] [pid 341679:tid 341881] [client 20.197.192.193:50929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/cro.php"] [unique_id "al9P6wWat-noHLkDuAhz7gAAAVI"]
[Tue Jul 21 07:54:35.417590 2026] [security2:error] [pid 341679:tid 341851] [client 20.197.192.193:62038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/cron-tab.php"] [unique_id "al9P6wWat-noHLkDuAhz7wAAATQ"]
[Tue Jul 21 07:54:35.463171 2026] [security2:error] [pid 341679:tid 341888] [client 20.197.192.193:50887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/koiy.php"] [unique_id "al9P6wWat-noHLkDuAhz8gAAAVk"]
[Tue Jul 21 07:54:35.567699 2026] [security2:error] [pid 341679:tid 341840] [client 122.164.127.47:61985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9P6wWat-noHLkDuAhz9QAAASk"]
[Tue Jul 21 07:54:35.568048 2026] [security2:error] [pid 341679:tid 341840] [client 122.164.127.47:61985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9P6wWat-noHLkDuAhz9QAAASk"]
[Tue Jul 21 07:54:35.645765 2026] [security2:error] [pid 341679:tid 341828] [client 20.197.192.193:62052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/hp2.php"] [unique_id "al9P6wWat-noHLkDuAhz-wAAAR0"]
[Tue Jul 21 07:54:35.695928 2026] [security2:error] [pid 341679:tid 341875] [client 204.8.98.45:49094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9P6wWat-noHLkDuAhz_QAAAUw"]
[Tue Jul 21 07:54:35.696015 2026] [security2:error] [pid 341679:tid 341875] [client 204.8.98.45:49094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9P6wWat-noHLkDuAhz_QAAAUw"]
[Tue Jul 21 07:54:35.696527 2026] [security2:error] [pid 341679:tid 341892] [client 4.204.201.85:48109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/BDKR28.php"] [unique_id "al9P6wWat-noHLkDuAhz_gAAAV0"]
[Tue Jul 21 07:54:35.723730 2026] [security2:error] [pid 341679:tid 341854] [client 20.104.96.117:55023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/iywwi.php"] [unique_id "al9P6wWat-noHLkDuAhz_wAAATc"]
[Tue Jul 21 07:54:35.825571 2026] [security2:error] [pid 341679:tid 341818] [client 51.68.111.219:20123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anjosolar.com.br"] [uri "/robots.txt"] [unique_id "al9P6wWat-noHLkDuAh0AAAAARM"]
[Tue Jul 21 07:54:35.825679 2026] [security2:error] [pid 341679:tid 341818] [client 51.68.111.219:20123] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "anjosolar.com.br"] [uri "/robots.txt"] [unique_id "al9P6wWat-noHLkDuAh0AAAAARM"]
[Tue Jul 21 07:54:35.874343 2026] [security2:error] [pid 341679:tid 341890] [client 20.197.192.193:62059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/hp3.php"] [unique_id "al9P6wWat-noHLkDuAh0BAAAAVs"]
[Tue Jul 21 07:54:35.914152 2026] [security2:error] [pid 341679:tid 341821] [client 20.197.192.193:61164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/aa1.php"] [unique_id "al9P6wWat-noHLkDuAh0BQAAARY"]
[Tue Jul 21 07:54:35.930935 2026] [security2:error] [pid 341679:tid 341878] [client 20.197.192.193:50936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/acew67.php"] [unique_id "al9P6wWat-noHLkDuAh0BgAAAU8"]
[Tue Jul 21 07:54:35.965491 2026] [security2:error] [pid 341679:tid 341845] [client 20.197.192.193:61155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/bscclapb.php"] [unique_id "al9P6wWat-noHLkDuAh0BwAAAS4"]
[Tue Jul 21 07:54:36.040764 2026] [security2:error] [pid 341679:tid 341907] [client 20.197.192.193:61150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/else1.php"] [unique_id "al9P7AWat-noHLkDuAh0CAAAAWw"]
[Tue Jul 21 07:54:36.097579 2026] [security2:error] [pid 341679:tid 341914] [client 20.197.192.193:29771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/tkikikoko.php"] [unique_id "al9P7AWat-noHLkDuAh0CQAAAXM"]
[Tue Jul 21 07:54:36.139593 2026] [security2:error] [pid 341679:tid 341933] [client 20.197.192.193:61171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9P7AWat-noHLkDuAh0DQAAAYY"]
[Tue Jul 21 07:54:36.288468 2026] [security2:error] [pid 341679:tid 341893] [client 20.226.60.151:56706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/kq1.php"] [unique_id "al9P7AWat-noHLkDuAh0EAAAAV4"]
[Tue Jul 21 07:54:36.303765 2026] [security2:error] [pid 341679:tid 341809] [client 20.197.192.193:61149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wp-css.php"] [unique_id "al9P7AWat-noHLkDuAh0EQAAAQo"]
[Tue Jul 21 07:54:36.349630 2026] [security2:error] [pid 341679:tid 341835] [client 4.204.201.85:48022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/green1.php"] [unique_id "al9P7AWat-noHLkDuAh0FAAAASQ"]
[Tue Jul 21 07:54:36.421825 2026] [security2:error] [pid 341679:tid 341763] [remote 72.167.132.114:44158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thiagomartins.com"] [uri "/wp-login.php"] [unique_id "al9P7AWat-noHLkDuAh0GAABg1M"]
[Tue Jul 21 07:54:36.594828 2026] [security2:error] [pid 341679:tid 341921] [client 20.197.192.193:61120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/wp-explorer.php"] [unique_id "al9P7AWat-noHLkDuAh0GgAAAXo"]
[Tue Jul 21 07:54:36.800862 2026] [security2:error] [pid 341679:tid 341811] [client 20.197.192.193:61135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/akismet.php"] [unique_id "al9P7AWat-noHLkDuAh0IQAAAQw"]
[Tue Jul 21 07:54:36.843506 2026] [security2:error] [pid 341679:tid 341882] [client 20.197.192.193:61131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/ace2.php"] [unique_id "al9P7AWat-noHLkDuAh0IwAAAVM"]
[Tue Jul 21 07:54:36.862045 2026] [security2:error] [pid 341679:tid 341857] [client 20.104.96.117:54981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/gqgsa.php"] [unique_id "al9P7AWat-noHLkDuAh0JQAAATo"]
[Tue Jul 21 07:54:36.873744 2026] [security2:error] [pid 341679:tid 341898] [client 74.249.245.134:24786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/dropdown.php"] [unique_id "al9P7AWat-noHLkDuAh0JgAAAWM"]
[Tue Jul 21 07:54:36.922285 2026] [security2:error] [pid 341679:tid 341884] [client 20.197.192.193:62030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "weseguro.com.br"] [uri "/ms.php"] [unique_id "al9P7AWat-noHLkDuAh0KAAAAVU"]
[Tue Jul 21 07:54:36.945124 2026] [security2:error] [pid 341679:tid 341934] [client 103.86.117.203:59156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P7AWat-noHLkDuAh0KwAAAYc"]
[Tue Jul 21 07:54:36.945234 2026] [security2:error] [pid 341679:tid 341934] [client 103.86.117.203:59156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P7AWat-noHLkDuAh0KwAAAYc"]
[Tue Jul 21 07:54:36.956930 2026] [security2:error] [pid 341679:tid 341913] [client 4.204.201.85:48127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/nc4.php"] [unique_id "al9P7AWat-noHLkDuAh0LAAAAXI"]
[Tue Jul 21 07:54:37.123967 2026] [security2:error] [pid 341679:tid 341741] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9P7QWat-noHLkDuAh0LgABID0"]
[Tue Jul 21 07:54:37.124185 2026] [security2:error] [pid 341679:tid 341831] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9P7QWat-noHLkDuAh0LgABID0"]
[Tue Jul 21 07:54:37.636155 2026] [security2:error] [pid 341679:tid 341863] [client 4.204.201.85:63109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/a1.php"] [unique_id "al9P7QWat-noHLkDuAh0QQAAAUA"]
[Tue Jul 21 07:54:37.999599 2026] [security2:error] [pid 341679:tid 341902] [client 218.190.242.173:15829] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "benattiodontologia.com.br"] [uri "/site/wp-content/uploads/2019/07/protese-fixa-2.jpg"] [unique_id "al9P7QWat-noHLkDuAh0SQAAAWc"]
[Tue Jul 21 07:54:38.200795 2026] [security2:error] [pid 341679:tid 341929] [client 136.144.33.215:48967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9P7gWat-noHLkDuAh0TQAAAYI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:38.411949 2026] [security2:error] [pid 341679:tid 341821] [client 65.111.31.218:49623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.31.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9P7gWat-noHLkDuAh0UgAAARY"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:54:38.574393 2026] [security2:error] [pid 341679:tid 341884] [client 4.204.201.85:48093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/eee.php"] [unique_id "al9P7gWat-noHLkDuAh0WQAAAVU"]
[Tue Jul 21 07:54:39.136111 2026] [security2:error] [pid 341679:tid 341857] [client 178.153.91.96:52390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9P7wWat-noHLkDuAh0ZwAAATo"]
[Tue Jul 21 07:54:39.136231 2026] [security2:error] [pid 341679:tid 341857] [client 178.153.91.96:52390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9P7wWat-noHLkDuAh0ZwAAATo"]
[Tue Jul 21 07:54:39.391461 2026] [security2:error] [pid 341679:tid 341848] [client 4.204.201.85:47968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wp-aothait.php"] [unique_id "al9P7wWat-noHLkDuAh0cwAAATE"]
[Tue Jul 21 07:54:39.485833 2026] [security2:error] [pid 341679:tid 341902] [client 74.249.245.134:65115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-links.php"] [unique_id "al9P7wWat-noHLkDuAh0dQAAAWc"]
[Tue Jul 21 07:54:39.520500 2026] [security2:error] [pid 341679:tid 341894] [client 122.162.144.145:13072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9P7wWat-noHLkDuAh0dgAAAV8"]
[Tue Jul 21 07:54:39.520660 2026] [security2:error] [pid 341679:tid 341894] [client 122.162.144.145:13072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9P7wWat-noHLkDuAh0dgAAAV8"]
[Tue Jul 21 07:54:39.576255 2026] [security2:error] [pid 341679:tid 341768] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P7wWat-noHLkDuAh0eQABElg"]
[Tue Jul 21 07:54:39.576405 2026] [security2:error] [pid 341679:tid 341817] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P7wWat-noHLkDuAh0eQABElg"]
[Tue Jul 21 07:54:39.640947 2026] [security2:error] [pid 341679:tid 341847] [client 223.236.153.128:2474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9P7wWat-noHLkDuAh0ewAAATA"]
[Tue Jul 21 07:54:39.641082 2026] [security2:error] [pid 341679:tid 341847] [client 223.236.153.128:2474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9P7wWat-noHLkDuAh0ewAAATA"]
[Tue Jul 21 07:54:39.739683 2026] [security2:error] [pid 341679:tid 341851] [client 20.226.60.151:56775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/fw/faiyy.php"] [unique_id "al9P7wWat-noHLkDuAh0fgAAATQ"]
[Tue Jul 21 07:54:39.894531 2026] [security2:error] [pid 341679:tid 341907] [client 117.217.38.194:52127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P7wWat-noHLkDuAh0gwAAAWw"]
[Tue Jul 21 07:54:39.894650 2026] [security2:error] [pid 341679:tid 341907] [client 117.217.38.194:52127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P7wWat-noHLkDuAh0gwAAAWw"]
[Tue Jul 21 07:54:39.910975 2026] [security2:error] [pid 341679:tid 341914] [client 117.247.80.59:13353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P7wWat-noHLkDuAh0hAAAAXM"]
[Tue Jul 21 07:54:39.911068 2026] [security2:error] [pid 341679:tid 341914] [client 117.247.80.59:13353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P7wWat-noHLkDuAh0hAAAAXM"]
[Tue Jul 21 07:54:40.066550 2026] [security2:error] [pid 341679:tid 341904] [client 4.204.201.85:63187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/config.json.php"] [unique_id "al9P8AWat-noHLkDuAh0hgAAAWk"]
[Tue Jul 21 07:54:40.158369 2026] [security2:error] [pid 341679:tid 341895] [client 20.104.96.117:55033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/elbzl.php"] [unique_id "al9P8AWat-noHLkDuAh0jQAAAWA"]
[Tue Jul 21 07:54:40.410181 2026] [security2:error] [pid 341679:tid 341877] [client 37.140.223.153:31945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9P8AWat-noHLkDuAh0jgAAAU4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:54:40.541642 2026] [security2:error] [pid 341679:tid 341854] [client 173.24.185.52:56936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9P8AWat-noHLkDuAh0kwAAATc"]
[Tue Jul 21 07:54:40.541745 2026] [security2:error] [pid 341679:tid 341854] [client 173.24.185.52:56936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9P8AWat-noHLkDuAh0kwAAATc"]
[Tue Jul 21 07:54:40.575734 2026] [security2:error] [pid 341679:tid 341891] [client 103.166.103.129:60902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9P8AWat-noHLkDuAh0lQAAAVw"]
[Tue Jul 21 07:54:40.575855 2026] [security2:error] [pid 341679:tid 341891] [client 103.166.103.129:60902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9P8AWat-noHLkDuAh0lQAAAVw"]
[Tue Jul 21 07:54:40.626680 2026] [security2:error] [pid 341679:tid 341781] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8AWat-noHLkDuAh0lwABgGU"]
[Tue Jul 21 07:54:40.626822 2026] [security2:error] [pid 341679:tid 341927] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8AWat-noHLkDuAh0lwABgGU"]
[Tue Jul 21 07:54:40.630785 2026] [security2:error] [pid 341679:tid 341888] [client 139.167.225.182:62260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8AWat-noHLkDuAh0mAAAAVk"]
[Tue Jul 21 07:54:40.630905 2026] [security2:error] [pid 341679:tid 341888] [client 139.167.225.182:62260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8AWat-noHLkDuAh0mAAAAVk"]
[Tue Jul 21 07:54:40.630970 2026] [security2:error] [pid 341679:tid 341776] [remote 192.241.143.148:39514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9P8AWat-noHLkDuAh0mgABFGA"]
[Tue Jul 21 07:54:40.652821 2026] [security2:error] [pid 341679:tid 341767] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8AWat-noHLkDuAh0nQABGVc"]
[Tue Jul 21 07:54:40.652966 2026] [security2:error] [pid 341679:tid 341824] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8AWat-noHLkDuAh0nQABGVc"]
[Tue Jul 21 07:54:40.660118 2026] [security2:error] [pid 341679:tid 341912] [client 4.204.201.85:48099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9P8AWat-noHLkDuAh0ngAAAXE"]
[Tue Jul 21 07:54:40.932599 2026] [security2:error] [pid 341679:tid 341844] [client 74.7.244.18:47970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "leoamaraldev.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9P8AWat-noHLkDuAh0rgABLRc"]
[Tue Jul 21 07:54:40.972229 2026] [security2:error] [pid 341679:tid 341796] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8AWat-noHLkDuAh0rwABL3Q"]
[Tue Jul 21 07:54:40.972366 2026] [security2:error] [pid 341679:tid 341846] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8AWat-noHLkDuAh0rwABL3Q"]
[Tue Jul 21 07:54:41.276716 2026] [security2:error] [pid 341679:tid 341905] [client 20.206.105.145:55808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/ok.php"] [unique_id "al9P8QWat-noHLkDuAh0vQAAAWo"]
[Tue Jul 21 07:54:41.382238 2026] [security2:error] [pid 341679:tid 341887] [client 103.78.200.11:64666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8QWat-noHLkDuAh0wAAAAVg"]
[Tue Jul 21 07:54:41.382329 2026] [security2:error] [pid 341679:tid 341887] [client 103.78.200.11:64666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8QWat-noHLkDuAh0wAAAAVg"]
[Tue Jul 21 07:54:41.546199 2026] [security2:error] [pid 341679:tid 341812] [client 20.226.60.151:56782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/h02ugyh.php"] [unique_id "al9P8QWat-noHLkDuAh0yQAAAQ0"]
[Tue Jul 21 07:54:41.654862 2026] [security2:error] [pid 341679:tid 341864] [client 193.36.225.60:58853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9P8QWat-noHLkDuAh0zQAAAUE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:41.721930 2026] [security2:error] [pid 341679:tid 341880] [client 4.204.201.85:48076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/k2.php"] [unique_id "al9P8QWat-noHLkDuAh00wAAAVE"]
[Tue Jul 21 07:54:41.899942 2026] [security2:error] [pid 341679:tid 341825] [client 41.68.90.219:56033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8QWat-noHLkDuAh02AAAARo"]
[Tue Jul 21 07:54:41.900862 2026] [security2:error] [pid 341679:tid 341825] [client 41.68.90.219:56033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8QWat-noHLkDuAh02AAAARo"]
[Tue Jul 21 07:54:42.033048 2026] [security2:error] [pid 341679:tid 341896] [client 74.249.245.134:64411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/xmrlpc.php"] [unique_id "al9P8gWat-noHLkDuAh03QAAAWE"]
[Tue Jul 21 07:54:42.325677 2026] [security2:error] [pid 341679:tid 341850] [client 4.204.201.85:48090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9P8gWat-noHLkDuAh04wAAATM"]
[Tue Jul 21 07:54:42.435802 2026] [security2:error] [pid 341679:tid 341933] [client 122.186.204.214:60874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P8gWat-noHLkDuAh06AAAAYY"]
[Tue Jul 21 07:54:42.435939 2026] [security2:error] [pid 341679:tid 341933] [client 122.186.204.214:60874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P8gWat-noHLkDuAh06AAAAYY"]
[Tue Jul 21 07:54:42.460530 2026] [security2:error] [pid 341679:tid 341889] [client 103.29.114.44:27630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8gWat-noHLkDuAh06wAAAVo"]
[Tue Jul 21 07:54:42.460648 2026] [security2:error] [pid 341679:tid 341889] [client 103.29.114.44:27630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8gWat-noHLkDuAh06wAAAVo"]
[Tue Jul 21 07:54:42.731408 2026] [security2:error] [pid 341679:tid 341935] [client 106.215.181.8:2488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8gWat-noHLkDuAh08AAAAYg"]
[Tue Jul 21 07:54:42.731560 2026] [security2:error] [pid 341679:tid 341935] [client 106.215.181.8:2488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8gWat-noHLkDuAh08AAAAYg"]
[Tue Jul 21 07:54:42.874110 2026] [security2:error] [pid 341679:tid 341818] [client 4.204.201.85:48033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9P8gWat-noHLkDuAh08gAAARM"]
[Tue Jul 21 07:54:43.241385 2026] [security2:error] [pid 341679:tid 341838] [client 4.204.201.85:48113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9P8wWat-noHLkDuAh0_wAAASc"]
[Tue Jul 21 07:54:43.342302 2026] [security2:error] [pid 341679:tid 341912] [client 92.119.178.3:57440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9P8wWat-noHLkDuAh1AAAAAXE"]
[Tue Jul 21 07:54:43.342424 2026] [security2:error] [pid 341679:tid 341912] [client 92.119.178.3:57440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9P8wWat-noHLkDuAh1AAAAAXE"]
[Tue Jul 21 07:54:43.374283 2026] [security2:error] [pid 341679:tid 341795] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8wWat-noHLkDuAh1AgABDnM"]
[Tue Jul 21 07:54:43.374435 2026] [security2:error] [pid 341679:tid 341813] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P8wWat-noHLkDuAh1AgABDnM"]
[Tue Jul 21 07:54:43.500718 2026] [security2:error] [pid 341679:tid 341749] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9P8wWat-noHLkDuAh1BAABDUU"]
[Tue Jul 21 07:54:43.500898 2026] [security2:error] [pid 341679:tid 341812] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9P8wWat-noHLkDuAh1BAABDUU"]
[Tue Jul 21 07:54:43.518638 2026] [security2:error] [pid 341679:tid 341836] [client 37.140.223.152:42013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9P8wWat-noHLkDuAh1AQAAASU"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:54:43.571773 2026] [security2:error] [pid 341679:tid 341830] [client 4.204.201.85:63139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/for.php"] [unique_id "al9P8wWat-noHLkDuAh1CAAAAR8"]
[Tue Jul 21 07:54:43.962985 2026] [security2:error] [pid 341679:tid 341864] [client 182.8.255.181:17685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9P8wWat-noHLkDuAh1DwAAAUE"]
[Tue Jul 21 07:54:43.963135 2026] [security2:error] [pid 341679:tid 341864] [client 182.8.255.181:17685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9P8wWat-noHLkDuAh1DwAAAUE"]
[Tue Jul 21 07:54:44.070578 2026] [security2:error] [pid 341679:tid 341821] [client 4.204.201.85:63127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/raw.php"] [unique_id "al9P9AWat-noHLkDuAh1GgAAARY"]
[Tue Jul 21 07:54:44.156439 2026] [security2:error] [pid 341679:tid 341889] [client 20.226.60.151:56743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-temp.php"] [unique_id "al9P9AWat-noHLkDuAh1HQAAAVo"]
[Tue Jul 21 07:54:44.164691 2026] [security2:error] [pid 341679:tid 341868] [client 109.60.28.94:52868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P9AWat-noHLkDuAh1HgAAAUU"]
[Tue Jul 21 07:54:44.164805 2026] [security2:error] [pid 341679:tid 341868] [client 109.60.28.94:52868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P9AWat-noHLkDuAh1HgAAAUU"]
[Tue Jul 21 07:54:44.478587 2026] [security2:error] [pid 341679:tid 341848] [client 122.179.91.63:26135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9P9AWat-noHLkDuAh1KwAAATE"]
[Tue Jul 21 07:54:44.478708 2026] [security2:error] [pid 341679:tid 341848] [client 122.179.91.63:26135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9P9AWat-noHLkDuAh1KwAAATE"]
[Tue Jul 21 07:54:44.511583 2026] [security2:error] [pid 341679:tid 341926] [client 20.104.96.117:54946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/adjig.php"] [unique_id "al9P9AWat-noHLkDuAh1LAAAAX8"]
[Tue Jul 21 07:54:44.748560 2026] [security2:error] [pid 341679:tid 341901] [client 202.143.127.214:65128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P9AWat-noHLkDuAh1NgAAAWY"]
[Tue Jul 21 07:54:44.748697 2026] [security2:error] [pid 341679:tid 341901] [client 202.143.127.214:65128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P9AWat-noHLkDuAh1NgAAAWY"]
[Tue Jul 21 07:54:44.854981 2026] [security2:error] [pid 341679:tid 341831] [client 20.206.105.145:55839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/mac.php"] [unique_id "al9P9AWat-noHLkDuAh1OwAAASA"]
[Tue Jul 21 07:54:45.044946 2026] [security2:error] [pid 341679:tid 341693] [remote 104.207.33.36:15937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9P9QWat-noHLkDuAh1PQABDg0"]
[Tue Jul 21 07:54:45.220025 2026] [security2:error] [pid 341679:tid 341835] [client 74.249.245.134:64083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/htaccess.php"] [unique_id "al9P9QWat-noHLkDuAh1RAAAASQ"]
[Tue Jul 21 07:54:45.243531 2026] [security2:error] [pid 341679:tid 341873] [client 20.220.225.223:19973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/wp-css.php"] [unique_id "al9P9QWat-noHLkDuAh1RQAAAUo"]
[Tue Jul 21 07:54:45.366783 2026] [security2:error] [pid 341679:tid 341906] [client 136.144.33.241:51235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9P9QWat-noHLkDuAh1SwAAAWs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:45.543384 2026] [security2:error] [pid 341679:tid 341845] [client 102.206.115.33:61377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9P9QWat-noHLkDuAh1UAAAAS4"]
[Tue Jul 21 07:54:45.543518 2026] [security2:error] [pid 341679:tid 341845] [client 102.206.115.33:61377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9P9QWat-noHLkDuAh1UAAAAS4"]
[Tue Jul 21 07:54:45.576986 2026] [security2:error] [pid 341679:tid 341913] [client 20.226.60.151:56802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-content/cong.php"] [unique_id "al9P9QWat-noHLkDuAh1UQAAAXI"]
[Tue Jul 21 07:54:45.579004 2026] [security2:error] [pid 341679:tid 341729] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9P9QWat-noHLkDuAh1UgABejE"]
[Tue Jul 21 07:54:45.579135 2026] [security2:error] [pid 341679:tid 341921] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9P9QWat-noHLkDuAh1UgABejE"]
[Tue Jul 21 07:54:45.844962 2026] [security2:error] [pid 341679:tid 341856] [client 107.189.6.149:56334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "solarisimplementos.com"] [uri "/"] [unique_id "al9P9QWat-noHLkDuAh1XAAAATk"]
[Tue Jul 21 07:54:46.021778 2026] [security2:error] [pid 341679:tid 341897] [client 51.68.111.219:28105] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "appauto.com.br"] [uri "/robots.txt"] [unique_id "al9P9gWat-noHLkDuAh1YQAAAWI"]
[Tue Jul 21 07:54:46.021869 2026] [security2:error] [pid 341679:tid 341897] [client 51.68.111.219:28105] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "appauto.com.br"] [uri "/robots.txt"] [unique_id "al9P9gWat-noHLkDuAh1YQAAAWI"]
[Tue Jul 21 07:54:46.045894 2026] [security2:error] [pid 341679:tid 341904] [client 107.189.6.149:56333] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "solarisimplementos.com"] [uri "/"] [unique_id "al9P9gWat-noHLkDuAh1YgAAAWk"]
[Tue Jul 21 07:54:46.107570 2026] [security2:error] [pid 341679:tid 341881] [client 122.164.127.47:62777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9P9gWat-noHLkDuAh1ZAAAAVI"]
[Tue Jul 21 07:54:46.107700 2026] [security2:error] [pid 341679:tid 341881] [client 122.164.127.47:62777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9P9gWat-noHLkDuAh1ZAAAAVI"]
[Tue Jul 21 07:54:46.239973 2026] [security2:error] [pid 341679:tid 341880] [client 107.189.6.149:56388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "solarisimplementos.com"] [uri "/"] [unique_id "al9P9gWat-noHLkDuAh1bAAAAVE"]
[Tue Jul 21 07:54:46.631734 2026] [security2:error] [pid 341679:tid 341858] [client 107.189.6.149:56411] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "solarisimplementos.com"] [uri "/"] [unique_id "al9P9gWat-noHLkDuAh1dgAAATs"]
[Tue Jul 21 07:54:46.814790 2026] [autoindex:error] [pid 341679:tid 341914] [client 185.213.175.37:17956] AH01276: Cannot serve directory /home1/pedid516/atmo.hunteron.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:54:47.272986 2026] [security2:error] [pid 341679:tid 341735] [remote 154.61.75.100:59686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/wp-login.php"] [unique_id "al9P9wWat-noHLkDuAh1iQABfjc"]
[Tue Jul 21 07:54:47.331463 2026] [security2:error] [pid 341679:tid 341935] [client 20.104.96.117:57775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/byp.php"] [unique_id "al9P9wWat-noHLkDuAh1igAAAYg"]
[Tue Jul 21 07:54:47.437113 2026] [security2:error] [pid 341679:tid 341921] [client 103.86.117.203:59697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P9wWat-noHLkDuAh1jQAAAXo"]
[Tue Jul 21 07:54:47.437226 2026] [security2:error] [pid 341679:tid 341921] [client 103.86.117.203:59697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P9wWat-noHLkDuAh1jQAAAXo"]
[Tue Jul 21 07:54:47.497298 2026] [security2:error] [pid 341679:tid 341901] [client 20.206.105.145:55922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wefile.php"] [unique_id "al9P9wWat-noHLkDuAh1kgAAAWY"]
[Tue Jul 21 07:54:47.700292 2026] [security2:error] [pid 341679:tid 341902] [client 20.226.60.151:50511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-includes/css/index.php"] [unique_id "al9P9wWat-noHLkDuAh1mwAAAWc"]
[Tue Jul 21 07:54:47.805314 2026] [security2:error] [pid 341679:tid 341742] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9P9wWat-noHLkDuAh1nQABSD4"]
[Tue Jul 21 07:54:47.805491 2026] [security2:error] [pid 341679:tid 341871] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9P9wWat-noHLkDuAh1nQABSD4"]
[Tue Jul 21 07:54:48.449633 2026] [security2:error] [pid 341679:tid 341851] [client 20.220.225.223:19663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/wp-explorer.php"] [unique_id "al9P-AWat-noHLkDuAh1qAAAATQ"]
[Tue Jul 21 07:54:48.471268 2026] [security2:error] [pid 341679:tid 341868] [client 20.226.60.151:56728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/jj.php"] [unique_id "al9P-AWat-noHLkDuAh1qQAAAUU"]
[Tue Jul 21 07:54:48.672333 2026] [security2:error] [pid 341679:tid 341912] [client 193.36.225.11:50479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9P-AWat-noHLkDuAh1sQAAAXE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:48.901870 2026] [security2:error] [pid 341679:tid 341702] [remote 5.182.209.54:55666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9P-AWat-noHLkDuAh1wwABcxY"]
[Tue Jul 21 07:54:49.055085 2026] [security2:error] [pid 341679:tid 341888] [client 20.104.96.117:55011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9P-QWat-noHLkDuAh1zAAAAVk"]
[Tue Jul 21 07:54:49.372820 2026] [security2:error] [pid 341679:tid 341885] [client 65.111.22.20:14827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9P-QWat-noHLkDuAh10wAAAVY"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:54:49.427431 2026] [security2:error] [pid 341679:tid 341896] [client 193.36.225.150:42537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9P-QWat-noHLkDuAh12gAAAWE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:54:49.671251 2026] [security2:error] [pid 341679:tid 341844] [client 20.206.105.145:55835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9P-QWat-noHLkDuAh15wAAAS0"]
[Tue Jul 21 07:54:49.696197 2026] [security2:error] [pid 341679:tid 341925] [client 178.153.91.96:53016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9P-QWat-noHLkDuAh16AAAAX4"]
[Tue Jul 21 07:54:49.696344 2026] [security2:error] [pid 341679:tid 341925] [client 178.153.91.96:53016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9P-QWat-noHLkDuAh16AAAAX4"]
[Tue Jul 21 07:54:49.871208 2026] [security2:error] [pid 341679:tid 341898] [client 20.226.60.151:56765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/class-walker-footer-dev.php"] [unique_id "al9P-QWat-noHLkDuAh18gAAAWM"]
[Tue Jul 21 07:54:49.937037 2026] [security2:error] [pid 341679:tid 341687] [remote 173.252.82.12:38526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9P-QWat-noHLkDuAh17QABNQc"]
[Tue Jul 21 07:54:50.264422 2026] [security2:error] [pid 341679:tid 341831] [client 122.162.144.145:17717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9P-gWat-noHLkDuAh1_QAAASA"]
[Tue Jul 21 07:54:50.264537 2026] [security2:error] [pid 341679:tid 341831] [client 122.162.144.145:17717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9P-gWat-noHLkDuAh1_QAAASA"]
[Tue Jul 21 07:54:50.286827 2026] [security2:error] [pid 341679:tid 341888] [client 74.249.245.134:24802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/readme.php"] [unique_id "al9P-gWat-noHLkDuAh1_wAAAVk"]
[Tue Jul 21 07:54:50.397459 2026] [security2:error] [pid 341679:tid 341908] [client 117.247.80.59:13840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P-gWat-noHLkDuAh2AgAAAW0"]
[Tue Jul 21 07:54:50.397555 2026] [security2:error] [pid 341679:tid 341908] [client 117.247.80.59:13840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P-gWat-noHLkDuAh2AgAAAW0"]
[Tue Jul 21 07:54:50.435979 2026] [security2:error] [pid 341679:tid 341906] [client 117.217.38.194:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P-gWat-noHLkDuAh2BQAAAWs"]
[Tue Jul 21 07:54:50.436060 2026] [security2:error] [pid 341679:tid 341906] [client 117.217.38.194:52626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P-gWat-noHLkDuAh2BQAAAWs"]
[Tue Jul 21 07:54:50.535421 2026] [security2:error] [pid 341679:tid 341822] [client 223.236.153.128:2487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9P-gWat-noHLkDuAh2BwAAARc"]
[Tue Jul 21 07:54:50.535524 2026] [security2:error] [pid 341679:tid 341822] [client 223.236.153.128:2487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9P-gWat-noHLkDuAh2BwAAARc"]
[Tue Jul 21 07:54:50.663451 2026] [security2:error] [pid 341679:tid 341704] [remote 103.187.169.251:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iducali.com.br"] [uri "/wp-login.php"] [unique_id "al9P-gWat-noHLkDuAh2DgABaRg"]
[Tue Jul 21 07:54:50.698141 2026] [security2:error] [pid 341679:tid 341855] [client 45.3.40.234:28991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.40.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9P-gWat-noHLkDuAh2BgAAATg"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:54:50.857509 2026] [security2:error] [pid 341679:tid 341835] [client 20.220.225.223:19309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/akismet.php"] [unique_id "al9P-gWat-noHLkDuAh2FwAAASQ"]
[Tue Jul 21 07:54:50.965105 2026] [security2:error] [pid 341679:tid 341733] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P-gWat-noHLkDuAh2HgABETU"]
[Tue Jul 21 07:54:50.965280 2026] [security2:error] [pid 341679:tid 341816] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P-gWat-noHLkDuAh2HgABETU"]
[Tue Jul 21 07:54:50.999081 2026] [security2:error] [pid 341679:tid 341884] [client 139.167.225.182:62913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P-gWat-noHLkDuAh2IAAAAVU"]
[Tue Jul 21 07:54:50.999176 2026] [security2:error] [pid 341679:tid 341884] [client 139.167.225.182:62913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P-gWat-noHLkDuAh2IAAAAVU"]
[Tue Jul 21 07:54:51.121642 2026] [security2:error] [pid 341679:tid 341865] [client 173.24.185.52:57414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9P-wWat-noHLkDuAh2JgAAAUI"]
[Tue Jul 21 07:54:51.121753 2026] [security2:error] [pid 341679:tid 341865] [client 173.24.185.52:57414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9P-wWat-noHLkDuAh2JgAAAUI"]
[Tue Jul 21 07:54:51.125567 2026] [security2:error] [pid 341679:tid 341740] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P-wWat-noHLkDuAh2KAABTTw"]
[Tue Jul 21 07:54:51.125733 2026] [security2:error] [pid 341679:tid 341876] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P-wWat-noHLkDuAh2KAABTTw"]
[Tue Jul 21 07:54:51.432640 2026] [security2:error] [pid 341679:tid 341863] [client 103.166.103.129:61446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9P-wWat-noHLkDuAh2LwAAAUA"]
[Tue Jul 21 07:54:51.432780 2026] [security2:error] [pid 341679:tid 341863] [client 103.166.103.129:61446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9P-wWat-noHLkDuAh2LwAAAUA"]
[Tue Jul 21 07:54:51.435872 2026] [security2:error] [pid 341679:tid 341774] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P-wWat-noHLkDuAh2MAABGF4"]
[Tue Jul 21 07:54:51.435995 2026] [security2:error] [pid 341679:tid 341823] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P-wWat-noHLkDuAh2MAABGF4"]
[Tue Jul 21 07:54:51.574874 2026] [security2:error] [pid 341679:tid 341924] [client 20.206.105.145:55898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9P-wWat-noHLkDuAh2NwAAAX0"]
[Tue Jul 21 07:54:51.580824 2026] [security2:error] [pid 341679:tid 341922] [client 193.36.225.120:32433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9P-wWat-noHLkDuAh2NgAAAXs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:54:51.733404 2026] [security2:error] [pid 341679:tid 341693] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P-wWat-noHLkDuAh2RAABIg0"]
[Tue Jul 21 07:54:51.733526 2026] [security2:error] [pid 341679:tid 341833] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P-wWat-noHLkDuAh2RAABIg0"]
[Tue Jul 21 07:54:52.135125 2026] [security2:error] [pid 341679:tid 341859] [client 20.104.96.117:55039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/classwithtostring.php"] [unique_id "al9P_AWat-noHLkDuAh2TQAAATw"]
[Tue Jul 21 07:54:52.390473 2026] [security2:error] [pid 341679:tid 341717] [remote 68.178.160.25:57880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guilhermeverissimo.com.br"] [uri "/wp-login.php"] [unique_id "al9P_AWat-noHLkDuAh2VQABIyU"]
[Tue Jul 21 07:54:52.863621 2026] [security2:error] [pid 341679:tid 341921] [client 45.3.35.44:24823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.35.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9P-wWat-noHLkDuAh2PwAAAXo"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:54:52.950759 2026] [security2:error] [pid 341679:tid 341864] [client 103.78.200.11:65127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P_AWat-noHLkDuAh2bQAAAUE"]
[Tue Jul 21 07:54:52.950867 2026] [security2:error] [pid 341679:tid 341864] [client 103.78.200.11:65127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P_AWat-noHLkDuAh2bQAAAUE"]
[Tue Jul 21 07:54:53.042856 2026] [security2:error] [pid 341679:tid 341832] [client 41.68.90.219:56495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P_QWat-noHLkDuAh2bwAAASE"]
[Tue Jul 21 07:54:53.042977 2026] [security2:error] [pid 341679:tid 341832] [client 41.68.90.219:56495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P_QWat-noHLkDuAh2bwAAASE"]
[Tue Jul 21 07:54:53.052927 2026] [security2:error] [pid 341679:tid 341818] [client 20.206.105.145:28620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/like.php"] [unique_id "al9P_QWat-noHLkDuAh2cQAAARM"]
[Tue Jul 21 07:54:53.174115 2026] [security2:error] [pid 341679:tid 341879] [client 122.186.204.214:61412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P_QWat-noHLkDuAh2dgAAAVA"]
[Tue Jul 21 07:54:53.174238 2026] [security2:error] [pid 341679:tid 341879] [client 122.186.204.214:61412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9P_QWat-noHLkDuAh2dgAAAVA"]
[Tue Jul 21 07:54:53.201559 2026] [security2:error] [pid 341679:tid 341851] [client 103.29.114.44:47454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P_QWat-noHLkDuAh2eAAAATQ"]
[Tue Jul 21 07:54:53.201681 2026] [security2:error] [pid 341679:tid 341851] [client 103.29.114.44:47454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P_QWat-noHLkDuAh2eAAAATQ"]
[Tue Jul 21 07:54:53.296550 2026] [security2:error] [pid 341679:tid 341831] [client 106.215.181.8:11054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P_QWat-noHLkDuAh2eQAAASA"]
[Tue Jul 21 07:54:53.296692 2026] [security2:error] [pid 341679:tid 341831] [client 106.215.181.8:11054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P_QWat-noHLkDuAh2eQAAASA"]
[Tue Jul 21 07:54:53.869754 2026] [security2:error] [pid 341679:tid 341846] [client 20.104.96.117:57789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/root.php"] [unique_id "al9P_QWat-noHLkDuAh2hQAAAS8"]
[Tue Jul 21 07:54:54.130040 2026] [security2:error] [pid 341679:tid 341731] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P_gWat-noHLkDuAh2jgABFDM"]
[Tue Jul 21 07:54:54.130212 2026] [security2:error] [pid 341679:tid 341819] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P_gWat-noHLkDuAh2jgABFDM"]
[Tue Jul 21 07:54:54.198953 2026] [security2:error] [pid 341679:tid 341901] [client 122.179.91.63:4660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9P_gWat-noHLkDuAh2kAAAAWY"]
[Tue Jul 21 07:54:54.199345 2026] [security2:error] [pid 341679:tid 341901] [client 122.179.91.63:4660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9P_gWat-noHLkDuAh2kAAAAWY"]
[Tue Jul 21 07:54:54.384740 2026] [security2:error] [pid 341679:tid 341912] [client 182.8.255.181:17214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9P_gWat-noHLkDuAh2lwAAAXE"]
[Tue Jul 21 07:54:54.384857 2026] [security2:error] [pid 341679:tid 341912] [client 182.8.255.181:17214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9P_gWat-noHLkDuAh2lwAAAXE"]
[Tue Jul 21 07:54:54.477248 2026] [security2:error] [pid 341679:tid 341735] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9P_gWat-noHLkDuAh2nQABEDc"]
[Tue Jul 21 07:54:54.477392 2026] [security2:error] [pid 341679:tid 341815] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9P_gWat-noHLkDuAh2nQABEDc"]
[Tue Jul 21 07:54:54.514723 2026] [security2:error] [pid 341679:tid 341870] [client 151.123.177.111:56417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9P_gWat-noHLkDuAh2lgAAAUc"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:54:54.635510 2026] [security2:error] [pid 341679:tid 341877] [client 136.144.33.215:31121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9P_AWat-noHLkDuAh2WQAAAU4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:54.843795 2026] [security2:error] [pid 341679:tid 341850] [client 74.249.245.134:24804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/403.php"] [unique_id "al9P_gWat-noHLkDuAh2pwAAATM"]
[Tue Jul 21 07:54:55.110556 2026] [security2:error] [pid 341679:tid 341858] [client 109.60.28.94:36599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P_wWat-noHLkDuAh2rQAAATs"]
[Tue Jul 21 07:54:55.111387 2026] [security2:error] [pid 341679:tid 341858] [client 109.60.28.94:36599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P_wWat-noHLkDuAh2rQAAATs"]
[Tue Jul 21 07:54:55.327414 2026] [security2:error] [pid 341679:tid 341918] [client 20.226.60.151:50687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/txets.php"] [unique_id "al9P_wWat-noHLkDuAh2tQAAAXc"]
[Tue Jul 21 07:54:55.825528 2026] [security2:error] [pid 341679:tid 341876] [client 202.143.127.214:49216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P_wWat-noHLkDuAh2yQAAAU0"]
[Tue Jul 21 07:54:55.826079 2026] [security2:error] [pid 341679:tid 341876] [client 202.143.127.214:49216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9P_wWat-noHLkDuAh2yQAAAU0"]
[Tue Jul 21 07:54:55.966637 2026] [security2:error] [pid 341679:tid 341835] [client 114.119.136.86:47761] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.meuflatnapraia.com.br"] [uri "/image/d235/meu-flat-na-praia-centro-de-porto-de-galinhas-conforto-e-loc-67641771f742f411ef485426"] [unique_id "al9P_wWat-noHLkDuAh2zAAAASQ"], referer: https://www.meuflatnapraia.com.br/pt/apartment/MJ01I/a-50m-do-mar-no-centro-de-porto-de-galinhas.
[Tue Jul 21 07:54:56.041680 2026] [security2:error] [pid 341679:tid 341845] [client 102.206.115.33:58691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QAAWat-noHLkDuAh20gAAAS4"]
[Tue Jul 21 07:54:56.041788 2026] [security2:error] [pid 341679:tid 341845] [client 102.206.115.33:58691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QAAWat-noHLkDuAh20gAAAS4"]
[Tue Jul 21 07:54:56.117822 2026] [security2:error] [pid 341679:tid 341821] [client 20.206.105.145:55915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/.well-known/about.php"] [unique_id "al9QAAWat-noHLkDuAh22wAAARY"]
[Tue Jul 21 07:54:56.300170 2026] [security2:error] [pid 341679:tid 341748] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QAAWat-noHLkDuAh3GgABiEQ"]
[Tue Jul 21 07:54:56.300355 2026] [security2:error] [pid 341679:tid 341935] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QAAWat-noHLkDuAh3GgABiEQ"]
[Tue Jul 21 07:54:57.013709 2026] [security2:error] [pid 341679:tid 341912] [client 20.104.96.117:54936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/sym403.php"] [unique_id "al9QAQWat-noHLkDuAh3QQAAAXE"]
[Tue Jul 21 07:54:57.018757 2026] [security2:error] [pid 341679:tid 341870] [client 122.164.127.47:63499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QAQWat-noHLkDuAh3QgAAAUc"]
[Tue Jul 21 07:54:57.018892 2026] [security2:error] [pid 341679:tid 341870] [client 122.164.127.47:63499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QAQWat-noHLkDuAh3QgAAAUc"]
[Tue Jul 21 07:54:57.198373 2026] [access_compat:error] [pid 341679:tid 341827] [client 162.241.63.68:30412] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:54:57.653539 2026] [security2:error] [pid 341679:tid 341868] [client 20.104.96.117:55015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/v543.php"] [unique_id "al9QAQWat-noHLkDuAh3UwAAAUU"]
[Tue Jul 21 07:54:57.747208 2026] [security2:error] [pid 341679:tid 341888] [client 20.206.105.145:55920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9QAQWat-noHLkDuAh3VgAAAVk"]
[Tue Jul 21 07:54:57.919617 2026] [security2:error] [pid 341679:tid 341908] [client 103.86.117.203:60239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QAQWat-noHLkDuAh3VwAAAW0"]
[Tue Jul 21 07:54:57.919745 2026] [security2:error] [pid 341679:tid 341908] [client 103.86.117.203:60239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QAQWat-noHLkDuAh3VwAAAW0"]
[Tue Jul 21 07:54:58.175241 2026] [security2:error] [pid 341679:tid 341762] [remote 5.252.52.249:49756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arthromdcanada.online"] [uri "/wp-login.php"] [unique_id "al9QAgWat-noHLkDuAh3YAABd1I"]
[Tue Jul 21 07:54:58.524177 2026] [security2:error] [pid 341679:tid 341842] [client 193.36.225.11:33733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QAgWat-noHLkDuAh3aAAAASs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:54:58.537178 2026] [security2:error] [pid 341679:tid 341771] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QAgWat-noHLkDuAh3agABLFs"]
[Tue Jul 21 07:54:58.537306 2026] [security2:error] [pid 341679:tid 341843] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QAgWat-noHLkDuAh3agABLFs"]
[Tue Jul 21 07:54:59.296549 2026] [security2:error] [pid 341679:tid 341827] [client 20.197.192.193:3690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/ez.php"] [unique_id "al9QAwWat-noHLkDuAh3eQAAARw"]
[Tue Jul 21 07:54:59.695524 2026] [security2:error] [pid 341679:tid 341853] [client 20.226.60.151:56780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/dex.php"] [unique_id "al9QAwWat-noHLkDuAh3ggAAATY"]
[Tue Jul 21 07:54:59.723208 2026] [security2:error] [pid 341679:tid 341903] [client 20.104.96.117:54948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/sixxis.php"] [unique_id "al9QAwWat-noHLkDuAh3gwAAAWg"]
[Tue Jul 21 07:55:00.093946 2026] [security2:error] [pid 341679:tid 341924] [client 184.75.221.3:49354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9QBAWat-noHLkDuAh3jwAAAX0"]
[Tue Jul 21 07:55:00.094038 2026] [security2:error] [pid 341679:tid 341924] [client 184.75.221.3:49354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9QBAWat-noHLkDuAh3jwAAAX0"]
[Tue Jul 21 07:55:00.179889 2026] [security2:error] [pid 341679:tid 341936] [client 20.206.105.145:55829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/pucci.php"] [unique_id "al9QBAWat-noHLkDuAh3lgAAAYk"]
[Tue Jul 21 07:55:00.209217 2026] [security2:error] [pid 341679:tid 341839] [client 178.153.91.96:57543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QBAWat-noHLkDuAh3mAAAASg"]
[Tue Jul 21 07:55:00.209328 2026] [security2:error] [pid 341679:tid 341839] [client 178.153.91.96:57543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QBAWat-noHLkDuAh3mAAAASg"]
[Tue Jul 21 07:55:00.526281 2026] [autoindex:error] [pid 341679:tid 341778] [remote 155.254.38.253:37749] AH01276: Cannot serve directory /home2/werley42/impactoensino.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:00.617887 2026] [security2:error] [pid 341679:tid 341683] [remote 167.71.240.77:39232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.240.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-login.php"] [unique_id "al9QBAWat-noHLkDuAh3pQABFAM"]
[Tue Jul 21 07:55:00.668092 2026] [security2:error] [pid 341679:tid 341698] [remote 142.44.228.178:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "marketingderua.com.br"] [uri "/metricas-essenciais-para-medir-resultados-em-campanhas-ooh/"] [unique_id "al9QBAWat-noHLkDuAh3pwABexI"]
[Tue Jul 21 07:55:00.668277 2026] [security2:error] [pid 341679:tid 341922] [client 142.44.228.178:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "marketingderua.com.br"] [uri "/metricas-essenciais-para-medir-resultados-em-campanhas-ooh/"] [unique_id "al9QBAWat-noHLkDuAh3pwABexI"]
[Tue Jul 21 07:55:00.791113 2026] [security2:error] [pid 341679:tid 341910] [client 20.220.225.223:19654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/ace2.php"] [unique_id "al9QBAWat-noHLkDuAh3qwAAAW8"]
[Tue Jul 21 07:55:00.911448 2026] [security2:error] [pid 341679:tid 341904] [client 117.247.80.59:14351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBAWat-noHLkDuAh3sAAAAWk"]
[Tue Jul 21 07:55:00.911572 2026] [security2:error] [pid 341679:tid 341904] [client 117.247.80.59:14351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBAWat-noHLkDuAh3sAAAAWk"]
[Tue Jul 21 07:55:00.958237 2026] [security2:error] [pid 341679:tid 341913] [client 122.162.144.145:33140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QBAWat-noHLkDuAh3sQAAAXI"]
[Tue Jul 21 07:55:00.958336 2026] [security2:error] [pid 341679:tid 341913] [client 122.162.144.145:33140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QBAWat-noHLkDuAh3sQAAAXI"]
[Tue Jul 21 07:55:01.075135 2026] [security2:error] [pid 341679:tid 341885] [client 117.217.38.194:53132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBQWat-noHLkDuAh3swAAAVY"]
[Tue Jul 21 07:55:01.075258 2026] [security2:error] [pid 341679:tid 341885] [client 117.217.38.194:53132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBQWat-noHLkDuAh3swAAAVY"]
[Tue Jul 21 07:55:01.150292 2026] [security2:error] [pid 341679:tid 341933] [client 223.236.153.128:5120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QBQWat-noHLkDuAh3tQAAAYY"]
[Tue Jul 21 07:55:01.150397 2026] [security2:error] [pid 341679:tid 341933] [client 223.236.153.128:5120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QBQWat-noHLkDuAh3tQAAAYY"]
[Tue Jul 21 07:55:01.385898 2026] [security2:error] [pid 341679:tid 341854] [client 20.104.96.117:54964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/ip.php"] [unique_id "al9QBQWat-noHLkDuAh3xQAAATc"]
[Tue Jul 21 07:55:01.707472 2026] [security2:error] [pid 341679:tid 341894] [client 139.167.225.182:63563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBQWat-noHLkDuAh3zgAAAV8"]
[Tue Jul 21 07:55:01.709208 2026] [security2:error] [pid 341679:tid 341894] [client 139.167.225.182:63563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBQWat-noHLkDuAh3zgAAAV8"]
[Tue Jul 21 07:55:01.716450 2026] [security2:error] [pid 341679:tid 341726] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBQWat-noHLkDuAh30AABKC4"]
[Tue Jul 21 07:55:01.716609 2026] [security2:error] [pid 341679:tid 341839] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBQWat-noHLkDuAh30AABKC4"]
[Tue Jul 21 07:55:01.734869 2026] [security2:error] [pid 341679:tid 341788] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBQWat-noHLkDuAh30wABOmw"]
[Tue Jul 21 07:55:01.735041 2026] [security2:error] [pid 341679:tid 341857] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBQWat-noHLkDuAh30wABOmw"]
[Tue Jul 21 07:55:01.776486 2026] [security2:error] [pid 341679:tid 341823] [client 173.24.185.52:57949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9QBQWat-noHLkDuAh31AAAARg"]
[Tue Jul 21 07:55:01.776588 2026] [security2:error] [pid 341679:tid 341823] [client 173.24.185.52:57949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9QBQWat-noHLkDuAh31AAAARg"]
[Tue Jul 21 07:55:01.875174 2026] [security2:error] [pid 341679:tid 341700] [remote 65.111.9.171:56795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.9.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9QBQWat-noHLkDuAh33gABgBQ"]
[Tue Jul 21 07:55:01.969581 2026] [security2:error] [pid 341679:tid 341779] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBQWat-noHLkDuAh35QABaWM"]
[Tue Jul 21 07:55:01.969775 2026] [security2:error] [pid 341679:tid 341904] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBQWat-noHLkDuAh35QABaWM"]
[Tue Jul 21 07:55:01.994618 2026] [security2:error] [pid 341679:tid 341878] [client 20.206.105.145:55881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wp-temp.php"] [unique_id "al9QBQWat-noHLkDuAh38QAAAU8"]
[Tue Jul 21 07:55:02.097829 2026] [security2:error] [pid 341679:tid 341906] [client 103.166.103.129:61988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QBgWat-noHLkDuAh4IQAAAWs"]
[Tue Jul 21 07:55:02.097976 2026] [security2:error] [pid 341679:tid 341906] [client 103.166.103.129:61988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QBgWat-noHLkDuAh4IQAAAWs"]
[Tue Jul 21 07:55:02.136788 2026] [security2:error] [pid 341679:tid 341853] [client 136.144.33.101:21015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QBgWat-noHLkDuAh4IgAAATY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:02.995656 2026] [security2:error] [pid 341679:tid 341859] [client 103.78.200.11:49200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBgWat-noHLkDuAh4gwAAATw"]
[Tue Jul 21 07:55:02.995842 2026] [security2:error] [pid 341679:tid 341859] [client 103.78.200.11:49200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBgWat-noHLkDuAh4gwAAATw"]
[Tue Jul 21 07:55:03.000311 2026] [security2:error] [pid 341679:tid 341695] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBgWat-noHLkDuAh4hAABQg8"]
[Tue Jul 21 07:55:03.000457 2026] [security2:error] [pid 341679:tid 341865] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBgWat-noHLkDuAh4hAABQg8"]
[Tue Jul 21 07:55:03.083806 2026] [security2:error] [pid 341679:tid 341875] [client 20.206.105.145:55846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/xmu.php"] [unique_id "al9QBwWat-noHLkDuAh4iQAAAUw"]
[Tue Jul 21 07:55:03.565899 2026] [security2:error] [pid 341679:tid 341897] [client 20.226.60.151:61630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wmore1.php"] [unique_id "al9QBwWat-noHLkDuAh4wAAAAWI"]
[Tue Jul 21 07:55:03.774836 2026] [security2:error] [pid 341679:tid 341918] [client 106.215.181.8:31273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBwWat-noHLkDuAh4xAAAAXc"]
[Tue Jul 21 07:55:03.774965 2026] [security2:error] [pid 341679:tid 341918] [client 106.215.181.8:31273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QBwWat-noHLkDuAh4xAAAAXc"]
[Tue Jul 21 07:55:03.976694 2026] [security2:error] [pid 341679:tid 341824] [client 20.206.105.145:55842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9QBwWat-noHLkDuAh40wAAARk"]
[Tue Jul 21 07:55:03.996091 2026] [security2:error] [pid 341679:tid 341882] [client 122.186.204.214:61956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QBwWat-noHLkDuAh41AAAAVM"]
[Tue Jul 21 07:55:04.015377 2026] [security2:error] [pid 341679:tid 341882] [client 122.186.204.214:61956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QBwWat-noHLkDuAh41AAAAVM"]
[Tue Jul 21 07:55:04.097970 2026] [security2:error] [pid 341679:tid 341818] [client 20.226.60.151:50670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xpwer1.php"] [unique_id "al9QCAWat-noHLkDuAh41QAAARM"]
[Tue Jul 21 07:55:04.380696 2026] [security2:error] [pid 341679:tid 341885] [client 41.68.90.219:56962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QCAWat-noHLkDuAh43QAAAVY"]
[Tue Jul 21 07:55:04.381777 2026] [security2:error] [pid 341679:tid 341885] [client 41.68.90.219:56962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QCAWat-noHLkDuAh43QAAAVY"]
[Tue Jul 21 07:55:04.680755 2026] [security2:error] [pid 341679:tid 341834] [client 103.29.114.44:49722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QCAWat-noHLkDuAh5BgAAASM"]
[Tue Jul 21 07:55:04.680902 2026] [security2:error] [pid 341679:tid 341834] [client 103.29.114.44:49722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QCAWat-noHLkDuAh5BgAAASM"]
[Tue Jul 21 07:55:04.769871 2026] [security2:error] [pid 341679:tid 341810] [client 182.8.255.181:17484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QCAWat-noHLkDuAh5FwAAAQs"]
[Tue Jul 21 07:55:04.770449 2026] [security2:error] [pid 341679:tid 341810] [client 182.8.255.181:17484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QCAWat-noHLkDuAh5FwAAAQs"]
[Tue Jul 21 07:55:04.993681 2026] [security2:error] [pid 341679:tid 341806] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QCAWat-noHLkDuAh5IAABd34"]
[Tue Jul 21 07:55:04.993799 2026] [security2:error] [pid 341679:tid 341918] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QCAWat-noHLkDuAh5IAABd34"]
[Tue Jul 21 07:55:05.012954 2026] [security2:error] [pid 341679:tid 341857] [client 65.111.20.1:23141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QCAWat-noHLkDuAh5GwAAATo"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:55:05.428942 2026] [security2:error] [pid 341679:tid 341696] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QCQWat-noHLkDuAh5LAABZhA"]
[Tue Jul 21 07:55:05.429115 2026] [security2:error] [pid 341679:tid 341901] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QCQWat-noHLkDuAh5LAABZhA"]
[Tue Jul 21 07:55:05.622829 2026] [security2:error] [pid 341679:tid 341924] [client 114.119.156.129:55289] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nbmnews.com"] [uri "/products/christmas-led-beanies&media=/cdn.shopify.com/s/files/1/0623/6169/8541/products/Christmas_LED_Beanies_27_1024x1024.jpg"] [unique_id "al9QCQWat-noHLkDuAh5NAAAAX0"], referer: https://nbmnews.com/products/christmas-led-beanies&media=/cdn.shopify.com/s/files/1/0623/6169/8541/products/Christmas_LED_Beanies_27_1024x1024.jpg?v=1642809738&description=Christmas%20LED%20Beanies
[Tue Jul 21 07:55:06.143777 2026] [security2:error] [pid 341679:tid 341819] [client 109.60.28.94:53716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QCgWat-noHLkDuAh5RQAAARQ"]
[Tue Jul 21 07:55:06.143939 2026] [security2:error] [pid 341679:tid 341819] [client 109.60.28.94:53716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QCgWat-noHLkDuAh5RQAAARQ"]
[Tue Jul 21 07:55:06.182984 2026] [security2:error] [pid 341679:tid 341913] [client 20.220.225.223:19656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "_dc-mx.d24832f1ec4d.conquisteemcasa.com.br"] [uri "/ms.php"] [unique_id "al9QCgWat-noHLkDuAh5RgAAAXI"]
[Tue Jul 21 07:55:06.256599 2026] [security2:error] [pid 341679:tid 341877] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9QCgWat-noHLkDuAh5SAAAAU4"]
[Tue Jul 21 07:55:06.468750 2026] [security2:error] [pid 341679:tid 341875] [client 122.179.91.63:31325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QCgWat-noHLkDuAh5TAAAAUw"]
[Tue Jul 21 07:55:06.468887 2026] [security2:error] [pid 341679:tid 341875] [client 122.179.91.63:31325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QCgWat-noHLkDuAh5TAAAAUw"]
[Tue Jul 21 07:55:06.551623 2026] [security2:error] [pid 341679:tid 341860] [client 143.244.57.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QCgWat-noHLkDuAh5TwAAAT0"]
[Tue Jul 21 07:55:06.590153 2026] [security2:error] [pid 341679:tid 341876] [client 102.206.115.33:63626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QCgWat-noHLkDuAh5VAAAAU0"]
[Tue Jul 21 07:55:06.590286 2026] [security2:error] [pid 341679:tid 341876] [client 102.206.115.33:63626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QCgWat-noHLkDuAh5VAAAAU0"]
[Tue Jul 21 07:55:06.641933 2026] [autoindex:error] [pid 341679:tid 341909] [client 54.242.199.200:51930] AH01276: Cannot serve directory /home1/leon6484/lumevisual.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:06.691776 2026] [security2:error] [pid 341679:tid 341903] [client 202.143.127.214:49694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QCgWat-noHLkDuAh5WwAAAWg"]
[Tue Jul 21 07:55:06.691916 2026] [security2:error] [pid 341679:tid 341903] [client 202.143.127.214:49694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QCgWat-noHLkDuAh5WwAAAWg"]
[Tue Jul 21 07:55:06.853763 2026] [security2:error] [pid 341679:tid 341832] [client 136.144.33.98:50405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QCgWat-noHLkDuAh5YAAAASE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:06.996608 2026] [security2:error] [pid 341679:tid 341839] [client 20.104.96.117:54925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/kq1.php"] [unique_id "al9QCgWat-noHLkDuAh5bAAAASg"]
[Tue Jul 21 07:55:07.000143 2026] [security2:error] [pid 341679:tid 341922] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9QCgWat-noHLkDuAh5bgAAAXs"]
[Tue Jul 21 07:55:07.061420 2026] [security2:error] [pid 341679:tid 341753] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QCwWat-noHLkDuAh5cgABLUk"]
[Tue Jul 21 07:55:07.061566 2026] [security2:error] [pid 341679:tid 341844] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QCwWat-noHLkDuAh5cgABLUk"]
[Tue Jul 21 07:55:07.236541 2026] [security2:error] [pid 341679:tid 341857] [client 122.164.127.47:64087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QCwWat-noHLkDuAh5dwAAATo"]
[Tue Jul 21 07:55:07.240730 2026] [security2:error] [pid 341679:tid 341857] [client 122.164.127.47:64087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QCwWat-noHLkDuAh5dwAAATo"]
[Tue Jul 21 07:55:07.359599 2026] [security2:error] [pid 341679:tid 341847] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9QCwWat-noHLkDuAh5ggAAATA"]
[Tue Jul 21 07:55:07.592298 2026] [security2:error] [pid 341679:tid 341878] [client 20.206.105.145:55825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/puc.php"] [unique_id "al9QCwWat-noHLkDuAh5kwAAAU8"]
[Tue Jul 21 07:55:07.644997 2026] [security2:error] [pid 341679:tid 341820] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9QCwWat-noHLkDuAh5mAAAARU"]
[Tue Jul 21 07:55:07.928738 2026] [security2:error] [pid 341679:tid 341894] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9QCwWat-noHLkDuAh5mgAAAV8"]
[Tue Jul 21 07:55:08.146285 2026] [security2:error] [pid 341679:tid 341919] [client 74.249.245.134:64406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/max.php"] [unique_id "al9QDAWat-noHLkDuAh5sQAAAXg"]
[Tue Jul 21 07:55:08.213979 2026] [security2:error] [pid 341679:tid 341877] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9QDAWat-noHLkDuAh5uAAAAU4"]
[Tue Jul 21 07:55:08.404100 2026] [security2:error] [pid 341679:tid 341818] [client 103.86.117.203:60783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QDAWat-noHLkDuAh5vQAAARM"]
[Tue Jul 21 07:55:08.404229 2026] [security2:error] [pid 341679:tid 341818] [client 103.86.117.203:60783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QDAWat-noHLkDuAh5vQAAARM"]
[Tue Jul 21 07:55:08.433062 2026] [security2:error] [pid 341679:tid 341882] [client 20.226.60.151:56825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/flox.php"] [unique_id "al9QDAWat-noHLkDuAh5vgAAAVM"]
[Tue Jul 21 07:55:08.502036 2026] [security2:error] [pid 341679:tid 341887] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9QDAWat-noHLkDuAh5wAAAAVg"]
[Tue Jul 21 07:55:08.750404 2026] [autoindex:error] [pid 341679:tid 341736] [remote 74.7.227.139:40714] AH01276: Cannot serve directory /home3/agroci73/purityox.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:08.784610 2026] [security2:error] [pid 341679:tid 341848] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9QDAWat-noHLkDuAh5zQAAATE"]
[Tue Jul 21 07:55:09.071991 2026] [security2:error] [pid 341679:tid 341839] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9QDQWat-noHLkDuAh51QAAASg"]
[Tue Jul 21 07:55:09.104341 2026] [security2:error] [pid 341679:tid 341681] [remote 68.178.165.65:56748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9QDQWat-noHLkDuAh51gABLwE"]
[Tue Jul 21 07:55:09.152905 2026] [security2:error] [pid 341679:tid 341927] [client 20.104.96.117:54992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9QDQWat-noHLkDuAh51wAAAYA"]
[Tue Jul 21 07:55:09.170364 2026] [security2:error] [pid 341679:tid 341716] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QDQWat-noHLkDuAh52AABVCQ"]
[Tue Jul 21 07:55:09.170475 2026] [security2:error] [pid 341679:tid 341883] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QDQWat-noHLkDuAh52AABVCQ"]
[Tue Jul 21 07:55:09.356025 2026] [security2:error] [pid 341679:tid 341862] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9QDQWat-noHLkDuAh54AAAAT8"]
[Tue Jul 21 07:55:09.523593 2026] [security2:error] [pid 341679:tid 341847] [client 20.206.105.145:28612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/themes.php"] [unique_id "al9QDQWat-noHLkDuAh54wAAATA"]
[Tue Jul 21 07:55:09.638412 2026] [security2:error] [pid 341679:tid 341897] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9QDQWat-noHLkDuAh55AAAAWI"]
[Tue Jul 21 07:55:09.788594 2026] [security2:error] [pid 341679:tid 341874] [client 20.226.60.151:56766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/popo.php"] [unique_id "al9QDQWat-noHLkDuAh57AAAAUs"]
[Tue Jul 21 07:55:09.924016 2026] [security2:error] [pid 341679:tid 341929] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9QDQWat-noHLkDuAh58gAAAYI"]
[Tue Jul 21 07:55:10.073479 2026] [security2:error] [pid 341679:tid 341850] [client 74.7.175.152:33194] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.purityox.com.br.agrocibus.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9QDgWat-noHLkDuAh59QABM20"]
[Tue Jul 21 07:55:10.208449 2026] [security2:error] [pid 341679:tid 341935] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9QDgWat-noHLkDuAh5-wAAAYg"]
[Tue Jul 21 07:55:10.324236 2026] [security2:error] [pid 341679:tid 341854] [client 193.36.225.68:49789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QDgWat-noHLkDuAh6AAAAATc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:10.403167 2026] [security2:error] [pid 341679:tid 341926] [client 20.104.96.117:54950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/h02ugyh.php"] [unique_id "al9QDgWat-noHLkDuAh6AgAAAX8"]
[Tue Jul 21 07:55:10.492673 2026] [security2:error] [pid 341679:tid 341867] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9QDgWat-noHLkDuAh6BAAAAUQ"]
[Tue Jul 21 07:55:10.596606 2026] [security2:error] [pid 341679:tid 341883] [client 20.226.60.151:61538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/solo1.php"] [unique_id "al9QDgWat-noHLkDuAh6BQAAAVQ"]
[Tue Jul 21 07:55:10.651239 2026] [security2:error] [pid 341679:tid 341856] [client 178.153.91.96:54272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QDgWat-noHLkDuAh6CQAAATk"]
[Tue Jul 21 07:55:10.651362 2026] [security2:error] [pid 341679:tid 341856] [client 178.153.91.96:54272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QDgWat-noHLkDuAh6CQAAATk"]
[Tue Jul 21 07:55:10.776404 2026] [security2:error] [pid 341679:tid 341931] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9QDgWat-noHLkDuAh6DQAAAYQ"]
[Tue Jul 21 07:55:10.940634 2026] [security2:error] [pid 341679:tid 341869] [client 20.206.105.145:55817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/8.php"] [unique_id "al9QDgWat-noHLkDuAh6GQAAAUY"]
[Tue Jul 21 07:55:11.060971 2026] [security2:error] [pid 341679:tid 341844] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9QDwWat-noHLkDuAh6HwAAAS0"]
[Tue Jul 21 07:55:11.260800 2026] [security2:error] [pid 341679:tid 341850] [client 65.21.113.253:45138] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9QDwWat-noHLkDuAh6JgAAATM"]
[Tue Jul 21 07:55:11.275744 2026] [security2:error] [pid 341679:tid 341920] [client 74.7.228.61:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.seja-anhembimorumbi.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9QDwWat-noHLkDuAh6JwAAAXk"]
[Tue Jul 21 07:55:11.276261 2026] [security2:error] [pid 341679:tid 341903] [client 74.7.228.61:54502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.seja-anhembimorumbi.com.br"] [uri "/robots.txt"] [unique_id "al9QDwWat-noHLkDuAh6JAABaGc"]
[Tue Jul 21 07:55:11.346677 2026] [security2:error] [pid 341679:tid 341832] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9QDwWat-noHLkDuAh6KAAAASE"]
[Tue Jul 21 07:55:11.399644 2026] [security2:error] [pid 341679:tid 341860] [client 20.226.60.151:56792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/yas.php"] [unique_id "al9QDwWat-noHLkDuAh6LQAAAT0"]
[Tue Jul 21 07:55:11.416406 2026] [security2:error] [pid 341679:tid 341843] [client 117.247.80.59:14834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QDwWat-noHLkDuAh6LgAAASw"]
[Tue Jul 21 07:55:11.416501 2026] [security2:error] [pid 341679:tid 341843] [client 117.247.80.59:14834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QDwWat-noHLkDuAh6LgAAASw"]
[Tue Jul 21 07:55:11.572891 2026] [security2:error] [pid 341679:tid 341855] [client 117.217.38.194:53627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QDwWat-noHLkDuAh6NQAAATg"]
[Tue Jul 21 07:55:11.573000 2026] [security2:error] [pid 341679:tid 341855] [client 117.217.38.194:53627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QDwWat-noHLkDuAh6NQAAATg"]
[Tue Jul 21 07:55:11.604518 2026] [security2:error] [pid 341679:tid 341909] [client 74.7.244.32:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "seja-anhembimorumbi.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9QDwWat-noHLkDuAh6OAAAAW4"]
[Tue Jul 21 07:55:11.605248 2026] [security2:error] [pid 341679:tid 341871] [client 74.7.244.32:43470] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "seja-anhembimorumbi.com.br"] [uri "/robots.txt"] [unique_id "al9QDwWat-noHLkDuAh6NgABSAc"]
[Tue Jul 21 07:55:11.658857 2026] [security2:error] [pid 341679:tid 341811] [client 65.21.113.253:58214] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QDwWat-noHLkDuAh6MAAAAQw"]
[Tue Jul 21 07:55:11.794552 2026] [security2:error] [pid 341679:tid 341828] [client 122.162.144.145:12719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QDwWat-noHLkDuAh6PQAAAR0"]
[Tue Jul 21 07:55:11.796873 2026] [security2:error] [pid 341679:tid 341828] [client 122.162.144.145:12719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QDwWat-noHLkDuAh6PQAAAR0"]
[Tue Jul 21 07:55:11.878681 2026] [security2:error] [pid 341679:tid 341770] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sbbarrosadvocacia.com.br"] [uri "/.env"] [unique_id "al9QDwWat-noHLkDuAh6QgABIFo"]
[Tue Jul 21 07:55:11.905128 2026] [security2:error] [pid 341679:tid 341887] [client 223.236.153.128:1898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QDwWat-noHLkDuAh6QwAAAVg"]
[Tue Jul 21 07:55:11.905254 2026] [security2:error] [pid 341679:tid 341887] [client 223.236.153.128:1898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QDwWat-noHLkDuAh6QwAAAVg"]
[Tue Jul 21 07:55:11.961247 2026] [security2:error] [pid 341679:tid 341726] [remote 130.185.118.215:43462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9QDwWat-noHLkDuAh6RwABNC4"]
[Tue Jul 21 07:55:11.961412 2026] [security2:error] [pid 341679:tid 341851] [client 130.185.118.215:43462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9QDwWat-noHLkDuAh6RwABNC4"]
[Tue Jul 21 07:55:12.066524 2026] [security2:error] [pid 341679:tid 341873] [client 20.104.96.117:54938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-temp.php"] [unique_id "al9QEAWat-noHLkDuAh6SQAAAUo"]
[Tue Jul 21 07:55:12.082720 2026] [security2:error] [pid 341679:tid 341816] [client 65.21.113.253:58218] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QDwWat-noHLkDuAh6RgAAARE"]
[Tue Jul 21 07:55:12.124948 2026] [security2:error] [pid 341679:tid 341686] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEAWat-noHLkDuAh6TQABNgY"]
[Tue Jul 21 07:55:12.125099 2026] [security2:error] [pid 341679:tid 341853] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEAWat-noHLkDuAh6TQABNgY"]
[Tue Jul 21 07:55:12.213420 2026] [security2:error] [pid 341679:tid 341892] [client 20.206.105.145:55895] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.aede.com.br"] [uri "/1.php"] [unique_id "al9QEAWat-noHLkDuAh6TgAAAV0"]
[Tue Jul 21 07:55:12.213543 2026] [security2:error] [pid 341679:tid 341892] [client 20.206.105.145:55895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/1.php"] [unique_id "al9QEAWat-noHLkDuAh6TgAAAV0"]
[Tue Jul 21 07:55:12.261217 2026] [security2:error] [pid 341679:tid 341765] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEAWat-noHLkDuAh6UQABbFU"]
[Tue Jul 21 07:55:12.261393 2026] [security2:error] [pid 341679:tid 341907] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEAWat-noHLkDuAh6UQABbFU"]
[Tue Jul 21 07:55:12.338912 2026] [security2:error] [pid 341679:tid 341861] [client 173.24.185.52:58433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9QEAWat-noHLkDuAh6VQAAAT4"]
[Tue Jul 21 07:55:12.339027 2026] [security2:error] [pid 341679:tid 341861] [client 173.24.185.52:58433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9QEAWat-noHLkDuAh6VQAAAT4"]
[Tue Jul 21 07:55:12.477208 2026] [security2:error] [pid 341679:tid 341737] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEAWat-noHLkDuAh6XgABDTk"]
[Tue Jul 21 07:55:12.477353 2026] [security2:error] [pid 341679:tid 341812] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEAWat-noHLkDuAh6XgABDTk"]
[Tue Jul 21 07:55:12.544075 2026] [security2:error] [pid 341679:tid 341863] [client 65.21.113.253:45154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QEAWat-noHLkDuAh6XwAAAUA"]
[Tue Jul 21 07:55:12.577241 2026] [security2:error] [pid 341679:tid 341896] [client 20.226.60.151:56753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/file61.php"] [unique_id "al9QEAWat-noHLkDuAh6YAAAAWE"]
[Tue Jul 21 07:55:12.736829 2026] [security2:error] [pid 341679:tid 341906] [client 103.166.103.129:47401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QEAWat-noHLkDuAh6ZAAAAWs"]
[Tue Jul 21 07:55:12.737017 2026] [security2:error] [pid 341679:tid 341906] [client 103.166.103.129:47401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QEAWat-noHLkDuAh6ZAAAAWs"]
[Tue Jul 21 07:55:12.834503 2026] [security2:error] [pid 341679:tid 341888] [client 65.21.113.253:58232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QEAWat-noHLkDuAh6WQAAAVk"]
[Tue Jul 21 07:55:13.076597 2026] [security2:error] [pid 341679:tid 341878] [client 139.167.225.182:64230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEQWat-noHLkDuAh6cgAAAU8"]
[Tue Jul 21 07:55:13.078327 2026] [security2:error] [pid 341679:tid 341878] [client 139.167.225.182:64230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEQWat-noHLkDuAh6cgAAAU8"]
[Tue Jul 21 07:55:13.239670 2026] [security2:error] [pid 341679:tid 341854] [client 103.78.200.11:49672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEQWat-noHLkDuAh6eQAAATc"]
[Tue Jul 21 07:55:13.240344 2026] [security2:error] [pid 341679:tid 341854] [client 103.78.200.11:49672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEQWat-noHLkDuAh6eQAAATc"]
[Tue Jul 21 07:55:13.283454 2026] [security2:error] [pid 341679:tid 341904] [client 180.153.236.232:50889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mahcruz.com.br"] [uri "/"] [unique_id "al9QEQWat-noHLkDuAh6egAAAWk"], referer: http://mahcruz.com.br/
[Tue Jul 21 07:55:13.283591 2026] [security2:error] [pid 341679:tid 341904] [client 180.153.236.232:50889] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mahcruz.com.br"] [uri "/"] [unique_id "al9QEQWat-noHLkDuAh6egAAAWk"], referer: http://mahcruz.com.br/
[Tue Jul 21 07:55:13.286958 2026] [security2:error] [pid 341679:tid 341875] [client 20.206.105.145:55831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/100.php"] [unique_id "al9QEQWat-noHLkDuAh6ewAAAUw"]
[Tue Jul 21 07:55:13.612156 2026] [security2:error] [pid 341679:tid 341898] [client 65.21.113.253:58234] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QEQWat-noHLkDuAh6eAAAAWM"]
[Tue Jul 21 07:55:13.616414 2026] [security2:error] [pid 341679:tid 341922] [client 20.104.96.117:55022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9QEQWat-noHLkDuAh6hwAAAXs"]
[Tue Jul 21 07:55:13.958266 2026] [security2:error] [pid 341679:tid 341738] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEQWat-noHLkDuAh6jwABDDo"]
[Tue Jul 21 07:55:13.958410 2026] [security2:error] [pid 341679:tid 341811] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEQWat-noHLkDuAh6jwABDDo"]
[Tue Jul 21 07:55:13.981499 2026] [security2:error] [pid 341679:tid 341883] [client 20.104.96.117:62779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9QEQWat-noHLkDuAh6kgAAAVQ"]
[Tue Jul 21 07:55:14.054011 2026] [security2:error] [pid 341679:tid 341881] [client 20.197.192.193:41482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/fz.php"] [unique_id "al9QEgWat-noHLkDuAh6kwAAAVI"]
[Tue Jul 21 07:55:14.212429 2026] [security2:error] [pid 341679:tid 341867] [client 136.144.33.29:55853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QEgWat-noHLkDuAh6nAAAAUQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:14.291394 2026] [security2:error] [pid 341679:tid 341833] [client 106.215.181.8:23582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEgWat-noHLkDuAh6oAAAASI"]
[Tue Jul 21 07:55:14.291510 2026] [security2:error] [pid 341679:tid 341833] [client 106.215.181.8:23582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEgWat-noHLkDuAh6oAAAASI"]
[Tue Jul 21 07:55:14.325208 2026] [security2:error] [pid 341679:tid 341865] [client 103.29.114.44:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEgWat-noHLkDuAh6oQAAAUI"]
[Tue Jul 21 07:55:14.325391 2026] [security2:error] [pid 341679:tid 341865] [client 103.29.114.44:54356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEgWat-noHLkDuAh6oQAAAUI"]
[Tue Jul 21 07:55:14.581312 2026] [security2:error] [pid 341679:tid 341862] [client 20.104.96.117:54959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9QEgWat-noHLkDuAh6rQAAAT8"]
[Tue Jul 21 07:55:14.725036 2026] [security2:error] [pid 341679:tid 341817] [client 122.186.204.214:62507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QEgWat-noHLkDuAh6sAAAARI"]
[Tue Jul 21 07:55:14.725163 2026] [security2:error] [pid 341679:tid 341817] [client 122.186.204.214:62507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QEgWat-noHLkDuAh6sAAAARI"]
[Tue Jul 21 07:55:15.120298 2026] [security2:error] [pid 341679:tid 341756] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sbbarrosadvocacia.com.br"] [uri "/api/.env"] [unique_id "al9QEwWat-noHLkDuAh6vgABL0w"]
[Tue Jul 21 07:55:15.130387 2026] [security2:error] [pid 341679:tid 341854] [client 182.8.255.181:17675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QEwWat-noHLkDuAh6wAAAATc"]
[Tue Jul 21 07:55:15.130486 2026] [security2:error] [pid 341679:tid 341854] [client 182.8.255.181:17675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QEwWat-noHLkDuAh6wAAAATc"]
[Tue Jul 21 07:55:15.295768 2026] [security2:error] [pid 341679:tid 341888] [client 20.104.96.117:57730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/jj.php"] [unique_id "al9QEwWat-noHLkDuAh6wQAAAVk"]
[Tue Jul 21 07:55:15.506652 2026] [security2:error] [pid 341679:tid 341911] [client 20.104.96.117:46403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9QEwWat-noHLkDuAh6ygAAAXA"]
[Tue Jul 21 07:55:15.579607 2026] [security2:error] [pid 341679:tid 341710] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEwWat-noHLkDuAh6zgABLR4"]
[Tue Jul 21 07:55:15.579853 2026] [security2:error] [pid 341679:tid 341844] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEwWat-noHLkDuAh6zgABLR4"]
[Tue Jul 21 07:55:15.635104 2026] [security2:error] [pid 341679:tid 341881] [client 45.3.38.36:39671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.38.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QEwWat-noHLkDuAh6xgAAAVI"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:55:15.813702 2026] [security2:error] [pid 341679:tid 341820] [client 198.54.128.138:44698] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9QEwWat-noHLkDuAh66gAAARU"]
[Tue Jul 21 07:55:15.813775 2026] [security2:error] [pid 341679:tid 341820] [client 198.54.128.138:44698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9QEwWat-noHLkDuAh66gAAARU"]
[Tue Jul 21 07:55:15.921662 2026] [security2:error] [pid 341679:tid 341824] [client 20.206.105.145:55822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/about.php"] [unique_id "al9QEwWat-noHLkDuAh7FgAAARk"]
[Tue Jul 21 07:55:16.055083 2026] [security2:error] [pid 341679:tid 341841] [client 20.104.96.117:62778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/xyn.php"] [unique_id "al9QFAWat-noHLkDuAh7IgAAASo"]
[Tue Jul 21 07:55:16.116300 2026] [security2:error] [pid 341679:tid 341867] [client 122.179.91.63:18578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QFAWat-noHLkDuAh7IwAAAUQ"]
[Tue Jul 21 07:55:16.116442 2026] [security2:error] [pid 341679:tid 341867] [client 122.179.91.63:18578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QFAWat-noHLkDuAh7IwAAAUQ"]
[Tue Jul 21 07:55:16.141932 2026] [security2:error] [pid 341679:tid 341893] [client 41.68.90.219:57457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QFAWat-noHLkDuAh7JwAAAV4"]
[Tue Jul 21 07:55:16.143238 2026] [security2:error] [pid 341679:tid 341893] [client 41.68.90.219:57457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QFAWat-noHLkDuAh7JwAAAV4"]
[Tue Jul 21 07:55:16.280678 2026] [security2:error] [pid 341679:tid 341888] [client 92.119.178.3:49220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9QFAWat-noHLkDuAh7NAAAAVk"]
[Tue Jul 21 07:55:16.280804 2026] [security2:error] [pid 341679:tid 341888] [client 92.119.178.3:49220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9QFAWat-noHLkDuAh7NAAAAVk"]
[Tue Jul 21 07:55:16.422586 2026] [security2:error] [pid 341679:tid 341756] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QFAWat-noHLkDuAh7aQABe0w"]
[Tue Jul 21 07:55:16.422739 2026] [security2:error] [pid 341679:tid 341922] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QFAWat-noHLkDuAh7aQABe0w"]
[Tue Jul 21 07:55:16.430296 2026] [security2:error] [pid 341679:tid 341876] [client 74.249.245.134:65126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/m.php"] [unique_id "al9QFAWat-noHLkDuAh7agAAAU0"]
[Tue Jul 21 07:55:16.445323 2026] [security2:error] [pid 341679:tid 341836] [client 65.21.113.253:58232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QEwWat-noHLkDuAh7HQAAASU"]
[Tue Jul 21 07:55:16.469630 2026] [security2:error] [pid 341679:tid 341812] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QEwWat-noHLkDuAh6vwABDV4"]
[Tue Jul 21 07:55:16.533271 2026] [security2:error] [pid 341679:tid 341892] [client 172.245.102.30:58121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QFAWat-noHLkDuAh7ZwAAAV0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:55:16.786479 2026] [security2:error] [pid 341679:tid 341930] [client 20.226.60.151:50570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/water.php"] [unique_id "al9QFAWat-noHLkDuAh7cwAAAYM"]
[Tue Jul 21 07:55:16.924296 2026] [security2:error] [pid 341679:tid 341710] [remote 45.79.123.44:52944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roha.life"] [uri "/wp-login.php"] [unique_id "al9QFAWat-noHLkDuAh7eAABDx4"]
[Tue Jul 21 07:55:16.997297 2026] [security2:error] [pid 341679:tid 341925] [client 20.104.96.117:62783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/patie.php"] [unique_id "al9QFAWat-noHLkDuAh7fQAAAX4"]
[Tue Jul 21 07:55:17.061842 2026] [security2:error] [pid 341679:tid 341827] [client 109.60.28.94:37509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QFQWat-noHLkDuAh7kQAAARw"]
[Tue Jul 21 07:55:17.062441 2026] [security2:error] [pid 341679:tid 341827] [client 109.60.28.94:37509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QFQWat-noHLkDuAh7kQAAARw"]
[Tue Jul 21 07:55:17.217758 2026] [security2:error] [pid 341679:tid 341881] [client 119.148.14.233:52977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.14.148.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hometohomelondon.com"] [uri "/xmlrpc.php"] [unique_id "al9QFQWat-noHLkDuAh7lwAAAVI"]
[Tue Jul 21 07:55:17.217893 2026] [security2:error] [pid 341679:tid 341881] [client 119.148.14.233:52977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hometohomelondon.com"] [uri "/xmlrpc.php"] [unique_id "al9QFQWat-noHLkDuAh7lwAAAVI"]
[Tue Jul 21 07:55:17.415984 2026] [security2:error] [pid 341679:tid 341907] [client 102.206.115.33:57494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QFQWat-noHLkDuAh7mgAAAWw"]
[Tue Jul 21 07:55:17.416114 2026] [security2:error] [pid 341679:tid 341907] [client 102.206.115.33:57494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QFQWat-noHLkDuAh7mgAAAWw"]
[Tue Jul 21 07:55:17.619292 2026] [security2:error] [pid 341679:tid 341832] [client 20.206.105.145:55886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/about.php"] [unique_id "al9QFQWat-noHLkDuAh7pAAAASE"]
[Tue Jul 21 07:55:17.783110 2026] [security2:error] [pid 341679:tid 341829] [client 202.143.127.214:50166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QFQWat-noHLkDuAh7qAAAAR4"]
[Tue Jul 21 07:55:17.783253 2026] [security2:error] [pid 341679:tid 341829] [client 202.143.127.214:50166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QFQWat-noHLkDuAh7qAAAAR4"]
[Tue Jul 21 07:55:17.880203 2026] [security2:error] [pid 341679:tid 341716] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QFQWat-noHLkDuAh7qgABSyQ"]
[Tue Jul 21 07:55:17.880383 2026] [security2:error] [pid 341679:tid 341874] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QFQWat-noHLkDuAh7qgABSyQ"]
[Tue Jul 21 07:55:17.892718 2026] [security2:error] [pid 341679:tid 341816] [client 122.164.127.47:64671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QFQWat-noHLkDuAh7qwAAARE"]
[Tue Jul 21 07:55:17.892884 2026] [security2:error] [pid 341679:tid 341816] [client 122.164.127.47:64671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QFQWat-noHLkDuAh7qwAAARE"]
[Tue Jul 21 07:55:17.983376 2026] [security2:error] [pid 341679:tid 341824] [client 20.197.192.193:3702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/la.php"] [unique_id "al9QFQWat-noHLkDuAh7rAAAARk"]
[Tue Jul 21 07:55:18.074189 2026] [security2:error] [pid 341679:tid 341801] [remote 154.0.166.254:52862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/wp-login.php"] [unique_id "al9QFgWat-noHLkDuAh7tAABYnk"]
[Tue Jul 21 07:55:18.077544 2026] [security2:error] [pid 341679:tid 341875] [client 37.140.223.68:45821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QFgWat-noHLkDuAh7swAAAUw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:18.087382 2026] [security2:error] [pid 341679:tid 341866] [client 65.111.23.6:58571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QFQWat-noHLkDuAh7lAAAAUM"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:55:18.176802 2026] [security2:error] [pid 341679:tid 341846] [client 20.104.96.117:62801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/aa.php"] [unique_id "al9QFgWat-noHLkDuAh7uQAAAS8"]
[Tue Jul 21 07:55:18.252185 2026] [security2:error] [pid 341679:tid 341864] [client 20.206.105.145:55813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/admin.php"] [unique_id "al9QFgWat-noHLkDuAh7uwAAAUE"]
[Tue Jul 21 07:55:18.281276 2026] [security2:error] [pid 341679:tid 341830] [client 91.92.41.115:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9QFgWat-noHLkDuAh7vAAAAR8"]
[Tue Jul 21 07:55:18.814345 2026] [proxy:error] [pid 341679:tid 341836] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:55:18.814387 2026] [proxy_http:error] [pid 341679:tid 341836] [client 91.92.41.115:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:55:18.814860 2026] [proxy:error] [pid 341679:tid 341836] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:55:18.814887 2026] [proxy_http:error] [pid 341679:tid 341836] [client 91.92.41.115:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:55:18.860629 2026] [security2:error] [pid 341679:tid 341834] [client 65.21.113.253:58232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QFgWat-noHLkDuAh7vQAAASM"]
[Tue Jul 21 07:55:18.926025 2026] [security2:error] [pid 341679:tid 341883] [client 103.86.117.203:61332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QFgWat-noHLkDuAh7ygAAAVQ"]
[Tue Jul 21 07:55:18.926171 2026] [security2:error] [pid 341679:tid 341883] [client 103.86.117.203:61332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QFgWat-noHLkDuAh7ygAAAVQ"]
[Tue Jul 21 07:55:19.009994 2026] [core:alert] [pid 341679:tid 341890] [client 57.141.18.79:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:55:19.129013 2026] [security2:error] [pid 341679:tid 341872] [client 20.226.60.151:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/nano.php"] [unique_id "al9QFwWat-noHLkDuAh71wAAAUk"]
[Tue Jul 21 07:55:19.168224 2026] [security2:error] [pid 341679:tid 341835] [client 20.104.96.117:54947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9QFwWat-noHLkDuAh72AAAASQ"]
[Tue Jul 21 07:55:19.227540 2026] [security2:error] [pid 341679:tid 341936] [client 74.249.245.134:64238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/click.php"] [unique_id "al9QFwWat-noHLkDuAh72QAAAYk"]
[Tue Jul 21 07:55:19.394856 2026] [security2:error] [pid 341679:tid 341866] [client 20.104.96.117:46412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/xwpg.php"] [unique_id "al9QFwWat-noHLkDuAh74AAAAUM"]
[Tue Jul 21 07:55:19.820304 2026] [security2:error] [pid 341679:tid 341724] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QFwWat-noHLkDuAh8FwABIiw"]
[Tue Jul 21 07:55:19.820510 2026] [security2:error] [pid 341679:tid 341833] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QFwWat-noHLkDuAh8FwABIiw"]
[Tue Jul 21 07:55:19.856139 2026] [security2:error] [pid 341679:tid 341926] [client 65.21.113.253:45838] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QFwWat-noHLkDuAh8GAAAAX8"]
[Tue Jul 21 07:55:20.205305 2026] [security2:error] [pid 341679:tid 341873] [client 20.104.96.117:62776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ops.php"] [unique_id "al9QGAWat-noHLkDuAh8LAAAAUo"]
[Tue Jul 21 07:55:20.398697 2026] [security2:error] [pid 341679:tid 341868] [client 37.140.223.118:50599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QGAWat-noHLkDuAh8LQAAAUU"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:55:20.450135 2026] [security2:error] [pid 341679:tid 341847] [client 65.21.113.253:58232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QGAWat-noHLkDuAh8HgAAATA"]
[Tue Jul 21 07:55:20.480434 2026] [security2:error] [pid 341679:tid 341882] [client 20.206.105.145:55830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/admin.php"] [unique_id "al9QGAWat-noHLkDuAh8NAAAAVM"]
[Tue Jul 21 07:55:20.587561 2026] [security2:error] [pid 341679:tid 341861] [client 216.73.160.191:63437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9QGAWat-noHLkDuAh8NwAAAT4"]
[Tue Jul 21 07:55:20.760949 2026] [autoindex:error] [pid 341679:tid 341866] [client 20.226.60.151:61586] AH01276: Cannot serve directory /home3/averme47/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:20.778955 2026] [security2:error] [pid 341679:tid 341768] [remote 102.134.101.35:51576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.bomnegociopromotora.com.br"] [uri "/wp-login.php"] [unique_id "al9QGAWat-noHLkDuAh8RwABJVg"]
[Tue Jul 21 07:55:20.842922 2026] [security2:error] [pid 341679:tid 341867] [client 20.226.60.151:50634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/moon.php"] [unique_id "al9QGAWat-noHLkDuAh8SQAAAUQ"]
[Tue Jul 21 07:55:21.188608 2026] [security2:error] [pid 341679:tid 341872] [client 65.21.113.253:49696] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QGAWat-noHLkDuAh8RAAAAUk"]
[Tue Jul 21 07:55:21.292092 2026] [security2:error] [pid 341679:tid 341829] [client 178.153.91.96:54894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QGQWat-noHLkDuAh8VgAAAR4"]
[Tue Jul 21 07:55:21.292208 2026] [security2:error] [pid 341679:tid 341829] [client 178.153.91.96:54894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QGQWat-noHLkDuAh8VgAAAR4"]
[Tue Jul 21 07:55:21.344158 2026] [security2:error] [pid 341679:tid 341854] [client 20.104.96.117:54960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/txets.php"] [unique_id "al9QGQWat-noHLkDuAh8XQAAATc"]
[Tue Jul 21 07:55:21.544846 2026] [security2:error] [pid 341679:tid 341849] [client 20.104.96.117:62835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/mac.php"] [unique_id "al9QGQWat-noHLkDuAh8YwAAATI"]
[Tue Jul 21 07:55:21.878323 2026] [security2:error] [pid 341679:tid 341820] [client 20.206.105.145:55853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/edit.php"] [unique_id "al9QGQWat-noHLkDuAh8bgAAARU"]
[Tue Jul 21 07:55:21.892956 2026] [security2:error] [pid 341679:tid 341919] [client 65.21.113.253:45838] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QGQWat-noHLkDuAh8bwAAAXg"]
[Tue Jul 21 07:55:21.954129 2026] [security2:error] [pid 341679:tid 341916] [client 117.247.80.59:15341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGQWat-noHLkDuAh8cQAAAXU"]
[Tue Jul 21 07:55:21.954234 2026] [security2:error] [pid 341679:tid 341916] [client 117.247.80.59:15341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGQWat-noHLkDuAh8cQAAAXU"]
[Tue Jul 21 07:55:22.030147 2026] [security2:error] [pid 341679:tid 341844] [client 117.217.38.194:54131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8cwAAAS0"]
[Tue Jul 21 07:55:22.030244 2026] [security2:error] [pid 341679:tid 341844] [client 117.217.38.194:54131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8cwAAAS0"]
[Tue Jul 21 07:55:22.253100 2026] [security2:error] [pid 341679:tid 341923] [client 204.8.98.45:39924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8fgAAAXw"]
[Tue Jul 21 07:55:22.253182 2026] [security2:error] [pid 341679:tid 341923] [client 204.8.98.45:39924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8fgAAAXw"]
[Tue Jul 21 07:55:22.504527 2026] [security2:error] [pid 341679:tid 341856] [client 65.21.113.253:49696] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QGgWat-noHLkDuAh8dQAAATk"]
[Tue Jul 21 07:55:22.555075 2026] [security2:error] [pid 341679:tid 341859] [client 122.162.144.145:6837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8jAAAATw"]
[Tue Jul 21 07:55:22.557427 2026] [security2:error] [pid 341679:tid 341859] [client 122.162.144.145:6837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8jAAAATw"]
[Tue Jul 21 07:55:22.621432 2026] [security2:error] [pid 341679:tid 341817] [client 20.226.60.151:50643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-info.php"] [unique_id "al9QGgWat-noHLkDuAh8jQAAARI"]
[Tue Jul 21 07:55:22.636145 2026] [security2:error] [pid 341679:tid 341816] [client 223.236.153.128:5947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8jwAAARE"]
[Tue Jul 21 07:55:22.636332 2026] [security2:error] [pid 341679:tid 341816] [client 223.236.153.128:5947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8jwAAARE"]
[Tue Jul 21 07:55:22.689229 2026] [security2:error] [pid 341679:tid 341697] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8kwABQhE"]
[Tue Jul 21 07:55:22.689397 2026] [security2:error] [pid 341679:tid 341865] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8kwABQhE"]
[Tue Jul 21 07:55:22.732562 2026] [security2:error] [pid 341679:tid 341858] [client 20.226.60.151:61586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/cong.php"] [unique_id "al9QGgWat-noHLkDuAh8lQAAATs"]
[Tue Jul 21 07:55:22.799535 2026] [security2:error] [pid 341679:tid 341716] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8mAABaSQ"]
[Tue Jul 21 07:55:22.799674 2026] [security2:error] [pid 341679:tid 341904] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8mAABaSQ"]
[Tue Jul 21 07:55:22.832293 2026] [security2:error] [pid 341679:tid 341864] [client 172.245.102.44:36131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QGgWat-noHLkDuAh8mQAAAUE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:22.868370 2026] [rewrite:warn] [pid 341679:tid 341745] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 07:55:22.939975 2026] [security2:error] [pid 341679:tid 341838] [client 173.24.185.52:58918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8owAAASc"]
[Tue Jul 21 07:55:22.940088 2026] [security2:error] [pid 341679:tid 341838] [client 173.24.185.52:58918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8owAAASc"]
[Tue Jul 21 07:55:22.983658 2026] [security2:error] [pid 341679:tid 341801] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8pAABbXk"]
[Tue Jul 21 07:55:22.983886 2026] [security2:error] [pid 341679:tid 341908] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGgWat-noHLkDuAh8pAABbXk"]
[Tue Jul 21 07:55:23.206641 2026] [authz_core:error] [pid 341679:tid 341923] [client 82.102.18.182:0] AH01630: client denied by server configuration: /home4/bomexi25/agenciawats.com.br/wp-content/uploads/index.php
[Tue Jul 21 07:55:23.217886 2026] [security2:error] [pid 341679:tid 341833] [client 20.104.96.117:57740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/dex.php"] [unique_id "al9QGwWat-noHLkDuAh8rgAAASI"]
[Tue Jul 21 07:55:23.353257 2026] [security2:error] [pid 341679:tid 341888] [client 74.7.244.34:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.shopmelhorcompraonline.com"] [uri "/index.php"] [unique_id "al9QGgWat-noHLkDuAh8iAABWTg"]
[Tue Jul 21 07:55:23.370355 2026] [security2:error] [pid 341679:tid 341885] [client 139.167.225.182:64885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGwWat-noHLkDuAh8tQAAAVY"]
[Tue Jul 21 07:55:23.370471 2026] [security2:error] [pid 341679:tid 341885] [client 139.167.225.182:64885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGwWat-noHLkDuAh8tQAAAVY"]
[Tue Jul 21 07:55:23.523304 2026] [security2:error] [pid 341679:tid 341891] [client 20.104.96.117:62744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/mg.php"] [unique_id "al9QGwWat-noHLkDuAh8ugAAAVw"]
[Tue Jul 21 07:55:23.523610 2026] [security2:error] [pid 341679:tid 341876] [client 103.166.103.129:47949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QGwWat-noHLkDuAh8uwAAAU0"]
[Tue Jul 21 07:55:23.523735 2026] [security2:error] [pid 341679:tid 341876] [client 103.166.103.129:47949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QGwWat-noHLkDuAh8uwAAAU0"]
[Tue Jul 21 07:55:23.609371 2026] [autoindex:error] [pid 341679:tid 341840] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:23.825261 2026] [autoindex:error] [pid 341679:tid 341835] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:23.830966 2026] [security2:error] [pid 341679:tid 341934] [client 74.7.244.34:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shopmelhorcompraonline.com"] [uri "/index.php"] [unique_id "al9QGwWat-noHLkDuAh8wwABh3Q"], referer: https://www.shopmelhorcompraonline.com/robots.txt
[Tue Jul 21 07:55:23.872343 2026] [security2:error] [pid 341679:tid 341869] [client 103.78.200.11:50144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGwWat-noHLkDuAh8yQAAAUY"]
[Tue Jul 21 07:55:23.875203 2026] [security2:error] [pid 341679:tid 341869] [client 103.78.200.11:50144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGwWat-noHLkDuAh8yQAAAUY"]
[Tue Jul 21 07:55:23.998610 2026] [autoindex:error] [pid 341679:tid 341896] [client 205.210.31.18:62690] AH01276: Cannot serve directory /home2/bavosc49/booking.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:24.035128 2026] [autoindex:error] [pid 341679:tid 341838] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:24.070941 2026] [security2:error] [pid 341679:tid 341861] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QGwWat-noHLkDuAh8zgABPlk"]
[Tue Jul 21 07:55:24.092624 2026] [security2:error] [pid 341679:tid 341897] [client 74.249.245.134:65141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/lv.php"] [unique_id "al9QHAWat-noHLkDuAh81AAAAWI"]
[Tue Jul 21 07:55:24.243583 2026] [autoindex:error] [pid 341679:tid 341841] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:24.323024 2026] [security2:error] [pid 341679:tid 341880] [client 20.104.96.117:62834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-post-data.php"] [unique_id "al9QHAWat-noHLkDuAh84QAAAVE"]
[Tue Jul 21 07:55:24.354825 2026] [security2:error] [pid 341679:tid 341878] [client 65.21.113.253:45838] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QHAWat-noHLkDuAh84wAAAU8"]
[Tue Jul 21 07:55:24.450042 2026] [autoindex:error] [pid 341679:tid 341827] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:24.461105 2026] [security2:error] [pid 341679:tid 341885] [client 20.226.60.151:50660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/2000.php"] [unique_id "al9QHAWat-noHLkDuAh87wAAAVY"]
[Tue Jul 21 07:55:24.588839 2026] [security2:error] [pid 341679:tid 341855] [client 20.206.105.145:55809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9QHAWat-noHLkDuAh88QAAATg"]
[Tue Jul 21 07:55:24.669908 2026] [autoindex:error] [pid 341679:tid 341890] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:24.836257 2026] [security2:error] [pid 341679:tid 341811] [client 106.215.181.8:19834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QHAWat-noHLkDuAh8_gAAAQw"]
[Tue Jul 21 07:55:24.836362 2026] [security2:error] [pid 341679:tid 341811] [client 106.215.181.8:19834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QHAWat-noHLkDuAh8_gAAAQw"]
[Tue Jul 21 07:55:24.878293 2026] [autoindex:error] [pid 341679:tid 341911] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:24.972537 2026] [security2:error] [pid 341679:tid 341867] [client 103.29.114.44:58002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QHAWat-noHLkDuAh9CAAAAUQ"]
[Tue Jul 21 07:55:24.972637 2026] [security2:error] [pid 341679:tid 341867] [client 103.29.114.44:58002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QHAWat-noHLkDuAh9CAAAAUQ"]
[Tue Jul 21 07:55:25.009158 2026] [security2:error] [pid 341679:tid 341919] [client 204.8.98.45:39926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9QHQWat-noHLkDuAh9CgAAAXg"]
[Tue Jul 21 07:55:25.009285 2026] [security2:error] [pid 341679:tid 341919] [client 204.8.98.45:39926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9QHQWat-noHLkDuAh9CgAAAXg"]
[Tue Jul 21 07:55:25.015407 2026] [security2:error] [pid 341679:tid 341706] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QHQWat-noHLkDuAh9CwABdRo"]
[Tue Jul 21 07:55:25.015552 2026] [security2:error] [pid 341679:tid 341916] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QHQWat-noHLkDuAh9CwABdRo"]
[Tue Jul 21 07:55:25.142892 2026] [security2:error] [pid 341679:tid 341846] [client 20.104.96.117:62748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/pucci.php"] [unique_id "al9QHQWat-noHLkDuAh9FwAAAS8"]
[Tue Jul 21 07:55:25.287316 2026] [security2:error] [pid 341679:tid 341823] [client 65.21.113.253:49710] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QHAWat-noHLkDuAh8_QAAARg"]
[Tue Jul 21 07:55:25.385037 2026] [security2:error] [pid 341679:tid 341924] [client 31.57.219.92:38022] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "nbmnews.com"] [uri "/"] [unique_id "al9QHQWat-noHLkDuAh9IgAAAX0"]
[Tue Jul 21 07:55:25.434473 2026] [security2:error] [pid 341679:tid 341840] [client 65.21.113.253:49718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QHQWat-noHLkDuAh9DAAAASk"]
[Tue Jul 21 07:55:25.614341 2026] [security2:error] [pid 341679:tid 341812] [client 182.8.255.181:17599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QHQWat-noHLkDuAh9KgAAAQ0"]
[Tue Jul 21 07:55:25.614476 2026] [security2:error] [pid 341679:tid 341812] [client 182.8.255.181:17599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QHQWat-noHLkDuAh9KgAAAQ0"]
[Tue Jul 21 07:55:25.775162 2026] [security2:error] [pid 341679:tid 341936] [client 20.226.60.151:56723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/122.php"] [unique_id "al9QHQWat-noHLkDuAh9LgAAAYk"]
[Tue Jul 21 07:55:25.817545 2026] [security2:error] [pid 341679:tid 341868] [client 74.249.245.134:24778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/cong.php"] [unique_id "al9QHQWat-noHLkDuAh9LwAAAUU"]
[Tue Jul 21 07:55:25.850207 2026] [security2:error] [pid 341679:tid 341884] [client 45.146.55.201:38041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lumerah.com.br"] [uri "/wp-login.php"] [unique_id "al9QHQWat-noHLkDuAh9KwAAAVU"]
[Tue Jul 21 07:55:26.036747 2026] [security2:error] [pid 341679:tid 341844] [client 3.135.244.30:56694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "tabelionatoportoalegre.com.br"] [uri "/robots.txt"] [unique_id "al9QHgWat-noHLkDuAh9OAAAAS0"]
[Tue Jul 21 07:55:26.057953 2026] [security2:error] [pid 341679:tid 341680] [remote 45.79.123.44:38158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compressoresra.com.br"] [uri "/wp-login.php"] [unique_id "al9QHgWat-noHLkDuAh9OQABcAA"]
[Tue Jul 21 07:55:26.107390 2026] [security2:error] [pid 341679:tid 341850] [client 20.104.96.117:62785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/black.php"] [unique_id "al9QHgWat-noHLkDuAh9OwAAATM"]
[Tue Jul 21 07:55:26.209280 2026] [security2:error] [pid 341679:tid 341762] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QHgWat-noHLkDuAh9QAABNFI"]
[Tue Jul 21 07:55:26.209433 2026] [security2:error] [pid 341679:tid 341851] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QHgWat-noHLkDuAh9QAABNFI"]
[Tue Jul 21 07:55:26.314678 2026] [security2:error] [pid 341679:tid 341814] [client 3.135.244.30:48690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9QHgWat-noHLkDuAh9QwAAAQ8"]
[Tue Jul 21 07:55:26.349775 2026] [security2:error] [pid 341679:tid 341856] [client 3.135.244.30:56700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "tabelionatoportoalegre.com.br"] [uri "/ads.txt"] [unique_id "al9QHgWat-noHLkDuAh9RgAAATk"]
[Tue Jul 21 07:55:26.369283 2026] [security2:error] [pid 341679:tid 341889] [client 3.135.244.30:48712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "tabelionatoportoalegre.com.br"] [uri "/robots.txt"] [unique_id "al9QHgWat-noHLkDuAh9SQAAAVo"]
[Tue Jul 21 07:55:26.757089 2026] [security2:error] [pid 341679:tid 341863] [client 122.186.204.214:63045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QHgWat-noHLkDuAh9WgAAAUA"]
[Tue Jul 21 07:55:26.760543 2026] [security2:error] [pid 341679:tid 341863] [client 122.186.204.214:63045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QHgWat-noHLkDuAh9WgAAAUA"]
[Tue Jul 21 07:55:26.822855 2026] [security2:error] [pid 341679:tid 341896] [client 3.135.244.30:48718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9QHgWat-noHLkDuAh9XAAAAWE"]
[Tue Jul 21 07:55:26.910791 2026] [security2:error] [pid 341679:tid 341866] [client 20.197.192.193:3185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9QHgWat-noHLkDuAh9XgAAAUM"]
[Tue Jul 21 07:55:26.968163 2026] [security2:error] [pid 341679:tid 341906] [client 41.68.90.219:57919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QHgWat-noHLkDuAh9ZwAAAWs"]
[Tue Jul 21 07:55:26.969880 2026] [security2:error] [pid 341679:tid 341906] [client 41.68.90.219:57919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QHgWat-noHLkDuAh9ZwAAAWs"]
[Tue Jul 21 07:55:26.997461 2026] [security2:error] [pid 341679:tid 341880] [client 20.104.96.117:62830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/zlece.php"] [unique_id "al9QHgWat-noHLkDuAh9aAAAAVE"]
[Tue Jul 21 07:55:27.078085 2026] [security2:error] [pid 341679:tid 341924] [client 122.179.91.63:22908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QHwWat-noHLkDuAh9bQAAAX0"]
[Tue Jul 21 07:55:27.078201 2026] [security2:error] [pid 341679:tid 341924] [client 122.179.91.63:22908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QHwWat-noHLkDuAh9bQAAAX0"]
[Tue Jul 21 07:55:27.382844 2026] [security2:error] [pid 341679:tid 341890] [client 136.144.33.96:41171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QHwWat-noHLkDuAh9dwAAAVs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:27.476704 2026] [security2:error] [pid 341679:tid 341739] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QHwWat-noHLkDuAh9fQABETs"]
[Tue Jul 21 07:55:27.476843 2026] [security2:error] [pid 341679:tid 341816] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QHwWat-noHLkDuAh9fQABETs"]
[Tue Jul 21 07:55:27.919072 2026] [security2:error] [pid 341679:tid 341905] [client 109.60.28.94:37955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QHwWat-noHLkDuAh9iwAAAWo"]
[Tue Jul 21 07:55:27.920320 2026] [security2:error] [pid 341679:tid 341905] [client 109.60.28.94:37955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QHwWat-noHLkDuAh9iwAAAWo"]
[Tue Jul 21 07:55:28.051370 2026] [security2:error] [pid 341679:tid 341889] [client 102.206.115.33:57924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QIAWat-noHLkDuAh9kQAAAVo"]
[Tue Jul 21 07:55:28.051898 2026] [security2:error] [pid 341679:tid 341889] [client 102.206.115.33:57924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QIAWat-noHLkDuAh9kQAAAVo"]
[Tue Jul 21 07:55:28.139808 2026] [security2:error] [pid 341679:tid 341901] [client 74.249.245.134:18457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/brand.php"] [unique_id "al9QIAWat-noHLkDuAh9mQAAAWY"]
[Tue Jul 21 07:55:28.281472 2026] [security2:error] [pid 341679:tid 341893] [client 20.104.96.117:46458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/vssrs.php"] [unique_id "al9QIAWat-noHLkDuAh9ogAAAV4"]
[Tue Jul 21 07:55:28.472735 2026] [security2:error] [pid 341679:tid 341875] [client 65.21.113.253:49710] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QIAWat-noHLkDuAh9kAAAAUw"]
[Tue Jul 21 07:55:28.641973 2026] [security2:error] [pid 341679:tid 341916] [client 202.143.127.214:50633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QIAWat-noHLkDuAh9rgAAAXU"]
[Tue Jul 21 07:55:28.642103 2026] [security2:error] [pid 341679:tid 341916] [client 202.143.127.214:50633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QIAWat-noHLkDuAh9rgAAAXU"]
[Tue Jul 21 07:55:28.664697 2026] [security2:error] [pid 341679:tid 341812] [client 204.8.98.45:46478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9QIAWat-noHLkDuAh9sQAAAQ0"]
[Tue Jul 21 07:55:28.664790 2026] [security2:error] [pid 341679:tid 341812] [client 204.8.98.45:46478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9QIAWat-noHLkDuAh9sQAAAQ0"]
[Tue Jul 21 07:55:28.665882 2026] [security2:error] [pid 341679:tid 341868] [client 122.164.127.47:65261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QIAWat-noHLkDuAh9sgAAAUU"]
[Tue Jul 21 07:55:28.665976 2026] [security2:error] [pid 341679:tid 341868] [client 122.164.127.47:65261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QIAWat-noHLkDuAh9sgAAAUU"]
[Tue Jul 21 07:55:28.669378 2026] [security2:error] [pid 341679:tid 341714] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QIAWat-noHLkDuAh9swABfCI"]
[Tue Jul 21 07:55:28.669477 2026] [security2:error] [pid 341679:tid 341923] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QIAWat-noHLkDuAh9swABfCI"]
[Tue Jul 21 07:55:29.104775 2026] [autoindex:error] [pid 341679:tid 341819] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:29.129986 2026] [security2:error] [pid 341679:tid 341926] [client 20.206.105.145:55896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/f6.php"] [unique_id "al9QIQWat-noHLkDuAh9xQAAAX8"]
[Tue Jul 21 07:55:29.163998 2026] [security2:error] [pid 341679:tid 341735] [remote 45.79.123.44:35764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9QIQWat-noHLkDuAh9yQABOzc"]
[Tue Jul 21 07:55:29.317912 2026] [autoindex:error] [pid 341679:tid 341814] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:29.404288 2026] [security2:error] [pid 341679:tid 341842] [client 103.86.117.203:61877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QIQWat-noHLkDuAh91AAAASs"]
[Tue Jul 21 07:55:29.404384 2026] [security2:error] [pid 341679:tid 341842] [client 103.86.117.203:61877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QIQWat-noHLkDuAh91AAAASs"]
[Tue Jul 21 07:55:29.548899 2026] [security2:error] [pid 341679:tid 341824] [client 20.104.96.117:62754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wicked.php"] [unique_id "al9QIQWat-noHLkDuAh94gAAARk"]
[Tue Jul 21 07:55:29.742497 2026] [autoindex:error] [pid 341679:tid 341907] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:29.952585 2026] [autoindex:error] [pid 341679:tid 341834] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:29.998142 2026] [security2:error] [pid 341679:tid 341830] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9QIQWat-noHLkDuAh99QAAAR8"]
[Tue Jul 21 07:55:30.042235 2026] [security2:error] [pid 341679:tid 341867] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9QIgWat-noHLkDuAh9-QAAAUQ"]
[Tue Jul 21 07:55:30.167940 2026] [autoindex:error] [pid 341679:tid 341818] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:30.348200 2026] [security2:error] [pid 341679:tid 341851] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9QIgWat-noHLkDuAh-BgAAATQ"]
[Tue Jul 21 07:55:30.379124 2026] [autoindex:error] [pid 341679:tid 341893] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:30.400171 2026] [security2:error] [pid 341679:tid 341810] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9QIgWat-noHLkDuAh-CgAAAQs"]
[Tue Jul 21 07:55:30.586917 2026] [security2:error] [pid 341679:tid 341745] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QIgWat-noHLkDuAh-EwABO0E"]
[Tue Jul 21 07:55:30.587038 2026] [security2:error] [pid 341679:tid 341858] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QIgWat-noHLkDuAh-EwABO0E"]
[Tue Jul 21 07:55:30.588560 2026] [security2:error] [pid 341679:tid 341839] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9QIgWat-noHLkDuAh-FAAAASg"]
[Tue Jul 21 07:55:30.589665 2026] [autoindex:error] [pid 341679:tid 341859] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:30.642292 2026] [security2:error] [pid 341679:tid 341856] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9QIgWat-noHLkDuAh-FQAAATk"]
[Tue Jul 21 07:55:30.805670 2026] [security2:error] [pid 341679:tid 341842] [client 65.21.113.253:49710] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QIgWat-noHLkDuAh-CwAAASs"]
[Tue Jul 21 07:55:30.841712 2026] [security2:error] [pid 341679:tid 341884] [client 74.249.245.134:65185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/atomlib.php"] [unique_id "al9QIgWat-noHLkDuAh-HwAAAVU"]
[Tue Jul 21 07:55:30.954253 2026] [security2:error] [pid 341679:tid 341903] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9QIgWat-noHLkDuAh-JwAAAWg"]
[Tue Jul 21 07:55:30.963200 2026] [security2:error] [pid 341679:tid 341834] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9QIgWat-noHLkDuAh-KAAAASM"]
[Tue Jul 21 07:55:30.989439 2026] [security2:error] [pid 341679:tid 341830] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9QIgWat-noHLkDuAh-KgAAAR8"]
[Tue Jul 21 07:55:31.010325 2026] [autoindex:error] [pid 341679:tid 341840] [client 20.226.60.151:53983] AH01276: Cannot serve directory /home3/averme47/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:31.020421 2026] [security2:error] [pid 341679:tid 341860] [client 20.226.60.151:53983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/public/css.php"] [unique_id "al9QIwWat-noHLkDuAh-LwAAAT0"]
[Tue Jul 21 07:55:31.058660 2026] [security2:error] [pid 341679:tid 341844] [client 20.226.60.151:50596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/mds.php"] [unique_id "al9QIwWat-noHLkDuAh-MQAAAS0"]
[Tue Jul 21 07:55:31.063527 2026] [security2:error] [pid 341679:tid 341846] [client 136.144.33.241:64025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QIgWat-noHLkDuAh-IgAAAS8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:31.218931 2026] [security2:error] [pid 341679:tid 341914] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9QIwWat-noHLkDuAh-OwAAAXM"]
[Tue Jul 21 07:55:31.229704 2026] [security2:error] [pid 341679:tid 341880] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9QIwWat-noHLkDuAh-PAAAAVE"]
[Tue Jul 21 07:55:31.282609 2026] [security2:error] [pid 341679:tid 341855] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9QIwWat-noHLkDuAh-QQAAATg"]
[Tue Jul 21 07:55:31.478392 2026] [security2:error] [pid 341679:tid 341883] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9QIwWat-noHLkDuAh-UgAAAVQ"]
[Tue Jul 21 07:55:31.479752 2026] [security2:error] [pid 341679:tid 341813] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9QIwWat-noHLkDuAh-UwAAAQ4"]
[Tue Jul 21 07:55:31.678540 2026] [security2:error] [pid 341679:tid 341835] [client 20.104.96.117:46358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/24.php"] [unique_id "al9QIwWat-noHLkDuAh-XgAAASQ"]
[Tue Jul 21 07:55:31.724422 2026] [security2:error] [pid 341679:tid 341903] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9QIwWat-noHLkDuAh-YQAAAWg"]
[Tue Jul 21 07:55:31.729107 2026] [security2:error] [pid 341679:tid 341929] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9QIwWat-noHLkDuAh-YwAAAYI"]
[Tue Jul 21 07:55:31.749488 2026] [security2:error] [pid 341679:tid 341711] [remote 65.111.24.196:45639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9QIgWat-noHLkDuAh-EAABQB8"]
[Tue Jul 21 07:55:31.766561 2026] [security2:error] [pid 341679:tid 341896] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9QIwWat-noHLkDuAh-ZgAAAWE"]
[Tue Jul 21 07:55:31.814811 2026] [security2:error] [pid 341679:tid 341907] [client 198.54.128.138:34880] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9QIwWat-noHLkDuAh-WwAAAWw"]
[Tue Jul 21 07:55:31.814903 2026] [security2:error] [pid 341679:tid 341907] [client 198.54.128.138:34880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9QIwWat-noHLkDuAh-WwAAAWw"]
[Tue Jul 21 07:55:31.828483 2026] [security2:error] [pid 341679:tid 341846] [client 65.21.113.253:44150] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QIwWat-noHLkDuAh-aQAAAS8"]
[Tue Jul 21 07:55:31.828554 2026] [security2:error] [pid 341679:tid 341857] [client 178.153.91.96:60289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QIwWat-noHLkDuAh-awAAATo"]
[Tue Jul 21 07:55:31.828658 2026] [security2:error] [pid 341679:tid 341857] [client 178.153.91.96:60289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QIwWat-noHLkDuAh-awAAATo"]
[Tue Jul 21 07:55:31.882040 2026] [security2:error] [pid 341679:tid 341817] [client 49.13.164.148:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9QIwWat-noHLkDuAh-bgABEmY"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:55:31.981164 2026] [security2:error] [pid 341679:tid 341926] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9QIwWat-noHLkDuAh-cAAAAX8"]
[Tue Jul 21 07:55:31.992519 2026] [security2:error] [pid 341679:tid 341849] [client 20.104.96.117:54967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/xpwer1.php"] [unique_id "al9QIwWat-noHLkDuAh-cQAAATI"]
[Tue Jul 21 07:55:32.016050 2026] [autoindex:error] [pid 341679:tid 341914] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:32.148795 2026] [security2:error] [pid 341679:tid 341935] [client 38.100.221.102:18988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJAWat-noHLkDuAh-fQAAAYg"]
[Tue Jul 21 07:55:32.148957 2026] [security2:error] [pid 341679:tid 341935] [client 38.100.221.102:18988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJAWat-noHLkDuAh-fQAAAYg"]
[Tue Jul 21 07:55:32.228125 2026] [security2:error] [pid 341679:tid 341815] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9QJAWat-noHLkDuAh-ggAAARA"]
[Tue Jul 21 07:55:32.310155 2026] [security2:error] [pid 341679:tid 341887] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9QJAWat-noHLkDuAh-gwAAAVg"]
[Tue Jul 21 07:55:32.414556 2026] [security2:error] [pid 341679:tid 341821] [client 117.247.80.59:15831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJAWat-noHLkDuAh-iAAAARY"]
[Tue Jul 21 07:55:32.414646 2026] [security2:error] [pid 341679:tid 341821] [client 117.247.80.59:15831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJAWat-noHLkDuAh-iAAAARY"]
[Tue Jul 21 07:55:32.427050 2026] [security2:error] [pid 341679:tid 341859] [client 49.13.164.148:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9QJAWat-noHLkDuAh-igABPEQ"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:55:32.428771 2026] [security2:error] [pid 341679:tid 341881] [client 65.21.113.253:49710] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QJAWat-noHLkDuAh-eAAAAVI"]
[Tue Jul 21 07:55:32.457357 2026] [security2:error] [pid 341679:tid 341882] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9QJAWat-noHLkDuAh-iwAAAVM"]
[Tue Jul 21 07:55:32.466100 2026] [security2:error] [pid 341679:tid 341921] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9QJAWat-noHLkDuAh-jAAAAXo"]
[Tue Jul 21 07:55:32.534877 2026] [security2:error] [pid 341679:tid 341918] [client 117.217.38.194:54622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJAWat-noHLkDuAh-kAAAAXc"]
[Tue Jul 21 07:55:32.535161 2026] [security2:error] [pid 341679:tid 341918] [client 117.217.38.194:54622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJAWat-noHLkDuAh-kAAAAXc"]
[Tue Jul 21 07:55:32.649245 2026] [security2:error] [pid 341679:tid 341936] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9QJAWat-noHLkDuAh-lwAAAYk"]
[Tue Jul 21 07:55:32.771604 2026] [security2:error] [pid 341679:tid 341866] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9QJAWat-noHLkDuAh-nQAAAUM"]
[Tue Jul 21 07:55:32.780997 2026] [security2:error] [pid 341679:tid 341844] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9QJAWat-noHLkDuAh-ngAAAS0"]
[Tue Jul 21 07:55:33.019193 2026] [security2:error] [pid 341679:tid 341858] [client 20.104.96.117:62745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/xacs.php"] [unique_id "al9QJQWat-noHLkDuAh-ugAAATs"]
[Tue Jul 21 07:55:33.041969 2026] [security2:error] [pid 341679:tid 341827] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9QJQWat-noHLkDuAh-uwAAARw"]
[Tue Jul 21 07:55:33.112588 2026] [security2:error] [pid 341679:tid 341879] [client 160.30.136.8:65367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9QJQWat-noHLkDuAh-wAAAAVA"]
[Tue Jul 21 07:55:33.117866 2026] [security2:error] [pid 341679:tid 341873] [client 20.206.105.145:55932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/inputs.php"] [unique_id "al9QJQWat-noHLkDuAh-wQAAAUo"]
[Tue Jul 21 07:55:33.122510 2026] [security2:error] [pid 341679:tid 341920] [client 91.92.41.115:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.lucasrochadesousa1782842679000.0711679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9QJQWat-noHLkDuAh-wgAAAXk"]
[Tue Jul 21 07:55:33.273353 2026] [security2:error] [pid 341679:tid 341869] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9QJQWat-noHLkDuAh-xgAAAUY"]
[Tue Jul 21 07:55:33.274662 2026] [security2:error] [pid 341679:tid 341811] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473155000.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9QJQWat-noHLkDuAh-xwAAAQw"]
[Tue Jul 21 07:55:33.290208 2026] [security2:error] [pid 341679:tid 341840] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9QJQWat-noHLkDuAh-yAAAASk"]
[Tue Jul 21 07:55:33.341292 2026] [security2:error] [pid 341679:tid 341780] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJQWat-noHLkDuAh-ygABe2Q"]
[Tue Jul 21 07:55:33.341415 2026] [security2:error] [pid 341679:tid 341922] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJQWat-noHLkDuAh-ygABe2Q"]
[Tue Jul 21 07:55:33.382580 2026] [security2:error] [pid 341679:tid 341868] [client 223.236.153.128:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QJQWat-noHLkDuAh-zQAAAUU"]
[Tue Jul 21 07:55:33.382729 2026] [security2:error] [pid 341679:tid 341868] [client 223.236.153.128:5522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QJQWat-noHLkDuAh-zQAAAUU"]
[Tue Jul 21 07:55:33.463489 2026] [security2:error] [pid 341679:tid 341862] [client 122.162.144.145:10881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QJQWat-noHLkDuAh-1QAAAT8"]
[Tue Jul 21 07:55:33.463697 2026] [security2:error] [pid 341679:tid 341862] [client 122.162.144.145:10881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QJQWat-noHLkDuAh-1QAAAT8"]
[Tue Jul 21 07:55:33.490469 2026] [security2:error] [pid 341679:tid 341894] [client 173.24.185.52:59406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9QJQWat-noHLkDuAh-1wAAAV8"]
[Tue Jul 21 07:55:33.490612 2026] [security2:error] [pid 341679:tid 341894] [client 173.24.185.52:59406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9QJQWat-noHLkDuAh-1wAAAV8"]
[Tue Jul 21 07:55:33.511479 2026] [security2:error] [pid 341679:tid 341934] [client 65.21.113.253:51402] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QJQWat-noHLkDuAh-vQAAAYc"]
[Tue Jul 21 07:55:33.531947 2026] [security2:error] [pid 341679:tid 341724] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJQWat-noHLkDuAh-2QABZyw"]
[Tue Jul 21 07:55:33.532119 2026] [security2:error] [pid 341679:tid 341902] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJQWat-noHLkDuAh-2QABZyw"]
[Tue Jul 21 07:55:33.535204 2026] [proxy:error] [pid 341679:tid 341906] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:55:33.535256 2026] [proxy_http:error] [pid 341679:tid 341906] [client 91.92.41.115:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:55:33.535895 2026] [proxy:error] [pid 341679:tid 341906] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:55:33.535919 2026] [proxy_http:error] [pid 341679:tid 341906] [client 91.92.41.115:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:55:33.645176 2026] [security2:error] [pid 341679:tid 341849] [client 74.249.245.134:8822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/0x.php"] [unique_id "al9QJQWat-noHLkDuAh-3AAAATI"]
[Tue Jul 21 07:55:33.764463 2026] [security2:error] [pid 341679:tid 341893] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9QJQWat-noHLkDuAh-5AAAAV4"]
[Tue Jul 21 07:55:33.793696 2026] [security2:error] [pid 341679:tid 341734] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJQWat-noHLkDuAh-5QABfzY"]
[Tue Jul 21 07:55:33.793855 2026] [security2:error] [pid 341679:tid 341926] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJQWat-noHLkDuAh-5QABfzY"]
[Tue Jul 21 07:55:33.830791 2026] [security2:error] [pid 341679:tid 341910] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9QJQWat-noHLkDuAh-5gAAAW8"]
[Tue Jul 21 07:55:33.851034 2026] [security2:error] [pid 341679:tid 341924] [client 160.30.136.8:55025] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arielson.com.br"] [uri "/"] [unique_id "al9QJQWat-noHLkDuAh-5wAAAX0"]
[Tue Jul 21 07:55:33.984893 2026] [security2:error] [pid 341679:tid 341850] [client 20.226.60.151:56770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-blink.php"] [unique_id "al9QJQWat-noHLkDuAh-8gAAATM"]
[Tue Jul 21 07:55:34.082089 2026] [security2:error] [pid 341679:tid 341813] [client 20.104.96.117:55001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/flox.php"] [unique_id "al9QJgWat-noHLkDuAh-9wAAAQ4"]
[Tue Jul 21 07:55:34.140527 2026] [security2:error] [pid 341679:tid 341830] [client 139.167.225.182:49165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJgWat-noHLkDuAh--wAAAR8"]
[Tue Jul 21 07:55:34.140684 2026] [security2:error] [pid 341679:tid 341830] [client 139.167.225.182:49165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJgWat-noHLkDuAh--wAAAR8"]
[Tue Jul 21 07:55:34.172770 2026] [security2:error] [pid 341679:tid 341811] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9QJgWat-noHLkDuAh-_QAAAQw"]
[Tue Jul 21 07:55:34.174696 2026] [security2:error] [pid 341679:tid 341840] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9QJgWat-noHLkDuAh-_gAAASk"]
[Tue Jul 21 07:55:34.264167 2026] [security2:error] [pid 341679:tid 341836] [client 103.166.103.129:48491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QJgWat-noHLkDuAh_AAAAASU"]
[Tue Jul 21 07:55:34.264382 2026] [security2:error] [pid 341679:tid 341836] [client 103.166.103.129:48491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QJgWat-noHLkDuAh_AAAAASU"]
[Tue Jul 21 07:55:34.279088 2026] [security2:error] [pid 341679:tid 341922] [client 88.99.80.227:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9QJgWat-noHLkDuAh_AQABe3E"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:55:34.617531 2026] [security2:error] [pid 341679:tid 341861] [client 160.30.136.8:64472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9QJgWat-noHLkDuAh_MgAAAT4"]
[Tue Jul 21 07:55:34.645594 2026] [security2:error] [pid 341679:tid 341852] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9QJgWat-noHLkDuAh_MwAAATU"]
[Tue Jul 21 07:55:34.819032 2026] [security2:error] [pid 341679:tid 341823] [client 88.99.80.227:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9QJgWat-noHLkDuAh_QAABGCQ"], referer: https://albegaoficial.com.br
[Tue Jul 21 07:55:34.916269 2026] [security2:error] [pid 341679:tid 341920] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9QJgWat-noHLkDuAh_RAAAAXk"]
[Tue Jul 21 07:55:34.998116 2026] [security2:error] [pid 341679:tid 341855] [client 20.104.96.117:62802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/zildan.php"] [unique_id "al9QJgWat-noHLkDuAh_TAAAATg"]
[Tue Jul 21 07:55:35.090134 2026] [security2:error] [pid 341679:tid 341880] [client 103.78.200.11:50601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJwWat-noHLkDuAh_eQAAAVE"]
[Tue Jul 21 07:55:35.090223 2026] [security2:error] [pid 341679:tid 341880] [client 103.78.200.11:50601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJwWat-noHLkDuAh_eQAAAVE"]
[Tue Jul 21 07:55:35.107674 2026] [security2:error] [pid 341679:tid 341901] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJgWat-noHLkDuAh_RgABZnk"]
[Tue Jul 21 07:55:35.322129 2026] [security2:error] [pid 341679:tid 341909] [client 160.30.136.8:56213] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arielson.com.br"] [uri "/"] [unique_id "al9QJwWat-noHLkDuAh_iAAAAW4"]
[Tue Jul 21 07:55:35.331644 2026] [security2:error] [pid 341679:tid 341849] [client 106.215.181.8:24599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJwWat-noHLkDuAh_iQAAATI"]
[Tue Jul 21 07:55:35.331770 2026] [security2:error] [pid 341679:tid 341849] [client 106.215.181.8:24599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJwWat-noHLkDuAh_iQAAATI"]
[Tue Jul 21 07:55:35.333936 2026] [security2:error] [pid 341679:tid 341914] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.jurandirdasilvafigue1753316644000.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9QJwWat-noHLkDuAh_igAAAXM"]
[Tue Jul 21 07:55:35.585620 2026] [security2:error] [pid 341679:tid 341831] [client 193.36.225.58:43311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QJwWat-noHLkDuAh_lgAAASA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:35.607791 2026] [security2:error] [pid 341679:tid 341926] [client 65.21.113.253:44150] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QJwWat-noHLkDuAh_mQAAAX8"]
[Tue Jul 21 07:55:35.763865 2026] [autoindex:error] [pid 341679:tid 341817] [client 43.164.196.47:56148] AH01276: Cannot serve directory /home2/inlaud99/choppcontrol.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:35.819250 2026] [security2:error] [pid 341679:tid 341879] [client 103.29.114.44:8091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJwWat-noHLkDuAh_ogAAAVA"]
[Tue Jul 21 07:55:35.819347 2026] [security2:error] [pid 341679:tid 341879] [client 103.29.114.44:8091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QJwWat-noHLkDuAh_ogAAAVA"]
[Tue Jul 21 07:55:35.876597 2026] [security2:error] [pid 341679:tid 341836] [client 182.8.255.181:17532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QJwWat-noHLkDuAh_pgAAASU"]
[Tue Jul 21 07:55:35.876785 2026] [security2:error] [pid 341679:tid 341836] [client 182.8.255.181:17532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QJwWat-noHLkDuAh_pgAAASU"]
[Tue Jul 21 07:55:36.043372 2026] [security2:error] [pid 341679:tid 341855] [client 160.30.136.8:64164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9QKAWat-noHLkDuAh_sAAAATg"]
[Tue Jul 21 07:55:36.047520 2026] [security2:error] [pid 341679:tid 341734] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QKAWat-noHLkDuAh_sgABSTY"]
[Tue Jul 21 07:55:36.047699 2026] [security2:error] [pid 341679:tid 341872] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QKAWat-noHLkDuAh_sgABSTY"]
[Tue Jul 21 07:55:36.093675 2026] [security2:error] [pid 341679:tid 341766] [remote 199.189.225.40:64007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "governess.com.br"] [uri "/wp-login.php"] [unique_id "al9QKAWat-noHLkDuAh_tQABO1Y"]
[Tue Jul 21 07:55:36.209690 2026] [security2:error] [pid 341679:tid 341827] [client 65.21.113.253:51402] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QJwWat-noHLkDuAh_owAAARw"]
[Tue Jul 21 07:55:36.235357 2026] [security2:error] [pid 341679:tid 341878] [client 122.186.204.214:63589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QKAWat-noHLkDuAh_vAAAAU8"]
[Tue Jul 21 07:55:36.235499 2026] [security2:error] [pid 341679:tid 341878] [client 122.186.204.214:63589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QKAWat-noHLkDuAh_vAAAAU8"]
[Tue Jul 21 07:55:36.433921 2026] [security2:error] [pid 341679:tid 341902] [client 20.197.192.193:61854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/inso.php"] [unique_id "al9QKAWat-noHLkDuAh_zQAAAWc"]
[Tue Jul 21 07:55:36.559950 2026] [security2:error] [pid 341679:tid 341851] [client 20.104.96.117:62777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/csa.php"] [unique_id "al9QKAWat-noHLkDuAh_1AAAATQ"]
[Tue Jul 21 07:55:36.612070 2026] [security2:error] [pid 341679:tid 341924] [client 92.119.178.3:58672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9QKAWat-noHLkDuAh_3AAAAX0"]
[Tue Jul 21 07:55:36.612149 2026] [security2:error] [pid 341679:tid 341924] [client 92.119.178.3:58672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9QKAWat-noHLkDuAh_3AAAAX0"]
[Tue Jul 21 07:55:36.737731 2026] [security2:error] [pid 341679:tid 341832] [client 193.36.225.150:29617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QKAWat-noHLkDuAh_3QAAASE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:55:36.755112 2026] [security2:error] [pid 341679:tid 341897] [client 160.30.136.8:64198] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arielson.com.br"] [uri "/"] [unique_id "al9QKAWat-noHLkDuAh_3wAAAWI"]
[Tue Jul 21 07:55:36.782835 2026] [security2:error] [pid 341679:tid 341874] [client 122.179.91.63:7372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QKAWat-noHLkDuAh_4AAAAUs"]
[Tue Jul 21 07:55:36.782998 2026] [security2:error] [pid 341679:tid 341874] [client 122.179.91.63:7372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QKAWat-noHLkDuAh_4AAAAUs"]
[Tue Jul 21 07:55:36.819139 2026] [security2:error] [pid 341679:tid 341920] [client 20.104.96.117:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/popo.php"] [unique_id "al9QKAWat-noHLkDuAh_4QAAAXk"]
[Tue Jul 21 07:55:36.954798 2026] [security2:error] [pid 341679:tid 341719] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QKAWat-noHLkDuAh_7AABWyc"]
[Tue Jul 21 07:55:36.954926 2026] [security2:error] [pid 341679:tid 341890] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QKAWat-noHLkDuAh_7AABWyc"]
[Tue Jul 21 07:55:37.350237 2026] [security2:error] [pid 341679:tid 341836] [client 65.21.113.253:51418] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QKAWat-noHLkDuAh_6wAAASU"]
[Tue Jul 21 07:55:37.490656 2026] [security2:error] [pid 341679:tid 341852] [client 160.30.136.8:53448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9QKQWat-noHLkDuAiAAAAAATU"]
[Tue Jul 21 07:55:37.686108 2026] [security2:error] [pid 341679:tid 341818] [client 104.207.34.237:19245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.34.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QKQWat-noHLkDuAiACQAAARM"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:55:37.796517 2026] [security2:error] [pid 341679:tid 341891] [client 20.206.105.145:55884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/inputs.php"] [unique_id "al9QKQWat-noHLkDuAiADAAAAVw"]
[Tue Jul 21 07:55:38.123568 2026] [security2:error] [pid 341679:tid 341904] [client 41.68.90.219:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QKgWat-noHLkDuAiAFwAAAWk"]
[Tue Jul 21 07:55:38.124645 2026] [security2:error] [pid 341679:tid 341904] [client 41.68.90.219:58400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QKgWat-noHLkDuAiAFwAAAWk"]
[Tue Jul 21 07:55:38.198297 2026] [security2:error] [pid 341679:tid 341838] [client 160.30.136.8:53736] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "arielson.com.br"] [uri "/"] [unique_id "al9QKgWat-noHLkDuAiAGwAAASc"]
[Tue Jul 21 07:55:38.482007 2026] [security2:error] [pid 341679:tid 341803] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QKgWat-noHLkDuAiAIgABIXs"]
[Tue Jul 21 07:55:38.482164 2026] [security2:error] [pid 341679:tid 341832] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QKgWat-noHLkDuAiAIgABIXs"]
[Tue Jul 21 07:55:38.542751 2026] [security2:error] [pid 341679:tid 341820] [client 20.104.96.117:62831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/w3llscc.php"] [unique_id "al9QKgWat-noHLkDuAiAJgAAARU"]
[Tue Jul 21 07:55:38.550361 2026] [security2:error] [pid 341679:tid 341879] [client 102.206.115.33:61807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QKgWat-noHLkDuAiAJwAAAVA"]
[Tue Jul 21 07:55:38.550491 2026] [security2:error] [pid 341679:tid 341879] [client 102.206.115.33:61807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QKgWat-noHLkDuAiAJwAAAVA"]
[Tue Jul 21 07:55:38.827101 2026] [security2:error] [pid 341679:tid 341901] [client 104.207.41.231:36267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.41.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QKgWat-noHLkDuAiAKQAAAWY"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:55:38.836960 2026] [security2:error] [pid 341679:tid 341869] [client 109.60.28.94:55012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QKgWat-noHLkDuAiAMgAAAUY"]
[Tue Jul 21 07:55:38.837043 2026] [security2:error] [pid 341679:tid 341869] [client 109.60.28.94:55012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QKgWat-noHLkDuAiAMgAAAUY"]
[Tue Jul 21 07:55:38.861861 2026] [security2:error] [pid 341679:tid 341934] [client 172.245.102.30:47717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QKgWat-noHLkDuAiANAAAAYc"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:55:39.106060 2026] [security2:error] [pid 341679:tid 341871] [client 65.21.113.253:44150] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QKwWat-noHLkDuAiAOgAAAUg"]
[Tue Jul 21 07:55:39.137496 2026] [security2:error] [pid 341679:tid 341816] [client 20.226.60.151:61610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/output.php"] [unique_id "al9QKwWat-noHLkDuAiAPwAAARE"]
[Tue Jul 21 07:55:39.312971 2026] [security2:error] [pid 341679:tid 341864] [client 122.164.127.47:49454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QKwWat-noHLkDuAiASAAAAUE"]
[Tue Jul 21 07:55:39.313073 2026] [security2:error] [pid 341679:tid 341864] [client 122.164.127.47:49454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QKwWat-noHLkDuAiASAAAAUE"]
[Tue Jul 21 07:55:39.426052 2026] [security2:error] [pid 341679:tid 341790] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QKwWat-noHLkDuAiAUgABhm4"]
[Tue Jul 21 07:55:39.426191 2026] [security2:error] [pid 341679:tid 341933] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QKwWat-noHLkDuAiAUgABhm4"]
[Tue Jul 21 07:55:39.429670 2026] [security2:error] [pid 341679:tid 341918] [client 74.249.245.134:65128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/buy.php"] [unique_id "al9QKwWat-noHLkDuAiAUwAAAXc"]
[Tue Jul 21 07:55:39.481619 2026] [security2:error] [pid 341679:tid 341924] [client 193.36.225.66:50333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QKwWat-noHLkDuAiARwAAAX0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:39.530859 2026] [security2:error] [pid 341679:tid 341906] [client 202.143.127.214:51099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QKwWat-noHLkDuAiAVgAAAWs"]
[Tue Jul 21 07:55:39.530980 2026] [security2:error] [pid 341679:tid 341906] [client 202.143.127.214:51099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QKwWat-noHLkDuAiAVgAAAWs"]
[Tue Jul 21 07:55:39.724113 2026] [security2:error] [pid 341679:tid 341827] [client 65.21.113.253:51418] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QKwWat-noHLkDuAiASQAAARw"]
[Tue Jul 21 07:55:39.879745 2026] [security2:error] [pid 341679:tid 341831] [client 117.210.135.0:61019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QKwWat-noHLkDuAiASwAAASA"]
[Tue Jul 21 07:55:39.891441 2026] [security2:error] [pid 341679:tid 341813] [client 103.86.117.203:62425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QKwWat-noHLkDuAiAbgAAAQ4"]
[Tue Jul 21 07:55:39.891583 2026] [security2:error] [pid 341679:tid 341813] [client 103.86.117.203:62425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QKwWat-noHLkDuAiAbgAAAQ4"]
[Tue Jul 21 07:55:39.967507 2026] [security2:error] [pid 341679:tid 341840] [client 104.207.38.126:15253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.38.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QKwWat-noHLkDuAiAagAAASk"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:55:40.313452 2026] [security2:error] [pid 341679:tid 341788] [remote 192.241.143.148:36482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com.br"] [uri "/wp-login.php"] [unique_id "al9QLAWat-noHLkDuAiAhQABamw"]
[Tue Jul 21 07:55:40.628487 2026] [security2:error] [pid 341679:tid 341865] [client 65.21.113.253:49008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QLAWat-noHLkDuAiAfgAAAUI"]
[Tue Jul 21 07:55:40.726488 2026] [security2:error] [pid 341679:tid 341828] [client 82.102.18.182:55524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agenciawats.com.br"] [uri "/wp-login.php"] [unique_id "al9QLAWat-noHLkDuAiAlwAAAR0"]
[Tue Jul 21 07:55:41.157961 2026] [security2:error] [pid 341679:tid 341688] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QLQWat-noHLkDuAiAqAABDgg"]
[Tue Jul 21 07:55:41.158189 2026] [security2:error] [pid 341679:tid 341813] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QLQWat-noHLkDuAiAqAABDgg"]
[Tue Jul 21 07:55:41.303009 2026] [security2:error] [pid 341679:tid 341835] [client 20.226.60.151:56786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/zc-208.php"] [unique_id "al9QLQWat-noHLkDuAiAqQAAASQ"]
[Tue Jul 21 07:55:41.361522 2026] [security2:error] [pid 341679:tid 341896] [client 20.104.96.117:62742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wpx.php"] [unique_id "al9QLQWat-noHLkDuAiAsAAAAWE"]
[Tue Jul 21 07:55:41.834489 2026] [security2:error] [pid 341679:tid 341872] [client 65.21.113.253:44150] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QLQWat-noHLkDuAiAwgAAAUk"]
[Tue Jul 21 07:55:42.059086 2026] [security2:error] [pid 341679:tid 341857] [client 182.252.67.97:10233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.67.252.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QLgWat-noHLkDuAiAzQAAATo"]
[Tue Jul 21 07:55:42.059202 2026] [security2:error] [pid 341679:tid 341857] [client 182.252.67.97:10233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hvrtecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QLgWat-noHLkDuAiAzQAAATo"]
[Tue Jul 21 07:55:42.246005 2026] [security2:error] [pid 341679:tid 341869] [client 38.100.221.102:18135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QLgWat-noHLkDuAiA1wAAAUY"]
[Tue Jul 21 07:55:42.246122 2026] [security2:error] [pid 341679:tid 341869] [client 38.100.221.102:18135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QLgWat-noHLkDuAiA1wAAAUY"]
[Tue Jul 21 07:55:42.330152 2026] [security2:error] [pid 341679:tid 341874] [client 178.153.91.96:61341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QLgWat-noHLkDuAiA3gAAAUs"]
[Tue Jul 21 07:55:42.330313 2026] [security2:error] [pid 341679:tid 341874] [client 178.153.91.96:61341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QLgWat-noHLkDuAiA3gAAAUs"]
[Tue Jul 21 07:55:42.475064 2026] [security2:error] [pid 341679:tid 341923] [client 65.21.113.253:49008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QLgWat-noHLkDuAiAzgAAAXw"]
[Tue Jul 21 07:55:42.536599 2026] [security2:error] [pid 341679:tid 341908] [client 37.140.223.163:59319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QLgWat-noHLkDuAiA3wAAAW0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:55:43.010803 2026] [security2:error] [pid 341679:tid 341873] [client 117.217.38.194:55121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QLwWat-noHLkDuAiA-gAAAUo"]
[Tue Jul 21 07:55:43.011133 2026] [security2:error] [pid 341679:tid 341873] [client 117.217.38.194:55121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QLwWat-noHLkDuAiA-gAAAUo"]
[Tue Jul 21 07:55:43.023308 2026] [security2:error] [pid 341679:tid 341921] [client 193.36.225.61:33615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QLwWat-noHLkDuAiA_AAAAXo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:43.047876 2026] [security2:error] [pid 341679:tid 341905] [client 117.247.80.59:16315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QLwWat-noHLkDuAiBAAAAAWo"]
[Tue Jul 21 07:55:43.048011 2026] [security2:error] [pid 341679:tid 341905] [client 117.247.80.59:16315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QLwWat-noHLkDuAiBAAAAAWo"]
[Tue Jul 21 07:55:43.187295 2026] [security2:error] [pid 341679:tid 341818] [client 20.206.105.145:55928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/av.php"] [unique_id "al9QLwWat-noHLkDuAiBAwAAARM"]
[Tue Jul 21 07:55:43.297769 2026] [security2:error] [pid 341679:tid 341724] [remote 72.167.132.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QLwWat-noHLkDuAiBCgABQyw"], referer: http://assumaocontrole.com/
[Tue Jul 21 07:55:43.413782 2026] [security2:error] [pid 341679:tid 341827] [client 74.249.245.134:54357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9QLwWat-noHLkDuAiBFAAAARw"]
[Tue Jul 21 07:55:43.688338 2026] [security2:error] [pid 341679:tid 341924] [client 20.104.96.117:62767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-css.php"] [unique_id "al9QLwWat-noHLkDuAiBLQAAAX0"]
[Tue Jul 21 07:55:43.712927 2026] [security2:error] [pid 341679:tid 341721] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QLwWat-noHLkDuAiBNAABNCk"]
[Tue Jul 21 07:55:43.713090 2026] [security2:error] [pid 341679:tid 341851] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QLwWat-noHLkDuAiBNAABNCk"]
[Tue Jul 21 07:55:43.885560 2026] [security2:error] [pid 341679:tid 341752] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QLwWat-noHLkDuAiBPAABK0g"]
[Tue Jul 21 07:55:43.885689 2026] [security2:error] [pid 341679:tid 341842] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QLwWat-noHLkDuAiBPAABK0g"]
[Tue Jul 21 07:55:44.005466 2026] [security2:error] [pid 341679:tid 341814] [client 223.236.153.128:5447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QMAWat-noHLkDuAiBTwAAAQ8"]
[Tue Jul 21 07:55:44.005549 2026] [security2:error] [pid 341679:tid 341814] [client 223.236.153.128:5447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QMAWat-noHLkDuAiBTwAAAQ8"]
[Tue Jul 21 07:55:44.036819 2026] [security2:error] [pid 341679:tid 341857] [client 173.24.185.52:59830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.185.24.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9QMAWat-noHLkDuAiBUwAAATo"]
[Tue Jul 21 07:55:44.036901 2026] [security2:error] [pid 341679:tid 341846] [client 20.226.60.151:56719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/sid4.php"] [unique_id "al9QMAWat-noHLkDuAiBUgAAAS8"]
[Tue Jul 21 07:55:44.036903 2026] [security2:error] [pid 341679:tid 341857] [client 173.24.185.52:59830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ryancastroweb.com"] [uri "/xmlrpc.php"] [unique_id "al9QMAWat-noHLkDuAiBUwAAATo"]
[Tue Jul 21 07:55:44.060120 2026] [security2:error] [pid 341679:tid 341750] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMAWat-noHLkDuAiBVAABC0Y"]
[Tue Jul 21 07:55:44.060253 2026] [security2:error] [pid 341679:tid 341810] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMAWat-noHLkDuAiBVAABC0Y"]
[Tue Jul 21 07:55:44.115529 2026] [security2:error] [pid 341679:tid 341861] [client 122.162.144.145:32845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QMAWat-noHLkDuAiBWwAAAT4"]
[Tue Jul 21 07:55:44.115646 2026] [security2:error] [pid 341679:tid 341861] [client 122.162.144.145:32845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QMAWat-noHLkDuAiBWwAAAT4"]
[Tue Jul 21 07:55:44.331221 2026] [security2:error] [pid 341679:tid 341904] [client 65.21.113.253:49014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QLwWat-noHLkDuAiBRAAAAWk"]
[Tue Jul 21 07:55:44.547355 2026] [security2:error] [pid 341679:tid 341918] [client 20.104.96.117:54961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/yas.php"] [unique_id "al9QMAWat-noHLkDuAiBfwAAAXc"]
[Tue Jul 21 07:55:44.923282 2026] [security2:error] [pid 341679:tid 341825] [client 139.167.225.182:49838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMAWat-noHLkDuAiBlgAAARo"]
[Tue Jul 21 07:55:44.923410 2026] [security2:error] [pid 341679:tid 341825] [client 139.167.225.182:49838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMAWat-noHLkDuAiBlgAAARo"]
[Tue Jul 21 07:55:45.025569 2026] [security2:error] [pid 341679:tid 341892] [client 103.166.103.129:49033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QMQWat-noHLkDuAiBmwAAAV0"]
[Tue Jul 21 07:55:45.025677 2026] [security2:error] [pid 341679:tid 341892] [client 103.166.103.129:49033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QMQWat-noHLkDuAiBmwAAAV0"]
[Tue Jul 21 07:55:45.041519 2026] [security2:error] [pid 341679:tid 341871] [client 20.206.105.145:55811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/classwithtostring.php"] [unique_id "al9QMQWat-noHLkDuAiBnAAAAUg"]
[Tue Jul 21 07:55:45.084454 2026] [security2:error] [pid 341679:tid 341881] [client 92.119.178.3:35580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9QMQWat-noHLkDuAiBnwAAAVI"]
[Tue Jul 21 07:55:45.084521 2026] [security2:error] [pid 341679:tid 341881] [client 92.119.178.3:35580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9QMQWat-noHLkDuAiBnwAAAVI"]
[Tue Jul 21 07:55:45.103614 2026] [security2:error] [pid 341679:tid 341905] [client 20.104.96.117:62746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ho.php"] [unique_id "al9QMQWat-noHLkDuAiBowAAAWo"]
[Tue Jul 21 07:55:45.243333 2026] [security2:error] [pid 341679:tid 341878] [client 185.198.240.89:41643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "voweltravel.com.br"] [uri "/wp-login.php"] [unique_id "al9QMQWat-noHLkDuAiBrgAAAU8"]
[Tue Jul 21 07:55:45.321149 2026] [security2:error] [pid 341679:tid 341868] [client 103.78.200.11:51069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMQWat-noHLkDuAiBtgAAAUU"]
[Tue Jul 21 07:55:45.321281 2026] [security2:error] [pid 341679:tid 341868] [client 103.78.200.11:51069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMQWat-noHLkDuAiBtgAAAUU"]
[Tue Jul 21 07:55:45.454303 2026] [autoindex:error] [pid 341679:tid 341794] [remote 162.55.132.97:47648] AH01276: Cannot serve directory /home1/leon6484/lumevisual.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:45.487950 2026] [security2:error] [pid 341679:tid 341703] [remote 42.200.84.61:54370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9QMQWat-noHLkDuAiBwQABYxc"]
[Tue Jul 21 07:55:45.531464 2026] [security2:error] [pid 341679:tid 341854] [client 74.249.245.134:5522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9QMQWat-noHLkDuAiBwwAAATc"]
[Tue Jul 21 07:55:45.600766 2026] [security2:error] [pid 341679:tid 341692] [remote 185.27.20.235:34788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.20.27.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedrocromo.com.br"] [uri "/wp-login.php"] [unique_id "al9QMQWat-noHLkDuAiBxwABQAw"]
[Tue Jul 21 07:55:45.796342 2026] [security2:error] [pid 341679:tid 341839] [client 106.215.181.8:2811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMQWat-noHLkDuAiBzAAAASg"]
[Tue Jul 21 07:55:45.796449 2026] [security2:error] [pid 341679:tid 341839] [client 106.215.181.8:2811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMQWat-noHLkDuAiBzAAAASg"]
[Tue Jul 21 07:55:46.128931 2026] [security2:error] [pid 341679:tid 341821] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMgWat-noHLkDuAiB2AABFkI"]
[Tue Jul 21 07:55:46.165258 2026] [security2:error] [pid 341679:tid 341844] [client 193.36.225.120:23855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QMgWat-noHLkDuAiB3wAAAS0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:55:46.272898 2026] [security2:error] [pid 341679:tid 341892] [client 65.21.113.253:49014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QMQWat-noHLkDuAiB0AAAAV0"]
[Tue Jul 21 07:55:46.337553 2026] [security2:error] [pid 341679:tid 341876] [client 103.29.114.44:58700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMgWat-noHLkDuAiB4QAAAU0"]
[Tue Jul 21 07:55:46.337715 2026] [security2:error] [pid 341679:tid 341876] [client 103.29.114.44:58700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMgWat-noHLkDuAiB4QAAAU0"]
[Tue Jul 21 07:55:46.348970 2026] [security2:error] [pid 341679:tid 341902] [client 20.104.96.117:62758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/xy.php"] [unique_id "al9QMgWat-noHLkDuAiB5QAAAWc"]
[Tue Jul 21 07:55:46.366899 2026] [security2:error] [pid 341679:tid 341810] [client 204.8.98.45:33168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9QMgWat-noHLkDuAiB6wAAAQs"]
[Tue Jul 21 07:55:46.366992 2026] [security2:error] [pid 341679:tid 341810] [client 204.8.98.45:33168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9QMgWat-noHLkDuAiB6wAAAQs"]
[Tue Jul 21 07:55:46.392018 2026] [security2:error] [pid 341679:tid 341817] [client 182.8.255.181:17592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QMgWat-noHLkDuAiB8AAAARI"]
[Tue Jul 21 07:55:46.392138 2026] [security2:error] [pid 341679:tid 341817] [client 182.8.255.181:17592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QMgWat-noHLkDuAiB8AAAARI"]
[Tue Jul 21 07:55:46.811689 2026] [security2:error] [pid 341679:tid 341882] [client 20.206.105.145:55840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9QMgWat-noHLkDuAiCAgAAAVM"]
[Tue Jul 21 07:55:46.901083 2026] [security2:error] [pid 341679:tid 341846] [client 122.186.204.214:64128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QMgWat-noHLkDuAiCBQAAAS8"]
[Tue Jul 21 07:55:46.901212 2026] [security2:error] [pid 341679:tid 341846] [client 122.186.204.214:64128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QMgWat-noHLkDuAiCBQAAAS8"]
[Tue Jul 21 07:55:47.039523 2026] [security2:error] [pid 341679:tid 341699] [remote 185.236.20.134:48108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9QMwWat-noHLkDuAiCDAABEBM"]
[Tue Jul 21 07:55:47.058467 2026] [security2:error] [pid 341679:tid 341762] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMwWat-noHLkDuAiCDgABf1I"]
[Tue Jul 21 07:55:47.058669 2026] [security2:error] [pid 341679:tid 341926] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMwWat-noHLkDuAiCDgABf1I"]
[Tue Jul 21 07:55:47.440747 2026] [security2:error] [pid 341679:tid 341870] [client 20.226.60.151:61629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wp-file-120.php"] [unique_id "al9QMwWat-noHLkDuAiCHwAAAUc"]
[Tue Jul 21 07:55:47.448270 2026] [security2:error] [pid 341679:tid 341867] [client 122.179.91.63:29484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QMwWat-noHLkDuAiCIAAAAUQ"]
[Tue Jul 21 07:55:47.448376 2026] [security2:error] [pid 341679:tid 341867] [client 122.179.91.63:29484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QMwWat-noHLkDuAiCIAAAAUQ"]
[Tue Jul 21 07:55:47.605020 2026] [security2:error] [pid 341679:tid 341878] [client 185.236.20.134:10668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9QMwWat-noHLkDuAiCLAAAAU8"]
[Tue Jul 21 07:55:47.680529 2026] [autoindex:error] [pid 341679:tid 341834] [client 20.226.60.151:56744] AH01276: Cannot serve directory /home3/factor11/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:47.706276 2026] [security2:error] [pid 341679:tid 341918] [client 20.226.60.151:56744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wmore1.php"] [unique_id "al9QMwWat-noHLkDuAiCMgAAAXc"]
[Tue Jul 21 07:55:47.911924 2026] [security2:error] [pid 341679:tid 341818] [client 74.249.245.134:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/wp.php"] [unique_id "al9QMwWat-noHLkDuAiCNwAAARM"]
[Tue Jul 21 07:55:47.919824 2026] [security2:error] [pid 341679:tid 341730] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMwWat-noHLkDuAiCOAABaTI"]
[Tue Jul 21 07:55:47.919970 2026] [security2:error] [pid 341679:tid 341904] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QMwWat-noHLkDuAiCOAABaTI"]
[Tue Jul 21 07:55:47.946710 2026] [security2:error] [pid 341679:tid 341831] [client 172.245.102.42:35853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QMwWat-noHLkDuAiCMwAAASA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:48.186045 2026] [security2:error] [pid 341679:tid 341877] [client 65.21.113.253:53888] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QNAWat-noHLkDuAiCRwAAAU4"]
[Tue Jul 21 07:55:48.217534 2026] [security2:error] [pid 341679:tid 341845] [client 20.104.96.117:62775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/loader.php"] [unique_id "al9QNAWat-noHLkDuAiCSQAAAS4"]
[Tue Jul 21 07:55:48.318756 2026] [security2:error] [pid 341679:tid 341929] [client 20.206.105.145:28610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wp-blog.php"] [unique_id "al9QNAWat-noHLkDuAiCSwAAAYI"]
[Tue Jul 21 07:55:48.341609 2026] [security2:error] [pid 341679:tid 341827] [client 65.21.113.253:49014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QMwWat-noHLkDuAiCOQAAARw"]
[Tue Jul 21 07:55:48.619636 2026] [security2:error] [pid 341679:tid 341721] [remote 185.236.20.134:48122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.northcomm.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9QNAWat-noHLkDuAiCWAABOCk"]
[Tue Jul 21 07:55:48.649428 2026] [security2:error] [pid 341679:tid 341909] [client 41.68.90.219:58857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QNAWat-noHLkDuAiCWgAAAW4"]
[Tue Jul 21 07:55:48.650584 2026] [security2:error] [pid 341679:tid 341909] [client 41.68.90.219:58857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QNAWat-noHLkDuAiCWgAAAW4"]
[Tue Jul 21 07:55:49.072725 2026] [security2:error] [pid 341679:tid 341923] [client 102.206.115.33:61195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QNQWat-noHLkDuAiCbAAAAXw"]
[Tue Jul 21 07:55:49.072872 2026] [security2:error] [pid 341679:tid 341923] [client 102.206.115.33:61195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QNQWat-noHLkDuAiCbAAAAXw"]
[Tue Jul 21 07:55:49.214139 2026] [security2:error] [pid 341679:tid 341708] [remote 185.236.20.134:48126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9QNQWat-noHLkDuAiCcgABLRw"]
[Tue Jul 21 07:55:49.286746 2026] [security2:error] [pid 341679:tid 341888] [client 65.21.113.253:49030] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QNAWat-noHLkDuAiCZQAAAVk"]
[Tue Jul 21 07:55:49.388272 2026] [security2:error] [pid 341679:tid 341935] [client 20.104.96.117:46415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/spadex.php"] [unique_id "al9QNQWat-noHLkDuAiCdgAAAYg"]
[Tue Jul 21 07:55:49.426950 2026] [security2:error] [pid 341679:tid 341752] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QNQWat-noHLkDuAiCeAABT0g"]
[Tue Jul 21 07:55:49.427096 2026] [security2:error] [pid 341679:tid 341878] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QNQWat-noHLkDuAiCeAABT0g"]
[Tue Jul 21 07:55:49.606316 2026] [security2:error] [pid 341679:tid 341807] [remote 217.154.106.221:49436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.106.154.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9QNAWat-noHLkDuAiCVgABEX8"]
[Tue Jul 21 07:55:49.655870 2026] [security2:error] [pid 341679:tid 341813] [client 109.60.28.94:38839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QNQWat-noHLkDuAiCiAAAAQ4"]
[Tue Jul 21 07:55:49.656699 2026] [security2:error] [pid 341679:tid 341813] [client 109.60.28.94:38839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QNQWat-noHLkDuAiCiAAAAQ4"]
[Tue Jul 21 07:55:49.819075 2026] [security2:error] [pid 341679:tid 341815] [client 185.236.20.134:10680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9QNQWat-noHLkDuAiCjQAAARA"]
[Tue Jul 21 07:55:49.897041 2026] [security2:error] [pid 341679:tid 341811] [client 122.164.127.47:50045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QNQWat-noHLkDuAiCkQAAAQw"]
[Tue Jul 21 07:55:49.897154 2026] [security2:error] [pid 341679:tid 341811] [client 122.164.127.47:50045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QNQWat-noHLkDuAiCkQAAAQw"]
[Tue Jul 21 07:55:50.018031 2026] [security2:error] [pid 341679:tid 341832] [client 117.210.135.0:61742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QNQWat-noHLkDuAiClwAAASE"]
[Tue Jul 21 07:55:50.185644 2026] [security2:error] [pid 341679:tid 341764] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QNgWat-noHLkDuAiCoQABFlQ"]
[Tue Jul 21 07:55:50.185840 2026] [security2:error] [pid 341679:tid 341821] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QNgWat-noHLkDuAiCoQABFlQ"]
[Tue Jul 21 07:55:50.375886 2026] [security2:error] [pid 341679:tid 341871] [client 74.249.245.134:5562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/new.php"] [unique_id "al9QNgWat-noHLkDuAiCrAAAAUg"]
[Tue Jul 21 07:55:50.375888 2026] [security2:error] [pid 341679:tid 341865] [client 103.86.117.203:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QNgWat-noHLkDuAiCrQAAAUI"]
[Tue Jul 21 07:55:50.376004 2026] [security2:error] [pid 341679:tid 341865] [client 103.86.117.203:62968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QNgWat-noHLkDuAiCrQAAAUI"]
[Tue Jul 21 07:55:50.575286 2026] [security2:error] [pid 341679:tid 341841] [client 202.143.127.214:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QNgWat-noHLkDuAiCtQAAASo"]
[Tue Jul 21 07:55:50.575453 2026] [security2:error] [pid 341679:tid 341841] [client 202.143.127.214:51568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QNgWat-noHLkDuAiCtQAAASo"]
[Tue Jul 21 07:55:50.582528 2026] [security2:error] [pid 341679:tid 341853] [client 65.21.113.253:49014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QNgWat-noHLkDuAiCoAAAATY"]
[Tue Jul 21 07:55:50.621056 2026] [security2:error] [pid 341679:tid 341742] [remote 185.236.20.134:48138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.northcomm.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9QNgWat-noHLkDuAiCtgABTz4"]
[Tue Jul 21 07:55:50.650174 2026] [security2:error] [pid 341679:tid 341863] [client 37.140.223.150:23181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QNAWat-noHLkDuAiCWQAAAUA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:55:50.744827 2026] [security2:error] [pid 341679:tid 341824] [client 92.119.178.3:40640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9QNgWat-noHLkDuAiCvAAAARk"]
[Tue Jul 21 07:55:50.744939 2026] [security2:error] [pid 341679:tid 341824] [client 92.119.178.3:40640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9QNgWat-noHLkDuAiCvAAAARk"]
[Tue Jul 21 07:55:50.864158 2026] [security2:error] [pid 341679:tid 341889] [client 45.3.55.22:26839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QNgWat-noHLkDuAiCuwAAAVo"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:55:50.976064 2026] [security2:error] [pid 341679:tid 341781] [remote 173.252.82.23:57550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9QNgWat-noHLkDuAiCvwABaWU"]
[Tue Jul 21 07:55:51.220059 2026] [security2:error] [pid 341679:tid 341697] [remote 185.236.20.134:48150] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "northcomm.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9QNwWat-noHLkDuAiC0gABeBE"]
[Tue Jul 21 07:55:51.265843 2026] [security2:error] [pid 341679:tid 341829] [client 20.206.105.145:55871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9QNwWat-noHLkDuAiC0wAAAR4"]
[Tue Jul 21 07:55:51.294160 2026] [security2:error] [pid 341679:tid 341921] [client 136.144.33.111:56415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QNwWat-noHLkDuAiC1QAAAXo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:51.831542 2026] [security2:error] [pid 341679:tid 341842] [client 185.236.20.134:10690] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "northcomm.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9QNwWat-noHLkDuAiC7wAAASs"]
[Tue Jul 21 07:55:51.860756 2026] [security2:error] [pid 341679:tid 341866] [client 20.104.96.117:62739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/2x.php"] [unique_id "al9QNwWat-noHLkDuAiC8QAAAUM"]
[Tue Jul 21 07:55:51.893161 2026] [security2:error] [pid 341679:tid 341934] [client 65.111.20.177:64707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QNwWat-noHLkDuAiC9AAAAYc"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:55:51.925631 2026] [security2:error] [pid 341679:tid 341739] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QNwWat-noHLkDuAiC9QABWjs"]
[Tue Jul 21 07:55:51.925756 2026] [security2:error] [pid 341679:tid 341889] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QNwWat-noHLkDuAiC9QABWjs"]
[Tue Jul 21 07:55:51.948874 2026] [security2:error] [pid 341679:tid 341915] [client 204.8.98.45:42394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9QNwWat-noHLkDuAiC9gAAAXQ"]
[Tue Jul 21 07:55:51.948938 2026] [security2:error] [pid 341679:tid 341915] [client 204.8.98.45:42394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9QNwWat-noHLkDuAiC9gAAAXQ"]
[Tue Jul 21 07:55:52.476869 2026] [security2:error] [pid 341679:tid 341847] [client 20.206.105.145:28647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/adminfuns.php"] [unique_id "al9QOAWat-noHLkDuAiDCAAAATA"]
[Tue Jul 21 07:55:52.500626 2026] [security2:error] [pid 341679:tid 341872] [client 173.252.95.8:48760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9QOAWat-noHLkDuAiDCQAAAUk"]
[Tue Jul 21 07:55:52.539130 2026] [security2:error] [pid 341679:tid 341933] [client 65.21.113.253:49014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QOAWat-noHLkDuAiC_gAAAYY"]
[Tue Jul 21 07:55:52.766397 2026] [security2:error] [pid 341679:tid 341703] [remote 185.236.20.134:48158] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.northcomm.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9QOAWat-noHLkDuAiDFgABNBc"]
[Tue Jul 21 07:55:52.836600 2026] [security2:error] [pid 341679:tid 341827] [client 178.153.91.96:62259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QOAWat-noHLkDuAiDFwAAARw"]
[Tue Jul 21 07:55:52.836778 2026] [security2:error] [pid 341679:tid 341827] [client 178.153.91.96:62259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QOAWat-noHLkDuAiDFwAAARw"]
[Tue Jul 21 07:55:52.955676 2026] [security2:error] [pid 341679:tid 341838] [client 38.100.221.102:17672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QOAWat-noHLkDuAiDIAAAASc"]
[Tue Jul 21 07:55:52.955835 2026] [security2:error] [pid 341679:tid 341838] [client 38.100.221.102:17672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QOAWat-noHLkDuAiDIAAAASc"]
[Tue Jul 21 07:55:53.139473 2026] [security2:error] [pid 341679:tid 341897] [client 193.36.225.143:26263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QOAWat-noHLkDuAiDIQAAAWI"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:55:53.336640 2026] [security2:error] [pid 341679:tid 341844] [client 20.104.96.117:46417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ctex1.php"] [unique_id "al9QOQWat-noHLkDuAiDMAAAAS0"]
[Tue Jul 21 07:55:53.477633 2026] [security2:error] [pid 341679:tid 341896] [client 117.217.38.194:55614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QOQWat-noHLkDuAiDNgAAAWE"]
[Tue Jul 21 07:55:53.477896 2026] [security2:error] [pid 341679:tid 341896] [client 117.217.38.194:55614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QOQWat-noHLkDuAiDNgAAAWE"]
[Tue Jul 21 07:55:53.605875 2026] [security2:error] [pid 341679:tid 341892] [client 117.247.80.59:16774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QOQWat-noHLkDuAiDOwAAAV0"]
[Tue Jul 21 07:55:53.606016 2026] [security2:error] [pid 341679:tid 341892] [client 117.247.80.59:16774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QOQWat-noHLkDuAiDOwAAAV0"]
[Tue Jul 21 07:55:53.920651 2026] [autoindex:error] [pid 341679:tid 341818] [client 82.102.18.182:45336] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:53.948456 2026] [security2:error] [pid 341679:tid 341879] [client 74.249.245.134:54352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/class-t.api.php"] [unique_id "al9QOQWat-noHLkDuAiDSAAAAVA"]
[Tue Jul 21 07:55:54.194415 2026] [security2:error] [pid 341679:tid 341681] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QOgWat-noHLkDuAiDTwABJQE"]
[Tue Jul 21 07:55:54.194596 2026] [security2:error] [pid 341679:tid 341836] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QOgWat-noHLkDuAiDTwABJQE"]
[Tue Jul 21 07:55:54.347701 2026] [security2:error] [pid 341679:tid 341824] [client 65.111.26.86:57369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QOQWat-noHLkDuAiDMQAAARk"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:55:54.451585 2026] [security2:error] [pid 341679:tid 341799] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QOgWat-noHLkDuAiDWQABfnc"]
[Tue Jul 21 07:55:54.451761 2026] [security2:error] [pid 341679:tid 341925] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QOgWat-noHLkDuAiDWQABfnc"]
[Tue Jul 21 07:55:54.591137 2026] [security2:error] [pid 341679:tid 341869] [client 20.206.105.145:55821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/goods.php"] [unique_id "al9QOgWat-noHLkDuAiDXwAAAUY"]
[Tue Jul 21 07:55:54.591929 2026] [security2:error] [pid 341679:tid 341737] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QOgWat-noHLkDuAiDYAABEDk"]
[Tue Jul 21 07:55:54.592073 2026] [security2:error] [pid 341679:tid 341815] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QOgWat-noHLkDuAiDYAABEDk"]
[Tue Jul 21 07:55:54.703250 2026] [security2:error] [pid 341679:tid 341863] [client 223.236.153.128:7414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QOgWat-noHLkDuAiDZAAAAUA"]
[Tue Jul 21 07:55:54.703449 2026] [security2:error] [pid 341679:tid 341863] [client 223.236.153.128:7414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QOgWat-noHLkDuAiDZAAAAUA"]
[Tue Jul 21 07:55:54.716989 2026] [autoindex:error] [pid 341679:tid 341860] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-content/cache/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:54.842239 2026] [security2:error] [pid 341679:tid 341842] [client 122.162.144.145:31203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QOgWat-noHLkDuAiDaQAAASs"]
[Tue Jul 21 07:55:54.842346 2026] [security2:error] [pid 341679:tid 341842] [client 122.162.144.145:31203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QOgWat-noHLkDuAiDaQAAASs"]
[Tue Jul 21 07:55:54.908953 2026] [security2:error] [pid 341679:tid 341861] [client 20.104.96.117:46430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/edorxrr.php"] [unique_id "al9QOgWat-noHLkDuAiDagAAAT4"]
[Tue Jul 21 07:55:54.916440 2026] [security2:error] [pid 341679:tid 341821] [client 204.8.98.45:60112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9QOgWat-noHLkDuAiDbAAAARY"]
[Tue Jul 21 07:55:54.916521 2026] [security2:error] [pid 341679:tid 341821] [client 204.8.98.45:60112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9QOgWat-noHLkDuAiDbAAAARY"]
[Tue Jul 21 07:55:54.959676 2026] [autoindex:error] [pid 341679:tid 341811] [client 82.102.18.182:45336] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:55.026095 2026] [security2:error] [pid 341679:tid 341872] [client 74.249.245.134:64087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/sx.php"] [unique_id "al9QOwWat-noHLkDuAiDcgAAAUk"]
[Tue Jul 21 07:55:55.157771 2026] [authz_core:error] [pid 341679:tid 341911] [client 82.102.18.182:0] AH01630: client denied by server configuration: /home4/bomexi25/agenciawats.com.br/wp-content/plugins/akismet/
[Tue Jul 21 07:55:55.224706 2026] [security2:error] [pid 341679:tid 341849] [client 139.167.225.182:50491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QOwWat-noHLkDuAiDfAAAATI"]
[Tue Jul 21 07:55:55.224843 2026] [security2:error] [pid 341679:tid 341849] [client 139.167.225.182:50491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QOwWat-noHLkDuAiDfAAAATI"]
[Tue Jul 21 07:55:55.331921 2026] [security2:error] [pid 341679:tid 341924] [client 65.21.113.253:49014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QOgWat-noHLkDuAiDbQAAAX0"]
[Tue Jul 21 07:55:55.375856 2026] [autoindex:error] [pid 341679:tid 341838] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:55.465237 2026] [security2:error] [pid 341679:tid 341915] [client 74.249.245.134:5529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/plugins.php"] [unique_id "al9QOwWat-noHLkDuAiDhQAAAXQ"]
[Tue Jul 21 07:55:55.567446 2026] [security2:error] [pid 341679:tid 341841] [client 65.111.6.178:17687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.6.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QOwWat-noHLkDuAiDhAAAASo"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:55:55.585838 2026] [autoindex:error] [pid 341679:tid 341859] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:55.675202 2026] [security2:error] [pid 341679:tid 341839] [client 103.166.103.129:49575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QOwWat-noHLkDuAiDlAAAASg"]
[Tue Jul 21 07:55:55.675292 2026] [security2:error] [pid 341679:tid 341839] [client 103.166.103.129:49575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QOwWat-noHLkDuAiDlAAAASg"]
[Tue Jul 21 07:55:55.793238 2026] [autoindex:error] [pid 341679:tid 341847] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:55.825723 2026] [security2:error] [pid 341679:tid 341850] [client 172.245.102.45:54733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QOwWat-noHLkDuAiDnwAAATM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:56.006723 2026] [autoindex:error] [pid 341679:tid 341892] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:56.214432 2026] [autoindex:error] [pid 341679:tid 341816] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:56.365018 2026] [security2:error] [pid 341679:tid 341936] [client 106.215.181.8:2240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QPAWat-noHLkDuAiDtwAAAYk"]
[Tue Jul 21 07:55:56.365168 2026] [security2:error] [pid 341679:tid 341936] [client 106.215.181.8:2240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QPAWat-noHLkDuAiDtwAAAYk"]
[Tue Jul 21 07:55:56.377429 2026] [security2:error] [pid 341679:tid 341874] [client 65.21.113.253:44624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QPAWat-noHLkDuAiDuAAAAUs"]
[Tue Jul 21 07:55:56.432712 2026] [autoindex:error] [pid 341679:tid 341877] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:56.543704 2026] [security2:error] [pid 341679:tid 341836] [client 104.207.47.241:38721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.47.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QPAWat-noHLkDuAiDvwAAASU"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:55:56.687464 2026] [autoindex:error] [pid 341679:tid 341810] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:56.751415 2026] [security2:error] [pid 341679:tid 341896] [client 20.226.60.151:61577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/special.php"] [unique_id "al9QPAWat-noHLkDuAiDyQAAAWE"]
[Tue Jul 21 07:55:56.802452 2026] [security2:error] [pid 341679:tid 341827] [client 103.78.200.11:51531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QPAWat-noHLkDuAiDzwAAARw"]
[Tue Jul 21 07:55:56.802566 2026] [security2:error] [pid 341679:tid 341827] [client 103.78.200.11:51531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QPAWat-noHLkDuAiDzwAAARw"]
[Tue Jul 21 07:55:56.855348 2026] [security2:error] [pid 341679:tid 341829] [client 182.8.255.181:2898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QPAWat-noHLkDuAiD0QAAAR4"]
[Tue Jul 21 07:55:56.855524 2026] [security2:error] [pid 341679:tid 341829] [client 182.8.255.181:2898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QPAWat-noHLkDuAiD0QAAAR4"]
[Tue Jul 21 07:55:56.896621 2026] [autoindex:error] [pid 341679:tid 341892] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:56.917942 2026] [security2:error] [pid 341679:tid 341861] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QPAWat-noHLkDuAiDzgABPik"]
[Tue Jul 21 07:55:56.989184 2026] [security2:error] [pid 341679:tid 341825] [client 65.21.113.253:49014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QPAWat-noHLkDuAiDwAAAARo"]
[Tue Jul 21 07:55:57.198564 2026] [access_compat:error] [pid 341679:tid 341887] [client 162.241.63.68:53982] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:55:57.217825 2026] [security2:error] [pid 341679:tid 341934] [client 74.249.245.134:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/jp.php"] [unique_id "al9QPQWat-noHLkDuAiD6QAAAYc"]
[Tue Jul 21 07:55:57.255548 2026] [security2:error] [pid 341679:tid 341925] [client 92.119.178.3:60718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9QPQWat-noHLkDuAiD6gAAAX4"]
[Tue Jul 21 07:55:57.255668 2026] [security2:error] [pid 341679:tid 341925] [client 92.119.178.3:60718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9QPQWat-noHLkDuAiD6gAAAX4"]
[Tue Jul 21 07:55:57.277173 2026] [security2:error] [pid 341679:tid 341936] [client 20.206.105.145:55847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/ms-edit.php"] [unique_id "al9QPQWat-noHLkDuAiD6wAAAYk"]
[Tue Jul 21 07:55:57.441231 2026] [security2:error] [pid 341679:tid 341910] [client 20.104.96.117:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/file61.php"] [unique_id "al9QPQWat-noHLkDuAiD8wAAAW8"]
[Tue Jul 21 07:55:57.555722 2026] [security2:error] [pid 341679:tid 341749] [remote 117.0.21.154:33776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9QPQWat-noHLkDuAiD-QABbUU"]
[Tue Jul 21 07:55:57.656805 2026] [security2:error] [pid 341679:tid 341911] [client 122.186.204.214:64668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QPQWat-noHLkDuAiD_wAAAXA"]
[Tue Jul 21 07:55:57.660204 2026] [security2:error] [pid 341679:tid 341911] [client 122.186.204.214:64668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QPQWat-noHLkDuAiD_wAAAXA"]
[Tue Jul 21 07:55:57.687637 2026] [security2:error] [pid 341679:tid 341898] [client 45.3.38.233:59639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.38.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QPQWat-noHLkDuAiD-AAAAWM"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:55:57.734485 2026] [autoindex:error] [pid 341679:tid 341858] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:57.739428 2026] [security2:error] [pid 341679:tid 341933] [client 20.104.96.117:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/miru1.php"] [unique_id "al9QPQWat-noHLkDuAiEBAAAAYY"]
[Tue Jul 21 07:55:57.748498 2026] [security2:error] [pid 341679:tid 341880] [client 103.29.114.44:56881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QPQWat-noHLkDuAiEBQAAAVE"]
[Tue Jul 21 07:55:57.748593 2026] [security2:error] [pid 341679:tid 341880] [client 103.29.114.44:56881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QPQWat-noHLkDuAiEBQAAAVE"]
[Tue Jul 21 07:55:57.949756 2026] [autoindex:error] [pid 341679:tid 341890] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:58.127036 2026] [security2:error] [pid 341679:tid 341710] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QPgWat-noHLkDuAiEEwABSh4"]
[Tue Jul 21 07:55:58.127165 2026] [security2:error] [pid 341679:tid 341873] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QPgWat-noHLkDuAiEEwABSh4"]
[Tue Jul 21 07:55:58.173876 2026] [autoindex:error] [pid 341679:tid 341866] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:58.384608 2026] [autoindex:error] [pid 341679:tid 341832] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:58.510872 2026] [core:error] [pid 341679:tid 341803] [remote 40.77.167.77:18360] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:55:58.510900 2026] [core:error] [pid 341679:tid 341803] [remote 40.77.167.77:18360] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:55:58.513978 2026] [security2:error] [pid 341679:tid 341921] [client 65.21.113.253:35180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QPgWat-noHLkDuAiEEAAAAXo"]
[Tue Jul 21 07:55:58.590198 2026] [security2:error] [pid 341679:tid 341867] [client 20.104.96.117:57735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/water.php"] [unique_id "al9QPgWat-noHLkDuAiEKgAAAUQ"]
[Tue Jul 21 07:55:58.596076 2026] [autoindex:error] [pid 341679:tid 341828] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:58.607468 2026] [security2:error] [pid 341679:tid 341716] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QPgWat-noHLkDuAiEKwABdyQ"]
[Tue Jul 21 07:55:58.607585 2026] [security2:error] [pid 341679:tid 341918] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QPgWat-noHLkDuAiEKwABdyQ"]
[Tue Jul 21 07:55:58.664575 2026] [security2:error] [pid 341679:tid 341763] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QPgWat-noHLkDuAiELgABJ1M"]
[Tue Jul 21 07:55:58.664762 2026] [security2:error] [pid 341679:tid 341838] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QPgWat-noHLkDuAiELgABJ1M"]
[Tue Jul 21 07:55:58.676766 2026] [security2:error] [pid 341679:tid 341771] [remote 40.77.167.10:40955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9QPgWat-noHLkDuAiEMwABeFs"]
[Tue Jul 21 07:55:58.804786 2026] [autoindex:error] [pid 341679:tid 341811] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:58.929463 2026] [security2:error] [pid 341679:tid 341879] [client 20.206.105.145:55935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/222.php"] [unique_id "al9QPgWat-noHLkDuAiEPQAAAVA"]
[Tue Jul 21 07:55:59.035990 2026] [security2:error] [pid 341679:tid 341873] [client 20.226.60.151:56783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/solo1.php"] [unique_id "al9QPwWat-noHLkDuAiEQAAAAUo"]
[Tue Jul 21 07:55:59.056006 2026] [autoindex:error] [pid 341679:tid 341903] [client 82.102.18.182:45336] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:59.096379 2026] [security2:error] [pid 341679:tid 341821] [client 20.104.96.117:62773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/sump1.php"] [unique_id "al9QPwWat-noHLkDuAiEQgAAARY"]
[Tue Jul 21 07:55:59.106524 2026] [security2:error] [pid 341679:tid 341849] [client 47.128.52.123:53110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thiagomartins.com"] [uri "/robots.txt"] [unique_id "al9QPwWat-noHLkDuAiEQwAAATI"]
[Tue Jul 21 07:55:59.249664 2026] [security2:error] [pid 341679:tid 341819] [client 20.104.96.117:54987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/nano.php"] [unique_id "al9QPwWat-noHLkDuAiESQAAARQ"]
[Tue Jul 21 07:55:59.254622 2026] [security2:error] [pid 341679:tid 341825] [client 193.36.225.70:34633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QPwWat-noHLkDuAiEQQAAARo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:55:59.296853 2026] [autoindex:error] [pid 341679:tid 341839] [client 82.102.18.182:45336] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:55:59.352104 2026] [security2:error] [pid 341679:tid 341862] [client 41.68.90.219:59316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QPwWat-noHLkDuAiEUgAAAT8"]
[Tue Jul 21 07:55:59.353471 2026] [security2:error] [pid 341679:tid 341862] [client 41.68.90.219:59316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QPwWat-noHLkDuAiEUgAAAT8"]
[Tue Jul 21 07:55:59.643826 2026] [security2:error] [pid 341679:tid 341885] [client 102.206.115.33:59192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QPwWat-noHLkDuAiEWwAAAVY"]
[Tue Jul 21 07:55:59.644284 2026] [security2:error] [pid 341679:tid 341885] [client 102.206.115.33:59192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QPwWat-noHLkDuAiEWwAAAVY"]
[Tue Jul 21 07:55:59.660847 2026] [security2:error] [pid 341679:tid 341689] [remote 65.111.23.239:48485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9QPgWat-noHLkDuAiEIgABWAk"]
[Tue Jul 21 07:55:59.762910 2026] [security2:error] [pid 341679:tid 341869] [client 20.197.192.193:54391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/berlin.php"] [unique_id "al9QPwWat-noHLkDuAiEZQAAAUY"]
[Tue Jul 21 07:55:59.835997 2026] [security2:error] [pid 341679:tid 341908] [client 198.54.128.138:58116] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9QPwWat-noHLkDuAiEZwAAAW0"]
[Tue Jul 21 07:55:59.836144 2026] [security2:error] [pid 341679:tid 341908] [client 198.54.128.138:58116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9QPwWat-noHLkDuAiEZwAAAW0"]
[Tue Jul 21 07:55:59.844436 2026] [security2:error] [pid 341679:tid 341906] [client 65.111.2.224:38245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.2.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QPgWat-noHLkDuAiENAAAAWs"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:56:00.197581 2026] [security2:error] [pid 341679:tid 341897] [client 20.206.105.145:55891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9QQAWat-noHLkDuAiEdQAAAWI"]
[Tue Jul 21 07:56:00.289690 2026] [security2:error] [pid 341679:tid 341889] [client 122.179.91.63:1253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEegAAAVo"]
[Tue Jul 21 07:56:00.290026 2026] [security2:error] [pid 341679:tid 341889] [client 122.179.91.63:1253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEegAAAVo"]
[Tue Jul 21 07:56:00.353592 2026] [security2:error] [pid 341679:tid 341715] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEgwABXyM"]
[Tue Jul 21 07:56:00.353793 2026] [security2:error] [pid 341679:tid 341894] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEgwABXyM"]
[Tue Jul 21 07:56:00.370130 2026] [security2:error] [pid 341679:tid 341831] [client 74.249.245.134:54365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/error.php"] [unique_id "al9QQAWat-noHLkDuAiEhAAAASA"]
[Tue Jul 21 07:56:00.639311 2026] [security2:error] [pid 341679:tid 341898] [client 122.164.127.47:50623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEjwAAAWM"]
[Tue Jul 21 07:56:00.639404 2026] [security2:error] [pid 341679:tid 341898] [client 122.164.127.47:50623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEjwAAAWM"]
[Tue Jul 21 07:56:00.705773 2026] [security2:error] [pid 341679:tid 341926] [client 109.60.28.94:39291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEkgAAAX8"]
[Tue Jul 21 07:56:00.705881 2026] [security2:error] [pid 341679:tid 341926] [client 109.60.28.94:39291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEkgAAAX8"]
[Tue Jul 21 07:56:00.767173 2026] [security2:error] [pid 341679:tid 341861] [client 117.210.135.0:62461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEkAAAAT4"]
[Tue Jul 21 07:56:00.846873 2026] [security2:error] [pid 341679:tid 341817] [client 103.86.117.203:63510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEmgAAARI"]
[Tue Jul 21 07:56:00.846969 2026] [security2:error] [pid 341679:tid 341817] [client 103.86.117.203:63510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEmgAAARI"]
[Tue Jul 21 07:56:00.922356 2026] [security2:error] [pid 341679:tid 341707] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEoAABRBs"]
[Tue Jul 21 07:56:00.922523 2026] [security2:error] [pid 341679:tid 341867] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEoAABRBs"]
[Tue Jul 21 07:56:00.958874 2026] [security2:error] [pid 341679:tid 341911] [client 184.75.221.3:60902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEpAAAAXA"]
[Tue Jul 21 07:56:00.959009 2026] [security2:error] [pid 341679:tid 341911] [client 184.75.221.3:60902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9QQAWat-noHLkDuAiEpAAAAXA"]
[Tue Jul 21 07:56:01.079543 2026] [security2:error] [pid 341679:tid 341811] [client 20.104.96.117:55032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/moon.php"] [unique_id "al9QQQWat-noHLkDuAiEpwAAAQw"]
[Tue Jul 21 07:56:01.299046 2026] [security2:error] [pid 341679:tid 341819] [client 65.21.113.253:44624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QQQWat-noHLkDuAiEsQAAARQ"]
[Tue Jul 21 07:56:01.311894 2026] [security2:error] [pid 341679:tid 341893] [client 20.206.105.145:55907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9QQQWat-noHLkDuAiEsgAAAV4"]
[Tue Jul 21 07:56:01.398554 2026] [security2:error] [pid 341679:tid 341831] [client 20.151.10.161:17345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9QQQWat-noHLkDuAiEugAAASA"]
[Tue Jul 21 07:56:01.519060 2026] [security2:error] [pid 341679:tid 341901] [client 20.104.96.117:62845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file5.php"] [unique_id "al9QQQWat-noHLkDuAiExAAAAWY"]
[Tue Jul 21 07:56:01.582801 2026] [security2:error] [pid 341679:tid 341838] [client 202.143.127.214:52042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QQQWat-noHLkDuAiExgAAASc"]
[Tue Jul 21 07:56:01.582962 2026] [security2:error] [pid 341679:tid 341838] [client 202.143.127.214:52042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QQQWat-noHLkDuAiExgAAASc"]
[Tue Jul 21 07:56:01.662163 2026] [security2:error] [pid 341679:tid 341698] [remote 72.167.132.114:57208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9QQQWat-noHLkDuAiEyAABDRI"]
[Tue Jul 21 07:56:01.861566 2026] [security2:error] [pid 341679:tid 341841] [client 65.21.113.253:35180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QQQWat-noHLkDuAiEuQAAASo"]
[Tue Jul 21 07:56:01.971509 2026] [security2:error] [pid 341679:tid 341915] [client 65.111.2.77:54251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.2.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QQAWat-noHLkDuAiEmAAAAXQ"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:56:02.033577 2026] [security2:error] [pid 341679:tid 341865] [client 20.151.10.161:17374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9QQgWat-noHLkDuAiE1wAAAUI"]
[Tue Jul 21 07:56:02.039400 2026] [security2:error] [pid 341679:tid 341891] [client 74.249.245.134:65172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/article.php"] [unique_id "al9QQgWat-noHLkDuAiE2AAAAVw"]
[Tue Jul 21 07:56:02.125410 2026] [security2:error] [pid 341679:tid 341688] [remote 65.111.0.96:21551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.0.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9QQQWat-noHLkDuAiE0gABNAg"]
[Tue Jul 21 07:56:02.398164 2026] [security2:error] [pid 341679:tid 341861] [client 65.21.113.253:32778] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QQQWat-noHLkDuAiE1AAAAT4"]
[Tue Jul 21 07:56:02.409692 2026] [security2:error] [pid 341679:tid 341925] [client 20.206.105.145:55899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/raw.php"] [unique_id "al9QQgWat-noHLkDuAiE6gAAAX4"]
[Tue Jul 21 07:56:02.578425 2026] [security2:error] [pid 341679:tid 341921] [client 20.151.10.161:17364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/media.php"] [unique_id "al9QQgWat-noHLkDuAiE9QAAAXo"]
[Tue Jul 21 07:56:02.617521 2026] [security2:error] [pid 341679:tid 341760] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QQgWat-noHLkDuAiE9gABGVA"]
[Tue Jul 21 07:56:02.617670 2026] [security2:error] [pid 341679:tid 341824] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QQgWat-noHLkDuAiE9gABGVA"]
[Tue Jul 21 07:56:03.034936 2026] [security2:error] [pid 341679:tid 341858] [client 20.104.96.117:57765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-info.php"] [unique_id "al9QQwWat-noHLkDuAiFBAAAATs"]
[Tue Jul 21 07:56:03.060017 2026] [security2:error] [pid 341679:tid 341857] [client 136.144.33.96:20159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QQwWat-noHLkDuAiFBQAAATo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:56:03.086249 2026] [security2:error] [pid 341679:tid 341848] [client 20.151.10.161:17348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/images.php"] [unique_id "al9QQwWat-noHLkDuAiFBgAAATE"]
[Tue Jul 21 07:56:03.366062 2026] [security2:error] [pid 341679:tid 341920] [client 178.153.91.96:63109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QQwWat-noHLkDuAiFEgAAAXk"]
[Tue Jul 21 07:56:03.366068 2026] [security2:error] [pid 341679:tid 341812] [client 38.100.221.102:17852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QQwWat-noHLkDuAiFEQAAAQ0"]
[Tue Jul 21 07:56:03.366184 2026] [security2:error] [pid 341679:tid 341812] [client 38.100.221.102:17852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QQwWat-noHLkDuAiFEQAAAQ0"]
[Tue Jul 21 07:56:03.366185 2026] [security2:error] [pid 341679:tid 341920] [client 178.153.91.96:63109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QQwWat-noHLkDuAiFEgAAAXk"]
[Tue Jul 21 07:56:03.494084 2026] [security2:error] [pid 341679:tid 341814] [client 20.151.10.161:17380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/adminner.php"] [unique_id "al9QQwWat-noHLkDuAiFFwAAAQ8"]
[Tue Jul 21 07:56:03.499206 2026] [security2:error] [pid 341679:tid 341873] [client 20.104.96.117:62790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/0xD.php"] [unique_id "al9QQwWat-noHLkDuAiFGAAAAUo"]
[Tue Jul 21 07:56:03.576834 2026] [security2:error] [pid 341679:tid 341825] [client 74.249.245.134:5513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/classwithtostring.php"] [unique_id "al9QQwWat-noHLkDuAiFHQAAARo"]
[Tue Jul 21 07:56:03.745573 2026] [security2:error] [pid 341679:tid 341863] [client 198.54.128.138:52020] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9QQwWat-noHLkDuAiFJAAAAUA"]
[Tue Jul 21 07:56:03.745678 2026] [security2:error] [pid 341679:tid 341863] [client 198.54.128.138:52020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9QQwWat-noHLkDuAiFJAAAAUA"]
[Tue Jul 21 07:56:03.781685 2026] [security2:error] [pid 341679:tid 341838] [client 20.151.10.161:17369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/admin.php"] [unique_id "al9QQwWat-noHLkDuAiFKAAAASc"]
[Tue Jul 21 07:56:03.975234 2026] [security2:error] [pid 341679:tid 341890] [client 117.217.38.194:56118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QQwWat-noHLkDuAiFMwAAAVs"]
[Tue Jul 21 07:56:03.975375 2026] [security2:error] [pid 341679:tid 341890] [client 117.217.38.194:56118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QQwWat-noHLkDuAiFMwAAAVs"]
[Tue Jul 21 07:56:04.005512 2026] [security2:error] [pid 341679:tid 341848] [client 20.206.105.145:55933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/abcd.php"] [unique_id "al9QRAWat-noHLkDuAiFNQAAATE"]
[Tue Jul 21 07:56:04.097518 2026] [security2:error] [pid 341679:tid 341875] [client 117.247.80.59:17264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRAWat-noHLkDuAiFNwAAAUw"]
[Tue Jul 21 07:56:04.098162 2026] [security2:error] [pid 341679:tid 341875] [client 117.247.80.59:17264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRAWat-noHLkDuAiFNwAAAUw"]
[Tue Jul 21 07:56:04.254252 2026] [security2:error] [pid 341679:tid 341829] [client 20.151.10.161:17290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/k.php"] [unique_id "al9QRAWat-noHLkDuAiFPgAAAR4"]
[Tue Jul 21 07:56:04.355767 2026] [security2:error] [pid 341679:tid 341823] [client 20.104.96.117:54939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/2000.php"] [unique_id "al9QRAWat-noHLkDuAiFPwAAARg"]
[Tue Jul 21 07:56:04.639158 2026] [security2:error] [pid 341679:tid 341894] [client 20.151.10.161:17365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/x.php"] [unique_id "al9QRAWat-noHLkDuAiFTQAAAV8"]
[Tue Jul 21 07:56:04.678971 2026] [security2:error] [pid 341679:tid 341753] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRAWat-noHLkDuAiFUQABYkk"]
[Tue Jul 21 07:56:04.679160 2026] [security2:error] [pid 341679:tid 341897] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRAWat-noHLkDuAiFUQABYkk"]
[Tue Jul 21 07:56:04.777426 2026] [security2:error] [pid 341679:tid 341901] [client 65.21.113.253:35180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QRAWat-noHLkDuAiFQAAAAWY"]
[Tue Jul 21 07:56:04.868833 2026] [security2:error] [pid 341679:tid 341818] [client 110.225.227.86:28941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.227.225.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "geohistorianiteroi.com"] [uri "/xmlrpc.php"] [unique_id "al9QQwWat-noHLkDuAiFKgAAARM"]
[Tue Jul 21 07:56:04.868993 2026] [security2:error] [pid 341679:tid 341818] [client 110.225.227.86:28941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "geohistorianiteroi.com"] [uri "/xmlrpc.php"] [unique_id "al9QQwWat-noHLkDuAiFKgAAARM"]
[Tue Jul 21 07:56:04.945734 2026] [security2:error] [pid 341679:tid 341744] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRAWat-noHLkDuAiFVgABKkA"]
[Tue Jul 21 07:56:04.945919 2026] [security2:error] [pid 341679:tid 341841] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRAWat-noHLkDuAiFVgABKkA"]
[Tue Jul 21 07:56:04.980443 2026] [security2:error] [pid 341679:tid 341842] [client 20.104.96.117:54978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/122.php"] [unique_id "al9QRAWat-noHLkDuAiFWAAAASs"]
[Tue Jul 21 07:56:05.018006 2026] [security2:error] [pid 341679:tid 341890] [client 20.151.10.161:17359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wss.php"] [unique_id "al9QRQWat-noHLkDuAiFXQAAAVs"]
[Tue Jul 21 07:56:05.114614 2026] [security2:error] [pid 341679:tid 341749] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRQWat-noHLkDuAiFYAABf0U"]
[Tue Jul 21 07:56:05.114757 2026] [security2:error] [pid 341679:tid 341926] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRQWat-noHLkDuAiFYAABf0U"]
[Tue Jul 21 07:56:05.308852 2026] [security2:error] [pid 341679:tid 341776] [remote 156.59.198.136:10624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "issima.net.br"] [uri "/equestre/esquema/issima-shinny.pdf"] [unique_id "al9QRQWat-noHLkDuAiFawABEWA"]
[Tue Jul 21 07:56:05.314566 2026] [security2:error] [pid 341679:tid 341920] [client 20.151.10.161:17292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/ty.php"] [unique_id "al9QRQWat-noHLkDuAiFbAAAAXk"]
[Tue Jul 21 07:56:05.384934 2026] [security2:error] [pid 341679:tid 341868] [client 223.236.153.128:7284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QRQWat-noHLkDuAiFbgAAAUU"]
[Tue Jul 21 07:56:05.385067 2026] [security2:error] [pid 341679:tid 341868] [client 223.236.153.128:7284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QRQWat-noHLkDuAiFbgAAAUU"]
[Tue Jul 21 07:56:05.626784 2026] [security2:error] [pid 341679:tid 341813] [client 122.162.144.145:10048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QRQWat-noHLkDuAiFegAAAQ4"]
[Tue Jul 21 07:56:05.626917 2026] [security2:error] [pid 341679:tid 341813] [client 122.162.144.145:10048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QRQWat-noHLkDuAiFegAAAQ4"]
[Tue Jul 21 07:56:05.683268 2026] [security2:error] [pid 341679:tid 341936] [client 20.151.10.161:17390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/155.php"] [unique_id "al9QRQWat-noHLkDuAiFfAAAAYk"]
[Tue Jul 21 07:56:05.726358 2026] [security2:error] [pid 341679:tid 341877] [client 139.167.225.182:51146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRQWat-noHLkDuAiFfgAAAU4"]
[Tue Jul 21 07:56:05.728199 2026] [security2:error] [pid 341679:tid 341877] [client 139.167.225.182:51146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRQWat-noHLkDuAiFfgAAAU4"]
[Tue Jul 21 07:56:05.833538 2026] [autoindex:error] [pid 341679:tid 341863] [client 20.226.60.151:56807] AH01276: Cannot serve directory /home3/factor11/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:05.987389 2026] [security2:error] [pid 341679:tid 341890] [client 20.151.10.161:17306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/ops.php"] [unique_id "al9QRQWat-noHLkDuAiFiQAAAVs"]
[Tue Jul 21 07:56:06.054919 2026] [security2:error] [pid 341679:tid 341926] [client 20.104.96.117:57462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/mds.php"] [unique_id "al9QRgWat-noHLkDuAiFjwAAAX8"]
[Tue Jul 21 07:56:06.252228 2026] [security2:error] [pid 341679:tid 341823] [client 20.104.96.117:62806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/fnstall.php"] [unique_id "al9QRgWat-noHLkDuAiFlQAAARg"]
[Tue Jul 21 07:56:06.329709 2026] [security2:error] [pid 341679:tid 341851] [client 20.151.10.161:17288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/ingfo.php"] [unique_id "al9QRgWat-noHLkDuAiFlwAAATQ"]
[Tue Jul 21 07:56:06.397391 2026] [security2:error] [pid 341679:tid 341892] [client 103.166.103.129:65186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QRgWat-noHLkDuAiFnQAAAV0"]
[Tue Jul 21 07:56:06.397529 2026] [security2:error] [pid 341679:tid 341892] [client 103.166.103.129:65186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QRgWat-noHLkDuAiFnQAAAV0"]
[Tue Jul 21 07:56:06.592926 2026] [security2:error] [pid 341679:tid 341825] [client 74.7.228.56:47610] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mdmetal.net.br"] [uri "/index.php"] [unique_id "al9QRgWat-noHLkDuAiFpwABGmU"]
[Tue Jul 21 07:56:06.651024 2026] [security2:error] [pid 341679:tid 341901] [client 20.151.10.161:17296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/error_log.php"] [unique_id "al9QRgWat-noHLkDuAiFrAAAAWY"]
[Tue Jul 21 07:56:06.693632 2026] [security2:error] [pid 341679:tid 341847] [client 103.78.200.11:51991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRgWat-noHLkDuAiFrQAAATA"]
[Tue Jul 21 07:56:06.694297 2026] [security2:error] [pid 341679:tid 341847] [client 103.78.200.11:51991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRgWat-noHLkDuAiFrQAAATA"]
[Tue Jul 21 07:56:06.748753 2026] [security2:error] [pid 341679:tid 341846] [client 106.215.181.8:9278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRgWat-noHLkDuAiFsAAAAS8"]
[Tue Jul 21 07:56:06.748861 2026] [security2:error] [pid 341679:tid 341846] [client 106.215.181.8:9278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRgWat-noHLkDuAiFsAAAAS8"]
[Tue Jul 21 07:56:06.846798 2026] [security2:error] [pid 341679:tid 341902] [client 193.36.225.68:30987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QRgWat-noHLkDuAiFswAAAWc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:56:06.917295 2026] [security2:error] [pid 341679:tid 341906] [client 198.54.128.138:58128] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9QRgWat-noHLkDuAiFtAAAAWs"]
[Tue Jul 21 07:56:06.917653 2026] [security2:error] [pid 341679:tid 341906] [client 198.54.128.138:58128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9QRgWat-noHLkDuAiFtAAAAWs"]
[Tue Jul 21 07:56:06.943260 2026] [security2:error] [pid 341679:tid 341904] [client 65.21.113.253:48816] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QRgWat-noHLkDuAiFtgAAAWk"]
[Tue Jul 21 07:56:06.963884 2026] [security2:error] [pid 341679:tid 341869] [client 92.119.178.3:35648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9QRgWat-noHLkDuAiFuAAAAUY"]
[Tue Jul 21 07:56:06.963963 2026] [security2:error] [pid 341679:tid 341869] [client 92.119.178.3:35648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9QRgWat-noHLkDuAiFuAAAAUY"]
[Tue Jul 21 07:56:06.975134 2026] [autoindex:error] [pid 341679:tid 341926] [client 82.102.18.182:56362] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:07.047195 2026] [security2:error] [pid 341679:tid 341858] [client 20.151.10.161:17376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/ok.php"] [unique_id "al9QRwWat-noHLkDuAiFvQAAATs"]
[Tue Jul 21 07:56:07.134731 2026] [security2:error] [pid 341679:tid 341899] [client 20.206.105.145:55844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/a1.php"] [unique_id "al9QRwWat-noHLkDuAiFwwAAAWQ"]
[Tue Jul 21 07:56:07.138195 2026] [security2:error] [pid 341679:tid 341829] [client 20.226.60.151:61613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/as.php"] [unique_id "al9QRwWat-noHLkDuAiFxAAAAR4"]
[Tue Jul 21 07:56:07.150750 2026] [security2:error] [pid 341679:tid 341878] [client 182.8.255.181:10171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QRwWat-noHLkDuAiFxgAAAU8"]
[Tue Jul 21 07:56:07.150864 2026] [security2:error] [pid 341679:tid 341878] [client 182.8.255.181:10171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QRwWat-noHLkDuAiFxgAAAU8"]
[Tue Jul 21 07:56:07.408128 2026] [security2:error] [pid 341679:tid 341879] [client 92.119.178.3:34614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9QRwWat-noHLkDuAiF0wAAAVA"]
[Tue Jul 21 07:56:07.408228 2026] [security2:error] [pid 341679:tid 341879] [client 92.119.178.3:34614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9QRwWat-noHLkDuAiF0wAAAVA"]
[Tue Jul 21 07:56:07.482873 2026] [security2:error] [pid 341679:tid 341896] [client 20.151.10.161:17329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/mac.php"] [unique_id "al9QRwWat-noHLkDuAiF2gAAAWE"]
[Tue Jul 21 07:56:07.566555 2026] [security2:error] [pid 341679:tid 341812] [client 65.21.113.253:35180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QRwWat-noHLkDuAiFxwAAAQ0"]
[Tue Jul 21 07:56:07.594569 2026] [security2:error] [pid 341679:tid 341862] [client 103.29.114.44:33331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRwWat-noHLkDuAiF3gAAAT8"]
[Tue Jul 21 07:56:07.594686 2026] [security2:error] [pid 341679:tid 341862] [client 103.29.114.44:33331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRwWat-noHLkDuAiF3gAAAT8"]
[Tue Jul 21 07:56:07.603060 2026] [security2:error] [pid 341679:tid 341925] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QRwWat-noHLkDuAiF2QABfk0"]
[Tue Jul 21 07:56:07.643216 2026] [security2:error] [pid 341679:tid 341832] [client 74.249.245.134:54379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/bless.php"] [unique_id "al9QRwWat-noHLkDuAiF5QAAASE"]
[Tue Jul 21 07:56:07.750464 2026] [security2:error] [pid 341679:tid 341864] [client 20.206.105.145:55855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9QRwWat-noHLkDuAiF6AAAAUE"]
[Tue Jul 21 07:56:07.962632 2026] [security2:error] [pid 341679:tid 341739] [remote 20.153.140.50:33596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9QRwWat-noHLkDuAiF8gABDzs"]
[Tue Jul 21 07:56:08.088098 2026] [security2:error] [pid 341679:tid 341871] [client 20.104.96.117:62726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/acp.php"] [unique_id "al9QSAWat-noHLkDuAiF9gAAAUg"]
[Tue Jul 21 07:56:08.277390 2026] [security2:error] [pid 341679:tid 341868] [client 20.151.10.161:17407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wefile.php"] [unique_id "al9QSAWat-noHLkDuAiF_wAAAUU"]
[Tue Jul 21 07:56:08.484171 2026] [security2:error] [pid 341679:tid 341865] [client 122.186.204.214:65217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QSAWat-noHLkDuAiGBQAAAUI"]
[Tue Jul 21 07:56:08.484312 2026] [security2:error] [pid 341679:tid 341865] [client 122.186.204.214:65217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QSAWat-noHLkDuAiGBQAAAUI"]
[Tue Jul 21 07:56:08.523646 2026] [security2:error] [pid 341679:tid 341742] [remote 104.207.63.109:37137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.63.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9QRwWat-noHLkDuAiF0gABYj4"]
[Tue Jul 21 07:56:08.637941 2026] [security2:error] [pid 341679:tid 341833] [client 20.104.96.117:54999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-blink.php"] [unique_id "al9QSAWat-noHLkDuAiGEgAAASI"]
[Tue Jul 21 07:56:08.767129 2026] [security2:error] [pid 341679:tid 341920] [client 20.206.105.145:55934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9QSAWat-noHLkDuAiGEwAAAXk"]
[Tue Jul 21 07:56:08.878255 2026] [security2:error] [pid 341679:tid 341846] [client 20.151.10.161:17350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9QSAWat-noHLkDuAiGGAAAAS8"]
[Tue Jul 21 07:56:09.139425 2026] [security2:error] [pid 341679:tid 341723] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QSQWat-noHLkDuAiGIAABSys"]
[Tue Jul 21 07:56:09.139575 2026] [security2:error] [pid 341679:tid 341874] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QSQWat-noHLkDuAiGIAABSys"]
[Tue Jul 21 07:56:09.163887 2026] [security2:error] [pid 341679:tid 341711] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QSQWat-noHLkDuAiGJgABDx8"]
[Tue Jul 21 07:56:09.164025 2026] [security2:error] [pid 341679:tid 341814] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QSQWat-noHLkDuAiGJgABDx8"]
[Tue Jul 21 07:56:09.362781 2026] [autoindex:error] [pid 341679:tid 341878] [client 20.151.10.161:0] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:09.452992 2026] [security2:error] [pid 341679:tid 341925] [client 122.179.91.63:21515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QSQWat-noHLkDuAiGMwAAAX4"]
[Tue Jul 21 07:56:09.453325 2026] [security2:error] [pid 341679:tid 341925] [client 122.179.91.63:21515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QSQWat-noHLkDuAiGMwAAAX4"]
[Tue Jul 21 07:56:09.518083 2026] [security2:error] [pid 341679:tid 341698] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QSQWat-noHLkDuAiGNgABRhI"]
[Tue Jul 21 07:56:09.518227 2026] [security2:error] [pid 341679:tid 341869] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QSQWat-noHLkDuAiGNgABRhI"]
[Tue Jul 21 07:56:09.692542 2026] [autoindex:error] [pid 341679:tid 341915] [client 20.151.10.161:17373] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:09.775169 2026] [security2:error] [pid 341679:tid 341867] [client 20.104.96.117:54916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/zc-208.php"] [unique_id "al9QSQWat-noHLkDuAiGRQAAAUQ"]
[Tue Jul 21 07:56:09.835232 2026] [security2:error] [pid 341679:tid 341901] [client 20.151.10.161:17373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9QSQWat-noHLkDuAiGRwAAAWY"]
[Tue Jul 21 07:56:10.042729 2026] [security2:error] [pid 341679:tid 341894] [client 41.68.90.219:59785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QSgWat-noHLkDuAiGTwAAAV8"]
[Tue Jul 21 07:56:10.042868 2026] [security2:error] [pid 341679:tid 341894] [client 41.68.90.219:59785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QSgWat-noHLkDuAiGTwAAAV8"]
[Tue Jul 21 07:56:10.059391 2026] [security2:error] [pid 341679:tid 341845] [client 65.21.113.253:41468] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QSQWat-noHLkDuAiGPAAAAS4"]
[Tue Jul 21 07:56:10.065836 2026] [security2:error] [pid 341679:tid 341866] [client 20.206.105.145:28615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9QSgWat-noHLkDuAiGUwAAAUM"]
[Tue Jul 21 07:56:10.132277 2026] [security2:error] [pid 341679:tid 341911] [client 102.206.115.33:59720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QSgWat-noHLkDuAiGWAAAAXA"]
[Tue Jul 21 07:56:10.132450 2026] [security2:error] [pid 341679:tid 341911] [client 102.206.115.33:59720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QSgWat-noHLkDuAiGWAAAAXA"]
[Tue Jul 21 07:56:10.132926 2026] [security2:error] [pid 341679:tid 341820] [client 65.21.113.253:48816] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QSgWat-noHLkDuAiGVwAAARU"]
[Tue Jul 21 07:56:10.326346 2026] [security2:error] [pid 341679:tid 341936] [client 20.226.60.151:56807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/cong.php"] [unique_id "al9QSgWat-noHLkDuAiGYAAAAYk"]
[Tue Jul 21 07:56:10.491099 2026] [security2:error] [pid 341679:tid 341833] [client 20.104.96.117:62771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/mosty.php"] [unique_id "al9QSgWat-noHLkDuAiGZgAAASI"]
[Tue Jul 21 07:56:10.824075 2026] [security2:error] [pid 341679:tid 341884] [client 136.144.33.106:27495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QSgWat-noHLkDuAiGbAAAAVU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:56:10.923358 2026] [security2:error] [pid 341679:tid 341881] [client 117.210.135.0:63189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QSgWat-noHLkDuAiGcwAAAVI"]
[Tue Jul 21 07:56:11.078516 2026] [security2:error] [pid 341679:tid 341887] [client 20.206.105.145:55878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/simple.php"] [unique_id "al9QSwWat-noHLkDuAiGgAAAAVg"]
[Tue Jul 21 07:56:11.200156 2026] [security2:error] [pid 341679:tid 341875] [client 122.164.127.47:51207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QSwWat-noHLkDuAiGgQAAAUw"]
[Tue Jul 21 07:56:11.203888 2026] [security2:error] [pid 341679:tid 341875] [client 122.164.127.47:51207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QSwWat-noHLkDuAiGgQAAAUw"]
[Tue Jul 21 07:56:11.209566 2026] [security2:error] [pid 341679:tid 341899] [client 74.249.245.134:64081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/bootstrap.php"] [unique_id "al9QSwWat-noHLkDuAiGggAAAWQ"]
[Tue Jul 21 07:56:11.213089 2026] [security2:error] [pid 341679:tid 341862] [client 65.21.113.253:41478] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QSgWat-noHLkDuAiGcgAAAT8"]
[Tue Jul 21 07:56:11.228778 2026] [security2:error] [pid 341679:tid 341756] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QSwWat-noHLkDuAiGiQABMEw"]
[Tue Jul 21 07:56:11.228898 2026] [security2:error] [pid 341679:tid 341847] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QSwWat-noHLkDuAiGiQABMEw"]
[Tue Jul 21 07:56:11.342568 2026] [security2:error] [pid 341679:tid 341819] [client 20.104.96.117:54993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/sid4.php"] [unique_id "al9QSwWat-noHLkDuAiGjgAAARQ"]
[Tue Jul 21 07:56:11.344085 2026] [security2:error] [pid 341679:tid 341836] [client 103.86.117.203:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QSwWat-noHLkDuAiGjwAAASU"]
[Tue Jul 21 07:56:11.344212 2026] [security2:error] [pid 341679:tid 341836] [client 103.86.117.203:64047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QSwWat-noHLkDuAiGjwAAASU"]
[Tue Jul 21 07:56:11.412823 2026] [security2:error] [pid 341679:tid 341933] [client 109.60.28.94:56290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QSwWat-noHLkDuAiGkQAAAYY"]
[Tue Jul 21 07:56:11.413560 2026] [security2:error] [pid 341679:tid 341933] [client 109.60.28.94:56290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QSwWat-noHLkDuAiGkQAAAYY"]
[Tue Jul 21 07:56:11.562713 2026] [security2:error] [pid 341679:tid 341879] [client 82.102.18.182:49652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agenciawats.com.br"] [uri "/wp-login.php"] [unique_id "al9QSwWat-noHLkDuAiGlgAAAVA"]
[Tue Jul 21 07:56:11.573182 2026] [security2:error] [pid 341679:tid 341705] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QSwWat-noHLkDuAiGlwABCxk"]
[Tue Jul 21 07:56:11.573307 2026] [security2:error] [pid 341679:tid 341810] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QSwWat-noHLkDuAiGlwABCxk"]
[Tue Jul 21 07:56:11.711656 2026] [security2:error] [pid 341679:tid 341913] [client 20.104.96.117:62828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/6.php"] [unique_id "al9QSwWat-noHLkDuAiGnQAAAXI"]
[Tue Jul 21 07:56:11.836206 2026] [security2:error] [pid 341679:tid 341918] [client 74.249.245.134:54364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/storage/index.php"] [unique_id "al9QSwWat-noHLkDuAiGpAAAAXc"]
[Tue Jul 21 07:56:12.262463 2026] [security2:error] [pid 341679:tid 341876] [client 20.104.96.117:54933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wmore1.php"] [unique_id "al9QTAWat-noHLkDuAiGtQAAAU0"]
[Tue Jul 21 07:56:12.425948 2026] [security2:error] [pid 341679:tid 341834] [client 37.140.223.138:46171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QSwWat-noHLkDuAiGjAAAASM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:56:12.456390 2026] [security2:error] [pid 341679:tid 341861] [client 202.143.127.214:52516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QTAWat-noHLkDuAiGvAAAAT4"]
[Tue Jul 21 07:56:12.456511 2026] [security2:error] [pid 341679:tid 341861] [client 202.143.127.214:52516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QTAWat-noHLkDuAiGvAAAAT4"]
[Tue Jul 21 07:56:12.634147 2026] [security2:error] [pid 341679:tid 341877] [client 65.21.113.253:41468] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QTAWat-noHLkDuAiGsgAAAU4"]
[Tue Jul 21 07:56:12.734300 2026] [security2:error] [pid 341679:tid 341825] [client 82.102.18.182:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agenciawats.com.br"] [uri "/wp-login.php"] [unique_id "al9QTAWat-noHLkDuAiGwwAAARo"]
[Tue Jul 21 07:56:12.858561 2026] [security2:error] [pid 341679:tid 341913] [client 20.206.105.145:55889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/xxx.php"] [unique_id "al9QTAWat-noHLkDuAiGyAAAAXI"]
[Tue Jul 21 07:56:13.217577 2026] [security2:error] [pid 341679:tid 341763] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QTQWat-noHLkDuAiG1wABW1M"]
[Tue Jul 21 07:56:13.217761 2026] [security2:error] [pid 341679:tid 341890] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QTQWat-noHLkDuAiG1wABW1M"]
[Tue Jul 21 07:56:13.375652 2026] [security2:error] [pid 341679:tid 341848] [client 20.104.96.117:54958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/solo1.php"] [unique_id "al9QTQWat-noHLkDuAiG3gAAATE"]
[Tue Jul 21 07:56:13.625360 2026] [autoindex:error] [pid 341679:tid 341811] [client 82.102.18.182:56362] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:13.818996 2026] [security2:error] [pid 341679:tid 341834] [client 20.104.96.117:62780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9QTQWat-noHLkDuAiG6wAAASM"]
[Tue Jul 21 07:56:13.824607 2026] [security2:error] [pid 341679:tid 341881] [client 178.153.91.96:58030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QTQWat-noHLkDuAiG7QAAAVI"]
[Tue Jul 21 07:56:13.824731 2026] [security2:error] [pid 341679:tid 341881] [client 178.153.91.96:58030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QTQWat-noHLkDuAiG7QAAAVI"]
[Tue Jul 21 07:56:13.957785 2026] [security2:error] [pid 341679:tid 341904] [client 38.100.221.102:17590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QTQWat-noHLkDuAiG8gAAAWk"]
[Tue Jul 21 07:56:13.957913 2026] [security2:error] [pid 341679:tid 341904] [client 38.100.221.102:17590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QTQWat-noHLkDuAiG8gAAAWk"]
[Tue Jul 21 07:56:14.340670 2026] [security2:error] [pid 341679:tid 341877] [client 65.21.113.253:41468] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QTQWat-noHLkDuAiG8QAAAU4"]
[Tue Jul 21 07:56:14.430941 2026] [security2:error] [pid 341679:tid 341923] [client 20.151.10.161:17385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/like.php"] [unique_id "al9QTgWat-noHLkDuAiHAAAAAXw"]
[Tue Jul 21 07:56:14.520407 2026] [security2:error] [pid 341679:tid 341910] [client 117.217.38.194:56616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QTgWat-noHLkDuAiHCQAAAW8"]
[Tue Jul 21 07:56:14.520764 2026] [security2:error] [pid 341679:tid 341910] [client 117.217.38.194:56616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QTgWat-noHLkDuAiHCQAAAW8"]
[Tue Jul 21 07:56:14.655851 2026] [security2:error] [pid 341679:tid 341933] [client 117.247.80.59:17761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QTgWat-noHLkDuAiHCwAAAYY"]
[Tue Jul 21 07:56:14.655989 2026] [security2:error] [pid 341679:tid 341933] [client 117.247.80.59:17761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QTgWat-noHLkDuAiHCwAAAYY"]
[Tue Jul 21 07:56:14.676268 2026] [security2:error] [pid 341679:tid 341835] [client 20.226.60.151:60010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9QTgWat-noHLkDuAiHDwAAASQ"]
[Tue Jul 21 07:56:14.824872 2026] [security2:error] [pid 341679:tid 341820] [client 82.102.18.182:35260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agenciawats.com.br"] [uri "/wp-login.php"] [unique_id "al9QTgWat-noHLkDuAiHGAAAARU"]
[Tue Jul 21 07:56:14.889593 2026] [security2:error] [pid 341679:tid 341902] [client 184.75.221.3:35424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9QTgWat-noHLkDuAiHGgAAAWc"]
[Tue Jul 21 07:56:14.889697 2026] [security2:error] [pid 341679:tid 341902] [client 184.75.221.3:35424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9QTgWat-noHLkDuAiHGgAAAWc"]
[Tue Jul 21 07:56:14.901756 2026] [security2:error] [pid 341679:tid 341862] [client 20.151.10.161:17349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/.well-known/about.php"] [unique_id "al9QTgWat-noHLkDuAiHGwAAAT8"]
[Tue Jul 21 07:56:15.029076 2026] [autoindex:error] [pid 341679:tid 341840] [client 82.102.18.182:0] AH01276: Cannot serve directory /home4/bomexi25/agenciawats.com.br/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:15.135772 2026] [security2:error] [pid 341679:tid 341880] [client 184.75.221.3:35434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9QTwWat-noHLkDuAiHJgAAAVE"]
[Tue Jul 21 07:56:15.135870 2026] [security2:error] [pid 341679:tid 341880] [client 184.75.221.3:35434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9QTwWat-noHLkDuAiHJgAAAVE"]
[Tue Jul 21 07:56:15.209019 2026] [security2:error] [pid 341679:tid 341771] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QTwWat-noHLkDuAiHJwABZFs"]
[Tue Jul 21 07:56:15.209188 2026] [security2:error] [pid 341679:tid 341899] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QTwWat-noHLkDuAiHJwABZFs"]
[Tue Jul 21 07:56:15.230852 2026] [security2:error] [pid 341679:tid 341821] [client 20.206.105.145:55856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/hypo.php"] [unique_id "al9QTwWat-noHLkDuAiHKAAAARY"]
[Tue Jul 21 07:56:15.341936 2026] [security2:error] [pid 341679:tid 341829] [client 193.36.225.71:25281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QTwWat-noHLkDuAiHLQAAAR4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:56:15.486499 2026] [security2:error] [pid 341679:tid 341783] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QTwWat-noHLkDuAiHMgABWmc"]
[Tue Jul 21 07:56:15.486643 2026] [security2:error] [pid 341679:tid 341889] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QTwWat-noHLkDuAiHMgABWmc"]
[Tue Jul 21 07:56:15.560251 2026] [security2:error] [pid 341679:tid 341846] [client 141.11.107.74:57829] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.oticapersona.com.br"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "al9QTwWat-noHLkDuAiHNwAAAS8"]
[Tue Jul 21 07:56:15.576724 2026] [security2:error] [pid 341679:tid 341910] [client 141.11.107.74:57878] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.oticapersona.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9QTwWat-noHLkDuAiHOgAAAW8"]
[Tue Jul 21 07:56:15.583593 2026] [security2:error] [pid 341679:tid 341832] [client 141.11.107.74:57898] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.oticapersona.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9QTwWat-noHLkDuAiHPAAAASE"]
[Tue Jul 21 07:56:15.590856 2026] [security2:error] [pid 341679:tid 341849] [client 141.11.107.74:57906] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.oticapersona.com.br"] [uri "/"] [unique_id "al9QTwWat-noHLkDuAiHPQAAATI"]
[Tue Jul 21 07:56:15.592003 2026] [security2:error] [pid 341679:tid 341895] [client 141.11.107.74:57896] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "oticapersona.com.br"] [uri "/"] [unique_id "al9QTwWat-noHLkDuAiHPgAAAWA"]
[Tue Jul 21 07:56:15.605731 2026] [security2:error] [pid 341679:tid 341812] [client 141.11.107.74:57952] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.oticapersona.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9QTwWat-noHLkDuAiHPwAAAQ0"]
[Tue Jul 21 07:56:15.606206 2026] [security2:error] [pid 341679:tid 341901] [client 141.11.107.74:57960] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.oticapersona.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9QTwWat-noHLkDuAiHQAAAAWY"]
[Tue Jul 21 07:56:15.608578 2026] [security2:error] [pid 341679:tid 341826] [client 141.11.107.74:57957] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.oticapersona.com.br"] [uri "/"] [unique_id "al9QTwWat-noHLkDuAiHQQAAARs"]
[Tue Jul 21 07:56:15.660870 2026] [security2:error] [pid 341679:tid 341702] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QTwWat-noHLkDuAiHQgABgRY"]
[Tue Jul 21 07:56:15.661013 2026] [security2:error] [pid 341679:tid 341928] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QTwWat-noHLkDuAiHQgABgRY"]
[Tue Jul 21 07:56:15.674188 2026] [security2:error] [pid 341679:tid 341906] [client 20.226.60.151:61512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9QTwWat-noHLkDuAiHQwAAAWs"]
[Tue Jul 21 07:56:15.790442 2026] [security2:error] [pid 341679:tid 341824] [client 141.11.107.74:58108] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ftp.oticapersona.com.br"] [uri "/"] [unique_id "al9QTwWat-noHLkDuAiHRQAAARk"]
[Tue Jul 21 07:56:15.791887 2026] [security2:error] [pid 341679:tid 341844] [client 20.226.60.151:59935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9QTwWat-noHLkDuAiHRgAAAS0"]
[Tue Jul 21 07:56:15.864153 2026] [autoindex:error] [pid 341679:tid 341816] [client 20.226.60.151:50660] AH01276: Cannot serve directory /home3/factor11/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:15.872867 2026] [security2:error] [pid 341679:tid 341831] [client 20.226.60.151:50660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/public/css.php"] [unique_id "al9QTwWat-noHLkDuAiHTAAAASA"]
[Tue Jul 21 07:56:15.943181 2026] [security2:error] [pid 341679:tid 341905] [client 20.104.96.117:54971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/cong.php"] [unique_id "al9QTwWat-noHLkDuAiHUAAAAWo"]
[Tue Jul 21 07:56:16.062932 2026] [security2:error] [pid 341679:tid 341837] [client 20.151.10.161:17360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9QUAWat-noHLkDuAiHVgAAASY"]
[Tue Jul 21 07:56:16.106383 2026] [security2:error] [pid 341679:tid 341893] [client 20.206.105.145:55909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/chosen.php"] [unique_id "al9QUAWat-noHLkDuAiHWgAAAV4"]
[Tue Jul 21 07:56:16.118700 2026] [security2:error] [pid 341679:tid 341876] [client 74.249.245.134:5508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/g.php"] [unique_id "al9QUAWat-noHLkDuAiHWwAAAU0"]
[Tue Jul 21 07:56:16.133554 2026] [security2:error] [pid 341679:tid 341839] [client 223.236.153.128:4560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QUAWat-noHLkDuAiHXAAAASg"]
[Tue Jul 21 07:56:16.133678 2026] [security2:error] [pid 341679:tid 341839] [client 223.236.153.128:4560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QUAWat-noHLkDuAiHXAAAASg"]
[Tue Jul 21 07:56:16.222473 2026] [security2:error] [pid 341679:tid 341851] [client 92.119.178.3:43354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9QUAWat-noHLkDuAiHXQAAATQ"]
[Tue Jul 21 07:56:16.222570 2026] [security2:error] [pid 341679:tid 341851] [client 92.119.178.3:43354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9QUAWat-noHLkDuAiHXQAAATQ"]
[Tue Jul 21 07:56:16.410249 2026] [security2:error] [pid 341679:tid 341934] [client 122.162.144.145:20396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QUAWat-noHLkDuAiHZwAAAYc"]
[Tue Jul 21 07:56:16.410359 2026] [security2:error] [pid 341679:tid 341934] [client 122.162.144.145:20396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QUAWat-noHLkDuAiHZwAAAYc"]
[Tue Jul 21 07:56:16.603008 2026] [security2:error] [pid 341679:tid 341863] [client 139.167.225.182:51805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QUAWat-noHLkDuAiHbgAAAUA"]
[Tue Jul 21 07:56:16.603093 2026] [security2:error] [pid 341679:tid 341863] [client 139.167.225.182:51805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QUAWat-noHLkDuAiHbgAAAUA"]
[Tue Jul 21 07:56:16.748891 2026] [security2:error] [pid 341679:tid 341703] [remote 45.3.42.63:57243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9QTwWat-noHLkDuAiHOwABgxc"]
[Tue Jul 21 07:56:16.919290 2026] [security2:error] [pid 341679:tid 341827] [client 20.104.96.117:57768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/public/css.php"] [unique_id "al9QUAWat-noHLkDuAiHfQAAARw"]
[Tue Jul 21 07:56:16.976007 2026] [autoindex:error] [pid 341679:tid 341890] [client 20.151.10.161:17400] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:17.023669 2026] [security2:error] [pid 341679:tid 341834] [client 20.226.60.151:59915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/xyn.php"] [unique_id "al9QUQWat-noHLkDuAiHjAAAASM"]
[Tue Jul 21 07:56:17.033557 2026] [security2:error] [pid 341679:tid 341862] [client 172.245.102.30:30077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QUQWat-noHLkDuAiHjQAAAT8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:56:17.123906 2026] [security2:error] [pid 341679:tid 341876] [client 20.104.96.117:62724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/qqqa.php"] [unique_id "al9QUQWat-noHLkDuAiHjwAAAU0"]
[Tue Jul 21 07:56:17.225049 2026] [security2:error] [pid 341679:tid 341896] [client 103.166.103.129:50833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QUQWat-noHLkDuAiHngAAAWE"]
[Tue Jul 21 07:56:17.225157 2026] [security2:error] [pid 341679:tid 341896] [client 103.166.103.129:50833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QUQWat-noHLkDuAiHngAAAWE"]
[Tue Jul 21 07:56:17.301290 2026] [autoindex:error] [pid 341679:tid 341925] [client 20.151.10.161:17400] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:17.331591 2026] [security2:error] [pid 341679:tid 341913] [client 106.215.181.8:14944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QUQWat-noHLkDuAiHpAAAAXI"]
[Tue Jul 21 07:56:17.341321 2026] [security2:error] [pid 341679:tid 341913] [client 106.215.181.8:14944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QUQWat-noHLkDuAiHpAAAAXI"]
[Tue Jul 21 07:56:17.404559 2026] [security2:error] [pid 341679:tid 341869] [client 103.78.200.11:52452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QUQWat-noHLkDuAiHpQAAAUY"]
[Tue Jul 21 07:56:17.404678 2026] [security2:error] [pid 341679:tid 341869] [client 103.78.200.11:52452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QUQWat-noHLkDuAiHpQAAAUY"]
[Tue Jul 21 07:56:17.439252 2026] [security2:error] [pid 341679:tid 341894] [client 20.151.10.161:17400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/pucci.php"] [unique_id "al9QUQWat-noHLkDuAiHpgAAAV8"]
[Tue Jul 21 07:56:17.538335 2026] [security2:error] [pid 341679:tid 341874] [client 182.8.255.181:17561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QUQWat-noHLkDuAiHrAAAAUs"]
[Tue Jul 21 07:56:17.538464 2026] [security2:error] [pid 341679:tid 341874] [client 182.8.255.181:17561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QUQWat-noHLkDuAiHrAAAAUs"]
[Tue Jul 21 07:56:17.940573 2026] [security2:error] [pid 341679:tid 341847] [client 204.8.98.45:57788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9QUQWat-noHLkDuAiHvgAAATA"]
[Tue Jul 21 07:56:17.940649 2026] [security2:error] [pid 341679:tid 341847] [client 204.8.98.45:57788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9QUQWat-noHLkDuAiHvgAAATA"]
[Tue Jul 21 07:56:17.946497 2026] [security2:error] [pid 341679:tid 341814] [client 20.226.60.151:59969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/patie.php"] [unique_id "al9QUQWat-noHLkDuAiHvwAAAQ8"]
[Tue Jul 21 07:56:18.165996 2026] [security2:error] [pid 341679:tid 341838] [client 65.21.113.253:32828] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QUgWat-noHLkDuAiHxAAAASc"]
[Tue Jul 21 07:56:18.248449 2026] [security2:error] [pid 341679:tid 341854] [client 65.21.113.253:41468] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QUQWat-noHLkDuAiHtgAAATc"]
[Tue Jul 21 07:56:18.248720 2026] [security2:error] [pid 341679:tid 341865] [client 103.29.114.44:58149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QUgWat-noHLkDuAiHxwAAAUI"]
[Tue Jul 21 07:56:18.248885 2026] [security2:error] [pid 341679:tid 341865] [client 103.29.114.44:58149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QUgWat-noHLkDuAiHxwAAAUI"]
[Tue Jul 21 07:56:18.407574 2026] [security2:error] [pid 341679:tid 341876] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QUgWat-noHLkDuAiHyAABTRw"]
[Tue Jul 21 07:56:18.854754 2026] [security2:error] [pid 341679:tid 341872] [client 74.249.245.134:64078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/config-backup.php"] [unique_id "al9QUgWat-noHLkDuAiH3wAAAUk"]
[Tue Jul 21 07:56:18.886319 2026] [security2:error] [pid 341679:tid 341860] [client 193.36.225.67:50115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QUgWat-noHLkDuAiH4QAAAT0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:56:19.122962 2026] [security2:error] [pid 341679:tid 341811] [client 20.104.96.117:54975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/output.php"] [unique_id "al9QUwWat-noHLkDuAiH5gAAAQw"]
[Tue Jul 21 07:56:19.229979 2026] [security2:error] [pid 341679:tid 341874] [client 65.21.113.253:41488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QUgWat-noHLkDuAiH3AAAAUs"]
[Tue Jul 21 07:56:19.258605 2026] [security2:error] [pid 341679:tid 341866] [client 122.186.204.214:49378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QUwWat-noHLkDuAiH5wAAAUM"]
[Tue Jul 21 07:56:19.258728 2026] [security2:error] [pid 341679:tid 341866] [client 122.186.204.214:49378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QUwWat-noHLkDuAiH5wAAAUM"]
[Tue Jul 21 07:56:19.434272 2026] [security2:error] [pid 341679:tid 341816] [client 20.206.105.145:55908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/file5.php"] [unique_id "al9QUwWat-noHLkDuAiH6gAAARE"]
[Tue Jul 21 07:56:19.454162 2026] [security2:error] [pid 341679:tid 341831] [client 20.226.60.151:59973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/aa.php"] [unique_id "al9QUwWat-noHLkDuAiH7wAAASA"]
[Tue Jul 21 07:56:19.508575 2026] [security2:error] [pid 341679:tid 341812] [client 122.179.91.63:31666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QUwWat-noHLkDuAiH8AAAAQ0"]
[Tue Jul 21 07:56:19.508914 2026] [security2:error] [pid 341679:tid 341812] [client 122.179.91.63:31666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QUwWat-noHLkDuAiH8AAAAQ0"]
[Tue Jul 21 07:56:19.644905 2026] [autoindex:error] [pid 341679:tid 341857] [client 20.151.10.161:0] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:19.758394 2026] [security2:error] [pid 341679:tid 341710] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QUwWat-noHLkDuAiH-gABTx4"]
[Tue Jul 21 07:56:19.758568 2026] [security2:error] [pid 341679:tid 341878] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QUwWat-noHLkDuAiH-gABTx4"]
[Tue Jul 21 07:56:19.936894 2026] [autoindex:error] [pid 341679:tid 341851] [client 20.151.10.161:0] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:20.071159 2026] [security2:error] [pid 341679:tid 341929] [client 20.104.96.117:62840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/aunmc.php"] [unique_id "al9QVAWat-noHLkDuAiIBQAAAYI"]
[Tue Jul 21 07:56:20.095100 2026] [security2:error] [pid 341679:tid 341934] [client 20.151.10.161:17405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wp-temp.php"] [unique_id "al9QVAWat-noHLkDuAiIBwAAAYc"]
[Tue Jul 21 07:56:20.107824 2026] [security2:error] [pid 341679:tid 341858] [client 65.21.113.253:41468] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QUwWat-noHLkDuAiH-AAAATs"]
[Tue Jul 21 07:56:20.312090 2026] [security2:error] [pid 341679:tid 341690] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QVAWat-noHLkDuAiIFAABQQo"]
[Tue Jul 21 07:56:20.312237 2026] [security2:error] [pid 341679:tid 341864] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QVAWat-noHLkDuAiIFAABQQo"]
[Tue Jul 21 07:56:20.384600 2026] [security2:error] [pid 341679:tid 341759] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QVAWat-noHLkDuAiIFgABg08"]
[Tue Jul 21 07:56:20.384743 2026] [security2:error] [pid 341679:tid 341930] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QVAWat-noHLkDuAiIFgABg08"]
[Tue Jul 21 07:56:20.552439 2026] [security2:error] [pid 341679:tid 341863] [client 41.68.90.219:60249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QVAWat-noHLkDuAiIIgAAAUA"]
[Tue Jul 21 07:56:20.553682 2026] [security2:error] [pid 341679:tid 341863] [client 41.68.90.219:60249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QVAWat-noHLkDuAiIIgAAAUA"]
[Tue Jul 21 07:56:20.718566 2026] [security2:error] [pid 341679:tid 341818] [client 102.206.115.33:60032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QVAWat-noHLkDuAiIJwAAARM"]
[Tue Jul 21 07:56:20.718684 2026] [security2:error] [pid 341679:tid 341818] [client 102.206.115.33:60032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QVAWat-noHLkDuAiIJwAAARM"]
[Tue Jul 21 07:56:20.967725 2026] [security2:error] [pid 341679:tid 341927] [client 65.21.113.253:32828] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QVAWat-noHLkDuAiINQAAAYA"]
[Tue Jul 21 07:56:21.303927 2026] [security2:error] [pid 341679:tid 341919] [client 20.226.60.151:59930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/xwpg.php"] [unique_id "al9QVQWat-noHLkDuAiIPQAAAXg"]
[Tue Jul 21 07:56:21.574967 2026] [security2:error] [pid 341679:tid 341879] [client 65.21.113.253:41468] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QVQWat-noHLkDuAiIOQAAAVA"]
[Tue Jul 21 07:56:21.581515 2026] [security2:error] [pid 341679:tid 341829] [client 117.210.135.0:63880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QVQWat-noHLkDuAiIQAAAAR4"]
[Tue Jul 21 07:56:21.717778 2026] [security2:error] [pid 341679:tid 341848] [client 74.249.245.134:54350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/nf.php"] [unique_id "al9QVQWat-noHLkDuAiITQAAATE"]
[Tue Jul 21 07:56:21.828313 2026] [security2:error] [pid 341679:tid 341920] [client 103.86.117.203:64591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QVQWat-noHLkDuAiITwAAAXk"]
[Tue Jul 21 07:56:21.828423 2026] [security2:error] [pid 341679:tid 341920] [client 103.86.117.203:64591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QVQWat-noHLkDuAiITwAAAXk"]
[Tue Jul 21 07:56:21.878092 2026] [security2:error] [pid 341679:tid 341911] [client 20.104.96.117:62846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/uoocf.php"] [unique_id "al9QVQWat-noHLkDuAiIUAAAAXA"]
[Tue Jul 21 07:56:21.901462 2026] [security2:error] [pid 341679:tid 341935] [client 122.164.127.47:51793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QVQWat-noHLkDuAiIUgAAAYg"]
[Tue Jul 21 07:56:21.901601 2026] [security2:error] [pid 341679:tid 341935] [client 122.164.127.47:51793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QVQWat-noHLkDuAiIUgAAAYg"]
[Tue Jul 21 07:56:22.152696 2026] [security2:error] [pid 341679:tid 341702] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QVgWat-noHLkDuAiIWQABPxY"]
[Tue Jul 21 07:56:22.152843 2026] [security2:error] [pid 341679:tid 341862] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QVgWat-noHLkDuAiIWQABPxY"]
[Tue Jul 21 07:56:22.241311 2026] [security2:error] [pid 341679:tid 341858] [client 74.249.245.134:64093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/goods.php"] [unique_id "al9QVgWat-noHLkDuAiIXgAAATs"]
[Tue Jul 21 07:56:22.255943 2026] [security2:error] [pid 341679:tid 341902] [client 109.60.28.94:40133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QVgWat-noHLkDuAiIXwAAAWc"]
[Tue Jul 21 07:56:22.256088 2026] [security2:error] [pid 341679:tid 341902] [client 109.60.28.94:40133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QVgWat-noHLkDuAiIXwAAAWc"]
[Tue Jul 21 07:56:22.329495 2026] [security2:error] [pid 341679:tid 341700] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QVgWat-noHLkDuAiIYQABWRQ"]
[Tue Jul 21 07:56:22.329713 2026] [security2:error] [pid 341679:tid 341888] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QVgWat-noHLkDuAiIYQABWRQ"]
[Tue Jul 21 07:56:22.504891 2026] [security2:error] [pid 341679:tid 341810] [client 65.111.15.106:31699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QVQWat-noHLkDuAiIQgAAAQs"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:56:22.551379 2026] [security2:error] [pid 341679:tid 341852] [client 20.226.60.151:61541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/w1px.php"] [unique_id "al9QVgWat-noHLkDuAiIaQAAATU"]
[Tue Jul 21 07:56:22.618479 2026] [autoindex:error] [pid 341679:tid 341824] [client 20.151.10.161:0] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:22.621064 2026] [security2:error] [pid 341679:tid 341904] [client 20.226.60.151:59983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/ops.php"] [unique_id "al9QVgWat-noHLkDuAiIbgAAAWk"]
[Tue Jul 21 07:56:22.895847 2026] [security2:error] [pid 341679:tid 341871] [client 20.151.10.161:17397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/xmu.php"] [unique_id "al9QVgWat-noHLkDuAiIeAAAAUg"]
[Tue Jul 21 07:56:22.932044 2026] [security2:error] [pid 341679:tid 341895] [client 65.21.113.253:32828] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QVgWat-noHLkDuAiIegAAAWA"]
[Tue Jul 21 07:56:23.103255 2026] [security2:error] [pid 341679:tid 341817] [client 20.151.10.161:28846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9QVwWat-noHLkDuAiIgQAAARI"]
[Tue Jul 21 07:56:23.415436 2026] [security2:error] [pid 341679:tid 341865] [client 202.143.127.214:52985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QVwWat-noHLkDuAiIiwAAAUI"]
[Tue Jul 21 07:56:23.415905 2026] [security2:error] [pid 341679:tid 341865] [client 202.143.127.214:52985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QVwWat-noHLkDuAiIiwAAAUI"]
[Tue Jul 21 07:56:23.558578 2026] [security2:error] [pid 341679:tid 341868] [client 216.73.216.212:25844] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1450"] [id "9011111"] [msg "SQUID data collection"] [hostname "www.3d-surgery.com.br"] [uri "/"] [unique_id "al9QVwWat-noHLkDuAiIkAAAAUU"]
[Tue Jul 21 07:56:23.564046 2026] [security2:error] [pid 341679:tid 341858] [client 216.73.216.212:0] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1450"] [id "9011111"] [msg "SQUID data collection"] [hostname "www.3d-surgery.com.br"] [uri "/"] [unique_id "al9QVwWat-noHLkDuAiIkgAAATs"]
[Tue Jul 21 07:56:23.573738 2026] [security2:error] [pid 341679:tid 341890] [client 193.36.225.57:48677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QVwWat-noHLkDuAiIigAAAVs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:56:23.951141 2026] [security2:error] [pid 341679:tid 341919] [client 20.104.96.117:54995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-file-120.php"] [unique_id "al9QVwWat-noHLkDuAiInAAAAXg"]
[Tue Jul 21 07:56:23.956158 2026] [security2:error] [pid 341679:tid 341769] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QVwWat-noHLkDuAiImwABZVk"]
[Tue Jul 21 07:56:23.956369 2026] [security2:error] [pid 341679:tid 341900] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QVwWat-noHLkDuAiImwABZVk"]
[Tue Jul 21 07:56:23.989412 2026] [security2:error] [pid 341679:tid 341857] [client 65.21.113.253:38546] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QVwWat-noHLkDuAiIkwAAATo"]
[Tue Jul 21 07:56:24.352831 2026] [security2:error] [pid 341679:tid 341883] [client 20.206.105.145:55910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/file.php"] [unique_id "al9QWAWat-noHLkDuAiIpwAAAVQ"]
[Tue Jul 21 07:56:24.394762 2026] [security2:error] [pid 341679:tid 341828] [client 178.153.91.96:64799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QWAWat-noHLkDuAiIqAAAAR0"]
[Tue Jul 21 07:56:24.394879 2026] [security2:error] [pid 341679:tid 341828] [client 178.153.91.96:64799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QWAWat-noHLkDuAiIqAAAAR0"]
[Tue Jul 21 07:56:24.406872 2026] [security2:error] [pid 341679:tid 341895] [client 92.119.178.3:42462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9QWAWat-noHLkDuAiIqQAAAWA"]
[Tue Jul 21 07:56:24.406959 2026] [security2:error] [pid 341679:tid 341895] [client 92.119.178.3:42462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9QWAWat-noHLkDuAiIqQAAAWA"]
[Tue Jul 21 07:56:24.416167 2026] [security2:error] [pid 341679:tid 341827] [client 20.151.10.161:28850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9QWAWat-noHLkDuAiIqgAAARw"]
[Tue Jul 21 07:56:24.444046 2026] [security2:error] [pid 341679:tid 341836] [client 20.151.10.161:17394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9QWAWat-noHLkDuAiIqwAAASU"]
[Tue Jul 21 07:56:24.543431 2026] [security2:error] [pid 341679:tid 341864] [client 38.100.221.102:18494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWAWat-noHLkDuAiIrQAAAUE"]
[Tue Jul 21 07:56:24.543764 2026] [security2:error] [pid 341679:tid 341864] [client 38.100.221.102:18494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWAWat-noHLkDuAiIrQAAAUE"]
[Tue Jul 21 07:56:24.820738 2026] [security2:error] [pid 341679:tid 341899] [client 74.249.245.134:5520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/xda.php"] [unique_id "al9QWAWat-noHLkDuAiIuQAAAWQ"]
[Tue Jul 21 07:56:25.050654 2026] [security2:error] [pid 341679:tid 341905] [client 20.104.96.117:62735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/iywwi.php"] [unique_id "al9QWQWat-noHLkDuAiIvgAAAWo"]
[Tue Jul 21 07:56:25.081697 2026] [security2:error] [pid 341679:tid 341840] [client 117.217.38.194:57117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWQWat-noHLkDuAiIvwAAASk"]
[Tue Jul 21 07:56:25.081795 2026] [security2:error] [pid 341679:tid 341840] [client 117.217.38.194:57117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWQWat-noHLkDuAiIvwAAASk"]
[Tue Jul 21 07:56:25.190319 2026] [security2:error] [pid 341679:tid 341870] [client 117.247.80.59:18293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWQWat-noHLkDuAiIxwAAAUc"]
[Tue Jul 21 07:56:25.190796 2026] [security2:error] [pid 341679:tid 341870] [client 117.247.80.59:18293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWQWat-noHLkDuAiIxwAAAUc"]
[Tue Jul 21 07:56:25.480866 2026] [security2:error] [pid 341679:tid 341830] [client 20.151.10.161:17375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/puc.php"] [unique_id "al9QWQWat-noHLkDuAiI1AAAAR8"]
[Tue Jul 21 07:56:25.691363 2026] [security2:error] [pid 341679:tid 341844] [client 20.104.96.117:57458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/special.php"] [unique_id "al9QWQWat-noHLkDuAiI2gAAAS0"]
[Tue Jul 21 07:56:25.718694 2026] [security2:error] [pid 341679:tid 341734] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWQWat-noHLkDuAiI3AABMDY"]
[Tue Jul 21 07:56:25.718854 2026] [security2:error] [pid 341679:tid 341847] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWQWat-noHLkDuAiI3AABMDY"]
[Tue Jul 21 07:56:25.900679 2026] [core:alert] [pid 341679:tid 341846] [client 57.141.18.92:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:56:25.916363 2026] [security2:error] [pid 341679:tid 341838] [client 20.226.60.151:59929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/mac.php"] [unique_id "al9QWQWat-noHLkDuAiI6gAAASc"]
[Tue Jul 21 07:56:25.991348 2026] [security2:error] [pid 341679:tid 341767] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWQWat-noHLkDuAiI7AABMVc"]
[Tue Jul 21 07:56:25.991584 2026] [security2:error] [pid 341679:tid 341848] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWQWat-noHLkDuAiI7AABMVc"]
[Tue Jul 21 07:56:26.076152 2026] [security2:error] [pid 341679:tid 341891] [client 20.226.60.151:61599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/yawa.php"] [unique_id "al9QWgWat-noHLkDuAiI7gAAAVw"]
[Tue Jul 21 07:56:26.149626 2026] [proxy:error] [pid 341679:tid 341699] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:56:26.149706 2026] [proxy_http:error] [pid 341679:tid 341699] [remote 198.235.24.48:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:56:26.150157 2026] [proxy:error] [pid 341679:tid 341699] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:56:26.150187 2026] [proxy_http:error] [pid 341679:tid 341699] [remote 198.235.24.48:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:56:26.190262 2026] [security2:error] [pid 341679:tid 341802] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWgWat-noHLkDuAiI8QABX3o"]
[Tue Jul 21 07:56:26.190381 2026] [security2:error] [pid 341679:tid 341894] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWgWat-noHLkDuAiI8QABX3o"]
[Tue Jul 21 07:56:26.398752 2026] [security2:error] [pid 341679:tid 341825] [client 20.104.96.117:55030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/as.php"] [unique_id "al9QWgWat-noHLkDuAiI9gAAARo"]
[Tue Jul 21 07:56:26.628959 2026] [security2:error] [pid 341679:tid 341890] [client 20.151.10.161:17289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/themes.php"] [unique_id "al9QWgWat-noHLkDuAiI_gAAAVs"]
[Tue Jul 21 07:56:26.709347 2026] [security2:error] [pid 341679:tid 341878] [client 139.167.225.182:52461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWgWat-noHLkDuAiJAQAAAU8"]
[Tue Jul 21 07:56:26.710988 2026] [security2:error] [pid 341679:tid 341878] [client 139.167.225.182:52461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWgWat-noHLkDuAiJAQAAAU8"]
[Tue Jul 21 07:56:26.789376 2026] [security2:error] [pid 341679:tid 341899] [client 223.236.153.128:2481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QWgWat-noHLkDuAiJAgAAAWQ"]
[Tue Jul 21 07:56:26.794029 2026] [security2:error] [pid 341679:tid 341899] [client 223.236.153.128:2481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QWgWat-noHLkDuAiJAgAAAWQ"]
[Tue Jul 21 07:56:27.035951 2026] [security2:error] [pid 341679:tid 341814] [client 122.162.144.145:23511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QWwWat-noHLkDuAiJCwAAAQ8"]
[Tue Jul 21 07:56:27.036065 2026] [security2:error] [pid 341679:tid 341814] [client 122.162.144.145:23511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QWwWat-noHLkDuAiJCwAAAQ8"]
[Tue Jul 21 07:56:27.043092 2026] [security2:error] [pid 341679:tid 341883] [client 20.197.192.193:54346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/mimpi.php"] [unique_id "al9QWwWat-noHLkDuAiJDAAAAVQ"]
[Tue Jul 21 07:56:27.397659 2026] [autoindex:error] [pid 341679:tid 341905] [client 20.151.10.161:0] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:27.403033 2026] [security2:error] [pid 341679:tid 341684] [remote 188.95.113.76:47358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/wp-login.php"] [unique_id "al9QWwWat-noHLkDuAiJFAABGAQ"]
[Tue Jul 21 07:56:27.503439 2026] [security2:error] [pid 341679:tid 341876] [client 172.245.102.41:26609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QWwWat-noHLkDuAiJGQAAAU0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:56:27.543828 2026] [security2:error] [pid 341679:tid 341810] [client 74.249.245.134:24817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/init.php"] [unique_id "al9QWwWat-noHLkDuAiJGgAAAQs"]
[Tue Jul 21 07:56:27.678122 2026] [security2:error] [pid 341679:tid 341900] [client 20.104.96.117:62837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/gqgsa.php"] [unique_id "al9QWwWat-noHLkDuAiJHgAAAWU"]
[Tue Jul 21 07:56:27.696367 2026] [security2:error] [pid 341679:tid 341861] [client 20.151.10.161:17377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/8.php"] [unique_id "al9QWwWat-noHLkDuAiJHwAAAT4"]
[Tue Jul 21 07:56:27.767268 2026] [security2:error] [pid 341679:tid 341857] [client 20.104.96.117:54951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9QWwWat-noHLkDuAiJIQAAATo"]
[Tue Jul 21 07:56:27.858629 2026] [security2:error] [pid 341679:tid 341908] [client 182.8.255.181:17174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QWwWat-noHLkDuAiJJQAAAW0"]
[Tue Jul 21 07:56:27.858742 2026] [security2:error] [pid 341679:tid 341908] [client 182.8.255.181:17174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QWwWat-noHLkDuAiJJQAAAW0"]
[Tue Jul 21 07:56:27.945398 2026] [security2:error] [pid 341679:tid 341930] [client 103.166.103.129:49878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QWwWat-noHLkDuAiJJwAAAYM"]
[Tue Jul 21 07:56:27.945531 2026] [security2:error] [pid 341679:tid 341930] [client 103.166.103.129:49878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QWwWat-noHLkDuAiJJwAAAYM"]
[Tue Jul 21 07:56:27.947012 2026] [security2:error] [pid 341679:tid 341838] [client 106.215.181.8:16665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWwWat-noHLkDuAiJKAAAASc"]
[Tue Jul 21 07:56:27.947116 2026] [security2:error] [pid 341679:tid 341838] [client 106.215.181.8:16665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QWwWat-noHLkDuAiJKAAAASc"]
[Tue Jul 21 07:56:28.060692 2026] [security2:error] [pid 341679:tid 341813] [client 103.78.200.11:52917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QXAWat-noHLkDuAiJLgAAAQ4"]
[Tue Jul 21 07:56:28.060802 2026] [security2:error] [pid 341679:tid 341813] [client 103.78.200.11:52917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QXAWat-noHLkDuAiJLgAAAQ4"]
[Tue Jul 21 07:56:28.221965 2026] [security2:error] [pid 341679:tid 341860] [client 20.226.60.151:56822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/output.php"] [unique_id "al9QXAWat-noHLkDuAiJMgAAAT0"]
[Tue Jul 21 07:56:28.230180 2026] [security2:error] [pid 341679:tid 341922] [client 193.36.225.107:31181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QXAWat-noHLkDuAiJLwAAAXs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:56:28.461185 2026] [security2:error] [pid 341679:tid 341865] [client 74.249.245.134:5517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/shell.php"] [unique_id "al9QXAWat-noHLkDuAiJOgAAAUI"]
[Tue Jul 21 07:56:28.722486 2026] [security2:error] [pid 341679:tid 341840] [client 20.206.105.145:55923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/aa2.php"] [unique_id "al9QXAWat-noHLkDuAiJQgAAASk"]
[Tue Jul 21 07:56:28.810553 2026] [security2:error] [pid 341679:tid 341829] [client 103.29.114.44:21732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QXAWat-noHLkDuAiJRAAAAR4"]
[Tue Jul 21 07:56:28.810675 2026] [security2:error] [pid 341679:tid 341829] [client 103.29.114.44:21732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QXAWat-noHLkDuAiJRAAAAR4"]
[Tue Jul 21 07:56:29.240119 2026] [security2:error] [pid 341679:tid 341851] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QXQWat-noHLkDuAiJTAABNGo"]
[Tue Jul 21 07:56:29.635300 2026] [security2:error] [pid 341679:tid 341884] [client 20.151.10.161:28832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/x.php"] [unique_id "al9QXQWat-noHLkDuAiJWwAAAVU"]
[Tue Jul 21 07:56:29.839862 2026] [security2:error] [pid 341679:tid 341871] [client 20.151.10.161:17291] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.bestdealsvalmir.com"] [uri "/1.php"] [unique_id "al9QXQWat-noHLkDuAiJYQAAAUg"]
[Tue Jul 21 07:56:29.839987 2026] [security2:error] [pid 341679:tid 341871] [client 20.151.10.161:17291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/1.php"] [unique_id "al9QXQWat-noHLkDuAiJYQAAAUg"]
[Tue Jul 21 07:56:29.875582 2026] [security2:error] [pid 341679:tid 341900] [client 122.186.204.214:49928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QXQWat-noHLkDuAiJYgAAAWU"]
[Tue Jul 21 07:56:29.875718 2026] [security2:error] [pid 341679:tid 341900] [client 122.186.204.214:49928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QXQWat-noHLkDuAiJYgAAAWU"]
[Tue Jul 21 07:56:29.906882 2026] [security2:error] [pid 341679:tid 341819] [client 20.104.96.117:54985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/w1px.php"] [unique_id "al9QXQWat-noHLkDuAiJYwAAARQ"]
[Tue Jul 21 07:56:30.332749 2026] [security2:error] [pid 341679:tid 341920] [client 20.104.96.117:62793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/elbzl.php"] [unique_id "al9QXgWat-noHLkDuAiJdQAAAXk"]
[Tue Jul 21 07:56:30.392720 2026] [security2:error] [pid 341679:tid 341713] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QXgWat-noHLkDuAiJdgABhyE"]
[Tue Jul 21 07:56:30.392935 2026] [security2:error] [pid 341679:tid 341934] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QXgWat-noHLkDuAiJdgABhyE"]
[Tue Jul 21 07:56:30.942625 2026] [security2:error] [pid 341679:tid 341824] [client 20.151.10.161:17326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/100.php"] [unique_id "al9QXgWat-noHLkDuAiJhgAAARk"]
[Tue Jul 21 07:56:30.965016 2026] [security2:error] [pid 341679:tid 341828] [client 136.144.33.108:47705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QXgWat-noHLkDuAiJhwAAAR0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:56:31.055462 2026] [security2:error] [pid 341679:tid 341702] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QXwWat-noHLkDuAiJiwABdxY"]
[Tue Jul 21 07:56:31.055692 2026] [security2:error] [pid 341679:tid 341918] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QXwWat-noHLkDuAiJiwABdxY"]
[Tue Jul 21 07:56:31.105844 2026] [security2:error] [pid 341679:tid 341893] [client 74.249.245.134:5548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/3.php"] [unique_id "al9QXwWat-noHLkDuAiJjAAAAV4"]
[Tue Jul 21 07:56:31.131074 2026] [security2:error] [pid 341679:tid 341833] [client 20.226.60.151:61609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/js.php"] [unique_id "al9QXwWat-noHLkDuAiJjQAAASI"]
[Tue Jul 21 07:56:31.161902 2026] [security2:error] [pid 341679:tid 341840] [client 122.179.91.63:22660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QXwWat-noHLkDuAiJjwAAASk"]
[Tue Jul 21 07:56:31.162030 2026] [security2:error] [pid 341679:tid 341840] [client 122.179.91.63:22660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QXwWat-noHLkDuAiJjwAAASk"]
[Tue Jul 21 07:56:31.164574 2026] [security2:error] [pid 341679:tid 341889] [client 102.206.115.33:60726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QXwWat-noHLkDuAiJkAAAAVo"]
[Tue Jul 21 07:56:31.164650 2026] [security2:error] [pid 341679:tid 341889] [client 102.206.115.33:60726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QXwWat-noHLkDuAiJkAAAAVo"]
[Tue Jul 21 07:56:31.462723 2026] [security2:error] [pid 341679:tid 341739] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QXwWat-noHLkDuAiJmgABPTs"]
[Tue Jul 21 07:56:31.462873 2026] [security2:error] [pid 341679:tid 341860] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QXwWat-noHLkDuAiJmgABPTs"]
[Tue Jul 21 07:56:31.469630 2026] [security2:error] [pid 341679:tid 341846] [client 20.104.96.117:46446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/adjig.php"] [unique_id "al9QXwWat-noHLkDuAiJnwAAAS8"]
[Tue Jul 21 07:56:31.470045 2026] [security2:error] [pid 341679:tid 341841] [client 20.226.60.151:56806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-file-120.php"] [unique_id "al9QXwWat-noHLkDuAiJoAAAASo"]
[Tue Jul 21 07:56:31.619519 2026] [security2:error] [pid 341679:tid 341825] [client 41.68.90.219:60727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QXwWat-noHLkDuAiJogAAARo"]
[Tue Jul 21 07:56:31.620626 2026] [security2:error] [pid 341679:tid 341825] [client 41.68.90.219:60727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QXwWat-noHLkDuAiJogAAARo"]
[Tue Jul 21 07:56:31.743369 2026] [security2:error] [pid 341679:tid 341863] [client 37.140.223.200:45207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QXgWat-noHLkDuAiJewAAAUA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:56:31.768377 2026] [security2:error] [pid 341679:tid 341935] [client 20.104.96.117:55035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/yawa.php"] [unique_id "al9QXwWat-noHLkDuAiJqQAAAYg"]
[Tue Jul 21 07:56:31.921560 2026] [security2:error] [pid 341679:tid 341839] [client 204.8.98.45:34754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9QXwWat-noHLkDuAiJrQAAASg"]
[Tue Jul 21 07:56:31.921647 2026] [security2:error] [pid 341679:tid 341839] [client 204.8.98.45:34754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9QXwWat-noHLkDuAiJrQAAASg"]
[Tue Jul 21 07:56:31.993408 2026] [security2:error] [pid 341679:tid 341919] [client 20.104.96.117:62753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/byp.php"] [unique_id "al9QXwWat-noHLkDuAiJrwAAAXg"]
[Tue Jul 21 07:56:32.278356 2026] [security2:error] [pid 341679:tid 341848] [client 65.21.113.253:53724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QXwWat-noHLkDuAiJqgAAATE"]
[Tue Jul 21 07:56:32.307116 2026] [security2:error] [pid 341679:tid 341906] [client 103.86.117.203:65133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QYAWat-noHLkDuAiJvAAAAWs"]
[Tue Jul 21 07:56:32.307242 2026] [security2:error] [pid 341679:tid 341906] [client 103.86.117.203:65133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QYAWat-noHLkDuAiJvAAAAWs"]
[Tue Jul 21 07:56:32.322839 2026] [security2:error] [pid 341679:tid 341887] [client 122.164.127.47:52379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QYAWat-noHLkDuAiJvgAAAVg"]
[Tue Jul 21 07:56:32.323000 2026] [security2:error] [pid 341679:tid 341887] [client 122.164.127.47:52379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QYAWat-noHLkDuAiJvgAAAVg"]
[Tue Jul 21 07:56:32.344546 2026] [security2:error] [pid 341679:tid 341865] [client 117.210.135.0:64587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QYAWat-noHLkDuAiJtQAAAUI"]
[Tue Jul 21 07:56:32.417688 2026] [security2:error] [pid 341679:tid 341849] [client 92.119.178.3:34394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9QYAWat-noHLkDuAiJwAAAATI"]
[Tue Jul 21 07:56:32.417781 2026] [security2:error] [pid 341679:tid 341849] [client 92.119.178.3:34394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9QYAWat-noHLkDuAiJwAAAATI"]
[Tue Jul 21 07:56:32.745149 2026] [security2:error] [pid 341679:tid 341858] [client 74.249.245.134:5554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/mds.php"] [unique_id "al9QYAWat-noHLkDuAiJzwAAATs"]
[Tue Jul 21 07:56:32.757678 2026] [security2:error] [pid 341679:tid 341895] [client 20.206.105.145:55893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/ccou.php"] [unique_id "al9QYAWat-noHLkDuAiJ0AAAAWA"]
[Tue Jul 21 07:56:32.878340 2026] [security2:error] [pid 341679:tid 341821] [client 20.226.60.151:60027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/mg.php"] [unique_id "al9QYAWat-noHLkDuAiJ1QAAARY"]
[Tue Jul 21 07:56:32.934555 2026] [security2:error] [pid 341679:tid 341879] [client 20.151.10.161:17401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/about.php"] [unique_id "al9QYAWat-noHLkDuAiJ1wAAAVA"]
[Tue Jul 21 07:56:32.949471 2026] [security2:error] [pid 341679:tid 341869] [client 45.3.38.31:18515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.38.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QYAWat-noHLkDuAiJ0QAAAUY"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:56:33.023692 2026] [security2:error] [pid 341679:tid 341698] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QYQWat-noHLkDuAiJ2QABVRI"]
[Tue Jul 21 07:56:33.023895 2026] [security2:error] [pid 341679:tid 341884] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QYQWat-noHLkDuAiJ2QABVRI"]
[Tue Jul 21 07:56:33.049661 2026] [security2:error] [pid 341679:tid 341813] [client 109.60.28.94:57138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QYQWat-noHLkDuAiJ3AAAAQ4"]
[Tue Jul 21 07:56:33.050463 2026] [security2:error] [pid 341679:tid 341813] [client 109.60.28.94:57138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QYQWat-noHLkDuAiJ3AAAAQ4"]
[Tue Jul 21 07:56:33.089028 2026] [security2:error] [pid 341679:tid 341935] [client 92.119.178.3:54024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9QYQWat-noHLkDuAiJ4AAAAYg"]
[Tue Jul 21 07:56:33.089123 2026] [security2:error] [pid 341679:tid 341935] [client 92.119.178.3:54024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9QYQWat-noHLkDuAiJ4AAAAYg"]
[Tue Jul 21 07:56:33.310988 2026] [security2:error] [pid 341679:tid 341801] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QYQWat-noHLkDuAiJ4QABcnk"]
[Tue Jul 21 07:56:33.311155 2026] [security2:error] [pid 341679:tid 341913] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QYQWat-noHLkDuAiJ4QABcnk"]
[Tue Jul 21 07:56:33.318561 2026] [security2:error] [pid 341679:tid 341902] [client 20.104.96.117:46402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9QYQWat-noHLkDuAiJ4gAAAWc"]
[Tue Jul 21 07:56:33.613527 2026] [security2:error] [pid 341679:tid 341848] [client 20.151.10.161:17286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/about.php"] [unique_id "al9QYQWat-noHLkDuAiJ7wAAATE"]
[Tue Jul 21 07:56:33.955429 2026] [security2:error] [pid 341679:tid 341925] [client 20.104.96.117:62788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/classwithtostring.php"] [unique_id "al9QYQWat-noHLkDuAiJ-wAAAX4"]
[Tue Jul 21 07:56:33.997945 2026] [security2:error] [pid 341679:tid 341823] [client 20.151.10.161:17381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/admin.php"] [unique_id "al9QYQWat-noHLkDuAiJ_QAAARg"]
[Tue Jul 21 07:56:34.244700 2026] [security2:error] [pid 341679:tid 341895] [client 74.249.245.134:5531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/archive.php"] [unique_id "al9QYgWat-noHLkDuAiKAwAAAWA"]
[Tue Jul 21 07:56:34.316003 2026] [security2:error] [pid 341679:tid 341887] [client 202.143.127.214:53436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QYgWat-noHLkDuAiKBAAAAVg"]
[Tue Jul 21 07:56:34.316132 2026] [security2:error] [pid 341679:tid 341887] [client 202.143.127.214:53436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QYgWat-noHLkDuAiKBAAAAVg"]
[Tue Jul 21 07:56:34.415099 2026] [security2:error] [pid 341679:tid 341911] [client 151.123.178.61:62917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.178.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QYgWat-noHLkDuAiKCQAAAXA"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:56:34.567591 2026] [security2:error] [pid 341679:tid 341772] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QYgWat-noHLkDuAiKDQABDlw"]
[Tue Jul 21 07:56:34.567741 2026] [security2:error] [pid 341679:tid 341813] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QYgWat-noHLkDuAiKDQABDlw"]
[Tue Jul 21 07:56:34.613385 2026] [fcgid:warn] [pid 341679:tid 341863] (70014)End of file found: [client 66.132.172.47:44168] mod_fcgid: can't get data from http client
[Tue Jul 21 07:56:34.616725 2026] [proxy:error] [pid 341679:tid 341680] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:56:34.616761 2026] [proxy_http:error] [pid 341679:tid 341680] [remote 205.210.31.32:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:56:34.617244 2026] [proxy:error] [pid 341679:tid 341680] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:56:34.617273 2026] [proxy_http:error] [pid 341679:tid 341680] [remote 205.210.31.32:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:56:34.698190 2026] [security2:error] [pid 341679:tid 341935] [client 20.226.60.151:50507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/special.php"] [unique_id "al9QYgWat-noHLkDuAiKEgAAAYg"]
[Tue Jul 21 07:56:34.733789 2026] [security2:error] [pid 341679:tid 341876] [client 20.104.96.117:62829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/root.php"] [unique_id "al9QYgWat-noHLkDuAiKEwAAAU0"]
[Tue Jul 21 07:56:34.846427 2026] [security2:error] [pid 341679:tid 341811] [client 136.144.33.98:22417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QYgWat-noHLkDuAiKGQAAAQw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:56:34.945993 2026] [security2:error] [pid 341679:tid 341900] [client 178.153.91.96:1097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QYgWat-noHLkDuAiKIgAAAWU"]
[Tue Jul 21 07:56:34.946151 2026] [security2:error] [pid 341679:tid 341900] [client 178.153.91.96:1097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QYgWat-noHLkDuAiKIgAAAWU"]
[Tue Jul 21 07:56:34.975500 2026] [security2:error] [pid 341679:tid 341933] [client 20.151.10.161:17301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/admin.php"] [unique_id "al9QYgWat-noHLkDuAiKJAAAAYY"]
[Tue Jul 21 07:56:35.039467 2026] [security2:error] [pid 341679:tid 341878] [client 204.8.98.45:57458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9QYwWat-noHLkDuAiKKAAAAU8"]
[Tue Jul 21 07:56:35.039558 2026] [security2:error] [pid 341679:tid 341878] [client 204.8.98.45:57458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9QYwWat-noHLkDuAiKKAAAAU8"]
[Tue Jul 21 07:56:35.158578 2026] [security2:error] [pid 341679:tid 341922] [client 20.104.96.117:62807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/sym403.php"] [unique_id "al9QYwWat-noHLkDuAiKKQAAAXs"]
[Tue Jul 21 07:56:35.172334 2026] [security2:error] [pid 341679:tid 341884] [client 38.100.221.102:19007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QYwWat-noHLkDuAiKKwAAAVU"]
[Tue Jul 21 07:56:35.172456 2026] [security2:error] [pid 341679:tid 341884] [client 38.100.221.102:19007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QYwWat-noHLkDuAiKKwAAAVU"]
[Tue Jul 21 07:56:35.287802 2026] [security2:error] [pid 341679:tid 341920] [client 65.21.113.253:53724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QYgWat-noHLkDuAiKFwAAAXk"]
[Tue Jul 21 07:56:35.524252 2026] [security2:error] [pid 341679:tid 341847] [client 20.104.96.117:46400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/v543.php"] [unique_id "al9QYwWat-noHLkDuAiKOwAAATA"]
[Tue Jul 21 07:56:35.571542 2026] [security2:error] [pid 341679:tid 341836] [client 117.217.38.194:57464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.38.217.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QYwWat-noHLkDuAiKPQAAASU"]
[Tue Jul 21 07:56:35.571684 2026] [security2:error] [pid 341679:tid 341836] [client 117.217.38.194:57464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QYwWat-noHLkDuAiKPQAAASU"]
[Tue Jul 21 07:56:35.617127 2026] [security2:error] [pid 341679:tid 341921] [client 104.207.43.98:60049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.43.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QYwWat-noHLkDuAiKOgAAAXo"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:56:35.618850 2026] [security2:error] [pid 341679:tid 341891] [client 74.249.245.134:5534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/amax.php"] [unique_id "al9QYwWat-noHLkDuAiKQQAAAVw"]
[Tue Jul 21 07:56:35.679553 2026] [security2:error] [pid 341679:tid 341849] [client 59.93.4.33:59665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QYwWat-noHLkDuAiKQwAAATI"]
[Tue Jul 21 07:56:35.679704 2026] [security2:error] [pid 341679:tid 341849] [client 59.93.4.33:59665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QYwWat-noHLkDuAiKQwAAATI"]
[Tue Jul 21 07:56:35.714055 2026] [security2:error] [pid 341679:tid 341909] [client 65.21.113.253:36296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QYwWat-noHLkDuAiKRAAAAW4"]
[Tue Jul 21 07:56:35.734304 2026] [security2:error] [pid 341679:tid 341853] [client 117.247.80.59:18789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QYwWat-noHLkDuAiKRQAAATY"]
[Tue Jul 21 07:56:35.734426 2026] [security2:error] [pid 341679:tid 341853] [client 117.247.80.59:18789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QYwWat-noHLkDuAiKRQAAATY"]
[Tue Jul 21 07:56:35.926236 2026] [authz_core:error] [pid 341679:tid 341862] [client 74.249.245.134:0] AH01630: client denied by server configuration: /home2/andr8586/public_html/php.ini
[Tue Jul 21 07:56:35.963371 2026] [security2:error] [pid 341679:tid 341934] [client 20.104.96.117:62723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/sixxis.php"] [unique_id "al9QYwWat-noHLkDuAiKUgAAAYc"]
[Tue Jul 21 07:56:36.066744 2026] [security2:error] [pid 341679:tid 341931] [client 74.249.245.134:64086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/settings.php"] [unique_id "al9QZAWat-noHLkDuAiKVQAAAYQ"]
[Tue Jul 21 07:56:36.139293 2026] [security2:error] [pid 341679:tid 341918] [client 20.151.10.161:17361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/edit.php"] [unique_id "al9QZAWat-noHLkDuAiKVwAAAXc"]
[Tue Jul 21 07:56:36.183931 2026] [security2:error] [pid 341679:tid 341831] [client 20.206.105.145:28619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/dr.php"] [unique_id "al9QZAWat-noHLkDuAiKWQAAASA"]
[Tue Jul 21 07:56:36.253972 2026] [security2:error] [pid 341679:tid 341874] [client 20.151.10.161:29102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/j260624_13.php"] [unique_id "al9QZAWat-noHLkDuAiKWgAAAUs"]
[Tue Jul 21 07:56:36.307946 2026] [security2:error] [pid 341679:tid 341868] [client 65.21.113.253:53724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QYwWat-noHLkDuAiKTwAAAUU"]
[Tue Jul 21 07:56:36.309133 2026] [security2:error] [pid 341679:tid 341693] [remote 154.61.75.100:57408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fremetexlondrina.com.br"] [uri "/wp-login.php"] [unique_id "al9QZAWat-noHLkDuAiKXAABUQ0"]
[Tue Jul 21 07:56:36.401372 2026] [security2:error] [pid 341679:tid 341860] [client 20.104.96.117:46357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ip.php"] [unique_id "al9QZAWat-noHLkDuAiKZAAAAT0"]
[Tue Jul 21 07:56:36.542133 2026] [security2:error] [pid 341679:tid 341709] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZAWat-noHLkDuAiKaAABJB0"]
[Tue Jul 21 07:56:36.542262 2026] [security2:error] [pid 341679:tid 341835] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZAWat-noHLkDuAiKaAABJB0"]
[Tue Jul 21 07:56:36.679897 2026] [security2:error] [pid 341679:tid 341800] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZAWat-noHLkDuAiKbgABTng"]
[Tue Jul 21 07:56:36.680069 2026] [security2:error] [pid 341679:tid 341877] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZAWat-noHLkDuAiKbgABTng"]
[Tue Jul 21 07:56:36.746827 2026] [security2:error] [pid 341679:tid 341863] [client 20.151.10.161:17293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wp-content/admin.php"] [unique_id "al9QZAWat-noHLkDuAiKcQAAAUA"]
[Tue Jul 21 07:56:36.789092 2026] [security2:error] [pid 341679:tid 341936] [client 20.104.96.117:62791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/kq1.php"] [unique_id "al9QZAWat-noHLkDuAiKcgAAAYk"]
[Tue Jul 21 07:56:36.904089 2026] [security2:error] [pid 341679:tid 341690] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZAWat-noHLkDuAiKdgABDwo"]
[Tue Jul 21 07:56:36.904228 2026] [security2:error] [pid 341679:tid 341814] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZAWat-noHLkDuAiKdgABDwo"]
[Tue Jul 21 07:56:36.964308 2026] [security2:error] [pid 341679:tid 341872] [client 74.249.245.134:17424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/moon.php"] [unique_id "al9QZAWat-noHLkDuAiKeQAAAUk"]
[Tue Jul 21 07:56:37.032764 2026] [security2:error] [pid 341679:tid 341848] [client 204.8.98.45:57466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9QZQWat-noHLkDuAiKggAAATE"]
[Tue Jul 21 07:56:37.032875 2026] [security2:error] [pid 341679:tid 341848] [client 204.8.98.45:57466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9QZQWat-noHLkDuAiKggAAATE"]
[Tue Jul 21 07:56:37.120046 2026] [security2:error] [pid 341679:tid 341930] [client 20.104.96.117:62832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9QZQWat-noHLkDuAiKhwAAAYM"]
[Tue Jul 21 07:56:37.260083 2026] [security2:error] [pid 341679:tid 341845] [client 139.167.225.182:53120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZQWat-noHLkDuAiKigAAAS4"]
[Tue Jul 21 07:56:37.260243 2026] [security2:error] [pid 341679:tid 341845] [client 139.167.225.182:53120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZQWat-noHLkDuAiKigAAAS4"]
[Tue Jul 21 07:56:37.274057 2026] [security2:error] [pid 341679:tid 341904] [client 20.151.10.161:17368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/f6.php"] [unique_id "al9QZQWat-noHLkDuAiKiwAAAWk"]
[Tue Jul 21 07:56:37.289770 2026] [security2:error] [pid 341679:tid 341740] [remote 188.95.113.76:39168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bellascleaningsolutionsllc.com"] [uri "/wp-login.php"] [unique_id "al9QZQWat-noHLkDuAiKjQABiDw"]
[Tue Jul 21 07:56:37.567096 2026] [security2:error] [pid 341679:tid 341836] [client 223.236.153.128:7065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QZQWat-noHLkDuAiKlwAAASU"]
[Tue Jul 21 07:56:37.567226 2026] [security2:error] [pid 341679:tid 341836] [client 223.236.153.128:7065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QZQWat-noHLkDuAiKlwAAASU"]
[Tue Jul 21 07:56:37.611953 2026] [security2:error] [pid 341679:tid 341895] [client 20.104.96.117:62811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/h02ugyh.php"] [unique_id "al9QZQWat-noHLkDuAiKmQAAAWA"]
[Tue Jul 21 07:56:37.651357 2026] [security2:error] [pid 341679:tid 341883] [client 204.8.98.45:34762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9QZQWat-noHLkDuAiKmgAAAVQ"]
[Tue Jul 21 07:56:37.651448 2026] [security2:error] [pid 341679:tid 341883] [client 204.8.98.45:34762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9QZQWat-noHLkDuAiKmgAAAVQ"]
[Tue Jul 21 07:56:37.760391 2026] [security2:error] [pid 341679:tid 341819] [client 20.104.96.117:57766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/js.php"] [unique_id "al9QZQWat-noHLkDuAiKngAAARQ"]
[Tue Jul 21 07:56:37.835706 2026] [security2:error] [pid 341679:tid 341832] [client 122.162.144.145:3995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QZQWat-noHLkDuAiKoAAAASE"]
[Tue Jul 21 07:56:37.838115 2026] [security2:error] [pid 341679:tid 341832] [client 122.162.144.145:3995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QZQWat-noHLkDuAiKoAAAASE"]
[Tue Jul 21 07:56:37.853358 2026] [security2:error] [pid 341679:tid 341850] [client 20.151.10.161:29092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/d62.php"] [unique_id "al9QZQWat-noHLkDuAiKoQAAATM"]
[Tue Jul 21 07:56:37.924377 2026] [security2:error] [pid 341679:tid 341854] [client 20.151.10.161:17396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/inputs.php"] [unique_id "al9QZQWat-noHLkDuAiKpQAAATc"]
[Tue Jul 21 07:56:37.978341 2026] [security2:error] [pid 341679:tid 341863] [client 74.249.245.134:5526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/ws83.php"] [unique_id "al9QZQWat-noHLkDuAiKpgAAAUA"]
[Tue Jul 21 07:56:38.006042 2026] [security2:error] [pid 341679:tid 341813] [client 74.249.245.134:24798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/g.php"] [unique_id "al9QZgWat-noHLkDuAiKqAAAAQ4"]
[Tue Jul 21 07:56:38.137759 2026] [security2:error] [pid 341679:tid 341821] [client 20.226.60.151:61555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/core.php"] [unique_id "al9QZgWat-noHLkDuAiKrAAAARY"]
[Tue Jul 21 07:56:38.176563 2026] [security2:error] [pid 341679:tid 341921] [client 20.104.96.117:62722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-temp.php"] [unique_id "al9QZgWat-noHLkDuAiKrQAAAXo"]
[Tue Jul 21 07:56:38.244951 2026] [security2:error] [pid 341679:tid 341902] [client 20.151.10.161:17323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/inputs.php"] [unique_id "al9QZgWat-noHLkDuAiKrwAAAWc"]
[Tue Jul 21 07:56:38.250301 2026] [security2:error] [pid 341679:tid 341870] [client 182.8.255.181:21058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QZgWat-noHLkDuAiKsAAAAUc"]
[Tue Jul 21 07:56:38.250416 2026] [security2:error] [pid 341679:tid 341870] [client 182.8.255.181:21058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QZgWat-noHLkDuAiKsAAAAUc"]
[Tue Jul 21 07:56:38.341747 2026] [security2:error] [pid 341679:tid 341858] [client 106.215.181.8:10167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZgWat-noHLkDuAiKsgAAATs"]
[Tue Jul 21 07:56:38.341871 2026] [security2:error] [pid 341679:tid 341858] [client 106.215.181.8:10167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZgWat-noHLkDuAiKsgAAATs"]
[Tue Jul 21 07:56:38.361010 2026] [security2:error] [pid 341679:tid 341919] [client 74.249.245.134:5564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/CDX1.php"] [unique_id "al9QZgWat-noHLkDuAiKtQAAAXg"]
[Tue Jul 21 07:56:38.436027 2026] [security2:error] [pid 341679:tid 341827] [client 193.36.225.57:53285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QZgWat-noHLkDuAiKuQAAARw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:56:38.706441 2026] [security2:error] [pid 341679:tid 341823] [client 20.226.60.151:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-post-data.php"] [unique_id "al9QZgWat-noHLkDuAiKwQAAARg"]
[Tue Jul 21 07:56:38.770546 2026] [security2:error] [pid 341679:tid 341913] [client 103.166.103.129:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QZgWat-noHLkDuAiKxgAAAXI"]
[Tue Jul 21 07:56:38.771380 2026] [security2:error] [pid 341679:tid 341913] [client 103.166.103.129:52872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QZgWat-noHLkDuAiKxgAAAXI"]
[Tue Jul 21 07:56:38.797423 2026] [security2:error] [pid 341679:tid 341909] [client 103.78.200.11:53378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZgWat-noHLkDuAiKyAAAAW4"]
[Tue Jul 21 07:56:38.821182 2026] [security2:error] [pid 341679:tid 341909] [client 103.78.200.11:53378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZgWat-noHLkDuAiKyAAAAW4"]
[Tue Jul 21 07:56:38.868082 2026] [security2:error] [pid 341679:tid 341889] [client 20.104.96.117:62734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9QZgWat-noHLkDuAiKyQAAAVo"]
[Tue Jul 21 07:56:38.917053 2026] [security2:error] [pid 341679:tid 341895] [client 20.151.10.161:17379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/av.php"] [unique_id "al9QZgWat-noHLkDuAiKygAAAWA"]
[Tue Jul 21 07:56:38.942838 2026] [security2:error] [pid 341679:tid 341898] [client 20.151.10.161:28859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/ups.php"] [unique_id "al9QZgWat-noHLkDuAiKywAAAWM"]
[Tue Jul 21 07:56:38.965699 2026] [autoindex:error] [pid 341679:tid 341835] [client 66.132.172.47:44170] AH01276: Cannot serve directory /home1/imperd48/clickedbought.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:39.014910 2026] [security2:error] [pid 341679:tid 341850] [client 20.104.96.117:57420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/core.php"] [unique_id "al9QZwWat-noHLkDuAiK0AAAATM"]
[Tue Jul 21 07:56:39.135425 2026] [security2:error] [pid 341679:tid 341864] [client 20.206.105.145:55851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/file31.php"] [unique_id "al9QZwWat-noHLkDuAiK1QAAAUE"]
[Tue Jul 21 07:56:39.216175 2026] [security2:error] [pid 341679:tid 341869] [client 74.249.245.134:5527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/inputs.php"] [unique_id "al9QZwWat-noHLkDuAiK2QAAAUY"]
[Tue Jul 21 07:56:39.367339 2026] [security2:error] [pid 341679:tid 341921] [client 20.151.10.161:17304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/classwithtostring.php"] [unique_id "al9QZwWat-noHLkDuAiK3wAAAXo"]
[Tue Jul 21 07:56:39.425421 2026] [security2:error] [pid 341679:tid 341839] [client 20.104.96.117:46366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9QZwWat-noHLkDuAiK4AAAASg"]
[Tue Jul 21 07:56:39.435641 2026] [security2:error] [pid 341679:tid 341903] [client 74.7.228.20:55766] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.liranesuliano.com.br"] [uri "/robots.txt"] [unique_id "al9QZwWat-noHLkDuAiK4gABaBo"]
[Tue Jul 21 07:56:39.435740 2026] [security2:error] [pid 341679:tid 341837] [client 103.29.114.44:5580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZwWat-noHLkDuAiK4wAAASY"]
[Tue Jul 21 07:56:39.435880 2026] [security2:error] [pid 341679:tid 341837] [client 103.29.114.44:5580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZwWat-noHLkDuAiK4wAAASY"]
[Tue Jul 21 07:56:39.508005 2026] [security2:error] [pid 341679:tid 341853] [client 20.226.60.151:50567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/as.php"] [unique_id "al9QZwWat-noHLkDuAiK5QAAATY"]
[Tue Jul 21 07:56:39.764614 2026] [security2:error] [pid 341679:tid 341878] [client 20.104.96.117:46407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/jj.php"] [unique_id "al9QZwWat-noHLkDuAiK7gAAAU8"]
[Tue Jul 21 07:56:39.794050 2026] [security2:error] [pid 341679:tid 341861] [client 20.151.10.161:17372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9QZwWat-noHLkDuAiK8AAAAT4"]
[Tue Jul 21 07:56:39.865590 2026] [security2:error] [pid 341679:tid 341811] [client 20.151.10.161:28824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/k.php"] [unique_id "al9QZwWat-noHLkDuAiK8gAAAQw"]
[Tue Jul 21 07:56:40.054067 2026] [security2:error] [pid 341679:tid 341913] [client 20.104.96.117:62729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9QaAWat-noHLkDuAiK-AAAAXI"]
[Tue Jul 21 07:56:40.138630 2026] [security2:error] [pid 341679:tid 341842] [client 20.151.10.161:17347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wp-blog.php"] [unique_id "al9QaAWat-noHLkDuAiK_gAAASs"]
[Tue Jul 21 07:56:40.166480 2026] [security2:error] [pid 341679:tid 341831] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QZwWat-noHLkDuAiK8wABIGk"]
[Tue Jul 21 07:56:40.494362 2026] [security2:error] [pid 341679:tid 341822] [client 20.104.96.117:62827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/txets.php"] [unique_id "al9QaAWat-noHLkDuAiLBwAAARc"]
[Tue Jul 21 07:56:40.566971 2026] [security2:error] [pid 341679:tid 341936] [client 20.104.96.117:54934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/19.php"] [unique_id "al9QaAWat-noHLkDuAiLCAAAAYk"]
[Tue Jul 21 07:56:40.598705 2026] [autoindex:error] [pid 341679:tid 341814] [client 20.151.10.161:0] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:40.609783 2026] [security2:error] [pid 341679:tid 341701] [remote 45.3.54.194:37461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9QZwWat-noHLkDuAiK7AABfRU"]
[Tue Jul 21 07:56:40.638906 2026] [security2:error] [pid 341679:tid 341874] [client 122.186.204.214:50473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QaAWat-noHLkDuAiLDAAAAUs"]
[Tue Jul 21 07:56:40.639033 2026] [security2:error] [pid 341679:tid 341874] [client 122.186.204.214:50473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QaAWat-noHLkDuAiLDAAAAUs"]
[Tue Jul 21 07:56:40.643362 2026] [security2:error] [pid 341679:tid 341857] [client 37.140.223.117:58127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QZwWat-noHLkDuAiK5AAAATo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:56:40.696438 2026] [security2:error] [pid 341679:tid 341923] [client 20.151.10.161:28844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/k2.php"] [unique_id "al9QaAWat-noHLkDuAiLEAAAAXw"]
[Tue Jul 21 07:56:40.816571 2026] [security2:error] [pid 341679:tid 341870] [client 92.119.178.3:35838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9QaAWat-noHLkDuAiLFgAAAUc"]
[Tue Jul 21 07:56:40.816679 2026] [security2:error] [pid 341679:tid 341870] [client 92.119.178.3:35838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9QaAWat-noHLkDuAiLFgAAAUc"]
[Tue Jul 21 07:56:40.825910 2026] [security2:error] [pid 341679:tid 341890] [client 20.104.96.117:62798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/dex.php"] [unique_id "al9QaAWat-noHLkDuAiLFwAAAVs"]
[Tue Jul 21 07:56:40.869494 2026] [security2:error] [pid 341679:tid 341853] [client 20.151.10.161:17316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wp-content/admin.php"] [unique_id "al9QaAWat-noHLkDuAiLGQAAATY"]
[Tue Jul 21 07:56:41.015725 2026] [security2:error] [pid 341679:tid 341827] [client 20.197.192.193:54618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/dp.php"] [unique_id "al9QaQWat-noHLkDuAiLHQAAARw"]
[Tue Jul 21 07:56:41.116227 2026] [security2:error] [pid 341679:tid 341698] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QaQWat-noHLkDuAiLIQABIxI"]
[Tue Jul 21 07:56:41.116371 2026] [security2:error] [pid 341679:tid 341834] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QaQWat-noHLkDuAiLIQABIxI"]
[Tue Jul 21 07:56:41.124386 2026] [security2:error] [pid 341679:tid 341896] [client 20.206.105.145:55848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/file6.php"] [unique_id "al9QaQWat-noHLkDuAiLIgAAAWE"]
[Tue Jul 21 07:56:41.197422 2026] [security2:error] [pid 341679:tid 341880] [client 20.104.96.117:62728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/xpwer1.php"] [unique_id "al9QaQWat-noHLkDuAiLKAAAAVE"]
[Tue Jul 21 07:56:41.403996 2026] [security2:error] [pid 341679:tid 341825] [client 20.151.10.161:28812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/k3.php"] [unique_id "al9QaQWat-noHLkDuAiLKwAAARo"]
[Tue Jul 21 07:56:41.470428 2026] [security2:error] [pid 341679:tid 341832] [client 74.249.245.134:8769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/403.php"] [unique_id "al9QaQWat-noHLkDuAiLLQAAASE"]
[Tue Jul 21 07:56:41.527843 2026] [security2:error] [pid 341679:tid 341854] [client 20.104.96.117:62812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/flox.php"] [unique_id "al9QaQWat-noHLkDuAiLMgAAATc"]
[Tue Jul 21 07:56:41.660730 2026] [security2:error] [pid 341679:tid 341922] [client 20.151.10.161:17399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/adminfuns.php"] [unique_id "al9QaQWat-noHLkDuAiLNAAAAXs"]
[Tue Jul 21 07:56:41.663492 2026] [security2:error] [pid 341679:tid 341907] [client 102.206.115.33:60879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QaQWat-noHLkDuAiLNQAAAWw"]
[Tue Jul 21 07:56:41.663611 2026] [security2:error] [pid 341679:tid 341907] [client 102.206.115.33:60879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QaQWat-noHLkDuAiLNQAAAWw"]
[Tue Jul 21 07:56:41.771311 2026] [security2:error] [pid 341679:tid 341894] [client 74.249.245.134:5559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/ms-edit.php"] [unique_id "al9QaQWat-noHLkDuAiLPQAAAV8"]
[Tue Jul 21 07:56:41.802324 2026] [security2:error] [pid 341679:tid 341930] [client 20.151.10.161:29088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/k4.php"] [unique_id "al9QaQWat-noHLkDuAiLPgAAAYM"]
[Tue Jul 21 07:56:41.840354 2026] [security2:error] [pid 341679:tid 341820] [client 20.104.96.117:46414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/popo.php"] [unique_id "al9QaQWat-noHLkDuAiLPwAAARU"]
[Tue Jul 21 07:56:41.871902 2026] [security2:error] [pid 341679:tid 341796] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QaQWat-noHLkDuAiLQQABMHQ"]
[Tue Jul 21 07:56:41.872018 2026] [security2:error] [pid 341679:tid 341847] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QaQWat-noHLkDuAiLQQABMHQ"]
[Tue Jul 21 07:56:42.152522 2026] [security2:error] [pid 341679:tid 341811] [client 20.151.10.161:17295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/goods.php"] [unique_id "al9QagWat-noHLkDuAiLSAAAAQw"]
[Tue Jul 21 07:56:42.155152 2026] [security2:error] [pid 341679:tid 341812] [client 20.104.96.117:46409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/yas.php"] [unique_id "al9QagWat-noHLkDuAiLSQAAAQ0"]
[Tue Jul 21 07:56:42.182866 2026] [security2:error] [pid 341679:tid 341823] [client 20.151.10.161:28825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/k5.php"] [unique_id "al9QagWat-noHLkDuAiLSgAAARg"]
[Tue Jul 21 07:56:42.357249 2026] [security2:error] [pid 341679:tid 341828] [client 65.21.113.253:40882] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QagWat-noHLkDuAiLUQAAAR0"]
[Tue Jul 21 07:56:42.453779 2026] [security2:error] [pid 341679:tid 341831] [client 20.104.96.117:57785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/inc.php"] [unique_id "al9QagWat-noHLkDuAiLUwAAASA"]
[Tue Jul 21 07:56:42.479216 2026] [security2:error] [pid 341679:tid 341819] [client 20.226.60.151:60023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/pucci.php"] [unique_id "al9QagWat-noHLkDuAiLWQAAARQ"]
[Tue Jul 21 07:56:42.556654 2026] [security2:error] [pid 341679:tid 341765] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QagWat-noHLkDuAiLWwABVFU"]
[Tue Jul 21 07:56:42.556859 2026] [security2:error] [pid 341679:tid 341883] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QagWat-noHLkDuAiLWwABVFU"]
[Tue Jul 21 07:56:42.562642 2026] [security2:error] [pid 341679:tid 341850] [client 20.104.96.117:62762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file61.php"] [unique_id "al9QagWat-noHLkDuAiLXAAAATM"]
[Tue Jul 21 07:56:42.646294 2026] [security2:error] [pid 341679:tid 341899] [client 20.151.10.161:29069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/w.php"] [unique_id "al9QagWat-noHLkDuAiLXwAAAWQ"]
[Tue Jul 21 07:56:42.712056 2026] [security2:error] [pid 341679:tid 341864] [client 20.151.10.161:17351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/ms-edit.php"] [unique_id "al9QagWat-noHLkDuAiLYgAAAUE"]
[Tue Jul 21 07:56:42.787394 2026] [security2:error] [pid 341679:tid 341896] [client 103.86.117.203:49292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QagWat-noHLkDuAiLaQAAAWE"]
[Tue Jul 21 07:56:42.787521 2026] [security2:error] [pid 341679:tid 341896] [client 103.86.117.203:49292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QagWat-noHLkDuAiLaQAAAWE"]
[Tue Jul 21 07:56:42.849304 2026] [security2:error] [pid 341679:tid 341915] [client 122.179.91.63:16991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QagWat-noHLkDuAiLagAAAXQ"]
[Tue Jul 21 07:56:42.849422 2026] [security2:error] [pid 341679:tid 341915] [client 122.179.91.63:16991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QagWat-noHLkDuAiLagAAAXQ"]
[Tue Jul 21 07:56:42.920932 2026] [security2:error] [pid 341679:tid 341880] [client 122.164.127.47:52961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QagWat-noHLkDuAiLbQAAAVE"]
[Tue Jul 21 07:56:42.921039 2026] [security2:error] [pid 341679:tid 341880] [client 122.164.127.47:52961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QagWat-noHLkDuAiLbQAAAVE"]
[Tue Jul 21 07:56:42.933326 2026] [security2:error] [pid 341679:tid 341894] [client 20.104.96.117:62836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/water.php"] [unique_id "al9QagWat-noHLkDuAiLcAAAAV8"]
[Tue Jul 21 07:56:43.044187 2026] [security2:error] [pid 341679:tid 341836] [client 117.210.135.0:65310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QagWat-noHLkDuAiLcQAAASU"]
[Tue Jul 21 07:56:43.156230 2026] [security2:error] [pid 341679:tid 341827] [client 74.249.245.134:65096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/api.php"] [unique_id "al9QawWat-noHLkDuAiLeQAAARw"]
[Tue Jul 21 07:56:43.168792 2026] [security2:error] [pid 341679:tid 341919] [client 20.151.10.161:29106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/fpwch.php"] [unique_id "al9QawWat-noHLkDuAiLegAAAXg"]
[Tue Jul 21 07:56:43.183835 2026] [security2:error] [pid 341679:tid 341888] [client 20.151.10.161:17389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/222.php"] [unique_id "al9QawWat-noHLkDuAiLewAAAVk"]
[Tue Jul 21 07:56:43.237561 2026] [security2:error] [pid 341679:tid 341834] [client 20.104.96.117:46394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/nano.php"] [unique_id "al9QawWat-noHLkDuAiLfgAAASM"]
[Tue Jul 21 07:56:43.414792 2026] [security2:error] [pid 341679:tid 341865] [client 193.36.225.68:26841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QawWat-noHLkDuAiLhAAAAUI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:56:43.420317 2026] [security2:error] [pid 341679:tid 341923] [client 65.21.113.253:43590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QawWat-noHLkDuAiLcgAAAXw"]
[Tue Jul 21 07:56:43.613460 2026] [security2:error] [pid 341679:tid 341819] [client 20.151.10.161:28831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/w2025.php"] [unique_id "al9QawWat-noHLkDuAiLiwAAARQ"]
[Tue Jul 21 07:56:43.618740 2026] [security2:error] [pid 341679:tid 341868] [client 20.206.105.145:55916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/file15.php"] [unique_id "al9QawWat-noHLkDuAiLjAAAAUU"]
[Tue Jul 21 07:56:43.630339 2026] [security2:error] [pid 341679:tid 341901] [client 20.104.96.117:46447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/moon.php"] [unique_id "al9QawWat-noHLkDuAiLjgAAAWY"]
[Tue Jul 21 07:56:43.782302 2026] [security2:error] [pid 341679:tid 341863] [client 20.104.96.117:54923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9QawWat-noHLkDuAiLjwAAAUA"]
[Tue Jul 21 07:56:43.849021 2026] [security2:error] [pid 341679:tid 341886] [client 109.60.28.94:41025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QawWat-noHLkDuAiLkwAAAVc"]
[Tue Jul 21 07:56:43.849150 2026] [security2:error] [pid 341679:tid 341886] [client 109.60.28.94:41025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QawWat-noHLkDuAiLkwAAAVc"]
[Tue Jul 21 07:56:43.931852 2026] [security2:error] [pid 341679:tid 341876] [client 20.104.96.117:46437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-info.php"] [unique_id "al9QawWat-noHLkDuAiLlwAAAU0"]
[Tue Jul 21 07:56:43.937497 2026] [security2:error] [pid 341679:tid 341924] [client 20.151.10.161:29073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/scxy.php"] [unique_id "al9QawWat-noHLkDuAiLmAAAAX0"]
[Tue Jul 21 07:56:43.945540 2026] [security2:error] [pid 341679:tid 341849] [client 20.151.10.161:17388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/cgi-bin/index.php"] [unique_id "al9QawWat-noHLkDuAiLmQAAATI"]
[Tue Jul 21 07:56:43.953684 2026] [security2:error] [pid 341679:tid 341724] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QawWat-noHLkDuAiLmgABJCw"]
[Tue Jul 21 07:56:43.953869 2026] [security2:error] [pid 341679:tid 341835] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QawWat-noHLkDuAiLmgABJCw"]
[Tue Jul 21 07:56:44.031184 2026] [security2:error] [pid 341679:tid 341693] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QbAWat-noHLkDuAiLmwABEw0"]
[Tue Jul 21 07:56:44.031333 2026] [security2:error] [pid 341679:tid 341818] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QbAWat-noHLkDuAiLmwABEw0"]
[Tue Jul 21 07:56:44.147510 2026] [security2:error] [pid 341679:tid 341936] [client 193.36.225.142:37809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QbAWat-noHLkDuAiLnQAAAYk"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:56:44.151779 2026] [security2:error] [pid 341679:tid 341821] [client 20.226.60.151:61547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/19.php"] [unique_id "al9QbAWat-noHLkDuAiLnwAAARY"]
[Tue Jul 21 07:56:44.296730 2026] [security2:error] [pid 341679:tid 341905] [client 20.104.96.117:62841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/2000.php"] [unique_id "al9QbAWat-noHLkDuAiLqgAAAWo"]
[Tue Jul 21 07:56:44.547273 2026] [security2:error] [pid 341679:tid 341923] [client 20.197.192.193:3615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/bootstrap.php"] [unique_id "al9QbAWat-noHLkDuAiLswAAAXw"]
[Tue Jul 21 07:56:44.655713 2026] [security2:error] [pid 341679:tid 341819] [client 20.104.96.117:62819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/122.php"] [unique_id "al9QbAWat-noHLkDuAiLugAAARQ"]
[Tue Jul 21 07:56:44.718715 2026] [security2:error] [pid 341679:tid 341860] [client 41.68.90.219:61197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbAWat-noHLkDuAiLvAAAAT0"]
[Tue Jul 21 07:56:44.719579 2026] [security2:error] [pid 341679:tid 341860] [client 41.68.90.219:61197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbAWat-noHLkDuAiLvAAAAT0"]
[Tue Jul 21 07:56:44.945370 2026] [autoindex:error] [pid 341679:tid 341864] [client 20.151.10.161:0] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:44.969588 2026] [security2:error] [pid 341679:tid 341896] [client 20.151.10.161:29076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/FWAZ.php"] [unique_id "al9QbAWat-noHLkDuAiLxAAAAWE"]
[Tue Jul 21 07:56:45.015372 2026] [security2:error] [pid 341679:tid 341874] [client 20.104.96.117:62842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/mds.php"] [unique_id "al9QbQWat-noHLkDuAiLxQAAAUs"]
[Tue Jul 21 07:56:45.019185 2026] [security2:error] [pid 341679:tid 341684] [remote 42.200.84.61:54136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9QbQWat-noHLkDuAiLxgABLgQ"]
[Tue Jul 21 07:56:45.019751 2026] [security2:error] [pid 341679:tid 341845] [client 42.200.84.61:54136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9QbQWat-noHLkDuAiLxgABLgQ"]
[Tue Jul 21 07:56:45.036351 2026] [security2:error] [pid 341679:tid 341719] [remote 182.77.62.24:59022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9QbQWat-noHLkDuAiLyAABhic"]
[Tue Jul 21 07:56:45.192477 2026] [security2:error] [pid 341679:tid 341821] [client 20.206.105.145:55823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/jp.php"] [unique_id "al9QbQWat-noHLkDuAiLyQAAARY"]
[Tue Jul 21 07:56:45.229713 2026] [security2:error] [pid 341679:tid 341847] [client 20.151.10.161:17378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/BDKR28WP.php"] [unique_id "al9QbQWat-noHLkDuAiLzAAAATA"]
[Tue Jul 21 07:56:45.307729 2026] [security2:error] [pid 341679:tid 341714] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QbQWat-noHLkDuAiLzwABfSI"]
[Tue Jul 21 07:56:45.307931 2026] [security2:error] [pid 341679:tid 341924] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QbQWat-noHLkDuAiLzwABfSI"]
[Tue Jul 21 07:56:45.319370 2026] [security2:error] [pid 341679:tid 341919] [client 184.75.221.3:44356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9QbQWat-noHLkDuAiL0AAAAXg"]
[Tue Jul 21 07:56:45.319464 2026] [security2:error] [pid 341679:tid 341919] [client 184.75.221.3:44356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9QbQWat-noHLkDuAiL0AAAAXg"]
[Tue Jul 21 07:56:45.327556 2026] [security2:error] [pid 341679:tid 341907] [client 20.104.96.117:62810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-blink.php"] [unique_id "al9QbQWat-noHLkDuAiL0QAAAWw"]
[Tue Jul 21 07:56:45.332422 2026] [security2:error] [pid 341679:tid 341890] [client 20.206.105.145:55819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/f35.php"] [unique_id "al9QbQWat-noHLkDuAiL0gAAAVs"]
[Tue Jul 21 07:56:45.377612 2026] [security2:error] [pid 341679:tid 341905] [client 20.206.105.145:55913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wp-load.php"] [unique_id "al9QbQWat-noHLkDuAiL1wAAAWo"]
[Tue Jul 21 07:56:45.384154 2026] [security2:error] [pid 341679:tid 341889] [client 202.143.127.214:53912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbQWat-noHLkDuAiL2QAAAVo"]
[Tue Jul 21 07:56:45.384239 2026] [security2:error] [pid 341679:tid 341889] [client 202.143.127.214:53912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbQWat-noHLkDuAiL2QAAAVo"]
[Tue Jul 21 07:56:45.398135 2026] [security2:error] [pid 341679:tid 341908] [client 20.104.96.117:55021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9QbQWat-noHLkDuAiL3AAAAW0"]
[Tue Jul 21 07:56:45.494198 2026] [security2:error] [pid 341679:tid 341877] [client 178.153.91.96:59904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QbQWat-noHLkDuAiL3gAAAU4"]
[Tue Jul 21 07:56:45.494359 2026] [security2:error] [pid 341679:tid 341877] [client 178.153.91.96:59904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QbQWat-noHLkDuAiL3gAAAU4"]
[Tue Jul 21 07:56:45.502467 2026] [security2:error] [pid 341679:tid 341851] [client 20.151.10.161:29076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/qterm.php"] [unique_id "al9QbQWat-noHLkDuAiL3wAAATQ"]
[Tue Jul 21 07:56:45.610697 2026] [security2:error] [pid 341679:tid 341927] [client 20.104.96.117:62725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/zc-208.php"] [unique_id "al9QbQWat-noHLkDuAiL4QAAAYA"]
[Tue Jul 21 07:56:45.630102 2026] [security2:error] [pid 341679:tid 341814] [client 59.93.4.33:60355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbQWat-noHLkDuAiL4gAAAQ8"]
[Tue Jul 21 07:56:45.630265 2026] [security2:error] [pid 341679:tid 341814] [client 59.93.4.33:60355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbQWat-noHLkDuAiL4gAAAQ8"]
[Tue Jul 21 07:56:45.692870 2026] [autoindex:error] [pid 341679:tid 341842] [client 20.151.10.161:0] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:45.787399 2026] [security2:error] [pid 341679:tid 341818] [client 38.100.221.102:18201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbQWat-noHLkDuAiL6gAAARM"]
[Tue Jul 21 07:56:45.787707 2026] [security2:error] [pid 341679:tid 341818] [client 38.100.221.102:18201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbQWat-noHLkDuAiL6gAAARM"]
[Tue Jul 21 07:56:45.801866 2026] [security2:error] [pid 341679:tid 341841] [client 74.249.245.134:54354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/simple.php"] [unique_id "al9QbQWat-noHLkDuAiL7QAAASo"]
[Tue Jul 21 07:56:45.887019 2026] [security2:error] [pid 341679:tid 341868] [client 20.104.96.117:62800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/sid4.php"] [unique_id "al9QbQWat-noHLkDuAiL8wAAAUU"]
[Tue Jul 21 07:56:45.936467 2026] [security2:error] [pid 341679:tid 341914] [client 20.206.105.145:55887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9QbQWat-noHLkDuAiL-AAAAXM"]
[Tue Jul 21 07:56:45.981850 2026] [authz_core:error] [pid 341679:tid 341835] [client 20.151.10.161:0] AH01630: client denied by server configuration: /home2/valmi544/public_html/wp-content/uploads/index.php
[Tue Jul 21 07:56:46.125141 2026] [security2:error] [pid 341679:tid 341921] [client 20.151.10.161:17313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/raw.php"] [unique_id "al9QbgWat-noHLkDuAiL_wAAAXo"]
[Tue Jul 21 07:56:46.149895 2026] [security2:error] [pid 341679:tid 341847] [client 20.151.10.161:28821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/blurbs.php"] [unique_id "al9QbgWat-noHLkDuAiMAQAAATA"]
[Tue Jul 21 07:56:46.325458 2026] [security2:error] [pid 341679:tid 341810] [client 20.104.96.117:46348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wmore1.php"] [unique_id "al9QbgWat-noHLkDuAiMDAAAAQs"]
[Tue Jul 21 07:56:46.325889 2026] [security2:error] [pid 341679:tid 341831] [client 117.247.80.59:19438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbgWat-noHLkDuAiMDQAAASA"]
[Tue Jul 21 07:56:46.326048 2026] [security2:error] [pid 341679:tid 341831] [client 117.247.80.59:19438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbgWat-noHLkDuAiMDQAAASA"]
[Tue Jul 21 07:56:46.331682 2026] [security2:error] [pid 341679:tid 341920] [client 20.206.105.145:28636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wp-links.php"] [unique_id "al9QbgWat-noHLkDuAiMDgAAAXk"]
[Tue Jul 21 07:56:46.474790 2026] [security2:error] [pid 341679:tid 341884] [client 20.151.10.161:29115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/v543.php"] [unique_id "al9QbgWat-noHLkDuAiMEQAAAVU"]
[Tue Jul 21 07:56:46.491521 2026] [security2:error] [pid 341679:tid 341932] [client 20.151.10.161:17393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/abcd.php"] [unique_id "al9QbgWat-noHLkDuAiMFAAAAYU"]
[Tue Jul 21 07:56:46.534931 2026] [security2:error] [pid 341679:tid 341927] [client 20.104.96.117:54952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/ss.php"] [unique_id "al9QbgWat-noHLkDuAiMGAAAAYA"]
[Tue Jul 21 07:56:46.609759 2026] [security2:error] [pid 341679:tid 341814] [client 20.104.96.117:46389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/solo1.php"] [unique_id "al9QbgWat-noHLkDuAiMGQAAAQ8"]
[Tue Jul 21 07:56:46.637295 2026] [security2:error] [pid 341679:tid 341931] [client 20.206.105.145:55872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/solo1.php"] [unique_id "al9QbgWat-noHLkDuAiMGwAAAYQ"]
[Tue Jul 21 07:56:46.649213 2026] [security2:error] [pid 341679:tid 341898] [client 20.226.60.151:61542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/inc.php"] [unique_id "al9QbgWat-noHLkDuAiMHAAAAWM"]
[Tue Jul 21 07:56:46.774739 2026] [security2:error] [pid 341679:tid 341911] [client 65.21.113.253:40882] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QbgWat-noHLkDuAiMIAAAAXA"]
[Tue Jul 21 07:56:46.830191 2026] [security2:error] [pid 341679:tid 341818] [client 20.206.105.145:55888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/sixxis.php"] [unique_id "al9QbgWat-noHLkDuAiMIQAAARM"]
[Tue Jul 21 07:56:46.912540 2026] [security2:error] [pid 341679:tid 341860] [client 20.151.10.161:28802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/w3lls.php"] [unique_id "al9QbgWat-noHLkDuAiMIwAAAT0"]
[Tue Jul 21 07:56:46.985422 2026] [security2:error] [pid 341679:tid 341905] [client 65.21.113.253:43604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QbgWat-noHLkDuAiMFwAAAWo"]
[Tue Jul 21 07:56:46.992170 2026] [security2:error] [pid 341679:tid 341864] [client 20.151.10.161:17391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/a1.php"] [unique_id "al9QbgWat-noHLkDuAiMKQAAAUE"]
[Tue Jul 21 07:56:47.058570 2026] [security2:error] [pid 341679:tid 341820] [client 65.111.20.218:42265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QbQWat-noHLkDuAiL9AAAARU"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:56:47.061552 2026] [security2:error] [pid 341679:tid 341879] [client 20.104.96.117:46425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/cong.php"] [unique_id "al9QbwWat-noHLkDuAiMKgAAAVA"]
[Tue Jul 21 07:56:47.183618 2026] [security2:error] [pid 341679:tid 341791] [remote 52.167.144.213:57145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/"] [unique_id "al9QbgWat-noHLkDuAiMAwABSm8"]
[Tue Jul 21 07:56:47.184058 2026] [security2:error] [pid 341679:tid 341743] [remote 102.218.148.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.148.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbwWat-noHLkDuAiMLAABIT8"]
[Tue Jul 21 07:56:47.184203 2026] [security2:error] [pid 341679:tid 341832] [client 102.218.148.132:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbwWat-noHLkDuAiMLAABIT8"]
[Tue Jul 21 07:56:47.215133 2026] [security2:error] [pid 341679:tid 341763] [remote 139.167.225.126:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbwWat-noHLkDuAiMLgABM1M"]
[Tue Jul 21 07:56:47.215262 2026] [security2:error] [pid 341679:tid 341850] [client 139.167.225.126:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "luminabeauty.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbwWat-noHLkDuAiMLgABM1M"]
[Tue Jul 21 07:56:47.289652 2026] [security2:error] [pid 341679:tid 341862] [client 20.226.60.151:56741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/cgi-bin/index.php"] [unique_id "al9QbwWat-noHLkDuAiMMgAAAT8"]
[Tue Jul 21 07:56:47.295676 2026] [security2:error] [pid 341679:tid 341889] [client 20.206.105.145:28626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/2P.update.php"] [unique_id "al9QbwWat-noHLkDuAiMMwAAAVo"]
[Tue Jul 21 07:56:47.298354 2026] [security2:error] [pid 341679:tid 341906] [client 20.151.10.161:29221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-ws68.php"] [unique_id "al9QbwWat-noHLkDuAiMNAAAAWs"]
[Tue Jul 21 07:56:47.402735 2026] [security2:error] [pid 341679:tid 341683] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbwWat-noHLkDuAiMNgABLgM"]
[Tue Jul 21 07:56:47.402874 2026] [security2:error] [pid 341679:tid 341845] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QbwWat-noHLkDuAiMNgABLgM"]
[Tue Jul 21 07:56:47.512090 2026] [security2:error] [pid 341679:tid 341931] [client 20.104.96.117:62731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/public/css.php"] [unique_id "al9QbwWat-noHLkDuAiMPQAAAYQ"]
[Tue Jul 21 07:56:47.513441 2026] [authz_core:error] [pid 341679:tid 341869] [client 107.189.2.5:43212] AH01630: client denied by server configuration: /home2/digi0249/karolve.com.br/htdocs/bagisto-2.4/public/.env.save
[Tue Jul 21 07:56:47.640898 2026] [security2:error] [pid 341679:tid 341828] [client 20.151.10.161:17355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9QbwWat-noHLkDuAiMQQAAAR0"]
[Tue Jul 21 07:56:47.646727 2026] [security2:error] [pid 341679:tid 341819] [client 184.75.221.3:39834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9QbwWat-noHLkDuAiMQgAAARQ"]
[Tue Jul 21 07:56:47.646852 2026] [security2:error] [pid 341679:tid 341819] [client 184.75.221.3:39834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9QbwWat-noHLkDuAiMQgAAARQ"]
[Tue Jul 21 07:56:47.686909 2026] [security2:error] [pid 341679:tid 341935] [client 20.151.10.161:28801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/xyn.php"] [unique_id "al9QbwWat-noHLkDuAiMQwAAAYg"]
[Tue Jul 21 07:56:47.796541 2026] [security2:error] [pid 341679:tid 341899] [client 20.104.96.117:62743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/output.php"] [unique_id "al9QbwWat-noHLkDuAiMRwAAAWQ"]
[Tue Jul 21 07:56:47.855662 2026] [security2:error] [pid 341679:tid 341831] [client 65.21.113.253:43614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QbwWat-noHLkDuAiMOAAAASA"]
[Tue Jul 21 07:56:47.975921 2026] [security2:error] [pid 341679:tid 341873] [client 20.151.10.161:17352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9QbwWat-noHLkDuAiMTAAAAUo"]
[Tue Jul 21 07:56:47.987007 2026] [security2:error] [pid 341679:tid 341821] [client 107.189.2.5:43156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karolve.com.br"] [uri "/.env"] [unique_id "al9QbwWat-noHLkDuAiMUAAAARY"]
[Tue Jul 21 07:56:47.987411 2026] [security2:error] [pid 341679:tid 341836] [client 107.189.2.5:43202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "karolve.com.br"] [uri "/.env.bak"] [unique_id "al9QbwWat-noHLkDuAiMTgAAASU"]
[Tue Jul 21 07:56:47.987412 2026] [security2:error] [pid 341679:tid 341910] [client 107.189.2.5:43282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "karolve.com.br"] [uri "/.env~"] [unique_id "al9QbwWat-noHLkDuAiMVAAAAW8"]
[Tue Jul 21 07:56:47.988053 2026] [security2:error] [pid 341679:tid 341936] [client 107.189.2.5:43292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "karolve.com.br"] [uri "/.env.swp"] [unique_id "al9QbwWat-noHLkDuAiMVgAAAYk"]
[Tue Jul 21 07:56:47.988345 2026] [authz_core:error] [pid 341679:tid 341839] [client 107.189.2.5:43190] AH01630: client denied by server configuration: /home2/digi0249/karolve.com.br/htdocs/bagisto-2.4/public/.env.development
[Tue Jul 21 07:56:47.988401 2026] [security2:error] [pid 341679:tid 341921] [client 107.189.2.5:43228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "karolve.com.br"] [uri "/.env.backup"] [unique_id "al9QbwWat-noHLkDuAiMVwAAAXo"]
[Tue Jul 21 07:56:47.988543 2026] [security2:error] [pid 341679:tid 341891] [client 107.189.2.5:43140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karolve.com.br"] [uri "/backend/.env"] [unique_id "al9QbwWat-noHLkDuAiMWQAAAVw"]
[Tue Jul 21 07:56:47.988625 2026] [authz_core:error] [pid 341679:tid 341880] [client 107.189.2.5:43180] AH01630: client denied by server configuration: /home2/digi0249/karolve.com.br/htdocs/bagisto-2.4/public/.env.production
[Tue Jul 21 07:56:47.988625 2026] [authz_core:error] [pid 341679:tid 341857] [client 107.189.2.5:43164] AH01630: client denied by server configuration: /home2/digi0249/karolve.com.br/htdocs/bagisto-2.4/public/.env.local
[Tue Jul 21 07:56:47.988830 2026] [authz_core:error] [pid 341679:tid 341887] [client 107.189.2.5:43322] AH01630: client denied by server configuration: /home2/digi0249/karolve.com.br/htdocs/bagisto-2.4/public/.env_backup
[Tue Jul 21 07:56:47.989260 2026] [authz_core:error] [pid 341679:tid 341825] [client 107.189.2.5:43240] AH01630: client denied by server configuration: /home2/digi0249/karolve.com.br/htdocs/bagisto-2.4/public/.env.staging
[Tue Jul 21 07:56:47.989306 2026] [authz_core:error] [pid 341679:tid 341881] [client 107.189.2.5:43304] AH01630: client denied by server configuration: /home2/digi0249/karolve.com.br/htdocs/bagisto-2.4/public/.env.sample
[Tue Jul 21 07:56:47.990753 2026] [authz_core:error] [pid 341679:tid 341897] [client 107.189.2.5:43262] AH01630: client denied by server configuration: /home2/digi0249/karolve.com.br/htdocs/bagisto-2.4/public/.env.dev
[Tue Jul 21 07:56:47.990927 2026] [authz_core:error] [pid 341679:tid 341907] [client 107.189.2.5:43250] AH01630: client denied by server configuration: /home2/digi0249/karolve.com.br/htdocs/bagisto-2.4/public/.env.prod
[Tue Jul 21 07:56:47.991051 2026] [authz_core:error] [pid 341679:tid 341930] [client 107.189.2.5:43314] AH01630: client denied by server configuration: /home2/digi0249/karolve.com.br/htdocs/bagisto-2.4/public/.env.dist
[Tue Jul 21 07:56:47.991109 2026] [authz_core:error] [pid 341679:tid 341870] [client 107.189.2.5:43276] AH01630: client denied by server configuration: /home2/digi0249/karolve.com.br/htdocs/bagisto-2.4/public/.env.test
[Tue Jul 21 07:56:47.991588 2026] [authz_core:error] [pid 341679:tid 341890] [client 107.189.2.5:43336] AH01630: client denied by server configuration: /home2/digi0249/karolve.com.br/htdocs/bagisto-2.4/public/.env_secret
[Tue Jul 21 07:56:47.995948 2026] [security2:error] [pid 341679:tid 341832] [client 107.189.2.5:43212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "karolve.com.br"] [uri "/.env.old"] [unique_id "al9QbwWat-noHLkDuAiMXwAAASE"]
[Tue Jul 21 07:56:48.048176 2026] [security2:error] [pid 341679:tid 341837] [client 20.104.96.117:57728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/min.php"] [unique_id "al9QcAWat-noHLkDuAiMYQAAASY"]
[Tue Jul 21 07:56:48.075229 2026] [security2:error] [pid 341679:tid 341863] [client 20.104.96.117:62730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-file-120.php"] [unique_id "al9QcAWat-noHLkDuAiMYgAAAUA"]
[Tue Jul 21 07:56:48.175275 2026] [security2:error] [pid 341679:tid 341908] [client 223.236.153.128:7612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QcAWat-noHLkDuAiMawAAAW0"]
[Tue Jul 21 07:56:48.175394 2026] [security2:error] [pid 341679:tid 341908] [client 223.236.153.128:7612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QcAWat-noHLkDuAiMawAAAW0"]
[Tue Jul 21 07:56:48.212264 2026] [security2:error] [pid 341679:tid 341849] [client 139.167.225.182:53774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QcAWat-noHLkDuAiMbQAAATI"]
[Tue Jul 21 07:56:48.212358 2026] [security2:error] [pid 341679:tid 341849] [client 139.167.225.182:53774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QcAWat-noHLkDuAiMbQAAATI"]
[Tue Jul 21 07:56:48.244038 2026] [security2:error] [pid 341679:tid 341931] [client 20.206.105.145:55815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/a.php"] [unique_id "al9QcAWat-noHLkDuAiMbgAAAYQ"]
[Tue Jul 21 07:56:48.252650 2026] [security2:error] [pid 341679:tid 341858] [client 20.151.10.161:29199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/green3.php"] [unique_id "al9QcAWat-noHLkDuAiMcAAAATs"]
[Tue Jul 21 07:56:48.256893 2026] [security2:error] [pid 341679:tid 341704] [remote 43.157.224.197:45532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.224.157.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "frsadvocacia.net"] [uri "/xmlrpc.php"] [unique_id "al9QcAWat-noHLkDuAiMbwABDRg"]
[Tue Jul 21 07:56:48.257014 2026] [security2:error] [pid 341679:tid 341812] [client 43.157.224.197:45532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "frsadvocacia.net"] [uri "/xmlrpc.php"] [unique_id "al9QcAWat-noHLkDuAiMbwABDRg"]
[Tue Jul 21 07:56:48.269818 2026] [security2:error] [pid 341679:tid 341848] [client 87.116.180.198:13972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QcAWat-noHLkDuAiMZgAAATE"]
[Tue Jul 21 07:56:48.269925 2026] [security2:error] [pid 341679:tid 341848] [client 87.116.180.198:13972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QcAWat-noHLkDuAiMZgAAATE"]
[Tue Jul 21 07:56:48.382050 2026] [security2:error] [pid 341679:tid 341918] [client 20.104.96.117:62774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/special.php"] [unique_id "al9QcAWat-noHLkDuAiMdAAAAXc"]
[Tue Jul 21 07:56:48.457642 2026] [security2:error] [pid 341679:tid 341928] [client 185.213.175.37:48360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.ajsdiesel.com.br"] [uri "/"] [unique_id "al9QcAWat-noHLkDuAiMdwAAAYE"]
[Tue Jul 21 07:56:48.457771 2026] [security2:error] [pid 341679:tid 341928] [client 185.213.175.37:48360] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.ajsdiesel.com.br"] [uri "/"] [unique_id "al9QcAWat-noHLkDuAiMdwAAAYE"]
[Tue Jul 21 07:56:48.556297 2026] [security2:error] [pid 341679:tid 341833] [client 122.162.144.145:6542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QcAWat-noHLkDuAiMfgAAASI"]
[Tue Jul 21 07:56:48.556438 2026] [security2:error] [pid 341679:tid 341833] [client 122.162.144.145:6542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QcAWat-noHLkDuAiMfgAAASI"]
[Tue Jul 21 07:56:48.569897 2026] [security2:error] [pid 341679:tid 341909] [client 20.151.10.161:17311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wp-content/BypassBest.php"] [unique_id "al9QcAWat-noHLkDuAiMfwAAAW4"]
[Tue Jul 21 07:56:48.646888 2026] [security2:error] [pid 341679:tid 341872] [client 193.36.225.55:53721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QcAWat-noHLkDuAiMeAAAAUk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:56:48.674997 2026] [security2:error] [pid 341679:tid 341867] [client 182.8.255.181:17292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QcAWat-noHLkDuAiMgwAAAUQ"]
[Tue Jul 21 07:56:48.675144 2026] [security2:error] [pid 341679:tid 341867] [client 182.8.255.181:17292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QcAWat-noHLkDuAiMgwAAAUQ"]
[Tue Jul 21 07:56:48.704187 2026] [security2:error] [pid 341679:tid 341846] [client 20.104.96.117:62839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/as.php"] [unique_id "al9QcAWat-noHLkDuAiMhQAAAS8"]
[Tue Jul 21 07:56:48.851581 2026] [security2:error] [pid 341679:tid 341873] [client 20.151.10.161:29116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/ccs.php"] [unique_id "al9QcAWat-noHLkDuAiMhgAAAUo"]
[Tue Jul 21 07:56:48.930991 2026] [security2:error] [pid 341679:tid 341826] [client 106.215.181.8:5922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QcAWat-noHLkDuAiMigAAARs"]
[Tue Jul 21 07:56:48.931073 2026] [security2:error] [pid 341679:tid 341826] [client 106.215.181.8:5922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QcAWat-noHLkDuAiMigAAARs"]
[Tue Jul 21 07:56:48.933508 2026] [security2:error] [pid 341679:tid 341881] [client 34.74.242.206:1645] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "robertaramos.com.br"] [uri "/robots.txt"] [unique_id "al9QcAWat-noHLkDuAiMiwAAAVI"]
[Tue Jul 21 07:56:48.933599 2026] [security2:error] [pid 341679:tid 341881] [client 34.74.242.206:1645] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "robertaramos.com.br"] [uri "/robots.txt"] [unique_id "al9QcAWat-noHLkDuAiMiwAAAVI"]
[Tue Jul 21 07:56:48.961768 2026] [security2:error] [pid 341679:tid 341853] [client 136.144.42.180:53373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QbwWat-noHLkDuAiMRAAAATY"]
[Tue Jul 21 07:56:48.983424 2026] [security2:error] [pid 341679:tid 341907] [client 20.104.96.117:62814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9QcAWat-noHLkDuAiMjAAAAWw"]
[Tue Jul 21 07:56:49.000741 2026] [security2:error] [pid 341679:tid 341890] [client 107.189.2.5:43230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karolve.com.br"] [uri "/api/.env"] [unique_id "al9QcAWat-noHLkDuAiMkAAAAVs"]
[Tue Jul 21 07:56:49.003080 2026] [security2:error] [pid 341679:tid 341832] [client 20.206.105.145:28633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/k.php"] [unique_id "al9QcQWat-noHLkDuAiMkQAAASE"]
[Tue Jul 21 07:56:49.020841 2026] [security2:error] [pid 341679:tid 341922] [client 172.238.32.188:37262] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "quattrotech.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9QcQWat-noHLkDuAiMkgAAAXs"]
[Tue Jul 21 07:56:49.073874 2026] [security2:error] [pid 341679:tid 341838] [client 20.226.60.151:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/black.php"] [unique_id "al9QcQWat-noHLkDuAiMlQAAASc"]
[Tue Jul 21 07:56:49.116089 2026] [security2:error] [pid 341679:tid 341810] [client 107.189.2.5:43140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karolve.com.br"] [uri "/app/.env"] [unique_id "al9QcQWat-noHLkDuAiMngAAAQs"]
[Tue Jul 21 07:56:49.117037 2026] [security2:error] [pid 341679:tid 341851] [client 107.189.2.5:43156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karolve.com.br"] [uri "/config/.env"] [unique_id "al9QcQWat-noHLkDuAiMnwAAATQ"]
[Tue Jul 21 07:56:49.118953 2026] [security2:error] [pid 341679:tid 341840] [client 107.189.2.5:43292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karolve.com.br"] [uri "/src/.env"] [unique_id "al9QcQWat-noHLkDuAiMoAAAASk"]
[Tue Jul 21 07:56:49.119385 2026] [security2:error] [pid 341679:tid 341914] [client 107.189.2.5:43212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karolve.com.br"] [uri "/server/.env"] [unique_id "al9QcQWat-noHLkDuAiMpAAAAXM"]
[Tue Jul 21 07:56:49.121171 2026] [security2:error] [pid 341679:tid 341812] [client 107.189.2.5:43336] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "karolve.com.br"] [uri "/web/.env"] [unique_id "al9QcQWat-noHLkDuAiMqQAAAQ0"]
[Tue Jul 21 07:56:49.172236 2026] [security2:error] [pid 341679:tid 341911] [client 34.74.242.206:1648] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "robertaramos.com.br"] [uri "/"] [unique_id "al9QcQWat-noHLkDuAiMrQAAAXA"]
[Tue Jul 21 07:56:49.172352 2026] [security2:error] [pid 341679:tid 341911] [client 34.74.242.206:1648] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "robertaramos.com.br"] [uri "/"] [unique_id "al9QcQWat-noHLkDuAiMrQAAAXA"]
[Tue Jul 21 07:56:49.203230 2026] [security2:error] [pid 341679:tid 341888] [client 172.238.32.188:37262] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "quattrotech.com.br"] [uri "/"] [unique_id "al9QcQWat-noHLkDuAiMrwAAAVk"]
[Tue Jul 21 07:56:49.206350 2026] [security2:error] [pid 341679:tid 341902] [client 185.251.19.78:58051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QbwWat-noHLkDuAiMRQAAAWc"]
[Tue Jul 21 07:56:49.252472 2026] [security2:error] [pid 341679:tid 341818] [client 20.151.10.161:17398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/simple.php"] [unique_id "al9QcQWat-noHLkDuAiMswAAARM"]
[Tue Jul 21 07:56:49.294589 2026] [security2:error] [pid 341679:tid 341893] [client 20.104.96.117:46420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/w1px.php"] [unique_id "al9QcQWat-noHLkDuAiMtQAAAV4"]
[Tue Jul 21 07:56:49.339329 2026] [security2:error] [pid 341679:tid 341876] [client 103.166.103.129:53871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QcQWat-noHLkDuAiMtgAAAU0"]
[Tue Jul 21 07:56:49.339456 2026] [security2:error] [pid 341679:tid 341876] [client 103.166.103.129:53871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QcQWat-noHLkDuAiMtgAAAU0"]
[Tue Jul 21 07:56:49.344584 2026] [core:error] [pid 341679:tid 341737] [remote 52.167.144.219:60570] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:56:49.344601 2026] [core:error] [pid 341679:tid 341737] [remote 52.167.144.219:60570] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:56:49.447824 2026] [security2:error] [pid 341679:tid 341896] [client 103.78.200.11:53846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QcQWat-noHLkDuAiMuwAAAWE"]
[Tue Jul 21 07:56:49.448002 2026] [security2:error] [pid 341679:tid 341896] [client 103.78.200.11:53846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QcQWat-noHLkDuAiMuwAAAWE"]
[Tue Jul 21 07:56:49.529482 2026] [security2:error] [pid 341679:tid 341886] [client 20.197.192.193:54338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/wp-editor.php"] [unique_id "al9QcQWat-noHLkDuAiMvAAAAVc"]
[Tue Jul 21 07:56:49.622716 2026] [security2:error] [pid 341679:tid 341884] [client 65.21.113.253:43604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QcQWat-noHLkDuAiMmQAAAVU"]
[Tue Jul 21 07:56:49.663308 2026] [security2:error] [pid 341679:tid 341857] [client 20.151.10.161:28860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/ccc.php"] [unique_id "al9QcQWat-noHLkDuAiMwQAAATo"]
[Tue Jul 21 07:56:49.692896 2026] [security2:error] [pid 341679:tid 341881] [client 20.104.96.117:62817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/yawa.php"] [unique_id "al9QcQWat-noHLkDuAiMwgAAAVI"]
[Tue Jul 21 07:56:49.862079 2026] [security2:error] [pid 341679:tid 341922] [client 20.104.96.117:54990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9QcQWat-noHLkDuAiMxgAAAXs"]
[Tue Jul 21 07:56:49.949076 2026] [security2:error] [pid 341679:tid 341726] [remote 180.153.236.202:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cinsofe.com"] [uri "/"] [unique_id "al9QcQWat-noHLkDuAiMygABIS4"], referer: https://www.cinsofe.com/
[Tue Jul 21 07:56:49.949260 2026] [security2:error] [pid 341679:tid 341832] [client 180.153.236.202:0] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.cinsofe.com"] [uri "/"] [unique_id "al9QcQWat-noHLkDuAiMygABIS4"], referer: https://www.cinsofe.com/
[Tue Jul 21 07:56:50.005462 2026] [security2:error] [pid 341679:tid 341845] [client 20.104.96.117:46405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/js.php"] [unique_id "al9QcgWat-noHLkDuAiMywAAAS4"]
[Tue Jul 21 07:56:50.069408 2026] [security2:error] [pid 341679:tid 341850] [client 20.151.10.161:17353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/xxx.php"] [unique_id "al9QcgWat-noHLkDuAiMzAAAATM"]
[Tue Jul 21 07:56:50.153925 2026] [security2:error] [pid 341679:tid 341868] [client 103.29.114.44:60043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QcgWat-noHLkDuAiM0QAAAUU"]
[Tue Jul 21 07:56:50.154060 2026] [security2:error] [pid 341679:tid 341868] [client 103.29.114.44:60043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QcgWat-noHLkDuAiM0QAAAUU"]
[Tue Jul 21 07:56:50.305249 2026] [security2:error] [pid 341679:tid 341903] [client 20.104.96.117:62743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/core.php"] [unique_id "al9QcgWat-noHLkDuAiM1AAAAWg"]
[Tue Jul 21 07:56:50.312344 2026] [security2:error] [pid 341679:tid 341908] [client 180.153.236.103:21127] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.cacosmeticosclub.com.br"] [uri "/"] [unique_id "al9QcgWat-noHLkDuAiM1QAAAW0"], referer: http://www.cacosmeticosclub.com.br/
[Tue Jul 21 07:56:50.312447 2026] [security2:error] [pid 341679:tid 341908] [client 180.153.236.103:21127] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.cacosmeticosclub.com.br"] [uri "/"] [unique_id "al9QcgWat-noHLkDuAiM1QAAAW0"], referer: http://www.cacosmeticosclub.com.br/
[Tue Jul 21 07:56:50.380597 2026] [security2:error] [pid 341679:tid 341874] [client 20.151.10.161:28856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/get.php"] [unique_id "al9QcgWat-noHLkDuAiM1gAAAUs"]
[Tue Jul 21 07:56:50.414518 2026] [security2:error] [pid 341679:tid 341839] [client 37.140.223.118:56335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QcQWat-noHLkDuAiMsgAAASg"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:56:50.503007 2026] [security2:error] [pid 341679:tid 341902] [client 20.151.10.161:17282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/hypo.php"] [unique_id "al9QcgWat-noHLkDuAiM2gAAAWc"]
[Tue Jul 21 07:56:50.600132 2026] [security2:error] [pid 341679:tid 341928] [client 20.104.96.117:46374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/19.php"] [unique_id "al9QcgWat-noHLkDuAiM3QAAAYE"]
[Tue Jul 21 07:56:50.734438 2026] [security2:error] [pid 341679:tid 341909] [client 20.104.96.117:54919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9QcgWat-noHLkDuAiM4gAAAW4"]
[Tue Jul 21 07:56:50.784777 2026] [security2:error] [pid 341679:tid 341904] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QcgWat-noHLkDuAiM3gABaXA"]
[Tue Jul 21 07:56:50.882096 2026] [security2:error] [pid 341679:tid 341905] [client 20.104.96.117:62847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/inc.php"] [unique_id "al9QcgWat-noHLkDuAiM5QAAAWo"]
[Tue Jul 21 07:56:51.008962 2026] [autoindex:error] [pid 341679:tid 341924] [client 20.151.10.161:17336] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:51.165531 2026] [security2:error] [pid 341679:tid 341841] [client 20.104.96.117:62809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9QcwWat-noHLkDuAiM7AAAASo"]
[Tue Jul 21 07:56:51.221915 2026] [security2:error] [pid 341679:tid 341919] [client 20.206.105.145:55859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/w.php"] [unique_id "al9QcwWat-noHLkDuAiM7gAAAXg"]
[Tue Jul 21 07:56:51.308179 2026] [security2:error] [pid 341679:tid 341821] [client 20.151.10.161:17336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/chosen.php"] [unique_id "al9QcwWat-noHLkDuAiM9AAAARY"]
[Tue Jul 21 07:56:51.346228 2026] [security2:error] [pid 341679:tid 341873] [client 20.151.10.161:28853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/images.php"] [unique_id "al9QcwWat-noHLkDuAiM9QAAAUo"]
[Tue Jul 21 07:56:51.412270 2026] [security2:error] [pid 341679:tid 341876] [client 122.186.204.214:51016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QcwWat-noHLkDuAiM9gAAAU0"]
[Tue Jul 21 07:56:51.412431 2026] [security2:error] [pid 341679:tid 341876] [client 122.186.204.214:51016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QcwWat-noHLkDuAiM9gAAAU0"]
[Tue Jul 21 07:56:51.459400 2026] [security2:error] [pid 341679:tid 341891] [client 20.104.96.117:62794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9QcwWat-noHLkDuAiM-AAAAVw"]
[Tue Jul 21 07:56:51.741986 2026] [security2:error] [pid 341679:tid 341811] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9QcgWat-noHLkDuAiM3AABDHQ"]
[Tue Jul 21 07:56:51.743110 2026] [security2:error] [pid 341679:tid 341889] [client 20.104.96.117:46454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ss.php"] [unique_id "al9QcwWat-noHLkDuAiM_gAAAVo"]
[Tue Jul 21 07:56:51.822808 2026] [security2:error] [pid 341679:tid 341680] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QcwWat-noHLkDuAiNAgABMQA"]
[Tue Jul 21 07:56:51.822968 2026] [security2:error] [pid 341679:tid 341848] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QcwWat-noHLkDuAiNAgABMQA"]
[Tue Jul 21 07:56:51.853928 2026] [autoindex:error] [pid 341679:tid 341934] [client 20.151.10.161:0] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:51.965309 2026] [security2:error] [pid 341679:tid 341741] [remote 119.195.102.159:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9QcwWat-noHLkDuAiNCgABiT0"]
[Tue Jul 21 07:56:52.033495 2026] [security2:error] [pid 341679:tid 341913] [client 20.104.96.117:46449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/min.php"] [unique_id "al9QdAWat-noHLkDuAiNDgAAAXI"]
[Tue Jul 21 07:56:52.111616 2026] [security2:error] [pid 341679:tid 341842] [client 20.151.10.161:28833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/alls.php"] [unique_id "al9QdAWat-noHLkDuAiNEQAAASs"]
[Tue Jul 21 07:56:52.129974 2026] [security2:error] [pid 341679:tid 341818] [client 20.151.10.161:17284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/file5.php"] [unique_id "al9QdAWat-noHLkDuAiNEwAAARM"]
[Tue Jul 21 07:56:52.147622 2026] [security2:error] [pid 341679:tid 341870] [client 102.206.115.33:58558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QdAWat-noHLkDuAiNFAAAAUc"]
[Tue Jul 21 07:56:52.148436 2026] [security2:error] [pid 341679:tid 341870] [client 102.206.115.33:58558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QdAWat-noHLkDuAiNFAAAAUc"]
[Tue Jul 21 07:56:52.190499 2026] [security2:error] [pid 341679:tid 341860] [client 74.249.245.134:54359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/404.php"] [unique_id "al9QdAWat-noHLkDuAiNFQAAAT0"]
[Tue Jul 21 07:56:52.206138 2026] [security2:error] [pid 341679:tid 341770] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9QdAWat-noHLkDuAiNFgABhFo"]
[Tue Jul 21 07:56:52.223043 2026] [security2:error] [pid 341679:tid 341708] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9QdAWat-noHLkDuAiNGgABSRw"]
[Tue Jul 21 07:56:52.244003 2026] [security2:error] [pid 341679:tid 341854] [client 20.104.96.117:55010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9QdAWat-noHLkDuAiNGwAAATc"]
[Tue Jul 21 07:56:52.274164 2026] [security2:error] [pid 341679:tid 341694] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/media.php"] [unique_id "al9QdAWat-noHLkDuAiNHAABUA4"]
[Tue Jul 21 07:56:52.278988 2026] [security2:error] [pid 341679:tid 341896] [client 20.226.60.151:60003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/zlece.php"] [unique_id "al9QdAWat-noHLkDuAiNHQAAAWE"]
[Tue Jul 21 07:56:52.314236 2026] [security2:error] [pid 341679:tid 341782] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/images.php"] [unique_id "al9QdAWat-noHLkDuAiNIgABHGY"]
[Tue Jul 21 07:56:52.319361 2026] [security2:error] [pid 341679:tid 341924] [client 20.104.96.117:46413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9QdAWat-noHLkDuAiNIwAAAX0"]
[Tue Jul 21 07:56:52.340276 2026] [security2:error] [pid 341679:tid 341724] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/adminner.php"] [unique_id "al9QdAWat-noHLkDuAiNJAABTyw"]
[Tue Jul 21 07:56:52.438157 2026] [security2:error] [pid 341679:tid 341748] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QdAWat-noHLkDuAiNKgABXkQ"]
[Tue Jul 21 07:56:52.438307 2026] [security2:error] [pid 341679:tid 341893] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QdAWat-noHLkDuAiNKgABXkQ"]
[Tue Jul 21 07:56:52.465250 2026] [security2:error] [pid 341679:tid 341887] [client 20.151.10.161:17305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/file.php"] [unique_id "al9QdAWat-noHLkDuAiNLwAAAVg"]
[Tue Jul 21 07:56:52.555545 2026] [security2:error] [pid 341679:tid 341895] [client 193.36.225.55:31273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QdAWat-noHLkDuAiNMAAAAWA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:56:52.623583 2026] [security2:error] [pid 341679:tid 341863] [client 20.104.96.117:62740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9QdAWat-noHLkDuAiNNAAAAUA"]
[Tue Jul 21 07:56:52.697744 2026] [security2:error] [pid 341679:tid 341811] [client 20.151.10.161:29083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/yyu.php"] [unique_id "al9QdAWat-noHLkDuAiNOAAAAQw"]
[Tue Jul 21 07:56:52.713407 2026] [security2:error] [pid 341679:tid 341902] [client 122.179.91.63:22064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QdAWat-noHLkDuAiNOQAAAWc"]
[Tue Jul 21 07:56:52.713532 2026] [security2:error] [pid 341679:tid 341902] [client 122.179.91.63:22064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QdAWat-noHLkDuAiNOQAAAWc"]
[Tue Jul 21 07:56:52.777493 2026] [security2:error] [pid 341679:tid 341838] [client 20.151.10.161:17234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/aa2.php"] [unique_id "al9QdAWat-noHLkDuAiNPQAAASc"]
[Tue Jul 21 07:56:52.901087 2026] [security2:error] [pid 341679:tid 341847] [client 20.104.96.117:46377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9QdAWat-noHLkDuAiNQQAAATA"]
[Tue Jul 21 07:56:52.934556 2026] [security2:error] [pid 341679:tid 341842] [client 20.226.60.151:61589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9QdAWat-noHLkDuAiNQgAAASs"]
[Tue Jul 21 07:56:53.209887 2026] [security2:error] [pid 341679:tid 341871] [client 20.226.60.151:56821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/w1px.php"] [unique_id "al9QdQWat-noHLkDuAiNSQAAAUg"]
[Tue Jul 21 07:56:53.217316 2026] [security2:error] [pid 341679:tid 341865] [client 20.104.96.117:58266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9QdQWat-noHLkDuAiNSgAAAUI"]
[Tue Jul 21 07:56:53.279753 2026] [security2:error] [pid 341679:tid 341930] [client 103.86.117.203:49840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QdQWat-noHLkDuAiNSwAAAYM"]
[Tue Jul 21 07:56:53.279899 2026] [security2:error] [pid 341679:tid 341930] [client 103.86.117.203:49840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QdQWat-noHLkDuAiNSwAAAYM"]
[Tue Jul 21 07:56:53.337540 2026] [security2:error] [pid 341679:tid 341900] [client 20.151.10.161:17225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/ccou.php"] [unique_id "al9QdQWat-noHLkDuAiNTwAAAWU"]
[Tue Jul 21 07:56:53.520198 2026] [security2:error] [pid 341679:tid 341893] [client 20.104.96.117:46443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/albin.php"] [unique_id "al9QdQWat-noHLkDuAiNWAAAAV4"]
[Tue Jul 21 07:56:53.555466 2026] [security2:error] [pid 341679:tid 341848] [client 122.164.127.47:53549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QdQWat-noHLkDuAiNWgAAATE"]
[Tue Jul 21 07:56:53.555592 2026] [security2:error] [pid 341679:tid 341848] [client 122.164.127.47:53549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QdQWat-noHLkDuAiNWgAAATE"]
[Tue Jul 21 07:56:53.576148 2026] [security2:error] [pid 341679:tid 341786] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QdQWat-noHLkDuAiNWwABVGo"]
[Tue Jul 21 07:56:53.576298 2026] [security2:error] [pid 341679:tid 341883] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QdQWat-noHLkDuAiNWwABVGo"]
[Tue Jul 21 07:56:53.703994 2026] [security2:error] [pid 341679:tid 341710] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/admin.php"] [unique_id "al9QdQWat-noHLkDuAiNXwABFx4"]
[Tue Jul 21 07:56:53.769840 2026] [security2:error] [pid 341679:tid 341902] [client 20.151.10.161:17382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/dr.php"] [unique_id "al9QdQWat-noHLkDuAiNYgAAAWc"]
[Tue Jul 21 07:56:53.835038 2026] [security2:error] [pid 341679:tid 341832] [client 20.104.96.117:46408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/cilus.php"] [unique_id "al9QdQWat-noHLkDuAiNYwAAASE"]
[Tue Jul 21 07:56:53.989123 2026] [security2:error] [pid 341679:tid 341855] [client 204.8.98.45:47668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9QdQWat-noHLkDuAiNbAAAATg"]
[Tue Jul 21 07:56:53.989252 2026] [security2:error] [pid 341679:tid 341855] [client 204.8.98.45:47668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9QdQWat-noHLkDuAiNbAAAATg"]
[Tue Jul 21 07:56:54.123082 2026] [security2:error] [pid 341679:tid 341826] [client 20.104.96.117:46411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/gptsh.php"] [unique_id "al9QdgWat-noHLkDuAiNbwAAARs"]
[Tue Jul 21 07:56:54.166223 2026] [security2:error] [pid 341679:tid 341864] [client 20.151.10.161:17387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/file31.php"] [unique_id "al9QdgWat-noHLkDuAiNcwAAAUE"]
[Tue Jul 21 07:56:54.234769 2026] [security2:error] [pid 341679:tid 341779] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/k.php"] [unique_id "al9QdgWat-noHLkDuAiNdQABiGM"]
[Tue Jul 21 07:56:54.249975 2026] [security2:error] [pid 341679:tid 341745] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/x.php"] [unique_id "al9QdgWat-noHLkDuAiNdgABQkE"]
[Tue Jul 21 07:56:54.264760 2026] [security2:error] [pid 341679:tid 341777] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wss.php"] [unique_id "al9QdgWat-noHLkDuAiNdwABIGE"]
[Tue Jul 21 07:56:54.293424 2026] [security2:error] [pid 341679:tid 341807] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/ty.php"] [unique_id "al9QdgWat-noHLkDuAiNeAABYX8"]
[Tue Jul 21 07:56:54.308415 2026] [security2:error] [pid 341679:tid 341740] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/155.php"] [unique_id "al9QdgWat-noHLkDuAiNeQABHDw"]
[Tue Jul 21 07:56:54.343941 2026] [security2:error] [pid 341679:tid 341729] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/ops.php"] [unique_id "al9QdgWat-noHLkDuAiNegABNTE"]
[Tue Jul 21 07:56:54.351710 2026] [security2:error] [pid 341679:tid 341878] [client 20.151.10.161:29063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/by.php"] [unique_id "al9QdgWat-noHLkDuAiNewAAAU8"]
[Tue Jul 21 07:56:54.358545 2026] [security2:error] [pid 341679:tid 341747] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/ingfo.php"] [unique_id "al9QdgWat-noHLkDuAiNfAABDkM"]
[Tue Jul 21 07:56:54.373312 2026] [security2:error] [pid 341679:tid 341791] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/error_log.php"] [unique_id "al9QdgWat-noHLkDuAiNfgABUG8"]
[Tue Jul 21 07:56:54.421409 2026] [security2:error] [pid 341679:tid 341890] [client 20.104.96.117:62749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/rithin.php"] [unique_id "al9QdgWat-noHLkDuAiNhQAAAVs"]
[Tue Jul 21 07:56:54.525594 2026] [security2:error] [pid 341679:tid 341849] [client 172.245.102.31:62937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QdgWat-noHLkDuAiNfQAAATI"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:56:54.531678 2026] [security2:error] [pid 341679:tid 341906] [client 20.151.10.161:17309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/file6.php"] [unique_id "al9QdgWat-noHLkDuAiNjwAAAWs"]
[Tue Jul 21 07:56:54.563890 2026] [security2:error] [pid 341679:tid 341818] [client 109.60.28.94:58096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QdgWat-noHLkDuAiNkAAAARM"]
[Tue Jul 21 07:56:54.564014 2026] [security2:error] [pid 341679:tid 341818] [client 109.60.28.94:58096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QdgWat-noHLkDuAiNkAAAARM"]
[Tue Jul 21 07:56:54.654048 2026] [security2:error] [pid 341679:tid 341790] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QdgWat-noHLkDuAiNlQABZG4"]
[Tue Jul 21 07:56:54.654168 2026] [security2:error] [pid 341679:tid 341899] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QdgWat-noHLkDuAiNlQABZG4"]
[Tue Jul 21 07:56:54.756604 2026] [security2:error] [pid 341679:tid 341840] [client 20.104.96.117:62781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/fffm.php"] [unique_id "al9QdgWat-noHLkDuAiNnwAAASk"]
[Tue Jul 21 07:56:54.800680 2026] [security2:error] [pid 341679:tid 341700] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/ok.php"] [unique_id "al9QdgWat-noHLkDuAiNpQABYRQ"]
[Tue Jul 21 07:56:54.815303 2026] [security2:error] [pid 341679:tid 341739] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/mac.php"] [unique_id "al9QdgWat-noHLkDuAiNpgABgDs"]
[Tue Jul 21 07:56:54.829277 2026] [security2:error] [pid 341679:tid 341794] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wefile.php"] [unique_id "al9QdgWat-noHLkDuAiNpwABT3I"]
[Tue Jul 21 07:56:54.845554 2026] [security2:error] [pid 341679:tid 341706] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9QdgWat-noHLkDuAiNqAABUBo"]
[Tue Jul 21 07:56:54.894172 2026] [security2:error] [pid 341679:tid 341750] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al9QdgWat-noHLkDuAiNrAABekY"]
[Tue Jul 21 07:56:54.909080 2026] [security2:error] [pid 341679:tid 341715] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-admin/js/"] [unique_id "al9QdgWat-noHLkDuAiNrQABYCM"]
[Tue Jul 21 07:56:54.925225 2026] [security2:error] [pid 341679:tid 341785] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9QdgWat-noHLkDuAiNrgABOmk"]
[Tue Jul 21 07:56:54.942742 2026] [security2:error] [pid 341679:tid 341773] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wordpress/wp-admin/maint/"] [unique_id "al9QdgWat-noHLkDuAiNsgABc10"]
[Tue Jul 21 07:56:54.952006 2026] [security2:error] [pid 341679:tid 341742] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QdgWat-noHLkDuAiNswABNj4"]
[Tue Jul 21 07:56:54.952200 2026] [security2:error] [pid 341679:tid 341853] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QdgWat-noHLkDuAiNswABNj4"]
[Tue Jul 21 07:56:54.976373 2026] [security2:error] [pid 341679:tid 341849] [client 20.151.10.161:17392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/file15.php"] [unique_id "al9QdgWat-noHLkDuAiNtAAAATI"]
[Tue Jul 21 07:56:55.092830 2026] [security2:error] [pid 341679:tid 341812] [client 20.104.96.117:46349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/dfre.php"] [unique_id "al9QdwWat-noHLkDuAiNuQAAAQ0"]
[Tue Jul 21 07:56:55.096039 2026] [security2:error] [pid 341679:tid 341836] [client 20.226.60.151:59976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/vssrs.php"] [unique_id "al9QdwWat-noHLkDuAiNugAAASU"]
[Tue Jul 21 07:56:55.198058 2026] [security2:error] [pid 341679:tid 341681] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/like.php"] [unique_id "al9QdwWat-noHLkDuAiNvwABXQE"]
[Tue Jul 21 07:56:55.213461 2026] [security2:error] [pid 341679:tid 341722] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/.well-known/about.php"] [unique_id "al9QdwWat-noHLkDuAiNwAABRSo"]
[Tue Jul 21 07:56:55.274715 2026] [security2:error] [pid 341679:tid 341737] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9QdwWat-noHLkDuAiNwQABJjk"]
[Tue Jul 21 07:56:55.289514 2026] [security2:error] [pid 341679:tid 341797] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-admin/css/"] [unique_id "al9QdwWat-noHLkDuAiNwgABK3U"]
[Tue Jul 21 07:56:55.304703 2026] [security2:error] [pid 341679:tid 341732] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al9QdwWat-noHLkDuAiNwwABGzQ"]
[Tue Jul 21 07:56:55.320562 2026] [security2:error] [pid 341679:tid 341769] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/pucci.php"] [unique_id "al9QdwWat-noHLkDuAiNxAABdVk"]
[Tue Jul 21 07:56:55.359930 2026] [security2:error] [pid 341679:tid 341698] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-includes/blocks/details/"] [unique_id "al9QdwWat-noHLkDuAiNxwABPRI"]
[Tue Jul 21 07:56:55.380775 2026] [security2:error] [pid 341679:tid 341905] [client 20.104.96.117:62761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/wp-happy.php"] [unique_id "al9QdwWat-noHLkDuAiNyQAAAWo"]
[Tue Jul 21 07:56:55.499562 2026] [security2:error] [pid 341679:tid 341900] [client 20.151.10.161:28691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/FAQ.php"] [unique_id "al9QdwWat-noHLkDuAiN0gAAAWU"]
[Tue Jul 21 07:56:55.518627 2026] [security2:error] [pid 341679:tid 341858] [client 74.249.245.134:5524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/file3.php"] [unique_id "al9QdwWat-noHLkDuAiN0wAAATs"]
[Tue Jul 21 07:56:55.523146 2026] [security2:error] [pid 341679:tid 341827] [client 20.151.10.161:17403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/jp.php"] [unique_id "al9QdwWat-noHLkDuAiN1AAAARw"]
[Tue Jul 21 07:56:55.673822 2026] [security2:error] [pid 341679:tid 341876] [client 20.104.96.117:65448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/fpr4.php"] [unique_id "al9QdwWat-noHLkDuAiN1gAAAU0"]
[Tue Jul 21 07:56:55.767222 2026] [security2:error] [pid 341679:tid 341895] [client 20.226.60.151:50563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/yawa.php"] [unique_id "al9QdwWat-noHLkDuAiN2wAAAWA"]
[Tue Jul 21 07:56:55.862400 2026] [security2:error] [pid 341679:tid 341816] [client 41.68.90.219:61691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QdwWat-noHLkDuAiN3wAAARE"]
[Tue Jul 21 07:56:55.863628 2026] [security2:error] [pid 341679:tid 341816] [client 41.68.90.219:61691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QdwWat-noHLkDuAiN3wAAARE"]
[Tue Jul 21 07:56:55.972974 2026] [security2:error] [pid 341679:tid 341933] [client 20.104.96.117:62834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/file88.php"] [unique_id "al9QdwWat-noHLkDuAiN4QAAAYY"]
[Tue Jul 21 07:56:56.054414 2026] [security2:error] [pid 341679:tid 341755] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QeAWat-noHLkDuAiN5AABJUs"]
[Tue Jul 21 07:56:56.054555 2026] [security2:error] [pid 341679:tid 341836] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QeAWat-noHLkDuAiN5AABJUs"]
[Tue Jul 21 07:56:56.065030 2026] [security2:error] [pid 341679:tid 341871] [client 178.153.91.96:2629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QeAWat-noHLkDuAiN5gAAAUg"]
[Tue Jul 21 07:56:56.065148 2026] [security2:error] [pid 341679:tid 341871] [client 178.153.91.96:2629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QeAWat-noHLkDuAiN5gAAAUg"]
[Tue Jul 21 07:56:56.070718 2026] [security2:error] [pid 341679:tid 341911] [client 20.151.10.161:17297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/f35.php"] [unique_id "al9QeAWat-noHLkDuAiN6AAAAXA"]
[Tue Jul 21 07:56:56.093059 2026] [security2:error] [pid 341679:tid 341897] [client 20.206.105.145:28630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/insc.php"] [unique_id "al9QeAWat-noHLkDuAiN6gAAAWI"]
[Tue Jul 21 07:56:56.174588 2026] [security2:error] [pid 341679:tid 341823] [client 117.210.135.0:49973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QdQWat-noHLkDuAiNYAAAARg"]
[Tue Jul 21 07:56:56.246286 2026] [security2:error] [pid 341679:tid 341835] [client 59.93.4.33:60901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QeAWat-noHLkDuAiN7wAAASQ"]
[Tue Jul 21 07:56:56.246609 2026] [security2:error] [pid 341679:tid 341835] [client 59.93.4.33:60901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QeAWat-noHLkDuAiN7wAAASQ"]
[Tue Jul 21 07:56:56.258894 2026] [security2:error] [pid 341679:tid 341840] [client 20.104.96.117:62763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ccc.php"] [unique_id "al9QeAWat-noHLkDuAiN8AAAASk"]
[Tue Jul 21 07:56:56.411860 2026] [security2:error] [pid 341679:tid 341825] [client 20.151.10.161:17366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wp-load.php"] [unique_id "al9QeAWat-noHLkDuAiN9AAAARo"]
[Tue Jul 21 07:56:56.437202 2026] [security2:error] [pid 341679:tid 341922] [client 38.100.221.102:17631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QeAWat-noHLkDuAiN9QAAAXs"]
[Tue Jul 21 07:56:56.437297 2026] [security2:error] [pid 341679:tid 341922] [client 38.100.221.102:17631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QeAWat-noHLkDuAiN9QAAAXs"]
[Tue Jul 21 07:56:56.488958 2026] [security2:error] [pid 341679:tid 341935] [client 20.226.60.151:59912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wicked.php"] [unique_id "al9QeAWat-noHLkDuAiN9gAAAYg"]
[Tue Jul 21 07:56:56.546667 2026] [security2:error] [pid 341679:tid 341889] [client 202.143.127.214:54394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QeAWat-noHLkDuAiN-QAAAVo"]
[Tue Jul 21 07:56:56.546783 2026] [security2:error] [pid 341679:tid 341889] [client 202.143.127.214:54394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QeAWat-noHLkDuAiN-QAAAVo"]
[Tue Jul 21 07:56:56.586779 2026] [security2:error] [pid 341679:tid 341858] [client 20.104.96.117:62751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/777.php"] [unique_id "al9QeAWat-noHLkDuAiN_QAAATs"]
[Tue Jul 21 07:56:56.888404 2026] [security2:error] [pid 341679:tid 341851] [client 20.104.96.117:46380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/for.php"] [unique_id "al9QeAWat-noHLkDuAiOAgAAATQ"]
[Tue Jul 21 07:56:56.904175 2026] [security2:error] [pid 341679:tid 341864] [client 117.247.80.59:19665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QeAWat-noHLkDuAiOAwAAAUE"]
[Tue Jul 21 07:56:56.904275 2026] [security2:error] [pid 341679:tid 341864] [client 117.247.80.59:19665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QeAWat-noHLkDuAiOAwAAAUE"]
[Tue Jul 21 07:56:56.943433 2026] [autoindex:error] [pid 341679:tid 341845] [client 20.151.10.161:0] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:57.182213 2026] [security2:error] [pid 341679:tid 341894] [client 136.144.33.103:63657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QeQWat-noHLkDuAiODAAAAV8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:56:57.215414 2026] [security2:error] [pid 341679:tid 341821] [client 20.104.96.117:65417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/ssla.php"] [unique_id "al9QeQWat-noHLkDuAiODgAAARY"]
[Tue Jul 21 07:56:57.239112 2026] [security2:error] [pid 341679:tid 341762] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-includes/blocks/audio/"] [unique_id "al9QeQWat-noHLkDuAiOEgABS1I"]
[Tue Jul 21 07:56:57.268416 2026] [security2:error] [pid 341679:tid 341760] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-temp.php"] [unique_id "al9QeQWat-noHLkDuAiOFAABI1A"]
[Tue Jul 21 07:56:57.288851 2026] [autoindex:error] [pid 341679:tid 341871] [client 20.151.10.161:17272] AH01276: Cannot serve directory /home2/valmi544/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:56:57.321629 2026] [security2:error] [pid 341679:tid 341893] [client 74.249.245.134:5515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/wp-mail.php"] [unique_id "al9QeQWat-noHLkDuAiOGQAAAV4"]
[Tue Jul 21 07:56:57.337027 2026] [security2:error] [pid 341679:tid 341767] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-includes/blocks/buttons/"] [unique_id "al9QeQWat-noHLkDuAiOGgABV1c"]
[Tue Jul 21 07:56:57.347344 2026] [security2:error] [pid 341679:tid 341899] [client 20.104.96.117:55029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9QeQWat-noHLkDuAiOGwAAAWQ"]
[Tue Jul 21 07:56:57.366459 2026] [security2:error] [pid 341679:tid 341919] [client 20.226.60.151:61616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9QeQWat-noHLkDuAiOHAAAAXg"]
[Tue Jul 21 07:56:57.369902 2026] [security2:error] [pid 341679:tid 341680] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/xmu.php"] [unique_id "al9QeQWat-noHLkDuAiOHQABaAA"]
[Tue Jul 21 07:56:57.392210 2026] [security2:error] [pid 341679:tid 341733] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9QeQWat-noHLkDuAiOHgABgTU"]
[Tue Jul 21 07:56:57.427470 2026] [security2:error] [pid 341679:tid 341835] [client 20.151.10.161:17272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9QeQWat-noHLkDuAiOIQAAASQ"]
[Tue Jul 21 07:56:57.444474 2026] [security2:error] [pid 341679:tid 341717] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/puc.php"] [unique_id "al9QeQWat-noHLkDuAiOIgABGyU"]
[Tue Jul 21 07:56:57.483220 2026] [security2:error] [pid 341679:tid 341770] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/themes.php"] [unique_id "al9QeQWat-noHLkDuAiOIwABRlo"]
[Tue Jul 21 07:56:57.499165 2026] [security2:error] [pid 341679:tid 341708] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-includes/Requests/"] [unique_id "al9QeQWat-noHLkDuAiOJQABPRw"]
[Tue Jul 21 07:56:57.531243 2026] [security2:error] [pid 341679:tid 341888] [client 20.104.96.117:46375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alperembalagens.com.br"] [uri "/zc-131.php"] [unique_id "al9QeQWat-noHLkDuAiOJgAAAVk"]
[Tue Jul 21 07:56:57.544017 2026] [security2:error] [pid 341679:tid 341705] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/8.php"] [unique_id "al9QeQWat-noHLkDuAiOKAABDBk"]
[Tue Jul 21 07:56:57.604072 2026] [security2:error] [pid 341679:tid 341694] [remote 20.206.105.145:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.digiterapia.com.br"] [uri "/1.php"] [unique_id "al9QeQWat-noHLkDuAiOKgABQg4"]
[Tue Jul 21 07:56:57.604176 2026] [security2:error] [pid 341679:tid 341694] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/1.php"] [unique_id "al9QeQWat-noHLkDuAiOKgABQg4"]
[Tue Jul 21 07:56:57.618749 2026] [security2:error] [pid 341679:tid 341782] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/100.php"] [unique_id "al9QeQWat-noHLkDuAiOKwABImY"]
[Tue Jul 21 07:56:57.633517 2026] [security2:error] [pid 341679:tid 341748] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/about.php"] [unique_id "al9QeQWat-noHLkDuAiOLgABe0Q"]
[Tue Jul 21 07:56:57.660810 2026] [security2:error] [pid 341679:tid 341820] [client 45.3.38.161:51305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.38.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QeQWat-noHLkDuAiOJAAAARU"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:56:57.696098 2026] [access_compat:error] [pid 341679:tid 341915] [client 162.241.63.68:35424] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:56:57.755229 2026] [security2:error] [pid 341679:tid 341858] [client 20.226.60.151:60006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/24.php"] [unique_id "al9QeQWat-noHLkDuAiOMwAAATs"]
[Tue Jul 21 07:56:57.946193 2026] [security2:error] [pid 341679:tid 341891] [client 20.151.10.161:29081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/coffexium.php"] [unique_id "al9QeQWat-noHLkDuAiONwAAAVw"]
[Tue Jul 21 07:56:57.972920 2026] [security2:error] [pid 341679:tid 341793] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QeQWat-noHLkDuAiOOAABfHE"]
[Tue Jul 21 07:56:57.973041 2026] [security2:error] [pid 341679:tid 341923] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QeQWat-noHLkDuAiOOAABfHE"]
[Tue Jul 21 07:56:58.062915 2026] [security2:error] [pid 341679:tid 341914] [client 20.151.10.161:17317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wp-links.php"] [unique_id "al9QegWat-noHLkDuAiOOQAAAXM"]
[Tue Jul 21 07:56:58.094329 2026] [security2:error] [pid 341679:tid 341863] [client 20.226.60.151:56791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/js.php"] [unique_id "al9QegWat-noHLkDuAiOOgAAAUA"]
[Tue Jul 21 07:56:58.452998 2026] [security2:error] [pid 341679:tid 341898] [client 139.167.225.182:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QegWat-noHLkDuAiORAAAAWM"]
[Tue Jul 21 07:56:58.453097 2026] [security2:error] [pid 341679:tid 341898] [client 139.167.225.182:54436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QegWat-noHLkDuAiORAAAAWM"]
[Tue Jul 21 07:56:58.468336 2026] [security2:error] [pid 341679:tid 341934] [client 92.119.178.3:52636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9QegWat-noHLkDuAiORQAAAYc"]
[Tue Jul 21 07:56:58.468432 2026] [security2:error] [pid 341679:tid 341934] [client 92.119.178.3:52636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9QegWat-noHLkDuAiORQAAAYc"]
[Tue Jul 21 07:56:58.501383 2026] [security2:error] [pid 341679:tid 341847] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9QegWat-noHLkDuAiOQwABMFg"]
[Tue Jul 21 07:56:58.517468 2026] [security2:error] [pid 341679:tid 341886] [client 20.151.10.161:17223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/solo1.php"] [unique_id "al9QegWat-noHLkDuAiORgAAAVc"]
[Tue Jul 21 07:56:58.517697 2026] [security2:error] [pid 341679:tid 341881] [client 87.116.180.198:13919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QegWat-noHLkDuAiORwAAAVI"]
[Tue Jul 21 07:56:58.517826 2026] [security2:error] [pid 341679:tid 341881] [client 87.116.180.198:13919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QegWat-noHLkDuAiORwAAAVI"]
[Tue Jul 21 07:56:58.692051 2026] [security2:error] [pid 341679:tid 341835] [client 20.151.10.161:28847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/red.php"] [unique_id "al9QegWat-noHLkDuAiOTAAAASQ"]
[Tue Jul 21 07:56:58.775220 2026] [security2:error] [pid 341679:tid 341864] [client 223.236.153.128:5127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QegWat-noHLkDuAiOTQAAAUE"]
[Tue Jul 21 07:56:58.775321 2026] [security2:error] [pid 341679:tid 341864] [client 223.236.153.128:5127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QegWat-noHLkDuAiOTQAAAUE"]
[Tue Jul 21 07:56:58.795508 2026] [security2:error] [pid 341679:tid 341682] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/about.php"] [unique_id "al9QegWat-noHLkDuAiOTgABDAI"]
[Tue Jul 21 07:56:58.922762 2026] [security2:error] [pid 341679:tid 341922] [client 20.151.10.161:17404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/sixxis.php"] [unique_id "al9QegWat-noHLkDuAiOUgAAAXs"]
[Tue Jul 21 07:56:58.960716 2026] [security2:error] [pid 341679:tid 341836] [client 182.8.255.181:2883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QegWat-noHLkDuAiOVgAAASU"]
[Tue Jul 21 07:56:58.960833 2026] [security2:error] [pid 341679:tid 341836] [client 182.8.255.181:2883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QegWat-noHLkDuAiOVgAAASU"]
[Tue Jul 21 07:56:58.999069 2026] [security2:error] [pid 341679:tid 341831] [client 20.206.105.145:55863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9QegWat-noHLkDuAiOVwAAASA"]
[Tue Jul 21 07:56:59.055232 2026] [security2:error] [pid 341679:tid 341727] [remote 202.92.5.232:34762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.5.92.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QewWat-noHLkDuAiOWAABVS8"]
[Tue Jul 21 07:56:59.055389 2026] [security2:error] [pid 341679:tid 341884] [client 202.92.5.232:34762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QewWat-noHLkDuAiOWAABVS8"]
[Tue Jul 21 07:56:59.057760 2026] [security2:error] [pid 341679:tid 341913] [client 20.226.60.151:59937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/xacs.php"] [unique_id "al9QewWat-noHLkDuAiOWQAAAXI"]
[Tue Jul 21 07:56:59.329266 2026] [security2:error] [pid 341679:tid 341861] [client 20.151.10.161:17298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/2P.update.php"] [unique_id "al9QewWat-noHLkDuAiOZQAAAT4"]
[Tue Jul 21 07:56:59.391314 2026] [security2:error] [pid 341679:tid 341892] [client 122.162.144.145:27455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QewWat-noHLkDuAiOaQAAAV0"]
[Tue Jul 21 07:56:59.391454 2026] [security2:error] [pid 341679:tid 341892] [client 122.162.144.145:27455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QewWat-noHLkDuAiOaQAAAV0"]
[Tue Jul 21 07:56:59.414085 2026] [security2:error] [pid 341679:tid 341759] [remote 185.213.175.37:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.alphafix.com.br"] [uri "/"] [unique_id "al9QewWat-noHLkDuAiObQABVk8"]
[Tue Jul 21 07:56:59.429629 2026] [security2:error] [pid 341679:tid 341936] [client 65.21.113.253:59226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QewWat-noHLkDuAiObgAAAYk"]
[Tue Jul 21 07:56:59.461657 2026] [security2:error] [pid 341679:tid 341868] [client 106.215.181.8:11687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QewWat-noHLkDuAiObwAAAUU"]
[Tue Jul 21 07:56:59.461780 2026] [security2:error] [pid 341679:tid 341868] [client 106.215.181.8:11687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QewWat-noHLkDuAiObwAAAUU"]
[Tue Jul 21 07:56:59.489787 2026] [security2:error] [pid 341679:tid 341805] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/admin.php"] [unique_id "al9QewWat-noHLkDuAiOdAABX30"]
[Tue Jul 21 07:56:59.535905 2026] [security2:error] [pid 341679:tid 341871] [client 20.226.60.151:50678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/core.php"] [unique_id "al9QewWat-noHLkDuAiOeAAAAUg"]
[Tue Jul 21 07:56:59.716338 2026] [security2:error] [pid 341679:tid 341689] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/admin.php"] [unique_id "al9QewWat-noHLkDuAiOewABbwk"]
[Tue Jul 21 07:56:59.724588 2026] [security2:error] [pid 341679:tid 341898] [client 20.151.10.161:17232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/a.php"] [unique_id "al9QewWat-noHLkDuAiOfQAAAWM"]
[Tue Jul 21 07:56:59.728160 2026] [security2:error] [pid 341679:tid 341933] [client 92.119.178.3:51640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9QewWat-noHLkDuAiOfgAAAYY"]
[Tue Jul 21 07:56:59.728242 2026] [security2:error] [pid 341679:tid 341933] [client 92.119.178.3:51640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9QewWat-noHLkDuAiOfgAAAYY"]
[Tue Jul 21 07:56:59.738165 2026] [security2:error] [pid 341679:tid 341934] [client 20.151.10.161:28851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9QewWat-noHLkDuAiOgAAAAYc"]
[Tue Jul 21 07:56:59.740270 2026] [security2:error] [pid 341679:tid 341779] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/edit.php"] [unique_id "al9QewWat-noHLkDuAiOggABV2M"]
[Tue Jul 21 07:56:59.761647 2026] [security2:error] [pid 341679:tid 341777] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9QewWat-noHLkDuAiOhQABJGE"]
[Tue Jul 21 07:56:59.809298 2026] [security2:error] [pid 341679:tid 341740] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/f6.php"] [unique_id "al9QewWat-noHLkDuAiOiQABPTw"]
[Tue Jul 21 07:56:59.825000 2026] [security2:error] [pid 341679:tid 341729] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/inputs.php"] [unique_id "al9QewWat-noHLkDuAiOigABWTE"]
[Tue Jul 21 07:56:59.877434 2026] [security2:error] [pid 341679:tid 341791] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/inputs.php"] [unique_id "al9QewWat-noHLkDuAiOjAABK28"]
[Tue Jul 21 07:56:59.899269 2026] [security2:error] [pid 341679:tid 341831] [client 74.249.245.134:5550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/about.php"] [unique_id "al9QewWat-noHLkDuAiOjQAAASA"]
[Tue Jul 21 07:56:59.930518 2026] [security2:error] [pid 341679:tid 341763] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/av.php"] [unique_id "al9QewWat-noHLkDuAiOjwABR1M"]
[Tue Jul 21 07:56:59.953846 2026] [security2:error] [pid 341679:tid 341783] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/classwithtostring.php"] [unique_id "al9QewWat-noHLkDuAiOkAABg2c"]
[Tue Jul 21 07:56:59.972703 2026] [security2:error] [pid 341679:tid 341683] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9QewWat-noHLkDuAiOkQABVQM"]
[Tue Jul 21 07:57:00.035085 2026] [security2:error] [pid 341679:tid 341904] [client 20.151.10.161:17220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/k.php"] [unique_id "al9QfAWat-noHLkDuAiOlQAAAWk"]
[Tue Jul 21 07:57:00.036452 2026] [security2:error] [pid 341679:tid 341716] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-blog.php"] [unique_id "al9QfAWat-noHLkDuAiOlgABDiQ"]
[Tue Jul 21 07:57:00.052857 2026] [security2:error] [pid 341679:tid 341790] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-includes/js/jquery/"] [unique_id "al9QfAWat-noHLkDuAiOlwABUW4"]
[Tue Jul 21 07:57:00.093088 2026] [security2:error] [pid 341679:tid 341752] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9QfAWat-noHLkDuAiOmQABTUg"]
[Tue Jul 21 07:57:00.109351 2026] [security2:error] [pid 341679:tid 341695] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/adminfuns.php"] [unique_id "al9QfAWat-noHLkDuAiOmgABfQ8"]
[Tue Jul 21 07:57:00.124652 2026] [security2:error] [pid 341679:tid 341712] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/goods.php"] [unique_id "al9QfAWat-noHLkDuAiOmwABVCA"]
[Tue Jul 21 07:57:00.141135 2026] [security2:error] [pid 341679:tid 341771] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/ms-edit.php"] [unique_id "al9QfAWat-noHLkDuAiOnAABJls"]
[Tue Jul 21 07:57:00.158299 2026] [security2:error] [pid 341679:tid 341784] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/222.php"] [unique_id "al9QfAWat-noHLkDuAiOnQABXGg"]
[Tue Jul 21 07:57:00.175040 2026] [security2:error] [pid 341679:tid 341816] [client 103.166.103.129:51478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QfAWat-noHLkDuAiOngAAARE"]
[Tue Jul 21 07:57:00.175162 2026] [security2:error] [pid 341679:tid 341816] [client 103.166.103.129:51478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QfAWat-noHLkDuAiOngAAARE"]
[Tue Jul 21 07:57:00.175588 2026] [security2:error] [pid 341679:tid 341700] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9QfAWat-noHLkDuAiOnwABWxQ"]
[Tue Jul 21 07:57:00.221311 2026] [security2:error] [pid 341679:tid 341787] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-includes/css/dist/"] [unique_id "al9QfAWat-noHLkDuAiOowABhGs"]
[Tue Jul 21 07:57:00.236998 2026] [security2:error] [pid 341679:tid 341803] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9QfAWat-noHLkDuAiOpQABLns"]
[Tue Jul 21 07:57:00.253148 2026] [security2:error] [pid 341679:tid 341706] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-includes/l10n/"] [unique_id "al9QfAWat-noHLkDuAiOqAABeho"]
[Tue Jul 21 07:57:00.268202 2026] [security2:error] [pid 341679:tid 341750] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-content/uploads/"] [unique_id "al9QfAWat-noHLkDuAiOqgABM0Y"]
[Tue Jul 21 07:57:00.307141 2026] [security2:error] [pid 341679:tid 341715] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/raw.php"] [unique_id "al9QfAWat-noHLkDuAiOqwABiSM"]
[Tue Jul 21 07:57:00.325887 2026] [security2:error] [pid 341679:tid 341773] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/abcd.php"] [unique_id "al9QfAWat-noHLkDuAiOrgABMl0"]
[Tue Jul 21 07:57:00.341349 2026] [security2:error] [pid 341679:tid 341751] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/a1.php"] [unique_id "al9QfAWat-noHLkDuAiOsAABS0c"]
[Tue Jul 21 07:57:00.352977 2026] [security2:error] [pid 341679:tid 341894] [client 20.104.96.117:57443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/albin.php"] [unique_id "al9QfAWat-noHLkDuAiOsQAAAV8"]
[Tue Jul 21 07:57:00.358622 2026] [security2:error] [pid 341679:tid 341911] [client 20.151.10.161:17402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/w.php"] [unique_id "al9QfAWat-noHLkDuAiOsgAAAXA"]
[Tue Jul 21 07:57:00.363043 2026] [security2:error] [pid 341679:tid 341742] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9QfAWat-noHLkDuAiOswABXj4"]
[Tue Jul 21 07:57:00.409327 2026] [security2:error] [pid 341679:tid 341711] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9QfAWat-noHLkDuAiOtAABbx8"]
[Tue Jul 21 07:57:00.427394 2026] [security2:error] [pid 341679:tid 341898] [client 20.226.60.151:61627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/ss.php"] [unique_id "al9QfAWat-noHLkDuAiOtQAAAWM"]
[Tue Jul 21 07:57:00.437765 2026] [security2:error] [pid 341679:tid 341758] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9QfAWat-noHLkDuAiOtgABhk4"]
[Tue Jul 21 07:57:00.453410 2026] [security2:error] [pid 341679:tid 341788] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-content/"] [unique_id "al9QfAWat-noHLkDuAiOtwABh2w"]
[Tue Jul 21 07:57:00.468263 2026] [security2:error] [pid 341679:tid 341766] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/simple.php"] [unique_id "al9QfAWat-noHLkDuAiO1wABIVY"]
[Tue Jul 21 07:57:00.478765 2026] [security2:error] [pid 341679:tid 341838] [client 65.21.113.253:54006] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QfAWat-noHLkDuAiOmAAAASc"]
[Tue Jul 21 07:57:00.656500 2026] [security2:error] [pid 341679:tid 341811] [client 20.226.60.151:61621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/min.php"] [unique_id "al9QfAWat-noHLkDuAiO3QAAAQw"]
[Tue Jul 21 07:57:00.702697 2026] [security2:error] [pid 341679:tid 341810] [client 103.78.200.11:54307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QfAWat-noHLkDuAiO6QAAAQs"]
[Tue Jul 21 07:57:00.704502 2026] [security2:error] [pid 341679:tid 341810] [client 103.78.200.11:54307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QfAWat-noHLkDuAiO6QAAAQs"]
[Tue Jul 21 07:57:00.761318 2026] [security2:error] [pid 341679:tid 341733] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/xxx.php"] [unique_id "al9QfAWat-noHLkDuAiO6gABYTU"]
[Tue Jul 21 07:57:00.780284 2026] [security2:error] [pid 341679:tid 341913] [client 103.29.114.44:60137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QfAWat-noHLkDuAiO7AAAAXI"]
[Tue Jul 21 07:57:00.780448 2026] [security2:error] [pid 341679:tid 341913] [client 103.29.114.44:60137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QfAWat-noHLkDuAiO7AAAAXI"]
[Tue Jul 21 07:57:00.812789 2026] [security2:error] [pid 341679:tid 341770] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/hypo.php"] [unique_id "al9QfAWat-noHLkDuAiO8AABg1o"]
[Tue Jul 21 07:57:00.852553 2026] [security2:error] [pid 341679:tid 341925] [client 92.119.178.3:51648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9QfAWat-noHLkDuAiO8QAAAX4"]
[Tue Jul 21 07:57:00.852652 2026] [security2:error] [pid 341679:tid 341925] [client 92.119.178.3:51648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9QfAWat-noHLkDuAiO8QAAAX4"]
[Tue Jul 21 07:57:00.858433 2026] [security2:error] [pid 341679:tid 341708] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-admin/css/colors/blue/"] [unique_id "al9QfAWat-noHLkDuAiO8gABaRw"]
[Tue Jul 21 07:57:00.891608 2026] [security2:error] [pid 341679:tid 341694] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/chosen.php"] [unique_id "al9QfAWat-noHLkDuAiO9AABDg4"]
[Tue Jul 21 07:57:00.907515 2026] [security2:error] [pid 341679:tid 341730] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-includes/block-bindings/"] [unique_id "al9QfAWat-noHLkDuAiO9wABUTI"]
[Tue Jul 21 07:57:00.953311 2026] [security2:error] [pid 341679:tid 341837] [client 20.151.10.161:17356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/insc.php"] [unique_id "al9QfAWat-noHLkDuAiO_AAAASY"]
[Tue Jul 21 07:57:00.970081 2026] [security2:error] [pid 341679:tid 341890] [client 74.249.245.134:5523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/adminfuns.php"] [unique_id "al9QfAWat-noHLkDuAiO_QAAAVs"]
[Tue Jul 21 07:57:00.971582 2026] [security2:error] [pid 341679:tid 341724] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/file5.php"] [unique_id "al9QfAWat-noHLkDuAiO_gABbiw"]
[Tue Jul 21 07:57:00.986370 2026] [security2:error] [pid 341679:tid 341746] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/file.php"] [unique_id "al9QfAWat-noHLkDuAiO_wABZkI"]
[Tue Jul 21 07:57:00.987266 2026] [security2:error] [pid 341679:tid 341923] [client 20.226.60.151:50522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/19.php"] [unique_id "al9QfAWat-noHLkDuAiPAAAAAXw"]
[Tue Jul 21 07:57:01.001542 2026] [security2:error] [pid 341679:tid 341738] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/aa2.php"] [unique_id "al9QfQWat-noHLkDuAiPAgABQjo"]
[Tue Jul 21 07:57:01.016827 2026] [security2:error] [pid 341679:tid 341793] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/ccou.php"] [unique_id "al9QfQWat-noHLkDuAiPAwABYHE"]
[Tue Jul 21 07:57:01.072737 2026] [security2:error] [pid 341679:tid 341723] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/dr.php"] [unique_id "al9QfQWat-noHLkDuAiPCgABiSs"]
[Tue Jul 21 07:57:01.092097 2026] [security2:error] [pid 341679:tid 341682] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/file31.php"] [unique_id "al9QfQWat-noHLkDuAiPEQABHwI"]
[Tue Jul 21 07:57:01.107498 2026] [security2:error] [pid 341679:tid 341693] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/file6.php"] [unique_id "al9QfQWat-noHLkDuAiPEwABXw0"]
[Tue Jul 21 07:57:01.178623 2026] [security2:error] [pid 341679:tid 341804] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/file15.php"] [unique_id "al9QfQWat-noHLkDuAiPFQABYnw"]
[Tue Jul 21 07:57:01.201343 2026] [security2:error] [pid 341679:tid 341720] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/jp.php"] [unique_id "al9QfQWat-noHLkDuAiPFwABhig"]
[Tue Jul 21 07:57:01.238515 2026] [security2:error] [pid 341679:tid 341832] [client 20.226.60.151:59975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/zildan.php"] [unique_id "al9QfQWat-noHLkDuAiPGQAAASE"]
[Tue Jul 21 07:57:01.242396 2026] [security2:error] [pid 341679:tid 341727] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/f35.php"] [unique_id "al9QfQWat-noHLkDuAiPGgABRC8"]
[Tue Jul 21 07:57:01.311981 2026] [security2:error] [pid 341679:tid 341847] [client 20.151.10.161:17325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9QfQWat-noHLkDuAiPHwAAATA"]
[Tue Jul 21 07:57:01.398086 2026] [security2:error] [pid 341679:tid 341849] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QfQWat-noHLkDuAiPGwABMm0"]
[Tue Jul 21 07:57:01.402174 2026] [security2:error] [pid 341679:tid 341888] [client 20.151.10.161:29095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/footer.php"] [unique_id "al9QfQWat-noHLkDuAiPJAAAAVk"]
[Tue Jul 21 07:57:01.634778 2026] [security2:error] [pid 341679:tid 341836] [client 20.151.10.161:17318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/u.php"] [unique_id "al9QfQWat-noHLkDuAiPKwAAASU"]
[Tue Jul 21 07:57:01.715824 2026] [security2:error] [pid 341679:tid 341710] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-load.php"] [unique_id "al9QfQWat-noHLkDuAiPLQABOx4"]
[Tue Jul 21 07:57:01.723984 2026] [security2:error] [pid 341679:tid 341816] [client 65.21.113.253:54018] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QfQWat-noHLkDuAiPFgAAARE"]
[Tue Jul 21 07:57:01.731506 2026] [security2:error] [pid 341679:tid 341927] [client 20.104.96.117:54983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/cilus.php"] [unique_id "al9QfQWat-noHLkDuAiPLgAAAYA"]
[Tue Jul 21 07:57:01.787397 2026] [security2:error] [pid 341679:tid 341697] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-includes/assets/"] [unique_id "al9QfQWat-noHLkDuAiPMAABFRE"]
[Tue Jul 21 07:57:01.816537 2026] [security2:error] [pid 341679:tid 341814] [client 136.144.33.97:45557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QfAWat-noHLkDuAiO2gAAAQ8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:01.844070 2026] [security2:error] [pid 341679:tid 341689] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "al9QfQWat-noHLkDuAiPMwABfQk"]
[Tue Jul 21 07:57:02.094529 2026] [security2:error] [pid 341679:tid 341922] [client 122.186.204.214:51548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QfgWat-noHLkDuAiPWAAAAXs"]
[Tue Jul 21 07:57:02.094699 2026] [security2:error] [pid 341679:tid 341922] [client 122.186.204.214:51548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QfgWat-noHLkDuAiPWAAAAXs"]
[Tue Jul 21 07:57:02.112524 2026] [security2:error] [pid 341679:tid 341934] [client 20.151.10.161:17247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/sss.php"] [unique_id "al9QfgWat-noHLkDuAiPWQAAAYc"]
[Tue Jul 21 07:57:02.172449 2026] [security2:error] [pid 341679:tid 341810] [client 122.179.91.63:24598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QfgWat-noHLkDuAiPWgAAAQs"]
[Tue Jul 21 07:57:02.172565 2026] [security2:error] [pid 341679:tid 341810] [client 122.179.91.63:24598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QfgWat-noHLkDuAiPWgAAAQs"]
[Tue Jul 21 07:57:02.192818 2026] [security2:error] [pid 341679:tid 341867] [client 20.151.10.161:28829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-content/index.php"] [unique_id "al9QfgWat-noHLkDuAiPXAAAAUQ"]
[Tue Jul 21 07:57:02.251358 2026] [security2:error] [pid 341679:tid 341729] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9QfgWat-noHLkDuAiPXQABUjE"]
[Tue Jul 21 07:57:02.268301 2026] [security2:error] [pid 341679:tid 341807] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wp-links.php"] [unique_id "al9QfgWat-noHLkDuAiPXgABaH8"]
[Tue Jul 21 07:57:02.284411 2026] [security2:error] [pid 341679:tid 341786] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/solo1.php"] [unique_id "al9QfgWat-noHLkDuAiPXwABDWo"]
[Tue Jul 21 07:57:02.300102 2026] [security2:error] [pid 341679:tid 341774] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/sixxis.php"] [unique_id "al9QfgWat-noHLkDuAiPYAABFl4"]
[Tue Jul 21 07:57:02.315942 2026] [security2:error] [pid 341679:tid 341791] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/2P.update.php"] [unique_id "al9QfgWat-noHLkDuAiPYgABF28"]
[Tue Jul 21 07:57:02.332732 2026] [security2:error] [pid 341679:tid 341763] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/a.php"] [unique_id "al9QfgWat-noHLkDuAiPZQABalM"]
[Tue Jul 21 07:57:02.348534 2026] [security2:error] [pid 341679:tid 341783] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/k.php"] [unique_id "al9QfgWat-noHLkDuAiPZgABKGc"]
[Tue Jul 21 07:57:02.410196 2026] [security2:error] [pid 341679:tid 341930] [client 20.197.192.193:54634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/cro.php"] [unique_id "al9QfgWat-noHLkDuAiPawAAAYM"]
[Tue Jul 21 07:57:02.426279 2026] [security2:error] [pid 341679:tid 341896] [client 20.151.10.161:17324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/sss.php"] [unique_id "al9QfgWat-noHLkDuAiPbQAAAWE"]
[Tue Jul 21 07:57:02.432169 2026] [security2:error] [pid 341679:tid 341752] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QfgWat-noHLkDuAiPbgABNUg"]
[Tue Jul 21 07:57:02.432355 2026] [security2:error] [pid 341679:tid 341852] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QfgWat-noHLkDuAiPbgABNUg"]
[Tue Jul 21 07:57:02.544269 2026] [security2:error] [pid 341679:tid 341927] [client 20.151.10.161:29105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/zoro.php"] [unique_id "al9QfgWat-noHLkDuAiPcgAAAYA"]
[Tue Jul 21 07:57:02.646298 2026] [security2:error] [pid 341679:tid 341910] [client 102.206.115.33:59712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QfgWat-noHLkDuAiPdAAAAW8"]
[Tue Jul 21 07:57:02.646488 2026] [security2:error] [pid 341679:tid 341910] [client 102.206.115.33:59712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QfgWat-noHLkDuAiPdAAAAW8"]
[Tue Jul 21 07:57:02.714253 2026] [security2:error] [pid 341679:tid 341876] [client 20.151.10.161:17303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/c.php"] [unique_id "al9QfgWat-noHLkDuAiPdwAAAU0"]
[Tue Jul 21 07:57:02.851160 2026] [security2:error] [pid 341679:tid 341827] [client 20.226.60.151:56748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/inc.php"] [unique_id "al9QfgWat-noHLkDuAiPeQAAARw"]
[Tue Jul 21 07:57:02.875971 2026] [security2:error] [pid 341679:tid 341931] [client 20.151.10.161:29231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/admin.php"] [unique_id "al9QfgWat-noHLkDuAiPewAAAYQ"]
[Tue Jul 21 07:57:03.068464 2026] [security2:error] [pid 341679:tid 341850] [client 20.151.10.161:17383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/aa.php"] [unique_id "al9QfwWat-noHLkDuAiPgwAAATM"]
[Tue Jul 21 07:57:03.182004 2026] [security2:error] [pid 341679:tid 341860] [client 20.206.105.145:55882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/u.php"] [unique_id "al9QfwWat-noHLkDuAiPhwAAAT0"]
[Tue Jul 21 07:57:03.201605 2026] [security2:error] [pid 341679:tid 341803] [remote 199.189.225.40:44093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9QfwWat-noHLkDuAiPiQABens"]
[Tue Jul 21 07:57:03.210523 2026] [security2:error] [pid 341679:tid 341868] [client 20.151.10.161:29114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/greap.php"] [unique_id "al9QfwWat-noHLkDuAiPjAAAAUU"]
[Tue Jul 21 07:57:03.226532 2026] [security2:error] [pid 341679:tid 341739] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QfwWat-noHLkDuAiPjwABLjs"]
[Tue Jul 21 07:57:03.226655 2026] [security2:error] [pid 341679:tid 341845] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QfwWat-noHLkDuAiPjwABLjs"]
[Tue Jul 21 07:57:03.328035 2026] [security2:error] [pid 341679:tid 341750] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/w.php"] [unique_id "al9QfwWat-noHLkDuAiPlAABckY"]
[Tue Jul 21 07:57:03.345228 2026] [security2:error] [pid 341679:tid 341715] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/insc.php"] [unique_id "al9QfwWat-noHLkDuAiPlQABICM"]
[Tue Jul 21 07:57:03.382903 2026] [security2:error] [pid 341679:tid 341773] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9QfwWat-noHLkDuAiPmAABZV0"]
[Tue Jul 21 07:57:03.384207 2026] [security2:error] [pid 341679:tid 341833] [client 20.151.10.161:17230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/100.php"] [unique_id "al9QfwWat-noHLkDuAiPmgAAASI"]
[Tue Jul 21 07:57:03.439996 2026] [security2:error] [pid 341679:tid 341742] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/u.php"] [unique_id "al9QfwWat-noHLkDuAiPoQABgD4"]
[Tue Jul 21 07:57:03.460523 2026] [security2:error] [pid 341679:tid 341877] [client 74.249.245.134:54348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/php8.php"] [unique_id "al9QfwWat-noHLkDuAiPowAAAU4"]
[Tue Jul 21 07:57:03.482966 2026] [security2:error] [pid 341679:tid 341788] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/sss.php"] [unique_id "al9QfwWat-noHLkDuAiPpwABD2w"]
[Tue Jul 21 07:57:03.512025 2026] [security2:error] [pid 341679:tid 341722] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/sss.php"] [unique_id "al9QfwWat-noHLkDuAiPqgABUSo"]
[Tue Jul 21 07:57:03.528300 2026] [security2:error] [pid 341679:tid 341701] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/c.php"] [unique_id "al9QfwWat-noHLkDuAiPrAABHBU"]
[Tue Jul 21 07:57:03.543983 2026] [security2:error] [pid 341679:tid 341692] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/aa.php"] [unique_id "al9QfwWat-noHLkDuAiPrQABXAw"]
[Tue Jul 21 07:57:03.564216 2026] [security2:error] [pid 341679:tid 341728] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/100.php"] [unique_id "al9QfwWat-noHLkDuAiPrgABVDA"]
[Tue Jul 21 07:57:03.581020 2026] [security2:error] [pid 341679:tid 341780] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/footer.php"] [unique_id "al9QfwWat-noHLkDuAiPrwABHWQ"]
[Tue Jul 21 07:57:03.602886 2026] [security2:error] [pid 341679:tid 341815] [client 20.226.60.151:60014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/csa.php"] [unique_id "al9QfwWat-noHLkDuAiPsAAAARA"]
[Tue Jul 21 07:57:03.639400 2026] [security2:error] [pid 341679:tid 341879] [client 20.151.10.161:28828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/177.php"] [unique_id "al9QfwWat-noHLkDuAiPsQAAAVA"]
[Tue Jul 21 07:57:03.694396 2026] [security2:error] [pid 341679:tid 341810] [client 20.151.10.161:17231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/footer.php"] [unique_id "al9QfwWat-noHLkDuAiPtQAAAQs"]
[Tue Jul 21 07:57:03.768740 2026] [security2:error] [pid 341679:tid 341885] [client 103.86.117.203:50388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QfwWat-noHLkDuAiPtwAAAVY"]
[Tue Jul 21 07:57:03.768895 2026] [security2:error] [pid 341679:tid 341885] [client 103.86.117.203:50388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QfwWat-noHLkDuAiPtwAAAVY"]
[Tue Jul 21 07:57:04.029371 2026] [security2:error] [pid 341679:tid 341889] [client 20.151.10.161:17221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/users.php"] [unique_id "al9QgAWat-noHLkDuAiPvgAAAVo"]
[Tue Jul 21 07:57:04.108535 2026] [security2:error] [pid 341679:tid 341888] [client 20.104.96.117:55007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/gptsh.php"] [unique_id "al9QgAWat-noHLkDuAiPwgAAAVk"]
[Tue Jul 21 07:57:04.185063 2026] [security2:error] [pid 341679:tid 341834] [client 20.151.10.161:29228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/199.php"] [unique_id "al9QgAWat-noHLkDuAiPwwAAASM"]
[Tue Jul 21 07:57:04.192419 2026] [security2:error] [pid 341679:tid 341930] [client 122.164.127.47:54137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QgAWat-noHLkDuAiPxAAAAYM"]
[Tue Jul 21 07:57:04.192500 2026] [security2:error] [pid 341679:tid 341930] [client 122.164.127.47:54137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QgAWat-noHLkDuAiPxAAAAYM"]
[Tue Jul 21 07:57:04.510532 2026] [security2:error] [pid 341679:tid 341872] [client 20.151.10.161:17227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/177.php"] [unique_id "al9QgAWat-noHLkDuAiPygAAAUk"]
[Tue Jul 21 07:57:04.561605 2026] [security2:error] [pid 341679:tid 341877] [client 184.75.221.3:51186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9QgAWat-noHLkDuAiPzwAAAU4"]
[Tue Jul 21 07:57:04.561714 2026] [security2:error] [pid 341679:tid 341877] [client 184.75.221.3:51186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9QgAWat-noHLkDuAiPzwAAAU4"]
[Tue Jul 21 07:57:04.609273 2026] [security2:error] [pid 341679:tid 341702] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QgAWat-noHLkDuAiP0gABbxY"]
[Tue Jul 21 07:57:04.609410 2026] [security2:error] [pid 341679:tid 341910] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QgAWat-noHLkDuAiP0gABbxY"]
[Tue Jul 21 07:57:04.765271 2026] [security2:error] [pid 341679:tid 341737] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/users.php"] [unique_id "al9QgAWat-noHLkDuAiP1QABXDk"]
[Tue Jul 21 07:57:04.783906 2026] [security2:error] [pid 341679:tid 341685] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/177.php"] [unique_id "al9QgAWat-noHLkDuAiP1wABQgU"]
[Tue Jul 21 07:57:04.801207 2026] [security2:error] [pid 341679:tid 341806] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/config.php"] [unique_id "al9QgAWat-noHLkDuAiP2QABdH4"]
[Tue Jul 21 07:57:04.808271 2026] [security2:error] [pid 341679:tid 341816] [client 20.151.10.161:17302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/config.php"] [unique_id "al9QgAWat-noHLkDuAiP2wAAARE"]
[Tue Jul 21 07:57:04.817537 2026] [security2:error] [pid 341679:tid 341868] [client 117.210.135.0:50703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QgAWat-noHLkDuAiP1AAAAUU"]
[Tue Jul 21 07:57:04.833713 2026] [security2:error] [pid 341679:tid 341718] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/gettest.php"] [unique_id "al9QgAWat-noHLkDuAiP3QABECY"]
[Tue Jul 21 07:57:04.840384 2026] [security2:error] [pid 341679:tid 341797] [remote 140.245.231.239:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.231.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9QgAWat-noHLkDuAiP0wABHHU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:57:04.843938 2026] [security2:error] [pid 341679:tid 341732] [remote 140.245.231.239:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.231.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9QgAWat-noHLkDuAiP3gABOjQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:57:04.849909 2026] [security2:error] [pid 341679:tid 341769] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/min.php"] [unique_id "al9QgAWat-noHLkDuAiP3wABN1k"]
[Tue Jul 21 07:57:04.854270 2026] [security2:error] [pid 341679:tid 341922] [client 20.226.60.151:50587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-ppoxua4.php"] [unique_id "al9QgAWat-noHLkDuAiP4AAAAXs"]
[Tue Jul 21 07:57:04.857270 2026] [security2:error] [pid 341679:tid 341801] [remote 140.245.231.239:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.231.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9QgAWat-noHLkDuAiP4QABD3k"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:57:04.866216 2026] [security2:error] [pid 341679:tid 341766] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/edorxrr.php"] [unique_id "al9QgAWat-noHLkDuAiP4gABUFY"]
[Tue Jul 21 07:57:04.903571 2026] [security2:error] [pid 341679:tid 341719] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/hur.php"] [unique_id "al9QgAWat-noHLkDuAiP4wABCyc"]
[Tue Jul 21 07:57:04.920231 2026] [security2:error] [pid 341679:tid 341726] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/zoro.php"] [unique_id "al9QgAWat-noHLkDuAiP5AABSC4"]
[Tue Jul 21 07:57:04.947108 2026] [security2:error] [pid 341679:tid 341687] [remote 140.245.231.239:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.231.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9QgAWat-noHLkDuAiP1gABHwc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:57:05.006967 2026] [security2:error] [pid 341679:tid 341881] [client 20.151.10.161:29111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/file52.php"] [unique_id "al9QgQWat-noHLkDuAiP6gAAAVI"]
[Tue Jul 21 07:57:05.063948 2026] [security2:error] [pid 341679:tid 341767] [remote 5.252.52.249:45814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9QgQWat-noHLkDuAiP7gABT1c"]
[Tue Jul 21 07:57:05.090366 2026] [security2:error] [pid 341679:tid 341839] [client 20.151.10.161:17406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/gettest.php"] [unique_id "al9QgQWat-noHLkDuAiP8gAAASg"]
[Tue Jul 21 07:57:05.186008 2026] [security2:error] [pid 341679:tid 341756] [remote 45.150.79.142:54100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wp-login.php"] [unique_id "al9QgQWat-noHLkDuAiP9QABf0w"]
[Tue Jul 21 07:57:05.228806 2026] [security2:error] [pid 341679:tid 341733] [remote 140.245.231.239:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.231.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9QgQWat-noHLkDuAiP9gABVTU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:57:05.264019 2026] [security2:error] [pid 341679:tid 341770] [remote 140.245.231.239:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.231.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9QgQWat-noHLkDuAiP9wABW1o"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:57:05.284256 2026] [security2:error] [pid 341679:tid 341741] [remote 140.245.231.239:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.231.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9QgQWat-noHLkDuAiP-QABKz0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:57:05.370541 2026] [security2:error] [pid 341679:tid 341734] [remote 140.245.231.239:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.231.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9QgQWat-noHLkDuAiP_AABSTY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:57:05.392285 2026] [security2:error] [pid 341679:tid 341694] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/coffexium.php"] [unique_id "al9QgQWat-noHLkDuAiP_QABNg4"]
[Tue Jul 21 07:57:05.398658 2026] [security2:error] [pid 341679:tid 341705] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QgQWat-noHLkDuAiP_gABIxk"]
[Tue Jul 21 07:57:05.398858 2026] [security2:error] [pid 341679:tid 341834] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QgQWat-noHLkDuAiP_gABIxk"]
[Tue Jul 21 07:57:05.407144 2026] [security2:error] [pid 341679:tid 341850] [client 109.60.28.94:58880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QgQWat-noHLkDuAiP_wAAATM"]
[Tue Jul 21 07:57:05.407977 2026] [security2:error] [pid 341679:tid 341850] [client 109.60.28.94:58880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QgQWat-noHLkDuAiP_wAAATM"]
[Tue Jul 21 07:57:05.419917 2026] [security2:error] [pid 341679:tid 341782] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/app.php"] [unique_id "al9QgQWat-noHLkDuAiQAAABfmY"]
[Tue Jul 21 07:57:05.451656 2026] [security2:error] [pid 341679:tid 341730] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/core.php"] [unique_id "al9QgQWat-noHLkDuAiQAQABDjI"]
[Tue Jul 21 07:57:05.487519 2026] [security2:error] [pid 341679:tid 341721] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/main.php"] [unique_id "al9QgQWat-noHLkDuAiQAwABTSk"]
[Tue Jul 21 07:57:05.532400 2026] [security2:error] [pid 341679:tid 341896] [client 20.151.10.161:17339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/min.php"] [unique_id "al9QgQWat-noHLkDuAiQDAAAAWE"]
[Tue Jul 21 07:57:05.576909 2026] [security2:error] [pid 341679:tid 341895] [client 20.206.105.145:55903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/sss.php"] [unique_id "al9QgQWat-noHLkDuAiQEAAAAWA"]
[Tue Jul 21 07:57:05.611409 2026] [security2:error] [pid 341679:tid 341802] [remote 140.245.231.239:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.231.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9QgQWat-noHLkDuAiQFAABN3o"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:57:05.682232 2026] [security2:error] [pid 341679:tid 341680] [remote 140.245.231.239:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.231.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9QgQWat-noHLkDuAiQGQABSAA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:57:05.721406 2026] [autoindex:error] [pid 341679:tid 341851] [client 54.164.167.77:32704] AH01276: Cannot serve directory /home1/bastar15/mirth.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:05.788712 2026] [security2:error] [pid 341679:tid 341858] [client 193.36.225.10:56431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QgQWat-noHLkDuAiQKQAAATs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:05.824567 2026] [security2:error] [pid 341679:tid 341892] [client 20.151.10.161:17300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/edorxrr.php"] [unique_id "al9QgQWat-noHLkDuAiQKgAAAV0"]
[Tue Jul 21 07:57:05.853922 2026] [security2:error] [pid 341679:tid 341753] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QgQWat-noHLkDuAiQKwABaUk"]
[Tue Jul 21 07:57:05.854124 2026] [security2:error] [pid 341679:tid 341904] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QgQWat-noHLkDuAiQKwABaUk"]
[Tue Jul 21 07:57:05.874349 2026] [security2:error] [pid 341679:tid 341826] [client 20.104.96.117:54998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/rithin.php"] [unique_id "al9QgQWat-noHLkDuAiQLQAAARs"]
[Tue Jul 21 07:57:05.927965 2026] [security2:error] [pid 341679:tid 341881] [client 20.151.10.161:28858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/122.php"] [unique_id "al9QgQWat-noHLkDuAiQMQAAAVI"]
[Tue Jul 21 07:57:05.965102 2026] [security2:error] [pid 341679:tid 341867] [client 198.54.128.138:43704] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9QgAWat-noHLkDuAiP5QAAAUQ"]
[Tue Jul 21 07:57:05.965206 2026] [security2:error] [pid 341679:tid 341867] [client 198.54.128.138:43704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9QgAWat-noHLkDuAiP5QAAAUQ"]
[Tue Jul 21 07:57:06.120431 2026] [security2:error] [pid 341679:tid 341863] [client 20.151.10.161:17280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/hur.php"] [unique_id "al9QggWat-noHLkDuAiQOAAAAUA"]
[Tue Jul 21 07:57:06.138305 2026] [security2:error] [pid 341679:tid 341884] [client 20.226.60.151:60015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/w3llscc.php"] [unique_id "al9QggWat-noHLkDuAiQOwAAAVU"]
[Tue Jul 21 07:57:06.352985 2026] [security2:error] [pid 341679:tid 341893] [client 41.68.90.219:62211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QggWat-noHLkDuAiQQAAAAV4"]
[Tue Jul 21 07:57:06.354010 2026] [security2:error] [pid 341679:tid 341893] [client 41.68.90.219:62211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QggWat-noHLkDuAiQQAAAAV4"]
[Tue Jul 21 07:57:06.412357 2026] [security2:error] [pid 341679:tid 341902] [client 20.151.10.161:17314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/zoro.php"] [unique_id "al9QggWat-noHLkDuAiQQgAAAWc"]
[Tue Jul 21 07:57:06.414207 2026] [security2:error] [pid 341679:tid 341848] [client 74.249.245.134:5545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/info.php"] [unique_id "al9QggWat-noHLkDuAiQRAAAATE"]
[Tue Jul 21 07:57:06.521920 2026] [security2:error] [pid 341679:tid 341896] [client 20.151.10.161:28840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/green1.php"] [unique_id "al9QggWat-noHLkDuAiQRwAAAWE"]
[Tue Jul 21 07:57:06.609201 2026] [security2:error] [pid 341679:tid 341916] [client 178.153.91.96:3395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QggWat-noHLkDuAiQSwAAAXU"]
[Tue Jul 21 07:57:06.609323 2026] [security2:error] [pid 341679:tid 341916] [client 178.153.91.96:3395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QggWat-noHLkDuAiQSwAAAXU"]
[Tue Jul 21 07:57:06.622146 2026] [security2:error] [pid 341679:tid 341807] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QggWat-noHLkDuAiQTwABR38"]
[Tue Jul 21 07:57:06.622297 2026] [security2:error] [pid 341679:tid 341870] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QggWat-noHLkDuAiQTwABR38"]
[Tue Jul 21 07:57:06.708789 2026] [security2:error] [pid 341679:tid 341832] [client 20.151.10.161:17334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/coffexium.php"] [unique_id "al9QggWat-noHLkDuAiQWwAAASE"]
[Tue Jul 21 07:57:06.738924 2026] [security2:error] [pid 341679:tid 341871] [client 20.104.96.117:54984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/fffm.php"] [unique_id "al9QggWat-noHLkDuAiQXAAAAUg"]
[Tue Jul 21 07:57:06.755896 2026] [security2:error] [pid 341679:tid 341830] [client 37.140.223.153:22875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QggWat-noHLkDuAiQXQAAAR8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:57:06.823898 2026] [security2:error] [pid 341679:tid 341841] [client 204.8.98.45:41562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9QggWat-noHLkDuAiQXwAAASo"]
[Tue Jul 21 07:57:06.823996 2026] [security2:error] [pid 341679:tid 341841] [client 204.8.98.45:41562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9QggWat-noHLkDuAiQXwAAASo"]
[Tue Jul 21 07:57:06.904361 2026] [security2:error] [pid 341679:tid 341853] [client 59.93.4.33:61416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QggWat-noHLkDuAiQcQAAATY"]
[Tue Jul 21 07:57:06.904476 2026] [security2:error] [pid 341679:tid 341853] [client 59.93.4.33:61416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QggWat-noHLkDuAiQcQAAATY"]
[Tue Jul 21 07:57:06.996691 2026] [security2:error] [pid 341679:tid 341846] [client 38.100.221.102:18068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QggWat-noHLkDuAiQdAAAAS8"]
[Tue Jul 21 07:57:06.996832 2026] [security2:error] [pid 341679:tid 341846] [client 38.100.221.102:18068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QggWat-noHLkDuAiQdAAAAS8"]
[Tue Jul 21 07:57:07.015571 2026] [security2:error] [pid 341679:tid 341867] [client 204.8.98.45:54904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9QgwWat-noHLkDuAiQdQAAAUQ"]
[Tue Jul 21 07:57:07.015667 2026] [security2:error] [pid 341679:tid 341867] [client 204.8.98.45:54904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9QgwWat-noHLkDuAiQdQAAAUQ"]
[Tue Jul 21 07:57:07.029454 2026] [security2:error] [pid 341679:tid 341878] [client 20.151.10.161:17256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/app.php"] [unique_id "al9QgwWat-noHLkDuAiQdgAAAU8"]
[Tue Jul 21 07:57:07.037129 2026] [security2:error] [pid 341679:tid 341906] [client 20.151.10.161:28835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/biufile.php"] [unique_id "al9QgwWat-noHLkDuAiQeAAAAWs"]
[Tue Jul 21 07:57:07.121085 2026] [security2:error] [pid 341679:tid 341788] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/init.php"] [unique_id "al9QgwWat-noHLkDuAiQfgABJ2w"]
[Tue Jul 21 07:57:07.150454 2026] [security2:error] [pid 341679:tid 341722] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/prekel.php"] [unique_id "al9QgwWat-noHLkDuAiQfwABJSo"]
[Tue Jul 21 07:57:07.188857 2026] [security2:error] [pid 341679:tid 341701] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/0.php"] [unique_id "al9QgwWat-noHLkDuAiQggABKxU"]
[Tue Jul 21 07:57:07.217765 2026] [security2:error] [pid 341679:tid 341692] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/BDKR28.php"] [unique_id "al9QgwWat-noHLkDuAiQhQABTQw"]
[Tue Jul 21 07:57:07.395999 2026] [security2:error] [pid 341679:tid 341885] [client 117.247.80.59:15300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QgwWat-noHLkDuAiQigAAAVY"]
[Tue Jul 21 07:57:07.396115 2026] [security2:error] [pid 341679:tid 341885] [client 117.247.80.59:15300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QgwWat-noHLkDuAiQigAAAVY"]
[Tue Jul 21 07:57:07.511096 2026] [security2:error] [pid 341679:tid 341931] [client 20.151.10.161:17273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/core.php"] [unique_id "al9QgwWat-noHLkDuAiQjAAAAYQ"]
[Tue Jul 21 07:57:07.539547 2026] [security2:error] [pid 341679:tid 341869] [client 65.21.113.253:59234] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QgwWat-noHLkDuAiQjQAAAUY"]
[Tue Jul 21 07:57:07.668371 2026] [security2:error] [pid 341679:tid 341873] [client 202.143.127.214:54867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QgwWat-noHLkDuAiQlAAAAUo"]
[Tue Jul 21 07:57:07.668493 2026] [security2:error] [pid 341679:tid 341873] [client 202.143.127.214:54867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QgwWat-noHLkDuAiQlAAAAUo"]
[Tue Jul 21 07:57:07.762702 2026] [security2:error] [pid 341679:tid 341898] [client 20.151.10.161:29091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wpconf.php"] [unique_id "al9QgwWat-noHLkDuAiQmQAAAWM"]
[Tue Jul 21 07:57:07.770962 2026] [security2:error] [pid 341679:tid 341709] [remote 46.105.28.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naldoinvest.com.br"] [uri "/wp-login.php"] [unique_id "al9QgwWat-noHLkDuAiQmwABPR0"]
[Tue Jul 21 07:57:07.863641 2026] [security2:error] [pid 341679:tid 341702] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/f35.update.php"] [unique_id "al9QgwWat-noHLkDuAiQoQABhhY"]
[Tue Jul 21 07:57:07.933434 2026] [security2:error] [pid 341679:tid 341903] [client 20.151.10.161:17363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/main.php"] [unique_id "al9QgwWat-noHLkDuAiQpAAAAWg"]
[Tue Jul 21 07:57:08.319941 2026] [security2:error] [pid 341679:tid 341911] [client 20.206.105.145:55841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/sss.php"] [unique_id "al9QhAWat-noHLkDuAiQwQAAAXA"]
[Tue Jul 21 07:57:08.341896 2026] [security2:error] [pid 341679:tid 341869] [client 20.151.10.161:17187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/init.php"] [unique_id "al9QhAWat-noHLkDuAiQwgAAAUY"]
[Tue Jul 21 07:57:08.354939 2026] [security2:error] [pid 341679:tid 341915] [client 141.11.107.74:58137] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.transitoaberto.com.br"] [uri "/"] [unique_id "al9QhAWat-noHLkDuAiQwwAAAXQ"]
[Tue Jul 21 07:57:08.359612 2026] [security2:error] [pid 341679:tid 341861] [client 20.104.96.117:3503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9QhAWat-noHLkDuAiQxQAAAT4"]
[Tue Jul 21 07:57:08.368293 2026] [security2:error] [pid 341679:tid 341816] [client 141.11.107.74:58139] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.transitoaberto.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9QhAWat-noHLkDuAiQyAAAARE"]
[Tue Jul 21 07:57:08.376286 2026] [security2:error] [pid 341679:tid 341858] [client 141.11.107.74:58158] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.transitoaberto.com.br"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "al9QhAWat-noHLkDuAiQygAAATs"]
[Tue Jul 21 07:57:08.387049 2026] [security2:error] [pid 341679:tid 341767] [remote 173.252.95.112:61570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9QhAWat-noHLkDuAiQvQABQVc"]
[Tue Jul 21 07:57:08.388472 2026] [security2:error] [pid 341679:tid 341887] [client 141.11.107.74:58170] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.transitoaberto.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9QhAWat-noHLkDuAiQywAAAVg"]
[Tue Jul 21 07:57:08.394974 2026] [security2:error] [pid 341679:tid 341851] [client 20.151.10.161:29223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/mosty.php"] [unique_id "al9QhAWat-noHLkDuAiQzAAAATQ"]
[Tue Jul 21 07:57:08.401348 2026] [security2:error] [pid 341679:tid 341830] [client 20.104.96.117:57413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/dfre.php"] [unique_id "al9QhAWat-noHLkDuAiQzQAAAR8"]
[Tue Jul 21 07:57:08.405445 2026] [security2:error] [pid 341679:tid 341871] [client 141.11.107.74:58203] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ftp.transitoaberto.com.br"] [uri "/"] [unique_id "al9QhAWat-noHLkDuAiQzgAAAUg"]
[Tue Jul 21 07:57:08.426313 2026] [security2:error] [pid 341679:tid 341819] [client 141.11.107.74:58384] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "transitoaberto.com.br"] [uri "/"] [unique_id "al9QhAWat-noHLkDuAiQ0AAAARQ"]
[Tue Jul 21 07:57:08.426312 2026] [security2:error] [pid 341679:tid 341815] [client 141.11.107.74:58232] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.transitoaberto.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9QhAWat-noHLkDuAiQzwAAARA"]
[Tue Jul 21 07:57:08.463556 2026] [security2:error] [pid 341679:tid 341853] [client 141.11.107.74:58396] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.transitoaberto.com.br"] [uri "/"] [unique_id "al9QhAWat-noHLkDuAiQ0gAAATY"]
[Tue Jul 21 07:57:08.573737 2026] [security2:error] [pid 341679:tid 341825] [client 141.11.107.74:58578] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.transitoaberto.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9QhAWat-noHLkDuAiQ1QAAARo"]
[Tue Jul 21 07:57:08.625439 2026] [security2:error] [pid 341679:tid 341889] [client 65.21.113.253:54026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QhAWat-noHLkDuAiQvgAAAVo"]
[Tue Jul 21 07:57:08.662221 2026] [security2:error] [pid 341679:tid 341688] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QhAWat-noHLkDuAiQ1wABiAg"]
[Tue Jul 21 07:57:08.662368 2026] [security2:error] [pid 341679:tid 341935] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QhAWat-noHLkDuAiQ1wABiAg"]
[Tue Jul 21 07:57:08.721328 2026] [security2:error] [pid 341679:tid 341823] [client 20.151.10.161:17310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/prekel.php"] [unique_id "al9QhAWat-noHLkDuAiQ2wAAARg"]
[Tue Jul 21 07:57:08.792627 2026] [security2:error] [pid 341679:tid 341782] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/f900.php"] [unique_id "al9QhAWat-noHLkDuAiQ4QABSWY"]
[Tue Jul 21 07:57:08.833615 2026] [security2:error] [pid 341679:tid 341730] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/xmrl.php"] [unique_id "al9QhAWat-noHLkDuAiQ4wABHTI"]
[Tue Jul 21 07:57:08.869245 2026] [security2:error] [pid 341679:tid 341748] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/memberfuns.php"] [unique_id "al9QhAWat-noHLkDuAiQ5wABVkQ"]
[Tue Jul 21 07:57:08.884159 2026] [security2:error] [pid 341679:tid 341724] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/ms.php"] [unique_id "al9QhAWat-noHLkDuAiQ6AABXCw"]
[Tue Jul 21 07:57:08.905080 2026] [security2:error] [pid 341679:tid 341820] [client 20.104.96.117:3468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9QhAWat-noHLkDuAiQ6wAAARU"]
[Tue Jul 21 07:57:08.949237 2026] [security2:error] [pid 341679:tid 341761] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/zz.php"] [unique_id "al9QhAWat-noHLkDuAiQ7AABfFE"]
[Tue Jul 21 07:57:08.964575 2026] [security2:error] [pid 341679:tid 341879] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9QhAWat-noHLkDuAiQ6gABUEI"]
[Tue Jul 21 07:57:09.026520 2026] [security2:error] [pid 341679:tid 341900] [client 20.151.10.161:17222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/0.php"] [unique_id "al9QhQWat-noHLkDuAiQ7QAAAWU"]
[Tue Jul 21 07:57:09.027571 2026] [security2:error] [pid 341679:tid 341699] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/for.php"] [unique_id "al9QhQWat-noHLkDuAiQ7gABhBM"]
[Tue Jul 21 07:57:09.048160 2026] [security2:error] [pid 341679:tid 341928] [client 139.167.225.182:55015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.225.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QhQWat-noHLkDuAiQ8AAAAYE"]
[Tue Jul 21 07:57:09.048265 2026] [security2:error] [pid 341679:tid 341928] [client 139.167.225.182:55015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agmiz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QhQWat-noHLkDuAiQ8AAAAYE"]
[Tue Jul 21 07:57:09.072297 2026] [security2:error] [pid 341679:tid 341762] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/yup.php"] [unique_id "al9QhQWat-noHLkDuAiQ8QABR1I"]
[Tue Jul 21 07:57:09.138861 2026] [security2:error] [pid 341679:tid 341802] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/wpxml.php"] [unique_id "al9QhQWat-noHLkDuAiQ8wABEXo"]
[Tue Jul 21 07:57:09.138958 2026] [security2:error] [pid 341679:tid 341925] [client 87.116.180.198:27379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QhQWat-noHLkDuAiQ9AAAAX4"]
[Tue Jul 21 07:57:09.144003 2026] [security2:error] [pid 341679:tid 341925] [client 87.116.180.198:27379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QhQWat-noHLkDuAiQ9AAAAX4"]
[Tue Jul 21 07:57:09.364660 2026] [security2:error] [pid 341679:tid 341936] [client 20.151.10.161:17153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/BDKR28.php"] [unique_id "al9QhQWat-noHLkDuAiRAAAAAYk"]
[Tue Jul 21 07:57:09.400883 2026] [security2:error] [pid 341679:tid 341905] [client 182.8.255.181:17571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QhQWat-noHLkDuAiRAQAAAWo"]
[Tue Jul 21 07:57:09.401022 2026] [security2:error] [pid 341679:tid 341905] [client 182.8.255.181:17571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QhQWat-noHLkDuAiRAQAAAWo"]
[Tue Jul 21 07:57:09.431217 2026] [security2:error] [pid 341679:tid 341927] [client 20.226.60.151:56750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-u3nxbvx.php"] [unique_id "al9QhQWat-noHLkDuAiRAgAAAYA"]
[Tue Jul 21 07:57:09.465665 2026] [security2:error] [pid 341679:tid 341859] [client 223.236.153.128:4572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QhQWat-noHLkDuAiRBAAAATw"]
[Tue Jul 21 07:57:09.476710 2026] [security2:error] [pid 341679:tid 341859] [client 223.236.153.128:4572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QhQWat-noHLkDuAiRBAAAATw"]
[Tue Jul 21 07:57:09.639405 2026] [security2:error] [pid 341679:tid 341889] [client 193.36.225.106:34627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QhQWat-noHLkDuAiRBQAAAVo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:57:09.663955 2026] [security2:error] [pid 341679:tid 341855] [client 20.151.10.161:17236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/f35.update.php"] [unique_id "al9QhQWat-noHLkDuAiRCAAAATg"]
[Tue Jul 21 07:57:09.679410 2026] [security2:error] [pid 341679:tid 341884] [client 20.104.96.117:3463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/media.php"] [unique_id "al9QhQWat-noHLkDuAiRCgAAAVU"]
[Tue Jul 21 07:57:09.698077 2026] [security2:error] [pid 341679:tid 341836] [client 139.28.219.70:60362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tecnoturbo.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9QhQWat-noHLkDuAiRCwAAASU"]
[Tue Jul 21 07:57:09.833478 2026] [security2:error] [pid 341679:tid 341804] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/fffm.php"] [unique_id "al9QhQWat-noHLkDuAiRFAABVHw"]
[Tue Jul 21 07:57:09.951290 2026] [security2:error] [pid 341679:tid 341900] [client 20.151.10.161:17319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/f900.php"] [unique_id "al9QhQWat-noHLkDuAiRHgAAAWU"]
[Tue Jul 21 07:57:10.016521 2026] [security2:error] [pid 341679:tid 341811] [client 106.215.181.8:31162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QhgWat-noHLkDuAiRIgAAAQw"]
[Tue Jul 21 07:57:10.016641 2026] [security2:error] [pid 341679:tid 341811] [client 106.215.181.8:31162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QhgWat-noHLkDuAiRIgAAAQw"]
[Tue Jul 21 07:57:10.063949 2026] [security2:error] [pid 341679:tid 341846] [client 122.162.144.145:18640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QhgWat-noHLkDuAiRJAAAAS8"]
[Tue Jul 21 07:57:10.064049 2026] [security2:error] [pid 341679:tid 341846] [client 122.162.144.145:18640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QhgWat-noHLkDuAiRJAAAAS8"]
[Tue Jul 21 07:57:10.167974 2026] [security2:error] [pid 341679:tid 341887] [client 20.226.60.151:59960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wpx.php"] [unique_id "al9QhgWat-noHLkDuAiRKAAAAVg"]
[Tue Jul 21 07:57:10.232119 2026] [security2:error] [pid 341679:tid 341932] [client 20.197.192.193:54394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/cron-tab.php"] [unique_id "al9QhgWat-noHLkDuAiRKwAAAYU"]
[Tue Jul 21 07:57:10.247223 2026] [security2:error] [pid 341679:tid 341818] [client 20.104.96.117:57435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/wp-happy.php"] [unique_id "al9QhgWat-noHLkDuAiRLgAAARM"]
[Tue Jul 21 07:57:10.253425 2026] [security2:error] [pid 341679:tid 341853] [client 20.151.10.161:17299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/xmrl.php"] [unique_id "al9QhgWat-noHLkDuAiRLwAAATY"]
[Tue Jul 21 07:57:10.336882 2026] [security2:error] [pid 341679:tid 341779] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/gecko.php"] [unique_id "al9QhgWat-noHLkDuAiRMQABT2M"]
[Tue Jul 21 07:57:10.375414 2026] [security2:error] [pid 341679:tid 341731] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/a1.php"] [unique_id "al9QhgWat-noHLkDuAiRNQABPTM"]
[Tue Jul 21 07:57:10.412387 2026] [security2:error] [pid 341679:tid 341800] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/k2.php"] [unique_id "al9QhgWat-noHLkDuAiRNgABQHg"]
[Tue Jul 21 07:57:10.422753 2026] [security2:error] [pid 341679:tid 341922] [client 193.36.225.55:29903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QhgWat-noHLkDuAiRNwAAAXs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:10.568719 2026] [security2:error] [pid 341679:tid 341903] [client 20.104.96.117:3555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/images.php"] [unique_id "al9QhgWat-noHLkDuAiRPgAAAWg"]
[Tue Jul 21 07:57:10.596633 2026] [security2:error] [pid 341679:tid 341890] [client 20.151.10.161:17158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/memberfuns.php"] [unique_id "al9QhgWat-noHLkDuAiRQAAAAVs"]
[Tue Jul 21 07:57:10.601228 2026] [security2:error] [pid 341679:tid 341864] [client 139.28.219.70:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QhgWat-noHLkDuAiRPwAAAUE"]
[Tue Jul 21 07:57:10.638188 2026] [security2:error] [pid 341679:tid 341842] [client 20.151.10.161:29119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/dejavu.php"] [unique_id "al9QhgWat-noHLkDuAiRQQAAASs"]
[Tue Jul 21 07:57:10.674294 2026] [security2:error] [pid 341679:tid 341902] [client 74.249.245.134:54355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/edit.php"] [unique_id "al9QhgWat-noHLkDuAiRRgAAAWc"]
[Tue Jul 21 07:57:10.689915 2026] [security2:error] [pid 341679:tid 341911] [client 74.7.244.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "links.principiamatematica.com"] [uri "/index.php"] [unique_id "al9QhQWat-noHLkDuAiRIQAAAXA"]
[Tue Jul 21 07:57:10.690560 2026] [security2:error] [pid 341679:tid 341891] [client 74.7.244.30:55676] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "links.principiamatematica.com"] [uri "/robots.txt"] [unique_id "al9QhQWat-noHLkDuAiRHwABXCs"]
[Tue Jul 21 07:57:10.695371 2026] [core:error] [pid 341679:tid 341740] [remote 40.77.167.77:18326] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:10.695386 2026] [core:error] [pid 341679:tid 341740] [remote 40.77.167.77:18326] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:10.737702 2026] [security2:error] [pid 341679:tid 341849] [client 103.78.200.11:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QhgWat-noHLkDuAiRSgAAATI"]
[Tue Jul 21 07:57:10.737841 2026] [security2:error] [pid 341679:tid 341849] [client 103.78.200.11:54772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QhgWat-noHLkDuAiRSgAAATI"]
[Tue Jul 21 07:57:10.840231 2026] [security2:error] [pid 341679:tid 341830] [client 103.166.103.129:55726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QhgWat-noHLkDuAiRUQAAAR8"]
[Tue Jul 21 07:57:10.840416 2026] [security2:error] [pid 341679:tid 341830] [client 103.166.103.129:55726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QhgWat-noHLkDuAiRUQAAAR8"]
[Tue Jul 21 07:57:11.121754 2026] [security2:error] [pid 341679:tid 341884] [client 20.151.10.161:17218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/ms.php"] [unique_id "al9QhwWat-noHLkDuAiRWwAAAVU"]
[Tue Jul 21 07:57:11.253001 2026] [security2:error] [pid 341679:tid 341735] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/82.php"] [unique_id "al9QhwWat-noHLkDuAiRXwABWzc"]
[Tue Jul 21 07:57:11.282228 2026] [security2:error] [pid 341679:tid 341790] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/config.json.php"] [unique_id "al9QhwWat-noHLkDuAiRYAABLm4"]
[Tue Jul 21 07:57:11.377441 2026] [security2:error] [pid 341679:tid 341899] [client 136.144.19.39:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "naldoinvest.com.br"] [uri "/wp-login.php"] [unique_id "al9QhQWat-noHLkDuAiRDwABZCI"]
[Tue Jul 21 07:57:11.615490 2026] [security2:error] [pid 341679:tid 341865] [client 20.151.10.161:17162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/zz.php"] [unique_id "al9QhwWat-noHLkDuAiRbQAAAUI"]
[Tue Jul 21 07:57:11.821657 2026] [security2:error] [pid 341679:tid 341725] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.digiterapia.com.br"] [uri "/fpwch.php"] [unique_id "al9QhwWat-noHLkDuAiRcAABKC0"]
[Tue Jul 21 07:57:11.833451 2026] [security2:error] [pid 341679:tid 341832] [client 103.29.114.44:32291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QhwWat-noHLkDuAiRcgAAASE"]
[Tue Jul 21 07:57:11.833541 2026] [security2:error] [pid 341679:tid 341832] [client 103.29.114.44:32291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QhwWat-noHLkDuAiRcgAAASE"]
[Tue Jul 21 07:57:12.019076 2026] [security2:error] [pid 341679:tid 341934] [client 20.151.10.161:17266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/for.php"] [unique_id "al9QiAWat-noHLkDuAiRfAAAAYc"]
[Tue Jul 21 07:57:12.020572 2026] [security2:error] [pid 341679:tid 341795] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QiAWat-noHLkDuAiRewABE3M"]
[Tue Jul 21 07:57:12.020699 2026] [security2:error] [pid 341679:tid 341818] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QiAWat-noHLkDuAiRewABE3M"]
[Tue Jul 21 07:57:12.057431 2026] [security2:error] [pid 341679:tid 341825] [client 65.21.113.253:59234] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QiAWat-noHLkDuAiRfQAAARo"]
[Tue Jul 21 07:57:12.058174 2026] [security2:error] [pid 341679:tid 341927] [client 20.104.96.117:3533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/gecko.php"] [unique_id "al9QiAWat-noHLkDuAiRfgAAAYA"]
[Tue Jul 21 07:57:12.086595 2026] [security2:error] [pid 341679:tid 341906] [client 20.226.60.151:59991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-css.php"] [unique_id "al9QiAWat-noHLkDuAiRfwAAAWs"]
[Tue Jul 21 07:57:12.518394 2026] [security2:error] [pid 341679:tid 341887] [client 122.179.91.63:7968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QiAWat-noHLkDuAiRlAAAAVg"]
[Tue Jul 21 07:57:12.518510 2026] [security2:error] [pid 341679:tid 341887] [client 122.179.91.63:7968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QiAWat-noHLkDuAiRlAAAAVg"]
[Tue Jul 21 07:57:12.807471 2026] [security2:error] [pid 341679:tid 341913] [client 122.186.204.214:52037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.204.186.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QiAWat-noHLkDuAiRmQAAAXI"]
[Tue Jul 21 07:57:12.807588 2026] [security2:error] [pid 341679:tid 341913] [client 122.186.204.214:52037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QiAWat-noHLkDuAiRmQAAAXI"]
[Tue Jul 21 07:57:12.837889 2026] [security2:error] [pid 341679:tid 341869] [client 74.249.245.134:5535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/166.php"] [unique_id "al9QiAWat-noHLkDuAiRmwAAAUY"]
[Tue Jul 21 07:57:12.854035 2026] [security2:error] [pid 341679:tid 341918] [client 180.153.236.115:16113] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tatianabarbosa.online"] [uri "/"] [unique_id "al9QiAWat-noHLkDuAiRnwAAAXc"], referer: http://www.tatianabarbosa.online/
[Tue Jul 21 07:57:12.854185 2026] [security2:error] [pid 341679:tid 341918] [client 180.153.236.115:16113] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.tatianabarbosa.online"] [uri "/"] [unique_id "al9QiAWat-noHLkDuAiRnwAAAXc"], referer: http://www.tatianabarbosa.online/
[Tue Jul 21 07:57:12.892035 2026] [security2:error] [pid 341679:tid 341893] [client 65.21.113.253:42096] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QiAWat-noHLkDuAiRlwAAAV4"]
[Tue Jul 21 07:57:13.118434 2026] [security2:error] [pid 341679:tid 341695] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QiQWat-noHLkDuAiRrwABdA8"]
[Tue Jul 21 07:57:13.118569 2026] [security2:error] [pid 341679:tid 341915] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QiQWat-noHLkDuAiRrwABdA8"]
[Tue Jul 21 07:57:13.124445 2026] [security2:error] [pid 341679:tid 341860] [client 20.104.96.117:55020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/fpr4.php"] [unique_id "al9QiQWat-noHLkDuAiRsAAAAT0"]
[Tue Jul 21 07:57:13.147257 2026] [security2:error] [pid 341679:tid 341888] [client 139.28.219.70:60997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QiQWat-noHLkDuAiRsgAAAVk"]
[Tue Jul 21 07:57:13.147375 2026] [security2:error] [pid 341679:tid 341888] [client 139.28.219.70:60997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QiQWat-noHLkDuAiRsgAAAVk"]
[Tue Jul 21 07:57:13.201467 2026] [security2:error] [pid 341679:tid 341863] [client 20.104.96.117:3548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/82.php"] [unique_id "al9QiQWat-noHLkDuAiRtAAAAUA"]
[Tue Jul 21 07:57:13.212479 2026] [security2:error] [pid 341679:tid 341883] [client 102.206.115.33:62172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QiQWat-noHLkDuAiRtwAAAVQ"]
[Tue Jul 21 07:57:13.212606 2026] [security2:error] [pid 341679:tid 341883] [client 102.206.115.33:62172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QiQWat-noHLkDuAiRtwAAAVQ"]
[Tue Jul 21 07:57:13.241768 2026] [security2:error] [pid 341679:tid 341848] [client 20.151.10.161:17312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/yup.php"] [unique_id "al9QiQWat-noHLkDuAiRuAAAATE"]
[Tue Jul 21 07:57:13.711921 2026] [autoindex:error] [pid 341679:tid 341877] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:13.929697 2026] [security2:error] [pid 341679:tid 341854] [client 37.140.223.68:21123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QiQWat-noHLkDuAiRygAAATc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:13.970173 2026] [security2:error] [pid 341679:tid 341896] [client 65.21.113.253:42098] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QiQWat-noHLkDuAiRwQAAAWE"]
[Tue Jul 21 07:57:14.039936 2026] [security2:error] [pid 341679:tid 341685] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QigWat-noHLkDuAiR0gABWgU"]
[Tue Jul 21 07:57:14.040035 2026] [security2:error] [pid 341679:tid 341889] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QigWat-noHLkDuAiR0gABWgU"]
[Tue Jul 21 07:57:14.094929 2026] [autoindex:error] [pid 341679:tid 341839] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:14.191119 2026] [security2:error] [pid 341679:tid 341871] [client 20.104.96.117:3571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/admin.php"] [unique_id "al9QigWat-noHLkDuAiR1wAAAUg"]
[Tue Jul 21 07:57:14.245333 2026] [security2:error] [pid 341679:tid 341931] [client 103.86.117.203:51132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QigWat-noHLkDuAiR2QAAAYQ"]
[Tue Jul 21 07:57:14.245446 2026] [security2:error] [pid 341679:tid 341931] [client 103.86.117.203:51132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QigWat-noHLkDuAiR2QAAAYQ"]
[Tue Jul 21 07:57:14.307630 2026] [autoindex:error] [pid 341679:tid 341817] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:14.372061 2026] [security2:error] [pid 341679:tid 341908] [client 65.21.113.253:42110] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QiQWat-noHLkDuAiRywAAAW0"]
[Tue Jul 21 07:57:14.489075 2026] [security2:error] [pid 341679:tid 341827] [client 20.226.60.151:56789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/ss.php"] [unique_id "al9QigWat-noHLkDuAiR4gAAARw"]
[Tue Jul 21 07:57:14.520596 2026] [autoindex:error] [pid 341679:tid 341863] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:14.530200 2026] [security2:error] [pid 341679:tid 341835] [client 20.151.10.161:17166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/wpxml.php"] [unique_id "al9QigWat-noHLkDuAiR6AAAASQ"]
[Tue Jul 21 07:57:14.634743 2026] [security2:error] [pid 341679:tid 341845] [client 20.104.96.117:54943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/file88.php"] [unique_id "al9QigWat-noHLkDuAiR7QAAAS4"]
[Tue Jul 21 07:57:14.645027 2026] [security2:error] [pid 341679:tid 341849] [client 122.164.127.47:54710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QigWat-noHLkDuAiR7gAAATI"]
[Tue Jul 21 07:57:14.645176 2026] [security2:error] [pid 341679:tid 341849] [client 122.164.127.47:54710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QigWat-noHLkDuAiR7gAAATI"]
[Tue Jul 21 07:57:14.733496 2026] [security2:error] [pid 341679:tid 341903] [client 20.151.10.161:28823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/aaf.php"] [unique_id "al9QigWat-noHLkDuAiR8QAAAWg"]
[Tue Jul 21 07:57:14.770575 2026] [autoindex:error] [pid 341679:tid 341813] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:14.978243 2026] [autoindex:error] [pid 341679:tid 341841] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:15.187718 2026] [autoindex:error] [pid 341679:tid 341829] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:15.373871 2026] [security2:error] [pid 341679:tid 341836] [client 117.210.135.0:51417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QiwWat-noHLkDuAiSDwAAASU"]
[Tue Jul 21 07:57:15.400314 2026] [autoindex:error] [pid 341679:tid 341838] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:15.627979 2026] [security2:error] [pid 341679:tid 341906] [client 65.21.113.253:47970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9QiwWat-noHLkDuAiSHQAAAWs"]
[Tue Jul 21 07:57:15.631944 2026] [security2:error] [pid 341679:tid 341857] [client 20.151.10.161:17181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/fffm.php"] [unique_id "al9QiwWat-noHLkDuAiSHwAAATo"]
[Tue Jul 21 07:57:15.674500 2026] [security2:error] [pid 341679:tid 341782] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QiwWat-noHLkDuAiSIQABQGY"]
[Tue Jul 21 07:57:15.674637 2026] [security2:error] [pid 341679:tid 341863] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QiwWat-noHLkDuAiSIQABQGY"]
[Tue Jul 21 07:57:15.675389 2026] [security2:error] [pid 341679:tid 341930] [client 20.206.105.145:55870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/c.php"] [unique_id "al9QiwWat-noHLkDuAiSIgAAAYM"]
[Tue Jul 21 07:57:15.909992 2026] [security2:error] [pid 341679:tid 341903] [client 20.104.96.117:3475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/adminner.php"] [unique_id "al9QiwWat-noHLkDuAiSLAAAAWg"]
[Tue Jul 21 07:57:16.043953 2026] [security2:error] [pid 341679:tid 341874] [client 65.21.113.253:42096] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QiwWat-noHLkDuAiSKAAAAUs"]
[Tue Jul 21 07:57:16.150747 2026] [security2:error] [pid 341679:tid 341733] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QjAWat-noHLkDuAiSNgABiTU"]
[Tue Jul 21 07:57:16.150986 2026] [security2:error] [pid 341679:tid 341936] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QjAWat-noHLkDuAiSNgABiTU"]
[Tue Jul 21 07:57:16.227315 2026] [security2:error] [pid 341679:tid 341814] [client 20.226.60.151:61518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9QjAWat-noHLkDuAiSOQAAAQ8"]
[Tue Jul 21 07:57:16.268121 2026] [security2:error] [pid 341679:tid 341892] [client 65.21.113.253:59234] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QjAWat-noHLkDuAiSOwAAAV0"]
[Tue Jul 21 07:57:16.401977 2026] [security2:error] [pid 341679:tid 341876] [client 109.60.28.94:59332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjAWat-noHLkDuAiSQQAAAU0"]
[Tue Jul 21 07:57:16.402080 2026] [security2:error] [pid 341679:tid 341876] [client 109.60.28.94:59332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjAWat-noHLkDuAiSQQAAAU0"]
[Tue Jul 21 07:57:16.537730 2026] [security2:error] [pid 341679:tid 341915] [client 20.226.60.151:59995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/ho.php"] [unique_id "al9QjAWat-noHLkDuAiSRAAAAXQ"]
[Tue Jul 21 07:57:16.673248 2026] [security2:error] [pid 341679:tid 341848] [client 74.249.245.134:5566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/8.php"] [unique_id "al9QjAWat-noHLkDuAiSSQAAATE"]
[Tue Jul 21 07:57:16.749418 2026] [security2:error] [pid 341679:tid 341900] [client 65.21.113.253:42110] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QjAWat-noHLkDuAiSPAAAAWU"]
[Tue Jul 21 07:57:16.851699 2026] [security2:error] [pid 341679:tid 341833] [client 20.226.60.151:56714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/min.php"] [unique_id "al9QjAWat-noHLkDuAiSTgAAASI"]
[Tue Jul 21 07:57:16.856910 2026] [security2:error] [pid 341679:tid 341693] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QjAWat-noHLkDuAiSTwABNg0"]
[Tue Jul 21 07:57:16.857087 2026] [security2:error] [pid 341679:tid 341853] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QjAWat-noHLkDuAiSTwABNg0"]
[Tue Jul 21 07:57:16.889470 2026] [security2:error] [pid 341679:tid 341877] [client 41.68.90.219:62899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjAWat-noHLkDuAiSUwAAAU4"]
[Tue Jul 21 07:57:16.889631 2026] [security2:error] [pid 341679:tid 341877] [client 41.68.90.219:62899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjAWat-noHLkDuAiSUwAAAU4"]
[Tue Jul 21 07:57:17.078759 2026] [security2:error] [pid 341679:tid 341846] [client 178.153.91.96:62022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QjQWat-noHLkDuAiSVgAAAS8"]
[Tue Jul 21 07:57:17.078898 2026] [security2:error] [pid 341679:tid 341846] [client 178.153.91.96:62022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QjQWat-noHLkDuAiSVgAAAS8"]
[Tue Jul 21 07:57:17.207361 2026] [security2:error] [pid 341679:tid 341924] [client 20.104.96.117:3546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/admin.php"] [unique_id "al9QjQWat-noHLkDuAiSWwAAAX0"]
[Tue Jul 21 07:57:17.301964 2026] [security2:error] [pid 341679:tid 341690] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QjQWat-noHLkDuAiSXgABWAo"]
[Tue Jul 21 07:57:17.302120 2026] [security2:error] [pid 341679:tid 341887] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QjQWat-noHLkDuAiSXgABWAo"]
[Tue Jul 21 07:57:17.324896 2026] [security2:error] [pid 341679:tid 341886] [client 65.21.113.253:42116] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QjAWat-noHLkDuAiSVAAAAVc"]
[Tue Jul 21 07:57:17.390420 2026] [security2:error] [pid 341679:tid 341879] [client 193.36.225.71:51835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QjQWat-noHLkDuAiSYQAAAVA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:17.407123 2026] [autoindex:error] [pid 341679:tid 341847] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:17.493922 2026] [security2:error] [pid 341679:tid 341922] [client 20.151.10.161:17165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/gecko.php"] [unique_id "al9QjQWat-noHLkDuAiSZAAAAXs"]
[Tue Jul 21 07:57:17.621941 2026] [autoindex:error] [pid 341679:tid 341834] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:17.656895 2026] [security2:error] [pid 341679:tid 341925] [client 59.93.4.33:61928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjQWat-noHLkDuAiSbgAAAX4"]
[Tue Jul 21 07:57:17.657008 2026] [security2:error] [pid 341679:tid 341925] [client 59.93.4.33:61928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjQWat-noHLkDuAiSbgAAAX4"]
[Tue Jul 21 07:57:17.851750 2026] [security2:error] [pid 341679:tid 341888] [client 65.111.23.225:58021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QjQWat-noHLkDuAiScgAAAVk"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:57:17.885264 2026] [security2:error] [pid 341679:tid 341825] [client 117.247.80.59:21476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjQWat-noHLkDuAiSfQAAARo"]
[Tue Jul 21 07:57:17.885414 2026] [security2:error] [pid 341679:tid 341825] [client 117.247.80.59:21476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjQWat-noHLkDuAiSfQAAARo"]
[Tue Jul 21 07:57:17.896047 2026] [security2:error] [pid 341679:tid 341835] [client 20.151.10.161:29241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/term.php"] [unique_id "al9QjQWat-noHLkDuAiSfgAAASQ"]
[Tue Jul 21 07:57:17.968994 2026] [security2:error] [pid 341679:tid 341779] [remote 119.195.102.159:45602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "manual.fernandohipolito.com.br"] [uri "/wp-login.php"] [unique_id "al9QjQWat-noHLkDuAiSfwABDGM"]
[Tue Jul 21 07:57:18.039555 2026] [autoindex:error] [pid 341679:tid 341848] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:18.118555 2026] [security2:error] [pid 341679:tid 341816] [client 20.206.105.145:28666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/aa.php"] [unique_id "al9QjgWat-noHLkDuAiSgwAAARE"]
[Tue Jul 21 07:57:18.186200 2026] [security2:error] [pid 341679:tid 341833] [client 20.104.96.117:54949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/ccc.php"] [unique_id "al9QjgWat-noHLkDuAiSiAAAASI"]
[Tue Jul 21 07:57:18.235961 2026] [security2:error] [pid 341679:tid 341867] [client 198.54.128.138:43760] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9QjgWat-noHLkDuAiSjwAAAUQ"]
[Tue Jul 21 07:57:18.236049 2026] [security2:error] [pid 341679:tid 341867] [client 198.54.128.138:43760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9QjgWat-noHLkDuAiSjwAAAUQ"]
[Tue Jul 21 07:57:18.244599 2026] [autoindex:error] [pid 341679:tid 341927] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:18.262183 2026] [security2:error] [pid 341679:tid 341837] [client 38.100.221.102:19080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjgWat-noHLkDuAiSkAAAASY"]
[Tue Jul 21 07:57:18.262505 2026] [security2:error] [pid 341679:tid 341837] [client 38.100.221.102:19080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjgWat-noHLkDuAiSkAAAASY"]
[Tue Jul 21 07:57:18.321855 2026] [security2:error] [pid 341679:tid 341845] [client 20.104.96.117:3524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/k.php"] [unique_id "al9QjgWat-noHLkDuAiSlQAAAS4"]
[Tue Jul 21 07:57:18.447058 2026] [autoindex:error] [pid 341679:tid 341874] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:18.653450 2026] [autoindex:error] [pid 341679:tid 341829] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:18.721614 2026] [security2:error] [pid 341679:tid 341894] [client 202.143.127.214:55362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjgWat-noHLkDuAiSqgAAAV8"]
[Tue Jul 21 07:57:18.721743 2026] [security2:error] [pid 341679:tid 341894] [client 202.143.127.214:55362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjgWat-noHLkDuAiSqgAAAV8"]
[Tue Jul 21 07:57:18.854019 2026] [autoindex:error] [pid 341679:tid 341931] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:18.971358 2026] [security2:error] [pid 341679:tid 341784] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjgWat-noHLkDuAiSsgABD2g"]
[Tue Jul 21 07:57:18.971577 2026] [security2:error] [pid 341679:tid 341814] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjgWat-noHLkDuAiSsgABD2g"]
[Tue Jul 21 07:57:19.204602 2026] [security2:error] [pid 341679:tid 341816] [client 20.226.60.151:59972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/xy.php"] [unique_id "al9QjwWat-noHLkDuAiSwAAAARE"]
[Tue Jul 21 07:57:19.269580 2026] [security2:error] [pid 341679:tid 341878] [client 74.249.245.134:5506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/ws38.php"] [unique_id "al9QjwWat-noHLkDuAiSxAAAAU8"]
[Tue Jul 21 07:57:19.390086 2026] [security2:error] [pid 341679:tid 341823] [client 20.104.96.117:3583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/blurbs.php"] [unique_id "al9QjwWat-noHLkDuAiSzAAAARg"]
[Tue Jul 21 07:57:19.472057 2026] [security2:error] [pid 341679:tid 341849] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9QjwWat-noHLkDuAiSzQABMkg"]
[Tue Jul 21 07:57:19.584209 2026] [security2:error] [pid 341679:tid 341842] [client 20.151.10.161:17253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/a1.php"] [unique_id "al9QjwWat-noHLkDuAiS1QAAASs"]
[Tue Jul 21 07:57:19.703110 2026] [security2:error] [pid 341679:tid 341898] [client 182.8.255.181:2931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QjwWat-noHLkDuAiS3QAAAWM"]
[Tue Jul 21 07:57:19.703227 2026] [security2:error] [pid 341679:tid 341898] [client 182.8.255.181:2931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QjwWat-noHLkDuAiS3QAAAWM"]
[Tue Jul 21 07:57:19.803025 2026] [security2:error] [pid 341679:tid 341876] [client 20.206.105.145:55880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/100.php"] [unique_id "al9QjwWat-noHLkDuAiS4wAAAU0"]
[Tue Jul 21 07:57:19.834880 2026] [security2:error] [pid 341679:tid 341867] [client 87.116.180.198:27383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjwWat-noHLkDuAiS5AAAAUQ"]
[Tue Jul 21 07:57:19.836030 2026] [security2:error] [pid 341679:tid 341867] [client 87.116.180.198:27383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QjwWat-noHLkDuAiS5AAAAUQ"]
[Tue Jul 21 07:57:20.042405 2026] [security2:error] [pid 341679:tid 341857] [client 223.236.153.128:6534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QkAWat-noHLkDuAiS8gAAATo"]
[Tue Jul 21 07:57:20.047447 2026] [security2:error] [pid 341679:tid 341857] [client 223.236.153.128:6534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QkAWat-noHLkDuAiS8gAAATo"]
[Tue Jul 21 07:57:20.090934 2026] [security2:error] [pid 341679:tid 341848] [client 20.104.96.117:54970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/777.php"] [unique_id "al9QkAWat-noHLkDuAiS9AAAATE"]
[Tue Jul 21 07:57:20.149317 2026] [autoindex:error] [pid 341679:tid 341877] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:20.211086 2026] [security2:error] [pid 341679:tid 341821] [client 20.104.96.117:3547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/bajah.php"] [unique_id "al9QkAWat-noHLkDuAiS-AAAARY"]
[Tue Jul 21 07:57:20.281732 2026] [security2:error] [pid 341679:tid 341855] [client 20.226.60.151:60001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/loader.php"] [unique_id "al9QkAWat-noHLkDuAiS_gAAATg"]
[Tue Jul 21 07:57:20.345909 2026] [core:crit] [pid 341679:tid 341928] (13)Permission denied: [client 82.102.18.182:0] AH00529: /home2/dalto241/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home2/dalto241/public_html/cgi-bin/' is executable
[Tue Jul 21 07:57:20.619018 2026] [security2:error] [pid 341679:tid 341914] [client 106.215.181.8:3514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QkAWat-noHLkDuAiTCgAAAXM"]
[Tue Jul 21 07:57:20.619158 2026] [security2:error] [pid 341679:tid 341914] [client 106.215.181.8:3514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QkAWat-noHLkDuAiTCgAAAXM"]
[Tue Jul 21 07:57:20.767466 2026] [security2:error] [pid 341679:tid 341906] [client 122.162.144.145:21349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QkAWat-noHLkDuAiTDQAAAWs"]
[Tue Jul 21 07:57:20.767620 2026] [security2:error] [pid 341679:tid 341906] [client 122.162.144.145:21349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QkAWat-noHLkDuAiTDQAAAWs"]
[Tue Jul 21 07:57:21.159226 2026] [security2:error] [pid 341679:tid 341934] [client 20.206.105.145:28657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/footer.php"] [unique_id "al9QkQWat-noHLkDuAiTGwAAAYc"]
[Tue Jul 21 07:57:21.173914 2026] [security2:error] [pid 341679:tid 341893] [client 20.104.96.117:3508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/a.php"] [unique_id "al9QkQWat-noHLkDuAiTHAAAAV4"]
[Tue Jul 21 07:57:21.219892 2026] [security2:error] [pid 341679:tid 341842] [client 103.78.200.11:55227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QkQWat-noHLkDuAiTHQAAASs"]
[Tue Jul 21 07:57:21.220017 2026] [security2:error] [pid 341679:tid 341842] [client 103.78.200.11:55227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QkQWat-noHLkDuAiTHQAAASs"]
[Tue Jul 21 07:57:21.450641 2026] [security2:error] [pid 341679:tid 341823] [client 20.226.60.151:59905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/spadex.php"] [unique_id "al9QkQWat-noHLkDuAiTKAAAARg"]
[Tue Jul 21 07:57:21.529138 2026] [security2:error] [pid 341679:tid 341894] [client 103.166.103.129:56587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QkQWat-noHLkDuAiTLAAAAV8"]
[Tue Jul 21 07:57:21.529293 2026] [security2:error] [pid 341679:tid 341894] [client 103.166.103.129:56587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QkQWat-noHLkDuAiTLAAAAV8"]
[Tue Jul 21 07:57:21.642526 2026] [core:error] [pid 341679:tid 341697] [remote 52.167.144.184:62139] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:21.642553 2026] [core:error] [pid 341679:tid 341697] [remote 52.167.144.184:62139] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:21.689020 2026] [security2:error] [pid 341679:tid 341841] [client 20.197.192.193:3614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/koiy.php"] [unique_id "al9QkQWat-noHLkDuAiTLwAAASo"]
[Tue Jul 21 07:57:21.741315 2026] [security2:error] [pid 341679:tid 341889] [client 74.7.230.15:34396] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.atacadomaster.com"] [uri "/index.php"] [unique_id "al9QjwWat-noHLkDuAiS6gABWmw"]
[Tue Jul 21 07:57:22.045016 2026] [security2:error] [pid 341679:tid 341820] [client 20.226.60.151:50580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9QkgWat-noHLkDuAiTVwAAARU"]
[Tue Jul 21 07:57:22.077203 2026] [security2:error] [pid 341679:tid 341921] [client 193.36.225.11:58825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QkgWat-noHLkDuAiTWAAAAXo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:22.123976 2026] [security2:error] [pid 341679:tid 341900] [client 103.29.114.44:59961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QkgWat-noHLkDuAiTWQAAAWU"]
[Tue Jul 21 07:57:22.124101 2026] [security2:error] [pid 341679:tid 341900] [client 103.29.114.44:59961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QkgWat-noHLkDuAiTWQAAAWU"]
[Tue Jul 21 07:57:22.204095 2026] [security2:error] [pid 341679:tid 341879] [client 20.104.96.117:3498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/edit.php"] [unique_id "al9QkgWat-noHLkDuAiTXAAAAVA"]
[Tue Jul 21 07:57:22.468244 2026] [security2:error] [pid 341679:tid 341853] [client 198.54.128.138:42034] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9QkgWat-noHLkDuAiTawAAATY"]
[Tue Jul 21 07:57:22.468361 2026] [security2:error] [pid 341679:tid 341853] [client 198.54.128.138:42034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9QkgWat-noHLkDuAiTawAAATY"]
[Tue Jul 21 07:57:22.745461 2026] [security2:error] [pid 341679:tid 341849] [client 20.206.105.145:28566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/users.php"] [unique_id "al9QkgWat-noHLkDuAiTdQAAATI"]
[Tue Jul 21 07:57:22.770942 2026] [security2:error] [pid 341679:tid 341878] [client 74.249.245.134:17449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/a7.php"] [unique_id "al9QkgWat-noHLkDuAiTdgAAAU8"]
[Tue Jul 21 07:57:22.852857 2026] [security2:error] [pid 341679:tid 341874] [client 65.21.113.253:42910] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QkgWat-noHLkDuAiTegAAAUs"]
[Tue Jul 21 07:57:22.960030 2026] [security2:error] [pid 341679:tid 341727] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QkgWat-noHLkDuAiThAABhi8"]
[Tue Jul 21 07:57:22.960606 2026] [security2:error] [pid 341679:tid 341933] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QkgWat-noHLkDuAiThAABhi8"]
[Tue Jul 21 07:57:23.193242 2026] [security2:error] [pid 341679:tid 341820] [client 20.104.96.117:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/hosty.php"] [unique_id "al9QkwWat-noHLkDuAiTjQAAARU"]
[Tue Jul 21 07:57:23.196255 2026] [security2:error] [pid 341679:tid 341881] [client 122.179.91.63:1277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QkwWat-noHLkDuAiTjgAAAVI"]
[Tue Jul 21 07:57:23.196523 2026] [security2:error] [pid 341679:tid 341881] [client 122.179.91.63:1277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QkwWat-noHLkDuAiTjgAAAVI"]
[Tue Jul 21 07:57:23.698436 2026] [security2:error] [pid 341679:tid 341830] [client 20.206.105.145:55883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/177.php"] [unique_id "al9QkwWat-noHLkDuAiTnQAAAR8"]
[Tue Jul 21 07:57:23.710288 2026] [security2:error] [pid 341679:tid 341869] [client 102.206.115.33:61933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QkwWat-noHLkDuAiTngAAAUY"]
[Tue Jul 21 07:57:23.710411 2026] [security2:error] [pid 341679:tid 341869] [client 102.206.115.33:61933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QkwWat-noHLkDuAiTngAAAUY"]
[Tue Jul 21 07:57:23.713204 2026] [security2:error] [pid 341679:tid 341807] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QkwWat-noHLkDuAiTnwABfn8"]
[Tue Jul 21 07:57:23.713343 2026] [security2:error] [pid 341679:tid 341925] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QkwWat-noHLkDuAiTnwABfn8"]
[Tue Jul 21 07:57:23.776149 2026] [security2:error] [pid 341679:tid 341860] [client 20.104.96.117:57750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/for.php"] [unique_id "al9QkwWat-noHLkDuAiToQAAAT0"]
[Tue Jul 21 07:57:23.923663 2026] [security2:error] [pid 341679:tid 341815] [client 65.21.113.253:52220] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QkwWat-noHLkDuAiTmwAAARA"]
[Tue Jul 21 07:57:23.927919 2026] [security2:error] [pid 341679:tid 341928] [client 20.226.60.151:60019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/2x.php"] [unique_id "al9QkwWat-noHLkDuAiTpgAAAYE"]
[Tue Jul 21 07:57:24.116907 2026] [security2:error] [pid 341679:tid 341906] [client 20.151.10.161:29096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/ha.php"] [unique_id "al9QlAWat-noHLkDuAiTtwAAAWs"]
[Tue Jul 21 07:57:24.176803 2026] [security2:error] [pid 341679:tid 341813] [client 20.151.10.161:17258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/k2.php"] [unique_id "al9QlAWat-noHLkDuAiTuAAAAQ4"]
[Tue Jul 21 07:57:24.389951 2026] [security2:error] [pid 341679:tid 341876] [client 20.104.96.117:3580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/k.php"] [unique_id "al9QlAWat-noHLkDuAiTuwAAAU0"]
[Tue Jul 21 07:57:24.493776 2026] [security2:error] [pid 341679:tid 341828] [client 20.206.105.145:55865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/config.php"] [unique_id "al9QlAWat-noHLkDuAiTwAAAAR0"]
[Tue Jul 21 07:57:24.721097 2026] [security2:error] [pid 341679:tid 341774] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QlAWat-noHLkDuAiTygABVl4"]
[Tue Jul 21 07:57:24.721310 2026] [security2:error] [pid 341679:tid 341885] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QlAWat-noHLkDuAiTygABVl4"]
[Tue Jul 21 07:57:24.731833 2026] [security2:error] [pid 341679:tid 341841] [client 103.86.117.203:51815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QlAWat-noHLkDuAiTzQAAASo"]
[Tue Jul 21 07:57:24.731971 2026] [security2:error] [pid 341679:tid 341841] [client 103.86.117.203:51815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QlAWat-noHLkDuAiTzQAAASo"]
[Tue Jul 21 07:57:25.177542 2026] [security2:error] [pid 341679:tid 341881] [client 122.164.127.47:55290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QlQWat-noHLkDuAiT4AAAAVI"]
[Tue Jul 21 07:57:25.177644 2026] [security2:error] [pid 341679:tid 341881] [client 122.164.127.47:55290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QlQWat-noHLkDuAiT4AAAAVI"]
[Tue Jul 21 07:57:25.413548 2026] [security2:error] [pid 341679:tid 341891] [client 20.104.96.117:57445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/ssla.php"] [unique_id "al9QlQWat-noHLkDuAiT4QAAAVw"]
[Tue Jul 21 07:57:25.588926 2026] [security2:error] [pid 341679:tid 341886] [client 20.226.60.151:59934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/ctex1.php"] [unique_id "al9QlQWat-noHLkDuAiT5AAAAVc"]
[Tue Jul 21 07:57:25.877729 2026] [security2:error] [pid 341679:tid 341814] [client 20.151.10.161:17260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/82.php"] [unique_id "al9QlQWat-noHLkDuAiT7wAAAQ8"]
[Tue Jul 21 07:57:25.902045 2026] [security2:error] [pid 341679:tid 341777] [remote 37.140.223.22:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elpcons.com.br"] [uri "/wp-login.php"] [unique_id "al9QlAWat-noHLkDuAiT0wABXmE"]
[Tue Jul 21 07:57:25.953869 2026] [security2:error] [pid 341679:tid 341931] [client 117.210.135.0:52124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QlQWat-noHLkDuAiT7gAAAYQ"]
[Tue Jul 21 07:57:26.112976 2026] [security2:error] [pid 341679:tid 341837] [client 136.144.33.97:43381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QlgWat-noHLkDuAiT9wAAASY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:26.222143 2026] [security2:error] [pid 341679:tid 341831] [client 20.206.105.145:28545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/gettest.php"] [unique_id "al9QlgWat-noHLkDuAiT_gAAASA"]
[Tue Jul 21 07:57:26.349723 2026] [security2:error] [pid 341679:tid 341776] [remote 104.207.58.39:64665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9QlgWat-noHLkDuAiUAAABKWA"]
[Tue Jul 21 07:57:26.485597 2026] [security2:error] [pid 341679:tid 341863] [client 82.102.18.182:45382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocsdbodyboarding.com.br"] [uri "/wp-login.php"] [unique_id "al9QlgWat-noHLkDuAiUAgAAAUA"]
[Tue Jul 21 07:57:26.505236 2026] [security2:error] [pid 341679:tid 341895] [client 74.249.245.134:54337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/classsmtps.php"] [unique_id "al9QlgWat-noHLkDuAiUBwAAAWA"]
[Tue Jul 21 07:57:26.674101 2026] [security2:error] [pid 341679:tid 341781] [remote 81.173.115.7:53936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cezaretto.com.br"] [uri "/wp-login.php"] [unique_id "al9QlgWat-noHLkDuAiUDQABEmU"]
[Tue Jul 21 07:57:26.674294 2026] [security2:error] [pid 341679:tid 341865] [client 20.151.10.161:17283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/config.json.php"] [unique_id "al9QlgWat-noHLkDuAiUDgAAAUI"]
[Tue Jul 21 07:57:26.763866 2026] [security2:error] [pid 341679:tid 341816] [client 20.104.96.117:3495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/aaa.php"] [unique_id "al9QlgWat-noHLkDuAiUGAAAARE"]
[Tue Jul 21 07:57:26.788798 2026] [security2:error] [pid 341679:tid 341887] [client 20.151.10.161:28803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/hur.php"] [unique_id "al9QlgWat-noHLkDuAiUGgAAAVg"]
[Tue Jul 21 07:57:26.804204 2026] [security2:error] [pid 341679:tid 341786] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QlgWat-noHLkDuAiUGwABX2o"]
[Tue Jul 21 07:57:26.804358 2026] [security2:error] [pid 341679:tid 341894] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QlgWat-noHLkDuAiUGwABX2o"]
[Tue Jul 21 07:57:26.890523 2026] [security2:error] [pid 341679:tid 341773] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QlgWat-noHLkDuAiUHgABIl0"]
[Tue Jul 21 07:57:26.890724 2026] [security2:error] [pid 341679:tid 341833] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QlgWat-noHLkDuAiUHgABIl0"]
[Tue Jul 21 07:57:27.042887 2026] [security2:error] [pid 341679:tid 341811] [client 37.140.223.154:42915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QlgWat-noHLkDuAiUHQAAAQw"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:57:27.164202 2026] [security2:error] [pid 341679:tid 341911] [client 109.60.28.94:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QlwWat-noHLkDuAiUIwAAAXA"]
[Tue Jul 21 07:57:27.164353 2026] [security2:error] [pid 341679:tid 341911] [client 109.60.28.94:59768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QlwWat-noHLkDuAiUIwAAAXA"]
[Tue Jul 21 07:57:27.223985 2026] [security2:error] [pid 341679:tid 341888] [client 65.21.113.253:42910] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QlwWat-noHLkDuAiULQAAAVk"]
[Tue Jul 21 07:57:27.235594 2026] [security2:error] [pid 341679:tid 341913] [client 20.206.105.145:28611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/min.php"] [unique_id "al9QlwWat-noHLkDuAiULgAAAXI"]
[Tue Jul 21 07:57:27.328200 2026] [security2:error] [pid 341679:tid 341821] [client 41.68.90.219:63442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QlwWat-noHLkDuAiUMQAAARY"]
[Tue Jul 21 07:57:27.329608 2026] [security2:error] [pid 341679:tid 341821] [client 41.68.90.219:63442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QlwWat-noHLkDuAiUMQAAARY"]
[Tue Jul 21 07:57:27.389441 2026] [security2:error] [pid 341679:tid 341879] [client 20.151.10.161:17358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.bestdealsvalmir.com"] [uri "/fpwch.php"] [unique_id "al9QlwWat-noHLkDuAiUNQAAAVA"]
[Tue Jul 21 07:57:27.599633 2026] [security2:error] [pid 341679:tid 341838] [client 178.153.91.96:5380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QlwWat-noHLkDuAiUOQAAASc"]
[Tue Jul 21 07:57:27.599797 2026] [security2:error] [pid 341679:tid 341838] [client 178.153.91.96:5380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QlwWat-noHLkDuAiUOQAAASc"]
[Tue Jul 21 07:57:27.823786 2026] [security2:error] [pid 341679:tid 341806] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QlwWat-noHLkDuAiURAABM34"]
[Tue Jul 21 07:57:27.823969 2026] [security2:error] [pid 341679:tid 341850] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QlwWat-noHLkDuAiURAABM34"]
[Tue Jul 21 07:57:28.001038 2026] [security2:error] [pid 341679:tid 341727] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QmAWat-noHLkDuAiUcgABGi8"]
[Tue Jul 21 07:57:28.001170 2026] [security2:error] [pid 341679:tid 341825] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QmAWat-noHLkDuAiUcgABGi8"]
[Tue Jul 21 07:57:28.077623 2026] [security2:error] [pid 341679:tid 341857] [client 38.100.221.102:17796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmAWat-noHLkDuAiUewAAATo"]
[Tue Jul 21 07:57:28.077744 2026] [security2:error] [pid 341679:tid 341857] [client 38.100.221.102:17796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmAWat-noHLkDuAiUewAAATo"]
[Tue Jul 21 07:57:28.133319 2026] [security2:error] [pid 341679:tid 341868] [client 20.206.105.145:55824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/edorxrr.php"] [unique_id "al9QmAWat-noHLkDuAiUhQAAAUU"]
[Tue Jul 21 07:57:28.177376 2026] [security2:error] [pid 341679:tid 341925] [client 59.93.4.33:62434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmAWat-noHLkDuAiUhwAAAX4"]
[Tue Jul 21 07:57:28.177714 2026] [security2:error] [pid 341679:tid 341925] [client 59.93.4.33:62434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmAWat-noHLkDuAiUhwAAAX4"]
[Tue Jul 21 07:57:28.285489 2026] [security2:error] [pid 341679:tid 341874] [client 65.21.113.253:52224] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QlwWat-noHLkDuAiUbQAAAUs"]
[Tue Jul 21 07:57:28.421052 2026] [security2:error] [pid 341679:tid 341848] [client 117.247.80.59:22611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmAWat-noHLkDuAiUlQAAATE"]
[Tue Jul 21 07:57:28.421182 2026] [security2:error] [pid 341679:tid 341848] [client 117.247.80.59:22611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmAWat-noHLkDuAiUlQAAATE"]
[Tue Jul 21 07:57:28.529424 2026] [security2:error] [pid 341679:tid 341836] [client 20.151.10.161:29093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/h02ugyh.php"] [unique_id "al9QmAWat-noHLkDuAiUmgAAASU"]
[Tue Jul 21 07:57:28.547379 2026] [security2:error] [pid 341679:tid 341832] [client 65.21.113.253:52230] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QmAWat-noHLkDuAiUggAAASE"]
[Tue Jul 21 07:57:29.085119 2026] [security2:error] [pid 341679:tid 341857] [client 4.204.201.85:9645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9QmQWat-noHLkDuAiUqgAAATo"]
[Tue Jul 21 07:57:29.134332 2026] [security2:error] [pid 341679:tid 341930] [client 193.36.225.141:35943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QmAWat-noHLkDuAiUqAAAAYM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:57:29.436705 2026] [security2:error] [pid 341679:tid 341740] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmQWat-noHLkDuAiUtQABSTw"]
[Tue Jul 21 07:57:29.436851 2026] [security2:error] [pid 341679:tid 341872] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmQWat-noHLkDuAiUtQABSTw"]
[Tue Jul 21 07:57:29.665977 2026] [security2:error] [pid 341679:tid 341927] [client 65.21.113.253:42910] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QmQWat-noHLkDuAiUugAAAYA"]
[Tue Jul 21 07:57:29.695949 2026] [security2:error] [pid 341679:tid 341883] [client 20.104.96.117:57780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.infoalert.com.br"] [uri "/zc-131.php"] [unique_id "al9QmQWat-noHLkDuAiUvAAAAVQ"]
[Tue Jul 21 07:57:29.704625 2026] [security2:error] [pid 341679:tid 341854] [client 136.144.33.215:23921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QmQWat-noHLkDuAiUvQAAATc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:29.820947 2026] [security2:error] [pid 341679:tid 341931] [client 74.249.245.134:5539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/rip.php"] [unique_id "al9QmQWat-noHLkDuAiUxQAAAYQ"]
[Tue Jul 21 07:57:29.917383 2026] [security2:error] [pid 341679:tid 341921] [client 202.143.127.214:55875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmQWat-noHLkDuAiUygAAAXo"]
[Tue Jul 21 07:57:29.917519 2026] [security2:error] [pid 341679:tid 341921] [client 202.143.127.214:55875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmQWat-noHLkDuAiUygAAAXo"]
[Tue Jul 21 07:57:29.950469 2026] [security2:error] [pid 341679:tid 341892] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9QmQWat-noHLkDuAiUyAABXSA"]
[Tue Jul 21 07:57:30.099038 2026] [security2:error] [pid 341679:tid 341877] [client 20.206.105.145:55867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/hur.php"] [unique_id "al9QmgWat-noHLkDuAiU0gAAAU4"]
[Tue Jul 21 07:57:30.139907 2026] [security2:error] [pid 341679:tid 341910] [client 182.8.255.181:17580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QmgWat-noHLkDuAiU0wAAAW8"]
[Tue Jul 21 07:57:30.140072 2026] [security2:error] [pid 341679:tid 341910] [client 182.8.255.181:17580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QmgWat-noHLkDuAiU0wAAAW8"]
[Tue Jul 21 07:57:30.285791 2026] [security2:error] [pid 341679:tid 341757] [remote 159.65.81.207:47892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9QmgWat-noHLkDuAiU2AABbE0"]
[Tue Jul 21 07:57:30.294620 2026] [security2:error] [pid 341679:tid 341815] [client 65.21.113.253:52230] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QmQWat-noHLkDuAiUyQAAARA"]
[Tue Jul 21 07:57:30.358850 2026] [core:error] [pid 341679:tid 341795] [remote 40.77.167.187:50637] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:30.358873 2026] [core:error] [pid 341679:tid 341795] [remote 40.77.167.187:50637] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:30.390005 2026] [security2:error] [pid 341679:tid 341900] [client 4.204.201.85:9539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9QmgWat-noHLkDuAiU6QAAAWU"]
[Tue Jul 21 07:57:30.470704 2026] [security2:error] [pid 341679:tid 341823] [client 92.119.178.3:51188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9QmgWat-noHLkDuAiU8gAAARg"]
[Tue Jul 21 07:57:30.470791 2026] [security2:error] [pid 341679:tid 341823] [client 92.119.178.3:51188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9QmgWat-noHLkDuAiU8gAAARg"]
[Tue Jul 21 07:57:30.537140 2026] [security2:error] [pid 341679:tid 341922] [client 87.116.180.198:27245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmgWat-noHLkDuAiVGQAAAXs"]
[Tue Jul 21 07:57:30.537248 2026] [security2:error] [pid 341679:tid 341922] [client 87.116.180.198:27245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmgWat-noHLkDuAiVGQAAAXs"]
[Tue Jul 21 07:57:30.550840 2026] [security2:error] [pid 341679:tid 341924] [client 20.104.96.117:3523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/file5.php"] [unique_id "al9QmgWat-noHLkDuAiVHAAAAX0"]
[Tue Jul 21 07:57:30.664852 2026] [security2:error] [pid 341679:tid 341818] [client 20.206.105.145:28669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/zoro.php"] [unique_id "al9QmgWat-noHLkDuAiVHgAAARM"]
[Tue Jul 21 07:57:30.754942 2026] [security2:error] [pid 341679:tid 341853] [client 223.236.153.128:4834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QmgWat-noHLkDuAiVIQAAATY"]
[Tue Jul 21 07:57:30.755057 2026] [security2:error] [pid 341679:tid 341853] [client 223.236.153.128:4834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QmgWat-noHLkDuAiVIQAAATY"]
[Tue Jul 21 07:57:30.769999 2026] [security2:error] [pid 341679:tid 341814] [client 20.226.60.151:56818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/autoload_classmap.php"] [unique_id "al9QmgWat-noHLkDuAiVIwAAAQ8"]
[Tue Jul 21 07:57:30.774976 2026] [security2:error] [pid 341679:tid 341688] [remote 159.223.116.62:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.116.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9QmgWat-noHLkDuAiVIgABRgg"]
[Tue Jul 21 07:57:30.909273 2026] [security2:error] [pid 341679:tid 341828] [client 20.197.192.193:54645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/hp2.php"] [unique_id "al9QmgWat-noHLkDuAiVKwAAAR0"]
[Tue Jul 21 07:57:30.935654 2026] [core:error] [pid 341679:tid 341736] [remote 40.77.167.77:18344] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:30.935674 2026] [core:error] [pid 341679:tid 341736] [remote 40.77.167.77:18344] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:31.059117 2026] [security2:error] [pid 341679:tid 341911] [client 4.204.201.85:9581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/media.php"] [unique_id "al9QmwWat-noHLkDuAiVQAAAAXA"]
[Tue Jul 21 07:57:31.134346 2026] [security2:error] [pid 341679:tid 341872] [client 20.226.60.151:61507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9QmwWat-noHLkDuAiVVgAAAUk"]
[Tue Jul 21 07:57:31.175101 2026] [security2:error] [pid 341679:tid 341876] [client 106.215.181.8:32935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmwWat-noHLkDuAiVVwAAAU0"]
[Tue Jul 21 07:57:31.175254 2026] [security2:error] [pid 341679:tid 341876] [client 106.215.181.8:32935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmwWat-noHLkDuAiVVwAAAU0"]
[Tue Jul 21 07:57:31.399028 2026] [security2:error] [pid 341679:tid 341931] [client 20.151.10.161:29098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/seiso.php"] [unique_id "al9QmwWat-noHLkDuAiVYAAAAYQ"]
[Tue Jul 21 07:57:31.414048 2026] [security2:error] [pid 341679:tid 341861] [client 65.21.113.253:52730] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QmgWat-noHLkDuAiVLgAAAT4"]
[Tue Jul 21 07:57:31.517021 2026] [security2:error] [pid 341679:tid 341864] [client 20.226.60.151:59910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/edorxrr.php"] [unique_id "al9QmwWat-noHLkDuAiVaQAAAUE"]
[Tue Jul 21 07:57:31.521017 2026] [security2:error] [pid 341679:tid 341873] [client 20.206.105.145:55816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/coffexium.php"] [unique_id "al9QmwWat-noHLkDuAiVawAAAUo"]
[Tue Jul 21 07:57:31.628776 2026] [security2:error] [pid 341679:tid 341934] [client 122.162.144.145:26180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QmwWat-noHLkDuAiVbAAAAYc"]
[Tue Jul 21 07:57:31.628887 2026] [security2:error] [pid 341679:tid 341934] [client 122.162.144.145:26180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QmwWat-noHLkDuAiVbAAAAYc"]
[Tue Jul 21 07:57:31.771537 2026] [security2:error] [pid 341679:tid 341850] [client 65.21.113.253:42910] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QmwWat-noHLkDuAiVcAAAATM"]
[Tue Jul 21 07:57:31.797965 2026] [security2:error] [pid 341679:tid 341761] [remote 45.3.52.62:23731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9QmgWat-noHLkDuAiVJQABYFE"]
[Tue Jul 21 07:57:31.835409 2026] [security2:error] [pid 341679:tid 341935] [client 103.78.200.11:55687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmwWat-noHLkDuAiVcgAAAYg"]
[Tue Jul 21 07:57:31.835544 2026] [security2:error] [pid 341679:tid 341935] [client 103.78.200.11:55687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QmwWat-noHLkDuAiVcgAAAYg"]
[Tue Jul 21 07:57:31.878026 2026] [security2:error] [pid 341679:tid 341691] [remote 20.153.140.50:52364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fisiopelvicafloripa.com.br"] [uri "/wp-login.php"] [unique_id "al9QmwWat-noHLkDuAiVcwABews"]
[Tue Jul 21 07:57:32.372511 2026] [security2:error] [pid 341679:tid 341898] [client 103.166.103.129:57467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QnAWat-noHLkDuAiVigAAAWM"]
[Tue Jul 21 07:57:32.372626 2026] [security2:error] [pid 341679:tid 341898] [client 103.166.103.129:57467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QnAWat-noHLkDuAiVigAAAWM"]
[Tue Jul 21 07:57:32.383882 2026] [security2:error] [pid 341679:tid 341933] [client 20.151.10.161:29094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/155.php"] [unique_id "al9QnAWat-noHLkDuAiVjAAAAYY"]
[Tue Jul 21 07:57:32.864311 2026] [security2:error] [pid 341679:tid 341935] [client 20.206.105.145:55826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/app.php"] [unique_id "al9QnAWat-noHLkDuAiVoAAAAYg"]
[Tue Jul 21 07:57:32.896579 2026] [security2:error] [pid 341679:tid 341914] [client 65.21.113.253:52732] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QnAWat-noHLkDuAiVjgAAAXM"]
[Tue Jul 21 07:57:32.921917 2026] [qos:error] [pid 341679:tid 341864] [client 187.43.201.140:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9QnAWat-noHLkDuAiWLAAAAUE, referer: https://brasilmotoeletrica.com/scooter-eletricas/?utm_medium=paid&utm_source=ig&utm_id=120244557335750549&utm_content=120248979284690549&utm_term=120244557336090549&utm_campaign=120244557335750549&fbclid=PAZXh0bgNhZW0BMABhZGlkAas1zz_4dyVzcnRjBmFwcF9pZA81NjcwNjczNDMzNTI0MjcAAafmjQtxFVggVqlzhrHBKBHeiZistS-kEca0FB2vCK4Dq3XJtDEgufF8oNYi2g_aem_YECiRvKcgU-vjaKQxoEq_A
[Tue Jul 21 07:57:32.922099 2026] [qos:error] [pid 341679:tid 341861] [client 187.43.201.140:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9QnAWat-noHLkDuAiWKAAAAT4, referer: https://brasilmotoeletrica.com/wp-content/uploads/elementor/css/post-378.css?ver=1784571016
[Tue Jul 21 07:57:32.922112 2026] [qos:error] [pid 341679:tid 341865] [client 187.43.201.140:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9QnAWat-noHLkDuAiWKQAAAUI, referer: https://brasilmotoeletrica.com/scooter-eletricas/?utm_medium=paid&utm_source=ig&utm_id=120244557335750549&utm_content=120248979284690549&utm_term=120244557336090549&utm_campaign=120244557335750549&fbclid=PAZXh0bgNhZW0BMABhZGlkAas1zz_4dyVzcnRjBmFwcF9pZA81NjcwNjczNDMzNTI0MjcAAafmjQtxFVggVqlzhrHBKBHeiZistS-kEca0FB2vCK4Dq3XJtDEgufF8oNYi2g_aem_YECiRvKcgU-vjaKQxoEq_A
[Tue Jul 21 07:57:32.922127 2026] [qos:error] [pid 341679:tid 341933] [client 187.43.201.140:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=103, c=50.6.100.222, id=al9QnAWat-noHLkDuAiWKgAAAYY, referer: https://brasilmotoeletrica.com/wp-content/uploads/elementor/css/post-378.css?ver=1784571016
[Tue Jul 21 07:57:32.922132 2026] [qos:error] [pid 341679:tid 341848] [client 187.43.201.140:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.100.222, id=al9QnAWat-noHLkDuAiWKwAAATE, referer: https://brasilmotoeletrica.com/wp-content/uploads/elementor/css/post-378.css?ver=1784571016
[Tue Jul 21 07:57:32.922142 2026] [qos:error] [pid 341679:tid 341934] [client 187.43.201.140:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.100.222, id=al9QnAWat-noHLkDuAiWLgAAAYc, referer: https://instagram.com/
[Tue Jul 21 07:57:32.922188 2026] [qos:error] [pid 341679:tid 341902] [client 187.43.201.140:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=104, c=50.6.100.222, id=al9QnAWat-noHLkDuAiWLwAAAWc, referer: https://brasilmotoeletrica.com/wp-content/uploads/elementor/css/post-378.css?ver=1784571016
[Tue Jul 21 07:57:32.924070 2026] [qos:error] [pid 341679:tid 341868] [client 187.43.201.140:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9QnAWat-noHLkDuAiWMQAAAUU, referer: https://brasilmotoeletrica.com/wp-content/uploads/elementor/css/post-378.css?ver=1784571016
[Tue Jul 21 07:57:32.924162 2026] [qos:error] [pid 341679:tid 341863] [client 187.43.201.140:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9QnAWat-noHLkDuAiWMwAAAUA, referer: https://brasilmotoeletrica.com/scooter-eletricas/?utm_medium=paid&utm_source=ig&utm_id=120244557335750549&utm_content=120248979284690549&utm_term=120244557336090549&utm_campaign=120244557335750549&fbclid=PAZXh0bgNhZW0BMABhZGlkAas1zz_4dyVzcnRjBmFwcF9pZA81NjcwNjczNDMzNTI0MjcAAafmjQtxFVggVqlzhrHBKBHeiZistS-kEca0FB2vCK4Dq3XJtDEgufF8oNYi2g_aem_YECiRvKcgU-vjaKQxoEq_A
[Tue Jul 21 07:57:32.924165 2026] [qos:error] [pid 341679:tid 341880] [client 187.43.201.140:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9QnAWat-noHLkDuAiWNAAAAVE, referer: https://brasilmotoeletrica.com/wp-content/uploads/elementor/css/post-378.css?ver=1784571016
[Tue Jul 21 07:57:32.924673 2026] [qos:error] [pid 341679:tid 341879] [client 187.43.201.140:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9QnAWat-noHLkDuAiWNQAAAVA, referer: https://brasilmotoeletrica.com/scooter-eletricas/?utm_medium=paid&utm_source=ig&utm_id=120244557335750549&utm_content=120248979284690549&utm_term=120244557336090549&utm_campaign=120244557335750549&fbclid=PAZXh0bgNhZW0BMABhZGlkAas1zz_4dyVzcnRjBmFwcF9pZA81NjcwNjczNDMzNTI0MjcAAafmjQtxFVggVqlzhrHBKBHeiZistS-kEca0FB2vCK4Dq3XJtDEgufF8oNYi2g_aem_YECiRvKcgU-vjaKQxoEq_A
[Tue Jul 21 07:57:32.978182 2026] [security2:error] [pid 341679:tid 341890] [client 103.29.114.44:34384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QnAWat-noHLkDuAiWOQAAAVs"]
[Tue Jul 21 07:57:32.978307 2026] [security2:error] [pid 341679:tid 341890] [client 103.29.114.44:34384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QnAWat-noHLkDuAiWOQAAAVs"]
[Tue Jul 21 07:57:33.109807 2026] [core:alert] [pid 341679:tid 341871] [client 57.141.18.114:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:57:33.256579 2026] [security2:error] [pid 341679:tid 341928] [client 20.151.10.161:28855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/ppp.php"] [unique_id "al9QnQWat-noHLkDuAiWTQAAAYE"]
[Tue Jul 21 07:57:33.289256 2026] [security2:error] [pid 341679:tid 341850] [client 20.104.96.117:3515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/222.php"] [unique_id "al9QnQWat-noHLkDuAiWTgAAATM"]
[Tue Jul 21 07:57:33.425603 2026] [security2:error] [pid 341679:tid 341743] [remote 14.225.211.68:37664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.211.225.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9QnQWat-noHLkDuAiWUAABQD8"]
[Tue Jul 21 07:57:33.615669 2026] [security2:error] [pid 341679:tid 341858] [client 65.21.113.253:52730] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QnQWat-noHLkDuAiWSwAAATs"]
[Tue Jul 21 07:57:33.688042 2026] [security2:error] [pid 341679:tid 341753] [remote 45.3.42.127:15549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9QnQWat-noHLkDuAiWXAABOEk"]
[Tue Jul 21 07:57:33.760908 2026] [security2:error] [pid 341679:tid 341888] [client 172.245.102.44:43441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QnQWat-noHLkDuAiWagAAAVk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:33.782144 2026] [security2:error] [pid 341679:tid 341754] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QnQWat-noHLkDuAiWawABHko"]
[Tue Jul 21 07:57:33.782284 2026] [security2:error] [pid 341679:tid 341829] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QnQWat-noHLkDuAiWawABHko"]
[Tue Jul 21 07:57:33.860109 2026] [security2:error] [pid 341679:tid 341891] [client 122.179.91.63:10608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QnQWat-noHLkDuAiWbAAAAVw"]
[Tue Jul 21 07:57:33.860217 2026] [security2:error] [pid 341679:tid 341891] [client 122.179.91.63:10608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QnQWat-noHLkDuAiWbAAAAVw"]
[Tue Jul 21 07:57:33.863485 2026] [security2:error] [pid 341679:tid 341862] [client 20.151.10.161:29185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/201.php"] [unique_id "al9QnQWat-noHLkDuAiWbQAAAT8"]
[Tue Jul 21 07:57:33.941832 2026] [security2:error] [pid 341679:tid 341902] [client 4.204.201.85:9617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/images.php"] [unique_id "al9QnQWat-noHLkDuAiWcAAAAWc"]
[Tue Jul 21 07:57:34.077395 2026] [security2:error] [pid 341679:tid 341840] [client 74.249.245.134:54375] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/1.php"] [unique_id "al9QngWat-noHLkDuAiWeAAAASk"]
[Tue Jul 21 07:57:34.077515 2026] [security2:error] [pid 341679:tid 341840] [client 74.249.245.134:54375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/1.php"] [unique_id "al9QngWat-noHLkDuAiWeAAAASk"]
[Tue Jul 21 07:57:34.199615 2026] [security2:error] [pid 341679:tid 341812] [client 20.151.10.161:29071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/ops.php"] [unique_id "al9QngWat-noHLkDuAiWfgAAAQ0"]
[Tue Jul 21 07:57:34.257874 2026] [security2:error] [pid 341679:tid 341897] [client 102.206.115.33:60088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QngWat-noHLkDuAiWgAAAAWI"]
[Tue Jul 21 07:57:34.258209 2026] [security2:error] [pid 341679:tid 341897] [client 102.206.115.33:60088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QngWat-noHLkDuAiWgAAAAWI"]
[Tue Jul 21 07:57:34.395377 2026] [security2:error] [pid 341679:tid 341764] [remote 45.117.83.212:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/wp-login.php"] [unique_id "al9QngWat-noHLkDuAiWhAABclQ"]
[Tue Jul 21 07:57:34.440209 2026] [security2:error] [pid 341679:tid 341776] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QngWat-noHLkDuAiWhwABDmA"]
[Tue Jul 21 07:57:34.440322 2026] [security2:error] [pid 341679:tid 341813] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QngWat-noHLkDuAiWhwABDmA"]
[Tue Jul 21 07:57:34.610603 2026] [security2:error] [pid 341679:tid 341914] [client 20.151.10.161:29117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/ingfo.php"] [unique_id "al9QngWat-noHLkDuAiWkgAAAXM"]
[Tue Jul 21 07:57:34.633328 2026] [security2:error] [pid 341679:tid 341819] [client 20.206.105.145:55892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/core.php"] [unique_id "al9QngWat-noHLkDuAiWlgAAARQ"]
[Tue Jul 21 07:57:35.173175 2026] [security2:error] [pid 341679:tid 341839] [client 20.151.10.161:29074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/error_log.php"] [unique_id "al9QnwWat-noHLkDuAiWpQAAASg"]
[Tue Jul 21 07:57:35.191595 2026] [security2:error] [pid 341679:tid 341929] [client 20.104.96.117:3518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/test.php"] [unique_id "al9QnwWat-noHLkDuAiWpgAAAYI"]
[Tue Jul 21 07:57:35.221702 2026] [security2:error] [pid 341679:tid 341884] [client 103.86.117.203:52356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QnwWat-noHLkDuAiWqgAAAVU"]
[Tue Jul 21 07:57:35.221870 2026] [security2:error] [pid 341679:tid 341884] [client 103.86.117.203:52356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QnwWat-noHLkDuAiWqgAAAVU"]
[Tue Jul 21 07:57:35.532646 2026] [security2:error] [pid 341679:tid 341802] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QnwWat-noHLkDuAiWsgABI3o"]
[Tue Jul 21 07:57:35.532804 2026] [security2:error] [pid 341679:tid 341834] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QnwWat-noHLkDuAiWsgABI3o"]
[Tue Jul 21 07:57:35.589075 2026] [security2:error] [pid 341679:tid 341833] [client 4.204.201.85:9577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/gecko.php"] [unique_id "al9QnwWat-noHLkDuAiWtQAAASI"]
[Tue Jul 21 07:57:35.830443 2026] [security2:error] [pid 341679:tid 341916] [client 122.164.127.47:55876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QnwWat-noHLkDuAiWvwAAAXU"]
[Tue Jul 21 07:57:35.830566 2026] [security2:error] [pid 341679:tid 341916] [client 122.164.127.47:55876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QnwWat-noHLkDuAiWvwAAAXU"]
[Tue Jul 21 07:57:35.834350 2026] [security2:error] [pid 341679:tid 341862] [client 20.151.10.161:29197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/xenon1337.php"] [unique_id "al9QnwWat-noHLkDuAiWwAAAAT8"]
[Tue Jul 21 07:57:36.002635 2026] [security2:error] [pid 341679:tid 341865] [client 20.206.105.145:28667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/main.php"] [unique_id "al9QoAWat-noHLkDuAiWxQAAAUI"]
[Tue Jul 21 07:57:36.331269 2026] [security2:error] [pid 341679:tid 341874] [client 20.151.10.161:29225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/test11.php"] [unique_id "al9QoAWat-noHLkDuAiW1QAAAUs"]
[Tue Jul 21 07:57:36.485477 2026] [security2:error] [pid 341679:tid 341819] [client 117.210.135.0:52834] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QoAWat-noHLkDuAiW1wAAARQ"]
[Tue Jul 21 07:57:36.485712 2026] [security2:error] [pid 341679:tid 341819] [client 117.210.135.0:52834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QoAWat-noHLkDuAiW1wAAARQ"]
[Tue Jul 21 07:57:36.522067 2026] [security2:error] [pid 341679:tid 341899] [client 20.226.60.151:56707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-link-zorm.php"] [unique_id "al9QoAWat-noHLkDuAiW2AAAAWQ"]
[Tue Jul 21 07:57:36.559175 2026] [security2:error] [pid 341679:tid 341936] [client 65.21.113.253:52730] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QoAWat-noHLkDuAiWxgAAAYk"]
[Tue Jul 21 07:57:36.723476 2026] [security2:error] [pid 341679:tid 341934] [client 103.178.2.190:53508] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "eclipsesofts.com"] [uri "/wp-comments-post.php"] [unique_id "al9QnwWat-noHLkDuAiWrwAAAYc"]
[Tue Jul 21 07:57:36.756601 2026] [security2:error] [pid 341679:tid 341818] [client 20.151.10.161:29232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/koala.php"] [unique_id "al9QoAWat-noHLkDuAiW5wAAARM"]
[Tue Jul 21 07:57:36.967969 2026] [security2:error] [pid 341679:tid 341914] [client 20.104.96.117:3553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/aaa.php"] [unique_id "al9QoAWat-noHLkDuAiW6wAAAXM"]
[Tue Jul 21 07:57:37.131259 2026] [security2:error] [pid 341679:tid 341894] [client 4.204.201.85:61576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/82.php"] [unique_id "al9QoQWat-noHLkDuAiW7gAAAV8"]
[Tue Jul 21 07:57:37.237939 2026] [autoindex:error] [pid 341679:tid 341841] [client 82.102.18.182:44604] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:37.269115 2026] [security2:error] [pid 341679:tid 341872] [client 20.151.10.161:29207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/mac.php"] [unique_id "al9QoQWat-noHLkDuAiW_QAAAUk"]
[Tue Jul 21 07:57:37.297873 2026] [security2:error] [pid 341679:tid 341741] [remote 20.153.140.50:49818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shop-officialstore.com"] [uri "/wp-login.php"] [unique_id "al9QoQWat-noHLkDuAiW_gABDj0"]
[Tue Jul 21 07:57:37.484621 2026] [security2:error] [pid 341679:tid 341895] [client 193.36.225.56:46275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QoQWat-noHLkDuAiW_wAAAWA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:37.575089 2026] [security2:error] [pid 341679:tid 341725] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QoQWat-noHLkDuAiXBQABFi0"]
[Tue Jul 21 07:57:37.575240 2026] [security2:error] [pid 341679:tid 341821] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QoQWat-noHLkDuAiXBQABFi0"]
[Tue Jul 21 07:57:37.664400 2026] [security2:error] [pid 341679:tid 341907] [client 20.206.105.145:55919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/init.php"] [unique_id "al9QoQWat-noHLkDuAiXDAAAAWw"]
[Tue Jul 21 07:57:37.737673 2026] [security2:error] [pid 341679:tid 341878] [client 65.21.113.253:50120] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QoQWat-noHLkDuAiXEQAAAU8"]
[Tue Jul 21 07:57:37.758805 2026] [security2:error] [pid 341679:tid 341685] [remote 65.111.14.57:24473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.14.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9QoQWat-noHLkDuAiXEgABNQU"]
[Tue Jul 21 07:57:37.795402 2026] [security2:error] [pid 341679:tid 341884] [client 20.151.10.161:28849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/25d653587fdfd1.php"] [unique_id "al9QoQWat-noHLkDuAiXFgAAAVU"]
[Tue Jul 21 07:57:37.838568 2026] [security2:error] [pid 341679:tid 341737] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QoQWat-noHLkDuAiXGAABXTk"]
[Tue Jul 21 07:57:37.838717 2026] [security2:error] [pid 341679:tid 341892] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QoQWat-noHLkDuAiXGAABXTk"]
[Tue Jul 21 07:57:37.866879 2026] [security2:error] [pid 341679:tid 341929] [client 41.68.90.219:63949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QoQWat-noHLkDuAiXGQAAAYI"]
[Tue Jul 21 07:57:37.868383 2026] [security2:error] [pid 341679:tid 341929] [client 41.68.90.219:63949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QoQWat-noHLkDuAiXGQAAAYI"]
[Tue Jul 21 07:57:38.054278 2026] [security2:error] [pid 341679:tid 341921] [client 109.60.28.94:60212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QogWat-noHLkDuAiXHwAAAXo"]
[Tue Jul 21 07:57:38.054438 2026] [security2:error] [pid 341679:tid 341921] [client 109.60.28.94:60212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QogWat-noHLkDuAiXHwAAAXo"]
[Tue Jul 21 07:57:38.184209 2026] [security2:error] [pid 341679:tid 341922] [client 178.153.91.96:6260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QogWat-noHLkDuAiXIgAAAXs"]
[Tue Jul 21 07:57:38.184372 2026] [security2:error] [pid 341679:tid 341922] [client 178.153.91.96:6260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QogWat-noHLkDuAiXIgAAAXs"]
[Tue Jul 21 07:57:38.226191 2026] [security2:error] [pid 341679:tid 341930] [client 20.104.96.117:3574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/11.php"] [unique_id "al9QogWat-noHLkDuAiXJwAAAYM"]
[Tue Jul 21 07:57:38.378922 2026] [security2:error] [pid 341679:tid 341890] [client 65.21.113.253:52730] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QoQWat-noHLkDuAiXHQAAAVs"]
[Tue Jul 21 07:57:38.382041 2026] [security2:error] [pid 341679:tid 341895] [client 20.151.10.161:28818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wefile.php"] [unique_id "al9QogWat-noHLkDuAiXKwAAAWA"]
[Tue Jul 21 07:57:38.485403 2026] [autoindex:error] [pid 341679:tid 341839] [client 82.102.18.182:44604] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:38.526834 2026] [security2:error] [pid 341679:tid 341856] [client 4.204.201.85:9571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/admin.php"] [unique_id "al9QogWat-noHLkDuAiXLwAAATk"]
[Tue Jul 21 07:57:38.670591 2026] [security2:error] [pid 341679:tid 341840] [client 38.100.221.102:18931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QogWat-noHLkDuAiXMAAAASk"]
[Tue Jul 21 07:57:38.670737 2026] [security2:error] [pid 341679:tid 341840] [client 38.100.221.102:18931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QogWat-noHLkDuAiXMAAAASk"]
[Tue Jul 21 07:57:38.743150 2026] [security2:error] [pid 341679:tid 341758] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QogWat-noHLkDuAiXNgABTk4"]
[Tue Jul 21 07:57:38.743308 2026] [security2:error] [pid 341679:tid 341877] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QogWat-noHLkDuAiXNgABTk4"]
[Tue Jul 21 07:57:38.771239 2026] [security2:error] [pid 341679:tid 341872] [client 59.93.4.33:62945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QogWat-noHLkDuAiXOQAAAUk"]
[Tue Jul 21 07:57:38.771321 2026] [security2:error] [pid 341679:tid 341872] [client 59.93.4.33:62945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QogWat-noHLkDuAiXOQAAAUk"]
[Tue Jul 21 07:57:38.854939 2026] [security2:error] [pid 341679:tid 341778] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QogWat-noHLkDuAiXRgABhWI"]
[Tue Jul 21 07:57:38.855066 2026] [security2:error] [pid 341679:tid 341932] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QogWat-noHLkDuAiXRgABhWI"]
[Tue Jul 21 07:57:39.080143 2026] [security2:error] [pid 341679:tid 341853] [client 20.104.96.117:3509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/mac.php"] [unique_id "al9QowWat-noHLkDuAiXTAAAATY"]
[Tue Jul 21 07:57:39.150125 2026] [security2:error] [pid 341679:tid 341924] [client 117.247.80.59:22479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QowWat-noHLkDuAiXTwAAAX0"]
[Tue Jul 21 07:57:39.150255 2026] [security2:error] [pid 341679:tid 341924] [client 117.247.80.59:22479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QowWat-noHLkDuAiXTwAAAX0"]
[Tue Jul 21 07:57:39.198207 2026] [autoindex:error] [pid 341679:tid 341855] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:39.201756 2026] [security2:error] [pid 341679:tid 341828] [client 20.226.60.151:59918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/miru1.php"] [unique_id "al9QowWat-noHLkDuAiXVAAAAR0"]
[Tue Jul 21 07:57:39.405444 2026] [autoindex:error] [pid 341679:tid 341835] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:39.453838 2026] [security2:error] [pid 341679:tid 341848] [client 20.151.10.161:29184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-admin/css/colour.php"] [unique_id "al9QowWat-noHLkDuAiXZQAAATE"]
[Tue Jul 21 07:57:39.610444 2026] [autoindex:error] [pid 341679:tid 341890] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:39.699260 2026] [security2:error] [pid 341679:tid 341927] [client 4.204.201.85:9574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/adminner.php"] [unique_id "al9QowWat-noHLkDuAiXcwAAAYA"]
[Tue Jul 21 07:57:39.758722 2026] [security2:error] [pid 341679:tid 341840] [client 65.21.113.253:50120] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QowWat-noHLkDuAiXdQAAASk"]
[Tue Jul 21 07:57:39.815115 2026] [autoindex:error] [pid 341679:tid 341819] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:39.885043 2026] [security2:error] [pid 341679:tid 341846] [client 20.151.10.161:28839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/2P.php"] [unique_id "al9QowWat-noHLkDuAiXgAAAAS8"]
[Tue Jul 21 07:57:39.997088 2026] [security2:error] [pid 341679:tid 341768] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QowWat-noHLkDuAiXgwABN1g"]
[Tue Jul 21 07:57:39.997297 2026] [security2:error] [pid 341679:tid 341854] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QowWat-noHLkDuAiXgwABN1g"]
[Tue Jul 21 07:57:40.012084 2026] [security2:error] [pid 341679:tid 341827] [client 204.8.98.45:48506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9QpAWat-noHLkDuAiXhwAAARw"]
[Tue Jul 21 07:57:40.012171 2026] [security2:error] [pid 341679:tid 341827] [client 204.8.98.45:48506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9QpAWat-noHLkDuAiXhwAAARw"]
[Tue Jul 21 07:57:40.014344 2026] [core:error] [pid 341679:tid 341760] [remote 40.77.167.247:44160] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:40.014358 2026] [core:error] [pid 341679:tid 341760] [remote 40.77.167.247:44160] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:40.023863 2026] [autoindex:error] [pid 341679:tid 341887] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:40.138985 2026] [core:error] [pid 341679:tid 341721] [remote 40.77.167.247:44160] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:40.139014 2026] [core:error] [pid 341679:tid 341721] [remote 40.77.167.247:44160] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:40.229745 2026] [autoindex:error] [pid 341679:tid 341921] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:40.263997 2026] [core:error] [pid 341679:tid 341680] [remote 40.77.167.247:44160] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:40.264023 2026] [core:error] [pid 341679:tid 341680] [remote 40.77.167.247:44160] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:40.420631 2026] [security2:error] [pid 341679:tid 341890] [client 20.151.10.161:29113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/.well-known/about.php"] [unique_id "al9QpAWat-noHLkDuAiXoQAAAVs"]
[Tue Jul 21 07:57:40.442634 2026] [autoindex:error] [pid 341679:tid 341927] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:40.459829 2026] [security2:error] [pid 341679:tid 341845] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9QpAWat-noHLkDuAiXnQABLh4"]
[Tue Jul 21 07:57:40.518844 2026] [security2:error] [pid 341679:tid 341878] [client 182.8.255.181:17199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QpAWat-noHLkDuAiXqAAAAU8"]
[Tue Jul 21 07:57:40.518993 2026] [security2:error] [pid 341679:tid 341878] [client 182.8.255.181:17199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QpAWat-noHLkDuAiXqAAAAU8"]
[Tue Jul 21 07:57:40.528941 2026] [security2:error] [pid 341679:tid 341840] [client 20.104.96.117:3551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/chosen.php"] [unique_id "al9QpAWat-noHLkDuAiXqgAAASk"]
[Tue Jul 21 07:57:40.647506 2026] [autoindex:error] [pid 341679:tid 341906] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:40.663857 2026] [security2:error] [pid 341679:tid 341874] [client 20.226.60.151:60020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/sump1.php"] [unique_id "al9QpAWat-noHLkDuAiXsQAAAUs"]
[Tue Jul 21 07:57:40.724010 2026] [security2:error] [pid 341679:tid 341864] [client 20.206.105.145:28625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/prekel.php"] [unique_id "al9QpAWat-noHLkDuAiXswAAAUE"]
[Tue Jul 21 07:57:40.844104 2026] [security2:error] [pid 341679:tid 341935] [client 65.21.113.253:54420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QpAWat-noHLkDuAiXpAAAAYg"]
[Tue Jul 21 07:57:41.013282 2026] [security2:error] [pid 341679:tid 341814] [client 202.143.127.214:56344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QpQWat-noHLkDuAiXvwAAAQ8"]
[Tue Jul 21 07:57:41.013441 2026] [security2:error] [pid 341679:tid 341814] [client 202.143.127.214:56344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QpQWat-noHLkDuAiXvwAAAQ8"]
[Tue Jul 21 07:57:41.036918 2026] [security2:error] [pid 341679:tid 341934] [client 103.178.2.190:53508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "eclipsesofts.com"] [uri "/wp-comments-post.php"] [unique_id "al9QnwWat-noHLkDuAiWrwAAAYc"]
[Tue Jul 21 07:57:41.045145 2026] [security2:error] [pid 341679:tid 341776] [remote 65.111.1.0:36403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.1.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9QpQWat-noHLkDuAiXwAABdmA"]
[Tue Jul 21 07:57:41.211087 2026] [security2:error] [pid 341679:tid 341923] [client 87.116.180.198:13874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QpQWat-noHLkDuAiXxAAAAXw"]
[Tue Jul 21 07:57:41.213364 2026] [security2:error] [pid 341679:tid 341923] [client 87.116.180.198:13874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QpQWat-noHLkDuAiXxAAAAXw"]
[Tue Jul 21 07:57:41.362458 2026] [autoindex:error] [pid 341679:tid 341922] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:41.386741 2026] [security2:error] [pid 341679:tid 341903] [client 20.151.10.161:29108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9QpQWat-noHLkDuAiXzQAAAWg"]
[Tue Jul 21 07:57:41.401873 2026] [security2:error] [pid 341679:tid 341868] [client 204.8.98.45:51672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9QpQWat-noHLkDuAiXzgAAAUU"]
[Tue Jul 21 07:57:41.401999 2026] [security2:error] [pid 341679:tid 341868] [client 204.8.98.45:51672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9QpQWat-noHLkDuAiXzgAAAUU"]
[Tue Jul 21 07:57:41.499155 2026] [security2:error] [pid 341679:tid 341813] [client 136.144.33.103:34055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QpQWat-noHLkDuAiX1AAAAQ4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:41.537131 2026] [security2:error] [pid 341679:tid 341872] [client 223.236.153.128:7497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QpQWat-noHLkDuAiX1gAAAUk"]
[Tue Jul 21 07:57:41.537233 2026] [security2:error] [pid 341679:tid 341872] [client 223.236.153.128:7497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QpQWat-noHLkDuAiX1gAAAUk"]
[Tue Jul 21 07:57:41.583486 2026] [autoindex:error] [pid 341679:tid 341856] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:41.664477 2026] [security2:error] [pid 341679:tid 341845] [client 4.204.201.85:9586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/admin.php"] [unique_id "al9QpQWat-noHLkDuAiX3AAAAS4"]
[Tue Jul 21 07:57:41.713367 2026] [security2:error] [pid 341679:tid 341853] [client 106.215.181.8:2899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QpQWat-noHLkDuAiX3QAAATY"]
[Tue Jul 21 07:57:41.713536 2026] [security2:error] [pid 341679:tid 341853] [client 106.215.181.8:2899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QpQWat-noHLkDuAiX3QAAATY"]
[Tue Jul 21 07:57:41.758546 2026] [security2:error] [pid 341679:tid 341906] [client 20.206.105.145:28670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/0.php"] [unique_id "al9QpQWat-noHLkDuAiX3gAAAWs"]
[Tue Jul 21 07:57:41.795055 2026] [autoindex:error] [pid 341679:tid 341839] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:42.013441 2026] [autoindex:error] [pid 341679:tid 341902] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:42.111761 2026] [security2:error] [pid 341679:tid 341914] [client 198.54.128.138:49264] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9QpgWat-noHLkDuAiX8wAAAXM"]
[Tue Jul 21 07:57:42.111875 2026] [security2:error] [pid 341679:tid 341914] [client 198.54.128.138:49264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9QpgWat-noHLkDuAiX8wAAAXM"]
[Tue Jul 21 07:57:42.234104 2026] [autoindex:error] [pid 341679:tid 341818] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:42.304131 2026] [security2:error] [pid 341679:tid 341873] [client 20.151.10.161:28705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/bob.php"] [unique_id "al9QpgWat-noHLkDuAiYGgAAAUo"]
[Tue Jul 21 07:57:42.328896 2026] [security2:error] [pid 341679:tid 341820] [client 122.162.144.145:10056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QpgWat-noHLkDuAiYKgAAARU"]
[Tue Jul 21 07:57:42.328980 2026] [security2:error] [pid 341679:tid 341820] [client 122.162.144.145:10056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QpgWat-noHLkDuAiYKgAAARU"]
[Tue Jul 21 07:57:42.446494 2026] [autoindex:error] [pid 341679:tid 341911] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:42.466108 2026] [security2:error] [pid 341679:tid 341879] [client 103.78.200.11:56150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QpgWat-noHLkDuAiYNAAAAVA"]
[Tue Jul 21 07:57:42.466203 2026] [security2:error] [pid 341679:tid 341879] [client 103.78.200.11:56150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QpgWat-noHLkDuAiYNAAAAVA"]
[Tue Jul 21 07:57:42.554166 2026] [security2:error] [pid 341679:tid 341856] [client 20.104.96.117:3539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/cream1.php"] [unique_id "al9QpgWat-noHLkDuAiYPAAAATk"]
[Tue Jul 21 07:57:42.705165 2026] [autoindex:error] [pid 341679:tid 341853] [client 82.102.18.182:44604] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:42.790264 2026] [security2:error] [pid 341679:tid 341936] [client 4.204.201.85:9560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/k.php"] [unique_id "al9QpgWat-noHLkDuAiYcAAAAYk"]
[Tue Jul 21 07:57:42.951713 2026] [autoindex:error] [pid 341679:tid 341854] [client 82.102.18.182:44604] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:42.980078 2026] [security2:error] [pid 341679:tid 341934] [client 65.21.113.253:50120] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QpgWat-noHLkDuAiYfQAAAYc"]
[Tue Jul 21 07:57:43.083301 2026] [security2:error] [pid 341679:tid 341836] [client 103.166.103.129:58665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QpwWat-noHLkDuAiYggAAASU"]
[Tue Jul 21 07:57:43.083721 2026] [security2:error] [pid 341679:tid 341836] [client 103.166.103.129:58665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QpwWat-noHLkDuAiYggAAASU"]
[Tue Jul 21 07:57:43.100569 2026] [security2:error] [pid 341679:tid 341868] [client 65.21.113.253:54430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QpgWat-noHLkDuAiYZgAAAUU"]
[Tue Jul 21 07:57:43.135760 2026] [security2:error] [pid 341679:tid 341825] [client 20.197.192.193:3624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/hp3.php"] [unique_id "al9QpwWat-noHLkDuAiYjAAAARo"]
[Tue Jul 21 07:57:43.174022 2026] [security2:error] [pid 341679:tid 341905] [client 103.178.2.190:53790] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "eclipsesofts.com"] [uri "/wp-comments-post.php"] [unique_id "al9QpwWat-noHLkDuAiYrgAAAWo"]
[Tue Jul 21 07:57:43.209393 2026] [autoindex:error] [pid 341679:tid 341841] [client 20.104.96.117:3561] AH01276: Cannot serve directory /home2/thekin17/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:43.234981 2026] [security2:error] [pid 341679:tid 341892] [client 20.226.60.151:56732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-link-szoppm.php"] [unique_id "al9QpwWat-noHLkDuAiYtwAAAV0"]
[Tue Jul 21 07:57:43.331557 2026] [security2:error] [pid 341679:tid 341847] [client 37.140.223.49:21879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QpwWat-noHLkDuAiYrQAAATA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:57:43.372408 2026] [security2:error] [pid 341679:tid 341905] [client 103.178.2.190:53790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "eclipsesofts.com"] [uri "/wp-comments-post.php"] [unique_id "al9QpwWat-noHLkDuAiYrgAAAWo"]
[Tue Jul 21 07:57:43.474086 2026] [security2:error] [pid 341679:tid 341839] [client 103.29.114.44:63200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QpwWat-noHLkDuAiYvgAAASg"]
[Tue Jul 21 07:57:43.474251 2026] [security2:error] [pid 341679:tid 341839] [client 103.29.114.44:63200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QpwWat-noHLkDuAiYvgAAASg"]
[Tue Jul 21 07:57:43.511025 2026] [security2:error] [pid 341679:tid 341872] [client 4.204.201.85:9582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/blurbs.php"] [unique_id "al9QpwWat-noHLkDuAiYvwAAAUk"]
[Tue Jul 21 07:57:43.534149 2026] [autoindex:error] [pid 341679:tid 341849] [client 20.104.96.117:3561] AH01276: Cannot serve directory /home2/thekin17/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:43.691178 2026] [security2:error] [pid 341679:tid 341869] [client 20.104.96.117:3561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/dr.php"] [unique_id "al9QpwWat-noHLkDuAiY0wAAAUY"]
[Tue Jul 21 07:57:43.695303 2026] [security2:error] [pid 341679:tid 341883] [client 204.8.98.45:48512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9QpwWat-noHLkDuAiY1AAAAVQ"]
[Tue Jul 21 07:57:43.695409 2026] [security2:error] [pid 341679:tid 341883] [client 204.8.98.45:48512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9QpwWat-noHLkDuAiY1AAAAVQ"]
[Tue Jul 21 07:57:43.819802 2026] [security2:error] [pid 341679:tid 341854] [client 184.75.221.3:39006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9QpwWat-noHLkDuAiY1wAAATc"]
[Tue Jul 21 07:57:43.819943 2026] [security2:error] [pid 341679:tid 341854] [client 184.75.221.3:39006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9QpwWat-noHLkDuAiY1wAAATc"]
[Tue Jul 21 07:57:43.875258 2026] [security2:error] [pid 341679:tid 341837] [client 20.206.105.145:55904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/BDKR28.php"] [unique_id "al9QpwWat-noHLkDuAiY2wAAASY"]
[Tue Jul 21 07:57:44.084492 2026] [security2:error] [pid 341679:tid 341828] [client 20.151.10.161:28841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/crgio.php"] [unique_id "al9QqAWat-noHLkDuAiY6wAAAR0"]
[Tue Jul 21 07:57:44.120891 2026] [security2:error] [pid 341679:tid 341890] [client 204.8.98.45:51692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9QqAWat-noHLkDuAiY7AAAAVs"]
[Tue Jul 21 07:57:44.121012 2026] [security2:error] [pid 341679:tid 341890] [client 204.8.98.45:51692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9QqAWat-noHLkDuAiY7AAAAVs"]
[Tue Jul 21 07:57:44.139198 2026] [security2:error] [pid 341679:tid 341848] [client 65.21.113.253:54434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QpwWat-noHLkDuAiYzwAAATE"]
[Tue Jul 21 07:57:44.161474 2026] [core:error] [pid 341679:tid 341769] [remote 52.167.144.184:62129] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:44.161498 2026] [core:error] [pid 341679:tid 341769] [remote 52.167.144.184:62129] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:44.293940 2026] [core:error] [pid 341679:tid 341683] [remote 52.167.144.184:62129] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:44.293957 2026] [core:error] [pid 341679:tid 341683] [remote 52.167.144.184:62129] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:44.307088 2026] [security2:error] [pid 341679:tid 341791] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QqAWat-noHLkDuAiY9wABYW8"]
[Tue Jul 21 07:57:44.307236 2026] [security2:error] [pid 341679:tid 341896] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QqAWat-noHLkDuAiY9wABYW8"]
[Tue Jul 21 07:57:44.363740 2026] [security2:error] [pid 341679:tid 341879] [client 74.249.245.134:54378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/chosen.php"] [unique_id "al9QqAWat-noHLkDuAiY-wAAAVA"]
[Tue Jul 21 07:57:44.417894 2026] [core:error] [pid 341679:tid 341761] [remote 52.167.144.184:62129] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:44.417916 2026] [core:error] [pid 341679:tid 341761] [remote 52.167.144.184:62129] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:44.549209 2026] [core:error] [pid 341679:tid 341767] [remote 52.167.144.184:62129] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:44.549242 2026] [core:error] [pid 341679:tid 341767] [remote 52.167.144.184:62129] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:44.565263 2026] [security2:error] [pid 341679:tid 341876] [client 122.179.91.63:20588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QqAWat-noHLkDuAiZBwAAAU0"]
[Tue Jul 21 07:57:44.565391 2026] [security2:error] [pid 341679:tid 341876] [client 122.179.91.63:20588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QqAWat-noHLkDuAiZBwAAAU0"]
[Tue Jul 21 07:57:44.674409 2026] [core:error] [pid 341679:tid 341781] [remote 52.167.144.184:62129] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:44.674428 2026] [core:error] [pid 341679:tid 341781] [remote 52.167.144.184:62129] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:44.737240 2026] [security2:error] [pid 341679:tid 341814] [client 20.206.105.145:55833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/f35.update.php"] [unique_id "al9QqAWat-noHLkDuAiZDgAAAQ8"]
[Tue Jul 21 07:57:44.740064 2026] [security2:error] [pid 341679:tid 341898] [client 102.206.115.33:63468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QqAWat-noHLkDuAiZDwAAAWM"]
[Tue Jul 21 07:57:44.740230 2026] [security2:error] [pid 341679:tid 341898] [client 102.206.115.33:63468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QqAWat-noHLkDuAiZDwAAAWM"]
[Tue Jul 21 07:57:44.767099 2026] [security2:error] [pid 341679:tid 341853] [client 4.204.201.85:9638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/bajah.php"] [unique_id "al9QqAWat-noHLkDuAiZEQAAATY"]
[Tue Jul 21 07:57:44.834569 2026] [security2:error] [pid 341679:tid 341878] [client 20.104.96.117:3487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/x.php"] [unique_id "al9QqAWat-noHLkDuAiZFgAAAU8"]
[Tue Jul 21 07:57:44.861717 2026] [security2:error] [pid 341679:tid 341827] [client 20.151.10.161:29077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/pucci.php"] [unique_id "al9QqAWat-noHLkDuAiZFwAAARw"]
[Tue Jul 21 07:57:45.038024 2026] [security2:error] [pid 341679:tid 341716] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QqQWat-noHLkDuAiZHQABJiQ"]
[Tue Jul 21 07:57:45.038166 2026] [security2:error] [pid 341679:tid 341837] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QqQWat-noHLkDuAiZHQABJiQ"]
[Tue Jul 21 07:57:45.056584 2026] [security2:error] [pid 341679:tid 341893] [client 193.36.225.57:38725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QqQWat-noHLkDuAiZHwAAAV4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:45.284874 2026] [security2:error] [pid 341679:tid 341879] [client 20.226.60.151:60013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/file5.php"] [unique_id "al9QqQWat-noHLkDuAiZKQAAAVA"]
[Tue Jul 21 07:57:45.332231 2026] [security2:error] [pid 341679:tid 341907] [client 20.104.96.117:3544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/155.php"] [unique_id "al9QqQWat-noHLkDuAiZLAAAAWw"]
[Tue Jul 21 07:57:45.494327 2026] [security2:error] [pid 341679:tid 341884] [client 103.178.2.190:53866] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "eclipsesofts.com"] [uri "/wp-comments-post.php"] [unique_id "al9QqQWat-noHLkDuAiZMQAAAVU"]
[Tue Jul 21 07:57:45.617546 2026] [security2:error] [pid 341679:tid 341935] [client 4.204.201.85:9579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/a.php"] [unique_id "al9QqQWat-noHLkDuAiZOAAAAYg"]
[Tue Jul 21 07:57:45.703442 2026] [security2:error] [pid 341679:tid 341894] [client 103.86.117.203:52896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QqQWat-noHLkDuAiZQwAAAV8"]
[Tue Jul 21 07:57:45.703596 2026] [security2:error] [pid 341679:tid 341894] [client 103.86.117.203:52896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QqQWat-noHLkDuAiZQwAAAV8"]
[Tue Jul 21 07:57:45.709163 2026] [security2:error] [pid 341679:tid 341884] [client 103.178.2.190:53866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "eclipsesofts.com"] [uri "/wp-comments-post.php"] [unique_id "al9QqQWat-noHLkDuAiZMQAAAVU"]
[Tue Jul 21 07:57:45.826313 2026] [security2:error] [pid 341679:tid 341823] [client 20.104.96.117:3459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/ops.php"] [unique_id "al9QqQWat-noHLkDuAiZSQAAARg"]
[Tue Jul 21 07:57:46.033377 2026] [security2:error] [pid 341679:tid 341699] [remote 72.167.132.114:41548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9QqgWat-noHLkDuAiZVQABPBM"]
[Tue Jul 21 07:57:46.045605 2026] [security2:error] [pid 341679:tid 341828] [client 193.36.225.152:48919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QqQWat-noHLkDuAiZTAAAAR0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:57:46.092418 2026] [security2:error] [pid 341679:tid 341835] [client 20.151.10.161:29113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-temp.php"] [unique_id "al9QqgWat-noHLkDuAiZWAAAASQ"]
[Tue Jul 21 07:57:46.209506 2026] [security2:error] [pid 341679:tid 341741] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QqgWat-noHLkDuAiZcQABdT0"]
[Tue Jul 21 07:57:46.209745 2026] [security2:error] [pid 341679:tid 341916] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QqgWat-noHLkDuAiZcQABdT0"]
[Tue Jul 21 07:57:46.359128 2026] [security2:error] [pid 341679:tid 341869] [client 122.164.127.47:56470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QqgWat-noHLkDuAiZdwAAAUY"]
[Tue Jul 21 07:57:46.359320 2026] [security2:error] [pid 341679:tid 341869] [client 122.164.127.47:56470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QqgWat-noHLkDuAiZdwAAAUY"]
[Tue Jul 21 07:57:46.460809 2026] [security2:error] [pid 341679:tid 341876] [client 20.104.96.117:45139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/file31.php"] [unique_id "al9QqgWat-noHLkDuAiZgAAAAU0"]
[Tue Jul 21 07:57:46.698315 2026] [security2:error] [pid 341679:tid 341878] [client 4.204.201.85:9626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/edit.php"] [unique_id "al9QqgWat-noHLkDuAiZjgAAAU8"]
[Tue Jul 21 07:57:46.729605 2026] [security2:error] [pid 341679:tid 341827] [client 20.197.192.193:3753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/aa1.php"] [unique_id "al9QqgWat-noHLkDuAiZkAAAARw"]
[Tue Jul 21 07:57:46.755085 2026] [security2:error] [pid 341679:tid 341839] [client 20.151.10.161:28816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-admin/js/index.php"] [unique_id "al9QqgWat-noHLkDuAiZkQAAASg"]
[Tue Jul 21 07:57:46.797710 2026] [security2:error] [pid 341679:tid 341850] [client 65.21.113.253:50120] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QqgWat-noHLkDuAiZlwAAATM"]
[Tue Jul 21 07:57:46.803194 2026] [security2:error] [pid 341679:tid 341820] [client 168.0.212.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "naturofarma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QqQWat-noHLkDuAiZIwABFSk"]
[Tue Jul 21 07:57:46.930184 2026] [security2:error] [pid 341679:tid 341849] [client 65.111.20.63:54091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QqgWat-noHLkDuAiZkgAAATI"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:57:46.992182 2026] [security2:error] [pid 341679:tid 341752] [remote 72.167.132.114:41556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9QqgWat-noHLkDuAiZmwABDUg"]
[Tue Jul 21 07:57:46.993331 2026] [security2:error] [pid 341679:tid 341864] [client 20.206.105.145:55914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/f900.php"] [unique_id "al9QqgWat-noHLkDuAiZnAAAAUE"]
[Tue Jul 21 07:57:47.149077 2026] [security2:error] [pid 341679:tid 341925] [client 117.210.135.0:53547] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QqwWat-noHLkDuAiZpwAAAX4"]
[Tue Jul 21 07:57:47.149280 2026] [security2:error] [pid 341679:tid 341925] [client 117.210.135.0:53547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QqwWat-noHLkDuAiZpwAAAX4"]
[Tue Jul 21 07:57:47.177785 2026] [security2:error] [pid 341679:tid 341838] [client 20.151.10.161:28805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/puc.php"] [unique_id "al9QqwWat-noHLkDuAiZrAAAASc"]
[Tue Jul 21 07:57:47.363098 2026] [security2:error] [pid 341679:tid 341902] [client 20.104.96.117:3476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/file6.php"] [unique_id "al9QqwWat-noHLkDuAiZtAAAAWc"]
[Tue Jul 21 07:57:47.432429 2026] [security2:error] [pid 341679:tid 341871] [client 65.21.113.253:54430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QqwWat-noHLkDuAiZoAAAAUg"]
[Tue Jul 21 07:57:47.500790 2026] [security2:error] [pid 341679:tid 341887] [client 20.151.10.161:29247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/themes.php"] [unique_id "al9QqwWat-noHLkDuAiZugAAAVg"]
[Tue Jul 21 07:57:47.514068 2026] [security2:error] [pid 341679:tid 341862] [client 4.204.201.85:9636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/hosty.php"] [unique_id "al9QqwWat-noHLkDuAiZvAAAAT8"]
[Tue Jul 21 07:57:47.857299 2026] [security2:error] [pid 341679:tid 341842] [client 103.178.2.190:53956] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "eclipsesofts.com"] [uri "/wp-comments-post.php"] [unique_id "al9QqwWat-noHLkDuAiZyAAAASs"]
[Tue Jul 21 07:57:47.989039 2026] [security2:error] [pid 341679:tid 341898] [client 168.0.212.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "naturofarma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QqwWat-noHLkDuAiZyQABYwg"]
[Tue Jul 21 07:57:48.066273 2026] [security2:error] [pid 341679:tid 341842] [client 103.178.2.190:53956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "eclipsesofts.com"] [uri "/wp-comments-post.php"] [unique_id "al9QqwWat-noHLkDuAiZyAAAASs"]
[Tue Jul 21 07:57:48.118144 2026] [security2:error] [pid 341679:tid 341874] [client 20.151.10.161:28852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/dx.php"] [unique_id "al9QrAWat-noHLkDuAiZ0QAAAUs"]
[Tue Jul 21 07:57:48.243165 2026] [security2:error] [pid 341679:tid 341916] [client 4.204.201.85:9564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/k.php"] [unique_id "al9QrAWat-noHLkDuAiZ1gAAAXU"]
[Tue Jul 21 07:57:48.262592 2026] [autoindex:error] [pid 341679:tid 341860] [client 20.104.96.117:3465] AH01276: Cannot serve directory /home2/thekin17/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:48.292470 2026] [security2:error] [pid 341679:tid 341740] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QrAWat-noHLkDuAiZ2wABYTw"]
[Tue Jul 21 07:57:48.292639 2026] [security2:error] [pid 341679:tid 341896] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QrAWat-noHLkDuAiZ2wABYTw"]
[Tue Jul 21 07:57:48.391787 2026] [security2:error] [pid 341679:tid 341905] [client 65.111.26.181:52663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QrAWat-noHLkDuAiZ4QAAAWo"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:57:48.406993 2026] [security2:error] [pid 341679:tid 341895] [client 41.68.90.219:64406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrAWat-noHLkDuAiZ4gAAAWA"]
[Tue Jul 21 07:57:48.408179 2026] [security2:error] [pid 341679:tid 341895] [client 41.68.90.219:64406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrAWat-noHLkDuAiZ4gAAAWA"]
[Tue Jul 21 07:57:48.426244 2026] [security2:error] [pid 341679:tid 341929] [client 74.249.245.134:54351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/css.php"] [unique_id "al9QrAWat-noHLkDuAiZ4wAAAYI"]
[Tue Jul 21 07:57:48.459428 2026] [security2:error] [pid 341679:tid 341839] [client 65.21.113.253:54450] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QqwWat-noHLkDuAiZygAAASg"]
[Tue Jul 21 07:57:48.512818 2026] [security2:error] [pid 341679:tid 341830] [client 20.151.10.161:28693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/p.php"] [unique_id "al9QrAWat-noHLkDuAiZ5gAAAR8"]
[Tue Jul 21 07:57:48.545577 2026] [security2:error] [pid 341679:tid 341911] [client 20.104.96.117:3465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/adminfuns.php"] [unique_id "al9QrAWat-noHLkDuAiZ5wAAAXA"]
[Tue Jul 21 07:57:48.752189 2026] [security2:error] [pid 341679:tid 341920] [client 178.153.91.96:7133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QrAWat-noHLkDuAiZ7wAAAXk"]
[Tue Jul 21 07:57:48.752355 2026] [security2:error] [pid 341679:tid 341920] [client 178.153.91.96:7133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QrAWat-noHLkDuAiZ7wAAAXk"]
[Tue Jul 21 07:57:48.868407 2026] [security2:error] [pid 341679:tid 341821] [client 109.60.28.94:43753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrAWat-noHLkDuAiZ-AAAARY"]
[Tue Jul 21 07:57:48.868558 2026] [security2:error] [pid 341679:tid 341821] [client 109.60.28.94:43753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrAWat-noHLkDuAiZ-AAAARY"]
[Tue Jul 21 07:57:48.950376 2026] [security2:error] [pid 341679:tid 341791] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrAWat-noHLkDuAiZ-wABDW8"]
[Tue Jul 21 07:57:48.950514 2026] [security2:error] [pid 341679:tid 341812] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrAWat-noHLkDuAiZ-wABDW8"]
[Tue Jul 21 07:57:49.028338 2026] [security2:error] [pid 341679:tid 341873] [client 20.151.10.161:29216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/bthil.php"] [unique_id "al9QrQWat-noHLkDuAiZ_QAAAUo"]
[Tue Jul 21 07:57:49.054764 2026] [security2:error] [pid 341679:tid 341823] [client 4.204.201.85:9592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/aaa.php"] [unique_id "al9QrQWat-noHLkDuAiZ_gAAARg"]
[Tue Jul 21 07:57:49.111709 2026] [security2:error] [pid 341679:tid 341913] [client 20.104.96.117:3491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/goods.php"] [unique_id "al9QrQWat-noHLkDuAiaBAAAAXI"]
[Tue Jul 21 07:57:49.210378 2026] [core:error] [pid 341679:tid 341748] [remote 40.77.167.247:44191] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:49.210406 2026] [core:error] [pid 341679:tid 341748] [remote 40.77.167.247:44191] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:49.291197 2026] [security2:error] [pid 341679:tid 341856] [client 38.100.221.102:19044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrQWat-noHLkDuAiaDQAAATk"]
[Tue Jul 21 07:57:49.291498 2026] [security2:error] [pid 341679:tid 341856] [client 38.100.221.102:19044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrQWat-noHLkDuAiaDQAAATk"]
[Tue Jul 21 07:57:49.357216 2026] [security2:error] [pid 341679:tid 341801] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QrQWat-noHLkDuAiaEgABKnk"]
[Tue Jul 21 07:57:49.357426 2026] [security2:error] [pid 341679:tid 341841] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QrQWat-noHLkDuAiaEgABKnk"]
[Tue Jul 21 07:57:49.421496 2026] [security2:error] [pid 341679:tid 341932] [client 20.151.10.161:28842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/7.php"] [unique_id "al9QrQWat-noHLkDuAiaGAAAAYU"]
[Tue Jul 21 07:57:49.578403 2026] [security2:error] [pid 341679:tid 341819] [client 59.93.4.33:63467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrQWat-noHLkDuAiaGwAAARQ"]
[Tue Jul 21 07:57:49.578577 2026] [security2:error] [pid 341679:tid 341819] [client 59.93.4.33:63467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrQWat-noHLkDuAiaGwAAARQ"]
[Tue Jul 21 07:57:49.587152 2026] [security2:error] [pid 341679:tid 341859] [client 117.247.80.59:23438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrQWat-noHLkDuAiaHgAAATw"]
[Tue Jul 21 07:57:49.587266 2026] [security2:error] [pid 341679:tid 341859] [client 117.247.80.59:23438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrQWat-noHLkDuAiaHgAAATw"]
[Tue Jul 21 07:57:49.731465 2026] [security2:error] [pid 341679:tid 341930] [client 20.151.10.161:28822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/8.php"] [unique_id "al9QrQWat-noHLkDuAiaIwAAAYM"]
[Tue Jul 21 07:57:49.811598 2026] [security2:error] [pid 341679:tid 341862] [client 4.204.201.85:9652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/file5.php"] [unique_id "al9QrQWat-noHLkDuAiaJwAAAT8"]
[Tue Jul 21 07:57:49.856865 2026] [security2:error] [pid 341679:tid 341680] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QrQWat-noHLkDuAiaKwABOAA"]
[Tue Jul 21 07:57:49.857068 2026] [security2:error] [pid 341679:tid 341855] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QrQWat-noHLkDuAiaKwABOAA"]
[Tue Jul 21 07:57:49.900725 2026] [security2:error] [pid 341679:tid 341917] [client 103.178.2.190:54028] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "eclipsesofts.com"] [uri "/wp-comments-post.php"] [unique_id "al9QrQWat-noHLkDuAiaLgAAAXY"]
[Tue Jul 21 07:57:49.920935 2026] [security2:error] [pid 341679:tid 341899] [client 20.104.96.117:3552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/100.php"] [unique_id "al9QrQWat-noHLkDuAiaLwAAAWQ"]
[Tue Jul 21 07:57:49.931450 2026] [autoindex:error] [pid 341679:tid 341874] [client 82.102.18.182:41806] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:50.015673 2026] [security2:error] [pid 341679:tid 341889] [client 136.144.33.100:30605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QrQWat-noHLkDuAiaKgAAAVo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:50.023301 2026] [security2:error] [pid 341679:tid 341921] [client 193.36.225.151:51083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QrAWat-noHLkDuAiZ9wAAAXo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:57:50.023504 2026] [security2:error] [pid 341679:tid 341879] [client 20.206.105.145:28624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/xmrl.php"] [unique_id "al9QrgWat-noHLkDuAiaMAAAAVA"]
[Tue Jul 21 07:57:50.094719 2026] [security2:error] [pid 341679:tid 341917] [client 103.178.2.190:54028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "eclipsesofts.com"] [uri "/wp-comments-post.php"] [unique_id "al9QrQWat-noHLkDuAiaLgAAAXY"]
[Tue Jul 21 07:57:50.099211 2026] [security2:error] [pid 341679:tid 341925] [client 20.151.10.161:28717] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "api.factorial.studio"] [uri "/1.php"] [unique_id "al9QrgWat-noHLkDuAiaMwAAAX4"]
[Tue Jul 21 07:57:50.099330 2026] [security2:error] [pid 341679:tid 341925] [client 20.151.10.161:28717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/1.php"] [unique_id "al9QrgWat-noHLkDuAiaMwAAAX4"]
[Tue Jul 21 07:57:50.364910 2026] [security2:error] [pid 341679:tid 341935] [client 184.75.221.3:38580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9QrgWat-noHLkDuAiaQAAAAYg"]
[Tue Jul 21 07:57:50.365017 2026] [security2:error] [pid 341679:tid 341935] [client 184.75.221.3:38580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9QrgWat-noHLkDuAiaQAAAAYg"]
[Tue Jul 21 07:57:50.509989 2026] [security2:error] [pid 341679:tid 341787] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrgWat-noHLkDuAiaRAABWWs"]
[Tue Jul 21 07:57:50.510262 2026] [security2:error] [pid 341679:tid 341888] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrgWat-noHLkDuAiaRAABWWs"]
[Tue Jul 21 07:57:50.635910 2026] [security2:error] [pid 341679:tid 341907] [client 20.104.96.117:3461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/about.php"] [unique_id "al9QrgWat-noHLkDuAiaTAAAAWw"]
[Tue Jul 21 07:57:50.668240 2026] [security2:error] [pid 341679:tid 341918] [client 20.226.60.151:59989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/0xD.php"] [unique_id "al9QrgWat-noHLkDuAiaTQAAAXc"]
[Tue Jul 21 07:57:50.861287 2026] [security2:error] [pid 341679:tid 341836] [client 20.151.10.161:29087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/100.php"] [unique_id "al9QrgWat-noHLkDuAiaVwAAASU"]
[Tue Jul 21 07:57:50.898273 2026] [security2:error] [pid 341679:tid 341869] [client 182.8.255.181:21206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QrgWat-noHLkDuAiaWQAAAUY"]
[Tue Jul 21 07:57:50.898456 2026] [security2:error] [pid 341679:tid 341869] [client 182.8.255.181:21206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QrgWat-noHLkDuAiaWQAAAUY"]
[Tue Jul 21 07:57:50.899589 2026] [security2:error] [pid 341679:tid 341848] [client 4.204.201.85:9627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/222.php"] [unique_id "al9QrgWat-noHLkDuAiaWgAAATE"]
[Tue Jul 21 07:57:50.987640 2026] [security2:error] [pid 341679:tid 341863] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9QrgWat-noHLkDuAiaWwABQAY"]
[Tue Jul 21 07:57:51.063015 2026] [core:error] [pid 341679:tid 341689] [remote 52.167.144.184:62090] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:51.063037 2026] [core:error] [pid 341679:tid 341689] [remote 52.167.144.184:62090] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:51.194883 2026] [security2:error] [pid 341679:tid 341867] [client 65.21.113.253:50120] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QrwWat-noHLkDuAiaaQAAAUQ"]
[Tue Jul 21 07:57:51.407988 2026] [security2:error] [pid 341679:tid 341902] [client 92.119.178.3:38098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9QrwWat-noHLkDuAiapwAAAWc"]
[Tue Jul 21 07:57:51.408068 2026] [security2:error] [pid 341679:tid 341902] [client 92.119.178.3:38098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9QrwWat-noHLkDuAiapwAAAWc"]
[Tue Jul 21 07:57:51.707589 2026] [autoindex:error] [pid 341679:tid 341869] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-content/plugins/woocommerce/assets/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:51.717112 2026] [security2:error] [pid 341679:tid 341868] [client 74.249.245.134:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/php.php"] [unique_id "al9QrwWat-noHLkDuAia2AAAAUU"]
[Tue Jul 21 07:57:51.726464 2026] [security2:error] [pid 341679:tid 341923] [client 20.104.96.117:3496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/about.php"] [unique_id "al9QrwWat-noHLkDuAia2wAAAXw"]
[Tue Jul 21 07:57:51.791358 2026] [security2:error] [pid 341679:tid 341879] [client 4.204.201.85:9555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/test.php"] [unique_id "al9QrwWat-noHLkDuAia3gAAAVA"]
[Tue Jul 21 07:57:51.871091 2026] [security2:error] [pid 341679:tid 341865] [client 65.21.113.253:54450] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QrwWat-noHLkDuAiaqQAAAUI"]
[Tue Jul 21 07:57:51.890167 2026] [security2:error] [pid 341679:tid 341898] [client 87.116.180.198:27178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrwWat-noHLkDuAia4gAAAWM"]
[Tue Jul 21 07:57:51.892412 2026] [security2:error] [pid 341679:tid 341931] [client 103.178.2.190:54116] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "eclipsesofts.com"] [uri "/wp-comments-post.php"] [unique_id "al9QrwWat-noHLkDuAia4QAAAYQ"]
[Tue Jul 21 07:57:51.896002 2026] [security2:error] [pid 341679:tid 341898] [client 87.116.180.198:27178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QrwWat-noHLkDuAia4gAAAWM"]
[Tue Jul 21 07:57:51.918980 2026] [autoindex:error] [pid 341679:tid 341855] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-content/plugins/woocommerce/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:51.934863 2026] [security2:error] [pid 341679:tid 341934] [client 20.151.10.161:28718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/about.php"] [unique_id "al9QrwWat-noHLkDuAia5gAAAYc"]
[Tue Jul 21 07:57:52.127541 2026] [security2:error] [pid 341679:tid 341896] [client 223.236.153.128:14219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QsAWat-noHLkDuAia7gAAAWE"]
[Tue Jul 21 07:57:52.127709 2026] [security2:error] [pid 341679:tid 341896] [client 223.236.153.128:14219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QsAWat-noHLkDuAia7gAAAWE"]
[Tue Jul 21 07:57:52.187025 2026] [security2:error] [pid 341679:tid 341894] [client 106.215.181.8:21329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QsAWat-noHLkDuAia8AAAAV8"]
[Tue Jul 21 07:57:52.192152 2026] [security2:error] [pid 341679:tid 341894] [client 106.215.181.8:21329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QsAWat-noHLkDuAia8AAAAV8"]
[Tue Jul 21 07:57:52.347784 2026] [security2:error] [pid 341679:tid 341815] [client 20.104.96.117:3522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/admin.php"] [unique_id "al9QsAWat-noHLkDuAia-AAAARA"]
[Tue Jul 21 07:57:52.460745 2026] [security2:error] [pid 341679:tid 341914] [client 202.143.127.214:56817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QsAWat-noHLkDuAibAQAAAXM"]
[Tue Jul 21 07:57:52.460867 2026] [security2:error] [pid 341679:tid 341914] [client 202.143.127.214:56817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QsAWat-noHLkDuAibAQAAAXM"]
[Tue Jul 21 07:57:52.660435 2026] [security2:error] [pid 341679:tid 341896] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9QsAWat-noHLkDuAibfgAAAWE"]
[Tue Jul 21 07:57:52.759213 2026] [security2:error] [pid 341679:tid 341845] [client 20.206.105.145:55927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/memberfuns.php"] [unique_id "al9QsAWat-noHLkDuAibggAAAS4"]
[Tue Jul 21 07:57:52.885554 2026] [security2:error] [pid 341679:tid 341914] [client 20.151.10.161:29203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/admin.php"] [unique_id "al9QsAWat-noHLkDuAibhQAAAXM"]
[Tue Jul 21 07:57:52.893973 2026] [security2:error] [pid 341679:tid 341873] [client 4.204.201.85:9643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/aaa.php"] [unique_id "al9QsAWat-noHLkDuAibhgAAAUo"]
[Tue Jul 21 07:57:52.915128 2026] [security2:error] [pid 341679:tid 341904] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9QsAWat-noHLkDuAibhwAAAWk"]
[Tue Jul 21 07:57:53.013466 2026] [security2:error] [pid 341679:tid 341866] [client 122.162.144.145:23211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QsQWat-noHLkDuAibkAAAAUM"]
[Tue Jul 21 07:57:53.013626 2026] [security2:error] [pid 341679:tid 341866] [client 122.162.144.145:23211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QsQWat-noHLkDuAibkAAAAUM"]
[Tue Jul 21 07:57:53.061006 2026] [security2:error] [pid 341679:tid 341881] [client 20.104.96.117:3504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/admin.php"] [unique_id "al9QsQWat-noHLkDuAibkgAAAVI"]
[Tue Jul 21 07:57:53.209574 2026] [security2:error] [pid 341679:tid 341931] [client 103.178.2.190:54116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "eclipsesofts.com"] [uri "/wp-comments-post.php"] [unique_id "al9QrwWat-noHLkDuAia4QAAAYQ"]
[Tue Jul 21 07:57:53.230750 2026] [security2:error] [pid 341679:tid 341898] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9QsQWat-noHLkDuAibmAAAAWM"]
[Tue Jul 21 07:57:53.269361 2026] [security2:error] [pid 341679:tid 341849] [client 103.78.200.11:56619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QsQWat-noHLkDuAibmQAAATI"]
[Tue Jul 21 07:57:53.271118 2026] [security2:error] [pid 341679:tid 341849] [client 103.78.200.11:56619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QsQWat-noHLkDuAibmQAAATI"]
[Tue Jul 21 07:57:53.383182 2026] [security2:error] [pid 341679:tid 341831] [client 37.140.223.158:60831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QsQWat-noHLkDuAibnwAAASA"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:57:53.472905 2026] [security2:error] [pid 341679:tid 341876] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9QsQWat-noHLkDuAibogAAAU0"]
[Tue Jul 21 07:57:53.609718 2026] [security2:error] [pid 341679:tid 341885] [client 20.104.96.117:3575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/themes.php"] [unique_id "al9QsQWat-noHLkDuAibqAAAAVY"]
[Tue Jul 21 07:57:53.722340 2026] [security2:error] [pid 341679:tid 341909] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9QsQWat-noHLkDuAibrwAAAW4"]
[Tue Jul 21 07:57:53.860648 2026] [security2:error] [pid 341679:tid 341879] [client 20.151.10.161:29237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/edit.php"] [unique_id "al9QsQWat-noHLkDuAibuAAAAVA"]
[Tue Jul 21 07:57:53.903737 2026] [security2:error] [pid 341679:tid 341925] [client 4.204.201.85:9653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/11.php"] [unique_id "al9QsQWat-noHLkDuAibuQAAAX4"]
[Tue Jul 21 07:57:53.911437 2026] [security2:error] [pid 341679:tid 341874] [client 103.166.103.129:59595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QsQWat-noHLkDuAibugAAAUs"]
[Tue Jul 21 07:57:53.911526 2026] [security2:error] [pid 341679:tid 341874] [client 103.166.103.129:59595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QsQWat-noHLkDuAibugAAAUs"]
[Tue Jul 21 07:57:53.998730 2026] [security2:error] [pid 341679:tid 341840] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9QsQWat-noHLkDuAibwQAAASk"]
[Tue Jul 21 07:57:54.063204 2026] [security2:error] [pid 341679:tid 341935] [client 82.102.18.182:45348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocsdbodyboarding.com.br"] [uri "/wp-login.php"] [unique_id "al9QsgWat-noHLkDuAibwgAAAYg"]
[Tue Jul 21 07:57:54.129238 2026] [autoindex:error] [pid 341679:tid 341897] [client 20.104.96.117:3488] AH01276: Cannot serve directory /home2/thekin17/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:54.137312 2026] [security2:error] [pid 341679:tid 341864] [client 103.29.114.44:63856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QsgWat-noHLkDuAibxAAAAUE"]
[Tue Jul 21 07:57:54.137422 2026] [security2:error] [pid 341679:tid 341864] [client 103.29.114.44:63856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QsgWat-noHLkDuAibxAAAAUE"]
[Tue Jul 21 07:57:54.154048 2026] [security2:error] [pid 341679:tid 341895] [client 20.226.60.151:61526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9QsgWat-noHLkDuAibxQAAAWA"]
[Tue Jul 21 07:57:54.171193 2026] [security2:error] [pid 341679:tid 341831] [client 20.226.60.151:60022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/fnstall.php"] [unique_id "al9QsgWat-noHLkDuAibyAAAASA"]
[Tue Jul 21 07:57:54.246864 2026] [security2:error] [pid 341679:tid 341814] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9QsgWat-noHLkDuAibzAAAAQ8"]
[Tue Jul 21 07:57:54.484872 2026] [security2:error] [pid 341679:tid 341888] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9QsgWat-noHLkDuAib1wAAAVk"]
[Tue Jul 21 07:57:54.781570 2026] [security2:error] [pid 341679:tid 341901] [client 20.151.10.161:28813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-content/admin.php"] [unique_id "al9QsgWat-noHLkDuAib3wAAAWY"]
[Tue Jul 21 07:57:54.782275 2026] [security2:error] [pid 341679:tid 341838] [client 193.36.225.54:59459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QsgWat-noHLkDuAib4AAAASc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:54.816795 2026] [security2:error] [pid 341679:tid 341931] [client 4.204.201.85:9575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/mac.php"] [unique_id "al9QsgWat-noHLkDuAib4QAAAYQ"]
[Tue Jul 21 07:57:54.832530 2026] [security2:error] [pid 341679:tid 341903] [client 74.249.245.134:54372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/aa.php"] [unique_id "al9QsgWat-noHLkDuAib4gAAAWg"]
[Tue Jul 21 07:57:54.845495 2026] [security2:error] [pid 341679:tid 341840] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9QsgWat-noHLkDuAib4wAAASk"]
[Tue Jul 21 07:57:54.878563 2026] [core:error] [pid 341679:tid 341786] [remote 40.77.167.77:18316] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:54.878583 2026] [core:error] [pid 341679:tid 341786] [remote 40.77.167.77:18316] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:57:55.044304 2026] [security2:error] [pid 341679:tid 341696] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QswWat-noHLkDuAib6wABYxA"]
[Tue Jul 21 07:57:55.044459 2026] [security2:error] [pid 341679:tid 341898] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QswWat-noHLkDuAib6wABYxA"]
[Tue Jul 21 07:57:55.088089 2026] [security2:error] [pid 341679:tid 341914] [client 65.21.113.253:42864] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QsgWat-noHLkDuAib2QAAAXM"]
[Tue Jul 21 07:57:55.144855 2026] [security2:error] [pid 341679:tid 341817] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9QswWat-noHLkDuAib7QAAARI"]
[Tue Jul 21 07:57:55.296974 2026] [security2:error] [pid 341679:tid 341881] [client 102.206.115.33:63900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QswWat-noHLkDuAib9AAAAVI"]
[Tue Jul 21 07:57:55.297115 2026] [security2:error] [pid 341679:tid 341881] [client 102.206.115.33:63900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QswWat-noHLkDuAib9AAAAVI"]
[Tue Jul 21 07:57:55.333294 2026] [security2:error] [pid 341679:tid 341910] [client 122.179.91.63:8149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QswWat-noHLkDuAib9QAAAW8"]
[Tue Jul 21 07:57:55.333457 2026] [security2:error] [pid 341679:tid 341910] [client 122.179.91.63:8149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QswWat-noHLkDuAib9QAAAW8"]
[Tue Jul 21 07:57:55.471515 2026] [security2:error] [pid 341679:tid 341904] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9QswWat-noHLkDuAicAgAAAWk"]
[Tue Jul 21 07:57:55.645396 2026] [security2:error] [pid 341679:tid 341785] [remote 102.253.35.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.35.253.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QswWat-noHLkDuAicCAABiWk"]
[Tue Jul 21 07:57:55.645570 2026] [security2:error] [pid 341679:tid 341936] [client 102.253.35.13:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9QswWat-noHLkDuAicCAABiWk"]
[Tue Jul 21 07:57:55.695851 2026] [security2:error] [pid 341679:tid 341892] [client 82.102.18.182:45362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocsdbodyboarding.com.br"] [uri "/wp-login.php"] [unique_id "al9QswWat-noHLkDuAicDwAAAV0"]
[Tue Jul 21 07:57:55.768081 2026] [security2:error] [pid 341679:tid 341918] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.leonardoborgesandrad1782568373000.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9QswWat-noHLkDuAicHwAAAXc"]
[Tue Jul 21 07:57:56.014796 2026] [security2:error] [pid 341679:tid 341934] [client 20.104.96.117:3488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/.well-known/about.php"] [unique_id "al9QtAWat-noHLkDuAicOAAAAYc"]
[Tue Jul 21 07:57:56.040606 2026] [security2:error] [pid 341679:tid 341881] [client 20.226.60.151:50626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/albin.php"] [unique_id "al9QtAWat-noHLkDuAicOQAAAVI"]
[Tue Jul 21 07:57:56.045305 2026] [security2:error] [pid 341679:tid 341878] [client 20.226.60.151:59943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/acp.php"] [unique_id "al9QtAWat-noHLkDuAicOgAAAU8"]
[Tue Jul 21 07:57:56.071735 2026] [security2:error] [pid 341679:tid 341891] [client 20.151.10.161:29061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/f6.php"] [unique_id "al9QtAWat-noHLkDuAicPwAAAVw"]
[Tue Jul 21 07:57:56.184763 2026] [security2:error] [pid 341679:tid 341888] [client 103.86.117.203:53434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QtAWat-noHLkDuAicSgAAAVk"]
[Tue Jul 21 07:57:56.184869 2026] [security2:error] [pid 341679:tid 341888] [client 103.86.117.203:53434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QtAWat-noHLkDuAicSgAAAVk"]
[Tue Jul 21 07:57:56.417734 2026] [security2:error] [pid 341679:tid 341918] [client 4.204.201.85:9583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/chosen.php"] [unique_id "al9QtAWat-noHLkDuAicYQAAAXc"]
[Tue Jul 21 07:57:56.431109 2026] [security2:error] [pid 341679:tid 341931] [client 20.206.105.145:55860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/ms.php"] [unique_id "al9QtAWat-noHLkDuAicYgAAAYQ"]
[Tue Jul 21 07:57:56.432121 2026] [security2:error] [pid 341679:tid 341856] [client 184.75.221.3:38588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9QtAWat-noHLkDuAicYwAAATk"]
[Tue Jul 21 07:57:56.432259 2026] [security2:error] [pid 341679:tid 341856] [client 184.75.221.3:38588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9QtAWat-noHLkDuAicYwAAATk"]
[Tue Jul 21 07:57:56.592897 2026] [autoindex:error] [pid 341679:tid 341897] [client 82.102.18.182:41806] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:56.900961 2026] [security2:error] [pid 341679:tid 341822] [client 122.164.127.47:57056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QtAWat-noHLkDuAicgQAAARc"]
[Tue Jul 21 07:57:56.901169 2026] [security2:error] [pid 341679:tid 341822] [client 122.164.127.47:57056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QtAWat-noHLkDuAicgQAAARc"]
[Tue Jul 21 07:57:57.021241 2026] [security2:error] [pid 341679:tid 341745] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QtQWat-noHLkDuAicjAABHkE"]
[Tue Jul 21 07:57:57.021376 2026] [security2:error] [pid 341679:tid 341829] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QtQWat-noHLkDuAicjAABHkE"]
[Tue Jul 21 07:57:57.396064 2026] [security2:error] [pid 341679:tid 341934] [client 74.249.245.134:54358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/bolt.php"] [unique_id "al9QtQWat-noHLkDuAictgAAAYc"]
[Tue Jul 21 07:57:57.438362 2026] [security2:error] [pid 341679:tid 341910] [client 20.151.10.161:28810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/inputs.php"] [unique_id "al9QtQWat-noHLkDuAicuQAAAW8"]
[Tue Jul 21 07:57:57.599079 2026] [security2:error] [pid 341679:tid 341854] [client 65.21.113.253:42692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QtQWat-noHLkDuAicwgAAATc"]
[Tue Jul 21 07:57:57.673067 2026] [security2:error] [pid 341679:tid 341864] [client 4.204.201.85:9607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/cream1.php"] [unique_id "al9QtQWat-noHLkDuAicygAAAUE"]
[Tue Jul 21 07:57:57.699728 2026] [security2:error] [pid 341679:tid 341873] [client 117.210.135.0:54255] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QtQWat-noHLkDuAiczgAAAUo"]
[Tue Jul 21 07:57:57.699893 2026] [security2:error] [pid 341679:tid 341873] [client 117.210.135.0:54255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QtQWat-noHLkDuAiczgAAAUo"]
[Tue Jul 21 07:57:57.721784 2026] [security2:error] [pid 341679:tid 341929] [client 20.104.96.117:3481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9QtQWat-noHLkDuAiczwAAAYI"]
[Tue Jul 21 07:57:57.754721 2026] [access_compat:error] [pid 341679:tid 341860] [client 162.241.63.68:39948] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:57:57.834305 2026] [security2:error] [pid 341679:tid 341698] [remote 185.191.171.7:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "androapkmod.com"] [uri "/mini-dayz-2/"] [unique_id "al9QtQWat-noHLkDuAic1gABQxI"]
[Tue Jul 21 07:57:57.834437 2026] [security2:error] [pid 341679:tid 341866] [client 185.191.171.7:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "androapkmod.com"] [uri "/mini-dayz-2/"] [unique_id "al9QtQWat-noHLkDuAic1gABQxI"]
[Tue Jul 21 07:57:58.071411 2026] [security2:error] [pid 341679:tid 341908] [client 20.226.60.151:59906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/mosty.php"] [unique_id "al9QtgWat-noHLkDuAic5AAAAW0"]
[Tue Jul 21 07:57:58.206866 2026] [security2:error] [pid 341679:tid 341925] [client 193.36.225.57:20929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QtgWat-noHLkDuAic7AAAAX4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:57:58.207529 2026] [security2:error] [pid 341679:tid 341823] [client 65.21.113.253:42864] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QtQWat-noHLkDuAic1QAAARg"]
[Tue Jul 21 07:57:58.219207 2026] [security2:error] [pid 341679:tid 341847] [client 82.102.18.182:50156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocsdbodyboarding.com.br"] [uri "/wp-login.php"] [unique_id "al9QtgWat-noHLkDuAic7gAAATA"]
[Tue Jul 21 07:57:58.425751 2026] [autoindex:error] [pid 341679:tid 341932] [client 82.102.18.182:0] AH01276: Cannot serve directory /home2/dalto241/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:58.678139 2026] [security2:error] [pid 341679:tid 341931] [client 74.249.245.134:54371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/x.php"] [unique_id "al9QtgWat-noHLkDuAidFwAAAYQ"]
[Tue Jul 21 07:57:58.716415 2026] [security2:error] [pid 341679:tid 341827] [client 65.111.0.231:9281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.0.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QtgWat-noHLkDuAidHAAAARw"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:57:58.747642 2026] [security2:error] [pid 341679:tid 341908] [client 20.206.105.145:28616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/zz.php"] [unique_id "al9QtgWat-noHLkDuAidIwAAAW0"]
[Tue Jul 21 07:57:58.869598 2026] [security2:error] [pid 341679:tid 341853] [client 4.204.201.85:9542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/dr.php"] [unique_id "al9QtgWat-noHLkDuAidLgAAATY"]
[Tue Jul 21 07:57:58.938396 2026] [security2:error] [pid 341679:tid 341867] [client 41.68.90.219:64865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QtgWat-noHLkDuAidMwAAAUQ"]
[Tue Jul 21 07:57:58.939284 2026] [security2:error] [pid 341679:tid 341867] [client 41.68.90.219:64865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QtgWat-noHLkDuAidMwAAAUQ"]
[Tue Jul 21 07:57:59.034183 2026] [security2:error] [pid 341679:tid 341746] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QtwWat-noHLkDuAidOQABFUI"]
[Tue Jul 21 07:57:59.034323 2026] [security2:error] [pid 341679:tid 341820] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QtwWat-noHLkDuAidOQABFUI"]
[Tue Jul 21 07:57:59.260189 2026] [autoindex:error] [pid 341679:tid 341748] [remote 173.252.95.9:46868] AH01276: Cannot serve directory /home2/vaniel58/academiaupsaude.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:57:59.265376 2026] [security2:error] [pid 341679:tid 341892] [client 178.153.91.96:64502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QtwWat-noHLkDuAidRQAAAV0"]
[Tue Jul 21 07:57:59.265530 2026] [security2:error] [pid 341679:tid 341892] [client 178.153.91.96:64502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QtwWat-noHLkDuAidRQAAAV0"]
[Tue Jul 21 07:57:59.298407 2026] [security2:error] [pid 341679:tid 341929] [client 4.204.201.85:9557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/x.php"] [unique_id "al9QtwWat-noHLkDuAidRgAAAYI"]
[Tue Jul 21 07:57:59.559953 2026] [security2:error] [pid 341679:tid 341852] [client 20.104.96.117:3532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wefile.php"] [unique_id "al9QtwWat-noHLkDuAidWgAAATU"]
[Tue Jul 21 07:57:59.591387 2026] [security2:error] [pid 341679:tid 341825] [client 20.151.10.161:29056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/av.php"] [unique_id "al9QtwWat-noHLkDuAidXAAAARo"]
[Tue Jul 21 07:57:59.614763 2026] [security2:error] [pid 341679:tid 341933] [client 65.21.113.253:42692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QtwWat-noHLkDuAidXQAAAYY"]
[Tue Jul 21 07:57:59.626385 2026] [security2:error] [pid 341679:tid 341815] [client 109.60.28.94:61090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QtwWat-noHLkDuAidXwAAARA"]
[Tue Jul 21 07:57:59.627099 2026] [security2:error] [pid 341679:tid 341815] [client 109.60.28.94:61090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QtwWat-noHLkDuAidXwAAARA"]
[Tue Jul 21 07:57:59.824472 2026] [security2:error] [pid 341679:tid 341910] [client 20.226.60.151:60025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/6.php"] [unique_id "al9QtwWat-noHLkDuAidagAAAW8"]
[Tue Jul 21 07:57:59.868141 2026] [security2:error] [pid 341679:tid 341860] [client 38.100.221.102:18217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QtwWat-noHLkDuAidawAAAT0"]
[Tue Jul 21 07:57:59.868286 2026] [security2:error] [pid 341679:tid 341860] [client 38.100.221.102:18217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QtwWat-noHLkDuAidawAAAT0"]
[Tue Jul 21 07:57:59.943657 2026] [security2:error] [pid 341679:tid 341840] [client 74.249.245.134:5516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/jga.php"] [unique_id "al9QtwWat-noHLkDuAidcQAAASk"]
[Tue Jul 21 07:58:00.054732 2026] [security2:error] [pid 341679:tid 341770] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QuAWat-noHLkDuAiddQABH1o"]
[Tue Jul 21 07:58:00.054870 2026] [security2:error] [pid 341679:tid 341830] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QuAWat-noHLkDuAiddQABH1o"]
[Tue Jul 21 07:58:00.114615 2026] [security2:error] [pid 341679:tid 341700] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QuAWat-noHLkDuAiddgABSBQ"]
[Tue Jul 21 07:58:00.114781 2026] [security2:error] [pid 341679:tid 341871] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QuAWat-noHLkDuAiddgABSBQ"]
[Tue Jul 21 07:58:00.127832 2026] [security2:error] [pid 341679:tid 341834] [client 59.93.4.33:63986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QuAWat-noHLkDuAiddwAAASM"]
[Tue Jul 21 07:58:00.127942 2026] [security2:error] [pid 341679:tid 341834] [client 59.93.4.33:63986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QuAWat-noHLkDuAiddwAAASM"]
[Tue Jul 21 07:58:00.211014 2026] [security2:error] [pid 341679:tid 341914] [client 117.247.80.59:24148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QuAWat-noHLkDuAidfAAAAXM"]
[Tue Jul 21 07:58:00.211120 2026] [security2:error] [pid 341679:tid 341914] [client 117.247.80.59:24148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QuAWat-noHLkDuAidfAAAAXM"]
[Tue Jul 21 07:58:00.399455 2026] [security2:error] [pid 341679:tid 341856] [client 20.104.96.117:3473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9QuAWat-noHLkDuAidgQAAATk"]
[Tue Jul 21 07:58:00.415037 2026] [security2:error] [pid 341679:tid 341913] [client 4.204.201.85:9644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/155.php"] [unique_id "al9QuAWat-noHLkDuAidggAAAXI"]
[Tue Jul 21 07:58:00.732113 2026] [security2:error] [pid 341679:tid 341889] [client 65.21.113.253:39626] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QuAWat-noHLkDuAidfgAAAVo"]
[Tue Jul 21 07:58:00.830680 2026] [security2:error] [pid 341679:tid 341818] [client 193.36.225.96:37735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QuAWat-noHLkDuAidkAAAARM"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:58:00.851708 2026] [security2:error] [pid 341679:tid 341890] [client 65.21.113.253:39628] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QuAWat-noHLkDuAidgAAAAVs"]
[Tue Jul 21 07:58:00.855750 2026] [security2:error] [pid 341679:tid 341731] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QuAWat-noHLkDuAidlgABPzM"]
[Tue Jul 21 07:58:00.855961 2026] [security2:error] [pid 341679:tid 341862] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QuAWat-noHLkDuAidlgABPzM"]
[Tue Jul 21 07:58:00.962013 2026] [security2:error] [pid 341679:tid 341907] [client 74.7.244.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.bordignonconsultoria.com"] [uri "/index.php"] [unique_id "al9QtwWat-noHLkDuAidbwAAAWw"]
[Tue Jul 21 07:58:00.962827 2026] [security2:error] [pid 341679:tid 341878] [client 74.7.244.30:60646] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.bordignonconsultoria.com"] [uri "/robots.txt"] [unique_id "al9QtwWat-noHLkDuAidbAABT1c"]
[Tue Jul 21 07:58:00.990340 2026] [security2:error] [pid 341679:tid 341892] [client 74.249.245.134:5556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/k.php"] [unique_id "al9QuAWat-noHLkDuAidnwAAAV0"]
[Tue Jul 21 07:58:01.011823 2026] [security2:error] [pid 341679:tid 341708] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QuQWat-noHLkDuAidoAABHRw"]
[Tue Jul 21 07:58:01.011967 2026] [security2:error] [pid 341679:tid 341828] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QuQWat-noHLkDuAidoAABHRw"]
[Tue Jul 21 07:58:01.033745 2026] [security2:error] [pid 341679:tid 341902] [client 4.204.201.85:9625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/ops.php"] [unique_id "al9QuQWat-noHLkDuAidogAAAWc"]
[Tue Jul 21 07:58:01.246637 2026] [security2:error] [pid 341679:tid 341934] [client 182.8.255.181:21112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QuQWat-noHLkDuAidqAAAAYc"]
[Tue Jul 21 07:58:01.246776 2026] [security2:error] [pid 341679:tid 341934] [client 182.8.255.181:21112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QuQWat-noHLkDuAidqAAAAYc"]
[Tue Jul 21 07:58:01.333793 2026] [security2:error] [pid 341679:tid 341876] [client 20.206.105.145:55885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/for.php"] [unique_id "al9QuQWat-noHLkDuAidrAAAAU0"]
[Tue Jul 21 07:58:01.339431 2026] [security2:error] [pid 341679:tid 341917] [client 151.123.178.177:31753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.178.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QuAWat-noHLkDuAideAAAAXY"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:58:01.444532 2026] [security2:error] [pid 341679:tid 341910] [client 74.7.244.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bordignonconsultoria.com"] [uri "/index.php"] [unique_id "al9QuQWat-noHLkDuAidsQAAAW8"], referer: https://www.bordignonconsultoria.com/robots.txt
[Tue Jul 21 07:58:01.456424 2026] [security2:error] [pid 341679:tid 341815] [client 74.7.244.30:60658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bordignonconsultoria.com"] [uri "/robots.txt"] [unique_id "al9QuQWat-noHLkDuAidrQABEGU"], referer: https://www.bordignonconsultoria.com/robots.txt
[Tue Jul 21 07:58:01.476684 2026] [security2:error] [pid 341679:tid 341807] [remote 154.0.166.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9QuQWat-noHLkDuAidtQABYH8"]
[Tue Jul 21 07:58:01.480643 2026] [security2:error] [pid 341679:tid 341909] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9QuQWat-noHLkDuAidswABbmw"]
[Tue Jul 21 07:58:01.511750 2026] [security2:error] [pid 341679:tid 341932] [client 74.7.241.162:56334] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bordignonconsultoria.com"] [uri "/robots.txt"] [unique_id "al9QuQWat-noHLkDuAidtwABhSw"]
[Tue Jul 21 07:58:01.654323 2026] [autoindex:error] [pid 341679:tid 341924] [client 20.104.96.117:3502] AH01276: Cannot serve directory /home2/thekin17/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:58:01.990895 2026] [autoindex:error] [pid 341679:tid 341936] [client 20.104.96.117:3502] AH01276: Cannot serve directory /home2/thekin17/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:58:02.013208 2026] [security2:error] [pid 341679:tid 341931] [client 4.204.201.85:9536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/file31.php"] [unique_id "al9QugWat-noHLkDuAidzQAAAYQ"]
[Tue Jul 21 07:58:02.098499 2026] [security2:error] [pid 341679:tid 341841] [client 74.249.245.134:17440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/vx.php"] [unique_id "al9QugWat-noHLkDuAidzwAAASo"]
[Tue Jul 21 07:58:02.161110 2026] [security2:error] [pid 341679:tid 341908] [client 20.104.96.117:3502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9QugWat-noHLkDuAid1QAAAW0"]
[Tue Jul 21 07:58:02.185142 2026] [security2:error] [pid 341679:tid 341832] [client 20.226.60.151:50657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/cilus.php"] [unique_id "al9QugWat-noHLkDuAid1wAAASE"]
[Tue Jul 21 07:58:02.216218 2026] [security2:error] [pid 341679:tid 341809] [client 136.144.33.98:42533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QugWat-noHLkDuAid2AAAAQo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:58:02.271153 2026] [security2:error] [pid 341679:tid 341928] [client 20.226.60.151:59963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/32e17094cfindex.php"] [unique_id "al9QugWat-noHLkDuAid2gAAAYE"]
[Tue Jul 21 07:58:02.425938 2026] [security2:error] [pid 341679:tid 341838] [client 20.206.105.145:28621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/yup.php"] [unique_id "al9QugWat-noHLkDuAid4wAAASc"]
[Tue Jul 21 07:58:02.583997 2026] [security2:error] [pid 341679:tid 341914] [client 87.116.180.198:13899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QugWat-noHLkDuAid5QAAAXM"]
[Tue Jul 21 07:58:02.584134 2026] [security2:error] [pid 341679:tid 341914] [client 87.116.180.198:13899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QugWat-noHLkDuAid5QAAAXM"]
[Tue Jul 21 07:58:02.714153 2026] [security2:error] [pid 341679:tid 341905] [client 223.236.153.128:7062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QugWat-noHLkDuAid6gAAAWo"]
[Tue Jul 21 07:58:02.718892 2026] [security2:error] [pid 341679:tid 341905] [client 223.236.153.128:7062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QugWat-noHLkDuAid6gAAAWo"]
[Tue Jul 21 07:58:02.734649 2026] [security2:error] [pid 341679:tid 341859] [client 106.215.181.8:4142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QugWat-noHLkDuAid6wAAATw"]
[Tue Jul 21 07:58:02.739426 2026] [security2:error] [pid 341679:tid 341859] [client 106.215.181.8:4142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QugWat-noHLkDuAid6wAAATw"]
[Tue Jul 21 07:58:02.998001 2026] [security2:error] [pid 341679:tid 341911] [client 20.151.10.161:29059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/classwithtostring.php"] [unique_id "al9QugWat-noHLkDuAid9QAAAXA"]
[Tue Jul 21 07:58:03.115104 2026] [security2:error] [pid 341679:tid 341901] [client 4.204.201.85:9596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/file6.php"] [unique_id "al9QuwWat-noHLkDuAid_QAAAWY"]
[Tue Jul 21 07:58:03.265888 2026] [security2:error] [pid 341679:tid 341930] [client 20.104.96.117:3535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/8.php"] [unique_id "al9QuwWat-noHLkDuAieAgAAAYM"]
[Tue Jul 21 07:58:03.274497 2026] [security2:error] [pid 341679:tid 341815] [client 202.143.127.214:57267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QuwWat-noHLkDuAieAwAAARA"]
[Tue Jul 21 07:58:03.274633 2026] [security2:error] [pid 341679:tid 341815] [client 202.143.127.214:57267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QuwWat-noHLkDuAieAwAAARA"]
[Tue Jul 21 07:58:03.536529 2026] [security2:error] [pid 341679:tid 341914] [client 20.206.105.145:28644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/wpxml.php"] [unique_id "al9QuwWat-noHLkDuAieCQAAAXM"]
[Tue Jul 21 07:58:03.786270 2026] [security2:error] [pid 341679:tid 341840] [client 74.249.245.134:54341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/ws77.php"] [unique_id "al9QuwWat-noHLkDuAieFAAAASk"]
[Tue Jul 21 07:58:03.890642 2026] [security2:error] [pid 341679:tid 341825] [client 122.162.144.145:32910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QuwWat-noHLkDuAieHQAAARo"]
[Tue Jul 21 07:58:03.890781 2026] [security2:error] [pid 341679:tid 341825] [client 122.162.144.145:32910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QuwWat-noHLkDuAieHQAAARo"]
[Tue Jul 21 07:58:03.980843 2026] [security2:error] [pid 341679:tid 341833] [client 103.78.200.11:57086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QuwWat-noHLkDuAieIwAAASI"]
[Tue Jul 21 07:58:03.982546 2026] [security2:error] [pid 341679:tid 341833] [client 103.78.200.11:57086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QuwWat-noHLkDuAieIwAAASI"]
[Tue Jul 21 07:58:04.034341 2026] [security2:error] [pid 341679:tid 341911] [client 20.226.60.151:65423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/qqqa.php"] [unique_id "al9QvAWat-noHLkDuAieKAAAAXA"]
[Tue Jul 21 07:58:04.048793 2026] [security2:error] [pid 341679:tid 341935] [client 193.36.225.102:22029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QuwWat-noHLkDuAieGwAAAYg"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:58:04.147999 2026] [security2:error] [pid 341679:tid 341936] [client 65.21.113.253:42692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QvAWat-noHLkDuAieKwAAAYk"]
[Tue Jul 21 07:58:04.166091 2026] [security2:error] [pid 341679:tid 341931] [client 4.204.201.85:9546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/adminfuns.php"] [unique_id "al9QvAWat-noHLkDuAieLAAAAYQ"]
[Tue Jul 21 07:58:04.585136 2026] [security2:error] [pid 341679:tid 341917] [client 184.75.221.3:60720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9QvAWat-noHLkDuAieQAAAAXY"]
[Tue Jul 21 07:58:04.585264 2026] [security2:error] [pid 341679:tid 341917] [client 184.75.221.3:60720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9QvAWat-noHLkDuAieQAAAAXY"]
[Tue Jul 21 07:58:04.688449 2026] [security2:error] [pid 341679:tid 341918] [client 103.29.114.44:30038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QvAWat-noHLkDuAieQgAAAXc"]
[Tue Jul 21 07:58:04.688575 2026] [security2:error] [pid 341679:tid 341918] [client 103.29.114.44:30038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QvAWat-noHLkDuAieQgAAAXc"]
[Tue Jul 21 07:58:04.784189 2026] [security2:error] [pid 341679:tid 341897] [client 65.21.113.253:39628] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QvAWat-noHLkDuAieNQAAAWI"]
[Tue Jul 21 07:58:04.796140 2026] [security2:error] [pid 341679:tid 341863] [client 103.166.103.129:60501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QvAWat-noHLkDuAieRwAAAUA"]
[Tue Jul 21 07:58:04.799145 2026] [security2:error] [pid 341679:tid 341863] [client 103.166.103.129:60501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QvAWat-noHLkDuAieRwAAAUA"]
[Tue Jul 21 07:58:05.194665 2026] [security2:error] [pid 341679:tid 341915] [client 4.204.201.85:60996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/goods.php"] [unique_id "al9QvQWat-noHLkDuAieUgAAAXQ"]
[Tue Jul 21 07:58:05.212520 2026] [security2:error] [pid 341679:tid 341899] [client 74.249.245.134:5537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/2.php"] [unique_id "al9QvQWat-noHLkDuAieVAAAAWQ"]
[Tue Jul 21 07:58:05.261701 2026] [security2:error] [pid 341679:tid 341931] [client 20.206.105.145:55812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/fffm.php"] [unique_id "al9QvQWat-noHLkDuAieWAAAAYQ"]
[Tue Jul 21 07:58:05.593066 2026] [security2:error] [pid 341679:tid 341801] [remote 62.210.185.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.185.210.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9QvQWat-noHLkDuAieXgABNHk"]
[Tue Jul 21 07:58:05.757964 2026] [security2:error] [pid 341679:tid 341779] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QvQWat-noHLkDuAieYQABIGM"]
[Tue Jul 21 07:58:05.758114 2026] [security2:error] [pid 341679:tid 341831] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QvQWat-noHLkDuAieYQABIGM"]
[Tue Jul 21 07:58:05.803910 2026] [security2:error] [pid 341679:tid 341885] [client 102.206.115.33:64338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QvQWat-noHLkDuAieZQAAAVY"]
[Tue Jul 21 07:58:05.804036 2026] [security2:error] [pid 341679:tid 341885] [client 102.206.115.33:64338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QvQWat-noHLkDuAieZQAAAVY"]
[Tue Jul 21 07:58:05.886309 2026] [security2:error] [pid 341679:tid 341862] [client 136.144.33.106:29353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QvQWat-noHLkDuAieaAAAAT8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:58:05.958494 2026] [security2:error] [pid 341679:tid 341914] [client 20.104.96.117:45487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9QvQWat-noHLkDuAiebQAAAXM"]
[Tue Jul 21 07:58:06.202661 2026] [security2:error] [pid 341679:tid 341933] [client 4.204.201.85:9662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/100.php"] [unique_id "al9QvgWat-noHLkDuAiedAAAAYY"]
[Tue Jul 21 07:58:06.570087 2026] [security2:error] [pid 341679:tid 341927] [client 122.179.91.63:30683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QvgWat-noHLkDuAieiQAAAYA"]
[Tue Jul 21 07:58:06.570571 2026] [security2:error] [pid 341679:tid 341927] [client 122.179.91.63:30683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QvgWat-noHLkDuAieiQAAAYA"]
[Tue Jul 21 07:58:06.649372 2026] [security2:error] [pid 341679:tid 341810] [client 103.86.117.203:53982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QvgWat-noHLkDuAieiwAAAQs"]
[Tue Jul 21 07:58:06.649526 2026] [security2:error] [pid 341679:tid 341810] [client 103.86.117.203:53982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QvgWat-noHLkDuAieiwAAAQs"]
[Tue Jul 21 07:58:06.953587 2026] [security2:error] [pid 341679:tid 341849] [client 20.226.60.151:59985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/aunmc.php"] [unique_id "al9QvgWat-noHLkDuAiekAAAATI"]
[Tue Jul 21 07:58:07.147276 2026] [security2:error] [pid 341679:tid 341832] [client 4.204.201.85:61570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/about.php"] [unique_id "al9QvwWat-noHLkDuAiemQAAASE"]
[Tue Jul 21 07:58:07.429993 2026] [security2:error] [pid 341679:tid 341857] [client 122.164.127.47:57630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QvwWat-noHLkDuAieoAAAATo"]
[Tue Jul 21 07:58:07.430149 2026] [security2:error] [pid 341679:tid 341857] [client 122.164.127.47:57630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QvwWat-noHLkDuAieoAAAATo"]
[Tue Jul 21 07:58:07.477158 2026] [security2:error] [pid 341679:tid 341877] [client 74.7.230.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "clientes.agenciawats.com.br"] [uri "/index.php"] [unique_id "al9QvgWat-noHLkDuAiefAAAAU4"]
[Tue Jul 21 07:58:07.478246 2026] [security2:error] [pid 341679:tid 341863] [client 74.7.230.7:40192] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "clientes.agenciawats.com.br"] [uri "/robots.txt"] [unique_id "al9QvgWat-noHLkDuAieegABQEY"]
[Tue Jul 21 07:58:07.510545 2026] [security2:error] [pid 341679:tid 341905] [client 20.104.96.117:3484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/f6.php"] [unique_id "al9QvwWat-noHLkDuAieqAAAAWo"]
[Tue Jul 21 07:58:07.775986 2026] [security2:error] [pid 341679:tid 341908] [client 20.151.10.161:29204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-content/themes/index.php"] [unique_id "al9QvwWat-noHLkDuAiesAAAAW0"]
[Tue Jul 21 07:58:07.869950 2026] [security2:error] [pid 341679:tid 341769] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QvwWat-noHLkDuAietAABRVk"]
[Tue Jul 21 07:58:07.870117 2026] [security2:error] [pid 341679:tid 341868] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QvwWat-noHLkDuAietAABRVk"]
[Tue Jul 21 07:58:08.153452 2026] [security2:error] [pid 341679:tid 341854] [client 20.104.96.117:3566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/inputs.php"] [unique_id "al9QwAWat-noHLkDuAievAAAATc"]
[Tue Jul 21 07:58:08.416230 2026] [security2:error] [pid 341679:tid 341912] [client 65.21.113.253:42692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QwAWat-noHLkDuAifAAAAAXE"]
[Tue Jul 21 07:58:08.471148 2026] [security2:error] [pid 341679:tid 341892] [client 92.119.178.3:50776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9QwAWat-noHLkDuAifBAAAAV0"]
[Tue Jul 21 07:58:08.471253 2026] [security2:error] [pid 341679:tid 341892] [client 92.119.178.3:50776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9QwAWat-noHLkDuAifBAAAAV0"]
[Tue Jul 21 07:58:08.609110 2026] [security2:error] [pid 341679:tid 341898] [client 65.21.113.253:39632] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QwAWat-noHLkDuAieuwAAAWM"]
[Tue Jul 21 07:58:08.639995 2026] [security2:error] [pid 341679:tid 341899] [client 117.210.135.0:54966] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwAWat-noHLkDuAieyAAAAWQ"]
[Tue Jul 21 07:58:08.640146 2026] [security2:error] [pid 341679:tid 341899] [client 117.210.135.0:54966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwAWat-noHLkDuAieyAAAAWQ"]
[Tue Jul 21 07:58:08.799933 2026] [security2:error] [pid 341679:tid 341915] [client 20.104.96.117:45126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/inputs.php"] [unique_id "al9QwAWat-noHLkDuAifFgAAAXQ"]
[Tue Jul 21 07:58:08.943959 2026] [security2:error] [pid 341679:tid 341911] [client 4.204.201.85:9580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/about.php"] [unique_id "al9QwAWat-noHLkDuAifGwAAAXA"]
[Tue Jul 21 07:58:08.989073 2026] [security2:error] [pid 341679:tid 341922] [client 74.249.245.134:5542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/asd.php"] [unique_id "al9QwAWat-noHLkDuAifHAAAAXs"]
[Tue Jul 21 07:58:09.168382 2026] [security2:error] [pid 341679:tid 341846] [client 20.104.96.117:45137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/classwithtostring.php"] [unique_id "al9QwQWat-noHLkDuAifJQAAAS8"]
[Tue Jul 21 07:58:09.435073 2026] [security2:error] [pid 341679:tid 341850] [client 92.119.178.3:42014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9QwQWat-noHLkDuAifKAAAATM"]
[Tue Jul 21 07:58:09.435183 2026] [security2:error] [pid 341679:tid 341850] [client 92.119.178.3:42014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9QwQWat-noHLkDuAifKAAAATM"]
[Tue Jul 21 07:58:09.479963 2026] [security2:error] [pid 341679:tid 341852] [client 41.68.90.219:65319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwQWat-noHLkDuAifLAAAATU"]
[Tue Jul 21 07:58:09.481014 2026] [security2:error] [pid 341679:tid 341852] [client 41.68.90.219:65319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwQWat-noHLkDuAifLAAAATU"]
[Tue Jul 21 07:58:09.544036 2026] [security2:error] [pid 341679:tid 341879] [client 65.21.113.253:39640] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QwQWat-noHLkDuAifIwAAAVA"]
[Tue Jul 21 07:58:09.694903 2026] [security2:error] [pid 341679:tid 341881] [client 20.226.60.151:56716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/gptsh.php"] [unique_id "al9QwQWat-noHLkDuAifMgAAAVI"]
[Tue Jul 21 07:58:09.696447 2026] [security2:error] [pid 341679:tid 341787] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QwQWat-noHLkDuAifMwABb2s"]
[Tue Jul 21 07:58:09.696609 2026] [security2:error] [pid 341679:tid 341910] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QwQWat-noHLkDuAifMwABb2s"]
[Tue Jul 21 07:58:09.716790 2026] [security2:error] [pid 341679:tid 341918] [client 20.104.96.117:3478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9QwQWat-noHLkDuAifNAAAAXc"]
[Tue Jul 21 07:58:09.772678 2026] [security2:error] [pid 341679:tid 341931] [client 178.153.91.96:8803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QwQWat-noHLkDuAifNgAAAYQ"]
[Tue Jul 21 07:58:09.772822 2026] [security2:error] [pid 341679:tid 341931] [client 178.153.91.96:8803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QwQWat-noHLkDuAifNgAAAYQ"]
[Tue Jul 21 07:58:09.989551 2026] [security2:error] [pid 341679:tid 341905] [client 20.206.105.145:28548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/gecko.php"] [unique_id "al9QwQWat-noHLkDuAifPAAAAWo"]
[Tue Jul 21 07:58:10.007156 2026] [lsapi:error] [pid 341679:tid 341690] [remote 201.49.111.241:0] [host cristaofitsuplementos.com] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown, referer: https://cristaofitsuplementos.com/?utm_medium=paid&utm_source=an&utm_id=120253850803500054&utm_content=120253850803560054&utm_term=120253850803490054&utm_campaign=120253850803500054&fbclid=IwY2xjawTMMA9leHRuA2FlbQEwAGFkaWQBqzo-sfOFNnVzcm0AAAAAAAAADnNydGMGYXBwX2lkDzI0NTc5MDgxODk1NTg2OAABHsDXToMSjkoJjTxThzznp3pDzltKLyk3534Szo-5Iea9lUwtg9EiLxsPO3WW_aem_XQRzv840wDguXKGzDTsIPw
[Tue Jul 21 07:58:10.007175 2026] [lsapi:error] [pid 341679:tid 341690] [remote 201.49.111.241:0] [host cristaofitsuplementos.com] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache, referer: https://cristaofitsuplementos.com/?utm_medium=paid&utm_source=an&utm_id=120253850803500054&utm_content=120253850803560054&utm_term=120253850803490054&utm_campaign=120253850803500054&fbclid=IwY2xjawTMMA9leHRuA2FlbQEwAGFkaWQBqzo-sfOFNnVzcm0AAAAAAAAADnNydGMGYXBwX2lkDzI0NTc5MDgxODk1NTg2OAABHsDXToMSjkoJjTxThzznp3pDzltKLyk3534Szo-5Iea9lUwtg9EiLxsPO3WW_aem_XQRzv840wDguXKGzDTsIPw
[Tue Jul 21 07:58:10.007187 2026] [lsapi:error] [pid 341679:tid 341690] [remote 201.49.111.241:0] [host cristaofitsuplementos.com] Client error on sending request(POST /wp-admin/admin-ajax.php HTTP/2.0); uri(/wp-admin/admin-ajax.php) content-length(130): user_get_body(tmpstackbuf, 16384): read from client failed, referer: https://cristaofitsuplementos.com/?utm_medium=paid&utm_source=an&utm_id=120253850803500054&utm_content=120253850803560054&utm_term=120253850803490054&utm_campaign=120253850803500054&fbclid=IwY2xjawTMMA9leHRuA2FlbQEwAGFkaWQBqzo-sfOFNnVzcm0AAAAAAAAADnNydGMGYXBwX2lkDzI0NTc5MDgxODk1NTg2OAABHsDXToMSjkoJjTxThzznp3pDzltKLyk3534Szo-5Iea9lUwtg9EiLxsPO3WW_aem_XQRzv840wDguXKGzDTsIPw
[Tue Jul 21 07:58:10.029136 2026] [security2:error] [pid 341679:tid 341809] [client 20.104.96.117:3479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-blog.php"] [unique_id "al9QwgWat-noHLkDuAifPgAAAQo"]
[Tue Jul 21 07:58:10.083391 2026] [security2:error] [pid 341679:tid 341898] [client 20.226.60.151:64989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/uoocf.php"] [unique_id "al9QwgWat-noHLkDuAifPwAAAWM"]
[Tue Jul 21 07:58:10.179522 2026] [security2:error] [pid 341679:tid 341851] [client 20.226.60.151:59996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/iywwi.php"] [unique_id "al9QwgWat-noHLkDuAifRAAAATQ"]
[Tue Jul 21 07:58:10.232376 2026] [security2:error] [pid 341679:tid 341900] [client 4.204.201.85:9632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/admin.php"] [unique_id "al9QwgWat-noHLkDuAifRgAAAWU"]
[Tue Jul 21 07:58:10.233874 2026] [security2:error] [pid 341679:tid 341930] [client 20.226.60.151:59917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/gqgsa.php"] [unique_id "al9QwgWat-noHLkDuAifRwAAAYM"]
[Tue Jul 21 07:58:10.260110 2026] [security2:error] [pid 341679:tid 341911] [client 20.220.225.223:1313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9QwgWat-noHLkDuAifSAAAAXA"]
[Tue Jul 21 07:58:10.335602 2026] [security2:error] [pid 341679:tid 341908] [client 20.226.60.151:59992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/elbzl.php"] [unique_id "al9QwgWat-noHLkDuAifSQAAAW0"]
[Tue Jul 21 07:58:10.426791 2026] [security2:error] [pid 341679:tid 341853] [client 37.140.223.68:32859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QwgWat-noHLkDuAifTQAAATY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:58:10.458048 2026] [security2:error] [pid 341679:tid 341818] [client 38.100.221.102:18343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwgWat-noHLkDuAifTgAAARM"]
[Tue Jul 21 07:58:10.458187 2026] [security2:error] [pid 341679:tid 341818] [client 38.100.221.102:18343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwgWat-noHLkDuAifTgAAARM"]
[Tue Jul 21 07:58:10.461834 2026] [security2:error] [pid 341679:tid 341833] [client 109.60.28.94:44657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwgWat-noHLkDuAifUAAAASI"]
[Tue Jul 21 07:58:10.461916 2026] [security2:error] [pid 341679:tid 341833] [client 109.60.28.94:44657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwgWat-noHLkDuAifUAAAASI"]
[Tue Jul 21 07:58:10.522931 2026] [autoindex:error] [pid 341679:tid 341828] [client 20.104.96.117:3469] AH01276: Cannot serve directory /home2/thekin17/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:58:10.615764 2026] [security2:error] [pid 341679:tid 341699] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9QwgWat-noHLkDuAifVQABWxM"]
[Tue Jul 21 07:58:10.620493 2026] [security2:error] [pid 341679:tid 341714] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QwgWat-noHLkDuAifVwABbCI"]
[Tue Jul 21 07:58:10.620652 2026] [security2:error] [pid 341679:tid 341907] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QwgWat-noHLkDuAifVwABbCI"]
[Tue Jul 21 07:58:10.648054 2026] [security2:error] [pid 341679:tid 341701] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9QwgWat-noHLkDuAifWQABVhU"]
[Tue Jul 21 07:58:10.676331 2026] [security2:error] [pid 341679:tid 341731] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wander.php"] [unique_id "al9QwgWat-noHLkDuAifWwABUDM"]
[Tue Jul 21 07:58:10.719282 2026] [security2:error] [pid 341679:tid 341711] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/jga.php"] [unique_id "al9QwgWat-noHLkDuAifXAABgh8"]
[Tue Jul 21 07:58:10.735367 2026] [security2:error] [pid 341679:tid 341750] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/x.php"] [unique_id "al9QwgWat-noHLkDuAifXQABdkY"]
[Tue Jul 21 07:58:10.761396 2026] [security2:error] [pid 341679:tid 341767] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9QwgWat-noHLkDuAifXwABfFc"]
[Tue Jul 21 07:58:10.787454 2026] [security2:error] [pid 341679:tid 341740] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/ee.php"] [unique_id "al9QwgWat-noHLkDuAifYQABeTw"]
[Tue Jul 21 07:58:10.790131 2026] [security2:error] [pid 341679:tid 341899] [client 59.93.4.33:64512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwgWat-noHLkDuAifYgAAAWQ"]
[Tue Jul 21 07:58:10.790219 2026] [security2:error] [pid 341679:tid 341899] [client 59.93.4.33:64512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwgWat-noHLkDuAifYgAAAWQ"]
[Tue Jul 21 07:58:10.805068 2026] [security2:error] [pid 341679:tid 341702] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/blue.php"] [unique_id "al9QwgWat-noHLkDuAifYwABFxY"]
[Tue Jul 21 07:58:10.820892 2026] [security2:error] [pid 341679:tid 341823] [client 65.21.113.253:42692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QwgWat-noHLkDuAifZAAAARg"]
[Tue Jul 21 07:58:10.823114 2026] [security2:error] [pid 341679:tid 341680] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wp-signup.php"] [unique_id "al9QwgWat-noHLkDuAifZQABfQA"]
[Tue Jul 21 07:58:10.851073 2026] [security2:error] [pid 341679:tid 341761] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/csa.php"] [unique_id "al9QwgWat-noHLkDuAifZgABDlE"]
[Tue Jul 21 07:58:10.855098 2026] [security2:error] [pid 341679:tid 341847] [client 117.247.80.59:24649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwgWat-noHLkDuAifZwAAATA"]
[Tue Jul 21 07:58:10.855225 2026] [security2:error] [pid 341679:tid 341847] [client 117.247.80.59:24649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwgWat-noHLkDuAifZwAAATA"]
[Tue Jul 21 07:58:10.890886 2026] [security2:error] [pid 341679:tid 341709] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/min.php"] [unique_id "al9QwgWat-noHLkDuAifaAABXR0"]
[Tue Jul 21 07:58:10.936713 2026] [security2:error] [pid 341679:tid 341769] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/echkm.php"] [unique_id "al9QwgWat-noHLkDuAifaQABKVk"]
[Tue Jul 21 07:58:10.966618 2026] [security2:error] [pid 341679:tid 341692] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/mac.php"] [unique_id "al9QwgWat-noHLkDuAifbAABOww"]
[Tue Jul 21 07:58:10.998618 2026] [security2:error] [pid 341679:tid 341786] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/samll.php"] [unique_id "al9QwgWat-noHLkDuAifbwABDWo"]
[Tue Jul 21 07:58:11.009891 2026] [security2:error] [pid 341679:tid 341809] [client 20.104.96.117:3469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9QwwWat-noHLkDuAifcQAAAQo"]
[Tue Jul 21 07:58:11.034579 2026] [security2:error] [pid 341679:tid 341788] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/abcd.php"] [unique_id "al9QwwWat-noHLkDuAifcwABgGw"]
[Tue Jul 21 07:58:11.072905 2026] [security2:error] [pid 341679:tid 341757] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/xyn.php"] [unique_id "al9QwwWat-noHLkDuAifdQABWk0"]
[Tue Jul 21 07:58:11.100441 2026] [security2:error] [pid 341679:tid 341778] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/byp8.php"] [unique_id "al9QwwWat-noHLkDuAifeAABf2I"]
[Tue Jul 21 07:58:11.136312 2026] [security2:error] [pid 341679:tid 341799] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/user.php"] [unique_id "al9QwwWat-noHLkDuAiffAABD3c"]
[Tue Jul 21 07:58:11.160227 2026] [security2:error] [pid 341679:tid 341737] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwwWat-noHLkDuAiffgABFTk"]
[Tue Jul 21 07:58:11.160397 2026] [security2:error] [pid 341679:tid 341820] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwwWat-noHLkDuAiffgABFTk"]
[Tue Jul 21 07:58:11.166162 2026] [security2:error] [pid 341679:tid 341718] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/ops.php"] [unique_id "al9QwwWat-noHLkDuAiffwABTSY"]
[Tue Jul 21 07:58:11.203519 2026] [security2:error] [pid 341679:tid 341684] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/term.php"] [unique_id "al9QwwWat-noHLkDuAifgQABRAQ"]
[Tue Jul 21 07:58:11.237789 2026] [security2:error] [pid 341679:tid 341802] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/ah25.php"] [unique_id "al9QwwWat-noHLkDuAifggABH3o"]
[Tue Jul 21 07:58:11.281653 2026] [security2:error] [pid 341679:tid 341759] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/8.php"] [unique_id "al9QwwWat-noHLkDuAifhAABJE8"]
[Tue Jul 21 07:58:11.314053 2026] [security2:error] [pid 341679:tid 341753] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/red.php"] [unique_id "al9QwwWat-noHLkDuAifhgABNkk"]
[Tue Jul 21 07:58:11.331257 2026] [security2:error] [pid 341679:tid 341780] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/fffm.php"] [unique_id "al9QwwWat-noHLkDuAifhwABE2Q"]
[Tue Jul 21 07:58:11.349963 2026] [security2:error] [pid 341679:tid 341758] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/ftde.php"] [unique_id "al9QwwWat-noHLkDuAifiAABIk4"]
[Tue Jul 21 07:58:11.386510 2026] [security2:error] [pid 341679:tid 341803] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/yup.php"] [unique_id "al9QwwWat-noHLkDuAifjAABS3s"]
[Tue Jul 21 07:58:11.403555 2026] [security2:error] [pid 341679:tid 341719] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/jj.php"] [unique_id "al9QwwWat-noHLkDuAifjQABMyc"]
[Tue Jul 21 07:58:11.423181 2026] [security2:error] [pid 341679:tid 341919] [client 4.204.201.85:61569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/admin.php"] [unique_id "al9QwwWat-noHLkDuAifjwAAAXg"]
[Tue Jul 21 07:58:11.424728 2026] [security2:error] [pid 341679:tid 341827] [client 20.220.225.223:1284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9QwwWat-noHLkDuAifkAAAARw"]
[Tue Jul 21 07:58:11.447300 2026] [security2:error] [pid 341679:tid 341721] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/dragonshell.php"] [unique_id "al9QwwWat-noHLkDuAifkgABbCk"]
[Tue Jul 21 07:58:11.449307 2026] [security2:error] [pid 341679:tid 341894] [client 65.21.113.253:39632] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QwwWat-noHLkDuAifdAAAAV8"]
[Tue Jul 21 07:58:11.481966 2026] [security2:error] [pid 341679:tid 341698] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wp-mt.php"] [unique_id "al9QwwWat-noHLkDuAifkwABSBI"]
[Tue Jul 21 07:58:11.541321 2026] [security2:error] [pid 341679:tid 341743] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/ww.php"] [unique_id "al9QwwWat-noHLkDuAiflQABNT8"]
[Tue Jul 21 07:58:11.541638 2026] [security2:error] [pid 341679:tid 341694] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwwWat-noHLkDuAiflgABaA4"]
[Tue Jul 21 07:58:11.541764 2026] [security2:error] [pid 341679:tid 341903] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QwwWat-noHLkDuAiflgABaA4"]
[Tue Jul 21 07:58:11.568249 2026] [security2:error] [pid 341679:tid 341783] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/cron.php"] [unique_id "al9QwwWat-noHLkDuAiflwABQWc"]
[Tue Jul 21 07:58:11.584931 2026] [security2:error] [pid 341679:tid 341734] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/xxx.php"] [unique_id "al9QwwWat-noHLkDuAifmAABODY"]
[Tue Jul 21 07:58:11.603471 2026] [security2:error] [pid 341679:tid 341804] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/hunter.php"] [unique_id "al9QwwWat-noHLkDuAifmwABJnw"]
[Tue Jul 21 07:58:11.613330 2026] [security2:error] [pid 341679:tid 341900] [client 37.140.223.122:52489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QwwWat-noHLkDuAifkQAAAWU"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:58:11.688336 2026] [security2:error] [pid 341679:tid 341933] [client 182.8.255.181:17156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QwwWat-noHLkDuAifoQAAAYY"]
[Tue Jul 21 07:58:11.688509 2026] [security2:error] [pid 341679:tid 341933] [client 182.8.255.181:17156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QwwWat-noHLkDuAifoQAAAYY"]
[Tue Jul 21 07:58:11.708498 2026] [security2:error] [pid 341679:tid 341924] [client 92.119.178.3:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9QwwWat-noHLkDuAifogAAAX0"]
[Tue Jul 21 07:58:11.708594 2026] [security2:error] [pid 341679:tid 341924] [client 92.119.178.3:56724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9QwwWat-noHLkDuAifogAAAX0"]
[Tue Jul 21 07:58:11.793865 2026] [security2:error] [pid 341679:tid 341916] [client 20.104.96.117:3569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/ms-edit.php"] [unique_id "al9QwwWat-noHLkDuAifqQAAAXU"]
[Tue Jul 21 07:58:11.806445 2026] [security2:error] [pid 341679:tid 341735] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QwwWat-noHLkDuAifqgABRjc"]
[Tue Jul 21 07:58:11.806611 2026] [security2:error] [pid 341679:tid 341869] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9QwwWat-noHLkDuAifqgABRjc"]
[Tue Jul 21 07:58:11.847275 2026] [security2:error] [pid 341679:tid 341858] [client 92.119.178.3:56726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9QwwWat-noHLkDuAifrQAAATs"]
[Tue Jul 21 07:58:11.847372 2026] [security2:error] [pid 341679:tid 341858] [client 92.119.178.3:56726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9QwwWat-noHLkDuAifrQAAATs"]
[Tue Jul 21 07:58:11.870926 2026] [security2:error] [pid 341679:tid 341725] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/we.php"] [unique_id "al9QwwWat-noHLkDuAifrgABTi0"]
[Tue Jul 21 07:58:11.898039 2026] [security2:error] [pid 341679:tid 341885] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9QwwWat-noHLkDuAifqwABVkc"]
[Tue Jul 21 07:58:12.044508 2026] [security2:error] [pid 341679:tid 341796] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/phpinfo.php1"] [unique_id "al9QxAWat-noHLkDuAifrwABf3Q"]
[Tue Jul 21 07:58:12.065096 2026] [security2:error] [pid 341679:tid 341815] [client 74.249.245.134:54366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/default.php"] [unique_id "al9QxAWat-noHLkDuAifsQAAARA"]
[Tue Jul 21 07:58:12.253292 2026] [security2:error] [pid 341679:tid 341830] [client 20.104.96.117:3543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9QxAWat-noHLkDuAifuQAAAR8"]
[Tue Jul 21 07:58:12.294952 2026] [security2:error] [pid 341679:tid 341838] [client 4.204.201.85:9556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/themes.php"] [unique_id "al9QxAWat-noHLkDuAifvQAAASc"]
[Tue Jul 21 07:58:12.404142 2026] [security2:error] [pid 341679:tid 341697] [remote 65.111.22.163:23331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9QxAWat-noHLkDuAifwAABiRE"]
[Tue Jul 21 07:58:12.769482 2026] [autoindex:error] [pid 341679:tid 341823] [client 20.104.96.117:3514] AH01276: Cannot serve directory /home2/thekin17/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:58:12.834910 2026] [security2:error] [pid 341679:tid 341747] [remote 185.191.171.8:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "androapkmod.com"] [uri "/rpg-roguelike-na-masmorra-ordem-do-destino/"] [unique_id "al9QxAWat-noHLkDuAif3QABO0M"]
[Tue Jul 21 07:58:12.835050 2026] [security2:error] [pid 341679:tid 341858] [client 185.191.171.8:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "androapkmod.com"] [uri "/rpg-roguelike-na-masmorra-ordem-do-destino/"] [unique_id "al9QxAWat-noHLkDuAif3QABO0M"]
[Tue Jul 21 07:58:12.956487 2026] [security2:error] [pid 341679:tid 341801] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/.env"] [unique_id "al9QxAWat-noHLkDuAif5AABPXk"]
[Tue Jul 21 07:58:13.045496 2026] [security2:error] [pid 341679:tid 341830] [client 20.104.96.117:3514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9QxQWat-noHLkDuAif5wAAAR8"]
[Tue Jul 21 07:58:13.286075 2026] [security2:error] [pid 341679:tid 341877] [client 87.116.180.198:27278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QxQWat-noHLkDuAif8wAAAU4"]
[Tue Jul 21 07:58:13.286234 2026] [security2:error] [pid 341679:tid 341877] [client 87.116.180.198:27278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QxQWat-noHLkDuAif8wAAAU4"]
[Tue Jul 21 07:58:13.370395 2026] [security2:error] [pid 341679:tid 341865] [client 223.236.153.128:5894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QxQWat-noHLkDuAif9QAAAUI"]
[Tue Jul 21 07:58:13.370698 2026] [security2:error] [pid 341679:tid 341929] [client 106.215.181.8:16515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QxQWat-noHLkDuAif9gAAAYI"]
[Tue Jul 21 07:58:13.370810 2026] [security2:error] [pid 341679:tid 341929] [client 106.215.181.8:16515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QxQWat-noHLkDuAif9gAAAYI"]
[Tue Jul 21 07:58:13.385223 2026] [security2:error] [pid 341679:tid 341865] [client 223.236.153.128:5894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9QxQWat-noHLkDuAif9QAAAUI"]
[Tue Jul 21 07:58:13.448369 2026] [security2:error] [pid 341679:tid 341919] [client 20.220.225.223:1312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/dp.php"] [unique_id "al9QxQWat-noHLkDuAif-AAAAXg"]
[Tue Jul 21 07:58:13.545510 2026] [security2:error] [pid 341679:tid 341923] [client 20.206.105.145:55890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/a1.php"] [unique_id "al9QxQWat-noHLkDuAigAAAAAXw"]
[Tue Jul 21 07:58:13.560040 2026] [autoindex:error] [pid 341679:tid 341900] [client 20.104.96.117:3511] AH01276: Cannot serve directory /home2/thekin17/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:58:13.696045 2026] [security2:error] [pid 341679:tid 341926] [client 204.8.98.45:52054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9QxQWat-noHLkDuAigCQAAAX8"]
[Tue Jul 21 07:58:13.696140 2026] [security2:error] [pid 341679:tid 341926] [client 204.8.98.45:52054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9QxQWat-noHLkDuAigCQAAAX8"]
[Tue Jul 21 07:58:13.708581 2026] [security2:error] [pid 341679:tid 341762] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/wp-json"] [unique_id "al9QxQWat-noHLkDuAigCgABYVI"]
[Tue Jul 21 07:58:13.708757 2026] [security2:error] [pid 341679:tid 341896] [client 34.101.153.152:59920] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.gradiente.com"] [uri "/wp-json"] [unique_id "al9QxQWat-noHLkDuAigCgABYVI"]
[Tue Jul 21 07:58:13.711244 2026] [security2:error] [pid 341679:tid 341688] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.gradiente.com"] [uri "/z9x8c7v6b5-debug-trigger-dashboard.gradiente.com"] [unique_id "al9QxQWat-noHLkDuAigEgABKQg"]
[Tue Jul 21 07:58:13.896208 2026] [security2:error] [pid 341679:tid 341895] [client 65.21.113.253:42692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QxQWat-noHLkDuAigHQAAAWA"]
[Tue Jul 21 07:58:13.910060 2026] [autoindex:error] [pid 341679:tid 341820] [client 20.104.96.117:3511] AH01276: Cannot serve directory /home2/thekin17/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:58:13.975087 2026] [security2:error] [pid 341679:tid 341879] [client 65.21.113.253:44572] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QxQWat-noHLkDuAif_QAAAVA"]
[Tue Jul 21 07:58:14.055451 2026] [security2:error] [pid 341679:tid 341914] [client 4.204.201.85:9585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/.well-known/about.php"] [unique_id "al9QxgWat-noHLkDuAigIgAAAXM"]
[Tue Jul 21 07:58:14.069964 2026] [security2:error] [pid 341679:tid 341865] [client 20.104.96.117:3511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/abcd.php"] [unique_id "al9QxgWat-noHLkDuAigIwAAAUI"]
[Tue Jul 21 07:58:14.087878 2026] [security2:error] [pid 341679:tid 341894] [client 45.8.19.182:50287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9QxgWat-noHLkDuAigJAAAAV8"]
[Tue Jul 21 07:58:14.106949 2026] [security2:error] [pid 341679:tid 341750] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dashboard.gradiente.com"] [uri "/graphql"] [unique_id "al9QxgWat-noHLkDuAigJQABKUY"]
[Tue Jul 21 07:58:14.128836 2026] [security2:error] [pid 341679:tid 341907] [client 45.8.19.185:40587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9QxgWat-noHLkDuAigKQAAAWw"]
[Tue Jul 21 07:58:14.289826 2026] [security2:error] [pid 341679:tid 341927] [client 202.143.127.214:57738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QxgWat-noHLkDuAigNwAAAYA"]
[Tue Jul 21 07:58:14.289941 2026] [security2:error] [pid 341679:tid 341927] [client 202.143.127.214:57738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QxgWat-noHLkDuAigNwAAAYA"]
[Tue Jul 21 07:58:14.347236 2026] [security2:error] [pid 341679:tid 341897] [client 136.144.33.109:52529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QxgWat-noHLkDuAigOQAAAWI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:58:14.486204 2026] [security2:error] [pid 341679:tid 341786] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dashboard.gradiente.com"] [uri "/api/graphql"] [unique_id "al9QxgWat-noHLkDuAigPQABKWo"]
[Tue Jul 21 07:58:14.498313 2026] [security2:error] [pid 341679:tid 341757] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.gradiente.com"] [uri "/.gitconfig"] [unique_id "al9QxgWat-noHLkDuAigPwABKU0"]
[Tue Jul 21 07:58:14.562008 2026] [security2:error] [pid 341679:tid 341899] [client 103.78.200.11:57553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QxgWat-noHLkDuAigQQAAAWQ"]
[Tue Jul 21 07:58:14.562168 2026] [security2:error] [pid 341679:tid 341899] [client 103.78.200.11:57553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QxgWat-noHLkDuAigQQAAAWQ"]
[Tue Jul 21 07:58:14.584182 2026] [security2:error] [pid 341679:tid 341763] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/.gitlab-ci.yml"] [unique_id "al9QxgWat-noHLkDuAigRAABKVM"]
[Tue Jul 21 07:58:14.584341 2026] [security2:error] [pid 341679:tid 341840] [client 34.101.153.152:59920] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.gradiente.com"] [uri "/.gitlab-ci.yml"] [unique_id "al9QxgWat-noHLkDuAigRAABKVM"]
[Tue Jul 21 07:58:14.618618 2026] [security2:error] [pid 341679:tid 341905] [client 20.151.10.161:28863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-blog.php"] [unique_id "al9QxgWat-noHLkDuAigRgAAAWo"]
[Tue Jul 21 07:58:14.625974 2026] [security2:error] [pid 341679:tid 341917] [client 20.104.96.117:45152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/file15.php"] [unique_id "al9QxgWat-noHLkDuAigRwAAAXY"]
[Tue Jul 21 07:58:14.632562 2026] [security2:error] [pid 341679:tid 341892] [client 122.162.144.145:11989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QxgWat-noHLkDuAigSAAAAV0"]
[Tue Jul 21 07:58:14.632689 2026] [security2:error] [pid 341679:tid 341892] [client 122.162.144.145:11989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9QxgWat-noHLkDuAigSAAAAV0"]
[Tue Jul 21 07:58:14.803362 2026] [security2:error] [pid 341679:tid 341825] [client 20.220.225.223:1324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/old.php"] [unique_id "al9QxgWat-noHLkDuAigWAAAARo"]
[Tue Jul 21 07:58:14.940287 2026] [security2:error] [pid 341679:tid 341721] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/.env"] [unique_id "al9QxgWat-noHLkDuAigXwABcCk"]
[Tue Jul 21 07:58:14.964186 2026] [security2:error] [pid 341679:tid 341830] [client 20.226.60.151:59966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/adjig.php"] [unique_id "al9QxgWat-noHLkDuAigYQAAAR8"]
[Tue Jul 21 07:58:15.056217 2026] [security2:error] [pid 341679:tid 341865] [client 74.249.245.134:17466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/gettest.php"] [unique_id "al9QxwWat-noHLkDuAigZwAAAUI"]
[Tue Jul 21 07:58:15.077021 2026] [security2:error] [pid 341679:tid 341821] [client 65.21.113.253:44578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QxgWat-noHLkDuAigQgAAARY"]
[Tue Jul 21 07:58:15.107066 2026] [security2:error] [pid 341679:tid 341907] [client 20.104.96.117:3572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/jp.php"] [unique_id "al9QxwWat-noHLkDuAigaQAAAWw"]
[Tue Jul 21 07:58:15.332387 2026] [security2:error] [pid 341679:tid 341898] [client 4.204.201.85:9565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9QxwWat-noHLkDuAigeAAAAWM"]
[Tue Jul 21 07:58:15.391407 2026] [security2:error] [pid 341679:tid 341868] [client 103.166.103.129:55230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QxwWat-noHLkDuAigeQAAAUU"]
[Tue Jul 21 07:58:15.391791 2026] [security2:error] [pid 341679:tid 341868] [client 103.166.103.129:55230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9QxwWat-noHLkDuAigeQAAAUU"]
[Tue Jul 21 07:58:15.420900 2026] [security2:error] [pid 341679:tid 341805] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/.env.backup"] [unique_id "al9QxwWat-noHLkDuAigegABXH0"]
[Tue Jul 21 07:58:15.438399 2026] [security2:error] [pid 341679:tid 341872] [client 103.29.114.44:65404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QxwWat-noHLkDuAigewAAAUk"]
[Tue Jul 21 07:58:15.438565 2026] [security2:error] [pid 341679:tid 341872] [client 103.29.114.44:65404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QxwWat-noHLkDuAigewAAAUk"]
[Tue Jul 21 07:58:15.511140 2026] [security2:error] [pid 341679:tid 341729] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dashboard.gradiente.com"] [uri "/v1/graphql"] [unique_id "al9QxwWat-noHLkDuAigfQABiTE"]
[Tue Jul 21 07:58:15.538349 2026] [security2:error] [pid 341679:tid 341812] [client 20.104.96.117:3517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/f35.php"] [unique_id "al9QxwWat-noHLkDuAiggQAAAQ0"]
[Tue Jul 21 07:58:15.577145 2026] [security2:error] [pid 341679:tid 341728] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/.env.local"] [unique_id "al9QxwWat-noHLkDuAighgABfzA"]
[Tue Jul 21 07:58:15.735259 2026] [security2:error] [pid 341679:tid 341723] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.gradiente.com"] [uri "/.env.old"] [unique_id "al9QxwWat-noHLkDuAigiwABDys"]
[Tue Jul 21 07:58:15.737268 2026] [security2:error] [pid 341679:tid 341697] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/.env.bak"] [unique_id "al9QxwWat-noHLkDuAigjAABDxE"]
[Tue Jul 21 07:58:15.821481 2026] [security2:error] [pid 341679:tid 341706] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/api/.env"] [unique_id "al9QxwWat-noHLkDuAigkgABdBo"]
[Tue Jul 21 07:58:15.977979 2026] [security2:error] [pid 341679:tid 341791] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/backend/.env"] [unique_id "al9QxwWat-noHLkDuAignAABIW8"]
[Tue Jul 21 07:58:15.990600 2026] [security2:error] [pid 341679:tid 341736] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.gradiente.com"] [uri "/secrets.json"] [unique_id "al9QxwWat-noHLkDuAignwABIjg"]
[Tue Jul 21 07:58:15.992100 2026] [security2:error] [pid 341679:tid 341749] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/config/.env"] [unique_id "al9QxwWat-noHLkDuAigngABIkU"]
[Tue Jul 21 07:58:16.102943 2026] [security2:error] [pid 341679:tid 341818] [client 20.104.96.117:3497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-load.php"] [unique_id "al9QyAWat-noHLkDuAigpgAAARM"]
[Tue Jul 21 07:58:16.281005 2026] [security2:error] [pid 341679:tid 341871] [client 20.104.96.117:46622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9QyAWat-noHLkDuAigqwAAAUg"]
[Tue Jul 21 07:58:16.302321 2026] [security2:error] [pid 341679:tid 341857] [client 74.249.245.134:5561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/tfm.php"] [unique_id "al9QyAWat-noHLkDuAigrAAAATo"]
[Tue Jul 21 07:58:16.336233 2026] [security2:error] [pid 341679:tid 341889] [client 4.204.201.85:9578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/wefile.php"] [unique_id "al9QyAWat-noHLkDuAigrgAAAVo"]
[Tue Jul 21 07:58:16.347043 2026] [security2:error] [pid 341679:tid 341913] [client 102.206.115.33:64772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QyAWat-noHLkDuAigrwAAAXI"]
[Tue Jul 21 07:58:16.347135 2026] [security2:error] [pid 341679:tid 341913] [client 102.206.115.33:64772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9QyAWat-noHLkDuAigrwAAAXI"]
[Tue Jul 21 07:58:16.374408 2026] [security2:error] [pid 341679:tid 341800] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.gradiente.com"] [uri "/.s3cfg"] [unique_id "al9QyAWat-noHLkDuAigtQABQXg"]
[Tue Jul 21 07:58:16.374414 2026] [security2:error] [pid 341679:tid 341779] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/.htpasswd"] [unique_id "al9QyAWat-noHLkDuAigtAABQWM"]
[Tue Jul 21 07:58:16.501399 2026] [security2:error] [pid 341679:tid 341890] [client 20.220.225.223:1292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/ms-new.php"] [unique_id "al9QyAWat-noHLkDuAigvgAAAVs"]
[Tue Jul 21 07:58:16.655921 2026] [security2:error] [pid 341679:tid 341920] [client 122.179.91.63:17141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QyAWat-noHLkDuAigxgAAAXk"]
[Tue Jul 21 07:58:16.656080 2026] [security2:error] [pid 341679:tid 341920] [client 122.179.91.63:17141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9QyAWat-noHLkDuAigxgAAAXk"]
[Tue Jul 21 07:58:16.784866 2026] [security2:error] [pid 341679:tid 341812] [client 20.104.96.117:45476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/xyn.php"] [unique_id "al9QyAWat-noHLkDuAigyAAAAQ0"]
[Tue Jul 21 07:58:16.827623 2026] [security2:error] [pid 341679:tid 341777] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/.svn/entries"] [unique_id "al9QyAWat-noHLkDuAigzQABGmE"]
[Tue Jul 21 07:58:16.853170 2026] [security2:error] [pid 341679:tid 341691] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/.ssh/id_rsa"] [unique_id "al9QyAWat-noHLkDuAig0QABaws"]
[Tue Jul 21 07:58:17.005011 2026] [security2:error] [pid 341679:tid 341935] [client 65.21.113.253:44572] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QyAWat-noHLkDuAigwQAAAYg"]
[Tue Jul 21 07:58:17.027300 2026] [security2:error] [pid 341679:tid 341768] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/.ssh/id_dsa"] [unique_id "al9QyQWat-noHLkDuAig3QABX1g"]
[Tue Jul 21 07:58:17.143929 2026] [security2:error] [pid 341679:tid 341903] [client 103.86.117.203:54524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QyQWat-noHLkDuAig3wAAAWg"]
[Tue Jul 21 07:58:17.144083 2026] [security2:error] [pid 341679:tid 341903] [client 103.86.117.203:54524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9QyQWat-noHLkDuAig3wAAAWg"]
[Tue Jul 21 07:58:17.146954 2026] [security2:error] [pid 341679:tid 341835] [client 172.245.102.29:25151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9QxgWat-noHLkDuAigYwAAASQ"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:58:17.344966 2026] [autoindex:error] [pid 341679:tid 341857] [client 205.210.31.128:62898] AH01276: Cannot serve directory /home4/dralul00/ventdigital.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:58:17.345371 2026] [autoindex:error] [pid 341679:tid 341927] [client 20.104.96.117:3530] AH01276: Cannot serve directory /home2/thekin17/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:58:17.394700 2026] [security2:error] [pid 341679:tid 341919] [client 4.204.201.85:61023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9QyQWat-noHLkDuAig6QAAAXg"]
[Tue Jul 21 07:58:17.482996 2026] [security2:error] [pid 341679:tid 341788] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QyQWat-noHLkDuAig7wABSGw"]
[Tue Jul 21 07:58:17.483177 2026] [security2:error] [pid 341679:tid 341871] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QyQWat-noHLkDuAig7wABSGw"]
[Tue Jul 21 07:58:17.541299 2026] [security2:error] [pid 341679:tid 341887] [client 20.151.10.161:28682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-content/admin.php"] [unique_id "al9QyQWat-noHLkDuAig8gAAAVg"]
[Tue Jul 21 07:58:17.608047 2026] [security2:error] [pid 341679:tid 341799] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/id_dsa"] [unique_id "al9QyQWat-noHLkDuAig9gABWXc"]
[Tue Jul 21 07:58:17.613486 2026] [security2:error] [pid 341679:tid 341839] [client 20.206.105.145:28622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/k2.php"] [unique_id "al9QyQWat-noHLkDuAig-gAAASg"]
[Tue Jul 21 07:58:17.623797 2026] [security2:error] [pid 341679:tid 341701] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/id_rsa"] [unique_id "al9QyQWat-noHLkDuAig-wABKRU"]
[Tue Jul 21 07:58:17.714168 2026] [autoindex:error] [pid 341679:tid 341874] [client 20.104.96.117:3530] AH01276: Cannot serve directory /home2/thekin17/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:58:17.898066 2026] [security2:error] [pid 341679:tid 341830] [client 20.104.96.117:3530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/ccc.php"] [unique_id "al9QyQWat-noHLkDuAihBgAAAR8"]
[Tue Jul 21 07:58:17.956064 2026] [security2:error] [pid 341679:tid 341880] [client 122.164.127.47:58208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QyQWat-noHLkDuAihCwAAAVE"]
[Tue Jul 21 07:58:17.956167 2026] [security2:error] [pid 341679:tid 341880] [client 122.164.127.47:58208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9QyQWat-noHLkDuAihCwAAAVE"]
[Tue Jul 21 07:58:18.006003 2026] [security2:error] [pid 341679:tid 341719] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/key.pem"] [unique_id "al9QygWat-noHLkDuAihEgABISc"]
[Tue Jul 21 07:58:18.044609 2026] [security2:error] [pid 341679:tid 341713] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/privatekey.key"] [unique_id "al9QygWat-noHLkDuAihFAABhCE"]
[Tue Jul 21 07:58:18.046485 2026] [security2:error] [pid 341679:tid 341761] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/localhost.key"] [unique_id "al9QygWat-noHLkDuAihFQABD1E"]
[Tue Jul 21 07:58:18.114505 2026] [security2:error] [pid 341679:tid 341910] [client 74.249.245.134:62857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/ws81.php"] [unique_id "al9QygWat-noHLkDuAihGwAAAW8"]
[Tue Jul 21 07:58:18.246915 2026] [security2:error] [pid 341679:tid 341705] [remote 20.153.140.50:47418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9QygWat-noHLkDuAihHwABGhk"]
[Tue Jul 21 07:58:18.446505 2026] [security2:error] [pid 341679:tid 341729] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/.hermes/.env"] [unique_id "al9QygWat-noHLkDuAihJwABHDE"]
[Tue Jul 21 07:58:18.490079 2026] [security2:error] [pid 341679:tid 341796] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9QygWat-noHLkDuAihKwABY3Q"]
[Tue Jul 21 07:58:18.521369 2026] [security2:error] [pid 341679:tid 341888] [client 20.104.96.117:45183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/w.php"] [unique_id "al9QygWat-noHLkDuAihMQAAAVk"]
[Tue Jul 21 07:58:18.639752 2026] [security2:error] [pid 341679:tid 341723] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QygWat-noHLkDuAihNQABhSs"]
[Tue Jul 21 07:58:18.639939 2026] [security2:error] [pid 341679:tid 341932] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QygWat-noHLkDuAihNQABhSs"]
[Tue Jul 21 07:58:18.707649 2026] [security2:error] [pid 341679:tid 341828] [client 20.151.10.161:28686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/adminfuns.php"] [unique_id "al9QygWat-noHLkDuAihOgAAAR0"]
[Tue Jul 21 07:58:18.966425 2026] [security2:error] [pid 341679:tid 341865] [client 20.104.96.117:3490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9QygWat-noHLkDuAihSgAAAUI"]
[Tue Jul 21 07:58:18.979353 2026] [security2:error] [pid 341679:tid 341929] [client 117.210.135.0:55656] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QygWat-noHLkDuAihSwAAAYI"]
[Tue Jul 21 07:58:18.979482 2026] [security2:error] [pid 341679:tid 341929] [client 117.210.135.0:55656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QygWat-noHLkDuAihSwAAAYI"]
[Tue Jul 21 07:58:19.018929 2026] [security2:error] [pid 341679:tid 341715] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.gradiente.com"] [uri "/.claude/settings.json"] [unique_id "al9QywWat-noHLkDuAihTwABaCM"]
[Tue Jul 21 07:58:19.046717 2026] [security2:error] [pid 341679:tid 341912] [client 20.220.225.223:1815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/track.php"] [unique_id "al9QywWat-noHLkDuAihUQAAAXE"]
[Tue Jul 21 07:58:19.055914 2026] [security2:error] [pid 341679:tid 341861] [client 4.204.201.85:61582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9QywWat-noHLkDuAihVgAAAT4"]
[Tue Jul 21 07:58:19.097360 2026] [security2:error] [pid 341679:tid 341858] [client 136.144.33.53:40833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9QywWat-noHLkDuAihWAAAATs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:58:19.258058 2026] [security2:error] [pid 341679:tid 341718] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "dashboard.gradiente.com"] [uri "/wp-config.php.old"] [unique_id "al9QywWat-noHLkDuAihZgABRSY"]
[Tue Jul 21 07:58:19.258440 2026] [security2:error] [pid 341679:tid 341800] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "dashboard.gradiente.com"] [uri "/wp-config.php.bak"] [unique_id "al9QywWat-noHLkDuAihZwABRXg"]
[Tue Jul 21 07:58:19.328533 2026] [security2:error] [pid 341679:tid 341752] [remote 182.77.62.24:53956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-login.php"] [unique_id "al9QywWat-noHLkDuAihbAABSUg"]
[Tue Jul 21 07:58:19.361836 2026] [security2:error] [pid 341679:tid 341936] [client 20.104.96.117:3464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/FWAZ.php"] [unique_id "al9QywWat-noHLkDuAihbgAAAYk"]
[Tue Jul 21 07:58:19.373167 2026] [security2:error] [pid 341679:tid 341772] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/server/.env"] [unique_id "al9QywWat-noHLkDuAihcAABEFw"]
[Tue Jul 21 07:58:19.373931 2026] [security2:error] [pid 341679:tid 341741] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/config/.env"] [unique_id "al9QywWat-noHLkDuAihcQABFD0"]
[Tue Jul 21 07:58:19.375505 2026] [security2:error] [pid 341679:tid 341696] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/.env~"] [unique_id "al9QywWat-noHLkDuAihcgABahA"]
[Tue Jul 21 07:58:19.376731 2026] [security2:error] [pid 341679:tid 341762] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/laravel/.env"] [unique_id "al9QywWat-noHLkDuAihdQABhVI"]
[Tue Jul 21 07:58:19.376776 2026] [security2:error] [pid 341679:tid 341787] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/project/.env"] [unique_id "al9QywWat-noHLkDuAihdAABams"]
[Tue Jul 21 07:58:19.386252 2026] [security2:error] [pid 341679:tid 341688] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/storage/.env"] [unique_id "al9QywWat-noHLkDuAihdgABJwg"]
[Tue Jul 21 07:58:19.394556 2026] [security2:error] [pid 341679:tid 341781] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/home/.env"] [unique_id "al9QywWat-noHLkDuAihdwABd2U"]
[Tue Jul 21 07:58:19.401660 2026] [security2:error] [pid 341679:tid 341695] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/public/.env"] [unique_id "al9QywWat-noHLkDuAiheQABGA8"]
[Tue Jul 21 07:58:19.408840 2026] [security2:error] [pid 341679:tid 341770] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/api/.env"] [unique_id "al9QywWat-noHLkDuAihewABf1o"]
[Tue Jul 21 07:58:19.408840 2026] [security2:error] [pid 341679:tid 341710] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/build/.env"] [unique_id "al9QywWat-noHLkDuAihegABaR4"]
[Tue Jul 21 07:58:19.411127 2026] [security2:error] [pid 341679:tid 341699] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/bootstrap/.env"] [unique_id "al9QywWat-noHLkDuAihfAABeRM"]
[Tue Jul 21 07:58:19.411436 2026] [security2:error] [pid 341679:tid 341777] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/output/.env"] [unique_id "al9QywWat-noHLkDuAihfQABeWE"]
[Tue Jul 21 07:58:19.442569 2026] [security2:error] [pid 341679:tid 341691] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/wp-content/plugins/.env"] [unique_id "al9QywWat-noHLkDuAihggABfws"]
[Tue Jul 21 07:58:19.489021 2026] [security2:error] [pid 341679:tid 341854] [client 74.249.245.134:54361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/222.php"] [unique_id "al9QywWat-noHLkDuAihhgAAATc"]
[Tue Jul 21 07:58:19.613723 2026] [core:error] [pid 341679:tid 341746] [remote 40.77.167.247:44436] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:19.613750 2026] [core:error] [pid 341679:tid 341746] [remote 40.77.167.247:44436] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:19.639632 2026] [security2:error] [pid 341679:tid 341708] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/laravel/.env"] [unique_id "al9QywWat-noHLkDuAihkQABQRw"]
[Tue Jul 21 07:58:19.639847 2026] [security2:error] [pid 341679:tid 341864] [client 34.101.153.152:59920] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.gradiente.com"] [uri "/laravel/.env"] [unique_id "al9QywWat-noHLkDuAihkQABQRw"]
[Tue Jul 21 07:58:19.650984 2026] [security2:error] [pid 341679:tid 341683] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/.env.bak"] [unique_id "al9QywWat-noHLkDuAihlQABYAM"]
[Tue Jul 21 07:58:19.709660 2026] [security2:error] [pid 341679:tid 341712] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/backend/.env"] [unique_id "al9QywWat-noHLkDuAihnAABiCA"]
[Tue Jul 21 07:58:19.709768 2026] [security2:error] [pid 341679:tid 341900] [client 20.226.60.151:56763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/rithin.php"] [unique_id "al9QywWat-noHLkDuAihnQAAAWU"]
[Tue Jul 21 07:58:19.718203 2026] [core:error] [pid 341679:tid 341757] [remote 40.77.167.77:33827] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:19.718224 2026] [core:error] [pid 341679:tid 341757] [remote 40.77.167.77:33827] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:19.732585 2026] [security2:error] [pid 341679:tid 341684] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/out/.env"] [unique_id "al9QywWat-noHLkDuAihowABJgQ"]
[Tue Jul 21 07:58:19.732585 2026] [security2:error] [pid 341679:tid 341716] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/.env.old"] [unique_id "al9QywWat-noHLkDuAihoAABQiQ"]
[Tue Jul 21 07:58:19.738771 2026] [core:error] [pid 341679:tid 341727] [remote 40.77.167.247:44436] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:19.738799 2026] [core:error] [pid 341679:tid 341727] [remote 40.77.167.247:44436] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:19.739355 2026] [security2:error] [pid 341679:tid 341769] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/dist/.env"] [unique_id "al9QywWat-noHLkDuAihpwABE1k"]
[Tue Jul 21 07:58:19.739990 2026] [security2:error] [pid 341679:tid 341778] [remote 169.58.9.109:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.9.58.169.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getveltrixhealth.com"] [uri "/.env.local.php"] [unique_id "al9QywWat-noHLkDuAihpgABSGI"]
[Tue Jul 21 07:58:19.740659 2026] [security2:error] [pid 341679:tid 341737] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/wp-content/uploads/.env"] [unique_id "al9QywWat-noHLkDuAihqQABFjk"]
[Tue Jul 21 07:58:19.746198 2026] [security2:error] [pid 341679:tid 341806] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/app/.env"] [unique_id "al9QywWat-noHLkDuAihqwABJH4"]
[Tue Jul 21 07:58:19.747244 2026] [security2:error] [pid 341679:tid 341758] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/.env.backup"] [unique_id "al9QywWat-noHLkDuAihrAABXU4"]
[Tue Jul 21 07:58:19.747914 2026] [security2:error] [pid 341679:tid 341803] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/wp-content/themes/.env"] [unique_id "al9QywWat-noHLkDuAihrQABUHs"]
[Tue Jul 21 07:58:19.751797 2026] [security2:error] [pid 341679:tid 341780] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.gradiente.com"] [uri "/.env.php.bak"] [unique_id "al9QywWat-noHLkDuAihrgABQWQ"]
[Tue Jul 21 07:58:19.752999 2026] [security2:error] [pid 341679:tid 341698] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/wp-admin/.env"] [unique_id "al9QywWat-noHLkDuAihsAABbxI"]
[Tue Jul 21 07:58:19.758797 2026] [security2:error] [pid 341679:tid 341690] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/wp-content/.env"] [unique_id "al9QywWat-noHLkDuAihsgABfgo"]
[Tue Jul 21 07:58:19.763276 2026] [security2:error] [pid 341679:tid 341790] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/src/.env"] [unique_id "al9QywWat-noHLkDuAihtAABgG4"]
[Tue Jul 21 07:58:19.813264 2026] [security2:error] [pid 341679:tid 341694] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/root/.env"] [unique_id "al9QywWat-noHLkDuAihtgABHg4"]
[Tue Jul 21 07:58:19.819388 2026] [security2:error] [pid 341679:tid 341783] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.gradiente.com"] [uri "/core/.env"] [unique_id "al9QywWat-noHLkDuAihuAABQWc"]
[Tue Jul 21 07:58:19.862696 2026] [security2:error] [pid 341679:tid 341720] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.gradiente.com"] [uri "/config.php.bak"] [unique_id "al9QywWat-noHLkDuAihvgABQSg"]
[Tue Jul 21 07:58:19.898267 2026] [security2:error] [pid 341679:tid 341840] [client 20.220.225.223:1332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/2352356666.php"] [unique_id "al9QywWat-noHLkDuAihvwAAASk"]
[Tue Jul 21 07:58:19.975581 2026] [security2:error] [pid 341679:tid 341805] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/configuration.php.bak"] [unique_id "al9QywWat-noHLkDuAihwgABQX0"]
[Tue Jul 21 07:58:19.980398 2026] [security2:error] [pid 341679:tid 341739] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/vendor/.env"] [unique_id "al9QywWat-noHLkDuAihxQABNzs"]
[Tue Jul 21 07:58:20.007995 2026] [security2:error] [pid 341679:tid 341810] [client 20.104.96.117:45122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/miru1.php"] [unique_id "al9QzAWat-noHLkDuAihxwAAAQs"]
[Tue Jul 21 07:58:20.027857 2026] [security2:error] [pid 341679:tid 341796] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/.env.swp"] [unique_id "al9QzAWat-noHLkDuAihyAABQXQ"]
[Tue Jul 21 07:58:20.036114 2026] [security2:error] [pid 341679:tid 341866] [client 41.68.90.219:49400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QzAWat-noHLkDuAihywAAAUM"]
[Tue Jul 21 07:58:20.037310 2026] [security2:error] [pid 341679:tid 341866] [client 41.68.90.219:49400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QzAWat-noHLkDuAihywAAAUM"]
[Tue Jul 21 07:58:20.056494 2026] [security2:error] [pid 341679:tid 341862] [client 4.204.201.85:9599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/8.php"] [unique_id "al9QzAWat-noHLkDuAihzQAAAT8"]
[Tue Jul 21 07:58:20.081455 2026] [security2:error] [pid 341679:tid 341880] [client 65.21.113.253:44572] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9QywWat-noHLkDuAihiQAAAVE"]
[Tue Jul 21 07:58:20.098351 2026] [security2:error] [pid 341679:tid 341751] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/web/.env"] [unique_id "al9QzAWat-noHLkDuAihzgABQUc"]
[Tue Jul 21 07:58:20.098595 2026] [security2:error] [pid 341679:tid 341728] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/public/.env"] [unique_id "al9QzAWat-noHLkDuAihzwABQTA"]
[Tue Jul 21 07:58:20.160293 2026] [security2:error] [pid 341679:tid 341723] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "dashboard.gradiente.com"] [uri "/application.properties"] [unique_id "al9QzAWat-noHLkDuAih1wABQSs"]
[Tue Jul 21 07:58:20.349328 2026] [security2:error] [pid 341679:tid 341744] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QzAWat-noHLkDuAih3wABWkA"]
[Tue Jul 21 07:58:20.349520 2026] [security2:error] [pid 341679:tid 341889] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9QzAWat-noHLkDuAih3wABWkA"]
[Tue Jul 21 07:58:20.367264 2026] [security2:error] [pid 341679:tid 341881] [client 178.153.91.96:9611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QzAWat-noHLkDuAih4QAAAVI"]
[Tue Jul 21 07:58:20.367502 2026] [security2:error] [pid 341679:tid 341881] [client 178.153.91.96:9611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9QzAWat-noHLkDuAih4QAAAVI"]
[Tue Jul 21 07:58:20.450690 2026] [security2:error] [pid 341679:tid 341709] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.gradiente.com"] [uri "/.gradle/gradle.properties"] [unique_id "al9QzAWat-noHLkDuAih6AABQR0"]
[Tue Jul 21 07:58:20.472520 2026] [security2:error] [pid 341679:tid 341829] [client 20.104.96.117:3538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/aa.php"] [unique_id "al9QzAWat-noHLkDuAih7QAAAR4"]
[Tue Jul 21 07:58:20.607063 2026] [security2:error] [pid 341679:tid 341932] [client 20.151.10.161:29208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/goods.php"] [unique_id "al9QzAWat-noHLkDuAih9wAAAYU"]
[Tue Jul 21 07:58:20.643560 2026] [security2:error] [pid 341679:tid 341685] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.gradiente.com"] [uri "/config/.env.php"] [unique_id "al9QywWat-noHLkDuAihkgABQQU"]
[Tue Jul 21 07:58:20.855107 2026] [security2:error] [pid 341679:tid 341917] [client 20.220.225.223:1811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/pn.php"] [unique_id "al9QzAWat-noHLkDuAiiAwAAAXY"]
[Tue Jul 21 07:58:20.917976 2026] [security2:error] [pid 341679:tid 341696] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/web.config"] [unique_id "al9QzAWat-noHLkDuAiiBwABQxA"]
[Tue Jul 21 07:58:20.948416 2026] [security2:error] [pid 341679:tid 341762] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/local.settings.json"] [unique_id "al9QzAWat-noHLkDuAiiDQABUVI"]
[Tue Jul 21 07:58:20.948608 2026] [security2:error] [pid 341679:tid 341880] [client 34.101.153.152:59920] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.gradiente.com"] [uri "/local.settings.json"] [unique_id "al9QzAWat-noHLkDuAiiDQABUVI"]
[Tue Jul 21 07:58:20.953047 2026] [security2:error] [pid 341679:tid 341859] [client 4.204.201.85:9622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9QzAWat-noHLkDuAiiDwAAATw"]
[Tue Jul 21 07:58:21.020602 2026] [security2:error] [pid 341679:tid 341927] [client 38.100.221.102:17346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QzQWat-noHLkDuAiiFgAAAYA"]
[Tue Jul 21 07:58:21.020714 2026] [security2:error] [pid 341679:tid 341927] [client 38.100.221.102:17346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QzQWat-noHLkDuAiiFgAAAYA"]
[Tue Jul 21 07:58:21.024371 2026] [security2:error] [pid 341679:tid 341890] [client 20.104.96.117:3458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/122.php"] [unique_id "al9QzQWat-noHLkDuAiiFwAAAVs"]
[Tue Jul 21 07:58:21.106876 2026] [security2:error] [pid 341679:tid 341914] [client 65.111.5.177:38841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.5.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QzAWat-noHLkDuAiiDAAAAXM"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:58:21.134203 2026] [security2:error] [pid 341679:tid 341871] [client 20.206.105.145:28632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/82.php"] [unique_id "al9QzQWat-noHLkDuAiiIgAAAUg"]
[Tue Jul 21 07:58:21.169457 2026] [security2:error] [pid 341679:tid 341691] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/.bundle/.env"] [unique_id "al9QzQWat-noHLkDuAiiIwABews"]
[Tue Jul 21 07:58:21.195479 2026] [security2:error] [pid 341679:tid 341760] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/manifests/.env"] [unique_id "al9QzQWat-noHLkDuAiiJAABHlA"]
[Tue Jul 21 07:58:21.195946 2026] [security2:error] [pid 341679:tid 341768] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/configuration/.env"] [unique_id "al9QzQWat-noHLkDuAiiLAABNVg"]
[Tue Jul 21 07:58:21.196012 2026] [security2:error] [pid 341679:tid 341798] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/opt/.env"] [unique_id "al9QzQWat-noHLkDuAiiLwABRXY"]
[Tue Jul 21 07:58:21.196081 2026] [security2:error] [pid 341679:tid 341708] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/config/credentials/.env"] [unique_id "al9QzQWat-noHLkDuAiiMAABbhw"]
[Tue Jul 21 07:58:21.196514 2026] [security2:error] [pid 341679:tid 341789] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/usr/local/.env"] [unique_id "al9QzQWat-noHLkDuAiiKQABZG0"]
[Tue Jul 21 07:58:21.196538 2026] [security2:error] [pid 341679:tid 341740] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/docker/config/.env"] [unique_id "al9QzQWat-noHLkDuAiiLgABeDw"]
[Tue Jul 21 07:58:21.197761 2026] [security2:error] [pid 341679:tid 341726] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/myproject/.env"] [unique_id "al9QzQWat-noHLkDuAiiMwABZi4"]
[Tue Jul 21 07:58:21.199055 2026] [security2:error] [pid 341679:tid 341702] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/config/environments/.env"] [unique_id "al9QzQWat-noHLkDuAiiNAABFRY"]
[Tue Jul 21 07:58:21.202841 2026] [security2:error] [pid 341679:tid 341721] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/etc/.env"] [unique_id "al9QzQWat-noHLkDuAiiNwABRSk"]
[Tue Jul 21 07:58:21.252478 2026] [security2:error] [pid 341679:tid 341830] [client 109.60.28.94:61968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QzQWat-noHLkDuAiiPQAAAR8"]
[Tue Jul 21 07:58:21.252592 2026] [security2:error] [pid 341679:tid 341830] [client 109.60.28.94:61968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QzQWat-noHLkDuAiiPQAAAR8"]
[Tue Jul 21 07:58:21.346589 2026] [security2:error] [pid 341679:tid 341806] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QzQWat-noHLkDuAiiRAABan4"]
[Tue Jul 21 07:58:21.346908 2026] [security2:error] [pid 341679:tid 341905] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9QzQWat-noHLkDuAiiRAABan4"]
[Tue Jul 21 07:58:21.395049 2026] [security2:error] [pid 341679:tid 341876] [client 74.249.245.134:17443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/t.php"] [unique_id "al9QzQWat-noHLkDuAiiRQAAAU0"]
[Tue Jul 21 07:58:21.398646 2026] [security2:error] [pid 341679:tid 341859] [client 20.151.10.161:28809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/ms-edit.php"] [unique_id "al9QzQWat-noHLkDuAiiRgAAATw"]
[Tue Jul 21 07:58:21.416045 2026] [security2:error] [pid 341679:tid 341915] [client 20.220.225.223:1823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9QzQWat-noHLkDuAiiRwAAAXQ"]
[Tue Jul 21 07:58:21.439592 2026] [security2:error] [pid 341679:tid 341803] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/docker/.env"] [unique_id "al9QzQWat-noHLkDuAiiSQABgXs"]
[Tue Jul 21 07:58:21.440855 2026] [security2:error] [pid 341679:tid 341780] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/.nuxt/.env"] [unique_id "al9QzQWat-noHLkDuAiiSgABRmQ"]
[Tue Jul 21 07:58:21.468153 2026] [core:error] [pid 341679:tid 341698] [remote 52.167.144.184:62089] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:21.468172 2026] [core:error] [pid 341679:tid 341698] [remote 52.167.144.184:62089] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:21.471512 2026] [security2:error] [pid 341679:tid 341846] [client 59.93.4.33:65032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QzQWat-noHLkDuAiiTAAAAS8"]
[Tue Jul 21 07:58:21.471619 2026] [security2:error] [pid 341679:tid 341846] [client 59.93.4.33:65032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QzQWat-noHLkDuAiiTAAAAS8"]
[Tue Jul 21 07:58:21.531715 2026] [security2:error] [pid 341679:tid 341743] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/var/.env"] [unique_id "al9QzQWat-noHLkDuAiiUQABSj8"]
[Tue Jul 21 07:58:21.531715 2026] [security2:error] [pid 341679:tid 341763] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/helm/.env"] [unique_id "al9QzQWat-noHLkDuAiiUAABI1M"]
[Tue Jul 21 07:58:21.535278 2026] [security2:error] [pid 341679:tid 341735] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/containers/.env"] [unique_id "al9QzQWat-noHLkDuAiiUwABUzc"]
[Tue Jul 21 07:58:21.536929 2026] [security2:error] [pid 341679:tid 341704] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/instance/.env"] [unique_id "al9QzQWat-noHLkDuAiiVgABQxg"]
[Tue Jul 21 07:58:21.537140 2026] [security2:error] [pid 341679:tid 341783] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/k8s/.env"] [unique_id "al9QzQWat-noHLkDuAiiVwABMWc"]
[Tue Jul 21 07:58:21.540126 2026] [security2:error] [pid 341679:tid 341725] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/kubernetes/.env"] [unique_id "al9QzQWat-noHLkDuAiiWgABci0"]
[Tue Jul 21 07:58:21.542224 2026] [security2:error] [pid 341679:tid 341926] [client 117.247.80.59:25131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QzQWat-noHLkDuAiiXAAAAX8"]
[Tue Jul 21 07:58:21.542332 2026] [security2:error] [pid 341679:tid 341926] [client 117.247.80.59:25131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QzQWat-noHLkDuAiiXAAAAX8"]
[Tue Jul 21 07:58:21.553340 2026] [security2:error] [pid 341679:tid 341681] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/settings/.env"] [unique_id "al9QzQWat-noHLkDuAiiWQABgwE"]
[Tue Jul 21 07:58:21.561056 2026] [security2:error] [pid 341679:tid 341729] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/Config/.env"] [unique_id "al9QzQWat-noHLkDuAiiXwABIjE"]
[Tue Jul 21 07:58:21.562058 2026] [security2:error] [pid 341679:tid 341774] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/charts/.env"] [unique_id "al9QzQWat-noHLkDuAiiYQABDl4"]
[Tue Jul 21 07:58:21.562302 2026] [security2:error] [pid 341679:tid 341689] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/wsgi/.env"] [unique_id "al9QzQWat-noHLkDuAiiYwABDwk"]
[Tue Jul 21 07:58:21.563302 2026] [security2:error] [pid 341679:tid 341728] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/volumes/.env"] [unique_id "al9QzQWat-noHLkDuAiiZAABFjA"]
[Tue Jul 21 07:58:21.564843 2026] [security2:error] [pid 341679:tid 341723] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/deployments/.env"] [unique_id "al9QzQWat-noHLkDuAiiZgABSCs"]
[Tue Jul 21 07:58:21.573520 2026] [security2:error] [pid 341679:tid 341929] [client 4.204.201.85:9549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/f6.php"] [unique_id "al9QzQWat-noHLkDuAiiZwAAAYI"]
[Tue Jul 21 07:58:21.617498 2026] [security2:error] [pid 341679:tid 341877] [client 20.104.96.117:3556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/get.php"] [unique_id "al9QzQWat-noHLkDuAiiawAAAU4"]
[Tue Jul 21 07:58:21.705977 2026] [security2:error] [pid 341679:tid 341799] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/.env.development"] [unique_id "al9QzQWat-noHLkDuAiidAABFHc"]
[Tue Jul 21 07:58:21.774833 2026] [security2:error] [pid 341679:tid 341862] [client 20.151.10.161:28843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/222.php"] [unique_id "al9QzQWat-noHLkDuAiifgAAAT8"]
[Tue Jul 21 07:58:22.028369 2026] [security2:error] [pid 341679:tid 341707] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QzgWat-noHLkDuAiihgABFRs"]
[Tue Jul 21 07:58:22.028531 2026] [security2:error] [pid 341679:tid 341820] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QzgWat-noHLkDuAiihgABFRs"]
[Tue Jul 21 07:58:22.037005 2026] [security2:error] [pid 341679:tid 341835] [client 20.104.96.117:45159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/as.php"] [unique_id "al9QzgWat-noHLkDuAiihwAAASQ"]
[Tue Jul 21 07:58:22.088698 2026] [security2:error] [pid 341679:tid 341715] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/src/.env"] [unique_id "al9QzgWat-noHLkDuAiijQABTiM"]
[Tue Jul 21 07:58:22.088802 2026] [security2:error] [pid 341679:tid 341682] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/dev/.env"] [unique_id "al9QzgWat-noHLkDuAiijwABTgI"]
[Tue Jul 21 07:58:22.089864 2026] [security2:error] [pid 341679:tid 341736] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/docker/.env"] [unique_id "al9QzgWat-noHLkDuAiijgABTjg"]
[Tue Jul 21 07:58:22.090534 2026] [security2:error] [pid 341679:tid 341687] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/app/.env"] [unique_id "al9QzgWat-noHLkDuAiikAABTgc"]
[Tue Jul 21 07:58:22.108732 2026] [security2:error] [pid 341679:tid 341692] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/server/.env"] [unique_id "al9QzgWat-noHLkDuAiilAABHgw"]
[Tue Jul 21 07:58:22.108971 2026] [security2:error] [pid 341679:tid 341747] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/production/.env"] [unique_id "al9QzgWat-noHLkDuAiilQABHkM"]
[Tue Jul 21 07:58:22.109062 2026] [security2:error] [pid 341679:tid 341773] [remote 34.101.153.152:59920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.gradiente.com"] [uri "/frontend/.env"] [unique_id "al9QzgWat-noHLkDuAiilgABHl0"]
[Tue Jul 21 07:58:22.111923 2026] [security2:error] [pid 341679:tid 341927] [client 104.207.33.88:37879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9QzgWat-noHLkDuAiikgAAAYA"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:58:22.201636 2026] [security2:error] [pid 341679:tid 341753] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QzgWat-noHLkDuAiinAABiUk"]
[Tue Jul 21 07:58:22.201861 2026] [security2:error] [pid 341679:tid 341936] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9QzgWat-noHLkDuAiinAABiUk"]
[Tue Jul 21 07:58:22.202828 2026] [security2:error] [pid 341679:tid 341895] [client 4.204.201.85:9541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/inputs.php"] [unique_id "al9QzgWat-noHLkDuAiinwAAAWA"]
[Tue Jul 21 07:58:22.203544 2026] [security2:error] [pid 341679:tid 341935] [client 182.8.255.181:21067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QzgWat-noHLkDuAiioAAAAYg"]
[Tue Jul 21 07:58:22.203640 2026] [security2:error] [pid 341679:tid 341935] [client 182.8.255.181:21067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9QzgWat-noHLkDuAiioAAAAYg"]
[Tue Jul 21 07:58:22.371909 2026] [security2:error] [pid 341679:tid 341922] [client 185.213.175.37:51122] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "atmo.hunteron.com.br"] [uri "/cgi-sys/images/favicons/favicon-128.png"] [unique_id "al9QzgWat-noHLkDuAiiqQAAAXs"]
[Tue Jul 21 07:58:22.372082 2026] [security2:error] [pid 341679:tid 341922] [client 185.213.175.37:51122] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "atmo.hunteron.com.br"] [uri "/cgi-sys/images/favicons/favicon-128.png"] [unique_id "al9QzgWat-noHLkDuAiiqQAAAXs"]
[Tue Jul 21 07:58:22.396354 2026] [security2:error] [pid 341679:tid 341821] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9QzgWat-noHLkDuAiipgABFgU"]
[Tue Jul 21 07:58:22.473108 2026] [security2:error] [pid 341679:tid 341900] [client 185.213.175.37:51186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "atmo.hunteron.com.br"] [uri "/cgi-sys/images/favicons/favicon-96.png"] [unique_id "al9QzgWat-noHLkDuAiirAAAAWU"]
[Tue Jul 21 07:58:22.473225 2026] [security2:error] [pid 341679:tid 341900] [client 185.213.175.37:51186] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "atmo.hunteron.com.br"] [uri "/cgi-sys/images/favicons/favicon-96.png"] [unique_id "al9QzgWat-noHLkDuAiirAAAAWU"]
[Tue Jul 21 07:58:22.482735 2026] [security2:error] [pid 341679:tid 341904] [client 185.213.175.37:51156] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "atmo.hunteron.com.br"] [uri "/cgi-sys/images/favicons/favicon.ico"] [unique_id "al9QzgWat-noHLkDuAiirgAAAWk"]
[Tue Jul 21 07:58:22.670381 2026] [http2:info] [pid 352421:tid 352421] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 07:58:22.692161 2026] [security2:error] [pid 352421:tid 352661] [client 20.151.10.161:29075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/cgi-bin/index.php"] [unique_id "al9QzsJSWzG9jbYOtu4cdwAAAPM"]
[Tue Jul 21 07:58:22.697748 2026] [security2:error] [pid 352421:tid 352560] [client 93.152.221.13:55412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/phpinfo.php"] [unique_id "al9QzsJSWzG9jbYOtu4ceAAAAI4"]
[Tue Jul 21 07:58:22.750537 2026] [security2:error] [pid 341679:tid 341818] [client 136.144.33.97:20517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9QzgWat-noHLkDuAiirwAAARM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:58:22.841091 2026] [security2:error] [pid 352421:tid 352552] [client 74.7.241.170:47474] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "acheservicos.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9QzsJSWzG9jbYOtu4cfQAAhgE"]
[Tue Jul 21 07:58:22.845009 2026] [security2:error] [pid 352421:tid 352568] [client 65.21.113.253:55614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9QzsJSWzG9jbYOtu4cfwAAAJY"]
[Tue Jul 21 07:58:22.898210 2026] [security2:error] [pid 352421:tid 352574] [client 20.104.96.117:45452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/ccou.php"] [unique_id "al9QzsJSWzG9jbYOtu4cgwAAAJw"]
[Tue Jul 21 07:58:22.955427 2026] [security2:error] [pid 352421:tid 352578] [client 4.204.201.85:9569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/inputs.php"] [unique_id "al9QzsJSWzG9jbYOtu4chAAAAKA"]
[Tue Jul 21 07:58:22.961416 2026] [security2:error] [pid 352421:tid 352579] [client 20.197.192.193:3735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/else1.php"] [unique_id "al9QzsJSWzG9jbYOtu4chQAAAKE"]
[Tue Jul 21 07:58:23.093030 2026] [security2:error] [pid 352421:tid 352594] [client 93.152.221.13:62250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/test.php"] [unique_id "al9Qz8JSWzG9jbYOtu4cjgAAALA"]
[Tue Jul 21 07:58:23.114717 2026] [security2:error] [pid 352421:tid 352429] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Qz8JSWzG9jbYOtu4ckQAAigc"]
[Tue Jul 21 07:58:23.114941 2026] [security2:error] [pid 352421:tid 352556] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Qz8JSWzG9jbYOtu4ckQAAigc"]
[Tue Jul 21 07:58:23.235792 2026] [security2:error] [pid 352421:tid 352566] [client 65.111.11.162:34433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.11.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9Qz8JSWzG9jbYOtu4cjQAAAJQ"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:58:23.310760 2026] [security2:error] [pid 352421:tid 352433] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/django/.env"] [unique_id "al9Qz8JSWzG9jbYOtu4cnAAAtws"]
[Tue Jul 21 07:58:23.378195 2026] [security2:error] [pid 352421:tid 352442] [remote 34.101.153.152:37750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/config/gcp-credentials.json"] [unique_id "al9Qz8JSWzG9jbYOtu4cpQAA-xQ"]
[Tue Jul 21 07:58:23.378419 2026] [security2:error] [pid 352421:tid 352444] [remote 34.101.153.152:37750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/api/config"] [unique_id "al9Qz8JSWzG9jbYOtu4cpgAA-xY"]
[Tue Jul 21 07:58:23.378472 2026] [security2:error] [pid 352421:tid 352669] [client 34.101.153.152:37750] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.gradiente.com"] [uri "/config/gcp-credentials.json"] [unique_id "al9Qz8JSWzG9jbYOtu4cpQAA-xQ"]
[Tue Jul 21 07:58:23.378764 2026] [security2:error] [pid 352421:tid 352443] [remote 34.101.153.152:37750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/api/v1/settings"] [unique_id "al9Qz8JSWzG9jbYOtu4cpwAA-xU"]
[Tue Jul 21 07:58:23.379009 2026] [security2:error] [pid 352421:tid 352669] [client 34.101.153.152:37750] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.gradiente.com"] [uri "/api/v1/settings"] [unique_id "al9Qz8JSWzG9jbYOtu4cpwAA-xU"]
[Tue Jul 21 07:58:23.379406 2026] [security2:error] [pid 352421:tid 352443] [remote 34.101.153.152:37750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/__/firebase/init.json"] [unique_id "al9Qz8JSWzG9jbYOtu4cqwAA-xU"]
[Tue Jul 21 07:58:23.409600 2026] [security2:error] [pid 352421:tid 352457] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/strapi/.env"] [unique_id "al9Qz8JSWzG9jbYOtu4ctQAAziM"]
[Tue Jul 21 07:58:23.413236 2026] [security2:error] [pid 352421:tid 352469] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/symfony/.env"] [unique_id "al9Qz8JSWzG9jbYOtu4cwQAA1S8"]
[Tue Jul 21 07:58:23.414457 2026] [security2:error] [pid 352421:tid 352470] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/magento/.env"] [unique_id "al9Qz8JSWzG9jbYOtu4cwgAA2TA"]
[Tue Jul 21 07:58:23.415797 2026] [security2:error] [pid 352421:tid 352470] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/nextjs/.env"] [unique_id "al9Qz8JSWzG9jbYOtu4cxAAA2zA"]
[Tue Jul 21 07:58:23.416273 2026] [security2:error] [pid 352421:tid 352473] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/rails/.env"] [unique_id "al9Qz8JSWzG9jbYOtu4cxQABAzM"]
[Tue Jul 21 07:58:23.438491 2026] [security2:error] [pid 352421:tid 352678] [client 20.104.96.117:3565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/w3lls.php"] [unique_id "al9Qz8JSWzG9jbYOtu4cywAAAQQ"]
[Tue Jul 21 07:58:23.454351 2026] [security2:error] [pid 352421:tid 352478] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/drupal/.env"] [unique_id "al9Qz8JSWzG9jbYOtu4cyQAA5Dg"]
[Tue Jul 21 07:58:23.769769 2026] [security2:error] [pid 352421:tid 352584] [client 20.220.225.223:1295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/dr.php"] [unique_id "al9Qz8JSWzG9jbYOtu4c6QAAAKY"]
[Tue Jul 21 07:58:23.804543 2026] [security2:error] [pid 352421:tid 352587] [client 4.204.201.85:9598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Qz8JSWzG9jbYOtu4c7AAAAKk"]
[Tue Jul 21 07:58:23.815914 2026] [security2:error] [pid 352421:tid 352667] [client 172.245.102.30:30213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Qz8JSWzG9jbYOtu4c3QAAAPk"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:58:23.890168 2026] [security2:error] [pid 352421:tid 352600] [client 106.215.181.8:25344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Qz8JSWzG9jbYOtu4c8gAAALY"]
[Tue Jul 21 07:58:23.890318 2026] [security2:error] [pid 352421:tid 352600] [client 106.215.181.8:25344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Qz8JSWzG9jbYOtu4c8gAAALY"]
[Tue Jul 21 07:58:23.911426 2026] [security2:error] [pid 352421:tid 352666] [client 87.116.180.198:13993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Qz8JSWzG9jbYOtu4c8wAAAPg"]
[Tue Jul 21 07:58:23.915825 2026] [security2:error] [pid 352421:tid 352666] [client 87.116.180.198:13993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Qz8JSWzG9jbYOtu4c8wAAAPg"]
[Tue Jul 21 07:58:23.926678 2026] [security2:error] [pid 352421:tid 352657] [client 65.21.113.253:42120] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Qz8JSWzG9jbYOtu4c2gAAAO8"]
[Tue Jul 21 07:58:23.942832 2026] [security2:error] [pid 352421:tid 352609] [client 65.21.113.253:42110] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Qz8JSWzG9jbYOtu4c1gAAAL8"]
[Tue Jul 21 07:58:23.992302 2026] [security2:error] [pid 352421:tid 352599] [client 20.151.10.161:29209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/BDKR28WP.php"] [unique_id "al9Qz8JSWzG9jbYOtu4c9wAAALU"]
[Tue Jul 21 07:58:24.088506 2026] [security2:error] [pid 352421:tid 352659] [client 223.236.153.128:5894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Q0MJSWzG9jbYOtu4c-wAAAPE"]
[Tue Jul 21 07:58:24.088626 2026] [security2:error] [pid 352421:tid 352659] [client 223.236.153.128:5894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Q0MJSWzG9jbYOtu4c-wAAAPE"]
[Tue Jul 21 07:58:24.478389 2026] [security2:error] [pid 352421:tid 352574] [client 4.204.201.85:61002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9Q0MJSWzG9jbYOtu4dFgAAAJw"]
[Tue Jul 21 07:58:24.489774 2026] [security2:error] [pid 352421:tid 352526] [remote 34.101.153.152:37750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/api/env"] [unique_id "al9Q0MJSWzG9jbYOtu4dFwAAnmg"]
[Tue Jul 21 07:58:24.539245 2026] [security2:error] [pid 352421:tid 352555] [client 20.104.96.117:45173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/test1.php"] [unique_id "al9Q0MJSWzG9jbYOtu4dGgAAAIk"]
[Tue Jul 21 07:58:24.570318 2026] [security2:error] [pid 352421:tid 352579] [client 93.152.221.13:50017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/info.php"] [unique_id "al9Q0MJSWzG9jbYOtu4dHAAAAKE"]
[Tue Jul 21 07:58:24.705282 2026] [security2:error] [pid 352421:tid 352634] [client 65.111.30.99:41107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.30.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9Q0MJSWzG9jbYOtu4dHgAAANg"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:58:24.859850 2026] [security2:error] [pid 352421:tid 352535] [remote 34.101.153.152:37750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/manifest.webmanifest"] [unique_id "al9Q0MJSWzG9jbYOtu4dKwAA-HE"]
[Tue Jul 21 07:58:24.883948 2026] [security2:error] [pid 352421:tid 352539] [remote 34.101.153.152:37750] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.gradiente.com"] [uri "/openapi.json"] [unique_id "al9Q0MJSWzG9jbYOtu4dMAAAtXU"]
[Tue Jul 21 07:58:24.957144 2026] [security2:error] [pid 352421:tid 352595] [client 20.206.105.145:55917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/config.json.php"] [unique_id "al9Q0MJSWzG9jbYOtu4dNAAAALE"]
[Tue Jul 21 07:58:24.962874 2026] [security2:error] [pid 352421:tid 352608] [client 93.152.221.13:63962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/php.php"] [unique_id "al9Q0MJSWzG9jbYOtu4dNQAAAL4"]
[Tue Jul 21 07:58:25.047410 2026] [security2:error] [pid 352421:tid 352655] [client 74.249.245.134:5546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/a.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dNgAAAO0"]
[Tue Jul 21 07:58:25.059831 2026] [security2:error] [pid 352421:tid 352654] [client 20.220.225.223:1297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/2x.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dNwAAAOw"]
[Tue Jul 21 07:58:25.121822 2026] [security2:error] [pid 352421:tid 352663] [client 198.54.128.138:47038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dOAAAAPU"]
[Tue Jul 21 07:58:25.121927 2026] [security2:error] [pid 352421:tid 352663] [client 198.54.128.138:47038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dOAAAAPU"]
[Tue Jul 21 07:58:25.127075 2026] [security2:error] [pid 352421:tid 352605] [client 20.104.96.117:3579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/database.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dOQAAALs"]
[Tue Jul 21 07:58:25.271089 2026] [security2:error] [pid 352421:tid 352431] [remote 34.101.153.152:37750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/graphql"] [unique_id "al9Q0cJSWzG9jbYOtu4dRwAA1Ak"]
[Tue Jul 21 07:58:25.277346 2026] [security2:error] [pid 352421:tid 352624] [client 20.226.60.151:61625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/albin.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dSAAAAM4"]
[Tue Jul 21 07:58:25.289957 2026] [security2:error] [pid 352421:tid 352572] [client 103.78.200.11:58026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dSgAAAJo"]
[Tue Jul 21 07:58:25.290178 2026] [security2:error] [pid 352421:tid 352572] [client 103.78.200.11:58026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dSgAAAJo"]
[Tue Jul 21 07:58:25.325398 2026] [security2:error] [pid 352421:tid 352580] [client 122.162.144.145:18616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dUQAAAKI"]
[Tue Jul 21 07:58:25.325598 2026] [security2:error] [pid 352421:tid 352580] [client 122.162.144.145:18616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dUQAAAKI"]
[Tue Jul 21 07:58:25.353707 2026] [security2:error] [pid 352421:tid 352604] [client 93.152.221.13:65343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/php_info.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dVAAAALo"]
[Tue Jul 21 07:58:25.401532 2026] [security2:error] [pid 352421:tid 352559] [client 202.143.127.214:58208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dWQAAAI0"]
[Tue Jul 21 07:58:25.401771 2026] [security2:error] [pid 352421:tid 352559] [client 202.143.127.214:58208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dWQAAAI0"]
[Tue Jul 21 07:58:25.426200 2026] [security2:error] [pid 352421:tid 352551] [client 4.204.201.85:61031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/wp-blog.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dWwAAAIU"]
[Tue Jul 21 07:58:25.624120 2026] [security2:error] [pid 352421:tid 352587] [client 20.104.96.117:3576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/file.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dZAAAAKk"]
[Tue Jul 21 07:58:25.656233 2026] [security2:error] [pid 352421:tid 352589] [client 20.226.60.151:59986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/byp.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dZwAAAKs"]
[Tue Jul 21 07:58:25.743199 2026] [security2:error] [pid 352421:tid 352593] [client 93.152.221.13:61161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/i.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dbAAAAK8"]
[Tue Jul 21 07:58:25.744772 2026] [security2:error] [pid 352421:tid 352597] [client 65.111.13.176:13463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.13.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dawAAALM"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:58:25.763502 2026] [security2:error] [pid 352421:tid 352611] [client 185.198.240.28:32149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dener.design"] [uri "/wp-login.php"] [unique_id "al9Q0MJSWzG9jbYOtu4dIQAAAME"]
[Tue Jul 21 07:58:25.770951 2026] [security2:error] [pid 352421:tid 352469] [remote 34.101.153.152:37750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.gradiente.com"] [uri "/pi.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dbgAAtS8"]
[Tue Jul 21 07:58:25.776859 2026] [security2:error] [pid 352421:tid 352434] [remote 34.101.153.152:37750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/actuator/mappings"] [unique_id "al9Q0cJSWzG9jbYOtu4dbwAA2Qw"]
[Tue Jul 21 07:58:25.776859 2026] [security2:error] [pid 352421:tid 352478] [remote 34.101.153.152:37750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.gradiente.com"] [uri "/info.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dcQAA2Tg"]
[Tue Jul 21 07:58:25.777065 2026] [security2:error] [pid 352421:tid 352635] [client 34.101.153.152:37750] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.gradiente.com"] [uri "/info.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dcQAA2Tg"]
[Tue Jul 21 07:58:25.777506 2026] [security2:error] [pid 352421:tid 352473] [remote 34.101.153.152:37750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.gradiente.com"] [uri "/phpinfo.php"] [unique_id "al9Q0cJSWzG9jbYOtu4dcwAA2TM"]
[Tue Jul 21 07:58:25.896466 2026] [security2:error] [pid 352421:tid 352662] [client 103.29.114.44:12771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q0cJSWzG9jbYOtu4deAAAAPQ"]
[Tue Jul 21 07:58:25.896609 2026] [security2:error] [pid 352421:tid 352662] [client 103.29.114.44:12771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q0cJSWzG9jbYOtu4deAAAAPQ"]
[Tue Jul 21 07:58:25.917160 2026] [security2:error] [pid 352421:tid 352618] [client 20.151.10.161:29217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp.php"] [unique_id "al9Q0cJSWzG9jbYOtu4deQAAAMg"]
[Tue Jul 21 07:58:26.138310 2026] [security2:error] [pid 352421:tid 352620] [client 93.152.221.13:57926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/pi.php"] [unique_id "al9Q0sJSWzG9jbYOtu4dhAAAAMo"]
[Tue Jul 21 07:58:26.172016 2026] [security2:error] [pid 352421:tid 352561] [client 103.166.103.129:55762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Q0sJSWzG9jbYOtu4dhQAAAI8"]
[Tue Jul 21 07:58:26.173626 2026] [security2:error] [pid 352421:tid 352561] [client 103.166.103.129:55762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Q0sJSWzG9jbYOtu4dhQAAAI8"]
[Tue Jul 21 07:58:26.308625 2026] [security2:error] [pid 352421:tid 352615] [client 20.104.96.117:3534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/file.php"] [unique_id "al9Q0sJSWzG9jbYOtu4diQAAAMU"]
[Tue Jul 21 07:58:26.342964 2026] [security2:error] [pid 352421:tid 352638] [client 193.36.225.143:39243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Q0sJSWzG9jbYOtu4djAAAANw"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:58:26.507774 2026] [security2:error] [pid 352421:tid 352636] [client 65.21.113.253:55614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Q0sJSWzG9jbYOtu4dlgAAANo"]
[Tue Jul 21 07:58:26.672772 2026] [security2:error] [pid 352421:tid 352591] [client 20.151.10.161:28838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/abcd.php"] [unique_id "al9Q0sJSWzG9jbYOtu4dnQAAAK0"]
[Tue Jul 21 07:58:26.775750 2026] [security2:error] [pid 352421:tid 352603] [client 4.204.201.85:9615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Q0sJSWzG9jbYOtu4doAAAALk"]
[Tue Jul 21 07:58:26.811439 2026] [security2:error] [pid 352421:tid 352516] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/shopware/.env"] [unique_id "al9Q0sJSWzG9jbYOtu4doQAAq14"]
[Tue Jul 21 07:58:26.815603 2026] [security2:error] [pid 352421:tid 352510] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/flask/.env"] [unique_id "al9Q0sJSWzG9jbYOtu4dowAA-Vg"]
[Tue Jul 21 07:58:26.817068 2026] [security2:error] [pid 352421:tid 352450] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/springboot/.env"] [unique_id "al9Q0sJSWzG9jbYOtu4dpAAAthw"]
[Tue Jul 21 07:58:26.818540 2026] [security2:error] [pid 352421:tid 352465] [remote 169.58.9.109:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "getveltrixhealth.com"] [uri "/express/.env"] [unique_id "al9Q0sJSWzG9jbYOtu4dpgAAsis"]
[Tue Jul 21 07:58:26.866982 2026] [security2:error] [pid 352421:tid 352604] [client 102.206.115.33:60812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Q0sJSWzG9jbYOtu4dqwAAALo"]
[Tue Jul 21 07:58:26.867108 2026] [security2:error] [pid 352421:tid 352604] [client 102.206.115.33:60812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Q0sJSWzG9jbYOtu4dqwAAALo"]
[Tue Jul 21 07:58:27.177055 2026] [security2:error] [pid 352421:tid 352627] [client 20.104.96.117:3477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/777.php"] [unique_id "al9Q08JSWzG9jbYOtu4d0wAAANE"]
[Tue Jul 21 07:58:27.187091 2026] [security2:error] [pid 352421:tid 352558] [client 65.21.113.253:42110] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q0sJSWzG9jbYOtu4dnwAAAIw"]
[Tue Jul 21 07:58:27.226439 2026] [security2:error] [pid 352421:tid 352615] [client 204.8.98.45:39384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Q08JSWzG9jbYOtu4d1QAAAMU"]
[Tue Jul 21 07:58:27.226530 2026] [security2:error] [pid 352421:tid 352615] [client 204.8.98.45:39384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Q08JSWzG9jbYOtu4d1QAAAMU"]
[Tue Jul 21 07:58:27.227525 2026] [security2:error] [pid 352421:tid 352581] [client 37.140.223.69:52093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Q08JSWzG9jbYOtu4d1gAAAKM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:58:27.280193 2026] [security2:error] [pid 352421:tid 352555] [client 122.179.91.63:29709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Q08JSWzG9jbYOtu4d2AAAAIk"]
[Tue Jul 21 07:58:27.280992 2026] [security2:error] [pid 352421:tid 352555] [client 122.179.91.63:29709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Q08JSWzG9jbYOtu4d2AAAAIk"]
[Tue Jul 21 07:58:27.285482 2026] [security2:error] [pid 352421:tid 352640] [client 20.151.10.161:29057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/a1.php"] [unique_id "al9Q08JSWzG9jbYOtu4d2QAAAN4"]
[Tue Jul 21 07:58:27.316385 2026] [security2:error] [pid 352421:tid 352632] [client 20.220.225.223:1341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/kq1.php"] [unique_id "al9Q08JSWzG9jbYOtu4d2gAAANY"]
[Tue Jul 21 07:58:27.500874 2026] [security2:error] [pid 352421:tid 352636] [client 93.152.221.13:60915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/admin/phpinfo.php"] [unique_id "al9Q08JSWzG9jbYOtu4d4gAAANo"]
[Tue Jul 21 07:58:27.532163 2026] [security2:error] [pid 352421:tid 352665] [client 20.206.105.145:28617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.aede.com.br"] [uri "/fpwch.php"] [unique_id "al9Q08JSWzG9jbYOtu4d5AAAAPc"]
[Tue Jul 21 07:58:27.615692 2026] [security2:error] [pid 352421:tid 352586] [client 103.86.117.203:55067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q08JSWzG9jbYOtu4d6QAAAKg"]
[Tue Jul 21 07:58:27.615820 2026] [security2:error] [pid 352421:tid 352586] [client 103.86.117.203:55067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q08JSWzG9jbYOtu4d6QAAAKg"]
[Tue Jul 21 07:58:27.693720 2026] [security2:error] [pid 352421:tid 352578] [client 20.104.96.117:45470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/ssixta.php"] [unique_id "al9Q08JSWzG9jbYOtu4d6gAAAKA"]
[Tue Jul 21 07:58:27.722454 2026] [security2:error] [pid 352421:tid 352631] [client 20.151.10.161:28938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9Q08JSWzG9jbYOtu4d7gAAANU"]
[Tue Jul 21 07:58:27.888777 2026] [security2:error] [pid 352421:tid 352593] [client 93.152.221.13:60552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/pinfo.php"] [unique_id "al9Q08JSWzG9jbYOtu4d9AAAAK8"]
[Tue Jul 21 07:58:28.038885 2026] [security2:error] [pid 352421:tid 352651] [client 65.21.113.253:42136] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q08JSWzG9jbYOtu4d5QAAAOk"]
[Tue Jul 21 07:58:28.044060 2026] [security2:error] [pid 352421:tid 352553] [client 74.249.245.134:54392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/a1.php"] [unique_id "al9Q1MJSWzG9jbYOtu4d9gAAAIc"]
[Tue Jul 21 07:58:28.087612 2026] [security2:error] [pid 352421:tid 352459] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q1MJSWzG9jbYOtu4d_wAAriU"]
[Tue Jul 21 07:58:28.087741 2026] [security2:error] [pid 352421:tid 352592] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q1MJSWzG9jbYOtu4d_wAAriU"]
[Tue Jul 21 07:58:28.278270 2026] [security2:error] [pid 352421:tid 352552] [client 93.152.221.13:51750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/php_version.php"] [unique_id "al9Q1MJSWzG9jbYOtu4eAgAAAIY"]
[Tue Jul 21 07:58:28.469112 2026] [security2:error] [pid 352421:tid 352634] [client 122.164.127.47:58792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Q1MJSWzG9jbYOtu4eBgAAANg"]
[Tue Jul 21 07:58:28.470905 2026] [security2:error] [pid 352421:tid 352634] [client 122.164.127.47:58792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Q1MJSWzG9jbYOtu4eBgAAANg"]
[Tue Jul 21 07:58:28.482310 2026] [security2:error] [pid 352421:tid 352646] [client 20.104.96.117:3474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/1c.php"] [unique_id "al9Q1MJSWzG9jbYOtu4eBwAAAOQ"]
[Tue Jul 21 07:58:28.835032 2026] [security2:error] [pid 352421:tid 352651] [client 20.226.60.151:61535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/cilus.php"] [unique_id "al9Q1MJSWzG9jbYOtu4ePQAAAOk"]
[Tue Jul 21 07:58:28.842833 2026] [security2:error] [pid 352421:tid 352580] [client 20.220.225.223:1318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/zzz.php"] [unique_id "al9Q1MJSWzG9jbYOtu4eQAAAAKI"]
[Tue Jul 21 07:58:28.889765 2026] [security2:error] [pid 352421:tid 352624] [client 20.151.10.161:28688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/cgi-bin/admin.php"] [unique_id "al9Q1MJSWzG9jbYOtu4eQgAAAM4"]
[Tue Jul 21 07:58:28.981429 2026] [security2:error] [pid 352421:tid 352565] [client 184.75.221.3:38938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Q1MJSWzG9jbYOtu4eRAAAAJM"]
[Tue Jul 21 07:58:28.981495 2026] [security2:error] [pid 352421:tid 352565] [client 184.75.221.3:38938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Q1MJSWzG9jbYOtu4eRAAAAJM"]
[Tue Jul 21 07:58:29.078197 2026] [security2:error] [pid 352421:tid 352590] [client 20.104.96.117:3501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/test2.php"] [unique_id "al9Q1cJSWzG9jbYOtu4eSwAAAKw"]
[Tue Jul 21 07:58:29.227644 2026] [security2:error] [pid 352421:tid 352617] [client 20.226.60.151:56781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/fffm.php"] [unique_id "al9Q1cJSWzG9jbYOtu4eWgAAAMc"]
[Tue Jul 21 07:58:29.235546 2026] [security2:error] [pid 352421:tid 352613] [client 4.204.201.85:62813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/ms-edit.php"] [unique_id "al9Q1cJSWzG9jbYOtu4eWwAAAMM"]
[Tue Jul 21 07:58:29.254706 2026] [security2:error] [pid 352421:tid 352644] [client 93.152.221.13:56757] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pedido-online.net"] [uri "/.env"] [unique_id "al9Q1cJSWzG9jbYOtu4eXAAAAOI"]
[Tue Jul 21 07:58:29.350319 2026] [security2:error] [pid 352421:tid 352450] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q1cJSWzG9jbYOtu4eXQAAxRw"]
[Tue Jul 21 07:58:29.350579 2026] [security2:error] [pid 352421:tid 352615] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q1cJSWzG9jbYOtu4eXQAAxRw"]
[Tue Jul 21 07:58:29.387498 2026] [security2:error] [pid 352421:tid 352639] [client 65.21.113.253:55614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Q1cJSWzG9jbYOtu4eXwAAAN0"]
[Tue Jul 21 07:58:29.452497 2026] [security2:error] [pid 352421:tid 352591] [client 20.104.96.117:45465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/buy.php"] [unique_id "al9Q1cJSWzG9jbYOtu4eYQAAAK0"]
[Tue Jul 21 07:58:29.685574 2026] [security2:error] [pid 352421:tid 352652] [client 117.210.135.0:56330] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q1cJSWzG9jbYOtu4eagAAAOo"]
[Tue Jul 21 07:58:29.685710 2026] [security2:error] [pid 352421:tid 352652] [client 117.210.135.0:56330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q1cJSWzG9jbYOtu4eagAAAOo"]
[Tue Jul 21 07:58:29.727287 2026] [security2:error] [pid 352421:tid 352620] [client 20.151.10.161:29188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/gettest.php"] [unique_id "al9Q1cJSWzG9jbYOtu4ebwAAAMo"]
[Tue Jul 21 07:58:29.735168 2026] [security2:error] [pid 352421:tid 352543] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.git-credentials"] [unique_id "al9Q1cJSWzG9jbYOtu4ecAAA-Hk"]
[Tue Jul 21 07:58:29.735168 2026] [security2:error] [pid 352421:tid 352534] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.git/HEAD"] [unique_id "al9Q1cJSWzG9jbYOtu4ecQAA-HA"]
[Tue Jul 21 07:58:29.735386 2026] [security2:error] [pid 352421:tid 352666] [client 34.101.153.152:37754] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/.git/HEAD"] [unique_id "al9Q1cJSWzG9jbYOtu4ecQAA-HA"]
[Tue Jul 21 07:58:29.804832 2026] [security2:error] [pid 352421:tid 352661] [client 20.220.225.223:1807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wicked.php"] [unique_id "al9Q1cJSWzG9jbYOtu4edQAAAPM"]
[Tue Jul 21 07:58:29.814108 2026] [security2:error] [pid 352421:tid 352572] [client 20.104.96.117:45171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/ssend.php"] [unique_id "al9Q1cJSWzG9jbYOtu4edgAAAJo"]
[Tue Jul 21 07:58:29.887365 2026] [core:error] [pid 352421:tid 352542] [remote 40.77.167.77:18329] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:29.887384 2026] [core:error] [pid 352421:tid 352542] [remote 40.77.167.77:18329] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:30.002561 2026] [security2:error] [pid 352421:tid 352593] [client 65.21.113.253:42136] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q1cJSWzG9jbYOtu4eZgAAAK8"]
[Tue Jul 21 07:58:30.011206 2026] [core:error] [pid 352421:tid 352428] [remote 40.77.167.77:18329] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:30.011236 2026] [core:error] [pid 352421:tid 352428] [remote 40.77.167.77:18329] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:30.014393 2026] [security2:error] [pid 352421:tid 352429] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.aws/credentials"] [unique_id "al9Q1sJSWzG9jbYOtu4eggAApgc"]
[Tue Jul 21 07:58:30.070561 2026] [security2:error] [pid 352421:tid 352644] [client 74.249.245.134:54391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/w.php"] [unique_id "al9Q1sJSWzG9jbYOtu4elQAAAOI"]
[Tue Jul 21 07:58:30.138009 2026] [security2:error] [pid 352421:tid 352525] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env"] [unique_id "al9Q1sJSWzG9jbYOtu4elwAApmc"]
[Tue Jul 21 07:58:30.140156 2026] [core:error] [pid 352421:tid 352431] [remote 40.77.167.77:18329] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:30.140176 2026] [core:error] [pid 352421:tid 352431] [remote 40.77.167.77:18329] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:30.254744 2026] [security2:error] [pid 352421:tid 352605] [client 20.104.96.117:3492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/item.php"] [unique_id "al9Q1sJSWzG9jbYOtu4eoQAAALs"]
[Tue Jul 21 07:58:30.363008 2026] [security2:error] [pid 352421:tid 352520] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/.env.example"] [unique_id "al9Q1sJSWzG9jbYOtu4epAAAuWI"]
[Tue Jul 21 07:58:30.414419 2026] [security2:error] [pid 352421:tid 352579] [client 204.8.98.45:55196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Q1sJSWzG9jbYOtu4eqgAAAKE"]
[Tue Jul 21 07:58:30.414531 2026] [security2:error] [pid 352421:tid 352579] [client 204.8.98.45:55196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Q1sJSWzG9jbYOtu4eqgAAAKE"]
[Tue Jul 21 07:58:30.429214 2026] [security2:error] [pid 352421:tid 352531] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.backup"] [unique_id "al9Q1sJSWzG9jbYOtu4eqwAAuW0"]
[Tue Jul 21 07:58:30.499023 2026] [security2:error] [pid 352421:tid 352598] [client 20.226.60.151:50624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/dfre.php"] [unique_id "al9Q1sJSWzG9jbYOtu4esAAAALQ"]
[Tue Jul 21 07:58:30.526445 2026] [security2:error] [pid 352421:tid 352626] [client 41.68.90.219:49869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q1sJSWzG9jbYOtu4etAAAANA"]
[Tue Jul 21 07:58:30.527826 2026] [security2:error] [pid 352421:tid 352626] [client 41.68.90.219:49869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q1sJSWzG9jbYOtu4etAAAANA"]
[Tue Jul 21 07:58:30.554410 2026] [security2:error] [pid 352421:tid 352533] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "gradiente.com"] [uri "/graphql"] [unique_id "al9Q1sJSWzG9jbYOtu4etQAAuW8"]
[Tue Jul 21 07:58:30.608949 2026] [security2:error] [pid 352421:tid 352612] [client 20.104.96.117:3581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/ss.php"] [unique_id "al9Q1sJSWzG9jbYOtu4etgAAAMI"]
[Tue Jul 21 07:58:30.663468 2026] [security2:error] [pid 352421:tid 352591] [client 93.152.221.13:56757] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "pedido-online.net"] [uri "/.env.backup"] [unique_id "al9Q1sJSWzG9jbYOtu4etwAAAK0"]
[Tue Jul 21 07:58:30.670461 2026] [security2:error] [pid 352421:tid 352524] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.bak"] [unique_id "al9Q1sJSWzG9jbYOtu4euAAAkmY"]
[Tue Jul 21 07:58:30.795106 2026] [security2:error] [pid 352421:tid 352422] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/api/.env"] [unique_id "al9Q1sJSWzG9jbYOtu4evAAA_QA"]
[Tue Jul 21 07:58:30.799206 2026] [security2:error] [pid 352421:tid 352538] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.old"] [unique_id "al9Q1sJSWzG9jbYOtu4evQAA-XQ"]
[Tue Jul 21 07:58:30.859523 2026] [security2:error] [pid 352421:tid 352642] [client 93.152.221.13:56757] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "pedido-online.net"] [uri "/config/.env"] [unique_id "al9Q1sJSWzG9jbYOtu4ewAAAAOA"]
[Tue Jul 21 07:58:30.908955 2026] [security2:error] [pid 352421:tid 352606] [client 20.104.96.117:3489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/hypo.php"] [unique_id "al9Q1sJSWzG9jbYOtu4ewwAAALw"]
[Tue Jul 21 07:58:30.930572 2026] [security2:error] [pid 352421:tid 352453] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Q1sJSWzG9jbYOtu4exAAA2B8"]
[Tue Jul 21 07:58:30.930764 2026] [security2:error] [pid 352421:tid 352634] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Q1sJSWzG9jbYOtu4exAAA2B8"]
[Tue Jul 21 07:58:30.976916 2026] [security2:error] [pid 352421:tid 352600] [client 178.153.91.96:49994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q1sJSWzG9jbYOtu4exgAAALY"]
[Tue Jul 21 07:58:30.977057 2026] [security2:error] [pid 352421:tid 352600] [client 178.153.91.96:49994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q1sJSWzG9jbYOtu4exgAAALY"]
[Tue Jul 21 07:58:30.988907 2026] [security2:error] [pid 352421:tid 352452] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/config/.env"] [unique_id "al9Q1sJSWzG9jbYOtu4eyAAA5x4"]
[Tue Jul 21 07:58:30.989649 2026] [security2:error] [pid 352421:tid 352458] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/backend/.env"] [unique_id "al9Q1sJSWzG9jbYOtu4eygAA5yQ"]
[Tue Jul 21 07:58:31.043833 2026] [security2:error] [pid 352421:tid 352657] [client 136.144.33.109:57569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Q18JSWzG9jbYOtu4e1AAAAO8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:58:31.144249 2026] [security2:error] [pid 352421:tid 352444] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "gradiente.com"] [uri "/api/graphql"] [unique_id "al9Q18JSWzG9jbYOtu4e1wAA5xY"]
[Tue Jul 21 07:58:31.189620 2026] [security2:error] [pid 352421:tid 352629] [client 198.54.128.138:41412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Q18JSWzG9jbYOtu4e3QAAANM"]
[Tue Jul 21 07:58:31.189740 2026] [security2:error] [pid 352421:tid 352629] [client 198.54.128.138:41412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Q18JSWzG9jbYOtu4e3QAAANM"]
[Tue Jul 21 07:58:31.372647 2026] [security2:error] [pid 352421:tid 352487] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/.htpasswd"] [unique_id "al9Q18JSWzG9jbYOtu4e-QAA5UE"]
[Tue Jul 21 07:58:31.476656 2026] [security2:error] [pid 352421:tid 352574] [client 20.104.96.117:45123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/users.php"] [unique_id "al9Q18JSWzG9jbYOtu4e_QAAAJw"]
[Tue Jul 21 07:58:31.487054 2026] [security2:error] [pid 352421:tid 352488] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.boto"] [unique_id "al9Q18JSWzG9jbYOtu4e_wAA8EI"]
[Tue Jul 21 07:58:31.487182 2026] [security2:error] [pid 352421:tid 352658] [client 34.101.153.152:37754] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/.boto"] [unique_id "al9Q18JSWzG9jbYOtu4e_wAA8EI"]
[Tue Jul 21 07:58:31.498226 2026] [security2:error] [pid 352421:tid 352475] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/terraform.tfstate"] [unique_id "al9Q18JSWzG9jbYOtu4fAgAA8DU"]
[Tue Jul 21 07:58:31.518255 2026] [security2:error] [pid 352421:tid 352490] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "gradiente.com"] [uri "/v1/graphql"] [unique_id "al9Q18JSWzG9jbYOtu4fBgAA8EQ"]
[Tue Jul 21 07:58:31.644743 2026] [security2:error] [pid 352421:tid 352651] [client 38.100.221.102:18738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q18JSWzG9jbYOtu4fFAAAAOk"]
[Tue Jul 21 07:58:31.644846 2026] [security2:error] [pid 352421:tid 352651] [client 38.100.221.102:18738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q18JSWzG9jbYOtu4fFAAAAOk"]
[Tue Jul 21 07:58:31.773179 2026] [security2:error] [pid 352421:tid 352450] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.ssh/id_rsa"] [unique_id "al9Q18JSWzG9jbYOtu4fGgAAtxw"]
[Tue Jul 21 07:58:31.823413 2026] [security2:error] [pid 352421:tid 352632] [client 20.104.96.117:3494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/177.php"] [unique_id "al9Q18JSWzG9jbYOtu4fGwAAANY"]
[Tue Jul 21 07:58:31.825406 2026] [security2:error] [pid 352421:tid 352465] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.ssh/id_dsa"] [unique_id "al9Q18JSWzG9jbYOtu4fHAAAwis"]
[Tue Jul 21 07:58:31.866836 2026] [security2:error] [pid 352421:tid 352539] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/.ssh/authorized_keys"] [unique_id "al9Q18JSWzG9jbYOtu4fIwAAhnU"]
[Tue Jul 21 07:58:31.934970 2026] [security2:error] [pid 352421:tid 352584] [client 193.36.225.142:32491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Q18JSWzG9jbYOtu4fGQAAAKY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:58:31.975978 2026] [security2:error] [pid 352421:tid 352536] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Q18JSWzG9jbYOtu4fLgABBHI"]
[Tue Jul 21 07:58:31.976184 2026] [security2:error] [pid 352421:tid 352678] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Q18JSWzG9jbYOtu4fLgABBHI"]
[Tue Jul 21 07:58:32.018263 2026] [security2:error] [pid 352421:tid 352542] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/id_rsa"] [unique_id "al9Q2MJSWzG9jbYOtu4fLwAAhng"]
[Tue Jul 21 07:58:32.084509 2026] [security2:error] [pid 352421:tid 352598] [client 109.60.28.94:45647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fMAAAALQ"]
[Tue Jul 21 07:58:32.084607 2026] [security2:error] [pid 352421:tid 352598] [client 109.60.28.94:45647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fMAAAALQ"]
[Tue Jul 21 07:58:32.093042 2026] [security2:error] [pid 352421:tid 352621] [client 59.93.4.33:49173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fMwAAAMs"]
[Tue Jul 21 07:58:32.093144 2026] [security2:error] [pid 352421:tid 352621] [client 59.93.4.33:49173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fMwAAAMs"]
[Tue Jul 21 07:58:32.101697 2026] [security2:error] [pid 352421:tid 352522] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/id_dsa"] [unique_id "al9Q2MJSWzG9jbYOtu4fNAAAq2Q"]
[Tue Jul 21 07:58:32.180219 2026] [security2:error] [pid 352421:tid 352436] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/key.pem"] [unique_id "al9Q2MJSWzG9jbYOtu4fQAAAqw4"]
[Tue Jul 21 07:58:32.222028 2026] [security2:error] [pid 352421:tid 352547] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/privatekey.key"] [unique_id "al9Q2MJSWzG9jbYOtu4fQgAAq30"]
[Tue Jul 21 07:58:32.253662 2026] [security2:error] [pid 352421:tid 352576] [client 20.104.96.117:3562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/config.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fRgAAAJ4"]
[Tue Jul 21 07:58:32.279604 2026] [security2:error] [pid 352421:tid 352657] [client 117.247.80.59:25714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fSgAAAO8"]
[Tue Jul 21 07:58:32.279790 2026] [security2:error] [pid 352421:tid 352657] [client 117.247.80.59:25714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fSgAAAO8"]
[Tue Jul 21 07:58:32.355931 2026] [security2:error] [pid 352421:tid 352562] [client 20.151.10.161:28702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/simple.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fTwAAAJA"]
[Tue Jul 21 07:58:32.500241 2026] [security2:error] [pid 352421:tid 352640] [client 65.21.113.253:54176] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q18JSWzG9jbYOtu4fLAAAAN4"]
[Tue Jul 21 07:58:32.504643 2026] [security2:error] [pid 352421:tid 352459] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9Q2MJSWzG9jbYOtu4fYgAAqyU"]
[Tue Jul 21 07:58:32.555318 2026] [security2:error] [pid 352421:tid 352427] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fYwAAwgU"]
[Tue Jul 21 07:58:32.555533 2026] [security2:error] [pid 352421:tid 352612] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fYwAAwgU"]
[Tue Jul 21 07:58:32.585402 2026] [security2:error] [pid 352421:tid 352520] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fZgAAjmI"]
[Tue Jul 21 07:58:32.585571 2026] [security2:error] [pid 352421:tid 352560] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fZgAAjmI"]
[Tue Jul 21 07:58:32.611542 2026] [security2:error] [pid 352421:tid 352573] [client 20.220.225.223:1336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/edit.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fZwAAAJs"]
[Tue Jul 21 07:58:32.613547 2026] [security2:error] [pid 352421:tid 352630] [client 182.8.255.181:21187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Q2MJSWzG9jbYOtu4faQAAANQ"]
[Tue Jul 21 07:58:32.613676 2026] [security2:error] [pid 352421:tid 352630] [client 182.8.255.181:21187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Q2MJSWzG9jbYOtu4faQAAANQ"]
[Tue Jul 21 07:58:32.622213 2026] [security2:error] [pid 352421:tid 352627] [client 212.32.69.197:30481] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sigmas.app.br"] [uri "/.env"] [unique_id "al9Q2MJSWzG9jbYOtu4fagAAANE"]
[Tue Jul 21 07:58:32.755638 2026] [security2:error] [pid 352421:tid 352671] [client 20.104.96.117:3512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/gettest.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fcQAAAP0"]
[Tue Jul 21 07:58:32.855020 2026] [security2:error] [pid 352421:tid 352626] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fcgAA0Hc"]
[Tue Jul 21 07:58:32.870574 2026] [security2:error] [pid 352421:tid 352583] [client 20.226.60.151:53906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/gptsh.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fdwAAAKU"]
[Tue Jul 21 07:58:32.899294 2026] [security2:error] [pid 352421:tid 352524] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.hermes/.env"] [unique_id "al9Q2MJSWzG9jbYOtu4fegAAzGY"]
[Tue Jul 21 07:58:32.951840 2026] [security2:error] [pid 352421:tid 352601] [client 74.249.245.134:17415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/wp-good.php"] [unique_id "al9Q2MJSWzG9jbYOtu4fgwAAALc"]
[Tue Jul 21 07:58:33.017052 2026] [security2:error] [pid 352421:tid 352532] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "al9Q2cJSWzG9jbYOtu4fhgAAzG4"]
[Tue Jul 21 07:58:33.159763 2026] [security2:error] [pid 352421:tid 352477] [remote 182.77.62.24:51214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9Q2cJSWzG9jbYOtu4fkQAA-Tc"]
[Tue Jul 21 07:58:33.271010 2026] [security2:error] [pid 352421:tid 352672] [client 20.104.96.117:45440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/min.php"] [unique_id "al9Q2cJSWzG9jbYOtu4flQAAAP4"]
[Tue Jul 21 07:58:33.453674 2026] [security2:error] [pid 352421:tid 352546] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "gradiente.com"] [uri "/wp-config.php.old"] [unique_id "al9Q2cJSWzG9jbYOtu4fpQAAzHw"]
[Tue Jul 21 07:58:33.454179 2026] [security2:error] [pid 352421:tid 352466] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "gradiente.com"] [uri "/wp-config.php.bak"] [unique_id "al9Q2cJSWzG9jbYOtu4fpgAAzCw"]
[Tue Jul 21 07:58:33.477564 2026] [security2:error] [pid 352421:tid 352486] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/laravel/.env"] [unique_id "al9Q2cJSWzG9jbYOtu4fqAAAzEA"]
[Tue Jul 21 07:58:33.496787 2026] [security2:error] [pid 352421:tid 352469] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/config/.env.php"] [unique_id "al9Q2cJSWzG9jbYOtu4frQAAzC8"]
[Tue Jul 21 07:58:33.548409 2026] [security2:error] [pid 352421:tid 352457] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/.env.php.bak"] [unique_id "al9Q2cJSWzG9jbYOtu4fsAAA2SM"]
[Tue Jul 21 07:58:33.548696 2026] [security2:error] [pid 352421:tid 352567] [client 65.21.113.253:55614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Q2cJSWzG9jbYOtu4frwAAAJU"]
[Tue Jul 21 07:58:33.648504 2026] [security2:error] [pid 352421:tid 352472] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/core/.env"] [unique_id "al9Q2cJSWzG9jbYOtu4ftAAA9jI"]
[Tue Jul 21 07:58:33.700038 2026] [security2:error] [pid 352421:tid 352478] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Q2cJSWzG9jbYOtu4fuAAAwDg"]
[Tue Jul 21 07:58:33.700196 2026] [security2:error] [pid 352421:tid 352610] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Q2cJSWzG9jbYOtu4fuAAAwDg"]
[Tue Jul 21 07:58:33.720636 2026] [security2:error] [pid 352421:tid 352658] [client 20.104.96.117:3466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/dvjul.php"] [unique_id "al9Q2cJSWzG9jbYOtu4fuQAAAPA"]
[Tue Jul 21 07:58:33.841120 2026] [security2:error] [pid 352421:tid 352494] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/config.php.bak"] [unique_id "al9Q2cJSWzG9jbYOtu4fwwAAxEg"]
[Tue Jul 21 07:58:33.859776 2026] [security2:error] [pid 352421:tid 352470] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/configuration.php.bak"] [unique_id "al9Q2cJSWzG9jbYOtu4fygAAxDA"]
[Tue Jul 21 07:58:33.860327 2026] [security2:error] [pid 352421:tid 352441] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/.env.swp"] [unique_id "al9Q2cJSWzG9jbYOtu4fyQAAxBM"]
[Tue Jul 21 07:58:33.915998 2026] [security2:error] [pid 352421:tid 352464] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/config.js"] [unique_id "al9Q2cJSWzG9jbYOtu4f0QAAxCo"]
[Tue Jul 21 07:58:33.970551 2026] [security2:error] [pid 352421:tid 352468] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/public/.env"] [unique_id "al9Q2cJSWzG9jbYOtu4f1QAAxC4"]
[Tue Jul 21 07:58:33.971241 2026] [security2:error] [pid 352421:tid 352440] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gradiente.com"] [uri "/web/.env"] [unique_id "al9Q2cJSWzG9jbYOtu4f1AAAxBI"]
[Tue Jul 21 07:58:34.015744 2026] [security2:error] [pid 352421:tid 352630] [client 20.104.96.117:3526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/biufile.php"] [unique_id "al9Q2sJSWzG9jbYOtu4f1gAAANQ"]
[Tue Jul 21 07:58:34.118160 2026] [security2:error] [pid 352421:tid 352566] [client 198.54.128.138:58590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Q2sJSWzG9jbYOtu4f2QAAAJQ"]
[Tue Jul 21 07:58:34.118255 2026] [security2:error] [pid 352421:tid 352566] [client 198.54.128.138:58590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Q2sJSWzG9jbYOtu4f2QAAAJQ"]
[Tue Jul 21 07:58:34.124319 2026] [security2:error] [pid 352421:tid 352571] [client 20.151.10.161:28826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/xxx.php"] [unique_id "al9Q2sJSWzG9jbYOtu4f2gAAAJk"]
[Tue Jul 21 07:58:34.170488 2026] [security2:error] [pid 352421:tid 352651] [client 65.21.113.253:54176] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q2cJSWzG9jbYOtu4fuwAAAOk"]
[Tue Jul 21 07:58:34.317498 2026] [security2:error] [pid 352421:tid 352498] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/api/config"] [unique_id "al9Q2sJSWzG9jbYOtu4f5QAA2Uw"]
[Tue Jul 21 07:58:34.339428 2026] [security2:error] [pid 352421:tid 352576] [client 20.220.225.223:1851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/kua.php"] [unique_id "al9Q2sJSWzG9jbYOtu4f5wAAAJ4"]
[Tue Jul 21 07:58:34.412378 2026] [security2:error] [pid 352421:tid 352501] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/env.js"] [unique_id "al9Q2sJSWzG9jbYOtu4f8AAAsk8"]
[Tue Jul 21 07:58:34.414737 2026] [security2:error] [pid 352421:tid 352558] [client 20.104.96.117:45441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/av.php"] [unique_id "al9Q2sJSWzG9jbYOtu4f9AAAAIw"]
[Tue Jul 21 07:58:34.474047 2026] [core:error] [pid 352421:tid 352536] [remote 52.167.144.184:62096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:34.474066 2026] [core:error] [pid 352421:tid 352536] [remote 52.167.144.184:62096] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:58:34.480171 2026] [security2:error] [pid 352421:tid 352603] [client 106.215.181.8:32883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q2sJSWzG9jbYOtu4gAwAAALk"]
[Tue Jul 21 07:58:34.480313 2026] [security2:error] [pid 352421:tid 352603] [client 106.215.181.8:32883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q2sJSWzG9jbYOtu4gAwAAALk"]
[Tue Jul 21 07:58:34.640778 2026] [security2:error] [pid 352421:tid 352599] [client 87.116.180.198:14078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q2sJSWzG9jbYOtu4gEAAAALU"]
[Tue Jul 21 07:58:34.644855 2026] [security2:error] [pid 352421:tid 352599] [client 87.116.180.198:14078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q2sJSWzG9jbYOtu4gEAAAALU"]
[Tue Jul 21 07:58:34.672106 2026] [security2:error] [pid 352421:tid 352588] [client 193.36.225.143:24955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Q2sJSWzG9jbYOtu4gEQAAAKo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:58:34.718569 2026] [security2:error] [pid 352421:tid 352669] [client 223.236.153.128:1895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Q2sJSWzG9jbYOtu4gEgAAAPs"]
[Tue Jul 21 07:58:34.723345 2026] [security2:error] [pid 352421:tid 352669] [client 223.236.153.128:1895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Q2sJSWzG9jbYOtu4gEgAAAPs"]
[Tue Jul 21 07:58:34.837359 2026] [security2:error] [pid 352421:tid 352621] [client 20.104.96.117:3528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/coffexium.php"] [unique_id "al9Q2sJSWzG9jbYOtu4gFgAAAMs"]
[Tue Jul 21 07:58:35.084593 2026] [security2:error] [pid 352421:tid 352459] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/swagger.json"] [unique_id "al9Q28JSWzG9jbYOtu4gLwAA3yU"]
[Tue Jul 21 07:58:35.084751 2026] [security2:error] [pid 352421:tid 352641] [client 34.101.153.152:37754] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/swagger.json"] [unique_id "al9Q28JSWzG9jbYOtu4gLwAA3yU"]
[Tue Jul 21 07:58:35.199226 2026] [security2:error] [pid 352421:tid 352554] [client 20.104.96.117:45133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/core.php"] [unique_id "al9Q28JSWzG9jbYOtu4gOAAAAIg"]
[Tue Jul 21 07:58:35.228339 2026] [security2:error] [pid 352421:tid 352632] [client 20.151.10.161:28950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/hypo.php"] [unique_id "al9Q28JSWzG9jbYOtu4gPQAAANY"]
[Tue Jul 21 07:58:35.563984 2026] [security2:error] [pid 352421:tid 352639] [client 20.104.96.117:45141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/als.php"] [unique_id "al9Q28JSWzG9jbYOtu4gVAAAAN0"]
[Tue Jul 21 07:58:35.571198 2026] [security2:error] [pid 352421:tid 352592] [client 78.46.215.1:41558] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9Q28JSWzG9jbYOtu4gVQAAAK4"], referer: https://artetoner.com.br
[Tue Jul 21 07:58:35.723382 2026] [security2:error] [pid 352421:tid 352524] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/api/graphql"] [unique_id "al9Q28JSWzG9jbYOtu4gXgAA4GY"]
[Tue Jul 21 07:58:35.723535 2026] [security2:error] [pid 352421:tid 352642] [client 34.101.153.152:37754] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gradiente.com"] [uri "/api/graphql"] [unique_id "al9Q28JSWzG9jbYOtu4gXgAA4GY"]
[Tue Jul 21 07:58:35.922833 2026] [security2:error] [pid 352421:tid 352576] [client 20.226.60.151:61505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/rithin.php"] [unique_id "al9Q28JSWzG9jbYOtu4gcQAAAJ4"]
[Tue Jul 21 07:58:35.923822 2026] [security2:error] [pid 352421:tid 352519] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/phpinfo.php"] [unique_id "al9Q28JSWzG9jbYOtu4gcgAAhmE"]
[Tue Jul 21 07:58:35.944329 2026] [security2:error] [pid 352421:tid 352535] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/pi.php"] [unique_id "al9Q28JSWzG9jbYOtu4gcwAAjXE"]
[Tue Jul 21 07:58:35.960858 2026] [security2:error] [pid 352421:tid 352649] [client 20.151.10.161:28962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/chosen.php"] [unique_id "al9Q28JSWzG9jbYOtu4gdgAAAOc"]
[Tue Jul 21 07:58:35.962446 2026] [security2:error] [pid 352421:tid 352460] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/i.php"] [unique_id "al9Q28JSWzG9jbYOtu4gdwAAlSY"]
[Tue Jul 21 07:58:35.975357 2026] [security2:error] [pid 352421:tid 352477] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/test.php"] [unique_id "al9Q28JSWzG9jbYOtu4gegAAzDc"]
[Tue Jul 21 07:58:36.007854 2026] [security2:error] [pid 352421:tid 352491] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/info.php"] [unique_id "al9Q3MJSWzG9jbYOtu4gfwAAzEU"]
[Tue Jul 21 07:58:36.107273 2026] [security2:error] [pid 352421:tid 352592] [client 20.104.96.117:3570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/simple.php"] [unique_id "al9Q3MJSWzG9jbYOtu4ghQAAAK4"]
[Tue Jul 21 07:58:36.148590 2026] [security2:error] [pid 352421:tid 352607] [client 37.140.223.69:41695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Q2sJSWzG9jbYOtu4gJwAAAL0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:58:36.186221 2026] [security2:error] [pid 352421:tid 352670] [client 122.162.144.145:28179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Q3MJSWzG9jbYOtu4ghwAAAPw"]
[Tue Jul 21 07:58:36.188718 2026] [security2:error] [pid 352421:tid 352670] [client 122.162.144.145:28179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Q3MJSWzG9jbYOtu4ghwAAAPw"]
[Tue Jul 21 07:58:36.194866 2026] [security2:error] [pid 352421:tid 352609] [client 20.220.225.223:1338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/ez.php"] [unique_id "al9Q3MJSWzG9jbYOtu4giQAAAL8"]
[Tue Jul 21 07:58:36.369485 2026] [security2:error] [pid 352421:tid 352659] [client 202.143.127.214:58669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q3MJSWzG9jbYOtu4gkQAAAPE"]
[Tue Jul 21 07:58:36.369632 2026] [security2:error] [pid 352421:tid 352659] [client 202.143.127.214:58669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q3MJSWzG9jbYOtu4gkQAAAPE"]
[Tue Jul 21 07:58:36.412781 2026] [security2:error] [pid 352421:tid 352667] [client 204.8.98.45:43652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Q3MJSWzG9jbYOtu4gkgAAAPk"]
[Tue Jul 21 07:58:36.412877 2026] [security2:error] [pid 352421:tid 352667] [client 204.8.98.45:43652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Q3MJSWzG9jbYOtu4gkgAAAPk"]
[Tue Jul 21 07:58:36.489619 2026] [security2:error] [pid 352421:tid 352552] [client 65.21.113.253:55614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Q3MJSWzG9jbYOtu4glgAAAIY"]
[Tue Jul 21 07:58:36.505770 2026] [security2:error] [pid 352421:tid 352602] [client 103.29.114.44:10592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q3MJSWzG9jbYOtu4glwAAALg"]
[Tue Jul 21 07:58:36.505910 2026] [security2:error] [pid 352421:tid 352602] [client 103.29.114.44:10592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q3MJSWzG9jbYOtu4glwAAALg"]
[Tue Jul 21 07:58:36.680069 2026] [security2:error] [pid 352421:tid 352655] [client 65.21.113.253:54182] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q3MJSWzG9jbYOtu4giAAAAO0"]
[Tue Jul 21 07:58:36.689573 2026] [security2:error] [pid 352421:tid 352634] [client 20.104.96.117:45466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/init.php"] [unique_id "al9Q3MJSWzG9jbYOtu4gmwAAANg"]
[Tue Jul 21 07:58:36.701267 2026] [security2:error] [pid 352421:tid 352639] [client 45.3.45.195:29439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9Q3MJSWzG9jbYOtu4gmAAAAN0"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:58:36.711511 2026] [security2:error] [pid 352421:tid 352571] [client 20.151.10.161:29065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/als.php"] [unique_id "al9Q3MJSWzG9jbYOtu4gnAAAAJk"]
[Tue Jul 21 07:58:36.748617 2026] [security2:error] [pid 352421:tid 352653] [client 20.226.60.151:56774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-happy.php"] [unique_id "al9Q3MJSWzG9jbYOtu4gnQAAAOs"]
[Tue Jul 21 07:58:36.780915 2026] [security2:error] [pid 352421:tid 352557] [client 103.78.200.11:58501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q3MJSWzG9jbYOtu4gowAAAIs"]
[Tue Jul 21 07:58:36.782593 2026] [security2:error] [pid 352421:tid 352557] [client 103.78.200.11:58501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q3MJSWzG9jbYOtu4gowAAAIs"]
[Tue Jul 21 07:58:37.071693 2026] [security2:error] [pid 352421:tid 352662] [client 103.166.103.129:63093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Q3cJSWzG9jbYOtu4grwAAAPQ"]
[Tue Jul 21 07:58:37.071913 2026] [security2:error] [pid 352421:tid 352662] [client 103.166.103.129:63093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Q3cJSWzG9jbYOtu4grwAAAPQ"]
[Tue Jul 21 07:58:37.310139 2026] [security2:error] [pid 352421:tid 352606] [client 20.104.96.117:45475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/fpwch.php"] [unique_id "al9Q3cJSWzG9jbYOtu4gtgAAALw"]
[Tue Jul 21 07:58:37.322850 2026] [security2:error] [pid 352421:tid 352457] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/_profiler/open"] [unique_id "al9Q3cJSWzG9jbYOtu4gtwAAzyM"]
[Tue Jul 21 07:58:37.349881 2026] [security2:error] [pid 352421:tid 352478] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "gradiente.com"] [uri "/_ignition/health-check"] [unique_id "al9Q3cJSWzG9jbYOtu4gugAAyjg"]
[Tue Jul 21 07:58:37.352934 2026] [security2:error] [pid 352421:tid 352601] [client 102.206.115.33:57619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Q3cJSWzG9jbYOtu4gvAAAALc"]
[Tue Jul 21 07:58:37.353102 2026] [security2:error] [pid 352421:tid 352601] [client 102.206.115.33:57619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Q3cJSWzG9jbYOtu4gvAAAALc"]
[Tue Jul 21 07:58:37.361634 2026] [security2:error] [pid 352421:tid 352470] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/app_dev.php"] [unique_id "al9Q3cJSWzG9jbYOtu4gwwAAyjA"]
[Tue Jul 21 07:58:37.362456 2026] [security2:error] [pid 352421:tid 352470] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/app_dev.php/_profiler"] [unique_id "al9Q3cJSWzG9jbYOtu4gxAAAyjA"]
[Tue Jul 21 07:58:37.406100 2026] [security2:error] [pid 352421:tid 352666] [client 20.151.10.161:29194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/pol.php"] [unique_id "al9Q3cJSWzG9jbYOtu4gzwAAAPg"]
[Tue Jul 21 07:58:37.406223 2026] [security2:error] [pid 352421:tid 352434] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gradiente.com"] [uri "/server-info"] [unique_id "al9Q3cJSWzG9jbYOtu4g0QAAygw"]
[Tue Jul 21 07:58:37.407660 2026] [security2:error] [pid 352421:tid 352623] [client 157.245.148.238:57268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.148.245.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lafirmo.com"] [uri "/xmlrpc.php"] [unique_id "al9Q3cJSWzG9jbYOtu4gtAAAAM0"]
[Tue Jul 21 07:58:37.407807 2026] [security2:error] [pid 352421:tid 352623] [client 157.245.148.238:57268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lafirmo.com"] [uri "/xmlrpc.php"] [unique_id "al9Q3cJSWzG9jbYOtu4gtAAAAM0"]
[Tue Jul 21 07:58:37.473160 2026] [access_compat:error] [pid 352421:tid 352437] [remote 34.101.153.152:37754] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Tue Jul 21 07:58:37.516307 2026] [security2:error] [pid 352421:tid 352608] [client 20.220.225.223:1286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/fz.php"] [unique_id "al9Q3cJSWzG9jbYOtu4g1gAAAL4"]
[Tue Jul 21 07:58:37.517026 2026] [security2:error] [pid 352421:tid 352559] [client 4.204.201.85:9567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Q3cJSWzG9jbYOtu4g1wAAAI0"]
[Tue Jul 21 07:58:37.605196 2026] [security2:error] [pid 352421:tid 352647] [client 65.21.113.253:54196] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q3cJSWzG9jbYOtu4gsgAAAOU"]
[Tue Jul 21 07:58:37.630133 2026] [security2:error] [pid 352421:tid 352574] [client 74.249.245.134:54347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/.info.php"] [unique_id "al9Q3cJSWzG9jbYOtu4g3QAAAJw"]
[Tue Jul 21 07:58:37.767894 2026] [security2:error] [pid 352421:tid 352641] [client 20.104.96.117:45167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/domvf.php"] [unique_id "al9Q3cJSWzG9jbYOtu4g3wAAAN8"]
[Tue Jul 21 07:58:37.958211 2026] [security2:error] [pid 352421:tid 352558] [client 122.179.91.63:28472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Q3cJSWzG9jbYOtu4g6AAAAIw"]
[Tue Jul 21 07:58:37.958342 2026] [security2:error] [pid 352421:tid 352558] [client 122.179.91.63:28472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Q3cJSWzG9jbYOtu4g6AAAAIw"]
[Tue Jul 21 07:58:38.091939 2026] [security2:error] [pid 352421:tid 352581] [client 103.86.117.203:55608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q3sJSWzG9jbYOtu4g7gAAAKM"]
[Tue Jul 21 07:58:38.092092 2026] [security2:error] [pid 352421:tid 352581] [client 103.86.117.203:55608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q3sJSWzG9jbYOtu4g7gAAAKM"]
[Tue Jul 21 07:58:38.499495 2026] [security2:error] [pid 352421:tid 352628] [client 20.151.10.161:29196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/file5.php"] [unique_id "al9Q3sJSWzG9jbYOtu4g-gAAANI"]
[Tue Jul 21 07:58:38.557026 2026] [security2:error] [pid 352421:tid 352671] [client 20.104.96.117:3542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp.php"] [unique_id "al9Q3sJSWzG9jbYOtu4g_AAAAP0"]
[Tue Jul 21 07:58:38.662269 2026] [autoindex:error] [pid 352421:tid 352598] [client 185.226.197.15:14862] AH01276: Cannot serve directory /home4/segu6252/dizi.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:58:38.743749 2026] [core:alert] [pid 352421:tid 352586] [client 57.141.18.46:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:58:38.841986 2026] [security2:error] [pid 352421:tid 352449] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q3sJSWzG9jbYOtu4hCAAAvhs"]
[Tue Jul 21 07:58:38.842132 2026] [security2:error] [pid 352421:tid 352608] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q3sJSWzG9jbYOtu4hCAAAvhs"]
[Tue Jul 21 07:58:39.080652 2026] [security2:error] [pid 352421:tid 352667] [client 122.164.127.47:59379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Q38JSWzG9jbYOtu4hEgAAAPk"]
[Tue Jul 21 07:58:39.080736 2026] [security2:error] [pid 352421:tid 352667] [client 122.164.127.47:59379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Q38JSWzG9jbYOtu4hEgAAAPk"]
[Tue Jul 21 07:58:39.124708 2026] [security2:error] [pid 352421:tid 352674] [client 20.104.96.117:3529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/class.php"] [unique_id "al9Q38JSWzG9jbYOtu4hFAAAAQA"]
[Tue Jul 21 07:58:39.150029 2026] [security2:error] [pid 352421:tid 352599] [client 65.21.113.253:55614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Q38JSWzG9jbYOtu4hGAAAALU"]
[Tue Jul 21 07:58:39.547900 2026] [security2:error] [pid 352421:tid 352673] [client 184.75.221.3:46750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Q38JSWzG9jbYOtu4hKwAAAP8"]
[Tue Jul 21 07:58:39.548017 2026] [security2:error] [pid 352421:tid 352673] [client 184.75.221.3:46750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Q38JSWzG9jbYOtu4hKwAAAP8"]
[Tue Jul 21 07:58:39.602761 2026] [security2:error] [pid 352421:tid 352563] [client 20.151.10.161:29234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Q38JSWzG9jbYOtu4hMQAAAJE"]
[Tue Jul 21 07:58:39.665834 2026] [security2:error] [pid 352421:tid 352610] [client 20.104.96.117:3500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/echkm.php"] [unique_id "al9Q38JSWzG9jbYOtu4hNAAAAMA"]
[Tue Jul 21 07:58:39.688395 2026] [security2:error] [pid 352421:tid 352571] [client 184.75.221.3:46752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Q38JSWzG9jbYOtu4hNwAAAJk"]
[Tue Jul 21 07:58:39.688491 2026] [security2:error] [pid 352421:tid 352571] [client 184.75.221.3:46752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Q38JSWzG9jbYOtu4hNwAAAJk"]
[Tue Jul 21 07:58:39.777000 2026] [security2:error] [pid 352421:tid 352554] [client 65.21.113.253:54182] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q38JSWzG9jbYOtu4hIQAAAIg"]
[Tue Jul 21 07:58:39.978049 2026] [security2:error] [pid 352421:tid 352525] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q38JSWzG9jbYOtu4hQAAAjGc"]
[Tue Jul 21 07:58:39.978241 2026] [security2:error] [pid 352421:tid 352558] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q38JSWzG9jbYOtu4hQAAAjGc"]
[Tue Jul 21 07:58:40.044745 2026] [security2:error] [pid 352421:tid 352629] [client 193.36.225.70:57999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Q4MJSWzG9jbYOtu4hQgAAANM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:58:40.070844 2026] [security2:error] [pid 352421:tid 352599] [client 20.104.96.117:45121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/lib.php"] [unique_id "al9Q4MJSWzG9jbYOtu4hQwAAALU"]
[Tue Jul 21 07:58:40.077159 2026] [security2:error] [pid 352421:tid 352564] [client 20.220.225.223:1822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/la.php"] [unique_id "al9Q4MJSWzG9jbYOtu4hRAAAAJI"]
[Tue Jul 21 07:58:40.204786 2026] [security2:error] [pid 352421:tid 352576] [client 117.210.135.0:57011] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q4MJSWzG9jbYOtu4hTQAAAJ4"]
[Tue Jul 21 07:58:40.204956 2026] [security2:error] [pid 352421:tid 352576] [client 117.210.135.0:57011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q4MJSWzG9jbYOtu4hTQAAAJ4"]
[Tue Jul 21 07:58:40.591526 2026] [security2:error] [pid 352421:tid 352561] [client 20.104.96.117:45155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/login.php"] [unique_id "al9Q4MJSWzG9jbYOtu4hYwAAAI8"]
[Tue Jul 21 07:58:40.840641 2026] [security2:error] [pid 352421:tid 352626] [client 65.21.113.253:32798] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q4MJSWzG9jbYOtu4hWAAAANA"]
[Tue Jul 21 07:58:41.032697 2026] [security2:error] [pid 352421:tid 352552] [client 41.68.90.219:50336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hcgAAAIY"]
[Tue Jul 21 07:58:41.032853 2026] [security2:error] [pid 352421:tid 352552] [client 41.68.90.219:50336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hcgAAAIY"]
[Tue Jul 21 07:58:41.203397 2026] [security2:error] [pid 352421:tid 352560] [client 20.104.96.117:45182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/a2.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hgAAAAI4"]
[Tue Jul 21 07:58:41.213438 2026] [core:error] [pid 352421:tid 352474] [remote 198.235.24.43:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpcalendars.comunidadekarov.com/
[Tue Jul 21 07:58:41.213455 2026] [core:error] [pid 352421:tid 352474] [remote 198.235.24.43:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpcalendars.comunidadekarov.com/
[Tue Jul 21 07:58:41.247156 2026] [security2:error] [pid 352421:tid 352645] [client 20.226.60.151:59999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/ortasekerli1.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hhAAAAOM"]
[Tue Jul 21 07:58:41.269439 2026] [security2:error] [pid 352421:tid 352651] [client 20.226.60.151:61508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/fffm.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hhgAAAOk"]
[Tue Jul 21 07:58:41.424457 2026] [security2:error] [pid 352421:tid 352655] [client 65.21.113.253:55614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Q4cJSWzG9jbYOtu4higAAAO0"]
[Tue Jul 21 07:58:41.463840 2026] [security2:error] [pid 352421:tid 352566] [client 20.220.225.223:1818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hjQAAAJQ"]
[Tue Jul 21 07:58:41.541187 2026] [security2:error] [pid 352421:tid 352617] [client 20.151.10.161:29066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/file.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hlgAAAMc"]
[Tue Jul 21 07:58:41.555682 2026] [security2:error] [pid 352421:tid 352558] [client 178.153.91.96:10903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hlwAAAIw"]
[Tue Jul 21 07:58:41.555790 2026] [security2:error] [pid 352421:tid 352558] [client 178.153.91.96:10903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hlwAAAIw"]
[Tue Jul 21 07:58:41.611325 2026] [security2:error] [pid 352421:tid 352677] [client 74.249.245.134:5532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/item.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hnwAAAQM"]
[Tue Jul 21 07:58:41.634552 2026] [security2:error] [pid 352421:tid 352486] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hoAAA7EA"]
[Tue Jul 21 07:58:41.634727 2026] [security2:error] [pid 352421:tid 352654] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hoAAA7EA"]
[Tue Jul 21 07:58:41.709495 2026] [security2:error] [pid 352421:tid 352611] [client 4.204.201.85:9629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hpAAAAME"]
[Tue Jul 21 07:58:41.757957 2026] [security2:error] [pid 352421:tid 352616] [client 193.36.225.142:53901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hqwAAAMY"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:58:42.014208 2026] [security2:error] [pid 352421:tid 352591] [client 20.104.96.117:45127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/d61.php"] [unique_id "al9Q4sJSWzG9jbYOtu4htwAAAK0"]
[Tue Jul 21 07:58:42.059245 2026] [security2:error] [pid 352421:tid 352629] [client 65.21.113.253:32798] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q4cJSWzG9jbYOtu4hogAAANM"]
[Tue Jul 21 07:58:42.231211 2026] [security2:error] [pid 352421:tid 352670] [client 38.100.221.102:18953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q4sJSWzG9jbYOtu4hxQAAAPw"]
[Tue Jul 21 07:58:42.231321 2026] [security2:error] [pid 352421:tid 352670] [client 38.100.221.102:18953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q4sJSWzG9jbYOtu4hxQAAAPw"]
[Tue Jul 21 07:58:42.528677 2026] [security2:error] [pid 352421:tid 352499] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Q4sJSWzG9jbYOtu4h0wAAkk0"]
[Tue Jul 21 07:58:42.528858 2026] [security2:error] [pid 352421:tid 352564] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Q4sJSWzG9jbYOtu4h0wAAkk0"]
[Tue Jul 21 07:58:42.624088 2026] [security2:error] [pid 352421:tid 352512] [remote 2a09:bac1:76a0:460::5e:63:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "promocao-relampago.assumaocontrole.com"] [uri "/.env"] [unique_id "al9Q4sJSWzG9jbYOtu4h3AAAxlo"]
[Tue Jul 21 07:58:42.679884 2026] [security2:error] [pid 352421:tid 352575] [client 59.93.4.33:49705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q4sJSWzG9jbYOtu4h4AAAAJ0"]
[Tue Jul 21 07:58:42.679973 2026] [security2:error] [pid 352421:tid 352575] [client 59.93.4.33:49705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q4sJSWzG9jbYOtu4h4AAAAJ0"]
[Tue Jul 21 07:58:42.890242 2026] [security2:error] [pid 352421:tid 352592] [client 20.226.60.151:56717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/fpr4.php"] [unique_id "al9Q4sJSWzG9jbYOtu4h6wAAAK4"]
[Tue Jul 21 07:58:42.915226 2026] [security2:error] [pid 352421:tid 352598] [client 109.60.28.94:62878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q4sJSWzG9jbYOtu4h7AAAALQ"]
[Tue Jul 21 07:58:42.915403 2026] [security2:error] [pid 352421:tid 352598] [client 109.60.28.94:62878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q4sJSWzG9jbYOtu4h7AAAALQ"]
[Tue Jul 21 07:58:42.923826 2026] [security2:error] [pid 352421:tid 352634] [client 20.220.225.223:1282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/inso.php"] [unique_id "al9Q4sJSWzG9jbYOtu4h7QAAANg"]
[Tue Jul 21 07:58:43.000704 2026] [security2:error] [pid 352421:tid 352589] [client 182.8.255.181:21208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Q48JSWzG9jbYOtu4h7wAAAKs"]
[Tue Jul 21 07:58:43.000805 2026] [security2:error] [pid 352421:tid 352589] [client 182.8.255.181:21208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Q48JSWzG9jbYOtu4h7wAAAKs"]
[Tue Jul 21 07:58:43.048126 2026] [security2:error] [pid 352421:tid 352640] [client 20.151.10.161:29058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/cfile.php"] [unique_id "al9Q48JSWzG9jbYOtu4h9AAAAN4"]
[Tue Jul 21 07:58:43.073065 2026] [security2:error] [pid 352421:tid 352625] [client 20.104.96.117:3525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/info.php"] [unique_id "al9Q48JSWzG9jbYOtu4h9wAAAM8"]
[Tue Jul 21 07:58:43.119233 2026] [security2:error] [pid 352421:tid 352560] [client 117.247.80.59:26198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q48JSWzG9jbYOtu4h-QAAAI4"]
[Tue Jul 21 07:58:43.119345 2026] [security2:error] [pid 352421:tid 352560] [client 117.247.80.59:26198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q48JSWzG9jbYOtu4h-QAAAI4"]
[Tue Jul 21 07:58:43.134425 2026] [security2:error] [pid 352421:tid 352479] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q48JSWzG9jbYOtu4h-gAAiDk"]
[Tue Jul 21 07:58:43.134581 2026] [security2:error] [pid 352421:tid 352554] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q48JSWzG9jbYOtu4h-gAAiDk"]
[Tue Jul 21 07:58:43.253001 2026] [security2:error] [pid 352421:tid 352548] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Q48JSWzG9jbYOtu4iAwAA3H4"]
[Tue Jul 21 07:58:43.253124 2026] [security2:error] [pid 352421:tid 352638] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Q48JSWzG9jbYOtu4iAwAA3H4"]
[Tue Jul 21 07:58:43.559754 2026] [security2:error] [pid 352421:tid 352563] [client 193.36.225.66:27895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Q48JSWzG9jbYOtu4iEQAAAJE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:58:43.641180 2026] [security2:error] [pid 352421:tid 352449] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q48JSWzG9jbYOtu4iGAAA7Rs"]
[Tue Jul 21 07:58:43.641336 2026] [security2:error] [pid 352421:tid 352655] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q48JSWzG9jbYOtu4iGAAA7Rs"]
[Tue Jul 21 07:58:43.695522 2026] [security2:error] [pid 352421:tid 352634] [client 4.204.201.85:9594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/abcd.php"] [unique_id "al9Q48JSWzG9jbYOtu4iGgAAANg"]
[Tue Jul 21 07:58:43.887366 2026] [security2:error] [pid 352421:tid 352574] [client 20.226.60.151:61553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/dfre.php"] [unique_id "al9Q48JSWzG9jbYOtu4iJgAAAJw"]
[Tue Jul 21 07:58:43.972257 2026] [security2:error] [pid 352421:tid 352608] [client 193.36.225.143:40833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Q48JSWzG9jbYOtu4iKAAAAL4"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:58:43.972282 2026] [security2:error] [pid 352421:tid 352638] [client 20.104.96.117:45168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/11.php"] [unique_id "al9Q48JSWzG9jbYOtu4iKQAAANw"]
[Tue Jul 21 07:58:44.078844 2026] [security2:error] [pid 352421:tid 352580] [client 110.225.227.86:2220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.227.225.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "geohistorianiteroi.com"] [uri "/xmlrpc.php"] [unique_id "al9Q5MJSWzG9jbYOtu4iLQAAAKI"]
[Tue Jul 21 07:58:44.078975 2026] [security2:error] [pid 352421:tid 352580] [client 110.225.227.86:2220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "geohistorianiteroi.com"] [uri "/xmlrpc.php"] [unique_id "al9Q5MJSWzG9jbYOtu4iLQAAAKI"]
[Tue Jul 21 07:58:44.095401 2026] [security2:error] [pid 352421:tid 352456] [remote 2a09:bac1:76a0:460::5e:63:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "promocao-relampago.assumaocontrole.com"] [uri "/.env.old"] [unique_id "al9Q5MJSWzG9jbYOtu4iMQAAoCI"]
[Tue Jul 21 07:58:44.098422 2026] [autoindex:error] [pid 352421:tid 352663] [client 172.121.172.176:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:58:44.232173 2026] [security2:error] [pid 352421:tid 352671] [client 20.151.10.161:28708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/class-wp.php"] [unique_id "al9Q5MJSWzG9jbYOtu4iSgAAAP0"]
[Tue Jul 21 07:58:44.386611 2026] [security2:error] [pid 352421:tid 352539] [remote 65.111.11.115:39829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.11.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9Q48JSWzG9jbYOtu4iAAAA5XU"]
[Tue Jul 21 07:58:44.419839 2026] [security2:error] [pid 352421:tid 352529] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Q5MJSWzG9jbYOtu4iVQAA3Ws"]
[Tue Jul 21 07:58:44.420084 2026] [security2:error] [pid 352421:tid 352639] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Q5MJSWzG9jbYOtu4iVQAA3Ws"]
[Tue Jul 21 07:58:44.535419 2026] [security2:error] [pid 352421:tid 352554] [client 20.104.96.117:45448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/v2.php"] [unique_id "al9Q5MJSWzG9jbYOtu4iWwAAAIg"]
[Tue Jul 21 07:58:44.597647 2026] [security2:error] [pid 352421:tid 352643] [client 4.204.201.85:9639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/file15.php"] [unique_id "al9Q5MJSWzG9jbYOtu4iXwAAAOE"]
[Tue Jul 21 07:58:44.623874 2026] [security2:error] [pid 352421:tid 352619] [client 65.21.113.253:32806] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q5MJSWzG9jbYOtu4iQwAAAMk"]
[Tue Jul 21 07:58:44.736676 2026] [security2:error] [pid 352421:tid 352525] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/wp-login.php"] [unique_id "al9Q5MJSWzG9jbYOtu4iXAAA7Gc"], referer: https://gradiente.com/login
[Tue Jul 21 07:58:44.882183 2026] [security2:error] [pid 352421:tid 352651] [client 20.104.96.117:45161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/panel.php"] [unique_id "al9Q5MJSWzG9jbYOtu4iaAAAAOk"]
[Tue Jul 21 07:58:45.063045 2026] [security2:error] [pid 352421:tid 352583] [client 106.215.181.8:4843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q5cJSWzG9jbYOtu4ibAAAAKU"]
[Tue Jul 21 07:58:45.066247 2026] [security2:error] [pid 352421:tid 352583] [client 106.215.181.8:4843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q5cJSWzG9jbYOtu4ibAAAAKU"]
[Tue Jul 21 07:58:45.098572 2026] [security2:error] [pid 352421:tid 352482] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/wp-login.php"] [unique_id "al9Q5cJSWzG9jbYOtu4ibwAAiTw"], referer: https://gradiente.com/wp-admin/
[Tue Jul 21 07:58:45.117169 2026] [security2:error] [pid 352421:tid 352537] [remote 34.101.153.152:37754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gradiente.com"] [uri "/wp-login.php"] [unique_id "al9Q5cJSWzG9jbYOtu4icAAAxXM"], referer: https://gradiente.com/wp-admin/
[Tue Jul 21 07:58:45.248077 2026] [security2:error] [pid 352421:tid 352638] [client 87.116.180.198:13952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q5cJSWzG9jbYOtu4idgAAANw"]
[Tue Jul 21 07:58:45.252956 2026] [security2:error] [pid 352421:tid 352638] [client 87.116.180.198:13952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q5cJSWzG9jbYOtu4idgAAANw"]
[Tue Jul 21 07:58:45.276924 2026] [security2:error] [pid 352421:tid 352611] [client 223.236.153.128:5444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Q5cJSWzG9jbYOtu4idwAAAME"]
[Tue Jul 21 07:58:45.277013 2026] [security2:error] [pid 352421:tid 352611] [client 223.236.153.128:5444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Q5cJSWzG9jbYOtu4idwAAAME"]
[Tue Jul 21 07:58:45.336115 2026] [security2:error] [pid 352421:tid 352606] [client 20.104.96.117:45142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/dex.php"] [unique_id "al9Q5cJSWzG9jbYOtu4ifAAAALw"]
[Tue Jul 21 07:58:45.384678 2026] [security2:error] [pid 352421:tid 352622] [client 20.151.10.161:29078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/admin.php"] [unique_id "al9Q5cJSWzG9jbYOtu4igAAAAMw"]
[Tue Jul 21 07:58:45.417143 2026] [security2:error] [pid 352421:tid 352634] [client 4.204.201.85:9661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/jp.php"] [unique_id "al9Q5cJSWzG9jbYOtu4igQAAANg"]
[Tue Jul 21 07:58:45.438463 2026] [security2:error] [pid 352421:tid 352653] [client 74.249.245.134:5551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/albin.php"] [unique_id "al9Q5cJSWzG9jbYOtu4iggAAAOs"]
[Tue Jul 21 07:58:45.489350 2026] [security2:error] [pid 352421:tid 352448] [remote 124.55.178.99:53542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/wp-login.php"] [unique_id "al9Q5cJSWzG9jbYOtu4ihgAAmBo"]
[Tue Jul 21 07:58:45.607722 2026] [security2:error] [pid 341679:tid 341779] [remote 202.51.202.242:58828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/xmlrpc.php"] [unique_id "al9Q5QWat-noHLkDuAiisAABIWM"]
[Tue Jul 21 07:58:45.607940 2026] [security2:error] [pid 341679:tid 341832] [client 202.51.202.242:58828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "buyonlinetodayatadiscount.net"] [uri "/xmlrpc.php"] [unique_id "al9Q5QWat-noHLkDuAiisAABIWM"]
[Tue Jul 21 07:58:45.803639 2026] [security2:error] [pid 352421:tid 352640] [client 198.54.128.138:41194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Q5cJSWzG9jbYOtu4ijgAAAN4"]
[Tue Jul 21 07:58:45.803770 2026] [security2:error] [pid 352421:tid 352640] [client 198.54.128.138:41194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Q5cJSWzG9jbYOtu4ijgAAAN4"]
[Tue Jul 21 07:58:45.870408 2026] [security2:error] [pid 352421:tid 352576] [client 20.104.96.117:3573] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "thekingsdistribuidora.com.br"] [uri "/1.php"] [unique_id "al9Q5cJSWzG9jbYOtu4ikAAAAJ4"]
[Tue Jul 21 07:58:45.870546 2026] [security2:error] [pid 352421:tid 352576] [client 20.104.96.117:3573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/1.php"] [unique_id "al9Q5cJSWzG9jbYOtu4ikAAAAJ4"]
[Tue Jul 21 07:58:46.173425 2026] [security2:error] [pid 352421:tid 352604] [client 4.204.201.85:9566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/f35.php"] [unique_id "al9Q5sJSWzG9jbYOtu4imAAAALo"]
[Tue Jul 21 07:58:46.245439 2026] [security2:error] [pid 352421:tid 352556] [client 20.104.96.117:45125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/ms.php"] [unique_id "al9Q5sJSWzG9jbYOtu4inAAAAIo"]
[Tue Jul 21 07:58:46.356600 2026] [security2:error] [pid 352421:tid 352564] [client 185.213.175.37:26846] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "aulaexperimental.esidiomass.com.br"] [uri "/cgi-sys/images/favicons/favicon.ico"] [unique_id "al9Q5sJSWzG9jbYOtu4iqwAAAJI"]
[Tue Jul 21 07:58:46.411598 2026] [security2:error] [pid 352421:tid 352551] [client 37.140.223.154:37737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Q5sJSWzG9jbYOtu4imwAAAIU"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:58:46.489566 2026] [security2:error] [pid 352421:tid 352625] [client 103.78.200.11:58985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q5sJSWzG9jbYOtu4isQAAAM8"]
[Tue Jul 21 07:58:46.489695 2026] [security2:error] [pid 352421:tid 352625] [client 103.78.200.11:58985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q5sJSWzG9jbYOtu4isQAAAM8"]
[Tue Jul 21 07:58:46.647182 2026] [security2:error] [pid 352421:tid 352559] [client 185.213.175.37:26902] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "aulaexperimental.esidiomass.com.br"] [uri "/cgi-sys/css/bootstrap.min.css"] [unique_id "al9Q5sJSWzG9jbYOtu4ivgAAAI0"]
[Tue Jul 21 07:58:46.942164 2026] [security2:error] [pid 352421:tid 352676] [client 122.162.144.145:12673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Q5sJSWzG9jbYOtu4izAAAAQI"]
[Tue Jul 21 07:58:46.942248 2026] [security2:error] [pid 352421:tid 352676] [client 122.162.144.145:12673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Q5sJSWzG9jbYOtu4izAAAAQI"]
[Tue Jul 21 07:58:46.983546 2026] [autoindex:error] [pid 352421:tid 352632] [client 20.104.96.117:3527] AH01276: Cannot serve directory /home2/thekin17/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:58:47.151488 2026] [security2:error] [pid 352421:tid 352630] [client 103.29.114.44:24632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q58JSWzG9jbYOtu4i0AAAANQ"]
[Tue Jul 21 07:58:47.151728 2026] [security2:error] [pid 352421:tid 352630] [client 103.29.114.44:24632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q58JSWzG9jbYOtu4i0AAAANQ"]
[Tue Jul 21 07:58:47.198514 2026] [security2:error] [pid 352421:tid 352622] [client 20.151.10.161:28680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/aa2.php"] [unique_id "al9Q58JSWzG9jbYOtu4i0gAAAMw"]
[Tue Jul 21 07:58:47.344057 2026] [security2:error] [pid 352421:tid 352634] [client 20.104.96.117:3527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/memberfuns.php"] [unique_id "al9Q58JSWzG9jbYOtu4i1AAAANg"]
[Tue Jul 21 07:58:47.395808 2026] [security2:error] [pid 352421:tid 352562] [client 202.143.127.214:59126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q58JSWzG9jbYOtu4i1gAAAJA"]
[Tue Jul 21 07:58:47.395965 2026] [security2:error] [pid 352421:tid 352562] [client 202.143.127.214:59126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q58JSWzG9jbYOtu4i1gAAAJA"]
[Tue Jul 21 07:58:47.527917 2026] [security2:error] [pid 352421:tid 352469] [remote 41.76.214.143:34626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9Q58JSWzG9jbYOtu4i5gAArS8"]
[Tue Jul 21 07:58:47.607875 2026] [security2:error] [pid 352421:tid 352590] [client 103.166.103.129:63927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Q58JSWzG9jbYOtu4i6QAAAKw"]
[Tue Jul 21 07:58:47.608005 2026] [security2:error] [pid 352421:tid 352590] [client 103.166.103.129:63927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Q58JSWzG9jbYOtu4i6QAAAKw"]
[Tue Jul 21 07:58:47.610297 2026] [security2:error] [pid 352421:tid 352574] [client 4.204.201.85:61020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/wp-load.php"] [unique_id "al9Q58JSWzG9jbYOtu4i6gAAAJw"]
[Tue Jul 21 07:58:47.841096 2026] [security2:error] [pid 352421:tid 352635] [client 20.151.10.161:29192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/ccou.php"] [unique_id "al9Q58JSWzG9jbYOtu4i9QAAANk"]
[Tue Jul 21 07:58:47.887082 2026] [security2:error] [pid 352421:tid 352580] [client 20.104.96.117:3563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/0.php"] [unique_id "al9Q58JSWzG9jbYOtu4i9wAAAKI"]
[Tue Jul 21 07:58:47.921123 2026] [security2:error] [pid 352421:tid 352636] [client 102.206.115.33:61082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Q58JSWzG9jbYOtu4i-QAAANo"]
[Tue Jul 21 07:58:47.921261 2026] [security2:error] [pid 352421:tid 352636] [client 102.206.115.33:61082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Q58JSWzG9jbYOtu4i-QAAANo"]
[Tue Jul 21 07:58:48.112228 2026] [security2:error] [pid 352421:tid 352557] [client 20.220.225.223:1801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wpx.php"] [unique_id "al9Q6MJSWzG9jbYOtu4jBwAAAIs"]
[Tue Jul 21 07:58:48.121124 2026] [security2:error] [pid 352421:tid 352618] [client 193.36.225.68:23577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Q58JSWzG9jbYOtu4i_QAAAMg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:58:48.150596 2026] [security2:error] [pid 352421:tid 352597] [client 65.21.113.253:32806] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q58JSWzG9jbYOtu4i7AAAALM"]
[Tue Jul 21 07:58:48.183507 2026] [security2:error] [pid 352421:tid 352638] [client 65.21.113.253:58192] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Q6MJSWzG9jbYOtu4jDwAAANw"]
[Tue Jul 21 07:58:48.262913 2026] [security2:error] [pid 352421:tid 352602] [client 20.104.96.117:45131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/BDKR28.php"] [unique_id "al9Q6MJSWzG9jbYOtu4jFgAAALg"]
[Tue Jul 21 07:58:48.335382 2026] [security2:error] [pid 352421:tid 352672] [client 4.204.201.85:9587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/xyn.php"] [unique_id "al9Q6MJSWzG9jbYOtu4jFwAAAP4"]
[Tue Jul 21 07:58:48.447105 2026] [security2:error] [pid 352421:tid 352609] [client 122.179.91.63:19250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Q6MJSWzG9jbYOtu4jHAAAAL8"]
[Tue Jul 21 07:58:48.447207 2026] [security2:error] [pid 352421:tid 352609] [client 122.179.91.63:19250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Q6MJSWzG9jbYOtu4jHAAAAL8"]
[Tue Jul 21 07:58:48.577580 2026] [security2:error] [pid 352421:tid 352643] [client 103.86.117.203:56147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q6MJSWzG9jbYOtu4jJQAAAOE"]
[Tue Jul 21 07:58:48.577693 2026] [security2:error] [pid 352421:tid 352643] [client 103.86.117.203:56147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q6MJSWzG9jbYOtu4jJQAAAOE"]
[Tue Jul 21 07:58:48.731654 2026] [security2:error] [pid 352421:tid 352561] [client 193.36.225.120:37035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Q6MJSWzG9jbYOtu4jIgAAAI8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:58:48.819410 2026] [security2:error] [pid 352421:tid 352637] [client 65.21.113.253:32806] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q6MJSWzG9jbYOtu4jGQAAANs"]
[Tue Jul 21 07:58:48.878196 2026] [security2:error] [pid 352421:tid 352607] [client 20.151.10.161:29068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/dr.php"] [unique_id "al9Q6MJSWzG9jbYOtu4jLQAAAL0"]
[Tue Jul 21 07:58:48.931466 2026] [security2:error] [pid 352421:tid 352632] [client 20.104.96.117:45162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/green1.php"] [unique_id "al9Q6MJSWzG9jbYOtu4jLgAAANY"]
[Tue Jul 21 07:58:49.339584 2026] [security2:error] [pid 352421:tid 352666] [client 184.154.36.178:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "weightloss-review.shop"] [uri "/index.php"] [unique_id "al9Q6cJSWzG9jbYOtu4jPwAAAPg"]
[Tue Jul 21 07:58:49.566654 2026] [security2:error] [pid 352421:tid 352533] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q6cJSWzG9jbYOtu4jTQAAv28"]
[Tue Jul 21 07:58:49.566841 2026] [security2:error] [pid 352421:tid 352609] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q6cJSWzG9jbYOtu4jTQAAv28"]
[Tue Jul 21 07:58:49.623617 2026] [security2:error] [pid 352421:tid 352576] [client 4.204.201.85:9552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/ccc.php"] [unique_id "al9Q6cJSWzG9jbYOtu4jTgAAAJ4"]
[Tue Jul 21 07:58:49.653378 2026] [security2:error] [pid 352421:tid 352610] [client 122.164.127.47:59955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Q6cJSWzG9jbYOtu4jTwAAAMA"]
[Tue Jul 21 07:58:49.653496 2026] [security2:error] [pid 352421:tid 352610] [client 122.164.127.47:59955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Q6cJSWzG9jbYOtu4jTwAAAMA"]
[Tue Jul 21 07:58:49.886673 2026] [security2:error] [pid 352421:tid 352578] [client 20.226.60.151:61517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/wp-happy.php"] [unique_id "al9Q6cJSWzG9jbYOtu4jUgAAAKA"]
[Tue Jul 21 07:58:49.962426 2026] [security2:error] [pid 352421:tid 352561] [client 20.151.10.161:29213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/xamp.php"] [unique_id "al9Q6cJSWzG9jbYOtu4jVAAAAI8"]
[Tue Jul 21 07:58:50.234220 2026] [security2:error] [pid 352421:tid 352485] [remote 182.77.62.24:60742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "archrender.com.br"] [uri "/wp-login.php"] [unique_id "al9Q6MJSWzG9jbYOtu4jFAAAiD8"]
[Tue Jul 21 07:58:50.426070 2026] [security2:error] [pid 352421:tid 352666] [client 74.249.245.134:54376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/alfa.php"] [unique_id "al9Q6sJSWzG9jbYOtu4jaAAAAPg"]
[Tue Jul 21 07:58:50.449694 2026] [security2:error] [pid 352421:tid 352591] [client 20.104.96.117:45459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/nc4.php"] [unique_id "al9Q6sJSWzG9jbYOtu4jaQAAAK0"]
[Tue Jul 21 07:58:50.566477 2026] [security2:error] [pid 352421:tid 352638] [client 184.154.36.178:54940] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "weightloss-review.shop"] [uri "/wp-content/uploads/elementor/css/post-8.css"] [unique_id "al9Q6sJSWzG9jbYOtu4jdQAAANw"]
[Tue Jul 21 07:58:50.594007 2026] [security2:error] [pid 352421:tid 352529] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q6sJSWzG9jbYOtu4jdgAAmms"]
[Tue Jul 21 07:58:50.594170 2026] [security2:error] [pid 352421:tid 352572] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q6sJSWzG9jbYOtu4jdgAAmms"]
[Tue Jul 21 07:58:50.751281 2026] [security2:error] [pid 352421:tid 352555] [client 117.210.135.0:57688] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q6sJSWzG9jbYOtu4jfwAAAIk"]
[Tue Jul 21 07:58:50.751456 2026] [security2:error] [pid 352421:tid 352555] [client 117.210.135.0:57688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q6sJSWzG9jbYOtu4jfwAAAIk"]
[Tue Jul 21 07:58:50.768888 2026] [security2:error] [pid 352421:tid 352531] [remote 45.79.123.44:45444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tempex.com.br"] [uri "/wp-login.php"] [unique_id "al9Q6sJSWzG9jbYOtu4jgAAA-m0"]
[Tue Jul 21 07:58:50.788529 2026] [security2:error] [pid 352421:tid 352639] [client 198.54.128.138:57334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Q6sJSWzG9jbYOtu4jgQAAAN0"]
[Tue Jul 21 07:58:50.788634 2026] [security2:error] [pid 352421:tid 352639] [client 198.54.128.138:57334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Q6sJSWzG9jbYOtu4jgQAAAN0"]
[Tue Jul 21 07:58:50.906998 2026] [security2:error] [pid 352421:tid 352599] [client 4.204.201.85:9558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/w.php"] [unique_id "al9Q6sJSWzG9jbYOtu4jhAAAALU"]
[Tue Jul 21 07:58:51.132119 2026] [security2:error] [pid 352421:tid 352578] [client 20.104.96.117:45701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/a1.php"] [unique_id "al9Q68JSWzG9jbYOtu4jiAAAAKA"]
[Tue Jul 21 07:58:51.398128 2026] [security2:error] [pid 352421:tid 352451] [remote 124.55.178.99:53558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrsolar.org.br"] [uri "/wp-login.php"] [unique_id "al9Q68JSWzG9jbYOtu4jkwAA_B0"]
[Tue Jul 21 07:58:51.552426 2026] [security2:error] [pid 352421:tid 352596] [client 41.68.90.219:50788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q68JSWzG9jbYOtu4jmgAAALI"]
[Tue Jul 21 07:58:51.553945 2026] [security2:error] [pid 352421:tid 352596] [client 41.68.90.219:50788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q68JSWzG9jbYOtu4jmgAAALI"]
[Tue Jul 21 07:58:51.670303 2026] [security2:error] [pid 352421:tid 352640] [client 20.104.96.117:3510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/eee.php"] [unique_id "al9Q68JSWzG9jbYOtu4jpAAAAN4"]
[Tue Jul 21 07:58:51.737990 2026] [security2:error] [pid 352421:tid 352586] [client 184.154.36.178:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "weightloss-review.shop"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al9Q68JSWzG9jbYOtu4jqwAAAKg"]
[Tue Jul 21 07:58:51.738856 2026] [security2:error] [pid 352421:tid 352642] [client 184.154.36.178:55338] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "weightloss-review.shop"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al9Q68JSWzG9jbYOtu4jqQAAAOA"]
[Tue Jul 21 07:58:51.883367 2026] [security2:error] [pid 352421:tid 352623] [client 136.144.33.103:51837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Q68JSWzG9jbYOtu4jrAAAAM0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:58:51.899657 2026] [security2:error] [pid 352421:tid 352582] [client 20.151.10.161:28845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/bless.php"] [unique_id "al9Q68JSWzG9jbYOtu4jrQAAAKQ"]
[Tue Jul 21 07:58:51.973289 2026] [security2:error] [pid 352421:tid 352664] [client 20.226.60.151:50662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/file88.php"] [unique_id "al9Q68JSWzG9jbYOtu4jrgAAAPY"]
[Tue Jul 21 07:58:52.063295 2026] [security2:error] [pid 352421:tid 352595] [client 65.21.113.253:43082] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q68JSWzG9jbYOtu4jnQAAALE"]
[Tue Jul 21 07:58:52.075280 2026] [security2:error] [pid 352421:tid 352665] [client 4.204.201.85:61016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Q7MJSWzG9jbYOtu4jrwAAAPc"]
[Tue Jul 21 07:58:52.075414 2026] [security2:error] [pid 352421:tid 352584] [client 178.153.91.96:51238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q7MJSWzG9jbYOtu4jsAAAAKY"]
[Tue Jul 21 07:58:52.075552 2026] [security2:error] [pid 352421:tid 352584] [client 178.153.91.96:51238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q7MJSWzG9jbYOtu4jsAAAAKY"]
[Tue Jul 21 07:58:52.114888 2026] [security2:error] [pid 352421:tid 352651] [client 20.104.96.117:45444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-aothait.php"] [unique_id "al9Q7MJSWzG9jbYOtu4jsgAAAOk"]
[Tue Jul 21 07:58:52.262915 2026] [security2:error] [pid 352421:tid 352675] [client 20.220.225.223:1280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/berlin.php"] [unique_id "al9Q7MJSWzG9jbYOtu4juAAAAQE"]
[Tue Jul 21 07:58:52.418536 2026] [security2:error] [pid 352421:tid 352596] [client 65.21.113.253:58192] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Q7MJSWzG9jbYOtu4jvgAAALI"]
[Tue Jul 21 07:58:52.428729 2026] [security2:error] [pid 352421:tid 352500] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Q7MJSWzG9jbYOtu4jvwAAoU4"]
[Tue Jul 21 07:58:52.428906 2026] [security2:error] [pid 352421:tid 352579] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Q7MJSWzG9jbYOtu4jvwAAoU4"]
[Tue Jul 21 07:58:52.558563 2026] [security2:error] [pid 352421:tid 352523] [remote 92.222.104.193:46306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "3d-surgery.com.br"] [uri "/robots.txt"] [unique_id "al9Q7MJSWzG9jbYOtu4jwwAAn2U"]
[Tue Jul 21 07:58:52.558721 2026] [security2:error] [pid 352421:tid 352577] [client 92.222.104.193:46306] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "3d-surgery.com.br"] [uri "/robots.txt"] [unique_id "al9Q7MJSWzG9jbYOtu4jwwAAn2U"]
[Tue Jul 21 07:58:52.697555 2026] [security2:error] [pid 352421:tid 352589] [client 20.220.225.223:1337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/billur.php"] [unique_id "al9Q7MJSWzG9jbYOtu4jygAAAKs"]
[Tue Jul 21 07:58:52.763920 2026] [security2:error] [pid 352421:tid 352673] [client 38.100.221.102:17329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q7MJSWzG9jbYOtu4jzwAAAP8"]
[Tue Jul 21 07:58:52.764055 2026] [security2:error] [pid 352421:tid 352673] [client 38.100.221.102:17329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q7MJSWzG9jbYOtu4jzwAAAP8"]
[Tue Jul 21 07:58:52.901184 2026] [security2:error] [pid 352421:tid 352668] [client 20.104.96.117:45293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/config.json.php"] [unique_id "al9Q7MJSWzG9jbYOtu4j1QAAAPo"]
[Tue Jul 21 07:58:53.114714 2026] [security2:error] [pid 352421:tid 352466] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Q7cJSWzG9jbYOtu4j2gAAzCw"]
[Tue Jul 21 07:58:53.114972 2026] [security2:error] [pid 352421:tid 352622] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Q7cJSWzG9jbYOtu4j2gAAzCw"]
[Tue Jul 21 07:58:53.378785 2026] [security2:error] [pid 352421:tid 352571] [client 182.8.255.181:21233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Q7cJSWzG9jbYOtu4j4QAAAJk"]
[Tue Jul 21 07:58:53.379072 2026] [security2:error] [pid 352421:tid 352571] [client 182.8.255.181:21233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Q7cJSWzG9jbYOtu4j4QAAAJk"]
[Tue Jul 21 07:58:53.391735 2026] [security2:error] [pid 352421:tid 352588] [client 20.226.60.151:65414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/classwithtostring.php"] [unique_id "al9Q7cJSWzG9jbYOtu4j4gAAAKo"]
[Tue Jul 21 07:58:53.482431 2026] [security2:error] [pid 352421:tid 352555] [client 65.21.113.253:43092] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q7cJSWzG9jbYOtu4j2QAAAIk"]
[Tue Jul 21 07:58:53.507970 2026] [security2:error] [pid 352421:tid 352642] [client 59.93.4.33:50244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q7cJSWzG9jbYOtu4j6wAAAOA"]
[Tue Jul 21 07:58:53.508095 2026] [security2:error] [pid 352421:tid 352642] [client 59.93.4.33:50244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q7cJSWzG9jbYOtu4j6wAAAOA"]
[Tue Jul 21 07:58:53.640404 2026] [security2:error] [pid 352421:tid 352454] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q7cJSWzG9jbYOtu4j8gAAwiA"]
[Tue Jul 21 07:58:53.640539 2026] [security2:error] [pid 352421:tid 352612] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q7cJSWzG9jbYOtu4j8gAAwiA"]
[Tue Jul 21 07:58:53.718577 2026] [security2:error] [pid 352421:tid 352569] [client 20.104.96.117:45136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9Q7cJSWzG9jbYOtu4kDgAAAJc"]
[Tue Jul 21 07:58:53.719766 2026] [security2:error] [pid 352421:tid 352471] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Q7cJSWzG9jbYOtu4kDQAA5DE"]
[Tue Jul 21 07:58:53.719887 2026] [security2:error] [pid 352421:tid 352646] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Q7cJSWzG9jbYOtu4kDQAA5DE"]
[Tue Jul 21 07:58:53.777960 2026] [security2:error] [pid 352421:tid 352637] [client 109.60.28.94:63328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q7cJSWzG9jbYOtu4kFQAAANs"]
[Tue Jul 21 07:58:53.778063 2026] [security2:error] [pid 352421:tid 352637] [client 109.60.28.94:63328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q7cJSWzG9jbYOtu4kFQAAANs"]
[Tue Jul 21 07:58:53.810025 2026] [security2:error] [pid 352421:tid 352439] [remote 72.167.132.114:49552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/wp-login.php"] [unique_id "al9Q7cJSWzG9jbYOtu4kGAAA7RE"]
[Tue Jul 21 07:58:53.844527 2026] [security2:error] [pid 352421:tid 352556] [client 117.247.80.59:26524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q7cJSWzG9jbYOtu4kMwAAAIo"]
[Tue Jul 21 07:58:53.844618 2026] [security2:error] [pid 352421:tid 352556] [client 117.247.80.59:26524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q7cJSWzG9jbYOtu4kMwAAAIo"]
[Tue Jul 21 07:58:53.941765 2026] [security2:error] [pid 352421:tid 352586] [client 4.204.201.85:61038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/FWAZ.php"] [unique_id "al9Q7cJSWzG9jbYOtu4kOgAAAKg"]
[Tue Jul 21 07:58:53.966343 2026] [security2:error] [pid 352421:tid 352674] [client 20.220.225.223:1800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/mimpi.php"] [unique_id "al9Q7cJSWzG9jbYOtu4kOwAAAQA"]
[Tue Jul 21 07:58:54.087668 2026] [security2:error] [pid 352421:tid 352547] [remote 152.42.185.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.185.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.elpcons.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q7sJSWzG9jbYOtu4kPQAAx30"], referer: cpc.partnercare.com/blog//wp-login.php
[Tue Jul 21 07:58:54.137608 2026] [security2:error] [pid 352421:tid 352431] [remote 148.113.128.133:29512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "3d-surgery.com.br"] [uri "/"] [unique_id "al9Q7sJSWzG9jbYOtu4kQwAA3Qk"]
[Tue Jul 21 07:58:54.137781 2026] [security2:error] [pid 352421:tid 352639] [client 148.113.128.133:29512] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "3d-surgery.com.br"] [uri "/"] [unique_id "al9Q7sJSWzG9jbYOtu4kQwAA3Qk"]
[Tue Jul 21 07:58:54.313619 2026] [security2:error] [pid 352421:tid 352613] [client 65.108.13.173:8569] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "65.108.13.173" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "valloratoodo.com"] [uri "/wp-comments-post.php"] [unique_id "al9Q7sJSWzG9jbYOtu4kSQAAAMM"], referer: https://valloratoodo.com/hello-world/#comment-7855
[Tue Jul 21 07:58:54.313727 2026] [security2:error] [pid 352421:tid 352613] [client 65.108.13.173:8569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "valloratoodo.com"] [uri "/wp-comments-post.php"] [unique_id "al9Q7sJSWzG9jbYOtu4kSQAAAMM"], referer: https://valloratoodo.com/hello-world/#comment-7855
[Tue Jul 21 07:58:54.466763 2026] [security2:error] [pid 352421:tid 352628] [client 20.104.96.117:45140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/k2.php"] [unique_id "al9Q7sJSWzG9jbYOtu4kVQAAANI"]
[Tue Jul 21 07:58:54.559339 2026] [security2:error] [pid 352421:tid 352598] [client 20.220.225.223:1069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/dp.php"] [unique_id "al9Q7sJSWzG9jbYOtu4kWwAAALQ"]
[Tue Jul 21 07:58:54.699255 2026] [security2:error] [pid 352421:tid 352514] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q7sJSWzG9jbYOtu4kYAAAhlw"]
[Tue Jul 21 07:58:54.699438 2026] [security2:error] [pid 352421:tid 352552] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q7sJSWzG9jbYOtu4kYAAAhlw"]
[Tue Jul 21 07:58:54.908198 2026] [security2:error] [pid 352421:tid 352558] [client 65.21.113.253:58192] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Q7sJSWzG9jbYOtu4kagAAAIw"]
[Tue Jul 21 07:58:54.925407 2026] [security2:error] [pid 352421:tid 352656] [client 20.104.96.117:3549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9Q7sJSWzG9jbYOtu4kawAAAO4"]
[Tue Jul 21 07:58:54.935557 2026] [security2:error] [pid 352421:tid 352564] [client 20.226.60.151:50673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/ccc.php"] [unique_id "al9Q7sJSWzG9jbYOtu4kbQAAAJI"]
[Tue Jul 21 07:58:55.139889 2026] [proxy:error] [pid 352421:tid 352426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:58:55.139932 2026] [proxy_http:error] [pid 352421:tid 352426] [remote 152.42.185.27:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: cpc.partnercare.com/blog//wp-login.php
[Tue Jul 21 07:58:55.140702 2026] [proxy:error] [pid 352421:tid 352426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:58:55.140732 2026] [proxy_http:error] [pid 352421:tid 352426] [remote 152.42.185.27:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: cpc.partnercare.com/blog//wp-login.php
[Tue Jul 21 07:58:55.154161 2026] [security2:error] [pid 352421:tid 352448] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Q78JSWzG9jbYOtu4kdQAA9Bo"]
[Tue Jul 21 07:58:55.154429 2026] [security2:error] [pid 352421:tid 352662] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Q78JSWzG9jbYOtu4kdQAA9Bo"]
[Tue Jul 21 07:58:55.169907 2026] [security2:error] [pid 352421:tid 352614] [client 74.249.245.134:5530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/autoload_classmap.php"] [unique_id "al9Q78JSWzG9jbYOtu4kdgAAAMQ"]
[Tue Jul 21 07:58:55.223298 2026] [security2:error] [pid 352421:tid 352635] [client 20.151.10.161:28808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/file46.php"] [unique_id "al9Q78JSWzG9jbYOtu4kdwAAANk"]
[Tue Jul 21 07:58:55.242682 2026] [security2:error] [pid 352421:tid 352657] [client 65.108.13.173:8576] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "65.108.13.173" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "valloratoodo.com"] [uri "/wp-comments-post.php"] [unique_id "al9Q78JSWzG9jbYOtu4keAAAAO8"], referer: https://valloratoodo.com/hello-world/#comment-7855
[Tue Jul 21 07:58:55.242863 2026] [security2:error] [pid 352421:tid 352657] [client 65.108.13.173:8576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "valloratoodo.com"] [uri "/wp-comments-post.php"] [unique_id "al9Q78JSWzG9jbYOtu4keAAAAO8"], referer: https://valloratoodo.com/hello-world/#comment-7855
[Tue Jul 21 07:58:55.290230 2026] [security2:error] [pid 352421:tid 352599] [client 74.7.228.47:33436] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thiagomartins.com"] [uri "/index.php"] [unique_id "al9Q7sJSWzG9jbYOtu4kRAAAtVg"]
[Tue Jul 21 07:58:55.304415 2026] [security2:error] [pid 352421:tid 352559] [client 20.104.96.117:3472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9Q78JSWzG9jbYOtu4kfAAAAI0"]
[Tue Jul 21 07:58:55.367287 2026] [security2:error] [pid 352421:tid 352595] [client 20.226.60.151:54005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/fpr4.php"] [unique_id "al9Q78JSWzG9jbYOtu4kfgAAALE"]
[Tue Jul 21 07:58:55.585737 2026] [security2:error] [pid 352421:tid 352617] [client 65.21.113.253:43082] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q78JSWzG9jbYOtu4kcgAAAMc"]
[Tue Jul 21 07:58:55.595178 2026] [proxy:error] [pid 352421:tid 352452] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:58:55.595249 2026] [proxy_http:error] [pid 352421:tid 352452] [remote 152.42.185.27:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: cpc.partnercare.com/blog//wp-login.php
[Tue Jul 21 07:58:55.595999 2026] [proxy:error] [pid 352421:tid 352452] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:58:55.596037 2026] [proxy_http:error] [pid 352421:tid 352452] [remote 152.42.185.27:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: cpc.partnercare.com/blog//wp-login.php
[Tue Jul 21 07:58:55.864971 2026] [security2:error] [pid 352421:tid 352445] [remote 45.146.55.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mecanicanogueira.com.br"] [uri "/wp-login.php"] [unique_id "al9Q78JSWzG9jbYOtu4kkwAAwhc"]
[Tue Jul 21 07:58:55.869079 2026] [security2:error] [pid 352421:tid 352563] [client 20.104.96.117:3456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9Q78JSWzG9jbYOtu4kmQAAAJE"]
[Tue Jul 21 07:58:55.885781 2026] [security2:error] [pid 352421:tid 352624] [client 136.144.33.29:52399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Q78JSWzG9jbYOtu4kmgAAAM4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:58:55.887150 2026] [security2:error] [pid 352421:tid 352593] [client 4.204.201.85:9624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/miru1.php"] [unique_id "al9Q78JSWzG9jbYOtu4kmwAAAK8"]
[Tue Jul 21 07:58:55.969769 2026] [security2:error] [pid 352421:tid 352582] [client 106.215.181.8:27085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q78JSWzG9jbYOtu4kowAAAKQ"]
[Tue Jul 21 07:58:55.969879 2026] [security2:error] [pid 352421:tid 352582] [client 106.215.181.8:27085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q78JSWzG9jbYOtu4kowAAAKQ"]
[Tue Jul 21 07:58:56.002567 2026] [security2:error] [pid 352421:tid 352665] [client 65.21.113.253:43098] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q78JSWzG9jbYOtu4kjwAAAPc"]
[Tue Jul 21 07:58:56.005221 2026] [security2:error] [pid 352421:tid 352584] [client 87.116.180.198:14035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q8MJSWzG9jbYOtu4kpAAAAKY"]
[Tue Jul 21 07:58:56.005350 2026] [security2:error] [pid 352421:tid 352584] [client 87.116.180.198:14035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q8MJSWzG9jbYOtu4kpAAAAKY"]
[Tue Jul 21 07:58:56.049331 2026] [proxy:error] [pid 352421:tid 352477] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:58:56.049405 2026] [proxy_http:error] [pid 352421:tid 352477] [remote 152.42.185.27:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: cpc.partnercare.com/blog//wp-login.php
[Tue Jul 21 07:58:56.050068 2026] [proxy:error] [pid 352421:tid 352477] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:58:56.050106 2026] [proxy_http:error] [pid 352421:tid 352477] [remote 152.42.185.27:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: cpc.partnercare.com/blog//wp-login.php
[Tue Jul 21 07:58:56.186781 2026] [security2:error] [pid 352421:tid 352561] [client 20.151.10.161:20419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Q8MJSWzG9jbYOtu4kqgAAAI8"]
[Tue Jul 21 07:58:56.344680 2026] [security2:error] [pid 352421:tid 352607] [client 20.220.225.223:1314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/bootstrap.php"] [unique_id "al9Q8MJSWzG9jbYOtu4krwAAAL0"]
[Tue Jul 21 07:58:56.463152 2026] [security2:error] [pid 352421:tid 352618] [client 20.104.96.117:3536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/for.php"] [unique_id "al9Q8MJSWzG9jbYOtu4ktAAAAMg"]
[Tue Jul 21 07:58:56.481369 2026] [proxy:error] [pid 352421:tid 352454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:58:56.481430 2026] [proxy_http:error] [pid 352421:tid 352454] [remote 152.42.185.27:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: cpc.partnercare.com/blog//wp-login.php
[Tue Jul 21 07:58:56.481950 2026] [proxy:error] [pid 352421:tid 352454] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:58:56.481993 2026] [proxy_http:error] [pid 352421:tid 352454] [remote 152.42.185.27:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: cpc.partnercare.com/blog//wp-login.php
[Tue Jul 21 07:58:56.486210 2026] [security2:error] [pid 352421:tid 352573] [client 20.151.10.161:20369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Q8MJSWzG9jbYOtu4kuQAAAJs"]
[Tue Jul 21 07:58:56.749086 2026] [security2:error] [pid 352421:tid 352581] [client 223.236.153.128:14214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Q8MJSWzG9jbYOtu4kvQAAAKM"]
[Tue Jul 21 07:58:56.758777 2026] [security2:error] [pid 352421:tid 352581] [client 223.236.153.128:14214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Q8MJSWzG9jbYOtu4kvQAAAKM"]
[Tue Jul 21 07:58:56.787248 2026] [security2:error] [pid 352421:tid 352556] [client 20.151.10.161:20364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/media.php"] [unique_id "al9Q8MJSWzG9jbYOtu4kwwAAAIo"]
[Tue Jul 21 07:58:56.880861 2026] [security2:error] [pid 352421:tid 352635] [client 103.78.200.11:59695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q8MJSWzG9jbYOtu4kxQAAANk"]
[Tue Jul 21 07:58:56.880982 2026] [security2:error] [pid 352421:tid 352635] [client 103.78.200.11:59695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q8MJSWzG9jbYOtu4kxQAAANk"]
[Tue Jul 21 07:58:57.104552 2026] [security2:error] [pid 352421:tid 352665] [client 20.151.10.161:20366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/images.php"] [unique_id "al9Q8cJSWzG9jbYOtu4k0gAAAPc"]
[Tue Jul 21 07:58:57.121172 2026] [security2:error] [pid 352421:tid 352584] [client 20.104.96.117:3480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/raw.php"] [unique_id "al9Q8cJSWzG9jbYOtu4k0wAAAKY"]
[Tue Jul 21 07:58:57.326518 2026] [security2:error] [pid 352421:tid 352639] [client 4.204.201.85:9620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/aa.php"] [unique_id "al9Q8cJSWzG9jbYOtu4k2AAAAN0"]
[Tue Jul 21 07:58:57.674551 2026] [security2:error] [pid 352421:tid 352589] [client 122.162.144.145:7726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Q8cJSWzG9jbYOtu4k5QAAAKs"]
[Tue Jul 21 07:58:57.674691 2026] [security2:error] [pid 352421:tid 352589] [client 122.162.144.145:7726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Q8cJSWzG9jbYOtu4k5QAAAKs"]
[Tue Jul 21 07:58:57.710631 2026] [security2:error] [pid 352421:tid 352642] [client 20.220.225.223:1334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wp-editor.php"] [unique_id "al9Q8cJSWzG9jbYOtu4k5gAAAOA"]
[Tue Jul 21 07:58:57.716777 2026] [security2:error] [pid 352421:tid 352618] [client 20.151.10.161:20428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/adminner.php"] [unique_id "al9Q8cJSWzG9jbYOtu4k5wAAAMg"]
[Tue Jul 21 07:58:57.763260 2026] [security2:error] [pid 352421:tid 352610] [client 103.29.114.44:28950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q8cJSWzG9jbYOtu4k6AAAAMA"]
[Tue Jul 21 07:58:57.763404 2026] [security2:error] [pid 352421:tid 352610] [client 103.29.114.44:28950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q8cJSWzG9jbYOtu4k6AAAAMA"]
[Tue Jul 21 07:58:57.842419 2026] [access_compat:error] [pid 352421:tid 352622] [client 162.241.63.68:36830] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:58:58.020910 2026] [security2:error] [pid 352421:tid 352568] [client 104.207.52.125:61733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9Q8MJSWzG9jbYOtu4kxAAAAJY"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:58:58.135625 2026] [security2:error] [pid 352421:tid 352556] [client 20.151.10.161:20448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/admin.php"] [unique_id "al9Q8sJSWzG9jbYOtu4k9AAAAIo"]
[Tue Jul 21 07:58:58.204994 2026] [security2:error] [pid 352421:tid 352447] [remote 212.80.9.235:45044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Q8sJSWzG9jbYOtu4k9wAA0hk"]
[Tue Jul 21 07:58:58.357627 2026] [security2:error] [pid 352421:tid 352630] [client 103.166.103.129:64735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Q8sJSWzG9jbYOtu4lBwAAANQ"]
[Tue Jul 21 07:58:58.357959 2026] [security2:error] [pid 352421:tid 352630] [client 103.166.103.129:64735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Q8sJSWzG9jbYOtu4lBwAAANQ"]
[Tue Jul 21 07:58:58.458043 2026] [security2:error] [pid 352421:tid 352602] [client 20.151.10.161:20455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/k.php"] [unique_id "al9Q8sJSWzG9jbYOtu4lEAAAALg"]
[Tue Jul 21 07:58:58.494452 2026] [security2:error] [pid 352421:tid 352575] [client 102.206.115.33:61050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Q8sJSWzG9jbYOtu4lEgAAAJ0"]
[Tue Jul 21 07:58:58.494581 2026] [security2:error] [pid 352421:tid 352575] [client 102.206.115.33:61050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Q8sJSWzG9jbYOtu4lEgAAAJ0"]
[Tue Jul 21 07:58:58.527708 2026] [security2:error] [pid 352421:tid 352659] [client 202.143.127.214:59596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q8sJSWzG9jbYOtu4lEwAAAPE"]
[Tue Jul 21 07:58:58.527838 2026] [security2:error] [pid 352421:tid 352659] [client 202.143.127.214:59596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q8sJSWzG9jbYOtu4lEwAAAPE"]
[Tue Jul 21 07:58:58.554546 2026] [security2:error] [pid 352421:tid 352614] [client 184.75.221.3:58836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Q8sJSWzG9jbYOtu4lFwAAAMQ"]
[Tue Jul 21 07:58:58.554667 2026] [security2:error] [pid 352421:tid 352614] [client 184.75.221.3:58836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Q8sJSWzG9jbYOtu4lFwAAAMQ"]
[Tue Jul 21 07:58:58.585921 2026] [security2:error] [pid 352421:tid 352585] [client 20.226.60.151:56777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/777.php"] [unique_id "al9Q8sJSWzG9jbYOtu4lGgAAAKc"]
[Tue Jul 21 07:58:58.928727 2026] [security2:error] [pid 352421:tid 352660] [client 65.21.113.253:43082] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q8sJSWzG9jbYOtu4lEQAAAPI"]
[Tue Jul 21 07:58:58.999290 2026] [security2:error] [pid 352421:tid 352552] [client 20.226.60.151:61566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/file88.php"] [unique_id "al9Q8sJSWzG9jbYOtu4lIwAAAIY"]
[Tue Jul 21 07:58:59.036897 2026] [security2:error] [pid 352421:tid 352590] [client 20.151.10.161:20421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/x.php"] [unique_id "al9Q88JSWzG9jbYOtu4lJQAAAKw"]
[Tue Jul 21 07:58:59.056271 2026] [security2:error] [pid 352421:tid 352638] [client 103.86.117.203:56685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q88JSWzG9jbYOtu4lJwAAANw"]
[Tue Jul 21 07:58:59.056402 2026] [security2:error] [pid 352421:tid 352638] [client 103.86.117.203:56685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q88JSWzG9jbYOtu4lJwAAANw"]
[Tue Jul 21 07:58:59.081316 2026] [security2:error] [pid 352421:tid 352596] [client 74.249.245.134:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/av.php"] [unique_id "al9Q88JSWzG9jbYOtu4lLAAAALI"]
[Tue Jul 21 07:58:59.099654 2026] [security2:error] [pid 352421:tid 352618] [client 45.3.32.194:35295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.32.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9Q88JSWzG9jbYOtu4lLwAAAMg"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:58:59.290769 2026] [security2:error] [pid 352421:tid 352632] [client 122.179.91.63:16057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Q88JSWzG9jbYOtu4lMwAAANY"]
[Tue Jul 21 07:58:59.290886 2026] [security2:error] [pid 352421:tid 352632] [client 122.179.91.63:16057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Q88JSWzG9jbYOtu4lMwAAANY"]
[Tue Jul 21 07:58:59.339431 2026] [security2:error] [pid 352421:tid 352669] [client 20.151.10.161:29109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/eee.php"] [unique_id "al9Q88JSWzG9jbYOtu4lNwAAAPs"]
[Tue Jul 21 07:58:59.348650 2026] [security2:error] [pid 352421:tid 352665] [client 20.151.10.161:20427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wss.php"] [unique_id "al9Q88JSWzG9jbYOtu4lOAAAAPc"]
[Tue Jul 21 07:58:59.527689 2026] [security2:error] [pid 352421:tid 352563] [client 92.119.178.3:42358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Q88JSWzG9jbYOtu4lQAAAAJE"]
[Tue Jul 21 07:58:59.527787 2026] [security2:error] [pid 352421:tid 352563] [client 92.119.178.3:42358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Q88JSWzG9jbYOtu4lQAAAAJE"]
[Tue Jul 21 07:58:59.680970 2026] [security2:error] [pid 352421:tid 352636] [client 20.151.10.161:20445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/ty.php"] [unique_id "al9Q88JSWzG9jbYOtu4lRwAAANo"]
[Tue Jul 21 07:58:59.961429 2026] [security2:error] [pid 352421:tid 352622] [client 20.151.10.161:20356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/155.php"] [unique_id "al9Q88JSWzG9jbYOtu4lTAAAAMw"]
[Tue Jul 21 07:58:59.974736 2026] [security2:error] [pid 352421:tid 352650] [client 20.226.60.151:50625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/for.php"] [unique_id "al9Q88JSWzG9jbYOtu4lTQAAAOg"]
[Tue Jul 21 07:58:59.993568 2026] [security2:error] [pid 352421:tid 352557] [client 4.204.201.85:9619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/122.php"] [unique_id "al9Q88JSWzG9jbYOtu4lTgAAAIs"]
[Tue Jul 21 07:59:00.042261 2026] [security2:error] [pid 352421:tid 352645] [client 141.11.107.74:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.sefacil.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9Q9MJSWzG9jbYOtu4lTwAAAOM"]
[Tue Jul 21 07:59:00.043542 2026] [security2:error] [pid 352421:tid 352674] [client 141.11.107.74:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.sefacil.com.br"] [uri "/"] [unique_id "al9Q9MJSWzG9jbYOtu4lUQAAAQA"]
[Tue Jul 21 07:59:00.065330 2026] [security2:error] [pid 352421:tid 352673] [client 122.164.127.47:60532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Q9MJSWzG9jbYOtu4lUwAAAP8"]
[Tue Jul 21 07:59:00.065420 2026] [security2:error] [pid 352421:tid 352673] [client 122.164.127.47:60532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Q9MJSWzG9jbYOtu4lUwAAAP8"]
[Tue Jul 21 07:59:00.079035 2026] [security2:error] [pid 352421:tid 352553] [client 136.144.33.111:59683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9Q88JSWzG9jbYOtu4lSgAAAIc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:00.327667 2026] [security2:error] [pid 352421:tid 352635] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Q9MJSWzG9jbYOtu4lWwAAANk"]
[Tue Jul 21 07:59:00.349709 2026] [security2:error] [pid 352421:tid 352572] [client 20.151.10.161:20442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/ops.php"] [unique_id "al9Q9MJSWzG9jbYOtu4lXAAAAJo"]
[Tue Jul 21 07:59:00.508370 2026] [security2:error] [pid 352421:tid 352542] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q9MJSWzG9jbYOtu4lXgAAl3g"]
[Tue Jul 21 07:59:00.508592 2026] [security2:error] [pid 352421:tid 352569] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q9MJSWzG9jbYOtu4lXgAAl3g"]
[Tue Jul 21 07:59:00.615214 2026] [security2:error] [pid 352421:tid 352630] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Q9MJSWzG9jbYOtu4lagAAANQ"]
[Tue Jul 21 07:59:00.664113 2026] [security2:error] [pid 352421:tid 352633] [client 20.151.10.161:20353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/ingfo.php"] [unique_id "al9Q9MJSWzG9jbYOtu4lbQAAANc"]
[Tue Jul 21 07:59:00.854902 2026] [security2:error] [pid 352421:tid 352619] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Q9MJSWzG9jbYOtu4ldwAAAMk"]
[Tue Jul 21 07:59:01.050297 2026] [security2:error] [pid 352421:tid 352570] [client 20.151.10.161:20478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/error_log.php"] [unique_id "al9Q9cJSWzG9jbYOtu4legAAAJg"]
[Tue Jul 21 07:59:01.060408 2026] [security2:error] [pid 352421:tid 352559] [client 104.207.60.35:34657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.60.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9Q9MJSWzG9jbYOtu4lUgAAAI0"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:59:01.150275 2026] [security2:error] [pid 352421:tid 352645] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Q9cJSWzG9jbYOtu4lfgAAAOM"]
[Tue Jul 21 07:59:01.178896 2026] [security2:error] [pid 352421:tid 352648] [client 20.220.225.223:1285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/cro.php"] [unique_id "al9Q9cJSWzG9jbYOtu4lgAAAAOY"]
[Tue Jul 21 07:59:01.217904 2026] [security2:error] [pid 352421:tid 352494] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q9cJSWzG9jbYOtu4lgQAA8kg"]
[Tue Jul 21 07:59:01.218100 2026] [security2:error] [pid 352421:tid 352660] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q9cJSWzG9jbYOtu4lgQAA8kg"]
[Tue Jul 21 07:59:01.302420 2026] [security2:error] [pid 352421:tid 352667] [client 117.210.135.0:58371] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q9cJSWzG9jbYOtu4lhQAAAPk"]
[Tue Jul 21 07:59:01.302554 2026] [security2:error] [pid 352421:tid 352667] [client 117.210.135.0:58371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q9cJSWzG9jbYOtu4lhQAAAPk"]
[Tue Jul 21 07:59:01.406674 2026] [security2:error] [pid 352421:tid 352635] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Q9cJSWzG9jbYOtu4ljAAAANk"]
[Tue Jul 21 07:59:01.417421 2026] [security2:error] [pid 352421:tid 352662] [client 65.21.113.253:51372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Q9cJSWzG9jbYOtu4ljgAAAPQ"]
[Tue Jul 21 07:59:01.458640 2026] [security2:error] [pid 352421:tid 352612] [client 20.151.10.161:20423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/ok.php"] [unique_id "al9Q9cJSWzG9jbYOtu4lkAAAAMI"]
[Tue Jul 21 07:59:01.654936 2026] [security2:error] [pid 352421:tid 352633] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Q9cJSWzG9jbYOtu4loAAAANc"]
[Tue Jul 21 07:59:01.738306 2026] [security2:error] [pid 352421:tid 352651] [client 20.151.10.161:20469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/mac.php"] [unique_id "al9Q9cJSWzG9jbYOtu4lpwAAAOk"]
[Tue Jul 21 07:59:01.964131 2026] [security2:error] [pid 352421:tid 352610] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Q9cJSWzG9jbYOtu4lsgAAAMA"]
[Tue Jul 21 07:59:02.078388 2026] [security2:error] [pid 352421:tid 352553] [client 20.151.10.161:20365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wefile.php"] [unique_id "al9Q9sJSWzG9jbYOtu4ltwAAAIc"]
[Tue Jul 21 07:59:02.112186 2026] [security2:error] [pid 352421:tid 352616] [client 41.68.90.219:51249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q9sJSWzG9jbYOtu4luAAAAMY"]
[Tue Jul 21 07:59:02.113289 2026] [security2:error] [pid 352421:tid 352616] [client 41.68.90.219:51249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q9sJSWzG9jbYOtu4luAAAAMY"]
[Tue Jul 21 07:59:02.134543 2026] [security2:error] [pid 352421:tid 352582] [client 65.21.113.253:43082] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q9cJSWzG9jbYOtu4lnAAAAKQ"]
[Tue Jul 21 07:59:02.239760 2026] [security2:error] [pid 352421:tid 352635] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Q9sJSWzG9jbYOtu4lvwAAANk"]
[Tue Jul 21 07:59:02.308646 2026] [security2:error] [pid 352421:tid 352642] [client 4.204.201.85:61629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/get.php"] [unique_id "al9Q9sJSWzG9jbYOtu4lwAAAAOA"]
[Tue Jul 21 07:59:02.368863 2026] [security2:error] [pid 352421:tid 352628] [client 20.226.60.151:50635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/ssla.php"] [unique_id "al9Q9sJSWzG9jbYOtu4lwQAAANI"]
[Tue Jul 21 07:59:02.381568 2026] [security2:error] [pid 352421:tid 352674] [client 20.220.225.223:1804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/cron-tab.php"] [unique_id "al9Q9sJSWzG9jbYOtu4lwgAAAQA"]
[Tue Jul 21 07:59:02.447707 2026] [security2:error] [pid 352421:tid 352602] [client 20.151.10.161:20420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9Q9sJSWzG9jbYOtu4lxgAAALg"]
[Tue Jul 21 07:59:02.550809 2026] [security2:error] [pid 352421:tid 352589] [client 178.153.91.96:12227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q9sJSWzG9jbYOtu4lyAAAAKs"]
[Tue Jul 21 07:59:02.550939 2026] [security2:error] [pid 352421:tid 352589] [client 178.153.91.96:12227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q9sJSWzG9jbYOtu4lyAAAAKs"]
[Tue Jul 21 07:59:02.558403 2026] [security2:error] [pid 352421:tid 352566] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Q9sJSWzG9jbYOtu4lyQAAAJQ"]
[Tue Jul 21 07:59:02.742972 2026] [security2:error] [pid 352421:tid 352629] [client 89.19.88.156:16784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "carolinadona.com"] [uri "/labs/"] [unique_id "al9Q9sJSWzG9jbYOtu4l0gAAANM"]
[Tue Jul 21 07:59:02.902893 2026] [proxy:error] [pid 352421:tid 352619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:02.902928 2026] [proxy_http:error] [pid 352421:tid 352619] [client 20.151.10.161:20359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:02.903519 2026] [proxy:error] [pid 352421:tid 352619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:02.903542 2026] [proxy_http:error] [pid 352421:tid 352619] [client 20.151.10.161:20359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:02.928458 2026] [security2:error] [pid 352421:tid 352595] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Q9sJSWzG9jbYOtu4l2QAAALE"]
[Tue Jul 21 07:59:03.115618 2026] [security2:error] [pid 352421:tid 352541] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Q98JSWzG9jbYOtu4l3wAA6nc"]
[Tue Jul 21 07:59:03.115737 2026] [security2:error] [pid 352421:tid 352652] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9Q98JSWzG9jbYOtu4l3wAA6nc"]
[Tue Jul 21 07:59:03.195964 2026] [security2:error] [pid 352421:tid 352553] [client 20.151.10.161:28723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/file25.php"] [unique_id "al9Q98JSWzG9jbYOtu4l5AAAAIc"]
[Tue Jul 21 07:59:03.226426 2026] [security2:error] [pid 352421:tid 352552] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Q98JSWzG9jbYOtu4l6AAAAIY"]
[Tue Jul 21 07:59:03.302607 2026] [proxy:error] [pid 352421:tid 352616] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:03.302698 2026] [proxy_http:error] [pid 352421:tid 352616] [client 20.151.10.161:20372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:03.303372 2026] [proxy:error] [pid 352421:tid 352616] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:03.303415 2026] [proxy_http:error] [pid 352421:tid 352616] [client 20.151.10.161:20372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:03.353001 2026] [security2:error] [pid 352421:tid 352582] [client 20.220.225.223:1289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/koiy.php"] [unique_id "al9Q98JSWzG9jbYOtu4l7gAAAKQ"]
[Tue Jul 21 07:59:03.363232 2026] [security2:error] [pid 352421:tid 352661] [client 38.100.221.102:17238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q98JSWzG9jbYOtu4l7wAAAPM"]
[Tue Jul 21 07:59:03.363619 2026] [security2:error] [pid 352421:tid 352661] [client 38.100.221.102:17238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q98JSWzG9jbYOtu4l7wAAAPM"]
[Tue Jul 21 07:59:03.456133 2026] [http2:info] [pid 352421:tid 352626] [client 104.22.10.132:12569] AH10180: h2_stream(352421-324-1,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 07:59:03.544695 2026] [security2:error] [pid 352421:tid 352647] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.luisursulinodesantan1753370147934.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Q98JSWzG9jbYOtu4l9QAAAOU"]
[Tue Jul 21 07:59:03.609542 2026] [security2:error] [pid 352421:tid 352592] [client 20.151.10.161:20449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Q98JSWzG9jbYOtu4l9wAAAK4"]
[Tue Jul 21 07:59:03.625054 2026] [security2:error] [pid 352421:tid 352657] [client 20.226.60.151:56739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "factorial.studio"] [uri "/zc-131.php"] [unique_id "al9Q98JSWzG9jbYOtu4l-AAAAO8"]
[Tue Jul 21 07:59:03.757096 2026] [security2:error] [pid 352421:tid 352475] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Q98JSWzG9jbYOtu4mAwAA5DU"]
[Tue Jul 21 07:59:03.757268 2026] [security2:error] [pid 352421:tid 352646] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Q98JSWzG9jbYOtu4mAwAA5DU"]
[Tue Jul 21 07:59:03.769963 2026] [security2:error] [pid 352421:tid 352610] [client 182.8.255.181:2893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Q98JSWzG9jbYOtu4mBAAAAMA"]
[Tue Jul 21 07:59:03.770128 2026] [security2:error] [pid 352421:tid 352610] [client 182.8.255.181:2893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Q98JSWzG9jbYOtu4mBAAAAMA"]
[Tue Jul 21 07:59:03.913674 2026] [proxy:error] [pid 352421:tid 352655] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:03.913757 2026] [proxy_http:error] [pid 352421:tid 352655] [client 20.151.10.161:20376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:03.914437 2026] [proxy:error] [pid 352421:tid 352655] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:03.914466 2026] [proxy_http:error] [pid 352421:tid 352655] [client 20.151.10.161:20376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:04.113038 2026] [security2:error] [pid 352421:tid 352439] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q-MJSWzG9jbYOtu4mDwAArxE"]
[Tue Jul 21 07:59:04.113171 2026] [security2:error] [pid 352421:tid 352593] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q-MJSWzG9jbYOtu4mDwAArxE"]
[Tue Jul 21 07:59:04.141572 2026] [security2:error] [pid 352421:tid 352562] [client 59.93.4.33:50772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q-MJSWzG9jbYOtu4mEAAAAJA"]
[Tue Jul 21 07:59:04.141683 2026] [security2:error] [pid 352421:tid 352562] [client 59.93.4.33:50772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q-MJSWzG9jbYOtu4mEAAAAJA"]
[Tue Jul 21 07:59:04.204630 2026] [security2:error] [pid 352421:tid 352469] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Q-MJSWzG9jbYOtu4mFwAAtS8"]
[Tue Jul 21 07:59:04.204768 2026] [security2:error] [pid 352421:tid 352599] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Q-MJSWzG9jbYOtu4mFwAAtS8"]
[Tue Jul 21 07:59:04.408961 2026] [security2:error] [pid 352421:tid 352425] [remote 81.173.115.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "annaguimaraes.com.br"] [uri "/wp-login.php"] [unique_id "al9Q-MJSWzG9jbYOtu4mHgAAxQM"]
[Tue Jul 21 07:59:04.446158 2026] [security2:error] [pid 352421:tid 352622] [client 20.151.10.161:20479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/like.php"] [unique_id "al9Q-MJSWzG9jbYOtu4mIAAAAMw"]
[Tue Jul 21 07:59:04.667641 2026] [security2:error] [pid 352421:tid 352561] [client 117.247.80.59:22710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q-MJSWzG9jbYOtu4mJgAAAI8"]
[Tue Jul 21 07:59:04.667784 2026] [security2:error] [pid 352421:tid 352561] [client 117.247.80.59:22710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q-MJSWzG9jbYOtu4mJgAAAI8"]
[Tue Jul 21 07:59:04.702967 2026] [security2:error] [pid 352421:tid 352611] [client 65.21.113.253:51372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Q-MJSWzG9jbYOtu4mJwAAAME"]
[Tue Jul 21 07:59:04.715482 2026] [security2:error] [pid 352421:tid 352585] [client 193.36.225.11:56895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Q-MJSWzG9jbYOtu4mKgAAAKc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:04.715791 2026] [security2:error] [pid 352421:tid 352608] [client 109.60.28.94:63790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q-MJSWzG9jbYOtu4mKwAAAL4"]
[Tue Jul 21 07:59:04.715918 2026] [security2:error] [pid 352421:tid 352608] [client 109.60.28.94:63790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q-MJSWzG9jbYOtu4mKwAAAL4"]
[Tue Jul 21 07:59:04.781328 2026] [security2:error] [pid 352421:tid 352613] [client 20.151.10.161:20463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Q-MJSWzG9jbYOtu4mLgAAAMM"]
[Tue Jul 21 07:59:05.165606 2026] [security2:error] [pid 352421:tid 352629] [client 20.151.10.161:20432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Q-cJSWzG9jbYOtu4mPQAAANM"]
[Tue Jul 21 07:59:05.324179 2026] [security2:error] [pid 352421:tid 352665] [client 37.140.223.158:41611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Q-cJSWzG9jbYOtu4mOwAAAPc"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:59:05.545486 2026] [proxy:error] [pid 352421:tid 352603] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:05.545580 2026] [proxy_http:error] [pid 352421:tid 352603] [client 20.151.10.161:20374] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:05.547041 2026] [proxy:error] [pid 352421:tid 352603] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:05.547086 2026] [proxy_http:error] [pid 352421:tid 352603] [client 20.151.10.161:20374] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:05.692137 2026] [security2:error] [pid 352421:tid 352463] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q-cJSWzG9jbYOtu4mUAAAxik"]
[Tue Jul 21 07:59:05.692292 2026] [security2:error] [pid 352421:tid 352616] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q-cJSWzG9jbYOtu4mUAAAxik"]
[Tue Jul 21 07:59:05.770507 2026] [security2:error] [pid 352421:tid 352612] [client 20.220.225.223:1802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/hp2.php"] [unique_id "al9Q-cJSWzG9jbYOtu4mUgAAAMI"]
[Tue Jul 21 07:59:05.775803 2026] [security2:error] [pid 352421:tid 352609] [client 20.226.60.151:61525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/ccc.php"] [unique_id "al9Q-cJSWzG9jbYOtu4mUwAAAL8"]
[Tue Jul 21 07:59:05.783581 2026] [security2:error] [pid 352421:tid 352562] [client 65.21.113.253:32902] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q-cJSWzG9jbYOtu4mRAAAAJA"]
[Tue Jul 21 07:59:05.924940 2026] [security2:error] [pid 352421:tid 352574] [client 4.204.201.85:9554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/as.php"] [unique_id "al9Q-cJSWzG9jbYOtu4mXQAAAJw"]
[Tue Jul 21 07:59:05.959007 2026] [security2:error] [pid 352421:tid 352579] [client 87.186.29.230:46899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "carolinadona.com"] [uri "/labs/"] [unique_id "al9Q-cJSWzG9jbYOtu4mXgAAAKE"]
[Tue Jul 21 07:59:05.974249 2026] [proxy:error] [pid 352421:tid 352566] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:05.974325 2026] [proxy_http:error] [pid 352421:tid 352566] [client 20.151.10.161:20436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:05.975075 2026] [proxy:error] [pid 352421:tid 352566] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:05.975105 2026] [proxy_http:error] [pid 352421:tid 352566] [client 20.151.10.161:20436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:06.090247 2026] [security2:error] [pid 352421:tid 352613] [client 20.220.225.223:1834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/hp3.php"] [unique_id "al9Q-sJSWzG9jbYOtu4mYQAAAMM"]
[Tue Jul 21 07:59:06.176875 2026] [security2:error] [pid 352421:tid 352520] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Q-sJSWzG9jbYOtu4mYwAA5WI"]
[Tue Jul 21 07:59:06.177091 2026] [security2:error] [pid 352421:tid 352647] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Q-sJSWzG9jbYOtu4mYwAA5WI"]
[Tue Jul 21 07:59:06.227038 2026] [security2:error] [pid 352421:tid 352553] [client 223.236.153.128:1915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Q-sJSWzG9jbYOtu4maAAAAIc"]
[Tue Jul 21 07:59:06.227167 2026] [security2:error] [pid 352421:tid 352553] [client 223.236.153.128:1915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9Q-sJSWzG9jbYOtu4maAAAAIc"]
[Tue Jul 21 07:59:06.273494 2026] [security2:error] [pid 352421:tid 352633] [client 20.151.10.161:29112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/file48.php"] [unique_id "al9Q-sJSWzG9jbYOtu4maQAAANc"]
[Tue Jul 21 07:59:06.578069 2026] [security2:error] [pid 352421:tid 352650] [client 20.104.96.117:46699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xyn.php"] [unique_id "al9Q-sJSWzG9jbYOtu4mcgAAAOg"]
[Tue Jul 21 07:59:06.637240 2026] [security2:error] [pid 352421:tid 352665] [client 20.151.10.161:20453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/pucci.php"] [unique_id "al9Q-sJSWzG9jbYOtu4mcwAAAPc"]
[Tue Jul 21 07:59:06.700551 2026] [core:error] [pid 352421:tid 352525] [remote 87.250.224.211:40896] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:59:06.700577 2026] [core:error] [pid 352421:tid 352525] [remote 87.250.224.211:40896] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:59:06.767790 2026] [security2:error] [pid 352421:tid 352594] [client 87.116.180.198:27142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q-sJSWzG9jbYOtu4mewAAALA"]
[Tue Jul 21 07:59:06.767951 2026] [security2:error] [pid 352421:tid 352594] [client 87.116.180.198:27142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q-sJSWzG9jbYOtu4mewAAALA"]
[Tue Jul 21 07:59:06.835983 2026] [security2:error] [pid 352421:tid 352623] [client 20.220.225.223:1320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/aa1.php"] [unique_id "al9Q-sJSWzG9jbYOtu4mfQAAAM0"]
[Tue Jul 21 07:59:07.110950 2026] [proxy:error] [pid 352421:tid 352628] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:07.111033 2026] [proxy_http:error] [pid 352421:tid 352628] [client 20.151.10.161:20361] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:07.111670 2026] [proxy:error] [pid 352421:tid 352628] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:07.111697 2026] [proxy_http:error] [pid 352421:tid 352628] [client 20.151.10.161:20361] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:07.170173 2026] [security2:error] [pid 352421:tid 352629] [client 106.215.181.8:26307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q-8JSWzG9jbYOtu4mhgAAANM"]
[Tue Jul 21 07:59:07.170308 2026] [security2:error] [pid 352421:tid 352629] [client 106.215.181.8:26307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q-8JSWzG9jbYOtu4mhgAAANM"]
[Tue Jul 21 07:59:07.190988 2026] [security2:error] [pid 352421:tid 352577] [client 65.21.113.253:32916] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q-sJSWzG9jbYOtu4mdwAAAJ8"]
[Tue Jul 21 07:59:07.227523 2026] [security2:error] [pid 352421:tid 352648] [client 65.21.113.253:51372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Q-8JSWzG9jbYOtu4migAAAOY"]
[Tue Jul 21 07:59:07.394939 2026] [proxy:error] [pid 352421:tid 352619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:07.395015 2026] [proxy_http:error] [pid 352421:tid 352619] [client 20.151.10.161:20430] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:07.395574 2026] [proxy:error] [pid 352421:tid 352619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:07.395602 2026] [proxy_http:error] [pid 352421:tid 352619] [client 20.151.10.161:20430] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:07.683904 2026] [security2:error] [pid 352421:tid 352580] [client 20.151.10.161:20426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wp-temp.php"] [unique_id "al9Q-8JSWzG9jbYOtu4mlAAAAKI"]
[Tue Jul 21 07:59:07.984555 2026] [proxy:error] [pid 352421:tid 352660] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:07.984628 2026] [proxy_http:error] [pid 352421:tid 352660] [client 20.151.10.161:20319] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:07.985136 2026] [proxy:error] [pid 352421:tid 352660] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:07.985162 2026] [proxy_http:error] [pid 352421:tid 352660] [client 20.151.10.161:20319] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:08.035305 2026] [security2:error] [pid 352421:tid 352597] [client 103.78.200.11:60346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q_MJSWzG9jbYOtu4moQAAALM"]
[Tue Jul 21 07:59:08.035885 2026] [security2:error] [pid 352421:tid 352597] [client 103.78.200.11:60346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q_MJSWzG9jbYOtu4moQAAALM"]
[Tue Jul 21 07:59:08.182970 2026] [security2:error] [pid 352421:tid 352556] [client 20.220.225.223:1319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/acew67.php"] [unique_id "al9Q_MJSWzG9jbYOtu4mqQAAAIo"]
[Tue Jul 21 07:59:08.302511 2026] [security2:error] [pid 352421:tid 352593] [client 65.21.113.253:32932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q-8JSWzG9jbYOtu4mnAAAAK8"]
[Tue Jul 21 07:59:08.331733 2026] [security2:error] [pid 352421:tid 352612] [client 20.151.10.161:20447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/xmu.php"] [unique_id "al9Q_MJSWzG9jbYOtu4msgAAAMI"]
[Tue Jul 21 07:59:08.387493 2026] [security2:error] [pid 352421:tid 352581] [client 20.104.96.117:46614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/patie.php"] [unique_id "al9Q_MJSWzG9jbYOtu4mtAAAAKM"]
[Tue Jul 21 07:59:08.435631 2026] [security2:error] [pid 352421:tid 352658] [client 122.162.144.145:21557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Q_MJSWzG9jbYOtu4muAAAAPA"]
[Tue Jul 21 07:59:08.435771 2026] [security2:error] [pid 352421:tid 352658] [client 122.162.144.145:21557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9Q_MJSWzG9jbYOtu4muAAAAPA"]
[Tue Jul 21 07:59:08.506672 2026] [security2:error] [pid 352421:tid 352669] [client 103.29.114.44:54071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q_MJSWzG9jbYOtu4mugAAAPs"]
[Tue Jul 21 07:59:08.506787 2026] [security2:error] [pid 352421:tid 352669] [client 103.29.114.44:54071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q_MJSWzG9jbYOtu4mugAAAPs"]
[Tue Jul 21 07:59:08.559298 2026] [security2:error] [pid 352421:tid 352640] [client 20.226.60.151:61617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/777.php"] [unique_id "al9Q_MJSWzG9jbYOtu4mvAAAAN4"]
[Tue Jul 21 07:59:08.661859 2026] [security2:error] [pid 352421:tid 352621] [client 193.36.225.102:37181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Q_MJSWzG9jbYOtu4mwQAAAMs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:59:08.698883 2026] [security2:error] [pid 352421:tid 352608] [client 20.151.10.161:20441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9Q_MJSWzG9jbYOtu4mwgAAAL4"]
[Tue Jul 21 07:59:08.711528 2026] [security2:error] [pid 352421:tid 352642] [client 20.104.96.117:46660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/aa.php"] [unique_id "al9Q_MJSWzG9jbYOtu4mwwAAAOA"]
[Tue Jul 21 07:59:08.778153 2026] [security2:error] [pid 352421:tid 352610] [client 20.151.10.161:29224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/file6.php"] [unique_id "al9Q_MJSWzG9jbYOtu4myQAAAMA"]
[Tue Jul 21 07:59:08.961316 2026] [security2:error] [pid 352421:tid 352558] [client 103.166.103.129:1043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Q_MJSWzG9jbYOtu4m0gAAAIw"]
[Tue Jul 21 07:59:08.961484 2026] [security2:error] [pid 352421:tid 352558] [client 103.166.103.129:1043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Q_MJSWzG9jbYOtu4m0gAAAIw"]
[Tue Jul 21 07:59:08.987446 2026] [security2:error] [pid 352421:tid 352564] [client 102.206.115.33:64409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Q_MJSWzG9jbYOtu4m1QAAAJI"]
[Tue Jul 21 07:59:08.987584 2026] [security2:error] [pid 352421:tid 352564] [client 102.206.115.33:64409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Q_MJSWzG9jbYOtu4m1QAAAJI"]
[Tue Jul 21 07:59:09.253294 2026] [security2:error] [pid 352421:tid 352673] [client 47.128.58.61:43462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "combolog.com.br"] [uri "/robots.txt"] [unique_id "al9Q_cJSWzG9jbYOtu4m3gAAAP8"]
[Tue Jul 21 07:59:09.274326 2026] [security2:error] [pid 352421:tid 352603] [client 20.151.10.161:20439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/puc.php"] [unique_id "al9Q_cJSWzG9jbYOtu4m4gAAALk"]
[Tue Jul 21 07:59:09.375878 2026] [security2:error] [pid 352421:tid 352674] [client 74.249.245.134:62890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/gg.php"] [unique_id "al9Q_cJSWzG9jbYOtu4m5gAAAQA"]
[Tue Jul 21 07:59:09.376744 2026] [security2:error] [pid 352421:tid 352581] [client 204.8.98.45:55460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Q_cJSWzG9jbYOtu4m5wAAAKM"]
[Tue Jul 21 07:59:09.376853 2026] [security2:error] [pid 352421:tid 352581] [client 204.8.98.45:55460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Q_cJSWzG9jbYOtu4m5wAAAKM"]
[Tue Jul 21 07:59:09.553343 2026] [security2:error] [pid 352421:tid 352578] [client 103.86.117.203:57235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q_cJSWzG9jbYOtu4m9AAAAKA"]
[Tue Jul 21 07:59:09.553497 2026] [security2:error] [pid 352421:tid 352578] [client 103.86.117.203:57235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Q_cJSWzG9jbYOtu4m9AAAAKA"]
[Tue Jul 21 07:59:09.655519 2026] [security2:error] [pid 352421:tid 352588] [client 202.143.127.214:60076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q_cJSWzG9jbYOtu4m9QAAAKo"]
[Tue Jul 21 07:59:09.655725 2026] [security2:error] [pid 352421:tid 352588] [client 202.143.127.214:60076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q_cJSWzG9jbYOtu4m9QAAAKo"]
[Tue Jul 21 07:59:09.701731 2026] [security2:error] [pid 352421:tid 352617] [client 136.144.33.100:33263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Q_cJSWzG9jbYOtu4nAQAAAMc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:09.740398 2026] [security2:error] [pid 352421:tid 352599] [client 20.151.10.161:20434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/themes.php"] [unique_id "al9Q_cJSWzG9jbYOtu4nFwAAALU"]
[Tue Jul 21 07:59:09.742191 2026] [security2:error] [pid 352421:tid 352591] [client 20.104.96.117:46618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xwpg.php"] [unique_id "al9Q_cJSWzG9jbYOtu4nGAAAAK0"]
[Tue Jul 21 07:59:09.756275 2026] [security2:error] [pid 352421:tid 352668] [client 20.226.60.151:61579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/for.php"] [unique_id "al9Q_cJSWzG9jbYOtu4nGQAAAPo"]
[Tue Jul 21 07:59:09.862159 2026] [security2:error] [pid 352421:tid 352585] [client 122.179.91.63:13267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Q_cJSWzG9jbYOtu4nHQAAAKc"]
[Tue Jul 21 07:59:09.862279 2026] [security2:error] [pid 352421:tid 352585] [client 122.179.91.63:13267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9Q_cJSWzG9jbYOtu4nHQAAAKc"]
[Tue Jul 21 07:59:09.867692 2026] [security2:error] [pid 352421:tid 352650] [client 20.226.60.151:64967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/root.php"] [unique_id "al9Q_cJSWzG9jbYOtu4nHgAAAOg"]
[Tue Jul 21 07:59:09.898774 2026] [security2:error] [pid 352421:tid 352676] [client 4.204.201.85:9648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/ccou.php"] [unique_id "al9Q_cJSWzG9jbYOtu4nHwAAAQI"]
[Tue Jul 21 07:59:10.137483 2026] [proxy:error] [pid 352421:tid 352677] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:10.137563 2026] [proxy_http:error] [pid 352421:tid 352677] [client 20.151.10.161:20390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:10.138212 2026] [proxy:error] [pid 352421:tid 352677] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:10.138239 2026] [proxy_http:error] [pid 352421:tid 352677] [client 20.151.10.161:20390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:10.383519 2026] [security2:error] [pid 352421:tid 352598] [client 20.220.225.223:1820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/bscclapb.php"] [unique_id "al9Q_sJSWzG9jbYOtu4nPQAAALQ"]
[Tue Jul 21 07:59:10.433456 2026] [security2:error] [pid 352421:tid 352638] [client 20.151.10.161:20392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/8.php"] [unique_id "al9Q_sJSWzG9jbYOtu4nQgAAANw"]
[Tue Jul 21 07:59:10.618143 2026] [security2:error] [pid 352421:tid 352551] [client 122.164.127.47:61107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Q_sJSWzG9jbYOtu4nSQAAAIU"]
[Tue Jul 21 07:59:10.618253 2026] [security2:error] [pid 352421:tid 352551] [client 122.164.127.47:61107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Q_sJSWzG9jbYOtu4nSQAAAIU"]
[Tue Jul 21 07:59:10.686359 2026] [security2:error] [pid 352421:tid 352583] [client 20.104.96.117:46664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/ops.php"] [unique_id "al9Q_sJSWzG9jbYOtu4nSwAAAKU"]
[Tue Jul 21 07:59:11.247619 2026] [security2:error] [pid 352421:tid 352560] [client 20.151.10.161:20474] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/1.php"] [unique_id "al9Q_8JSWzG9jbYOtu4nVgAAAI4"]
[Tue Jul 21 07:59:11.247722 2026] [security2:error] [pid 352421:tid 352560] [client 20.151.10.161:20474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/1.php"] [unique_id "al9Q_8JSWzG9jbYOtu4nVgAAAI4"]
[Tue Jul 21 07:59:11.336149 2026] [security2:error] [pid 352421:tid 352423] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q_8JSWzG9jbYOtu4nWwAA6QE"]
[Tue Jul 21 07:59:11.336345 2026] [security2:error] [pid 352421:tid 352651] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q_8JSWzG9jbYOtu4nWwAA6QE"]
[Tue Jul 21 07:59:11.532711 2026] [security2:error] [pid 352421:tid 352604] [client 65.21.113.253:51372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Q_8JSWzG9jbYOtu4nZAAAALo"]
[Tue Jul 21 07:59:11.731324 2026] [security2:error] [pid 352421:tid 352632] [client 20.151.10.161:20476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/100.php"] [unique_id "al9Q_8JSWzG9jbYOtu4nbAAAANY"]
[Tue Jul 21 07:59:11.779702 2026] [security2:error] [pid 352421:tid 352531] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q_8JSWzG9jbYOtu4nbgAAyG0"]
[Tue Jul 21 07:59:11.779911 2026] [security2:error] [pid 352421:tid 352618] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Q_8JSWzG9jbYOtu4nbgAAyG0"]
[Tue Jul 21 07:59:11.974711 2026] [security2:error] [pid 352421:tid 352590] [client 4.204.201.85:61577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/w3lls.php"] [unique_id "al9Q_8JSWzG9jbYOtu4newAAAKw"]
[Tue Jul 21 07:59:12.033719 2026] [security2:error] [pid 352421:tid 352636] [client 193.36.225.96:43989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9Q_8JSWzG9jbYOtu4ndAAAANo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:59:12.139951 2026] [security2:error] [pid 352421:tid 352609] [client 117.210.135.0:59099] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RAMJSWzG9jbYOtu4nfwAAAL8"]
[Tue Jul 21 07:59:12.140081 2026] [security2:error] [pid 352421:tid 352609] [client 117.210.135.0:59099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RAMJSWzG9jbYOtu4nfwAAAL8"]
[Tue Jul 21 07:59:12.166710 2026] [security2:error] [pid 352421:tid 352558] [client 74.249.245.134:17441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/sql.php"] [unique_id "al9RAMJSWzG9jbYOtu4nggAAAIw"]
[Tue Jul 21 07:59:12.167116 2026] [security2:error] [pid 352421:tid 352640] [client 65.21.113.253:32916] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Q_8JSWzG9jbYOtu4nbQAAAN4"]
[Tue Jul 21 07:59:12.310065 2026] [security2:error] [pid 352421:tid 352585] [client 20.226.60.151:61543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/ssla.php"] [unique_id "al9RAMJSWzG9jbYOtu4nhAAAAKc"]
[Tue Jul 21 07:59:12.356603 2026] [security2:error] [pid 352421:tid 352634] [client 20.104.96.117:46597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/mac.php"] [unique_id "al9RAMJSWzG9jbYOtu4nhQAAANg"]
[Tue Jul 21 07:59:12.461674 2026] [security2:error] [pid 352421:tid 352652] [client 20.151.10.161:20397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/about.php"] [unique_id "al9RAMJSWzG9jbYOtu4nhgAAAOo"]
[Tue Jul 21 07:59:12.593007 2026] [security2:error] [pid 352421:tid 352623] [client 41.68.90.219:51706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RAMJSWzG9jbYOtu4njQAAAM0"]
[Tue Jul 21 07:59:12.594228 2026] [security2:error] [pid 352421:tid 352623] [client 41.68.90.219:51706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RAMJSWzG9jbYOtu4njQAAAM0"]
[Tue Jul 21 07:59:13.002920 2026] [security2:error] [pid 352421:tid 352665] [client 20.104.96.117:46709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/mg.php"] [unique_id "al9RAcJSWzG9jbYOtu4nnwAAAPc"]
[Tue Jul 21 07:59:13.024563 2026] [security2:error] [pid 352421:tid 352596] [client 20.151.10.161:20443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/about.php"] [unique_id "al9RAcJSWzG9jbYOtu4noQAAALI"]
[Tue Jul 21 07:59:13.108339 2026] [security2:error] [pid 352421:tid 352628] [client 91.92.47.101:41774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/database.php"] [unique_id "al9RAcJSWzG9jbYOtu4nqAAAANI"], referer: http://sigmas.app.br/
[Tue Jul 21 07:59:13.108554 2026] [security2:error] [pid 352421:tid 352616] [client 178.153.91.96:52480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RAcJSWzG9jbYOtu4nqgAAAMY"]
[Tue Jul 21 07:59:13.108690 2026] [security2:error] [pid 352421:tid 352616] [client 178.153.91.96:52480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RAcJSWzG9jbYOtu4nqgAAAMY"]
[Tue Jul 21 07:59:13.202391 2026] [security2:error] [pid 352421:tid 352567] [client 65.21.113.253:34380] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RAMJSWzG9jbYOtu4nmAAAAJU"]
[Tue Jul 21 07:59:13.306828 2026] [security2:error] [pid 352421:tid 352494] [remote 216.73.216.75:52597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rgagestaodecondominios.adm.br"] [uri "/xmlrpc.php"] [unique_id "al9Q_8JSWzG9jbYOtu4negAAiUg"]
[Tue Jul 21 07:59:13.309062 2026] [security2:error] [pid 352421:tid 352667] [client 91.92.47.101:41790] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "sigmas.app.br"] [uri "/.env.bak"] [unique_id "al9RAcJSWzG9jbYOtu4nsgAAAPk"], referer: http://sigmas.app.br/
[Tue Jul 21 07:59:13.331528 2026] [security2:error] [pid 352421:tid 352565] [client 91.92.47.101:41804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/settings.php"] [unique_id "al9RAcJSWzG9jbYOtu4ntAAAAJM"], referer: http://sigmas.app.br/
[Tue Jul 21 07:59:13.333066 2026] [security2:error] [pid 352421:tid 352666] [client 91.92.47.101:41798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "sigmas.app.br"] [uri "/web.config"] [unique_id "al9RAcJSWzG9jbYOtu4ntQAAAPg"], referer: http://sigmas.app.br/
[Tue Jul 21 07:59:13.340373 2026] [security2:error] [pid 352421:tid 352583] [client 172.245.102.45:35109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RAcJSWzG9jbYOtu4nrgAAAKU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:13.482950 2026] [security2:error] [pid 352421:tid 352668] [client 91.92.47.101:41766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/db.php"] [unique_id "al9RAcJSWzG9jbYOtu4ntgAAAPo"], referer: http://sigmas.app.br/
[Tue Jul 21 07:59:13.679410 2026] [security2:error] [pid 352421:tid 352552] [client 20.151.10.161:20470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/admin.php"] [unique_id "al9RAcJSWzG9jbYOtu4nvQAAAIY"]
[Tue Jul 21 07:59:13.772895 2026] [security2:error] [pid 352421:tid 352466] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RAcJSWzG9jbYOtu4nxwAAqCw"]
[Tue Jul 21 07:59:13.773061 2026] [security2:error] [pid 352421:tid 352586] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RAcJSWzG9jbYOtu4nxwAAqCw"]
[Tue Jul 21 07:59:13.820501 2026] [security2:error] [pid 352421:tid 352654] [client 20.226.60.151:53980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avermetais.com.br"] [uri "/zc-131.php"] [unique_id "al9RAcJSWzG9jbYOtu4nyAAAAOw"]
[Tue Jul 21 07:59:13.923731 2026] [security2:error] [pid 352421:tid 352571] [client 38.100.221.102:17805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RAcJSWzG9jbYOtu4nywAAAJk"]
[Tue Jul 21 07:59:13.923852 2026] [security2:error] [pid 352421:tid 352571] [client 38.100.221.102:17805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RAcJSWzG9jbYOtu4nywAAAJk"]
[Tue Jul 21 07:59:13.987211 2026] [security2:error] [pid 352421:tid 352620] [client 20.104.96.117:46676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-post-data.php"] [unique_id "al9RAcJSWzG9jbYOtu4n0AAAAMo"]
[Tue Jul 21 07:59:14.129293 2026] [security2:error] [pid 352421:tid 352578] [client 182.8.255.181:21237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RAsJSWzG9jbYOtu4n0wAAAKA"]
[Tue Jul 21 07:59:14.129419 2026] [security2:error] [pid 352421:tid 352578] [client 182.8.255.181:21237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RAsJSWzG9jbYOtu4n0wAAAKA"]
[Tue Jul 21 07:59:14.178446 2026] [autoindex:error] [pid 352421:tid 352541] [remote 74.7.243.247:46040] AH01276: Cannot serve directory /home1/pedid516/cursodepilacaoprofissional.pedido-online.net/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:59:14.325443 2026] [security2:error] [pid 352421:tid 352590] [client 20.151.10.161:20454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/admin.php"] [unique_id "al9RAsJSWzG9jbYOtu4n2gAAAKw"]
[Tue Jul 21 07:59:14.442424 2026] [security2:error] [pid 352421:tid 352446] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RAsJSWzG9jbYOtu4n2wAA7Rg"]
[Tue Jul 21 07:59:14.442548 2026] [security2:error] [pid 352421:tid 352655] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RAsJSWzG9jbYOtu4n2wAA7Rg"]
[Tue Jul 21 07:59:14.613684 2026] [security2:error] [pid 352421:tid 352663] [client 74.7.241.153:57218] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.cursodepilacaoprofissional.pedido-online.net"] [uri "/cgi-sys/404.html"] [unique_id "al9RAsJSWzG9jbYOtu4n4wAA9Q8"]
[Tue Jul 21 07:59:14.620528 2026] [security2:error] [pid 352421:tid 352468] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RAsJSWzG9jbYOtu4n5AAA1y4"]
[Tue Jul 21 07:59:14.620643 2026] [security2:error] [pid 352421:tid 352633] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RAsJSWzG9jbYOtu4n5AAA1y4"]
[Tue Jul 21 07:59:14.641778 2026] [security2:error] [pid 352421:tid 352630] [client 20.151.10.161:28820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/a2.php"] [unique_id "al9RAsJSWzG9jbYOtu4n5QAAANQ"]
[Tue Jul 21 07:59:14.726518 2026] [security2:error] [pid 352421:tid 352487] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RAsJSWzG9jbYOtu4n6QAAwkE"]
[Tue Jul 21 07:59:14.726719 2026] [security2:error] [pid 352421:tid 352612] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RAsJSWzG9jbYOtu4n6QAAwkE"]
[Tue Jul 21 07:59:14.755034 2026] [security2:error] [pid 352421:tid 352647] [client 4.204.201.85:61578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/test1.php"] [unique_id "al9RAsJSWzG9jbYOtu4n6wAAAOU"]
[Tue Jul 21 07:59:14.807802 2026] [security2:error] [pid 352421:tid 352556] [client 92.119.178.3:51580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9RAsJSWzG9jbYOtu4n7gAAAIo"]
[Tue Jul 21 07:59:14.807963 2026] [security2:error] [pid 352421:tid 352556] [client 92.119.178.3:51580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9RAsJSWzG9jbYOtu4n7gAAAIo"]
[Tue Jul 21 07:59:14.809392 2026] [security2:error] [pid 352421:tid 352601] [client 20.151.10.161:20438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/edit.php"] [unique_id "al9RAsJSWzG9jbYOtu4n7wAAALc"]
[Tue Jul 21 07:59:14.851305 2026] [security2:error] [pid 352421:tid 352670] [client 59.93.4.33:51297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RAsJSWzG9jbYOtu4n8QAAAPw"]
[Tue Jul 21 07:59:14.851422 2026] [security2:error] [pid 352421:tid 352670] [client 59.93.4.33:51297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RAsJSWzG9jbYOtu4n8QAAAPw"]
[Tue Jul 21 07:59:15.029451 2026] [security2:error] [pid 352421:tid 352672] [client 20.104.96.117:46696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/pucci.php"] [unique_id "al9RA8JSWzG9jbYOtu4n-wAAAP4"]
[Tue Jul 21 07:59:15.148941 2026] [security2:error] [pid 352421:tid 352646] [client 20.151.10.161:20459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9RA8JSWzG9jbYOtu4oAQAAAOQ"]
[Tue Jul 21 07:59:15.286177 2026] [security2:error] [pid 352421:tid 352574] [client 4.204.201.85:61602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/database.php"] [unique_id "al9RA8JSWzG9jbYOtu4oBgAAAJw"]
[Tue Jul 21 07:59:15.445070 2026] [security2:error] [pid 352421:tid 352643] [client 117.247.80.59:27586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RA8JSWzG9jbYOtu4oBwAAAOE"]
[Tue Jul 21 07:59:15.445221 2026] [security2:error] [pid 352421:tid 352643] [client 117.247.80.59:27586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RA8JSWzG9jbYOtu4oBwAAAOE"]
[Tue Jul 21 07:59:15.460568 2026] [security2:error] [pid 352421:tid 352620] [client 109.60.28.94:47563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RA8JSWzG9jbYOtu4oCAAAAMo"]
[Tue Jul 21 07:59:15.461362 2026] [security2:error] [pid 352421:tid 352620] [client 109.60.28.94:47563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RA8JSWzG9jbYOtu4oCAAAAMo"]
[Tue Jul 21 07:59:15.508114 2026] [security2:error] [pid 352421:tid 352625] [client 20.151.10.161:20466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/f6.php"] [unique_id "al9RA8JSWzG9jbYOtu4oCwAAAM8"]
[Tue Jul 21 07:59:15.526117 2026] [security2:error] [pid 352421:tid 352655] [client 20.197.192.193:48732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9RA8JSWzG9jbYOtu4oDgAAAO0"]
[Tue Jul 21 07:59:15.530367 2026] [security2:error] [pid 352421:tid 352608] [client 20.104.96.117:46607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/black.php"] [unique_id "al9RA8JSWzG9jbYOtu4oDwAAAL4"]
[Tue Jul 21 07:59:15.688635 2026] [security2:error] [pid 352421:tid 352475] [remote 57.141.18.50:58156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemap_index.xml"] [unique_id "al9RA8JSWzG9jbYOtu4oFAAAlTU"]
[Tue Jul 21 07:59:15.919925 2026] [security2:error] [pid 352421:tid 352593] [client 20.197.192.193:3749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/wp-css.php"] [unique_id "al9RA8JSWzG9jbYOtu4oGwAAAK8"]
[Tue Jul 21 07:59:15.933994 2026] [security2:error] [pid 352421:tid 352612] [client 20.151.10.161:20398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/inputs.php"] [unique_id "al9RA8JSWzG9jbYOtu4oHAAAAMI"]
[Tue Jul 21 07:59:15.999693 2026] [security2:error] [pid 352421:tid 352673] [client 193.36.225.140:45469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9RAsJSWzG9jbYOtu4n8AAAAP8"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:59:16.020240 2026] [security2:error] [pid 352421:tid 352647] [client 4.204.201.85:61039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/file.php"] [unique_id "al9RBMJSWzG9jbYOtu4oHgAAAOU"]
[Tue Jul 21 07:59:16.049467 2026] [security2:error] [pid 352421:tid 352422] [remote 119.195.102.159:41514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiapleno.com"] [uri "/wp-login.php"] [unique_id "al9RBMJSWzG9jbYOtu4oHwAAxgA"]
[Tue Jul 21 07:59:16.266691 2026] [security2:error] [pid 352421:tid 352654] [client 65.21.113.253:51372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RBMJSWzG9jbYOtu4oKAAAAOw"]
[Tue Jul 21 07:59:16.565485 2026] [security2:error] [pid 352421:tid 352574] [client 20.104.96.117:46685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/zlece.php"] [unique_id "al9RBMJSWzG9jbYOtu4oNQAAAJw"]
[Tue Jul 21 07:59:16.595793 2026] [security2:error] [pid 352421:tid 352619] [client 202.165.86.44:53836] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "carolinadona.com"] [uri "/jurisprompts/"] [unique_id "al9RBMJSWzG9jbYOtu4oNgAAAMk"]
[Tue Jul 21 07:59:16.706794 2026] [security2:error] [pid 352421:tid 352656] [client 223.236.153.128:16036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RBMJSWzG9jbYOtu4oPAAAAO4"]
[Tue Jul 21 07:59:16.716520 2026] [security2:error] [pid 352421:tid 352656] [client 223.236.153.128:16036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RBMJSWzG9jbYOtu4oPAAAAO4"]
[Tue Jul 21 07:59:17.034729 2026] [security2:error] [pid 352421:tid 352583] [client 4.204.201.85:61572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/file.php"] [unique_id "al9RBcJSWzG9jbYOtu4oRQAAAKU"]
[Tue Jul 21 07:59:17.038620 2026] [security2:error] [pid 352421:tid 352526] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RBcJSWzG9jbYOtu4oRgAArWg"]
[Tue Jul 21 07:59:17.038745 2026] [security2:error] [pid 352421:tid 352591] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RBcJSWzG9jbYOtu4oRgAArWg"]
[Tue Jul 21 07:59:17.069899 2026] [security2:error] [pid 352421:tid 352649] [client 92.119.178.3:59114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9RBcJSWzG9jbYOtu4oSAAAAOc"]
[Tue Jul 21 07:59:17.070009 2026] [security2:error] [pid 352421:tid 352649] [client 92.119.178.3:59114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9RBcJSWzG9jbYOtu4oSAAAAOc"]
[Tue Jul 21 07:59:17.071347 2026] [security2:error] [pid 352421:tid 352558] [client 20.151.10.161:20370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/inputs.php"] [unique_id "al9RBcJSWzG9jbYOtu4oSQAAAIw"]
[Tue Jul 21 07:59:17.090543 2026] [security2:error] [pid 352421:tid 352639] [client 65.21.113.253:34388] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RBMJSWzG9jbYOtu4oRAAAAN0"]
[Tue Jul 21 07:59:17.338955 2026] [security2:error] [pid 352421:tid 352517] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RBcJSWzG9jbYOtu4oUwAAk18"]
[Tue Jul 21 07:59:17.339138 2026] [security2:error] [pid 352421:tid 352565] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RBcJSWzG9jbYOtu4oUwAAk18"]
[Tue Jul 21 07:59:17.346882 2026] [security2:error] [pid 352421:tid 352595] [client 184.75.221.3:55956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9RBcJSWzG9jbYOtu4oVAAAALE"]
[Tue Jul 21 07:59:17.346989 2026] [security2:error] [pid 352421:tid 352595] [client 184.75.221.3:55956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9RBcJSWzG9jbYOtu4oVAAAALE"]
[Tue Jul 21 07:59:17.383708 2026] [security2:error] [pid 352421:tid 352628] [client 87.116.180.198:14074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RBcJSWzG9jbYOtu4oVQAAANI"]
[Tue Jul 21 07:59:17.383847 2026] [security2:error] [pid 352421:tid 352628] [client 87.116.180.198:14074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RBcJSWzG9jbYOtu4oVQAAANI"]
[Tue Jul 21 07:59:17.412847 2026] [security2:error] [pid 352421:tid 352561] [client 20.104.96.117:46703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/vssrs.php"] [unique_id "al9RBcJSWzG9jbYOtu4oWQAAAI8"]
[Tue Jul 21 07:59:17.422625 2026] [security2:error] [pid 352421:tid 352586] [client 20.220.225.223:1805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/else1.php"] [unique_id "al9RBcJSWzG9jbYOtu4oWgAAAKg"]
[Tue Jul 21 07:59:17.448699 2026] [security2:error] [pid 352421:tid 352661] [client 20.151.10.161:28991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/file15.php"] [unique_id "al9RBcJSWzG9jbYOtu4oXAAAAPM"]
[Tue Jul 21 07:59:17.546581 2026] [security2:error] [pid 352421:tid 352584] [client 20.151.10.161:20352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/av.php"] [unique_id "al9RBcJSWzG9jbYOtu4oYgAAAKY"]
[Tue Jul 21 07:59:17.714929 2026] [security2:error] [pid 352421:tid 352616] [client 65.21.113.253:34380] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RBcJSWzG9jbYOtu4oUgAAAMY"]
[Tue Jul 21 07:59:17.846493 2026] [security2:error] [pid 352421:tid 352599] [client 106.215.181.8:21617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RBcJSWzG9jbYOtu4oawAAALU"]
[Tue Jul 21 07:59:17.846628 2026] [security2:error] [pid 352421:tid 352599] [client 106.215.181.8:21617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RBcJSWzG9jbYOtu4oawAAALU"]
[Tue Jul 21 07:59:17.866677 2026] [security2:error] [pid 352421:tid 352632] [client 20.197.192.193:48733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/wp-explorer.php"] [unique_id "al9RBcJSWzG9jbYOtu4obAAAANY"]
[Tue Jul 21 07:59:17.942321 2026] [security2:error] [pid 352421:tid 352600] [client 4.204.201.85:9623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/777.php"] [unique_id "al9RBcJSWzG9jbYOtu4ocAAAALY"]
[Tue Jul 21 07:59:18.276827 2026] [security2:error] [pid 352421:tid 352659] [client 136.144.33.28:49537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RBsJSWzG9jbYOtu4odwAAAPE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:18.301973 2026] [security2:error] [pid 352421:tid 352630] [client 20.151.10.161:20471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/classwithtostring.php"] [unique_id "al9RBsJSWzG9jbYOtu4oegAAANQ"]
[Tue Jul 21 07:59:18.383918 2026] [security2:error] [pid 352421:tid 352585] [client 20.226.60.151:59938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/sym403.php"] [unique_id "al9RBsJSWzG9jbYOtu4ofQAAAKc"]
[Tue Jul 21 07:59:18.501459 2026] [security2:error] [pid 352421:tid 352594] [client 4.204.201.85:61033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/ssixta.php"] [unique_id "al9RBsJSWzG9jbYOtu4ogQAAALA"]
[Tue Jul 21 07:59:18.720292 2026] [security2:error] [pid 352421:tid 352657] [client 20.104.96.117:46669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wicked.php"] [unique_id "al9RBsJSWzG9jbYOtu4ohgAAAO8"]
[Tue Jul 21 07:59:18.768169 2026] [security2:error] [pid 352421:tid 352575] [client 20.151.10.161:20362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9RBsJSWzG9jbYOtu4oiAAAAJ0"]
[Tue Jul 21 07:59:18.871142 2026] [security2:error] [pid 352421:tid 352602] [client 65.21.113.253:34394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RBsJSWzG9jbYOtu4ogAAAALg"]
[Tue Jul 21 07:59:19.003180 2026] [security2:error] [pid 352421:tid 352607] [client 103.78.200.11:60825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RB8JSWzG9jbYOtu4okgAAAL0"]
[Tue Jul 21 07:59:19.006301 2026] [security2:error] [pid 352421:tid 352607] [client 103.78.200.11:60825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RB8JSWzG9jbYOtu4okgAAAL0"]
[Tue Jul 21 07:59:19.158304 2026] [security2:error] [pid 352421:tid 352668] [client 103.29.114.44:60015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RB8JSWzG9jbYOtu4okwAAAPo"]
[Tue Jul 21 07:59:19.158421 2026] [security2:error] [pid 352421:tid 352668] [client 103.29.114.44:60015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RB8JSWzG9jbYOtu4okwAAAPo"]
[Tue Jul 21 07:59:19.204108 2026] [security2:error] [pid 352421:tid 352599] [client 4.204.201.85:61573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/1c.php"] [unique_id "al9RB8JSWzG9jbYOtu4olAAAALU"]
[Tue Jul 21 07:59:19.253476 2026] [security2:error] [pid 352421:tid 352632] [client 20.151.10.161:20464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wp-blog.php"] [unique_id "al9RB8JSWzG9jbYOtu4olQAAANY"]
[Tue Jul 21 07:59:19.326421 2026] [security2:error] [pid 352421:tid 352628] [client 122.162.144.145:11522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9RB8JSWzG9jbYOtu4olgAAANI"]
[Tue Jul 21 07:59:19.326519 2026] [security2:error] [pid 352421:tid 352628] [client 122.162.144.145:11522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9RB8JSWzG9jbYOtu4olgAAANI"]
[Tue Jul 21 07:59:19.487771 2026] [security2:error] [pid 352421:tid 352614] [client 102.206.115.33:62161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RB8JSWzG9jbYOtu4onwAAAMQ"]
[Tue Jul 21 07:59:19.487906 2026] [security2:error] [pid 352421:tid 352614] [client 102.206.115.33:62161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RB8JSWzG9jbYOtu4onwAAAMQ"]
[Tue Jul 21 07:59:19.506248 2026] [security2:error] [pid 352421:tid 352666] [client 20.104.96.117:46681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/24.php"] [unique_id "al9RB8JSWzG9jbYOtu4ooAAAAPg"]
[Tue Jul 21 07:59:19.665580 2026] [security2:error] [pid 352421:tid 352604] [client 103.166.103.129:58790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RB8JSWzG9jbYOtu4opAAAALo"]
[Tue Jul 21 07:59:19.665708 2026] [security2:error] [pid 352421:tid 352604] [client 103.166.103.129:58790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RB8JSWzG9jbYOtu4opAAAALo"]
[Tue Jul 21 07:59:19.690498 2026] [security2:error] [pid 352421:tid 352634] [client 20.151.10.161:28676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/jp.php"] [unique_id "al9RB8JSWzG9jbYOtu4opQAAANg"]
[Tue Jul 21 07:59:19.973220 2026] [security2:error] [pid 352421:tid 352670] [client 204.8.98.45:41176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9RB8JSWzG9jbYOtu4osQAAAPw"]
[Tue Jul 21 07:59:19.973301 2026] [security2:error] [pid 352421:tid 352670] [client 204.8.98.45:41176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9RB8JSWzG9jbYOtu4osQAAAPw"]
[Tue Jul 21 07:59:20.031337 2026] [security2:error] [pid 352421:tid 352656] [client 103.86.117.203:57779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RCMJSWzG9jbYOtu4osgAAAO4"]
[Tue Jul 21 07:59:20.031471 2026] [security2:error] [pid 352421:tid 352656] [client 103.86.117.203:57779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RCMJSWzG9jbYOtu4osgAAAO4"]
[Tue Jul 21 07:59:20.089263 2026] [proxy:error] [pid 352421:tid 352657] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:20.089338 2026] [proxy_http:error] [pid 352421:tid 352657] [client 20.151.10.161:20417] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:20.089784 2026] [proxy:error] [pid 352421:tid 352657] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:20.089811 2026] [proxy_http:error] [pid 352421:tid 352657] [client 20.151.10.161:20417] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:20.161667 2026] [security2:error] [pid 352421:tid 352470] [remote 5.252.52.249:52584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9RCMJSWzG9jbYOtu4otQAAyzA"]
[Tue Jul 21 07:59:20.261875 2026] [security2:error] [pid 352421:tid 352653] [client 20.151.10.161:28729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/f35.php"] [unique_id "al9RCMJSWzG9jbYOtu4otwAAAOs"]
[Tue Jul 21 07:59:20.348274 2026] [security2:error] [pid 352421:tid 352672] [client 65.21.113.253:59996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9RCMJSWzG9jbYOtu4ouAAAAP4"]
[Tue Jul 21 07:59:20.390397 2026] [security2:error] [pid 352421:tid 352587] [client 4.204.201.85:9657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/test2.php"] [unique_id "al9RCMJSWzG9jbYOtu4ouwAAAKk"]
[Tue Jul 21 07:59:20.560820 2026] [security2:error] [pid 352421:tid 352606] [client 122.179.91.63:2130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RCMJSWzG9jbYOtu4oxAAAALw"]
[Tue Jul 21 07:59:20.560948 2026] [security2:error] [pid 352421:tid 352606] [client 122.179.91.63:2130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RCMJSWzG9jbYOtu4oxAAAALw"]
[Tue Jul 21 07:59:20.640392 2026] [security2:error] [pid 352421:tid 352598] [client 171.7.105.16:56208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "carolinadona.com"] [uri "/jurisprompts/"] [unique_id "al9RCMJSWzG9jbYOtu4oxgAAALQ"]
[Tue Jul 21 07:59:20.697811 2026] [security2:error] [pid 352421:tid 352582] [client 20.151.10.161:29198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-load.php"] [unique_id "al9RCMJSWzG9jbYOtu4oyAAAAKQ"]
[Tue Jul 21 07:59:20.724259 2026] [security2:error] [pid 352421:tid 352619] [client 65.21.113.253:34388] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RCMJSWzG9jbYOtu4oxQAAAMk"]
[Tue Jul 21 07:59:20.830945 2026] [security2:error] [pid 352421:tid 352628] [client 20.104.96.117:46674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xacs.php"] [unique_id "al9RCMJSWzG9jbYOtu4oyQAAANI"]
[Tue Jul 21 07:59:20.952573 2026] [security2:error] [pid 352421:tid 352635] [client 65.21.113.253:51372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RCMJSWzG9jbYOtu4ozgAAANk"]
[Tue Jul 21 07:59:21.050724 2026] [security2:error] [pid 352421:tid 352605] [client 202.143.127.214:60573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RCcJSWzG9jbYOtu4o1wAAALs"]
[Tue Jul 21 07:59:21.050849 2026] [security2:error] [pid 352421:tid 352605] [client 202.143.127.214:60573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RCcJSWzG9jbYOtu4o1wAAALs"]
[Tue Jul 21 07:59:21.071442 2026] [security2:error] [pid 352421:tid 352604] [client 20.220.225.223:1798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/tkikikoko.php"] [unique_id "al9RCcJSWzG9jbYOtu4o2AAAALo"]
[Tue Jul 21 07:59:21.174854 2026] [security2:error] [pid 352421:tid 352648] [client 20.151.10.161:28945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/xwpg.php"] [unique_id "al9RCcJSWzG9jbYOtu4o2gAAAOY"]
[Tue Jul 21 07:59:21.190433 2026] [security2:error] [pid 352421:tid 352671] [client 20.151.10.161:20415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9RCcJSWzG9jbYOtu4o3AAAAP0"]
[Tue Jul 21 07:59:21.216684 2026] [security2:error] [pid 352421:tid 352592] [client 104.207.62.93:16843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.62.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RCcJSWzG9jbYOtu4o1gAAAK4"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:59:21.287236 2026] [security2:error] [pid 352421:tid 352609] [client 20.104.96.117:46613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/zildan.php"] [unique_id "al9RCcJSWzG9jbYOtu4o3wAAAL8"]
[Tue Jul 21 07:59:21.570199 2026] [security2:error] [pid 352421:tid 352661] [client 4.204.201.85:61600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/buy.php"] [unique_id "al9RCcJSWzG9jbYOtu4o6QAAAPM"]
[Tue Jul 21 07:59:21.595303 2026] [security2:error] [pid 352421:tid 352612] [client 65.21.113.253:34394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RCcJSWzG9jbYOtu4o2wAAAMI"]
[Tue Jul 21 07:59:21.612711 2026] [security2:error] [pid 352421:tid 352575] [client 20.104.96.117:46665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/csa.php"] [unique_id "al9RCcJSWzG9jbYOtu4o6gAAAJ0"]
[Tue Jul 21 07:59:21.708085 2026] [security2:error] [pid 352421:tid 352653] [client 34.74.242.206:1583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "linkmaster.net.br"] [uri "/robots.txt"] [unique_id "al9RCcJSWzG9jbYOtu4o7QAAAOs"]
[Tue Jul 21 07:59:21.708228 2026] [security2:error] [pid 352421:tid 352653] [client 34.74.242.206:1583] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "linkmaster.net.br"] [uri "/robots.txt"] [unique_id "al9RCcJSWzG9jbYOtu4o7QAAAOs"]
[Tue Jul 21 07:59:21.754413 2026] [security2:error] [pid 352421:tid 352607] [client 136.144.33.96:31439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RCcJSWzG9jbYOtu4o7gAAAL0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:21.945036 2026] [security2:error] [pid 352421:tid 352668] [client 20.151.10.161:28721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/waf.php"] [unique_id "al9RCcJSWzG9jbYOtu4o-QAAAPo"]
[Tue Jul 21 07:59:21.945513 2026] [security2:error] [pid 352421:tid 352675] [client 34.74.242.206:1573] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "linkmaster.net.br"] [uri "/"] [unique_id "al9RCcJSWzG9jbYOtu4o-gAAAQE"]
[Tue Jul 21 07:59:21.945603 2026] [security2:error] [pid 352421:tid 352675] [client 34.74.242.206:1573] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "linkmaster.net.br"] [uri "/"] [unique_id "al9RCcJSWzG9jbYOtu4o-gAAAQE"]
[Tue Jul 21 07:59:22.124285 2026] [security2:error] [pid 352421:tid 352556] [client 20.151.10.161:20389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/adminfuns.php"] [unique_id "al9RCsJSWzG9jbYOtu4pBQAAAIo"]
[Tue Jul 21 07:59:22.227014 2026] [security2:error] [pid 352421:tid 352451] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RCsJSWzG9jbYOtu4pBgAAmh0"]
[Tue Jul 21 07:59:22.227189 2026] [security2:error] [pid 352421:tid 352572] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RCsJSWzG9jbYOtu4pBgAAmh0"]
[Tue Jul 21 07:59:22.269149 2026] [security2:error] [pid 352421:tid 352615] [client 74.249.245.134:17464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/up.php"] [unique_id "al9RCsJSWzG9jbYOtu4pBwAAAMU"]
[Tue Jul 21 07:59:22.425955 2026] [security2:error] [pid 352421:tid 352482] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RCsJSWzG9jbYOtu4pCQAA5jw"]
[Tue Jul 21 07:59:22.426100 2026] [security2:error] [pid 352421:tid 352648] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RCsJSWzG9jbYOtu4pCQAA5jw"]
[Tue Jul 21 07:59:22.494626 2026] [security2:error] [pid 352421:tid 352601] [client 20.151.10.161:29186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/xstelth.php"] [unique_id "al9RCsJSWzG9jbYOtu4pFAAAALc"]
[Tue Jul 21 07:59:22.656493 2026] [security2:error] [pid 352421:tid 352652] [client 20.226.60.151:59927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/v543.php"] [unique_id "al9RCsJSWzG9jbYOtu4pHQAAAOo"]
[Tue Jul 21 07:59:22.926631 2026] [security2:error] [pid 352421:tid 352664] [client 20.104.96.117:46662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/w3llscc.php"] [unique_id "al9RCsJSWzG9jbYOtu4pIgAAAPY"]
[Tue Jul 21 07:59:22.945328 2026] [security2:error] [pid 352421:tid 352616] [client 4.204.201.85:9641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/ssend.php"] [unique_id "al9RCsJSWzG9jbYOtu4pIwAAAMY"]
[Tue Jul 21 07:59:22.954573 2026] [security2:error] [pid 352421:tid 352617] [client 20.151.10.161:29118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-links.php"] [unique_id "al9RCsJSWzG9jbYOtu4pJQAAAMc"]
[Tue Jul 21 07:59:23.077225 2026] [security2:error] [pid 352421:tid 352650] [client 41.68.90.219:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RC8JSWzG9jbYOtu4pLQAAAOg"]
[Tue Jul 21 07:59:23.078311 2026] [security2:error] [pid 352421:tid 352650] [client 41.68.90.219:52166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RC8JSWzG9jbYOtu4pLQAAAOg"]
[Tue Jul 21 07:59:23.121101 2026] [security2:error] [pid 352421:tid 352662] [client 20.151.10.161:20435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/goods.php"] [unique_id "al9RC8JSWzG9jbYOtu4pMgAAAPQ"]
[Tue Jul 21 07:59:23.146645 2026] [security2:error] [pid 352421:tid 352639] [client 117.210.135.0:59777] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RCsJSWzG9jbYOtu4pHwAAAN0"]
[Tue Jul 21 07:59:23.146753 2026] [security2:error] [pid 352421:tid 352639] [client 117.210.135.0:59777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RCsJSWzG9jbYOtu4pHwAAAN0"]
[Tue Jul 21 07:59:23.299053 2026] [security2:error] [pid 352421:tid 352643] [client 92.119.178.3:51972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9RC8JSWzG9jbYOtu4pNgAAAOE"]
[Tue Jul 21 07:59:23.299190 2026] [security2:error] [pid 352421:tid 352643] [client 92.119.178.3:51972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9RC8JSWzG9jbYOtu4pNgAAAOE"]
[Tue Jul 21 07:59:23.551933 2026] [security2:error] [pid 352421:tid 352602] [client 178.153.91.96:13601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RC8JSWzG9jbYOtu4pQAAAALg"]
[Tue Jul 21 07:59:23.552037 2026] [security2:error] [pid 352421:tid 352602] [client 178.153.91.96:13601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RC8JSWzG9jbYOtu4pQAAAALg"]
[Tue Jul 21 07:59:23.753160 2026] [security2:error] [pid 352421:tid 352670] [client 65.21.113.253:51372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RC8JSWzG9jbYOtu4pSQAAAPw"]
[Tue Jul 21 07:59:23.795303 2026] [security2:error] [pid 352421:tid 352653] [client 179.49.155.7:11573] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "carolinadona.com"] [uri "/jurisprompts/"] [unique_id "al9RC8JSWzG9jbYOtu4pSwAAAOs"]
[Tue Jul 21 07:59:23.845383 2026] [security2:error] [pid 352421:tid 352678] [client 65.21.113.253:48296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RC8JSWzG9jbYOtu4pOQAAAQQ"]
[Tue Jul 21 07:59:23.936641 2026] [security2:error] [pid 352421:tid 352571] [client 92.119.178.3:57136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9RC8JSWzG9jbYOtu4pTAAAAJk"]
[Tue Jul 21 07:59:23.936752 2026] [security2:error] [pid 352421:tid 352571] [client 92.119.178.3:57136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9RC8JSWzG9jbYOtu4pTAAAAJk"]
[Tue Jul 21 07:59:23.973283 2026] [security2:error] [pid 352421:tid 352575] [client 20.151.10.161:28692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9RC8JSWzG9jbYOtu4pTQAAAJ0"]
[Tue Jul 21 07:59:24.354783 2026] [security2:error] [pid 352421:tid 352617] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9RDMJSWzG9jbYOtu4pWAAAAMc"]
[Tue Jul 21 07:59:24.376743 2026] [security2:error] [pid 352421:tid 352663] [client 20.151.10.161:20399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/ms-edit.php"] [unique_id "al9RDMJSWzG9jbYOtu4pWQAAAPU"]
[Tue Jul 21 07:59:24.399907 2026] [security2:error] [pid 352421:tid 352474] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RDMJSWzG9jbYOtu4pWwAAhzQ"]
[Tue Jul 21 07:59:24.400090 2026] [security2:error] [pid 352421:tid 352553] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RDMJSWzG9jbYOtu4pWwAAhzQ"]
[Tue Jul 21 07:59:24.480300 2026] [security2:error] [pid 352421:tid 352596] [client 38.100.221.102:18567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RDMJSWzG9jbYOtu4pYAAAALI"]
[Tue Jul 21 07:59:24.480493 2026] [security2:error] [pid 352421:tid 352596] [client 38.100.221.102:18567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RDMJSWzG9jbYOtu4pYAAAALI"]
[Tue Jul 21 07:59:24.531093 2026] [security2:error] [pid 352421:tid 352613] [client 182.8.255.181:21246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RDMJSWzG9jbYOtu4pYwAAAMM"]
[Tue Jul 21 07:59:24.531265 2026] [security2:error] [pid 352421:tid 352613] [client 182.8.255.181:21246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RDMJSWzG9jbYOtu4pYwAAAMM"]
[Tue Jul 21 07:59:24.641794 2026] [security2:error] [pid 352421:tid 352599] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RDMJSWzG9jbYOtu4pZgAAALU"]
[Tue Jul 21 07:59:24.804613 2026] [security2:error] [pid 352421:tid 352664] [client 65.21.113.253:48306] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RDMJSWzG9jbYOtu4pXAAAAPY"]
[Tue Jul 21 07:59:24.966929 2026] [security2:error] [pid 352421:tid 352670] [client 20.151.10.161:20291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/222.php"] [unique_id "al9RDMJSWzG9jbYOtu4peAAAAPw"]
[Tue Jul 21 07:59:24.983156 2026] [security2:error] [pid 352421:tid 352576] [client 20.151.10.161:28684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.factorial.studio"] [uri "/aaa.php"] [unique_id "al9RDMJSWzG9jbYOtu4peQAAAJ4"]
[Tue Jul 21 07:59:25.071183 2026] [security2:error] [pid 352421:tid 352478] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RDcJSWzG9jbYOtu4pewAA-Tg"]
[Tue Jul 21 07:59:25.071310 2026] [security2:error] [pid 352421:tid 352667] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RDcJSWzG9jbYOtu4pewAA-Tg"]
[Tue Jul 21 07:59:25.111664 2026] [security2:error] [pid 352421:tid 352488] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RDcJSWzG9jbYOtu4pfwAA-EI"]
[Tue Jul 21 07:59:25.111810 2026] [security2:error] [pid 352421:tid 352666] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RDcJSWzG9jbYOtu4pfwAA-EI"]
[Tue Jul 21 07:59:25.166512 2026] [security2:error] [pid 352421:tid 352571] [client 4.204.201.85:9537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/item.php"] [unique_id "al9RDcJSWzG9jbYOtu4pgwAAAJk"]
[Tue Jul 21 07:59:25.219772 2026] [security2:error] [pid 352421:tid 352458] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RDcJSWzG9jbYOtu4phQAAmyQ"]
[Tue Jul 21 07:59:25.219974 2026] [security2:error] [pid 352421:tid 352573] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RDcJSWzG9jbYOtu4phQAAmyQ"]
[Tue Jul 21 07:59:25.533871 2026] [security2:error] [pid 352421:tid 352555] [client 59.93.4.33:51827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RDcJSWzG9jbYOtu4plAAAAIk"]
[Tue Jul 21 07:59:25.534000 2026] [security2:error] [pid 352421:tid 352555] [client 59.93.4.33:51827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RDcJSWzG9jbYOtu4plAAAAIk"]
[Tue Jul 21 07:59:25.575499 2026] [security2:error] [pid 352421:tid 352613] [client 20.151.10.161:20473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9RDcJSWzG9jbYOtu4pmAAAAMM"]
[Tue Jul 21 07:59:25.888907 2026] [security2:error] [pid 352421:tid 352572] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9RDcJSWzG9jbYOtu4poAAAAJo"]
[Tue Jul 21 07:59:25.960386 2026] [proxy:error] [pid 352421:tid 352557] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:25.960477 2026] [proxy_http:error] [pid 352421:tid 352557] [client 20.151.10.161:20458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:25.961323 2026] [proxy:error] [pid 352421:tid 352557] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:25.961355 2026] [proxy_http:error] [pid 352421:tid 352557] [client 20.151.10.161:20458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:26.026740 2026] [security2:error] [pid 352421:tid 352641] [client 193.36.225.10:46987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RDsJSWzG9jbYOtu4pogAAAN8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:26.090518 2026] [security2:error] [pid 352421:tid 352562] [client 20.104.96.117:46621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wpx.php"] [unique_id "al9RDsJSWzG9jbYOtu4ppAAAAJA"]
[Tue Jul 21 07:59:26.175514 2026] [security2:error] [pid 352421:tid 352560] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9RDsJSWzG9jbYOtu4pqQAAAI4"]
[Tue Jul 21 07:59:26.314704 2026] [security2:error] [pid 352421:tid 352580] [client 117.247.80.59:27294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RDsJSWzG9jbYOtu4prQAAAKI"]
[Tue Jul 21 07:59:26.314851 2026] [security2:error] [pid 352421:tid 352580] [client 117.247.80.59:27294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RDsJSWzG9jbYOtu4prQAAAKI"]
[Tue Jul 21 07:59:26.335732 2026] [security2:error] [pid 352421:tid 352459] [remote 103.187.169.251:59276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiferreira.com.br"] [uri "/wp-login.php"] [unique_id "al9RDsJSWzG9jbYOtu4psAAA3SU"]
[Tue Jul 21 07:59:26.379693 2026] [security2:error] [pid 352421:tid 352664] [client 109.60.28.94:64702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RDsJSWzG9jbYOtu4psQAAAPY"]
[Tue Jul 21 07:59:26.379781 2026] [security2:error] [pid 352421:tid 352664] [client 109.60.28.94:64702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RDsJSWzG9jbYOtu4psQAAAPY"]
[Tue Jul 21 07:59:26.408518 2026] [security2:error] [pid 352421:tid 352593] [client 20.151.10.161:20472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9RDsJSWzG9jbYOtu4pswAAAK8"]
[Tue Jul 21 07:59:26.462033 2026] [security2:error] [pid 352421:tid 352667] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9RDsJSWzG9jbYOtu4ptQAAAPk"]
[Tue Jul 21 07:59:26.512229 2026] [security2:error] [pid 352421:tid 352678] [client 20.226.60.151:64961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/sixxis.php"] [unique_id "al9RDsJSWzG9jbYOtu4ptgAAAQQ"]
[Tue Jul 21 07:59:26.762522 2026] [security2:error] [pid 352421:tid 352674] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9RDsJSWzG9jbYOtu4pvQAAAQA"]
[Tue Jul 21 07:59:26.850555 2026] [proxy:error] [pid 352421:tid 352611] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:26.850619 2026] [proxy_http:error] [pid 352421:tid 352611] [client 20.151.10.161:20296] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:26.851110 2026] [proxy:error] [pid 352421:tid 352611] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:26.851137 2026] [proxy_http:error] [pid 352421:tid 352611] [client 20.151.10.161:20296] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:26.857074 2026] [security2:error] [pid 352421:tid 352567] [client 74.249.245.134:17433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/66.php"] [unique_id "al9RDsJSWzG9jbYOtu4pxAAAAJU"]
[Tue Jul 21 07:59:26.924070 2026] [security2:error] [pid 352421:tid 352581] [client 4.204.201.85:9603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/ss.php"] [unique_id "al9RDsJSWzG9jbYOtu4pxgAAAKM"]
[Tue Jul 21 07:59:27.048232 2026] [security2:error] [pid 352421:tid 352672] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9RD8JSWzG9jbYOtu4pyAAAAP4"]
[Tue Jul 21 07:59:27.177129 2026] [security2:error] [pid 352421:tid 352576] [client 223.236.153.128:2482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RD8JSWzG9jbYOtu4pzwAAAJ4"]
[Tue Jul 21 07:59:27.177237 2026] [security2:error] [pid 352421:tid 352576] [client 223.236.153.128:2482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RD8JSWzG9jbYOtu4pzwAAAJ4"]
[Tue Jul 21 07:59:27.182569 2026] [security2:error] [pid 352421:tid 352652] [client 65.21.113.253:48296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RDsJSWzG9jbYOtu4pvAAAAOo"]
[Tue Jul 21 07:59:27.317333 2026] [proxy:error] [pid 352421:tid 352673] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:27.317404 2026] [proxy_http:error] [pid 352421:tid 352673] [client 20.151.10.161:20377] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:27.318023 2026] [proxy:error] [pid 352421:tid 352673] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:27.318050 2026] [proxy_http:error] [pid 352421:tid 352673] [client 20.151.10.161:20377] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:27.335158 2026] [security2:error] [pid 352421:tid 352557] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9RD8JSWzG9jbYOtu4p1AAAAIs"]
[Tue Jul 21 07:59:27.448274 2026] [security2:error] [pid 352421:tid 352648] [client 134.249.86.112:64953] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "carolinadona.com"] [uri "/templates-magneticos/"] [unique_id "al9RD8JSWzG9jbYOtu4p2AAAAOY"]
[Tue Jul 21 07:59:27.618143 2026] [security2:error] [pid 352421:tid 352678] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9RD8JSWzG9jbYOtu4p3gAAAQQ"]
[Tue Jul 21 07:59:27.629454 2026] [security2:error] [pid 352421:tid 352665] [client 20.151.10.161:20450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/raw.php"] [unique_id "al9RD8JSWzG9jbYOtu4p3wAAAPc"]
[Tue Jul 21 07:59:27.733236 2026] [security2:error] [pid 352421:tid 352585] [client 92.119.178.3:57152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9RD8JSWzG9jbYOtu4p4gAAAKc"]
[Tue Jul 21 07:59:27.733359 2026] [security2:error] [pid 352421:tid 352585] [client 92.119.178.3:57152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9RD8JSWzG9jbYOtu4p4gAAAKc"]
[Tue Jul 21 07:59:27.904463 2026] [security2:error] [pid 352421:tid 352571] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9RD8JSWzG9jbYOtu4p6AAAAJk"]
[Tue Jul 21 07:59:27.954148 2026] [security2:error] [pid 352421:tid 352586] [client 20.151.10.161:20375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/abcd.php"] [unique_id "al9RD8JSWzG9jbYOtu4p6wAAAKg"]
[Tue Jul 21 07:59:27.954565 2026] [security2:error] [pid 352421:tid 352463] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RD8JSWzG9jbYOtu4p6gAA3Sk"]
[Tue Jul 21 07:59:27.954699 2026] [security2:error] [pid 352421:tid 352639] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RD8JSWzG9jbYOtu4p6gAA3Sk"]
[Tue Jul 21 07:59:28.068315 2026] [security2:error] [pid 352421:tid 352597] [client 87.116.180.198:13973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9REMJSWzG9jbYOtu4p7AAAALM"]
[Tue Jul 21 07:59:28.070055 2026] [security2:error] [pid 352421:tid 352597] [client 87.116.180.198:13973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9REMJSWzG9jbYOtu4p7AAAALM"]
[Tue Jul 21 07:59:28.190207 2026] [security2:error] [pid 352421:tid 352615] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9REMJSWzG9jbYOtu4p8wAAAMU"]
[Tue Jul 21 07:59:28.369167 2026] [security2:error] [pid 352421:tid 352650] [client 20.151.10.161:20403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/a1.php"] [unique_id "al9REMJSWzG9jbYOtu4p9QAAAOg"]
[Tue Jul 21 07:59:28.416600 2026] [security2:error] [pid 352421:tid 352518] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9REMJSWzG9jbYOtu4p9wAAwWA"]
[Tue Jul 21 07:59:28.416746 2026] [security2:error] [pid 352421:tid 352611] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9REMJSWzG9jbYOtu4p9wAAwWA"]
[Tue Jul 21 07:59:28.435982 2026] [security2:error] [pid 352421:tid 352503] [remote 72.167.132.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp/wp-login.php"] [unique_id "al9REMJSWzG9jbYOtu4p-wABA1E"]
[Tue Jul 21 07:59:28.451692 2026] [security2:error] [pid 352421:tid 352588] [client 106.215.181.8:1904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9REMJSWzG9jbYOtu4p_wAAAKo"]
[Tue Jul 21 07:59:28.451772 2026] [security2:error] [pid 352421:tid 352588] [client 106.215.181.8:1904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9REMJSWzG9jbYOtu4p_wAAAKo"]
[Tue Jul 21 07:59:28.475958 2026] [security2:error] [pid 352421:tid 352643] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9REMJSWzG9jbYOtu4qAQAAAOE"]
[Tue Jul 21 07:59:28.492004 2026] [security2:error] [pid 352421:tid 352569] [client 20.151.10.161:39812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9REMJSWzG9jbYOtu4qAgAAAJc"]
[Tue Jul 21 07:59:28.578072 2026] [security2:error] [pid 352421:tid 352610] [client 4.204.201.85:9573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/hypo.php"] [unique_id "al9REMJSWzG9jbYOtu4qBgAAAMA"]
[Tue Jul 21 07:59:28.629279 2026] [security2:error] [pid 352421:tid 352612] [client 103.78.200.11:61298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9REMJSWzG9jbYOtu4qBwAAAMI"]
[Tue Jul 21 07:59:28.629874 2026] [security2:error] [pid 352421:tid 352612] [client 103.78.200.11:61298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9REMJSWzG9jbYOtu4qBwAAAMI"]
[Tue Jul 21 07:59:28.737115 2026] [security2:error] [pid 352421:tid 352570] [client 92.119.178.3:40722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9REMJSWzG9jbYOtu4qDQAAAJg"]
[Tue Jul 21 07:59:28.737568 2026] [security2:error] [pid 352421:tid 352570] [client 92.119.178.3:40722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9REMJSWzG9jbYOtu4qDQAAAJg"]
[Tue Jul 21 07:59:28.762535 2026] [security2:error] [pid 352421:tid 352653] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9REMJSWzG9jbYOtu4qDwAAAOs"]
[Tue Jul 21 07:59:28.830799 2026] [security2:error] [pid 352421:tid 352606] [client 20.151.10.161:20299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9REMJSWzG9jbYOtu4qEQAAALw"]
[Tue Jul 21 07:59:28.873398 2026] [security2:error] [pid 352421:tid 352665] [client 204.8.98.45:53384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9REMJSWzG9jbYOtu4qFAAAAPc"]
[Tue Jul 21 07:59:28.873486 2026] [security2:error] [pid 352421:tid 352665] [client 204.8.98.45:53384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9REMJSWzG9jbYOtu4qFAAAAPc"]
[Tue Jul 21 07:59:29.004154 2026] [security2:error] [pid 352421:tid 352572] [client 37.140.223.163:21597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9REMJSWzG9jbYOtu4qEgAAAJo"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:59:29.046470 2026] [security2:error] [pid 352421:tid 352587] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9REcJSWzG9jbYOtu4qGQAAAKk"]
[Tue Jul 21 07:59:29.246549 2026] [security2:error] [pid 352421:tid 352561] [client 20.151.10.161:20331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9REcJSWzG9jbYOtu4qHwAAAI8"]
[Tue Jul 21 07:59:29.332783 2026] [security2:error] [pid 352421:tid 352553] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9REcJSWzG9jbYOtu4qJAAAAIc"]
[Tue Jul 21 07:59:29.362893 2026] [security2:error] [pid 352421:tid 352672] [client 136.144.33.109:49557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9REcJSWzG9jbYOtu4qJQAAAP4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:29.618981 2026] [security2:error] [pid 352421:tid 352616] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9REcJSWzG9jbYOtu4qMgAAAMY"]
[Tue Jul 21 07:59:29.808807 2026] [security2:error] [pid 352421:tid 352625] [client 20.104.96.117:46691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-css.php"] [unique_id "al9REcJSWzG9jbYOtu4qNgAAAM8"]
[Tue Jul 21 07:59:29.809307 2026] [security2:error] [pid 352421:tid 352639] [client 103.29.114.44:33273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9REcJSWzG9jbYOtu4qNwAAAN0"]
[Tue Jul 21 07:59:29.809395 2026] [security2:error] [pid 352421:tid 352639] [client 103.29.114.44:33273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9REcJSWzG9jbYOtu4qNwAAAN0"]
[Tue Jul 21 07:59:29.871065 2026] [security2:error] [pid 352421:tid 352481] [remote 39.97.110.217:51924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.110.97.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9REcJSWzG9jbYOtu4qOQAAtzs"]
[Tue Jul 21 07:59:29.894887 2026] [security2:error] [pid 352421:tid 352583] [client 20.151.10.161:20336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9REcJSWzG9jbYOtu4qOgAAAKU"]
[Tue Jul 21 07:59:29.904000 2026] [security2:error] [pid 352421:tid 352635] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9REcJSWzG9jbYOtu4qPAAAANk"]
[Tue Jul 21 07:59:29.990693 2026] [security2:error] [pid 352421:tid 352576] [client 102.206.115.33:58616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9REcJSWzG9jbYOtu4qPgAAAJ4"]
[Tue Jul 21 07:59:29.991112 2026] [security2:error] [pid 352421:tid 352576] [client 102.206.115.33:58616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9REcJSWzG9jbYOtu4qPgAAAJ4"]
[Tue Jul 21 07:59:30.005266 2026] [security2:error] [pid 352421:tid 352551] [client 4.204.201.85:63235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/users.php"] [unique_id "al9REsJSWzG9jbYOtu4qPwAAAIU"]
[Tue Jul 21 07:59:30.150201 2026] [security2:error] [pid 352421:tid 352611] [client 122.162.144.145:23806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9REsJSWzG9jbYOtu4qRgAAAME"]
[Tue Jul 21 07:59:30.150339 2026] [security2:error] [pid 352421:tid 352611] [client 122.162.144.145:23806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9REsJSWzG9jbYOtu4qRgAAAME"]
[Tue Jul 21 07:59:30.191974 2026] [security2:error] [pid 352421:tid 352651] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9REsJSWzG9jbYOtu4qRwAAAOk"]
[Tue Jul 21 07:59:30.292413 2026] [security2:error] [pid 352421:tid 352661] [client 20.226.60.151:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/ip.php"] [unique_id "al9REsJSWzG9jbYOtu4qTAAAAPM"]
[Tue Jul 21 07:59:30.381682 2026] [security2:error] [pid 352421:tid 352636] [client 103.166.103.129:2705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9REsJSWzG9jbYOtu4qTgAAANo"]
[Tue Jul 21 07:59:30.382189 2026] [security2:error] [pid 352421:tid 352636] [client 103.166.103.129:2705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9REsJSWzG9jbYOtu4qTgAAANo"]
[Tue Jul 21 07:59:30.450320 2026] [security2:error] [pid 352421:tid 352645] [client 65.21.113.253:50066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9REsJSWzG9jbYOtu4qUwAAAOM"]
[Tue Jul 21 07:59:30.491146 2026] [proxy:error] [pid 352421:tid 352619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:30.491214 2026] [proxy_http:error] [pid 352421:tid 352619] [client 20.151.10.161:20465] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:30.491728 2026] [proxy:error] [pid 352421:tid 352619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:30.491751 2026] [proxy_http:error] [pid 352421:tid 352619] [client 20.151.10.161:20465] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:30.530985 2026] [security2:error] [pid 352421:tid 352662] [client 103.86.117.203:58323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9REsJSWzG9jbYOtu4qWgAAAPQ"]
[Tue Jul 21 07:59:30.531084 2026] [security2:error] [pid 352421:tid 352662] [client 103.86.117.203:58323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9REsJSWzG9jbYOtu4qWgAAAPQ"]
[Tue Jul 21 07:59:30.557927 2026] [security2:error] [pid 352421:tid 352629] [client 74.249.245.134:54383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/666.php"] [unique_id "al9REsJSWzG9jbYOtu4qWwAAANM"]
[Tue Jul 21 07:59:30.624879 2026] [security2:error] [pid 352421:tid 352541] [remote 68.178.160.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexandrevitor1781543539748.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9REsJSWzG9jbYOtu4qXQABA3c"]
[Tue Jul 21 07:59:30.625153 2026] [security2:error] [pid 352421:tid 352677] [client 68.178.160.25:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alexandrevitor1781543539748.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9REsJSWzG9jbYOtu4qXQABA3c"]
[Tue Jul 21 07:59:30.637476 2026] [security2:error] [pid 352421:tid 352606] [client 65.21.113.253:48296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9REsJSWzG9jbYOtu4qSAAAALw"]
[Tue Jul 21 07:59:31.054684 2026] [security2:error] [pid 352421:tid 352566] [client 20.151.10.161:20371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/simple.php"] [unique_id "al9RE8JSWzG9jbYOtu4qaAAAAJQ"]
[Tue Jul 21 07:59:31.132316 2026] [security2:error] [pid 352421:tid 352576] [client 92.119.178.3:45276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9RE8JSWzG9jbYOtu4qbQAAAJ4"]
[Tue Jul 21 07:59:31.132410 2026] [security2:error] [pid 352421:tid 352576] [client 92.119.178.3:45276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9RE8JSWzG9jbYOtu4qbQAAAJ4"]
[Tue Jul 21 07:59:31.174993 2026] [security2:error] [pid 352421:tid 352615] [client 122.179.91.63:19457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RE8JSWzG9jbYOtu4qbgAAAMU"]
[Tue Jul 21 07:59:31.175258 2026] [security2:error] [pid 352421:tid 352615] [client 122.179.91.63:19457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RE8JSWzG9jbYOtu4qbgAAAMU"]
[Tue Jul 21 07:59:31.216551 2026] [security2:error] [pid 352421:tid 352598] [client 95.17.48.254:39521] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "carolinadona.com"] [uri "/templates-magneticos/"] [unique_id "al9RE8JSWzG9jbYOtu4qbwAAALQ"]
[Tue Jul 21 07:59:31.500290 2026] [security2:error] [pid 352421:tid 352671] [client 65.21.113.253:56968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RE8JSWzG9jbYOtu4qbAAAAP0"]
[Tue Jul 21 07:59:31.531108 2026] [security2:error] [pid 352421:tid 352626] [client 20.151.10.161:20400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/xxx.php"] [unique_id "al9RE8JSWzG9jbYOtu4qeAAAANA"]
[Tue Jul 21 07:59:31.672785 2026] [security2:error] [pid 352421:tid 352602] [client 198.54.128.138:41616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9RE8JSWzG9jbYOtu4qgAAAALg"]
[Tue Jul 21 07:59:31.672885 2026] [security2:error] [pid 352421:tid 352602] [client 198.54.128.138:41616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9RE8JSWzG9jbYOtu4qgAAAALg"]
[Tue Jul 21 07:59:32.026720 2026] [security2:error] [pid 352421:tid 352642] [client 4.204.201.85:61588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/177.php"] [unique_id "al9RFMJSWzG9jbYOtu4qiwAAAOA"]
[Tue Jul 21 07:59:32.160237 2026] [security2:error] [pid 352421:tid 352594] [client 202.143.127.214:61055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RFMJSWzG9jbYOtu4qkAAAALA"]
[Tue Jul 21 07:59:32.160385 2026] [security2:error] [pid 352421:tid 352594] [client 202.143.127.214:61055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RFMJSWzG9jbYOtu4qkAAAALA"]
[Tue Jul 21 07:59:32.171703 2026] [security2:error] [pid 352421:tid 352621] [client 195.63.31.239:57111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RFMJSWzG9jbYOtu4qigAAAMs"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:59:32.368026 2026] [security2:error] [pid 352421:tid 352677] [client 20.151.10.161:20382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/hypo.php"] [unique_id "al9RFMJSWzG9jbYOtu4qkQAAAQM"]
[Tue Jul 21 07:59:32.498822 2026] [security2:error] [pid 352421:tid 352582] [client 184.75.221.3:55404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9RFMJSWzG9jbYOtu4qlwAAAKQ"]
[Tue Jul 21 07:59:32.498929 2026] [security2:error] [pid 352421:tid 352582] [client 184.75.221.3:55404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9RFMJSWzG9jbYOtu4qlwAAAKQ"]
[Tue Jul 21 07:59:32.827715 2026] [security2:error] [pid 352421:tid 352625] [client 20.104.96.117:46698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/ho.php"] [unique_id "al9RFMJSWzG9jbYOtu4qnwAAAM8"]
[Tue Jul 21 07:59:32.886377 2026] [security2:error] [pid 352421:tid 352487] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RFMJSWzG9jbYOtu4qoAAAwEE"]
[Tue Jul 21 07:59:32.886507 2026] [security2:error] [pid 352421:tid 352610] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RFMJSWzG9jbYOtu4qoAAAwEE"]
[Tue Jul 21 07:59:32.957941 2026] [security2:error] [pid 352421:tid 352563] [client 193.36.225.120:56267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9RFMJSWzG9jbYOtu4qpwAAAJE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:59:33.094364 2026] [security2:error] [pid 352421:tid 352495] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RFcJSWzG9jbYOtu4qqgAAu0k"]
[Tue Jul 21 07:59:33.094564 2026] [security2:error] [pid 352421:tid 352605] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RFcJSWzG9jbYOtu4qqgAAu0k"]
[Tue Jul 21 07:59:33.165577 2026] [proxy:error] [pid 352421:tid 352653] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:33.165677 2026] [proxy_http:error] [pid 352421:tid 352653] [client 20.151.10.161:20368] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:33.166552 2026] [proxy:error] [pid 352421:tid 352653] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:33.166590 2026] [proxy_http:error] [pid 352421:tid 352653] [client 20.151.10.161:20368] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:33.415989 2026] [security2:error] [pid 352421:tid 352577] [client 4.204.201.85:61618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/config.php"] [unique_id "al9RFcJSWzG9jbYOtu4qsgAAAJ8"]
[Tue Jul 21 07:59:33.478552 2026] [security2:error] [pid 352421:tid 352595] [client 136.144.33.104:24945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RFcJSWzG9jbYOtu4qsQAAALE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:33.512762 2026] [security2:error] [pid 352421:tid 352635] [client 117.210.135.0:60464] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RFcJSWzG9jbYOtu4qtgAAANk"]
[Tue Jul 21 07:59:33.512897 2026] [security2:error] [pid 352421:tid 352635] [client 117.210.135.0:60464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RFcJSWzG9jbYOtu4qtgAAANk"]
[Tue Jul 21 07:59:33.564072 2026] [security2:error] [pid 352421:tid 352667] [client 41.68.90.219:52624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RFcJSWzG9jbYOtu4quAAAAPk"]
[Tue Jul 21 07:59:33.565224 2026] [security2:error] [pid 352421:tid 352667] [client 41.68.90.219:52624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RFcJSWzG9jbYOtu4quAAAAPk"]
[Tue Jul 21 07:59:33.894829 2026] [security2:error] [pid 352421:tid 352581] [client 20.104.96.117:46684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xy.php"] [unique_id "al9RFcJSWzG9jbYOtu4qvgAAAKM"]
[Tue Jul 21 07:59:34.083534 2026] [security2:error] [pid 352421:tid 352602] [client 178.153.91.96:53730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RFsJSWzG9jbYOtu4qxwAAALg"]
[Tue Jul 21 07:59:34.083688 2026] [security2:error] [pid 352421:tid 352602] [client 178.153.91.96:53730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RFsJSWzG9jbYOtu4qxwAAALg"]
[Tue Jul 21 07:59:34.186503 2026] [security2:error] [pid 352421:tid 352632] [client 20.151.10.161:20367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/chosen.php"] [unique_id "al9RFsJSWzG9jbYOtu4qyQAAANY"]
[Tue Jul 21 07:59:34.541226 2026] [security2:error] [pid 352421:tid 352648] [client 4.204.201.85:61571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/gettest.php"] [unique_id "al9RFsJSWzG9jbYOtu4q0wAAAOY"]
[Tue Jul 21 07:59:34.757346 2026] [security2:error] [pid 352421:tid 352647] [client 65.21.113.253:50066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RFsJSWzG9jbYOtu4q2gAAAOU"]
[Tue Jul 21 07:59:34.929249 2026] [security2:error] [pid 352421:tid 352652] [client 182.8.255.181:17213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RFsJSWzG9jbYOtu4q3AAAAOo"]
[Tue Jul 21 07:59:34.929402 2026] [security2:error] [pid 352421:tid 352652] [client 182.8.255.181:17213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RFsJSWzG9jbYOtu4q3AAAAOo"]
[Tue Jul 21 07:59:34.985711 2026] [proxy:error] [pid 352421:tid 352653] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:34.985790 2026] [proxy_http:error] [pid 352421:tid 352653] [client 20.151.10.161:20444] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:34.986280 2026] [proxy:error] [pid 352421:tid 352653] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:34.986310 2026] [proxy_http:error] [pid 352421:tid 352653] [client 20.151.10.161:20444] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:34.989412 2026] [security2:error] [pid 352421:tid 352559] [client 38.100.221.102:18285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RFsJSWzG9jbYOtu4q3wAAAI0"]
[Tue Jul 21 07:59:34.989515 2026] [security2:error] [pid 352421:tid 352559] [client 38.100.221.102:18285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RFsJSWzG9jbYOtu4q3wAAAI0"]
[Tue Jul 21 07:59:35.138712 2026] [security2:error] [pid 352421:tid 352435] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RF8JSWzG9jbYOtu4q5AAAjA0"]
[Tue Jul 21 07:59:35.138908 2026] [security2:error] [pid 352421:tid 352558] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RF8JSWzG9jbYOtu4q5AAAjA0"]
[Tue Jul 21 07:59:35.251144 2026] [security2:error] [pid 352421:tid 352571] [client 20.226.60.151:65440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/kq1.php"] [unique_id "al9RF8JSWzG9jbYOtu4q5QAAAJk"]
[Tue Jul 21 07:59:35.399833 2026] [security2:error] [pid 352421:tid 352592] [client 65.21.113.253:48296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RFsJSWzG9jbYOtu4q3QAAAK4"]
[Tue Jul 21 07:59:35.455772 2026] [security2:error] [pid 352421:tid 352496] [remote 165.22.141.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.141.22.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RF8JSWzG9jbYOtu4q6wAAmko"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:59:35.481266 2026] [security2:error] [pid 352421:tid 352459] [remote 165.22.141.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.141.22.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RF8JSWzG9jbYOtu4q7AAA2CU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:59:35.493612 2026] [security2:error] [pid 352421:tid 352646] [client 20.104.96.117:46654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/loader.php"] [unique_id "al9RF8JSWzG9jbYOtu4q8gAAAOQ"]
[Tue Jul 21 07:59:35.599524 2026] [security2:error] [pid 352421:tid 352657] [client 20.151.10.161:20433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/file5.php"] [unique_id "al9RF8JSWzG9jbYOtu4q_QAAAO8"]
[Tue Jul 21 07:59:35.679002 2026] [security2:error] [pid 352421:tid 352540] [remote 165.22.141.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.141.22.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RF8JSWzG9jbYOtu4rAAAAnXY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:59:35.699504 2026] [security2:error] [pid 352421:tid 352511] [remote 165.22.141.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.141.22.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RF8JSWzG9jbYOtu4rAQAAm1k"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:59:35.716353 2026] [security2:error] [pid 352421:tid 352506] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RF8JSWzG9jbYOtu4rAgAA7FQ"]
[Tue Jul 21 07:59:35.716561 2026] [security2:error] [pid 352421:tid 352654] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RF8JSWzG9jbYOtu4rAgAA7FQ"]
[Tue Jul 21 07:59:35.738120 2026] [security2:error] [pid 352421:tid 352456] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RF8JSWzG9jbYOtu4rBAAA6CI"]
[Tue Jul 21 07:59:35.738310 2026] [security2:error] [pid 352421:tid 352650] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RF8JSWzG9jbYOtu4rBAAA6CI"]
[Tue Jul 21 07:59:35.739378 2026] [security2:error] [pid 352421:tid 352544] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RF8JSWzG9jbYOtu4rAwAA43o"]
[Tue Jul 21 07:59:35.739629 2026] [security2:error] [pid 352421:tid 352645] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RF8JSWzG9jbYOtu4rAwAA43o"]
[Tue Jul 21 07:59:35.772111 2026] [security2:error] [pid 352421:tid 352590] [client 4.204.201.85:61592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/min.php"] [unique_id "al9RF8JSWzG9jbYOtu4rBQAAAKw"]
[Tue Jul 21 07:59:35.813766 2026] [security2:error] [pid 352421:tid 352570] [client 65.21.113.253:56972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RF8JSWzG9jbYOtu4q7wAAAJg"]
[Tue Jul 21 07:59:35.888184 2026] [security2:error] [pid 352421:tid 352479] [remote 165.22.141.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.141.22.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RF8JSWzG9jbYOtu4rCgAAnTk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:59:35.908146 2026] [security2:error] [pid 352421:tid 352504] [remote 165.22.141.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.141.22.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RF8JSWzG9jbYOtu4rCwAAm1I"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:59:36.076995 2026] [security2:error] [pid 352421:tid 352611] [client 188.87.191.143:42832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "carolinadona.com"] [uri "/templates-magneticos/"] [unique_id "al9RGMJSWzG9jbYOtu4rDgAAAME"]
[Tue Jul 21 07:59:36.099007 2026] [security2:error] [pid 352421:tid 352431] [remote 165.22.141.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.141.22.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RGMJSWzG9jbYOtu4rEAAAnQk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:59:36.109880 2026] [security2:error] [pid 352421:tid 352586] [client 59.93.4.33:52354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RGMJSWzG9jbYOtu4rEQAAAKg"]
[Tue Jul 21 07:59:36.110007 2026] [security2:error] [pid 352421:tid 352586] [client 59.93.4.33:52354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RGMJSWzG9jbYOtu4rEQAAAKg"]
[Tue Jul 21 07:59:36.115757 2026] [security2:error] [pid 352421:tid 352520] [remote 165.22.141.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.141.22.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RGMJSWzG9jbYOtu4rEgAAm2I"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:59:36.312925 2026] [security2:error] [pid 352421:tid 352440] [remote 165.22.141.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.141.22.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RGMJSWzG9jbYOtu4rFgAAnRI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:59:36.401041 2026] [security2:error] [pid 352421:tid 352517] [remote 165.22.141.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.141.22.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RF8JSWzG9jbYOtu4q6QAAnV8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:59:36.446298 2026] [security2:error] [pid 352421:tid 352476] [remote 165.22.141.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.141.22.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RF8JSWzG9jbYOtu4q6gAAmzY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 07:59:36.485154 2026] [security2:error] [pid 352421:tid 352663] [client 20.151.10.161:20386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/file.php"] [unique_id "al9RGMJSWzG9jbYOtu4rHgAAAPU"]
[Tue Jul 21 07:59:36.512358 2026] [security2:error] [pid 352421:tid 352559] [client 74.249.245.134:5567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/byp.php"] [unique_id "al9RGMJSWzG9jbYOtu4rIQAAAI0"]
[Tue Jul 21 07:59:36.927944 2026] [security2:error] [pid 352421:tid 352562] [client 193.36.225.72:37395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RGMJSWzG9jbYOtu4rNAAAAJA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:37.044272 2026] [security2:error] [pid 352421:tid 352609] [client 117.247.80.59:12475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RGcJSWzG9jbYOtu4rNQAAAL8"]
[Tue Jul 21 07:59:37.044924 2026] [security2:error] [pid 352421:tid 352609] [client 117.247.80.59:12475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RGcJSWzG9jbYOtu4rNQAAAL8"]
[Tue Jul 21 07:59:37.056977 2026] [security2:error] [pid 352421:tid 352606] [client 4.204.201.85:61054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/dvjul.php"] [unique_id "al9RGcJSWzG9jbYOtu4rNgAAALw"]
[Tue Jul 21 07:59:37.167702 2026] [security2:error] [pid 352421:tid 352628] [client 109.60.28.94:48549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RGcJSWzG9jbYOtu4rPgAAANI"]
[Tue Jul 21 07:59:37.167799 2026] [security2:error] [pid 352421:tid 352628] [client 109.60.28.94:48549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RGcJSWzG9jbYOtu4rPgAAANI"]
[Tue Jul 21 07:59:37.195557 2026] [security2:error] [pid 352421:tid 352645] [client 65.21.113.253:50066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RGcJSWzG9jbYOtu4rPwAAAOM"]
[Tue Jul 21 07:59:37.206605 2026] [security2:error] [pid 352421:tid 352623] [client 20.104.96.117:46601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/spadex.php"] [unique_id "al9RGcJSWzG9jbYOtu4rQAAAAM0"]
[Tue Jul 21 07:59:37.208467 2026] [security2:error] [pid 352421:tid 352600] [client 20.151.10.161:20322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/aa2.php"] [unique_id "al9RGcJSWzG9jbYOtu4rQQAAALY"]
[Tue Jul 21 07:59:37.811708 2026] [security2:error] [pid 352421:tid 352567] [client 223.236.153.128:5999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RGcJSWzG9jbYOtu4rZAAAAJU"]
[Tue Jul 21 07:59:37.811873 2026] [security2:error] [pid 352421:tid 352567] [client 223.236.153.128:5999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RGcJSWzG9jbYOtu4rZAAAAJU"]
[Tue Jul 21 07:59:37.811952 2026] [security2:error] [pid 352421:tid 352612] [client 65.21.113.253:48296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RGcJSWzG9jbYOtu4rTQAAAMI"]
[Tue Jul 21 07:59:37.946931 2026] [security2:error] [pid 352421:tid 352630] [client 20.151.10.161:20467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/ccou.php"] [unique_id "al9RGcJSWzG9jbYOtu4rZQAAANQ"]
[Tue Jul 21 07:59:37.947964 2026] [security2:error] [pid 352421:tid 352604] [client 20.197.192.193:3733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/ace2.php"] [unique_id "al9RGcJSWzG9jbYOtu4rZgAAALo"]
[Tue Jul 21 07:59:37.974377 2026] [security2:error] [pid 352421:tid 352597] [client 175.144.82.48:53300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RGcJSWzG9jbYOtu4rYwAAALM"]
[Tue Jul 21 07:59:37.974499 2026] [security2:error] [pid 352421:tid 352597] [client 175.144.82.48:53300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RGcJSWzG9jbYOtu4rYwAAALM"]
[Tue Jul 21 07:59:38.503322 2026] [security2:error] [pid 352421:tid 352652] [client 20.151.10.161:20308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/dr.php"] [unique_id "al9RGsJSWzG9jbYOtu4rfgAAAOo"]
[Tue Jul 21 07:59:38.660981 2026] [security2:error] [pid 352421:tid 352663] [client 87.116.180.198:27268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RGsJSWzG9jbYOtu4riAAAAPU"]
[Tue Jul 21 07:59:38.661084 2026] [security2:error] [pid 352421:tid 352663] [client 87.116.180.198:27268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RGsJSWzG9jbYOtu4riAAAAPU"]
[Tue Jul 21 07:59:38.894913 2026] [security2:error] [pid 352421:tid 352639] [client 20.151.10.161:20460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/file31.php"] [unique_id "al9RGsJSWzG9jbYOtu4rkgAAAN0"]
[Tue Jul 21 07:59:38.950475 2026] [security2:error] [pid 352421:tid 352495] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RGsJSWzG9jbYOtu4rkwAAsEk"]
[Tue Jul 21 07:59:38.950655 2026] [security2:error] [pid 352421:tid 352594] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RGsJSWzG9jbYOtu4rkwAAsEk"]
[Tue Jul 21 07:59:38.957344 2026] [security2:error] [pid 352421:tid 352491] [remote 45.79.123.44:50320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kaducontractor.com"] [uri "/wp-login.php"] [unique_id "al9RGsJSWzG9jbYOtu4rlAAAmkU"]
[Tue Jul 21 07:59:39.051554 2026] [security2:error] [pid 352421:tid 352577] [client 106.215.181.8:11540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RG8JSWzG9jbYOtu4roAAAAJ8"]
[Tue Jul 21 07:59:39.051707 2026] [security2:error] [pid 352421:tid 352577] [client 106.215.181.8:11540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RG8JSWzG9jbYOtu4roAAAAJ8"]
[Tue Jul 21 07:59:39.207631 2026] [security2:error] [pid 352421:tid 352672] [client 4.204.201.85:9660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/biufile.php"] [unique_id "al9RG8JSWzG9jbYOtu4rqAAAAP4"]
[Tue Jul 21 07:59:39.277897 2026] [security2:error] [pid 352421:tid 352625] [client 20.151.10.161:20379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/file6.php"] [unique_id "al9RG8JSWzG9jbYOtu4rtgAAAM8"]
[Tue Jul 21 07:59:39.375994 2026] [security2:error] [pid 352421:tid 352489] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RG8JSWzG9jbYOtu4ruQAAiEM"]
[Tue Jul 21 07:59:39.376208 2026] [security2:error] [pid 352421:tid 352554] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RG8JSWzG9jbYOtu4ruQAAiEM"]
[Tue Jul 21 07:59:39.530093 2026] [security2:error] [pid 352421:tid 352585] [client 65.21.113.253:50066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RG8JSWzG9jbYOtu4rwAAAAKc"]
[Tue Jul 21 07:59:39.555644 2026] [security2:error] [pid 352421:tid 352633] [client 45.188.76.215:42199] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "carolinadona.com"] [uri "/"] [unique_id "al9RG8JSWzG9jbYOtu4rwQAAANc"]
[Tue Jul 21 07:59:39.595730 2026] [security2:error] [pid 352421:tid 352643] [client 103.78.200.11:61771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RG8JSWzG9jbYOtu4rwgAAAOE"]
[Tue Jul 21 07:59:39.595873 2026] [security2:error] [pid 352421:tid 352643] [client 103.78.200.11:61771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RG8JSWzG9jbYOtu4rwgAAAOE"]
[Tue Jul 21 07:59:39.731827 2026] [security2:error] [pid 352421:tid 352624] [client 143.244.57.121:49312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9RG8JSWzG9jbYOtu4rxAAAAM4"]
[Tue Jul 21 07:59:39.746210 2026] [security2:error] [pid 352421:tid 352668] [client 20.151.10.161:20429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/file15.php"] [unique_id "al9RG8JSWzG9jbYOtu4rxQAAAPo"]
[Tue Jul 21 07:59:39.873500 2026] [security2:error] [pid 352421:tid 352557] [client 65.21.113.253:56980] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RG8JSWzG9jbYOtu4ruwAAAIs"]
[Tue Jul 21 07:59:40.146560 2026] [security2:error] [pid 352421:tid 352678] [client 20.151.10.161:20332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/jp.php"] [unique_id "al9RHMJSWzG9jbYOtu4r1wAAAQQ"]
[Tue Jul 21 07:59:40.440034 2026] [security2:error] [pid 352421:tid 352485] [remote 102.134.101.35:38352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-login.php"] [unique_id "al9RHMJSWzG9jbYOtu4r8AAA0D8"]
[Tue Jul 21 07:59:40.459428 2026] [security2:error] [pid 352421:tid 352641] [client 103.29.114.44:52424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RHMJSWzG9jbYOtu4r8QAAAN8"]
[Tue Jul 21 07:59:40.459590 2026] [security2:error] [pid 352421:tid 352641] [client 103.29.114.44:52424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RHMJSWzG9jbYOtu4r8QAAAN8"]
[Tue Jul 21 07:59:40.536635 2026] [security2:error] [pid 352421:tid 352577] [client 20.151.10.161:20246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/f35.php"] [unique_id "al9RHMJSWzG9jbYOtu4r8gAAAJ8"]
[Tue Jul 21 07:59:40.537330 2026] [security2:error] [pid 352421:tid 352588] [client 102.206.115.33:59729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RHMJSWzG9jbYOtu4r8wAAAKo"]
[Tue Jul 21 07:59:40.537437 2026] [security2:error] [pid 352421:tid 352588] [client 102.206.115.33:59729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RHMJSWzG9jbYOtu4r8wAAAKo"]
[Tue Jul 21 07:59:40.545930 2026] [security2:error] [pid 352421:tid 352528] [remote 62.60.130.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "vidrosprovetro.com.br"] [uri "/wp-includes/id3/license.txt/"] [unique_id "al9RHMJSWzG9jbYOtu4r9AAAsGo"]
[Tue Jul 21 07:59:40.615482 2026] [security2:error] [pid 352421:tid 352619] [client 65.21.113.253:33952] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RHMJSWzG9jbYOtu4r2QAAAMk"]
[Tue Jul 21 07:59:40.719708 2026] [security2:error] [pid 352421:tid 352632] [client 143.244.57.121:44672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "franciscaco.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RHMJSWzG9jbYOtu4r_AAAANY"]
[Tue Jul 21 07:59:40.791976 2026] [security2:error] [pid 352421:tid 352567] [client 20.151.10.161:39889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9RHMJSWzG9jbYOtu4sAwAAAJU"]
[Tue Jul 21 07:59:40.821900 2026] [security2:error] [pid 352421:tid 352430] [remote 62.60.130.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "vidrosprovetro.com.br"] [uri "/wp-includes/id3/license.txt/wp-json/batch/v1"] [unique_id "al9RHMJSWzG9jbYOtu4sBAAA1Ag"]
[Tue Jul 21 07:59:40.903832 2026] [security2:error] [pid 352421:tid 352644] [client 20.104.96.117:46688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/2x.php"] [unique_id "al9RHMJSWzG9jbYOtu4sCQAAAOI"]
[Tue Jul 21 07:59:40.982021 2026] [security2:error] [pid 352421:tid 352555] [client 20.151.10.161:20416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wp-load.php"] [unique_id "al9RHMJSWzG9jbYOtu4sDAAAAIk"]
[Tue Jul 21 07:59:41.009644 2026] [security2:error] [pid 352421:tid 352603] [client 103.86.117.203:58867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RHcJSWzG9jbYOtu4sDQAAALk"]
[Tue Jul 21 07:59:41.009792 2026] [security2:error] [pid 352421:tid 352603] [client 103.86.117.203:58867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RHcJSWzG9jbYOtu4sDQAAALk"]
[Tue Jul 21 07:59:41.036418 2026] [security2:error] [pid 352421:tid 352600] [client 122.162.144.145:5860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9RHcJSWzG9jbYOtu4sDgAAALY"]
[Tue Jul 21 07:59:41.036560 2026] [security2:error] [pid 352421:tid 352600] [client 122.162.144.145:5860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9RHcJSWzG9jbYOtu4sDgAAALY"]
[Tue Jul 21 07:59:41.056807 2026] [security2:error] [pid 352421:tid 352615] [client 103.166.103.129:3553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RHcJSWzG9jbYOtu4sDwAAAMU"]
[Tue Jul 21 07:59:41.056920 2026] [security2:error] [pid 352421:tid 352615] [client 103.166.103.129:3553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RHcJSWzG9jbYOtu4sDwAAAMU"]
[Tue Jul 21 07:59:41.103359 2026] [security2:error] [pid 352421:tid 352552] [client 172.245.102.44:49223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RHMJSWzG9jbYOtu4sCgAAAIY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:41.395162 2026] [proxy:error] [pid 352421:tid 352556] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:41.395237 2026] [proxy_http:error] [pid 352421:tid 352556] [client 20.151.10.161:20395] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:41.395694 2026] [proxy:error] [pid 352421:tid 352556] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:41.395720 2026] [proxy_http:error] [pid 352421:tid 352556] [client 20.151.10.161:20395] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:41.534448 2026] [security2:error] [pid 352421:tid 352668] [client 143.244.57.121:44686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9RHcJSWzG9jbYOtu4sGgAAAPo"]
[Tue Jul 21 07:59:41.537521 2026] [security2:error] [pid 352421:tid 352573] [client 37.140.223.122:36849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9RHcJSWzG9jbYOtu4sFwAAAJs"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:59:41.788622 2026] [security2:error] [pid 352421:tid 352651] [client 122.179.91.63:11353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RHcJSWzG9jbYOtu4sIAAAAOk"]
[Tue Jul 21 07:59:41.788801 2026] [security2:error] [pid 352421:tid 352651] [client 122.179.91.63:11353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RHcJSWzG9jbYOtu4sIAAAAOk"]
[Tue Jul 21 07:59:41.812977 2026] [proxy:error] [pid 352421:tid 352594] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:41.813053 2026] [proxy_http:error] [pid 352421:tid 352594] [client 20.151.10.161:20461] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:41.813563 2026] [proxy:error] [pid 352421:tid 352594] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 07:59:41.813588 2026] [proxy_http:error] [pid 352421:tid 352594] [client 20.151.10.161:20461] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 07:59:42.353444 2026] [security2:error] [pid 352421:tid 352563] [client 143.244.57.121:42343] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9RHsJSWzG9jbYOtu4sPwAAAJE"]
[Tue Jul 21 07:59:42.419345 2026] [security2:error] [pid 352421:tid 352608] [client 122.164.127.47:63088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RHsJSWzG9jbYOtu4sQwAAAL4"]
[Tue Jul 21 07:59:42.419458 2026] [security2:error] [pid 352421:tid 352608] [client 122.164.127.47:63088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RHsJSWzG9jbYOtu4sQwAAAL4"]
[Tue Jul 21 07:59:42.495036 2026] [security2:error] [pid 352421:tid 352633] [client 20.151.10.161:20396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9RHsJSWzG9jbYOtu4sTQAAANc"]
[Tue Jul 21 07:59:42.692369 2026] [security2:error] [pid 352421:tid 352597] [client 104.207.34.232:62013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.34.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RHsJSWzG9jbYOtu4sUAAAALM"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:59:42.940588 2026] [security2:error] [pid 352421:tid 352623] [client 74.249.245.134:54382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/date.php"] [unique_id "al9RHsJSWzG9jbYOtu4saQAAAM0"]
[Tue Jul 21 07:59:43.100318 2026] [security2:error] [pid 352421:tid 352640] [client 20.151.10.161:20388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wp-links.php"] [unique_id "al9RH8JSWzG9jbYOtu4sbAAAAN4"]
[Tue Jul 21 07:59:43.177987 2026] [security2:error] [pid 352421:tid 352576] [client 143.244.57.121:44714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9RH8JSWzG9jbYOtu4sbgAAAJ4"]
[Tue Jul 21 07:59:43.329206 2026] [security2:error] [pid 352421:tid 352612] [client 195.130.83.22:12857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "carolinadona.com"] [uri "/"] [unique_id "al9RH8JSWzG9jbYOtu4scwAAAMI"]
[Tue Jul 21 07:59:43.556501 2026] [security2:error] [pid 352421:tid 352614] [client 202.143.127.214:61567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RH8JSWzG9jbYOtu4sfgAAAMQ"]
[Tue Jul 21 07:59:43.556634 2026] [security2:error] [pid 352421:tid 352614] [client 202.143.127.214:61567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RH8JSWzG9jbYOtu4sfgAAAMQ"]
[Tue Jul 21 07:59:43.594058 2026] [security2:error] [pid 352421:tid 352622] [client 65.21.113.253:56980] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RH8JSWzG9jbYOtu4sbQAAAMw"]
[Tue Jul 21 07:59:43.596773 2026] [security2:error] [pid 352421:tid 352559] [client 92.119.178.3:47094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9RH8JSWzG9jbYOtu4sgQAAAI0"]
[Tue Jul 21 07:59:43.596859 2026] [security2:error] [pid 352421:tid 352559] [client 92.119.178.3:47094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9RH8JSWzG9jbYOtu4sgQAAAI0"]
[Tue Jul 21 07:59:43.699051 2026] [security2:error] [pid 352421:tid 352441] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RH8JSWzG9jbYOtu4siQAA8hM"]
[Tue Jul 21 07:59:43.699254 2026] [security2:error] [pid 352421:tid 352660] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RH8JSWzG9jbYOtu4siQAA8hM"]
[Tue Jul 21 07:59:43.716586 2026] [security2:error] [pid 352421:tid 352459] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RH8JSWzG9jbYOtu4siwAAxiU"]
[Tue Jul 21 07:59:43.716772 2026] [security2:error] [pid 352421:tid 352616] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RH8JSWzG9jbYOtu4siwAAxiU"]
[Tue Jul 21 07:59:43.836625 2026] [security2:error] [pid 352421:tid 352673] [client 45.3.48.20:62891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.48.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RH8JSWzG9jbYOtu4siAAAAP8"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:59:43.858715 2026] [security2:error] [pid 352421:tid 352571] [client 20.151.10.161:20422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/solo1.php"] [unique_id "al9RH8JSWzG9jbYOtu4smQAAAJk"]
[Tue Jul 21 07:59:43.999095 2026] [security2:error] [pid 352421:tid 352613] [client 143.244.57.121:44718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9RH8JSWzG9jbYOtu4sogAAAMM"]
[Tue Jul 21 07:59:44.084498 2026] [security2:error] [pid 352421:tid 352596] [client 41.68.90.219:53089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RIMJSWzG9jbYOtu4sqQAAALI"]
[Tue Jul 21 07:59:44.085463 2026] [security2:error] [pid 352421:tid 352596] [client 41.68.90.219:53089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RIMJSWzG9jbYOtu4sqQAAALI"]
[Tue Jul 21 07:59:44.140408 2026] [security2:error] [pid 352421:tid 352598] [client 117.210.135.0:61183] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RIMJSWzG9jbYOtu4sqwAAALQ"]
[Tue Jul 21 07:59:44.140857 2026] [security2:error] [pid 352421:tid 352598] [client 117.210.135.0:61183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RIMJSWzG9jbYOtu4sqwAAALQ"]
[Tue Jul 21 07:59:44.153840 2026] [autoindex:error] [pid 352421:tid 352656] [client 198.235.24.240:58624] AH01276: Cannot serve directory /home2/andr9968/artemcamadas.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:59:44.230580 2026] [security2:error] [pid 352421:tid 352657] [client 20.151.10.161:20406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/sixxis.php"] [unique_id "al9RIMJSWzG9jbYOtu4suQAAAO8"]
[Tue Jul 21 07:59:44.346748 2026] [security2:error] [pid 352421:tid 352674] [client 4.204.201.85:61568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/av.php"] [unique_id "al9RIMJSWzG9jbYOtu4swAAAAQA"]
[Tue Jul 21 07:59:44.672925 2026] [security2:error] [pid 352421:tid 352578] [client 178.153.91.96:14995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RIMJSWzG9jbYOtu4szgAAAKA"]
[Tue Jul 21 07:59:44.673041 2026] [security2:error] [pid 352421:tid 352578] [client 178.153.91.96:14995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RIMJSWzG9jbYOtu4szgAAAKA"]
[Tue Jul 21 07:59:44.810039 2026] [security2:error] [pid 352421:tid 352651] [client 104.207.40.176:22781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.40.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RIMJSWzG9jbYOtu4s0QAAAOk"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 07:59:44.816880 2026] [security2:error] [pid 352421:tid 352570] [client 143.244.57.121:44728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9RIMJSWzG9jbYOtu4s0wAAAJg"]
[Tue Jul 21 07:59:44.819248 2026] [security2:error] [pid 352421:tid 352558] [client 20.151.10.161:20391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/2P.update.php"] [unique_id "al9RIMJSWzG9jbYOtu4s1AAAAIw"]
[Tue Jul 21 07:59:44.988104 2026] [autoindex:error] [pid 352421:tid 352608] [client 157.230.13.33:46502] AH01276: Cannot serve directory /home2/inlaud99/kenyetuquinha.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 07:59:45.010807 2026] [security2:error] [pid 352421:tid 352619] [client 193.36.225.70:57887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RIcJSWzG9jbYOtu4s3wAAAMk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:45.183041 2026] [security2:error] [pid 352421:tid 352636] [client 20.226.60.151:59952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/fw/faiyy.php"] [unique_id "al9RIcJSWzG9jbYOtu4s8gAAANo"]
[Tue Jul 21 07:59:45.326180 2026] [security2:error] [pid 352421:tid 352611] [client 182.8.255.181:17701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RIcJSWzG9jbYOtu4tAQAAAME"]
[Tue Jul 21 07:59:45.326307 2026] [security2:error] [pid 352421:tid 352611] [client 182.8.255.181:17701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RIcJSWzG9jbYOtu4tAQAAAME"]
[Tue Jul 21 07:59:45.579190 2026] [security2:error] [pid 352421:tid 352555] [client 38.100.221.102:17673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RIcJSWzG9jbYOtu4tLQAAAIk"]
[Tue Jul 21 07:59:45.579320 2026] [security2:error] [pid 352421:tid 352555] [client 38.100.221.102:17673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RIcJSWzG9jbYOtu4tLQAAAIk"]
[Tue Jul 21 07:59:45.580883 2026] [security2:error] [pid 352421:tid 352458] [remote 199.189.225.40:25747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9RIcJSWzG9jbYOtu4tLAAAhyQ"]
[Tue Jul 21 07:59:45.632455 2026] [security2:error] [pid 352421:tid 352490] [remote 193.36.225.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "onkosclinica.com"] [uri "/"] [unique_id "al9RIcJSWzG9jbYOtu4tMQAA00Q"], referer: http://onkosclinica.com/
[Tue Jul 21 07:59:45.645724 2026] [security2:error] [pid 352421:tid 352657] [client 143.244.57.121:44740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9RIcJSWzG9jbYOtu4tNgAAAO8"]
[Tue Jul 21 07:59:45.740676 2026] [security2:error] [pid 352421:tid 352578] [client 20.151.10.161:20462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/a.php"] [unique_id "al9RIcJSWzG9jbYOtu4tQQAAAKA"]
[Tue Jul 21 07:59:45.816041 2026] [security2:error] [pid 352421:tid 352507] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RIcJSWzG9jbYOtu4tRAAA7FU"]
[Tue Jul 21 07:59:45.816210 2026] [security2:error] [pid 352421:tid 352654] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RIcJSWzG9jbYOtu4tRAAA7FU"]
[Tue Jul 21 07:59:46.076656 2026] [security2:error] [pid 352421:tid 352615] [client 20.104.96.117:46683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/ctex1.php"] [unique_id "al9RIsJSWzG9jbYOtu4tUwAAAMU"]
[Tue Jul 21 07:59:46.092864 2026] [core:alert] [pid 352421:tid 352554] [client 57.141.18.97:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 07:59:46.114973 2026] [security2:error] [pid 352421:tid 352667] [client 20.151.10.161:20328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/k.php"] [unique_id "al9RIsJSWzG9jbYOtu4tWAAAAPk"]
[Tue Jul 21 07:59:46.122839 2026] [security2:error] [pid 352421:tid 352469] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RIsJSWzG9jbYOtu4tWQAAwC8"]
[Tue Jul 21 07:59:46.122985 2026] [security2:error] [pid 352421:tid 352610] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RIsJSWzG9jbYOtu4tWQAAwC8"]
[Tue Jul 21 07:59:46.201708 2026] [security2:error] [pid 352421:tid 352546] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RIsJSWzG9jbYOtu4tXwAA6Xw"]
[Tue Jul 21 07:59:46.201968 2026] [security2:error] [pid 352421:tid 352651] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RIsJSWzG9jbYOtu4tXwAA6Xw"]
[Tue Jul 21 07:59:46.288263 2026] [security2:error] [pid 352421:tid 352573] [client 65.21.113.253:36230] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RIsJSWzG9jbYOtu4tYwAAAJs"]
[Tue Jul 21 07:59:46.328340 2026] [security2:error] [pid 352421:tid 352638] [client 172.245.102.31:49653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9RIcJSWzG9jbYOtu4s7wAAANw"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:59:46.330122 2026] [security2:error] [pid 352421:tid 352544] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RIsJSWzG9jbYOtu4tZQAA-no"]
[Tue Jul 21 07:59:46.330259 2026] [security2:error] [pid 352421:tid 352668] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RIsJSWzG9jbYOtu4tZQAA-no"]
[Tue Jul 21 07:59:46.361679 2026] [security2:error] [pid 352421:tid 352645] [client 156.216.136.50:54470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "carolinadona.com"] [uri "/"] [unique_id "al9RIsJSWzG9jbYOtu4tZgAAAOM"]
[Tue Jul 21 07:59:46.442244 2026] [security2:error] [pid 352421:tid 352671] [client 20.151.10.161:20477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/w.php"] [unique_id "al9RIsJSWzG9jbYOtu4tbwAAAP0"]
[Tue Jul 21 07:59:46.478057 2026] [security2:error] [pid 352421:tid 352571] [client 143.244.57.121:24644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9RIsJSWzG9jbYOtu4tcAAAAJk"]
[Tue Jul 21 07:59:46.529562 2026] [security2:error] [pid 352421:tid 352530] [remote 193.36.225.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "onkosclinica.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al9RIsJSWzG9jbYOtu4tdQAAzWw"], referer: http://onkosclinica.com/wp-includes/css/buttons.css
[Tue Jul 21 07:59:46.588661 2026] [security2:error] [pid 352421:tid 352432] [remote 192.241.143.148:41706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9RIcJSWzG9jbYOtu4tLgABAAo"]
[Tue Jul 21 07:59:46.733425 2026] [security2:error] [pid 352421:tid 352643] [client 59.93.4.33:52878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RIsJSWzG9jbYOtu4tfwAAAOE"]
[Tue Jul 21 07:59:46.733604 2026] [security2:error] [pid 352421:tid 352643] [client 59.93.4.33:52878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RIsJSWzG9jbYOtu4tfwAAAOE"]
[Tue Jul 21 07:59:46.830713 2026] [security2:error] [pid 352421:tid 352604] [client 20.220.225.223:1293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wp-explorer.php"] [unique_id "al9RIsJSWzG9jbYOtu4tggAAALo"]
[Tue Jul 21 07:59:46.919830 2026] [security2:error] [pid 352421:tid 352559] [client 20.151.10.161:20289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/insc.php"] [unique_id "al9RIsJSWzG9jbYOtu4thAAAAI0"]
[Tue Jul 21 07:59:46.958752 2026] [security2:error] [pid 352421:tid 352625] [client 65.21.113.253:56980] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RIsJSWzG9jbYOtu4tdAAAAM8"]
[Tue Jul 21 07:59:47.287259 2026] [security2:error] [pid 352421:tid 352551] [client 20.151.10.161:20380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9RI8JSWzG9jbYOtu4t0AAAAIU"]
[Tue Jul 21 07:59:47.299422 2026] [security2:error] [pid 352421:tid 352552] [client 143.244.57.121:44754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9RI8JSWzG9jbYOtu4t0QAAAIY"]
[Tue Jul 21 07:59:47.435727 2026] [security2:error] [pid 352421:tid 352516] [remote 193.36.225.116:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "onkosclinica.com"] [uri "/media/system/js/core.js"] [unique_id "al9RI8JSWzG9jbYOtu4t2AAArV4"], referer: http://onkosclinica.com/media/system/js/core.js
[Tue Jul 21 07:59:47.588748 2026] [security2:error] [pid 352421:tid 352604] [client 20.226.60.151:59959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/h02ugyh.php"] [unique_id "al9RI8JSWzG9jbYOtu4t3AAAALo"]
[Tue Jul 21 07:59:47.640402 2026] [security2:error] [pid 352421:tid 352512] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9RI8JSWzG9jbYOtu4t4AAA_Fo"], referer: www.google.com
[Tue Jul 21 07:59:47.643801 2026] [security2:error] [pid 352421:tid 352506] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9RI8JSWzG9jbYOtu4t4QAAv1Q"]
[Tue Jul 21 07:59:47.674556 2026] [security2:error] [pid 352421:tid 352428] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp-plain.php"] [unique_id "al9RI8JSWzG9jbYOtu4t4wAAxgY"], referer: www.google.com
[Tue Jul 21 07:59:47.677990 2026] [security2:error] [pid 352421:tid 352569] [client 20.151.10.161:20475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/u.php"] [unique_id "al9RI8JSWzG9jbYOtu4t5QAAAJc"]
[Tue Jul 21 07:59:47.790138 2026] [security2:error] [pid 352421:tid 352605] [client 117.247.80.59:12892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RI8JSWzG9jbYOtu4t6wAAALs"]
[Tue Jul 21 07:59:47.790258 2026] [security2:error] [pid 352421:tid 352605] [client 117.247.80.59:12892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RI8JSWzG9jbYOtu4t6wAAALs"]
[Tue Jul 21 07:59:47.921685 2026] [security2:error] [pid 352421:tid 352566] [client 109.60.28.94:49023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RI8JSWzG9jbYOtu4t8wAAAJQ"]
[Tue Jul 21 07:59:47.922414 2026] [security2:error] [pid 352421:tid 352566] [client 109.60.28.94:49023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RI8JSWzG9jbYOtu4t8wAAAJQ"]
[Tue Jul 21 07:59:47.998664 2026] [security2:error] [pid 352421:tid 352611] [client 74.249.245.134:54394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/pomo.php"] [unique_id "al9RI8JSWzG9jbYOtu4t-gAAAME"]
[Tue Jul 21 07:59:48.062866 2026] [security2:error] [pid 352421:tid 352668] [client 4.204.201.85:9602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/coffexium.php"] [unique_id "al9RJMJSWzG9jbYOtu4t_AAAAPo"]
[Tue Jul 21 07:59:48.114674 2026] [security2:error] [pid 352421:tid 352606] [client 20.151.10.161:20341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/sss.php"] [unique_id "al9RJMJSWzG9jbYOtu4t_wAAALw"]
[Tue Jul 21 07:59:48.116642 2026] [security2:error] [pid 352421:tid 352633] [client 143.244.57.121:44770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9RJMJSWzG9jbYOtu4uAAAAANc"]
[Tue Jul 21 07:59:48.299859 2026] [security2:error] [pid 352421:tid 352517] [remote 182.77.62.24:53174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9RJMJSWzG9jbYOtu4uAwAAnV8"]
[Tue Jul 21 07:59:48.365513 2026] [security2:error] [pid 352421:tid 352678] [client 223.236.153.128:3771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RJMJSWzG9jbYOtu4uCQAAAQQ"]
[Tue Jul 21 07:59:48.365623 2026] [security2:error] [pid 352421:tid 352678] [client 223.236.153.128:3771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RJMJSWzG9jbYOtu4uCQAAAQQ"]
[Tue Jul 21 07:59:48.417403 2026] [security2:error] [pid 352421:tid 352634] [client 20.104.96.117:46610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/edorxrr.php"] [unique_id "al9RJMJSWzG9jbYOtu4uDQAAANg"]
[Tue Jul 21 07:59:48.440223 2026] [security2:error] [pid 352421:tid 352600] [client 65.21.113.253:33964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RI8JSWzG9jbYOtu4t9QAAALY"]
[Tue Jul 21 07:59:48.447127 2026] [security2:error] [pid 352421:tid 352579] [client 20.151.10.161:20325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/sss.php"] [unique_id "al9RJMJSWzG9jbYOtu4uDgAAAKE"]
[Tue Jul 21 07:59:48.762775 2026] [security2:error] [pid 352421:tid 352643] [client 172.245.102.41:33563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RJMJSWzG9jbYOtu4uJwAAAOE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:48.939106 2026] [security2:error] [pid 352421:tid 352566] [client 20.151.10.161:20456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/c.php"] [unique_id "al9RJMJSWzG9jbYOtu4uOQAAAJQ"]
[Tue Jul 21 07:59:48.945104 2026] [security2:error] [pid 352421:tid 352597] [client 143.244.57.121:44778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9RJMJSWzG9jbYOtu4uOgAAALM"]
[Tue Jul 21 07:59:48.982429 2026] [security2:error] [pid 352421:tid 352554] [client 20.151.10.161:39880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/x.php"] [unique_id "al9RJMJSWzG9jbYOtu4uOwAAAIg"]
[Tue Jul 21 07:59:49.217233 2026] [security2:error] [pid 352421:tid 352644] [client 87.116.180.198:27279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RJcJSWzG9jbYOtu4uSQAAAOI"]
[Tue Jul 21 07:59:49.219206 2026] [security2:error] [pid 352421:tid 352644] [client 87.116.180.198:27279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RJcJSWzG9jbYOtu4uSQAAAOI"]
[Tue Jul 21 07:59:49.223767 2026] [security2:error] [pid 352421:tid 352633] [client 20.151.10.161:20457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/aa.php"] [unique_id "al9RJcJSWzG9jbYOtu4uSgAAANc"]
[Tue Jul 21 07:59:49.402178 2026] [security2:error] [pid 352421:tid 352436] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xsvcouon.php"] [unique_id "al9RJcJSWzG9jbYOtu4uUgAAoQ4"], referer: www.google.com
[Tue Jul 21 07:59:49.540368 2026] [security2:error] [pid 352421:tid 352630] [client 20.151.10.161:20358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/100.php"] [unique_id "al9RJcJSWzG9jbYOtu4uVgAAANQ"]
[Tue Jul 21 07:59:49.665575 2026] [security2:error] [pid 352421:tid 352541] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9RJcJSWzG9jbYOtu4uWQAAoHc"], referer: www.google.com
[Tue Jul 21 07:59:49.700135 2026] [security2:error] [pid 352421:tid 352651] [client 106.215.181.8:17649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RJcJSWzG9jbYOtu4uWgAAAOk"]
[Tue Jul 21 07:59:49.700282 2026] [security2:error] [pid 352421:tid 352651] [client 106.215.181.8:17649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RJcJSWzG9jbYOtu4uWgAAAOk"]
[Tue Jul 21 07:59:49.766489 2026] [security2:error] [pid 352421:tid 352678] [client 143.244.57.121:44794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9RJcJSWzG9jbYOtu4uXgAAAQQ"]
[Tue Jul 21 07:59:49.886431 2026] [security2:error] [pid 352421:tid 352655] [client 20.151.10.161:20393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/footer.php"] [unique_id "al9RJcJSWzG9jbYOtu4uYAAAAO0"]
[Tue Jul 21 07:59:49.903431 2026] [security2:error] [pid 352421:tid 352502] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RJcJSWzG9jbYOtu4uYQAAulA"]
[Tue Jul 21 07:59:49.903584 2026] [security2:error] [pid 352421:tid 352604] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RJcJSWzG9jbYOtu4uYQAAulA"]
[Tue Jul 21 07:59:49.925099 2026] [security2:error] [pid 352421:tid 352559] [client 20.226.60.151:60012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-temp.php"] [unique_id "al9RJcJSWzG9jbYOtu4uYwAAAI0"]
[Tue Jul 21 07:59:50.121993 2026] [security2:error] [pid 352421:tid 352483] [remote 185.27.20.235:50264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.20.27.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9RJsJSWzG9jbYOtu4udQAAtz0"]
[Tue Jul 21 07:59:50.149273 2026] [security2:error] [pid 352421:tid 352611] [client 20.104.96.117:46708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/miru1.php"] [unique_id "al9RJsJSWzG9jbYOtu4ueQAAAME"]
[Tue Jul 21 07:59:50.162124 2026] [security2:error] [pid 352421:tid 352626] [client 103.78.200.11:62245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RJsJSWzG9jbYOtu4uegAAANA"]
[Tue Jul 21 07:59:50.162295 2026] [security2:error] [pid 352421:tid 352626] [client 103.78.200.11:62245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RJsJSWzG9jbYOtu4uegAAANA"]
[Tue Jul 21 07:59:50.291217 2026] [security2:error] [pid 352421:tid 352641] [client 20.151.10.161:20373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/users.php"] [unique_id "al9RJsJSWzG9jbYOtu4ukAAAAN8"]
[Tue Jul 21 07:59:50.333554 2026] [security2:error] [pid 352421:tid 352667] [client 65.21.113.253:36230] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RJsJSWzG9jbYOtu4ukgAAAPk"]
[Tue Jul 21 07:59:50.454412 2026] [security2:error] [pid 352421:tid 352549] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RJsJSWzG9jbYOtu4ukwAAuX8"]
[Tue Jul 21 07:59:50.454586 2026] [security2:error] [pid 352421:tid 352603] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RJsJSWzG9jbYOtu4ukwAAuX8"]
[Tue Jul 21 07:59:50.590207 2026] [security2:error] [pid 352421:tid 352661] [client 143.244.57.121:41336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9RJsJSWzG9jbYOtu4umAAAAPM"]
[Tue Jul 21 07:59:50.723097 2026] [security2:error] [pid 352421:tid 352562] [client 20.104.96.117:46673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/sump1.php"] [unique_id "al9RJsJSWzG9jbYOtu4umQAAAJA"]
[Tue Jul 21 07:59:50.778417 2026] [security2:error] [pid 352421:tid 352650] [client 20.151.10.161:20312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/177.php"] [unique_id "al9RJsJSWzG9jbYOtu4uoAAAAOg"]
[Tue Jul 21 07:59:50.936219 2026] [core:error] [pid 352421:tid 352464] [remote 52.167.144.184:62106] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:59:50.936846 2026] [core:error] [pid 352421:tid 352464] [remote 52.167.144.184:62106] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:59:50.968382 2026] [security2:error] [pid 352421:tid 352575] [client 65.21.113.253:33964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RJsJSWzG9jbYOtu4ulgAAAJ0"]
[Tue Jul 21 07:59:51.000460 2026] [security2:error] [pid 352421:tid 352633] [client 103.29.114.44:54669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uqQAAANc"]
[Tue Jul 21 07:59:51.000567 2026] [security2:error] [pid 352421:tid 352633] [client 103.29.114.44:54669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uqQAAANc"]
[Tue Jul 21 07:59:51.038506 2026] [security2:error] [pid 352421:tid 352555] [client 102.206.115.33:61147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uqgAAAIk"]
[Tue Jul 21 07:59:51.038601 2026] [security2:error] [pid 352421:tid 352555] [client 102.206.115.33:61147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uqgAAAIk"]
[Tue Jul 21 07:59:51.061266 2026] [core:error] [pid 352421:tid 352489] [remote 52.167.144.184:62106] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:59:51.061292 2026] [core:error] [pid 352421:tid 352489] [remote 52.167.144.184:62106] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 07:59:51.236025 2026] [security2:error] [pid 352421:tid 352615] [client 20.151.10.161:20363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/config.php"] [unique_id "al9RJ8JSWzG9jbYOtu4usAAAAMU"]
[Tue Jul 21 07:59:51.413084 2026] [security2:error] [pid 352421:tid 352673] [client 143.244.57.121:41342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9RJ8JSWzG9jbYOtu4uuAAAAP8"]
[Tue Jul 21 07:59:51.462933 2026] [security2:error] [pid 352421:tid 352571] [client 20.104.96.117:27127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/file5.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uuQAAAJk"]
[Tue Jul 21 07:59:51.502887 2026] [security2:error] [pid 352421:tid 352609] [client 103.86.117.203:59409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uuwAAAL8"]
[Tue Jul 21 07:59:51.503013 2026] [security2:error] [pid 352421:tid 352609] [client 103.86.117.203:59409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uuwAAAL8"]
[Tue Jul 21 07:59:51.554180 2026] [security2:error] [pid 352421:tid 352521] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uvAAA42M"]
[Tue Jul 21 07:59:51.588305 2026] [security2:error] [pid 352421:tid 352607] [client 20.151.10.161:20326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/gettest.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uwQAAAL0"]
[Tue Jul 21 07:59:51.784822 2026] [security2:error] [pid 352421:tid 352655] [client 122.162.144.145:23868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.144.162.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uxAAAAO0"]
[Tue Jul 21 07:59:51.787300 2026] [security2:error] [pid 352421:tid 352655] [client 122.162.144.145:23868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uxAAAAO0"]
[Tue Jul 21 07:59:51.794652 2026] [security2:error] [pid 352421:tid 352620] [client 103.166.103.129:60414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uxQAAAMo"]
[Tue Jul 21 07:59:51.794772 2026] [security2:error] [pid 352421:tid 352620] [client 103.166.103.129:60414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uxQAAAMo"]
[Tue Jul 21 07:59:51.831492 2026] [security2:error] [pid 352421:tid 352616] [client 4.204.201.85:61599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/core.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uxwAAAMY"]
[Tue Jul 21 07:59:51.924018 2026] [security2:error] [pid 352421:tid 352621] [client 20.151.10.161:20290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/min.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uzgAAAMs"]
[Tue Jul 21 07:59:51.924858 2026] [security2:error] [pid 352421:tid 352594] [client 74.249.245.134:54336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/test1.php"] [unique_id "al9RJ8JSWzG9jbYOtu4uzwAAALA"]
[Tue Jul 21 07:59:51.951965 2026] [security2:error] [pid 352421:tid 352643] [client 198.54.128.138:33374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9RJ8JSWzG9jbYOtu4u0gAAAOE"]
[Tue Jul 21 07:59:51.952086 2026] [security2:error] [pid 352421:tid 352643] [client 198.54.128.138:33374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9RJ8JSWzG9jbYOtu4u0gAAAOE"]
[Tue Jul 21 07:59:52.117108 2026] [security2:error] [pid 352421:tid 352486] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al9RKMJSWzG9jbYOtu4u6AAA-0A"]
[Tue Jul 21 07:59:52.229673 2026] [security2:error] [pid 352421:tid 352657] [client 20.151.10.161:20440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/edorxrr.php"] [unique_id "al9RKMJSWzG9jbYOtu4u8gAAAO8"]
[Tue Jul 21 07:59:52.243729 2026] [security2:error] [pid 352421:tid 352608] [client 143.244.57.121:41344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9RKMJSWzG9jbYOtu4u9AAAAL4"]
[Tue Jul 21 07:59:52.251764 2026] [security2:error] [pid 352421:tid 352590] [client 175.144.82.48:54007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RKMJSWzG9jbYOtu4u9gAAAKw"]
[Tue Jul 21 07:59:52.252612 2026] [security2:error] [pid 352421:tid 352590] [client 175.144.82.48:54007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RKMJSWzG9jbYOtu4u9gAAAKw"]
[Tue Jul 21 07:59:52.264891 2026] [security2:error] [pid 352421:tid 352551] [client 65.21.113.253:36230] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RKMJSWzG9jbYOtu4u9wAAAIU"]
[Tue Jul 21 07:59:52.450156 2026] [security2:error] [pid 352421:tid 352650] [client 122.179.91.63:10506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RKMJSWzG9jbYOtu4vAwAAAOg"]
[Tue Jul 21 07:59:52.450381 2026] [security2:error] [pid 352421:tid 352650] [client 122.179.91.63:10506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RKMJSWzG9jbYOtu4vAwAAAOg"]
[Tue Jul 21 07:59:52.581909 2026] [security2:error] [pid 352421:tid 352614] [client 65.21.113.253:42044] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RKMJSWzG9jbYOtu4u3AAAAMQ"]
[Tue Jul 21 07:59:52.654597 2026] [security2:error] [pid 352421:tid 352553] [client 20.151.10.161:20297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/hur.php"] [unique_id "al9RKMJSWzG9jbYOtu4vDwAAAIc"]
[Tue Jul 21 07:59:52.814477 2026] [security2:error] [pid 352421:tid 352656] [client 20.151.10.161:39933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/j260624_13.php"] [unique_id "al9RKMJSWzG9jbYOtu4vFgAAAO4"]
[Tue Jul 21 07:59:52.955957 2026] [security2:error] [pid 352421:tid 352663] [client 20.104.96.117:46668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/0xD.php"] [unique_id "al9RKMJSWzG9jbYOtu4vJgAAAPU"]
[Tue Jul 21 07:59:52.956177 2026] [security2:error] [pid 352421:tid 352602] [client 20.151.10.161:20385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/zoro.php"] [unique_id "al9RKMJSWzG9jbYOtu4vJwAAALg"]
[Tue Jul 21 07:59:53.071952 2026] [security2:error] [pid 352421:tid 352670] [client 143.244.57.121:14730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9RKcJSWzG9jbYOtu4vNgAAAPw"]
[Tue Jul 21 07:59:53.079376 2026] [security2:error] [pid 352421:tid 352671] [client 122.164.127.47:63942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RKcJSWzG9jbYOtu4vNwAAAP0"]
[Tue Jul 21 07:59:53.079509 2026] [security2:error] [pid 352421:tid 352671] [client 122.164.127.47:63942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RKcJSWzG9jbYOtu4vNwAAAP0"]
[Tue Jul 21 07:59:53.359601 2026] [security2:error] [pid 352421:tid 352578] [client 65.21.113.253:42052] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RKMJSWzG9jbYOtu4vKAAAAKA"]
[Tue Jul 21 07:59:53.430012 2026] [security2:error] [pid 352421:tid 352555] [client 20.151.10.161:20292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/coffexium.php"] [unique_id "al9RKcJSWzG9jbYOtu4vYAAAAIk"]
[Tue Jul 21 07:59:53.439966 2026] [security2:error] [pid 352421:tid 352601] [client 136.144.33.98:54441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RKcJSWzG9jbYOtu4vYQAAALc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:53.737934 2026] [security2:error] [pid 352421:tid 352608] [client 20.151.10.161:20409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/app.php"] [unique_id "al9RKcJSWzG9jbYOtu4vhAAAAL4"]
[Tue Jul 21 07:59:53.873771 2026] [security2:error] [pid 352421:tid 352572] [client 20.220.225.223:1796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/akismet.php"] [unique_id "al9RKcJSWzG9jbYOtu4vngAAAJo"]
[Tue Jul 21 07:59:53.895018 2026] [security2:error] [pid 352421:tid 352581] [client 143.244.57.121:41360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaco.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9RKcJSWzG9jbYOtu4vogAAAKM"]
[Tue Jul 21 07:59:54.055895 2026] [security2:error] [pid 352421:tid 352436] [remote 45.90.123.233:39266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9RKsJSWzG9jbYOtu4vsAAA2A4"]
[Tue Jul 21 07:59:54.140116 2026] [security2:error] [pid 352421:tid 352649] [client 20.151.10.161:20321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/core.php"] [unique_id "al9RKsJSWzG9jbYOtu4vtwAAAOc"]
[Tue Jul 21 07:59:54.207320 2026] [security2:error] [pid 352421:tid 352595] [client 4.204.201.85:60992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/als.php"] [unique_id "al9RKsJSWzG9jbYOtu4vuwAAALE"]
[Tue Jul 21 07:59:54.239121 2026] [security2:error] [pid 352421:tid 352559] [client 37.140.223.191:57131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9RKcJSWzG9jbYOtu4vNQAAAI0"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:59:54.354337 2026] [security2:error] [pid 352421:tid 352443] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RKsJSWzG9jbYOtu4vxAAAmxU"]
[Tue Jul 21 07:59:54.354552 2026] [security2:error] [pid 352421:tid 352573] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RKsJSWzG9jbYOtu4vxAAAmxU"]
[Tue Jul 21 07:59:54.404141 2026] [security2:error] [pid 352421:tid 352585] [client 204.8.98.45:33712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9RKsJSWzG9jbYOtu4vxQAAAKc"]
[Tue Jul 21 07:59:54.404240 2026] [security2:error] [pid 352421:tid 352585] [client 204.8.98.45:33712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9RKsJSWzG9jbYOtu4vxQAAAKc"]
[Tue Jul 21 07:59:54.409051 2026] [security2:error] [pid 352421:tid 352563] [client 20.226.60.151:59961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-content/cong.php"] [unique_id "al9RKsJSWzG9jbYOtu4vxgAAAJE"]
[Tue Jul 21 07:59:54.418311 2026] [security2:error] [pid 352421:tid 352602] [client 20.104.96.117:46602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/fnstall.php"] [unique_id "al9RKsJSWzG9jbYOtu4vxwAAALg"]
[Tue Jul 21 07:59:54.455695 2026] [security2:error] [pid 352421:tid 352514] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RKsJSWzG9jbYOtu4vzAAAplw"]
[Tue Jul 21 07:59:54.455862 2026] [security2:error] [pid 352421:tid 352584] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RKsJSWzG9jbYOtu4vzAAAplw"]
[Tue Jul 21 07:59:54.545772 2026] [security2:error] [pid 352421:tid 352626] [client 20.151.10.161:20307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/main.php"] [unique_id "al9RKsJSWzG9jbYOtu4vzwAAANA"]
[Tue Jul 21 07:59:54.648974 2026] [security2:error] [pid 352421:tid 352631] [client 41.68.90.219:53551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RKsJSWzG9jbYOtu4v0wAAANU"]
[Tue Jul 21 07:59:54.649107 2026] [security2:error] [pid 352421:tid 352631] [client 41.68.90.219:53551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RKsJSWzG9jbYOtu4v0wAAANU"]
[Tue Jul 21 07:59:54.708636 2026] [security2:error] [pid 352421:tid 352651] [client 117.210.135.0:61890] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RKsJSWzG9jbYOtu4v1AAAAOk"]
[Tue Jul 21 07:59:54.708771 2026] [security2:error] [pid 352421:tid 352651] [client 117.210.135.0:61890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RKsJSWzG9jbYOtu4v1AAAAOk"]
[Tue Jul 21 07:59:54.822142 2026] [security2:error] [pid 352421:tid 352616] [client 202.143.127.214:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RKsJSWzG9jbYOtu4v3QAAAMY"]
[Tue Jul 21 07:59:54.822254 2026] [security2:error] [pid 352421:tid 352616] [client 202.143.127.214:62291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RKsJSWzG9jbYOtu4v3QAAAMY"]
[Tue Jul 21 07:59:55.120973 2026] [security2:error] [pid 352421:tid 352591] [client 20.151.10.161:20384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/init.php"] [unique_id "al9RK8JSWzG9jbYOtu4v9AAAAK0"]
[Tue Jul 21 07:59:55.145435 2026] [security2:error] [pid 352421:tid 352639] [client 178.153.91.96:15685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RK8JSWzG9jbYOtu4v9QAAAN0"]
[Tue Jul 21 07:59:55.145554 2026] [security2:error] [pid 352421:tid 352639] [client 178.153.91.96:15685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RK8JSWzG9jbYOtu4v9QAAAN0"]
[Tue Jul 21 07:59:55.428178 2026] [security2:error] [pid 352421:tid 352659] [client 20.104.96.117:46692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/acp.php"] [unique_id "al9RK8JSWzG9jbYOtu4wAAAAAPE"]
[Tue Jul 21 07:59:55.463361 2026] [security2:error] [pid 352421:tid 352593] [client 216.244.66.201:44248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.combolog.com.br"] [uri "/"] [unique_id "al9RK8JSWzG9jbYOtu4wAwAAAK8"]
[Tue Jul 21 07:59:55.463483 2026] [security2:error] [pid 352421:tid 352593] [client 216.244.66.201:44248] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.combolog.com.br"] [uri "/"] [unique_id "al9RK8JSWzG9jbYOtu4wAwAAAK8"]
[Tue Jul 21 07:59:55.507024 2026] [security2:error] [pid 352421:tid 352555] [client 74.249.245.134:17448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/fw.php"] [unique_id "al9RK8JSWzG9jbYOtu4wDgAAAIk"]
[Tue Jul 21 07:59:55.519201 2026] [security2:error] [pid 352421:tid 352652] [client 20.151.10.161:20451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/prekel.php"] [unique_id "al9RK8JSWzG9jbYOtu4wEAAAAOo"]
[Tue Jul 21 07:59:55.566929 2026] [security2:error] [pid 352421:tid 352586] [client 20.151.10.161:39825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/d62.php"] [unique_id "al9RK8JSWzG9jbYOtu4wFAAAAKg"]
[Tue Jul 21 07:59:55.612315 2026] [security2:error] [pid 352421:tid 352611] [client 20.226.60.151:60018] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.lupipet.com"] [uri "/wp-admin/js/widget/"] [unique_id "al9RK8JSWzG9jbYOtu4wHAAAAME"]
[Tue Jul 21 07:59:55.623621 2026] [security2:error] [pid 352421:tid 352576] [client 182.8.255.181:21065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RK8JSWzG9jbYOtu4wHQAAAJ4"]
[Tue Jul 21 07:59:55.623735 2026] [security2:error] [pid 352421:tid 352576] [client 182.8.255.181:21065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RK8JSWzG9jbYOtu4wHQAAAJ4"]
[Tue Jul 21 07:59:55.658405 2026] [security2:error] [pid 352421:tid 352472] [remote 5.252.52.249:39042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9RK8JSWzG9jbYOtu4wIwAAtjI"]
[Tue Jul 21 07:59:55.885508 2026] [security2:error] [pid 352421:tid 352534] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "al9RK8JSWzG9jbYOtu4wOwABA3A"]
[Tue Jul 21 07:59:55.960149 2026] [security2:error] [pid 352421:tid 352650] [client 20.151.10.161:20418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/0.php"] [unique_id "al9RK8JSWzG9jbYOtu4wPAAAAOg"]
[Tue Jul 21 07:59:56.102254 2026] [security2:error] [pid 352421:tid 352657] [client 65.21.113.253:42044] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RK8JSWzG9jbYOtu4wJAAAAO8"]
[Tue Jul 21 07:59:56.161786 2026] [security2:error] [pid 352421:tid 352633] [client 38.100.221.102:17554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RLMJSWzG9jbYOtu4wQgAAANc"]
[Tue Jul 21 07:59:56.162054 2026] [security2:error] [pid 352421:tid 352633] [client 38.100.221.102:17554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RLMJSWzG9jbYOtu4wQgAAANc"]
[Tue Jul 21 07:59:56.209011 2026] [security2:error] [pid 352421:tid 352581] [client 4.204.201.85:9601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/simple.php"] [unique_id "al9RLMJSWzG9jbYOtu4wQwAAAKM"]
[Tue Jul 21 07:59:56.214068 2026] [security2:error] [pid 352421:tid 352665] [client 20.151.10.161:4229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botecocarnenalata.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9RLMJSWzG9jbYOtu4wRAAAAPc"]
[Tue Jul 21 07:59:56.239097 2026] [security2:error] [pid 352421:tid 352564] [client 65.21.113.253:36230] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RLMJSWzG9jbYOtu4wRwAAAJI"]
[Tue Jul 21 07:59:56.399379 2026] [security2:error] [pid 352421:tid 352604] [client 20.151.10.161:20401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/BDKR28.php"] [unique_id "al9RLMJSWzG9jbYOtu4wTQAAALo"]
[Tue Jul 21 07:59:56.491147 2026] [security2:error] [pid 352421:tid 352563] [client 20.151.10.161:4871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botecocarnenalata.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9RLMJSWzG9jbYOtu4wTwAAAJE"]
[Tue Jul 21 07:59:56.539864 2026] [security2:error] [pid 352421:tid 352470] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RLMJSWzG9jbYOtu4wUAAA1DA"]
[Tue Jul 21 07:59:56.540103 2026] [security2:error] [pid 352421:tid 352630] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RLMJSWzG9jbYOtu4wUAAA1DA"]
[Tue Jul 21 07:59:56.626202 2026] [security2:error] [pid 352421:tid 352525] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RLMJSWzG9jbYOtu4wUwAAwWc"]
[Tue Jul 21 07:59:56.626333 2026] [security2:error] [pid 352421:tid 352611] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RLMJSWzG9jbYOtu4wUwAAwWc"]
[Tue Jul 21 07:59:56.638425 2026] [security2:error] [pid 352421:tid 352429] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "al9RLMJSWzG9jbYOtu4wVgAAtgc"]
[Tue Jul 21 07:59:56.654474 2026] [security2:error] [pid 352421:tid 352519] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RLMJSWzG9jbYOtu4wVwAA4mE"]
[Tue Jul 21 07:59:56.654639 2026] [security2:error] [pid 352421:tid 352644] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RLMJSWzG9jbYOtu4wVwAA4mE"]
[Tue Jul 21 07:59:56.705324 2026] [security2:error] [pid 352421:tid 352456] [remote 18.61.192.253:34872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "formaesplendida.com"] [uri "/wp-login.php"] [unique_id "al9RLMJSWzG9jbYOtu4wWQAAriI"]
[Tue Jul 21 07:59:56.768973 2026] [security2:error] [pid 352421:tid 352662] [client 20.151.10.161:4908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botecocarnenalata.com.br"] [uri "/images.php"] [unique_id "al9RLMJSWzG9jbYOtu4wWgAAAPQ"]
[Tue Jul 21 07:59:56.771743 2026] [security2:error] [pid 352421:tid 352638] [client 136.144.33.112:63951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RLMJSWzG9jbYOtu4wWwAAANw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 07:59:56.794555 2026] [security2:error] [pid 352421:tid 352631] [client 20.151.10.161:20305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/f35.update.php"] [unique_id "al9RLMJSWzG9jbYOtu4wXAAAANU"]
[Tue Jul 21 07:59:56.868368 2026] [security2:error] [pid 352421:tid 352582] [client 65.21.113.253:42044] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RLMJSWzG9jbYOtu4wTgAAAKQ"]
[Tue Jul 21 07:59:56.952915 2026] [security2:error] [pid 352421:tid 352635] [client 204.8.98.45:60156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9RLMJSWzG9jbYOtu4wYwAAANk"]
[Tue Jul 21 07:59:56.953016 2026] [security2:error] [pid 352421:tid 352635] [client 204.8.98.45:60156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9RLMJSWzG9jbYOtu4wYwAAANk"]
[Tue Jul 21 07:59:56.990387 2026] [security2:error] [pid 352421:tid 352524] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RLMJSWzG9jbYOtu4wZAAAzWY"]
[Tue Jul 21 07:59:56.990513 2026] [security2:error] [pid 352421:tid 352623] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RLMJSWzG9jbYOtu4wZAAAzWY"]
[Tue Jul 21 07:59:57.052339 2026] [security2:error] [pid 352421:tid 352666] [client 20.151.10.161:4872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botecocarnenalata.com.br"] [uri "/for.php"] [unique_id "al9RLcJSWzG9jbYOtu4wZQAAAPg"]
[Tue Jul 21 07:59:57.247273 2026] [security2:error] [pid 352421:tid 352654] [client 20.151.10.161:20381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/f900.php"] [unique_id "al9RLcJSWzG9jbYOtu4wbAAAAOw"]
[Tue Jul 21 07:59:57.327760 2026] [security2:error] [pid 352421:tid 352653] [client 20.151.10.161:4224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botecocarnenalata.com.br"] [uri "/2larp.php"] [unique_id "al9RLcJSWzG9jbYOtu4wcgAAAOs"]
[Tue Jul 21 07:59:57.423715 2026] [security2:error] [pid 352421:tid 352610] [client 59.93.4.33:53411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RLcJSWzG9jbYOtu4wdQAAAMA"]
[Tue Jul 21 07:59:57.423921 2026] [security2:error] [pid 352421:tid 352610] [client 59.93.4.33:53411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RLcJSWzG9jbYOtu4wdQAAAMA"]
[Tue Jul 21 07:59:57.451959 2026] [security2:error] [pid 352421:tid 352574] [client 20.226.60.151:65464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-includes/css/index.php"] [unique_id "al9RLcJSWzG9jbYOtu4wewAAAJw"]
[Tue Jul 21 07:59:57.466451 2026] [security2:error] [pid 352421:tid 352563] [client 74.7.241.181:40738] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.gpcom.com.br"] [uri "/robots.txt"] [unique_id "al9RLcJSWzG9jbYOtu4wfAAAAJE"]
[Tue Jul 21 07:59:57.529830 2026] [security2:error] [pid 352421:tid 352659] [client 20.220.225.223:1330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/ace2.php"] [unique_id "al9RLcJSWzG9jbYOtu4wggAAAPE"]
[Tue Jul 21 07:59:57.584583 2026] [security2:error] [pid 352421:tid 352600] [client 74.7.244.5:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.psicologafernandaguedes.com"] [uri "/___proxy_subdomain_cpanel/cgi-sys/404.html"] [unique_id "al9RLcJSWzG9jbYOtu4wiAAAALY"]
[Tue Jul 21 07:59:57.585046 2026] [security2:error] [pid 352421:tid 352615] [client 74.7.244.5:55882] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel.psicologafernandaguedes.com"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "al9RLcJSWzG9jbYOtu4whQAAxS0"]
[Tue Jul 21 07:59:57.616751 2026] [security2:error] [pid 352421:tid 352644] [client 20.151.10.161:4898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botecocarnenalata.com.br"] [uri "/adminner.php"] [unique_id "al9RLcJSWzG9jbYOtu4wkgAAAOI"]
[Tue Jul 21 07:59:57.642891 2026] [security2:error] [pid 352421:tid 352588] [client 20.151.10.161:20412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/xmrl.php"] [unique_id "al9RLcJSWzG9jbYOtu4wkwAAAKo"]
[Tue Jul 21 07:59:57.899143 2026] [security2:error] [pid 352421:tid 352661] [client 20.151.10.161:4232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botecocarnenalata.com.br"] [uri "/82.php"] [unique_id "al9RLcJSWzG9jbYOtu4wqQAAAPM"]
[Tue Jul 21 07:59:58.043225 2026] [security2:error] [pid 352421:tid 352664] [client 20.151.10.161:20387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/memberfuns.php"] [unique_id "al9RLsJSWzG9jbYOtu4wsAAAAPY"]
[Tue Jul 21 07:59:58.177680 2026] [security2:error] [pid 352421:tid 352564] [client 20.151.10.161:4894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botecocarnenalata.com.br"] [uri "/kir.php"] [unique_id "al9RLsJSWzG9jbYOtu4wtQAAAJI"]
[Tue Jul 21 07:59:58.265886 2026] [security2:error] [pid 352421:tid 352612] [client 20.104.96.117:46678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/mosty.php"] [unique_id "al9RLsJSWzG9jbYOtu4wugAAAMI"]
[Tue Jul 21 07:59:58.299600 2026] [access_compat:error] [pid 352421:tid 352566] [client 162.241.63.68:21472] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 07:59:58.324460 2026] [security2:error] [pid 352421:tid 352558] [client 175.144.82.48:54375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RLsJSWzG9jbYOtu4wvAAAAIw"]
[Tue Jul 21 07:59:58.325192 2026] [security2:error] [pid 352421:tid 352558] [client 175.144.82.48:54375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RLsJSWzG9jbYOtu4wvAAAAIw"]
[Tue Jul 21 07:59:58.350361 2026] [security2:error] [pid 352421:tid 352555] [client 20.151.10.161:20354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/ms.php"] [unique_id "al9RLsJSWzG9jbYOtu4wvQAAAIk"]
[Tue Jul 21 07:59:58.391530 2026] [security2:error] [pid 352421:tid 352643] [client 74.249.245.134:54369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/fm.php"] [unique_id "al9RLsJSWzG9jbYOtu4wvwAAAOE"]
[Tue Jul 21 07:59:58.520447 2026] [security2:error] [pid 352421:tid 352652] [client 20.151.10.161:39916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/ups.php"] [unique_id "al9RLsJSWzG9jbYOtu4wxgAAAOo"]
[Tue Jul 21 07:59:58.540505 2026] [security2:error] [pid 352421:tid 352675] [client 37.140.223.152:28913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9RLsJSWzG9jbYOtu4wyAAAAQE"], referer: https://efrelectronics.com.br/wp-admin/
[Tue Jul 21 07:59:58.597594 2026] [security2:error] [pid 352421:tid 352556] [client 117.247.80.59:28405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RLsJSWzG9jbYOtu4wyQAAAIo"]
[Tue Jul 21 07:59:58.597721 2026] [security2:error] [pid 352421:tid 352556] [client 117.247.80.59:28405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RLsJSWzG9jbYOtu4wyQAAAIo"]
[Tue Jul 21 07:59:58.668401 2026] [security2:error] [pid 352421:tid 352646] [client 20.104.96.117:46600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/6.php"] [unique_id "al9RLsJSWzG9jbYOtu4wzgAAAOQ"]
[Tue Jul 21 07:59:58.699288 2026] [security2:error] [pid 352421:tid 352667] [client 20.151.10.161:20301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/zz.php"] [unique_id "al9RLsJSWzG9jbYOtu4wzwAAAPk"]
[Tue Jul 21 07:59:58.911183 2026] [security2:error] [pid 352421:tid 352640] [client 4.204.201.85:9590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/init.php"] [unique_id "al9RLsJSWzG9jbYOtu4w1QAAAN4"]
[Tue Jul 21 07:59:58.952428 2026] [security2:error] [pid 352421:tid 352604] [client 109.60.28.94:50038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RLsJSWzG9jbYOtu4w1wAAALo"]
[Tue Jul 21 07:59:58.952587 2026] [security2:error] [pid 352421:tid 352604] [client 109.60.28.94:50038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RLsJSWzG9jbYOtu4w1wAAALo"]
[Tue Jul 21 07:59:58.975839 2026] [security2:error] [pid 352421:tid 352661] [client 20.226.60.151:60017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/jj.php"] [unique_id "al9RLsJSWzG9jbYOtu4w2QAAAPM"]
[Tue Jul 21 07:59:59.048917 2026] [security2:error] [pid 352421:tid 352597] [client 223.236.153.128:5289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RL8JSWzG9jbYOtu4w3QAAALM"]
[Tue Jul 21 07:59:59.053727 2026] [security2:error] [pid 352421:tid 352597] [client 223.236.153.128:5289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RL8JSWzG9jbYOtu4w3QAAALM"]
[Tue Jul 21 07:59:59.180091 2026] [security2:error] [pid 352421:tid 352551] [client 20.151.10.161:20394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/for.php"] [unique_id "al9RL8JSWzG9jbYOtu4w4wAAAIU"]
[Tue Jul 21 07:59:59.499502 2026] [security2:error] [pid 352421:tid 352643] [client 20.220.225.223:1326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/ms.php"] [unique_id "al9RL8JSWzG9jbYOtu4w8QAAAOE"]
[Tue Jul 21 07:59:59.610061 2026] [security2:error] [pid 352421:tid 352552] [client 65.21.113.253:42056] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RL8JSWzG9jbYOtu4w3wAAAIY"]
[Tue Jul 21 07:59:59.661349 2026] [security2:error] [pid 352421:tid 352641] [client 20.151.10.161:20339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/yup.php"] [unique_id "al9RL8JSWzG9jbYOtu4xAwAAAN8"]
[Tue Jul 21 07:59:59.774807 2026] [security2:error] [pid 352421:tid 352580] [client 20.104.96.117:27095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9RL8JSWzG9jbYOtu4xFQAAAKI"]
[Tue Jul 21 07:59:59.839548 2026] [security2:error] [pid 352421:tid 352575] [client 87.116.180.198:27298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RL8JSWzG9jbYOtu4xFwAAAJ0"]
[Tue Jul 21 07:59:59.839675 2026] [security2:error] [pid 352421:tid 352575] [client 87.116.180.198:27298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RL8JSWzG9jbYOtu4xFwAAAJ0"]
[Tue Jul 21 07:59:59.972937 2026] [security2:error] [pid 352421:tid 352657] [client 20.226.60.151:65443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al9RL8JSWzG9jbYOtu4xIAAAAO8"]
[Tue Jul 21 07:59:59.978749 2026] [security2:error] [pid 352421:tid 352631] [client 20.151.10.161:39905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/k.php"] [unique_id "al9RL8JSWzG9jbYOtu4xIQAAANU"]
[Tue Jul 21 08:00:00.064017 2026] [security2:error] [pid 352421:tid 352590] [client 20.151.10.161:20378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/wpxml.php"] [unique_id "al9RMMJSWzG9jbYOtu4xJwAAAKw"]
[Tue Jul 21 08:00:00.120593 2026] [core:error] [pid 352421:tid 352519] [remote 40.77.167.247:44423] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:00:00.120608 2026] [core:error] [pid 352421:tid 352519] [remote 40.77.167.247:44423] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:00:00.179108 2026] [core:error] [pid 352421:tid 352655] [client 66.249.66.68:42804] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:00:00.179124 2026] [core:error] [pid 352421:tid 352655] [client 66.249.66.68:42804] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:00:00.336713 2026] [security2:error] [pid 352421:tid 352611] [client 106.215.181.8:2513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RMMJSWzG9jbYOtu4xXQAAAME"]
[Tue Jul 21 08:00:00.336871 2026] [security2:error] [pid 352421:tid 352611] [client 106.215.181.8:2513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RMMJSWzG9jbYOtu4xXQAAAME"]
[Tue Jul 21 08:00:00.340392 2026] [security2:error] [pid 352421:tid 352573] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9RMMJSWzG9jbYOtu4xXgAAAJs"]
[Tue Jul 21 08:00:00.365315 2026] [security2:error] [pid 352421:tid 352585] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9RMMJSWzG9jbYOtu4xYAAAAKc"]
[Tue Jul 21 08:00:00.385170 2026] [security2:error] [pid 352421:tid 352557] [client 20.151.10.161:20288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/fffm.php"] [unique_id "al9RMMJSWzG9jbYOtu4xYQAAAIs"]
[Tue Jul 21 08:00:00.587806 2026] [security2:error] [pid 352421:tid 352556] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9RMMJSWzG9jbYOtu4xigAAAIo"]
[Tue Jul 21 08:00:00.639990 2026] [security2:error] [pid 352421:tid 352667] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9RMMJSWzG9jbYOtu4xlgAAAPk"]
[Tue Jul 21 08:00:00.649624 2026] [security2:error] [pid 352421:tid 352597] [client 103.78.200.11:62716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RMMJSWzG9jbYOtu4xlwAAALM"]
[Tue Jul 21 08:00:00.649718 2026] [security2:error] [pid 352421:tid 352597] [client 103.78.200.11:62716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RMMJSWzG9jbYOtu4xlwAAALM"]
[Tue Jul 21 08:00:00.705592 2026] [security2:error] [pid 352421:tid 352561] [client 20.151.10.161:20294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/gecko.php"] [unique_id "al9RMMJSWzG9jbYOtu4xngAAAI8"]
[Tue Jul 21 08:00:00.716325 2026] [security2:error] [pid 352421:tid 352613] [client 20.226.60.151:59987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/txets.php"] [unique_id "al9RMMJSWzG9jbYOtu4xoQAAAMM"]
[Tue Jul 21 08:00:00.871105 2026] [security2:error] [pid 352421:tid 352562] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9RMMJSWzG9jbYOtu4xrQAAAJA"]
[Tue Jul 21 08:00:00.953719 2026] [security2:error] [pid 352421:tid 352519] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RMMJSWzG9jbYOtu4xsAAA92E"]
[Tue Jul 21 08:00:00.953909 2026] [security2:error] [pid 352421:tid 352665] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RMMJSWzG9jbYOtu4xsAAA92E"]
[Tue Jul 21 08:00:01.046458 2026] [security2:error] [pid 352421:tid 352652] [client 20.151.10.161:20468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/a1.php"] [unique_id "al9RMcJSWzG9jbYOtu4xsQAAAOo"]
[Tue Jul 21 08:00:01.058212 2026] [security2:error] [pid 352421:tid 352654] [client 4.204.201.85:9609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/fpwch.php"] [unique_id "al9RMcJSWzG9jbYOtu4xsgAAAOw"]
[Tue Jul 21 08:00:01.114297 2026] [security2:error] [pid 352421:tid 352670] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9RMcJSWzG9jbYOtu4xtwAAAPw"]
[Tue Jul 21 08:00:01.124345 2026] [security2:error] [pid 352421:tid 352658] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9RMcJSWzG9jbYOtu4xuAAAAPA"]
[Tue Jul 21 08:00:01.147239 2026] [security2:error] [pid 352421:tid 352466] [remote 132.148.72.88:52984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9RMcJSWzG9jbYOtu4xugAAmSw"]
[Tue Jul 21 08:00:01.154294 2026] [security2:error] [pid 352421:tid 352643] [client 20.151.10.161:39873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/k2.php"] [unique_id "al9RMcJSWzG9jbYOtu4xuwAAAOE"]
[Tue Jul 21 08:00:01.256396 2026] [security2:error] [pid 352421:tid 352659] [client 20.104.96.117:46598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/qqqa.php"] [unique_id "al9RMcJSWzG9jbYOtu4xvAAAAPE"]
[Tue Jul 21 08:00:01.389133 2026] [security2:error] [pid 352421:tid 352627] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9RMcJSWzG9jbYOtu4x1AAAANE"]
[Tue Jul 21 08:00:01.393164 2026] [security2:error] [pid 352421:tid 352663] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9RMcJSWzG9jbYOtu4x1QAAAPU"]
[Tue Jul 21 08:00:01.404195 2026] [security2:error] [pid 352421:tid 352618] [client 20.151.10.161:20452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/k2.php"] [unique_id "al9RMcJSWzG9jbYOtu4x1wAAAMg"]
[Tue Jul 21 08:00:01.522375 2026] [security2:error] [pid 352421:tid 352610] [client 136.144.33.101:26791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RMcJSWzG9jbYOtu4x4QAAAMA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:00:01.522549 2026] [security2:error] [pid 352421:tid 352533] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RMcJSWzG9jbYOtu4x4gAAiW8"]
[Tue Jul 21 08:00:01.522929 2026] [security2:error] [pid 352421:tid 352555] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RMcJSWzG9jbYOtu4x4gAAiW8"]
[Tue Jul 21 08:00:01.554349 2026] [security2:error] [pid 352421:tid 352631] [client 102.206.115.33:65177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RMcJSWzG9jbYOtu4x4wAAANU"]
[Tue Jul 21 08:00:01.554500 2026] [security2:error] [pid 352421:tid 352631] [client 102.206.115.33:65177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RMcJSWzG9jbYOtu4x4wAAANU"]
[Tue Jul 21 08:00:01.645685 2026] [security2:error] [pid 352421:tid 352572] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9RMcJSWzG9jbYOtu4x6AAAAJo"]
[Tue Jul 21 08:00:01.647080 2026] [security2:error] [pid 352421:tid 352492] [remote 216.73.160.43:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-login.php"] [unique_id "al9RMcJSWzG9jbYOtu4x5wAA0kY"]
[Tue Jul 21 08:00:01.719444 2026] [security2:error] [pid 352421:tid 352552] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9RMcJSWzG9jbYOtu4x7AAAAIY"]
[Tue Jul 21 08:00:01.737717 2026] [security2:error] [pid 352421:tid 352664] [client 103.29.114.44:55300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RMcJSWzG9jbYOtu4x7QAAAPY"]
[Tue Jul 21 08:00:01.738035 2026] [security2:error] [pid 352421:tid 352664] [client 103.29.114.44:55300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RMcJSWzG9jbYOtu4x7QAAAPY"]
[Tue Jul 21 08:00:01.793895 2026] [security2:error] [pid 352421:tid 352652] [client 20.151.10.161:20279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/82.php"] [unique_id "al9RMcJSWzG9jbYOtu4x8AAAAOo"]
[Tue Jul 21 08:00:01.908920 2026] [security2:error] [pid 352421:tid 352656] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9RMcJSWzG9jbYOtu4x_AAAAO4"]
[Tue Jul 21 08:00:01.926210 2026] [security2:error] [pid 352421:tid 352559] [client 20.151.10.161:39918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/k3.php"] [unique_id "al9RMcJSWzG9jbYOtu4yBgAAAI0"]
[Tue Jul 21 08:00:01.981032 2026] [security2:error] [pid 352421:tid 352607] [client 103.86.117.203:59950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RMcJSWzG9jbYOtu4yBwAAAL0"]
[Tue Jul 21 08:00:01.981341 2026] [security2:error] [pid 352421:tid 352607] [client 103.86.117.203:59950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RMcJSWzG9jbYOtu4yBwAAAL0"]
[Tue Jul 21 08:00:01.999483 2026] [security2:error] [pid 352421:tid 352659] [client 4.204.201.85:9568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/domvf.php"] [unique_id "al9RMcJSWzG9jbYOtu4yCAAAAPE"]
[Tue Jul 21 08:00:02.004789 2026] [security2:error] [pid 352421:tid 352602] [client 74.249.245.134:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/ini.php"] [unique_id "al9RMsJSWzG9jbYOtu4yCQAAALg"]
[Tue Jul 21 08:00:02.109399 2026] [security2:error] [pid 352421:tid 352642] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9RMsJSWzG9jbYOtu4yCgAAAOA"]
[Tue Jul 21 08:00:02.157423 2026] [security2:error] [pid 352421:tid 352619] [client 20.151.10.161:20335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/config.json.php"] [unique_id "al9RMsJSWzG9jbYOtu4yDAAAAMk"]
[Tue Jul 21 08:00:02.205704 2026] [security2:error] [pid 352421:tid 352593] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9RMsJSWzG9jbYOtu4yEAAAAK8"]
[Tue Jul 21 08:00:02.363686 2026] [security2:error] [pid 352421:tid 352583] [client 20.151.10.161:39823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/k4.php"] [unique_id "al9RMsJSWzG9jbYOtu4yHwAAAKU"]
[Tue Jul 21 08:00:02.370168 2026] [security2:error] [pid 352421:tid 352625] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9RMsJSWzG9jbYOtu4yIAAAAM8"]
[Tue Jul 21 08:00:02.513739 2026] [security2:error] [pid 352421:tid 352654] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9RMsJSWzG9jbYOtu4yKwAAAOw"]
[Tue Jul 21 08:00:02.576447 2026] [security2:error] [pid 352421:tid 352569] [client 103.166.103.129:5210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RMsJSWzG9jbYOtu4yLgAAAJc"]
[Tue Jul 21 08:00:02.576621 2026] [security2:error] [pid 352421:tid 352569] [client 103.166.103.129:5210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RMsJSWzG9jbYOtu4yLgAAAJc"]
[Tue Jul 21 08:00:02.618089 2026] [security2:error] [pid 352421:tid 352621] [client 20.151.10.161:20424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.produtosnapromo.com.br"] [uri "/fpwch.php"] [unique_id "al9RMsJSWzG9jbYOtu4yMgAAAMs"]
[Tue Jul 21 08:00:02.641839 2026] [security2:error] [pid 352421:tid 352643] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9RMsJSWzG9jbYOtu4yMwAAAOE"]
[Tue Jul 21 08:00:02.779886 2026] [security2:error] [pid 352421:tid 352588] [client 20.151.10.161:39929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/k5.php"] [unique_id "al9RMsJSWzG9jbYOtu4yPwAAAKo"]
[Tue Jul 21 08:00:02.901941 2026] [security2:error] [pid 352421:tid 352561] [client 4.204.201.85:61028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/wp.php"] [unique_id "al9RMsJSWzG9jbYOtu4yRQAAAI8"]
[Tue Jul 21 08:00:02.946930 2026] [security2:error] [pid 352421:tid 352624] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9RMsJSWzG9jbYOtu4yUAAAAM4"]
[Tue Jul 21 08:00:02.985827 2026] [security2:error] [pid 352421:tid 352584] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9RMsJSWzG9jbYOtu4yVwAAAKY"]
[Tue Jul 21 08:00:03.204543 2026] [security2:error] [pid 352421:tid 352655] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9RM8JSWzG9jbYOtu4yZAAAAO0"]
[Tue Jul 21 08:00:03.211624 2026] [security2:error] [pid 352421:tid 352629] [client 20.104.96.117:46603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/aunmc.php"] [unique_id "al9RM8JSWzG9jbYOtu4yZgAAANM"]
[Tue Jul 21 08:00:03.251079 2026] [security2:error] [pid 352421:tid 352612] [client 122.179.91.63:6965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RM8JSWzG9jbYOtu4yaQAAAMI"]
[Tue Jul 21 08:00:03.252020 2026] [security2:error] [pid 352421:tid 352612] [client 122.179.91.63:6965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RM8JSWzG9jbYOtu4yaQAAAMI"]
[Tue Jul 21 08:00:03.260630 2026] [security2:error] [pid 352421:tid 352621] [client 20.226.60.151:59916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/dex.php"] [unique_id "al9RM8JSWzG9jbYOtu4yagAAAMs"]
[Tue Jul 21 08:00:03.285870 2026] [security2:error] [pid 352421:tid 352585] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9RM8JSWzG9jbYOtu4ybQAAAKc"]
[Tue Jul 21 08:00:03.323218 2026] [security2:error] [pid 352421:tid 352636] [client 20.151.10.161:39885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/w.php"] [unique_id "al9RM8JSWzG9jbYOtu4ybwAAANo"]
[Tue Jul 21 08:00:03.513473 2026] [security2:error] [pid 352421:tid 352669] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9RM8JSWzG9jbYOtu4ydwAAAPs"]
[Tue Jul 21 08:00:03.526188 2026] [security2:error] [pid 352421:tid 352649] [client 122.164.127.47:64536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RM8JSWzG9jbYOtu4yeAAAAOc"]
[Tue Jul 21 08:00:03.526327 2026] [security2:error] [pid 352421:tid 352649] [client 122.164.127.47:64536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RM8JSWzG9jbYOtu4yeAAAAOc"]
[Tue Jul 21 08:00:03.530099 2026] [security2:error] [pid 352421:tid 352615] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9RM8JSWzG9jbYOtu4yegAAAMU"]
[Tue Jul 21 08:00:03.649331 2026] [security2:error] [pid 352421:tid 352623] [client 20.151.10.161:39901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/fpwch.php"] [unique_id "al9RM8JSWzG9jbYOtu4yfQAAAM0"]
[Tue Jul 21 08:00:03.877715 2026] [security2:error] [pid 352421:tid 352606] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9RM8JSWzG9jbYOtu4yhAAAALw"]
[Tue Jul 21 08:00:03.891409 2026] [security2:error] [pid 352421:tid 352678] [client 74.249.245.134:62856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/themes.php"] [unique_id "al9RM8JSWzG9jbYOtu4yhgAAAQQ"]
[Tue Jul 21 08:00:04.028272 2026] [security2:error] [pid 352421:tid 352660] [client 180.153.236.123:22947] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "portalerotes.com.br"] [uri "/"] [unique_id "al9RNMJSWzG9jbYOtu4yigAAAPI"], referer: http://portalerotes.com.br/
[Tue Jul 21 08:00:04.028404 2026] [security2:error] [pid 352421:tid 352660] [client 180.153.236.123:22947] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "portalerotes.com.br"] [uri "/"] [unique_id "al9RNMJSWzG9jbYOtu4yigAAAPI"], referer: http://portalerotes.com.br/
[Tue Jul 21 08:00:04.175546 2026] [security2:error] [pid 352421:tid 352658] [client 4.204.201.85:9659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/class.php"] [unique_id "al9RNMJSWzG9jbYOtu4yjAAAAPA"]
[Tue Jul 21 08:00:04.181195 2026] [security2:error] [pid 352421:tid 352671] [client 20.151.10.161:39903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/w2025.php"] [unique_id "al9RNMJSWzG9jbYOtu4yjQAAAP0"]
[Tue Jul 21 08:00:04.649635 2026] [security2:error] [pid 352421:tid 352504] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "al9RNMJSWzG9jbYOtu4ymwABAVI"]
[Tue Jul 21 08:00:04.761589 2026] [core:error] [pid 352421:tid 352524] [remote 40.77.167.77:18304] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:00:04.761611 2026] [core:error] [pid 352421:tid 352524] [remote 40.77.167.77:18304] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:00:04.847666 2026] [security2:error] [pid 352421:tid 352573] [client 104.207.53.255:37183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RNMJSWzG9jbYOtu4yoAAAAJs"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:00:05.111869 2026] [security2:error] [pid 352421:tid 352577] [client 20.151.10.161:39928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/scxy.php"] [unique_id "al9RNcJSWzG9jbYOtu4yrAAAAJ8"]
[Tue Jul 21 08:00:05.141606 2026] [security2:error] [pid 352421:tid 352567] [client 4.204.201.85:61045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/echkm.php"] [unique_id "al9RNcJSWzG9jbYOtu4yrQAAAJU"]
[Tue Jul 21 08:00:05.179181 2026] [security2:error] [pid 352421:tid 352558] [client 41.68.90.219:54017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RNcJSWzG9jbYOtu4yrwAAAIw"]
[Tue Jul 21 08:00:05.180227 2026] [security2:error] [pid 352421:tid 352558] [client 41.68.90.219:54017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RNcJSWzG9jbYOtu4yrwAAAIw"]
[Tue Jul 21 08:00:05.389423 2026] [security2:error] [pid 352421:tid 352514] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RNcJSWzG9jbYOtu4ytAAAylw"]
[Tue Jul 21 08:00:05.389596 2026] [security2:error] [pid 352421:tid 352620] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RNcJSWzG9jbYOtu4ytAAAylw"]
[Tue Jul 21 08:00:05.391324 2026] [security2:error] [pid 352421:tid 352655] [client 136.144.33.28:44893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RNcJSWzG9jbYOtu4yswAAAO0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:00:05.434184 2026] [security2:error] [pid 352421:tid 352576] [client 20.104.96.117:46672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/uoocf.php"] [unique_id "al9RNcJSWzG9jbYOtu4yuAAAAJ4"]
[Tue Jul 21 08:00:05.446222 2026] [security2:error] [pid 352421:tid 352597] [client 117.210.135.0:62632] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RNcJSWzG9jbYOtu4yuQAAALM"]
[Tue Jul 21 08:00:05.446361 2026] [security2:error] [pid 352421:tid 352597] [client 117.210.135.0:62632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RNcJSWzG9jbYOtu4yuQAAALM"]
[Tue Jul 21 08:00:05.640766 2026] [security2:error] [pid 352421:tid 352659] [client 20.151.10.161:39859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/FWAZ.php"] [unique_id "al9RNcJSWzG9jbYOtu4yxAAAAPE"]
[Tue Jul 21 08:00:05.718589 2026] [autoindex:error] [pid 352421:tid 352652] [client 205.210.31.210:0] AH01276: Cannot serve directory /home4/conte946/produtosnapromo.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:00:05.725641 2026] [security2:error] [pid 352421:tid 352570] [client 178.153.91.96:55618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RNcJSWzG9jbYOtu4yyQAAAJg"]
[Tue Jul 21 08:00:05.725759 2026] [security2:error] [pid 352421:tid 352570] [client 178.153.91.96:55618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RNcJSWzG9jbYOtu4yyQAAAJg"]
[Tue Jul 21 08:00:05.799484 2026] [security2:error] [pid 352421:tid 352582] [client 74.249.245.134:54374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/dropdown.php"] [unique_id "al9RNcJSWzG9jbYOtu4yywAAAKQ"]
[Tue Jul 21 08:00:05.818572 2026] [security2:error] [pid 352421:tid 352606] [client 202.143.127.214:62840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RNcJSWzG9jbYOtu4yzAAAALw"]
[Tue Jul 21 08:00:05.818766 2026] [security2:error] [pid 352421:tid 352606] [client 202.143.127.214:62840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RNcJSWzG9jbYOtu4yzAAAALw"]
[Tue Jul 21 08:00:05.877325 2026] [security2:error] [pid 352421:tid 352510] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RNcJSWzG9jbYOtu4yzgAA91g"]
[Tue Jul 21 08:00:05.877499 2026] [security2:error] [pid 352421:tid 352665] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RNcJSWzG9jbYOtu4yzgAA91g"]
[Tue Jul 21 08:00:05.886872 2026] [security2:error] [pid 352421:tid 352573] [client 20.226.60.151:65444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/xpwer1.php"] [unique_id "al9RNcJSWzG9jbYOtu4yzwAAAJs"]
[Tue Jul 21 08:00:06.009303 2026] [security2:error] [pid 352421:tid 352613] [client 182.8.255.181:17280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RNsJSWzG9jbYOtu4y1wAAAMM"]
[Tue Jul 21 08:00:06.009535 2026] [security2:error] [pid 352421:tid 352613] [client 182.8.255.181:17280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RNsJSWzG9jbYOtu4y1wAAAMM"]
[Tue Jul 21 08:00:06.061226 2026] [security2:error] [pid 352421:tid 352622] [client 45.3.48.112:48707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.48.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RNcJSWzG9jbYOtu4y0AAAAMw"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:00:06.140464 2026] [security2:error] [pid 352421:tid 352625] [client 65.21.113.253:55586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RNcJSWzG9jbYOtu4yxQAAAM8"]
[Tue Jul 21 08:00:06.237659 2026] [security2:error] [pid 352421:tid 352632] [client 20.151.10.161:39879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/qterm.php"] [unique_id "al9RNsJSWzG9jbYOtu4y3AAAANY"]
[Tue Jul 21 08:00:06.466991 2026] [security2:error] [pid 352421:tid 352658] [client 4.204.201.85:9650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/lib.php"] [unique_id "al9RNsJSWzG9jbYOtu4y5QAAAPA"]
[Tue Jul 21 08:00:06.468341 2026] [security2:error] [pid 352421:tid 352634] [client 65.21.113.253:46312] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RNsJSWzG9jbYOtu4y5AAAANg"]
[Tue Jul 21 08:00:06.662887 2026] [security2:error] [pid 352421:tid 352556] [client 20.151.10.161:39930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/blurbs.php"] [unique_id "al9RNsJSWzG9jbYOtu4y6wAAAIo"]
[Tue Jul 21 08:00:06.721452 2026] [security2:error] [pid 352421:tid 352584] [client 38.100.221.102:17585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RNsJSWzG9jbYOtu4y8QAAAKY"]
[Tue Jul 21 08:00:06.721552 2026] [security2:error] [pid 352421:tid 352584] [client 38.100.221.102:17585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RNsJSWzG9jbYOtu4y8QAAAKY"]
[Tue Jul 21 08:00:06.773791 2026] [security2:error] [pid 352421:tid 352652] [client 20.104.96.117:27077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/iywwi.php"] [unique_id "al9RNsJSWzG9jbYOtu4y9AAAAOo"]
[Tue Jul 21 08:00:07.156122 2026] [security2:error] [pid 352421:tid 352446] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RN8JSWzG9jbYOtu4zAAAAzBg"]
[Tue Jul 21 08:00:07.156384 2026] [security2:error] [pid 352421:tid 352622] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RN8JSWzG9jbYOtu4zAAAAzBg"]
[Tue Jul 21 08:00:07.181077 2026] [security2:error] [pid 352421:tid 352471] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RN8JSWzG9jbYOtu4zAgAAzTE"]
[Tue Jul 21 08:00:07.181203 2026] [security2:error] [pid 352421:tid 352623] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RN8JSWzG9jbYOtu4zAgAAzTE"]
[Tue Jul 21 08:00:07.304439 2026] [security2:error] [pid 352421:tid 352647] [client 198.54.128.138:37034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9RN8JSWzG9jbYOtu4zBAAAAOU"]
[Tue Jul 21 08:00:07.304688 2026] [security2:error] [pid 352421:tid 352647] [client 198.54.128.138:37034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9RN8JSWzG9jbYOtu4zBAAAAOU"]
[Tue Jul 21 08:00:07.320884 2026] [security2:error] [pid 352421:tid 352675] [client 20.151.10.161:39855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/v543.php"] [unique_id "al9RN8JSWzG9jbYOtu4zBQAAAQE"]
[Tue Jul 21 08:00:07.383011 2026] [security2:error] [pid 352421:tid 352463] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RN8JSWzG9jbYOtu4zBwAA_yk"]
[Tue Jul 21 08:00:07.383181 2026] [security2:error] [pid 352421:tid 352673] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RN8JSWzG9jbYOtu4zBwAA_yk"]
[Tue Jul 21 08:00:07.541985 2026] [security2:error] [pid 352421:tid 352646] [client 4.204.201.85:61007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/login.php"] [unique_id "al9RN8JSWzG9jbYOtu4zCwAAAOQ"]
[Tue Jul 21 08:00:07.570223 2026] [security2:error] [pid 352421:tid 352582] [client 65.21.113.253:55602] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RN8JSWzG9jbYOtu4y_wAAAKQ"]
[Tue Jul 21 08:00:07.619687 2026] [security2:error] [pid 352421:tid 352480] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RN8JSWzG9jbYOtu4zEQAAszo"]
[Tue Jul 21 08:00:07.619810 2026] [security2:error] [pid 352421:tid 352597] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RN8JSWzG9jbYOtu4zEQAAszo"]
[Tue Jul 21 08:00:07.971784 2026] [security2:error] [pid 352421:tid 352635] [client 20.104.96.117:46697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/gqgsa.php"] [unique_id "al9RN8JSWzG9jbYOtu4zHwAAANk"]
[Tue Jul 21 08:00:08.030160 2026] [security2:error] [pid 352421:tid 352567] [client 59.93.4.33:53936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ROMJSWzG9jbYOtu4zIQAAAJU"]
[Tue Jul 21 08:00:08.030328 2026] [security2:error] [pid 352421:tid 352567] [client 59.93.4.33:53936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ROMJSWzG9jbYOtu4zIQAAAJU"]
[Tue Jul 21 08:00:08.195565 2026] [security2:error] [pid 352421:tid 352557] [client 65.111.7.79:51369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.7.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RN8JSWzG9jbYOtu4y-gAAAIs"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:00:08.294427 2026] [security2:error] [pid 352421:tid 352647] [client 20.226.60.151:60021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/flox.php"] [unique_id "al9ROMJSWzG9jbYOtu4zKwAAAOU"]
[Tue Jul 21 08:00:08.415478 2026] [security2:error] [pid 352421:tid 352604] [client 20.151.10.161:39934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/w3lls.php"] [unique_id "al9ROMJSWzG9jbYOtu4zLgAAALo"]
[Tue Jul 21 08:00:08.698292 2026] [security2:error] [pid 352421:tid 352571] [client 4.204.201.85:9538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/a2.php"] [unique_id "al9ROMJSWzG9jbYOtu4zPgAAAJk"]
[Tue Jul 21 08:00:08.922767 2026] [security2:error] [pid 352421:tid 352677] [client 136.144.33.112:26159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9ROMJSWzG9jbYOtu4zRwAAAQM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:00:09.134151 2026] [security2:error] [pid 352421:tid 352462] [remote 65.111.23.69:22713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9ROcJSWzG9jbYOtu4zTwAAuyg"]
[Tue Jul 21 08:00:09.305776 2026] [security2:error] [pid 352421:tid 352578] [client 223.236.153.128:4580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9ROcJSWzG9jbYOtu4zWQAAAKA"]
[Tue Jul 21 08:00:09.305979 2026] [security2:error] [pid 352421:tid 352578] [client 223.236.153.128:4580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9ROcJSWzG9jbYOtu4zWQAAAKA"]
[Tue Jul 21 08:00:09.316930 2026] [security2:error] [pid 352421:tid 352652] [client 65.111.9.55:11507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.9.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9ROcJSWzG9jbYOtu4zUAAAAOo"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:00:09.318424 2026] [security2:error] [pid 352421:tid 352612] [client 117.247.80.59:13547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ROcJSWzG9jbYOtu4zWwAAAMI"]
[Tue Jul 21 08:00:09.318620 2026] [security2:error] [pid 352421:tid 352612] [client 117.247.80.59:13547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ROcJSWzG9jbYOtu4zWwAAAMI"]
[Tue Jul 21 08:00:09.320431 2026] [security2:error] [pid 352421:tid 352558] [client 65.21.113.253:46312] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9ROcJSWzG9jbYOtu4zWgAAAIw"]
[Tue Jul 21 08:00:09.349848 2026] [security2:error] [pid 352421:tid 352583] [client 4.204.201.85:63251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/d61.php"] [unique_id "al9ROcJSWzG9jbYOtu4zXQAAAKU"]
[Tue Jul 21 08:00:09.820303 2026] [security2:error] [pid 352421:tid 352573] [client 109.60.28.94:50987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ROcJSWzG9jbYOtu4zaAAAAJs"]
[Tue Jul 21 08:00:09.820404 2026] [security2:error] [pid 352421:tid 352573] [client 109.60.28.94:50987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ROcJSWzG9jbYOtu4zaAAAAJs"]
[Tue Jul 21 08:00:09.868428 2026] [security2:error] [pid 352421:tid 352584] [client 20.104.96.117:46625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/elbzl.php"] [unique_id "al9ROcJSWzG9jbYOtu4zawAAAKY"]
[Tue Jul 21 08:00:09.923439 2026] [security2:error] [pid 352421:tid 352590] [client 65.21.113.253:55586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ROcJSWzG9jbYOtu4zXwAAAKw"]
[Tue Jul 21 08:00:09.941600 2026] [security2:error] [pid 352421:tid 352555] [client 204.8.98.45:37206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ROcJSWzG9jbYOtu4zbAAAAIk"]
[Tue Jul 21 08:00:09.941709 2026] [security2:error] [pid 352421:tid 352555] [client 204.8.98.45:37206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ROcJSWzG9jbYOtu4zbAAAAIk"]
[Tue Jul 21 08:00:10.340479 2026] [security2:error] [pid 352421:tid 352565] [client 20.151.10.161:39887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-ws68.php"] [unique_id "al9ROsJSWzG9jbYOtu4zfwAAAJM"]
[Tue Jul 21 08:00:10.387693 2026] [security2:error] [pid 352421:tid 352578] [client 4.204.201.85:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/info.php"] [unique_id "al9ROsJSWzG9jbYOtu4zgwAAAKA"]
[Tue Jul 21 08:00:10.522306 2026] [security2:error] [pid 352421:tid 352602] [client 87.116.180.198:13922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ROsJSWzG9jbYOtu4zhgAAALg"]
[Tue Jul 21 08:00:10.522421 2026] [security2:error] [pid 352421:tid 352602] [client 87.116.180.198:13922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ROsJSWzG9jbYOtu4zhgAAALg"]
[Tue Jul 21 08:00:10.921476 2026] [security2:error] [pid 352421:tid 352567] [client 106.215.181.8:27263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ROsJSWzG9jbYOtu4zmAAAAJU"]
[Tue Jul 21 08:00:10.921585 2026] [security2:error] [pid 352421:tid 352567] [client 106.215.181.8:27263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ROsJSWzG9jbYOtu4zmAAAAJU"]
[Tue Jul 21 08:00:10.996736 2026] [security2:error] [pid 352421:tid 352634] [client 175.144.82.48:54796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ROsJSWzG9jbYOtu4zmgAAANg"]
[Tue Jul 21 08:00:10.997220 2026] [security2:error] [pid 352421:tid 352634] [client 175.144.82.48:54796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ROsJSWzG9jbYOtu4zmgAAANg"]
[Tue Jul 21 08:00:10.997769 2026] [security2:error] [pid 352421:tid 352625] [client 4.204.201.85:9589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/11.php"] [unique_id "al9ROsJSWzG9jbYOtu4zmwAAAM8"]
[Tue Jul 21 08:00:11.173867 2026] [security2:error] [pid 352421:tid 352660] [client 103.78.200.11:63192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RO8JSWzG9jbYOtu4znwAAAPI"]
[Tue Jul 21 08:00:11.173963 2026] [security2:error] [pid 352421:tid 352660] [client 103.78.200.11:63192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RO8JSWzG9jbYOtu4znwAAAPI"]
[Tue Jul 21 08:00:11.285513 2026] [security2:error] [pid 352421:tid 352564] [client 74.249.245.134:17419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/wp-links.php"] [unique_id "al9RO8JSWzG9jbYOtu4zpQAAAJI"]
[Tue Jul 21 08:00:11.495906 2026] [security2:error] [pid 352421:tid 352642] [client 20.104.96.117:46616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/adjig.php"] [unique_id "al9RO8JSWzG9jbYOtu4zrgAAAOA"]
[Tue Jul 21 08:00:11.618959 2026] [security2:error] [pid 352421:tid 352584] [client 4.204.201.85:9656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/v2.php"] [unique_id "al9RO8JSWzG9jbYOtu4zrwAAAKY"]
[Tue Jul 21 08:00:11.772873 2026] [security2:error] [pid 352421:tid 352557] [client 65.21.113.253:35474] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RO8JSWzG9jbYOtu4zowAAAIs"]
[Tue Jul 21 08:00:11.878290 2026] [security2:error] [pid 352421:tid 352514] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RO8JSWzG9jbYOtu4zuAAA7lw"]
[Tue Jul 21 08:00:11.878455 2026] [security2:error] [pid 352421:tid 352656] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RO8JSWzG9jbYOtu4zuAAA7lw"]
[Tue Jul 21 08:00:12.217459 2026] [security2:error] [pid 352421:tid 352643] [client 102.206.115.33:60413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RPMJSWzG9jbYOtu4zvwAAAOE"]
[Tue Jul 21 08:00:12.217577 2026] [security2:error] [pid 352421:tid 352643] [client 102.206.115.33:60413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RPMJSWzG9jbYOtu4zvwAAAOE"]
[Tue Jul 21 08:00:12.284986 2026] [security2:error] [pid 352421:tid 352655] [client 103.29.114.44:6568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RPMJSWzG9jbYOtu4zxAAAAO0"]
[Tue Jul 21 08:00:12.285210 2026] [security2:error] [pid 352421:tid 352655] [client 103.29.114.44:6568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RPMJSWzG9jbYOtu4zxAAAAO0"]
[Tue Jul 21 08:00:12.362251 2026] [security2:error] [pid 352421:tid 352647] [client 136.144.33.53:31171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RPMJSWzG9jbYOtu4zzwAAAOU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:00:12.419055 2026] [security2:error] [pid 352421:tid 352569] [client 92.119.178.3:60986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9RPMJSWzG9jbYOtu4z0wAAAJc"]
[Tue Jul 21 08:00:12.419154 2026] [security2:error] [pid 352421:tid 352569] [client 92.119.178.3:60986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9RPMJSWzG9jbYOtu4z0wAAAJc"]
[Tue Jul 21 08:00:12.465826 2026] [security2:error] [pid 352421:tid 352677] [client 103.86.117.203:60495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RPMJSWzG9jbYOtu4z1wAAAQM"]
[Tue Jul 21 08:00:12.465941 2026] [security2:error] [pid 352421:tid 352677] [client 103.86.117.203:60495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RPMJSWzG9jbYOtu4z1wAAAQM"]
[Tue Jul 21 08:00:12.472366 2026] [security2:error] [pid 352421:tid 352630] [client 4.204.201.85:9553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/panel.php"] [unique_id "al9RPMJSWzG9jbYOtu4z2QAAANQ"]
[Tue Jul 21 08:00:12.491557 2026] [security2:error] [pid 352421:tid 352456] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RPMJSWzG9jbYOtu4z3AAAvCI"]
[Tue Jul 21 08:00:12.491699 2026] [security2:error] [pid 352421:tid 352606] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RPMJSWzG9jbYOtu4z3AAAvCI"]
[Tue Jul 21 08:00:12.939345 2026] [security2:error] [pid 352421:tid 352585] [client 4.204.201.85:61579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/dex.php"] [unique_id "al9RPMJSWzG9jbYOtu4z6AAAAKc"]
[Tue Jul 21 08:00:13.054994 2026] [security2:error] [pid 352421:tid 352627] [client 20.226.60.151:65470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/popo.php"] [unique_id "al9RPcJSWzG9jbYOtu4z6wAAANE"]
[Tue Jul 21 08:00:13.298101 2026] [security2:error] [pid 352421:tid 352634] [client 20.151.10.161:39893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/xyn.php"] [unique_id "al9RPcJSWzG9jbYOtu4z8QAAANg"]
[Tue Jul 21 08:00:13.308908 2026] [security2:error] [pid 352421:tid 352602] [client 103.166.103.129:6039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RPcJSWzG9jbYOtu4z8gAAALg"]
[Tue Jul 21 08:00:13.309139 2026] [security2:error] [pid 352421:tid 352602] [client 103.166.103.129:6039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RPcJSWzG9jbYOtu4z8gAAALg"]
[Tue Jul 21 08:00:13.571283 2026] [security2:error] [pid 352421:tid 352469] [remote 185.27.20.235:58234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.20.27.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/wp-login.php"] [unique_id "al9RPcJSWzG9jbYOtu40AQAAsC8"]
[Tue Jul 21 08:00:13.581692 2026] [security2:error] [pid 352421:tid 352653] [client 4.204.201.85:9550] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/1.php"] [unique_id "al9RPcJSWzG9jbYOtu40AgAAAOs"]
[Tue Jul 21 08:00:13.581792 2026] [security2:error] [pid 352421:tid 352653] [client 4.204.201.85:9550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/1.php"] [unique_id "al9RPcJSWzG9jbYOtu40AgAAAOs"]
[Tue Jul 21 08:00:13.992197 2026] [security2:error] [pid 352421:tid 352489] [remote 185.236.20.134:62772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zooparquevet.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9RPcJSWzG9jbYOtu40EAAAvUM"]
[Tue Jul 21 08:00:14.078860 2026] [security2:error] [pid 352421:tid 352565] [client 122.164.127.47:65122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RPsJSWzG9jbYOtu40FgAAAJM"]
[Tue Jul 21 08:00:14.078964 2026] [security2:error] [pid 352421:tid 352565] [client 122.164.127.47:65122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RPsJSWzG9jbYOtu40FgAAAJM"]
[Tue Jul 21 08:00:14.206139 2026] [security2:error] [pid 352421:tid 352675] [client 4.204.201.85:63283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/ms.php"] [unique_id "al9RPsJSWzG9jbYOtu40FwAAAQE"]
[Tue Jul 21 08:00:14.609675 2026] [security2:error] [pid 352421:tid 352566] [client 185.236.20.134:29848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zooparquevet.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9RPsJSWzG9jbYOtu40JQAAAJQ"]
[Tue Jul 21 08:00:14.942170 2026] [security2:error] [pid 352421:tid 352570] [client 74.249.245.134:5509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/xmrlpc.php"] [unique_id "al9RPsJSWzG9jbYOtu40LgAAAJg"]
[Tue Jul 21 08:00:15.061903 2026] [security2:error] [pid 352421:tid 352438] [remote 18.61.192.253:45360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9RP8JSWzG9jbYOtu40MwAA9hA"]
[Tue Jul 21 08:00:15.062063 2026] [security2:error] [pid 352421:tid 352664] [client 18.61.192.253:45360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9RP8JSWzG9jbYOtu40MwAA9hA"]
[Tue Jul 21 08:00:15.325674 2026] [security2:error] [pid 352421:tid 352605] [client 198.54.128.138:52420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9RP8JSWzG9jbYOtu40OQAAALs"]
[Tue Jul 21 08:00:15.325907 2026] [security2:error] [pid 352421:tid 352605] [client 198.54.128.138:52420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9RP8JSWzG9jbYOtu40OQAAALs"]
[Tue Jul 21 08:00:15.393025 2026] [security2:error] [pid 352421:tid 352659] [client 20.104.96.117:46713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/byp.php"] [unique_id "al9RP8JSWzG9jbYOtu40OgAAAPE"]
[Tue Jul 21 08:00:15.408418 2026] [security2:error] [pid 352421:tid 352455] [remote 185.236.20.134:7074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.zooparquevet.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9RP8JSWzG9jbYOtu40OwAAvSE"]
[Tue Jul 21 08:00:15.876207 2026] [security2:error] [pid 352421:tid 352479] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RP8JSWzG9jbYOtu40RwAAkDk"]
[Tue Jul 21 08:00:15.876341 2026] [security2:error] [pid 352421:tid 352562] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RP8JSWzG9jbYOtu40RwAAkDk"]
[Tue Jul 21 08:00:16.070884 2026] [security2:error] [pid 352421:tid 352570] [client 4.204.201.85:9576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/memberfuns.php"] [unique_id "al9RQMJSWzG9jbYOtu40UQAAAJg"]
[Tue Jul 21 08:00:16.087825 2026] [security2:error] [pid 352421:tid 352461] [remote 97.74.87.194:49392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9RQMJSWzG9jbYOtu40UgAAnic"]
[Tue Jul 21 08:00:16.137144 2026] [security2:error] [pid 352421:tid 352658] [client 117.210.135.0:63370] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RQMJSWzG9jbYOtu40VwAAAPA"]
[Tue Jul 21 08:00:16.137248 2026] [security2:error] [pid 352421:tid 352658] [client 117.210.135.0:63370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RQMJSWzG9jbYOtu40VwAAAPA"]
[Tue Jul 21 08:00:16.220825 2026] [security2:error] [pid 352421:tid 352579] [client 65.21.113.253:56886] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RQMJSWzG9jbYOtu40WwAAAKE"]
[Tue Jul 21 08:00:16.252879 2026] [security2:error] [pid 352421:tid 352596] [client 178.153.91.96:16914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RQMJSWzG9jbYOtu40XAAAALI"]
[Tue Jul 21 08:00:16.253001 2026] [security2:error] [pid 352421:tid 352596] [client 178.153.91.96:16914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RQMJSWzG9jbYOtu40XAAAALI"]
[Tue Jul 21 08:00:16.365411 2026] [security2:error] [pid 352421:tid 352544] [remote 185.236.20.134:7086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zooparquevet.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9RQMJSWzG9jbYOtu40YQAAuno"]
[Tue Jul 21 08:00:16.466000 2026] [security2:error] [pid 352421:tid 352629] [client 182.8.255.181:21081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RQMJSWzG9jbYOtu40YwAAANM"]
[Tue Jul 21 08:00:16.466115 2026] [security2:error] [pid 352421:tid 352629] [client 182.8.255.181:21081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RQMJSWzG9jbYOtu40YwAAANM"]
[Tue Jul 21 08:00:16.534337 2026] [security2:error] [pid 352421:tid 352566] [client 41.68.90.219:54479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RQMJSWzG9jbYOtu40awAAAJQ"]
[Tue Jul 21 08:00:16.535878 2026] [security2:error] [pid 352421:tid 352566] [client 41.68.90.219:54479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RQMJSWzG9jbYOtu40awAAAJQ"]
[Tue Jul 21 08:00:16.552540 2026] [security2:error] [pid 352421:tid 352508] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RQMJSWzG9jbYOtu40bQAAiFY"]
[Tue Jul 21 08:00:16.552675 2026] [security2:error] [pid 352421:tid 352554] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RQMJSWzG9jbYOtu40bQAAiFY"]
[Tue Jul 21 08:00:16.712746 2026] [security2:error] [pid 352421:tid 352598] [client 20.104.96.117:46611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9RQMJSWzG9jbYOtu40cgAAALQ"]
[Tue Jul 21 08:00:16.828246 2026] [security2:error] [pid 352421:tid 352651] [client 65.21.113.253:35474] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RQMJSWzG9jbYOtu40YgAAAOk"]
[Tue Jul 21 08:00:16.849905 2026] [security2:error] [pid 352421:tid 352585] [client 52.192.8.67:52993] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "larissafurlaneto.online"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9RQMJSWzG9jbYOtu40dAAAAKc"]
[Tue Jul 21 08:00:16.978850 2026] [security2:error] [pid 352421:tid 352605] [client 20.151.10.161:39810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/green3.php"] [unique_id "al9RQMJSWzG9jbYOtu40eQAAALs"]
[Tue Jul 21 08:00:17.033685 2026] [security2:error] [pid 352421:tid 352556] [client 193.36.225.54:62115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RQMJSWzG9jbYOtu40dQAAAIo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:00:17.116945 2026] [security2:error] [pid 352421:tid 352629] [client 185.236.20.134:29854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zooparquevet.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9RQcJSWzG9jbYOtu40gQAAANM"]
[Tue Jul 21 08:00:17.136313 2026] [security2:error] [pid 352421:tid 352624] [client 202.143.127.214:63310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RQcJSWzG9jbYOtu40ggAAAM4"]
[Tue Jul 21 08:00:17.136414 2026] [security2:error] [pid 352421:tid 352624] [client 202.143.127.214:63310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RQcJSWzG9jbYOtu40ggAAAM4"]
[Tue Jul 21 08:00:17.213462 2026] [security2:error] [pid 352421:tid 352562] [client 38.100.221.102:18948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RQcJSWzG9jbYOtu40hQAAAJA"]
[Tue Jul 21 08:00:17.213597 2026] [security2:error] [pid 352421:tid 352562] [client 38.100.221.102:18948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RQcJSWzG9jbYOtu40hQAAAJA"]
[Tue Jul 21 08:00:17.346123 2026] [security2:error] [pid 352421:tid 352594] [client 122.179.91.63:28117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RQcJSWzG9jbYOtu40igAAALA"]
[Tue Jul 21 08:00:17.346334 2026] [security2:error] [pid 352421:tid 352594] [client 122.179.91.63:28117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RQcJSWzG9jbYOtu40igAAALA"]
[Tue Jul 21 08:00:17.476591 2026] [security2:error] [pid 352421:tid 352638] [client 65.21.113.253:35482] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RQMJSWzG9jbYOtu40egAAANw"]
[Tue Jul 21 08:00:17.543704 2026] [security2:error] [pid 352421:tid 352560] [client 52.192.8.67:54078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.8.192.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "larissafurlaneto.online"] [uri "/xmlrpc.php"] [unique_id "al9RQcJSWzG9jbYOtu40jgAAAI4"]
[Tue Jul 21 08:00:17.633495 2026] [security2:error] [pid 352421:tid 352658] [client 74.249.245.134:5540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/htaccess.php"] [unique_id "al9RQcJSWzG9jbYOtu40kgAAAPA"]
[Tue Jul 21 08:00:17.643993 2026] [security2:error] [pid 352421:tid 352496] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RQcJSWzG9jbYOtu40kwAAoko"]
[Tue Jul 21 08:00:17.644139 2026] [security2:error] [pid 352421:tid 352580] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RQcJSWzG9jbYOtu40kwAAoko"]
[Tue Jul 21 08:00:17.663574 2026] [security2:error] [pid 352421:tid 352423] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RQcJSWzG9jbYOtu40lQAA6QE"]
[Tue Jul 21 08:00:17.663715 2026] [security2:error] [pid 352421:tid 352651] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RQcJSWzG9jbYOtu40lQAA6QE"]
[Tue Jul 21 08:00:17.856222 2026] [security2:error] [pid 352421:tid 352612] [client 107.161.92.6:37146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "britotavares.com"] [uri "/.env"] [unique_id "al9RQcJSWzG9jbYOtu40nQAAAMI"]
[Tue Jul 21 08:00:18.098231 2026] [security2:error] [pid 352421:tid 352446] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RQsJSWzG9jbYOtu40owAAkRg"]
[Tue Jul 21 08:00:18.098417 2026] [security2:error] [pid 352421:tid 352563] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RQsJSWzG9jbYOtu40owAAkRg"]
[Tue Jul 21 08:00:18.139015 2026] [security2:error] [pid 352421:tid 352618] [client 4.204.201.85:61590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/0.php"] [unique_id "al9RQsJSWzG9jbYOtu40qAAAAMg"]
[Tue Jul 21 08:00:18.228117 2026] [security2:error] [pid 352421:tid 352578] [client 52.192.8.67:54467] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "larissafurlaneto.online"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9RQsJSWzG9jbYOtu40qwAAAKA"]
[Tue Jul 21 08:00:18.238293 2026] [security2:error] [pid 352421:tid 352531] [remote 185.236.20.134:7088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.zooparquevet.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9RQsJSWzG9jbYOtu40rQAAz20"]
[Tue Jul 21 08:00:18.239416 2026] [security2:error] [pid 352421:tid 352521] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RQsJSWzG9jbYOtu40rgAAxGM"]
[Tue Jul 21 08:00:18.239539 2026] [security2:error] [pid 352421:tid 352614] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RQsJSWzG9jbYOtu40rgAAxGM"]
[Tue Jul 21 08:00:18.690197 2026] [security2:error] [pid 352421:tid 352629] [client 59.93.4.33:54454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RQsJSWzG9jbYOtu40ugAAANM"]
[Tue Jul 21 08:00:18.690315 2026] [security2:error] [pid 352421:tid 352629] [client 59.93.4.33:54454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RQsJSWzG9jbYOtu40ugAAANM"]
[Tue Jul 21 08:00:18.841221 2026] [security2:error] [pid 352421:tid 352437] [remote 185.236.20.134:7102] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "zooparquevet.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9RQsJSWzG9jbYOtu40vQAA1Q8"]
[Tue Jul 21 08:00:18.905793 2026] [security2:error] [pid 352421:tid 352649] [client 52.192.8.67:54894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "larissafurlaneto.online"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9RQsJSWzG9jbYOtu40wAAAAOc"]
[Tue Jul 21 08:00:19.067951 2026] [security2:error] [pid 352421:tid 352558] [client 198.54.128.138:56130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9RQ8JSWzG9jbYOtu40xwAAAIw"]
[Tue Jul 21 08:00:19.068057 2026] [security2:error] [pid 352421:tid 352558] [client 198.54.128.138:56130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9RQ8JSWzG9jbYOtu40xwAAAIw"]
[Tue Jul 21 08:00:19.152656 2026] [security2:error] [pid 352421:tid 352608] [client 4.204.201.85:9610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/BDKR28.php"] [unique_id "al9RQ8JSWzG9jbYOtu40yQAAAL4"]
[Tue Jul 21 08:00:19.290263 2026] [security2:error] [pid 352421:tid 352677] [client 107.161.92.6:37146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "britotavares.com"] [uri "/.env.bak"] [unique_id "al9RQ8JSWzG9jbYOtu40zgAAAQM"]
[Tue Jul 21 08:00:19.357543 2026] [security2:error] [pid 352421:tid 352598] [client 65.21.113.253:56886] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RQ8JSWzG9jbYOtu40zwAAALQ"]
[Tue Jul 21 08:00:19.444942 2026] [security2:error] [pid 352421:tid 352570] [client 185.236.20.134:29856] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "zooparquevet.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9RQ8JSWzG9jbYOtu400QAAAJg"]
[Tue Jul 21 08:00:19.525007 2026] [security2:error] [pid 352421:tid 352651] [client 20.104.96.117:46695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/classwithtostring.php"] [unique_id "al9RQ8JSWzG9jbYOtu400gAAAOk"]
[Tue Jul 21 08:00:19.564910 2026] [security2:error] [pid 352421:tid 352666] [client 65.111.6.84:61849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.6.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RQ8JSWzG9jbYOtu401AAAAPg"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:00:19.568749 2026] [security2:error] [pid 352421:tid 352564] [client 107.161.92.6:37146] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "britotavares.com"] [uri "/.env.backup"] [unique_id "al9RQ8JSWzG9jbYOtu401QAAAJI"]
[Tue Jul 21 08:00:19.586285 2026] [security2:error] [pid 352421:tid 352629] [client 52.192.8.67:55306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "larissafurlaneto.online"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9RQ8JSWzG9jbYOtu402QAAANM"]
[Tue Jul 21 08:00:19.656183 2026] [proxy:error] [pid 352421:tid 352469] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:00:19.656222 2026] [proxy_http:error] [pid 352421:tid 352469] [remote 198.235.24.12:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:00:19.656777 2026] [proxy:error] [pid 352421:tid 352469] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:00:19.656799 2026] [proxy_http:error] [pid 352421:tid 352469] [remote 198.235.24.12:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:00:19.698683 2026] [security2:error] [pid 352421:tid 352604] [client 223.236.153.128:16038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RQ8JSWzG9jbYOtu403gAAALo"]
[Tue Jul 21 08:00:19.698842 2026] [security2:error] [pid 352421:tid 352604] [client 223.236.153.128:16038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RQ8JSWzG9jbYOtu403gAAALo"]
[Tue Jul 21 08:00:19.880549 2026] [security2:error] [pid 352421:tid 352603] [client 20.226.60.151:59944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/yas.php"] [unique_id "al9RQ8JSWzG9jbYOtu405gAAALk"]
[Tue Jul 21 08:00:19.974945 2026] [security2:error] [pid 352421:tid 352579] [client 65.21.113.253:35482] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RQ8JSWzG9jbYOtu402gAAAKE"]
[Tue Jul 21 08:00:20.048389 2026] [security2:error] [pid 352421:tid 352620] [client 117.247.80.59:14469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RRMJSWzG9jbYOtu406gAAAMo"]
[Tue Jul 21 08:00:20.048516 2026] [security2:error] [pid 352421:tid 352620] [client 117.247.80.59:14469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RRMJSWzG9jbYOtu406gAAAMo"]
[Tue Jul 21 08:00:20.138107 2026] [security2:error] [pid 352421:tid 352591] [client 20.151.10.161:39920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/ccs.php"] [unique_id "al9RRMJSWzG9jbYOtu408AAAAK0"]
[Tue Jul 21 08:00:20.154243 2026] [security2:error] [pid 352421:tid 352661] [client 4.204.201.85:63270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/green1.php"] [unique_id "al9RRMJSWzG9jbYOtu408gAAAPM"]
[Tue Jul 21 08:00:20.266822 2026] [security2:error] [pid 352421:tid 352580] [client 52.192.8.67:55723] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "larissafurlaneto.online"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9RRMJSWzG9jbYOtu40_AAAAKI"]
[Tue Jul 21 08:00:20.346528 2026] [security2:error] [pid 352421:tid 352634] [client 175.144.82.48:55143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RRMJSWzG9jbYOtu41AAAAANg"]
[Tue Jul 21 08:00:20.347065 2026] [security2:error] [pid 352421:tid 352634] [client 175.144.82.48:55143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RRMJSWzG9jbYOtu41AAAAANg"]
[Tue Jul 21 08:00:20.469937 2026] [security2:error] [pid 352421:tid 352547] [remote 185.236.20.134:7114] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.zooparquevet.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9RRMJSWzG9jbYOtu41AgAA-n0"]
[Tue Jul 21 08:00:20.684738 2026] [security2:error] [pid 352421:tid 352610] [client 109.60.28.94:51867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RRMJSWzG9jbYOtu41EgAAAMA"]
[Tue Jul 21 08:00:20.684886 2026] [security2:error] [pid 352421:tid 352610] [client 109.60.28.94:51867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RRMJSWzG9jbYOtu41EgAAAMA"]
[Tue Jul 21 08:00:20.797175 2026] [http2:info] [pid 358661:tid 358661] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 08:00:20.830711 2026] [security2:error] [pid 358661:tid 358794] [client 4.204.201.85:61009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/nc4.php"] [unique_id "al9RRAlWhjQfpOo60_HCGwAAAAA"]
[Tue Jul 21 08:00:20.938823 2026] [security2:error] [pid 358661:tid 358799] [client 52.192.8.67:56219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "larissafurlaneto.online"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9RRAlWhjQfpOo60_HCHQAAAAU"]
[Tue Jul 21 08:00:21.056229 2026] [security2:error] [pid 352421:tid 352556] [client 172.245.102.45:59257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RRcJSWzG9jbYOtu41KAAAAIo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:00:21.184900 2026] [security2:error] [pid 352421:tid 352622] [client 87.116.180.198:13906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RRcJSWzG9jbYOtu41LAAAAMw"]
[Tue Jul 21 08:00:21.185602 2026] [security2:error] [pid 352421:tid 352422] [remote 104.207.45.170:44017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.45.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9RRcJSWzG9jbYOtu41JAAA4wA"]
[Tue Jul 21 08:00:21.185640 2026] [security2:error] [pid 352421:tid 352622] [client 87.116.180.198:13906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RRcJSWzG9jbYOtu41LAAAAMw"]
[Tue Jul 21 08:00:21.189484 2026] [security2:error] [pid 352421:tid 352585] [client 107.161.92.6:37158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "britotavares.com"] [uri "/.ssh/id_rsa"] [unique_id "al9RRcJSWzG9jbYOtu41LQAAAKc"]
[Tue Jul 21 08:00:21.395715 2026] [security2:error] [pid 358661:tid 358667] [remote 42.200.84.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "extrapro21.com"] [uri "/wp-login.php"] [unique_id "al9RRQlWhjQfpOo60_HCIwAACwI"]
[Tue Jul 21 08:00:21.434331 2026] [security2:error] [pid 352421:tid 352580] [client 107.161.92.6:37158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "britotavares.com"] [uri "/.ssh/id_dsa"] [unique_id "al9RRcJSWzG9jbYOtu41NAAAAKI"]
[Tue Jul 21 08:00:21.491591 2026] [security2:error] [pid 352421:tid 352586] [client 106.215.181.8:27764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RRcJSWzG9jbYOtu41NQAAAKg"]
[Tue Jul 21 08:00:21.491719 2026] [security2:error] [pid 352421:tid 352586] [client 106.215.181.8:27764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RRcJSWzG9jbYOtu41NQAAAKg"]
[Tue Jul 21 08:00:21.589116 2026] [security2:error] [pid 358661:tid 358819] [client 4.204.201.85:9596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/a1.php"] [unique_id "al9RRQlWhjQfpOo60_HCKAAAABk"]
[Tue Jul 21 08:00:21.626594 2026] [security2:error] [pid 358661:tid 358820] [client 52.192.8.67:56655] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "larissafurlaneto.online"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9RRQlWhjQfpOo60_HCKgAAABo"]
[Tue Jul 21 08:00:21.633593 2026] [security2:error] [pid 352421:tid 352658] [client 35.205.50.49:61728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "woma.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9RRcJSWzG9jbYOtu41PQAAAPA"]
[Tue Jul 21 08:00:21.672664 2026] [security2:error] [pid 352421:tid 352594] [client 45.3.43.251:9129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.43.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RRcJSWzG9jbYOtu41PgAAALA"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:00:21.728001 2026] [security2:error] [pid 358661:tid 358800] [client 103.78.200.11:63668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RRQlWhjQfpOo60_HCKwAAAAY"]
[Tue Jul 21 08:00:21.728148 2026] [security2:error] [pid 358661:tid 358800] [client 103.78.200.11:63668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RRQlWhjQfpOo60_HCKwAAAAY"]
[Tue Jul 21 08:00:21.958042 2026] [security2:error] [pid 352421:tid 352585] [client 82.102.18.188:40368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ekon.eng.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9RRcJSWzG9jbYOtu41TAAAAKc"]
[Tue Jul 21 08:00:22.000336 2026] [security2:error] [pid 352421:tid 352669] [client 65.21.113.253:46740] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RRcJSWzG9jbYOtu41OgAAAPs"]
[Tue Jul 21 08:00:22.189635 2026] [security2:error] [pid 352421:tid 352654] [client 107.161.92.6:37158] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "britotavares.com"] [uri "/config/env.js"] [unique_id "al9RRsJSWzG9jbYOtu41TwAAAOw"]
[Tue Jul 21 08:00:22.301466 2026] [security2:error] [pid 352421:tid 352554] [client 4.204.201.85:9593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/eee.php"] [unique_id "al9RRsJSWzG9jbYOtu41VAAAAIg"]
[Tue Jul 21 08:00:22.310554 2026] [security2:error] [pid 352421:tid 352677] [client 52.192.8.67:57183] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "larissafurlaneto.online"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9RRsJSWzG9jbYOtu41VgAAAQM"]
[Tue Jul 21 08:00:22.686981 2026] [security2:error] [pid 352421:tid 352641] [client 65.21.113.253:56886] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RRsJSWzG9jbYOtu41ZAAAAN8"]
[Tue Jul 21 08:00:22.747119 2026] [security2:error] [pid 358661:tid 358846] [client 82.102.18.188:35038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ekon.eng.br"] [uri "/xmlrpc.php"] [unique_id "al9RRglWhjQfpOo60_HCOAAAADQ"]
[Tue Jul 21 08:00:22.837045 2026] [security2:error] [pid 358661:tid 358834] [client 103.29.114.44:59760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RRglWhjQfpOo60_HCOwAAACg"]
[Tue Jul 21 08:00:22.837164 2026] [security2:error] [pid 358661:tid 358834] [client 103.29.114.44:59760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RRglWhjQfpOo60_HCOwAAACg"]
[Tue Jul 21 08:00:22.889982 2026] [security2:error] [pid 352421:tid 352661] [client 45.3.48.173:43477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.48.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RRsJSWzG9jbYOtu41aAAAAPM"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:00:22.896863 2026] [security2:error] [pid 352421:tid 352434] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RRsJSWzG9jbYOtu41cwAAmAw"]
[Tue Jul 21 08:00:22.897000 2026] [security2:error] [pid 352421:tid 352570] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RRsJSWzG9jbYOtu41cwAAmAw"]
[Tue Jul 21 08:00:22.957310 2026] [security2:error] [pid 358661:tid 358840] [client 103.86.117.203:61040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RRglWhjQfpOo60_HCPQAAAC4"]
[Tue Jul 21 08:00:22.957436 2026] [security2:error] [pid 358661:tid 358840] [client 103.86.117.203:61040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RRglWhjQfpOo60_HCPQAAAC4"]
[Tue Jul 21 08:00:22.983755 2026] [security2:error] [pid 352421:tid 352580] [client 102.206.115.33:65191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RRsJSWzG9jbYOtu41egAAAKI"]
[Tue Jul 21 08:00:22.983883 2026] [security2:error] [pid 352421:tid 352580] [client 102.206.115.33:65191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RRsJSWzG9jbYOtu41egAAAKI"]
[Tue Jul 21 08:00:22.992742 2026] [security2:error] [pid 352421:tid 352649] [client 52.192.8.67:57691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "larissafurlaneto.online"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9RRsJSWzG9jbYOtu41fAAAAOc"]
[Tue Jul 21 08:00:23.003979 2026] [security2:error] [pid 358661:tid 358863] [client 20.151.10.161:39884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/ccc.php"] [unique_id "al9RRwlWhjQfpOo60_HCPgAAAEU"]
[Tue Jul 21 08:00:23.218084 2026] [security2:error] [pid 358661:tid 358871] [client 4.204.201.85:62792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/wp-aothait.php"] [unique_id "al9RRwlWhjQfpOo60_HCQwAAAE0"]
[Tue Jul 21 08:00:23.297598 2026] [security2:error] [pid 352421:tid 352629] [client 107.161.92.6:37200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "britotavares.com"] [uri "/web.config"] [unique_id "al9RR8JSWzG9jbYOtu41hQAAANM"]
[Tue Jul 21 08:00:23.297804 2026] [security2:error] [pid 352421:tid 352629] [client 107.161.92.6:37200] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "britotavares.com"] [uri "/web.config"] [unique_id "al9RR8JSWzG9jbYOtu41hQAAANM"]
[Tue Jul 21 08:00:23.360707 2026] [security2:error] [pid 352421:tid 352620] [client 65.21.113.253:46740] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RRsJSWzG9jbYOtu41dgAAAMo"]
[Tue Jul 21 08:00:23.514887 2026] [security2:error] [pid 352421:tid 352468] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RR8JSWzG9jbYOtu41jgAAly4"]
[Tue Jul 21 08:00:23.515106 2026] [security2:error] [pid 352421:tid 352569] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RR8JSWzG9jbYOtu41jgAAly4"]
[Tue Jul 21 08:00:23.677024 2026] [security2:error] [pid 352421:tid 352661] [client 52.192.8.67:58260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "larissafurlaneto.online"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9RR8JSWzG9jbYOtu41kwAAAPM"]
[Tue Jul 21 08:00:23.803796 2026] [security2:error] [pid 358661:tid 358892] [client 4.204.201.85:61630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/config.json.php"] [unique_id "al9RRwlWhjQfpOo60_HCUQAAAGI"]
[Tue Jul 21 08:00:23.921600 2026] [security2:error] [pid 358661:tid 358900] [client 107.161.92.6:37190] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "britotavares.com"] [uri "/webpack-stats.json"] [unique_id "al9RRwlWhjQfpOo60_HCVwAAAGo"]
[Tue Jul 21 08:00:24.025701 2026] [security2:error] [pid 358661:tid 358885] [client 104.207.47.40:27405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.47.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RRwlWhjQfpOo60_HCVQAAAFs"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:00:24.157908 2026] [security2:error] [pid 352421:tid 352560] [client 103.166.103.129:6885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RSMJSWzG9jbYOtu41nQAAAI4"]
[Tue Jul 21 08:00:24.158246 2026] [security2:error] [pid 352421:tid 352560] [client 103.166.103.129:6885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RSMJSWzG9jbYOtu41nQAAAI4"]
[Tue Jul 21 08:00:24.170264 2026] [security2:error] [pid 358661:tid 358917] [client 20.104.96.117:46667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/root.php"] [unique_id "al9RSAlWhjQfpOo60_HCXgAAAHs"]
[Tue Jul 21 08:00:24.198786 2026] [security2:error] [pid 358661:tid 358796] [client 74.249.245.134:17431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/readme.php"] [unique_id "al9RSAlWhjQfpOo60_HCYgAAAAI"]
[Tue Jul 21 08:00:24.209387 2026] [security2:error] [pid 358661:tid 358866] [client 47.128.26.121:25786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gtlocacoes.net"] [uri "/robots.txt"] [unique_id "al9RSAlWhjQfpOo60_HCYwAAAEg"]
[Tue Jul 21 08:00:24.458594 2026] [security2:error] [pid 352421:tid 352596] [client 195.200.28.67:64387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.28.200.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9RR8JSWzG9jbYOtu41jAAAALI"], referer: https://sscoenper.com.br/
[Tue Jul 21 08:00:24.492604 2026] [security2:error] [pid 358661:tid 358805] [client 4.204.201.85:9570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9RSAlWhjQfpOo60_HCaAAAAAs"]
[Tue Jul 21 08:00:24.618282 2026] [security2:error] [pid 352421:tid 352566] [client 122.164.127.47:49321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RSMJSWzG9jbYOtu41rAAAAJQ"]
[Tue Jul 21 08:00:24.618454 2026] [security2:error] [pid 352421:tid 352566] [client 122.164.127.47:49321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RSMJSWzG9jbYOtu41rAAAAJQ"]
[Tue Jul 21 08:00:24.664401 2026] [security2:error] [pid 352421:tid 352629] [client 107.161.92.6:37172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.92.161.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "britotavares.com"] [uri "/phpinfo.php"] [unique_id "al9RSMJSWzG9jbYOtu41qgAAANM"]
[Tue Jul 21 08:00:24.759952 2026] [security2:error] [pid 352421:tid 352659] [client 107.161.92.6:37186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.92.161.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "britotavares.com"] [uri "/info.php"] [unique_id "al9RSMJSWzG9jbYOtu41rgAAAPE"]
[Tue Jul 21 08:00:24.910336 2026] [security2:error] [pid 352421:tid 352570] [client 136.144.33.110:46485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RSMJSWzG9jbYOtu41sgAAAJg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:00:25.052180 2026] [security2:error] [pid 358661:tid 358826] [client 35.205.50.49:62665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RSAlWhjQfpOo60_HCdQAAACA"]
[Tue Jul 21 08:00:25.162570 2026] [core:error] [pid 352421:tid 352500] [remote 74.7.175.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:00:25.162596 2026] [core:error] [pid 352421:tid 352500] [remote 74.7.175.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:00:25.162775 2026] [security2:error] [pid 352421:tid 352612] [client 74.7.175.184:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "webmail.naldoinvest.com.br"] [uri "/___proxy_subdomain_webmail/index.php"] [unique_id "al9RScJSWzG9jbYOtu41ugAAwk4"]
[Tue Jul 21 08:00:25.380829 2026] [security2:error] [pid 352421:tid 352661] [client 107.161.92.6:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.92.161.107.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "britotavares.com"] [uri "/test.php"] [unique_id "al9RScJSWzG9jbYOtu41vgAAAPM"]
[Tue Jul 21 08:00:25.402973 2026] [security2:error] [pid 352421:tid 352580] [client 4.204.201.85:61580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/k2.php"] [unique_id "al9RScJSWzG9jbYOtu41vwAAAKI"]
[Tue Jul 21 08:00:25.485592 2026] [security2:error] [pid 358661:tid 358858] [client 20.151.10.161:39863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/get.php"] [unique_id "al9RSQlWhjQfpOo60_HCgQAAAEA"]
[Tue Jul 21 08:00:25.640388 2026] [security2:error] [pid 358661:tid 358822] [client 104.207.50.216:61719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RSQlWhjQfpOo60_HCfwAAABw"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:00:25.653306 2026] [security2:error] [pid 358661:tid 358862] [client 82.102.18.188:35054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ekon.eng.br"] [uri "/xmlrpc.php"] [unique_id "al9RSQlWhjQfpOo60_HChwAAAEQ"]
[Tue Jul 21 08:00:25.653442 2026] [security2:error] [pid 358661:tid 358862] [client 82.102.18.188:35054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ekon.eng.br"] [uri "/xmlrpc.php"] [unique_id "al9RSQlWhjQfpOo60_HChwAAAEQ"]
[Tue Jul 21 08:00:25.874200 2026] [security2:error] [pid 358661:tid 358874] [client 20.226.60.151:65471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/file61.php"] [unique_id "al9RSQlWhjQfpOo60_HCjAAAAFA"]
[Tue Jul 21 08:00:25.904607 2026] [security2:error] [pid 358661:tid 358689] [remote 103.187.169.251:57686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9RSQlWhjQfpOo60_HCjQAAMxg"]
[Tue Jul 21 08:00:25.983185 2026] [security2:error] [pid 358661:tid 358846] [client 35.205.50.49:64653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RSQlWhjQfpOo60_HCiwAAADQ"]
[Tue Jul 21 08:00:26.199767 2026] [security2:error] [pid 358661:tid 358851] [client 65.21.113.253:46752] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RSQlWhjQfpOo60_HCigAAADk"]
[Tue Jul 21 08:00:26.323325 2026] [security2:error] [pid 352421:tid 352668] [client 173.252.95.17:55032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9RSsJSWzG9jbYOtu414gAAAPo"]
[Tue Jul 21 08:00:26.415141 2026] [security2:error] [pid 352421:tid 352661] [client 4.204.201.85:9561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9RSsJSWzG9jbYOtu415gAAAPM"]
[Tue Jul 21 08:00:26.562942 2026] [security2:error] [pid 352421:tid 352454] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RSsJSWzG9jbYOtu416wAA3SA"]
[Tue Jul 21 08:00:26.563082 2026] [security2:error] [pid 352421:tid 352639] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RSsJSWzG9jbYOtu416wAA3SA"]
[Tue Jul 21 08:00:26.587172 2026] [security2:error] [pid 352421:tid 352614] [client 173.252.95.13:33720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9RSsJSWzG9jbYOtu417QAAAMQ"]
[Tue Jul 21 08:00:26.728085 2026] [security2:error] [pid 352421:tid 352552] [client 117.210.135.0:64077] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RSsJSWzG9jbYOtu419QAAAIY"]
[Tue Jul 21 08:00:26.728242 2026] [security2:error] [pid 352421:tid 352552] [client 117.210.135.0:64077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RSsJSWzG9jbYOtu419QAAAIY"]
[Tue Jul 21 08:00:26.796928 2026] [autoindex:error] [pid 358661:tid 358919] [client 91.92.47.173:0] AH01276: Cannot serve directory /home3/agroci73/agrocibus.com/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:00:26.834070 2026] [security2:error] [pid 352421:tid 352564] [client 182.8.255.181:17191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RSsJSWzG9jbYOtu41-AAAAJI"]
[Tue Jul 21 08:00:26.834228 2026] [security2:error] [pid 352421:tid 352564] [client 182.8.255.181:17191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RSsJSWzG9jbYOtu41-AAAAJI"]
[Tue Jul 21 08:00:26.866611 2026] [security2:error] [pid 358661:tid 358905] [client 178.153.91.96:56910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RSglWhjQfpOo60_HCpQAAAG8"]
[Tue Jul 21 08:00:26.866732 2026] [security2:error] [pid 358661:tid 358905] [client 178.153.91.96:56910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RSglWhjQfpOo60_HCpQAAAG8"]
[Tue Jul 21 08:00:26.916864 2026] [security2:error] [pid 352421:tid 352645] [client 35.205.50.49:65162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RSsJSWzG9jbYOtu419gAAAOM"]
[Tue Jul 21 08:00:27.152235 2026] [security2:error] [pid 352421:tid 352570] [client 173.252.95.112:50384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9RS8JSWzG9jbYOtu42BgAAAJg"]
[Tue Jul 21 08:00:27.185790 2026] [security2:error] [pid 352421:tid 352580] [client 65.21.113.253:56886] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RS8JSWzG9jbYOtu42DAAAAKI"]
[Tue Jul 21 08:00:27.227032 2026] [security2:error] [pid 358661:tid 358828] [client 4.204.201.85:9608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9RSwlWhjQfpOo60_HCrQAAACI"]
[Tue Jul 21 08:00:27.354924 2026] [security2:error] [pid 352421:tid 352491] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RS8JSWzG9jbYOtu42DwAAp0U"]
[Tue Jul 21 08:00:27.355247 2026] [security2:error] [pid 352421:tid 352491] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RS8JSWzG9jbYOtu42DwAAp0U"]
[Tue Jul 21 08:00:27.365219 2026] [security2:error] [pid 352421:tid 352654] [client 74.249.245.134:62875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/403.php"] [unique_id "al9RS8JSWzG9jbYOtu42EAAAAOw"]
[Tue Jul 21 08:00:27.448014 2026] [security2:error] [pid 352421:tid 352560] [client 107.161.92.6:52642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "britotavares.com"] [uri "/key.json"] [unique_id "al9RS8JSWzG9jbYOtu42EwAAAI4"]
[Tue Jul 21 08:00:27.448207 2026] [security2:error] [pid 352421:tid 352560] [client 107.161.92.6:52642] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "britotavares.com"] [uri "/key.json"] [unique_id "al9RS8JSWzG9jbYOtu42EwAAAI4"]
[Tue Jul 21 08:00:27.770581 2026] [security2:error] [pid 358661:tid 358827] [client 41.68.90.219:54968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RSwlWhjQfpOo60_HCuQAAACE"]
[Tue Jul 21 08:00:27.771859 2026] [security2:error] [pid 358661:tid 358827] [client 41.68.90.219:54968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RSwlWhjQfpOo60_HCuQAAACE"]
[Tue Jul 21 08:00:27.775468 2026] [security2:error] [pid 352421:tid 352644] [client 38.100.221.102:17198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RS8JSWzG9jbYOtu42HwAAAOI"]
[Tue Jul 21 08:00:27.775606 2026] [security2:error] [pid 352421:tid 352644] [client 38.100.221.102:17198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RS8JSWzG9jbYOtu42HwAAAOI"]
[Tue Jul 21 08:00:27.823083 2026] [security2:error] [pid 358661:tid 358841] [client 65.21.113.253:46752] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RSwlWhjQfpOo60_HCsgAAAC8"]
[Tue Jul 21 08:00:27.842397 2026] [security2:error] [pid 358661:tid 358826] [client 35.205.50.49:49187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RSwlWhjQfpOo60_HCtgAAACA"]
[Tue Jul 21 08:00:28.076874 2026] [cgid:error] [pid 352421:tid 352591] [client 91.92.47.173:0] AH01264: stderr from /home3/agroci73/agrocibus.com/cgi-bin: script not found or unable to stat
[Tue Jul 21 08:00:28.108694 2026] [security2:error] [pid 358661:tid 358702] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RTAlWhjQfpOo60_HCvAAAQCU"]
[Tue Jul 21 08:00:28.108871 2026] [security2:error] [pid 358661:tid 358858] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RTAlWhjQfpOo60_HCvAAAQCU"]
[Tue Jul 21 08:00:28.187458 2026] [security2:error] [pid 358661:tid 358840] [client 4.204.201.85:63261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9RTAlWhjQfpOo60_HCvgAAAC4"]
[Tue Jul 21 08:00:28.204667 2026] [security2:error] [pid 352421:tid 352498] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTMJSWzG9jbYOtu42KQAAtEw"]
[Tue Jul 21 08:00:28.204849 2026] [security2:error] [pid 352421:tid 352598] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTMJSWzG9jbYOtu42KQAAtEw"]
[Tue Jul 21 08:00:28.319782 2026] [security2:error] [pid 352421:tid 352626] [client 217.181.91.159:46241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.91.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RS8JSWzG9jbYOtu42BwAAANA"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:00:28.385751 2026] [security2:error] [pid 358661:tid 358878] [client 74.249.245.134:54398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/max.php"] [unique_id "al9RTAlWhjQfpOo60_HCxAAAAFQ"]
[Tue Jul 21 08:00:28.522906 2026] [security2:error] [pid 352421:tid 352653] [client 20.151.10.161:39888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/images.php"] [unique_id "al9RTMJSWzG9jbYOtu42LgAAAOs"]
[Tue Jul 21 08:00:28.542523 2026] [security2:error] [pid 358661:tid 358879] [client 20.104.96.117:46619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/sym403.php"] [unique_id "al9RTAlWhjQfpOo60_HCxgAAAFU"]
[Tue Jul 21 08:00:28.582146 2026] [security2:error] [pid 358661:tid 358806] [client 20.226.60.151:59936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/water.php"] [unique_id "al9RTAlWhjQfpOo60_HCxwAAAAw"]
[Tue Jul 21 08:00:28.782605 2026] [security2:error] [pid 352421:tid 352607] [client 35.205.50.49:49743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTMJSWzG9jbYOtu42NAAAAL0"]
[Tue Jul 21 08:00:28.812334 2026] [security2:error] [pid 358661:tid 358906] [client 4.204.201.85:9588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/for.php"] [unique_id "al9RTAlWhjQfpOo60_HCzwAAAHA"]
[Tue Jul 21 08:00:28.830212 2026] [security2:error] [pid 358661:tid 358705] [remote 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RTAlWhjQfpOo60_HC0QAAVyg"]
[Tue Jul 21 08:00:28.830432 2026] [security2:error] [pid 358661:tid 358881] [client 2001:4490:4ec1:ec62:e0f1:3df8:7f6f:d6c8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "getveltrixhealth.com"] [uri "/xmlrpc.php"] [unique_id "al9RTAlWhjQfpOo60_HC0QAAVyg"]
[Tue Jul 21 08:00:28.893060 2026] [security2:error] [pid 358661:tid 358706] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RTAlWhjQfpOo60_HC0gAAcyk"]
[Tue Jul 21 08:00:28.893218 2026] [security2:error] [pid 358661:tid 358909] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RTAlWhjQfpOo60_HC0gAAcyk"]
[Tue Jul 21 08:00:29.035711 2026] [security2:error] [pid 352421:tid 352668] [client 202.143.127.214:63812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTcJSWzG9jbYOtu42PwAAAPo"]
[Tue Jul 21 08:00:29.036273 2026] [security2:error] [pid 352421:tid 352668] [client 202.143.127.214:63812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTcJSWzG9jbYOtu42PwAAAPo"]
[Tue Jul 21 08:00:29.242633 2026] [security2:error] [pid 352421:tid 352566] [client 20.151.10.161:39915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/alls.php"] [unique_id "al9RTcJSWzG9jbYOtu42RgAAAJQ"]
[Tue Jul 21 08:00:29.287172 2026] [security2:error] [pid 352421:tid 352646] [client 74.249.245.134:5511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/m.php"] [unique_id "al9RTcJSWzG9jbYOtu42SgAAAOQ"]
[Tue Jul 21 08:00:29.441607 2026] [security2:error] [pid 358661:tid 358900] [client 59.93.4.33:54992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTQlWhjQfpOo60_HC2gAAAGo"]
[Tue Jul 21 08:00:29.441767 2026] [security2:error] [pid 358661:tid 358900] [client 59.93.4.33:54992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTQlWhjQfpOo60_HC2gAAAGo"]
[Tue Jul 21 08:00:29.738356 2026] [security2:error] [pid 352421:tid 352644] [client 35.205.50.49:50644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTcJSWzG9jbYOtu42UwAAAOI"]
[Tue Jul 21 08:00:29.786389 2026] [security2:error] [pid 358661:tid 358802] [client 4.204.201.85:61575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/raw.php"] [unique_id "al9RTQlWhjQfpOo60_HC3wAAAAg"]
[Tue Jul 21 08:00:29.814163 2026] [security2:error] [pid 352421:tid 352649] [client 20.151.10.161:39927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/yyu.php"] [unique_id "al9RTcJSWzG9jbYOtu42WwAAAOc"]
[Tue Jul 21 08:00:29.855430 2026] [security2:error] [pid 358661:tid 358819] [client 20.226.60.151:59984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/nano.php"] [unique_id "al9RTQlWhjQfpOo60_HC4QAAABk"]
[Tue Jul 21 08:00:29.996809 2026] [security2:error] [pid 358661:tid 358830] [client 136.144.33.215:39241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RTAlWhjQfpOo60_HC0AAAACQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:00:30.203196 2026] [security2:error] [pid 352421:tid 352624] [client 223.236.153.128:3748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RTsJSWzG9jbYOtu42YgAAAM4"]
[Tue Jul 21 08:00:30.207856 2026] [security2:error] [pid 352421:tid 352624] [client 223.236.153.128:3748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RTsJSWzG9jbYOtu42YgAAAM4"]
[Tue Jul 21 08:00:30.217467 2026] [security2:error] [pid 352421:tid 352617] [client 65.21.113.253:47864] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RTcJSWzG9jbYOtu42WQAAAMc"]
[Tue Jul 21 08:00:30.232611 2026] [core:alert] [pid 358661:tid 358836] [client 69.63.189.37:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:00:30.244148 2026] [security2:error] [pid 352421:tid 352635] [client 74.249.245.134:5505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/click.php"] [unique_id "al9RTsJSWzG9jbYOtu42aQAAANk"]
[Tue Jul 21 08:00:30.279285 2026] [security2:error] [pid 358661:tid 358710] [remote 151.123.177.234:42949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9RTglWhjQfpOo60_HC5gAAFC0"]
[Tue Jul 21 08:00:30.346170 2026] [security2:error] [pid 352421:tid 352582] [client 65.21.113.253:56886] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RTsJSWzG9jbYOtu42bAAAAKQ"]
[Tue Jul 21 08:00:30.587406 2026] [security2:error] [pid 358661:tid 358838] [client 184.75.221.3:40560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9RTglWhjQfpOo60_HC7AAAACw"]
[Tue Jul 21 08:00:30.587499 2026] [security2:error] [pid 358661:tid 358838] [client 184.75.221.3:40560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9RTglWhjQfpOo60_HC7AAAACw"]
[Tue Jul 21 08:00:30.662935 2026] [security2:error] [pid 358661:tid 358856] [client 20.151.10.161:39828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/by.php"] [unique_id "al9RTglWhjQfpOo60_HC7wAAAD4"]
[Tue Jul 21 08:00:30.711687 2026] [security2:error] [pid 358661:tid 358812] [client 35.205.50.49:51599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTglWhjQfpOo60_HC6wAAABI"]
[Tue Jul 21 08:00:30.870480 2026] [security2:error] [pid 358661:tid 358873] [client 20.226.60.151:65434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/moon.php"] [unique_id "al9RTglWhjQfpOo60_HC9AAAAE8"]
[Tue Jul 21 08:00:30.870556 2026] [security2:error] [pid 358661:tid 358833] [client 117.247.80.59:14891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTglWhjQfpOo60_HC9QAAACc"]
[Tue Jul 21 08:00:30.870681 2026] [security2:error] [pid 358661:tid 358833] [client 117.247.80.59:14891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTglWhjQfpOo60_HC9QAAACc"]
[Tue Jul 21 08:00:30.913389 2026] [security2:error] [pid 358661:tid 358826] [client 86.38.98.84:52526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.98.38.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojadoclimatizador.com.br"] [uri "/wp-login.php/wp-login.php"] [unique_id "al9RTglWhjQfpOo60_HC9gAAACA"]
[Tue Jul 21 08:00:31.165542 2026] [core:alert] [pid 358661:tid 358893] [client 173.252.70.44:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:00:31.478325 2026] [security2:error] [pid 358661:tid 358858] [client 65.21.113.253:47872] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RTwlWhjQfpOo60_HC-wAAAEA"]
[Tue Jul 21 08:00:31.621507 2026] [security2:error] [pid 358661:tid 358880] [client 109.60.28.94:52721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTwlWhjQfpOo60_HDCQAAAFY"]
[Tue Jul 21 08:00:31.622403 2026] [security2:error] [pid 358661:tid 358880] [client 109.60.28.94:52721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTwlWhjQfpOo60_HDCQAAAFY"]
[Tue Jul 21 08:00:31.636323 2026] [security2:error] [pid 358661:tid 358906] [client 86.38.98.84:52528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.98.38.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojadoclimatizador.com.br"] [uri "/wp-login.php"] [unique_id "al9RTwlWhjQfpOo60_HDCgAAAHA"]
[Tue Jul 21 08:00:31.639429 2026] [security2:error] [pid 358661:tid 358846] [client 35.205.50.49:52285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTwlWhjQfpOo60_HDBgAAADQ"]
[Tue Jul 21 08:00:31.753484 2026] [security2:error] [pid 358661:tid 358919] [client 20.151.10.161:39844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/FAQ.php"] [unique_id "al9RTwlWhjQfpOo60_HDDQAAAH0"]
[Tue Jul 21 08:00:31.819677 2026] [security2:error] [pid 352421:tid 352563] [client 198.54.128.138:54156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9RT8JSWzG9jbYOtu42gwAAAJE"]
[Tue Jul 21 08:00:31.819772 2026] [security2:error] [pid 352421:tid 352563] [client 198.54.128.138:54156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9RT8JSWzG9jbYOtu42gwAAAJE"]
[Tue Jul 21 08:00:31.869929 2026] [security2:error] [pid 352421:tid 352579] [client 104.207.58.25:32423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RTsJSWzG9jbYOtu42dAAAAKE"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:00:31.893054 2026] [security2:error] [pid 358661:tid 358894] [client 87.116.180.198:27300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTwlWhjQfpOo60_HDDgAAAGQ"]
[Tue Jul 21 08:00:31.893164 2026] [security2:error] [pid 358661:tid 358894] [client 87.116.180.198:27300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RTwlWhjQfpOo60_HDDgAAAGQ"]
[Tue Jul 21 08:00:32.118141 2026] [security2:error] [pid 358661:tid 358904] [client 106.215.181.8:2227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RUAlWhjQfpOo60_HDEwAAAG4"]
[Tue Jul 21 08:00:32.118245 2026] [security2:error] [pid 358661:tid 358904] [client 106.215.181.8:2227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RUAlWhjQfpOo60_HDEwAAAG4"]
[Tue Jul 21 08:00:32.124735 2026] [security2:error] [pid 352421:tid 352450] [remote 57.141.18.102:57042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "camilajung.com.br"] [uri "/wp-content/plugins/litespeed-cache/guest.vary.php"] [unique_id "al9RUMJSWzG9jbYOtu42iQAAhxw"], referer: https://camilajung.com.br/ferramenta/
[Tue Jul 21 08:00:32.178744 2026] [security2:error] [pid 352421:tid 352573] [client 74.249.245.134:17455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/lv.php"] [unique_id "al9RUMJSWzG9jbYOtu42igAAAJs"]
[Tue Jul 21 08:00:32.298542 2026] [security2:error] [pid 358661:tid 358917] [client 103.78.200.11:64143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RUAlWhjQfpOo60_HDFQAAAHs"]
[Tue Jul 21 08:00:32.298829 2026] [security2:error] [pid 358661:tid 358917] [client 103.78.200.11:64143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RUAlWhjQfpOo60_HDFQAAAHs"]
[Tue Jul 21 08:00:32.419168 2026] [security2:error] [pid 358661:tid 358854] [client 175.144.82.48:55554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RUAlWhjQfpOo60_HDHgAAADw"]
[Tue Jul 21 08:00:32.420401 2026] [security2:error] [pid 358661:tid 358854] [client 175.144.82.48:55554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RUAlWhjQfpOo60_HDHgAAADw"]
[Tue Jul 21 08:00:32.521452 2026] [proxy:error] [pid 358661:tid 358852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:00:32.521504 2026] [proxy_http:error] [pid 358661:tid 358852] [client 164.92.69.127:39126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:00:32.522341 2026] [proxy:error] [pid 358661:tid 358852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:00:32.522369 2026] [proxy_http:error] [pid 358661:tid 358852] [client 164.92.69.127:39126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:00:32.568534 2026] [security2:error] [pid 358661:tid 358888] [client 35.205.50.49:52763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RUAlWhjQfpOo60_HDHwAAAF4"]
[Tue Jul 21 08:00:32.730073 2026] [core:alert] [pid 358661:tid 358873] [client 173.252.107.31:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:00:32.784871 2026] [security2:error] [pid 352421:tid 352619] [client 20.151.10.161:39756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/coffexium.php"] [unique_id "al9RUMJSWzG9jbYOtu42mQAAAMk"]
[Tue Jul 21 08:00:32.886726 2026] [proxy:error] [pid 358661:tid 358864] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:00:32.886833 2026] [proxy_http:error] [pid 358661:tid 358864] [client 164.92.69.127:39142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.grupotecc.com.br/
[Tue Jul 21 08:00:32.887747 2026] [proxy:error] [pid 358661:tid 358864] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:00:32.887806 2026] [proxy_http:error] [pid 358661:tid 358864] [client 164.92.69.127:39142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.grupotecc.com.br/
[Tue Jul 21 08:00:33.055250 2026] [security2:error] [pid 352421:tid 352614] [client 65.21.113.253:56886] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RUcJSWzG9jbYOtu42ngAAAMQ"]
[Tue Jul 21 08:00:33.425613 2026] [security2:error] [pid 358661:tid 358893] [client 65.111.22.141:32645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RUQlWhjQfpOo60_HDNQAAAGM"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:00:33.433201 2026] [security2:error] [pid 358661:tid 358868] [client 103.86.117.203:61589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RUQlWhjQfpOo60_HDNgAAAEo"]
[Tue Jul 21 08:00:33.433319 2026] [security2:error] [pid 358661:tid 358868] [client 103.86.117.203:61589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RUQlWhjQfpOo60_HDNgAAAEo"]
[Tue Jul 21 08:00:33.458880 2026] [security2:error] [pid 352421:tid 352649] [client 103.29.114.44:65272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RUcJSWzG9jbYOtu42pwAAAOc"]
[Tue Jul 21 08:00:33.459002 2026] [security2:error] [pid 352421:tid 352649] [client 103.29.114.44:65272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RUcJSWzG9jbYOtu42pwAAAOc"]
[Tue Jul 21 08:00:33.490382 2026] [security2:error] [pid 358661:tid 358836] [client 136.144.33.105:20921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RUQlWhjQfpOo60_HDOAAAACo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:00:33.516160 2026] [security2:error] [pid 358661:tid 358886] [client 35.205.50.49:53363] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RUQlWhjQfpOo60_HDMAAAAFw"]
[Tue Jul 21 08:00:33.516194 2026] [security2:error] [pid 358661:tid 358886] [client 35.205.50.49:53363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RUQlWhjQfpOo60_HDMAAAAFw"]
[Tue Jul 21 08:00:33.543492 2026] [security2:error] [pid 358661:tid 358879] [client 102.206.115.33:65263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RUQlWhjQfpOo60_HDOgAAAFU"]
[Tue Jul 21 08:00:33.543640 2026] [security2:error] [pid 358661:tid 358879] [client 102.206.115.33:65263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RUQlWhjQfpOo60_HDOgAAAFU"]
[Tue Jul 21 08:00:33.636629 2026] [proxy:error] [pid 358661:tid 358895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:00:33.636699 2026] [proxy_http:error] [pid 358661:tid 358895] [client 164.92.69.127:33248] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:00:33.638297 2026] [proxy:error] [pid 358661:tid 358895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:00:33.638364 2026] [proxy_http:error] [pid 358661:tid 358895] [client 164.92.69.127:33248] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:00:33.745304 2026] [security2:error] [pid 352421:tid 352615] [client 65.21.113.253:47864] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RUcJSWzG9jbYOtu42pAAAAMU"]
[Tue Jul 21 08:00:33.850034 2026] [security2:error] [pid 358661:tid 358753] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RUQlWhjQfpOo60_HDSwAATVg"]
[Tue Jul 21 08:00:33.850193 2026] [security2:error] [pid 358661:tid 358871] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RUQlWhjQfpOo60_HDSwAATVg"]
[Tue Jul 21 08:00:33.880656 2026] [security2:error] [pid 358661:tid 358821] [client 74.249.245.134:5555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/cong.php"] [unique_id "al9RUQlWhjQfpOo60_HDTAAAABs"]
[Tue Jul 21 08:00:34.080629 2026] [security2:error] [pid 352421:tid 352594] [client 86.38.98.84:52538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.98.38.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojadoclimatizador.com.br"] [uri "/wp-login.php"] [unique_id "al9RUsJSWzG9jbYOtu42tQAAALA"]
[Tue Jul 21 08:00:34.269034 2026] [security2:error] [pid 352421:tid 352514] [remote 104.207.57.228:27135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9RUcJSWzG9jbYOtu42owAA4lw"]
[Tue Jul 21 08:00:34.432498 2026] [security2:error] [pid 352421:tid 352609] [client 20.226.60.151:59919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-info.php"] [unique_id "al9RUsJSWzG9jbYOtu42vgAAAL8"]
[Tue Jul 21 08:00:34.455775 2026] [security2:error] [pid 358661:tid 358756] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RUglWhjQfpOo60_HDVgAAOFs"]
[Tue Jul 21 08:00:34.455955 2026] [security2:error] [pid 358661:tid 358850] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RUglWhjQfpOo60_HDVgAAOFs"]
[Tue Jul 21 08:00:34.490750 2026] [security2:error] [pid 358661:tid 358898] [client 35.205.50.49:54164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RUglWhjQfpOo60_HDVAAAAGg"]
[Tue Jul 21 08:00:34.665387 2026] [autoindex:error] [pid 358661:tid 358823] [client 143.244.57.121:0] AH01276: Cannot serve directory /home1/sofiag86/sofiagheller1782846626000.0721679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:00:34.814604 2026] [security2:error] [pid 358661:tid 358897] [client 20.151.10.161:39886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/red.php"] [unique_id "al9RUglWhjQfpOo60_HDXQAAAGc"]
[Tue Jul 21 08:00:34.822042 2026] [security2:error] [pid 358661:tid 358814] [client 65.21.113.253:47882] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RUglWhjQfpOo60_HDVQAAABQ"]
[Tue Jul 21 08:00:34.840264 2026] [autoindex:error] [pid 358661:tid 358845] [client 143.244.57.121:0] AH01276: Cannot serve directory /home1/sofiag86/sofiagheller1782846626000.0721679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:00:34.935069 2026] [security2:error] [pid 352421:tid 352659] [client 103.166.103.129:7565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RUsJSWzG9jbYOtu42yAAAAPE"]
[Tue Jul 21 08:00:34.935197 2026] [security2:error] [pid 352421:tid 352659] [client 103.166.103.129:7565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RUsJSWzG9jbYOtu42yAAAAPE"]
[Tue Jul 21 08:00:34.994856 2026] [security2:error] [pid 352421:tid 352551] [client 198.54.128.138:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9RUsJSWzG9jbYOtu42yQAAAIU"]
[Tue Jul 21 08:00:34.994936 2026] [security2:error] [pid 352421:tid 352551] [client 198.54.128.138:54158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9RUsJSWzG9jbYOtu42yQAAAIU"]
[Tue Jul 21 08:00:34.998804 2026] [security2:error] [pid 358661:tid 358874] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9RUglWhjQfpOo60_HDYAAAAFA"]
[Tue Jul 21 08:00:35.059376 2026] [security2:error] [pid 352421:tid 352572] [client 20.104.96.117:27093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/v543.php"] [unique_id "al9RU8JSWzG9jbYOtu42zQAAAJo"]
[Tue Jul 21 08:00:35.113915 2026] [security2:error] [pid 358661:tid 358860] [client 122.164.127.47:49908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RUwlWhjQfpOo60_HDZQAAAEI"]
[Tue Jul 21 08:00:35.114018 2026] [security2:error] [pid 358661:tid 358860] [client 122.164.127.47:49908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RUwlWhjQfpOo60_HDZQAAAEI"]
[Tue Jul 21 08:00:35.286267 2026] [security2:error] [pid 352421:tid 352564] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RU8JSWzG9jbYOtu420QAAAJI"]
[Tue Jul 21 08:00:35.286431 2026] [security2:error] [pid 352421:tid 352614] [client 35.205.50.49:54829] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RU8JSWzG9jbYOtu420AAAAMQ"]
[Tue Jul 21 08:00:35.286567 2026] [security2:error] [pid 352421:tid 352614] [client 35.205.50.49:54829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RU8JSWzG9jbYOtu420AAAAMQ"]
[Tue Jul 21 08:00:35.342310 2026] [security2:error] [pid 352421:tid 352628] [client 65.21.113.253:56886] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RU8JSWzG9jbYOtu421AAAANI"]
[Tue Jul 21 08:00:35.449455 2026] [security2:error] [pid 358661:tid 358906] [client 92.119.178.3:47920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9RUwlWhjQfpOo60_HDawAAAHA"]
[Tue Jul 21 08:00:35.449546 2026] [security2:error] [pid 358661:tid 358906] [client 92.119.178.3:47920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9RUwlWhjQfpOo60_HDawAAAHA"]
[Tue Jul 21 08:00:35.476871 2026] [security2:error] [pid 352421:tid 352580] [client 45.3.46.219:11921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.46.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RUsJSWzG9jbYOtu42vwAAAKI"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:00:35.484845 2026] [security2:error] [pid 352421:tid 352635] [client 35.205.50.49:54829] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RU8JSWzG9jbYOtu422AAAANk"]
[Tue Jul 21 08:00:35.484991 2026] [security2:error] [pid 352421:tid 352635] [client 35.205.50.49:54829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RU8JSWzG9jbYOtu422AAAANk"]
[Tue Jul 21 08:00:35.577654 2026] [autoindex:error] [pid 358661:tid 358900] [client 143.244.57.121:0] AH01276: Cannot serve directory /home1/sofiag86/sofiagheller1782846626000.0721679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:00:35.683395 2026] [security2:error] [pid 352421:tid 352620] [client 35.205.50.49:54829] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RU8JSWzG9jbYOtu423QAAAMo"]
[Tue Jul 21 08:00:35.683565 2026] [security2:error] [pid 352421:tid 352620] [client 35.205.50.49:54829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "woma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RU8JSWzG9jbYOtu423QAAAMo"]
[Tue Jul 21 08:00:35.720465 2026] [security2:error] [pid 358661:tid 358795] [client 74.249.245.134:54396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/brand.php"] [unique_id "al9RUwlWhjQfpOo60_HDcgAAAAE"]
[Tue Jul 21 08:00:35.736952 2026] [security2:error] [pid 358661:tid 358807] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9RUwlWhjQfpOo60_HDcwAAAA0"]
[Tue Jul 21 08:00:35.984873 2026] [security2:error] [pid 358661:tid 358765] [remote 65.111.15.73:11755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9RUwlWhjQfpOo60_HDeQAAC2Q"]
[Tue Jul 21 08:00:35.995557 2026] [security2:error] [pid 358661:tid 358905] [client 65.21.113.253:47882] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RUwlWhjQfpOo60_HDcAAAAG8"]
[Tue Jul 21 08:00:36.026187 2026] [security2:error] [pid 358661:tid 358854] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9RVAlWhjQfpOo60_HDewAAADw"]
[Tue Jul 21 08:00:36.114695 2026] [security2:error] [pid 358661:tid 358917] [client 78.46.190.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9RVAlWhjQfpOo60_HDfgAAe2Y"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:00:36.311589 2026] [security2:error] [pid 358661:tid 358832] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9RVAlWhjQfpOo60_HDfwAAACY"]
[Tue Jul 21 08:00:36.463448 2026] [security2:error] [pid 352421:tid 352590] [client 20.151.10.161:39877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9RVMJSWzG9jbYOtu427AAAAKw"]
[Tue Jul 21 08:00:36.598256 2026] [security2:error] [pid 352421:tid 352657] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9RVMJSWzG9jbYOtu427gAAAO8"]
[Tue Jul 21 08:00:36.664801 2026] [security2:error] [pid 352421:tid 352554] [client 78.46.190.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9RVMJSWzG9jbYOtu428QAAiBI"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:00:36.885108 2026] [security2:error] [pid 352421:tid 352579] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9RVMJSWzG9jbYOtu42-AAAAKE"]
[Tue Jul 21 08:00:37.105554 2026] [core:alert] [pid 352421:tid 352624] [client 69.63.184.7:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:00:37.170026 2026] [security2:error] [pid 352421:tid 352620] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9RVcJSWzG9jbYOtu43AwAAAMo"]
[Tue Jul 21 08:00:37.228253 2026] [security2:error] [pid 352421:tid 352524] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RVcJSWzG9jbYOtu43BQAA1mY"]
[Tue Jul 21 08:00:37.228430 2026] [security2:error] [pid 352421:tid 352632] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RVcJSWzG9jbYOtu43BQAA1mY"]
[Tue Jul 21 08:00:37.256197 2026] [security2:error] [pid 358661:tid 358826] [client 182.8.255.181:2914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RVQlWhjQfpOo60_HDlQAAACA"]
[Tue Jul 21 08:00:37.256369 2026] [security2:error] [pid 358661:tid 358826] [client 182.8.255.181:2914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RVQlWhjQfpOo60_HDlQAAACA"]
[Tue Jul 21 08:00:37.310391 2026] [security2:error] [pid 352421:tid 352574] [client 178.153.91.96:57530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RVcJSWzG9jbYOtu43BgAAAJw"]
[Tue Jul 21 08:00:37.310613 2026] [security2:error] [pid 352421:tid 352574] [client 178.153.91.96:57530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RVcJSWzG9jbYOtu43BgAAAJw"]
[Tue Jul 21 08:00:37.455339 2026] [security2:error] [pid 352421:tid 352642] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9RVcJSWzG9jbYOtu43DwAAAOA"]
[Tue Jul 21 08:00:37.741513 2026] [security2:error] [pid 358661:tid 358810] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9RVQlWhjQfpOo60_HDmgAAABA"]
[Tue Jul 21 08:00:37.793482 2026] [security2:error] [pid 352421:tid 352590] [client 198.54.128.138:54166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9RVcJSWzG9jbYOtu43FAAAAKw"]
[Tue Jul 21 08:00:37.793572 2026] [security2:error] [pid 352421:tid 352590] [client 198.54.128.138:54166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9RVcJSWzG9jbYOtu43FAAAAKw"]
[Tue Jul 21 08:00:37.828224 2026] [security2:error] [pid 358661:tid 358824] [client 74.249.245.134:5528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/atomlib.php"] [unique_id "al9RVQlWhjQfpOo60_HDmwAAAB4"]
[Tue Jul 21 08:00:37.834000 2026] [security2:error] [pid 358661:tid 358916] [client 103.219.58.100:17505] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/ice"] [unique_id "al9RVQlWhjQfpOo60_HDnAAAAHo"]
[Tue Jul 21 08:00:37.866239 2026] [security2:error] [pid 352421:tid 352601] [client 103.219.58.100:28676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/ice"] [unique_id "al9RVcJSWzG9jbYOtu43FgAAALc"]
[Tue Jul 21 08:00:37.977089 2026] [security2:error] [pid 358661:tid 358834] [client 172.245.102.42:54037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RVQlWhjQfpOo60_HDoQAAACg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:00:38.000299 2026] [security2:error] [pid 358661:tid 358782] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RVQlWhjQfpOo60_HDogAAAXU"]
[Tue Jul 21 08:00:38.000491 2026] [security2:error] [pid 358661:tid 358795] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RVQlWhjQfpOo60_HDogAAAXU"]
[Tue Jul 21 08:00:38.026668 2026] [security2:error] [pid 358661:tid 358843] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9RVglWhjQfpOo60_HDpAAAADE"]
[Tue Jul 21 08:00:38.227042 2026] [security2:error] [pid 352421:tid 352551] [client 185.213.175.37:13952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.archrender.com.br"] [uri "/"] [unique_id "al9RVsJSWzG9jbYOtu43HwAAAIU"]
[Tue Jul 21 08:00:38.227175 2026] [security2:error] [pid 352421:tid 352551] [client 185.213.175.37:13952] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.archrender.com.br"] [uri "/"] [unique_id "al9RVsJSWzG9jbYOtu43HwAAAIU"]
[Tue Jul 21 08:00:38.271952 2026] [security2:error] [pid 358661:tid 358866] [client 41.68.90.219:55433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RVglWhjQfpOo60_HDqgAAAEg"]
[Tue Jul 21 08:00:38.273037 2026] [security2:error] [pid 358661:tid 358866] [client 41.68.90.219:55433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RVglWhjQfpOo60_HDqgAAAEg"]
[Tue Jul 21 08:00:38.315034 2026] [proxy:error] [pid 358661:tid 358821] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:00:38.315140 2026] [proxy_http:error] [pid 358661:tid 358821] [client 164.92.69.127:33358] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.grupotecc.com.br/
[Tue Jul 21 08:00:38.316196 2026] [proxy:error] [pid 358661:tid 358821] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:00:38.316273 2026] [proxy_http:error] [pid 358661:tid 358821] [client 164.92.69.127:33358] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.grupotecc.com.br/
[Tue Jul 21 08:00:38.325077 2026] [security2:error] [pid 358661:tid 358841] [client 20.151.10.161:39878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/footer.php"] [unique_id "al9RVglWhjQfpOo60_HDrQAAAC8"]
[Tue Jul 21 08:00:38.329234 2026] [security2:error] [pid 352421:tid 352558] [client 20.226.60.151:59978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/2000.php"] [unique_id "al9RVsJSWzG9jbYOtu43IgAAAIw"]
[Tue Jul 21 08:00:38.376150 2026] [security2:error] [pid 352421:tid 352635] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9RVsJSWzG9jbYOtu43JAAAANk"]
[Tue Jul 21 08:00:38.399470 2026] [security2:error] [pid 358661:tid 358901] [client 38.100.221.102:17535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RVglWhjQfpOo60_HDrgAAAGs"]
[Tue Jul 21 08:00:38.399606 2026] [security2:error] [pid 358661:tid 358901] [client 38.100.221.102:17535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RVglWhjQfpOo60_HDrgAAAGs"]
[Tue Jul 21 08:00:38.527148 2026] [security2:error] [pid 352421:tid 352631] [client 103.219.58.100:29012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/iou"] [unique_id "al9RVsJSWzG9jbYOtu43KQAAANU"]
[Tue Jul 21 08:00:38.553683 2026] [security2:error] [pid 358661:tid 358876] [client 103.219.58.100:10226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/iou"] [unique_id "al9RVglWhjQfpOo60_HDtgAAAFI"]
[Tue Jul 21 08:00:38.650260 2026] [security2:error] [pid 352421:tid 352459] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RVsJSWzG9jbYOtu43LQAAnCU"]
[Tue Jul 21 08:00:38.650391 2026] [security2:error] [pid 352421:tid 352574] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RVsJSWzG9jbYOtu43LQAAnCU"]
[Tue Jul 21 08:00:38.664571 2026] [security2:error] [pid 352421:tid 352430] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RVsJSWzG9jbYOtu43LgAAmwg"]
[Tue Jul 21 08:00:38.664702 2026] [security2:error] [pid 352421:tid 352573] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RVsJSWzG9jbYOtu43LgAAmwg"]
[Tue Jul 21 08:00:38.668792 2026] [security2:error] [pid 358661:tid 358882] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9RVglWhjQfpOo60_HDuQAAAFg"]
[Tue Jul 21 08:00:38.936800 2026] [security2:error] [pid 358661:tid 358913] [client 74.249.245.134:5565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/0x.php"] [unique_id "al9RVglWhjQfpOo60_HDyQAAAHc"]
[Tue Jul 21 08:00:38.954255 2026] [security2:error] [pid 352421:tid 352630] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9RVsJSWzG9jbYOtu43MgAAANQ"]
[Tue Jul 21 08:00:39.035509 2026] [security2:error] [pid 358661:tid 358880] [client 20.104.96.117:27084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/sixxis.php"] [unique_id "al9RVwlWhjQfpOo60_HD1wAAAFY"]
[Tue Jul 21 08:00:39.119327 2026] [security2:error] [pid 358661:tid 358824] [client 103.219.58.100:21151] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/pal"] [unique_id "al9RVwlWhjQfpOo60_HD3gAAAB4"]
[Tue Jul 21 08:00:39.149466 2026] [security2:error] [pid 358661:tid 358816] [client 103.219.58.100:11685] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/pal"] [unique_id "al9RVwlWhjQfpOo60_HD4gAAABY"]
[Tue Jul 21 08:00:39.221699 2026] [security2:error] [pid 358661:tid 358849] [client 65.21.113.253:47896] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RVglWhjQfpOo60_HDwQAAADc"]
[Tue Jul 21 08:00:39.239483 2026] [security2:error] [pid 358661:tid 358920] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9RVwlWhjQfpOo60_HD7QAAAH4"]
[Tue Jul 21 08:00:39.451431 2026] [security2:error] [pid 352421:tid 352642] [client 168.119.96.239:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9RV8JSWzG9jbYOtu43PAAA4FM"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:00:39.482415 2026] [security2:error] [pid 358661:tid 358732] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RVwlWhjQfpOo60_HD8gAADUM"]
[Tue Jul 21 08:00:39.482575 2026] [security2:error] [pid 358661:tid 358807] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RVwlWhjQfpOo60_HD8gAADUM"]
[Tue Jul 21 08:00:39.527564 2026] [security2:error] [pid 358661:tid 358829] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9RVwlWhjQfpOo60_HD9AAAACM"]
[Tue Jul 21 08:00:39.666848 2026] [security2:error] [pid 352421:tid 352659] [client 117.210.135.0:64771] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RVcJSWzG9jbYOtu43BwAAAPE"]
[Tue Jul 21 08:00:39.666982 2026] [security2:error] [pid 352421:tid 352659] [client 117.210.135.0:64771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RVcJSWzG9jbYOtu43BwAAAPE"]
[Tue Jul 21 08:00:39.720451 2026] [security2:error] [pid 352421:tid 352577] [client 103.219.58.100:22662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/wal"] [unique_id "al9RV8JSWzG9jbYOtu43QgAAAJ8"]
[Tue Jul 21 08:00:39.737925 2026] [security2:error] [pid 358661:tid 358863] [client 103.219.58.100:25728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/wal"] [unique_id "al9RVwlWhjQfpOo60_HD9wAAAEU"]
[Tue Jul 21 08:00:39.813385 2026] [security2:error] [pid 358661:tid 358847] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9RVwlWhjQfpOo60_HD-wAAADU"]
[Tue Jul 21 08:00:40.002255 2026] [security2:error] [pid 358661:tid 358825] [client 168.119.96.239:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9RWAlWhjQfpOo60_HECAAAH0o"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:00:40.006550 2026] [security2:error] [pid 358661:tid 358917] [client 59.93.4.33:55515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.4.93.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RWAlWhjQfpOo60_HECQAAAHs"]
[Tue Jul 21 08:00:40.006642 2026] [security2:error] [pid 358661:tid 358917] [client 59.93.4.33:55515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RWAlWhjQfpOo60_HECQAAAHs"]
[Tue Jul 21 08:00:40.058957 2026] [core:alert] [pid 352421:tid 352588] [client 173.252.69.7:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:00:40.077873 2026] [security2:error] [pid 352421:tid 352634] [client 202.143.127.214:64281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RWMJSWzG9jbYOtu43SQAAANg"]
[Tue Jul 21 08:00:40.077994 2026] [security2:error] [pid 352421:tid 352634] [client 202.143.127.214:64281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RWMJSWzG9jbYOtu43SQAAANg"]
[Tue Jul 21 08:00:40.098110 2026] [security2:error] [pid 358661:tid 358858] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.sofiagheller1782846626000.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9RWAlWhjQfpOo60_HEDAAAAEA"]
[Tue Jul 21 08:00:40.240578 2026] [security2:error] [pid 358661:tid 358814] [client 185.213.175.37:9580] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.arielson.com.br"] [uri "/"] [unique_id "al9RWAlWhjQfpOo60_HEFgAAABQ"]
[Tue Jul 21 08:00:40.304237 2026] [security2:error] [pid 358661:tid 358895] [client 74.249.245.134:54342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/buy.php"] [unique_id "al9RWAlWhjQfpOo60_HEFwAAAGU"]
[Tue Jul 21 08:00:40.527894 2026] [security2:error] [pid 358661:tid 358864] [client 175.144.82.48:55988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RWAlWhjQfpOo60_HEGwAAAEY"]
[Tue Jul 21 08:00:40.528779 2026] [security2:error] [pid 358661:tid 358864] [client 175.144.82.48:55988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RWAlWhjQfpOo60_HEGwAAAEY"]
[Tue Jul 21 08:00:40.646685 2026] [security2:error] [pid 358661:tid 358828] [client 223.236.153.128:5122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RWAlWhjQfpOo60_HEIAAAACI"]
[Tue Jul 21 08:00:40.651534 2026] [security2:error] [pid 358661:tid 358828] [client 223.236.153.128:5122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RWAlWhjQfpOo60_HEIAAAACI"]
[Tue Jul 21 08:00:41.621458 2026] [security2:error] [pid 352421:tid 352661] [client 65.21.113.253:51284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RWcJSWzG9jbYOtu43bQAAAPM"]
[Tue Jul 21 08:00:41.680258 2026] [security2:error] [pid 358661:tid 358918] [client 193.36.225.56:43337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RWQlWhjQfpOo60_HEKwAAAHw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:00:41.712682 2026] [security2:error] [pid 352421:tid 352664] [client 117.247.80.59:12155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RWcJSWzG9jbYOtu43bgAAAPY"]
[Tue Jul 21 08:00:41.712778 2026] [security2:error] [pid 352421:tid 352664] [client 117.247.80.59:12155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RWcJSWzG9jbYOtu43bgAAAPY"]
[Tue Jul 21 08:00:41.908019 2026] [security2:error] [pid 352421:tid 352552] [client 20.151.10.161:39919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-content/index.php"] [unique_id "al9RWcJSWzG9jbYOtu43cgAAAIY"]
[Tue Jul 21 08:00:42.056467 2026] [security2:error] [pid 358661:tid 358912] [client 20.226.60.151:65459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/122.php"] [unique_id "al9RWglWhjQfpOo60_HEOwAAAHY"]
[Tue Jul 21 08:00:42.326899 2026] [security2:error] [pid 358661:tid 358908] [client 65.21.113.253:47896] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RWQlWhjQfpOo60_HENQAAAHI"]
[Tue Jul 21 08:00:42.473887 2026] [security2:error] [pid 352421:tid 352582] [client 51.195.39.149:43362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "roanalacerda.com.br"] [uri "/"] [unique_id "al9RWsJSWzG9jbYOtu43fgAAAKQ"]
[Tue Jul 21 08:00:42.508870 2026] [security2:error] [pid 352421:tid 352614] [client 109.60.28.94:53551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RWsJSWzG9jbYOtu43gAAAAMQ"]
[Tue Jul 21 08:00:42.508985 2026] [security2:error] [pid 352421:tid 352614] [client 109.60.28.94:53551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RWsJSWzG9jbYOtu43gAAAAMQ"]
[Tue Jul 21 08:00:42.511014 2026] [security2:error] [pid 358661:tid 358855] [client 87.116.180.198:13877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RWglWhjQfpOo60_HEQwAAAD0"]
[Tue Jul 21 08:00:42.514451 2026] [security2:error] [pid 358661:tid 358855] [client 87.116.180.198:13877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RWglWhjQfpOo60_HEQwAAAD0"]
[Tue Jul 21 08:00:42.598222 2026] [security2:error] [pid 358661:tid 358797] [client 184.75.221.3:45088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9RWglWhjQfpOo60_HESAAAAAM"]
[Tue Jul 21 08:00:42.598302 2026] [security2:error] [pid 358661:tid 358797] [client 184.75.221.3:45088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9RWglWhjQfpOo60_HESAAAAAM"]
[Tue Jul 21 08:00:42.850117 2026] [security2:error] [pid 358661:tid 358880] [client 106.215.181.8:11047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RWglWhjQfpOo60_HESwAAAFY"]
[Tue Jul 21 08:00:42.850239 2026] [security2:error] [pid 358661:tid 358880] [client 106.215.181.8:11047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RWglWhjQfpOo60_HESwAAAFY"]
[Tue Jul 21 08:00:43.022253 2026] [security2:error] [pid 358661:tid 358919] [client 74.249.245.134:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/sx.php"] [unique_id "al9RWwlWhjQfpOo60_HETgAAAH0"]
[Tue Jul 21 08:00:43.083509 2026] [security2:error] [pid 358661:tid 358888] [client 20.104.96.117:46714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/ip.php"] [unique_id "al9RWwlWhjQfpOo60_HEUAAAAF4"]
[Tue Jul 21 08:00:43.187578 2026] [security2:error] [pid 352421:tid 352551] [client 103.78.200.11:64620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RW8JSWzG9jbYOtu43iQAAAIU"]
[Tue Jul 21 08:00:43.187733 2026] [security2:error] [pid 352421:tid 352551] [client 103.78.200.11:64620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RW8JSWzG9jbYOtu43iQAAAIU"]
[Tue Jul 21 08:00:43.543976 2026] [security2:error] [pid 358661:tid 358791] [remote 154.61.75.100:49566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9RWwlWhjQfpOo60_HEWgAABH4"]
[Tue Jul 21 08:00:43.544192 2026] [security2:error] [pid 358661:tid 358798] [client 154.61.75.100:49566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9RWwlWhjQfpOo60_HEWgAABH4"]
[Tue Jul 21 08:00:43.725488 2026] [security2:error] [pid 358661:tid 358913] [client 184.75.221.3:54374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9RWwlWhjQfpOo60_HEYAAAAHc"]
[Tue Jul 21 08:00:43.725580 2026] [security2:error] [pid 358661:tid 358913] [client 184.75.221.3:54374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9RWwlWhjQfpOo60_HEYAAAAHc"]
[Tue Jul 21 08:00:43.777482 2026] [security2:error] [pid 358661:tid 358854] [client 65.21.113.253:32994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RWwlWhjQfpOo60_HEVAAAADw"]
[Tue Jul 21 08:00:43.907955 2026] [security2:error] [pid 358661:tid 358823] [client 103.86.117.203:62132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RWwlWhjQfpOo60_HEZAAAAB0"]
[Tue Jul 21 08:00:43.908096 2026] [security2:error] [pid 358661:tid 358823] [client 103.86.117.203:62132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RWwlWhjQfpOo60_HEZAAAAB0"]
[Tue Jul 21 08:00:43.910062 2026] [security2:error] [pid 352421:tid 352658] [client 198.54.128.138:49280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9RW8JSWzG9jbYOtu43lAAAAPA"]
[Tue Jul 21 08:00:43.910138 2026] [security2:error] [pid 352421:tid 352658] [client 198.54.128.138:49280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9RW8JSWzG9jbYOtu43lAAAAPA"]
[Tue Jul 21 08:00:44.017327 2026] [security2:error] [pid 352421:tid 352659] [client 185.213.175.37:13964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.artetoner.com.br"] [uri "/"] [unique_id "al9RXMJSWzG9jbYOtu43mwAAAPE"]
[Tue Jul 21 08:00:44.017422 2026] [security2:error] [pid 352421:tid 352659] [client 185.213.175.37:13964] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.artetoner.com.br"] [uri "/"] [unique_id "al9RXMJSWzG9jbYOtu43mwAAAPE"]
[Tue Jul 21 08:00:44.064020 2026] [security2:error] [pid 352421:tid 352567] [client 20.226.60.151:59997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/mds.php"] [unique_id "al9RXMJSWzG9jbYOtu43nAAAAJU"]
[Tue Jul 21 08:00:44.091516 2026] [security2:error] [pid 358661:tid 358882] [client 103.29.114.44:11752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RXAlWhjQfpOo60_HEZwAAAFg"]
[Tue Jul 21 08:00:44.091673 2026] [security2:error] [pid 358661:tid 358882] [client 103.29.114.44:11752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RXAlWhjQfpOo60_HEZwAAAFg"]
[Tue Jul 21 08:00:44.138565 2026] [security2:error] [pid 358661:tid 358877] [client 102.206.115.33:62293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RXAlWhjQfpOo60_HEagAAAFM"]
[Tue Jul 21 08:00:44.139057 2026] [security2:error] [pid 358661:tid 358877] [client 102.206.115.33:62293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RXAlWhjQfpOo60_HEagAAAFM"]
[Tue Jul 21 08:00:44.761379 2026] [security2:error] [pid 358661:tid 358682] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RXAlWhjQfpOo60_HEdAAAFhE"]
[Tue Jul 21 08:00:44.761540 2026] [security2:error] [pid 358661:tid 358816] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RXAlWhjQfpOo60_HEdAAAFhE"]
[Tue Jul 21 08:00:44.928957 2026] [security2:error] [pid 352421:tid 352564] [client 20.151.10.161:39777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/zoro.php"] [unique_id "al9RXMJSWzG9jbYOtu43rgAAAJI"]
[Tue Jul 21 08:00:45.041941 2026] [security2:error] [pid 352421:tid 352604] [client 20.104.96.117:27091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/kq1.php"] [unique_id "al9RXcJSWzG9jbYOtu43swAAALo"]
[Tue Jul 21 08:00:45.100789 2026] [security2:error] [pid 352421:tid 352630] [client 65.21.113.253:51284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RXcJSWzG9jbYOtu43tQAAANQ"]
[Tue Jul 21 08:00:45.416190 2026] [security2:error] [pid 352421:tid 352507] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RXcJSWzG9jbYOtu43twAAq1U"]
[Tue Jul 21 08:00:45.416411 2026] [security2:error] [pid 352421:tid 352589] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RXcJSWzG9jbYOtu43twAAq1U"]
[Tue Jul 21 08:00:45.427041 2026] [security2:error] [pid 352421:tid 352598] [client 74.249.245.134:5557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/article.php"] [unique_id "al9RXcJSWzG9jbYOtu43uAAAALQ"]
[Tue Jul 21 08:00:45.569052 2026] [security2:error] [pid 358661:tid 358866] [client 122.164.127.47:50488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RXQlWhjQfpOo60_HEhwAAAEg"]
[Tue Jul 21 08:00:45.569157 2026] [security2:error] [pid 358661:tid 358866] [client 122.164.127.47:50488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RXQlWhjQfpOo60_HEhwAAAEg"]
[Tue Jul 21 08:00:45.580810 2026] [security2:error] [pid 352421:tid 352621] [client 20.226.60.151:59909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-blink.php"] [unique_id "al9RXcJSWzG9jbYOtu43uwAAAMs"]
[Tue Jul 21 08:00:45.732459 2026] [security2:error] [pid 358661:tid 358865] [client 65.21.113.253:32994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RXQlWhjQfpOo60_HEggAAAEc"]
[Tue Jul 21 08:00:45.835945 2026] [security2:error] [pid 358661:tid 358833] [client 103.166.103.129:63096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RXQlWhjQfpOo60_HEiQAAACc"]
[Tue Jul 21 08:00:45.836397 2026] [security2:error] [pid 358661:tid 358833] [client 103.166.103.129:63096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RXQlWhjQfpOo60_HEiQAAACc"]
[Tue Jul 21 08:00:45.838400 2026] [security2:error] [pid 352421:tid 352445] [remote 178.20.101.93:33278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.101.20.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9RXcJSWzG9jbYOtu43wAAAyRc"]
[Tue Jul 21 08:00:45.883493 2026] [autoindex:error] [pid 358661:tid 358836] [client 198.235.24.178:63370] AH01276: Cannot serve directory /home4/ciclod61/dmkimoveis.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:00:46.085189 2026] [security2:error] [pid 352421:tid 352622] [client 122.179.91.63:12044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RXsJSWzG9jbYOtu43yAAAAMw"]
[Tue Jul 21 08:00:46.085316 2026] [security2:error] [pid 352421:tid 352622] [client 122.179.91.63:12044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RXsJSWzG9jbYOtu43yAAAAMw"]
[Tue Jul 21 08:00:46.294067 2026] [security2:error] [pid 352421:tid 352466] [remote 45.90.123.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/wp-login.php"] [unique_id "al9RXsJSWzG9jbYOtu43zAAAtyw"]
[Tue Jul 21 08:00:46.346956 2026] [security2:error] [pid 358661:tid 358880] [client 136.144.33.28:63975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RXglWhjQfpOo60_HEjwAAAFY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:00:46.638225 2026] [security2:error] [pid 358661:tid 358855] [client 204.8.98.45:34370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9RXglWhjQfpOo60_HEkQAAAD0"]
[Tue Jul 21 08:00:46.638327 2026] [security2:error] [pid 358661:tid 358855] [client 204.8.98.45:34370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9RXglWhjQfpOo60_HEkQAAAD0"]
[Tue Jul 21 08:00:47.311682 2026] [security2:error] [pid 352421:tid 352656] [client 74.7.241.153:48484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.concielo.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9RX8JSWzG9jbYOtu433AAA7mo"]
[Tue Jul 21 08:00:47.428545 2026] [security2:error] [pid 358661:tid 358811] [client 20.151.10.161:39763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/admin.php"] [unique_id "al9RXwlWhjQfpOo60_HEpAAAABE"]
[Tue Jul 21 08:00:47.432630 2026] [security2:error] [pid 358661:tid 358847] [client 20.226.60.151:59945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/zc-208.php"] [unique_id "al9RXwlWhjQfpOo60_HEpQAAADU"]
[Tue Jul 21 08:00:47.619642 2026] [security2:error] [pid 352421:tid 352620] [client 182.8.255.181:17212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RX8JSWzG9jbYOtu434gAAAMo"]
[Tue Jul 21 08:00:47.619919 2026] [security2:error] [pid 352421:tid 352620] [client 182.8.255.181:17212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RX8JSWzG9jbYOtu434gAAAMo"]
[Tue Jul 21 08:00:47.620729 2026] [security2:error] [pid 352421:tid 352444] [remote 5.252.52.249:59844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "companhiatop.com.br"] [uri "/wp-login.php"] [unique_id "al9RX8JSWzG9jbYOtu434QAAxRY"]
[Tue Jul 21 08:00:47.756997 2026] [security2:error] [pid 358661:tid 358899] [client 20.104.96.117:46649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9RXwlWhjQfpOo60_HEqAAAAGk"]
[Tue Jul 21 08:00:47.760268 2026] [security2:error] [pid 352421:tid 352664] [client 74.249.245.134:5547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/bootstrap.php"] [unique_id "al9RX8JSWzG9jbYOtu435gAAAPY"]
[Tue Jul 21 08:00:47.798216 2026] [security2:error] [pid 358661:tid 358807] [client 178.153.91.96:58158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RXwlWhjQfpOo60_HEqQAAAA0"]
[Tue Jul 21 08:00:47.798348 2026] [security2:error] [pid 358661:tid 358807] [client 178.153.91.96:58158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RXwlWhjQfpOo60_HEqQAAAA0"]
[Tue Jul 21 08:00:47.861161 2026] [security2:error] [pid 358661:tid 358711] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RXwlWhjQfpOo60_HEqwAAHC4"]
[Tue Jul 21 08:00:47.861343 2026] [security2:error] [pid 358661:tid 358822] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RXwlWhjQfpOo60_HEqwAAHC4"]
[Tue Jul 21 08:00:48.123246 2026] [security2:error] [pid 358661:tid 358798] [client 117.210.135.0:65498] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RYAlWhjQfpOo60_HErAAAAAQ"]
[Tue Jul 21 08:00:48.123428 2026] [security2:error] [pid 358661:tid 358798] [client 117.210.135.0:65498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RYAlWhjQfpOo60_HErAAAAAQ"]
[Tue Jul 21 08:00:48.397047 2026] [security2:error] [pid 352421:tid 352520] [remote 124.55.178.99:36740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9RYMJSWzG9jbYOtu438QAA4mI"]
[Tue Jul 21 08:00:48.667167 2026] [security2:error] [pid 358661:tid 358714] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RYAlWhjQfpOo60_HEtQAAYTE"]
[Tue Jul 21 08:00:48.667310 2026] [security2:error] [pid 358661:tid 358891] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RYAlWhjQfpOo60_HEtQAAYTE"]
[Tue Jul 21 08:00:48.687151 2026] [security2:error] [pid 352421:tid 352582] [client 65.21.113.253:51284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RYMJSWzG9jbYOtu438wAAAKQ"]
[Tue Jul 21 08:00:48.768742 2026] [security2:error] [pid 352421:tid 352654] [client 41.68.90.219:55897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RYMJSWzG9jbYOtu439wAAAOw"]
[Tue Jul 21 08:00:48.769861 2026] [security2:error] [pid 352421:tid 352654] [client 41.68.90.219:55897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RYMJSWzG9jbYOtu439wAAAOw"]
[Tue Jul 21 08:00:48.797797 2026] [security2:error] [pid 352421:tid 352610] [client 20.151.10.161:39898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/greap.php"] [unique_id "al9RYMJSWzG9jbYOtu43-AAAAMA"]
[Tue Jul 21 08:00:48.944363 2026] [autoindex:error] [pid 358661:tid 358838] [client 43.130.101.151:55876] AH01276: Cannot serve directory /home2/tiago878/public_html/hostserv/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:00:48.965059 2026] [security2:error] [pid 358661:tid 358794] [client 38.100.221.102:17616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RYAlWhjQfpOo60_HEvwAAAAA"]
[Tue Jul 21 08:00:48.965239 2026] [security2:error] [pid 358661:tid 358794] [client 38.100.221.102:17616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RYAlWhjQfpOo60_HEvwAAAAA"]
[Tue Jul 21 08:00:49.080313 2026] [security2:error] [pid 352421:tid 352591] [client 20.104.96.117:46609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/h02ugyh.php"] [unique_id "al9RYcJSWzG9jbYOtu43_QAAAK0"]
[Tue Jul 21 08:00:49.175760 2026] [security2:error] [pid 352421:tid 352546] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RYcJSWzG9jbYOtu43_gAA-nw"]
[Tue Jul 21 08:00:49.175930 2026] [security2:error] [pid 352421:tid 352668] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RYcJSWzG9jbYOtu43_gAA-nw"]
[Tue Jul 21 08:00:49.189980 2026] [security2:error] [pid 352421:tid 352470] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RYcJSWzG9jbYOtu43_wAAizA"]
[Tue Jul 21 08:00:49.190140 2026] [security2:error] [pid 352421:tid 352557] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RYcJSWzG9jbYOtu43_wAAizA"]
[Tue Jul 21 08:00:49.192962 2026] [security2:error] [pid 352421:tid 352625] [client 65.21.113.253:33006] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RYMJSWzG9jbYOtu439AAAAM8"]
[Tue Jul 21 08:00:49.608937 2026] [security2:error] [pid 358661:tid 358825] [client 74.249.245.134:62853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/config-backup.php"] [unique_id "al9RYQlWhjQfpOo60_HExwAAAB8"]
[Tue Jul 21 08:00:49.766807 2026] [security2:error] [pid 358661:tid 358899] [client 65.21.113.253:33014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RYQlWhjQfpOo60_HExgAAAGk"]
[Tue Jul 21 08:00:49.859034 2026] [security2:error] [pid 352421:tid 352556] [client 20.151.10.161:39803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/177.php"] [unique_id "al9RYcJSWzG9jbYOtu44CwAAAIo"]
[Tue Jul 21 08:00:50.011051 2026] [security2:error] [pid 358661:tid 358845] [client 184.75.221.3:35320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9RYglWhjQfpOo60_HEzgAAADM"]
[Tue Jul 21 08:00:50.011212 2026] [security2:error] [pid 358661:tid 358845] [client 184.75.221.3:35320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9RYglWhjQfpOo60_HEzgAAADM"]
[Tue Jul 21 08:00:50.067279 2026] [security2:error] [pid 358661:tid 358732] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RYglWhjQfpOo60_HEzwAAW0M"]
[Tue Jul 21 08:00:50.067507 2026] [security2:error] [pid 358661:tid 358885] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RYglWhjQfpOo60_HEzwAAW0M"]
[Tue Jul 21 08:00:50.348090 2026] [security2:error] [pid 358661:tid 358881] [client 175.144.82.48:56369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RYglWhjQfpOo60_HE0QAAAFc"]
[Tue Jul 21 08:00:50.348319 2026] [security2:error] [pid 358661:tid 358881] [client 175.144.82.48:56369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RYglWhjQfpOo60_HE0QAAAFc"]
[Tue Jul 21 08:00:50.358246 2026] [security2:error] [pid 358661:tid 358871] [client 20.226.60.151:16002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/sid4.php"] [unique_id "al9RYglWhjQfpOo60_HE0gAAAE0"]
[Tue Jul 21 08:00:51.106291 2026] [security2:error] [pid 358661:tid 358918] [client 202.143.127.214:64748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RYwlWhjQfpOo60_HE2gAAAHw"]
[Tue Jul 21 08:00:51.107118 2026] [security2:error] [pid 358661:tid 358918] [client 202.143.127.214:64748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RYwlWhjQfpOo60_HE2gAAAHw"]
[Tue Jul 21 08:00:51.122046 2026] [security2:error] [pid 358661:tid 358843] [client 223.236.153.128:4860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RYwlWhjQfpOo60_HE2wAAADE"]
[Tue Jul 21 08:00:51.122176 2026] [security2:error] [pid 358661:tid 358843] [client 223.236.153.128:4860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RYwlWhjQfpOo60_HE2wAAADE"]
[Tue Jul 21 08:00:51.500940 2026] [security2:error] [pid 352421:tid 352607] [client 20.151.10.161:39881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/199.php"] [unique_id "al9RY8JSWzG9jbYOtu44IwAAAL0"]
[Tue Jul 21 08:00:51.513110 2026] [security2:error] [pid 352421:tid 352636] [client 172.245.102.44:35223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RYsJSWzG9jbYOtu44EgAAANo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:00:52.392898 2026] [security2:error] [pid 358661:tid 358816] [client 74.249.245.134:5508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/goods.php"] [unique_id "al9RZAlWhjQfpOo60_HE7gAAABY"]
[Tue Jul 21 08:00:52.510443 2026] [security2:error] [pid 358661:tid 358814] [client 117.247.80.59:16061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RZAlWhjQfpOo60_HE7wAAABQ"]
[Tue Jul 21 08:00:52.510579 2026] [security2:error] [pid 358661:tid 358814] [client 117.247.80.59:16061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RZAlWhjQfpOo60_HE7wAAABQ"]
[Tue Jul 21 08:00:52.526636 2026] [core:alert] [pid 358661:tid 358920] [client 173.252.87.114:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:00:52.567921 2026] [security2:error] [pid 358661:tid 358868] [client 204.8.98.45:58790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9RZAlWhjQfpOo60_HE8gAAAEo"]
[Tue Jul 21 08:00:52.568022 2026] [security2:error] [pid 358661:tid 358868] [client 204.8.98.45:58790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9RZAlWhjQfpOo60_HE8gAAAEo"]
[Tue Jul 21 08:00:52.803900 2026] [security2:error] [pid 352421:tid 352552] [client 20.104.96.117:27079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-temp.php"] [unique_id "al9RZMJSWzG9jbYOtu44QAAAAIY"]
[Tue Jul 21 08:00:52.870272 2026] [security2:error] [pid 358661:tid 358912] [client 20.226.60.151:59983] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.lupipet.com"] [uri "/wp-includes/l10n/"] [unique_id "al9RZAlWhjQfpOo60_HE9AAAAHY"]
[Tue Jul 21 08:00:52.871450 2026] [security2:error] [pid 352421:tid 352565] [client 65.21.113.253:51284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RZMJSWzG9jbYOtu44QgAAAJM"]
[Tue Jul 21 08:00:53.117939 2026] [security2:error] [pid 352421:tid 352607] [client 20.151.10.161:39816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/file52.php"] [unique_id "al9RZcJSWzG9jbYOtu44SgAAAL0"]
[Tue Jul 21 08:00:53.280334 2026] [security2:error] [pid 352421:tid 352577] [client 87.116.180.198:14039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RZcJSWzG9jbYOtu44TAAAAJ8"]
[Tue Jul 21 08:00:53.280517 2026] [security2:error] [pid 352421:tid 352577] [client 87.116.180.198:14039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RZcJSWzG9jbYOtu44TAAAAJ8"]
[Tue Jul 21 08:00:53.338060 2026] [core:alert] [pid 352421:tid 352674] [client 57.141.18.24:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:00:53.419901 2026] [security2:error] [pid 358661:tid 358799] [client 106.215.181.8:1558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RZQlWhjQfpOo60_HE_QAAAAU"]
[Tue Jul 21 08:00:53.429688 2026] [security2:error] [pid 358661:tid 358799] [client 106.215.181.8:1558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RZQlWhjQfpOo60_HE_QAAAAU"]
[Tue Jul 21 08:00:53.437848 2026] [security2:error] [pid 358661:tid 358876] [client 109.60.28.94:54355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RZQlWhjQfpOo60_HE_gAAAFI"]
[Tue Jul 21 08:00:53.438557 2026] [security2:error] [pid 358661:tid 358876] [client 109.60.28.94:54355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RZQlWhjQfpOo60_HE_gAAAFI"]
[Tue Jul 21 08:00:53.571339 2026] [security2:error] [pid 352421:tid 352582] [client 65.21.113.253:33006] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RZcJSWzG9jbYOtu44SQAAAKQ"]
[Tue Jul 21 08:00:53.602691 2026] [security2:error] [pid 358661:tid 358851] [client 20.151.10.161:39775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/122.php"] [unique_id "al9RZQlWhjQfpOo60_HFBAAAADk"]
[Tue Jul 21 08:00:53.795002 2026] [security2:error] [pid 352421:tid 352618] [client 103.78.200.11:65096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RZcJSWzG9jbYOtu44VQAAAMg"]
[Tue Jul 21 08:00:53.795141 2026] [security2:error] [pid 352421:tid 352618] [client 103.78.200.11:65096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RZcJSWzG9jbYOtu44VQAAAMg"]
[Tue Jul 21 08:00:54.388047 2026] [security2:error] [pid 358661:tid 358854] [client 74.249.245.134:54381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/init.php"] [unique_id "al9RZglWhjQfpOo60_HFEgAAADw"]
[Tue Jul 21 08:00:54.404130 2026] [security2:error] [pid 352421:tid 352625] [client 103.86.117.203:62679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RZsJSWzG9jbYOtu44YQAAAM8"]
[Tue Jul 21 08:00:54.404256 2026] [security2:error] [pid 352421:tid 352625] [client 103.86.117.203:62679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RZsJSWzG9jbYOtu44YQAAAM8"]
[Tue Jul 21 08:00:54.604791 2026] [security2:error] [pid 358661:tid 358806] [client 20.151.10.161:39912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/green1.php"] [unique_id "al9RZglWhjQfpOo60_HFFwAAAAw"]
[Tue Jul 21 08:00:54.669349 2026] [security2:error] [pid 352421:tid 352592] [client 65.21.113.253:42424] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RZsJSWzG9jbYOtu44XAAAAK4"]
[Tue Jul 21 08:00:54.680517 2026] [security2:error] [pid 358661:tid 358863] [client 20.226.60.151:59967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wmore1.php"] [unique_id "al9RZglWhjQfpOo60_HFGwAAAEU"]
[Tue Jul 21 08:00:54.681761 2026] [security2:error] [pid 352421:tid 352593] [client 103.29.114.44:58371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RZsJSWzG9jbYOtu44ZgAAAK8"]
[Tue Jul 21 08:00:54.687225 2026] [security2:error] [pid 352421:tid 352593] [client 103.29.114.44:58371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RZsJSWzG9jbYOtu44ZgAAAK8"]
[Tue Jul 21 08:00:54.705509 2026] [security2:error] [pid 358661:tid 358856] [client 102.206.115.33:63349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RZglWhjQfpOo60_HFHAAAAD4"]
[Tue Jul 21 08:00:54.708075 2026] [security2:error] [pid 358661:tid 358856] [client 102.206.115.33:63349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RZglWhjQfpOo60_HFHAAAAD4"]
[Tue Jul 21 08:00:54.734726 2026] [security2:error] [pid 358661:tid 358751] [remote 182.77.62.24:59270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9RZQlWhjQfpOo60_HFBwAAblY"]
[Tue Jul 21 08:00:54.873585 2026] [security2:error] [pid 358661:tid 358762] [remote 45.90.123.233:49482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/wp-login.php"] [unique_id "al9RZglWhjQfpOo60_HFHgAAL2E"]
[Tue Jul 21 08:00:55.215106 2026] [security2:error] [pid 352421:tid 352639] [client 45.3.40.25:45019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.40.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RZ8JSWzG9jbYOtu44bAAAAN0"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:00:55.687521 2026] [security2:error] [pid 352421:tid 352543] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RZ8JSWzG9jbYOtu44eAAAsHk"]
[Tue Jul 21 08:00:55.687791 2026] [security2:error] [pid 352421:tid 352594] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RZ8JSWzG9jbYOtu44eAAAsHk"]
[Tue Jul 21 08:00:55.730215 2026] [security2:error] [pid 358661:tid 358749] [remote 192.241.143.148:45684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9RZwlWhjQfpOo60_HFKgAABlQ"]
[Tue Jul 21 08:00:55.740234 2026] [security2:error] [pid 358661:tid 358852] [client 20.104.96.117:27097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9RZwlWhjQfpOo60_HFKwAAADo"]
[Tue Jul 21 08:00:55.832829 2026] [security2:error] [pid 358661:tid 358835] [client 20.151.10.161:39904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/biufile.php"] [unique_id "al9RZwlWhjQfpOo60_HFLQAAACk"]
[Tue Jul 21 08:00:55.889101 2026] [security2:error] [pid 358661:tid 358833] [client 92.119.178.3:52394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9RZwlWhjQfpOo60_HFLgAAACc"]
[Tue Jul 21 08:00:55.889180 2026] [security2:error] [pid 358661:tid 358833] [client 92.119.178.3:52394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9RZwlWhjQfpOo60_HFLgAAACc"]
[Tue Jul 21 08:00:56.067174 2026] [security2:error] [pid 358661:tid 358847] [client 122.164.127.47:51069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RaAlWhjQfpOo60_HFMgAAADU"]
[Tue Jul 21 08:00:56.067307 2026] [security2:error] [pid 358661:tid 358847] [client 122.164.127.47:51069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RaAlWhjQfpOo60_HFMgAAADU"]
[Tue Jul 21 08:00:56.121529 2026] [security2:error] [pid 358661:tid 358908] [client 20.226.60.151:59904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/solo1.php"] [unique_id "al9RaAlWhjQfpOo60_HFNwAAAHI"]
[Tue Jul 21 08:00:56.441826 2026] [security2:error] [pid 358661:tid 358918] [client 103.166.103.129:63638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RaAlWhjQfpOo60_HFQgAAAHw"]
[Tue Jul 21 08:00:56.441985 2026] [security2:error] [pid 358661:tid 358918] [client 103.166.103.129:63638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RaAlWhjQfpOo60_HFQgAAAHw"]
[Tue Jul 21 08:00:56.659987 2026] [security2:error] [pid 358661:tid 358776] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RaAlWhjQfpOo60_HFSAAACW8"]
[Tue Jul 21 08:00:56.660119 2026] [security2:error] [pid 358661:tid 358803] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RaAlWhjQfpOo60_HFSAAACW8"]
[Tue Jul 21 08:00:56.760701 2026] [security2:error] [pid 358661:tid 358920] [client 114.119.146.114:21201] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.folegofinanceiro.com.br"] [uri "/wp-login.php"] [unique_id "al9RaAlWhjQfpOo60_HFRgAAAH4"], referer: https://www.folegofinanceiro.com.br/wp-login.php
[Tue Jul 21 08:00:56.775076 2026] [security2:error] [pid 358661:tid 358787] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.git-credentials"] [unique_id "al9RaAlWhjQfpOo60_HFTgAAK3o"]
[Tue Jul 21 08:00:56.775307 2026] [security2:error] [pid 358661:tid 358837] [client 34.17.160.209:43104] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.git-credentials"] [unique_id "al9RaAlWhjQfpOo60_HFTgAAK3o"]
[Tue Jul 21 08:00:57.016066 2026] [security2:error] [pid 358661:tid 358667] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.git/HEAD"] [unique_id "al9RaQlWhjQfpOo60_HFWgAAKwI"]
[Tue Jul 21 08:00:57.016187 2026] [security2:error] [pid 358661:tid 358837] [client 34.17.160.209:43104] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.git/HEAD"] [unique_id "al9RaQlWhjQfpOo60_HFWgAAKwI"]
[Tue Jul 21 08:00:57.076633 2026] [security2:error] [pid 358661:tid 358679] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "app.institutocrismonteiro.com.br"] [uri "/graphql"] [unique_id "al9RaQlWhjQfpOo60_HFXgAANw4"]
[Tue Jul 21 08:00:57.094941 2026] [security2:error] [pid 358661:tid 358792] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.env"] [unique_id "al9RaQlWhjQfpOo60_HFYQAAan8"]
[Tue Jul 21 08:00:57.094939 2026] [security2:error] [pid 358661:tid 358680] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.env.example"] [unique_id "al9RaQlWhjQfpOo60_HFYAAAag8"]
[Tue Jul 21 08:00:57.125113 2026] [authz_core:error] [pid 352421:tid 352616] [client 74.249.245.134:0] AH01630: client denied by server configuration: /home4/rqraca07/rqrconsultoria.com.br/php.ini
[Tue Jul 21 08:00:57.214279 2026] [security2:error] [pid 358661:tid 358676] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.env.backup"] [unique_id "al9RaQlWhjQfpOo60_HFZQAAIAs"]
[Tue Jul 21 08:00:57.274708 2026] [security2:error] [pid 358661:tid 358683] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.env.bak"] [unique_id "al9RaQlWhjQfpOo60_HFZgAAdhI"]
[Tue Jul 21 08:00:57.277259 2026] [security2:error] [pid 358661:tid 358874] [client 74.249.245.134:5564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/settings.php"] [unique_id "al9RaQlWhjQfpOo60_HFaAAAAFA"]
[Tue Jul 21 08:00:57.353703 2026] [security2:error] [pid 358661:tid 358682] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.env.old"] [unique_id "al9RaQlWhjQfpOo60_HFagAAChE"]
[Tue Jul 21 08:00:57.354356 2026] [security2:error] [pid 358661:tid 358688] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/api/.env"] [unique_id "al9RaQlWhjQfpOo60_HFawAAChc"]
[Tue Jul 21 08:00:57.364722 2026] [security2:error] [pid 358661:tid 358696] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/admin/.env"] [unique_id "al9RaQlWhjQfpOo60_HFbAAASB8"]
[Tue Jul 21 08:00:57.367028 2026] [security2:error] [pid 358661:tid 358866] [client 34.17.160.209:43104] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.institutocrismonteiro.com.br"] [uri "/admin/.env"] [unique_id "al9RaQlWhjQfpOo60_HFbAAASB8"]
[Tue Jul 21 08:00:57.478825 2026] [security2:error] [pid 358661:tid 358668] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "app.institutocrismonteiro.com.br"] [uri "/api/graphql"] [unique_id "al9RaQlWhjQfpOo60_HFbwAATAM"]
[Tue Jul 21 08:00:57.500475 2026] [security2:error] [pid 358661:tid 358706] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/config/.env"] [unique_id "al9RaQlWhjQfpOo60_HFcgAAASk"]
[Tue Jul 21 08:00:57.502301 2026] [security2:error] [pid 358661:tid 358714] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/backend/.env"] [unique_id "al9RaQlWhjQfpOo60_HFdAAAATE"]
[Tue Jul 21 08:00:57.563912 2026] [security2:error] [pid 358661:tid 358732] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/serviceAccountKey.json"] [unique_id "al9RaQlWhjQfpOo60_HFeQAAAUM"]
[Tue Jul 21 08:00:57.711944 2026] [security2:error] [pid 358661:tid 358744] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "app.institutocrismonteiro.com.br"] [uri "/v1/graphql"] [unique_id "al9RaQlWhjQfpOo60_HFgQAAU08"]
[Tue Jul 21 08:00:57.767937 2026] [authz_core:error] [pid 358661:tid 358687] [remote 34.17.160.209:43104] AH01630: client denied by server configuration: /home1/pedid516/app.institutocrismonteiro.com.br/.htpasswd
[Tue Jul 21 08:00:57.905824 2026] [security2:error] [pid 358661:tid 358686] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.ssh/id_dsa"] [unique_id "al9RaQlWhjQfpOo60_HFhwAABxU"]
[Tue Jul 21 08:00:57.919800 2026] [security2:error] [pid 358661:tid 358755] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9RaQlWhjQfpOo60_HFiwAAB1o"]
[Tue Jul 21 08:00:57.935590 2026] [security2:error] [pid 352421:tid 352640] [client 20.151.10.161:39858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wpconf.php"] [unique_id "al9RacJSWzG9jbYOtu44mwAAAN4"]
[Tue Jul 21 08:00:58.035716 2026] [security2:error] [pid 358661:tid 358753] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/id_rsa"] [unique_id "al9RaglWhjQfpOo60_HFkwAAdlg"]
[Tue Jul 21 08:00:58.092838 2026] [security2:error] [pid 358661:tid 358827] [client 182.8.255.181:17335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RaglWhjQfpOo60_HFlAAAACE"]
[Tue Jul 21 08:00:58.092968 2026] [security2:error] [pid 358661:tid 358827] [client 182.8.255.181:17335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RaglWhjQfpOo60_HFlAAAACE"]
[Tue Jul 21 08:00:58.190462 2026] [security2:error] [pid 358661:tid 358767] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/id_dsa"] [unique_id "al9RaglWhjQfpOo60_HFmAAASGY"]
[Tue Jul 21 08:00:58.223831 2026] [security2:error] [pid 358661:tid 358775] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/privatekey.key"] [unique_id "al9RaglWhjQfpOo60_HFmQAASG4"]
[Tue Jul 21 08:00:58.269400 2026] [security2:error] [pid 358661:tid 358787] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/private-key"] [unique_id "al9RaglWhjQfpOo60_HFnQAASHo"]
[Tue Jul 21 08:00:58.294370 2026] [security2:error] [pid 358661:tid 358772] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/key.pem"] [unique_id "al9RaglWhjQfpOo60_HFoAAASGs"]
[Tue Jul 21 08:00:58.304781 2026] [security2:error] [pid 352421:tid 352659] [client 172.245.102.43:54427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.102.245.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RasJSWzG9jbYOtu44oQAAAPE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:00:58.331850 2026] [access_compat:error] [pid 358661:tid 358821] [client 162.241.63.68:14462] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:00:58.362792 2026] [qos:error] [pid 358661:tid 358799] [client 162.241.63.68:14486] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9RaglWhjQfpOo60_HFpAAAAAU
[Tue Jul 21 08:00:58.371821 2026] [security2:error] [pid 358661:tid 358889] [client 178.153.91.96:58792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RaglWhjQfpOo60_HFpgAAAF8"]
[Tue Jul 21 08:00:58.371994 2026] [security2:error] [pid 358661:tid 358889] [client 178.153.91.96:58792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RaglWhjQfpOo60_HFpgAAAF8"]
[Tue Jul 21 08:00:58.386503 2026] [security2:error] [pid 352421:tid 352574] [client 65.21.113.253:42424] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RacJSWzG9jbYOtu44mgAAAJw"]
[Tue Jul 21 08:00:58.403361 2026] [qos:error] [pid 358661:tid 358834] [client 162.241.63.68:14500] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9RaglWhjQfpOo60_HFqgAAACg
[Tue Jul 21 08:00:58.418432 2026] [qos:error] [pid 358661:tid 358901] [client 162.241.63.68:14516] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9RaglWhjQfpOo60_HFqwAAAGs
[Tue Jul 21 08:00:58.454315 2026] [security2:error] [pid 358661:tid 358770] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.openclaw/.env"] [unique_id "al9RaglWhjQfpOo60_HFrgAASGk"]
[Tue Jul 21 08:00:58.516550 2026] [qos:error] [pid 358661:tid 358791] [remote 57.141.18.55:22162] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.55, id=al9RaglWhjQfpOo60_HFrwAAbn4
[Tue Jul 21 08:00:58.578320 2026] [security2:error] [pid 358661:tid 358786] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.hermes/.env"] [unique_id "al9RaglWhjQfpOo60_HFtAAAV3k"]
[Tue Jul 21 08:00:58.578707 2026] [security2:error] [pid 352421:tid 352427] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RasJSWzG9jbYOtu44owAAyQU"]
[Tue Jul 21 08:00:58.579141 2026] [security2:error] [pid 352421:tid 352619] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RasJSWzG9jbYOtu44owAAyQU"]
[Tue Jul 21 08:00:58.611708 2026] [security2:error] [pid 352421:tid 352638] [client 20.226.60.151:65427] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.lupipet.com"] [uri "/wp-includes/assets/"] [unique_id "al9RasJSWzG9jbYOtu44pAAAANw"]
[Tue Jul 21 08:00:58.652210 2026] [security2:error] [pid 358661:tid 358680] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.hermes/auth.json"] [unique_id "al9RaglWhjQfpOo60_HFtgAAHQ8"]
[Tue Jul 21 08:00:58.716458 2026] [security2:error] [pid 352421:tid 352664] [client 117.210.135.0:49928] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RasJSWzG9jbYOtu44qAAAAPY"]
[Tue Jul 21 08:00:58.716608 2026] [security2:error] [pid 352421:tid 352664] [client 117.210.135.0:49928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RasJSWzG9jbYOtu44qAAAAPY"]
[Tue Jul 21 08:00:58.776347 2026] [security2:error] [pid 358661:tid 358746] [remote 68.178.160.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9RaQlWhjQfpOo60_HFhAAAK1E"]
[Tue Jul 21 08:00:58.829449 2026] [security2:error] [pid 358661:tid 358700] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.profile"] [unique_id "al9RaglWhjQfpOo60_HFvgAASiM"]
[Tue Jul 21 08:00:58.832485 2026] [qos:error] [pid 352421:tid 352520] [remote 57.141.18.48:45108] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.48, id=al9RasJSWzG9jbYOtu44qwAAsGI
[Tue Jul 21 08:00:58.839900 2026] [security2:error] [pid 358661:tid 358826] [client 65.21.113.253:53154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RaglWhjQfpOo60_HFwAAAACA"]
[Tue Jul 21 08:00:58.854404 2026] [security2:error] [pid 358661:tid 358852] [client 122.179.91.63:21951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RaglWhjQfpOo60_HFwQAAADo"]
[Tue Jul 21 08:00:58.854485 2026] [security2:error] [pid 358661:tid 358852] [client 122.179.91.63:21951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RaglWhjQfpOo60_HFwQAAADo"]
[Tue Jul 21 08:00:58.940167 2026] [security2:error] [pid 358661:tid 358706] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "app.institutocrismonteiro.com.br"] [uri "/wp-config.php.bak"] [unique_id "al9RaglWhjQfpOo60_HFyAAACSk"]
[Tue Jul 21 08:00:58.940271 2026] [security2:error] [pid 358661:tid 358714] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "app.institutocrismonteiro.com.br"] [uri "/wp-config.php.old"] [unique_id "al9RaglWhjQfpOo60_HFyQAACTE"]
[Tue Jul 21 08:00:59.001941 2026] [security2:error] [pid 358661:tid 358708] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/laravel/.env"] [unique_id "al9RaglWhjQfpOo60_HFywAAIis"]
[Tue Jul 21 08:00:59.059930 2026] [security2:error] [pid 358661:tid 358711] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/core/.env"] [unique_id "al9RawlWhjQfpOo60_HFzAAAMi4"]
[Tue Jul 21 08:00:59.073116 2026] [security2:error] [pid 358661:tid 358741] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/config/.env.php"] [unique_id "al9RawlWhjQfpOo60_HFzQAAREw"]
[Tue Jul 21 08:00:59.147300 2026] [qos:error] [pid 358661:tid 358710] [remote 57.141.18.28:54894] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.28, id=al9RawlWhjQfpOo60_HFzgAAGy0
[Tue Jul 21 08:00:59.147573 2026] [security2:error] [pid 358661:tid 358721] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.env.php.bak"] [unique_id "al9RawlWhjQfpOo60_HF0AAAKDg"]
[Tue Jul 21 08:00:59.197154 2026] [security2:error] [pid 358661:tid 358725] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.env.swp"] [unique_id "al9RawlWhjQfpOo60_HF0wAAKDw"]
[Tue Jul 21 08:00:59.221340 2026] [security2:error] [pid 358661:tid 358681] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/config.php.bak"] [unique_id "al9RawlWhjQfpOo60_HF1QAAKBA"]
[Tue Jul 21 08:00:59.221387 2026] [security2:error] [pid 358661:tid 358678] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/configuration.php.bak"] [unique_id "al9RawlWhjQfpOo60_HF1AAAKA0"]
[Tue Jul 21 08:00:59.231701 2026] [security2:error] [pid 358661:tid 358908] [client 20.151.10.161:39808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/mosty.php"] [unique_id "al9RawlWhjQfpOo60_HF1gAAAHI"]
[Tue Jul 21 08:00:59.311919 2026] [security2:error] [pid 358661:tid 358686] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/public/.env"] [unique_id "al9RawlWhjQfpOo60_HF2QAAExU"]
[Tue Jul 21 08:00:59.312257 2026] [security2:error] [pid 358661:tid 358813] [client 34.17.160.209:43104] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.institutocrismonteiro.com.br"] [uri "/public/.env"] [unique_id "al9RawlWhjQfpOo60_HF2QAAExU"]
[Tue Jul 21 08:00:59.314133 2026] [security2:error] [pid 358661:tid 358687] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/web/.env"] [unique_id "al9RawlWhjQfpOo60_HF2wAAExY"]
[Tue Jul 21 08:00:59.317183 2026] [security2:error] [pid 358661:tid 358915] [client 74.7.241.180:44874] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.lumerah.com.br"] [uri "/index.php"] [unique_id "al9RaQlWhjQfpOo60_HFegAAeT4"]
[Tue Jul 21 08:00:59.320463 2026] [qos:error] [pid 352421:tid 352446] [remote 57.141.18.33:20242] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.33, id=al9Ra8JSWzG9jbYOtu44tQAApBg
[Tue Jul 21 08:00:59.325262 2026] [qos:error] [pid 358661:tid 358881] [client 162.241.63.68:58164] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9RawlWhjQfpOo60_HF3QAAAFc
[Tue Jul 21 08:00:59.335162 2026] [security2:error] [pid 358661:tid 358860] [client 74.249.245.134:17460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/g.php"] [unique_id "al9RawlWhjQfpOo60_HF3gAAAEI"]
[Tue Jul 21 08:00:59.353975 2026] [security2:error] [pid 358661:tid 358812] [client 20.197.195.24:24176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9RawlWhjQfpOo60_HF3wAAABI"]
[Tue Jul 21 08:00:59.404011 2026] [security2:error] [pid 358661:tid 358748] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/api/config"] [unique_id "al9RawlWhjQfpOo60_HF4gAAE1M"]
[Tue Jul 21 08:00:59.405144 2026] [security2:error] [pid 352421:tid 352546] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ra8JSWzG9jbYOtu44twAA5Xw"]
[Tue Jul 21 08:00:59.405291 2026] [security2:error] [pid 352421:tid 352647] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ra8JSWzG9jbYOtu44twAA5Xw"]
[Tue Jul 21 08:00:59.417801 2026] [security2:error] [pid 358661:tid 358801] [client 41.68.90.219:56386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RawlWhjQfpOo60_HF5QAAAAc"]
[Tue Jul 21 08:00:59.419171 2026] [security2:error] [pid 358661:tid 358801] [client 41.68.90.219:56386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RawlWhjQfpOo60_HF5QAAAAc"]
[Tue Jul 21 08:00:59.452537 2026] [security2:error] [pid 358661:tid 358745] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/api/settings"] [unique_id "al9RawlWhjQfpOo60_HF5gAAOlA"]
[Tue Jul 21 08:00:59.452720 2026] [security2:error] [pid 358661:tid 358852] [client 34.17.160.209:43104] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.institutocrismonteiro.com.br"] [uri "/api/settings"] [unique_id "al9RawlWhjQfpOo60_HF5gAAOlA"]
[Tue Jul 21 08:00:59.509498 2026] [security2:error] [pid 352421:tid 352579] [client 65.21.113.253:42424] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Ra8JSWzG9jbYOtu44sAAAAKE"]
[Tue Jul 21 08:00:59.530137 2026] [autoindex:error] [pid 352421:tid 352673] [client 129.226.195.146:50844] AH01276: Cannot serve directory /home2/rebe1126/rebecavivone.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:00:59.613221 2026] [security2:error] [pid 358661:tid 358790] [remote 173.252.70.0:45826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.70.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9RaglWhjQfpOo60_HFrQAAPX0"]
[Tue Jul 21 08:00:59.662996 2026] [security2:error] [pid 352421:tid 352437] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Ra8JSWzG9jbYOtu44uwAAow8"]
[Tue Jul 21 08:00:59.663149 2026] [security2:error] [pid 352421:tid 352581] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Ra8JSWzG9jbYOtu44uwAAow8"]
[Tue Jul 21 08:00:59.681196 2026] [security2:error] [pid 352421:tid 352456] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ra8JSWzG9jbYOtu44vAAA2SI"]
[Tue Jul 21 08:00:59.681465 2026] [security2:error] [pid 352421:tid 352635] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ra8JSWzG9jbYOtu44vAAA2SI"]
[Tue Jul 21 08:00:59.876044 2026] [qos:error] [pid 352421:tid 352538] [remote 57.141.18.41:29850] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.41, id=al9Ra8JSWzG9jbYOtu44wQAAjXQ
[Tue Jul 21 08:00:59.888941 2026] [security2:error] [pid 358661:tid 358849] [client 74.7.241.180:44884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lumerah.com.br"] [uri "/index.php"] [unique_id "al9RawlWhjQfpOo60_HF8AAANzM"], referer: https://www.lumerah.com.br/robots.txt
[Tue Jul 21 08:01:00.064921 2026] [qos:error] [pid 358661:tid 358770] [remote 57.141.18.29:22514] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.29, id=al9RbAlWhjQfpOo60_HGAgAAKWk
[Tue Jul 21 08:01:00.124342 2026] [security2:error] [pid 352421:tid 352624] [client 74.7.175.132:35578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lumerah.com.br"] [uri "/index.php"] [unique_id "al9Ra8JSWzG9jbYOtu44xgAAzjo"]
[Tue Jul 21 08:01:00.187844 2026] [qos:error] [pid 358661:tid 358679] [remote 57.141.18.120:22580] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.120, id=al9RbAlWhjQfpOo60_HGCgAAKA4
[Tue Jul 21 08:01:00.260702 2026] [security2:error] [pid 358661:tid 358792] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/phpinfo.php"] [unique_id "al9RbAlWhjQfpOo60_HGDgAAbn8"]
[Tue Jul 21 08:01:00.261201 2026] [security2:error] [pid 358661:tid 358746] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/info.php"] [unique_id "al9RbAlWhjQfpOo60_HGDAAAblE"]
[Tue Jul 21 08:01:00.380134 2026] [security2:error] [pid 358661:tid 358683] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/test.php"] [unique_id "al9RbAlWhjQfpOo60_HGEQAAQhI"]
[Tue Jul 21 08:01:00.383537 2026] [security2:error] [pid 358661:tid 358682] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/pi.php"] [unique_id "al9RbAlWhjQfpOo60_HGEgAAEhE"]
[Tue Jul 21 08:01:00.386131 2026] [security2:error] [pid 358661:tid 358891] [client 20.151.10.161:39925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/dejavu.php"] [unique_id "al9RbAlWhjQfpOo60_HGEwAAAGE"]
[Tue Jul 21 08:01:00.430368 2026] [security2:error] [pid 358661:tid 358801] [client 205.185.113.241:51952] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "www.nutrawidenews.com"] [uri "/"] [unique_id "al9RbAlWhjQfpOo60_HGFAAAAAc"]
[Tue Jul 21 08:01:00.461005 2026] [security2:error] [pid 358661:tid 358688] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/i.php"] [unique_id "al9RbAlWhjQfpOo60_HGFQAAKxc"]
[Tue Jul 21 08:01:00.491499 2026] [security2:error] [pid 358661:tid 358696] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "al9RbAlWhjQfpOo60_HGGAAAKx8"]
[Tue Jul 21 08:01:00.505749 2026] [qos:error] [pid 352421:tid 352425] [remote 57.141.18.79:42404] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.79, id=al9RbMJSWzG9jbYOtu440AAAygM
[Tue Jul 21 08:01:00.547832 2026] [security2:error] [pid 358661:tid 358668] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/app_dev.php"] [unique_id "al9RbAlWhjQfpOo60_HGGgAAewM"]
[Tue Jul 21 08:01:00.583808 2026] [security2:error] [pid 358661:tid 358874] [client 205.185.113.241:51954] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "www.nutrawidenews.com.oficialwebsite.com.br"] [uri "/"] [unique_id "al9RbAlWhjQfpOo60_HGHwAAAFA"]
[Tue Jul 21 08:01:00.654259 2026] [security2:error] [pid 352421:tid 352565] [client 20.197.192.193:42210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9RbMJSWzG9jbYOtu440QAAAJM"]
[Tue Jul 21 08:01:00.696796 2026] [security2:error] [pid 358661:tid 358710] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/server-status"] [unique_id "al9RbAlWhjQfpOo60_HGIAAAfC0"]
[Tue Jul 21 08:01:00.745364 2026] [security2:error] [pid 358661:tid 358725] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/server-info"] [unique_id "al9RbAlWhjQfpOo60_HGIwAAfDw"]
[Tue Jul 21 08:01:00.756089 2026] [security2:error] [pid 352421:tid 352448] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RbMJSWzG9jbYOtu440wAA7xo"]
[Tue Jul 21 08:01:00.756277 2026] [security2:error] [pid 352421:tid 352657] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RbMJSWzG9jbYOtu440wAA7xo"]
[Tue Jul 21 08:01:00.823669 2026] [security2:error] [pid 358661:tid 358862] [client 20.226.60.151:65436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/cong.php"] [unique_id "al9RbAlWhjQfpOo60_HGKQAAAEQ"]
[Tue Jul 21 08:01:00.829412 2026] [security2:error] [pid 352421:tid 352615] [client 175.144.82.48:56785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RbMJSWzG9jbYOtu441gAAAMU"]
[Tue Jul 21 08:01:00.830337 2026] [security2:error] [pid 352421:tid 352615] [client 175.144.82.48:56785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RbMJSWzG9jbYOtu441gAAAMU"]
[Tue Jul 21 08:01:00.876591 2026] [qos:error] [pid 352421:tid 352442] [remote 57.141.18.69:43114] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.69, id=al9RbMJSWzG9jbYOtu442AABARQ
[Tue Jul 21 08:01:01.067633 2026] [security2:error] [pid 358661:tid 358915] [client 74.249.245.134:17427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/403.php"] [unique_id "al9RbQlWhjQfpOo60_HGMwAAAHk"]
[Tue Jul 21 08:01:01.131151 2026] [security2:error] [pid 352421:tid 352577] [client 20.151.10.161:39895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/aaf.php"] [unique_id "al9RbcJSWzG9jbYOtu443AAAAJ8"]
[Tue Jul 21 08:01:01.240263 2026] [qos:error] [pid 352421:tid 352529] [remote 57.141.18.69:43116] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.69, id=al9RbcJSWzG9jbYOtu443QAAmms
[Tue Jul 21 08:01:01.318503 2026] [qos:error] [pid 352421:tid 352564] [client 162.241.63.68:58196] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9RbcJSWzG9jbYOtu443wAAAJI
[Tue Jul 21 08:01:01.562241 2026] [security2:error] [pid 352421:tid 352616] [client 20.104.96.117:46624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9RbcJSWzG9jbYOtu447QAAAMY"]
[Tue Jul 21 08:01:01.643118 2026] [security2:error] [pid 358661:tid 358854] [client 38.100.221.102:19000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RbQlWhjQfpOo60_HGQgAAADw"]
[Tue Jul 21 08:01:01.643242 2026] [security2:error] [pid 358661:tid 358854] [client 38.100.221.102:19000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RbQlWhjQfpOo60_HGQgAAADw"]
[Tue Jul 21 08:01:01.670464 2026] [security2:error] [pid 358661:tid 358826] [client 20.197.195.24:24142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9RbQlWhjQfpOo60_HGQwAAACA"]
[Tue Jul 21 08:01:01.755475 2026] [security2:error] [pid 352421:tid 352654] [client 223.236.153.128:4598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RbcJSWzG9jbYOtu448QAAAOw"]
[Tue Jul 21 08:01:01.755660 2026] [security2:error] [pid 352421:tid 352654] [client 223.236.153.128:4598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RbcJSWzG9jbYOtu448QAAAOw"]
[Tue Jul 21 08:01:01.930839 2026] [security2:error] [pid 358661:tid 358844] [client 20.151.10.161:39814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/term.php"] [unique_id "al9RbQlWhjQfpOo60_HGSQAAADI"]
[Tue Jul 21 08:01:02.089216 2026] [qos:error] [pid 358661:tid 358751] [remote 57.141.18.108:63428] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.108, id=al9RbglWhjQfpOo60_HGTwAARFY
[Tue Jul 21 08:01:02.176677 2026] [security2:error] [pid 352421:tid 352560] [client 202.143.127.214:65212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RbsJSWzG9jbYOtu45CQAAAI4"]
[Tue Jul 21 08:01:02.176803 2026] [security2:error] [pid 352421:tid 352560] [client 202.143.127.214:65212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RbsJSWzG9jbYOtu45CQAAAI4"]
[Tue Jul 21 08:01:02.224014 2026] [security2:error] [pid 358661:tid 358804] [client 136.144.33.101:28003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RbglWhjQfpOo60_HGVAAAAAo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:01:02.268102 2026] [security2:error] [pid 358661:tid 358822] [client 20.197.195.24:24139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/media.php"] [unique_id "al9RbglWhjQfpOo60_HGVQAAABw"]
[Tue Jul 21 08:01:02.328983 2026] [qos:error] [pid 358661:tid 358851] [client 162.241.63.68:58210] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9RbglWhjQfpOo60_HGVgAAADk
[Tue Jul 21 08:01:02.347972 2026] [qos:error] [pid 352421:tid 352591] [client 162.241.63.68:58234] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9RbsJSWzG9jbYOtu45GQAAAK0
[Tue Jul 21 08:01:02.681973 2026] [security2:error] [pid 358661:tid 358772] [remote 103.187.169.251:60906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-login.php"] [unique_id "al9RbglWhjQfpOo60_HGXgAANWs"]
[Tue Jul 21 08:01:02.724826 2026] [security2:error] [pid 358661:tid 358918] [client 20.151.10.161:39924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/ha.php"] [unique_id "al9RbglWhjQfpOo60_HGXwAAAHw"]
[Tue Jul 21 08:01:02.747936 2026] [security2:error] [pid 358661:tid 358919] [client 65.21.113.253:53154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RbglWhjQfpOo60_HGYAAAAH0"]
[Tue Jul 21 08:01:02.766391 2026] [security2:error] [pid 358661:tid 358836] [client 20.104.96.117:27104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/jj.php"] [unique_id "al9RbglWhjQfpOo60_HGYQAAACo"]
[Tue Jul 21 08:01:02.986049 2026] [security2:error] [pid 358661:tid 358804] [client 20.226.60.151:59971] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.lupipet.com"] [uri "/wp-includes/css/"] [unique_id "al9RbglWhjQfpOo60_HGaAAAAAo"]
[Tue Jul 21 08:01:03.189288 2026] [security2:error] [pid 352421:tid 352554] [client 117.247.80.59:16409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rb8JSWzG9jbYOtu45PQAAAIg"]
[Tue Jul 21 08:01:03.189405 2026] [security2:error] [pid 352421:tid 352554] [client 117.247.80.59:16409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rb8JSWzG9jbYOtu45PQAAAIg"]
[Tue Jul 21 08:01:03.606704 2026] [security2:error] [pid 352421:tid 352588] [client 20.151.10.161:39914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/hur.php"] [unique_id "al9Rb8JSWzG9jbYOtu45QwAAAKo"]
[Tue Jul 21 08:01:03.641796 2026] [security2:error] [pid 358661:tid 358862] [client 65.21.113.253:41754] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RbwlWhjQfpOo60_HGawAAAEQ"]
[Tue Jul 21 08:01:03.838537 2026] [qos:error] [pid 352421:tid 352522] [remote 57.141.18.109:28600] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.109, id=al9Rb8JSWzG9jbYOtu45SAAAo2Q
[Tue Jul 21 08:01:03.885387 2026] [security2:error] [pid 358661:tid 358813] [client 65.21.113.253:41766] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RbwlWhjQfpOo60_HGdAAAABM"]
[Tue Jul 21 08:01:03.895789 2026] [qos:error] [pid 358661:tid 358784] [remote 57.141.18.96:44316] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.96, id=al9RbwlWhjQfpOo60_HGegAAfXc
[Tue Jul 21 08:01:03.896127 2026] [security2:error] [pid 352421:tid 352576] [client 87.116.180.198:14021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rb8JSWzG9jbYOtu45SgAAAJ4"]
[Tue Jul 21 08:01:03.896219 2026] [security2:error] [pid 352421:tid 352576] [client 87.116.180.198:14021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rb8JSWzG9jbYOtu45SgAAAJ4"]
[Tue Jul 21 08:01:04.024057 2026] [qos:error] [pid 352421:tid 352447] [remote 57.141.18.74:43870] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.74, id=al9RcMJSWzG9jbYOtu45TgAA0xk
[Tue Jul 21 08:01:04.039949 2026] [security2:error] [pid 352421:tid 352612] [client 20.197.195.24:58489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/images.php"] [unique_id "al9RcMJSWzG9jbYOtu45TwAAAMI"]
[Tue Jul 21 08:01:04.133470 2026] [security2:error] [pid 352421:tid 352656] [client 106.215.181.8:18367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RcMJSWzG9jbYOtu45UgAAAO4"]
[Tue Jul 21 08:01:04.133633 2026] [security2:error] [pid 352421:tid 352656] [client 106.215.181.8:18367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RcMJSWzG9jbYOtu45UgAAAO4"]
[Tue Jul 21 08:01:04.208382 2026] [security2:error] [pid 358661:tid 358836] [client 109.60.28.94:54985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RcAlWhjQfpOo60_HGfQAAACo"]
[Tue Jul 21 08:01:04.208640 2026] [security2:error] [pid 358661:tid 358836] [client 109.60.28.94:54985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RcAlWhjQfpOo60_HGfQAAACo"]
[Tue Jul 21 08:01:04.403462 2026] [security2:error] [pid 352421:tid 352591] [client 20.104.96.117:46710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9RcMJSWzG9jbYOtu45aAAAAK0"]
[Tue Jul 21 08:01:04.429825 2026] [security2:error] [pid 358661:tid 358874] [client 103.78.200.11:49192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RcAlWhjQfpOo60_HGigAAAFA"]
[Tue Jul 21 08:01:04.430038 2026] [security2:error] [pid 358661:tid 358874] [client 103.78.200.11:49192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RcAlWhjQfpOo60_HGigAAAFA"]
[Tue Jul 21 08:01:04.703958 2026] [security2:error] [pid 352421:tid 352563] [client 74.249.245.134:5515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rqrconsultoria.com.br.rqracademy.com"] [uri "/api.php"] [unique_id "al9RcMJSWzG9jbYOtu45iwAAAJE"]
[Tue Jul 21 08:01:04.850627 2026] [qos:error] [pid 352421:tid 352458] [remote 57.141.18.7:58154] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.7, id=al9RcMJSWzG9jbYOtu45jAAAkiQ
[Tue Jul 21 08:01:04.895023 2026] [security2:error] [pid 358661:tid 358821] [client 103.86.117.203:63225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RcAlWhjQfpOo60_HGlAAAABs"]
[Tue Jul 21 08:01:04.895172 2026] [security2:error] [pid 358661:tid 358821] [client 103.86.117.203:63225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RcAlWhjQfpOo60_HGlAAAABs"]
[Tue Jul 21 08:01:04.976524 2026] [security2:error] [pid 358661:tid 358862] [client 20.151.10.161:39809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/h02ugyh.php"] [unique_id "al9RcAlWhjQfpOo60_HGmQAAAEQ"]
[Tue Jul 21 08:01:05.173049 2026] [security2:error] [pid 358661:tid 358696] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/wp-login.php"] [unique_id "al9RcAlWhjQfpOo60_HGmgAASh8"], referer: https://app.institutocrismonteiro.com.br/login
[Tue Jul 21 08:01:05.284262 2026] [security2:error] [pid 358661:tid 358700] [remote 34.17.160.209:43104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.160.17.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/wp-login.php"] [unique_id "al9RcQlWhjQfpOo60_HGoAAAHCM"], referer: https://app.institutocrismonteiro.com.br/wp-admin/
[Tue Jul 21 08:01:05.286527 2026] [qos:error] [pid 358661:tid 358700] [remote 57.141.18.121:20698] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.121, id=al9RcQlWhjQfpOo60_HGoQAAFiM
[Tue Jul 21 08:01:05.292625 2026] [security2:error] [pid 358661:tid 358916] [client 102.206.115.33:58649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RcQlWhjQfpOo60_HGogAAAHo"]
[Tue Jul 21 08:01:05.292843 2026] [security2:error] [pid 358661:tid 358916] [client 102.206.115.33:58649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RcQlWhjQfpOo60_HGogAAAHo"]
[Tue Jul 21 08:01:05.349531 2026] [security2:error] [pid 358661:tid 358857] [client 103.29.114.44:34667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RcQlWhjQfpOo60_HGowAAAD8"]
[Tue Jul 21 08:01:05.349741 2026] [security2:error] [pid 358661:tid 358857] [client 103.29.114.44:34667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RcQlWhjQfpOo60_HGowAAAD8"]
[Tue Jul 21 08:01:05.541766 2026] [http2:info] [pid 358661:tid 358826] [client 104.23.175.97:10768] AH10180: h2_stream(358661-217-1,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 08:01:05.744147 2026] [security2:error] [pid 358661:tid 358833] [client 20.151.10.161:39752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/seiso.php"] [unique_id "al9RcQlWhjQfpOo60_HGqQAAACc"]
[Tue Jul 21 08:01:05.752591 2026] [security2:error] [pid 358661:tid 358820] [client 20.197.195.24:58998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/gecko.php"] [unique_id "al9RcQlWhjQfpOo60_HGqgAAABo"]
[Tue Jul 21 08:01:06.260097 2026] [security2:error] [pid 352421:tid 352594] [client 20.197.195.24:58947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/82.php"] [unique_id "al9RcsJSWzG9jbYOtu45ygAAALA"]
[Tue Jul 21 08:01:06.376951 2026] [security2:error] [pid 352421:tid 352657] [client 130.210.6.241:60795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.6.210.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/wp-login.php"] [unique_id "al9RcsJSWzG9jbYOtu45zAAAAO8"], referer: https://wordpress.org/
[Tue Jul 21 08:01:06.406883 2026] [security2:error] [pid 358661:tid 358852] [client 20.151.10.161:39852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/155.php"] [unique_id "al9RcglWhjQfpOo60_HGwgAAADo"]
[Tue Jul 21 08:01:06.652386 2026] [http2:info] [pid 358661:tid 358806] [client 104.23.175.107:14038] AH10180: h2_stream(358661-221-1,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 08:01:06.655102 2026] [security2:error] [pid 358661:tid 358678] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RcglWhjQfpOo60_HGyAAAVw0"]
[Tue Jul 21 08:01:06.655357 2026] [security2:error] [pid 358661:tid 358881] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RcglWhjQfpOo60_HGyAAAVw0"]
[Tue Jul 21 08:01:06.675170 2026] [security2:error] [pid 352421:tid 352667] [client 122.164.127.47:51650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RcsJSWzG9jbYOtu45zgAAAPk"]
[Tue Jul 21 08:01:06.675305 2026] [security2:error] [pid 352421:tid 352667] [client 122.164.127.47:51650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RcsJSWzG9jbYOtu45zgAAAPk"]
[Tue Jul 21 08:01:06.961428 2026] [security2:error] [pid 352421:tid 352629] [client 136.144.33.97:62099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RcsJSWzG9jbYOtu451wAAANM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:01:07.144496 2026] [http2:info] [pid 358661:tid 358835] [client 104.23.175.97:10768] AH10180: h2_stream(358661-217-3,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 08:01:07.226532 2026] [security2:error] [pid 358661:tid 358804] [client 65.21.113.253:53154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RcwlWhjQfpOo60_HGzwAAAAo"]
[Tue Jul 21 08:01:07.231964 2026] [security2:error] [pid 358661:tid 358816] [client 20.226.60.151:59949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/public/css.php"] [unique_id "al9RcwlWhjQfpOo60_HG0gAAABY"]
[Tue Jul 21 08:01:07.248482 2026] [security2:error] [pid 358661:tid 358863] [client 103.166.103.129:64174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RcwlWhjQfpOo60_HG1AAAAEU"]
[Tue Jul 21 08:01:07.248579 2026] [security2:error] [pid 358661:tid 358863] [client 103.166.103.129:64174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RcwlWhjQfpOo60_HG1AAAAEU"]
[Tue Jul 21 08:01:07.279949 2026] [security2:error] [pid 352421:tid 352555] [client 130.210.6.241:60881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.6.210.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/wp-login.php"] [unique_id "al9Rc8JSWzG9jbYOtu45-gAAAIk"], referer: https://www.google.com/
[Tue Jul 21 08:01:07.473712 2026] [security2:error] [pid 358661:tid 358813] [client 20.197.195.24:24137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/admin.php"] [unique_id "al9RcwlWhjQfpOo60_HG2AAAABM"]
[Tue Jul 21 08:01:07.496305 2026] [security2:error] [pid 358661:tid 358919] [client 20.104.96.117:46632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/txets.php"] [unique_id "al9RcwlWhjQfpOo60_HG2QAAAH0"]
[Tue Jul 21 08:01:07.604579 2026] [http2:info] [pid 358661:tid 358803] [client 104.23.175.107:14038] AH10180: h2_stream(358661-221-3,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 08:01:07.610296 2026] [security2:error] [pid 358661:tid 358748] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RcwlWhjQfpOo60_HG3QAATFM"]
[Tue Jul 21 08:01:07.610433 2026] [security2:error] [pid 358661:tid 358870] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RcwlWhjQfpOo60_HG3QAATFM"]
[Tue Jul 21 08:01:07.687132 2026] [security2:error] [pid 358661:tid 358921] [client 122.179.91.63:21999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RcwlWhjQfpOo60_HG3gAAAH8"]
[Tue Jul 21 08:01:07.687302 2026] [security2:error] [pid 358661:tid 358921] [client 122.179.91.63:21999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RcwlWhjQfpOo60_HG3gAAAH8"]
[Tue Jul 21 08:01:07.712081 2026] [security2:error] [pid 358661:tid 358836] [client 20.151.10.161:39837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/ppp.php"] [unique_id "al9RcwlWhjQfpOo60_HG3wAAACo"]
[Tue Jul 21 08:01:07.765217 2026] [security2:error] [pid 358661:tid 358902] [client 20.226.60.151:59951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/output.php"] [unique_id "al9RcwlWhjQfpOo60_HG4QAAAGw"]
[Tue Jul 21 08:01:07.815110 2026] [security2:error] [pid 358661:tid 358867] [client 20.226.60.151:60007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-file-120.php"] [unique_id "al9RcwlWhjQfpOo60_HG5AAAAEk"]
[Tue Jul 21 08:01:07.857013 2026] [security2:error] [pid 358661:tid 358906] [client 65.21.113.253:41754] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RcwlWhjQfpOo60_HG1wAAAHA"]
[Tue Jul 21 08:01:08.084907 2026] [http2:info] [pid 358661:tid 358877] [client 104.23.175.97:10768] AH10180: h2_stream(358661-217-5,IDLE): Request header exceeds LimitRequestFieldSize(8190): cookie
[Tue Jul 21 08:01:08.387133 2026] [security2:error] [pid 352421:tid 352621] [client 182.8.255.181:17298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RdMJSWzG9jbYOtu46CQAAAMs"]
[Tue Jul 21 08:01:08.387264 2026] [security2:error] [pid 352421:tid 352621] [client 182.8.255.181:17298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RdMJSWzG9jbYOtu46CQAAAMs"]
[Tue Jul 21 08:01:08.503300 2026] [security2:error] [pid 358661:tid 358802] [client 20.226.60.151:16009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/special.php"] [unique_id "al9RdAlWhjQfpOo60_HG7QAAAAg"]
[Tue Jul 21 08:01:08.580304 2026] [security2:error] [pid 358661:tid 358820] [client 20.151.10.161:39906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/201.php"] [unique_id "al9RdAlWhjQfpOo60_HG7gAAABo"]
[Tue Jul 21 08:01:08.699224 2026] [security2:error] [pid 358661:tid 358862] [client 204.8.98.45:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9RdAlWhjQfpOo60_HG8QAAAEQ"]
[Tue Jul 21 08:01:08.699333 2026] [security2:error] [pid 358661:tid 358862] [client 204.8.98.45:53622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9RdAlWhjQfpOo60_HG8QAAAEQ"]
[Tue Jul 21 08:01:08.911152 2026] [security2:error] [pid 358661:tid 358878] [client 178.153.91.96:20221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RdAlWhjQfpOo60_HG9AAAAFQ"]
[Tue Jul 21 08:01:08.911272 2026] [security2:error] [pid 358661:tid 358878] [client 178.153.91.96:20221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RdAlWhjQfpOo60_HG9AAAAFQ"]
[Tue Jul 21 08:01:09.065295 2026] [security2:error] [pid 358661:tid 358835] [client 20.104.96.117:27102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/dex.php"] [unique_id "al9RdQlWhjQfpOo60_HG9gAAACk"]
[Tue Jul 21 08:01:09.213724 2026] [security2:error] [pid 352421:tid 352613] [client 20.151.10.161:39902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/ops.php"] [unique_id "al9RdcJSWzG9jbYOtu46JgAAAMM"]
[Tue Jul 21 08:01:09.258862 2026] [security2:error] [pid 358661:tid 358717] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RdQlWhjQfpOo60_HG-AAAcjQ"]
[Tue Jul 21 08:01:09.259194 2026] [security2:error] [pid 358661:tid 358908] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RdQlWhjQfpOo60_HG-AAAcjQ"]
[Tue Jul 21 08:01:09.265161 2026] [security2:error] [pid 352421:tid 352594] [client 117.210.135.0:50679] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RdcJSWzG9jbYOtu46LAAAALA"]
[Tue Jul 21 08:01:09.265421 2026] [security2:error] [pid 352421:tid 352594] [client 117.210.135.0:50679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RdcJSWzG9jbYOtu46LAAAALA"]
[Tue Jul 21 08:01:09.297906 2026] [security2:error] [pid 358661:tid 358851] [client 20.197.195.24:24172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/adminner.php"] [unique_id "al9RdQlWhjQfpOo60_HG-QAAADk"]
[Tue Jul 21 08:01:09.455103 2026] [security2:error] [pid 352421:tid 352624] [client 65.21.113.253:41776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RdMJSWzG9jbYOtu46EAAAAM4"]
[Tue Jul 21 08:01:09.523217 2026] [security2:error] [pid 358661:tid 358821] [client 20.226.60.151:60002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/as.php"] [unique_id "al9RdQlWhjQfpOo60_HHAAAAABs"]
[Tue Jul 21 08:01:09.590131 2026] [security2:error] [pid 358661:tid 358802] [client 92.119.178.3:43012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9RdQlWhjQfpOo60_HHAQAAAAg"]
[Tue Jul 21 08:01:09.590218 2026] [security2:error] [pid 358661:tid 358802] [client 92.119.178.3:43012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9RdQlWhjQfpOo60_HHAQAAAAg"]
[Tue Jul 21 08:01:09.834965 2026] [security2:error] [pid 358661:tid 358889] [client 130.210.6.241:61123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.6.210.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/wp-login.php"] [unique_id "al9RdQlWhjQfpOo60_HHAwAAAF8"]
[Tue Jul 21 08:01:10.016300 2026] [security2:error] [pid 352421:tid 352582] [client 41.68.90.219:56865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RdsJSWzG9jbYOtu46PwAAAKQ"]
[Tue Jul 21 08:01:10.016491 2026] [security2:error] [pid 352421:tid 352582] [client 41.68.90.219:56865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RdsJSWzG9jbYOtu46PwAAAKQ"]
[Tue Jul 21 08:01:10.033178 2026] [security2:error] [pid 352421:tid 352449] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RdsJSWzG9jbYOtu46QAAAshs"]
[Tue Jul 21 08:01:10.033381 2026] [security2:error] [pid 352421:tid 352596] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RdsJSWzG9jbYOtu46QAAAshs"]
[Tue Jul 21 08:01:10.051282 2026] [security2:error] [pid 352421:tid 352622] [client 20.151.10.161:39922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/ingfo.php"] [unique_id "al9RdsJSWzG9jbYOtu46QgAAAMw"]
[Tue Jul 21 08:01:10.181840 2026] [security2:error] [pid 358661:tid 358745] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RdglWhjQfpOo60_HHBwAARFA"]
[Tue Jul 21 08:01:10.181982 2026] [security2:error] [pid 358661:tid 358862] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RdglWhjQfpOo60_HHBwAARFA"]
[Tue Jul 21 08:01:10.195543 2026] [security2:error] [pid 358661:tid 358747] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RdglWhjQfpOo60_HHCAAAB1I"]
[Tue Jul 21 08:01:10.195729 2026] [security2:error] [pid 358661:tid 358801] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RdglWhjQfpOo60_HHCAAAB1I"]
[Tue Jul 21 08:01:10.250721 2026] [security2:error] [pid 358661:tid 358907] [client 38.100.221.102:18406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RdglWhjQfpOo60_HHCQAAAHE"]
[Tue Jul 21 08:01:10.250867 2026] [security2:error] [pid 358661:tid 358907] [client 38.100.221.102:18406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RdglWhjQfpOo60_HHCQAAAHE"]
[Tue Jul 21 08:01:10.501123 2026] [security2:error] [pid 358661:tid 358804] [client 20.151.10.161:39909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/error_log.php"] [unique_id "al9RdglWhjQfpOo60_HHDwAAAAo"]
[Tue Jul 21 08:01:10.751323 2026] [security2:error] [pid 358661:tid 358863] [client 20.197.195.24:24148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/admin.php"] [unique_id "al9RdglWhjQfpOo60_HHFQAAAEU"]
[Tue Jul 21 08:01:10.844368 2026] [security2:error] [pid 358661:tid 358904] [client 173.252.95.41:38476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9RdglWhjQfpOo60_HHFgAAAG4"]
[Tue Jul 21 08:01:10.889373 2026] [security2:error] [pid 358661:tid 358812] [client 20.197.195.24:11087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/k.php"] [unique_id "al9RdglWhjQfpOo60_HHGAAAABI"]
[Tue Jul 21 08:01:11.011141 2026] [security2:error] [pid 352421:tid 352616] [client 20.226.60.151:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/cgi-bin/index.php"] [unique_id "al9Rd8JSWzG9jbYOtu46fAAAAMY"]
[Tue Jul 21 08:01:11.305054 2026] [security2:error] [pid 358661:tid 358907] [client 20.151.10.161:39819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/xenon1337.php"] [unique_id "al9RdwlWhjQfpOo60_HHKgAAAHE"]
[Tue Jul 21 08:01:11.429928 2026] [security2:error] [pid 358661:tid 358806] [client 193.36.225.61:34777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RdwlWhjQfpOo60_HHLQAAAAw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:01:11.458281 2026] [security2:error] [pid 358661:tid 358749] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RdwlWhjQfpOo60_HHLgAAW1Q"]
[Tue Jul 21 08:01:11.458392 2026] [security2:error] [pid 358661:tid 358885] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RdwlWhjQfpOo60_HHLgAAW1Q"]
[Tue Jul 21 08:01:12.076599 2026] [security2:error] [pid 358661:tid 358853] [client 20.151.10.161:39861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/test11.php"] [unique_id "al9ReAlWhjQfpOo60_HHNQAAADs"]
[Tue Jul 21 08:01:12.086834 2026] [security2:error] [pid 358661:tid 358772] [remote 69.5.20.170:35328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.20.5.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ReAlWhjQfpOo60_HHNgAAcms"]
[Tue Jul 21 08:01:12.240905 2026] [security2:error] [pid 352421:tid 352673] [client 223.236.153.128:2965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9ReMJSWzG9jbYOtu46ogAAAP8"]
[Tue Jul 21 08:01:12.245606 2026] [security2:error] [pid 352421:tid 352673] [client 223.236.153.128:2965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9ReMJSWzG9jbYOtu46ogAAAP8"]
[Tue Jul 21 08:01:12.442231 2026] [security2:error] [pid 352421:tid 352631] [client 20.197.195.24:58488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/blurbs.php"] [unique_id "al9ReMJSWzG9jbYOtu46pgAAANU"]
[Tue Jul 21 08:01:12.484212 2026] [security2:error] [pid 358661:tid 358787] [remote 217.182.128.41:45552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9ReAlWhjQfpOo60_HHOAAAbno"]
[Tue Jul 21 08:01:12.916069 2026] [security2:error] [pid 352421:tid 352677] [client 20.226.60.151:59954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/w1px.php"] [unique_id "al9ReMJSWzG9jbYOtu46tgAAAQM"]
[Tue Jul 21 08:01:13.197156 2026] [security2:error] [pid 358661:tid 358817] [client 202.143.127.214:49297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ReQlWhjQfpOo60_HHPQAAABc"]
[Tue Jul 21 08:01:13.197326 2026] [security2:error] [pid 358661:tid 358817] [client 202.143.127.214:49297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ReQlWhjQfpOo60_HHPQAAABc"]
[Tue Jul 21 08:01:13.350805 2026] [security2:error] [pid 352421:tid 352668] [client 20.104.96.117:46648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/xpwer1.php"] [unique_id "al9RecJSWzG9jbYOtu46zwAAAPo"]
[Tue Jul 21 08:01:13.409449 2026] [security2:error] [pid 358661:tid 358844] [client 20.151.10.161:39900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/koala.php"] [unique_id "al9ReQlWhjQfpOo60_HHQAAAADI"]
[Tue Jul 21 08:01:13.687124 2026] [security2:error] [pid 352421:tid 352579] [client 65.21.113.253:41776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RecJSWzG9jbYOtu46wQAAAKE"]
[Tue Jul 21 08:01:14.048249 2026] [security2:error] [pid 358661:tid 358861] [client 120.56.162.40:57732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RdwlWhjQfpOo60_HHMAAAAEM"]
[Tue Jul 21 08:01:14.096375 2026] [security2:error] [pid 358661:tid 358867] [client 117.247.80.59:16876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ReglWhjQfpOo60_HHVwAAAEk"]
[Tue Jul 21 08:01:14.096540 2026] [security2:error] [pid 358661:tid 358867] [client 117.247.80.59:16876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ReglWhjQfpOo60_HHVwAAAEk"]
[Tue Jul 21 08:01:14.164499 2026] [security2:error] [pid 358661:tid 358862] [client 20.197.195.24:58478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/bajah.php"] [unique_id "al9ReglWhjQfpOo60_HHWwAAAEQ"]
[Tue Jul 21 08:01:14.407712 2026] [security2:error] [pid 358661:tid 358835] [client 20.151.10.161:39836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/mac.php"] [unique_id "al9ReglWhjQfpOo60_HHcAAAACk"]
[Tue Jul 21 08:01:14.419021 2026] [security2:error] [pid 352421:tid 352645] [client 175.144.82.48:57233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ResJSWzG9jbYOtu463wAAAOM"]
[Tue Jul 21 08:01:14.419779 2026] [security2:error] [pid 352421:tid 352645] [client 175.144.82.48:57233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ResJSWzG9jbYOtu463wAAAOM"]
[Tue Jul 21 08:01:14.559407 2026] [security2:error] [pid 352421:tid 352624] [client 87.116.180.198:14074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ResJSWzG9jbYOtu464QAAAM4"]
[Tue Jul 21 08:01:14.559533 2026] [security2:error] [pid 352421:tid 352624] [client 87.116.180.198:14074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ResJSWzG9jbYOtu464QAAAM4"]
[Tue Jul 21 08:01:14.586617 2026] [security2:error] [pid 358661:tid 358873] [client 20.226.60.151:59968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/yawa.php"] [unique_id "al9ReglWhjQfpOo60_HHhAAAAE8"]
[Tue Jul 21 08:01:14.662533 2026] [security2:error] [pid 358661:tid 358853] [client 65.21.113.253:60266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9ReglWhjQfpOo60_HHiwAAADs"]
[Tue Jul 21 08:01:14.894768 2026] [security2:error] [pid 358661:tid 358921] [client 106.215.181.8:3125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ReglWhjQfpOo60_HHoAAAAH8"]
[Tue Jul 21 08:01:14.894873 2026] [security2:error] [pid 358661:tid 358921] [client 106.215.181.8:3125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ReglWhjQfpOo60_HHoAAAAH8"]
[Tue Jul 21 08:01:15.195418 2026] [security2:error] [pid 358661:tid 358879] [client 109.60.28.94:55645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RewlWhjQfpOo60_HHrQAAAFU"]
[Tue Jul 21 08:01:15.195641 2026] [security2:error] [pid 358661:tid 358879] [client 109.60.28.94:55645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RewlWhjQfpOo60_HHrQAAAFU"]
[Tue Jul 21 08:01:15.369117 2026] [security2:error] [pid 352421:tid 352657] [client 20.151.10.161:39761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9Re8JSWzG9jbYOtu468gAAAO8"]
[Tue Jul 21 08:01:15.382110 2026] [security2:error] [pid 358661:tid 358816] [client 103.86.117.203:63772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RewlWhjQfpOo60_HHtQAAABY"]
[Tue Jul 21 08:01:15.382248 2026] [security2:error] [pid 358661:tid 358816] [client 103.86.117.203:63772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RewlWhjQfpOo60_HHtQAAABY"]
[Tue Jul 21 08:01:15.396627 2026] [security2:error] [pid 352421:tid 352565] [client 65.21.113.253:41776] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ResJSWzG9jbYOtu466AAAAJM"]
[Tue Jul 21 08:01:15.461091 2026] [security2:error] [pid 352421:tid 352442] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9Re8JSWzG9jbYOtu468QAAhhQ"]
[Tue Jul 21 08:01:15.461372 2026] [security2:error] [pid 352421:tid 352552] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9Re8JSWzG9jbYOtu468QAAhhQ"]
[Tue Jul 21 08:01:15.477350 2026] [security2:error] [pid 358661:tid 358916] [client 20.197.195.24:24080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/a.php"] [unique_id "al9RewlWhjQfpOo60_HHtwAAAHo"]
[Tue Jul 21 08:01:15.510199 2026] [security2:error] [pid 358661:tid 358907] [client 103.78.200.11:49680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RewlWhjQfpOo60_HHuAAAAHE"]
[Tue Jul 21 08:01:15.510333 2026] [security2:error] [pid 358661:tid 358907] [client 103.78.200.11:49680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RewlWhjQfpOo60_HHuAAAAHE"]
[Tue Jul 21 08:01:15.615380 2026] [security2:error] [pid 358661:tid 358863] [client 20.226.60.151:59931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/js.php"] [unique_id "al9RewlWhjQfpOo60_HHuQAAAEU"]
[Tue Jul 21 08:01:15.790426 2026] [security2:error] [pid 358661:tid 358836] [client 102.206.115.33:58826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RewlWhjQfpOo60_HHwQAAACo"]
[Tue Jul 21 08:01:15.790530 2026] [security2:error] [pid 358661:tid 358836] [client 102.206.115.33:58826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RewlWhjQfpOo60_HHwQAAACo"]
[Tue Jul 21 08:01:15.955318 2026] [security2:error] [pid 358661:tid 358852] [client 148.113.128.190:38496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "cromosolucoes.com.br"] [uri "/robots.txt"] [unique_id "al9RewlWhjQfpOo60_HHwwAAADo"]
[Tue Jul 21 08:01:15.955450 2026] [security2:error] [pid 358661:tid 358852] [client 148.113.128.190:38496] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cromosolucoes.com.br"] [uri "/robots.txt"] [unique_id "al9RewlWhjQfpOo60_HHwwAAADo"]
[Tue Jul 21 08:01:15.977712 2026] [security2:error] [pid 358661:tid 358876] [client 103.29.114.44:59593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RewlWhjQfpOo60_HHxwAAAFI"]
[Tue Jul 21 08:01:15.977832 2026] [security2:error] [pid 358661:tid 358876] [client 103.29.114.44:59593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RewlWhjQfpOo60_HHxwAAAFI"]
[Tue Jul 21 08:01:16.132752 2026] [security2:error] [pid 358661:tid 358830] [client 136.144.33.111:59757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RewlWhjQfpOo60_HHxQAAACQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:01:16.170839 2026] [security2:error] [pid 352421:tid 352616] [client 20.226.60.151:60008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/core.php"] [unique_id "al9RfMJSWzG9jbYOtu46-wAAAMY"]
[Tue Jul 21 08:01:16.369938 2026] [security2:error] [pid 358661:tid 358847] [client 20.197.195.24:58479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/edit.php"] [unique_id "al9RfAlWhjQfpOo60_HHzQAAADU"]
[Tue Jul 21 08:01:16.885906 2026] [security2:error] [pid 352421:tid 352652] [client 20.151.10.161:39847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wefile.php"] [unique_id "al9RfMJSWzG9jbYOtu47CQAAAOo"]
[Tue Jul 21 08:01:16.979433 2026] [security2:error] [pid 358661:tid 358834] [client 20.197.195.24:58449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/hosty.php"] [unique_id "al9RfAlWhjQfpOo60_HH0wAAACg"]
[Tue Jul 21 08:01:16.981381 2026] [lsapi:error] [pid 358661:tid 358801] [client 52.167.144.166:0] [host www.roanalacerda.com.br] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1608; user ID 1608), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Tue Jul 21 08:01:17.194154 2026] [security2:error] [pid 352421:tid 352672] [client 65.21.113.253:59814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RfMJSWzG9jbYOtu47BgAAAP4"]
[Tue Jul 21 08:01:17.197092 2026] [security2:error] [pid 358661:tid 358826] [client 122.164.127.47:52239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RfQlWhjQfpOo60_HH1gAAACA"]
[Tue Jul 21 08:01:17.215804 2026] [security2:error] [pid 358661:tid 358826] [client 122.164.127.47:52239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RfQlWhjQfpOo60_HH1gAAACA"]
[Tue Jul 21 08:01:17.550453 2026] [security2:error] [pid 352421:tid 352601] [client 20.226.60.151:16017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/19.php"] [unique_id "al9RfcJSWzG9jbYOtu47EQAAALc"]
[Tue Jul 21 08:01:17.605767 2026] [security2:error] [pid 358661:tid 358670] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RfQlWhjQfpOo60_HH3wAABQU"]
[Tue Jul 21 08:01:17.605926 2026] [security2:error] [pid 358661:tid 358799] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RfQlWhjQfpOo60_HH3wAABQU"]
[Tue Jul 21 08:01:17.859022 2026] [security2:error] [pid 358661:tid 358879] [client 65.21.113.253:60266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RfQlWhjQfpOo60_HH5AAAAFU"]
[Tue Jul 21 08:01:17.998160 2026] [security2:error] [pid 352421:tid 352635] [client 103.166.103.129:10157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RfcJSWzG9jbYOtu47GQAAANk"]
[Tue Jul 21 08:01:17.998257 2026] [security2:error] [pid 352421:tid 352635] [client 103.166.103.129:10157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RfcJSWzG9jbYOtu47GQAAANk"]
[Tue Jul 21 08:01:18.158947 2026] [security2:error] [pid 358661:tid 358877] [client 20.197.195.24:59004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/k.php"] [unique_id "al9RfglWhjQfpOo60_HH6QAAAFM"]
[Tue Jul 21 08:01:18.187976 2026] [security2:error] [pid 358661:tid 358828] [client 122.179.91.63:10755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RfglWhjQfpOo60_HH6gAAACI"]
[Tue Jul 21 08:01:18.188148 2026] [security2:error] [pid 358661:tid 358828] [client 122.179.91.63:10755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RfglWhjQfpOo60_HH6gAAACI"]
[Tue Jul 21 08:01:18.250684 2026] [security2:error] [pid 358661:tid 358831] [client 20.226.60.151:60006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/inc.php"] [unique_id "al9RfglWhjQfpOo60_HH6wAAACU"]
[Tue Jul 21 08:01:18.461357 2026] [security2:error] [pid 358661:tid 358804] [client 20.104.96.117:27114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/flox.php"] [unique_id "al9RfglWhjQfpOo60_HH8AAAAAo"]
[Tue Jul 21 08:01:18.694589 2026] [security2:error] [pid 352421:tid 352570] [client 65.21.113.253:59824] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RfsJSWzG9jbYOtu47HgAAAJg"]
[Tue Jul 21 08:01:18.770297 2026] [security2:error] [pid 352421:tid 352566] [client 182.8.255.181:21110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RfsJSWzG9jbYOtu47IAAAAJQ"]
[Tue Jul 21 08:01:18.770414 2026] [security2:error] [pid 352421:tid 352566] [client 182.8.255.181:21110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RfsJSWzG9jbYOtu47IAAAAJQ"]
[Tue Jul 21 08:01:18.799262 2026] [security2:error] [pid 352421:tid 352621] [client 20.226.60.151:59937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-ppoxua4.php"] [unique_id "al9RfsJSWzG9jbYOtu47JAAAAMs"]
[Tue Jul 21 08:01:18.966478 2026] [security2:error] [pid 352421:tid 352491] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RfsJSWzG9jbYOtu47KAAAmUU"]
[Tue Jul 21 08:01:18.966726 2026] [security2:error] [pid 352421:tid 352571] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RfsJSWzG9jbYOtu47KAAAmUU"]
[Tue Jul 21 08:01:19.245550 2026] [security2:error] [pid 352421:tid 352623] [client 20.226.60.151:59970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-u3nxbvx.php"] [unique_id "al9Rf8JSWzG9jbYOtu47KwAAAM0"]
[Tue Jul 21 08:01:19.373006 2026] [security2:error] [pid 352421:tid 352455] [remote 188.95.113.76:51642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9Rf8JSWzG9jbYOtu47LgAAwCE"]
[Tue Jul 21 08:01:19.373286 2026] [security2:error] [pid 352421:tid 352610] [client 188.95.113.76:51642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9Rf8JSWzG9jbYOtu47LgAAwCE"]
[Tue Jul 21 08:01:19.377143 2026] [security2:error] [pid 352421:tid 352667] [client 20.197.195.24:58982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/aaa.php"] [unique_id "al9Rf8JSWzG9jbYOtu47MAAAAPk"]
[Tue Jul 21 08:01:19.400918 2026] [security2:error] [pid 352421:tid 352607] [client 65.21.113.253:59814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RfsJSWzG9jbYOtu47JgAAAL0"]
[Tue Jul 21 08:01:19.440786 2026] [security2:error] [pid 358661:tid 358889] [client 178.153.91.96:60034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RfwlWhjQfpOo60_HH_AAAAF8"]
[Tue Jul 21 08:01:19.440909 2026] [security2:error] [pid 358661:tid 358889] [client 178.153.91.96:60034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RfwlWhjQfpOo60_HH_AAAAF8"]
[Tue Jul 21 08:01:19.811094 2026] [security2:error] [pid 358661:tid 358862] [client 20.226.60.151:60005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/ss.php"] [unique_id "al9RfwlWhjQfpOo60_HIAAAAAEQ"]
[Tue Jul 21 08:01:19.834287 2026] [security2:error] [pid 358661:tid 358788] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RfwlWhjQfpOo60_HIAQAAF3s"]
[Tue Jul 21 08:01:19.834477 2026] [security2:error] [pid 358661:tid 358817] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RfwlWhjQfpOo60_HIAQAAF3s"]
[Tue Jul 21 08:01:19.973853 2026] [security2:error] [pid 358661:tid 358828] [client 20.151.10.161:39759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9RfwlWhjQfpOo60_HICgAAACI"]
[Tue Jul 21 08:01:20.143021 2026] [security2:error] [pid 358661:tid 358908] [client 117.210.135.0:51388] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RgAlWhjQfpOo60_HIDQAAAHI"]
[Tue Jul 21 08:01:20.143156 2026] [security2:error] [pid 358661:tid 358908] [client 117.210.135.0:51388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RgAlWhjQfpOo60_HIDQAAAHI"]
[Tue Jul 21 08:01:20.436218 2026] [security2:error] [pid 352421:tid 352663] [client 41.68.90.219:57342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RgMJSWzG9jbYOtu47OwAAAPU"]
[Tue Jul 21 08:01:20.437158 2026] [security2:error] [pid 352421:tid 352663] [client 41.68.90.219:57342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RgMJSWzG9jbYOtu47OwAAAPU"]
[Tue Jul 21 08:01:20.601290 2026] [security2:error] [pid 358661:tid 358868] [client 37.140.223.69:38247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RgAlWhjQfpOo60_HIEgAAAEo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:01:20.623811 2026] [security2:error] [pid 358661:tid 358794] [client 20.197.192.193:48898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/dp.php"] [unique_id "al9RgAlWhjQfpOo60_HIEwAAAAA"]
[Tue Jul 21 08:01:20.676200 2026] [security2:error] [pid 358661:tid 358700] [remote 199.189.225.40:52355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/wp-login.php"] [unique_id "al9RgAlWhjQfpOo60_HIFAAAcSM"]
[Tue Jul 21 08:01:20.686312 2026] [security2:error] [pid 358661:tid 358910] [client 38.100.221.102:17802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RgAlWhjQfpOo60_HIFQAAAHQ"]
[Tue Jul 21 08:01:20.686422 2026] [security2:error] [pid 358661:tid 358910] [client 38.100.221.102:17802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RgAlWhjQfpOo60_HIFQAAAHQ"]
[Tue Jul 21 08:01:20.719317 2026] [security2:error] [pid 358661:tid 358725] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RgAlWhjQfpOo60_HIFwAABzw"]
[Tue Jul 21 08:01:20.719471 2026] [security2:error] [pid 358661:tid 358801] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RgAlWhjQfpOo60_HIFwAABzw"]
[Tue Jul 21 08:01:20.739258 2026] [security2:error] [pid 352421:tid 352505] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RgMJSWzG9jbYOtu47PwAA_lM"]
[Tue Jul 21 08:01:20.739383 2026] [security2:error] [pid 352421:tid 352672] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RgMJSWzG9jbYOtu47PwAA_lM"]
[Tue Jul 21 08:01:20.900129 2026] [security2:error] [pid 358661:tid 358892] [client 20.226.60.151:65412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/min.php"] [unique_id "al9RgAlWhjQfpOo60_HIGAAAAGI"]
[Tue Jul 21 08:01:20.959082 2026] [security2:error] [pid 352421:tid 352648] [client 20.197.195.24:58476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/file5.php"] [unique_id "al9RgMJSWzG9jbYOtu47RAAAAOY"]
[Tue Jul 21 08:01:21.158684 2026] [security2:error] [pid 358661:tid 358879] [client 20.197.192.193:42191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/old.php"] [unique_id "al9RgQlWhjQfpOo60_HIHwAAAFU"]
[Tue Jul 21 08:01:21.204885 2026] [autoindex:error] [pid 358661:tid 358850] [client 98.91.173.173:8363] AH01276: Cannot serve directory /home2/acupu265/mkt.acupunturaebemestar.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:21.212203 2026] [security2:error] [pid 358661:tid 358817] [client 20.197.192.193:42230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/ms-new.php"] [unique_id "al9RgQlWhjQfpOo60_HIIgAAABc"]
[Tue Jul 21 08:01:21.348475 2026] [security2:error] [pid 358661:tid 358856] [client 20.104.96.117:46716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/popo.php"] [unique_id "al9RgQlWhjQfpOo60_HIJQAAAD4"]
[Tue Jul 21 08:01:21.397377 2026] [security2:error] [pid 358661:tid 358816] [client 20.197.192.193:41594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/track.php"] [unique_id "al9RgQlWhjQfpOo60_HIJwAAABY"]
[Tue Jul 21 08:01:21.464827 2026] [security2:error] [pid 358661:tid 358802] [client 20.197.192.193:41589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/2352356666.php"] [unique_id "al9RgQlWhjQfpOo60_HIKwAAAAg"]
[Tue Jul 21 08:01:21.507156 2026] [security2:error] [pid 358661:tid 358851] [client 20.197.192.193:41568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/pn.php"] [unique_id "al9RgQlWhjQfpOo60_HILAAAADk"]
[Tue Jul 21 08:01:21.508829 2026] [security2:error] [pid 358661:tid 358823] [client 20.151.10.161:39876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/2P.php"] [unique_id "al9RgQlWhjQfpOo60_HILQAAAB0"]
[Tue Jul 21 08:01:21.552724 2026] [security2:error] [pid 358661:tid 358902] [client 20.197.192.193:41567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/wp-wpbak.php"] [unique_id "al9RgQlWhjQfpOo60_HILgAAAGw"]
[Tue Jul 21 08:01:21.574990 2026] [security2:error] [pid 358661:tid 358804] [client 20.197.192.193:41572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/dr.php"] [unique_id "al9RgQlWhjQfpOo60_HILwAAAAo"]
[Tue Jul 21 08:01:21.656707 2026] [security2:error] [pid 352421:tid 352651] [client 20.197.192.193:42193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/2x.php"] [unique_id "al9RgcJSWzG9jbYOtu47SgAAAOk"]
[Tue Jul 21 08:01:21.729574 2026] [security2:error] [pid 358661:tid 358794] [client 20.197.192.193:42233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/kq1.php"] [unique_id "al9RgQlWhjQfpOo60_HIMAAAAAA"]
[Tue Jul 21 08:01:21.774172 2026] [security2:error] [pid 352421:tid 352631] [client 20.197.192.193:48922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/zzz.php"] [unique_id "al9RgcJSWzG9jbYOtu47TgAAANU"]
[Tue Jul 21 08:01:21.779060 2026] [security2:error] [pid 358661:tid 358810] [client 175.144.82.48:57616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RgQlWhjQfpOo60_HIMQAAABA"]
[Tue Jul 21 08:01:21.779610 2026] [security2:error] [pid 358661:tid 358810] [client 175.144.82.48:57616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RgQlWhjQfpOo60_HIMQAAABA"]
[Tue Jul 21 08:01:21.840102 2026] [security2:error] [pid 352421:tid 352605] [client 20.226.60.151:60030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9RgcJSWzG9jbYOtu47UAAAALs"]
[Tue Jul 21 08:01:21.914303 2026] [security2:error] [pid 352421:tid 352614] [client 20.197.195.24:24131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/222.php"] [unique_id "al9RgcJSWzG9jbYOtu47VAAAAMQ"]
[Tue Jul 21 08:01:21.930729 2026] [security2:error] [pid 352421:tid 352644] [client 20.197.192.193:41576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/wicked.php"] [unique_id "al9RgcJSWzG9jbYOtu47VgAAAOI"]
[Tue Jul 21 08:01:21.982348 2026] [security2:error] [pid 352421:tid 352506] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RgcJSWzG9jbYOtu47WgAAq1Q"]
[Tue Jul 21 08:01:21.982568 2026] [security2:error] [pid 352421:tid 352589] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RgcJSWzG9jbYOtu47WgAAq1Q"]
[Tue Jul 21 08:01:22.041859 2026] [security2:error] [pid 352421:tid 352657] [client 20.197.192.193:42181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/edit.php"] [unique_id "al9RgsJSWzG9jbYOtu47XAAAAO8"]
[Tue Jul 21 08:01:22.116726 2026] [security2:error] [pid 358661:tid 358801] [client 20.197.192.193:41538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/kua.php"] [unique_id "al9RgglWhjQfpOo60_HIMgAAAAc"]
[Tue Jul 21 08:01:22.205160 2026] [security2:error] [pid 358661:tid 358681] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RgglWhjQfpOo60_HINQAAQxA"]
[Tue Jul 21 08:01:22.205393 2026] [security2:error] [pid 358661:tid 358861] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RgglWhjQfpOo60_HINQAAQxA"]
[Tue Jul 21 08:01:22.208046 2026] [security2:error] [pid 358661:tid 358822] [client 20.197.192.193:41569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/ez.php"] [unique_id "al9RgglWhjQfpOo60_HINgAAABw"]
[Tue Jul 21 08:01:22.256968 2026] [security2:error] [pid 352421:tid 352463] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RgsJSWzG9jbYOtu47XgAAmSk"]
[Tue Jul 21 08:01:22.257166 2026] [security2:error] [pid 352421:tid 352571] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RgsJSWzG9jbYOtu47XgAAmSk"]
[Tue Jul 21 08:01:22.277457 2026] [security2:error] [pid 352421:tid 352591] [client 20.197.192.193:42204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/fz.php"] [unique_id "al9RgsJSWzG9jbYOtu47XwAAAK0"]
[Tue Jul 21 08:01:22.374885 2026] [security2:error] [pid 358661:tid 358830] [client 20.197.192.193:42197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/la.php"] [unique_id "al9RgglWhjQfpOo60_HINwAAACQ"]
[Tue Jul 21 08:01:22.411080 2026] [security2:error] [pid 358661:tid 358868] [client 120.56.162.40:58538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RgglWhjQfpOo60_HIOAAAAEo"]
[Tue Jul 21 08:01:22.422730 2026] [security2:error] [pid 358661:tid 358833] [client 20.197.192.193:42232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/nhvoanpl.php"] [unique_id "al9RgglWhjQfpOo60_HIOQAAACc"]
[Tue Jul 21 08:01:22.540132 2026] [core:error] [pid 352421:tid 352428] [remote 40.77.167.247:44163] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:01:22.540152 2026] [core:error] [pid 352421:tid 352428] [remote 40.77.167.247:44163] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:01:22.544778 2026] [security2:error] [pid 358661:tid 358860] [client 20.104.96.117:46623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/yas.php"] [unique_id "al9RgglWhjQfpOo60_HIPQAAAEI"]
[Tue Jul 21 08:01:22.609373 2026] [security2:error] [pid 358661:tid 358816] [client 20.197.192.193:42216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/inso.php"] [unique_id "al9RgglWhjQfpOo60_HIQgAAABY"]
[Tue Jul 21 08:01:22.618217 2026] [security2:error] [pid 352421:tid 352639] [client 65.21.113.253:34254] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RgsJSWzG9jbYOtu47XQAAAN0"]
[Tue Jul 21 08:01:22.659149 2026] [security2:error] [pid 358661:tid 358707] [remote 154.61.75.100:33272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-login.php"] [unique_id "al9RgglWhjQfpOo60_HIQwAAdio"]
[Tue Jul 21 08:01:22.706045 2026] [security2:error] [pid 358661:tid 358800] [client 20.226.60.151:59982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/autoload_classmap.php"] [unique_id "al9RgglWhjQfpOo60_HIRAAAAAY"]
[Tue Jul 21 08:01:22.760073 2026] [security2:error] [pid 358661:tid 358907] [client 223.236.153.128:5529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RgglWhjQfpOo60_HIRQAAAHE"]
[Tue Jul 21 08:01:22.760211 2026] [security2:error] [pid 358661:tid 358907] [client 223.236.153.128:5529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RgglWhjQfpOo60_HIRQAAAHE"]
[Tue Jul 21 08:01:22.960435 2026] [security2:error] [pid 352421:tid 352661] [client 184.75.221.3:47362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9RgsJSWzG9jbYOtu47aQAAAPM"]
[Tue Jul 21 08:01:22.960538 2026] [security2:error] [pid 352421:tid 352661] [client 184.75.221.3:47362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9RgsJSWzG9jbYOtu47aQAAAPM"]
[Tue Jul 21 08:01:23.007022 2026] [security2:error] [pid 352421:tid 352649] [client 20.197.192.193:42225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/wpx.php"] [unique_id "al9Rg8JSWzG9jbYOtu47bQAAAOc"]
[Tue Jul 21 08:01:23.009829 2026] [security2:error] [pid 352421:tid 352613] [client 198.54.128.138:37376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Rg8JSWzG9jbYOtu47bgAAAMM"]
[Tue Jul 21 08:01:23.009903 2026] [security2:error] [pid 352421:tid 352613] [client 198.54.128.138:37376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Rg8JSWzG9jbYOtu47bgAAAMM"]
[Tue Jul 21 08:01:23.073067 2026] [security2:error] [pid 358661:tid 358916] [client 20.197.192.193:42178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/berlin.php"] [unique_id "al9RgwlWhjQfpOo60_HIRwAAAHo"]
[Tue Jul 21 08:01:23.183668 2026] [security2:error] [pid 358661:tid 358812] [client 20.197.192.193:41545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/billur.php"] [unique_id "al9RgwlWhjQfpOo60_HISgAAABI"]
[Tue Jul 21 08:01:23.583818 2026] [security2:error] [pid 358661:tid 358821] [client 20.197.195.24:58971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/test.php"] [unique_id "al9RgwlWhjQfpOo60_HITgAAABs"]
[Tue Jul 21 08:01:23.632911 2026] [security2:error] [pid 352421:tid 352450] [remote 134.209.147.209:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.147.209.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9Rg8JSWzG9jbYOtu47dwAA_Rw"]
[Tue Jul 21 08:01:23.684706 2026] [security2:error] [pid 352421:tid 352672] [client 20.197.192.193:42209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/mimpi.php"] [unique_id "al9Rg8JSWzG9jbYOtu47eQAAAP4"]
[Tue Jul 21 08:01:24.002259 2026] [security2:error] [pid 358661:tid 358817] [client 20.197.192.193:56770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9RhAlWhjQfpOo60_HIWAAAABc"]
[Tue Jul 21 08:01:24.119628 2026] [security2:error] [pid 352421:tid 352601] [client 20.226.60.151:60000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-link-zorm.php"] [unique_id "al9RhMJSWzG9jbYOtu47gQAAALc"]
[Tue Jul 21 08:01:24.122286 2026] [security2:error] [pid 352421:tid 352447] [remote 193.70.112.205:48340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9RhMJSWzG9jbYOtu47gAAA6hk"]
[Tue Jul 21 08:01:24.144496 2026] [security2:error] [pid 352421:tid 352624] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9RhMJSWzG9jbYOtu47hAAAAM4"]
[Tue Jul 21 08:01:24.175297 2026] [security2:error] [pid 352421:tid 352673] [client 20.151.10.161:39865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/.well-known/about.php"] [unique_id "al9RhMJSWzG9jbYOtu47hgAAAP8"]
[Tue Jul 21 08:01:24.177861 2026] [security2:error] [pid 352421:tid 352638] [client 148.113.130.19:24596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "cromosolucoes.com.br"] [uri "/"] [unique_id "al9RhMJSWzG9jbYOtu47hwAAANw"]
[Tue Jul 21 08:01:24.177932 2026] [security2:error] [pid 352421:tid 352638] [client 148.113.130.19:24596] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cromosolucoes.com.br"] [uri "/"] [unique_id "al9RhMJSWzG9jbYOtu47hwAAANw"]
[Tue Jul 21 08:01:24.288239 2026] [security2:error] [pid 358661:tid 358853] [client 136.144.33.54:35617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RhAlWhjQfpOo60_HIYgAAADs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:01:24.427499 2026] [security2:error] [pid 358661:tid 358824] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhAlWhjQfpOo60_HIYwAAAB4"]
[Tue Jul 21 08:01:24.520245 2026] [security2:error] [pid 358661:tid 358823] [client 20.104.96.117:46712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/file61.php"] [unique_id "al9RhAlWhjQfpOo60_HIZgAAAB0"]
[Tue Jul 21 08:01:24.562713 2026] [security2:error] [pid 358661:tid 358826] [client 202.143.127.214:49782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhAlWhjQfpOo60_HIaAAAACA"]
[Tue Jul 21 08:01:24.562885 2026] [security2:error] [pid 358661:tid 358826] [client 202.143.127.214:49782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhAlWhjQfpOo60_HIaAAAACA"]
[Tue Jul 21 08:01:24.803791 2026] [security2:error] [pid 352421:tid 352631] [client 117.247.80.59:14966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhMJSWzG9jbYOtu47kwAAANU"]
[Tue Jul 21 08:01:24.803998 2026] [security2:error] [pid 352421:tid 352631] [client 117.247.80.59:14966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhMJSWzG9jbYOtu47kwAAANU"]
[Tue Jul 21 08:01:24.897497 2026] [security2:error] [pid 358661:tid 358878] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9RhAlWhjQfpOo60_HIbgAAAFQ"]
[Tue Jul 21 08:01:24.916003 2026] [security2:error] [pid 358661:tid 358840] [client 20.226.60.151:59976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-link-szoppm.php"] [unique_id "al9RhAlWhjQfpOo60_HIbwAAAC4"]
[Tue Jul 21 08:01:25.108080 2026] [security2:error] [pid 358661:tid 358817] [client 20.197.195.24:24162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/aaa.php"] [unique_id "al9RhQlWhjQfpOo60_HIdgAAABc"]
[Tue Jul 21 08:01:25.179864 2026] [security2:error] [pid 358661:tid 358879] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9RhQlWhjQfpOo60_HIegAAAFU"]
[Tue Jul 21 08:01:25.185628 2026] [security2:error] [pid 358661:tid 358810] [client 87.116.180.198:13890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhQlWhjQfpOo60_HIewAAABA"]
[Tue Jul 21 08:01:25.190514 2026] [security2:error] [pid 358661:tid 358810] [client 87.116.180.198:13890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhQlWhjQfpOo60_HIewAAABA"]
[Tue Jul 21 08:01:25.418825 2026] [proxy:error] [pid 352421:tid 352577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:01:25.418894 2026] [proxy_http:error] [pid 352421:tid 352577] [client 185.247.137.42:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:01:25.419565 2026] [proxy:error] [pid 352421:tid 352577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:01:25.419598 2026] [proxy_http:error] [pid 352421:tid 352577] [client 185.247.137.42:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:01:25.463319 2026] [security2:error] [pid 352421:tid 352655] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9RhcJSWzG9jbYOtu47nAAAAO0"]
[Tue Jul 21 08:01:25.530455 2026] [security2:error] [pid 352421:tid 352628] [client 104.207.57.157:34921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RhMJSWzG9jbYOtu47jAAAANI"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:01:25.551699 2026] [security2:error] [pid 358661:tid 358892] [client 106.215.181.8:22184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhQlWhjQfpOo60_HIfgAAAGI"]
[Tue Jul 21 08:01:25.551797 2026] [security2:error] [pid 358661:tid 358892] [client 106.215.181.8:22184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhQlWhjQfpOo60_HIfgAAAGI"]
[Tue Jul 21 08:01:25.596247 2026] [security2:error] [pid 358661:tid 358813] [client 103.78.200.11:50153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhQlWhjQfpOo60_HIgQAAABM"]
[Tue Jul 21 08:01:25.596352 2026] [security2:error] [pid 358661:tid 358813] [client 103.78.200.11:50153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhQlWhjQfpOo60_HIgQAAABM"]
[Tue Jul 21 08:01:25.666697 2026] [security2:error] [pid 352421:tid 352661] [client 20.104.96.117:46608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/water.php"] [unique_id "al9RhcJSWzG9jbYOtu47nwAAAPM"]
[Tue Jul 21 08:01:25.744840 2026] [security2:error] [pid 352421:tid 352670] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9RhcJSWzG9jbYOtu47ogAAAPw"]
[Tue Jul 21 08:01:25.819968 2026] [security2:error] [pid 358661:tid 358842] [client 20.197.195.24:24143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/11.php"] [unique_id "al9RhQlWhjQfpOo60_HIhQAAADA"]
[Tue Jul 21 08:01:25.860847 2026] [security2:error] [pid 358661:tid 358919] [client 103.86.117.203:64322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RhQlWhjQfpOo60_HIhwAAAH0"]
[Tue Jul 21 08:01:25.861001 2026] [security2:error] [pid 358661:tid 358919] [client 103.86.117.203:64322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RhQlWhjQfpOo60_HIhwAAAH0"]
[Tue Jul 21 08:01:25.886085 2026] [security2:error] [pid 352421:tid 352607] [client 109.60.28.94:56272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhcJSWzG9jbYOtu47pQAAAL0"]
[Tue Jul 21 08:01:25.886202 2026] [security2:error] [pid 352421:tid 352607] [client 109.60.28.94:56272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhcJSWzG9jbYOtu47pQAAAL0"]
[Tue Jul 21 08:01:25.995262 2026] [security2:error] [pid 358661:tid 358921] [client 20.197.192.193:56820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9RhQlWhjQfpOo60_HIiQAAAH8"]
[Tue Jul 21 08:01:26.027393 2026] [security2:error] [pid 352421:tid 352625] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9RhsJSWzG9jbYOtu47pgAAAM8"]
[Tue Jul 21 08:01:26.065334 2026] [security2:error] [pid 358661:tid 358852] [client 20.151.10.161:39827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9RhglWhjQfpOo60_HIiwAAADo"]
[Tue Jul 21 08:01:26.067934 2026] [security2:error] [pid 352421:tid 352612] [client 20.226.60.151:59991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/albin.php"] [unique_id "al9RhsJSWzG9jbYOtu47pwAAAMI"]
[Tue Jul 21 08:01:26.248735 2026] [security2:error] [pid 358661:tid 358822] [client 184.75.221.3:47378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9RhglWhjQfpOo60_HIjQAAABw"]
[Tue Jul 21 08:01:26.248849 2026] [security2:error] [pid 358661:tid 358822] [client 184.75.221.3:47378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9RhglWhjQfpOo60_HIjQAAABw"]
[Tue Jul 21 08:01:26.311095 2026] [security2:error] [pid 358661:tid 358817] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9RhglWhjQfpOo60_HIjwAAABc"]
[Tue Jul 21 08:01:26.357756 2026] [security2:error] [pid 352421:tid 352602] [client 102.206.115.33:62542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RhsJSWzG9jbYOtu47rwAAALg"]
[Tue Jul 21 08:01:26.357918 2026] [security2:error] [pid 352421:tid 352602] [client 102.206.115.33:62542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RhsJSWzG9jbYOtu47rwAAALg"]
[Tue Jul 21 08:01:26.594691 2026] [security2:error] [pid 352421:tid 352653] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9RhsJSWzG9jbYOtu47swAAAOs"]
[Tue Jul 21 08:01:26.744627 2026] [security2:error] [pid 358661:tid 358847] [client 20.197.195.24:58985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/mac.php"] [unique_id "al9RhglWhjQfpOo60_HIkwAAADU"]
[Tue Jul 21 08:01:26.877516 2026] [security2:error] [pid 358661:tid 358857] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9RhglWhjQfpOo60_HImQAAAD8"]
[Tue Jul 21 08:01:26.926318 2026] [security2:error] [pid 352421:tid 352663] [client 65.21.113.253:34254] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RhsJSWzG9jbYOtu47sQAAAPU"]
[Tue Jul 21 08:01:26.945922 2026] [security2:error] [pid 358661:tid 358912] [client 20.151.10.161:39874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/bob.php"] [unique_id "al9RhglWhjQfpOo60_HImgAAAHY"]
[Tue Jul 21 08:01:27.144475 2026] [security2:error] [pid 358661:tid 358812] [client 103.29.114.44:34512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhwlWhjQfpOo60_HInQAAABI"]
[Tue Jul 21 08:01:27.144631 2026] [security2:error] [pid 358661:tid 358812] [client 103.29.114.44:34512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RhwlWhjQfpOo60_HInQAAABI"]
[Tue Jul 21 08:01:27.160681 2026] [security2:error] [pid 358661:tid 358849] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9RhwlWhjQfpOo60_HIngAAADc"]
[Tue Jul 21 08:01:27.253412 2026] [autoindex:error] [pid 358661:tid 358794] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:27.321061 2026] [security2:error] [pid 358661:tid 358823] [client 65.21.113.253:53966] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9RhwlWhjQfpOo60_HIpQAAAB0"]
[Tue Jul 21 08:01:27.443489 2026] [security2:error] [pid 358661:tid 358826] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9RhwlWhjQfpOo60_HIqAAAACA"]
[Tue Jul 21 08:01:27.505198 2026] [autoindex:error] [pid 358661:tid 358713] [remote 170.82.90.217:19024] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/
[Tue Jul 21 08:01:27.543808 2026] [security2:error] [pid 358661:tid 358684] [remote 103.187.169.251:55940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextfitjourney.com"] [uri "/wp-login.php"] [unique_id "al9RhwlWhjQfpOo60_HIrgAANhM"]
[Tue Jul 21 08:01:27.597125 2026] [security2:error] [pid 358661:tid 358836] [client 20.226.60.151:60009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/cilus.php"] [unique_id "al9RhwlWhjQfpOo60_HIsQAAACo"]
[Tue Jul 21 08:01:27.635386 2026] [autoindex:error] [pid 358661:tid 358852] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:27.700233 2026] [autoindex:error] [pid 358661:tid 358749] [remote 170.82.90.217:19024] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/?pag=chamada_consulta
[Tue Jul 21 08:01:27.720252 2026] [security2:error] [pid 358661:tid 358873] [client 20.197.195.24:58442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/chosen.php"] [unique_id "al9RhwlWhjQfpOo60_HItgAAAE8"]
[Tue Jul 21 08:01:27.728227 2026] [security2:error] [pid 358661:tid 358840] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9RhwlWhjQfpOo60_HIuAAAAC4"]
[Tue Jul 21 08:01:27.745497 2026] [security2:error] [pid 358661:tid 358867] [client 65.111.1.220:43993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.1.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RhglWhjQfpOo60_HIkQAAAEk"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:01:27.834043 2026] [autoindex:error] [pid 358661:tid 358817] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:27.889462 2026] [security2:error] [pid 352421:tid 352477] [remote 103.161.172.221:49902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Rh8JSWzG9jbYOtu47ywAAozc"]
[Tue Jul 21 08:01:27.892951 2026] [security2:error] [pid 352421:tid 352615] [client 122.164.127.47:52833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Rh8JSWzG9jbYOtu47zAAAAMU"]
[Tue Jul 21 08:01:27.893048 2026] [security2:error] [pid 352421:tid 352615] [client 122.164.127.47:52833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9Rh8JSWzG9jbYOtu47zAAAAMU"]
[Tue Jul 21 08:01:28.012245 2026] [security2:error] [pid 352421:tid 352551] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9RiMJSWzG9jbYOtu47zQAAAIU"]
[Tue Jul 21 08:01:28.031711 2026] [autoindex:error] [pid 358661:tid 358856] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:28.180799 2026] [security2:error] [pid 358661:tid 358868] [client 193.36.225.71:50141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RiAlWhjQfpOo60_HIvwAAAEo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:01:28.201645 2026] [security2:error] [pid 352421:tid 352577] [client 65.21.113.253:34258] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RiMJSWzG9jbYOtu47zgAAAJ8"]
[Tue Jul 21 08:01:28.232509 2026] [autoindex:error] [pid 358661:tid 358850] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:28.296345 2026] [security2:error] [pid 352421:tid 352668] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9RiMJSWzG9jbYOtu471gAAAPo"]
[Tue Jul 21 08:01:28.354837 2026] [security2:error] [pid 352421:tid 352659] [client 20.197.195.24:24178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/cream1.php"] [unique_id "al9RiMJSWzG9jbYOtu472QAAAPE"]
[Tue Jul 21 08:01:28.429671 2026] [autoindex:error] [pid 358661:tid 358895] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:28.514882 2026] [security2:error] [pid 358661:tid 358893] [client 20.151.10.161:39923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/crgio.php"] [unique_id "al9RiAlWhjQfpOo60_HIxwAAAGM"]
[Tue Jul 21 08:01:28.534641 2026] [security2:error] [pid 352421:tid 352633] [client 184.75.221.3:34808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9RiMJSWzG9jbYOtu473gAAANc"]
[Tue Jul 21 08:01:28.534742 2026] [security2:error] [pid 352421:tid 352633] [client 184.75.221.3:34808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9RiMJSWzG9jbYOtu473gAAANc"]
[Tue Jul 21 08:01:28.556149 2026] [security2:error] [pid 358661:tid 358898] [client 20.226.60.151:59993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/gptsh.php"] [unique_id "al9RiAlWhjQfpOo60_HIyAAAAGg"]
[Tue Jul 21 08:01:28.579522 2026] [security2:error] [pid 358661:tid 358911] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9RiAlWhjQfpOo60_HIyQAAAHU"]
[Tue Jul 21 08:01:28.599264 2026] [security2:error] [pid 358661:tid 358757] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RiAlWhjQfpOo60_HIygAAQVw"]
[Tue Jul 21 08:01:28.599404 2026] [security2:error] [pid 358661:tid 358859] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RiAlWhjQfpOo60_HIygAAQVw"]
[Tue Jul 21 08:01:28.617188 2026] [authz_core:error] [pid 358661:tid 358849] [client 20.197.195.24:0] AH01630: client denied by server configuration: /home1/meufla20/public_html/wp-content/uploads/index.php
[Tue Jul 21 08:01:28.628194 2026] [autoindex:error] [pid 358661:tid 358892] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:28.632806 2026] [security2:error] [pid 358661:tid 358860] [client 103.166.103.129:65254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RiAlWhjQfpOo60_HI0AAAAEI"]
[Tue Jul 21 08:01:28.632913 2026] [security2:error] [pid 358661:tid 358860] [client 103.166.103.129:65254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RiAlWhjQfpOo60_HI0AAAAEI"]
[Tue Jul 21 08:01:28.645323 2026] [autoindex:error] [pid 358661:tid 358851] [client 20.197.195.24:0] AH01276: Cannot serve directory /home1/meufla20/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:28.657691 2026] [security2:error] [pid 358661:tid 358823] [client 20.197.195.24:24083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/dr.php"] [unique_id "al9RiAlWhjQfpOo60_HI0wAAAB0"]
[Tue Jul 21 08:01:28.663628 2026] [security2:error] [pid 358661:tid 358872] [client 65.21.113.253:53970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RiAlWhjQfpOo60_HI1AAAAE4"]
[Tue Jul 21 08:01:28.755293 2026] [security2:error] [pid 352421:tid 352576] [client 74.7.230.46:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "espacocandeia.com"] [uri "/index.php"] [unique_id "al9RiMJSWzG9jbYOtu472AAAAJ4"]
[Tue Jul 21 08:01:28.755961 2026] [security2:error] [pid 358661:tid 358916] [client 74.7.244.36:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "espacocandeia.com.elevoclean.com"] [uri "/index.php"] [unique_id "al9RhwlWhjQfpOo60_HIrQAAAHo"]
[Tue Jul 21 08:01:28.756149 2026] [security2:error] [pid 358661:tid 358835] [client 74.7.230.46:45946] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "espacocandeia.com"] [uri "/robots.txt"] [unique_id "al9RiAlWhjQfpOo60_HIwgAAKXE"]
[Tue Jul 21 08:01:28.756579 2026] [security2:error] [pid 352421:tid 352582] [client 74.7.244.36:48334] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "espacocandeia.com.elevoclean.com"] [uri "/robots.txt"] [unique_id "al9Rh8JSWzG9jbYOtu47xwAApGA"]
[Tue Jul 21 08:01:28.825962 2026] [autoindex:error] [pid 358661:tid 358873] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:28.864676 2026] [security2:error] [pid 352421:tid 352650] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9RiMJSWzG9jbYOtu475QAAAOg"]
[Tue Jul 21 08:01:28.914581 2026] [security2:error] [pid 358661:tid 358881] [client 122.179.91.63:2329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RiAlWhjQfpOo60_HI4wAAAFc"]
[Tue Jul 21 08:01:28.916401 2026] [security2:error] [pid 358661:tid 358881] [client 122.179.91.63:2329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RiAlWhjQfpOo60_HI4wAAAFc"]
[Tue Jul 21 08:01:28.954597 2026] [security2:error] [pid 352421:tid 352652] [client 20.197.195.24:58962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/x.php"] [unique_id "al9RiMJSWzG9jbYOtu476gAAAOo"]
[Tue Jul 21 08:01:28.960455 2026] [security2:error] [pid 352421:tid 352579] [client 204.12.208.18:58510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-includes/addb8871/index.php"] [unique_id "al9RiMJSWzG9jbYOtu476wAAAKE"], referer: https://rkcentroautomotivoo.com.br/wp-includes/addb8871/index.php
[Tue Jul 21 08:01:29.146930 2026] [security2:error] [pid 352421:tid 352673] [client 20.151.10.161:39822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/pucci.php"] [unique_id "al9RicJSWzG9jbYOtu477AAAAP8"]
[Tue Jul 21 08:01:29.148189 2026] [security2:error] [pid 358661:tid 358799] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9RiQlWhjQfpOo60_HI5QAAAAU"]
[Tue Jul 21 08:01:29.152817 2026] [security2:error] [pid 358661:tid 358906] [client 20.226.60.151:60029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/rithin.php"] [unique_id "al9RiQlWhjQfpOo60_HI5gAAAHA"]
[Tue Jul 21 08:01:29.159377 2026] [security2:error] [pid 358661:tid 358856] [client 20.197.195.24:24152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/155.php"] [unique_id "al9RiQlWhjQfpOo60_HI5wAAAD4"]
[Tue Jul 21 08:01:29.208231 2026] [security2:error] [pid 352421:tid 352671] [client 65.111.29.113:17893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.29.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RicJSWzG9jbYOtu477QAAAP0"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:01:29.208996 2026] [security2:error] [pid 352421:tid 352585] [client 182.8.255.181:21074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RicJSWzG9jbYOtu477gAAAKc"]
[Tue Jul 21 08:01:29.209265 2026] [security2:error] [pid 352421:tid 352585] [client 182.8.255.181:21074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RicJSWzG9jbYOtu477gAAAKc"]
[Tue Jul 21 08:01:29.218481 2026] [security2:error] [pid 352421:tid 352566] [client 20.197.195.24:58472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/ops.php"] [unique_id "al9RicJSWzG9jbYOtu478AAAAJQ"]
[Tue Jul 21 08:01:29.292857 2026] [security2:error] [pid 352421:tid 352580] [client 65.21.113.253:34254] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RiMJSWzG9jbYOtu475gAAAKI"]
[Tue Jul 21 08:01:29.397945 2026] [security2:error] [pid 358661:tid 358904] [client 20.197.195.24:24128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/file31.php"] [unique_id "al9RiQlWhjQfpOo60_HI7AAAAG4"]
[Tue Jul 21 08:01:29.504212 2026] [security2:error] [pid 358661:tid 358850] [client 204.12.208.18:58526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-includes/addb8871/index.php"] [unique_id "al9RiQlWhjQfpOo60_HI7gAAADg"], referer: https://rkcentroautomotivoo.com.br/wp-includes/addb8871/index.php
[Tue Jul 21 08:01:29.679887 2026] [security2:error] [pid 358661:tid 358812] [client 20.104.96.117:27098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/nano.php"] [unique_id "al9RiQlWhjQfpOo60_HI8AAAABI"]
[Tue Jul 21 08:01:29.857551 2026] [security2:error] [pid 358661:tid 358726] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RiQlWhjQfpOo60_HI8wAAYz0"]
[Tue Jul 21 08:01:29.857698 2026] [security2:error] [pid 358661:tid 358893] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RiQlWhjQfpOo60_HI8wAAYz0"]
[Tue Jul 21 08:01:29.865716 2026] [security2:error] [pid 352421:tid 352564] [client 184.75.221.3:52118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9RicJSWzG9jbYOtu47-wAAAJI"]
[Tue Jul 21 08:01:29.865807 2026] [security2:error] [pid 352421:tid 352564] [client 184.75.221.3:52118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9RicJSWzG9jbYOtu47-wAAAJI"]
[Tue Jul 21 08:01:29.965985 2026] [security2:error] [pid 358661:tid 358805] [client 20.226.60.151:65430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/fffm.php"] [unique_id "al9RiQlWhjQfpOo60_HI9AAAAAs"]
[Tue Jul 21 08:01:30.004259 2026] [security2:error] [pid 352421:tid 352573] [client 178.153.91.96:60708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RisJSWzG9jbYOtu47_wAAAJs"]
[Tue Jul 21 08:01:30.004350 2026] [security2:error] [pid 352421:tid 352573] [client 178.153.91.96:60708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RisJSWzG9jbYOtu47_wAAAJs"]
[Tue Jul 21 08:01:30.020878 2026] [security2:error] [pid 358661:tid 358902] [client 20.197.192.193:50579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wander.php"] [unique_id "al9RiglWhjQfpOo60_HI9wAAAGw"]
[Tue Jul 21 08:01:30.051158 2026] [security2:error] [pid 352421:tid 352643] [client 204.12.208.18:58539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-includes/addb8871/index.php"] [unique_id "al9RisJSWzG9jbYOtu48AAAAAOE"], referer: https://rkcentroautomotivoo.com.br/wp-includes/addb8871/index.php
[Tue Jul 21 08:01:30.284508 2026] [security2:error] [pid 352421:tid 352641] [client 184.75.221.3:52134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9RisJSWzG9jbYOtu48BAAAAN8"]
[Tue Jul 21 08:01:30.284722 2026] [security2:error] [pid 352421:tid 352641] [client 184.75.221.3:52134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9RisJSWzG9jbYOtu48BAAAAN8"]
[Tue Jul 21 08:01:30.300763 2026] [security2:error] [pid 358661:tid 358863] [client 20.151.10.161:39843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-temp.php"] [unique_id "al9RiglWhjQfpOo60_HJBgAAAEU"]
[Tue Jul 21 08:01:30.440627 2026] [security2:error] [pid 358661:tid 358879] [client 117.210.135.0:52089] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RiglWhjQfpOo60_HJBwAAAFU"]
[Tue Jul 21 08:01:30.440785 2026] [security2:error] [pid 358661:tid 358879] [client 117.210.135.0:52089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RiglWhjQfpOo60_HJBwAAAFU"]
[Tue Jul 21 08:01:30.483197 2026] [security2:error] [pid 352421:tid 352646] [client 20.197.195.24:58482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/file6.php"] [unique_id "al9RisJSWzG9jbYOtu48CQAAAOQ"]
[Tue Jul 21 08:01:30.591050 2026] [security2:error] [pid 352421:tid 352439] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RisJSWzG9jbYOtu48CgAApRE"]
[Tue Jul 21 08:01:30.591210 2026] [security2:error] [pid 352421:tid 352583] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RisJSWzG9jbYOtu48CgAApRE"]
[Tue Jul 21 08:01:30.781584 2026] [autoindex:error] [pid 358661:tid 358913] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:30.977536 2026] [security2:error] [pid 358661:tid 358873] [client 41.68.90.219:57809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RiglWhjQfpOo60_HJEQAAAE8"]
[Tue Jul 21 08:01:30.978751 2026] [security2:error] [pid 358661:tid 358873] [client 41.68.90.219:57809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RiglWhjQfpOo60_HJEQAAAE8"]
[Tue Jul 21 08:01:30.978968 2026] [autoindex:error] [pid 358661:tid 358796] [client 20.197.195.24:0] AH01276: Cannot serve directory /home1/meufla20/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:31.035600 2026] [security2:error] [pid 352421:tid 352678] [client 20.197.195.24:58460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/adminfuns.php"] [unique_id "al9Ri8JSWzG9jbYOtu48EgAAAQQ"]
[Tue Jul 21 08:01:31.157831 2026] [security2:error] [pid 358661:tid 358733] [remote 154.61.75.100:36820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "growe-ag.jaypi.com.br"] [uri "/wp-login.php"] [unique_id "al9RiwlWhjQfpOo60_HJEwAAb0Q"]
[Tue Jul 21 08:01:31.187379 2026] [autoindex:error] [pid 358661:tid 358895] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:31.197776 2026] [security2:error] [pid 358661:tid 358680] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RiwlWhjQfpOo60_HJFQAAcA8"]
[Tue Jul 21 08:01:31.197922 2026] [security2:error] [pid 358661:tid 358906] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RiwlWhjQfpOo60_HJFQAAcA8"]
[Tue Jul 21 08:01:31.201218 2026] [security2:error] [pid 358661:tid 358840] [client 20.226.60.151:59921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/dfre.php"] [unique_id "al9RiwlWhjQfpOo60_HJFgAAAC4"]
[Tue Jul 21 08:01:31.229644 2026] [security2:error] [pid 352421:tid 352613] [client 38.100.221.102:18953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ri8JSWzG9jbYOtu48FAAAAMM"]
[Tue Jul 21 08:01:31.229896 2026] [security2:error] [pid 352421:tid 352613] [client 38.100.221.102:18953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ri8JSWzG9jbYOtu48FAAAAMM"]
[Tue Jul 21 08:01:31.299659 2026] [security2:error] [pid 352421:tid 352436] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ri8JSWzG9jbYOtu48FQAAqQ4"]
[Tue Jul 21 08:01:31.299890 2026] [security2:error] [pid 352421:tid 352587] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ri8JSWzG9jbYOtu48FQAAqQ4"]
[Tue Jul 21 08:01:31.385895 2026] [autoindex:error] [pid 358661:tid 358898] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:31.404514 2026] [security2:error] [pid 358661:tid 358809] [client 182.9.35.66:23295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.35.9.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilly.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RiglWhjQfpOo60_HJAAAAAA8"]
[Tue Jul 21 08:01:31.404674 2026] [security2:error] [pid 358661:tid 358809] [client 182.9.35.66:23295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hilly.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RiglWhjQfpOo60_HJAAAAAA8"]
[Tue Jul 21 08:01:31.539156 2026] [security2:error] [pid 358661:tid 358910] [client 20.197.195.24:24170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/goods.php"] [unique_id "al9RiwlWhjQfpOo60_HJGwAAAHQ"]
[Tue Jul 21 08:01:31.543085 2026] [security2:error] [pid 352421:tid 352555] [client 20.104.96.117:46646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/moon.php"] [unique_id "al9Ri8JSWzG9jbYOtu48HQAAAIk"]
[Tue Jul 21 08:01:31.583176 2026] [autoindex:error] [pid 358661:tid 358851] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:31.590169 2026] [security2:error] [pid 352421:tid 352645] [client 20.151.10.161:39821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9Ri8JSWzG9jbYOtu48HgAAAOM"]
[Tue Jul 21 08:01:31.603230 2026] [security2:error] [pid 352421:tid 352496] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ri8JSWzG9jbYOtu48HwAA7ko"]
[Tue Jul 21 08:01:31.603396 2026] [security2:error] [pid 352421:tid 352656] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ri8JSWzG9jbYOtu48HwAA7ko"]
[Tue Jul 21 08:01:31.783178 2026] [autoindex:error] [pid 358661:tid 358823] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:31.805375 2026] [security2:error] [pid 358661:tid 358893] [client 173.252.95.26:62250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9RiwlWhjQfpOo60_HJHwAAAGM"]
[Tue Jul 21 08:01:31.946152 2026] [security2:error] [pid 352421:tid 352659] [client 193.36.225.63:39299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Ri8JSWzG9jbYOtu48JAAAAPE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:01:31.979098 2026] [autoindex:error] [pid 358661:tid 358848] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:32.013155 2026] [security2:error] [pid 358661:tid 358859] [client 65.21.113.253:50860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RiwlWhjQfpOo60_HJHQAAAEE"]
[Tue Jul 21 08:01:32.274079 2026] [security2:error] [pid 352421:tid 352581] [client 104.207.35.183:29661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.35.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RisJSWzG9jbYOtu48AgAAAKM"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:01:32.311428 2026] [security2:error] [pid 358661:tid 358834] [client 175.144.82.48:58045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RjAlWhjQfpOo60_HJKAAAACg"]
[Tue Jul 21 08:01:32.311641 2026] [security2:error] [pid 358661:tid 358834] [client 175.144.82.48:58045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RjAlWhjQfpOo60_HJKAAAACg"]
[Tue Jul 21 08:01:32.579214 2026] [security2:error] [pid 352421:tid 352663] [client 136.144.42.175:41541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/wp-login.php"] [unique_id "al9RjMJSWzG9jbYOtu48LgAAAPU"]
[Tue Jul 21 08:01:32.621249 2026] [autoindex:error] [pid 358661:tid 358919] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:32.810040 2026] [core:crit] [pid 358661:tid 358914] (13)Permission denied: [client 85.204.70.102:42090] AH00529: /home2/chri2452/public_html/cgi-bin/.htaccess pcfg_openfile: unable to check htaccess file, ensure it is readable and that '/home2/chri2452/public_html/cgi-bin/' is executable
[Tue Jul 21 08:01:32.853591 2026] [security2:error] [pid 358661:tid 358703] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RjAlWhjQfpOo60_HJMgAAdyY"]
[Tue Jul 21 08:01:32.853812 2026] [security2:error] [pid 358661:tid 358913] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RjAlWhjQfpOo60_HJMgAAdyY"]
[Tue Jul 21 08:01:32.886323 2026] [security2:error] [pid 358661:tid 358889] [client 20.226.60.151:59941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/wp-happy.php"] [unique_id "al9RjAlWhjQfpOo60_HJNQAAAF8"]
[Tue Jul 21 08:01:32.893615 2026] [security2:error] [pid 352421:tid 352463] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RjMJSWzG9jbYOtu48MwAAmSk"]
[Tue Jul 21 08:01:32.893717 2026] [security2:error] [pid 352421:tid 352571] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RjMJSWzG9jbYOtu48MwAAmSk"]
[Tue Jul 21 08:01:33.016665 2026] [security2:error] [pid 352421:tid 352580] [client 120.56.162.40:58955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RjMJSWzG9jbYOtu48NgAAAKI"]
[Tue Jul 21 08:01:33.059979 2026] [security2:error] [pid 358661:tid 358816] [client 20.104.96.117:46615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-info.php"] [unique_id "al9RjQlWhjQfpOo60_HJOQAAABY"]
[Tue Jul 21 08:01:33.258849 2026] [security2:error] [pid 352421:tid 352639] [client 20.197.192.193:42207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/dp.php"] [unique_id "al9RjcJSWzG9jbYOtu48OQAAAN0"]
[Tue Jul 21 08:01:33.286361 2026] [security2:error] [pid 352421:tid 352589] [client 223.236.153.128:7814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RjcJSWzG9jbYOtu48OgAAAKs"]
[Tue Jul 21 08:01:33.286557 2026] [security2:error] [pid 352421:tid 352589] [client 223.236.153.128:7814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RjcJSWzG9jbYOtu48OgAAAKs"]
[Tue Jul 21 08:01:33.290667 2026] [security2:error] [pid 358661:tid 358905] [client 65.21.113.253:53970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RjQlWhjQfpOo60_HJPQAAAG8"]
[Tue Jul 21 08:01:33.297618 2026] [security2:error] [pid 358661:tid 358895] [client 20.197.195.24:58454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/100.php"] [unique_id "al9RjQlWhjQfpOo60_HJPgAAAGU"]
[Tue Jul 21 08:01:33.303551 2026] [security2:error] [pid 358661:tid 358906] [client 198.54.128.138:35076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9RjQlWhjQfpOo60_HJPwAAAHA"]
[Tue Jul 21 08:01:33.303706 2026] [security2:error] [pid 358661:tid 358906] [client 198.54.128.138:35076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9RjQlWhjQfpOo60_HJPwAAAHA"]
[Tue Jul 21 08:01:33.469735 2026] [security2:error] [pid 358661:tid 358907] [client 20.151.10.161:39868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/puc.php"] [unique_id "al9RjQlWhjQfpOo60_HJRQAAAHE"]
[Tue Jul 21 08:01:33.788402 2026] [security2:error] [pid 358661:tid 358872] [client 92.119.178.3:60768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9RjQlWhjQfpOo60_HJTgAAAE4"]
[Tue Jul 21 08:01:33.788510 2026] [security2:error] [pid 358661:tid 358872] [client 92.119.178.3:60768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9RjQlWhjQfpOo60_HJTgAAAE4"]
[Tue Jul 21 08:01:33.926185 2026] [security2:error] [pid 358661:tid 358853] [client 65.21.113.253:50860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RjQlWhjQfpOo60_HJSAAAADs"]
[Tue Jul 21 08:01:34.580226 2026] [security2:error] [pid 352421:tid 352574] [client 20.226.60.151:65462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/fpr4.php"] [unique_id "al9RjsJSWzG9jbYOtu48TgAAAJw"]
[Tue Jul 21 08:01:34.939692 2026] [security2:error] [pid 358661:tid 358870] [client 20.151.10.161:39764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/themes.php"] [unique_id "al9RjglWhjQfpOo60_HJXwAAAEw"]
[Tue Jul 21 08:01:35.007696 2026] [security2:error] [pid 352421:tid 352660] [client 20.104.96.117:46605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/2000.php"] [unique_id "al9Rj8JSWzG9jbYOtu48VAAAAPI"]
[Tue Jul 21 08:01:35.166607 2026] [security2:error] [pid 352421:tid 352605] [client 184.75.221.3:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Rj8JSWzG9jbYOtu48WgAAALs"]
[Tue Jul 21 08:01:35.166689 2026] [security2:error] [pid 352421:tid 352605] [client 184.75.221.3:52166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Rj8JSWzG9jbYOtu48WgAAALs"]
[Tue Jul 21 08:01:35.450214 2026] [security2:error] [pid 352421:tid 352664] [client 20.151.10.161:39935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/dx.php"] [unique_id "al9Rj8JSWzG9jbYOtu48XAAAAPY"]
[Tue Jul 21 08:01:35.495520 2026] [security2:error] [pid 352421:tid 352652] [client 202.143.127.214:50256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rj8JSWzG9jbYOtu48XgAAAOo"]
[Tue Jul 21 08:01:35.495676 2026] [security2:error] [pid 352421:tid 352652] [client 202.143.127.214:50256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rj8JSWzG9jbYOtu48XgAAAOo"]
[Tue Jul 21 08:01:35.521830 2026] [security2:error] [pid 358661:tid 358830] [client 117.247.80.59:18118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RjwlWhjQfpOo60_HJZwAAACQ"]
[Tue Jul 21 08:01:35.521981 2026] [security2:error] [pid 358661:tid 358830] [client 117.247.80.59:18118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RjwlWhjQfpOo60_HJZwAAACQ"]
[Tue Jul 21 08:01:35.796200 2026] [security2:error] [pid 358661:tid 358823] [client 20.197.192.193:42213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/bootstrap.php"] [unique_id "al9RjwlWhjQfpOo60_HJbQAAAB0"]
[Tue Jul 21 08:01:35.843193 2026] [security2:error] [pid 352421:tid 352596] [client 37.140.223.69:43427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Rj8JSWzG9jbYOtu48ZAAAALI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:01:35.865787 2026] [security2:error] [pid 358661:tid 358846] [client 20.151.10.161:39817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/p.php"] [unique_id "al9RjwlWhjQfpOo60_HJbgAAADQ"]
[Tue Jul 21 08:01:35.897249 2026] [security2:error] [pid 358661:tid 358850] [client 87.116.180.198:27205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RjwlWhjQfpOo60_HJbwAAADg"]
[Tue Jul 21 08:01:35.897337 2026] [security2:error] [pid 358661:tid 358850] [client 87.116.180.198:27205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RjwlWhjQfpOo60_HJbwAAADg"]
[Tue Jul 21 08:01:35.939288 2026] [security2:error] [pid 358661:tid 358859] [client 85.204.70.102:47288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wp-login.php"] [unique_id "al9RjwlWhjQfpOo60_HJcAAAAEE"]
[Tue Jul 21 08:01:35.960294 2026] [security2:error] [pid 358661:tid 358845] [client 92.119.178.3:44816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9RjwlWhjQfpOo60_HJcwAAADM"]
[Tue Jul 21 08:01:35.960387 2026] [security2:error] [pid 358661:tid 358845] [client 92.119.178.3:44816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9RjwlWhjQfpOo60_HJcwAAADM"]
[Tue Jul 21 08:01:35.990558 2026] [security2:error] [pid 358661:tid 358826] [client 20.226.60.151:60010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/file88.php"] [unique_id "al9RjwlWhjQfpOo60_HJdAAAACA"]
[Tue Jul 21 08:01:36.180019 2026] [security2:error] [pid 352421:tid 352566] [client 106.215.181.8:27206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RkMJSWzG9jbYOtu48ZwAAAJQ"]
[Tue Jul 21 08:01:36.180144 2026] [security2:error] [pid 352421:tid 352566] [client 106.215.181.8:27206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RkMJSWzG9jbYOtu48ZwAAAJQ"]
[Tue Jul 21 08:01:36.224353 2026] [security2:error] [pid 358661:tid 358808] [client 20.197.195.24:24158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/about.php"] [unique_id "al9RkAlWhjQfpOo60_HJegAAAA4"]
[Tue Jul 21 08:01:36.290624 2026] [security2:error] [pid 358661:tid 358849] [client 103.78.200.11:50640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RkAlWhjQfpOo60_HJewAAADc"]
[Tue Jul 21 08:01:36.290827 2026] [security2:error] [pid 358661:tid 358849] [client 103.78.200.11:50640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RkAlWhjQfpOo60_HJewAAADc"]
[Tue Jul 21 08:01:36.291236 2026] [security2:error] [pid 358661:tid 358862] [client 20.197.192.193:50591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/jga.php"] [unique_id "al9RkAlWhjQfpOo60_HJfAAAAEQ"]
[Tue Jul 21 08:01:36.356147 2026] [security2:error] [pid 358661:tid 358794] [client 103.86.117.203:64867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RkAlWhjQfpOo60_HJfgAAAAA"]
[Tue Jul 21 08:01:36.356397 2026] [security2:error] [pid 358661:tid 358794] [client 103.86.117.203:64867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RkAlWhjQfpOo60_HJfgAAAAA"]
[Tue Jul 21 08:01:36.376310 2026] [security2:error] [pid 358661:tid 358855] [client 20.104.96.117:46627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/122.php"] [unique_id "al9RkAlWhjQfpOo60_HJgQAAAD0"]
[Tue Jul 21 08:01:36.378049 2026] [security2:error] [pid 358661:tid 358881] [client 65.21.113.253:53970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RkAlWhjQfpOo60_HJgAAAAFc"]
[Tue Jul 21 08:01:36.404795 2026] [security2:error] [pid 358661:tid 358867] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.samilacalculos.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9RkAlWhjQfpOo60_HJggAAAEk"]
[Tue Jul 21 08:01:36.515155 2026] [security2:error] [pid 358661:tid 358815] [client 20.151.10.161:39776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/bthil.php"] [unique_id "al9RkAlWhjQfpOo60_HJgwAAABU"]
[Tue Jul 21 08:01:36.580243 2026] [security2:error] [pid 358661:tid 358817] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.samilacalculos.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9RkAlWhjQfpOo60_HJhAAAABc"]
[Tue Jul 21 08:01:36.700664 2026] [security2:error] [pid 352421:tid 352667] [client 109.60.28.94:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RkMJSWzG9jbYOtu48cAAAAPk"]
[Tue Jul 21 08:01:36.701459 2026] [security2:error] [pid 352421:tid 352667] [client 109.60.28.94:53852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RkMJSWzG9jbYOtu48cAAAAPk"]
[Tue Jul 21 08:01:36.957352 2026] [security2:error] [pid 352421:tid 352564] [client 102.206.115.33:60259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RkMJSWzG9jbYOtu48dAAAAJI"]
[Tue Jul 21 08:01:36.957453 2026] [security2:error] [pid 352421:tid 352564] [client 102.206.115.33:60259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RkMJSWzG9jbYOtu48dAAAAJI"]
[Tue Jul 21 08:01:37.121959 2026] [security2:error] [pid 352421:tid 352655] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.samilacalculos.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9RkcJSWzG9jbYOtu48dQAAAO0"]
[Tue Jul 21 08:01:37.240986 2026] [security2:error] [pid 352421:tid 352615] [client 103.29.114.44:60812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RkcJSWzG9jbYOtu48fAAAAMU"]
[Tue Jul 21 08:01:37.241116 2026] [security2:error] [pid 352421:tid 352615] [client 103.29.114.44:60812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RkcJSWzG9jbYOtu48fAAAAMU"]
[Tue Jul 21 08:01:37.251714 2026] [security2:error] [pid 352421:tid 352588] [client 20.151.10.161:39826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/7.php"] [unique_id "al9RkcJSWzG9jbYOtu48fQAAAKo"]
[Tue Jul 21 08:01:37.436079 2026] [security2:error] [pid 352421:tid 352569] [client 20.197.195.24:24168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/about.php"] [unique_id "al9RkcJSWzG9jbYOtu48fwAAAJc"]
[Tue Jul 21 08:01:37.470688 2026] [security2:error] [pid 358661:tid 358840] [client 65.21.113.253:50862] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RkQlWhjQfpOo60_HJjwAAAC4"]
[Tue Jul 21 08:01:37.504362 2026] [security2:error] [pid 358661:tid 358860] [client 20.197.192.193:42219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/wp-editor.php"] [unique_id "al9RkQlWhjQfpOo60_HJkgAAAEI"]
[Tue Jul 21 08:01:37.787807 2026] [security2:error] [pid 358661:tid 358836] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.samilacalculos.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9RkQlWhjQfpOo60_HJmwAAACo"]
[Tue Jul 21 08:01:37.914287 2026] [security2:error] [pid 358661:tid 358853] [client 20.151.10.161:39804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/8.php"] [unique_id "al9RkQlWhjQfpOo60_HJoQAAADs"]
[Tue Jul 21 08:01:37.918724 2026] [security2:error] [pid 358661:tid 358834] [client 20.226.60.151:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/ccc.php"] [unique_id "al9RkQlWhjQfpOo60_HJogAAACg"]
[Tue Jul 21 08:01:38.094480 2026] [security2:error] [pid 358661:tid 358849] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.samilacalculos.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9RkglWhjQfpOo60_HJqwAAADc"]
[Tue Jul 21 08:01:38.094526 2026] [security2:error] [pid 358661:tid 358910] [client 65.21.113.253:50874] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RkQlWhjQfpOo60_HJlAAAAHQ"]
[Tue Jul 21 08:01:38.341546 2026] [security2:error] [pid 352421:tid 352601] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.samilacalculos.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9RksJSWzG9jbYOtu48jgAAALc"]
[Tue Jul 21 08:01:38.348768 2026] [security2:error] [pid 358661:tid 358914] [client 20.151.10.161:39856] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.jandel.com.br"] [uri "/1.php"] [unique_id "al9RkglWhjQfpOo60_HJrgAAAHg"]
[Tue Jul 21 08:01:38.348929 2026] [security2:error] [pid 358661:tid 358914] [client 20.151.10.161:39856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/1.php"] [unique_id "al9RkglWhjQfpOo60_HJrgAAAHg"]
[Tue Jul 21 08:01:38.511132 2026] [security2:error] [pid 358661:tid 358842] [client 122.164.127.47:53385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.127.164.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RkglWhjQfpOo60_HJsAAAADA"]
[Tue Jul 21 08:01:38.511235 2026] [security2:error] [pid 358661:tid 358842] [client 122.164.127.47:53385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9RkglWhjQfpOo60_HJsAAAADA"]
[Tue Jul 21 08:01:38.544005 2026] [security2:error] [pid 358661:tid 358920] [client 20.197.192.193:42206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/cro.php"] [unique_id "al9RkglWhjQfpOo60_HJsQAAAH4"]
[Tue Jul 21 08:01:38.622198 2026] [security2:error] [pid 358661:tid 358829] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.samilacalculos.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9RkglWhjQfpOo60_HJsgAAACM"]
[Tue Jul 21 08:01:38.943171 2026] [security2:error] [pid 352421:tid 352596] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.samilacalculos.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9RksJSWzG9jbYOtu48mAAAALI"]
[Tue Jul 21 08:01:38.948736 2026] [security2:error] [pid 358661:tid 358858] [client 20.151.10.161:39817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/100.php"] [unique_id "al9RkglWhjQfpOo60_HJtwAAAEA"]
[Tue Jul 21 08:01:38.981980 2026] [security2:error] [pid 358661:tid 358895] [client 20.197.195.24:58468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/admin.php"] [unique_id "al9RkglWhjQfpOo60_HJuAAAAGU"]
[Tue Jul 21 08:01:39.162865 2026] [security2:error] [pid 352421:tid 352671] [client 103.166.103.129:49402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Rk8JSWzG9jbYOtu48nQAAAP0"]
[Tue Jul 21 08:01:39.162972 2026] [security2:error] [pid 352421:tid 352671] [client 103.166.103.129:49402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Rk8JSWzG9jbYOtu48nQAAAP0"]
[Tue Jul 21 08:01:39.192251 2026] [security2:error] [pid 358661:tid 358860] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.samilacalculos.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9RkwlWhjQfpOo60_HJvgAAAEI"]
[Tue Jul 21 08:01:39.448788 2026] [security2:error] [pid 358661:tid 358892] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.samilacalculos.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9RkwlWhjQfpOo60_HJwwAAAGI"]
[Tue Jul 21 08:01:39.450359 2026] [security2:error] [pid 358661:tid 358872] [client 20.197.192.193:41541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/cron-tab.php"] [unique_id "al9RkwlWhjQfpOo60_HJxAAAAE4"]
[Tue Jul 21 08:01:39.573962 2026] [security2:error] [pid 358661:tid 358875] [client 182.8.255.181:17572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RkwlWhjQfpOo60_HJxgAAAFE"]
[Tue Jul 21 08:01:39.574081 2026] [security2:error] [pid 358661:tid 358875] [client 182.8.255.181:17572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RkwlWhjQfpOo60_HJxgAAAFE"]
[Tue Jul 21 08:01:39.577217 2026] [security2:error] [pid 358661:tid 358777] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RkwlWhjQfpOo60_HJxwAAInA"]
[Tue Jul 21 08:01:39.577332 2026] [security2:error] [pid 358661:tid 358828] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RkwlWhjQfpOo60_HJxwAAInA"]
[Tue Jul 21 08:01:39.699042 2026] [security2:error] [pid 352421:tid 352577] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.samilacalculos.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Rk8JSWzG9jbYOtu48pgAAAJ8"]
[Tue Jul 21 08:01:39.734410 2026] [security2:error] [pid 358661:tid 358811] [client 122.179.91.63:32069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RkwlWhjQfpOo60_HJyQAAABE"]
[Tue Jul 21 08:01:39.734761 2026] [security2:error] [pid 358661:tid 358811] [client 122.179.91.63:32069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RkwlWhjQfpOo60_HJyQAAABE"]
[Tue Jul 21 08:01:39.819659 2026] [security2:error] [pid 358661:tid 358807] [client 37.140.223.68:34103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RkwlWhjQfpOo60_HJzQAAAA0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:01:39.905147 2026] [security2:error] [pid 352421:tid 352589] [client 20.197.192.193:48916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/koiy.php"] [unique_id "al9Rk8JSWzG9jbYOtu48qQAAAKs"]
[Tue Jul 21 08:01:39.946254 2026] [security2:error] [pid 358661:tid 358808] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.samilacalculos.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9RkwlWhjQfpOo60_HJ0QAAAA4"]
[Tue Jul 21 08:01:40.199919 2026] [security2:error] [pid 358661:tid 358674] [remote 159.65.81.207:60756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/wp-login.php"] [unique_id "al9RlAlWhjQfpOo60_HJ2AAAJQk"]
[Tue Jul 21 08:01:40.392646 2026] [security2:error] [pid 358661:tid 358913] [client 92.119.178.3:54010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9RlAlWhjQfpOo60_HJ3QAAAHc"]
[Tue Jul 21 08:01:40.392773 2026] [security2:error] [pid 358661:tid 358913] [client 92.119.178.3:54010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9RlAlWhjQfpOo60_HJ3QAAAHc"]
[Tue Jul 21 08:01:40.474331 2026] [security2:error] [pid 358661:tid 358803] [client 20.226.60.151:65428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/777.php"] [unique_id "al9RlAlWhjQfpOo60_HJ3wAAAAk"]
[Tue Jul 21 08:01:40.513407 2026] [security2:error] [pid 358661:tid 358870] [client 198.54.128.138:36026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9RlAlWhjQfpOo60_HJ4AAAAEw"]
[Tue Jul 21 08:01:40.513503 2026] [security2:error] [pid 358661:tid 358870] [client 198.54.128.138:36026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9RlAlWhjQfpOo60_HJ4AAAAEw"]
[Tue Jul 21 08:01:40.545208 2026] [security2:error] [pid 358661:tid 358781] [remote 5.202.15.246:60692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.15.202.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/wp-login.php"] [unique_id "al9RlAlWhjQfpOo60_HJ4wAAfXQ"]
[Tue Jul 21 08:01:40.569848 2026] [security2:error] [pid 358661:tid 358902] [client 178.153.91.96:22089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RlAlWhjQfpOo60_HJ5wAAAGw"]
[Tue Jul 21 08:01:40.569935 2026] [security2:error] [pid 358661:tid 358902] [client 178.153.91.96:22089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RlAlWhjQfpOo60_HJ5wAAAGw"]
[Tue Jul 21 08:01:40.705141 2026] [autoindex:error] [pid 358661:tid 358905] [client 85.204.70.102:42090] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:40.790707 2026] [security2:error] [pid 352421:tid 352562] [client 20.104.96.117:27115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/mds.php"] [unique_id "al9RlMJSWzG9jbYOtu48tgAAAJA"]
[Tue Jul 21 08:01:40.887578 2026] [security2:error] [pid 352421:tid 352588] [client 20.197.195.24:24067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/admin.php"] [unique_id "al9RlMJSWzG9jbYOtu48uAAAAKo"]
[Tue Jul 21 08:01:41.113097 2026] [security2:error] [pid 358661:tid 358859] [client 20.151.10.161:39875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/about.php"] [unique_id "al9RlQlWhjQfpOo60_HJ8wAAAEE"]
[Tue Jul 21 08:01:41.150267 2026] [security2:error] [pid 358661:tid 358748] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlQlWhjQfpOo60_HJ9AAADVM"]
[Tue Jul 21 08:01:41.150399 2026] [security2:error] [pid 358661:tid 358807] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlQlWhjQfpOo60_HJ9AAADVM"]
[Tue Jul 21 08:01:41.184502 2026] [security2:error] [pid 352421:tid 352678] [client 117.210.135.0:52800] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlcJSWzG9jbYOtu48uQAAAQQ"]
[Tue Jul 21 08:01:41.184604 2026] [security2:error] [pid 352421:tid 352678] [client 117.210.135.0:52800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlcJSWzG9jbYOtu48uQAAAQQ"]
[Tue Jul 21 08:01:41.188568 2026] [security2:error] [pid 358661:tid 358686] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlQlWhjQfpOo60_HJ9QAAXBU"]
[Tue Jul 21 08:01:41.188727 2026] [security2:error] [pid 358661:tid 358886] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlQlWhjQfpOo60_HJ9QAAXBU"]
[Tue Jul 21 08:01:41.600704 2026] [security2:error] [pid 358661:tid 358897] [client 41.68.90.219:58267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlQlWhjQfpOo60_HJ_gAAAGc"]
[Tue Jul 21 08:01:41.601725 2026] [security2:error] [pid 358661:tid 358897] [client 41.68.90.219:58267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlQlWhjQfpOo60_HJ_gAAAGc"]
[Tue Jul 21 08:01:41.680725 2026] [security2:error] [pid 352421:tid 352543] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RlcJSWzG9jbYOtu48wAAA5Xk"]
[Tue Jul 21 08:01:41.680935 2026] [security2:error] [pid 352421:tid 352647] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RlcJSWzG9jbYOtu48wAAA5Xk"]
[Tue Jul 21 08:01:41.764366 2026] [security2:error] [pid 352421:tid 352430] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlcJSWzG9jbYOtu48xAAA_gg"]
[Tue Jul 21 08:01:41.764506 2026] [security2:error] [pid 352421:tid 352672] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlcJSWzG9jbYOtu48xAAA_gg"]
[Tue Jul 21 08:01:41.794277 2026] [autoindex:error] [pid 352421:tid 352645] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:41.832871 2026] [security2:error] [pid 358661:tid 358895] [client 110.224.174.120:61027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.174.224.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9RlQlWhjQfpOo60_HJ_wAAAGU"]
[Tue Jul 21 08:01:41.833010 2026] [security2:error] [pid 358661:tid 358895] [client 110.224.174.120:61027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojadedoces.com"] [uri "/xmlrpc.php"] [unique_id "al9RlQlWhjQfpOo60_HJ_wAAAGU"]
[Tue Jul 21 08:01:41.908705 2026] [security2:error] [pid 352421:tid 352580] [client 38.100.221.102:19009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlcJSWzG9jbYOtu48xwAAAKI"]
[Tue Jul 21 08:01:41.908837 2026] [security2:error] [pid 352421:tid 352580] [client 38.100.221.102:19009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlcJSWzG9jbYOtu48xwAAAKI"]
[Tue Jul 21 08:01:41.988108 2026] [authz_core:error] [pid 352421:tid 352635] [client 85.204.70.102:43374] AH01630: client denied by server configuration: /home2/chri2452/public_html/wp-content/plugins/akismet/
[Tue Jul 21 08:01:42.152558 2026] [security2:error] [pid 358661:tid 358666] [remote 185.192.20.168:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "185.192.20.168" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "extrapro21.com"] [uri "/wp-comments-post.php"] [unique_id "al9RlglWhjQfpOo60_HKBwAAMgE"], referer: https://extrapro21.com/2025/11/26/hello-world/
[Tue Jul 21 08:01:42.152731 2026] [security2:error] [pid 358661:tid 358844] [client 185.192.20.168:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "extrapro21.com"] [uri "/wp-comments-post.php"] [unique_id "al9RlglWhjQfpOo60_HKBwAAMgE"], referer: https://extrapro21.com/2025/11/26/hello-world/
[Tue Jul 21 08:01:42.186911 2026] [autoindex:error] [pid 352421:tid 352624] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:42.215117 2026] [security2:error] [pid 358661:tid 358800] [client 184.75.221.3:44046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9RlglWhjQfpOo60_HKDQAAAAY"]
[Tue Jul 21 08:01:42.215242 2026] [security2:error] [pid 358661:tid 358800] [client 184.75.221.3:44046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9RlglWhjQfpOo60_HKDQAAAAY"]
[Tue Jul 21 08:01:42.385848 2026] [autoindex:error] [pid 352421:tid 352614] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:42.418891 2026] [security2:error] [pid 358661:tid 358840] [client 20.197.192.193:42177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/hp2.php"] [unique_id "al9RlglWhjQfpOo60_HKEAAAAC4"]
[Tue Jul 21 08:01:42.583692 2026] [autoindex:error] [pid 352421:tid 352581] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:42.600086 2026] [security2:error] [pid 358661:tid 358687] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlglWhjQfpOo60_HKFQAAEBY"]
[Tue Jul 21 08:01:42.600219 2026] [security2:error] [pid 358661:tid 358810] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlglWhjQfpOo60_HKFQAAEBY"]
[Tue Jul 21 08:01:42.709344 2026] [security2:error] [pid 358661:tid 358829] [client 175.144.82.48:58463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlglWhjQfpOo60_HKFwAAACM"]
[Tue Jul 21 08:01:42.710177 2026] [security2:error] [pid 358661:tid 358829] [client 175.144.82.48:58463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlglWhjQfpOo60_HKFwAAACM"]
[Tue Jul 21 08:01:42.783826 2026] [autoindex:error] [pid 352421:tid 352621] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:42.981303 2026] [autoindex:error] [pid 352421:tid 352552] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:43.180713 2026] [autoindex:error] [pid 352421:tid 352608] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:43.210867 2026] [security2:error] [pid 358661:tid 358850] [client 104.207.55.8:44603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.55.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RlwlWhjQfpOo60_HKIwAAADg"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:01:43.273062 2026] [security2:error] [pid 358661:tid 358714] [remote 40.77.167.101:48004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9RlwlWhjQfpOo60_HKIAAACDE"]
[Tue Jul 21 08:01:43.351889 2026] [security2:error] [pid 358661:tid 358828] [client 14.252.120.89:61321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.120.252.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9RlwlWhjQfpOo60_HKIQAAACI"]
[Tue Jul 21 08:01:43.352211 2026] [security2:error] [pid 358661:tid 358828] [client 14.252.120.89:61321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9RlwlWhjQfpOo60_HKIQAAACI"]
[Tue Jul 21 08:01:43.363931 2026] [security2:error] [pid 358661:tid 358842] [client 20.197.192.193:41582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/hp3.php"] [unique_id "al9RlwlWhjQfpOo60_HKJAAAADA"]
[Tue Jul 21 08:01:43.372234 2026] [security2:error] [pid 358661:tid 358879] [client 20.197.195.24:58480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/themes.php"] [unique_id "al9RlwlWhjQfpOo60_HKJQAAAFU"]
[Tue Jul 21 08:01:43.381731 2026] [autoindex:error] [pid 352421:tid 352619] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:43.437529 2026] [security2:error] [pid 358661:tid 358890] [client 20.226.60.151:59990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/for.php"] [unique_id "al9RlwlWhjQfpOo60_HKJgAAAGA"]
[Tue Jul 21 08:01:43.486891 2026] [security2:error] [pid 358661:tid 358723] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RlwlWhjQfpOo60_HKJwAAIDo"]
[Tue Jul 21 08:01:43.487024 2026] [security2:error] [pid 358661:tid 358826] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RlwlWhjQfpOo60_HKJwAAIDo"]
[Tue Jul 21 08:01:43.547607 2026] [security2:error] [pid 358661:tid 358909] [client 20.151.10.161:39867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/admin.php"] [unique_id "al9RlwlWhjQfpOo60_HKKgAAAHM"]
[Tue Jul 21 08:01:43.584010 2026] [autoindex:error] [pid 352421:tid 352563] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:43.613620 2026] [security2:error] [pid 352421:tid 352517] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Rl8JSWzG9jbYOtu483wAAwl8"]
[Tue Jul 21 08:01:43.613765 2026] [security2:error] [pid 352421:tid 352612] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Rl8JSWzG9jbYOtu483wAAwl8"]
[Tue Jul 21 08:01:43.700796 2026] [security2:error] [pid 358661:tid 358899] [client 120.56.162.40:59370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RlwlWhjQfpOo60_HKLQAAAGk"]
[Tue Jul 21 08:01:43.710288 2026] [security2:error] [pid 358661:tid 358823] [client 223.236.153.128:5032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RlwlWhjQfpOo60_HKMAAAAB0"]
[Tue Jul 21 08:01:43.714993 2026] [security2:error] [pid 358661:tid 358823] [client 223.236.153.128:5032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RlwlWhjQfpOo60_HKMAAAAB0"]
[Tue Jul 21 08:01:43.877012 2026] [security2:error] [pid 358661:tid 358888] [client 74.7.241.139:58464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.aud-7.com"] [uri "/index.php"] [unique_id "al9RlwlWhjQfpOo60_HKMQAAXmI"]
[Tue Jul 21 08:01:44.010028 2026] [autoindex:error] [pid 352421:tid 352639] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:44.210487 2026] [autoindex:error] [pid 352421:tid 352655] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:44.254697 2026] [security2:error] [pid 352421:tid 352589] [client 45.3.38.161:9977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.38.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RmMJSWzG9jbYOtu487wAAAKs"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:01:44.408090 2026] [autoindex:error] [pid 352421:tid 352598] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:44.495803 2026] [security2:error] [pid 358661:tid 358862] [client 37.140.223.68:43815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RmAlWhjQfpOo60_HKPAAAAEQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:01:44.599389 2026] [security2:error] [pid 358661:tid 358797] [client 65.21.113.253:55854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RmAlWhjQfpOo60_HKQwAAAAM"]
[Tue Jul 21 08:01:44.602497 2026] [security2:error] [pid 358661:tid 358836] [client 110.224.174.120:61046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.174.224.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojadoclimatizador.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmAlWhjQfpOo60_HKRAAAACo"]
[Tue Jul 21 08:01:44.606347 2026] [autoindex:error] [pid 352421:tid 352616] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:44.615963 2026] [security2:error] [pid 358661:tid 358836] [client 110.224.174.120:61046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lojadoclimatizador.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmAlWhjQfpOo60_HKRAAAACo"]
[Tue Jul 21 08:01:44.805501 2026] [autoindex:error] [pid 352421:tid 352617] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:44.820874 2026] [security2:error] [pid 358661:tid 358810] [client 65.21.113.253:46800] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RmAlWhjQfpOo60_HKPQAAABA"]
[Tue Jul 21 08:01:44.844914 2026] [security2:error] [pid 358661:tid 358691] [remote 124.55.178.99:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fidellium.com"] [uri "/wp-login.php"] [unique_id "al9RmAlWhjQfpOo60_HKSAAAFxo"]
[Tue Jul 21 08:01:45.004577 2026] [autoindex:error] [pid 352421:tid 352620] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:45.059287 2026] [security2:error] [pid 358661:tid 358808] [client 20.226.60.151:59974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/ssla.php"] [unique_id "al9RmQlWhjQfpOo60_HKSgAAAA4"]
[Tue Jul 21 08:01:45.164249 2026] [security2:error] [pid 358661:tid 358806] [client 20.151.10.161:39830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/edit.php"] [unique_id "al9RmQlWhjQfpOo60_HKTAAAAAw"]
[Tue Jul 21 08:01:45.240856 2026] [autoindex:error] [pid 352421:tid 352579] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:45.422033 2026] [security2:error] [pid 358661:tid 358909] [client 20.226.60.151:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lupipet.com"] [uri "/zc-131.php"] [unique_id "al9RmQlWhjQfpOo60_HKUAAAAHM"]
[Tue Jul 21 08:01:45.474956 2026] [autoindex:error] [pid 352421:tid 352601] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:45.687843 2026] [security2:error] [pid 358661:tid 358841] [client 65.21.113.253:46808] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RmQlWhjQfpOo60_HKTwAAAC8"]
[Tue Jul 21 08:01:45.757078 2026] [security2:error] [pid 358661:tid 358854] [client 20.104.96.117:27072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-blink.php"] [unique_id "al9RmQlWhjQfpOo60_HKUQAAADw"]
[Tue Jul 21 08:01:45.795135 2026] [security2:error] [pid 352421:tid 352444] [remote 18.61.192.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp/wp-login.php"] [unique_id "al9RmcJSWzG9jbYOtu49CAAAnBY"]
[Tue Jul 21 08:01:46.006780 2026] [autoindex:error] [pid 352421:tid 352568] [client 20.197.195.24:0] AH01276: Cannot serve directory /home1/meufla20/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:46.291427 2026] [security2:error] [pid 352421:tid 352560] [client 117.247.80.59:18542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmsJSWzG9jbYOtu49FwAAAI4"]
[Tue Jul 21 08:01:46.291620 2026] [security2:error] [pid 352421:tid 352560] [client 117.247.80.59:18542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmsJSWzG9jbYOtu49FwAAAI4"]
[Tue Jul 21 08:01:46.374022 2026] [security2:error] [pid 358661:tid 358809] [client 198.54.128.138:36040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9RmglWhjQfpOo60_HKXwAAAA8"]
[Tue Jul 21 08:01:46.374130 2026] [security2:error] [pid 358661:tid 358809] [client 198.54.128.138:36040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9RmglWhjQfpOo60_HKXwAAAA8"]
[Tue Jul 21 08:01:46.654837 2026] [security2:error] [pid 352421:tid 352611] [client 87.116.180.198:27383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmsJSWzG9jbYOtu49IQAAAME"]
[Tue Jul 21 08:01:46.659613 2026] [security2:error] [pid 352421:tid 352611] [client 87.116.180.198:27383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmsJSWzG9jbYOtu49IQAAAME"]
[Tue Jul 21 08:01:46.773992 2026] [security2:error] [pid 352421:tid 352590] [client 202.143.127.214:50731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmsJSWzG9jbYOtu49JQAAAKw"]
[Tue Jul 21 08:01:46.774106 2026] [security2:error] [pid 352421:tid 352590] [client 202.143.127.214:50731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmsJSWzG9jbYOtu49JQAAAKw"]
[Tue Jul 21 08:01:46.782575 2026] [security2:error] [pid 358661:tid 358892] [client 20.151.10.161:39829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9RmglWhjQfpOo60_HKYAAAAGI"]
[Tue Jul 21 08:01:46.832978 2026] [security2:error] [pid 358661:tid 358838] [client 103.86.117.203:65410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RmglWhjQfpOo60_HKYQAAACw"]
[Tue Jul 21 08:01:46.833116 2026] [security2:error] [pid 358661:tid 358838] [client 103.86.117.203:65410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RmglWhjQfpOo60_HKYQAAACw"]
[Tue Jul 21 08:01:46.836381 2026] [security2:error] [pid 352421:tid 352626] [client 106.215.181.8:26103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmsJSWzG9jbYOtu49JwAAANA"]
[Tue Jul 21 08:01:46.836616 2026] [security2:error] [pid 352421:tid 352626] [client 106.215.181.8:26103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmsJSWzG9jbYOtu49JwAAANA"]
[Tue Jul 21 08:01:46.899010 2026] [security2:error] [pid 358661:tid 358912] [client 103.78.200.11:51131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmglWhjQfpOo60_HKYgAAAHY"]
[Tue Jul 21 08:01:46.899186 2026] [security2:error] [pid 358661:tid 358912] [client 103.78.200.11:51131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmglWhjQfpOo60_HKYgAAAHY"]
[Tue Jul 21 08:01:47.003778 2026] [security2:error] [pid 358661:tid 358852] [client 178.128.110.71:51006] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "piskefotografia.com"] [uri "/license.txt"] [unique_id "al9RmwlWhjQfpOo60_HKYwAAADo"]
[Tue Jul 21 08:01:47.115799 2026] [fcgid:warn] [pid 358661:tid 358862] (70014)End of file found: [client 165.154.182.168:54098] mod_fcgid: can't get data from http client
[Tue Jul 21 08:01:47.364454 2026] [security2:error] [pid 352421:tid 352633] [client 20.104.96.117:27082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/zc-208.php"] [unique_id "al9Rm8JSWzG9jbYOtu49MAAAANc"]
[Tue Jul 21 08:01:47.390416 2026] [security2:error] [pid 358661:tid 358824] [client 102.206.115.33:57800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RmwlWhjQfpOo60_HKawAAAB4"]
[Tue Jul 21 08:01:47.390570 2026] [security2:error] [pid 358661:tid 358824] [client 102.206.115.33:57800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RmwlWhjQfpOo60_HKawAAAB4"]
[Tue Jul 21 08:01:47.537556 2026] [autoindex:error] [pid 352421:tid 352558] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-content/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:47.614849 2026] [security2:error] [pid 358661:tid 358872] [client 109.60.28.94:54332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmwlWhjQfpOo60_HKbQAAAE4"]
[Tue Jul 21 08:01:47.614945 2026] [security2:error] [pid 358661:tid 358872] [client 109.60.28.94:54332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmwlWhjQfpOo60_HKbQAAAE4"]
[Tue Jul 21 08:01:47.715352 2026] [fcgid:warn] [pid 358661:tid 358895] (70014)End of file found: [client 165.154.182.168:54756] mod_fcgid: can't get data from http client
[Tue Jul 21 08:01:47.885382 2026] [security2:error] [pid 358661:tid 358832] [client 103.29.114.44:61422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmwlWhjQfpOo60_HKfAAAACY"]
[Tue Jul 21 08:01:47.885484 2026] [security2:error] [pid 358661:tid 358832] [client 103.29.114.44:61422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RmwlWhjQfpOo60_HKfAAAACY"]
[Tue Jul 21 08:01:47.911299 2026] [security2:error] [pid 358661:tid 358778] [remote 68.178.160.25:56142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9RmwlWhjQfpOo60_HKfQAAOHE"]
[Tue Jul 21 08:01:47.911474 2026] [security2:error] [pid 358661:tid 358850] [client 68.178.160.25:56142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9RmwlWhjQfpOo60_HKfQAAOHE"]
[Tue Jul 21 08:01:48.449147 2026] [autoindex:error] [pid 352421:tid 352575] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:48.555030 2026] [security2:error] [pid 358661:tid 358840] [client 184.75.221.3:53690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9RnAlWhjQfpOo60_HKhQAAAC4"]
[Tue Jul 21 08:01:48.555111 2026] [security2:error] [pid 358661:tid 358840] [client 184.75.221.3:53690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9RnAlWhjQfpOo60_HKhQAAAC4"]
[Tue Jul 21 08:01:48.590938 2026] [security2:error] [pid 358661:tid 358809] [client 20.197.195.24:24179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/.well-known/about.php"] [unique_id "al9RnAlWhjQfpOo60_HKhgAAAA8"]
[Tue Jul 21 08:01:48.712834 2026] [fcgid:warn] [pid 358661:tid 358892] (70014)End of file found: [client 165.154.182.168:55016] mod_fcgid: can't get data from http client
[Tue Jul 21 08:01:48.783785 2026] [security2:error] [pid 358661:tid 358771] [remote 192.241.143.148:60008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/wp-login.php"] [unique_id "al9RnAlWhjQfpOo60_HKiQAAfWo"]
[Tue Jul 21 08:01:48.891738 2026] [security2:error] [pid 358661:tid 358906] [client 20.104.96.117:46612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/sid4.php"] [unique_id "al9RnAlWhjQfpOo60_HKjwAAAHA"]
[Tue Jul 21 08:01:49.118411 2026] [core:error] [pid 358661:tid 358898] [client 87.250.224.122:46148] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:01:49.118431 2026] [core:error] [pid 358661:tid 358898] [client 87.250.224.122:46148] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:01:49.185121 2026] [security2:error] [pid 352421:tid 352580] [client 123.253.49.184:50334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.49.253.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9RncJSWzG9jbYOtu49TAAAAKI"]
[Tue Jul 21 08:01:49.185292 2026] [security2:error] [pid 352421:tid 352580] [client 123.253.49.184:50334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9RncJSWzG9jbYOtu49TAAAAKI"]
[Tue Jul 21 08:01:49.413415 2026] [security2:error] [pid 358661:tid 358857] [client 20.197.195.24:58954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9RnQlWhjQfpOo60_HKmQAAAD8"]
[Tue Jul 21 08:01:49.528097 2026] [security2:error] [pid 358661:tid 358908] [client 172.245.102.46:59191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RnQlWhjQfpOo60_HKlwAAAHI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:01:49.643912 2026] [security2:error] [pid 358661:tid 358801] [client 103.166.103.129:49938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RnQlWhjQfpOo60_HKngAAAAc"]
[Tue Jul 21 08:01:49.644089 2026] [security2:error] [pid 358661:tid 358801] [client 103.166.103.129:49938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RnQlWhjQfpOo60_HKngAAAAc"]
[Tue Jul 21 08:01:49.799595 2026] [autoindex:error] [pid 358661:tid 358856] [client 20.104.96.117:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:49.998179 2026] [security2:error] [pid 358661:tid 358872] [client 182.8.255.181:21062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RnQlWhjQfpOo60_HKqQAAAE4"]
[Tue Jul 21 08:01:49.998323 2026] [security2:error] [pid 358661:tid 358872] [client 182.8.255.181:21062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RnQlWhjQfpOo60_HKqQAAAE4"]
[Tue Jul 21 08:01:50.075927 2026] [security2:error] [pid 358661:tid 358864] [client 20.104.96.117:27106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wmore1.php"] [unique_id "al9RnglWhjQfpOo60_HKqwAAAEY"]
[Tue Jul 21 08:01:50.276448 2026] [security2:error] [pid 358661:tid 358880] [client 198.54.128.138:55672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9RnglWhjQfpOo60_HKrgAAAFY"]
[Tue Jul 21 08:01:50.276629 2026] [security2:error] [pid 358661:tid 358880] [client 198.54.128.138:55672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9RnglWhjQfpOo60_HKrgAAAFY"]
[Tue Jul 21 08:01:50.293490 2026] [security2:error] [pid 352421:tid 352560] [client 122.179.91.63:25377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RnsJSWzG9jbYOtu49XQAAAI4"]
[Tue Jul 21 08:01:50.293719 2026] [security2:error] [pid 352421:tid 352560] [client 122.179.91.63:25377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RnsJSWzG9jbYOtu49XQAAAI4"]
[Tue Jul 21 08:01:50.328703 2026] [security2:error] [pid 358661:tid 358912] [client 20.151.10.161:39910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/f6.php"] [unique_id "al9RnglWhjQfpOo60_HKsAAAAHY"]
[Tue Jul 21 08:01:50.454141 2026] [security2:error] [pid 358661:tid 358810] [client 20.197.192.193:56798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/x.php"] [unique_id "al9RnglWhjQfpOo60_HKtQAAABA"]
[Tue Jul 21 08:01:50.454685 2026] [security2:error] [pid 358661:tid 358817] [client 20.197.195.24:58978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wefile.php"] [unique_id "al9RnglWhjQfpOo60_HKtgAAABc"]
[Tue Jul 21 08:01:50.545352 2026] [security2:error] [pid 352421:tid 352448] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RnsJSWzG9jbYOtu49YgAAsxo"]
[Tue Jul 21 08:01:50.545506 2026] [security2:error] [pid 352421:tid 352597] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RnsJSWzG9jbYOtu49YgAAsxo"]
[Tue Jul 21 08:01:50.887395 2026] [security2:error] [pid 358661:tid 358795] [client 85.204.70.102:49420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wp-login.php"] [unique_id "al9RnglWhjQfpOo60_HKxQAAAAE"]
[Tue Jul 21 08:01:51.013460 2026] [security2:error] [pid 358661:tid 358822] [client 178.153.91.96:22765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RnwlWhjQfpOo60_HKygAAABw"]
[Tue Jul 21 08:01:51.015970 2026] [security2:error] [pid 358661:tid 358822] [client 178.153.91.96:22765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RnwlWhjQfpOo60_HKygAAABw"]
[Tue Jul 21 08:01:51.058769 2026] [security2:error] [pid 352421:tid 352666] [client 184.75.221.3:59362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Rn8JSWzG9jbYOtu49bQAAAPg"]
[Tue Jul 21 08:01:51.058876 2026] [security2:error] [pid 352421:tid 352666] [client 184.75.221.3:59362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Rn8JSWzG9jbYOtu49bQAAAPg"]
[Tue Jul 21 08:01:51.530461 2026] [security2:error] [pid 358661:tid 358875] [client 20.197.195.24:58992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9RnwlWhjQfpOo60_HKzQAAAFE"]
[Tue Jul 21 08:01:51.710913 2026] [security2:error] [pid 352421:tid 352646] [client 65.21.113.253:54986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Rn8JSWzG9jbYOtu49cQAAAOQ"]
[Tue Jul 21 08:01:51.807316 2026] [security2:error] [pid 352421:tid 352650] [client 184.75.221.3:59374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Rn8JSWzG9jbYOtu49fAAAAOg"]
[Tue Jul 21 08:01:51.807446 2026] [security2:error] [pid 352421:tid 352650] [client 184.75.221.3:59374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Rn8JSWzG9jbYOtu49fAAAAOg"]
[Tue Jul 21 08:01:51.845261 2026] [security2:error] [pid 358661:tid 358737] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RnwlWhjQfpOo60_HK4QAACUg"]
[Tue Jul 21 08:01:51.845411 2026] [security2:error] [pid 358661:tid 358803] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RnwlWhjQfpOo60_HK4QAACUg"]
[Tue Jul 21 08:01:51.940907 2026] [security2:error] [pid 358661:tid 358872] [client 85.204.70.102:37456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wp-login.php"] [unique_id "al9RnwlWhjQfpOo60_HK5QAAAE4"]
[Tue Jul 21 08:01:52.022240 2026] [security2:error] [pid 352421:tid 352555] [client 20.104.96.117:46617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/solo1.php"] [unique_id "al9RoMJSWzG9jbYOtu49gAAAAIk"]
[Tue Jul 21 08:01:52.031145 2026] [security2:error] [pid 352421:tid 352596] [client 117.210.135.0:53505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rn8JSWzG9jbYOtu49fQAAALI"]
[Tue Jul 21 08:01:52.031291 2026] [security2:error] [pid 352421:tid 352596] [client 117.210.135.0:53505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rn8JSWzG9jbYOtu49fQAAALI"]
[Tue Jul 21 08:01:52.095040 2026] [security2:error] [pid 358661:tid 358788] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RoAlWhjQfpOo60_HK5gAASns"]
[Tue Jul 21 08:01:52.095168 2026] [security2:error] [pid 358661:tid 358868] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RoAlWhjQfpOo60_HK5gAASns"]
[Tue Jul 21 08:01:52.132640 2026] [security2:error] [pid 352421:tid 352503] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RoMJSWzG9jbYOtu49hQAAsVE"]
[Tue Jul 21 08:01:52.132774 2026] [security2:error] [pid 352421:tid 352595] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RoMJSWzG9jbYOtu49hQAAsVE"]
[Tue Jul 21 08:01:52.206731 2026] [autoindex:error] [pid 352421:tid 352675] [client 20.197.195.24:0] AH01276: Cannot serve directory /home1/meufla20/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:52.234305 2026] [security2:error] [pid 352421:tid 352557] [client 92.119.178.3:60126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9RoMJSWzG9jbYOtu49iwAAAIs"]
[Tue Jul 21 08:01:52.234427 2026] [security2:error] [pid 352421:tid 352557] [client 92.119.178.3:60126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9RoMJSWzG9jbYOtu49iwAAAIs"]
[Tue Jul 21 08:01:52.276733 2026] [autoindex:error] [pid 352421:tid 352584] [client 20.197.195.24:24181] AH01276: Cannot serve directory /home1/meufla20/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:52.284478 2026] [security2:error] [pid 352421:tid 352614] [client 20.197.195.24:24181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9RoMJSWzG9jbYOtu49jQAAAMQ"]
[Tue Jul 21 08:01:52.291998 2026] [security2:error] [pid 352421:tid 352467] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RoMJSWzG9jbYOtu49jgAAuC0"]
[Tue Jul 21 08:01:52.292252 2026] [security2:error] [pid 352421:tid 352602] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RoMJSWzG9jbYOtu49jgAAuC0"]
[Tue Jul 21 08:01:52.301365 2026] [security2:error] [pid 352421:tid 352581] [client 20.151.10.161:39838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/inputs.php"] [unique_id "al9RoMJSWzG9jbYOtu49jwAAAKM"]
[Tue Jul 21 08:01:52.321889 2026] [security2:error] [pid 352421:tid 352620] [client 41.68.90.219:58732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RoMJSWzG9jbYOtu49kAAAAMo"]
[Tue Jul 21 08:01:52.322526 2026] [security2:error] [pid 352421:tid 352620] [client 41.68.90.219:58732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RoMJSWzG9jbYOtu49kAAAAMo"]
[Tue Jul 21 08:01:52.436783 2026] [security2:error] [pid 358661:tid 358912] [client 20.197.192.193:42185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/aa1.php"] [unique_id "al9RoAlWhjQfpOo60_HK7QAAAHY"]
[Tue Jul 21 08:01:52.466477 2026] [security2:error] [pid 352421:tid 352623] [client 38.100.221.102:17590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RoMJSWzG9jbYOtu49lQAAAM0"]
[Tue Jul 21 08:01:52.466623 2026] [security2:error] [pid 352421:tid 352623] [client 38.100.221.102:17590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RoMJSWzG9jbYOtu49lQAAAM0"]
[Tue Jul 21 08:01:52.761332 2026] [security2:error] [pid 352421:tid 352462] [remote 102.134.101.35:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9RoMJSWzG9jbYOtu49nAAAvig"]
[Tue Jul 21 08:01:52.797250 2026] [autoindex:error] [pid 352421:tid 352571] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:53.106231 2026] [security2:error] [pid 352421:tid 352579] [client 193.36.225.64:43601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RocJSWzG9jbYOtu49pQAAAKE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:01:53.167795 2026] [security2:error] [pid 358661:tid 358852] [client 175.144.82.48:58888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RoQlWhjQfpOo60_HK-wAAADo"]
[Tue Jul 21 08:01:53.168675 2026] [security2:error] [pid 358661:tid 358852] [client 175.144.82.48:58888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RoQlWhjQfpOo60_HK-wAAADo"]
[Tue Jul 21 08:01:53.273195 2026] [security2:error] [pid 358661:tid 358668] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RoQlWhjQfpOo60_HK_AAAYAM"]
[Tue Jul 21 08:01:53.273531 2026] [security2:error] [pid 358661:tid 358890] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RoQlWhjQfpOo60_HK_AAAYAM"]
[Tue Jul 21 08:01:53.509023 2026] [security2:error] [pid 352421:tid 352564] [client 20.197.195.24:24150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/8.php"] [unique_id "al9RocJSWzG9jbYOtu49qAAAAJI"]
[Tue Jul 21 08:01:53.616313 2026] [security2:error] [pid 358661:tid 358877] [client 20.151.10.161:39811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/av.php"] [unique_id "al9RoQlWhjQfpOo60_HLAAAAAFM"]
[Tue Jul 21 08:01:53.772804 2026] [security2:error] [pid 358661:tid 358848] [client 65.21.113.253:60826] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RoQlWhjQfpOo60_HLAQAAADY"]
[Tue Jul 21 08:01:53.827222 2026] [autoindex:error] [pid 358661:tid 358867] [client 20.104.96.117:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:53.853612 2026] [security2:error] [pid 352421:tid 352633] [client 85.204.70.102:37464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wp-login.php"] [unique_id "al9RocJSWzG9jbYOtu49sAAAANc"]
[Tue Jul 21 08:01:54.051501 2026] [autoindex:error] [pid 352421:tid 352562] [client 85.204.70.102:43374] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:54.103936 2026] [security2:error] [pid 358661:tid 358888] [client 20.104.96.117:46647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/cong.php"] [unique_id "al9RoglWhjQfpOo60_HLBgAAAF4"]
[Tue Jul 21 08:01:54.156355 2026] [security2:error] [pid 358661:tid 358706] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RoglWhjQfpOo60_HLCAAATCk"]
[Tue Jul 21 08:01:54.156506 2026] [security2:error] [pid 358661:tid 358870] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RoglWhjQfpOo60_HLCAAATCk"]
[Tue Jul 21 08:01:54.193474 2026] [security2:error] [pid 358661:tid 358665] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RoglWhjQfpOo60_HLCQAAOwA"]
[Tue Jul 21 08:01:54.193625 2026] [security2:error] [pid 358661:tid 358853] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RoglWhjQfpOo60_HLCQAAOwA"]
[Tue Jul 21 08:01:54.250098 2026] [security2:error] [pid 358661:tid 358879] [client 223.236.153.128:7395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RoglWhjQfpOo60_HLCgAAAFU"]
[Tue Jul 21 08:01:54.250239 2026] [security2:error] [pid 358661:tid 358879] [client 223.236.153.128:7395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RoglWhjQfpOo60_HLCgAAAFU"]
[Tue Jul 21 08:01:54.375909 2026] [security2:error] [pid 358661:tid 358822] [client 120.56.162.40:59781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RoglWhjQfpOo60_HLCwAAABw"]
[Tue Jul 21 08:01:54.442475 2026] [security2:error] [pid 352421:tid 352674] [client 65.21.113.253:54986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RosJSWzG9jbYOtu49sgAAAQA"]
[Tue Jul 21 08:01:54.480875 2026] [security2:error] [pid 358661:tid 358857] [client 20.151.10.161:39870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/classwithtostring.php"] [unique_id "al9RoglWhjQfpOo60_HLDAAAAD8"]
[Tue Jul 21 08:01:54.881994 2026] [security2:error] [pid 352421:tid 352498] [remote 182.77.62.24:50972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dener.design"] [uri "/wp-login.php"] [unique_id "al9RocJSWzG9jbYOtu49sQAAl0w"]
[Tue Jul 21 08:01:55.028745 2026] [security2:error] [pid 352421:tid 352558] [client 45.3.44.102:19703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9Ro8JSWzG9jbYOtu49vgAAAIw"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:01:55.308326 2026] [security2:error] [pid 358661:tid 358840] [client 20.151.10.161:39896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9RowlWhjQfpOo60_HLFwAAAC4"]
[Tue Jul 21 08:01:55.426196 2026] [security2:error] [pid 358661:tid 358802] [client 20.197.195.24:11030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9RowlWhjQfpOo60_HLHAAAAAg"]
[Tue Jul 21 08:01:55.844352 2026] [security2:error] [pid 352421:tid 352623] [client 20.151.10.161:39866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-blog.php"] [unique_id "al9Ro8JSWzG9jbYOtu49zAAAAM0"]
[Tue Jul 21 08:01:55.967110 2026] [security2:error] [pid 358661:tid 358846] [client 92.119.178.3:60142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9RowlWhjQfpOo60_HLJAAAADQ"]
[Tue Jul 21 08:01:55.967223 2026] [security2:error] [pid 358661:tid 358846] [client 92.119.178.3:60142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9RowlWhjQfpOo60_HLJAAAADQ"]
[Tue Jul 21 08:01:56.484202 2026] [security2:error] [pid 358661:tid 358901] [client 20.197.192.193:42190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/acew67.php"] [unique_id "al9RpAlWhjQfpOo60_HLKAAAAGs"]
[Tue Jul 21 08:01:56.693692 2026] [security2:error] [pid 352421:tid 352556] [client 20.197.195.24:58986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/f6.php"] [unique_id "al9RpMJSWzG9jbYOtu492AAAAIo"]
[Tue Jul 21 08:01:56.807715 2026] [security2:error] [pid 352421:tid 352636] [client 72.60.201.51:51164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "criatividadepedagogica.com"] [uri "/.git/config"] [unique_id "al9RpMJSWzG9jbYOtu492gAAANo"]
[Tue Jul 21 08:01:57.128539 2026] [security2:error] [pid 358661:tid 358867] [client 117.247.80.59:18990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RpQlWhjQfpOo60_HLNgAAAEk"]
[Tue Jul 21 08:01:57.128698 2026] [security2:error] [pid 358661:tid 358867] [client 117.247.80.59:18990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RpQlWhjQfpOo60_HLNgAAAEk"]
[Tue Jul 21 08:01:57.312168 2026] [security2:error] [pid 352421:tid 352608] [client 103.86.117.203:49577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RpcJSWzG9jbYOtu495QAAAL4"]
[Tue Jul 21 08:01:57.312368 2026] [security2:error] [pid 352421:tid 352608] [client 103.86.117.203:49577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RpcJSWzG9jbYOtu495QAAAL4"]
[Tue Jul 21 08:01:57.340368 2026] [security2:error] [pid 358661:tid 358903] [client 87.116.180.198:27271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RpQlWhjQfpOo60_HLOgAAAG0"]
[Tue Jul 21 08:01:57.340576 2026] [security2:error] [pid 358661:tid 358903] [client 87.116.180.198:27271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RpQlWhjQfpOo60_HLOgAAAG0"]
[Tue Jul 21 08:01:57.393866 2026] [security2:error] [pid 358661:tid 358799] [client 193.36.225.68:63965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RpQlWhjQfpOo60_HLOwAAAAU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:01:57.411327 2026] [security2:error] [pid 358661:tid 358888] [client 106.215.181.8:14951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RpQlWhjQfpOo60_HLPAAAAF4"]
[Tue Jul 21 08:01:57.411472 2026] [security2:error] [pid 358661:tid 358888] [client 106.215.181.8:14951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RpQlWhjQfpOo60_HLPAAAAF4"]
[Tue Jul 21 08:01:57.568573 2026] [security2:error] [pid 358661:tid 358891] [client 20.151.10.161:39907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9RpQlWhjQfpOo60_HLPQAAAGE"]
[Tue Jul 21 08:01:57.707627 2026] [security2:error] [pid 358661:tid 358884] [client 103.78.200.11:51614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RpQlWhjQfpOo60_HLPgAAAFo"]
[Tue Jul 21 08:01:57.708698 2026] [security2:error] [pid 358661:tid 358884] [client 103.78.200.11:51614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RpQlWhjQfpOo60_HLPgAAAFo"]
[Tue Jul 21 08:01:57.840100 2026] [security2:error] [pid 358661:tid 358803] [client 202.143.127.214:51205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RpQlWhjQfpOo60_HLRAAAAAk"]
[Tue Jul 21 08:01:57.840224 2026] [security2:error] [pid 358661:tid 358803] [client 202.143.127.214:51205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RpQlWhjQfpOo60_HLRAAAAAk"]
[Tue Jul 21 08:01:57.909270 2026] [security2:error] [pid 352421:tid 352588] [client 102.206.115.33:58265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RpcJSWzG9jbYOtu498AAAAKo"]
[Tue Jul 21 08:01:57.909411 2026] [security2:error] [pid 352421:tid 352588] [client 102.206.115.33:58265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RpcJSWzG9jbYOtu498AAAAKo"]
[Tue Jul 21 08:01:58.210901 2026] [security2:error] [pid 352421:tid 352583] [client 20.197.195.24:58434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/inputs.php"] [unique_id "al9RpsJSWzG9jbYOtu498wAAAKU"]
[Tue Jul 21 08:01:58.407937 2026] [fcgid:warn] [pid 358661:tid 358910] (70014)End of file found: [client 165.154.182.168:47494] mod_fcgid: can't get data from http client
[Tue Jul 21 08:01:58.496997 2026] [security2:error] [pid 358661:tid 358797] [client 103.29.114.44:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RpglWhjQfpOo60_HLVQAAAAM"]
[Tue Jul 21 08:01:58.497117 2026] [security2:error] [pid 358661:tid 358797] [client 103.29.114.44:55224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RpglWhjQfpOo60_HLVQAAAAM"]
[Tue Jul 21 08:01:58.531689 2026] [autoindex:error] [pid 358661:tid 358765] [remote 170.82.90.217:19025] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/?pag=aluno_chamada
[Tue Jul 21 08:01:58.564352 2026] [security2:error] [pid 358661:tid 358858] [client 109.60.28.94:58445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RpglWhjQfpOo60_HLVwAAAEA"]
[Tue Jul 21 08:01:58.564489 2026] [security2:error] [pid 358661:tid 358858] [client 109.60.28.94:58445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RpglWhjQfpOo60_HLVwAAAEA"]
[Tue Jul 21 08:01:58.615453 2026] [security2:error] [pid 358661:tid 358843] [client 204.8.98.45:37306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9RpglWhjQfpOo60_HLWQAAADE"]
[Tue Jul 21 08:01:58.615565 2026] [security2:error] [pid 358661:tid 358843] [client 204.8.98.45:37306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9RpglWhjQfpOo60_HLWQAAADE"]
[Tue Jul 21 08:01:58.694559 2026] [access_compat:error] [pid 358661:tid 358807] [client 162.241.63.68:17648] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:01:58.804221 2026] [security2:error] [pid 358661:tid 358834] [client 20.151.10.161:39892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/adminfuns.php"] [unique_id "al9RpglWhjQfpOo60_HLXQAAACg"]
[Tue Jul 21 08:01:58.834058 2026] [security2:error] [pid 358661:tid 358892] [client 65.21.113.253:54994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RpglWhjQfpOo60_HLUQAAAGI"]
[Tue Jul 21 08:01:59.222198 2026] [security2:error] [pid 352421:tid 352488] [remote 152.42.185.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.185.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Rp8JSWzG9jbYOtu4-AgAAy0I"]
[Tue Jul 21 08:01:59.243082 2026] [security2:error] [pid 352421:tid 352527] [remote 154.61.75.100:35412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rp8JSWzG9jbYOtu4-BQAAyGk"]
[Tue Jul 21 08:01:59.243216 2026] [security2:error] [pid 352421:tid 352618] [client 154.61.75.100:35412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rp8JSWzG9jbYOtu4-BQAAyGk"]
[Tue Jul 21 08:01:59.249845 2026] [core:alert] [pid 358661:tid 358829] [client 57.141.18.59:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:01:59.424781 2026] [security2:error] [pid 352421:tid 352568] [client 45.45.237.7:49292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/.git/config"] [unique_id "al9Rp8JSWzG9jbYOtu4-CAAAAJY"]
[Tue Jul 21 08:01:59.424911 2026] [security2:error] [pid 352421:tid 352568] [client 45.45.237.7:49292] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kvengenharia.com"] [uri "/.git/config"] [unique_id "al9Rp8JSWzG9jbYOtu4-CAAAAJY"]
[Tue Jul 21 08:01:59.523667 2026] [autoindex:error] [pid 352421:tid 352668] [client 20.104.96.117:0] AH01276: Cannot serve directory /home1/asse7722/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:01:59.800910 2026] [security2:error] [pid 358661:tid 358810] [client 20.104.96.117:27414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/public/css.php"] [unique_id "al9RpwlWhjQfpOo60_HLbQAAABA"]
[Tue Jul 21 08:02:00.003587 2026] [security2:error] [pid 358661:tid 358837] [client 20.197.195.24:24183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/inputs.php"] [unique_id "al9RqAlWhjQfpOo60_HLcgAAACs"]
[Tue Jul 21 08:02:00.137232 2026] [security2:error] [pid 358661:tid 358888] [client 103.166.103.129:12377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RqAlWhjQfpOo60_HLdAAAAF4"]
[Tue Jul 21 08:02:00.137348 2026] [security2:error] [pid 358661:tid 358888] [client 103.166.103.129:12377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RqAlWhjQfpOo60_HLdAAAAF4"]
[Tue Jul 21 08:02:00.276428 2026] [security2:error] [pid 352421:tid 352661] [client 20.197.192.193:56795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9RqMJSWzG9jbYOtu4-FQAAAPM"]
[Tue Jul 21 08:02:00.299395 2026] [security2:error] [pid 358661:tid 358912] [client 182.8.255.181:21099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RqAlWhjQfpOo60_HLdgAAAHY"]
[Tue Jul 21 08:02:00.299587 2026] [security2:error] [pid 358661:tid 358912] [client 182.8.255.181:21099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RqAlWhjQfpOo60_HLdgAAAHY"]
[Tue Jul 21 08:02:00.342040 2026] [security2:error] [pid 352421:tid 352580] [client 65.21.113.253:47460] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RqMJSWzG9jbYOtu4-FwAAAKI"]
[Tue Jul 21 08:02:00.450641 2026] [security2:error] [pid 352421:tid 352610] [client 20.151.10.161:39857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/goods.php"] [unique_id "al9RqMJSWzG9jbYOtu4-GAAAAMA"]
[Tue Jul 21 08:02:00.497763 2026] [security2:error] [pid 358661:tid 358903] [client 45.45.237.7:49308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/.git/HEAD"] [unique_id "al9RqAlWhjQfpOo60_HLewAAAG0"]
[Tue Jul 21 08:02:00.497893 2026] [security2:error] [pid 358661:tid 358903] [client 45.45.237.7:49308] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kvengenharia.com"] [uri "/.git/HEAD"] [unique_id "al9RqAlWhjQfpOo60_HLewAAAG0"]
[Tue Jul 21 08:02:00.771458 2026] [autoindex:error] [pid 358661:tid 358755] [remote 170.82.90.217:19025] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/?pag=chamada_consulta&modal=chamada&chamada=451
[Tue Jul 21 08:02:00.947163 2026] [security2:error] [pid 358661:tid 358871] [client 65.21.113.253:54994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RqAlWhjQfpOo60_HLfAAAAE0"]
[Tue Jul 21 08:02:01.177208 2026] [security2:error] [pid 358661:tid 358920] [client 20.104.96.117:46637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/output.php"] [unique_id "al9RqQlWhjQfpOo60_HLhgAAAH4"]
[Tue Jul 21 08:02:01.195076 2026] [security2:error] [pid 358661:tid 358698] [remote 91.142.222.105:39338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinadona.com"] [uri "/wp-login.php"] [unique_id "al9RqQlWhjQfpOo60_HLhwAAbyE"]
[Tue Jul 21 08:02:01.298752 2026] [security2:error] [pid 352421:tid 352674] [client 20.197.195.24:11124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/classwithtostring.php"] [unique_id "al9RqcJSWzG9jbYOtu4-HgAAAQA"]
[Tue Jul 21 08:02:01.469273 2026] [security2:error] [pid 358661:tid 358773] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RqQlWhjQfpOo60_HLjAAAeWw"]
[Tue Jul 21 08:02:01.469539 2026] [security2:error] [pid 358661:tid 358915] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RqQlWhjQfpOo60_HLjAAAeWw"]
[Tue Jul 21 08:02:01.569233 2026] [security2:error] [pid 358661:tid 358884] [client 136.144.33.99:57781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RqQlWhjQfpOo60_HLigAAAFo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:02:01.589923 2026] [security2:error] [pid 358661:tid 358813] [client 20.151.10.161:39818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/ms-edit.php"] [unique_id "al9RqQlWhjQfpOo60_HLjQAAABM"]
[Tue Jul 21 08:02:01.670185 2026] [security2:error] [pid 358661:tid 358918] [client 178.153.91.96:62760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RqQlWhjQfpOo60_HLjgAAAHw"]
[Tue Jul 21 08:02:01.670330 2026] [security2:error] [pid 358661:tid 358918] [client 178.153.91.96:62760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RqQlWhjQfpOo60_HLjgAAAHw"]
[Tue Jul 21 08:02:01.759006 2026] [security2:error] [pid 358661:tid 358831] [client 198.54.128.138:36968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9RqQlWhjQfpOo60_HLkgAAACU"]
[Tue Jul 21 08:02:01.759108 2026] [security2:error] [pid 358661:tid 358831] [client 198.54.128.138:36968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9RqQlWhjQfpOo60_HLkgAAACU"]
[Tue Jul 21 08:02:02.228846 2026] [security2:error] [pid 358661:tid 358919] [client 122.179.91.63:30611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RqglWhjQfpOo60_HLlwAAAH0"]
[Tue Jul 21 08:02:02.228995 2026] [security2:error] [pid 358661:tid 358919] [client 122.179.91.63:30611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RqglWhjQfpOo60_HLlwAAAH0"]
[Tue Jul 21 08:02:02.388177 2026] [security2:error] [pid 352421:tid 352613] [client 20.197.195.24:24189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9RqsJSWzG9jbYOtu4-NAAAAMM"]
[Tue Jul 21 08:02:02.401159 2026] [security2:error] [pid 358661:tid 358860] [client 117.210.135.0:54200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RqglWhjQfpOo60_HLmQAAAEI"]
[Tue Jul 21 08:02:02.401306 2026] [security2:error] [pid 358661:tid 358860] [client 117.210.135.0:54200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RqglWhjQfpOo60_HLmQAAAEI"]
[Tue Jul 21 08:02:02.527061 2026] [security2:error] [pid 358661:tid 358873] [client 20.151.10.161:39846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/222.php"] [unique_id "al9RqglWhjQfpOo60_HLmwAAAE8"]
[Tue Jul 21 08:02:02.585883 2026] [security2:error] [pid 358661:tid 358747] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RqglWhjQfpOo60_HLnAAASFI"]
[Tue Jul 21 08:02:02.586061 2026] [security2:error] [pid 358661:tid 358866] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RqglWhjQfpOo60_HLnAAASFI"]
[Tue Jul 21 08:02:02.609710 2026] [security2:error] [pid 352421:tid 352442] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RqsJSWzG9jbYOtu4-PQAA7RQ"]
[Tue Jul 21 08:02:02.609913 2026] [security2:error] [pid 352421:tid 352655] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RqsJSWzG9jbYOtu4-PQAA7RQ"]
[Tue Jul 21 08:02:02.766680 2026] [security2:error] [pid 352421:tid 352448] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RqsJSWzG9jbYOtu4-PgAAiho"]
[Tue Jul 21 08:02:02.766806 2026] [security2:error] [pid 352421:tid 352556] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RqsJSWzG9jbYOtu4-PgAAiho"]
[Tue Jul 21 08:02:02.887930 2026] [security2:error] [pid 358661:tid 358827] [client 45.45.237.7:49306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/.well-known/security.txt"] [unique_id "al9RqglWhjQfpOo60_HLnQAAACE"]
[Tue Jul 21 08:02:02.888057 2026] [security2:error] [pid 358661:tid 358827] [client 45.45.237.7:49306] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kvengenharia.com"] [uri "/.well-known/security.txt"] [unique_id "al9RqglWhjQfpOo60_HLnQAAACE"]
[Tue Jul 21 08:02:02.889252 2026] [security2:error] [pid 358661:tid 358840] [client 41.68.90.219:59217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RqglWhjQfpOo60_HLngAAAC4"]
[Tue Jul 21 08:02:02.890569 2026] [security2:error] [pid 358661:tid 358840] [client 41.68.90.219:59217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RqglWhjQfpOo60_HLngAAAC4"]
[Tue Jul 21 08:02:02.952084 2026] [security2:error] [pid 358661:tid 358701] [remote 65.60.38.74:45774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.38.60.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "izabelreck.com"] [uri "/wp-login.php"] [unique_id "al9RqglWhjQfpOo60_HLoAAAMyQ"]
[Tue Jul 21 08:02:03.014506 2026] [security2:error] [pid 358661:tid 358906] [client 20.151.10.161:39891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9RqwlWhjQfpOo60_HLogAAAHA"]
[Tue Jul 21 08:02:03.191973 2026] [security2:error] [pid 352421:tid 352644] [client 38.100.221.102:18445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rq8JSWzG9jbYOtu4-RAAAAOI"]
[Tue Jul 21 08:02:03.192196 2026] [security2:error] [pid 352421:tid 352644] [client 38.100.221.102:18445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rq8JSWzG9jbYOtu4-RAAAAOI"]
[Tue Jul 21 08:02:03.289895 2026] [security2:error] [pid 358661:tid 358752] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RqwlWhjQfpOo60_HLpwAAAFc"]
[Tue Jul 21 08:02:03.290152 2026] [security2:error] [pid 358661:tid 358794] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RqwlWhjQfpOo60_HLpwAAAFc"]
[Tue Jul 21 08:02:03.450335 2026] [security2:error] [pid 352421:tid 352677] [client 180.153.236.144:51709] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carlaalbuquerqueugc.online"] [uri "/"] [unique_id "al9Rq8JSWzG9jbYOtu4-RgAAAQM"], referer: http://carlaalbuquerqueugc.online/
[Tue Jul 21 08:02:03.450471 2026] [security2:error] [pid 352421:tid 352677] [client 180.153.236.144:51709] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "carlaalbuquerqueugc.online"] [uri "/"] [unique_id "al9Rq8JSWzG9jbYOtu4-RgAAAQM"], referer: http://carlaalbuquerqueugc.online/
[Tue Jul 21 08:02:03.470771 2026] [security2:error] [pid 352421:tid 352585] [client 20.104.96.117:27080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-file-120.php"] [unique_id "al9Rq8JSWzG9jbYOtu4-SAAAAKc"]
[Tue Jul 21 08:02:03.612089 2026] [security2:error] [pid 352421:tid 352580] [client 20.197.195.24:24069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-blog.php"] [unique_id "al9Rq8JSWzG9jbYOtu4-TQAAAKI"]
[Tue Jul 21 08:02:03.672064 2026] [security2:error] [pid 358661:tid 358876] [client 175.144.82.48:59312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RqwlWhjQfpOo60_HLrwAAAFI"]
[Tue Jul 21 08:02:03.672212 2026] [security2:error] [pid 358661:tid 358876] [client 175.144.82.48:59312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RqwlWhjQfpOo60_HLrwAAAFI"]
[Tue Jul 21 08:02:04.018828 2026] [security2:error] [pid 358661:tid 358758] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RrAlWhjQfpOo60_HLsgAAY10"]
[Tue Jul 21 08:02:04.018966 2026] [security2:error] [pid 358661:tid 358893] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RrAlWhjQfpOo60_HLsgAAY10"]
[Tue Jul 21 08:02:04.079511 2026] [security2:error] [pid 358661:tid 358901] [client 65.21.113.253:43562] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RqwlWhjQfpOo60_HLrgAAAGs"]
[Tue Jul 21 08:02:04.481569 2026] [security2:error] [pid 358661:tid 358872] [client 20.197.192.193:48906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/bscclapb.php"] [unique_id "al9RrAlWhjQfpOo60_HLvQAAAE4"]
[Tue Jul 21 08:02:04.611866 2026] [autoindex:error] [pid 358661:tid 358751] [remote 170.82.90.217:19025] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/?pag=chamada_consulta&modal=chamada&chamada=451
[Tue Jul 21 08:02:04.623036 2026] [core:error] [pid 358661:tid 358862] [client 66.249.66.160:37144] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:02:04.623057 2026] [core:error] [pid 358661:tid 358862] [client 66.249.66.160:37144] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:02:04.781731 2026] [security2:error] [pid 352421:tid 352535] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RrMJSWzG9jbYOtu4-WgAAo3E"]
[Tue Jul 21 08:02:04.781906 2026] [security2:error] [pid 352421:tid 352581] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RrMJSWzG9jbYOtu4-WgAAo3E"]
[Tue Jul 21 08:02:04.810786 2026] [security2:error] [pid 358661:tid 358875] [client 223.236.153.128:4544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RrAlWhjQfpOo60_HLxAAAAFE"]
[Tue Jul 21 08:02:04.810906 2026] [security2:error] [pid 358661:tid 358875] [client 223.236.153.128:4544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RrAlWhjQfpOo60_HLxAAAAFE"]
[Tue Jul 21 08:02:04.993040 2026] [security2:error] [pid 358661:tid 358915] [client 20.197.192.193:60469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/else1.php"] [unique_id "al9RrAlWhjQfpOo60_HLxQAAAHk"]
[Tue Jul 21 08:02:04.993967 2026] [security2:error] [pid 358661:tid 358685] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RrAlWhjQfpOo60_HLxgAAPhQ"]
[Tue Jul 21 08:02:04.994117 2026] [security2:error] [pid 358661:tid 358856] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RrAlWhjQfpOo60_HLxgAAPhQ"]
[Tue Jul 21 08:02:05.027516 2026] [security2:error] [pid 358661:tid 358884] [client 120.56.162.40:60195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RrAlWhjQfpOo60_HLxwAAAFo"]
[Tue Jul 21 08:02:05.056456 2026] [autoindex:error] [pid 358661:tid 358869] [client 20.197.195.24:0] AH01276: Cannot serve directory /home1/meufla20/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:02:05.098881 2026] [security2:error] [pid 358661:tid 358795] [client 20.197.195.24:24154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9RrQlWhjQfpOo60_HLywAAAAE"]
[Tue Jul 21 08:02:05.131170 2026] [security2:error] [pid 358661:tid 358850] [client 45.45.237.7:49518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/js/index.js"] [unique_id "al9RrQlWhjQfpOo60_HLzgAAADg"]
[Tue Jul 21 08:02:05.131273 2026] [security2:error] [pid 358661:tid 358850] [client 45.45.237.7:49518] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kvengenharia.com"] [uri "/wp-content/plugins/contact-form-7/includes/swv/js/index.js"] [unique_id "al9RrQlWhjQfpOo60_HLzgAAADg"]
[Tue Jul 21 08:02:05.160179 2026] [security2:error] [pid 358661:tid 358840] [client 45.45.237.7:50058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/vercel.json"] [unique_id "al9RrQlWhjQfpOo60_HL4QAAAC4"]
[Tue Jul 21 08:02:05.160321 2026] [security2:error] [pid 358661:tid 358840] [client 45.45.237.7:50058] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kvengenharia.com"] [uri "/vercel.json"] [unique_id "al9RrQlWhjQfpOo60_HL4QAAAC4"]
[Tue Jul 21 08:02:05.160517 2026] [security2:error] [pid 352421:tid 352562] [client 45.45.237.7:49968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/.netrc"] [unique_id "al9RrcJSWzG9jbYOtu4-aAAAAJA"]
[Tue Jul 21 08:02:05.160535 2026] [security2:error] [pid 358661:tid 358797] [client 45.45.237.7:49672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kvengenharia.com"] [uri "/app/.env"] [unique_id "al9RrQlWhjQfpOo60_HL1AAAAAM"]
[Tue Jul 21 08:02:05.160612 2026] [security2:error] [pid 352421:tid 352562] [client 45.45.237.7:49968] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kvengenharia.com"] [uri "/.netrc"] [unique_id "al9RrcJSWzG9jbYOtu4-aAAAAJA"]
[Tue Jul 21 08:02:05.160985 2026] [security2:error] [pid 358661:tid 358858] [client 45.45.237.7:49694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kvengenharia.com"] [uri "/public/.env"] [unique_id "al9RrQlWhjQfpOo60_HL1wAAAEA"]
[Tue Jul 21 08:02:05.161182 2026] [security2:error] [pid 352421:tid 352577] [client 45.45.237.7:49950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "kvengenharia.com"] [uri "/web.config"] [unique_id "al9RrcJSWzG9jbYOtu4-ZgAAAJ8"]
[Tue Jul 21 08:02:05.161185 2026] [security2:error] [pid 358661:tid 358833] [client 45.45.237.7:49624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "kvengenharia.com"] [uri "/.env.bak"] [unique_id "al9RrQlWhjQfpOo60_HL3QAAACc"]
[Tue Jul 21 08:02:05.161946 2026] [security2:error] [pid 358661:tid 358913] [client 45.45.237.7:49588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kvengenharia.com"] [uri "/.env"] [unique_id "al9RrQlWhjQfpOo60_HL0AAAAHc"]
[Tue Jul 21 08:02:05.162016 2026] [security2:error] [pid 358661:tid 358852] [client 45.45.237.7:49684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kvengenharia.com"] [uri "/api/.env"] [unique_id "al9RrQlWhjQfpOo60_HL2AAAADo"]
[Tue Jul 21 08:02:05.162010 2026] [security2:error] [pid 358661:tid 358830] [client 45.45.237.7:49682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kvengenharia.com"] [uri "/backend/.env"] [unique_id "al9RrQlWhjQfpOo60_HL3wAAACQ"]
[Tue Jul 21 08:02:05.162077 2026] [security2:error] [pid 358661:tid 358903] [client 45.45.237.7:49702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kvengenharia.com"] [uri "/laravel/.env"] [unique_id "al9RrQlWhjQfpOo60_HL2gAAAG0"]
[Tue Jul 21 08:02:05.185450 2026] [security2:error] [pid 358661:tid 358919] [client 45.45.237.7:49944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "kvengenharia.com"] [uri "/wp-config.php.bak"] [unique_id "al9RrQlWhjQfpOo60_HL8wAAAH0"]
[Tue Jul 21 08:02:05.185529 2026] [security2:error] [pid 358661:tid 358816] [client 45.45.237.7:49908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/actuator/env"] [unique_id "al9RrQlWhjQfpOo60_HL9AAAABY"]
[Tue Jul 21 08:02:05.185642 2026] [security2:error] [pid 358661:tid 358816] [client 45.45.237.7:49908] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kvengenharia.com"] [uri "/actuator/env"] [unique_id "al9RrQlWhjQfpOo60_HL9AAAABY"]
[Tue Jul 21 08:02:05.192895 2026] [security2:error] [pid 352421:tid 352656] [client 45.45.237.7:49938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kvengenharia.com"] [uri "/wp-config.php"] [unique_id "al9RrcJSWzG9jbYOtu4-bwAAAO4"]
[Tue Jul 21 08:02:05.215192 2026] [security2:error] [pid 358661:tid 358895] [client 45.45.237.7:49508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/wp-includes/js/dist/i18n.min.js"] [unique_id "al9RrQlWhjQfpOo60_HMBgAAAGU"]
[Tue Jul 21 08:02:05.215376 2026] [security2:error] [pid 358661:tid 358895] [client 45.45.237.7:49508] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kvengenharia.com"] [uri "/wp-includes/js/dist/i18n.min.js"] [unique_id "al9RrQlWhjQfpOo60_HMBgAAAGU"]
[Tue Jul 21 08:02:05.217289 2026] [security2:error] [pid 352421:tid 352657] [client 45.45.237.7:49658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/.env.test"] [unique_id "al9RrcJSWzG9jbYOtu4-cAAAAO8"]
[Tue Jul 21 08:02:05.217431 2026] [security2:error] [pid 352421:tid 352657] [client 45.45.237.7:49658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kvengenharia.com"] [uri "/.env.test"] [unique_id "al9RrcJSWzG9jbYOtu4-cAAAAO8"]
[Tue Jul 21 08:02:05.219599 2026] [security2:error] [pid 358661:tid 358885] [client 45.45.237.7:49648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "kvengenharia.com"] [uri "/.env.old"] [unique_id "al9RrQlWhjQfpOo60_HMCAAAAFs"]
[Tue Jul 21 08:02:05.224952 2026] [security2:error] [pid 358661:tid 358910] [client 45.45.237.7:49638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "kvengenharia.com"] [uri "/.env.backup"] [unique_id "al9RrQlWhjQfpOo60_HMCQAAAHQ"]
[Tue Jul 21 08:02:05.228174 2026] [security2:error] [pid 358661:tid 358896] [client 45.45.237.7:49362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kvengenharia.com"] [uri "/wp/.env"] [unique_id "al9RrQlWhjQfpOo60_HMCgAAAGY"]
[Tue Jul 21 08:02:05.453687 2026] [security2:error] [pid 352421:tid 352593] [client 20.197.192.193:56822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/ee.php"] [unique_id "al9RrcJSWzG9jbYOtu4-cgAAAK8"]
[Tue Jul 21 08:02:05.590855 2026] [security2:error] [pid 352421:tid 352642] [client 20.197.195.24:24144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/ms-edit.php"] [unique_id "al9RrcJSWzG9jbYOtu4-dQAAAOA"]
[Tue Jul 21 08:02:05.637199 2026] [security2:error] [pid 358661:tid 358869] [client 20.197.192.193:41536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/tkikikoko.php"] [unique_id "al9RrQlWhjQfpOo60_HMGAAAAEs"]
[Tue Jul 21 08:02:05.782642 2026] [security2:error] [pid 358661:tid 358840] [client 20.151.10.161:39813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9RrQlWhjQfpOo60_HMJwAAAC4"]
[Tue Jul 21 08:02:06.000273 2026] [security2:error] [pid 352421:tid 352603] [client 20.197.192.193:42186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/wp-Blogs.php"] [unique_id "al9RrcJSWzG9jbYOtu4-fgAAALk"]
[Tue Jul 21 08:02:06.031676 2026] [security2:error] [pid 358661:tid 358885] [client 20.197.195.24:58975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9RrglWhjQfpOo60_HMLQAAAFs"]
[Tue Jul 21 08:02:06.107606 2026] [security2:error] [pid 358661:tid 358829] [client 193.36.225.57:34649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RrglWhjQfpOo60_HMLgAAACM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:02:06.297953 2026] [security2:error] [pid 358661:tid 358802] [client 20.197.192.193:42217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/wp-css.php"] [unique_id "al9RrglWhjQfpOo60_HMMQAAAAg"]
[Tue Jul 21 08:02:06.366853 2026] [security2:error] [pid 358661:tid 358809] [client 65.21.113.253:47464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RrglWhjQfpOo60_HMMgAAAA8"]
[Tue Jul 21 08:02:06.547331 2026] [security2:error] [pid 352421:tid 352624] [client 95.164.247.71:5700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9RrMJSWzG9jbYOtu4-XQAAAM4"]
[Tue Jul 21 08:02:06.637129 2026] [security2:error] [pid 358661:tid 358782] [remote 8.217.108.67:50900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9RrglWhjQfpOo60_HMPgAAVXU"]
[Tue Jul 21 08:02:06.696127 2026] [security2:error] [pid 352421:tid 352651] [client 20.197.192.193:41553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/wp-explorer.php"] [unique_id "al9RrsJSWzG9jbYOtu4-iAAAAOk"]
[Tue Jul 21 08:02:06.989708 2026] [security2:error] [pid 358661:tid 358815] [client 65.21.113.253:43562] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RrglWhjQfpOo60_HMPQAAABU"]
[Tue Jul 21 08:02:07.002261 2026] [autoindex:error] [pid 352421:tid 352587] [client 20.197.195.24:0] AH01276: Cannot serve directory /home1/meufla20/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:02:07.020321 2026] [security2:error] [pid 358661:tid 358872] [client 20.197.195.24:58464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9RrwlWhjQfpOo60_HMSAAAAE4"]
[Tue Jul 21 08:02:07.153219 2026] [security2:error] [pid 352421:tid 352469] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Rr8JSWzG9jbYOtu4-kgAA6y8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.232313 2026] [security2:error] [pid 358661:tid 358772] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RrwlWhjQfpOo60_HMTgAAGWs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.293866 2026] [security2:error] [pid 358661:tid 358730] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RrwlWhjQfpOo60_HMSQAAJEE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.310717 2026] [security2:error] [pid 352421:tid 352491] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Rr8JSWzG9jbYOtu4-kQAArEU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.338123 2026] [security2:error] [pid 358661:tid 358749] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RrwlWhjQfpOo60_HMUAAAflQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.387347 2026] [autoindex:error] [pid 358661:tid 358898] [client 20.197.195.24:0] AH01276: Cannot serve directory /home1/meufla20/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:02:07.414434 2026] [authz_core:error] [pid 358661:tid 358809] [client 20.197.195.24:0] AH01630: client denied by server configuration: /home1/meufla20/public_html/wp-content/uploads/index.php
[Tue Jul 21 08:02:07.419185 2026] [security2:error] [pid 358661:tid 358766] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RrwlWhjQfpOo60_HMVQAAJWU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.423090 2026] [security2:error] [pid 352421:tid 352616] [client 20.197.195.24:24125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/abcd.php"] [unique_id "al9Rr8JSWzG9jbYOtu4-lgAAAMY"]
[Tue Jul 21 08:02:07.497601 2026] [security2:error] [pid 358661:tid 358712] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RrwlWhjQfpOo60_HMWgAAay8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.519693 2026] [security2:error] [pid 358661:tid 358699] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RrwlWhjQfpOo60_HMXAAAYyI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.555917 2026] [security2:error] [pid 358661:tid 358779] [remote 192.241.143.148:41792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9RrwlWhjQfpOo60_HMXQAAZnI"]
[Tue Jul 21 08:02:07.612839 2026] [security2:error] [pid 358661:tid 358785] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RrwlWhjQfpOo60_HMXgAAAXg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.701310 2026] [security2:error] [pid 358661:tid 358726] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RrwlWhjQfpOo60_HMXwAAUj0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.736496 2026] [security2:error] [pid 352421:tid 352660] [client 20.197.195.24:24163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/file15.php"] [unique_id "al9Rr8JSWzG9jbYOtu4-mwAAAPI"]
[Tue Jul 21 08:02:07.775028 2026] [security2:error] [pid 358661:tid 358716] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RrwlWhjQfpOo60_HMYgAAbzM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.788277 2026] [security2:error] [pid 358661:tid 358843] [client 45.45.237.7:49482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/wp-content/plugins/rrdevs-for-elementor/assets/js/slick.js.map"] [unique_id "al9RrwlWhjQfpOo60_HMZAAAADE"]
[Tue Jul 21 08:02:07.788378 2026] [security2:error] [pid 358661:tid 358843] [client 45.45.237.7:49482] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kvengenharia.com"] [uri "/wp-content/plugins/rrdevs-for-elementor/assets/js/slick.js.map"] [unique_id "al9RrwlWhjQfpOo60_HMZAAAADE"]
[Tue Jul 21 08:02:07.798367 2026] [security2:error] [pid 358661:tid 358919] [client 103.86.117.203:50131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RrwlWhjQfpOo60_HMawAAAH0"]
[Tue Jul 21 08:02:07.798502 2026] [security2:error] [pid 358661:tid 358919] [client 103.86.117.203:50131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RrwlWhjQfpOo60_HMawAAAH0"]
[Tue Jul 21 08:02:07.822799 2026] [security2:error] [pid 358661:tid 358718] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RrwlWhjQfpOo60_HMbgAABDU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.882865 2026] [security2:error] [pid 358661:tid 358672] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RrwlWhjQfpOo60_HMbwAAFQc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.929635 2026] [security2:error] [pid 358661:tid 358914] [client 106.215.181.8:12491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RrwlWhjQfpOo60_HMcQAAAHg"]
[Tue Jul 21 08:02:07.929790 2026] [security2:error] [pid 358661:tid 358914] [client 106.215.181.8:12491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RrwlWhjQfpOo60_HMcQAAAHg"]
[Tue Jul 21 08:02:07.958457 2026] [security2:error] [pid 358661:tid 358719] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RrwlWhjQfpOo60_HMcgAAAzY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.978629 2026] [security2:error] [pid 358661:tid 358787] [remote 109.203.107.150:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.107.203.109.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9RrwlWhjQfpOo60_HMcwAAOno"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:02:07.992874 2026] [security2:error] [pid 352421:tid 352678] [client 87.116.180.198:13993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rr8JSWzG9jbYOtu4-oQAAAQQ"]
[Tue Jul 21 08:02:07.994674 2026] [security2:error] [pid 352421:tid 352678] [client 87.116.180.198:13993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rr8JSWzG9jbYOtu4-oQAAAQQ"]
[Tue Jul 21 08:02:08.075318 2026] [security2:error] [pid 358661:tid 358816] [client 95.164.247.71:5726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9RrwlWhjQfpOo60_HMTwAAABY"]
[Tue Jul 21 08:02:08.247854 2026] [security2:error] [pid 358661:tid 358813] [client 20.197.195.24:58965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/jp.php"] [unique_id "al9RsAlWhjQfpOo60_HMeQAAABM"]
[Tue Jul 21 08:02:08.251218 2026] [security2:error] [pid 352421:tid 352627] [client 65.21.113.253:43574] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Rr8JSWzG9jbYOtu4-nwAAANE"]
[Tue Jul 21 08:02:08.390793 2026] [security2:error] [pid 352421:tid 352647] [client 103.78.200.11:52091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RsMJSWzG9jbYOtu4-pQAAAOU"]
[Tue Jul 21 08:02:08.390955 2026] [security2:error] [pid 352421:tid 352647] [client 103.78.200.11:52091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RsMJSWzG9jbYOtu4-pQAAAOU"]
[Tue Jul 21 08:02:08.445982 2026] [security2:error] [pid 358661:tid 358895] [client 102.206.115.33:58718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RsAlWhjQfpOo60_HMgAAAAGU"]
[Tue Jul 21 08:02:08.446091 2026] [security2:error] [pid 358661:tid 358895] [client 102.206.115.33:58718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RsAlWhjQfpOo60_HMgAAAAGU"]
[Tue Jul 21 08:02:08.724627 2026] [security2:error] [pid 358661:tid 358900] [client 20.220.225.223:34212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9RsAlWhjQfpOo60_HMgQAAAGo"]
[Tue Jul 21 08:02:08.869326 2026] [security2:error] [pid 352421:tid 352657] [client 117.247.80.59:17869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RsMJSWzG9jbYOtu4-rgAAAO8"]
[Tue Jul 21 08:02:08.869416 2026] [security2:error] [pid 352421:tid 352657] [client 117.247.80.59:17869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RsMJSWzG9jbYOtu4-rgAAAO8"]
[Tue Jul 21 08:02:08.926769 2026] [security2:error] [pid 358661:tid 358855] [client 202.143.127.214:51677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RsAlWhjQfpOo60_HMgwAAAD0"]
[Tue Jul 21 08:02:08.926866 2026] [security2:error] [pid 358661:tid 358855] [client 202.143.127.214:51677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RsAlWhjQfpOo60_HMgwAAAD0"]
[Tue Jul 21 08:02:08.957296 2026] [security2:error] [pid 358661:tid 358906] [client 20.151.10.161:39854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp.php"] [unique_id "al9RsAlWhjQfpOo60_HMhAAAAHA"]
[Tue Jul 21 08:02:09.078723 2026] [security2:error] [pid 358661:tid 358901] [client 103.29.114.44:30509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RsQlWhjQfpOo60_HMhgAAAGs"]
[Tue Jul 21 08:02:09.078898 2026] [security2:error] [pid 358661:tid 358901] [client 103.29.114.44:30509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RsQlWhjQfpOo60_HMhgAAAGs"]
[Tue Jul 21 08:02:09.481169 2026] [security2:error] [pid 358661:tid 358812] [client 109.60.28.94:59283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RsQlWhjQfpOo60_HMjAAAABI"]
[Tue Jul 21 08:02:09.481314 2026] [security2:error] [pid 358661:tid 358812] [client 109.60.28.94:59283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RsQlWhjQfpOo60_HMjAAAABI"]
[Tue Jul 21 08:02:09.713266 2026] [security2:error] [pid 352421:tid 352618] [client 20.197.192.193:41551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/akismet.php"] [unique_id "al9RscJSWzG9jbYOtu4-uQAAAMg"]
[Tue Jul 21 08:02:09.883619 2026] [security2:error] [pid 358661:tid 358870] [client 20.197.195.24:58436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/f35.php"] [unique_id "al9RsQlWhjQfpOo60_HMkgAAAEw"]
[Tue Jul 21 08:02:10.126934 2026] [security2:error] [pid 358661:tid 358840] [client 136.243.220.214:42858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.220.243.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dharmanet.com.br"] [uri "/noticias/index.php"] [unique_id "al9RsglWhjQfpOo60_HMlAAAAC4"]
[Tue Jul 21 08:02:10.268613 2026] [security2:error] [pid 352421:tid 352606] [client 20.151.10.161:39792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/abcd.php"] [unique_id "al9RssJSWzG9jbYOtu4-wgAAALw"]
[Tue Jul 21 08:02:10.626267 2026] [security2:error] [pid 358661:tid 358873] [client 20.197.192.193:56200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/blue.php"] [unique_id "al9RsglWhjQfpOo60_HMnQAAAE8"]
[Tue Jul 21 08:02:10.749670 2026] [security2:error] [pid 352421:tid 352589] [client 103.166.103.129:12911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RssJSWzG9jbYOtu4-ygAAAKs"]
[Tue Jul 21 08:02:10.749788 2026] [security2:error] [pid 352421:tid 352589] [client 103.166.103.129:12911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RssJSWzG9jbYOtu4-ygAAAKs"]
[Tue Jul 21 08:02:10.768233 2026] [security2:error] [pid 358661:tid 358920] [client 136.144.33.29:34643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RsglWhjQfpOo60_HMngAAAH4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:02:10.797295 2026] [security2:error] [pid 352421:tid 352661] [client 182.8.255.181:21071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RssJSWzG9jbYOtu4-ywAAAPM"]
[Tue Jul 21 08:02:10.797404 2026] [security2:error] [pid 352421:tid 352661] [client 182.8.255.181:21071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RssJSWzG9jbYOtu4-ywAAAPM"]
[Tue Jul 21 08:02:10.817156 2026] [security2:error] [pid 352421:tid 352552] [client 20.151.10.161:39882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/a1.php"] [unique_id "al9RssJSWzG9jbYOtu4-zgAAAIY"]
[Tue Jul 21 08:02:10.840094 2026] [security2:error] [pid 358661:tid 358831] [client 65.21.113.253:47464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RsglWhjQfpOo60_HMogAAACU"]
[Tue Jul 21 08:02:10.976767 2026] [security2:error] [pid 352421:tid 352577] [client 20.104.96.117:46690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/special.php"] [unique_id "al9RssJSWzG9jbYOtu4-1AAAAJ8"]
[Tue Jul 21 08:02:11.236076 2026] [security2:error] [pid 352421:tid 352620] [client 20.151.10.161:39744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9Rs8JSWzG9jbYOtu4-2gAAAMo"]
[Tue Jul 21 08:02:11.377145 2026] [security2:error] [pid 352421:tid 352595] [client 20.197.192.193:48921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/ace2.php"] [unique_id "al9Rs8JSWzG9jbYOtu4-3wAAALE"]
[Tue Jul 21 08:02:11.395602 2026] [security2:error] [pid 358661:tid 358812] [client 20.197.195.24:58448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-load.php"] [unique_id "al9RswlWhjQfpOo60_HMpAAAABI"]
[Tue Jul 21 08:02:11.438646 2026] [security2:error] [pid 358661:tid 358770] [remote 5.252.52.249:35768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "odontoclinicms.com.br"] [uri "/wp-login.php"] [unique_id "al9RswlWhjQfpOo60_HMpQAAcmk"]
[Tue Jul 21 08:02:11.505629 2026] [security2:error] [pid 352421:tid 352621] [client 65.21.113.253:43574] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Rs8JSWzG9jbYOtu4-1QAAAMs"]
[Tue Jul 21 08:02:12.081753 2026] [security2:error] [pid 352421:tid 352631] [client 178.153.91.96:63382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RtMJSWzG9jbYOtu4-6wAAANU"]
[Tue Jul 21 08:02:12.081912 2026] [security2:error] [pid 352421:tid 352631] [client 178.153.91.96:63382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RtMJSWzG9jbYOtu4-6wAAANU"]
[Tue Jul 21 08:02:12.083487 2026] [security2:error] [pid 352421:tid 352615] [client 20.197.192.193:50576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-signup.php"] [unique_id "al9RtMJSWzG9jbYOtu4-7AAAAMU"]
[Tue Jul 21 08:02:12.329773 2026] [security2:error] [pid 352421:tid 352602] [client 20.197.195.24:58967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/xyn.php"] [unique_id "al9RtMJSWzG9jbYOtu4-8QAAALg"]
[Tue Jul 21 08:02:12.359364 2026] [security2:error] [pid 352421:tid 352608] [client 20.151.10.161:39849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9RtMJSWzG9jbYOtu4-8gAAAL4"]
[Tue Jul 21 08:02:12.368596 2026] [security2:error] [pid 352421:tid 352666] [client 20.104.96.117:46702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/as.php"] [unique_id "al9RtMJSWzG9jbYOtu4-8wAAAPg"]
[Tue Jul 21 08:02:12.553837 2026] [security2:error] [pid 358661:tid 358768] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RtAlWhjQfpOo60_HMswAAQGc"]
[Tue Jul 21 08:02:12.554023 2026] [security2:error] [pid 358661:tid 358858] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RtAlWhjQfpOo60_HMswAAQGc"]
[Tue Jul 21 08:02:12.713577 2026] [security2:error] [pid 358661:tid 358823] [client 122.179.91.63:16253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RtAlWhjQfpOo60_HMtQAAAB0"]
[Tue Jul 21 08:02:12.713710 2026] [security2:error] [pid 358661:tid 358823] [client 122.179.91.63:16253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RtAlWhjQfpOo60_HMtQAAAB0"]
[Tue Jul 21 08:02:12.716619 2026] [security2:error] [pid 358661:tid 358820] [client 20.197.192.193:42176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pontodooleomecanica.com"] [uri "/ms.php"] [unique_id "al9RtAlWhjQfpOo60_HMtgAAABo"]
[Tue Jul 21 08:02:12.735718 2026] [security2:error] [pid 358661:tid 358840] [client 65.21.113.253:41600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RtAlWhjQfpOo60_HMrgAAAC4"]
[Tue Jul 21 08:02:12.894056 2026] [security2:error] [pid 358661:tid 358885] [client 20.151.10.161:39684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/gettest.php"] [unique_id "al9RtAlWhjQfpOo60_HMtwAAAFs"]
[Tue Jul 21 08:02:12.900934 2026] [security2:error] [pid 358661:tid 358798] [client 117.210.135.0:54899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtAlWhjQfpOo60_HMuAAAAAQ"]
[Tue Jul 21 08:02:12.901027 2026] [security2:error] [pid 358661:tid 358798] [client 117.210.135.0:54899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtAlWhjQfpOo60_HMuAAAAAQ"]
[Tue Jul 21 08:02:13.060833 2026] [security2:error] [pid 352421:tid 352476] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RtcJSWzG9jbYOtu4-_QAAvzY"]
[Tue Jul 21 08:02:13.060966 2026] [security2:error] [pid 352421:tid 352609] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RtcJSWzG9jbYOtu4-_QAAvzY"]
[Tue Jul 21 08:02:13.311919 2026] [security2:error] [pid 352421:tid 352440] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtcJSWzG9jbYOtu4_AgAAvBI"]
[Tue Jul 21 08:02:13.312226 2026] [security2:error] [pid 352421:tid 352606] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtcJSWzG9jbYOtu4_AgAAvBI"]
[Tue Jul 21 08:02:13.518566 2026] [security2:error] [pid 352421:tid 352487] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtcJSWzG9jbYOtu4_AwAAjUE"]
[Tue Jul 21 08:02:13.518762 2026] [security2:error] [pid 352421:tid 352559] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtcJSWzG9jbYOtu4_AwAAjUE"]
[Tue Jul 21 08:02:13.543451 2026] [security2:error] [pid 352421:tid 352590] [client 41.68.90.219:59690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtcJSWzG9jbYOtu4_BwAAAKw"]
[Tue Jul 21 08:02:13.543571 2026] [security2:error] [pid 352421:tid 352590] [client 41.68.90.219:59690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtcJSWzG9jbYOtu4_BwAAAKw"]
[Tue Jul 21 08:02:13.679087 2026] [security2:error] [pid 352421:tid 352605] [client 38.100.221.102:17767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtcJSWzG9jbYOtu4_CQAAALs"]
[Tue Jul 21 08:02:13.679204 2026] [security2:error] [pid 352421:tid 352605] [client 38.100.221.102:17767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtcJSWzG9jbYOtu4_CQAAALs"]
[Tue Jul 21 08:02:13.740250 2026] [security2:error] [pid 352421:tid 352493] [remote 45.131.193.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.193.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elpcons.com.br"] [uri "/wp-login.php"] [unique_id "al9RtcJSWzG9jbYOtu4_DAAAxEc"]
[Tue Jul 21 08:02:13.757860 2026] [security2:error] [pid 352421:tid 352552] [client 184.75.221.3:38550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9RtcJSWzG9jbYOtu4_DQAAAIY"]
[Tue Jul 21 08:02:13.757952 2026] [security2:error] [pid 352421:tid 352552] [client 184.75.221.3:38550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9RtcJSWzG9jbYOtu4_DQAAAIY"]
[Tue Jul 21 08:02:13.804386 2026] [autoindex:error] [pid 358661:tid 358831] [client 20.197.195.24:0] AH01276: Cannot serve directory /home1/meufla20/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:02:13.819429 2026] [security2:error] [pid 358661:tid 358736] [remote 132.148.72.88:43048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9RtQlWhjQfpOo60_HMxwAAfEc"]
[Tue Jul 21 08:02:13.908079 2026] [security2:error] [pid 358661:tid 358841] [client 20.151.10.161:39862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/simple.php"] [unique_id "al9RtQlWhjQfpOo60_HMyQAAAC8"]
[Tue Jul 21 08:02:13.914808 2026] [autoindex:error] [pid 358661:tid 358827] [client 20.197.195.24:58463] AH01276: Cannot serve directory /home1/meufla20/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:02:13.920620 2026] [security2:error] [pid 358661:tid 358872] [client 20.197.195.24:58463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/ccc.php"] [unique_id "al9RtQlWhjQfpOo60_HMygAAAE4"]
[Tue Jul 21 08:02:14.120440 2026] [security2:error] [pid 352421:tid 352568] [client 20.104.96.117:46706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9RtsJSWzG9jbYOtu4_FAAAAJY"]
[Tue Jul 21 08:02:14.168943 2026] [security2:error] [pid 352421:tid 352671] [client 175.144.82.48:59739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtsJSWzG9jbYOtu4_GAAAAP0"]
[Tue Jul 21 08:02:14.169882 2026] [security2:error] [pid 352421:tid 352671] [client 175.144.82.48:59739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtsJSWzG9jbYOtu4_GAAAAP0"]
[Tue Jul 21 08:02:14.225063 2026] [security2:error] [pid 358661:tid 358805] [client 20.197.192.193:50560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/csa.php"] [unique_id "al9RtglWhjQfpOo60_HM0gAAAAs"]
[Tue Jul 21 08:02:14.303964 2026] [security2:error] [pid 352421:tid 352449] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtsJSWzG9jbYOtu4_GgAAwxs"]
[Tue Jul 21 08:02:14.304191 2026] [security2:error] [pid 352421:tid 352613] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtsJSWzG9jbYOtu4_GgAAwxs"]
[Tue Jul 21 08:02:14.342281 2026] [security2:error] [pid 352421:tid 352657] [client 209.141.34.121:51932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "cursosonlinesiteoficial.com"] [uri "/"] [unique_id "al9RtsJSWzG9jbYOtu4_HAAAAO8"]
[Tue Jul 21 08:02:14.373675 2026] [security2:error] [pid 358661:tid 358820] [client 20.151.10.161:39894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/xxx.php"] [unique_id "al9RtglWhjQfpOo60_HM0wAAABo"]
[Tue Jul 21 08:02:14.604665 2026] [security2:error] [pid 358661:tid 358846] [client 193.36.225.68:24507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RtglWhjQfpOo60_HM1AAAADQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:02:14.638355 2026] [security2:error] [pid 358661:tid 358823] [client 65.111.13.77:41839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.13.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RtglWhjQfpOo60_HM1gAAAB0"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:02:14.683172 2026] [security2:error] [pid 352421:tid 352636] [client 209.141.34.121:51996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "cursosonlinesiteoficial.com"] [uri "/"] [unique_id "al9RtsJSWzG9jbYOtu4_IAAAANo"]
[Tue Jul 21 08:02:14.734566 2026] [security2:error] [pid 352421:tid 352607] [client 20.197.192.193:56790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/min.php"] [unique_id "al9RtsJSWzG9jbYOtu4_IQAAAL0"]
[Tue Jul 21 08:02:14.738641 2026] [security2:error] [pid 358661:tid 358885] [client 20.197.195.24:2878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/w.php"] [unique_id "al9RtglWhjQfpOo60_HM2AAAAFs"]
[Tue Jul 21 08:02:14.768504 2026] [security2:error] [pid 352421:tid 352522] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtsJSWzG9jbYOtu4_IgAAsmQ"]
[Tue Jul 21 08:02:14.768682 2026] [security2:error] [pid 352421:tid 352596] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RtsJSWzG9jbYOtu4_IgAAsmQ"]
[Tue Jul 21 08:02:14.902100 2026] [security2:error] [pid 358661:tid 358870] [client 65.21.113.253:47464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RtglWhjQfpOo60_HM2QAAAEw"]
[Tue Jul 21 08:02:15.352647 2026] [security2:error] [pid 358661:tid 358854] [client 20.151.10.161:39820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/hypo.php"] [unique_id "al9RtwlWhjQfpOo60_HM3QAAADw"]
[Tue Jul 21 08:02:15.403730 2026] [security2:error] [pid 358661:tid 358905] [client 223.236.153.128:1895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RtwlWhjQfpOo60_HM4AAAAG8"]
[Tue Jul 21 08:02:15.408336 2026] [security2:error] [pid 358661:tid 358905] [client 223.236.153.128:1895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RtwlWhjQfpOo60_HM4AAAAG8"]
[Tue Jul 21 08:02:15.462076 2026] [security2:error] [pid 358661:tid 358696] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RtwlWhjQfpOo60_HM4QAAFh8"]
[Tue Jul 21 08:02:15.462259 2026] [security2:error] [pid 358661:tid 358816] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RtwlWhjQfpOo60_HM4QAAFh8"]
[Tue Jul 21 08:02:15.570459 2026] [security2:error] [pid 358661:tid 358901] [client 65.21.113.253:41600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RtwlWhjQfpOo60_HM2gAAAGs"]
[Tue Jul 21 08:02:15.698621 2026] [security2:error] [pid 358661:tid 358775] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RtwlWhjQfpOo60_HM5wAACW4"]
[Tue Jul 21 08:02:15.698753 2026] [security2:error] [pid 358661:tid 358803] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RtwlWhjQfpOo60_HM5wAACW4"]
[Tue Jul 21 08:02:15.738366 2026] [security2:error] [pid 352421:tid 352597] [client 120.56.162.40:60618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rt8JSWzG9jbYOtu4_MAAAALM"]
[Tue Jul 21 08:02:15.875201 2026] [security2:error] [pid 358661:tid 358881] [client 20.104.96.117:46628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/w1px.php"] [unique_id "al9RtwlWhjQfpOo60_HM6AAAAFc"]
[Tue Jul 21 08:02:15.903286 2026] [security2:error] [pid 358661:tid 358836] [client 20.197.195.24:58955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9RtwlWhjQfpOo60_HM6QAAACo"]
[Tue Jul 21 08:02:16.560483 2026] [security2:error] [pid 358661:tid 358851] [client 20.197.195.24:2938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/FWAZ.php"] [unique_id "al9RuAlWhjQfpOo60_HM8AAAADk"]
[Tue Jul 21 08:02:16.851516 2026] [security2:error] [pid 358661:tid 358908] [client 20.151.10.161:39845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/chosen.php"] [unique_id "al9RuAlWhjQfpOo60_HM9gAAAHI"]
[Tue Jul 21 08:02:17.064269 2026] [security2:error] [pid 358661:tid 358863] [client 20.197.195.24:2934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/miru1.php"] [unique_id "al9RuQlWhjQfpOo60_HM-AAAAEU"]
[Tue Jul 21 08:02:17.376463 2026] [security2:error] [pid 352421:tid 352627] [client 20.197.195.24:2903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/aa.php"] [unique_id "al9RucJSWzG9jbYOtu4_RgAAANE"]
[Tue Jul 21 08:02:17.459763 2026] [security2:error] [pid 358661:tid 358914] [client 20.104.96.117:46659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/yawa.php"] [unique_id "al9RuQlWhjQfpOo60_HNAAAAAHg"]
[Tue Jul 21 08:02:17.519213 2026] [security2:error] [pid 358661:tid 358830] [client 65.21.113.253:41602] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RuQlWhjQfpOo60_HM9wAAACQ"]
[Tue Jul 21 08:02:17.748243 2026] [security2:error] [pid 358661:tid 358840] [client 20.197.195.24:2943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/122.php"] [unique_id "al9RuQlWhjQfpOo60_HNCAAAAC4"]
[Tue Jul 21 08:02:17.753219 2026] [security2:error] [pid 358661:tid 358885] [client 20.151.10.161:39834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/als.php"] [unique_id "al9RuQlWhjQfpOo60_HNCQAAAFs"]
[Tue Jul 21 08:02:17.777062 2026] [security2:error] [pid 358661:tid 358919] [client 65.21.113.253:47464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RuQlWhjQfpOo60_HNCgAAAH0"]
[Tue Jul 21 08:02:18.281143 2026] [security2:error] [pid 352421:tid 352626] [client 103.86.117.203:50807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RusJSWzG9jbYOtu4_UgAAANA"]
[Tue Jul 21 08:02:18.281307 2026] [security2:error] [pid 352421:tid 352626] [client 103.86.117.203:50807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RusJSWzG9jbYOtu4_UgAAANA"]
[Tue Jul 21 08:02:18.295250 2026] [security2:error] [pid 358661:tid 358803] [client 20.151.10.161:39754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/pol.php"] [unique_id "al9RuglWhjQfpOo60_HNEgAAAAk"]
[Tue Jul 21 08:02:18.404377 2026] [security2:error] [pid 358661:tid 358833] [client 136.144.33.28:20885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RuglWhjQfpOo60_HNFQAAACc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:02:18.457156 2026] [security2:error] [pid 352421:tid 352595] [client 106.215.181.8:28351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RusJSWzG9jbYOtu4_VAAAALE"]
[Tue Jul 21 08:02:18.457295 2026] [security2:error] [pid 352421:tid 352595] [client 106.215.181.8:28351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RusJSWzG9jbYOtu4_VAAAALE"]
[Tue Jul 21 08:02:18.541053 2026] [security2:error] [pid 358661:tid 358688] [remote 119.195.102.159:38124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9RuglWhjQfpOo60_HNFwAATBc"]
[Tue Jul 21 08:02:18.541202 2026] [security2:error] [pid 358661:tid 358870] [client 119.195.102.159:38124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9RuglWhjQfpOo60_HNFwAATBc"]
[Tue Jul 21 08:02:18.611015 2026] [security2:error] [pid 358661:tid 358869] [client 117.247.80.59:20702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RuglWhjQfpOo60_HNGAAAAEs"]
[Tue Jul 21 08:02:18.611133 2026] [security2:error] [pid 358661:tid 358869] [client 117.247.80.59:20702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RuglWhjQfpOo60_HNGAAAAEs"]
[Tue Jul 21 08:02:18.642698 2026] [security2:error] [pid 358661:tid 358864] [client 87.116.180.198:27370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RuglWhjQfpOo60_HNGQAAAEY"]
[Tue Jul 21 08:02:18.642782 2026] [security2:error] [pid 358661:tid 358864] [client 87.116.180.198:27370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RuglWhjQfpOo60_HNGQAAAEY"]
[Tue Jul 21 08:02:18.673568 2026] [security2:error] [pid 358661:tid 358819] [client 20.197.195.24:2872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/get.php"] [unique_id "al9RuglWhjQfpOo60_HNGgAAABk"]
[Tue Jul 21 08:02:18.691370 2026] [security2:error] [pid 352421:tid 352576] [client 20.151.10.161:39835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/file5.php"] [unique_id "al9RusJSWzG9jbYOtu4_VgAAAJ4"]
[Tue Jul 21 08:02:18.834993 2026] [security2:error] [pid 358661:tid 358842] [client 65.21.113.253:41608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RuglWhjQfpOo60_HNFgAAADA"]
[Tue Jul 21 08:02:18.946915 2026] [security2:error] [pid 352421:tid 352619] [client 102.206.115.33:63043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RusJSWzG9jbYOtu4_WgAAAMk"]
[Tue Jul 21 08:02:18.947032 2026] [security2:error] [pid 352421:tid 352619] [client 102.206.115.33:63043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RusJSWzG9jbYOtu4_WgAAAMk"]
[Tue Jul 21 08:02:18.987389 2026] [security2:error] [pid 358661:tid 358844] [client 103.78.200.11:52576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RuglWhjQfpOo60_HNHAAAADI"]
[Tue Jul 21 08:02:18.987507 2026] [security2:error] [pid 358661:tid 358844] [client 103.78.200.11:52576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RuglWhjQfpOo60_HNHAAAADI"]
[Tue Jul 21 08:02:19.267188 2026] [security2:error] [pid 358661:tid 358876] [client 20.151.10.161:39890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9RuwlWhjQfpOo60_HNHgAAAFI"]
[Tue Jul 21 08:02:19.290015 2026] [security2:error] [pid 352421:tid 352464] [remote 65.111.8.221:23127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9Ru8JSWzG9jbYOtu4_XAAAmSo"]
[Tue Jul 21 08:02:19.335127 2026] [security2:error] [pid 358661:tid 358834] [client 20.197.192.193:56817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/echkm.php"] [unique_id "al9RuwlWhjQfpOo60_HNIQAAACg"]
[Tue Jul 21 08:02:19.728257 2026] [security2:error] [pid 358661:tid 358861] [client 103.29.114.44:34193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RuwlWhjQfpOo60_HNKQAAAEM"]
[Tue Jul 21 08:02:19.728390 2026] [security2:error] [pid 358661:tid 358861] [client 103.29.114.44:34193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RuwlWhjQfpOo60_HNKQAAAEM"]
[Tue Jul 21 08:02:19.837937 2026] [security2:error] [pid 358661:tid 358827] [client 45.45.237.7:48322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/service/legalizacao-de-imoveis"] [unique_id "al9RuwlWhjQfpOo60_HNLAAAACE"]
[Tue Jul 21 08:02:19.838047 2026] [security2:error] [pid 358661:tid 358827] [client 45.45.237.7:48322] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kvengenharia.com"] [uri "/service/legalizacao-de-imoveis"] [unique_id "al9RuwlWhjQfpOo60_HNLAAAACE"]
[Tue Jul 21 08:02:19.839664 2026] [security2:error] [pid 352421:tid 352565] [client 45.45.237.7:48178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/feed"] [unique_id "al9Ru8JSWzG9jbYOtu4_bAAAAJM"]
[Tue Jul 21 08:02:19.839766 2026] [security2:error] [pid 352421:tid 352565] [client 45.45.237.7:48178] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kvengenharia.com"] [uri "/feed"] [unique_id "al9Ru8JSWzG9jbYOtu4_bAAAAJM"]
[Tue Jul 21 08:02:19.840049 2026] [security2:error] [pid 352421:tid 352608] [client 45.45.237.7:48190] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/comments/feed"] [unique_id "al9Ru8JSWzG9jbYOtu4_bQAAAL4"]
[Tue Jul 21 08:02:19.840116 2026] [security2:error] [pid 352421:tid 352608] [client 45.45.237.7:48190] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kvengenharia.com"] [uri "/comments/feed"] [unique_id "al9Ru8JSWzG9jbYOtu4_bQAAAL4"]
[Tue Jul 21 08:02:19.845699 2026] [security2:error] [pid 358661:tid 358921] [client 20.104.96.117:46629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/js.php"] [unique_id "al9RuwlWhjQfpOo60_HNNgAAAH8"]
[Tue Jul 21 08:02:20.010917 2026] [security2:error] [pid 358661:tid 358824] [client 45.45.237.7:48226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kvengenharia.com"] [uri "/xmlrpc.php"] [unique_id "al9RuwlWhjQfpOo60_HNNAAAAB4"]
[Tue Jul 21 08:02:20.011077 2026] [security2:error] [pid 358661:tid 358824] [client 45.45.237.7:48226] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "kvengenharia.com"] [uri "/xmlrpc.php"] [unique_id "al9RuwlWhjQfpOo60_HNNAAAAB4"]
[Tue Jul 21 08:02:20.027648 2026] [security2:error] [pid 352421:tid 352668] [client 20.197.195.24:2834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/as.php"] [unique_id "al9RvMJSWzG9jbYOtu4_cQAAAPo"]
[Tue Jul 21 08:02:20.114123 2026] [security2:error] [pid 352421:tid 352560] [client 20.151.10.161:39760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/file.php"] [unique_id "al9RvMJSWzG9jbYOtu4_dAAAAI4"]
[Tue Jul 21 08:02:20.185347 2026] [security2:error] [pid 358661:tid 358911] [client 2.57.168.19:25433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.168.57.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9RvAlWhjQfpOo60_HNOAAAAHU"]
[Tue Jul 21 08:02:20.293593 2026] [security2:error] [pid 352421:tid 352587] [client 202.143.127.214:52165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RvMJSWzG9jbYOtu4_dQAAAKk"]
[Tue Jul 21 08:02:20.293802 2026] [security2:error] [pid 352421:tid 352587] [client 202.143.127.214:52165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RvMJSWzG9jbYOtu4_dQAAAKk"]
[Tue Jul 21 08:02:20.407330 2026] [security2:error] [pid 358661:tid 358914] [client 109.60.28.94:55712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RvAlWhjQfpOo60_HNQQAAAHg"]
[Tue Jul 21 08:02:20.408171 2026] [security2:error] [pid 358661:tid 358914] [client 109.60.28.94:55712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RvAlWhjQfpOo60_HNQQAAAHg"]
[Tue Jul 21 08:02:20.428796 2026] [security2:error] [pid 352421:tid 352574] [client 20.151.10.161:39833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/cfile.php"] [unique_id "al9RvMJSWzG9jbYOtu4_eQAAAJw"]
[Tue Jul 21 08:02:20.661551 2026] [security2:error] [pid 358661:tid 358868] [client 47.128.126.227:45112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "odontoclinicms.com.br"] [uri "/robots.txt"] [unique_id "al9RvAlWhjQfpOo60_HNTAAAAEo"]
[Tue Jul 21 08:02:20.740605 2026] [security2:error] [pid 352421:tid 352614] [client 20.151.10.161:39917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/class-wp.php"] [unique_id "al9RvMJSWzG9jbYOtu4_gAAAAMQ"]
[Tue Jul 21 08:02:20.902526 2026] [core:error] [pid 352421:tid 352524] [remote 74.7.228.22:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:02:20.902546 2026] [core:error] [pid 352421:tid 352524] [remote 74.7.228.22:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:02:20.903315 2026] [security2:error] [pid 352421:tid 352554] [client 74.7.228.22:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.vanderleiasilva.com.br"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "al9RvMJSWzG9jbYOtu4_hAAAiGY"]
[Tue Jul 21 08:02:21.126741 2026] [security2:error] [pid 358661:tid 358883] [client 20.151.10.161:39786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/admin.php"] [unique_id "al9RvQlWhjQfpOo60_HNUwAAAFk"]
[Tue Jul 21 08:02:21.224714 2026] [security2:error] [pid 358661:tid 358905] [client 182.8.255.181:21079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RvQlWhjQfpOo60_HNVAAAAG8"]
[Tue Jul 21 08:02:21.224852 2026] [security2:error] [pid 358661:tid 358905] [client 182.8.255.181:21079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9RvQlWhjQfpOo60_HNVAAAAG8"]
[Tue Jul 21 08:02:21.372031 2026] [security2:error] [pid 358661:tid 358847] [client 65.21.113.253:41602] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RvAlWhjQfpOo60_HNUAAAADU"]
[Tue Jul 21 08:02:21.385314 2026] [security2:error] [pid 352421:tid 352576] [client 20.220.225.223:34182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9RvcJSWzG9jbYOtu4_jAAAAJ4"]
[Tue Jul 21 08:02:21.426231 2026] [security2:error] [pid 352421:tid 352607] [client 20.151.10.161:39824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/aa2.php"] [unique_id "al9RvcJSWzG9jbYOtu4_kQAAAL0"]
[Tue Jul 21 08:02:21.501142 2026] [security2:error] [pid 352421:tid 352596] [client 20.197.195.24:2877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/ccou.php"] [unique_id "al9RvcJSWzG9jbYOtu4_kgAAALI"]
[Tue Jul 21 08:02:21.564624 2026] [security2:error] [pid 358661:tid 358833] [client 103.166.103.129:51522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RvQlWhjQfpOo60_HNVwAAACc"]
[Tue Jul 21 08:02:21.564821 2026] [security2:error] [pid 358661:tid 358833] [client 103.166.103.129:51522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RvQlWhjQfpOo60_HNVwAAACc"]
[Tue Jul 21 08:02:21.636709 2026] [security2:error] [pid 358661:tid 358863] [client 20.197.192.193:56812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/mac.php"] [unique_id "al9RvQlWhjQfpOo60_HNWAAAAEU"]
[Tue Jul 21 08:02:21.822083 2026] [security2:error] [pid 358661:tid 358805] [client 20.151.10.161:39853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/ccou.php"] [unique_id "al9RvQlWhjQfpOo60_HNWQAAAAs"]
[Tue Jul 21 08:02:21.976383 2026] [security2:error] [pid 358661:tid 358860] [client 65.21.113.253:47464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RvQlWhjQfpOo60_HNWwAAAEI"]
[Tue Jul 21 08:02:22.064340 2026] [security2:error] [pid 358661:tid 358804] [client 20.197.195.24:2860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/w3lls.php"] [unique_id "al9RvglWhjQfpOo60_HNXQAAAAo"]
[Tue Jul 21 08:02:22.414877 2026] [security2:error] [pid 352421:tid 352654] [client 193.36.225.58:60349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9RvsJSWzG9jbYOtu4_mwAAAOw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:02:22.617089 2026] [security2:error] [pid 358661:tid 358884] [client 65.21.113.253:41602] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RvglWhjQfpOo60_HNYAAAAFo"]
[Tue Jul 21 08:02:22.741582 2026] [security2:error] [pid 358661:tid 358859] [client 178.153.91.96:24771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RvglWhjQfpOo60_HNaQAAAEE"]
[Tue Jul 21 08:02:22.741720 2026] [security2:error] [pid 358661:tid 358859] [client 178.153.91.96:24771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RvglWhjQfpOo60_HNaQAAAEE"]
[Tue Jul 21 08:02:22.847160 2026] [security2:error] [pid 358661:tid 358915] [client 20.151.10.161:39770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/dr.php"] [unique_id "al9RvglWhjQfpOo60_HNawAAAHk"]
[Tue Jul 21 08:02:23.182338 2026] [security2:error] [pid 358661:tid 358911] [client 122.179.91.63:12873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RvwlWhjQfpOo60_HNbgAAAHU"]
[Tue Jul 21 08:02:23.182455 2026] [security2:error] [pid 358661:tid 358911] [client 122.179.91.63:12873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RvwlWhjQfpOo60_HNbgAAAHU"]
[Tue Jul 21 08:02:23.378706 2026] [security2:error] [pid 358661:tid 358882] [client 20.151.10.161:39751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/xamp.php"] [unique_id "al9RvwlWhjQfpOo60_HNbwAAAFg"]
[Tue Jul 21 08:02:23.515012 2026] [security2:error] [pid 358661:tid 358790] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RvwlWhjQfpOo60_HNdAAAF30"]
[Tue Jul 21 08:02:23.515191 2026] [security2:error] [pid 358661:tid 358817] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RvwlWhjQfpOo60_HNdAAAF30"]
[Tue Jul 21 08:02:23.560272 2026] [security2:error] [pid 358661:tid 358744] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RvwlWhjQfpOo60_HNdgAABU8"]
[Tue Jul 21 08:02:23.560456 2026] [security2:error] [pid 358661:tid 358799] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RvwlWhjQfpOo60_HNdgAABU8"]
[Tue Jul 21 08:02:23.782317 2026] [security2:error] [pid 352421:tid 352468] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rv8JSWzG9jbYOtu4_rwAAvy4"]
[Tue Jul 21 08:02:23.782449 2026] [security2:error] [pid 352421:tid 352609] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rv8JSWzG9jbYOtu4_rwAAvy4"]
[Tue Jul 21 08:02:23.980399 2026] [security2:error] [pid 352421:tid 352608] [client 117.210.135.0:55561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rv8JSWzG9jbYOtu4_swAAAL4"]
[Tue Jul 21 08:02:23.980524 2026] [security2:error] [pid 352421:tid 352608] [client 117.210.135.0:55561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rv8JSWzG9jbYOtu4_swAAAL4"]
[Tue Jul 21 08:02:24.103545 2026] [security2:error] [pid 358661:tid 358907] [client 20.197.195.24:58997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/test1.php"] [unique_id "al9RwAlWhjQfpOo60_HNfAAAAHE"]
[Tue Jul 21 08:02:24.308146 2026] [security2:error] [pid 358661:tid 358811] [client 20.151.10.161:39767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/bless.php"] [unique_id "al9RwAlWhjQfpOo60_HNfgAAABE"]
[Tue Jul 21 08:02:24.315974 2026] [security2:error] [pid 358661:tid 358802] [client 41.68.90.219:60162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwAlWhjQfpOo60_HNfwAAAAg"]
[Tue Jul 21 08:02:24.316132 2026] [security2:error] [pid 358661:tid 358802] [client 41.68.90.219:60162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwAlWhjQfpOo60_HNfwAAAAg"]
[Tue Jul 21 08:02:24.383171 2026] [security2:error] [pid 358661:tid 358825] [client 38.100.221.102:17766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwAlWhjQfpOo60_HNggAAAB8"]
[Tue Jul 21 08:02:24.383293 2026] [security2:error] [pid 358661:tid 358825] [client 38.100.221.102:17766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwAlWhjQfpOo60_HNggAAAB8"]
[Tue Jul 21 08:02:24.494526 2026] [security2:error] [pid 358661:tid 358687] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwAlWhjQfpOo60_HNhAAATBY"]
[Tue Jul 21 08:02:24.494718 2026] [security2:error] [pid 358661:tid 358870] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwAlWhjQfpOo60_HNhAAATBY"]
[Tue Jul 21 08:02:24.662154 2026] [security2:error] [pid 358661:tid 358759] [remote 216.73.216.248:16627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwAlWhjQfpOo60_HNgAAAdl4"]
[Tue Jul 21 08:02:24.665621 2026] [security2:error] [pid 358661:tid 358901] [client 175.144.82.48:60163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwAlWhjQfpOo60_HNiQAAAGs"]
[Tue Jul 21 08:02:24.666544 2026] [security2:error] [pid 358661:tid 358901] [client 175.144.82.48:60163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwAlWhjQfpOo60_HNiQAAAGs"]
[Tue Jul 21 08:02:24.768585 2026] [security2:error] [pid 358661:tid 358816] [client 20.104.96.117:27076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/core.php"] [unique_id "al9RwAlWhjQfpOo60_HNiwAAABY"]
[Tue Jul 21 08:02:24.886597 2026] [security2:error] [pid 358661:tid 358814] [client 65.21.113.253:43358] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RwAlWhjQfpOo60_HNgwAAABQ"]
[Tue Jul 21 08:02:25.286157 2026] [security2:error] [pid 358661:tid 358792] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwQlWhjQfpOo60_HNkwAAQn8"]
[Tue Jul 21 08:02:25.286346 2026] [security2:error] [pid 358661:tid 358860] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwQlWhjQfpOo60_HNkwAAQn8"]
[Tue Jul 21 08:02:25.540478 2026] [security2:error] [pid 358661:tid 358823] [client 20.197.195.24:59007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/database.php"] [unique_id "al9RwQlWhjQfpOo60_HNngAAAB0"]
[Tue Jul 21 08:02:25.732141 2026] [security2:error] [pid 352421:tid 352470] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwcJSWzG9jbYOtu4_xwAA8jA"]
[Tue Jul 21 08:02:25.732279 2026] [security2:error] [pid 352421:tid 352660] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwcJSWzG9jbYOtu4_xwAA8jA"]
[Tue Jul 21 08:02:25.795727 2026] [security2:error] [pid 352421:tid 352574] [client 223.236.153.128:6550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RwcJSWzG9jbYOtu4_yAAAAJw"]
[Tue Jul 21 08:02:25.810353 2026] [security2:error] [pid 352421:tid 352574] [client 223.236.153.128:6550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RwcJSWzG9jbYOtu4_yAAAAJw"]
[Tue Jul 21 08:02:25.831879 2026] [security2:error] [pid 358661:tid 358797] [client 20.151.10.161:39899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/file46.php"] [unique_id "al9RwQlWhjQfpOo60_HNoQAAAAM"]
[Tue Jul 21 08:02:26.125010 2026] [security2:error] [pid 352421:tid 352443] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RwsJSWzG9jbYOtu4_zwAA5hU"]
[Tue Jul 21 08:02:26.125172 2026] [security2:error] [pid 352421:tid 352648] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RwsJSWzG9jbYOtu4_zwAA5hU"]
[Tue Jul 21 08:02:26.364849 2026] [security2:error] [pid 358661:tid 358735] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RwglWhjQfpOo60_HNrgAAE0Y"]
[Tue Jul 21 08:02:26.364997 2026] [security2:error] [pid 358661:tid 358813] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RwglWhjQfpOo60_HNrgAAE0Y"]
[Tue Jul 21 08:02:26.507871 2026] [security2:error] [pid 358661:tid 358893] [client 120.56.162.40:61043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwglWhjQfpOo60_HNrQAAAGM"]
[Tue Jul 21 08:02:26.617925 2026] [security2:error] [pid 358661:tid 358839] [client 65.21.113.253:47464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RwglWhjQfpOo60_HNsAAAAC0"]
[Tue Jul 21 08:02:27.043526 2026] [security2:error] [pid 358661:tid 358894] [client 20.197.195.24:58953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/file.php"] [unique_id "al9RwwlWhjQfpOo60_HNuQAAAGQ"]
[Tue Jul 21 08:02:27.260746 2026] [security2:error] [pid 358661:tid 358819] [client 65.21.113.253:43358] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RwglWhjQfpOo60_HNswAAABk"]
[Tue Jul 21 08:02:27.377360 2026] [security2:error] [pid 358661:tid 358814] [client 173.252.95.21:56510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9RwwlWhjQfpOo60_HNvQAAABQ"]
[Tue Jul 21 08:02:27.452917 2026] [security2:error] [pid 358661:tid 358805] [client 172.245.102.45:44919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RwglWhjQfpOo60_HNrAAAAAs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:02:27.599458 2026] [security2:error] [pid 358661:tid 358916] [client 20.220.225.223:34301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/dp.php"] [unique_id "al9RwwlWhjQfpOo60_HNxgAAAHo"]
[Tue Jul 21 08:02:27.929400 2026] [security2:error] [pid 358661:tid 358913] [client 20.197.192.193:56780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/samll.php"] [unique_id "al9RwwlWhjQfpOo60_HNywAAAHc"]
[Tue Jul 21 08:02:27.944317 2026] [security2:error] [pid 358661:tid 358667] [remote 4.205.168.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/wp-login.php"] [unique_id "al9RwwlWhjQfpOo60_HNzAAAWgI"]
[Tue Jul 21 08:02:28.100489 2026] [security2:error] [pid 358661:tid 358907] [client 31.128.76.67:34330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.76.128.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwglWhjQfpOo60_HNtAAAAHE"]
[Tue Jul 21 08:02:28.100696 2026] [security2:error] [pid 358661:tid 358907] [client 31.128.76.67:34330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "inlaudo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RwglWhjQfpOo60_HNtAAAAHE"]
[Tue Jul 21 08:02:28.618434 2026] [security2:error] [pid 352421:tid 352456] [remote 119.195.102.159:35016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9RxMJSWzG9jbYOtu4_8QAAuSI"]
[Tue Jul 21 08:02:28.767899 2026] [security2:error] [pid 358661:tid 358911] [client 103.86.117.203:51527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RxAlWhjQfpOo60_HN1QAAAHU"]
[Tue Jul 21 08:02:28.768053 2026] [security2:error] [pid 358661:tid 358911] [client 103.86.117.203:51527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9RxAlWhjQfpOo60_HN1QAAAHU"]
[Tue Jul 21 08:02:28.880627 2026] [security2:error] [pid 352421:tid 352606] [client 65.21.113.253:43370] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RxMJSWzG9jbYOtu4_7gAAALw"]
[Tue Jul 21 08:02:28.907301 2026] [security2:error] [pid 358661:tid 358802] [client 20.197.195.24:2859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/file.php"] [unique_id "al9RxAlWhjQfpOo60_HN1wAAAAg"]
[Tue Jul 21 08:02:28.951387 2026] [security2:error] [pid 358661:tid 358754] [remote 114.34.90.9:45350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteoficialgs.com"] [uri "/wp-login.php"] [unique_id "al9RxAlWhjQfpOo60_HN2QAAcFk"]
[Tue Jul 21 08:02:28.992363 2026] [security2:error] [pid 358661:tid 358752] [remote 199.189.225.40:52135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9RxAlWhjQfpOo60_HN2gAAO1c"]
[Tue Jul 21 08:02:29.006172 2026] [security2:error] [pid 358661:tid 358920] [client 106.215.181.8:6656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RxQlWhjQfpOo60_HN2wAAAH4"]
[Tue Jul 21 08:02:29.016029 2026] [security2:error] [pid 358661:tid 358920] [client 106.215.181.8:6656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RxQlWhjQfpOo60_HN2wAAAH4"]
[Tue Jul 21 08:02:29.283952 2026] [security2:error] [pid 358661:tid 358902] [client 87.116.180.198:13899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RxQlWhjQfpOo60_HN4QAAAGw"]
[Tue Jul 21 08:02:29.288273 2026] [security2:error] [pid 358661:tid 358902] [client 87.116.180.198:13899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RxQlWhjQfpOo60_HN4QAAAGw"]
[Tue Jul 21 08:02:29.387264 2026] [security2:error] [pid 352421:tid 352590] [client 117.247.80.59:21383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RxcJSWzG9jbYOtu4__gAAAKw"]
[Tue Jul 21 08:02:29.387367 2026] [security2:error] [pid 352421:tid 352590] [client 117.247.80.59:21383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RxcJSWzG9jbYOtu4__gAAAKw"]
[Tue Jul 21 08:02:29.499715 2026] [security2:error] [pid 352421:tid 352589] [client 102.206.115.33:57917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RxcJSWzG9jbYOtu5AAAAAAKs"]
[Tue Jul 21 08:02:29.500101 2026] [security2:error] [pid 352421:tid 352589] [client 102.206.115.33:57917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9RxcJSWzG9jbYOtu5AAAAAAKs"]
[Tue Jul 21 08:02:30.068067 2026] [autoindex:error] [pid 358661:tid 358860] [client 192.36.109.82:39821] AH01276: Cannot serve directory /home2/rebe1126/rebecavivone.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:02:30.290511 2026] [security2:error] [pid 358661:tid 358888] [client 103.29.114.44:56229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RxglWhjQfpOo60_HN7QAAAF4"]
[Tue Jul 21 08:02:30.290623 2026] [security2:error] [pid 358661:tid 358888] [client 103.29.114.44:56229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RxglWhjQfpOo60_HN7QAAAF4"]
[Tue Jul 21 08:02:30.329377 2026] [security2:error] [pid 358661:tid 358840] [client 20.151.10.161:39699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/eee.php"] [unique_id "al9RxglWhjQfpOo60_HN7wAAAC4"]
[Tue Jul 21 08:02:30.347487 2026] [security2:error] [pid 352421:tid 352584] [client 20.220.225.223:34241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/old.php"] [unique_id "al9RxsJSWzG9jbYOtu5AFAAAAKY"]
[Tue Jul 21 08:02:30.350914 2026] [security2:error] [pid 358661:tid 358824] [client 65.21.113.253:47464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RxglWhjQfpOo60_HN8AAAAB4"]
[Tue Jul 21 08:02:30.599100 2026] [security2:error] [pid 358661:tid 358919] [client 20.197.192.193:52268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9RxglWhjQfpOo60_HN9QAAAH0"]
[Tue Jul 21 08:02:30.844019 2026] [security2:error] [pid 358661:tid 358846] [client 20.197.195.24:2821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/777.php"] [unique_id "al9RxglWhjQfpOo60_HN9gAAADQ"]
[Tue Jul 21 08:02:30.951253 2026] [security2:error] [pid 358661:tid 358897] [client 20.151.10.161:39864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/file25.php"] [unique_id "al9RxglWhjQfpOo60_HN-AAAAGc"]
[Tue Jul 21 08:02:30.990875 2026] [security2:error] [pid 352421:tid 352621] [client 65.21.113.253:43370] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RxsJSWzG9jbYOtu5AFQAAAMs"]
[Tue Jul 21 08:02:31.189057 2026] [security2:error] [pid 352421:tid 352640] [client 109.60.28.94:60557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rx8JSWzG9jbYOtu5AHwAAAN4"]
[Tue Jul 21 08:02:31.189203 2026] [security2:error] [pid 352421:tid 352640] [client 109.60.28.94:60557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rx8JSWzG9jbYOtu5AHwAAAN4"]
[Tue Jul 21 08:02:31.300928 2026] [security2:error] [pid 358661:tid 358767] [remote 97.74.93.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amandamorau.adv.br"] [uri "/wp-login.php"] [unique_id "al9RxwlWhjQfpOo60_HN_gAAcWY"]
[Tue Jul 21 08:02:31.391480 2026] [security2:error] [pid 358661:tid 358893] [client 103.78.200.11:53060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RxwlWhjQfpOo60_HOAAAAAGM"]
[Tue Jul 21 08:02:31.391582 2026] [security2:error] [pid 358661:tid 358893] [client 103.78.200.11:53060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RxwlWhjQfpOo60_HOAAAAAGM"]
[Tue Jul 21 08:02:31.468502 2026] [security2:error] [pid 358661:tid 358875] [client 20.104.96.117:46642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/19.php"] [unique_id "al9RxwlWhjQfpOo60_HOAQAAAFE"]
[Tue Jul 21 08:02:31.589130 2026] [security2:error] [pid 352421:tid 352661] [client 182.8.255.181:21057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Rx8JSWzG9jbYOtu5AIwAAAPM"]
[Tue Jul 21 08:02:31.589297 2026] [security2:error] [pid 352421:tid 352661] [client 182.8.255.181:21057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Rx8JSWzG9jbYOtu5AIwAAAPM"]
[Tue Jul 21 08:02:31.659211 2026] [security2:error] [pid 358661:tid 358864] [client 202.143.127.214:52693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RxwlWhjQfpOo60_HOAwAAAEY"]
[Tue Jul 21 08:02:31.659370 2026] [security2:error] [pid 358661:tid 358864] [client 202.143.127.214:52693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RxwlWhjQfpOo60_HOAwAAAEY"]
[Tue Jul 21 08:02:31.806380 2026] [security2:error] [pid 352421:tid 352672] [client 136.144.33.101:40913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9Rx8JSWzG9jbYOtu5AKQAAAP4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:02:31.973704 2026] [security2:error] [pid 358661:tid 358822] [client 20.197.192.193:50585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/abcd.php"] [unique_id "al9RxwlWhjQfpOo60_HOCQAAABw"]
[Tue Jul 21 08:02:32.409434 2026] [security2:error] [pid 358661:tid 358853] [client 103.166.103.129:14019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RyAlWhjQfpOo60_HOEAAAADs"]
[Tue Jul 21 08:02:32.409576 2026] [security2:error] [pid 358661:tid 358853] [client 103.166.103.129:14019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9RyAlWhjQfpOo60_HOEAAAADs"]
[Tue Jul 21 08:02:32.800487 2026] [security2:error] [pid 358661:tid 358826] [client 122.179.91.63:3555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RyAlWhjQfpOo60_HOGAAAACA"]
[Tue Jul 21 08:02:32.800686 2026] [security2:error] [pid 358661:tid 358826] [client 122.179.91.63:3555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9RyAlWhjQfpOo60_HOGAAAACA"]
[Tue Jul 21 08:02:32.836863 2026] [security2:error] [pid 358661:tid 358860] [client 65.21.113.253:47464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RyAlWhjQfpOo60_HOGQAAAEI"]
[Tue Jul 21 08:02:33.165029 2026] [security2:error] [pid 352421:tid 352564] [client 65.21.113.253:44348] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RyMJSWzG9jbYOtu5ANQAAAJI"]
[Tue Jul 21 08:02:33.412362 2026] [security2:error] [pid 358661:tid 358885] [client 178.153.91.96:64628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RyQlWhjQfpOo60_HOJAAAAFs"]
[Tue Jul 21 08:02:33.412499 2026] [security2:error] [pid 358661:tid 358885] [client 178.153.91.96:64628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9RyQlWhjQfpOo60_HOJAAAAFs"]
[Tue Jul 21 08:02:33.839619 2026] [security2:error] [pid 358661:tid 358818] [client 20.197.192.193:53160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9RyQlWhjQfpOo60_HOJQAAABg"]
[Tue Jul 21 08:02:33.907671 2026] [security2:error] [pid 352421:tid 352600] [client 65.21.113.253:44352] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RycJSWzG9jbYOtu5AQwAAALY"]
[Tue Jul 21 08:02:34.043141 2026] [security2:error] [pid 358661:tid 358702] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RyglWhjQfpOo60_HOKgAAIyU"]
[Tue Jul 21 08:02:34.043344 2026] [security2:error] [pid 358661:tid 358829] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9RyglWhjQfpOo60_HOKgAAIyU"]
[Tue Jul 21 08:02:34.066271 2026] [security2:error] [pid 358661:tid 358919] [client 117.210.135.0:56221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RyglWhjQfpOo60_HOKwAAAH0"]
[Tue Jul 21 08:02:34.066418 2026] [security2:error] [pid 358661:tid 358919] [client 117.210.135.0:56221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RyglWhjQfpOo60_HOKwAAAH0"]
[Tue Jul 21 08:02:34.320365 2026] [security2:error] [pid 358661:tid 358710] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RyglWhjQfpOo60_HOLQAAJS0"]
[Tue Jul 21 08:02:34.320562 2026] [security2:error] [pid 358661:tid 358831] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RyglWhjQfpOo60_HOLQAAJS0"]
[Tue Jul 21 08:02:34.446647 2026] [security2:error] [pid 358661:tid 358772] [remote 62.60.130.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "conquisteemcasa.com.br"] [uri "/"] [unique_id "al9RyglWhjQfpOo60_HOMAAAYWs"]
[Tue Jul 21 08:02:34.511881 2026] [security2:error] [pid 358661:tid 358914] [client 104.207.42.64:45551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.42.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9RyglWhjQfpOo60_HOLgAAAHg"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:02:34.523949 2026] [security2:error] [pid 358661:tid 358762] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RyglWhjQfpOo60_HONAAACmE"]
[Tue Jul 21 08:02:34.524089 2026] [security2:error] [pid 358661:tid 358804] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9RyglWhjQfpOo60_HONAAACmE"]
[Tue Jul 21 08:02:34.525850 2026] [security2:error] [pid 358661:tid 358875] [client 20.220.225.223:34281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/ms-new.php"] [unique_id "al9RyglWhjQfpOo60_HONQAAAFE"]
[Tue Jul 21 08:02:34.721457 2026] [security2:error] [pid 358661:tid 358778] [remote 62.60.130.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "conquisteemcasa.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9RyglWhjQfpOo60_HOOAAACHE"]
[Tue Jul 21 08:02:34.779130 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779225 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779332 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779374 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779409 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779517 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779586 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779630 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779696 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779733 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779771 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779809 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779857 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779893 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779929 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779963 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.779999 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780035 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780070 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780105 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780140 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780175 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780210 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780245 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780281 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780317 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780353 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780388 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780473 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780510 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780545 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780580 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780616 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780658 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780698 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780733 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780769 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780805 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780860 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780895 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780945 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.780986 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781027 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781087 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781128 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781164 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781200 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781235 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781284 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781329 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781364 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781400 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781436 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781473 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781508 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781544 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781581 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781618 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781660 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781692 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781730 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781776 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781808 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781862 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781900 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781933 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.781978 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782015 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782051 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782089 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782130 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782168 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782209 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782246 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782281 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782317 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782355 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782411 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782462 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782518 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782572 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782625 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782670 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782709 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782764 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782824 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782880 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782939 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.782999 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.783054 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.783120 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.783181 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.783249 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.783308 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.783376 2026] [lsapi:warn] [pid 358661:tid 358900] [client 43.130.40.120:51496] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:02:34.843682 2026] [security2:error] [pid 358661:tid 358907] [client 38.100.221.102:18990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RyglWhjQfpOo60_HOOQAAAHE"]
[Tue Jul 21 08:02:34.843807 2026] [security2:error] [pid 358661:tid 358907] [client 38.100.221.102:18990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RyglWhjQfpOo60_HOOQAAAHE"]
[Tue Jul 21 08:02:34.881665 2026] [security2:error] [pid 352421:tid 352558] [client 20.197.192.193:56806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/xyn.php"] [unique_id "al9RysJSWzG9jbYOtu5AVAAAAIw"]
[Tue Jul 21 08:02:34.883395 2026] [security2:error] [pid 352421:tid 352591] [client 20.151.10.161:39869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/file48.php"] [unique_id "al9RysJSWzG9jbYOtu5AVQAAAK0"]
[Tue Jul 21 08:02:34.927460 2026] [security2:error] [pid 358661:tid 358838] [client 204.8.98.45:53326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9RyglWhjQfpOo60_HOOgAAACw"]
[Tue Jul 21 08:02:34.927585 2026] [security2:error] [pid 358661:tid 358838] [client 204.8.98.45:53326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9RyglWhjQfpOo60_HOOgAAACw"]
[Tue Jul 21 08:02:34.953964 2026] [security2:error] [pid 358661:tid 358910] [client 41.68.90.219:60638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RyglWhjQfpOo60_HOOwAAAHQ"]
[Tue Jul 21 08:02:34.954999 2026] [security2:error] [pid 358661:tid 358910] [client 41.68.90.219:60638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RyglWhjQfpOo60_HOOwAAAHQ"]
[Tue Jul 21 08:02:34.986499 2026] [security2:error] [pid 352421:tid 352626] [client 20.197.195.24:2921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/ssixta.php"] [unique_id "al9RysJSWzG9jbYOtu5AVwAAANA"]
[Tue Jul 21 08:02:35.158669 2026] [security2:error] [pid 358661:tid 358813] [client 175.144.82.48:60587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RywlWhjQfpOo60_HOQAAAABM"]
[Tue Jul 21 08:02:35.159238 2026] [security2:error] [pid 358661:tid 358813] [client 175.144.82.48:60587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RywlWhjQfpOo60_HOQAAAABM"]
[Tue Jul 21 08:02:35.326969 2026] [security2:error] [pid 358661:tid 358757] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RywlWhjQfpOo60_HOQQAAAlw"]
[Tue Jul 21 08:02:35.327163 2026] [security2:error] [pid 358661:tid 358796] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RywlWhjQfpOo60_HOQQAAAlw"]
[Tue Jul 21 08:02:35.594937 2026] [security2:error] [pid 358661:tid 358834] [client 20.197.192.193:53157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/wander.php"] [unique_id "al9RywlWhjQfpOo60_HOSgAAACg"]
[Tue Jul 21 08:02:35.610476 2026] [security2:error] [pid 358661:tid 358832] [client 136.144.33.108:64519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9RywlWhjQfpOo60_HOSwAAACY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:02:36.020105 2026] [security2:error] [pid 352421:tid 352588] [client 92.119.178.3:40174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9RzMJSWzG9jbYOtu5AZAAAAKo"]
[Tue Jul 21 08:02:36.020181 2026] [security2:error] [pid 352421:tid 352588] [client 92.119.178.3:40174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9RzMJSWzG9jbYOtu5AZAAAAKo"]
[Tue Jul 21 08:02:36.247914 2026] [security2:error] [pid 358661:tid 358899] [client 223.236.153.128:5170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RzAlWhjQfpOo60_HOTwAAAGk"]
[Tue Jul 21 08:02:36.248044 2026] [security2:error] [pid 358661:tid 358899] [client 223.236.153.128:5170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9RzAlWhjQfpOo60_HOTwAAAGk"]
[Tue Jul 21 08:02:36.255207 2026] [security2:error] [pid 358661:tid 358903] [client 20.151.10.161:39842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/file6.php"] [unique_id "al9RzAlWhjQfpOo60_HOUAAAAG0"]
[Tue Jul 21 08:02:36.270096 2026] [security2:error] [pid 352421:tid 352638] [client 65.21.113.253:44348] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Ry8JSWzG9jbYOtu5AYQAAANw"]
[Tue Jul 21 08:02:36.286627 2026] [security2:error] [pid 358661:tid 358726] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RzAlWhjQfpOo60_HOUQAAXj0"]
[Tue Jul 21 08:02:36.286777 2026] [security2:error] [pid 358661:tid 358888] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RzAlWhjQfpOo60_HOUQAAXj0"]
[Tue Jul 21 08:02:36.465312 2026] [security2:error] [pid 358661:tid 358803] [client 216.73.160.43:59337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/wp-login.php"] [unique_id "al9RzAlWhjQfpOo60_HOUgAAAAk"]
[Tue Jul 21 08:02:36.547286 2026] [security2:error] [pid 352421:tid 352613] [client 20.197.192.193:52249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/jga.php"] [unique_id "al9RzMJSWzG9jbYOtu5AbAAAAMM"]
[Tue Jul 21 08:02:36.576022 2026] [security2:error] [pid 352421:tid 352430] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RzMJSWzG9jbYOtu5AcQAA0wg"]
[Tue Jul 21 08:02:36.576195 2026] [security2:error] [pid 352421:tid 352629] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RzMJSWzG9jbYOtu5AcQAA0wg"]
[Tue Jul 21 08:02:36.630003 2026] [security2:error] [pid 358661:tid 358921] [client 65.21.113.253:47464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9RzAlWhjQfpOo60_HOUwAAAH8"]
[Tue Jul 21 08:02:36.703291 2026] [security2:error] [pid 352421:tid 352459] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RzMJSWzG9jbYOtu5AdAAAsSU"]
[Tue Jul 21 08:02:36.703454 2026] [security2:error] [pid 352421:tid 352595] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9RzMJSWzG9jbYOtu5AdAAAsSU"]
[Tue Jul 21 08:02:36.729282 2026] [security2:error] [pid 358661:tid 358866] [client 45.8.19.150:25631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeireirapiske.com.br"] [uri "/wp-login.php"] [unique_id "al9RzAlWhjQfpOo60_HOVAAAAEg"]
[Tue Jul 21 08:02:36.968228 2026] [security2:error] [pid 358661:tid 358856] [client 120.56.162.40:61473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RzAlWhjQfpOo60_HOVgAAAD4"]
[Tue Jul 21 08:02:37.149798 2026] [security2:error] [pid 358661:tid 358718] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RzQlWhjQfpOo60_HOWgAAPTU"]
[Tue Jul 21 08:02:37.149967 2026] [security2:error] [pid 358661:tid 358855] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9RzQlWhjQfpOo60_HOWgAAPTU"]
[Tue Jul 21 08:02:37.244630 2026] [security2:error] [pid 352421:tid 352667] [client 65.21.113.253:44348] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9RzMJSWzG9jbYOtu5AdgAAAPk"]
[Tue Jul 21 08:02:37.259212 2026] [security2:error] [pid 352421:tid 352461] [remote 209.42.18.223:59742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "manual.fernandohipolito.com.br"] [uri "/wp-login.php"] [unique_id "al9RzcJSWzG9jbYOtu5AfQAA6yc"]
[Tue Jul 21 08:02:37.531526 2026] [security2:error] [pid 352421:tid 352618] [client 20.197.192.193:50604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/byp8.php"] [unique_id "al9RzcJSWzG9jbYOtu5AhAAAAMg"]
[Tue Jul 21 08:02:37.587348 2026] [security2:error] [pid 358661:tid 358733] [remote 124.55.178.99:60204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9RzQlWhjQfpOo60_HOZAAADUQ"]
[Tue Jul 21 08:02:37.713040 2026] [security2:error] [pid 352421:tid 352592] [client 20.197.195.24:2827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/1c.php"] [unique_id "al9RzcJSWzG9jbYOtu5AjgAAAK4"]
[Tue Jul 21 08:02:37.917632 2026] [security2:error] [pid 358661:tid 358800] [client 92.119.178.3:59912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9RzQlWhjQfpOo60_HOZQAAAAY"]
[Tue Jul 21 08:02:37.917767 2026] [security2:error] [pid 358661:tid 358800] [client 92.119.178.3:59912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9RzQlWhjQfpOo60_HOZQAAAAY"]
[Tue Jul 21 08:02:37.977455 2026] [security2:error] [pid 352421:tid 352614] [client 20.151.10.161:39705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/a2.php"] [unique_id "al9RzcJSWzG9jbYOtu5AjwAAAMQ"]
[Tue Jul 21 08:02:38.460367 2026] [security2:error] [pid 352421:tid 352633] [client 20.197.192.193:53154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/x.php"] [unique_id "al9RzsJSWzG9jbYOtu5AmAAAANc"]
[Tue Jul 21 08:02:39.247897 2026] [security2:error] [pid 352421:tid 352591] [client 103.86.117.203:51927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.117.86.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Rz8JSWzG9jbYOtu5ArQAAAK0"]
[Tue Jul 21 08:02:39.248020 2026] [security2:error] [pid 352421:tid 352591] [client 103.86.117.203:51927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deniansantos.com"] [uri "/xmlrpc.php"] [unique_id "al9Rz8JSWzG9jbYOtu5ArQAAAK0"]
[Tue Jul 21 08:02:39.616582 2026] [security2:error] [pid 352421:tid 352607] [client 106.215.181.8:3329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rz8JSWzG9jbYOtu5AsQAAAL0"]
[Tue Jul 21 08:02:39.616714 2026] [security2:error] [pid 352421:tid 352607] [client 106.215.181.8:3329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Rz8JSWzG9jbYOtu5AsQAAAL0"]
[Tue Jul 21 08:02:39.791158 2026] [security2:error] [pid 358661:tid 358842] [client 20.197.195.24:24090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/test2.php"] [unique_id "al9RzwlWhjQfpOo60_HOcQAAADA"]
[Tue Jul 21 08:02:39.948222 2026] [security2:error] [pid 358661:tid 358843] [client 87.116.180.198:27363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RzwlWhjQfpOo60_HOcwAAADE"]
[Tue Jul 21 08:02:39.948350 2026] [security2:error] [pid 358661:tid 358843] [client 87.116.180.198:27363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9RzwlWhjQfpOo60_HOcwAAADE"]
[Tue Jul 21 08:02:40.043101 2026] [security2:error] [pid 358661:tid 358870] [client 102.206.115.33:60092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9R0AlWhjQfpOo60_HOdAAAAEw"]
[Tue Jul 21 08:02:40.043539 2026] [security2:error] [pid 358661:tid 358870] [client 102.206.115.33:60092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9R0AlWhjQfpOo60_HOdAAAAEw"]
[Tue Jul 21 08:02:40.099395 2026] [security2:error] [pid 358661:tid 358814] [client 20.151.10.161:39685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/file15.php"] [unique_id "al9R0AlWhjQfpOo60_HOdQAAABQ"]
[Tue Jul 21 08:02:40.120009 2026] [security2:error] [pid 352421:tid 352676] [client 117.247.80.59:22074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R0MJSWzG9jbYOtu5AuAAAAQI"]
[Tue Jul 21 08:02:40.120150 2026] [security2:error] [pid 352421:tid 352676] [client 117.247.80.59:22074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R0MJSWzG9jbYOtu5AuAAAAQI"]
[Tue Jul 21 08:02:40.287091 2026] [security2:error] [pid 352421:tid 352654] [client 103.78.200.11:53552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R0MJSWzG9jbYOtu5AugAAAOw"]
[Tue Jul 21 08:02:40.287257 2026] [security2:error] [pid 352421:tid 352654] [client 103.78.200.11:53552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R0MJSWzG9jbYOtu5AugAAAOw"]
[Tue Jul 21 08:02:40.411857 2026] [security2:error] [pid 358661:tid 358911] [client 136.144.33.111:42191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9R0AlWhjQfpOo60_HOewAAAHU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:02:40.566825 2026] [security2:error] [pid 358661:tid 358840] [client 20.197.192.193:56799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/user.php"] [unique_id "al9R0AlWhjQfpOo60_HOgAAAAC4"]
[Tue Jul 21 08:02:40.705598 2026] [security2:error] [pid 352421:tid 352616] [client 20.104.96.117:27113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/inc.php"] [unique_id "al9R0MJSWzG9jbYOtu5AxAAAAMY"]
[Tue Jul 21 08:02:40.933428 2026] [security2:error] [pid 352421:tid 352674] [client 103.29.114.44:36789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R0MJSWzG9jbYOtu5AyQAAAQA"]
[Tue Jul 21 08:02:40.933527 2026] [security2:error] [pid 352421:tid 352674] [client 103.29.114.44:36789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R0MJSWzG9jbYOtu5AyQAAAQA"]
[Tue Jul 21 08:02:40.970673 2026] [security2:error] [pid 358661:tid 358867] [client 173.252.95.61:56718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9R0AlWhjQfpOo60_HOgQAAAEk"]
[Tue Jul 21 08:02:41.003758 2026] [security2:error] [pid 352421:tid 352556] [client 47.128.127.10:27886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "startonesite.com.br"] [uri "/robots.txt"] [unique_id "al9R0cJSWzG9jbYOtu5AywAAAIo"]
[Tue Jul 21 08:02:41.335249 2026] [security2:error] [pid 352421:tid 352526] [remote 49.13.1.223:46426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agrocibus.com.br"] [uri "/wp-login.php"] [unique_id "al9R0cJSWzG9jbYOtu5A0AAA4mg"]
[Tue Jul 21 08:02:41.955407 2026] [security2:error] [pid 352421:tid 352611] [client 109.60.28.94:56614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R0cJSWzG9jbYOtu5A3gAAAME"]
[Tue Jul 21 08:02:41.955570 2026] [security2:error] [pid 352421:tid 352611] [client 109.60.28.94:56614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R0cJSWzG9jbYOtu5A3gAAAME"]
[Tue Jul 21 08:02:42.261389 2026] [security2:error] [pid 358661:tid 358810] [client 65.21.113.253:50930] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9R0glWhjQfpOo60_HOmgAAABA"]
[Tue Jul 21 08:02:42.527538 2026] [security2:error] [pid 358661:tid 358844] [client 20.29.126.15:5832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9R0glWhjQfpOo60_HOnwAAADI"]
[Tue Jul 21 08:02:42.867520 2026] [security2:error] [pid 352421:tid 352588] [client 202.143.127.214:53177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R0sJSWzG9jbYOtu5A6QAAAKo"]
[Tue Jul 21 08:02:42.867666 2026] [security2:error] [pid 352421:tid 352588] [client 202.143.127.214:53177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R0sJSWzG9jbYOtu5A6QAAAKo"]
[Tue Jul 21 08:02:42.962699 2026] [security2:error] [pid 352421:tid 352584] [client 182.8.255.181:21071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9R0sJSWzG9jbYOtu5A7QAAAKY"]
[Tue Jul 21 08:02:42.962841 2026] [security2:error] [pid 352421:tid 352584] [client 182.8.255.181:21071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9R0sJSWzG9jbYOtu5A7QAAAKY"]
[Tue Jul 21 08:02:42.981600 2026] [security2:error] [pid 358661:tid 358737] [remote 188.164.197.230:37816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "monicamirandapereira1751478737000.bellarthconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "al9R0QlWhjQfpOo60_HOlwAABkg"]
[Tue Jul 21 08:02:43.098667 2026] [security2:error] [pid 358661:tid 358894] [client 103.166.103.129:52586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9R0wlWhjQfpOo60_HOpgAAAGQ"]
[Tue Jul 21 08:02:43.098803 2026] [security2:error] [pid 358661:tid 358894] [client 103.166.103.129:52586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9R0wlWhjQfpOo60_HOpgAAAGQ"]
[Tue Jul 21 08:02:43.164367 2026] [security2:error] [pid 358661:tid 358738] [remote 185.242.3.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-admin/install.php"] [unique_id "al9R0wlWhjQfpOo60_HOpwAAFEk"]
[Tue Jul 21 08:02:43.290187 2026] [security2:error] [pid 358661:tid 358869] [client 65.21.113.253:41018] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R0glWhjQfpOo60_HOowAAAEs"]
[Tue Jul 21 08:02:43.399866 2026] [security2:error] [pid 352421:tid 352621] [client 20.197.195.24:11134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/buy.php"] [unique_id "al9R08JSWzG9jbYOtu5A8wAAAMs"]
[Tue Jul 21 08:02:43.468328 2026] [security2:error] [pid 358661:tid 358822] [client 92.119.178.3:41082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9R0wlWhjQfpOo60_HOrAAAABw"]
[Tue Jul 21 08:02:43.468407 2026] [security2:error] [pid 358661:tid 358822] [client 92.119.178.3:41082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9R0wlWhjQfpOo60_HOrAAAABw"]
[Tue Jul 21 08:02:43.539759 2026] [security2:error] [pid 358661:tid 358847] [client 122.179.91.63:31356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9R0wlWhjQfpOo60_HOrgAAADU"]
[Tue Jul 21 08:02:43.540109 2026] [security2:error] [pid 358661:tid 358847] [client 122.179.91.63:31356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9R0wlWhjQfpOo60_HOrgAAADU"]
[Tue Jul 21 08:02:43.683273 2026] [security2:error] [pid 358661:tid 358683] [remote 185.242.3.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9R0wlWhjQfpOo60_HOrwAAbRI"]
[Tue Jul 21 08:02:43.896482 2026] [security2:error] [pid 358661:tid 358876] [client 178.153.91.96:65248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9R0wlWhjQfpOo60_HOsAAAAFI"]
[Tue Jul 21 08:02:43.896643 2026] [security2:error] [pid 358661:tid 358876] [client 178.153.91.96:65248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9R0wlWhjQfpOo60_HOsAAAAFI"]
[Tue Jul 21 08:02:44.263075 2026] [security2:error] [pid 352421:tid 352565] [client 20.151.10.161:39787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/jp.php"] [unique_id "al9R1MJSWzG9jbYOtu5A_gAAAJM"]
[Tue Jul 21 08:02:44.313014 2026] [security2:error] [pid 358661:tid 358897] [client 20.29.126.15:16946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9R1AlWhjQfpOo60_HOuAAAAGc"]
[Tue Jul 21 08:02:44.373108 2026] [security2:error] [pid 352421:tid 352668] [client 20.197.192.193:53133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/tinyfilemanager.php"] [unique_id "al9R1MJSWzG9jbYOtu5BAAAAAPo"]
[Tue Jul 21 08:02:44.441809 2026] [security2:error] [pid 358661:tid 358815] [client 65.21.113.253:41024] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R0wlWhjQfpOo60_HOswAAABU"]
[Tue Jul 21 08:02:44.485578 2026] [security2:error] [pid 358661:tid 358775] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9R1AlWhjQfpOo60_HOvgAAEm4"]
[Tue Jul 21 08:02:44.485787 2026] [security2:error] [pid 358661:tid 358812] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9R1AlWhjQfpOo60_HOvgAAEm4"]
[Tue Jul 21 08:02:44.595416 2026] [security2:error] [pid 352421:tid 352654] [client 117.210.135.0:56891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1MJSWzG9jbYOtu5BCAAAAOw"]
[Tue Jul 21 08:02:44.595509 2026] [security2:error] [pid 352421:tid 352654] [client 117.210.135.0:56891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1MJSWzG9jbYOtu5BCAAAAOw"]
[Tue Jul 21 08:02:44.809138 2026] [security2:error] [pid 352421:tid 352424] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1MJSWzG9jbYOtu5BCgAAogI"]
[Tue Jul 21 08:02:44.809260 2026] [security2:error] [pid 352421:tid 352580] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1MJSWzG9jbYOtu5BCgAAogI"]
[Tue Jul 21 08:02:44.836704 2026] [security2:error] [pid 358661:tid 358807] [client 20.151.10.161:39771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/f35.php"] [unique_id "al9R1AlWhjQfpOo60_HOvwAAAA0"]
[Tue Jul 21 08:02:45.114713 2026] [security2:error] [pid 358661:tid 358881] [client 193.36.225.10:46739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9R1QlWhjQfpOo60_HOwQAAAFc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:02:45.392833 2026] [security2:error] [pid 352421:tid 352566] [client 41.68.90.219:61090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1cJSWzG9jbYOtu5BEQAAAJQ"]
[Tue Jul 21 08:02:45.393509 2026] [security2:error] [pid 352421:tid 352566] [client 41.68.90.219:61090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1cJSWzG9jbYOtu5BEQAAAJQ"]
[Tue Jul 21 08:02:45.405071 2026] [security2:error] [pid 358661:tid 358797] [client 65.111.24.61:16045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9R1QlWhjQfpOo60_HOwgAAAAM"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:02:45.414889 2026] [security2:error] [pid 358661:tid 358668] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1QlWhjQfpOo60_HOwwAAOAM"]
[Tue Jul 21 08:02:45.415056 2026] [security2:error] [pid 358661:tid 358850] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1QlWhjQfpOo60_HOwwAAOAM"]
[Tue Jul 21 08:02:45.484236 2026] [security2:error] [pid 358661:tid 358891] [client 38.100.221.102:17698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1QlWhjQfpOo60_HOyAAAAGE"]
[Tue Jul 21 08:02:45.484723 2026] [security2:error] [pid 358661:tid 358891] [client 38.100.221.102:17698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1QlWhjQfpOo60_HOyAAAAGE"]
[Tue Jul 21 08:02:45.522056 2026] [security2:error] [pid 358661:tid 358753] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9R1QlWhjQfpOo60_HOygAASlg"]
[Tue Jul 21 08:02:45.522168 2026] [security2:error] [pid 358661:tid 358868] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9R1QlWhjQfpOo60_HOygAASlg"]
[Tue Jul 21 08:02:45.573173 2026] [security2:error] [pid 358661:tid 358878] [client 175.144.82.48:61018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1QlWhjQfpOo60_HOywAAAFQ"]
[Tue Jul 21 08:02:45.574165 2026] [security2:error] [pid 358661:tid 358878] [client 175.144.82.48:61018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1QlWhjQfpOo60_HOywAAAFQ"]
[Tue Jul 21 08:02:45.591072 2026] [security2:error] [pid 358661:tid 358910] [client 20.197.192.193:50580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/ops.php"] [unique_id "al9R1QlWhjQfpOo60_HOzQAAAHQ"]
[Tue Jul 21 08:02:45.650083 2026] [security2:error] [pid 358661:tid 358851] [client 20.104.96.117:27103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9R1QlWhjQfpOo60_HO0AAAADk"]
[Tue Jul 21 08:02:45.872060 2026] [security2:error] [pid 358661:tid 358877] [client 20.151.10.161:39701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-load.php"] [unique_id "al9R1QlWhjQfpOo60_HO1AAAAFM"]
[Tue Jul 21 08:02:45.913013 2026] [security2:error] [pid 358661:tid 358848] [client 65.21.113.253:50930] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9R1QlWhjQfpOo60_HO1QAAADY"]
[Tue Jul 21 08:02:46.393023 2026] [security2:error] [pid 358661:tid 358776] [remote 45.117.83.212:53376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1glWhjQfpOo60_HO4gAAT28"]
[Tue Jul 21 08:02:46.393167 2026] [security2:error] [pid 358661:tid 358873] [client 45.117.83.212:53376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1glWhjQfpOo60_HO4gAAT28"]
[Tue Jul 21 08:02:46.531780 2026] [security2:error] [pid 358661:tid 358817] [client 65.21.113.253:41024] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R1glWhjQfpOo60_HO3gAAABc"]
[Tue Jul 21 08:02:46.567631 2026] [security2:error] [pid 358661:tid 358803] [client 20.197.192.193:53169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/ee.php"] [unique_id "al9R1glWhjQfpOo60_HO5QAAAAk"]
[Tue Jul 21 08:02:46.709566 2026] [security2:error] [pid 358661:tid 358845] [client 223.236.153.128:5925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9R1glWhjQfpOo60_HO6gAAADM"]
[Tue Jul 21 08:02:46.709703 2026] [security2:error] [pid 358661:tid 358845] [client 223.236.153.128:5925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9R1glWhjQfpOo60_HO6gAAADM"]
[Tue Jul 21 08:02:46.937879 2026] [security2:error] [pid 352421:tid 352577] [client 45.3.54.215:11649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9R1sJSWzG9jbYOtu5BKQAAAJ8"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:02:47.091272 2026] [security2:error] [pid 358661:tid 358919] [client 20.197.192.193:50572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/term.php"] [unique_id "al9R1wlWhjQfpOo60_HO7QAAAH0"]
[Tue Jul 21 08:02:47.256376 2026] [security2:error] [pid 358661:tid 358777] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1wlWhjQfpOo60_HO8gAAWnA"]
[Tue Jul 21 08:02:47.256523 2026] [security2:error] [pid 358661:tid 358884] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1wlWhjQfpOo60_HO8gAAWnA"]
[Tue Jul 21 08:02:47.397148 2026] [security2:error] [pid 352421:tid 352503] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9R18JSWzG9jbYOtu5BLwAAu1E"]
[Tue Jul 21 08:02:47.397324 2026] [security2:error] [pid 352421:tid 352605] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9R18JSWzG9jbYOtu5BLwAAu1E"]
[Tue Jul 21 08:02:47.436312 2026] [security2:error] [pid 358661:tid 358748] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1wlWhjQfpOo60_HO8wAAN1M"]
[Tue Jul 21 08:02:47.436479 2026] [security2:error] [pid 358661:tid 358849] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1wlWhjQfpOo60_HO8wAAN1M"]
[Tue Jul 21 08:02:47.445600 2026] [security2:error] [pid 358661:tid 358898] [client 20.220.225.223:34277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/track.php"] [unique_id "al9R1wlWhjQfpOo60_HO9AAAAGg"]
[Tue Jul 21 08:02:47.463115 2026] [security2:error] [pid 358661:tid 358893] [client 20.197.195.24:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/ssend.php"] [unique_id "al9R1wlWhjQfpOo60_HO9QAAAGM"]
[Tue Jul 21 08:02:47.688945 2026] [security2:error] [pid 358661:tid 358812] [client 120.56.162.40:61893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R1wlWhjQfpOo60_HO-wAAABI"]
[Tue Jul 21 08:02:47.722535 2026] [security2:error] [pid 358661:tid 358707] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9R1wlWhjQfpOo60_HO_AAAUSo"]
[Tue Jul 21 08:02:47.722693 2026] [security2:error] [pid 358661:tid 358875] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9R1wlWhjQfpOo60_HO_AAAUSo"]
[Tue Jul 21 08:02:47.876943 2026] [autoindex:error] [pid 358661:tid 358838] [client 43.159.152.4:33734] AH01276: Cannot serve directory /home3/eltonf08/efrelectronics.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:02:47.960081 2026] [security2:error] [pid 358661:tid 358883] [client 65.21.113.253:50930] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9R1wlWhjQfpOo60_HO_wAAAFk"]
[Tue Jul 21 08:02:48.053410 2026] [security2:error] [pid 352421:tid 352567] [client 65.21.113.253:41026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R18JSWzG9jbYOtu5BMwAAAJU"]
[Tue Jul 21 08:02:48.495566 2026] [security2:error] [pid 358661:tid 358795] [client 20.197.192.193:56802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/ah25.php"] [unique_id "al9R2AlWhjQfpOo60_HPAwAAAAE"]
[Tue Jul 21 08:02:48.504096 2026] [security2:error] [pid 358661:tid 358814] [client 20.197.192.193:53155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/blue.php"] [unique_id "al9R2AlWhjQfpOo60_HPBAAAABQ"]
[Tue Jul 21 08:02:48.509361 2026] [security2:error] [pid 352421:tid 352660] [client 104.207.57.148:44631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9R2MJSWzG9jbYOtu5BRQAAAPI"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:02:49.022409 2026] [security2:error] [pid 352421:tid 352619] [client 172.245.102.45:40319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9R2cJSWzG9jbYOtu5BTgAAAMk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:02:49.037784 2026] [security2:error] [pid 358661:tid 358819] [client 65.21.113.253:41028] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R2AlWhjQfpOo60_HPBgAAABk"]
[Tue Jul 21 08:02:49.202104 2026] [security2:error] [pid 358661:tid 358856] [client 20.151.10.161:39748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/xwpg.php"] [unique_id "al9R2QlWhjQfpOo60_HPGAAAAD4"]
[Tue Jul 21 08:02:49.606552 2026] [security2:error] [pid 352421:tid 352557] [client 20.197.192.193:56792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/8.php"] [unique_id "al9R2cJSWzG9jbYOtu5BVQAAAIs"]
[Tue Jul 21 08:02:49.623476 2026] [security2:error] [pid 352421:tid 352635] [client 20.220.225.223:34185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/2352356666.php"] [unique_id "al9R2cJSWzG9jbYOtu5BVwAAANk"]
[Tue Jul 21 08:02:50.114931 2026] [security2:error] [pid 352421:tid 352602] [client 106.215.181.8:15762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R2sJSWzG9jbYOtu5BYQAAALg"]
[Tue Jul 21 08:02:50.115095 2026] [security2:error] [pid 352421:tid 352602] [client 106.215.181.8:15762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R2sJSWzG9jbYOtu5BYQAAALg"]
[Tue Jul 21 08:02:50.205810 2026] [security2:error] [pid 352421:tid 352600] [client 65.111.22.248:43773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9R2sJSWzG9jbYOtu5BYAAAALY"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:02:50.621688 2026] [security2:error] [pid 358661:tid 358800] [client 20.197.195.24:2908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/item.php"] [unique_id "al9R2glWhjQfpOo60_HPKwAAAAY"]
[Tue Jul 21 08:02:50.635379 2026] [security2:error] [pid 352421:tid 352626] [client 87.116.180.198:27178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R2sJSWzG9jbYOtu5BbwAAANA"]
[Tue Jul 21 08:02:50.635479 2026] [security2:error] [pid 352421:tid 352626] [client 87.116.180.198:27178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R2sJSWzG9jbYOtu5BbwAAANA"]
[Tue Jul 21 08:02:50.667611 2026] [security2:error] [pid 352421:tid 352590] [client 102.206.115.33:60546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9R2sJSWzG9jbYOtu5BcAAAAKw"]
[Tue Jul 21 08:02:50.667706 2026] [security2:error] [pid 352421:tid 352590] [client 102.206.115.33:60546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9R2sJSWzG9jbYOtu5BcAAAAKw"]
[Tue Jul 21 08:02:50.783621 2026] [security2:error] [pid 358661:tid 358868] [client 117.247.80.59:19766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R2glWhjQfpOo60_HPLgAAAEo"]
[Tue Jul 21 08:02:50.783804 2026] [security2:error] [pid 358661:tid 358868] [client 117.247.80.59:19766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R2glWhjQfpOo60_HPLgAAAEo"]
[Tue Jul 21 08:02:50.929542 2026] [security2:error] [pid 352421:tid 352648] [client 65.21.113.253:41026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R2sJSWzG9jbYOtu5BdAAAAOY"]
[Tue Jul 21 08:02:50.942137 2026] [security2:error] [pid 352421:tid 352627] [client 103.78.200.11:54037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R2sJSWzG9jbYOtu5BeAAAANE"]
[Tue Jul 21 08:02:50.942940 2026] [security2:error] [pid 352421:tid 352627] [client 103.78.200.11:54037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R2sJSWzG9jbYOtu5BeAAAANE"]
[Tue Jul 21 08:02:51.084447 2026] [security2:error] [pid 358661:tid 358847] [client 65.21.113.253:50930] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9R2wlWhjQfpOo60_HPNAAAADU"]
[Tue Jul 21 08:02:51.487829 2026] [security2:error] [pid 358661:tid 358840] [client 20.104.96.117:46675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9R2wlWhjQfpOo60_HPPAAAAC4"]
[Tue Jul 21 08:02:51.526396 2026] [security2:error] [pid 352421:tid 352663] [client 20.151.10.161:39921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/waf.php"] [unique_id "al9R28JSWzG9jbYOtu5BgwAAAPU"]
[Tue Jul 21 08:02:51.541832 2026] [security2:error] [pid 358661:tid 358892] [client 103.29.114.44:65402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R2wlWhjQfpOo60_HPPQAAAGI"]
[Tue Jul 21 08:02:51.541986 2026] [security2:error] [pid 358661:tid 358892] [client 103.29.114.44:65402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R2wlWhjQfpOo60_HPPQAAAGI"]
[Tue Jul 21 08:02:51.712289 2026] [security2:error] [pid 352421:tid 352657] [client 65.21.113.253:41026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R28JSWzG9jbYOtu5BfgAAAO8"]
[Tue Jul 21 08:02:51.777201 2026] [security2:error] [pid 358661:tid 358816] [client 20.197.195.24:2833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/ss.php"] [unique_id "al9R2wlWhjQfpOo60_HPQAAAABY"]
[Tue Jul 21 08:02:51.895980 2026] [security2:error] [pid 352421:tid 352562] [client 104.207.52.111:49925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9R28JSWzG9jbYOtu5BhwAAAJA"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:02:52.320779 2026] [security2:error] [pid 358661:tid 358813] [client 182.8.255.181:21064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9R3AlWhjQfpOo60_HPSQAAABM"]
[Tue Jul 21 08:02:52.320918 2026] [security2:error] [pid 358661:tid 358813] [client 182.8.255.181:21064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9R3AlWhjQfpOo60_HPSQAAABM"]
[Tue Jul 21 08:02:52.349040 2026] [security2:error] [pid 358661:tid 358849] [client 20.29.126.15:8562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/wp.php"] [unique_id "al9R3AlWhjQfpOo60_HPSgAAADc"]
[Tue Jul 21 08:02:52.812901 2026] [security2:error] [pid 352421:tid 352606] [client 109.60.28.94:57074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R3MJSWzG9jbYOtu5BlQAAALw"]
[Tue Jul 21 08:02:52.813112 2026] [security2:error] [pid 352421:tid 352606] [client 109.60.28.94:57074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R3MJSWzG9jbYOtu5BlQAAALw"]
[Tue Jul 21 08:02:53.054708 2026] [security2:error] [pid 358661:tid 358883] [client 20.151.10.161:39755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/xstelth.php"] [unique_id "al9R3QlWhjQfpOo60_HPVwAAAFk"]
[Tue Jul 21 08:02:53.169168 2026] [security2:error] [pid 358661:tid 358902] [client 20.220.225.223:34208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/pn.php"] [unique_id "al9R3QlWhjQfpOo60_HPWAAAAGw"]
[Tue Jul 21 08:02:53.678976 2026] [security2:error] [pid 358661:tid 358877] [client 185.198.240.22:45141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mbarcondicionados.com.br"] [uri "/wp-login.php"] [unique_id "al9R3QlWhjQfpOo60_HPXgAAAFM"]
[Tue Jul 21 08:02:53.837714 2026] [security2:error] [pid 352421:tid 352581] [client 202.143.127.214:53641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R3cJSWzG9jbYOtu5BnAAAAKM"]
[Tue Jul 21 08:02:53.837839 2026] [security2:error] [pid 352421:tid 352581] [client 202.143.127.214:53641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R3cJSWzG9jbYOtu5BnAAAAKM"]
[Tue Jul 21 08:02:53.845657 2026] [security2:error] [pid 358661:tid 358795] [client 103.166.103.129:15115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9R3QlWhjQfpOo60_HPXwAAAAE"]
[Tue Jul 21 08:02:53.845797 2026] [security2:error] [pid 358661:tid 358795] [client 103.166.103.129:15115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9R3QlWhjQfpOo60_HPXwAAAAE"]
[Tue Jul 21 08:02:53.878275 2026] [security2:error] [pid 352421:tid 352640] [client 193.36.225.60:54573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9R3cJSWzG9jbYOtu5BngAAAN4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:02:54.158258 2026] [security2:error] [pid 352421:tid 352574] [client 141.11.107.74:52423] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.bomtempo.eng.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9R3sJSWzG9jbYOtu5BpAAAAJw"]
[Tue Jul 21 08:02:54.201632 2026] [security2:error] [pid 352421:tid 352645] [client 141.11.107.74:52499] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bomtempo.eng.br"] [uri "/"] [unique_id "al9R3sJSWzG9jbYOtu5BpQAAAOM"]
[Tue Jul 21 08:02:54.235109 2026] [security2:error] [pid 352421:tid 352577] [client 141.11.107.74:52505] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.bomtempo.eng.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9R3sJSWzG9jbYOtu5BpgAAAJ8"]
[Tue Jul 21 08:02:54.453057 2026] [security2:error] [pid 358661:tid 358887] [client 178.153.91.96:26751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9R3glWhjQfpOo60_HPZQAAAF0"]
[Tue Jul 21 08:02:54.453161 2026] [security2:error] [pid 358661:tid 358887] [client 178.153.91.96:26751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9R3glWhjQfpOo60_HPZQAAAF0"]
[Tue Jul 21 08:02:54.518192 2026] [security2:error] [pid 358661:tid 358803] [client 20.151.10.161:39768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/wp-links.php"] [unique_id "al9R3glWhjQfpOo60_HPZgAAAAk"]
[Tue Jul 21 08:02:54.571788 2026] [security2:error] [pid 358661:tid 358918] [client 65.21.113.253:56252] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R3glWhjQfpOo60_HPYwAAAHw"]
[Tue Jul 21 08:02:54.730714 2026] [security2:error] [pid 358661:tid 358845] [client 92.119.178.3:58226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9R3glWhjQfpOo60_HPZwAAADM"]
[Tue Jul 21 08:02:54.730833 2026] [security2:error] [pid 358661:tid 358845] [client 92.119.178.3:58226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9R3glWhjQfpOo60_HPZwAAADM"]
[Tue Jul 21 08:02:54.895683 2026] [security2:error] [pid 358661:tid 358824] [client 20.151.10.161:28604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9R3glWhjQfpOo60_HPawAAAB4"]
[Tue Jul 21 08:02:54.958339 2026] [security2:error] [pid 358661:tid 358734] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9R3glWhjQfpOo60_HPbAAAb0U"]
[Tue Jul 21 08:02:54.958467 2026] [security2:error] [pid 358661:tid 358905] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9R3glWhjQfpOo60_HPbAAAb0U"]
[Tue Jul 21 08:02:55.121351 2026] [security2:error] [pid 358661:tid 358876] [client 117.210.135.0:57558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R3wlWhjQfpOo60_HPcgAAAFI"]
[Tue Jul 21 08:02:55.121462 2026] [security2:error] [pid 358661:tid 358876] [client 117.210.135.0:57558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R3wlWhjQfpOo60_HPcgAAAFI"]
[Tue Jul 21 08:02:55.143298 2026] [security2:error] [pid 352421:tid 352585] [client 20.104.96.117:46656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/ss.php"] [unique_id "al9R38JSWzG9jbYOtu5BtQAAAKc"]
[Tue Jul 21 08:02:55.146208 2026] [security2:error] [pid 352421:tid 352584] [client 20.197.195.24:58959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/hypo.php"] [unique_id "al9R38JSWzG9jbYOtu5BtgAAAKY"]
[Tue Jul 21 08:02:55.221792 2026] [security2:error] [pid 352421:tid 352626] [client 20.197.192.193:56818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/red.php"] [unique_id "al9R38JSWzG9jbYOtu5BtwAAANA"]
[Tue Jul 21 08:02:55.305536 2026] [security2:error] [pid 352421:tid 352596] [client 20.197.195.24:2890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/users.php"] [unique_id "al9R38JSWzG9jbYOtu5BuAAAALI"]
[Tue Jul 21 08:02:55.331957 2026] [security2:error] [pid 358661:tid 358751] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R3wlWhjQfpOo60_HPdAAAGFY"]
[Tue Jul 21 08:02:55.332085 2026] [security2:error] [pid 358661:tid 358818] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R3wlWhjQfpOo60_HPdAAAGFY"]
[Tue Jul 21 08:02:55.426519 2026] [security2:error] [pid 352421:tid 352639] [client 20.197.195.24:58944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/177.php"] [unique_id "al9R38JSWzG9jbYOtu5BugAAAN0"]
[Tue Jul 21 08:02:55.774083 2026] [security2:error] [pid 358661:tid 358802] [client 65.21.113.253:50930] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9R3wlWhjQfpOo60_HPfgAAAAg"]
[Tue Jul 21 08:02:55.955002 2026] [security2:error] [pid 352421:tid 352620] [client 20.151.10.161:28534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9R38JSWzG9jbYOtu5BwgAAAMo"]
[Tue Jul 21 08:02:56.027260 2026] [security2:error] [pid 358661:tid 358880] [client 175.144.82.48:61439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R4AlWhjQfpOo60_HPggAAAFY"]
[Tue Jul 21 08:02:56.027410 2026] [security2:error] [pid 358661:tid 358880] [client 175.144.82.48:61439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R4AlWhjQfpOo60_HPggAAAFY"]
[Tue Jul 21 08:02:56.045025 2026] [security2:error] [pid 352421:tid 352586] [client 41.68.90.219:61562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R4MJSWzG9jbYOtu5BwwAAAKg"]
[Tue Jul 21 08:02:56.046197 2026] [security2:error] [pid 352421:tid 352586] [client 41.68.90.219:61562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R4MJSWzG9jbYOtu5BwwAAAKg"]
[Tue Jul 21 08:02:56.088016 2026] [security2:error] [pid 358661:tid 358769] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R4AlWhjQfpOo60_HPgwAAamg"]
[Tue Jul 21 08:02:56.088176 2026] [security2:error] [pid 358661:tid 358900] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R4AlWhjQfpOo60_HPgwAAamg"]
[Tue Jul 21 08:02:56.088586 2026] [security2:error] [pid 352421:tid 352672] [client 38.100.221.102:18938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R4MJSWzG9jbYOtu5ByQAAAP4"]
[Tue Jul 21 08:02:56.088686 2026] [security2:error] [pid 352421:tid 352672] [client 38.100.221.102:18938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R4MJSWzG9jbYOtu5ByQAAAP4"]
[Tue Jul 21 08:02:56.377818 2026] [security2:error] [pid 358661:tid 358914] [client 65.21.113.253:56252] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R3wlWhjQfpOo60_HPgQAAAHg"]
[Tue Jul 21 08:02:56.519267 2026] [security2:error] [pid 358661:tid 358796] [client 20.151.10.161:28230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/x.php"] [unique_id "al9R4AlWhjQfpOo60_HPiAAAAAI"]
[Tue Jul 21 08:02:56.571863 2026] [security2:error] [pid 358661:tid 358710] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9R4AlWhjQfpOo60_HPiQAAdC0"]
[Tue Jul 21 08:02:56.572066 2026] [security2:error] [pid 358661:tid 358910] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9R4AlWhjQfpOo60_HPiQAAdC0"]
[Tue Jul 21 08:02:57.246174 2026] [security2:error] [pid 358661:tid 358852] [client 65.21.113.253:56266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R4QlWhjQfpOo60_HPjwAAADo"]
[Tue Jul 21 08:02:57.341152 2026] [security2:error] [pid 352421:tid 352665] [client 20.29.126.15:8525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/new.php"] [unique_id "al9R4cJSWzG9jbYOtu5B1gAAAPc"]
[Tue Jul 21 08:02:57.342612 2026] [security2:error] [pid 352421:tid 352622] [client 223.236.153.128:7198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9R4cJSWzG9jbYOtu5B1wAAAMw"]
[Tue Jul 21 08:02:57.342705 2026] [security2:error] [pid 352421:tid 352622] [client 223.236.153.128:7198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9R4cJSWzG9jbYOtu5B1wAAAMw"]
[Tue Jul 21 08:02:57.349299 2026] [security2:error] [pid 358661:tid 358762] [remote 167.71.211.64:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "extrapro21.com"] [uri "/"] [unique_id "al9R4QlWhjQfpOo60_HPlAAARWE"], referer: http://extrapro21.com/
[Tue Jul 21 08:02:57.524726 2026] [security2:error] [pid 358661:tid 358817] [client 20.197.192.193:56829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/fffm.php"] [unique_id "al9R4QlWhjQfpOo60_HPmQAAABc"]
[Tue Jul 21 08:02:57.617490 2026] [security2:error] [pid 358661:tid 358887] [client 20.151.10.161:28509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/j260624_13.php"] [unique_id "al9R4QlWhjQfpOo60_HPmwAAAF0"]
[Tue Jul 21 08:02:57.652109 2026] [security2:error] [pid 358661:tid 358918] [client 20.197.195.24:2868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/config.php"] [unique_id "al9R4QlWhjQfpOo60_HPnQAAAHw"]
[Tue Jul 21 08:02:58.061670 2026] [security2:error] [pid 358661:tid 358757] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9R4glWhjQfpOo60_HPoQAASVw"]
[Tue Jul 21 08:02:58.061833 2026] [security2:error] [pid 358661:tid 358867] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9R4glWhjQfpOo60_HPoQAASVw"]
[Tue Jul 21 08:02:58.238927 2026] [security2:error] [pid 358661:tid 358699] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R4glWhjQfpOo60_HPqQAAPSI"]
[Tue Jul 21 08:02:58.239101 2026] [security2:error] [pid 358661:tid 358855] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R4glWhjQfpOo60_HPqQAAPSI"]
[Tue Jul 21 08:02:58.255075 2026] [security2:error] [pid 352421:tid 352606] [client 120.56.162.40:62322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R4sJSWzG9jbYOtu5B4QAAALw"]
[Tue Jul 21 08:02:58.261760 2026] [security2:error] [pid 352421:tid 352489] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R4sJSWzG9jbYOtu5B4gAA5EM"]
[Tue Jul 21 08:02:58.261892 2026] [security2:error] [pid 352421:tid 352646] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R4sJSWzG9jbYOtu5B4gAA5EM"]
[Tue Jul 21 08:02:58.326195 2026] [security2:error] [pid 352421:tid 352581] [client 20.29.126.15:16088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/class-t.api.php"] [unique_id "al9R4sJSWzG9jbYOtu5B4wAAAKM"]
[Tue Jul 21 08:02:58.344804 2026] [security2:error] [pid 358661:tid 358779] [remote 167.71.211.64:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "extrapro21.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al9R4glWhjQfpOo60_HPqwAAb3I"], referer: http://extrapro21.com/wp-includes/css/buttons.css
[Tue Jul 21 08:02:58.354086 2026] [security2:error] [pid 352421:tid 352540] [remote 207.180.241.245:57242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9R4sJSWzG9jbYOtu5B5AAAiHY"]
[Tue Jul 21 08:02:58.357992 2026] [security2:error] [pid 358661:tid 358712] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9R4glWhjQfpOo60_HPrAAAUi8"]
[Tue Jul 21 08:02:58.358129 2026] [security2:error] [pid 358661:tid 358876] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9R4glWhjQfpOo60_HPrAAAUi8"]
[Tue Jul 21 08:02:58.412935 2026] [security2:error] [pid 358661:tid 358871] [client 20.220.225.223:34283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wp-wpbak.php"] [unique_id "al9R4glWhjQfpOo60_HPrQAAAE0"]
[Tue Jul 21 08:02:58.643742 2026] [security2:error] [pid 358661:tid 358726] [remote 97.74.93.24:46580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "link.aede.com.br"] [uri "/wp-login.php"] [unique_id "al9R4glWhjQfpOo60_HPrwAAND0"]
[Tue Jul 21 08:02:58.664749 2026] [security2:error] [pid 358661:tid 358716] [remote 68.178.165.65:55444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9R4glWhjQfpOo60_HPsAAAeTM"]
[Tue Jul 21 08:02:58.667549 2026] [security2:error] [pid 352421:tid 352643] [client 20.151.10.161:28492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/d62.php"] [unique_id "al9R4sJSWzG9jbYOtu5B7gAAAOE"]
[Tue Jul 21 08:02:58.942865 2026] [security2:error] [pid 358661:tid 358916] [client 65.21.113.253:50930] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9R4glWhjQfpOo60_HPtAAAAHo"]
[Tue Jul 21 08:02:59.174152 2026] [security2:error] [pid 358661:tid 358851] [client 193.36.225.67:30725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9R4wlWhjQfpOo60_HPtQAAADk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:02:59.199482 2026] [security2:error] [pid 352421:tid 352538] [remote 152.53.111.131:41624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "growe-ag.jaypi.com.br"] [uri "/wp-login.php"] [unique_id "al9R48JSWzG9jbYOtu5B-wAArXQ"]
[Tue Jul 21 08:02:59.212336 2026] [access_compat:error] [pid 352421:tid 352607] [client 162.241.63.68:10690] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:02:59.217719 2026] [security2:error] [pid 358661:tid 358848] [client 114.119.151.89:29947] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.prismaseg.com"] [uri "/vida.php"] [unique_id "al9R4wlWhjQfpOo60_HPvQAAADY"], referer: http://www.prismaseg.com/vida.php
[Tue Jul 21 08:02:59.332088 2026] [security2:error] [pid 358661:tid 358718] [remote 167.71.211.64:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "extrapro21.com"] [uri "/media/system/js/core.js"] [unique_id "al9R4wlWhjQfpOo60_HPvgAAOzU"], referer: http://extrapro21.com/media/system/js/core.js
[Tue Jul 21 08:02:59.393736 2026] [security2:error] [pid 358661:tid 358883] [client 20.151.10.161:28518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ups.php"] [unique_id "al9R4wlWhjQfpOo60_HPwAAAAFk"]
[Tue Jul 21 08:02:59.474753 2026] [security2:error] [pid 358661:tid 358902] [client 20.197.192.193:56824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/ftde.php"] [unique_id "al9R4wlWhjQfpOo60_HPwQAAAGw"]
[Tue Jul 21 08:02:59.555255 2026] [security2:error] [pid 358661:tid 358825] [client 65.21.113.253:56266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R4wlWhjQfpOo60_HPugAAAB8"]
[Tue Jul 21 08:02:59.824341 2026] [security2:error] [pid 358661:tid 358813] [client 74.7.228.34:60560] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.ocaminhodarecuperacao.com"] [uri "/index.php"] [unique_id "al9R4glWhjQfpOo60_HPqgAAE2o"]
[Tue Jul 21 08:02:59.994230 2026] [security2:error] [pid 358661:tid 358852] [client 20.220.225.223:34297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/dr.php"] [unique_id "al9R4wlWhjQfpOo60_HPyAAAADo"]
[Tue Jul 21 08:03:00.035181 2026] [security2:error] [pid 358661:tid 358854] [client 20.151.10.161:28500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/k.php"] [unique_id "al9R5AlWhjQfpOo60_HPyQAAADw"]
[Tue Jul 21 08:03:00.324484 2026] [security2:error] [pid 358661:tid 358899] [client 204.8.98.45:48170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9R5AlWhjQfpOo60_HPzAAAAGk"]
[Tue Jul 21 08:03:00.324602 2026] [security2:error] [pid 358661:tid 358899] [client 204.8.98.45:48170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9R5AlWhjQfpOo60_HPzAAAAGk"]
[Tue Jul 21 08:03:00.378974 2026] [security2:error] [pid 352421:tid 352586] [client 74.7.228.34:60570] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ocaminhodarecuperacao.com"] [uri "/index.php"] [unique_id "al9R5MJSWzG9jbYOtu5CBQAAqHE"], referer: https://www.ocaminhodarecuperacao.com/robots.txt
[Tue Jul 21 08:03:00.473517 2026] [security2:error] [pid 358661:tid 358740] [remote 173.252.87.36:43372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9R5AlWhjQfpOo60_HPywAAKks"]
[Tue Jul 21 08:03:00.476954 2026] [security2:error] [pid 358661:tid 358865] [client 65.21.113.253:53982] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R5AlWhjQfpOo60_HPygAAAEc"]
[Tue Jul 21 08:03:00.623549 2026] [security2:error] [pid 358661:tid 358820] [client 20.151.10.161:28585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/k2.php"] [unique_id "al9R5AlWhjQfpOo60_HP0QAAABo"]
[Tue Jul 21 08:03:00.751440 2026] [security2:error] [pid 358661:tid 358889] [client 106.215.181.8:15299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R5AlWhjQfpOo60_HP0gAAAF8"]
[Tue Jul 21 08:03:00.751554 2026] [security2:error] [pid 358661:tid 358889] [client 106.215.181.8:15299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R5AlWhjQfpOo60_HP0gAAAF8"]
[Tue Jul 21 08:03:00.951067 2026] [security2:error] [pid 358661:tid 358833] [client 184.75.221.3:36332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9R5AlWhjQfpOo60_HP1gAAACc"]
[Tue Jul 21 08:03:00.951176 2026] [security2:error] [pid 358661:tid 358833] [client 184.75.221.3:36332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9R5AlWhjQfpOo60_HP1gAAACc"]
[Tue Jul 21 08:03:00.995158 2026] [security2:error] [pid 358661:tid 358919] [client 65.21.113.253:50930] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9R5AlWhjQfpOo60_HP1wAAAH0"]
[Tue Jul 21 08:03:01.032750 2026] [security2:error] [pid 358661:tid 358672] [remote 81.173.115.7:50340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rosisestefanoadvocacia.guiiaz.com.br"] [uri "/wp-login.php"] [unique_id "al9R5QlWhjQfpOo60_HP2AAAewc"]
[Tue Jul 21 08:03:01.098410 2026] [security2:error] [pid 352421:tid 352672] [client 102.206.115.33:61010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9R5cJSWzG9jbYOtu5CEgAAAP4"]
[Tue Jul 21 08:03:01.098518 2026] [security2:error] [pid 352421:tid 352672] [client 102.206.115.33:61010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9R5cJSWzG9jbYOtu5CEgAAAP4"]
[Tue Jul 21 08:03:01.274015 2026] [security2:error] [pid 352421:tid 352668] [client 180.153.236.118:41323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "statusedigital.online"] [uri "/"] [unique_id "al9R5cJSWzG9jbYOtu5CGAAAAPo"], referer: http://statusedigital.online/
[Tue Jul 21 08:03:01.274141 2026] [security2:error] [pid 352421:tid 352668] [client 180.153.236.118:41323] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "statusedigital.online"] [uri "/"] [unique_id "al9R5cJSWzG9jbYOtu5CGAAAAPo"], referer: http://statusedigital.online/
[Tue Jul 21 08:03:01.288344 2026] [security2:error] [pid 358661:tid 358866] [client 87.116.180.198:27179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R5QlWhjQfpOo60_HP2gAAAEg"]
[Tue Jul 21 08:03:01.292803 2026] [security2:error] [pid 358661:tid 358866] [client 87.116.180.198:27179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R5QlWhjQfpOo60_HP2gAAAEg"]
[Tue Jul 21 08:03:01.461041 2026] [security2:error] [pid 352421:tid 352560] [client 103.78.200.11:54532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R5cJSWzG9jbYOtu5CGwAAAI4"]
[Tue Jul 21 08:03:01.461176 2026] [security2:error] [pid 352421:tid 352560] [client 103.78.200.11:54532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R5cJSWzG9jbYOtu5CGwAAAI4"]
[Tue Jul 21 08:03:01.519952 2026] [security2:error] [pid 358661:tid 358885] [client 117.247.80.59:23461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R5QlWhjQfpOo60_HP3wAAAFs"]
[Tue Jul 21 08:03:01.520087 2026] [security2:error] [pid 358661:tid 358885] [client 117.247.80.59:23461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R5QlWhjQfpOo60_HP3wAAAFs"]
[Tue Jul 21 08:03:01.617222 2026] [security2:error] [pid 358661:tid 358807] [client 65.21.113.253:53982] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R5QlWhjQfpOo60_HP2QAAAA0"]
[Tue Jul 21 08:03:01.643178 2026] [security2:error] [pid 358661:tid 358880] [client 184.75.221.3:37938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9R5QlWhjQfpOo60_HP4QAAAFY"]
[Tue Jul 21 08:03:01.643311 2026] [security2:error] [pid 358661:tid 358880] [client 184.75.221.3:37938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9R5QlWhjQfpOo60_HP4QAAAFY"]
[Tue Jul 21 08:03:01.648058 2026] [security2:error] [pid 358661:tid 358900] [client 20.197.195.24:2862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/gettest.php"] [unique_id "al9R5QlWhjQfpOo60_HP4gAAAGo"]
[Tue Jul 21 08:03:01.941985 2026] [security2:error] [pid 358661:tid 358822] [client 20.151.10.161:28519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/k3.php"] [unique_id "al9R5QlWhjQfpOo60_HP6QAAABw"]
[Tue Jul 21 08:03:02.078831 2026] [security2:error] [pid 352421:tid 352587] [client 103.29.114.44:49630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R5sJSWzG9jbYOtu5CIQAAAKk"]
[Tue Jul 21 08:03:02.078958 2026] [security2:error] [pid 352421:tid 352587] [client 103.29.114.44:49630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R5sJSWzG9jbYOtu5CIQAAAKk"]
[Tue Jul 21 08:03:02.225232 2026] [security2:error] [pid 352421:tid 352592] [client 20.220.225.223:34272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/2x.php"] [unique_id "al9R5sJSWzG9jbYOtu5CIgAAAK4"]
[Tue Jul 21 08:03:02.448866 2026] [security2:error] [pid 358661:tid 358852] [client 20.151.10.161:28564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/k4.php"] [unique_id "al9R5glWhjQfpOo60_HP8AAAADo"]
[Tue Jul 21 08:03:02.483854 2026] [security2:error] [pid 352421:tid 352610] [client 20.106.206.77:57542] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.71"] [uri "/index.cgi"] [unique_id "al9R5sJSWzG9jbYOtu5CKwAAAMA"]
[Tue Jul 21 08:03:02.648451 2026] [security2:error] [pid 358661:tid 358805] [client 182.8.255.181:17190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9R5glWhjQfpOo60_HP9QAAAAs"]
[Tue Jul 21 08:03:02.648565 2026] [security2:error] [pid 358661:tid 358805] [client 182.8.255.181:17190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9R5glWhjQfpOo60_HP9QAAAAs"]
[Tue Jul 21 08:03:02.875096 2026] [security2:error] [pid 352421:tid 352634] [client 65.111.23.6:23773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9R5sJSWzG9jbYOtu5CMAAAANg"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:03:03.109128 2026] [security2:error] [pid 358661:tid 358803] [client 65.21.113.253:50930] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9R5wlWhjQfpOo60_HP-gAAAAk"]
[Tue Jul 21 08:03:03.130435 2026] [security2:error] [pid 358661:tid 358794] [client 193.36.225.71:57737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9R5wlWhjQfpOo60_HP-wAAAAA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:03:03.449692 2026] [security2:error] [pid 358661:tid 358896] [client 20.151.10.161:28503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/k5.php"] [unique_id "al9R5wlWhjQfpOo60_HQAAAAAGY"]
[Tue Jul 21 08:03:03.638608 2026] [security2:error] [pid 352421:tid 352591] [client 204.8.98.45:54184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9R58JSWzG9jbYOtu5COAAAAK0"]
[Tue Jul 21 08:03:03.638727 2026] [security2:error] [pid 352421:tid 352591] [client 204.8.98.45:54184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9R58JSWzG9jbYOtu5COAAAAK0"]
[Tue Jul 21 08:03:03.671998 2026] [security2:error] [pid 358661:tid 358879] [client 109.60.28.94:62355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R5wlWhjQfpOo60_HQAwAAAFU"]
[Tue Jul 21 08:03:03.672130 2026] [security2:error] [pid 358661:tid 358879] [client 109.60.28.94:62355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R5wlWhjQfpOo60_HQAwAAAFU"]
[Tue Jul 21 08:03:03.865117 2026] [security2:error] [pid 352421:tid 352636] [client 20.151.10.161:28590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/w.php"] [unique_id "al9R58JSWzG9jbYOtu5CPQAAANo"]
[Tue Jul 21 08:03:04.133100 2026] [security2:error] [pid 352421:tid 352590] [client 65.21.113.253:54014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R58JSWzG9jbYOtu5CQQAAAKw"]
[Tue Jul 21 08:03:04.170772 2026] [security2:error] [pid 358661:tid 358806] [client 20.220.225.223:34303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/kq1.php"] [unique_id "al9R6AlWhjQfpOo60_HQBwAAAAw"]
[Tue Jul 21 08:03:04.172444 2026] [security2:error] [pid 352421:tid 352662] [client 65.21.113.253:53998] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R58JSWzG9jbYOtu5COQAAAPQ"]
[Tue Jul 21 08:03:04.609250 2026] [security2:error] [pid 358661:tid 358837] [client 103.166.103.129:15669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9R6AlWhjQfpOo60_HQEQAAACs"]
[Tue Jul 21 08:03:04.609347 2026] [security2:error] [pid 358661:tid 358837] [client 103.166.103.129:15669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9R6AlWhjQfpOo60_HQEQAAACs"]
[Tue Jul 21 08:03:04.796992 2026] [security2:error] [pid 352421:tid 352588] [client 122.179.91.63:31365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9R6MJSWzG9jbYOtu5CTgAAAKo"]
[Tue Jul 21 08:03:04.797126 2026] [security2:error] [pid 352421:tid 352588] [client 122.179.91.63:31365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9R6MJSWzG9jbYOtu5CTgAAAKo"]
[Tue Jul 21 08:03:04.814094 2026] [security2:error] [pid 358661:tid 358853] [client 20.151.10.161:28091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/fpwch.php"] [unique_id "al9R6AlWhjQfpOo60_HQEgAAADs"]
[Tue Jul 21 08:03:04.904408 2026] [security2:error] [pid 352421:tid 352657] [client 20.197.195.24:2928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/min.php"] [unique_id "al9R6MJSWzG9jbYOtu5CUQAAAO8"]
[Tue Jul 21 08:03:04.920963 2026] [security2:error] [pid 352421:tid 352579] [client 65.111.4.182:22049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.4.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9R58JSWzG9jbYOtu5CPwAAAKE"], referer: https://albuquerqueeharo.com/wp-login.php
[Tue Jul 21 08:03:05.022142 2026] [security2:error] [pid 358661:tid 358900] [client 178.153.91.96:50118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9R6QlWhjQfpOo60_HQFwAAAGo"]
[Tue Jul 21 08:03:05.022267 2026] [security2:error] [pid 358661:tid 358900] [client 178.153.91.96:50118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9R6QlWhjQfpOo60_HQFwAAAGo"]
[Tue Jul 21 08:03:05.139307 2026] [security2:error] [pid 358661:tid 358838] [client 202.143.127.214:54137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R6QlWhjQfpOo60_HQGQAAACw"]
[Tue Jul 21 08:03:05.139409 2026] [security2:error] [pid 358661:tid 358838] [client 202.143.127.214:54137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R6QlWhjQfpOo60_HQGQAAACw"]
[Tue Jul 21 08:03:05.194072 2026] [security2:error] [pid 358661:tid 358852] [client 204.8.98.45:54188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9R6QlWhjQfpOo60_HQGgAAADo"]
[Tue Jul 21 08:03:05.194179 2026] [security2:error] [pid 358661:tid 358852] [client 204.8.98.45:54188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9R6QlWhjQfpOo60_HQGgAAADo"]
[Tue Jul 21 08:03:05.414935 2026] [security2:error] [pid 352421:tid 352548] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9R6cJSWzG9jbYOtu5CWwAAxH4"]
[Tue Jul 21 08:03:05.415085 2026] [security2:error] [pid 352421:tid 352614] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9R6cJSWzG9jbYOtu5CWwAAxH4"]
[Tue Jul 21 08:03:05.441094 2026] [security2:error] [pid 352421:tid 352580] [client 20.151.10.161:28592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/w2025.php"] [unique_id "al9R6cJSWzG9jbYOtu5CXAAAAKI"]
[Tue Jul 21 08:03:05.646351 2026] [security2:error] [pid 358661:tid 358908] [client 117.210.135.0:58237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R6QlWhjQfpOo60_HQHgAAAHI"]
[Tue Jul 21 08:03:05.646499 2026] [security2:error] [pid 358661:tid 358908] [client 117.210.135.0:58237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R6QlWhjQfpOo60_HQHgAAAHI"]
[Tue Jul 21 08:03:05.832328 2026] [security2:error] [pid 352421:tid 352575] [client 20.104.96.117:46694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/min.php"] [unique_id "al9R6cJSWzG9jbYOtu5CagAAAJ0"]
[Tue Jul 21 08:03:05.897699 2026] [security2:error] [pid 352421:tid 352528] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R6cJSWzG9jbYOtu5CbQAA2Go"]
[Tue Jul 21 08:03:05.897834 2026] [security2:error] [pid 352421:tid 352634] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R6cJSWzG9jbYOtu5CbQAA2Go"]
[Tue Jul 21 08:03:06.276510 2026] [security2:error] [pid 358661:tid 358829] [client 20.151.10.161:28607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/scxy.php"] [unique_id "al9R6glWhjQfpOo60_HQLAAAACM"]
[Tue Jul 21 08:03:06.380256 2026] [security2:error] [pid 352421:tid 352636] [client 20.197.192.193:50587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/yup.php"] [unique_id "al9R6sJSWzG9jbYOtu5CeQAAANo"]
[Tue Jul 21 08:03:06.502185 2026] [security2:error] [pid 352421:tid 352626] [client 65.21.113.253:54014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R6sJSWzG9jbYOtu5CdwAAANA"]
[Tue Jul 21 08:03:06.624336 2026] [security2:error] [pid 352421:tid 352612] [client 175.144.82.48:61867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R6sJSWzG9jbYOtu5CfgAAAMI"]
[Tue Jul 21 08:03:06.625171 2026] [security2:error] [pid 352421:tid 352612] [client 175.144.82.48:61867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R6sJSWzG9jbYOtu5CfgAAAMI"]
[Tue Jul 21 08:03:06.641891 2026] [security2:error] [pid 358661:tid 358819] [client 38.100.221.102:18318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R6glWhjQfpOo60_HQMwAAABk"]
[Tue Jul 21 08:03:06.642042 2026] [security2:error] [pid 358661:tid 358819] [client 38.100.221.102:18318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R6glWhjQfpOo60_HQMwAAABk"]
[Tue Jul 21 08:03:06.756019 2026] [security2:error] [pid 352421:tid 352585] [client 41.68.90.219:62035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R6sJSWzG9jbYOtu5CgQAAAKc"]
[Tue Jul 21 08:03:06.756391 2026] [core:alert] [pid 352421:tid 352567] [client 57.141.18.80:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:03:06.756961 2026] [security2:error] [pid 352421:tid 352585] [client 41.68.90.219:62035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R6sJSWzG9jbYOtu5CgQAAAKc"]
[Tue Jul 21 08:03:06.778043 2026] [security2:error] [pid 358661:tid 358668] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R6glWhjQfpOo60_HQNwAAUgM"]
[Tue Jul 21 08:03:06.778162 2026] [security2:error] [pid 358661:tid 358876] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R6glWhjQfpOo60_HQNwAAUgM"]
[Tue Jul 21 08:03:07.214454 2026] [security2:error] [pid 358661:tid 358799] [client 184.75.221.3:36346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9R6wlWhjQfpOo60_HQQwAAAAU"]
[Tue Jul 21 08:03:07.214555 2026] [security2:error] [pid 358661:tid 358799] [client 184.75.221.3:36346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9R6wlWhjQfpOo60_HQQwAAAAU"]
[Tue Jul 21 08:03:07.441429 2026] [security2:error] [pid 358661:tid 358803] [client 102.221.29.109:60819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.29.221.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inovasoulfigital.com"] [uri "/xmlrpc.php"] [unique_id "al9R6glWhjQfpOo60_HQKwAAAAk"]
[Tue Jul 21 08:03:07.441582 2026] [security2:error] [pid 358661:tid 358803] [client 102.221.29.109:60819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "inovasoulfigital.com"] [uri "/xmlrpc.php"] [unique_id "al9R6glWhjQfpOo60_HQKwAAAAk"]
[Tue Jul 21 08:03:07.480106 2026] [security2:error] [pid 352421:tid 352448] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9R68JSWzG9jbYOtu5CsQAA8Ro"]
[Tue Jul 21 08:03:07.480257 2026] [security2:error] [pid 352421:tid 352659] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9R68JSWzG9jbYOtu5CsQAA8Ro"]
[Tue Jul 21 08:03:07.874334 2026] [security2:error] [pid 352421:tid 352674] [client 20.151.10.161:28524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/FWAZ.php"] [unique_id "al9R68JSWzG9jbYOtu5CtwAAAQA"]
[Tue Jul 21 08:03:07.894799 2026] [security2:error] [pid 358661:tid 358844] [client 223.236.153.128:5670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9R6wlWhjQfpOo60_HQSwAAADI"]
[Tue Jul 21 08:03:07.894927 2026] [security2:error] [pid 358661:tid 358844] [client 223.236.153.128:5670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9R6wlWhjQfpOo60_HQSwAAADI"]
[Tue Jul 21 08:03:08.069729 2026] [security2:error] [pid 358661:tid 358914] [client 136.144.33.99:39019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9R7AlWhjQfpOo60_HQTgAAAHg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:03:08.136362 2026] [security2:error] [pid 352421:tid 352580] [client 20.220.225.223:34276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/zzz.php"] [unique_id "al9R7MJSWzG9jbYOtu5CvAAAAKI"]
[Tue Jul 21 08:03:08.249006 2026] [security2:error] [pid 352421:tid 352606] [client 20.29.126.15:20188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/plugins.php"] [unique_id "al9R7MJSWzG9jbYOtu5CwQAAALw"]
[Tue Jul 21 08:03:08.470345 2026] [security2:error] [pid 352421:tid 352583] [client 20.151.10.161:39801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.jandel.com.br"] [uri "/aaa.php"] [unique_id "al9R7MJSWzG9jbYOtu5CwwAAAKU"]
[Tue Jul 21 08:03:08.623219 2026] [security2:error] [pid 358661:tid 358681] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9R7AlWhjQfpOo60_HQTwAAQRA"]
[Tue Jul 21 08:03:08.623365 2026] [security2:error] [pid 358661:tid 358859] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9R7AlWhjQfpOo60_HQTwAAQRA"]
[Tue Jul 21 08:03:08.861871 2026] [security2:error] [pid 352421:tid 352667] [client 120.56.162.40:62756] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R7MJSWzG9jbYOtu5C0AAAAPk"]
[Tue Jul 21 08:03:08.861998 2026] [security2:error] [pid 352421:tid 352667] [client 120.56.162.40:62756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R7MJSWzG9jbYOtu5C0AAAAPk"]
[Tue Jul 21 08:03:09.027664 2026] [security2:error] [pid 358661:tid 358708] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R7QlWhjQfpOo60_HQVgAAHSs"]
[Tue Jul 21 08:03:09.027867 2026] [security2:error] [pid 358661:tid 358823] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R7QlWhjQfpOo60_HQVgAAHSs"]
[Tue Jul 21 08:03:09.089546 2026] [security2:error] [pid 352421:tid 352518] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9R7cJSWzG9jbYOtu5C0wAA4WA"]
[Tue Jul 21 08:03:09.089712 2026] [security2:error] [pid 352421:tid 352643] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9R7cJSWzG9jbYOtu5C0wAA4WA"]
[Tue Jul 21 08:03:09.172919 2026] [security2:error] [pid 352421:tid 352593] [client 20.151.10.161:28525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/qterm.php"] [unique_id "al9R7cJSWzG9jbYOtu5C1QAAAK8"]
[Tue Jul 21 08:03:09.239163 2026] [security2:error] [pid 358661:tid 358674] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R7QlWhjQfpOo60_HQWgAARAk"]
[Tue Jul 21 08:03:09.239314 2026] [security2:error] [pid 358661:tid 358862] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R7QlWhjQfpOo60_HQWgAARAk"]
[Tue Jul 21 08:03:09.245993 2026] [security2:error] [pid 358661:tid 358896] [client 151.63.71.144:57107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9R7QlWhjQfpOo60_HQVwAAAGY"]
[Tue Jul 21 08:03:09.246134 2026] [security2:error] [pid 358661:tid 358896] [client 151.63.71.144:57107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9R7QlWhjQfpOo60_HQVwAAAGY"]
[Tue Jul 21 08:03:09.356554 2026] [security2:error] [pid 352421:tid 352605] [client 65.21.113.253:54014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R7cJSWzG9jbYOtu5C1AAAALs"]
[Tue Jul 21 08:03:09.383728 2026] [security2:error] [pid 358661:tid 358854] [client 20.197.192.193:53142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/csa.php"] [unique_id "al9R7QlWhjQfpOo60_HQWwAAADw"]
[Tue Jul 21 08:03:09.481730 2026] [security2:error] [pid 358661:tid 358750] [remote 207.180.241.245:58372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/wp-login.php"] [unique_id "al9R7QlWhjQfpOo60_HQXQAAUVU"]
[Tue Jul 21 08:03:09.492189 2026] [security2:error] [pid 358661:tid 358819] [client 20.104.96.117:46689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9R7QlWhjQfpOo60_HQXgAAABk"]
[Tue Jul 21 08:03:09.831655 2026] [security2:error] [pid 358661:tid 358853] [client 20.151.10.161:28232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/blurbs.php"] [unique_id "al9R7QlWhjQfpOo60_HQZAAAADs"]
[Tue Jul 21 08:03:10.409658 2026] [security2:error] [pid 358661:tid 358900] [client 20.151.10.161:28244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/v543.php"] [unique_id "al9R7glWhjQfpOo60_HQbQAAAGo"]
[Tue Jul 21 08:03:11.291748 2026] [security2:error] [pid 352421:tid 352663] [client 106.215.181.8:23119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R78JSWzG9jbYOtu5C-gAAAPU"]
[Tue Jul 21 08:03:11.291905 2026] [security2:error] [pid 352421:tid 352663] [client 106.215.181.8:23119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R78JSWzG9jbYOtu5C-gAAAPU"]
[Tue Jul 21 08:03:11.294139 2026] [security2:error] [pid 358661:tid 358815] [client 20.197.195.24:2816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/dvjul.php"] [unique_id "al9R7wlWhjQfpOo60_HQdAAAABU"]
[Tue Jul 21 08:03:11.386400 2026] [security2:error] [pid 352421:tid 352519] [remote 20.153.140.50:42220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9R78JSWzG9jbYOtu5C_AAA72E"]
[Tue Jul 21 08:03:11.388865 2026] [security2:error] [pid 352421:tid 352569] [client 65.21.113.253:52310] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9R78JSWzG9jbYOtu5C_gAAAJc"]
[Tue Jul 21 08:03:11.668824 2026] [security2:error] [pid 352421:tid 352672] [client 102.206.115.33:57496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9R78JSWzG9jbYOtu5DHwAAAP4"]
[Tue Jul 21 08:03:11.668972 2026] [security2:error] [pid 352421:tid 352672] [client 102.206.115.33:57496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9R78JSWzG9jbYOtu5DHwAAAP4"]
[Tue Jul 21 08:03:11.696339 2026] [security2:error] [pid 352421:tid 352678] [client 20.151.10.161:28546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/w3lls.php"] [unique_id "al9R78JSWzG9jbYOtu5DIAAAAQQ"]
[Tue Jul 21 08:03:11.718945 2026] [security2:error] [pid 358661:tid 358879] [client 20.104.96.117:46687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9R7wlWhjQfpOo60_HQeQAAAFU"]
[Tue Jul 21 08:03:11.770564 2026] [security2:error] [pid 358661:tid 358830] [client 20.197.192.193:50605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/jj.php"] [unique_id "al9R7wlWhjQfpOo60_HQegAAACQ"]
[Tue Jul 21 08:03:11.945363 2026] [security2:error] [pid 358661:tid 358859] [client 87.116.180.198:27230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R7wlWhjQfpOo60_HQfQAAAEE"]
[Tue Jul 21 08:03:11.945484 2026] [security2:error] [pid 358661:tid 358859] [client 87.116.180.198:27230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R7wlWhjQfpOo60_HQfQAAAEE"]
[Tue Jul 21 08:03:12.026270 2026] [security2:error] [pid 352421:tid 352602] [client 65.21.113.253:54014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R78JSWzG9jbYOtu5DGgAAALg"]
[Tue Jul 21 08:03:12.059314 2026] [security2:error] [pid 352421:tid 352613] [client 193.36.225.11:52203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9R8MJSWzG9jbYOtu5DJgAAAMM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:03:12.100829 2026] [security2:error] [pid 352421:tid 352554] [client 20.151.10.161:28510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-ws68.php"] [unique_id "al9R8MJSWzG9jbYOtu5DKAAAAIg"]
[Tue Jul 21 08:03:12.236875 2026] [security2:error] [pid 352421:tid 352619] [client 103.78.200.11:55015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R8MJSWzG9jbYOtu5DLAAAAMk"]
[Tue Jul 21 08:03:12.237012 2026] [security2:error] [pid 352421:tid 352619] [client 103.78.200.11:55015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R8MJSWzG9jbYOtu5DLAAAAMk"]
[Tue Jul 21 08:03:12.279315 2026] [security2:error] [pid 352421:tid 352639] [client 20.197.195.24:2889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/biufile.php"] [unique_id "al9R8MJSWzG9jbYOtu5DLgAAAN0"]
[Tue Jul 21 08:03:12.392339 2026] [security2:error] [pid 358661:tid 358829] [client 117.247.80.59:23811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R8AlWhjQfpOo60_HQgwAAACM"]
[Tue Jul 21 08:03:12.392499 2026] [security2:error] [pid 358661:tid 358829] [client 117.247.80.59:23811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R8AlWhjQfpOo60_HQgwAAACM"]
[Tue Jul 21 08:03:12.624774 2026] [security2:error] [pid 358661:tid 358888] [client 20.151.10.161:28554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/xyn.php"] [unique_id "al9R8AlWhjQfpOo60_HQhgAAAF4"]
[Tue Jul 21 08:03:12.667509 2026] [security2:error] [pid 358661:tid 358799] [client 20.197.195.24:58957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/av.php"] [unique_id "al9R8AlWhjQfpOo60_HQiQAAAAU"]
[Tue Jul 21 08:03:12.857159 2026] [security2:error] [pid 358661:tid 358913] [client 20.104.96.117:46671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9R8AlWhjQfpOo60_HQigAAAHc"]
[Tue Jul 21 08:03:13.022251 2026] [security2:error] [pid 358661:tid 358856] [client 20.29.126.15:11829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/jp.php"] [unique_id "al9R8QlWhjQfpOo60_HQjQAAAD4"]
[Tue Jul 21 08:03:13.050944 2026] [security2:error] [pid 358661:tid 358834] [client 20.197.195.24:2838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/coffexium.php"] [unique_id "al9R8QlWhjQfpOo60_HQjgAAACg"]
[Tue Jul 21 08:03:13.144661 2026] [security2:error] [pid 358661:tid 358876] [client 182.8.255.181:17509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9R8QlWhjQfpOo60_HQjwAAAFI"]
[Tue Jul 21 08:03:13.144795 2026] [security2:error] [pid 358661:tid 358876] [client 182.8.255.181:17509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9R8QlWhjQfpOo60_HQjwAAAFI"]
[Tue Jul 21 08:03:13.193111 2026] [security2:error] [pid 358661:tid 358836] [client 20.197.192.193:50583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/dragonshell.php"] [unique_id "al9R8QlWhjQfpOo60_HQkAAAACo"]
[Tue Jul 21 08:03:13.217245 2026] [security2:error] [pid 352421:tid 352627] [client 20.151.10.161:28599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/green3.php"] [unique_id "al9R8cJSWzG9jbYOtu5DPgAAANE"]
[Tue Jul 21 08:03:13.713185 2026] [security2:error] [pid 358661:tid 358912] [client 65.21.113.253:35960] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R8QlWhjQfpOo60_HQkgAAAHY"]
[Tue Jul 21 08:03:13.784089 2026] [security2:error] [pid 352421:tid 352622] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9R8cJSWzG9jbYOtu5DRwAAAMw"]
[Tue Jul 21 08:03:13.915754 2026] [security2:error] [pid 358661:tid 358839] [client 20.197.195.24:2899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/core.php"] [unique_id "al9R8QlWhjQfpOo60_HQmwAAAC0"]
[Tue Jul 21 08:03:14.061329 2026] [security2:error] [pid 352421:tid 352614] [client 20.151.10.161:28596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ccs.php"] [unique_id "al9R8sJSWzG9jbYOtu5DTQAAAMQ"]
[Tue Jul 21 08:03:14.231074 2026] [security2:error] [pid 352421:tid 352582] [client 20.197.192.193:50593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-mt.php"] [unique_id "al9R8sJSWzG9jbYOtu5DUAAAAKQ"]
[Tue Jul 21 08:03:14.341177 2026] [security2:error] [pid 352421:tid 352456] [remote 72.167.132.114:57154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9R8sJSWzG9jbYOtu5DUgAAoyI"]
[Tue Jul 21 08:03:14.526980 2026] [security2:error] [pid 352421:tid 352673] [client 109.60.28.94:62953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R8sJSWzG9jbYOtu5DVQAAAP8"]
[Tue Jul 21 08:03:14.527116 2026] [security2:error] [pid 352421:tid 352673] [client 109.60.28.94:62953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R8sJSWzG9jbYOtu5DVQAAAP8"]
[Tue Jul 21 08:03:14.600978 2026] [security2:error] [pid 358661:tid 358875] [client 20.197.195.24:2920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/als.php"] [unique_id "al9R8glWhjQfpOo60_HQogAAAFE"]
[Tue Jul 21 08:03:14.852376 2026] [security2:error] [pid 358661:tid 358885] [client 20.197.192.193:53161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/min.php"] [unique_id "al9R8glWhjQfpOo60_HQowAAAFs"]
[Tue Jul 21 08:03:14.867693 2026] [security2:error] [pid 358661:tid 358807] [client 20.151.10.161:28482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ccc.php"] [unique_id "al9R8glWhjQfpOo60_HQpAAAAA0"]
[Tue Jul 21 08:03:14.872010 2026] [security2:error] [pid 358661:tid 358915] [client 20.104.96.117:46693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9R8glWhjQfpOo60_HQpQAAAHk"]
[Tue Jul 21 08:03:14.962727 2026] [security2:error] [pid 358661:tid 358891] [client 20.197.195.24:2874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/simple.php"] [unique_id "al9R8glWhjQfpOo60_HQqQAAAGE"]
[Tue Jul 21 08:03:15.080775 2026] [security2:error] [pid 358661:tid 358879] [client 146.70.194.252:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.194.70.146.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "energyzapp.com"] [uri "/xmlrpc.php"] [unique_id "al9R8glWhjQfpOo60_HQnAAAAFU"]
[Tue Jul 21 08:03:15.328462 2026] [security2:error] [pid 352421:tid 352645] [client 65.21.113.253:52310] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9R88JSWzG9jbYOtu5DXwAAAOM"]
[Tue Jul 21 08:03:15.329190 2026] [security2:error] [pid 352421:tid 352575] [client 103.166.103.129:54194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9R88JSWzG9jbYOtu5DYAAAAJ0"]
[Tue Jul 21 08:03:15.329291 2026] [security2:error] [pid 352421:tid 352575] [client 103.166.103.129:54194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9R88JSWzG9jbYOtu5DYAAAAJ0"]
[Tue Jul 21 08:03:15.511290 2026] [security2:error] [pid 358661:tid 358919] [client 178.153.91.96:28017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9R8wlWhjQfpOo60_HQsAAAAH0"]
[Tue Jul 21 08:03:15.511434 2026] [security2:error] [pid 358661:tid 358919] [client 178.153.91.96:28017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9R8wlWhjQfpOo60_HQsAAAAH0"]
[Tue Jul 21 08:03:15.839968 2026] [security2:error] [pid 358661:tid 358856] [client 20.197.195.24:58970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/init.php"] [unique_id "al9R8wlWhjQfpOo60_HQuQAAAD4"]
[Tue Jul 21 08:03:15.885210 2026] [security2:error] [pid 358661:tid 358822] [client 122.179.91.63:2918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9R8wlWhjQfpOo60_HQuwAAABw"]
[Tue Jul 21 08:03:15.885510 2026] [security2:error] [pid 358661:tid 358822] [client 122.179.91.63:2918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9R8wlWhjQfpOo60_HQuwAAABw"]
[Tue Jul 21 08:03:15.902161 2026] [security2:error] [pid 352421:tid 352512] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9R88JSWzG9jbYOtu5DbwAAlVo"]
[Tue Jul 21 08:03:15.902310 2026] [security2:error] [pid 352421:tid 352567] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9R88JSWzG9jbYOtu5DbwAAlVo"]
[Tue Jul 21 08:03:15.938236 2026] [security2:error] [pid 358661:tid 358813] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9R8wlWhjQfpOo60_HQvQAAABM"]
[Tue Jul 21 08:03:15.957173 2026] [security2:error] [pid 358661:tid 358814] [client 65.21.113.253:35960] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R8wlWhjQfpOo60_HQsQAAABQ"]
[Tue Jul 21 08:03:16.018395 2026] [security2:error] [pid 358661:tid 358887] [client 20.151.10.161:28587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/get.php"] [unique_id "al9R9AlWhjQfpOo60_HQvgAAAF0"]
[Tue Jul 21 08:03:16.038038 2026] [security2:error] [pid 358661:tid 358908] [client 20.197.192.193:5092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9R9AlWhjQfpOo60_HQvwAAAHI"]
[Tue Jul 21 08:03:16.190028 2026] [security2:error] [pid 352421:tid 352607] [client 117.210.135.0:58917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R9MJSWzG9jbYOtu5DcgAAAL0"]
[Tue Jul 21 08:03:16.190148 2026] [security2:error] [pid 352421:tid 352607] [client 117.210.135.0:58917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R9MJSWzG9jbYOtu5DcgAAAL0"]
[Tue Jul 21 08:03:16.194965 2026] [security2:error] [pid 352421:tid 352620] [client 20.197.192.193:5024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9R9MJSWzG9jbYOtu5DcwAAAMo"]
[Tue Jul 21 08:03:16.225248 2026] [security2:error] [pid 358661:tid 358911] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9R9AlWhjQfpOo60_HQxAAAAHU"]
[Tue Jul 21 08:03:16.229861 2026] [security2:error] [pid 358661:tid 358855] [client 20.197.192.193:4994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/dp.php"] [unique_id "al9R9AlWhjQfpOo60_HQxQAAAD0"]
[Tue Jul 21 08:03:16.260714 2026] [security2:error] [pid 358661:tid 358827] [client 20.197.192.193:5110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/old.php"] [unique_id "al9R9AlWhjQfpOo60_HQxwAAACE"]
[Tue Jul 21 08:03:16.265193 2026] [security2:error] [pid 352421:tid 352617] [client 202.143.127.214:54622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R9MJSWzG9jbYOtu5DdAAAAMc"]
[Tue Jul 21 08:03:16.265568 2026] [security2:error] [pid 352421:tid 352617] [client 202.143.127.214:54622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R9MJSWzG9jbYOtu5DdAAAAMc"]
[Tue Jul 21 08:03:16.329755 2026] [security2:error] [pid 358661:tid 358816] [client 20.197.192.193:54981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/ms-new.php"] [unique_id "al9R9AlWhjQfpOo60_HQyAAAABY"]
[Tue Jul 21 08:03:16.369924 2026] [security2:error] [pid 358661:tid 358759] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R9AlWhjQfpOo60_HQyQAAeF4"]
[Tue Jul 21 08:03:16.370092 2026] [security2:error] [pid 358661:tid 358914] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R9AlWhjQfpOo60_HQyQAAeF4"]
[Tue Jul 21 08:03:16.444487 2026] [security2:error] [pid 352421:tid 352571] [client 20.197.192.193:50578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/ww.php"] [unique_id "al9R9MJSWzG9jbYOtu5DdwAAAJk"]
[Tue Jul 21 08:03:16.455974 2026] [security2:error] [pid 358661:tid 358917] [client 20.197.192.193:5046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/track.php"] [unique_id "al9R9AlWhjQfpOo60_HQygAAAHs"]
[Tue Jul 21 08:03:16.494880 2026] [security2:error] [pid 358661:tid 358830] [client 20.151.10.161:28569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/images.php"] [unique_id "al9R9AlWhjQfpOo60_HQzAAAACQ"]
[Tue Jul 21 08:03:16.513760 2026] [security2:error] [pid 358661:tid 358866] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9R9AlWhjQfpOo60_HQzgAAAEg"]
[Tue Jul 21 08:03:16.543294 2026] [security2:error] [pid 352421:tid 352553] [client 20.197.195.24:58484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/fpwch.php"] [unique_id "al9R9MJSWzG9jbYOtu5DeQAAAIc"]
[Tue Jul 21 08:03:16.562687 2026] [security2:error] [pid 358661:tid 358808] [client 20.197.192.193:5083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/2352356666.php"] [unique_id "al9R9AlWhjQfpOo60_HQzwAAAA4"]
[Tue Jul 21 08:03:16.605934 2026] [security2:error] [pid 358661:tid 358860] [client 65.21.113.253:35970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R9AlWhjQfpOo60_HQwwAAAEI"]
[Tue Jul 21 08:03:16.693498 2026] [security2:error] [pid 358661:tid 358885] [client 20.197.192.193:5096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/pn.php"] [unique_id "al9R9AlWhjQfpOo60_HQ1AAAAFs"]
[Tue Jul 21 08:03:16.811616 2026] [security2:error] [pid 358661:tid 358870] [client 20.151.10.161:28237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/alls.php"] [unique_id "al9R9AlWhjQfpOo60_HQ1wAAAEw"]
[Tue Jul 21 08:03:16.831666 2026] [security2:error] [pid 358661:tid 358846] [client 20.197.192.193:53132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/echkm.php"] [unique_id "al9R9AlWhjQfpOo60_HQ2AAAADQ"]
[Tue Jul 21 08:03:16.833777 2026] [security2:error] [pid 358661:tid 358867] [client 20.197.195.24:11123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/domvf.php"] [unique_id "al9R9AlWhjQfpOo60_HQ2QAAAEk"]
[Tue Jul 21 08:03:16.884443 2026] [security2:error] [pid 358661:tid 358884] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9R9AlWhjQfpOo60_HQ2wAAAFo"]
[Tue Jul 21 08:03:17.042609 2026] [security2:error] [pid 352421:tid 352659] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9R9cJSWzG9jbYOtu5DgAAAAPE"]
[Tue Jul 21 08:03:17.132190 2026] [security2:error] [pid 358661:tid 358916] [client 20.197.192.193:56826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/cron.php"] [unique_id "al9R9QlWhjQfpOo60_HQ3wAAAHo"]
[Tue Jul 21 08:03:17.142553 2026] [security2:error] [pid 358661:tid 358817] [client 175.144.82.48:62295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R9QlWhjQfpOo60_HQ4AAAABc"]
[Tue Jul 21 08:03:17.142681 2026] [security2:error] [pid 358661:tid 358817] [client 175.144.82.48:62295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R9QlWhjQfpOo60_HQ4AAAABc"]
[Tue Jul 21 08:03:17.154246 2026] [security2:error] [pid 358661:tid 358803] [client 20.197.192.193:5028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/wp-wpbak.php"] [unique_id "al9R9QlWhjQfpOo60_HQ4QAAAAk"]
[Tue Jul 21 08:03:17.308842 2026] [security2:error] [pid 358661:tid 358905] [client 38.100.221.102:18313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R9QlWhjQfpOo60_HQ5QAAAG8"]
[Tue Jul 21 08:03:17.308964 2026] [security2:error] [pid 358661:tid 358905] [client 38.100.221.102:18313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R9QlWhjQfpOo60_HQ5QAAAG8"]
[Tue Jul 21 08:03:17.329136 2026] [security2:error] [pid 358661:tid 358861] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9R9QlWhjQfpOo60_HQ5gAAAEM"]
[Tue Jul 21 08:03:17.342910 2026] [security2:error] [pid 358661:tid 358880] [client 41.68.90.219:62755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R9QlWhjQfpOo60_HQ5wAAAFY"]
[Tue Jul 21 08:03:17.343976 2026] [security2:error] [pid 358661:tid 358880] [client 41.68.90.219:62755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R9QlWhjQfpOo60_HQ5wAAAFY"]
[Tue Jul 21 08:03:17.467044 2026] [security2:error] [pid 358661:tid 358918] [client 20.151.10.161:28490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/yyu.php"] [unique_id "al9R9QlWhjQfpOo60_HQ8AAAAHw"]
[Tue Jul 21 08:03:17.541399 2026] [security2:error] [pid 358661:tid 358741] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R9QlWhjQfpOo60_HQ8QAAakw"]
[Tue Jul 21 08:03:17.541564 2026] [security2:error] [pid 358661:tid 358900] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R9QlWhjQfpOo60_HQ8QAAakw"]
[Tue Jul 21 08:03:17.615703 2026] [security2:error] [pid 352421:tid 352580] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9R9cJSWzG9jbYOtu5DiQAAAKI"]
[Tue Jul 21 08:03:17.771991 2026] [security2:error] [pid 358661:tid 358843] [client 20.197.195.24:24066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp.php"] [unique_id "al9R9QlWhjQfpOo60_HQ8gAAADE"]
[Tue Jul 21 08:03:17.831922 2026] [security2:error] [pid 358661:tid 358827] [client 20.197.192.193:54984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/dr.php"] [unique_id "al9R9QlWhjQfpOo60_HQ8wAAACE"]
[Tue Jul 21 08:03:17.869728 2026] [security2:error] [pid 358661:tid 358819] [client 136.144.33.54:31879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9R8wlWhjQfpOo60_HQtAAAABk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:03:17.903770 2026] [security2:error] [pid 358661:tid 358845] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9R9QlWhjQfpOo60_HQ9AAAADM"]
[Tue Jul 21 08:03:17.990106 2026] [security2:error] [pid 358661:tid 358815] [client 20.151.10.161:28243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/by.php"] [unique_id "al9R9QlWhjQfpOo60_HQ9wAAABU"]
[Tue Jul 21 08:03:18.132787 2026] [security2:error] [pid 352421:tid 352671] [client 20.197.192.193:5014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/2x.php"] [unique_id "al9R9sJSWzG9jbYOtu5DlAAAAP0"]
[Tue Jul 21 08:03:18.191008 2026] [security2:error] [pid 358661:tid 358866] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9R9glWhjQfpOo60_HQ-AAAAEg"]
[Tue Jul 21 08:03:18.429350 2026] [security2:error] [pid 352421:tid 352490] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9R9sJSWzG9jbYOtu5DmgAAuUQ"]
[Tue Jul 21 08:03:18.429527 2026] [security2:error] [pid 352421:tid 352603] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9R9sJSWzG9jbYOtu5DmgAAuUQ"]
[Tue Jul 21 08:03:18.466438 2026] [security2:error] [pid 352421:tid 352576] [client 20.197.192.193:5079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/kq1.php"] [unique_id "al9R9sJSWzG9jbYOtu5DmwAAAJ4"]
[Tue Jul 21 08:03:18.477091 2026] [security2:error] [pid 352421:tid 352556] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9R9sJSWzG9jbYOtu5DngAAAIo"]
[Tue Jul 21 08:03:18.487951 2026] [security2:error] [pid 352421:tid 352587] [client 223.236.153.128:7069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.153.236.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9R9sJSWzG9jbYOtu5DnwAAAKk"]
[Tue Jul 21 08:03:18.488059 2026] [security2:error] [pid 352421:tid 352587] [client 223.236.153.128:7069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9R9sJSWzG9jbYOtu5DnwAAAKk"]
[Tue Jul 21 08:03:18.645055 2026] [security2:error] [pid 352421:tid 352555] [client 20.197.195.24:2911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/class.php"] [unique_id "al9R9sJSWzG9jbYOtu5DowAAAIk"]
[Tue Jul 21 08:03:18.728537 2026] [security2:error] [pid 352421:tid 352574] [client 20.197.192.193:5070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/zzz.php"] [unique_id "al9R9sJSWzG9jbYOtu5DpgAAAJw"]
[Tue Jul 21 08:03:18.766502 2026] [security2:error] [pid 358661:tid 358851] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9R9glWhjQfpOo60_HRAwAAADk"]
[Tue Jul 21 08:03:18.948194 2026] [security2:error] [pid 358661:tid 358829] [client 65.21.113.253:35970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R9glWhjQfpOo60_HRAgAAACM"]
[Tue Jul 21 08:03:18.994543 2026] [security2:error] [pid 352421:tid 352612] [client 20.104.96.117:46596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/albin.php"] [unique_id "al9R9sJSWzG9jbYOtu5DrAAAAMI"]
[Tue Jul 21 08:03:19.064871 2026] [security2:error] [pid 358661:tid 358803] [client 20.197.195.24:58949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/echkm.php"] [unique_id "al9R9wlWhjQfpOo60_HRDAAAAAk"]
[Tue Jul 21 08:03:19.070357 2026] [security2:error] [pid 358661:tid 358842] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9R9wlWhjQfpOo60_HRDQAAADA"]
[Tue Jul 21 08:03:19.157972 2026] [security2:error] [pid 358661:tid 358902] [client 20.197.192.193:5049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/wicked.php"] [unique_id "al9R9wlWhjQfpOo60_HRDwAAAGw"]
[Tue Jul 21 08:03:19.212565 2026] [security2:error] [pid 358661:tid 358805] [client 20.197.192.193:4993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/edit.php"] [unique_id "al9R9wlWhjQfpOo60_HREAAAAAs"]
[Tue Jul 21 08:03:19.280668 2026] [security2:error] [pid 352421:tid 352518] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9R98JSWzG9jbYOtu5DrQAA3WA"]
[Tue Jul 21 08:03:19.280819 2026] [security2:error] [pid 352421:tid 352639] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9R98JSWzG9jbYOtu5DrQAA3WA"]
[Tue Jul 21 08:03:19.281737 2026] [security2:error] [pid 358661:tid 358905] [client 20.197.192.193:5036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/kua.php"] [unique_id "al9R9wlWhjQfpOo60_HREgAAAG8"]
[Tue Jul 21 08:03:19.355013 2026] [security2:error] [pid 352421:tid 352620] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9R98JSWzG9jbYOtu5DsAAAAMo"]
[Tue Jul 21 08:03:19.371129 2026] [security2:error] [pid 352421:tid 352661] [client 20.151.10.161:28506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/FAQ.php"] [unique_id "al9R98JSWzG9jbYOtu5DsgAAAPM"]
[Tue Jul 21 08:03:19.372316 2026] [security2:error] [pid 352421:tid 352605] [client 151.63.71.144:57623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9R98JSWzG9jbYOtu5DswAAALs"]
[Tue Jul 21 08:03:19.372478 2026] [security2:error] [pid 352421:tid 352605] [client 151.63.71.144:57623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9R98JSWzG9jbYOtu5DswAAALs"]
[Tue Jul 21 08:03:19.508481 2026] [security2:error] [pid 352421:tid 352571] [client 20.197.192.193:5077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/ez.php"] [unique_id "al9R98JSWzG9jbYOtu5DtwAAAJk"]
[Tue Jul 21 08:03:19.589225 2026] [security2:error] [pid 352421:tid 352613] [client 120.56.162.40:63199] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R98JSWzG9jbYOtu5DuQAAAMM"]
[Tue Jul 21 08:03:19.589366 2026] [security2:error] [pid 352421:tid 352613] [client 120.56.162.40:63199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R98JSWzG9jbYOtu5DuQAAAMM"]
[Tue Jul 21 08:03:19.694088 2026] [security2:error] [pid 358661:tid 358789] [remote 185.177.238.46:50694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9R9wlWhjQfpOo60_HRGgAAKHw"]
[Tue Jul 21 08:03:19.712516 2026] [security2:error] [pid 358661:tid 358844] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9R9wlWhjQfpOo60_HRGwAAADI"]
[Tue Jul 21 08:03:19.735201 2026] [security2:error] [pid 352421:tid 352507] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9R98JSWzG9jbYOtu5DugABAlU"]
[Tue Jul 21 08:03:19.735320 2026] [security2:error] [pid 352421:tid 352676] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9R98JSWzG9jbYOtu5DugABAlU"]
[Tue Jul 21 08:03:19.936944 2026] [security2:error] [pid 358661:tid 358907] [client 20.197.192.193:5085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/fz.php"] [unique_id "al9R9wlWhjQfpOo60_HRHwAAAHE"]
[Tue Jul 21 08:03:19.999594 2026] [security2:error] [pid 358661:tid 358901] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9R9wlWhjQfpOo60_HRIAAAAGs"]
[Tue Jul 21 08:03:20.086277 2026] [security2:error] [pid 352421:tid 352622] [client 185.177.238.46:53926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9R-MJSWzG9jbYOtu5DwgAAAMw"]
[Tue Jul 21 08:03:20.110796 2026] [security2:error] [pid 358661:tid 358714] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R-AlWhjQfpOo60_HRIgAAIDE"]
[Tue Jul 21 08:03:20.110920 2026] [security2:error] [pid 358661:tid 358826] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R-AlWhjQfpOo60_HRIgAAIDE"]
[Tue Jul 21 08:03:20.160488 2026] [security2:error] [pid 358661:tid 358773] [remote 185.177.238.46:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "infoalert.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9R9wlWhjQfpOo60_HRDgAAB2w"]
[Tue Jul 21 08:03:20.213109 2026] [security2:error] [pid 352421:tid 352549] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R-MJSWzG9jbYOtu5DxQAAq38"]
[Tue Jul 21 08:03:20.213269 2026] [security2:error] [pid 352421:tid 352589] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R-MJSWzG9jbYOtu5DxQAAq38"]
[Tue Jul 21 08:03:20.286735 2026] [security2:error] [pid 358661:tid 358816] [client 146.70.194.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "energyzapp.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9R-AlWhjQfpOo60_HRJwAAABY"]
[Tue Jul 21 08:03:20.353869 2026] [security2:error] [pid 358661:tid 358914] [client 20.197.195.24:2892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/lib.php"] [unique_id "al9R-AlWhjQfpOo60_HRKAAAAHg"]
[Tue Jul 21 08:03:20.411278 2026] [security2:error] [pid 358661:tid 358917] [client 20.151.10.161:28556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/coffexium.php"] [unique_id "al9R-AlWhjQfpOo60_HRKgAAAHs"]
[Tue Jul 21 08:03:20.546852 2026] [security2:error] [pid 358661:tid 358808] [client 20.197.192.193:54983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/la.php"] [unique_id "al9R-AlWhjQfpOo60_HRLAAAAA4"]
[Tue Jul 21 08:03:20.582660 2026] [security2:error] [pid 358661:tid 358747] [remote 185.213.175.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.conquisteemcasa.com.br"] [uri "/"] [unique_id "al9R-AlWhjQfpOo60_HRLQAAYVI"]
[Tue Jul 21 08:03:20.582823 2026] [security2:error] [pid 358661:tid 358891] [client 185.213.175.37:0] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.conquisteemcasa.com.br"] [uri "/"] [unique_id "al9R-AlWhjQfpOo60_HRLQAAYVI"]
[Tue Jul 21 08:03:20.731738 2026] [security2:error] [pid 358661:tid 358694] [remote 185.177.238.46:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "infoalert.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9R-AlWhjQfpOo60_HRLgAAHR0"], referer: http://infoalert.com.br/wp-admin/admin-ajax.php
[Tue Jul 21 08:03:20.733913 2026] [security2:error] [pid 358661:tid 358862] [client 204.8.98.45:36934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9R-AlWhjQfpOo60_HRLwAAAEQ"]
[Tue Jul 21 08:03:20.734002 2026] [security2:error] [pid 358661:tid 358862] [client 204.8.98.45:36934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9R-AlWhjQfpOo60_HRLwAAAEQ"]
[Tue Jul 21 08:03:20.792223 2026] [security2:error] [pid 352421:tid 352633] [client 20.197.192.193:53125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/mac.php"] [unique_id "al9R-MJSWzG9jbYOtu5DzAAAANc"]
[Tue Jul 21 08:03:20.821836 2026] [security2:error] [pid 358661:tid 358799] [client 20.197.192.193:5042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/nhvoanpl.php"] [unique_id "al9R-AlWhjQfpOo60_HRMQAAAAU"]
[Tue Jul 21 08:03:20.843268 2026] [security2:error] [pid 352421:tid 352552] [client 20.151.10.161:28563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/red.php"] [unique_id "al9R-MJSWzG9jbYOtu5DzgAAAIY"]
[Tue Jul 21 08:03:20.978695 2026] [security2:error] [pid 358661:tid 358893] [client 20.197.192.193:5118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/inso.php"] [unique_id "al9R-AlWhjQfpOo60_HRNAAAAGM"]
[Tue Jul 21 08:03:21.024671 2026] [security2:error] [pid 358661:tid 358853] [client 20.197.192.193:5031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/wpx.php"] [unique_id "al9R-QlWhjQfpOo60_HRNQAAADs"]
[Tue Jul 21 08:03:21.093079 2026] [security2:error] [pid 358661:tid 358701] [remote 185.177.238.46:50696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.folegofinanceiro.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9R-QlWhjQfpOo60_HROAAAYiQ"]
[Tue Jul 21 08:03:21.114675 2026] [security2:error] [pid 358661:tid 358806] [client 20.197.192.193:5117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/berlin.php"] [unique_id "al9R-QlWhjQfpOo60_HROQAAAAw"]
[Tue Jul 21 08:03:21.226280 2026] [security2:error] [pid 358661:tid 358805] [client 20.197.192.193:54989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/billur.php"] [unique_id "al9R-QlWhjQfpOo60_HROgAAAAs"]
[Tue Jul 21 08:03:21.335699 2026] [security2:error] [pid 358661:tid 358713] [remote 185.177.238.46:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.infoalert.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9R-QlWhjQfpOo60_HRPgAAVzA"]
[Tue Jul 21 08:03:21.366811 2026] [security2:error] [pid 352421:tid 352585] [client 20.197.192.193:5097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/mimpi.php"] [unique_id "al9R-cJSWzG9jbYOtu5D0wAAAKc"]
[Tue Jul 21 08:03:21.412413 2026] [security2:error] [pid 358661:tid 358811] [client 20.197.192.193:5051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/dp.php"] [unique_id "al9R-QlWhjQfpOo60_HRPwAAABE"]
[Tue Jul 21 08:03:21.466620 2026] [security2:error] [pid 358661:tid 358863] [client 20.197.192.193:5027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/bootstrap.php"] [unique_id "al9R-QlWhjQfpOo60_HRQgAAAEU"]
[Tue Jul 21 08:03:21.556505 2026] [security2:error] [pid 358661:tid 358814] [client 20.197.192.193:5047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/wp-editor.php"] [unique_id "al9R-QlWhjQfpOo60_HRRQAAABQ"]
[Tue Jul 21 08:03:21.590483 2026] [security2:error] [pid 352421:tid 352556] [client 20.197.195.24:2843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/login.php"] [unique_id "al9R-cJSWzG9jbYOtu5D2gAAAIo"]
[Tue Jul 21 08:03:21.679304 2026] [security2:error] [pid 358661:tid 358767] [remote 185.177.238.46:50698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9R-QlWhjQfpOo60_HRRwAAEGY"]
[Tue Jul 21 08:03:21.772311 2026] [security2:error] [pid 352421:tid 352595] [client 193.36.225.65:58943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9R-cJSWzG9jbYOtu5D3QAAALE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:03:21.835645 2026] [security2:error] [pid 358661:tid 358901] [client 20.151.10.161:28229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9R-QlWhjQfpOo60_HRSQAAAGs"]
[Tue Jul 21 08:03:21.841497 2026] [security2:error] [pid 358661:tid 358869] [client 106.215.181.8:15155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R-QlWhjQfpOo60_HRSgAAAEs"]
[Tue Jul 21 08:03:21.841615 2026] [security2:error] [pid 358661:tid 358869] [client 106.215.181.8:15155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R-QlWhjQfpOo60_HRSgAAAEs"]
[Tue Jul 21 08:03:21.879453 2026] [security2:error] [pid 358661:tid 358717] [remote 185.177.238.46:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "infoalert.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9R-QlWhjQfpOo60_HRSwAAUjQ"]
[Tue Jul 21 08:03:21.901236 2026] [security2:error] [pid 352421:tid 352644] [client 20.197.192.193:4149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/cro.php"] [unique_id "al9R-cJSWzG9jbYOtu5D3wAAAOI"]
[Tue Jul 21 08:03:22.071190 2026] [security2:error] [pid 352421:tid 352600] [client 185.177.238.46:53932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "folegofinanceiro.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9R-sJSWzG9jbYOtu5D4wAAALY"]
[Tue Jul 21 08:03:22.072756 2026] [security2:error] [pid 352421:tid 352652] [client 20.197.192.193:5053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/cron-tab.php"] [unique_id "al9R-sJSWzG9jbYOtu5D5AAAAOo"]
[Tue Jul 21 08:03:22.102466 2026] [security2:error] [pid 358661:tid 358685] [remote 185.177.238.46:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "infoalert.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9R-glWhjQfpOo60_HRUgAAHxQ"], referer: http://infoalert.com.br/wp-admin/admin-ajax.php
[Tue Jul 21 08:03:22.223687 2026] [security2:error] [pid 352421:tid 352656] [client 20.197.192.193:5017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/koiy.php"] [unique_id "al9R-sJSWzG9jbYOtu5D7AAAAO4"]
[Tue Jul 21 08:03:22.266487 2026] [security2:error] [pid 352421:tid 352645] [client 102.206.115.33:59271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9R-sJSWzG9jbYOtu5D7QAAAOM"]
[Tue Jul 21 08:03:22.266624 2026] [security2:error] [pid 352421:tid 352645] [client 102.206.115.33:59271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9R-sJSWzG9jbYOtu5D7QAAAOM"]
[Tue Jul 21 08:03:22.277753 2026] [security2:error] [pid 352421:tid 352650] [client 20.151.10.161:28175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/footer.php"] [unique_id "al9R-sJSWzG9jbYOtu5D7gAAAOg"]
[Tue Jul 21 08:03:22.319048 2026] [security2:error] [pid 352421:tid 352605] [client 20.197.192.193:5057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/hp2.php"] [unique_id "al9R-sJSWzG9jbYOtu5D8AAAALs"]
[Tue Jul 21 08:03:22.324990 2026] [security2:error] [pid 352421:tid 352618] [client 20.197.195.24:24087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/a2.php"] [unique_id "al9R-sJSWzG9jbYOtu5D8QAAAMg"]
[Tue Jul 21 08:03:22.439808 2026] [security2:error] [pid 358661:tid 358866] [client 65.21.113.253:40410] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R-glWhjQfpOo60_HRVAAAAEg"]
[Tue Jul 21 08:03:22.512963 2026] [security2:error] [pid 358661:tid 358845] [client 87.116.180.198:27268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R-glWhjQfpOo60_HRWgAAADM"]
[Tue Jul 21 08:03:22.514029 2026] [security2:error] [pid 358661:tid 358845] [client 87.116.180.198:27268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R-glWhjQfpOo60_HRWgAAADM"]
[Tue Jul 21 08:03:22.627236 2026] [security2:error] [pid 358661:tid 358867] [client 20.197.192.193:54992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/hp3.php"] [unique_id "al9R-glWhjQfpOo60_HRWwAAAEk"]
[Tue Jul 21 08:03:22.643981 2026] [security2:error] [pid 352421:tid 352430] [remote 185.177.238.46:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.infoalert.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9R-sJSWzG9jbYOtu5D-QABAgg"]
[Tue Jul 21 08:03:22.658234 2026] [security2:error] [pid 352421:tid 352525] [remote 185.177.238.46:50700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.folegofinanceiro.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9R-sJSWzG9jbYOtu5D-gAA9Gc"]
[Tue Jul 21 08:03:22.705608 2026] [security2:error] [pid 358661:tid 358808] [client 5.156.39.40:5147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.39.156.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iflyballoon.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R-glWhjQfpOo60_HRXwAAAA4"]
[Tue Jul 21 08:03:22.705748 2026] [security2:error] [pid 358661:tid 358808] [client 5.156.39.40:5147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "iflyballoon.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R-glWhjQfpOo60_HRXwAAAA4"]
[Tue Jul 21 08:03:22.754854 2026] [security2:error] [pid 352421:tid 352624] [client 20.151.10.161:28266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-content/index.php"] [unique_id "al9R-sJSWzG9jbYOtu5D-wAAAM4"]
[Tue Jul 21 08:03:22.819119 2026] [security2:error] [pid 352421:tid 352589] [client 20.197.192.193:5050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/aa1.php"] [unique_id "al9R-sJSWzG9jbYOtu5D_gAAAKs"]
[Tue Jul 21 08:03:22.879228 2026] [security2:error] [pid 352421:tid 352468] [remote 5.252.52.249:43730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/wp-login.php"] [unique_id "al9R-sJSWzG9jbYOtu5EAAAA0C4"]
[Tue Jul 21 08:03:22.892484 2026] [security2:error] [pid 352421:tid 352675] [client 20.197.192.193:5063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/acew67.php"] [unique_id "al9R-sJSWzG9jbYOtu5EAQAAAQE"]
[Tue Jul 21 08:03:22.993584 2026] [security2:error] [pid 358661:tid 358803] [client 20.197.192.193:56801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/xxx.php"] [unique_id "al9R-glWhjQfpOo60_HRZAAAAAk"]
[Tue Jul 21 08:03:23.035189 2026] [security2:error] [pid 358661:tid 358919] [client 20.197.192.193:5033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/bscclapb.php"] [unique_id "al9R-wlWhjQfpOo60_HRZQAAAH0"]
[Tue Jul 21 08:03:23.076951 2026] [security2:error] [pid 358661:tid 358820] [client 65.21.113.253:35970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R-glWhjQfpOo60_HRXgAAABo"]
[Tue Jul 21 08:03:23.167884 2026] [security2:error] [pid 352421:tid 352629] [client 117.247.80.59:24325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R-8JSWzG9jbYOtu5ECAAAANM"]
[Tue Jul 21 08:03:23.168025 2026] [security2:error] [pid 352421:tid 352629] [client 117.247.80.59:24325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R-8JSWzG9jbYOtu5ECAAAANM"]
[Tue Jul 21 08:03:23.178081 2026] [security2:error] [pid 352421:tid 352482] [remote 185.177.238.46:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "infoalert.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9R-8JSWzG9jbYOtu5ECQAAojw"]
[Tue Jul 21 08:03:23.190310 2026] [security2:error] [pid 352421:tid 352633] [client 20.151.10.161:28589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/zoro.php"] [unique_id "al9R-8JSWzG9jbYOtu5ECgAAANc"]
[Tue Jul 21 08:03:23.242974 2026] [security2:error] [pid 358661:tid 358702] [remote 185.177.238.46:50702] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "folegofinanceiro.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9R-wlWhjQfpOo60_HRbQAATSU"]
[Tue Jul 21 08:03:23.320942 2026] [security2:error] [pid 352421:tid 352581] [client 20.197.192.193:5045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/else1.php"] [unique_id "al9R-8JSWzG9jbYOtu5EDAAAAKM"]
[Tue Jul 21 08:03:23.326455 2026] [security2:error] [pid 358661:tid 358885] [client 103.29.114.44:50852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R-wlWhjQfpOo60_HRbgAAAFs"]
[Tue Jul 21 08:03:23.326566 2026] [security2:error] [pid 358661:tid 358885] [client 103.29.114.44:50852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R-wlWhjQfpOo60_HRbgAAAFs"]
[Tue Jul 21 08:03:23.415248 2026] [security2:error] [pid 358661:tid 358879] [client 182.8.255.181:2924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9R-wlWhjQfpOo60_HRbwAAAFU"]
[Tue Jul 21 08:03:23.415536 2026] [security2:error] [pid 358661:tid 358879] [client 182.8.255.181:2924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9R-wlWhjQfpOo60_HRbwAAAFU"]
[Tue Jul 21 08:03:23.555293 2026] [security2:error] [pid 358661:tid 358827] [client 20.197.192.193:55034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/tkikikoko.php"] [unique_id "al9R-wlWhjQfpOo60_HRdAAAACE"]
[Tue Jul 21 08:03:23.632547 2026] [security2:error] [pid 358661:tid 358815] [client 185.177.238.46:53950] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "folegofinanceiro.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9R-wlWhjQfpOo60_HReAAAABU"]
[Tue Jul 21 08:03:23.661124 2026] [security2:error] [pid 352421:tid 352604] [client 20.151.10.161:28269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/admin.php"] [unique_id "al9R-8JSWzG9jbYOtu5EEQAAALo"]
[Tue Jul 21 08:03:23.697769 2026] [security2:error] [pid 358661:tid 358839] [client 20.197.192.193:5022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/wp-Blogs.php"] [unique_id "al9R-wlWhjQfpOo60_HReQAAAC0"]
[Tue Jul 21 08:03:23.742694 2026] [security2:error] [pid 358661:tid 358764] [remote 185.177.238.46:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "infoalert.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9R-wlWhjQfpOo60_HRegAAB2M"], referer: http://infoalert.com.br/wp-content/plugins/super-forms/readme.txt
[Tue Jul 21 08:03:23.957942 2026] [security2:error] [pid 358661:tid 358762] [remote 91.142.222.105:54044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caminhoneiro.giovanoniadv.com.br"] [uri "/wp-login.php"] [unique_id "al9R-wlWhjQfpOo60_HRfwAAFmE"]
[Tue Jul 21 08:03:24.031017 2026] [security2:error] [pid 358661:tid 358866] [client 20.197.192.193:54990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/wp-css.php"] [unique_id "al9R_AlWhjQfpOo60_HRggAAAEg"]
[Tue Jul 21 08:03:24.057244 2026] [security2:error] [pid 352421:tid 352595] [client 20.197.195.24:24073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/d61.php"] [unique_id "al9R_MJSWzG9jbYOtu5EFQAAALE"]
[Tue Jul 21 08:03:24.220662 2026] [security2:error] [pid 352421:tid 352533] [remote 185.177.238.46:50704] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.folegofinanceiro.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9R_MJSWzG9jbYOtu5EGwAA-28"]
[Tue Jul 21 08:03:24.299587 2026] [security2:error] [pid 352421:tid 352491] [remote 185.177.238.46:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.infoalert.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9R_MJSWzG9jbYOtu5EHQAAlEU"]
[Tue Jul 21 08:03:24.317506 2026] [security2:error] [pid 352421:tid 352528] [remote 45.79.123.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samilacalculos.com.br"] [uri "/wp-login.php"] [unique_id "al9R_MJSWzG9jbYOtu5EHgAA2Go"]
[Tue Jul 21 08:03:24.332385 2026] [security2:error] [pid 352421:tid 352667] [client 20.151.10.161:28485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/greap.php"] [unique_id "al9R_MJSWzG9jbYOtu5EHwAAAPk"]
[Tue Jul 21 08:03:24.512302 2026] [security2:error] [pid 358661:tid 358893] [client 20.197.192.193:5052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/wp-explorer.php"] [unique_id "al9R_AlWhjQfpOo60_HRkQAAAGM"]
[Tue Jul 21 08:03:24.743029 2026] [security2:error] [pid 358661:tid 358795] [client 20.151.10.161:28493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/177.php"] [unique_id "al9R_AlWhjQfpOo60_HRpwAAAAE"]
[Tue Jul 21 08:03:24.793704 2026] [security2:error] [pid 358661:tid 358889] [client 103.78.200.11:55505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R_AlWhjQfpOo60_HRqQAAAF8"]
[Tue Jul 21 08:03:24.793837 2026] [security2:error] [pid 358661:tid 358889] [client 103.78.200.11:55505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R_AlWhjQfpOo60_HRqQAAAF8"]
[Tue Jul 21 08:03:24.796683 2026] [security2:error] [pid 358661:tid 358761] [remote 156.59.198.135:49538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "issima.net.br"] [uri "/equestre/etiqueta/etiqueta-issima-equestre.pdf"] [unique_id "al9R_AlWhjQfpOo60_HRqgAADGA"]
[Tue Jul 21 08:03:24.814504 2026] [security2:error] [pid 358661:tid 358803] [client 184.75.221.3:46900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9R_AlWhjQfpOo60_HRqwAAAAk"]
[Tue Jul 21 08:03:24.814594 2026] [security2:error] [pid 358661:tid 358803] [client 184.75.221.3:46900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9R_AlWhjQfpOo60_HRqwAAAAk"]
[Tue Jul 21 08:03:24.846561 2026] [security2:error] [pid 352421:tid 352554] [client 20.197.192.193:5009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/akismet.php"] [unique_id "al9R_MJSWzG9jbYOtu5EJgAAAIg"]
[Tue Jul 21 08:03:25.058171 2026] [security2:error] [pid 358661:tid 358820] [client 20.197.192.193:5005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/ace2.php"] [unique_id "al9R_QlWhjQfpOo60_HRrQAAABo"]
[Tue Jul 21 08:03:25.173880 2026] [security2:error] [pid 358661:tid 358916] [client 20.197.192.193:5065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.getecma.com"] [uri "/ms.php"] [unique_id "al9R_QlWhjQfpOo60_HRsgAAAHo"]
[Tue Jul 21 08:03:25.206934 2026] [security2:error] [pid 358661:tid 358874] [client 20.151.10.161:28226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/199.php"] [unique_id "al9R_QlWhjQfpOo60_HRswAAAFA"]
[Tue Jul 21 08:03:25.355863 2026] [security2:error] [pid 358661:tid 358814] [client 65.21.113.253:35970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9R_QlWhjQfpOo60_HRsQAAABQ"]
[Tue Jul 21 08:03:25.393039 2026] [security2:error] [pid 352421:tid 352590] [client 109.60.28.94:63539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R_cJSWzG9jbYOtu5ELAAAAKw"]
[Tue Jul 21 08:03:25.393275 2026] [security2:error] [pid 352421:tid 352590] [client 109.60.28.94:63539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R_cJSWzG9jbYOtu5ELAAAAKw"]
[Tue Jul 21 08:03:25.544422 2026] [security2:error] [pid 358661:tid 358815] [client 20.151.10.161:28264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file52.php"] [unique_id "al9R_QlWhjQfpOo60_HRuQAAABU"]
[Tue Jul 21 08:03:25.711100 2026] [security2:error] [pid 352421:tid 352565] [client 20.104.96.117:27088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/cilus.php"] [unique_id "al9R_cJSWzG9jbYOtu5EMQAAAJM"]
[Tue Jul 21 08:03:25.910753 2026] [security2:error] [pid 352421:tid 352574] [client 20.151.10.161:28597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/122.php"] [unique_id "al9R_cJSWzG9jbYOtu5ENAAAAJw"]
[Tue Jul 21 08:03:26.032744 2026] [security2:error] [pid 358661:tid 358838] [client 103.166.103.129:54724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9R_glWhjQfpOo60_HRxAAAACw"]
[Tue Jul 21 08:03:26.032895 2026] [security2:error] [pid 358661:tid 358838] [client 103.166.103.129:54724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9R_glWhjQfpOo60_HRxAAAACw"]
[Tue Jul 21 08:03:26.181183 2026] [security2:error] [pid 358661:tid 358876] [client 122.179.91.63:6195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9R_glWhjQfpOo60_HRzwAAAFI"]
[Tue Jul 21 08:03:26.181303 2026] [security2:error] [pid 358661:tid 358876] [client 122.179.91.63:6195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9R_glWhjQfpOo60_HRzwAAAFI"]
[Tue Jul 21 08:03:26.192972 2026] [security2:error] [pid 358661:tid 358914] [client 178.153.91.96:28679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9R_glWhjQfpOo60_HR0AAAAHg"]
[Tue Jul 21 08:03:26.193099 2026] [security2:error] [pid 358661:tid 358914] [client 178.153.91.96:28679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9R_glWhjQfpOo60_HR0AAAAHg"]
[Tue Jul 21 08:03:26.222894 2026] [security2:error] [pid 352421:tid 352440] [remote 103.187.169.251:45342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9R_sJSWzG9jbYOtu5EOQAA1RI"]
[Tue Jul 21 08:03:26.244572 2026] [security2:error] [pid 358661:tid 358867] [client 20.197.195.24:2819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/info.php"] [unique_id "al9R_glWhjQfpOo60_HR0QAAAEk"]
[Tue Jul 21 08:03:26.356377 2026] [security2:error] [pid 358661:tid 358832] [client 20.151.10.161:28508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/green1.php"] [unique_id "al9R_glWhjQfpOo60_HR0gAAACY"]
[Tue Jul 21 08:03:26.383953 2026] [security2:error] [pid 358661:tid 358845] [client 193.36.225.55:29867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9R_glWhjQfpOo60_HR0wAAADM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:03:26.387100 2026] [security2:error] [pid 358661:tid 358770] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9R_glWhjQfpOo60_HR1AAAdGk"]
[Tue Jul 21 08:03:26.387231 2026] [security2:error] [pid 358661:tid 358910] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9R_glWhjQfpOo60_HR1AAAdGk"]
[Tue Jul 21 08:03:26.741474 2026] [security2:error] [pid 352421:tid 352564] [client 20.151.10.161:28250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/biufile.php"] [unique_id "al9R_sJSWzG9jbYOtu5EPwAAAJI"]
[Tue Jul 21 08:03:26.792262 2026] [security2:error] [pid 358661:tid 358866] [client 117.210.135.0:59588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R_glWhjQfpOo60_HR4AAAAEg"]
[Tue Jul 21 08:03:26.792415 2026] [security2:error] [pid 358661:tid 358866] [client 117.210.135.0:59588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R_glWhjQfpOo60_HR4AAAAEg"]
[Tue Jul 21 08:03:26.868591 2026] [security2:error] [pid 358661:tid 358708] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R_glWhjQfpOo60_HR7gAAfSs"]
[Tue Jul 21 08:03:26.868719 2026] [security2:error] [pid 358661:tid 358919] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R_glWhjQfpOo60_HR7gAAfSs"]
[Tue Jul 21 08:03:27.083337 2026] [security2:error] [pid 358661:tid 358917] [client 172.234.129.144:39842] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "rstlimoveis.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9R_wlWhjQfpOo60_HSDwAAAHs"]
[Tue Jul 21 08:03:27.206382 2026] [security2:error] [pid 358661:tid 358823] [client 172.234.129.144:39842] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "rstlimoveis.com.br"] [uri "/"] [unique_id "al9R_wlWhjQfpOo60_HSOgAAAB0"]
[Tue Jul 21 08:03:27.320473 2026] [security2:error] [pid 358661:tid 358846] [client 20.197.192.193:50586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/hunter.php"] [unique_id "al9R_wlWhjQfpOo60_HSPgAAADQ"]
[Tue Jul 21 08:03:27.554889 2026] [security2:error] [pid 358661:tid 358873] [client 202.143.127.214:55107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R_wlWhjQfpOo60_HSQgAAAE8"]
[Tue Jul 21 08:03:27.555071 2026] [security2:error] [pid 358661:tid 358873] [client 202.143.127.214:55107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R_wlWhjQfpOo60_HSQgAAAE8"]
[Tue Jul 21 08:03:27.730160 2026] [security2:error] [pid 358661:tid 358893] [client 20.151.10.161:28248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wpconf.php"] [unique_id "al9R_wlWhjQfpOo60_HSRQAAAGM"]
[Tue Jul 21 08:03:27.869088 2026] [security2:error] [pid 358661:tid 358910] [client 74.7.228.45:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "raulvaccarirodrigues1781900131469.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9R_wlWhjQfpOo60_HSSAAAdD0"]
[Tue Jul 21 08:03:27.870478 2026] [security2:error] [pid 358661:tid 358816] [client 38.100.221.102:18873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R_wlWhjQfpOo60_HSSQAAABY"]
[Tue Jul 21 08:03:27.870601 2026] [security2:error] [pid 358661:tid 358816] [client 38.100.221.102:18873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R_wlWhjQfpOo60_HSSQAAABY"]
[Tue Jul 21 08:03:27.885967 2026] [security2:error] [pid 358661:tid 358855] [client 41.68.90.219:63334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R_wlWhjQfpOo60_HSSwAAAD0"]
[Tue Jul 21 08:03:27.887019 2026] [security2:error] [pid 358661:tid 358855] [client 41.68.90.219:63334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9R_wlWhjQfpOo60_HSSwAAAD0"]
[Tue Jul 21 08:03:28.228600 2026] [security2:error] [pid 358661:tid 358779] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SAAlWhjQfpOo60_HSTQAAGnI"]
[Tue Jul 21 08:03:28.228799 2026] [security2:error] [pid 358661:tid 358820] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SAAlWhjQfpOo60_HSTQAAGnI"]
[Tue Jul 21 08:03:28.284807 2026] [security2:error] [pid 352421:tid 352652] [client 20.151.10.161:28555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/mosty.php"] [unique_id "al9SAMJSWzG9jbYOtu5EVwAAAOo"]
[Tue Jul 21 08:03:28.509583 2026] [security2:error] [pid 358661:tid 358827] [client 175.144.82.48:62717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SAAlWhjQfpOo60_HSWAAAACE"]
[Tue Jul 21 08:03:28.510453 2026] [security2:error] [pid 358661:tid 358827] [client 175.144.82.48:62717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SAAlWhjQfpOo60_HSWAAAACE"]
[Tue Jul 21 08:03:28.668539 2026] [security2:error] [pid 352421:tid 352658] [client 20.197.195.24:58969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/11.php"] [unique_id "al9SAMJSWzG9jbYOtu5EYwAAAPA"]
[Tue Jul 21 08:03:28.716873 2026] [security2:error] [pid 352421:tid 352570] [client 20.151.10.161:28245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/dejavu.php"] [unique_id "al9SAMJSWzG9jbYOtu5EZQAAAJg"]
[Tue Jul 21 08:03:29.407116 2026] [security2:error] [pid 358661:tid 358709] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SAQlWhjQfpOo60_HScAAAJyw"]
[Tue Jul 21 08:03:29.407345 2026] [security2:error] [pid 358661:tid 358833] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SAQlWhjQfpOo60_HScAAAJyw"]
[Tue Jul 21 08:03:29.463205 2026] [security2:error] [pid 358661:tid 358838] [client 20.151.10.161:28530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/aaf.php"] [unique_id "al9SAQlWhjQfpOo60_HScgAAACw"]
[Tue Jul 21 08:03:29.902217 2026] [security2:error] [pid 352421:tid 352629] [client 20.29.126.15:15309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/error.php"] [unique_id "al9SAcJSWzG9jbYOtu5EgAAAANM"]
[Tue Jul 21 08:03:29.911964 2026] [security2:error] [pid 358661:tid 358700] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SAQlWhjQfpOo60_HSegAAeCM"]
[Tue Jul 21 08:03:29.912132 2026] [security2:error] [pid 358661:tid 358914] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SAQlWhjQfpOo60_HSegAAeCM"]
[Tue Jul 21 08:03:30.245606 2026] [security2:error] [pid 352421:tid 352657] [client 20.151.10.161:28514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/term.php"] [unique_id "al9SAsJSWzG9jbYOtu5EgwAAAO8"]
[Tue Jul 21 08:03:30.263132 2026] [security2:error] [pid 358661:tid 358860] [client 120.56.162.40:63645] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SAglWhjQfpOo60_HSfgAAAEI"]
[Tue Jul 21 08:03:30.263234 2026] [security2:error] [pid 358661:tid 358860] [client 120.56.162.40:63645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SAglWhjQfpOo60_HSfgAAAEI"]
[Tue Jul 21 08:03:30.404844 2026] [security2:error] [pid 358661:tid 358887] [client 20.197.195.24:59002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/v2.php"] [unique_id "al9SAglWhjQfpOo60_HSgwAAAF0"]
[Tue Jul 21 08:03:30.488963 2026] [security2:error] [pid 358661:tid 358745] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SAglWhjQfpOo60_HSywAACFA"]
[Tue Jul 21 08:03:30.489142 2026] [security2:error] [pid 358661:tid 358802] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SAglWhjQfpOo60_HSywAACFA"]
[Tue Jul 21 08:03:30.513770 2026] [security2:error] [pid 358661:tid 358845] [client 74.7.230.26:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "luanadasilvabenitez1782166357603.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9SAglWhjQfpOo60_HS1QAAMww"]
[Tue Jul 21 08:03:31.094685 2026] [security2:error] [pid 352421:tid 352542] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SA8JSWzG9jbYOtu5EowAAuHg"]
[Tue Jul 21 08:03:31.094905 2026] [security2:error] [pid 352421:tid 352602] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SA8JSWzG9jbYOtu5EowAAuHg"]
[Tue Jul 21 08:03:31.163469 2026] [security2:error] [pid 352421:tid 352615] [client 193.36.225.62:30793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SAcJSWzG9jbYOtu5EgQAAAMU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:03:31.204621 2026] [security2:error] [pid 352421:tid 352536] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SA8JSWzG9jbYOtu5EpgAAwXI"]
[Tue Jul 21 08:03:31.204800 2026] [security2:error] [pid 352421:tid 352611] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SA8JSWzG9jbYOtu5EpgAAwXI"]
[Tue Jul 21 08:03:31.376090 2026] [security2:error] [pid 352421:tid 352620] [client 20.151.10.161:28576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ha.php"] [unique_id "al9SA8JSWzG9jbYOtu5EpwAAAMo"]
[Tue Jul 21 08:03:32.037787 2026] [security2:error] [pid 358661:tid 358823] [client 20.104.96.117:46638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/gptsh.php"] [unique_id "al9SBAlWhjQfpOo60_HS6AAAAB0"]
[Tue Jul 21 08:03:32.331738 2026] [security2:error] [pid 352421:tid 352650] [client 106.215.181.8:20446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SBMJSWzG9jbYOtu5EuwAAAOg"]
[Tue Jul 21 08:03:32.331894 2026] [security2:error] [pid 352421:tid 352650] [client 106.215.181.8:20446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SBMJSWzG9jbYOtu5EuwAAAOg"]
[Tue Jul 21 08:03:32.438195 2026] [security2:error] [pid 358661:tid 358808] [client 20.151.10.161:28523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/hur.php"] [unique_id "al9SBAlWhjQfpOo60_HS7QAAAA4"]
[Tue Jul 21 08:03:32.700000 2026] [security2:error] [pid 358661:tid 358883] [client 20.197.192.193:53145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/samll.php"] [unique_id "al9SBAlWhjQfpOo60_HS8AAAAFk"]
[Tue Jul 21 08:03:32.808851 2026] [security2:error] [pid 352421:tid 352565] [client 102.206.115.33:62400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SBMJSWzG9jbYOtu5ExgAAAJM"]
[Tue Jul 21 08:03:32.808950 2026] [security2:error] [pid 352421:tid 352565] [client 102.206.115.33:62400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SBMJSWzG9jbYOtu5ExgAAAJM"]
[Tue Jul 21 08:03:32.830022 2026] [security2:error] [pid 358661:tid 358803] [client 20.220.225.223:34293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/edit.php"] [unique_id "al9SBAlWhjQfpOo60_HS8QAAAAk"]
[Tue Jul 21 08:03:33.048362 2026] [security2:error] [pid 352421:tid 352668] [client 20.151.10.161:28573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/h02ugyh.php"] [unique_id "al9SBcJSWzG9jbYOtu5EzwAAAPo"]
[Tue Jul 21 08:03:33.060171 2026] [security2:error] [pid 352421:tid 352635] [client 20.197.195.24:24121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/panel.php"] [unique_id "al9SBcJSWzG9jbYOtu5E0QAAANk"]
[Tue Jul 21 08:03:33.157673 2026] [security2:error] [pid 358661:tid 358893] [client 87.116.180.198:27233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SBQlWhjQfpOo60_HS-wAAAGM"]
[Tue Jul 21 08:03:33.157820 2026] [security2:error] [pid 358661:tid 358893] [client 87.116.180.198:27233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SBQlWhjQfpOo60_HS-wAAAGM"]
[Tue Jul 21 08:03:33.406383 2026] [security2:error] [pid 358661:tid 358875] [client 20.151.10.161:28535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/seiso.php"] [unique_id "al9SBQlWhjQfpOo60_HS_gAAAFE"]
[Tue Jul 21 08:03:33.454209 2026] [security2:error] [pid 358661:tid 358811] [client 20.197.192.193:50614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/we.php"] [unique_id "al9SBQlWhjQfpOo60_HS_wAAABE"]
[Tue Jul 21 08:03:33.806432 2026] [security2:error] [pid 358661:tid 358890] [client 20.151.10.161:28552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/155.php"] [unique_id "al9SBQlWhjQfpOo60_HTAQAAAGA"]
[Tue Jul 21 08:03:33.832673 2026] [security2:error] [pid 358661:tid 358918] [client 182.8.255.181:17492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SBQlWhjQfpOo60_HTAgAAAHw"]
[Tue Jul 21 08:03:33.832791 2026] [security2:error] [pid 358661:tid 358918] [client 182.8.255.181:17492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SBQlWhjQfpOo60_HTAgAAAHw"]
[Tue Jul 21 08:03:33.841109 2026] [security2:error] [pid 358661:tid 358797] [client 103.78.200.11:55987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SBQlWhjQfpOo60_HTAwAAAAM"]
[Tue Jul 21 08:03:33.841217 2026] [security2:error] [pid 358661:tid 358797] [client 103.78.200.11:55987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SBQlWhjQfpOo60_HTAwAAAAM"]
[Tue Jul 21 08:03:33.987190 2026] [security2:error] [pid 352421:tid 352438] [remote 5.252.52.249:50938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "frsadvocacia.net"] [uri "/wp-login.php"] [unique_id "al9SBcJSWzG9jbYOtu5E5AAAohA"]
[Tue Jul 21 08:03:33.992160 2026] [security2:error] [pid 352421:tid 352637] [client 117.247.80.59:20446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SBcJSWzG9jbYOtu5E5QAAANs"]
[Tue Jul 21 08:03:33.992263 2026] [security2:error] [pid 352421:tid 352637] [client 117.247.80.59:20446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SBcJSWzG9jbYOtu5E5QAAANs"]
[Tue Jul 21 08:03:34.008994 2026] [security2:error] [pid 358661:tid 358847] [client 103.29.114.44:8577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SBglWhjQfpOo60_HTBAAAADU"]
[Tue Jul 21 08:03:34.009104 2026] [security2:error] [pid 358661:tid 358847] [client 103.29.114.44:8577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SBglWhjQfpOo60_HTBAAAADU"]
[Tue Jul 21 08:03:34.252286 2026] [security2:error] [pid 358661:tid 358850] [client 20.151.10.161:28483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ppp.php"] [unique_id "al9SBglWhjQfpOo60_HTCAAAADg"]
[Tue Jul 21 08:03:34.324668 2026] [security2:error] [pid 352421:tid 352613] [client 20.197.192.193:52262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/abcd.php"] [unique_id "al9SBsJSWzG9jbYOtu5E7gAAAMM"]
[Tue Jul 21 08:03:34.455801 2026] [security2:error] [pid 352421:tid 352623] [client 20.197.192.193:56793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/phpinfo.php1"] [unique_id "al9SBsJSWzG9jbYOtu5E8gAAAM0"]
[Tue Jul 21 08:03:34.694148 2026] [security2:error] [pid 358661:tid 358838] [client 20.151.10.161:28255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/201.php"] [unique_id "al9SBglWhjQfpOo60_HTCwAAACw"]
[Tue Jul 21 08:03:34.694737 2026] [security2:error] [pid 352421:tid 352430] [remote 167.71.218.184:34744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-login.php"] [unique_id "al9SBsJSWzG9jbYOtu5E9gAA3Qg"]
[Tue Jul 21 08:03:35.124171 2026] [security2:error] [pid 358661:tid 358877] [client 20.151.10.161:28225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ops.php"] [unique_id "al9SBwlWhjQfpOo60_HTFAAAAFM"]
[Tue Jul 21 08:03:35.283889 2026] [security2:error] [pid 358661:tid 358864] [client 20.197.195.24:58494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/dex.php"] [unique_id "al9SBwlWhjQfpOo60_HTGgAAAEY"]
[Tue Jul 21 08:03:35.845269 2026] [security2:error] [pid 358661:tid 358847] [client 20.151.10.161:28481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ingfo.php"] [unique_id "al9SBwlWhjQfpOo60_HTLwAAADU"]
[Tue Jul 21 08:03:36.025867 2026] [security2:error] [pid 358661:tid 358794] [client 193.36.225.69:62937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SCAlWhjQfpOo60_HTQQAAAAA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:03:36.241030 2026] [security2:error] [pid 358661:tid 358911] [client 92.119.178.3:47774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9SCAlWhjQfpOo60_HTQwAAAHU"]
[Tue Jul 21 08:03:36.241158 2026] [security2:error] [pid 358661:tid 358911] [client 92.119.178.3:47774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9SCAlWhjQfpOo60_HTQwAAAHU"]
[Tue Jul 21 08:03:36.245474 2026] [security2:error] [pid 358661:tid 358814] [client 109.60.28.94:59314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCAlWhjQfpOo60_HTRAAAABQ"]
[Tue Jul 21 08:03:36.245738 2026] [security2:error] [pid 358661:tid 358814] [client 109.60.28.94:59314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCAlWhjQfpOo60_HTRAAAABQ"]
[Tue Jul 21 08:03:36.632368 2026] [security2:error] [pid 352421:tid 352610] [client 178.153.91.96:51984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SCMJSWzG9jbYOtu5FIAAAAMA"]
[Tue Jul 21 08:03:36.632490 2026] [security2:error] [pid 352421:tid 352610] [client 178.153.91.96:51984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SCMJSWzG9jbYOtu5FIAAAAMA"]
[Tue Jul 21 08:03:36.841129 2026] [security2:error] [pid 358661:tid 358757] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SCAlWhjQfpOo60_HTTQAAZlw"]
[Tue Jul 21 08:03:36.841351 2026] [security2:error] [pid 358661:tid 358896] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SCAlWhjQfpOo60_HTTQAAZlw"]
[Tue Jul 21 08:03:37.160108 2026] [security2:error] [pid 358661:tid 358894] [client 103.166.103.129:55260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SCQlWhjQfpOo60_HTUAAAAGQ"]
[Tue Jul 21 08:03:37.160529 2026] [security2:error] [pid 358661:tid 358894] [client 103.166.103.129:55260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SCQlWhjQfpOo60_HTUAAAAGQ"]
[Tue Jul 21 08:03:37.294330 2026] [security2:error] [pid 358661:tid 358845] [client 20.104.96.117:46717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/rithin.php"] [unique_id "al9SCQlWhjQfpOo60_HTVwAAADM"]
[Tue Jul 21 08:03:37.316560 2026] [security2:error] [pid 352421:tid 352596] [client 117.210.135.0:60274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCcJSWzG9jbYOtu5FOQAAALI"]
[Tue Jul 21 08:03:37.317142 2026] [security2:error] [pid 352421:tid 352596] [client 117.210.135.0:60274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCcJSWzG9jbYOtu5FOQAAALI"]
[Tue Jul 21 08:03:37.373857 2026] [security2:error] [pid 358661:tid 358696] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCQlWhjQfpOo60_HTWQAATx8"]
[Tue Jul 21 08:03:37.374017 2026] [security2:error] [pid 358661:tid 358873] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCQlWhjQfpOo60_HTWQAATx8"]
[Tue Jul 21 08:03:37.620549 2026] [security2:error] [pid 352421:tid 352636] [client 122.179.91.63:22266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SCcJSWzG9jbYOtu5FPQAAANo"]
[Tue Jul 21 08:03:37.620729 2026] [security2:error] [pid 352421:tid 352636] [client 122.179.91.63:22266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SCcJSWzG9jbYOtu5FPQAAANo"]
[Tue Jul 21 08:03:37.704695 2026] [security2:error] [pid 358661:tid 358875] [client 20.197.195.24:58976] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "meuflatnapraia.com.br"] [uri "/1.php"] [unique_id "al9SCQlWhjQfpOo60_HTXQAAAFE"]
[Tue Jul 21 08:03:37.704827 2026] [security2:error] [pid 358661:tid 358875] [client 20.197.195.24:58976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/1.php"] [unique_id "al9SCQlWhjQfpOo60_HTXQAAAFE"]
[Tue Jul 21 08:03:37.784079 2026] [security2:error] [pid 352421:tid 352642] [client 20.29.126.15:11924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/classwithtostring.php"] [unique_id "al9SCcJSWzG9jbYOtu5FQwAAAOA"]
[Tue Jul 21 08:03:37.889106 2026] [security2:error] [pid 358661:tid 358856] [client 20.151.10.161:28527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/error_log.php"] [unique_id "al9SCQlWhjQfpOo60_HTYwAAAD4"]
[Tue Jul 21 08:03:38.178268 2026] [security2:error] [pid 358661:tid 358888] [client 20.220.225.223:34265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/kua.php"] [unique_id "al9SCglWhjQfpOo60_HTkgAAAF4"]
[Tue Jul 21 08:03:38.518287 2026] [security2:error] [pid 358661:tid 358899] [client 38.100.221.102:18473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCglWhjQfpOo60_HTlgAAAGk"]
[Tue Jul 21 08:03:38.518443 2026] [security2:error] [pid 358661:tid 358899] [client 38.100.221.102:18473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCglWhjQfpOo60_HTlgAAAGk"]
[Tue Jul 21 08:03:38.559221 2026] [security2:error] [pid 358661:tid 358859] [client 20.104.96.117:27094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/fffm.php"] [unique_id "al9SCglWhjQfpOo60_HTlwAAAEE"]
[Tue Jul 21 08:03:38.645765 2026] [security2:error] [pid 358661:tid 358818] [client 65.21.113.253:41760] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SCglWhjQfpOo60_HTkwAAABg"]
[Tue Jul 21 08:03:38.765774 2026] [security2:error] [pid 358661:tid 358805] [client 41.68.90.219:63869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCglWhjQfpOo60_HTmgAAAAs"]
[Tue Jul 21 08:03:38.765928 2026] [security2:error] [pid 358661:tid 358805] [client 41.68.90.219:63869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCglWhjQfpOo60_HTmgAAAAs"]
[Tue Jul 21 08:03:38.816980 2026] [security2:error] [pid 352421:tid 352589] [client 202.143.127.214:55589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCsJSWzG9jbYOtu5FUwAAAKs"]
[Tue Jul 21 08:03:38.817540 2026] [security2:error] [pid 352421:tid 352589] [client 202.143.127.214:55589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCsJSWzG9jbYOtu5FUwAAAKs"]
[Tue Jul 21 08:03:38.846653 2026] [security2:error] [pid 358661:tid 358751] [remote 65.111.27.104:30387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9SCglWhjQfpOo60_HTnQAALlY"]
[Tue Jul 21 08:03:38.902871 2026] [security2:error] [pid 358661:tid 358809] [client 175.144.82.48:63146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCglWhjQfpOo60_HToAAAAA8"]
[Tue Jul 21 08:03:38.903930 2026] [security2:error] [pid 358661:tid 358809] [client 175.144.82.48:63146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCglWhjQfpOo60_HToAAAAA8"]
[Tue Jul 21 08:03:38.913500 2026] [security2:error] [pid 358661:tid 358808] [client 20.197.195.24:2851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/ms.php"] [unique_id "al9SCglWhjQfpOo60_HToQAAAA4"]
[Tue Jul 21 08:03:38.982496 2026] [security2:error] [pid 352421:tid 352576] [client 20.197.192.193:52266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/xyn.php"] [unique_id "al9SCsJSWzG9jbYOtu5FVwAAAJ4"]
[Tue Jul 21 08:03:39.041431 2026] [security2:error] [pid 352421:tid 352450] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SC8JSWzG9jbYOtu5FWQAAphw"]
[Tue Jul 21 08:03:39.041625 2026] [security2:error] [pid 352421:tid 352584] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SC8JSWzG9jbYOtu5FWQAAphw"]
[Tue Jul 21 08:03:39.090576 2026] [security2:error] [pid 352421:tid 352443] [remote 74.7.243.219:55334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autoq.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SCcJSWzG9jbYOtu5FQgABBBU"], referer: https://autoq.com.br/
[Tue Jul 21 08:03:39.346313 2026] [autoindex:error] [pid 352421:tid 352630] [client 20.197.195.24:2841] AH01276: Cannot serve directory /home1/meufla20/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:03:39.356510 2026] [security2:error] [pid 352421:tid 352608] [client 20.197.195.24:2841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/memberfuns.php"] [unique_id "al9SC8JSWzG9jbYOtu5FZAAAAL4"]
[Tue Jul 21 08:03:39.981137 2026] [security2:error] [pid 358661:tid 358891] [client 20.220.225.223:34302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/ez.php"] [unique_id "al9SCwlWhjQfpOo60_HTswAAAGE"]
[Tue Jul 21 08:03:40.050109 2026] [security2:error] [pid 358661:tid 358867] [client 172.245.102.45:24603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.102.245.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SDAlWhjQfpOo60_HTtwAAAEk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:03:40.358912 2026] [security2:error] [pid 352421:tid 352451] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SDMJSWzG9jbYOtu5FcgAArR0"]
[Tue Jul 21 08:03:40.359025 2026] [security2:error] [pid 352421:tid 352591] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SDMJSWzG9jbYOtu5FcgAArR0"]
[Tue Jul 21 08:03:40.605283 2026] [security2:error] [pid 358661:tid 358796] [client 20.197.195.24:59005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/0.php"] [unique_id "al9SDAlWhjQfpOo60_HTvgAAAAI"]
[Tue Jul 21 08:03:40.640621 2026] [security2:error] [pid 352421:tid 352424] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SDMJSWzG9jbYOtu5FeAAA6AI"]
[Tue Jul 21 08:03:40.640796 2026] [security2:error] [pid 352421:tid 352650] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SDMJSWzG9jbYOtu5FeAAA6AI"]
[Tue Jul 21 08:03:40.685302 2026] [security2:error] [pid 358661:tid 358809] [client 20.29.126.15:2610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/bless.php"] [unique_id "al9SDAlWhjQfpOo60_HTvwAAAA8"]
[Tue Jul 21 08:03:40.819014 2026] [security2:error] [pid 358661:tid 358855] [client 20.151.10.161:28249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/xenon1337.php"] [unique_id "al9SDAlWhjQfpOo60_HTxQAAAD0"]
[Tue Jul 21 08:03:40.900270 2026] [security2:error] [pid 358661:tid 358835] [client 103.76.88.36:59721] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "anjosolar.com.br"] [uri "/.env"] [unique_id "al9SDAlWhjQfpOo60_HTyQAAACk"]
[Tue Jul 21 08:03:41.106734 2026] [security2:error] [pid 352421:tid 352579] [client 120.56.162.40:64084] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SDMJSWzG9jbYOtu5FfwAAAKE"]
[Tue Jul 21 08:03:41.106882 2026] [security2:error] [pid 352421:tid 352579] [client 120.56.162.40:64084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SDMJSWzG9jbYOtu5FfwAAAKE"]
[Tue Jul 21 08:03:41.120980 2026] [security2:error] [pid 352421:tid 352565] [client 20.220.225.223:34188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/fz.php"] [unique_id "al9SDcJSWzG9jbYOtu5FgwAAAJM"]
[Tue Jul 21 08:03:41.144235 2026] [security2:error] [pid 352421:tid 352578] [client 20.197.192.193:52253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/byp8.php"] [unique_id "al9SDcJSWzG9jbYOtu5FhAAAAKA"]
[Tue Jul 21 08:03:41.169899 2026] [security2:error] [pid 352421:tid 352448] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SDcJSWzG9jbYOtu5FhgAA0xo"]
[Tue Jul 21 08:03:41.170083 2026] [security2:error] [pid 352421:tid 352629] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SDcJSWzG9jbYOtu5FhgAA0xo"]
[Tue Jul 21 08:03:41.268746 2026] [security2:error] [pid 358661:tid 358802] [client 18.192.166.72:15066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9SDQlWhjQfpOo60_HT0AAAAAg"], referer: https://artetoner.com.br
[Tue Jul 21 08:03:41.543824 2026] [security2:error] [pid 358661:tid 358896] [client 74.7.175.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.lp.oticapersona.com.br"] [uri "/index.php"] [unique_id "al9SDAlWhjQfpOo60_HTwwAAAGY"]
[Tue Jul 21 08:03:41.544487 2026] [security2:error] [pid 352421:tid 352638] [client 74.7.175.158:38600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.lp.oticapersona.com.br"] [uri "/robots.txt"] [unique_id "al9SDMJSWzG9jbYOtu5FeQAA3EA"]
[Tue Jul 21 08:03:41.811881 2026] [security2:error] [pid 358661:tid 358667] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SDQlWhjQfpOo60_HT1AAAYwI"]
[Tue Jul 21 08:03:41.812082 2026] [security2:error] [pid 358661:tid 358893] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SDQlWhjQfpOo60_HT1AAAYwI"]
[Tue Jul 21 08:03:41.814006 2026] [security2:error] [pid 352421:tid 352646] [client 216.73.160.191:52983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9SDcJSWzG9jbYOtu5FkQAAAOQ"]
[Tue Jul 21 08:03:41.814700 2026] [security2:error] [pid 358661:tid 358797] [client 216.73.160.24:47523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9SDQlWhjQfpOo60_HT0wAAAAM"]
[Tue Jul 21 08:03:41.816158 2026] [security2:error] [pid 352421:tid 352641] [client 216.73.160.186:49851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9SDcJSWzG9jbYOtu5FkgAAAN8"]
[Tue Jul 21 08:03:41.977386 2026] [security2:error] [pid 358661:tid 358918] [client 216.73.160.178:43735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9SDQlWhjQfpOo60_HT1QAAAHw"]
[Tue Jul 21 08:03:42.059386 2026] [security2:error] [pid 358661:tid 358875] [client 65.21.113.253:41760] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SDQlWhjQfpOo60_HT2AAAAFE"]
[Tue Jul 21 08:03:42.077108 2026] [security2:error] [pid 352421:tid 352499] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SDsJSWzG9jbYOtu5FmwAAsU0"]
[Tue Jul 21 08:03:42.077275 2026] [security2:error] [pid 352421:tid 352595] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SDsJSWzG9jbYOtu5FmwAAsU0"]
[Tue Jul 21 08:03:42.186012 2026] [security2:error] [pid 352421:tid 352652] [client 20.197.195.24:2826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/BDKR28.php"] [unique_id "al9SDsJSWzG9jbYOtu5FngAAAOo"]
[Tue Jul 21 08:03:42.192742 2026] [security2:error] [pid 352421:tid 352600] [client 20.104.96.117:46604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/dfre.php"] [unique_id "al9SDsJSWzG9jbYOtu5FnwAAALY"]
[Tue Jul 21 08:03:42.241336 2026] [security2:error] [pid 352421:tid 352563] [client 74.7.175.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lp.oticapersona.com.br"] [uri "/index.php"] [unique_id "al9SDsJSWzG9jbYOtu5FnQAAAJE"], referer: https://www.lp.oticapersona.com.br/robots.txt
[Tue Jul 21 08:03:42.242076 2026] [security2:error] [pid 352421:tid 352678] [client 74.7.175.158:39638] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lp.oticapersona.com.br"] [uri "/robots.txt"] [unique_id "al9SDsJSWzG9jbYOtu5FnAABBHg"], referer: https://www.lp.oticapersona.com.br/robots.txt
[Tue Jul 21 08:03:42.395109 2026] [security2:error] [pid 358661:tid 358891] [client 184.75.221.3:44320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9SDglWhjQfpOo60_HT2gAAAGE"]
[Tue Jul 21 08:03:42.395196 2026] [security2:error] [pid 358661:tid 358891] [client 184.75.221.3:44320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9SDglWhjQfpOo60_HT2gAAAGE"]
[Tue Jul 21 08:03:42.594696 2026] [security2:error] [pid 358661:tid 358811] [client 198.54.128.138:52538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9SDglWhjQfpOo60_HT3QAAABE"]
[Tue Jul 21 08:03:42.594799 2026] [security2:error] [pid 358661:tid 358811] [client 198.54.128.138:52538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9SDglWhjQfpOo60_HT3QAAABE"]
[Tue Jul 21 08:03:42.645287 2026] [security2:error] [pid 358661:tid 358853] [client 20.29.126.15:11907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/storage/index.php"] [unique_id "al9SDglWhjQfpOo60_HT4AAAADs"]
[Tue Jul 21 08:03:42.840597 2026] [security2:error] [pid 352421:tid 352645] [client 20.197.192.193:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/user.php"] [unique_id "al9SDsJSWzG9jbYOtu5FqQAAAOM"]
[Tue Jul 21 08:03:42.851981 2026] [security2:error] [pid 352421:tid 352618] [client 20.197.195.24:24166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/green1.php"] [unique_id "al9SDsJSWzG9jbYOtu5FqgAAAMg"]
[Tue Jul 21 08:03:43.001392 2026] [security2:error] [pid 352421:tid 352580] [client 106.215.181.8:32099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SD8JSWzG9jbYOtu5FrwAAAKI"]
[Tue Jul 21 08:03:43.001501 2026] [security2:error] [pid 352421:tid 352580] [client 106.215.181.8:32099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SD8JSWzG9jbYOtu5FrwAAAKI"]
[Tue Jul 21 08:03:43.348127 2026] [security2:error] [pid 358661:tid 358833] [client 102.206.115.33:58731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SDwlWhjQfpOo60_HT5QAAACc"]
[Tue Jul 21 08:03:43.348297 2026] [security2:error] [pid 358661:tid 358833] [client 102.206.115.33:58731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SDwlWhjQfpOo60_HT5QAAACc"]
[Tue Jul 21 08:03:43.421117 2026] [security2:error] [pid 358661:tid 358821] [client 20.197.195.24:58972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/nc4.php"] [unique_id "al9SDwlWhjQfpOo60_HT5wAAABs"]
[Tue Jul 21 08:03:43.588321 2026] [security2:error] [pid 358661:tid 358877] [client 151.63.71.144:58635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9SDwlWhjQfpOo60_HT6AAAAFM"]
[Tue Jul 21 08:03:43.588496 2026] [security2:error] [pid 358661:tid 358877] [client 151.63.71.144:58635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9SDwlWhjQfpOo60_HT6AAAAFM"]
[Tue Jul 21 08:03:43.669078 2026] [security2:error] [pid 352421:tid 352626] [client 20.197.195.24:24112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/a1.php"] [unique_id "al9SD8JSWzG9jbYOtu5FugAAANA"]
[Tue Jul 21 08:03:43.753690 2026] [security2:error] [pid 358661:tid 358736] [remote 119.195.102.159:42820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9SDwlWhjQfpOo60_HT7gAALEc"]
[Tue Jul 21 08:03:43.805840 2026] [security2:error] [pid 352421:tid 352663] [client 20.197.195.24:24092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/eee.php"] [unique_id "al9SD8JSWzG9jbYOtu5FwAAAAPU"]
[Tue Jul 21 08:03:43.942210 2026] [security2:error] [pid 358661:tid 358807] [client 87.116.180.198:13874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SDwlWhjQfpOo60_HT7wAAAA0"]
[Tue Jul 21 08:03:43.943242 2026] [security2:error] [pid 358661:tid 358807] [client 87.116.180.198:13874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SDwlWhjQfpOo60_HT7wAAAA0"]
[Tue Jul 21 08:03:43.972946 2026] [security2:error] [pid 352421:tid 352630] [client 65.21.232.200:46187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.232.21.65.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-comments-post.php"] [unique_id "al9SDsJSWzG9jbYOtu5FqAAAANQ"], referer: https://valloratoodo.com/hello-world/#comment-6729
[Tue Jul 21 08:03:43.973051 2026] [security2:error] [pid 352421:tid 352630] [client 65.21.232.200:46187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "valloratoodo.com"] [uri "/wp-comments-post.php"] [unique_id "al9SDsJSWzG9jbYOtu5FqAAAANQ"], referer: https://valloratoodo.com/hello-world/#comment-6729
[Tue Jul 21 08:03:44.020746 2026] [security2:error] [pid 358661:tid 358796] [client 103.78.200.11:56473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SEAlWhjQfpOo60_HT8gAAAAI"]
[Tue Jul 21 08:03:44.020885 2026] [security2:error] [pid 358661:tid 358796] [client 103.78.200.11:56473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SEAlWhjQfpOo60_HT8gAAAAI"]
[Tue Jul 21 08:03:44.060435 2026] [security2:error] [pid 352421:tid 352567] [client 20.197.195.24:58964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-aothait.php"] [unique_id "al9SEMJSWzG9jbYOtu5FxAAAAJU"]
[Tue Jul 21 08:03:44.135165 2026] [security2:error] [pid 352421:tid 352665] [client 20.197.195.24:2917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/config.json.php"] [unique_id "al9SEMJSWzG9jbYOtu5FxwAAAPc"]
[Tue Jul 21 08:03:44.265058 2026] [security2:error] [pid 352421:tid 352622] [client 182.8.255.181:17520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SEMJSWzG9jbYOtu5FyAAAAMw"]
[Tue Jul 21 08:03:44.265224 2026] [security2:error] [pid 352421:tid 352622] [client 182.8.255.181:17520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SEMJSWzG9jbYOtu5FyAAAAMw"]
[Tue Jul 21 08:03:44.310902 2026] [security2:error] [pid 358661:tid 358872] [client 20.197.195.24:24164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9SEAlWhjQfpOo60_HT-wAAAE4"]
[Tue Jul 21 08:03:44.549035 2026] [security2:error] [pid 358661:tid 358911] [client 193.36.225.55:49285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SEAlWhjQfpOo60_HT_AAAAHU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:03:44.657991 2026] [security2:error] [pid 358661:tid 358915] [client 103.29.114.44:34214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SEAlWhjQfpOo60_HT_wAAAHk"]
[Tue Jul 21 08:03:44.658105 2026] [security2:error] [pid 358661:tid 358915] [client 103.29.114.44:34214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SEAlWhjQfpOo60_HT_wAAAHk"]
[Tue Jul 21 08:03:44.804232 2026] [security2:error] [pid 352421:tid 352648] [client 117.247.80.59:21620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SEMJSWzG9jbYOtu5F0gAAAOY"]
[Tue Jul 21 08:03:44.804363 2026] [security2:error] [pid 352421:tid 352648] [client 117.247.80.59:21620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SEMJSWzG9jbYOtu5F0gAAAOY"]
[Tue Jul 21 08:03:44.959470 2026] [security2:error] [pid 358661:tid 358893] [client 20.197.195.24:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/k2.php"] [unique_id "al9SEAlWhjQfpOo60_HUAgAAAGM"]
[Tue Jul 21 08:03:45.222954 2026] [security2:error] [pid 358661:tid 358836] [client 20.151.10.161:28048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/test11.php"] [unique_id "al9SEQlWhjQfpOo60_HUBAAAACo"]
[Tue Jul 21 08:03:45.427920 2026] [security2:error] [pid 358661:tid 358885] [client 20.197.195.24:2932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9SEQlWhjQfpOo60_HUBQAAAFs"]
[Tue Jul 21 08:03:45.700567 2026] [security2:error] [pid 358661:tid 358891] [client 173.252.95.41:39472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9SEQlWhjQfpOo60_HUCwAAAGE"]
[Tue Jul 21 08:03:45.885517 2026] [security2:error] [pid 358661:tid 358837] [client 20.104.96.117:27534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/wp-happy.php"] [unique_id "al9SEQlWhjQfpOo60_HUDQAAACs"]
[Tue Jul 21 08:03:46.087219 2026] [security2:error] [pid 358661:tid 358805] [client 20.220.225.223:34210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/la.php"] [unique_id "al9SEglWhjQfpOo60_HUEQAAAAs"]
[Tue Jul 21 08:03:46.169352 2026] [security2:error] [pid 358661:tid 358809] [client 20.197.195.24:2853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9SEglWhjQfpOo60_HUFgAAAA8"]
[Tue Jul 21 08:03:46.776656 2026] [security2:error] [pid 358661:tid 358861] [client 20.197.195.24:58991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9SEglWhjQfpOo60_HUHwAAAEM"]
[Tue Jul 21 08:03:46.989261 2026] [security2:error] [pid 352421:tid 352482] [remote 65.111.29.52:33573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.29.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9SEsJSWzG9jbYOtu5F8gAAsjw"]
[Tue Jul 21 08:03:47.073315 2026] [security2:error] [pid 358661:tid 358827] [client 34.182.229.158:51114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9SEwlWhjQfpOo60_HUJgAAACE"]
[Tue Jul 21 08:03:47.117076 2026] [security2:error] [pid 358661:tid 358796] [client 109.60.28.94:64722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SEwlWhjQfpOo60_HUKAAAAAI"]
[Tue Jul 21 08:03:47.117246 2026] [security2:error] [pid 358661:tid 358796] [client 109.60.28.94:64722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SEwlWhjQfpOo60_HUKAAAAAI"]
[Tue Jul 21 08:03:47.160897 2026] [security2:error] [pid 358661:tid 358854] [client 20.197.192.193:52251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/ops.php"] [unique_id "al9SEwlWhjQfpOo60_HUKQAAADw"]
[Tue Jul 21 08:03:47.172194 2026] [security2:error] [pid 358661:tid 358903] [client 178.153.91.96:29969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SEwlWhjQfpOo60_HUKgAAAG0"]
[Tue Jul 21 08:03:47.172300 2026] [security2:error] [pid 358661:tid 358903] [client 178.153.91.96:29969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SEwlWhjQfpOo60_HUKgAAAG0"]
[Tue Jul 21 08:03:47.297285 2026] [security2:error] [pid 352421:tid 352436] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SE8JSWzG9jbYOtu5F-AABAA4"]
[Tue Jul 21 08:03:47.297425 2026] [security2:error] [pid 352421:tid 352674] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SE8JSWzG9jbYOtu5F-AABAA4"]
[Tue Jul 21 08:03:47.477485 2026] [security2:error] [pid 358661:tid 358875] [client 65.21.113.253:39026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9SEwlWhjQfpOo60_HULwAAAFE"]
[Tue Jul 21 08:03:47.690148 2026] [security2:error] [pid 358661:tid 358811] [client 20.220.225.223:34285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/nhvoanpl.php"] [unique_id "al9SEwlWhjQfpOo60_HUNQAAABE"]
[Tue Jul 21 08:03:47.834545 2026] [security2:error] [pid 352421:tid 352581] [client 20.29.126.15:12043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/g.php"] [unique_id "al9SE8JSWzG9jbYOtu5GAwAAAKM"]
[Tue Jul 21 08:03:47.860496 2026] [security2:error] [pid 358661:tid 358790] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SEwlWhjQfpOo60_HUOgAAdH0"]
[Tue Jul 21 08:03:47.860649 2026] [security2:error] [pid 358661:tid 358910] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SEwlWhjQfpOo60_HUOgAAdH0"]
[Tue Jul 21 08:03:47.867191 2026] [security2:error] [pid 358661:tid 358864] [client 117.210.135.0:60982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SEwlWhjQfpOo60_HUPAAAAEY"]
[Tue Jul 21 08:03:47.867312 2026] [security2:error] [pid 358661:tid 358864] [client 117.210.135.0:60982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SEwlWhjQfpOo60_HUPAAAAEY"]
[Tue Jul 21 08:03:47.990782 2026] [security2:error] [pid 352421:tid 352587] [client 74.7.244.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "jurandirdasilvafigue1777856535000.0711679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9SE8JSWzG9jbYOtu5GCQAAqVg"]
[Tue Jul 21 08:03:48.012171 2026] [security2:error] [pid 358661:tid 358911] [client 103.166.103.129:55790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SFAlWhjQfpOo60_HUQAAAAHU"]
[Tue Jul 21 08:03:48.012351 2026] [security2:error] [pid 358661:tid 358911] [client 103.166.103.129:55790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SFAlWhjQfpOo60_HUQAAAAHU"]
[Tue Jul 21 08:03:48.208382 2026] [security2:error] [pid 358661:tid 358878] [client 20.197.195.24:58474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/for.php"] [unique_id "al9SFAlWhjQfpOo60_HURgAAAFQ"]
[Tue Jul 21 08:03:48.254462 2026] [security2:error] [pid 358661:tid 358885] [client 122.179.91.63:9831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SFAlWhjQfpOo60_HUSQAAAFs"]
[Tue Jul 21 08:03:48.254582 2026] [security2:error] [pid 358661:tid 358885] [client 122.179.91.63:9831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SFAlWhjQfpOo60_HUSQAAAFs"]
[Tue Jul 21 08:03:48.309754 2026] [security2:error] [pid 352421:tid 352609] [client 65.21.113.253:56728] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SFMJSWzG9jbYOtu5GDAAAAL8"]
[Tue Jul 21 08:03:48.415532 2026] [security2:error] [pid 352421:tid 352611] [client 20.220.225.223:34194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/inso.php"] [unique_id "al9SFMJSWzG9jbYOtu5GFQAAAME"]
[Tue Jul 21 08:03:48.762357 2026] [security2:error] [pid 358661:tid 358845] [client 65.21.113.253:39032] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SFAlWhjQfpOo60_HUTgAAADM"]
[Tue Jul 21 08:03:48.803990 2026] [security2:error] [pid 352421:tid 352604] [client 92.119.178.3:36702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SFMJSWzG9jbYOtu5GHAAAALo"]
[Tue Jul 21 08:03:48.804083 2026] [security2:error] [pid 352421:tid 352604] [client 92.119.178.3:36702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SFMJSWzG9jbYOtu5GHAAAALo"]
[Tue Jul 21 08:03:49.049918 2026] [security2:error] [pid 358661:tid 358890] [client 20.220.225.223:34254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wpx.php"] [unique_id "al9SFQlWhjQfpOo60_HUUQAAAGA"]
[Tue Jul 21 08:03:49.067687 2026] [security2:error] [pid 358661:tid 358826] [client 20.197.195.24:2907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/raw.php"] [unique_id "al9SFQlWhjQfpOo60_HUUgAAACA"]
[Tue Jul 21 08:03:49.105673 2026] [security2:error] [pid 358661:tid 358858] [client 193.36.225.72:21817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SFQlWhjQfpOo60_HUUwAAAEA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:03:49.270315 2026] [access_compat:error] [pid 352421:tid 352594] [client 173.252.95.2:0] AH01797: client denied by server configuration: /home4/fabi0417/powerflats.com.br/index.php4
[Tue Jul 21 08:03:49.473687 2026] [security2:error] [pid 358661:tid 358830] [client 175.144.82.48:63583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SFQlWhjQfpOo60_HUYAAAACQ"]
[Tue Jul 21 08:03:49.474303 2026] [security2:error] [pid 358661:tid 358830] [client 175.144.82.48:63583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SFQlWhjQfpOo60_HUYAAAACQ"]
[Tue Jul 21 08:03:49.628068 2026] [security2:error] [pid 358661:tid 358713] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SFQlWhjQfpOo60_HUYQAARjA"]
[Tue Jul 21 08:03:49.628244 2026] [security2:error] [pid 358661:tid 358864] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SFQlWhjQfpOo60_HUYQAARjA"]
[Tue Jul 21 08:03:49.813690 2026] [security2:error] [pid 358661:tid 358818] [client 20.29.126.15:4265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/nf.php"] [unique_id "al9SFQlWhjQfpOo60_HUZwAAABg"]
[Tue Jul 21 08:03:49.846421 2026] [security2:error] [pid 358661:tid 358903] [client 65.21.113.253:37162] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SFQlWhjQfpOo60_HUXgAAAG0"]
[Tue Jul 21 08:03:49.906217 2026] [security2:error] [pid 352421:tid 352620] [client 38.100.221.102:18396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SFcJSWzG9jbYOtu5GNAAAAMo"]
[Tue Jul 21 08:03:49.906389 2026] [security2:error] [pid 352421:tid 352620] [client 38.100.221.102:18396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SFcJSWzG9jbYOtu5GNAAAAMo"]
[Tue Jul 21 08:03:49.938219 2026] [security2:error] [pid 358661:tid 358836] [client 41.68.90.219:64337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SFQlWhjQfpOo60_HUagAAACo"]
[Tue Jul 21 08:03:49.939121 2026] [security2:error] [pid 358661:tid 358836] [client 41.68.90.219:64337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SFQlWhjQfpOo60_HUagAAACo"]
[Tue Jul 21 08:03:49.979077 2026] [security2:error] [pid 358661:tid 358879] [client 202.143.127.214:56069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SFQlWhjQfpOo60_HUbAAAAFU"]
[Tue Jul 21 08:03:49.979775 2026] [security2:error] [pid 358661:tid 358879] [client 202.143.127.214:56069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SFQlWhjQfpOo60_HUbAAAAFU"]
[Tue Jul 21 08:03:50.116953 2026] [security2:error] [pid 358661:tid 358815] [client 20.220.225.223:34180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/berlin.php"] [unique_id "al9SFglWhjQfpOo60_HUbQAAABU"]
[Tue Jul 21 08:03:50.153865 2026] [security2:error] [pid 352421:tid 352640] [client 34.182.229.158:57226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cezaretto.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SFcJSWzG9jbYOtu5GOAAAAN4"]
[Tue Jul 21 08:03:50.597109 2026] [access_compat:error] [pid 352421:tid 352646] [client 173.252.95.62:0] AH01797: client denied by server configuration: /home4/fabi0417/powerflats.com.br/index.php4
[Tue Jul 21 08:03:50.697023 2026] [security2:error] [pid 352421:tid 352587] [client 20.104.96.117:46704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/fpr4.php"] [unique_id "al9SFsJSWzG9jbYOtu5GSQAAAKk"]
[Tue Jul 21 08:03:50.708165 2026] [security2:error] [pid 358661:tid 358913] [client 198.54.128.138:53540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SFglWhjQfpOo60_HUdgAAAHc"]
[Tue Jul 21 08:03:50.708291 2026] [security2:error] [pid 358661:tid 358913] [client 198.54.128.138:53540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SFglWhjQfpOo60_HUdgAAAHc"]
[Tue Jul 21 08:03:51.249544 2026] [security2:error] [pid 358661:tid 358770] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SFwlWhjQfpOo60_HUfQAABmk"]
[Tue Jul 21 08:03:51.249709 2026] [security2:error] [pid 358661:tid 358800] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SFwlWhjQfpOo60_HUfQAABmk"]
[Tue Jul 21 08:03:51.327563 2026] [security2:error] [pid 358661:tid 358753] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SFwlWhjQfpOo60_HUggAAP1g"]
[Tue Jul 21 08:03:51.327743 2026] [security2:error] [pid 358661:tid 358857] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SFwlWhjQfpOo60_HUggAAP1g"]
[Tue Jul 21 08:03:51.548284 2026] [security2:error] [pid 352421:tid 352589] [client 92.119.178.3:55694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9SF8JSWzG9jbYOtu5GWgAAAKs"]
[Tue Jul 21 08:03:51.548411 2026] [security2:error] [pid 352421:tid 352589] [client 92.119.178.3:55694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9SF8JSWzG9jbYOtu5GWgAAAKs"]
[Tue Jul 21 08:03:51.555060 2026] [security2:error] [pid 352421:tid 352652] [client 20.151.10.161:28560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/koala.php"] [unique_id "al9SF8JSWzG9jbYOtu5GWwAAAOo"]
[Tue Jul 21 08:03:51.646754 2026] [security2:error] [pid 358661:tid 358883] [client 120.56.162.40:64534] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SFwlWhjQfpOo60_HUhgAAAFk"]
[Tue Jul 21 08:03:51.646913 2026] [security2:error] [pid 358661:tid 358883] [client 120.56.162.40:64534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SFwlWhjQfpOo60_HUhgAAAFk"]
[Tue Jul 21 08:03:51.790572 2026] [security2:error] [pid 352421:tid 352515] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SF8JSWzG9jbYOtu5GXwAA210"]
[Tue Jul 21 08:03:51.790743 2026] [security2:error] [pid 352421:tid 352637] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SF8JSWzG9jbYOtu5GXwAA210"]
[Tue Jul 21 08:03:52.176906 2026] [security2:error] [pid 358661:tid 358871] [client 20.220.225.223:34184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/billur.php"] [unique_id "al9SGAlWhjQfpOo60_HUjAAAAE0"]
[Tue Jul 21 08:03:52.528033 2026] [security2:error] [pid 358661:tid 358677] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SGAlWhjQfpOo60_HUkAAAJAw"]
[Tue Jul 21 08:03:52.528181 2026] [security2:error] [pid 358661:tid 358830] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SGAlWhjQfpOo60_HUkAAAJAw"]
[Tue Jul 21 08:03:52.741222 2026] [security2:error] [pid 358661:tid 358797] [client 20.29.126.15:19150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/xda.php"] [unique_id "al9SGAlWhjQfpOo60_HUlQAAAAM"]
[Tue Jul 21 08:03:52.885986 2026] [security2:error] [pid 358661:tid 358702] [remote 97.74.87.194:33116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bellascleaningsolutionsllc.com"] [uri "/wp-login.php"] [unique_id "al9SGAlWhjQfpOo60_HUlwAAEiU"]
[Tue Jul 21 08:03:53.007476 2026] [security2:error] [pid 352421:tid 352674] [client 20.220.225.223:34202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/mimpi.php"] [unique_id "al9SGcJSWzG9jbYOtu5GeQAAAQA"]
[Tue Jul 21 08:03:53.025105 2026] [security2:error] [pid 352421:tid 352538] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SGcJSWzG9jbYOtu5GegAA3XQ"]
[Tue Jul 21 08:03:53.025235 2026] [security2:error] [pid 352421:tid 352639] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SGcJSWzG9jbYOtu5GegAA3XQ"]
[Tue Jul 21 08:03:53.090647 2026] [security2:error] [pid 358661:tid 358865] [client 45.8.19.154:60839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luanaarruda.com"] [uri "/wp-login.php"] [unique_id "al9SGQlWhjQfpOo60_HUmwAAAEc"]
[Tue Jul 21 08:03:53.497227 2026] [security2:error] [pid 352421:tid 352653] [client 106.215.181.8:16146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SGcJSWzG9jbYOtu5GgwAAAOs"]
[Tue Jul 21 08:03:53.501275 2026] [security2:error] [pid 352421:tid 352653] [client 106.215.181.8:16146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SGcJSWzG9jbYOtu5GgwAAAOs"]
[Tue Jul 21 08:03:53.676929 2026] [security2:error] [pid 358661:tid 358800] [client 74.7.244.38:33226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "psooffshore.com.br"] [uri "/index.php"] [unique_id "al9SGQlWhjQfpOo60_HUqgAABnA"]
[Tue Jul 21 08:03:53.728264 2026] [security2:error] [pid 352421:tid 352618] [client 20.220.225.223:34177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/dp.php"] [unique_id "al9SGcJSWzG9jbYOtu5GiAAAAMg"]
[Tue Jul 21 08:03:53.851006 2026] [security2:error] [pid 358661:tid 358841] [client 102.206.115.33:58452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SGQlWhjQfpOo60_HUrwAAAC8"]
[Tue Jul 21 08:03:53.851149 2026] [security2:error] [pid 358661:tid 358841] [client 102.206.115.33:58452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SGQlWhjQfpOo60_HUrwAAAC8"]
[Tue Jul 21 08:03:53.869370 2026] [security2:error] [pid 352421:tid 352615] [client 136.144.33.106:55679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SGcJSWzG9jbYOtu5GhgAAAMU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:03:54.577290 2026] [security2:error] [pid 358661:tid 358917] [client 87.116.180.198:27240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SGglWhjQfpOo60_HUugAAAHs"]
[Tue Jul 21 08:03:54.577413 2026] [security2:error] [pid 358661:tid 358917] [client 87.116.180.198:27240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SGglWhjQfpOo60_HUugAAAHs"]
[Tue Jul 21 08:03:54.676621 2026] [security2:error] [pid 358661:tid 358799] [client 182.8.255.181:17686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SGglWhjQfpOo60_HUuwAAAAU"]
[Tue Jul 21 08:03:54.676798 2026] [security2:error] [pid 358661:tid 358799] [client 182.8.255.181:17686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SGglWhjQfpOo60_HUuwAAAAU"]
[Tue Jul 21 08:03:54.818830 2026] [security2:error] [pid 352421:tid 352567] [client 103.78.200.11:56958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SGsJSWzG9jbYOtu5GnwAAAJU"]
[Tue Jul 21 08:03:54.818937 2026] [security2:error] [pid 352421:tid 352567] [client 103.78.200.11:56958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SGsJSWzG9jbYOtu5GnwAAAJU"]
[Tue Jul 21 08:03:55.048898 2026] [security2:error] [pid 352421:tid 352605] [client 20.104.96.117:46669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/file88.php"] [unique_id "al9SG8JSWzG9jbYOtu5GpAAAALs"]
[Tue Jul 21 08:03:55.113473 2026] [security2:error] [pid 358661:tid 358901] [client 20.220.225.223:34453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/bootstrap.php"] [unique_id "al9SGwlWhjQfpOo60_HUvgAAAGs"]
[Tue Jul 21 08:03:55.224667 2026] [security2:error] [pid 358661:tid 358825] [client 20.197.192.193:51909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/term.php"] [unique_id "al9SGwlWhjQfpOo60_HUwAAAAB8"]
[Tue Jul 21 08:03:55.496833 2026] [security2:error] [pid 358661:tid 358836] [client 65.21.113.253:53786] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SGwlWhjQfpOo60_HUwgAAACo"]
[Tue Jul 21 08:03:55.638041 2026] [security2:error] [pid 358661:tid 358818] [client 117.247.80.59:25902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SGwlWhjQfpOo60_HUxQAAABg"]
[Tue Jul 21 08:03:55.638229 2026] [security2:error] [pid 358661:tid 358818] [client 117.247.80.59:25902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SGwlWhjQfpOo60_HUxQAAABg"]
[Tue Jul 21 08:03:55.947541 2026] [autoindex:error] [pid 358661:tid 358905] [client 100.50.152.193:8050] AH01276: Cannot serve directory /home4/dralul00/moniquemenezes.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:03:55.998402 2026] [security2:error] [pid 358661:tid 358797] [client 103.29.114.44:37409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SGwlWhjQfpOo60_HUzQAAAAM"]
[Tue Jul 21 08:03:55.998503 2026] [security2:error] [pid 358661:tid 358797] [client 103.29.114.44:37409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SGwlWhjQfpOo60_HUzQAAAAM"]
[Tue Jul 21 08:03:56.234884 2026] [security2:error] [pid 352421:tid 352661] [client 20.151.10.161:28532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/mac.php"] [unique_id "al9SHMJSWzG9jbYOtu5GuwAAAPM"]
[Tue Jul 21 08:03:56.342545 2026] [security2:error] [pid 352421:tid 352578] [client 20.220.225.223:34252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wp-editor.php"] [unique_id "al9SHMJSWzG9jbYOtu5GvQAAAKA"]
[Tue Jul 21 08:03:56.549076 2026] [security2:error] [pid 358661:tid 358848] [client 65.21.113.253:37164] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SHAlWhjQfpOo60_HUzwAAADY"]
[Tue Jul 21 08:03:57.056397 2026] [security2:error] [pid 352421:tid 352675] [client 20.104.96.117:46665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/ccc.php"] [unique_id "al9SHcJSWzG9jbYOtu5GygAAAQE"]
[Tue Jul 21 08:03:57.115187 2026] [security2:error] [pid 358661:tid 358823] [client 20.220.225.223:34250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/cro.php"] [unique_id "al9SHQlWhjQfpOo60_HU2gAAAB0"]
[Tue Jul 21 08:03:57.550750 2026] [security2:error] [pid 352421:tid 352639] [client 193.36.225.55:41001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SHcJSWzG9jbYOtu5GzwAAAN0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:03:57.654049 2026] [security2:error] [pid 358661:tid 358824] [client 178.153.91.96:53234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SHQlWhjQfpOo60_HU4gAAAB4"]
[Tue Jul 21 08:03:57.654192 2026] [security2:error] [pid 358661:tid 358824] [client 178.153.91.96:53234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SHQlWhjQfpOo60_HU4gAAAB4"]
[Tue Jul 21 08:03:57.772697 2026] [security2:error] [pid 352421:tid 352482] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SHcJSWzG9jbYOtu5G1AAArzw"]
[Tue Jul 21 08:03:57.772893 2026] [security2:error] [pid 352421:tid 352593] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SHcJSWzG9jbYOtu5G1AAArzw"]
[Tue Jul 21 08:03:57.863205 2026] [security2:error] [pid 358661:tid 358884] [client 109.60.28.94:65350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SHQlWhjQfpOo60_HU6AAAAFo"]
[Tue Jul 21 08:03:57.863571 2026] [security2:error] [pid 358661:tid 358884] [client 109.60.28.94:65350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SHQlWhjQfpOo60_HU6AAAAFo"]
[Tue Jul 21 08:03:58.149224 2026] [security2:error] [pid 358661:tid 358813] [client 20.104.96.117:46718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/777.php"] [unique_id "al9SHglWhjQfpOo60_HU6gAAABM"]
[Tue Jul 21 08:03:58.293132 2026] [security2:error] [pid 358661:tid 358840] [client 20.220.225.223:34245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/cron-tab.php"] [unique_id "al9SHglWhjQfpOo60_HU7AAAAC4"]
[Tue Jul 21 08:03:58.345434 2026] [security2:error] [pid 358661:tid 358832] [client 117.210.135.0:61681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SHglWhjQfpOo60_HU7QAAACY"]
[Tue Jul 21 08:03:58.345550 2026] [security2:error] [pid 358661:tid 358832] [client 117.210.135.0:61681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SHglWhjQfpOo60_HU7QAAACY"]
[Tue Jul 21 08:03:58.354637 2026] [security2:error] [pid 358661:tid 358707] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SHglWhjQfpOo60_HU7gAAWyo"]
[Tue Jul 21 08:03:58.354828 2026] [security2:error] [pid 358661:tid 358885] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SHglWhjQfpOo60_HU7gAAWyo"]
[Tue Jul 21 08:03:58.541749 2026] [security2:error] [pid 358661:tid 358879] [client 103.166.103.129:18477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SHglWhjQfpOo60_HU8AAAAFU"]
[Tue Jul 21 08:03:58.543608 2026] [security2:error] [pid 358661:tid 358879] [client 103.166.103.129:18477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SHglWhjQfpOo60_HU8AAAAFU"]
[Tue Jul 21 08:03:59.294045 2026] [security2:error] [pid 358661:tid 358850] [client 65.21.113.253:53786] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SHwlWhjQfpOo60_HU9wAAADg"]
[Tue Jul 21 08:03:59.405162 2026] [security2:error] [pid 352421:tid 352611] [client 104.234.53.146:50211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-comments-post.php"] [unique_id "al9SHsJSWzG9jbYOtu5G2wAAAME"], referer: https://valloratoodo.com/hello-world/#comment-1101
[Tue Jul 21 08:03:59.405313 2026] [security2:error] [pid 352421:tid 352611] [client 104.234.53.146:50211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "valloratoodo.com"] [uri "/wp-comments-post.php"] [unique_id "al9SHsJSWzG9jbYOtu5G2wAAAME"], referer: https://valloratoodo.com/hello-world/#comment-1101
[Tue Jul 21 08:03:59.539031 2026] [security2:error] [pid 358661:tid 358921] [client 175.144.82.48:63959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SHwlWhjQfpOo60_HVAAAAAH8"]
[Tue Jul 21 08:03:59.539781 2026] [security2:error] [pid 358661:tid 358921] [client 175.144.82.48:63959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SHwlWhjQfpOo60_HVAAAAAH8"]
[Tue Jul 21 08:03:59.595751 2026] [security2:error] [pid 358661:tid 358810] [client 20.151.10.161:28537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9SHwlWhjQfpOo60_HVAgAAABA"]
[Tue Jul 21 08:03:59.635855 2026] [access_compat:error] [pid 358661:tid 358869] [client 162.241.63.68:46482] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:03:59.640395 2026] [security2:error] [pid 358661:tid 358894] [client 38.100.221.102:18842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SHwlWhjQfpOo60_HVBAAAAGQ"]
[Tue Jul 21 08:03:59.640504 2026] [security2:error] [pid 358661:tid 358894] [client 38.100.221.102:18842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SHwlWhjQfpOo60_HVBAAAAGQ"]
[Tue Jul 21 08:03:59.861595 2026] [security2:error] [pid 358661:tid 358881] [client 91.92.47.101:4494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/php_info.php"] [unique_id "al9SHwlWhjQfpOo60_HVCwAAAFc"], referer: http://sigmas.app.br/
[Tue Jul 21 08:03:59.862147 2026] [security2:error] [pid 352421:tid 352588] [client 91.92.47.101:4532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/phpinfo/info.php"] [unique_id "al9SH8JSWzG9jbYOtu5G8gAAAKo"], referer: http://sigmas.app.br/
[Tue Jul 21 08:03:59.863737 2026] [security2:error] [pid 352421:tid 352598] [client 91.92.47.101:4558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/index.php"] [unique_id "al9SH8JSWzG9jbYOtu5G9AAAALQ"], referer: http://sigmas.app.br/
[Tue Jul 21 08:03:59.863896 2026] [security2:error] [pid 358661:tid 358811] [client 91.92.47.101:4490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/pinfo.php"] [unique_id "al9SHwlWhjQfpOo60_HVDQAAABE"], referer: http://sigmas.app.br/
[Tue Jul 21 08:03:59.865234 2026] [security2:error] [pid 352421:tid 352619] [client 91.92.47.101:4510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/functions.php"] [unique_id "al9SH8JSWzG9jbYOtu5G9gAAAMk"], referer: http://sigmas.app.br/
[Tue Jul 21 08:03:59.865423 2026] [security2:error] [pid 358661:tid 358826] [client 91.92.47.101:4588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/portal/phpinfo.php"] [unique_id "al9SHwlWhjQfpOo60_HVEAAAACA"], referer: http://sigmas.app.br/
[Tue Jul 21 08:03:59.865932 2026] [security2:error] [pid 358661:tid 358837] [client 91.92.47.101:4600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/server_info.php"] [unique_id "al9SHwlWhjQfpOo60_HVEQAAACs"], referer: http://sigmas.app.br/
[Tue Jul 21 08:03:59.866026 2026] [security2:error] [pid 358661:tid 358853] [client 91.92.47.101:4606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/configuration.php"] [unique_id "al9SHwlWhjQfpOo60_HVEgAAADs"], referer: http://sigmas.app.br/
[Tue Jul 21 08:03:59.866699 2026] [security2:error] [pid 358661:tid 358901] [client 91.92.47.101:4540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sigmas.app.br"] [uri "/test.php"] [unique_id "al9SHwlWhjQfpOo60_HVFQAAAGs"], referer: http://sigmas.app.br/
[Tue Jul 21 08:04:00.076179 2026] [security2:error] [pid 352421:tid 352599] [client 122.179.91.63:24534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SIMJSWzG9jbYOtu5G-AAAALU"]
[Tue Jul 21 08:04:00.076462 2026] [security2:error] [pid 352421:tid 352599] [client 122.179.91.63:24534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SIMJSWzG9jbYOtu5G-AAAALU"]
[Tue Jul 21 08:04:00.342719 2026] [security2:error] [pid 358661:tid 358772] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SIAlWhjQfpOo60_HVHwAAfWs"]
[Tue Jul 21 08:04:00.342922 2026] [security2:error] [pid 358661:tid 358919] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SIAlWhjQfpOo60_HVHwAAfWs"]
[Tue Jul 21 08:04:00.371165 2026] [security2:error] [pid 358661:tid 358844] [client 65.21.113.253:56646] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SHwlWhjQfpOo60_HVGAAAADI"]
[Tue Jul 21 08:04:00.441328 2026] [security2:error] [pid 358661:tid 358907] [client 74.7.230.33:57966] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dralulmabhering.com"] [uri "/index.php"] [unique_id "al9SHwlWhjQfpOo60_HU9QAAcWM"]
[Tue Jul 21 08:04:00.780301 2026] [security2:error] [pid 358661:tid 358815] [client 41.68.90.219:64797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SIAlWhjQfpOo60_HVIwAAABU"]
[Tue Jul 21 08:04:00.781289 2026] [security2:error] [pid 358661:tid 358815] [client 41.68.90.219:64797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SIAlWhjQfpOo60_HVIwAAABU"]
[Tue Jul 21 08:04:00.828727 2026] [security2:error] [pid 358661:tid 358694] [remote 185.213.175.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.cromobelo.com.br"] [uri "/"] [unique_id "al9SIAlWhjQfpOo60_HVJAAADB0"]
[Tue Jul 21 08:04:00.828926 2026] [security2:error] [pid 358661:tid 358806] [client 185.213.175.37:0] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.cromobelo.com.br"] [uri "/"] [unique_id "al9SIAlWhjQfpOo60_HVJAAADB0"]
[Tue Jul 21 08:04:01.169446 2026] [security2:error] [pid 358661:tid 358910] [client 202.143.127.214:56544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SIQlWhjQfpOo60_HVJwAAAHQ"]
[Tue Jul 21 08:04:01.169535 2026] [security2:error] [pid 358661:tid 358910] [client 202.143.127.214:56544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SIQlWhjQfpOo60_HVJwAAAHQ"]
[Tue Jul 21 08:04:01.451236 2026] [security2:error] [pid 358661:tid 358841] [client 20.104.96.117:46691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/for.php"] [unique_id "al9SIQlWhjQfpOo60_HVLQAAAC8"]
[Tue Jul 21 08:04:01.561918 2026] [autoindex:error] [pid 358661:tid 358726] [remote 74.7.242.13:37102] AH01276: Cannot serve directory /home1/imperd48/ussabinooffers.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:04:01.615297 2026] [security2:error] [pid 358661:tid 358899] [client 65.21.113.253:53786] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SIQlWhjQfpOo60_HVLwAAAGk"]
[Tue Jul 21 08:04:01.660373 2026] [security2:error] [pid 358661:tid 358782] [remote 124.55.178.99:35642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/xmlrpc.php"] [unique_id "al9SIQlWhjQfpOo60_HVMAAACHU"]
[Tue Jul 21 08:04:01.660555 2026] [security2:error] [pid 358661:tid 358802] [client 124.55.178.99:35642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "supremaservices.net"] [uri "/xmlrpc.php"] [unique_id "al9SIQlWhjQfpOo60_HVMAAACHU"]
[Tue Jul 21 08:04:01.732724 2026] [security2:error] [pid 358661:tid 358883] [client 20.151.10.161:28060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wefile.php"] [unique_id "al9SIQlWhjQfpOo60_HVMQAAAFk"]
[Tue Jul 21 08:04:01.829085 2026] [security2:error] [pid 352421:tid 352639] [client 74.7.230.40:60780] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.ussabinooffers.com.imperdivelbestpromotionofthedaytodayonly.com"] [uri "/cgi-sys/404.html"] [unique_id "al9SIcJSWzG9jbYOtu5HGQAA3WM"]
[Tue Jul 21 08:04:02.027793 2026] [security2:error] [pid 352421:tid 352455] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SIsJSWzG9jbYOtu5HHgAA5CE"]
[Tue Jul 21 08:04:02.028189 2026] [security2:error] [pid 352421:tid 352646] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SIsJSWzG9jbYOtu5HHgAA5CE"]
[Tue Jul 21 08:04:02.147001 2026] [security2:error] [pid 358661:tid 358908] [client 20.220.225.223:34280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/koiy.php"] [unique_id "al9SIglWhjQfpOo60_HVMwAAAHI"]
[Tue Jul 21 08:04:02.254888 2026] [security2:error] [pid 358661:tid 358781] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SIglWhjQfpOo60_HVNAAAenQ"]
[Tue Jul 21 08:04:02.255073 2026] [security2:error] [pid 358661:tid 358916] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SIglWhjQfpOo60_HVNAAAenQ"]
[Tue Jul 21 08:04:02.333128 2026] [security2:error] [pid 358661:tid 358877] [client 120.56.162.40:64985] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SIglWhjQfpOo60_HVNQAAAFM"]
[Tue Jul 21 08:04:02.333263 2026] [security2:error] [pid 358661:tid 358877] [client 120.56.162.40:64985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SIglWhjQfpOo60_HVNQAAAFM"]
[Tue Jul 21 08:04:02.348913 2026] [security2:error] [pid 358661:tid 358843] [client 20.29.126.15:4235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/shell.php"] [unique_id "al9SIglWhjQfpOo60_HVNgAAADE"]
[Tue Jul 21 08:04:02.370920 2026] [security2:error] [pid 358661:tid 358862] [client 193.36.225.54:44531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SIglWhjQfpOo60_HVOAAAAEQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:04:02.570667 2026] [security2:error] [pid 358661:tid 358674] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SIglWhjQfpOo60_HVPwAAZAk"]
[Tue Jul 21 08:04:02.570792 2026] [security2:error] [pid 358661:tid 358894] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SIglWhjQfpOo60_HVPwAAZAk"]
[Tue Jul 21 08:04:02.576080 2026] [security2:error] [pid 358661:tid 358679] [remote 182.77.62.24:49348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9SIglWhjQfpOo60_HVQAAASQ4"]
[Tue Jul 21 08:04:02.713949 2026] [security2:error] [pid 352421:tid 352658] [client 65.21.113.253:56650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SIsJSWzG9jbYOtu5HIgAAAPA"]
[Tue Jul 21 08:04:03.154030 2026] [security2:error] [pid 358661:tid 358720] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SIwlWhjQfpOo60_HVTAAACzc"]
[Tue Jul 21 08:04:03.154243 2026] [security2:error] [pid 358661:tid 358805] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SIwlWhjQfpOo60_HVTAAACzc"]
[Tue Jul 21 08:04:03.190442 2026] [security2:error] [pid 352421:tid 352452] [remote 192.241.143.148:44116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9SI8JSWzG9jbYOtu5HNgAArB4"]
[Tue Jul 21 08:04:03.565873 2026] [security2:error] [pid 358661:tid 358879] [client 92.119.178.3:47390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SIwlWhjQfpOo60_HVUwAAAFU"]
[Tue Jul 21 08:04:03.565960 2026] [security2:error] [pid 358661:tid 358879] [client 92.119.178.3:47390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SIwlWhjQfpOo60_HVUwAAAFU"]
[Tue Jul 21 08:04:03.668877 2026] [security2:error] [pid 358661:tid 358733] [remote 72.167.132.114:55900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9SIwlWhjQfpOo60_HVVAAAfUQ"]
[Tue Jul 21 08:04:03.687770 2026] [security2:error] [pid 358661:tid 358914] [client 47.128.37.153:31918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "multicarsc.com.br"] [uri "/robots.txt"] [unique_id "al9SIwlWhjQfpOo60_HVVgAAAHg"]
[Tue Jul 21 08:04:03.808246 2026] [security2:error] [pid 358661:tid 358861] [client 20.151.10.161:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9SIwlWhjQfpOo60_HVWAAAAEM"]
[Tue Jul 21 08:04:04.034097 2026] [security2:error] [pid 358661:tid 358740] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SJAlWhjQfpOo60_HVWgAASks"]
[Tue Jul 21 08:04:04.034233 2026] [security2:error] [pid 358661:tid 358868] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SJAlWhjQfpOo60_HVWgAASks"]
[Tue Jul 21 08:04:04.172855 2026] [security2:error] [pid 352421:tid 352591] [client 106.215.181.8:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SJMJSWzG9jbYOtu5HRQAAAK0"]
[Tue Jul 21 08:04:04.172975 2026] [security2:error] [pid 352421:tid 352591] [client 106.215.181.8:13282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SJMJSWzG9jbYOtu5HRQAAAK0"]
[Tue Jul 21 08:04:04.385487 2026] [security2:error] [pid 358661:tid 358880] [client 102.206.115.33:63842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SJAlWhjQfpOo60_HVXwAAAFY"]
[Tue Jul 21 08:04:04.385692 2026] [security2:error] [pid 358661:tid 358880] [client 102.206.115.33:63842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SJAlWhjQfpOo60_HVXwAAAFY"]
[Tue Jul 21 08:04:04.412067 2026] [security2:error] [pid 358661:tid 358871] [client 20.220.225.223:34295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/hp2.php"] [unique_id "al9SJAlWhjQfpOo60_HVYAAAAE0"]
[Tue Jul 21 08:04:04.992749 2026] [security2:error] [pid 358661:tid 358819] [client 182.8.255.181:17504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SJAlWhjQfpOo60_HVZgAAABk"]
[Tue Jul 21 08:04:04.992911 2026] [security2:error] [pid 358661:tid 358819] [client 182.8.255.181:17504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SJAlWhjQfpOo60_HVZgAAABk"]
[Tue Jul 21 08:04:05.048431 2026] [security2:error] [pid 358661:tid 358881] [client 20.104.96.117:46719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/ssla.php"] [unique_id "al9SJQlWhjQfpOo60_HVZwAAAFc"]
[Tue Jul 21 08:04:05.187321 2026] [security2:error] [pid 358661:tid 358802] [client 103.78.200.11:57444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SJQlWhjQfpOo60_HVagAAAAg"]
[Tue Jul 21 08:04:05.187440 2026] [security2:error] [pid 358661:tid 358802] [client 103.78.200.11:57444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SJQlWhjQfpOo60_HVagAAAAg"]
[Tue Jul 21 08:04:05.588415 2026] [security2:error] [pid 358661:tid 358843] [client 87.116.180.198:27138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SJQlWhjQfpOo60_HVbgAAADE"]
[Tue Jul 21 08:04:05.588859 2026] [security2:error] [pid 358661:tid 358843] [client 87.116.180.198:27138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SJQlWhjQfpOo60_HVbgAAADE"]
[Tue Jul 21 08:04:05.884211 2026] [security2:error] [pid 358661:tid 358853] [client 103.29.114.44:7572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SJQlWhjQfpOo60_HVcQAAADs"]
[Tue Jul 21 08:04:05.884382 2026] [security2:error] [pid 358661:tid 358853] [client 103.29.114.44:7572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SJQlWhjQfpOo60_HVcQAAADs"]
[Tue Jul 21 08:04:05.959312 2026] [security2:error] [pid 358661:tid 358900] [client 65.21.113.253:53786] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SJQlWhjQfpOo60_HVdQAAAGo"]
[Tue Jul 21 08:04:06.083304 2026] [security2:error] [pid 358661:tid 358822] [client 136.144.33.103:44361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SJglWhjQfpOo60_HVdgAAABw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:04:06.385775 2026] [security2:error] [pid 358661:tid 358794] [client 117.247.80.59:26148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SJglWhjQfpOo60_HVfAAAAAA"]
[Tue Jul 21 08:04:06.385907 2026] [security2:error] [pid 358661:tid 358794] [client 117.247.80.59:26148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SJglWhjQfpOo60_HVfAAAAAA"]
[Tue Jul 21 08:04:06.456768 2026] [security2:error] [pid 358661:tid 358690] [remote 8.217.108.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-login.php"] [unique_id "al9SJglWhjQfpOo60_HVfQAAARk"]
[Tue Jul 21 08:04:06.641839 2026] [security2:error] [pid 352421:tid 352654] [client 20.104.96.117:46700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "agmiz.com.br"] [uri "/zc-131.php"] [unique_id "al9SJsJSWzG9jbYOtu5HaAAAAOw"]
[Tue Jul 21 08:04:06.717725 2026] [security2:error] [pid 358661:tid 358857] [client 20.151.10.161:28488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/2P.php"] [unique_id "al9SJglWhjQfpOo60_HVggAAAD8"]
[Tue Jul 21 08:04:07.033859 2026] [security2:error] [pid 358661:tid 358914] [client 65.21.113.253:56658] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SJglWhjQfpOo60_HVgQAAAHg"]
[Tue Jul 21 08:04:07.588889 2026] [core:error] [pid 352421:tid 352477] [remote 45.148.10.238:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:04:07.588919 2026] [core:error] [pid 352421:tid 352477] [remote 45.148.10.238:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:04:07.699930 2026] [security2:error] [pid 358661:tid 358901] [client 20.220.225.223:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/hp3.php"] [unique_id "al9SJwlWhjQfpOo60_HViwAAAGs"]
[Tue Jul 21 08:04:08.041510 2026] [security2:error] [pid 352421:tid 352628] [client 20.29.126.15:19188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/3.php"] [unique_id "al9SKMJSWzG9jbYOtu5HfQAAANI"]
[Tue Jul 21 08:04:08.154755 2026] [proxy:error] [pid 358661:tid 358812] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:04:08.154841 2026] [proxy_http:error] [pid 358661:tid 358812] [client 167.71.164.46:41004] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:04:08.155461 2026] [proxy:error] [pid 358661:tid 358812] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:04:08.155491 2026] [proxy_http:error] [pid 358661:tid 358812] [client 167.71.164.46:41004] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:04:08.183383 2026] [security2:error] [pid 358661:tid 358877] [client 178.153.91.96:53866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SKAlWhjQfpOo60_HVlgAAAFM"]
[Tue Jul 21 08:04:08.183523 2026] [security2:error] [pid 358661:tid 358877] [client 178.153.91.96:53866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SKAlWhjQfpOo60_HVlgAAAFM"]
[Tue Jul 21 08:04:08.231724 2026] [security2:error] [pid 358661:tid 358749] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SKAlWhjQfpOo60_HVlwAAHlQ"]
[Tue Jul 21 08:04:08.231986 2026] [security2:error] [pid 358661:tid 358824] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SKAlWhjQfpOo60_HVlwAAHlQ"]
[Tue Jul 21 08:04:08.394450 2026] [proxy:error] [pid 352421:tid 352671] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:04:08.394524 2026] [proxy_http:error] [pid 352421:tid 352671] [client 167.71.164.46:41008] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.novoar.net.br/
[Tue Jul 21 08:04:08.395148 2026] [proxy:error] [pid 352421:tid 352671] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:04:08.395177 2026] [proxy_http:error] [pid 352421:tid 352671] [client 167.71.164.46:41008] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.novoar.net.br/
[Tue Jul 21 08:04:08.518892 2026] [security2:error] [pid 358661:tid 358809] [client 109.60.28.94:1421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKAlWhjQfpOo60_HVmAAAAA8"]
[Tue Jul 21 08:04:08.519192 2026] [security2:error] [pid 358661:tid 358809] [client 109.60.28.94:1421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKAlWhjQfpOo60_HVmAAAAA8"]
[Tue Jul 21 08:04:08.673263 2026] [security2:error] [pid 358661:tid 358716] [remote 199.189.225.40:51431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/wp-login.php"] [unique_id "al9SKAlWhjQfpOo60_HVnAAAGDM"]
[Tue Jul 21 08:04:08.748030 2026] [security2:error] [pid 358661:tid 358822] [client 92.119.178.3:44688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9SKAlWhjQfpOo60_HVngAAABw"]
[Tue Jul 21 08:04:08.748154 2026] [security2:error] [pid 358661:tid 358822] [client 92.119.178.3:44688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9SKAlWhjQfpOo60_HVngAAABw"]
[Tue Jul 21 08:04:08.863295 2026] [proxy:error] [pid 352421:tid 352642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:04:08.863332 2026] [proxy_http:error] [pid 352421:tid 352642] [client 167.71.164.46:34660] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:04:08.863984 2026] [proxy:error] [pid 352421:tid 352642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:04:08.864012 2026] [proxy_http:error] [pid 352421:tid 352642] [client 167.71.164.46:34660] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:04:08.866007 2026] [security2:error] [pid 352421:tid 352530] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKMJSWzG9jbYOtu5HigAA1Gw"]
[Tue Jul 21 08:04:08.866129 2026] [security2:error] [pid 352421:tid 352630] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKMJSWzG9jbYOtu5HigAA1Gw"]
[Tue Jul 21 08:04:08.924133 2026] [security2:error] [pid 358661:tid 358838] [client 117.210.135.0:62371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKAlWhjQfpOo60_HVnwAAACw"]
[Tue Jul 21 08:04:08.924256 2026] [security2:error] [pid 358661:tid 358838] [client 117.210.135.0:62371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKAlWhjQfpOo60_HVnwAAACw"]
[Tue Jul 21 08:04:09.263060 2026] [security2:error] [pid 352421:tid 352645] [client 103.166.103.129:56866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SKcJSWzG9jbYOtu5HkAAAAOM"]
[Tue Jul 21 08:04:09.263518 2026] [security2:error] [pid 352421:tid 352645] [client 103.166.103.129:56866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SKcJSWzG9jbYOtu5HkAAAAOM"]
[Tue Jul 21 08:04:09.360848 2026] [security2:error] [pid 358661:tid 358874] [client 20.197.192.193:51949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/ah25.php"] [unique_id "al9SKQlWhjQfpOo60_HVpwAAAFA"]
[Tue Jul 21 08:04:09.629943 2026] [security2:error] [pid 352421:tid 352618] [client 31.57.219.92:29720] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "neuroalfabetizaanacolombo.com"] [uri "/"] [unique_id "al9SKcJSWzG9jbYOtu5HmAAAAMg"]
[Tue Jul 21 08:04:09.697976 2026] [security2:error] [pid 352421:tid 352615] [client 20.151.10.161:28280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/.well-known/about.php"] [unique_id "al9SKcJSWzG9jbYOtu5HmgAAAMU"]
[Tue Jul 21 08:04:09.830085 2026] [security2:error] [pid 358661:tid 358913] [client 175.144.82.48:64423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKQlWhjQfpOo60_HVqgAAAHc"]
[Tue Jul 21 08:04:09.831020 2026] [security2:error] [pid 358661:tid 358913] [client 175.144.82.48:64423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKQlWhjQfpOo60_HVqgAAAHc"]
[Tue Jul 21 08:04:10.220121 2026] [security2:error] [pid 358661:tid 358888] [client 38.100.221.102:18892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKglWhjQfpOo60_HVrQAAAF4"]
[Tue Jul 21 08:04:10.220300 2026] [security2:error] [pid 358661:tid 358888] [client 38.100.221.102:18892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKglWhjQfpOo60_HVrQAAAF4"]
[Tue Jul 21 08:04:10.310796 2026] [security2:error] [pid 358661:tid 358910] [client 122.179.91.63:10352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SKglWhjQfpOo60_HVrwAAAHQ"]
[Tue Jul 21 08:04:10.310937 2026] [security2:error] [pid 358661:tid 358910] [client 122.179.91.63:10352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SKglWhjQfpOo60_HVrwAAAHQ"]
[Tue Jul 21 08:04:10.413311 2026] [security2:error] [pid 352421:tid 352666] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9SKsJSWzG9jbYOtu5HqwAAAPg"]
[Tue Jul 21 08:04:10.698166 2026] [security2:error] [pid 358661:tid 358909] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKglWhjQfpOo60_HVtAAAAHM"]
[Tue Jul 21 08:04:10.858256 2026] [security2:error] [pid 352421:tid 352564] [client 193.36.225.11:40321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SKsJSWzG9jbYOtu5HtQAAAJI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:04:10.998697 2026] [security2:error] [pid 358661:tid 358779] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKglWhjQfpOo60_HVtwAAT3I"]
[Tue Jul 21 08:04:10.998841 2026] [security2:error] [pid 358661:tid 358873] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKglWhjQfpOo60_HVtwAAT3I"]
[Tue Jul 21 08:04:11.060755 2026] [security2:error] [pid 358661:tid 358901] [client 184.75.221.3:34894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9SKwlWhjQfpOo60_HVuAAAAGs"]
[Tue Jul 21 08:04:11.060911 2026] [security2:error] [pid 358661:tid 358901] [client 184.75.221.3:34894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9SKwlWhjQfpOo60_HVuAAAAGs"]
[Tue Jul 21 08:04:11.134707 2026] [security2:error] [pid 358661:tid 358894] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9SKwlWhjQfpOo60_HVuQAAAGQ"]
[Tue Jul 21 08:04:11.441015 2026] [security2:error] [pid 358661:tid 358877] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9SKwlWhjQfpOo60_HVvwAAAFM"]
[Tue Jul 21 08:04:11.727247 2026] [security2:error] [pid 352421:tid 352594] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9SK8JSWzG9jbYOtu5HwgAAALA"]
[Tue Jul 21 08:04:11.870364 2026] [proxy:error] [pid 358661:tid 358859] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:04:11.870401 2026] [proxy_http:error] [pid 358661:tid 358859] [client 167.71.164.46:52270] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.novoar.net.br/
[Tue Jul 21 08:04:11.870840 2026] [proxy:error] [pid 358661:tid 358859] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:04:11.870863 2026] [proxy_http:error] [pid 358661:tid 358859] [client 167.71.164.46:52270] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.novoar.net.br/
[Tue Jul 21 08:04:11.925049 2026] [security2:error] [pid 358661:tid 358912] [client 41.68.90.219:65257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKwlWhjQfpOo60_HVxgAAAHY"]
[Tue Jul 21 08:04:11.926375 2026] [security2:error] [pid 358661:tid 358912] [client 41.68.90.219:65257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SKwlWhjQfpOo60_HVxgAAAHY"]
[Tue Jul 21 08:04:12.011691 2026] [security2:error] [pid 358661:tid 358853] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9SLAlWhjQfpOo60_HVxwAAADs"]
[Tue Jul 21 08:04:12.203495 2026] [security2:error] [pid 358661:tid 358829] [client 202.143.127.214:57027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SLAlWhjQfpOo60_HVyQAAACM"]
[Tue Jul 21 08:04:12.203620 2026] [security2:error] [pid 358661:tid 358829] [client 202.143.127.214:57027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SLAlWhjQfpOo60_HVyQAAACM"]
[Tue Jul 21 08:04:12.301238 2026] [security2:error] [pid 358661:tid 358879] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9SLAlWhjQfpOo60_HVygAAAFU"]
[Tue Jul 21 08:04:12.383274 2026] [core:error] [pid 358661:tid 358767] [remote 205.210.31.232:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:04:12.383297 2026] [core:error] [pid 358661:tid 358767] [remote 205.210.31.232:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:04:12.442894 2026] [security2:error] [pid 352421:tid 352574] [client 20.29.126.15:2863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/mds.php"] [unique_id "al9SLMJSWzG9jbYOtu5H0QAAAJw"]
[Tue Jul 21 08:04:12.584268 2026] [security2:error] [pid 352421:tid 352558] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9SLMJSWzG9jbYOtu5H0wAAAIw"]
[Tue Jul 21 08:04:12.587404 2026] [core:alert] [pid 352421:tid 352636] [client 57.141.18.31:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:04:12.650422 2026] [security2:error] [pid 358661:tid 358863] [client 20.151.10.161:28543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9SLAlWhjQfpOo60_HV0AAAAEU"]
[Tue Jul 21 08:04:12.729506 2026] [security2:error] [pid 358661:tid 358773] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SLAlWhjQfpOo60_HV0wAAS2w"]
[Tue Jul 21 08:04:12.729649 2026] [security2:error] [pid 358661:tid 358869] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SLAlWhjQfpOo60_HV0wAAS2w"]
[Tue Jul 21 08:04:12.753767 2026] [security2:error] [pid 352421:tid 352585] [client 20.197.192.193:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/8.php"] [unique_id "al9SLMJSWzG9jbYOtu5H1wAAAKc"]
[Tue Jul 21 08:04:12.868641 2026] [security2:error] [pid 352421:tid 352555] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9SLMJSWzG9jbYOtu5H2wAAAIk"]
[Tue Jul 21 08:04:12.967209 2026] [security2:error] [pid 358661:tid 358884] [client 184.75.221.3:49298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9SLAlWhjQfpOo60_HV2AAAAFo"]
[Tue Jul 21 08:04:12.967290 2026] [security2:error] [pid 358661:tid 358884] [client 184.75.221.3:49298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9SLAlWhjQfpOo60_HV2AAAAFo"]
[Tue Jul 21 08:04:13.042329 2026] [security2:error] [pid 352421:tid 352640] [client 120.56.162.40:65429] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SLcJSWzG9jbYOtu5H3QAAAN4"]
[Tue Jul 21 08:04:13.042497 2026] [security2:error] [pid 352421:tid 352640] [client 120.56.162.40:65429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SLcJSWzG9jbYOtu5H3QAAAN4"]
[Tue Jul 21 08:04:13.071134 2026] [security2:error] [pid 358661:tid 358890] [client 65.21.113.253:41664] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SLQlWhjQfpOo60_HV2gAAAGA"]
[Tue Jul 21 08:04:13.097894 2026] [security2:error] [pid 358661:tid 358880] [client 20.220.225.223:34176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/aa1.php"] [unique_id "al9SLQlWhjQfpOo60_HV2wAAAFY"]
[Tue Jul 21 08:04:13.145186 2026] [security2:error] [pid 358661:tid 358728] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SLQlWhjQfpOo60_HV3AAAOj8"]
[Tue Jul 21 08:04:13.145338 2026] [security2:error] [pid 358661:tid 358852] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SLQlWhjQfpOo60_HV3AAAOj8"]
[Tue Jul 21 08:04:13.153490 2026] [security2:error] [pid 358661:tid 358883] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9SLQlWhjQfpOo60_HV3QAAAFk"]
[Tue Jul 21 08:04:13.201245 2026] [security2:error] [pid 352421:tid 352440] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SLcJSWzG9jbYOtu5H4QAAwBI"]
[Tue Jul 21 08:04:13.201368 2026] [security2:error] [pid 352421:tid 352610] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SLcJSWzG9jbYOtu5H4QAAwBI"]
[Tue Jul 21 08:04:13.221762 2026] [security2:error] [pid 352421:tid 352641] [client 82.102.18.188:44406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brasilmotoeletrica.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9SLcJSWzG9jbYOtu5H4gAAAN8"]
[Tue Jul 21 08:04:13.439041 2026] [security2:error] [pid 358661:tid 358819] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9SLQlWhjQfpOo60_HV4gAAABk"]
[Tue Jul 21 08:04:13.472921 2026] [security2:error] [pid 358661:tid 358901] [client 92.119.178.3:45632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SLQlWhjQfpOo60_HV6AAAAGs"]
[Tue Jul 21 08:04:13.473027 2026] [security2:error] [pid 358661:tid 358901] [client 92.119.178.3:45632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SLQlWhjQfpOo60_HV6AAAAGs"]
[Tue Jul 21 08:04:13.618256 2026] [security2:error] [pid 352421:tid 352506] [remote 119.195.102.159:49922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/wp-login.php"] [unique_id "al9SLMJSWzG9jbYOtu5H1QAA_VQ"]
[Tue Jul 21 08:04:13.738879 2026] [security2:error] [pid 352421:tid 352595] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9SLcJSWzG9jbYOtu5H5wAAALE"]
[Tue Jul 21 08:04:13.873103 2026] [security2:error] [pid 358661:tid 358754] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SLQlWhjQfpOo60_HV7QAAFlk"]
[Tue Jul 21 08:04:13.874301 2026] [security2:error] [pid 358661:tid 358816] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SLQlWhjQfpOo60_HV7QAAFlk"]
[Tue Jul 21 08:04:14.016780 2026] [security2:error] [pid 358661:tid 358837] [client 82.102.18.188:34096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilmotoeletrica.com"] [uri "/xmlrpc.php"] [unique_id "al9SLglWhjQfpOo60_HV8wAAACs"]
[Tue Jul 21 08:04:14.023350 2026] [security2:error] [pid 358661:tid 358899] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9SLglWhjQfpOo60_HV9AAAAGk"]
[Tue Jul 21 08:04:14.028571 2026] [security2:error] [pid 358661:tid 358840] [client 20.151.10.161:28507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/bob.php"] [unique_id "al9SLglWhjQfpOo60_HV9QAAAC4"]
[Tue Jul 21 08:04:14.150925 2026] [security2:error] [pid 358661:tid 358892] [client 65.21.113.253:33854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SLQlWhjQfpOo60_HV6gAAAGI"]
[Tue Jul 21 08:04:14.261717 2026] [security2:error] [pid 352421:tid 352472] [remote 92.113.19.180:28656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.19.113.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moneyclass.com.br"] [uri "/wp-login.php"] [unique_id "al9SLsJSWzG9jbYOtu5H7gAA1jI"]
[Tue Jul 21 08:04:14.296305 2026] [security2:error] [pid 358661:tid 358822] [client 20.197.192.193:52255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/red.php"] [unique_id "al9SLglWhjQfpOo60_HV9wAAABw"]
[Tue Jul 21 08:04:14.307335 2026] [security2:error] [pid 358661:tid 358815] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9SLglWhjQfpOo60_HV-QAAABU"]
[Tue Jul 21 08:04:14.591460 2026] [security2:error] [pid 358661:tid 358849] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9SLglWhjQfpOo60_HWAgAAADc"]
[Tue Jul 21 08:04:14.686613 2026] [security2:error] [pid 352421:tid 352668] [client 20.220.225.223:34198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/acew67.php"] [unique_id "al9SLsJSWzG9jbYOtu5H8wAAAPo"]
[Tue Jul 21 08:04:14.719799 2026] [security2:error] [pid 358661:tid 358810] [client 193.36.225.63:53543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SLglWhjQfpOo60_HWAwAAABA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:04:14.800835 2026] [security2:error] [pid 358661:tid 358666] [remote 188.164.197.230:50606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9SLglWhjQfpOo60_HWBAAAXwE"]
[Tue Jul 21 08:04:14.800990 2026] [security2:error] [pid 358661:tid 358889] [client 188.164.197.230:50606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9SLglWhjQfpOo60_HWBAAAXwE"]
[Tue Jul 21 08:04:14.875086 2026] [security2:error] [pid 352421:tid 352628] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9SLsJSWzG9jbYOtu5H-AAAANI"]
[Tue Jul 21 08:04:14.911511 2026] [security2:error] [pid 358661:tid 358829] [client 102.206.115.33:61012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SLglWhjQfpOo60_HWCQAAACM"]
[Tue Jul 21 08:04:14.911694 2026] [security2:error] [pid 358661:tid 358829] [client 102.206.115.33:61012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SLglWhjQfpOo60_HWCQAAACM"]
[Tue Jul 21 08:04:14.956559 2026] [security2:error] [pid 358661:tid 358855] [client 106.215.181.8:19644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SLglWhjQfpOo60_HWCgAAAD0"]
[Tue Jul 21 08:04:14.956657 2026] [security2:error] [pid 358661:tid 358855] [client 106.215.181.8:19644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SLglWhjQfpOo60_HWCgAAAD0"]
[Tue Jul 21 08:04:15.068195 2026] [security2:error] [pid 358661:tid 358686] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SLwlWhjQfpOo60_HWDgAAchU"]
[Tue Jul 21 08:04:15.068433 2026] [security2:error] [pid 358661:tid 358908] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SLwlWhjQfpOo60_HWDgAAchU"]
[Tue Jul 21 08:04:15.160187 2026] [security2:error] [pid 358661:tid 358862] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9SLwlWhjQfpOo60_HWDwAAAEQ"]
[Tue Jul 21 08:04:15.353606 2026] [security2:error] [pid 352421:tid 352663] [client 20.197.192.193:52279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/fffm.php"] [unique_id "al9SL8JSWzG9jbYOtu5H_QAAAPU"]
[Tue Jul 21 08:04:15.444130 2026] [security2:error] [pid 358661:tid 358820] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.sofiagheller1782846537000.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9SLwlWhjQfpOo60_HWEwAAABo"]
[Tue Jul 21 08:04:15.474505 2026] [security2:error] [pid 352421:tid 352588] [client 182.8.255.181:2898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SL8JSWzG9jbYOtu5IAAAAAKo"]
[Tue Jul 21 08:04:15.474882 2026] [security2:error] [pid 352421:tid 352588] [client 182.8.255.181:2898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SL8JSWzG9jbYOtu5IAAAAAKo"]
[Tue Jul 21 08:04:15.555491 2026] [security2:error] [pid 352421:tid 352554] [client 74.7.228.14:49272] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.franquias.acaiofficial.com.br"] [uri "/robots.txt"] [unique_id "al9SL8JSWzG9jbYOtu5IBAAAiEg"]
[Tue Jul 21 08:04:15.610504 2026] [security2:error] [pid 358661:tid 358823] [client 65.21.113.253:33868] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SLwlWhjQfpOo60_HWEAAAAB0"]
[Tue Jul 21 08:04:15.730942 2026] [security2:error] [pid 352421:tid 352650] [client 74.7.228.14:49272] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.franquias.acaiofficial.com.br"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al9SL8JSWzG9jbYOtu5IBQAA6Bg"], referer: https://www.franquias.acaiofficial.com.br/robots.txt
[Tue Jul 21 08:04:16.001631 2026] [security2:error] [pid 352421:tid 352605] [client 103.78.200.11:57931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SMMJSWzG9jbYOtu5IDAAAALs"]
[Tue Jul 21 08:04:16.001839 2026] [security2:error] [pid 352421:tid 352605] [client 103.78.200.11:57931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SMMJSWzG9jbYOtu5IDAAAALs"]
[Tue Jul 21 08:04:16.043301 2026] [security2:error] [pid 358661:tid 358846] [client 47.128.50.150:16350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "compressoresra.com.br"] [uri "/robots.txt"] [unique_id "al9SMAlWhjQfpOo60_HWIQAAADQ"]
[Tue Jul 21 08:04:16.140029 2026] [security2:error] [pid 358661:tid 358794] [client 20.220.225.223:34261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/bscclapb.php"] [unique_id "al9SMAlWhjQfpOo60_HWJQAAAAA"]
[Tue Jul 21 08:04:16.181765 2026] [security2:error] [pid 358661:tid 358812] [client 87.116.180.198:27330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SMAlWhjQfpOo60_HWJgAAABI"]
[Tue Jul 21 08:04:16.182397 2026] [security2:error] [pid 358661:tid 358812] [client 87.116.180.198:27330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SMAlWhjQfpOo60_HWJgAAABI"]
[Tue Jul 21 08:04:16.392678 2026] [security2:error] [pid 358661:tid 358795] [client 20.151.10.161:28252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/crgio.php"] [unique_id "al9SMAlWhjQfpOo60_HWKAAAAAE"]
[Tue Jul 21 08:04:16.457261 2026] [security2:error] [pid 352421:tid 352642] [client 103.29.114.44:32722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SMMJSWzG9jbYOtu5IFAAAAOA"]
[Tue Jul 21 08:04:16.457396 2026] [security2:error] [pid 352421:tid 352642] [client 103.29.114.44:32722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SMMJSWzG9jbYOtu5IFAAAAOA"]
[Tue Jul 21 08:04:17.045714 2026] [security2:error] [pid 358661:tid 358913] [client 82.102.18.188:34108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilmotoeletrica.com"] [uri "/xmlrpc.php"] [unique_id "al9SMQlWhjQfpOo60_HWMAAAAHc"]
[Tue Jul 21 08:04:17.045837 2026] [security2:error] [pid 358661:tid 358913] [client 82.102.18.188:34108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilmotoeletrica.com"] [uri "/xmlrpc.php"] [unique_id "al9SMQlWhjQfpOo60_HWMAAAAHc"]
[Tue Jul 21 08:04:17.088321 2026] [security2:error] [pid 358661:tid 358884] [client 20.220.225.223:34296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/else1.php"] [unique_id "al9SMQlWhjQfpOo60_HWMgAAAFo"]
[Tue Jul 21 08:04:17.206290 2026] [security2:error] [pid 352421:tid 352615] [client 117.247.80.59:21531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SMcJSWzG9jbYOtu5IHQAAAMU"]
[Tue Jul 21 08:04:17.206891 2026] [security2:error] [pid 352421:tid 352615] [client 117.247.80.59:21531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SMcJSWzG9jbYOtu5IHQAAAMU"]
[Tue Jul 21 08:04:18.489932 2026] [security2:error] [pid 352421:tid 352662] [client 20.197.192.193:52270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/ftde.php"] [unique_id "al9SMsJSWzG9jbYOtu5IMgAAAPQ"]
[Tue Jul 21 08:04:18.646948 2026] [security2:error] [pid 358661:tid 358704] [remote 87.106.217.70:39798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.217.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "domuscondominios.com.br"] [uri "/wp-login.php"] [unique_id "al9SMQlWhjQfpOo60_HWNQAAQyc"]
[Tue Jul 21 08:04:18.693756 2026] [security2:error] [pid 358661:tid 358843] [client 20.151.10.161:28497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/pucci.php"] [unique_id "al9SMglWhjQfpOo60_HWQgAAADE"]
[Tue Jul 21 08:04:18.736116 2026] [security2:error] [pid 352421:tid 352540] [remote 173.252.87.1:59256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9SMsJSWzG9jbYOtu5INwAAmXY"]
[Tue Jul 21 08:04:18.806513 2026] [security2:error] [pid 358661:tid 358873] [client 178.153.91.96:54508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SMglWhjQfpOo60_HWQwAAAE8"]
[Tue Jul 21 08:04:18.806736 2026] [security2:error] [pid 358661:tid 358873] [client 178.153.91.96:54508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SMglWhjQfpOo60_HWQwAAAE8"]
[Tue Jul 21 08:04:18.820275 2026] [security2:error] [pid 352421:tid 352425] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SMsJSWzG9jbYOtu5IOgAA0AM"]
[Tue Jul 21 08:04:18.820418 2026] [security2:error] [pid 352421:tid 352626] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SMsJSWzG9jbYOtu5IOgAA0AM"]
[Tue Jul 21 08:04:19.082731 2026] [security2:error] [pid 352421:tid 352639] [client 20.220.225.223:34255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/tkikikoko.php"] [unique_id "al9SM8JSWzG9jbYOtu5IPAAAAN0"]
[Tue Jul 21 08:04:19.325999 2026] [security2:error] [pid 358661:tid 358838] [client 65.21.113.253:49744] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SMwlWhjQfpOo60_HWSwAAACw"]
[Tue Jul 21 08:04:19.353956 2026] [security2:error] [pid 358661:tid 358774] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SMwlWhjQfpOo60_HWTAAAYm0"]
[Tue Jul 21 08:04:19.354133 2026] [security2:error] [pid 358661:tid 358892] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SMwlWhjQfpOo60_HWTAAAYm0"]
[Tue Jul 21 08:04:19.356196 2026] [security2:error] [pid 358661:tid 358833] [client 109.60.28.94:2028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SMwlWhjQfpOo60_HWTQAAACc"]
[Tue Jul 21 08:04:19.357053 2026] [security2:error] [pid 358661:tid 358833] [client 109.60.28.94:2028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SMwlWhjQfpOo60_HWTQAAACc"]
[Tue Jul 21 08:04:19.402983 2026] [security2:error] [pid 358661:tid 358822] [client 184.75.221.3:55006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SMwlWhjQfpOo60_HWTgAAABw"]
[Tue Jul 21 08:04:19.403098 2026] [security2:error] [pid 358661:tid 358822] [client 184.75.221.3:55006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SMwlWhjQfpOo60_HWTgAAABw"]
[Tue Jul 21 08:04:19.448393 2026] [security2:error] [pid 358661:tid 358823] [client 117.210.135.0:63047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SMwlWhjQfpOo60_HWTwAAAB0"]
[Tue Jul 21 08:04:19.448581 2026] [security2:error] [pid 358661:tid 358823] [client 117.210.135.0:63047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SMwlWhjQfpOo60_HWTwAAAB0"]
[Tue Jul 21 08:04:19.642779 2026] [security2:error] [pid 358661:tid 358869] [client 20.220.225.223:34242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wp-Blogs.php"] [unique_id "al9SMwlWhjQfpOo60_HWVAAAAEs"]
[Tue Jul 21 08:04:19.933054 2026] [security2:error] [pid 358661:tid 358795] [client 65.21.113.253:33868] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SMwlWhjQfpOo60_HWUQAAAAE"]
[Tue Jul 21 08:04:20.038842 2026] [security2:error] [pid 358661:tid 358878] [client 103.166.103.129:57398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SNAlWhjQfpOo60_HWVQAAAFQ"]
[Tue Jul 21 08:04:20.038983 2026] [security2:error] [pid 358661:tid 358878] [client 103.166.103.129:57398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SNAlWhjQfpOo60_HWVQAAAFQ"]
[Tue Jul 21 08:04:20.240656 2026] [security2:error] [pid 352421:tid 352523] [remote 97.74.93.24:45246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-login.php"] [unique_id "al9SNMJSWzG9jbYOtu5ITQAAiGU"]
[Tue Jul 21 08:04:20.259180 2026] [security2:error] [pid 358661:tid 358866] [client 122.179.91.63:11429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SNAlWhjQfpOo60_HWVwAAAEg"]
[Tue Jul 21 08:04:20.259558 2026] [security2:error] [pid 358661:tid 358866] [client 122.179.91.63:11429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SNAlWhjQfpOo60_HWVwAAAEg"]
[Tue Jul 21 08:04:20.310596 2026] [security2:error] [pid 358661:tid 358829] [client 20.220.225.223:34284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wp-css.php"] [unique_id "al9SNAlWhjQfpOo60_HWWwAAACM"]
[Tue Jul 21 08:04:20.643189 2026] [security2:error] [pid 358661:tid 358796] [client 20.29.126.15:2159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/archive.php"] [unique_id "al9SNAlWhjQfpOo60_HWYAAAAAI"]
[Tue Jul 21 08:04:20.656258 2026] [security2:error] [pid 358661:tid 358909] [client 20.151.10.161:28235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-temp.php"] [unique_id "al9SNAlWhjQfpOo60_HWYQAAAHM"]
[Tue Jul 21 08:04:20.799669 2026] [security2:error] [pid 352421:tid 352582] [client 38.100.221.102:17498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SNMJSWzG9jbYOtu5IVwAAAKQ"]
[Tue Jul 21 08:04:20.799794 2026] [security2:error] [pid 352421:tid 352582] [client 38.100.221.102:17498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SNMJSWzG9jbYOtu5IVwAAAKQ"]
[Tue Jul 21 08:04:21.126954 2026] [security2:error] [pid 358661:tid 358914] [client 20.220.225.223:34298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/wp-explorer.php"] [unique_id "al9SNQlWhjQfpOo60_HWaQAAAHg"]
[Tue Jul 21 08:04:21.283945 2026] [security2:error] [pid 358661:tid 358854] [client 193.36.225.66:57793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SMwlWhjQfpOo60_HWSQAAADw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:04:21.445947 2026] [security2:error] [pid 358661:tid 358809] [client 20.151.10.161:28581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9SNQlWhjQfpOo60_HWcQAAAA8"]
[Tue Jul 21 08:04:21.661698 2026] [security2:error] [pid 358661:tid 358758] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SNQlWhjQfpOo60_HWcwAAK10"]
[Tue Jul 21 08:04:21.661847 2026] [security2:error] [pid 358661:tid 358837] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SNQlWhjQfpOo60_HWcwAAK10"]
[Tue Jul 21 08:04:21.674823 2026] [security2:error] [pid 358661:tid 358770] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9SNQlWhjQfpOo60_HWdAAAFGk"]
[Tue Jul 21 08:04:21.694326 2026] [security2:error] [pid 358661:tid 358727] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9SNQlWhjQfpOo60_HWdQAAaT4"]
[Tue Jul 21 08:04:21.747948 2026] [security2:error] [pid 358661:tid 358802] [client 175.144.82.48:64845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SNQlWhjQfpOo60_HWeAAAAAg"]
[Tue Jul 21 08:04:21.848107 2026] [security2:error] [pid 352421:tid 352625] [client 20.151.10.161:28572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/puc.php"] [unique_id "al9SNcJSWzG9jbYOtu5IYQAAAM8"]
[Tue Jul 21 08:04:22.067042 2026] [security2:error] [pid 352421:tid 352438] [remote 167.172.73.193:48456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.73.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tempex.com.br"] [uri "/wp-login.php"] [unique_id "al9SNsJSWzG9jbYOtu5IZAAA7RA"]
[Tue Jul 21 08:04:22.453178 2026] [security2:error] [pid 358661:tid 358869] [client 20.151.10.161:28595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/themes.php"] [unique_id "al9SNglWhjQfpOo60_HWgAAAAEs"]
[Tue Jul 21 08:04:22.546097 2026] [security2:error] [pid 358661:tid 358748] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/media.php"] [unique_id "al9SNglWhjQfpOo60_HWggAAUlM"]
[Tue Jul 21 08:04:22.574138 2026] [security2:error] [pid 358661:tid 358759] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/images.php"] [unique_id "al9SNglWhjQfpOo60_HWgwAAdV4"]
[Tue Jul 21 08:04:22.621431 2026] [security2:error] [pid 352421:tid 352572] [client 41.68.90.219:49335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SNsJSWzG9jbYOtu5IbAAAAJo"]
[Tue Jul 21 08:04:22.622317 2026] [security2:error] [pid 352421:tid 352572] [client 41.68.90.219:49335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SNsJSWzG9jbYOtu5IbAAAAJo"]
[Tue Jul 21 08:04:22.629981 2026] [security2:error] [pid 352421:tid 352669] [client 20.220.225.223:34288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/akismet.php"] [unique_id "al9SNsJSWzG9jbYOtu5IbgAAAPs"]
[Tue Jul 21 08:04:22.884591 2026] [security2:error] [pid 358661:tid 358802] [client 175.144.82.48:64845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SNQlWhjQfpOo60_HWeAAAAAg"]
[Tue Jul 21 08:04:22.927533 2026] [security2:error] [pid 358661:tid 358800] [client 20.151.10.161:28240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/dx.php"] [unique_id "al9SNglWhjQfpOo60_HWhgAAAAY"]
[Tue Jul 21 08:04:23.279521 2026] [security2:error] [pid 358661:tid 358872] [client 202.143.127.214:57498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SNwlWhjQfpOo60_HWiAAAAE4"]
[Tue Jul 21 08:04:23.279661 2026] [security2:error] [pid 358661:tid 358872] [client 202.143.127.214:57498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SNwlWhjQfpOo60_HWiAAAAE4"]
[Tue Jul 21 08:04:23.395679 2026] [security2:error] [pid 358661:tid 358722] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/adminner.php"] [unique_id "al9SNwlWhjQfpOo60_HWiwAAOjk"]
[Tue Jul 21 08:04:23.446920 2026] [security2:error] [pid 358661:tid 358702] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/admin.php"] [unique_id "al9SNwlWhjQfpOo60_HWjgAADSU"]
[Tue Jul 21 08:04:23.462923 2026] [security2:error] [pid 358661:tid 358768] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/k.php"] [unique_id "al9SNwlWhjQfpOo60_HWjwAAemc"]
[Tue Jul 21 08:04:23.487792 2026] [security2:error] [pid 358661:tid 358668] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/x.php"] [unique_id "al9SNwlWhjQfpOo60_HWkAAALwM"]
[Tue Jul 21 08:04:23.494301 2026] [security2:error] [pid 352421:tid 352468] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SN8JSWzG9jbYOtu5IewAAxi4"]
[Tue Jul 21 08:04:23.494482 2026] [security2:error] [pid 352421:tid 352616] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SN8JSWzG9jbYOtu5IewAAxi4"]
[Tue Jul 21 08:04:23.501889 2026] [security2:error] [pid 358661:tid 358796] [client 20.151.10.161:28584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/p.php"] [unique_id "al9SNwlWhjQfpOo60_HWkQAAAAI"]
[Tue Jul 21 08:04:23.541641 2026] [security2:error] [pid 358661:tid 358791] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wss.php"] [unique_id "al9SNwlWhjQfpOo60_HWkgAAPn4"]
[Tue Jul 21 08:04:23.611840 2026] [security2:error] [pid 352421:tid 352624] [client 120.56.162.40:49492] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SN8JSWzG9jbYOtu5IfAAAAM4"]
[Tue Jul 21 08:04:23.611987 2026] [security2:error] [pid 352421:tid 352624] [client 120.56.162.40:49492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SN8JSWzG9jbYOtu5IfAAAAM4"]
[Tue Jul 21 08:04:23.675964 2026] [security2:error] [pid 358661:tid 358901] [client 20.220.225.223:34441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/ace2.php"] [unique_id "al9SNwlWhjQfpOo60_HWkwAAAGs"]
[Tue Jul 21 08:04:23.803215 2026] [security2:error] [pid 358661:tid 358864] [client 65.21.113.253:49744] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SNwlWhjQfpOo60_HWlgAAAEY"]
[Tue Jul 21 08:04:23.886130 2026] [security2:error] [pid 358661:tid 358723] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SNwlWhjQfpOo60_HWlwAAVTo"]
[Tue Jul 21 08:04:23.886250 2026] [security2:error] [pid 358661:tid 358879] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SNwlWhjQfpOo60_HWlwAAVTo"]
[Tue Jul 21 08:04:24.021272 2026] [security2:error] [pid 358661:tid 358669] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SOAlWhjQfpOo60_HWmQAAYwQ"]
[Tue Jul 21 08:04:24.021417 2026] [security2:error] [pid 358661:tid 358893] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SOAlWhjQfpOo60_HWmQAAYwQ"]
[Tue Jul 21 08:04:24.041730 2026] [security2:error] [pid 358661:tid 358766] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/ty.php"] [unique_id "al9SOAlWhjQfpOo60_HWmgAAGmU"]
[Tue Jul 21 08:04:24.113612 2026] [security2:error] [pid 358661:tid 358861] [client 20.151.10.161:28550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/bthil.php"] [unique_id "al9SOAlWhjQfpOo60_HWnQAAAEM"]
[Tue Jul 21 08:04:24.566503 2026] [security2:error] [pid 352421:tid 352648] [client 20.151.10.161:28591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/7.php"] [unique_id "al9SOMJSWzG9jbYOtu5IjwAAAOY"]
[Tue Jul 21 08:04:24.762752 2026] [security2:error] [pid 352421:tid 352505] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SOMJSWzG9jbYOtu5IkgAAqVM"]
[Tue Jul 21 08:04:24.762927 2026] [security2:error] [pid 352421:tid 352587] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SOMJSWzG9jbYOtu5IkgAAqVM"]
[Tue Jul 21 08:04:24.844846 2026] [security2:error] [pid 358661:tid 358854] [client 65.21.113.253:39536] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SOAlWhjQfpOo60_HWogAAADw"]
[Tue Jul 21 08:04:25.151506 2026] [security2:error] [pid 352421:tid 352677] [client 20.151.10.161:28578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/8.php"] [unique_id "al9SOcJSWzG9jbYOtu5InAAAAQM"]
[Tue Jul 21 08:04:25.394366 2026] [security2:error] [pid 358661:tid 358813] [client 20.220.225.223:34215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wilkermoronicriminalista.com"] [uri "/ms.php"] [unique_id "al9SOQlWhjQfpOo60_HWrwAAABM"]
[Tue Jul 21 08:04:25.418485 2026] [security2:error] [pid 358661:tid 358844] [client 102.206.115.33:64762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SOQlWhjQfpOo60_HWsAAAADI"]
[Tue Jul 21 08:04:25.418676 2026] [security2:error] [pid 358661:tid 358844] [client 102.206.115.33:64762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SOQlWhjQfpOo60_HWsAAAADI"]
[Tue Jul 21 08:04:25.476156 2026] [security2:error] [pid 358661:tid 358721] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/155.php"] [unique_id "al9SOQlWhjQfpOo60_HWsQAAbzg"]
[Tue Jul 21 08:04:25.492150 2026] [security2:error] [pid 358661:tid 358735] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/ops.php"] [unique_id "al9SOQlWhjQfpOo60_HWswAAZEY"]
[Tue Jul 21 08:04:25.511380 2026] [security2:error] [pid 358661:tid 358691] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/ingfo.php"] [unique_id "al9SOQlWhjQfpOo60_HWtAAAMBo"]
[Tue Jul 21 08:04:25.524862 2026] [security2:error] [pid 352421:tid 352627] [client 20.151.10.161:28238] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ibericaladrilhos.com.br"] [uri "/1.php"] [unique_id "al9SOcJSWzG9jbYOtu5IpgAAANE"]
[Tue Jul 21 08:04:25.524979 2026] [security2:error] [pid 352421:tid 352627] [client 20.151.10.161:28238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/1.php"] [unique_id "al9SOcJSWzG9jbYOtu5IpgAAANE"]
[Tue Jul 21 08:04:25.555696 2026] [security2:error] [pid 358661:tid 358744] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/error_log.php"] [unique_id "al9SOQlWhjQfpOo60_HWtQAAFU8"]
[Tue Jul 21 08:04:25.585695 2026] [security2:error] [pid 358661:tid 358741] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/ok.php"] [unique_id "al9SOQlWhjQfpOo60_HWuAAAJ0w"]
[Tue Jul 21 08:04:25.590063 2026] [security2:error] [pid 358661:tid 358822] [client 35.231.89.254:55906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "catalaourgente.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9SOQlWhjQfpOo60_HWuQAAABw"]
[Tue Jul 21 08:04:25.608631 2026] [security2:error] [pid 358661:tid 358776] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/mac.php"] [unique_id "al9SOQlWhjQfpOo60_HWugAAHW8"]
[Tue Jul 21 08:04:25.618236 2026] [security2:error] [pid 358661:tid 358840] [client 106.215.181.8:9228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SOQlWhjQfpOo60_HWuwAAAC4"]
[Tue Jul 21 08:04:25.618362 2026] [security2:error] [pid 358661:tid 358840] [client 106.215.181.8:9228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SOQlWhjQfpOo60_HWuwAAAC4"]
[Tue Jul 21 08:04:25.623921 2026] [security2:error] [pid 358661:tid 358684] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wefile.php"] [unique_id "al9SOQlWhjQfpOo60_HWvAAASxM"]
[Tue Jul 21 08:04:25.629899 2026] [security2:error] [pid 352421:tid 352566] [client 136.144.33.28:25475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SOcJSWzG9jbYOtu5IpwAAAJQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:04:25.642396 2026] [security2:error] [pid 358661:tid 358792] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9SOQlWhjQfpOo60_HWvQAAQn8"]
[Tue Jul 21 08:04:25.817278 2026] [security2:error] [pid 358661:tid 358908] [client 182.8.255.181:10147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SOQlWhjQfpOo60_HWvgAAAHI"]
[Tue Jul 21 08:04:25.817420 2026] [security2:error] [pid 358661:tid 358908] [client 182.8.255.181:10147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SOQlWhjQfpOo60_HWvgAAAHI"]
[Tue Jul 21 08:04:25.826345 2026] [security2:error] [pid 352421:tid 352623] [client 20.151.10.161:28603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/100.php"] [unique_id "al9SOcJSWzG9jbYOtu5IqwAAAM0"]
[Tue Jul 21 08:04:26.111121 2026] [security2:error] [pid 352421:tid 352551] [client 20.151.10.161:28241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/about.php"] [unique_id "al9SOsJSWzG9jbYOtu5IsQAAAIU"]
[Tue Jul 21 08:04:26.162341 2026] [security2:error] [pid 358661:tid 358743] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SOQlWhjQfpOo60_HWvwAAIE4"]
[Tue Jul 21 08:04:26.162557 2026] [security2:error] [pid 358661:tid 358826] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SOQlWhjQfpOo60_HWvwAAIE4"]
[Tue Jul 21 08:04:26.481793 2026] [security2:error] [pid 358661:tid 358797] [client 20.151.10.161:28035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/admin.php"] [unique_id "al9SOglWhjQfpOo60_HWwgAAAAM"]
[Tue Jul 21 08:04:26.627148 2026] [security2:error] [pid 352421:tid 352613] [client 103.78.200.11:58418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SOsJSWzG9jbYOtu5IugAAAMM"]
[Tue Jul 21 08:04:26.627255 2026] [security2:error] [pid 352421:tid 352613] [client 103.78.200.11:58418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SOsJSWzG9jbYOtu5IugAAAMM"]
[Tue Jul 21 08:04:26.630089 2026] [security2:error] [pid 358661:tid 358888] [client 54.39.203.208:49070] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "weseguro.com.br"] [uri "/robots.txt"] [unique_id "al9SOglWhjQfpOo60_HWxQAAAF4"]
[Tue Jul 21 08:04:26.630192 2026] [security2:error] [pid 358661:tid 358888] [client 54.39.203.208:49070] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "weseguro.com.br"] [uri "/robots.txt"] [unique_id "al9SOglWhjQfpOo60_HWxQAAAF4"]
[Tue Jul 21 08:04:26.752117 2026] [security2:error] [pid 358661:tid 358678] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al9SOglWhjQfpOo60_HWxgAAfw0"]
[Tue Jul 21 08:04:26.785147 2026] [security2:error] [pid 358661:tid 358786] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-admin/js/"] [unique_id "al9SOglWhjQfpOo60_HWxwAAPXk"]
[Tue Jul 21 08:04:26.808257 2026] [security2:error] [pid 358661:tid 358742] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9SOglWhjQfpOo60_HWyAAAfE0"]
[Tue Jul 21 08:04:26.856893 2026] [security2:error] [pid 352421:tid 352663] [client 87.116.180.198:27161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SOsJSWzG9jbYOtu5IvwAAAPU"]
[Tue Jul 21 08:04:26.857017 2026] [security2:error] [pid 352421:tid 352663] [client 87.116.180.198:27161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SOsJSWzG9jbYOtu5IvwAAAPU"]
[Tue Jul 21 08:04:26.967002 2026] [security2:error] [pid 358661:tid 358856] [client 20.151.10.161:28257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/edit.php"] [unique_id "al9SOglWhjQfpOo60_HWywAAAD4"]
[Tue Jul 21 08:04:27.072809 2026] [security2:error] [pid 352421:tid 352629] [client 103.29.114.44:12704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SO8JSWzG9jbYOtu5IxAAAANM"]
[Tue Jul 21 08:04:27.072930 2026] [security2:error] [pid 352421:tid 352629] [client 103.29.114.44:12704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SO8JSWzG9jbYOtu5IxAAAANM"]
[Tue Jul 21 08:04:27.432039 2026] [security2:error] [pid 352421:tid 352650] [client 35.231.89.254:56246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9SO8JSWzG9jbYOtu5IxgAAAOg"]
[Tue Jul 21 08:04:27.851388 2026] [security2:error] [pid 358661:tid 358772] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wordpress/wp-admin/maint/"] [unique_id "al9SOwlWhjQfpOo60_HW2wAAK2s"]
[Tue Jul 21 08:04:27.898547 2026] [security2:error] [pid 358661:tid 358879] [client 117.247.80.59:25000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SOwlWhjQfpOo60_HW3AAAAFU"]
[Tue Jul 21 08:04:27.898712 2026] [security2:error] [pid 358661:tid 358879] [client 117.247.80.59:25000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SOwlWhjQfpOo60_HW3AAAAFU"]
[Tue Jul 21 08:04:28.058095 2026] [security2:error] [pid 352421:tid 352593] [client 20.151.10.161:28531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9SPMJSWzG9jbYOtu5I1AAAAK8"]
[Tue Jul 21 08:04:28.090447 2026] [security2:error] [pid 352421:tid 352610] [client 5.39.1.231:41616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "weseguro.com.br"] [uri "/"] [unique_id "al9SPMJSWzG9jbYOtu5I1QAAAMA"]
[Tue Jul 21 08:04:28.090549 2026] [security2:error] [pid 352421:tid 352610] [client 5.39.1.231:41616] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "weseguro.com.br"] [uri "/"] [unique_id "al9SPMJSWzG9jbYOtu5I1QAAAMA"]
[Tue Jul 21 08:04:28.164006 2026] [security2:error] [pid 358661:tid 358809] [client 35.231.89.254:56601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9SOwlWhjQfpOo60_HW3QAAAA8"]
[Tue Jul 21 08:04:28.244334 2026] [security2:error] [pid 358661:tid 358764] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/like.php"] [unique_id "al9SPAlWhjQfpOo60_HW3wAAQWM"]
[Tue Jul 21 08:04:28.271104 2026] [security2:error] [pid 358661:tid 358710] [remote 172.245.102.5:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "expovilhena.com"] [uri "/"] [unique_id "al9SPAlWhjQfpOo60_HW4AAARC0"], referer: http://expovilhena.com/
[Tue Jul 21 08:04:28.299054 2026] [security2:error] [pid 358661:tid 358694] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/.well-known/about.php"] [unique_id "al9SPAlWhjQfpOo60_HW4QAAFB0"]
[Tue Jul 21 08:04:28.340019 2026] [security2:error] [pid 358661:tid 358696] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9SPAlWhjQfpOo60_HW4gAAMh8"]
[Tue Jul 21 08:04:28.354771 2026] [security2:error] [pid 358661:tid 358778] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-admin/css/"] [unique_id "al9SPAlWhjQfpOo60_HW4wAAb3E"]
[Tue Jul 21 08:04:28.522468 2026] [security2:error] [pid 358661:tid 358876] [client 20.151.10.161:28267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/f6.php"] [unique_id "al9SPAlWhjQfpOo60_HW6AAAAFI"]
[Tue Jul 21 08:04:28.802436 2026] [security2:error] [pid 352421:tid 352423] [remote 68.178.165.65:54256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/wp-login.php"] [unique_id "al9SPMJSWzG9jbYOtu5I4AAA3QE"]
[Tue Jul 21 08:04:28.934405 2026] [security2:error] [pid 352421:tid 352641] [client 35.231.89.254:56221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9SPMJSWzG9jbYOtu5I3gAAAN8"]
[Tue Jul 21 08:04:29.018962 2026] [security2:error] [pid 358661:tid 358811] [client 198.54.128.138:60070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9SPQlWhjQfpOo60_HW7wAAABE"]
[Tue Jul 21 08:04:29.019056 2026] [security2:error] [pid 358661:tid 358811] [client 198.54.128.138:60070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9SPQlWhjQfpOo60_HW7wAAABE"]
[Tue Jul 21 08:04:29.133639 2026] [security2:error] [pid 352421:tid 352446] [remote 172.245.102.5:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "expovilhena.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al9SPcJSWzG9jbYOtu5I6QAAmBg"], referer: http://expovilhena.com/wp-includes/css/buttons.css
[Tue Jul 21 08:04:29.224565 2026] [security2:error] [pid 358661:tid 358808] [client 20.151.10.161:28094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/inputs.php"] [unique_id "al9SPQlWhjQfpOo60_HXGQAAAA4"]
[Tue Jul 21 08:04:29.278248 2026] [security2:error] [pid 358661:tid 358693] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SPQlWhjQfpOo60_HXIAAALBw"]
[Tue Jul 21 08:04:29.278399 2026] [security2:error] [pid 358661:tid 358838] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SPQlWhjQfpOo60_HXIAAALBw"]
[Tue Jul 21 08:04:29.372810 2026] [security2:error] [pid 358661:tid 358847] [client 178.153.91.96:55129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SPQlWhjQfpOo60_HXJwAAADU"]
[Tue Jul 21 08:04:29.372932 2026] [security2:error] [pid 358661:tid 358847] [client 178.153.91.96:55129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SPQlWhjQfpOo60_HXJwAAADU"]
[Tue Jul 21 08:04:29.498121 2026] [security2:error] [pid 358661:tid 358921] [client 20.29.126.15:2895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/amax.php"] [unique_id "al9SPQlWhjQfpOo60_HXKgAAAH8"]
[Tue Jul 21 08:04:29.629369 2026] [security2:error] [pid 352421:tid 352581] [client 37.140.223.68:55211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SPcJSWzG9jbYOtu5I9QAAAKM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:04:29.680978 2026] [security2:error] [pid 352421:tid 352603] [client 35.231.89.254:56525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9SPcJSWzG9jbYOtu5I8AAAALk"]
[Tue Jul 21 08:04:29.685573 2026] [security2:error] [pid 358661:tid 358746] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al9SPQlWhjQfpOo60_HXLAAAL1E"]
[Tue Jul 21 08:04:29.708963 2026] [security2:error] [pid 358661:tid 358736] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/pucci.php"] [unique_id "al9SPQlWhjQfpOo60_HXLQAAOUc"]
[Tue Jul 21 08:04:29.729792 2026] [security2:error] [pid 352421:tid 352573] [client 20.151.10.161:28058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/av.php"] [unique_id "al9SPcJSWzG9jbYOtu5I9gAAAJs"]
[Tue Jul 21 08:04:29.733638 2026] [security2:error] [pid 358661:tid 358701] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-includes/blocks/details/"] [unique_id "al9SPQlWhjQfpOo60_HXLgAAayQ"]
[Tue Jul 21 08:04:29.751077 2026] [security2:error] [pid 358661:tid 358747] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-includes/blocks/audio/"] [unique_id "al9SPQlWhjQfpOo60_HXMAAAJVI"]
[Tue Jul 21 08:04:29.765950 2026] [security2:error] [pid 358661:tid 358666] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-temp.php"] [unique_id "al9SPQlWhjQfpOo60_HXMgAARQE"]
[Tue Jul 21 08:04:29.782682 2026] [security2:error] [pid 358661:tid 358763] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-includes/blocks/buttons/"] [unique_id "al9SPQlWhjQfpOo60_HXNgAAGmI"]
[Tue Jul 21 08:04:29.798973 2026] [security2:error] [pid 358661:tid 358682] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/xmu.php"] [unique_id "al9SPQlWhjQfpOo60_HXNwAAVxE"]
[Tue Jul 21 08:04:29.832584 2026] [security2:error] [pid 358661:tid 358673] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9SPQlWhjQfpOo60_HXOQAAUQg"]
[Tue Jul 21 08:04:29.854138 2026] [security2:error] [pid 358661:tid 358711] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/puc.php"] [unique_id "al9SPQlWhjQfpOo60_HXOgAAeC4"]
[Tue Jul 21 08:04:29.869829 2026] [security2:error] [pid 358661:tid 358790] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/themes.php"] [unique_id "al9SPQlWhjQfpOo60_HXOwAAe30"]
[Tue Jul 21 08:04:29.879764 2026] [security2:error] [pid 358661:tid 358825] [client 172.233.177.18:44614] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "santotchay.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9SPQlWhjQfpOo60_HXPAAAAB8"]
[Tue Jul 21 08:04:29.887125 2026] [security2:error] [pid 358661:tid 358745] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-includes/Requests/"] [unique_id "al9SPQlWhjQfpOo60_HXPQAAU1A"]
[Tue Jul 21 08:04:29.889113 2026] [security2:error] [pid 352421:tid 352426] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SPcJSWzG9jbYOtu5I-gAAtAQ"]
[Tue Jul 21 08:04:29.889262 2026] [security2:error] [pid 352421:tid 352598] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SPcJSWzG9jbYOtu5I-gAAtAQ"]
[Tue Jul 21 08:04:29.929598 2026] [security2:error] [pid 358661:tid 358788] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/8.php"] [unique_id "al9SPQlWhjQfpOo60_HXPwAAG3s"]
[Tue Jul 21 08:04:29.945196 2026] [security2:error] [pid 358661:tid 358688] [remote 20.206.105.145:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/1.php"] [unique_id "al9SPQlWhjQfpOo60_HXQAAAZxc"]
[Tue Jul 21 08:04:29.945326 2026] [security2:error] [pid 358661:tid 358688] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/1.php"] [unique_id "al9SPQlWhjQfpOo60_HXQAAAZxc"]
[Tue Jul 21 08:04:29.967619 2026] [security2:error] [pid 358661:tid 358732] [remote 195.26.244.42:33058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-login.php"] [unique_id "al9SPQlWhjQfpOo60_HXQQAAB0M"]
[Tue Jul 21 08:04:29.986264 2026] [security2:error] [pid 358661:tid 358850] [client 117.210.135.0:63697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SPQlWhjQfpOo60_HXQgAAADg"]
[Tue Jul 21 08:04:29.986375 2026] [security2:error] [pid 358661:tid 358850] [client 117.210.135.0:63697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SPQlWhjQfpOo60_HXQgAAADg"]
[Tue Jul 21 08:04:29.991805 2026] [security2:error] [pid 358661:tid 358867] [client 172.233.177.18:44614] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "santotchay.com.br"] [uri "/"] [unique_id "al9SPQlWhjQfpOo60_HXQwAAAEk"]
[Tue Jul 21 08:04:30.013613 2026] [security2:error] [pid 358661:tid 358919] [client 122.179.91.63:25907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SPglWhjQfpOo60_HXRAAAAH0"]
[Tue Jul 21 08:04:30.013782 2026] [security2:error] [pid 358661:tid 358919] [client 122.179.91.63:25907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SPglWhjQfpOo60_HXRAAAAH0"]
[Tue Jul 21 08:04:30.016230 2026] [security2:error] [pid 358661:tid 358704] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/100.php"] [unique_id "al9SPglWhjQfpOo60_HXRQAAISc"]
[Tue Jul 21 08:04:30.016582 2026] [security2:error] [pid 358661:tid 358697] [remote 172.245.102.5:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "expovilhena.com"] [uri "/media/system/js/core.js"] [unique_id "al9SPglWhjQfpOo60_HXRgAARyA"], referer: http://expovilhena.com/media/system/js/core.js
[Tue Jul 21 08:04:30.045518 2026] [security2:error] [pid 358661:tid 358774] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/about.php"] [unique_id "al9SPglWhjQfpOo60_HXRwAAK20"]
[Tue Jul 21 08:04:30.156516 2026] [security2:error] [pid 358661:tid 358812] [client 2.57.122.202:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.agrocibus.com"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9SPglWhjQfpOo60_HXSwAAABI"]
[Tue Jul 21 08:04:30.297174 2026] [security2:error] [pid 358661:tid 358905] [client 20.151.10.161:28251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9SPglWhjQfpOo60_HXTAAAAG8"]
[Tue Jul 21 08:04:30.318696 2026] [security2:error] [pid 352421:tid 352663] [client 109.60.28.94:2553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SPsJSWzG9jbYOtu5JAQAAAPU"]
[Tue Jul 21 08:04:30.319251 2026] [security2:error] [pid 352421:tid 352663] [client 109.60.28.94:2553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SPsJSWzG9jbYOtu5JAQAAAPU"]
[Tue Jul 21 08:04:30.432531 2026] [security2:error] [pid 352421:tid 352645] [client 35.231.89.254:56934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9SPsJSWzG9jbYOtu5JAAAAAOM"]
[Tue Jul 21 08:04:30.505646 2026] [proxy:error] [pid 358661:tid 358902] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:04:30.505712 2026] [proxy_http:error] [pid 358661:tid 358902] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:04:30.506144 2026] [proxy:error] [pid 358661:tid 358902] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:04:30.506165 2026] [proxy_http:error] [pid 358661:tid 358902] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:04:30.625710 2026] [security2:error] [pid 352421:tid 352596] [client 175.144.82.48:65275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SPsJSWzG9jbYOtu5JCwAAALI"]
[Tue Jul 21 08:04:30.626360 2026] [security2:error] [pid 352421:tid 352596] [client 175.144.82.48:65275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SPsJSWzG9jbYOtu5JCwAAALI"]
[Tue Jul 21 08:04:30.824193 2026] [security2:error] [pid 358661:tid 358810] [client 20.151.10.161:28529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9SPglWhjQfpOo60_HXVQAAABA"]
[Tue Jul 21 08:04:30.911321 2026] [security2:error] [pid 352421:tid 352565] [client 103.166.103.129:58102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SPsJSWzG9jbYOtu5JDwAAAJM"]
[Tue Jul 21 08:04:30.911438 2026] [security2:error] [pid 352421:tid 352565] [client 103.166.103.129:58102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SPsJSWzG9jbYOtu5JDwAAAJM"]
[Tue Jul 21 08:04:31.010791 2026] [security2:error] [pid 358661:tid 358713] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/about.php"] [unique_id "al9SPwlWhjQfpOo60_HXXQAAYDA"]
[Tue Jul 21 08:04:31.162759 2026] [security2:error] [pid 358661:tid 358834] [client 35.231.89.254:57513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9SPglWhjQfpOo60_HXWQAAACg"]
[Tue Jul 21 08:04:31.259797 2026] [security2:error] [pid 358661:tid 358800] [client 38.100.221.102:17790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SPwlWhjQfpOo60_HXYgAAAAY"]
[Tue Jul 21 08:04:31.260210 2026] [security2:error] [pid 358661:tid 358800] [client 38.100.221.102:17790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SPwlWhjQfpOo60_HXYgAAAAY"]
[Tue Jul 21 08:04:31.482225 2026] [proxy:error] [pid 358661:tid 358875] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:04:31.482299 2026] [proxy_http:error] [pid 358661:tid 358875] [client 205.210.31.181:62626] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:04:31.482968 2026] [proxy:error] [pid 358661:tid 358875] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:04:31.483010 2026] [proxy_http:error] [pid 358661:tid 358875] [client 205.210.31.181:62626] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:04:31.921329 2026] [security2:error] [pid 358661:tid 358818] [client 20.151.10.161:27918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-blog.php"] [unique_id "al9SPwlWhjQfpOo60_HXcQAAABg"]
[Tue Jul 21 08:04:32.000716 2026] [security2:error] [pid 358661:tid 358877] [client 35.231.89.254:57514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9SPwlWhjQfpOo60_HXbwAAAFM"]
[Tue Jul 21 08:04:32.293588 2026] [security2:error] [pid 358661:tid 358758] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SQAlWhjQfpOo60_HXdQAAIV0"]
[Tue Jul 21 08:04:32.293733 2026] [security2:error] [pid 358661:tid 358827] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SQAlWhjQfpOo60_HXdQAAIV0"]
[Tue Jul 21 08:04:32.328125 2026] [security2:error] [pid 358661:tid 358770] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/admin.php"] [unique_id "al9SQAlWhjQfpOo60_HXdgAAZGk"]
[Tue Jul 21 08:04:32.377223 2026] [security2:error] [pid 358661:tid 358727] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/admin.php"] [unique_id "al9SQAlWhjQfpOo60_HXdwAAMD4"]
[Tue Jul 21 08:04:32.421498 2026] [security2:error] [pid 358661:tid 358689] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/edit.php"] [unique_id "al9SQAlWhjQfpOo60_HXeAAAJxg"]
[Tue Jul 21 08:04:32.457142 2026] [security2:error] [pid 358661:tid 358683] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9SQAlWhjQfpOo60_HXeQAAHBI"]
[Tue Jul 21 08:04:32.477685 2026] [security2:error] [pid 358661:tid 358715] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/f6.php"] [unique_id "al9SQAlWhjQfpOo60_HXegAAHTI"]
[Tue Jul 21 08:04:32.491444 2026] [security2:error] [pid 358661:tid 358815] [client 20.29.126.15:6720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/moon.php"] [unique_id "al9SQAlWhjQfpOo60_HXewAAABU"]
[Tue Jul 21 08:04:32.511545 2026] [security2:error] [pid 358661:tid 358706] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/inputs.php"] [unique_id "al9SQAlWhjQfpOo60_HXfQAAUik"]
[Tue Jul 21 08:04:32.528565 2026] [security2:error] [pid 358661:tid 358768] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/inputs.php"] [unique_id "al9SQAlWhjQfpOo60_HXiQAACmc"]
[Tue Jul 21 08:04:32.635351 2026] [security2:error] [pid 358661:tid 358856] [client 20.151.10.161:28282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9SQAlWhjQfpOo60_HXjgAAAD4"]
[Tue Jul 21 08:04:32.742933 2026] [security2:error] [pid 352421:tid 352649] [client 35.231.89.254:57696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9SQMJSWzG9jbYOtu5JJAAAAOc"]
[Tue Jul 21 08:04:32.934750 2026] [security2:error] [pid 358661:tid 358831] [client 20.151.10.161:28239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/adminfuns.php"] [unique_id "al9SQAlWhjQfpOo60_HXnAAAACU"]
[Tue Jul 21 08:04:33.148253 2026] [security2:error] [pid 352421:tid 352657] [client 41.68.90.219:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SQcJSWzG9jbYOtu5JMgAAAO8"]
[Tue Jul 21 08:04:33.149223 2026] [security2:error] [pid 352421:tid 352657] [client 41.68.90.219:49796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SQcJSWzG9jbYOtu5JMgAAAO8"]
[Tue Jul 21 08:04:33.291524 2026] [security2:error] [pid 352421:tid 352567] [client 193.36.225.55:21707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SQcJSWzG9jbYOtu5JNAAAAJU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:04:33.315513 2026] [security2:error] [pid 358661:tid 358860] [client 20.151.10.161:28286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/goods.php"] [unique_id "al9SQQlWhjQfpOo60_HXqwAAAEI"]
[Tue Jul 21 08:04:33.376272 2026] [security2:error] [pid 358661:tid 358677] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/av.php"] [unique_id "al9SQQlWhjQfpOo60_HXrAAAJgw"]
[Tue Jul 21 08:04:33.473096 2026] [security2:error] [pid 358661:tid 358795] [client 198.54.128.138:60084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9SQQlWhjQfpOo60_HXsAAAAAE"]
[Tue Jul 21 08:04:33.473213 2026] [security2:error] [pid 358661:tid 358795] [client 198.54.128.138:60084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9SQQlWhjQfpOo60_HXsAAAAAE"]
[Tue Jul 21 08:04:33.506338 2026] [security2:error] [pid 358661:tid 358816] [client 35.231.89.254:58056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9SQQlWhjQfpOo60_HXqAAAABY"]
[Tue Jul 21 08:04:33.731694 2026] [security2:error] [pid 358661:tid 358808] [client 20.151.10.161:28233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ms-edit.php"] [unique_id "al9SQQlWhjQfpOo60_HXtQAAAA4"]
[Tue Jul 21 08:04:34.166761 2026] [security2:error] [pid 358661:tid 358735] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SQglWhjQfpOo60_HXtwAAWkY"]
[Tue Jul 21 08:04:34.166945 2026] [security2:error] [pid 358661:tid 358884] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SQglWhjQfpOo60_HXtwAAWkY"]
[Tue Jul 21 08:04:34.202943 2026] [security2:error] [pid 352421:tid 352433] [remote 46.105.28.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "printcom.com.br"] [uri "/wp-login.php"] [unique_id "al9SQsJSWzG9jbYOtu5JQwAAyQs"]
[Tue Jul 21 08:04:34.223445 2026] [security2:error] [pid 358661:tid 358872] [client 120.56.162.40:49952] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SQglWhjQfpOo60_HXugAAAE4"]
[Tue Jul 21 08:04:34.223558 2026] [security2:error] [pid 358661:tid 358872] [client 120.56.162.40:49952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SQglWhjQfpOo60_HXugAAAE4"]
[Tue Jul 21 08:04:34.229602 2026] [security2:error] [pid 358661:tid 358744] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/classwithtostring.php"] [unique_id "al9SQglWhjQfpOo60_HXuwAAJU8"]
[Tue Jul 21 08:04:34.253216 2026] [security2:error] [pid 352421:tid 352600] [client 35.231.89.254:57235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9SQsJSWzG9jbYOtu5JQAAAALY"]
[Tue Jul 21 08:04:34.259270 2026] [security2:error] [pid 358661:tid 358741] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9SQglWhjQfpOo60_HXvAAAVkw"]
[Tue Jul 21 08:04:34.276617 2026] [security2:error] [pid 358661:tid 358776] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-blog.php"] [unique_id "al9SQglWhjQfpOo60_HXvQAAUW8"]
[Tue Jul 21 08:04:34.313904 2026] [security2:error] [pid 358661:tid 358792] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-includes/js/jquery/"] [unique_id "al9SQglWhjQfpOo60_HXvwAAV38"]
[Tue Jul 21 08:04:34.329122 2026] [security2:error] [pid 358661:tid 358743] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9SQglWhjQfpOo60_HXwAAAE04"]
[Tue Jul 21 08:04:34.356749 2026] [security2:error] [pid 358661:tid 358760] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/adminfuns.php"] [unique_id "al9SQglWhjQfpOo60_HXwQAAW18"]
[Tue Jul 21 08:04:34.407904 2026] [security2:error] [pid 358661:tid 358777] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/goods.php"] [unique_id "al9SQglWhjQfpOo60_HXwgAAe3A"]
[Tue Jul 21 08:04:34.408550 2026] [security2:error] [pid 358661:tid 358824] [client 20.151.10.161:28080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/222.php"] [unique_id "al9SQglWhjQfpOo60_HXwwAAAB4"]
[Tue Jul 21 08:04:34.427781 2026] [security2:error] [pid 358661:tid 358678] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/ms-edit.php"] [unique_id "al9SQglWhjQfpOo60_HXxAAAKg0"]
[Tue Jul 21 08:04:34.444802 2026] [security2:error] [pid 358661:tid 358789] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/222.php"] [unique_id "al9SQglWhjQfpOo60_HXxQAAG3w"]
[Tue Jul 21 08:04:34.482514 2026] [security2:error] [pid 358661:tid 358786] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9SQglWhjQfpOo60_HXxwAAMXk"]
[Tue Jul 21 08:04:34.498742 2026] [security2:error] [pid 358661:tid 358707] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-includes/css/dist/"] [unique_id "al9SQglWhjQfpOo60_HXyQAAOCo"]
[Tue Jul 21 08:04:34.532591 2026] [security2:error] [pid 358661:tid 358772] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9SQglWhjQfpOo60_HXygAAfWs"]
[Tue Jul 21 08:04:34.552888 2026] [security2:error] [pid 352421:tid 352498] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SQsJSWzG9jbYOtu5JTAAArEw"]
[Tue Jul 21 08:04:34.553083 2026] [security2:error] [pid 352421:tid 352590] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SQsJSWzG9jbYOtu5JTAAArEw"]
[Tue Jul 21 08:04:34.570271 2026] [security2:error] [pid 358661:tid 358687] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-includes/l10n/"] [unique_id "al9SQglWhjQfpOo60_HXywAAYxY"]
[Tue Jul 21 08:04:34.628640 2026] [security2:error] [pid 358661:tid 358764] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-content/uploads/"] [unique_id "al9SQglWhjQfpOo60_HXzAAAU2M"]
[Tue Jul 21 08:04:34.902314 2026] [security2:error] [pid 352421:tid 352492] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SQsJSWzG9jbYOtu5JVgAA5kY"]
[Tue Jul 21 08:04:34.902495 2026] [security2:error] [pid 352421:tid 352648] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SQsJSWzG9jbYOtu5JVgAA5kY"]
[Tue Jul 21 08:04:34.943516 2026] [security2:error] [pid 358661:tid 358921] [client 74.7.241.137:44664] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gradiente.com"] [uri "/robots.txt"] [unique_id "al9SQglWhjQfpOo60_HX0gAAf2E"]
[Tue Jul 21 08:04:34.986114 2026] [security2:error] [pid 358661:tid 358873] [client 35.231.89.254:58406] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9SQglWhjQfpOo60_HXzwAAAE8"]
[Tue Jul 21 08:04:34.986157 2026] [security2:error] [pid 358661:tid 358873] [client 35.231.89.254:58406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9SQglWhjQfpOo60_HXzwAAAE8"]
[Tue Jul 21 08:04:35.114122 2026] [security2:error] [pid 358661:tid 358696] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/raw.php"] [unique_id "al9SQwlWhjQfpOo60_HX0wAAIR8"]
[Tue Jul 21 08:04:35.129173 2026] [security2:error] [pid 358661:tid 358778] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/abcd.php"] [unique_id "al9SQwlWhjQfpOo60_HX1AAAenE"]
[Tue Jul 21 08:04:35.146542 2026] [security2:error] [pid 358661:tid 358867] [client 202.143.127.214:57932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SQwlWhjQfpOo60_HX1QAAAEk"]
[Tue Jul 21 08:04:35.146654 2026] [security2:error] [pid 358661:tid 358867] [client 202.143.127.214:57932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SQwlWhjQfpOo60_HX1QAAAEk"]
[Tue Jul 21 08:04:35.167218 2026] [security2:error] [pid 358661:tid 358756] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/a1.php"] [unique_id "al9SQwlWhjQfpOo60_HX1gAAMls"]
[Tue Jul 21 08:04:35.218029 2026] [security2:error] [pid 358661:tid 358782] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9SQwlWhjQfpOo60_HX2AAAZHU"]
[Tue Jul 21 08:04:35.269545 2026] [security2:error] [pid 358661:tid 358757] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9SQwlWhjQfpOo60_HX2gAAS1w"]
[Tue Jul 21 08:04:35.282507 2026] [security2:error] [pid 358661:tid 358860] [client 20.29.126.15:6764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/ws83.php"] [unique_id "al9SQwlWhjQfpOo60_HX3AAAAEI"]
[Tue Jul 21 08:04:35.285209 2026] [security2:error] [pid 358661:tid 358781] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9SQwlWhjQfpOo60_HX3QAAFXQ"]
[Tue Jul 21 08:04:35.300743 2026] [security2:error] [pid 358661:tid 358785] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-content/"] [unique_id "al9SQwlWhjQfpOo60_HX3gAAJng"]
[Tue Jul 21 08:04:35.323656 2026] [security2:error] [pid 358661:tid 358845] [client 20.151.10.161:28166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9SQwlWhjQfpOo60_HX3wAAADM"]
[Tue Jul 21 08:04:35.477319 2026] [security2:error] [pid 358661:tid 358720] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SQwlWhjQfpOo60_HX5AAABTc"]
[Tue Jul 21 08:04:35.477464 2026] [security2:error] [pid 358661:tid 358799] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SQwlWhjQfpOo60_HX5AAABTc"]
[Tue Jul 21 08:04:35.543723 2026] [security2:error] [pid 358661:tid 358804] [client 35.231.89.254:56955] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9SQwlWhjQfpOo60_HX5QAAAAo"]
[Tue Jul 21 08:04:35.543831 2026] [security2:error] [pid 358661:tid 358804] [client 35.231.89.254:56955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "catalaourgente.com"] [uri "/xmlrpc.php"] [unique_id "al9SQwlWhjQfpOo60_HX5QAAAAo"]
[Tue Jul 21 08:04:36.032347 2026] [security2:error] [pid 358661:tid 358856] [client 102.206.115.33:62478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SRAlWhjQfpOo60_HX6gAAAD4"]
[Tue Jul 21 08:04:36.036574 2026] [security2:error] [pid 358661:tid 358856] [client 102.206.115.33:62478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SRAlWhjQfpOo60_HX6gAAAD4"]
[Tue Jul 21 08:04:36.141341 2026] [security2:error] [pid 358661:tid 358724] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/simple.php"] [unique_id "al9SRAlWhjQfpOo60_HX6wAAPTs"]
[Tue Jul 21 08:04:36.176602 2026] [security2:error] [pid 358661:tid 358857] [client 106.215.181.8:16413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SRAlWhjQfpOo60_HX7AAAAD8"]
[Tue Jul 21 08:04:36.176709 2026] [security2:error] [pid 358661:tid 358857] [client 106.215.181.8:16413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SRAlWhjQfpOo60_HX7AAAAD8"]
[Tue Jul 21 08:04:36.182405 2026] [security2:error] [pid 358661:tid 358733] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/xxx.php"] [unique_id "al9SRAlWhjQfpOo60_HX7QAAAkQ"]
[Tue Jul 21 08:04:36.191978 2026] [security2:error] [pid 358661:tid 358835] [client 20.151.10.161:28515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9SRAlWhjQfpOo60_HX7gAAACk"]
[Tue Jul 21 08:04:36.252340 2026] [security2:error] [pid 352421:tid 352649] [client 184.75.221.3:42870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9SRMJSWzG9jbYOtu5JbgAAAOc"]
[Tue Jul 21 08:04:36.252431 2026] [security2:error] [pid 352421:tid 352649] [client 184.75.221.3:42870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9SRMJSWzG9jbYOtu5JbgAAAOc"]
[Tue Jul 21 08:04:36.311002 2026] [security2:error] [pid 352421:tid 352660] [client 182.8.255.181:17524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SRMJSWzG9jbYOtu5JgAAAAPI"]
[Tue Jul 21 08:04:36.311107 2026] [security2:error] [pid 352421:tid 352660] [client 182.8.255.181:17524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SRMJSWzG9jbYOtu5JgAAAAPI"]
[Tue Jul 21 08:04:36.607786 2026] [security2:error] [pid 358661:tid 358671] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/hypo.php"] [unique_id "al9SRAlWhjQfpOo60_HX-QAARQY"]
[Tue Jul 21 08:04:36.687920 2026] [security2:error] [pid 352421:tid 352588] [client 65.21.113.253:58946] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SRMJSWzG9jbYOtu5JjAAAAKo"]
[Tue Jul 21 08:04:37.124644 2026] [security2:error] [pid 358661:tid 358730] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SRQlWhjQfpOo60_HX_gAAa0E"]
[Tue Jul 21 08:04:37.124811 2026] [security2:error] [pid 358661:tid 358901] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SRQlWhjQfpOo60_HX_gAAa0E"]
[Tue Jul 21 08:04:37.207386 2026] [security2:error] [pid 358661:tid 358821] [client 103.78.200.11:58911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SRQlWhjQfpOo60_HX_wAAABs"]
[Tue Jul 21 08:04:37.211578 2026] [security2:error] [pid 358661:tid 358821] [client 103.78.200.11:58911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SRQlWhjQfpOo60_HX_wAAABs"]
[Tue Jul 21 08:04:37.425317 2026] [security2:error] [pid 358661:tid 358729] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-admin/css/colors/blue/"] [unique_id "al9SRQlWhjQfpOo60_HYAgAAVUA"]
[Tue Jul 21 08:04:37.505413 2026] [security2:error] [pid 358661:tid 358859] [client 87.116.180.198:27271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SRQlWhjQfpOo60_HYAwAAAEE"]
[Tue Jul 21 08:04:37.505565 2026] [security2:error] [pid 358661:tid 358859] [client 87.116.180.198:27271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SRQlWhjQfpOo60_HYAwAAAEE"]
[Tue Jul 21 08:04:37.711496 2026] [security2:error] [pid 358661:tid 358916] [client 20.104.96.117:7973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9SRQlWhjQfpOo60_HYBAAAAHo"]
[Tue Jul 21 08:04:37.755874 2026] [security2:error] [pid 358661:tid 358807] [client 65.21.113.253:48432] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SRQlWhjQfpOo60_HYAQAAAA0"]
[Tue Jul 21 08:04:37.762424 2026] [security2:error] [pid 358661:tid 358921] [client 103.29.114.44:40873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SRQlWhjQfpOo60_HYBwAAAH8"]
[Tue Jul 21 08:04:37.762574 2026] [security2:error] [pid 358661:tid 358921] [client 103.29.114.44:40873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SRQlWhjQfpOo60_HYBwAAAH8"]
[Tue Jul 21 08:04:37.986335 2026] [security2:error] [pid 352421:tid 352651] [client 20.151.10.161:28480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp.php"] [unique_id "al9SRcJSWzG9jbYOtu5JqwAAAOk"]
[Tue Jul 21 08:04:38.066044 2026] [security2:error] [pid 352421:tid 352664] [client 20.104.96.117:7977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9SRsJSWzG9jbYOtu5JrwAAAPY"]
[Tue Jul 21 08:04:38.205689 2026] [security2:error] [pid 358661:tid 358893] [client 193.36.225.54:29757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SRglWhjQfpOo60_HYDgAAAGM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:04:38.387808 2026] [security2:error] [pid 358661:tid 358840] [client 20.151.10.161:28606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/abcd.php"] [unique_id "al9SRglWhjQfpOo60_HYEAAAAC4"]
[Tue Jul 21 08:04:38.414878 2026] [security2:error] [pid 352421:tid 352428] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SRsJSWzG9jbYOtu5JtwAAlAY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:38.451669 2026] [security2:error] [pid 352421:tid 352478] [remote 8.217.108.67:58816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9SRsJSWzG9jbYOtu5JuAAAiTg"]
[Tue Jul 21 08:04:38.515051 2026] [security2:error] [pid 352421:tid 352532] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SRsJSWzG9jbYOtu5JuQAA1m4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:38.518738 2026] [security2:error] [pid 358661:tid 358690] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SRglWhjQfpOo60_HYEQAANxk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:38.539053 2026] [security2:error] [pid 358661:tid 358787] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SRglWhjQfpOo60_HYEwAANXo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:38.556098 2026] [security2:error] [pid 352421:tid 352557] [client 20.104.96.117:7983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/media.php"] [unique_id "al9SRsJSWzG9jbYOtu5JvgAAAIs"]
[Tue Jul 21 08:04:38.594217 2026] [security2:error] [pid 352421:tid 352456] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SRsJSWzG9jbYOtu5JwAAAriI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:38.658437 2026] [security2:error] [pid 352421:tid 352561] [client 117.247.80.59:27686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SRsJSWzG9jbYOtu5JxQAAAI8"]
[Tue Jul 21 08:04:38.658539 2026] [security2:error] [pid 352421:tid 352561] [client 117.247.80.59:27686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SRsJSWzG9jbYOtu5JxQAAAI8"]
[Tue Jul 21 08:04:38.683368 2026] [security2:error] [pid 358661:tid 358740] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/chosen.php"] [unique_id "al9SRglWhjQfpOo60_HYFQAAPks"]
[Tue Jul 21 08:04:38.740550 2026] [security2:error] [pid 352421:tid 352515] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SRsJSWzG9jbYOtu5JxgAAhV0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:38.746769 2026] [security2:error] [pid 358661:tid 358771] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SRglWhjQfpOo60_HYFgAAPWo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:38.810558 2026] [security2:error] [pid 358661:tid 358749] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SRglWhjQfpOo60_HYGAAAH1Q"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:38.847500 2026] [security2:error] [pid 358661:tid 358738] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-includes/block-bindings/"] [unique_id "al9SRglWhjQfpOo60_HYGQAAWkk"]
[Tue Jul 21 08:04:38.885935 2026] [security2:error] [pid 358661:tid 358719] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/file5.php"] [unique_id "al9SRglWhjQfpOo60_HYGgAALzY"]
[Tue Jul 21 08:04:38.908398 2026] [security2:error] [pid 352421:tid 352659] [client 20.151.10.161:28586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/a1.php"] [unique_id "al9SRsJSWzG9jbYOtu5JywAAAPE"]
[Tue Jul 21 08:04:38.911345 2026] [security2:error] [pid 358661:tid 358703] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/file.php"] [unique_id "al9SRglWhjQfpOo60_HYGwAATiY"]
[Tue Jul 21 08:04:38.941512 2026] [security2:error] [pid 358661:tid 358737] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/aa2.php"] [unique_id "al9SRglWhjQfpOo60_HYHQAAVkg"]
[Tue Jul 21 08:04:38.955890 2026] [security2:error] [pid 358661:tid 358672] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/ccou.php"] [unique_id "al9SRglWhjQfpOo60_HYHgAAEgc"]
[Tue Jul 21 08:04:38.966827 2026] [security2:error] [pid 358661:tid 358761] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SRglWhjQfpOo60_HYHwAAV2A"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:38.971594 2026] [security2:error] [pid 358661:tid 358779] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/dr.php"] [unique_id "al9SRglWhjQfpOo60_HYIAAAE3I"]
[Tue Jul 21 08:04:38.999034 2026] [security2:error] [pid 358661:tid 358718] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/file31.php"] [unique_id "al9SRglWhjQfpOo60_HYIQAAfDU"]
[Tue Jul 21 08:04:39.044015 2026] [security2:error] [pid 352421:tid 352426] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SR8JSWzG9jbYOtu5JzwAAtQQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:39.061680 2026] [security2:error] [pid 358661:tid 358700] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SRwlWhjQfpOo60_HYIwAAeyM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:39.148049 2026] [security2:error] [pid 358661:tid 358824] [client 20.104.96.117:7939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/images.php"] [unique_id "al9SRwlWhjQfpOo60_HYJAAAAB4"]
[Tue Jul 21 08:04:39.197636 2026] [security2:error] [pid 358661:tid 358716] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SRwlWhjQfpOo60_HYJQAALTM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:39.231565 2026] [security2:error] [pid 352421:tid 352453] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SR8JSWzG9jbYOtu5J0wAA7R8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:39.284509 2026] [security2:error] [pid 358661:tid 358698] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/file6.php"] [unique_id "al9SRwlWhjQfpOo60_HYJwAAfSE"]
[Tue Jul 21 08:04:39.290607 2026] [security2:error] [pid 358661:tid 358705] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SRwlWhjQfpOo60_HYKAAAGCg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:39.308341 2026] [security2:error] [pid 358661:tid 358731] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SRwlWhjQfpOo60_HYKQAAU0I"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:39.311843 2026] [security2:error] [pid 358661:tid 358734] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/file15.php"] [unique_id "al9SRwlWhjQfpOo60_HYKgAAJEU"]
[Tue Jul 21 08:04:39.326913 2026] [security2:error] [pid 358661:tid 358767] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/jp.php"] [unique_id "al9SRwlWhjQfpOo60_HYKwAAI2Y"]
[Tue Jul 21 08:04:39.342652 2026] [security2:error] [pid 358661:tid 358780] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/f35.php"] [unique_id "al9SRwlWhjQfpOo60_HYLAAABnM"]
[Tue Jul 21 08:04:39.408414 2026] [security2:error] [pid 352421:tid 352437] [remote 161.97.181.232:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.181.97.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9SR8JSWzG9jbYOtu5J1wAA1w8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:04:39.594124 2026] [security2:error] [pid 358661:tid 358901] [client 20.104.96.117:7995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/gecko.php"] [unique_id "al9SRwlWhjQfpOo60_HYLwAAAGs"]
[Tue Jul 21 08:04:39.595912 2026] [security2:error] [pid 358661:tid 358699] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-load.php"] [unique_id "al9SRwlWhjQfpOo60_HYMAAANCI"]
[Tue Jul 21 08:04:39.612095 2026] [security2:error] [pid 358661:tid 358765] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-includes/assets/"] [unique_id "al9SRwlWhjQfpOo60_HYMQAAVWQ"]
[Tue Jul 21 08:04:39.645744 2026] [security2:error] [pid 358661:tid 358773] [remote 20.206.105.145:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "al9SRwlWhjQfpOo60_HYMgAAdmw"]
[Tue Jul 21 08:04:39.667941 2026] [security2:error] [pid 358661:tid 358693] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9SRwlWhjQfpOo60_HYMwAAQRw"]
[Tue Jul 21 08:04:39.737348 2026] [security2:error] [pid 352421:tid 352435] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SR8JSWzG9jbYOtu5J2wAA2g0"]
[Tue Jul 21 08:04:39.737513 2026] [security2:error] [pid 352421:tid 352636] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SR8JSWzG9jbYOtu5J2wAA2g0"]
[Tue Jul 21 08:04:39.905430 2026] [security2:error] [pid 358661:tid 358850] [client 178.153.91.96:33257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SRwlWhjQfpOo60_HYOAAAADg"]
[Tue Jul 21 08:04:39.905588 2026] [security2:error] [pid 358661:tid 358850] [client 178.153.91.96:33257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SRwlWhjQfpOo60_HYOAAAADg"]
[Tue Jul 21 08:04:40.165183 2026] [security2:error] [pid 358661:tid 358833] [client 20.197.192.193:53166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/jj.php"] [unique_id "al9SSAlWhjQfpOo60_HYOwAAACc"]
[Tue Jul 21 08:04:40.345959 2026] [security2:error] [pid 352421:tid 352489] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SSMJSWzG9jbYOtu5J5AAAnkM"]
[Tue Jul 21 08:04:40.346106 2026] [security2:error] [pid 352421:tid 352576] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SSMJSWzG9jbYOtu5J5AAAnkM"]
[Tue Jul 21 08:04:40.510565 2026] [security2:error] [pid 358661:tid 358809] [client 117.210.135.0:64352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SSAlWhjQfpOo60_HYQAAAAA8"]
[Tue Jul 21 08:04:40.510700 2026] [security2:error] [pid 358661:tid 358809] [client 117.210.135.0:64352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SSAlWhjQfpOo60_HYQAAAAA8"]
[Tue Jul 21 08:04:40.570328 2026] [security2:error] [pid 358661:tid 358755] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wp-links.php"] [unique_id "al9SSAlWhjQfpOo60_HYQQAAY1o"]
[Tue Jul 21 08:04:40.585291 2026] [security2:error] [pid 358661:tid 358714] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/solo1.php"] [unique_id "al9SSAlWhjQfpOo60_HYQgAAFjE"]
[Tue Jul 21 08:04:40.600601 2026] [security2:error] [pid 358661:tid 358754] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/sixxis.php"] [unique_id "al9SSAlWhjQfpOo60_HYQwAABVk"]
[Tue Jul 21 08:04:40.616566 2026] [security2:error] [pid 358661:tid 358751] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/2P.update.php"] [unique_id "al9SSAlWhjQfpOo60_HYRQAASlY"]
[Tue Jul 21 08:04:40.632953 2026] [security2:error] [pid 358661:tid 358736] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/a.php"] [unique_id "al9SSAlWhjQfpOo60_HYSAAAYkc"]
[Tue Jul 21 08:04:40.649349 2026] [security2:error] [pid 358661:tid 358701] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/k.php"] [unique_id "al9SSAlWhjQfpOo60_HYSQAALiQ"]
[Tue Jul 21 08:04:40.689106 2026] [security2:error] [pid 358661:tid 358747] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/w.php"] [unique_id "al9SSAlWhjQfpOo60_HYSgAAEVI"]
[Tue Jul 21 08:04:40.706429 2026] [security2:error] [pid 358661:tid 358666] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/insc.php"] [unique_id "al9SSAlWhjQfpOo60_HYTAAAaQE"]
[Tue Jul 21 08:04:40.719881 2026] [security2:error] [pid 358661:tid 358808] [client 20.151.10.161:28504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9SSAlWhjQfpOo60_HYTQAAAA4"]
[Tue Jul 21 08:04:40.757148 2026] [security2:error] [pid 352421:tid 352678] [client 20.104.96.117:7573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/82.php"] [unique_id "al9SSMJSWzG9jbYOtu5J6gAAAQQ"]
[Tue Jul 21 08:04:41.039433 2026] [security2:error] [pid 358661:tid 358911] [client 109.60.28.94:62006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SSQlWhjQfpOo60_HYUgAAAHU"]
[Tue Jul 21 08:04:41.040067 2026] [security2:error] [pid 358661:tid 358911] [client 109.60.28.94:62006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SSQlWhjQfpOo60_HYUgAAAHU"]
[Tue Jul 21 08:04:41.170919 2026] [security2:error] [pid 358661:tid 358820] [client 175.144.82.48:49327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SSQlWhjQfpOo60_HYVgAAABo"]
[Tue Jul 21 08:04:41.171057 2026] [security2:error] [pid 358661:tid 358820] [client 175.144.82.48:49327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SSQlWhjQfpOo60_HYVgAAABo"]
[Tue Jul 21 08:04:41.332331 2026] [security2:error] [pid 358661:tid 358876] [client 122.179.91.63:4363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SSQlWhjQfpOo60_HYWAAAAFI"]
[Tue Jul 21 08:04:41.332477 2026] [security2:error] [pid 358661:tid 358876] [client 122.179.91.63:4363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SSQlWhjQfpOo60_HYWAAAAFI"]
[Tue Jul 21 08:04:41.373860 2026] [security2:error] [pid 358661:tid 358673] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9SSQlWhjQfpOo60_HYWQAAUQg"]
[Tue Jul 21 08:04:41.408204 2026] [security2:error] [pid 358661:tid 358711] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/u.php"] [unique_id "al9SSQlWhjQfpOo60_HYWwAARS4"]
[Tue Jul 21 08:04:41.444595 2026] [security2:error] [pid 358661:tid 358790] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/sss.php"] [unique_id "al9SSQlWhjQfpOo60_HYXgAAI30"]
[Tue Jul 21 08:04:41.514660 2026] [security2:error] [pid 358661:tid 358712] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/sss.php"] [unique_id "al9SSQlWhjQfpOo60_HYXwAAPC8"]
[Tue Jul 21 08:04:41.518271 2026] [security2:error] [pid 358661:tid 358851] [client 184.75.221.3:44616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9SSQlWhjQfpOo60_HYYAAAADk"]
[Tue Jul 21 08:04:41.518363 2026] [security2:error] [pid 358661:tid 358851] [client 184.75.221.3:44616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9SSQlWhjQfpOo60_HYYAAAADk"]
[Tue Jul 21 08:04:41.558120 2026] [security2:error] [pid 358661:tid 358846] [client 20.197.192.193:52233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/dragonshell.php"] [unique_id "al9SSQlWhjQfpOo60_HYZAAAADQ"]
[Tue Jul 21 08:04:41.635326 2026] [security2:error] [pid 352421:tid 352575] [client 103.166.103.129:20691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SScJSWzG9jbYOtu5J9wAAAJ0"]
[Tue Jul 21 08:04:41.635886 2026] [security2:error] [pid 352421:tid 352575] [client 103.166.103.129:20691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SScJSWzG9jbYOtu5J9wAAAJ0"]
[Tue Jul 21 08:04:41.728295 2026] [security2:error] [pid 358661:tid 358745] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/c.php"] [unique_id "al9SSQlWhjQfpOo60_HYaQAAOFA"]
[Tue Jul 21 08:04:41.745698 2026] [security2:error] [pid 358661:tid 358788] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/aa.php"] [unique_id "al9SSQlWhjQfpOo60_HYagAAMHs"]
[Tue Jul 21 08:04:41.771012 2026] [security2:error] [pid 358661:tid 358688] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/100.php"] [unique_id "al9SSQlWhjQfpOo60_HYawAAbRc"]
[Tue Jul 21 08:04:41.809770 2026] [security2:error] [pid 352421:tid 352578] [client 38.100.221.102:17973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SScJSWzG9jbYOtu5J_AAAAKA"]
[Tue Jul 21 08:04:41.809908 2026] [security2:error] [pid 352421:tid 352578] [client 38.100.221.102:17973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SScJSWzG9jbYOtu5J_AAAAKA"]
[Tue Jul 21 08:04:41.823571 2026] [security2:error] [pid 358661:tid 358887] [client 136.144.33.53:38411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SSQlWhjQfpOo60_HYbAAAAF0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:04:41.834437 2026] [security2:error] [pid 358661:tid 358867] [client 20.29.126.15:7821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/CDX1.php"] [unique_id "al9SSQlWhjQfpOo60_HYbQAAAEk"]
[Tue Jul 21 08:04:41.942160 2026] [security2:error] [pid 358661:tid 358869] [client 20.104.96.117:7577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/admin.php"] [unique_id "al9SSQlWhjQfpOo60_HYcQAAAEs"]
[Tue Jul 21 08:04:41.989705 2026] [security2:error] [pid 358661:tid 358845] [client 20.151.10.161:28513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9SSQlWhjQfpOo60_HYcwAAADM"]
[Tue Jul 21 08:04:42.017350 2026] [security2:error] [pid 358661:tid 358697] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/footer.php"] [unique_id "al9SSglWhjQfpOo60_HYdAAAbyA"]
[Tue Jul 21 08:04:42.397687 2026] [security2:error] [pid 352421:tid 352647] [client 185.198.240.206:61871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9SSsJSWzG9jbYOtu5KBQAAAOU"]
[Tue Jul 21 08:04:42.658520 2026] [security2:error] [pid 358661:tid 358774] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/users.php"] [unique_id "al9SSglWhjQfpOo60_HYeQAAFm0"]
[Tue Jul 21 08:04:42.791178 2026] [security2:error] [pid 358661:tid 358913] [client 185.213.175.37:38258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.desconsultoria.com.br"] [uri "/.env"] [unique_id "al9SSglWhjQfpOo60_HYewAAAHc"]
[Tue Jul 21 08:04:42.890094 2026] [security2:error] [pid 358661:tid 358752] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/177.php"] [unique_id "al9SSglWhjQfpOo60_HYfAAAClc"]
[Tue Jul 21 08:04:42.950919 2026] [security2:error] [pid 358661:tid 358686] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/config.php"] [unique_id "al9SSglWhjQfpOo60_HYfQAATBU"]
[Tue Jul 21 08:04:42.953101 2026] [security2:error] [pid 358661:tid 358713] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SSglWhjQfpOo60_HYfgAAVDA"]
[Tue Jul 21 08:04:42.953279 2026] [security2:error] [pid 358661:tid 358878] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SSglWhjQfpOo60_HYfgAAVDA"]
[Tue Jul 21 08:04:42.966665 2026] [security2:error] [pid 358661:tid 358665] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/gettest.php"] [unique_id "al9SSglWhjQfpOo60_HYfwAALAA"]
[Tue Jul 21 08:04:42.981927 2026] [security2:error] [pid 358661:tid 358783] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/min.php"] [unique_id "al9SSglWhjQfpOo60_HYgAAAaXY"]
[Tue Jul 21 08:04:42.998254 2026] [security2:error] [pid 358661:tid 358758] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/edorxrr.php"] [unique_id "al9SSglWhjQfpOo60_HYgQAAN10"]
[Tue Jul 21 08:04:43.039062 2026] [security2:error] [pid 358661:tid 358770] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/hur.php"] [unique_id "al9SSwlWhjQfpOo60_HYggAAA2k"]
[Tue Jul 21 08:04:43.055403 2026] [security2:error] [pid 358661:tid 358727] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/zoro.php"] [unique_id "al9SSwlWhjQfpOo60_HYgwAATT4"]
[Tue Jul 21 08:04:43.070994 2026] [security2:error] [pid 358661:tid 358689] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/coffexium.php"] [unique_id "al9SSwlWhjQfpOo60_HYhQAAKBg"]
[Tue Jul 21 08:04:43.123080 2026] [security2:error] [pid 358661:tid 358683] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/app.php"] [unique_id "al9SSwlWhjQfpOo60_HYhwAAdRI"]
[Tue Jul 21 08:04:43.166025 2026] [security2:error] [pid 358661:tid 358715] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/core.php"] [unique_id "al9SSwlWhjQfpOo60_HYiQAAHzI"]
[Tue Jul 21 08:04:43.208768 2026] [security2:error] [pid 358661:tid 358900] [client 20.104.96.117:7567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/adminner.php"] [unique_id "al9SSwlWhjQfpOo60_HYiwAAAGo"]
[Tue Jul 21 08:04:43.401900 2026] [security2:error] [pid 358661:tid 358894] [client 185.198.240.212:49241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9SSglWhjQfpOo60_HYdwAAAGQ"]
[Tue Jul 21 08:04:43.559719 2026] [security2:error] [pid 358661:tid 358891] [client 20.151.10.161:28090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/gettest.php"] [unique_id "al9SSwlWhjQfpOo60_HYkwAAAGE"]
[Tue Jul 21 08:04:43.633599 2026] [security2:error] [pid 358661:tid 358912] [client 20.197.192.193:53130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9SSwlWhjQfpOo60_HYmAAAAHY"]
[Tue Jul 21 08:04:43.671313 2026] [security2:error] [pid 358661:tid 358768] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/main.php"] [unique_id "al9SSwlWhjQfpOo60_HYmQAAIWc"]
[Tue Jul 21 08:04:43.698277 2026] [security2:error] [pid 358661:tid 358748] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/init.php"] [unique_id "al9SSwlWhjQfpOo60_HYmgAAFFM"]
[Tue Jul 21 08:04:43.736575 2026] [security2:error] [pid 358661:tid 358907] [client 20.104.96.117:7951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/admin.php"] [unique_id "al9SSwlWhjQfpOo60_HYmwAAAHE"]
[Tue Jul 21 08:04:43.736671 2026] [security2:error] [pid 358661:tid 358775] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/prekel.php"] [unique_id "al9SSwlWhjQfpOo60_HYnAAAem4"]
[Tue Jul 21 08:04:43.777332 2026] [security2:error] [pid 358661:tid 358702] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/0.php"] [unique_id "al9SSwlWhjQfpOo60_HYnwAAASU"]
[Tue Jul 21 08:04:43.812681 2026] [security2:error] [pid 358661:tid 358722] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/BDKR28.php"] [unique_id "al9SSwlWhjQfpOo60_HYoAAAbTk"]
[Tue Jul 21 08:04:43.851205 2026] [security2:error] [pid 358661:tid 358753] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/f35.update.php"] [unique_id "al9SSwlWhjQfpOo60_HYoQAAHVg"]
[Tue Jul 21 08:04:43.878586 2026] [security2:error] [pid 358661:tid 358681] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/f900.php"] [unique_id "al9SSwlWhjQfpOo60_HYogAAAhA"]
[Tue Jul 21 08:04:43.907070 2026] [security2:error] [pid 358661:tid 358818] [client 41.68.90.219:50270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SSwlWhjQfpOo60_HYowAAABg"]
[Tue Jul 21 08:04:43.909912 2026] [security2:error] [pid 358661:tid 358818] [client 41.68.90.219:50270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SSwlWhjQfpOo60_HYowAAABg"]
[Tue Jul 21 08:04:43.976483 2026] [security2:error] [pid 352421:tid 352636] [client 65.21.113.253:58780] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SS8JSWzG9jbYOtu5KHgAAANo"]
[Tue Jul 21 08:04:44.279906 2026] [security2:error] [pid 352421:tid 352582] [client 20.104.96.117:7554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/k.php"] [unique_id "al9STMJSWzG9jbYOtu5KIwAAAKQ"]
[Tue Jul 21 08:04:44.339752 2026] [autoindex:error] [pid 352421:tid 352574] [client 147.185.132.171:59816] AH01276: Cannot serve directory /home3/factor11/atracta.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:04:44.571612 2026] [security2:error] [pid 352421:tid 352559] [client 47.128.55.138:59746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "academycont.com"] [uri "/robots.txt"] [unique_id "al9STMJSWzG9jbYOtu5KKwAAAI0"]
[Tue Jul 21 08:04:44.805218 2026] [security2:error] [pid 358661:tid 358723] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9STAlWhjQfpOo60_HYtgAAKDo"]
[Tue Jul 21 08:04:44.805360 2026] [security2:error] [pid 358661:tid 358834] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9STAlWhjQfpOo60_HYtgAAKDo"]
[Tue Jul 21 08:04:44.830177 2026] [security2:error] [pid 358661:tid 358677] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/xmrl.php"] [unique_id "al9STAlWhjQfpOo60_HYtwAAMgw"]
[Tue Jul 21 08:04:44.837551 2026] [security2:error] [pid 358661:tid 358822] [client 20.104.96.117:7575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/blurbs.php"] [unique_id "al9STAlWhjQfpOo60_HYuAAAABw"]
[Tue Jul 21 08:04:44.850384 2026] [security2:error] [pid 358661:tid 358668] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/memberfuns.php"] [unique_id "al9STAlWhjQfpOo60_HYuQAANQM"]
[Tue Jul 21 08:04:44.934344 2026] [security2:error] [pid 352421:tid 352594] [client 120.56.162.40:50401] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9STMJSWzG9jbYOtu5KMgAAALA"]
[Tue Jul 21 08:04:44.934546 2026] [security2:error] [pid 352421:tid 352594] [client 120.56.162.40:50401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9STMJSWzG9jbYOtu5KMgAAALA"]
[Tue Jul 21 08:04:45.085443 2026] [security2:error] [pid 358661:tid 358917] [client 65.21.113.253:43760] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9STAlWhjQfpOo60_HYsAAAAHs"]
[Tue Jul 21 08:04:45.296346 2026] [security2:error] [pid 352421:tid 352485] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9STcJSWzG9jbYOtu5KOQAAnT8"]
[Tue Jul 21 08:04:45.296538 2026] [security2:error] [pid 352421:tid 352575] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9STcJSWzG9jbYOtu5KOQAAnT8"]
[Tue Jul 21 08:04:45.344396 2026] [autoindex:error] [pid 358661:tid 358881] [client 34.53.191.165:61157] AH01276: Cannot serve directory /home4/ciclod61/bahtelecom.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:04:45.488917 2026] [security2:error] [pid 358661:tid 358741] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/ms.php"] [unique_id "al9STQlWhjQfpOo60_HYwQAAZ0w"]
[Tue Jul 21 08:04:45.510776 2026] [security2:error] [pid 358661:tid 358776] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/zz.php"] [unique_id "al9STQlWhjQfpOo60_HYwgAAUW8"]
[Tue Jul 21 08:04:45.530638 2026] [security2:error] [pid 358661:tid 358792] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/for.php"] [unique_id "al9STQlWhjQfpOo60_HYwwAAB38"]
[Tue Jul 21 08:04:45.569870 2026] [security2:error] [pid 358661:tid 358863] [client 20.197.192.193:52271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/wp-mt.php"] [unique_id "al9STQlWhjQfpOo60_HYxQAAAEU"]
[Tue Jul 21 08:04:45.571859 2026] [security2:error] [pid 358661:tid 358760] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/yup.php"] [unique_id "al9STQlWhjQfpOo60_HYxgAAC18"]
[Tue Jul 21 08:04:45.737398 2026] [security2:error] [pid 352421:tid 352668] [client 20.151.10.161:28588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/simple.php"] [unique_id "al9STcJSWzG9jbYOtu5KQwAAAPo"]
[Tue Jul 21 08:04:45.876410 2026] [security2:error] [pid 352421:tid 352599] [client 20.104.96.117:7582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/bajah.php"] [unique_id "al9STcJSWzG9jbYOtu5KSAAAALU"]
[Tue Jul 21 08:04:45.934585 2026] [security2:error] [pid 358661:tid 358678] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/wpxml.php"] [unique_id "al9STQlWhjQfpOo60_HYzQAANA0"]
[Tue Jul 21 08:04:45.949793 2026] [security2:error] [pid 358661:tid 358789] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/fffm.php"] [unique_id "al9STQlWhjQfpOo60_HYzgAAJXw"]
[Tue Jul 21 08:04:45.965557 2026] [security2:error] [pid 358661:tid 358786] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/gecko.php"] [unique_id "al9STQlWhjQfpOo60_HYzwAAdnk"]
[Tue Jul 21 08:04:45.979782 2026] [security2:error] [pid 358661:tid 358707] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/a1.php"] [unique_id "al9STQlWhjQfpOo60_HY0AAAFCo"]
[Tue Jul 21 08:04:45.994887 2026] [security2:error] [pid 358661:tid 358772] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/k2.php"] [unique_id "al9STQlWhjQfpOo60_HY0QAAYGs"]
[Tue Jul 21 08:04:46.011043 2026] [security2:error] [pid 358661:tid 358687] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/82.php"] [unique_id "al9STglWhjQfpOo60_HY0gAAcRY"]
[Tue Jul 21 08:04:46.026431 2026] [security2:error] [pid 358661:tid 358764] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/config.json.php"] [unique_id "al9STglWhjQfpOo60_HY0wAAemM"]
[Tue Jul 21 08:04:46.029204 2026] [security2:error] [pid 352421:tid 352481] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9STsJSWzG9jbYOtu5KSwAA6zs"]
[Tue Jul 21 08:04:46.029364 2026] [security2:error] [pid 352421:tid 352653] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9STsJSWzG9jbYOtu5KSwAA6zs"]
[Tue Jul 21 08:04:46.149895 2026] [security2:error] [pid 358661:tid 358691] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9STglWhjQfpOo60_HY1gAAIRo"]
[Tue Jul 21 08:04:46.150133 2026] [security2:error] [pid 358661:tid 358827] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9STglWhjQfpOo60_HY1gAAIRo"]
[Tue Jul 21 08:04:46.192391 2026] [security2:error] [pid 358661:tid 358762] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sbbarrosadvocacia.com.br"] [uri "/fpwch.php"] [unique_id "al9STglWhjQfpOo60_HY1wAAAWE"]
[Tue Jul 21 08:04:46.554195 2026] [security2:error] [pid 358661:tid 358878] [client 193.36.225.56:37437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9STglWhjQfpOo60_HY2gAAAFQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:04:46.611473 2026] [security2:error] [pid 358661:tid 358851] [client 182.8.255.181:10164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9STglWhjQfpOo60_HY3AAAADk"]
[Tue Jul 21 08:04:46.611614 2026] [security2:error] [pid 358661:tid 358851] [client 182.8.255.181:10164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9STglWhjQfpOo60_HY3AAAADk"]
[Tue Jul 21 08:04:46.629044 2026] [security2:error] [pid 358661:tid 358859] [client 102.206.115.33:60531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9STglWhjQfpOo60_HY3QAAAEE"]
[Tue Jul 21 08:04:46.629155 2026] [security2:error] [pid 358661:tid 358859] [client 102.206.115.33:60531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9STglWhjQfpOo60_HY3QAAAEE"]
[Tue Jul 21 08:04:46.890994 2026] [security2:error] [pid 352421:tid 352584] [client 20.104.96.117:7579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/a.php"] [unique_id "al9STsJSWzG9jbYOtu5KWwAAAKY"]
[Tue Jul 21 08:04:46.907098 2026] [security2:error] [pid 358661:tid 358861] [client 20.29.126.15:14510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/inputs.php"] [unique_id "al9STglWhjQfpOo60_HY4gAAAEM"]
[Tue Jul 21 08:04:46.918302 2026] [security2:error] [pid 352421:tid 352652] [client 106.215.181.8:11355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9STsJSWzG9jbYOtu5KXAAAAOo"]
[Tue Jul 21 08:04:46.918467 2026] [security2:error] [pid 352421:tid 352652] [client 106.215.181.8:11355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9STsJSWzG9jbYOtu5KXAAAAOo"]
[Tue Jul 21 08:04:47.341446 2026] [security2:error] [pid 358661:tid 358833] [client 202.143.127.214:58431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9STwlWhjQfpOo60_HY5QAAACc"]
[Tue Jul 21 08:04:47.341581 2026] [security2:error] [pid 358661:tid 358833] [client 202.143.127.214:58431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9STwlWhjQfpOo60_HY5QAAACc"]
[Tue Jul 21 08:04:47.371511 2026] [security2:error] [pid 352421:tid 352646] [client 65.21.113.253:58780] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9ST8JSWzG9jbYOtu5KaQAAAOQ"]
[Tue Jul 21 08:04:47.417330 2026] [security2:error] [pid 352421:tid 352614] [client 20.104.96.117:7970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/edit.php"] [unique_id "al9ST8JSWzG9jbYOtu5KawAAAMQ"]
[Tue Jul 21 08:04:47.733334 2026] [security2:error] [pid 352421:tid 352578] [client 204.8.98.45:52056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9ST8JSWzG9jbYOtu5KbgAAAKA"]
[Tue Jul 21 08:04:47.733470 2026] [security2:error] [pid 352421:tid 352578] [client 204.8.98.45:52056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9ST8JSWzG9jbYOtu5KbgAAAKA"]
[Tue Jul 21 08:04:47.864209 2026] [security2:error] [pid 352421:tid 352623] [client 20.104.96.117:7957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/hosty.php"] [unique_id "al9ST8JSWzG9jbYOtu5KcgAAAM0"]
[Tue Jul 21 08:04:47.901036 2026] [security2:error] [pid 352421:tid 352644] [client 103.78.200.11:59595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ST8JSWzG9jbYOtu5KcwAAAOI"]
[Tue Jul 21 08:04:47.901548 2026] [security2:error] [pid 352421:tid 352644] [client 103.78.200.11:59595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ST8JSWzG9jbYOtu5KcwAAAOI"]
[Tue Jul 21 08:04:47.987905 2026] [security2:error] [pid 358661:tid 358847] [client 20.197.192.193:53158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/ww.php"] [unique_id "al9STwlWhjQfpOo60_HY7QAAADU"]
[Tue Jul 21 08:04:48.199266 2026] [security2:error] [pid 358661:tid 358837] [client 87.116.180.198:27166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUAlWhjQfpOo60_HY8QAAACs"]
[Tue Jul 21 08:04:48.203607 2026] [security2:error] [pid 358661:tid 358837] [client 87.116.180.198:27166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUAlWhjQfpOo60_HY8QAAACs"]
[Tue Jul 21 08:04:48.223020 2026] [security2:error] [pid 358661:tid 358782] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUAlWhjQfpOo60_HY8gAADnU"]
[Tue Jul 21 08:04:48.223244 2026] [security2:error] [pid 358661:tid 358808] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUAlWhjQfpOo60_HY8gAADnU"]
[Tue Jul 21 08:04:48.364961 2026] [security2:error] [pid 352421:tid 352599] [client 20.104.96.117:7581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/k.php"] [unique_id "al9SUMJSWzG9jbYOtu5KgQAAALU"]
[Tue Jul 21 08:04:48.412863 2026] [security2:error] [pid 352421:tid 352597] [client 20.151.10.161:28052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/xxx.php"] [unique_id "al9SUMJSWzG9jbYOtu5KgwAAALM"]
[Tue Jul 21 08:04:48.513028 2026] [security2:error] [pid 358661:tid 358911] [client 65.21.113.253:43762] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SUAlWhjQfpOo60_HY7gAAAHU"]
[Tue Jul 21 08:04:48.559447 2026] [security2:error] [pid 352421:tid 352592] [client 103.29.114.44:34477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUMJSWzG9jbYOtu5KhwAAAK4"]
[Tue Jul 21 08:04:48.559576 2026] [security2:error] [pid 352421:tid 352592] [client 103.29.114.44:34477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUMJSWzG9jbYOtu5KhwAAAK4"]
[Tue Jul 21 08:04:48.589944 2026] [security2:error] [pid 358661:tid 358801] [client 85.208.96.211:52352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dharmanet.com.br"] [uri "/robots.txt"] [unique_id "al9SUAlWhjQfpOo60_HY9wAAAAc"]
[Tue Jul 21 08:04:48.590061 2026] [security2:error] [pid 358661:tid 358801] [client 85.208.96.211:52352] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.dharmanet.com.br"] [uri "/robots.txt"] [unique_id "al9SUAlWhjQfpOo60_HY9wAAAAc"]
[Tue Jul 21 08:04:48.669137 2026] [security2:error] [pid 352421:tid 352636] [client 34.182.139.74:62239] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "5liberdades.produtoswendellcarvalho.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9SUMJSWzG9jbYOtu5KigAAANo"]
[Tue Jul 21 08:04:48.841575 2026] [security2:error] [pid 358661:tid 358909] [client 65.21.113.253:43778] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SUAlWhjQfpOo60_HY9QAAAHM"]
[Tue Jul 21 08:04:48.889224 2026] [security2:error] [pid 358661:tid 358854] [client 85.208.96.195:19468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dharmanet.com.br"] [uri "/vajrayana/dagpo.htm"] [unique_id "al9SUAlWhjQfpOo60_HY_QAAADw"]
[Tue Jul 21 08:04:48.889351 2026] [security2:error] [pid 358661:tid 358854] [client 85.208.96.195:19468] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.dharmanet.com.br"] [uri "/vajrayana/dagpo.htm"] [unique_id "al9SUAlWhjQfpOo60_HY_QAAADw"]
[Tue Jul 21 08:04:49.313145 2026] [security2:error] [pid 352421:tid 352643] [client 117.247.80.59:12443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUcJSWzG9jbYOtu5KkwAAAOE"]
[Tue Jul 21 08:04:49.313283 2026] [security2:error] [pid 352421:tid 352643] [client 117.247.80.59:12443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUcJSWzG9jbYOtu5KkwAAAOE"]
[Tue Jul 21 08:04:49.671090 2026] [security2:error] [pid 352421:tid 352675] [client 20.151.10.161:28073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/hypo.php"] [unique_id "al9SUcJSWzG9jbYOtu5KnQAAAQE"]
[Tue Jul 21 08:04:49.747277 2026] [security2:error] [pid 352421:tid 352587] [client 20.104.96.117:7569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/aaa.php"] [unique_id "al9SUcJSWzG9jbYOtu5KngAAAKk"]
[Tue Jul 21 08:04:49.752662 2026] [security2:error] [pid 352421:tid 352654] [client 184.75.221.3:47490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SUcJSWzG9jbYOtu5KnwAAAOw"]
[Tue Jul 21 08:04:49.752738 2026] [security2:error] [pid 352421:tid 352654] [client 184.75.221.3:47490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SUcJSWzG9jbYOtu5KnwAAAOw"]
[Tue Jul 21 08:04:49.862790 2026] [security2:error] [pid 358661:tid 358860] [client 20.197.192.193:52241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9SUQlWhjQfpOo60_HZCwAAAEI"]
[Tue Jul 21 08:04:50.185198 2026] [security2:error] [pid 352421:tid 352610] [client 184.75.221.3:51388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9SUsJSWzG9jbYOtu5KqAAAAMA"]
[Tue Jul 21 08:04:50.185303 2026] [security2:error] [pid 352421:tid 352610] [client 184.75.221.3:51388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9SUsJSWzG9jbYOtu5KqAAAAMA"]
[Tue Jul 21 08:04:50.217477 2026] [security2:error] [pid 352421:tid 352478] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SUsJSWzG9jbYOtu5KqQAAsTg"]
[Tue Jul 21 08:04:50.217650 2026] [security2:error] [pid 352421:tid 352595] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SUsJSWzG9jbYOtu5KqQAAsTg"]
[Tue Jul 21 08:04:50.392715 2026] [security2:error] [pid 352421:tid 352601] [client 178.153.91.96:56402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SUsJSWzG9jbYOtu5KrAAAALc"]
[Tue Jul 21 08:04:50.392887 2026] [security2:error] [pid 352421:tid 352601] [client 178.153.91.96:56402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SUsJSWzG9jbYOtu5KrAAAALc"]
[Tue Jul 21 08:04:50.429862 2026] [security2:error] [pid 358661:tid 358804] [client 20.104.96.117:7578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/file5.php"] [unique_id "al9SUglWhjQfpOo60_HZEwAAAAo"]
[Tue Jul 21 08:04:50.497578 2026] [security2:error] [pid 358661:tid 358862] [client 193.36.225.58:52143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SUglWhjQfpOo60_HZFwAAAEQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:04:50.860964 2026] [security2:error] [pid 358661:tid 358692] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUglWhjQfpOo60_HZHgAAWRs"]
[Tue Jul 21 08:04:50.861118 2026] [security2:error] [pid 358661:tid 358883] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUglWhjQfpOo60_HZHgAAWRs"]
[Tue Jul 21 08:04:50.890087 2026] [security2:error] [pid 358661:tid 358799] [client 216.73.160.185:65037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9SUglWhjQfpOo60_HZHwAAAAU"]
[Tue Jul 21 08:04:50.952601 2026] [security2:error] [pid 358661:tid 358877] [client 20.104.96.117:7962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/222.php"] [unique_id "al9SUglWhjQfpOo60_HZIAAAAFM"]
[Tue Jul 21 08:04:50.995522 2026] [security2:error] [pid 358661:tid 358879] [client 34.182.139.74:62886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "5liberdades.produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SUglWhjQfpOo60_HZHQAAAFU"]
[Tue Jul 21 08:04:51.061142 2026] [security2:error] [pid 352421:tid 352644] [client 117.210.135.0:65001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SU8JSWzG9jbYOtu5KuQAAAOI"]
[Tue Jul 21 08:04:51.061248 2026] [security2:error] [pid 352421:tid 352644] [client 117.210.135.0:65001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SU8JSWzG9jbYOtu5KuQAAAOI"]
[Tue Jul 21 08:04:51.069742 2026] [security2:error] [pid 352421:tid 352599] [client 20.151.10.161:28059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/chosen.php"] [unique_id "al9SU8JSWzG9jbYOtu5KugAAALU"]
[Tue Jul 21 08:04:51.317233 2026] [security2:error] [pid 358661:tid 358805] [client 20.104.96.117:7942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/test.php"] [unique_id "al9SUwlWhjQfpOo60_HZJAAAAAs"]
[Tue Jul 21 08:04:51.572611 2026] [security2:error] [pid 358661:tid 358916] [client 162.241.63.68:17874] ModSecurity: Access denied with code 400 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "67"] [id "390703"] [rev "5"] [msg "Atomicorp.com WAF Rules: Possible URL Encoding Abuse Attack Attempt"] [severity "NOTICE"] [hostname "regonegociosimobiliarios.com.br"] [uri "/%post_type%/dicas-para-voce-planejar-a-compra-de-seu-imovel/"] [unique_id "al9SUwlWhjQfpOo60_HZLgAAAHo"]
[Tue Jul 21 08:04:51.596846 2026] [security2:error] [pid 358661:tid 358919] [client 65.21.113.253:43778] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SUwlWhjQfpOo60_HZJQAAAH0"]
[Tue Jul 21 08:04:51.625495 2026] [security2:error] [pid 358661:tid 358849] [client 184.75.221.3:51392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9SUwlWhjQfpOo60_HZLwAAADc"]
[Tue Jul 21 08:04:51.625587 2026] [security2:error] [pid 358661:tid 358849] [client 184.75.221.3:51392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9SUwlWhjQfpOo60_HZLwAAADc"]
[Tue Jul 21 08:04:51.652535 2026] [security2:error] [pid 352421:tid 352604] [client 34.182.139.74:49696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "5liberdades.produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SU8JSWzG9jbYOtu5KxwAAALo"]
[Tue Jul 21 08:04:51.662495 2026] [security2:error] [pid 358661:tid 358850] [client 20.29.126.15:14474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/ms-edit.php"] [unique_id "al9SUwlWhjQfpOo60_HZMgAAADg"]
[Tue Jul 21 08:04:51.671741 2026] [security2:error] [pid 358661:tid 358917] [client 175.144.82.48:49781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUwlWhjQfpOo60_HZMwAAAHs"]
[Tue Jul 21 08:04:51.672573 2026] [security2:error] [pid 358661:tid 358917] [client 175.144.82.48:49781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUwlWhjQfpOo60_HZMwAAAHs"]
[Tue Jul 21 08:04:51.722228 2026] [security2:error] [pid 358661:tid 358803] [client 41.106.180.79:31386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.180.106.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "insp1.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUwlWhjQfpOo60_HZLQAAAAk"]
[Tue Jul 21 08:04:51.722366 2026] [security2:error] [pid 358661:tid 358803] [client 41.106.180.79:31386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "insp1.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUwlWhjQfpOo60_HZLQAAAAk"]
[Tue Jul 21 08:04:51.744215 2026] [security2:error] [pid 358661:tid 358823] [client 20.104.96.117:7556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/aaa.php"] [unique_id "al9SUwlWhjQfpOo60_HZNQAAAB0"]
[Tue Jul 21 08:04:51.776064 2026] [security2:error] [pid 358661:tid 358858] [client 109.60.28.94:62456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUwlWhjQfpOo60_HZNgAAAEA"]
[Tue Jul 21 08:04:51.776214 2026] [security2:error] [pid 358661:tid 358858] [client 109.60.28.94:62456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SUwlWhjQfpOo60_HZNgAAAEA"]
[Tue Jul 21 08:04:52.043695 2026] [core:error] [pid 352421:tid 352582] [client 104.248.9.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:04:52.043718 2026] [core:error] [pid 352421:tid 352582] [client 104.248.9.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:04:52.107731 2026] [security2:error] [pid 352421:tid 352664] [client 65.21.113.253:58780] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SVMJSWzG9jbYOtu5K1AAAAPY"]
[Tue Jul 21 08:04:52.138279 2026] [security2:error] [pid 352421:tid 352574] [client 20.197.192.193:52257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/wander.php"] [unique_id "al9SVMJSWzG9jbYOtu5K2AAAAJw"]
[Tue Jul 21 08:04:52.243356 2026] [security2:error] [pid 352421:tid 352654] [client 20.104.96.117:7936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/11.php"] [unique_id "al9SVMJSWzG9jbYOtu5K2gAAAOw"]
[Tue Jul 21 08:04:52.309421 2026] [security2:error] [pid 352421:tid 352635] [client 34.182.139.74:50006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "5liberdades.produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SVMJSWzG9jbYOtu5K2QAAANk"]
[Tue Jul 21 08:04:52.367787 2026] [security2:error] [pid 358661:tid 358876] [client 103.166.103.129:59356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SVAlWhjQfpOo60_HZQQAAAFI"]
[Tue Jul 21 08:04:52.368032 2026] [security2:error] [pid 358661:tid 358876] [client 103.166.103.129:59356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SVAlWhjQfpOo60_HZQQAAAFI"]
[Tue Jul 21 08:04:52.381864 2026] [security2:error] [pid 358661:tid 358842] [client 122.179.91.63:25359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SVAlWhjQfpOo60_HZQgAAADA"]
[Tue Jul 21 08:04:52.382078 2026] [security2:error] [pid 358661:tid 358842] [client 122.179.91.63:25359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SVAlWhjQfpOo60_HZQgAAADA"]
[Tue Jul 21 08:04:52.399506 2026] [security2:error] [pid 358661:tid 358872] [client 38.100.221.102:18616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SVAlWhjQfpOo60_HZQwAAAE4"]
[Tue Jul 21 08:04:52.399698 2026] [security2:error] [pid 358661:tid 358872] [client 38.100.221.102:18616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SVAlWhjQfpOo60_HZQwAAAE4"]
[Tue Jul 21 08:04:52.494670 2026] [security2:error] [pid 358661:tid 358862] [client 20.151.10.161:28049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/als.php"] [unique_id "al9SVAlWhjQfpOo60_HZRQAAAEQ"]
[Tue Jul 21 08:04:52.679765 2026] [security2:error] [pid 352421:tid 352625] [client 20.104.96.117:7969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/mac.php"] [unique_id "al9SVMJSWzG9jbYOtu5K4wAAAM8"]
[Tue Jul 21 08:04:52.769641 2026] [security2:error] [pid 358661:tid 358908] [client 65.21.113.253:43778] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SVAlWhjQfpOo60_HZPwAAAHI"]
[Tue Jul 21 08:04:52.873239 2026] [security2:error] [pid 358661:tid 358809] [client 34.182.139.74:49648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "5liberdades.produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SVAlWhjQfpOo60_HZSgAAAA8"]
[Tue Jul 21 08:04:52.908372 2026] [security2:error] [pid 352421:tid 352561] [client 162.241.63.68:17884] ModSecurity: Access denied with code 400 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "67"] [id "390703"] [rev "5"] [msg "Atomicorp.com WAF Rules: Possible URL Encoding Abuse Attack Attempt"] [severity "NOTICE"] [hostname "regonegociosimobiliarios.com.br"] [uri "/%post_type%/dicas-para-voce-planejar-a-compra-de-seu-imovel/"] [unique_id "al9SVMJSWzG9jbYOtu5K7AAAAI8"]
[Tue Jul 21 08:04:53.128055 2026] [security2:error] [pid 352421:tid 352624] [client 20.197.192.193:52228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/cron.php"] [unique_id "al9SVcJSWzG9jbYOtu5K9AAAAM4"]
[Tue Jul 21 08:04:53.291989 2026] [security2:error] [pid 358661:tid 358857] [client 20.104.96.117:7566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/chosen.php"] [unique_id "al9SVQlWhjQfpOo60_HZUAAAAD8"]
[Tue Jul 21 08:04:53.489855 2026] [security2:error] [pid 352421:tid 352540] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SVcJSWzG9jbYOtu5K-AAA4nY"]
[Tue Jul 21 08:04:53.490036 2026] [security2:error] [pid 352421:tid 352644] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SVcJSWzG9jbYOtu5K-AAA4nY"]
[Tue Jul 21 08:04:53.782472 2026] [security2:error] [pid 358661:tid 358853] [client 212.32.69.197:64549] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nutritalitasantana.com.br"] [uri "/.env"] [unique_id "al9SVQlWhjQfpOo60_HZWgAAADs"]
[Tue Jul 21 08:04:53.875631 2026] [security2:error] [pid 358661:tid 358913] [client 20.104.96.117:7998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/cream1.php"] [unique_id "al9SVQlWhjQfpOo60_HZWwAAAHc"]
[Tue Jul 21 08:04:53.886314 2026] [security2:error] [pid 358661:tid 358871] [client 20.151.10.161:28242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/pol.php"] [unique_id "al9SVQlWhjQfpOo60_HZXAAAAE0"]
[Tue Jul 21 08:04:54.118317 2026] [security2:error] [pid 352421:tid 352606] [client 136.144.33.104:20323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SVsJSWzG9jbYOtu5LCQAAALw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:04:54.226584 2026] [security2:error] [pid 358661:tid 358900] [client 162.241.63.68:17908] ModSecurity: Access denied with code 400 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "67"] [id "390703"] [rev "5"] [msg "Atomicorp.com WAF Rules: Possible URL Encoding Abuse Attack Attempt"] [severity "NOTICE"] [hostname "regonegociosimobiliarios.com.br"] [uri "/%post_type%/qual-a-documentacao-necessaria-para-evitar-surpresas-na-hora-de-comprar-um-imovel/"] [unique_id "al9SVglWhjQfpOo60_HZYgAAAGo"]
[Tue Jul 21 08:04:54.248990 2026] [security2:error] [pid 352421:tid 352604] [client 41.68.90.219:50721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SVsJSWzG9jbYOtu5LDQAAALo"]
[Tue Jul 21 08:04:54.249161 2026] [security2:error] [pid 352421:tid 352604] [client 41.68.90.219:50721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SVsJSWzG9jbYOtu5LDQAAALo"]
[Tue Jul 21 08:04:54.511740 2026] [autoindex:error] [pid 358661:tid 358857] [client 20.104.96.117:7240] AH01276: Cannot serve directory /home3/tkcorr80/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:04:54.732915 2026] [security2:error] [pid 352421:tid 352560] [client 65.21.113.253:54680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SVsJSWzG9jbYOtu5LEAAAAI4"]
[Tue Jul 21 08:04:54.802314 2026] [autoindex:error] [pid 358661:tid 358842] [client 20.104.96.117:7240] AH01276: Cannot serve directory /home3/tkcorr80/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:04:54.996854 2026] [security2:error] [pid 358661:tid 358853] [client 20.104.96.117:7240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/dr.php"] [unique_id "al9SVglWhjQfpOo60_HZbgAAADs"]
[Tue Jul 21 08:04:55.008611 2026] [core:error] [pid 358661:tid 358889] [client 104.248.9.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.rustikusboxingschool.com/
[Tue Jul 21 08:04:55.008644 2026] [core:error] [pid 358661:tid 358889] [client 104.248.9.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.rustikusboxingschool.com/
[Tue Jul 21 08:04:55.113364 2026] [security2:error] [pid 358661:tid 358910] [client 209.112.91.75:37664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mulher-de-valor.com"] [uri "/awsconfiguration.json"] [unique_id "al9SVwlWhjQfpOo60_HZdAAAAHQ"]
[Tue Jul 21 08:04:55.113459 2026] [security2:error] [pid 358661:tid 358910] [client 209.112.91.75:37664] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mulher-de-valor.com"] [uri "/awsconfiguration.json"] [unique_id "al9SVwlWhjQfpOo60_HZdAAAAHQ"]
[Tue Jul 21 08:04:55.125562 2026] [security2:error] [pid 352421:tid 352590] [client 20.197.192.193:52283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/xxx.php"] [unique_id "al9SV8JSWzG9jbYOtu5LIQAAAKw"]
[Tue Jul 21 08:04:55.132964 2026] [security2:error] [pid 358661:tid 358856] [client 209.112.91.75:37588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "mulher-de-valor.com"] [uri "/web.config"] [unique_id "al9SVwlWhjQfpOo60_HZegAAAD4"]
[Tue Jul 21 08:04:55.162332 2026] [security2:error] [pid 352421:tid 352647] [client 209.112.91.75:37320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mulher-de-valor.com"] [uri "/laravel/.env"] [unique_id "al9SV8JSWzG9jbYOtu5LJAAAAOU"]
[Tue Jul 21 08:04:55.162422 2026] [security2:error] [pid 352421:tid 352647] [client 209.112.91.75:37320] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mulher-de-valor.com"] [uri "/laravel/.env"] [unique_id "al9SV8JSWzG9jbYOtu5LJAAAAOU"]
[Tue Jul 21 08:04:55.341411 2026] [security2:error] [pid 358661:tid 358795] [client 209.112.91.75:37194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mulher-de-valor.com"] [uri "/.env"] [unique_id "al9SVwlWhjQfpOo60_HZhQAAAAE"]
[Tue Jul 21 08:04:55.464204 2026] [security2:error] [pid 352421:tid 352597] [client 20.104.96.117:7570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/x.php"] [unique_id "al9SV8JSWzG9jbYOtu5LKwAAALM"]
[Tue Jul 21 08:04:55.478901 2026] [security2:error] [pid 358661:tid 358740] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SVwlWhjQfpOo60_HZjAAAH0s"]
[Tue Jul 21 08:04:55.479078 2026] [security2:error] [pid 358661:tid 358825] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SVwlWhjQfpOo60_HZjAAAH0s"]
[Tue Jul 21 08:04:55.483832 2026] [security2:error] [pid 358661:tid 358894] [client 209.112.91.75:37288] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mulher-de-valor.com"] [uri "/backend/.env"] [unique_id "al9SVwlWhjQfpOo60_HZjQAAAGQ"]
[Tue Jul 21 08:04:55.488155 2026] [security2:error] [pid 358661:tid 358867] [client 209.112.91.75:37216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mulher-de-valor.com"] [uri "/.env.production"] [unique_id "al9SVwlWhjQfpOo60_HZjgAAAEk"]
[Tue Jul 21 08:04:55.488237 2026] [security2:error] [pid 358661:tid 358867] [client 209.112.91.75:37216] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mulher-de-valor.com"] [uri "/.env.production"] [unique_id "al9SVwlWhjQfpOo60_HZjgAAAEk"]
[Tue Jul 21 08:04:55.496104 2026] [security2:error] [pid 358661:tid 358855] [client 209.112.91.75:37332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mulher-de-valor.com"] [uri "/wp/.env"] [unique_id "al9SVwlWhjQfpOo60_HZjwAAAD0"]
[Tue Jul 21 08:04:55.545579 2026] [security2:error] [pid 352421:tid 352608] [client 74.7.244.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lucasemiliobordignon1782304104400.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9SV8JSWzG9jbYOtu5LLQAAvkY"]
[Tue Jul 21 08:04:55.547677 2026] [security2:error] [pid 358661:tid 358884] [client 162.241.63.68:17930] ModSecurity: Access denied with code 400 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "67"] [id "390703"] [rev "5"] [msg "Atomicorp.com WAF Rules: Possible URL Encoding Abuse Attack Attempt"] [severity "NOTICE"] [hostname "regonegociosimobiliarios.com.br"] [uri "/%post_type%/qual-a-documentacao-necessaria-para-evitar-surpresas-na-hora-de-comprar-um-imovel/"] [unique_id "al9SVwlWhjQfpOo60_HZlwAAAFo"]
[Tue Jul 21 08:04:55.627923 2026] [security2:error] [pid 352421:tid 352598] [client 20.151.10.161:28275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file5.php"] [unique_id "al9SV8JSWzG9jbYOtu5LLwAAALQ"]
[Tue Jul 21 08:04:55.695899 2026] [security2:error] [pid 352421:tid 352471] [remote 124.55.178.99:56542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9SV8JSWzG9jbYOtu5LMwAAwzE"]
[Tue Jul 21 08:04:55.842179 2026] [security2:error] [pid 358661:tid 358836] [client 209.112.91.75:37228] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mulher-de-valor.com"] [uri "/.env.bak"] [unique_id "al9SVwlWhjQfpOo60_HZngAAACo"]
[Tue Jul 21 08:04:55.843179 2026] [security2:error] [pid 358661:tid 358907] [client 209.112.91.75:37272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mulher-de-valor.com"] [uri "/app/.env"] [unique_id "al9SVwlWhjQfpOo60_HZoAAAAHE"]
[Tue Jul 21 08:04:55.843716 2026] [security2:error] [pid 358661:tid 358919] [client 209.112.91.75:37294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mulher-de-valor.com"] [uri "/api/.env"] [unique_id "al9SVwlWhjQfpOo60_HZogAAAH0"]
[Tue Jul 21 08:04:55.843732 2026] [security2:error] [pid 358661:tid 358849] [client 209.112.91.75:37248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mulher-de-valor.com"] [uri "/.env.old"] [unique_id "al9SVwlWhjQfpOo60_HZoQAAADc"]
[Tue Jul 21 08:04:55.883785 2026] [security2:error] [pid 358661:tid 358850] [client 209.112.91.75:37238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mulher-de-valor.com"] [uri "/.env.backup"] [unique_id "al9SVwlWhjQfpOo60_HZowAAADg"]
[Tue Jul 21 08:04:55.953018 2026] [security2:error] [pid 352421:tid 352655] [client 20.104.96.117:7561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/155.php"] [unique_id "al9SV8JSWzG9jbYOtu5LOgAAAO0"]
[Tue Jul 21 08:04:55.963888 2026] [security2:error] [pid 358661:tid 358749] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SVwlWhjQfpOo60_HZpAAAG1Q"]
[Tue Jul 21 08:04:55.964164 2026] [security2:error] [pid 358661:tid 358821] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SVwlWhjQfpOo60_HZpAAAG1Q"]
[Tue Jul 21 08:04:56.048590 2026] [security2:error] [pid 352421:tid 352554] [client 92.119.178.3:52918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9SWMJSWzG9jbYOtu5LOwAAAIg"]
[Tue Jul 21 08:04:56.048693 2026] [security2:error] [pid 352421:tid 352554] [client 92.119.178.3:52918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9SWMJSWzG9jbYOtu5LOwAAAIg"]
[Tue Jul 21 08:04:56.508299 2026] [security2:error] [pid 358661:tid 358914] [client 216.73.161.169:63449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9SWAlWhjQfpOo60_HZrQAAAHg"]
[Tue Jul 21 08:04:56.511695 2026] [security2:error] [pid 358661:tid 358832] [client 173.239.211.143:35299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9SWAlWhjQfpOo60_HZrgAAACY"]
[Tue Jul 21 08:04:56.511698 2026] [security2:error] [pid 358661:tid 358796] [client 216.73.161.163:25567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9SWAlWhjQfpOo60_HZrwAAAAI"]
[Tue Jul 21 08:04:56.518952 2026] [security2:error] [pid 358661:tid 358893] [client 20.151.10.161:28270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9SWAlWhjQfpOo60_HZsAAAAGM"]
[Tue Jul 21 08:04:56.687900 2026] [security2:error] [pid 352421:tid 352654] [client 20.104.96.117:7974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/ops.php"] [unique_id "al9SWMJSWzG9jbYOtu5LQwAAAOw"]
[Tue Jul 21 08:04:56.803899 2026] [security2:error] [pid 358661:tid 358839] [client 162.241.63.68:17934] ModSecurity: Access denied with code 400 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "67"] [id "390703"] [rev "5"] [msg "Atomicorp.com WAF Rules: Possible URL Encoding Abuse Attack Attempt"] [severity "NOTICE"] [hostname "regonegociosimobiliarios.com.br"] [uri "/%post_type%/casa-ou-apartamento-o-que-e-melhor-para-voce/"] [unique_id "al9SWAlWhjQfpOo60_HZtQAAAC0"]
[Tue Jul 21 08:04:56.969147 2026] [security2:error] [pid 358661:tid 358810] [client 182.8.255.181:17519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SWAlWhjQfpOo60_HZuAAAABA"]
[Tue Jul 21 08:04:56.969261 2026] [security2:error] [pid 358661:tid 358810] [client 182.8.255.181:17519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SWAlWhjQfpOo60_HZuAAAABA"]
[Tue Jul 21 08:04:57.029537 2026] [security2:error] [pid 352421:tid 352485] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SWcJSWzG9jbYOtu5LSAAAuD8"]
[Tue Jul 21 08:04:57.029700 2026] [security2:error] [pid 352421:tid 352602] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SWcJSWzG9jbYOtu5LSAAAuD8"]
[Tue Jul 21 08:04:57.062546 2026] [security2:error] [pid 352421:tid 352591] [client 20.29.126.15:3065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/simple.php"] [unique_id "al9SWcJSWzG9jbYOtu5LSgAAAK0"]
[Tue Jul 21 08:04:57.161157 2026] [security2:error] [pid 352421:tid 352626] [client 102.206.115.33:64189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SWcJSWzG9jbYOtu5LTQAAANA"]
[Tue Jul 21 08:04:57.161264 2026] [security2:error] [pid 352421:tid 352626] [client 102.206.115.33:64189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SWcJSWzG9jbYOtu5LTQAAANA"]
[Tue Jul 21 08:04:57.172608 2026] [fcgid:warn] [pid 352421:tid 352640] (70014)End of file found: [client 66.132.172.128:43312] mod_fcgid: can't get data from http client
[Tue Jul 21 08:04:57.218535 2026] [security2:error] [pid 358661:tid 358670] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SWQlWhjQfpOo60_HZugAATAU"]
[Tue Jul 21 08:04:57.218686 2026] [security2:error] [pid 358661:tid 358870] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SWQlWhjQfpOo60_HZugAATAU"]
[Tue Jul 21 08:04:57.426453 2026] [security2:error] [pid 358661:tid 358906] [client 20.104.96.117:7588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/file31.php"] [unique_id "al9SWQlWhjQfpOo60_HZ-gAAAHA"]
[Tue Jul 21 08:04:57.613923 2026] [security2:error] [pid 352421:tid 352661] [client 65.21.113.253:54680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SWcJSWzG9jbYOtu5LTAAAAPM"]
[Tue Jul 21 08:04:57.691298 2026] [security2:error] [pid 358661:tid 358875] [client 65.21.113.253:56748] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SWQlWhjQfpOo60_HaBgAAAFE"]
[Tue Jul 21 08:04:57.776439 2026] [security2:error] [pid 358661:tid 358800] [client 106.215.181.8:19253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.181.215.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SWQlWhjQfpOo60_HaCwAAAAY"]
[Tue Jul 21 08:04:57.776537 2026] [security2:error] [pid 358661:tid 358800] [client 106.215.181.8:19253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SWQlWhjQfpOo60_HaCwAAAAY"]
[Tue Jul 21 08:04:57.957076 2026] [security2:error] [pid 358661:tid 358916] [client 120.56.162.40:50850] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SVwlWhjQfpOo60_HZmAAAAHo"]
[Tue Jul 21 08:04:57.957205 2026] [security2:error] [pid 358661:tid 358916] [client 120.56.162.40:50850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SVwlWhjQfpOo60_HZmAAAAHo"]
[Tue Jul 21 08:04:58.006680 2026] [security2:error] [pid 352421:tid 352647] [client 204.8.98.45:57440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9SWsJSWzG9jbYOtu5LXgAAAOU"]
[Tue Jul 21 08:04:58.006793 2026] [security2:error] [pid 352421:tid 352647] [client 204.8.98.45:57440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9SWsJSWzG9jbYOtu5LXgAAAOU"]
[Tue Jul 21 08:04:58.066138 2026] [security2:error] [pid 352421:tid 352588] [client 20.104.96.117:7585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/file6.php"] [unique_id "al9SWsJSWzG9jbYOtu5LXwAAAKo"]
[Tue Jul 21 08:04:58.099197 2026] [security2:error] [pid 358661:tid 358901] [client 162.241.63.68:17956] ModSecurity: Access denied with code 400 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "67"] [id "390703"] [rev "5"] [msg "Atomicorp.com WAF Rules: Possible URL Encoding Abuse Attack Attempt"] [severity "NOTICE"] [hostname "regonegociosimobiliarios.com.br"] [uri "/%post_type%/casa-ou-apartamento-o-que-e-melhor-para-voce/"] [unique_id "al9SWglWhjQfpOo60_HaDwAAAGs"]
[Tue Jul 21 08:04:58.357350 2026] [security2:error] [pid 352421:tid 352610] [client 65.21.113.253:54680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SWcJSWzG9jbYOtu5LXQAAAMA"]
[Tue Jul 21 08:04:58.387044 2026] [security2:error] [pid 352421:tid 352617] [client 20.197.192.193:53147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/hunter.php"] [unique_id "al9SWsJSWzG9jbYOtu5LZgAAAMc"]
[Tue Jul 21 08:04:58.461392 2026] [security2:error] [pid 358661:tid 358826] [client 202.143.127.214:58906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SWglWhjQfpOo60_HaGgAAACA"]
[Tue Jul 21 08:04:58.461502 2026] [security2:error] [pid 358661:tid 358826] [client 202.143.127.214:58906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SWglWhjQfpOo60_HaGgAAACA"]
[Tue Jul 21 08:04:58.498676 2026] [autoindex:error] [pid 358661:tid 358904] [client 20.104.96.117:7956] AH01276: Cannot serve directory /home3/tkcorr80/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:04:58.514600 2026] [security2:error] [pid 358661:tid 358865] [client 20.151.10.161:28562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file.php"] [unique_id "al9SWglWhjQfpOo60_HaHgAAAEc"]
[Tue Jul 21 08:04:58.576552 2026] [security2:error] [pid 358661:tid 358914] [client 103.78.200.11:60260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SWglWhjQfpOo60_HaHwAAAHg"]
[Tue Jul 21 08:04:58.579206 2026] [security2:error] [pid 358661:tid 358914] [client 103.78.200.11:60260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SWglWhjQfpOo60_HaHwAAAHg"]
[Tue Jul 21 08:04:58.591748 2026] [security2:error] [pid 358661:tid 358829] [client 209.112.91.75:37572] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mulher-de-valor.com"] [uri "/wp-config.php.bak"] [unique_id "al9SWglWhjQfpOo60_HaIQAAACM"]
[Tue Jul 21 08:04:58.760285 2026] [security2:error] [pid 358661:tid 358823] [client 209.112.91.75:37560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.91.112.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mulher-de-valor.com"] [uri "/wp-config.php"] [unique_id "al9SWglWhjQfpOo60_HaIwAAAB0"]
[Tue Jul 21 08:04:58.772872 2026] [security2:error] [pid 358661:tid 358871] [client 20.104.96.117:7956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/adminfuns.php"] [unique_id "al9SWglWhjQfpOo60_HaKgAAAE0"]
[Tue Jul 21 08:04:58.857280 2026] [security2:error] [pid 358661:tid 358799] [client 87.116.180.198:27347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SWglWhjQfpOo60_HaLgAAAAU"]
[Tue Jul 21 08:04:58.860650 2026] [security2:error] [pid 358661:tid 358799] [client 87.116.180.198:27347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SWglWhjQfpOo60_HaLgAAAAU"]
[Tue Jul 21 08:04:58.991174 2026] [security2:error] [pid 358661:tid 358806] [client 204.8.98.45:35604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9SWglWhjQfpOo60_HaNAAAAAw"]
[Tue Jul 21 08:04:58.991266 2026] [security2:error] [pid 358661:tid 358806] [client 204.8.98.45:35604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9SWglWhjQfpOo60_HaNAAAAAw"]
[Tue Jul 21 08:04:59.120317 2026] [security2:error] [pid 358661:tid 358847] [client 45.132.227.208:26189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiferreira.com.br"] [uri "/wp-login.php"] [unique_id "al9SWQlWhjQfpOo60_HZuQAAADU"]
[Tue Jul 21 08:04:59.162092 2026] [security2:error] [pid 358661:tid 358870] [client 103.29.114.44:44788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SWwlWhjQfpOo60_HaOQAAAEw"]
[Tue Jul 21 08:04:59.162195 2026] [security2:error] [pid 358661:tid 358870] [client 103.29.114.44:44788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SWwlWhjQfpOo60_HaOQAAAEw"]
[Tue Jul 21 08:04:59.167386 2026] [security2:error] [pid 358661:tid 358677] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SWwlWhjQfpOo60_HaOgAAEQw"]
[Tue Jul 21 08:04:59.167477 2026] [security2:error] [pid 358661:tid 358811] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SWwlWhjQfpOo60_HaOgAAEQw"]
[Tue Jul 21 08:04:59.584806 2026] [security2:error] [pid 358661:tid 358794] [client 20.151.10.161:28263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/cfile.php"] [unique_id "al9SWwlWhjQfpOo60_HaQQAAAAA"]
[Tue Jul 21 08:04:59.680421 2026] [access_compat:error] [pid 358661:tid 358907] [client 162.241.63.68:44962] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:05:00.008352 2026] [security2:error] [pid 358661:tid 358888] [client 117.247.80.59:12728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SXAlWhjQfpOo60_HaSgAAAF4"]
[Tue Jul 21 08:05:00.008443 2026] [security2:error] [pid 358661:tid 358888] [client 117.247.80.59:12728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SXAlWhjQfpOo60_HaSgAAAF4"]
[Tue Jul 21 08:05:00.015168 2026] [security2:error] [pid 358661:tid 358918] [client 20.104.96.117:7944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/goods.php"] [unique_id "al9SXAlWhjQfpOo60_HaTAAAAHw"]
[Tue Jul 21 08:05:00.043323 2026] [security2:error] [pid 358661:tid 358881] [client 193.36.225.70:29785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SWglWhjQfpOo60_HaLwAAAFc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:05:00.506636 2026] [security2:error] [pid 358661:tid 358826] [client 20.29.126.15:4132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/404.php"] [unique_id "al9SXAlWhjQfpOo60_HaUQAAACA"]
[Tue Jul 21 08:05:00.688732 2026] [security2:error] [pid 358661:tid 358744] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SXAlWhjQfpOo60_HaWwAAbk8"]
[Tue Jul 21 08:05:00.688915 2026] [security2:error] [pid 358661:tid 358904] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SXAlWhjQfpOo60_HaWwAAbk8"]
[Tue Jul 21 08:05:00.885292 2026] [security2:error] [pid 358661:tid 358855] [client 178.153.91.96:34635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SXAlWhjQfpOo60_HaXgAAAD0"]
[Tue Jul 21 08:05:00.885400 2026] [security2:error] [pid 358661:tid 358855] [client 178.153.91.96:34635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SXAlWhjQfpOo60_HaXgAAAD0"]
[Tue Jul 21 08:05:01.056680 2026] [security2:error] [pid 358661:tid 358822] [client 92.119.178.3:43172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SXQlWhjQfpOo60_HaZAAAABw"]
[Tue Jul 21 08:05:01.056756 2026] [security2:error] [pid 358661:tid 358822] [client 92.119.178.3:43172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SXQlWhjQfpOo60_HaZAAAABw"]
[Tue Jul 21 08:05:01.063843 2026] [security2:error] [pid 352421:tid 352610] [client 20.104.96.117:7574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/100.php"] [unique_id "al9SXcJSWzG9jbYOtu5LkQAAAMA"]
[Tue Jul 21 08:05:01.087480 2026] [security2:error] [pid 358661:tid 358805] [client 65.21.113.253:56748] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SXQlWhjQfpOo60_HaZQAAAAs"]
[Tue Jul 21 08:05:01.328479 2026] [security2:error] [pid 352421:tid 352506] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SXcJSWzG9jbYOtu5LlgAAs1Q"]
[Tue Jul 21 08:05:01.328762 2026] [security2:error] [pid 352421:tid 352597] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SXcJSWzG9jbYOtu5LlgAAs1Q"]
[Tue Jul 21 08:05:01.425680 2026] [security2:error] [pid 358661:tid 358799] [client 20.197.192.193:53131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/we.php"] [unique_id "al9SXQlWhjQfpOo60_HaZwAAAAU"]
[Tue Jul 21 08:05:01.600886 2026] [security2:error] [pid 358661:tid 358806] [client 20.197.192.193:53159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/jga.php"] [unique_id "al9SXQlWhjQfpOo60_HaagAAAAw"]
[Tue Jul 21 08:05:01.667533 2026] [security2:error] [pid 358661:tid 358824] [client 65.21.113.253:54428] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SXQlWhjQfpOo60_HaZgAAAB4"]
[Tue Jul 21 08:05:01.671587 2026] [security2:error] [pid 358661:tid 358823] [client 117.210.135.0:49298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SXQlWhjQfpOo60_HabAAAAB0"]
[Tue Jul 21 08:05:01.671713 2026] [security2:error] [pid 358661:tid 358823] [client 117.210.135.0:49298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SXQlWhjQfpOo60_HabAAAAB0"]
[Tue Jul 21 08:05:01.752764 2026] [security2:error] [pid 352421:tid 352573] [client 20.151.10.161:28187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/class-wp.php"] [unique_id "al9SXcJSWzG9jbYOtu5LogAAAJs"]
[Tue Jul 21 08:05:02.169198 2026] [security2:error] [pid 358661:tid 358858] [client 175.144.82.48:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SXglWhjQfpOo60_HacAAAAEA"]
[Tue Jul 21 08:05:02.169913 2026] [security2:error] [pid 358661:tid 358858] [client 175.144.82.48:50238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SXglWhjQfpOo60_HacAAAAEA"]
[Tue Jul 21 08:05:02.177150 2026] [security2:error] [pid 352421:tid 352613] [client 65.21.113.253:54440] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SXcJSWzG9jbYOtu5LpAAAAMM"]
[Tue Jul 21 08:05:02.536604 2026] [security2:error] [pid 352421:tid 352599] [client 109.60.28.94:4347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SXsJSWzG9jbYOtu5LsQAAALU"]
[Tue Jul 21 08:05:02.536742 2026] [security2:error] [pid 352421:tid 352599] [client 109.60.28.94:4347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SXsJSWzG9jbYOtu5LsQAAALU"]
[Tue Jul 21 08:05:02.944337 2026] [security2:error] [pid 352421:tid 352451] [remote 34.74.242.206:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sejabarbara.com.br"] [uri "/robots.txt"] [unique_id "al9SXsJSWzG9jbYOtu5LtgAA2R0"]
[Tue Jul 21 08:05:02.944478 2026] [security2:error] [pid 352421:tid 352635] [client 34.74.242.206:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sejabarbara.com.br"] [uri "/robots.txt"] [unique_id "al9SXsJSWzG9jbYOtu5LtgAA2R0"]
[Tue Jul 21 08:05:03.004600 2026] [security2:error] [pid 358661:tid 358902] [client 38.100.221.102:17582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SXwlWhjQfpOo60_HaegAAAGw"]
[Tue Jul 21 08:05:03.004740 2026] [security2:error] [pid 358661:tid 358902] [client 38.100.221.102:17582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SXwlWhjQfpOo60_HaegAAAGw"]
[Tue Jul 21 08:05:03.081721 2026] [security2:error] [pid 352421:tid 352604] [client 103.166.103.129:59884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SX8JSWzG9jbYOtu5LuQAAALo"]
[Tue Jul 21 08:05:03.081924 2026] [security2:error] [pid 352421:tid 352604] [client 103.166.103.129:59884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SX8JSWzG9jbYOtu5LuQAAALo"]
[Tue Jul 21 08:05:03.240881 2026] [security2:error] [pid 358661:tid 358819] [client 122.179.91.63:6320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SXwlWhjQfpOo60_HagAAAABk"]
[Tue Jul 21 08:05:03.241017 2026] [security2:error] [pid 358661:tid 358819] [client 122.179.91.63:6320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SXwlWhjQfpOo60_HagAAAABk"]
[Tue Jul 21 08:05:03.262003 2026] [security2:error] [pid 358661:tid 358900] [client 20.104.96.117:7242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/about.php"] [unique_id "al9SXwlWhjQfpOo60_HagQAAAGo"]
[Tue Jul 21 08:05:03.361829 2026] [security2:error] [pid 358661:tid 358707] [remote 34.74.242.206:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sejabarbara.com.br"] [uri "/"] [unique_id "al9SXwlWhjQfpOo60_HaggAAUio"]
[Tue Jul 21 08:05:03.362126 2026] [security2:error] [pid 358661:tid 358876] [client 34.74.242.206:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sejabarbara.com.br"] [uri "/"] [unique_id "al9SXwlWhjQfpOo60_HaggAAUio"]
[Tue Jul 21 08:05:03.674146 2026] [security2:error] [pid 358661:tid 358910] [client 65.21.113.253:56748] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SXwlWhjQfpOo60_HaiAAAAHQ"]
[Tue Jul 21 08:05:04.111239 2026] [security2:error] [pid 352421:tid 352435] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SYMJSWzG9jbYOtu5LxwAAiQ0"]
[Tue Jul 21 08:05:04.111380 2026] [security2:error] [pid 352421:tid 352555] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SYMJSWzG9jbYOtu5LxwAAiQ0"]
[Tue Jul 21 08:05:04.308116 2026] [security2:error] [pid 358661:tid 358800] [client 65.21.113.253:54428] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SXwlWhjQfpOo60_HajAAAAAY"]
[Tue Jul 21 08:05:04.409457 2026] [security2:error] [pid 358661:tid 358825] [client 20.29.126.15:2520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/file3.php"] [unique_id "al9SYAlWhjQfpOo60_HakgAAAB8"]
[Tue Jul 21 08:05:04.880593 2026] [security2:error] [pid 358661:tid 358866] [client 20.104.96.117:7958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/about.php"] [unique_id "al9SYAlWhjQfpOo60_HamgAAAEg"]
[Tue Jul 21 08:05:04.958826 2026] [security2:error] [pid 352421:tid 352563] [client 204.8.98.45:35612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9SYMJSWzG9jbYOtu5L1QAAAJE"]
[Tue Jul 21 08:05:04.958927 2026] [security2:error] [pid 352421:tid 352563] [client 204.8.98.45:35612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9SYMJSWzG9jbYOtu5L1QAAAJE"]
[Tue Jul 21 08:05:04.986069 2026] [security2:error] [pid 352421:tid 352641] [client 141.11.107.74:64378] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "artetoner.com.br"] [uri "/"] [unique_id "al9SYMJSWzG9jbYOtu5L1gAAAN8"]
[Tue Jul 21 08:05:04.987408 2026] [security2:error] [pid 358661:tid 358874] [client 141.11.107.74:64384] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.artetoner.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9SYAlWhjQfpOo60_HanQAAAFA"]
[Tue Jul 21 08:05:05.004845 2026] [security2:error] [pid 358661:tid 358861] [client 141.11.107.74:64396] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.artetoner.com.br"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "al9SYQlWhjQfpOo60_HangAAAEM"]
[Tue Jul 21 08:05:05.006801 2026] [security2:error] [pid 352421:tid 352668] [client 141.11.107.74:64398] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ftp.artetoner.com.br"] [uri "/"] [unique_id "al9SYcJSWzG9jbYOtu5L1wAAAPo"]
[Tue Jul 21 08:05:05.013891 2026] [security2:error] [pid 358661:tid 358845] [client 141.11.107.74:64406] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.artetoner.com.br"] [uri "/"] [unique_id "al9SYQlWhjQfpOo60_HanwAAADM"]
[Tue Jul 21 08:05:05.015046 2026] [security2:error] [pid 358661:tid 358863] [client 141.11.107.74:64404] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.artetoner.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9SYQlWhjQfpOo60_HaoAAAAEU"]
[Tue Jul 21 08:05:05.042141 2026] [security2:error] [pid 358661:tid 358921] [client 141.11.107.74:64433] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.artetoner.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9SYQlWhjQfpOo60_HaoQAAAH8"]
[Tue Jul 21 08:05:05.042141 2026] [security2:error] [pid 358661:tid 358794] [client 141.11.107.74:64427] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.artetoner.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9SYQlWhjQfpOo60_HaogAAAAA"]
[Tue Jul 21 08:05:05.060807 2026] [security2:error] [pid 358661:tid 358821] [client 193.36.225.65:35105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SYQlWhjQfpOo60_HaowAAABs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:05:05.076821 2026] [security2:error] [pid 352421:tid 352564] [client 141.11.107.74:64445] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.artetoner.com.br"] [uri "/"] [unique_id "al9SYcJSWzG9jbYOtu5L2AAAAJI"]
[Tue Jul 21 08:05:05.209034 2026] [security2:error] [pid 352421:tid 352575] [client 20.151.10.161:28227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/admin.php"] [unique_id "al9SYcJSWzG9jbYOtu5L3QAAAJ0"]
[Tue Jul 21 08:05:05.221913 2026] [security2:error] [pid 358661:tid 358831] [client 41.68.90.219:51194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SYQlWhjQfpOo60_HaqgAAACU"]
[Tue Jul 21 08:05:05.222868 2026] [security2:error] [pid 358661:tid 358831] [client 41.68.90.219:51194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SYQlWhjQfpOo60_HaqgAAACU"]
[Tue Jul 21 08:05:05.755927 2026] [security2:error] [pid 358661:tid 358885] [client 65.21.113.253:56748] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SYQlWhjQfpOo60_HatwAAAFs"]
[Tue Jul 21 08:05:06.128984 2026] [security2:error] [pid 358661:tid 358757] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SYglWhjQfpOo60_HauwAAZFw"]
[Tue Jul 21 08:05:06.129135 2026] [security2:error] [pid 358661:tid 358894] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SYglWhjQfpOo60_HauwAAZFw"]
[Tue Jul 21 08:05:06.227050 2026] [security2:error] [pid 358661:tid 358823] [client 20.197.192.193:53152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atividadessprontas.online"] [uri "/phpinfo.php1"] [unique_id "al9SYglWhjQfpOo60_HavgAAAB0"]
[Tue Jul 21 08:05:06.262455 2026] [security2:error] [pid 352421:tid 352607] [client 120.56.162.40:51303] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SYsJSWzG9jbYOtu5L7QAAAL0"]
[Tue Jul 21 08:05:06.262683 2026] [security2:error] [pid 352421:tid 352607] [client 120.56.162.40:51303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SYsJSWzG9jbYOtu5L7QAAAL0"]
[Tue Jul 21 08:05:06.304283 2026] [security2:error] [pid 358661:tid 358871] [client 20.104.96.117:7999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/admin.php"] [unique_id "al9SYglWhjQfpOo60_HavwAAAE0"]
[Tue Jul 21 08:05:06.644947 2026] [security2:error] [pid 352421:tid 352531] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SYsJSWzG9jbYOtu5L8wAA6W0"]
[Tue Jul 21 08:05:06.645067 2026] [security2:error] [pid 352421:tid 352651] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SYsJSWzG9jbYOtu5L8wAA6W0"]
[Tue Jul 21 08:05:06.686700 2026] [security2:error] [pid 352421:tid 352596] [client 196.251.121.187:59058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "pme.principiamatematica.com"] [uri "/"] [unique_id "al9SYsJSWzG9jbYOtu5L9QAAALI"]
[Tue Jul 21 08:05:06.760987 2026] [security2:error] [pid 358661:tid 358874] [client 20.151.10.161:28197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/aa2.php"] [unique_id "al9SYglWhjQfpOo60_HayAAAAFA"]
[Tue Jul 21 08:05:06.902298 2026] [security2:error] [pid 358661:tid 358801] [client 65.21.113.253:54454] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SYglWhjQfpOo60_HawgAAAAc"]
[Tue Jul 21 08:05:06.924259 2026] [security2:error] [pid 352421:tid 352637] [client 20.104.96.117:7586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/admin.php"] [unique_id "al9SYsJSWzG9jbYOtu5L-gAAANs"]
[Tue Jul 21 08:05:07.407191 2026] [security2:error] [pid 352421:tid 352574] [client 65.21.113.253:54466] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SYsJSWzG9jbYOtu5L-QAAAJw"]
[Tue Jul 21 08:05:07.486319 2026] [security2:error] [pid 358661:tid 358829] [client 182.8.255.181:17509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SYwlWhjQfpOo60_HazQAAACM"]
[Tue Jul 21 08:05:07.486411 2026] [security2:error] [pid 358661:tid 358829] [client 182.8.255.181:17509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SYwlWhjQfpOo60_HazQAAACM"]
[Tue Jul 21 08:05:07.685626 2026] [security2:error] [pid 358661:tid 358845] [client 102.206.115.33:57820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SYwlWhjQfpOo60_Ha0QAAADM"]
[Tue Jul 21 08:05:07.685892 2026] [security2:error] [pid 358661:tid 358845] [client 102.206.115.33:57820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SYwlWhjQfpOo60_Ha0QAAADM"]
[Tue Jul 21 08:05:07.758676 2026] [security2:error] [pid 358661:tid 358876] [client 20.104.96.117:7966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/themes.php"] [unique_id "al9SYwlWhjQfpOo60_Ha1AAAAFI"]
[Tue Jul 21 08:05:08.049982 2026] [security2:error] [pid 358661:tid 358674] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SZAlWhjQfpOo60_Ha2gAAOAk"]
[Tue Jul 21 08:05:08.050584 2026] [security2:error] [pid 358661:tid 358850] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SZAlWhjQfpOo60_Ha2gAAOAk"]
[Tue Jul 21 08:05:08.109040 2026] [security2:error] [pid 358661:tid 358720] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZAlWhjQfpOo60_Ha2wAAdDc"]
[Tue Jul 21 08:05:08.109238 2026] [security2:error] [pid 358661:tid 358910] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZAlWhjQfpOo60_Ha2wAAdDc"]
[Tue Jul 21 08:05:08.159148 2026] [security2:error] [pid 358661:tid 358893] [client 20.29.126.15:6864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/wp-mail.php"] [unique_id "al9SZAlWhjQfpOo60_Ha3QAAAGM"]
[Tue Jul 21 08:05:08.403231 2026] [security2:error] [pid 358661:tid 358685] [remote 69.171.234.32:62088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9SZAlWhjQfpOo60_Ha4gAAJhQ"]
[Tue Jul 21 08:05:08.463929 2026] [autoindex:error] [pid 358661:tid 358894] [client 20.104.96.117:7989] AH01276: Cannot serve directory /home3/tkcorr80/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:05:08.729763 2026] [security2:error] [pid 358661:tid 358843] [client 136.144.33.99:28909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SZAlWhjQfpOo60_Ha6QAAADE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:05:08.751636 2026] [core:error] [pid 358661:tid 358803] [client 20.104.96.117:7989] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:05:08.751660 2026] [core:error] [pid 358661:tid 358803] [client 20.104.96.117:7989] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:05:09.133213 2026] [security2:error] [pid 352421:tid 352621] [client 20.151.10.161:28258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ccou.php"] [unique_id "al9SZcJSWzG9jbYOtu5MGQAAAMs"]
[Tue Jul 21 08:05:09.167202 2026] [security2:error] [pid 352421:tid 352580] [client 103.78.200.11:60762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZcJSWzG9jbYOtu5MGgAAAKI"]
[Tue Jul 21 08:05:09.167322 2026] [security2:error] [pid 352421:tid 352580] [client 103.78.200.11:60762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZcJSWzG9jbYOtu5MGgAAAKI"]
[Tue Jul 21 08:05:09.429419 2026] [security2:error] [pid 358661:tid 358821] [client 20.104.96.117:7614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/.well-known/about.php"] [unique_id "al9SZQlWhjQfpOo60_Ha8gAAABs"]
[Tue Jul 21 08:05:09.525687 2026] [security2:error] [pid 358661:tid 358873] [client 87.116.180.198:27321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZQlWhjQfpOo60_Ha8wAAAE8"]
[Tue Jul 21 08:05:09.525794 2026] [security2:error] [pid 358661:tid 358873] [client 87.116.180.198:27321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZQlWhjQfpOo60_Ha8wAAAE8"]
[Tue Jul 21 08:05:09.562608 2026] [security2:error] [pid 358661:tid 358912] [client 202.143.127.214:59374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZQlWhjQfpOo60_Ha9AAAAHY"]
[Tue Jul 21 08:05:09.562717 2026] [security2:error] [pid 358661:tid 358912] [client 202.143.127.214:59374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZQlWhjQfpOo60_Ha9AAAAHY"]
[Tue Jul 21 08:05:09.706646 2026] [security2:error] [pid 358661:tid 358857] [client 103.29.114.44:9708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZQlWhjQfpOo60_Ha9gAAAD8"]
[Tue Jul 21 08:05:09.706801 2026] [security2:error] [pid 358661:tid 358857] [client 103.29.114.44:9708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZQlWhjQfpOo60_Ha9gAAAD8"]
[Tue Jul 21 08:05:10.106881 2026] [security2:error] [pid 358661:tid 358910] [client 20.104.96.117:7555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9SZglWhjQfpOo60_Ha-gAAAHQ"]
[Tue Jul 21 08:05:10.148291 2026] [security2:error] [pid 358661:tid 358771] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZglWhjQfpOo60_Ha_AAARmo"]
[Tue Jul 21 08:05:10.148465 2026] [security2:error] [pid 358661:tid 358864] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZglWhjQfpOo60_Ha_AAARmo"]
[Tue Jul 21 08:05:10.401607 2026] [security2:error] [pid 358661:tid 358885] [client 20.151.10.161:27949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/dr.php"] [unique_id "al9SZglWhjQfpOo60_Ha_wAAAFs"]
[Tue Jul 21 08:05:10.740978 2026] [security2:error] [pid 352421:tid 352603] [client 20.104.96.117:7955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wefile.php"] [unique_id "al9SZsJSWzG9jbYOtu5MNAAAALk"]
[Tue Jul 21 08:05:10.752846 2026] [security2:error] [pid 358661:tid 358813] [client 117.247.80.59:28304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZglWhjQfpOo60_HbBQAAABM"]
[Tue Jul 21 08:05:10.752986 2026] [security2:error] [pid 358661:tid 358813] [client 117.247.80.59:28304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZglWhjQfpOo60_HbBQAAABM"]
[Tue Jul 21 08:05:10.926461 2026] [security2:error] [pid 352421:tid 352557] [client 20.151.10.161:28571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/xamp.php"] [unique_id "al9SZsJSWzG9jbYOtu5MOgAAAIs"]
[Tue Jul 21 08:05:11.168398 2026] [security2:error] [pid 352421:tid 352495] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SZ8JSWzG9jbYOtu5MPQAA-Uk"]
[Tue Jul 21 08:05:11.168563 2026] [security2:error] [pid 352421:tid 352667] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SZ8JSWzG9jbYOtu5MPQAA-Uk"]
[Tue Jul 21 08:05:11.264273 2026] [security2:error] [pid 358661:tid 358851] [client 92.119.178.3:34884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9SZwlWhjQfpOo60_HbCgAAADk"]
[Tue Jul 21 08:05:11.264447 2026] [security2:error] [pid 358661:tid 358851] [client 92.119.178.3:34884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9SZwlWhjQfpOo60_HbCgAAADk"]
[Tue Jul 21 08:05:11.353571 2026] [security2:error] [pid 358661:tid 358866] [client 20.151.10.161:28553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/bless.php"] [unique_id "al9SZwlWhjQfpOo60_HbDgAAAEg"]
[Tue Jul 21 08:05:11.367579 2026] [security2:error] [pid 358661:tid 358878] [client 20.104.96.117:7952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9SZwlWhjQfpOo60_HbDwAAAFQ"]
[Tue Jul 21 08:05:11.404104 2026] [security2:error] [pid 352421:tid 352625] [client 178.153.91.96:57646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SZ8JSWzG9jbYOtu5MQgAAAM8"]
[Tue Jul 21 08:05:11.404217 2026] [security2:error] [pid 352421:tid 352625] [client 178.153.91.96:57646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SZ8JSWzG9jbYOtu5MQgAAAM8"]
[Tue Jul 21 08:05:11.429779 2026] [security2:error] [pid 358661:tid 358892] [client 20.197.192.193:52260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/x.php"] [unique_id "al9SZwlWhjQfpOo60_HbEAAAAGI"]
[Tue Jul 21 08:05:11.705545 2026] [autoindex:error] [pid 358661:tid 358821] [client 20.104.96.117:7975] AH01276: Cannot serve directory /home3/tkcorr80/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:05:11.793272 2026] [security2:error] [pid 352421:tid 352656] [client 20.151.10.161:28040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file46.php"] [unique_id "al9SZ8JSWzG9jbYOtu5MSQAAAO4"]
[Tue Jul 21 08:05:11.879142 2026] [security2:error] [pid 352421:tid 352527] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZ8JSWzG9jbYOtu5MTAAA32k"]
[Tue Jul 21 08:05:11.879334 2026] [security2:error] [pid 352421:tid 352641] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SZ8JSWzG9jbYOtu5MTAAA32k"]
[Tue Jul 21 08:05:12.056297 2026] [autoindex:error] [pid 358661:tid 358794] [client 20.104.96.117:7975] AH01276: Cannot serve directory /home3/tkcorr80/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:05:12.205550 2026] [security2:error] [pid 358661:tid 358809] [client 20.104.96.117:7975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9SaAlWhjQfpOo60_HbIAAAAA8"]
[Tue Jul 21 08:05:12.258473 2026] [security2:error] [pid 352421:tid 352617] [client 117.210.135.0:50023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SaMJSWzG9jbYOtu5MUQAAAMc"]
[Tue Jul 21 08:05:12.258700 2026] [security2:error] [pid 352421:tid 352617] [client 117.210.135.0:50023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SaMJSWzG9jbYOtu5MUQAAAMc"]
[Tue Jul 21 08:05:12.280956 2026] [security2:error] [pid 352421:tid 352669] [client 20.151.10.161:28087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/eee.php"] [unique_id "al9SaMJSWzG9jbYOtu5MUwAAAPs"]
[Tue Jul 21 08:05:12.285055 2026] [security2:error] [pid 352421:tid 352644] [client 65.21.113.253:54466] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SZ8JSWzG9jbYOtu5MSAAAAOI"]
[Tue Jul 21 08:05:12.500477 2026] [security2:error] [pid 352421:tid 352648] [client 20.104.96.117:7947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/8.php"] [unique_id "al9SaMJSWzG9jbYOtu5MVgAAAOY"]
[Tue Jul 21 08:05:12.524787 2026] [security2:error] [pid 352421:tid 352585] [client 20.197.192.193:53172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9SaMJSWzG9jbYOtu5MVwAAAKc"]
[Tue Jul 21 08:05:12.583788 2026] [security2:error] [pid 352421:tid 352573] [client 20.29.126.15:10057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/about.php"] [unique_id "al9SaMJSWzG9jbYOtu5MWAAAAJs"]
[Tue Jul 21 08:05:12.584786 2026] [security2:error] [pid 358661:tid 358873] [client 175.144.82.48:50695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SaAlWhjQfpOo60_HbJQAAAE8"]
[Tue Jul 21 08:05:12.585581 2026] [security2:error] [pid 358661:tid 358873] [client 175.144.82.48:50695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SaAlWhjQfpOo60_HbJQAAAE8"]
[Tue Jul 21 08:05:12.734406 2026] [security2:error] [pid 352421:tid 352586] [client 136.144.33.215:44909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SaMJSWzG9jbYOtu5MVQAAAKg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:05:12.863298 2026] [security2:error] [pid 358661:tid 358812] [client 20.151.10.161:28285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file25.php"] [unique_id "al9SaAlWhjQfpOo60_HbKwAAABI"]
[Tue Jul 21 08:05:12.890904 2026] [security2:error] [pid 352421:tid 352672] [client 20.104.96.117:7571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9SaMJSWzG9jbYOtu5MXwAAAP4"]
[Tue Jul 21 08:05:12.934962 2026] [security2:error] [pid 358661:tid 358885] [client 198.54.128.138:52490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SaAlWhjQfpOo60_HbLAAAAFs"]
[Tue Jul 21 08:05:12.935045 2026] [security2:error] [pid 358661:tid 358885] [client 198.54.128.138:52490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SaAlWhjQfpOo60_HbLAAAAFs"]
[Tue Jul 21 08:05:13.149726 2026] [security2:error] [pid 352421:tid 352577] [client 122.179.91.63:29287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SacJSWzG9jbYOtu5MYQAAAJ8"]
[Tue Jul 21 08:05:13.149922 2026] [security2:error] [pid 352421:tid 352577] [client 122.179.91.63:29287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9SacJSWzG9jbYOtu5MYQAAAJ8"]
[Tue Jul 21 08:05:13.371666 2026] [security2:error] [pid 352421:tid 352635] [client 20.104.96.117:7286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/f6.php"] [unique_id "al9SacJSWzG9jbYOtu5MZwAAANk"]
[Tue Jul 21 08:05:13.387462 2026] [security2:error] [pid 358661:tid 358830] [client 109.60.28.94:63362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SaQlWhjQfpOo60_HbMAAAACQ"]
[Tue Jul 21 08:05:13.387575 2026] [security2:error] [pid 358661:tid 358830] [client 109.60.28.94:63362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SaQlWhjQfpOo60_HbMAAAACQ"]
[Tue Jul 21 08:05:13.437480 2026] [security2:error] [pid 352421:tid 352618] [client 20.151.10.161:28565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file48.php"] [unique_id "al9SacJSWzG9jbYOtu5MagAAAMg"]
[Tue Jul 21 08:05:13.536257 2026] [security2:error] [pid 352421:tid 352513] [remote 114.34.90.9:57378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9SacJSWzG9jbYOtu5MbAABBFs"]
[Tue Jul 21 08:05:13.621674 2026] [security2:error] [pid 358661:tid 358823] [client 65.21.113.253:59534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SaQlWhjQfpOo60_HbMgAAAB0"]
[Tue Jul 21 08:05:13.847922 2026] [autoindex:error] [pid 358661:tid 358675] [remote 74.7.227.39:43264] AH01276: Cannot serve directory /home1/pedid516/parceiroraizenpower.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:05:13.923882 2026] [security2:error] [pid 358661:tid 358800] [client 103.166.103.129:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SaQlWhjQfpOo60_HbNgAAAAY"]
[Tue Jul 21 08:05:13.923988 2026] [security2:error] [pid 358661:tid 358800] [client 103.166.103.129:60412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SaQlWhjQfpOo60_HbNgAAAAY"]
[Tue Jul 21 08:05:13.993409 2026] [security2:error] [pid 358661:tid 358858] [client 20.104.96.117:7557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/inputs.php"] [unique_id "al9SaQlWhjQfpOo60_HbNwAAAEA"]
[Tue Jul 21 08:05:14.242333 2026] [security2:error] [pid 352421:tid 352637] [client 65.21.113.253:54466] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SacJSWzG9jbYOtu5McAAAANs"]
[Tue Jul 21 08:05:14.272926 2026] [security2:error] [pid 352421:tid 352667] [client 74.7.241.146:36420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "parceiroraizenpower.com.pedido-online.net"] [uri "/cgi-sys/404.html"] [unique_id "al9SasJSWzG9jbYOtu5MdgAA-Xk"]
[Tue Jul 21 08:05:14.378580 2026] [security2:error] [pid 358661:tid 358856] [client 20.151.10.161:28247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file6.php"] [unique_id "al9SaglWhjQfpOo60_HbPQAAAD4"]
[Tue Jul 21 08:05:14.398508 2026] [security2:error] [pid 352421:tid 352590] [client 20.104.96.117:7967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/inputs.php"] [unique_id "al9SasJSWzG9jbYOtu5MeQAAAKw"]
[Tue Jul 21 08:05:14.773766 2026] [security2:error] [pid 358661:tid 358862] [client 20.104.96.117:7986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/classwithtostring.php"] [unique_id "al9SaglWhjQfpOo60_HbRgAAAEQ"]
[Tue Jul 21 08:05:15.093916 2026] [security2:error] [pid 358661:tid 358716] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SawlWhjQfpOo60_HbSwAAMDM"]
[Tue Jul 21 08:05:15.094054 2026] [security2:error] [pid 358661:tid 358842] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SawlWhjQfpOo60_HbSwAAMDM"]
[Tue Jul 21 08:05:15.412493 2026] [security2:error] [pid 352421:tid 352644] [client 20.104.96.117:7568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9Sa8JSWzG9jbYOtu5MhwAAAOI"]
[Tue Jul 21 08:05:15.477969 2026] [security2:error] [pid 358661:tid 358897] [client 20.29.126.15:6656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/adminfuns.php"] [unique_id "al9SawlWhjQfpOo60_HbUQAAAGc"]
[Tue Jul 21 08:05:15.606858 2026] [security2:error] [pid 358661:tid 358893] [client 151.63.71.144:63276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9SawlWhjQfpOo60_HbUgAAAGM"]
[Tue Jul 21 08:05:15.606992 2026] [security2:error] [pid 358661:tid 358893] [client 151.63.71.144:63276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9SawlWhjQfpOo60_HbUgAAAGM"]
[Tue Jul 21 08:05:15.793307 2026] [security2:error] [pid 352421:tid 352564] [client 41.68.90.219:51655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sa8JSWzG9jbYOtu5MjQAAAJI"]
[Tue Jul 21 08:05:15.795443 2026] [security2:error] [pid 352421:tid 352564] [client 41.68.90.219:51655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sa8JSWzG9jbYOtu5MjQAAAJI"]
[Tue Jul 21 08:05:15.821717 2026] [security2:error] [pid 358661:tid 358826] [client 20.104.96.117:7238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-blog.php"] [unique_id "al9SawlWhjQfpOo60_HbVwAAACA"]
[Tue Jul 21 08:05:16.210820 2026] [autoindex:error] [pid 358661:tid 358891] [client 20.104.96.117:8066] AH01276: Cannot serve directory /home3/tkcorr80/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:05:16.406206 2026] [security2:error] [pid 358661:tid 358913] [client 65.21.113.253:48552] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SawlWhjQfpOo60_HbWAAAAHc"]
[Tue Jul 21 08:05:16.484975 2026] [security2:error] [pid 358661:tid 358803] [client 20.104.96.117:8066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9SbAlWhjQfpOo60_HbYAAAAAk"]
[Tue Jul 21 08:05:16.553048 2026] [security2:error] [pid 358661:tid 358871] [client 20.151.10.161:28605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/a2.php"] [unique_id "al9SbAlWhjQfpOo60_HbYwAAAE0"]
[Tue Jul 21 08:05:16.557885 2026] [security2:error] [pid 352421:tid 352552] [client 136.144.33.112:64043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SbMJSWzG9jbYOtu5MlwAAAIY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:05:16.762202 2026] [security2:error] [pid 358661:tid 358698] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SbAlWhjQfpOo60_HbZQAAfyE"]
[Tue Jul 21 08:05:16.762410 2026] [security2:error] [pid 358661:tid 358921] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SbAlWhjQfpOo60_HbZQAAfyE"]
[Tue Jul 21 08:05:16.855044 2026] [security2:error] [pid 358661:tid 358796] [client 20.104.96.117:7982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/ms-edit.php"] [unique_id "al9SbAlWhjQfpOo60_HbaQAAAAI"]
[Tue Jul 21 08:05:16.910276 2026] [security2:error] [pid 352421:tid 352675] [client 120.56.162.40:51756] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SbMJSWzG9jbYOtu5MmwAAAQE"]
[Tue Jul 21 08:05:16.910422 2026] [security2:error] [pid 352421:tid 352675] [client 120.56.162.40:51756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SbMJSWzG9jbYOtu5MmwAAAQE"]
[Tue Jul 21 08:05:17.183523 2026] [security2:error] [pid 352421:tid 352595] [client 20.104.96.117:7972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9SbcJSWzG9jbYOtu5MogAAALE"]
[Tue Jul 21 08:05:17.325430 2026] [security2:error] [pid 358661:tid 358682] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SbQlWhjQfpOo60_HbawAARBE"]
[Tue Jul 21 08:05:17.325676 2026] [security2:error] [pid 358661:tid 358862] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SbQlWhjQfpOo60_HbawAARBE"]
[Tue Jul 21 08:05:17.502401 2026] [security2:error] [pid 358661:tid 358873] [client 198.54.128.138:52530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SbQlWhjQfpOo60_HbbgAAAE8"]
[Tue Jul 21 08:05:17.502492 2026] [security2:error] [pid 358661:tid 358873] [client 198.54.128.138:52530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SbQlWhjQfpOo60_HbbgAAAE8"]
[Tue Jul 21 08:05:17.643882 2026] [autoindex:error] [pid 358661:tid 358809] [client 20.104.96.117:7287] AH01276: Cannot serve directory /home3/tkcorr80/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:05:17.859760 2026] [security2:error] [pid 358661:tid 358907] [client 182.8.255.181:17292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SbQlWhjQfpOo60_HbiAAAAHE"]
[Tue Jul 21 08:05:17.859887 2026] [security2:error] [pid 358661:tid 358907] [client 182.8.255.181:17292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SbQlWhjQfpOo60_HbiAAAAHE"]
[Tue Jul 21 08:05:17.942870 2026] [security2:error] [pid 358661:tid 358887] [client 20.104.96.117:7287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9SbQlWhjQfpOo60_HbiQAAAF0"]
[Tue Jul 21 08:05:17.996076 2026] [security2:error] [pid 358661:tid 358840] [client 20.151.10.161:28042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file15.php"] [unique_id "al9SbQlWhjQfpOo60_HbiwAAAC4"]
[Tue Jul 21 08:05:18.048312 2026] [security2:error] [pid 358661:tid 358804] [client 65.21.113.253:59534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SbglWhjQfpOo60_HbjAAAAAo"]
[Tue Jul 21 08:05:18.211697 2026] [security2:error] [pid 352421:tid 352457] [remote 45.3.40.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.40.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9SbsJSWzG9jbYOtu5MvAAA-yM"], referer: https://www.google.com/
[Tue Jul 21 08:05:18.342882 2026] [autoindex:error] [pid 352421:tid 352648] [client 20.104.96.117:7978] AH01276: Cannot serve directory /home3/tkcorr80/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:05:18.467404 2026] [security2:error] [pid 358661:tid 358895] [client 102.206.115.33:64096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SbglWhjQfpOo60_HbmgAAAGU"]
[Tue Jul 21 08:05:18.467535 2026] [security2:error] [pid 358661:tid 358895] [client 102.206.115.33:64096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SbglWhjQfpOo60_HbmgAAAGU"]
[Tue Jul 21 08:05:18.504659 2026] [security2:error] [pid 358661:tid 358800] [client 20.197.192.193:53168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/ee.php"] [unique_id "al9SbglWhjQfpOo60_HbnAAAAAY"]
[Tue Jul 21 08:05:18.637329 2026] [autoindex:error] [pid 352421:tid 352612] [client 20.104.96.117:7978] AH01276: Cannot serve directory /home3/tkcorr80/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:05:18.702750 2026] [security2:error] [pid 358661:tid 358867] [client 65.21.113.253:48552] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SbglWhjQfpOo60_HblgAAAEk"]
[Tue Jul 21 08:05:18.775603 2026] [security2:error] [pid 352421:tid 352593] [client 20.104.96.117:7978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/abcd.php"] [unique_id "al9SbsJSWzG9jbYOtu5MxQAAAK8"]
[Tue Jul 21 08:05:18.892361 2026] [security2:error] [pid 358661:tid 358729] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SbglWhjQfpOo60_HboQAATUA"]
[Tue Jul 21 08:05:18.892555 2026] [security2:error] [pid 358661:tid 358871] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SbglWhjQfpOo60_HboQAATUA"]
[Tue Jul 21 08:05:18.920730 2026] [core:alert] [pid 352421:tid 352577] [client 57.141.18.105:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:05:19.093545 2026] [security2:error] [pid 358661:tid 358816] [client 20.104.96.117:7266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/file15.php"] [unique_id "al9SbwlWhjQfpOo60_HbpQAAABY"]
[Tue Jul 21 08:05:19.365452 2026] [security2:error] [pid 358661:tid 358845] [client 20.151.10.161:28038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/jp.php"] [unique_id "al9SbwlWhjQfpOo60_HbqgAAADM"]
[Tue Jul 21 08:05:19.439779 2026] [security2:error] [pid 352421:tid 352561] [client 20.104.96.117:7247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/jp.php"] [unique_id "al9Sb8JSWzG9jbYOtu5M1AAAAI8"]
[Tue Jul 21 08:05:19.764782 2026] [security2:error] [pid 358661:tid 358804] [client 20.104.96.117:7988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/f35.php"] [unique_id "al9SbwlWhjQfpOo60_HbsgAAAAo"]
[Tue Jul 21 08:05:19.970153 2026] [security2:error] [pid 358661:tid 358835] [client 20.197.192.193:53183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/blue.php"] [unique_id "al9SbwlWhjQfpOo60_HbtQAAACk"]
[Tue Jul 21 08:05:19.980879 2026] [security2:error] [pid 358661:tid 358677] [remote 182.77.62.24:36678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.site"] [uri "/wp-login.php"] [unique_id "al9SbwlWhjQfpOo60_HbtwAACQw"]
[Tue Jul 21 08:05:19.991986 2026] [security2:error] [pid 358661:tid 358900] [client 204.8.98.45:47608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9SbwlWhjQfpOo60_HbuAAAAGo"]
[Tue Jul 21 08:05:19.992070 2026] [security2:error] [pid 358661:tid 358900] [client 204.8.98.45:47608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9SbwlWhjQfpOo60_HbuAAAAGo"]
[Tue Jul 21 08:05:20.022094 2026] [security2:error] [pid 358661:tid 358775] [remote 5.252.52.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "printcom.com.br"] [uri "/wp-login.php"] [unique_id "al9ScAlWhjQfpOo60_HbugAAY24"]
[Tue Jul 21 08:05:20.077425 2026] [security2:error] [pid 358661:tid 358883] [client 20.104.96.117:7610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-load.php"] [unique_id "al9ScAlWhjQfpOo60_HbuwAAAFk"]
[Tue Jul 21 08:05:20.129176 2026] [security2:error] [pid 352421:tid 352616] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Sb8JSWzG9jbYOtu5MzQAAxjE"]
[Tue Jul 21 08:05:20.200599 2026] [security2:error] [pid 358661:tid 358812] [client 87.116.180.198:13995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScAlWhjQfpOo60_HbvQAAABI"]
[Tue Jul 21 08:05:20.202060 2026] [security2:error] [pid 358661:tid 358812] [client 87.116.180.198:13995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScAlWhjQfpOo60_HbvQAAABI"]
[Tue Jul 21 08:05:20.445461 2026] [security2:error] [pid 358661:tid 358907] [client 103.29.114.44:58205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScAlWhjQfpOo60_HbwAAAAHE"]
[Tue Jul 21 08:05:20.445576 2026] [security2:error] [pid 358661:tid 358907] [client 103.29.114.44:58205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScAlWhjQfpOo60_HbwAAAAHE"]
[Tue Jul 21 08:05:20.535284 2026] [security2:error] [pid 358661:tid 358856] [client 20.104.96.117:7250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/xyn.php"] [unique_id "al9ScAlWhjQfpOo60_HbwwAAAD4"]
[Tue Jul 21 08:05:20.602144 2026] [security2:error] [pid 358661:tid 358826] [client 202.143.127.214:59866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScAlWhjQfpOo60_HbxQAAACA"]
[Tue Jul 21 08:05:20.602346 2026] [security2:error] [pid 358661:tid 358826] [client 202.143.127.214:59866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScAlWhjQfpOo60_HbxQAAACA"]
[Tue Jul 21 08:05:20.663362 2026] [security2:error] [pid 358661:tid 358813] [client 103.78.200.11:61262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScAlWhjQfpOo60_HbyAAAABM"]
[Tue Jul 21 08:05:20.663499 2026] [security2:error] [pid 358661:tid 358813] [client 103.78.200.11:61262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScAlWhjQfpOo60_HbyAAAABM"]
[Tue Jul 21 08:05:20.726232 2026] [security2:error] [pid 358661:tid 358917] [client 65.21.113.253:59534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9ScAlWhjQfpOo60_HbywAAAHs"]
[Tue Jul 21 08:05:20.808142 2026] [security2:error] [pid 352421:tid 352574] [client 65.21.113.253:59926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ScMJSWzG9jbYOtu5M3gAAAJw"]
[Tue Jul 21 08:05:20.847764 2026] [security2:error] [pid 358661:tid 358868] [client 61.1.167.83:50521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SbwlWhjQfpOo60_HbsAAAAEo"]
[Tue Jul 21 08:05:20.847833 2026] [security2:error] [pid 358661:tid 358750] [remote 216.26.243.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.243.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ScAlWhjQfpOo60_HbyQAAVlU"], referer: https://duckduckgo.com/
[Tue Jul 21 08:05:20.847917 2026] [security2:error] [pid 358661:tid 358868] [client 61.1.167.83:50521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SbwlWhjQfpOo60_HbsAAAAEo"]
[Tue Jul 21 08:05:20.894645 2026] [security2:error] [pid 352421:tid 352670] [client 20.151.10.161:28064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/f35.php"] [unique_id "al9ScMJSWzG9jbYOtu5M5QAAAPw"]
[Tue Jul 21 08:05:20.904491 2026] [autoindex:error] [pid 358661:tid 358862] [client 20.104.96.117:7583] AH01276: Cannot serve directory /home3/tkcorr80/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:05:21.070123 2026] [security2:error] [pid 358661:tid 358784] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScQlWhjQfpOo60_Hb0AAAT3c"]
[Tue Jul 21 08:05:21.070264 2026] [security2:error] [pid 358661:tid 358873] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScQlWhjQfpOo60_Hb0AAAT3c"]
[Tue Jul 21 08:05:21.265830 2026] [autoindex:error] [pid 358661:tid 358879] [client 20.104.96.117:7583] AH01276: Cannot serve directory /home3/tkcorr80/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:05:21.400450 2026] [security2:error] [pid 352421:tid 352645] [client 20.29.126.15:14329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/php8.php"] [unique_id "al9SccJSWzG9jbYOtu5M7wAAAOM"]
[Tue Jul 21 08:05:21.404823 2026] [security2:error] [pid 358661:tid 358827] [client 20.104.96.117:7583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/ccc.php"] [unique_id "al9ScQlWhjQfpOo60_Hb1QAAACE"]
[Tue Jul 21 08:05:21.452289 2026] [security2:error] [pid 358661:tid 358795] [client 117.247.80.59:13859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScQlWhjQfpOo60_Hb1wAAAAE"]
[Tue Jul 21 08:05:21.452418 2026] [security2:error] [pid 358661:tid 358795] [client 117.247.80.59:13859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScQlWhjQfpOo60_Hb1wAAAAE"]
[Tue Jul 21 08:05:21.648047 2026] [security2:error] [pid 358661:tid 358735] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ScQlWhjQfpOo60_Hb3AAARkY"]
[Tue Jul 21 08:05:21.648270 2026] [security2:error] [pid 358661:tid 358864] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ScQlWhjQfpOo60_Hb3AAARkY"]
[Tue Jul 21 08:05:21.689370 2026] [security2:error] [pid 358661:tid 358808] [client 20.104.96.117:7979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/w.php"] [unique_id "al9ScQlWhjQfpOo60_Hb3QAAAA4"]
[Tue Jul 21 08:05:21.801754 2026] [security2:error] [pid 358661:tid 358876] [client 193.36.225.72:49677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9ScAlWhjQfpOo60_HbxwAAAFI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:05:21.804507 2026] [security2:error] [pid 358661:tid 358843] [client 65.21.113.253:59930] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ScQlWhjQfpOo60_Hb1gAAADE"]
[Tue Jul 21 08:05:21.899327 2026] [security2:error] [pid 352421:tid 352677] [client 178.153.91.96:58282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SccJSWzG9jbYOtu5M9gAAAQM"]
[Tue Jul 21 08:05:21.899443 2026] [security2:error] [pid 352421:tid 352677] [client 178.153.91.96:58282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SccJSWzG9jbYOtu5M9gAAAQM"]
[Tue Jul 21 08:05:21.934099 2026] [security2:error] [pid 358661:tid 358743] [remote 45.3.32.194:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.32.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9ScQlWhjQfpOo60_Hb4QAAY04"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:22.061884 2026] [security2:error] [pid 352421:tid 352676] [client 20.104.96.117:7994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9ScsJSWzG9jbYOtu5M-wAAAQI"]
[Tue Jul 21 08:05:22.406947 2026] [security2:error] [pid 358661:tid 358719] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScglWhjQfpOo60_Hb6wAAYjY"]
[Tue Jul 21 08:05:22.407070 2026] [security2:error] [pid 358661:tid 358892] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScglWhjQfpOo60_Hb6wAAYjY"]
[Tue Jul 21 08:05:22.516999 2026] [security2:error] [pid 358661:tid 358904] [client 20.104.96.117:7598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/FWAZ.php"] [unique_id "al9ScglWhjQfpOo60_Hb7gAAAG4"]
[Tue Jul 21 08:05:22.575748 2026] [security2:error] [pid 358661:tid 358887] [client 20.29.126.15:6856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/info.php"] [unique_id "al9ScglWhjQfpOo60_Hb8AAAAF0"]
[Tue Jul 21 08:05:22.578237 2026] [security2:error] [pid 358661:tid 358836] [client 20.151.10.161:28526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-load.php"] [unique_id "al9ScglWhjQfpOo60_Hb8QAAACo"]
[Tue Jul 21 08:05:23.038344 2026] [security2:error] [pid 358661:tid 358903] [client 20.104.96.117:8083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/miru1.php"] [unique_id "al9ScwlWhjQfpOo60_Hb_gAAAG0"]
[Tue Jul 21 08:05:23.071550 2026] [security2:error] [pid 352421:tid 352618] [client 128.201.99.135:58627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.99.201.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScsJSWzG9jbYOtu5NEAAAAMg"]
[Tue Jul 21 08:05:23.071740 2026] [security2:error] [pid 352421:tid 352618] [client 128.201.99.135:58627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ibericaladrilhos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScsJSWzG9jbYOtu5NEAAAAMg"]
[Tue Jul 21 08:05:23.127541 2026] [security2:error] [pid 358661:tid 358905] [client 175.144.82.48:51161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScwlWhjQfpOo60_HcAAAAAG8"]
[Tue Jul 21 08:05:23.128497 2026] [security2:error] [pid 358661:tid 358905] [client 175.144.82.48:51161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ScwlWhjQfpOo60_HcAAAAAG8"]
[Tue Jul 21 08:05:23.306974 2026] [security2:error] [pid 358661:tid 358889] [client 122.179.91.63:14787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.91.179.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9ScwlWhjQfpOo60_HcAgAAAF8"]
[Tue Jul 21 08:05:23.307156 2026] [security2:error] [pid 358661:tid 358889] [client 122.179.91.63:14787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gtlocacoes.net"] [uri "/xmlrpc.php"] [unique_id "al9ScwlWhjQfpOo60_HcAgAAAF8"]
[Tue Jul 21 08:05:23.430408 2026] [security2:error] [pid 352421:tid 352602] [client 117.210.135.0:50716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sc8JSWzG9jbYOtu5NGwAAALg"]
[Tue Jul 21 08:05:23.430520 2026] [security2:error] [pid 352421:tid 352602] [client 117.210.135.0:50716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sc8JSWzG9jbYOtu5NGwAAALg"]
[Tue Jul 21 08:05:23.641018 2026] [security2:error] [pid 352421:tid 352625] [client 20.104.96.117:7253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/aa.php"] [unique_id "al9Sc8JSWzG9jbYOtu5NHgAAAM8"]
[Tue Jul 21 08:05:23.950913 2026] [security2:error] [pid 358661:tid 358814] [client 20.104.96.117:7252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/122.php"] [unique_id "al9ScwlWhjQfpOo60_HcBwAAABQ"]
[Tue Jul 21 08:05:24.154525 2026] [security2:error] [pid 358661:tid 358893] [client 38.100.221.102:18825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SdAlWhjQfpOo60_HcDAAAAGM"]
[Tue Jul 21 08:05:24.154656 2026] [security2:error] [pid 358661:tid 358893] [client 38.100.221.102:18825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SdAlWhjQfpOo60_HcDAAAAGM"]
[Tue Jul 21 08:05:24.159083 2026] [security2:error] [pid 358661:tid 358690] [remote 104.207.57.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SdAlWhjQfpOo60_HcCwAAThk"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:24.193706 2026] [security2:error] [pid 352421:tid 352500] [remote 47.128.62.80:59178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "institutoecommerce.com.br"] [uri "/"] [unique_id "al9SdMJSWzG9jbYOtu5NJwAAv04"]
[Tue Jul 21 08:05:24.202299 2026] [security2:error] [pid 352421:tid 352588] [client 109.60.28.94:5573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SdMJSWzG9jbYOtu5NKAAAAKo"]
[Tue Jul 21 08:05:24.203047 2026] [security2:error] [pid 352421:tid 352588] [client 109.60.28.94:5573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SdMJSWzG9jbYOtu5NKAAAAKo"]
[Tue Jul 21 08:05:24.312757 2026] [security2:error] [pid 352421:tid 352579] [client 20.104.96.117:7948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/get.php"] [unique_id "al9SdMJSWzG9jbYOtu5NKQAAAKE"]
[Tue Jul 21 08:05:24.398806 2026] [security2:error] [pid 358661:tid 358921] [client 20.151.10.161:28092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/xwpg.php"] [unique_id "al9SdAlWhjQfpOo60_HcEQAAAH8"]
[Tue Jul 21 08:05:24.667358 2026] [security2:error] [pid 352421:tid 352580] [client 103.166.103.129:22933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SdMJSWzG9jbYOtu5NLwAAAKI"]
[Tue Jul 21 08:05:24.667513 2026] [security2:error] [pid 352421:tid 352580] [client 103.166.103.129:22933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SdMJSWzG9jbYOtu5NLwAAAKI"]
[Tue Jul 21 08:05:24.704533 2026] [security2:error] [pid 358661:tid 358880] [client 20.104.96.117:7613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/as.php"] [unique_id "al9SdAlWhjQfpOo60_HcEwAAAFY"]
[Tue Jul 21 08:05:24.965831 2026] [security2:error] [pid 358661:tid 358836] [client 65.21.113.253:59534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SdAlWhjQfpOo60_HcFwAAACo"]
[Tue Jul 21 08:05:25.133125 2026] [security2:error] [pid 358661:tid 358834] [client 20.104.96.117:7615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/ccou.php"] [unique_id "al9SdQlWhjQfpOo60_HcGQAAACg"]
[Tue Jul 21 08:05:25.383763 2026] [security2:error] [pid 352421:tid 352566] [client 37.140.223.68:64447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.223.140.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SdcJSWzG9jbYOtu5NNgAAAJQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:05:25.618130 2026] [security2:error] [pid 352421:tid 352606] [client 20.104.96.117:7564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/w3lls.php"] [unique_id "al9SdcJSWzG9jbYOtu5NOAAAALw"]
[Tue Jul 21 08:05:25.625593 2026] [security2:error] [pid 358661:tid 358844] [client 198.54.128.138:56618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SdQlWhjQfpOo60_HcJAAAADI"]
[Tue Jul 21 08:05:25.625689 2026] [security2:error] [pid 358661:tid 358844] [client 198.54.128.138:56618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SdQlWhjQfpOo60_HcJAAAADI"]
[Tue Jul 21 08:05:25.649991 2026] [security2:error] [pid 358661:tid 358919] [client 20.29.126.15:16217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/edit.php"] [unique_id "al9SdQlWhjQfpOo60_HcJwAAAH0"]
[Tue Jul 21 08:05:25.652703 2026] [autoindex:error] [pid 358661:tid 358771] [remote 74.7.242.31:59844] AH01276: Cannot serve directory /home3/factor11/yunofp/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:05:25.687730 2026] [security2:error] [pid 352421:tid 352434] [remote 119.30.64.227:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.64.30.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SdcJSWzG9jbYOtu5NOgAAjQw"]
[Tue Jul 21 08:05:25.687867 2026] [security2:error] [pid 352421:tid 352559] [client 119.30.64.227:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SdcJSWzG9jbYOtu5NOgAAjQw"]
[Tue Jul 21 08:05:25.814904 2026] [security2:error] [pid 358661:tid 358842] [client 65.21.113.253:59946] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SdQlWhjQfpOo60_HcKQAAADA"]
[Tue Jul 21 08:05:25.830602 2026] [security2:error] [pid 358661:tid 358812] [client 20.151.10.161:28542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/waf.php"] [unique_id "al9SdQlWhjQfpOo60_HcLQAAABI"]
[Tue Jul 21 08:05:25.916142 2026] [security2:error] [pid 352421:tid 352651] [client 20.197.192.193:51944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/wp-signup.php"] [unique_id "al9SdcJSWzG9jbYOtu5NPQAAAOk"]
[Tue Jul 21 08:05:25.988963 2026] [security2:error] [pid 352421:tid 352569] [client 74.7.244.16:57140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.campanha.factorial.studio"] [uri "/cgi-sys/404.html"] [unique_id "al9SdcJSWzG9jbYOtu5NPwAAlwI"]
[Tue Jul 21 08:05:26.026586 2026] [security2:error] [pid 358661:tid 358861] [client 41.68.90.219:52116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SdglWhjQfpOo60_HcMQAAAEM"]
[Tue Jul 21 08:05:26.027990 2026] [security2:error] [pid 358661:tid 358861] [client 41.68.90.219:52116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SdglWhjQfpOo60_HcMQAAAEM"]
[Tue Jul 21 08:05:26.102637 2026] [security2:error] [pid 358661:tid 358872] [client 20.197.192.193:53150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/csa.php"] [unique_id "al9SdglWhjQfpOo60_HcMgAAAE4"]
[Tue Jul 21 08:05:26.133941 2026] [security2:error] [pid 358661:tid 358889] [client 151.63.71.144:63791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9SdglWhjQfpOo60_HcNAAAAF8"]
[Tue Jul 21 08:05:26.134127 2026] [security2:error] [pid 358661:tid 358863] [client 20.104.96.117:7256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/test1.php"] [unique_id "al9SdglWhjQfpOo60_HcMwAAAEU"]
[Tue Jul 21 08:05:26.134597 2026] [security2:error] [pid 358661:tid 358889] [client 151.63.71.144:63791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9SdglWhjQfpOo60_HcNAAAAF8"]
[Tue Jul 21 08:05:26.365699 2026] [security2:error] [pid 352421:tid 352627] [client 20.151.10.161:28520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/xstelth.php"] [unique_id "al9SdsJSWzG9jbYOtu5NQgAAANE"]
[Tue Jul 21 08:05:26.447534 2026] [security2:error] [pid 352421:tid 352646] [client 20.29.126.15:8301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/166.php"] [unique_id "al9SdsJSWzG9jbYOtu5NRAAAAOQ"]
[Tue Jul 21 08:05:26.468334 2026] [security2:error] [pid 358661:tid 358669] [remote 209.50.170.120:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.170.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SdQlWhjQfpOo60_HcHAAASwQ"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:26.590759 2026] [security2:error] [pid 358661:tid 358914] [client 20.104.96.117:7953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/database.php"] [unique_id "al9SdglWhjQfpOo60_HcOAAAAHg"]
[Tue Jul 21 08:05:26.746748 2026] [security2:error] [pid 358661:tid 358887] [client 198.54.128.138:40534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9SdglWhjQfpOo60_HcOwAAAF0"]
[Tue Jul 21 08:05:26.746846 2026] [security2:error] [pid 358661:tid 358887] [client 198.54.128.138:40534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9SdglWhjQfpOo60_HcOwAAAF0"]
[Tue Jul 21 08:05:26.785404 2026] [security2:error] [pid 358661:tid 358875] [client 20.104.96.117:3153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9SdglWhjQfpOo60_HcPQAAAFE"]
[Tue Jul 21 08:05:26.884183 2026] [security2:error] [pid 352421:tid 352604] [client 65.21.113.253:59970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SdsJSWzG9jbYOtu5NSAAAALo"]
[Tue Jul 21 08:05:26.936715 2026] [security2:error] [pid 352421:tid 352599] [client 65.21.113.253:59962] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SdsJSWzG9jbYOtu5NSQAAALU"]
[Tue Jul 21 08:05:27.052772 2026] [security2:error] [pid 358661:tid 358878] [client 20.151.10.161:28083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-links.php"] [unique_id "al9SdwlWhjQfpOo60_HcRAAAAFQ"]
[Tue Jul 21 08:05:27.117047 2026] [security2:error] [pid 352421:tid 352628] [client 20.104.96.117:3187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Sd8JSWzG9jbYOtu5NTwAAANI"]
[Tue Jul 21 08:05:27.216048 2026] [security2:error] [pid 358661:tid 358802] [client 20.104.96.117:7565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/file.php"] [unique_id "al9SdwlWhjQfpOo60_HcRQAAAAg"]
[Tue Jul 21 08:05:27.289803 2026] [security2:error] [pid 352421:tid 352667] [client 20.197.192.193:3859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Sd8JSWzG9jbYOtu5NUAAAAPk"]
[Tue Jul 21 08:05:27.404780 2026] [security2:error] [pid 358661:tid 358832] [client 20.104.96.117:3166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/media.php"] [unique_id "al9SdwlWhjQfpOo60_HcSAAAACY"]
[Tue Jul 21 08:05:27.432121 2026] [security2:error] [pid 358661:tid 358717] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SdwlWhjQfpOo60_HcSQAAazQ"]
[Tue Jul 21 08:05:27.432274 2026] [security2:error] [pid 358661:tid 358901] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SdwlWhjQfpOo60_HcSQAAazQ"]
[Tue Jul 21 08:05:27.463909 2026] [security2:error] [pid 358661:tid 358838] [client 20.151.10.161:28194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9SdwlWhjQfpOo60_HcSgAAACw"]
[Tue Jul 21 08:05:27.558409 2026] [security2:error] [pid 358661:tid 358795] [client 120.56.162.40:52210] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SdwlWhjQfpOo60_HcTAAAAAE"]
[Tue Jul 21 08:05:27.558528 2026] [security2:error] [pid 358661:tid 358795] [client 120.56.162.40:52210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SdwlWhjQfpOo60_HcTAAAAAE"]
[Tue Jul 21 08:05:27.648226 2026] [security2:error] [pid 352421:tid 352499] [remote 209.50.176.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.176.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9Sd8JSWzG9jbYOtu5NUwAA5U0"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:27.818868 2026] [security2:error] [pid 358661:tid 358892] [client 20.151.10.161:28089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/aaa.php"] [unique_id "al9SdwlWhjQfpOo60_HcUwAAAGI"]
[Tue Jul 21 08:05:27.826850 2026] [security2:error] [pid 358661:tid 358869] [client 20.104.96.117:3199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/images.php"] [unique_id "al9SdwlWhjQfpOo60_HcVAAAAEs"]
[Tue Jul 21 08:05:27.925430 2026] [security2:error] [pid 352421:tid 352589] [client 204.8.98.45:47614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Sd8JSWzG9jbYOtu5NWgAAAKs"]
[Tue Jul 21 08:05:27.925511 2026] [security2:error] [pid 352421:tid 352589] [client 204.8.98.45:47614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Sd8JSWzG9jbYOtu5NWgAAAKs"]
[Tue Jul 21 08:05:28.032843 2026] [security2:error] [pid 352421:tid 352425] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SeMJSWzG9jbYOtu5NWwAA4wM"]
[Tue Jul 21 08:05:28.032982 2026] [security2:error] [pid 352421:tid 352645] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SeMJSWzG9jbYOtu5NWwAA4wM"]
[Tue Jul 21 08:05:28.121292 2026] [security2:error] [pid 358661:tid 358850] [client 20.104.96.117:3073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/gecko.php"] [unique_id "al9SeAlWhjQfpOo60_HcVwAAADg"]
[Tue Jul 21 08:05:28.284486 2026] [security2:error] [pid 358661:tid 358895] [client 182.8.255.181:17287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SeAlWhjQfpOo60_HcWQAAAGU"]
[Tue Jul 21 08:05:28.284677 2026] [security2:error] [pid 358661:tid 358895] [client 182.8.255.181:17287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SeAlWhjQfpOo60_HcWQAAAGU"]
[Tue Jul 21 08:05:28.332612 2026] [security2:error] [pid 358661:tid 358908] [client 20.104.96.117:7558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/file.php"] [unique_id "al9SeAlWhjQfpOo60_HcWgAAAHI"]
[Tue Jul 21 08:05:28.451781 2026] [security2:error] [pid 352421:tid 352524] [remote 65.111.20.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SeMJSWzG9jbYOtu5NZAAAkmY"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:28.890304 2026] [security2:error] [pid 352421:tid 352566] [client 20.104.96.117:3138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/82.php"] [unique_id "al9SeMJSWzG9jbYOtu5NaAAAAJQ"]
[Tue Jul 21 08:05:29.021836 2026] [security2:error] [pid 358661:tid 358814] [client 20.104.96.117:7599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/777.php"] [unique_id "al9SeQlWhjQfpOo60_HcagAAABQ"]
[Tue Jul 21 08:05:29.092106 2026] [security2:error] [pid 358661:tid 358840] [client 102.206.115.33:63101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SeQlWhjQfpOo60_HcbgAAAC4"]
[Tue Jul 21 08:05:29.092322 2026] [security2:error] [pid 358661:tid 358840] [client 102.206.115.33:63101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SeQlWhjQfpOo60_HcbgAAAC4"]
[Tue Jul 21 08:05:29.371883 2026] [security2:error] [pid 358661:tid 358892] [client 20.104.96.117:3126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/admin.php"] [unique_id "al9SeQlWhjQfpOo60_HccgAAAGI"]
[Tue Jul 21 08:05:29.512147 2026] [security2:error] [pid 352421:tid 352575] [client 172.245.102.44:40787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.102.245.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SecJSWzG9jbYOtu5NbgAAAJ0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:05:29.581021 2026] [security2:error] [pid 352421:tid 352462] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SecJSWzG9jbYOtu5NcgAA2Sg"]
[Tue Jul 21 08:05:29.581175 2026] [security2:error] [pid 352421:tid 352635] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SecJSWzG9jbYOtu5NcgAA2Sg"]
[Tue Jul 21 08:05:29.652910 2026] [security2:error] [pid 352421:tid 352603] [client 20.104.96.117:7268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/ssixta.php"] [unique_id "al9SecJSWzG9jbYOtu5NdQAAALk"]
[Tue Jul 21 08:05:29.671920 2026] [security2:error] [pid 352421:tid 352517] [remote 104.207.33.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SecJSWzG9jbYOtu5NcQAAjV8"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:29.975972 2026] [security2:error] [pid 358661:tid 358904] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SeQlWhjQfpOo60_HcegAAbmI"]
[Tue Jul 21 08:05:30.021831 2026] [security2:error] [pid 358661:tid 358905] [client 20.104.96.117:3189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/adminner.php"] [unique_id "al9SeglWhjQfpOo60_HcfgAAAG8"]
[Tue Jul 21 08:05:30.025771 2026] [security2:error] [pid 358661:tid 358808] [client 20.197.192.193:53120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/min.php"] [unique_id "al9SeglWhjQfpOo60_HcfwAAAA4"]
[Tue Jul 21 08:05:30.158509 2026] [security2:error] [pid 352421:tid 352627] [client 65.21.113.253:59962] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SecJSWzG9jbYOtu5NdwAAANE"]
[Tue Jul 21 08:05:30.211178 2026] [security2:error] [pid 358661:tid 358832] [client 20.104.96.117:7971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/1c.php"] [unique_id "al9SeglWhjQfpOo60_HcgQAAACY"]
[Tue Jul 21 08:05:30.250721 2026] [security2:error] [pid 358661:tid 358796] [client 103.78.200.11:61753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SeglWhjQfpOo60_HchAAAAAI"]
[Tue Jul 21 08:05:30.251336 2026] [security2:error] [pid 358661:tid 358796] [client 103.78.200.11:61753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SeglWhjQfpOo60_HchAAAAAI"]
[Tue Jul 21 08:05:30.278051 2026] [security2:error] [pid 352421:tid 352655] [client 61.1.167.83:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SesJSWzG9jbYOtu5NfwAAAO0"]
[Tue Jul 21 08:05:30.278269 2026] [security2:error] [pid 352421:tid 352655] [client 61.1.167.83:51232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SesJSWzG9jbYOtu5NfwAAAO0"]
[Tue Jul 21 08:05:30.499525 2026] [security2:error] [pid 358661:tid 358833] [client 20.197.192.193:53136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/echkm.php"] [unique_id "al9SeglWhjQfpOo60_HchwAAACc"]
[Tue Jul 21 08:05:30.540865 2026] [security2:error] [pid 358661:tid 358822] [client 20.104.96.117:3191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/admin.php"] [unique_id "al9SeglWhjQfpOo60_HciAAAABw"]
[Tue Jul 21 08:05:30.876671 2026] [security2:error] [pid 358661:tid 358754] [remote 216.26.227.213:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.227.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SeglWhjQfpOo60_HciQAAFFk"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:30.953059 2026] [security2:error] [pid 358661:tid 358866] [client 87.116.180.198:14038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SeglWhjQfpOo60_HcjAAAAEg"]
[Tue Jul 21 08:05:30.953136 2026] [security2:error] [pid 358661:tid 358866] [client 87.116.180.198:14038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SeglWhjQfpOo60_HcjAAAAEg"]
[Tue Jul 21 08:05:30.981585 2026] [security2:error] [pid 358661:tid 358876] [client 103.29.114.44:3201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SeglWhjQfpOo60_HcjQAAAFI"]
[Tue Jul 21 08:05:30.981694 2026] [security2:error] [pid 358661:tid 358876] [client 103.29.114.44:3201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SeglWhjQfpOo60_HcjQAAAFI"]
[Tue Jul 21 08:05:31.004541 2026] [security2:error] [pid 352421:tid 352652] [client 20.104.96.117:7237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/test2.php"] [unique_id "al9Se8JSWzG9jbYOtu5NiQAAAOo"]
[Tue Jul 21 08:05:31.039648 2026] [security2:error] [pid 358661:tid 358799] [client 20.104.96.117:3151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/k.php"] [unique_id "al9SewlWhjQfpOo60_HckAAAAAU"]
[Tue Jul 21 08:05:31.394437 2026] [security2:error] [pid 358661:tid 358802] [client 20.104.96.117:3084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/blurbs.php"] [unique_id "al9SewlWhjQfpOo60_HcmAAAAAg"]
[Tue Jul 21 08:05:31.642851 2026] [security2:error] [pid 358661:tid 358846] [client 20.104.96.117:7611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/buy.php"] [unique_id "al9SewlWhjQfpOo60_HcnAAAADQ"]
[Tue Jul 21 08:05:31.723939 2026] [security2:error] [pid 352421:tid 352630] [client 20.104.96.117:3114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/bajah.php"] [unique_id "al9Se8JSWzG9jbYOtu5NkAAAANQ"]
[Tue Jul 21 08:05:31.844173 2026] [security2:error] [pid 358661:tid 358850] [client 202.143.127.214:60345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SewlWhjQfpOo60_HcnwAAADg"]
[Tue Jul 21 08:05:31.844284 2026] [security2:error] [pid 358661:tid 358850] [client 202.143.127.214:60345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SewlWhjQfpOo60_HcnwAAADg"]
[Tue Jul 21 08:05:32.048017 2026] [security2:error] [pid 358661:tid 358712] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SfAlWhjQfpOo60_HcowAAHy8"]
[Tue Jul 21 08:05:32.048174 2026] [security2:error] [pid 358661:tid 358825] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SfAlWhjQfpOo60_HcowAAHy8"]
[Tue Jul 21 08:05:32.054616 2026] [security2:error] [pid 352421:tid 352589] [client 20.104.96.117:3178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/a.php"] [unique_id "al9SfMJSWzG9jbYOtu5NlQAAAKs"]
[Tue Jul 21 08:05:32.060639 2026] [security2:error] [pid 352421:tid 352489] [remote 209.50.169.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.169.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9Se8JSWzG9jbYOtu5NkQAAkEM"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:32.088785 2026] [security2:error] [pid 358661:tid 358688] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SfAlWhjQfpOo60_HcpAAAEhc"]
[Tue Jul 21 08:05:32.088968 2026] [security2:error] [pid 358661:tid 358812] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SfAlWhjQfpOo60_HcpAAAEhc"]
[Tue Jul 21 08:05:32.161088 2026] [security2:error] [pid 358661:tid 358877] [client 117.247.80.59:12865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SfAlWhjQfpOo60_HcpQAAAFM"]
[Tue Jul 21 08:05:32.161193 2026] [security2:error] [pid 358661:tid 358877] [client 117.247.80.59:12865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SfAlWhjQfpOo60_HcpQAAAFM"]
[Tue Jul 21 08:05:32.368788 2026] [security2:error] [pid 358661:tid 358887] [client 20.104.96.117:7965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/ssend.php"] [unique_id "al9SfAlWhjQfpOo60_HcrQAAAF0"]
[Tue Jul 21 08:05:32.379214 2026] [security2:error] [pid 358661:tid 358875] [client 20.197.192.193:41478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9SfAlWhjQfpOo60_HcrgAAAFE"]
[Tue Jul 21 08:05:32.393377 2026] [security2:error] [pid 358661:tid 358826] [client 20.104.96.117:3168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/edit.php"] [unique_id "al9SfAlWhjQfpOo60_HcrwAAACA"]
[Tue Jul 21 08:05:32.412773 2026] [security2:error] [pid 358661:tid 358821] [client 178.153.91.96:58906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SfAlWhjQfpOo60_HcsAAAABs"]
[Tue Jul 21 08:05:32.412929 2026] [security2:error] [pid 358661:tid 358821] [client 178.153.91.96:58906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SfAlWhjQfpOo60_HcsAAAABs"]
[Tue Jul 21 08:05:32.567763 2026] [proxy:error] [pid 358661:tid 358915] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:05:32.567829 2026] [proxy_http:error] [pid 358661:tid 358915] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:05:32.568233 2026] [proxy:error] [pid 358661:tid 358915] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:05:32.568254 2026] [proxy_http:error] [pid 358661:tid 358915] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:05:32.591947 2026] [security2:error] [pid 352421:tid 352573] [client 65.21.113.253:37256] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SfMJSWzG9jbYOtu5NmwAAAJs"]
[Tue Jul 21 08:05:32.718199 2026] [security2:error] [pid 358661:tid 358832] [client 20.104.96.117:3107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/hosty.php"] [unique_id "al9SfAlWhjQfpOo60_HcuAAAACY"]
[Tue Jul 21 08:05:32.961746 2026] [security2:error] [pid 358661:tid 358752] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SfAlWhjQfpOo60_HcuQAAclc"]
[Tue Jul 21 08:05:32.961949 2026] [security2:error] [pid 358661:tid 358908] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SfAlWhjQfpOo60_HcuQAAclc"]
[Tue Jul 21 08:05:33.037290 2026] [security2:error] [pid 358661:tid 358838] [client 20.104.96.117:3117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/k.php"] [unique_id "al9SfQlWhjQfpOo60_HcugAAACw"]
[Tue Jul 21 08:05:33.044089 2026] [security2:error] [pid 352421:tid 352677] [client 65.21.113.253:59962] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SfMJSWzG9jbYOtu5NnAAAAQM"]
[Tue Jul 21 08:05:33.296688 2026] [security2:error] [pid 358661:tid 358889] [client 20.104.96.117:7607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/item.php"] [unique_id "al9SfQlWhjQfpOo60_HcwAAAAF8"]
[Tue Jul 21 08:05:33.378384 2026] [security2:error] [pid 358661:tid 358890] [client 117.210.135.0:51335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SfQlWhjQfpOo60_HcwgAAAGA"]
[Tue Jul 21 08:05:33.378582 2026] [security2:error] [pid 358661:tid 358890] [client 117.210.135.0:51335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SfQlWhjQfpOo60_HcwgAAAGA"]
[Tue Jul 21 08:05:33.489730 2026] [security2:error] [pid 358661:tid 358875] [client 20.104.96.117:3181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/aaa.php"] [unique_id "al9SfQlWhjQfpOo60_HcxQAAAFE"]
[Tue Jul 21 08:05:33.562575 2026] [proxy:error] [pid 358661:tid 358801] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:05:33.562647 2026] [proxy_http:error] [pid 358661:tid 358801] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:05:33.563263 2026] [proxy:error] [pid 358661:tid 358801] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:05:33.563289 2026] [proxy_http:error] [pid 358661:tid 358801] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:05:33.726699 2026] [security2:error] [pid 358661:tid 358895] [client 65.21.113.253:47292] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SfQlWhjQfpOo60_HcvwAAAGU"]
[Tue Jul 21 08:05:33.961417 2026] [security2:error] [pid 358661:tid 358842] [client 198.54.128.138:45586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9SfQlWhjQfpOo60_HczwAAADA"]
[Tue Jul 21 08:05:33.961522 2026] [security2:error] [pid 358661:tid 358842] [client 198.54.128.138:45586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9SfQlWhjQfpOo60_HczwAAADA"]
[Tue Jul 21 08:05:33.986560 2026] [security2:error] [pid 358661:tid 358856] [client 20.104.96.117:3111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/file5.php"] [unique_id "al9SfQlWhjQfpOo60_Hc0gAAAD4"]
[Tue Jul 21 08:05:34.052741 2026] [security2:error] [pid 352421:tid 352514] [remote 216.26.233.206:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.233.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SfMJSWzG9jbYOtu5NoQAAhVw"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:34.131839 2026] [security2:error] [pid 358661:tid 358846] [client 34.91.115.13:57344] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.barcob.com"] [uri "/"] [unique_id "al9SfglWhjQfpOo60_Hc1AAAADQ"]
[Tue Jul 21 08:05:34.131945 2026] [security2:error] [pid 358661:tid 358846] [client 34.91.115.13:57344] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "webdisk.barcob.com"] [uri "/"] [unique_id "al9SfglWhjQfpOo60_Hc1AAAADQ"]
[Tue Jul 21 08:05:34.166669 2026] [proxy:error] [pid 358661:tid 358822] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:05:34.166731 2026] [proxy_http:error] [pid 358661:tid 358822] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:05:34.167489 2026] [proxy:error] [pid 358661:tid 358822] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:05:34.167523 2026] [proxy_http:error] [pid 358661:tid 358822] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:05:34.298523 2026] [security2:error] [pid 358661:tid 358853] [client 20.104.96.117:3135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/222.php"] [unique_id "al9SfglWhjQfpOo60_Hc2QAAADs"]
[Tue Jul 21 08:05:34.601469 2026] [security2:error] [pid 358661:tid 358890] [client 20.104.96.117:7987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/ss.php"] [unique_id "al9SfglWhjQfpOo60_Hc3AAAAGA"]
[Tue Jul 21 08:05:34.628319 2026] [security2:error] [pid 358661:tid 358887] [client 20.104.96.117:3176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/test.php"] [unique_id "al9SfglWhjQfpOo60_Hc3QAAAF0"]
[Tue Jul 21 08:05:34.699137 2026] [security2:error] [pid 358661:tid 358821] [client 20.29.126.15:8275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/8.php"] [unique_id "al9SfglWhjQfpOo60_Hc3wAAABs"]
[Tue Jul 21 08:05:34.716876 2026] [security2:error] [pid 358661:tid 358795] [client 38.100.221.102:17601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SfglWhjQfpOo60_Hc4AAAAAE"]
[Tue Jul 21 08:05:34.716969 2026] [security2:error] [pid 358661:tid 358795] [client 38.100.221.102:17601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SfglWhjQfpOo60_Hc4AAAAAE"]
[Tue Jul 21 08:05:34.844143 2026] [security2:error] [pid 352421:tid 352612] [client 175.144.82.48:51619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SfsJSWzG9jbYOtu5NuwAAAMI"]
[Tue Jul 21 08:05:34.844695 2026] [security2:error] [pid 352421:tid 352612] [client 175.144.82.48:51619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SfsJSWzG9jbYOtu5NuwAAAMI"]
[Tue Jul 21 08:05:35.023379 2026] [security2:error] [pid 352421:tid 352596] [client 20.104.96.117:3096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/aaa.php"] [unique_id "al9Sf8JSWzG9jbYOtu5NvAAAALI"]
[Tue Jul 21 08:05:35.102222 2026] [security2:error] [pid 358661:tid 358805] [client 109.60.28.94:64276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SfwlWhjQfpOo60_Hc7gAAAAs"]
[Tue Jul 21 08:05:35.102840 2026] [security2:error] [pid 358661:tid 358805] [client 109.60.28.94:64276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SfwlWhjQfpOo60_Hc7gAAAAs"]
[Tue Jul 21 08:05:35.144786 2026] [security2:error] [pid 358661:tid 358861] [client 136.144.33.111:56525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SfQlWhjQfpOo60_Hc0QAAAEM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:05:35.240517 2026] [security2:error] [pid 352421:tid 352638] [client 20.104.96.117:7559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/hypo.php"] [unique_id "al9Sf8JSWzG9jbYOtu5NwgAAANw"]
[Tue Jul 21 08:05:35.374174 2026] [security2:error] [pid 358661:tid 358826] [client 103.166.103.129:23475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SfwlWhjQfpOo60_Hc9AAAACA"]
[Tue Jul 21 08:05:35.374329 2026] [security2:error] [pid 358661:tid 358826] [client 103.166.103.129:23475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SfwlWhjQfpOo60_Hc9AAAACA"]
[Tue Jul 21 08:05:35.455553 2026] [security2:error] [pid 358661:tid 358840] [client 20.104.96.117:33090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/11.php"] [unique_id "al9SfwlWhjQfpOo60_Hc9gAAAC4"]
[Tue Jul 21 08:05:35.812108 2026] [security2:error] [pid 358661:tid 358802] [client 20.104.96.117:3180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/mac.php"] [unique_id "al9SfwlWhjQfpOo60_Hc-wAAAAg"]
[Tue Jul 21 08:05:36.107075 2026] [security2:error] [pid 358661:tid 358786] [remote 45.3.38.56:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.38.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SfwlWhjQfpOo60_Hc7QAATnk"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:36.145643 2026] [security2:error] [pid 358661:tid 358764] [remote 116.179.37.238:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9SfwlWhjQfpOo60_HdAAAAMGM"], referer: https://androapkmod.com/dev/whaleapp-ltd/
[Tue Jul 21 08:05:36.153481 2026] [security2:error] [pid 358661:tid 358839] [client 20.104.96.117:3113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/chosen.php"] [unique_id "al9SgAlWhjQfpOo60_HdAQAAAC0"]
[Tue Jul 21 08:05:36.267312 2026] [core:alert] [pid 352421:tid 352669] [client 173.252.95.42:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:05:36.491050 2026] [security2:error] [pid 358661:tid 358855] [client 20.104.96.117:3080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/cream1.php"] [unique_id "al9SgAlWhjQfpOo60_HdBgAAAD0"]
[Tue Jul 21 08:05:36.571488 2026] [security2:error] [pid 358661:tid 358908] [client 41.68.90.219:52587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SgAlWhjQfpOo60_HdBwAAAHI"]
[Tue Jul 21 08:05:36.572389 2026] [security2:error] [pid 358661:tid 358908] [client 41.68.90.219:52587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SgAlWhjQfpOo60_HdBwAAAHI"]
[Tue Jul 21 08:05:37.182423 2026] [security2:error] [pid 352421:tid 352649] [client 20.104.96.117:3150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/dr.php"] [unique_id "al9SgcJSWzG9jbYOtu5N5AAAAOc"]
[Tue Jul 21 08:05:37.365755 2026] [security2:error] [pid 358661:tid 358801] [client 20.104.96.117:7604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/users.php"] [unique_id "al9SgQlWhjQfpOo60_HdEgAAAAc"]
[Tue Jul 21 08:05:37.472968 2026] [security2:error] [pid 352421:tid 352639] [client 20.104.96.117:3079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/x.php"] [unique_id "al9SgcJSWzG9jbYOtu5N7gAAAN0"]
[Tue Jul 21 08:05:37.519111 2026] [security2:error] [pid 358661:tid 358722] [remote 119.195.102.159:50366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9SgQlWhjQfpOo60_HdFAAAYDk"]
[Tue Jul 21 08:05:37.670370 2026] [security2:error] [pid 352421:tid 352651] [client 65.21.113.253:59962] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SgcJSWzG9jbYOtu5N5QAAAOk"]
[Tue Jul 21 08:05:38.027979 2026] [security2:error] [pid 358661:tid 358883] [client 20.104.96.117:3143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/155.php"] [unique_id "al9SgglWhjQfpOo60_HdHAAAAFk"]
[Tue Jul 21 08:05:38.079295 2026] [security2:error] [pid 358661:tid 358784] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SgglWhjQfpOo60_HdHQAAZXc"]
[Tue Jul 21 08:05:38.079428 2026] [security2:error] [pid 358661:tid 358895] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SgglWhjQfpOo60_HdHQAAZXc"]
[Tue Jul 21 08:05:38.090964 2026] [security2:error] [pid 358661:tid 358912] [client 20.197.192.193:47378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/mac.php"] [unique_id "al9SgglWhjQfpOo60_HdHgAAAHY"]
[Tue Jul 21 08:05:38.135345 2026] [security2:error] [pid 358661:tid 358852] [client 120.56.162.40:52664] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SgglWhjQfpOo60_HdHwAAADo"]
[Tue Jul 21 08:05:38.135482 2026] [security2:error] [pid 358661:tid 358852] [client 120.56.162.40:52664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SgglWhjQfpOo60_HdHwAAADo"]
[Tue Jul 21 08:05:38.358328 2026] [security2:error] [pid 358661:tid 358778] [remote 209.50.175.137:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.175.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SgQlWhjQfpOo60_HdDQAAS3E"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:38.459510 2026] [security2:error] [pid 358661:tid 358892] [client 20.104.96.117:3147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/ops.php"] [unique_id "al9SgglWhjQfpOo60_HdIwAAAGI"]
[Tue Jul 21 08:05:38.473295 2026] [security2:error] [pid 358661:tid 358814] [client 65.21.113.253:37270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SgglWhjQfpOo60_HdJQAAABQ"]
[Tue Jul 21 08:05:38.631117 2026] [security2:error] [pid 358661:tid 358842] [client 182.8.255.181:17488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SgglWhjQfpOo60_HdKAAAADA"]
[Tue Jul 21 08:05:38.631520 2026] [security2:error] [pid 358661:tid 358842] [client 182.8.255.181:17488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SgglWhjQfpOo60_HdKAAAADA"]
[Tue Jul 21 08:05:38.663417 2026] [security2:error] [pid 358661:tid 358735] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SgglWhjQfpOo60_HdKQAAY0Y"]
[Tue Jul 21 08:05:38.663521 2026] [security2:error] [pid 358661:tid 358893] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SgglWhjQfpOo60_HdKQAAY0Y"]
[Tue Jul 21 08:05:38.807251 2026] [security2:error] [pid 358661:tid 358802] [client 20.104.96.117:3164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/file31.php"] [unique_id "al9SgglWhjQfpOo60_HdLgAAAAg"]
[Tue Jul 21 08:05:39.096447 2026] [security2:error] [pid 352421:tid 352613] [client 65.21.113.253:59962] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SgsJSWzG9jbYOtu5N-QAAAMM"]
[Tue Jul 21 08:05:39.183055 2026] [security2:error] [pid 358661:tid 358916] [client 20.104.96.117:3109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/file6.php"] [unique_id "al9SgwlWhjQfpOo60_HdMwAAAHo"]
[Tue Jul 21 08:05:39.577789 2026] [security2:error] [pid 358661:tid 358719] [remote 45.3.50.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.50.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SgwlWhjQfpOo60_HdNwAALTY"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:39.663103 2026] [security2:error] [pid 358661:tid 358868] [client 136.144.33.102:39285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9SgwlWhjQfpOo60_HdOgAAAEo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:05:39.669705 2026] [security2:error] [pid 358661:tid 358878] [client 20.104.96.117:3097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/adminfuns.php"] [unique_id "al9SgwlWhjQfpOo60_HdQQAAAFQ"]
[Tue Jul 21 08:05:39.690592 2026] [security2:error] [pid 358661:tid 358884] [client 102.206.115.33:62358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SgwlWhjQfpOo60_HdQgAAAFo"]
[Tue Jul 21 08:05:39.691109 2026] [security2:error] [pid 358661:tid 358884] [client 102.206.115.33:62358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SgwlWhjQfpOo60_HdQgAAAFo"]
[Tue Jul 21 08:05:40.016240 2026] [security2:error] [pid 358661:tid 358904] [client 20.104.96.117:3146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/goods.php"] [unique_id "al9ShAlWhjQfpOo60_HdSAAAAG4"]
[Tue Jul 21 08:05:40.239857 2026] [security2:error] [pid 358661:tid 358724] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShAlWhjQfpOo60_HdYgAAYDs"]
[Tue Jul 21 08:05:40.240069 2026] [security2:error] [pid 358661:tid 358890] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShAlWhjQfpOo60_HdYgAAYDs"]
[Tue Jul 21 08:05:40.295461 2026] [security2:error] [pid 358661:tid 358807] [client 20.104.96.117:3179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/100.php"] [unique_id "al9ShAlWhjQfpOo60_HdYwAAAA0"]
[Tue Jul 21 08:05:40.641075 2026] [core:alert] [pid 358661:tid 358878] [client 57.141.18.78:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:05:40.699594 2026] [security2:error] [pid 358661:tid 358914] [client 20.104.96.117:33092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/about.php"] [unique_id "al9ShAlWhjQfpOo60_HdcQAAAHg"]
[Tue Jul 21 08:05:40.720820 2026] [security2:error] [pid 358661:tid 358667] [remote 209.50.167.123:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.167.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9ShAlWhjQfpOo60_HdaQAAeQI"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:40.731490 2026] [security2:error] [pid 358661:tid 358892] [client 61.1.167.83:51743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShAlWhjQfpOo60_HdcgAAAGI"]
[Tue Jul 21 08:05:40.731570 2026] [security2:error] [pid 358661:tid 358892] [client 61.1.167.83:51743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShAlWhjQfpOo60_HdcgAAAGI"]
[Tue Jul 21 08:05:40.800111 2026] [security2:error] [pid 358661:tid 358865] [client 103.78.200.11:62252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShAlWhjQfpOo60_HdcwAAAEc"]
[Tue Jul 21 08:05:40.800264 2026] [security2:error] [pid 358661:tid 358865] [client 103.78.200.11:62252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShAlWhjQfpOo60_HdcwAAAEc"]
[Tue Jul 21 08:05:40.925775 2026] [security2:error] [pid 358661:tid 358866] [client 65.21.113.253:54852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ShAlWhjQfpOo60_HdaAAAAEg"]
[Tue Jul 21 08:05:40.939452 2026] [security2:error] [pid 358661:tid 358912] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9ShAlWhjQfpOo60_HddQAAdis"]
[Tue Jul 21 08:05:40.952546 2026] [security2:error] [pid 358661:tid 358801] [client 20.197.192.193:52237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/samll.php"] [unique_id "al9ShAlWhjQfpOo60_HdewAAAAc"]
[Tue Jul 21 08:05:41.050752 2026] [security2:error] [pid 358661:tid 358888] [client 20.104.96.117:3198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/about.php"] [unique_id "al9ShQlWhjQfpOo60_HdgQAAAF4"]
[Tue Jul 21 08:05:41.552675 2026] [security2:error] [pid 352421:tid 352660] [client 20.104.96.117:3076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/admin.php"] [unique_id "al9ShcJSWzG9jbYOtu5OIQAAAPI"]
[Tue Jul 21 08:05:41.555880 2026] [security2:error] [pid 358661:tid 358904] [client 87.116.180.198:27318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShQlWhjQfpOo60_HdhQAAAG4"]
[Tue Jul 21 08:05:41.556062 2026] [security2:error] [pid 358661:tid 358904] [client 87.116.180.198:27318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShQlWhjQfpOo60_HdhQAAAG4"]
[Tue Jul 21 08:05:41.682202 2026] [security2:error] [pid 358661:tid 358821] [client 103.29.114.44:59488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShQlWhjQfpOo60_HdhgAAABs"]
[Tue Jul 21 08:05:41.682329 2026] [security2:error] [pid 358661:tid 358821] [client 103.29.114.44:59488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShQlWhjQfpOo60_HdhgAAABs"]
[Tue Jul 21 08:05:41.767465 2026] [security2:error] [pid 352421:tid 352559] [client 157.90.156.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9ShcJSWzG9jbYOtu5OJQAAjSo"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:05:41.806538 2026] [security2:error] [pid 352421:tid 352618] [client 74.7.241.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "ferlab3d.com.br"] [uri "/robots.txt"] [unique_id "al9ShcJSWzG9jbYOtu5OJwAAyBA"]
[Tue Jul 21 08:05:41.909079 2026] [security2:error] [pid 352421:tid 352675] [client 20.104.96.117:3118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/admin.php"] [unique_id "al9ShcJSWzG9jbYOtu5OKQAAAQE"]
[Tue Jul 21 08:05:42.318350 2026] [security2:error] [pid 352421:tid 352607] [client 157.90.156.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9ShsJSWzG9jbYOtu5ONgAAvXA"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:05:42.342628 2026] [security2:error] [pid 358661:tid 358842] [client 20.104.96.117:33093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/themes.php"] [unique_id "al9ShglWhjQfpOo60_HdjwAAADA"]
[Tue Jul 21 08:05:42.575344 2026] [security2:error] [pid 358661:tid 358732] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ShglWhjQfpOo60_HdlQAAckM"]
[Tue Jul 21 08:05:42.575585 2026] [security2:error] [pid 358661:tid 358908] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9ShglWhjQfpOo60_HdlQAAckM"]
[Tue Jul 21 08:05:42.615565 2026] [security2:error] [pid 358661:tid 358801] [client 74.7.228.8:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "powerflats.com.br"] [uri "/index.php"] [unique_id "al9ShglWhjQfpOo60_HdkgAAAAc"]
[Tue Jul 21 08:05:42.616436 2026] [security2:error] [pid 358661:tid 358885] [client 74.7.228.8:55186] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "powerflats.com.br"] [uri "/robots.txt"] [unique_id "al9ShglWhjQfpOo60_HdkAAAWxU"]
[Tue Jul 21 08:05:42.778777 2026] [security2:error] [pid 358661:tid 358846] [client 198.54.128.138:43194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ShglWhjQfpOo60_HdmwAAADQ"]
[Tue Jul 21 08:05:42.778878 2026] [security2:error] [pid 358661:tid 358846] [client 198.54.128.138:43194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ShglWhjQfpOo60_HdmwAAADQ"]
[Tue Jul 21 08:05:42.830856 2026] [security2:error] [pid 358661:tid 358892] [client 117.247.80.59:12455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShglWhjQfpOo60_HdnwAAAGI"]
[Tue Jul 21 08:05:42.830998 2026] [security2:error] [pid 358661:tid 358892] [client 117.247.80.59:12455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShglWhjQfpOo60_HdnwAAAGI"]
[Tue Jul 21 08:05:42.901529 2026] [security2:error] [pid 352421:tid 352583] [client 178.153.91.96:37709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ShsJSWzG9jbYOtu5OPgAAAKU"]
[Tue Jul 21 08:05:42.901671 2026] [security2:error] [pid 352421:tid 352583] [client 178.153.91.96:37709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ShsJSWzG9jbYOtu5OPgAAAKU"]
[Tue Jul 21 08:05:42.937925 2026] [security2:error] [pid 352421:tid 352644] [client 92.119.178.3:45096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9ShsJSWzG9jbYOtu5OPwAAAOI"]
[Tue Jul 21 08:05:42.938019 2026] [security2:error] [pid 352421:tid 352644] [client 92.119.178.3:45096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9ShsJSWzG9jbYOtu5OPwAAAOI"]
[Tue Jul 21 08:05:42.951930 2026] [security2:error] [pid 352421:tid 352600] [client 202.143.127.214:60824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShsJSWzG9jbYOtu5OQAAAALY"]
[Tue Jul 21 08:05:42.952523 2026] [security2:error] [pid 352421:tid 352600] [client 202.143.127.214:60824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShsJSWzG9jbYOtu5OQAAAALY"]
[Tue Jul 21 08:05:42.957176 2026] [security2:error] [pid 358661:tid 358864] [client 20.104.96.117:3105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/.well-known/about.php"] [unique_id "al9ShglWhjQfpOo60_HdoQAAAEY"]
[Tue Jul 21 08:05:42.982537 2026] [security2:error] [pid 358661:tid 358758] [remote 38.242.157.30:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "falarmelhor.com.br"] [uri "/wp-login.php"] [unique_id "al9ShglWhjQfpOo60_HdowAAK10"]
[Tue Jul 21 08:05:42.995261 2026] [security2:error] [pid 358661:tid 358805] [client 20.104.96.117:7993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/177.php"] [unique_id "al9ShglWhjQfpOo60_HdpAAAAAs"]
[Tue Jul 21 08:05:43.081186 2026] [security2:error] [pid 352421:tid 352650] [client 20.197.192.193:52282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/abcd.php"] [unique_id "al9Sh8JSWzG9jbYOtu5OQwAAAOg"]
[Tue Jul 21 08:05:43.139754 2026] [security2:error] [pid 352421:tid 352549] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sh8JSWzG9jbYOtu5ORQAA9H8"]
[Tue Jul 21 08:05:43.139941 2026] [security2:error] [pid 352421:tid 352662] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sh8JSWzG9jbYOtu5ORQAA9H8"]
[Tue Jul 21 08:05:43.170744 2026] [security2:error] [pid 352421:tid 352658] [client 92.119.178.3:40368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Sh8JSWzG9jbYOtu5ORgAAAPA"]
[Tue Jul 21 08:05:43.170832 2026] [security2:error] [pid 352421:tid 352658] [client 92.119.178.3:40368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Sh8JSWzG9jbYOtu5ORgAAAPA"]
[Tue Jul 21 08:05:43.369565 2026] [security2:error] [pid 358661:tid 358914] [client 20.104.96.117:3086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9ShwlWhjQfpOo60_HdqQAAAHg"]
[Tue Jul 21 08:05:43.430590 2026] [security2:error] [pid 358661:tid 358770] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShwlWhjQfpOo60_HdqgAAHWk"]
[Tue Jul 21 08:05:43.430762 2026] [security2:error] [pid 358661:tid 358823] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShwlWhjQfpOo60_HdqgAAHWk"]
[Tue Jul 21 08:05:43.441418 2026] [security2:error] [pid 358661:tid 358790] [remote 216.26.249.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.249.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9ShglWhjQfpOo60_HdjgAAeX0"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:43.464137 2026] [security2:error] [pid 358661:tid 358865] [client 20.197.192.193:3649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/dp.php"] [unique_id "al9ShwlWhjQfpOo60_HdqwAAAEc"]
[Tue Jul 21 08:05:43.529264 2026] [security2:error] [pid 352421:tid 352642] [client 20.104.96.117:7277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/config.php"] [unique_id "al9Sh8JSWzG9jbYOtu5OSgAAAOA"]
[Tue Jul 21 08:05:43.908390 2026] [security2:error] [pid 358661:tid 358833] [client 117.210.135.0:51986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShwlWhjQfpOo60_HdsAAAACc"]
[Tue Jul 21 08:05:43.908504 2026] [security2:error] [pid 358661:tid 358833] [client 117.210.135.0:51986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ShwlWhjQfpOo60_HdsAAAACc"]
[Tue Jul 21 08:05:44.020019 2026] [security2:error] [pid 358661:tid 358894] [client 20.104.96.117:3101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/wefile.php"] [unique_id "al9SiAlWhjQfpOo60_HdtAAAAGQ"]
[Tue Jul 21 08:05:44.204108 2026] [security2:error] [pid 352421:tid 352566] [client 20.104.96.117:7255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/gettest.php"] [unique_id "al9SiMJSWzG9jbYOtu5OUgAAAJQ"]
[Tue Jul 21 08:05:44.212443 2026] [security2:error] [pid 358661:tid 358795] [client 74.7.241.185:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.elpcons.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9SiAlWhjQfpOo60_HduAAAARI"]
[Tue Jul 21 08:05:44.231735 2026] [security2:error] [pid 352421:tid 352649] [client 20.29.126.15:11407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/ws38.php"] [unique_id "al9SiMJSWzG9jbYOtu5OVAAAAOc"]
[Tue Jul 21 08:05:44.256527 2026] [security2:error] [pid 352421:tid 352569] [client 180.153.236.166:14241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vmccontabilidade.com.br"] [uri "/"] [unique_id "al9SiMJSWzG9jbYOtu5OVwAAAJc"], referer: http://vmccontabilidade.com.br/
[Tue Jul 21 08:05:44.256679 2026] [security2:error] [pid 352421:tid 352569] [client 180.153.236.166:14241] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vmccontabilidade.com.br"] [uri "/"] [unique_id "al9SiMJSWzG9jbYOtu5OVwAAAJc"], referer: http://vmccontabilidade.com.br/
[Tue Jul 21 08:05:44.644240 2026] [security2:error] [pid 358661:tid 358895] [client 65.21.113.253:54852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SiAlWhjQfpOo60_HdtwAAAGU"]
[Tue Jul 21 08:05:44.869002 2026] [security2:error] [pid 358661:tid 358855] [client 128.140.106.114:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9SiAlWhjQfpOo60_HdvwAAPWQ"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:05:44.952444 2026] [security2:error] [pid 358661:tid 358817] [client 20.104.96.117:7606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/min.php"] [unique_id "al9SiAlWhjQfpOo60_HdwQAAABc"]
[Tue Jul 21 08:05:44.992975 2026] [security2:error] [pid 358661:tid 358814] [client 20.104.96.117:3197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9SiAlWhjQfpOo60_HdwgAAABQ"]
[Tue Jul 21 08:05:45.070396 2026] [security2:error] [pid 352421:tid 352634] [client 128.140.106.114:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9SicJSWzG9jbYOtu5OYwAA2A4"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:05:45.120137 2026] [security2:error] [pid 358661:tid 358725] [remote 185.27.20.235:42280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.20.27.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atilafagundes.com.br"] [uri "/wp-login.php"] [unique_id "al9SiQlWhjQfpOo60_HdxAAAbjw"]
[Tue Jul 21 08:05:45.230406 2026] [security2:error] [pid 352421:tid 352646] [client 38.100.221.102:18548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SicJSWzG9jbYOtu5OZQAAAOQ"]
[Tue Jul 21 08:05:45.230702 2026] [security2:error] [pid 352421:tid 352646] [client 38.100.221.102:18548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SicJSWzG9jbYOtu5OZQAAAOQ"]
[Tue Jul 21 08:05:45.353353 2026] [security2:error] [pid 352421:tid 352624] [client 20.104.96.117:7985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/dvjul.php"] [unique_id "al9SicJSWzG9jbYOtu5OawAAAM4"]
[Tue Jul 21 08:05:45.656581 2026] [security2:error] [pid 352421:tid 352568] [client 20.104.96.117:7954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/biufile.php"] [unique_id "al9SicJSWzG9jbYOtu5ObgAAAJY"]
[Tue Jul 21 08:05:45.732933 2026] [security2:error] [pid 352421:tid 352654] [client 20.197.192.193:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/xyn.php"] [unique_id "al9SicJSWzG9jbYOtu5OcgAAAOw"]
[Tue Jul 21 08:05:45.927366 2026] [security2:error] [pid 358661:tid 358900] [client 109.60.28.94:6787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SiQlWhjQfpOo60_Hd0gAAAGo"]
[Tue Jul 21 08:05:45.928195 2026] [security2:error] [pid 358661:tid 358900] [client 109.60.28.94:6787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SiQlWhjQfpOo60_Hd0gAAAGo"]
[Tue Jul 21 08:05:46.038562 2026] [security2:error] [pid 352421:tid 352580] [client 20.104.96.117:7288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/av.php"] [unique_id "al9SisJSWzG9jbYOtu5OfwAAAKI"]
[Tue Jul 21 08:05:46.116040 2026] [core:error] [pid 358661:tid 358705] [remote 185.242.3.90:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:05:46.116059 2026] [core:error] [pid 358661:tid 358705] [remote 185.242.3.90:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:05:46.139532 2026] [core:error] [pid 352421:tid 352546] [remote 185.242.3.90:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:05:46.139557 2026] [core:error] [pid 352421:tid 352546] [remote 185.242.3.90:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:05:46.165916 2026] [security2:error] [pid 358661:tid 358785] [remote 185.242.3.90:0] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.fernandesdossantos.adv.br"] [uri "/"] [unique_id "al9SiglWhjQfpOo60_Hd1gAAVHg"]
[Tue Jul 21 08:05:46.176084 2026] [core:error] [pid 358661:tid 358721] [remote 185.242.3.90:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:05:46.176103 2026] [core:error] [pid 358661:tid 358721] [remote 185.242.3.90:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:05:46.198653 2026] [security2:error] [pid 352421:tid 352602] [client 103.166.103.129:24017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SisJSWzG9jbYOtu5OggAAALg"]
[Tue Jul 21 08:05:46.198798 2026] [security2:error] [pid 352421:tid 352602] [client 103.166.103.129:24017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SisJSWzG9jbYOtu5OggAAALg"]
[Tue Jul 21 08:05:46.382558 2026] [security2:error] [pid 358661:tid 358904] [client 20.104.96.117:7274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/coffexium.php"] [unique_id "al9SiglWhjQfpOo60_Hd2QAAAG4"]
[Tue Jul 21 08:05:46.676141 2026] [security2:error] [pid 352421:tid 352444] [remote 65.111.8.97:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SiMJSWzG9jbYOtu5OWgAAjxY"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:46.714896 2026] [security2:error] [pid 358661:tid 358901] [client 35.243.233.29:65236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "odontoclinicms.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9SiglWhjQfpOo60_Hd3wAAAGs"]
[Tue Jul 21 08:05:46.799965 2026] [security2:error] [pid 358661:tid 358866] [client 20.104.96.117:7248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/core.php"] [unique_id "al9SiglWhjQfpOo60_Hd4AAAAEg"]
[Tue Jul 21 08:05:46.815063 2026] [security2:error] [pid 358661:tid 358871] [client 20.104.96.117:3092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9SiglWhjQfpOo60_Hd4QAAAE0"]
[Tue Jul 21 08:05:46.953213 2026] [security2:error] [pid 358661:tid 358733] [remote 68.178.165.65:46298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9SiglWhjQfpOo60_Hd5QAAeUQ"]
[Tue Jul 21 08:05:47.073388 2026] [security2:error] [pid 352421:tid 352461] [remote 57.141.18.70:21676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9SicJSWzG9jbYOtu5OegAA6ic"]
[Tue Jul 21 08:05:47.102784 2026] [security2:error] [pid 358661:tid 358823] [client 175.144.82.48:52029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SiwlWhjQfpOo60_Hd5gAAAB0"]
[Tue Jul 21 08:05:47.102950 2026] [security2:error] [pid 358661:tid 358823] [client 175.144.82.48:52029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SiwlWhjQfpOo60_Hd5gAAAB0"]
[Tue Jul 21 08:05:47.194200 2026] [security2:error] [pid 352421:tid 352666] [client 41.68.90.219:53050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Si8JSWzG9jbYOtu5OlAAAAPg"]
[Tue Jul 21 08:05:47.195210 2026] [security2:error] [pid 352421:tid 352666] [client 41.68.90.219:53050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Si8JSWzG9jbYOtu5OlAAAAPg"]
[Tue Jul 21 08:05:47.197772 2026] [security2:error] [pid 352421:tid 352556] [client 20.104.96.117:7593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/als.php"] [unique_id "al9Si8JSWzG9jbYOtu5OlQAAAIo"]
[Tue Jul 21 08:05:47.255278 2026] [proxy:error] [pid 352421:tid 352618] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:05:47.255339 2026] [proxy_http:error] [pid 352421:tid 352618] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:05:47.256055 2026] [proxy:error] [pid 352421:tid 352618] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:05:47.256088 2026] [proxy_http:error] [pid 352421:tid 352618] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:05:47.514097 2026] [security2:error] [pid 352421:tid 352627] [client 20.104.96.117:7597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/simple.php"] [unique_id "al9Si8JSWzG9jbYOtu5OnQAAANE"]
[Tue Jul 21 08:05:47.873692 2026] [security2:error] [pid 358661:tid 358814] [client 20.29.126.15:10139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/a7.php"] [unique_id "al9SiwlWhjQfpOo60_Hd8AAAABQ"]
[Tue Jul 21 08:05:47.876126 2026] [security2:error] [pid 352421:tid 352522] [remote 216.26.234.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.234.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9Si8JSWzG9jbYOtu5OnwAA5GQ"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:47.876977 2026] [proxy:error] [pid 352421:tid 352568] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:05:47.877030 2026] [proxy_http:error] [pid 352421:tid 352568] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:05:47.877683 2026] [proxy:error] [pid 352421:tid 352568] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:05:47.877709 2026] [proxy_http:error] [pid 352421:tid 352568] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:05:47.941258 2026] [security2:error] [pid 358661:tid 358912] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9ShwlWhjQfpOo60_HdsQAAAHY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:05:48.012799 2026] [security2:error] [pid 352421:tid 352607] [client 20.104.96.117:7279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/init.php"] [unique_id "al9SjMJSWzG9jbYOtu5OpgAAAL0"]
[Tue Jul 21 08:05:48.150508 2026] [security2:error] [pid 352421:tid 352622] [client 20.104.96.117:3115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/8.php"] [unique_id "al9SjMJSWzG9jbYOtu5OqgAAAMw"]
[Tue Jul 21 08:05:48.465592 2026] [security2:error] [pid 358661:tid 358906] [client 65.21.113.253:54852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SiwlWhjQfpOo60_Hd8gAAAHA"]
[Tue Jul 21 08:05:48.489758 2026] [security2:error] [pid 352421:tid 352562] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9SjMJSWzG9jbYOtu5OsQAAAJA"]
[Tue Jul 21 08:05:48.726156 2026] [security2:error] [pid 358661:tid 358829] [client 20.104.96.117:7981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/fpwch.php"] [unique_id "al9SjAlWhjQfpOo60_HeBAAAACM"]
[Tue Jul 21 08:05:48.745500 2026] [security2:error] [pid 358661:tid 358779] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SjAlWhjQfpOo60_HeBQAATnI"]
[Tue Jul 21 08:05:48.745661 2026] [security2:error] [pid 358661:tid 358872] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SjAlWhjQfpOo60_HeBQAATnI"]
[Tue Jul 21 08:05:48.812925 2026] [security2:error] [pid 352421:tid 352653] [client 120.56.162.40:53114] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SjMJSWzG9jbYOtu5OsgAAAOs"]
[Tue Jul 21 08:05:48.813081 2026] [security2:error] [pid 352421:tid 352653] [client 120.56.162.40:53114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SjMJSWzG9jbYOtu5OsgAAAOs"]
[Tue Jul 21 08:05:48.915637 2026] [security2:error] [pid 358661:tid 358761] [remote 65.111.6.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.6.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SjAlWhjQfpOo60_HeCAAAb2A"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:49.071745 2026] [security2:error] [pid 358661:tid 358816] [client 182.8.255.181:17178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SjQlWhjQfpOo60_HeDAAAABY"]
[Tue Jul 21 08:05:49.071885 2026] [security2:error] [pid 358661:tid 358816] [client 182.8.255.181:17178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SjQlWhjQfpOo60_HeDAAAABY"]
[Tue Jul 21 08:05:49.103226 2026] [security2:error] [pid 352421:tid 352597] [client 159.223.41.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SjcJSWzG9jbYOtu5OvwAAALM"]
[Tue Jul 21 08:05:49.395220 2026] [security2:error] [pid 358661:tid 358671] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SjQlWhjQfpOo60_HeGAAASAY"]
[Tue Jul 21 08:05:49.395390 2026] [security2:error] [pid 358661:tid 358866] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SjQlWhjQfpOo60_HeGAAASAY"]
[Tue Jul 21 08:05:49.459234 2026] [security2:error] [pid 358661:tid 358867] [client 20.104.96.117:3144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9SjQlWhjQfpOo60_HeGgAAAEk"]
[Tue Jul 21 08:05:49.716735 2026] [proxy:error] [pid 358661:tid 358839] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:05:49.716793 2026] [proxy_http:error] [pid 358661:tid 358839] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:05:49.717235 2026] [proxy:error] [pid 358661:tid 358839] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:05:49.717257 2026] [proxy_http:error] [pid 358661:tid 358839] [client 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:05:49.859011 2026] [security2:error] [pid 358661:tid 358844] [client 20.104.96.117:7605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/domvf.php"] [unique_id "al9SjQlWhjQfpOo60_HeKQAAADI"]
[Tue Jul 21 08:05:50.026125 2026] [security2:error] [pid 358661:tid 358667] [remote 103.112.62.59:57654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9SjglWhjQfpOo60_HeLQAAMQI"]
[Tue Jul 21 08:05:50.258897 2026] [security2:error] [pid 358661:tid 358868] [client 102.206.115.33:59482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SjglWhjQfpOo60_HeMgAAAEo"]
[Tue Jul 21 08:05:50.259272 2026] [security2:error] [pid 358661:tid 358868] [client 102.206.115.33:59482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SjglWhjQfpOo60_HeMgAAAEo"]
[Tue Jul 21 08:05:50.308353 2026] [security2:error] [pid 358661:tid 358910] [client 20.197.192.193:62510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/old.php"] [unique_id "al9SjglWhjQfpOo60_HeMwAAAHQ"]
[Tue Jul 21 08:05:50.345434 2026] [security2:error] [pid 352421:tid 352666] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9SjsJSWzG9jbYOtu5OzAAAAPg"]
[Tue Jul 21 08:05:50.480332 2026] [security2:error] [pid 358661:tid 358867] [client 20.104.96.117:8091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp.php"] [unique_id "al9SjglWhjQfpOo60_HeNgAAAEk"]
[Tue Jul 21 08:05:50.647396 2026] [security2:error] [pid 352421:tid 352425] [remote 65.111.31.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.31.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SjsJSWzG9jbYOtu5OzwAA3QM"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:50.664571 2026] [security2:error] [pid 358661:tid 358872] [client 65.21.113.253:45950] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9SjglWhjQfpOo60_HeOwAAAE4"]
[Tue Jul 21 08:05:50.947371 2026] [security2:error] [pid 352421:tid 352524] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SjsJSWzG9jbYOtu5O1QAA0WY"]
[Tue Jul 21 08:05:50.947562 2026] [security2:error] [pid 352421:tid 352627] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SjsJSWzG9jbYOtu5O1QAA0WY"]
[Tue Jul 21 08:05:50.961257 2026] [security2:error] [pid 358661:tid 358844] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9SjglWhjQfpOo60_HeRAAAADI"]
[Tue Jul 21 08:05:51.144923 2026] [security2:error] [pid 358661:tid 358822] [client 61.1.167.83:52217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SjwlWhjQfpOo60_HeSAAAABw"]
[Tue Jul 21 08:05:51.145031 2026] [security2:error] [pid 358661:tid 358822] [client 61.1.167.83:52217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SjwlWhjQfpOo60_HeSAAAABw"]
[Tue Jul 21 08:05:51.264908 2026] [security2:error] [pid 358661:tid 358921] [client 20.104.96.117:3104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/f6.php"] [unique_id "al9SjwlWhjQfpOo60_HeSwAAAH8"]
[Tue Jul 21 08:05:51.322895 2026] [security2:error] [pid 358661:tid 358794] [client 20.29.126.15:14302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/classsmtps.php"] [unique_id "al9SjwlWhjQfpOo60_HeTgAAAAA"]
[Tue Jul 21 08:05:51.445631 2026] [security2:error] [pid 352421:tid 352621] [client 20.104.96.117:8074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/class.php"] [unique_id "al9Sj8JSWzG9jbYOtu5O4QAAAMs"]
[Tue Jul 21 08:05:51.509988 2026] [security2:error] [pid 352421:tid 352673] [client 65.21.113.253:54488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Sj8JSWzG9jbYOtu5O3gAAAP8"]
[Tue Jul 21 08:05:51.567781 2026] [security2:error] [pid 358661:tid 358855] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9SjwlWhjQfpOo60_HeUQAAAD0"]
[Tue Jul 21 08:05:51.578020 2026] [security2:error] [pid 352421:tid 352619] [client 103.78.200.11:62798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sj8JSWzG9jbYOtu5O5gAAAMk"]
[Tue Jul 21 08:05:51.578157 2026] [security2:error] [pid 352421:tid 352619] [client 103.78.200.11:62798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sj8JSWzG9jbYOtu5O5gAAAMk"]
[Tue Jul 21 08:05:51.786746 2026] [security2:error] [pid 352421:tid 352607] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Sj8JSWzG9jbYOtu5O6AAAvWM"]
[Tue Jul 21 08:05:51.961472 2026] [security2:error] [pid 358661:tid 358813] [client 65.21.113.253:45956] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SjwlWhjQfpOo60_HeVgAAABM"]
[Tue Jul 21 08:05:52.124974 2026] [security2:error] [pid 358661:tid 358916] [client 20.104.96.117:3133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/inputs.php"] [unique_id "al9SkAlWhjQfpOo60_HeWAAAAHo"]
[Tue Jul 21 08:05:52.184927 2026] [security2:error] [pid 358661:tid 358802] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9SkAlWhjQfpOo60_HeWQAAAAg"]
[Tue Jul 21 08:05:52.241459 2026] [security2:error] [pid 352421:tid 352653] [client 87.116.180.198:27369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkMJSWzG9jbYOtu5O8wAAAOs"]
[Tue Jul 21 08:05:52.241581 2026] [security2:error] [pid 352421:tid 352653] [client 87.116.180.198:27369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkMJSWzG9jbYOtu5O8wAAAOs"]
[Tue Jul 21 08:05:52.244704 2026] [security2:error] [pid 352421:tid 352583] [client 103.29.114.44:8838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkMJSWzG9jbYOtu5O9AAAAKU"]
[Tue Jul 21 08:05:52.244802 2026] [security2:error] [pid 352421:tid 352583] [client 103.29.114.44:8838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkMJSWzG9jbYOtu5O9AAAAKU"]
[Tue Jul 21 08:05:52.353746 2026] [security2:error] [pid 352421:tid 352555] [client 20.104.96.117:8110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/echkm.php"] [unique_id "al9SkMJSWzG9jbYOtu5O9wAAAIk"]
[Tue Jul 21 08:05:52.395029 2026] [security2:error] [pid 358661:tid 358814] [client 65.21.113.253:54852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SjwlWhjQfpOo60_HeVAAAABQ"]
[Tue Jul 21 08:05:52.404064 2026] [security2:error] [pid 352421:tid 352564] [client 35.243.233.29:63888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "odontoclinicms.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkMJSWzG9jbYOtu5O9gAAAJI"]
[Tue Jul 21 08:05:52.729086 2026] [security2:error] [pid 352421:tid 352523] [remote 104.207.34.65:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.34.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9Sj8JSWzG9jbYOtu5O6QAAqmU"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:52.793383 2026] [security2:error] [pid 358661:tid 358921] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9SkAlWhjQfpOo60_HeYAAAAH8"]
[Tue Jul 21 08:05:52.975139 2026] [security2:error] [pid 358661:tid 358865] [client 20.104.96.117:3160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/inputs.php"] [unique_id "al9SkAlWhjQfpOo60_HeZQAAAEc"]
[Tue Jul 21 08:05:53.005874 2026] [security2:error] [pid 358661:tid 358904] [client 65.21.113.253:54498] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SkAlWhjQfpOo60_HeXgAAAG4"]
[Tue Jul 21 08:05:53.026013 2026] [security2:error] [pid 358661:tid 358758] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SkQlWhjQfpOo60_HeZgAAU10"]
[Tue Jul 21 08:05:53.026163 2026] [security2:error] [pid 358661:tid 358877] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SkQlWhjQfpOo60_HeZgAAU10"]
[Tue Jul 21 08:05:53.263219 2026] [security2:error] [pid 358661:tid 358869] [client 20.104.96.117:7562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/lib.php"] [unique_id "al9SkQlWhjQfpOo60_HeagAAAEs"]
[Tue Jul 21 08:05:53.386213 2026] [security2:error] [pid 358661:tid 358805] [client 184.75.221.3:40516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9SkQlWhjQfpOo60_HebQAAAAs"]
[Tue Jul 21 08:05:53.386323 2026] [security2:error] [pid 358661:tid 358805] [client 184.75.221.3:40516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9SkQlWhjQfpOo60_HebQAAAAs"]
[Tue Jul 21 08:05:53.403684 2026] [security2:error] [pid 358661:tid 358914] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9SkQlWhjQfpOo60_HebgAAAHg"]
[Tue Jul 21 08:05:53.418537 2026] [security2:error] [pid 352421:tid 352581] [client 178.153.91.96:38515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SkcJSWzG9jbYOtu5PBwAAAKM"]
[Tue Jul 21 08:05:53.418691 2026] [security2:error] [pid 352421:tid 352581] [client 178.153.91.96:38515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SkcJSWzG9jbYOtu5PBwAAAKM"]
[Tue Jul 21 08:05:53.514657 2026] [security2:error] [pid 358661:tid 358835] [client 117.247.80.59:14230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkQlWhjQfpOo60_HecAAAACk"]
[Tue Jul 21 08:05:53.514773 2026] [security2:error] [pid 358661:tid 358835] [client 117.247.80.59:14230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkQlWhjQfpOo60_HecAAAACk"]
[Tue Jul 21 08:05:53.626483 2026] [security2:error] [pid 358661:tid 358837] [client 20.104.96.117:3078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/classwithtostring.php"] [unique_id "al9SkQlWhjQfpOo60_HecwAAACs"]
[Tue Jul 21 08:05:53.684277 2026] [security2:error] [pid 358661:tid 358833] [client 184.75.221.3:33792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9SkQlWhjQfpOo60_HedgAAACc"]
[Tue Jul 21 08:05:53.684354 2026] [security2:error] [pid 358661:tid 358833] [client 184.75.221.3:33792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9SkQlWhjQfpOo60_HedgAAACc"]
[Tue Jul 21 08:05:53.756149 2026] [security2:error] [pid 352421:tid 352511] [remote 45.3.41.87:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SkcJSWzG9jbYOtu5PCwAAxFk"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:53.964383 2026] [security2:error] [pid 358661:tid 358790] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkQlWhjQfpOo60_HeegAAen0"]
[Tue Jul 21 08:05:53.964572 2026] [security2:error] [pid 358661:tid 358916] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkQlWhjQfpOo60_HeegAAen0"]
[Tue Jul 21 08:05:54.012004 2026] [security2:error] [pid 352421:tid 352624] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9SksJSWzG9jbYOtu5PEAAAAM4"]
[Tue Jul 21 08:05:54.025353 2026] [security2:error] [pid 358661:tid 358683] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkglWhjQfpOo60_HeewAAaRI"]
[Tue Jul 21 08:05:54.025512 2026] [security2:error] [pid 358661:tid 358899] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkglWhjQfpOo60_HeewAAaRI"]
[Tue Jul 21 08:05:54.089880 2026] [security2:error] [pid 352421:tid 352639] [client 202.143.127.214:61303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SksJSWzG9jbYOtu5PEQAAAN0"]
[Tue Jul 21 08:05:54.090418 2026] [security2:error] [pid 352421:tid 352639] [client 202.143.127.214:61303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SksJSWzG9jbYOtu5PEQAAAN0"]
[Tue Jul 21 08:05:54.188240 2026] [security2:error] [pid 358661:tid 358910] [client 20.104.96.117:7595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/login.php"] [unique_id "al9SkglWhjQfpOo60_HefgAAAHQ"]
[Tue Jul 21 08:05:54.318921 2026] [security2:error] [pid 358661:tid 358915] [client 20.104.96.117:3116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9SkglWhjQfpOo60_HegQAAAHk"]
[Tue Jul 21 08:05:54.432651 2026] [security2:error] [pid 358661:tid 358824] [client 117.210.135.0:52635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkglWhjQfpOo60_HegwAAAB4"]
[Tue Jul 21 08:05:54.432770 2026] [security2:error] [pid 358661:tid 358824] [client 117.210.135.0:52635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkglWhjQfpOo60_HegwAAAB4"]
[Tue Jul 21 08:05:54.628838 2026] [security2:error] [pid 358661:tid 358837] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9SkglWhjQfpOo60_HehgAAACs"]
[Tue Jul 21 08:05:54.796994 2026] [security2:error] [pid 358661:tid 358802] [client 20.104.96.117:3075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/wp-blog.php"] [unique_id "al9SkglWhjQfpOo60_HeiQAAAAg"]
[Tue Jul 21 08:05:55.107505 2026] [security2:error] [pid 358661:tid 358794] [client 175.144.82.48:52489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkwlWhjQfpOo60_HekAAAAAA"]
[Tue Jul 21 08:05:55.108230 2026] [security2:error] [pid 358661:tid 358794] [client 175.144.82.48:52489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SkwlWhjQfpOo60_HekAAAAAA"]
[Tue Jul 21 08:05:55.243872 2026] [security2:error] [pid 358661:tid 358906] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9SkwlWhjQfpOo60_HekgAAAHA"]
[Tue Jul 21 08:05:55.283239 2026] [security2:error] [pid 358661:tid 358910] [client 20.104.96.117:7242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/a2.php"] [unique_id "al9SkwlWhjQfpOo60_HelAAAAHQ"]
[Tue Jul 21 08:05:55.396491 2026] [security2:error] [pid 358661:tid 358915] [client 20.197.192.193:3281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/ms-new.php"] [unique_id "al9SkwlWhjQfpOo60_HemQAAAHk"]
[Tue Jul 21 08:05:55.398847 2026] [security2:error] [pid 352421:tid 352650] [client 74.7.228.8:51178] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "megaroteiros.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Sk8JSWzG9jbYOtu5PJAAAAOg"]
[Tue Jul 21 08:05:55.537107 2026] [security2:error] [pid 358661:tid 358821] [client 20.226.60.151:12384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9SkwlWhjQfpOo60_HenQAAABs"]
[Tue Jul 21 08:05:55.726728 2026] [security2:error] [pid 352421:tid 352572] [client 20.104.96.117:3119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Sk8JSWzG9jbYOtu5PMAAAAJo"]
[Tue Jul 21 08:05:55.840835 2026] [security2:error] [pid 352421:tid 352654] [client 38.100.221.102:17419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sk8JSWzG9jbYOtu5PMgAAAOw"]
[Tue Jul 21 08:05:55.840951 2026] [security2:error] [pid 352421:tid 352654] [client 38.100.221.102:17419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sk8JSWzG9jbYOtu5PMgAAAOw"]
[Tue Jul 21 08:05:55.855988 2026] [security2:error] [pid 352421:tid 352608] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Sk8JSWzG9jbYOtu5PNAAAAL4"]
[Tue Jul 21 08:05:55.978260 2026] [security2:error] [pid 352421:tid 352449] [remote 91.142.222.105:60022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rustikusboxingschool.com"] [uri "/wp-login.php"] [unique_id "al9Sk8JSWzG9jbYOtu5PNwAA5Rs"]
[Tue Jul 21 08:05:56.046747 2026] [security2:error] [pid 358661:tid 358894] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SkwlWhjQfpOo60_HepwAAAGQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:05:56.080205 2026] [security2:error] [pid 358661:tid 358802] [client 65.21.113.253:54852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SkwlWhjQfpOo60_HenwAAAAg"]
[Tue Jul 21 08:05:56.328090 2026] [security2:error] [pid 358661:tid 358806] [client 20.104.96.117:7980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/d61.php"] [unique_id "al9SlAlWhjQfpOo60_HerQAAAAw"]
[Tue Jul 21 08:05:56.337428 2026] [security2:error] [pid 352421:tid 352666] [client 102.129.223.92:24925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.223.129.102.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premiercservices.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9SlMJSWzG9jbYOtu5PPwAAAPg"], referer: https://premiercservices.com/
[Tue Jul 21 08:05:56.396318 2026] [security2:error] [pid 352421:tid 352525] [remote 45.3.42.46:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9Sk8JSWzG9jbYOtu5PIAAAkGc"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:56.477382 2026] [security2:error] [pid 352421:tid 352625] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9SlMJSWzG9jbYOtu5PQQAAAM8"]
[Tue Jul 21 08:05:56.751272 2026] [security2:error] [pid 358661:tid 358853] [client 109.60.28.94:7361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SlAlWhjQfpOo60_HetQAAADs"]
[Tue Jul 21 08:05:56.751362 2026] [security2:error] [pid 358661:tid 358853] [client 109.60.28.94:7361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SlAlWhjQfpOo60_HetQAAADs"]
[Tue Jul 21 08:05:56.801648 2026] [security2:error] [pid 352421:tid 352630] [client 92.119.178.3:52084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SlMJSWzG9jbYOtu5PRwAAANQ"]
[Tue Jul 21 08:05:56.801722 2026] [security2:error] [pid 352421:tid 352630] [client 92.119.178.3:52084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SlMJSWzG9jbYOtu5PRwAAANQ"]
[Tue Jul 21 08:05:56.920800 2026] [security2:error] [pid 358661:tid 358874] [client 103.166.103.129:24581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SlAlWhjQfpOo60_HetwAAAFA"]
[Tue Jul 21 08:05:56.920929 2026] [security2:error] [pid 358661:tid 358874] [client 103.166.103.129:24581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SlAlWhjQfpOo60_HetwAAAFA"]
[Tue Jul 21 08:05:57.095509 2026] [security2:error] [pid 352421:tid 352636] [client 20.197.192.193:62477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/track.php"] [unique_id "al9SlcJSWzG9jbYOtu5PTwAAANo"]
[Tue Jul 21 08:05:57.107424 2026] [security2:error] [pid 352421:tid 352600] [client 20.104.96.117:33096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/ms-edit.php"] [unique_id "al9SlcJSWzG9jbYOtu5PUAAAALY"]
[Tue Jul 21 08:05:57.107992 2026] [security2:error] [pid 352421:tid 352673] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9SlcJSWzG9jbYOtu5PUQAAAP8"]
[Tue Jul 21 08:05:57.236347 2026] [security2:error] [pid 352421:tid 352609] [client 20.226.60.151:11994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9SlcJSWzG9jbYOtu5PVQAAAL8"]
[Tue Jul 21 08:05:57.268249 2026] [security2:error] [pid 352421:tid 352650] [client 20.104.96.117:7232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/info.php"] [unique_id "al9SlcJSWzG9jbYOtu5PVgAAAOg"]
[Tue Jul 21 08:05:57.291405 2026] [qos:error] [pid 352421:tid 352640] [client 162.241.63.68:60278] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9SlcJSWzG9jbYOtu5PVwAAAN4
[Tue Jul 21 08:05:57.298904 2026] [qos:error] [pid 352421:tid 352676] [client 162.241.63.68:60282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9SlcJSWzG9jbYOtu5PWAAAAQI
[Tue Jul 21 08:05:57.369942 2026] [security2:error] [pid 352421:tid 352564] [client 20.197.192.193:52265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/byp8.php"] [unique_id "al9SlcJSWzG9jbYOtu5PWgAAAJI"]
[Tue Jul 21 08:05:57.414800 2026] [security2:error] [pid 358661:tid 358811] [client 20.29.126.15:10128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/rip.php"] [unique_id "al9SlQlWhjQfpOo60_HeuwAAABE"]
[Tue Jul 21 08:05:57.483953 2026] [qos:error] [pid 352421:tid 352428] [remote 57.141.18.56:34282] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.56, id=al9SlcJSWzG9jbYOtu5PXQAA4AY
[Tue Jul 21 08:05:57.632498 2026] [security2:error] [pid 352421:tid 352527] [remote 192.241.143.148:45812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9SlcJSWzG9jbYOtu5PXwAApGk"]
[Tue Jul 21 08:05:57.641588 2026] [qos:error] [pid 352421:tid 352519] [remote 57.141.18.64:31722] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.64, id=al9SlcJSWzG9jbYOtu5PYQAAu2E
[Tue Jul 21 08:05:57.736881 2026] [security2:error] [pid 358661:tid 358907] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9SlQlWhjQfpOo60_HevgAAAHE"]
[Tue Jul 21 08:05:57.847072 2026] [security2:error] [pid 358661:tid 358854] [client 20.104.96.117:8110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/11.php"] [unique_id "al9SlQlWhjQfpOo60_HewAAAADw"]
[Tue Jul 21 08:05:57.880253 2026] [security2:error] [pid 352421:tid 352552] [client 41.68.90.219:53525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SlcJSWzG9jbYOtu5PZQAAAIY"]
[Tue Jul 21 08:05:57.881860 2026] [security2:error] [pid 352421:tid 352552] [client 41.68.90.219:53525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SlcJSWzG9jbYOtu5PZQAAAIY"]
[Tue Jul 21 08:05:57.882085 2026] [qos:error] [pid 352421:tid 352443] [remote 57.141.18.4:60756] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.4, id=al9SlcJSWzG9jbYOtu5PZgAAmBU
[Tue Jul 21 08:05:58.083411 2026] [security2:error] [pid 352421:tid 352476] [remote 65.111.30.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.30.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SlcJSWzG9jbYOtu5PZwAAiDY"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:58.212092 2026] [security2:error] [pid 358661:tid 358795] [client 185.213.175.37:31004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.desconsultoria.com.br"] [uri "/.env.bak"] [unique_id "al9SlglWhjQfpOo60_HewgAAAAE"]
[Tue Jul 21 08:05:58.354533 2026] [security2:error] [pid 352421:tid 352578] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9SlsJSWzG9jbYOtu5PcAAAAKA"]
[Tue Jul 21 08:05:58.358052 2026] [qos:error] [pid 358661:tid 358837] [client 162.241.63.68:60302] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9SlglWhjQfpOo60_HexAAAACs
[Tue Jul 21 08:05:58.369605 2026] [qos:error] [pid 352421:tid 352670] [client 162.241.63.68:60312] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9SlsJSWzG9jbYOtu5PcQAAAPw
[Tue Jul 21 08:05:58.509046 2026] [security2:error] [pid 352421:tid 352621] [client 20.104.96.117:7239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/v2.php"] [unique_id "al9SlsJSWzG9jbYOtu5PdQAAAMs"]
[Tue Jul 21 08:05:58.592206 2026] [qos:error] [pid 358661:tid 358677] [remote 57.141.18.80:47910] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.80, id=al9SlglWhjQfpOo60_HexQAAFAw
[Tue Jul 21 08:05:58.709420 2026] [qos:error] [pid 352421:tid 352454] [remote 57.141.18.24:64384] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.24, id=al9SlsJSWzG9jbYOtu5PdwAAmSA
[Tue Jul 21 08:05:58.752378 2026] [security2:error] [pid 358661:tid 358843] [client 65.21.113.253:45968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SlglWhjQfpOo60_HeyAAAADE"]
[Tue Jul 21 08:05:58.963057 2026] [security2:error] [pid 352421:tid 352658] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9SlsJSWzG9jbYOtu5PfQAAAPA"]
[Tue Jul 21 08:05:58.963702 2026] [security2:error] [pid 358661:tid 358784] [remote 185.198.243.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sejabarbara.com.br"] [uri "/000.php"] [unique_id "al9SlglWhjQfpOo60_HeygAAMnc"], referer: http://sejabarbara.com/000.php
[Tue Jul 21 08:05:59.002768 2026] [security2:error] [pid 352421:tid 352676] [client 20.226.60.151:11974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/media.php"] [unique_id "al9Sl8JSWzG9jbYOtu5PgQAAAQI"]
[Tue Jul 21 08:05:59.101488 2026] [security2:error] [pid 358661:tid 358874] [client 65.21.113.253:54852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SlglWhjQfpOo60_HexwAAAFA"]
[Tue Jul 21 08:05:59.150548 2026] [security2:error] [pid 358661:tid 358705] [remote 45.3.40.46:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.40.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SlwlWhjQfpOo60_HezAAAQCg"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:05:59.280389 2026] [security2:error] [pid 352421:tid 352669] [client 20.104.96.117:7959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/panel.php"] [unique_id "al9Sl8JSWzG9jbYOtu5PhwAAAPs"]
[Tue Jul 21 08:05:59.372112 2026] [security2:error] [pid 352421:tid 352516] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Sl8JSWzG9jbYOtu5PigAArF4"]
[Tue Jul 21 08:05:59.372252 2026] [security2:error] [pid 352421:tid 352590] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Sl8JSWzG9jbYOtu5PigAArF4"]
[Tue Jul 21 08:05:59.460199 2026] [security2:error] [pid 358661:tid 358822] [client 120.56.162.40:53575] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SlwlWhjQfpOo60_He0QAAABw"]
[Tue Jul 21 08:05:59.460298 2026] [security2:error] [pid 358661:tid 358822] [client 120.56.162.40:53575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SlwlWhjQfpOo60_He0QAAABw"]
[Tue Jul 21 08:05:59.475098 2026] [security2:error] [pid 352421:tid 352677] [client 182.8.255.181:17711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Sl8JSWzG9jbYOtu5PjQAAAQM"]
[Tue Jul 21 08:05:59.475241 2026] [security2:error] [pid 352421:tid 352677] [client 182.8.255.181:17711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9Sl8JSWzG9jbYOtu5PjQAAAQM"]
[Tue Jul 21 08:05:59.571271 2026] [security2:error] [pid 352421:tid 352603] [client 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9Sl8JSWzG9jbYOtu5PjwAAALk"]
[Tue Jul 21 08:05:59.635135 2026] [qos:error] [pid 352421:tid 352486] [remote 57.141.18.25:36574] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.25, id=al9Sl8JSWzG9jbYOtu5PkQAAuEA
[Tue Jul 21 08:05:59.812385 2026] [security2:error] [pid 358661:tid 358872] [client 65.21.113.253:58016] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SlwlWhjQfpOo60_He0AAAAE4"]
[Tue Jul 21 08:05:59.837572 2026] [qos:error] [pid 352421:tid 352477] [remote 57.141.18.38:42418] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.38, id=al9Sl8JSWzG9jbYOtu5PlgAAwjc
[Tue Jul 21 08:05:59.941207 2026] [security2:error] [pid 358661:tid 358901] [client 20.104.96.117:7258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/dex.php"] [unique_id "al9SlwlWhjQfpOo60_He1wAAAGs"]
[Tue Jul 21 08:06:00.135065 2026] [security2:error] [pid 358661:tid 358721] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SmAlWhjQfpOo60_He2QAAQjg"]
[Tue Jul 21 08:06:00.135162 2026] [security2:error] [pid 358661:tid 358860] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SmAlWhjQfpOo60_He2QAAQjg"]
[Tue Jul 21 08:06:00.157301 2026] [security2:error] [pid 352421:tid 352490] [remote 45.3.41.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SmMJSWzG9jbYOtu5PvQAA6kQ"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:00.211522 2026] [access_compat:error] [pid 358661:tid 358913] [client 162.241.63.68:33962] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:06:00.232301 2026] [security2:error] [pid 358661:tid 358676] [remote 185.198.243.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sejabarbara.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9SmAlWhjQfpOo60_He3QAAaAs"], referer: http://sejabarbara.com/wp-admin/css/index.php
[Tue Jul 21 08:06:00.264406 2026] [security2:error] [pid 358661:tid 358830] [client 20.104.96.117:3099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9SmAlWhjQfpOo60_He3gAAACQ"]
[Tue Jul 21 08:06:00.276932 2026] [qos:error] [pid 358661:tid 358904] [client 162.241.63.68:33976] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9SmAlWhjQfpOo60_He3wAAAG4
[Tue Jul 21 08:06:00.281916 2026] [qos:error] [pid 358661:tid 358877] [client 162.241.63.68:33990] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9SmAlWhjQfpOo60_He4AAAAFM
[Tue Jul 21 08:06:00.601582 2026] [qos:error] [pid 352421:tid 352547] [remote 57.141.18.52:20704] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.52, id=al9SmMJSWzG9jbYOtu5PxwAAmX0
[Tue Jul 21 08:06:00.678148 2026] [security2:error] [pid 358661:tid 358837] [client 20.226.60.151:12022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/images.php"] [unique_id "al9SmAlWhjQfpOo60_He6QAAACs"]
[Tue Jul 21 08:06:00.785959 2026] [security2:error] [pid 358661:tid 358919] [client 102.206.115.33:65516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SmAlWhjQfpOo60_He6gAAAH0"]
[Tue Jul 21 08:06:00.786073 2026] [security2:error] [pid 358661:tid 358919] [client 102.206.115.33:65516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SmAlWhjQfpOo60_He6gAAAH0"]
[Tue Jul 21 08:06:00.870642 2026] [security2:error] [pid 358661:tid 358813] [client 20.104.96.117:7596] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tkcorretoradeseguros.com.br"] [uri "/1.php"] [unique_id "al9SmAlWhjQfpOo60_He6wAAABM"]
[Tue Jul 21 08:06:00.870735 2026] [security2:error] [pid 358661:tid 358813] [client 20.104.96.117:7596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/1.php"] [unique_id "al9SmAlWhjQfpOo60_He6wAAABM"]
[Tue Jul 21 08:06:01.036687 2026] [security2:error] [pid 358661:tid 358743] [remote 185.198.243.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sejabarbara.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9SmQlWhjQfpOo60_He7AAAGk4"], referer: http://sejabarbara.com/wp-content/plugins/index.php
[Tue Jul 21 08:06:01.167846 2026] [security2:error] [pid 352421:tid 352586] [client 20.226.60.151:12026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/gecko.php"] [unique_id "al9SmcJSWzG9jbYOtu5P1gAAAKg"]
[Tue Jul 21 08:06:01.203137 2026] [qos:error] [pid 352421:tid 352501] [remote 57.141.18.67:58820] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.67, id=al9SmcJSWzG9jbYOtu5P1wAAj08
[Tue Jul 21 08:06:01.272971 2026] [qos:error] [pid 358661:tid 358843] [client 162.241.63.68:34018] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9SmQlWhjQfpOo60_He7wAAADE
[Tue Jul 21 08:06:01.348448 2026] [qos:error] [pid 358661:tid 358811] [client 162.241.63.68:34044] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9SmQlWhjQfpOo60_He8QAAABE
[Tue Jul 21 08:06:01.349876 2026] [qos:error] [pid 352421:tid 352647] [client 162.241.63.68:34054] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9SmcJSWzG9jbYOtu5P2QAAAOU
[Tue Jul 21 08:06:01.355584 2026] [security2:error] [pid 358661:tid 358720] [remote 216.26.237.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.237.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SmQlWhjQfpOo60_He7gAAazc"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:01.438016 2026] [security2:error] [pid 358661:tid 358898] [client 20.104.96.117:7960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/ms.php"] [unique_id "al9SmQlWhjQfpOo60_He8wAAAGg"]
[Tue Jul 21 08:06:01.690877 2026] [security2:error] [pid 352421:tid 352546] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SmcJSWzG9jbYOtu5P5QAAhnw"]
[Tue Jul 21 08:06:01.691089 2026] [security2:error] [pid 352421:tid 352552] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SmcJSWzG9jbYOtu5P5QAAhnw"]
[Tue Jul 21 08:06:01.791364 2026] [security2:error] [pid 352421:tid 352619] [client 61.1.167.83:52698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SmcJSWzG9jbYOtu5P6QAAAMk"]
[Tue Jul 21 08:06:01.791531 2026] [security2:error] [pid 352421:tid 352619] [client 61.1.167.83:52698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SmcJSWzG9jbYOtu5P6QAAAMk"]
[Tue Jul 21 08:06:01.845773 2026] [autoindex:error] [pid 352421:tid 352629] [client 20.104.96.117:7576] AH01276: Cannot serve directory /home3/tkcorr80/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:06:02.119193 2026] [security2:error] [pid 352421:tid 352568] [client 20.104.96.117:7576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/memberfuns.php"] [unique_id "al9SmsJSWzG9jbYOtu5P7wAAAJY"]
[Tue Jul 21 08:06:02.144771 2026] [security2:error] [pid 358661:tid 358913] [client 103.78.200.11:63288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SmglWhjQfpOo60_He_gAAAHc"]
[Tue Jul 21 08:06:02.144931 2026] [security2:error] [pid 358661:tid 358913] [client 103.78.200.11:63288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SmglWhjQfpOo60_He_gAAAHc"]
[Tue Jul 21 08:06:02.300642 2026] [security2:error] [pid 358661:tid 358813] [client 184.75.221.3:52296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SmglWhjQfpOo60_HfAQAAABM"]
[Tue Jul 21 08:06:02.300793 2026] [security2:error] [pid 358661:tid 358813] [client 184.75.221.3:52296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SmglWhjQfpOo60_HfAQAAABM"]
[Tue Jul 21 08:06:02.528675 2026] [security2:error] [pid 358661:tid 358853] [client 20.104.96.117:7591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/0.php"] [unique_id "al9SmglWhjQfpOo60_HfBAAAADs"]
[Tue Jul 21 08:06:02.586294 2026] [security2:error] [pid 358661:tid 358820] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SmglWhjQfpOo60_HfAwAAGlw"]
[Tue Jul 21 08:06:02.668029 2026] [security2:error] [pid 358661:tid 358742] [remote 185.198.243.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sejabarbara.com.br"] [uri "/wp-content/index.php"] [unique_id "al9SmglWhjQfpOo60_HfCwAAZE0"], referer: http://sejabarbara.com/wp-content/index.php
[Tue Jul 21 08:06:02.776513 2026] [security2:error] [pid 358661:tid 358771] [remote 209.50.165.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.165.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SmglWhjQfpOo60_HfBwAAbWo"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:02.801576 2026] [security2:error] [pid 358661:tid 358795] [client 20.104.96.117:3182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9SmglWhjQfpOo60_HfEgAAAAE"]
[Tue Jul 21 08:06:02.822178 2026] [security2:error] [pid 358661:tid 358879] [client 74.7.244.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "concielo.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9SmglWhjQfpOo60_HfEwAAVQQ"]
[Tue Jul 21 08:06:02.922097 2026] [security2:error] [pid 358661:tid 358872] [client 87.116.180.198:27278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SmglWhjQfpOo60_HfFgAAAE4"]
[Tue Jul 21 08:06:02.922233 2026] [security2:error] [pid 358661:tid 358872] [client 87.116.180.198:27278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SmglWhjQfpOo60_HfFgAAAE4"]
[Tue Jul 21 08:06:02.994963 2026] [security2:error] [pid 358661:tid 358919] [client 20.104.96.117:8071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/BDKR28.php"] [unique_id "al9SmglWhjQfpOo60_HfFwAAAH0"]
[Tue Jul 21 08:06:03.025905 2026] [security2:error] [pid 358661:tid 358835] [client 103.29.114.44:29577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SmwlWhjQfpOo60_HfGAAAACk"]
[Tue Jul 21 08:06:03.026032 2026] [security2:error] [pid 358661:tid 358835] [client 103.29.114.44:29577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SmwlWhjQfpOo60_HfGAAAACk"]
[Tue Jul 21 08:06:03.227054 2026] [qos:error] [pid 352421:tid 352434] [remote 57.141.18.46:50394] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.46, id=al9Sm8JSWzG9jbYOtu5P_gAA5gw
[Tue Jul 21 08:06:03.469576 2026] [security2:error] [pid 358661:tid 358874] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SmwlWhjQfpOo60_HfHAAAAFA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:03.509724 2026] [security2:error] [pid 358661:tid 358695] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SmwlWhjQfpOo60_HfHwAAax4"]
[Tue Jul 21 08:06:03.509913 2026] [security2:error] [pid 358661:tid 358901] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SmwlWhjQfpOo60_HfHwAAax4"]
[Tue Jul 21 08:06:03.555708 2026] [security2:error] [pid 358661:tid 358884] [client 20.104.96.117:7265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/green1.php"] [unique_id "al9SmwlWhjQfpOo60_HfIAAAAFo"]
[Tue Jul 21 08:06:03.600127 2026] [security2:error] [pid 358661:tid 358761] [remote 209.50.173.238:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.173.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SmwlWhjQfpOo60_HfIgAAJGA"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:03.605680 2026] [security2:error] [pid 358661:tid 358682] [remote 185.198.243.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sejabarbara.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9SmwlWhjQfpOo60_HfIwAAZBE"], referer: http://sejabarbara.com//wp-content/plugins/fix/up.php
[Tue Jul 21 08:06:03.664109 2026] [security2:error] [pid 352421:tid 352647] [client 20.29.126.15:9340] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.atilafagundes.com.br"] [uri "/1.php"] [unique_id "al9Sm8JSWzG9jbYOtu5QBgAAAOU"]
[Tue Jul 21 08:06:03.664217 2026] [security2:error] [pid 352421:tid 352647] [client 20.29.126.15:9340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/1.php"] [unique_id "al9Sm8JSWzG9jbYOtu5QBgAAAOU"]
[Tue Jul 21 08:06:03.772128 2026] [security2:error] [pid 358661:tid 358809] [client 20.226.60.151:12382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/82.php"] [unique_id "al9SmwlWhjQfpOo60_HfJAAAAA8"]
[Tue Jul 21 08:06:03.842337 2026] [security2:error] [pid 352421:tid 352551] [client 20.197.192.193:62479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/2352356666.php"] [unique_id "al9Sm8JSWzG9jbYOtu5QEAAAAIU"]
[Tue Jul 21 08:06:03.938402 2026] [security2:error] [pid 358661:tid 358914] [client 74.7.228.43:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "egcbatiment.com"] [uri "/index.php"] [unique_id "al9SmglWhjQfpOo60_HfEQAAAHg"]
[Tue Jul 21 08:06:03.938906 2026] [security2:error] [pid 358661:tid 358907] [client 74.7.228.43:52242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "egcbatiment.com"] [uri "/robots.txt"] [unique_id "al9SmglWhjQfpOo60_HfDwAAAHE"]
[Tue Jul 21 08:06:03.986422 2026] [security2:error] [pid 352421:tid 352638] [client 178.153.91.96:39265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Sm8JSWzG9jbYOtu5QFQAAANw"]
[Tue Jul 21 08:06:03.986645 2026] [security2:error] [pid 352421:tid 352638] [client 178.153.91.96:39265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Sm8JSWzG9jbYOtu5QFQAAANw"]
[Tue Jul 21 08:06:03.987536 2026] [security2:error] [pid 352421:tid 352581] [client 20.226.60.151:11997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/admin.php"] [unique_id "al9Sm8JSWzG9jbYOtu5QFgAAAKM"]
[Tue Jul 21 08:06:04.010541 2026] [qos:error] [pid 358661:tid 358751] [remote 74.7.227.54:52880] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=74.7.227.54, id=al9SnAlWhjQfpOo60_HfKAAAVVY, referer: https://arielson.com.br/coursos/?duration=medium%2CextraLong&filter_course-tag=130,454,134,249,455&filtering=1&instructor=2&level=all_levels&orderby=course_title_az&price_type=paid
[Tue Jul 21 08:06:04.015402 2026] [security2:error] [pid 352421:tid 352612] [client 20.104.96.117:7273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/nc4.php"] [unique_id "al9SnMJSWzG9jbYOtu5QFwAAAMI"]
[Tue Jul 21 08:06:04.060147 2026] [security2:error] [pid 358661:tid 358904] [client 65.21.113.253:54852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SmwlWhjQfpOo60_HfIQAAAG4"]
[Tue Jul 21 08:06:04.111064 2026] [security2:error] [pid 352421:tid 352626] [client 20.226.60.151:12371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/adminner.php"] [unique_id "al9SnMJSWzG9jbYOtu5QGQAAANA"]
[Tue Jul 21 08:06:04.202536 2026] [security2:error] [pid 358661:tid 358898] [client 117.247.80.59:14419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SnAlWhjQfpOo60_HfKgAAAGg"]
[Tue Jul 21 08:06:04.202645 2026] [security2:error] [pid 358661:tid 358898] [client 117.247.80.59:14419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SnAlWhjQfpOo60_HfKgAAAGg"]
[Tue Jul 21 08:06:04.322628 2026] [security2:error] [pid 358661:tid 358873] [client 20.226.60.151:12357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/admin.php"] [unique_id "al9SnAlWhjQfpOo60_HfLgAAAE8"]
[Tue Jul 21 08:06:04.344346 2026] [security2:error] [pid 358661:tid 358820] [client 20.104.96.117:7282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/a1.php"] [unique_id "al9SnAlWhjQfpOo60_HfLwAAABo"]
[Tue Jul 21 08:06:04.379297 2026] [security2:error] [pid 352421:tid 352568] [client 20.104.96.117:3172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/abcd.php"] [unique_id "al9SnMJSWzG9jbYOtu5QIAAAAJY"]
[Tue Jul 21 08:06:04.430401 2026] [security2:error] [pid 358661:tid 358671] [remote 104.207.60.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.60.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SnAlWhjQfpOo60_HfMQAAQgY"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:04.527563 2026] [security2:error] [pid 358661:tid 358678] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SnAlWhjQfpOo60_HfMwAAWg0"]
[Tue Jul 21 08:06:04.527732 2026] [security2:error] [pid 358661:tid 358884] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SnAlWhjQfpOo60_HfMwAAWg0"]
[Tue Jul 21 08:06:04.679345 2026] [security2:error] [pid 352421:tid 352624] [client 20.104.96.117:8077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/eee.php"] [unique_id "al9SnMJSWzG9jbYOtu5QIwAAAM4"]
[Tue Jul 21 08:06:04.825599 2026] [qos:error] [pid 352421:tid 352435] [remote 57.141.18.95:42946] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.95, id=al9SnMJSWzG9jbYOtu5QJQAAsQ0
[Tue Jul 21 08:06:04.930467 2026] [qos:error] [pid 358661:tid 358724] [remote 57.141.18.121:61902] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.121, id=al9SnAlWhjQfpOo60_HfOAAANzs
[Tue Jul 21 08:06:05.000486 2026] [security2:error] [pid 358661:tid 358811] [client 117.210.135.0:53278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SnQlWhjQfpOo60_HfOQAAABE"]
[Tue Jul 21 08:06:05.001126 2026] [security2:error] [pid 358661:tid 358811] [client 117.210.135.0:53278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SnQlWhjQfpOo60_HfOQAAABE"]
[Tue Jul 21 08:06:05.040493 2026] [security2:error] [pid 352421:tid 352650] [client 20.104.96.117:3156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/file15.php"] [unique_id "al9SncJSWzG9jbYOtu5QKAAAAOg"]
[Tue Jul 21 08:06:05.051025 2026] [security2:error] [pid 352421:tid 352643] [client 202.143.127.214:61927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SncJSWzG9jbYOtu5QKQAAAOE"]
[Tue Jul 21 08:06:05.051143 2026] [security2:error] [pid 352421:tid 352643] [client 202.143.127.214:61927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SncJSWzG9jbYOtu5QKQAAAOE"]
[Tue Jul 21 08:06:05.076537 2026] [security2:error] [pid 358661:tid 358782] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SnQlWhjQfpOo60_HfOwAANnU"]
[Tue Jul 21 08:06:05.076708 2026] [security2:error] [pid 358661:tid 358848] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SnQlWhjQfpOo60_HfOwAANnU"]
[Tue Jul 21 08:06:05.308877 2026] [security2:error] [pid 352421:tid 352669] [client 20.104.96.117:7941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-aothait.php"] [unique_id "al9SncJSWzG9jbYOtu5QLgAAAPs"]
[Tue Jul 21 08:06:05.479062 2026] [qos:error] [pid 358661:tid 358684] [remote 57.141.18.66:60512] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.66, id=al9SnQlWhjQfpOo60_HfQAAANRM
[Tue Jul 21 08:06:05.697913 2026] [security2:error] [pid 352421:tid 352640] [client 65.21.113.253:36114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SncJSWzG9jbYOtu5QNQAAAN4"]
[Tue Jul 21 08:06:06.017790 2026] [security2:error] [pid 352421:tid 352430] [remote 45.3.42.61:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SnsJSWzG9jbYOtu5QPQAAhQg"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:06.035802 2026] [security2:error] [pid 352421:tid 352633] [client 20.104.96.117:7940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/config.json.php"] [unique_id "al9SnsJSWzG9jbYOtu5QPgAAANc"]
[Tue Jul 21 08:06:06.058838 2026] [security2:error] [pid 352421:tid 352599] [client 92.119.178.3:48176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9SnsJSWzG9jbYOtu5QPwAAALU"]
[Tue Jul 21 08:06:06.058926 2026] [security2:error] [pid 352421:tid 352599] [client 92.119.178.3:48176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9SnsJSWzG9jbYOtu5QPwAAALU"]
[Tue Jul 21 08:06:06.262919 2026] [security2:error] [pid 352421:tid 352556] [client 20.226.60.151:12379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/k.php"] [unique_id "al9SnsJSWzG9jbYOtu5QQQAAAIo"]
[Tue Jul 21 08:06:06.314485 2026] [security2:error] [pid 358661:tid 358901] [client 65.21.113.253:54852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SnQlWhjQfpOo60_HfQgAAAGs"]
[Tue Jul 21 08:06:06.319282 2026] [security2:error] [pid 352421:tid 352674] [client 20.104.96.117:3165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/jp.php"] [unique_id "al9SnsJSWzG9jbYOtu5QRAAAAQA"]
[Tue Jul 21 08:06:06.374189 2026] [security2:error] [pid 352421:tid 352619] [client 20.104.96.117:7992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9SnsJSWzG9jbYOtu5QSwAAAMk"]
[Tue Jul 21 08:06:06.434735 2026] [security2:error] [pid 352421:tid 352665] [client 38.100.221.102:18152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SnsJSWzG9jbYOtu5QTQAAAPc"]
[Tue Jul 21 08:06:06.434846 2026] [security2:error] [pid 352421:tid 352665] [client 38.100.221.102:18152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SnsJSWzG9jbYOtu5QTQAAAPc"]
[Tue Jul 21 08:06:06.592973 2026] [security2:error] [pid 352421:tid 352621] [client 204.8.98.45:59802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9SnsJSWzG9jbYOtu5QTwAAAMs"]
[Tue Jul 21 08:06:06.593077 2026] [security2:error] [pid 352421:tid 352621] [client 204.8.98.45:59802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9SnsJSWzG9jbYOtu5QTwAAAMs"]
[Tue Jul 21 08:06:06.724491 2026] [security2:error] [pid 358661:tid 358894] [client 20.104.96.117:7267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/k2.php"] [unique_id "al9SnglWhjQfpOo60_HfRAAAAGQ"]
[Tue Jul 21 08:06:06.767763 2026] [security2:error] [pid 352421:tid 352657] [client 20.104.96.117:32773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/f35.php"] [unique_id "al9SnsJSWzG9jbYOtu5QUgAAAO8"]
[Tue Jul 21 08:06:06.771719 2026] [security2:error] [pid 358661:tid 358809] [client 20.197.192.193:39174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/pn.php"] [unique_id "al9SnglWhjQfpOo60_HfRgAAAA8"]
[Tue Jul 21 08:06:06.905945 2026] [security2:error] [pid 352421:tid 352662] [client 20.29.126.15:9288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/chosen.php"] [unique_id "al9SnsJSWzG9jbYOtu5QVgAAAPQ"]
[Tue Jul 21 08:06:07.102483 2026] [security2:error] [pid 358661:tid 358872] [client 20.104.96.117:7257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9SnwlWhjQfpOo60_HfTgAAAE4"]
[Tue Jul 21 08:06:07.316787 2026] [security2:error] [pid 352421:tid 352563] [client 20.104.96.117:33124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/wp-load.php"] [unique_id "al9Sn8JSWzG9jbYOtu5QWwAAAJE"]
[Tue Jul 21 08:06:07.404121 2026] [security2:error] [pid 352421:tid 352669] [client 20.104.96.117:7489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9Sn8JSWzG9jbYOtu5QXwAAAPs"]
[Tue Jul 21 08:06:07.419982 2026] [security2:error] [pid 352421:tid 352433] [remote 216.26.230.18:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.230.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9Sn8JSWzG9jbYOtu5QWgAAvws"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:07.453250 2026] [security2:error] [pid 352421:tid 352591] [client 175.144.82.48:53073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sn8JSWzG9jbYOtu5QYQAAAK0"]
[Tue Jul 21 08:06:07.454150 2026] [security2:error] [pid 352421:tid 352591] [client 175.144.82.48:53073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sn8JSWzG9jbYOtu5QYQAAAK0"]
[Tue Jul 21 08:06:07.597231 2026] [security2:error] [pid 358661:tid 358795] [client 103.166.103.129:63088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SnwlWhjQfpOo60_HfVQAAAAE"]
[Tue Jul 21 08:06:07.597359 2026] [security2:error] [pid 358661:tid 358795] [client 103.166.103.129:63088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SnwlWhjQfpOo60_HfVQAAAAE"]
[Tue Jul 21 08:06:07.665851 2026] [security2:error] [pid 352421:tid 352610] [client 109.60.28.94:49246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sn8JSWzG9jbYOtu5QYwAAAMA"]
[Tue Jul 21 08:06:07.666523 2026] [security2:error] [pid 352421:tid 352610] [client 109.60.28.94:49246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sn8JSWzG9jbYOtu5QYwAAAMA"]
[Tue Jul 21 08:06:07.761669 2026] [security2:error] [pid 358661:tid 358873] [client 20.104.96.117:8118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9SnwlWhjQfpOo60_HfVgAAAE8"]
[Tue Jul 21 08:06:08.077509 2026] [security2:error] [pid 358661:tid 358914] [client 20.104.96.117:7259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/for.php"] [unique_id "al9SoAlWhjQfpOo60_HfXgAAAHg"]
[Tue Jul 21 08:06:08.115686 2026] [security2:error] [pid 358661:tid 358872] [client 20.104.96.117:3098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/xyn.php"] [unique_id "al9SoAlWhjQfpOo60_HfXwAAAE4"]
[Tue Jul 21 08:06:08.260434 2026] [security2:error] [pid 358661:tid 358799] [client 20.226.60.151:12388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/blurbs.php"] [unique_id "al9SoAlWhjQfpOo60_HfYgAAAAU"]
[Tue Jul 21 08:06:08.395049 2026] [security2:error] [pid 358661:tid 358822] [client 41.68.90.219:53985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SoAlWhjQfpOo60_HfZAAAABw"]
[Tue Jul 21 08:06:08.395205 2026] [security2:error] [pid 358661:tid 358822] [client 41.68.90.219:53985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SoAlWhjQfpOo60_HfZAAAABw"]
[Tue Jul 21 08:06:08.625418 2026] [security2:error] [pid 358661:tid 358803] [client 20.104.96.117:7580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/raw.php"] [unique_id "al9SoAlWhjQfpOo60_HfZwAAAAk"]
[Tue Jul 21 08:06:08.692323 2026] [security2:error] [pid 358661:tid 358813] [client 65.21.113.253:58030] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SoAlWhjQfpOo60_HfYAAAABM"]
[Tue Jul 21 08:06:08.827940 2026] [security2:error] [pid 358661:tid 358884] [client 20.104.96.117:3163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/ccc.php"] [unique_id "al9SoAlWhjQfpOo60_HfaQAAAFo"]
[Tue Jul 21 08:06:08.901145 2026] [security2:error] [pid 352421:tid 352489] [remote 38.242.157.30:52154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9SoMJSWzG9jbYOtu5QcAAAx0M"]
[Tue Jul 21 08:06:08.905885 2026] [security2:error] [pid 358661:tid 358787] [remote 104.207.62.93:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.62.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SoAlWhjQfpOo60_HfagAAGno"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:09.258361 2026] [security2:error] [pid 352421:tid 352614] [client 20.104.96.117:32816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/w.php"] [unique_id "al9SocJSWzG9jbYOtu5QeAAAAMQ"]
[Tue Jul 21 08:06:09.720806 2026] [security2:error] [pid 358661:tid 358853] [client 20.104.96.117:3077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9SoQlWhjQfpOo60_HfdgAAADs"]
[Tue Jul 21 08:06:09.855273 2026] [security2:error] [pid 352421:tid 352565] [client 182.8.255.181:17502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.255.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SocJSWzG9jbYOtu5QfwAAAJM"]
[Tue Jul 21 08:06:09.855401 2026] [security2:error] [pid 352421:tid 352565] [client 182.8.255.181:17502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9SocJSWzG9jbYOtu5QfwAAAJM"]
[Tue Jul 21 08:06:09.869694 2026] [security2:error] [pid 358661:tid 358800] [client 20.29.126.15:12873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/css.php"] [unique_id "al9SoQlWhjQfpOo60_HfeAAAAAY"]
[Tue Jul 21 08:06:09.960832 2026] [security2:error] [pid 358661:tid 358758] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SoQlWhjQfpOo60_HfeQAAQl0"]
[Tue Jul 21 08:06:09.960972 2026] [security2:error] [pid 358661:tid 358860] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SoQlWhjQfpOo60_HfeQAAQl0"]
[Tue Jul 21 08:06:09.990808 2026] [security2:error] [pid 352421:tid 352528] [remote 65.111.11.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.11.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SocJSWzG9jbYOtu5QggAAsWo"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:10.067080 2026] [security2:error] [pid 358661:tid 358814] [client 20.104.96.117:3139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/FWAZ.php"] [unique_id "al9SoglWhjQfpOo60_HffwAAABQ"]
[Tue Jul 21 08:06:10.476713 2026] [security2:error] [pid 358661:tid 358837] [client 20.104.96.117:3093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/miru1.php"] [unique_id "al9SoglWhjQfpOo60_HfgAAAACs"]
[Tue Jul 21 08:06:10.803615 2026] [security2:error] [pid 352421:tid 352440] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SosJSWzG9jbYOtu5QiwAAsxI"]
[Tue Jul 21 08:06:10.803796 2026] [security2:error] [pid 352421:tid 352597] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SosJSWzG9jbYOtu5QiwAAsxI"]
[Tue Jul 21 08:06:10.893562 2026] [security2:error] [pid 358661:tid 358803] [client 20.104.96.117:3193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/aa.php"] [unique_id "al9SoglWhjQfpOo60_HfjAAAAAk"]
[Tue Jul 21 08:06:11.181768 2026] [security2:error] [pid 352421:tid 352575] [client 20.104.96.117:33089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/122.php"] [unique_id "al9So8JSWzG9jbYOtu5QkwAAAJ0"]
[Tue Jul 21 08:06:11.217862 2026] [security2:error] [pid 358661:tid 358813] [client 65.21.113.253:41344] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SowlWhjQfpOo60_HfjQAAABM"]
[Tue Jul 21 08:06:11.290121 2026] [security2:error] [pid 358661:tid 358835] [client 102.206.115.33:59329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SowlWhjQfpOo60_HfjwAAACk"]
[Tue Jul 21 08:06:11.290396 2026] [security2:error] [pid 358661:tid 358835] [client 102.206.115.33:59329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SowlWhjQfpOo60_HfjwAAACk"]
[Tue Jul 21 08:06:11.473598 2026] [security2:error] [pid 352421:tid 352572] [client 20.104.96.117:3110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/get.php"] [unique_id "al9So8JSWzG9jbYOtu5QlwAAAJo"]
[Tue Jul 21 08:06:11.491780 2026] [security2:error] [pid 358661:tid 358860] [client 20.226.60.151:12386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/bajah.php"] [unique_id "al9SowlWhjQfpOo60_HfkgAAAEI"]
[Tue Jul 21 08:06:11.787248 2026] [security2:error] [pid 352421:tid 352626] [client 20.104.96.117:3184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/as.php"] [unique_id "al9So8JSWzG9jbYOtu5QnQAAANA"]
[Tue Jul 21 08:06:11.859558 2026] [security2:error] [pid 358661:tid 358847] [client 65.21.113.253:58030] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SowlWhjQfpOo60_HfkAAAADU"]
[Tue Jul 21 08:06:11.970719 2026] [security2:error] [pid 358661:tid 358806] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SowlWhjQfpOo60_HflwAAAAw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:12.090773 2026] [security2:error] [pid 358661:tid 358812] [client 20.104.96.117:33136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/ccou.php"] [unique_id "al9SpAlWhjQfpOo60_HfnQAAABI"]
[Tue Jul 21 08:06:12.224423 2026] [security2:error] [pid 352421:tid 352614] [client 20.226.60.151:12000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/a.php"] [unique_id "al9SpMJSWzG9jbYOtu5QogAAAMQ"]
[Tue Jul 21 08:06:12.236205 2026] [security2:error] [pid 358661:tid 358834] [client 120.56.162.40:54029] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SoglWhjQfpOo60_HffgAAACg"]
[Tue Jul 21 08:06:12.236384 2026] [security2:error] [pid 358661:tid 358834] [client 120.56.162.40:54029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SoglWhjQfpOo60_HffgAAACg"]
[Tue Jul 21 08:06:12.316359 2026] [security2:error] [pid 358661:tid 358898] [client 20.197.192.193:52243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/user.php"] [unique_id "al9SpAlWhjQfpOo60_HfnwAAAGg"]
[Tue Jul 21 08:06:12.446258 2026] [security2:error] [pid 358661:tid 358863] [client 20.104.96.117:3183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/w3lls.php"] [unique_id "al9SpAlWhjQfpOo60_HfoAAAAEU"]
[Tue Jul 21 08:06:12.471554 2026] [security2:error] [pid 358661:tid 358915] [client 198.54.128.138:53648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9SpAlWhjQfpOo60_HfoQAAAHk"]
[Tue Jul 21 08:06:12.471651 2026] [security2:error] [pid 358661:tid 358915] [client 198.54.128.138:53648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9SpAlWhjQfpOo60_HfoQAAAHk"]
[Tue Jul 21 08:06:12.565520 2026] [security2:error] [pid 358661:tid 358765] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpAlWhjQfpOo60_HfpQAAcWQ"]
[Tue Jul 21 08:06:12.565762 2026] [security2:error] [pid 358661:tid 358907] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpAlWhjQfpOo60_HfpQAAcWQ"]
[Tue Jul 21 08:06:12.739347 2026] [security2:error] [pid 358661:tid 358838] [client 20.104.96.117:3134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/test1.php"] [unique_id "al9SpAlWhjQfpOo60_HfqwAAACw"]
[Tue Jul 21 08:06:13.047916 2026] [security2:error] [pid 358661:tid 358827] [client 20.104.96.117:3161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/database.php"] [unique_id "al9SpQlWhjQfpOo60_HfrwAAACE"]
[Tue Jul 21 08:06:13.058300 2026] [security2:error] [pid 358661:tid 358880] [client 65.21.113.253:50544] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SpAlWhjQfpOo60_HfqQAAAFY"]
[Tue Jul 21 08:06:13.119584 2026] [security2:error] [pid 352421:tid 352556] [client 103.78.200.11:63799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpcJSWzG9jbYOtu5QrQAAAIo"]
[Tue Jul 21 08:06:13.120534 2026] [security2:error] [pid 352421:tid 352556] [client 103.78.200.11:63799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpcJSWzG9jbYOtu5QrQAAAIo"]
[Tue Jul 21 08:06:13.307153 2026] [security2:error] [pid 358661:tid 358837] [client 74.7.228.9:38766] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "condominiogreenvillage.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9SpQlWhjQfpOo60_HftgAAKzI"]
[Tue Jul 21 08:06:13.475490 2026] [security2:error] [pid 352421:tid 352652] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SpcJSWzG9jbYOtu5QswAA6lc"]
[Tue Jul 21 08:06:13.595907 2026] [security2:error] [pid 358661:tid 358906] [client 87.116.180.198:14023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpQlWhjQfpOo60_HftwAAAHA"]
[Tue Jul 21 08:06:13.596077 2026] [security2:error] [pid 358661:tid 358906] [client 87.116.180.198:14023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpQlWhjQfpOo60_HftwAAAHA"]
[Tue Jul 21 08:06:13.603665 2026] [security2:error] [pid 358661:tid 358872] [client 20.226.60.151:11990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/edit.php"] [unique_id "al9SpQlWhjQfpOo60_HfuAAAAE4"]
[Tue Jul 21 08:06:13.708071 2026] [security2:error] [pid 358661:tid 358799] [client 20.104.96.117:33101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/file.php"] [unique_id "al9SpQlWhjQfpOo60_HfvAAAAAU"]
[Tue Jul 21 08:06:13.738981 2026] [security2:error] [pid 352421:tid 352623] [client 103.29.114.44:61396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpcJSWzG9jbYOtu5QtwAAAM0"]
[Tue Jul 21 08:06:13.739105 2026] [security2:error] [pid 352421:tid 352623] [client 103.29.114.44:61396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpcJSWzG9jbYOtu5QtwAAAM0"]
[Tue Jul 21 08:06:13.789680 2026] [security2:error] [pid 352421:tid 352648] [client 20.29.126.15:2719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/php.php"] [unique_id "al9SpcJSWzG9jbYOtu5QuAAAAOY"]
[Tue Jul 21 08:06:13.850478 2026] [security2:error] [pid 358661:tid 358864] [client 61.1.167.83:53169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpQlWhjQfpOo60_HfwAAAAEY"]
[Tue Jul 21 08:06:13.850597 2026] [security2:error] [pid 358661:tid 358864] [client 61.1.167.83:53169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpQlWhjQfpOo60_HfwAAAAEY"]
[Tue Jul 21 08:06:13.857294 2026] [autoindex:error] [pid 358661:tid 358685] [remote 74.7.243.229:47768] AH01276: Cannot serve directory /home2/italom32/condominiogreenvillage.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:06:13.976766 2026] [security2:error] [pid 352421:tid 352450] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SpcJSWzG9jbYOtu5QugAAmxw"]
[Tue Jul 21 08:06:13.976969 2026] [security2:error] [pid 352421:tid 352573] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SpcJSWzG9jbYOtu5QugAAmxw"]
[Tue Jul 21 08:06:14.153506 2026] [security2:error] [pid 358661:tid 358838] [client 20.104.96.117:32788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/file.php"] [unique_id "al9SpglWhjQfpOo60_HfwgAAACw"]
[Tue Jul 21 08:06:14.298211 2026] [security2:error] [pid 352421:tid 352602] [client 209.50.180.46:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9So8JSWzG9jbYOtu5QmAAAuHw"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:14.413897 2026] [security2:error] [pid 352421:tid 352647] [client 20.226.60.151:12376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/hosty.php"] [unique_id "al9SpsJSWzG9jbYOtu5QxAAAAOU"]
[Tue Jul 21 08:06:14.435863 2026] [security2:error] [pid 358661:tid 358865] [client 178.153.91.96:40057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SpglWhjQfpOo60_HfyAAAAEc"]
[Tue Jul 21 08:06:14.435976 2026] [security2:error] [pid 358661:tid 358865] [client 178.153.91.96:40057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SpglWhjQfpOo60_HfyAAAAEc"]
[Tue Jul 21 08:06:14.491192 2026] [security2:error] [pid 358661:tid 358874] [client 65.21.113.253:41344] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SpglWhjQfpOo60_HfyQAAAFA"]
[Tue Jul 21 08:06:14.558544 2026] [security2:error] [pid 352421:tid 352640] [client 20.104.96.117:33102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/777.php"] [unique_id "al9SpsJSWzG9jbYOtu5QxwAAAN4"]
[Tue Jul 21 08:06:14.842793 2026] [security2:error] [pid 358661:tid 358809] [client 117.247.80.59:14087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpglWhjQfpOo60_Hf0AAAAA8"]
[Tue Jul 21 08:06:14.842944 2026] [security2:error] [pid 358661:tid 358809] [client 117.247.80.59:14087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpglWhjQfpOo60_Hf0AAAAA8"]
[Tue Jul 21 08:06:15.007163 2026] [proxy:error] [pid 352421:tid 352551] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:15.007234 2026] [proxy_http:error] [pid 352421:tid 352551] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:15.008072 2026] [proxy:error] [pid 352421:tid 352551] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:15.008108 2026] [proxy_http:error] [pid 352421:tid 352551] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:15.010663 2026] [security2:error] [pid 358661:tid 358756] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpwlWhjQfpOo60_Hf0gAAKls"]
[Tue Jul 21 08:06:15.010796 2026] [security2:error] [pid 358661:tid 358836] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpwlWhjQfpOo60_Hf0gAAKls"]
[Tue Jul 21 08:06:15.126097 2026] [security2:error] [pid 358661:tid 358919] [client 65.21.113.253:50544] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SpglWhjQfpOo60_HfzgAAAH0"]
[Tue Jul 21 08:06:15.203711 2026] [security2:error] [pid 358661:tid 358759] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9SpwlWhjQfpOo60_Hf0wAARl4"]
[Tue Jul 21 08:06:15.330100 2026] [security2:error] [pid 358661:tid 358875] [client 20.104.96.117:32768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/ssixta.php"] [unique_id "al9SpwlWhjQfpOo60_Hf1gAAAFE"]
[Tue Jul 21 08:06:15.444684 2026] [security2:error] [pid 358661:tid 358778] [remote 104.207.43.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.43.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SpwlWhjQfpOo60_Hf1wAACXE"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:15.477123 2026] [security2:error] [pid 358661:tid 358863] [client 117.210.135.0:53926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpwlWhjQfpOo60_Hf2QAAAEU"]
[Tue Jul 21 08:06:15.477244 2026] [security2:error] [pid 358661:tid 358863] [client 117.210.135.0:53926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpwlWhjQfpOo60_Hf2QAAAEU"]
[Tue Jul 21 08:06:15.633938 2026] [security2:error] [pid 358661:tid 358741] [remote 82.102.18.190:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.alphafix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SpwlWhjQfpOo60_Hf3QAAVkw"]
[Tue Jul 21 08:06:15.699810 2026] [security2:error] [pid 358661:tid 358849] [client 20.104.96.117:3081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/1c.php"] [unique_id "al9SpwlWhjQfpOo60_Hf3gAAADc"]
[Tue Jul 21 08:06:15.800901 2026] [security2:error] [pid 358661:tid 358860] [client 20.226.60.151:11985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/k.php"] [unique_id "al9SpwlWhjQfpOo60_Hf5gAAAEI"]
[Tue Jul 21 08:06:15.997890 2026] [security2:error] [pid 358661:tid 358705] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9SpwlWhjQfpOo60_Hf6gAAOyg"]
[Tue Jul 21 08:06:16.008802 2026] [security2:error] [pid 358661:tid 358907] [client 20.197.192.193:52263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/ops.php"] [unique_id "al9SqAlWhjQfpOo60_Hf6wAAAHE"]
[Tue Jul 21 08:06:16.153715 2026] [security2:error] [pid 358661:tid 358726] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9SqAlWhjQfpOo60_Hf7AAAUT0"]
[Tue Jul 21 08:06:16.243731 2026] [security2:error] [pid 358661:tid 358904] [client 185.213.175.37:29994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.desconsultoria.com.br"] [uri "/.env.backup"] [unique_id "al9SqAlWhjQfpOo60_Hf7gAAAG4"]
[Tue Jul 21 08:06:16.243841 2026] [security2:error] [pid 358661:tid 358904] [client 185.213.175.37:29994] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.desconsultoria.com.br"] [uri "/.env.backup"] [unique_id "al9SqAlWhjQfpOo60_Hf7gAAAG4"]
[Tue Jul 21 08:06:16.249530 2026] [security2:error] [pid 352421:tid 352540] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SqMJSWzG9jbYOtu5Q4QAAkHY"]
[Tue Jul 21 08:06:16.249679 2026] [security2:error] [pid 352421:tid 352562] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SqMJSWzG9jbYOtu5Q4QAAkHY"]
[Tue Jul 21 08:06:16.277652 2026] [security2:error] [pid 352421:tid 352619] [client 202.143.127.214:62571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SqMJSWzG9jbYOtu5Q5AAAAMk"]
[Tue Jul 21 08:06:16.277947 2026] [security2:error] [pid 352421:tid 352619] [client 202.143.127.214:62571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SqMJSWzG9jbYOtu5Q5AAAAMk"]
[Tue Jul 21 08:06:16.310540 2026] [security2:error] [pid 358661:tid 358773] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9SqAlWhjQfpOo60_Hf7wAACWw"]
[Tue Jul 21 08:06:16.474578 2026] [security2:error] [pid 358661:tid 358676] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9SqAlWhjQfpOo60_Hf8wAAews"]
[Tue Jul 21 08:06:16.630004 2026] [security2:error] [pid 358661:tid 358675] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9SqAlWhjQfpOo60_Hf9QAAWAo"]
[Tue Jul 21 08:06:16.693169 2026] [security2:error] [pid 358661:tid 358874] [client 20.226.60.151:11989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/aaa.php"] [unique_id "al9SqAlWhjQfpOo60_Hf9wAAAFA"]
[Tue Jul 21 08:06:16.717201 2026] [security2:error] [pid 358661:tid 358774] [remote 216.26.227.55:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.227.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SqAlWhjQfpOo60_Hf9AAAGm0"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:16.785219 2026] [security2:error] [pid 358661:tid 358714] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9SqAlWhjQfpOo60_Hf-gAAGDE"]
[Tue Jul 21 08:06:16.862896 2026] [security2:error] [pid 358661:tid 358860] [client 20.104.96.117:33107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/test2.php"] [unique_id "al9SqAlWhjQfpOo60_Hf_wAAAEI"]
[Tue Jul 21 08:06:16.940908 2026] [security2:error] [pid 358661:tid 358743] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9SqAlWhjQfpOo60_HgAwAAEk4"]
[Tue Jul 21 08:06:17.113433 2026] [security2:error] [pid 358661:tid 358718] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9SqQlWhjQfpOo60_HgBAAAdzU"]
[Tue Jul 21 08:06:17.176935 2026] [security2:error] [pid 358661:tid 358814] [client 38.100.221.102:17198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SqQlWhjQfpOo60_HgBQAAABQ"]
[Tue Jul 21 08:06:17.177066 2026] [security2:error] [pid 358661:tid 358814] [client 38.100.221.102:17198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SqQlWhjQfpOo60_HgBQAAABQ"]
[Tue Jul 21 08:06:17.270596 2026] [security2:error] [pid 358661:tid 358830] [client 65.21.113.253:50558] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SqAlWhjQfpOo60_Hf_AAAACQ"]
[Tue Jul 21 08:06:17.272541 2026] [security2:error] [pid 358661:tid 358789] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9SqQlWhjQfpOo60_HgBgAAYXw"]
[Tue Jul 21 08:06:17.427864 2026] [security2:error] [pid 358661:tid 358701] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9SqQlWhjQfpOo60_HgCgAAEyQ"]
[Tue Jul 21 08:06:17.598375 2026] [security2:error] [pid 358661:tid 358720] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9SqQlWhjQfpOo60_HgDQAAWjc"]
[Tue Jul 21 08:06:17.754833 2026] [security2:error] [pid 358661:tid 358736] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9SqQlWhjQfpOo60_HgEAAAJ0c"]
[Tue Jul 21 08:06:17.914764 2026] [security2:error] [pid 358661:tid 358757] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9SqQlWhjQfpOo60_HgFgAAeFw"]
[Tue Jul 21 08:06:17.920531 2026] [security2:error] [pid 352421:tid 352511] [remote 104.207.39.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.39.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SqcJSWzG9jbYOtu5Q9wAAh1k"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:18.050401 2026] [security2:error] [pid 358661:tid 358847] [client 20.226.60.151:12017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/file5.php"] [unique_id "al9SqglWhjQfpOo60_HgGgAAADU"]
[Tue Jul 21 08:06:18.070373 2026] [security2:error] [pid 358661:tid 358692] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9SqglWhjQfpOo60_HgGwAAJBs"]
[Tue Jul 21 08:06:18.121732 2026] [security2:error] [pid 358661:tid 358824] [client 175.144.82.48:53767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SqglWhjQfpOo60_HgHAAAAB4"]
[Tue Jul 21 08:06:18.122363 2026] [security2:error] [pid 358661:tid 358824] [client 175.144.82.48:53767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SqglWhjQfpOo60_HgHAAAAB4"]
[Tue Jul 21 08:06:18.227130 2026] [security2:error] [pid 358661:tid 358691] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9SqglWhjQfpOo60_HgHgAAHBo"]
[Tue Jul 21 08:06:18.262324 2026] [security2:error] [pid 358661:tid 358836] [client 20.29.126.15:12882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/aa.php"] [unique_id "al9SqglWhjQfpOo60_HgHwAAACo"]
[Tue Jul 21 08:06:18.382690 2026] [security2:error] [pid 358661:tid 358742] [remote 82.102.18.190:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.alphafix.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9SqglWhjQfpOo60_HgIgAAbk0"]
[Tue Jul 21 08:06:18.487189 2026] [security2:error] [pid 358661:tid 358913] [client 109.60.28.94:49706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SqglWhjQfpOo60_HgKAAAAHc"]
[Tue Jul 21 08:06:18.487274 2026] [security2:error] [pid 358661:tid 358913] [client 109.60.28.94:49706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SqglWhjQfpOo60_HgKAAAAHc"]
[Tue Jul 21 08:06:18.488176 2026] [security2:error] [pid 358661:tid 358901] [client 103.166.103.129:63624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SqglWhjQfpOo60_HgKQAAAGs"]
[Tue Jul 21 08:06:18.488313 2026] [security2:error] [pid 358661:tid 358901] [client 103.166.103.129:63624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SqglWhjQfpOo60_HgKQAAAGs"]
[Tue Jul 21 08:06:18.514486 2026] [security2:error] [pid 358661:tid 358868] [client 46.105.46.43:19631] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "arielson.com.br"] [uri "/robots.txt"] [unique_id "al9SqglWhjQfpOo60_HgKgAAAEo"]
[Tue Jul 21 08:06:18.514559 2026] [security2:error] [pid 358661:tid 358868] [client 46.105.46.43:19631] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "arielson.com.br"] [uri "/robots.txt"] [unique_id "al9SqglWhjQfpOo60_HgKgAAAEo"]
[Tue Jul 21 08:06:18.930951 2026] [security2:error] [pid 352421:tid 352502] [remote 65.111.8.97:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SqsJSWzG9jbYOtu5RBQAAmlA"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:18.933030 2026] [security2:error] [pid 352421:tid 352599] [client 20.104.96.117:3129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/buy.php"] [unique_id "al9SqsJSWzG9jbYOtu5RBgAAALU"]
[Tue Jul 21 08:06:19.100214 2026] [security2:error] [pid 352421:tid 352610] [client 41.68.90.219:54453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sq8JSWzG9jbYOtu5RDAAAAMA"]
[Tue Jul 21 08:06:19.101827 2026] [security2:error] [pid 352421:tid 352610] [client 41.68.90.219:54453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sq8JSWzG9jbYOtu5RDAAAAMA"]
[Tue Jul 21 08:06:19.362550 2026] [security2:error] [pid 358661:tid 358847] [client 20.226.60.151:12019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/222.php"] [unique_id "al9SqwlWhjQfpOo60_HgMgAAADU"]
[Tue Jul 21 08:06:19.570227 2026] [security2:error] [pid 358661:tid 358891] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SqwlWhjQfpOo60_HgMwAAAGE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:20.312089 2026] [security2:error] [pid 358661:tid 358863] [client 20.226.60.151:12027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/test.php"] [unique_id "al9SrAlWhjQfpOo60_HgOgAAAEU"]
[Tue Jul 21 08:06:20.421342 2026] [security2:error] [pid 358661:tid 358761] [remote 104.207.51.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SrAlWhjQfpOo60_HgPAAAR2A"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:20.656788 2026] [security2:error] [pid 358661:tid 358779] [remote 5.252.52.249:56668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/wp-login.php"] [unique_id "al9SrAlWhjQfpOo60_HgQQAAd3I"]
[Tue Jul 21 08:06:20.669206 2026] [security2:error] [pid 358661:tid 358751] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SrAlWhjQfpOo60_HgQgAADFY"]
[Tue Jul 21 08:06:20.670608 2026] [security2:error] [pid 358661:tid 358806] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SrAlWhjQfpOo60_HgQgAADFY"]
[Tue Jul 21 08:06:20.753379 2026] [security2:error] [pid 358661:tid 358917] [client 120.56.162.40:54498] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SrAlWhjQfpOo60_HgQwAAAHs"]
[Tue Jul 21 08:06:20.753516 2026] [security2:error] [pid 358661:tid 358917] [client 120.56.162.40:54498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SrAlWhjQfpOo60_HgQwAAAHs"]
[Tue Jul 21 08:06:20.807480 2026] [security2:error] [pid 358661:tid 358838] [client 20.151.10.161:4237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.archrender.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9SrAlWhjQfpOo60_HgRQAAACw"]
[Tue Jul 21 08:06:20.968315 2026] [proxy:error] [pid 358661:tid 358887] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:20.968392 2026] [proxy_http:error] [pid 358661:tid 358887] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:20.969005 2026] [proxy:error] [pid 358661:tid 358887] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:20.969038 2026] [proxy_http:error] [pid 358661:tid 358887] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:21.086694 2026] [security2:error] [pid 352421:tid 352582] [client 20.151.10.161:4893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.archrender.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9SrcJSWzG9jbYOtu5RKQAAAKQ"]
[Tue Jul 21 08:06:21.150679 2026] [security2:error] [pid 358661:tid 358863] [client 20.197.192.193:52275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/term.php"] [unique_id "al9SrQlWhjQfpOo60_HgUQAAAEU"]
[Tue Jul 21 08:06:21.341975 2026] [security2:error] [pid 358661:tid 358865] [client 65.21.113.253:42050] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SrQlWhjQfpOo60_HgUgAAAEc"]
[Tue Jul 21 08:06:21.366008 2026] [security2:error] [pid 358661:tid 358901] [client 92.119.178.3:54940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SrQlWhjQfpOo60_HgVAAAAGs"]
[Tue Jul 21 08:06:21.366136 2026] [security2:error] [pid 358661:tid 358901] [client 92.119.178.3:54940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SrQlWhjQfpOo60_HgVAAAAGs"]
[Tue Jul 21 08:06:21.366341 2026] [security2:error] [pid 358661:tid 358813] [client 20.151.10.161:4907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.archrender.com.br"] [uri "/images.php"] [unique_id "al9SrQlWhjQfpOo60_HgUwAAABM"]
[Tue Jul 21 08:06:21.475172 2026] [security2:error] [pid 358661:tid 358671] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SrQlWhjQfpOo60_HgVQAAVgY"]
[Tue Jul 21 08:06:21.475341 2026] [security2:error] [pid 358661:tid 358880] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SrQlWhjQfpOo60_HgVQAAVgY"]
[Tue Jul 21 08:06:21.543417 2026] [security2:error] [pid 352421:tid 352470] [remote 104.207.44.122:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.44.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SrcJSWzG9jbYOtu5RLAAAuDA"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:21.591906 2026] [security2:error] [pid 352421:tid 352596] [client 20.226.60.151:12374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/aaa.php"] [unique_id "al9SrcJSWzG9jbYOtu5RLwAAALI"]
[Tue Jul 21 08:06:21.632842 2026] [security2:error] [pid 358661:tid 358834] [client 20.197.192.193:39201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9SrQlWhjQfpOo60_HgWwAAACg"]
[Tue Jul 21 08:06:21.680047 2026] [security2:error] [pid 358661:tid 358796] [client 20.151.10.161:4232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.archrender.com.br"] [uri "/for.php"] [unique_id "al9SrQlWhjQfpOo60_HgXAAAAAI"]
[Tue Jul 21 08:06:21.698033 2026] [autoindex:error] [pid 352421:tid 352588] [client 165.232.128.192:0] AH01276: Cannot serve directory /home3/denilt24/deniltoncostasilva1748033966000.0721679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:06:21.856544 2026] [security2:error] [pid 358661:tid 358882] [client 102.206.115.33:63225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SrQlWhjQfpOo60_HgXQAAAFg"]
[Tue Jul 21 08:06:21.856696 2026] [security2:error] [pid 358661:tid 358882] [client 102.206.115.33:63225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SrQlWhjQfpOo60_HgXQAAAFg"]
[Tue Jul 21 08:06:21.919231 2026] [security2:error] [pid 358661:tid 358917] [client 45.227.253.15:34138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.253.227.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "anjosolar.com.br"] [uri "/index.php/jk"] [unique_id "al9SrQlWhjQfpOo60_HgXgAAAHs"]
[Tue Jul 21 08:06:21.958485 2026] [security2:error] [pid 358661:tid 358838] [client 20.151.10.161:4881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.archrender.com.br"] [uri "/2larp.php"] [unique_id "al9SrQlWhjQfpOo60_HgXwAAACw"]
[Tue Jul 21 08:06:21.976103 2026] [security2:error] [pid 358661:tid 358818] [client 65.21.113.253:50558] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SrQlWhjQfpOo60_HgWQAAABg"]
[Tue Jul 21 08:06:22.234130 2026] [security2:error] [pid 352421:tid 352564] [client 20.151.10.161:4883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.archrender.com.br"] [uri "/adminner.php"] [unique_id "al9SrsJSWzG9jbYOtu5RPAAAAJI"]
[Tue Jul 21 08:06:22.329051 2026] [security2:error] [pid 358661:tid 358848] [client 20.104.96.117:3177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/ssend.php"] [unique_id "al9SrglWhjQfpOo60_HgYwAAADY"]
[Tue Jul 21 08:06:22.510525 2026] [security2:error] [pid 358661:tid 358891] [client 20.151.10.161:4873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.archrender.com.br"] [uri "/82.php"] [unique_id "al9SrglWhjQfpOo60_HgZAAAAGE"]
[Tue Jul 21 08:06:22.567099 2026] [security2:error] [pid 352421:tid 352632] [client 65.21.113.253:45852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SrsJSWzG9jbYOtu5RNAAAANY"]
[Tue Jul 21 08:06:22.697652 2026] [security2:error] [pid 358661:tid 358678] [remote 104.207.35.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.35.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SrglWhjQfpOo60_HgZQAAOw0"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:22.797992 2026] [security2:error] [pid 358661:tid 358882] [client 20.151.10.161:4224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.archrender.com.br"] [uri "/kir.php"] [unique_id "al9SrglWhjQfpOo60_HgeAAAAFg"]
[Tue Jul 21 08:06:23.051099 2026] [security2:error] [pid 352421:tid 352635] [client 74.7.244.22:45216] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "luanaarruda.com"] [uri "/index.php"] [unique_id "al9SrsJSWzG9jbYOtu5RPQAA2RI"]
[Tue Jul 21 08:06:23.218598 2026] [security2:error] [pid 358661:tid 358806] [client 20.226.60.151:12399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/11.php"] [unique_id "al9SrwlWhjQfpOo60_HgkQAAAAw"]
[Tue Jul 21 08:06:23.313218 2026] [security2:error] [pid 352421:tid 352451] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sr8JSWzG9jbYOtu5RZwAA2x0"]
[Tue Jul 21 08:06:23.313527 2026] [security2:error] [pid 352421:tid 352451] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sr8JSWzG9jbYOtu5RZwAA2x0"]
[Tue Jul 21 08:06:23.349933 2026] [security2:error] [pid 358661:tid 358875] [client 103.78.200.11:64283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SrwlWhjQfpOo60_HglQAAAFE"]
[Tue Jul 21 08:06:23.350173 2026] [security2:error] [pid 358661:tid 358875] [client 103.78.200.11:64283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SrwlWhjQfpOo60_HglQAAAFE"]
[Tue Jul 21 08:06:23.573051 2026] [security2:error] [pid 358661:tid 358800] [client 20.104.96.117:33112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/item.php"] [unique_id "al9SrwlWhjQfpOo60_HgmAAAAAY"]
[Tue Jul 21 08:06:23.871690 2026] [security2:error] [pid 352421:tid 352486] [remote 45.3.35.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.35.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9Sr8JSWzG9jbYOtu5RbAAAmkA"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:24.321798 2026] [security2:error] [pid 358661:tid 358872] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SsAlWhjQfpOo60_HgwQAATlc"]
[Tue Jul 21 08:06:24.373035 2026] [security2:error] [pid 352421:tid 352570] [client 87.116.180.198:14010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SsMJSWzG9jbYOtu5RdQAAAJg"]
[Tue Jul 21 08:06:24.374890 2026] [security2:error] [pid 352421:tid 352570] [client 87.116.180.198:14010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SsMJSWzG9jbYOtu5RdQAAAJg"]
[Tue Jul 21 08:06:24.429006 2026] [security2:error] [pid 358661:tid 358854] [client 103.29.114.44:29853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SsAlWhjQfpOo60_HgxwAAADw"]
[Tue Jul 21 08:06:24.429161 2026] [security2:error] [pid 358661:tid 358854] [client 103.29.114.44:29853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SsAlWhjQfpOo60_HgxwAAADw"]
[Tue Jul 21 08:06:24.432058 2026] [security2:error] [pid 358661:tid 358749] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SsAlWhjQfpOo60_HgyAAAO1Q"]
[Tue Jul 21 08:06:24.432260 2026] [security2:error] [pid 358661:tid 358853] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SsAlWhjQfpOo60_HgyAAAO1Q"]
[Tue Jul 21 08:06:24.679960 2026] [security2:error] [pid 352421:tid 352524] [remote 104.207.35.183:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.35.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SsMJSWzG9jbYOtu5RgQAAzmY"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:24.837647 2026] [security2:error] [pid 352421:tid 352629] [client 74.7.228.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "brasilmotoeletrica.com"] [uri "/index.php"] [unique_id "al9SsMJSWzG9jbYOtu5RggAAANM"]
[Tue Jul 21 08:06:24.837711 2026] [security2:error] [pid 352421:tid 352557] [client 74.7.228.62:44814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "brasilmotoeletrica.com"] [uri "/robots.txt"] [unique_id "al9SsMJSWzG9jbYOtu5RewAAi3E"]
[Tue Jul 21 08:06:24.838170 2026] [security2:error] [pid 352421:tid 352601] [client 20.226.60.151:12370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/mac.php"] [unique_id "al9SsMJSWzG9jbYOtu5RiAAAALc"]
[Tue Jul 21 08:06:25.005956 2026] [security2:error] [pid 358661:tid 358818] [client 178.153.91.96:62248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SsQlWhjQfpOo60_Hg0wAAABg"]
[Tue Jul 21 08:06:25.006097 2026] [security2:error] [pid 358661:tid 358818] [client 178.153.91.96:62248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SsQlWhjQfpOo60_Hg0wAAABg"]
[Tue Jul 21 08:06:25.139773 2026] [proxy:error] [pid 352421:tid 352648] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:25.139851 2026] [proxy_http:error] [pid 352421:tid 352648] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:25.140302 2026] [proxy:error] [pid 352421:tid 352648] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:25.140330 2026] [proxy_http:error] [pid 352421:tid 352648] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:25.520462 2026] [security2:error] [pid 352421:tid 352553] [client 20.104.96.117:3089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/ss.php"] [unique_id "al9SscJSWzG9jbYOtu5RlgAAAIc"]
[Tue Jul 21 08:06:25.547698 2026] [security2:error] [pid 352421:tid 352521] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SscJSWzG9jbYOtu5RlwAAumM"]
[Tue Jul 21 08:06:25.547900 2026] [security2:error] [pid 352421:tid 352604] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SscJSWzG9jbYOtu5RlwAAumM"]
[Tue Jul 21 08:06:25.604959 2026] [security2:error] [pid 358661:tid 358832] [client 117.247.80.59:12549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SsQlWhjQfpOo60_Hg4AAAACY"]
[Tue Jul 21 08:06:25.605127 2026] [security2:error] [pid 358661:tid 358832] [client 117.247.80.59:12549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SsQlWhjQfpOo60_Hg4AAAACY"]
[Tue Jul 21 08:06:25.836091 2026] [security2:error] [pid 358661:tid 358848] [client 65.21.113.253:42050] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SsQlWhjQfpOo60_Hg5QAAADY"]
[Tue Jul 21 08:06:25.995226 2026] [security2:error] [pid 352421:tid 352663] [client 117.210.135.0:54575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SscJSWzG9jbYOtu5RnQAAAPU"]
[Tue Jul 21 08:06:25.995357 2026] [security2:error] [pid 352421:tid 352663] [client 117.210.135.0:54575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SscJSWzG9jbYOtu5RnQAAAPU"]
[Tue Jul 21 08:06:26.143040 2026] [security2:error] [pid 358661:tid 358684] [remote 65.111.31.35:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.31.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SsglWhjQfpOo60_Hg5wAAURM"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:26.241853 2026] [security2:error] [pid 352421:tid 352581] [client 20.226.60.151:12148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/chosen.php"] [unique_id "al9SssJSWzG9jbYOtu5RpgAAAKM"]
[Tue Jul 21 08:06:26.278699 2026] [proxy:error] [pid 352421:tid 352551] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:26.278800 2026] [proxy_http:error] [pid 352421:tid 352551] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:26.280961 2026] [proxy:error] [pid 352421:tid 352551] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:26.281048 2026] [proxy_http:error] [pid 352421:tid 352551] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:26.430653 2026] [security2:error] [pid 352421:tid 352603] [client 65.21.113.253:45852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SscJSWzG9jbYOtu5RnAAAALk"]
[Tue Jul 21 08:06:26.913235 2026] [security2:error] [pid 358661:tid 358843] [client 65.21.113.253:45864] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SsglWhjQfpOo60_Hg6gAAADE"]
[Tue Jul 21 08:06:27.021257 2026] [security2:error] [pid 352421:tid 352653] [client 20.197.192.193:52245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/ah25.php"] [unique_id "al9Ss8JSWzG9jbYOtu5RsgAAAOs"]
[Tue Jul 21 08:06:27.134010 2026] [security2:error] [pid 358661:tid 358849] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SsglWhjQfpOo60_Hg8AAAADc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:27.207965 2026] [security2:error] [pid 358661:tid 358855] [client 20.226.60.151:12387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/cream1.php"] [unique_id "al9SswlWhjQfpOo60_Hg9QAAAD0"]
[Tue Jul 21 08:06:27.238670 2026] [security2:error] [pid 358661:tid 358762] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SswlWhjQfpOo60_Hg9gAAWGE"]
[Tue Jul 21 08:06:27.238865 2026] [security2:error] [pid 358661:tid 358882] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SswlWhjQfpOo60_Hg9gAAWGE"]
[Tue Jul 21 08:06:27.364546 2026] [security2:error] [pid 358661:tid 358821] [client 202.143.127.214:63075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SswlWhjQfpOo60_Hg_AAAABs"]
[Tue Jul 21 08:06:27.364779 2026] [security2:error] [pid 358661:tid 358821] [client 202.143.127.214:63075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SswlWhjQfpOo60_Hg_AAAABs"]
[Tue Jul 21 08:06:27.554072 2026] [security2:error] [pid 358661:tid 358832] [client 20.29.126.15:2728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/bolt.php"] [unique_id "al9SswlWhjQfpOo60_Hg_QAAACY"]
[Tue Jul 21 08:06:27.626745 2026] [security2:error] [pid 358661:tid 358818] [client 175.144.82.48:54308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SswlWhjQfpOo60_Hg_wAAABg"]
[Tue Jul 21 08:06:27.628852 2026] [security2:error] [pid 358661:tid 358818] [client 175.144.82.48:54308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SswlWhjQfpOo60_Hg_wAAABg"]
[Tue Jul 21 08:06:27.634129 2026] [security2:error] [pid 358661:tid 358868] [client 38.100.221.102:17602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SswlWhjQfpOo60_HhAAAAAEo"]
[Tue Jul 21 08:06:27.634486 2026] [security2:error] [pid 358661:tid 358868] [client 38.100.221.102:17602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SswlWhjQfpOo60_HhAAAAAEo"]
[Tue Jul 21 08:06:28.179819 2026] [security2:error] [pid 352421:tid 352581] [client 20.197.192.193:3506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9StMJSWzG9jbYOtu5RwAAAAKM"]
[Tue Jul 21 08:06:28.681869 2026] [security2:error] [pid 358661:tid 358813] [client 92.119.178.3:41636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9StAlWhjQfpOo60_HhDQAAABM"]
[Tue Jul 21 08:06:28.681949 2026] [security2:error] [pid 358661:tid 358813] [client 92.119.178.3:41636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9StAlWhjQfpOo60_HhDQAAABM"]
[Tue Jul 21 08:06:28.698129 2026] [proxy:error] [pid 358661:tid 358915] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:28.698205 2026] [proxy_http:error] [pid 358661:tid 358915] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:28.698784 2026] [proxy:error] [pid 358661:tid 358915] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:28.698821 2026] [proxy_http:error] [pid 358661:tid 358915] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:29.156425 2026] [security2:error] [pid 352421:tid 352577] [client 103.166.103.129:64162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9StcJSWzG9jbYOtu5R0QAAAJ8"]
[Tue Jul 21 08:06:29.156583 2026] [security2:error] [pid 352421:tid 352577] [client 103.166.103.129:64162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9StcJSWzG9jbYOtu5R0QAAAJ8"]
[Tue Jul 21 08:06:29.158091 2026] [security2:error] [pid 358661:tid 358832] [client 20.197.192.193:3510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/dr.php"] [unique_id "al9StQlWhjQfpOo60_HhFgAAACY"]
[Tue Jul 21 08:06:29.260159 2026] [security2:error] [pid 358661:tid 358806] [client 109.60.28.94:8851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9StQlWhjQfpOo60_HhGAAAAAw"]
[Tue Jul 21 08:06:29.260831 2026] [security2:error] [pid 358661:tid 358806] [client 109.60.28.94:8851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9StQlWhjQfpOo60_HhGAAAAAw"]
[Tue Jul 21 08:06:29.381628 2026] [security2:error] [pid 358661:tid 358838] [client 20.104.96.117:3155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/hypo.php"] [unique_id "al9StQlWhjQfpOo60_HhHAAAACw"]
[Tue Jul 21 08:06:29.384896 2026] [security2:error] [pid 358661:tid 358826] [client 173.252.95.24:50818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9StQlWhjQfpOo60_HhHQAAACA"]
[Tue Jul 21 08:06:29.443466 2026] [security2:error] [pid 358661:tid 358830] [client 20.226.60.151:12023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/dr.php"] [unique_id "al9StQlWhjQfpOo60_HhIgAAACQ"]
[Tue Jul 21 08:06:29.543303 2026] [security2:error] [pid 358661:tid 358884] [client 65.21.113.253:42050] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9StQlWhjQfpOo60_HhIwAAAFo"]
[Tue Jul 21 08:06:29.603531 2026] [security2:error] [pid 352421:tid 352658] [client 65.21.113.253:45852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9StcJSWzG9jbYOtu5R0AAAAPA"]
[Tue Jul 21 08:06:29.611760 2026] [security2:error] [pid 358661:tid 358798] [client 41.68.90.219:54915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9StQlWhjQfpOo60_HhJwAAAAQ"]
[Tue Jul 21 08:06:29.612741 2026] [security2:error] [pid 358661:tid 358798] [client 41.68.90.219:54915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9StQlWhjQfpOo60_HhJwAAAAQ"]
[Tue Jul 21 08:06:29.891121 2026] [security2:error] [pid 352421:tid 352489] [remote 45.3.43.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.43.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9StMJSWzG9jbYOtu5RyAAAyUM"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:30.239148 2026] [security2:error] [pid 358661:tid 358807] [client 20.226.60.151:12016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/x.php"] [unique_id "al9StglWhjQfpOo60_HhYgAAAA0"]
[Tue Jul 21 08:06:30.666401 2026] [security2:error] [pid 358661:tid 358849] [client 65.21.113.253:39334] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9StglWhjQfpOo60_HhYQAAADc"]
[Tue Jul 21 08:06:30.677270 2026] [security2:error] [pid 358661:tid 358695] [remote 72.167.132.114:34172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "trconsultcontabilidade.com"] [uri "/wp-login.php"] [unique_id "al9StglWhjQfpOo60_HhZQAAJR4"]
[Tue Jul 21 08:06:30.783552 2026] [security2:error] [pid 358661:tid 358838] [client 20.104.96.117:32807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/users.php"] [unique_id "al9StglWhjQfpOo60_HhaQAAACw"]
[Tue Jul 21 08:06:31.104586 2026] [security2:error] [pid 358661:tid 358779] [remote 216.26.251.158:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.251.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9StglWhjQfpOo60_HhawAAIHI"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:31.297566 2026] [security2:error] [pid 358661:tid 358682] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9StwlWhjQfpOo60_HhbgAAKxE"]
[Tue Jul 21 08:06:31.297788 2026] [security2:error] [pid 358661:tid 358837] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9StwlWhjQfpOo60_HhbgAAKxE"]
[Tue Jul 21 08:06:31.397424 2026] [security2:error] [pid 352421:tid 352606] [client 120.56.162.40:54970] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9St8JSWzG9jbYOtu5R9QAAALw"]
[Tue Jul 21 08:06:31.397612 2026] [security2:error] [pid 352421:tid 352606] [client 120.56.162.40:54970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9St8JSWzG9jbYOtu5R9QAAALw"]
[Tue Jul 21 08:06:31.454032 2026] [security2:error] [pid 358661:tid 358808] [client 34.182.139.74:51736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "locadoracmd.com.br"] [uri "/xmlrpc.php"] [unique_id "al9StAlWhjQfpOo60_HhDwAAAA4"]
[Tue Jul 21 08:06:32.007061 2026] [security2:error] [pid 352421:tid 352525] [remote 69.63.184.112:59876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.184.63.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9St8JSWzG9jbYOtu5R_wAAi2c"]
[Tue Jul 21 08:06:32.063146 2026] [security2:error] [pid 352421:tid 352649] [client 20.226.60.151:12353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/155.php"] [unique_id "al9SuMJSWzG9jbYOtu5SBQAAAOc"]
[Tue Jul 21 08:06:32.193484 2026] [security2:error] [pid 352421:tid 352446] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SuMJSWzG9jbYOtu5SCwAA0hg"]
[Tue Jul 21 08:06:32.193671 2026] [security2:error] [pid 352421:tid 352628] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SuMJSWzG9jbYOtu5SCwAA0hg"]
[Tue Jul 21 08:06:32.252807 2026] [security2:error] [pid 352421:tid 352623] [client 20.104.96.117:3112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/177.php"] [unique_id "al9SuMJSWzG9jbYOtu5SDAAAAM0"]
[Tue Jul 21 08:06:32.297162 2026] [security2:error] [pid 358661:tid 358747] [remote 209.50.188.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.188.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SuAlWhjQfpOo60_HhfwAAGFI"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:32.346199 2026] [autoindex:error] [pid 352421:tid 352560] [client 167.86.66.204:0] AH01276: Cannot serve directory /home2/anap6468/santaofertas.com.br/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Tue Jul 21 08:06:32.354799 2026] [security2:error] [pid 352421:tid 352616] [client 65.21.113.253:45852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9St8JSWzG9jbYOtu5R_gAAAMY"]
[Tue Jul 21 08:06:32.392794 2026] [security2:error] [pid 358661:tid 358834] [client 102.206.115.33:58110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SuAlWhjQfpOo60_HhlQAAACg"]
[Tue Jul 21 08:06:32.392978 2026] [security2:error] [pid 358661:tid 358834] [client 102.206.115.33:58110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SuAlWhjQfpOo60_HhlQAAACg"]
[Tue Jul 21 08:06:32.543397 2026] [security2:error] [pid 352421:tid 352584] [client 204.8.98.45:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9SuMJSWzG9jbYOtu5SEAAAAKY"]
[Tue Jul 21 08:06:32.543503 2026] [security2:error] [pid 352421:tid 352584] [client 204.8.98.45:58440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9SuMJSWzG9jbYOtu5SEAAAAKY"]
[Tue Jul 21 08:06:32.807375 2026] [security2:error] [pid 352421:tid 352455] [remote 154.61.75.100:38976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-login.php"] [unique_id "al9SuMJSWzG9jbYOtu5SEwAA2SE"]
[Tue Jul 21 08:06:32.879131 2026] [security2:error] [pid 358661:tid 358831] [client 20.104.96.117:3074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/config.php"] [unique_id "al9SuAlWhjQfpOo60_HhnQAAACU"]
[Tue Jul 21 08:06:32.987542 2026] [security2:error] [pid 358661:tid 358838] [client 204.8.98.45:58454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9SuAlWhjQfpOo60_HhngAAACw"]
[Tue Jul 21 08:06:32.987653 2026] [security2:error] [pid 358661:tid 358838] [client 204.8.98.45:58454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9SuAlWhjQfpOo60_HhngAAACw"]
[Tue Jul 21 08:06:33.420062 2026] [security2:error] [pid 352421:tid 352569] [client 20.104.96.117:33129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/gettest.php"] [unique_id "al9SucJSWzG9jbYOtu5SGgAAAJc"]
[Tue Jul 21 08:06:33.828278 2026] [security2:error] [pid 352421:tid 352522] [remote 104.207.57.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SucJSWzG9jbYOtu5SHwAA1mQ"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:33.865420 2026] [security2:error] [pid 358661:tid 358808] [client 20.104.96.117:33127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/min.php"] [unique_id "al9SuQlWhjQfpOo60_HhpQAAAA4"]
[Tue Jul 21 08:06:33.870239 2026] [security2:error] [pid 352421:tid 352571] [client 34.182.139.74:60788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "locadoracmd.com.br"] [uri "/xmlrpc.php"] [unique_id "al9St8JSWzG9jbYOtu5R_QAAAJk"]
[Tue Jul 21 08:06:34.068249 2026] [security2:error] [pid 358661:tid 358913] [client 180.153.236.96:61903] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nataliareisugc.online"] [uri "/"] [unique_id "al9SuglWhjQfpOo60_HhpwAAAHc"], referer: http://nataliareisugc.online/
[Tue Jul 21 08:06:34.068385 2026] [security2:error] [pid 358661:tid 358913] [client 180.153.236.96:61903] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "nataliareisugc.online"] [uri "/"] [unique_id "al9SuglWhjQfpOo60_HhpwAAAHc"], referer: http://nataliareisugc.online/
[Tue Jul 21 08:06:34.081270 2026] [security2:error] [pid 352421:tid 352440] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SusJSWzG9jbYOtu5SJQAAoxI"]
[Tue Jul 21 08:06:34.081416 2026] [security2:error] [pid 352421:tid 352581] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SusJSWzG9jbYOtu5SJQAAoxI"]
[Tue Jul 21 08:06:34.164046 2026] [security2:error] [pid 358661:tid 358888] [client 103.78.200.11:64776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SuglWhjQfpOo60_HhqgAAAF4"]
[Tue Jul 21 08:06:34.164158 2026] [security2:error] [pid 358661:tid 358888] [client 103.78.200.11:64776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SuglWhjQfpOo60_HhqgAAAF4"]
[Tue Jul 21 08:06:34.230796 2026] [security2:error] [pid 358661:tid 358852] [client 20.104.96.117:3188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/dvjul.php"] [unique_id "al9SuglWhjQfpOo60_HhqwAAADo"]
[Tue Jul 21 08:06:34.601512 2026] [security2:error] [pid 358661:tid 358704] [remote 192.241.143.148:36328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9SuglWhjQfpOo60_HhrAAAfCc"]
[Tue Jul 21 08:06:34.625210 2026] [security2:error] [pid 352421:tid 352606] [client 20.104.96.117:3185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/biufile.php"] [unique_id "al9SusJSWzG9jbYOtu5SKwAAALw"]
[Tue Jul 21 08:06:34.849106 2026] [security2:error] [pid 358661:tid 358807] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SuglWhjQfpOo60_HhrgAAAA0"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:34.909778 2026] [security2:error] [pid 352421:tid 352480] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SusJSWzG9jbYOtu5SMQAAnDo"]
[Tue Jul 21 08:06:34.909911 2026] [security2:error] [pid 352421:tid 352574] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SusJSWzG9jbYOtu5SMQAAnDo"]
[Tue Jul 21 08:06:35.058283 2026] [security2:error] [pid 352421:tid 352621] [client 103.29.114.44:46014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Su8JSWzG9jbYOtu5SNAAAAMs"]
[Tue Jul 21 08:06:35.058414 2026] [security2:error] [pid 352421:tid 352621] [client 103.29.114.44:46014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Su8JSWzG9jbYOtu5SNAAAAMs"]
[Tue Jul 21 08:06:35.094884 2026] [security2:error] [pid 358661:tid 358798] [client 87.116.180.198:14068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SuwlWhjQfpOo60_HhsgAAAAQ"]
[Tue Jul 21 08:06:35.096038 2026] [security2:error] [pid 358661:tid 358798] [client 87.116.180.198:14068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SuwlWhjQfpOo60_HhsgAAAAQ"]
[Tue Jul 21 08:06:35.264189 2026] [security2:error] [pid 352421:tid 352603] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Su8JSWzG9jbYOtu5SNwAAuR0"]
[Tue Jul 21 08:06:35.352131 2026] [security2:error] [pid 358661:tid 358710] [remote 65.111.29.250:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.29.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SuwlWhjQfpOo60_HhuQAAcC0"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:35.418270 2026] [security2:error] [pid 358661:tid 358849] [client 20.104.96.117:3095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/av.php"] [unique_id "al9SuwlWhjQfpOo60_HhugAAADc"]
[Tue Jul 21 08:06:35.432312 2026] [security2:error] [pid 358661:tid 358871] [client 178.153.91.96:62866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SuwlWhjQfpOo60_HhuwAAAE0"]
[Tue Jul 21 08:06:35.432432 2026] [security2:error] [pid 358661:tid 358871] [client 178.153.91.96:62866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SuwlWhjQfpOo60_HhuwAAAE0"]
[Tue Jul 21 08:06:35.541819 2026] [security2:error] [pid 358661:tid 358803] [client 20.226.60.151:12014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/ops.php"] [unique_id "al9SuwlWhjQfpOo60_HhvwAAAAk"]
[Tue Jul 21 08:06:35.793541 2026] [security2:error] [pid 352421:tid 352649] [client 65.21.113.253:45852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Su8JSWzG9jbYOtu5SOQAAAOc"]
[Tue Jul 21 08:06:35.793896 2026] [security2:error] [pid 352421:tid 352540] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.env.bak"] [unique_id "al9Su8JSWzG9jbYOtu5SSwAAyXY"]
[Tue Jul 21 08:06:35.794059 2026] [security2:error] [pid 352421:tid 352619] [client 34.146.29.21:51310] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/.env.bak"] [unique_id "al9Su8JSWzG9jbYOtu5SSwAAyXY"]
[Tue Jul 21 08:06:35.797195 2026] [security2:error] [pid 352421:tid 352425] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/z9x8c7v6b5-debug-trigger-principiamatematica.com"] [unique_id "al9Su8JSWzG9jbYOtu5STAAAyQM"]
[Tue Jul 21 08:06:35.804774 2026] [security2:error] [pid 352421:tid 352503] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/.env.backup"] [unique_id "al9Su8JSWzG9jbYOtu5STgAAyVE"]
[Tue Jul 21 08:06:36.019651 2026] [security2:error] [pid 358661:tid 358730] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvAlWhjQfpOo60_HhygAAeEE"]
[Tue Jul 21 08:06:36.019892 2026] [security2:error] [pid 358661:tid 358914] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvAlWhjQfpOo60_HhygAAeEE"]
[Tue Jul 21 08:06:36.045019 2026] [security2:error] [pid 352421:tid 352430] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/.env.old"] [unique_id "al9SvMJSWzG9jbYOtu5SUwAAyQg"]
[Tue Jul 21 08:06:36.065519 2026] [security2:error] [pid 352421:tid 352514] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "principiamatematica.com"] [uri "/graphql"] [unique_id "al9SvMJSWzG9jbYOtu5SVQAAyVw"]
[Tue Jul 21 08:06:36.089555 2026] [security2:error] [pid 352421:tid 352569] [client 20.104.96.117:3194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/coffexium.php"] [unique_id "al9SvMJSWzG9jbYOtu5SVwAAAJc"]
[Tue Jul 21 08:06:36.180179 2026] [security2:error] [pid 352421:tid 352549] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/api/.env"] [unique_id "al9SvMJSWzG9jbYOtu5SXQAAyX8"]
[Tue Jul 21 08:06:36.325970 2026] [security2:error] [pid 352421:tid 352523] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "principiamatematica.com"] [uri "/api/graphql"] [unique_id "al9SvMJSWzG9jbYOtu5SXwAAyWU"]
[Tue Jul 21 08:06:36.349236 2026] [security2:error] [pid 358661:tid 358795] [client 117.247.80.59:14806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvAlWhjQfpOo60_Hh1AAAAAE"]
[Tue Jul 21 08:06:36.349517 2026] [security2:error] [pid 358661:tid 358795] [client 117.247.80.59:14806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvAlWhjQfpOo60_Hh1AAAAAE"]
[Tue Jul 21 08:06:36.433496 2026] [security2:error] [pid 352421:tid 352572] [client 34.182.139.74:60221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "locadoracmd.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SusJSWzG9jbYOtu5SJwAAAJo"]
[Tue Jul 21 08:06:36.521711 2026] [security2:error] [pid 358661:tid 358863] [client 117.210.135.0:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvAlWhjQfpOo60_Hh2gAAAEU"]
[Tue Jul 21 08:06:36.521935 2026] [security2:error] [pid 358661:tid 358863] [client 117.210.135.0:55224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvAlWhjQfpOo60_Hh2gAAAEU"]
[Tue Jul 21 08:06:36.583653 2026] [security2:error] [pid 352421:tid 352548] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "principiamatematica.com"] [uri "/v1/graphql"] [unique_id "al9SvMJSWzG9jbYOtu5SYwAAyX4"]
[Tue Jul 21 08:06:36.677714 2026] [security2:error] [pid 352421:tid 352513] [remote 216.26.233.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.233.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SvMJSWzG9jbYOtu5SYgAAzls"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:36.854061 2026] [security2:error] [pid 358661:tid 358814] [client 198.54.128.138:54458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9SvAlWhjQfpOo60_Hh5gAAABQ"]
[Tue Jul 21 08:06:36.854155 2026] [security2:error] [pid 358661:tid 358814] [client 198.54.128.138:54458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9SvAlWhjQfpOo60_Hh5gAAABQ"]
[Tue Jul 21 08:06:36.894147 2026] [security2:error] [pid 358661:tid 358917] [client 20.104.96.117:3167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/core.php"] [unique_id "al9SvAlWhjQfpOo60_Hh6AAAAHs"]
[Tue Jul 21 08:06:37.245831 2026] [security2:error] [pid 358661:tid 358819] [client 104.28.211.189:29206] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-content/plugins/burst-statistics/readme.txt"] [unique_id "al9SvQlWhjQfpOo60_Hh8AAAABk"]
[Tue Jul 21 08:06:37.603586 2026] [security2:error] [pid 352421:tid 352644] [client 20.104.96.117:33144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/als.php"] [unique_id "al9SvcJSWzG9jbYOtu5SbwAAAOI"]
[Tue Jul 21 08:06:37.676254 2026] [security2:error] [pid 358661:tid 358853] [client 20.197.192.193:51925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/8.php"] [unique_id "al9SvQlWhjQfpOo60_Hh9AAAADs"]
[Tue Jul 21 08:06:37.790086 2026] [security2:error] [pid 352421:tid 352670] [client 104.28.211.189:29213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.211.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-content/plugins/burst-statistics/burst-statistics.php"] [unique_id "al9SvcJSWzG9jbYOtu5ScwAAAPw"]
[Tue Jul 21 08:06:38.165565 2026] [security2:error] [pid 358661:tid 358875] [client 65.21.113.253:37788] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SvglWhjQfpOo60_Hh9gAAAFE"]
[Tue Jul 21 08:06:38.199218 2026] [security2:error] [pid 358661:tid 358795] [client 38.100.221.102:17331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvglWhjQfpOo60_Hh-AAAAAE"]
[Tue Jul 21 08:06:38.199342 2026] [security2:error] [pid 358661:tid 358795] [client 38.100.221.102:17331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvglWhjQfpOo60_Hh-AAAAAE"]
[Tue Jul 21 08:06:38.260005 2026] [security2:error] [pid 358661:tid 358717] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvglWhjQfpOo60_Hh-gAAcDQ"]
[Tue Jul 21 08:06:38.260277 2026] [security2:error] [pid 358661:tid 358906] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvglWhjQfpOo60_Hh-gAAcDQ"]
[Tue Jul 21 08:06:38.445539 2026] [security2:error] [pid 352421:tid 352658] [client 20.226.60.151:12030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/file31.php"] [unique_id "al9SvsJSWzG9jbYOtu5SgQAAAPA"]
[Tue Jul 21 08:06:38.469108 2026] [security2:error] [pid 358661:tid 358826] [client 20.104.96.117:33143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/simple.php"] [unique_id "al9SvglWhjQfpOo60_Hh_wAAACA"]
[Tue Jul 21 08:06:38.484437 2026] [security2:error] [pid 358661:tid 358850] [client 175.144.82.48:54753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvglWhjQfpOo60_HiAAAAADg"]
[Tue Jul 21 08:06:38.485318 2026] [security2:error] [pid 358661:tid 358850] [client 175.144.82.48:54753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvglWhjQfpOo60_HiAAAAADg"]
[Tue Jul 21 08:06:38.507467 2026] [autoindex:error] [pid 352421:tid 352585] [client 205.210.31.206:58500] AH01276: Cannot serve directory /home2/supr7264/monalizacleaning.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:06:38.553047 2026] [security2:error] [pid 358661:tid 358904] [client 202.143.127.214:63561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvglWhjQfpOo60_HiAgAAAG4"]
[Tue Jul 21 08:06:38.553258 2026] [security2:error] [pid 358661:tid 358904] [client 202.143.127.214:63561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvglWhjQfpOo60_HiAgAAAG4"]
[Tue Jul 21 08:06:38.689734 2026] [security2:error] [pid 352421:tid 352462] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.env"] [unique_id "al9SvsJSWzG9jbYOtu5ShQAAoig"]
[Tue Jul 21 08:06:38.834020 2026] [security2:error] [pid 352421:tid 352598] [client 65.21.113.253:45852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SvsJSWzG9jbYOtu5SfgAAALQ"]
[Tue Jul 21 08:06:38.857288 2026] [security2:error] [pid 358661:tid 358743] [remote 65.111.2.250:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.2.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SvQlWhjQfpOo60_Hh9QAAYk4"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:38.928651 2026] [security2:error] [pid 358661:tid 358843] [client 34.182.139.74:60841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "locadoracmd.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvAlWhjQfpOo60_Hh5QAAADE"]
[Tue Jul 21 08:06:38.949535 2026] [security2:error] [pid 352421:tid 352457] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/.ssh/id_rsa"] [unique_id "al9SvsJSWzG9jbYOtu5SjAAA8yM"]
[Tue Jul 21 08:06:39.029119 2026] [security2:error] [pid 352421:tid 352597] [client 20.104.96.117:33149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/init.php"] [unique_id "al9Sv8JSWzG9jbYOtu5SjwAAALM"]
[Tue Jul 21 08:06:39.192749 2026] [security2:error] [pid 352421:tid 352479] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/backend/.env"] [unique_id "al9Sv8JSWzG9jbYOtu5SlgAA0Tk"]
[Tue Jul 21 08:06:39.203978 2026] [security2:error] [pid 352421:tid 352547] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/.env.local"] [unique_id "al9Sv8JSWzG9jbYOtu5SmwAA0X0"]
[Tue Jul 21 08:06:39.435113 2026] [security2:error] [pid 352421:tid 352507] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.htpasswd"] [unique_id "al9Sv8JSWzG9jbYOtu5SpAAApVU"]
[Tue Jul 21 08:06:39.435263 2026] [security2:error] [pid 352421:tid 352583] [client 34.146.29.21:51310] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/.htpasswd"] [unique_id "al9Sv8JSWzG9jbYOtu5SpAAApVU"]
[Tue Jul 21 08:06:39.454342 2026] [security2:error] [pid 358661:tid 358854] [client 20.104.96.117:33114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/fpwch.php"] [unique_id "al9SvwlWhjQfpOo60_HiFQAAADw"]
[Tue Jul 21 08:06:39.489660 2026] [security2:error] [pid 352421:tid 352488] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.hermes/config.yaml"] [unique_id "al9Sv8JSWzG9jbYOtu5SqgAAhkI"]
[Tue Jul 21 08:06:39.489872 2026] [security2:error] [pid 352421:tid 352552] [client 34.146.29.21:51310] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/.hermes/config.yaml"] [unique_id "al9Sv8JSWzG9jbYOtu5SqgAAhkI"]
[Tue Jul 21 08:06:39.671641 2026] [security2:error] [pid 358661:tid 358798] [client 61.1.167.83:53683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvwlWhjQfpOo60_HiGAAAAAQ"]
[Tue Jul 21 08:06:39.671784 2026] [security2:error] [pid 358661:tid 358798] [client 61.1.167.83:53683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SvwlWhjQfpOo60_HiGAAAAAQ"]
[Tue Jul 21 08:06:39.703267 2026] [security2:error] [pid 352421:tid 352446] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/config/.env"] [unique_id "al9Sv8JSWzG9jbYOtu5SsAAAvxg"]
[Tue Jul 21 08:06:39.819673 2026] [security2:error] [pid 352421:tid 352428] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/terraform.tfstate"] [unique_id "al9Sv8JSWzG9jbYOtu5StgAA_wY"]
[Tue Jul 21 08:06:39.849195 2026] [security2:error] [pid 352421:tid 352519] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/.ssh/id_dsa"] [unique_id "al9Sv8JSWzG9jbYOtu5SvAAA_2E"]
[Tue Jul 21 08:06:39.864668 2026] [security2:error] [pid 358661:tid 358906] [client 20.104.96.117:20813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/domvf.php"] [unique_id "al9SvwlWhjQfpOo60_HiGgAAAHA"]
[Tue Jul 21 08:06:39.869187 2026] [security2:error] [pid 358661:tid 358838] [client 20.29.126.15:7421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/x.php"] [unique_id "al9SvwlWhjQfpOo60_HiGwAAACw"]
[Tue Jul 21 08:06:39.918314 2026] [security2:error] [pid 352421:tid 352663] [client 65.21.113.253:44272] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Sv8JSWzG9jbYOtu5SogAAAPU"]
[Tue Jul 21 08:06:40.058071 2026] [security2:error] [pid 358661:tid 358909] [client 109.60.28.94:50602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SwAlWhjQfpOo60_HiHgAAAHM"]
[Tue Jul 21 08:06:40.058807 2026] [security2:error] [pid 358661:tid 358909] [client 109.60.28.94:50602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SwAlWhjQfpOo60_HiHgAAAHM"]
[Tue Jul 21 08:06:40.074207 2026] [security2:error] [pid 352421:tid 352458] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.ssh/authorized_keys"] [unique_id "al9SwMJSWzG9jbYOtu5SwQAA1CQ"]
[Tue Jul 21 08:06:40.074356 2026] [security2:error] [pid 352421:tid 352630] [client 34.146.29.21:51310] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/.ssh/authorized_keys"] [unique_id "al9SwMJSWzG9jbYOtu5SwQAA1CQ"]
[Tue Jul 21 08:06:40.160652 2026] [security2:error] [pid 352421:tid 352634] [client 41.68.90.219:55393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SwMJSWzG9jbYOtu5SxAAAANg"]
[Tue Jul 21 08:06:40.162176 2026] [security2:error] [pid 352421:tid 352634] [client 41.68.90.219:55393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SwMJSWzG9jbYOtu5SxAAAANg"]
[Tue Jul 21 08:06:40.175513 2026] [security2:error] [pid 352421:tid 352474] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/api/graphql"] [unique_id "al9SwMJSWzG9jbYOtu5SxgAA1DQ"]
[Tue Jul 21 08:06:40.186987 2026] [security2:error] [pid 352421:tid 352440] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/privatekey.key"] [unique_id "al9SwMJSWzG9jbYOtu5SyAAA1BI"]
[Tue Jul 21 08:06:40.216303 2026] [security2:error] [pid 352421:tid 352426] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/.hermes/.env"] [unique_id "al9SwMJSWzG9jbYOtu5SywAA1AQ"]
[Tue Jul 21 08:06:40.335986 2026] [security2:error] [pid 352421:tid 352516] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/host.key"] [unique_id "al9SwMJSWzG9jbYOtu5S0gAA1F4"]
[Tue Jul 21 08:06:40.336271 2026] [security2:error] [pid 352421:tid 352630] [client 34.146.29.21:51310] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/host.key"] [unique_id "al9SwMJSWzG9jbYOtu5S0gAA1F4"]
[Tue Jul 21 08:06:40.346009 2026] [security2:error] [pid 352421:tid 352476] [remote 65.111.24.141:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SwMJSWzG9jbYOtu5S0wAA-zY"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:40.366906 2026] [security2:error] [pid 352421:tid 352644] [client 103.166.103.129:64698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SwMJSWzG9jbYOtu5S1QAAAOI"]
[Tue Jul 21 08:06:40.369038 2026] [security2:error] [pid 352421:tid 352644] [client 103.166.103.129:64698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SwMJSWzG9jbYOtu5S1QAAAOI"]
[Tue Jul 21 08:06:40.380046 2026] [security2:error] [pid 352421:tid 352584] [client 20.104.96.117:3072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/wp.php"] [unique_id "al9SwMJSWzG9jbYOtu5S1gAAAKY"]
[Tue Jul 21 08:06:40.451317 2026] [core:error] [pid 352421:tid 352546] [remote 40.77.167.45:39871] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:40.451338 2026] [core:error] [pid 352421:tid 352546] [remote 40.77.167.45:39871] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:40.456780 2026] [security2:error] [pid 352421:tid 352460] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/.openclaw/.env"] [unique_id "al9SwMJSWzG9jbYOtu5S2QAA1CY"]
[Tue Jul 21 08:06:40.464585 2026] [security2:error] [pid 352421:tid 352453] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/_ignition/health-check"] [unique_id "al9SwMJSWzG9jbYOtu5S2wAA1B8"]
[Tue Jul 21 08:06:40.465660 2026] [security2:error] [pid 352421:tid 352487] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/key.json"] [unique_id "al9SwMJSWzG9jbYOtu5S3AAA1EE"]
[Tue Jul 21 08:06:40.465736 2026] [security2:error] [pid 352421:tid 352630] [client 34.146.29.21:51310] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/key.json"] [unique_id "al9SwMJSWzG9jbYOtu5S3AAA1EE"]
[Tue Jul 21 08:06:40.493160 2026] [security2:error] [pid 352421:tid 352442] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/app_dev.php"] [unique_id "al9SwMJSWzG9jbYOtu5S3QAA1BQ"]
[Tue Jul 21 08:06:40.628649 2026] [security2:error] [pid 352421:tid 352666] [client 20.226.60.151:12409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/file6.php"] [unique_id "al9SwMJSWzG9jbYOtu5S4gAAAPg"]
[Tue Jul 21 08:06:40.628796 2026] [security2:error] [pid 352421:tid 352425] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/id_rsa"] [unique_id "al9SwMJSWzG9jbYOtu5S4QAAqQM"]
[Tue Jul 21 08:06:40.737090 2026] [security2:error] [pid 352421:tid 352514] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/id_dsa"] [unique_id "al9SwMJSWzG9jbYOtu5S5wAAqVw"]
[Tue Jul 21 08:06:40.741950 2026] [security2:error] [pid 352421:tid 352549] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/_debugbar/open"] [unique_id "al9SwMJSWzG9jbYOtu5S6AAAqX8"]
[Tue Jul 21 08:06:40.785283 2026] [security2:error] [pid 358661:tid 358799] [client 204.8.98.45:34702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SwAlWhjQfpOo60_HiJAAAAAU"]
[Tue Jul 21 08:06:40.785372 2026] [security2:error] [pid 358661:tid 358799] [client 204.8.98.45:34702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SwAlWhjQfpOo60_HiJAAAAAU"]
[Tue Jul 21 08:06:40.842199 2026] [security2:error] [pid 358661:tid 358891] [client 20.104.96.117:3127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/class.php"] [unique_id "al9SwAlWhjQfpOo60_HiJgAAAGE"]
[Tue Jul 21 08:06:41.008315 2026] [security2:error] [pid 352421:tid 352492] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/.continue/config.json"] [unique_id "al9SwcJSWzG9jbYOtu5S9AAAqUY"]
[Tue Jul 21 08:06:41.158300 2026] [security2:error] [pid 352421:tid 352422] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/app_dev.php/_profiler"] [unique_id "al9SwcJSWzG9jbYOtu5S_gAAqQA"]
[Tue Jul 21 08:06:41.193910 2026] [security2:error] [pid 352421:tid 352504] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/server-status"] [unique_id "al9SwcJSWzG9jbYOtu5S_wAAqVI"]
[Tue Jul 21 08:06:41.228883 2026] [security2:error] [pid 358661:tid 358918] [client 20.104.96.117:32817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/echkm.php"] [unique_id "al9SwQlWhjQfpOo60_HiLQAAAHw"]
[Tue Jul 21 08:06:41.288785 2026] [security2:error] [pid 352421:tid 352521] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/server.key"] [unique_id "al9SwcJSWzG9jbYOtu5TAwAAu2M"]
[Tue Jul 21 08:06:41.341454 2026] [security2:error] [pid 358661:tid 358819] [client 209.141.34.121:63551] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "sugar-delete.online"] [uri "/"] [unique_id "al9SwQlWhjQfpOo60_HiLgAAABk"]
[Tue Jul 21 08:06:41.380759 2026] [security2:error] [pid 352421:tid 352541] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/phpinfo.php"] [unique_id "al9SwcJSWzG9jbYOtu5TDAAAu3c"]
[Tue Jul 21 08:06:41.392625 2026] [security2:error] [pid 352421:tid 352535] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/server-info"] [unique_id "al9SwcJSWzG9jbYOtu5TDgAAu3E"]
[Tue Jul 21 08:06:41.470522 2026] [security2:error] [pid 352421:tid 352524] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/key.pem"] [unique_id "al9SwcJSWzG9jbYOtu5TEQAAu2Y"]
[Tue Jul 21 08:06:41.650559 2026] [security2:error] [pid 352421:tid 352462] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/core/.env"] [unique_id "al9SwcJSWzG9jbYOtu5TFgAA-Sg"]
[Tue Jul 21 08:06:41.651663 2026] [security2:error] [pid 358661:tid 358863] [client 20.104.96.117:3169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/lib.php"] [unique_id "al9SwQlWhjQfpOo60_HiMwAAAEU"]
[Tue Jul 21 08:06:41.660461 2026] [security2:error] [pid 352421:tid 352457] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/storage/logs/laravel.log"] [unique_id "al9SwcJSWzG9jbYOtu5TGAAAvCM"]
[Tue Jul 21 08:06:41.688117 2026] [security2:error] [pid 352421:tid 352490] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/api/env"] [unique_id "al9SwcJSWzG9jbYOtu5TGQAA_EQ"]
[Tue Jul 21 08:06:41.688264 2026] [security2:error] [pid 352421:tid 352670] [client 34.146.29.21:51310] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/api/env"] [unique_id "al9SwcJSWzG9jbYOtu5TGQAA_EQ"]
[Tue Jul 21 08:06:41.735206 2026] [security2:error] [pid 352421:tid 352495] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/.env.php.bak"] [unique_id "al9SwcJSWzG9jbYOtu5TGwAAnEk"]
[Tue Jul 21 08:06:41.752950 2026] [security2:error] [pid 352421:tid 352432] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/config/.env.php"] [unique_id "al9SwcJSWzG9jbYOtu5THgAAnAo"]
[Tue Jul 21 08:06:41.837394 2026] [security2:error] [pid 352421:tid 352544] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "principiamatematica.com"] [uri "/wp-config.php.old"] [unique_id "al9SwcJSWzG9jbYOtu5TIQAAnHo"]
[Tue Jul 21 08:06:41.837564 2026] [security2:error] [pid 352421:tid 352574] [client 34.146.29.21:51310] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/wp-config.php.old"] [unique_id "al9SwcJSWzG9jbYOtu5TIQAAnHo"]
[Tue Jul 21 08:06:41.847490 2026] [security2:error] [pid 352421:tid 352489] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/actuator/mappings"] [unique_id "al9SwcJSWzG9jbYOtu5TIgAAnEM"]
[Tue Jul 21 08:06:41.847590 2026] [security2:error] [pid 352421:tid 352574] [client 34.146.29.21:51310] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/actuator/mappings"] [unique_id "al9SwcJSWzG9jbYOtu5TIgAAnEM"]
[Tue Jul 21 08:06:41.858519 2026] [security2:error] [pid 352421:tid 352620] [client 209.141.34.121:63623] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "sugar-delete.online"] [uri "/"] [unique_id "al9SwcJSWzG9jbYOtu5TJAAAAMo"]
[Tue Jul 21 08:06:41.908691 2026] [security2:error] [pid 358661:tid 358733] [remote 216.26.249.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.249.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SwQlWhjQfpOo60_HiNwAAZkQ"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:41.926604 2026] [security2:error] [pid 352421:tid 352528] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SwcJSWzG9jbYOtu5TKwAA9Wo"]
[Tue Jul 21 08:06:41.926774 2026] [security2:error] [pid 352421:tid 352663] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SwcJSWzG9jbYOtu5TKwAA9Wo"]
[Tue Jul 21 08:06:41.933987 2026] [security2:error] [pid 352421:tid 352438] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/test.php"] [unique_id "al9SwcJSWzG9jbYOtu5TLAAAnBA"]
[Tue Jul 21 08:06:42.017459 2026] [security2:error] [pid 352421:tid 352488] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/pi.php"] [unique_id "al9SwsJSWzG9jbYOtu5TLgAAnEI"]
[Tue Jul 21 08:06:42.079419 2026] [security2:error] [pid 352421:tid 352542] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/info.php"] [unique_id "al9SwsJSWzG9jbYOtu5TMAAAuXg"]
[Tue Jul 21 08:06:42.086555 2026] [security2:error] [pid 358661:tid 358853] [client 120.56.162.40:55437] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SwglWhjQfpOo60_HiOwAAADs"]
[Tue Jul 21 08:06:42.086702 2026] [security2:error] [pid 358661:tid 358853] [client 120.56.162.40:55437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SwglWhjQfpOo60_HiOwAAADs"]
[Tue Jul 21 08:06:42.089838 2026] [security2:error] [pid 358661:tid 358873] [client 20.104.96.117:3082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/login.php"] [unique_id "al9SwglWhjQfpOo60_HiPAAAAE8"]
[Tue Jul 21 08:06:42.267700 2026] [security2:error] [pid 352421:tid 352428] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/_profiler/latest"] [unique_id "al9SwsJSWzG9jbYOtu5TOAAAuQY"]
[Tue Jul 21 08:06:42.283361 2026] [security2:error] [pid 352421:tid 352519] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/i.php"] [unique_id "al9SwsJSWzG9jbYOtu5TOgAAuWE"]
[Tue Jul 21 08:06:42.314158 2026] [security2:error] [pid 352421:tid 352556] [client 20.197.192.193:53151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/red.php"] [unique_id "al9SwsJSWzG9jbYOtu5TPgAAAIo"]
[Tue Jul 21 08:06:42.342269 2026] [security2:error] [pid 352421:tid 352459] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/.env.swp"] [unique_id "al9SwsJSWzG9jbYOtu5TPwAAuSU"]
[Tue Jul 21 08:06:42.383032 2026] [security2:error] [pid 352421:tid 352461] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/public/.env"] [unique_id "al9SwsJSWzG9jbYOtu5TQQAAuSc"]
[Tue Jul 21 08:06:42.456072 2026] [security2:error] [pid 352421:tid 352515] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/web/.env"] [unique_id "al9SwsJSWzG9jbYOtu5TRAAAyV0"]
[Tue Jul 21 08:06:42.475326 2026] [security2:error] [pid 352421:tid 352501] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/configuration.php.bak"] [unique_id "al9SwsJSWzG9jbYOtu5TRQAAn08"]
[Tue Jul 21 08:06:42.483881 2026] [security2:error] [pid 352421:tid 352458] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/v1/graphql"] [unique_id "al9SwsJSWzG9jbYOtu5TRwAAqiQ"]
[Tue Jul 21 08:06:42.545075 2026] [security2:error] [pid 352421:tid 352526] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/config.php.bak"] [unique_id "al9SwsJSWzG9jbYOtu5TSgAAqmg"]
[Tue Jul 21 08:06:42.545857 2026] [security2:error] [pid 352421:tid 352468] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/laravel/.env"] [unique_id "al9SwsJSWzG9jbYOtu5TSQAAqi4"]
[Tue Jul 21 08:06:42.555759 2026] [security2:error] [pid 352421:tid 352568] [client 20.104.96.117:33095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/a2.php"] [unique_id "al9SwsJSWzG9jbYOtu5TSwAAAJY"]
[Tue Jul 21 08:06:42.599970 2026] [security2:error] [pid 352421:tid 352443] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "principiamatematica.com"] [uri "/wp-config.php.bak"] [unique_id "al9SwsJSWzG9jbYOtu5TTAAA4RU"]
[Tue Jul 21 08:06:42.637608 2026] [security2:error] [pid 352421:tid 352440] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.bash_profile"] [unique_id "al9SwsJSWzG9jbYOtu5TTgAAjhI"]
[Tue Jul 21 08:06:42.637820 2026] [security2:error] [pid 352421:tid 352560] [client 34.146.29.21:51310] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/.bash_profile"] [unique_id "al9SwsJSWzG9jbYOtu5TTgAAjhI"]
[Tue Jul 21 08:06:42.728859 2026] [security2:error] [pid 358661:tid 358894] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SwglWhjQfpOo60_HiRgAAAGQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:42.728987 2026] [security2:error] [pid 358661:tid 358894] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SwglWhjQfpOo60_HiRgAAAGQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:42.818478 2026] [security2:error] [pid 352421:tid 352476] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SwsJSWzG9jbYOtu5TVwAAjzY"]
[Tue Jul 21 08:06:42.818630 2026] [security2:error] [pid 352421:tid 352561] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SwsJSWzG9jbYOtu5TVwAAjzY"]
[Tue Jul 21 08:06:42.849346 2026] [security2:error] [pid 358661:tid 358813] [client 20.197.192.193:52259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/fffm.php"] [unique_id "al9SwglWhjQfpOo60_HiRwAAABM"]
[Tue Jul 21 08:06:42.952877 2026] [security2:error] [pid 358661:tid 358726] [remote 209.50.167.123:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.167.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SwglWhjQfpOo60_HiSAAAQz0"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:42.987266 2026] [security2:error] [pid 358661:tid 358804] [client 102.206.115.33:61183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SwglWhjQfpOo60_HiSQAAAAo"]
[Tue Jul 21 08:06:42.987372 2026] [security2:error] [pid 358661:tid 358804] [client 102.206.115.33:61183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SwglWhjQfpOo60_HiSQAAAAo"]
[Tue Jul 21 08:06:43.138285 2026] [security2:error] [pid 352421:tid 352572] [client 20.104.96.117:3159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/d61.php"] [unique_id "al9Sw8JSWzG9jbYOtu5TYgAAAJo"]
[Tue Jul 21 08:06:43.354552 2026] [security2:error] [pid 352421:tid 352669] [client 150.129.202.39:65230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sw8JSWzG9jbYOtu5TYwAAAPs"]
[Tue Jul 21 08:06:43.354803 2026] [security2:error] [pid 352421:tid 352669] [client 150.129.202.39:65230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sw8JSWzG9jbYOtu5TYwAAAPs"]
[Tue Jul 21 08:06:43.559649 2026] [security2:error] [pid 352421:tid 352573] [client 65.21.113.253:44272] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Sw8JSWzG9jbYOtu5TWgAAAJs"]
[Tue Jul 21 08:06:43.590291 2026] [security2:error] [pid 358661:tid 358869] [client 20.104.96.117:32783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/info.php"] [unique_id "al9SwwlWhjQfpOo60_HiVAAAAEs"]
[Tue Jul 21 08:06:43.836859 2026] [security2:error] [pid 352421:tid 352636] [client 103.154.231.97:32876] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "lojadedoces.com"] [uri "/wp-comments-post.php"] [unique_id "al9SwsJSWzG9jbYOtu5TSAAAANo"]
[Tue Jul 21 08:06:43.885513 2026] [security2:error] [pid 352421:tid 352552] [client 20.104.96.117:3091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/11.php"] [unique_id "al9Sw8JSWzG9jbYOtu5TegAAAIY"]
[Tue Jul 21 08:06:44.021029 2026] [security2:error] [pid 352421:tid 352636] [client 103.154.231.97:32876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "lojadedoces.com"] [uri "/wp-comments-post.php"] [unique_id "al9SwsJSWzG9jbYOtu5TSAAAANo"]
[Tue Jul 21 08:06:44.128306 2026] [security2:error] [pid 358661:tid 358831] [client 20.226.60.151:12403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/adminfuns.php"] [unique_id "al9SxAlWhjQfpOo60_HiYwAAACU"]
[Tue Jul 21 08:06:44.223499 2026] [security2:error] [pid 352421:tid 352571] [client 20.104.96.117:33108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/v2.php"] [unique_id "al9SxMJSWzG9jbYOtu5TiAAAAJk"]
[Tue Jul 21 08:06:44.244099 2026] [security2:error] [pid 352421:tid 352617] [client 92.119.178.3:42576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SxMJSWzG9jbYOtu5TiwAAAMc"]
[Tue Jul 21 08:06:44.244179 2026] [security2:error] [pid 352421:tid 352617] [client 92.119.178.3:42576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SxMJSWzG9jbYOtu5TiwAAAMc"]
[Tue Jul 21 08:06:44.328224 2026] [security2:error] [pid 352421:tid 352435] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9SxMJSWzG9jbYOtu5TgwAA5g0"], referer: https://principiamatematica.com/login
[Tue Jul 21 08:06:44.431717 2026] [security2:error] [pid 358661:tid 358894] [client 65.21.113.253:49292] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SxAlWhjQfpOo60_HiZwAAAGQ"]
[Tue Jul 21 08:06:44.480195 2026] [security2:error] [pid 352421:tid 352539] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9SxMJSWzG9jbYOtu5TjwAAyXU"], referer: https://principiamatematica.com/wp-admin/
[Tue Jul 21 08:06:44.549407 2026] [security2:error] [pid 358661:tid 358915] [client 20.104.96.117:3090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/panel.php"] [unique_id "al9SxAlWhjQfpOo60_HiawAAAHk"]
[Tue Jul 21 08:06:44.581941 2026] [security2:error] [pid 352421:tid 352422] [remote 34.146.29.21:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9SxMJSWzG9jbYOtu5TkQAArAA"], referer: https://principiamatematica.com/wp-admin/
[Tue Jul 21 08:06:44.790272 2026] [security2:error] [pid 358661:tid 358837] [client 20.29.126.15:5304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/jga.php"] [unique_id "al9SxAlWhjQfpOo60_HicAAAACs"]
[Tue Jul 21 08:06:44.800225 2026] [core:error] [pid 358661:tid 358747] [remote 52.167.144.201:23224] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:44.800248 2026] [core:error] [pid 358661:tid 358747] [remote 52.167.144.201:23224] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:44.927799 2026] [core:error] [pid 358661:tid 358684] [remote 52.167.144.201:23224] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:44.927832 2026] [core:error] [pid 358661:tid 358684] [remote 52.167.144.201:23224] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:44.973048 2026] [security2:error] [pid 352421:tid 352655] [client 103.78.200.11:65261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SxMJSWzG9jbYOtu5TlgAAAO0"]
[Tue Jul 21 08:06:44.973183 2026] [security2:error] [pid 352421:tid 352655] [client 103.78.200.11:65261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SxMJSWzG9jbYOtu5TlgAAAO0"]
[Tue Jul 21 08:06:45.040885 2026] [security2:error] [pid 352421:tid 352635] [client 65.21.113.253:44272] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SxMJSWzG9jbYOtu5TkgAAANk"]
[Tue Jul 21 08:06:45.050192 2026] [core:error] [pid 358661:tid 358719] [remote 52.167.144.201:23224] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:45.050218 2026] [core:error] [pid 358661:tid 358719] [remote 52.167.144.201:23224] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:45.099064 2026] [security2:error] [pid 352421:tid 352666] [client 20.104.96.117:33111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/dex.php"] [unique_id "al9SxcJSWzG9jbYOtu5TmgAAAPg"]
[Tue Jul 21 08:06:45.313056 2026] [security2:error] [pid 358661:tid 358874] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SxQlWhjQfpOo60_HiewAAAFA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:45.386036 2026] [security2:error] [pid 358661:tid 358738] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SxQlWhjQfpOo60_HifAAALUk"]
[Tue Jul 21 08:06:45.386218 2026] [security2:error] [pid 358661:tid 358839] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SxQlWhjQfpOo60_HifAAALUk"]
[Tue Jul 21 08:06:45.410251 2026] [security2:error] [pid 358661:tid 358870] [client 20.104.96.117:3085] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "muskiwear.com.br"] [uri "/1.php"] [unique_id "al9SxQlWhjQfpOo60_HifQAAAEw"]
[Tue Jul 21 08:06:45.410328 2026] [security2:error] [pid 358661:tid 358870] [client 20.104.96.117:3085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/1.php"] [unique_id "al9SxQlWhjQfpOo60_HifQAAAEw"]
[Tue Jul 21 08:06:45.725532 2026] [security2:error] [pid 358661:tid 358873] [client 20.104.96.117:33125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/ms.php"] [unique_id "al9SxQlWhjQfpOo60_HifwAAAE8"]
[Tue Jul 21 08:06:45.812592 2026] [security2:error] [pid 352421:tid 352557] [client 87.116.180.198:27204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SxcJSWzG9jbYOtu5ToQAAAIs"]
[Tue Jul 21 08:06:45.812709 2026] [security2:error] [pid 352421:tid 352557] [client 87.116.180.198:27204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SxcJSWzG9jbYOtu5ToQAAAIs"]
[Tue Jul 21 08:06:45.939748 2026] [security2:error] [pid 358661:tid 358867] [client 178.153.91.96:63485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SxQlWhjQfpOo60_HihgAAAEk"]
[Tue Jul 21 08:06:45.939912 2026] [security2:error] [pid 358661:tid 358867] [client 178.153.91.96:63485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9SxQlWhjQfpOo60_HihgAAAEk"]
[Tue Jul 21 08:06:45.999876 2026] [security2:error] [pid 358661:tid 358900] [client 20.226.60.151:12156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/goods.php"] [unique_id "al9SxQlWhjQfpOo60_HihwAAAGo"]
[Tue Jul 21 08:06:46.026505 2026] [security2:error] [pid 358661:tid 358823] [client 92.119.178.3:42590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9SxglWhjQfpOo60_HiiQAAAB0"]
[Tue Jul 21 08:06:46.026588 2026] [security2:error] [pid 358661:tid 358823] [client 92.119.178.3:42590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9SxglWhjQfpOo60_HiiQAAAB0"]
[Tue Jul 21 08:06:46.046543 2026] [security2:error] [pid 358661:tid 358746] [remote 104.207.57.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SxQlWhjQfpOo60_HihQAAO1E"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:46.081253 2026] [security2:error] [pid 352421:tid 352569] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9SxcJSWzG9jbYOtu5TpAAAlxk"]
[Tue Jul 21 08:06:46.157041 2026] [security2:error] [pid 358661:tid 358905] [client 103.29.114.44:6038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SxglWhjQfpOo60_HijAAAAG8"]
[Tue Jul 21 08:06:46.157184 2026] [security2:error] [pid 358661:tid 358905] [client 103.29.114.44:6038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SxglWhjQfpOo60_HijAAAAG8"]
[Tue Jul 21 08:06:46.222499 2026] [security2:error] [pid 358661:tid 358832] [client 20.104.96.117:3094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/memberfuns.php"] [unique_id "al9SxglWhjQfpOo60_HijgAAACY"]
[Tue Jul 21 08:06:46.342082 2026] [security2:error] [pid 358661:tid 358674] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SxglWhjQfpOo60_HikQAAbgk"]
[Tue Jul 21 08:06:46.342463 2026] [security2:error] [pid 358661:tid 358904] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SxglWhjQfpOo60_HikQAAbgk"]
[Tue Jul 21 08:06:46.505054 2026] [security2:error] [pid 358661:tid 358919] [client 20.104.96.117:33126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/0.php"] [unique_id "al9SxglWhjQfpOo60_HikgAAAH0"]
[Tue Jul 21 08:06:46.508766 2026] [security2:error] [pid 352421:tid 352477] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SxsJSWzG9jbYOtu5TqQAA7jc"]
[Tue Jul 21 08:06:46.508903 2026] [security2:error] [pid 352421:tid 352656] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SxsJSWzG9jbYOtu5TqQAA7jc"]
[Tue Jul 21 08:06:46.532725 2026] [security2:error] [pid 358661:tid 358881] [client 184.75.221.3:37720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SxglWhjQfpOo60_HikwAAAFc"]
[Tue Jul 21 08:06:46.532819 2026] [security2:error] [pid 358661:tid 358881] [client 184.75.221.3:37720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9SxglWhjQfpOo60_HikwAAAFc"]
[Tue Jul 21 08:06:46.611095 2026] [security2:error] [pid 358661:tid 358849] [client 198.54.128.138:47932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SxglWhjQfpOo60_HilQAAADc"]
[Tue Jul 21 08:06:46.611199 2026] [security2:error] [pid 358661:tid 358849] [client 198.54.128.138:47932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SxglWhjQfpOo60_HilQAAADc"]
[Tue Jul 21 08:06:46.650399 2026] [security2:error] [pid 358661:tid 358892] [client 20.29.126.15:3001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/k.php"] [unique_id "al9SxglWhjQfpOo60_HilgAAAGI"]
[Tue Jul 21 08:06:46.735480 2026] [security2:error] [pid 358661:tid 358822] [client 65.21.113.253:44282] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SxglWhjQfpOo60_HijwAAABw"]
[Tue Jul 21 08:06:46.823388 2026] [security2:error] [pid 358661:tid 358876] [client 20.104.96.117:32809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/BDKR28.php"] [unique_id "al9SxglWhjQfpOo60_HimgAAAFI"]
[Tue Jul 21 08:06:46.982017 2026] [core:alert] [pid 358661:tid 358870] [client 69.171.249.10:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:06:47.018154 2026] [security2:error] [pid 358661:tid 358872] [client 65.21.113.253:49292] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SxwlWhjQfpOo60_HiogAAAE4"]
[Tue Jul 21 08:06:47.027206 2026] [security2:error] [pid 358661:tid 358888] [client 117.247.80.59:14956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SxwlWhjQfpOo60_HiowAAAF4"]
[Tue Jul 21 08:06:47.027303 2026] [security2:error] [pid 358661:tid 358888] [client 117.247.80.59:14956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SxwlWhjQfpOo60_HiowAAAF4"]
[Tue Jul 21 08:06:47.044296 2026] [security2:error] [pid 352421:tid 352610] [client 117.210.135.0:55877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sx8JSWzG9jbYOtu5TsAAAAMA"]
[Tue Jul 21 08:06:47.044388 2026] [security2:error] [pid 352421:tid 352610] [client 117.210.135.0:55877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Sx8JSWzG9jbYOtu5TsAAAAMA"]
[Tue Jul 21 08:06:47.117176 2026] [security2:error] [pid 352421:tid 352595] [client 20.104.96.117:33141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/green1.php"] [unique_id "al9Sx8JSWzG9jbYOtu5TsgAAALE"]
[Tue Jul 21 08:06:47.398534 2026] [security2:error] [pid 352421:tid 352620] [client 20.104.96.117:3106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/nc4.php"] [unique_id "al9Sx8JSWzG9jbYOtu5TtQAAAMo"]
[Tue Jul 21 08:06:47.765687 2026] [core:alert] [pid 358661:tid 358814] [client 57.141.18.113:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:06:47.876908 2026] [security2:error] [pid 358661:tid 358807] [client 20.104.96.117:3121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/a1.php"] [unique_id "al9SxwlWhjQfpOo60_HisgAAAA0"]
[Tue Jul 21 08:06:48.098044 2026] [security2:error] [pid 358661:tid 358867] [client 65.21.113.253:44296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SxwlWhjQfpOo60_HirQAAAEk"]
[Tue Jul 21 08:06:48.217818 2026] [security2:error] [pid 358661:tid 358800] [client 20.104.96.117:32784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/eee.php"] [unique_id "al9SyAlWhjQfpOo60_HiuQAAAAY"]
[Tue Jul 21 08:06:48.224994 2026] [security2:error] [pid 352421:tid 352648] [client 20.226.60.151:12410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/100.php"] [unique_id "al9SyMJSWzG9jbYOtu5TvwAAAOY"]
[Tue Jul 21 08:06:48.555667 2026] [security2:error] [pid 352421:tid 352602] [client 20.104.96.117:20802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/wp-aothait.php"] [unique_id "al9SyMJSWzG9jbYOtu5TwwAAALg"]
[Tue Jul 21 08:06:48.754858 2026] [security2:error] [pid 352421:tid 352571] [client 38.100.221.102:18828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SyMJSWzG9jbYOtu5TyAAAAJk"]
[Tue Jul 21 08:06:48.754964 2026] [security2:error] [pid 352421:tid 352571] [client 38.100.221.102:18828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SyMJSWzG9jbYOtu5TyAAAAJk"]
[Tue Jul 21 08:06:48.823269 2026] [security2:error] [pid 352421:tid 352588] [client 20.226.60.151:12122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/about.php"] [unique_id "al9SyMJSWzG9jbYOtu5TyQAAAKo"]
[Tue Jul 21 08:06:48.882650 2026] [security2:error] [pid 352421:tid 352655] [client 20.104.96.117:33147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/config.json.php"] [unique_id "al9SyMJSWzG9jbYOtu5TygAAAO0"]
[Tue Jul 21 08:06:48.937083 2026] [security2:error] [pid 358661:tid 358787] [remote 81.173.115.7:55422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/wp-login.php"] [unique_id "al9SyAlWhjQfpOo60_HivwAATno"]
[Tue Jul 21 08:06:49.102398 2026] [security2:error] [pid 352421:tid 352570] [client 20.29.126.15:2944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/vx.php"] [unique_id "al9SycJSWzG9jbYOtu5T0QAAAJg"]
[Tue Jul 21 08:06:49.196520 2026] [security2:error] [pid 358661:tid 358864] [client 20.104.96.117:33137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9SyQlWhjQfpOo60_HiyQAAAEY"]
[Tue Jul 21 08:06:49.258075 2026] [security2:error] [pid 358661:tid 358712] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SyQlWhjQfpOo60_HiywAAZi8"]
[Tue Jul 21 08:06:49.258292 2026] [security2:error] [pid 358661:tid 358896] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SyQlWhjQfpOo60_HiywAAZi8"]
[Tue Jul 21 08:06:49.559121 2026] [security2:error] [pid 358661:tid 358869] [client 198.54.128.138:35808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SyQlWhjQfpOo60_HizwAAAEs"]
[Tue Jul 21 08:06:49.559221 2026] [security2:error] [pid 358661:tid 358869] [client 198.54.128.138:35808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SyQlWhjQfpOo60_HizwAAAEs"]
[Tue Jul 21 08:06:49.573328 2026] [security2:error] [pid 358661:tid 358884] [client 20.104.96.117:33099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/k2.php"] [unique_id "al9SyQlWhjQfpOo60_Hi0AAAAFo"]
[Tue Jul 21 08:06:49.728365 2026] [security2:error] [pid 352421:tid 352553] [client 20.226.60.151:12369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/about.php"] [unique_id "al9SycJSWzG9jbYOtu5T1wAAAIc"]
[Tue Jul 21 08:06:49.802126 2026] [security2:error] [pid 358661:tid 358887] [client 202.143.127.214:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SyQlWhjQfpOo60_Hi1QAAAF0"]
[Tue Jul 21 08:06:49.802253 2026] [security2:error] [pid 358661:tid 358887] [client 202.143.127.214:64040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SyQlWhjQfpOo60_Hi1QAAAF0"]
[Tue Jul 21 08:06:49.856262 2026] [security2:error] [pid 358661:tid 358899] [client 20.104.96.117:33115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9SyQlWhjQfpOo60_Hi1wAAAGk"]
[Tue Jul 21 08:06:49.879683 2026] [security2:error] [pid 358661:tid 358824] [client 20.197.192.193:3487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/dp.php"] [unique_id "al9SyQlWhjQfpOo60_Hi2AAAAB4"]
[Tue Jul 21 08:06:50.136734 2026] [security2:error] [pid 352421:tid 352436] [remote 97.74.93.24:60630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "visiootica.com"] [uri "/wp-login.php"] [unique_id "al9SysJSWzG9jbYOtu5T3QAA1w4"]
[Tue Jul 21 08:06:50.142411 2026] [security2:error] [pid 352421:tid 352656] [client 20.104.96.117:32804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9SysJSWzG9jbYOtu5T3wAAAO4"]
[Tue Jul 21 08:06:50.203186 2026] [proxy:error] [pid 358661:tid 358798] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:50.203268 2026] [proxy_http:error] [pid 358661:tid 358798] [client 142.248.80.30:10632] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:50.203912 2026] [proxy:error] [pid 358661:tid 358798] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:50.203952 2026] [proxy_http:error] [pid 358661:tid 358798] [client 142.248.80.30:10632] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:50.334996 2026] [security2:error] [pid 358661:tid 358915] [client 65.21.113.253:44282] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SyQlWhjQfpOo60_Hi1gAAAHk"]
[Tue Jul 21 08:06:50.335848 2026] [security2:error] [pid 358661:tid 358866] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SyAlWhjQfpOo60_HiuAAAAEg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:50.430447 2026] [security2:error] [pid 358661:tid 358808] [client 175.144.82.48:55203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SyglWhjQfpOo60_Hi4wAAAA4"]
[Tue Jul 21 08:06:50.431018 2026] [security2:error] [pid 358661:tid 358808] [client 175.144.82.48:55203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SyglWhjQfpOo60_Hi4wAAAA4"]
[Tue Jul 21 08:06:50.465848 2026] [security2:error] [pid 358661:tid 358839] [client 20.104.96.117:3087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9SyglWhjQfpOo60_Hi5AAAAC0"]
[Tue Jul 21 08:06:50.617679 2026] [core:error] [pid 358661:tid 358874] [client 142.248.80.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:50.617699 2026] [core:error] [pid 358661:tid 358874] [client 142.248.80.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:50.643395 2026] [security2:error] [pid 358661:tid 358834] [client 20.226.60.151:11992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/admin.php"] [unique_id "al9SyglWhjQfpOo60_Hi6QAAACg"]
[Tue Jul 21 08:06:50.689010 2026] [security2:error] [pid 352421:tid 352531] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9SysJSWzG9jbYOtu5T4wAAhW0"]
[Tue Jul 21 08:06:50.699503 2026] [security2:error] [pid 358661:tid 358854] [client 41.68.90.219:55863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SyglWhjQfpOo60_Hi6gAAADw"]
[Tue Jul 21 08:06:50.701196 2026] [security2:error] [pid 358661:tid 358854] [client 41.68.90.219:55863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SyglWhjQfpOo60_Hi6gAAADw"]
[Tue Jul 21 08:06:50.715074 2026] [security2:error] [pid 352421:tid 352542] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9SysJSWzG9jbYOtu5T5AAAhng"]
[Tue Jul 21 08:06:50.763970 2026] [security2:error] [pid 352421:tid 352424] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/dp.php"] [unique_id "al9SysJSWzG9jbYOtu5T5gAAsQI"]
[Tue Jul 21 08:06:50.783902 2026] [security2:error] [pid 352421:tid 352472] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/old.php"] [unique_id "al9SysJSWzG9jbYOtu5T5wAA6zI"]
[Tue Jul 21 08:06:50.807120 2026] [security2:error] [pid 352421:tid 352500] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/ms-new.php"] [unique_id "al9SysJSWzG9jbYOtu5T6AAAv04"]
[Tue Jul 21 08:06:50.809200 2026] [security2:error] [pid 358661:tid 358781] [remote 104.207.57.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SyglWhjQfpOo60_Hi7wAAMnQ"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:50.827714 2026] [security2:error] [pid 352421:tid 352446] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/track.php"] [unique_id "al9SysJSWzG9jbYOtu5T6QAAxBg"]
[Tue Jul 21 08:06:50.858357 2026] [security2:error] [pid 352421:tid 352519] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/2352356666.php"] [unique_id "al9SysJSWzG9jbYOtu5T7AAApWE"]
[Tue Jul 21 08:06:50.877494 2026] [security2:error] [pid 352421:tid 352471] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/pn.php"] [unique_id "al9SysJSWzG9jbYOtu5T7QAAzDE"]
[Tue Jul 21 08:06:50.895400 2026] [security2:error] [pid 352421:tid 352663] [client 20.104.96.117:3140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/for.php"] [unique_id "al9SysJSWzG9jbYOtu5T7gAAAPU"]
[Tue Jul 21 08:06:50.901644 2026] [security2:error] [pid 352421:tid 352525] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wp-wpbak.php"] [unique_id "al9SysJSWzG9jbYOtu5T7wAA7Gc"]
[Tue Jul 21 08:06:50.914876 2026] [security2:error] [pid 358661:tid 358849] [client 109.60.28.94:51050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SyglWhjQfpOo60_Hi8QAAADc"]
[Tue Jul 21 08:06:50.915570 2026] [security2:error] [pid 358661:tid 358849] [client 109.60.28.94:51050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SyglWhjQfpOo60_Hi8QAAADc"]
[Tue Jul 21 08:06:50.923067 2026] [security2:error] [pid 352421:tid 352441] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/dr.php"] [unique_id "al9SysJSWzG9jbYOtu5T8QAAnBM"]
[Tue Jul 21 08:06:50.948773 2026] [security2:error] [pid 352421:tid 352461] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/2x.php"] [unique_id "al9SysJSWzG9jbYOtu5T8gAA-Sc"]
[Tue Jul 21 08:06:50.954156 2026] [security2:error] [pid 358661:tid 358822] [client 103.166.103.129:65242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SyglWhjQfpOo60_Hi8gAAABw"]
[Tue Jul 21 08:06:50.954345 2026] [security2:error] [pid 358661:tid 358822] [client 103.166.103.129:65242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9SyglWhjQfpOo60_Hi8gAAABw"]
[Tue Jul 21 08:06:50.974935 2026] [security2:error] [pid 352421:tid 352463] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/kq1.php"] [unique_id "al9SysJSWzG9jbYOtu5T8wAA8ik"]
[Tue Jul 21 08:06:51.005567 2026] [security2:error] [pid 352421:tid 352527] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/zzz.php"] [unique_id "al9Sy8JSWzG9jbYOtu5T9QAAvGk"]
[Tue Jul 21 08:06:51.025340 2026] [security2:error] [pid 352421:tid 352515] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wicked.php"] [unique_id "al9Sy8JSWzG9jbYOtu5T9gAAtV0"]
[Tue Jul 21 08:06:51.043227 2026] [security2:error] [pid 352421:tid 352501] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/edit.php"] [unique_id "al9Sy8JSWzG9jbYOtu5T-AAAx08"]
[Tue Jul 21 08:06:51.056831 2026] [core:error] [pid 358661:tid 358873] [client 142.248.80.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:51.056851 2026] [core:error] [pid 358661:tid 358873] [client 142.248.80.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:51.059122 2026] [core:error] [pid 358661:tid 358797] [client 142.248.80.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:51.059140 2026] [core:error] [pid 358661:tid 358797] [client 142.248.80.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:51.067192 2026] [security2:error] [pid 352421:tid 352458] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/kua.php"] [unique_id "al9Sy8JSWzG9jbYOtu5T-wAAySQ"]
[Tue Jul 21 08:06:51.085914 2026] [security2:error] [pid 352421:tid 352526] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/ez.php"] [unique_id "al9Sy8JSWzG9jbYOtu5T_AAA2Gg"]
[Tue Jul 21 08:06:51.110611 2026] [security2:error] [pid 352421:tid 352468] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/fz.php"] [unique_id "al9Sy8JSWzG9jbYOtu5T_QAAri4"]
[Tue Jul 21 08:06:51.131729 2026] [security2:error] [pid 352421:tid 352565] [client 104.28.219.195:19295] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.tragaseushow.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9Sy8JSWzG9jbYOtu5T_gAAAJM"]
[Tue Jul 21 08:06:51.132884 2026] [security2:error] [pid 352421:tid 352509] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/la.php"] [unique_id "al9Sy8JSWzG9jbYOtu5T_wAAuFc"]
[Tue Jul 21 08:06:51.155726 2026] [security2:error] [pid 352421:tid 352443] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/nhvoanpl.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UAAAA3RU"]
[Tue Jul 21 08:06:51.162608 2026] [core:error] [pid 358661:tid 358914] [client 104.28.219.194:25760] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:51.162630 2026] [core:error] [pid 358661:tid 358914] [client 104.28.219.194:25760] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:06:51.183000 2026] [security2:error] [pid 352421:tid 352440] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/inso.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UAQAAihI"]
[Tue Jul 21 08:06:51.193963 2026] [security2:error] [pid 358661:tid 358875] [client 20.104.96.117:3131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muskiwear.com.br"] [uri "/raw.php"] [unique_id "al9SywlWhjQfpOo60_Hi_gAAAFE"]
[Tue Jul 21 08:06:51.206848 2026] [security2:error] [pid 358661:tid 358799] [client 20.29.126.15:11171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/ws77.php"] [unique_id "al9SywlWhjQfpOo60_Hi_wAAAAU"]
[Tue Jul 21 08:06:51.210185 2026] [security2:error] [pid 352421:tid 352522] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wpx.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UAwAAlmQ"]
[Tue Jul 21 08:06:51.237212 2026] [security2:error] [pid 352421:tid 352423] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/berlin.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UBAAAtAE"]
[Tue Jul 21 08:06:51.271988 2026] [security2:error] [pid 352421:tid 352431] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/billur.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UBQAA6gk"]
[Tue Jul 21 08:06:51.303285 2026] [security2:error] [pid 352421:tid 352426] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/mimpi.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UCAAAqgQ"]
[Tue Jul 21 08:06:51.331025 2026] [security2:error] [pid 352421:tid 352476] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/dp.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UCgAA7TY"]
[Tue Jul 21 08:06:51.362525 2026] [security2:error] [pid 352421:tid 352454] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/bootstrap.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UCwAAjyA"]
[Tue Jul 21 08:06:51.392447 2026] [security2:error] [pid 352421:tid 352450] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wp-editor.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UDAAAmBw"]
[Tue Jul 21 08:06:51.416443 2026] [security2:error] [pid 352421:tid 352516] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/cro.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UDQAAn14"]
[Tue Jul 21 08:06:51.442244 2026] [security2:error] [pid 352421:tid 352545] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/cron-tab.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UDgAA-ns"]
[Tue Jul 21 08:06:51.472649 2026] [security2:error] [pid 352421:tid 352480] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/koiy.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UDwAA-Do"]
[Tue Jul 21 08:06:51.499135 2026] [security2:error] [pid 352421:tid 352452] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/hp2.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UEAAAnh4"]
[Tue Jul 21 08:06:51.522706 2026] [security2:error] [pid 352421:tid 352456] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/hp3.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UEgAA2SI"]
[Tue Jul 21 08:06:51.543313 2026] [security2:error] [pid 358661:tid 358851] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SywlWhjQfpOo60_HjBwAAADk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:51.543416 2026] [security2:error] [pid 358661:tid 358851] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SywlWhjQfpOo60_HjBwAAADk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:51.547373 2026] [security2:error] [pid 352421:tid 352460] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/aa1.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UEwAAzSY"]
[Tue Jul 21 08:06:51.566011 2026] [security2:error] [pid 352421:tid 352453] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/acew67.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UFQAA4x8"]
[Tue Jul 21 08:06:51.592226 2026] [security2:error] [pid 352421:tid 352487] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/bscclapb.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UFgAA4kE"]
[Tue Jul 21 08:06:51.613436 2026] [security2:error] [pid 352421:tid 352482] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/else1.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UGAAA1Dw"]
[Tue Jul 21 08:06:51.633664 2026] [security2:error] [pid 352421:tid 352451] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/tkikikoko.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UGgAAsB0"]
[Tue Jul 21 08:06:51.652491 2026] [security2:error] [pid 352421:tid 352442] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wp-Blogs.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UGwAA-xQ"]
[Tue Jul 21 08:06:51.677349 2026] [security2:error] [pid 352421:tid 352498] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wp-css.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UHAAAs0w"]
[Tue Jul 21 08:06:51.709208 2026] [security2:error] [pid 352421:tid 352505] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wp-explorer.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UHQAAh1M"]
[Tue Jul 21 08:06:51.858122 2026] [security2:error] [pid 352421:tid 352538] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/akismet.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UHwAAjXQ"]
[Tue Jul 21 08:06:51.902102 2026] [security2:error] [pid 352421:tid 352425] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/ace2.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UIgABAAM"]
[Tue Jul 21 08:06:51.926333 2026] [security2:error] [pid 352421:tid 352549] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/ms.php"] [unique_id "al9Sy8JSWzG9jbYOtu5UJQAAl38"]
[Tue Jul 21 08:06:51.957773 2026] [security2:error] [pid 358661:tid 358840] [client 20.226.60.151:12368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/admin.php"] [unique_id "al9SywlWhjQfpOo60_HjEQAAAC4"]
[Tue Jul 21 08:06:52.227684 2026] [security2:error] [pid 358661:tid 358884] [client 92.119.178.3:38004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9SzAlWhjQfpOo60_HjGwAAAFo"]
[Tue Jul 21 08:06:52.227769 2026] [security2:error] [pid 358661:tid 358884] [client 92.119.178.3:38004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9SzAlWhjQfpOo60_HjGwAAAFo"]
[Tue Jul 21 08:06:52.472559 2026] [security2:error] [pid 358661:tid 358765] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SzAlWhjQfpOo60_HjIAAAVGQ"]
[Tue Jul 21 08:06:52.472725 2026] [security2:error] [pid 358661:tid 358878] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9SzAlWhjQfpOo60_HjIAAAVGQ"]
[Tue Jul 21 08:06:52.532522 2026] [proxy:error] [pid 358661:tid 358914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:52.532609 2026] [proxy_http:error] [pid 358661:tid 358914] [client 204.10.194.153:64644] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:52.533321 2026] [proxy:error] [pid 358661:tid 358914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:52.533358 2026] [proxy_http:error] [pid 358661:tid 358914] [client 204.10.194.153:64644] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:52.694492 2026] [security2:error] [pid 358661:tid 358805] [client 120.56.162.40:55918] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SzAlWhjQfpOo60_HjJgAAAAs"]
[Tue Jul 21 08:06:52.694609 2026] [security2:error] [pid 358661:tid 358805] [client 120.56.162.40:55918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SzAlWhjQfpOo60_HjJgAAAAs"]
[Tue Jul 21 08:06:52.771436 2026] [proxy:error] [pid 358661:tid 358799] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:52.771476 2026] [proxy_http:error] [pid 358661:tid 358799] [client 204.10.194.153:44172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:52.772268 2026] [proxy:error] [pid 358661:tid 358799] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:52.772307 2026] [proxy_http:error] [pid 358661:tid 358799] [client 204.10.194.153:44172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:52.811322 2026] [security2:error] [pid 358661:tid 358830] [client 20.226.60.151:11978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/themes.php"] [unique_id "al9SzAlWhjQfpOo60_HjKQAAACQ"]
[Tue Jul 21 08:06:52.874871 2026] [security2:error] [pid 358661:tid 358772] [remote 104.207.33.55:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SywlWhjQfpOo60_HjDgAANWs"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:53.069340 2026] [security2:error] [pid 358661:tid 358913] [client 150.129.202.39:65348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SzQlWhjQfpOo60_HjLAAAAHc"]
[Tue Jul 21 08:06:53.069638 2026] [security2:error] [pid 358661:tid 358913] [client 150.129.202.39:65348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SzQlWhjQfpOo60_HjLAAAAHc"]
[Tue Jul 21 08:06:53.154987 2026] [security2:error] [pid 358661:tid 358836] [client 198.54.128.138:50384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9SzQlWhjQfpOo60_HjMQAAACo"]
[Tue Jul 21 08:06:53.155099 2026] [security2:error] [pid 358661:tid 358836] [client 198.54.128.138:50384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9SzQlWhjQfpOo60_HjMQAAACo"]
[Tue Jul 21 08:06:53.364059 2026] [proxy:error] [pid 358661:tid 358865] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:53.364150 2026] [proxy_http:error] [pid 358661:tid 358865] [client 204.10.194.153:44192] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:53.364373 2026] [proxy:error] [pid 358661:tid 358854] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:53.364416 2026] [proxy_http:error] [pid 358661:tid 358854] [client 204.10.194.153:44188] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:53.364840 2026] [proxy:error] [pid 358661:tid 358865] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:53.364872 2026] [proxy_http:error] [pid 358661:tid 358865] [client 204.10.194.153:44192] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:53.365049 2026] [proxy:error] [pid 358661:tid 358854] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:06:53.365076 2026] [proxy_http:error] [pid 358661:tid 358854] [client 204.10.194.153:44188] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:06:53.404976 2026] [security2:error] [pid 358661:tid 358737] [remote 119.195.102.159:59748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9SzQlWhjQfpOo60_HjOAAAc0g"]
[Tue Jul 21 08:06:53.527907 2026] [security2:error] [pid 358661:tid 358851] [client 102.206.115.33:58557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SzQlWhjQfpOo60_HjOgAAADk"]
[Tue Jul 21 08:06:53.528044 2026] [security2:error] [pid 358661:tid 358851] [client 102.206.115.33:58557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9SzQlWhjQfpOo60_HjOgAAADk"]
[Tue Jul 21 08:06:53.547153 2026] [security2:error] [pid 358661:tid 358791] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SzQlWhjQfpOo60_HjOwAAJX4"]
[Tue Jul 21 08:06:53.547278 2026] [security2:error] [pid 358661:tid 358831] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9SzQlWhjQfpOo60_HjOwAAJX4"]
[Tue Jul 21 08:06:54.028756 2026] [security2:error] [pid 358661:tid 358832] [client 65.21.113.253:44282] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SzQlWhjQfpOo60_HjPQAAACY"]
[Tue Jul 21 08:06:54.046160 2026] [security2:error] [pid 352421:tid 352513] [remote 209.50.175.221:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.175.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9SzcJSWzG9jbYOtu5UOwAA6Vs"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:54.531313 2026] [security2:error] [pid 358661:tid 358890] [client 20.197.192.193:39255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/old.php"] [unique_id "al9SzglWhjQfpOo60_HjUAAAAGA"]
[Tue Jul 21 08:06:54.538348 2026] [security2:error] [pid 358661:tid 358799] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9SzglWhjQfpOo60_HjUQAAAAU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:55.015499 2026] [security2:error] [pid 358661:tid 358864] [client 65.21.113.253:46568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9SzwlWhjQfpOo60_HjXQAAAEY"]
[Tue Jul 21 08:06:55.076315 2026] [security2:error] [pid 352421:tid 352568] [client 20.226.60.151:11981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Sz8JSWzG9jbYOtu5USwAAAJY"]
[Tue Jul 21 08:06:55.233983 2026] [security2:error] [pid 358661:tid 358789] [remote 159.223.116.62:44124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.116.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rgagestaodecondominios.adm.br"] [uri "/wp-login.php"] [unique_id "al9SzwlWhjQfpOo60_HjYgAAR3w"]
[Tue Jul 21 08:06:55.258106 2026] [security2:error] [pid 358661:tid 358831] [client 198.54.128.138:35814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SzwlWhjQfpOo60_HjZAAAACU"]
[Tue Jul 21 08:06:55.258253 2026] [security2:error] [pid 358661:tid 358831] [client 198.54.128.138:35814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9SzwlWhjQfpOo60_HjZAAAACU"]
[Tue Jul 21 08:06:55.273575 2026] [security2:error] [pid 352421:tid 352447] [remote 45.3.41.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9Sz8JSWzG9jbYOtu5UTAAA9xk"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:55.434094 2026] [security2:error] [pid 358661:tid 358816] [client 103.78.200.11:49371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SzwlWhjQfpOo60_HjaAAAABY"]
[Tue Jul 21 08:06:55.434203 2026] [security2:error] [pid 358661:tid 358816] [client 103.78.200.11:49371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9SzwlWhjQfpOo60_HjaAAAABY"]
[Tue Jul 21 08:06:55.505110 2026] [autoindex:error] [pid 352421:tid 352611] [client 147.185.132.15:61854] AH01276: Cannot serve directory /home3/treesa21/treeenfermagem.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:06:55.698668 2026] [security2:error] [pid 358661:tid 358874] [client 65.21.113.253:44282] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9SzwlWhjQfpOo60_HjYwAAAFA"]
[Tue Jul 21 08:06:55.832128 2026] [security2:error] [pid 358661:tid 358866] [client 20.226.60.151:12021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9SzwlWhjQfpOo60_HjdAAAAEg"]
[Tue Jul 21 08:06:55.854148 2026] [security2:error] [pid 358661:tid 358691] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SzwlWhjQfpOo60_HjdQAAExo"]
[Tue Jul 21 08:06:55.854329 2026] [security2:error] [pid 358661:tid 358813] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9SzwlWhjQfpOo60_HjdQAAExo"]
[Tue Jul 21 08:06:56.251242 2026] [security2:error] [pid 352421:tid 352584] [client 103.29.114.44:63978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S0MJSWzG9jbYOtu5UXAAAAKY"]
[Tue Jul 21 08:06:56.251710 2026] [security2:error] [pid 352421:tid 352584] [client 103.29.114.44:63978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S0MJSWzG9jbYOtu5UXAAAAKY"]
[Tue Jul 21 08:06:56.317247 2026] [security2:error] [pid 352421:tid 352524] [remote 104.207.43.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.43.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S0MJSWzG9jbYOtu5UXQAA-2Y"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:56.493245 2026] [security2:error] [pid 358661:tid 358893] [client 87.116.180.198:27263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S0AlWhjQfpOo60_HjgQAAAGM"]
[Tue Jul 21 08:06:56.493377 2026] [security2:error] [pid 358661:tid 358893] [client 87.116.180.198:27263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S0AlWhjQfpOo60_HjgQAAAGM"]
[Tue Jul 21 08:06:56.539285 2026] [security2:error] [pid 358661:tid 358799] [client 178.153.91.96:64108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9S0AlWhjQfpOo60_HjhQAAAAU"]
[Tue Jul 21 08:06:56.539472 2026] [security2:error] [pid 358661:tid 358799] [client 178.153.91.96:64108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9S0AlWhjQfpOo60_HjhQAAAAU"]
[Tue Jul 21 08:06:56.793654 2026] [security2:error] [pid 358661:tid 358822] [client 20.226.60.151:12151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/wefile.php"] [unique_id "al9S0AlWhjQfpOo60_HjhwAAABw"]
[Tue Jul 21 08:06:56.931041 2026] [security2:error] [pid 358661:tid 358794] [client 20.226.60.151:65069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9S0AlWhjQfpOo60_HjiAAAAAA"]
[Tue Jul 21 08:06:56.966602 2026] [security2:error] [pid 358661:tid 358921] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S0AlWhjQfpOo60_HjiQAAAH8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:57.041919 2026] [security2:error] [pid 352421:tid 352469] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S0cJSWzG9jbYOtu5UZwAA0y8"]
[Tue Jul 21 08:06:57.042106 2026] [security2:error] [pid 352421:tid 352629] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S0cJSWzG9jbYOtu5UZwAA0y8"]
[Tue Jul 21 08:06:57.071834 2026] [security2:error] [pid 352421:tid 352555] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9S0MJSWzG9jbYOtu5UZgAAiXA"]
[Tue Jul 21 08:06:57.074192 2026] [security2:error] [pid 352421:tid 352612] [client 20.29.126.15:20693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/2.php"] [unique_id "al9S0cJSWzG9jbYOtu5UaAAAAMI"]
[Tue Jul 21 08:06:57.110240 2026] [security2:error] [pid 352421:tid 352462] [remote 104.207.61.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S0cJSWzG9jbYOtu5UaQAAvig"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:57.129809 2026] [security2:error] [pid 358661:tid 358914] [client 20.197.192.193:3508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/ms-new.php"] [unique_id "al9S0QlWhjQfpOo60_HjjAAAAHg"]
[Tue Jul 21 08:06:57.243505 2026] [security2:error] [pid 352421:tid 352600] [client 20.226.60.151:65085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9S0cJSWzG9jbYOtu5UawAAALY"]
[Tue Jul 21 08:06:57.440120 2026] [security2:error] [pid 358661:tid 358867] [client 92.119.178.3:57418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9S0QlWhjQfpOo60_HjkQAAAEk"]
[Tue Jul 21 08:06:57.440210 2026] [security2:error] [pid 358661:tid 358867] [client 92.119.178.3:57418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9S0QlWhjQfpOo60_HjkQAAAEk"]
[Tue Jul 21 08:06:57.544412 2026] [security2:error] [pid 352421:tid 352656] [client 117.210.135.0:56522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S0cJSWzG9jbYOtu5UcQAAAO4"]
[Tue Jul 21 08:06:57.545029 2026] [security2:error] [pid 352421:tid 352656] [client 117.210.135.0:56522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S0cJSWzG9jbYOtu5UcQAAAO4"]
[Tue Jul 21 08:06:57.597724 2026] [security2:error] [pid 358661:tid 358824] [client 172.233.172.167:54906] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "mgdcondominial.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9S0QlWhjQfpOo60_HjlAAAAB4"]
[Tue Jul 21 08:06:57.604804 2026] [security2:error] [pid 352421:tid 352448] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S0cJSWzG9jbYOtu5UcgAA_Bo"]
[Tue Jul 21 08:06:57.604993 2026] [security2:error] [pid 352421:tid 352670] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S0cJSWzG9jbYOtu5UcgAA_Bo"]
[Tue Jul 21 08:06:57.615481 2026] [security2:error] [pid 358661:tid 358763] [remote 182.77.62.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9S0QlWhjQfpOo60_HjlQAAfWI"]
[Tue Jul 21 08:06:57.652154 2026] [security2:error] [pid 358661:tid 358889] [client 117.247.80.59:15087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S0QlWhjQfpOo60_HjlgAAAF8"]
[Tue Jul 21 08:06:57.652263 2026] [security2:error] [pid 358661:tid 358889] [client 117.247.80.59:15087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S0QlWhjQfpOo60_HjlgAAAF8"]
[Tue Jul 21 08:06:57.709901 2026] [security2:error] [pid 358661:tid 358892] [client 172.233.172.167:54906] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "mgdcondominial.com.br"] [uri "/"] [unique_id "al9S0QlWhjQfpOo60_HjmAAAAGI"]
[Tue Jul 21 08:06:57.860581 2026] [security2:error] [pid 358661:tid 358908] [client 20.226.60.151:12356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9S0QlWhjQfpOo60_HjnAAAAHI"]
[Tue Jul 21 08:06:58.060113 2026] [security2:error] [pid 352421:tid 352506] [remote 209.50.169.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.169.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S0cJSWzG9jbYOtu5UdQAAzFQ"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:06:58.093348 2026] [security2:error] [pid 358661:tid 358894] [client 20.226.60.151:65040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/xyn.php"] [unique_id "al9S0glWhjQfpOo60_HjngAAAGQ"]
[Tue Jul 21 08:06:58.139659 2026] [security2:error] [pid 358661:tid 358893] [client 65.21.113.253:46568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9S0glWhjQfpOo60_HjnwAAAGM"]
[Tue Jul 21 08:06:58.159950 2026] [security2:error] [pid 358661:tid 358799] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S0glWhjQfpOo60_HjoAAAAAU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:58.160074 2026] [security2:error] [pid 358661:tid 358799] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S0glWhjQfpOo60_HjoAAAAAU"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:06:58.461186 2026] [security2:error] [pid 358661:tid 358669] [remote 45.117.83.212:49172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/wp-login.php"] [unique_id "al9S0glWhjQfpOo60_HjogAANQQ"]
[Tue Jul 21 08:06:58.648028 2026] [security2:error] [pid 358661:tid 358895] [client 20.29.126.15:5263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/asd.php"] [unique_id "al9S0glWhjQfpOo60_HjowAAAGU"]
[Tue Jul 21 08:06:58.686689 2026] [security2:error] [pid 358661:tid 358831] [client 204.8.98.45:55540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9S0glWhjQfpOo60_HjpAAAACU"]
[Tue Jul 21 08:06:58.686791 2026] [security2:error] [pid 358661:tid 358831] [client 204.8.98.45:55540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9S0glWhjQfpOo60_HjpAAAACU"]
[Tue Jul 21 08:06:58.943875 2026] [security2:error] [pid 358661:tid 358846] [client 20.226.60.151:65039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/patie.php"] [unique_id "al9S0glWhjQfpOo60_HjqgAAADQ"]
[Tue Jul 21 08:06:58.998459 2026] [security2:error] [pid 352421:tid 352556] [client 92.119.178.3:43478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9S0sJSWzG9jbYOtu5UhAAAAIo"]
[Tue Jul 21 08:06:58.998554 2026] [security2:error] [pid 352421:tid 352556] [client 92.119.178.3:43478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9S0sJSWzG9jbYOtu5UhAAAAIo"]
[Tue Jul 21 08:06:59.194529 2026] [security2:error] [pid 358661:tid 358851] [client 65.21.113.253:42764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S0glWhjQfpOo60_HjpgAAADk"]
[Tue Jul 21 08:06:59.350296 2026] [security2:error] [pid 352421:tid 352617] [client 38.100.221.102:18770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S08JSWzG9jbYOtu5UigAAAMc"]
[Tue Jul 21 08:06:59.350535 2026] [security2:error] [pid 352421:tid 352617] [client 38.100.221.102:18770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S08JSWzG9jbYOtu5UigAAAMc"]
[Tue Jul 21 08:06:59.516775 2026] [security2:error] [pid 358661:tid 358824] [client 20.226.60.151:64842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/aa.php"] [unique_id "al9S0wlWhjQfpOo60_HjtAAAAB4"]
[Tue Jul 21 08:07:00.101417 2026] [security2:error] [pid 358661:tid 358755] [remote 65.111.8.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S0wlWhjQfpOo60_HjrQAAQlo"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:00.128817 2026] [security2:error] [pid 358661:tid 358798] [client 65.21.113.253:43266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S0wlWhjQfpOo60_HjtgAAAAQ"]
[Tue Jul 21 08:07:00.194831 2026] [security2:error] [pid 358661:tid 358768] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S1AlWhjQfpOo60_HjvwAACGc"]
[Tue Jul 21 08:07:00.195025 2026] [security2:error] [pid 358661:tid 358802] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S1AlWhjQfpOo60_HjvwAACGc"]
[Tue Jul 21 08:07:00.275130 2026] [access_compat:error] [pid 358661:tid 358897] [client 162.241.63.68:27678] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:07:00.293227 2026] [security2:error] [pid 358661:tid 358803] [client 20.226.60.151:65024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/xwpg.php"] [unique_id "al9S1AlWhjQfpOo60_HjwwAAAAk"]
[Tue Jul 21 08:07:00.476968 2026] [security2:error] [pid 358661:tid 358895] [client 20.29.126.15:2968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/default.php"] [unique_id "al9S1AlWhjQfpOo60_HjxgAAAGU"]
[Tue Jul 21 08:07:00.647123 2026] [security2:error] [pid 352421:tid 352559] [client 20.226.60.151:64864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/ops.php"] [unique_id "al9S1MJSWzG9jbYOtu5UmAAAAI0"]
[Tue Jul 21 08:07:00.964329 2026] [security2:error] [pid 358661:tid 358878] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S1AlWhjQfpOo60_HjzQAAAFQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:00.988991 2026] [security2:error] [pid 358661:tid 358852] [client 74.7.241.140:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "henricconosvitzgarci1743697324314.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9S1AlWhjQfpOo60_HjzgAAOj0"]
[Tue Jul 21 08:07:01.123953 2026] [security2:error] [pid 352421:tid 352555] [client 20.226.60.151:65052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/mac.php"] [unique_id "al9S1cJSWzG9jbYOtu5UoQAAAIk"]
[Tue Jul 21 08:07:01.185359 2026] [security2:error] [pid 358661:tid 358795] [client 41.68.90.219:56319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S1QlWhjQfpOo60_Hj0AAAAAE"]
[Tue Jul 21 08:07:01.186160 2026] [security2:error] [pid 358661:tid 358795] [client 41.68.90.219:56319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S1QlWhjQfpOo60_Hj0AAAAAE"]
[Tue Jul 21 08:07:01.188882 2026] [security2:error] [pid 358661:tid 358918] [client 202.143.127.214:64530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S1QlWhjQfpOo60_Hj0QAAAHw"]
[Tue Jul 21 08:07:01.189002 2026] [security2:error] [pid 358661:tid 358918] [client 202.143.127.214:64530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S1QlWhjQfpOo60_Hj0QAAAHw"]
[Tue Jul 21 08:07:01.239886 2026] [security2:error] [pid 352421:tid 352600] [client 20.226.60.151:64835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/mg.php"] [unique_id "al9S1cJSWzG9jbYOtu5UpQAAALY"]
[Tue Jul 21 08:07:01.315795 2026] [security2:error] [pid 352421:tid 352527] [remote 45.3.38.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.38.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S1cJSWzG9jbYOtu5UowAAvmk"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:01.329470 2026] [security2:error] [pid 358661:tid 358851] [client 20.226.60.151:64843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-post-data.php"] [unique_id "al9S1QlWhjQfpOo60_Hj0gAAADk"]
[Tue Jul 21 08:07:01.363522 2026] [security2:error] [pid 358661:tid 358880] [client 20.226.60.151:64860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/pucci.php"] [unique_id "al9S1QlWhjQfpOo60_Hj1AAAAFY"]
[Tue Jul 21 08:07:01.468050 2026] [security2:error] [pid 358661:tid 358867] [client 20.226.60.151:64846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/black.php"] [unique_id "al9S1QlWhjQfpOo60_Hj1wAAAEk"]
[Tue Jul 21 08:07:01.651916 2026] [security2:error] [pid 352421:tid 352578] [client 109.60.28.94:51490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S1cJSWzG9jbYOtu5UsQAAAKA"]
[Tue Jul 21 08:07:01.652081 2026] [security2:error] [pid 352421:tid 352578] [client 109.60.28.94:51490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S1cJSWzG9jbYOtu5UsQAAAKA"]
[Tue Jul 21 08:07:01.784067 2026] [security2:error] [pid 358661:tid 358833] [client 20.226.60.151:65075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/zlece.php"] [unique_id "al9S1QlWhjQfpOo60_Hj2wAAACc"]
[Tue Jul 21 08:07:01.810280 2026] [security2:error] [pid 352421:tid 352572] [client 61.1.167.83:54217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S1cJSWzG9jbYOtu5UtAAAAJo"]
[Tue Jul 21 08:07:01.810447 2026] [security2:error] [pid 352421:tid 352572] [client 61.1.167.83:54217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S1cJSWzG9jbYOtu5UtAAAAJo"]
[Tue Jul 21 08:07:01.864597 2026] [security2:error] [pid 352421:tid 352640] [client 103.166.103.129:27867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9S1cJSWzG9jbYOtu5UtQAAAN4"]
[Tue Jul 21 08:07:01.864750 2026] [security2:error] [pid 352421:tid 352640] [client 103.166.103.129:27867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9S1cJSWzG9jbYOtu5UtQAAAN4"]
[Tue Jul 21 08:07:01.920714 2026] [security2:error] [pid 358661:tid 358873] [client 20.226.60.151:12002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9S1QlWhjQfpOo60_Hj3QAAAE8"]
[Tue Jul 21 08:07:02.159466 2026] [security2:error] [pid 358661:tid 358894] [client 20.197.192.193:39268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/track.php"] [unique_id "al9S1glWhjQfpOo60_Hj4AAAAGQ"]
[Tue Jul 21 08:07:02.234583 2026] [security2:error] [pid 352421:tid 352589] [client 20.226.60.151:65028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/vssrs.php"] [unique_id "al9S1sJSWzG9jbYOtu5UuQAAAKs"]
[Tue Jul 21 08:07:02.449957 2026] [fcgid:warn] [pid 358661:tid 358905] (70014)End of file found: [client 199.45.154.128:41370] mod_fcgid: can't get data from http client
[Tue Jul 21 08:07:02.467988 2026] [security2:error] [pid 358661:tid 358871] [client 185.251.19.67:60439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9S1glWhjQfpOo60_Hj5gAAAE0"]
[Tue Jul 21 08:07:02.471155 2026] [security2:error] [pid 358661:tid 358903] [client 185.251.19.67:57841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9S1glWhjQfpOo60_Hj5wAAAG0"]
[Tue Jul 21 08:07:02.497523 2026] [security2:error] [pid 358661:tid 358847] [client 65.21.113.253:46568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9S1glWhjQfpOo60_Hj6AAAADU"]
[Tue Jul 21 08:07:02.519450 2026] [security2:error] [pid 352421:tid 352598] [client 20.226.60.151:11980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/8.php"] [unique_id "al9S1sJSWzG9jbYOtu5UvgAAALQ"]
[Tue Jul 21 08:07:02.556689 2026] [security2:error] [pid 358661:tid 358800] [client 20.226.60.151:64867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wicked.php"] [unique_id "al9S1glWhjQfpOo60_Hj6gAAAAY"]
[Tue Jul 21 08:07:02.679036 2026] [security2:error] [pid 352421:tid 352645] [client 204.8.98.45:55542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9S1sJSWzG9jbYOtu5UwwAAAOM"]
[Tue Jul 21 08:07:02.679131 2026] [security2:error] [pid 352421:tid 352645] [client 204.8.98.45:55542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9S1sJSWzG9jbYOtu5UwwAAAOM"]
[Tue Jul 21 08:07:02.787062 2026] [security2:error] [pid 358661:tid 358884] [client 142.44.220.56:58082] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "vestfitness.com.br"] [uri "/robots.txt"] [unique_id "al9S1glWhjQfpOo60_Hj7wAAAFo"]
[Tue Jul 21 08:07:02.787202 2026] [security2:error] [pid 358661:tid 358884] [client 142.44.220.56:58082] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vestfitness.com.br"] [uri "/robots.txt"] [unique_id "al9S1glWhjQfpOo60_Hj7wAAAFo"]
[Tue Jul 21 08:07:02.935962 2026] [security2:error] [pid 358661:tid 358794] [client 20.226.60.151:64859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/24.php"] [unique_id "al9S1glWhjQfpOo60_Hj8AAAAAA"]
[Tue Jul 21 08:07:03.041285 2026] [security2:error] [pid 352421:tid 352434] [remote 216.26.248.208:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.248.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S1sJSWzG9jbYOtu5UxwAAsww"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:03.053847 2026] [security2:error] [pid 352421:tid 352637] [client 20.226.60.151:12096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9S18JSWzG9jbYOtu5UygAAANs"]
[Tue Jul 21 08:07:03.054251 2026] [security2:error] [pid 358661:tid 358764] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9S1wlWhjQfpOo60_Hj9AAAAWM"]
[Tue Jul 21 08:07:03.054414 2026] [security2:error] [pid 358661:tid 358795] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9S1wlWhjQfpOo60_Hj9AAAAWM"]
[Tue Jul 21 08:07:03.095580 2026] [security2:error] [pid 358661:tid 358822] [client 65.21.113.253:43266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S1glWhjQfpOo60_Hj7gAAABw"]
[Tue Jul 21 08:07:03.300074 2026] [security2:error] [pid 352421:tid 352596] [client 120.56.162.40:56398] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S18JSWzG9jbYOtu5UzAAAALI"]
[Tue Jul 21 08:07:03.300274 2026] [security2:error] [pid 352421:tid 352596] [client 120.56.162.40:56398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S18JSWzG9jbYOtu5UzAAAALI"]
[Tue Jul 21 08:07:03.365044 2026] [security2:error] [pid 358661:tid 358910] [client 20.226.60.151:65048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/xacs.php"] [unique_id "al9S1wlWhjQfpOo60_Hj-gAAAHQ"]
[Tue Jul 21 08:07:03.472735 2026] [security2:error] [pid 358661:tid 358825] [client 20.29.126.15:3006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/gettest.php"] [unique_id "al9S1wlWhjQfpOo60_Hj-wAAAB8"]
[Tue Jul 21 08:07:03.568085 2026] [security2:error] [pid 358661:tid 358798] [client 45.132.227.201:65465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9S1glWhjQfpOo60_Hj4wAAAAQ"]
[Tue Jul 21 08:07:03.599795 2026] [security2:error] [pid 358661:tid 358858] [client 20.197.192.193:39283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/kq1.php"] [unique_id "al9S1wlWhjQfpOo60_Hj_wAAAEA"]
[Tue Jul 21 08:07:03.658582 2026] [security2:error] [pid 358661:tid 358860] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S1wlWhjQfpOo60_HkAQAAAEI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:03.749452 2026] [security2:error] [pid 358661:tid 358842] [client 92.119.178.3:35018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.178.119.92.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9S1wlWhjQfpOo60_HkBgAAADA"]
[Tue Jul 21 08:07:03.749558 2026] [security2:error] [pid 358661:tid 358842] [client 92.119.178.3:35018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9S1wlWhjQfpOo60_HkBgAAADA"]
[Tue Jul 21 08:07:03.752734 2026] [security2:error] [pid 358661:tid 358852] [client 150.129.202.39:64881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S1wlWhjQfpOo60_HkBwAAADo"]
[Tue Jul 21 08:07:03.752856 2026] [security2:error] [pid 358661:tid 358852] [client 150.129.202.39:64881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S1wlWhjQfpOo60_HkBwAAADo"]
[Tue Jul 21 08:07:04.022555 2026] [security2:error] [pid 352421:tid 352573] [client 102.206.115.33:64923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9S2MJSWzG9jbYOtu5U1wAAAJs"]
[Tue Jul 21 08:07:04.024710 2026] [security2:error] [pid 352421:tid 352573] [client 102.206.115.33:64923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9S2MJSWzG9jbYOtu5U1wAAAJs"]
[Tue Jul 21 08:07:04.132228 2026] [security2:error] [pid 358661:tid 358813] [client 65.21.113.253:43268] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S1wlWhjQfpOo60_HkAgAAABM"]
[Tue Jul 21 08:07:04.157320 2026] [security2:error] [pid 358661:tid 358859] [client 20.226.60.151:12113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/f6.php"] [unique_id "al9S2AlWhjQfpOo60_HkEQAAAEE"]
[Tue Jul 21 08:07:04.198779 2026] [security2:error] [pid 352421:tid 352610] [client 51.161.37.203:51278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "vestfitness.com.br"] [uri "/"] [unique_id "al9S2MJSWzG9jbYOtu5U3QAAAMA"]
[Tue Jul 21 08:07:04.198888 2026] [security2:error] [pid 352421:tid 352610] [client 51.161.37.203:51278] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vestfitness.com.br"] [uri "/"] [unique_id "al9S2MJSWzG9jbYOtu5U3QAAAMA"]
[Tue Jul 21 08:07:04.252855 2026] [security2:error] [pid 358661:tid 358846] [client 20.226.60.151:56386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/zildan.php"] [unique_id "al9S2AlWhjQfpOo60_HkEgAAADQ"]
[Tue Jul 21 08:07:04.276109 2026] [security2:error] [pid 352421:tid 352444] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9S2MJSWzG9jbYOtu5U3gAAvhY"]
[Tue Jul 21 08:07:04.276331 2026] [security2:error] [pid 352421:tid 352608] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9S2MJSWzG9jbYOtu5U3gAAvhY"]
[Tue Jul 21 08:07:04.297118 2026] [security2:error] [pid 358661:tid 358746] [remote 216.26.224.29:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.224.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S2AlWhjQfpOo60_HkEAAAbFE"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:04.854900 2026] [proxy:error] [pid 358661:tid 358889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:07:04.854986 2026] [proxy_http:error] [pid 358661:tid 358889] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:07:04.855742 2026] [proxy:error] [pid 358661:tid 358889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:07:04.855778 2026] [proxy_http:error] [pid 358661:tid 358889] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:07:04.880427 2026] [security2:error] [pid 358661:tid 358891] [client 20.226.60.151:65071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/csa.php"] [unique_id "al9S2AlWhjQfpOo60_HkIQAAAGE"]
[Tue Jul 21 08:07:04.895001 2026] [security2:error] [pid 358661:tid 358910] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S2AlWhjQfpOo60_HkIgAAAHQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:04.895145 2026] [security2:error] [pid 358661:tid 358910] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S2AlWhjQfpOo60_HkIgAAAHQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:05.106783 2026] [security2:error] [pid 358661:tid 358825] [client 20.226.60.151:12366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/inputs.php"] [unique_id "al9S2QlWhjQfpOo60_HkJQAAAB8"]
[Tue Jul 21 08:07:05.247585 2026] [proxy:error] [pid 352421:tid 352589] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:07:05.247666 2026] [proxy_http:error] [pid 352421:tid 352589] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:07:05.248382 2026] [proxy:error] [pid 352421:tid 352589] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:07:05.248423 2026] [proxy_http:error] [pid 352421:tid 352589] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:07:05.565935 2026] [security2:error] [pid 358661:tid 358873] [client 20.226.60.151:56388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/w3llscc.php"] [unique_id "al9S2QlWhjQfpOo60_HkLQAAAE8"]
[Tue Jul 21 08:07:05.931129 2026] [security2:error] [pid 352421:tid 352511] [remote 216.26.245.113:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.245.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S2cJSWzG9jbYOtu5U9gAAolk"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:06.035396 2026] [security2:error] [pid 352421:tid 352492] [remote 20.153.140.50:51362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9S2sJSWzG9jbYOtu5U-gAAlkY"]
[Tue Jul 21 08:07:06.202920 2026] [security2:error] [pid 358661:tid 358868] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9S2glWhjQfpOo60_HkNAAAAEo"]
[Tue Jul 21 08:07:06.239017 2026] [security2:error] [pid 358661:tid 358894] [client 20.226.60.151:12375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/inputs.php"] [unique_id "al9S2glWhjQfpOo60_HkNgAAAGQ"]
[Tue Jul 21 08:07:06.263413 2026] [security2:error] [pid 358661:tid 358860] [client 103.78.200.11:49871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S2glWhjQfpOo60_HkOAAAAEI"]
[Tue Jul 21 08:07:06.263572 2026] [security2:error] [pid 358661:tid 358860] [client 103.78.200.11:49871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S2glWhjQfpOo60_HkOAAAAEI"]
[Tue Jul 21 08:07:06.331682 2026] [security2:error] [pid 358661:tid 358731] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9S2glWhjQfpOo60_HkOQAADEI"]
[Tue Jul 21 08:07:06.331968 2026] [security2:error] [pid 358661:tid 358806] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9S2glWhjQfpOo60_HkOQAADEI"]
[Tue Jul 21 08:07:06.399867 2026] [security2:error] [pid 352421:tid 352590] [client 20.226.60.151:65064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wpx.php"] [unique_id "al9S2sJSWzG9jbYOtu5U_wAAAKw"]
[Tue Jul 21 08:07:06.649698 2026] [security2:error] [pid 358661:tid 358867] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9S2glWhjQfpOo60_HkQAAAAEk"]
[Tue Jul 21 08:07:06.874007 2026] [security2:error] [pid 358661:tid 358880] [client 65.21.113.253:46568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9S2glWhjQfpOo60_HkRAAAAFY"]
[Tue Jul 21 08:07:06.893352 2026] [security2:error] [pid 358661:tid 358844] [client 1.39.117.130:59239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S2AlWhjQfpOo60_HkHAAAADI"]
[Tue Jul 21 08:07:06.950057 2026] [security2:error] [pid 358661:tid 358881] [client 103.29.114.44:64618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S2glWhjQfpOo60_HkRgAAAFc"]
[Tue Jul 21 08:07:06.950174 2026] [security2:error] [pid 358661:tid 358881] [client 103.29.114.44:64618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S2glWhjQfpOo60_HkRgAAAFc"]
[Tue Jul 21 08:07:06.974444 2026] [security2:error] [pid 358661:tid 358812] [client 178.153.91.96:44333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9S2glWhjQfpOo60_HkRwAAABI"]
[Tue Jul 21 08:07:06.974644 2026] [security2:error] [pid 358661:tid 358812] [client 178.153.91.96:44333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9S2glWhjQfpOo60_HkRwAAABI"]
[Tue Jul 21 08:07:06.994348 2026] [security2:error] [pid 358661:tid 358846] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9S2glWhjQfpOo60_HkNQAANCY"]
[Tue Jul 21 08:07:07.003171 2026] [security2:error] [pid 358661:tid 358672] [remote 104.207.47.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.47.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S2glWhjQfpOo60_HkSAAADgc"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:07.045262 2026] [security2:error] [pid 352421:tid 352553] [client 20.226.60.151:12010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/classwithtostring.php"] [unique_id "al9S28JSWzG9jbYOtu5VBQAAAIc"]
[Tue Jul 21 08:07:07.050942 2026] [security2:error] [pid 358661:tid 358820] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9S2wlWhjQfpOo60_HkSQAAABo"]
[Tue Jul 21 08:07:07.215417 2026] [security2:error] [pid 352421:tid 352632] [client 87.116.180.198:27310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S28JSWzG9jbYOtu5VBwAAANY"]
[Tue Jul 21 08:07:07.215548 2026] [security2:error] [pid 352421:tid 352632] [client 87.116.180.198:27310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S28JSWzG9jbYOtu5VBwAAANY"]
[Tue Jul 21 08:07:07.273470 2026] [security2:error] [pid 352421:tid 352596] [client 20.226.60.151:65057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-css.php"] [unique_id "al9S28JSWzG9jbYOtu5VCQAAALI"]
[Tue Jul 21 08:07:07.503137 2026] [security2:error] [pid 352421:tid 352600] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9S28JSWzG9jbYOtu5VDwAAALY"]
[Tue Jul 21 08:07:07.554336 2026] [security2:error] [pid 358661:tid 358842] [client 65.21.113.253:43268] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S2wlWhjQfpOo60_HkTAAAADA"]
[Tue Jul 21 08:07:07.558785 2026] [security2:error] [pid 358661:tid 358770] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S2wlWhjQfpOo60_HkUQAADWk"]
[Tue Jul 21 08:07:07.558916 2026] [security2:error] [pid 358661:tid 358807] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S2wlWhjQfpOo60_HkUQAADWk"]
[Tue Jul 21 08:07:07.767277 2026] [security2:error] [pid 352421:tid 352656] [client 20.226.60.151:64832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/ho.php"] [unique_id "al9S28JSWzG9jbYOtu5VEgAAAO4"]
[Tue Jul 21 08:07:07.874246 2026] [security2:error] [pid 358661:tid 358795] [client 198.54.128.138:47730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9S2wlWhjQfpOo60_HkVgAAAAE"]
[Tue Jul 21 08:07:07.874344 2026] [security2:error] [pid 358661:tid 358795] [client 198.54.128.138:47730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9S2wlWhjQfpOo60_HkVgAAAAE"]
[Tue Jul 21 08:07:07.884169 2026] [security2:error] [pid 358661:tid 358829] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S2wlWhjQfpOo60_HkVwAAACM"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:08.022394 2026] [security2:error] [pid 352421:tid 352552] [client 20.29.126.15:2397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/tfm.php"] [unique_id "al9S3MJSWzG9jbYOtu5VGAAAAIY"]
[Tue Jul 21 08:07:08.057842 2026] [security2:error] [pid 352421:tid 352612] [client 117.210.135.0:57171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S3MJSWzG9jbYOtu5VGgAAAMI"]
[Tue Jul 21 08:07:08.057969 2026] [security2:error] [pid 352421:tid 352612] [client 117.210.135.0:57171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S3MJSWzG9jbYOtu5VGgAAAMI"]
[Tue Jul 21 08:07:08.094189 2026] [security2:error] [pid 358661:tid 358794] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9S2wlWhjQfpOo60_HkWAAAAEs"]
[Tue Jul 21 08:07:08.192140 2026] [security2:error] [pid 352421:tid 352576] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9S3MJSWzG9jbYOtu5VHQAAAJ4"]
[Tue Jul 21 08:07:08.310232 2026] [security2:error] [pid 352421:tid 352567] [client 65.21.113.253:43276] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S28JSWzG9jbYOtu5VFQAAAJU"]
[Tue Jul 21 08:07:08.311612 2026] [security2:error] [pid 358661:tid 358878] [client 117.247.80.59:12965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S3AlWhjQfpOo60_HkWwAAAFQ"]
[Tue Jul 21 08:07:08.311847 2026] [security2:error] [pid 358661:tid 358878] [client 117.247.80.59:12965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S3AlWhjQfpOo60_HkWwAAAFQ"]
[Tue Jul 21 08:07:08.418499 2026] [security2:error] [pid 352421:tid 352658] [client 20.226.60.151:12378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9S3MJSWzG9jbYOtu5VJAAAAPA"]
[Tue Jul 21 08:07:08.557440 2026] [security2:error] [pid 358661:tid 358687] [remote 104.207.56.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.56.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S3AlWhjQfpOo60_HkXAAAHxY"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:08.573663 2026] [security2:error] [pid 352421:tid 352566] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9S3MJSWzG9jbYOtu5VKwAAAJQ"]
[Tue Jul 21 08:07:08.612415 2026] [security2:error] [pid 352421:tid 352665] [client 20.226.60.151:64872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/xy.php"] [unique_id "al9S3MJSWzG9jbYOtu5VLAAAAPc"]
[Tue Jul 21 08:07:08.665954 2026] [security2:error] [pid 352421:tid 352541] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S3MJSWzG9jbYOtu5VLQAArXc"]
[Tue Jul 21 08:07:08.666136 2026] [security2:error] [pid 352421:tid 352591] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S3MJSWzG9jbYOtu5VLQAArXc"]
[Tue Jul 21 08:07:08.955041 2026] [security2:error] [pid 358661:tid 358909] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9S3AlWhjQfpOo60_HkZQAAAHM"]
[Tue Jul 21 08:07:08.972216 2026] [security2:error] [pid 358661:tid 358820] [client 20.226.60.151:12377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/wp-blog.php"] [unique_id "al9S3AlWhjQfpOo60_HkZgAAABo"]
[Tue Jul 21 08:07:09.132671 2026] [security2:error] [pid 358661:tid 358859] [client 20.226.60.151:65031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/loader.php"] [unique_id "al9S3QlWhjQfpOo60_HkbAAAAEE"]
[Tue Jul 21 08:07:09.228516 2026] [security2:error] [pid 358661:tid 358781] [remote 199.189.225.40:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produto-express.com"] [uri "/wp-login.php"] [unique_id "al9S3QlWhjQfpOo60_HkbQAAS3Q"]
[Tue Jul 21 08:07:09.351732 2026] [security2:error] [pid 352421:tid 352630] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9S3cJSWzG9jbYOtu5VNQAAANQ"]
[Tue Jul 21 08:07:09.544769 2026] [security2:error] [pid 358661:tid 358903] [client 20.226.60.151:64875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/spadex.php"] [unique_id "al9S3QlWhjQfpOo60_HkcgAAAG0"]
[Tue Jul 21 08:07:09.739012 2026] [security2:error] [pid 358661:tid 358837] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9S3QlWhjQfpOo60_HkeQAAACs"]
[Tue Jul 21 08:07:09.947885 2026] [security2:error] [pid 352421:tid 352676] [client 38.100.221.102:17226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S3cJSWzG9jbYOtu5VPgAAAQI"]
[Tue Jul 21 08:07:09.948037 2026] [security2:error] [pid 352421:tid 352676] [client 38.100.221.102:17226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S3cJSWzG9jbYOtu5VPgAAAQI"]
[Tue Jul 21 08:07:10.099382 2026] [security2:error] [pid 358661:tid 358868] [client 8.208.9.170:52951] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ssvistorias.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9S3QlWhjQfpOo60_HkegAAAEo"]
[Tue Jul 21 08:07:10.120626 2026] [security2:error] [pid 352421:tid 352663] [client 20.226.60.151:56320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/2x.php"] [unique_id "al9S3sJSWzG9jbYOtu5VQgAAAPU"]
[Tue Jul 21 08:07:10.156428 2026] [security2:error] [pid 352421:tid 352564] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9S3sJSWzG9jbYOtu5VQwAAAJI"]
[Tue Jul 21 08:07:10.419948 2026] [security2:error] [pid 358661:tid 358910] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S3glWhjQfpOo60_HkfwAAAHQ"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:10.555299 2026] [security2:error] [pid 352421:tid 352623] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9S3sJSWzG9jbYOtu5VSgAAAM0"]
[Tue Jul 21 08:07:10.665254 2026] [security2:error] [pid 352421:tid 352432] [remote 34.24.57.82:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dees.ind.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9S3sJSWzG9jbYOtu5VTgAA0Qo"]
[Tue Jul 21 08:07:10.705998 2026] [security2:error] [pid 352421:tid 352656] [client 8.208.9.170:52964] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ssvistorias.com.br"] [uri "/"] [unique_id "al9S3sJSWzG9jbYOtu5VTwAAAO4"]
[Tue Jul 21 08:07:10.878116 2026] [security2:error] [pid 358661:tid 358798] [client 20.226.60.151:12098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9S3glWhjQfpOo60_HkgwAAAAQ"]
[Tue Jul 21 08:07:10.931996 2026] [security2:error] [pid 352421:tid 352574] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9S3sJSWzG9jbYOtu5VUwAAAJw"]
[Tue Jul 21 08:07:10.984570 2026] [security2:error] [pid 352421:tid 352622] [client 20.226.60.151:65068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/ctex1.php"] [unique_id "al9S3sJSWzG9jbYOtu5VWAAAAMw"]
[Tue Jul 21 08:07:11.112901 2026] [security2:error] [pid 352421:tid 352544] [remote 34.24.57.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.24.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dees.ind.br"] [uri "/xmlrpc.php"] [unique_id "al9S38JSWzG9jbYOtu5VWgAAuXo"]
[Tue Jul 21 08:07:11.175388 2026] [security2:error] [pid 358661:tid 358839] [client 20.29.126.15:16092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/ws81.php"] [unique_id "al9S3wlWhjQfpOo60_HkigAAAC0"]
[Tue Jul 21 08:07:11.312341 2026] [security2:error] [pid 352421:tid 352483] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S38JSWzG9jbYOtu5VXQAA3j0"]
[Tue Jul 21 08:07:11.312652 2026] [security2:error] [pid 352421:tid 352640] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S38JSWzG9jbYOtu5VXQAA3j0"]
[Tue Jul 21 08:07:11.325998 2026] [security2:error] [pid 358661:tid 358760] [remote 216.26.246.178:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.246.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S3glWhjQfpOo60_HkfQAAQl8"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:11.326514 2026] [security2:error] [pid 352421:tid 352602] [client 8.208.9.170:52973] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ssvistorias.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9S38JSWzG9jbYOtu5VXgAAALg"]
[Tue Jul 21 08:07:11.359458 2026] [security2:error] [pid 352421:tid 352639] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9S38JSWzG9jbYOtu5VYAAAAN0"]
[Tue Jul 21 08:07:11.505654 2026] [security2:error] [pid 358661:tid 358869] [client 20.226.60.151:12028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/ms-edit.php"] [unique_id "al9S3wlWhjQfpOo60_HkjwAAAEs"]
[Tue Jul 21 08:07:11.553501 2026] [security2:error] [pid 352421:tid 352529] [remote 45.14.225.216:51884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.225.14.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9S3cJSWzG9jbYOtu5VOgAArGs"]
[Tue Jul 21 08:07:11.560368 2026] [security2:error] [pid 358661:tid 358810] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S3wlWhjQfpOo60_HkkgAAABA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:11.560502 2026] [security2:error] [pid 358661:tid 358810] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S3wlWhjQfpOo60_HkkgAAABA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:11.662069 2026] [security2:error] [pid 358661:tid 358836] [client 184.75.221.3:43896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9S3wlWhjQfpOo60_HklAAAACo"]
[Tue Jul 21 08:07:11.662158 2026] [security2:error] [pid 358661:tid 358836] [client 184.75.221.3:43896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9S3wlWhjQfpOo60_HklAAAACo"]
[Tue Jul 21 08:07:11.716177 2026] [security2:error] [pid 358661:tid 358799] [client 41.68.90.219:56791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S3wlWhjQfpOo60_HklgAAAAU"]
[Tue Jul 21 08:07:11.717059 2026] [security2:error] [pid 358661:tid 358799] [client 41.68.90.219:56791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S3wlWhjQfpOo60_HklgAAAAU"]
[Tue Jul 21 08:07:11.783554 2026] [security2:error] [pid 358661:tid 358835] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9S3wlWhjQfpOo60_HkmAAAACk"]
[Tue Jul 21 08:07:11.935521 2026] [security2:error] [pid 352421:tid 352611] [client 8.208.9.170:52979] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ssvistorias.com.br"] [uri "/"] [unique_id "al9S38JSWzG9jbYOtu5VaQAAAME"]
[Tue Jul 21 08:07:11.988694 2026] [security2:error] [pid 352421:tid 352594] [client 175.144.82.48:56085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S38JSWzG9jbYOtu5VbgAAALA"]
[Tue Jul 21 08:07:11.988863 2026] [security2:error] [pid 352421:tid 352594] [client 175.144.82.48:56085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S38JSWzG9jbYOtu5VbgAAALA"]
[Tue Jul 21 08:07:12.071193 2026] [security2:error] [pid 352421:tid 352598] [client 65.21.113.253:43276] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S38JSWzG9jbYOtu5VZgAAALQ"]
[Tue Jul 21 08:07:12.192501 2026] [security2:error] [pid 352421:tid 352632] [client 20.226.60.151:11972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9S4MJSWzG9jbYOtu5VcAAAANY"]
[Tue Jul 21 08:07:12.293558 2026] [security2:error] [pid 358661:tid 358840] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9S4AlWhjQfpOo60_HkmgAAAC4"]
[Tue Jul 21 08:07:12.358233 2026] [security2:error] [pid 358661:tid 358867] [client 20.226.60.151:64874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/edorxrr.php"] [unique_id "al9S4AlWhjQfpOo60_HknAAAAEk"]
[Tue Jul 21 08:07:12.379501 2026] [security2:error] [pid 358661:tid 358899] [client 103.166.103.129:28422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9S4AlWhjQfpOo60_HknQAAAGk"]
[Tue Jul 21 08:07:12.384726 2026] [security2:error] [pid 358661:tid 358899] [client 103.166.103.129:28422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9S4AlWhjQfpOo60_HknQAAAGk"]
[Tue Jul 21 08:07:12.390864 2026] [security2:error] [pid 352421:tid 352424] [remote 209.50.174.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.174.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S4MJSWzG9jbYOtu5VcwAAsgI"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:12.404628 2026] [security2:error] [pid 358661:tid 358854] [client 109.60.28.94:51946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S4AlWhjQfpOo60_HkngAAADw"]
[Tue Jul 21 08:07:12.404730 2026] [security2:error] [pid 358661:tid 358854] [client 109.60.28.94:51946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S4AlWhjQfpOo60_HkngAAADw"]
[Tue Jul 21 08:07:12.531600 2026] [security2:error] [pid 358661:tid 358918] [client 202.143.127.214:65008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S4AlWhjQfpOo60_HkoQAAAHw"]
[Tue Jul 21 08:07:12.531750 2026] [security2:error] [pid 358661:tid 358918] [client 202.143.127.214:65008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S4AlWhjQfpOo60_HkoQAAAHw"]
[Tue Jul 21 08:07:12.546041 2026] [security2:error] [pid 358661:tid 358857] [client 8.208.9.170:52985] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ssvistorias.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9S4AlWhjQfpOo60_HkowAAAD8"]
[Tue Jul 21 08:07:12.580320 2026] [core:error] [pid 352421:tid 352479] [remote 40.77.167.35:58211] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:07:12.580341 2026] [core:error] [pid 352421:tid 352479] [remote 40.77.167.35:58211] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:07:12.885539 2026] [security2:error] [pid 352421:tid 352519] [remote 45.8.148.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.148.8.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9S4MJSWzG9jbYOtu5VfgAAtWE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:07:12.885633 2026] [security2:error] [pid 358661:tid 358758] [remote 45.8.148.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.148.8.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9S4AlWhjQfpOo60_HkqAAAT10"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:07:12.893516 2026] [security2:error] [pid 358661:tid 358791] [remote 45.8.148.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.148.8.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9S4AlWhjQfpOo60_HkqQAAeH4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:07:12.933353 2026] [security2:error] [pid 352421:tid 352471] [remote 45.8.148.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.148.8.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9S4MJSWzG9jbYOtu5VfwAA_DE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:07:13.115867 2026] [security2:error] [pid 358661:tid 358673] [remote 45.8.148.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.148.8.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9S4QlWhjQfpOo60_HkrAAALAg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:07:13.149073 2026] [security2:error] [pid 352421:tid 352562] [client 8.208.9.170:52990] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ssvistorias.com.br"] [uri "/"] [unique_id "al9S4cJSWzG9jbYOtu5VhQAAAJA"]
[Tue Jul 21 08:07:13.167759 2026] [security2:error] [pid 352421:tid 352525] [remote 45.8.148.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.148.8.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9S4cJSWzG9jbYOtu5VhgAA0Wc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:07:13.171277 2026] [security2:error] [pid 352421:tid 352441] [remote 45.8.148.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.148.8.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9S4cJSWzG9jbYOtu5VhwAA7hM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:07:13.347104 2026] [security2:error] [pid 358661:tid 358814] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9S4QlWhjQfpOo60_HksgAAABQ"]
[Tue Jul 21 08:07:13.396836 2026] [security2:error] [pid 352421:tid 352527] [remote 45.8.148.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.148.8.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9S4cJSWzG9jbYOtu5VigAA8mk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:07:13.404162 2026] [security2:error] [pid 352421:tid 352501] [remote 45.8.148.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.148.8.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9S4cJSWzG9jbYOtu5ViwAA9k8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:07:13.446944 2026] [security2:error] [pid 352421:tid 352673] [client 20.226.60.151:12415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9S4cJSWzG9jbYOtu5VjQAAAP8"]
[Tue Jul 21 08:07:13.470675 2026] [security2:error] [pid 358661:tid 358822] [client 20.29.126.15:5841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/222.php"] [unique_id "al9S4QlWhjQfpOo60_HktQAAABw"]
[Tue Jul 21 08:07:13.495033 2026] [security2:error] [pid 358661:tid 358698] [remote 45.8.148.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.148.8.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9S4QlWhjQfpOo60_HktgAAQSE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:07:13.620083 2026] [security2:error] [pid 358661:tid 358789] [remote 216.26.236.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.236.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S4QlWhjQfpOo60_HktAAAb3w"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:13.751204 2026] [security2:error] [pid 352421:tid 352443] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9S4cJSWzG9jbYOtu5VkwAAuRU"]
[Tue Jul 21 08:07:13.751335 2026] [security2:error] [pid 352421:tid 352603] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9S4cJSWzG9jbYOtu5VkwAAuRU"]
[Tue Jul 21 08:07:13.759455 2026] [security2:error] [pid 358661:tid 358799] [client 8.208.9.170:52994] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ssvistorias.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9S4QlWhjQfpOo60_HkuQAAAAU"]
[Tue Jul 21 08:07:13.795476 2026] [security2:error] [pid 358661:tid 358890] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9S4QlWhjQfpOo60_HkugAAAGA"]
[Tue Jul 21 08:07:13.808635 2026] [security2:error] [pid 358661:tid 358699] [remote 45.8.148.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.148.8.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9S4QlWhjQfpOo60_HkuwAAPiI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:07:13.892655 2026] [security2:error] [pid 352421:tid 352639] [client 20.197.192.193:53140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/yup.php"] [unique_id "al9S4cJSWzG9jbYOtu5VlgAAAN0"]
[Tue Jul 21 08:07:13.897748 2026] [security2:error] [pid 352421:tid 352651] [client 120.56.162.40:56866] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S4cJSWzG9jbYOtu5VlwAAAOk"]
[Tue Jul 21 08:07:13.897892 2026] [security2:error] [pid 352421:tid 352651] [client 120.56.162.40:56866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S4cJSWzG9jbYOtu5VlwAAAOk"]
[Tue Jul 21 08:07:13.976871 2026] [security2:error] [pid 352421:tid 352652] [client 74.7.244.10:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "antoniojosedasilvaju1754466516089.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9S4cJSWzG9jbYOtu5VmAAA6mQ"]
[Tue Jul 21 08:07:14.078318 2026] [security2:error] [pid 352421:tid 352423] [remote 45.150.79.142:36144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "escoladaseguranca.com.br"] [uri "/wp-login.php"] [unique_id "al9S4sJSWzG9jbYOtu5VnAAAxQE"]
[Tue Jul 21 08:07:14.172650 2026] [security2:error] [pid 358661:tid 358800] [client 20.226.60.151:64873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/miru1.php"] [unique_id "al9S4glWhjQfpOo60_HkwAAAAAY"]
[Tue Jul 21 08:07:14.216570 2026] [security2:error] [pid 358661:tid 358845] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9S4glWhjQfpOo60_HkwgAAADM"]
[Tue Jul 21 08:07:14.328381 2026] [security2:error] [pid 358661:tid 358807] [client 150.129.202.39:65516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S4glWhjQfpOo60_HkyAAAAA0"]
[Tue Jul 21 08:07:14.328651 2026] [security2:error] [pid 358661:tid 358807] [client 150.129.202.39:65516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S4glWhjQfpOo60_HkyAAAAA0"]
[Tue Jul 21 08:07:14.362384 2026] [security2:error] [pid 358661:tid 358910] [client 8.208.9.170:53000] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ssvistorias.com.br"] [uri "/"] [unique_id "al9S4glWhjQfpOo60_HkygAAAHQ"]
[Tue Jul 21 08:07:14.481987 2026] [security2:error] [pid 358661:tid 358909] [client 198.54.128.138:57952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9S4glWhjQfpOo60_HkzQAAAHM"]
[Tue Jul 21 08:07:14.482101 2026] [security2:error] [pid 358661:tid 358909] [client 198.54.128.138:57952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9S4glWhjQfpOo60_HkzQAAAHM"]
[Tue Jul 21 08:07:14.483890 2026] [security2:error] [pid 358661:tid 358846] [client 65.21.113.253:56994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9S4glWhjQfpOo60_HkzAAAADQ"]
[Tue Jul 21 08:07:14.605958 2026] [security2:error] [pid 358661:tid 358921] [client 102.206.115.33:64384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9S4glWhjQfpOo60_Hk0AAAAH8"]
[Tue Jul 21 08:07:14.606070 2026] [security2:error] [pid 358661:tid 358921] [client 102.206.115.33:64384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9S4glWhjQfpOo60_Hk0AAAAH8"]
[Tue Jul 21 08:07:14.658440 2026] [security2:error] [pid 352421:tid 352604] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9S4sJSWzG9jbYOtu5VqAAAALo"]
[Tue Jul 21 08:07:14.693834 2026] [security2:error] [pid 358661:tid 358915] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S4glWhjQfpOo60_Hk0wAAAHk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:14.881034 2026] [security2:error] [pid 358661:tid 358801] [client 74.7.230.55:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lorenadesouzapinheir1750877234635.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9S4glWhjQfpOo60_Hk1QAABz8"]
[Tue Jul 21 08:07:14.902830 2026] [security2:error] [pid 358661:tid 358810] [client 20.226.60.151:12397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/abcd.php"] [unique_id "al9S4glWhjQfpOo60_Hk1wAAABA"]
[Tue Jul 21 08:07:14.955857 2026] [security2:error] [pid 358661:tid 358691] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9S4glWhjQfpOo60_Hk2gAAeBo"]
[Tue Jul 21 08:07:14.955995 2026] [security2:error] [pid 358661:tid 358914] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9S4glWhjQfpOo60_Hk2gAAeBo"]
[Tue Jul 21 08:07:14.977673 2026] [security2:error] [pid 352421:tid 352452] [remote 34.24.57.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.24.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dees.ind.br"] [uri "/xmlrpc.php"] [unique_id "al9S4sJSWzG9jbYOtu5VrQABAh4"]
[Tue Jul 21 08:07:14.977873 2026] [security2:error] [pid 352421:tid 352676] [client 34.24.57.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dees.ind.br"] [uri "/xmlrpc.php"] [unique_id "al9S4sJSWzG9jbYOtu5VrQABAh4"]
[Tue Jul 21 08:07:15.118906 2026] [security2:error] [pid 352421:tid 352585] [client 65.21.113.253:43276] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S4sJSWzG9jbYOtu5VqwAAAKc"]
[Tue Jul 21 08:07:15.147139 2026] [security2:error] [pid 358661:tid 358902] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9S4wlWhjQfpOo60_Hk3gAAAGw"]
[Tue Jul 21 08:07:15.413834 2026] [security2:error] [pid 358661:tid 358795] [client 20.226.60.151:12003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/file15.php"] [unique_id "al9S4wlWhjQfpOo60_Hk5gAAAAE"]
[Tue Jul 21 08:07:15.656381 2026] [security2:error] [pid 358661:tid 358866] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9S4wlWhjQfpOo60_Hk6QAAAEg"]
[Tue Jul 21 08:07:15.931123 2026] [security2:error] [pid 358661:tid 358830] [client 20.197.192.193:39277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/zzz.php"] [unique_id "al9S4wlWhjQfpOo60_Hk7QAAACQ"]
[Tue Jul 21 08:07:16.067275 2026] [security2:error] [pid 358661:tid 358840] [client 65.21.113.253:34218] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S4wlWhjQfpOo60_Hk6AAAAC4"]
[Tue Jul 21 08:07:16.075758 2026] [security2:error] [pid 358661:tid 358909] [client 20.226.60.151:65076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/sump1.php"] [unique_id "al9S5AlWhjQfpOo60_Hk7wAAAHM"]
[Tue Jul 21 08:07:16.084022 2026] [security2:error] [pid 358661:tid 358897] [client 20.226.60.151:12112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/jp.php"] [unique_id "al9S5AlWhjQfpOo60_Hk8AAAAGc"]
[Tue Jul 21 08:07:16.258271 2026] [security2:error] [pid 352421:tid 352583] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9S5MJSWzG9jbYOtu5VvwAAAKU"]
[Tue Jul 21 08:07:16.334857 2026] [security2:error] [pid 358661:tid 358757] [remote 209.50.189.125:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.189.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S5AlWhjQfpOo60_Hk8gAAdFw"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:16.369757 2026] [security2:error] [pid 352421:tid 352670] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9S5MJSWzG9jbYOtu5VuwAA_BQ"]
[Tue Jul 21 08:07:16.375348 2026] [security2:error] [pid 352421:tid 352557] [client 20.29.126.15:8928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/t.php"] [unique_id "al9S5MJSWzG9jbYOtu5VwwAAAIs"]
[Tue Jul 21 08:07:16.772159 2026] [security2:error] [pid 358661:tid 358878] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9S5AlWhjQfpOo60_Hk_wAAAFQ"]
[Tue Jul 21 08:07:16.866914 2026] [security2:error] [pid 352421:tid 352661] [client 20.226.60.151:64848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/file5.php"] [unique_id "al9S5MJSWzG9jbYOtu5VyAAAAPM"]
[Tue Jul 21 08:07:16.885550 2026] [security2:error] [pid 358661:tid 358790] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9S5AlWhjQfpOo60_HlAAAAbn0"]
[Tue Jul 21 08:07:16.885743 2026] [security2:error] [pid 358661:tid 358904] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9S5AlWhjQfpOo60_HlAAAAbn0"]
[Tue Jul 21 08:07:16.932710 2026] [security2:error] [pid 358661:tid 358891] [client 20.226.60.151:56412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/0xD.php"] [unique_id "al9S5AlWhjQfpOo60_HlAQAAAGE"]
[Tue Jul 21 08:07:16.990552 2026] [security2:error] [pid 358661:tid 358837] [client 20.226.60.151:65025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/fnstall.php"] [unique_id "al9S5AlWhjQfpOo60_HlAwAAACs"]
[Tue Jul 21 08:07:17.028707 2026] [security2:error] [pid 358661:tid 358855] [client 20.226.60.151:65066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/acp.php"] [unique_id "al9S5QlWhjQfpOo60_HlBAAAAD0"]
[Tue Jul 21 08:07:17.117605 2026] [security2:error] [pid 358661:tid 358896] [client 20.226.60.151:12381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/f35.php"] [unique_id "al9S5QlWhjQfpOo60_HlBQAAAGY"]
[Tue Jul 21 08:07:17.130919 2026] [security2:error] [pid 358661:tid 358869] [client 103.78.200.11:50369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S5QlWhjQfpOo60_HlBgAAAEs"]
[Tue Jul 21 08:07:17.131026 2026] [security2:error] [pid 358661:tid 358869] [client 103.78.200.11:50369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S5QlWhjQfpOo60_HlBgAAAEs"]
[Tue Jul 21 08:07:17.184693 2026] [security2:error] [pid 358661:tid 358833] [client 20.226.60.151:56395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/mosty.php"] [unique_id "al9S5QlWhjQfpOo60_HlCQAAACc"]
[Tue Jul 21 08:07:17.186090 2026] [security2:error] [pid 358661:tid 358885] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S5QlWhjQfpOo60_HlCAAAAFs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:17.306750 2026] [security2:error] [pid 352421:tid 352619] [client 20.226.60.151:56403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/6.php"] [unique_id "al9S5cJSWzG9jbYOtu5VzQAAAMk"]
[Tue Jul 21 08:07:17.382699 2026] [security2:error] [pid 358661:tid 358843] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9S5QlWhjQfpOo60_HlDwAAADE"]
[Tue Jul 21 08:07:17.384576 2026] [security2:error] [pid 358661:tid 358732] [remote 216.26.250.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.250.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S5QlWhjQfpOo60_HlCgAARkM"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:17.509864 2026] [security2:error] [pid 358661:tid 358807] [client 20.226.60.151:64863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/32e17094cfindex.php"] [unique_id "al9S5QlWhjQfpOo60_HlEwAAAA0"]
[Tue Jul 21 08:07:17.527530 2026] [security2:error] [pid 358661:tid 358822] [client 178.153.91.96:65346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9S5QlWhjQfpOo60_HlFAAAABw"]
[Tue Jul 21 08:07:17.527655 2026] [security2:error] [pid 358661:tid 358822] [client 178.153.91.96:65346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9S5QlWhjQfpOo60_HlFAAAABw"]
[Tue Jul 21 08:07:17.693684 2026] [rewrite:warn] [pid 358661:tid 358679] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:07:17.696172 2026] [security2:error] [pid 358661:tid 358862] [client 103.29.114.44:65256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S5QlWhjQfpOo60_HlFwAAAEQ"]
[Tue Jul 21 08:07:17.696273 2026] [security2:error] [pid 358661:tid 358862] [client 103.29.114.44:65256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S5QlWhjQfpOo60_HlFwAAAEQ"]
[Tue Jul 21 08:07:17.861418 2026] [security2:error] [pid 352421:tid 352616] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9S5cJSWzG9jbYOtu5V0wAAAMY"]
[Tue Jul 21 08:07:17.896408 2026] [security2:error] [pid 358661:tid 358717] [remote 97.74.93.24:42594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9S5QlWhjQfpOo60_HlIAAASTQ"]
[Tue Jul 21 08:07:17.953213 2026] [security2:error] [pid 358661:tid 358854] [client 87.116.180.198:13853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S5QlWhjQfpOo60_HlIQAAADw"]
[Tue Jul 21 08:07:17.953357 2026] [security2:error] [pid 358661:tid 358854] [client 87.116.180.198:13853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S5QlWhjQfpOo60_HlIQAAADw"]
[Tue Jul 21 08:07:18.113948 2026] [security2:error] [pid 352421:tid 352475] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S5sJSWzG9jbYOtu5V1gAAxzU"]
[Tue Jul 21 08:07:18.114093 2026] [security2:error] [pid 352421:tid 352617] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S5sJSWzG9jbYOtu5V1gAAxzU"]
[Tue Jul 21 08:07:18.141034 2026] [security2:error] [pid 358661:tid 358914] [client 65.21.113.253:56994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9S5glWhjQfpOo60_HlIwAAAHg"]
[Tue Jul 21 08:07:18.303964 2026] [security2:error] [pid 358661:tid 358810] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9S5glWhjQfpOo60_HlKAAAABA"]
[Tue Jul 21 08:07:18.379063 2026] [security2:error] [pid 358661:tid 358836] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S5glWhjQfpOo60_HlMQAAACo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:18.379185 2026] [security2:error] [pid 358661:tid 358836] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S5glWhjQfpOo60_HlMQAAACo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:18.548313 2026] [security2:error] [pid 358661:tid 358918] [client 20.226.60.151:64894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/qqqa.php"] [unique_id "al9S5glWhjQfpOo60_HlOQAAAHw"]
[Tue Jul 21 08:07:18.550423 2026] [security2:error] [pid 358661:tid 358800] [client 20.29.126.15:8540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/a.php"] [unique_id "al9S5glWhjQfpOo60_HlOgAAAAY"]
[Tue Jul 21 08:07:18.599967 2026] [security2:error] [pid 358661:tid 358771] [remote 216.26.227.87:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.227.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S5glWhjQfpOo60_HlMgAAQWo"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:18.605590 2026] [security2:error] [pid 358661:tid 358838] [client 117.210.135.0:57817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S5glWhjQfpOo60_HlPQAAACw"]
[Tue Jul 21 08:07:18.605726 2026] [security2:error] [pid 358661:tid 358838] [client 117.210.135.0:57817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S5glWhjQfpOo60_HlPQAAACw"]
[Tue Jul 21 08:07:18.652180 2026] [security2:error] [pid 358661:tid 358797] [client 20.226.60.151:12394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/wp-load.php"] [unique_id "al9S5glWhjQfpOo60_HlQAAAAAM"]
[Tue Jul 21 08:07:18.709757 2026] [security2:error] [pid 358661:tid 358830] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9S5glWhjQfpOo60_HlQQAAACQ"]
[Tue Jul 21 08:07:18.753247 2026] [security2:error] [pid 358661:tid 358921] [client 65.21.113.253:34218] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S5glWhjQfpOo60_HlLgAAAH8"]
[Tue Jul 21 08:07:18.883536 2026] [security2:error] [pid 358661:tid 358748] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9S5glWhjQfpOo60_HlRwAALVM"]
[Tue Jul 21 08:07:18.883715 2026] [security2:error] [pid 358661:tid 358839] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9S5glWhjQfpOo60_HlRwAALVM"]
[Tue Jul 21 08:07:18.980315 2026] [security2:error] [pid 358661:tid 358802] [client 117.247.80.59:15428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S5glWhjQfpOo60_HlSgAAAAg"]
[Tue Jul 21 08:07:18.980444 2026] [security2:error] [pid 358661:tid 358802] [client 117.247.80.59:15428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S5glWhjQfpOo60_HlSgAAAAg"]
[Tue Jul 21 08:07:19.180023 2026] [security2:error] [pid 358661:tid 358884] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9S5wlWhjQfpOo60_HlTQAAAFo"]
[Tue Jul 21 08:07:19.330244 2026] [security2:error] [pid 352421:tid 352568] [client 20.226.60.151:65030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/aunmc.php"] [unique_id "al9S58JSWzG9jbYOtu5V6gAAAJY"]
[Tue Jul 21 08:07:19.497734 2026] [security2:error] [pid 358661:tid 358805] [client 20.226.60.151:56397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/uoocf.php"] [unique_id "al9S5wlWhjQfpOo60_HlUgAAAAs"]
[Tue Jul 21 08:07:19.583562 2026] [security2:error] [pid 352421:tid 352597] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9S58JSWzG9jbYOtu5V9QAAALM"]
[Tue Jul 21 08:07:19.806431 2026] [security2:error] [pid 358661:tid 358863] [client 20.226.60.151:56396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/iywwi.php"] [unique_id "al9S5wlWhjQfpOo60_HlXAAAAEU"]
[Tue Jul 21 08:07:19.840786 2026] [security2:error] [pid 358661:tid 358733] [remote 209.50.171.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.171.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S5wlWhjQfpOo60_HlWQAAYUQ"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:19.944926 2026] [security2:error] [pid 358661:tid 358856] [client 34.26.20.91:64546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bracksimoveis.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9S5wlWhjQfpOo60_HlYgAAAD4"]
[Tue Jul 21 08:07:19.972581 2026] [security2:error] [pid 358661:tid 358896] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9S5wlWhjQfpOo60_HlYwAAAGY"]
[Tue Jul 21 08:07:20.074127 2026] [security2:error] [pid 358661:tid 358898] [client 20.226.60.151:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/gqgsa.php"] [unique_id "al9S6AlWhjQfpOo60_HlZAAAAGg"]
[Tue Jul 21 08:07:20.110942 2026] [security2:error] [pid 352421:tid 352606] [client 20.226.60.151:12138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/xyn.php"] [unique_id "al9S6MJSWzG9jbYOtu5V_QAAALw"]
[Tue Jul 21 08:07:20.379229 2026] [security2:error] [pid 358661:tid 358859] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9S6AlWhjQfpOo60_HlZQAAAEE"]
[Tue Jul 21 08:07:20.499168 2026] [rewrite:warn] [pid 352421:tid 352537] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:07:20.530492 2026] [security2:error] [pid 358661:tid 358848] [client 38.100.221.102:18693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S6AlWhjQfpOo60_HlaAAAADY"]
[Tue Jul 21 08:07:20.530653 2026] [security2:error] [pid 358661:tid 358848] [client 38.100.221.102:18693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S6AlWhjQfpOo60_HlaAAAADY"]
[Tue Jul 21 08:07:20.661647 2026] [security2:error] [pid 352421:tid 352551] [client 65.21.113.253:57872] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S6MJSWzG9jbYOtu5WAQAAAIU"]
[Tue Jul 21 08:07:20.756512 2026] [security2:error] [pid 358661:tid 358779] [remote 216.26.237.143:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.237.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S6AlWhjQfpOo60_HlaQAARHI"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:20.774823 2026] [security2:error] [pid 352421:tid 352617] [client 91.230.225.147:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.marcelandremalon1751551540280.0721679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9S6MJSWzG9jbYOtu5WEAAAAMc"]
[Tue Jul 21 08:07:21.035678 2026] [security2:error] [pid 358661:tid 358695] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S6QlWhjQfpOo60_HlbwAAKR4"]
[Tue Jul 21 08:07:21.035887 2026] [security2:error] [pid 358661:tid 358835] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S6QlWhjQfpOo60_HlbwAAKR4"]
[Tue Jul 21 08:07:21.218888 2026] [security2:error] [pid 358661:tid 358876] [client 20.226.60.151:65042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/elbzl.php"] [unique_id "al9S6QlWhjQfpOo60_HlcwAAAFI"]
[Tue Jul 21 08:07:21.427842 2026] [security2:error] [pid 358661:tid 358884] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S6QlWhjQfpOo60_HldgAAAFo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:21.720156 2026] [security2:error] [pid 358661:tid 358803] [client 20.197.192.193:39265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/pn.php"] [unique_id "al9S6QlWhjQfpOo60_HlegAAAAk"]
[Tue Jul 21 08:07:21.902948 2026] [security2:error] [pid 358661:tid 358850] [client 20.226.60.151:65051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/adjig.php"] [unique_id "al9S6QlWhjQfpOo60_HlgAAAADg"]
[Tue Jul 21 08:07:22.178585 2026] [security2:error] [pid 352421:tid 352602] [client 61.1.167.83:54737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S6sJSWzG9jbYOtu5WJgAAALg"]
[Tue Jul 21 08:07:22.178714 2026] [security2:error] [pid 352421:tid 352602] [client 61.1.167.83:54737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S6sJSWzG9jbYOtu5WJgAAALg"]
[Tue Jul 21 08:07:22.234944 2026] [security2:error] [pid 358661:tid 358854] [client 41.68.90.219:57256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S6glWhjQfpOo60_HlhgAAADw"]
[Tue Jul 21 08:07:22.235060 2026] [security2:error] [pid 358661:tid 358854] [client 41.68.90.219:57256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S6glWhjQfpOo60_HlhgAAADw"]
[Tue Jul 21 08:07:22.418322 2026] [security2:error] [pid 358661:tid 358727] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S6glWhjQfpOo60_HliQAAbT4"]
[Tue Jul 21 08:07:22.418474 2026] [security2:error] [pid 358661:tid 358903] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S6glWhjQfpOo60_HliQAAbT4"]
[Tue Jul 21 08:07:22.418665 2026] [security2:error] [pid 358661:tid 358856] [client 20.226.60.151:11987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/ccc.php"] [unique_id "al9S6glWhjQfpOo60_HligAAAD4"]
[Tue Jul 21 08:07:22.987687 2026] [security2:error] [pid 358661:tid 358761] [remote 104.207.49.222:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.49.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S6QlWhjQfpOo60_HlfQAAcWA"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:23.048889 2026] [security2:error] [pid 352421:tid 352555] [client 20.226.60.151:64868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/byp.php"] [unique_id "al9S68JSWzG9jbYOtu5WNQAAAIk"]
[Tue Jul 21 08:07:23.149004 2026] [security2:error] [pid 358661:tid 358812] [client 175.144.82.48:56560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S6wlWhjQfpOo60_HllgAAABI"]
[Tue Jul 21 08:07:23.150022 2026] [security2:error] [pid 358661:tid 358812] [client 175.144.82.48:56560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S6wlWhjQfpOo60_HllgAAABI"]
[Tue Jul 21 08:07:23.188410 2026] [security2:error] [pid 358661:tid 358917] [client 109.60.28.94:11165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S6wlWhjQfpOo60_HllwAAAHs"]
[Tue Jul 21 08:07:23.188510 2026] [security2:error] [pid 358661:tid 358917] [client 109.60.28.94:11165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S6wlWhjQfpOo60_HllwAAAHs"]
[Tue Jul 21 08:07:23.422623 2026] [security2:error] [pid 358661:tid 358833] [client 103.166.103.129:50464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9S6wlWhjQfpOo60_HlmgAAACc"]
[Tue Jul 21 08:07:23.424153 2026] [security2:error] [pid 358661:tid 358833] [client 103.166.103.129:50464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9S6wlWhjQfpOo60_HlmgAAACc"]
[Tue Jul 21 08:07:23.663736 2026] [security2:error] [pid 352421:tid 352661] [client 202.143.127.214:65485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S68JSWzG9jbYOtu5WPwAAAPM"]
[Tue Jul 21 08:07:23.664380 2026] [security2:error] [pid 352421:tid 352661] [client 202.143.127.214:65485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S68JSWzG9jbYOtu5WPwAAAPM"]
[Tue Jul 21 08:07:23.714045 2026] [security2:error] [pid 358661:tid 358814] [client 20.226.60.151:12395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/w.php"] [unique_id "al9S6wlWhjQfpOo60_HlnQAAABQ"]
[Tue Jul 21 08:07:23.854701 2026] [security2:error] [pid 358661:tid 358888] [client 151.63.71.144:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9S6wlWhjQfpOo60_HloQAAAF4"]
[Tue Jul 21 08:07:23.854862 2026] [security2:error] [pid 358661:tid 358888] [client 151.63.71.144:53186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9S6wlWhjQfpOo60_HloQAAAF4"]
[Tue Jul 21 08:07:24.014099 2026] [security2:error] [pid 358661:tid 358736] [remote 65.111.21.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.21.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S7AlWhjQfpOo60_HlpAAAZEc"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:24.219165 2026] [security2:error] [pid 358661:tid 358916] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S7AlWhjQfpOo60_HlpQAAAHo"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:24.257593 2026] [security2:error] [pid 358661:tid 358877] [client 20.197.192.193:3480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9S7AlWhjQfpOo60_HlpwAAAFM"]
[Tue Jul 21 08:07:24.354893 2026] [security2:error] [pid 358661:tid 358821] [client 20.226.60.151:65080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/ortasekerli1.php"] [unique_id "al9S7AlWhjQfpOo60_HlrAAAABs"]
[Tue Jul 21 08:07:24.418195 2026] [security2:error] [pid 352421:tid 352519] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9S7MJSWzG9jbYOtu5WSwAA6WE"]
[Tue Jul 21 08:07:24.418357 2026] [security2:error] [pid 352421:tid 352651] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9S7MJSWzG9jbYOtu5WSwAA6WE"]
[Tue Jul 21 08:07:24.567772 2026] [security2:error] [pid 352421:tid 352652] [client 65.21.113.253:57872] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S7MJSWzG9jbYOtu5WRAAAAOo"]
[Tue Jul 21 08:07:24.671482 2026] [security2:error] [pid 358661:tid 358824] [client 120.56.162.40:57337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S7AlWhjQfpOo60_HlrQAAAB4"]
[Tue Jul 21 08:07:24.671657 2026] [security2:error] [pid 358661:tid 358824] [client 120.56.162.40:57337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S7AlWhjQfpOo60_HlrQAAAB4"]
[Tue Jul 21 08:07:24.873093 2026] [security2:error] [pid 358661:tid 358832] [client 20.226.60.151:12412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9S7AlWhjQfpOo60_HlsgAAACY"]
[Tue Jul 21 08:07:24.958682 2026] [security2:error] [pid 358661:tid 358813] [client 198.54.128.138:59676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.128.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9S7AlWhjQfpOo60_HlswAAABM"]
[Tue Jul 21 08:07:24.958789 2026] [security2:error] [pid 358661:tid 358813] [client 198.54.128.138:59676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9S7AlWhjQfpOo60_HlswAAABM"]
[Tue Jul 21 08:07:25.031373 2026] [security2:error] [pid 358661:tid 358863] [client 150.129.202.39:64684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S7QlWhjQfpOo60_HltAAAAEU"]
[Tue Jul 21 08:07:25.031534 2026] [security2:error] [pid 358661:tid 358863] [client 150.129.202.39:64684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S7QlWhjQfpOo60_HltAAAAEU"]
[Tue Jul 21 08:07:25.190755 2026] [security2:error] [pid 358661:tid 358865] [client 102.206.115.33:65076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9S7QlWhjQfpOo60_HluAAAAEc"]
[Tue Jul 21 08:07:25.190895 2026] [security2:error] [pid 358661:tid 358865] [client 102.206.115.33:65076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9S7QlWhjQfpOo60_HluAAAAEc"]
[Tue Jul 21 08:07:25.355320 2026] [security2:error] [pid 358661:tid 358811] [client 65.21.113.253:48028] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9S7QlWhjQfpOo60_HluwAAABE"]
[Tue Jul 21 08:07:25.448598 2026] [security2:error] [pid 352421:tid 352678] [client 74.7.241.145:47952] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "tainux.io"] [uri "/cgi-sys/404.html"] [unique_id "al9S7cJSWzG9jbYOtu5WWQABBHI"]
[Tue Jul 21 08:07:25.609196 2026] [security2:error] [pid 352421:tid 352527] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9S7cJSWzG9jbYOtu5WXAAAymk"]
[Tue Jul 21 08:07:25.609364 2026] [security2:error] [pid 352421:tid 352620] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9S7cJSWzG9jbYOtu5WXAAAymk"]
[Tue Jul 21 08:07:25.611577 2026] [security2:error] [pid 358661:tid 358839] [client 20.29.126.15:8521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/a1.php"] [unique_id "al9S7QlWhjQfpOo60_HlvgAAAC0"]
[Tue Jul 21 08:07:25.622890 2026] [security2:error] [pid 358661:tid 358840] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S7QlWhjQfpOo60_HlvwAAAC4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:25.623001 2026] [security2:error] [pid 358661:tid 358840] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S7QlWhjQfpOo60_HlvwAAAC4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:25.734161 2026] [security2:error] [pid 358661:tid 358719] [remote 216.26.255.118:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.255.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S7QlWhjQfpOo60_HlvQAAKTY"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:25.844023 2026] [security2:error] [pid 352421:tid 352671] [client 20.226.60.151:64847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/classwithtostring.php"] [unique_id "al9S7cJSWzG9jbYOtu5WYgAAAP0"]
[Tue Jul 21 08:07:25.983074 2026] [security2:error] [pid 352421:tid 352569] [client 65.21.113.253:57872] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S7cJSWzG9jbYOtu5WWwAAAJc"]
[Tue Jul 21 08:07:26.295577 2026] [security2:error] [pid 358661:tid 358852] [client 20.226.60.151:11983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/FWAZ.php"] [unique_id "al9S7glWhjQfpOo60_HlxQAAADo"]
[Tue Jul 21 08:07:26.472370 2026] [security2:error] [pid 358661:tid 358908] [client 20.226.60.151:56413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/root.php"] [unique_id "al9S7glWhjQfpOo60_HlyQAAAHI"]
[Tue Jul 21 08:07:26.912398 2026] [security2:error] [pid 358661:tid 358806] [client 34.26.20.91:58086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.20.26.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bracksimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S7glWhjQfpOo60_HlywAAAAw"]
[Tue Jul 21 08:07:26.912549 2026] [security2:error] [pid 358661:tid 358806] [client 34.26.20.91:58086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bracksimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S7glWhjQfpOo60_HlywAAAAw"]
[Tue Jul 21 08:07:26.995713 2026] [security2:error] [pid 358661:tid 358842] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9S7glWhjQfpOo60_HlzgAAMCw"]
[Tue Jul 21 08:07:27.098596 2026] [security2:error] [pid 358661:tid 358853] [client 20.226.60.151:12099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/miru1.php"] [unique_id "al9S7wlWhjQfpOo60_Hl0gAAADs"]
[Tue Jul 21 08:07:27.366714 2026] [security2:error] [pid 358661:tid 358799] [client 65.21.113.253:57882] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S7wlWhjQfpOo60_Hl0wAAAAU"]
[Tue Jul 21 08:07:27.397094 2026] [security2:error] [pid 358661:tid 358773] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9S7wlWhjQfpOo60_Hl1wAAb2w"]
[Tue Jul 21 08:07:27.397301 2026] [security2:error] [pid 358661:tid 358905] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9S7wlWhjQfpOo60_Hl1wAAb2w"]
[Tue Jul 21 08:07:27.494954 2026] [security2:error] [pid 352421:tid 352563] [client 20.226.60.151:11984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/aa.php"] [unique_id "al9S78JSWzG9jbYOtu5WdgAAAJE"]
[Tue Jul 21 08:07:27.531182 2026] [security2:error] [pid 358661:tid 358918] [client 20.226.60.151:56332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/sym403.php"] [unique_id "al9S7wlWhjQfpOo60_Hl2gAAAHw"]
[Tue Jul 21 08:07:27.852681 2026] [security2:error] [pid 358661:tid 358862] [client 103.78.200.11:50856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S7wlWhjQfpOo60_Hl3QAAAEQ"]
[Tue Jul 21 08:07:27.852838 2026] [security2:error] [pid 358661:tid 358862] [client 103.78.200.11:50856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S7wlWhjQfpOo60_Hl3QAAAEQ"]
[Tue Jul 21 08:07:27.940856 2026] [security2:error] [pid 358661:tid 358848] [client 204.8.98.45:43190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9S7wlWhjQfpOo60_Hl4AAAADY"]
[Tue Jul 21 08:07:27.940948 2026] [security2:error] [pid 358661:tid 358848] [client 204.8.98.45:43190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9S7wlWhjQfpOo60_Hl4AAAADY"]
[Tue Jul 21 08:07:28.041938 2026] [security2:error] [pid 358661:tid 358885] [client 178.153.91.96:46285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9S8AlWhjQfpOo60_Hl5AAAAFs"]
[Tue Jul 21 08:07:28.042041 2026] [security2:error] [pid 358661:tid 358885] [client 178.153.91.96:46285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9S8AlWhjQfpOo60_Hl5AAAAFs"]
[Tue Jul 21 08:07:28.161054 2026] [security2:error] [pid 358661:tid 358834] [client 103.29.114.44:25480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S8AlWhjQfpOo60_Hl5gAAACg"]
[Tue Jul 21 08:07:28.161169 2026] [security2:error] [pid 358661:tid 358834] [client 103.29.114.44:25480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S8AlWhjQfpOo60_Hl5gAAACg"]
[Tue Jul 21 08:07:28.306657 2026] [security2:error] [pid 352421:tid 352616] [client 204.8.98.45:50320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.98.8.204.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9S8MJSWzG9jbYOtu5WgQAAAMY"]
[Tue Jul 21 08:07:28.306750 2026] [security2:error] [pid 352421:tid 352616] [client 204.8.98.45:50320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9S8MJSWzG9jbYOtu5WgQAAAMY"]
[Tue Jul 21 08:07:28.354695 2026] [security2:error] [pid 358661:tid 358746] [remote 65.111.26.203:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S7wlWhjQfpOo60_Hl1QAAZ1E"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:28.419163 2026] [security2:error] [pid 358661:tid 358876] [client 20.197.192.193:3557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/dr.php"] [unique_id "al9S8AlWhjQfpOo60_Hl7AAAAFI"]
[Tue Jul 21 08:07:28.492626 2026] [security2:error] [pid 358661:tid 358864] [client 65.21.113.253:57892] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S8AlWhjQfpOo60_Hl4wAAAEY"]
[Tue Jul 21 08:07:28.590287 2026] [security2:error] [pid 352421:tid 352456] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S8MJSWzG9jbYOtu5WiQAA3iI"]
[Tue Jul 21 08:07:28.590421 2026] [security2:error] [pid 352421:tid 352640] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S8MJSWzG9jbYOtu5WiQAA3iI"]
[Tue Jul 21 08:07:28.620255 2026] [security2:error] [pid 358661:tid 358795] [client 87.116.180.198:14023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S8AlWhjQfpOo60_Hl7gAAAAE"]
[Tue Jul 21 08:07:28.620381 2026] [security2:error] [pid 358661:tid 358795] [client 87.116.180.198:14023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S8AlWhjQfpOo60_Hl7gAAAAE"]
[Tue Jul 21 08:07:28.829387 2026] [security2:error] [pid 352421:tid 352639] [client 104.239.91.197:48567] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "advcelsopinto.com.br"] [uri "/"] [unique_id "al9S8MJSWzG9jbYOtu5WiwAAAN0"]
[Tue Jul 21 08:07:28.897596 2026] [security2:error] [pid 358661:tid 358908] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S8AlWhjQfpOo60_HmJgAAAHI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:28.918210 2026] [security2:error] [pid 358661:tid 358817] [client 20.226.60.151:65087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/v543.php"] [unique_id "al9S8AlWhjQfpOo60_HmKQAAABc"]
[Tue Jul 21 08:07:29.067182 2026] [security2:error] [pid 352421:tid 352590] [client 20.226.60.151:12097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/122.php"] [unique_id "al9S8cJSWzG9jbYOtu5WkQAAAKw"]
[Tue Jul 21 08:07:29.112286 2026] [security2:error] [pid 358661:tid 358851] [client 117.210.135.0:58465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S8QlWhjQfpOo60_HmLQAAADk"]
[Tue Jul 21 08:07:29.112402 2026] [security2:error] [pid 358661:tid 358851] [client 117.210.135.0:58465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S8QlWhjQfpOo60_HmLQAAADk"]
[Tue Jul 21 08:07:29.558763 2026] [security2:error] [pid 358661:tid 358910] [client 20.226.60.151:12365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/get.php"] [unique_id "al9S8QlWhjQfpOo60_HmNgAAAHQ"]
[Tue Jul 21 08:07:29.578472 2026] [security2:error] [pid 358661:tid 358728] [remote 65.111.0.18:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.0.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S8QlWhjQfpOo60_HmMAAAMD8"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:29.605251 2026] [security2:error] [pid 358661:tid 358884] [client 117.247.80.59:15516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S8QlWhjQfpOo60_HmOAAAAFo"]
[Tue Jul 21 08:07:29.605381 2026] [security2:error] [pid 358661:tid 358884] [client 117.247.80.59:15516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S8QlWhjQfpOo60_HmOAAAAFo"]
[Tue Jul 21 08:07:29.711324 2026] [security2:error] [pid 358661:tid 358901] [client 65.21.113.253:48028] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9S8QlWhjQfpOo60_HmOgAAAGs"]
[Tue Jul 21 08:07:29.823914 2026] [security2:error] [pid 358661:tid 358918] [client 184.75.221.3:40020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.221.75.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9S8QlWhjQfpOo60_HmPAAAAHw"]
[Tue Jul 21 08:07:29.824004 2026] [security2:error] [pid 358661:tid 358918] [client 184.75.221.3:40020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9S8QlWhjQfpOo60_HmPAAAAHw"]
[Tue Jul 21 08:07:29.866910 2026] [security2:error] [pid 358661:tid 358667] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9S8QlWhjQfpOo60_HmQAAAKgI"]
[Tue Jul 21 08:07:29.867091 2026] [security2:error] [pid 358661:tid 358836] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9S8QlWhjQfpOo60_HmQAAAKgI"]
[Tue Jul 21 08:07:30.157527 2026] [security2:error] [pid 358661:tid 358871] [client 20.29.126.15:9158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/w.php"] [unique_id "al9S8glWhjQfpOo60_HmRQAAAE0"]
[Tue Jul 21 08:07:30.195134 2026] [security2:error] [pid 352421:tid 352577] [client 216.173.74.200:39299] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "advcelsopinto.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9S8sJSWzG9jbYOtu5WnwAAAJ8"]
[Tue Jul 21 08:07:30.333438 2026] [security2:error] [pid 358661:tid 358921] [client 65.21.113.253:57892] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S8QlWhjQfpOo60_HmQgAAAH8"]
[Tue Jul 21 08:07:30.745198 2026] [security2:error] [pid 358661:tid 358835] [client 20.226.60.151:12383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/as.php"] [unique_id "al9S8glWhjQfpOo60_HmTQAAACk"]
[Tue Jul 21 08:07:30.825989 2026] [security2:error] [pid 352421:tid 352478] [remote 209.50.188.131:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.188.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S8sJSWzG9jbYOtu5WpAAAlzg"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:31.109785 2026] [security2:error] [pid 352421:tid 352572] [client 20.226.60.151:12133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/ccou.php"] [unique_id "al9S88JSWzG9jbYOtu5WqQAAAJo"]
[Tue Jul 21 08:07:31.213559 2026] [security2:error] [pid 352421:tid 352558] [client 38.100.221.102:18778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S88JSWzG9jbYOtu5WrgAAAIw"]
[Tue Jul 21 08:07:31.213672 2026] [security2:error] [pid 352421:tid 352558] [client 38.100.221.102:18778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S88JSWzG9jbYOtu5WrgAAAIw"]
[Tue Jul 21 08:07:31.488619 2026] [security2:error] [pid 358661:tid 358880] [client 20.226.60.151:12029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/w3lls.php"] [unique_id "al9S8wlWhjQfpOo60_HmVAAAAFY"]
[Tue Jul 21 08:07:31.496039 2026] [security2:error] [pid 358661:tid 358867] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S8wlWhjQfpOo60_HmVQAAAEk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:31.575867 2026] [security2:error] [pid 352421:tid 352613] [client 20.226.60.151:56427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/sixxis.php"] [unique_id "al9S88JSWzG9jbYOtu5WtAAAAMM"]
[Tue Jul 21 08:07:31.744428 2026] [security2:error] [pid 358661:tid 358803] [client 171.22.249.49:55887] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "advcelsopinto.com.br"] [uri "/"] [unique_id "al9S8wlWhjQfpOo60_HmVwAAAAk"]
[Tue Jul 21 08:07:31.945531 2026] [security2:error] [pid 358661:tid 358675] [remote 35.221.29.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.29.221.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.printcom.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S8wlWhjQfpOo60_HmWAAACwo"]
[Tue Jul 21 08:07:32.114439 2026] [security2:error] [pid 358661:tid 358790] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.printcom.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9S9AlWhjQfpOo60_HmXwAAH30"]
[Tue Jul 21 08:07:32.210890 2026] [security2:error] [pid 358661:tid 358821] [client 20.226.60.151:12413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/test1.php"] [unique_id "al9S9AlWhjQfpOo60_HmYQAAABs"]
[Tue Jul 21 08:07:32.293607 2026] [security2:error] [pid 358661:tid 358732] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.printcom.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9S9AlWhjQfpOo60_HmZAAAHkM"]
[Tue Jul 21 08:07:32.373553 2026] [security2:error] [pid 358661:tid 358842] [client 20.226.60.151:11979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/database.php"] [unique_id "al9S9AlWhjQfpOo60_HmaAAAADA"]
[Tue Jul 21 08:07:32.424371 2026] [security2:error] [pid 352421:tid 352664] [client 65.21.113.253:56990] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S88JSWzG9jbYOtu5WvgAAAPY"]
[Tue Jul 21 08:07:32.619412 2026] [security2:error] [pid 358661:tid 358677] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.printcom.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9S9AlWhjQfpOo60_HmagAAZgw"]
[Tue Jul 21 08:07:32.700758 2026] [security2:error] [pid 352421:tid 352551] [client 41.68.90.219:57724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S9MJSWzG9jbYOtu5WyAAAAIU"]
[Tue Jul 21 08:07:32.704057 2026] [security2:error] [pid 352421:tid 352551] [client 41.68.90.219:57724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S9MJSWzG9jbYOtu5WyAAAAIU"]
[Tue Jul 21 08:07:32.749493 2026] [security2:error] [pid 358661:tid 358665] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.printcom.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9S9AlWhjQfpOo60_HmbAAAQwA"]
[Tue Jul 21 08:07:32.931917 2026] [security2:error] [pid 358661:tid 358748] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.printcom.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9S9AlWhjQfpOo60_HmcQAARFM"]
[Tue Jul 21 08:07:32.937863 2026] [security2:error] [pid 358661:tid 358816] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S9AlWhjQfpOo60_HmcgAAABY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:32.937974 2026] [security2:error] [pid 358661:tid 358816] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S9AlWhjQfpOo60_HmcgAAABY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:32.967256 2026] [security2:error] [pid 352421:tid 352573] [client 20.226.60.151:12020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/file.php"] [unique_id "al9S9MJSWzG9jbYOtu5WywAAAJs"]
[Tue Jul 21 08:07:33.034227 2026] [security2:error] [pid 358661:tid 358802] [client 175.144.82.48:56993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S9QlWhjQfpOo60_HmcwAAAAg"]
[Tue Jul 21 08:07:33.034999 2026] [security2:error] [pid 358661:tid 358802] [client 175.144.82.48:56993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S9QlWhjQfpOo60_HmcwAAAAg"]
[Tue Jul 21 08:07:33.055034 2026] [security2:error] [pid 358661:tid 358755] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.printcom.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9S9QlWhjQfpOo60_HmdAAAI1o"]
[Tue Jul 21 08:07:33.230734 2026] [security2:error] [pid 358661:tid 358741] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.printcom.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9S9QlWhjQfpOo60_HmdgAAcEw"]
[Tue Jul 21 08:07:33.231759 2026] [security2:error] [pid 358661:tid 358676] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S9QlWhjQfpOo60_HmdQAAHAs"]
[Tue Jul 21 08:07:33.231905 2026] [security2:error] [pid 358661:tid 358822] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S9QlWhjQfpOo60_HmdQAAHAs"]
[Tue Jul 21 08:07:33.289566 2026] [security2:error] [pid 358661:tid 358813] [client 65.21.113.253:48028] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9S9QlWhjQfpOo60_HmdwAAABM"]
[Tue Jul 21 08:07:33.332150 2026] [security2:error] [pid 358661:tid 358768] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S9QlWhjQfpOo60_HmeAAAUWc"]
[Tue Jul 21 08:07:33.332254 2026] [security2:error] [pid 358661:tid 358875] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S9QlWhjQfpOo60_HmeAAAUWc"]
[Tue Jul 21 08:07:33.379264 2026] [security2:error] [pid 358661:tid 358812] [client 89.249.196.30:45415] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "advcelsopinto.com.br"] [uri "/"] [unique_id "al9S9QlWhjQfpOo60_HmegAAABI"]
[Tue Jul 21 08:07:33.513323 2026] [security2:error] [pid 358661:tid 358670] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.printcom.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9S9QlWhjQfpOo60_HmewAAfQU"]
[Tue Jul 21 08:07:33.645842 2026] [security2:error] [pid 352421:tid 352499] [remote 57.141.18.14:46300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9S9cJSWzG9jbYOtu5W1AAAp00"]
[Tue Jul 21 08:07:33.682605 2026] [security2:error] [pid 358661:tid 358759] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.printcom.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9S9QlWhjQfpOo60_HmfQAADV4"]
[Tue Jul 21 08:07:33.782578 2026] [security2:error] [pid 358661:tid 358859] [client 20.226.60.151:64888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/ip.php"] [unique_id "al9S9QlWhjQfpOo60_HmgQAAAEE"]
[Tue Jul 21 08:07:33.906695 2026] [security2:error] [pid 352421:tid 352604] [client 65.21.113.253:56990] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S9cJSWzG9jbYOtu5W1QAAALo"]
[Tue Jul 21 08:07:34.010571 2026] [security2:error] [pid 358661:tid 358763] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.printcom.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9S9glWhjQfpOo60_HmgwAAT2I"]
[Tue Jul 21 08:07:34.027761 2026] [security2:error] [pid 352421:tid 352564] [client 103.166.103.129:29537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9S9sJSWzG9jbYOtu5W3AAAAJI"]
[Tue Jul 21 08:07:34.027921 2026] [security2:error] [pid 352421:tid 352564] [client 103.166.103.129:29537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9S9sJSWzG9jbYOtu5W3AAAAJI"]
[Tue Jul 21 08:07:34.045221 2026] [security2:error] [pid 358661:tid 358880] [client 20.226.60.151:65073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/kq1.php"] [unique_id "al9S9glWhjQfpOo60_HmhAAAAFY"]
[Tue Jul 21 08:07:34.055158 2026] [security2:error] [pid 352421:tid 352621] [client 109.60.28.94:11637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S9sJSWzG9jbYOtu5W3QAAAMs"]
[Tue Jul 21 08:07:34.055310 2026] [security2:error] [pid 352421:tid 352621] [client 109.60.28.94:11637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S9sJSWzG9jbYOtu5W3QAAAMs"]
[Tue Jul 21 08:07:34.064982 2026] [security2:error] [pid 358661:tid 358867] [client 20.226.60.151:64883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/fw/faiyy.php"] [unique_id "al9S9glWhjQfpOo60_HmhQAAAEk"]
[Tue Jul 21 08:07:34.090601 2026] [security2:error] [pid 352421:tid 352605] [client 20.226.60.151:64891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/h02ugyh.php"] [unique_id "al9S9sJSWzG9jbYOtu5W3gAAALs"]
[Tue Jul 21 08:07:34.144195 2026] [security2:error] [pid 352421:tid 352628] [client 20.226.60.151:56393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-temp.php"] [unique_id "al9S9sJSWzG9jbYOtu5W4AAAANI"]
[Tue Jul 21 08:07:34.199989 2026] [security2:error] [pid 358661:tid 358878] [client 20.226.60.151:12390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/file.php"] [unique_id "al9S9glWhjQfpOo60_HmiAAAAFQ"]
[Tue Jul 21 08:07:34.257031 2026] [security2:error] [pid 358661:tid 358685] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.printcom.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9S9glWhjQfpOo60_HmiQAAeBQ"]
[Tue Jul 21 08:07:34.427710 2026] [security2:error] [pid 358661:tid 358766] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.printcom.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9S9glWhjQfpOo60_HmjAAAU2U"]
[Tue Jul 21 08:07:34.487246 2026] [security2:error] [pid 358661:tid 358700] [remote 216.26.245.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.245.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S9AlWhjQfpOo60_HmZQAAYCM"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:34.640673 2026] [security2:error] [pid 358661:tid 358827] [client 151.63.71.144:53701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9S9glWhjQfpOo60_HmkAAAACE"]
[Tue Jul 21 08:07:34.640859 2026] [security2:error] [pid 358661:tid 358827] [client 151.63.71.144:53701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9S9glWhjQfpOo60_HmkAAAACE"]
[Tue Jul 21 08:07:34.672267 2026] [security2:error] [pid 358661:tid 358854] [client 20.226.60.151:65060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-content/cong.php"] [unique_id "al9S9glWhjQfpOo60_HmkgAAADw"]
[Tue Jul 21 08:07:34.825718 2026] [security2:error] [pid 352421:tid 352607] [client 194.39.34.132:36755] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "806"] [severity "CRITICAL"] [tag "SQLi"] [hostname "advcelsopinto.com.br"] [uri "/"] [unique_id "al9S9sJSWzG9jbYOtu5W5wAAAL0"]
[Tue Jul 21 08:07:34.900599 2026] [security2:error] [pid 358661:tid 358888] [client 202.143.127.214:49585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S9glWhjQfpOo60_HmlQAAAF4"]
[Tue Jul 21 08:07:34.900731 2026] [security2:error] [pid 358661:tid 358888] [client 202.143.127.214:49585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S9glWhjQfpOo60_HmlQAAAF4"]
[Tue Jul 21 08:07:35.073662 2026] [security2:error] [pid 352421:tid 352460] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9S98JSWzG9jbYOtu5W7AAAwyY"]
[Tue Jul 21 08:07:35.073803 2026] [security2:error] [pid 352421:tid 352613] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9S98JSWzG9jbYOtu5W7AAAwyY"]
[Tue Jul 21 08:07:35.191575 2026] [security2:error] [pid 352421:tid 352670] [client 120.56.162.40:58153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S98JSWzG9jbYOtu5W7wAAAPw"]
[Tue Jul 21 08:07:35.191858 2026] [security2:error] [pid 352421:tid 352670] [client 120.56.162.40:58153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S98JSWzG9jbYOtu5W7wAAAPw"]
[Tue Jul 21 08:07:35.294757 2026] [security2:error] [pid 358661:tid 358898] [client 20.226.60.151:12392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/777.php"] [unique_id "al9S9wlWhjQfpOo60_HmmAAAAGg"]
[Tue Jul 21 08:07:35.466731 2026] [security2:error] [pid 358661:tid 358861] [client 164.92.82.111:53098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.82.92.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/wp-login.php"] [unique_id "al9S9wlWhjQfpOo60_HmnAAAAEM"]
[Tue Jul 21 08:07:35.653130 2026] [security2:error] [pid 352421:tid 352563] [client 65.21.113.253:56996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S98JSWzG9jbYOtu5W8AAAAJE"]
[Tue Jul 21 08:07:35.706224 2026] [security2:error] [pid 352421:tid 352570] [client 102.206.115.33:64374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9S98JSWzG9jbYOtu5W-QAAAJg"]
[Tue Jul 21 08:07:35.706396 2026] [security2:error] [pid 352421:tid 352570] [client 102.206.115.33:64374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9S98JSWzG9jbYOtu5W-QAAAJg"]
[Tue Jul 21 08:07:35.769496 2026] [security2:error] [pid 358661:tid 358906] [client 20.226.60.151:64834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-includes/css/index.php"] [unique_id "al9S9wlWhjQfpOo60_HmowAAAHA"]
[Tue Jul 21 08:07:35.776133 2026] [security2:error] [pid 352421:tid 352532] [remote 104.207.48.156:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.48.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S98JSWzG9jbYOtu5W9QAA5G4"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:35.971247 2026] [security2:error] [pid 358661:tid 358896] [client 150.129.202.39:65358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S9wlWhjQfpOo60_HmpQAAAGY"]
[Tue Jul 21 08:07:35.971424 2026] [security2:error] [pid 358661:tid 358896] [client 150.129.202.39:65358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S9wlWhjQfpOo60_HmpQAAAGY"]
[Tue Jul 21 08:07:35.974763 2026] [security2:error] [pid 358661:tid 358875] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S9wlWhjQfpOo60_HmpgAAAFE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:36.183142 2026] [security2:error] [pid 358661:tid 358917] [client 164.92.82.111:51398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.82.92.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/wp-login.php"] [unique_id "al9S-AlWhjQfpOo60_HmqQAAAHs"], referer: https://advcelsopinto.com.br/wp-login.php
[Tue Jul 21 08:07:36.289280 2026] [security2:error] [pid 352421:tid 352447] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9S-MJSWzG9jbYOtu5XAAAA3hk"]
[Tue Jul 21 08:07:36.289407 2026] [security2:error] [pid 352421:tid 352640] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9S-MJSWzG9jbYOtu5XAAAA3hk"]
[Tue Jul 21 08:07:36.540504 2026] [security2:error] [pid 352421:tid 352586] [client 20.226.60.151:12201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/ssixta.php"] [unique_id "al9S-MJSWzG9jbYOtu5XBgAAAKg"]
[Tue Jul 21 08:07:36.663741 2026] [security2:error] [pid 358661:tid 358815] [client 20.226.60.151:65027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/jj.php"] [unique_id "al9S-AlWhjQfpOo60_HmqgAAABU"]
[Tue Jul 21 08:07:37.390940 2026] [security2:error] [pid 358661:tid 358817] [client 20.226.60.151:56424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al9S-QlWhjQfpOo60_HmtAAAABc"]
[Tue Jul 21 08:07:37.485697 2026] [security2:error] [pid 358661:tid 358833] [client 185.198.240.119:37779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-login.php"] [unique_id "al9S-QlWhjQfpOo60_HmswAAACc"]
[Tue Jul 21 08:07:37.541531 2026] [security2:error] [pid 358661:tid 358869] [client 51.89.129.22:55942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "gfacil.com.br"] [uri "/robots.txt"] [unique_id "al9S-QlWhjQfpOo60_HmtwAAAEs"]
[Tue Jul 21 08:07:37.541646 2026] [security2:error] [pid 358661:tid 358869] [client 51.89.129.22:55942] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gfacil.com.br"] [uri "/robots.txt"] [unique_id "al9S-QlWhjQfpOo60_HmtwAAAEs"]
[Tue Jul 21 08:07:37.589033 2026] [security2:error] [pid 358661:tid 358803] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9S-QlWhjQfpOo60_HmtQAACT4"]
[Tue Jul 21 08:07:37.806695 2026] [security2:error] [pid 358661:tid 358697] [remote 45.3.32.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.32.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S-AlWhjQfpOo60_HmsAAAaiA"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:37.848122 2026] [security2:error] [pid 358661:tid 358821] [client 20.226.60.151:12013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/1c.php"] [unique_id "al9S-QlWhjQfpOo60_HmvAAAABs"]
[Tue Jul 21 08:07:37.882805 2026] [security2:error] [pid 352421:tid 352449] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9S-cJSWzG9jbYOtu5XGAAA0xs"]
[Tue Jul 21 08:07:37.882959 2026] [security2:error] [pid 352421:tid 352629] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9S-cJSWzG9jbYOtu5XGAAA0xs"]
[Tue Jul 21 08:07:37.908879 2026] [security2:error] [pid 358661:tid 358743] [remote 72.167.132.114:45228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9S-QlWhjQfpOo60_HmvgAAc04"]
[Tue Jul 21 08:07:38.219475 2026] [security2:error] [pid 352421:tid 352560] [client 20.226.60.151:65043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/txets.php"] [unique_id "al9S-sJSWzG9jbYOtu5XIAAAAI4"]
[Tue Jul 21 08:07:38.418759 2026] [security2:error] [pid 358661:tid 358794] [client 103.78.200.11:51340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S-glWhjQfpOo60_HmxgAAAAA"]
[Tue Jul 21 08:07:38.418910 2026] [security2:error] [pid 358661:tid 358794] [client 103.78.200.11:51340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S-glWhjQfpOo60_HmxgAAAAA"]
[Tue Jul 21 08:07:38.464280 2026] [security2:error] [pid 358661:tid 358809] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S-glWhjQfpOo60_HmxwAAAA8"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:38.548720 2026] [security2:error] [pid 358661:tid 358918] [client 20.226.60.151:11971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/test2.php"] [unique_id "al9S-glWhjQfpOo60_HmyAAAAHw"]
[Tue Jul 21 08:07:38.592462 2026] [security2:error] [pid 352421:tid 352604] [client 178.153.91.96:50204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9S-sJSWzG9jbYOtu5XJgAAALo"]
[Tue Jul 21 08:07:38.592571 2026] [security2:error] [pid 352421:tid 352604] [client 178.153.91.96:50204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9S-sJSWzG9jbYOtu5XJgAAALo"]
[Tue Jul 21 08:07:38.760598 2026] [security2:error] [pid 358661:tid 358883] [client 103.29.114.44:20167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S-glWhjQfpOo60_HmzAAAAFk"]
[Tue Jul 21 08:07:38.760731 2026] [security2:error] [pid 358661:tid 358883] [client 103.29.114.44:20167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S-glWhjQfpOo60_HmzAAAAFk"]
[Tue Jul 21 08:07:38.946293 2026] [security2:error] [pid 358661:tid 358843] [client 142.44.225.140:61036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "gfacil.com.br"] [uri "/"] [unique_id "al9S-glWhjQfpOo60_Hm0wAAADE"]
[Tue Jul 21 08:07:38.946392 2026] [security2:error] [pid 358661:tid 358843] [client 142.44.225.140:61036] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gfacil.com.br"] [uri "/"] [unique_id "al9S-glWhjQfpOo60_Hm0wAAADE"]
[Tue Jul 21 08:07:38.992880 2026] [security2:error] [pid 358661:tid 358764] [remote 216.26.224.128:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.224.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S-glWhjQfpOo60_Hm0gAAVWM"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:39.072916 2026] [security2:error] [pid 358661:tid 358807] [client 20.226.60.151:12129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/buy.php"] [unique_id "al9S-wlWhjQfpOo60_Hm1gAAAA0"]
[Tue Jul 21 08:07:39.141521 2026] [security2:error] [pid 358661:tid 358684] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S-wlWhjQfpOo60_Hm2AAASBM"]
[Tue Jul 21 08:07:39.141685 2026] [security2:error] [pid 358661:tid 358866] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S-wlWhjQfpOo60_Hm2AAASBM"]
[Tue Jul 21 08:07:39.292201 2026] [security2:error] [pid 352421:tid 352628] [client 62.102.148.158:41560] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9S-sJSWzG9jbYOtu5XHwAAANI"]
[Tue Jul 21 08:07:39.292337 2026] [security2:error] [pid 352421:tid 352628] [client 62.102.148.158:41560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9S-sJSWzG9jbYOtu5XHwAAANI"]
[Tue Jul 21 08:07:39.334186 2026] [security2:error] [pid 358661:tid 358921] [client 87.116.180.198:27157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S-wlWhjQfpOo60_Hm3AAAAH8"]
[Tue Jul 21 08:07:39.335698 2026] [security2:error] [pid 358661:tid 358921] [client 87.116.180.198:27157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S-wlWhjQfpOo60_Hm3AAAAH8"]
[Tue Jul 21 08:07:39.383886 2026] [security2:error] [pid 358661:tid 358867] [client 20.226.60.151:64895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/dex.php"] [unique_id "al9S-wlWhjQfpOo60_Hm3QAAAEk"]
[Tue Jul 21 08:07:39.598237 2026] [security2:error] [pid 358661:tid 358811] [client 117.210.135.0:59110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S-wlWhjQfpOo60_Hm3wAAABE"]
[Tue Jul 21 08:07:39.598883 2026] [security2:error] [pid 358661:tid 358811] [client 117.210.135.0:59110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S-wlWhjQfpOo60_Hm3wAAABE"]
[Tue Jul 21 08:07:39.609952 2026] [security2:error] [pid 352421:tid 352601] [client 20.226.60.151:65059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/xpwer1.php"] [unique_id "al9S-8JSWzG9jbYOtu5XNgAAALc"]
[Tue Jul 21 08:07:39.699993 2026] [security2:error] [pid 358661:tid 358850] [client 37.140.223.69:20859] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S-wlWhjQfpOo60_Hm4AAAADg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:39.700168 2026] [security2:error] [pid 358661:tid 358850] [client 37.140.223.69:20859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9S-wlWhjQfpOo60_Hm4AAAADg"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:40.031980 2026] [security2:error] [pid 352421:tid 352619] [client 20.197.192.193:3478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/edit.php"] [unique_id "al9S_MJSWzG9jbYOtu5XPwAAAMk"]
[Tue Jul 21 08:07:40.043968 2026] [security2:error] [pid 358661:tid 358709] [remote 216.26.233.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.233.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S_AlWhjQfpOo60_Hm4wAAYCw"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:40.328010 2026] [security2:error] [pid 358661:tid 358908] [client 117.247.80.59:15574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S_AlWhjQfpOo60_Hm6QAAAHI"]
[Tue Jul 21 08:07:40.328145 2026] [security2:error] [pid 358661:tid 358908] [client 117.247.80.59:15574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S_AlWhjQfpOo60_Hm6QAAAHI"]
[Tue Jul 21 08:07:40.335342 2026] [security2:error] [pid 352421:tid 352646] [client 65.21.113.253:56996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S-8JSWzG9jbYOtu5XOwAAAOQ"]
[Tue Jul 21 08:07:40.450268 2026] [security2:error] [pid 358661:tid 358739] [remote 20.153.140.50:33034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carrosselbuique.com.br"] [uri "/wp-login.php"] [unique_id "al9S_AlWhjQfpOo60_Hm7AAAIUo"]
[Tue Jul 21 08:07:40.595760 2026] [security2:error] [pid 358661:tid 358901] [client 62.102.148.158:38138] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9S_AlWhjQfpOo60_Hm7wAAAGs"]
[Tue Jul 21 08:07:40.595861 2026] [security2:error] [pid 358661:tid 358901] [client 62.102.148.158:38138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9S_AlWhjQfpOo60_Hm7wAAAGs"]
[Tue Jul 21 08:07:40.649965 2026] [security2:error] [pid 358661:tid 358903] [client 20.226.60.151:56445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/flox.php"] [unique_id "al9S_AlWhjQfpOo60_Hm8QAAAG0"]
[Tue Jul 21 08:07:40.871832 2026] [security2:error] [pid 358661:tid 358692] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9S_AlWhjQfpOo60_Hm8wAAHhs"]
[Tue Jul 21 08:07:40.872001 2026] [security2:error] [pid 358661:tid 358824] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9S_AlWhjQfpOo60_Hm8wAAHhs"]
[Tue Jul 21 08:07:41.086341 2026] [security2:error] [pid 358661:tid 358813] [client 20.226.60.151:12360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/ssend.php"] [unique_id "al9S_QlWhjQfpOo60_Hm-QAAABM"]
[Tue Jul 21 08:07:41.107927 2026] [security2:error] [pid 358661:tid 358818] [client 65.21.113.253:43430] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9S_QlWhjQfpOo60_Hm-wAAABg"]
[Tue Jul 21 08:07:41.203192 2026] [security2:error] [pid 352421:tid 352423] [remote 45.3.33.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.33.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S_cJSWzG9jbYOtu5XTgAAjQE"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:41.505011 2026] [security2:error] [pid 358661:tid 358881] [client 86.106.84.166:59046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9S_AlWhjQfpOo60_Hm7QAAAFc"]
[Tue Jul 21 08:07:41.505126 2026] [security2:error] [pid 358661:tid 358881] [client 86.106.84.166:59046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9S_AlWhjQfpOo60_Hm7QAAAFc"]
[Tue Jul 21 08:07:41.633455 2026] [security2:error] [pid 358661:tid 358907] [client 38.100.221.102:18960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S_QlWhjQfpOo60_HnAQAAAHE"]
[Tue Jul 21 08:07:41.633599 2026] [security2:error] [pid 358661:tid 358907] [client 38.100.221.102:18960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S_QlWhjQfpOo60_HnAQAAAHE"]
[Tue Jul 21 08:07:41.725909 2026] [security2:error] [pid 352421:tid 352642] [client 65.21.113.253:56996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S_cJSWzG9jbYOtu5XVgAAAOA"]
[Tue Jul 21 08:07:41.968774 2026] [security2:error] [pid 352421:tid 352597] [client 20.226.60.151:64871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/popo.php"] [unique_id "al9S_cJSWzG9jbYOtu5XaAAAALM"]
[Tue Jul 21 08:07:42.381147 2026] [security2:error] [pid 358661:tid 358775] [remote 65.111.1.250:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.1.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S_glWhjQfpOo60_HnDgAAdm4"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:42.828881 2026] [security2:error] [pid 358661:tid 358823] [client 20.197.192.193:3457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/2x.php"] [unique_id "al9S_glWhjQfpOo60_HnFgAAAB0"]
[Tue Jul 21 08:07:42.864471 2026] [security2:error] [pid 358661:tid 358804] [client 61.1.167.83:55259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S_glWhjQfpOo60_HnFwAAAAo"]
[Tue Jul 21 08:07:42.864591 2026] [security2:error] [pid 358661:tid 358804] [client 61.1.167.83:55259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S_glWhjQfpOo60_HnFwAAAAo"]
[Tue Jul 21 08:07:42.883365 2026] [security2:error] [pid 352421:tid 352589] [client 175.144.82.48:57441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S_sJSWzG9jbYOtu5XdQAAAKs"]
[Tue Jul 21 08:07:42.884038 2026] [security2:error] [pid 352421:tid 352589] [client 175.144.82.48:57441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S_sJSWzG9jbYOtu5XdQAAAKs"]
[Tue Jul 21 08:07:43.294618 2026] [security2:error] [pid 352421:tid 352563] [client 41.68.90.219:58190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S_8JSWzG9jbYOtu5XewAAAJE"]
[Tue Jul 21 08:07:43.295945 2026] [security2:error] [pid 352421:tid 352563] [client 41.68.90.219:58190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9S_8JSWzG9jbYOtu5XewAAAJE"]
[Tue Jul 21 08:07:43.329705 2026] [security2:error] [pid 358661:tid 358918] [client 20.197.192.193:39287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/kua.php"] [unique_id "al9S_wlWhjQfpOo60_HnHQAAAHw"]
[Tue Jul 21 08:07:43.363701 2026] [security2:error] [pid 358661:tid 358712] [remote 209.50.188.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.188.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9S_wlWhjQfpOo60_HnGgAADC8"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:44.172422 2026] [security2:error] [pid 352421:tid 352588] [client 65.21.113.253:58938] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9S_8JSWzG9jbYOtu5XgQAAAKo"]
[Tue Jul 21 08:07:44.212685 2026] [security2:error] [pid 358661:tid 358897] [client 20.226.60.151:63949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/yas.php"] [unique_id "al9TAAlWhjQfpOo60_HnLwAAAGc"]
[Tue Jul 21 08:07:44.214477 2026] [security2:error] [pid 352421:tid 352425] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TAMJSWzG9jbYOtu5XiQAA6wM"]
[Tue Jul 21 08:07:44.214644 2026] [security2:error] [pid 352421:tid 352653] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TAMJSWzG9jbYOtu5XiQAA6wM"]
[Tue Jul 21 08:07:44.377312 2026] [security2:error] [pid 358661:tid 358740] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TAAlWhjQfpOo60_HnNQAARks"]
[Tue Jul 21 08:07:44.377445 2026] [security2:error] [pid 358661:tid 358864] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TAAlWhjQfpOo60_HnNQAARks"]
[Tue Jul 21 08:07:44.420631 2026] [security2:error] [pid 352421:tid 352638] [client 193.36.225.72:32139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9TAMJSWzG9jbYOtu5XjwAAANw"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:44.495943 2026] [security2:error] [pid 352421:tid 352620] [client 34.23.44.61:53805] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oppbrazil.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9TAMJSWzG9jbYOtu5XkAAAAMo"]
[Tue Jul 21 08:07:44.805379 2026] [security2:error] [pid 358661:tid 358808] [client 103.166.103.129:51528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TAAlWhjQfpOo60_HnOwAAAA4"]
[Tue Jul 21 08:07:44.805505 2026] [security2:error] [pid 358661:tid 358808] [client 103.166.103.129:51528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TAAlWhjQfpOo60_HnOwAAAA4"]
[Tue Jul 21 08:07:44.829461 2026] [security2:error] [pid 352421:tid 352643] [client 109.60.28.94:12093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TAMJSWzG9jbYOtu5XlAAAAOE"]
[Tue Jul 21 08:07:44.830282 2026] [security2:error] [pid 352421:tid 352643] [client 109.60.28.94:12093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TAMJSWzG9jbYOtu5XlAAAAOE"]
[Tue Jul 21 08:07:44.985370 2026] [security2:error] [pid 352421:tid 352523] [remote 51.68.107.149:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "falarmelhor.com.br"] [uri "/robots.txt"] [unique_id "al9TAMJSWzG9jbYOtu5XlwAA42U"]
[Tue Jul 21 08:07:44.985582 2026] [security2:error] [pid 352421:tid 352645] [client 51.68.107.149:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "falarmelhor.com.br"] [uri "/robots.txt"] [unique_id "al9TAMJSWzG9jbYOtu5XlwAA42U"]
[Tue Jul 21 08:07:45.241864 2026] [security2:error] [pid 358661:tid 358798] [client 20.226.60.151:12024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/item.php"] [unique_id "al9TAQlWhjQfpOo60_HnRAAAAAQ"]
[Tue Jul 21 08:07:45.417955 2026] [security2:error] [pid 358661:tid 358918] [client 20.226.60.151:65044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/file61.php"] [unique_id "al9TAQlWhjQfpOo60_HnSwAAAHw"]
[Tue Jul 21 08:07:45.589989 2026] [security2:error] [pid 352421:tid 352592] [client 20.197.192.193:53160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/wp-mt.php"] [unique_id "al9TAcJSWzG9jbYOtu5XoQAAAK4"]
[Tue Jul 21 08:07:45.695097 2026] [security2:error] [pid 352421:tid 352439] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TAcJSWzG9jbYOtu5XpgAA0RE"]
[Tue Jul 21 08:07:45.695226 2026] [security2:error] [pid 352421:tid 352627] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TAcJSWzG9jbYOtu5XpgAA0RE"]
[Tue Jul 21 08:07:45.770853 2026] [security2:error] [pid 358661:tid 358909] [client 120.56.162.40:58756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TAQlWhjQfpOo60_HnVgAAAHM"]
[Tue Jul 21 08:07:45.770998 2026] [security2:error] [pid 358661:tid 358909] [client 120.56.162.40:58756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TAQlWhjQfpOo60_HnVgAAAHM"]
[Tue Jul 21 08:07:45.817123 2026] [autoindex:error] [pid 352421:tid 352624] [client 172.252.90.227:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:07:46.045869 2026] [security2:error] [pid 358661:tid 358787] [remote 65.111.24.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TAAlWhjQfpOo60_HnPAAASXo"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:46.068582 2026] [security2:error] [pid 352421:tid 352548] [remote 20.75.217.73:2198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "precisosolucao.com.br"] [uri "/wp-login.php"] [unique_id "al9TAsJSWzG9jbYOtu5XsAAAjn4"]
[Tue Jul 21 08:07:46.111949 2026] [security2:error] [pid 358661:tid 358832] [client 202.143.127.214:50116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TAglWhjQfpOo60_HnWwAAACY"]
[Tue Jul 21 08:07:46.112446 2026] [security2:error] [pid 358661:tid 358832] [client 202.143.127.214:50116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TAglWhjQfpOo60_HnWwAAACY"]
[Tue Jul 21 08:07:46.245956 2026] [security2:error] [pid 352421:tid 352579] [client 102.206.115.33:60841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TAsJSWzG9jbYOtu5XswAAAKE"]
[Tue Jul 21 08:07:46.246080 2026] [security2:error] [pid 352421:tid 352579] [client 102.206.115.33:60841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TAsJSWzG9jbYOtu5XswAAAKE"]
[Tue Jul 21 08:07:46.439933 2026] [security2:error] [pid 358661:tid 358915] [client 62.102.148.158:38200] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9TAglWhjQfpOo60_HnYAAAAHk"]
[Tue Jul 21 08:07:46.440040 2026] [security2:error] [pid 358661:tid 358915] [client 62.102.148.158:38200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9TAglWhjQfpOo60_HnYAAAAHk"]
[Tue Jul 21 08:07:46.440082 2026] [security2:error] [pid 358661:tid 358849] [client 20.29.126.15:20163] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "mail.atilafagundes.com.br"] [uri "/.info.php"] [unique_id "al9TAglWhjQfpOo60_HnYQAAADc"]
[Tue Jul 21 08:07:46.573985 2026] [security2:error] [pid 358661:tid 358842] [client 34.23.44.61:51171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.44.23.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oppbrazil.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TAQlWhjQfpOo60_HnUwAAADA"]
[Tue Jul 21 08:07:46.679998 2026] [security2:error] [pid 358661:tid 358822] [client 150.129.202.39:65181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TAglWhjQfpOo60_HnYgAAABw"]
[Tue Jul 21 08:07:46.680145 2026] [security2:error] [pid 358661:tid 358822] [client 150.129.202.39:65181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TAglWhjQfpOo60_HnYgAAABw"]
[Tue Jul 21 08:07:46.963091 2026] [security2:error] [pid 358661:tid 358729] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TAglWhjQfpOo60_HnZwAAf0A"]
[Tue Jul 21 08:07:46.963354 2026] [security2:error] [pid 358661:tid 358921] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TAglWhjQfpOo60_HnZwAAf0A"]
[Tue Jul 21 08:07:47.515683 2026] [security2:error] [pid 352421:tid 352615] [client 65.21.113.253:58938] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TA8JSWzG9jbYOtu5XvQAAAMU"]
[Tue Jul 21 08:07:47.719376 2026] [security2:error] [pid 358661:tid 358804] [client 65.21.113.253:43434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TAwlWhjQfpOo60_HncgAAAAo"]
[Tue Jul 21 08:07:48.063883 2026] [security2:error] [pid 358661:tid 358901] [client 20.197.192.193:64502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/kq1.php"] [unique_id "al9TBAlWhjQfpOo60_HndQAAAGs"]
[Tue Jul 21 08:07:48.229292 2026] [security2:error] [pid 358661:tid 358827] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TBAlWhjQfpOo60_HndwAAIWg"]
[Tue Jul 21 08:07:48.342318 2026] [security2:error] [pid 352421:tid 352541] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TBMJSWzG9jbYOtu5X1AAAl3c"]
[Tue Jul 21 08:07:48.342498 2026] [security2:error] [pid 352421:tid 352569] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TBMJSWzG9jbYOtu5X1AAAl3c"]
[Tue Jul 21 08:07:48.352466 2026] [security2:error] [pid 352421:tid 352665] [client 65.21.113.253:58938] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TA8JSWzG9jbYOtu5XzQAAAPc"]
[Tue Jul 21 08:07:48.555185 2026] [security2:error] [pid 358661:tid 358829] [client 20.226.60.151:64844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/water.php"] [unique_id "al9TBAlWhjQfpOo60_HnggAAACM"]
[Tue Jul 21 08:07:48.793883 2026] [security2:error] [pid 358661:tid 358678] [remote 209.50.180.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.180.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TBAlWhjQfpOo60_HngwAATQ0"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:49.032271 2026] [security2:error] [pid 358661:tid 358892] [client 103.78.200.11:51830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TBQlWhjQfpOo60_HnigAAAGI"]
[Tue Jul 21 08:07:49.032397 2026] [security2:error] [pid 358661:tid 358892] [client 103.78.200.11:51830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TBQlWhjQfpOo60_HnigAAAGI"]
[Tue Jul 21 08:07:49.075905 2026] [security2:error] [pid 352421:tid 352594] [client 178.153.91.96:47999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TBcJSWzG9jbYOtu5X4gAAALA"]
[Tue Jul 21 08:07:49.076013 2026] [security2:error] [pid 352421:tid 352594] [client 178.153.91.96:47999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TBcJSWzG9jbYOtu5X4gAAALA"]
[Tue Jul 21 08:07:49.537940 2026] [security2:error] [pid 358661:tid 358811] [client 193.36.225.64:40611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9TBQlWhjQfpOo60_HnkQAAABE"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:49.650562 2026] [security2:error] [pid 358661:tid 358760] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TBQlWhjQfpOo60_HnlAAAP18"]
[Tue Jul 21 08:07:49.650730 2026] [security2:error] [pid 358661:tid 358857] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TBQlWhjQfpOo60_HnlAAAP18"]
[Tue Jul 21 08:07:49.761052 2026] [security2:error] [pid 358661:tid 358867] [client 103.29.114.44:50815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TBQlWhjQfpOo60_HnlgAAAEk"]
[Tue Jul 21 08:07:49.761169 2026] [security2:error] [pid 358661:tid 358867] [client 103.29.114.44:50815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TBQlWhjQfpOo60_HnlgAAAEk"]
[Tue Jul 21 08:07:49.851552 2026] [security2:error] [pid 358661:tid 358869] [client 20.226.60.151:12363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/ss.php"] [unique_id "al9TBQlWhjQfpOo60_HnmwAAAEs"]
[Tue Jul 21 08:07:50.043270 2026] [security2:error] [pid 352421:tid 352575] [client 87.116.180.198:14053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TBsJSWzG9jbYOtu5YDQAAAJ0"]
[Tue Jul 21 08:07:50.043441 2026] [security2:error] [pid 352421:tid 352575] [client 87.116.180.198:14053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TBsJSWzG9jbYOtu5YDQAAAJ0"]
[Tue Jul 21 08:07:50.116464 2026] [security2:error] [pid 358661:tid 358835] [client 117.210.135.0:59762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TBglWhjQfpOo60_HnoAAAACk"]
[Tue Jul 21 08:07:50.116591 2026] [security2:error] [pid 358661:tid 358835] [client 117.210.135.0:59762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TBglWhjQfpOo60_HnoAAAACk"]
[Tue Jul 21 08:07:50.527330 2026] [security2:error] [pid 358661:tid 358872] [client 20.29.126.15:7096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/item.php"] [unique_id "al9TBglWhjQfpOo60_HnrgAAAE4"]
[Tue Jul 21 08:07:50.842749 2026] [security2:error] [pid 352421:tid 352657] [client 20.197.192.193:39282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/ez.php"] [unique_id "al9TBsJSWzG9jbYOtu5YGAAAAO8"]
[Tue Jul 21 08:07:50.887283 2026] [security2:error] [pid 352421:tid 352664] [client 20.226.60.151:56414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/nano.php"] [unique_id "al9TBsJSWzG9jbYOtu5YGQAAAPY"]
[Tue Jul 21 08:07:51.022175 2026] [security2:error] [pid 358661:tid 358860] [client 117.247.80.59:15088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TBwlWhjQfpOo60_HntAAAAEI"]
[Tue Jul 21 08:07:51.022322 2026] [security2:error] [pid 358661:tid 358860] [client 117.247.80.59:15088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TBwlWhjQfpOo60_HntAAAAEI"]
[Tue Jul 21 08:07:51.087309 2026] [security2:error] [pid 358661:tid 358765] [remote 41.186.86.12:65464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9TBglWhjQfpOo60_HnswAAfGQ"]
[Tue Jul 21 08:07:51.296409 2026] [security2:error] [pid 358661:tid 358680] [remote 65.111.22.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TBwlWhjQfpOo60_HnuAAAHw8"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:51.361253 2026] [security2:error] [pid 352421:tid 352595] [client 20.197.192.193:3476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/zzz.php"] [unique_id "al9TB8JSWzG9jbYOtu5YIQAAALE"]
[Tue Jul 21 08:07:51.449293 2026] [security2:error] [pid 358661:tid 358854] [client 20.10.88.201:62595] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rioclaroimovel.com.br"] [uri "/index.php"] [unique_id "al9TBwlWhjQfpOo60_HntgAAADw"]
[Tue Jul 21 08:07:51.847847 2026] [security2:error] [pid 358661:tid 358713] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TBwlWhjQfpOo60_HnvgAAQDA"]
[Tue Jul 21 08:07:51.848060 2026] [security2:error] [pid 358661:tid 358858] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TBwlWhjQfpOo60_HnvgAAQDA"]
[Tue Jul 21 08:07:51.910103 2026] [security2:error] [pid 358661:tid 358867] [client 162.219.176.3:60256] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9TBwlWhjQfpOo60_HnvwAAAEk"]
[Tue Jul 21 08:07:51.910203 2026] [security2:error] [pid 358661:tid 358867] [client 162.219.176.3:60256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9TBwlWhjQfpOo60_HnvwAAAEk"]
[Tue Jul 21 08:07:52.228831 2026] [security2:error] [pid 352421:tid 352677] [client 38.100.221.102:17414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TCMJSWzG9jbYOtu5YQQAAAQM"]
[Tue Jul 21 08:07:52.228990 2026] [security2:error] [pid 352421:tid 352677] [client 38.100.221.102:17414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TCMJSWzG9jbYOtu5YQQAAAQM"]
[Tue Jul 21 08:07:52.299769 2026] [security2:error] [pid 352421:tid 352671] [client 20.226.60.151:65056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/moon.php"] [unique_id "al9TCMJSWzG9jbYOtu5YQwAAAP0"]
[Tue Jul 21 08:07:52.527208 2026] [security2:error] [pid 352421:tid 352498] [remote 216.26.225.209:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.225.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TCMJSWzG9jbYOtu5YRAAA30w"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:52.574363 2026] [security2:error] [pid 358661:tid 358895] [client 65.21.113.253:57220] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TCAlWhjQfpOo60_HnwgAAAGU"]
[Tue Jul 21 08:07:52.777018 2026] [security2:error] [pid 358661:tid 358910] [client 34.23.44.61:51904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.44.23.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oppbrazil.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TCAlWhjQfpOo60_HnzgAAAHQ"]
[Tue Jul 21 08:07:52.777175 2026] [security2:error] [pid 358661:tid 358910] [client 34.23.44.61:51904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oppbrazil.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TCAlWhjQfpOo60_HnzgAAAHQ"]
[Tue Jul 21 08:07:53.217563 2026] [security2:error] [pid 352421:tid 352569] [client 193.36.225.73:54525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9TCcJSWzG9jbYOtu5YVgAAAJc"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:53.251567 2026] [security2:error] [pid 352421:tid 352622] [client 172.236.244.218:60454] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "fgengenharia.eng.br"] [uri "/wp-json/batch/v1"] [unique_id "al9TCcJSWzG9jbYOtu5YWAAAAMw"]
[Tue Jul 21 08:07:53.288251 2026] [security2:error] [pid 352421:tid 352478] [remote 65.111.6.189:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.6.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TCcJSWzG9jbYOtu5YWgAAzjg"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:53.394656 2026] [security2:error] [pid 358661:tid 358899] [client 20.29.126.15:2353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/albin.php"] [unique_id "al9TCQlWhjQfpOo60_Hn1gAAAGk"]
[Tue Jul 21 08:07:53.426532 2026] [security2:error] [pid 352421:tid 352599] [client 172.236.244.218:60454] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "fgengenharia.eng.br"] [uri "/"] [unique_id "al9TCcJSWzG9jbYOtu5YXAAAALU"]
[Tue Jul 21 08:07:53.642102 2026] [security2:error] [pid 358661:tid 358838] [client 20.226.60.151:12373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/hypo.php"] [unique_id "al9TCQlWhjQfpOo60_Hn2wAAACw"]
[Tue Jul 21 08:07:53.671691 2026] [security2:error] [pid 352421:tid 352554] [client 175.144.82.48:57917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TCcJSWzG9jbYOtu5YZgAAAIg"]
[Tue Jul 21 08:07:53.672593 2026] [security2:error] [pid 352421:tid 352554] [client 175.144.82.48:57917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TCcJSWzG9jbYOtu5YZgAAAIg"]
[Tue Jul 21 08:07:53.853303 2026] [security2:error] [pid 352421:tid 352572] [client 41.68.90.219:58653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TCcJSWzG9jbYOtu5YawAAAJo"]
[Tue Jul 21 08:07:53.854375 2026] [security2:error] [pid 352421:tid 352572] [client 41.68.90.219:58653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TCcJSWzG9jbYOtu5YawAAAJo"]
[Tue Jul 21 08:07:54.021989 2026] [security2:error] [pid 358661:tid 358918] [client 20.226.60.151:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-info.php"] [unique_id "al9TCglWhjQfpOo60_Hn3QAAAHw"]
[Tue Jul 21 08:07:54.106887 2026] [core:alert] [pid 358661:tid 358804] [client 57.141.18.45:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:07:54.296646 2026] [security2:error] [pid 358661:tid 358857] [client 74.7.228.8:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "danielaleaonaccari1755804563209.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9TCglWhjQfpOo60_Hn5wAAPwM"]
[Tue Jul 21 08:07:54.464194 2026] [security2:error] [pid 358661:tid 358673] [remote 216.26.230.119:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.230.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TCglWhjQfpOo60_Hn5gAAPAg"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:55.003926 2026] [security2:error] [pid 352421:tid 352462] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TC8JSWzG9jbYOtu5YjgAAxSg"]
[Tue Jul 21 08:07:55.004114 2026] [security2:error] [pid 352421:tid 352615] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TC8JSWzG9jbYOtu5YjgAAxSg"]
[Tue Jul 21 08:07:55.221295 2026] [security2:error] [pid 352421:tid 352500] [remote 65.111.6.91:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.6.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TC8JSWzG9jbYOtu5YlwAAyU4"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:55.384287 2026] [security2:error] [pid 358661:tid 358805] [client 65.21.113.253:46176] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9TCwlWhjQfpOo60_Hn-gAAAAs"]
[Tue Jul 21 08:07:55.424792 2026] [security2:error] [pid 352421:tid 352649] [client 20.197.192.193:52246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/ww.php"] [unique_id "al9TC8JSWzG9jbYOtu5YngAAAOc"]
[Tue Jul 21 08:07:55.447243 2026] [security2:error] [pid 352421:tid 352483] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TC8JSWzG9jbYOtu5YnwAA1D0"]
[Tue Jul 21 08:07:55.447450 2026] [security2:error] [pid 352421:tid 352630] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TC8JSWzG9jbYOtu5YnwAA1D0"]
[Tue Jul 21 08:07:55.570853 2026] [security2:error] [pid 358661:tid 358878] [client 20.104.96.117:62547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9TCwlWhjQfpOo60_Hn_AAAAFQ"]
[Tue Jul 21 08:07:55.580003 2026] [security2:error] [pid 352421:tid 352653] [client 109.60.28.94:12567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TC8JSWzG9jbYOtu5YoAAAAOs"]
[Tue Jul 21 08:07:55.580840 2026] [security2:error] [pid 352421:tid 352653] [client 109.60.28.94:12567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TC8JSWzG9jbYOtu5YoAAAAOs"]
[Tue Jul 21 08:07:55.584983 2026] [security2:error] [pid 358661:tid 358914] [client 20.226.60.151:11988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/users.php"] [unique_id "al9TCwlWhjQfpOo60_Hn_QAAAHg"]
[Tue Jul 21 08:07:55.627415 2026] [security2:error] [pid 358661:tid 358833] [client 103.166.103.129:30645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TCwlWhjQfpOo60_Hn_wAAACc"]
[Tue Jul 21 08:07:55.629210 2026] [security2:error] [pid 358661:tid 358833] [client 103.166.103.129:30645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TCwlWhjQfpOo60_Hn_wAAACc"]
[Tue Jul 21 08:07:55.813279 2026] [security2:error] [pid 358661:tid 358737] [remote 45.150.79.142:50922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9TCwlWhjQfpOo60_HoBwAAckg"]
[Tue Jul 21 08:07:56.156098 2026] [security2:error] [pid 358661:tid 358874] [client 65.21.113.253:57220] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TCwlWhjQfpOo60_HoAAAAAFA"]
[Tue Jul 21 08:07:56.231394 2026] [security2:error] [pid 358661:tid 358872] [client 65.21.113.253:57234] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TDAlWhjQfpOo60_HoDQAAAE4"]
[Tue Jul 21 08:07:56.281399 2026] [security2:error] [pid 358661:tid 358789] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TDAlWhjQfpOo60_HoEQAAbXw"]
[Tue Jul 21 08:07:56.281575 2026] [security2:error] [pid 358661:tid 358903] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TDAlWhjQfpOo60_HoEQAAbXw"]
[Tue Jul 21 08:07:56.444373 2026] [security2:error] [pid 358661:tid 358827] [client 20.226.60.151:65062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/2000.php"] [unique_id "al9TDAlWhjQfpOo60_HoHQAAACE"]
[Tue Jul 21 08:07:56.459073 2026] [security2:error] [pid 352421:tid 352641] [client 120.56.162.40:59234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TDMJSWzG9jbYOtu5YuAAAAN8"]
[Tue Jul 21 08:07:56.459192 2026] [security2:error] [pid 352421:tid 352641] [client 120.56.162.40:59234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TDMJSWzG9jbYOtu5YuAAAAN8"]
[Tue Jul 21 08:07:56.679542 2026] [security2:error] [pid 358661:tid 358814] [client 65.21.113.253:46188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TDAlWhjQfpOo60_HoHwAAABQ"]
[Tue Jul 21 08:07:56.689475 2026] [security2:error] [pid 358661:tid 358699] [remote 216.26.249.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.249.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TDAlWhjQfpOo60_HoIAAAeSI"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:56.737684 2026] [security2:error] [pid 358661:tid 358710] [remote 185.27.20.235:44714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.20.27.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roha.life"] [uri "/wp-login.php"] [unique_id "al9TDAlWhjQfpOo60_HoIgAAGi0"]
[Tue Jul 21 08:07:56.821465 2026] [security2:error] [pid 352421:tid 352602] [client 102.206.115.33:57957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TDMJSWzG9jbYOtu5YvAAAALg"]
[Tue Jul 21 08:07:56.821717 2026] [security2:error] [pid 352421:tid 352602] [client 102.206.115.33:57957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TDMJSWzG9jbYOtu5YvAAAALg"]
[Tue Jul 21 08:07:56.998096 2026] [security2:error] [pid 352421:tid 352552] [client 20.226.60.151:64878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/122.php"] [unique_id "al9TDMJSWzG9jbYOtu5YwAAAAIY"]
[Tue Jul 21 08:07:57.021387 2026] [security2:error] [pid 358661:tid 358683] [remote 97.74.93.24:33666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9TDQlWhjQfpOo60_HoJgAAMBI"]
[Tue Jul 21 08:07:57.145924 2026] [security2:error] [pid 352421:tid 352606] [client 202.143.127.214:50585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.127.143.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TDcJSWzG9jbYOtu5YxQAAALw"]
[Tue Jul 21 08:07:57.146027 2026] [security2:error] [pid 352421:tid 352606] [client 202.143.127.214:50585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TDcJSWzG9jbYOtu5YxQAAALw"]
[Tue Jul 21 08:07:57.258240 2026] [security2:error] [pid 352421:tid 352563] [client 34.23.44.61:55934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.raphaelicarolicitacoes.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9TDcJSWzG9jbYOtu5YygAAAJE"]
[Tue Jul 21 08:07:57.291364 2026] [security2:error] [pid 358661:tid 358863] [client 65.21.113.253:57220] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TDAlWhjQfpOo60_HoJAAAAEU"]
[Tue Jul 21 08:07:57.308844 2026] [security2:error] [pid 352421:tid 352562] [client 20.226.60.151:64890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/mds.php"] [unique_id "al9TDcJSWzG9jbYOtu5YywAAAJA"]
[Tue Jul 21 08:07:57.447382 2026] [security2:error] [pid 358661:tid 358822] [client 150.129.202.39:64935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TDQlWhjQfpOo60_HoLQAAABw"]
[Tue Jul 21 08:07:57.447599 2026] [security2:error] [pid 358661:tid 358822] [client 150.129.202.39:64935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TDQlWhjQfpOo60_HoLQAAABw"]
[Tue Jul 21 08:07:57.540525 2026] [security2:error] [pid 352421:tid 352610] [client 20.226.60.151:12130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/177.php"] [unique_id "al9TDcJSWzG9jbYOtu5Y0QAAAMA"]
[Tue Jul 21 08:07:57.668395 2026] [security2:error] [pid 358661:tid 358728] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TDQlWhjQfpOo60_HoLwAAFj8"]
[Tue Jul 21 08:07:57.668464 2026] [core:error] [pid 352421:tid 352663] [client 66.249.66.69:61735] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:07:57.668484 2026] [core:error] [pid 352421:tid 352663] [client 66.249.66.69:61735] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:07:57.668569 2026] [security2:error] [pid 358661:tid 358816] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TDQlWhjQfpOo60_HoLwAAFj8"]
[Tue Jul 21 08:07:57.785003 2026] [security2:error] [pid 352421:tid 352594] [client 193.36.225.68:60363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9TDcJSWzG9jbYOtu5Y0gAAALA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:07:57.789443 2026] [security2:error] [pid 358661:tid 358792] [remote 57.141.18.80:49626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9TDQlWhjQfpOo60_HoMQAAF38"]
[Tue Jul 21 08:07:57.841869 2026] [security2:error] [pid 358661:tid 358823] [client 162.219.176.3:45820] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9TDQlWhjQfpOo60_HoMgAAAB0"]
[Tue Jul 21 08:07:57.842023 2026] [security2:error] [pid 358661:tid 358823] [client 162.219.176.3:45820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9TDQlWhjQfpOo60_HoMgAAAB0"]
[Tue Jul 21 08:07:57.939262 2026] [security2:error] [pid 358661:tid 358878] [client 34.23.44.61:60307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.44.23.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.raphaelicarolicitacoes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TDQlWhjQfpOo60_HoNQAAAFQ"]
[Tue Jul 21 08:07:58.296365 2026] [security2:error] [pid 358661:tid 358874] [client 20.226.60.151:56326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-blink.php"] [unique_id "al9TDglWhjQfpOo60_HoOwAAAFA"]
[Tue Jul 21 08:07:58.388629 2026] [security2:error] [pid 352421:tid 352443] [remote 216.26.248.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.248.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TDsJSWzG9jbYOtu5Y3AAA5xU"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:58.615325 2026] [security2:error] [pid 358661:tid 358912] [client 65.21.113.253:46188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TDglWhjQfpOo60_HoQgAAAHY"]
[Tue Jul 21 08:07:58.705166 2026] [security2:error] [pid 358661:tid 358871] [client 20.104.96.117:62535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9TDglWhjQfpOo60_HoRAAAAE0"]
[Tue Jul 21 08:07:58.833403 2026] [security2:error] [pid 352421:tid 352633] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TDsJSWzG9jbYOtu5Y4QAA1ww"]
[Tue Jul 21 08:07:58.879679 2026] [security2:error] [pid 358661:tid 358756] [remote 77.90.2.3:59114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.2.90.77.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ffstrength.com"] [uri "/wp-login.php"] [unique_id "al9TDglWhjQfpOo60_HoTAAAYls"]
[Tue Jul 21 08:07:58.955097 2026] [security2:error] [pid 358661:tid 358718] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TDglWhjQfpOo60_HoTQAATDU"]
[Tue Jul 21 08:07:58.955297 2026] [security2:error] [pid 358661:tid 358870] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TDglWhjQfpOo60_HoTQAATDU"]
[Tue Jul 21 08:07:59.123032 2026] [security2:error] [pid 352421:tid 352600] [client 62.102.148.158:42774] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9TD8JSWzG9jbYOtu5Y6AAAALY"]
[Tue Jul 21 08:07:59.123427 2026] [security2:error] [pid 352421:tid 352600] [client 62.102.148.158:42774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9TD8JSWzG9jbYOtu5Y6AAAALY"]
[Tue Jul 21 08:07:59.127095 2026] [security2:error] [pid 352421:tid 352584] [client 20.197.192.193:52244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/cron.php"] [unique_id "al9TD8JSWzG9jbYOtu5Y6QAAAKY"]
[Tue Jul 21 08:07:59.295221 2026] [security2:error] [pid 358661:tid 358898] [client 20.226.60.151:12385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/config.php"] [unique_id "al9TDwlWhjQfpOo60_HoUwAAAGg"]
[Tue Jul 21 08:07:59.494870 2026] [security2:error] [pid 358661:tid 358859] [client 65.21.113.253:57238] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TDglWhjQfpOo60_HoUAAAAEE"]
[Tue Jul 21 08:07:59.584082 2026] [security2:error] [pid 352421:tid 352651] [client 178.153.91.96:51442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TD8JSWzG9jbYOtu5Y9wAAAOk"]
[Tue Jul 21 08:07:59.584233 2026] [security2:error] [pid 352421:tid 352651] [client 178.153.91.96:51442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TD8JSWzG9jbYOtu5Y9wAAAOk"]
[Tue Jul 21 08:07:59.635560 2026] [security2:error] [pid 358661:tid 358753] [remote 216.26.224.250:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.224.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TDwlWhjQfpOo60_HoWAAAJlg"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:07:59.720254 2026] [security2:error] [pid 352421:tid 352643] [client 65.21.113.253:57250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TD8JSWzG9jbYOtu5Y6wAAAOE"]
[Tue Jul 21 08:07:59.896492 2026] [security2:error] [pid 358661:tid 358790] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9TDwlWhjQfpOo60_HoXQAAJ30"]
[Tue Jul 21 08:07:59.928576 2026] [security2:error] [pid 358661:tid 358910] [client 20.226.60.151:65081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/zc-208.php"] [unique_id "al9TDwlWhjQfpOo60_HoXgAAAHQ"]
[Tue Jul 21 08:07:59.935324 2026] [security2:error] [pid 352421:tid 352626] [client 103.78.200.11:52321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TD8JSWzG9jbYOtu5Y_AAAANA"]
[Tue Jul 21 08:07:59.935498 2026] [security2:error] [pid 352421:tid 352626] [client 103.78.200.11:52321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TD8JSWzG9jbYOtu5Y_AAAANA"]
[Tue Jul 21 08:07:59.938771 2026] [security2:error] [pid 358661:tid 358702] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9TDwlWhjQfpOo60_HoXwAAZSU"]
[Tue Jul 21 08:07:59.967679 2026] [security2:error] [pid 358661:tid 358679] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/dp.php"] [unique_id "al9TDwlWhjQfpOo60_HoYgAADw4"]
[Tue Jul 21 08:07:59.987170 2026] [security2:error] [pid 358661:tid 358669] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/old.php"] [unique_id "al9TDwlWhjQfpOo60_HoYwAABgQ"]
[Tue Jul 21 08:08:00.005851 2026] [security2:error] [pid 358661:tid 358742] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/ms-new.php"] [unique_id "al9TEAlWhjQfpOo60_HoZAAAa00"]
[Tue Jul 21 08:08:00.031798 2026] [security2:error] [pid 358661:tid 358717] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/track.php"] [unique_id "al9TEAlWhjQfpOo60_HoZQAAWDQ"]
[Tue Jul 21 08:08:00.050007 2026] [security2:error] [pid 358661:tid 358677] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/2352356666.php"] [unique_id "al9TEAlWhjQfpOo60_HoZgAADAw"]
[Tue Jul 21 08:08:00.069478 2026] [security2:error] [pid 358661:tid 358665] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/pn.php"] [unique_id "al9TEAlWhjQfpOo60_HoaQAANQA"]
[Tue Jul 21 08:08:00.076192 2026] [security2:error] [pid 352421:tid 352609] [client 205.185.113.241:49674] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "arthromdcanada.online"] [uri "/"] [unique_id "al9TEMJSWzG9jbYOtu5ZAAAAAL8"]
[Tue Jul 21 08:08:00.098084 2026] [security2:error] [pid 358661:tid 358771] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wp-wpbak.php"] [unique_id "al9TEAlWhjQfpOo60_HoagAAOWo"]
[Tue Jul 21 08:08:00.099061 2026] [security2:error] [pid 358661:tid 358889] [client 34.23.44.61:52905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.44.23.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.raphaelicarolicitacoes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TEAlWhjQfpOo60_HoawAAAF8"]
[Tue Jul 21 08:08:00.099171 2026] [security2:error] [pid 358661:tid 358889] [client 34.23.44.61:52905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.raphaelicarolicitacoes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TEAlWhjQfpOo60_HoawAAAF8"]
[Tue Jul 21 08:08:00.130652 2026] [security2:error] [pid 352421:tid 352672] [client 103.29.114.44:46640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TEMJSWzG9jbYOtu5ZAgAAAP4"]
[Tue Jul 21 08:08:00.130773 2026] [security2:error] [pid 352421:tid 352672] [client 103.29.114.44:46640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TEMJSWzG9jbYOtu5ZAgAAAP4"]
[Tue Jul 21 08:08:00.200299 2026] [security2:error] [pid 358661:tid 358748] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/dr.php"] [unique_id "al9TEAlWhjQfpOo60_HobQAASlM"]
[Tue Jul 21 08:08:00.203504 2026] [security2:error] [pid 352421:tid 352516] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TEMJSWzG9jbYOtu5ZAwAA314"]
[Tue Jul 21 08:08:00.203654 2026] [security2:error] [pid 352421:tid 352641] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TEMJSWzG9jbYOtu5ZAwAA314"]
[Tue Jul 21 08:08:00.234501 2026] [security2:error] [pid 358661:tid 358755] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/2x.php"] [unique_id "al9TEAlWhjQfpOo60_HobgAAUFo"]
[Tue Jul 21 08:08:00.239782 2026] [security2:error] [pid 358661:tid 358826] [client 205.185.113.241:49684] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "arthromdcanada.online.oficialwebsite.com.br"] [uri "/"] [unique_id "al9TEAlWhjQfpOo60_HobwAAACA"]
[Tue Jul 21 08:08:00.261199 2026] [security2:error] [pid 358661:tid 358741] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/kq1.php"] [unique_id "al9TEAlWhjQfpOo60_HocAAAE0w"]
[Tue Jul 21 08:08:00.291052 2026] [security2:error] [pid 358661:tid 358676] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/zzz.php"] [unique_id "al9TEAlWhjQfpOo60_HocQAATgs"]
[Tue Jul 21 08:08:00.325149 2026] [security2:error] [pid 358661:tid 358768] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wicked.php"] [unique_id "al9TEAlWhjQfpOo60_HocgAAQ2c"]
[Tue Jul 21 08:08:00.353470 2026] [security2:error] [pid 358661:tid 358670] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/edit.php"] [unique_id "al9TEAlWhjQfpOo60_HocwAAegU"]
[Tue Jul 21 08:08:00.380284 2026] [security2:error] [pid 358661:tid 358759] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/kua.php"] [unique_id "al9TEAlWhjQfpOo60_HodAAAbV4"]
[Tue Jul 21 08:08:00.402257 2026] [security2:error] [pid 358661:tid 358720] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/ez.php"] [unique_id "al9TEAlWhjQfpOo60_HodQAALDc"]
[Tue Jul 21 08:08:00.423246 2026] [security2:error] [pid 358661:tid 358733] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/fz.php"] [unique_id "al9TEAlWhjQfpOo60_HoeAAABEQ"]
[Tue Jul 21 08:08:00.440238 2026] [security2:error] [pid 358661:tid 358763] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/la.php"] [unique_id "al9TEAlWhjQfpOo60_HoeQAAKmI"]
[Tue Jul 21 08:08:00.457910 2026] [security2:error] [pid 358661:tid 358685] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/nhvoanpl.php"] [unique_id "al9TEAlWhjQfpOo60_HoegAAQhQ"]
[Tue Jul 21 08:08:00.481773 2026] [security2:error] [pid 358661:tid 358766] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/inso.php"] [unique_id "al9TEAlWhjQfpOo60_HoewAAA2U"]
[Tue Jul 21 08:08:00.509489 2026] [security2:error] [pid 358661:tid 358700] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wpx.php"] [unique_id "al9TEAlWhjQfpOo60_HofAAAfCM"]
[Tue Jul 21 08:08:00.535736 2026] [security2:error] [pid 358661:tid 358779] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/berlin.php"] [unique_id "al9TEAlWhjQfpOo60_HofQAAfXI"]
[Tue Jul 21 08:08:00.555648 2026] [security2:error] [pid 358661:tid 358726] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/billur.php"] [unique_id "al9TEAlWhjQfpOo60_HofwAAHz0"]
[Tue Jul 21 08:08:00.577976 2026] [security2:error] [pid 358661:tid 358695] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/mimpi.php"] [unique_id "al9TEAlWhjQfpOo60_HogAAABx4"]
[Tue Jul 21 08:08:00.603136 2026] [security2:error] [pid 358661:tid 358727] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/dp.php"] [unique_id "al9TEAlWhjQfpOo60_HogQAAJD4"]
[Tue Jul 21 08:08:00.621866 2026] [security2:error] [pid 358661:tid 358697] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/bootstrap.php"] [unique_id "al9TEAlWhjQfpOo60_HogwAAISA"]
[Tue Jul 21 08:08:00.645189 2026] [security2:error] [pid 358661:tid 358722] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wp-editor.php"] [unique_id "al9TEAlWhjQfpOo60_HohAAAVzk"]
[Tue Jul 21 08:08:00.662790 2026] [security2:error] [pid 358661:tid 358743] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/cro.php"] [unique_id "al9TEAlWhjQfpOo60_HohQAAYk4"]
[Tue Jul 21 08:08:00.668874 2026] [security2:error] [pid 358661:tid 358902] [client 117.210.135.0:60409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TEAlWhjQfpOo60_HohgAAAGw"]
[Tue Jul 21 08:08:00.668984 2026] [security2:error] [pid 358661:tid 358902] [client 117.210.135.0:60409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TEAlWhjQfpOo60_HohgAAAGw"]
[Tue Jul 21 08:08:00.674379 2026] [access_compat:error] [pid 358661:tid 358876] [client 162.241.63.68:30726] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:08:00.682456 2026] [security2:error] [pid 358661:tid 358761] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/cron-tab.php"] [unique_id "al9TEAlWhjQfpOo60_HoiAAAP2A"]
[Tue Jul 21 08:08:00.716001 2026] [security2:error] [pid 358661:tid 358747] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/koiy.php"] [unique_id "al9TEAlWhjQfpOo60_HoiQAAElI"]
[Tue Jul 21 08:08:00.717460 2026] [security2:error] [pid 352421:tid 352583] [client 87.116.180.198:27278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TEMJSWzG9jbYOtu5ZCgAAAKU"]
[Tue Jul 21 08:08:00.717559 2026] [security2:error] [pid 352421:tid 352583] [client 87.116.180.198:27278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TEMJSWzG9jbYOtu5ZCgAAAKU"]
[Tue Jul 21 08:08:00.753764 2026] [security2:error] [pid 358661:tid 358736] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/hp2.php"] [unique_id "al9TEAlWhjQfpOo60_HoiwAARkc"]
[Tue Jul 21 08:08:00.791979 2026] [security2:error] [pid 358661:tid 358682] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/hp3.php"] [unique_id "al9TEAlWhjQfpOo60_HojAAAeRE"]
[Tue Jul 21 08:08:00.812469 2026] [security2:error] [pid 358661:tid 358764] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/aa1.php"] [unique_id "al9TEAlWhjQfpOo60_HojQAADWM"]
[Tue Jul 21 08:08:00.836532 2026] [security2:error] [pid 358661:tid 358684] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/acew67.php"] [unique_id "al9TEAlWhjQfpOo60_HojgAAcRM"]
[Tue Jul 21 08:08:00.875853 2026] [security2:error] [pid 358661:tid 358704] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/bscclapb.php"] [unique_id "al9TEAlWhjQfpOo60_HojwAARCc"]
[Tue Jul 21 08:08:00.905975 2026] [security2:error] [pid 358661:tid 358690] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/else1.php"] [unique_id "al9TEAlWhjQfpOo60_HokAAABRk"]
[Tue Jul 21 08:08:00.922994 2026] [security2:error] [pid 358661:tid 358709] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/tkikikoko.php"] [unique_id "al9TEAlWhjQfpOo60_HokQAAYCw"]
[Tue Jul 21 08:08:00.941692 2026] [security2:error] [pid 358661:tid 358705] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wp-Blogs.php"] [unique_id "al9TEAlWhjQfpOo60_HokwAATyg"]
[Tue Jul 21 08:08:00.969961 2026] [security2:error] [pid 358661:tid 358751] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wp-css.php"] [unique_id "al9TEAlWhjQfpOo60_HolAAAKFY"]
[Tue Jul 21 08:08:00.995221 2026] [security2:error] [pid 358661:tid 358739] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/wp-explorer.php"] [unique_id "al9TEAlWhjQfpOo60_HolQAAaEo"]
[Tue Jul 21 08:08:01.052175 2026] [security2:error] [pid 358661:tid 358749] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/akismet.php"] [unique_id "al9TEQlWhjQfpOo60_HomAAALVQ"]
[Tue Jul 21 08:08:01.063085 2026] [security2:error] [pid 358661:tid 358869] [client 20.226.60.151:12006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/gettest.php"] [unique_id "al9TEQlWhjQfpOo60_HomQAAAEs"]
[Tue Jul 21 08:08:01.083170 2026] [security2:error] [pid 358661:tid 358692] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/ace2.php"] [unique_id "al9TEQlWhjQfpOo60_HomwAAUxs"]
[Tue Jul 21 08:08:01.119019 2026] [security2:error] [pid 358661:tid 358773] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.online"] [uri "/ms.php"] [unique_id "al9TEQlWhjQfpOo60_HonAAAd2w"]
[Tue Jul 21 08:08:01.222500 2026] [security2:error] [pid 358661:tid 358832] [client 20.29.126.15:2052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/alfa.php"] [unique_id "al9TEQlWhjQfpOo60_HonwAAACY"]
[Tue Jul 21 08:08:01.307441 2026] [security2:error] [pid 358661:tid 358719] [remote 216.26.252.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.252.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TEQlWhjQfpOo60_HonQAAQTY"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:01.641996 2026] [security2:error] [pid 358661:tid 358795] [client 20.104.96.117:62465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/xyn.php"] [unique_id "al9TEQlWhjQfpOo60_HoqAAAAAE"]
[Tue Jul 21 08:08:01.697038 2026] [security2:error] [pid 358661:tid 358842] [client 117.247.80.59:15813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TEQlWhjQfpOo60_HoqwAAADA"]
[Tue Jul 21 08:08:01.697160 2026] [security2:error] [pid 358661:tid 358842] [client 117.247.80.59:15813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TEQlWhjQfpOo60_HoqwAAADA"]
[Tue Jul 21 08:08:01.851931 2026] [security2:error] [pid 352421:tid 352628] [client 136.144.33.53:64891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9TEcJSWzG9jbYOtu5ZHQAAANI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:08:01.918527 2026] [security2:error] [pid 358661:tid 358868] [client 20.226.60.151:65072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/sid4.php"] [unique_id "al9TEQlWhjQfpOo60_HosQAAAEo"]
[Tue Jul 21 08:08:02.071048 2026] [security2:error] [pid 352421:tid 352677] [client 20.226.60.151:12004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/min.php"] [unique_id "al9TEsJSWzG9jbYOtu5ZIQAAAQM"]
[Tue Jul 21 08:08:02.576462 2026] [security2:error] [pid 358661:tid 358830] [client 20.226.60.151:12142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/dvjul.php"] [unique_id "al9TEglWhjQfpOo60_HovAAAACQ"]
[Tue Jul 21 08:08:02.600866 2026] [security2:error] [pid 352421:tid 352513] [remote 57.141.18.12:50802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9TEsJSWzG9jbYOtu5ZKQAA01s"]
[Tue Jul 21 08:08:02.625677 2026] [security2:error] [pid 352421:tid 352645] [client 20.197.192.193:52231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/xxx.php"] [unique_id "al9TEsJSWzG9jbYOtu5ZKwAAAOM"]
[Tue Jul 21 08:08:02.712734 2026] [autoindex:error] [pid 358661:tid 358799] [client 205.210.31.180:59050] AH01276: Cannot serve directory /home2/tiago878/public_html/hostserv/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:08:02.805325 2026] [security2:error] [pid 358661:tid 358856] [client 38.100.221.102:17892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TEglWhjQfpOo60_HoyAAAAD4"]
[Tue Jul 21 08:08:02.805480 2026] [security2:error] [pid 358661:tid 358856] [client 38.100.221.102:17892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TEglWhjQfpOo60_HoyAAAAD4"]
[Tue Jul 21 08:08:02.852637 2026] [security2:error] [pid 352421:tid 352548] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TEsJSWzG9jbYOtu5ZLwAApn4"]
[Tue Jul 21 08:08:02.852804 2026] [security2:error] [pid 352421:tid 352584] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TEsJSWzG9jbYOtu5ZLwAApn4"]
[Tue Jul 21 08:08:02.932601 2026] [security2:error] [pid 358661:tid 358893] [client 20.226.60.151:12154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/biufile.php"] [unique_id "al9TEglWhjQfpOo60_HoywAAAGM"]
[Tue Jul 21 08:08:02.998041 2026] [security2:error] [pid 352421:tid 352644] [client 20.226.60.151:64892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wmore1.php"] [unique_id "al9TEsJSWzG9jbYOtu5ZMgAAAOI"]
[Tue Jul 21 08:08:03.098270 2026] [security2:error] [pid 358661:tid 358858] [client 65.21.113.253:46188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TEwlWhjQfpOo60_Ho0wAAAEA"]
[Tue Jul 21 08:08:03.103031 2026] [security2:error] [pid 358661:tid 358900] [client 162.219.176.3:47106] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9TEwlWhjQfpOo60_Ho1AAAAGo"]
[Tue Jul 21 08:08:03.103165 2026] [security2:error] [pid 358661:tid 358900] [client 162.219.176.3:47106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9TEwlWhjQfpOo60_Ho1AAAAGo"]
[Tue Jul 21 08:08:03.146188 2026] [security2:error] [pid 358661:tid 358821] [client 20.104.96.117:62519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/patie.php"] [unique_id "al9TEwlWhjQfpOo60_Ho1gAAABs"]
[Tue Jul 21 08:08:03.287321 2026] [security2:error] [pid 358661:tid 358875] [client 47.128.35.3:52254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "olimposolar.com.br"] [uri "/robots.txt"] [unique_id "al9TEwlWhjQfpOo60_Ho2wAAAFE"]
[Tue Jul 21 08:08:03.333340 2026] [security2:error] [pid 358661:tid 358795] [client 20.226.60.151:56370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/solo1.php"] [unique_id "al9TEwlWhjQfpOo60_Ho3gAAAAE"]
[Tue Jul 21 08:08:03.465941 2026] [security2:error] [pid 352421:tid 352659] [client 175.144.82.48:58333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TE8JSWzG9jbYOtu5ZOAAAAPE"]
[Tue Jul 21 08:08:03.466596 2026] [security2:error] [pid 352421:tid 352659] [client 175.144.82.48:58333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TE8JSWzG9jbYOtu5ZOAAAAPE"]
[Tue Jul 21 08:08:03.662588 2026] [security2:error] [pid 352421:tid 352604] [client 20.226.60.151:12401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/av.php"] [unique_id "al9TE8JSWzG9jbYOtu5ZQAAAALo"]
[Tue Jul 21 08:08:03.715203 2026] [security2:error] [pid 358661:tid 358831] [client 65.21.113.253:57238] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TEwlWhjQfpOo60_Ho3QAAACU"]
[Tue Jul 21 08:08:03.782452 2026] [security2:error] [pid 352421:tid 352552] [client 20.226.60.151:65063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/cong.php"] [unique_id "al9TE8JSWzG9jbYOtu5ZRQAAAIY"]
[Tue Jul 21 08:08:03.852316 2026] [security2:error] [pid 358661:tid 358899] [client 20.197.192.193:53170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/hunter.php"] [unique_id "al9TEwlWhjQfpOo60_Ho6QAAAGk"]
[Tue Jul 21 08:08:03.988220 2026] [security2:error] [pid 352421:tid 352664] [client 136.108.31.74:56050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "geracaosemtelinha.com.br.kslifepro.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9TE8JSWzG9jbYOtu5ZSAAAAPY"]
[Tue Jul 21 08:08:04.059192 2026] [proxy:error] [pid 352421:tid 352657] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:08:04.059273 2026] [proxy_http:error] [pid 352421:tid 352657] [client 143.244.57.90:53578] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:08:04.060031 2026] [proxy:error] [pid 352421:tid 352657] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:08:04.060065 2026] [proxy_http:error] [pid 352421:tid 352657] [client 143.244.57.90:53578] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:08:04.182700 2026] [security2:error] [pid 358661:tid 358687] [remote 57.141.18.21:59524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9TFAlWhjQfpOo60_Ho7AAABxY"]
[Tue Jul 21 08:08:04.237924 2026] [security2:error] [pid 358661:tid 358864] [client 20.226.60.151:12153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/coffexium.php"] [unique_id "al9TFAlWhjQfpOo60_Ho7wAAAEY"]
[Tue Jul 21 08:08:04.288403 2026] [security2:error] [pid 352421:tid 352585] [client 65.21.113.253:60604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TE8JSWzG9jbYOtu5ZRwAAAKc"]
[Tue Jul 21 08:08:04.358230 2026] [security2:error] [pid 352421:tid 352572] [client 41.68.90.219:59125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TFMJSWzG9jbYOtu5ZUAAAAJo"]
[Tue Jul 21 08:08:04.359294 2026] [security2:error] [pid 352421:tid 352572] [client 41.68.90.219:59125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TFMJSWzG9jbYOtu5ZUAAAAJo"]
[Tue Jul 21 08:08:04.475376 2026] [proxy:error] [pid 352421:tid 352612] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:08:04.475458 2026] [proxy_http:error] [pid 352421:tid 352612] [client 143.244.57.90:42834] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:08:04.475899 2026] [proxy:error] [pid 352421:tid 352612] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:08:04.475922 2026] [proxy_http:error] [pid 352421:tid 352612] [client 143.244.57.90:42834] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:08:04.514389 2026] [security2:error] [pid 352421:tid 352637] [client 20.226.60.151:56425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/public/css.php"] [unique_id "al9TFMJSWzG9jbYOtu5ZVAAAANs"]
[Tue Jul 21 08:08:04.534127 2026] [security2:error] [pid 358661:tid 358672] [remote 45.3.49.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.49.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TEglWhjQfpOo60_HougAAfAc"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:04.817561 2026] [security2:error] [pid 358661:tid 358740] [remote 57.141.18.20:45908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9TEglWhjQfpOo60_HoyQAAOks"]
[Tue Jul 21 08:08:04.889850 2026] [security2:error] [pid 358661:tid 358878] [client 143.244.57.90:42840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9TFAlWhjQfpOo60_Ho_gAAAFQ"]
[Tue Jul 21 08:08:04.899371 2026] [security2:error] [pid 358661:tid 358816] [client 20.226.60.151:12121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/core.php"] [unique_id "al9TFAlWhjQfpOo60_Ho_wAAABY"]
[Tue Jul 21 08:08:04.903858 2026] [security2:error] [pid 358661:tid 358840] [client 20.226.60.151:56432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/output.php"] [unique_id "al9TFAlWhjQfpOo60_HpAAAAAC4"]
[Tue Jul 21 08:08:05.270226 2026] [security2:error] [pid 358661:tid 358880] [client 20.226.60.151:56405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-file-120.php"] [unique_id "al9TFQlWhjQfpOo60_HpCAAAAFY"]
[Tue Jul 21 08:08:05.298766 2026] [proxy:error] [pid 358661:tid 358868] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:08:05.298856 2026] [proxy_http:error] [pid 358661:tid 358868] [client 143.244.57.90:42848] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:08:05.299433 2026] [proxy:error] [pid 358661:tid 358868] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:08:05.299461 2026] [proxy_http:error] [pid 358661:tid 358868] [client 143.244.57.90:42848] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:08:05.433771 2026] [security2:error] [pid 358661:tid 358820] [client 136.108.31.74:56360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.31.108.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "geracaosemtelinha.com.br.kslifepro.com"] [uri "/xmlrpc.php"] [unique_id "al9TFAlWhjQfpOo60_Ho8wAAABo"]
[Tue Jul 21 08:08:05.539425 2026] [security2:error] [pid 358661:tid 358708] [remote 45.3.52.56:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TFQlWhjQfpOo60_HpDwAAeis"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:05.559807 2026] [security2:error] [pid 358661:tid 358837] [client 61.1.167.83:55789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TFQlWhjQfpOo60_HpEAAAACs"]
[Tue Jul 21 08:08:05.559956 2026] [security2:error] [pid 358661:tid 358837] [client 61.1.167.83:55789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TFQlWhjQfpOo60_HpEAAAACs"]
[Tue Jul 21 08:08:05.721846 2026] [security2:error] [pid 358661:tid 358883] [client 143.244.57.90:42862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9TFQlWhjQfpOo60_HpFgAAAFk"]
[Tue Jul 21 08:08:05.872880 2026] [security2:error] [pid 358661:tid 358830] [client 20.226.60.151:56369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/special.php"] [unique_id "al9TFQlWhjQfpOo60_HpGwAAACQ"]
[Tue Jul 21 08:08:05.883509 2026] [security2:error] [pid 352421:tid 352661] [client 20.226.60.151:12367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/als.php"] [unique_id "al9TFcJSWzG9jbYOtu5ZawAAAPM"]
[Tue Jul 21 08:08:06.013553 2026] [security2:error] [pid 352421:tid 352432] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TFsJSWzG9jbYOtu5ZbwAAzQo"]
[Tue Jul 21 08:08:06.013677 2026] [security2:error] [pid 352421:tid 352623] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TFsJSWzG9jbYOtu5ZbwAAzQo"]
[Tue Jul 21 08:08:06.132737 2026] [security2:error] [pid 358661:tid 358812] [client 143.244.57.90:42878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9TFglWhjQfpOo60_HpIAAAABI"]
[Tue Jul 21 08:08:06.288685 2026] [security2:error] [pid 358661:tid 358814] [client 20.226.60.151:65058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/as.php"] [unique_id "al9TFglWhjQfpOo60_HpJQAAABQ"]
[Tue Jul 21 08:08:06.356510 2026] [security2:error] [pid 352421:tid 352500] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TFsJSWzG9jbYOtu5ZegAAvk4"]
[Tue Jul 21 08:08:06.356689 2026] [security2:error] [pid 352421:tid 352608] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TFsJSWzG9jbYOtu5ZegAAvk4"]
[Tue Jul 21 08:08:06.371053 2026] [security2:error] [pid 352421:tid 352571] [client 103.166.103.129:52594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TFsJSWzG9jbYOtu5ZfQAAAJk"]
[Tue Jul 21 08:08:06.374015 2026] [security2:error] [pid 352421:tid 352571] [client 103.166.103.129:52594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TFsJSWzG9jbYOtu5ZfQAAAJk"]
[Tue Jul 21 08:08:06.452662 2026] [security2:error] [pid 352421:tid 352564] [client 109.60.28.94:54204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TFsJSWzG9jbYOtu5ZgAAAAJI"]
[Tue Jul 21 08:08:06.452873 2026] [security2:error] [pid 352421:tid 352564] [client 109.60.28.94:54204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TFsJSWzG9jbYOtu5ZgAAAAJI"]
[Tue Jul 21 08:08:06.509715 2026] [security2:error] [pid 358661:tid 358865] [client 62.102.148.158:42788] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9TFglWhjQfpOo60_HpKAAAAEc"]
[Tue Jul 21 08:08:06.509839 2026] [security2:error] [pid 358661:tid 358865] [client 62.102.148.158:42788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9TFglWhjQfpOo60_HpKAAAAEc"]
[Tue Jul 21 08:08:06.554999 2026] [security2:error] [pid 358661:tid 358822] [client 143.244.57.90:42890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9TFglWhjQfpOo60_HpKwAAABw"]
[Tue Jul 21 08:08:06.661680 2026] [security2:error] [pid 358661:tid 358821] [client 31.57.219.92:24248] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "newpostapp.com"] [uri "/"] [unique_id "al9TFglWhjQfpOo60_HpLgAAABs"]
[Tue Jul 21 08:08:06.740008 2026] [security2:error] [pid 358661:tid 358680] [remote 65.111.3.196:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.3.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TFglWhjQfpOo60_HpLAAAdQ8"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:06.813454 2026] [security2:error] [pid 352421:tid 352625] [client 20.226.60.151:12007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/simple.php"] [unique_id "al9TFsJSWzG9jbYOtu5ZiwAAAM8"]
[Tue Jul 21 08:08:06.881800 2026] [security2:error] [pid 358661:tid 358835] [client 193.36.225.54:55763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9TFglWhjQfpOo60_HpKgAAACk"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:08:06.899372 2026] [security2:error] [pid 352421:tid 352438] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TFsJSWzG9jbYOtu5ZkgAAkRA"]
[Tue Jul 21 08:08:06.899558 2026] [security2:error] [pid 352421:tid 352563] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TFsJSWzG9jbYOtu5ZkgAAkRA"]
[Tue Jul 21 08:08:06.967325 2026] [security2:error] [pid 358661:tid 358809] [client 143.244.57.90:42896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9TFglWhjQfpOo60_HpMgAAAA8"]
[Tue Jul 21 08:08:07.018208 2026] [security2:error] [pid 358661:tid 358882] [client 20.226.60.151:65081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/cgi-bin/index.php"] [unique_id "al9TFwlWhjQfpOo60_HpMwAAAFg"]
[Tue Jul 21 08:08:07.053232 2026] [security2:error] [pid 358661:tid 358900] [client 120.56.162.40:59719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TFwlWhjQfpOo60_HpNAAAAGo"]
[Tue Jul 21 08:08:07.053358 2026] [security2:error] [pid 358661:tid 358900] [client 120.56.162.40:59719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TFwlWhjQfpOo60_HpNAAAAGo"]
[Tue Jul 21 08:08:07.245011 2026] [security2:error] [pid 352421:tid 352585] [client 20.29.126.15:2332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9TF8JSWzG9jbYOtu5ZlQAAAKc"]
[Tue Jul 21 08:08:07.358209 2026] [security2:error] [pid 352421:tid 352579] [client 102.206.115.33:62445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TF8JSWzG9jbYOtu5ZmgAAAKE"]
[Tue Jul 21 08:08:07.358331 2026] [security2:error] [pid 352421:tid 352579] [client 102.206.115.33:62445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TF8JSWzG9jbYOtu5ZmgAAAKE"]
[Tue Jul 21 08:08:07.390189 2026] [security2:error] [pid 358661:tid 358880] [client 143.244.57.90:42908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9TFwlWhjQfpOo60_HpNgAAAFY"]
[Tue Jul 21 08:08:07.578192 2026] [security2:error] [pid 358661:tid 358884] [client 20.104.96.117:62563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/aa.php"] [unique_id "al9TFwlWhjQfpOo60_HpOwAAAFo"]
[Tue Jul 21 08:08:07.729137 2026] [autoindex:error] [pid 358661:tid 358912] [client 103.215.74.26:33006] AH01276: Cannot serve directory /home1/monte290/atendimento.monteirosantosesilva.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:08:07.810715 2026] [security2:error] [pid 358661:tid 358826] [client 143.244.57.90:42922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9TFwlWhjQfpOo60_HpPwAAACA"]
[Tue Jul 21 08:08:07.874401 2026] [security2:error] [pid 358661:tid 358786] [remote 20.75.217.64:10558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9TFwlWhjQfpOo60_HpQAAAFXk"]
[Tue Jul 21 08:08:07.880007 2026] [security2:error] [pid 352421:tid 352573] [client 136.108.31.74:56956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.31.108.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "geracaosemtelinha.com.br.kslifepro.com"] [uri "/xmlrpc.php"] [unique_id "al9TF8JSWzG9jbYOtu5ZpAAAAJs"]
[Tue Jul 21 08:08:07.880113 2026] [security2:error] [pid 352421:tid 352573] [client 136.108.31.74:56956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "geracaosemtelinha.com.br.kslifepro.com"] [uri "/xmlrpc.php"] [unique_id "al9TF8JSWzG9jbYOtu5ZpAAAAJs"]
[Tue Jul 21 08:08:07.937032 2026] [security2:error] [pid 358661:tid 358908] [client 150.129.202.39:65133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TFwlWhjQfpOo60_HpQQAAAHI"]
[Tue Jul 21 08:08:07.937147 2026] [security2:error] [pid 358661:tid 358908] [client 150.129.202.39:65133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TFwlWhjQfpOo60_HpQQAAAHI"]
[Tue Jul 21 08:08:08.119915 2026] [security2:error] [pid 352421:tid 352580] [client 20.226.60.151:12389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/init.php"] [unique_id "al9TGMJSWzG9jbYOtu5ZqgAAAKI"]
[Tue Jul 21 08:08:08.225847 2026] [security2:error] [pid 358661:tid 358825] [client 143.244.57.90:42936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9TGAlWhjQfpOo60_HpRAAAAB8"]
[Tue Jul 21 08:08:08.256129 2026] [security2:error] [pid 352421:tid 352436] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TGMJSWzG9jbYOtu5ZqwABBA4"]
[Tue Jul 21 08:08:08.256267 2026] [security2:error] [pid 352421:tid 352678] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TGMJSWzG9jbYOtu5ZqwABBA4"]
[Tue Jul 21 08:08:08.275628 2026] [security2:error] [pid 352421:tid 352567] [client 20.226.60.151:12001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/fpwch.php"] [unique_id "al9TGMJSWzG9jbYOtu5ZrQAAAJU"]
[Tue Jul 21 08:08:08.435852 2026] [security2:error] [pid 352421:tid 352477] [remote 216.26.248.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.248.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TGMJSWzG9jbYOtu5ZrAAA5zc"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:08.558895 2026] [security2:error] [pid 358661:tid 358856] [client 65.21.113.253:59154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TGAlWhjQfpOo60_HpSgAAAD4"]
[Tue Jul 21 08:08:08.633516 2026] [security2:error] [pid 358661:tid 358914] [client 143.244.57.90:42942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9TGAlWhjQfpOo60_HpSwAAAHg"]
[Tue Jul 21 08:08:08.649921 2026] [security2:error] [pid 352421:tid 352559] [client 20.226.60.151:12161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/domvf.php"] [unique_id "al9TGMJSWzG9jbYOtu5ZswAAAI0"]
[Tue Jul 21 08:08:08.907953 2026] [security2:error] [pid 352421:tid 352638] [client 65.21.113.253:60604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TGMJSWzG9jbYOtu5ZsQAAANw"]
[Tue Jul 21 08:08:09.047692 2026] [security2:error] [pid 358661:tid 358891] [client 143.244.57.90:42956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9TGQlWhjQfpOo60_HpTgAAAGE"]
[Tue Jul 21 08:08:09.097538 2026] [security2:error] [pid 358661:tid 358844] [client 20.29.126.15:8381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/av.php"] [unique_id "al9TGQlWhjQfpOo60_HpUAAAADI"]
[Tue Jul 21 08:08:09.233285 2026] [security2:error] [pid 352421:tid 352632] [client 20.226.60.151:11993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/wp.php"] [unique_id "al9TGcJSWzG9jbYOtu5ZuwAAANY"]
[Tue Jul 21 08:08:09.432155 2026] [security2:error] [pid 352421:tid 352423] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TGcJSWzG9jbYOtu5ZwAAAwwE"]
[Tue Jul 21 08:08:09.432314 2026] [security2:error] [pid 352421:tid 352613] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TGcJSWzG9jbYOtu5ZwAAAwwE"]
[Tue Jul 21 08:08:09.438141 2026] [security2:error] [pid 358661:tid 358906] [client 20.226.60.151:64845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/w1px.php"] [unique_id "al9TGQlWhjQfpOo60_HpVAAAAHA"]
[Tue Jul 21 08:08:09.472805 2026] [security2:error] [pid 352421:tid 352675] [client 143.244.57.90:42964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9TGcJSWzG9jbYOtu5ZwgAAAQE"]
[Tue Jul 21 08:08:09.517123 2026] [security2:error] [pid 358661:tid 358869] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TGQlWhjQfpOo60_HpUwAAS0E"]
[Tue Jul 21 08:08:09.663938 2026] [security2:error] [pid 358661:tid 358898] [client 65.21.113.253:60612] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TGQlWhjQfpOo60_HpUQAAAGg"]
[Tue Jul 21 08:08:09.787995 2026] [security2:error] [pid 352421:tid 352614] [client 74.7.175.176:54518] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.jornalbrasileiro.com.br"] [uri "/index.php"] [unique_id "al9TGcJSWzG9jbYOtu5ZxgAAxAk"]
[Tue Jul 21 08:08:09.891294 2026] [security2:error] [pid 352421:tid 352641] [client 143.244.57.90:42974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9TGcJSWzG9jbYOtu5ZxwAAAN8"]
[Tue Jul 21 08:08:09.918435 2026] [security2:error] [pid 358661:tid 358694] [remote 97.74.93.24:60902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9TGQlWhjQfpOo60_HpWQAAMR0"]
[Tue Jul 21 08:08:09.976381 2026] [security2:error] [pid 358661:tid 358714] [remote 216.26.245.130:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.245.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TGQlWhjQfpOo60_HpXQAAWDE"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:10.047102 2026] [security2:error] [pid 358661:tid 358900] [client 20.226.60.151:12108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/class.php"] [unique_id "al9TGglWhjQfpOo60_HpXgAAAGo"]
[Tue Jul 21 08:08:10.088664 2026] [security2:error] [pid 358661:tid 358865] [client 178.153.91.96:49929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TGglWhjQfpOo60_HpYAAAAEc"]
[Tue Jul 21 08:08:10.088828 2026] [security2:error] [pid 358661:tid 358865] [client 178.153.91.96:49929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TGglWhjQfpOo60_HpYAAAAEc"]
[Tue Jul 21 08:08:10.192726 2026] [security2:error] [pid 358661:tid 358806] [client 74.7.175.176:54534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jornalbrasileiro.com.br"] [uri "/index.php"] [unique_id "al9TGglWhjQfpOo60_HpYQAADAE"], referer: https://www.jornalbrasileiro.com.br/robots.txt
[Tue Jul 21 08:08:10.297862 2026] [security2:error] [pid 352421:tid 352575] [client 103.78.200.11:52798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TGsJSWzG9jbYOtu5ZzwAAAJ0"]
[Tue Jul 21 08:08:10.300237 2026] [security2:error] [pid 352421:tid 352575] [client 103.78.200.11:52798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TGsJSWzG9jbYOtu5ZzwAAAJ0"]
[Tue Jul 21 08:08:10.300378 2026] [security2:error] [pid 358661:tid 358907] [client 143.244.57.90:36397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9TGglWhjQfpOo60_HpYgAAAHE"]
[Tue Jul 21 08:08:10.372932 2026] [security2:error] [pid 358661:tid 358868] [client 20.226.60.151:64861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/yawa.php"] [unique_id "al9TGglWhjQfpOo60_HpZAAAAEo"]
[Tue Jul 21 08:08:10.565746 2026] [security2:error] [pid 358661:tid 358912] [client 162.219.176.3:44630] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9TGglWhjQfpOo60_HpagAAAHY"]
[Tue Jul 21 08:08:10.565830 2026] [security2:error] [pid 358661:tid 358912] [client 162.219.176.3:44630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9TGglWhjQfpOo60_HpagAAAHY"]
[Tue Jul 21 08:08:10.673647 2026] [security2:error] [pid 358661:tid 358668] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TGglWhjQfpOo60_HpawAAHQM"]
[Tue Jul 21 08:08:10.673772 2026] [security2:error] [pid 358661:tid 358823] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TGglWhjQfpOo60_HpawAAHQM"]
[Tue Jul 21 08:08:10.722491 2026] [security2:error] [pid 358661:tid 358903] [client 143.244.57.90:38892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9TGglWhjQfpOo60_HpbAAAAG0"]
[Tue Jul 21 08:08:10.843300 2026] [security2:error] [pid 358661:tid 358795] [client 103.29.114.44:50837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TGglWhjQfpOo60_HpbwAAAAE"]
[Tue Jul 21 08:08:10.843506 2026] [security2:error] [pid 358661:tid 358795] [client 103.29.114.44:50837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TGglWhjQfpOo60_HpbwAAAAE"]
[Tue Jul 21 08:08:11.126173 2026] [security2:error] [pid 358661:tid 358915] [client 20.226.60.151:12159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/echkm.php"] [unique_id "al9TGwlWhjQfpOo60_HpcwAAAHk"]
[Tue Jul 21 08:08:11.137372 2026] [security2:error] [pid 358661:tid 358817] [client 143.244.57.90:3382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9TGwlWhjQfpOo60_HpdAAAABc"]
[Tue Jul 21 08:08:11.209702 2026] [security2:error] [pid 358661:tid 358838] [client 117.210.135.0:61080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TGwlWhjQfpOo60_HpdQAAACw"]
[Tue Jul 21 08:08:11.209820 2026] [security2:error] [pid 358661:tid 358838] [client 117.210.135.0:61080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TGwlWhjQfpOo60_HpdQAAACw"]
[Tue Jul 21 08:08:11.338640 2026] [security2:error] [pid 358661:tid 358794] [client 87.116.180.198:13960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TGwlWhjQfpOo60_HpeAAAAAA"]
[Tue Jul 21 08:08:11.338862 2026] [security2:error] [pid 358661:tid 358794] [client 87.116.180.198:13960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TGwlWhjQfpOo60_HpeAAAAAA"]
[Tue Jul 21 08:08:11.356836 2026] [security2:error] [pid 352421:tid 352672] [client 136.144.33.102:46807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9TG8JSWzG9jbYOtu5Z4AAAAP4"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:08:11.557147 2026] [security2:error] [pid 358661:tid 358871] [client 143.244.57.90:38924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.guilhermeverissimo.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9TGwlWhjQfpOo60_HpgAAAAE0"]
[Tue Jul 21 08:08:11.609182 2026] [security2:error] [pid 358661:tid 358867] [client 20.29.126.15:20206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/gg.php"] [unique_id "al9TGwlWhjQfpOo60_HpggAAAEk"]
[Tue Jul 21 08:08:11.966720 2026] [security2:error] [pid 352421:tid 352551] [client 65.21.113.253:60604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TG8JSWzG9jbYOtu5Z5AAAAIU"]
[Tue Jul 21 08:08:12.150299 2026] [rewrite:warn] [pid 358661:tid 358789] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:08:12.187305 2026] [security2:error] [pid 352421:tid 352580] [client 20.226.60.151:56347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/js.php"] [unique_id "al9THMJSWzG9jbYOtu5Z6wAAAKI"]
[Tue Jul 21 08:08:12.276261 2026] [rewrite:warn] [pid 358661:tid 358715] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:08:12.279411 2026] [rewrite:warn] [pid 358661:tid 358699] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:08:12.341665 2026] [rewrite:warn] [pid 358661:tid 358710] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:08:12.348404 2026] [rewrite:warn] [pid 358661:tid 358683] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:08:12.410534 2026] [rewrite:warn] [pid 358661:tid 358754] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:08:12.426501 2026] [rewrite:warn] [pid 358661:tid 358689] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:08:12.643785 2026] [security2:error] [pid 358661:tid 358686] [remote 45.3.47.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.47.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TGwlWhjQfpOo60_HpewAAKBU"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:12.662598 2026] [security2:error] [pid 352421:tid 352578] [client 117.247.80.59:15926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9THMJSWzG9jbYOtu5Z7gAAAKA"]
[Tue Jul 21 08:08:12.662761 2026] [security2:error] [pid 352421:tid 352578] [client 117.247.80.59:15926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9THMJSWzG9jbYOtu5Z7gAAAKA"]
[Tue Jul 21 08:08:12.786005 2026] [security2:error] [pid 358661:tid 358915] [client 20.226.60.151:11973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/lib.php"] [unique_id "al9THAlWhjQfpOo60_HpqwAAAHk"]
[Tue Jul 21 08:08:12.920869 2026] [security2:error] [pid 352421:tid 352629] [client 20.104.96.117:62528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/xwpg.php"] [unique_id "al9THMJSWzG9jbYOtu5Z9gAAANM"]
[Tue Jul 21 08:08:12.927326 2026] [security2:error] [pid 358661:tid 358856] [client 20.226.60.151:12193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/login.php"] [unique_id "al9THAlWhjQfpOo60_HprQAAAD4"]
[Tue Jul 21 08:08:12.944547 2026] [security2:error] [pid 358661:tid 358821] [client 175.144.82.48:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9THAlWhjQfpOo60_HprgAAABs"]
[Tue Jul 21 08:08:12.945344 2026] [security2:error] [pid 358661:tid 358821] [client 175.144.82.48:58750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9THAlWhjQfpOo60_HprgAAABs"]
[Tue Jul 21 08:08:13.018853 2026] [security2:error] [pid 352421:tid 352584] [client 20.226.60.151:12361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/a2.php"] [unique_id "al9THcJSWzG9jbYOtu5Z9wAAAKY"]
[Tue Jul 21 08:08:13.035521 2026] [security2:error] [pid 358661:tid 358877] [client 65.21.113.253:59154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9THQlWhjQfpOo60_HpsAAAAFM"]
[Tue Jul 21 08:08:13.095351 2026] [security2:error] [pid 352421:tid 352624] [client 20.226.60.151:12005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/d61.php"] [unique_id "al9THcJSWzG9jbYOtu5Z-gAAAM4"]
[Tue Jul 21 08:08:13.356739 2026] [security2:error] [pid 358661:tid 358906] [client 20.226.60.151:12141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/info.php"] [unique_id "al9THQlWhjQfpOo60_HpvgAAAHA"]
[Tue Jul 21 08:08:13.404785 2026] [security2:error] [pid 352421:tid 352638] [client 38.100.221.102:18112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9THcJSWzG9jbYOtu5aAQAAANw"]
[Tue Jul 21 08:08:13.404970 2026] [security2:error] [pid 352421:tid 352638] [client 38.100.221.102:18112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9THcJSWzG9jbYOtu5aAQAAANw"]
[Tue Jul 21 08:08:13.690034 2026] [security2:error] [pid 352421:tid 352608] [client 65.21.113.253:60604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9THcJSWzG9jbYOtu5Z_wAAAL4"]
[Tue Jul 21 08:08:13.702798 2026] [security2:error] [pid 358661:tid 358822] [client 20.226.60.151:56423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/core.php"] [unique_id "al9THQlWhjQfpOo60_HpwgAAABw"]
[Tue Jul 21 08:08:13.838506 2026] [security2:error] [pid 358661:tid 358721] [remote 45.3.35.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.35.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9THQlWhjQfpOo60_HpxAAAFjg"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:13.851582 2026] [security2:error] [pid 352421:tid 352492] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9THcJSWzG9jbYOtu5aDwAA2kY"]
[Tue Jul 21 08:08:13.851833 2026] [security2:error] [pid 352421:tid 352636] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9THcJSWzG9jbYOtu5aDwAA2kY"]
[Tue Jul 21 08:08:14.447274 2026] [security2:error] [pid 358661:tid 358820] [client 20.29.126.15:9208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/sql.php"] [unique_id "al9THglWhjQfpOo60_HpzAAAABo"]
[Tue Jul 21 08:08:14.681032 2026] [security2:error] [pid 358661:tid 358823] [client 20.226.60.151:64862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/19.php"] [unique_id "al9THglWhjQfpOo60_Hp0wAAAB0"]
[Tue Jul 21 08:08:14.687308 2026] [security2:error] [pid 358661:tid 358691] [remote 49.42.211.30:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.211.42.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9THglWhjQfpOo60_HpzQAASho"]
[Tue Jul 21 08:08:14.687477 2026] [security2:error] [pid 358661:tid 358868] [client 49.42.211.30:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9THglWhjQfpOo60_HpzQAASho"]
[Tue Jul 21 08:08:14.829233 2026] [security2:error] [pid 352421:tid 352573] [client 20.226.60.151:12180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/11.php"] [unique_id "al9THsJSWzG9jbYOtu5aHwAAAJs"]
[Tue Jul 21 08:08:15.167957 2026] [security2:error] [pid 358661:tid 358795] [client 162.219.176.3:34670] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9THwlWhjQfpOo60_Hp2wAAAAE"]
[Tue Jul 21 08:08:15.168063 2026] [security2:error] [pid 358661:tid 358795] [client 162.219.176.3:34670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9THwlWhjQfpOo60_Hp2wAAAAE"]
[Tue Jul 21 08:08:15.196173 2026] [security2:error] [pid 358661:tid 358848] [client 41.68.90.219:59599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9THwlWhjQfpOo60_Hp3QAAADY"]
[Tue Jul 21 08:08:15.196940 2026] [security2:error] [pid 358661:tid 358848] [client 41.68.90.219:59599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9THwlWhjQfpOo60_Hp3QAAADY"]
[Tue Jul 21 08:08:15.214885 2026] [security2:error] [pid 358661:tid 358897] [client 65.21.113.253:59154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9THwlWhjQfpOo60_Hp3gAAAGc"]
[Tue Jul 21 08:08:15.244133 2026] [security2:error] [pid 358661:tid 358830] [client 20.226.60.151:56383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/inc.php"] [unique_id "al9THwlWhjQfpOo60_Hp3wAAACQ"]
[Tue Jul 21 08:08:15.387437 2026] [security2:error] [pid 358661:tid 358902] [client 74.7.244.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "www.volyo.com.br"] [uri "/robots.txt"] [unique_id "al9THwlWhjQfpOo60_Hp5AAAbCU"]
[Tue Jul 21 08:08:15.591215 2026] [security2:error] [pid 358661:tid 358860] [client 65.21.113.253:55090] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9THwlWhjQfpOo60_Hp1gAAAEI"]
[Tue Jul 21 08:08:15.730441 2026] [security2:error] [pid 352421:tid 352578] [client 20.197.192.193:53156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/we.php"] [unique_id "al9TH8JSWzG9jbYOtu5aMQAAAKA"]
[Tue Jul 21 08:08:16.143472 2026] [security2:error] [pid 358661:tid 358886] [client 20.226.60.151:11968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/v2.php"] [unique_id "al9TIAlWhjQfpOo60_Hp8AAAAFw"]
[Tue Jul 21 08:08:16.272794 2026] [security2:error] [pid 358661:tid 358810] [client 65.21.113.253:55100] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9THwlWhjQfpOo60_Hp6wAAABA"]
[Tue Jul 21 08:08:16.778218 2026] [security2:error] [pid 352421:tid 352647] [client 173.252.95.28:41992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9TIMJSWzG9jbYOtu5aQQAAAOU"]
[Tue Jul 21 08:08:16.849057 2026] [security2:error] [pid 358661:tid 358861] [client 20.226.60.151:65038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-ppoxua4.php"] [unique_id "al9TIAlWhjQfpOo60_Hp_AAAAEM"]
[Tue Jul 21 08:08:16.926275 2026] [security2:error] [pid 352421:tid 352435] [remote 65.111.10.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9THsJSWzG9jbYOtu5aIQAAxQ0"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:16.943744 2026] [security2:error] [pid 352421:tid 352532] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TIMJSWzG9jbYOtu5aRwAAhm4"]
[Tue Jul 21 08:08:16.944718 2026] [security2:error] [pid 352421:tid 352552] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TIMJSWzG9jbYOtu5aRwAAhm4"]
[Tue Jul 21 08:08:16.945117 2026] [security2:error] [pid 352421:tid 352657] [client 20.226.60.151:12359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/panel.php"] [unique_id "al9TIMJSWzG9jbYOtu5aSAAAAO8"]
[Tue Jul 21 08:08:17.133715 2026] [security2:error] [pid 352421:tid 352618] [client 196.251.121.187:61578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "lojadedoces.com"] [uri "/"] [unique_id "al9TIcJSWzG9jbYOtu5aTgAAAMg"]
[Tue Jul 21 08:08:17.191247 2026] [security2:error] [pid 352421:tid 352457] [remote 46.105.28.235:59638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compressoresra.com.br"] [uri "/wp-login.php"] [unique_id "al9TIcJSWzG9jbYOtu5aTwAA2iM"]
[Tue Jul 21 08:08:17.202240 2026] [security2:error] [pid 358661:tid 358813] [client 20.197.192.193:52242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "esidiomass.com.br"] [uri "/phpinfo.php1"] [unique_id "al9TIQlWhjQfpOo60_Hp_gAAABM"]
[Tue Jul 21 08:08:17.277550 2026] [security2:error] [pid 352421:tid 352575] [client 109.60.28.94:13525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TIcJSWzG9jbYOtu5aUQAAAJ0"]
[Tue Jul 21 08:08:17.278258 2026] [security2:error] [pid 352421:tid 352575] [client 109.60.28.94:13525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TIcJSWzG9jbYOtu5aUQAAAJ0"]
[Tue Jul 21 08:08:17.460454 2026] [security2:error] [pid 358661:tid 358665] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TIQlWhjQfpOo60_HqAQAAeQA"]
[Tue Jul 21 08:08:17.460647 2026] [security2:error] [pid 358661:tid 358915] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TIQlWhjQfpOo60_HqAQAAeQA"]
[Tue Jul 21 08:08:17.548967 2026] [security2:error] [pid 358661:tid 358771] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TIQlWhjQfpOo60_HqAgAAD2o"]
[Tue Jul 21 08:08:17.549112 2026] [security2:error] [pid 358661:tid 358809] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TIQlWhjQfpOo60_HqAgAAD2o"]
[Tue Jul 21 08:08:17.761882 2026] [security2:error] [pid 358661:tid 358833] [client 120.56.162.40:60212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TIQlWhjQfpOo60_HqCQAAACc"]
[Tue Jul 21 08:08:17.762096 2026] [security2:error] [pid 358661:tid 358833] [client 120.56.162.40:60212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TIQlWhjQfpOo60_HqCQAAACc"]
[Tue Jul 21 08:08:17.831478 2026] [security2:error] [pid 352421:tid 352620] [client 102.206.115.33:64538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TIcJSWzG9jbYOtu5aWgAAAMo"]
[Tue Jul 21 08:08:17.831583 2026] [security2:error] [pid 352421:tid 352620] [client 102.206.115.33:64538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TIcJSWzG9jbYOtu5aWgAAAMo"]
[Tue Jul 21 08:08:17.947761 2026] [security2:error] [pid 352421:tid 352573] [client 193.36.225.71:26375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9TIcJSWzG9jbYOtu5aWwAAAJs"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:08:18.147463 2026] [security2:error] [pid 358661:tid 358919] [client 20.226.60.151:65036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-u3nxbvx.php"] [unique_id "al9TIglWhjQfpOo60_HqEwAAAH0"]
[Tue Jul 21 08:08:18.238011 2026] [security2:error] [pid 358661:tid 358822] [client 20.104.96.117:62562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/ops.php"] [unique_id "al9TIglWhjQfpOo60_HqFAAAABw"]
[Tue Jul 21 08:08:18.332209 2026] [security2:error] [pid 352421:tid 352678] [client 20.226.60.151:65035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/ss.php"] [unique_id "al9TIsJSWzG9jbYOtu5aYgAAAQQ"]
[Tue Jul 21 08:08:18.340394 2026] [security2:error] [pid 358661:tid 358845] [client 61.1.167.83:56319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TIglWhjQfpOo60_HqFgAAADM"]
[Tue Jul 21 08:08:18.340514 2026] [security2:error] [pid 358661:tid 358845] [client 61.1.167.83:56319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TIglWhjQfpOo60_HqFgAAADM"]
[Tue Jul 21 08:08:18.596099 2026] [security2:error] [pid 358661:tid 358831] [client 150.129.202.39:65150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TIglWhjQfpOo60_HqGQAAACU"]
[Tue Jul 21 08:08:18.596284 2026] [security2:error] [pid 358661:tid 358831] [client 150.129.202.39:65150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TIglWhjQfpOo60_HqGQAAACU"]
[Tue Jul 21 08:08:18.691556 2026] [security2:error] [pid 352421:tid 352640] [client 20.226.60.151:65079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/min.php"] [unique_id "al9TIsJSWzG9jbYOtu5aaAAAAN4"]
[Tue Jul 21 08:08:18.800731 2026] [security2:error] [pid 358661:tid 358896] [client 65.21.113.253:59154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TIglWhjQfpOo60_HqPAAAAGY"]
[Tue Jul 21 08:08:18.830689 2026] [security2:error] [pid 352421:tid 352650] [client 20.226.60.151:12123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/dex.php"] [unique_id "al9TIsJSWzG9jbYOtu5aagAAAOg"]
[Tue Jul 21 08:08:18.889581 2026] [security2:error] [pid 358661:tid 358840] [client 185.213.175.37:44804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.desconsultoria.com.br"] [uri "/public/.git/HEAD"] [unique_id "al9TIglWhjQfpOo60_HqQAAAAC4"]
[Tue Jul 21 08:08:18.889742 2026] [security2:error] [pid 358661:tid 358840] [client 185.213.175.37:44804] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.desconsultoria.com.br"] [uri "/public/.git/HEAD"] [unique_id "al9TIglWhjQfpOo60_HqQAAAAC4"]
[Tue Jul 21 08:08:18.983336 2026] [security2:error] [pid 352421:tid 352530] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TIsJSWzG9jbYOtu5abgAAjWw"]
[Tue Jul 21 08:08:18.983483 2026] [security2:error] [pid 352421:tid 352559] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TIsJSWzG9jbYOtu5abgAAjWw"]
[Tue Jul 21 08:08:19.052692 2026] [security2:error] [pid 358661:tid 358903] [client 162.219.176.3:37790] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9TIwlWhjQfpOo60_HqRwAAAG0"]
[Tue Jul 21 08:08:19.052861 2026] [security2:error] [pid 358661:tid 358903] [client 162.219.176.3:37790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9TIwlWhjQfpOo60_HqRwAAAG0"]
[Tue Jul 21 08:08:19.111327 2026] [security2:error] [pid 352421:tid 352645] [client 196.251.121.187:62198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "lojacasacosta.com"] [uri "/"] [unique_id "al9TI8JSWzG9jbYOtu5abwAAAOM"]
[Tue Jul 21 08:08:19.183851 2026] [security2:error] [pid 358661:tid 358783] [remote 57.141.18.46:61268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9TIwlWhjQfpOo60_HqaAAAI3Y"]
[Tue Jul 21 08:08:19.340992 2026] [security2:error] [pid 352421:tid 352424] [remote 147.50.252.213:52228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aprendizadosemlimites.store"] [uri "/wp-login.php"] [unique_id "al9TI8JSWzG9jbYOtu5acAAAsgI"]
[Tue Jul 21 08:08:19.434216 2026] [security2:error] [pid 358661:tid 358813] [client 65.21.113.253:55090] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TIwlWhjQfpOo60_HqRgAAABM"]
[Tue Jul 21 08:08:19.439253 2026] [security2:error] [pid 358661:tid 358884] [client 20.226.60.151:56398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9TIwlWhjQfpOo60_HqbQAAAFo"]
[Tue Jul 21 08:08:19.455582 2026] [security2:error] [pid 358661:tid 358768] [remote 65.111.25.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.25.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TIglWhjQfpOo60_HqFwAASWc"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:19.585958 2026] [security2:error] [pid 358661:tid 358876] [client 20.226.60.151:11999] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "flangeforte.com.br"] [uri "/1.php"] [unique_id "al9TIwlWhjQfpOo60_HqfQAAAFI"]
[Tue Jul 21 08:08:19.586092 2026] [security2:error] [pid 358661:tid 358876] [client 20.226.60.151:11999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/1.php"] [unique_id "al9TIwlWhjQfpOo60_HqfQAAAFI"]
[Tue Jul 21 08:08:19.607722 2026] [security2:error] [pid 352421:tid 352643] [client 20.197.192.193:64467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/edit.php"] [unique_id "al9TI8JSWzG9jbYOtu5afQAAAOE"]
[Tue Jul 21 08:08:19.653105 2026] [security2:error] [pid 358661:tid 358856] [client 74.7.175.129:55932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cenem.com.br"] [uri "/robots.txt"] [unique_id "al9TIwlWhjQfpOo60_HqfgAAPnE"]
[Tue Jul 21 08:08:19.795549 2026] [security2:error] [pid 358661:tid 358811] [client 20.226.60.151:56419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/autoload_classmap.php"] [unique_id "al9TIwlWhjQfpOo60_HqgQAAABE"]
[Tue Jul 21 08:08:19.848744 2026] [security2:error] [pid 358661:tid 358762] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TIwlWhjQfpOo60_HqhgAADWE"]
[Tue Jul 21 08:08:19.848908 2026] [security2:error] [pid 358661:tid 358807] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TIwlWhjQfpOo60_HqhgAADWE"]
[Tue Jul 21 08:08:20.059085 2026] [security2:error] [pid 352421:tid 352587] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TI8JSWzG9jbYOtu5aiQAAqXI"]
[Tue Jul 21 08:08:20.117596 2026] [security2:error] [pid 358661:tid 358699] [remote 182.77.62.24:57348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "growe-ag.jaypi.com.br"] [uri "/wp-login.php"] [unique_id "al9TJAlWhjQfpOo60_HqiQAAJyI"]
[Tue Jul 21 08:08:20.562611 2026] [security2:error] [pid 358661:tid 358797] [client 20.226.60.151:56368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-link-zorm.php"] [unique_id "al9TJAlWhjQfpOo60_HqjgAAAAM"]
[Tue Jul 21 08:08:20.625017 2026] [security2:error] [pid 358661:tid 358819] [client 20.226.60.151:12157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/ms.php"] [unique_id "al9TJAlWhjQfpOo60_HqkQAAABk"]
[Tue Jul 21 08:08:20.659212 2026] [security2:error] [pid 358661:tid 358913] [client 178.153.91.96:51509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TJAlWhjQfpOo60_HqkgAAAHc"]
[Tue Jul 21 08:08:20.659376 2026] [security2:error] [pid 358661:tid 358913] [client 178.153.91.96:51509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TJAlWhjQfpOo60_HqkgAAAHc"]
[Tue Jul 21 08:08:20.756070 2026] [security2:error] [pid 358661:tid 358683] [remote 45.3.50.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.50.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TJAlWhjQfpOo60_HqkAAAeBI"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:20.779796 2026] [security2:error] [pid 358661:tid 358886] [client 65.21.113.253:53478] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TJAlWhjQfpOo60_HqjQAAAFw"]
[Tue Jul 21 08:08:20.784205 2026] [security2:error] [pid 358661:tid 358894] [client 20.29.126.15:7100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/up.php"] [unique_id "al9TJAlWhjQfpOo60_HqkwAAAGQ"]
[Tue Jul 21 08:08:21.023488 2026] [security2:error] [pid 352421:tid 352613] [client 20.226.60.151:56422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-link-szoppm.php"] [unique_id "al9TJcJSWzG9jbYOtu5a2gAAAMM"]
[Tue Jul 21 08:08:21.205213 2026] [security2:error] [pid 358661:tid 358689] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TJQlWhjQfpOo60_HqmAAAUBg"]
[Tue Jul 21 08:08:21.205329 2026] [security2:error] [pid 358661:tid 358874] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TJQlWhjQfpOo60_HqmAAAUBg"]
[Tue Jul 21 08:08:21.280081 2026] [security2:error] [pid 352421:tid 352481] [remote 185.236.20.134:44100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9TJcJSWzG9jbYOtu5a3AAA9Ts"]
[Tue Jul 21 08:08:21.364691 2026] [security2:error] [pid 352421:tid 352620] [client 20.226.60.151:64851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/albin.php"] [unique_id "al9TJcJSWzG9jbYOtu5a3gAAAMo"]
[Tue Jul 21 08:08:21.453196 2026] [security2:error] [pid 358661:tid 358834] [client 20.104.96.117:62532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/mac.php"] [unique_id "al9TJQlWhjQfpOo60_HqmwAAACg"]
[Tue Jul 21 08:08:21.518481 2026] [security2:error] [pid 358661:tid 358885] [client 103.29.114.44:16879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TJQlWhjQfpOo60_HqngAAAFs"]
[Tue Jul 21 08:08:21.518637 2026] [security2:error] [pid 358661:tid 358885] [client 103.29.114.44:16879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TJQlWhjQfpOo60_HqngAAAFs"]
[Tue Jul 21 08:08:21.688435 2026] [security2:error] [pid 358661:tid 358825] [client 20.226.60.151:11995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/memberfuns.php"] [unique_id "al9TJQlWhjQfpOo60_HqowAAAB8"]
[Tue Jul 21 08:08:21.718207 2026] [security2:error] [pid 358661:tid 358838] [client 103.166.103.129:53140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TJQlWhjQfpOo60_HqpAAAACw"]
[Tue Jul 21 08:08:21.718316 2026] [security2:error] [pid 358661:tid 358838] [client 103.166.103.129:53140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TJQlWhjQfpOo60_HqpAAAACw"]
[Tue Jul 21 08:08:21.756764 2026] [security2:error] [pid 352421:tid 352637] [client 117.210.135.0:61730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TJcJSWzG9jbYOtu5a5QAAANs"]
[Tue Jul 21 08:08:21.756872 2026] [security2:error] [pid 352421:tid 352637] [client 117.210.135.0:61730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TJcJSWzG9jbYOtu5a5QAAANs"]
[Tue Jul 21 08:08:22.026293 2026] [security2:error] [pid 352421:tid 352532] [remote 4.205.168.44:60344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9TJsJSWzG9jbYOtu5a6gAA524"]
[Tue Jul 21 08:08:22.038071 2026] [security2:error] [pid 358661:tid 358866] [client 185.236.20.134:19560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9TJglWhjQfpOo60_HqpQAAAEg"]
[Tue Jul 21 08:08:22.085530 2026] [security2:error] [pid 358661:tid 358795] [client 87.116.180.198:14018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TJglWhjQfpOo60_HqpwAAAAE"]
[Tue Jul 21 08:08:22.085669 2026] [security2:error] [pid 358661:tid 358795] [client 87.116.180.198:14018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TJglWhjQfpOo60_HqpwAAAAE"]
[Tue Jul 21 08:08:22.107852 2026] [security2:error] [pid 358661:tid 358884] [client 20.226.60.151:56409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/cilus.php"] [unique_id "al9TJglWhjQfpOo60_HqqAAAAFo"]
[Tue Jul 21 08:08:22.237439 2026] [security2:error] [pid 358661:tid 358855] [client 20.226.60.151:12116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/0.php"] [unique_id "al9TJglWhjQfpOo60_HqqgAAAD0"]
[Tue Jul 21 08:08:22.581586 2026] [security2:error] [pid 358661:tid 358814] [client 20.226.60.151:12380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/BDKR28.php"] [unique_id "al9TJglWhjQfpOo60_HqrgAAABQ"]
[Tue Jul 21 08:08:22.597187 2026] [security2:error] [pid 352421:tid 352602] [client 103.78.200.11:53286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TJsJSWzG9jbYOtu5a9wAAALg"]
[Tue Jul 21 08:08:22.597282 2026] [security2:error] [pid 352421:tid 352602] [client 103.78.200.11:53286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TJsJSWzG9jbYOtu5a9wAAALg"]
[Tue Jul 21 08:08:22.616614 2026] [security2:error] [pid 358661:tid 358918] [client 20.226.60.151:65082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/gptsh.php"] [unique_id "al9TJglWhjQfpOo60_HqrwAAAHw"]
[Tue Jul 21 08:08:22.817955 2026] [security2:error] [pid 352421:tid 352564] [client 20.197.192.193:64486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/la.php"] [unique_id "al9TJsJSWzG9jbYOtu5a_AAAAJI"]
[Tue Jul 21 08:08:22.850309 2026] [security2:error] [pid 352421:tid 352483] [remote 185.236.20.134:44112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.essenceclinicadesaude.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9TJsJSWzG9jbYOtu5a_QAAvz0"]
[Tue Jul 21 08:08:23.062546 2026] [security2:error] [pid 352421:tid 352632] [client 117.247.80.59:16000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TJ8JSWzG9jbYOtu5bAwAAANY"]
[Tue Jul 21 08:08:23.062658 2026] [security2:error] [pid 352421:tid 352632] [client 117.247.80.59:16000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TJ8JSWzG9jbYOtu5bAwAAANY"]
[Tue Jul 21 08:08:23.176712 2026] [security2:error] [pid 352421:tid 352552] [client 20.226.60.151:12408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/green1.php"] [unique_id "al9TJ8JSWzG9jbYOtu5bBgAAAIY"]
[Tue Jul 21 08:08:23.238778 2026] [security2:error] [pid 358661:tid 358917] [client 20.226.60.151:56433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/rithin.php"] [unique_id "al9TJwlWhjQfpOo60_HqsgAAAHs"]
[Tue Jul 21 08:08:23.390684 2026] [security2:error] [pid 358661:tid 358863] [client 20.226.60.151:12405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/nc4.php"] [unique_id "al9TJwlWhjQfpOo60_HqswAAAEU"]
[Tue Jul 21 08:08:23.477262 2026] [security2:error] [pid 352421:tid 352503] [remote 216.26.244.95:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.244.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TJ8JSWzG9jbYOtu5bCQAA81E"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:23.594970 2026] [security2:error] [pid 358661:tid 358810] [client 193.36.225.61:44741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9TJglWhjQfpOo60_HqrQAAABA"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:08:23.657160 2026] [security2:error] [pid 358661:tid 358774] [remote 185.236.20.134:44114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9TJwlWhjQfpOo60_HqtQAAHm0"]
[Tue Jul 21 08:08:23.683899 2026] [security2:error] [pid 358661:tid 358908] [client 175.144.82.48:59219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TJwlWhjQfpOo60_HqtgAAAHI"]
[Tue Jul 21 08:08:23.684032 2026] [security2:error] [pid 358661:tid 358908] [client 175.144.82.48:59219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TJwlWhjQfpOo60_HqtgAAAHI"]
[Tue Jul 21 08:08:23.934535 2026] [security2:error] [pid 358661:tid 358831] [client 20.226.60.151:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/fffm.php"] [unique_id "al9TJwlWhjQfpOo60_HquQAAACU"]
[Tue Jul 21 08:08:24.015245 2026] [security2:error] [pid 352421:tid 352656] [client 38.100.221.102:17641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TKMJSWzG9jbYOtu5bFAAAAO4"]
[Tue Jul 21 08:08:24.015429 2026] [security2:error] [pid 352421:tid 352656] [client 38.100.221.102:17641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TKMJSWzG9jbYOtu5bFAAAAO4"]
[Tue Jul 21 08:08:24.294550 2026] [security2:error] [pid 358661:tid 358840] [client 20.226.60.151:12358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/a1.php"] [unique_id "al9TKAlWhjQfpOo60_HqvwAAAC4"]
[Tue Jul 21 08:08:24.699072 2026] [security2:error] [pid 358661:tid 358667] [remote 104.167.19.160:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.19.167.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TKAlWhjQfpOo60_HqwQAAQQI"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:24.843071 2026] [security2:error] [pid 358661:tid 358674] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TKAlWhjQfpOo60_HqxQAAVAk"]
[Tue Jul 21 08:08:24.843313 2026] [security2:error] [pid 358661:tid 358878] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TKAlWhjQfpOo60_HqxQAAVAk"]
[Tue Jul 21 08:08:25.059477 2026] [security2:error] [pid 358661:tid 358808] [client 20.226.60.151:12355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/eee.php"] [unique_id "al9TKQlWhjQfpOo60_HqxgAAAA4"]
[Tue Jul 21 08:08:25.100271 2026] [security2:error] [pid 352421:tid 352673] [client 185.236.20.134:30730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9TKcJSWzG9jbYOtu5bJgAAAP8"]
[Tue Jul 21 08:08:25.516571 2026] [security2:error] [pid 358661:tid 358825] [client 185.191.171.18:36508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivaconcierge.com.br"] [uri "/en/imoveis/cdm-0033/"] [unique_id "al9TKQlWhjQfpOo60_HqygAAAB8"]
[Tue Jul 21 08:08:25.516714 2026] [security2:error] [pid 358661:tid 358825] [client 185.191.171.18:36508] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vivaconcierge.com.br"] [uri "/en/imoveis/cdm-0033/"] [unique_id "al9TKQlWhjQfpOo60_HqygAAAB8"]
[Tue Jul 21 08:08:25.674386 2026] [security2:error] [pid 358661:tid 358798] [client 65.21.113.253:53478] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TKQlWhjQfpOo60_HqyQAAAAQ"]
[Tue Jul 21 08:08:25.887093 2026] [security2:error] [pid 358661:tid 358897] [client 41.68.90.219:60065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TKQlWhjQfpOo60_Hq0wAAAGc"]
[Tue Jul 21 08:08:25.887712 2026] [security2:error] [pid 358661:tid 358897] [client 41.68.90.219:60065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TKQlWhjQfpOo60_Hq0wAAAGc"]
[Tue Jul 21 08:08:26.036777 2026] [security2:error] [pid 358661:tid 358891] [client 65.21.113.253:47850] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TKglWhjQfpOo60_Hq1QAAAGE"]
[Tue Jul 21 08:08:26.077593 2026] [security2:error] [pid 358661:tid 358807] [client 20.226.60.151:64852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/dfre.php"] [unique_id "al9TKglWhjQfpOo60_Hq1wAAAA0"]
[Tue Jul 21 08:08:26.176837 2026] [security2:error] [pid 358661:tid 358702] [remote 65.111.29.63:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.29.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TKglWhjQfpOo60_Hq2AAATCU"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:26.354965 2026] [security2:error] [pid 358661:tid 358675] [remote 185.236.20.134:42344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.essenceclinicadesaude.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9TKglWhjQfpOo60_Hq4AAAewo"]
[Tue Jul 21 08:08:26.565217 2026] [security2:error] [pid 358661:tid 358797] [client 20.226.60.151:11845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/wp-aothait.php"] [unique_id "al9TKglWhjQfpOo60_Hq4gAAAAM"]
[Tue Jul 21 08:08:26.663027 2026] [security2:error] [pid 358661:tid 358833] [client 65.21.113.253:53478] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TKglWhjQfpOo60_Hq2wAAACc"]
[Tue Jul 21 08:08:26.810465 2026] [security2:error] [pid 358661:tid 358860] [client 20.226.60.151:65052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/wp-happy.php"] [unique_id "al9TKglWhjQfpOo60_Hq5gAAAEI"]
[Tue Jul 21 08:08:26.957188 2026] [security2:error] [pid 358661:tid 358742] [remote 185.236.20.134:42358] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9TKglWhjQfpOo60_Hq6QAAZk0"]
[Tue Jul 21 08:08:27.217755 2026] [security2:error] [pid 358661:tid 358834] [client 20.226.60.151:12170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/config.json.php"] [unique_id "al9TKwlWhjQfpOo60_Hq8QAAACg"]
[Tue Jul 21 08:08:27.369616 2026] [security2:error] [pid 352421:tid 352560] [client 20.226.60.151:64877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/fpr4.php"] [unique_id "al9TK8JSWzG9jbYOtu5bRwAAAI4"]
[Tue Jul 21 08:08:27.442012 2026] [security2:error] [pid 358661:tid 358838] [client 20.226.60.151:11991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9TKwlWhjQfpOo60_Hq9gAAACw"]
[Tue Jul 21 08:08:27.729241 2026] [security2:error] [pid 358661:tid 358842] [client 20.226.60.151:11872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/k2.php"] [unique_id "al9TKwlWhjQfpOo60_Hq-gAAADA"]
[Tue Jul 21 08:08:27.905315 2026] [security2:error] [pid 358661:tid 358741] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TKwlWhjQfpOo60_HrAgAAIUw"]
[Tue Jul 21 08:08:27.905513 2026] [security2:error] [pid 358661:tid 358827] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TKwlWhjQfpOo60_HrAgAAIUw"]
[Tue Jul 21 08:08:28.126872 2026] [security2:error] [pid 352421:tid 352628] [client 109.60.28.94:13997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TLMJSWzG9jbYOtu5bUAAAANI"]
[Tue Jul 21 08:08:28.127564 2026] [security2:error] [pid 352421:tid 352628] [client 109.60.28.94:13997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TLMJSWzG9jbYOtu5bUAAAANI"]
[Tue Jul 21 08:08:28.147801 2026] [security2:error] [pid 358661:tid 358676] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TLAlWhjQfpOo60_HrBAAAUgs"]
[Tue Jul 21 08:08:28.147971 2026] [security2:error] [pid 358661:tid 358876] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TLAlWhjQfpOo60_HrBAAAUgs"]
[Tue Jul 21 08:08:28.269702 2026] [security2:error] [pid 358661:tid 358879] [client 103.166.103.129:32301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TLAlWhjQfpOo60_HrBgAAAFU"]
[Tue Jul 21 08:08:28.269877 2026] [security2:error] [pid 358661:tid 358879] [client 103.166.103.129:32301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TLAlWhjQfpOo60_HrBgAAAFU"]
[Tue Jul 21 08:08:28.330614 2026] [security2:error] [pid 352421:tid 352597] [client 102.206.115.33:59360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TLMJSWzG9jbYOtu5bVAAAALM"]
[Tue Jul 21 08:08:28.330769 2026] [security2:error] [pid 352421:tid 352597] [client 102.206.115.33:59360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TLMJSWzG9jbYOtu5bVAAAALM"]
[Tue Jul 21 08:08:28.342720 2026] [security2:error] [pid 358661:tid 358864] [client 136.144.33.99:26863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.33.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9TLAlWhjQfpOo60_HrAwAAAEY"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:08:28.357348 2026] [security2:error] [pid 358661:tid 358832] [client 120.56.162.40:60700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TLAlWhjQfpOo60_HrBwAAACY"]
[Tue Jul 21 08:08:28.357453 2026] [security2:error] [pid 358661:tid 358832] [client 120.56.162.40:60700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TLAlWhjQfpOo60_HrBwAAACY"]
[Tue Jul 21 08:08:28.373320 2026] [security2:error] [pid 352421:tid 352577] [client 20.197.192.193:64497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/kua.php"] [unique_id "al9TLMJSWzG9jbYOtu5bVwAAAJ8"]
[Tue Jul 21 08:08:28.404924 2026] [security2:error] [pid 358661:tid 358733] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TLAlWhjQfpOo60_HrCQAAAkQ"]
[Tue Jul 21 08:08:28.405053 2026] [security2:error] [pid 358661:tid 358796] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TLAlWhjQfpOo60_HrCQAAAkQ"]
[Tue Jul 21 08:08:28.420699 2026] [security2:error] [pid 358661:tid 358890] [client 20.104.96.117:63442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/mg.php"] [unique_id "al9TLAlWhjQfpOo60_HrCgAAAGA"]
[Tue Jul 21 08:08:28.481212 2026] [security2:error] [pid 352421:tid 352616] [client 162.219.176.3:56416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9TLMJSWzG9jbYOtu5bWgAAAMY"]
[Tue Jul 21 08:08:28.481340 2026] [security2:error] [pid 352421:tid 352616] [client 162.219.176.3:56416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9TLMJSWzG9jbYOtu5bWgAAAMY"]
[Tue Jul 21 08:08:28.568439 2026] [security2:error] [pid 358661:tid 358906] [client 20.226.60.151:64879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/file88.php"] [unique_id "al9TLAlWhjQfpOo60_HrDQAAAHA"]
[Tue Jul 21 08:08:28.716862 2026] [security2:error] [pid 358661:tid 358677] [remote 65.111.25.127:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.25.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TKwlWhjQfpOo60_Hq-QAAFQw"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:28.725358 2026] [security2:error] [pid 358661:tid 358726] [remote 57.141.18.21:50120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9TLAlWhjQfpOo60_HrEwAAcj0"]
[Tue Jul 21 08:08:28.885451 2026] [security2:error] [pid 358661:tid 358868] [client 20.197.192.193:3102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9TLAlWhjQfpOo60_HrFAAAAEo"]
[Tue Jul 21 08:08:28.991698 2026] [security2:error] [pid 352421:tid 352570] [client 20.226.60.151:65053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/ccc.php"] [unique_id "al9TLMJSWzG9jbYOtu5bYgAAAJg"]
[Tue Jul 21 08:08:29.189452 2026] [security2:error] [pid 352421:tid 352649] [client 20.226.60.151:12126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9TLcJSWzG9jbYOtu5bZAAAAOc"]
[Tue Jul 21 08:08:29.336522 2026] [security2:error] [pid 358661:tid 358860] [client 20.29.126.15:2357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/66.php"] [unique_id "al9TLQlWhjQfpOo60_HrGAAAAEI"]
[Tue Jul 21 08:08:29.451165 2026] [security2:error] [pid 358661:tid 358810] [client 150.129.202.39:65271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TLQlWhjQfpOo60_HrGwAAABA"]
[Tue Jul 21 08:08:29.451324 2026] [security2:error] [pid 358661:tid 358810] [client 150.129.202.39:65271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TLQlWhjQfpOo60_HrGwAAABA"]
[Tue Jul 21 08:08:29.460146 2026] [security2:error] [pid 358661:tid 358806] [client 162.219.176.3:56430] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9TLQlWhjQfpOo60_HrHAAAAAw"]
[Tue Jul 21 08:08:29.460270 2026] [security2:error] [pid 358661:tid 358806] [client 162.219.176.3:56430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9TLQlWhjQfpOo60_HrHAAAAAw"]
[Tue Jul 21 08:08:29.685958 2026] [security2:error] [pid 352421:tid 352598] [client 65.21.113.253:53488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TLcJSWzG9jbYOtu5bZQAAALQ"]
[Tue Jul 21 08:08:29.702248 2026] [security2:error] [pid 352421:tid 352498] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TLcJSWzG9jbYOtu5bbAAAoEw"]
[Tue Jul 21 08:08:29.702402 2026] [security2:error] [pid 352421:tid 352578] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TLcJSWzG9jbYOtu5bbAAAoEw"]
[Tue Jul 21 08:08:30.185462 2026] [security2:error] [pid 352421:tid 352571] [client 20.226.60.151:56435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/777.php"] [unique_id "al9TLsJSWzG9jbYOtu5bdgAAAJk"]
[Tue Jul 21 08:08:30.387003 2026] [security2:error] [pid 358661:tid 358685] [remote 209.50.181.183:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.181.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TLglWhjQfpOo60_HrJQAAKBQ"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:30.436479 2026] [security2:error] [pid 352421:tid 352502] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TLsJSWzG9jbYOtu5bewAA2FA"]
[Tue Jul 21 08:08:30.436685 2026] [security2:error] [pid 352421:tid 352634] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TLsJSWzG9jbYOtu5bewAA2FA"]
[Tue Jul 21 08:08:30.616396 2026] [security2:error] [pid 352421:tid 352662] [client 62.102.148.158:60788] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9TLsJSWzG9jbYOtu5bgAAAAPQ"]
[Tue Jul 21 08:08:30.616488 2026] [security2:error] [pid 352421:tid 352662] [client 62.102.148.158:60788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9TLsJSWzG9jbYOtu5bgAAAAPQ"]
[Tue Jul 21 08:08:30.652381 2026] [security2:error] [pid 352421:tid 352657] [client 20.226.60.151:12103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9TLsJSWzG9jbYOtu5bgQAAAO8"]
[Tue Jul 21 08:08:30.682377 2026] [security2:error] [pid 358661:tid 358899] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TLglWhjQfpOo60_HrKgAAaWY"]
[Tue Jul 21 08:08:30.875530 2026] [security2:error] [pid 358661:tid 358830] [client 65.21.113.253:47850] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TLglWhjQfpOo60_HrLgAAACQ"]
[Tue Jul 21 08:08:31.049866 2026] [security2:error] [pid 358661:tid 358798] [client 20.226.60.151:56446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/for.php"] [unique_id "al9TLwlWhjQfpOo60_HrMgAAAAQ"]
[Tue Jul 21 08:08:31.171122 2026] [security2:error] [pid 352421:tid 352648] [client 178.153.91.96:53882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TL8JSWzG9jbYOtu5bigAAAOY"]
[Tue Jul 21 08:08:31.171228 2026] [security2:error] [pid 352421:tid 352648] [client 178.153.91.96:53882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TL8JSWzG9jbYOtu5bigAAAOY"]
[Tue Jul 21 08:08:31.449346 2026] [security2:error] [pid 352421:tid 352494] [remote 65.111.1.250:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.1.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TL8JSWzG9jbYOtu5bkAAAvEg"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:31.475929 2026] [security2:error] [pid 352421:tid 352593] [client 65.21.113.253:53488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TL8JSWzG9jbYOtu5biQAAAK8"]
[Tue Jul 21 08:08:31.521576 2026] [security2:error] [pid 358661:tid 358848] [client 103.78.200.11:53804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TLwlWhjQfpOo60_HrOgAAADY"]
[Tue Jul 21 08:08:31.522220 2026] [security2:error] [pid 358661:tid 358848] [client 103.78.200.11:53804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TLwlWhjQfpOo60_HrOgAAADY"]
[Tue Jul 21 08:08:31.539248 2026] [security2:error] [pid 352421:tid 352579] [client 20.29.126.15:6381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/666.php"] [unique_id "al9TL8JSWzG9jbYOtu5blAAAAKE"]
[Tue Jul 21 08:08:31.717025 2026] [security2:error] [pid 358661:tid 358743] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TLwlWhjQfpOo60_HrPgAAe04"]
[Tue Jul 21 08:08:31.717214 2026] [security2:error] [pid 358661:tid 358917] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TLwlWhjQfpOo60_HrPgAAe04"]
[Tue Jul 21 08:08:31.802464 2026] [security2:error] [pid 358661:tid 358843] [client 61.1.167.83:56805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TLwlWhjQfpOo60_HrPwAAADE"]
[Tue Jul 21 08:08:31.802663 2026] [security2:error] [pid 358661:tid 358843] [client 61.1.167.83:56805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TLwlWhjQfpOo60_HrPwAAADE"]
[Tue Jul 21 08:08:32.028119 2026] [security2:error] [pid 358661:tid 358800] [client 20.226.60.151:56361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/ssla.php"] [unique_id "al9TMAlWhjQfpOo60_HrQgAAAAY"]
[Tue Jul 21 08:08:32.112181 2026] [security2:error] [pid 352421:tid 352665] [client 103.29.114.44:36699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TMMJSWzG9jbYOtu5bmgAAAPc"]
[Tue Jul 21 08:08:32.112299 2026] [security2:error] [pid 352421:tid 352665] [client 103.29.114.44:36699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TMMJSWzG9jbYOtu5bmgAAAPc"]
[Tue Jul 21 08:08:32.307776 2026] [security2:error] [pid 358661:tid 358801] [client 117.210.135.0:62378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TMAlWhjQfpOo60_HrRQAAAAc"]
[Tue Jul 21 08:08:32.307907 2026] [security2:error] [pid 358661:tid 358801] [client 117.210.135.0:62378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TMAlWhjQfpOo60_HrRQAAAAc"]
[Tue Jul 21 08:08:32.619466 2026] [security2:error] [pid 358661:tid 358812] [client 193.36.225.61:27245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.225.36.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9TMAlWhjQfpOo60_HrSQAAABI"], referer: https://moldurasbrilhante.com.br/wp-login.php
[Tue Jul 21 08:08:32.732851 2026] [security2:error] [pid 358661:tid 358831] [client 87.116.180.198:13861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TMAlWhjQfpOo60_HrSwAAACU"]
[Tue Jul 21 08:08:32.732983 2026] [security2:error] [pid 358661:tid 358831] [client 87.116.180.198:13861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TMAlWhjQfpOo60_HrSwAAACU"]
[Tue Jul 21 08:08:32.751041 2026] [security2:error] [pid 352421:tid 352581] [client 20.226.60.151:12352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9TMMJSWzG9jbYOtu5bpQAAAKM"]
[Tue Jul 21 08:08:32.786766 2026] [autoindex:error] [pid 352421:tid 352636] [client 64.23.212.162:0] AH01276: Cannot serve directory /home2/jurand34/jurandirdasilvafigue1753473113000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:08:33.033932 2026] [security2:error] [pid 352421:tid 352490] [remote 49.42.211.30:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.211.42.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TMcJSWzG9jbYOtu5bqgAA-0Q"]
[Tue Jul 21 08:08:33.034074 2026] [security2:error] [pid 352421:tid 352669] [client 49.42.211.30:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TMcJSWzG9jbYOtu5bqgAA-0Q"]
[Tue Jul 21 08:08:33.126414 2026] [security2:error] [pid 358661:tid 358833] [client 20.226.60.151:56401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.mannucarvalho.com"] [uri "/zc-131.php"] [unique_id "al9TMQlWhjQfpOo60_HrVAAAACc"]
[Tue Jul 21 08:08:33.302950 2026] [security2:error] [pid 352421:tid 352629] [client 20.197.192.193:3101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/ez.php"] [unique_id "al9TMcJSWzG9jbYOtu5brgAAANM"]
[Tue Jul 21 08:08:33.322074 2026] [security2:error] [pid 358661:tid 358803] [client 162.219.176.3:44968] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9TMQlWhjQfpOo60_HrWAAAAAk"]
[Tue Jul 21 08:08:33.322181 2026] [security2:error] [pid 358661:tid 358803] [client 162.219.176.3:44968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9TMQlWhjQfpOo60_HrWAAAAAk"]
[Tue Jul 21 08:08:33.455686 2026] [security2:error] [pid 358661:tid 358842] [client 20.104.96.117:62578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-post-data.php"] [unique_id "al9TMQlWhjQfpOo60_HrWQAAADA"]
[Tue Jul 21 08:08:33.740432 2026] [security2:error] [pid 358661:tid 358918] [client 65.21.113.253:47850] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TMQlWhjQfpOo60_HrXQAAAHw"]
[Tue Jul 21 08:08:33.749909 2026] [security2:error] [pid 358661:tid 358874] [client 117.247.80.59:14825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TMQlWhjQfpOo60_HrXwAAAFA"]
[Tue Jul 21 08:08:33.750023 2026] [security2:error] [pid 358661:tid 358874] [client 117.247.80.59:14825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TMQlWhjQfpOo60_HrXwAAAFA"]
[Tue Jul 21 08:08:33.886408 2026] [security2:error] [pid 352421:tid 352674] [client 198.54.129.60:55632] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9TMMJSWzG9jbYOtu5bpAAAAQA"]
[Tue Jul 21 08:08:33.886506 2026] [security2:error] [pid 352421:tid 352674] [client 198.54.129.60:55632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9TMMJSWzG9jbYOtu5bpAAAAQA"]
[Tue Jul 21 08:08:34.136850 2026] [security2:error] [pid 358661:tid 358747] [remote 216.26.255.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.255.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TMAlWhjQfpOo60_HrUQAAb1I"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:34.252951 2026] [security2:error] [pid 358661:tid 358858] [client 162.219.176.3:56440] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9TMglWhjQfpOo60_HrYwAAAEA"]
[Tue Jul 21 08:08:34.253035 2026] [security2:error] [pid 358661:tid 358858] [client 162.219.176.3:56440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9TMglWhjQfpOo60_HrYwAAAEA"]
[Tue Jul 21 08:08:34.379761 2026] [security2:error] [pid 358661:tid 358849] [client 20.226.60.151:12015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/for.php"] [unique_id "al9TMglWhjQfpOo60_HrZQAAADc"]
[Tue Jul 21 08:08:34.457854 2026] [security2:error] [pid 358661:tid 358843] [client 185.236.20.134:30734] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9TMglWhjQfpOo60_HraQAAADE"]
[Tue Jul 21 08:08:34.505938 2026] [security2:error] [pid 352421:tid 352534] [remote 57.141.18.121:57162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9TMsJSWzG9jbYOtu5bwAAAunA"]
[Tue Jul 21 08:08:34.542049 2026] [security2:error] [pid 352421:tid 352578] [client 38.100.221.102:18105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TMsJSWzG9jbYOtu5bwwAAAKA"]
[Tue Jul 21 08:08:34.542158 2026] [security2:error] [pid 352421:tid 352578] [client 38.100.221.102:18105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TMsJSWzG9jbYOtu5bwwAAAKA"]
[Tue Jul 21 08:08:34.813590 2026] [security2:error] [pid 358661:tid 358863] [client 65.21.113.253:52170] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TMglWhjQfpOo60_HrZgAAAEU"]
[Tue Jul 21 08:08:35.138335 2026] [security2:error] [pid 358661:tid 358824] [client 65.21.113.253:52180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TMglWhjQfpOo60_HrbAAAAB4"]
[Tue Jul 21 08:08:35.401945 2026] [security2:error] [pid 358661:tid 358704] [remote 216.26.239.174:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.239.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TMwlWhjQfpOo60_HrcgAAXCc"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:35.479045 2026] [security2:error] [pid 352421:tid 352562] [client 20.226.60.151:12109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flangeforte.com.br"] [uri "/raw.php"] [unique_id "al9TM8JSWzG9jbYOtu5b0QAAAJA"]
[Tue Jul 21 08:08:35.489039 2026] [security2:error] [pid 352421:tid 352613] [client 86.106.84.166:35174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9TM8JSWzG9jbYOtu5b0gAAAMM"]
[Tue Jul 21 08:08:35.489111 2026] [security2:error] [pid 352421:tid 352613] [client 86.106.84.166:35174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9TM8JSWzG9jbYOtu5b0gAAAMM"]
[Tue Jul 21 08:08:35.556894 2026] [security2:error] [pid 358661:tid 358847] [client 86.106.84.166:35162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9TMwlWhjQfpOo60_HrdQAAADU"]
[Tue Jul 21 08:08:35.556993 2026] [security2:error] [pid 358661:tid 358847] [client 86.106.84.166:35162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9TMwlWhjQfpOo60_HrdQAAADU"]
[Tue Jul 21 08:08:35.579067 2026] [security2:error] [pid 352421:tid 352595] [client 20.29.126.15:7058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/byp.php"] [unique_id "al9TM8JSWzG9jbYOtu5b1AAAALE"]
[Tue Jul 21 08:08:35.852064 2026] [security2:error] [pid 352421:tid 352484] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TM8JSWzG9jbYOtu5b4AAAlD4"]
[Tue Jul 21 08:08:35.852201 2026] [security2:error] [pid 352421:tid 352566] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TM8JSWzG9jbYOtu5b4AAAlD4"]
[Tue Jul 21 08:08:36.022277 2026] [security2:error] [pid 352421:tid 352622] [client 172.232.181.176:20148] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "ns1102.hostgator.com.br"] [uri "/"] [unique_id "al9TNMJSWzG9jbYOtu5b4wAAAMw"]
[Tue Jul 21 08:08:36.405469 2026] [security2:error] [pid 352421:tid 352466] [remote 185.236.20.134:15412] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.essenceclinicadesaude.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9TNMJSWzG9jbYOtu5b6wAA6Cw"]
[Tue Jul 21 08:08:36.431939 2026] [security2:error] [pid 358661:tid 358784] [remote 209.50.177.153:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.177.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TNAlWhjQfpOo60_HrfAAAdXc"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:36.527559 2026] [security2:error] [pid 358661:tid 358853] [client 86.106.84.166:43198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9TNAlWhjQfpOo60_HrfgAAADs"]
[Tue Jul 21 08:08:36.527681 2026] [security2:error] [pid 358661:tid 358853] [client 86.106.84.166:43198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9TNAlWhjQfpOo60_HrfgAAADs"]
[Tue Jul 21 08:08:36.806346 2026] [security2:error] [pid 352421:tid 352614] [client 41.68.90.219:60535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TNMJSWzG9jbYOtu5b8QAAAMQ"]
[Tue Jul 21 08:08:36.806538 2026] [security2:error] [pid 352421:tid 352614] [client 41.68.90.219:60535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TNMJSWzG9jbYOtu5b8QAAAMQ"]
[Tue Jul 21 08:08:37.384285 2026] [security2:error] [pid 352421:tid 352587] [client 20.104.96.117:62591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/pucci.php"] [unique_id "al9TNcJSWzG9jbYOtu5b-QAAAKk"]
[Tue Jul 21 08:08:37.463858 2026] [security2:error] [pid 352421:tid 352621] [client 175.144.82.48:59667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TNcJSWzG9jbYOtu5b_gAAAMs"]
[Tue Jul 21 08:08:37.464638 2026] [security2:error] [pid 352421:tid 352621] [client 175.144.82.48:59667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TNcJSWzG9jbYOtu5b_gAAAMs"]
[Tue Jul 21 08:08:38.064209 2026] [security2:error] [pid 358661:tid 358744] [remote 216.26.244.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.244.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TNQlWhjQfpOo60_HrjgAAYU8"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:38.806372 2026] [security2:error] [pid 358661:tid 358775] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TNglWhjQfpOo60_HrmwAAV24"]
[Tue Jul 21 08:08:38.806517 2026] [security2:error] [pid 358661:tid 358881] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TNglWhjQfpOo60_HrmwAAV24"]
[Tue Jul 21 08:08:38.833589 2026] [security2:error] [pid 358661:tid 358868] [client 65.21.113.253:52180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TNglWhjQfpOo60_HrmgAAAEo"]
[Tue Jul 21 08:08:38.855053 2026] [security2:error] [pid 352421:tid 352468] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TNsJSWzG9jbYOtu5cEAAA8i4"]
[Tue Jul 21 08:08:38.855236 2026] [security2:error] [pid 352421:tid 352660] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TNsJSWzG9jbYOtu5cEAAA8i4"]
[Tue Jul 21 08:08:39.034833 2026] [security2:error] [pid 358661:tid 358864] [client 120.56.162.40:61190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TNwlWhjQfpOo60_HrnwAAAEY"]
[Tue Jul 21 08:08:39.034962 2026] [security2:error] [pid 358661:tid 358864] [client 120.56.162.40:61190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TNwlWhjQfpOo60_HrnwAAAEY"]
[Tue Jul 21 08:08:39.080459 2026] [security2:error] [pid 358661:tid 358850] [client 109.60.28.94:14479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TNwlWhjQfpOo60_HroQAAADg"]
[Tue Jul 21 08:08:39.081216 2026] [security2:error] [pid 358661:tid 358850] [client 109.60.28.94:14479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TNwlWhjQfpOo60_HroQAAADg"]
[Tue Jul 21 08:08:39.146997 2026] [security2:error] [pid 352421:tid 352536] [remote 65.111.6.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.6.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TN8JSWzG9jbYOtu5cGAAA_XI"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:39.173442 2026] [security2:error] [pid 358661:tid 358813] [client 103.166.103.129:32847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TNwlWhjQfpOo60_HrogAAABM"]
[Tue Jul 21 08:08:39.226395 2026] [security2:error] [pid 358661:tid 358871] [client 102.206.115.33:60028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TNwlWhjQfpOo60_HrowAAAE0"]
[Tue Jul 21 08:08:39.228209 2026] [security2:error] [pid 358661:tid 358871] [client 102.206.115.33:60028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TNwlWhjQfpOo60_HrowAAAE0"]
[Tue Jul 21 08:08:39.241447 2026] [security2:error] [pid 358661:tid 358813] [client 103.166.103.129:32847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TNwlWhjQfpOo60_HrogAAABM"]
[Tue Jul 21 08:08:39.391130 2026] [security2:error] [pid 352421:tid 352495] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TN8JSWzG9jbYOtu5cHAAAxUk"]
[Tue Jul 21 08:08:39.391280 2026] [security2:error] [pid 352421:tid 352615] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TN8JSWzG9jbYOtu5cHAAAxUk"]
[Tue Jul 21 08:08:39.433887 2026] [security2:error] [pid 358661:tid 358831] [client 20.104.96.117:62493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/black.php"] [unique_id "al9TNwlWhjQfpOo60_HrpQAAACU"]
[Tue Jul 21 08:08:39.545185 2026] [security2:error] [pid 358661:tid 358903] [client 20.29.126.15:2316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/date.php"] [unique_id "al9TNwlWhjQfpOo60_HrpgAAAG0"]
[Tue Jul 21 08:08:39.673674 2026] [security2:error] [pid 352421:tid 352652] [client 86.106.84.166:35190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9TN8JSWzG9jbYOtu5cHwAAAOo"]
[Tue Jul 21 08:08:39.673772 2026] [security2:error] [pid 352421:tid 352652] [client 86.106.84.166:35190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9TN8JSWzG9jbYOtu5cHwAAAOo"]
[Tue Jul 21 08:08:39.956180 2026] [security2:error] [pid 358661:tid 358896] [client 150.129.202.39:65150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TNwlWhjQfpOo60_HrrQAAAGY"]
[Tue Jul 21 08:08:39.956360 2026] [security2:error] [pid 358661:tid 358896] [client 150.129.202.39:65150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TNwlWhjQfpOo60_HrrQAAAGY"]
[Tue Jul 21 08:08:40.460443 2026] [security2:error] [pid 358661:tid 358687] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TOAlWhjQfpOo60_HrsQAAZBY"]
[Tue Jul 21 08:08:40.460648 2026] [security2:error] [pid 358661:tid 358894] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TOAlWhjQfpOo60_HrsQAAZBY"]
[Tue Jul 21 08:08:40.574488 2026] [security2:error] [pid 358661:tid 358821] [client 20.29.126.15:7088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/pomo.php"] [unique_id "al9TOAlWhjQfpOo60_HrswAAABs"]
[Tue Jul 21 08:08:40.665076 2026] [security2:error] [pid 358661:tid 358708] [remote 91.142.222.105:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TOAlWhjQfpOo60_HrtQAAMCs"]
[Tue Jul 21 08:08:40.665075 2026] [security2:error] [pid 358661:tid 358780] [remote 65.111.24.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TOAlWhjQfpOo60_HrtgAALHM"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:40.665260 2026] [security2:error] [pid 358661:tid 358842] [client 91.142.222.105:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TOAlWhjQfpOo60_HrtQAAMCs"]
[Tue Jul 21 08:08:40.926990 2026] [security2:error] [pid 358661:tid 358703] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TOAlWhjQfpOo60_HruQAABCY"]
[Tue Jul 21 08:08:40.927221 2026] [security2:error] [pid 358661:tid 358798] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TOAlWhjQfpOo60_HruQAABCY"]
[Tue Jul 21 08:08:41.170147 2026] [security2:error] [pid 358661:tid 358905] [client 20.104.96.117:62499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/zlece.php"] [unique_id "al9TOQlWhjQfpOo60_HrvQAAAG8"]
[Tue Jul 21 08:08:41.241506 2026] [security2:error] [pid 358661:tid 358887] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TOQlWhjQfpOo60_HrvAAAXTM"]
[Tue Jul 21 08:08:41.747897 2026] [security2:error] [pid 352421:tid 352657] [client 178.153.91.96:55149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TOcJSWzG9jbYOtu5cPQAAAO8"]
[Tue Jul 21 08:08:41.748065 2026] [security2:error] [pid 352421:tid 352657] [client 178.153.91.96:55149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TOcJSWzG9jbYOtu5cPQAAAO8"]
[Tue Jul 21 08:08:42.183226 2026] [security2:error] [pid 358661:tid 358863] [client 103.78.200.11:54293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TOglWhjQfpOo60_HrygAAAEU"]
[Tue Jul 21 08:08:42.183358 2026] [security2:error] [pid 358661:tid 358863] [client 103.78.200.11:54293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TOglWhjQfpOo60_HrygAAAEU"]
[Tue Jul 21 08:08:42.228726 2026] [security2:error] [pid 358661:tid 358765] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TOglWhjQfpOo60_HrzAAAOGQ"]
[Tue Jul 21 08:08:42.228867 2026] [security2:error] [pid 358661:tid 358850] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TOglWhjQfpOo60_HrzAAAOGQ"]
[Tue Jul 21 08:08:42.300367 2026] [security2:error] [pid 352421:tid 352608] [client 175.144.82.48:60146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TOsJSWzG9jbYOtu5cRwAAAL4"]
[Tue Jul 21 08:08:42.301473 2026] [security2:error] [pid 358661:tid 358806] [client 65.21.113.253:34656] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TOglWhjQfpOo60_HrzQAAAAw"]
[Tue Jul 21 08:08:42.301487 2026] [security2:error] [pid 352421:tid 352608] [client 175.144.82.48:60146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TOsJSWzG9jbYOtu5cRwAAAL4"]
[Tue Jul 21 08:08:42.379344 2026] [security2:error] [pid 352421:tid 352425] [remote 216.26.246.183:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.246.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TOsJSWzG9jbYOtu5cRQAAmgM"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:42.527965 2026] [security2:error] [pid 358661:tid 358740] [remote 159.65.81.207:43878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrsolar.org.br"] [uri "/wp-login.php"] [unique_id "al9TOQlWhjQfpOo60_HrxAAAQEs"]
[Tue Jul 21 08:08:42.897435 2026] [security2:error] [pid 352421:tid 352603] [client 117.210.135.0:63028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TOsJSWzG9jbYOtu5cUgAAALk"]
[Tue Jul 21 08:08:42.897578 2026] [security2:error] [pid 352421:tid 352603] [client 117.210.135.0:63028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TOsJSWzG9jbYOtu5cUgAAALk"]
[Tue Jul 21 08:08:42.935447 2026] [security2:error] [pid 358661:tid 358839] [client 65.21.113.253:52180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TOglWhjQfpOo60_Hr0gAAAC0"]
[Tue Jul 21 08:08:43.040669 2026] [security2:error] [pid 352421:tid 352669] [client 20.29.126.15:15354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/test1.php"] [unique_id "al9TO8JSWzG9jbYOtu5cVQAAAPs"]
[Tue Jul 21 08:08:43.144501 2026] [security2:error] [pid 358661:tid 358814] [client 103.29.114.44:2525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TOwlWhjQfpOo60_Hr0wAAABQ"]
[Tue Jul 21 08:08:43.144641 2026] [security2:error] [pid 358661:tid 358814] [client 103.29.114.44:2525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TOwlWhjQfpOo60_Hr0wAAABQ"]
[Tue Jul 21 08:08:43.483319 2026] [security2:error] [pid 358661:tid 358731] [remote 45.3.46.80:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.46.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TOwlWhjQfpOo60_Hr1wAAWUI"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:43.508465 2026] [security2:error] [pid 358661:tid 358823] [client 87.116.180.198:27171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TOwlWhjQfpOo60_Hr2AAAAB0"]
[Tue Jul 21 08:08:43.511141 2026] [security2:error] [pid 358661:tid 358823] [client 87.116.180.198:27171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TOwlWhjQfpOo60_Hr2AAAAB0"]
[Tue Jul 21 08:08:43.528251 2026] [security2:error] [pid 358661:tid 358782] [remote 45.79.123.44:50486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moneyclass.com.br"] [uri "/wp-login.php"] [unique_id "al9TOwlWhjQfpOo60_Hr2QAAdXU"]
[Tue Jul 21 08:08:43.925789 2026] [security2:error] [pid 358661:tid 358914] [client 162.219.176.3:40542] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9TOwlWhjQfpOo60_Hr4QAAAHg"]
[Tue Jul 21 08:08:43.925909 2026] [security2:error] [pid 358661:tid 358914] [client 162.219.176.3:40542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9TOwlWhjQfpOo60_Hr4QAAAHg"]
[Tue Jul 21 08:08:44.252662 2026] [security2:error] [pid 358661:tid 358878] [client 61.1.167.83:57321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TPAlWhjQfpOo60_Hr5wAAAFQ"]
[Tue Jul 21 08:08:44.252788 2026] [security2:error] [pid 358661:tid 358878] [client 61.1.167.83:57321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TPAlWhjQfpOo60_Hr5wAAAFQ"]
[Tue Jul 21 08:08:44.341271 2026] [security2:error] [pid 352421:tid 352633] [client 117.247.80.59:16213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TPMJSWzG9jbYOtu5cZgAAANc"]
[Tue Jul 21 08:08:44.341440 2026] [security2:error] [pid 352421:tid 352633] [client 117.247.80.59:16213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TPMJSWzG9jbYOtu5cZgAAANc"]
[Tue Jul 21 08:08:44.660339 2026] [security2:error] [pid 358661:tid 358694] [remote 104.207.32.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.32.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TPAlWhjQfpOo60_Hr7gAAZx0"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:44.666219 2026] [security2:error] [pid 352421:tid 352666] [client 20.197.192.193:64482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/fz.php"] [unique_id "al9TPMJSWzG9jbYOtu5cbAAAAPg"]
[Tue Jul 21 08:08:44.852163 2026] [security2:error] [pid 358661:tid 358811] [client 65.21.113.253:34656] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TPAlWhjQfpOo60_Hr9gAAABE"]
[Tue Jul 21 08:08:44.929718 2026] [security2:error] [pid 358661:tid 358798] [client 65.21.113.253:55354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TPAlWhjQfpOo60_Hr7QAAAAQ"]
[Tue Jul 21 08:08:45.235292 2026] [security2:error] [pid 358661:tid 358887] [client 38.100.221.102:18126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TPQlWhjQfpOo60_Hr-wAAAF0"]
[Tue Jul 21 08:08:45.235441 2026] [security2:error] [pid 358661:tid 358887] [client 38.100.221.102:18126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TPQlWhjQfpOo60_Hr-wAAAF0"]
[Tue Jul 21 08:08:45.477142 2026] [security2:error] [pid 352421:tid 352657] [client 20.104.96.117:63441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/vssrs.php"] [unique_id "al9TPcJSWzG9jbYOtu5cegAAAO8"]
[Tue Jul 21 08:08:45.731755 2026] [security2:error] [pid 358661:tid 358851] [client 20.29.126.15:15298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/fw.php"] [unique_id "al9TPQlWhjQfpOo60_HsBwAAADk"]
[Tue Jul 21 08:08:45.878733 2026] [security2:error] [pid 358661:tid 358673] [remote 216.26.237.177:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.237.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TPQlWhjQfpOo60_HsBgAASgg"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:45.897970 2026] [security2:error] [pid 358661:tid 358819] [client 65.21.113.253:55368] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TPQlWhjQfpOo60_HsBQAAABk"]
[Tue Jul 21 08:08:46.855293 2026] [security2:error] [pid 352421:tid 352533] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TPsJSWzG9jbYOtu5ckAAAsW8"]
[Tue Jul 21 08:08:46.855462 2026] [security2:error] [pid 352421:tid 352595] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TPsJSWzG9jbYOtu5ckAAAsW8"]
[Tue Jul 21 08:08:47.030407 2026] [security2:error] [pid 358661:tid 358877] [client 74.7.244.36:45108] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.buy-officialsite.pedido-online.net"] [uri "/index.php"] [unique_id "al9TPglWhjQfpOo60_HsFgAAU0g"]
[Tue Jul 21 08:08:47.422416 2026] [security2:error] [pid 352421:tid 352670] [client 41.68.90.219:61003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TP8JSWzG9jbYOtu5cnAAAAPw"]
[Tue Jul 21 08:08:47.423151 2026] [security2:error] [pid 352421:tid 352670] [client 41.68.90.219:61003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TP8JSWzG9jbYOtu5cnAAAAPw"]
[Tue Jul 21 08:08:47.568026 2026] [security2:error] [pid 352421:tid 352611] [client 78.47.98.55:31762] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9TP8JSWzG9jbYOtu5coAAAAME"], referer: https://artetoner.com.br
[Tue Jul 21 08:08:47.605207 2026] [security2:error] [pid 358661:tid 358832] [client 45.146.55.189:63049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lumerah.com.br"] [uri "/wp-login.php"] [unique_id "al9TPwlWhjQfpOo60_HsIQAAACY"]
[Tue Jul 21 08:08:47.630530 2026] [security2:error] [pid 358661:tid 358813] [client 162.219.176.3:45216] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9TPwlWhjQfpOo60_HsIgAAABM"]
[Tue Jul 21 08:08:47.630642 2026] [security2:error] [pid 358661:tid 358813] [client 162.219.176.3:45216] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9TPwlWhjQfpOo60_HsIgAAABM"]
[Tue Jul 21 08:08:47.630672 2026] [security2:error] [pid 358661:tid 358813] [client 162.219.176.3:45216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9TPwlWhjQfpOo60_HsIgAAABM"]
[Tue Jul 21 08:08:48.016806 2026] [security2:error] [pid 352421:tid 352640] [client 34.182.139.74:57204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "deals-ecomm.shop.oficialwebsite.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9TQMJSWzG9jbYOtu5cqAAAAN4"]
[Tue Jul 21 08:08:48.569113 2026] [security2:error] [pid 352421:tid 352460] [remote 217.181.91.80:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.91.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TP8JSWzG9jbYOtu5cmwAA9SY"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:48.589338 2026] [security2:error] [pid 358661:tid 358814] [client 34.182.139.74:50108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.139.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deals-ecomm.shop.oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQAlWhjQfpOo60_HsLgAAABQ"]
[Tue Jul 21 08:08:48.724972 2026] [security2:error] [pid 358661:tid 358810] [client 65.21.113.253:34656] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TQAlWhjQfpOo60_HsMgAAABA"]
[Tue Jul 21 08:08:48.798727 2026] [security2:error] [pid 358661:tid 358911] [client 62.102.148.158:55056] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9TQAlWhjQfpOo60_HsMQAAAHU"]
[Tue Jul 21 08:08:48.798859 2026] [security2:error] [pid 358661:tid 358911] [client 62.102.148.158:55056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9TQAlWhjQfpOo60_HsMQAAAHU"]
[Tue Jul 21 08:08:49.055198 2026] [security2:error] [pid 352421:tid 352638] [client 20.29.126.15:15326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/fm.php"] [unique_id "al9TQcJSWzG9jbYOtu5ctwAAANw"]
[Tue Jul 21 08:08:49.201534 2026] [security2:error] [pid 358661:tid 358867] [client 65.21.113.253:55354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TQAlWhjQfpOo60_HsMwAAAEk"]
[Tue Jul 21 08:08:49.425533 2026] [security2:error] [pid 352421:tid 352449] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TQcJSWzG9jbYOtu5cvwAAsxs"]
[Tue Jul 21 08:08:49.425784 2026] [security2:error] [pid 352421:tid 352597] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TQcJSWzG9jbYOtu5cvwAAsxs"]
[Tue Jul 21 08:08:49.435485 2026] [security2:error] [pid 358661:tid 358825] [client 102.206.115.33:64968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TQQlWhjQfpOo60_HsPAAAAB8"]
[Tue Jul 21 08:08:49.435588 2026] [security2:error] [pid 358661:tid 358825] [client 102.206.115.33:64968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TQQlWhjQfpOo60_HsPAAAAB8"]
[Tue Jul 21 08:08:49.686879 2026] [security2:error] [pid 358661:tid 358838] [client 103.166.103.129:33429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TQQlWhjQfpOo60_HsUQAAACw"]
[Tue Jul 21 08:08:49.687030 2026] [security2:error] [pid 358661:tid 358838] [client 103.166.103.129:33429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TQQlWhjQfpOo60_HsUQAAACw"]
[Tue Jul 21 08:08:49.717419 2026] [security2:error] [pid 358661:tid 358908] [client 120.56.162.40:61672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQQlWhjQfpOo60_HsUgAAAHI"]
[Tue Jul 21 08:08:49.717545 2026] [security2:error] [pid 358661:tid 358908] [client 120.56.162.40:61672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQQlWhjQfpOo60_HsUgAAAHI"]
[Tue Jul 21 08:08:49.819503 2026] [security2:error] [pid 358661:tid 358842] [client 65.21.113.253:36386] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TQQlWhjQfpOo60_HsOgAAADA"]
[Tue Jul 21 08:08:49.822210 2026] [security2:error] [pid 352421:tid 352479] [remote 65.111.15.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TQcJSWzG9jbYOtu5cxQAAoTk"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:49.834806 2026] [security2:error] [pid 358661:tid 358665] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQQlWhjQfpOo60_HsbQAAFQA"]
[Tue Jul 21 08:08:49.835019 2026] [security2:error] [pid 358661:tid 358815] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQQlWhjQfpOo60_HsbQAAFQA"]
[Tue Jul 21 08:08:49.840491 2026] [security2:error] [pid 358661:tid 358904] [client 109.60.28.94:56024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQQlWhjQfpOo60_HsbgAAAG4"]
[Tue Jul 21 08:08:49.840626 2026] [security2:error] [pid 358661:tid 358904] [client 109.60.28.94:56024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQQlWhjQfpOo60_HsbgAAAG4"]
[Tue Jul 21 08:08:50.266295 2026] [security2:error] [pid 352421:tid 352629] [client 62.102.148.158:55072] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9TQsJSWzG9jbYOtu5czgAAANM"]
[Tue Jul 21 08:08:50.266396 2026] [security2:error] [pid 352421:tid 352629] [client 62.102.148.158:55072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9TQsJSWzG9jbYOtu5czgAAANM"]
[Tue Jul 21 08:08:50.533757 2026] [security2:error] [pid 352421:tid 352527] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQsJSWzG9jbYOtu5c1gAAxWk"]
[Tue Jul 21 08:08:50.533901 2026] [security2:error] [pid 352421:tid 352615] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQsJSWzG9jbYOtu5c1gAAxWk"]
[Tue Jul 21 08:08:50.634014 2026] [security2:error] [pid 352421:tid 352660] [client 150.129.202.39:65193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQsJSWzG9jbYOtu5c2QAAAPI"]
[Tue Jul 21 08:08:50.634134 2026] [security2:error] [pid 352421:tid 352660] [client 150.129.202.39:65193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQsJSWzG9jbYOtu5c2QAAAPI"]
[Tue Jul 21 08:08:50.740850 2026] [security2:error] [pid 352421:tid 352677] [client 20.104.96.117:57946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9TQsJSWzG9jbYOtu5c3gAAAQM"]
[Tue Jul 21 08:08:50.956682 2026] [security2:error] [pid 352421:tid 352614] [client 35.221.29.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.29.221.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQsJSWzG9jbYOtu5c4wAAAMQ"]
[Tue Jul 21 08:08:50.958969 2026] [security2:error] [pid 352421:tid 352567] [client 34.182.139.74:59569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.139.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deals-ecomm.shop.oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQsJSWzG9jbYOtu5c5AAAAJU"]
[Tue Jul 21 08:08:50.959061 2026] [security2:error] [pid 352421:tid 352567] [client 34.182.139.74:59569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "deals-ecomm.shop.oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQsJSWzG9jbYOtu5c5AAAAJU"]
[Tue Jul 21 08:08:50.982467 2026] [security2:error] [pid 352421:tid 352515] [remote 209.50.160.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.160.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TQsJSWzG9jbYOtu5c4QAAwF0"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:51.028499 2026] [security2:error] [pid 358661:tid 358807] [client 35.221.29.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.29.221.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TQwlWhjQfpOo60_HsfQAAAA0"]
[Tue Jul 21 08:08:51.057864 2026] [security2:error] [pid 358661:tid 358722] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TQwlWhjQfpOo60_HsfwAALTk"]
[Tue Jul 21 08:08:51.058019 2026] [security2:error] [pid 358661:tid 358839] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TQwlWhjQfpOo60_HsfwAALTk"]
[Tue Jul 21 08:08:51.220340 2026] [security2:error] [pid 358661:tid 358834] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9TQwlWhjQfpOo60_HsjQAAACg"]
[Tue Jul 21 08:08:51.383432 2026] [security2:error] [pid 358661:tid 358911] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9TQwlWhjQfpOo60_HskgAAAHU"]
[Tue Jul 21 08:08:51.396049 2026] [security2:error] [pid 352421:tid 352536] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TQ8JSWzG9jbYOtu5c7QAA4nI"]
[Tue Jul 21 08:08:51.396191 2026] [security2:error] [pid 352421:tid 352644] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TQ8JSWzG9jbYOtu5c7QAA4nI"]
[Tue Jul 21 08:08:51.472119 2026] [security2:error] [pid 358661:tid 358821] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9TQwlWhjQfpOo60_HskwAAABs"]
[Tue Jul 21 08:08:51.647132 2026] [security2:error] [pid 358661:tid 358889] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9TQwlWhjQfpOo60_HslwAAAF8"]
[Tue Jul 21 08:08:51.779871 2026] [security2:error] [pid 358661:tid 358860] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9TQwlWhjQfpOo60_HsmQAAAEI"]
[Tue Jul 21 08:08:51.806496 2026] [security2:error] [pid 358661:tid 358878] [client 20.104.96.117:62521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wicked.php"] [unique_id "al9TQwlWhjQfpOo60_HsmgAAAFQ"]
[Tue Jul 21 08:08:51.895560 2026] [security2:error] [pid 358661:tid 358874] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9TQwlWhjQfpOo60_HsnQAAAFA"]
[Tue Jul 21 08:08:51.962836 2026] [security2:error] [pid 358661:tid 358867] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TQwlWhjQfpOo60_HsmAAASVY"]
[Tue Jul 21 08:08:52.025097 2026] [security2:error] [pid 358661:tid 358897] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9TRAlWhjQfpOo60_HsoQAAAGc"]
[Tue Jul 21 08:08:52.129295 2026] [security2:error] [pid 358661:tid 358906] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9TRAlWhjQfpOo60_HspQAAAHA"]
[Tue Jul 21 08:08:52.177298 2026] [security2:error] [pid 358661:tid 358746] [remote 45.3.48.118:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.48.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TRAlWhjQfpOo60_HsoAAAMVE"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:52.234480 2026] [security2:error] [pid 358661:tid 358913] [client 178.153.91.96:56342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TRAlWhjQfpOo60_HsqgAAAHc"]
[Tue Jul 21 08:08:52.234599 2026] [security2:error] [pid 358661:tid 358913] [client 178.153.91.96:56342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TRAlWhjQfpOo60_HsqgAAAHc"]
[Tue Jul 21 08:08:52.361213 2026] [security2:error] [pid 358661:tid 358893] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9TRAlWhjQfpOo60_HsqwAAAGM"]
[Tue Jul 21 08:08:52.385806 2026] [security2:error] [pid 352421:tid 352588] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9TRMJSWzG9jbYOtu5c-gAAAKo"]
[Tue Jul 21 08:08:52.607897 2026] [security2:error] [pid 358661:tid 358850] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9TRAlWhjQfpOo60_HsrwAAADg"]
[Tue Jul 21 08:08:52.683950 2026] [security2:error] [pid 358661:tid 358866] [client 65.21.113.253:55354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TRAlWhjQfpOo60_HsqQAAAEg"]
[Tue Jul 21 08:08:52.698086 2026] [security2:error] [pid 358661:tid 358886] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9TRAlWhjQfpOo60_HsswAAAFw"]
[Tue Jul 21 08:08:52.790727 2026] [security2:error] [pid 358661:tid 358745] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TRAlWhjQfpOo60_HstQAAaFA"]
[Tue Jul 21 08:08:52.790898 2026] [security2:error] [pid 358661:tid 358898] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TRAlWhjQfpOo60_HstQAAaFA"]
[Tue Jul 21 08:08:52.801343 2026] [security2:error] [pid 358661:tid 358846] [client 175.144.82.48:60610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TRAlWhjQfpOo60_HstgAAADQ"]
[Tue Jul 21 08:08:52.802174 2026] [security2:error] [pid 358661:tid 358846] [client 175.144.82.48:60610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TRAlWhjQfpOo60_HstgAAADQ"]
[Tue Jul 21 08:08:52.814533 2026] [security2:error] [pid 358661:tid 358833] [client 103.78.200.11:54780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TRAlWhjQfpOo60_HsuAAAACc"]
[Tue Jul 21 08:08:52.814668 2026] [security2:error] [pid 358661:tid 358833] [client 103.78.200.11:54780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TRAlWhjQfpOo60_HsuAAAACc"]
[Tue Jul 21 08:08:52.863345 2026] [security2:error] [pid 358661:tid 358835] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9TRAlWhjQfpOo60_HsugAAACk"]
[Tue Jul 21 08:08:52.983647 2026] [security2:error] [pid 358661:tid 358824] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9TRAlWhjQfpOo60_HsvAAAAB4"]
[Tue Jul 21 08:08:53.111526 2026] [security2:error] [pid 358661:tid 358861] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9TRQlWhjQfpOo60_HsvwAAAEM"]
[Tue Jul 21 08:08:53.256368 2026] [security2:error] [pid 352421:tid 352620] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9TRcJSWzG9jbYOtu5dDAAAAMo"]
[Tue Jul 21 08:08:53.356180 2026] [security2:error] [pid 352421:tid 352555] [client 62.102.148.158:55074] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9TRcJSWzG9jbYOtu5dDgAAAIk"]
[Tue Jul 21 08:08:53.356279 2026] [security2:error] [pid 352421:tid 352555] [client 62.102.148.158:55074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9TRcJSWzG9jbYOtu5dDgAAAIk"]
[Tue Jul 21 08:08:53.382852 2026] [security2:error] [pid 352421:tid 352568] [client 20.197.192.193:64470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/wpx.php"] [unique_id "al9TRcJSWzG9jbYOtu5dDwAAAJY"]
[Tue Jul 21 08:08:53.405871 2026] [security2:error] [pid 358661:tid 358859] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9TRQlWhjQfpOo60_HsxQAAAEE"]
[Tue Jul 21 08:08:53.433156 2026] [security2:error] [pid 352421:tid 352637] [client 117.210.135.0:63673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TRcJSWzG9jbYOtu5dEQAAANs"]
[Tue Jul 21 08:08:53.441147 2026] [autoindex:error] [pid 358661:tid 358812] [client 74.7.242.44:35742] AH01276: Cannot serve directory /home2/reser379/megaroteiros.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.themumbai.in
[Tue Jul 21 08:08:53.552973 2026] [security2:error] [pid 358661:tid 358868] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9TRQlWhjQfpOo60_HsyAAAAEo"]
[Tue Jul 21 08:08:53.650502 2026] [security2:error] [pid 358661:tid 358810] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9TRQlWhjQfpOo60_HsygAAABA"]
[Tue Jul 21 08:08:53.662507 2026] [security2:error] [pid 358661:tid 358819] [client 20.197.192.193:3485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/berlin.php"] [unique_id "al9TRQlWhjQfpOo60_HsywAAABk"]
[Tue Jul 21 08:08:53.860373 2026] [security2:error] [pid 358661:tid 358914] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9TRQlWhjQfpOo60_HszQAAAHg"]
[Tue Jul 21 08:08:53.889939 2026] [security2:error] [pid 358661:tid 358918] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9TRQlWhjQfpOo60_HszwAAAHw"]
[Tue Jul 21 08:08:53.896132 2026] [security2:error] [pid 352421:tid 352454] [remote 65.111.26.1:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TRcJSWzG9jbYOtu5dFQAA5yA"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:54.064512 2026] [security2:error] [pid 352421:tid 352640] [client 20.29.126.15:6375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/ini.php"] [unique_id "al9TRsJSWzG9jbYOtu5dGgAAAN4"]
[Tue Jul 21 08:08:54.067204 2026] [security2:error] [pid 352421:tid 352614] [client 20.197.192.193:3089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/billur.php"] [unique_id "al9TRsJSWzG9jbYOtu5dGwAAAMQ"]
[Tue Jul 21 08:08:54.201156 2026] [security2:error] [pid 352421:tid 352670] [client 87.116.180.198:27311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TRsJSWzG9jbYOtu5dHQAAAPw"]
[Tue Jul 21 08:08:54.201306 2026] [security2:error] [pid 352421:tid 352670] [client 87.116.180.198:27311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TRsJSWzG9jbYOtu5dHQAAAPw"]
[Tue Jul 21 08:08:54.253581 2026] [security2:error] [pid 358661:tid 358867] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9TRglWhjQfpOo60_Hs1AAAAEk"]
[Tue Jul 21 08:08:54.255080 2026] [security2:error] [pid 358661:tid 358916] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9TRglWhjQfpOo60_Hs1QAAAHo"]
[Tue Jul 21 08:08:54.558190 2026] [security2:error] [pid 358661:tid 358908] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9TRglWhjQfpOo60_Hs2wAAAHI"]
[Tue Jul 21 08:08:54.590345 2026] [security2:error] [pid 352421:tid 352637] [client 117.210.135.0:63673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TRcJSWzG9jbYOtu5dEQAAANs"]
[Tue Jul 21 08:08:54.828773 2026] [security2:error] [pid 358661:tid 358780] [remote 72.167.132.114:38766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cezadvogados.com"] [uri "/wp-login.php"] [unique_id "al9TRglWhjQfpOo60_Hs3gAAMXM"]
[Tue Jul 21 08:08:55.598075 2026] [security2:error] [pid 358661:tid 358871] [client 65.21.113.253:55354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TRwlWhjQfpOo60_Hs4AAAAE0"]
[Tue Jul 21 08:08:55.770680 2026] [security2:error] [pid 358661:tid 358844] [client 38.100.221.102:18790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TRwlWhjQfpOo60_Hs6wAAADI"]
[Tue Jul 21 08:08:55.770969 2026] [security2:error] [pid 358661:tid 358844] [client 38.100.221.102:18790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TRwlWhjQfpOo60_Hs6wAAADI"]
[Tue Jul 21 08:08:55.867571 2026] [security2:error] [pid 358661:tid 358899] [client 103.29.114.44:20476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TRwlWhjQfpOo60_Hs7QAAAGk"]
[Tue Jul 21 08:08:55.867723 2026] [security2:error] [pid 358661:tid 358899] [client 103.29.114.44:20476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TRwlWhjQfpOo60_Hs7QAAAGk"]
[Tue Jul 21 08:08:55.891766 2026] [security2:error] [pid 352421:tid 352551] [client 20.104.96.117:58380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9TR8JSWzG9jbYOtu5ddQAAAIU"]
[Tue Jul 21 08:08:56.124231 2026] [security2:error] [pid 358661:tid 358862] [client 20.29.126.15:15334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/themes.php"] [unique_id "al9TSAlWhjQfpOo60_Hs8gAAAEQ"]
[Tue Jul 21 08:08:56.213899 2026] [security2:error] [pid 352421:tid 352524] [remote 209.50.160.102:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.160.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TR8JSWzG9jbYOtu5dXQAA42Y"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:56.223301 2026] [security2:error] [pid 352421:tid 352671] [client 198.54.129.60:40650] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9TSMJSWzG9jbYOtu5dgAAAAP0"]
[Tue Jul 21 08:08:56.223398 2026] [security2:error] [pid 352421:tid 352671] [client 198.54.129.60:40650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9TSMJSWzG9jbYOtu5dgAAAAP0"]
[Tue Jul 21 08:08:56.327055 2026] [security2:error] [pid 358661:tid 358853] [client 62.102.148.158:55088] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9TSAlWhjQfpOo60_Hs-AAAADs"]
[Tue Jul 21 08:08:56.327143 2026] [security2:error] [pid 358661:tid 358853] [client 62.102.148.158:55088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9TSAlWhjQfpOo60_Hs-AAAADs"]
[Tue Jul 21 08:08:56.732535 2026] [security2:error] [pid 352421:tid 352614] [client 20.220.225.223:1818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9TSMJSWzG9jbYOtu5dhgAAAMQ"]
[Tue Jul 21 08:08:56.947117 2026] [security2:error] [pid 358661:tid 358840] [client 65.21.113.253:36168] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TSAlWhjQfpOo60_HtBAAAAC4"]
[Tue Jul 21 08:08:57.221283 2026] [security2:error] [pid 358661:tid 358897] [client 34.34.186.87:64966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "triaxion.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9TSQlWhjQfpOo60_HtCAAAAGc"]
[Tue Jul 21 08:08:57.313932 2026] [security2:error] [pid 352421:tid 352641] [client 159.65.243.120:62431] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.dorathiotoadvogados.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9TScJSWzG9jbYOtu5dkQAAAN8"]
[Tue Jul 21 08:08:57.564899 2026] [security2:error] [pid 358661:tid 358893] [client 65.21.113.253:55354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TSQlWhjQfpOo60_HtBgAAAGM"]
[Tue Jul 21 08:08:57.787057 2026] [security2:error] [pid 352421:tid 352644] [client 159.65.243.120:51198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.243.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.dorathiotoadvogados.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TScJSWzG9jbYOtu5dmQAAAOI"]
[Tue Jul 21 08:08:57.790746 2026] [security2:error] [pid 358661:tid 358912] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TSAlWhjQfpOo60_HtAQAAdjo"]
[Tue Jul 21 08:08:57.902681 2026] [security2:error] [pid 352421:tid 352515] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TScJSWzG9jbYOtu5dmgAAu10"]
[Tue Jul 21 08:08:57.902828 2026] [security2:error] [pid 352421:tid 352605] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TScJSWzG9jbYOtu5dmgAAu10"]
[Tue Jul 21 08:08:57.930580 2026] [security2:error] [pid 352421:tid 352638] [client 20.197.192.193:64509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/la.php"] [unique_id "al9TScJSWzG9jbYOtu5dnQAAANw"]
[Tue Jul 21 08:08:58.196679 2026] [security2:error] [pid 358661:tid 358740] [remote 65.111.1.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.1.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TSQlWhjQfpOo60_HtBwAAd0s"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:58.420828 2026] [security2:error] [pid 358661:tid 358799] [client 41.68.90.219:61497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TSglWhjQfpOo60_HtIAAAAAU"]
[Tue Jul 21 08:08:58.421411 2026] [security2:error] [pid 358661:tid 358799] [client 41.68.90.219:61497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TSglWhjQfpOo60_HtIAAAAAU"]
[Tue Jul 21 08:08:58.701301 2026] [security2:error] [pid 358661:tid 358830] [client 20.220.225.223:1281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9TSglWhjQfpOo60_HtJgAAACQ"]
[Tue Jul 21 08:08:59.278689 2026] [security2:error] [pid 358661:tid 358852] [client 65.21.113.253:36168] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TSwlWhjQfpOo60_HtOwAAADo"]
[Tue Jul 21 08:08:59.376314 2026] [security2:error] [pid 358661:tid 358666] [remote 216.26.241.245:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TSwlWhjQfpOo60_HtOQAAcAE"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:08:59.570874 2026] [security2:error] [pid 352421:tid 352568] [client 20.29.126.15:2341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/dropdown.php"] [unique_id "al9TS8JSWzG9jbYOtu5dsAAAAJY"]
[Tue Jul 21 08:08:59.649168 2026] [security2:error] [pid 358661:tid 358873] [client 159.65.243.120:54906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.243.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.dorathiotoadvogados.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TSwlWhjQfpOo60_HtaQAAAE8"]
[Tue Jul 21 08:08:59.649278 2026] [security2:error] [pid 358661:tid 358873] [client 159.65.243.120:54906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.dorathiotoadvogados.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TSwlWhjQfpOo60_HtaQAAAE8"]
[Tue Jul 21 08:08:59.953294 2026] [security2:error] [pid 352421:tid 352652] [client 20.197.192.193:3466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/mimpi.php"] [unique_id "al9TS8JSWzG9jbYOtu5dtQAAAOo"]
[Tue Jul 21 08:08:59.974217 2026] [security2:error] [pid 358661:tid 358795] [client 102.206.115.33:64775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TSwlWhjQfpOo60_HtbwAAAAE"]
[Tue Jul 21 08:08:59.974337 2026] [security2:error] [pid 358661:tid 358795] [client 102.206.115.33:64775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TSwlWhjQfpOo60_HtbwAAAAE"]
[Tue Jul 21 08:09:00.028405 2026] [security2:error] [pid 358661:tid 358742] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TTAlWhjQfpOo60_HtcgAAIU0"]
[Tue Jul 21 08:09:00.028608 2026] [security2:error] [pid 358661:tid 358827] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TTAlWhjQfpOo60_HtcgAAIU0"]
[Tue Jul 21 08:09:00.369582 2026] [security2:error] [pid 358661:tid 358913] [client 65.21.113.253:58514] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TSwlWhjQfpOo60_HtcAAAAHc"]
[Tue Jul 21 08:09:00.391790 2026] [security2:error] [pid 352421:tid 352509] [remote 104.207.34.65:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.34.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TTMJSWzG9jbYOtu5dvwAA3Vc"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:00.397229 2026] [security2:error] [pid 352421:tid 352655] [client 20.104.96.117:62587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/24.php"] [unique_id "al9TTMJSWzG9jbYOtu5dwAAAAO0"]
[Tue Jul 21 08:09:00.451620 2026] [security2:error] [pid 352421:tid 352667] [client 20.220.225.223:1286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/dp.php"] [unique_id "al9TTMJSWzG9jbYOtu5dwQAAAPk"]
[Tue Jul 21 08:09:00.725923 2026] [security2:error] [pid 358661:tid 358825] [client 198.54.129.60:40662] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9TTAlWhjQfpOo60_HtnwAAAB8"]
[Tue Jul 21 08:09:00.726027 2026] [security2:error] [pid 358661:tid 358825] [client 198.54.129.60:40662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9TTAlWhjQfpOo60_HtnwAAAB8"]
[Tue Jul 21 08:09:00.821017 2026] [security2:error] [pid 352421:tid 352611] [client 74.7.244.56:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "drrafaelsalomao.com.br"] [uri "/index.php"] [unique_id "al9TTMJSWzG9jbYOtu5dugAAAME"]
[Tue Jul 21 08:09:00.821844 2026] [security2:error] [pid 358661:tid 358808] [client 74.7.244.56:44302] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "drrafaelsalomao.com.br"] [uri "/robots.txt"] [unique_id "al9TTAlWhjQfpOo60_HtgQAADls"]
[Tue Jul 21 08:09:00.840020 2026] [security2:error] [pid 358661:tid 358881] [client 34.34.186.87:52156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.34.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triaxion.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TTAlWhjQfpOo60_HtpAAAAFc"]
[Tue Jul 21 08:09:00.840140 2026] [security2:error] [pid 358661:tid 358881] [client 34.34.186.87:52156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "triaxion.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TTAlWhjQfpOo60_HtpAAAAFc"]
[Tue Jul 21 08:09:00.889855 2026] [security2:error] [pid 352421:tid 352614] [client 109.60.28.94:56474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TTMJSWzG9jbYOtu5dygAAAMQ"]
[Tue Jul 21 08:09:00.890065 2026] [security2:error] [pid 352421:tid 352614] [client 109.60.28.94:56474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TTMJSWzG9jbYOtu5dygAAAMQ"]
[Tue Jul 21 08:09:00.936717 2026] [security2:error] [pid 352421:tid 352480] [remote 20.153.140.50:45352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrsolar.org.br"] [uri "/wp-login.php"] [unique_id "al9TTMJSWzG9jbYOtu5dzAAA5zo"]
[Tue Jul 21 08:09:00.952504 2026] [security2:error] [pid 352421:tid 352623] [client 65.21.113.253:58522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TTMJSWzG9jbYOtu5dwgAAAM0"]
[Tue Jul 21 08:09:00.966985 2026] [security2:error] [pid 358661:tid 358749] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TTAlWhjQfpOo60_HtsgAAZVQ"]
[Tue Jul 21 08:09:00.967129 2026] [security2:error] [pid 358661:tid 358895] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TTAlWhjQfpOo60_HtsgAAZVQ"]
[Tue Jul 21 08:09:01.019231 2026] [access_compat:error] [pid 352421:tid 352558] [client 162.241.63.68:52596] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:09:01.119154 2026] [core:alert] [pid 358661:tid 358842] [client 57.141.18.94:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:09:01.201284 2026] [security2:error] [pid 352421:tid 352651] [client 150.129.202.39:65255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TTcJSWzG9jbYOtu5d0wAAAOk"]
[Tue Jul 21 08:09:01.201401 2026] [security2:error] [pid 352421:tid 352651] [client 150.129.202.39:65255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TTcJSWzG9jbYOtu5d0wAAAOk"]
[Tue Jul 21 08:09:01.464980 2026] [security2:error] [pid 352421:tid 352549] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TTcJSWzG9jbYOtu5d1QAA1X8"]
[Tue Jul 21 08:09:01.465172 2026] [security2:error] [pid 352421:tid 352631] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TTcJSWzG9jbYOtu5d1QAA1X8"]
[Tue Jul 21 08:09:01.715892 2026] [security2:error] [pid 358661:tid 358770] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TTQlWhjQfpOo60_HtyQAAQWk"]
[Tue Jul 21 08:09:01.716022 2026] [security2:error] [pid 358661:tid 358859] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TTQlWhjQfpOo60_HtyQAAQWk"]
[Tue Jul 21 08:09:01.764983 2026] [security2:error] [pid 358661:tid 358899] [client 103.166.103.129:34009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TTQlWhjQfpOo60_HtzAAAAGk"]
[Tue Jul 21 08:09:01.765126 2026] [security2:error] [pid 358661:tid 358899] [client 103.166.103.129:34009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TTQlWhjQfpOo60_HtzAAAAGk"]
[Tue Jul 21 08:09:01.862140 2026] [security2:error] [pid 352421:tid 352482] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TTcJSWzG9jbYOtu5d3QAA7jw"]
[Tue Jul 21 08:09:01.862359 2026] [security2:error] [pid 352421:tid 352656] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TTcJSWzG9jbYOtu5d3QAA7jw"]
[Tue Jul 21 08:09:02.099767 2026] [security2:error] [pid 352421:tid 352422] [remote 216.26.246.81:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.246.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TTcJSWzG9jbYOtu5d4AAA0QA"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:02.212081 2026] [security2:error] [pid 352421:tid 352665] [client 20.220.225.223:1300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/old.php"] [unique_id "al9TTsJSWzG9jbYOtu5d5AAAAPc"]
[Tue Jul 21 08:09:02.349945 2026] [security2:error] [pid 352421:tid 352653] [client 86.106.84.166:53868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9TTsJSWzG9jbYOtu5d6QAAAOs"]
[Tue Jul 21 08:09:02.350041 2026] [security2:error] [pid 352421:tid 352653] [client 86.106.84.166:53868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9TTsJSWzG9jbYOtu5d6QAAAOs"]
[Tue Jul 21 08:09:02.408314 2026] [security2:error] [pid 358661:tid 358884] [client 65.21.113.253:36168] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TTglWhjQfpOo60_Ht1AAAAFo"]
[Tue Jul 21 08:09:02.473230 2026] [security2:error] [pid 352421:tid 352546] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TTsJSWzG9jbYOtu5d7AAAyHw"]
[Tue Jul 21 08:09:02.473419 2026] [security2:error] [pid 352421:tid 352618] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TTsJSWzG9jbYOtu5d7AAAyHw"]
[Tue Jul 21 08:09:02.556297 2026] [security2:error] [pid 352421:tid 352425] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cromobelo.com.br"] [uri "/phpinfo.php"] [unique_id "al9TTsJSWzG9jbYOtu5d7QAA5AM"], referer: http://cpcalendars.cromobelo.com.br/phpinfo.php
[Tue Jul 21 08:09:02.765324 2026] [security2:error] [pid 352421:tid 352620] [client 20.220.225.223:1320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/ms-new.php"] [unique_id "al9TTsJSWzG9jbYOtu5d9AAAAMo"]
[Tue Jul 21 08:09:02.782750 2026] [security2:error] [pid 352421:tid 352555] [client 20.104.96.117:57925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/xyn.php"] [unique_id "al9TTsJSWzG9jbYOtu5d9gAAAIk"]
[Tue Jul 21 08:09:02.841210 2026] [security2:error] [pid 358661:tid 358820] [client 178.153.91.96:55190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TTglWhjQfpOo60_Ht1QAAABo"]
[Tue Jul 21 08:09:02.841334 2026] [security2:error] [pid 358661:tid 358820] [client 178.153.91.96:55190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TTglWhjQfpOo60_Ht1QAAABo"]
[Tue Jul 21 08:09:03.018289 2026] [security2:error] [pid 352421:tid 352615] [client 65.21.113.253:58522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TTsJSWzG9jbYOtu5d7wAAAMU"]
[Tue Jul 21 08:09:03.279205 2026] [security2:error] [pid 352421:tid 352584] [client 175.144.82.48:61073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TT8JSWzG9jbYOtu5d_gAAAKY"]
[Tue Jul 21 08:09:03.280102 2026] [security2:error] [pid 352421:tid 352584] [client 175.144.82.48:61073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TT8JSWzG9jbYOtu5d_gAAAKY"]
[Tue Jul 21 08:09:03.281579 2026] [security2:error] [pid 358661:tid 358785] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TTwlWhjQfpOo60_Ht3AAAZXg"]
[Tue Jul 21 08:09:03.281733 2026] [security2:error] [pid 358661:tid 358895] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TTwlWhjQfpOo60_Ht3AAAZXg"]
[Tue Jul 21 08:09:03.337888 2026] [security2:error] [pid 358661:tid 358703] [remote 57.141.18.121:20286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9TTwlWhjQfpOo60_Ht3gAABCY"]
[Tue Jul 21 08:09:03.510894 2026] [security2:error] [pid 358661:tid 358836] [client 20.220.225.223:1808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/track.php"] [unique_id "al9TTwlWhjQfpOo60_Ht4QAAACo"]
[Tue Jul 21 08:09:03.816614 2026] [security2:error] [pid 358661:tid 358713] [remote 104.207.50.169:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TTwlWhjQfpOo60_Ht5AAACjA"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:03.951808 2026] [security2:error] [pid 358661:tid 358795] [client 20.220.225.223:1322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/2352356666.php"] [unique_id "al9TTwlWhjQfpOo60_HuBAAAAAE"]
[Tue Jul 21 08:09:04.753454 2026] [security2:error] [pid 352421:tid 352562] [client 20.104.96.117:62565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/xacs.php"] [unique_id "al9TUMJSWzG9jbYOtu5eFgAAAJA"]
[Tue Jul 21 08:09:04.918541 2026] [security2:error] [pid 358661:tid 358904] [client 87.116.180.198:14030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TUAlWhjQfpOo60_HuEgAAAG4"]
[Tue Jul 21 08:09:04.918671 2026] [security2:error] [pid 358661:tid 358904] [client 87.116.180.198:14030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TUAlWhjQfpOo60_HuEgAAAG4"]
[Tue Jul 21 08:09:05.071794 2026] [security2:error] [pid 358661:tid 358918] [client 20.29.126.15:20211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/wp-links.php"] [unique_id "al9TUQlWhjQfpOo60_HuEwAAAHw"]
[Tue Jul 21 08:09:05.317489 2026] [security2:error] [pid 358661:tid 358781] [remote 216.26.244.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.244.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TUQlWhjQfpOo60_HuFgAAX3Q"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:05.498533 2026] [security2:error] [pid 358661:tid 358840] [client 20.220.225.223:1342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/pn.php"] [unique_id "al9TUQlWhjQfpOo60_HuLQAAAC4"]
[Tue Jul 21 08:09:06.362855 2026] [security2:error] [pid 358661:tid 358796] [client 38.100.221.102:17581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TUglWhjQfpOo60_HuPwAAAAI"]
[Tue Jul 21 08:09:06.363045 2026] [security2:error] [pid 358661:tid 358796] [client 38.100.221.102:17581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TUglWhjQfpOo60_HuPwAAAAI"]
[Tue Jul 21 08:09:06.418988 2026] [security2:error] [pid 358661:tid 358795] [client 20.220.225.223:1821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9TUglWhjQfpOo60_HuQwAAAAE"]
[Tue Jul 21 08:09:06.419069 2026] [rewrite:warn] [pid 352421:tid 352445] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:09:06.550156 2026] [security2:error] [pid 358661:tid 358861] [client 172.234.215.24:34222] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "ejemconsultoria.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9TUglWhjQfpOo60_HuRgAAAEM"]
[Tue Jul 21 08:09:06.689255 2026] [security2:error] [pid 358661:tid 358919] [client 172.234.215.24:34222] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "ejemconsultoria.com.br"] [uri "/"] [unique_id "al9TUglWhjQfpOo60_HuSgAAAH0"]
[Tue Jul 21 08:09:06.781801 2026] [proxy:error] [pid 352421:tid 352447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:06.781872 2026] [proxy_http:error] [pid 352421:tid 352447] [remote 176.65.132.57:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.cromobelo.com.br/_profiler/phpinfo
[Tue Jul 21 08:09:06.783210 2026] [proxy:error] [pid 352421:tid 352447] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:06.783255 2026] [proxy_http:error] [pid 352421:tid 352447] [remote 176.65.132.57:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.cromobelo.com.br/_profiler/phpinfo
[Tue Jul 21 08:09:06.819647 2026] [security2:error] [pid 358661:tid 358855] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TUglWhjQfpOo60_HuTAAAPQs"]
[Tue Jul 21 08:09:07.053979 2026] [security2:error] [pid 358661:tid 358835] [client 65.21.113.253:58528] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TUglWhjQfpOo60_HuRwAAACk"]
[Tue Jul 21 08:09:07.524264 2026] [security2:error] [pid 358661:tid 358819] [client 20.104.96.117:62510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/zildan.php"] [unique_id "al9TUwlWhjQfpOo60_HuUwAAABk"]
[Tue Jul 21 08:09:08.440495 2026] [security2:error] [pid 352421:tid 352606] [client 20.220.225.223:1288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/dr.php"] [unique_id "al9TVMJSWzG9jbYOtu5eTwAAALw"]
[Tue Jul 21 08:09:08.595931 2026] [security2:error] [pid 358661:tid 358733] [remote 65.111.7.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.7.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TUglWhjQfpOo60_HuRQAAV0Q"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:08.738385 2026] [security2:error] [pid 358661:tid 358901] [client 65.21.113.253:37568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TVAlWhjQfpOo60_HuWwAAAGs"]
[Tue Jul 21 08:09:08.844708 2026] [security2:error] [pid 352421:tid 352479] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TVMJSWzG9jbYOtu5eVwABAzk"]
[Tue Jul 21 08:09:08.844837 2026] [security2:error] [pid 352421:tid 352677] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TVMJSWzG9jbYOtu5eVwABAzk"]
[Tue Jul 21 08:09:08.895985 2026] [security2:error] [pid 358661:tid 358886] [client 20.29.126.15:6337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/xmrlpc.php"] [unique_id "al9TVAlWhjQfpOo60_HuXQAAAFw"]
[Tue Jul 21 08:09:08.988110 2026] [security2:error] [pid 358661:tid 358798] [client 20.220.225.223:1289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/2x.php"] [unique_id "al9TVAlWhjQfpOo60_HuYgAAAAQ"]
[Tue Jul 21 08:09:09.347956 2026] [security2:error] [pid 358661:tid 358815] [client 65.21.113.253:58528] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TVAlWhjQfpOo60_HuXwAAABU"]
[Tue Jul 21 08:09:09.694022 2026] [security2:error] [pid 352421:tid 352652] [client 20.220.225.223:1325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/kq1.php"] [unique_id "al9TVcJSWzG9jbYOtu5eZAAAAOo"]
[Tue Jul 21 08:09:10.234165 2026] [security2:error] [pid 352421:tid 352477] [remote 151.123.177.138:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TVsJSWzG9jbYOtu5eawAA-jc"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:10.282187 2026] [security2:error] [pid 352421:tid 352653] [client 65.21.113.253:41032] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TVcJSWzG9jbYOtu5eZgAAAOs"]
[Tue Jul 21 08:09:10.306086 2026] [security2:error] [pid 358661:tid 358795] [client 41.68.90.219:62003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TVglWhjQfpOo60_HufQAAAAE"]
[Tue Jul 21 08:09:10.307258 2026] [security2:error] [pid 358661:tid 358795] [client 41.68.90.219:62003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TVglWhjQfpOo60_HufQAAAAE"]
[Tue Jul 21 08:09:10.317753 2026] [security2:error] [pid 358661:tid 358809] [client 62.102.148.158:35742] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9TVglWhjQfpOo60_HufgAAAA8"]
[Tue Jul 21 08:09:10.317939 2026] [security2:error] [pid 358661:tid 358809] [client 62.102.148.158:35742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9TVglWhjQfpOo60_HufgAAAA8"]
[Tue Jul 21 08:09:10.463279 2026] [security2:error] [pid 358661:tid 358861] [client 102.206.115.33:61773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TVglWhjQfpOo60_HugQAAAEM"]
[Tue Jul 21 08:09:10.463449 2026] [security2:error] [pid 358661:tid 358861] [client 102.206.115.33:61773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TVglWhjQfpOo60_HugQAAAEM"]
[Tue Jul 21 08:09:10.710181 2026] [security2:error] [pid 352421:tid 352526] [remote 103.153.130.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.130.153.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TVsJSWzG9jbYOtu5ecwAA3mg"]
[Tue Jul 21 08:09:10.710310 2026] [security2:error] [pid 352421:tid 352640] [client 103.153.130.41:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TVsJSWzG9jbYOtu5ecwAA3mg"]
[Tue Jul 21 08:09:11.420552 2026] [security2:error] [pid 352421:tid 352600] [client 20.104.96.117:62476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/csa.php"] [unique_id "al9TV8JSWzG9jbYOtu5eegAAALY"]
[Tue Jul 21 08:09:11.465182 2026] [security2:error] [pid 358661:tid 358773] [remote 209.50.172.40:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.172.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TVwlWhjQfpOo60_HukAAALmw"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:11.593963 2026] [security2:error] [pid 358661:tid 358916] [client 198.54.129.60:50852] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9TVwlWhjQfpOo60_HumAAAAHo"]
[Tue Jul 21 08:09:11.594094 2026] [security2:error] [pid 358661:tid 358916] [client 198.54.129.60:50852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9TVwlWhjQfpOo60_HumAAAAHo"]
[Tue Jul 21 08:09:11.668051 2026] [security2:error] [pid 358661:tid 358822] [client 109.60.28.94:56924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TVwlWhjQfpOo60_HumwAAABw"]
[Tue Jul 21 08:09:11.668162 2026] [security2:error] [pid 358661:tid 358822] [client 109.60.28.94:56924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TVwlWhjQfpOo60_HumwAAABw"]
[Tue Jul 21 08:09:11.815279 2026] [security2:error] [pid 358661:tid 358903] [client 20.104.96.117:62482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/w3llscc.php"] [unique_id "al9TVwlWhjQfpOo60_HunQAAAG0"]
[Tue Jul 21 08:09:11.923788 2026] [security2:error] [pid 352421:tid 352604] [client 150.129.202.39:65021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TV8JSWzG9jbYOtu5eggAAALo"]
[Tue Jul 21 08:09:11.923972 2026] [security2:error] [pid 352421:tid 352604] [client 150.129.202.39:65021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TV8JSWzG9jbYOtu5eggAAALo"]
[Tue Jul 21 08:09:12.250720 2026] [security2:error] [pid 358661:tid 358853] [client 65.21.113.253:37568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TWAlWhjQfpOo60_HupAAAADs"]
[Tue Jul 21 08:09:12.319082 2026] [security2:error] [pid 358661:tid 358679] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TWAlWhjQfpOo60_HupwAABQ4"]
[Tue Jul 21 08:09:12.319240 2026] [security2:error] [pid 358661:tid 358799] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TWAlWhjQfpOo60_HupwAABQ4"]
[Tue Jul 21 08:09:12.321865 2026] [security2:error] [pid 358661:tid 358739] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TWAlWhjQfpOo60_HuqAAAXUo"]
[Tue Jul 21 08:09:12.322003 2026] [security2:error] [pid 358661:tid 358887] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TWAlWhjQfpOo60_HuqAAAXUo"]
[Tue Jul 21 08:09:12.441161 2026] [security2:error] [pid 352421:tid 352431] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TWMJSWzG9jbYOtu5ehwAAnAk"]
[Tue Jul 21 08:09:12.441316 2026] [security2:error] [pid 352421:tid 352574] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TWMJSWzG9jbYOtu5ehwAAnAk"]
[Tue Jul 21 08:09:12.476658 2026] [security2:error] [pid 358661:tid 358700] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TWAlWhjQfpOo60_HuqwAAYCM"]
[Tue Jul 21 08:09:12.476799 2026] [security2:error] [pid 358661:tid 358890] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TWAlWhjQfpOo60_HuqwAAYCM"]
[Tue Jul 21 08:09:12.596965 2026] [security2:error] [pid 352421:tid 352572] [client 20.220.225.223:1797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/zzz.php"] [unique_id "al9TWMJSWzG9jbYOtu5ejAAAAJo"]
[Tue Jul 21 08:09:12.951114 2026] [security2:error] [pid 352421:tid 352678] [client 65.21.113.253:41032] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TWMJSWzG9jbYOtu5eiQAAAQQ"]
[Tue Jul 21 08:09:13.107193 2026] [security2:error] [pid 358661:tid 358677] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TWQlWhjQfpOo60_HuvwAAKAw"]
[Tue Jul 21 08:09:13.107346 2026] [security2:error] [pid 358661:tid 358834] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TWQlWhjQfpOo60_HuvwAAKAw"]
[Tue Jul 21 08:09:13.171333 2026] [security2:error] [pid 358661:tid 358808] [client 20.29.126.15:6343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/htaccess.php"] [unique_id "al9TWQlWhjQfpOo60_HuwAAAAA4"]
[Tue Jul 21 08:09:13.367405 2026] [security2:error] [pid 358661:tid 358872] [client 178.153.91.96:58698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TWQlWhjQfpOo60_HuxAAAAE4"]
[Tue Jul 21 08:09:13.367578 2026] [security2:error] [pid 358661:tid 358872] [client 178.153.91.96:58698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TWQlWhjQfpOo60_HuxAAAAE4"]
[Tue Jul 21 08:09:13.743951 2026] [security2:error] [pid 358661:tid 358912] [client 120.56.162.40:62664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TWQlWhjQfpOo60_HuywAAAHY"]
[Tue Jul 21 08:09:13.744094 2026] [security2:error] [pid 358661:tid 358912] [client 120.56.162.40:62664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TWQlWhjQfpOo60_HuywAAAHY"]
[Tue Jul 21 08:09:13.758631 2026] [security2:error] [pid 358661:tid 358827] [client 175.144.82.48:61536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TWQlWhjQfpOo60_HuzQAAACE"]
[Tue Jul 21 08:09:13.759461 2026] [security2:error] [pid 358661:tid 358827] [client 175.144.82.48:61536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TWQlWhjQfpOo60_HuzQAAACE"]
[Tue Jul 21 08:09:13.816009 2026] [security2:error] [pid 358661:tid 358687] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TWQlWhjQfpOo60_HuzgAALhY"]
[Tue Jul 21 08:09:13.816192 2026] [security2:error] [pid 358661:tid 358840] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TWQlWhjQfpOo60_HuzgAALhY"]
[Tue Jul 21 08:09:13.898786 2026] [security2:error] [pid 352421:tid 352671] [client 20.197.192.193:39232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/dp.php"] [unique_id "al9TWcJSWzG9jbYOtu5eqQAAAP0"]
[Tue Jul 21 08:09:13.991406 2026] [security2:error] [pid 352421:tid 352650] [client 20.104.96.117:62580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wpx.php"] [unique_id "al9TWcJSWzG9jbYOtu5eqwAAAOg"]
[Tue Jul 21 08:09:14.104057 2026] [security2:error] [pid 352421:tid 352666] [client 65.21.113.253:41036] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TWcJSWzG9jbYOtu5enwAAAPg"]
[Tue Jul 21 08:09:14.174364 2026] [security2:error] [pid 358661:tid 358855] [client 198.54.129.60:45714] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9TWglWhjQfpOo60_HuzwAAAD0"]
[Tue Jul 21 08:09:14.174480 2026] [security2:error] [pid 358661:tid 358855] [client 198.54.129.60:45714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9TWglWhjQfpOo60_HuzwAAAD0"]
[Tue Jul 21 08:09:14.181100 2026] [security2:error] [pid 358661:tid 358670] [remote 34.182.235.64:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.235.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.wendelleite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TWQlWhjQfpOo60_HuwQAAOgU"]
[Tue Jul 21 08:09:14.420037 2026] [security2:error] [pid 352421:tid 352498] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wendelleite.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9TWsJSWzG9jbYOtu5erwAAlUw"]
[Tue Jul 21 08:09:14.467782 2026] [security2:error] [pid 358661:tid 358784] [remote 209.50.160.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.160.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TWAlWhjQfpOo60_HupQAANXc"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:14.596792 2026] [security2:error] [pid 352421:tid 352453] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wendelleite.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9TWsJSWzG9jbYOtu5esgAAkh8"]
[Tue Jul 21 08:09:14.619651 2026] [security2:error] [pid 358661:tid 358760] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cromobelo.com.br"] [uri "/i.php"] [unique_id "al9TWglWhjQfpOo60_Hu3AAAdV8"], referer: http://cpcalendars.cromobelo.com.br/i.php
[Tue Jul 21 08:09:14.869054 2026] [security2:error] [pid 358661:tid 358785] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wendelleite.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9TWglWhjQfpOo60_Hu4QAALHg"]
[Tue Jul 21 08:09:14.993447 2026] [security2:error] [pid 352421:tid 352487] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wendelleite.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9TWsJSWzG9jbYOtu5etgAA3kE"]
[Tue Jul 21 08:09:15.005898 2026] [security2:error] [pid 358661:tid 358906] [client 65.21.113.253:37568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TWwlWhjQfpOo60_Hu6QAAAHA"]
[Tue Jul 21 08:09:15.021562 2026] [security2:error] [pid 352421:tid 352644] [client 103.166.103.129:55792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TW8JSWzG9jbYOtu5etwAAAOI"]
[Tue Jul 21 08:09:15.022463 2026] [security2:error] [pid 352421:tid 352644] [client 103.166.103.129:55792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TW8JSWzG9jbYOtu5etwAAAOI"]
[Tue Jul 21 08:09:15.065273 2026] [security2:error] [pid 358661:tid 358919] [client 198.54.129.60:45704] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9TWwlWhjQfpOo60_Hu6gAAAH0"]
[Tue Jul 21 08:09:15.065374 2026] [security2:error] [pid 358661:tid 358919] [client 198.54.129.60:45704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9TWwlWhjQfpOo60_Hu6gAAAH0"]
[Tue Jul 21 08:09:15.158338 2026] [security2:error] [pid 358661:tid 358782] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wendelleite.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9TWwlWhjQfpOo60_Hu7gAAaHU"]
[Tue Jul 21 08:09:15.172800 2026] [security2:error] [pid 358661:tid 358798] [client 62.102.148.158:38504] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9TWwlWhjQfpOo60_Hu7wAAAAQ"]
[Tue Jul 21 08:09:15.172904 2026] [security2:error] [pid 358661:tid 358798] [client 62.102.148.158:38504] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9TWwlWhjQfpOo60_Hu7wAAAAQ"]
[Tue Jul 21 08:09:15.172925 2026] [security2:error] [pid 358661:tid 358798] [client 62.102.148.158:38504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9TWwlWhjQfpOo60_Hu7wAAAAQ"]
[Tue Jul 21 08:09:15.377955 2026] [security2:error] [pid 352421:tid 352528] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wendelleite.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9TW8JSWzG9jbYOtu5evwAApmo"]
[Tue Jul 21 08:09:15.473081 2026] [security2:error] [pid 352421:tid 352433] [remote 65.111.4.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.4.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TW8JSWzG9jbYOtu5ewQAAsgs"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:15.598395 2026] [security2:error] [pid 358661:tid 358850] [client 87.116.180.198:27350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TWwlWhjQfpOo60_Hu9QAAADg"]
[Tue Jul 21 08:09:15.598604 2026] [security2:error] [pid 358661:tid 358850] [client 87.116.180.198:27350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TWwlWhjQfpOo60_Hu9QAAADg"]
[Tue Jul 21 08:09:15.639639 2026] [security2:error] [pid 352421:tid 352646] [client 65.21.113.253:41036] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TW8JSWzG9jbYOtu5evAAAAOQ"]
[Tue Jul 21 08:09:15.640232 2026] [security2:error] [pid 352421:tid 352485] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wendelleite.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9TW8JSWzG9jbYOtu5ewwAAvz8"]
[Tue Jul 21 08:09:15.766157 2026] [security2:error] [pid 358661:tid 358768] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wendelleite.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9TWwlWhjQfpOo60_Hu_gAAW2c"]
[Tue Jul 21 08:09:15.892044 2026] [security2:error] [pid 352421:tid 352523] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wendelleite.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9TW8JSWzG9jbYOtu5eyAAA8GU"]
[Tue Jul 21 08:09:16.016967 2026] [security2:error] [pid 358661:tid 358725] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wendelleite.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9TXAlWhjQfpOo60_HvBAAADTw"]
[Tue Jul 21 08:09:16.169226 2026] [security2:error] [pid 352421:tid 352537] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wendelleite.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9TXMJSWzG9jbYOtu5eygAAnHM"]
[Tue Jul 21 08:09:16.324375 2026] [security2:error] [pid 352421:tid 352589] [client 20.197.192.193:64460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/bootstrap.php"] [unique_id "al9TXMJSWzG9jbYOtu5ezwAAAKs"]
[Tue Jul 21 08:09:16.422830 2026] [security2:error] [pid 358661:tid 358696] [remote 41.186.86.12:33681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9TXAlWhjQfpOo60_HvCwAAFB8"]
[Tue Jul 21 08:09:16.457851 2026] [security2:error] [pid 358661:tid 358674] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.wendelleite.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9TXAlWhjQfpOo60_HvDAAAdwk"]
[Tue Jul 21 08:09:16.922129 2026] [security2:error] [pid 358661:tid 358726] [remote 104.207.53.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TXAlWhjQfpOo60_HvEQAAAD0"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:16.942743 2026] [security2:error] [pid 352421:tid 352628] [client 38.100.221.102:18208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TXMJSWzG9jbYOtu5e2gAAANI"]
[Tue Jul 21 08:09:16.942873 2026] [security2:error] [pid 352421:tid 352628] [client 38.100.221.102:18208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TXMJSWzG9jbYOtu5e2gAAANI"]
[Tue Jul 21 08:09:17.295313 2026] [security2:error] [pid 352421:tid 352597] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TXcJSWzG9jbYOtu5e3gAAs18"]
[Tue Jul 21 08:09:17.360874 2026] [security2:error] [pid 358661:tid 358905] [client 65.21.113.253:37568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TXQlWhjQfpOo60_HvFQAAAG8"]
[Tue Jul 21 08:09:17.472098 2026] [security2:error] [pid 358661:tid 358908] [client 20.220.225.223:1338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wicked.php"] [unique_id "al9TXQlWhjQfpOo60_HvGQAAAHI"]
[Tue Jul 21 08:09:17.807043 2026] [autoindex:error] [pid 358661:tid 358857] [client 186.202.163.107:34932] AH01276: Cannot serve directory /home2/cla35313/reidocouro.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:09:17.812875 2026] [security2:error] [pid 358661:tid 358820] [client 65.21.113.253:41048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TXQlWhjQfpOo60_HvFAAAABo"]
[Tue Jul 21 08:09:17.815390 2026] [security2:error] [pid 358661:tid 358693] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cromobelo.com.br"] [uri "/pi.php"] [unique_id "al9TXQlWhjQfpOo60_HvHgAAKxw"], referer: http://cpcalendars.cromobelo.com.br/pi.php
[Tue Jul 21 08:09:18.322098 2026] [security2:error] [pid 352421:tid 352556] [client 117.247.80.59:13476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.80.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TXsJSWzG9jbYOtu5e7QAAAIo"]
[Tue Jul 21 08:09:18.322262 2026] [security2:error] [pid 352421:tid 352556] [client 117.247.80.59:13476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "havoy.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TXsJSWzG9jbYOtu5e7QAAAIo"]
[Tue Jul 21 08:09:18.383093 2026] [security2:error] [pid 352421:tid 352472] [remote 72.167.132.114:60836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9TXsJSWzG9jbYOtu5e7wAA0zI"]
[Tue Jul 21 08:09:18.410841 2026] [security2:error] [pid 358661:tid 358915] [client 65.21.113.253:41062] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TXglWhjQfpOo60_HvIgAAAHk"]
[Tue Jul 21 08:09:18.556393 2026] [security2:error] [pid 352421:tid 352603] [client 20.29.126.15:7078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/readme.php"] [unique_id "al9TXsJSWzG9jbYOtu5e8wAAALk"]
[Tue Jul 21 08:09:18.607563 2026] [security2:error] [pid 358661:tid 358912] [client 154.208.47.43:35830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TXglWhjQfpOo60_HvKAAAAHY"]
[Tue Jul 21 08:09:18.607683 2026] [security2:error] [pid 358661:tid 358912] [client 154.208.47.43:35830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TXglWhjQfpOo60_HvKAAAAHY"]
[Tue Jul 21 08:09:18.634822 2026] [security2:error] [pid 352421:tid 352483] [remote 217.181.91.69:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.91.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TXsJSWzG9jbYOtu5e8AAA-T0"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:19.016844 2026] [autoindex:error] [pid 358661:tid 358669] [remote 45.175.115.210:51374] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/
[Tue Jul 21 08:09:19.249486 2026] [autoindex:error] [pid 358661:tid 358695] [remote 45.175.115.210:51374] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/?pag=chamada_consulta
[Tue Jul 21 08:09:19.355928 2026] [security2:error] [pid 352421:tid 352624] [client 103.29.114.44:12738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TX8JSWzG9jbYOtu5e_wAAAM4"]
[Tue Jul 21 08:09:19.356071 2026] [security2:error] [pid 352421:tid 352624] [client 103.29.114.44:12738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TX8JSWzG9jbYOtu5e_wAAAM4"]
[Tue Jul 21 08:09:19.364172 2026] [security2:error] [pid 352421:tid 352609] [client 20.104.96.117:57923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/patie.php"] [unique_id "al9TX8JSWzG9jbYOtu5fAAAAAL8"]
[Tue Jul 21 08:09:19.673528 2026] [security2:error] [pid 358661:tid 358754] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TXwlWhjQfpOo60_HvOAAAa1k"]
[Tue Jul 21 08:09:19.673680 2026] [security2:error] [pid 358661:tid 358901] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TXwlWhjQfpOo60_HvOAAAa1k"]
[Tue Jul 21 08:09:20.522121 2026] [security2:error] [pid 358661:tid 358838] [client 65.21.113.253:41048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TYAlWhjQfpOo60_HvPgAAACw"]
[Tue Jul 21 08:09:20.702892 2026] [security2:error] [pid 358661:tid 358872] [client 20.220.225.223:1292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/edit.php"] [unique_id "al9TYAlWhjQfpOo60_HvRAAAAE4"]
[Tue Jul 21 08:09:20.767806 2026] [security2:error] [pid 352421:tid 352435] [remote 65.111.20.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TX8JSWzG9jbYOtu5fCQAArQ0"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:20.943025 2026] [security2:error] [pid 358661:tid 358892] [client 102.206.115.33:58599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TYAlWhjQfpOo60_HvRQAAAGI"]
[Tue Jul 21 08:09:20.943153 2026] [security2:error] [pid 358661:tid 358892] [client 102.206.115.33:58599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TYAlWhjQfpOo60_HvRQAAAGI"]
[Tue Jul 21 08:09:21.435037 2026] [security2:error] [pid 352421:tid 352577] [client 41.68.90.219:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TYcJSWzG9jbYOtu5fIwAAAJ8"]
[Tue Jul 21 08:09:21.436078 2026] [security2:error] [pid 352421:tid 352577] [client 41.68.90.219:62685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TYcJSWzG9jbYOtu5fIwAAAJ8"]
[Tue Jul 21 08:09:21.695390 2026] [security2:error] [pid 358661:tid 358871] [client 185.198.240.183:49137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dener.design"] [uri "/wp-login.php"] [unique_id "al9TYQlWhjQfpOo60_HvcQAAAE0"]
[Tue Jul 21 08:09:21.704717 2026] [security2:error] [pid 352421:tid 352501] [remote 104.207.61.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TYcJSWzG9jbYOtu5fJgAA0U8"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:22.092166 2026] [security2:error] [pid 358661:tid 358761] [remote 45.117.83.212:56752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9TYglWhjQfpOo60_HvgwAAC2A"]
[Tue Jul 21 08:09:22.421652 2026] [security2:error] [pid 352421:tid 352620] [client 109.60.28.94:57380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TYsJSWzG9jbYOtu5fMwAAAMo"]
[Tue Jul 21 08:09:22.421910 2026] [security2:error] [pid 352421:tid 352620] [client 109.60.28.94:57380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TYsJSWzG9jbYOtu5fMwAAAMo"]
[Tue Jul 21 08:09:22.431391 2026] [security2:error] [pid 352421:tid 352676] [client 20.197.192.193:3128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/inso.php"] [unique_id "al9TYsJSWzG9jbYOtu5fNAAAAQI"]
[Tue Jul 21 08:09:22.455452 2026] [security2:error] [pid 358661:tid 358864] [client 150.129.202.39:64861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TYglWhjQfpOo60_HvjgAAAEY"]
[Tue Jul 21 08:09:22.455612 2026] [security2:error] [pid 358661:tid 358864] [client 150.129.202.39:64861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TYglWhjQfpOo60_HvjgAAAEY"]
[Tue Jul 21 08:09:22.490028 2026] [security2:error] [pid 358661:tid 358737] [remote 57.141.18.123:51070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9TYQlWhjQfpOo60_HvTQAAEEg"]
[Tue Jul 21 08:09:22.902073 2026] [security2:error] [pid 358661:tid 358712] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TYglWhjQfpOo60_HvkwAAWS8"]
[Tue Jul 21 08:09:22.902262 2026] [security2:error] [pid 358661:tid 358883] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TYglWhjQfpOo60_HvkwAAWS8"]
[Tue Jul 21 08:09:23.022075 2026] [security2:error] [pid 358661:tid 358759] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TYwlWhjQfpOo60_HvlAAAdV4"]
[Tue Jul 21 08:09:23.022222 2026] [security2:error] [pid 358661:tid 358911] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TYwlWhjQfpOo60_HvlAAAdV4"]
[Tue Jul 21 08:09:23.178024 2026] [security2:error] [pid 352421:tid 352640] [client 103.166.103.129:56192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.103.166.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TY8JSWzG9jbYOtu5fUQAAAN4"]
[Tue Jul 21 08:09:23.178144 2026] [security2:error] [pid 352421:tid 352640] [client 103.166.103.129:56192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9TY8JSWzG9jbYOtu5fUQAAAN4"]
[Tue Jul 21 08:09:23.236473 2026] [security2:error] [pid 358661:tid 358906] [client 20.104.96.117:62525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-css.php"] [unique_id "al9TYwlWhjQfpOo60_HvmgAAAHA"]
[Tue Jul 21 08:09:23.330547 2026] [security2:error] [pid 352421:tid 352480] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TY8JSWzG9jbYOtu5fVAAAjTo"]
[Tue Jul 21 08:09:23.330774 2026] [security2:error] [pid 352421:tid 352559] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TY8JSWzG9jbYOtu5fVAAAjTo"]
[Tue Jul 21 08:09:23.554677 2026] [security2:error] [pid 358661:tid 358729] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TYwlWhjQfpOo60_HvrQAAOEA"]
[Tue Jul 21 08:09:23.554830 2026] [security2:error] [pid 358661:tid 358850] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TYwlWhjQfpOo60_HvrQAAOEA"]
[Tue Jul 21 08:09:23.690617 2026] [security2:error] [pid 352421:tid 352461] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TY8JSWzG9jbYOtu5fWQABACc"]
[Tue Jul 21 08:09:23.690869 2026] [security2:error] [pid 352421:tid 352674] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TY8JSWzG9jbYOtu5fWQABACc"]
[Tue Jul 21 08:09:23.847784 2026] [security2:error] [pid 358661:tid 358808] [client 178.153.91.96:56468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TYwlWhjQfpOo60_HvyQAAAA4"]
[Tue Jul 21 08:09:23.847941 2026] [security2:error] [pid 358661:tid 358808] [client 178.153.91.96:56468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TYwlWhjQfpOo60_HvyQAAAA4"]
[Tue Jul 21 08:09:23.891194 2026] [security2:error] [pid 358661:tid 358705] [remote 209.50.175.135:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.175.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TYglWhjQfpOo60_HvkgAAESg"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:24.231161 2026] [security2:error] [pid 358661:tid 358836] [client 175.144.82.48:61998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TZAlWhjQfpOo60_Hv1QAAACo"]
[Tue Jul 21 08:09:24.231788 2026] [security2:error] [pid 358661:tid 358836] [client 175.144.82.48:61998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TZAlWhjQfpOo60_Hv1QAAACo"]
[Tue Jul 21 08:09:24.275367 2026] [security2:error] [pid 358661:tid 358921] [client 65.21.113.253:41048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TYwlWhjQfpOo60_HvyAAAAH8"]
[Tue Jul 21 08:09:24.340895 2026] [security2:error] [pid 352421:tid 352422] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TZMJSWzG9jbYOtu5fZAAAswA"]
[Tue Jul 21 08:09:24.341029 2026] [security2:error] [pid 352421:tid 352597] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TZMJSWzG9jbYOtu5fZAAAswA"]
[Tue Jul 21 08:09:24.836075 2026] [security2:error] [pid 358661:tid 358848] [client 65.21.113.253:48136] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TZAlWhjQfpOo60_Hv2wAAADY"]
[Tue Jul 21 08:09:25.110469 2026] [security2:error] [pid 358661:tid 358896] [client 62.102.148.158:54620] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9TZQlWhjQfpOo60_Hv4AAAAGY"]
[Tue Jul 21 08:09:25.110590 2026] [security2:error] [pid 358661:tid 358896] [client 62.102.148.158:54620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9TZQlWhjQfpOo60_Hv4AAAAGY"]
[Tue Jul 21 08:09:25.350637 2026] [proxy:error] [pid 358661:tid 358673] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:25.350678 2026] [proxy_http:error] [pid 358661:tid 358673] [remote 176.65.132.57:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.cromobelo.com.br/.aws/credentials
[Tue Jul 21 08:09:25.351139 2026] [proxy:error] [pid 358661:tid 358673] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:25.351166 2026] [proxy_http:error] [pid 358661:tid 358673] [remote 176.65.132.57:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.cromobelo.com.br/.aws/credentials
[Tue Jul 21 08:09:25.458481 2026] [security2:error] [pid 358661:tid 358874] [client 65.21.113.253:41048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TZQlWhjQfpOo60_Hv3wAAAFA"]
[Tue Jul 21 08:09:25.797380 2026] [security2:error] [pid 358661:tid 358672] [remote 20.84.23.222:6980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.23.84.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9TZQlWhjQfpOo60_Hv6QAAKAc"]
[Tue Jul 21 08:09:25.955968 2026] [security2:error] [pid 358661:tid 358817] [client 103.78.200.11:56261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TZQlWhjQfpOo60_Hv6wAAABc"]
[Tue Jul 21 08:09:25.956113 2026] [security2:error] [pid 358661:tid 358817] [client 103.78.200.11:56261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TZQlWhjQfpOo60_Hv6wAAABc"]
[Tue Jul 21 08:09:26.274554 2026] [security2:error] [pid 352421:tid 352557] [client 87.116.180.198:14032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TZsJSWzG9jbYOtu5fhQAAAIs"]
[Tue Jul 21 08:09:26.274712 2026] [security2:error] [pid 352421:tid 352557] [client 87.116.180.198:14032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TZsJSWzG9jbYOtu5fhQAAAIs"]
[Tue Jul 21 08:09:26.275780 2026] [security2:error] [pid 358661:tid 358837] [client 20.104.96.117:63440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/ho.php"] [unique_id "al9TZglWhjQfpOo60_Hv7wAAACs"]
[Tue Jul 21 08:09:26.375769 2026] [security2:error] [pid 358661:tid 358695] [remote 65.111.30.14:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.30.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TZglWhjQfpOo60_Hv8AAAOB4"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:26.441441 2026] [security2:error] [pid 352421:tid 352611] [client 20.220.225.223:1310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/kua.php"] [unique_id "al9TZsJSWzG9jbYOtu5fhwAAAME"]
[Tue Jul 21 08:09:26.595534 2026] [security2:error] [pid 358661:tid 358839] [client 34.182.235.64:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.235.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TZglWhjQfpOo60_Hv8wAAAC0"]
[Tue Jul 21 08:09:26.843147 2026] [security2:error] [pid 358661:tid 358796] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9TZglWhjQfpOo60_Hv9AAAAAI"]
[Tue Jul 21 08:09:27.296606 2026] [security2:error] [pid 352421:tid 352617] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9TZ8JSWzG9jbYOtu5foAAAAMc"]
[Tue Jul 21 08:09:27.328644 2026] [security2:error] [pid 358661:tid 358868] [client 20.220.225.223:1331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/ez.php"] [unique_id "al9TZwlWhjQfpOo60_Hv-QAAAEo"]
[Tue Jul 21 08:09:27.519692 2026] [security2:error] [pid 352421:tid 352622] [client 20.104.96.117:62567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/xy.php"] [unique_id "al9TZ8JSWzG9jbYOtu5fpQAAAMw"]
[Tue Jul 21 08:09:27.526474 2026] [security2:error] [pid 352421:tid 352562] [client 38.100.221.102:18904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TZ8JSWzG9jbYOtu5fpgAAAJA"]
[Tue Jul 21 08:09:27.526554 2026] [security2:error] [pid 352421:tid 352562] [client 38.100.221.102:18904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TZ8JSWzG9jbYOtu5fpgAAAJA"]
[Tue Jul 21 08:09:27.565768 2026] [security2:error] [pid 358661:tid 358836] [client 20.29.126.15:5108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/403.php"] [unique_id "al9TZwlWhjQfpOo60_Hv_wAAACo"]
[Tue Jul 21 08:09:27.737910 2026] [autoindex:error] [pid 352421:tid 352591] [client 109.70.100.13:37842] AH01276: Cannot serve directory /home2/ric83751/sanovitta.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:09:27.805304 2026] [security2:error] [pid 358661:tid 358921] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9TZwlWhjQfpOo60_HwAgAAAH8"]
[Tue Jul 21 08:09:27.838403 2026] [security2:error] [pid 358661:tid 358805] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TZwlWhjQfpOo60_HwAQAACxc"]
[Tue Jul 21 08:09:27.857349 2026] [security2:error] [pid 352421:tid 352556] [client 20.220.225.223:1804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/fz.php"] [unique_id "al9TZ8JSWzG9jbYOtu5frgAAAIo"]
[Tue Jul 21 08:09:28.061231 2026] [security2:error] [pid 358661:tid 358867] [client 216.244.66.228:47758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lucaskotovicz.com"] [uri "/robots.txt"] [unique_id "al9TaAlWhjQfpOo60_HwBQAAAEk"]
[Tue Jul 21 08:09:28.061339 2026] [security2:error] [pid 358661:tid 358867] [client 216.244.66.228:47758] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lucaskotovicz.com"] [uri "/robots.txt"] [unique_id "al9TaAlWhjQfpOo60_HwBQAAAEk"]
[Tue Jul 21 08:09:28.497973 2026] [security2:error] [pid 358661:tid 358719] [remote 104.207.60.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.60.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TZwlWhjQfpOo60_Hv_QAAPTY"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:28.516751 2026] [security2:error] [pid 352421:tid 352637] [client 62.102.148.158:43530] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9TaMJSWzG9jbYOtu5fuAAAANs"]
[Tue Jul 21 08:09:28.516842 2026] [security2:error] [pid 352421:tid 352637] [client 62.102.148.158:43530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9TaMJSWzG9jbYOtu5fuAAAANs"]
[Tue Jul 21 08:09:28.594933 2026] [security2:error] [pid 358661:tid 358883] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9TaAlWhjQfpOo60_HwCQAAAFk"]
[Tue Jul 21 08:09:28.777178 2026] [security2:error] [pid 352421:tid 352667] [client 65.21.113.253:48866] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TaMJSWzG9jbYOtu5fvAAAAPk"]
[Tue Jul 21 08:09:28.844886 2026] [security2:error] [pid 358661:tid 358762] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cromobelo.com.br"] [uri "/pinfo.php"] [unique_id "al9TaAlWhjQfpOo60_HwDgAAXGE"], referer: http://cpcalendars.cromobelo.com.br/pinfo.php
[Tue Jul 21 08:09:29.120133 2026] [security2:error] [pid 358661:tid 358877] [client 20.220.225.223:1285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/la.php"] [unique_id "al9TaQlWhjQfpOo60_HwFAAAAFM"]
[Tue Jul 21 08:09:29.154610 2026] [security2:error] [pid 352421:tid 352576] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9TacJSWzG9jbYOtu5fwwAAAJ4"]
[Tue Jul 21 08:09:29.269768 2026] [security2:error] [pid 352421:tid 352558] [client 154.208.47.43:36607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TacJSWzG9jbYOtu5fxgAAAIw"]
[Tue Jul 21 08:09:29.269936 2026] [security2:error] [pid 352421:tid 352558] [client 154.208.47.43:36607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TacJSWzG9jbYOtu5fxgAAAIw"]
[Tue Jul 21 08:09:29.273119 2026] [security2:error] [pid 358661:tid 358916] [client 20.197.192.193:64492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/wpx.php"] [unique_id "al9TaQlWhjQfpOo60_HwFwAAAHo"]
[Tue Jul 21 08:09:29.526839 2026] [security2:error] [pid 358661:tid 358757] [remote 45.3.52.56:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TaQlWhjQfpOo60_HwKwAAOFw"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:29.553756 2026] [security2:error] [pid 358661:tid 358840] [client 65.21.113.253:48136] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TaQlWhjQfpOo60_HwLAAAAC4"]
[Tue Jul 21 08:09:29.614810 2026] [security2:error] [pid 358661:tid 358771] [remote 144.217.254.10:39368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.254.217.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "links.principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9TaQlWhjQfpOo60_HwMwAAH2o"]
[Tue Jul 21 08:09:29.757335 2026] [security2:error] [pid 358661:tid 358815] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9TaQlWhjQfpOo60_HwOAAAABU"]
[Tue Jul 21 08:09:29.902529 2026] [security2:error] [pid 358661:tid 358817] [client 65.21.113.253:56008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TaQlWhjQfpOo60_HwIwAAABc"]
[Tue Jul 21 08:09:30.085772 2026] [security2:error] [pid 358661:tid 358821] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9TaglWhjQfpOo60_HwPgAAABs"]
[Tue Jul 21 08:09:30.343709 2026] [security2:error] [pid 358661:tid 358881] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9TaglWhjQfpOo60_HwUAAAAFc"]
[Tue Jul 21 08:09:30.397250 2026] [security2:error] [pid 352421:tid 352619] [client 20.220.225.223:1308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9TasJSWzG9jbYOtu5f2QAAAMk"]
[Tue Jul 21 08:09:30.522417 2026] [security2:error] [pid 358661:tid 358832] [client 69.30.223.218:48430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.223.30.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-includes/adc37af5/edit.php"] [unique_id "al9TaglWhjQfpOo60_HwUwAAACY"], referer: https://aumentodevendas.factorial.studio/wp-includes/adc37af5/edit.php
[Tue Jul 21 08:09:30.650202 2026] [security2:error] [pid 358661:tid 358682] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TaglWhjQfpOo60_HwWQAAGBE"]
[Tue Jul 21 08:09:30.650370 2026] [security2:error] [pid 358661:tid 358818] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TaglWhjQfpOo60_HwWQAAGBE"]
[Tue Jul 21 08:09:30.661694 2026] [security2:error] [pid 358661:tid 358848] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9TaglWhjQfpOo60_HwWgAAADY"]
[Tue Jul 21 08:09:30.665044 2026] [security2:error] [pid 358661:tid 358814] [client 65.21.113.253:56014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TaglWhjQfpOo60_HwSAAAABQ"]
[Tue Jul 21 08:09:30.690607 2026] [security2:error] [pid 358661:tid 358692] [remote 65.111.12.217:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.12.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TaglWhjQfpOo60_HwVQAAaRs"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:30.922703 2026] [security2:error] [pid 358661:tid 358918] [client 62.102.148.158:44852] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9TaglWhjQfpOo60_HwXwAAAHw"]
[Tue Jul 21 08:09:30.922791 2026] [security2:error] [pid 358661:tid 358918] [client 62.102.148.158:44852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9TaglWhjQfpOo60_HwXwAAAHw"]
[Tue Jul 21 08:09:30.939094 2026] [security2:error] [pid 358661:tid 358858] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9TaglWhjQfpOo60_HwYQAAAEA"]
[Tue Jul 21 08:09:31.183553 2026] [security2:error] [pid 358661:tid 358813] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9TawlWhjQfpOo60_HwZAAAABM"]
[Tue Jul 21 08:09:31.338134 2026] [security2:error] [pid 358661:tid 358804] [client 20.104.96.117:63425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/loader.php"] [unique_id "al9TawlWhjQfpOo60_HwaQAAAAo"]
[Tue Jul 21 08:09:31.435341 2026] [security2:error] [pid 352421:tid 352562] [client 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Ta8JSWzG9jbYOtu5f5wAAAJA"]
[Tue Jul 21 08:09:31.459457 2026] [security2:error] [pid 358661:tid 358815] [client 20.151.10.161:4242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asholdings.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9TawlWhjQfpOo60_HwagAAABU"]
[Tue Jul 21 08:09:31.498530 2026] [security2:error] [pid 358661:tid 358916] [client 102.206.115.33:59803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TawlWhjQfpOo60_HwbAAAAHo"]
[Tue Jul 21 08:09:31.500942 2026] [security2:error] [pid 358661:tid 358916] [client 102.206.115.33:59803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TawlWhjQfpOo60_HwbAAAAHo"]
[Tue Jul 21 08:09:31.602316 2026] [security2:error] [pid 358661:tid 358795] [client 74.7.228.34:43264] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "dsoler.com.br"] [uri "/robots.txt"] [unique_id "al9TawlWhjQfpOo60_HwbQAAAAE"]
[Tue Jul 21 08:09:31.615803 2026] [security2:error] [pid 358661:tid 358808] [client 20.220.225.223:1309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/inso.php"] [unique_id "al9TawlWhjQfpOo60_HwbgAAAA4"]
[Tue Jul 21 08:09:31.735846 2026] [security2:error] [pid 358661:tid 358921] [client 20.151.10.161:4233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asholdings.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9TawlWhjQfpOo60_HwdQAAAH8"]
[Tue Jul 21 08:09:31.738283 2026] [core:error] [pid 358661:tid 358700] [remote 143.198.104.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:09:31.738300 2026] [core:error] [pid 358661:tid 358700] [remote 143.198.104.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:09:31.943828 2026] [security2:error] [pid 358661:tid 358844] [client 151.63.71.144:59992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9TawlWhjQfpOo60_HweAAAADI"]
[Tue Jul 21 08:09:31.944378 2026] [security2:error] [pid 358661:tid 358844] [client 151.63.71.144:59992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9TawlWhjQfpOo60_HweAAAADI"]
[Tue Jul 21 08:09:31.955327 2026] [security2:error] [pid 358661:tid 358819] [client 62.102.148.158:44854] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9TawlWhjQfpOo60_HweQAAABk"]
[Tue Jul 21 08:09:31.955403 2026] [security2:error] [pid 358661:tid 358819] [client 62.102.148.158:44854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9TawlWhjQfpOo60_HweQAAABk"]
[Tue Jul 21 08:09:32.010749 2026] [security2:error] [pid 358661:tid 358882] [client 20.151.10.161:4913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asholdings.com.br"] [uri "/images.php"] [unique_id "al9TbAlWhjQfpOo60_HwewAAAFg"]
[Tue Jul 21 08:09:32.075749 2026] [security2:error] [pid 358661:tid 358807] [client 86.106.84.166:55412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9TbAlWhjQfpOo60_HwgAAAAA0"]
[Tue Jul 21 08:09:32.075851 2026] [security2:error] [pid 358661:tid 358807] [client 86.106.84.166:55412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9TbAlWhjQfpOo60_HwgAAAAA0"]
[Tue Jul 21 08:09:32.098440 2026] [security2:error] [pid 358661:tid 358843] [client 41.68.90.219:63281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TbAlWhjQfpOo60_HwggAAADE"]
[Tue Jul 21 08:09:32.099551 2026] [security2:error] [pid 358661:tid 358843] [client 41.68.90.219:63281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TbAlWhjQfpOo60_HwggAAADE"]
[Tue Jul 21 08:09:32.175415 2026] [security2:error] [pid 358661:tid 358835] [client 20.29.126.15:6226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/max.php"] [unique_id "al9TbAlWhjQfpOo60_HwhAAAACk"]
[Tue Jul 21 08:09:32.230587 2026] [security2:error] [pid 352421:tid 352435] [remote 20.153.140.50:35180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/wp-login.php"] [unique_id "al9Ta8JSWzG9jbYOtu5f4wAAmw0"]
[Tue Jul 21 08:09:32.287178 2026] [security2:error] [pid 358661:tid 358874] [client 20.151.10.161:4926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asholdings.com.br"] [uri "/for.php"] [unique_id "al9TbAlWhjQfpOo60_HwjQAAAFA"]
[Tue Jul 21 08:09:32.504692 2026] [core:error] [pid 352421:tid 352470] [remote 143.198.104.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcontacts.ferlab3d.com.br/
[Tue Jul 21 08:09:32.504715 2026] [core:error] [pid 352421:tid 352470] [remote 143.198.104.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcontacts.ferlab3d.com.br/
[Tue Jul 21 08:09:32.566078 2026] [security2:error] [pid 352421:tid 352577] [client 20.151.10.161:4247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asholdings.com.br"] [uri "/2larp.php"] [unique_id "al9TbMJSWzG9jbYOtu5f-wAAAJ8"]
[Tue Jul 21 08:09:32.690059 2026] [security2:error] [pid 358661:tid 358816] [client 65.21.113.253:48136] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TbAlWhjQfpOo60_HwlQAAABY"]
[Tue Jul 21 08:09:32.841402 2026] [security2:error] [pid 352421:tid 352609] [client 20.151.10.161:4921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asholdings.com.br"] [uri "/adminner.php"] [unique_id "al9TbMJSWzG9jbYOtu5gAwAAAL8"]
[Tue Jul 21 08:09:32.942234 2026] [security2:error] [pid 358661:tid 358826] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9TbAlWhjQfpOo60_HwnAAAACA"]
[Tue Jul 21 08:09:33.030688 2026] [security2:error] [pid 352421:tid 352567] [client 150.129.202.39:64753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TbcJSWzG9jbYOtu5gBwAAAJU"]
[Tue Jul 21 08:09:33.030824 2026] [security2:error] [pid 352421:tid 352567] [client 150.129.202.39:64753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TbcJSWzG9jbYOtu5gBwAAAJU"]
[Tue Jul 21 08:09:33.124750 2026] [security2:error] [pid 352421:tid 352601] [client 20.151.10.161:4896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asholdings.com.br"] [uri "/82.php"] [unique_id "al9TbcJSWzG9jbYOtu5gCgAAALc"]
[Tue Jul 21 08:09:33.188836 2026] [security2:error] [pid 358661:tid 358851] [client 74.7.228.34:53194] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dsoler.com.br"] [uri "/index.php"] [unique_id "al9TawlWhjQfpOo60_HwegAAOUg"], referer: http://dsoler.com.br/robots.txt
[Tue Jul 21 08:09:33.232323 2026] [security2:error] [pid 352421:tid 352626] [client 109.60.28.94:16773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TbcJSWzG9jbYOtu5gDgAAANA"]
[Tue Jul 21 08:09:33.233044 2026] [security2:error] [pid 352421:tid 352626] [client 109.60.28.94:16773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TbcJSWzG9jbYOtu5gDgAAANA"]
[Tue Jul 21 08:09:33.257912 2026] [security2:error] [pid 352421:tid 352576] [client 20.220.225.223:1336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wpx.php"] [unique_id "al9TbcJSWzG9jbYOtu5gEAAAAJ4"]
[Tue Jul 21 08:09:33.296502 2026] [security2:error] [pid 358661:tid 358915] [client 65.21.113.253:56008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TbAlWhjQfpOo60_HwmwAAAHk"]
[Tue Jul 21 08:09:33.325452 2026] [security2:error] [pid 358661:tid 358868] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9TbQlWhjQfpOo60_HwoQAAAEo"]
[Tue Jul 21 08:09:33.363261 2026] [security2:error] [pid 352421:tid 352536] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TbcJSWzG9jbYOtu5gEwAA3nI"]
[Tue Jul 21 08:09:33.363419 2026] [security2:error] [pid 352421:tid 352640] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TbcJSWzG9jbYOtu5gEwAA3nI"]
[Tue Jul 21 08:09:33.388170 2026] [security2:error] [pid 358661:tid 358689] [remote 217.181.92.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.92.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TbAlWhjQfpOo60_HwhQAAWRg"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:33.410336 2026] [security2:error] [pid 358661:tid 358913] [client 20.151.10.161:4888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asholdings.com.br"] [uri "/kir.php"] [unique_id "al9TbQlWhjQfpOo60_HwowAAAHc"]
[Tue Jul 21 08:09:33.778244 2026] [security2:error] [pid 358661:tid 358780] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TbQlWhjQfpOo60_HwsAAACHM"]
[Tue Jul 21 08:09:33.778373 2026] [security2:error] [pid 358661:tid 358802] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TbQlWhjQfpOo60_HwsAAACHM"]
[Tue Jul 21 08:09:33.828089 2026] [security2:error] [pid 358661:tid 358905] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9TbQlWhjQfpOo60_HwsgAAAG8"]
[Tue Jul 21 08:09:34.287289 2026] [security2:error] [pid 358661:tid 358833] [client 20.104.96.117:62504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/spadex.php"] [unique_id "al9TbglWhjQfpOo60_HwvQAAACc"]
[Tue Jul 21 08:09:34.301911 2026] [security2:error] [pid 358661:tid 358888] [client 20.197.192.193:64460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/berlin.php"] [unique_id "al9TbglWhjQfpOo60_HwwAAAAF4"]
[Tue Jul 21 08:09:34.306852 2026] [security2:error] [pid 352421:tid 352522] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TbsJSWzG9jbYOtu5gIgAAo2Q"]
[Tue Jul 21 08:09:34.307071 2026] [security2:error] [pid 352421:tid 352581] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TbsJSWzG9jbYOtu5gIgAAo2Q"]
[Tue Jul 21 08:09:34.336138 2026] [security2:error] [pid 352421:tid 352628] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9TbsJSWzG9jbYOtu5gJAAAANI"]
[Tue Jul 21 08:09:34.435957 2026] [security2:error] [pid 358661:tid 358740] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cromobelo.com.br"] [uri "/php_version.php"] [unique_id "al9TbglWhjQfpOo60_HwxwAAcUs"], referer: http://cpcalendars.cromobelo.com.br/php_version.php
[Tue Jul 21 08:09:34.479289 2026] [security2:error] [pid 352421:tid 352580] [client 178.153.91.96:57008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.91.153.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TbsJSWzG9jbYOtu5gKgAAAKI"]
[Tue Jul 21 08:09:34.479439 2026] [security2:error] [pid 352421:tid 352580] [client 178.153.91.96:57008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TbsJSWzG9jbYOtu5gKgAAAKI"]
[Tue Jul 21 08:09:34.514259 2026] [security2:error] [pid 352421:tid 352505] [remote 104.207.60.35:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.60.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TbsJSWzG9jbYOtu5gLQAAnVM"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:34.555640 2026] [security2:error] [pid 358661:tid 358860] [client 20.220.225.223:1794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/berlin.php"] [unique_id "al9TbglWhjQfpOo60_Hw0QAAAEI"]
[Tue Jul 21 08:09:34.602505 2026] [security2:error] [pid 358661:tid 358891] [client 20.197.192.193:64471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/billur.php"] [unique_id "al9TbglWhjQfpOo60_Hw1gAAAGE"]
[Tue Jul 21 08:09:34.640598 2026] [security2:error] [pid 358661:tid 358848] [client 175.144.82.48:62458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TbglWhjQfpOo60_Hw2QAAADY"]
[Tue Jul 21 08:09:34.640745 2026] [security2:error] [pid 358661:tid 358848] [client 175.144.82.48:62458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TbglWhjQfpOo60_Hw2QAAADY"]
[Tue Jul 21 08:09:34.668171 2026] [security2:error] [pid 358661:tid 358705] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TbglWhjQfpOo60_Hw3AAAdCg"]
[Tue Jul 21 08:09:34.668336 2026] [security2:error] [pid 358661:tid 358910] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TbglWhjQfpOo60_Hw3AAAdCg"]
[Tue Jul 21 08:09:34.715319 2026] [security2:error] [pid 358661:tid 358867] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9TbglWhjQfpOo60_Hw3gAAAEk"]
[Tue Jul 21 08:09:34.750584 2026] [security2:error] [pid 358661:tid 358889] [client 65.21.113.253:48136] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TbglWhjQfpOo60_Hw4QAAAF8"]
[Tue Jul 21 08:09:34.862488 2026] [security2:error] [pid 352421:tid 352474] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TbsJSWzG9jbYOtu5gOwAAtTQ"]
[Tue Jul 21 08:09:34.862602 2026] [security2:error] [pid 352421:tid 352599] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TbsJSWzG9jbYOtu5gOwAAtTQ"]
[Tue Jul 21 08:09:34.979619 2026] [security2:error] [pid 358661:tid 358680] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TbglWhjQfpOo60_Hw6gAAYg8"]
[Tue Jul 21 08:09:34.979774 2026] [security2:error] [pid 358661:tid 358892] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TbglWhjQfpOo60_Hw6gAAYg8"]
[Tue Jul 21 08:09:35.095457 2026] [security2:error] [pid 358661:tid 358871] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9TbwlWhjQfpOo60_Hw7AAAAE0"]
[Tue Jul 21 08:09:35.162330 2026] [security2:error] [pid 358661:tid 358816] [client 20.220.225.223:1319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/billur.php"] [unique_id "al9TbwlWhjQfpOo60_Hw7QAAABY"]
[Tue Jul 21 08:09:35.213171 2026] [security2:error] [pid 352421:tid 352610] [client 185.213.175.37:6538] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.kettlebellevolution.com.br"] [uri "/"] [unique_id "al9Tb8JSWzG9jbYOtu5gQQAAAMA"]
[Tue Jul 21 08:09:35.270689 2026] [security2:error] [pid 358661:tid 358730] [remote 103.255.134.61:36980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roseoliveirarose.com.br"] [uri "/wp-login.php"] [unique_id "al9TbwlWhjQfpOo60_Hw7wAAEEE"]
[Tue Jul 21 08:09:35.445331 2026] [security2:error] [pid 352421:tid 352556] [client 65.21.113.253:56018] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TbsJSWzG9jbYOtu5gPQAAAIo"]
[Tue Jul 21 08:09:35.477451 2026] [security2:error] [pid 358661:tid 358819] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9TbwlWhjQfpOo60_Hw9wAAABk"]
[Tue Jul 21 08:09:35.627275 2026] [security2:error] [pid 358661:tid 358891] [client 74.7.228.34:53194] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dsoler.com.br"] [uri "/index.php"] [unique_id "al9TbwlWhjQfpOo60_Hw-gAAYXE"]
[Tue Jul 21 08:09:35.730953 2026] [security2:error] [pid 358661:tid 358716] [remote 45.3.41.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TbwlWhjQfpOo60_Hw-wAAVTM"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:35.882841 2026] [security2:error] [pid 358661:tid 358916] [client 65.21.113.253:56022] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TbwlWhjQfpOo60_Hw9AAAAHo"]
[Tue Jul 21 08:09:35.887527 2026] [security2:error] [pid 358661:tid 358911] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9TbwlWhjQfpOo60_Hw_gAAAHU"]
[Tue Jul 21 08:09:36.274037 2026] [security2:error] [pid 358661:tid 358830] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9TcAlWhjQfpOo60_HxBgAAACQ"]
[Tue Jul 21 08:09:36.660280 2026] [security2:error] [pid 352421:tid 352574] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9TcMJSWzG9jbYOtu5gVAAAAJw"]
[Tue Jul 21 08:09:36.869533 2026] [security2:error] [pid 352421:tid 352663] [client 103.78.200.11:56762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TcMJSWzG9jbYOtu5gVwAAAPU"]
[Tue Jul 21 08:09:36.869686 2026] [security2:error] [pid 352421:tid 352663] [client 103.78.200.11:56762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TcMJSWzG9jbYOtu5gVwAAAPU"]
[Tue Jul 21 08:09:36.894837 2026] [security2:error] [pid 358661:tid 358754] [remote 104.207.37.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.37.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TcAlWhjQfpOo60_HxDwAAIFk"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:36.924627 2026] [security2:error] [pid 358661:tid 358866] [client 87.116.180.198:13899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TcAlWhjQfpOo60_HxEgAAAEg"]
[Tue Jul 21 08:09:36.926066 2026] [security2:error] [pid 358661:tid 358866] [client 87.116.180.198:13899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TcAlWhjQfpOo60_HxEgAAAEg"]
[Tue Jul 21 08:09:37.072857 2026] [security2:error] [pid 352421:tid 352672] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9TccJSWzG9jbYOtu5gXQAAAP4"]
[Tue Jul 21 08:09:37.290202 2026] [security2:error] [pid 358661:tid 358719] [remote 47.128.63.129:20780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "institutoecommerce.com.br"] [uri "/"] [unique_id "al9TcQlWhjQfpOo60_HxGwAAfzY"]
[Tue Jul 21 08:09:37.356071 2026] [security2:error] [pid 358661:tid 358904] [client 185.213.175.37:42008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.klvviagens.com.br"] [uri "/"] [unique_id "al9TcQlWhjQfpOo60_HxHgAAAG4"]
[Tue Jul 21 08:09:37.356221 2026] [security2:error] [pid 358661:tid 358904] [client 185.213.175.37:42008] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.klvviagens.com.br"] [uri "/"] [unique_id "al9TcQlWhjQfpOo60_HxHgAAAG4"]
[Tue Jul 21 08:09:37.518281 2026] [security2:error] [pid 358661:tid 358845] [client 20.151.10.161:13279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9TcQlWhjQfpOo60_HxJgAAADM"]
[Tue Jul 21 08:09:37.702498 2026] [security2:error] [pid 358661:tid 358814] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9TcQlWhjQfpOo60_HxKwAAABQ"]
[Tue Jul 21 08:09:37.811555 2026] [security2:error] [pid 358661:tid 358897] [client 20.104.96.117:63443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/2x.php"] [unique_id "al9TcQlWhjQfpOo60_HxLAAAAGc"]
[Tue Jul 21 08:09:37.921593 2026] [security2:error] [pid 358661:tid 358818] [client 20.29.126.15:2808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/m.php"] [unique_id "al9TcQlWhjQfpOo60_HxLgAAABg"]
[Tue Jul 21 08:09:37.974690 2026] [security2:error] [pid 358661:tid 358830] [client 20.151.10.161:13301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9TcQlWhjQfpOo60_HxMAAAACQ"]
[Tue Jul 21 08:09:38.009974 2026] [security2:error] [pid 358661:tid 358686] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cromobelo.com.br"] [uri "/version.php"] [unique_id "al9TcglWhjQfpOo60_HxMgAAeBU"], referer: http://cpcalendars.cromobelo.com.br/version.php
[Tue Jul 21 08:09:38.112980 2026] [security2:error] [pid 358661:tid 358862] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9TcglWhjQfpOo60_HxNAAAAEQ"]
[Tue Jul 21 08:09:38.179701 2026] [security2:error] [pid 358661:tid 358916] [client 38.100.221.102:18166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TcglWhjQfpOo60_HxNQAAAHo"]
[Tue Jul 21 08:09:38.179795 2026] [security2:error] [pid 358661:tid 358916] [client 38.100.221.102:18166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TcglWhjQfpOo60_HxNQAAAHo"]
[Tue Jul 21 08:09:38.363109 2026] [security2:error] [pid 352421:tid 352511] [remote 65.111.25.127:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.25.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TcsJSWzG9jbYOtu5gbwAA-lk"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:38.399073 2026] [security2:error] [pid 358661:tid 358866] [client 20.151.10.161:13284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/media.php"] [unique_id "al9TcglWhjQfpOo60_HxOQAAAEg"]
[Tue Jul 21 08:09:38.492983 2026] [security2:error] [pid 352421:tid 352593] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9TcsJSWzG9jbYOtu5gcAAAAK8"]
[Tue Jul 21 08:09:38.541336 2026] [security2:error] [pid 352421:tid 352666] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TcsJSWzG9jbYOtu5gbgAA-Ds"]
[Tue Jul 21 08:09:38.612003 2026] [security2:error] [pid 358661:tid 358792] [remote 81.173.115.7:35936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9TcglWhjQfpOo60_HxPAAAVH8"]
[Tue Jul 21 08:09:38.887534 2026] [security2:error] [pid 358661:tid 358872] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9TcglWhjQfpOo60_HxQgAAAE4"]
[Tue Jul 21 08:09:38.979400 2026] [security2:error] [pid 358661:tid 358835] [client 20.151.10.161:13248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/images.php"] [unique_id "al9TcglWhjQfpOo60_HxRQAAACk"]
[Tue Jul 21 08:09:39.170540 2026] [security2:error] [pid 352421:tid 352599] [client 65.21.113.253:56018] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TcsJSWzG9jbYOtu5gcwAAALU"]
[Tue Jul 21 08:09:39.225353 2026] [security2:error] [pid 358661:tid 358741] [remote 194.164.192.228:52524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/wp-login.php"] [unique_id "al9TcglWhjQfpOo60_HxNgAAfEw"]
[Tue Jul 21 08:09:39.277614 2026] [security2:error] [pid 352421:tid 352654] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9Tc8JSWzG9jbYOtu5gfQAAAOw"]
[Tue Jul 21 08:09:39.346302 2026] [security2:error] [pid 358661:tid 358882] [client 20.151.10.161:13259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/adminner.php"] [unique_id "al9TcwlWhjQfpOo60_HxUwAAAFg"]
[Tue Jul 21 08:09:39.454663 2026] [security2:error] [pid 358661:tid 358897] [client 20.197.192.193:3099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/mimpi.php"] [unique_id "al9TcwlWhjQfpOo60_HxVgAAAGc"]
[Tue Jul 21 08:09:39.597089 2026] [security2:error] [pid 358661:tid 358763] [remote 216.26.239.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.239.26.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TcwlWhjQfpOo60_HxVQAAM2I"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:39.669138 2026] [security2:error] [pid 352421:tid 352633] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9Tc8JSWzG9jbYOtu5ggwAAANc"]
[Tue Jul 21 08:09:39.747099 2026] [security2:error] [pid 358661:tid 358819] [client 154.208.47.43:37033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TcwlWhjQfpOo60_HxYAAAABk"]
[Tue Jul 21 08:09:39.747223 2026] [security2:error] [pid 358661:tid 358819] [client 154.208.47.43:37033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TcwlWhjQfpOo60_HxYAAAABk"]
[Tue Jul 21 08:09:39.775464 2026] [security2:error] [pid 358661:tid 358834] [client 20.151.10.161:13268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/admin.php"] [unique_id "al9TcwlWhjQfpOo60_HxYQAAACg"]
[Tue Jul 21 08:09:40.131219 2026] [security2:error] [pid 358661:tid 358808] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9TdAlWhjQfpOo60_HxcQAAAA4"]
[Tue Jul 21 08:09:40.232902 2026] [security2:error] [pid 358661:tid 358918] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9TdAlWhjQfpOo60_HxdgAAAHw"]
[Tue Jul 21 08:09:40.239642 2026] [security2:error] [pid 358661:tid 358886] [client 20.151.10.161:13307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/k.php"] [unique_id "al9TdAlWhjQfpOo60_HxeAAAAFw"]
[Tue Jul 21 08:09:40.384519 2026] [security2:error] [pid 352421:tid 352544] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9TdMJSWzG9jbYOtu5gjwAA73o"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:09:40.408366 2026] [security2:error] [pid 358661:tid 358704] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9TdAlWhjQfpOo60_HxeQAAfic"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:09:40.442635 2026] [security2:error] [pid 358661:tid 358850] [client 143.244.57.118:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TdAlWhjQfpOo60_HxfAAAADg"]
[Tue Jul 21 08:09:40.469851 2026] [security2:error] [pid 352421:tid 352484] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9TdMJSWzG9jbYOtu5gkAAA0D4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:09:40.542562 2026] [autoindex:error] [pid 352421:tid 352531] [remote 45.175.115.210:51108] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/?pag=chamada_consulta
[Tue Jul 21 08:09:40.585485 2026] [security2:error] [pid 352421:tid 352449] [remote 104.207.32.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.32.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TdMJSWzG9jbYOtu5glgAAvBs"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:40.598049 2026] [security2:error] [pid 352421:tid 352513] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9TdMJSWzG9jbYOtu5glwAA-1s"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:09:40.666717 2026] [security2:error] [pid 352421:tid 352572] [client 20.151.10.161:13300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/x.php"] [unique_id "al9TdMJSWzG9jbYOtu5gmQAAAJo"]
[Tue Jul 21 08:09:40.674125 2026] [security2:error] [pid 352421:tid 352489] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9TdMJSWzG9jbYOtu5gmgAAo0M"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:09:40.721060 2026] [security2:error] [pid 352421:tid 352664] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9TdMJSWzG9jbYOtu5gnwAAAPY"]
[Tue Jul 21 08:09:40.779197 2026] [security2:error] [pid 352421:tid 352503] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9TdMJSWzG9jbYOtu5goQAA-1E"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:09:40.874502 2026] [security2:error] [pid 358661:tid 358806] [client 20.104.96.117:62523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/ctex1.php"] [unique_id "al9TdAlWhjQfpOo60_HxhgAAAAw"]
[Tue Jul 21 08:09:40.894871 2026] [security2:error] [pid 358661:tid 358773] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9TdAlWhjQfpOo60_HxiAAAVGw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:09:41.003398 2026] [security2:error] [pid 352421:tid 352621] [client 20.151.10.161:13253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wss.php"] [unique_id "al9TdcJSWzG9jbYOtu5gpAAAAMs"]
[Tue Jul 21 08:09:41.007416 2026] [security2:error] [pid 358661:tid 358901] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9TdQlWhjQfpOo60_HxjAAAAGs"]
[Tue Jul 21 08:09:41.121023 2026] [security2:error] [pid 352421:tid 352591] [client 20.220.225.223:1293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/mimpi.php"] [unique_id "al9TdcJSWzG9jbYOtu5gpwAAAK0"]
[Tue Jul 21 08:09:41.136960 2026] [security2:error] [pid 358661:tid 358857] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9TdQlWhjQfpOo60_HxkAAAAD8"]
[Tue Jul 21 08:09:41.142601 2026] [security2:error] [pid 358661:tid 358764] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9TdQlWhjQfpOo60_HxkQAABmM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:09:41.338875 2026] [security2:error] [pid 352421:tid 352573] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9TdcJSWzG9jbYOtu5grgAAAJs"]
[Tue Jul 21 08:09:41.370097 2026] [security2:error] [pid 358661:tid 358736] [remote 57.129.136.58:48034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.136.129.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kslifepro.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9TdAlWhjQfpOo60_HxcwAAHEc"], referer: https://kslifepro.com/
[Tue Jul 21 08:09:41.374021 2026] [security2:error] [pid 358661:tid 358910] [client 20.29.126.15:6724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/click.php"] [unique_id "al9TdQlWhjQfpOo60_HxlQAAAHQ"]
[Tue Jul 21 08:09:41.393792 2026] [security2:error] [pid 358661:tid 358709] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cromobelo.com.br"] [uri "/server-info.php"] [unique_id "al9TdQlWhjQfpOo60_HxlgAADiw"], referer: http://cpcalendars.cromobelo.com.br/server-info.php
[Tue Jul 21 08:09:41.409002 2026] [security2:error] [pid 352421:tid 352457] [remote 34.136.1.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.1.136.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9TdMJSWzG9jbYOtu5gjQAA-yM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:09:41.436600 2026] [security2:error] [pid 358661:tid 358917] [client 65.21.113.253:54140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TdQlWhjQfpOo60_HxmAAAAHs"]
[Tue Jul 21 08:09:41.438945 2026] [security2:error] [pid 358661:tid 358870] [client 20.151.10.161:13311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/ty.php"] [unique_id "al9TdQlWhjQfpOo60_HxmQAAAEw"]
[Tue Jul 21 08:09:41.495732 2026] [security2:error] [pid 352421:tid 352543] [remote 45.117.83.212:45330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "platinumcleaningkansas.com"] [uri "/wp-login.php"] [unique_id "al9TdcJSWzG9jbYOtu5gsQAA93k"]
[Tue Jul 21 08:09:41.520104 2026] [security2:error] [pid 358661:tid 358905] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9TdQlWhjQfpOo60_HxmgAAAG8"]
[Tue Jul 21 08:09:41.527025 2026] [security2:error] [pid 352421:tid 352524] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TdcJSWzG9jbYOtu5gsgAA-mY"]
[Tue Jul 21 08:09:41.527156 2026] [security2:error] [pid 352421:tid 352668] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TdcJSWzG9jbYOtu5gsgAA-mY"]
[Tue Jul 21 08:09:41.631842 2026] [security2:error] [pid 358661:tid 358874] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9TdQlWhjQfpOo60_HxnAAAAFA"]
[Tue Jul 21 08:09:41.727268 2026] [security2:error] [pid 358661:tid 358867] [client 20.197.192.193:64497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/cro.php"] [unique_id "al9TdQlWhjQfpOo60_HxnwAAAEk"]
[Tue Jul 21 08:09:41.874062 2026] [security2:error] [pid 358661:tid 358838] [client 20.151.10.161:13262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/155.php"] [unique_id "al9TdQlWhjQfpOo60_HxpAAAACw"]
[Tue Jul 21 08:09:41.899602 2026] [security2:error] [pid 358661:tid 358818] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9TdQlWhjQfpOo60_HxpQAAABg"]
[Tue Jul 21 08:09:41.944459 2026] [security2:error] [pid 352421:tid 352603] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9TdcJSWzG9jbYOtu5gtgAAALk"]
[Tue Jul 21 08:09:42.027676 2026] [security2:error] [pid 358661:tid 358823] [client 102.206.115.33:62652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TdglWhjQfpOo60_HxqAAAAB0"]
[Tue Jul 21 08:09:42.027804 2026] [security2:error] [pid 358661:tid 358823] [client 102.206.115.33:62652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TdglWhjQfpOo60_HxqAAAAB0"]
[Tue Jul 21 08:09:42.042294 2026] [security2:error] [pid 352421:tid 352677] [client 65.21.113.253:56018] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TdcJSWzG9jbYOtu5gswAAAQM"]
[Tue Jul 21 08:09:42.240230 2026] [security2:error] [pid 352421:tid 352649] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9TdsJSWzG9jbYOtu5gugAAAOc"]
[Tue Jul 21 08:09:42.255961 2026] [security2:error] [pid 358661:tid 358906] [client 20.220.225.223:1329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/dp.php"] [unique_id "al9TdglWhjQfpOo60_HxrQAAAHA"]
[Tue Jul 21 08:09:42.292219 2026] [security2:error] [pid 358661:tid 358712] [remote 217.181.91.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.91.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TdglWhjQfpOo60_HxqwAAXy8"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:42.331345 2026] [security2:error] [pid 352421:tid 352633] [client 20.151.10.161:13280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/ops.php"] [unique_id "al9TdsJSWzG9jbYOtu5gvQAAANc"]
[Tue Jul 21 08:09:42.376600 2026] [security2:error] [pid 358661:tid 358840] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9TdglWhjQfpOo60_HxrwAAAC4"]
[Tue Jul 21 08:09:42.444195 2026] [security2:error] [pid 358661:tid 358833] [client 20.104.96.117:63367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/edorxrr.php"] [unique_id "al9TdglWhjQfpOo60_HxsAAAACc"]
[Tue Jul 21 08:09:42.556621 2026] [security2:error] [pid 358661:tid 358916] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9TdglWhjQfpOo60_HxtAAAAHo"]
[Tue Jul 21 08:09:42.623168 2026] [security2:error] [pid 352421:tid 352607] [client 20.197.192.193:3488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/dp.php"] [unique_id "al9TdsJSWzG9jbYOtu5gwgAAAL0"]
[Tue Jul 21 08:09:42.680876 2026] [security2:error] [pid 358661:tid 358706] [remote 154.0.166.254:57274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colegioperseveranca.com"] [uri "/wp-login.php"] [unique_id "al9TdglWhjQfpOo60_HxtQAAfyk"]
[Tue Jul 21 08:09:42.727596 2026] [security2:error] [pid 358661:tid 358836] [client 20.151.10.161:13274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/ingfo.php"] [unique_id "al9TdglWhjQfpOo60_HxuAAAACo"]
[Tue Jul 21 08:09:42.778964 2026] [security2:error] [pid 358661:tid 358871] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9TdglWhjQfpOo60_HxuQAAAE0"]
[Tue Jul 21 08:09:42.791262 2026] [security2:error] [pid 358661:tid 358904] [client 41.68.90.219:63813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TdglWhjQfpOo60_HxugAAAG4"]
[Tue Jul 21 08:09:42.792374 2026] [security2:error] [pid 358661:tid 358904] [client 41.68.90.219:63813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TdglWhjQfpOo60_HxugAAAG4"]
[Tue Jul 21 08:09:42.845478 2026] [security2:error] [pid 358661:tid 358901] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9TdglWhjQfpOo60_HxvQAAAGs"]
[Tue Jul 21 08:09:43.064357 2026] [security2:error] [pid 352421:tid 352600] [client 20.151.10.161:13185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/error_log.php"] [unique_id "al9Td8JSWzG9jbYOtu5gxwAAALY"]
[Tue Jul 21 08:09:43.170064 2026] [security2:error] [pid 358661:tid 358802] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9TdwlWhjQfpOo60_HxwwAAAAg"]
[Tue Jul 21 08:09:43.181023 2026] [security2:error] [pid 358661:tid 358822] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9TdwlWhjQfpOo60_HxxAAAABw"]
[Tue Jul 21 08:09:43.376214 2026] [security2:error] [pid 358661:tid 358874] [client 20.151.10.161:13308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/ok.php"] [unique_id "al9TdwlWhjQfpOo60_HxywAAAFA"]
[Tue Jul 21 08:09:43.438598 2026] [security2:error] [pid 358661:tid 358744] [remote 209.50.165.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.165.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TdwlWhjQfpOo60_HxzQAATE8"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:43.461589 2026] [security2:error] [pid 358661:tid 358875] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9TdwlWhjQfpOo60_HxzwAAAFE"]
[Tue Jul 21 08:09:43.557639 2026] [security2:error] [pid 358661:tid 358882] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9TdwlWhjQfpOo60_Hx0AAAAFg"]
[Tue Jul 21 08:09:43.692068 2026] [security2:error] [pid 352421:tid 352570] [client 20.151.10.161:13202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/mac.php"] [unique_id "al9Td8JSWzG9jbYOtu5g0gAAAJg"]
[Tue Jul 21 08:09:43.746331 2026] [security2:error] [pid 352421:tid 352554] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Td8JSWzG9jbYOtu5g0wAAAIg"]
[Tue Jul 21 08:09:43.834151 2026] [security2:error] [pid 352421:tid 352658] [client 150.129.202.39:64670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Td8JSWzG9jbYOtu5g1QAAAPA"]
[Tue Jul 21 08:09:43.834272 2026] [security2:error] [pid 352421:tid 352658] [client 150.129.202.39:64670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Td8JSWzG9jbYOtu5g1QAAAPA"]
[Tue Jul 21 08:09:43.838073 2026] [security2:error] [pid 352421:tid 352471] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Td8JSWzG9jbYOtu5g1gAA9TE"]
[Tue Jul 21 08:09:43.838247 2026] [security2:error] [pid 352421:tid 352663] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Td8JSWzG9jbYOtu5g1gAA9TE"]
[Tue Jul 21 08:09:43.930649 2026] [security2:error] [pid 358661:tid 358794] [client 109.60.28.94:58592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TdwlWhjQfpOo60_Hx2gAAAAA"]
[Tue Jul 21 08:09:43.930843 2026] [security2:error] [pid 358661:tid 358794] [client 109.60.28.94:58592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TdwlWhjQfpOo60_Hx2gAAAAA"]
[Tue Jul 21 08:09:43.959475 2026] [security2:error] [pid 352421:tid 352672] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9Td8JSWzG9jbYOtu5g2wAAAP4"]
[Tue Jul 21 08:09:43.971828 2026] [security2:error] [pid 358661:tid 358887] [client 20.220.225.223:1812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/bootstrap.php"] [unique_id "al9TdwlWhjQfpOo60_Hx3AAAAF0"]
[Tue Jul 21 08:09:44.037325 2026] [security2:error] [pid 358661:tid 358843] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9TeAlWhjQfpOo60_Hx4gAAADE"]
[Tue Jul 21 08:09:44.103777 2026] [security2:error] [pid 358661:tid 358853] [client 61.1.167.83:59371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TeAlWhjQfpOo60_Hx5QAAADs"]
[Tue Jul 21 08:09:44.103903 2026] [security2:error] [pid 358661:tid 358853] [client 61.1.167.83:59371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TeAlWhjQfpOo60_Hx5QAAADs"]
[Tue Jul 21 08:09:44.151361 2026] [security2:error] [pid 352421:tid 352655] [client 20.151.10.161:13283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wefile.php"] [unique_id "al9TeMJSWzG9jbYOtu5g4QAAAO0"]
[Tue Jul 21 08:09:44.205125 2026] [security2:error] [pid 358661:tid 358786] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cromobelo.com.br"] [uri "/env.php"] [unique_id "al9TeAlWhjQfpOo60_Hx6AAAKnk"], referer: http://cpcalendars.cromobelo.com.br/env.php
[Tue Jul 21 08:09:44.340394 2026] [security2:error] [pid 352421:tid 352608] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9TeMJSWzG9jbYOtu5g5AAAAL4"]
[Tue Jul 21 08:09:44.351029 2026] [security2:error] [pid 358661:tid 358852] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9TeAlWhjQfpOo60_Hx8gAAADo"]
[Tue Jul 21 08:09:44.396991 2026] [security2:error] [pid 358661:tid 358765] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cromobelo.com.br"] [uri "/init.php"] [unique_id "al9TeAlWhjQfpOo60_Hx9wAAaWQ"], referer: http://cpcalendars.cromobelo.com.br/init.php
[Tue Jul 21 08:09:44.465050 2026] [security2:error] [pid 358661:tid 358740] [remote 45.3.34.133:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.34.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TeAlWhjQfpOo60_Hx-gAANks"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:44.467205 2026] [security2:error] [pid 358661:tid 358783] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TeAlWhjQfpOo60_Hx-wAAa3Y"]
[Tue Jul 21 08:09:44.467319 2026] [security2:error] [pid 358661:tid 358901] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TeAlWhjQfpOo60_Hx-wAAa3Y"]
[Tue Jul 21 08:09:44.479866 2026] [security2:error] [pid 358661:tid 358827] [client 20.151.10.161:13200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9TeAlWhjQfpOo60_Hx_AAAACE"]
[Tue Jul 21 08:09:44.646482 2026] [security2:error] [pid 358661:tid 358855] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9TeAlWhjQfpOo60_Hx_gAAAD0"]
[Tue Jul 21 08:09:44.710880 2026] [security2:error] [pid 358661:tid 358666] [remote 199.189.225.40:37193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moratoadvogado.com"] [uri "/wp-login.php"] [unique_id "al9TeAlWhjQfpOo60_Hx_wAAbgE"]
[Tue Jul 21 08:09:44.736479 2026] [security2:error] [pid 358661:tid 358845] [client 20.220.225.223:1333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wp-editor.php"] [unique_id "al9TeAlWhjQfpOo60_HyAAAAADM"]
[Tue Jul 21 08:09:44.741315 2026] [security2:error] [pid 358661:tid 358892] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9TeAlWhjQfpOo60_HyAgAAAGI"]
[Tue Jul 21 08:09:44.894032 2026] [proxy:error] [pid 352421:tid 352627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:44.894081 2026] [proxy_http:error] [pid 352421:tid 352627] [client 20.151.10.161:13277] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:44.894564 2026] [proxy:error] [pid 352421:tid 352627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:44.894596 2026] [proxy_http:error] [pid 352421:tid 352627] [client 20.151.10.161:13277] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:44.949724 2026] [security2:error] [pid 358661:tid 358895] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9TeAlWhjQfpOo60_HyBgAAAGU"]
[Tue Jul 21 08:09:44.994410 2026] [security2:error] [pid 358661:tid 358805] [client 65.21.113.253:54140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TeAlWhjQfpOo60_HyBwAAAAs"]
[Tue Jul 21 08:09:45.081685 2026] [security2:error] [pid 358661:tid 358725] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TeQlWhjQfpOo60_HyCAAAFTw"]
[Tue Jul 21 08:09:45.081858 2026] [security2:error] [pid 358661:tid 358815] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TeQlWhjQfpOo60_HyCAAAFTw"]
[Tue Jul 21 08:09:45.084475 2026] [security2:error] [pid 358661:tid 358888] [client 20.29.126.15:6737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/lv.php"] [unique_id "al9TeQlWhjQfpOo60_HyCQAAAF4"]
[Tue Jul 21 08:09:45.126653 2026] [security2:error] [pid 358661:tid 358825] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9TeQlWhjQfpOo60_HyCgAAAB8"]
[Tue Jul 21 08:09:45.159937 2026] [security2:error] [pid 358661:tid 358853] [client 20.220.225.223:1810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/cro.php"] [unique_id "al9TeQlWhjQfpOo60_HyCwAAADs"]
[Tue Jul 21 08:09:45.193602 2026] [security2:error] [pid 358661:tid 358831] [client 175.144.82.48:62919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TeQlWhjQfpOo60_HyDgAAACU"]
[Tue Jul 21 08:09:45.193898 2026] [security2:error] [pid 358661:tid 358831] [client 175.144.82.48:62919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TeQlWhjQfpOo60_HyDgAAACU"]
[Tue Jul 21 08:09:45.232835 2026] [security2:error] [pid 358661:tid 358836] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9TeQlWhjQfpOo60_HyEAAAACo"]
[Tue Jul 21 08:09:45.327188 2026] [proxy:error] [pid 358661:tid 358877] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:45.327291 2026] [proxy_http:error] [pid 358661:tid 358877] [client 20.151.10.161:13309] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:45.329455 2026] [proxy:error] [pid 358661:tid 358877] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:45.329514 2026] [proxy_http:error] [pid 358661:tid 358877] [client 20.151.10.161:13309] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:45.403779 2026] [security2:error] [pid 358661:tid 358711] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TeQlWhjQfpOo60_HyFwAAQy4"]
[Tue Jul 21 08:09:45.403946 2026] [security2:error] [pid 358661:tid 358861] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TeQlWhjQfpOo60_HyFwAAQy4"]
[Tue Jul 21 08:09:45.512164 2026] [security2:error] [pid 352421:tid 352677] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9TecJSWzG9jbYOtu5g-AAAAQM"]
[Tue Jul 21 08:09:45.543661 2026] [security2:error] [pid 352421:tid 352620] [client 143.244.57.118:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9TecJSWzG9jbYOtu5g-QAAAMo"]
[Tue Jul 21 08:09:45.564753 2026] [security2:error] [pid 358661:tid 358822] [client 162.219.176.3:52034] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9TeQlWhjQfpOo60_HyGgAAABw"]
[Tue Jul 21 08:09:45.564869 2026] [security2:error] [pid 358661:tid 358822] [client 162.219.176.3:52034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9TeQlWhjQfpOo60_HyGgAAABw"]
[Tue Jul 21 08:09:45.596621 2026] [security2:error] [pid 352421:tid 352632] [client 20.197.192.193:3087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/bootstrap.php"] [unique_id "al9TecJSWzG9jbYOtu5g-wAAANY"]
[Tue Jul 21 08:09:45.688102 2026] [security2:error] [pid 358661:tid 358694] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TeQlWhjQfpOo60_HyHQAANB0"]
[Tue Jul 21 08:09:45.688286 2026] [security2:error] [pid 358661:tid 358846] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TeQlWhjQfpOo60_HyHQAANB0"]
[Tue Jul 21 08:09:45.706100 2026] [security2:error] [pid 352421:tid 352607] [client 20.151.10.161:13136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9TecJSWzG9jbYOtu5hAQAAAL0"]
[Tue Jul 21 08:09:45.769071 2026] [security2:error] [pid 352421:tid 352645] [client 86.106.84.166:59782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9TecJSWzG9jbYOtu5hBAAAAOM"]
[Tue Jul 21 08:09:45.769188 2026] [security2:error] [pid 352421:tid 352645] [client 86.106.84.166:59782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9TecJSWzG9jbYOtu5hBAAAAOM"]
[Tue Jul 21 08:09:45.795634 2026] [security2:error] [pid 358661:tid 358851] [client 65.21.113.253:58240] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TeQlWhjQfpOo60_HyEwAAADk"]
[Tue Jul 21 08:09:45.900153 2026] [security2:error] [pid 358661:tid 358848] [client 91.230.225.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.muriloscapin1746469575000.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9TeQlWhjQfpOo60_HyIwAAADY"]
[Tue Jul 21 08:09:45.907897 2026] [security2:error] [pid 358661:tid 358901] [client 20.197.192.193:39259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/cron-tab.php"] [unique_id "al9TeQlWhjQfpOo60_HyJAAAAGs"]
[Tue Jul 21 08:09:46.048767 2026] [security2:error] [pid 358661:tid 358814] [client 162.219.176.3:52358] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9TeglWhjQfpOo60_HyKgAAABQ"]
[Tue Jul 21 08:09:46.048880 2026] [security2:error] [pid 358661:tid 358814] [client 162.219.176.3:52358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9TeglWhjQfpOo60_HyKgAAABQ"]
[Tue Jul 21 08:09:46.058213 2026] [security2:error] [pid 352421:tid 352603] [client 65.21.113.253:58252] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TecJSWzG9jbYOtu5g_wAAALk"]
[Tue Jul 21 08:09:46.134089 2026] [security2:error] [pid 358661:tid 358680] [remote 209.50.185.11:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.185.50.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-login.php"] [unique_id "al9TeQlWhjQfpOo60_HyKAAAYA8"], referer: https://shopmelhorcompraonline.com/wp-login.php
[Tue Jul 21 08:09:46.310975 2026] [proxy:error] [pid 358661:tid 358833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:46.311083 2026] [proxy_http:error] [pid 358661:tid 358833] [client 20.151.10.161:13272] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:46.312945 2026] [proxy:error] [pid 358661:tid 358833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:46.313140 2026] [proxy_http:error] [pid 358661:tid 358833] [client 20.151.10.161:13272] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:46.458228 2026] [security2:error] [pid 358661:tid 358716] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TeglWhjQfpOo60_HyNAAAZTM"]
[Tue Jul 21 08:09:46.458364 2026] [security2:error] [pid 358661:tid 358895] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TeglWhjQfpOo60_HyNAAAZTM"]
[Tue Jul 21 08:09:46.706268 2026] [security2:error] [pid 352421:tid 352674] [client 20.220.225.223:1305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/cron-tab.php"] [unique_id "al9TesJSWzG9jbYOtu5hEwAAAQA"]
[Tue Jul 21 08:09:46.858311 2026] [security2:error] [pid 358661:tid 358821] [client 20.104.96.117:54110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9TeglWhjQfpOo60_HyPgAAABs"]
[Tue Jul 21 08:09:46.976332 2026] [security2:error] [pid 358661:tid 358905] [client 20.151.10.161:13263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/like.php"] [unique_id "al9TeglWhjQfpOo60_HyQQAAAG8"]
[Tue Jul 21 08:09:47.257298 2026] [security2:error] [pid 358661:tid 358896] [client 20.104.96.117:62480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/miru1.php"] [unique_id "al9TewlWhjQfpOo60_HySwAAAGY"]
[Tue Jul 21 08:09:47.474527 2026] [security2:error] [pid 358661:tid 358781] [remote 124.55.178.99:36418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "precisosolucao.com.br"] [uri "/wp-login.php"] [unique_id "al9TewlWhjQfpOo60_HyUQAADHQ"]
[Tue Jul 21 08:09:47.572408 2026] [autoindex:error] [pid 352421:tid 352502] [remote 45.175.115.210:51108] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/?pag=chamada_consulta&filtro_alu=&filtro_mes=&filtro_ano=&pag_ano=2
[Tue Jul 21 08:09:47.598699 2026] [security2:error] [pid 358661:tid 358874] [client 87.116.180.198:13827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TewlWhjQfpOo60_HyWAAAAFA"]
[Tue Jul 21 08:09:47.598783 2026] [security2:error] [pid 358661:tid 358874] [client 87.116.180.198:13827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TewlWhjQfpOo60_HyWAAAAFA"]
[Tue Jul 21 08:09:47.599352 2026] [security2:error] [pid 358661:tid 358919] [client 65.21.113.253:54140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TewlWhjQfpOo60_HyVwAAAH0"]
[Tue Jul 21 08:09:47.689223 2026] [autoindex:error] [pid 352421:tid 352656] [client 32.192.53.254:43466] AH01276: Cannot serve directory /home2/silv4569/silviolevada.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:09:47.777867 2026] [security2:error] [pid 358661:tid 358846] [client 20.151.10.161:13254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/.well-known/about.php"] [unique_id "al9TewlWhjQfpOo60_HyZwAAADQ"]
[Tue Jul 21 08:09:47.811101 2026] [autoindex:error] [pid 352421:tid 352608] [client 32.192.53.254:38540] AH01276: Cannot serve directory /home2/silv4569/silviolevada.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:09:48.055915 2026] [security2:error] [pid 358661:tid 358892] [client 216.244.66.199:34412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.brlead.com.br"] [uri "/robots.txt"] [unique_id "al9TfAlWhjQfpOo60_HygAAAAGI"]
[Tue Jul 21 08:09:48.055991 2026] [security2:error] [pid 358661:tid 358892] [client 216.244.66.199:34412] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.brlead.com.br"] [uri "/robots.txt"] [unique_id "al9TfAlWhjQfpOo60_HygAAAAGI"]
[Tue Jul 21 08:09:48.231620 2026] [security2:error] [pid 358661:tid 358824] [client 65.21.113.253:58240] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TewlWhjQfpOo60_HyawAAAB4"]
[Tue Jul 21 08:09:48.297055 2026] [security2:error] [pid 358661:tid 358857] [client 20.104.96.117:57969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/xwpg.php"] [unique_id "al9TfAlWhjQfpOo60_HyhAAAAD8"]
[Tue Jul 21 08:09:48.597844 2026] [security2:error] [pid 358661:tid 358891] [client 20.151.10.161:13285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9TfAlWhjQfpOo60_HyiwAAAGE"]
[Tue Jul 21 08:09:48.667933 2026] [security2:error] [pid 358661:tid 358855] [client 20.29.126.15:16525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/cong.php"] [unique_id "al9TfAlWhjQfpOo60_HykAAAAD0"]
[Tue Jul 21 08:09:48.728468 2026] [security2:error] [pid 358661:tid 358919] [client 38.100.221.102:18281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TfAlWhjQfpOo60_HykQAAAH0"]
[Tue Jul 21 08:09:48.728645 2026] [security2:error] [pid 358661:tid 358919] [client 38.100.221.102:18281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TfAlWhjQfpOo60_HykQAAAH0"]
[Tue Jul 21 08:09:48.845469 2026] [security2:error] [pid 358661:tid 358757] [remote 154.61.75.100:46440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9TfAlWhjQfpOo60_HylQAAA1w"]
[Tue Jul 21 08:09:49.037679 2026] [security2:error] [pid 358661:tid 358807] [client 86.106.84.166:59786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9TfQlWhjQfpOo60_HylwAAAA0"]
[Tue Jul 21 08:09:49.037768 2026] [security2:error] [pid 358661:tid 358807] [client 86.106.84.166:59786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9TfQlWhjQfpOo60_HylwAAAA0"]
[Tue Jul 21 08:09:49.181671 2026] [security2:error] [pid 352421:tid 352607] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TfcJSWzG9jbYOtu5hPgAAvQY"]
[Tue Jul 21 08:09:49.248458 2026] [proxy:error] [pid 358661:tid 358918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:49.248545 2026] [proxy_http:error] [pid 358661:tid 358918] [client 20.151.10.161:13264] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:49.250054 2026] [proxy:error] [pid 358661:tid 358918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:49.250112 2026] [proxy_http:error] [pid 358661:tid 358918] [client 20.151.10.161:13264] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:49.421580 2026] [security2:error] [pid 358661:tid 358889] [client 20.197.192.193:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/wp-editor.php"] [unique_id "al9TfQlWhjQfpOo60_HypQAAAF8"]
[Tue Jul 21 08:09:49.480796 2026] [security2:error] [pid 358661:tid 358884] [client 62.102.148.158:58136] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9TfQlWhjQfpOo60_HypgAAAFo"]
[Tue Jul 21 08:09:49.480887 2026] [security2:error] [pid 358661:tid 358884] [client 62.102.148.158:58136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9TfQlWhjQfpOo60_HypgAAAFo"]
[Tue Jul 21 08:09:49.594319 2026] [proxy:error] [pid 358661:tid 358890] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:49.594397 2026] [proxy_http:error] [pid 358661:tid 358890] [client 20.151.10.161:13199] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:49.595033 2026] [proxy:error] [pid 358661:tid 358890] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:49.595062 2026] [proxy_http:error] [pid 358661:tid 358890] [client 20.151.10.161:13199] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:49.710924 2026] [security2:error] [pid 358661:tid 358753] [remote 45.146.54.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.54.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-login.php"] [unique_id "al9TfQlWhjQfpOo60_HypwAAFFg"]
[Tue Jul 21 08:09:49.765765 2026] [security2:error] [pid 358661:tid 358695] [remote 49.13.1.223:58012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zooparquevet.com.br"] [uri "/wp-login.php"] [unique_id "al9TfQlWhjQfpOo60_HyrgAAfh4"]
[Tue Jul 21 08:09:49.886774 2026] [security2:error] [pid 358661:tid 358837] [client 65.21.113.253:54140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TfQlWhjQfpOo60_HysAAAACs"]
[Tue Jul 21 08:09:49.907700 2026] [security2:error] [pid 358661:tid 358901] [client 20.151.10.161:13195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/pucci.php"] [unique_id "al9TfQlWhjQfpOo60_HysQAAAGs"]
[Tue Jul 21 08:09:50.046132 2026] [security2:error] [pid 358661:tid 358921] [client 162.219.176.3:50440] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9TfglWhjQfpOo60_HytgAAAH8"]
[Tue Jul 21 08:09:50.046226 2026] [security2:error] [pid 358661:tid 358921] [client 162.219.176.3:50440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9TfglWhjQfpOo60_HytgAAAH8"]
[Tue Jul 21 08:09:50.244307 2026] [security2:error] [pid 358661:tid 358839] [client 103.221.220.62:55538] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sulmov.com"] [uri "/new/.env"] [unique_id "al9TfglWhjQfpOo60_HyugAAAC0"]
[Tue Jul 21 08:09:50.244596 2026] [security2:error] [pid 358661:tid 358847] [client 103.221.220.62:55484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sulmov.com"] [uri "/app/.env"] [unique_id "al9TfglWhjQfpOo60_HyuwAAADU"]
[Tue Jul 21 08:09:50.245165 2026] [security2:error] [pid 358661:tid 358810] [client 103.221.220.62:55564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sulmov.com"] [uri "/bank/.env"] [unique_id "al9TfglWhjQfpOo60_HyvAAAABA"]
[Tue Jul 21 08:09:50.246135 2026] [security2:error] [pid 352421:tid 352597] [client 103.221.220.62:55500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sulmov.com"] [uri "/core/.env"] [unique_id "al9TfsJSWzG9jbYOtu5hTgAAALM"]
[Tue Jul 21 08:09:50.247536 2026] [security2:error] [pid 358661:tid 358822] [client 103.221.220.62:55508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sulmov.com"] [uri "/backend/.env"] [unique_id "al9TfglWhjQfpOo60_HyvQAAABw"]
[Tue Jul 21 08:09:50.308802 2026] [security2:error] [pid 358661:tid 358820] [client 62.102.148.158:58148] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9TfglWhjQfpOo60_HyvwAAABo"]
[Tue Jul 21 08:09:50.309042 2026] [security2:error] [pid 358661:tid 358820] [client 62.102.148.158:58148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9TfglWhjQfpOo60_HyvwAAABo"]
[Tue Jul 21 08:09:50.311155 2026] [security2:error] [pid 358661:tid 358887] [client 154.208.47.43:37465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TfglWhjQfpOo60_HywAAAAF0"]
[Tue Jul 21 08:09:50.311445 2026] [security2:error] [pid 358661:tid 358887] [client 154.208.47.43:37465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TfglWhjQfpOo60_HywAAAAF0"]
[Tue Jul 21 08:09:50.441973 2026] [security2:error] [pid 358661:tid 358832] [client 103.221.220.62:55548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sulmov.com"] [uri "/member/.env"] [unique_id "al9TfglWhjQfpOo60_HywwAAACY"]
[Tue Jul 21 08:09:50.446208 2026] [security2:error] [pid 358661:tid 358857] [client 103.221.220.62:55524] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sulmov.com"] [uri "/api/.env"] [unique_id "al9TfglWhjQfpOo60_HyxAAAAD8"]
[Tue Jul 21 08:09:50.456043 2026] [security2:error] [pid 358661:tid 358917] [client 198.54.129.60:58578] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9TfglWhjQfpOo60_HyvgAAAHs"]
[Tue Jul 21 08:09:50.456229 2026] [security2:error] [pid 358661:tid 358917] [client 198.54.129.60:58578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9TfglWhjQfpOo60_HyvgAAAHs"]
[Tue Jul 21 08:09:50.466708 2026] [proxy:error] [pid 358661:tid 358886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:50.466787 2026] [proxy_http:error] [pid 358661:tid 358886] [client 20.151.10.161:13191] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:50.467376 2026] [proxy:error] [pid 358661:tid 358886] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:50.467411 2026] [proxy_http:error] [pid 358661:tid 358886] [client 20.151.10.161:13191] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:50.478842 2026] [security2:error] [pid 352421:tid 352578] [client 20.220.225.223:1817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/koiy.php"] [unique_id "al9TfsJSWzG9jbYOtu5hUQAAAKA"]
[Tue Jul 21 08:09:50.553482 2026] [security2:error] [pid 358661:tid 358859] [client 20.104.96.117:62561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/sump1.php"] [unique_id "al9TfglWhjQfpOo60_HyxwAAAEE"]
[Tue Jul 21 08:09:50.587504 2026] [security2:error] [pid 352421:tid 352570] [client 65.21.113.253:46550] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TfsJSWzG9jbYOtu5hSAAAAJg"]
[Tue Jul 21 08:09:50.784384 2026] [proxy:error] [pid 352421:tid 352551] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:50.784475 2026] [proxy_http:error] [pid 352421:tid 352551] [client 20.151.10.161:13187] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:50.785378 2026] [proxy:error] [pid 352421:tid 352551] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:50.785441 2026] [proxy_http:error] [pid 352421:tid 352551] [client 20.151.10.161:13187] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:50.800598 2026] [proxy:error] [pid 352421:tid 352491] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:50.800666 2026] [proxy_http:error] [pid 352421:tid 352491] [remote 176.65.132.57:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.cromobelo.com.br/.env.bak
[Tue Jul 21 08:09:50.801447 2026] [proxy:error] [pid 352421:tid 352491] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:50.801493 2026] [proxy_http:error] [pid 352421:tid 352491] [remote 176.65.132.57:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.cromobelo.com.br/.env.bak
[Tue Jul 21 08:09:50.993431 2026] [security2:error] [pid 358661:tid 358801] [client 65.21.113.253:46566] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TfglWhjQfpOo60_HyyQAAAAc"]
[Tue Jul 21 08:09:51.001809 2026] [security2:error] [pid 352421:tid 352635] [client 20.197.192.193:39235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/koiy.php"] [unique_id "al9Tf8JSWzG9jbYOtu5hXwAAANk"]
[Tue Jul 21 08:09:51.147341 2026] [security2:error] [pid 358661:tid 358905] [client 103.221.220.62:55572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sulmov.com"] [uri "/.env"] [unique_id "al9TfwlWhjQfpOo60_HyzgAAAG8"]
[Tue Jul 21 08:09:51.217386 2026] [security2:error] [pid 358661:tid 358867] [client 20.151.10.161:13287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wp-temp.php"] [unique_id "al9TfwlWhjQfpOo60_HyzwAAAEk"]
[Tue Jul 21 08:09:51.563068 2026] [proxy:error] [pid 352421:tid 352592] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:51.563129 2026] [proxy_http:error] [pid 352421:tid 352592] [client 20.151.10.161:13250] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:51.563610 2026] [proxy:error] [pid 352421:tid 352592] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:51.563638 2026] [proxy_http:error] [pid 352421:tid 352592] [client 20.151.10.161:13250] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:51.747194 2026] [security2:error] [pid 352421:tid 352619] [client 20.104.96.117:54709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Tf8JSWzG9jbYOtu5hbAAAAMk"]
[Tue Jul 21 08:09:51.762482 2026] [security2:error] [pid 358661:tid 358897] [client 20.29.126.15:16549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/brand.php"] [unique_id "al9TfwlWhjQfpOo60_Hy2gAAAGc"]
[Tue Jul 21 08:09:51.880737 2026] [security2:error] [pid 358661:tid 358739] [remote 100.42.189.89:59776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goldentrips40.com"] [uri "/wp-login.php"] [unique_id "al9TfwlWhjQfpOo60_Hy2wAAUUo"]
[Tue Jul 21 08:09:52.067918 2026] [security2:error] [pid 352421:tid 352624] [client 86.106.84.166:54264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9TgMJSWzG9jbYOtu5hcQAAAM4"]
[Tue Jul 21 08:09:52.068027 2026] [security2:error] [pid 352421:tid 352624] [client 86.106.84.166:54264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9TgMJSWzG9jbYOtu5hcQAAAM4"]
[Tue Jul 21 08:09:52.159580 2026] [security2:error] [pid 352421:tid 352639] [client 20.151.10.161:13130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/xmu.php"] [unique_id "al9TgMJSWzG9jbYOtu5hdQAAAN0"]
[Tue Jul 21 08:09:52.477379 2026] [security2:error] [pid 352421:tid 352626] [client 102.206.115.33:63443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TgMJSWzG9jbYOtu5hewAAANA"]
[Tue Jul 21 08:09:52.477486 2026] [security2:error] [pid 352421:tid 352626] [client 102.206.115.33:63443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TgMJSWzG9jbYOtu5hewAAANA"]
[Tue Jul 21 08:09:52.579990 2026] [security2:error] [pid 358661:tid 358910] [client 20.151.10.161:13252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9TgAlWhjQfpOo60_Hy6gAAAHQ"]
[Tue Jul 21 08:09:52.580664 2026] [security2:error] [pid 358661:tid 358708] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TgAlWhjQfpOo60_Hy6QAAaSs"]
[Tue Jul 21 08:09:52.580882 2026] [security2:error] [pid 358661:tid 358899] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TgAlWhjQfpOo60_Hy6QAAaSs"]
[Tue Jul 21 08:09:52.955346 2026] [security2:error] [pid 352421:tid 352606] [client 86.106.84.166:47284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9TgMJSWzG9jbYOtu5hiAAAALw"]
[Tue Jul 21 08:09:52.955440 2026] [security2:error] [pid 352421:tid 352606] [client 86.106.84.166:47284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9TgMJSWzG9jbYOtu5hiAAAALw"]
[Tue Jul 21 08:09:53.064948 2026] [security2:error] [pid 358661:tid 358905] [client 20.151.10.161:13265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/puc.php"] [unique_id "al9TgQlWhjQfpOo60_HzEwAAAG8"]
[Tue Jul 21 08:09:53.098192 2026] [security2:error] [pid 358661:tid 358836] [client 151.63.71.144:61064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9TgQlWhjQfpOo60_HzFAAAACo"]
[Tue Jul 21 08:09:53.098342 2026] [security2:error] [pid 358661:tid 358836] [client 151.63.71.144:61064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9TgQlWhjQfpOo60_HzFAAAACo"]
[Tue Jul 21 08:09:53.239014 2026] [security2:error] [pid 358661:tid 358829] [client 20.197.192.193:64470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/cro.php"] [unique_id "al9TgQlWhjQfpOo60_HzIAAAACM"]
[Tue Jul 21 08:09:53.613256 2026] [security2:error] [pid 352421:tid 352621] [client 20.197.192.193:3076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/hp2.php"] [unique_id "al9TgcJSWzG9jbYOtu5hlAAAAMs"]
[Tue Jul 21 08:09:53.837313 2026] [security2:error] [pid 358661:tid 358857] [client 20.151.10.161:13229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/themes.php"] [unique_id "al9TgQlWhjQfpOo60_HzKwAAAD8"]
[Tue Jul 21 08:09:53.869102 2026] [security2:error] [pid 358661:tid 358809] [client 120.56.162.40:64690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TgQlWhjQfpOo60_HzMgAAAA8"]
[Tue Jul 21 08:09:53.869209 2026] [security2:error] [pid 358661:tid 358809] [client 120.56.162.40:64690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TgQlWhjQfpOo60_HzMgAAAA8"]
[Tue Jul 21 08:09:53.936688 2026] [security2:error] [pid 358661:tid 358904] [client 20.104.96.117:54098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/xyn.php"] [unique_id "al9TgQlWhjQfpOo60_HzNwAAAG4"]
[Tue Jul 21 08:09:54.110365 2026] [security2:error] [pid 352421:tid 352655] [client 66.179.30.133:55998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "wenith.com.br"] [uri "/"] [unique_id "al9TgsJSWzG9jbYOtu5hnQAAAO0"]
[Tue Jul 21 08:09:54.197652 2026] [security2:error] [pid 358661:tid 358820] [client 14.97.58.74:7338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9TgAlWhjQfpOo60_Hy3gAAABo"]
[Tue Jul 21 08:09:54.197850 2026] [security2:error] [pid 358661:tid 358820] [client 14.97.58.74:7338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9TgAlWhjQfpOo60_Hy3gAAABo"]
[Tue Jul 21 08:09:54.275858 2026] [security2:error] [pid 358661:tid 358915] [client 41.68.90.219:64278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TgglWhjQfpOo60_HzPwAAAHk"]
[Tue Jul 21 08:09:54.276131 2026] [security2:error] [pid 358661:tid 358915] [client 41.68.90.219:64278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TgglWhjQfpOo60_HzPwAAAHk"]
[Tue Jul 21 08:09:54.333286 2026] [security2:error] [pid 358661:tid 358671] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TgglWhjQfpOo60_HzQQAAWgY"]
[Tue Jul 21 08:09:54.333530 2026] [security2:error] [pid 358661:tid 358884] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TgglWhjQfpOo60_HzQQAAWgY"]
[Tue Jul 21 08:09:54.475259 2026] [security2:error] [pid 358661:tid 358794] [client 150.129.202.39:65279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TgglWhjQfpOo60_HzRAAAAAA"]
[Tue Jul 21 08:09:54.475400 2026] [security2:error] [pid 358661:tid 358794] [client 150.129.202.39:65279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TgglWhjQfpOo60_HzRAAAAAA"]
[Tue Jul 21 08:09:54.485081 2026] [security2:error] [pid 358661:tid 358833] [client 20.104.96.117:63366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/file5.php"] [unique_id "al9TgglWhjQfpOo60_HzRwAAACc"]
[Tue Jul 21 08:09:54.546401 2026] [security2:error] [pid 352421:tid 352568] [client 65.21.113.253:46550] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TgsJSWzG9jbYOtu5hmwAAAJY"]
[Tue Jul 21 08:09:54.577287 2026] [proxy:error] [pid 352421:tid 352653] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:54.577369 2026] [proxy_http:error] [pid 352421:tid 352653] [client 20.151.10.161:13273] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:54.577935 2026] [proxy:error] [pid 352421:tid 352653] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:54.577966 2026] [proxy_http:error] [pid 352421:tid 352653] [client 20.151.10.161:13273] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:09:54.639536 2026] [security2:error] [pid 352421:tid 352592] [client 20.220.225.223:1809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/hp2.php"] [unique_id "al9TgsJSWzG9jbYOtu5hpgAAAK4"]
[Tue Jul 21 08:09:54.699838 2026] [security2:error] [pid 352421:tid 352611] [client 109.60.28.94:17707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TgsJSWzG9jbYOtu5hqAAAAME"]
[Tue Jul 21 08:09:54.700611 2026] [security2:error] [pid 352421:tid 352611] [client 109.60.28.94:17707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TgsJSWzG9jbYOtu5hqAAAAME"]
[Tue Jul 21 08:09:55.147878 2026] [security2:error] [pid 358661:tid 358790] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TgwlWhjQfpOo60_HzWwAAEH0"]
[Tue Jul 21 08:09:55.147997 2026] [security2:error] [pid 358661:tid 358810] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TgwlWhjQfpOo60_HzWwAAEH0"]
[Tue Jul 21 08:09:55.472846 2026] [security2:error] [pid 358661:tid 358820] [client 20.151.10.161:13310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/8.php"] [unique_id "al9TgwlWhjQfpOo60_HzaQAAABo"]
[Tue Jul 21 08:09:55.495927 2026] [autoindex:error] [pid 358661:tid 358779] [remote 17.22.237.229:59204] AH01276: Cannot serve directory /home1/ofic8899/go-wideoffer.store/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:09:55.558169 2026] [proxy:error] [pid 352421:tid 352463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:55.558237 2026] [proxy_http:error] [pid 352421:tid 352463] [remote 176.65.132.57:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.cromobelo.com.br/backup_web_config.txt
[Tue Jul 21 08:09:55.558832 2026] [proxy:error] [pid 352421:tid 352463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:09:55.558862 2026] [proxy_http:error] [pid 352421:tid 352463] [remote 176.65.132.57:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.cromobelo.com.br/backup_web_config.txt
[Tue Jul 21 08:09:55.653433 2026] [security2:error] [pid 352421:tid 352488] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Tg8JSWzG9jbYOtu5htgAA80I"]
[Tue Jul 21 08:09:55.653612 2026] [security2:error] [pid 352421:tid 352661] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Tg8JSWzG9jbYOtu5htgAA80I"]
[Tue Jul 21 08:09:55.669520 2026] [security2:error] [pid 352421:tid 352556] [client 175.144.82.48:63380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.82.144.175.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tg8JSWzG9jbYOtu5htwAAAIo"]
[Tue Jul 21 08:09:55.670348 2026] [security2:error] [pid 352421:tid 352556] [client 175.144.82.48:63380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tg8JSWzG9jbYOtu5htwAAAIo"]
[Tue Jul 21 08:09:55.727311 2026] [security2:error] [pid 358661:tid 358832] [client 66.179.30.133:45510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "wenith.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9TgwlWhjQfpOo60_HzeQAAACY"]
[Tue Jul 21 08:09:55.951079 2026] [security2:error] [pid 358661:tid 358766] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TgwlWhjQfpOo60_HzhwAAI2U"]
[Tue Jul 21 08:09:55.951208 2026] [security2:error] [pid 358661:tid 358829] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TgwlWhjQfpOo60_HzhwAAI2U"]
[Tue Jul 21 08:09:56.842336 2026] [security2:error] [pid 352421:tid 352461] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ThMJSWzG9jbYOtu5hygAAoyc"]
[Tue Jul 21 08:09:56.842499 2026] [security2:error] [pid 352421:tid 352581] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ThMJSWzG9jbYOtu5hygAAoyc"]
[Tue Jul 21 08:09:57.062014 2026] [security2:error] [pid 358661:tid 358879] [client 20.151.10.161:13193] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/1.php"] [unique_id "al9ThQlWhjQfpOo60_HzmwAAAFU"]
[Tue Jul 21 08:09:57.062114 2026] [security2:error] [pid 358661:tid 358879] [client 20.151.10.161:13193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/1.php"] [unique_id "al9ThQlWhjQfpOo60_HzmwAAAFU"]
[Tue Jul 21 08:09:57.065334 2026] [security2:error] [pid 358661:tid 358825] [client 103.78.200.11:57762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ThQlWhjQfpOo60_HznAAAAB8"]
[Tue Jul 21 08:09:57.065448 2026] [security2:error] [pid 358661:tid 358825] [client 103.78.200.11:57762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ThQlWhjQfpOo60_HznAAAAB8"]
[Tue Jul 21 08:09:57.123684 2026] [security2:error] [pid 358661:tid 358838] [client 20.29.126.15:2135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/atomlib.php"] [unique_id "al9ThQlWhjQfpOo60_HznwAAACw"]
[Tue Jul 21 08:09:57.195068 2026] [security2:error] [pid 358661:tid 358830] [client 117.210.135.0:51298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ThQlWhjQfpOo60_HzoAAAACQ"]
[Tue Jul 21 08:09:57.195322 2026] [security2:error] [pid 358661:tid 358830] [client 117.210.135.0:51298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ThQlWhjQfpOo60_HzoAAAACQ"]
[Tue Jul 21 08:09:57.235490 2026] [security2:error] [pid 358661:tid 358818] [client 103.29.114.44:22324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.114.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ThQlWhjQfpOo60_HzoQAAABg"]
[Tue Jul 21 08:09:57.235671 2026] [security2:error] [pid 358661:tid 358818] [client 103.29.114.44:22324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ThQlWhjQfpOo60_HzoQAAABg"]
[Tue Jul 21 08:09:57.320846 2026] [security2:error] [pid 352421:tid 352623] [client 20.197.192.193:3122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/cron-tab.php"] [unique_id "al9ThcJSWzG9jbYOtu5h0gAAAM0"]
[Tue Jul 21 08:09:57.376552 2026] [security2:error] [pid 358661:tid 358740] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ThQlWhjQfpOo60_HzogAAN0s"]
[Tue Jul 21 08:09:57.376713 2026] [security2:error] [pid 358661:tid 358849] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ThQlWhjQfpOo60_HzogAAN0s"]
[Tue Jul 21 08:09:57.417949 2026] [security2:error] [pid 352421:tid 352585] [client 65.21.113.253:46550] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ThMJSWzG9jbYOtu5hywAAAKc"]
[Tue Jul 21 08:09:57.554280 2026] [security2:error] [pid 358661:tid 358785] [remote 199.189.225.40:55575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/xmlrpc.php"] [unique_id "al9ThQlWhjQfpOo60_HzpwAAfXg"]
[Tue Jul 21 08:09:57.554435 2026] [security2:error] [pid 358661:tid 358919] [client 199.189.225.40:55575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rlvmultiofertas.com"] [uri "/xmlrpc.php"] [unique_id "al9ThQlWhjQfpOo60_HzpwAAfXg"]
[Tue Jul 21 08:09:57.724592 2026] [security2:error] [pid 358661:tid 358884] [client 20.151.10.161:13302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/100.php"] [unique_id "al9ThQlWhjQfpOo60_HzqwAAAFo"]
[Tue Jul 21 08:09:57.786941 2026] [security2:error] [pid 358661:tid 358817] [client 20.220.225.223:1811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/hp3.php"] [unique_id "al9ThQlWhjQfpOo60_HzrAAAABc"]
[Tue Jul 21 08:09:57.841965 2026] [security2:error] [pid 358661:tid 358913] [client 20.206.105.145:56692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9ThQlWhjQfpOo60_HzrQAAAHc"]
[Tue Jul 21 08:09:58.086427 2026] [security2:error] [pid 358661:tid 358828] [client 20.104.96.117:63468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/0xD.php"] [unique_id "al9ThglWhjQfpOo60_HzsAAAACI"]
[Tue Jul 21 08:09:58.288011 2026] [security2:error] [pid 352421:tid 352635] [client 20.104.96.117:54121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/patie.php"] [unique_id "al9ThsJSWzG9jbYOtu5h4gAAANk"]
[Tue Jul 21 08:09:58.311227 2026] [security2:error] [pid 358661:tid 358853] [client 87.116.180.198:27138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ThglWhjQfpOo60_HztwAAADs"]
[Tue Jul 21 08:09:58.311429 2026] [security2:error] [pid 358661:tid 358853] [client 87.116.180.198:27138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ThglWhjQfpOo60_HztwAAADs"]
[Tue Jul 21 08:09:58.418767 2026] [security2:error] [pid 358661:tid 358875] [client 20.206.105.145:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9ThglWhjQfpOo60_HzuAAAAFE"]
[Tue Jul 21 08:09:58.526707 2026] [security2:error] [pid 352421:tid 352653] [client 20.151.10.161:13294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/about.php"] [unique_id "al9ThsJSWzG9jbYOtu5h6gAAAOs"]
[Tue Jul 21 08:09:58.739517 2026] [security2:error] [pid 358661:tid 358879] [client 65.21.113.253:40674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9ThglWhjQfpOo60_HzugAAAFU"]
[Tue Jul 21 08:09:58.873192 2026] [security2:error] [pid 358661:tid 358834] [client 20.206.105.145:56669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/media.php"] [unique_id "al9ThglWhjQfpOo60_HzvAAAACg"]
[Tue Jul 21 08:09:59.057999 2026] [security2:error] [pid 352421:tid 352502] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cromobelo.com.br"] [uri "/app_dev.php/_profiler/open"] [unique_id "al9Th8JSWzG9jbYOtu5h8QAA1lA"], referer: http://cpcalendars.cromobelo.com.br/app_dev.php/_profiler/open?file-app/config/parameters.yml
[Tue Jul 21 08:09:59.225496 2026] [security2:error] [pid 358661:tid 358832] [client 20.206.105.145:56576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/images.php"] [unique_id "al9ThwlWhjQfpOo60_HzxgAAACY"]
[Tue Jul 21 08:09:59.283918 2026] [security2:error] [pid 352421:tid 352677] [client 20.206.105.145:56681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/adminner.php"] [unique_id "al9Th8JSWzG9jbYOtu5h9AAAAQM"]
[Tue Jul 21 08:09:59.321470 2026] [security2:error] [pid 358661:tid 358843] [client 86.106.84.166:54270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9ThwlWhjQfpOo60_HzxwAAADE"]
[Tue Jul 21 08:09:59.321840 2026] [security2:error] [pid 358661:tid 358843] [client 86.106.84.166:54270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9ThwlWhjQfpOo60_HzxwAAADE"]
[Tue Jul 21 08:09:59.366757 2026] [security2:error] [pid 352421:tid 352666] [client 38.100.221.102:17398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Th8JSWzG9jbYOtu5h9QAAAPg"]
[Tue Jul 21 08:09:59.366940 2026] [security2:error] [pid 352421:tid 352666] [client 38.100.221.102:17398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Th8JSWzG9jbYOtu5h9QAAAPg"]
[Tue Jul 21 08:09:59.376771 2026] [security2:error] [pid 352421:tid 352602] [client 20.151.10.161:13184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/about.php"] [unique_id "al9Th8JSWzG9jbYOtu5h9wAAALg"]
[Tue Jul 21 08:09:59.576686 2026] [security2:error] [pid 358661:tid 358814] [client 65.21.113.253:59784] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ThwlWhjQfpOo60_HzywAAABQ"]
[Tue Jul 21 08:09:59.650599 2026] [security2:error] [pid 358661:tid 358886] [client 20.206.105.145:56596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/admin.php"] [unique_id "al9ThwlWhjQfpOo60_HzzAAAAFw"]
[Tue Jul 21 08:09:59.788594 2026] [security2:error] [pid 352421:tid 352600] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Th8JSWzG9jbYOtu5h-wAAtlw"]
[Tue Jul 21 08:09:59.904953 2026] [security2:error] [pid 358661:tid 358813] [client 20.206.105.145:56637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/k.php"] [unique_id "al9ThwlWhjQfpOo60_HzzgAAABM"]
[Tue Jul 21 08:10:00.033809 2026] [security2:error] [pid 352421:tid 352645] [client 65.21.113.253:54840] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TiMJSWzG9jbYOtu5iAgAAAOM"]
[Tue Jul 21 08:10:00.088188 2026] [security2:error] [pid 358661:tid 358881] [client 20.206.105.145:56591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/x.php"] [unique_id "al9TiAlWhjQfpOo60_Hz1QAAAFc"]
[Tue Jul 21 08:10:00.188374 2026] [security2:error] [pid 358661:tid 358858] [client 20.151.10.161:13297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/admin.php"] [unique_id "al9TiAlWhjQfpOo60_Hz1wAAAEA"]
[Tue Jul 21 08:10:00.247936 2026] [security2:error] [pid 358661:tid 358887] [client 20.104.96.117:63435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/fnstall.php"] [unique_id "al9TiAlWhjQfpOo60_Hz2gAAAF0"]
[Tue Jul 21 08:10:00.417797 2026] [security2:error] [pid 352421:tid 352604] [client 20.206.105.145:56612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wss.php"] [unique_id "al9TiMJSWzG9jbYOtu5iBwAAALo"]
[Tue Jul 21 08:10:00.487556 2026] [security2:error] [pid 352421:tid 352564] [client 162.219.176.3:54134] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9TiMJSWzG9jbYOtu5iCAAAAJI"]
[Tue Jul 21 08:10:00.487673 2026] [security2:error] [pid 352421:tid 352564] [client 162.219.176.3:54134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9TiMJSWzG9jbYOtu5iCAAAAJI"]
[Tue Jul 21 08:10:00.702999 2026] [security2:error] [pid 352421:tid 352652] [client 65.21.113.253:46550] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TiMJSWzG9jbYOtu5iBQAAAOo"]
[Tue Jul 21 08:10:00.773542 2026] [security2:error] [pid 358661:tid 358807] [client 20.151.10.161:13208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/admin.php"] [unique_id "al9TiAlWhjQfpOo60_Hz7wAAAA0"]
[Tue Jul 21 08:10:00.806645 2026] [security2:error] [pid 358661:tid 358810] [client 154.208.47.43:37869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TiAlWhjQfpOo60_Hz8QAAABA"]
[Tue Jul 21 08:10:00.806752 2026] [security2:error] [pid 358661:tid 358810] [client 154.208.47.43:37869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TiAlWhjQfpOo60_Hz8QAAABA"]
[Tue Jul 21 08:10:00.842001 2026] [security2:error] [pid 352421:tid 352587] [client 20.206.105.145:56701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ty.php"] [unique_id "al9TiMJSWzG9jbYOtu5iGQAAAKk"]
[Tue Jul 21 08:10:01.371408 2026] [security2:error] [pid 358661:tid 358814] [client 20.206.105.145:56686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/155.php"] [unique_id "al9TiQlWhjQfpOo60_Hz_AAAABQ"]
[Tue Jul 21 08:10:01.452359 2026] [security2:error] [pid 358661:tid 358900] [client 20.151.10.161:13192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/edit.php"] [unique_id "al9TiQlWhjQfpOo60_H0AQAAAGo"]
[Tue Jul 21 08:10:01.566787 2026] [access_compat:error] [pid 352421:tid 352552] [client 162.241.63.68:28872] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:10:01.617320 2026] [security2:error] [pid 358661:tid 358855] [client 20.29.126.15:7838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/0x.php"] [unique_id "al9TiQlWhjQfpOo60_H0BQAAAD0"]
[Tue Jul 21 08:10:01.838318 2026] [security2:error] [pid 352421:tid 352627] [client 65.21.113.253:59798] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TicJSWzG9jbYOtu5iIQAAANE"]
[Tue Jul 21 08:10:01.887171 2026] [security2:error] [pid 358661:tid 358893] [client 20.206.105.145:56672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ops.php"] [unique_id "al9TiQlWhjQfpOo60_H0CgAAAGM"]
[Tue Jul 21 08:10:01.888340 2026] [security2:error] [pid 358661:tid 358918] [client 20.151.10.161:13249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wp-content/admin.php"] [unique_id "al9TiQlWhjQfpOo60_H0CwAAAHw"]
[Tue Jul 21 08:10:02.060086 2026] [security2:error] [pid 352421:tid 352637] [client 20.104.96.117:57955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/ops.php"] [unique_id "al9TisJSWzG9jbYOtu5iMQAAANs"]
[Tue Jul 21 08:10:02.251845 2026] [security2:error] [pid 358661:tid 358916] [client 20.104.96.117:54694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/aa.php"] [unique_id "al9TiglWhjQfpOo60_H0EAAAAHo"]
[Tue Jul 21 08:10:02.363700 2026] [security2:error] [pid 358661:tid 358827] [client 20.151.10.161:13298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/f6.php"] [unique_id "al9TiglWhjQfpOo60_H0FAAAACE"]
[Tue Jul 21 08:10:02.706726 2026] [security2:error] [pid 358661:tid 358807] [client 20.197.192.193:3123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/hp3.php"] [unique_id "al9TiglWhjQfpOo60_H0HAAAAA0"]
[Tue Jul 21 08:10:02.748395 2026] [proxy:error] [pid 352421:tid 352531] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:02.748469 2026] [proxy_http:error] [pid 352421:tid 352531] [remote 176.65.132.57:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.cromobelo.com.br/web/dump-6-18-15.sql
[Tue Jul 21 08:10:02.749192 2026] [proxy:error] [pid 352421:tid 352531] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:02.749228 2026] [proxy_http:error] [pid 352421:tid 352531] [remote 176.65.132.57:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.cromobelo.com.br/web/dump-6-18-15.sql
[Tue Jul 21 08:10:02.817209 2026] [security2:error] [pid 352421:tid 352633] [client 125.18.144.2:27571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9TisJSWzG9jbYOtu5iPwAAANc"]
[Tue Jul 21 08:10:02.817395 2026] [security2:error] [pid 352421:tid 352633] [client 125.18.144.2:27571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9TisJSWzG9jbYOtu5iPwAAANc"]
[Tue Jul 21 08:10:02.927691 2026] [security2:error] [pid 358661:tid 358836] [client 20.151.10.161:13305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/inputs.php"] [unique_id "al9TiglWhjQfpOo60_H0HwAAACo"]
[Tue Jul 21 08:10:03.036762 2026] [security2:error] [pid 358661:tid 358828] [client 102.206.115.33:64785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TiwlWhjQfpOo60_H0IAAAACI"]
[Tue Jul 21 08:10:03.036867 2026] [security2:error] [pid 358661:tid 358828] [client 102.206.115.33:64785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TiwlWhjQfpOo60_H0IAAAACI"]
[Tue Jul 21 08:10:03.422631 2026] [security2:error] [pid 352421:tid 352663] [client 65.21.113.253:54840] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Ti8JSWzG9jbYOtu5iRwAAAPU"]
[Tue Jul 21 08:10:03.489862 2026] [security2:error] [pid 352421:tid 352623] [client 20.151.10.161:13121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/inputs.php"] [unique_id "al9Ti8JSWzG9jbYOtu5iSgAAAM0"]
[Tue Jul 21 08:10:03.535428 2026] [security2:error] [pid 352421:tid 352585] [client 20.206.105.145:56578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ingfo.php"] [unique_id "al9Ti8JSWzG9jbYOtu5iTAAAAKc"]
[Tue Jul 21 08:10:03.582224 2026] [security2:error] [pid 352421:tid 352452] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Ti8JSWzG9jbYOtu5iTgAAmR4"]
[Tue Jul 21 08:10:03.582370 2026] [security2:error] [pid 352421:tid 352571] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Ti8JSWzG9jbYOtu5iTgAAmR4"]
[Tue Jul 21 08:10:03.631833 2026] [security2:error] [pid 352421:tid 352587] [client 20.197.192.193:64499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/koiy.php"] [unique_id "al9Ti8JSWzG9jbYOtu5iUQAAAKk"]
[Tue Jul 21 08:10:04.000706 2026] [security2:error] [pid 352421:tid 352628] [client 20.104.96.117:62506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/acp.php"] [unique_id "al9Ti8JSWzG9jbYOtu5iVgAAANI"]
[Tue Jul 21 08:10:04.039389 2026] [security2:error] [pid 352421:tid 352621] [client 65.21.113.253:59798] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Ti8JSWzG9jbYOtu5iUgAAAMs"]
[Tue Jul 21 08:10:04.140603 2026] [security2:error] [pid 352421:tid 352594] [client 20.151.10.161:13197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/av.php"] [unique_id "al9TjMJSWzG9jbYOtu5iWQAAALA"]
[Tue Jul 21 08:10:04.324151 2026] [security2:error] [pid 358661:tid 358805] [client 120.56.162.40:65198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TjAlWhjQfpOo60_H0LwAAAAs"]
[Tue Jul 21 08:10:04.324396 2026] [security2:error] [pid 358661:tid 358805] [client 120.56.162.40:65198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TjAlWhjQfpOo60_H0LwAAAAs"]
[Tue Jul 21 08:10:04.796327 2026] [security2:error] [pid 358661:tid 358741] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TjAlWhjQfpOo60_H0MwAAUEw"]
[Tue Jul 21 08:10:04.796505 2026] [security2:error] [pid 358661:tid 358874] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TjAlWhjQfpOo60_H0MwAAUEw"]
[Tue Jul 21 08:10:04.941343 2026] [security2:error] [pid 352421:tid 352592] [client 20.206.105.145:56590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/error_log.php"] [unique_id "al9TjMJSWzG9jbYOtu5iZAAAAK4"]
400: No cPanel user controls a local domain called “franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br”. at cgi-priv/get_local.cgi.pl line 151.
[Tue Jul 21 08:10:05.052144 2026] [security2:error] [pid 358661:tid 358826] [client 41.68.90.219:64754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TjQlWhjQfpOo60_H0OgAAACA"]
[Tue Jul 21 08:10:05.053490 2026] [security2:error] [pid 358661:tid 358826] [client 41.68.90.219:64754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TjQlWhjQfpOo60_H0OgAAACA"]
[Tue Jul 21 08:10:05.095191 2026] [security2:error] [pid 358661:tid 358878] [client 173.252.95.1:40836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9TjQlWhjQfpOo60_H0OwAAAFQ"]
400: No cPanel user controls a local domain called “franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br”. at cgi-priv/get_local.cgi.pl line 151.
400: No cPanel user controls a local domain called “franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br”. at cgi-priv/get_local.cgi.pl line 151.
[Tue Jul 21 08:10:05.183321 2026] [security2:error] [pid 358661:tid 358804] [client 20.151.10.161:13218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/classwithtostring.php"] [unique_id "al9TjQlWhjQfpOo60_H0PQAAAAo"]
[Tue Jul 21 08:10:05.186175 2026] [security2:error] [pid 358661:tid 358884] [client 150.129.202.39:65238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TjQlWhjQfpOo60_H0PgAAAFo"]
[Tue Jul 21 08:10:05.186261 2026] [security2:error] [pid 358661:tid 358884] [client 150.129.202.39:65238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TjQlWhjQfpOo60_H0PgAAAFo"]
[Tue Jul 21 08:10:05.201053 2026] [security2:error] [pid 358661:tid 358915] [client 61.1.167.83:60414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TjQlWhjQfpOo60_H0QAAAAHk"]
[Tue Jul 21 08:10:05.201164 2026] [security2:error] [pid 358661:tid 358915] [client 61.1.167.83:60414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TjQlWhjQfpOo60_H0QAAAAHk"]
400: No cPanel user controls a local domain called “franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br”. at cgi-priv/get_local.cgi.pl line 151.
400: No cPanel user controls a local domain called “franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br”. at cgi-priv/get_local.cgi.pl line 151.
[Tue Jul 21 08:10:05.399801 2026] [core:error] [pid 358661:tid 358853] [client 198.235.24.36:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:10:05.399832 2026] [core:error] [pid 358661:tid 358853] [client 198.235.24.36:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
400: No cPanel user controls a local domain called “franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br”. at cgi-priv/get_local.cgi.pl line 151.
[Tue Jul 21 08:10:05.462255 2026] [security2:error] [pid 358661:tid 358877] [client 109.60.28.94:59624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TjQlWhjQfpOo60_H0RwAAAFM"]
[Tue Jul 21 08:10:05.462386 2026] [security2:error] [pid 358661:tid 358877] [client 109.60.28.94:59624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TjQlWhjQfpOo60_H0RwAAAFM"]
400: No cPanel user controls a local domain called “franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br”. at cgi-priv/get_local.cgi.pl line 151.
[Tue Jul 21 08:10:05.658958 2026] [security2:error] [pid 352421:tid 352600] [client 65.21.113.253:54840] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TjcJSWzG9jbYOtu5idAAAALY"]
[Tue Jul 21 08:10:05.832063 2026] [security2:error] [pid 358661:tid 358805] [client 20.151.10.161:13189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9TjQlWhjQfpOo60_H0VAAAAAs"]
[Tue Jul 21 08:10:05.872540 2026] [security2:error] [pid 352421:tid 352542] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TjcJSWzG9jbYOtu5iegAA3Xg"]
[Tue Jul 21 08:10:05.872691 2026] [security2:error] [pid 352421:tid 352639] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TjcJSWzG9jbYOtu5iegAA3Xg"]
[Tue Jul 21 08:10:06.086080 2026] [security2:error] [pid 352421:tid 352645] [client 20.206.105.145:56703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ok.php"] [unique_id "al9TjsJSWzG9jbYOtu5ifAAAAOM"]
[Tue Jul 21 08:10:06.274598 2026] [security2:error] [pid 358661:tid 358874] [client 20.151.10.161:13132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wp-blog.php"] [unique_id "al9TjglWhjQfpOo60_H0WAAAAFA"]
[Tue Jul 21 08:10:06.335673 2026] [security2:error] [pid 358661:tid 358686] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TjglWhjQfpOo60_H0WgAAdxU"]
[Tue Jul 21 08:10:06.336050 2026] [security2:error] [pid 358661:tid 358913] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TjglWhjQfpOo60_H0WgAAdxU"]
[Tue Jul 21 08:10:06.463346 2026] [security2:error] [pid 352421:tid 352431] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TjsJSWzG9jbYOtu5ihgAA1wk"]
[Tue Jul 21 08:10:06.463627 2026] [security2:error] [pid 352421:tid 352633] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TjsJSWzG9jbYOtu5ihgAA1wk"]
[Tue Jul 21 08:10:06.749595 2026] [security2:error] [pid 352421:tid 352558] [client 65.21.113.253:59808] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TjsJSWzG9jbYOtu5igwAAAIw"]
[Tue Jul 21 08:10:06.758136 2026] [security2:error] [pid 352421:tid 352663] [client 20.206.105.145:56642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/mac.php"] [unique_id "al9TjsJSWzG9jbYOtu5ijQAAAPU"]
[Tue Jul 21 08:10:07.025343 2026] [proxy:error] [pid 352421:tid 352578] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:07.025429 2026] [proxy_http:error] [pid 352421:tid 352578] [client 20.151.10.161:13306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:07.026066 2026] [proxy:error] [pid 352421:tid 352578] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:07.026109 2026] [proxy_http:error] [pid 352421:tid 352578] [client 20.151.10.161:13306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:07.057616 2026] [security2:error] [pid 358661:tid 358872] [client 65.21.113.253:59820] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TjglWhjQfpOo60_H0YAAAAE4"]
[Tue Jul 21 08:10:07.232625 2026] [security2:error] [pid 352421:tid 352625] [client 103.78.200.11:58265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tj8JSWzG9jbYOtu5imwAAAM8"]
[Tue Jul 21 08:10:07.232759 2026] [security2:error] [pid 352421:tid 352625] [client 103.78.200.11:58265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tj8JSWzG9jbYOtu5imwAAAM8"]
[Tue Jul 21 08:10:07.235438 2026] [security2:error] [pid 352421:tid 352635] [client 20.104.96.117:57950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/mac.php"] [unique_id "al9Tj8JSWzG9jbYOtu5inAAAANk"]
[Tue Jul 21 08:10:07.484470 2026] [security2:error] [pid 352421:tid 352654] [client 20.206.105.145:29664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wefile.php"] [unique_id "al9Tj8JSWzG9jbYOtu5ipAAAAOw"]
[Tue Jul 21 08:10:07.707662 2026] [security2:error] [pid 352421:tid 352561] [client 20.151.10.161:13230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wp-content/admin.php"] [unique_id "al9Tj8JSWzG9jbYOtu5irgAAAI8"]
[Tue Jul 21 08:10:07.728090 2026] [core:alert] [pid 352421:tid 352567] [client 57.141.18.43:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:10:07.941554 2026] [security2:error] [pid 352421:tid 352546] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tj8JSWzG9jbYOtu5itgAAlHw"]
[Tue Jul 21 08:10:07.941735 2026] [security2:error] [pid 352421:tid 352566] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tj8JSWzG9jbYOtu5itgAAlHw"]
[Tue Jul 21 08:10:07.961385 2026] [security2:error] [pid 352421:tid 352658] [client 117.210.135.0:51947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tj8JSWzG9jbYOtu5itwAAAPA"]
[Tue Jul 21 08:10:07.961507 2026] [security2:error] [pid 352421:tid 352658] [client 117.210.135.0:51947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tj8JSWzG9jbYOtu5itwAAAPA"]
[Tue Jul 21 08:10:08.256943 2026] [security2:error] [pid 352421:tid 352651] [client 74.7.244.14:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cpanel.albegaoficial.com.br"] [uri "/___proxy_subdomain_cpanel/robots.txt"] [unique_id "al9TkMJSWzG9jbYOtu5iwgAA6R0"]
[Tue Jul 21 08:10:08.271789 2026] [security2:error] [pid 352421:tid 352426] [remote 151.123.176.97:61673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.176.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9TkMJSWzG9jbYOtu5iuQABAQQ"]
[Tue Jul 21 08:10:08.369127 2026] [security2:error] [pid 352421:tid 352652] [client 20.151.10.161:13211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/adminfuns.php"] [unique_id "al9TkMJSWzG9jbYOtu5ixQAAAOo"]
[Tue Jul 21 08:10:09.003913 2026] [security2:error] [pid 352421:tid 352611] [client 20.151.10.161:13290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/goods.php"] [unique_id "al9TkcJSWzG9jbYOtu5i1gAAAME"]
[Tue Jul 21 08:10:09.039672 2026] [security2:error] [pid 352421:tid 352562] [client 87.116.180.198:14066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TkcJSWzG9jbYOtu5i1wAAAJA"]
[Tue Jul 21 08:10:09.039765 2026] [security2:error] [pid 352421:tid 352562] [client 87.116.180.198:14066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TkcJSWzG9jbYOtu5i1wAAAJA"]
[Tue Jul 21 08:10:09.138434 2026] [security2:error] [pid 352421:tid 352592] [client 20.104.96.117:58375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/mg.php"] [unique_id "al9TkcJSWzG9jbYOtu5i2AAAAK4"]
[Tue Jul 21 08:10:09.153942 2026] [security2:error] [pid 352421:tid 352654] [client 20.206.105.145:56583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9TkcJSWzG9jbYOtu5i2QAAAOw"]
[Tue Jul 21 08:10:09.329687 2026] [security2:error] [pid 352421:tid 352437] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TkcJSWzG9jbYOtu5i4AAAkQ8"]
[Tue Jul 21 08:10:09.329994 2026] [security2:error] [pid 352421:tid 352563] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TkcJSWzG9jbYOtu5i4AAAkQ8"]
[Tue Jul 21 08:10:09.821533 2026] [security2:error] [pid 352421:tid 352634] [client 20.151.10.161:13194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/ms-edit.php"] [unique_id "al9TkcJSWzG9jbYOtu5i7AAAANg"]
[Tue Jul 21 08:10:09.831762 2026] [security2:error] [pid 352421:tid 352630] [client 38.100.221.102:18157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TkcJSWzG9jbYOtu5i7QAAANQ"]
[Tue Jul 21 08:10:09.831856 2026] [security2:error] [pid 352421:tid 352630] [client 38.100.221.102:18157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TkcJSWzG9jbYOtu5i7QAAANQ"]
[Tue Jul 21 08:10:09.862163 2026] [security2:error] [pid 352421:tid 352633] [client 20.104.96.117:58418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-post-data.php"] [unique_id "al9TkcJSWzG9jbYOtu5i7wAAANc"]
[Tue Jul 21 08:10:09.992835 2026] [autoindex:error] [pid 352421:tid 352576] [client 20.206.105.145:56594] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:10.046483 2026] [autoindex:error] [pid 352421:tid 352599] [client 20.206.105.145:56594] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:10.051405 2026] [security2:error] [pid 352421:tid 352583] [client 20.206.105.145:56594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9TksJSWzG9jbYOtu5i9AAAAKU"]
[Tue Jul 21 08:10:10.133418 2026] [security2:error] [pid 352421:tid 352557] [client 20.197.192.193:39238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/hp2.php"] [unique_id "al9TksJSWzG9jbYOtu5i_AAAAIs"]
[Tue Jul 21 08:10:10.514440 2026] [security2:error] [pid 352421:tid 352635] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TksJSWzG9jbYOtu5jBAAA2SY"]
[Tue Jul 21 08:10:10.542793 2026] [security2:error] [pid 352421:tid 352644] [client 20.104.96.117:58385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/pucci.php"] [unique_id "al9TksJSWzG9jbYOtu5jBQAAAOI"]
[Tue Jul 21 08:10:10.549535 2026] [security2:error] [pid 352421:tid 352660] [client 162.219.176.3:33412] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9TksJSWzG9jbYOtu5jBgAAAPI"]
[Tue Jul 21 08:10:10.549609 2026] [security2:error] [pid 352421:tid 352660] [client 162.219.176.3:33412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9TksJSWzG9jbYOtu5jBgAAAPI"]
[Tue Jul 21 08:10:10.574789 2026] [security2:error] [pid 352421:tid 352575] [client 20.104.96.117:63429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/mosty.php"] [unique_id "al9TksJSWzG9jbYOtu5jCQAAAJ0"]
[Tue Jul 21 08:10:11.015252 2026] [security2:error] [pid 352421:tid 352631] [client 20.197.192.193:47087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jGAAAANU"]
[Tue Jul 21 08:10:11.047684 2026] [security2:error] [pid 352421:tid 352624] [client 20.197.192.193:14856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jGQAAAM4"]
[Tue Jul 21 08:10:11.072722 2026] [security2:error] [pid 352421:tid 352645] [client 20.151.10.161:13299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/222.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jHgAAAOM"]
[Tue Jul 21 08:10:11.110149 2026] [security2:error] [pid 352421:tid 352671] [client 20.197.192.193:14864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/dp.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jHwAAAP0"]
[Tue Jul 21 08:10:11.168854 2026] [security2:error] [pid 352421:tid 352633] [client 20.104.96.117:54118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/xwpg.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jIAAAANc"]
[Tue Jul 21 08:10:11.181046 2026] [security2:error] [pid 352421:tid 352678] [client 20.197.192.193:47063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/old.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jIQAAAQQ"]
[Tue Jul 21 08:10:11.208786 2026] [security2:error] [pid 352421:tid 352555] [client 20.197.192.193:14870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/ms-new.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jIgAAAIk"]
[Tue Jul 21 08:10:11.246438 2026] [security2:error] [pid 352421:tid 352675] [client 20.197.192.193:47045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/track.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jIwAAAQE"]
[Tue Jul 21 08:10:11.318051 2026] [security2:error] [pid 352421:tid 352557] [client 20.197.192.193:47082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/2352356666.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jKAAAAIs"]
[Tue Jul 21 08:10:11.341710 2026] [security2:error] [pid 352421:tid 352580] [client 154.208.47.43:38298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jKwAAAKI"]
[Tue Jul 21 08:10:11.341944 2026] [security2:error] [pid 352421:tid 352580] [client 154.208.47.43:38298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jKwAAAKI"]
[Tue Jul 21 08:10:11.358806 2026] [security2:error] [pid 352421:tid 352655] [client 20.197.192.193:47100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/pn.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jLAAAAO0"]
[Tue Jul 21 08:10:11.367054 2026] [security2:error] [pid 352421:tid 352656] [client 20.104.96.117:57949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/black.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jLQAAAO4"]
[Tue Jul 21 08:10:11.433854 2026] [security2:error] [pid 352421:tid 352585] [client 20.197.192.193:14861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jMAAAAKc"]
[Tue Jul 21 08:10:11.480772 2026] [security2:error] [pid 352421:tid 352587] [client 20.197.192.193:47062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/dr.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jMgAAAKk"]
[Tue Jul 21 08:10:11.588224 2026] [security2:error] [pid 352421:tid 352575] [client 20.197.192.193:47066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/2x.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jNQAAAJ0"]
[Tue Jul 21 08:10:11.602194 2026] [security2:error] [pid 352421:tid 352466] [remote 5.182.209.54:54632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fisiopelvicafloripa.com.br"] [uri "/wp-login.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jNgAA_iw"]
[Tue Jul 21 08:10:11.744640 2026] [security2:error] [pid 352421:tid 352653] [client 20.151.10.161:13198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/cgi-bin/index.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jOwAAAOs"]
[Tue Jul 21 08:10:11.786686 2026] [security2:error] [pid 352421:tid 352568] [client 20.197.192.193:3103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/aa1.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jPgAAAJY"]
[Tue Jul 21 08:10:11.863879 2026] [security2:error] [pid 352421:tid 352561] [client 20.197.192.193:47093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/kq1.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jQgAAAI8"]
[Tue Jul 21 08:10:11.957390 2026] [security2:error] [pid 352421:tid 352603] [client 20.197.192.193:14528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/zzz.php"] [unique_id "al9Tk8JSWzG9jbYOtu5jRgAAALk"]
[Tue Jul 21 08:10:12.103723 2026] [security2:error] [pid 352421:tid 352633] [client 20.197.192.193:47064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wicked.php"] [unique_id "al9TlMJSWzG9jbYOtu5jSgAAANc"]
[Tue Jul 21 08:10:12.210400 2026] [security2:error] [pid 352421:tid 352571] [client 20.197.192.193:47048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/edit.php"] [unique_id "al9TlMJSWzG9jbYOtu5jUgAAAJk"]
[Tue Jul 21 08:10:12.368807 2026] [security2:error] [pid 352421:tid 352605] [client 20.197.192.193:14859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/kua.php"] [unique_id "al9TlMJSWzG9jbYOtu5jWQAAALs"]
[Tue Jul 21 08:10:12.416449 2026] [security2:error] [pid 352421:tid 352660] [client 20.104.96.117:58394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/zlece.php"] [unique_id "al9TlMJSWzG9jbYOtu5jXAAAAPI"]
[Tue Jul 21 08:10:12.447352 2026] [proxy:error] [pid 352421:tid 352575] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:12.447434 2026] [proxy_http:error] [pid 352421:tid 352575] [client 20.151.10.161:13293] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:12.448062 2026] [proxy:error] [pid 352421:tid 352575] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:12.448090 2026] [proxy_http:error] [pid 352421:tid 352575] [client 20.151.10.161:13293] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:12.469941 2026] [security2:error] [pid 352421:tid 352672] [client 20.197.192.193:14862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/ez.php"] [unique_id "al9TlMJSWzG9jbYOtu5jXwAAAP4"]
[Tue Jul 21 08:10:12.497688 2026] [security2:error] [pid 352421:tid 352638] [client 20.206.105.145:56683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/like.php"] [unique_id "al9TlMJSWzG9jbYOtu5jYAAAANw"]
[Tue Jul 21 08:10:12.555419 2026] [security2:error] [pid 352421:tid 352617] [client 20.197.192.193:47042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/fz.php"] [unique_id "al9TlMJSWzG9jbYOtu5jYwAAAMc"]
[Tue Jul 21 08:10:12.586073 2026] [security2:error] [pid 352421:tid 352654] [client 20.104.96.117:62501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/6.php"] [unique_id "al9TlMJSWzG9jbYOtu5jZAAAAOw"]
[Tue Jul 21 08:10:12.605047 2026] [security2:error] [pid 352421:tid 352596] [client 20.197.192.193:47078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/la.php"] [unique_id "al9TlMJSWzG9jbYOtu5jaQAAALI"]
[Tue Jul 21 08:10:12.608105 2026] [security2:error] [pid 352421:tid 352631] [client 65.21.113.253:45742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TlMJSWzG9jbYOtu5jTAAAANU"]
[Tue Jul 21 08:10:12.649632 2026] [security2:error] [pid 352421:tid 352581] [client 20.197.192.193:14873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9TlMJSWzG9jbYOtu5jagAAAKM"]
[Tue Jul 21 08:10:12.653775 2026] [fcgid:warn] [pid 352421:tid 352602] (70014)End of file found: [client 168.144.100.227:0] mod_fcgid: can't get data from http client, referer: https://ambelliedeco-yayaya.pages.dev//blog//wp-login.php
[Tue Jul 21 08:10:12.696144 2026] [security2:error] [pid 352421:tid 352670] [client 20.197.192.193:14883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/inso.php"] [unique_id "al9TlMJSWzG9jbYOtu5jbgAAAPw"]
[Tue Jul 21 08:10:12.762446 2026] [security2:error] [pid 352421:tid 352662] [client 20.197.192.193:14849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wpx.php"] [unique_id "al9TlMJSWzG9jbYOtu5jcwAAAPQ"]
[Tue Jul 21 08:10:12.789618 2026] [security2:error] [pid 352421:tid 352577] [client 20.197.192.193:14853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/berlin.php"] [unique_id "al9TlMJSWzG9jbYOtu5jdgAAAJ8"]
[Tue Jul 21 08:10:12.852068 2026] [security2:error] [pid 352421:tid 352579] [client 20.197.192.193:47096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/billur.php"] [unique_id "al9TlMJSWzG9jbYOtu5jfQAAAKE"]
[Tue Jul 21 08:10:12.884715 2026] [security2:error] [pid 352421:tid 352621] [client 20.197.192.193:47065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/mimpi.php"] [unique_id "al9TlMJSWzG9jbYOtu5jgQAAAMs"]
[Tue Jul 21 08:10:12.915932 2026] [security2:error] [pid 352421:tid 352585] [client 20.197.192.193:47049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/dp.php"] [unique_id "al9TlMJSWzG9jbYOtu5jggAAAKc"]
[Tue Jul 21 08:10:12.993904 2026] [security2:error] [pid 352421:tid 352565] [client 20.29.126.15:16054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/buy.php"] [unique_id "al9TlMJSWzG9jbYOtu5jgwAAAJM"]
[Tue Jul 21 08:10:13.013198 2026] [security2:error] [pid 352421:tid 352545] [remote 45.90.123.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9TlcJSWzG9jbYOtu5jhgABAXs"]
[Tue Jul 21 08:10:13.013341 2026] [security2:error] [pid 352421:tid 352675] [client 45.90.123.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9TlcJSWzG9jbYOtu5jhgABAXs"]
[Tue Jul 21 08:10:13.041947 2026] [security2:error] [pid 352421:tid 352575] [client 20.197.192.193:47055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/bootstrap.php"] [unique_id "al9TlcJSWzG9jbYOtu5jiAAAAJ0"]
[Tue Jul 21 08:10:13.178419 2026] [security2:error] [pid 352421:tid 352664] [client 20.104.96.117:58393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/vssrs.php"] [unique_id "al9TlcJSWzG9jbYOtu5jjQAAAPY"]
[Tue Jul 21 08:10:13.178991 2026] [security2:error] [pid 352421:tid 352617] [client 20.206.105.145:56702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/.well-known/about.php"] [unique_id "al9TlcJSWzG9jbYOtu5jjgAAAMc"]
[Tue Jul 21 08:10:13.202580 2026] [security2:error] [pid 352421:tid 352627] [client 20.151.10.161:13255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/BDKR28WP.php"] [unique_id "al9TlcJSWzG9jbYOtu5jkQAAANE"]
[Tue Jul 21 08:10:13.275266 2026] [security2:error] [pid 352421:tid 352568] [client 20.197.192.193:14860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-editor.php"] [unique_id "al9TlcJSWzG9jbYOtu5jkwAAAJY"]
[Tue Jul 21 08:10:13.366558 2026] [security2:error] [pid 352421:tid 352623] [client 14.97.58.74:43018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9TlcJSWzG9jbYOtu5jlAAAAM0"]
[Tue Jul 21 08:10:13.366788 2026] [security2:error] [pid 352421:tid 352623] [client 14.97.58.74:43018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9TlcJSWzG9jbYOtu5jlAAAAM0"]
[Tue Jul 21 08:10:13.412084 2026] [http2:info] [pid 400813:tid 400813] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 08:10:13.449373 2026] [security2:error] [pid 400813:tid 400944] [client 20.197.192.193:14848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/cro.php"] [unique_id "al9TldZ1vbMzrdVQS3ETEwAAAQo"]
[Tue Jul 21 08:10:13.488011 2026] [security2:error] [pid 400813:tid 400947] [client 20.206.105.145:56661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9TldZ1vbMzrdVQS3ETFAAAAQ0"]
[Tue Jul 21 08:10:13.521520 2026] [security2:error] [pid 400813:tid 400950] [client 20.197.192.193:47072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/cron-tab.php"] [unique_id "al9TldZ1vbMzrdVQS3ETFgAAARA"]
[Tue Jul 21 08:10:13.678377 2026] [security2:error] [pid 400813:tid 400959] [client 20.197.192.193:14893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/koiy.php"] [unique_id "al9TldZ1vbMzrdVQS3ETHgAAARk"]
[Tue Jul 21 08:10:13.743874 2026] [security2:error] [pid 400813:tid 400967] [client 20.220.225.223:1304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/acew67.php"] [unique_id "al9TldZ1vbMzrdVQS3ETIQAAASE"]
[Tue Jul 21 08:10:13.863429 2026] [security2:error] [pid 352421:tid 352611] [client 102.206.115.33:65483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TlcJSWzG9jbYOtu5jlgAAAME"]
[Tue Jul 21 08:10:13.863594 2026] [security2:error] [pid 352421:tid 352611] [client 102.206.115.33:65483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TlcJSWzG9jbYOtu5jlgAAAME"]
[Tue Jul 21 08:10:13.912647 2026] [proxy:error] [pid 400813:tid 400976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:13.912913 2026] [proxy_http:error] [pid 400813:tid 400976] [client 20.151.10.161:13292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:13.913744 2026] [proxy:error] [pid 400813:tid 400976] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:13.913771 2026] [proxy_http:error] [pid 400813:tid 400976] [client 20.151.10.161:13292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:14.022617 2026] [security2:error] [pid 400813:tid 400986] [client 20.197.192.193:47103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/hp2.php"] [unique_id "al9TltZ1vbMzrdVQS3ETKQAAATQ"]
[Tue Jul 21 08:10:14.050119 2026] [security2:error] [pid 400813:tid 400989] [client 20.29.126.15:9092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/sx.php"] [unique_id "al9TltZ1vbMzrdVQS3ETLAAAATc"]
[Tue Jul 21 08:10:14.085895 2026] [security2:error] [pid 400813:tid 400995] [client 20.197.192.193:3613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/acew67.php"] [unique_id "al9TltZ1vbMzrdVQS3ETLwAAAT0"]
[Tue Jul 21 08:10:14.167558 2026] [security2:error] [pid 400813:tid 401001] [client 20.197.192.193:47051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/hp3.php"] [unique_id "al9TltZ1vbMzrdVQS3ETMAAAAUM"]
[Tue Jul 21 08:10:14.197364 2026] [security2:error] [pid 400813:tid 401004] [client 20.197.192.193:14102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/aa1.php"] [unique_id "al9TltZ1vbMzrdVQS3ETMQAAAUY"]
[Tue Jul 21 08:10:14.290135 2026] [security2:error] [pid 400813:tid 401014] [client 20.197.192.193:14900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/acew67.php"] [unique_id "al9TltZ1vbMzrdVQS3ETOAAAAVA"]
[Tue Jul 21 08:10:14.378274 2026] [security2:error] [pid 400813:tid 401025] [client 20.197.192.193:47056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/bscclapb.php"] [unique_id "al9TltZ1vbMzrdVQS3ETPgAAAVs"]
[Tue Jul 21 08:10:14.389552 2026] [security2:error] [pid 400813:tid 401026] [client 20.104.96.117:57944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wicked.php"] [unique_id "al9TltZ1vbMzrdVQS3ETPwAAAVw"]
[Tue Jul 21 08:10:14.410699 2026] [autoindex:error] [pid 400813:tid 401022] [client 20.206.105.145:56668] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:14.430207 2026] [security2:error] [pid 400813:tid 401028] [client 20.197.192.193:47074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/else1.php"] [unique_id "al9TltZ1vbMzrdVQS3ETQAAAAV4"]
[Tue Jul 21 08:10:14.470501 2026] [proxy:error] [pid 400813:tid 401035] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:14.470590 2026] [proxy_http:error] [pid 400813:tid 401035] [client 20.151.10.161:13304] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:14.471282 2026] [proxy:error] [pid 400813:tid 401035] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:14.471316 2026] [proxy_http:error] [pid 400813:tid 401035] [client 20.151.10.161:13304] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:14.490354 2026] [security2:error] [pid 400813:tid 401036] [client 20.197.192.193:14548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/tkikikoko.php"] [unique_id "al9TltZ1vbMzrdVQS3ETRwAAAWY"]
[Tue Jul 21 08:10:14.498544 2026] [autoindex:error] [pid 400813:tid 401033] [client 20.206.105.145:56668] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:14.524512 2026] [security2:error] [pid 400813:tid 401039] [client 20.206.105.145:56668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/pucci.php"] [unique_id "al9TltZ1vbMzrdVQS3ETSQAAAWk"]
[Tue Jul 21 08:10:14.529580 2026] [security2:error] [pid 400813:tid 401040] [client 20.197.192.193:47093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9TltZ1vbMzrdVQS3ETSgAAAWo"]
[Tue Jul 21 08:10:14.605738 2026] [security2:error] [pid 400813:tid 400829] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TltZ1vbMzrdVQS3ETTAABRQ4"]
[Tue Jul 21 08:10:14.605970 2026] [security2:error] [pid 400813:tid 401003] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TltZ1vbMzrdVQS3ETTAABRQ4"]
[Tue Jul 21 08:10:14.620270 2026] [security2:error] [pid 400813:tid 401051] [client 20.197.192.193:14866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-css.php"] [unique_id "al9TltZ1vbMzrdVQS3ETTgAAAXU"]
[Tue Jul 21 08:10:14.704383 2026] [security2:error] [pid 400813:tid 401054] [client 20.197.192.193:47052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/wp-explorer.php"] [unique_id "al9TltZ1vbMzrdVQS3ETUgAAAXg"]
[Tue Jul 21 08:10:14.892910 2026] [security2:error] [pid 400813:tid 401065] [client 20.197.192.193:47054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/akismet.php"] [unique_id "al9TltZ1vbMzrdVQS3ETWgAAAYM"]
[Tue Jul 21 08:10:14.894254 2026] [security2:error] [pid 400813:tid 401066] [client 198.54.129.60:59086] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9TltZ1vbMzrdVQS3ETWwAAAYQ"]
[Tue Jul 21 08:10:14.894376 2026] [security2:error] [pid 400813:tid 401066] [client 198.54.129.60:59086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9TltZ1vbMzrdVQS3ETWwAAAYQ"]
[Tue Jul 21 08:10:14.907066 2026] [security2:error] [pid 400813:tid 401012] [client 120.56.162.40:49303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TltZ1vbMzrdVQS3ETXQAAAU4"]
[Tue Jul 21 08:10:14.907194 2026] [security2:error] [pid 400813:tid 401012] [client 120.56.162.40:49303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TltZ1vbMzrdVQS3ETXQAAAU4"]
[Tue Jul 21 08:10:14.951739 2026] [security2:error] [pid 400813:tid 401071] [client 20.220.225.223:1323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/bscclapb.php"] [unique_id "al9TltZ1vbMzrdVQS3ETXgAAAYk"]
[Tue Jul 21 08:10:15.012056 2026] [security2:error] [pid 400813:tid 400948] [client 20.197.192.193:14854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/ace2.php"] [unique_id "al9Tl9Z1vbMzrdVQS3ETYAAAAQ4"]
[Tue Jul 21 08:10:15.131519 2026] [security2:error] [pid 400813:tid 400960] [client 20.151.10.161:13205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/raw.php"] [unique_id "al9Tl9Z1vbMzrdVQS3ETYgAAARo"]
[Tue Jul 21 08:10:15.165817 2026] [autoindex:error] [pid 400813:tid 400962] [client 20.206.105.145:56604] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:15.211927 2026] [security2:error] [pid 400813:tid 400967] [client 20.197.192.193:47041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thekingsdistribuidora.com.br"] [uri "/ms.php"] [unique_id "al9Tl9Z1vbMzrdVQS3ETZQAAASE"]
[Tue Jul 21 08:10:15.222443 2026] [autoindex:error] [pid 400813:tid 400968] [client 20.206.105.145:56604] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:15.226967 2026] [security2:error] [pid 400813:tid 400970] [client 20.206.105.145:56604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-temp.php"] [unique_id "al9Tl9Z1vbMzrdVQS3ETZwAAASQ"]
[Tue Jul 21 08:10:15.352503 2026] [security2:error] [pid 400813:tid 400839] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Tl9Z1vbMzrdVQS3ETaAABGRg"]
[Tue Jul 21 08:10:15.354903 2026] [security2:error] [pid 400813:tid 400959] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Tl9Z1vbMzrdVQS3ETaAABGRg"]
[Tue Jul 21 08:10:15.643806 2026] [security2:error] [pid 400813:tid 400977] [client 20.151.10.161:13295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/abcd.php"] [unique_id "al9Tl9Z1vbMzrdVQS3ETcgAAASs"]
[Tue Jul 21 08:10:15.693084 2026] [security2:error] [pid 400813:tid 401070] [client 150.129.202.39:65454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tl9Z1vbMzrdVQS3ETdAAAAYg"]
[Tue Jul 21 08:10:15.693781 2026] [security2:error] [pid 400813:tid 401070] [client 150.129.202.39:65454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tl9Z1vbMzrdVQS3ETdAAAAYg"]
[Tue Jul 21 08:10:15.834141 2026] [security2:error] [pid 400813:tid 400994] [client 62.102.148.158:49442] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Tl9Z1vbMzrdVQS3ETcwAAATw"]
[Tue Jul 21 08:10:15.834278 2026] [security2:error] [pid 400813:tid 400994] [client 62.102.148.158:49442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Tl9Z1vbMzrdVQS3ETcwAAATw"]
[Tue Jul 21 08:10:15.887077 2026] [security2:error] [pid 400813:tid 401006] [client 20.220.225.223:1796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/else1.php"] [unique_id "al9Tl9Z1vbMzrdVQS3ETegAAAUg"]
[Tue Jul 21 08:10:16.074214 2026] [security2:error] [pid 400813:tid 400986] [client 41.68.90.219:65227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TmNZ1vbMzrdVQS3EThgAAATQ"]
[Tue Jul 21 08:10:16.075499 2026] [security2:error] [pid 400813:tid 400986] [client 41.68.90.219:65227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TmNZ1vbMzrdVQS3EThgAAATQ"]
[Tue Jul 21 08:10:16.149481 2026] [security2:error] [pid 400813:tid 401041] [client 20.104.96.117:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/24.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETiAAAAWs"]
[Tue Jul 21 08:10:16.205700 2026] [security2:error] [pid 400813:tid 400996] [client 109.60.28.94:60082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETiwAAAT4"]
[Tue Jul 21 08:10:16.206532 2026] [security2:error] [pid 400813:tid 400996] [client 109.60.28.94:60082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETiwAAAT4"]
[Tue Jul 21 08:10:16.323432 2026] [security2:error] [pid 400813:tid 401055] [client 20.151.10.161:13214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/a1.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETkQAAAXk"]
[Tue Jul 21 08:10:16.364683 2026] [autoindex:error] [pid 400813:tid 401053] [client 20.206.105.145:29635] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:16.394390 2026] [security2:error] [pid 400813:tid 401064] [client 20.206.105.145:29635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/xmu.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETlwAAAYI"]
[Tue Jul 21 08:10:16.497993 2026] [security2:error] [pid 400813:tid 400858] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETnwABdis"]
[Tue Jul 21 08:10:16.498156 2026] [security2:error] [pid 400813:tid 401052] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETnwABdis"]
[Tue Jul 21 08:10:16.542771 2026] [security2:error] [pid 400813:tid 400962] [client 162.219.176.3:51862] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETogAAARw"]
[Tue Jul 21 08:10:16.542905 2026] [security2:error] [pid 400813:tid 400962] [client 162.219.176.3:51862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETogAAARw"]
[Tue Jul 21 08:10:16.929673 2026] [security2:error] [pid 400813:tid 400865] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETrQABGTI"]
[Tue Jul 21 08:10:16.929798 2026] [security2:error] [pid 400813:tid 400959] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETrQABGTI"]
[Tue Jul 21 08:10:16.930721 2026] [security2:error] [pid 400813:tid 400864] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETrAABXzE"]
[Tue Jul 21 08:10:16.930819 2026] [security2:error] [pid 400813:tid 401029] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETrAABXzE"]
[Tue Jul 21 08:10:16.949241 2026] [security2:error] [pid 400813:tid 400983] [client 20.104.96.117:54114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/ops.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETsQAAATE"]
[Tue Jul 21 08:10:16.983074 2026] [security2:error] [pid 400813:tid 400946] [client 20.151.10.161:13129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9TmNZ1vbMzrdVQS3ETswAAAQw"]
[Tue Jul 21 08:10:17.164882 2026] [security2:error] [pid 400813:tid 401051] [client 134.122.94.138:55987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "accjbc.org"] [uri "/api"] [unique_id "al9TmdZ1vbMzrdVQS3ETtgAAAXU"]
[Tue Jul 21 08:10:17.216803 2026] [security2:error] [pid 400813:tid 400952] [client 20.104.96.117:57967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/xacs.php"] [unique_id "al9TmdZ1vbMzrdVQS3ETuAAAARI"]
[Tue Jul 21 08:10:17.486896 2026] [security2:error] [pid 400813:tid 401027] [client 20.206.105.145:56649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9TmdZ1vbMzrdVQS3ETwAAAAV0"]
[Tue Jul 21 08:10:17.552023 2026] [security2:error] [pid 400813:tid 401008] [client 65.21.113.253:51362] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TmdZ1vbMzrdVQS3ETxAAAAUo"]
[Tue Jul 21 08:10:17.759465 2026] [security2:error] [pid 400813:tid 401030] [client 61.1.167.83:60923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TmdZ1vbMzrdVQS3ETzAAAAWA"]
[Tue Jul 21 08:10:17.759631 2026] [security2:error] [pid 400813:tid 401030] [client 61.1.167.83:60923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TmdZ1vbMzrdVQS3ETzAAAAWA"]
[Tue Jul 21 08:10:17.904927 2026] [security2:error] [pid 400813:tid 401025] [client 20.29.126.15:9861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/article.php"] [unique_id "al9TmdZ1vbMzrdVQS3ET0AAAAVs"]
[Tue Jul 21 08:10:18.009926 2026] [security2:error] [pid 400813:tid 401049] [client 20.104.96.117:62470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET0gAAAXM"]
[Tue Jul 21 08:10:18.098055 2026] [security2:error] [pid 400813:tid 400948] [client 20.151.10.161:13269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET2QAAAQ4"]
[Tue Jul 21 08:10:18.164202 2026] [security2:error] [pid 400813:tid 400949] [client 20.206.105.145:56577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/puc.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET2gAAAQ8"]
[Tue Jul 21 08:10:18.340212 2026] [security2:error] [pid 400813:tid 401033] [client 65.21.113.253:45756] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TmdZ1vbMzrdVQS3ETzwAAAWM"]
[Tue Jul 21 08:10:18.350351 2026] [security2:error] [pid 400813:tid 401047] [client 20.220.225.223:1290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/tkikikoko.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET4wAAAXE"]
[Tue Jul 21 08:10:18.367138 2026] [security2:error] [pid 400813:tid 400951] [client 20.104.96.117:58384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/zildan.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET5AAAARE"]
[Tue Jul 21 08:10:18.434920 2026] [security2:error] [pid 400813:tid 400990] [client 103.78.200.11:58748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET5gAAATg"]
[Tue Jul 21 08:10:18.436127 2026] [security2:error] [pid 400813:tid 400990] [client 103.78.200.11:58748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET5gAAATg"]
[Tue Jul 21 08:10:18.573355 2026] [security2:error] [pid 400813:tid 400891] [remote 81.173.115.7:54422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/wp-login.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET6wABdkw"]
[Tue Jul 21 08:10:18.712833 2026] [security2:error] [pid 400813:tid 401044] [client 65.21.113.253:45760] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET3QAAAW4"]
[Tue Jul 21 08:10:18.864780 2026] [security2:error] [pid 400813:tid 401069] [client 117.210.135.0:52602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET-AAAAYc"]
[Tue Jul 21 08:10:18.864952 2026] [security2:error] [pid 400813:tid 401069] [client 117.210.135.0:52602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET-AAAAYc"]
[Tue Jul 21 08:10:18.915557 2026] [security2:error] [pid 400813:tid 400901] [remote 154.61.75.100:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexandrevitor1781543539748.0711679.meusitehostgator.com.br"] [uri "/wp-login.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET-wABLVY"]
[Tue Jul 21 08:10:18.972793 2026] [security2:error] [pid 400813:tid 401045] [client 20.151.10.161:13203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wp-content/BypassBest.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET_QAAAW8"]
[Tue Jul 21 08:10:18.979987 2026] [security2:error] [pid 400813:tid 400903] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET_gABJlg"]
[Tue Jul 21 08:10:18.980156 2026] [security2:error] [pid 400813:tid 400972] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TmtZ1vbMzrdVQS3ET_gABJlg"]
[Tue Jul 21 08:10:19.094556 2026] [security2:error] [pid 400813:tid 401009] [client 20.206.105.145:56651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/themes.php"] [unique_id "al9Tm9Z1vbMzrdVQS3EUBgAAAUs"]
[Tue Jul 21 08:10:19.185278 2026] [security2:error] [pid 400813:tid 401014] [client 20.104.96.117:54702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/mac.php"] [unique_id "al9Tm9Z1vbMzrdVQS3EUCAAAAVA"]
[Tue Jul 21 08:10:19.412377 2026] [security2:error] [pid 400813:tid 400986] [client 20.104.96.117:58414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/csa.php"] [unique_id "al9Tm9Z1vbMzrdVQS3EUCwAAATQ"]
[Tue Jul 21 08:10:19.626737 2026] [security2:error] [pid 400813:tid 400982] [client 87.116.180.198:27170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tm9Z1vbMzrdVQS3EUEgAAATA"]
[Tue Jul 21 08:10:19.626840 2026] [security2:error] [pid 400813:tid 400982] [client 87.116.180.198:27170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tm9Z1vbMzrdVQS3EUEgAAATA"]
[Tue Jul 21 08:10:19.669500 2026] [security2:error] [pid 400813:tid 401055] [client 198.54.129.60:59088] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Tm9Z1vbMzrdVQS3EUFgAAAXk"]
[Tue Jul 21 08:10:19.669611 2026] [security2:error] [pid 400813:tid 401055] [client 198.54.129.60:59088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Tm9Z1vbMzrdVQS3EUFgAAAXk"]
[Tue Jul 21 08:10:19.752526 2026] [security2:error] [pid 400813:tid 401012] [client 20.220.225.223:1803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9Tm9Z1vbMzrdVQS3EUGAAAAU4"]
[Tue Jul 21 08:10:19.932149 2026] [security2:error] [pid 400813:tid 400951] [client 91.92.41.115:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dominandomeucelular.com.br.felipecampanholo1782866942550.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9Tm9Z1vbMzrdVQS3EUHgAAARE"]
[Tue Jul 21 08:10:19.982198 2026] [proxy:error] [pid 400813:tid 401005] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:19.982274 2026] [proxy_http:error] [pid 400813:tid 401005] [client 20.151.10.161:13224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:19.983060 2026] [proxy:error] [pid 400813:tid 401005] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:19.983105 2026] [proxy_http:error] [pid 400813:tid 401005] [client 20.151.10.161:13224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:20.088612 2026] [autoindex:error] [pid 400813:tid 401032] [client 20.206.105.145:29651] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:20.112510 2026] [security2:error] [pid 400813:tid 400976] [client 20.206.105.145:29651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/8.php"] [unique_id "al9TnNZ1vbMzrdVQS3EUKAAAASo"]
[Tue Jul 21 08:10:20.387556 2026] [security2:error] [pid 400813:tid 401068] [client 38.100.221.102:18623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TnNZ1vbMzrdVQS3EUMQAAAYY"]
[Tue Jul 21 08:10:20.387668 2026] [security2:error] [pid 400813:tid 401068] [client 38.100.221.102:18623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TnNZ1vbMzrdVQS3EUMQAAAYY"]
[Tue Jul 21 08:10:20.659644 2026] [security2:error] [pid 400813:tid 401027] [client 20.104.96.117:58399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/w3llscc.php"] [unique_id "al9TnNZ1vbMzrdVQS3EUPAAAAV0"]
[Tue Jul 21 08:10:20.663335 2026] [security2:error] [pid 400813:tid 401022] [client 20.151.10.161:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/simple.php"] [unique_id "al9TnNZ1vbMzrdVQS3EUPQAAAVg"]
[Tue Jul 21 08:10:20.866594 2026] [security2:error] [pid 400813:tid 400998] [client 20.220.225.223:1039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wp-css.php"] [unique_id "al9TnNZ1vbMzrdVQS3EURQAAAUA"]
[Tue Jul 21 08:10:20.919665 2026] [security2:error] [pid 400813:tid 400982] [client 20.104.96.117:54666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/mg.php"] [unique_id "al9TnNZ1vbMzrdVQS3EUSAAAATA"]
[Tue Jul 21 08:10:20.966431 2026] [security2:error] [pid 400813:tid 400934] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TnNZ1vbMzrdVQS3EUSQABZXc"]
[Tue Jul 21 08:10:20.966618 2026] [security2:error] [pid 400813:tid 401035] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TnNZ1vbMzrdVQS3EUSQABZXc"]
[Tue Jul 21 08:10:21.019875 2026] [security2:error] [pid 400813:tid 401024] [client 20.29.126.15:11397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/bootstrap.php"] [unique_id "al9TndZ1vbMzrdVQS3EUSgAAAVo"]
[Tue Jul 21 08:10:21.026673 2026] [security2:error] [pid 400813:tid 401007] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TnNZ1vbMzrdVQS3EURwABSXY"]
[Tue Jul 21 08:10:21.214462 2026] [security2:error] [pid 400813:tid 400990] [client 20.104.96.117:62469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/qqqa.php"] [unique_id "al9TndZ1vbMzrdVQS3EUVQAAATg"]
[Tue Jul 21 08:10:21.451783 2026] [security2:error] [pid 400813:tid 400967] [client 20.206.105.145:56693] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "evelinemilfontadv.com"] [uri "/1.php"] [unique_id "al9TndZ1vbMzrdVQS3EUWQAAASE"]
[Tue Jul 21 08:10:21.452157 2026] [security2:error] [pid 400813:tid 400967] [client 20.206.105.145:56693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/1.php"] [unique_id "al9TndZ1vbMzrdVQS3EUWQAAASE"]
[Tue Jul 21 08:10:21.674717 2026] [security2:error] [pid 400813:tid 400946] [client 198.54.129.60:49682] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9TndZ1vbMzrdVQS3EUYgAAAQw"]
[Tue Jul 21 08:10:21.674792 2026] [security2:error] [pid 400813:tid 400946] [client 198.54.129.60:49682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9TndZ1vbMzrdVQS3EUYgAAAQw"]
[Tue Jul 21 08:10:21.791250 2026] [security2:error] [pid 400813:tid 400972] [client 20.151.10.161:13237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/xxx.php"] [unique_id "al9TndZ1vbMzrdVQS3EUZQAAASY"]
[Tue Jul 21 08:10:21.812154 2026] [security2:error] [pid 400813:tid 400948] [client 154.208.47.43:38732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TndZ1vbMzrdVQS3EUZwAAAQ4"]
[Tue Jul 21 08:10:21.812285 2026] [security2:error] [pid 400813:tid 400948] [client 154.208.47.43:38732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TndZ1vbMzrdVQS3EUZwAAAQ4"]
[Tue Jul 21 08:10:21.820727 2026] [security2:error] [pid 400813:tid 401051] [client 20.104.96.117:57958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wpx.php"] [unique_id "al9TndZ1vbMzrdVQS3EUaAAAAXU"]
[Tue Jul 21 08:10:21.970620 2026] [security2:error] [pid 400813:tid 401006] [client 20.220.225.223:1792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wp-explorer.php"] [unique_id "al9TndZ1vbMzrdVQS3EUagAAAUg"]
[Tue Jul 21 08:10:21.986903 2026] [security2:error] [pid 400813:tid 400989] [client 20.206.105.145:56613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/100.php"] [unique_id "al9TndZ1vbMzrdVQS3EUawAAATc"]
[Tue Jul 21 08:10:22.054607 2026] [security2:error] [pid 400813:tid 401017] [client 65.21.113.253:51362] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TntZ1vbMzrdVQS3EUbQAAAVM"]
[Tue Jul 21 08:10:22.363413 2026] [security2:error] [pid 400813:tid 400828] [remote 45.90.123.233:54940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9TntZ1vbMzrdVQS3EUeAABbQ0"]
[Tue Jul 21 08:10:22.381917 2026] [security2:error] [pid 400813:tid 401030] [client 20.151.10.161:13135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/hypo.php"] [unique_id "al9TntZ1vbMzrdVQS3EUeQAAAWA"]
[Tue Jul 21 08:10:22.383534 2026] [security2:error] [pid 400813:tid 400996] [client 20.206.105.145:56657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/about.php"] [unique_id "al9TntZ1vbMzrdVQS3EUegAAAT4"]
[Tue Jul 21 08:10:22.543612 2026] [security2:error] [pid 400813:tid 400830] [remote 57.141.18.7:56442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9TntZ1vbMzrdVQS3EUfAABMA8"]
[Tue Jul 21 08:10:22.708100 2026] [security2:error] [pid 400813:tid 401008] [client 65.21.113.253:45756] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TntZ1vbMzrdVQS3EUdQAAAUo"]
[Tue Jul 21 08:10:22.798992 2026] [security2:error] [pid 400813:tid 401047] [client 148.113.130.25:64218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "farmacianaturofarma.com.br"] [uri "/robots.txt"] [unique_id "al9TntZ1vbMzrdVQS3EUiAAAAXE"]
[Tue Jul 21 08:10:22.799064 2026] [security2:error] [pid 400813:tid 401047] [client 148.113.130.25:64218] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "farmacianaturofarma.com.br"] [uri "/robots.txt"] [unique_id "al9TntZ1vbMzrdVQS3EUiAAAAXE"]
[Tue Jul 21 08:10:22.937124 2026] [proxy:error] [pid 400813:tid 401058] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:22.937226 2026] [proxy_http:error] [pid 400813:tid 401058] [client 20.151.10.161:13219] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:22.938316 2026] [proxy:error] [pid 400813:tid 401058] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:22.938375 2026] [proxy_http:error] [pid 400813:tid 401058] [client 20.151.10.161:13219] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:23.134047 2026] [security2:error] [pid 400813:tid 400999] [client 20.206.105.145:56656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/about.php"] [unique_id "al9Tn9Z1vbMzrdVQS3EUjQAAAUE"]
[Tue Jul 21 08:10:23.371209 2026] [security2:error] [pid 400813:tid 401016] [client 20.151.10.161:13127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/chosen.php"] [unique_id "al9Tn9Z1vbMzrdVQS3EUlwAAAVI"]
[Tue Jul 21 08:10:23.439287 2026] [security2:error] [pid 400813:tid 400988] [client 20.104.96.117:58396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-css.php"] [unique_id "al9Tn9Z1vbMzrdVQS3EUmQAAATY"]
[Tue Jul 21 08:10:23.766671 2026] [security2:error] [pid 400813:tid 401056] [client 65.21.113.253:51816] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Tn9Z1vbMzrdVQS3EUlQAAAXo"]
[Tue Jul 21 08:10:23.778990 2026] [security2:error] [pid 400813:tid 400969] [client 20.206.105.145:56675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/admin.php"] [unique_id "al9Tn9Z1vbMzrdVQS3EUoQAAASM"]
[Tue Jul 21 08:10:23.910908 2026] [proxy:error] [pid 400813:tid 400970] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:23.910979 2026] [proxy_http:error] [pid 400813:tid 400970] [client 20.151.10.161:13190] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:23.911480 2026] [proxy:error] [pid 400813:tid 400970] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:23.911511 2026] [proxy_http:error] [pid 400813:tid 400970] [client 20.151.10.161:13190] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:23.965136 2026] [security2:error] [pid 400813:tid 400981] [client 20.220.225.223:1025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/akismet.php"] [unique_id "al9Tn9Z1vbMzrdVQS3EUpwAAAS8"]
[Tue Jul 21 08:10:24.004149 2026] [security2:error] [pid 400813:tid 401012] [client 14.97.58.74:60987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ToNZ1vbMzrdVQS3EUqAAAAU4"]
[Tue Jul 21 08:10:24.004266 2026] [security2:error] [pid 400813:tid 401012] [client 14.97.58.74:60987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ToNZ1vbMzrdVQS3EUqAAAAU4"]
[Tue Jul 21 08:10:24.118620 2026] [security2:error] [pid 400813:tid 401028] [client 20.104.96.117:54662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-post-data.php"] [unique_id "al9ToNZ1vbMzrdVQS3EUqgAAAV4"]
[Tue Jul 21 08:10:24.129970 2026] [security2:error] [pid 400813:tid 401020] [client 34.182.139.74:56932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9ToNZ1vbMzrdVQS3EUrAAAAVY"]
[Tue Jul 21 08:10:24.236352 2026] [security2:error] [pid 400813:tid 400984] [client 54.39.203.198:15650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "farmacianaturofarma.com.br"] [uri "/"] [unique_id "al9ToNZ1vbMzrdVQS3EUrQAAATI"]
[Tue Jul 21 08:10:24.236453 2026] [security2:error] [pid 400813:tid 400984] [client 54.39.203.198:15650] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "farmacianaturofarma.com.br"] [uri "/"] [unique_id "al9ToNZ1vbMzrdVQS3EUrQAAATI"]
[Tue Jul 21 08:10:24.265319 2026] [security2:error] [pid 400813:tid 401036] [client 86.106.84.166:56744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9ToNZ1vbMzrdVQS3EUsAAAAWY"]
[Tue Jul 21 08:10:24.265463 2026] [security2:error] [pid 400813:tid 401036] [client 86.106.84.166:56744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9ToNZ1vbMzrdVQS3EUsAAAAWY"]
[Tue Jul 21 08:10:24.292693 2026] [security2:error] [pid 400813:tid 401039] [client 20.151.10.161:13222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/file5.php"] [unique_id "al9ToNZ1vbMzrdVQS3EUsgAAAWk"]
[Tue Jul 21 08:10:24.365741 2026] [security2:error] [pid 400813:tid 401070] [client 20.197.192.193:64468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/hp3.php"] [unique_id "al9ToNZ1vbMzrdVQS3EUtgAAAYg"]
[Tue Jul 21 08:10:24.618047 2026] [security2:error] [pid 400813:tid 400949] [client 20.29.126.15:6002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/config-backup.php"] [unique_id "al9ToNZ1vbMzrdVQS3EUugAAAQ8"]
[Tue Jul 21 08:10:24.630017 2026] [security2:error] [pid 400813:tid 401022] [client 102.206.115.33:61387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ToNZ1vbMzrdVQS3EUuwAAAVg"]
[Tue Jul 21 08:10:24.630147 2026] [security2:error] [pid 400813:tid 401022] [client 102.206.115.33:61387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ToNZ1vbMzrdVQS3EUuwAAAVg"]
[Tue Jul 21 08:10:24.762647 2026] [security2:error] [pid 400813:tid 401032] [client 20.151.10.161:13186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/file.php"] [unique_id "al9ToNZ1vbMzrdVQS3EUwgAAAWI"]
[Tue Jul 21 08:10:24.766421 2026] [security2:error] [pid 400813:tid 400980] [client 20.206.105.145:56606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/admin.php"] [unique_id "al9ToNZ1vbMzrdVQS3EUwwAAAS4"]
[Tue Jul 21 08:10:25.175713 2026] [security2:error] [pid 400813:tid 401060] [client 20.151.10.161:13276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/aa2.php"] [unique_id "al9TodZ1vbMzrdVQS3EUzAAAAX4"]
[Tue Jul 21 08:10:25.262724 2026] [security2:error] [pid 400813:tid 401051] [client 20.206.105.145:56641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/edit.php"] [unique_id "al9TodZ1vbMzrdVQS3EUzwAAAXU"]
[Tue Jul 21 08:10:25.474681 2026] [security2:error] [pid 400813:tid 400987] [client 20.151.10.161:13204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/ccou.php"] [unique_id "al9TodZ1vbMzrdVQS3EU2AAAATU"]
[Tue Jul 21 08:10:25.524672 2026] [security2:error] [pid 400813:tid 400871] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TodZ1vbMzrdVQS3EU2gABDjg"]
[Tue Jul 21 08:10:25.524800 2026] [security2:error] [pid 400813:tid 400948] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TodZ1vbMzrdVQS3EU2gABDjg"]
[Tue Jul 21 08:10:25.553312 2026] [security2:error] [pid 400813:tid 400979] [client 120.56.162.40:49811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TodZ1vbMzrdVQS3EU2wAAAS0"]
[Tue Jul 21 08:10:25.553662 2026] [security2:error] [pid 400813:tid 400979] [client 120.56.162.40:49811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TodZ1vbMzrdVQS3EU2wAAAS0"]
[Tue Jul 21 08:10:25.651734 2026] [security2:error] [pid 400813:tid 401043] [client 20.104.96.117:57952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/ho.php"] [unique_id "al9TodZ1vbMzrdVQS3EU3QAAAW0"]
[Tue Jul 21 08:10:25.819117 2026] [security2:error] [pid 400813:tid 400867] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TodZ1vbMzrdVQS3EU3wABZjQ"]
[Tue Jul 21 08:10:25.819247 2026] [security2:error] [pid 400813:tid 401036] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TodZ1vbMzrdVQS3EU3wABZjQ"]
[Tue Jul 21 08:10:25.927713 2026] [security2:error] [pid 400813:tid 401052] [client 20.151.10.161:13207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/dr.php"] [unique_id "al9TodZ1vbMzrdVQS3EU5wAAAXY"]
[Tue Jul 21 08:10:26.042443 2026] [security2:error] [pid 400813:tid 400949] [client 20.206.105.145:56678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-content/admin.php"] [unique_id "al9TotZ1vbMzrdVQS3EU6wAAAQ8"]
[Tue Jul 21 08:10:26.273464 2026] [security2:error] [pid 400813:tid 400984] [client 150.129.202.39:65209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TotZ1vbMzrdVQS3EU8AAAATI"]
[Tue Jul 21 08:10:26.273868 2026] [security2:error] [pid 400813:tid 400984] [client 150.129.202.39:65209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TotZ1vbMzrdVQS3EU8AAAATI"]
[Tue Jul 21 08:10:26.436999 2026] [security2:error] [pid 400813:tid 400980] [client 20.206.105.145:56600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/f6.php"] [unique_id "al9TotZ1vbMzrdVQS3EU9QAAAS4"]
[Tue Jul 21 08:10:26.489942 2026] [proxy:error] [pid 400813:tid 400967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:26.489999 2026] [proxy_http:error] [pid 400813:tid 400967] [client 167.99.113.80:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:26.491115 2026] [proxy:error] [pid 400813:tid 400967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:26.491142 2026] [proxy_http:error] [pid 400813:tid 400967] [client 167.99.113.80:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:26.502128 2026] [security2:error] [pid 400813:tid 401007] [client 20.151.10.161:13257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/file31.php"] [unique_id "al9TotZ1vbMzrdVQS3EU-wAAAUk"]
[Tue Jul 21 08:10:26.642304 2026] [security2:error] [pid 400813:tid 400974] [client 20.220.225.223:1828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/ace2.php"] [unique_id "al9TotZ1vbMzrdVQS3EU_wAAASg"]
[Tue Jul 21 08:10:26.682866 2026] [security2:error] [pid 400813:tid 400891] [remote 212.80.9.235:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zooparquevet.com.br"] [uri "/wp-login.php"] [unique_id "al9TotZ1vbMzrdVQS3EVAwABdEw"]
[Tue Jul 21 08:10:26.741041 2026] [security2:error] [pid 400813:tid 400983] [client 20.206.105.145:56588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/inputs.php"] [unique_id "al9TotZ1vbMzrdVQS3EVBgAAATE"]
[Tue Jul 21 08:10:26.769611 2026] [proxy:error] [pid 400813:tid 401051] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:26.769689 2026] [proxy_http:error] [pid 400813:tid 401051] [client 167.99.113.80:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.rubenscoelhonascimen1781537878645.0721679.meusitehostgator.com.br/
[Tue Jul 21 08:10:26.770407 2026] [proxy:error] [pid 400813:tid 401051] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:26.770450 2026] [proxy_http:error] [pid 400813:tid 401051] [client 167.99.113.80:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.rubenscoelhonascimen1781537878645.0721679.meusitehostgator.com.br/
[Tue Jul 21 08:10:26.795069 2026] [security2:error] [pid 400813:tid 400969] [client 20.104.96.117:62481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/aunmc.php"] [unique_id "al9TotZ1vbMzrdVQS3EVCAAAASM"]
[Tue Jul 21 08:10:26.801140 2026] [security2:error] [pid 400813:tid 401006] [client 20.206.105.145:56700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/inputs.php"] [unique_id "al9TotZ1vbMzrdVQS3EVCQAAAUg"]
[Tue Jul 21 08:10:26.887458 2026] [security2:error] [pid 400813:tid 400945] [client 20.206.105.145:29632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/av.php"] [unique_id "al9TotZ1vbMzrdVQS3EVDgAAAQs"]
[Tue Jul 21 08:10:26.948163 2026] [security2:error] [pid 400813:tid 400975] [client 109.60.28.94:60546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TotZ1vbMzrdVQS3EVDwAAASk"]
[Tue Jul 21 08:10:26.948277 2026] [security2:error] [pid 400813:tid 400975] [client 109.60.28.94:60546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TotZ1vbMzrdVQS3EVDwAAASk"]
[Tue Jul 21 08:10:27.011849 2026] [security2:error] [pid 400813:tid 400976] [client 41.68.90.219:49325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9To9Z1vbMzrdVQS3EVEwAAASo"]
[Tue Jul 21 08:10:27.012845 2026] [security2:error] [pid 400813:tid 400976] [client 41.68.90.219:49325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9To9Z1vbMzrdVQS3EVEwAAASo"]
[Tue Jul 21 08:10:27.086215 2026] [security2:error] [pid 400813:tid 400981] [client 20.151.10.161:13150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/file6.php"] [unique_id "al9To9Z1vbMzrdVQS3EVGQAAAS8"]
[Tue Jul 21 08:10:27.110163 2026] [security2:error] [pid 400813:tid 400903] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9To9Z1vbMzrdVQS3EVGgABJFg"]
[Tue Jul 21 08:10:27.110279 2026] [security2:error] [pid 400813:tid 400970] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9To9Z1vbMzrdVQS3EVGgABJFg"]
[Tue Jul 21 08:10:27.130157 2026] [security2:error] [pid 400813:tid 401049] [client 20.206.105.145:56636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/classwithtostring.php"] [unique_id "al9To9Z1vbMzrdVQS3EVGwAAAXM"]
[Tue Jul 21 08:10:27.301288 2026] [security2:error] [pid 400813:tid 401063] [client 62.102.148.158:41524] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9To9Z1vbMzrdVQS3EVHwAAAYE"]
[Tue Jul 21 08:10:27.301431 2026] [security2:error] [pid 400813:tid 401063] [client 62.102.148.158:41524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9To9Z1vbMzrdVQS3EVHwAAAYE"]
[Tue Jul 21 08:10:27.390094 2026] [security2:error] [pid 400813:tid 401025] [client 20.104.96.117:57953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/xy.php"] [unique_id "al9To9Z1vbMzrdVQS3EVIwAAAVs"]
[Tue Jul 21 08:10:27.415922 2026] [security2:error] [pid 400813:tid 401042] [client 20.206.105.145:56663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9To9Z1vbMzrdVQS3EVJAAAAWw"]
[Tue Jul 21 08:10:27.441570 2026] [security2:error] [pid 400813:tid 400907] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9To9Z1vbMzrdVQS3EVJQABiFw"]
[Tue Jul 21 08:10:27.441742 2026] [security2:error] [pid 400813:tid 401070] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9To9Z1vbMzrdVQS3EVJQABiFw"]
[Tue Jul 21 08:10:27.482319 2026] [security2:error] [pid 400813:tid 401039] [client 34.182.139.74:56614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.139.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/xmlrpc.php"] [unique_id "al9To9Z1vbMzrdVQS3EVJgAAAWk"]
[Tue Jul 21 08:10:27.482446 2026] [security2:error] [pid 400813:tid 401039] [client 34.182.139.74:56614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "auriculo.liranesuliano.com"] [uri "/xmlrpc.php"] [unique_id "al9To9Z1vbMzrdVQS3EVJgAAAWk"]
[Tue Jul 21 08:10:27.571807 2026] [security2:error] [pid 400813:tid 401053] [client 20.206.105.145:56598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-blog.php"] [unique_id "al9To9Z1vbMzrdVQS3EVKgAAAXc"]
[Tue Jul 21 08:10:27.588343 2026] [security2:error] [pid 400813:tid 400908] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9To9Z1vbMzrdVQS3EVKwABYl0"]
[Tue Jul 21 08:10:27.588511 2026] [security2:error] [pid 400813:tid 401032] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9To9Z1vbMzrdVQS3EVKwABYl0"]
[Tue Jul 21 08:10:27.821948 2026] [autoindex:error] [pid 400813:tid 400962] [client 20.206.105.145:56671] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:27.853444 2026] [security2:error] [pid 400813:tid 401068] [client 20.206.105.145:56671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-content/admin.php"] [unique_id "al9To9Z1vbMzrdVQS3EVOgAAAYY"]
[Tue Jul 21 08:10:27.940577 2026] [security2:error] [pid 400813:tid 401046] [client 20.151.10.161:13122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/file15.php"] [unique_id "al9To9Z1vbMzrdVQS3EVPgAAAXA"]
[Tue Jul 21 08:10:27.978372 2026] [security2:error] [pid 400813:tid 400958] [client 34.182.139.74:52031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.139.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/xmlrpc.php"] [unique_id "al9To9Z1vbMzrdVQS3EVPwAAARg"]
[Tue Jul 21 08:10:27.978459 2026] [security2:error] [pid 400813:tid 400958] [client 34.182.139.74:52031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "auriculo.liranesuliano.com"] [uri "/xmlrpc.php"] [unique_id "al9To9Z1vbMzrdVQS3EVPwAAARg"]
[Tue Jul 21 08:10:27.978928 2026] [security2:error] [pid 400813:tid 400969] [client 20.206.105.145:56614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/adminfuns.php"] [unique_id "al9To9Z1vbMzrdVQS3EVQAAAASM"]
[Tue Jul 21 08:10:28.165875 2026] [security2:error] [pid 400813:tid 401028] [client 20.206.105.145:56595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/goods.php"] [unique_id "al9TpNZ1vbMzrdVQS3EVRQAAAV4"]
[Tue Jul 21 08:10:28.388669 2026] [security2:error] [pid 400813:tid 401016] [client 20.206.105.145:56688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ms-edit.php"] [unique_id "al9TpNZ1vbMzrdVQS3EVSAAAAVI"]
[Tue Jul 21 08:10:28.393327 2026] [security2:error] [pid 400813:tid 400998] [client 20.151.10.161:13278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/jp.php"] [unique_id "al9TpNZ1vbMzrdVQS3EVSgAAAUA"]
[Tue Jul 21 08:10:28.439428 2026] [security2:error] [pid 400813:tid 401027] [client 20.206.105.145:29662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/222.php"] [unique_id "al9TpNZ1vbMzrdVQS3EVTQAAAV0"]
[Tue Jul 21 08:10:28.520780 2026] [security2:error] [pid 400813:tid 400964] [client 103.78.200.11:59348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TpNZ1vbMzrdVQS3EVTgAAAR4"]
[Tue Jul 21 08:10:28.520923 2026] [security2:error] [pid 400813:tid 400964] [client 103.78.200.11:59348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TpNZ1vbMzrdVQS3EVTgAAAR4"]
[Tue Jul 21 08:10:28.564381 2026] [security2:error] [pid 400813:tid 401036] [client 62.102.148.158:58436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9TpNZ1vbMzrdVQS3EVUwAAAWY"]
[Tue Jul 21 08:10:28.564458 2026] [security2:error] [pid 400813:tid 401036] [client 62.102.148.158:58436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9TpNZ1vbMzrdVQS3EVUwAAAWY"]
[Tue Jul 21 08:10:28.595861 2026] [rewrite:warn] [pid 400813:tid 400930] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:10:28.799262 2026] [security2:error] [pid 400813:tid 401041] [client 20.206.105.145:56603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/cgi-bin/index.php"] [unique_id "al9TpNZ1vbMzrdVQS3EVWwAAAWs"]
[Tue Jul 21 08:10:28.813725 2026] [security2:error] [pid 400813:tid 401063] [client 198.54.129.60:47322] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9TpNZ1vbMzrdVQS3EVXAAAAYE"]
[Tue Jul 21 08:10:28.813809 2026] [security2:error] [pid 400813:tid 401063] [client 198.54.129.60:47322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9TpNZ1vbMzrdVQS3EVXAAAAYE"]
[Tue Jul 21 08:10:28.976043 2026] [security2:error] [pid 400813:tid 401039] [client 20.104.96.117:54716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/pucci.php"] [unique_id "al9TpNZ1vbMzrdVQS3EVZAAAAWk"]
[Tue Jul 21 08:10:29.053727 2026] [security2:error] [pid 400813:tid 400957] [client 65.21.113.253:45096] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TpdZ1vbMzrdVQS3EVZQAAARc"]
[Tue Jul 21 08:10:29.061943 2026] [security2:error] [pid 400813:tid 401049] [client 65.21.113.253:51816] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TpNZ1vbMzrdVQS3EVWAAAAXM"]
[Tue Jul 21 08:10:29.088923 2026] [security2:error] [pid 400813:tid 401071] [client 20.29.126.15:6869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/goods.php"] [unique_id "al9TpdZ1vbMzrdVQS3EVZwAAAYk"]
[Tue Jul 21 08:10:29.163701 2026] [autoindex:error] [pid 400813:tid 401032] [client 20.206.105.145:29692] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:29.175271 2026] [security2:error] [pid 400813:tid 400963] [client 20.206.105.145:29692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/BDKR28WP.php"] [unique_id "al9TpdZ1vbMzrdVQS3EVbAAAAR0"]
[Tue Jul 21 08:10:29.437858 2026] [security2:error] [pid 400813:tid 401052] [client 117.210.135.0:53250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TpdZ1vbMzrdVQS3EVcQAAAXY"]
[Tue Jul 21 08:10:29.437967 2026] [security2:error] [pid 400813:tid 401052] [client 117.210.135.0:53250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TpdZ1vbMzrdVQS3EVcQAAAXY"]
[Tue Jul 21 08:10:29.489293 2026] [security2:error] [pid 400813:tid 400990] [client 20.104.96.117:62526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/uoocf.php"] [unique_id "al9TpdZ1vbMzrdVQS3EVdAAAATg"]
[Tue Jul 21 08:10:29.635755 2026] [security2:error] [pid 400813:tid 400974] [client 20.151.10.161:13141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/f35.php"] [unique_id "al9TpdZ1vbMzrdVQS3EVeQAAASg"]
[Tue Jul 21 08:10:30.040071 2026] [security2:error] [pid 400813:tid 400945] [client 20.104.96.117:58431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/loader.php"] [unique_id "al9TptZ1vbMzrdVQS3EVggAAAQs"]
[Tue Jul 21 08:10:30.046725 2026] [autoindex:error] [pid 400813:tid 401044] [client 20.206.105.145:56593] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:30.066819 2026] [autoindex:error] [pid 400813:tid 401028] [client 20.206.105.145:56593] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:30.077692 2026] [security2:error] [pid 400813:tid 400822] [remote 20.75.217.69:1071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9TptZ1vbMzrdVQS3EVhwABUwc"]
[Tue Jul 21 08:10:30.092733 2026] [security2:error] [pid 400813:tid 400968] [client 20.206.105.145:56593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/raw.php"] [unique_id "al9TptZ1vbMzrdVQS3EViAAAASI"]
[Tue Jul 21 08:10:30.120749 2026] [security2:error] [pid 400813:tid 400823] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TptZ1vbMzrdVQS3EViQABKgg"]
[Tue Jul 21 08:10:30.120899 2026] [security2:error] [pid 400813:tid 400976] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TptZ1vbMzrdVQS3EViQABKgg"]
[Tue Jul 21 08:10:30.133921 2026] [security2:error] [pid 400813:tid 401029] [client 65.21.113.253:54228] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TpdZ1vbMzrdVQS3EVfAAAAV8"]
[Tue Jul 21 08:10:30.148597 2026] [security2:error] [pid 400813:tid 400975] [client 62.102.148.158:58440] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9TptZ1vbMzrdVQS3EVjQAAASk"]
[Tue Jul 21 08:10:30.148677 2026] [security2:error] [pid 400813:tid 400975] [client 62.102.148.158:58440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9TptZ1vbMzrdVQS3EVjQAAASk"]
[Tue Jul 21 08:10:30.184224 2026] [security2:error] [pid 400813:tid 401057] [client 61.1.167.83:61428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TptZ1vbMzrdVQS3EVkQAAAXs"]
[Tue Jul 21 08:10:30.184368 2026] [security2:error] [pid 400813:tid 401057] [client 61.1.167.83:61428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TptZ1vbMzrdVQS3EVkQAAAXs"]
[Tue Jul 21 08:10:30.295514 2026] [security2:error] [pid 400813:tid 401056] [client 87.116.180.198:14060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TptZ1vbMzrdVQS3EVlAAAAXo"]
[Tue Jul 21 08:10:30.295715 2026] [security2:error] [pid 400813:tid 401056] [client 87.116.180.198:14060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TptZ1vbMzrdVQS3EVlAAAAXo"]
[Tue Jul 21 08:10:30.321710 2026] [security2:error] [pid 400813:tid 401059] [client 20.151.10.161:13242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wp-load.php"] [unique_id "al9TptZ1vbMzrdVQS3EVlgAAAX0"]
[Tue Jul 21 08:10:30.751234 2026] [security2:error] [pid 400813:tid 400973] [client 20.206.105.145:56679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/abcd.php"] [unique_id "al9TptZ1vbMzrdVQS3EVrAAAASc"]
[Tue Jul 21 08:10:30.943384 2026] [proxy:error] [pid 400813:tid 401024] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:30.943466 2026] [proxy_http:error] [pid 400813:tid 401024] [client 20.151.10.161:13281] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:30.944042 2026] [proxy:error] [pid 400813:tid 401024] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:30.944071 2026] [proxy_http:error] [pid 400813:tid 401024] [client 20.151.10.161:13281] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:30.975413 2026] [security2:error] [pid 400813:tid 401031] [client 38.100.221.102:18656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TptZ1vbMzrdVQS3EVuAAAAWE"]
[Tue Jul 21 08:10:30.975502 2026] [security2:error] [pid 400813:tid 401031] [client 38.100.221.102:18656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TptZ1vbMzrdVQS3EVuAAAAWE"]
[Tue Jul 21 08:10:31.063281 2026] [security2:error] [pid 400813:tid 401054] [client 20.29.126.15:11441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/init.php"] [unique_id "al9Tp9Z1vbMzrdVQS3EVvAAAAXg"]
[Tue Jul 21 08:10:31.394319 2026] [security2:error] [pid 400813:tid 401017] [client 141.11.107.74:64387] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cavilhaslufra.com.br"] [uri "/"] [unique_id "al9Tp9Z1vbMzrdVQS3EVygAAAVM"]
[Tue Jul 21 08:10:31.725618 2026] [security2:error] [pid 400813:tid 400944] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tp9Z1vbMzrdVQS3EV1wABCj0"]
[Tue Jul 21 08:10:31.728302 2026] [security2:error] [pid 400813:tid 401056] [client 65.21.113.253:45096] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Tp9Z1vbMzrdVQS3EV4AAAAXo"]
[Tue Jul 21 08:10:31.729319 2026] [autoindex:error] [pid 400813:tid 401010] [client 20.226.114.112:14376] AH01276: Cannot serve directory /home4/bcaccj52/accjbr.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:31.745970 2026] [autoindex:error] [pid 400813:tid 401055] [client 20.226.114.112:14376] AH01276: Cannot serve directory /home4/bcaccj52/accjbr.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:31.751274 2026] [security2:error] [pid 400813:tid 401041] [client 20.226.114.112:14376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "accjbr.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Tp9Z1vbMzrdVQS3EV4gAAAWs"]
[Tue Jul 21 08:10:31.776086 2026] [security2:error] [pid 400813:tid 401061] [client 20.226.114.112:11431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.114.226.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "accjbr.com"] [uri "/xmlrpc.php"] [unique_id "al9Tp9Z1vbMzrdVQS3EV4wAAAX8"]
[Tue Jul 21 08:10:31.813244 2026] [autoindex:error] [pid 400813:tid 400953] [client 20.226.114.112:9335] AH01276: Cannot serve directory /home4/bcaccj52/accjbr.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:31.822440 2026] [security2:error] [pid 400813:tid 401042] [client 20.226.114.112:9335] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "accjbr.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Tp9Z1vbMzrdVQS3EV6AAAAWw"]
[Tue Jul 21 08:10:31.853144 2026] [security2:error] [pid 400813:tid 401047] [client 20.226.114.112:9313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "accjbr.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Tp9Z1vbMzrdVQS3EV6wAAAXE"]
[Tue Jul 21 08:10:31.862986 2026] [security2:error] [pid 400813:tid 401066] [client 20.226.114.112:14380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "accjbr.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9Tp9Z1vbMzrdVQS3EV7AAAAYQ"]
[Tue Jul 21 08:10:31.883054 2026] [security2:error] [pid 400813:tid 401005] [client 20.226.114.112:15294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "accjbr.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Tp9Z1vbMzrdVQS3EV7QAAAUc"]
[Tue Jul 21 08:10:31.903470 2026] [security2:error] [pid 400813:tid 401049] [client 20.226.114.112:1774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "accjbr.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9Tp9Z1vbMzrdVQS3EV7gAAAXM"]
[Tue Jul 21 08:10:31.931806 2026] [security2:error] [pid 400813:tid 401038] [client 20.226.114.112:1736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "accjbr.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9Tp9Z1vbMzrdVQS3EV8gAAAWg"]
[Tue Jul 21 08:10:31.948592 2026] [security2:error] [pid 400813:tid 400971] [client 20.226.114.112:11632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "accjbr.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Tp9Z1vbMzrdVQS3EV8wAAASU"]
[Tue Jul 21 08:10:31.960506 2026] [security2:error] [pid 400813:tid 401030] [client 20.226.114.112:11597] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "accjbr.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Tp9Z1vbMzrdVQS3EV9AAAAWA"]
[Tue Jul 21 08:10:31.978533 2026] [security2:error] [pid 400813:tid 401053] [client 20.226.114.112:15227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "accjbr.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Tp9Z1vbMzrdVQS3EV9gAAAXc"]
[Tue Jul 21 08:10:31.993334 2026] [security2:error] [pid 400813:tid 401001] [client 20.226.114.112:9325] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "accjbr.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9Tp9Z1vbMzrdVQS3EV9wAAAUM"]
[Tue Jul 21 08:10:32.025239 2026] [security2:error] [pid 400813:tid 401035] [client 20.226.114.112:1781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "accjbr.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9TqNZ1vbMzrdVQS3EV_AAAAWU"]
[Tue Jul 21 08:10:32.031726 2026] [security2:error] [pid 400813:tid 400901] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TqNZ1vbMzrdVQS3EV_QABdlY"]
[Tue Jul 21 08:10:32.031902 2026] [security2:error] [pid 400813:tid 401052] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TqNZ1vbMzrdVQS3EV_QABdlY"]
[Tue Jul 21 08:10:32.037085 2026] [security2:error] [pid 400813:tid 401007] [client 20.104.96.117:57964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/spadex.php"] [unique_id "al9TqNZ1vbMzrdVQS3EV_gAAAUk"]
[Tue Jul 21 08:10:32.040827 2026] [security2:error] [pid 400813:tid 400999] [client 20.226.114.112:11600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "accjbr.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9TqNZ1vbMzrdVQS3EV_wAAAUE"]
[Tue Jul 21 08:10:32.072986 2026] [security2:error] [pid 400813:tid 400990] [client 20.226.114.112:15208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "accjbr.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9TqNZ1vbMzrdVQS3EWAAAAATg"]
[Tue Jul 21 08:10:32.151222 2026] [proxy:error] [pid 400813:tid 400965] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:32.151286 2026] [proxy_http:error] [pid 400813:tid 400965] [client 20.151.10.161:13271] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:32.151743 2026] [proxy:error] [pid 400813:tid 400965] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:10:32.151766 2026] [proxy_http:error] [pid 400813:tid 400965] [client 20.151.10.161:13271] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:10:32.288626 2026] [security2:error] [pid 400813:tid 400964] [client 154.208.47.43:39138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TqNZ1vbMzrdVQS3EWDgAAAR4"]
[Tue Jul 21 08:10:32.288849 2026] [security2:error] [pid 400813:tid 400964] [client 154.208.47.43:39138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TqNZ1vbMzrdVQS3EWDgAAAR4"]
[Tue Jul 21 08:10:32.318864 2026] [security2:error] [pid 400813:tid 401028] [client 20.206.105.145:56658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/a1.php"] [unique_id "al9TqNZ1vbMzrdVQS3EWEwAAAV4"]
[Tue Jul 21 08:10:32.395121 2026] [security2:error] [pid 400813:tid 401071] [client 65.21.113.253:51816] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Tp9Z1vbMzrdVQS3EV9QAAAYk"]
[Tue Jul 21 08:10:32.452833 2026] [security2:error] [pid 400813:tid 400948] [client 20.220.225.223:1340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/ms.php"] [unique_id "al9TqNZ1vbMzrdVQS3EWFwAAAQ4"]
[Tue Jul 21 08:10:32.745622 2026] [security2:error] [pid 400813:tid 401026] [client 20.151.10.161:13143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9TqNZ1vbMzrdVQS3EWJgAAAVw"]
[Tue Jul 21 08:10:32.765395 2026] [security2:error] [pid 400813:tid 401022] [client 20.104.96.117:54130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/black.php"] [unique_id "al9TqNZ1vbMzrdVQS3EWJwAAAVg"]
[Tue Jul 21 08:10:33.035642 2026] [security2:error] [pid 400813:tid 400963] [client 20.206.105.145:56605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9TqdZ1vbMzrdVQS3EWLgAAAR0"]
[Tue Jul 21 08:10:33.245534 2026] [security2:error] [pid 400813:tid 401070] [client 20.151.10.161:13196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wp-links.php"] [unique_id "al9TqdZ1vbMzrdVQS3EWNgAAAYg"]
[Tue Jul 21 08:10:33.264855 2026] [security2:error] [pid 400813:tid 400947] [client 20.197.192.193:2841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9TqdZ1vbMzrdVQS3EWNwAAAQ0"]
[Tue Jul 21 08:10:33.608105 2026] [security2:error] [pid 400813:tid 400967] [client 20.206.105.145:29634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9TqdZ1vbMzrdVQS3EWPQAAASE"]
[Tue Jul 21 08:10:33.701897 2026] [security2:error] [pid 400813:tid 401018] [client 20.151.10.161:13159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/solo1.php"] [unique_id "al9TqdZ1vbMzrdVQS3EWQwAAAVQ"]
[Tue Jul 21 08:10:33.728310 2026] [security2:error] [pid 400813:tid 400945] [client 20.151.10.161:55835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9TqdZ1vbMzrdVQS3EWRwAAAQs"]
[Tue Jul 21 08:10:33.844078 2026] [security2:error] [pid 400813:tid 401051] [client 114.119.140.13:38855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "diskvidros.com.br"] [uri "/"] [unique_id "al9TqdZ1vbMzrdVQS3EWSgAAAXU"], referer: http://diskvidros.com.br?page_id=12
[Tue Jul 21 08:10:33.925080 2026] [security2:error] [pid 400813:tid 401058] [client 20.206.105.145:56680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-content/BypassBest.php"] [unique_id "al9TqdZ1vbMzrdVQS3EWSwAAAXw"]
[Tue Jul 21 08:10:34.073291 2026] [security2:error] [pid 400813:tid 401036] [client 20.151.10.161:13140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/sixxis.php"] [unique_id "al9TqtZ1vbMzrdVQS3EWTwAAAWY"]
[Tue Jul 21 08:10:34.104943 2026] [security2:error] [pid 400813:tid 401031] [client 65.21.113.253:54236] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TqdZ1vbMzrdVQS3EWPwAAAWE"]
[Tue Jul 21 08:10:34.170260 2026] [security2:error] [pid 400813:tid 400944] [client 20.197.192.193:2756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9TqtZ1vbMzrdVQS3EWVAAAAQo"]
[Tue Jul 21 08:10:34.431036 2026] [security2:error] [pid 400813:tid 401053] [client 20.206.105.145:56602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/simple.php"] [unique_id "al9TqtZ1vbMzrdVQS3EWZQAAAXc"]
[Tue Jul 21 08:10:34.506011 2026] [security2:error] [pid 400813:tid 401033] [client 125.18.144.2:12421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9TqtZ1vbMzrdVQS3EWagAAAWM"]
[Tue Jul 21 08:10:34.506124 2026] [security2:error] [pid 400813:tid 401033] [client 125.18.144.2:12421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9TqtZ1vbMzrdVQS3EWagAAAWM"]
[Tue Jul 21 08:10:34.600549 2026] [security2:error] [pid 400813:tid 400993] [client 20.104.96.117:62509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/iywwi.php"] [unique_id "al9TqtZ1vbMzrdVQS3EWawAAATs"]
[Tue Jul 21 08:10:34.784412 2026] [security2:error] [pid 400813:tid 401017] [client 20.206.105.145:56654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/xxx.php"] [unique_id "al9TqtZ1vbMzrdVQS3EWkwAAAVM"]
[Tue Jul 21 08:10:34.842002 2026] [security2:error] [pid 400813:tid 401046] [client 20.104.96.117:54148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/2x.php"] [unique_id "al9TqtZ1vbMzrdVQS3EWmAAAAXA"]
[Tue Jul 21 08:10:34.993724 2026] [security2:error] [pid 400813:tid 400972] [client 20.151.10.161:13258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/2P.update.php"] [unique_id "al9TqtZ1vbMzrdVQS3EWoAAAASY"]
[Tue Jul 21 08:10:35.113200 2026] [security2:error] [pid 400813:tid 400956] [client 20.197.192.193:2833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/dp.php"] [unique_id "al9Tq9Z1vbMzrdVQS3EWpgAAARY"]
[Tue Jul 21 08:10:35.149422 2026] [security2:error] [pid 400813:tid 401047] [client 154.92.130.89:46335] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://:"] [hostname "www.elitegeo.com.br"] [uri "/"] [unique_id "al9Tq9Z1vbMzrdVQS3EWqAAAAXE"]
[Tue Jul 21 08:10:35.179221 2026] [security2:error] [pid 400813:tid 400954] [client 102.206.115.33:64951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Tq9Z1vbMzrdVQS3EWqQAAARQ"]
[Tue Jul 21 08:10:35.179322 2026] [security2:error] [pid 400813:tid 400954] [client 102.206.115.33:64951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Tq9Z1vbMzrdVQS3EWqQAAARQ"]
[Tue Jul 21 08:10:35.204800 2026] [security2:error] [pid 400813:tid 401054] [client 20.206.105.145:56699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/hypo.php"] [unique_id "al9Tq9Z1vbMzrdVQS3EWqgAAAXg"]
[Tue Jul 21 08:10:35.238287 2026] [security2:error] [pid 400813:tid 401051] [client 20.104.96.117:54127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/zlece.php"] [unique_id "al9Tq9Z1vbMzrdVQS3EWrwAAAXU"]
[Tue Jul 21 08:10:35.450569 2026] [autoindex:error] [pid 400813:tid 401041] [client 20.206.105.145:56607] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:35.475177 2026] [security2:error] [pid 400813:tid 401017] [client 20.206.105.145:56607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/chosen.php"] [unique_id "al9Tq9Z1vbMzrdVQS3EWwQAAAVM"]
[Tue Jul 21 08:10:35.624459 2026] [security2:error] [pid 400813:tid 400933] [remote 103.152.165.165:49226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.165.152.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rosisestefanoadvocacia.guiiaz.com.br"] [uri "/wp-login.php"] [unique_id "al9TqtZ1vbMzrdVQS3EWbQABLXY"]
[Tue Jul 21 08:10:35.788826 2026] [security2:error] [pid 400813:tid 400947] [client 20.151.10.161:13291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/a.php"] [unique_id "al9Tq9Z1vbMzrdVQS3EWyQAAAQ0"]
[Tue Jul 21 08:10:35.824267 2026] [autoindex:error] [pid 400813:tid 401063] [client 85.204.70.100:0] AH01276: Cannot serve directory /home2/andr9968/confeitariaemcamadas.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:35.828474 2026] [autoindex:error] [pid 400813:tid 401052] [client 20.206.105.145:29654] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:35.837600 2026] [security2:error] [pid 400813:tid 400951] [client 20.206.105.145:29654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file5.php"] [unique_id "al9Tq9Z1vbMzrdVQS3EWzgAAARE"]
[Tue Jul 21 08:10:35.976733 2026] [autoindex:error] [pid 400813:tid 401066] [client 85.204.70.100:0] AH01276: Cannot serve directory /home2/andr9968/confeitariaemcamadas.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:36.048142 2026] [security2:error] [pid 400813:tid 401018] [client 20.206.105.145:56645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file.php"] [unique_id "al9TrNZ1vbMzrdVQS3EW1AAAAVQ"]
[Tue Jul 21 08:10:36.128835 2026] [security2:error] [pid 400813:tid 400958] [client 20.151.10.161:55828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9TrNZ1vbMzrdVQS3EW2gAAARg"]
[Tue Jul 21 08:10:36.218873 2026] [security2:error] [pid 400813:tid 400963] [client 120.56.162.40:50297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TrNZ1vbMzrdVQS3EW3AAAAR0"]
[Tue Jul 21 08:10:36.219001 2026] [security2:error] [pid 400813:tid 400963] [client 120.56.162.40:50297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TrNZ1vbMzrdVQS3EW3AAAAR0"]
[Tue Jul 21 08:10:36.261174 2026] [security2:error] [pid 400813:tid 400997] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9TrNZ1vbMzrdVQS3EW3wAAAT8"]
[Tue Jul 21 08:10:36.294452 2026] [security2:error] [pid 400813:tid 400890] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TrNZ1vbMzrdVQS3EW4QABJks"]
[Tue Jul 21 08:10:36.294752 2026] [security2:error] [pid 400813:tid 400972] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TrNZ1vbMzrdVQS3EW4QABJks"]
[Tue Jul 21 08:10:36.300722 2026] [security2:error] [pid 400813:tid 401044] [client 20.206.105.145:29684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/aa2.php"] [unique_id "al9TrNZ1vbMzrdVQS3EW4wAAAW4"]
[Tue Jul 21 08:10:36.405785 2026] [security2:error] [pid 400813:tid 401045] [client 85.204.70.100:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TrNZ1vbMzrdVQS3EW6AAAAW8"]
[Tue Jul 21 08:10:36.476499 2026] [security2:error] [pid 400813:tid 400889] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TrNZ1vbMzrdVQS3EW6QABOUo"]
[Tue Jul 21 08:10:36.476635 2026] [security2:error] [pid 400813:tid 400991] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TrNZ1vbMzrdVQS3EW6QABOUo"]
[Tue Jul 21 08:10:36.505962 2026] [security2:error] [pid 400813:tid 401004] [client 74.7.228.49:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "sarareginadosreis1782388162420.0721679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9TrNZ1vbMzrdVQS3EW6gABRlg"]
[Tue Jul 21 08:10:36.632575 2026] [security2:error] [pid 400813:tid 401061] [client 20.206.105.145:29658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ccou.php"] [unique_id "al9TrNZ1vbMzrdVQS3EW8AAAAX8"]
[Tue Jul 21 08:10:36.686048 2026] [autoindex:error] [pid 400813:tid 401065] [client 85.204.70.100:0] AH01276: Cannot serve directory /home2/andr9968/confeitariaemcamadas.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:36.960008 2026] [security2:error] [pid 400813:tid 401066] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9TrNZ1vbMzrdVQS3EW_wAAAYQ"]
[Tue Jul 21 08:10:37.101627 2026] [security2:error] [pid 400813:tid 401047] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9TrdZ1vbMzrdVQS3EXCQAAAXE"]
[Tue Jul 21 08:10:37.104475 2026] [security2:error] [pid 400813:tid 401057] [client 150.129.202.39:65388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXCgAAAXs"]
[Tue Jul 21 08:10:37.107400 2026] [security2:error] [pid 400813:tid 401057] [client 150.129.202.39:65388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXCgAAAXs"]
[Tue Jul 21 08:10:37.126708 2026] [security2:error] [pid 400813:tid 400954] [client 20.206.105.145:56667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/dr.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXCwAAARQ"]
[Tue Jul 21 08:10:37.259834 2026] [security2:error] [pid 400813:tid 400945] [client 20.104.96.117:54679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/vssrs.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXEAAAAQs"]
[Tue Jul 21 08:10:37.322091 2026] [security2:error] [pid 400813:tid 401045] [client 20.151.10.161:55848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/x.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXFAAAAW8"]
[Tue Jul 21 08:10:37.330336 2026] [security2:error] [pid 400813:tid 400948] [client 20.151.10.161:13238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/k.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXFQAAAQ4"]
[Tue Jul 21 08:10:37.373440 2026] [security2:error] [pid 400813:tid 400952] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9TrdZ1vbMzrdVQS3EXGAAAARI"]
[Tue Jul 21 08:10:37.518741 2026] [security2:error] [pid 400813:tid 401022] [client 65.21.113.253:53736] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TrdZ1vbMzrdVQS3EXHgAAAVg"]
[Tue Jul 21 08:10:37.575746 2026] [security2:error] [pid 400813:tid 401053] [client 62.102.148.158:48772] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXIAAAAXc"]
[Tue Jul 21 08:10:37.575834 2026] [security2:error] [pid 400813:tid 401053] [client 62.102.148.158:48772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXIAAAAXc"]
[Tue Jul 21 08:10:37.645683 2026] [security2:error] [pid 400813:tid 401068] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9TrdZ1vbMzrdVQS3EXKQAAAYY"]
[Tue Jul 21 08:10:37.667571 2026] [security2:error] [pid 400813:tid 400977] [client 65.49.20.66:18098] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "roanalacerda.com.br"] [uri "/"] [unique_id "al9TrdZ1vbMzrdVQS3EXKgAAASs"]
[Tue Jul 21 08:10:37.672653 2026] [security2:error] [pid 400813:tid 401063] [client 20.197.192.193:3185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/aa1.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXKwAAAYE"]
[Tue Jul 21 08:10:37.731069 2026] [security2:error] [pid 400813:tid 400997] [client 41.68.90.219:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.90.68.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXLQAAAT8"]
[Tue Jul 21 08:10:37.732204 2026] [security2:error] [pid 400813:tid 400997] [client 41.68.90.219:49796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXLQAAAT8"]
[Tue Jul 21 08:10:37.800302 2026] [security2:error] [pid 400813:tid 400928] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXLwABg3E"]
[Tue Jul 21 08:10:37.800458 2026] [security2:error] [pid 400813:tid 401065] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXLwABg3E"]
[Tue Jul 21 08:10:37.831103 2026] [security2:error] [pid 400813:tid 400990] [client 109.60.28.94:19583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXMAAAATg"]
[Tue Jul 21 08:10:37.831678 2026] [security2:error] [pid 400813:tid 400990] [client 109.60.28.94:19583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXMAAAATg"]
[Tue Jul 21 08:10:37.917978 2026] [security2:error] [pid 400813:tid 400971] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9TrdZ1vbMzrdVQS3EXNAAAASU"]
[Tue Jul 21 08:10:37.920527 2026] [security2:error] [pid 400813:tid 400934] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXNQABJHc"]
[Tue Jul 21 08:10:37.920673 2026] [security2:error] [pid 400813:tid 400970] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXNQABJHc"]
[Tue Jul 21 08:10:37.932671 2026] [security2:error] [pid 400813:tid 400957] [client 20.226.60.151:48851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXNgAAARc"]
[Tue Jul 21 08:10:38.135318 2026] [security2:error] [pid 400813:tid 400984] [client 65.21.113.253:54236] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TrdZ1vbMzrdVQS3EXLgAAATI"]
[Tue Jul 21 08:10:38.152513 2026] [security2:error] [pid 400813:tid 401027] [client 20.151.10.161:13266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/w.php"] [unique_id "al9TrtZ1vbMzrdVQS3EXOwAAAV0"]
[Tue Jul 21 08:10:38.192578 2026] [security2:error] [pid 400813:tid 400969] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9TrtZ1vbMzrdVQS3EXPAAAASM"]
[Tue Jul 21 08:10:38.237612 2026] [security2:error] [pid 400813:tid 400937] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TrtZ1vbMzrdVQS3EXPQABVno"]
[Tue Jul 21 08:10:38.237736 2026] [security2:error] [pid 400813:tid 401020] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TrtZ1vbMzrdVQS3EXPQABVno"]
[Tue Jul 21 08:10:38.464485 2026] [security2:error] [pid 400813:tid 401056] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9TrtZ1vbMzrdVQS3EXRgAAAXo"]
[Tue Jul 21 08:10:38.549468 2026] [security2:error] [pid 400813:tid 401004] [client 20.206.105.145:56653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file31.php"] [unique_id "al9TrtZ1vbMzrdVQS3EXRwAAAUY"]
[Tue Jul 21 08:10:38.736581 2026] [security2:error] [pid 400813:tid 401000] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9TrtZ1vbMzrdVQS3EXSwAAAUI"]
[Tue Jul 21 08:10:38.762943 2026] [security2:error] [pid 400813:tid 401071] [client 20.104.96.117:54090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wicked.php"] [unique_id "al9TrtZ1vbMzrdVQS3EXTAAAAYk"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 08:10:38.936551 2026] [security2:error] [pid 400813:tid 400996] [client 20.151.10.161:51031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/j260624_13.php"] [unique_id "al9TrtZ1vbMzrdVQS3EXUwAAAT4"]
[Tue Jul 21 08:10:39.008161 2026] [security2:error] [pid 400813:tid 400981] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Tr9Z1vbMzrdVQS3EXWAAAAS8"]
[Tue Jul 21 08:10:39.030420 2026] [authz_core:error] [pid 400813:tid 401030] [client 20.29.126.15:2715] AH01630: client denied by server configuration: /home1/autom219/atilafagundes.com.br/php.ini
[Tue Jul 21 08:10:39.281227 2026] [security2:error] [pid 400813:tid 401001] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Tr9Z1vbMzrdVQS3EXXAAAAUM"]
[Tue Jul 21 08:10:39.325543 2026] [security2:error] [pid 400813:tid 401032] [client 20.29.126.15:2715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/settings.php"] [unique_id "al9Tr9Z1vbMzrdVQS3EXXgAAAWI"]
[Tue Jul 21 08:10:39.337968 2026] [security2:error] [pid 400813:tid 400968] [client 103.78.200.11:59982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tr9Z1vbMzrdVQS3EXYAAAASI"]
[Tue Jul 21 08:10:39.338168 2026] [security2:error] [pid 400813:tid 400968] [client 103.78.200.11:59982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tr9Z1vbMzrdVQS3EXYAAAASI"]
[Tue Jul 21 08:10:39.553665 2026] [security2:error] [pid 400813:tid 401052] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Tr9Z1vbMzrdVQS3EXaQAAAXY"]
[Tue Jul 21 08:10:39.578014 2026] [security2:error] [pid 400813:tid 400971] [client 20.226.60.151:48821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Tr9Z1vbMzrdVQS3EXawAAASU"]
[Tue Jul 21 08:10:39.633361 2026] [security2:error] [pid 400813:tid 401010] [client 65.21.113.253:54238] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Tr9Z1vbMzrdVQS3EXWgAAAUw"]
[Tue Jul 21 08:10:39.646310 2026] [security2:error] [pid 400813:tid 400970] [client 20.206.105.145:29659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file6.php"] [unique_id "al9Tr9Z1vbMzrdVQS3EXbgAAASQ"]
[Tue Jul 21 08:10:39.711972 2026] [security2:error] [pid 400813:tid 400982] [client 20.104.96.117:62570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/gqgsa.php"] [unique_id "al9Tr9Z1vbMzrdVQS3EXbwAAATA"]
[Tue Jul 21 08:10:39.727091 2026] [security2:error] [pid 400813:tid 401047] [client 20.104.96.117:54681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/24.php"] [unique_id "al9Tr9Z1vbMzrdVQS3EXcAAAAXE"]
[Tue Jul 21 08:10:39.848745 2026] [security2:error] [pid 400813:tid 401020] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9Tr9Z1vbMzrdVQS3EXcQAAAVY"]
[Tue Jul 21 08:10:39.975738 2026] [security2:error] [pid 400813:tid 401035] [client 117.210.135.0:53896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tr9Z1vbMzrdVQS3EXcwAAAWU"]
[Tue Jul 21 08:10:39.975870 2026] [security2:error] [pid 400813:tid 401035] [client 117.210.135.0:53896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tr9Z1vbMzrdVQS3EXcwAAAWU"]
[Tue Jul 21 08:10:40.097366 2026] [security2:error] [pid 400813:tid 401013] [client 20.206.105.145:56644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/file15.php"] [unique_id "al9TsNZ1vbMzrdVQS3EXegAAAU8"]
[Tue Jul 21 08:10:40.120002 2026] [security2:error] [pid 400813:tid 401058] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9TsNZ1vbMzrdVQS3EXewAAAXw"]
[Tue Jul 21 08:10:40.170362 2026] [security2:error] [pid 400813:tid 400980] [client 20.104.96.117:54108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/xacs.php"] [unique_id "al9TsNZ1vbMzrdVQS3EXfAAAAS4"]
[Tue Jul 21 08:10:40.246506 2026] [security2:error] [pid 400813:tid 400962] [client 20.151.10.161:13267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/insc.php"] [unique_id "al9TsNZ1vbMzrdVQS3EXfgAAARw"]
[Tue Jul 21 08:10:40.391946 2026] [security2:error] [pid 400813:tid 401047] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9TsNZ1vbMzrdVQS3EXgAAAAXE"]
[Tue Jul 21 08:10:40.509752 2026] [security2:error] [pid 400813:tid 400817] [remote 57.141.18.12:53346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9TsNZ1vbMzrdVQS3EXgQABJAI"]
[Tue Jul 21 08:10:40.617752 2026] [security2:error] [pid 400813:tid 401015] [client 20.151.10.161:51043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/d62.php"] [unique_id "al9TsNZ1vbMzrdVQS3EXiAAAAVE"]
[Tue Jul 21 08:10:40.633559 2026] [security2:error] [pid 400813:tid 401036] [client 20.29.126.15:2292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/g.php"] [unique_id "al9TsNZ1vbMzrdVQS3EXiQAAAWY"]
[Tue Jul 21 08:10:40.664407 2026] [security2:error] [pid 400813:tid 401041] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9TsNZ1vbMzrdVQS3EXigAAAWs"]
[Tue Jul 21 08:10:40.907358 2026] [security2:error] [pid 400813:tid 400960] [client 20.206.105.145:29643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/jp.php"] [unique_id "al9TsNZ1vbMzrdVQS3EXkQAAARo"]
[Tue Jul 21 08:10:40.912323 2026] [security2:error] [pid 400813:tid 401003] [client 87.116.180.198:27205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TsNZ1vbMzrdVQS3EXkgAAAUU"]
[Tue Jul 21 08:10:40.912450 2026] [security2:error] [pid 400813:tid 401003] [client 87.116.180.198:27205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TsNZ1vbMzrdVQS3EXkgAAAUU"]
[Tue Jul 21 08:10:40.936219 2026] [security2:error] [pid 400813:tid 401035] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.confeitariaemcamadas.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9TsNZ1vbMzrdVQS3EXlQAAAWU"]
[Tue Jul 21 08:10:40.936834 2026] [security2:error] [pid 400813:tid 401055] [client 20.226.60.151:48849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/media.php"] [unique_id "al9TsNZ1vbMzrdVQS3EXlgAAAXk"]
[Tue Jul 21 08:10:40.954728 2026] [security2:error] [pid 400813:tid 400841] [remote 68.178.160.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9TsNZ1vbMzrdVQS3EXlwABfRo"]
[Tue Jul 21 08:10:41.152082 2026] [security2:error] [pid 400813:tid 401053] [client 20.104.96.117:54690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/zildan.php"] [unique_id "al9TsdZ1vbMzrdVQS3EXnwAAAXc"]
[Tue Jul 21 08:10:41.231534 2026] [security2:error] [pid 400813:tid 400936] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TsdZ1vbMzrdVQS3EXowABRHk"]
[Tue Jul 21 08:10:41.231687 2026] [security2:error] [pid 400813:tid 401002] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TsdZ1vbMzrdVQS3EXowABRHk"]
[Tue Jul 21 08:10:41.238081 2026] [security2:error] [pid 400813:tid 400957] [client 20.206.105.145:29638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/f35.php"] [unique_id "al9TsdZ1vbMzrdVQS3EXpAAAARc"]
[Tue Jul 21 08:10:41.253118 2026] [security2:error] [pid 400813:tid 401067] [client 20.104.96.117:58425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/ctex1.php"] [unique_id "al9TsdZ1vbMzrdVQS3EXpgAAAYU"]
[Tue Jul 21 08:10:41.505123 2026] [security2:error] [pid 400813:tid 401030] [client 38.100.221.102:17541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TsdZ1vbMzrdVQS3EXrAAAAWA"]
[Tue Jul 21 08:10:41.505272 2026] [security2:error] [pid 400813:tid 401030] [client 38.100.221.102:17541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TsdZ1vbMzrdVQS3EXrAAAAWA"]
[Tue Jul 21 08:10:41.696962 2026] [security2:error] [pid 400813:tid 401022] [client 20.226.60.151:48830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/images.php"] [unique_id "al9TsdZ1vbMzrdVQS3EXtAAAAVg"]
[Tue Jul 21 08:10:41.737494 2026] [security2:error] [pid 400813:tid 401017] [client 162.219.176.3:53244] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9TsdZ1vbMzrdVQS3EXtQAAAVM"]
[Tue Jul 21 08:10:41.737600 2026] [security2:error] [pid 400813:tid 401017] [client 162.219.176.3:53244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9TsdZ1vbMzrdVQS3EXtQAAAVM"]
[Tue Jul 21 08:10:42.064166 2026] [autoindex:error] [pid 400813:tid 400854] [remote 45.175.115.210:51174] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/?pag=aluno_chamada
[Tue Jul 21 08:10:42.094702 2026] [security2:error] [pid 400813:tid 400991] [client 69.165.75.221:55587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.75.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/index.php"] [unique_id "al9TsdZ1vbMzrdVQS3EXngAAATk"], referer: https://oficialwebsite.com.br
[Tue Jul 21 08:10:42.124423 2026] [security2:error] [pid 400813:tid 400967] [client 20.226.60.151:48850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/gecko.php"] [unique_id "al9TstZ1vbMzrdVQS3EXvQAAASE"]
[Tue Jul 21 08:10:42.130689 2026] [security2:error] [pid 400813:tid 401016] [client 65.21.113.253:53736] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TstZ1vbMzrdVQS3EXvgAAAVI"]
[Tue Jul 21 08:10:42.293181 2026] [security2:error] [pid 400813:tid 401012] [client 20.206.105.145:56623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-load.php"] [unique_id "al9TstZ1vbMzrdVQS3EXwwAAAU4"]
[Tue Jul 21 08:10:42.420647 2026] [security2:error] [pid 400813:tid 401036] [client 20.197.192.193:61844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/acew67.php"] [unique_id "al9TstZ1vbMzrdVQS3EXygAAAWY"]
[Tue Jul 21 08:10:42.444854 2026] [security2:error] [pid 400813:tid 401044] [client 61.1.167.83:61931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TstZ1vbMzrdVQS3EXywAAAW4"]
[Tue Jul 21 08:10:42.445000 2026] [security2:error] [pid 400813:tid 401044] [client 61.1.167.83:61931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TstZ1vbMzrdVQS3EXywAAAW4"]
[Tue Jul 21 08:10:42.470599 2026] [security2:error] [pid 400813:tid 400865] [remote 207.180.241.245:36370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "premiercservices.com"] [uri "/wp-login.php"] [unique_id "al9TstZ1vbMzrdVQS3EXzQABNjI"]
[Tue Jul 21 08:10:42.482170 2026] [security2:error] [pid 400813:tid 400958] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TstZ1vbMzrdVQS3EXxAABGCo"]
[Tue Jul 21 08:10:42.503803 2026] [security2:error] [pid 400813:tid 400850] [remote 130.185.118.215:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9TstZ1vbMzrdVQS3EXzgABYSM"]
[Tue Jul 21 08:10:42.586635 2026] [security2:error] [pid 400813:tid 401039] [client 20.104.96.117:54712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/csa.php"] [unique_id "al9TstZ1vbMzrdVQS3EX1QAAAWk"]
[Tue Jul 21 08:10:42.759053 2026] [security2:error] [pid 400813:tid 401056] [client 65.21.113.253:54238] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TstZ1vbMzrdVQS3EXyQAAAXo"]
[Tue Jul 21 08:10:42.766419 2026] [security2:error] [pid 400813:tid 401013] [client 20.151.10.161:13260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9TstZ1vbMzrdVQS3EX3gAAAU8"]
[Tue Jul 21 08:10:42.783050 2026] [security2:error] [pid 400813:tid 400990] [client 20.29.126.15:2277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/403.php"] [unique_id "al9TstZ1vbMzrdVQS3EX3wAAATg"]
[Tue Jul 21 08:10:42.915800 2026] [security2:error] [pid 400813:tid 401028] [client 154.208.47.42:61364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TstZ1vbMzrdVQS3EX6AAAAV4"]
[Tue Jul 21 08:10:42.915957 2026] [security2:error] [pid 400813:tid 401028] [client 154.208.47.42:61364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TstZ1vbMzrdVQS3EX6AAAAV4"]
[Tue Jul 21 08:10:43.131558 2026] [autoindex:error] [pid 400813:tid 401019] [client 20.206.105.145:56615] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:43.510991 2026] [security2:error] [pid 400813:tid 401026] [client 20.226.60.151:48831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/82.php"] [unique_id "al9Ts9Z1vbMzrdVQS3EYBAAAAVw"]
[Tue Jul 21 08:10:43.530303 2026] [security2:error] [pid 400813:tid 400906] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ts9Z1vbMzrdVQS3EYBQABe1s"]
[Tue Jul 21 08:10:43.530557 2026] [security2:error] [pid 400813:tid 401057] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ts9Z1vbMzrdVQS3EYBQABe1s"]
[Tue Jul 21 08:10:43.758795 2026] [autoindex:error] [pid 400813:tid 401035] [client 20.206.105.145:56615] AH01276: Cannot serve directory /home1/evelin77/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:10:43.774121 2026] [security2:error] [pid 400813:tid 400975] [client 20.206.105.145:56615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9Ts9Z1vbMzrdVQS3EYEQAAASk"]
[Tue Jul 21 08:10:44.211155 2026] [security2:error] [pid 400813:tid 400979] [client 20.104.96.117:54684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/w3llscc.php"] [unique_id "al9TtNZ1vbMzrdVQS3EYGgAAAS0"]
[Tue Jul 21 08:10:44.298547 2026] [security2:error] [pid 400813:tid 401027] [client 20.206.105.145:56694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wp-links.php"] [unique_id "al9TtNZ1vbMzrdVQS3EYIwAAAV0"]
[Tue Jul 21 08:10:44.356564 2026] [autoindex:error] [pid 400813:tid 400919] [remote 45.175.115.210:51174] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/?pag=chamada_consulta&modal=chamada&chamada=117
[Tue Jul 21 08:10:44.367383 2026] [security2:error] [pid 400813:tid 400972] [client 20.151.10.161:51054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ups.php"] [unique_id "al9TtNZ1vbMzrdVQS3EYJQAAASY"]
[Tue Jul 21 08:10:44.587027 2026] [security2:error] [pid 400813:tid 401036] [client 20.151.10.161:13213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/u.php"] [unique_id "al9TtNZ1vbMzrdVQS3EYLAAAAWY"]
[Tue Jul 21 08:10:44.795968 2026] [security2:error] [pid 400813:tid 401057] [client 20.151.10.161:51041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/k.php"] [unique_id "al9TtNZ1vbMzrdVQS3EYNQAAAXs"]
[Tue Jul 21 08:10:44.892903 2026] [security2:error] [pid 400813:tid 401047] [client 65.21.113.253:40716] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TtNZ1vbMzrdVQS3EYKAAAAXE"]
[Tue Jul 21 08:10:45.130573 2026] [security2:error] [pid 400813:tid 401012] [client 14.97.58.74:28790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYPQAAAU4"]
[Tue Jul 21 08:10:45.130706 2026] [security2:error] [pid 400813:tid 401012] [client 14.97.58.74:28790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYPQAAAU4"]
[Tue Jul 21 08:10:45.301709 2026] [security2:error] [pid 400813:tid 401035] [client 20.206.105.145:56640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/solo1.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYRQAAAWU"]
[Tue Jul 21 08:10:45.469458 2026] [security2:error] [pid 400813:tid 400979] [client 20.104.96.117:54095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wpx.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYSgAAAS0"]
[Tue Jul 21 08:10:45.501305 2026] [security2:error] [pid 400813:tid 400997] [client 20.206.105.145:56660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/sixxis.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYSwAAAT8"]
[Tue Jul 21 08:10:45.536425 2026] [security2:error] [pid 400813:tid 401004] [client 20.206.105.145:56579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/2P.update.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYTAAAAUY"]
[Tue Jul 21 08:10:45.578863 2026] [security2:error] [pid 400813:tid 400956] [client 20.206.105.145:56666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/a.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYTgAAARY"]
[Tue Jul 21 08:10:45.599074 2026] [security2:error] [pid 400813:tid 400986] [client 20.206.105.145:56618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/k.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYTwAAATQ"]
[Tue Jul 21 08:10:45.698742 2026] [security2:error] [pid 400813:tid 400992] [client 65.21.113.253:53736] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TtdZ1vbMzrdVQS3EYUQAAATo"]
[Tue Jul 21 08:10:45.722470 2026] [security2:error] [pid 400813:tid 401056] [client 102.206.115.33:61308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYUwAAAXo"]
[Tue Jul 21 08:10:45.722942 2026] [security2:error] [pid 400813:tid 401056] [client 102.206.115.33:61308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYUwAAAXo"]
[Tue Jul 21 08:10:45.739251 2026] [security2:error] [pid 400813:tid 401040] [client 20.29.126.15:2267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.atilafagundes.com.br"] [uri "/api.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYVAAAAWo"]
[Tue Jul 21 08:10:45.782808 2026] [security2:error] [pid 400813:tid 400980] [client 20.151.10.161:13060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/sss.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYVwAAAS4"]
[Tue Jul 21 08:10:45.812717 2026] [security2:error] [pid 400813:tid 401046] [client 20.151.10.161:55857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/k2.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYXQAAAXA"]
[Tue Jul 21 08:10:45.816578 2026] [security2:error] [pid 400813:tid 401023] [client 20.206.105.145:29611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/w.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYXgAAAVk"]
[Tue Jul 21 08:10:46.334703 2026] [security2:error] [pid 400813:tid 401000] [client 65.21.113.253:40716] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TtdZ1vbMzrdVQS3EYYAAAAUI"]
[Tue Jul 21 08:10:46.508699 2026] [security2:error] [pid 400813:tid 400961] [client 20.197.192.193:64290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/else1.php"] [unique_id "al9TttZ1vbMzrdVQS3EYaQAAARs"]
[Tue Jul 21 08:10:46.516928 2026] [security2:error] [pid 400813:tid 400990] [client 20.151.10.161:51061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/k3.php"] [unique_id "al9TttZ1vbMzrdVQS3EYagAAATg"]
[Tue Jul 21 08:10:46.649466 2026] [mpm_event:notice] [pid 131539:tid 131539] AH00493: SIGUSR1 received.  Doing graceful restart
[Tue Jul 21 08:10:46.825540 2026] [security2:error] [pid 400813:tid 400940] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TttZ1vbMzrdVQS3EYcAABEn0"]
[Tue Jul 21 08:10:46.825744 2026] [security2:error] [pid 400813:tid 400952] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TttZ1vbMzrdVQS3EYcAABEn0"]
[Tue Jul 21 08:10:46.895646 2026] [security2:error] [pid 400813:tid 401044] [client 120.56.162.40:50798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TttZ1vbMzrdVQS3EYcQAAAW4"]
[Tue Jul 21 08:10:46.895777 2026] [security2:error] [pid 400813:tid 401044] [client 120.56.162.40:50798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TttZ1vbMzrdVQS3EYcQAAAW4"]
[Tue Jul 21 08:10:47.849439 2026] [:notice] [pid 229238:tid 229238] [host root@br1102.hostgator.com.br] mod_lsapi:  Selfstarter 229238 stopped
[Tue Jul 21 08:10:50.416670 2026] [lsapi:notice] [pid 131539:tid 131539] mod_lsapi:  version 1.1-92
[Tue Jul 21 08:10:50.432826 2026] [:notice] [pid 402022:tid 402022] [host root@br1102.hostgator.com.br] mod_lsapi:  Selfstarter 402022 started
[Tue Jul 21 08:10:50.447136 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oppbrazil.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.448727 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: locadoracmd.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.454140 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbc.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.464829 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbr.com.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.477665 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: metodoatracaoconsciente.com.vanderleiasilva.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.480210 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sofiagheller1782846626000.argentajoias.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.480614 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sofiagheller1782846537000.argentajoias.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.485777 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: getveltrixhealth.com.shopmelhorcompraonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.487699 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: adloop.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.488190 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: contafic.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.488701 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: climadek.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.489069 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lojacasacosta.com.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.489571 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: voztricolor.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.489941 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arenaalphaville.com.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.490299 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rioclaroimovel.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.490671 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marketingderua.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.491186 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tabelionatoportoalegre.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.491694 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: learningsociety.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.492025 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: clubmarketplace.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.492510 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arenaalphaville.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.492853 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: app.itqmogiguacu.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.493187 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lp.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.493685 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.494167 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.meupsiquiatraonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.494498 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: empresas.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.494892 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: dizi.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.495576 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rdgoseguros.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.495937 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: diziseguros.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.500653 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rilicitacoes.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.501113 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rilicitacoes.com.br.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.501596 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: espaconeuroascensao.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.502104 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: espaconeuroascensao.com.br.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.505441 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sscoenper.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.505846 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ssvistorias.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.506183 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rastreamentobh.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.506644 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: locamotobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.506990 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: companhiatop.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.507494 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: acheservicos.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.507832 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aluguelmotobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.508166 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aluguelcarrobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.514172 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: patihipopressivo.com.patyhipopressivo.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.514533 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: patihipopressivo.com.br.patyhipopressivo.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.518137 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyer.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.518618 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyerapp.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.518988 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.519313 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vespnutricao.com.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.519846 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.com.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.520207 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.533172 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lojinhadoprofessor.lojinhadaprofessora.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.537615 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: leonardodossantoshen1782739753000.metropollitano.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.539929 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: unoperformancedigital.com.br.karenvieiramarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.540406 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jbms.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.540764 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: benti.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.541108 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: yuribenassi.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.541439 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: wbapoiocontabil.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.541791 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: movimenti.com.br.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.549836 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sigescala.com.sigescala.meusitehostgator.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.562411 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vivenciarempauta.vivenciarempauta.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.568576 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: 3d-surgery.3d-surgery.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.569079 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vivafinanceiras.com.br.vivafinanceira.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.574100 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: academycont.com.goldentrips40.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.577129 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: trendsol.com.br.fusoesaquisicoes.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.579322 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: libertysolutions.figempreendimentos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.581612 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: naturofarma.com.br.farmaciafarmula.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.582126 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: farmacianaturofarma.com.br.farmaciafarmula.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.583157 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: meuamordevoltaa.estriasnuncamaiss.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.584240 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atividadessprontas.online.estriasnuncamaiss.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.590533 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: esidiomass.com.br.eslanguageschool.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.590911 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: porondeeuestive.com.br.eslanguageschool.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.601190 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: deniltoncostasilva1748033966000.samanenergia.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.605266 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: santotchay.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.605629 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: santotchay.com.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.606167 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: osantotchay.com.br.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.606664 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oinglesdescomplicado.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.607028 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: brasilmotoeletrica.com.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.614415 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: thenexbr.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.629344 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: c5liberdades.store.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.629689 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtoswendell.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.630041 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtosnapromo.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.631038 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: c5liberdades.com.br.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.638559 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtosnapromo.com.br.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.643606 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: weddinglarissaefelipe.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.646203 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtoswendellcarvalho.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.647218 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: exclusivepromotiontoday.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.653634 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pandie.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.654000 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guarushop.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.654355 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guarushop2.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.654710 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olhobionico.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.655054 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pandoradango.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.655387 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guiadeoferta.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.655722 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fofoqueironews.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.656061 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: reidocouro.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.656411 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bloquetebrasil.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.656771 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: protetordegraxa.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.660044 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atom-growth.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.660540 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atom-growth.com.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.661056 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: confiancedigital.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.661427 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: buddyclub.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.661898 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gotavitaoriginal.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.662361 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: motoboyjaguariuna.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.663195 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jandiraemdestaque.com.br.jornaldagrandesp.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.682901 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbc.com.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.689198 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.690986 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sociooculto.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.691635 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: exnova.tech.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.692703 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.store.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.693072 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marlonbarreto.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.693403 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.693899 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atilafagundes.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.694250 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: suaconsulta.fun.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.695244 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: escolhasaudavel.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.696070 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinicius-schneider.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.696531 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sociooculto.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.696881 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olimposolar.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.697362 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nextfitjourney.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.698118 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: themaisonhommes.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.698464 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tamojuntomidias.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.698822 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gustvoferraritrader.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.699290 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marlonbarreto.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.699723 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: escolhasaudavel.shop.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.700092 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atilafagundes.online.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.700423 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinicius-schneider.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.700960 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mariabonfim1762105378000.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.701414 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gustvoferraritrader.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.702621 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: flowwshop.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.703363 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agmiz.com.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.704200 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: comecx.online.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.704790 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: flowwshop.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.706393 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.findcomp.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.706944 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: importeicomponentes.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.711194 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aede.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.711878 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: suora.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.712420 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: condmidia.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.712934 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: recowmenda.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.713403 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: valeuefalou.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.714101 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: trilhasdafe.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.714950 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bergsantana.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.715785 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: shyoftherock.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.716580 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pegueaestrada.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.717182 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nocaminhodafe.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.717683 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arielson.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.718022 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: amareloturquesa.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.718466 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: terraluna.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.718917 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: zooparquevet.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.719235 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nosnaestrada.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.847367 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fusoesaquisicoes.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.891715 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conairmfg.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.898519 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.944859 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: revistareflexopolitico.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.946170 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ethanslowell.com.infoalert.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.948739 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: evolvaa.online.evolia.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.951332 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bracks.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.958426 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: raimundol.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.963195 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conhecaonordeste.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.963729 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: overkotz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.964319 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lucaskotovicz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.964732 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: kotovicz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.969292 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agendazap.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.971295 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ebookswl.com.wendelleite.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.974595 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: empacta.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.976179 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: inovaeditorial.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.977297 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: volyoaudiobooks.com.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.982960 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: slapingles.com.teacheraleff.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.983459 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: speakinglikeapro.teacheraleff.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.984005 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: brasilcertdigital.tavarescont.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.989568 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: wenith.com.br.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.990433 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783665345000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.991299 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783664968000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.992198 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783664932000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:50.992834 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783569474000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.001196 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: solarisimplementos.com.solarisimplementos.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.005006 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: madmoholding.saojorgesiderurgia.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.010938 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: evolvaa.com.evolia.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.013822 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sulmov.com.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.014335 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: expovilhena.com.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.014969 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tinybooks.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.015512 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: planamoveis.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.016025 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: paulakaoana.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.016523 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: expovilhena.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.017029 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: muskintranet.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.017528 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: infonetelecom.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.018046 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agendamasutti.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.018557 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: politicabrasil.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.019076 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: acerteaquestao.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.019535 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mavieloeducacao.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.020017 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: noticiasrondonia.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.020512 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jornalbrasileiro.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.021020 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mavieloperformance.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.021518 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ceramicasantoaugusto.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.024287 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mrragrorepresentacoes.com.mrragrorepresentacoesltda.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.035632 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aprendizadosemlimites.store.peticoesvencedorasofc.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.046684 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gabivet24h.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.047385 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blessoriginal.com.br.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.048254 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marmorariasolare.com.br.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.088595 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: institutonwa.nwalouwacom.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.089097 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: deniansantos.com.nwalouwacom.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.089426 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fitconecta.academiausina.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.090131 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinculampe.com.br.academiausina.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.094931 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: camilajung.mktcouple.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.095732 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mixpedido.mixpdv.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.096125 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guianordestino.mixpdv.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.100729 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sulprimesc.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.101679 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: zyveria.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.102471 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: multicarsc.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.102841 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marquemarketing360.com.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.103335 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pontodooleomecanica.com.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.103665 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: capitalautocentermecanica.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.107984 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.108469 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.store.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.108826 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.online.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.133925 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rcv.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.134236 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rtdi.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.134540 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rego.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.134876 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: forte.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.135211 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: claret.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.135541 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: portali.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.135888 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mcstilo.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.136233 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: joaorocha.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.136596 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: emonteiro.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.136959 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: robertinho.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.137313 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: parqueprado.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.137643 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: asrealestate.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.137958 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lopeslascasas.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.138286 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rstlimoveis.com.br.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.138613 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: residencialvilaliviero.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.145482 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aengenhariadolucro.com.br.infoalert.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.178742 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: beautyline2.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.179458 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: thejapanway.com.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.180232 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: shopbestdaily.com.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.181583 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oferta.roncostop.com.br.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.181932 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: artix.locaiestetica.com.br.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.182302 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: camillasandrini1772124780000.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.191741 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: potencialilimitado.com.br.alzirarhein.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.197419 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.202939 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: triviaodontologi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.248216 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mastercatu.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.255728 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.346692 2026] [log_config:warn] [pid 352421:tid 352647] (32)Broken pipe: [client 103.175.47.131:41438] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:10:51.346712 2026] [log_config:warn] [pid 352421:tid 352647] (32)Broken pipe: [client 103.175.47.131:41438] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:10:51.346949 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:10:51.368328 2026] [qos:notice] [pid 131539:tid 131539] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Tue Jul 21 08:10:51.695124 2026] [http2:info] [pid 131539:tid 131539] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Tue Jul 21 08:10:51.701245 2026] [mpm_event:notice] [pid 131539:tid 131539] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Tue Jul 21 08:10:51.701258 2026] [core:notice] [pid 131539:tid 131539] AH00094: Command line: '/usr/sbin/httpd'
[Tue Jul 21 08:10:52.245425 2026] [log_config:warn] [pid 400813:tid 400984] (32)Broken pipe: [client 212.156.70.154:16595] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:10:52.245448 2026] [log_config:warn] [pid 400813:tid 400984] (32)Broken pipe: [client 212.156.70.154:16595] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:10:52.781927 2026] [http2:info] [pid 402041:tid 402041] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 08:10:52.802184 2026] [security2:error] [pid 402041:tid 402174] [client 20.104.96.117:62533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/elbzl.php"] [unique_id "al9TvIiENNLP6XjiHQs3kAAAAZA"]
[Tue Jul 21 08:10:52.803227 2026] [security2:error] [pid 402041:tid 402177] [client 20.104.96.117:54714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-css.php"] [unique_id "al9TvIiENNLP6XjiHQs3kgAAAZM"]
[Tue Jul 21 08:10:52.803587 2026] [security2:error] [pid 402041:tid 402183] [client 20.151.10.161:51032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/k4.php"] [unique_id "al9TvIiENNLP6XjiHQs3lAAAAZk"]
[Tue Jul 21 08:10:52.803989 2026] [security2:error] [pid 402041:tid 402181] [client 20.226.60.151:48833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/admin.php"] [unique_id "al9TvIiENNLP6XjiHQs3lQAAAZc"]
[Tue Jul 21 08:10:52.804801 2026] [security2:error] [pid 402041:tid 402189] [client 62.102.148.158:59836] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9TvIiENNLP6XjiHQs3mAAAAZ8"]
[Tue Jul 21 08:10:52.804890 2026] [security2:error] [pid 402041:tid 402189] [client 62.102.148.158:59836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9TvIiENNLP6XjiHQs3mAAAAZ8"]
[Tue Jul 21 08:10:52.805393 2026] [security2:error] [pid 402041:tid 402194] [client 20.197.192.193:64260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/bscclapb.php"] [unique_id "al9TvIiENNLP6XjiHQs3mgAAAaQ"]
[Tue Jul 21 08:10:52.808561 2026] [security2:error] [pid 402041:tid 402198] [client 20.104.96.117:58428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/edorxrr.php"] [unique_id "al9TvIiENNLP6XjiHQs3nAAAAag"]
[Tue Jul 21 08:10:52.810796 2026] [security2:error] [pid 402041:tid 402210] [client 86.106.84.166:44842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9TvIiENNLP6XjiHQs3ogAAAbQ"]
[Tue Jul 21 08:10:52.810922 2026] [security2:error] [pid 402041:tid 402210] [client 86.106.84.166:44842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9TvIiENNLP6XjiHQs3ogAAAbQ"]
[Tue Jul 21 08:10:52.811278 2026] [security2:error] [pid 402041:tid 402213] [client 198.54.129.60:57258] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9TvIiENNLP6XjiHQs3owAAAbc"]
[Tue Jul 21 08:10:52.811381 2026] [security2:error] [pid 402041:tid 402213] [client 198.54.129.60:57258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9TvIiENNLP6XjiHQs3owAAAbc"]
[Tue Jul 21 08:10:52.819231 2026] [security2:error] [pid 402041:tid 402190] [client 20.151.10.161:13056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/sss.php"] [unique_id "al9TvIiENNLP6XjiHQs3pwAAAaA"]
[Tue Jul 21 08:10:52.820663 2026] [security2:error] [pid 402041:tid 402217] [client 65.21.113.253:56426] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TvIiENNLP6XjiHQs3pQAAAbs"]
[Tue Jul 21 08:10:52.931805 2026] [security2:error] [pid 402041:tid 402055] [remote 35.243.233.29:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "royalbsolutions.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9TvIiENNLP6XjiHQs3uAAB7ws"]
[Tue Jul 21 08:10:52.934329 2026] [security2:error] [pid 402041:tid 402056] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TvIiENNLP6XjiHQs3uQABrQw"]
[Tue Jul 21 08:10:52.934498 2026] [security2:error] [pid 402041:tid 402203] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TvIiENNLP6XjiHQs3uQABrQw"]
[Tue Jul 21 08:10:52.939560 2026] [security2:error] [pid 402041:tid 402219] [client 74.7.175.154:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "joandersonsilveiraso1749139264539.0721679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9TvIiENNLP6XjiHQs3vQABvQ4"]
[Tue Jul 21 08:10:52.971178 2026] [security2:error] [pid 402041:tid 402193] [client 162.219.176.3:57654] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9TvIiENNLP6XjiHQs3mQAAAaM"]
[Tue Jul 21 08:10:52.971295 2026] [security2:error] [pid 402041:tid 402193] [client 162.219.176.3:57654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9TvIiENNLP6XjiHQs3mQAAAaM"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 08:10:53.066131 2026] [security2:error] [pid 402041:tid 402064] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs3zAABwxQ"]
[Tue Jul 21 08:10:53.066204 2026] [security2:error] [pid 402041:tid 402064] [remote 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs3zAABwxQ"]
[Tue Jul 21 08:10:53.084492 2026] [security2:error] [pid 402041:tid 402065] [remote 35.243.233.29:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.233.243.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs3zgACDRU"]
[Tue Jul 21 08:10:53.108876 2026] [security2:error] [pid 402041:tid 402066] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs30wABpRY"]
[Tue Jul 21 08:10:53.109098 2026] [security2:error] [pid 402041:tid 402195] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs30wABpRY"]
[Tue Jul 21 08:10:53.121952 2026] [security2:error] [pid 402041:tid 402068] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs31QABwRg"]
[Tue Jul 21 08:10:53.122154 2026] [security2:error] [pid 402041:tid 402223] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs31QABwRg"]
[Tue Jul 21 08:10:53.170284 2026] [autoindex:error] [pid 402041:tid 402077] [remote 45.175.115.210:51420] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/?pag=chamada_consulta&modal=chamada&chamada=117
[Tue Jul 21 08:10:53.185870 2026] [security2:error] [pid 402041:tid 402190] [client 62.102.148.158:52470] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs33wAAAaA"]
[Tue Jul 21 08:10:53.185947 2026] [security2:error] [pid 402041:tid 402190] [client 62.102.148.158:52470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs33wAAAaA"]
[Tue Jul 21 08:10:53.202619 2026] [security2:error] [pid 402041:tid 402078] [remote 102.16.125.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.125.16.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs34QABpyI"]
[Tue Jul 21 08:10:53.202773 2026] [security2:error] [pid 402041:tid 402197] [client 102.16.125.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs34QABpyI"]
[Tue Jul 21 08:10:53.226082 2026] [security2:error] [pid 402041:tid 402081] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs35gABoiU"]
[Tue Jul 21 08:10:53.226220 2026] [security2:error] [pid 402041:tid 402192] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs35gABoiU"]
[Tue Jul 21 08:10:53.255703 2026] [security2:error] [pid 402041:tid 402199] [client 109.60.28.94:20065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs36QAAAak"]
[Tue Jul 21 08:10:53.256446 2026] [security2:error] [pid 402041:tid 402199] [client 109.60.28.94:20065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs36QAAAak"]
[Tue Jul 21 08:10:53.370929 2026] [security2:error] [pid 402041:tid 402218] [client 87.116.180.198:27189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs37wAAAbw"]
[Tue Jul 21 08:10:53.374267 2026] [security2:error] [pid 402041:tid 402218] [client 87.116.180.198:27189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs37wAAAbw"]
[Tue Jul 21 08:10:53.460321 2026] [security2:error] [pid 402041:tid 402228] [client 65.21.113.253:40732] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TvYiENNLP6XjiHQs3ywAAAcY"]
[Tue Jul 21 08:10:53.463992 2026] [security2:error] [pid 402041:tid 402246] [client 38.100.221.102:17314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs39AAAAdg"]
[Tue Jul 21 08:10:53.464326 2026] [security2:error] [pid 402041:tid 402246] [client 38.100.221.102:17314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs39AAAAdg"]
[Tue Jul 21 08:10:53.469111 2026] [security2:error] [pid 402041:tid 402215] [client 117.210.135.0:54558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs39QAAAbk"]
[Tue Jul 21 08:10:53.469201 2026] [security2:error] [pid 402041:tid 402215] [client 117.210.135.0:54558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs39QAAAbk"]
[Tue Jul 21 08:10:53.472667 2026] [security2:error] [pid 402041:tid 402265] [client 20.151.10.161:51011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/k5.php"] [unique_id "al9TvYiENNLP6XjiHQs39gAAAes"]
[Tue Jul 21 08:10:53.515983 2026] [security2:error] [pid 402041:tid 402247] [client 154.208.47.43:39974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs3-AAAAdk"]
[Tue Jul 21 08:10:53.516116 2026] [security2:error] [pid 402041:tid 402247] [client 154.208.47.43:39974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs3-AAAAdk"]
[Tue Jul 21 08:10:53.552792 2026] [security2:error] [pid 402041:tid 402273] [client 20.104.96.117:58386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/miru1.php"] [unique_id "al9TvYiENNLP6XjiHQs3-gAAAfM"]
[Tue Jul 21 08:10:53.571868 2026] [security2:error] [pid 402041:tid 402211] [client 103.78.200.11:60533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs3-wAAAbU"]
[Tue Jul 21 08:10:53.572701 2026] [security2:error] [pid 402041:tid 402211] [client 103.78.200.11:60533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvYiENNLP6XjiHQs3-wAAAbU"]
[Tue Jul 21 08:10:53.641047 2026] [security2:error] [pid 402041:tid 402275] [client 20.151.10.161:13139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/c.php"] [unique_id "al9TvYiENNLP6XjiHQs3_gAAAfU"]
[Tue Jul 21 08:10:53.805345 2026] [security2:error] [pid 402041:tid 402173] [client 20.206.105.145:56691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/insc.php"] [unique_id "al9TvIiENNLP6XjiHQs3kQAAAY8"]
[Tue Jul 21 08:10:53.893494 2026] [security2:error] [pid 402041:tid 402250] [client 134.122.94.138:65101] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "accjbc.org"] [uri "/"] [unique_id "al9TvYiENNLP6XjiHQs4CQAAAdw"]
[Tue Jul 21 08:10:53.893597 2026] [security2:error] [pid 402041:tid 402213] [client 20.226.60.151:48846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/adminner.php"] [unique_id "al9TvYiENNLP6XjiHQs4CAAAAbc"]
[Tue Jul 21 08:10:53.893727 2026] [security2:error] [pid 402041:tid 402259] [client 65.21.113.253:34304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TvYiENNLP6XjiHQs3-QAAAeU"]
[Tue Jul 21 08:10:53.983043 2026] [security2:error] [pid 402041:tid 402197] [client 20.151.10.161:55837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/w.php"] [unique_id "al9TvYiENNLP6XjiHQs4EAAAAac"]
[Tue Jul 21 08:10:53.984399 2026] [security2:error] [pid 402041:tid 402179] [client 78.47.173.76:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9TvIiENNLP6XjiHQs3xQABlRE"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:10:54.093331 2026] [security2:error] [pid 402041:tid 402282] [client 78.46.215.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9TvIiENNLP6XjiHQs3xgAB_BI"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:10:54.096131 2026] [security2:error] [pid 402041:tid 402192] [client 20.151.10.161:13152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/aa.php"] [unique_id "al9TvoiENNLP6XjiHQs4FwAAAaI"]
[Tue Jul 21 08:10:54.397170 2026] [security2:error] [pid 402041:tid 402235] [client 20.206.105.145:56620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9TvoiENNLP6XjiHQs4IQAAAc0"]
[Tue Jul 21 08:10:54.419412 2026] [security2:error] [pid 402041:tid 402109] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvoiENNLP6XjiHQs4JAAB5EE"]
[Tue Jul 21 08:10:54.419569 2026] [security2:error] [pid 402041:tid 402258] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TvoiENNLP6XjiHQs4JAAB5EE"]
[Tue Jul 21 08:10:54.534241 2026] [security2:error] [pid 402041:tid 402175] [client 78.47.173.76:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9TvoiENNLP6XjiHQs4JgABkUM"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:10:54.627100 2026] [security2:error] [pid 402041:tid 402203] [client 20.104.96.117:57975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/sump1.php"] [unique_id "al9TvoiENNLP6XjiHQs4KQAAAa0"]
[Tue Jul 21 08:10:54.640065 2026] [security2:error] [pid 402041:tid 402196] [client 78.46.215.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9TvoiENNLP6XjiHQs4KgABpkU"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:10:54.721254 2026] [security2:error] [pid 402041:tid 402264] [client 34.182.139.74:65084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oriorixas.blog.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9TvoiENNLP6XjiHQs4LAAAAeo"]
[Tue Jul 21 08:10:54.774891 2026] [security2:error] [pid 402041:tid 402204] [client 20.151.10.161:13163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/100.php"] [unique_id "al9TvoiENNLP6XjiHQs4MAAAAa4"]
[Tue Jul 21 08:10:54.897506 2026] [security2:error] [pid 402041:tid 402261] [client 20.206.105.145:29667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/u.php"] [unique_id "al9TvoiENNLP6XjiHQs4NgAAAec"]
[Tue Jul 21 08:10:54.923301 2026] [security2:error] [pid 402041:tid 402118] [remote 35.243.233.29:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.233.243.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TvoiENNLP6XjiHQs4NwAB-Uo"]
[Tue Jul 21 08:10:54.923512 2026] [security2:error] [pid 402041:tid 402279] [client 35.243.233.29:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TvoiENNLP6XjiHQs4NwAB-Uo"]
[Tue Jul 21 08:10:55.038961 2026] [security2:error] [pid 402041:tid 402211] [client 20.163.37.97:36198] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.71"] [uri "/index.cgi"] [unique_id "al9Tv4iENNLP6XjiHQs4PAAAAbU"]
[Tue Jul 21 08:10:55.063195 2026] [security2:error] [pid 402041:tid 402293] [client 20.206.105.145:29677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/sss.php"] [unique_id "al9Tv4iENNLP6XjiHQs4PQAAAgc"]
[Tue Jul 21 08:10:55.149026 2026] [security2:error] [pid 402041:tid 402268] [client 20.206.105.145:56698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/sss.php"] [unique_id "al9Tv4iENNLP6XjiHQs4PgAAAe4"]
[Tue Jul 21 08:10:55.203922 2026] [security2:error] [pid 402041:tid 402225] [client 20.206.105.145:29645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/c.php"] [unique_id "al9Tv4iENNLP6XjiHQs4PwAAAcM"]
[Tue Jul 21 08:10:55.204027 2026] [security2:error] [pid 402041:tid 402299] [client 20.226.60.151:48825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/admin.php"] [unique_id "al9Tv4iENNLP6XjiHQs4QAAAAg0"]
[Tue Jul 21 08:10:55.237210 2026] [security2:error] [pid 402041:tid 402292] [client 34.182.139.74:49838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.139.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oriorixas.blog.br"] [uri "/xmlrpc.php"] [unique_id "al9Tv4iENNLP6XjiHQs4QQAAAgY"]
[Tue Jul 21 08:10:55.347806 2026] [security2:error] [pid 402041:tid 402210] [client 20.206.105.145:56685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/aa.php"] [unique_id "al9Tv4iENNLP6XjiHQs4TAAAAbQ"]
[Tue Jul 21 08:10:55.375579 2026] [security2:error] [pid 402041:tid 402178] [client 20.104.96.117:58371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/file5.php"] [unique_id "al9Tv4iENNLP6XjiHQs4TQAAAZQ"]
[Tue Jul 21 08:10:55.594266 2026] [security2:error] [pid 402041:tid 402197] [client 20.151.10.161:51046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/fpwch.php"] [unique_id "al9Tv4iENNLP6XjiHQs4UQAAAac"]
[Tue Jul 21 08:10:55.595529 2026] [security2:error] [pid 402041:tid 402179] [client 20.151.10.161:13134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/footer.php"] [unique_id "al9Tv4iENNLP6XjiHQs4UgAAAZU"]
[Tue Jul 21 08:10:55.666957 2026] [security2:error] [pid 402041:tid 402130] [remote 188.164.197.230:45988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Tv4iENNLP6XjiHQs4VAABqFY"]
[Tue Jul 21 08:10:55.667138 2026] [security2:error] [pid 402041:tid 402198] [client 188.164.197.230:45988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Tv4iENNLP6XjiHQs4VAABqFY"]
[Tue Jul 21 08:10:55.735516 2026] [security2:error] [pid 402041:tid 402273] [client 61.1.167.83:62440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tv4iENNLP6XjiHQs4WgAAAfM"]
[Tue Jul 21 08:10:55.740951 2026] [security2:error] [pid 402041:tid 402273] [client 61.1.167.83:62440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tv4iENNLP6XjiHQs4WgAAAfM"]
[Tue Jul 21 08:10:55.752472 2026] [security2:error] [pid 402041:tid 402288] [client 111.93.58.162:42737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Tv4iENNLP6XjiHQs4WwAAAgI"]
[Tue Jul 21 08:10:55.752656 2026] [security2:error] [pid 402041:tid 402288] [client 111.93.58.162:42737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Tv4iENNLP6XjiHQs4WwAAAgI"]
[Tue Jul 21 08:10:55.826375 2026] [security2:error] [pid 402041:tid 402135] [remote 162.19.246.208:37622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "monicamirandapereira1751478737000.bellarthconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "al9Tv4iENNLP6XjiHQs4YAABsFs"]
[Tue Jul 21 08:10:55.832234 2026] [security2:error] [pid 402041:tid 402257] [client 20.206.105.145:56664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/100.php"] [unique_id "al9Tv4iENNLP6XjiHQs4YwAAAeM"]
[Tue Jul 21 08:10:55.844253 2026] [security2:error] [pid 402041:tid 402136] [remote 20.153.140.50:37354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/wp-login.php"] [unique_id "al9Tv4iENNLP6XjiHQs4ZQABk1w"]
[Tue Jul 21 08:10:56.026580 2026] [security2:error] [pid 402041:tid 402188] [client 104.28.251.192:40218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.fisiopelvicafloripa.com.br"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al9TwIiENNLP6XjiHQs4aAAAAZ4"]
[Tue Jul 21 08:10:56.090015 2026] [security2:error] [pid 402041:tid 402269] [client 20.104.96.117:54081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/ho.php"] [unique_id "al9TwIiENNLP6XjiHQs4agAAAe8"]
[Tue Jul 21 08:10:56.279077 2026] [security2:error] [pid 402041:tid 402234] [client 20.226.60.151:48776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/k.php"] [unique_id "al9TwIiENNLP6XjiHQs4cAAAAcw"]
[Tue Jul 21 08:10:56.298378 2026] [security2:error] [pid 402041:tid 402238] [client 20.206.105.145:56609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/footer.php"] [unique_id "al9TwIiENNLP6XjiHQs4cQAAAdA"]
[Tue Jul 21 08:10:56.322463 2026] [security2:error] [pid 402041:tid 402201] [client 102.206.115.33:61562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TwIiENNLP6XjiHQs4cgAAAas"]
[Tue Jul 21 08:10:56.322580 2026] [security2:error] [pid 402041:tid 402201] [client 102.206.115.33:61562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TwIiENNLP6XjiHQs4cgAAAas"]
[Tue Jul 21 08:10:56.525988 2026] [security2:error] [pid 402041:tid 402291] [client 20.151.10.161:55845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/w2025.php"] [unique_id "al9TwIiENNLP6XjiHQs4fAAAAgU"]
[Tue Jul 21 08:10:56.722685 2026] [security2:error] [pid 402041:tid 402298] [client 103.151.46.103:49278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TvoiENNLP6XjiHQs4KAAAAgw"]
[Tue Jul 21 08:10:56.722859 2026] [security2:error] [pid 402041:tid 402298] [client 103.151.46.103:49278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TvoiENNLP6XjiHQs4KAAAAgw"]
[Tue Jul 21 08:10:56.811929 2026] [security2:error] [pid 402041:tid 402174] [client 20.151.10.161:13246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/users.php"] [unique_id "al9TwIiENNLP6XjiHQs4fwAAAZA"]
[Tue Jul 21 08:10:56.868019 2026] [security2:error] [pid 402041:tid 402186] [client 20.151.10.161:55830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/scxy.php"] [unique_id "al9TwIiENNLP6XjiHQs4hAAAAZw"]
[Tue Jul 21 08:10:56.965244 2026] [security2:error] [pid 402041:tid 402179] [client 20.206.105.145:29694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/users.php"] [unique_id "al9TwIiENNLP6XjiHQs4jgAAAZU"]
[Tue Jul 21 08:10:57.101724 2026] [security2:error] [pid 402041:tid 402252] [client 20.104.96.117:63452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/adjig.php"] [unique_id "al9TwYiENNLP6XjiHQs4kAAAAd4"]
[Tue Jul 21 08:10:57.160959 2026] [security2:error] [pid 402041:tid 402253] [client 20.206.105.145:56695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/177.php"] [unique_id "al9TwYiENNLP6XjiHQs4kQAAAd8"]
[Tue Jul 21 08:10:57.172583 2026] [security2:error] [pid 402041:tid 402255] [client 20.226.60.151:48847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/blurbs.php"] [unique_id "al9TwYiENNLP6XjiHQs4kgAAAeE"]
[Tue Jul 21 08:10:57.303273 2026] [security2:error] [pid 402041:tid 402150] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TwYiENNLP6XjiHQs4lAABymo"]
[Tue Jul 21 08:10:57.303488 2026] [security2:error] [pid 402041:tid 402232] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9TwYiENNLP6XjiHQs4lAABymo"]
[Tue Jul 21 08:10:57.357320 2026] [security2:error] [pid 402041:tid 402222] [client 65.21.113.253:40732] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TwIiENNLP6XjiHQs4iQAAAcA"]
[Tue Jul 21 08:10:57.592106 2026] [security2:error] [pid 402041:tid 402175] [client 20.151.10.161:50976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/FWAZ.php"] [unique_id "al9TwYiENNLP6XjiHQs4oQAAAZE"]
[Tue Jul 21 08:10:57.593593 2026] [security2:error] [pid 402041:tid 402221] [client 120.56.162.40:51296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TwYiENNLP6XjiHQs4ogAAAb8"]
[Tue Jul 21 08:10:57.593718 2026] [security2:error] [pid 402041:tid 402221] [client 120.56.162.40:51296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TwYiENNLP6XjiHQs4ogAAAb8"]
[Tue Jul 21 08:10:57.648243 2026] [security2:error] [pid 402041:tid 402264] [client 20.197.192.193:64278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/else1.php"] [unique_id "al9TwYiENNLP6XjiHQs4pAAAAeo"]
[Tue Jul 21 08:10:57.655480 2026] [security2:error] [pid 402041:tid 402224] [client 20.206.105.145:56621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/config.php"] [unique_id "al9TwYiENNLP6XjiHQs4pQAAAcI"]
[Tue Jul 21 08:10:57.817670 2026] [security2:error] [pid 402041:tid 402204] [client 20.104.96.117:58391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/0xD.php"] [unique_id "al9TwYiENNLP6XjiHQs4qgAAAa4"]
[Tue Jul 21 08:10:58.118850 2026] [security2:error] [pid 402041:tid 402216] [client 20.151.10.161:55870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/qterm.php"] [unique_id "al9TwoiENNLP6XjiHQs4tAAAAbo"]
[Tue Jul 21 08:10:58.226313 2026] [security2:error] [pid 402041:tid 402236] [client 150.129.202.39:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TwoiENNLP6XjiHQs4uQAAAc4"]
[Tue Jul 21 08:10:58.226449 2026] [security2:error] [pid 402041:tid 402236] [client 150.129.202.39:65190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TwoiENNLP6XjiHQs4uQAAAc4"]
[Tue Jul 21 08:10:58.319833 2026] [security2:error] [pid 402041:tid 402169] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TwoiENNLP6XjiHQs4uwABoX0"]
[Tue Jul 21 08:10:58.319968 2026] [security2:error] [pid 402041:tid 402191] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TwoiENNLP6XjiHQs4uwABoX0"]
[Tue Jul 21 08:10:58.465861 2026] [security2:error] [pid 402041:tid 402192] [client 20.206.105.145:29672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/gettest.php"] [unique_id "al9TwoiENNLP6XjiHQs4wAAAAaI"]
[Tue Jul 21 08:10:58.517301 2026] [security2:error] [pid 402041:tid 402212] [client 20.151.10.161:13236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/177.php"] [unique_id "al9TwoiENNLP6XjiHQs4yAAAAbY"]
[Tue Jul 21 08:10:58.587993 2026] [security2:error] [pid 402041:tid 402232] [client 20.226.60.151:48857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/bajah.php"] [unique_id "al9TwoiENNLP6XjiHQs4yQAAAco"]
[Tue Jul 21 08:10:58.732684 2026] [security2:error] [pid 402041:tid 402046] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TwoiENNLP6XjiHQs4zAABxgI"]
[Tue Jul 21 08:10:58.732804 2026] [security2:error] [pid 402041:tid 402228] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TwoiENNLP6XjiHQs4zAABxgI"]
[Tue Jul 21 08:10:58.762982 2026] [security2:error] [pid 402041:tid 402209] [client 20.206.105.145:56611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/min.php"] [unique_id "al9TwoiENNLP6XjiHQs4zQAAAbM"]
[Tue Jul 21 08:10:58.976049 2026] [security2:error] [pid 402041:tid 402224] [client 20.151.10.161:51049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/blurbs.php"] [unique_id "al9TwoiENNLP6XjiHQs40wAAAcI"]
[Tue Jul 21 08:10:58.997021 2026] [security2:error] [pid 402041:tid 402271] [client 20.206.105.145:56652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/edorxrr.php"] [unique_id "al9TwoiENNLP6XjiHQs41wAAAfE"]
[Tue Jul 21 08:10:59.034043 2026] [security2:error] [pid 402041:tid 402245] [client 152.42.164.200:34106] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "162.241.63.72"] [uri "/"] [unique_id "al9Tw4iENNLP6XjiHQs42AAAAdc"]
[Tue Jul 21 08:10:59.270124 2026] [security2:error] [pid 402041:tid 402238] [client 20.206.105.145:56582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/hur.php"] [unique_id "al9Tw4iENNLP6XjiHQs43gAAAdA"]
[Tue Jul 21 08:10:59.331898 2026] [security2:error] [pid 402041:tid 402211] [client 20.226.60.151:48870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/a.php"] [unique_id "al9Tw4iENNLP6XjiHQs44QAAAbU"]
[Tue Jul 21 08:10:59.371282 2026] [security2:error] [pid 402041:tid 402219] [client 152.42.164.200:55574] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "162.241.63.72"] [uri "/"] [unique_id "al9Tw4iENNLP6XjiHQs44wAAAb0"]
[Tue Jul 21 08:10:59.443716 2026] [security2:error] [pid 402041:tid 402290] [client 162.219.176.3:56098] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Tw4iENNLP6XjiHQs46AAAAgQ"]
[Tue Jul 21 08:10:59.443830 2026] [security2:error] [pid 402041:tid 402290] [client 162.219.176.3:56098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Tw4iENNLP6XjiHQs46AAAAgQ"]
[Tue Jul 21 08:10:59.495062 2026] [security2:error] [pid 402041:tid 402266] [client 109.60.28.94:20549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tw4iENNLP6XjiHQs46gAAAew"]
[Tue Jul 21 08:10:59.495224 2026] [security2:error] [pid 402041:tid 402266] [client 109.60.28.94:20549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tw4iENNLP6XjiHQs46gAAAew"]
[Tue Jul 21 08:10:59.503726 2026] [security2:error] [pid 402041:tid 402250] [client 20.151.10.161:51055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/v543.php"] [unique_id "al9Tw4iENNLP6XjiHQs46wAAAdw"]
[Tue Jul 21 08:10:59.538322 2026] [security2:error] [pid 402041:tid 402294] [client 187.125.243.197:53105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Tw4iENNLP6XjiHQs45AAAAgg"]
[Tue Jul 21 08:10:59.538465 2026] [security2:error] [pid 402041:tid 402294] [client 187.125.243.197:53105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Tw4iENNLP6XjiHQs45AAAAgg"]
[Tue Jul 21 08:10:59.542492 2026] [security2:error] [pid 402041:tid 402054] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Tw4iENNLP6XjiHQs48AACBgo"]
[Tue Jul 21 08:10:59.542704 2026] [security2:error] [pid 402041:tid 402292] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Tw4iENNLP6XjiHQs48AACBgo"]
[Tue Jul 21 08:10:59.648974 2026] [security2:error] [pid 402041:tid 402251] [client 20.206.105.145:29649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/zoro.php"] [unique_id "al9Tw4iENNLP6XjiHQs48gAAAd0"]
[Tue Jul 21 08:10:59.754369 2026] [security2:error] [pid 402041:tid 402183] [client 65.21.113.253:58422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9Tw4iENNLP6XjiHQs48wAAAZk"]
[Tue Jul 21 08:10:59.778761 2026] [security2:error] [pid 402041:tid 402212] [client 20.226.60.151:48792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/edit.php"] [unique_id "al9Tw4iENNLP6XjiHQs49AAAAbY"]
[Tue Jul 21 08:10:59.857972 2026] [security2:error] [pid 402041:tid 402227] [client 20.197.192.193:61835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/tkikikoko.php"] [unique_id "al9Tw4iENNLP6XjiHQs49wAAAcU"]
[Tue Jul 21 08:11:00.050417 2026] [security2:error] [pid 402041:tid 402187] [client 20.226.60.151:48810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/hosty.php"] [unique_id "al9TxIiENNLP6XjiHQs5AQAAAZ0"]
[Tue Jul 21 08:11:00.342039 2026] [security2:error] [pid 402041:tid 402275] [client 20.151.10.161:13158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/config.php"] [unique_id "al9TxIiENNLP6XjiHQs5EAAAAfU"]
[Tue Jul 21 08:11:00.367296 2026] [security2:error] [pid 402041:tid 402188] [client 65.21.113.253:40732] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Tw4iENNLP6XjiHQs4_gAAAZ4"]
[Tue Jul 21 08:11:00.367325 2026] [security2:error] [pid 402041:tid 402279] [client 20.104.96.117:54116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/xy.php"] [unique_id "al9TxIiENNLP6XjiHQs5EQAAAfk"]
[Tue Jul 21 08:11:00.437226 2026] [security2:error] [pid 402041:tid 402261] [client 20.226.60.151:48790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/k.php"] [unique_id "al9TxIiENNLP6XjiHQs5EgAAAec"]
[Tue Jul 21 08:11:00.542827 2026] [security2:error] [pid 402041:tid 402194] [client 20.226.60.151:48834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/aaa.php"] [unique_id "al9TxIiENNLP6XjiHQs5FwAAAaQ"]
[Tue Jul 21 08:11:00.716683 2026] [security2:error] [pid 402041:tid 402212] [client 20.104.96.117:58379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/fnstall.php"] [unique_id "al9TxIiENNLP6XjiHQs5HgAAAbY"]
[Tue Jul 21 08:11:00.753232 2026] [security2:error] [pid 402041:tid 402274] [client 20.226.60.151:48794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/file5.php"] [unique_id "al9TxIiENNLP6XjiHQs5HwAAAfQ"]
[Tue Jul 21 08:11:00.967979 2026] [security2:error] [pid 402041:tid 402197] [client 20.104.96.117:56838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/byp.php"] [unique_id "al9TxIiENNLP6XjiHQs5JgAAAac"]
[Tue Jul 21 08:11:01.101613 2026] [security2:error] [pid 402041:tid 402263] [client 20.151.10.161:55822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/w3lls.php"] [unique_id "al9TxYiENNLP6XjiHQs5LAAAAek"]
[Tue Jul 21 08:11:01.107038 2026] [security2:error] [pid 402041:tid 402285] [client 103.78.200.11:61029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TxYiENNLP6XjiHQs5LQAAAf8"]
[Tue Jul 21 08:11:01.107143 2026] [security2:error] [pid 402041:tid 402285] [client 103.78.200.11:61029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TxYiENNLP6XjiHQs5LQAAAf8"]
[Tue Jul 21 08:11:01.114167 2026] [security2:error] [pid 402041:tid 402256] [client 20.206.105.145:29637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/coffexium.php"] [unique_id "al9TxYiENNLP6XjiHQs5LgAAAeI"]
[Tue Jul 21 08:11:01.177978 2026] [security2:error] [pid 402041:tid 402255] [client 20.226.60.151:48837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/222.php"] [unique_id "al9TxYiENNLP6XjiHQs5MwAAAeE"]
[Tue Jul 21 08:11:01.194214 2026] [security2:error] [pid 402041:tid 402185] [client 20.151.10.161:13058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/gettest.php"] [unique_id "al9TxYiENNLP6XjiHQs5NAAAAZs"]
[Tue Jul 21 08:11:01.384729 2026] [security2:error] [pid 402041:tid 402281] [client 117.210.135.0:55205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TxYiENNLP6XjiHQs5NQAAAfs"]
[Tue Jul 21 08:11:01.384875 2026] [security2:error] [pid 402041:tid 402281] [client 117.210.135.0:55205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TxYiENNLP6XjiHQs5NQAAAfs"]
[Tue Jul 21 08:11:01.512958 2026] [security2:error] [pid 402041:tid 402264] [client 34.182.139.74:51930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.139.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oriorixas.blog.br"] [uri "/xmlrpc.php"] [unique_id "al9TxYiENNLP6XjiHQs5NwAAAeo"]
[Tue Jul 21 08:11:01.513099 2026] [security2:error] [pid 402041:tid 402264] [client 34.182.139.74:51930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oriorixas.blog.br"] [uri "/xmlrpc.php"] [unique_id "al9TxYiENNLP6XjiHQs5NwAAAeo"]
[Tue Jul 21 08:11:01.684136 2026] [security2:error] [pid 402041:tid 402216] [client 20.151.10.161:51060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-ws68.php"] [unique_id "al9TxYiENNLP6XjiHQs5QgAAAbo"]
[Tue Jul 21 08:11:01.686521 2026] [access_compat:error] [pid 402041:tid 402193] [client 162.241.63.68:11718] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:11:01.844070 2026] [security2:error] [pid 402041:tid 402267] [client 65.21.113.253:44198] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TxYiENNLP6XjiHQs5NgAAAe0"]
[Tue Jul 21 08:11:02.242210 2026] [security2:error] [pid 402041:tid 402251] [client 20.226.60.151:48817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/test.php"] [unique_id "al9TxoiENNLP6XjiHQs5TwAAAd0"]
[Tue Jul 21 08:11:02.246657 2026] [security2:error] [pid 402041:tid 402203] [client 65.21.113.253:58422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TxoiENNLP6XjiHQs5UAAAAa0"]
[Tue Jul 21 08:11:02.311576 2026] [security2:error] [pid 402041:tid 402288] [client 20.151.10.161:55839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/xyn.php"] [unique_id "al9TxoiENNLP6XjiHQs5UQAAAgI"]
[Tue Jul 21 08:11:02.354520 2026] [security2:error] [pid 402041:tid 402284] [client 87.116.180.198:27312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TxoiENNLP6XjiHQs5UgAAAf4"]
[Tue Jul 21 08:11:02.358376 2026] [security2:error] [pid 402041:tid 402284] [client 87.116.180.198:27312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TxoiENNLP6XjiHQs5UgAAAf4"]
[Tue Jul 21 08:11:02.373936 2026] [security2:error] [pid 402041:tid 402218] [client 62.60.130.128:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "rlvgestaoempresarial.ricardoleandrovieira1748610715002.0711679.meusitehostgator.com.br"] [uri "/"] [unique_id "al9TxoiENNLP6XjiHQs5VAAAAbw"]
[Tue Jul 21 08:11:02.421649 2026] [security2:error] [pid 402041:tid 402183] [client 20.206.105.145:29668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/app.php"] [unique_id "al9TxoiENNLP6XjiHQs5VgAAAZk"]
[Tue Jul 21 08:11:02.571749 2026] [security2:error] [pid 402041:tid 402269] [client 20.151.10.161:13270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/min.php"] [unique_id "al9TxoiENNLP6XjiHQs5WwAAAe8"]
[Tue Jul 21 08:11:02.631511 2026] [security2:error] [pid 402041:tid 402231] [client 62.60.130.128:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "rlvgestaoempresarial.ricardoleandrovieira1748610715002.0711679.meusitehostgator.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9TxoiENNLP6XjiHQs5XQAAAck"]
[Tue Jul 21 08:11:02.857705 2026] [security2:error] [pid 402041:tid 402181] [client 20.226.60.151:48801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/aaa.php"] [unique_id "al9TxoiENNLP6XjiHQs5ZgAAAZc"]
[Tue Jul 21 08:11:02.863869 2026] [security2:error] [pid 402041:tid 402254] [client 20.151.10.161:50962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/green3.php"] [unique_id "al9TxoiENNLP6XjiHQs5ZwAAAeA"]
[Tue Jul 21 08:11:03.280837 2026] [security2:error] [pid 402041:tid 402240] [client 20.226.60.151:48835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/11.php"] [unique_id "al9Tx4iENNLP6XjiHQs5egAAAdI"]
[Tue Jul 21 08:11:03.298154 2026] [security2:error] [pid 402041:tid 402209] [client 65.21.113.253:44204] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TxoiENNLP6XjiHQs5aQAAAbM"]
[Tue Jul 21 08:11:03.356237 2026] [security2:error] [pid 402041:tid 402193] [client 20.151.10.161:13062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/edorxrr.php"] [unique_id "al9Tx4iENNLP6XjiHQs5ewAAAaM"]
[Tue Jul 21 08:11:03.451266 2026] [security2:error] [pid 402041:tid 402195] [client 20.151.10.161:55813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ccs.php"] [unique_id "al9Tx4iENNLP6XjiHQs5fgAAAaU"]
[Tue Jul 21 08:11:03.560704 2026] [security2:error] [pid 402041:tid 402255] [client 38.100.221.102:19036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tx4iENNLP6XjiHQs5fwAAAeE"]
[Tue Jul 21 08:11:03.560864 2026] [security2:error] [pid 402041:tid 402255] [client 38.100.221.102:19036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tx4iENNLP6XjiHQs5fwAAAeE"]
[Tue Jul 21 08:11:03.684090 2026] [security2:error] [pid 402041:tid 402266] [client 20.206.105.145:29657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/core.php"] [unique_id "al9Tx4iENNLP6XjiHQs5hQAAAew"]
[Tue Jul 21 08:11:03.732490 2026] [security2:error] [pid 402041:tid 402185] [client 154.208.47.43:40389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Tx4iENNLP6XjiHQs5iAAAAZs"]
[Tue Jul 21 08:11:03.732651 2026] [security2:error] [pid 402041:tid 402185] [client 154.208.47.43:40389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Tx4iENNLP6XjiHQs5iAAAAZs"]
[Tue Jul 21 08:11:03.749674 2026] [security2:error] [pid 402041:tid 402117] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tx4iENNLP6XjiHQs5jQABwUk"]
[Tue Jul 21 08:11:03.749828 2026] [security2:error] [pid 402041:tid 402223] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tx4iENNLP6XjiHQs5jQABwUk"]
[Tue Jul 21 08:11:03.932136 2026] [security2:error] [pid 402041:tid 402283] [client 20.151.10.161:51045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ccc.php"] [unique_id "al9Tx4iENNLP6XjiHQs5kwAAAf0"]
[Tue Jul 21 08:11:04.001332 2026] [security2:error] [pid 402041:tid 402232] [client 20.104.96.117:62527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9TyIiENNLP6XjiHQs5lQAAAco"]
[Tue Jul 21 08:11:04.016183 2026] [security2:error] [pid 402041:tid 402092] [remote 78.175.239.171:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.239.175.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "infoalert.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TxYiENNLP6XjiHQs5RQACDjA"]
[Tue Jul 21 08:11:04.016392 2026] [security2:error] [pid 402041:tid 402300] [client 78.175.239.171:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "infoalert.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TxYiENNLP6XjiHQs5RQACDjA"]
[Tue Jul 21 08:11:04.311650 2026] [security2:error] [pid 402041:tid 402228] [client 20.206.105.145:56584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/main.php"] [unique_id "al9TyIiENNLP6XjiHQs5oAAAAcY"]
[Tue Jul 21 08:11:04.407257 2026] [security2:error] [pid 402041:tid 402215] [client 20.104.96.117:58377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/acp.php"] [unique_id "al9TyIiENNLP6XjiHQs5pAAAAbk"]
[Tue Jul 21 08:11:04.417680 2026] [security2:error] [pid 402041:tid 402179] [client 103.151.46.103:49849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TyIiENNLP6XjiHQs5pQAAAZU"]
[Tue Jul 21 08:11:04.420380 2026] [security2:error] [pid 402041:tid 402179] [client 103.151.46.103:49849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TyIiENNLP6XjiHQs5pQAAAZU"]
[Tue Jul 21 08:11:04.422044 2026] [security2:error] [pid 402041:tid 402236] [client 20.151.10.161:55829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/get.php"] [unique_id "al9TyIiENNLP6XjiHQs5pgAAAc4"]
[Tue Jul 21 08:11:04.748901 2026] [security2:error] [pid 402041:tid 402295] [client 20.151.10.161:13169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/hur.php"] [unique_id "al9TyIiENNLP6XjiHQs5sAAAAgk"]
[Tue Jul 21 08:11:04.808261 2026] [security2:error] [pid 402041:tid 402291] [client 20.151.10.161:51039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/images.php"] [unique_id "al9TyIiENNLP6XjiHQs5swAAAgU"]
[Tue Jul 21 08:11:04.894422 2026] [security2:error] [pid 402041:tid 402206] [client 65.21.113.253:58422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TyIiENNLP6XjiHQs5twAAAbA"]
[Tue Jul 21 08:11:04.946066 2026] [security2:error] [pid 402041:tid 402290] [client 20.206.105.145:29665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/init.php"] [unique_id "al9TyIiENNLP6XjiHQs5uQAAAgQ"]
[Tue Jul 21 08:11:05.205589 2026] [security2:error] [pid 402041:tid 402233] [client 20.206.105.145:56617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/prekel.php"] [unique_id "al9TyYiENNLP6XjiHQs5vAAAAcs"]
[Tue Jul 21 08:11:05.244892 2026] [security2:error] [pid 402041:tid 402139] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TyYiENNLP6XjiHQs5wAAB6F8"]
[Tue Jul 21 08:11:05.245099 2026] [security2:error] [pid 402041:tid 402262] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TyYiENNLP6XjiHQs5wAAB6F8"]
[Tue Jul 21 08:11:05.250522 2026] [security2:error] [pid 402041:tid 402194] [client 20.226.60.151:49344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/mac.php"] [unique_id "al9TyYiENNLP6XjiHQs5wQAAAaQ"]
[Tue Jul 21 08:11:05.344369 2026] [security2:error] [pid 402041:tid 402186] [client 20.151.10.161:55909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/alls.php"] [unique_id "al9TyYiENNLP6XjiHQs5xwAAAZw"]
[Tue Jul 21 08:11:05.412125 2026] [security2:error] [pid 402041:tid 402289] [client 20.206.105.145:29641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/0.php"] [unique_id "al9TyYiENNLP6XjiHQs5zAAAAgM"]
[Tue Jul 21 08:11:05.504468 2026] [security2:error] [pid 402041:tid 402195] [client 65.21.113.253:44198] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TyYiENNLP6XjiHQs5ugAAAaU"]
[Tue Jul 21 08:11:05.605718 2026] [security2:error] [pid 402041:tid 402190] [client 20.206.105.145:56592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/BDKR28.php"] [unique_id "al9TyYiENNLP6XjiHQs5zgAAAaA"]
[Tue Jul 21 08:11:05.806336 2026] [security2:error] [pid 402041:tid 402217] [client 20.151.10.161:51014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/yyu.php"] [unique_id "al9TyYiENNLP6XjiHQs52AAAAbs"]
[Tue Jul 21 08:11:05.850340 2026] [security2:error] [pid 402041:tid 402187] [client 20.151.10.161:13216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/zoro.php"] [unique_id "al9TyYiENNLP6XjiHQs52QAAAZ0"]
[Tue Jul 21 08:11:05.949138 2026] [security2:error] [pid 402041:tid 402263] [client 20.197.192.193:61859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9TyYiENNLP6XjiHQs53QAAAek"]
[Tue Jul 21 08:11:05.953689 2026] [security2:error] [pid 402041:tid 402247] [client 20.206.105.145:56616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/f35.update.php"] [unique_id "al9TyYiENNLP6XjiHQs53gAAAdk"]
[Tue Jul 21 08:11:06.183941 2026] [security2:error] [pid 402041:tid 402246] [client 20.206.105.145:56690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/f900.php"] [unique_id "al9TyoiENNLP6XjiHQs54wAAAdg"]
[Tue Jul 21 08:11:06.348494 2026] [security2:error] [pid 402041:tid 402225] [client 20.104.96.117:54097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/loader.php"] [unique_id "al9TyoiENNLP6XjiHQs57AAAAcM"]
[Tue Jul 21 08:11:06.376146 2026] [security2:error] [pid 402041:tid 402207] [client 20.206.105.145:56629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/xmrl.php"] [unique_id "al9TyoiENNLP6XjiHQs57QAAAbE"]
[Tue Jul 21 08:11:06.435417 2026] [security2:error] [pid 402041:tid 402290] [client 162.219.176.3:41574] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9TyoiENNLP6XjiHQs58QAAAgQ"]
[Tue Jul 21 08:11:06.435506 2026] [security2:error] [pid 402041:tid 402290] [client 162.219.176.3:41574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9TyoiENNLP6XjiHQs58QAAAgQ"]
[Tue Jul 21 08:11:06.457549 2026] [security2:error] [pid 402041:tid 402240] [client 20.151.10.161:13143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/coffexium.php"] [unique_id "al9TyoiENNLP6XjiHQs58wAAAdI"]
[Tue Jul 21 08:11:06.578552 2026] [security2:error] [pid 402041:tid 402272] [client 20.226.60.151:49395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/chosen.php"] [unique_id "al9TyoiENNLP6XjiHQs59gAAAfI"]
[Tue Jul 21 08:11:06.749650 2026] [security2:error] [pid 402041:tid 402214] [client 20.206.105.145:29681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/memberfuns.php"] [unique_id "al9TyoiENNLP6XjiHQs5-gAAAbg"]
[Tue Jul 21 08:11:06.753496 2026] [security2:error] [pid 402041:tid 402227] [client 137.97.59.154:62582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9TyoiENNLP6XjiHQs59wAAAcU"]
[Tue Jul 21 08:11:06.753712 2026] [security2:error] [pid 402041:tid 402227] [client 137.97.59.154:62582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9TyoiENNLP6XjiHQs59wAAAcU"]
[Tue Jul 21 08:11:06.852327 2026] [security2:error] [pid 402041:tid 402168] [remote 124.55.178.99:42586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9TyoiENNLP6XjiHQs5_wACBnw"]
[Tue Jul 21 08:11:06.871071 2026] [security2:error] [pid 402041:tid 402275] [client 102.206.115.33:62936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TyoiENNLP6XjiHQs6AgAAAfU"]
[Tue Jul 21 08:11:06.871185 2026] [security2:error] [pid 402041:tid 402275] [client 102.206.115.33:62936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9TyoiENNLP6XjiHQs6AgAAAfU"]
[Tue Jul 21 08:11:06.912468 2026] [security2:error] [pid 402041:tid 402195] [client 65.21.113.253:58422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TyoiENNLP6XjiHQs6AwAAAaU"]
[Tue Jul 21 08:11:06.963242 2026] [security2:error] [pid 402041:tid 402220] [client 20.104.96.117:62590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/classwithtostring.php"] [unique_id "al9TyoiENNLP6XjiHQs6CAAAAb4"]
[Tue Jul 21 08:11:07.007480 2026] [security2:error] [pid 402041:tid 402300] [client 20.151.10.161:50954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/by.php"] [unique_id "al9Ty4iENNLP6XjiHQs6DQAAAg4"]
[Tue Jul 21 08:11:07.271064 2026] [security2:error] [pid 402041:tid 402200] [client 65.21.113.253:44208] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9TyoiENNLP6XjiHQs6AAAAAao"]
[Tue Jul 21 08:11:07.453662 2026] [security2:error] [pid 402041:tid 402179] [client 20.206.105.145:56622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/ms.php"] [unique_id "al9Ty4iENNLP6XjiHQs6GAAAAZU"]
[Tue Jul 21 08:11:07.723307 2026] [rewrite:warn] [pid 402041:tid 402055] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:11:07.786756 2026] [security2:error] [pid 402041:tid 402056] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Ty4iENNLP6XjiHQs6IgAB1ww"]
[Tue Jul 21 08:11:07.787020 2026] [security2:error] [pid 402041:tid 402245] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Ty4iENNLP6XjiHQs6IgAB1ww"]
[Tue Jul 21 08:11:07.980131 2026] [security2:error] [pid 402041:tid 402214] [client 20.104.96.117:63427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/root.php"] [unique_id "al9Ty4iENNLP6XjiHQs6KAAAAbg"]
[Tue Jul 21 08:11:07.985384 2026] [security2:error] [pid 402041:tid 402247] [client 65.21.113.253:44212] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Ty4iENNLP6XjiHQs6HgAAAdk"]
[Tue Jul 21 08:11:07.991917 2026] [security2:error] [pid 402041:tid 402238] [client 20.206.105.145:56581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/zz.php"] [unique_id "al9Ty4iENNLP6XjiHQs6KQAAAdA"]
[Tue Jul 21 08:11:08.153275 2026] [security2:error] [pid 402041:tid 402203] [client 20.206.105.145:29686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/for.php"] [unique_id "al9TzIiENNLP6XjiHQs6MgAAAa0"]
[Tue Jul 21 08:11:08.243945 2026] [security2:error] [pid 402041:tid 402232] [client 20.151.10.161:51050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/FAQ.php"] [unique_id "al9TzIiENNLP6XjiHQs6NAAAAco"]
[Tue Jul 21 08:11:08.273997 2026] [security2:error] [pid 402041:tid 402182] [client 20.151.10.161:13156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/app.php"] [unique_id "al9TzIiENNLP6XjiHQs6NQAAAZg"]
[Tue Jul 21 08:11:08.301210 2026] [security2:error] [pid 402041:tid 402215] [client 120.56.162.40:51791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TzIiENNLP6XjiHQs6NwAAAbk"]
[Tue Jul 21 08:11:08.301389 2026] [security2:error] [pid 402041:tid 402215] [client 120.56.162.40:51791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TzIiENNLP6XjiHQs6NwAAAbk"]
[Tue Jul 21 08:11:08.310484 2026] [security2:error] [pid 402041:tid 402196] [client 20.206.105.145:29608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/yup.php"] [unique_id "al9TzIiENNLP6XjiHQs6OAAAAaY"]
[Tue Jul 21 08:11:08.429324 2026] [security2:error] [pid 402041:tid 402183] [client 20.226.60.151:48812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/cream1.php"] [unique_id "al9TzIiENNLP6XjiHQs6PQAAAZk"]
[Tue Jul 21 08:11:08.747648 2026] [security2:error] [pid 402041:tid 402270] [client 20.151.10.161:51023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/coffexium.php"] [unique_id "al9TzIiENNLP6XjiHQs6QgAAAfA"]
[Tue Jul 21 08:11:08.782445 2026] [security2:error] [pid 402041:tid 402223] [client 150.129.202.39:65016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TzIiENNLP6XjiHQs6QwAAAcE"]
[Tue Jul 21 08:11:08.782563 2026] [security2:error] [pid 402041:tid 402223] [client 150.129.202.39:65016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TzIiENNLP6XjiHQs6QwAAAcE"]
[Tue Jul 21 08:11:08.826118 2026] [security2:error] [pid 402041:tid 402253] [client 20.206.105.145:56626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/wpxml.php"] [unique_id "al9TzIiENNLP6XjiHQs6RQAAAd8"]
[Tue Jul 21 08:11:08.923752 2026] [security2:error] [pid 402041:tid 402070] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TzIiENNLP6XjiHQs6SQAB8Ro"]
[Tue Jul 21 08:11:08.923903 2026] [security2:error] [pid 402041:tid 402271] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9TzIiENNLP6XjiHQs6SQAB8Ro"]
[Tue Jul 21 08:11:09.133642 2026] [security2:error] [pid 402041:tid 402240] [client 61.1.167.83:62946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TzYiENNLP6XjiHQs6TgAAAdI"]
[Tue Jul 21 08:11:09.133839 2026] [security2:error] [pid 402041:tid 402240] [client 61.1.167.83:62946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TzYiENNLP6XjiHQs6TgAAAdI"]
[Tue Jul 21 08:11:09.207658 2026] [security2:error] [pid 402041:tid 402279] [client 20.206.105.145:56673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/fffm.php"] [unique_id "al9TzYiENNLP6XjiHQs6TwAAAfk"]
[Tue Jul 21 08:11:09.333757 2026] [security2:error] [pid 402041:tid 402173] [client 20.151.10.161:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/red.php"] [unique_id "al9TzYiENNLP6XjiHQs6UwAAAY8"]
[Tue Jul 21 08:11:09.349088 2026] [security2:error] [pid 402041:tid 402206] [client 20.206.105.145:29629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/gecko.php"] [unique_id "al9TzYiENNLP6XjiHQs6VAAAAbA"]
[Tue Jul 21 08:11:09.498568 2026] [security2:error] [pid 402041:tid 402289] [client 20.104.96.117:58422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/mosty.php"] [unique_id "al9TzYiENNLP6XjiHQs6XAAAAgM"]
[Tue Jul 21 08:11:09.522294 2026] [security2:error] [pid 402041:tid 402292] [client 20.206.105.145:56580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/a1.php"] [unique_id "al9TzYiENNLP6XjiHQs6XQAAAgY"]
[Tue Jul 21 08:11:09.596845 2026] [security2:error] [pid 402041:tid 402281] [client 187.125.243.197:53625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TzYiENNLP6XjiHQs6YgAAAfs"]
[Tue Jul 21 08:11:09.597202 2026] [security2:error] [pid 402041:tid 402281] [client 187.125.243.197:53625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9TzYiENNLP6XjiHQs6YgAAAfs"]
[Tue Jul 21 08:11:09.654894 2026] [security2:error] [pid 402041:tid 402232] [client 20.151.10.161:13296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/core.php"] [unique_id "al9TzYiENNLP6XjiHQs6YwAAAco"]
[Tue Jul 21 08:11:09.677387 2026] [security2:error] [pid 402041:tid 402283] [client 20.206.105.145:29570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/k2.php"] [unique_id "al9TzYiENNLP6XjiHQs6ZAAAAf0"]
[Tue Jul 21 08:11:09.898909 2026] [security2:error] [pid 402041:tid 402083] [remote 185.236.20.134:7894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadanaturalis.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9TzYiENNLP6XjiHQs6ZgACDic"]
[Tue Jul 21 08:11:10.032734 2026] [security2:error] [pid 402041:tid 402057] [remote 45.76.153.27:38904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.153.76.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-login.php"] [unique_id "al9TzoiENNLP6XjiHQs6bAABoQ0"]
[Tue Jul 21 08:11:10.035362 2026] [security2:error] [pid 402041:tid 402231] [client 20.206.105.145:56682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/82.php"] [unique_id "al9TzoiENNLP6XjiHQs6bQAAAck"]
[Tue Jul 21 08:11:10.164207 2026] [security2:error] [pid 402041:tid 402052] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TzoiENNLP6XjiHQs6dAABqgg"]
[Tue Jul 21 08:11:10.164415 2026] [security2:error] [pid 402041:tid 402200] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9TzoiENNLP6XjiHQs6dAABqgg"]
[Tue Jul 21 08:11:10.367565 2026] [security2:error] [pid 402041:tid 402177] [client 109.60.28.94:21007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TzoiENNLP6XjiHQs6fgAAAZM"]
[Tue Jul 21 08:11:10.367677 2026] [security2:error] [pid 402041:tid 402177] [client 109.60.28.94:21007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9TzoiENNLP6XjiHQs6fgAAAZM"]
[Tue Jul 21 08:11:10.380409 2026] [security2:error] [pid 402041:tid 402297] [client 20.206.105.145:56659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/config.json.php"] [unique_id "al9TzoiENNLP6XjiHQs6fwAAAgs"]
[Tue Jul 21 08:11:10.418493 2026] [autoindex:error] [pid 402041:tid 402253] [client 20.226.60.151:48817] AH01276: Cannot serve directory /home4/moadvo53/moadvogadas.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:11:10.456672 2026] [autoindex:error] [pid 402041:tid 402271] [client 20.226.60.151:48817] AH01276: Cannot serve directory /home4/moadvo53/moadvogadas.com.br/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:11:10.462657 2026] [security2:error] [pid 402041:tid 402291] [client 20.226.60.151:48791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/dr.php"] [unique_id "al9TzoiENNLP6XjiHQs6hgAAAgU"]
[Tue Jul 21 08:11:10.502574 2026] [security2:error] [pid 402041:tid 402201] [client 185.236.20.134:23028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadanaturalis.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9TzoiENNLP6XjiHQs6hwAAAas"]
[Tue Jul 21 08:11:10.528509 2026] [security2:error] [pid 402041:tid 402184] [client 20.151.10.161:55854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9TzoiENNLP6XjiHQs6iAAAAZo"]
[Tue Jul 21 08:11:10.708592 2026] [security2:error] [pid 402041:tid 402207] [client 74.7.230.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ednadaconceicaoribei1743627840845.0711679.myhostgator.site"] [uri "/robots.txt"] [unique_id "al9TzoiENNLP6XjiHQs6jQABsTQ"]
[Tue Jul 21 08:11:10.734289 2026] [security2:error] [pid 402041:tid 402097] [remote 45.76.153.27:60016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.153.76.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9TzoiENNLP6XjiHQs6jgABvTU"]
[Tue Jul 21 08:11:10.778223 2026] [security2:error] [pid 402041:tid 402255] [client 20.206.105.145:29669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "evelinemilfontadv.com"] [uri "/fpwch.php"] [unique_id "al9TzoiENNLP6XjiHQs6jwAAAeE"]
[Tue Jul 21 08:11:10.826438 2026] [security2:error] [pid 402041:tid 402272] [client 20.104.96.117:54695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/spadex.php"] [unique_id "al9TzoiENNLP6XjiHQs6kQAAAfI"]
[Tue Jul 21 08:11:10.984112 2026] [security2:error] [pid 402041:tid 402192] [client 20.226.60.151:48784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/x.php"] [unique_id "al9TzoiENNLP6XjiHQs6kwAAAaI"]
[Tue Jul 21 08:11:10.991938 2026] [security2:error] [pid 402041:tid 402247] [client 65.21.113.253:58422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9TzoiENNLP6XjiHQs6lQAAAdk"]
[Tue Jul 21 08:11:11.020428 2026] [security2:error] [pid 402041:tid 402186] [client 20.151.10.161:13223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/main.php"] [unique_id "al9Tz4iENNLP6XjiHQs6mAAAAZw"]
[Tue Jul 21 08:11:11.104482 2026] [security2:error] [pid 402041:tid 402061] [remote 185.236.20.134:7898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadanaturalis.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9Tz4iENNLP6XjiHQs6mgAB3RE"]
[Tue Jul 21 08:11:11.148928 2026] [security2:error] [pid 402041:tid 402259] [client 20.104.96.117:62544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/sym403.php"] [unique_id "al9Tz4iENNLP6XjiHQs6ngAAAeU"]
[Tue Jul 21 08:11:11.298152 2026] [security2:error] [pid 402041:tid 402205] [client 20.104.96.117:54086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/2x.php"] [unique_id "al9Tz4iENNLP6XjiHQs6pwAAAa8"]
[Tue Jul 21 08:11:11.589918 2026] [security2:error] [pid 402041:tid 402222] [client 65.21.113.253:44208] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Tz4iENNLP6XjiHQs6owAAAcA"]
[Tue Jul 21 08:11:11.716276 2026] [security2:error] [pid 402041:tid 402276] [client 20.151.10.161:13067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/init.php"] [unique_id "al9Tz4iENNLP6XjiHQs6sQAAAfY"]
[Tue Jul 21 08:11:11.805303 2026] [core:error] [pid 402041:tid 402110] [remote 45.148.10.238:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:11:11.805326 2026] [core:error] [pid 402041:tid 402110] [remote 45.148.10.238:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:11:11.906227 2026] [security2:error] [pid 402041:tid 402112] [remote 185.236.20.134:7900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadanaturalis.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9Tz4iENNLP6XjiHQs6twACAEQ"]
[Tue Jul 21 08:11:11.975207 2026] [security2:error] [pid 402041:tid 402212] [client 117.210.135.0:55854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tz4iENNLP6XjiHQs6uQAAAbY"]
[Tue Jul 21 08:11:11.975321 2026] [security2:error] [pid 402041:tid 402212] [client 117.210.135.0:55854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Tz4iENNLP6XjiHQs6uQAAAbY"]
[Tue Jul 21 08:11:12.008264 2026] [security2:error] [pid 402041:tid 402217] [client 20.151.10.161:55853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/footer.php"] [unique_id "al9T0IiENNLP6XjiHQs6vAAAAbs"]
[Tue Jul 21 08:11:12.161500 2026] [security2:error] [pid 402041:tid 402210] [client 20.104.96.117:58402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/6.php"] [unique_id "al9T0IiENNLP6XjiHQs6vgAAAbQ"]
[Tue Jul 21 08:11:12.266349 2026] [security2:error] [pid 402041:tid 402223] [client 65.21.113.253:38944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Tz4iENNLP6XjiHQs6tAAAAcE"]
[Tue Jul 21 08:11:12.311196 2026] [security2:error] [pid 402041:tid 402264] [client 185.236.20.134:23032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadanaturalis.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9T0IiENNLP6XjiHQs6wgAAAeo"]
[Tue Jul 21 08:11:12.372252 2026] [security2:error] [pid 402041:tid 402292] [client 103.78.200.11:61525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T0IiENNLP6XjiHQs6yAAAAgY"]
[Tue Jul 21 08:11:12.373195 2026] [security2:error] [pid 402041:tid 402292] [client 103.78.200.11:61525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T0IiENNLP6XjiHQs6yAAAAgY"]
[Tue Jul 21 08:11:12.397304 2026] [security2:error] [pid 402041:tid 402247] [client 20.104.96.117:62508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/v543.php"] [unique_id "al9T0IiENNLP6XjiHQs6ywAAAdk"]
[Tue Jul 21 08:11:12.664845 2026] [security2:error] [pid 402041:tid 402251] [client 20.151.10.161:13107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/prekel.php"] [unique_id "al9T0IiENNLP6XjiHQs60wAAAd0"]
[Tue Jul 21 08:11:12.719890 2026] [security2:error] [pid 402041:tid 402278] [client 20.226.60.151:48796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/155.php"] [unique_id "al9T0IiENNLP6XjiHQs61AAAAfg"]
[Tue Jul 21 08:11:12.925837 2026] [security2:error] [pid 402041:tid 402124] [remote 185.236.20.134:7916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.20.236.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.pousadanaturalis.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9T0IiENNLP6XjiHQs62wAB1FA"]
[Tue Jul 21 08:11:13.041880 2026] [security2:error] [pid 402041:tid 402260] [client 87.116.180.198:27161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T0YiENNLP6XjiHQs63AAAAeY"]
[Tue Jul 21 08:11:13.046193 2026] [security2:error] [pid 402041:tid 402260] [client 87.116.180.198:27161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T0YiENNLP6XjiHQs63AAAAeY"]
[Tue Jul 21 08:11:13.212232 2026] [security2:error] [pid 402041:tid 402288] [client 104.248.207.193:36350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liranesuliano.com.br"] [uri "/"] [unique_id "al9T0YiENNLP6XjiHQs64gAAAgI"]
[Tue Jul 21 08:11:13.887657 2026] [security2:error] [pid 402041:tid 402295] [client 62.102.148.158:46132] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9T0YiENNLP6XjiHQs6-gAAAgk"]
[Tue Jul 21 08:11:13.887751 2026] [security2:error] [pid 402041:tid 402295] [client 62.102.148.158:46132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9T0YiENNLP6XjiHQs6-gAAAgk"]
[Tue Jul 21 08:11:13.932856 2026] [security2:error] [pid 402041:tid 402140] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T0YiENNLP6XjiHQs6-wABrGA"]
[Tue Jul 21 08:11:13.933044 2026] [security2:error] [pid 402041:tid 402202] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T0YiENNLP6XjiHQs6-wABrGA"]
[Tue Jul 21 08:11:13.944854 2026] [security2:error] [pid 402041:tid 402141] [remote 185.236.20.134:7922] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.pousadanaturalis.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9T0YiENNLP6XjiHQs6_AAB5GE"]
[Tue Jul 21 08:11:14.137382 2026] [security2:error] [pid 402041:tid 402239] [client 38.100.221.102:18012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T0oiENNLP6XjiHQs7AgAAAdE"]
[Tue Jul 21 08:11:14.137518 2026] [security2:error] [pid 402041:tid 402239] [client 38.100.221.102:18012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T0oiENNLP6XjiHQs7AgAAAdE"]
[Tue Jul 21 08:11:14.204955 2026] [core:alert] [pid 402041:tid 402190] [client 57.141.18.64:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:11:14.244475 2026] [security2:error] [pid 402041:tid 402183] [client 154.208.47.43:40810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9T0oiENNLP6XjiHQs7CQAAAZk"]
[Tue Jul 21 08:11:14.244567 2026] [security2:error] [pid 402041:tid 402183] [client 154.208.47.43:40810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9T0oiENNLP6XjiHQs7CQAAAZk"]
[Tue Jul 21 08:11:14.342131 2026] [security2:error] [pid 402041:tid 402186] [client 185.236.20.134:55458] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.pousadanaturalis.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9T0oiENNLP6XjiHQs7DwAAAZw"]
[Tue Jul 21 08:11:14.394331 2026] [security2:error] [pid 402041:tid 402203] [client 20.226.60.151:48824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/ops.php"] [unique_id "al9T0oiENNLP6XjiHQs7EgAAAa0"]
[Tue Jul 21 08:11:14.520108 2026] [security2:error] [pid 402041:tid 402242] [client 20.104.96.117:62524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/sixxis.php"] [unique_id "al9T0oiENNLP6XjiHQs7FAAAAdQ"]
[Tue Jul 21 08:11:14.618588 2026] [security2:error] [pid 402041:tid 402191] [client 20.151.10.161:55823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-content/index.php"] [unique_id "al9T0oiENNLP6XjiHQs7FwAAAaE"]
[Tue Jul 21 08:11:14.724943 2026] [security2:error] [pid 402041:tid 402155] [remote 84.247.172.23:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tavarescont.com.br"] [uri "/wp-login.php"] [unique_id "al9T0oiENNLP6XjiHQs7GgAB_28"]
[Tue Jul 21 08:11:14.797573 2026] [security2:error] [pid 402041:tid 402215] [client 20.104.96.117:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/32e17094cfindex.php"] [unique_id "al9T0oiENNLP6XjiHQs7HgAAAbk"]
[Tue Jul 21 08:11:14.963531 2026] [security2:error] [pid 402041:tid 402276] [client 20.151.10.161:13241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/0.php"] [unique_id "al9T0oiENNLP6XjiHQs7JAAAAfY"]
[Tue Jul 21 08:11:15.061699 2026] [security2:error] [pid 402041:tid 402220] [client 103.151.46.103:50506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T04iENNLP6XjiHQs7JgAAAb4"]
[Tue Jul 21 08:11:15.061880 2026] [security2:error] [pid 402041:tid 402220] [client 103.151.46.103:50506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T04iENNLP6XjiHQs7JgAAAb4"]
[Tue Jul 21 08:11:15.365730 2026] [security2:error] [pid 402041:tid 402162] [remote 185.236.20.134:62226] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.pousadanaturalis.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9T04iENNLP6XjiHQs7LAABtHY"]
[Tue Jul 21 08:11:15.457242 2026] [security2:error] [pid 402041:tid 402261] [client 20.226.60.151:48815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/file31.php"] [unique_id "al9T04iENNLP6XjiHQs7NQAAAec"]
[Tue Jul 21 08:11:15.671649 2026] [security2:error] [pid 402041:tid 402045] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T04iENNLP6XjiHQs7OwACCQE"]
[Tue Jul 21 08:11:15.671852 2026] [security2:error] [pid 402041:tid 402295] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T04iENNLP6XjiHQs7OwACCQE"]
[Tue Jul 21 08:11:15.674462 2026] [log_config:warn] [pid 358661:tid 358865] (32)Broken pipe: [client 131.100.41.172:7388] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:11:15.674483 2026] [log_config:warn] [pid 358661:tid 358865] (32)Broken pipe: [client 131.100.41.172:7388] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:11:15.749970 2026] [security2:error] [pid 402041:tid 402232] [client 65.21.113.253:58422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9T04iENNLP6XjiHQs7PAAAAco"]
[Tue Jul 21 08:11:15.842909 2026] [security2:error] [pid 402041:tid 402214] [client 20.104.96.117:54685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/ctex1.php"] [unique_id "al9T04iENNLP6XjiHQs7QAAAAbg"]
[Tue Jul 21 08:11:16.195503 2026] [security2:error] [pid 402041:tid 402195] [client 20.226.60.151:48872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/file6.php"] [unique_id "al9T1IiENNLP6XjiHQs7SAAAAaU"]
[Tue Jul 21 08:11:16.227620 2026] [security2:error] [pid 402041:tid 402055] [remote 57.141.18.89:49956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9T1IiENNLP6XjiHQs7SQABrws"]
[Tue Jul 21 08:11:16.252586 2026] [security2:error] [pid 402041:tid 402181] [client 20.104.96.117:57922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/qqqa.php"] [unique_id "al9T1IiENNLP6XjiHQs7SwAAAZc"]
[Tue Jul 21 08:11:16.255786 2026] [security2:error] [pid 402041:tid 402242] [client 20.151.10.161:13131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/BDKR28.php"] [unique_id "al9T1IiENNLP6XjiHQs7TQAAAdQ"]
[Tue Jul 21 08:11:16.346593 2026] [security2:error] [pid 402041:tid 402203] [client 65.21.113.253:38944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T04iENNLP6XjiHQs7RAAAAa0"]
[Tue Jul 21 08:11:16.721455 2026] [security2:error] [pid 402041:tid 402044] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T1IiENNLP6XjiHQs7WQACCgA"]
[Tue Jul 21 08:11:16.721656 2026] [security2:error] [pid 402041:tid 402296] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T1IiENNLP6XjiHQs7WQACCgA"]
[Tue Jul 21 08:11:16.858331 2026] [security2:error] [pid 402041:tid 402196] [client 65.21.113.253:38956] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T1IiENNLP6XjiHQs7UwAAAaY"]
[Tue Jul 21 08:11:16.928848 2026] [security2:error] [pid 402041:tid 402182] [client 125.18.144.2:12716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9T1IiENNLP6XjiHQs7XgAAAZg"]
[Tue Jul 21 08:11:16.928996 2026] [security2:error] [pid 402041:tid 402182] [client 125.18.144.2:12716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9T1IiENNLP6XjiHQs7XgAAAZg"]
[Tue Jul 21 08:11:17.470605 2026] [security2:error] [pid 402041:tid 402248] [client 102.206.115.33:61797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T1YiENNLP6XjiHQs7bAAAAdo"]
[Tue Jul 21 08:11:17.470730 2026] [security2:error] [pid 402041:tid 402248] [client 102.206.115.33:61797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T1YiENNLP6XjiHQs7bAAAAdo"]
[Tue Jul 21 08:11:17.546323 2026] [security2:error] [pid 402041:tid 402204] [client 20.151.10.161:13078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/f35.update.php"] [unique_id "al9T1YiENNLP6XjiHQs7cAAAAa4"]
[Tue Jul 21 08:11:17.716487 2026] [security2:error] [pid 402041:tid 402295] [client 20.197.192.193:57834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9T1YiENNLP6XjiHQs7eAAAAgk"]
[Tue Jul 21 08:11:17.809800 2026] [security2:error] [pid 402041:tid 402070] [remote 100.42.189.89:60280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/wp-login.php"] [unique_id "al9T1YiENNLP6XjiHQs7egAB0ho"]
[Tue Jul 21 08:11:17.835770 2026] [security2:error] [pid 402041:tid 402063] [remote 173.252.69.112:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.69.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9T1YiENNLP6XjiHQs7dgABwRM"]
[Tue Jul 21 08:11:18.133092 2026] [security2:error] [pid 402041:tid 402189] [client 20.104.96.117:62488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/ip.php"] [unique_id "al9T1oiENNLP6XjiHQs7hAAAAZ8"]
[Tue Jul 21 08:11:18.253222 2026] [security2:error] [pid 402041:tid 402080] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9T1oiENNLP6XjiHQs7jAACAyQ"]
[Tue Jul 21 08:11:18.253419 2026] [security2:error] [pid 402041:tid 402289] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9T1oiENNLP6XjiHQs7jAACAyQ"]
[Tue Jul 21 08:11:18.262756 2026] [security2:error] [pid 402041:tid 402242] [client 162.219.176.3:54174] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9T1oiENNLP6XjiHQs7jQAAAdQ"]
[Tue Jul 21 08:11:18.262876 2026] [security2:error] [pid 402041:tid 402242] [client 162.219.176.3:54174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9T1oiENNLP6XjiHQs7jQAAAdQ"]
[Tue Jul 21 08:11:18.295324 2026] [security2:error] [pid 402041:tid 402048] [remote 195.63.31.240:36011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9T1YiENNLP6XjiHQs7ZgABswQ"]
[Tue Jul 21 08:11:18.384154 2026] [security2:error] [pid 402041:tid 402203] [client 20.197.192.193:61825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/wp-css.php"] [unique_id "al9T1oiENNLP6XjiHQs7jwAAAa0"]
[Tue Jul 21 08:11:18.389740 2026] [security2:error] [pid 402041:tid 402298] [client 162.219.176.3:54190] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9T1oiENNLP6XjiHQs7kAAAAgw"]
[Tue Jul 21 08:11:18.389826 2026] [security2:error] [pid 402041:tid 402298] [client 162.219.176.3:54190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9T1oiENNLP6XjiHQs7kAAAAgw"]
[Tue Jul 21 08:11:18.688452 2026] [security2:error] [pid 402041:tid 402222] [client 74.7.241.155:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "renatalopesdeoliveir1781632576979.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9T1oiENNLP6XjiHQs7mwABwCk"]
[Tue Jul 21 08:11:18.779195 2026] [autoindex:error] [pid 402041:tid 402268] [client 20.226.60.151:48768] AH01276: Cannot serve directory /home4/moadvo53/moadvogadas.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:11:18.790207 2026] [security2:error] [pid 402041:tid 402231] [client 20.226.60.151:48799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/adminfuns.php"] [unique_id "al9T1oiENNLP6XjiHQs7oQAAAck"]
[Tue Jul 21 08:11:18.999010 2026] [security2:error] [pid 402041:tid 402218] [client 120.56.162.40:52287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T1oiENNLP6XjiHQs7pgAAAbw"]
[Tue Jul 21 08:11:18.999105 2026] [security2:error] [pid 402041:tid 402218] [client 120.56.162.40:52287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T1oiENNLP6XjiHQs7pgAAAbw"]
[Tue Jul 21 08:11:19.056758 2026] [security2:error] [pid 402041:tid 402180] [client 20.151.10.161:51065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/zoro.php"] [unique_id "al9T14iENNLP6XjiHQs7qgAAAZY"]
[Tue Jul 21 08:11:19.106120 2026] [security2:error] [pid 402041:tid 402098] [remote 192.241.143.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.hauptmann.com.br"] [uri "/wp-login.php"] [unique_id "al9T14iENNLP6XjiHQs7rQABzTY"]
[Tue Jul 21 08:11:19.128579 2026] [security2:error] [pid 402041:tid 402210] [client 20.104.96.117:58370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/aunmc.php"] [unique_id "al9T14iENNLP6XjiHQs7rwAAAbQ"]
[Tue Jul 21 08:11:19.316810 2026] [security2:error] [pid 402041:tid 402292] [client 20.226.60.151:48867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/goods.php"] [unique_id "al9T14iENNLP6XjiHQs7tAAAAgY"]
[Tue Jul 21 08:11:19.363157 2026] [security2:error] [pid 402041:tid 402225] [client 65.21.113.253:38956] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T1oiENNLP6XjiHQs7ogAAAcM"]
[Tue Jul 21 08:11:19.445673 2026] [autoindex:error] [pid 402041:tid 402105] [remote 34.146.29.21:44224] AH01276: Cannot serve directory /home4/fabi0417/admin.powerflats.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:11:19.520501 2026] [security2:error] [pid 402041:tid 402179] [client 150.129.202.39:64763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T14iENNLP6XjiHQs7ugAAAZU"]
[Tue Jul 21 08:11:19.520622 2026] [security2:error] [pid 402041:tid 402179] [client 150.129.202.39:64763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T14iENNLP6XjiHQs7ugAAAZU"]
[Tue Jul 21 08:11:19.624240 2026] [security2:error] [pid 402041:tid 402109] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9T14iENNLP6XjiHQs7vQABpEE"]
[Tue Jul 21 08:11:19.624454 2026] [security2:error] [pid 402041:tid 402194] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9T14iENNLP6XjiHQs7vQABpEE"]
[Tue Jul 21 08:11:19.730301 2026] [security2:error] [pid 402041:tid 402189] [client 20.151.10.161:13247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/f900.php"] [unique_id "al9T14iENNLP6XjiHQs7wAAAAZ8"]
[Tue Jul 21 08:11:19.750564 2026] [security2:error] [pid 402041:tid 402117] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/wp-json"] [unique_id "al9T14iENNLP6XjiHQs7yAAB1Ek"]
[Tue Jul 21 08:11:19.750717 2026] [security2:error] [pid 402041:tid 402242] [client 34.146.29.21:44224] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "admin.powerflats.com.br"] [uri "/wp-json"] [unique_id "al9T14iENNLP6XjiHQs7yAAB1Ek"]
[Tue Jul 21 08:11:19.750960 2026] [security2:error] [pid 402041:tid 402107] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "admin.powerflats.com.br"] [uri "/rclone.conf"] [unique_id "al9T14iENNLP6XjiHQs7ygAB1D8"]
[Tue Jul 21 08:11:19.969130 2026] [security2:error] [pid 402041:tid 402121] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/.aws/config"] [unique_id "al9T14iENNLP6XjiHQs7zgABkU0"]
[Tue Jul 21 08:11:20.007346 2026] [security2:error] [pid 402041:tid 402122] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/.env"] [unique_id "al9T2IiENNLP6XjiHQs71QABkE4"]
[Tue Jul 21 08:11:20.048833 2026] [security2:error] [pid 402041:tid 402131] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/.env.backup"] [unique_id "al9T2IiENNLP6XjiHQs73QABzlc"]
[Tue Jul 21 08:11:20.050831 2026] [security2:error] [pid 402041:tid 402133] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/.env.bak"] [unique_id "al9T2IiENNLP6XjiHQs73gABk1k"]
[Tue Jul 21 08:11:20.057104 2026] [fcgid:warn] [pid 402041:tid 402276] (70014)End of file found: [client 167.94.146.61:37012] mod_fcgid: can't get data from http client
[Tue Jul 21 08:11:20.247758 2026] [security2:error] [pid 402041:tid 402297] [client 62.102.148.158:48286] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9T2IiENNLP6XjiHQs74AAAAgs"]
[Tue Jul 21 08:11:20.247880 2026] [security2:error] [pid 402041:tid 402297] [client 62.102.148.158:48286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9T2IiENNLP6XjiHQs74AAAAgs"]
[Tue Jul 21 08:11:20.280697 2026] [security2:error] [pid 402041:tid 402140] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "admin.powerflats.com.br"] [uri "/graphql"] [unique_id "al9T2IiENNLP6XjiHQs75QAB8WA"]
[Tue Jul 21 08:11:20.297603 2026] [security2:error] [pid 402041:tid 402134] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "admin.powerflats.com.br"] [uri "/backend/.env"] [unique_id "al9T2IiENNLP6XjiHQs76AAB81o"]
[Tue Jul 21 08:11:20.300398 2026] [security2:error] [pid 402041:tid 402143] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/api/.env"] [unique_id "al9T2IiENNLP6XjiHQs76QABm2M"]
[Tue Jul 21 08:11:20.300568 2026] [security2:error] [pid 402041:tid 402185] [client 34.146.29.21:44224] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "admin.powerflats.com.br"] [uri "/api/.env"] [unique_id "al9T2IiENNLP6XjiHQs76QABm2M"]
[Tue Jul 21 08:11:20.302030 2026] [security2:error] [pid 402041:tid 402137] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/config/.env"] [unique_id "al9T2IiENNLP6XjiHQs76gABzF0"]
[Tue Jul 21 08:11:20.302753 2026] [security2:error] [pid 402041:tid 402146] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "admin.powerflats.com.br"] [uri "/.env.old"] [unique_id "al9T2IiENNLP6XjiHQs76wABvGY"]
[Tue Jul 21 08:11:20.431846 2026] [security2:error] [pid 402041:tid 402258] [client 20.104.96.117:54096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/edorxrr.php"] [unique_id "al9T2IiENNLP6XjiHQs79QAAAeQ"]
[Tue Jul 21 08:11:20.572167 2026] [security2:error] [pid 402041:tid 402144] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "admin.powerflats.com.br"] [uri "/api/graphql"] [unique_id "al9T2IiENNLP6XjiHQs7-wAB12Q"]
[Tue Jul 21 08:11:20.594689 2026] [authz_core:error] [pid 402041:tid 402162] [remote 34.146.29.21:44224] AH01630: client denied by server configuration: /home4/fabi0417/admin.powerflats.com.br/.htpasswd
[Tue Jul 21 08:11:20.604337 2026] [security2:error] [pid 402041:tid 402167] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/terraform.tfstate"] [unique_id "al9T2IiENNLP6XjiHQs8AgABlXs"]
[Tue Jul 21 08:11:20.630353 2026] [security2:error] [pid 402041:tid 402164] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9T2IiENNLP6XjiHQs8BQAB0Xg"]
[Tue Jul 21 08:11:20.639322 2026] [security2:error] [pid 402041:tid 402157] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T2IiENNLP6XjiHQs8CAABsHE"]
[Tue Jul 21 08:11:20.639445 2026] [security2:error] [pid 402041:tid 402206] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T2IiENNLP6XjiHQs8CAABsHE"]
[Tue Jul 21 08:11:20.646604 2026] [security2:error] [pid 402041:tid 402274] [client 20.226.60.151:48773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/100.php"] [unique_id "al9T2IiENNLP6XjiHQs8CgAAAfQ"]
[Tue Jul 21 08:11:20.747419 2026] [security2:error] [pid 402041:tid 402047] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9T2IiENNLP6XjiHQs8EwABnAM"]
[Tue Jul 21 08:11:20.747569 2026] [security2:error] [pid 402041:tid 402186] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9T2IiENNLP6XjiHQs8EwABnAM"]
[Tue Jul 21 08:11:20.834036 2026] [security2:error] [pid 402041:tid 402171] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "admin.powerflats.com.br"] [uri "/v1/graphql"] [unique_id "al9T2IiENNLP6XjiHQs8FwABr38"]
[Tue Jul 21 08:11:20.861293 2026] [security2:error] [pid 402041:tid 402170] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/.ssh/id_dsa"] [unique_id "al9T2IiENNLP6XjiHQs8GQACA34"]
[Tue Jul 21 08:11:20.885135 2026] [security2:error] [pid 402041:tid 402051] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "admin.powerflats.com.br"] [uri "/server.key"] [unique_id "al9T2IiENNLP6XjiHQs8HgACBAc"]
[Tue Jul 21 08:11:20.890624 2026] [security2:error] [pid 402041:tid 402058] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/id_rsa"] [unique_id "al9T2IiENNLP6XjiHQs8HwAB4A4"]
[Tue Jul 21 08:11:20.898204 2026] [security2:error] [pid 402041:tid 402152] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "admin.powerflats.com.br"] [uri "/id_dsa"] [unique_id "al9T2IiENNLP6XjiHQs8IgABj2w"]
[Tue Jul 21 08:11:20.931309 2026] [security2:error] [pid 402041:tid 402056] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/key.pem"] [unique_id "al9T2IiENNLP6XjiHQs8IwACDAw"]
[Tue Jul 21 08:11:20.936872 2026] [security2:error] [pid 402041:tid 402067] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/privatekey.key"] [unique_id "al9T2IiENNLP6XjiHQs8JAABoRc"]
[Tue Jul 21 08:11:21.035031 2026] [security2:error] [pid 402041:tid 402065] [remote 57.141.18.94:46926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9T2YiENNLP6XjiHQs8JQAB_RU"]
[Tue Jul 21 08:11:21.167001 2026] [security2:error] [pid 402041:tid 402078] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/.aider.conf.yml"] [unique_id "al9T2YiENNLP6XjiHQs8MgABwCI"]
[Tue Jul 21 08:11:21.167102 2026] [security2:error] [pid 402041:tid 402222] [client 34.146.29.21:44224] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "admin.powerflats.com.br"] [uri "/.aider.conf.yml"] [unique_id "al9T2YiENNLP6XjiHQs8MgABwCI"]
[Tue Jul 21 08:11:21.174596 2026] [security2:error] [pid 402041:tid 402076] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/.openclaw/.env"] [unique_id "al9T2YiENNLP6XjiHQs8NAAB_iA"]
[Tue Jul 21 08:11:21.222909 2026] [security2:error] [pid 402041:tid 402081] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/.hermes/.env"] [unique_id "al9T2YiENNLP6XjiHQs8NwABySU"]
[Tue Jul 21 08:11:21.238591 2026] [security2:error] [pid 402041:tid 402181] [client 65.21.113.253:38956] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T2IiENNLP6XjiHQs8GAAAAZc"]
[Tue Jul 21 08:11:21.251656 2026] [security2:error] [pid 402041:tid 402189] [client 109.60.28.94:62866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T2YiENNLP6XjiHQs8OgAAAZ8"]
[Tue Jul 21 08:11:21.251781 2026] [security2:error] [pid 402041:tid 402189] [client 109.60.28.94:62866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T2YiENNLP6XjiHQs8OgAAAZ8"]
[Tue Jul 21 08:11:21.320794 2026] [security2:error] [pid 402041:tid 402185] [client 20.104.96.117:62500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/kq1.php"] [unique_id "al9T2YiENNLP6XjiHQs8PgAAAZs"]
[Tue Jul 21 08:11:21.497181 2026] [security2:error] [pid 402041:tid 402096] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "admin.powerflats.com.br"] [uri "/wp-config.php.bak"] [unique_id "al9T2YiENNLP6XjiHQs8TwABsTQ"]
[Tue Jul 21 08:11:21.497983 2026] [security2:error] [pid 402041:tid 402069] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "admin.powerflats.com.br"] [uri "/wp-config.php.old"] [unique_id "al9T2YiENNLP6XjiHQs8UAABwxk"]
[Tue Jul 21 08:11:21.548822 2026] [security2:error] [pid 402041:tid 402280] [client 20.151.10.161:13217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/xmrl.php"] [unique_id "al9T2YiENNLP6XjiHQs8UwAAAfo"]
[Tue Jul 21 08:11:21.704843 2026] [security2:error] [pid 402041:tid 402101] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.powerflats.com.br"] [uri "/config/.env.php"] [unique_id "al9T2YiENNLP6XjiHQs8WAAB0jk"]
[Tue Jul 21 08:11:21.715837 2026] [security2:error] [pid 402041:tid 402091] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.powerflats.com.br"] [uri "/.env.php.bak"] [unique_id "al9T2YiENNLP6XjiHQs8WQACBS8"]
[Tue Jul 21 08:11:21.732059 2026] [security2:error] [pid 402041:tid 402105] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/laravel/.env"] [unique_id "al9T2YiENNLP6XjiHQs8WgAByz0"]
[Tue Jul 21 08:11:21.734458 2026] [security2:error] [pid 402041:tid 402104] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/core/.env"] [unique_id "al9T2YiENNLP6XjiHQs8WwABvTw"]
[Tue Jul 21 08:11:21.752659 2026] [security2:error] [pid 402041:tid 402099] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.powerflats.com.br"] [uri "/configuration.php.bak"] [unique_id "al9T2YiENNLP6XjiHQs8XwAB0Dc"]
[Tue Jul 21 08:11:21.762332 2026] [security2:error] [pid 402041:tid 402108] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/.env.swp"] [unique_id "al9T2YiENNLP6XjiHQs8YgAB2UA"]
[Tue Jul 21 08:11:21.770314 2026] [security2:error] [pid 402041:tid 402111] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/config.php.bak"] [unique_id "al9T2YiENNLP6XjiHQs8YwACDUM"]
[Tue Jul 21 08:11:21.770425 2026] [security2:error] [pid 402041:tid 402299] [client 34.146.29.21:44224] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "admin.powerflats.com.br"] [uri "/config.php.bak"] [unique_id "al9T2YiENNLP6XjiHQs8YwACDUM"]
[Tue Jul 21 08:11:21.791961 2026] [security2:error] [pid 402041:tid 402246] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T2YiENNLP6XjiHQs8QQAAAdg"]
[Tue Jul 21 08:11:21.803699 2026] [security2:error] [pid 402041:tid 402272] [client 154.57.197.145:50080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.197.57.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T2IiENNLP6XjiHQs8FQAAAfI"]
[Tue Jul 21 08:11:21.803822 2026] [security2:error] [pid 402041:tid 402272] [client 154.57.197.145:50080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T2IiENNLP6XjiHQs8FQAAAfI"]
[Tue Jul 21 08:11:21.828469 2026] [security2:error] [pid 402041:tid 402087] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/public/.env"] [unique_id "al9T2YiENNLP6XjiHQs8ZQABuCs"]
[Tue Jul 21 08:11:21.832473 2026] [security2:error] [pid 402041:tid 402112] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/web/.env"] [unique_id "al9T2YiENNLP6XjiHQs8ZgABxUQ"]
[Tue Jul 21 08:11:21.996207 2026] [security2:error] [pid 402041:tid 402116] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/config.json"] [unique_id "al9T2YiENNLP6XjiHQs8bQACA0g"]
[Tue Jul 21 08:11:21.996361 2026] [security2:error] [pid 402041:tid 402289] [client 34.146.29.21:44224] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "admin.powerflats.com.br"] [uri "/config.json"] [unique_id "al9T2YiENNLP6XjiHQs8bQACA0g"]
[Tue Jul 21 08:11:22.013530 2026] [security2:error] [pid 402041:tid 402113] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "admin.powerflats.com.br"] [uri "/api/v1/settings"] [unique_id "al9T2oiENNLP6XjiHQs8bwABs0U"]
[Tue Jul 21 08:11:22.233557 2026] [security2:error] [pid 402041:tid 402196] [client 61.1.167.83:63474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T2oiENNLP6XjiHQs8fwAAAaY"]
[Tue Jul 21 08:11:22.233667 2026] [security2:error] [pid 402041:tid 402196] [client 61.1.167.83:63474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T2oiENNLP6XjiHQs8fwAAAaY"]
[Tue Jul 21 08:11:22.255406 2026] [security2:error] [pid 402041:tid 402136] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "admin.powerflats.com.br"] [uri "/api/v1/config"] [unique_id "al9T2oiENNLP6XjiHQs8gQABk1w"]
[Tue Jul 21 08:11:22.285437 2026] [security2:error] [pid 402041:tid 402110] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "admin.powerflats.com.br"] [uri "/runtime-config.js"] [unique_id "al9T2oiENNLP6XjiHQs8hwABn0I"]
[Tue Jul 21 08:11:22.335107 2026] [security2:error] [pid 402041:tid 402140] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/api/health"] [unique_id "al9T2oiENNLP6XjiHQs8iwAB6WA"]
[Tue Jul 21 08:11:22.335211 2026] [security2:error] [pid 402041:tid 402263] [client 34.146.29.21:44224] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "admin.powerflats.com.br"] [uri "/api/health"] [unique_id "al9T2oiENNLP6XjiHQs8iwAB6WA"]
[Tue Jul 21 08:11:22.367635 2026] [security2:error] [pid 402041:tid 402134] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/app-config.json"] [unique_id "al9T2oiENNLP6XjiHQs8jQABrVo"]
[Tue Jul 21 08:11:22.367784 2026] [security2:error] [pid 402041:tid 402203] [client 34.146.29.21:44224] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "admin.powerflats.com.br"] [uri "/app-config.json"] [unique_id "al9T2oiENNLP6XjiHQs8jQABrVo"]
[Tue Jul 21 08:11:22.390837 2026] [security2:error] [pid 402041:tid 402300] [client 103.78.200.11:62002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T2oiENNLP6XjiHQs8jgAAAg4"]
[Tue Jul 21 08:11:22.390964 2026] [security2:error] [pid 402041:tid 402300] [client 103.78.200.11:62002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T2oiENNLP6XjiHQs8jgAAAg4"]
[Tue Jul 21 08:11:22.451080 2026] [security2:error] [pid 402041:tid 402141] [remote 65.111.30.179:15859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.30.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9T2IiENNLP6XjiHQs75gACCmE"]
[Tue Jul 21 08:11:22.554301 2026] [security2:error] [pid 402041:tid 402149] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "admin.powerflats.com.br"] [uri "/service-worker.js"] [unique_id "al9T2oiENNLP6XjiHQs8lgAB-Wk"]
[Tue Jul 21 08:11:22.613105 2026] [security2:error] [pid 402041:tid 402151] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/v1/graphql"] [unique_id "al9T2oiENNLP6XjiHQs8mwABlms"]
[Tue Jul 21 08:11:22.613247 2026] [security2:error] [pid 402041:tid 402180] [client 34.146.29.21:44224] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "admin.powerflats.com.br"] [uri "/v1/graphql"] [unique_id "al9T2oiENNLP6XjiHQs8mwABlms"]
[Tue Jul 21 08:11:22.712227 2026] [security2:error] [pid 402041:tid 402191] [client 117.210.135.0:56507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T2oiENNLP6XjiHQs8ogAAAaE"]
[Tue Jul 21 08:11:22.712327 2026] [security2:error] [pid 402041:tid 402191] [client 117.210.135.0:56507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T2oiENNLP6XjiHQs8ogAAAaE"]
[Tue Jul 21 08:11:22.785195 2026] [security2:error] [pid 402041:tid 402280] [client 20.226.60.151:48883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/about.php"] [unique_id "al9T2oiENNLP6XjiHQs8pAAAAfo"]
[Tue Jul 21 08:11:22.786324 2026] [security2:error] [pid 402041:tid 402162] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.powerflats.com.br"] [uri "/phpinfo.php"] [unique_id "al9T2oiENNLP6XjiHQs8pQACCXY"]
[Tue Jul 21 08:11:22.818884 2026] [security2:error] [pid 402041:tid 402158] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.powerflats.com.br"] [uri "/info.php"] [unique_id "al9T2oiENNLP6XjiHQs8pgABu3I"]
[Tue Jul 21 08:11:22.823188 2026] [security2:error] [pid 402041:tid 402167] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.powerflats.com.br"] [uri "/pi.php"] [unique_id "al9T2oiENNLP6XjiHQs8qAAB0Xs"]
[Tue Jul 21 08:11:22.835626 2026] [security2:error] [pid 402041:tid 402168] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.powerflats.com.br"] [uri "/test.php"] [unique_id "al9T2oiENNLP6XjiHQs8qwABynw"]
[Tue Jul 21 08:11:22.836688 2026] [security2:error] [pid 402041:tid 402166] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/_profiler/latest"] [unique_id "al9T2oiENNLP6XjiHQs8rAAB0no"]
[Tue Jul 21 08:11:22.847196 2026] [security2:error] [pid 402041:tid 402169] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.powerflats.com.br"] [uri "/i.php"] [unique_id "al9T2oiENNLP6XjiHQs8rQABvX0"]
[Tue Jul 21 08:11:22.875765 2026] [security2:error] [pid 402041:tid 402157] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.powerflats.com.br"] [uri "/app_dev.php"] [unique_id "al9T2oiENNLP6XjiHQs8rwABo3E"]
[Tue Jul 21 08:11:22.887636 2026] [security2:error] [pid 402041:tid 402139] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.powerflats.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "al9T2oiENNLP6XjiHQs8sAABrl8"]
[Tue Jul 21 08:11:22.945880 2026] [security2:error] [pid 402041:tid 402045] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/_ignition/health-check"] [unique_id "al9T2oiENNLP6XjiHQs8sgAB9AE"]
[Tue Jul 21 08:11:23.030004 2026] [security2:error] [pid 402041:tid 402245] [client 103.114.211.171:49874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.211.114.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/xmlrpc.php"] [unique_id "al9T2YiENNLP6XjiHQs8ZwAAAdc"]
[Tue Jul 21 08:11:23.030144 2026] [security2:error] [pid 402041:tid 402245] [client 103.114.211.171:49874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "issimastore.com"] [uri "/xmlrpc.php"] [unique_id "al9T2YiENNLP6XjiHQs8ZwAAAdc"]
[Tue Jul 21 08:11:23.091966 2026] [security2:error] [pid 402041:tid 402171] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/__debug__/"] [unique_id "al9T24iENNLP6XjiHQs8tgAB7X8"]
[Tue Jul 21 08:11:23.127793 2026] [security2:error] [pid 402041:tid 402170] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.powerflats.com.br"] [uri "/elmah.axd"] [unique_id "al9T24iENNLP6XjiHQs8uAABnH4"]
[Tue Jul 21 08:11:23.136920 2026] [security2:error] [pid 402041:tid 402053] [remote 34.146.29.21:44224] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "admin.powerflats.com.br"] [uri "/server-info"] [unique_id "al9T24iENNLP6XjiHQs8uwABugk"]
[Tue Jul 21 08:11:23.191059 2026] [access_compat:error] [pid 402041:tid 402050] [remote 34.146.29.21:44224] AH01797: client denied by server configuration: /home4/fabi0417/admin.powerflats.com.br/server-status
[Tue Jul 21 08:11:23.272619 2026] [security2:error] [pid 402041:tid 402178] [client 20.104.96.117:63385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9T24iENNLP6XjiHQs8ywAAAZQ"]
[Tue Jul 21 08:11:23.316429 2026] [security2:error] [pid 402041:tid 402249] [client 20.104.96.117:60105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/uoocf.php"] [unique_id "al9T24iENNLP6XjiHQs8zAAAAds"]
[Tue Jul 21 08:11:23.439609 2026] [security2:error] [pid 402041:tid 402241] [client 20.151.10.161:13289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/memberfuns.php"] [unique_id "al9T24iENNLP6XjiHQs81wAAAdM"]
[Tue Jul 21 08:11:23.671886 2026] [security2:error] [pid 402041:tid 402227] [client 87.116.180.198:27350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T24iENNLP6XjiHQs83wAAAcU"]
[Tue Jul 21 08:11:23.673345 2026] [security2:error] [pid 402041:tid 402227] [client 87.116.180.198:27350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T24iENNLP6XjiHQs83wAAAcU"]
[Tue Jul 21 08:11:23.770796 2026] [security2:error] [pid 402041:tid 402265] [client 20.104.96.117:54184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/iywwi.php"] [unique_id "al9T24iENNLP6XjiHQs85gAAAes"]
[Tue Jul 21 08:11:24.208678 2026] [security2:error] [pid 402041:tid 402219] [client 162.219.176.3:54206] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9T3IiENNLP6XjiHQs8-AAAAb0"]
[Tue Jul 21 08:11:24.208771 2026] [security2:error] [pid 402041:tid 402219] [client 162.219.176.3:54206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9T3IiENNLP6XjiHQs8-AAAAb0"]
[Tue Jul 21 08:11:24.224551 2026] [security2:error] [pid 402041:tid 402173] [client 198.54.129.60:53722] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9T24iENNLP6XjiHQs8xgAAAY8"]
[Tue Jul 21 08:11:24.224657 2026] [security2:error] [pid 402041:tid 402173] [client 198.54.129.60:53722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9T24iENNLP6XjiHQs8xgAAAY8"]
[Tue Jul 21 08:11:24.309639 2026] [security2:error] [pid 402041:tid 402267] [client 20.226.60.151:48881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/about.php"] [unique_id "al9T3IiENNLP6XjiHQs8_wAAAe0"]
[Tue Jul 21 08:11:24.396676 2026] [security2:error] [pid 402041:tid 402098] [remote 20.153.140.50:45982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "liranesuliano.com.br"] [uri "/wp-login.php"] [unique_id "al9T3IiENNLP6XjiHQs9BgABxjY"]
[Tue Jul 21 08:11:24.477449 2026] [security2:error] [pid 402041:tid 402101] [remote 104.207.48.107:60301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.48.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9T3IiENNLP6XjiHQs9CAAB0Dk"]
[Tue Jul 21 08:11:24.520678 2026] [security2:error] [pid 402041:tid 402206] [client 154.57.197.145:34266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.197.57.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T3IiENNLP6XjiHQs9CQAAAbA"]
[Tue Jul 21 08:11:24.520801 2026] [security2:error] [pid 402041:tid 402206] [client 154.57.197.145:34266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T3IiENNLP6XjiHQs9CQAAAbA"]
[Tue Jul 21 08:11:24.556960 2026] [security2:error] [pid 402041:tid 402097] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T3IiENNLP6XjiHQs9CgAB9DU"]
[Tue Jul 21 08:11:24.557121 2026] [security2:error] [pid 402041:tid 402274] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T3IiENNLP6XjiHQs9CgAB9DU"]
[Tue Jul 21 08:11:24.617838 2026] [security2:error] [pid 402041:tid 402199] [client 62.102.148.158:48302] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9T3IiENNLP6XjiHQs9DQAAAak"]
[Tue Jul 21 08:11:24.617998 2026] [security2:error] [pid 402041:tid 402199] [client 62.102.148.158:48302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9T3IiENNLP6XjiHQs9DQAAAak"]
[Tue Jul 21 08:11:24.703690 2026] [security2:error] [pid 402041:tid 402297] [client 20.226.60.151:48783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/admin.php"] [unique_id "al9T3IiENNLP6XjiHQs9EgAAAgs"]
[Tue Jul 21 08:11:24.728551 2026] [security2:error] [pid 402041:tid 402181] [client 20.151.10.161:13220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/ms.php"] [unique_id "al9T3IiENNLP6XjiHQs9EwAAAZc"]
[Tue Jul 21 08:11:24.756964 2026] [security2:error] [pid 402041:tid 402257] [client 38.100.221.102:18036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T3IiENNLP6XjiHQs9FwAAAeM"]
[Tue Jul 21 08:11:24.757060 2026] [security2:error] [pid 402041:tid 402257] [client 38.100.221.102:18036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T3IiENNLP6XjiHQs9FwAAAeM"]
[Tue Jul 21 08:11:24.776133 2026] [security2:error] [pid 402041:tid 402232] [client 154.208.47.43:41221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9T3IiENNLP6XjiHQs9GAAAAco"]
[Tue Jul 21 08:11:24.776222 2026] [security2:error] [pid 402041:tid 402232] [client 154.208.47.43:41221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9T3IiENNLP6XjiHQs9GAAAAco"]
[Tue Jul 21 08:11:24.831913 2026] [security2:error] [pid 402041:tid 402108] [remote 185.27.20.235:40966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.20.27.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9T3IiENNLP6XjiHQs9HgABpUA"]
[Tue Jul 21 08:11:24.832065 2026] [security2:error] [pid 402041:tid 402195] [client 185.27.20.235:40966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9T3IiENNLP6XjiHQs9HgABpUA"]
[Tue Jul 21 08:11:25.060820 2026] [security2:error] [pid 402041:tid 402293] [client 20.104.96.117:58419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/gqgsa.php"] [unique_id "al9T3YiENNLP6XjiHQs9JAAAAgc"]
[Tue Jul 21 08:11:25.295474 2026] [security2:error] [pid 402041:tid 402087] [remote 65.111.15.92:63235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9T3YiENNLP6XjiHQs9KQAB8Cs"]
[Tue Jul 21 08:11:25.394371 2026] [security2:error] [pid 402041:tid 402299] [client 31.57.219.92:20072] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "nextfitjourney.com"] [uri "/"] [unique_id "al9T3YiENNLP6XjiHQs9KwAAAg0"]
[Tue Jul 21 08:11:25.433262 2026] [security2:error] [pid 402041:tid 402259] [client 20.151.10.161:55814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/admin.php"] [unique_id "al9T3YiENNLP6XjiHQs9LwAAAeU"]
[Tue Jul 21 08:11:25.454937 2026] [security2:error] [pid 402041:tid 402254] [client 20.104.96.117:54703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/miru1.php"] [unique_id "al9T3YiENNLP6XjiHQs9MQAAAeA"]
[Tue Jul 21 08:11:25.567306 2026] [security2:error] [pid 402041:tid 402294] [client 20.151.10.161:13093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/zz.php"] [unique_id "al9T3YiENNLP6XjiHQs9OQAAAgg"]
[Tue Jul 21 08:11:25.601509 2026] [security2:error] [pid 402041:tid 402182] [client 20.226.60.151:48848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/admin.php"] [unique_id "al9T3YiENNLP6XjiHQs9OwAAAZg"]
[Tue Jul 21 08:11:25.860225 2026] [proxy:error] [pid 402041:tid 402124] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:11:25.860270 2026] [proxy_http:error] [pid 402041:tid 402124] [remote 74.7.241.160:48844] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:11:25.860982 2026] [proxy:error] [pid 402041:tid 402124] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:11:25.861010 2026] [proxy_http:error] [pid 402041:tid 402124] [remote 74.7.241.160:48844] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:11:25.939617 2026] [security2:error] [pid 402041:tid 402113] [remote 45.3.52.252:54739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9T3YiENNLP6XjiHQs9PQABxkU"]
[Tue Jul 21 08:11:25.983267 2026] [security2:error] [pid 402041:tid 402274] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T3YiENNLP6XjiHQs9NwAAAfQ"]
[Tue Jul 21 08:11:26.124517 2026] [security2:error] [pid 402041:tid 402290] [client 185.198.240.117:44825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "voweltravel.com.br"] [uri "/wp-login.php"] [unique_id "al9T3oiENNLP6XjiHQs9RQAAAgQ"]
[Tue Jul 21 08:11:26.291014 2026] [security2:error] [pid 402041:tid 402296] [client 20.104.96.117:62514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/h02ugyh.php"] [unique_id "al9T3oiENNLP6XjiHQs9TQAAAgo"]
[Tue Jul 21 08:11:26.310953 2026] [security2:error] [pid 402041:tid 402122] [remote 65.111.23.92:55359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9T3oiENNLP6XjiHQs9TwABpU4"]
[Tue Jul 21 08:11:26.318411 2026] [log_config:warn] [pid 400813:tid 400976] (32)Broken pipe: [client 186.159.137.69:46912] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:11:26.318426 2026] [log_config:warn] [pid 400813:tid 400976] (32)Broken pipe: [client 186.159.137.69:46912] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:11:26.364329 2026] [security2:error] [pid 402041:tid 402250] [client 20.151.10.161:13161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/for.php"] [unique_id "al9T3oiENNLP6XjiHQs9VQAAAdw"]
[Tue Jul 21 08:11:26.627043 2026] [security2:error] [pid 402041:tid 402245] [client 20.104.96.117:57954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/elbzl.php"] [unique_id "al9T3oiENNLP6XjiHQs9YAAAAdc"]
[Tue Jul 21 08:11:26.645557 2026] [autoindex:error] [pid 402041:tid 402280] [client 154.57.197.145:34268] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/ceramicasantoaugusto.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:11:26.686072 2026] [security2:error] [pid 402041:tid 402223] [client 20.104.96.117:63406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-temp.php"] [unique_id "al9T3oiENNLP6XjiHQs9YwAAAcE"]
[Tue Jul 21 08:11:26.920570 2026] [security2:error] [pid 402041:tid 402178] [client 62.102.148.158:58808] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9T3oiENNLP6XjiHQs9aQAAAZQ"]
[Tue Jul 21 08:11:26.920675 2026] [security2:error] [pid 402041:tid 402178] [client 62.102.148.158:58808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9T3oiENNLP6XjiHQs9aQAAAZQ"]
[Tue Jul 21 08:11:27.027937 2026] [security2:error] [pid 402041:tid 402140] [remote 65.111.10.116:59641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9T34iENNLP6XjiHQs9bgABmGA"]
[Tue Jul 21 08:11:27.114059 2026] [log_config:warn] [pid 358661:tid 358880] (32)Broken pipe: [client 143.0.191.106:26350] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:11:27.114080 2026] [log_config:warn] [pid 358661:tid 358880] (32)Broken pipe: [client 143.0.191.106:26350] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:11:27.197734 2026] [log_config:warn] [pid 358661:tid 358803] (32)Broken pipe: [client 180.253.108.123:52788] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:11:27.197749 2026] [log_config:warn] [pid 358661:tid 358803] (32)Broken pipe: [client 180.253.108.123:52788] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:11:27.246876 2026] [security2:error] [pid 402041:tid 402257] [client 154.57.197.145:34268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.197.57.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9T34iENNLP6XjiHQs9dAAAAeM"]
[Tue Jul 21 08:11:27.247001 2026] [security2:error] [pid 402041:tid 402257] [client 154.57.197.145:34268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9T34iENNLP6XjiHQs9dAAAAeM"]
[Tue Jul 21 08:11:27.300879 2026] [security2:error] [pid 402041:tid 402231] [client 20.151.10.161:13160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/yup.php"] [unique_id "al9T34iENNLP6XjiHQs9dgAAAck"]
[Tue Jul 21 08:11:27.442257 2026] [access_compat:error] [pid 402041:tid 402265] [client 34.146.29.21:0] AH01797: client denied by server configuration: /home4/fabi0417/powerflats.com.br/index.php4
[Tue Jul 21 08:11:27.455162 2026] [security2:error] [pid 402041:tid 402187] [client 20.197.192.193:57827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/wp-explorer.php"] [unique_id "al9T34iENNLP6XjiHQs9fQAAAZ0"]
[Tue Jul 21 08:11:27.505183 2026] [security2:error] [pid 402041:tid 402279] [client 20.226.60.151:48828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/themes.php"] [unique_id "al9T34iENNLP6XjiHQs9fwAAAfk"]
[Tue Jul 21 08:11:27.516505 2026] [security2:error] [pid 402041:tid 402148] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T34iENNLP6XjiHQs9gAAB8Wg"]
[Tue Jul 21 08:11:27.516657 2026] [security2:error] [pid 402041:tid 402271] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T34iENNLP6XjiHQs9gAAB8Wg"]
[Tue Jul 21 08:11:27.750763 2026] [security2:error] [pid 402041:tid 402235] [client 103.151.46.103:50962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T34iENNLP6XjiHQs9igAAAc0"]
[Tue Jul 21 08:11:27.750895 2026] [security2:error] [pid 402041:tid 402235] [client 103.151.46.103:50962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T34iENNLP6XjiHQs9igAAAc0"]
[Tue Jul 21 08:11:27.835485 2026] [security2:error] [pid 402041:tid 402292] [client 20.104.96.117:54194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/adjig.php"] [unique_id "al9T34iENNLP6XjiHQs9iwAAAgY"]
[Tue Jul 21 08:11:27.857772 2026] [security2:error] [pid 402041:tid 402209] [client 103.255.105.130:29797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9T34iENNLP6XjiHQs9hwAAAbM"]
[Tue Jul 21 08:11:27.857973 2026] [security2:error] [pid 402041:tid 402209] [client 103.255.105.130:29797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9T34iENNLP6XjiHQs9hwAAAbM"]
[Tue Jul 21 08:11:27.963949 2026] [security2:error] [pid 402041:tid 402270] [client 20.104.96.117:54080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/sump1.php"] [unique_id "al9T34iENNLP6XjiHQs9kwAAAfA"]
[Tue Jul 21 08:11:27.984852 2026] [security2:error] [pid 402041:tid 402205] [client 102.206.115.33:63987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T34iENNLP6XjiHQs9lgAAAa8"]
[Tue Jul 21 08:11:27.984978 2026] [security2:error] [pid 402041:tid 402205] [client 102.206.115.33:63987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T34iENNLP6XjiHQs9lgAAAa8"]
[Tue Jul 21 08:11:28.056861 2026] [security2:error] [pid 402041:tid 402254] [client 20.151.10.161:13286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/wpxml.php"] [unique_id "al9T4IiENNLP6XjiHQs9mQAAAeA"]
[Tue Jul 21 08:11:28.212192 2026] [security2:error] [pid 402041:tid 402262] [client 154.57.197.145:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.197.57.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9T4IiENNLP6XjiHQs9oQAAAeg"]
[Tue Jul 21 08:11:28.212307 2026] [security2:error] [pid 402041:tid 402262] [client 154.57.197.145:34270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9T4IiENNLP6XjiHQs9oQAAAeg"]
[Tue Jul 21 08:11:28.241980 2026] [security2:error] [pid 402041:tid 402227] [client 20.104.96.117:62497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9T4IiENNLP6XjiHQs9ogAAAcU"]
[Tue Jul 21 08:11:28.614726 2026] [security2:error] [pid 402041:tid 402281] [client 20.151.10.161:13303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/fffm.php"] [unique_id "al9T4IiENNLP6XjiHQs9rQAAAfs"]
[Tue Jul 21 08:11:28.773465 2026] [security2:error] [pid 402041:tid 402184] [client 20.104.96.117:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/byp.php"] [unique_id "al9T4IiENNLP6XjiHQs9tQAAAZo"]
[Tue Jul 21 08:11:28.781285 2026] [security2:error] [pid 402041:tid 402145] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9T4IiENNLP6XjiHQs9tgABtWU"]
[Tue Jul 21 08:11:28.781437 2026] [security2:error] [pid 402041:tid 402211] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9T4IiENNLP6XjiHQs9tgABtWU"]
[Tue Jul 21 08:11:28.876465 2026] [security2:error] [pid 402041:tid 402046] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/settings.json"] [unique_id "al9T4IiENNLP6XjiHQs9xAABywI"]
[Tue Jul 21 08:11:28.876624 2026] [security2:error] [pid 402041:tid 402233] [client 34.146.29.21:41658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "powerflats.com.br"] [uri "/settings.json"] [unique_id "al9T4IiENNLP6XjiHQs9xAABywI"]
[Tue Jul 21 08:11:28.992718 2026] [security2:error] [pid 402041:tid 402058] [remote 45.3.54.119:47785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9T4IiENNLP6XjiHQs90wABzQ4"]
[Tue Jul 21 08:11:29.479007 2026] [log_config:warn] [pid 352421:tid 352659] (32)Broken pipe: [client 170.238.178.125:48648] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:11:29.479026 2026] [log_config:warn] [pid 352421:tid 352659] (32)Broken pipe: [client 170.238.178.125:48648] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:11:29.662001 2026] [security2:error] [pid 402041:tid 402280] [client 120.56.162.40:52785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T4YiENNLP6XjiHQs99AAAAfo"]
[Tue Jul 21 08:11:29.662408 2026] [security2:error] [pid 402041:tid 402280] [client 120.56.162.40:52785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T4YiENNLP6XjiHQs99AAAAfo"]
[Tue Jul 21 08:11:29.711657 2026] [security2:error] [pid 402041:tid 402292] [client 20.104.96.117:57977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/ortasekerli1.php"] [unique_id "al9T4YiENNLP6XjiHQs99wAAAgY"]
[Tue Jul 21 08:11:29.869492 2026] [security2:error] [pid 402041:tid 402076] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/api/config"] [unique_id "al9T4YiENNLP6XjiHQs9-wAByCA"]
[Tue Jul 21 08:11:29.870024 2026] [security2:error] [pid 402041:tid 402230] [client 34.146.29.21:41658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "powerflats.com.br"] [uri "/api/config"] [unique_id "al9T4YiENNLP6XjiHQs9-wAByCA"]
[Tue Jul 21 08:11:29.886903 2026] [security2:error] [pid 402041:tid 402083] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "powerflats.com.br"] [uri "/graphql"] [unique_id "al9T4YiENNLP6XjiHQs9_QAByCc"]
[Tue Jul 21 08:11:29.896534 2026] [security2:error] [pid 402041:tid 402064] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "powerflats.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9T4YiENNLP6XjiHQs-CAAByBQ"]
[Tue Jul 21 08:11:29.903977 2026] [authz_core:error] [pid 402041:tid 402249] [client 34.146.29.21:0] AH01630: client denied by server configuration: /home4/fabi0417/powerflats.com.br/.htpasswd
[Tue Jul 21 08:11:29.926877 2026] [security2:error] [pid 402041:tid 402203] [client 20.151.10.161:13182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/gecko.php"] [unique_id "al9T4YiENNLP6XjiHQs-EgAAAa0"]
[Tue Jul 21 08:11:30.144084 2026] [security2:error] [pid 402041:tid 402094] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "powerflats.com.br"] [uri "/api/graphql"] [unique_id "al9T4oiENNLP6XjiHQs-GwAByDI"]
[Tue Jul 21 08:11:30.158962 2026] [security2:error] [pid 402041:tid 402059] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "powerflats.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9T4oiENNLP6XjiHQs-HgAByA8"]
[Tue Jul 21 08:11:30.255716 2026] [security2:error] [pid 402041:tid 402173] [client 151.63.71.144:49578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9T4oiENNLP6XjiHQs-KQAAAY8"]
[Tue Jul 21 08:11:30.255871 2026] [security2:error] [pid 402041:tid 402173] [client 151.63.71.144:49578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9T4oiENNLP6XjiHQs-KQAAAY8"]
[Tue Jul 21 08:11:30.348635 2026] [security2:error] [pid 402041:tid 402255] [client 150.129.202.39:65531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T4oiENNLP6XjiHQs-LAAAAeE"]
[Tue Jul 21 08:11:30.348822 2026] [security2:error] [pid 402041:tid 402255] [client 150.129.202.39:65531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T4oiENNLP6XjiHQs-LAAAAeE"]
[Tue Jul 21 08:11:30.401758 2026] [security2:error] [pid 402041:tid 402096] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "powerflats.com.br"] [uri "/v1/graphql"] [unique_id "al9T4oiENNLP6XjiHQs-LQAByDQ"]
[Tue Jul 21 08:11:30.433017 2026] [security2:error] [pid 402041:tid 402088] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/.ssh/id_dsa"] [unique_id "al9T4oiENNLP6XjiHQs-LgAByCw"]
[Tue Jul 21 08:11:30.445789 2026] [security2:error] [pid 402041:tid 402259] [client 20.151.10.161:55842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/greap.php"] [unique_id "al9T4oiENNLP6XjiHQs-LwAAAeU"]
[Tue Jul 21 08:11:30.446528 2026] [security2:error] [pid 402041:tid 402196] [client 65.21.113.253:59956] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T4oiENNLP6XjiHQs-KAAAAaY"]
[Tue Jul 21 08:11:30.540972 2026] [security2:error] [pid 402041:tid 402098] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T4oiENNLP6XjiHQs-MgAB1TY"]
[Tue Jul 21 08:11:30.541100 2026] [security2:error] [pid 402041:tid 402243] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T4oiENNLP6XjiHQs-MgAB1TY"]
[Tue Jul 21 08:11:30.580896 2026] [security2:error] [pid 402041:tid 402101] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9T4oiENNLP6XjiHQs-NQABkDk"]
[Tue Jul 21 08:11:30.581047 2026] [security2:error] [pid 402041:tid 402174] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9T4oiENNLP6XjiHQs-NQABkDk"]
[Tue Jul 21 08:11:30.592333 2026] [security2:error] [pid 402041:tid 402263] [client 187.125.243.197:54532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9T4oiENNLP6XjiHQs-NgAAAek"]
[Tue Jul 21 08:11:30.592439 2026] [security2:error] [pid 402041:tid 402263] [client 187.125.243.197:54532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9T4oiENNLP6XjiHQs-NgAAAek"]
[Tue Jul 21 08:11:30.676147 2026] [security2:error] [pid 402041:tid 402105] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/.gitlab-ci.yml"] [unique_id "al9T4oiENNLP6XjiHQs-PQABlj0"]
[Tue Jul 21 08:11:30.726075 2026] [security2:error] [pid 402041:tid 402108] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "powerflats.com.br"] [uri "/api/v1/config"] [unique_id "al9T4oiENNLP6XjiHQs-RwABlkA"]
[Tue Jul 21 08:11:30.889311 2026] [security2:error] [pid 402041:tid 402177] [client 20.220.225.223:30909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9T4oiENNLP6XjiHQs-XgAAAZM"]
[Tue Jul 21 08:11:30.974529 2026] [security2:error] [pid 402041:tid 402268] [client 20.151.10.161:13215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/a1.php"] [unique_id "al9T4oiENNLP6XjiHQs-ZgAAAe4"]
[Tue Jul 21 08:11:31.111397 2026] [security2:error] [pid 402041:tid 402293] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T4oiENNLP6XjiHQs-OwAAAgc"]
[Tue Jul 21 08:11:31.120479 2026] [security2:error] [pid 402041:tid 402197] [client 154.57.197.145:34274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.197.57.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "al9T44iENNLP6XjiHQs-bQAAAac"]
[Tue Jul 21 08:11:31.120560 2026] [security2:error] [pid 402041:tid 402197] [client 154.57.197.145:34274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "al9T44iENNLP6XjiHQs-bQAAAac"]
[Tue Jul 21 08:11:31.275912 2026] [security2:error] [pid 402041:tid 402181] [client 20.104.96.117:57945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/classwithtostring.php"] [unique_id "al9T44iENNLP6XjiHQs-dAAAAZc"]
[Tue Jul 21 08:11:31.317447 2026] [security2:error] [pid 402041:tid 402121] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9T44iENNLP6XjiHQs-dQAB_00"]
[Tue Jul 21 08:11:31.317774 2026] [security2:error] [pid 402041:tid 402285] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9T44iENNLP6XjiHQs-dQAB_00"]
[Tue Jul 21 08:11:31.360109 2026] [log_config:warn] [pid 400813:tid 400957] (32)Broken pipe: [client 37.215.37.28:8179] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:11:31.360132 2026] [log_config:warn] [pid 400813:tid 400957] (32)Broken pipe: [client 37.215.37.28:8179] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:11:31.579504 2026] [security2:error] [pid 402041:tid 402190] [client 20.104.96.117:54084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/file5.php"] [unique_id "al9T44iENNLP6XjiHQs-fQAAAaA"]
[Tue Jul 21 08:11:31.761764 2026] [security2:error] [pid 402041:tid 402281] [client 20.151.10.161:13209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/k2.php"] [unique_id "al9T44iENNLP6XjiHQs-hQAAAfs"]
[Tue Jul 21 08:11:32.087737 2026] [security2:error] [pid 402041:tid 402216] [client 109.60.28.94:63328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T5IiENNLP6XjiHQs-iQAAAbo"]
[Tue Jul 21 08:11:32.088377 2026] [security2:error] [pid 402041:tid 402216] [client 109.60.28.94:63328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T5IiENNLP6XjiHQs-iQAAAbo"]
[Tue Jul 21 08:11:32.199392 2026] [security2:error] [pid 402041:tid 402204] [client 20.104.96.117:58392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/root.php"] [unique_id "al9T5IiENNLP6XjiHQs-jgAAAa4"]
[Tue Jul 21 08:11:32.299721 2026] [security2:error] [pid 402041:tid 402135] [remote 45.79.123.44:39696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fisiopelvicafloripa.com.br"] [uri "/wp-login.php"] [unique_id "al9T5IiENNLP6XjiHQs-kwAB6Vs"]
[Tue Jul 21 08:11:32.328021 2026] [security2:error] [pid 402041:tid 402241] [client 20.151.10.161:13097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/82.php"] [unique_id "al9T5IiENNLP6XjiHQs-lAAAAdM"]
[Tue Jul 21 08:11:32.407076 2026] [autoindex:error] [pid 402041:tid 402295] [client 20.226.60.151:48828] AH01276: Cannot serve directory /home4/moadvo53/moadvogadas.com.br/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:11:32.412086 2026] [security2:error] [pid 402041:tid 402179] [client 154.57.197.145:34286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.197.57.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9T5IiENNLP6XjiHQs-lwAAAZU"]
[Tue Jul 21 08:11:32.412178 2026] [security2:error] [pid 402041:tid 402179] [client 154.57.197.145:34286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9T5IiENNLP6XjiHQs-lwAAAZU"]
[Tue Jul 21 08:11:32.736280 2026] [security2:error] [pid 402041:tid 402298] [client 20.151.10.161:50984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/177.php"] [unique_id "al9T5IiENNLP6XjiHQs-oQAAAgw"]
[Tue Jul 21 08:11:32.822993 2026] [security2:error] [pid 402041:tid 402141] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/ngsw.json"] [unique_id "al9T5IiENNLP6XjiHQs-pQAB8WE"]
[Tue Jul 21 08:11:32.971842 2026] [security2:error] [pid 402041:tid 402216] [client 20.151.10.161:13057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/config.json.php"] [unique_id "al9T5IiENNLP6XjiHQs-vQAAAbo"]
[Tue Jul 21 08:11:33.162178 2026] [security2:error] [pid 402041:tid 402162] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "powerflats.com.br"] [uri "/v1/graphql"] [unique_id "al9T5YiENNLP6XjiHQs-wAAB8XY"]
[Tue Jul 21 08:11:33.302598 2026] [security2:error] [pid 402041:tid 402167] [remote 104.207.39.171:35019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.39.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9T5YiENNLP6XjiHQs-xwABpHs"]
[Tue Jul 21 08:11:33.424171 2026] [security2:error] [pid 402041:tid 402175] [client 20.197.192.193:3182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/wp-explorer.php"] [unique_id "al9T5YiENNLP6XjiHQs-zAAAAZE"]
[Tue Jul 21 08:11:33.514507 2026] [security2:error] [pid 402041:tid 402213] [client 20.104.96.117:62485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9T5YiENNLP6XjiHQs-0AAAAbc"]
[Tue Jul 21 08:11:33.517719 2026] [security2:error] [pid 402041:tid 402296] [client 117.210.135.0:57163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T5YiENNLP6XjiHQs-0QAAAgo"]
[Tue Jul 21 08:11:33.517853 2026] [security2:error] [pid 402041:tid 402296] [client 117.210.135.0:57163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T5YiENNLP6XjiHQs-0QAAAgo"]
[Tue Jul 21 08:11:33.646057 2026] [security2:error] [pid 402041:tid 402160] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/phpinfo.php"] [unique_id "al9T5YiENNLP6XjiHQs-1AAB_HQ"]
[Tue Jul 21 08:11:33.653231 2026] [security2:error] [pid 402041:tid 402220] [client 20.151.10.161:13232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.ciclododinheiro.com"] [uri "/fpwch.php"] [unique_id "al9T5YiENNLP6XjiHQs-1QAAAb4"]
[Tue Jul 21 08:11:33.653522 2026] [security2:error] [pid 402041:tid 402242] [client 154.57.197.145:56612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.197.57.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9T5YiENNLP6XjiHQs-1gAAAdQ"]
[Tue Jul 21 08:11:33.653629 2026] [security2:error] [pid 402041:tid 402242] [client 154.57.197.145:56612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9T5YiENNLP6XjiHQs-1gAAAdQ"]
[Tue Jul 21 08:11:33.742393 2026] [security2:error] [pid 402041:tid 402139] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/actuator/configprops"] [unique_id "al9T5YiENNLP6XjiHQs-4wABlF8"]
[Tue Jul 21 08:11:33.742593 2026] [security2:error] [pid 402041:tid 402178] [client 34.146.29.21:41658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "powerflats.com.br"] [uri "/actuator/configprops"] [unique_id "al9T5YiENNLP6XjiHQs-4wABlF8"]
[Tue Jul 21 08:11:33.742690 2026] [security2:error] [pid 402041:tid 402058] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/info.php"] [unique_id "al9T5YiENNLP6XjiHQs-3gABlA4"]
[Tue Jul 21 08:11:33.742853 2026] [security2:error] [pid 402041:tid 402046] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/pi.php"] [unique_id "al9T5YiENNLP6XjiHQs-4QABlAI"]
[Tue Jul 21 08:11:33.743121 2026] [security2:error] [pid 402041:tid 402054] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/test.php"] [unique_id "al9T5YiENNLP6XjiHQs-5gABlAo"]
[Tue Jul 21 08:11:33.743591 2026] [security2:error] [pid 402041:tid 402051] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/id_dsa"] [unique_id "al9T5YiENNLP6XjiHQs-3wABlAc"]
[Tue Jul 21 08:11:33.744547 2026] [security2:error] [pid 402041:tid 402169] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/id_rsa"] [unique_id "al9T5YiENNLP6XjiHQs-5QABlH0"]
[Tue Jul 21 08:11:33.808602 2026] [security2:error] [pid 402041:tid 402045] [remote 72.167.132.114:40536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9T5YiENNLP6XjiHQs-8QACAAE"]
[Tue Jul 21 08:11:33.943854 2026] [security2:error] [pid 402041:tid 402152] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/server.key"] [unique_id "al9T5YiENNLP6XjiHQs--AABlGw"]
[Tue Jul 21 08:11:33.977644 2026] [security2:error] [pid 402041:tid 402055] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/i.php"] [unique_id "al9T5YiENNLP6XjiHQs--QABlAs"]
[Tue Jul 21 08:11:34.027558 2026] [security2:error] [pid 402041:tid 402056] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "powerflats.com.br"] [uri "/privatekey.key"] [unique_id "al9T5oiENNLP6XjiHQs-_wABlAw"]
[Tue Jul 21 08:11:34.029329 2026] [security2:error] [pid 402041:tid 402171] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/key.pem"] [unique_id "al9T5oiENNLP6XjiHQs-_AABlH8"]
[Tue Jul 21 08:11:34.229409 2026] [security2:error] [pid 402041:tid 402075] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/host.key"] [unique_id "al9T5oiENNLP6XjiHQs_DAABlB8"]
[Tue Jul 21 08:11:34.329976 2026] [security2:error] [pid 402041:tid 402246] [client 87.116.180.198:13888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T5oiENNLP6XjiHQs_FQAAAdg"]
[Tue Jul 21 08:11:34.335732 2026] [security2:error] [pid 402041:tid 402246] [client 87.116.180.198:13888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T5oiENNLP6XjiHQs_FQAAAdg"]
[Tue Jul 21 08:11:34.350598 2026] [security2:error] [pid 402041:tid 402076] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "powerflats.com.br"] [uri "/.openclaw/openclaw.json"] [unique_id "al9T5oiENNLP6XjiHQs_FwABlCA"]
[Tue Jul 21 08:11:34.534810 2026] [security2:error] [pid 402041:tid 402064] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/.openclaw/.env"] [unique_id "al9T5oiENNLP6XjiHQs_IwABlBQ"]
[Tue Jul 21 08:11:34.594058 2026] [security2:error] [pid 402041:tid 402084] [remote 68.178.160.25:54724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-login.php"] [unique_id "al9T5oiENNLP6XjiHQs_KgABzSg"]
[Tue Jul 21 08:11:34.665778 2026] [security2:error] [pid 402041:tid 402192] [client 20.104.96.117:57957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/sym403.php"] [unique_id "al9T5oiENNLP6XjiHQs_KwAAAaI"]
[Tue Jul 21 08:11:34.755608 2026] [security2:error] [pid 402041:tid 402060] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/.hermes/.env"] [unique_id "al9T5oiENNLP6XjiHQs_MAABlBA"]
[Tue Jul 21 08:11:34.755835 2026] [security2:error] [pid 402041:tid 402178] [client 34.146.29.21:41658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "powerflats.com.br"] [uri "/.hermes/.env"] [unique_id "al9T5oiENNLP6XjiHQs_MAABlBA"]
[Tue Jul 21 08:11:34.801750 2026] [security2:error] [pid 402041:tid 402077] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/laravel/.env"] [unique_id "al9T5oiENNLP6XjiHQs_OgABlCE"]
[Tue Jul 21 08:11:34.828955 2026] [security2:error] [pid 402041:tid 402088] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/.profile"] [unique_id "al9T5oiENNLP6XjiHQs_PgABlCw"]
[Tue Jul 21 08:11:34.858467 2026] [security2:error] [pid 402041:tid 402282] [client 154.57.197.145:56614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.197.57.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/main/xmlrpc.php"] [unique_id "al9T5oiENNLP6XjiHQs_QgAAAfw"]
[Tue Jul 21 08:11:34.858582 2026] [security2:error] [pid 402041:tid 402282] [client 154.57.197.145:56614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/main/xmlrpc.php"] [unique_id "al9T5oiENNLP6XjiHQs_QgAAAfw"]
[Tue Jul 21 08:11:34.960514 2026] [security2:error] [pid 402041:tid 402095] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/backend/.env"] [unique_id "al9T5oiENNLP6XjiHQs_RwABlDM"]
[Tue Jul 21 08:11:35.027602 2026] [security2:error] [pid 402041:tid 402085] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-admin/install.php"] [unique_id "al9T54iENNLP6XjiHQs_SQABnik"]
[Tue Jul 21 08:11:35.043275 2026] [security2:error] [pid 402041:tid 402093] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "powerflats.com.br"] [uri "/wp-config.php.bak"] [unique_id "al9T54iENNLP6XjiHQs_SgABlDE"]
[Tue Jul 21 08:11:35.139129 2026] [security2:error] [pid 402041:tid 402234] [client 61.1.167.83:63987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T54iENNLP6XjiHQs_UQAAAcw"]
[Tue Jul 21 08:11:35.139224 2026] [security2:error] [pid 402041:tid 402234] [client 61.1.167.83:63987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T54iENNLP6XjiHQs_UQAAAcw"]
[Tue Jul 21 08:11:35.195245 2026] [security2:error] [pid 402041:tid 402052] [remote 151.123.178.184:64575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.178.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9T54iENNLP6XjiHQs_SAAB-Qg"]
[Tue Jul 21 08:11:35.207084 2026] [security2:error] [pid 402041:tid 402099] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T54iENNLP6XjiHQs_VQABmTc"]
[Tue Jul 21 08:11:35.207238 2026] [security2:error] [pid 402041:tid 402183] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T54iENNLP6XjiHQs_VQABmTc"]
[Tue Jul 21 08:11:35.223329 2026] [security2:error] [pid 402041:tid 402111] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "denarios.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9T54iENNLP6XjiHQs_WAAByEM"]
[Tue Jul 21 08:11:35.234369 2026] [security2:error] [pid 402041:tid 402219] [client 20.104.96.117:54132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/0xD.php"] [unique_id "al9T54iENNLP6XjiHQs_WgAAAb0"]
[Tue Jul 21 08:11:35.326339 2026] [security2:error] [pid 402041:tid 402165] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "powerflats.com.br"] [uri "/wp-config.php.old"] [unique_id "al9T54iENNLP6XjiHQs_YgABlHk"]
[Tue Jul 21 08:11:35.326581 2026] [security2:error] [pid 402041:tid 402178] [client 34.146.29.21:41658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "powerflats.com.br"] [uri "/wp-config.php.old"] [unique_id "al9T54iENNLP6XjiHQs_YgABlHk"]
[Tue Jul 21 08:11:35.353380 2026] [security2:error] [pid 402041:tid 402292] [client 20.104.96.117:57962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/v543.php"] [unique_id "al9T54iENNLP6XjiHQs_YwAAAgY"]
[Tue Jul 21 08:11:35.402077 2026] [security2:error] [pid 402041:tid 402280] [client 198.54.129.60:56464] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9T54iENNLP6XjiHQs_ZQAAAfo"]
[Tue Jul 21 08:11:35.402258 2026] [security2:error] [pid 402041:tid 402280] [client 198.54.129.60:56464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9T54iENNLP6XjiHQs_ZQAAAfo"]
[Tue Jul 21 08:11:35.418294 2026] [security2:error] [pid 402041:tid 402182] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T5oiENNLP6XjiHQs_QwAAAZg"]
[Tue Jul 21 08:11:35.507228 2026] [security2:error] [pid 402041:tid 402201] [client 20.226.60.151:49370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/.well-known/about.php"] [unique_id "al9T54iENNLP6XjiHQs_ZwAAAas"]
[Tue Jul 21 08:11:35.635085 2026] [security2:error] [pid 402041:tid 402179] [client 20.151.10.161:55850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/199.php"] [unique_id "al9T54iENNLP6XjiHQs_bgAAAZU"]
[Tue Jul 21 08:11:35.818386 2026] [security2:error] [pid 402041:tid 402197] [client 103.78.200.11:62493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T54iENNLP6XjiHQs_dQAAAac"]
[Tue Jul 21 08:11:35.818502 2026] [security2:error] [pid 402041:tid 402197] [client 103.78.200.11:62493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T54iENNLP6XjiHQs_dQAAAac"]
[Tue Jul 21 08:11:35.831029 2026] [security2:error] [pid 402041:tid 402242] [client 154.57.197.145:56622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.197.57.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9T54iENNLP6XjiHQs_dwAAAdQ"]
[Tue Jul 21 08:11:35.831107 2026] [security2:error] [pid 402041:tid 402242] [client 154.57.197.145:56622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9T54iENNLP6XjiHQs_dwAAAdQ"]
[Tue Jul 21 08:11:36.058924 2026] [security2:error] [pid 402041:tid 402274] [client 20.104.96.117:58387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/sixxis.php"] [unique_id "al9T6IiENNLP6XjiHQs_gwAAAfQ"]
[Tue Jul 21 08:11:36.559639 2026] [security2:error] [pid 402041:tid 402129] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/.env.backup"] [unique_id "al9T6IiENNLP6XjiHQs_kgABvlU"]
[Tue Jul 21 08:11:36.576913 2026] [security2:error] [pid 402041:tid 402135] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "powerflats.com.br"] [uri "/.mcp.json"] [unique_id "al9T6IiENNLP6XjiHQs_lwABlVs"]
[Tue Jul 21 08:11:36.578683 2026] [security2:error] [pid 402041:tid 402061] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/.env.bak"] [unique_id "al9T6IiENNLP6XjiHQs_mAABlRE"]
[Tue Jul 21 08:11:36.580360 2026] [security2:error] [pid 402041:tid 402109] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/.env.old"] [unique_id "al9T6IiENNLP6XjiHQs_mQABlUE"]
[Tue Jul 21 08:11:36.582669 2026] [security2:error] [pid 402041:tid 402104] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "powerflats.com.br"] [uri "/admin/.env"] [unique_id "al9T6IiENNLP6XjiHQs_mgABlTw"]
[Tue Jul 21 08:11:36.585730 2026] [security2:error] [pid 402041:tid 402091] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/server-info"] [unique_id "al9T6IiENNLP6XjiHQs_mwABlS8"]
[Tue Jul 21 08:11:36.607991 2026] [security2:error] [pid 402041:tid 402048] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/api/.env"] [unique_id "al9T6IiENNLP6XjiHQs_nwABlQQ"]
[Tue Jul 21 08:11:36.614519 2026] [security2:error] [pid 402041:tid 402087] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "powerflats.com.br"] [uri "/server-status"] [unique_id "al9T6IiENNLP6XjiHQs_ogABlSs"]
[Tue Jul 21 08:11:36.792607 2026] [security2:error] [pid 402041:tid 402258] [client 154.57.197.145:56630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.197.57.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9T6IiENNLP6XjiHQs_pAAAAeQ"]
[Tue Jul 21 08:11:36.792715 2026] [security2:error] [pid 402041:tid 402258] [client 154.57.197.145:56630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9T6IiENNLP6XjiHQs_pAAAAeQ"]
[Tue Jul 21 08:11:36.811670 2026] [security2:error] [pid 402041:tid 402110] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "powerflats.com.br"] [uri "/elmah.axd"] [unique_id "al9T6IiENNLP6XjiHQs_pwABlUI"]
[Tue Jul 21 08:11:36.811720 2026] [security2:error] [pid 402041:tid 402092] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/configuration.php.bak"] [unique_id "al9T6IiENNLP6XjiHQs_pgABlTA"]
[Tue Jul 21 08:11:36.850005 2026] [security2:error] [pid 402041:tid 402278] [client 20.104.96.117:58395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/ip.php"] [unique_id "al9T6IiENNLP6XjiHQs_qAAAAfg"]
[Tue Jul 21 08:11:36.859721 2026] [security2:error] [pid 402041:tid 402102] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/config/.env.php"] [unique_id "al9T6IiENNLP6XjiHQs_qwABpDo"]
[Tue Jul 21 08:11:36.867354 2026] [security2:error] [pid 402041:tid 402131] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/core/.env"] [unique_id "al9T6IiENNLP6XjiHQs_rwAB9Fc"]
[Tue Jul 21 08:11:36.867516 2026] [security2:error] [pid 402041:tid 402274] [client 34.146.29.21:41658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "powerflats.com.br"] [uri "/core/.env"] [unique_id "al9T6IiENNLP6XjiHQs_rwAB9Fc"]
[Tue Jul 21 08:11:36.941633 2026] [security2:error] [pid 402041:tid 402162] [remote 97.74.93.24:54390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/wp-login.php"] [unique_id "al9T6IiENNLP6XjiHQs_tQABmHY"]
[Tue Jul 21 08:11:37.235717 2026] [security2:error] [pid 402041:tid 402149] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "powerflats.com.br"] [uri "/auth.json"] [unique_id "al9T6YiENNLP6XjiHQs_vQABv2k"]
[Tue Jul 21 08:11:37.302499 2026] [security2:error] [pid 402041:tid 402209] [client 20.104.96.117:54091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/fnstall.php"] [unique_id "al9T6YiENNLP6XjiHQs_vwAAAbM"]
[Tue Jul 21 08:11:37.344952 2026] [security2:error] [pid 402041:tid 402286] [client 38.100.221.102:17880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T6YiENNLP6XjiHQs_wAAAAgA"]
[Tue Jul 21 08:11:37.345086 2026] [security2:error] [pid 402041:tid 402286] [client 38.100.221.102:17880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T6YiENNLP6XjiHQs_wAAAAgA"]
[Tue Jul 21 08:11:37.362269 2026] [security2:error] [pid 402041:tid 402155] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/.env.php.bak"] [unique_id "al9T6YiENNLP6XjiHQs_wgAB9W8"]
[Tue Jul 21 08:11:37.371639 2026] [security2:error] [pid 402041:tid 402148] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/config.php.bak"] [unique_id "al9T6YiENNLP6XjiHQs_xQAB9Wg"]
[Tue Jul 21 08:11:37.371851 2026] [security2:error] [pid 402041:tid 402151] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/secrets.json"] [unique_id "al9T6YiENNLP6XjiHQs_xwAB9Ws"]
[Tue Jul 21 08:11:37.377837 2026] [security2:error] [pid 402041:tid 402127] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/web/.env"] [unique_id "al9T6YiENNLP6XjiHQs_zQAB9VM"]
[Tue Jul 21 08:11:37.385299 2026] [security2:error] [pid 402041:tid 402161] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/public/.env"] [unique_id "al9T6YiENNLP6XjiHQs_0QAB9XU"]
[Tue Jul 21 08:11:37.498349 2026] [security2:error] [pid 402041:tid 402160] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/config/.env"] [unique_id "al9T6YiENNLP6XjiHQs_1wAB9XQ"]
[Tue Jul 21 08:11:37.682110 2026] [security2:error] [pid 402041:tid 402051] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/.env.swp"] [unique_id "al9T6YiENNLP6XjiHQs_6QABuQc"]
[Tue Jul 21 08:11:37.848032 2026] [security2:error] [pid 402041:tid 402203] [client 20.226.60.151:48777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9T6YiENNLP6XjiHQs_8AAAAa0"]
[Tue Jul 21 08:11:37.925850 2026] [security2:error] [pid 402041:tid 402067] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "al9T6YiENNLP6XjiHQs_-gABuRc"]
[Tue Jul 21 08:11:38.011358 2026] [security2:error] [pid 402041:tid 402257] [client 154.57.197.145:56644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.197.57.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9T6oiENNLP6XjiHQtAAAAAAeM"]
[Tue Jul 21 08:11:38.011458 2026] [security2:error] [pid 402041:tid 402257] [client 154.57.197.145:56644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9T6oiENNLP6XjiHQtAAAAAAeM"]
[Tue Jul 21 08:11:38.055755 2026] [security2:error] [pid 402041:tid 402274] [client 20.104.96.117:58383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/kq1.php"] [unique_id "al9T6oiENNLP6XjiHQtAAgAAAfQ"]
[Tue Jul 21 08:11:38.073577 2026] [security2:error] [pid 402041:tid 402150] [remote 151.123.176.60:25033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.176.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9T6IiENNLP6XjiHQs_swABnGo"]
[Tue Jul 21 08:11:38.211944 2026] [security2:error] [pid 402041:tid 402066] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "powerflats.com.br"] [uri "/.env"] [unique_id "al9T6oiENNLP6XjiHQtABwABuRY"]
[Tue Jul 21 08:11:38.288997 2026] [security2:error] [pid 402041:tid 402050] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T6oiENNLP6XjiHQtACQABpQY"]
[Tue Jul 21 08:11:38.289229 2026] [security2:error] [pid 402041:tid 402195] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T6oiENNLP6XjiHQtACQABpQY"]
[Tue Jul 21 08:11:38.398322 2026] [security2:error] [pid 402041:tid 402189] [client 103.255.105.130:49342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9T6oiENNLP6XjiHQtACwAAAZ8"]
[Tue Jul 21 08:11:38.398770 2026] [security2:error] [pid 402041:tid 402189] [client 103.255.105.130:49342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9T6oiENNLP6XjiHQtACwAAAZ8"]
[Tue Jul 21 08:11:38.474848 2026] [security2:error] [pid 402041:tid 402064] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "powerflats.com.br"] [uri "/_ignition/health-check"] [unique_id "al9T6oiENNLP6XjiHQtAFgABuRQ"]
[Tue Jul 21 08:11:38.504496 2026] [security2:error] [pid 402041:tid 402259] [client 102.206.115.33:59244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T6oiENNLP6XjiHQtAFwAAAeU"]
[Tue Jul 21 08:11:38.504612 2026] [security2:error] [pid 402041:tid 402259] [client 102.206.115.33:59244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T6oiENNLP6XjiHQtAFwAAAeU"]
[Tue Jul 21 08:11:38.567077 2026] [security2:error] [pid 402041:tid 402068] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/app_dev.php"] [unique_id "al9T6oiENNLP6XjiHQtAGQAB2hg"]
[Tue Jul 21 08:11:38.593694 2026] [security2:error] [pid 402041:tid 402262] [client 20.151.10.161:51003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file52.php"] [unique_id "al9T6oiENNLP6XjiHQtAGwAAAeg"]
[Tue Jul 21 08:11:38.793925 2026] [security2:error] [pid 402041:tid 402275] [client 20.104.96.117:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/fw/faiyy.php"] [unique_id "al9T6oiENNLP6XjiHQtAKQAAAfU"]
[Tue Jul 21 08:11:38.815462 2026] [security2:error] [pid 402041:tid 402282] [client 151.63.71.144:50136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9T6oiENNLP6XjiHQtAKgAAAfw"]
[Tue Jul 21 08:11:38.815996 2026] [security2:error] [pid 402041:tid 402282] [client 151.63.71.144:50136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9T6oiENNLP6XjiHQtAKgAAAfw"]
[Tue Jul 21 08:11:38.851958 2026] [security2:error] [pid 402041:tid 402055] [remote 194.164.192.228:55994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9T6YiENNLP6XjiHQs_7wABtgs"]
[Tue Jul 21 08:11:38.999705 2026] [security2:error] [pid 402041:tid 402298] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T6oiENNLP6XjiHQtAGAAAAgw"]
[Tue Jul 21 08:11:39.017505 2026] [security2:error] [pid 402041:tid 402271] [client 20.104.96.117:63390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/jj.php"] [unique_id "al9T64iENNLP6XjiHQtALQAAAfE"]
[Tue Jul 21 08:11:39.059169 2026] [security2:error] [pid 402041:tid 402229] [client 20.197.192.193:61834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/akismet.php"] [unique_id "al9T64iENNLP6XjiHQtAMAAAAcc"]
[Tue Jul 21 08:11:39.286263 2026] [security2:error] [pid 402041:tid 402090] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9T64iENNLP6XjiHQtANwACBC4"]
[Tue Jul 21 08:11:39.286438 2026] [security2:error] [pid 402041:tid 402290] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9T64iENNLP6XjiHQtANwACBC4"]
[Tue Jul 21 08:11:39.457894 2026] [security2:error] [pid 402041:tid 402263] [client 20.104.96.117:54117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/acp.php"] [unique_id "al9T64iENNLP6XjiHQtAOwAAAek"]
[Tue Jul 21 08:11:39.523661 2026] [security2:error] [pid 402041:tid 402258] [client 154.57.197.145:56652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.197.57.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/wp-login.php"] [unique_id "al9T64iENNLP6XjiHQtAPgAAAeQ"]
[Tue Jul 21 08:11:39.640947 2026] [security2:error] [pid 402041:tid 402255] [client 20.151.10.161:51044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/122.php"] [unique_id "al9T64iENNLP6XjiHQtARQAAAeE"]
[Tue Jul 21 08:11:40.207423 2026] [security2:error] [pid 402041:tid 402285] [client 20.226.60.151:48813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wefile.php"] [unique_id "al9T7IiENNLP6XjiHQtAeAAAAf8"]
[Tue Jul 21 08:11:40.317886 2026] [security2:error] [pid 402041:tid 402223] [client 120.56.162.40:53284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T7IiENNLP6XjiHQtAgAAAAcE"]
[Tue Jul 21 08:11:40.318201 2026] [security2:error] [pid 402041:tid 402223] [client 120.56.162.40:53284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T7IiENNLP6XjiHQtAgAAAAcE"]
[Tue Jul 21 08:11:40.545331 2026] [security2:error] [pid 402041:tid 402257] [client 20.151.10.161:51057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/green1.php"] [unique_id "al9T7IiENNLP6XjiHQtAiwAAAeM"]
[Tue Jul 21 08:11:41.000872 2026] [security2:error] [pid 402041:tid 402251] [client 216.244.66.244:49804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nrfilmes.com"] [uri "/robots.txt"] [unique_id "al9T7YiENNLP6XjiHQtArgAAAd0"]
[Tue Jul 21 08:11:41.000971 2026] [security2:error] [pid 402041:tid 402251] [client 216.244.66.244:49804] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nrfilmes.com"] [uri "/robots.txt"] [unique_id "al9T7YiENNLP6XjiHQtArgAAAd0"]
[Tue Jul 21 08:11:41.022415 2026] [security2:error] [pid 402041:tid 402191] [client 150.129.202.39:12537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T7YiENNLP6XjiHQtAsgAAAaE"]
[Tue Jul 21 08:11:41.022571 2026] [security2:error] [pid 402041:tid 402191] [client 150.129.202.39:12537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T7YiENNLP6XjiHQtAsgAAAaE"]
[Tue Jul 21 08:11:41.042159 2026] [security2:error] [pid 402041:tid 402058] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T7YiENNLP6XjiHQtAtAACAA4"]
[Tue Jul 21 08:11:41.042335 2026] [security2:error] [pid 402041:tid 402286] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T7YiENNLP6XjiHQtAtAACAA4"]
[Tue Jul 21 08:11:41.137827 2026] [security2:error] [pid 402041:tid 402241] [client 20.104.96.117:54173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/h02ugyh.php"] [unique_id "al9T7YiENNLP6XjiHQtAuwAAAdM"]
[Tue Jul 21 08:11:41.138474 2026] [security2:error] [pid 402041:tid 402262] [client 187.125.243.197:54991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9T7YiENNLP6XjiHQtAvAAAAeg"]
[Tue Jul 21 08:11:41.138617 2026] [security2:error] [pid 402041:tid 402262] [client 187.125.243.197:54991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9T7YiENNLP6XjiHQtAvAAAAeg"]
[Tue Jul 21 08:11:41.236675 2026] [security2:error] [pid 402041:tid 402199] [client 20.197.192.193:2849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9T7YiENNLP6XjiHQtAvgAAAak"]
[Tue Jul 21 08:11:41.238969 2026] [security2:error] [pid 402041:tid 402271] [client 20.151.10.161:51019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/biufile.php"] [unique_id "al9T7YiENNLP6XjiHQtAvwAAAfE"]
[Tue Jul 21 08:11:41.470940 2026] [security2:error] [pid 402041:tid 402195] [client 20.197.192.193:2822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/dr.php"] [unique_id "al9T7YiENNLP6XjiHQtAzQAAAaU"]
[Tue Jul 21 08:11:41.488656 2026] [security2:error] [pid 402041:tid 402263] [client 20.226.60.151:49361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9T7YiENNLP6XjiHQtA0AAAAek"]
[Tue Jul 21 08:11:41.632629 2026] [security2:error] [pid 402041:tid 402080] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9T7YiENNLP6XjiHQtA1gABzCQ"]
[Tue Jul 21 08:11:41.632787 2026] [security2:error] [pid 402041:tid 402234] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9T7YiENNLP6XjiHQtA1gABzCQ"]
[Tue Jul 21 08:11:41.750568 2026] [security2:error] [pid 402041:tid 402292] [client 20.151.10.161:55859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wpconf.php"] [unique_id "al9T7YiENNLP6XjiHQtA4AAAAgY"]
[Tue Jul 21 08:11:41.884833 2026] [security2:error] [pid 402041:tid 402088] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9T7YiENNLP6XjiHQtA6AAB5iw"]
[Tue Jul 21 08:11:41.885022 2026] [security2:error] [pid 402041:tid 402260] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9T7YiENNLP6XjiHQtA6AAB5iw"]
[Tue Jul 21 08:11:41.913073 2026] [security2:error] [pid 402041:tid 402193] [client 20.197.192.193:2873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/2x.php"] [unique_id "al9T7YiENNLP6XjiHQtA6wAAAaM"]
[Tue Jul 21 08:11:42.124908 2026] [security2:error] [pid 402041:tid 402300] [client 20.197.192.193:2854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/kq1.php"] [unique_id "al9T7oiENNLP6XjiHQtA8QAAAg4"]
[Tue Jul 21 08:11:42.151907 2026] [security2:error] [pid 402041:tid 402183] [client 154.208.47.43:41663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9T7oiENNLP6XjiHQtA9gAAAZk"]
[Tue Jul 21 08:11:42.151989 2026] [security2:error] [pid 402041:tid 402183] [client 154.208.47.43:41663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9T7oiENNLP6XjiHQtA9gAAAZk"]
[Tue Jul 21 08:11:42.247853 2026] [security2:error] [pid 402041:tid 402252] [client 20.197.192.193:2792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/zzz.php"] [unique_id "al9T7oiENNLP6XjiHQtBAAAAAd4"]
[Tue Jul 21 08:11:42.260528 2026] [security2:error] [pid 402041:tid 402187] [client 20.104.96.117:54691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/mosty.php"] [unique_id "al9T7oiENNLP6XjiHQtBAQAAAZ0"]
[Tue Jul 21 08:11:42.327256 2026] [security2:error] [pid 402041:tid 402242] [client 20.151.10.161:50983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/mosty.php"] [unique_id "al9T7oiENNLP6XjiHQtBCAAAAdQ"]
[Tue Jul 21 08:11:42.453887 2026] [security2:error] [pid 402041:tid 402267] [client 20.197.192.193:2773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/wicked.php"] [unique_id "al9T7oiENNLP6XjiHQtBDwAAAe0"]
[Tue Jul 21 08:11:42.482718 2026] [security2:error] [pid 402041:tid 402296] [client 62.102.148.158:52284] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9T7oiENNLP6XjiHQtBEAAAAgo"]
[Tue Jul 21 08:11:42.482829 2026] [security2:error] [pid 402041:tid 402296] [client 62.102.148.158:52284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9T7oiENNLP6XjiHQtBEAAAAgo"]
[Tue Jul 21 08:11:42.520094 2026] [security2:error] [pid 402041:tid 402299] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T7oiENNLP6XjiHQtA8AAAAg0"]
[Tue Jul 21 08:11:42.619911 2026] [security2:error] [pid 402041:tid 402290] [client 20.197.192.193:2858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/edit.php"] [unique_id "al9T7oiENNLP6XjiHQtBEwAAAgQ"]
[Tue Jul 21 08:11:42.717281 2026] [security2:error] [pid 402041:tid 402281] [client 20.151.10.161:55840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/dejavu.php"] [unique_id "al9T7oiENNLP6XjiHQtBGAAAAfs"]
[Tue Jul 21 08:11:42.829284 2026] [security2:error] [pid 402041:tid 402255] [client 20.197.192.193:2839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/kua.php"] [unique_id "al9T7oiENNLP6XjiHQtBIAAAAeE"]
[Tue Jul 21 08:11:42.917398 2026] [security2:error] [pid 402041:tid 402227] [client 20.104.96.117:54172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-temp.php"] [unique_id "al9T7oiENNLP6XjiHQtBJAAAAcU"]
[Tue Jul 21 08:11:42.927400 2026] [security2:error] [pid 402041:tid 402125] [remote 176.31.139.16:48212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "s2bikeshopriopreto.com.br"] [uri "/robots.txt"] [unique_id "al9T7oiENNLP6XjiHQtBJgABllE"]
[Tue Jul 21 08:11:42.927627 2026] [security2:error] [pid 402041:tid 402180] [client 176.31.139.16:48212] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "s2bikeshopriopreto.com.br"] [uri "/robots.txt"] [unique_id "al9T7oiENNLP6XjiHQtBJgABllE"]
[Tue Jul 21 08:11:42.936964 2026] [security2:error] [pid 402041:tid 402247] [client 103.151.46.103:51415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T7oiENNLP6XjiHQtBKAAAAdk"]
[Tue Jul 21 08:11:42.938223 2026] [security2:error] [pid 402041:tid 402247] [client 103.151.46.103:51415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T7oiENNLP6XjiHQtBKAAAAdk"]
[Tue Jul 21 08:11:42.954655 2026] [security2:error] [pid 402041:tid 402287] [client 20.197.192.193:2397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/ez.php"] [unique_id "al9T7oiENNLP6XjiHQtBKgAAAgE"]
[Tue Jul 21 08:11:43.029116 2026] [security2:error] [pid 402041:tid 402261] [client 109.60.28.94:63792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.28.60.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T74iENNLP6XjiHQtBKwAAAec"]
[Tue Jul 21 08:11:43.029238 2026] [security2:error] [pid 402041:tid 402261] [client 109.60.28.94:63792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T74iENNLP6XjiHQtBKwAAAec"]
[Tue Jul 21 08:11:43.036599 2026] [security2:error] [pid 402041:tid 402191] [client 20.151.10.161:55924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/aaf.php"] [unique_id "al9T74iENNLP6XjiHQtBLAAAAaE"]
[Tue Jul 21 08:11:43.273418 2026] [security2:error] [pid 402041:tid 402216] [client 20.197.192.193:2790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/fz.php"] [unique_id "al9T74iENNLP6XjiHQtBMQAAAbo"]
[Tue Jul 21 08:11:43.424253 2026] [security2:error] [pid 402041:tid 402249] [client 20.197.192.193:2817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/la.php"] [unique_id "al9T74iENNLP6XjiHQtBNQAAAds"]
[Tue Jul 21 08:11:43.506022 2026] [security2:error] [pid 402041:tid 402265] [client 20.104.96.117:56871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9T74iENNLP6XjiHQtBOQAAAes"]
[Tue Jul 21 08:11:43.531703 2026] [security2:error] [pid 402041:tid 402200] [client 20.197.192.193:2853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9T74iENNLP6XjiHQtBPAAAAao"]
[Tue Jul 21 08:11:43.626116 2026] [security2:error] [pid 402041:tid 402290] [client 20.197.192.193:2863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/inso.php"] [unique_id "al9T74iENNLP6XjiHQtBQQAAAgQ"]
[Tue Jul 21 08:11:43.806753 2026] [security2:error] [pid 402041:tid 402225] [client 20.197.192.193:2830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/wpx.php"] [unique_id "al9T74iENNLP6XjiHQtBRgAAAcM"]
[Tue Jul 21 08:11:43.849478 2026] [security2:error] [pid 402041:tid 402184] [client 173.252.95.2:38486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9T74iENNLP6XjiHQtBSQAAAZo"]
[Tue Jul 21 08:11:43.904773 2026] [security2:error] [pid 402041:tid 402289] [client 20.104.96.117:54207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-content/cong.php"] [unique_id "al9T74iENNLP6XjiHQtBTQAAAgM"]
[Tue Jul 21 08:11:43.913084 2026] [security2:error] [pid 402041:tid 402215] [client 20.151.10.161:55844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/term.php"] [unique_id "al9T74iENNLP6XjiHQtBTgAAAbk"]
[Tue Jul 21 08:11:43.928509 2026] [security2:error] [pid 402041:tid 402228] [client 20.197.192.193:2768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/berlin.php"] [unique_id "al9T74iENNLP6XjiHQtBUAAAAcY"]
[Tue Jul 21 08:11:43.930791 2026] [security2:error] [pid 402041:tid 402193] [client 2.57.168.10:62261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.168.57.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9T74iENNLP6XjiHQtBTwAAAaM"]
[Tue Jul 21 08:11:43.977871 2026] [security2:error] [pid 402041:tid 402253] [client 103.78.200.11:62978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T74iENNLP6XjiHQtBUgAAAd8"]
[Tue Jul 21 08:11:43.981156 2026] [security2:error] [pid 402041:tid 402253] [client 103.78.200.11:62978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T74iENNLP6XjiHQtBUgAAAd8"]
[Tue Jul 21 08:11:44.108452 2026] [security2:error] [pid 402041:tid 402191] [client 45.3.42.26:36429] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "lojaracompressores.com.br"] [uri "/"] [unique_id "al9T8IiENNLP6XjiHQtBWQAAAaE"]
[Tue Jul 21 08:11:44.130037 2026] [security2:error] [pid 402041:tid 402251] [client 20.197.192.193:2852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/billur.php"] [unique_id "al9T8IiENNLP6XjiHQtBWgAAAd0"]
[Tue Jul 21 08:11:44.217465 2026] [security2:error] [pid 402041:tid 402190] [client 117.210.135.0:57827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T8IiENNLP6XjiHQtBYAAAAaA"]
[Tue Jul 21 08:11:44.218086 2026] [security2:error] [pid 402041:tid 402190] [client 117.210.135.0:57827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T8IiENNLP6XjiHQtBYAAAAaA"]
[Tue Jul 21 08:11:44.268756 2026] [security2:error] [pid 402041:tid 402248] [client 20.197.192.193:2827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/mimpi.php"] [unique_id "al9T8IiENNLP6XjiHQtBZQAAAdo"]
[Tue Jul 21 08:11:44.364305 2026] [security2:error] [pid 402041:tid 402257] [client 45.3.42.26:36429] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "lojaracompressores.com.br"] [uri "/"] [unique_id "al9T8IiENNLP6XjiHQtBaQAAAeM"]
[Tue Jul 21 08:11:44.417695 2026] [security2:error] [pid 402041:tid 402298] [client 20.197.192.193:2861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/dp.php"] [unique_id "al9T8IiENNLP6XjiHQtBagAAAgw"]
[Tue Jul 21 08:11:44.468610 2026] [security2:error] [pid 402041:tid 402165] [remote 54.39.203.234:25432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "s2bikeshopriopreto.com.br"] [uri "/"] [unique_id "al9T8IiENNLP6XjiHQtBbgABqnk"]
[Tue Jul 21 08:11:44.468741 2026] [security2:error] [pid 402041:tid 402200] [client 54.39.203.234:25432] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "s2bikeshopriopreto.com.br"] [uri "/"] [unique_id "al9T8IiENNLP6XjiHQtBbgABqnk"]
[Tue Jul 21 08:11:44.527223 2026] [security2:error] [pid 402041:tid 402211] [client 20.151.10.161:55820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ha.php"] [unique_id "al9T8IiENNLP6XjiHQtBcQAAAbU"]
[Tue Jul 21 08:11:44.579963 2026] [security2:error] [pid 402041:tid 402270] [client 20.197.192.193:2846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/bootstrap.php"] [unique_id "al9T8IiENNLP6XjiHQtBdQAAAfA"]
[Tue Jul 21 08:11:44.617747 2026] [security2:error] [pid 402041:tid 402262] [client 45.3.42.26:36429] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9T8IiENNLP6XjiHQtBdgAAAeg"]
[Tue Jul 21 08:11:44.650284 2026] [security2:error] [pid 402041:tid 402250] [client 20.197.192.193:2758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/wp-editor.php"] [unique_id "al9T8IiENNLP6XjiHQtBfAAAAdw"]
[Tue Jul 21 08:11:44.689216 2026] [security2:error] [pid 402041:tid 402267] [client 20.197.192.193:2787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/cro.php"] [unique_id "al9T8IiENNLP6XjiHQtBfgAAAe0"]
[Tue Jul 21 08:11:44.740415 2026] [security2:error] [pid 402041:tid 402209] [client 20.197.192.193:2783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/cron-tab.php"] [unique_id "al9T8IiENNLP6XjiHQtBgwAAAbM"]
[Tue Jul 21 08:11:44.782294 2026] [security2:error] [pid 402041:tid 402236] [client 20.104.96.117:63056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/6.php"] [unique_id "al9T8IiENNLP6XjiHQtBhgAAAc4"]
[Tue Jul 21 08:11:44.838906 2026] [security2:error] [pid 402041:tid 402259] [client 20.197.192.193:2775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/koiy.php"] [unique_id "al9T8IiENNLP6XjiHQtBiQAAAeU"]
[Tue Jul 21 08:11:44.907928 2026] [security2:error] [pid 402041:tid 402272] [client 20.151.10.161:55832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/hur.php"] [unique_id "al9T8IiENNLP6XjiHQtBjgAAAfI"]
[Tue Jul 21 08:11:44.963518 2026] [security2:error] [pid 402041:tid 402220] [client 20.197.192.193:2832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/hp2.php"] [unique_id "al9T8IiENNLP6XjiHQtBkAAAAb4"]
[Tue Jul 21 08:11:45.055555 2026] [security2:error] [pid 402041:tid 402299] [client 87.116.180.198:14077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T8YiENNLP6XjiHQtBlwAAAg0"]
[Tue Jul 21 08:11:45.055644 2026] [security2:error] [pid 402041:tid 402299] [client 87.116.180.198:14077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T8YiENNLP6XjiHQtBlwAAAg0"]
[Tue Jul 21 08:11:45.094035 2026] [security2:error] [pid 402041:tid 402210] [client 20.197.192.193:2824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/hp3.php"] [unique_id "al9T8YiENNLP6XjiHQtBmQAAAbQ"]
[Tue Jul 21 08:11:45.106841 2026] [security2:error] [pid 402041:tid 402216] [client 198.54.129.60:53890] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9T8YiENNLP6XjiHQtBmgAAAbo"]
[Tue Jul 21 08:11:45.106985 2026] [security2:error] [pid 402041:tid 402216] [client 198.54.129.60:53890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9T8YiENNLP6XjiHQtBmgAAAbo"]
[Tue Jul 21 08:11:45.168958 2026] [security2:error] [pid 402041:tid 402192] [client 20.197.192.193:2850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/aa1.php"] [unique_id "al9T8YiENNLP6XjiHQtBnAAAAaI"]
[Tue Jul 21 08:11:45.270118 2026] [security2:error] [pid 402041:tid 402265] [client 20.197.192.193:2788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/acew67.php"] [unique_id "al9T8YiENNLP6XjiHQtBoQAAAes"]
[Tue Jul 21 08:11:45.391491 2026] [security2:error] [pid 402041:tid 402182] [client 74.7.175.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "andreiapereiradossan1782652807342.0721679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9T8YiENNLP6XjiHQtBogABmGQ"]
[Tue Jul 21 08:11:45.396018 2026] [security2:error] [pid 402041:tid 402230] [client 20.151.10.161:55824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/h02ugyh.php"] [unique_id "al9T8YiENNLP6XjiHQtBpAAAAcg"]
[Tue Jul 21 08:11:45.436917 2026] [security2:error] [pid 402041:tid 402279] [client 20.197.192.193:2759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/bscclapb.php"] [unique_id "al9T8YiENNLP6XjiHQtBpwAAAfk"]
[Tue Jul 21 08:11:45.503168 2026] [security2:error] [pid 402041:tid 402262] [client 20.197.192.193:2876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/else1.php"] [unique_id "al9T8YiENNLP6XjiHQtBqwAAAeg"]
[Tue Jul 21 08:11:45.561860 2026] [security2:error] [pid 402041:tid 402284] [client 34.24.57.82:52689] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nrfilmes.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9T8YiENNLP6XjiHQtBrQAAAf4"]
[Tue Jul 21 08:11:45.608580 2026] [security2:error] [pid 402041:tid 402184] [client 20.197.192.193:2410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/tkikikoko.php"] [unique_id "al9T8YiENNLP6XjiHQtBrwAAAZo"]
[Tue Jul 21 08:11:45.731490 2026] [security2:error] [pid 402041:tid 402159] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T8YiENNLP6XjiHQtBsgABuXM"]
[Tue Jul 21 08:11:45.731719 2026] [security2:error] [pid 402041:tid 402215] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T8YiENNLP6XjiHQtBsgABuXM"]
[Tue Jul 21 08:11:45.800964 2026] [security2:error] [pid 402041:tid 402252] [client 38.100.221.102:18324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T8YiENNLP6XjiHQtBxgAAAd4"]
[Tue Jul 21 08:11:45.801113 2026] [security2:error] [pid 402041:tid 402252] [client 38.100.221.102:18324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T8YiENNLP6XjiHQtBxgAAAd4"]
[Tue Jul 21 08:11:45.987979 2026] [security2:error] [pid 402041:tid 402280] [client 20.151.10.161:55911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/seiso.php"] [unique_id "al9T8YiENNLP6XjiHQtBzAAAAfo"]
[Tue Jul 21 08:11:46.013529 2026] [security2:error] [pid 402041:tid 402194] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T8YiENNLP6XjiHQtBrAAAAaQ"]
[Tue Jul 21 08:11:46.107249 2026] [security2:error] [pid 402041:tid 402192] [client 20.197.192.193:2821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9T8oiENNLP6XjiHQtB0wAAAaI"]
[Tue Jul 21 08:11:46.212456 2026] [autoindex:error] [pid 402041:tid 402300] [client 20.226.60.151:48800] AH01276: Cannot serve directory /home4/moadvo53/moadvogadas.com.br/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:11:46.283460 2026] [autoindex:error] [pid 402041:tid 402249] [client 20.226.60.151:48800] AH01276: Cannot serve directory /home4/moadvo53/moadvogadas.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:11:46.288858 2026] [security2:error] [pid 402041:tid 402271] [client 20.226.60.151:49354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9T8oiENNLP6XjiHQtB3QAAAfE"]
[Tue Jul 21 08:11:46.316888 2026] [security2:error] [pid 402041:tid 402182] [client 20.104.96.117:58372] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-admin/js/widget/"] [unique_id "al9T8oiENNLP6XjiHQtB3wAAAZg"]
[Tue Jul 21 08:11:46.393205 2026] [security2:error] [pid 402041:tid 402257] [client 34.24.57.82:52123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.24.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/xmlrpc.php"] [unique_id "al9T8oiENNLP6XjiHQtB4wAAAeM"]
[Tue Jul 21 08:11:46.642966 2026] [security2:error] [pid 402041:tid 402226] [client 20.197.192.193:2879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/wp-css.php"] [unique_id "al9T8oiENNLP6XjiHQtB8wAAAcQ"]
[Tue Jul 21 08:11:46.789353 2026] [security2:error] [pid 402041:tid 402260] [client 20.151.10.161:51064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/155.php"] [unique_id "al9T8oiENNLP6XjiHQtB9wAAAeY"]
[Tue Jul 21 08:11:46.964515 2026] [access_compat:error] [pid 402041:tid 402064] [remote 34.146.29.21:41658] AH01797: client denied by server configuration: /home4/fabi0417/powerflats.com.br/wp-admin/index.php4, referer: https://powerflats.com.br/admin
[Tue Jul 21 08:11:46.966304 2026] [access_compat:error] [pid 402041:tid 402072] [remote 34.146.29.21:41658] AH01797: client denied by server configuration: /home4/fabi0417/powerflats.com.br/wp-admin/index.php4, referer: https://powerflats.com.br/dashboard
[Tue Jul 21 08:11:47.018262 2026] [security2:error] [pid 402041:tid 402243] [client 20.197.192.193:2778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/wp-explorer.php"] [unique_id "al9T84iENNLP6XjiHQtCCAAAAdU"]
[Tue Jul 21 08:11:47.079958 2026] [security2:error] [pid 402041:tid 402178] [client 20.104.96.117:63072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9T84iENNLP6XjiHQtCDgAAAZQ"]
[Tue Jul 21 08:11:47.139582 2026] [security2:error] [pid 402041:tid 402299] [client 173.252.95.25:43354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9T84iENNLP6XjiHQtCEQAAAg0"]
[Tue Jul 21 08:11:47.142209 2026] [security2:error] [pid 402041:tid 402295] [client 45.3.42.26:17541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojaracompressores.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T8YiENNLP6XjiHQtBmwAAAgk"]
[Tue Jul 21 08:11:47.158368 2026] [security2:error] [pid 402041:tid 402201] [client 20.151.10.161:50987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ppp.php"] [unique_id "al9T84iENNLP6XjiHQtCEgAAAas"]
[Tue Jul 21 08:11:47.245824 2026] [security2:error] [pid 402041:tid 402219] [client 154.208.47.43:42132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9T84iENNLP6XjiHQtCFQAAAb0"]
[Tue Jul 21 08:11:47.245947 2026] [security2:error] [pid 402041:tid 402219] [client 154.208.47.43:42132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9T84iENNLP6XjiHQtCFQAAAb0"]
[Tue Jul 21 08:11:47.250145 2026] [security2:error] [pid 402041:tid 402249] [client 20.197.192.193:2842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/akismet.php"] [unique_id "al9T84iENNLP6XjiHQtCFgAAAds"]
[Tue Jul 21 08:11:47.346602 2026] [security2:error] [pid 402041:tid 402214] [client 20.104.96.117:54150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9T84iENNLP6XjiHQtCGQAAAbg"]
[Tue Jul 21 08:11:47.527556 2026] [security2:error] [pid 402041:tid 402084] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/wp-login.php"] [unique_id "al9T84iENNLP6XjiHQtCGgAB6Sg"], referer: https://powerflats.com.br/login
[Tue Jul 21 08:11:47.548418 2026] [security2:error] [pid 402041:tid 402239] [client 20.197.192.193:2784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/ace2.php"] [unique_id "al9T84iENNLP6XjiHQtCJAAAAdE"]
[Tue Jul 21 08:11:47.643112 2026] [security2:error] [pid 402041:tid 402049] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/wp-login.php"] [unique_id "al9T84iENNLP6XjiHQtCKQABxgU"], referer: https://powerflats.com.br/wp-admin/
[Tue Jul 21 08:11:47.643202 2026] [security2:error] [pid 402041:tid 402138] [remote 34.146.29.21:41658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.29.146.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/wp-login.php"] [unique_id "al9T84iENNLP6XjiHQtCKAABxl4"], referer: https://powerflats.com.br/wp-admin/
[Tue Jul 21 08:11:47.663851 2026] [security2:error] [pid 402041:tid 402230] [client 45.3.42.26:53461] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "lojaracompressores.com.br"] [uri "/"] [unique_id "al9T84iENNLP6XjiHQtCKgAAAcg"]
[Tue Jul 21 08:11:47.666405 2026] [security2:error] [pid 402041:tid 402088] [remote 85.208.96.208:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "androapkmod.com"] [uri "/dragon-elfs-apk-mod/"] [unique_id "al9T84iENNLP6XjiHQtCLAACACw"]
[Tue Jul 21 08:11:47.666513 2026] [security2:error] [pid 402041:tid 402286] [client 85.208.96.208:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "androapkmod.com"] [uri "/dragon-elfs-apk-mod/"] [unique_id "al9T84iENNLP6XjiHQtCLAACACw"]
[Tue Jul 21 08:11:47.666770 2026] [security2:error] [pid 402041:tid 402267] [client 20.197.192.193:2779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/ms.php"] [unique_id "al9T84iENNLP6XjiHQtCLQAAAe0"]
[Tue Jul 21 08:11:47.762231 2026] [security2:error] [pid 402041:tid 402191] [client 20.104.96.117:62549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/txets.php"] [unique_id "al9T84iENNLP6XjiHQtCMAAAAaE"]
[Tue Jul 21 08:11:47.900568 2026] [security2:error] [pid 402041:tid 402220] [client 20.151.10.161:55817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/201.php"] [unique_id "al9T84iENNLP6XjiHQtCNgAAAb4"]
[Tue Jul 21 08:11:47.930348 2026] [security2:error] [pid 402041:tid 402243] [client 45.3.42.26:53461] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9T84iENNLP6XjiHQtCNwAAAdU"]
[Tue Jul 21 08:11:48.273302 2026] [security2:error] [pid 402041:tid 402173] [client 20.151.10.161:50952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ops.php"] [unique_id "al9T9IiENNLP6XjiHQtCQAAAAY8"]
[Tue Jul 21 08:11:48.316998 2026] [security2:error] [pid 402041:tid 402293] [client 61.1.167.83:64490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T9IiENNLP6XjiHQtCQQAAAgc"]
[Tue Jul 21 08:11:48.317107 2026] [security2:error] [pid 402041:tid 402293] [client 61.1.167.83:64490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T9IiENNLP6XjiHQtCQQAAAgc"]
[Tue Jul 21 08:11:48.336502 2026] [security2:error] [pid 402041:tid 402273] [client 20.226.60.151:49240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/8.php"] [unique_id "al9T9IiENNLP6XjiHQtCQwAAAfM"]
[Tue Jul 21 08:11:48.461765 2026] [security2:error] [pid 402041:tid 402196] [client 45.3.42.26:10243] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9T9IiENNLP6XjiHQtCSgAAAaY"]
[Tue Jul 21 08:11:48.469412 2026] [security2:error] [pid 402041:tid 402178] [client 151.63.71.144:50676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9T9IiENNLP6XjiHQtCTAAAAZQ"]
[Tue Jul 21 08:11:48.469550 2026] [security2:error] [pid 402041:tid 402178] [client 151.63.71.144:50676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9T9IiENNLP6XjiHQtCTAAAAZQ"]
[Tue Jul 21 08:11:48.562609 2026] [security2:error] [pid 402041:tid 402212] [client 20.104.96.117:58415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/jj.php"] [unique_id "al9T9IiENNLP6XjiHQtCTQAAAbY"]
[Tue Jul 21 08:11:48.655835 2026] [security2:error] [pid 402041:tid 402180] [client 20.151.10.161:51009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ingfo.php"] [unique_id "al9T9IiENNLP6XjiHQtCUgAAAZY"]
[Tue Jul 21 08:11:49.002470 2026] [security2:error] [pid 402041:tid 402262] [client 45.3.42.26:36031] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9T9YiENNLP6XjiHQtCXQAAAeg"]
[Tue Jul 21 08:11:49.068635 2026] [security2:error] [pid 402041:tid 402265] [client 102.206.115.33:64271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T9YiENNLP6XjiHQtCXgAAAes"]
[Tue Jul 21 08:11:49.068772 2026] [security2:error] [pid 402041:tid 402265] [client 102.206.115.33:64271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T9YiENNLP6XjiHQtCXgAAAes"]
[Tue Jul 21 08:11:49.069795 2026] [security2:error] [pid 402041:tid 402295] [client 103.255.105.130:62150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9T9YiENNLP6XjiHQtCXwAAAgk"]
[Tue Jul 21 08:11:49.069930 2026] [security2:error] [pid 402041:tid 402295] [client 103.255.105.130:62150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9T9YiENNLP6XjiHQtCXwAAAgk"]
[Tue Jul 21 08:11:49.204484 2026] [security2:error] [pid 402041:tid 402276] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T9IiENNLP6XjiHQtCWAAAAfY"]
[Tue Jul 21 08:11:49.279795 2026] [security2:error] [pid 402041:tid 402260] [client 46.37.124.20:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.brunocesarribeiro1782216213881.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/api/.env"] [unique_id "al9T9YiENNLP6XjiHQtCZgAAAeY"]
[Tue Jul 21 08:11:49.502654 2026] [security2:error] [pid 402041:tid 402114] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T9YiENNLP6XjiHQtCcQAB-0Y"]
[Tue Jul 21 08:11:49.502804 2026] [security2:error] [pid 402041:tid 402281] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T9YiENNLP6XjiHQtCcQAB-0Y"]
[Tue Jul 21 08:11:49.510191 2026] [security2:error] [pid 402041:tid 402274] [client 45.3.42.26:18763] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9T9YiENNLP6XjiHQtCcgAAAfQ"]
[Tue Jul 21 08:11:49.580318 2026] [security2:error] [pid 402041:tid 402183] [client 20.104.96.117:58408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9T9YiENNLP6XjiHQtCcwAAAZk"]
[Tue Jul 21 08:11:49.641552 2026] [security2:error] [pid 402041:tid 402233] [client 46.37.124.20:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.brunocesarribeiro1782216213881.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/backend/.env"] [unique_id "al9T9YiENNLP6XjiHQtCeAAAAcs"]
[Tue Jul 21 08:11:49.642949 2026] [security2:error] [pid 402041:tid 402196] [client 46.37.124.20:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.brunocesarribeiro1782216213881.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al9T9YiENNLP6XjiHQtCfgAAAaY"]
[Tue Jul 21 08:11:49.663059 2026] [security2:error] [pid 402041:tid 402182] [client 20.104.96.117:54688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/qqqa.php"] [unique_id "al9T9YiENNLP6XjiHQtCiAAAAZg"]
[Tue Jul 21 08:11:49.774718 2026] [security2:error] [pid 402041:tid 402294] [client 20.151.10.161:55865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/error_log.php"] [unique_id "al9T9YiENNLP6XjiHQtCkQAAAgg"]
[Tue Jul 21 08:11:49.819372 2026] [security2:error] [pid 402041:tid 402122] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9T9YiENNLP6XjiHQtClAAB2U4"]
[Tue Jul 21 08:11:49.819523 2026] [security2:error] [pid 402041:tid 402247] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9T9YiENNLP6XjiHQtClAAB2U4"]
[Tue Jul 21 08:11:50.031623 2026] [security2:error] [pid 402041:tid 402226] [client 45.3.42.26:58145] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9T9oiENNLP6XjiHQtCoAAAAcQ"]
[Tue Jul 21 08:11:50.065950 2026] [security2:error] [pid 402041:tid 402213] [client 34.24.57.82:54018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.24.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nrfilmes.com"] [uri "/xmlrpc.php"] [unique_id "al9T9oiENNLP6XjiHQtCoQAAAbc"]
[Tue Jul 21 08:11:50.066050 2026] [security2:error] [pid 402041:tid 402213] [client 34.24.57.82:54018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nrfilmes.com"] [uri "/xmlrpc.php"] [unique_id "al9T9oiENNLP6XjiHQtCoQAAAbc"]
[Tue Jul 21 08:11:50.126048 2026] [security2:error] [pid 402041:tid 402227] [client 20.226.60.151:48795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9T9oiENNLP6XjiHQtCogAAAcU"]
[Tue Jul 21 08:11:50.192991 2026] [security2:error] [pid 402041:tid 402267] [client 20.104.96.117:58401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/txets.php"] [unique_id "al9T9oiENNLP6XjiHQtCqAAAAe0"]
[Tue Jul 21 08:11:50.238026 2026] [security2:error] [pid 402041:tid 402181] [client 20.104.96.117:62467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/dex.php"] [unique_id "al9T9oiENNLP6XjiHQtCqQAAAZc"]
[Tue Jul 21 08:11:50.527022 2026] [security2:error] [pid 402041:tid 402220] [client 20.104.96.117:54103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/aunmc.php"] [unique_id "al9T9oiENNLP6XjiHQtCrwAAAb4"]
[Tue Jul 21 08:11:50.536330 2026] [security2:error] [pid 402041:tid 402190] [client 45.3.42.26:9019] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9T9oiENNLP6XjiHQtCsAAAAaA"]
[Tue Jul 21 08:11:50.567998 2026] [security2:error] [pid 402041:tid 402300] [client 103.151.46.103:51906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T9oiENNLP6XjiHQtCtAAAAg4"]
[Tue Jul 21 08:11:50.568804 2026] [security2:error] [pid 402041:tid 402300] [client 103.151.46.103:51906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T9oiENNLP6XjiHQtCtAAAAg4"]
[Tue Jul 21 08:11:50.599183 2026] [security2:error] [pid 402041:tid 402295] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T9oiENNLP6XjiHQtCpwAAAgk"]
[Tue Jul 21 08:11:51.048143 2026] [security2:error] [pid 402041:tid 402242] [client 45.3.42.26:51187] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9T94iENNLP6XjiHQtCxAAAAdQ"]
[Tue Jul 21 08:11:51.082169 2026] [security2:error] [pid 402041:tid 402202] [client 120.56.162.40:53780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T94iENNLP6XjiHQtCxgAAAaw"]
[Tue Jul 21 08:11:51.082326 2026] [security2:error] [pid 402041:tid 402202] [client 120.56.162.40:53780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T94iENNLP6XjiHQtCxgAAAaw"]
[Tue Jul 21 08:11:51.373833 2026] [security2:error] [pid 402041:tid 402249] [client 20.104.96.117:54141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/uoocf.php"] [unique_id "al9T94iENNLP6XjiHQtC1QAAAds"]
[Tue Jul 21 08:11:51.550520 2026] [security2:error] [pid 402041:tid 402137] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T94iENNLP6XjiHQtC3wAB_10"]
[Tue Jul 21 08:11:51.550749 2026] [security2:error] [pid 402041:tid 402285] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T94iENNLP6XjiHQtC3wAB_10"]
[Tue Jul 21 08:11:51.556946 2026] [security2:error] [pid 402041:tid 402217] [client 45.3.42.26:53653] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9T94iENNLP6XjiHQtC4QAAAbs"]
[Tue Jul 21 08:11:51.606386 2026] [security2:error] [pid 402041:tid 402214] [client 150.129.202.39:65149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T94iENNLP6XjiHQtC4wAAAbg"]
[Tue Jul 21 08:11:51.606466 2026] [security2:error] [pid 402041:tid 402214] [client 150.129.202.39:65149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T94iENNLP6XjiHQtC4wAAAbg"]
[Tue Jul 21 08:11:51.613977 2026] [security2:error] [pid 402041:tid 402276] [client 20.104.96.117:57935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/dex.php"] [unique_id "al9T94iENNLP6XjiHQtC5AAAAfY"]
[Tue Jul 21 08:11:51.616871 2026] [security2:error] [pid 402041:tid 402177] [client 187.125.243.197:55430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9T94iENNLP6XjiHQtC5QAAAZM"]
[Tue Jul 21 08:11:51.617010 2026] [security2:error] [pid 402041:tid 402177] [client 187.125.243.197:55430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9T94iENNLP6XjiHQtC5QAAAZM"]
[Tue Jul 21 08:11:51.656930 2026] [security2:error] [pid 402041:tid 402284] [client 51.68.111.205:34623] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.volyoaudiobooks.com"] [uri "/robots.txt"] [unique_id "al9T94iENNLP6XjiHQtC5wAAAf4"]
[Tue Jul 21 08:11:51.657002 2026] [security2:error] [pid 402041:tid 402284] [client 51.68.111.205:34623] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.volyoaudiobooks.com"] [uri "/robots.txt"] [unique_id "al9T94iENNLP6XjiHQtC5wAAAf4"]
[Tue Jul 21 08:11:52.068605 2026] [security2:error] [pid 402041:tid 402290] [client 45.3.42.26:20077] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9T-IiENNLP6XjiHQtC-QAAAgQ"]
[Tue Jul 21 08:11:52.083519 2026] [security2:error] [pid 402041:tid 402207] [client 62.102.148.158:45094] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9T-IiENNLP6XjiHQtC-gAAAbE"]
[Tue Jul 21 08:11:52.083630 2026] [security2:error] [pid 402041:tid 402207] [client 62.102.148.158:45094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9T-IiENNLP6XjiHQtC-gAAAbE"]
[Tue Jul 21 08:11:52.225431 2026] [security2:error] [pid 402041:tid 402179] [client 20.104.96.117:54123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/iywwi.php"] [unique_id "al9T-IiENNLP6XjiHQtC_wAAAZU"]
[Tue Jul 21 08:11:52.572070 2026] [security2:error] [pid 402041:tid 402241] [client 45.3.42.26:48303] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9T-IiENNLP6XjiHQtDEAAAAdM"]
[Tue Jul 21 08:11:52.574291 2026] [security2:error] [pid 402041:tid 402144] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9T-IiENNLP6XjiHQtDEQAB2GQ"]
[Tue Jul 21 08:11:52.574474 2026] [security2:error] [pid 402041:tid 402246] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9T-IiENNLP6XjiHQtDEQAB2GQ"]
[Tue Jul 21 08:11:52.710136 2026] [security2:error] [pid 402041:tid 402147] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9T-IiENNLP6XjiHQtDEwABnmc"]
[Tue Jul 21 08:11:52.710346 2026] [security2:error] [pid 402041:tid 402188] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9T-IiENNLP6XjiHQtDEwABnmc"]
[Tue Jul 21 08:11:52.838848 2026] [security2:error] [pid 402041:tid 402278] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T-IiENNLP6XjiHQtDBwAAAfg"]
[Tue Jul 21 08:11:52.839490 2026] [security2:error] [pid 402041:tid 402285] [client 20.151.10.161:50972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/xenon1337.php"] [unique_id "al9T-IiENNLP6XjiHQtDGAAAAf8"]
[Tue Jul 21 08:11:53.082162 2026] [security2:error] [pid 402041:tid 402243] [client 45.3.42.26:39471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9T-YiENNLP6XjiHQtDHwAAAdU"]
[Tue Jul 21 08:11:53.381681 2026] [security2:error] [pid 402041:tid 402274] [client 20.104.96.117:63100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/gqgsa.php"] [unique_id "al9T-YiENNLP6XjiHQtDKAAAAfQ"]
[Tue Jul 21 08:11:53.402134 2026] [security2:error] [pid 402041:tid 402250] [client 20.104.96.117:58410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/xpwer1.php"] [unique_id "al9T-YiENNLP6XjiHQtDKQAAAdw"]
[Tue Jul 21 08:11:53.659024 2026] [security2:error] [pid 402041:tid 402183] [client 45.3.42.26:40007] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lojaracompressores.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9T-YiENNLP6XjiHQtDMgAAAZk"]
[Tue Jul 21 08:11:53.883523 2026] [log_config:warn] [pid 352421:tid 352659] (32)Broken pipe: [client 110.137.100.79:3840] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:11:53.883547 2026] [log_config:warn] [pid 352421:tid 352659] (32)Broken pipe: [client 110.137.100.79:3840] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:11:53.994810 2026] [security2:error] [pid 402041:tid 402205] [client 74.7.228.43:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "egcbatiment.com"] [uri "/index.php"] [unique_id "al9T-YiENNLP6XjiHQtDPwAAAa8"]
[Tue Jul 21 08:11:53.995728 2026] [security2:error] [pid 402041:tid 402282] [client 74.7.228.43:38568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "egcbatiment.com"] [uri "/robots.txt"] [unique_id "al9T-YiENNLP6XjiHQtDOwAB_AM"]
[Tue Jul 21 08:11:54.117111 2026] [security2:error] [pid 402041:tid 402213] [client 20.226.60.151:48803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/f6.php"] [unique_id "al9T-oiENNLP6XjiHQtDSgAAAbc"]
[Tue Jul 21 08:11:54.181590 2026] [security2:error] [pid 402041:tid 402252] [client 20.104.96.117:63439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/xpwer1.php"] [unique_id "al9T-oiENNLP6XjiHQtDSwAAAd4"]
[Tue Jul 21 08:11:54.199571 2026] [security2:error] [pid 402041:tid 402265] [client 20.104.96.117:58398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/flox.php"] [unique_id "al9T-oiENNLP6XjiHQtDTQAAAes"]
[Tue Jul 21 08:11:54.487221 2026] [security2:error] [pid 402041:tid 402185] [client 103.78.200.11:63475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T-oiENNLP6XjiHQtDUwAAAZs"]
[Tue Jul 21 08:11:54.487826 2026] [security2:error] [pid 402041:tid 402185] [client 103.78.200.11:63475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T-oiENNLP6XjiHQtDUwAAAZs"]
[Tue Jul 21 08:11:54.527821 2026] [security2:error] [pid 402041:tid 402067] [remote 165.232.170.247:49692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.170.232.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9T-YiENNLP6XjiHQtDKwAB6Bc"]
[Tue Jul 21 08:11:54.553909 2026] [security2:error] [pid 402041:tid 402231] [client 20.226.60.151:48845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/inputs.php"] [unique_id "al9T-oiENNLP6XjiHQtDWAAAAck"]
[Tue Jul 21 08:11:54.587205 2026] [security2:error] [pid 402041:tid 402224] [client 20.226.60.151:48781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/inputs.php"] [unique_id "al9T-oiENNLP6XjiHQtDXAAAAcI"]
[Tue Jul 21 08:11:54.606241 2026] [security2:error] [pid 402041:tid 402300] [client 20.226.60.151:48811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/classwithtostring.php"] [unique_id "al9T-oiENNLP6XjiHQtDXgAAAg4"]
[Tue Jul 21 08:11:54.685235 2026] [security2:error] [pid 402041:tid 402193] [client 20.226.60.151:48836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9T-oiENNLP6XjiHQtDYwAAAaM"]
[Tue Jul 21 08:11:54.740826 2026] [security2:error] [pid 402041:tid 402295] [client 20.226.60.151:49349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wp-blog.php"] [unique_id "al9T-oiENNLP6XjiHQtDZAAAAgk"]
[Tue Jul 21 08:11:54.752264 2026] [security2:error] [pid 402041:tid 402216] [client 117.210.135.0:58473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T-oiENNLP6XjiHQtDZQAAAbo"]
[Tue Jul 21 08:11:54.752388 2026] [security2:error] [pid 402041:tid 402216] [client 117.210.135.0:58473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T-oiENNLP6XjiHQtDZQAAAbo"]
[Tue Jul 21 08:11:55.777025 2026] [security2:error] [pid 402041:tid 402282] [client 87.116.180.198:14053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T-4iENNLP6XjiHQtDjgAAAfw"]
[Tue Jul 21 08:11:55.777199 2026] [security2:error] [pid 402041:tid 402282] [client 87.116.180.198:14053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T-4iENNLP6XjiHQtDjgAAAfw"]
[Tue Jul 21 08:11:55.811997 2026] [security2:error] [pid 402041:tid 402276] [client 20.104.96.117:57965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/popo.php"] [unique_id "al9T-4iENNLP6XjiHQtDjwAAAfY"]
[Tue Jul 21 08:11:56.018893 2026] [security2:error] [pid 402041:tid 402281] [client 134.122.94.138:52120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "accjbc.org"] [uri "/api"] [unique_id "al9T_IiENNLP6XjiHQtDlwAAAfs"]
[Tue Jul 21 08:11:56.147003 2026] [security2:error] [pid 402041:tid 402235] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T-4iENNLP6XjiHQtDjAAAAc0"]
[Tue Jul 21 08:11:56.204234 2026] [security2:error] [pid 402041:tid 402163] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T_IiENNLP6XjiHQtDmwAB6Hc"]
[Tue Jul 21 08:11:56.204449 2026] [security2:error] [pid 402041:tid 402262] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T_IiENNLP6XjiHQtDmwAB6Hc"]
[Tue Jul 21 08:11:56.274962 2026] [security2:error] [pid 402041:tid 402283] [client 62.102.148.158:45106] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9T_IiENNLP6XjiHQtDngAAAf0"]
[Tue Jul 21 08:11:56.275040 2026] [security2:error] [pid 402041:tid 402283] [client 62.102.148.158:45106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9T_IiENNLP6XjiHQtDngAAAf0"]
[Tue Jul 21 08:11:56.434500 2026] [security2:error] [pid 402041:tid 402185] [client 38.100.221.102:17752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T_IiENNLP6XjiHQtDpgAAAZs"]
[Tue Jul 21 08:11:56.434655 2026] [security2:error] [pid 402041:tid 402185] [client 38.100.221.102:17752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9T_IiENNLP6XjiHQtDpgAAAZs"]
[Tue Jul 21 08:11:56.494104 2026] [security2:error] [pid 402041:tid 402234] [client 20.104.96.117:54687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/elbzl.php"] [unique_id "al9T_IiENNLP6XjiHQtDqQAAAcw"]
[Tue Jul 21 08:11:56.620402 2026] [security2:error] [pid 402041:tid 402284] [client 154.208.47.43:42561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9T_IiENNLP6XjiHQtDqwAAAf4"]
[Tue Jul 21 08:11:56.620550 2026] [security2:error] [pid 402041:tid 402284] [client 154.208.47.43:42561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9T_IiENNLP6XjiHQtDqwAAAf4"]
[Tue Jul 21 08:11:56.910032 2026] [autoindex:error] [pid 402041:tid 402259] [client 20.226.60.151:48835] AH01276: Cannot serve directory /home4/moadvo53/moadvogadas.com.br/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:11:56.950348 2026] [security2:error] [pid 402041:tid 402210] [client 20.226.60.151:48838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9T_IiENNLP6XjiHQtDtQAAAbQ"]
[Tue Jul 21 08:11:57.052877 2026] [security2:error] [pid 402041:tid 402228] [client 20.104.96.117:62585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/flox.php"] [unique_id "al9T_YiENNLP6XjiHQtDuQAAAcY"]
[Tue Jul 21 08:11:57.320996 2026] [security2:error] [pid 402041:tid 402222] [client 20.104.96.117:57933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/yas.php"] [unique_id "al9T_YiENNLP6XjiHQtDvwAAAcA"]
[Tue Jul 21 08:11:59.044901 2026] [security2:error] [pid 402041:tid 402297] [client 151.63.71.144:51217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9T_4iENNLP6XjiHQtD8QAAAgs"]
[Tue Jul 21 08:11:59.045058 2026] [security2:error] [pid 402041:tid 402297] [client 151.63.71.144:51217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9T_4iENNLP6XjiHQtD8QAAAgs"]
[Tue Jul 21 08:11:59.368387 2026] [security2:error] [pid 402041:tid 402236] [client 20.220.225.223:30870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/dp.php"] [unique_id "al9T_4iENNLP6XjiHQtD_gAAAc4"]
[Tue Jul 21 08:11:59.389698 2026] [security2:error] [pid 402041:tid 402295] [client 20.151.10.161:50944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/test11.php"] [unique_id "al9T_4iENNLP6XjiHQtD_wAAAgk"]
[Tue Jul 21 08:11:59.406938 2026] [security2:error] [pid 402041:tid 402204] [client 20.104.96.117:62581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/popo.php"] [unique_id "al9T_4iENNLP6XjiHQtEAAAAAa4"]
[Tue Jul 21 08:11:59.427759 2026] [security2:error] [pid 402041:tid 402298] [client 20.104.96.117:54164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/file61.php"] [unique_id "al9T_4iENNLP6XjiHQtEAQAAAgw"]
[Tue Jul 21 08:11:59.503718 2026] [security2:error] [pid 402041:tid 402193] [client 20.226.60.151:49356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/ms-edit.php"] [unique_id "al9T_4iENNLP6XjiHQtEAgAAAaM"]
[Tue Jul 21 08:11:59.654185 2026] [security2:error] [pid 402041:tid 402286] [client 14.97.58.74:19793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9T_4iENNLP6XjiHQtEBAAAAgA"]
[Tue Jul 21 08:11:59.654297 2026] [security2:error] [pid 402041:tid 402286] [client 14.97.58.74:19793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9T_4iENNLP6XjiHQtEBAAAAgA"]
[Tue Jul 21 08:11:59.666405 2026] [security2:error] [pid 402041:tid 402227] [client 102.206.115.33:59136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T_4iENNLP6XjiHQtEBwAAAcU"]
[Tue Jul 21 08:11:59.666504 2026] [security2:error] [pid 402041:tid 402227] [client 102.206.115.33:59136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9T_4iENNLP6XjiHQtEBwAAAcU"]
[Tue Jul 21 08:12:00.094646 2026] [security2:error] [pid 402041:tid 402178] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9T_4iENNLP6XjiHQtECQAAAZQ"]
[Tue Jul 21 08:12:00.272010 2026] [security2:error] [pid 402041:tid 402117] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UAIiENNLP6XjiHQtEFwABlkk"]
[Tue Jul 21 08:12:00.272140 2026] [security2:error] [pid 402041:tid 402180] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UAIiENNLP6XjiHQtEFwABlkk"]
[Tue Jul 21 08:12:00.571839 2026] [security2:error] [pid 402041:tid 402102] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UAIiENNLP6XjiHQtEIwAB_zo"]
[Tue Jul 21 08:12:00.572032 2026] [security2:error] [pid 402041:tid 402285] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UAIiENNLP6XjiHQtEIwAB_zo"]
[Tue Jul 21 08:12:00.749238 2026] [security2:error] [pid 402041:tid 402291] [client 20.220.225.223:30903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/old.php"] [unique_id "al9UAIiENNLP6XjiHQtEKgAAAgU"]
[Tue Jul 21 08:12:01.602135 2026] [security2:error] [pid 402041:tid 402185] [client 20.226.60.151:48855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9UAYiENNLP6XjiHQtESQAAAZs"]
[Tue Jul 21 08:12:01.605883 2026] [security2:error] [pid 402041:tid 402266] [client 20.104.96.117:63368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/yas.php"] [unique_id "al9UAYiENNLP6XjiHQtESgAAAew"]
[Tue Jul 21 08:12:01.656665 2026] [security2:error] [pid 402041:tid 402250] [client 20.197.192.193:3148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/ace2.php"] [unique_id "al9UAYiENNLP6XjiHQtETAAAAdw"]
[Tue Jul 21 08:12:01.751520 2026] [security2:error] [pid 402041:tid 402216] [client 120.56.162.40:54277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UAYiENNLP6XjiHQtEUAAAAbo"]
[Tue Jul 21 08:12:01.751837 2026] [security2:error] [pid 402041:tid 402216] [client 120.56.162.40:54277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UAYiENNLP6XjiHQtEUAAAAbo"]
[Tue Jul 21 08:12:01.879834 2026] [access_compat:error] [pid 402041:tid 402179] [client 162.241.63.68:19664] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:12:01.885437 2026] [security2:error] [pid 402041:tid 402210] [client 20.104.96.117:60099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/water.php"] [unique_id "al9UAYiENNLP6XjiHQtEVgAAAbQ"]
[Tue Jul 21 08:12:02.049309 2026] [security2:error] [pid 402041:tid 402268] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UAYiENNLP6XjiHQtESAAAAe4"]
[Tue Jul 21 08:12:02.098146 2026] [security2:error] [pid 402041:tid 402161] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UAoiENNLP6XjiHQtEXgACBnU"]
[Tue Jul 21 08:12:02.098289 2026] [security2:error] [pid 402041:tid 402292] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UAoiENNLP6XjiHQtEXgACBnU"]
[Tue Jul 21 08:12:02.154405 2026] [security2:error] [pid 402041:tid 402203] [client 187.125.243.197:55868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UAoiENNLP6XjiHQtEYAAAAa0"]
[Tue Jul 21 08:12:02.154561 2026] [security2:error] [pid 402041:tid 402203] [client 187.125.243.197:55868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UAoiENNLP6XjiHQtEYAAAAa0"]
[Tue Jul 21 08:12:02.329915 2026] [security2:error] [pid 402041:tid 402204] [client 20.197.192.193:57819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tkcorretoradeseguros.com.br"] [uri "/ms.php"] [unique_id "al9UAoiENNLP6XjiHQtEZgAAAa4"]
[Tue Jul 21 08:12:02.411624 2026] [security2:error] [pid 402041:tid 402173] [client 150.129.202.39:65228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UAoiENNLP6XjiHQtEaAAAAY8"]
[Tue Jul 21 08:12:02.411769 2026] [security2:error] [pid 402041:tid 402173] [client 150.129.202.39:65228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UAoiENNLP6XjiHQtEaAAAAY8"]
[Tue Jul 21 08:12:02.465956 2026] [security2:error] [pid 402041:tid 402187] [client 20.104.96.117:60110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/nano.php"] [unique_id "al9UAoiENNLP6XjiHQtEbAAAAZ0"]
[Tue Jul 21 08:12:03.190845 2026] [security2:error] [pid 402041:tid 402150] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UA4iENNLP6XjiHQtEfQAB02o"]
[Tue Jul 21 08:12:03.190995 2026] [security2:error] [pid 402041:tid 402241] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UA4iENNLP6XjiHQtEfQAB02o"]
[Tue Jul 21 08:12:03.241950 2026] [security2:error] [pid 402041:tid 402216] [client 20.104.96.117:63457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/file61.php"] [unique_id "al9UA4iENNLP6XjiHQtEfgAAAbo"]
[Tue Jul 21 08:12:03.284082 2026] [autoindex:error] [pid 402041:tid 402226] [client 20.226.60.151:48832] AH01276: Cannot serve directory /home4/moadvo53/moadvogadas.com.br/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:12:03.302441 2026] [security2:error] [pid 402041:tid 402179] [client 20.226.60.151:49369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9UA4iENNLP6XjiHQtEhQAAAZU"]
[Tue Jul 21 08:12:03.557608 2026] [autoindex:error] [pid 402041:tid 402297] [client 20.226.60.151:48832] AH01276: Cannot serve directory /home4/moadvo53/moadvogadas.com.br/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:12:03.581704 2026] [autoindex:error] [pid 402041:tid 402214] [client 20.226.60.151:48832] AH01276: Cannot serve directory /home4/moadvo53/moadvogadas.com.br/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:12:03.587888 2026] [security2:error] [pid 402041:tid 402248] [client 20.226.60.151:48806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/abcd.php"] [unique_id "al9UA4iENNLP6XjiHQtEjgAAAdo"]
[Tue Jul 21 08:12:03.722258 2026] [security2:error] [pid 402041:tid 402256] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UA4iENNLP6XjiHQtEhAAAAeI"]
[Tue Jul 21 08:12:03.907088 2026] [security2:error] [pid 402041:tid 402149] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UA4iENNLP6XjiHQtEmwABo2k"]
[Tue Jul 21 08:12:03.907268 2026] [security2:error] [pid 402041:tid 402193] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UA4iENNLP6XjiHQtEmwABo2k"]
[Tue Jul 21 08:12:04.074454 2026] [security2:error] [pid 402041:tid 402196] [client 20.104.96.117:54678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/adjig.php"] [unique_id "al9UBIiENNLP6XjiHQtEnAAAAaY"]
[Tue Jul 21 08:12:04.282642 2026] [security2:error] [pid 402041:tid 402182] [client 20.104.96.117:63365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/water.php"] [unique_id "al9UBIiENNLP6XjiHQtEogAAAZg"]
[Tue Jul 21 08:12:04.283497 2026] [security2:error] [pid 402041:tid 402056] [remote 185.22.228.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.228.22.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9UBIiENNLP6XjiHQtEoQABogw"]
[Tue Jul 21 08:12:04.529242 2026] [security2:error] [pid 402041:tid 402294] [client 20.151.10.161:51036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/koala.php"] [unique_id "al9UBIiENNLP6XjiHQtErAAAAgg"]
[Tue Jul 21 08:12:04.869006 2026] [security2:error] [pid 402041:tid 402180] [client 20.104.96.117:54176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/moon.php"] [unique_id "al9UBIiENNLP6XjiHQtEuAAAAZY"]
[Tue Jul 21 08:12:04.998960 2026] [security2:error] [pid 402041:tid 402194] [client 20.226.60.151:48873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/file15.php"] [unique_id "al9UBIiENNLP6XjiHQtEuwAAAaQ"]
[Tue Jul 21 08:12:05.291927 2026] [security2:error] [pid 402041:tid 402212] [client 117.210.135.0:59127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UBYiENNLP6XjiHQtEwQAAAbY"]
[Tue Jul 21 08:12:05.292040 2026] [security2:error] [pid 402041:tid 402212] [client 117.210.135.0:59127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UBYiENNLP6XjiHQtEwQAAAbY"]
[Tue Jul 21 08:12:05.431504 2026] [security2:error] [pid 402041:tid 402283] [client 61.1.167.83:65044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UBYiENNLP6XjiHQtExQAAAf0"]
[Tue Jul 21 08:12:05.431629 2026] [security2:error] [pid 402041:tid 402283] [client 61.1.167.83:65044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UBYiENNLP6XjiHQtExQAAAf0"]
[Tue Jul 21 08:12:05.489912 2026] [security2:error] [pid 402041:tid 402284] [client 103.78.200.11:63961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UBYiENNLP6XjiHQtEzAAAAf4"]
[Tue Jul 21 08:12:05.490031 2026] [security2:error] [pid 402041:tid 402284] [client 103.78.200.11:63961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UBYiENNLP6XjiHQtEzAAAAf4"]
[Tue Jul 21 08:12:06.074127 2026] [security2:error] [pid 402041:tid 402176] [client 20.226.60.151:48877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/jp.php"] [unique_id "al9UBoiENNLP6XjiHQtE2AAAAZI"]
[Tue Jul 21 08:12:06.292496 2026] [security2:error] [pid 402041:tid 402206] [client 20.104.96.117:63397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/nano.php"] [unique_id "al9UBoiENNLP6XjiHQtE3QAAAbA"]
[Tue Jul 21 08:12:06.478788 2026] [security2:error] [pid 402041:tid 402189] [client 87.116.180.198:27198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UBoiENNLP6XjiHQtE5gAAAZ8"]
[Tue Jul 21 08:12:06.482087 2026] [security2:error] [pid 402041:tid 402189] [client 87.116.180.198:27198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UBoiENNLP6XjiHQtE5gAAAZ8"]
[Tue Jul 21 08:12:06.603972 2026] [log_config:warn] [pid 400813:tid 400987] (32)Broken pipe: [client 140.213.15.111:56078] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:12:06.603993 2026] [log_config:warn] [pid 400813:tid 400987] (32)Broken pipe: [client 140.213.15.111:56078] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:12:06.606020 2026] [proxy:error] [pid 402041:tid 402188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:06.606058 2026] [proxy_http:error] [pid 402041:tid 402188] [client 134.209.80.15:43722] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:12:06.606500 2026] [proxy:error] [pid 402041:tid 402188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:06.606521 2026] [proxy_http:error] [pid 402041:tid 402188] [client 134.209.80.15:43722] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:12:06.732273 2026] [security2:error] [pid 402041:tid 402086] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UBoiENNLP6XjiHQtE7QABlCo"]
[Tue Jul 21 08:12:06.732490 2026] [security2:error] [pid 402041:tid 402178] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UBoiENNLP6XjiHQtE7QABlCo"]
[Tue Jul 21 08:12:06.996854 2026] [proxy:error] [pid 402041:tid 402259] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:06.996930 2026] [proxy_http:error] [pid 402041:tid 402259] [client 134.209.80.15:43726] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.equoterapiaprosseguir.com/
[Tue Jul 21 08:12:06.997433 2026] [proxy:error] [pid 402041:tid 402259] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:06.997459 2026] [proxy_http:error] [pid 402041:tid 402259] [client 134.209.80.15:43726] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.equoterapiaprosseguir.com/
[Tue Jul 21 08:12:06.999765 2026] [security2:error] [pid 402041:tid 402295] [client 38.100.221.102:17774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UBoiENNLP6XjiHQtE-gAAAgk"]
[Tue Jul 21 08:12:07.000249 2026] [security2:error] [pid 402041:tid 402295] [client 38.100.221.102:17774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UBoiENNLP6XjiHQtE-gAAAgk"]
[Tue Jul 21 08:12:07.050906 2026] [security2:error] [pid 402041:tid 402179] [client 20.104.96.117:57971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-info.php"] [unique_id "al9UB4iENNLP6XjiHQtE_QAAAZU"]
[Tue Jul 21 08:12:07.104381 2026] [security2:error] [pid 402041:tid 402274] [client 154.208.47.43:43023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UB4iENNLP6XjiHQtE_gAAAfQ"]
[Tue Jul 21 08:12:07.104554 2026] [security2:error] [pid 402041:tid 402274] [client 154.208.47.43:43023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UB4iENNLP6XjiHQtE_gAAAfQ"]
[Tue Jul 21 08:12:07.426105 2026] [security2:error] [pid 402041:tid 402190] [client 173.252.95.24:41888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9UB4iENNLP6XjiHQtFCAAAAaA"]
[Tue Jul 21 08:12:07.435831 2026] [security2:error] [pid 402041:tid 402289] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UB4iENNLP6XjiHQtE-wAAAgM"]
[Tue Jul 21 08:12:07.573610 2026] [security2:error] [pid 402041:tid 402193] [client 20.151.10.161:51052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/mac.php"] [unique_id "al9UB4iENNLP6XjiHQtFFAAAAaM"]
[Tue Jul 21 08:12:07.849893 2026] [security2:error] [pid 402041:tid 402177] [client 103.151.46.103:52919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UB4iENNLP6XjiHQtFIAAAAZM"]
[Tue Jul 21 08:12:07.850040 2026] [security2:error] [pid 402041:tid 402177] [client 103.151.46.103:52919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UB4iENNLP6XjiHQtFIAAAAZM"]
[Tue Jul 21 08:12:07.883128 2026] [proxy:error] [pid 402041:tid 402256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:07.883161 2026] [proxy_http:error] [pid 402041:tid 402256] [client 134.209.80.15:34142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:12:07.883725 2026] [proxy:error] [pid 402041:tid 402256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:07.883747 2026] [proxy_http:error] [pid 402041:tid 402256] [client 134.209.80.15:34142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:12:08.351170 2026] [security2:error] [pid 402041:tid 402225] [client 20.151.10.161:51029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9UCIiENNLP6XjiHQtFNQAAAcM"]
[Tue Jul 21 08:12:08.398031 2026] [security2:error] [pid 402041:tid 402299] [client 20.226.60.151:48844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/f35.php"] [unique_id "al9UCIiENNLP6XjiHQtFNgAAAg0"]
[Tue Jul 21 08:12:08.604276 2026] [security2:error] [pid 402041:tid 402283] [client 20.104.96.117:58424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/2000.php"] [unique_id "al9UCIiENNLP6XjiHQtFPwAAAf0"]
[Tue Jul 21 08:12:08.713266 2026] [security2:error] [pid 402041:tid 402203] [client 20.104.96.117:54704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/byp.php"] [unique_id "al9UCIiENNLP6XjiHQtFRwAAAa0"]
[Tue Jul 21 08:12:08.835831 2026] [security2:error] [pid 402041:tid 402190] [client 20.104.96.117:63433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/moon.php"] [unique_id "al9UCIiENNLP6XjiHQtFTQAAAaA"]
[Tue Jul 21 08:12:08.920440 2026] [security2:error] [pid 402041:tid 402271] [client 20.151.10.161:50947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wefile.php"] [unique_id "al9UCIiENNLP6XjiHQtFUwAAAfE"]
[Tue Jul 21 08:12:09.130364 2026] [security2:error] [pid 402041:tid 402206] [client 20.197.192.193:3160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "domineseucaos.com.br.moneyclass.com.br"] [uri "/ms.php"] [unique_id "al9UCYiENNLP6XjiHQtFWwAAAbA"]
[Tue Jul 21 08:12:09.289891 2026] [security2:error] [pid 402041:tid 402109] [remote 72.167.132.114:50240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9UCYiENNLP6XjiHQtFXwABzkE"]
[Tue Jul 21 08:12:09.290079 2026] [security2:error] [pid 402041:tid 402236] [client 72.167.132.114:50240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9UCYiENNLP6XjiHQtFXwABzkE"]
[Tue Jul 21 08:12:09.578955 2026] [security2:error] [pid 402041:tid 402178] [client 20.226.60.151:48842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wp-load.php"] [unique_id "al9UCYiENNLP6XjiHQtFbwAAAZQ"]
[Tue Jul 21 08:12:09.711600 2026] [security2:error] [pid 402041:tid 402255] [client 62.102.148.158:39330] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9UCYiENNLP6XjiHQtFcQAAAeE"]
[Tue Jul 21 08:12:09.711689 2026] [security2:error] [pid 402041:tid 402255] [client 62.102.148.158:39330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9UCYiENNLP6XjiHQtFcQAAAeE"]
[Tue Jul 21 08:12:09.851342 2026] [security2:error] [pid 402041:tid 402189] [client 151.63.71.144:51764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9UCYiENNLP6XjiHQtFdwAAAZ8"]
[Tue Jul 21 08:12:09.851722 2026] [security2:error] [pid 402041:tid 402189] [client 151.63.71.144:51764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9UCYiENNLP6XjiHQtFdwAAAZ8"]
[Tue Jul 21 08:12:10.000245 2026] [security2:error] [pid 402041:tid 402241] [client 20.151.10.161:55851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9UCYiENNLP6XjiHQtFfQAAAdM"]
[Tue Jul 21 08:12:10.128871 2026] [security2:error] [pid 402041:tid 402174] [client 102.206.115.33:64860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UCoiENNLP6XjiHQtFhAAAAZA"]
[Tue Jul 21 08:12:10.129001 2026] [security2:error] [pid 402041:tid 402174] [client 102.206.115.33:64860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UCoiENNLP6XjiHQtFhAAAAZA"]
[Tue Jul 21 08:12:10.190283 2026] [security2:error] [pid 402041:tid 402265] [client 20.104.96.117:63483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-info.php"] [unique_id "al9UCoiENNLP6XjiHQtFhQAAAes"]
[Tue Jul 21 08:12:10.190308 2026] [security2:error] [pid 402041:tid 402203] [client 20.226.60.151:48771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/xyn.php"] [unique_id "al9UCoiENNLP6XjiHQtFhgAAAa0"]
[Tue Jul 21 08:12:10.348431 2026] [security2:error] [pid 402041:tid 402225] [client 111.93.58.162:39718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UCoiENNLP6XjiHQtFjAAAAcM"]
[Tue Jul 21 08:12:10.348587 2026] [security2:error] [pid 402041:tid 402225] [client 111.93.58.162:39718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UCoiENNLP6XjiHQtFjAAAAcM"]
[Tue Jul 21 08:12:10.391455 2026] [log_config:warn] [pid 400813:tid 400946] (32)Broken pipe: [client 180.249.184.165:6994] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:12:10.391474 2026] [log_config:warn] [pid 400813:tid 400946] (32)Broken pipe: [client 180.249.184.165:6994] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:12:10.594892 2026] [security2:error] [pid 402041:tid 402173] [client 20.151.10.161:51059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/2P.php"] [unique_id "al9UCoiENNLP6XjiHQtFlgAAAY8"]
[Tue Jul 21 08:12:10.730096 2026] [security2:error] [pid 402041:tid 402130] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UCoiENNLP6XjiHQtFmwACB1Y"]
[Tue Jul 21 08:12:10.730287 2026] [security2:error] [pid 402041:tid 402293] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UCoiENNLP6XjiHQtFmwACB1Y"]
[Tue Jul 21 08:12:10.842012 2026] [security2:error] [pid 402041:tid 402273] [client 162.219.176.3:34060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9UCoiENNLP6XjiHQtFoAAAAfM"]
[Tue Jul 21 08:12:10.842135 2026] [security2:error] [pid 402041:tid 402273] [client 162.219.176.3:34060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9UCoiENNLP6XjiHQtFoAAAAfM"]
[Tue Jul 21 08:12:11.119918 2026] [security2:error] [pid 402041:tid 402260] [client 20.104.96.117:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/122.php"] [unique_id "al9UC4iENNLP6XjiHQtFrAAAAeY"]
[Tue Jul 21 08:12:11.625219 2026] [security2:error] [pid 402041:tid 402297] [client 65.21.113.253:60708] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UC4iENNLP6XjiHQtFrQAAAgs"]
[Tue Jul 21 08:12:12.021125 2026] [security2:error] [pid 402041:tid 402243] [client 20.151.10.161:50977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/.well-known/about.php"] [unique_id "al9UDIiENNLP6XjiHQtGCwAAAdU"]
[Tue Jul 21 08:12:12.044375 2026] [security2:error] [pid 402041:tid 402213] [client 2a01:4f9:c013:c11d::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UC4iENNLP6XjiHQtFwAABtxg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:12:12.088767 2026] [security2:error] [pid 402041:tid 402295] [client 2a01:4f9:c013:c11d::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UC4iENNLP6XjiHQtFvAACCW4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:12:12.099274 2026] [security2:error] [pid 402041:tid 402218] [client 2a01:4f9:c013:c11d::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UC4iENNLP6XjiHQtFugABvH0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:12:12.099281 2026] [security2:error] [pid 402041:tid 402249] [client 2a01:4f9:c013:c11d::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UC4iENNLP6XjiHQtFuwAB23E"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:12:12.321713 2026] [security2:error] [pid 402041:tid 402177] [client 2a01:4f9:c013:c11d::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UDIiENNLP6XjiHQtGHgABkzo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:12:12.395339 2026] [security2:error] [pid 402041:tid 402177] [client 2a01:4f9:c013:c11d::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UDIiENNLP6XjiHQtGIQABkzw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:12:12.411591 2026] [security2:error] [pid 402041:tid 402234] [client 2a01:4f9:c013:c11d::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UDIiENNLP6XjiHQtGJwABzEc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:12:12.413567 2026] [security2:error] [pid 402041:tid 402203] [client 120.56.162.40:54774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UDIiENNLP6XjiHQtGLwAAAa0"]
[Tue Jul 21 08:12:12.413659 2026] [security2:error] [pid 402041:tid 402203] [client 120.56.162.40:54774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UDIiENNLP6XjiHQtGLwAAAa0"]
[Tue Jul 21 08:12:12.430279 2026] [security2:error] [pid 402041:tid 402234] [client 2a01:4f9:c013:c11d::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UDIiENNLP6XjiHQtGKAABzDA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:12:12.436739 2026] [security2:error] [pid 402041:tid 402174] [client 65.21.113.253:35622] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UC4iENNLP6XjiHQtGCgAAAZA"]
[Tue Jul 21 08:12:12.594863 2026] [security2:error] [pid 402041:tid 402205] [client 187.125.243.197:56313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UDIiENNLP6XjiHQtGTgAAAa8"]
[Tue Jul 21 08:12:12.595391 2026] [security2:error] [pid 402041:tid 402205] [client 187.125.243.197:56313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UDIiENNLP6XjiHQtGTgAAAa8"]
[Tue Jul 21 08:12:12.617467 2026] [proxy:error] [pid 402041:tid 402196] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:12.617518 2026] [proxy_http:error] [pid 402041:tid 402196] [client 134.209.80.15:47136] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.equoterapiaprosseguir.com/
[Tue Jul 21 08:12:12.617946 2026] [proxy:error] [pid 402041:tid 402196] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:12.617976 2026] [proxy_http:error] [pid 402041:tid 402196] [client 134.209.80.15:47136] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.equoterapiaprosseguir.com/
[Tue Jul 21 08:12:12.650027 2026] [security2:error] [pid 402041:tid 402126] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UDIiENNLP6XjiHQtGUQABp1I"]
[Tue Jul 21 08:12:12.650164 2026] [security2:error] [pid 402041:tid 402197] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UDIiENNLP6XjiHQtGUQABp1I"]
[Tue Jul 21 08:12:12.704574 2026] [security2:error] [pid 402041:tid 402235] [client 2a01:4f9:c013:c11d::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UDIiENNLP6XjiHQtGTwABzWg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:12:12.756784 2026] [security2:error] [pid 402041:tid 402280] [client 20.104.96.117:57938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/mds.php"] [unique_id "al9UDIiENNLP6XjiHQtGWgAAAfo"]
[Tue Jul 21 08:12:12.850399 2026] [security2:error] [pid 402041:tid 402290] [client 20.151.10.161:51056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9UDIiENNLP6XjiHQtGagAAAgQ"]
[Tue Jul 21 08:12:12.870916 2026] [security2:error] [pid 402041:tid 402295] [client 20.220.225.223:58374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/ms-new.php"] [unique_id "al9UDIiENNLP6XjiHQtGawAAAgk"]
[Tue Jul 21 08:12:12.922027 2026] [security2:error] [pid 402041:tid 402249] [client 2a01:4f9:c013:c11d::1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UDIiENNLP6XjiHQtGbAAB2wE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:12:13.002892 2026] [security2:error] [pid 402041:tid 402257] [client 20.104.96.117:56844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/2000.php"] [unique_id "al9UDYiENNLP6XjiHQtGbwAAAeM"]
[Tue Jul 21 08:12:13.083639 2026] [security2:error] [pid 402041:tid 402220] [client 150.129.202.39:65357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UDYiENNLP6XjiHQtGsQAAAb4"]
[Tue Jul 21 08:12:13.083726 2026] [security2:error] [pid 402041:tid 402220] [client 150.129.202.39:65357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UDYiENNLP6XjiHQtGsQAAAb4"]
[Tue Jul 21 08:12:13.828709 2026] [security2:error] [pid 402041:tid 402169] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UDYiENNLP6XjiHQtGxQABtn0"]
[Tue Jul 21 08:12:13.828908 2026] [security2:error] [pid 402041:tid 402212] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UDYiENNLP6XjiHQtGxQABtn0"]
[Tue Jul 21 08:12:13.948387 2026] [security2:error] [pid 402041:tid 402280] [client 20.151.10.161:51048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/bob.php"] [unique_id "al9UDYiENNLP6XjiHQtGyQAAAfo"]
[Tue Jul 21 08:12:14.290233 2026] [autoindex:error] [pid 402041:tid 402262] [client 20.226.60.151:48852] AH01276: Cannot serve directory /home4/moadvo53/moadvogadas.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:12:14.663099 2026] [security2:error] [pid 402041:tid 402230] [client 20.104.96.117:57976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-blink.php"] [unique_id "al9UDoiENNLP6XjiHQtG3QAAAcg"]
[Tue Jul 21 08:12:14.691405 2026] [security2:error] [pid 402041:tid 402285] [client 20.104.96.117:63471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/122.php"] [unique_id "al9UDoiENNLP6XjiHQtG3gAAAf8"]
[Tue Jul 21 08:12:14.704914 2026] [autoindex:error] [pid 402041:tid 402242] [client 20.226.60.151:48852] AH01276: Cannot serve directory /home4/moadvo53/moadvogadas.com.br/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:12:14.712636 2026] [security2:error] [pid 402041:tid 402246] [client 20.226.60.151:49366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/ccc.php"] [unique_id "al9UDoiENNLP6XjiHQtG4AAAAdg"]
[Tue Jul 21 08:12:14.791161 2026] [security2:error] [pid 402041:tid 402177] [client 20.151.10.161:51025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/crgio.php"] [unique_id "al9UDoiENNLP6XjiHQtG5wAAAZM"]
[Tue Jul 21 08:12:14.864731 2026] [security2:error] [pid 402041:tid 402296] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UDYiENNLP6XjiHQtGvAACChg"]
[Tue Jul 21 08:12:15.082410 2026] [security2:error] [pid 402041:tid 402140] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UD4iENNLP6XjiHQtG8AABmWA"]
[Tue Jul 21 08:12:15.082596 2026] [security2:error] [pid 402041:tid 402183] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UD4iENNLP6XjiHQtG8AABmWA"]
[Tue Jul 21 08:12:15.181569 2026] [security2:error] [pid 402041:tid 402082] [remote 104.207.63.72:20055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.63.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9UD4iENNLP6XjiHQtG7wAB4iY"]
[Tue Jul 21 08:12:15.289636 2026] [security2:error] [pid 402041:tid 402185] [client 86.106.84.166:57300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9UD4iENNLP6XjiHQtHAQAAAZs"]
[Tue Jul 21 08:12:15.289714 2026] [security2:error] [pid 402041:tid 402185] [client 86.106.84.166:57300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9UD4iENNLP6XjiHQtHAQAAAZs"]
[Tue Jul 21 08:12:15.377400 2026] [security2:error] [pid 402041:tid 402146] [remote 103.112.62.59:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tavarescont.com.br"] [uri "/wp-login.php"] [unique_id "al9UD4iENNLP6XjiHQtHAgAB9WY"]
[Tue Jul 21 08:12:15.684776 2026] [security2:error] [pid 402041:tid 402282] [client 20.104.96.117:58421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/zc-208.php"] [unique_id "al9UD4iENNLP6XjiHQtHDQAAAfw"]
[Tue Jul 21 08:12:15.780586 2026] [security2:error] [pid 402041:tid 402189] [client 117.210.135.0:59775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UD4iENNLP6XjiHQtHEAAAAZ8"]
[Tue Jul 21 08:12:15.780757 2026] [security2:error] [pid 402041:tid 402189] [client 117.210.135.0:59775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UD4iENNLP6XjiHQtHEAAAAZ8"]
[Tue Jul 21 08:12:15.907126 2026] [proxy:error] [pid 402041:tid 402286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:15.907202 2026] [proxy_http:error] [pid 402041:tid 402286] [client 205.210.31.151:59406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:12:15.907906 2026] [proxy:error] [pid 402041:tid 402286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:15.907931 2026] [proxy_http:error] [pid 402041:tid 402286] [client 205.210.31.151:59406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:12:16.162900 2026] [security2:error] [pid 402041:tid 402257] [client 20.104.96.117:62473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/mds.php"] [unique_id "al9UEIiENNLP6XjiHQtHFwAAAeM"]
[Tue Jul 21 08:12:16.201242 2026] [security2:error] [pid 402041:tid 402196] [client 103.78.200.11:64455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UEIiENNLP6XjiHQtHGQAAAaY"]
[Tue Jul 21 08:12:16.201382 2026] [security2:error] [pid 402041:tid 402196] [client 103.78.200.11:64455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UEIiENNLP6XjiHQtHGQAAAaY"]
[Tue Jul 21 08:12:16.453697 2026] [security2:error] [pid 402041:tid 402176] [client 20.104.96.117:63050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9UEIiENNLP6XjiHQtHIgAAAZI"]
[Tue Jul 21 08:12:16.572669 2026] [security2:error] [pid 402041:tid 402229] [client 20.226.60.151:48818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/w.php"] [unique_id "al9UEIiENNLP6XjiHQtHIwAAAcc"]
[Tue Jul 21 08:12:16.619479 2026] [security2:error] [pid 402041:tid 402188] [client 20.104.96.117:57973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/sid4.php"] [unique_id "al9UEIiENNLP6XjiHQtHJAAAAZ4"]
[Tue Jul 21 08:12:16.697158 2026] [security2:error] [pid 402041:tid 402047] [remote 117.0.21.154:57140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9UEIiENNLP6XjiHQtHJgAB3AM"]
[Tue Jul 21 08:12:16.713962 2026] [security2:error] [pid 402041:tid 402236] [client 65.21.113.253:35622] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UEIiENNLP6XjiHQtHHQAAAc4"]
[Tue Jul 21 08:12:17.215150 2026] [security2:error] [pid 402041:tid 402272] [client 87.116.180.198:27386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UEYiENNLP6XjiHQtHMQAAAfI"]
[Tue Jul 21 08:12:17.215289 2026] [security2:error] [pid 402041:tid 402272] [client 87.116.180.198:27386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UEYiENNLP6XjiHQtHMQAAAfI"]
[Tue Jul 21 08:12:17.310739 2026] [security2:error] [pid 402041:tid 402171] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UEYiENNLP6XjiHQtHNgAB2X8"]
[Tue Jul 21 08:12:17.310892 2026] [security2:error] [pid 402041:tid 402247] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UEYiENNLP6XjiHQtHNgAB2X8"]
[Tue Jul 21 08:12:17.439605 2026] [security2:error] [pid 402041:tid 402065] [remote 202.51.202.242:55722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9UEYiENNLP6XjiHQtHOwAB3hU"]
[Tue Jul 21 08:12:17.548676 2026] [fcgid:warn] [pid 402041:tid 402204] (70014)End of file found: [client 199.45.154.117:55692] mod_fcgid: can't get data from http client
[Tue Jul 21 08:12:17.557252 2026] [security2:error] [pid 402041:tid 402232] [client 38.100.221.102:17623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UEYiENNLP6XjiHQtHPQAAAco"]
[Tue Jul 21 08:12:17.557395 2026] [security2:error] [pid 402041:tid 402232] [client 38.100.221.102:17623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UEYiENNLP6XjiHQtHPQAAAco"]
[Tue Jul 21 08:12:17.625569 2026] [security2:error] [pid 402041:tid 402225] [client 20.104.96.117:58389] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-includes/l10n/"] [unique_id "al9UEYiENNLP6XjiHQtHPgAAAcM"]
[Tue Jul 21 08:12:17.761008 2026] [security2:error] [pid 402041:tid 402180] [client 154.208.47.42:65415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UEYiENNLP6XjiHQtHRAAAAZY"]
[Tue Jul 21 08:12:17.761096 2026] [security2:error] [pid 402041:tid 402180] [client 154.208.47.42:65415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UEYiENNLP6XjiHQtHRAAAAZY"]
[Tue Jul 21 08:12:17.969044 2026] [security2:error] [pid 402041:tid 402206] [client 20.104.96.117:62464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-blink.php"] [unique_id "al9UEYiENNLP6XjiHQtHSgAAAbA"]
[Tue Jul 21 08:12:18.298340 2026] [security2:error] [pid 402041:tid 402269] [client 20.226.60.151:48808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9UEoiENNLP6XjiHQtHUAAAAe8"]
[Tue Jul 21 08:12:18.777839 2026] [security2:error] [pid 402041:tid 402296] [client 20.104.96.117:54168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wmore1.php"] [unique_id "al9UEoiENNLP6XjiHQtHZAAAAgo"]
[Tue Jul 21 08:12:18.830920 2026] [security2:error] [pid 402041:tid 402185] [client 20.220.225.223:30850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/track.php"] [unique_id "al9UEoiENNLP6XjiHQtHaAAAAZs"]
[Tue Jul 21 08:12:19.587991 2026] [security2:error] [pid 402041:tid 402286] [client 20.151.10.161:55816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/pucci.php"] [unique_id "al9UE4iENNLP6XjiHQtHeAAAAgA"]
[Tue Jul 21 08:12:19.652023 2026] [security2:error] [pid 402041:tid 402238] [client 20.104.96.117:58369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/solo1.php"] [unique_id "al9UE4iENNLP6XjiHQtHeQAAAdA"]
[Tue Jul 21 08:12:20.139171 2026] [security2:error] [pid 402041:tid 402190] [client 65.21.113.253:35622] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UE4iENNLP6XjiHQtHegAAAaA"]
[Tue Jul 21 08:12:20.166430 2026] [security2:error] [pid 402041:tid 402236] [client 20.104.96.117:62540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/zc-208.php"] [unique_id "al9UFIiENNLP6XjiHQtHhAAAAc4"]
[Tue Jul 21 08:12:20.197230 2026] [security2:error] [pid 402041:tid 402211] [client 20.226.60.151:48841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/FWAZ.php"] [unique_id "al9UFIiENNLP6XjiHQtHhQAAAbU"]
[Tue Jul 21 08:12:20.567352 2026] [core:alert] [pid 402041:tid 402272] [client 57.141.18.18:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:12:20.611972 2026] [security2:error] [pid 402041:tid 402294] [client 20.104.96.117:58373] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-includes/assets/"] [unique_id "al9UFIiENNLP6XjiHQtHlgAAAgg"]
[Tue Jul 21 08:12:20.640558 2026] [security2:error] [pid 402041:tid 402252] [client 20.151.10.161:50970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-temp.php"] [unique_id "al9UFIiENNLP6XjiHQtHlwAAAd4"]
[Tue Jul 21 08:12:20.652916 2026] [security2:error] [pid 402041:tid 402268] [client 102.206.115.33:62249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UFIiENNLP6XjiHQtHmAAAAe4"]
[Tue Jul 21 08:12:20.653036 2026] [security2:error] [pid 402041:tid 402268] [client 102.206.115.33:62249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UFIiENNLP6XjiHQtHmAAAAe4"]
[Tue Jul 21 08:12:20.915498 2026] [security2:error] [pid 402041:tid 402194] [client 125.18.144.2:58846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UFIiENNLP6XjiHQtHmgAAAaQ"]
[Tue Jul 21 08:12:20.915676 2026] [security2:error] [pid 402041:tid 402194] [client 125.18.144.2:58846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UFIiENNLP6XjiHQtHmgAAAaQ"]
[Tue Jul 21 08:12:21.132160 2026] [security2:error] [pid 402041:tid 402191] [client 20.104.96.117:58378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/cong.php"] [unique_id "al9UFYiENNLP6XjiHQtHowAAAaE"]
[Tue Jul 21 08:12:21.221662 2026] [security2:error] [pid 402041:tid 402060] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UFYiENNLP6XjiHQtHpAACCxA"]
[Tue Jul 21 08:12:21.221907 2026] [security2:error] [pid 402041:tid 402297] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UFYiENNLP6XjiHQtHpAACCxA"]
[Tue Jul 21 08:12:22.482023 2026] [security2:error] [pid 402041:tid 402216] [client 20.226.60.151:48797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/miru1.php"] [unique_id "al9UFoiENNLP6XjiHQtHzgAAAbo"]
[Tue Jul 21 08:12:22.643274 2026] [security2:error] [pid 402041:tid 402210] [client 20.104.96.117:62487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/sid4.php"] [unique_id "al9UFoiENNLP6XjiHQtH2AAAAbQ"]
[Tue Jul 21 08:12:22.745740 2026] [security2:error] [pid 402041:tid 402276] [client 20.104.96.117:54193] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-includes/css/"] [unique_id "al9UFoiENNLP6XjiHQtH2QAAAfY"]
[Tue Jul 21 08:12:23.084417 2026] [security2:error] [pid 402041:tid 402255] [client 187.125.243.197:56771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UF4iENNLP6XjiHQtH7wAAAeE"]
[Tue Jul 21 08:12:23.084507 2026] [security2:error] [pid 402041:tid 402255] [client 187.125.243.197:56771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UF4iENNLP6XjiHQtH7wAAAeE"]
[Tue Jul 21 08:12:23.108015 2026] [security2:error] [pid 402041:tid 402265] [client 20.151.10.161:50953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9UF4iENNLP6XjiHQtH8QAAAes"]
[Tue Jul 21 08:12:23.124485 2026] [security2:error] [pid 402041:tid 402221] [client 120.56.162.40:55278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UF4iENNLP6XjiHQtH9AAAAb8"]
[Tue Jul 21 08:12:23.124623 2026] [security2:error] [pid 402041:tid 402221] [client 120.56.162.40:55278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UF4iENNLP6XjiHQtH9AAAAb8"]
[Tue Jul 21 08:12:23.142935 2026] [security2:error] [pid 402041:tid 402108] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UF4iENNLP6XjiHQtH9QACDkA"]
[Tue Jul 21 08:12:23.143031 2026] [security2:error] [pid 402041:tid 402300] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UF4iENNLP6XjiHQtH9QACDkA"]
[Tue Jul 21 08:12:23.406174 2026] [security2:error] [pid 402041:tid 402297] [client 65.21.113.253:35622] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UFoiENNLP6XjiHQtH6wAAAgs"]
[Tue Jul 21 08:12:23.649860 2026] [security2:error] [pid 402041:tid 402222] [client 150.129.202.39:65191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UF4iENNLP6XjiHQtIAAAAAcA"]
[Tue Jul 21 08:12:23.649945 2026] [security2:error] [pid 402041:tid 402222] [client 150.129.202.39:65191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UF4iENNLP6XjiHQtIAAAAAcA"]
[Tue Jul 21 08:12:23.674053 2026] [security2:error] [pid 402041:tid 402263] [client 20.104.96.117:58423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/public/css.php"] [unique_id "al9UF4iENNLP6XjiHQtIBAAAAek"]
[Tue Jul 21 08:12:23.729738 2026] [security2:error] [pid 402041:tid 402165] [remote 13.41.15.21:46764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.15.41.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/wp-login.php"] [unique_id "al9UF4iENNLP6XjiHQtIBwABvHk"]
[Tue Jul 21 08:12:24.311843 2026] [security2:error] [pid 402041:tid 402275] [client 185.251.19.77:60457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9UGIiENNLP6XjiHQtIFwAAAfU"]
[Tue Jul 21 08:12:24.432015 2026] [security2:error] [pid 402041:tid 402102] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UGIiENNLP6XjiHQtIGgAB_To"]
[Tue Jul 21 08:12:24.432239 2026] [security2:error] [pid 402041:tid 402283] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UGIiENNLP6XjiHQtIGgAB_To"]
[Tue Jul 21 08:12:24.446093 2026] [security2:error] [pid 402041:tid 402196] [client 65.21.113.253:58682] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UF4iENNLP6XjiHQtICQAAAaY"]
[Tue Jul 21 08:12:25.019384 2026] [security2:error] [pid 402041:tid 402181] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UGIiENNLP6XjiHQtIIwABl1c"]
[Tue Jul 21 08:12:25.332586 2026] [security2:error] [pid 402041:tid 402216] [client 45.132.227.209:54839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9UGIiENNLP6XjiHQtIGQAAAbo"]
[Tue Jul 21 08:12:25.406088 2026] [security2:error] [pid 402041:tid 402185] [client 61.1.167.83:49204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UGYiENNLP6XjiHQtIMwAAAZs"]
[Tue Jul 21 08:12:25.406194 2026] [security2:error] [pid 402041:tid 402185] [client 61.1.167.83:49204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UGYiENNLP6XjiHQtIMwAAAZs"]
[Tue Jul 21 08:12:25.761933 2026] [security2:error] [pid 402041:tid 402155] [remote 185.213.175.37:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.marcomarafon.com.br"] [uri "/"] [unique_id "al9UGYiENNLP6XjiHQtIPQAB2G8"]
[Tue Jul 21 08:12:25.983582 2026] [security2:error] [pid 402041:tid 402236] [client 20.104.96.117:57983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/output.php"] [unique_id "al9UGYiENNLP6XjiHQtIQQAAAc4"]
[Tue Jul 21 08:12:26.043842 2026] [security2:error] [pid 402041:tid 402291] [client 20.226.60.151:48768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/aa.php"] [unique_id "al9UGoiENNLP6XjiHQtIQgAAAgU"]
[Tue Jul 21 08:12:26.214061 2026] [security2:error] [pid 402041:tid 402147] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UGoiENNLP6XjiHQtITAABpmc"]
[Tue Jul 21 08:12:26.214258 2026] [security2:error] [pid 402041:tid 402196] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UGoiENNLP6XjiHQtITAABpmc"]
[Tue Jul 21 08:12:26.382167 2026] [security2:error] [pid 402041:tid 402233] [client 117.210.135.0:60422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UGoiENNLP6XjiHQtIUgAAAcs"]
[Tue Jul 21 08:12:26.382293 2026] [security2:error] [pid 402041:tid 402233] [client 117.210.135.0:60422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UGoiENNLP6XjiHQtIUgAAAcs"]
[Tue Jul 21 08:12:26.490081 2026] [security2:error] [pid 402041:tid 402270] [client 20.104.96.117:54665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9UGoiENNLP6XjiHQtIUwAAAfA"]
[Tue Jul 21 08:12:26.691301 2026] [security2:error] [pid 402041:tid 402206] [client 172.105.106.93:20004] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "ns1103.hostgator.com.br"] [uri "/"] [unique_id "al9UGoiENNLP6XjiHQtIWwAAAbA"]
[Tue Jul 21 08:12:26.733417 2026] [security2:error] [pid 402041:tid 402046] [remote 199.189.225.40:27119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "trilhasdafe.com.br"] [uri "/wp-login.php"] [unique_id "al9UGoiENNLP6XjiHQtIXgABvQI"]
[Tue Jul 21 08:12:26.829231 2026] [security2:error] [pid 402041:tid 402243] [client 20.151.10.161:55833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/puc.php"] [unique_id "al9UGoiENNLP6XjiHQtIZAAAAdU"]
[Tue Jul 21 08:12:26.986105 2026] [security2:error] [pid 402041:tid 402150] [remote 45.146.55.194:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mecanicanogueira.com.br"] [uri "/wp-login.php"] [unique_id "al9UGoiENNLP6XjiHQtIYgACDmo"]
[Tue Jul 21 08:12:27.049665 2026] [security2:error] [pid 402041:tid 402177] [client 104.207.50.254:51071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.elitegeo.com.br"] [uri "/wp-login.php"] [unique_id "al9UGYiENNLP6XjiHQtIPwAAAZM"]
[Tue Jul 21 08:12:27.066194 2026] [security2:error] [pid 402041:tid 402245] [client 20.104.96.117:62538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wmore1.php"] [unique_id "al9UG4iENNLP6XjiHQtIaAAAAdc"]
[Tue Jul 21 08:12:27.163175 2026] [security2:error] [pid 402041:tid 402294] [client 103.78.200.11:64933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UG4iENNLP6XjiHQtIawAAAgg"]
[Tue Jul 21 08:12:27.163900 2026] [security2:error] [pid 402041:tid 402294] [client 103.78.200.11:64933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UG4iENNLP6XjiHQtIawAAAgg"]
[Tue Jul 21 08:12:27.201828 2026] [security2:error] [pid 402041:tid 402279] [client 20.220.225.223:30861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/2352356666.php"] [unique_id "al9UG4iENNLP6XjiHQtIbgAAAfk"]
[Tue Jul 21 08:12:27.676078 2026] [security2:error] [pid 402041:tid 402253] [client 20.151.10.161:13188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9UG4iENNLP6XjiHQtIeQAAAd8"]
[Tue Jul 21 08:12:27.676128 2026] [security2:error] [pid 402041:tid 402074] [remote 162.243.80.244:11688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oriorixas.blog.br"] [uri "/.env"] [unique_id "al9UG4iENNLP6XjiHQtIeAABwB4"]
[Tue Jul 21 08:12:27.877016 2026] [security2:error] [pid 402041:tid 402292] [client 87.116.180.198:13854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UG4iENNLP6XjiHQtIhAAAAgY"]
[Tue Jul 21 08:12:27.877130 2026] [security2:error] [pid 402041:tid 402292] [client 87.116.180.198:13854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UG4iENNLP6XjiHQtIhAAAAgY"]
[Tue Jul 21 08:12:27.882801 2026] [security2:error] [pid 402041:tid 402054] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UG4iENNLP6XjiHQtIhQACBQo"]
[Tue Jul 21 08:12:27.883012 2026] [security2:error] [pid 402041:tid 402291] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UG4iENNLP6XjiHQtIhQACBQo"]
[Tue Jul 21 08:12:28.127723 2026] [security2:error] [pid 402041:tid 402261] [client 20.104.96.117:54659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/root.php"] [unique_id "al9UHIiENNLP6XjiHQtIigAAAec"]
[Tue Jul 21 08:12:28.291588 2026] [security2:error] [pid 402041:tid 402051] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UGoiENNLP6XjiHQtISAAB3gc"]
[Tue Jul 21 08:12:28.291750 2026] [security2:error] [pid 402041:tid 402252] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UGoiENNLP6XjiHQtISAAB3gc"]
[Tue Jul 21 08:12:28.859637 2026] [security2:error] [pid 402041:tid 402296] [client 65.21.113.253:58682] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UHIiENNLP6XjiHQtIkwAAAgo"]
[Tue Jul 21 08:12:29.313504 2026] [security2:error] [pid 402041:tid 402258] [client 20.226.60.151:48827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/122.php"] [unique_id "al9UHYiENNLP6XjiHQtIqAAAAeQ"]
[Tue Jul 21 08:12:29.740298 2026] [security2:error] [pid 402041:tid 402280] [client 20.151.10.161:13196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9UHYiENNLP6XjiHQtIsgAAAfo"]
[Tue Jul 21 08:12:29.833388 2026] [security2:error] [pid 402041:tid 402233] [client 20.104.96.117:63424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/solo1.php"] [unique_id "al9UHYiENNLP6XjiHQtItwAAAcs"]
[Tue Jul 21 08:12:29.847440 2026] [security2:error] [pid 402041:tid 402232] [client 20.151.10.161:51021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/themes.php"] [unique_id "al9UHYiENNLP6XjiHQtIuAAAAco"]
[Tue Jul 21 08:12:30.346989 2026] [security2:error] [pid 402041:tid 402297] [client 20.226.60.151:48809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/get.php"] [unique_id "al9UHoiENNLP6XjiHQtIwwAAAgs"]
[Tue Jul 21 08:12:30.495177 2026] [security2:error] [pid 402041:tid 402268] [client 38.100.221.102:17723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UHoiENNLP6XjiHQtIyQAAAe4"]
[Tue Jul 21 08:12:30.495296 2026] [security2:error] [pid 402041:tid 402268] [client 38.100.221.102:17723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UHoiENNLP6XjiHQtIyQAAAe4"]
[Tue Jul 21 08:12:30.746808 2026] [security2:error] [pid 402041:tid 402300] [client 20.104.96.117:57972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-file-120.php"] [unique_id "al9UHoiENNLP6XjiHQtIywAAAg4"]
[Tue Jul 21 08:12:30.838036 2026] [security2:error] [pid 402041:tid 402294] [client 20.104.96.117:54682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/sym403.php"] [unique_id "al9UHoiENNLP6XjiHQtIzAAAAgg"]
[Tue Jul 21 08:12:30.920191 2026] [security2:error] [pid 402041:tid 402285] [client 20.226.60.151:49396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/as.php"] [unique_id "al9UHoiENNLP6XjiHQtI0QAAAf8"]
[Tue Jul 21 08:12:31.099693 2026] [security2:error] [pid 402041:tid 402258] [client 20.151.10.161:13264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/media.php"] [unique_id "al9UH4iENNLP6XjiHQtI2gAAAeQ"]
[Tue Jul 21 08:12:31.192793 2026] [security2:error] [pid 402041:tid 402178] [client 102.206.115.33:60498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UH4iENNLP6XjiHQtI2wAAAZQ"]
[Tue Jul 21 08:12:31.192944 2026] [security2:error] [pid 402041:tid 402178] [client 102.206.115.33:60498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UH4iENNLP6XjiHQtI2wAAAZQ"]
[Tue Jul 21 08:12:31.603010 2026] [security2:error] [pid 402041:tid 402214] [client 20.226.60.151:48772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/ccou.php"] [unique_id "al9UH4iENNLP6XjiHQtI6AAAAbg"]
[Tue Jul 21 08:12:31.651345 2026] [security2:error] [pid 402041:tid 402215] [client 111.93.58.162:11516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UH4iENNLP6XjiHQtI6QAAAbk"]
[Tue Jul 21 08:12:31.651541 2026] [security2:error] [pid 402041:tid 402215] [client 111.93.58.162:11516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UH4iENNLP6XjiHQtI6QAAAbk"]
[Tue Jul 21 08:12:31.684202 2026] [security2:error] [pid 402041:tid 402085] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UH4iENNLP6XjiHQtI6gAB_Sk"]
[Tue Jul 21 08:12:31.684421 2026] [security2:error] [pid 402041:tid 402283] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UH4iENNLP6XjiHQtI6gAB_Sk"]
[Tue Jul 21 08:12:31.974164 2026] [security2:error] [pid 402041:tid 402206] [client 20.151.10.161:13289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/images.php"] [unique_id "al9UH4iENNLP6XjiHQtI8QAAAbA"]
[Tue Jul 21 08:12:32.204625 2026] [security2:error] [pid 402041:tid 402228] [client 65.21.113.253:58682] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UH4iENNLP6XjiHQtI7AAAAcY"]
[Tue Jul 21 08:12:32.354913 2026] [security2:error] [pid 402041:tid 402088] [remote 117.0.21.154:52642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tryhealthonline.shop"] [uri "/wp-login.php"] [unique_id "al9UIIiENNLP6XjiHQtI9wABriw"]
[Tue Jul 21 08:12:32.602786 2026] [security2:error] [pid 402041:tid 402260] [client 20.151.10.161:13189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/adminner.php"] [unique_id "al9UIIiENNLP6XjiHQtJAwAAAeY"]
[Tue Jul 21 08:12:32.698525 2026] [security2:error] [pid 402041:tid 402210] [client 54.39.203.120:58386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "overkotz.com"] [uri "/robots.txt"] [unique_id "al9UIIiENNLP6XjiHQtJCAAAAbQ"]
[Tue Jul 21 08:12:32.698609 2026] [security2:error] [pid 402041:tid 402210] [client 54.39.203.120:58386] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "overkotz.com"] [uri "/robots.txt"] [unique_id "al9UIIiENNLP6XjiHQtJCAAAAbQ"]
[Tue Jul 21 08:12:32.886589 2026] [security2:error] [pid 402041:tid 402225] [client 20.226.60.151:49385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/w3lls.php"] [unique_id "al9UIIiENNLP6XjiHQtJDQAAAcM"]
[Tue Jul 21 08:12:32.963214 2026] [security2:error] [pid 402041:tid 402235] [client 20.151.10.161:13273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/admin.php"] [unique_id "al9UIIiENNLP6XjiHQtJDgAAAc0"]
[Tue Jul 21 08:12:33.347699 2026] [security2:error] [pid 402041:tid 402222] [client 20.151.10.161:13255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/k.php"] [unique_id "al9UIYiENNLP6XjiHQtJHAAAAcA"]
[Tue Jul 21 08:12:33.401719 2026] [security2:error] [pid 402041:tid 402286] [client 20.151.10.161:51040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/dx.php"] [unique_id "al9UIYiENNLP6XjiHQtJHgAAAgA"]
[Tue Jul 21 08:12:33.564539 2026] [security2:error] [pid 402041:tid 402275] [client 187.125.243.197:57228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UIYiENNLP6XjiHQtJJQAAAfU"]
[Tue Jul 21 08:12:33.564688 2026] [security2:error] [pid 402041:tid 402275] [client 187.125.243.197:57228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UIYiENNLP6XjiHQtJJQAAAfU"]
[Tue Jul 21 08:12:33.597019 2026] [security2:error] [pid 402041:tid 402188] [client 20.104.96.117:62987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/v543.php"] [unique_id "al9UIYiENNLP6XjiHQtJJgAAAZ4"]
[Tue Jul 21 08:12:33.641143 2026] [security2:error] [pid 402041:tid 402080] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UIYiENNLP6XjiHQtJJwABpyQ"]
[Tue Jul 21 08:12:33.641364 2026] [security2:error] [pid 402041:tid 402197] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UIYiENNLP6XjiHQtJJwABpyQ"]
[Tue Jul 21 08:12:33.684610 2026] [security2:error] [pid 402041:tid 402193] [client 20.151.10.161:13250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/x.php"] [unique_id "al9UIYiENNLP6XjiHQtJKwAAAaM"]
[Tue Jul 21 08:12:33.713317 2026] [security2:error] [pid 402041:tid 402186] [client 20.226.60.151:48775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/test1.php"] [unique_id "al9UIYiENNLP6XjiHQtJLAAAAZw"]
[Tue Jul 21 08:12:33.721161 2026] [security2:error] [pid 402041:tid 402209] [client 120.56.162.40:55781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UIYiENNLP6XjiHQtJLQAAAbM"]
[Tue Jul 21 08:12:33.721265 2026] [security2:error] [pid 402041:tid 402209] [client 120.56.162.40:55781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UIYiENNLP6XjiHQtJLQAAAbM"]
[Tue Jul 21 08:12:33.728699 2026] [security2:error] [pid 402041:tid 402233] [client 65.21.113.253:58682] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UIYiENNLP6XjiHQtJGwAAAcs"]
[Tue Jul 21 08:12:33.857258 2026] [security2:error] [pid 402041:tid 402265] [client 20.104.96.117:63469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/cong.php"] [unique_id "al9UIYiENNLP6XjiHQtJLwAAAes"]
[Tue Jul 21 08:12:33.880257 2026] [security2:error] [pid 402041:tid 402179] [client 103.151.46.103:53877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UIYiENNLP6XjiHQtJMAAAAZU"]
[Tue Jul 21 08:12:33.880623 2026] [security2:error] [pid 402041:tid 402179] [client 103.151.46.103:53877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UIYiENNLP6XjiHQtJMAAAAZU"]
[Tue Jul 21 08:12:34.108305 2026] [security2:error] [pid 402041:tid 402200] [client 20.151.10.161:13308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wss.php"] [unique_id "al9UIoiENNLP6XjiHQtJNgAAAao"]
[Tue Jul 21 08:12:34.290614 2026] [security2:error] [pid 402041:tid 402279] [client 51.161.37.2:37744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "overkotz.com"] [uri "/"] [unique_id "al9UIoiENNLP6XjiHQtJOgAAAfk"]
[Tue Jul 21 08:12:34.290696 2026] [security2:error] [pid 402041:tid 402279] [client 51.161.37.2:37744] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "overkotz.com"] [uri "/"] [unique_id "al9UIoiENNLP6XjiHQtJOgAAAfk"]
[Tue Jul 21 08:12:34.343331 2026] [security2:error] [pid 402041:tid 402260] [client 141.11.107.74:51903] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ftp.compressoresra.com.br"] [uri "/"] [unique_id "al9UIoiENNLP6XjiHQtJOwAAAeY"]
[Tue Jul 21 08:12:34.352496 2026] [security2:error] [pid 402041:tid 402259] [client 141.11.107.74:52018] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "compressoresra.com.br"] [uri "/"] [unique_id "al9UIoiENNLP6XjiHQtJPAAAAeU"]
[Tue Jul 21 08:12:34.539081 2026] [security2:error] [pid 402041:tid 402251] [client 150.129.202.39:64806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UIoiENNLP6XjiHQtJQgAAAd0"]
[Tue Jul 21 08:12:34.539229 2026] [security2:error] [pid 402041:tid 402251] [client 150.129.202.39:64806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UIoiENNLP6XjiHQtJQgAAAd0"]
[Tue Jul 21 08:12:34.541333 2026] [security2:error] [pid 402041:tid 402205] [client 20.151.10.161:13193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/ty.php"] [unique_id "al9UIoiENNLP6XjiHQtJQwAAAa8"]
[Tue Jul 21 08:12:34.851632 2026] [security2:error] [pid 402041:tid 402247] [client 20.220.225.223:30864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/pn.php"] [unique_id "al9UIoiENNLP6XjiHQtJTQAAAdk"]
[Tue Jul 21 08:12:34.877095 2026] [security2:error] [pid 402041:tid 402285] [client 65.21.113.253:58682] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UIoiENNLP6XjiHQtJPQAAAf8"]
[Tue Jul 21 08:12:34.895770 2026] [security2:error] [pid 402041:tid 402263] [client 20.151.10.161:13311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/155.php"] [unique_id "al9UIoiENNLP6XjiHQtJTgAAAek"]
[Tue Jul 21 08:12:35.108940 2026] [security2:error] [pid 402041:tid 402154] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UI4iENNLP6XjiHQtJVAAB8m4"]
[Tue Jul 21 08:12:35.109121 2026] [security2:error] [pid 402041:tid 402272] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UI4iENNLP6XjiHQtJVAAB8m4"]
[Tue Jul 21 08:12:35.183737 2026] [security2:error] [pid 402041:tid 402214] [client 20.151.10.161:13291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/ops.php"] [unique_id "al9UI4iENNLP6XjiHQtJVgAAAbg"]
[Tue Jul 21 08:12:35.453339 2026] [security2:error] [pid 402041:tid 402174] [client 154.208.47.43:43890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UI4iENNLP6XjiHQtJXAAAAZA"]
[Tue Jul 21 08:12:35.453629 2026] [security2:error] [pid 402041:tid 402174] [client 154.208.47.43:43890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UI4iENNLP6XjiHQtJXAAAAZA"]
[Tue Jul 21 08:12:35.498544 2026] [security2:error] [pid 402041:tid 402206] [client 20.151.10.161:13301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/ingfo.php"] [unique_id "al9UI4iENNLP6XjiHQtJXQAAAbA"]
[Tue Jul 21 08:12:35.519969 2026] [proxy:error] [pid 402041:tid 402197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:35.520032 2026] [proxy_http:error] [pid 402041:tid 402197] [client 87.236.176.63:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:12:35.520544 2026] [proxy:error] [pid 402041:tid 402197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:35.520573 2026] [proxy_http:error] [pid 402041:tid 402197] [client 87.236.176.63:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:12:35.605003 2026] [security2:error] [pid 402041:tid 402276] [client 20.104.96.117:57959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/special.php"] [unique_id "al9UI4iENNLP6XjiHQtJYwAAAfY"]
[Tue Jul 21 08:12:35.800109 2026] [security2:error] [pid 402041:tid 402293] [client 20.151.10.161:13184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/error_log.php"] [unique_id "al9UI4iENNLP6XjiHQtJaQAAAgc"]
[Tue Jul 21 08:12:35.993748 2026] [security2:error] [pid 402041:tid 402267] [client 20.226.60.151:48780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/database.php"] [unique_id "al9UI4iENNLP6XjiHQtJawAAAe0"]
[Tue Jul 21 08:12:36.104012 2026] [security2:error] [pid 402041:tid 402204] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UI4iENNLP6XjiHQtJagABrj0"]
[Tue Jul 21 08:12:36.241338 2026] [security2:error] [pid 402041:tid 402273] [client 20.151.10.161:13294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/ok.php"] [unique_id "al9UJIiENNLP6XjiHQtJdgAAAfM"]
[Tue Jul 21 08:12:36.501572 2026] [security2:error] [pid 402041:tid 402158] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UJIiENNLP6XjiHQtJfwABzHI"]
[Tue Jul 21 08:12:36.501721 2026] [security2:error] [pid 402041:tid 402234] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UJIiENNLP6XjiHQtJfwABzHI"]
[Tue Jul 21 08:12:36.717418 2026] [security2:error] [pid 402041:tid 402286] [client 20.151.10.161:13187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/mac.php"] [unique_id "al9UJIiENNLP6XjiHQtJigAAAgA"]
[Tue Jul 21 08:12:36.884183 2026] [security2:error] [pid 402041:tid 402175] [client 117.210.135.0:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UJIiENNLP6XjiHQtJlgAAAZE"]
[Tue Jul 21 08:12:36.884900 2026] [security2:error] [pid 402041:tid 402175] [client 117.210.135.0:61092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UJIiENNLP6XjiHQtJlgAAAZE"]
[Tue Jul 21 08:12:37.056036 2026] [security2:error] [pid 402041:tid 402206] [client 20.104.96.117:62534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/public/css.php"] [unique_id "al9UJYiENNLP6XjiHQtJnAAAAbA"]
[Tue Jul 21 08:12:37.069871 2026] [security2:error] [pid 402041:tid 402275] [client 20.104.96.117:54082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/sixxis.php"] [unique_id "al9UJYiENNLP6XjiHQtJnQAAAfU"]
[Tue Jul 21 08:12:37.286548 2026] [security2:error] [pid 402041:tid 402243] [client 20.151.10.161:13259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wefile.php"] [unique_id "al9UJYiENNLP6XjiHQtJogAAAdU"]
[Tue Jul 21 08:12:37.364571 2026] [security2:error] [pid 402041:tid 402218] [client 103.78.200.11:65425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UJYiENNLP6XjiHQtJpwAAAbw"]
[Tue Jul 21 08:12:37.364682 2026] [security2:error] [pid 402041:tid 402218] [client 103.78.200.11:65425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UJYiENNLP6XjiHQtJpwAAAbw"]
[Tue Jul 21 08:12:37.384204 2026] [security2:error] [pid 402041:tid 402159] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UJYiENNLP6XjiHQtJqAAB3nM"]
[Tue Jul 21 08:12:37.384420 2026] [security2:error] [pid 402041:tid 402252] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UJYiENNLP6XjiHQtJqAAB3nM"]
[Tue Jul 21 08:12:37.463118 2026] [security2:error] [pid 402041:tid 402209] [client 20.226.60.151:48852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/file.php"] [unique_id "al9UJYiENNLP6XjiHQtJqQAAAbM"]
[Tue Jul 21 08:12:37.590908 2026] [security2:error] [pid 402041:tid 402177] [client 20.151.10.161:13260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9UJYiENNLP6XjiHQtJqwAAAZM"]
[Tue Jul 21 08:12:37.617177 2026] [security2:error] [pid 402041:tid 402176] [client 177.93.4.113:56059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.4.93.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jacquelineandrade.com"] [uri "/xmlrpc.php"] [unique_id "al9UJYiENNLP6XjiHQtJrAAAAZI"]
[Tue Jul 21 08:12:37.617304 2026] [security2:error] [pid 402041:tid 402176] [client 177.93.4.113:56059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jacquelineandrade.com"] [uri "/xmlrpc.php"] [unique_id "al9UJYiENNLP6XjiHQtJrAAAAZI"]
[Tue Jul 21 08:12:37.719449 2026] [security2:error] [pid 402041:tid 402216] [client 20.104.96.117:60104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/as.php"] [unique_id "al9UJYiENNLP6XjiHQtJsAAAAbo"]
[Tue Jul 21 08:12:37.934867 2026] [security2:error] [pid 402041:tid 402202] [client 198.54.129.60:59626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9UJIiENNLP6XjiHQtJmQAAAaw"]
[Tue Jul 21 08:12:37.934970 2026] [security2:error] [pid 402041:tid 402202] [client 198.54.129.60:59626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9UJIiENNLP6XjiHQtJmQAAAaw"]
[Tue Jul 21 08:12:37.937330 2026] [security2:error] [pid 402041:tid 402134] [remote 34.141.178.234:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "angelogrimmmartini1751495600890.0711679.meusitehostgator.com.br"] [uri "/"] [unique_id "al9UJYiENNLP6XjiHQtJtgABtFo"]
[Tue Jul 21 08:12:37.937442 2026] [security2:error] [pid 402041:tid 402210] [client 34.141.178.234:0] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "angelogrimmmartini1751495600890.0711679.meusitehostgator.com.br"] [uri "/"] [unique_id "al9UJYiENNLP6XjiHQtJtgABtFo"]
[Tue Jul 21 08:12:38.278074 2026] [security2:error] [pid 402041:tid 402201] [client 162.219.176.3:53918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9UJoiENNLP6XjiHQtJuwAAAas"]
[Tue Jul 21 08:12:38.278164 2026] [security2:error] [pid 402041:tid 402201] [client 162.219.176.3:53918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9UJoiENNLP6XjiHQtJuwAAAas"]
[Tue Jul 21 08:12:38.391240 2026] [autoindex:error] [pid 402041:tid 402289] [client 20.151.10.161:13295] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:12:38.453453 2026] [security2:error] [pid 402041:tid 402065] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UJoiENNLP6XjiHQtJwwABohU"]
[Tue Jul 21 08:12:38.453654 2026] [security2:error] [pid 402041:tid 402192] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UJoiENNLP6XjiHQtJwwABohU"]
[Tue Jul 21 08:12:38.622169 2026] [security2:error] [pid 402041:tid 402225] [client 87.116.180.198:27291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UJoiENNLP6XjiHQtJxQAAAcM"]
[Tue Jul 21 08:12:38.626989 2026] [security2:error] [pid 402041:tid 402225] [client 87.116.180.198:27291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UJoiENNLP6XjiHQtJxQAAAcM"]
[Tue Jul 21 08:12:38.727718 2026] [security2:error] [pid 402041:tid 402298] [client 38.100.221.102:17990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UJoiENNLP6XjiHQtJygAAAgw"]
[Tue Jul 21 08:12:38.727838 2026] [security2:error] [pid 402041:tid 402298] [client 38.100.221.102:17990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UJoiENNLP6XjiHQtJygAAAgw"]
[Tue Jul 21 08:12:38.741409 2026] [security2:error] [pid 402041:tid 402271] [client 20.151.10.161:55860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/p.php"] [unique_id "al9UJoiENNLP6XjiHQtJzAAAAfE"]
[Tue Jul 21 08:12:38.849245 2026] [autoindex:error] [pid 402041:tid 402181] [client 20.151.10.161:13295] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:12:38.994163 2026] [security2:error] [pid 402041:tid 402253] [client 20.151.10.161:13263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wp-admin/css/colour.php"] [unique_id "al9UJoiENNLP6XjiHQtJ1gAAAd8"]
[Tue Jul 21 08:12:39.134494 2026] [security2:error] [pid 402041:tid 402283] [client 65.21.113.253:58682] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UJoiENNLP6XjiHQtJyQAAAf0"]
[Tue Jul 21 08:12:39.163798 2026] [security2:error] [pid 402041:tid 402228] [client 20.226.60.151:48886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/file.php"] [unique_id "al9UJ4iENNLP6XjiHQtJ2QAAAcY"]
[Tue Jul 21 08:12:39.788442 2026] [security2:error] [pid 402041:tid 402238] [client 20.104.96.117:57963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/cgi-bin/index.php"] [unique_id "al9UJ4iENNLP6XjiHQtJ6AAAAdA"]
[Tue Jul 21 08:12:40.028959 2026] [security2:error] [pid 402041:tid 402234] [client 20.104.96.117:62503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/output.php"] [unique_id "al9UKIiENNLP6XjiHQtJ8gAAAcw"]
[Tue Jul 21 08:12:40.053316 2026] [log_config:warn] [pid 358661:tid 358873] (32)Broken pipe: [client 123.136.25.128:8575] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:12:40.053336 2026] [log_config:warn] [pid 358661:tid 358873] (32)Broken pipe: [client 123.136.25.128:8575] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:12:40.367167 2026] [security2:error] [pid 402041:tid 402224] [client 20.151.10.161:13268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/like.php"] [unique_id "al9UKIiENNLP6XjiHQtJ-AAAAcI"]
[Tue Jul 21 08:12:40.417479 2026] [security2:error] [pid 402041:tid 402249] [client 20.151.10.161:50982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/bthil.php"] [unique_id "al9UKIiENNLP6XjiHQtJ_AAAAds"]
[Tue Jul 21 08:12:40.464338 2026] [security2:error] [pid 402041:tid 402256] [client 154.208.47.43:44323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UKIiENNLP6XjiHQtKAQAAAeI"]
[Tue Jul 21 08:12:40.464434 2026] [security2:error] [pid 402041:tid 402256] [client 154.208.47.43:44323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UKIiENNLP6XjiHQtKAQAAAeI"]
[Tue Jul 21 08:12:40.900189 2026] [security2:error] [pid 402041:tid 402070] [remote 159.65.81.207:45658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9UKIiENNLP6XjiHQtKDQABqRo"]
[Tue Jul 21 08:12:40.967233 2026] [security2:error] [pid 402041:tid 402228] [client 20.104.96.117:54111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/ip.php"] [unique_id "al9UKIiENNLP6XjiHQtKEQAAAcY"]
[Tue Jul 21 08:12:41.206404 2026] [security2:error] [pid 402041:tid 402216] [client 20.226.60.151:49386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/777.php"] [unique_id "al9UKYiENNLP6XjiHQtKGwAAAbo"]
[Tue Jul 21 08:12:41.242504 2026] [security2:error] [pid 402041:tid 402281] [client 20.151.10.161:50965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/7.php"] [unique_id "al9UKYiENNLP6XjiHQtKHQAAAfs"]
[Tue Jul 21 08:12:41.731329 2026] [security2:error] [pid 402041:tid 402209] [client 102.206.115.33:60707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UKYiENNLP6XjiHQtKKgAAAbM"]
[Tue Jul 21 08:12:41.731445 2026] [security2:error] [pid 402041:tid 402209] [client 102.206.115.33:60707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UKYiENNLP6XjiHQtKKgAAAbM"]
[Tue Jul 21 08:12:41.756680 2026] [security2:error] [pid 402041:tid 402196] [client 20.151.10.161:13274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/.well-known/about.php"] [unique_id "al9UKYiENNLP6XjiHQtKKwAAAaY"]
[Tue Jul 21 08:12:41.760057 2026] [security2:error] [pid 402041:tid 402187] [client 34.182.229.158:58644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.dorathiotoadvogados.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9UKYiENNLP6XjiHQtKLQAAAZ0"]
[Tue Jul 21 08:12:41.979430 2026] [security2:error] [pid 402041:tid 402258] [client 20.151.10.161:51034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/8.php"] [unique_id "al9UKYiENNLP6XjiHQtKNQAAAeQ"]
[Tue Jul 21 08:12:42.034696 2026] [security2:error] [pid 402041:tid 402206] [client 20.104.96.117:57956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/w1px.php"] [unique_id "al9UKoiENNLP6XjiHQtKNwAAAbA"]
[Tue Jul 21 08:12:42.090876 2026] [security2:error] [pid 402041:tid 402197] [client 20.151.10.161:13265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9UKoiENNLP6XjiHQtKOwAAAac"]
[Tue Jul 21 08:12:42.144473 2026] [security2:error] [pid 402041:tid 402112] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UKoiENNLP6XjiHQtKPAAB20Q"]
[Tue Jul 21 08:12:42.144621 2026] [security2:error] [pid 402041:tid 402249] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UKoiENNLP6XjiHQtKPAAB20Q"]
[Tue Jul 21 08:12:42.153919 2026] [security2:error] [pid 402041:tid 402232] [client 20.104.96.117:63481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-file-120.php"] [unique_id "al9UKoiENNLP6XjiHQtKPgAAAco"]
[Tue Jul 21 08:12:42.250803 2026] [security2:error] [pid 402041:tid 402223] [client 14.97.58.74:27880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UKoiENNLP6XjiHQtKQQAAAcE"]
[Tue Jul 21 08:12:42.250970 2026] [security2:error] [pid 402041:tid 402223] [client 14.97.58.74:27880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UKoiENNLP6XjiHQtKQQAAAcE"]
[Tue Jul 21 08:12:42.345099 2026] [security2:error] [pid 402041:tid 402186] [client 103.151.46.103:54379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UKoiENNLP6XjiHQtKRAAAAZw"]
[Tue Jul 21 08:12:42.345263 2026] [security2:error] [pid 402041:tid 402186] [client 103.151.46.103:54379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UKoiENNLP6XjiHQtKRAAAAZw"]
[Tue Jul 21 08:12:42.555534 2026] [security2:error] [pid 402041:tid 402293] [client 34.182.229.158:52859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.229.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.dorathiotoadvogados.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UKoiENNLP6XjiHQtKSgAAAgc"]
[Tue Jul 21 08:12:42.595798 2026] [security2:error] [pid 402041:tid 402173] [client 20.151.10.161:55847] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/1.php"] [unique_id "al9UKoiENNLP6XjiHQtKTwAAAY8"]
[Tue Jul 21 08:12:42.595904 2026] [security2:error] [pid 402041:tid 402173] [client 20.151.10.161:55847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/1.php"] [unique_id "al9UKoiENNLP6XjiHQtKTwAAAY8"]
[Tue Jul 21 08:12:42.608630 2026] [security2:error] [pid 402041:tid 402216] [client 20.104.96.117:54668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/kq1.php"] [unique_id "al9UKoiENNLP6XjiHQtKUAAAAbo"]
[Tue Jul 21 08:12:42.668884 2026] [security2:error] [pid 402041:tid 402213] [client 65.21.113.253:58682] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UKoiENNLP6XjiHQtKQAAAAbc"]
[Tue Jul 21 08:12:42.919905 2026] [autoindex:error] [pid 402041:tid 402217] [client 20.151.10.161:13295] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:12:42.982981 2026] [core:error] [pid 402041:tid 402205] [client 143.198.74.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:12:42.983000 2026] [core:error] [pid 402041:tid 402205] [client 143.198.74.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:12:43.173419 2026] [security2:error] [pid 402041:tid 402239] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UKoiENNLP6XjiHQtKUgAAAdE"]
[Tue Jul 21 08:12:43.309805 2026] [security2:error] [pid 402041:tid 402097] [remote 72.167.132.114:48744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9UK4iENNLP6XjiHQtKZQAB0DU"]
[Tue Jul 21 08:12:43.687328 2026] [security2:error] [pid 402041:tid 402197] [client 20.151.10.161:55855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/100.php"] [unique_id "al9UK4iENNLP6XjiHQtKcgAAAac"]
[Tue Jul 21 08:12:43.724994 2026] [autoindex:error] [pid 402041:tid 402231] [client 20.151.10.161:13295] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:12:43.874242 2026] [security2:error] [pid 402041:tid 402195] [client 20.151.10.161:13304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/pucci.php"] [unique_id "al9UK4iENNLP6XjiHQtKdgAAAaU"]
[Tue Jul 21 08:12:43.968955 2026] [security2:error] [pid 402041:tid 402243] [client 20.104.96.117:57937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/yawa.php"] [unique_id "al9UK4iENNLP6XjiHQtKegAAAdU"]
[Tue Jul 21 08:12:44.058628 2026] [security2:error] [pid 402041:tid 402268] [client 187.125.243.197:57685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ULIiENNLP6XjiHQtKfgAAAe4"]
[Tue Jul 21 08:12:44.058810 2026] [security2:error] [pid 402041:tid 402268] [client 187.125.243.197:57685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ULIiENNLP6XjiHQtKfgAAAe4"]
[Tue Jul 21 08:12:44.260739 2026] [security2:error] [pid 402041:tid 402125] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ULIiENNLP6XjiHQtKiwABnFE"]
[Tue Jul 21 08:12:44.260899 2026] [security2:error] [pid 402041:tid 402186] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ULIiENNLP6XjiHQtKiwABnFE"]
[Tue Jul 21 08:12:44.372359 2026] [security2:error] [pid 402041:tid 402276] [client 120.56.162.40:56287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ULIiENNLP6XjiHQtKjwAAAfY"]
[Tue Jul 21 08:12:44.372644 2026] [security2:error] [pid 402041:tid 402276] [client 120.56.162.40:56287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ULIiENNLP6XjiHQtKjwAAAfY"]
[Tue Jul 21 08:12:44.447681 2026] [security2:error] [pid 402041:tid 402202] [client 20.226.60.151:48814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/ssixta.php"] [unique_id "al9ULIiENNLP6XjiHQtKkQAAAaw"]
[Tue Jul 21 08:12:44.494174 2026] [security2:error] [pid 402041:tid 402209] [client 61.1.167.83:49763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ULIiENNLP6XjiHQtKkgAAAbM"]
[Tue Jul 21 08:12:44.494281 2026] [security2:error] [pid 402041:tid 402209] [client 61.1.167.83:49763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ULIiENNLP6XjiHQtKkgAAAbM"]
[Tue Jul 21 08:12:44.648973 2026] [security2:error] [pid 402041:tid 402119] [remote 8.217.108.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amandamorau.adv.br"] [uri "/wp-login.php"] [unique_id "al9ULIiENNLP6XjiHQtKlwACDUs"]
[Tue Jul 21 08:12:44.692917 2026] [security2:error] [pid 402041:tid 402270] [client 62.102.148.158:49296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9UKoiENNLP6XjiHQtKUQAAAfA"]
[Tue Jul 21 08:12:44.693017 2026] [security2:error] [pid 402041:tid 402270] [client 62.102.148.158:49296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9UKoiENNLP6XjiHQtKUQAAAfA"]
[Tue Jul 21 08:12:44.718727 2026] [security2:error] [pid 402041:tid 402153] [remote 97.74.93.24:58112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9ULIiENNLP6XjiHQtKngAB420"]
[Tue Jul 21 08:12:44.722775 2026] [security2:error] [pid 402041:tid 402222] [client 20.151.10.161:55810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/about.php"] [unique_id "al9ULIiENNLP6XjiHQtKnwAAAcA"]
[Tue Jul 21 08:12:44.726118 2026] [autoindex:error] [pid 402041:tid 402225] [client 20.151.10.161:13295] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:12:44.902584 2026] [security2:error] [pid 402041:tid 402192] [client 34.182.229.158:54828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.229.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.dorathiotoadvogados.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ULIiENNLP6XjiHQtKoQAAAaI"]
[Tue Jul 21 08:12:44.902727 2026] [security2:error] [pid 402041:tid 402192] [client 34.182.229.158:54828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.dorathiotoadvogados.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ULIiENNLP6XjiHQtKoQAAAaI"]
[Tue Jul 21 08:12:45.095299 2026] [security2:error] [pid 402041:tid 402175] [client 86.106.84.166:50326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9ULYiENNLP6XjiHQtKpQAAAZE"]
[Tue Jul 21 08:12:45.095388 2026] [security2:error] [pid 402041:tid 402175] [client 86.106.84.166:50326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9ULYiENNLP6XjiHQtKpQAAAZE"]
[Tue Jul 21 08:12:45.220489 2026] [security2:error] [pid 402041:tid 402300] [client 150.129.202.39:64819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ULYiENNLP6XjiHQtKqQAAAg4"]
[Tue Jul 21 08:12:45.220647 2026] [security2:error] [pid 402041:tid 402300] [client 150.129.202.39:64819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ULYiENNLP6XjiHQtKqQAAAg4"]
[Tue Jul 21 08:12:45.285666 2026] [security2:error] [pid 402041:tid 402105] [remote 69.171.234.25:36588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9ULYiENNLP6XjiHQtKpgABvz0"]
[Tue Jul 21 08:12:45.308360 2026] [autoindex:error] [pid 402041:tid 402219] [client 20.151.10.161:13295] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:12:45.445688 2026] [security2:error] [pid 402041:tid 402200] [client 20.151.10.161:13186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wp-temp.php"] [unique_id "al9ULYiENNLP6XjiHQtKswAAAao"]
[Tue Jul 21 08:12:45.737874 2026] [security2:error] [pid 402041:tid 402104] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9ULYiENNLP6XjiHQtKuwAB3jw"]
[Tue Jul 21 08:12:45.738021 2026] [security2:error] [pid 402041:tid 402252] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9ULYiENNLP6XjiHQtKuwAB3jw"]
[Tue Jul 21 08:12:46.013149 2026] [security2:error] [pid 402041:tid 402284] [client 20.104.96.117:54143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9ULoiENNLP6XjiHQtKwAAAAf4"]
[Tue Jul 21 08:12:46.154793 2026] [security2:error] [pid 402041:tid 402237] [client 162.219.176.3:34550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9ULoiENNLP6XjiHQtKxQAAAc8"]
[Tue Jul 21 08:12:46.154899 2026] [security2:error] [pid 402041:tid 402237] [client 162.219.176.3:34550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9ULoiENNLP6XjiHQtKxQAAAc8"]
[Tue Jul 21 08:12:46.233178 2026] [rewrite:warn] [pid 402041:tid 402116] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:12:46.650584 2026] [autoindex:error] [pid 402041:tid 402286] [client 20.151.10.161:13295] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:12:46.787034 2026] [security2:error] [pid 402041:tid 402298] [client 20.151.10.161:13224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/xmu.php"] [unique_id "al9ULoiENNLP6XjiHQtK4AAAAgw"]
[Tue Jul 21 08:12:46.792353 2026] [security2:error] [pid 402041:tid 402213] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ULoiENNLP6XjiHQtKzQAAAbc"]
[Tue Jul 21 08:12:46.824557 2026] [security2:error] [pid 402041:tid 402196] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ULoiENNLP6XjiHQtK2wABpkc"]
[Tue Jul 21 08:12:46.979763 2026] [proxy:error] [pid 402041:tid 402231] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:46.979855 2026] [proxy_http:error] [pid 402041:tid 402231] [client 143.244.57.121:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:12:46.980605 2026] [proxy:error] [pid 402041:tid 402231] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:46.980638 2026] [proxy_http:error] [pid 402041:tid 402231] [client 143.244.57.121:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:12:47.121941 2026] [security2:error] [pid 402041:tid 402058] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UL4iENNLP6XjiHQtK5QABuQ4"]
[Tue Jul 21 08:12:47.122132 2026] [security2:error] [pid 402041:tid 402215] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UL4iENNLP6XjiHQtK5QABuQ4"]
[Tue Jul 21 08:12:47.162890 2026] [security2:error] [pid 402041:tid 402181] [client 20.104.96.117:62586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/special.php"] [unique_id "al9UL4iENNLP6XjiHQtK5gAAAZc"]
[Tue Jul 21 08:12:47.264660 2026] [proxy:error] [pid 402041:tid 402293] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:47.264718 2026] [proxy_http:error] [pid 402041:tid 402293] [client 143.244.57.121:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:12:47.265253 2026] [proxy:error] [pid 402041:tid 402293] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:47.265281 2026] [proxy_http:error] [pid 402041:tid 402293] [client 143.244.57.121:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:12:47.297664 2026] [security2:error] [pid 402041:tid 402190] [client 20.104.96.117:58382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/js.php"] [unique_id "al9UL4iENNLP6XjiHQtK8QAAAaA"]
[Tue Jul 21 08:12:47.336325 2026] [security2:error] [pid 402041:tid 402177] [client 20.226.60.151:48860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/1c.php"] [unique_id "al9UL4iENNLP6XjiHQtK8gAAAZM"]
[Tue Jul 21 08:12:47.413761 2026] [security2:error] [pid 402041:tid 402272] [client 117.210.135.0:61753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UL4iENNLP6XjiHQtK8wAAAfI"]
[Tue Jul 21 08:12:47.413888 2026] [security2:error] [pid 402041:tid 402272] [client 117.210.135.0:61753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UL4iENNLP6XjiHQtK8wAAAfI"]
[Tue Jul 21 08:12:47.548068 2026] [security2:error] [pid 402041:tid 402186] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9UL4iENNLP6XjiHQtK9AAAAZw"]
[Tue Jul 21 08:12:47.721491 2026] [security2:error] [pid 402041:tid 402248] [client 20.151.10.161:51042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/admin.php"] [unique_id "al9UL4iENNLP6XjiHQtK-AAAAdo"]
[Tue Jul 21 08:12:47.882499 2026] [security2:error] [pid 402041:tid 402285] [client 20.151.10.161:13303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wp-admin/js/index.php"] [unique_id "al9UL4iENNLP6XjiHQtK_wAAAf8"]
[Tue Jul 21 08:12:48.041889 2026] [rewrite:warn] [pid 402041:tid 402065] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:12:48.122392 2026] [security2:error] [pid 402041:tid 402216] [client 103.78.200.11:49536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UMIiENNLP6XjiHQtLBQAAAbo"]
[Tue Jul 21 08:12:48.122588 2026] [security2:error] [pid 402041:tid 402216] [client 103.78.200.11:49536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UMIiENNLP6XjiHQtLBQAAAbo"]
[Tue Jul 21 08:12:48.203289 2026] [security2:error] [pid 402041:tid 402257] [client 20.151.10.161:13266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/puc.php"] [unique_id "al9UMIiENNLP6XjiHQtLBwAAAeM"]
[Tue Jul 21 08:12:48.309844 2026] [security2:error] [pid 402041:tid 402290] [client 20.104.96.117:54696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/h02ugyh.php"] [unique_id "al9UMIiENNLP6XjiHQtLDQAAAgQ"]
[Tue Jul 21 08:12:48.378364 2026] [security2:error] [pid 402041:tid 402298] [client 20.151.10.161:55888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/edit.php"] [unique_id "al9UMIiENNLP6XjiHQtLEAAAAgw"]
[Tue Jul 21 08:12:48.415029 2026] [security2:error] [pid 402041:tid 402196] [client 20.226.60.151:48829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/test2.php"] [unique_id "al9UMIiENNLP6XjiHQtLEQAAAaY"]
[Tue Jul 21 08:12:48.531281 2026] [security2:error] [pid 402041:tid 402152] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UMIiENNLP6XjiHQtLEwAB8Gw"]
[Tue Jul 21 08:12:48.531452 2026] [security2:error] [pid 402041:tid 402270] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UMIiENNLP6XjiHQtLEwAB8Gw"]
[Tue Jul 21 08:12:48.737609 2026] [core:error] [pid 402041:tid 402232] [client 143.198.74.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.solucaomodular.com.br/
[Tue Jul 21 08:12:48.737634 2026] [core:error] [pid 402041:tid 402232] [client 143.198.74.62:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.solucaomodular.com.br/
[Tue Jul 21 08:12:48.827955 2026] [security2:error] [pid 402041:tid 402279] [client 20.151.10.161:13203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/themes.php"] [unique_id "al9UMIiENNLP6XjiHQtLIAAAAfk"]
[Tue Jul 21 08:12:48.837947 2026] [security2:error] [pid 402041:tid 402234] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UL4iENNLP6XjiHQtK_QAAAcw"]
[Tue Jul 21 08:12:48.999404 2026] [security2:error] [pid 402041:tid 402272] [client 20.104.96.117:57939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/core.php"] [unique_id "al9UMIiENNLP6XjiHQtLJgAAAfI"]
[Tue Jul 21 08:12:49.081322 2026] [security2:error] [pid 402041:tid 402051] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UMYiENNLP6XjiHQtLKAAB1wc"]
[Tue Jul 21 08:12:49.081537 2026] [security2:error] [pid 402041:tid 402245] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UMYiENNLP6XjiHQtLKAAB1wc"]
[Tue Jul 21 08:12:49.124016 2026] [proxy:error] [pid 402041:tid 402264] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:49.124081 2026] [proxy_http:error] [pid 402041:tid 402264] [client 143.244.57.121:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:12:49.124724 2026] [proxy:error] [pid 402041:tid 402264] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:12:49.124764 2026] [proxy_http:error] [pid 402041:tid 402264] [client 143.244.57.121:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:12:49.245450 2026] [security2:error] [pid 402041:tid 402095] [remote 198.244.183.118:61428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "guianordestino.com.br"] [uri "/robots.txt"] [unique_id "al9UMYiENNLP6XjiHQtLLAAB7TM"]
[Tue Jul 21 08:12:49.245622 2026] [security2:error] [pid 402041:tid 402267] [client 198.244.183.118:61428] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "guianordestino.com.br"] [uri "/robots.txt"] [unique_id "al9UMYiENNLP6XjiHQtLLAAB7TM"]
[Tue Jul 21 08:12:49.252740 2026] [security2:error] [pid 402041:tid 402233] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UMIiENNLP6XjiHQtLIQAAAcs"]
[Tue Jul 21 08:12:49.310010 2026] [security2:error] [pid 402041:tid 402243] [client 87.116.180.198:27300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UMYiENNLP6XjiHQtLMQAAAdU"]
[Tue Jul 21 08:12:49.310141 2026] [security2:error] [pid 402041:tid 402243] [client 87.116.180.198:27300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UMYiENNLP6XjiHQtLMQAAAdU"]
[Tue Jul 21 08:12:49.336546 2026] [security2:error] [pid 402041:tid 402216] [client 20.151.10.161:55864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9UMYiENNLP6XjiHQtLNgAAAbo"]
[Tue Jul 21 08:12:49.410135 2026] [security2:error] [pid 402041:tid 402225] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9UMYiENNLP6XjiHQtLOwAAAcM"]
[Tue Jul 21 08:12:49.484549 2026] [security2:error] [pid 402041:tid 402265] [client 38.100.221.102:18942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UMYiENNLP6XjiHQtLPQAAAes"]
[Tue Jul 21 08:12:49.484661 2026] [security2:error] [pid 402041:tid 402265] [client 38.100.221.102:18942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UMYiENNLP6XjiHQtLPQAAAes"]
[Tue Jul 21 08:12:49.596463 2026] [autoindex:error] [pid 402041:tid 402298] [client 20.151.10.161:13295] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:12:49.648403 2026] [security2:error] [pid 402041:tid 402260] [client 154.208.47.43:44756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UMYiENNLP6XjiHQtLQQAAAeY"]
[Tue Jul 21 08:12:49.648562 2026] [security2:error] [pid 402041:tid 402260] [client 154.208.47.43:44756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UMYiENNLP6XjiHQtLQQAAAeY"]
[Tue Jul 21 08:12:49.650323 2026] [security2:error] [pid 402041:tid 402211] [client 74.7.175.192:40956] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.dezzign.eltonmelo.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9UMYiENNLP6XjiHQtLQAABtQs"]
[Tue Jul 21 08:12:49.694089 2026] [security2:error] [pid 402041:tid 402283] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9UMYiENNLP6XjiHQtLQwAAAf0"]
[Tue Jul 21 08:12:49.698425 2026] [security2:error] [pid 402041:tid 402247] [client 20.104.96.117:58429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/19.php"] [unique_id "al9UMYiENNLP6XjiHQtLRAAAAdk"]
[Tue Jul 21 08:12:49.750945 2026] [security2:error] [pid 402041:tid 402270] [client 20.151.10.161:13287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/8.php"] [unique_id "al9UMYiENNLP6XjiHQtLRQAAAfA"]
[Tue Jul 21 08:12:49.978802 2026] [security2:error] [pid 402041:tid 402177] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9UMYiENNLP6XjiHQtLUAAAAZM"]
[Tue Jul 21 08:12:50.264934 2026] [security2:error] [pid 402041:tid 402296] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9UMoiENNLP6XjiHQtLVgAAAgo"]
[Tue Jul 21 08:12:50.339725 2026] [security2:error] [pid 402041:tid 402259] [client 20.151.10.161:13299] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/1.php"] [unique_id "al9UMoiENNLP6XjiHQtLVwAAAeU"]
[Tue Jul 21 08:12:50.339855 2026] [security2:error] [pid 402041:tid 402259] [client 20.151.10.161:13299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/1.php"] [unique_id "al9UMoiENNLP6XjiHQtLVwAAAeU"]
[Tue Jul 21 08:12:50.400101 2026] [security2:error] [pid 402041:tid 402291] [client 20.226.60.151:48874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/buy.php"] [unique_id "al9UMoiENNLP6XjiHQtLWgAAAgU"]
[Tue Jul 21 08:12:50.462222 2026] [security2:error] [pid 402041:tid 402226] [client 20.151.10.161:51010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/f6.php"] [unique_id "al9UMoiENNLP6XjiHQtLYQAAAcQ"]
[Tue Jul 21 08:12:50.548964 2026] [security2:error] [pid 402041:tid 402285] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9UMoiENNLP6XjiHQtLYgAAAf8"]
[Tue Jul 21 08:12:50.564357 2026] [security2:error] [pid 402041:tid 402284] [client 20.104.96.117:60138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/inc.php"] [unique_id "al9UMoiENNLP6XjiHQtLYwAAAf4"]
[Tue Jul 21 08:12:50.776567 2026] [security2:error] [pid 402041:tid 402135] [remote 54.39.203.19:48078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "guianordestino.com.br"] [uri "/"] [unique_id "al9UMoiENNLP6XjiHQtLZgACDVs"]
[Tue Jul 21 08:12:50.776797 2026] [security2:error] [pid 402041:tid 402299] [client 54.39.203.19:48078] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "guianordestino.com.br"] [uri "/"] [unique_id "al9UMoiENNLP6XjiHQtLZgACDVs"]
[Tue Jul 21 08:12:50.833861 2026] [security2:error] [pid 402041:tid 402239] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9UMoiENNLP6XjiHQtLawAAAdE"]
[Tue Jul 21 08:12:50.986524 2026] [security2:error] [pid 402041:tid 402236] [client 20.104.96.117:63472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/as.php"] [unique_id "al9UMoiENNLP6XjiHQtLcgAAAc4"]
[Tue Jul 21 08:12:51.007865 2026] [security2:error] [pid 402041:tid 402260] [client 20.151.10.161:13256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/100.php"] [unique_id "al9UM4iENNLP6XjiHQtLdQAAAeY"]
[Tue Jul 21 08:12:51.070223 2026] [security2:error] [pid 402041:tid 402243] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UMoiENNLP6XjiHQtLZAAAAdU"]
[Tue Jul 21 08:12:51.118838 2026] [security2:error] [pid 402041:tid 402224] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9UM4iENNLP6XjiHQtLdgAAAcI"]
[Tue Jul 21 08:12:51.403719 2026] [security2:error] [pid 402041:tid 402185] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9UM4iENNLP6XjiHQtLfQAAAZs"]
[Tue Jul 21 08:12:51.534845 2026] [security2:error] [pid 402041:tid 402057] [remote 104.207.46.19:39123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.46.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9UM4iENNLP6XjiHQtLfAAB8A0"]
[Tue Jul 21 08:12:51.611350 2026] [security2:error] [pid 402041:tid 402190] [client 20.104.96.117:54204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9UM4iENNLP6XjiHQtLhAAAAaA"]
[Tue Jul 21 08:12:51.687447 2026] [security2:error] [pid 402041:tid 402177] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9UM4iENNLP6XjiHQtLhQAAAZM"]
[Tue Jul 21 08:12:51.738129 2026] [security2:error] [pid 402041:tid 402253] [client 103.151.46.103:54884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UM4iENNLP6XjiHQtLhgAAAd8"]
[Tue Jul 21 08:12:51.738259 2026] [security2:error] [pid 402041:tid 402253] [client 103.151.46.103:54884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UM4iENNLP6XjiHQtLhgAAAd8"]
[Tue Jul 21 08:12:51.743173 2026] [security2:error] [pid 402041:tid 402228] [client 20.151.10.161:55900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/inputs.php"] [unique_id "al9UM4iENNLP6XjiHQtLhwAAAcY"]
[Tue Jul 21 08:12:51.934827 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:51.934844 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:51.935228 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Globo-2.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:51.950112 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:51.950130 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:51.950547 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/IstoE.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:51.964210 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:51.964223 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:51.964543 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Terra.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:51.970926 2026] [security2:error] [pid 402041:tid 402291] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9UM4iENNLP6XjiHQtLjAAAAgU"]
[Tue Jul 21 08:12:51.973922 2026] [security2:error] [pid 402041:tid 402276] [client 20.151.10.161:13202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/about.php"] [unique_id "al9UM4iENNLP6XjiHQtLjgAAAfY"]
[Tue Jul 21 08:12:51.978195 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:51.978213 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:51.978417 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Caras.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:51.990823 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:51.990837 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:51.991477 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Contigo.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:52.008893 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:52.008909 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:52.009169 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Bons-Fluidos.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:52.022387 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:52.022398 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:52.022620 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Boa-Forma.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:52.034441 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:52.034468 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:52.034738 2026] [lsapi:warn] [pid 402041:tid 402283] [client 34.24.57.82:49632] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Lance.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:52.255572 2026] [security2:error] [pid 402041:tid 402262] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9UNIiENNLP6XjiHQtLkgAAAeg"]
[Tue Jul 21 08:12:52.310560 2026] [security2:error] [pid 402041:tid 402284] [client 20.151.10.161:55890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/av.php"] [unique_id "al9UNIiENNLP6XjiHQtLkwAAAf4"]
[Tue Jul 21 08:12:52.407644 2026] [security2:error] [pid 402041:tid 402299] [client 20.226.60.151:48807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/ssend.php"] [unique_id "al9UNIiENNLP6XjiHQtLlwAAAg0"]
[Tue Jul 21 08:12:52.497186 2026] [security2:error] [pid 402041:tid 402093] [remote 51.195.39.149:30950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "albuquerqueeharo.com"] [uri "/"] [unique_id "al9UNIiENNLP6XjiHQtLmQAB_zE"]
[Tue Jul 21 08:12:52.538921 2026] [security2:error] [pid 402041:tid 402281] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9UNIiENNLP6XjiHQtLngAAAfs"]
[Tue Jul 21 08:12:52.589405 2026] [security2:error] [pid 402041:tid 402236] [client 20.104.96.117:62979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-temp.php"] [unique_id "al9UNIiENNLP6XjiHQtLoAAAAc4"]
[Tue Jul 21 08:12:52.645127 2026] [security2:error] [pid 402041:tid 402175] [client 20.104.96.117:57926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9UNIiENNLP6XjiHQtLogAAAZE"]
[Tue Jul 21 08:12:52.676374 2026] [security2:error] [pid 402041:tid 402100] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UNIiENNLP6XjiHQtLowABrzg"]
[Tue Jul 21 08:12:52.676512 2026] [security2:error] [pid 402041:tid 402205] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UNIiENNLP6XjiHQtLowABrzg"]
[Tue Jul 21 08:12:52.678264 2026] [security2:error] [pid 402041:tid 402230] [client 102.206.115.33:64663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UNIiENNLP6XjiHQtLpAAAAcg"]
[Tue Jul 21 08:12:52.678407 2026] [security2:error] [pid 402041:tid 402230] [client 102.206.115.33:64663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UNIiENNLP6XjiHQtLpAAAAcg"]
[Tue Jul 21 08:12:52.750156 2026] [security2:error] [pid 402041:tid 402224] [client 20.151.10.161:51066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/classwithtostring.php"] [unique_id "al9UNIiENNLP6XjiHQtLpQAAAcI"]
[Tue Jul 21 08:12:52.845006 2026] [security2:error] [pid 402041:tid 402215] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9UNIiENNLP6XjiHQtLpgAAAbk"]
[Tue Jul 21 08:12:52.894141 2026] [security2:error] [pid 402041:tid 402261] [client 34.24.57.82:49632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "liranesuliano.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9UNIiENNLP6XjiHQtLpwAAAec"]
[Tue Jul 21 08:12:52.922328 2026] [security2:error] [pid 402041:tid 402258] [client 20.151.10.161:13241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/about.php"] [unique_id "al9UNIiENNLP6XjiHQtLqgAAAeQ"]
[Tue Jul 21 08:12:52.999038 2026] [security2:error] [pid 402041:tid 402226] [client 137.97.59.154:44661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UNIiENNLP6XjiHQtLrgAAAcQ"]
[Tue Jul 21 08:12:52.999206 2026] [security2:error] [pid 402041:tid 402226] [client 137.97.59.154:44661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UNIiENNLP6XjiHQtLrgAAAcQ"]
[Tue Jul 21 08:12:53.116982 2026] [security2:error] [pid 402041:tid 402270] [client 20.151.10.161:54931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9UNYiENNLP6XjiHQtLswAAAfA"]
[Tue Jul 21 08:12:53.130782 2026] [security2:error] [pid 402041:tid 402254] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9UNYiENNLP6XjiHQtLtAAAAeA"]
[Tue Jul 21 08:12:53.314547 2026] [security2:error] [pid 402041:tid 402300] [client 91.148.245.81:47124] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/"] [unique_id "al9UNYiENNLP6XjiHQtLtgAAAg4"]
[Tue Jul 21 08:12:53.314848 2026] [security2:error] [pid 402041:tid 402266] [client 91.148.245.81:47104] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/"] [unique_id "al9UNYiENNLP6XjiHQtLtwAAAew"]
[Tue Jul 21 08:12:53.375663 2026] [security2:error] [pid 402041:tid 402252] [client 34.24.57.82:63856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.24.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "liranesuliano.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UNYiENNLP6XjiHQtLuwAAAd4"]
[Tue Jul 21 08:12:53.414023 2026] [security2:error] [pid 402041:tid 402191] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9UNYiENNLP6XjiHQtLvwAAAaE"]
[Tue Jul 21 08:12:53.437441 2026] [security2:error] [pid 402041:tid 402097] [remote 193.56.28.115:41559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.28.56.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9UNYiENNLP6XjiHQtLwAAB2jU"]
[Tue Jul 21 08:12:53.494279 2026] [security2:error] [pid 402041:tid 402268] [client 20.151.10.161:13275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/admin.php"] [unique_id "al9UNYiENNLP6XjiHQtLxQAAAe4"]
[Tue Jul 21 08:12:53.612132 2026] [security2:error] [pid 402041:tid 402075] [remote 81.173.115.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vanderleiasilva.com.br"] [uri "/wp-login.php"] [unique_id "al9UNYiENNLP6XjiHQtLzgABsx8"]
[Tue Jul 21 08:12:53.674278 2026] [security2:error] [pid 402041:tid 402194] [client 20.104.96.117:58409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/ss.php"] [unique_id "al9UNYiENNLP6XjiHQtLzwAAAaQ"]
[Tue Jul 21 08:12:53.710695 2026] [security2:error] [pid 402041:tid 402218] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gabrielferreira1782822497721.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9UNYiENNLP6XjiHQtL0AAAAbw"]
[Tue Jul 21 08:12:53.748755 2026] [security2:error] [pid 402041:tid 402290] [client 20.151.10.161:50960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-blog.php"] [unique_id "al9UNYiENNLP6XjiHQtL0QAAAgQ"]
[Tue Jul 21 08:12:53.974063 2026] [security2:error] [pid 402041:tid 402081] [remote 192.241.143.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-login.php"] [unique_id "al9UNYiENNLP6XjiHQtL1wAB-iU"]
[Tue Jul 21 08:12:54.104418 2026] [security2:error] [pid 402041:tid 402295] [client 91.148.245.81:47148] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/backup.sql"] [unique_id "al9UNoiENNLP6XjiHQtL3gAAAgk"]
[Tue Jul 21 08:12:54.104584 2026] [security2:error] [pid 402041:tid 402217] [client 91.148.245.81:47138] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/config.xml"] [unique_id "al9UNoiENNLP6XjiHQtL3QAAAbs"]
[Tue Jul 21 08:12:54.105328 2026] [security2:error] [pid 402041:tid 402236] [client 91.148.245.81:47172] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9UNoiENNLP6XjiHQtL3wAAAc4"]
[Tue Jul 21 08:12:54.105579 2026] [security2:error] [pid 402041:tid 402247] [client 91.148.245.81:47160] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/config.php"] [unique_id "al9UNoiENNLP6XjiHQtL4AAAAdk"]
[Tue Jul 21 08:12:54.207325 2026] [security2:error] [pid 402041:tid 402197] [client 47.128.43.195:13326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carrosselbuique.com.br"] [uri "/robots.txt"] [unique_id "al9UNoiENNLP6XjiHQtL5AAAAac"]
[Tue Jul 21 08:12:54.270486 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.270509 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.270777 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Globo-2.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.282648 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.282667 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.282874 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/IstoE.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.294342 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.294347 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.294572 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Terra.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.306387 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.306403 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.306654 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Caras.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.320533 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.320546 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.320881 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Contigo.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.332870 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.332892 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.333120 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Bons-Fluidos.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.345368 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.345383 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.345584 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Boa-Forma.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.356763 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): SSL operation failed with code 1. OpenSSL Error messages:\nerror:0A000438:SSL routines::tlsv1 alert internal error in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.356776 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(): Failed to enable crypto in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.357009 2026] [lsapi:warn] [pid 402041:tid 402289] [client 34.24.57.82:60736] [host liranesuliano.com.br] Backend log: PHP Warning:  getimagesize(https://lab.visior.co/wp-content/uploads/2024/07/Lance.webp): failed to open stream: operation failed in /home2/acupu265/public_html/liranesuliano.com.br/wp-content/plugins/litespeed-cache/src/media.cls.php on line 1158\n
[Tue Jul 21 08:12:54.380894 2026] [security2:error] [pid 402041:tid 402228] [client 20.151.10.161:13248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/admin.php"] [unique_id "al9UNoiENNLP6XjiHQtL5wAAAcY"]
[Tue Jul 21 08:12:54.384041 2026] [security2:error] [pid 402041:tid 402251] [client 20.220.225.223:30669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/dr.php"] [unique_id "al9UNoiENNLP6XjiHQtL6AAAAd0"]
[Tue Jul 21 08:12:54.566734 2026] [security2:error] [pid 402041:tid 402203] [client 187.125.243.197:58149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UNoiENNLP6XjiHQtL8QAAAa0"]
[Tue Jul 21 08:12:54.567441 2026] [security2:error] [pid 402041:tid 402203] [client 187.125.243.197:58149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UNoiENNLP6XjiHQtL8QAAAa0"]
[Tue Jul 21 08:12:54.586177 2026] [security2:error] [pid 402041:tid 402109] [remote 45.79.123.44:42254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "escoladaseguranca.com.br"] [uri "/wp-login.php"] [unique_id "al9UNoiENNLP6XjiHQtL9AAB9UE"]
[Tue Jul 21 08:12:54.626001 2026] [security2:error] [pid 402041:tid 402208] [client 20.104.96.117:54187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/min.php"] [unique_id "al9UNoiENNLP6XjiHQtL9gAAAbI"]
[Tue Jul 21 08:12:54.777776 2026] [security2:error] [pid 402041:tid 402209] [client 20.151.10.161:50958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9UNoiENNLP6XjiHQtL-wAAAbM"]
[Tue Jul 21 08:12:54.829870 2026] [security2:error] [pid 402041:tid 402062] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UNoiENNLP6XjiHQtL_AAB5RI"]
[Tue Jul 21 08:12:54.830055 2026] [security2:error] [pid 402041:tid 402259] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UNoiENNLP6XjiHQtL_AAB5RI"]
[Tue Jul 21 08:12:54.972688 2026] [security2:error] [pid 402041:tid 402248] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UNoiENNLP6XjiHQtL7wAAAdo"]
[Tue Jul 21 08:12:55.021357 2026] [security2:error] [pid 402041:tid 402270] [client 120.56.162.40:56798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UN4iENNLP6XjiHQtL_gAAAfA"]
[Tue Jul 21 08:12:55.021511 2026] [security2:error] [pid 402041:tid 402270] [client 120.56.162.40:56798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UN4iENNLP6XjiHQtL_gAAAfA"]
[Tue Jul 21 08:12:55.074736 2026] [security2:error] [pid 402041:tid 402253] [client 91.148.245.81:47224] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/wp-config.php"] [unique_id "al9UN4iENNLP6XjiHQtMAQAAAd8"]
[Tue Jul 21 08:12:55.074829 2026] [security2:error] [pid 402041:tid 402257] [client 91.148.245.81:47200] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/database_backup.sql"] [unique_id "al9UN4iENNLP6XjiHQtMAgAAAeM"]
[Tue Jul 21 08:12:55.075448 2026] [security2:error] [pid 402041:tid 402274] [client 91.148.245.81:47178] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/.git/HEAD"] [unique_id "al9UN4iENNLP6XjiHQtMAwAAAfQ"]
[Tue Jul 21 08:12:55.075672 2026] [security2:error] [pid 402041:tid 402210] [client 91.148.245.81:47180] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/database.sql"] [unique_id "al9UN4iENNLP6XjiHQtMBAAAAbQ"]
[Tue Jul 21 08:12:55.234158 2026] [security2:error] [pid 402041:tid 402092] [remote 65.111.0.96:22545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.0.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9UN4iENNLP6XjiHQtMDAACADA"]
[Tue Jul 21 08:12:55.276343 2026] [security2:error] [pid 402041:tid 402285] [client 91.148.245.81:47192] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/secrets.json"] [unique_id "al9UN4iENNLP6XjiHQtMDgAAAf8"]
[Tue Jul 21 08:12:55.276496 2026] [security2:error] [pid 402041:tid 402218] [client 91.148.245.81:47216] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/.npmrc"] [unique_id "al9UN4iENNLP6XjiHQtMDwAAAbw"]
[Tue Jul 21 08:12:55.276894 2026] [security2:error] [pid 402041:tid 402194] [client 91.148.245.81:47176] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/.bash_history"] [unique_id "al9UN4iENNLP6XjiHQtMEAAAAaQ"]
[Tue Jul 21 08:12:55.541178 2026] [security2:error] [pid 402041:tid 402250] [client 20.151.10.161:13128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/edit.php"] [unique_id "al9UN4iENNLP6XjiHQtMEgAAAdw"]
[Tue Jul 21 08:12:55.912946 2026] [security2:error] [pid 402041:tid 402203] [client 20.104.96.117:57968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9UN4iENNLP6XjiHQtMHQAAAa0"]
[Tue Jul 21 08:12:55.940303 2026] [security2:error] [pid 402041:tid 402219] [client 150.129.202.39:64787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UN4iENNLP6XjiHQtMHgAAAb0"]
[Tue Jul 21 08:12:55.940460 2026] [security2:error] [pid 402041:tid 402219] [client 150.129.202.39:64787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UN4iENNLP6XjiHQtMHgAAAb0"]
[Tue Jul 21 08:12:55.975791 2026] [security2:error] [pid 402041:tid 402206] [client 20.104.96.117:62554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9UN4iENNLP6XjiHQtMHwAAAbA"]
[Tue Jul 21 08:12:55.993857 2026] [security2:error] [pid 402041:tid 402082] [remote 45.79.123.44:57174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/wp-login.php"] [unique_id "al9UN4iENNLP6XjiHQtMIAAByyY"]
[Tue Jul 21 08:12:56.019045 2026] [security2:error] [pid 402041:tid 402202] [client 20.151.10.161:51058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/adminfuns.php"] [unique_id "al9UOIiENNLP6XjiHQtMIQAAAaw"]
[Tue Jul 21 08:12:56.045292 2026] [security2:error] [pid 402041:tid 402167] [remote 207.180.241.245:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-login.php"] [unique_id "al9UOIiENNLP6XjiHQtMIgAB-Hs"]
[Tue Jul 21 08:12:56.344165 2026] [security2:error] [pid 402041:tid 402216] [client 20.151.10.161:13251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wp-content/admin.php"] [unique_id "al9UOIiENNLP6XjiHQtMLgAAAbo"]
[Tue Jul 21 08:12:56.355002 2026] [security2:error] [pid 402041:tid 402107] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UOIiENNLP6XjiHQtMLwAB8j8"]
[Tue Jul 21 08:12:56.355139 2026] [security2:error] [pid 402041:tid 402272] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UOIiENNLP6XjiHQtMLwAB8j8"]
[Tue Jul 21 08:12:56.444736 2026] [security2:error] [pid 402041:tid 402192] [client 20.226.60.151:48822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/item.php"] [unique_id "al9UOIiENNLP6XjiHQtMMAAAAaI"]
[Tue Jul 21 08:12:56.689012 2026] [security2:error] [pid 402041:tid 402229] [client 74.7.244.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.fidellium.com"] [uri "/index.php"] [unique_id "al9UN4iENNLP6XjiHQtMAAABx20"]
[Tue Jul 21 08:12:56.862374 2026] [security2:error] [pid 402041:tid 402247] [client 20.151.10.161:13276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/f6.php"] [unique_id "al9UOIiENNLP6XjiHQtMQAAAAdk"]
[Tue Jul 21 08:12:57.229888 2026] [security2:error] [pid 402041:tid 402281] [client 74.7.244.59:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fidellium.com"] [uri "/index.php"] [unique_id "al9UOYiENNLP6XjiHQtMRAAB-3M"], referer: https://www.fidellium.com/robots.txt
[Tue Jul 21 08:12:57.250928 2026] [security2:error] [pid 402041:tid 402199] [client 20.151.10.161:55868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/goods.php"] [unique_id "al9UOYiENNLP6XjiHQtMTwAAAak"]
[Tue Jul 21 08:12:57.289594 2026] [security2:error] [pid 402041:tid 402242] [client 20.104.96.117:57934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/autoload_classmap.php"] [unique_id "al9UOYiENNLP6XjiHQtMUQAAAdQ"]
[Tue Jul 21 08:12:57.606557 2026] [security2:error] [pid 402041:tid 402294] [client 20.151.10.161:13127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/inputs.php"] [unique_id "al9UOYiENNLP6XjiHQtMUwAAAgg"]
[Tue Jul 21 08:12:57.809063 2026] [security2:error] [pid 402041:tid 402065] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UOYiENNLP6XjiHQtMXgAB4hU"]
[Tue Jul 21 08:12:57.809203 2026] [security2:error] [pid 402041:tid 402256] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UOYiENNLP6XjiHQtMXgAB4hU"]
[Tue Jul 21 08:12:57.956291 2026] [security2:error] [pid 402041:tid 402221] [client 117.210.135.0:62394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UOYiENNLP6XjiHQtMYQAAAb8"]
[Tue Jul 21 08:12:57.956397 2026] [security2:error] [pid 402041:tid 402221] [client 117.210.135.0:62394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UOYiENNLP6XjiHQtMYQAAAb8"]
[Tue Jul 21 08:12:57.999244 2026] [security2:error] [pid 402041:tid 402297] [client 20.151.10.161:51024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ms-edit.php"] [unique_id "al9UOYiENNLP6XjiHQtMYgAAAgs"]
[Tue Jul 21 08:12:58.058702 2026] [security2:error] [pid 402041:tid 402222] [client 20.104.96.117:54710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9UOoiENNLP6XjiHQtMYwAAAcA"]
[Tue Jul 21 08:12:58.105661 2026] [security2:error] [pid 402041:tid 402227] [client 20.151.10.161:13298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/inputs.php"] [unique_id "al9UOoiENNLP6XjiHQtMZAAAAcU"]
[Tue Jul 21 08:12:58.190790 2026] [security2:error] [pid 402041:tid 402278] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UOYiENNLP6XjiHQtMWAAAAfg"]
[Tue Jul 21 08:12:58.477063 2026] [security2:error] [pid 402041:tid 402220] [client 20.104.96.117:54183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-link-zorm.php"] [unique_id "al9UOoiENNLP6XjiHQtMbwAAAb4"]
[Tue Jul 21 08:12:58.532341 2026] [security2:error] [pid 402041:tid 402224] [client 34.24.57.82:60736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.57.24.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "liranesuliano.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UOoiENNLP6XjiHQtMcAAAAcI"]
[Tue Jul 21 08:12:58.532480 2026] [security2:error] [pid 402041:tid 402224] [client 34.24.57.82:60736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "liranesuliano.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UOoiENNLP6XjiHQtMcAAAAcI"]
[Tue Jul 21 08:12:58.830398 2026] [security2:error] [pid 402041:tid 402284] [client 103.78.200.11:50034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UOoiENNLP6XjiHQtMegAAAf4"]
[Tue Jul 21 08:12:58.830526 2026] [security2:error] [pid 402041:tid 402284] [client 103.78.200.11:50034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UOoiENNLP6XjiHQtMegAAAf4"]
[Tue Jul 21 08:12:58.835709 2026] [security2:error] [pid 402041:tid 402236] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UOoiENNLP6XjiHQtMdQABzi8"]
[Tue Jul 21 08:12:58.877681 2026] [security2:error] [pid 402041:tid 402188] [client 20.151.10.161:13269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/av.php"] [unique_id "al9UOoiENNLP6XjiHQtMfAAAAZ4"]
[Tue Jul 21 08:12:59.161203 2026] [security2:error] [pid 402041:tid 402235] [client 74.7.241.181:55150] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "educacao.agendaclique.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9UO4iENNLP6XjiHQtMggABzTM"]
[Tue Jul 21 08:12:59.267178 2026] [security2:error] [pid 402041:tid 402204] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UOoiENNLP6XjiHQtMeQAAAa4"]
[Tue Jul 21 08:12:59.433928 2026] [security2:error] [pid 402041:tid 402173] [client 20.104.96.117:57981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9UO4iENNLP6XjiHQtMjgAAAY8"]
[Tue Jul 21 08:12:59.560984 2026] [security2:error] [pid 402041:tid 402053] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UO4iENNLP6XjiHQtMkQABvwk"]
[Tue Jul 21 08:12:59.561198 2026] [security2:error] [pid 402041:tid 402221] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UO4iENNLP6XjiHQtMkQABvwk"]
[Tue Jul 21 08:12:59.586708 2026] [security2:error] [pid 402041:tid 402055] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UO4iENNLP6XjiHQtMkgAB0Qs"]
[Tue Jul 21 08:12:59.586927 2026] [security2:error] [pid 402041:tid 402239] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UO4iENNLP6XjiHQtMkgAB0Qs"]
[Tue Jul 21 08:12:59.674124 2026] [security2:error] [pid 402041:tid 402297] [client 20.151.10.161:51069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/222.php"] [unique_id "al9UO4iENNLP6XjiHQtMlAAAAgs"]
[Tue Jul 21 08:13:00.014572 2026] [security2:error] [pid 402041:tid 402208] [client 87.116.180.198:27278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UPIiENNLP6XjiHQtMnwAAAbI"]
[Tue Jul 21 08:13:00.016864 2026] [security2:error] [pid 402041:tid 402208] [client 87.116.180.198:27278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UPIiENNLP6XjiHQtMnwAAAbI"]
[Tue Jul 21 08:13:00.090249 2026] [security2:error] [pid 402041:tid 402256] [client 38.100.221.102:19092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UPIiENNLP6XjiHQtMowAAAeI"]
[Tue Jul 21 08:13:00.090641 2026] [security2:error] [pid 402041:tid 402256] [client 38.100.221.102:19092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UPIiENNLP6XjiHQtMowAAAeI"]
[Tue Jul 21 08:13:00.216242 2026] [security2:error] [pid 402041:tid 402295] [client 20.151.10.161:13254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/classwithtostring.php"] [unique_id "al9UPIiENNLP6XjiHQtMqAAAAgk"]
[Tue Jul 21 08:13:00.479766 2026] [security2:error] [pid 402041:tid 402200] [client 20.226.60.151:48894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/ss.php"] [unique_id "al9UPIiENNLP6XjiHQtMrgAAAao"]
[Tue Jul 21 08:13:00.757062 2026] [security2:error] [pid 402041:tid 402204] [client 20.151.10.161:13200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wp-content/themes/index.php"] [unique_id "al9UPIiENNLP6XjiHQtMtwAAAa4"]
[Tue Jul 21 08:13:00.768880 2026] [security2:error] [pid 402041:tid 402294] [client 20.104.96.117:54126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9UPIiENNLP6XjiHQtMuAAAAgg"]
[Tue Jul 21 08:13:00.868109 2026] [security2:error] [pid 402041:tid 402275] [client 20.104.96.117:58397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/albin.php"] [unique_id "al9UPIiENNLP6XjiHQtMwAAAAfU"]
[Tue Jul 21 08:13:00.871225 2026] [security2:error] [pid 402041:tid 402177] [client 20.151.10.161:55896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9UPIiENNLP6XjiHQtMwQAAAZM"]
[Tue Jul 21 08:13:00.908958 2026] [security2:error] [pid 402041:tid 402242] [client 91.148.245.81:47242] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/actuator/heapdump"] [unique_id "al9UPIiENNLP6XjiHQtMwgAAAdQ"]
[Tue Jul 21 08:13:00.909304 2026] [security2:error] [pid 402041:tid 402199] [client 91.148.245.81:47254] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/config/production.json"] [unique_id "al9UPIiENNLP6XjiHQtMwwAAAak"]
[Tue Jul 21 08:13:00.910481 2026] [security2:error] [pid 402041:tid 402231] [client 91.148.245.81:47256] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/user_secrets.yml"] [unique_id "al9UPIiENNLP6XjiHQtMxAAAAck"]
[Tue Jul 21 08:13:00.910774 2026] [security2:error] [pid 402041:tid 402185] [client 91.148.245.81:47234] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/.env"] [unique_id "al9UPIiENNLP6XjiHQtMxQAAAZs"]
[Tue Jul 21 08:13:01.112967 2026] [security2:error] [pid 402041:tid 402234] [client 91.148.245.81:47276] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/docker-compose.yml"] [unique_id "al9UPYiENNLP6XjiHQtMyQAAAcw"]
[Tue Jul 21 08:13:01.113016 2026] [security2:error] [pid 402041:tid 402179] [client 91.148.245.81:47266] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/phpinfo.php"] [unique_id "al9UPYiENNLP6XjiHQtMygAAAZU"]
[Tue Jul 21 08:13:01.113524 2026] [security2:error] [pid 402041:tid 402245] [client 91.148.245.81:47280] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9UPYiENNLP6XjiHQtMywAAAdc"]
[Tue Jul 21 08:13:01.262014 2026] [security2:error] [pid 402041:tid 402180] [client 20.104.96.117:63453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/w1px.php"] [unique_id "al9UPYiENNLP6XjiHQtMzQAAAZY"]
[Tue Jul 21 08:13:01.312562 2026] [security2:error] [pid 402041:tid 402263] [client 20.151.10.161:13121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wp-blog.php"] [unique_id "al9UPYiENNLP6XjiHQtM0AAAAek"]
[Tue Jul 21 08:13:01.541822 2026] [security2:error] [pid 402041:tid 402220] [client 154.208.47.43:45172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UPYiENNLP6XjiHQtM2AAAAb4"]
[Tue Jul 21 08:13:01.541929 2026] [security2:error] [pid 402041:tid 402220] [client 154.208.47.43:45172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UPYiENNLP6XjiHQtM2AAAAb4"]
[Tue Jul 21 08:13:01.780328 2026] [security2:error] [pid 402041:tid 402235] [client 20.104.96.117:57927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/cilus.php"] [unique_id "al9UPYiENNLP6XjiHQtM4AAAAc0"]
[Tue Jul 21 08:13:01.876907 2026] [security2:error] [pid 402041:tid 402260] [client 91.148.245.81:47302] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/.env.production"] [unique_id "al9UPYiENNLP6XjiHQtM4gAAAeY"]
[Tue Jul 21 08:13:01.877626 2026] [security2:error] [pid 402041:tid 402248] [client 91.148.245.81:47322] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/server.key"] [unique_id "al9UPYiENNLP6XjiHQtM4wAAAdo"]
[Tue Jul 21 08:13:01.878129 2026] [security2:error] [pid 402041:tid 402241] [client 91.148.245.81:47308] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9UPYiENNLP6XjiHQtM5AAAAdM"]
[Tue Jul 21 08:13:01.878273 2026] [security2:error] [pid 402041:tid 402205] [client 91.148.245.81:47288] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9UPYiENNLP6XjiHQtM5QAAAa8"]
[Tue Jul 21 08:13:02.049548 2026] [security2:error] [pid 402041:tid 402283] [client 20.151.10.161:50981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9UPoiENNLP6XjiHQtM6wAAAf0"]
[Tue Jul 21 08:13:02.080532 2026] [security2:error] [pid 402041:tid 402284] [client 91.148.245.81:47352] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9UPoiENNLP6XjiHQtM7QAAAf4"]
[Tue Jul 21 08:13:02.080657 2026] [security2:error] [pid 402041:tid 402272] [client 91.148.245.81:47328] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/.svn/wc.db"] [unique_id "al9UPoiENNLP6XjiHQtM7gAAAfI"]
[Tue Jul 21 08:13:02.081481 2026] [security2:error] [pid 402041:tid 402218] [client 91.148.245.81:47342] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/api/.env"] [unique_id "al9UPoiENNLP6XjiHQtM7wAAAbw"]
[Tue Jul 21 08:13:02.150693 2026] [access_compat:error] [pid 402041:tid 402185] [client 162.241.63.68:57830] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:13:02.238090 2026] [security2:error] [pid 402041:tid 402197] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UPYiENNLP6XjiHQtM3QAAAac"]
[Tue Jul 21 08:13:02.516358 2026] [security2:error] [pid 402041:tid 402229] [client 20.104.96.117:54178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/gptsh.php"] [unique_id "al9UPoiENNLP6XjiHQtM_QAAAcc"]
[Tue Jul 21 08:13:02.659053 2026] [security2:error] [pid 402041:tid 402233] [client 20.226.60.151:48823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/hypo.php"] [unique_id "al9UPoiENNLP6XjiHQtNAAAAAcs"]
[Tue Jul 21 08:13:02.784078 2026] [security2:error] [pid 402041:tid 402231] [client 102.206.115.33:63553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UPoiENNLP6XjiHQtNAQAAAck"]
[Tue Jul 21 08:13:02.784501 2026] [security2:error] [pid 402041:tid 402231] [client 102.206.115.33:63553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UPoiENNLP6XjiHQtNAQAAAck"]
[Tue Jul 21 08:13:02.853421 2026] [security2:error] [pid 402041:tid 402210] [client 91.148.245.81:47372] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9UPoiENNLP6XjiHQtNBQAAAbQ"]
[Tue Jul 21 08:13:02.854742 2026] [security2:error] [pid 402041:tid 402174] [client 91.148.245.81:47382] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/dump.sql"] [unique_id "al9UPoiENNLP6XjiHQtNBgAAAZA"]
[Tue Jul 21 08:13:02.855473 2026] [security2:error] [pid 402041:tid 402295] [client 91.148.245.81:47388] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9UPoiENNLP6XjiHQtNBwAAAgk"]
[Tue Jul 21 08:13:02.856281 2026] [security2:error] [pid 402041:tid 402178] [client 91.148.245.81:47378] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/backup.zip"] [unique_id "al9UPoiENNLP6XjiHQtNCAAAAZQ"]
[Tue Jul 21 08:13:03.058277 2026] [security2:error] [pid 402041:tid 402243] [client 91.148.245.81:47416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/backup.tar.gz"] [unique_id "al9UP4iENNLP6XjiHQtNEAAAAdU"]
[Tue Jul 21 08:13:03.058341 2026] [security2:error] [pid 402041:tid 402215] [client 91.148.245.81:47404] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "pousadanaturalis.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9UP4iENNLP6XjiHQtNDwAAAbk"]
[Tue Jul 21 08:13:03.155451 2026] [security2:error] [pid 402041:tid 402061] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UP4iENNLP6XjiHQtNEgABuxE"]
[Tue Jul 21 08:13:03.155690 2026] [security2:error] [pid 402041:tid 402217] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UP4iENNLP6XjiHQtNEgABuxE"]
[Tue Jul 21 08:13:03.228293 2026] [security2:error] [pid 402041:tid 402203] [client 20.104.96.117:54101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/jj.php"] [unique_id "al9UP4iENNLP6XjiHQtNFgAAAa0"]
[Tue Jul 21 08:13:03.380294 2026] [security2:error] [pid 402041:tid 402213] [client 20.104.96.117:63442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/yawa.php"] [unique_id "al9UP4iENNLP6XjiHQtNGgAAAbc"]
[Tue Jul 21 08:13:03.525593 2026] [security2:error] [pid 402041:tid 402185] [client 20.220.225.223:58372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/2x.php"] [unique_id "al9UP4iENNLP6XjiHQtNIQAAAZs"]
[Tue Jul 21 08:13:03.546355 2026] [security2:error] [pid 402041:tid 402232] [client 14.97.58.74:62110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UP4iENNLP6XjiHQtNIgAAAco"]
[Tue Jul 21 08:13:03.546554 2026] [security2:error] [pid 402041:tid 402232] [client 14.97.58.74:62110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UP4iENNLP6XjiHQtNIgAAAco"]
[Tue Jul 21 08:13:03.560312 2026] [security2:error] [pid 402041:tid 402173] [client 74.7.241.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "marciohenriqueteixei1782901626000.0721679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9UP4iENNLP6XjiHQtNJgABj1U"]
[Tue Jul 21 08:13:03.692349 2026] [autoindex:error] [pid 402041:tid 402268] [client 20.151.10.161:13266] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:13:03.827377 2026] [security2:error] [pid 402041:tid 402206] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UP4iENNLP6XjiHQtNGwAAAbA"]
[Tue Jul 21 08:13:03.934138 2026] [security2:error] [pid 402041:tid 402245] [client 20.151.10.161:51062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp.php"] [unique_id "al9UP4iENNLP6XjiHQtNLwAAAdc"]
[Tue Jul 21 08:13:03.977664 2026] [security2:error] [pid 402041:tid 402267] [client 20.104.96.117:54180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/rithin.php"] [unique_id "al9UP4iENNLP6XjiHQtNMQAAAe0"]
[Tue Jul 21 08:13:04.176323 2026] [autoindex:error] [pid 402041:tid 402080] [remote 74.7.241.19:0] AH01276: Cannot serve directory /home2/mar26408/marciohenriqueteixei1782901626000.0721679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:13:04.542836 2026] [security2:error] [pid 402041:tid 402213] [client 20.151.10.161:13283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wp-content/admin.php"] [unique_id "al9UQIiENNLP6XjiHQtNSAAAAbc"]
[Tue Jul 21 08:13:04.577493 2026] [security2:error] [pid 402041:tid 402250] [client 198.54.129.60:50692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9UQIiENNLP6XjiHQtNSQAAAdw"]
[Tue Jul 21 08:13:04.577579 2026] [security2:error] [pid 402041:tid 402250] [client 198.54.129.60:50692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9UQIiENNLP6XjiHQtNSQAAAdw"]
[Tue Jul 21 08:13:04.585651 2026] [security2:error] [pid 402041:tid 402048] [remote 192.241.143.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9UQIiENNLP6XjiHQtNSgAB3gQ"]
[Tue Jul 21 08:13:05.050404 2026] [security2:error] [pid 402041:tid 402262] [client 187.125.243.197:58609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UQYiENNLP6XjiHQtNXgAAAeg"]
[Tue Jul 21 08:13:05.050500 2026] [security2:error] [pid 402041:tid 402262] [client 187.125.243.197:58609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UQYiENNLP6XjiHQtNXgAAAeg"]
[Tue Jul 21 08:13:05.178203 2026] [security2:error] [pid 402041:tid 402185] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UQIiENNLP6XjiHQtNUAAAAZs"]
[Tue Jul 21 08:13:05.329658 2026] [security2:error] [pid 402041:tid 402151] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UQYiENNLP6XjiHQtNagABpWs"]
[Tue Jul 21 08:13:05.329774 2026] [security2:error] [pid 402041:tid 402195] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UQYiENNLP6XjiHQtNagABpWs"]
[Tue Jul 21 08:13:05.330350 2026] [security2:error] [pid 402041:tid 402195] [client 34.138.76.29:59119] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "psicologo.guiiaz.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9UQYiENNLP6XjiHQtNawAAAaU"]
[Tue Jul 21 08:13:05.348027 2026] [security2:error] [pid 402041:tid 402260] [client 20.104.96.117:60127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/fffm.php"] [unique_id "al9UQYiENNLP6XjiHQtNbAAAAeY"]
[Tue Jul 21 08:13:05.482261 2026] [security2:error] [pid 402041:tid 402224] [client 20.226.60.151:49360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/users.php"] [unique_id "al9UQYiENNLP6XjiHQtNeQAAAcI"]
[Tue Jul 21 08:13:05.496725 2026] [security2:error] [pid 402041:tid 402242] [client 20.151.10.161:13300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/adminfuns.php"] [unique_id "al9UQYiENNLP6XjiHQtNfQAAAdQ"]
[Tue Jul 21 08:13:05.533163 2026] [security2:error] [pid 402041:tid 402270] [client 20.151.10.161:55809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/abcd.php"] [unique_id "al9UQYiENNLP6XjiHQtNggAAAfA"]
[Tue Jul 21 08:13:05.626899 2026] [security2:error] [pid 402041:tid 402245] [client 120.56.162.40:57288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UQYiENNLP6XjiHQtNlAAAAdc"]
[Tue Jul 21 08:13:05.627003 2026] [security2:error] [pid 402041:tid 402245] [client 120.56.162.40:57288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UQYiENNLP6XjiHQtNlAAAAdc"]
[Tue Jul 21 08:13:05.774086 2026] [security2:error] [pid 402041:tid 402300] [client 162.219.176.3:47174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9UQYiENNLP6XjiHQtNoAAAAg4"]
[Tue Jul 21 08:13:05.774186 2026] [security2:error] [pid 402041:tid 402300] [client 162.219.176.3:47174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9UQYiENNLP6XjiHQtNoAAAAg4"]
[Tue Jul 21 08:13:05.846957 2026] [security2:error] [pid 402041:tid 402283] [client 20.220.225.223:30694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/kq1.php"] [unique_id "al9UQYiENNLP6XjiHQtNowAAAf0"]
[Tue Jul 21 08:13:06.125796 2026] [security2:error] [pid 402041:tid 402178] [client 20.104.96.117:54701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9UQoiENNLP6XjiHQtNqgAAAZQ"]
[Tue Jul 21 08:13:06.246606 2026] [security2:error] [pid 402041:tid 402209] [client 62.102.148.158:48716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9UQoiENNLP6XjiHQtNrgAAAbM"]
[Tue Jul 21 08:13:06.246678 2026] [security2:error] [pid 402041:tid 402209] [client 62.102.148.158:48716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9UQoiENNLP6XjiHQtNrgAAAbM"]
[Tue Jul 21 08:13:06.253930 2026] [security2:error] [pid 402041:tid 402289] [client 34.138.76.29:55133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.76.138.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psicologo.guiiaz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UQoiENNLP6XjiHQtNrwAAAgM"]
[Tue Jul 21 08:13:06.466794 2026] [security2:error] [pid 402041:tid 402280] [client 20.151.10.161:13286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/goods.php"] [unique_id "al9UQoiENNLP6XjiHQtNtgAAAfo"]
[Tue Jul 21 08:13:06.470253 2026] [security2:error] [pid 402041:tid 402276] [client 150.129.202.39:65203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UQoiENNLP6XjiHQtNtwAAAfY"]
[Tue Jul 21 08:13:06.470366 2026] [security2:error] [pid 402041:tid 402276] [client 150.129.202.39:65203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UQoiENNLP6XjiHQtNtwAAAfY"]
[Tue Jul 21 08:13:06.568284 2026] [security2:error] [pid 402041:tid 402187] [client 61.1.167.83:50536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UQoiENNLP6XjiHQtNxgAAAZ0"]
[Tue Jul 21 08:13:06.568390 2026] [security2:error] [pid 402041:tid 402187] [client 61.1.167.83:50536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UQoiENNLP6XjiHQtNxgAAAZ0"]
[Tue Jul 21 08:13:06.750303 2026] [security2:error] [pid 402041:tid 402234] [client 151.63.71.144:54506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9UQoiENNLP6XjiHQtN0gAAAcw"]
[Tue Jul 21 08:13:06.750421 2026] [security2:error] [pid 402041:tid 402234] [client 151.63.71.144:54506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9UQoiENNLP6XjiHQtN0gAAAcw"]
[Tue Jul 21 08:13:06.767245 2026] [security2:error] [pid 402041:tid 402265] [client 20.104.96.117:58380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/dfre.php"] [unique_id "al9UQoiENNLP6XjiHQtN0wAAAes"]
[Tue Jul 21 08:13:06.975338 2026] [security2:error] [pid 402041:tid 402085] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UQoiENNLP6XjiHQtN3AAB5Sk"]
[Tue Jul 21 08:13:06.975470 2026] [security2:error] [pid 402041:tid 402259] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UQoiENNLP6XjiHQtN3AAB5Sk"]
[Tue Jul 21 08:13:07.094960 2026] [security2:error] [pid 402041:tid 402208] [client 103.151.46.103:55375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UQ4iENNLP6XjiHQtN4gAAAbI"]
[Tue Jul 21 08:13:07.095424 2026] [security2:error] [pid 402041:tid 402208] [client 103.151.46.103:55375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UQ4iENNLP6XjiHQtN4gAAAbI"]
[Tue Jul 21 08:13:07.336482 2026] [security2:error] [pid 402041:tid 402229] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UQoiENNLP6XjiHQtN2QAAAcc"]
[Tue Jul 21 08:13:07.719885 2026] [security2:error] [pid 402041:tid 402088] [remote 20.153.140.50:47508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9UQ4iENNLP6XjiHQtN9QAB1yw"]
[Tue Jul 21 08:13:07.736975 2026] [security2:error] [pid 402041:tid 402250] [client 20.104.96.117:57979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-happy.php"] [unique_id "al9UQ4iENNLP6XjiHQtN9gAAAdw"]
[Tue Jul 21 08:13:08.020069 2026] [security2:error] [pid 402041:tid 402285] [client 20.226.60.151:48876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/177.php"] [unique_id "al9URIiENNLP6XjiHQtN-wAAAf8"]
[Tue Jul 21 08:13:08.249925 2026] [security2:error] [pid 402041:tid 402157] [remote 97.74.87.194:60518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ellosemijoias.com.br"] [uri "/wp-login.php"] [unique_id "al9URIiENNLP6XjiHQtOCgACB3E"]
[Tue Jul 21 08:13:08.291119 2026] [security2:error] [pid 402041:tid 402188] [client 20.197.192.193:59910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9URIiENNLP6XjiHQtODgAAAZ4"]
[Tue Jul 21 08:13:08.323267 2026] [security2:error] [pid 402041:tid 402213] [client 20.197.192.193:20764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9URIiENNLP6XjiHQtODwAAAbc"]
[Tue Jul 21 08:13:08.349599 2026] [security2:error] [pid 402041:tid 402254] [client 20.151.10.161:13302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/ms-edit.php"] [unique_id "al9URIiENNLP6XjiHQtOEQAAAeA"]
[Tue Jul 21 08:13:08.352306 2026] [security2:error] [pid 402041:tid 402216] [client 20.197.192.193:59942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/dp.php"] [unique_id "al9URIiENNLP6XjiHQtOEgAAAbo"]
[Tue Jul 21 08:13:08.365654 2026] [security2:error] [pid 402041:tid 402262] [client 20.197.192.193:20759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/old.php"] [unique_id "al9URIiENNLP6XjiHQtOFAAAAeg"]
[Tue Jul 21 08:13:08.439510 2026] [security2:error] [pid 402041:tid 402210] [client 20.197.192.193:20742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/ms-new.php"] [unique_id "al9URIiENNLP6XjiHQtOFgAAAbQ"]
[Tue Jul 21 08:13:08.514499 2026] [security2:error] [pid 402041:tid 402251] [client 117.210.135.0:63033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URIiENNLP6XjiHQtOFwAAAd0"]
[Tue Jul 21 08:13:08.515076 2026] [security2:error] [pid 402041:tid 402251] [client 117.210.135.0:63033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URIiENNLP6XjiHQtOFwAAAd0"]
[Tue Jul 21 08:13:08.570864 2026] [security2:error] [pid 402041:tid 402108] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URIiENNLP6XjiHQtOGAABzUA"]
[Tue Jul 21 08:13:08.571047 2026] [security2:error] [pid 402041:tid 402235] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URIiENNLP6XjiHQtOGAABzUA"]
[Tue Jul 21 08:13:08.630333 2026] [security2:error] [pid 402041:tid 402147] [remote 119.195.102.159:52576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "overkotz.com"] [uri "/wp-login.php"] [unique_id "al9URIiENNLP6XjiHQtONwAB5mc"]
[Tue Jul 21 08:13:08.681528 2026] [security2:error] [pid 402041:tid 402192] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9URIiENNLP6XjiHQtOCAAAAaI"]
[Tue Jul 21 08:13:08.768247 2026] [security2:error] [pid 402041:tid 402218] [client 20.197.192.193:59951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/track.php"] [unique_id "al9URIiENNLP6XjiHQtOWgAAAbw"]
[Tue Jul 21 08:13:08.835146 2026] [security2:error] [pid 402041:tid 402225] [client 74.7.175.160:42970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "rota40.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9URIiENNLP6XjiHQtOWwABwy8"]
[Tue Jul 21 08:13:08.885977 2026] [security2:error] [pid 402041:tid 402231] [client 20.197.192.193:20750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/2352356666.php"] [unique_id "al9URIiENNLP6XjiHQtOXwAAAck"]
[Tue Jul 21 08:13:08.910918 2026] [security2:error] [pid 402041:tid 402178] [client 20.197.192.193:59905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/pn.php"] [unique_id "al9URIiENNLP6XjiHQtOYAAAAZQ"]
[Tue Jul 21 08:13:08.961864 2026] [log_config:warn] [pid 352421:tid 352629] (32)Broken pipe: [client 45.239.146.35:47908] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:13:08.961881 2026] [log_config:warn] [pid 352421:tid 352629] (32)Broken pipe: [client 45.239.146.35:47908] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:13:08.985866 2026] [security2:error] [pid 402041:tid 402280] [client 20.104.96.117:57932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/fpr4.php"] [unique_id "al9URIiENNLP6XjiHQtOagAAAfo"]
[Tue Jul 21 08:13:09.018888 2026] [security2:error] [pid 402041:tid 402262] [client 20.197.192.193:59944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9URYiENNLP6XjiHQtOhgAAAeg"]
[Tue Jul 21 08:13:09.063690 2026] [security2:error] [pid 402041:tid 402195] [client 20.197.192.193:20789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/dr.php"] [unique_id "al9URYiENNLP6XjiHQtOhwAAAaU"]
[Tue Jul 21 08:13:09.253407 2026] [security2:error] [pid 402041:tid 402187] [client 20.104.96.117:62546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/js.php"] [unique_id "al9URYiENNLP6XjiHQtOkQAAAZ0"]
[Tue Jul 21 08:13:09.267613 2026] [security2:error] [pid 402041:tid 402271] [client 20.197.192.193:20767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/2x.php"] [unique_id "al9URYiENNLP6XjiHQtOtgAAAfE"]
[Tue Jul 21 08:13:09.381793 2026] [autoindex:error] [pid 402041:tid 402154] [remote 74.7.242.46:60106] AH01276: Cannot serve directory /home2/italom32/rota40.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:13:09.397759 2026] [security2:error] [pid 402041:tid 402203] [client 34.138.76.29:60510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.76.138.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psicologo.guiiaz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URYiENNLP6XjiHQtO8wAAAa0"]
[Tue Jul 21 08:13:09.397850 2026] [security2:error] [pid 402041:tid 402203] [client 34.138.76.29:60510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "psicologo.guiiaz.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URYiENNLP6XjiHQtO8wAAAa0"]
[Tue Jul 21 08:13:09.445395 2026] [security2:error] [pid 402041:tid 402267] [client 20.197.192.193:20749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/kq1.php"] [unique_id "al9URYiENNLP6XjiHQtO9gAAAe0"]
[Tue Jul 21 08:13:09.535830 2026] [security2:error] [pid 402041:tid 402285] [client 103.78.200.11:50519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URYiENNLP6XjiHQtO-QAAAf8"]
[Tue Jul 21 08:13:09.535964 2026] [security2:error] [pid 402041:tid 402285] [client 103.78.200.11:50519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URYiENNLP6XjiHQtO-QAAAf8"]
[Tue Jul 21 08:13:09.629688 2026] [security2:error] [pid 402041:tid 402174] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URYiENNLP6XjiHQtO-AABkD4"]
[Tue Jul 21 08:13:09.743661 2026] [security2:error] [pid 402041:tid 402222] [client 20.104.96.117:60122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/file88.php"] [unique_id "al9URYiENNLP6XjiHQtPDQAAAcA"]
[Tue Jul 21 08:13:09.767882 2026] [security2:error] [pid 402041:tid 402260] [client 20.197.192.193:59911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/zzz.php"] [unique_id "al9URYiENNLP6XjiHQtPEQAAAeY"]
[Tue Jul 21 08:13:09.866736 2026] [security2:error] [pid 402041:tid 402281] [client 20.197.192.193:59936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/wicked.php"] [unique_id "al9URYiENNLP6XjiHQtPFwAAAfs"]
[Tue Jul 21 08:13:10.102368 2026] [fcgid:warn] [pid 402041:tid 402267] (70014)End of file found: [client 66.132.224.86:64388] mod_fcgid: can't get data from http client
[Tue Jul 21 08:13:10.105121 2026] [security2:error] [pid 402041:tid 402130] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URoiENNLP6XjiHQtPJAAB61Y"]
[Tue Jul 21 08:13:10.105273 2026] [security2:error] [pid 402041:tid 402265] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URoiENNLP6XjiHQtPJAAB61Y"]
[Tue Jul 21 08:13:10.198570 2026] [security2:error] [pid 402041:tid 402205] [client 20.197.192.193:20751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/edit.php"] [unique_id "al9URoiENNLP6XjiHQtPKQAAAa8"]
[Tue Jul 21 08:13:10.396881 2026] [security2:error] [pid 402041:tid 402268] [client 20.226.60.151:48786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/config.php"] [unique_id "al9URoiENNLP6XjiHQtPLwAAAe4"]
[Tue Jul 21 08:13:10.399969 2026] [security2:error] [pid 402041:tid 402203] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9URYiENNLP6XjiHQtPHwAAAa0"]
[Tue Jul 21 08:13:10.400292 2026] [security2:error] [pid 402041:tid 402179] [client 20.197.192.193:20744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/kua.php"] [unique_id "al9URoiENNLP6XjiHQtPMAAAAZU"]
[Tue Jul 21 08:13:10.583775 2026] [security2:error] [pid 402041:tid 402262] [client 154.208.47.43:45574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9URoiENNLP6XjiHQtPMgAAAeg"]
[Tue Jul 21 08:13:10.583919 2026] [security2:error] [pid 402041:tid 402262] [client 154.208.47.43:45574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9URoiENNLP6XjiHQtPMgAAAeg"]
[Tue Jul 21 08:13:10.618475 2026] [security2:error] [pid 402041:tid 402299] [client 20.197.192.193:20746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/ez.php"] [unique_id "al9URoiENNLP6XjiHQtPMwAAAg0"]
[Tue Jul 21 08:13:10.633069 2026] [security2:error] [pid 402041:tid 402144] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9URoiENNLP6XjiHQtPNAABkGQ"]
[Tue Jul 21 08:13:10.633192 2026] [security2:error] [pid 402041:tid 402174] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9URoiENNLP6XjiHQtPNAABkGQ"]
[Tue Jul 21 08:13:10.640154 2026] [security2:error] [pid 402041:tid 402236] [client 20.104.96.117:60157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/ccc.php"] [unique_id "al9URoiENNLP6XjiHQtPNQAAAc4"]
[Tue Jul 21 08:13:10.660924 2026] [security2:error] [pid 402041:tid 402263] [client 38.100.221.102:18537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URoiENNLP6XjiHQtPNgAAAek"]
[Tue Jul 21 08:13:10.661043 2026] [security2:error] [pid 402041:tid 402263] [client 38.100.221.102:18537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URoiENNLP6XjiHQtPNgAAAek"]
[Tue Jul 21 08:13:10.697197 2026] [security2:error] [pid 402041:tid 402290] [client 87.116.180.198:14011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URoiENNLP6XjiHQtPOAAAAgQ"]
[Tue Jul 21 08:13:10.697315 2026] [security2:error] [pid 402041:tid 402290] [client 87.116.180.198:14011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9URoiENNLP6XjiHQtPOAAAAgQ"]
[Tue Jul 21 08:13:10.816749 2026] [security2:error] [pid 402041:tid 402260] [client 20.197.192.193:59941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/fz.php"] [unique_id "al9URoiENNLP6XjiHQtPPQAAAeY"]
[Tue Jul 21 08:13:10.940648 2026] [security2:error] [pid 402041:tid 402238] [client 20.104.96.117:54085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/txets.php"] [unique_id "al9URoiENNLP6XjiHQtPQQAAAdA"]
[Tue Jul 21 08:13:10.961202 2026] [rewrite:error] [pid 402041:tid 402216] [client 57.141.18.31:0] AH10411: Rewritten query string contains control characters or spaces
[Tue Jul 21 08:13:11.011129 2026] [security2:error] [pid 402041:tid 402291] [client 20.197.192.193:59959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/la.php"] [unique_id "al9UR4iENNLP6XjiHQtPRgAAAgU"]
[Tue Jul 21 08:13:11.221067 2026] [security2:error] [pid 402041:tid 402187] [client 20.197.192.193:59949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9UR4iENNLP6XjiHQtPTAAAAZ0"]
[Tue Jul 21 08:13:11.247299 2026] [security2:error] [pid 402041:tid 402282] [client 162.219.176.3:51824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9UR4iENNLP6XjiHQtPTwAAAfw"]
[Tue Jul 21 08:13:11.247401 2026] [security2:error] [pid 402041:tid 402282] [client 162.219.176.3:51824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9UR4iENNLP6XjiHQtPTwAAAfw"]
[Tue Jul 21 08:13:11.319144 2026] [security2:error] [pid 402041:tid 402205] [client 20.197.192.193:20777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/inso.php"] [unique_id "al9UR4iENNLP6XjiHQtPVQAAAa8"]
[Tue Jul 21 08:13:11.434947 2026] [security2:error] [pid 402041:tid 402283] [client 20.197.192.193:59952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/wpx.php"] [unique_id "al9UR4iENNLP6XjiHQtPZAAAAf0"]
[Tue Jul 21 08:13:11.571344 2026] [security2:error] [pid 402041:tid 402274] [client 20.197.192.193:59907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/berlin.php"] [unique_id "al9UR4iENNLP6XjiHQtPigAAAfQ"]
[Tue Jul 21 08:13:11.827364 2026] [security2:error] [pid 402041:tid 402228] [client 20.197.192.193:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/billur.php"] [unique_id "al9UR4iENNLP6XjiHQtPkAAAAcY"]
[Tue Jul 21 08:13:12.017713 2026] [security2:error] [pid 402041:tid 402204] [client 20.104.96.117:58381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/777.php"] [unique_id "al9USIiENNLP6XjiHQtPmwAAAa4"]
[Tue Jul 21 08:13:12.029343 2026] [security2:error] [pid 402041:tid 402243] [client 20.197.192.193:59958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/mimpi.php"] [unique_id "al9USIiENNLP6XjiHQtPnAAAAdU"]
[Tue Jul 21 08:13:12.089438 2026] [security2:error] [pid 402041:tid 402246] [client 20.197.192.193:20754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/dp.php"] [unique_id "al9USIiENNLP6XjiHQtPngAAAdg"]
[Tue Jul 21 08:13:12.378411 2026] [security2:error] [pid 402041:tid 402286] [client 20.151.10.161:13231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/222.php"] [unique_id "al9USIiENNLP6XjiHQtPqQAAAgA"]
[Tue Jul 21 08:13:12.387102 2026] [security2:error] [pid 402041:tid 402218] [client 20.197.192.193:20753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/bootstrap.php"] [unique_id "al9USIiENNLP6XjiHQtPqgAAAbw"]
[Tue Jul 21 08:13:12.391179 2026] [security2:error] [pid 402041:tid 402191] [client 103.151.46.103:55884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9USIiENNLP6XjiHQtPqwAAAaE"]
[Tue Jul 21 08:13:12.391267 2026] [security2:error] [pid 402041:tid 402191] [client 103.151.46.103:55884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9USIiENNLP6XjiHQtPqwAAAaE"]
[Tue Jul 21 08:13:12.986808 2026] [security2:error] [pid 402041:tid 402274] [client 20.104.96.117:57966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/for.php"] [unique_id "al9USIiENNLP6XjiHQtPwAAAAfQ"]
[Tue Jul 21 08:13:13.062665 2026] [security2:error] [pid 402041:tid 402221] [client 20.220.225.223:30897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/zzz.php"] [unique_id "al9USYiENNLP6XjiHQtPwwAAAb8"]
[Tue Jul 21 08:13:13.310770 2026] [security2:error] [pid 402041:tid 402214] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9USIiENNLP6XjiHQtPuQAAAbg"]
[Tue Jul 21 08:13:13.363634 2026] [security2:error] [pid 402041:tid 402173] [client 102.206.115.33:64928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9USYiENNLP6XjiHQtPzQAAAY8"]
[Tue Jul 21 08:13:13.363847 2026] [security2:error] [pid 402041:tid 402173] [client 102.206.115.33:64928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9USYiENNLP6XjiHQtPzQAAAY8"]
[Tue Jul 21 08:13:13.387240 2026] [security2:error] [pid 402041:tid 402223] [client 20.197.192.193:20841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/wp-editor.php"] [unique_id "al9USYiENNLP6XjiHQtPzgAAAcE"]
[Tue Jul 21 08:13:13.695706 2026] [security2:error] [pid 402041:tid 402120] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9USYiENNLP6XjiHQtP1QAB7Uw"]
[Tue Jul 21 08:13:13.695938 2026] [security2:error] [pid 402041:tid 402267] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9USYiENNLP6XjiHQtP1QAB7Uw"]
[Tue Jul 21 08:13:13.739205 2026] [security2:error] [pid 402041:tid 402218] [client 20.104.96.117:57980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/ssla.php"] [unique_id "al9USYiENNLP6XjiHQtP1gAAAbw"]
[Tue Jul 21 08:13:13.878471 2026] [security2:error] [pid 402041:tid 402097] [remote 185.213.175.37:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.naldoinvest.com.br"] [uri "/"] [unique_id "al9USYiENNLP6XjiHQtP1wAB2zU"]
[Tue Jul 21 08:13:14.074449 2026] [security2:error] [pid 402041:tid 402208] [client 20.151.10.161:13235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/cgi-bin/index.php"] [unique_id "al9USoiENNLP6XjiHQtP4gAAAbI"]
[Tue Jul 21 08:13:14.148908 2026] [security2:error] [pid 402041:tid 402129] [remote 134.209.147.209:33990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.147.209.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9USoiENNLP6XjiHQtP4wAB_FU"]
[Tue Jul 21 08:13:14.149104 2026] [security2:error] [pid 402041:tid 402282] [client 134.209.147.209:33990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9USoiENNLP6XjiHQtP4wAB_FU"]
[Tue Jul 21 08:13:14.166459 2026] [security2:error] [pid 402041:tid 402179] [client 20.197.192.193:59917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/cro.php"] [unique_id "al9USoiENNLP6XjiHQtP5gAAAZU"]
[Tue Jul 21 08:13:14.176252 2026] [security2:error] [pid 402041:tid 402246] [client 14.97.58.74:10521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9USoiENNLP6XjiHQtP5wAAAdg"]
[Tue Jul 21 08:13:14.176358 2026] [security2:error] [pid 402041:tid 402246] [client 14.97.58.74:10521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9USoiENNLP6XjiHQtP5wAAAdg"]
[Tue Jul 21 08:13:14.211635 2026] [security2:error] [pid 402041:tid 402268] [client 20.220.225.223:30879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/wicked.php"] [unique_id "al9USoiENNLP6XjiHQtP6AAAAe4"]
[Tue Jul 21 08:13:14.417807 2026] [security2:error] [pid 402041:tid 402211] [client 198.54.129.60:37058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9USoiENNLP6XjiHQtP6QAAAbU"]
[Tue Jul 21 08:13:14.417893 2026] [security2:error] [pid 402041:tid 402211] [client 198.54.129.60:37058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9USoiENNLP6XjiHQtP6QAAAbU"]
[Tue Jul 21 08:13:14.686342 2026] [security2:error] [pid 402041:tid 402254] [client 20.226.60.151:48793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/gettest.php"] [unique_id "al9USoiENNLP6XjiHQtP9wAAAeA"]
[Tue Jul 21 08:13:14.752755 2026] [security2:error] [pid 402041:tid 402243] [client 20.104.96.117:60068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/zc-131.php"] [unique_id "al9USoiENNLP6XjiHQtP-gAAAdU"]
[Tue Jul 21 08:13:14.840587 2026] [security2:error] [pid 402041:tid 402200] [client 20.197.192.193:20781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/cron-tab.php"] [unique_id "al9USoiENNLP6XjiHQtP-wAAAao"]
[Tue Jul 21 08:13:14.847024 2026] [security2:error] [pid 402041:tid 402088] [remote 51.75.236.144:50652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "moveisrafael.com.br"] [uri "/robots.txt"] [unique_id "al9USoiENNLP6XjiHQtP_AABjyw"]
[Tue Jul 21 08:13:14.847161 2026] [security2:error] [pid 402041:tid 402173] [client 51.75.236.144:50652] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "moveisrafael.com.br"] [uri "/robots.txt"] [unique_id "al9USoiENNLP6XjiHQtP_AABjyw"]
[Tue Jul 21 08:13:14.947090 2026] [security2:error] [pid 402041:tid 402276] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9USoiENNLP6XjiHQtP8QAAAfY"]
[Tue Jul 21 08:13:15.203850 2026] [autoindex:error] [pid 402041:tid 402187] [client 20.151.10.161:13306] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:13:15.213460 2026] [security2:error] [pid 402041:tid 402167] [remote 20.75.217.64:8777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9US4iENNLP6XjiHQtQCQABxXs"]
[Tue Jul 21 08:13:15.478011 2026] [security2:error] [pid 402041:tid 402205] [client 20.151.10.161:13238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/BDKR28WP.php"] [unique_id "al9US4iENNLP6XjiHQtQDgAAAa8"]
[Tue Jul 21 08:13:15.523830 2026] [security2:error] [pid 402041:tid 402224] [client 20.197.192.193:20769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/koiy.php"] [unique_id "al9US4iENNLP6XjiHQtQEAAAAcI"]
[Tue Jul 21 08:13:15.551235 2026] [security2:error] [pid 402041:tid 402249] [client 187.125.243.197:59066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9US4iENNLP6XjiHQtQEQAAAds"]
[Tue Jul 21 08:13:15.551334 2026] [security2:error] [pid 402041:tid 402249] [client 187.125.243.197:59066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9US4iENNLP6XjiHQtQEQAAAds"]
[Tue Jul 21 08:13:15.588982 2026] [security2:error] [pid 402041:tid 402185] [client 20.104.96.117:62571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/core.php"] [unique_id "al9US4iENNLP6XjiHQtQEgAAAZs"]
[Tue Jul 21 08:13:15.832503 2026] [security2:error] [pid 402041:tid 402143] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9US4iENNLP6XjiHQtQGAABy2M"]
[Tue Jul 21 08:13:15.832684 2026] [security2:error] [pid 402041:tid 402233] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9US4iENNLP6XjiHQtQGAABy2M"]
[Tue Jul 21 08:13:15.933728 2026] [security2:error] [pid 402041:tid 402300] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9US4iENNLP6XjiHQtQDwAAAg4"]
[Tue Jul 21 08:13:16.035100 2026] [security2:error] [pid 402041:tid 402180] [client 20.197.192.193:59909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/hp2.php"] [unique_id "al9UTIiENNLP6XjiHQtQHwAAAZY"]
[Tue Jul 21 08:13:16.094902 2026] [security2:error] [pid 402041:tid 402209] [client 34.150.238.159:53348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "agenciawats.com.br.bomexito.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9UTIiENNLP6XjiHQtQIQAAAbM"]
[Tue Jul 21 08:13:16.147159 2026] [security2:error] [pid 402041:tid 402261] [client 20.104.96.117:63078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/dex.php"] [unique_id "al9UTIiENNLP6XjiHQtQJQAAAec"]
[Tue Jul 21 08:13:16.192665 2026] [autoindex:error] [pid 402041:tid 402188] [client 20.151.10.161:13306] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:13:16.220770 2026] [security2:error] [pid 402041:tid 402259] [client 120.56.162.40:58056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UTIiENNLP6XjiHQtQKAAAAeU"]
[Tue Jul 21 08:13:16.220877 2026] [security2:error] [pid 402041:tid 402259] [client 120.56.162.40:58056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UTIiENNLP6XjiHQtQKAAAAeU"]
[Tue Jul 21 08:13:16.372148 2026] [security2:error] [pid 402041:tid 402243] [client 20.151.10.161:50969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/a1.php"] [unique_id "al9UTIiENNLP6XjiHQtQLAAAAdU"]
[Tue Jul 21 08:13:16.393066 2026] [security2:error] [pid 402041:tid 402058] [remote 167.114.139.116:35428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "moveisrafael.com.br"] [uri "/"] [unique_id "al9UTIiENNLP6XjiHQtQLQAB2Q4"]
[Tue Jul 21 08:13:16.393221 2026] [security2:error] [pid 402041:tid 402247] [client 167.114.139.116:35428] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "moveisrafael.com.br"] [uri "/"] [unique_id "al9UTIiENNLP6XjiHQtQLQAB2Q4"]
[Tue Jul 21 08:13:16.636797 2026] [security2:error] [pid 402041:tid 402161] [remote 130.185.118.215:60290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homemsedutoronline.com"] [uri "/wp-login.php"] [unique_id "al9UTIiENNLP6XjiHQtQMgAB0HU"]
[Tue Jul 21 08:13:16.674042 2026] [security2:error] [pid 402041:tid 402223] [client 34.150.238.159:52436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.238.150.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agenciawats.com.br.bomexito.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UTIiENNLP6XjiHQtQNAAAAcE"]
[Tue Jul 21 08:13:16.704479 2026] [security2:error] [pid 402041:tid 402265] [client 20.197.192.193:59912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/hp3.php"] [unique_id "al9UTIiENNLP6XjiHQtQNwAAAes"]
[Tue Jul 21 08:13:17.012716 2026] [security2:error] [pid 402041:tid 402205] [client 142.44.233.214:59522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "leandroavelar.com.br"] [uri "/robots.txt"] [unique_id "al9UTYiENNLP6XjiHQtQOgAAAa8"]
[Tue Jul 21 08:13:17.012831 2026] [security2:error] [pid 402041:tid 402205] [client 142.44.233.214:59522] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "leandroavelar.com.br"] [uri "/robots.txt"] [unique_id "al9UTYiENNLP6XjiHQtQOgAAAa8"]
[Tue Jul 21 08:13:17.037044 2026] [security2:error] [pid 402041:tid 402298] [client 150.129.202.39:12726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UTYiENNLP6XjiHQtQOwAAAgw"]
[Tue Jul 21 08:13:17.037152 2026] [security2:error] [pid 402041:tid 402298] [client 150.129.202.39:12726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UTYiENNLP6XjiHQtQOwAAAgw"]
[Tue Jul 21 08:13:17.302203 2026] [security2:error] [pid 402041:tid 402196] [client 20.197.192.193:59947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/aa1.php"] [unique_id "al9UTYiENNLP6XjiHQtQQgAAAaY"]
[Tue Jul 21 08:13:17.589080 2026] [security2:error] [pid 402041:tid 402130] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UTYiENNLP6XjiHQtQRwAB-VY"]
[Tue Jul 21 08:13:17.589220 2026] [security2:error] [pid 402041:tid 402279] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UTYiENNLP6XjiHQtQRwAB-VY"]
[Tue Jul 21 08:13:17.769828 2026] [security2:error] [pid 402041:tid 402274] [client 20.197.192.193:20791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/acew67.php"] [unique_id "al9UTYiENNLP6XjiHQtQUwAAAfQ"]
[Tue Jul 21 08:13:18.038349 2026] [security2:error] [pid 402041:tid 402221] [client 20.197.192.193:59956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/bscclapb.php"] [unique_id "al9UToiENNLP6XjiHQtQWAAAAb8"]
[Tue Jul 21 08:13:18.160201 2026] [security2:error] [pid 402041:tid 402242] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UTYiENNLP6XjiHQtQTQAAAdQ"]
[Tue Jul 21 08:13:18.232846 2026] [security2:error] [pid 402041:tid 402291] [client 20.104.96.117:63474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/19.php"] [unique_id "al9UToiENNLP6XjiHQtQYwAAAgU"]
[Tue Jul 21 08:13:18.392825 2026] [security2:error] [pid 402041:tid 402204] [client 20.197.192.193:20763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/else1.php"] [unique_id "al9UToiENNLP6XjiHQtQagAAAa4"]
[Tue Jul 21 08:13:18.432210 2026] [security2:error] [pid 402041:tid 402267] [client 167.114.139.148:62328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "leandroavelar.com.br"] [uri "/"] [unique_id "al9UToiENNLP6XjiHQtQbgAAAe0"]
[Tue Jul 21 08:13:18.432335 2026] [security2:error] [pid 402041:tid 402267] [client 167.114.139.148:62328] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "leandroavelar.com.br"] [uri "/"] [unique_id "al9UToiENNLP6XjiHQtQbgAAAe0"]
[Tue Jul 21 08:13:18.543715 2026] [security2:error] [pid 402041:tid 402252] [client 198.54.129.60:37056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9UToiENNLP6XjiHQtQcQAAAd4"]
[Tue Jul 21 08:13:18.543800 2026] [security2:error] [pid 402041:tid 402252] [client 198.54.129.60:37056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9UToiENNLP6XjiHQtQcQAAAd4"]
[Tue Jul 21 08:13:18.616575 2026] [security2:error] [pid 402041:tid 402200] [client 20.197.192.193:59955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/tkikikoko.php"] [unique_id "al9UToiENNLP6XjiHQtQcwAAAao"]
[Tue Jul 21 08:13:18.741334 2026] [security2:error] [pid 402041:tid 402224] [client 20.197.192.193:20760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9UToiENNLP6XjiHQtQeAAAAcI"]
[Tue Jul 21 08:13:18.866136 2026] [security2:error] [pid 402041:tid 402286] [client 20.197.192.193:20851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/wp-css.php"] [unique_id "al9UToiENNLP6XjiHQtQfgAAAgA"]
[Tue Jul 21 08:13:18.894675 2026] [security2:error] [pid 402041:tid 402255] [client 20.151.10.161:13192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/raw.php"] [unique_id "al9UToiENNLP6XjiHQtQfwAAAeE"]
[Tue Jul 21 08:13:18.895420 2026] [security2:error] [pid 402041:tid 402266] [client 20.197.192.193:20745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/wp-explorer.php"] [unique_id "al9UToiENNLP6XjiHQtQgAAAAew"]
[Tue Jul 21 08:13:18.897846 2026] [security2:error] [pid 402041:tid 402177] [client 20.226.60.151:48856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/min.php"] [unique_id "al9UToiENNLP6XjiHQtQgQAAAZM"]
[Tue Jul 21 08:13:18.906397 2026] [security2:error] [pid 402041:tid 402265] [client 65.21.113.253:37472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UToiENNLP6XjiHQtQbwAAAes"]
[Tue Jul 21 08:13:18.968153 2026] [security2:error] [pid 402041:tid 402206] [client 20.197.192.193:20761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/akismet.php"] [unique_id "al9UToiENNLP6XjiHQtQgwAAAbA"]
[Tue Jul 21 08:13:18.968197 2026] [security2:error] [pid 402041:tid 402288] [client 117.210.135.0:63676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UToiENNLP6XjiHQtQhAAAAgI"]
[Tue Jul 21 08:13:18.968277 2026] [security2:error] [pid 402041:tid 402288] [client 117.210.135.0:63676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UToiENNLP6XjiHQtQhAAAAgI"]
[Tue Jul 21 08:13:19.036850 2026] [security2:error] [pid 402041:tid 402203] [client 20.197.192.193:20757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/ace2.php"] [unique_id "al9UT4iENNLP6XjiHQtQhwAAAa0"]
[Tue Jul 21 08:13:19.163403 2026] [security2:error] [pid 402041:tid 402269] [client 20.197.192.193:59961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.produtosnapromo.com.br"] [uri "/ms.php"] [unique_id "al9UT4iENNLP6XjiHQtQjQAAAe8"]
[Tue Jul 21 08:13:19.173640 2026] [security2:error] [pid 402041:tid 402152] [remote 74.7.241.42:44982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.241.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UToiENNLP6XjiHQtQfQABsmw"], referer: https://app.institutocrismonteiro.com.br/2022/08/03/o-nosso-lar/
[Tue Jul 21 08:13:19.223861 2026] [security2:error] [pid 402041:tid 402228] [client 20.151.10.161:13195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/abcd.php"] [unique_id "al9UT4iENNLP6XjiHQtQjwAAAcY"]
[Tue Jul 21 08:13:19.377155 2026] [security2:error] [pid 402041:tid 402103] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UT4iENNLP6XjiHQtQlwACATs"]
[Tue Jul 21 08:13:19.377309 2026] [security2:error] [pid 402041:tid 402287] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UT4iENNLP6XjiHQtQlwACATs"]
[Tue Jul 21 08:13:19.447265 2026] [proxy:error] [pid 402041:tid 402247] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:13:19.447340 2026] [proxy_http:error] [pid 402041:tid 402247] [client 143.244.57.90:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:13:19.448543 2026] [proxy:error] [pid 402041:tid 402247] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:13:19.448587 2026] [proxy_http:error] [pid 402041:tid 402247] [client 143.244.57.90:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:13:19.609752 2026] [security2:error] [pid 402041:tid 402202] [client 20.151.10.161:13201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/a1.php"] [unique_id "al9UT4iENNLP6XjiHQtQmwAAAaw"]
[Tue Jul 21 08:13:19.757904 2026] [proxy:error] [pid 402041:tid 402188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:13:19.757966 2026] [proxy_http:error] [pid 402041:tid 402188] [client 143.244.57.90:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:13:19.758476 2026] [proxy:error] [pid 402041:tid 402188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:13:19.758516 2026] [proxy_http:error] [pid 402041:tid 402188] [client 143.244.57.90:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:13:19.945799 2026] [security2:error] [pid 402041:tid 402195] [client 20.151.10.161:51013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9UT4iENNLP6XjiHQtQpwAAAaU"]
[Tue Jul 21 08:13:19.947875 2026] [security2:error] [pid 402041:tid 402249] [client 20.151.10.161:13220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9UT4iENNLP6XjiHQtQqQAAAds"]
[Tue Jul 21 08:13:19.986753 2026] [security2:error] [pid 402041:tid 402057] [remote 185.115.217.185:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.217.115.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "annaguimaraes.com.br"] [uri "/wp-login.php"] [unique_id "al9UT4iENNLP6XjiHQtQqgABvg0"]
[Tue Jul 21 08:13:20.042742 2026] [security2:error] [pid 402041:tid 402196] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9UUIiENNLP6XjiHQtQrwAAAaY"]
[Tue Jul 21 08:13:20.056609 2026] [proxy:error] [pid 402041:tid 402285] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:13:20.056687 2026] [proxy_http:error] [pid 402041:tid 402285] [client 64.23.245.156:60160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:13:20.057354 2026] [proxy:error] [pid 402041:tid 402285] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:13:20.057380 2026] [proxy_http:error] [pid 402041:tid 402285] [client 64.23.245.156:60160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:13:20.221703 2026] [security2:error] [pid 402041:tid 402257] [client 103.78.200.11:51010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UUIiENNLP6XjiHQtQtgAAAeM"]
[Tue Jul 21 08:13:20.221842 2026] [security2:error] [pid 402041:tid 402257] [client 103.78.200.11:51010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UUIiENNLP6XjiHQtQtgAAAeM"]
[Tue Jul 21 08:13:20.250481 2026] [security2:error] [pid 402041:tid 402180] [client 20.151.10.161:13210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/cgi-bin/admin.php"] [unique_id "al9UUIiENNLP6XjiHQtQuAAAAZY"]
[Tue Jul 21 08:13:20.329164 2026] [security2:error] [pid 402041:tid 402269] [client 143.244.57.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UUIiENNLP6XjiHQtQuQAAAe8"]
[Tue Jul 21 08:13:20.338824 2026] [security2:error] [pid 402041:tid 402288] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UUIiENNLP6XjiHQtQtAACAlQ"]
[Tue Jul 21 08:13:20.435332 2026] [proxy:error] [pid 402041:tid 402295] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:13:20.435418 2026] [proxy_http:error] [pid 402041:tid 402295] [client 64.23.245.156:60166] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.moveisrafael.com.br/
[Tue Jul 21 08:13:20.436164 2026] [proxy:error] [pid 402041:tid 402295] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:13:20.436205 2026] [proxy_http:error] [pid 402041:tid 402295] [client 64.23.245.156:60166] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.moveisrafael.com.br/
[Tue Jul 21 08:13:20.549930 2026] [security2:error] [pid 402041:tid 402221] [client 20.151.10.161:13204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wp-content/BypassBest.php"] [unique_id "al9UUIiENNLP6XjiHQtQxAAAAb8"]
[Tue Jul 21 08:13:20.566661 2026] [security2:error] [pid 402041:tid 402095] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UUIiENNLP6XjiHQtQxgAB1zM"]
[Tue Jul 21 08:13:20.566783 2026] [security2:error] [pid 402041:tid 402245] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UUIiENNLP6XjiHQtQxgAB1zM"]
[Tue Jul 21 08:13:20.614241 2026] [proxy:error] [pid 402041:tid 402248] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:13:20.614298 2026] [proxy_http:error] [pid 402041:tid 402248] [client 143.244.57.90:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:13:20.614746 2026] [proxy:error] [pid 402041:tid 402248] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:13:20.614768 2026] [proxy_http:error] [pid 402041:tid 402248] [client 143.244.57.90:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:13:20.791130 2026] [security2:error] [pid 402041:tid 402176] [client 34.150.238.159:62627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.238.150.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agenciawats.com.br.bomexito.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UUIiENNLP6XjiHQtQzQAAAZI"]
[Tue Jul 21 08:13:20.791221 2026] [security2:error] [pid 402041:tid 402176] [client 34.150.238.159:62627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "agenciawats.com.br.bomexito.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UUIiENNLP6XjiHQtQzQAAAZI"]
[Tue Jul 21 08:13:20.915069 2026] [security2:error] [pid 402041:tid 402188] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9UUIiENNLP6XjiHQtQ1QAAAZ4"]
[Tue Jul 21 08:13:21.035890 2026] [security2:error] [pid 402041:tid 402261] [client 154.208.47.43:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UUYiENNLP6XjiHQtQ1wAAAec"]
[Tue Jul 21 08:13:21.036015 2026] [security2:error] [pid 402041:tid 402261] [client 154.208.47.43:46028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UUYiENNLP6XjiHQtQ1wAAAec"]
[Tue Jul 21 08:13:21.158945 2026] [proxy:error] [pid 402041:tid 402175] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:13:21.158979 2026] [proxy_http:error] [pid 402041:tid 402175] [client 64.23.245.156:53504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:13:21.159398 2026] [proxy:error] [pid 402041:tid 402175] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:13:21.159418 2026] [proxy_http:error] [pid 402041:tid 402175] [client 64.23.245.156:53504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:13:21.197371 2026] [security2:error] [pid 402041:tid 402234] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9UUYiENNLP6XjiHQtQ2wAAAcw"]
[Tue Jul 21 08:13:21.253675 2026] [security2:error] [pid 402041:tid 402260] [client 38.100.221.102:17958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UUYiENNLP6XjiHQtQ3gAAAeY"]
[Tue Jul 21 08:13:21.253790 2026] [security2:error] [pid 402041:tid 402260] [client 38.100.221.102:17958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UUYiENNLP6XjiHQtQ3gAAAeY"]
[Tue Jul 21 08:13:21.404672 2026] [security2:error] [pid 402041:tid 402284] [client 87.116.180.198:27298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UUYiENNLP6XjiHQtQ6gAAAf4"]
[Tue Jul 21 08:13:21.408735 2026] [security2:error] [pid 402041:tid 402284] [client 87.116.180.198:27298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UUYiENNLP6XjiHQtQ6gAAAf4"]
[Tue Jul 21 08:13:21.480117 2026] [security2:error] [pid 402041:tid 402279] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9UUYiENNLP6XjiHQtQ6wAAAfk"]
[Tue Jul 21 08:13:21.592555 2026] [security2:error] [pid 402041:tid 402211] [client 62.102.148.158:44952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9UUYiENNLP6XjiHQtQ7gAAAbU"]
[Tue Jul 21 08:13:21.592649 2026] [security2:error] [pid 402041:tid 402211] [client 62.102.148.158:44952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9UUYiENNLP6XjiHQtQ7gAAAbU"]
[Tue Jul 21 08:13:21.653123 2026] [security2:error] [pid 402041:tid 402114] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UUYiENNLP6XjiHQtQ8wAB60Y"]
[Tue Jul 21 08:13:21.653352 2026] [security2:error] [pid 402041:tid 402265] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UUYiENNLP6XjiHQtQ8wAB60Y"]
[Tue Jul 21 08:13:21.765993 2026] [security2:error] [pid 402041:tid 402212] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9UUYiENNLP6XjiHQtQ9QAAAbY"]
[Tue Jul 21 08:13:21.956789 2026] [security2:error] [pid 402041:tid 402271] [client 20.151.10.161:51016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9UUYiENNLP6XjiHQtRAAAAAfE"]
[Tue Jul 21 08:13:22.048799 2026] [security2:error] [pid 402041:tid 402241] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9UUoiENNLP6XjiHQtRAwAAAdM"]
[Tue Jul 21 08:13:22.100215 2026] [security2:error] [pid 402041:tid 402296] [client 103.151.46.103:56353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UUoiENNLP6XjiHQtRBQAAAgo"]
[Tue Jul 21 08:13:22.100446 2026] [security2:error] [pid 402041:tid 402296] [client 103.151.46.103:56353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UUoiENNLP6XjiHQtRBQAAAgo"]
[Tue Jul 21 08:13:22.331323 2026] [security2:error] [pid 402041:tid 402188] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9UUoiENNLP6XjiHQtRCgAAAZ4"]
[Tue Jul 21 08:13:22.483206 2026] [security2:error] [pid 402041:tid 402230] [client 20.151.10.161:13280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/simple.php"] [unique_id "al9UUoiENNLP6XjiHQtRDgAAAcg"]
[Tue Jul 21 08:13:22.618354 2026] [security2:error] [pid 402041:tid 402249] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9UUoiENNLP6XjiHQtRFAAAAds"]
[Tue Jul 21 08:13:22.763629 2026] [security2:error] [pid 402041:tid 402285] [client 20.151.10.161:13243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/xxx.php"] [unique_id "al9UUoiENNLP6XjiHQtRGAAAAf8"]
[Tue Jul 21 08:13:22.901247 2026] [security2:error] [pid 402041:tid 402181] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9UUoiENNLP6XjiHQtRIAAAAZc"]
[Tue Jul 21 08:13:23.014693 2026] [security2:error] [pid 402041:tid 402299] [client 20.104.96.117:63431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/inc.php"] [unique_id "al9UU4iENNLP6XjiHQtRJgAAAg0"]
[Tue Jul 21 08:13:23.076034 2026] [security2:error] [pid 402041:tid 402210] [client 20.151.10.161:13219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/hypo.php"] [unique_id "al9UU4iENNLP6XjiHQtRJwAAAbQ"]
[Tue Jul 21 08:13:23.119142 2026] [security2:error] [pid 402041:tid 402266] [client 20.151.10.161:50999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/gettest.php"] [unique_id "al9UU4iENNLP6XjiHQtRKQAAAew"]
[Tue Jul 21 08:13:23.184089 2026] [security2:error] [pid 402041:tid 402258] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9UU4iENNLP6XjiHQtRKwAAAeQ"]
[Tue Jul 21 08:13:23.257890 2026] [security2:error] [pid 402041:tid 402223] [client 47.128.40.133:31460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sogastro.com.br"] [uri "/robots.txt"] [unique_id "al9UU4iENNLP6XjiHQtRLwAAAcE"]
[Tue Jul 21 08:13:23.269059 2026] [security2:error] [pid 402041:tid 402192] [client 20.226.60.151:48869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/dvjul.php"] [unique_id "al9UU4iENNLP6XjiHQtRMAAAAaI"]
[Tue Jul 21 08:13:23.326003 2026] [security2:error] [pid 402041:tid 402096] [remote 97.74.93.24:42730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "girassollimpeza.com.br"] [uri "/wp-login.php"] [unique_id "al9UUoiENNLP6XjiHQtRCAABszQ"]
[Tue Jul 21 08:13:23.465933 2026] [security2:error] [pid 402041:tid 402214] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9UU4iENNLP6XjiHQtRNQAAAbg"]
[Tue Jul 21 08:13:23.537058 2026] [security2:error] [pid 402041:tid 402291] [client 62.102.148.158:59928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9UU4iENNLP6XjiHQtROwAAAgU"]
[Tue Jul 21 08:13:23.537159 2026] [security2:error] [pid 402041:tid 402291] [client 62.102.148.158:59928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9UU4iENNLP6XjiHQtROwAAAgU"]
[Tue Jul 21 08:13:23.561822 2026] [autoindex:error] [pid 402041:tid 402204] [client 20.151.10.161:13306] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:13:23.723273 2026] [security2:error] [pid 402041:tid 402290] [client 20.151.10.161:13305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/chosen.php"] [unique_id "al9UU4iENNLP6XjiHQtRSQAAAgQ"]
[Tue Jul 21 08:13:23.771993 2026] [security2:error] [pid 402041:tid 402239] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9UU4iENNLP6XjiHQtRSgAAAdE"]
[Tue Jul 21 08:13:23.818378 2026] [security2:error] [pid 402041:tid 402255] [client 20.151.10.161:55827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/simple.php"] [unique_id "al9UU4iENNLP6XjiHQtRTQAAAeE"]
[Tue Jul 21 08:13:23.958691 2026] [security2:error] [pid 402041:tid 402276] [client 102.206.115.33:61850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UU4iENNLP6XjiHQtRUwAAAfY"]
[Tue Jul 21 08:13:23.958800 2026] [security2:error] [pid 402041:tid 402276] [client 102.206.115.33:61850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UU4iENNLP6XjiHQtRUwAAAfY"]
[Tue Jul 21 08:13:24.056295 2026] [security2:error] [pid 402041:tid 402265] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9UVIiENNLP6XjiHQtRWAAAAes"]
[Tue Jul 21 08:13:24.181909 2026] [security2:error] [pid 402041:tid 402129] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UVIiENNLP6XjiHQtRWwAByVU"]
[Tue Jul 21 08:13:24.182035 2026] [security2:error] [pid 402041:tid 402231] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UVIiENNLP6XjiHQtRWwAByVU"]
[Tue Jul 21 08:13:24.325958 2026] [autoindex:error] [pid 402041:tid 402192] [client 20.151.10.161:13306] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:13:24.341713 2026] [security2:error] [pid 402041:tid 402287] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9UVIiENNLP6XjiHQtRXwAAAgE"]
[Tue Jul 21 08:13:24.449611 2026] [security2:error] [pid 402041:tid 402263] [client 20.151.10.161:55856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/xxx.php"] [unique_id "al9UVIiENNLP6XjiHQtRYwAAAek"]
[Tue Jul 21 08:13:24.481663 2026] [security2:error] [pid 402041:tid 402186] [client 20.151.10.161:13122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/file5.php"] [unique_id "al9UVIiENNLP6XjiHQtRZAAAAZw"]
[Tue Jul 21 08:13:24.624717 2026] [security2:error] [pid 402041:tid 402199] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9UVIiENNLP6XjiHQtRaQAAAak"]
[Tue Jul 21 08:13:24.802162 2026] [security2:error] [pid 402041:tid 402175] [client 20.151.10.161:13197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/file.php"] [unique_id "al9UVIiENNLP6XjiHQtRawAAAZE"]
[Tue Jul 21 08:13:24.864958 2026] [security2:error] [pid 402041:tid 402195] [client 111.93.58.162:27161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UVIiENNLP6XjiHQtRbgAAAaU"]
[Tue Jul 21 08:13:24.865112 2026] [security2:error] [pid 402041:tid 402195] [client 111.93.58.162:27161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UVIiENNLP6XjiHQtRbgAAAaU"]
[Tue Jul 21 08:13:24.907977 2026] [security2:error] [pid 402041:tid 402196] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9UVIiENNLP6XjiHQtRbwAAAaY"]
[Tue Jul 21 08:13:24.933047 2026] [security2:error] [pid 402041:tid 402107] [remote 41.186.86.12:59105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9UVIiENNLP6XjiHQtRcAAB_D8"]
[Tue Jul 21 08:13:24.969467 2026] [security2:error] [pid 402041:tid 402255] [client 20.104.96.117:54661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/xpwer1.php"] [unique_id "al9UVIiENNLP6XjiHQtRdAAAAeE"]
[Tue Jul 21 08:13:25.122072 2026] [security2:error] [pid 402041:tid 402252] [client 20.151.10.161:13206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/aa2.php"] [unique_id "al9UVYiENNLP6XjiHQtReQAAAd4"]
[Tue Jul 21 08:13:25.186315 2026] [security2:error] [pid 402041:tid 402227] [client 151.63.71.144:55596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9UVYiENNLP6XjiHQtRegAAAcU"]
[Tue Jul 21 08:13:25.186603 2026] [security2:error] [pid 402041:tid 402227] [client 151.63.71.144:55596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9UVYiENNLP6XjiHQtRegAAAcU"]
[Tue Jul 21 08:13:25.190908 2026] [security2:error] [pid 402041:tid 402181] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gustavofurtadocrisos1781873322708.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9UVYiENNLP6XjiHQtRewAAAZc"]
[Tue Jul 21 08:13:25.398734 2026] [security2:error] [pid 402041:tid 402217] [client 20.151.10.161:13267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/ccou.php"] [unique_id "al9UVYiENNLP6XjiHQtRfQAAAbs"]
[Tue Jul 21 08:13:25.401074 2026] [security2:error] [pid 402041:tid 402265] [client 20.151.10.161:55852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/hypo.php"] [unique_id "al9UVYiENNLP6XjiHQtRfgAAAes"]
[Tue Jul 21 08:13:25.489725 2026] [proxy:error] [pid 402041:tid 402281] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:13:25.489789 2026] [proxy_http:error] [pid 402041:tid 402281] [client 64.23.245.156:53580] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.moveisrafael.com.br/
[Tue Jul 21 08:13:25.490312 2026] [proxy:error] [pid 402041:tid 402281] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:13:25.490335 2026] [proxy_http:error] [pid 402041:tid 402281] [client 64.23.245.156:53580] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.moveisrafael.com.br/
[Tue Jul 21 08:13:25.729889 2026] [security2:error] [pid 402041:tid 402183] [client 61.1.167.83:51247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UVYiENNLP6XjiHQtRjwAAAZk"]
[Tue Jul 21 08:13:25.730005 2026] [security2:error] [pid 402041:tid 402183] [client 61.1.167.83:51247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UVYiENNLP6XjiHQtRjwAAAZk"]
[Tue Jul 21 08:13:25.733401 2026] [security2:error] [pid 402041:tid 402242] [client 20.151.10.161:13159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/dr.php"] [unique_id "al9UVYiENNLP6XjiHQtRkAAAAdQ"]
[Tue Jul 21 08:13:26.027006 2026] [security2:error] [pid 402041:tid 402275] [client 187.125.243.197:59526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UVoiENNLP6XjiHQtRlgAAAfU"]
[Tue Jul 21 08:13:26.027165 2026] [security2:error] [pid 402041:tid 402275] [client 187.125.243.197:59526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UVoiENNLP6XjiHQtRlgAAAfU"]
[Tue Jul 21 08:13:26.029681 2026] [security2:error] [pid 402041:tid 402235] [client 20.151.10.161:13174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/file31.php"] [unique_id "al9UVoiENNLP6XjiHQtRlwAAAc0"]
[Tue Jul 21 08:13:26.304742 2026] [security2:error] [pid 402041:tid 402161] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UVoiENNLP6XjiHQtRogABr3U"]
[Tue Jul 21 08:13:26.304902 2026] [security2:error] [pid 402041:tid 402205] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UVoiENNLP6XjiHQtRogABr3U"]
[Tue Jul 21 08:13:26.340650 2026] [security2:error] [pid 402041:tid 402254] [client 20.151.10.161:55884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/chosen.php"] [unique_id "al9UVoiENNLP6XjiHQtRowAAAeA"]
[Tue Jul 21 08:13:26.682941 2026] [security2:error] [pid 402041:tid 402269] [client 20.151.10.161:13191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/file6.php"] [unique_id "al9UVoiENNLP6XjiHQtRrQAAAe8"]
[Tue Jul 21 08:13:26.944241 2026] [security2:error] [pid 402041:tid 402285] [client 120.56.162.40:58685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UVoiENNLP6XjiHQtRtQAAAf8"]
[Tue Jul 21 08:13:26.944354 2026] [security2:error] [pid 402041:tid 402285] [client 120.56.162.40:58685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UVoiENNLP6XjiHQtRtQAAAf8"]
[Tue Jul 21 08:13:26.947255 2026] [core:alert] [pid 402041:tid 402197] [client 57.141.18.78:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:13:27.106299 2026] [security2:error] [pid 402041:tid 402176] [client 20.151.10.161:13146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/file15.php"] [unique_id "al9UV4iENNLP6XjiHQtRvQAAAZI"]
[Tue Jul 21 08:13:27.112865 2026] [security2:error] [pid 402041:tid 402191] [client 20.151.10.161:50948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/als.php"] [unique_id "al9UV4iENNLP6XjiHQtRvgAAAaE"]
[Tue Jul 21 08:13:27.496505 2026] [security2:error] [pid 402041:tid 402173] [client 20.151.10.161:13207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/jp.php"] [unique_id "al9UV4iENNLP6XjiHQtRxQAAAY8"]
[Tue Jul 21 08:13:27.553580 2026] [security2:error] [pid 402041:tid 402182] [client 150.129.202.39:64681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UV4iENNLP6XjiHQtRyAAAAZg"]
[Tue Jul 21 08:13:27.553677 2026] [security2:error] [pid 402041:tid 402182] [client 150.129.202.39:64681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UV4iENNLP6XjiHQtRyAAAAZg"]
[Tue Jul 21 08:13:27.616676 2026] [security2:error] [pid 402041:tid 402235] [client 20.226.60.151:49359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/biufile.php"] [unique_id "al9UV4iENNLP6XjiHQtRywAAAc0"]
[Tue Jul 21 08:13:27.941714 2026] [security2:error] [pid 402041:tid 402239] [client 20.151.10.161:55875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/pol.php"] [unique_id "al9UV4iENNLP6XjiHQtR0wAAAdE"]
[Tue Jul 21 08:13:27.962054 2026] [security2:error] [pid 402041:tid 402196] [client 20.220.225.223:58373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/edit.php"] [unique_id "al9UV4iENNLP6XjiHQtR1AAAAaY"]
[Tue Jul 21 08:13:27.969911 2026] [security2:error] [pid 402041:tid 402209] [client 20.151.10.161:13190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/f35.php"] [unique_id "al9UV4iENNLP6XjiHQtR1QAAAbM"]
[Tue Jul 21 08:13:28.192388 2026] [security2:error] [pid 402041:tid 402170] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UWIiENNLP6XjiHQtR3AAB3n4"]
[Tue Jul 21 08:13:28.192538 2026] [security2:error] [pid 402041:tid 402252] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UWIiENNLP6XjiHQtR3AAB3n4"]
[Tue Jul 21 08:13:28.464918 2026] [fcgid:warn] [pid 402041:tid 402265] (70014)End of file found: [client 66.132.172.187:44772] mod_fcgid: can't get data from http client
[Tue Jul 21 08:13:28.616684 2026] [security2:error] [pid 402041:tid 402179] [client 20.104.96.117:54693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/flox.php"] [unique_id "al9UWIiENNLP6XjiHQtR7QAAAZU"]
[Tue Jul 21 08:13:28.683023 2026] [security2:error] [pid 402041:tid 402189] [client 20.151.10.161:13212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wp-load.php"] [unique_id "al9UWIiENNLP6XjiHQtR7gAAAZ8"]
[Tue Jul 21 08:13:29.080446 2026] [security2:error] [pid 402041:tid 402271] [client 162.219.176.3:56838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9UWYiENNLP6XjiHQtR-QAAAfE"]
[Tue Jul 21 08:13:29.080565 2026] [security2:error] [pid 402041:tid 402271] [client 162.219.176.3:56838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9UWYiENNLP6XjiHQtR-QAAAfE"]
[Tue Jul 21 08:13:29.488036 2026] [security2:error] [pid 402041:tid 402223] [client 117.210.135.0:64313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UWYiENNLP6XjiHQtSBwAAAcE"]
[Tue Jul 21 08:13:29.488147 2026] [security2:error] [pid 402041:tid 402223] [client 117.210.135.0:64313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UWYiENNLP6XjiHQtSBwAAAcE"]
[Tue Jul 21 08:13:29.795762 2026] [security2:error] [pid 402041:tid 402200] [client 20.226.60.151:49350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/av.php"] [unique_id "al9UWYiENNLP6XjiHQtSEQAAAao"]
[Tue Jul 21 08:13:29.806042 2026] [security2:error] [pid 402041:tid 402224] [client 20.104.96.117:63048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/popo.php"] [unique_id "al9UWYiENNLP6XjiHQtSEgAAAcI"]
[Tue Jul 21 08:13:30.054048 2026] [autoindex:error] [pid 402041:tid 402205] [client 20.151.10.161:13185] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:13:30.074289 2026] [security2:error] [pid 402041:tid 402298] [client 65.21.113.253:42286] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UWYiENNLP6XjiHQtSDAAAAgw"]
[Tue Jul 21 08:13:30.182864 2026] [security2:error] [pid 402041:tid 402157] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UWoiENNLP6XjiHQtSIQAB1nE"]
[Tue Jul 21 08:13:30.183000 2026] [security2:error] [pid 402041:tid 402244] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UWoiENNLP6XjiHQtSIQAB1nE"]
[Tue Jul 21 08:13:30.260081 2026] [security2:error] [pid 402041:tid 402077] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9UWoiENNLP6XjiHQtSIwABySE"]
[Tue Jul 21 08:13:30.279782 2026] [security2:error] [pid 402041:tid 402135] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9UWoiENNLP6XjiHQtSJQABkls"]
[Tue Jul 21 08:13:30.309969 2026] [security2:error] [pid 402041:tid 402162] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/dp.php"] [unique_id "al9UWoiENNLP6XjiHQtSJgABoXY"]
[Tue Jul 21 08:13:30.334961 2026] [security2:error] [pid 402041:tid 402095] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/old.php"] [unique_id "al9UWoiENNLP6XjiHQtSJwABkDM"]
[Tue Jul 21 08:13:30.366846 2026] [security2:error] [pid 402041:tid 402151] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/ms-new.php"] [unique_id "al9UWoiENNLP6XjiHQtSKQAB7ms"]
[Tue Jul 21 08:13:30.391034 2026] [security2:error] [pid 402041:tid 402045] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/track.php"] [unique_id "al9UWoiENNLP6XjiHQtSKgACAQE"]
[Tue Jul 21 08:13:30.416934 2026] [security2:error] [pid 402041:tid 402060] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/2352356666.php"] [unique_id "al9UWoiENNLP6XjiHQtSLQAB8hA"]
[Tue Jul 21 08:13:30.434115 2026] [security2:error] [pid 402041:tid 402094] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/pn.php"] [unique_id "al9UWoiENNLP6XjiHQtSLwABrDI"]
[Tue Jul 21 08:13:30.457807 2026] [security2:error] [pid 402041:tid 402141] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/wp-wpbak.php"] [unique_id "al9UWoiENNLP6XjiHQtSMQABymE"]
[Tue Jul 21 08:13:30.482067 2026] [security2:error] [pid 402041:tid 402110] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/dr.php"] [unique_id "al9UWoiENNLP6XjiHQtSMgACAkI"]
[Tue Jul 21 08:13:30.516329 2026] [security2:error] [pid 402041:tid 402123] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/2x.php"] [unique_id "al9UWoiENNLP6XjiHQtSNAABmk8"]
[Tue Jul 21 08:13:30.529810 2026] [security2:error] [pid 402041:tid 402086] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/kq1.php"] [unique_id "al9UWoiENNLP6XjiHQtSNwAB1Co"]
[Tue Jul 21 08:13:30.543254 2026] [autoindex:error] [pid 402041:tid 402247] [client 20.151.10.161:13185] AH01276: Cannot serve directory /home1/pedid516/consultecobertura.com.br/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:13:30.546650 2026] [security2:error] [pid 402041:tid 402171] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/zzz.php"] [unique_id "al9UWoiENNLP6XjiHQtSOQABnn8"]
[Tue Jul 21 08:13:30.569615 2026] [security2:error] [pid 402041:tid 402046] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/wicked.php"] [unique_id "al9UWoiENNLP6XjiHQtSOwABkQI"]
[Tue Jul 21 08:13:30.569934 2026] [security2:error] [pid 402041:tid 402108] [remote 192.241.143.148:60270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "selleto.com.br"] [uri "/wp-login.php"] [unique_id "al9UWoiENNLP6XjiHQtSPAABxkA"]
[Tue Jul 21 08:13:30.583092 2026] [security2:error] [pid 402041:tid 402078] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/edit.php"] [unique_id "al9UWoiENNLP6XjiHQtSPgABmSI"]
[Tue Jul 21 08:13:30.595849 2026] [security2:error] [pid 402041:tid 402137] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/kua.php"] [unique_id "al9UWoiENNLP6XjiHQtSPwACCl0"]
[Tue Jul 21 08:13:30.608687 2026] [security2:error] [pid 402041:tid 402085] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/ez.php"] [unique_id "al9UWoiENNLP6XjiHQtSQAABlyk"]
[Tue Jul 21 08:13:30.648599 2026] [security2:error] [pid 402041:tid 402092] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/fz.php"] [unique_id "al9UWoiENNLP6XjiHQtSQwAB8DA"]
[Tue Jul 21 08:13:30.672011 2026] [security2:error] [pid 402041:tid 402100] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/la.php"] [unique_id "al9UWoiENNLP6XjiHQtSRwAB5Tg"]
[Tue Jul 21 08:13:30.680591 2026] [security2:error] [pid 402041:tid 402215] [client 20.151.10.161:13307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9UWoiENNLP6XjiHQtSSQAAAbk"]
[Tue Jul 21 08:13:30.687360 2026] [security2:error] [pid 402041:tid 402124] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/nhvoanpl.php"] [unique_id "al9UWoiENNLP6XjiHQtSSgACBVA"]
[Tue Jul 21 08:13:30.708140 2026] [security2:error] [pid 402041:tid 402081] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/inso.php"] [unique_id "al9UWoiENNLP6XjiHQtSSwABpSU"]
[Tue Jul 21 08:13:30.736204 2026] [security2:error] [pid 402041:tid 402068] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/wpx.php"] [unique_id "al9UWoiENNLP6XjiHQtSTAABsxg"]
[Tue Jul 21 08:13:30.760482 2026] [security2:error] [pid 402041:tid 402087] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/berlin.php"] [unique_id "al9UWoiENNLP6XjiHQtSTQABpis"]
[Tue Jul 21 08:13:30.774797 2026] [security2:error] [pid 402041:tid 402166] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/billur.php"] [unique_id "al9UWoiENNLP6XjiHQtSTgAB0Xo"]
[Tue Jul 21 08:13:30.789656 2026] [security2:error] [pid 402041:tid 402090] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/mimpi.php"] [unique_id "al9UWoiENNLP6XjiHQtSTwAB6S4"]
[Tue Jul 21 08:13:30.817145 2026] [security2:error] [pid 402041:tid 402133] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/dp.php"] [unique_id "al9UWoiENNLP6XjiHQtSUAABvlk"]
[Tue Jul 21 08:13:30.830931 2026] [security2:error] [pid 402041:tid 402101] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/bootstrap.php"] [unique_id "al9UWoiENNLP6XjiHQtSUQAByDk"]
[Tue Jul 21 08:13:30.843671 2026] [security2:error] [pid 402041:tid 402096] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/wp-editor.php"] [unique_id "al9UWoiENNLP6XjiHQtSUwAB4TQ"]
[Tue Jul 21 08:13:30.852164 2026] [autoindex:error] [pid 402041:tid 402254] [client 205.210.31.35:62214] AH01276: Cannot serve directory /home1/ofic8899/sulinex.oficialwebsite.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:13:30.864461 2026] [security2:error] [pid 402041:tid 402072] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/cro.php"] [unique_id "al9UWoiENNLP6XjiHQtSVAACBBw"]
[Tue Jul 21 08:13:30.878458 2026] [security2:error] [pid 402041:tid 402155] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/cron-tab.php"] [unique_id "al9UWoiENNLP6XjiHQtSVQABqm8"]
[Tue Jul 21 08:13:30.902601 2026] [security2:error] [pid 402041:tid 402111] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/koiy.php"] [unique_id "al9UWoiENNLP6XjiHQtSWQAB2kM"]
[Tue Jul 21 08:13:30.918104 2026] [security2:error] [pid 402041:tid 402083] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/hp2.php"] [unique_id "al9UWoiENNLP6XjiHQtSWgAB6ic"]
[Tue Jul 21 08:13:30.942928 2026] [security2:error] [pid 402041:tid 402044] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/hp3.php"] [unique_id "al9UWoiENNLP6XjiHQtSWwAB3gA"]
[Tue Jul 21 08:13:30.956374 2026] [security2:error] [pid 402041:tid 402112] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/aa1.php"] [unique_id "al9UWoiENNLP6XjiHQtSXAAB40Q"]
[Tue Jul 21 08:13:30.969089 2026] [security2:error] [pid 402041:tid 402099] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/acew67.php"] [unique_id "al9UWoiENNLP6XjiHQtSXQAB5jc"]
[Tue Jul 21 08:13:30.995699 2026] [security2:error] [pid 402041:tid 402061] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/bscclapb.php"] [unique_id "al9UWoiENNLP6XjiHQtSXgABsBE"]
[Tue Jul 21 08:13:31.016753 2026] [security2:error] [pid 402041:tid 402276] [client 162.219.176.3:46678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9UW4iENNLP6XjiHQtSXwAAAfY"]
[Tue Jul 21 08:13:31.016834 2026] [security2:error] [pid 402041:tid 402276] [client 162.219.176.3:46678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9UW4iENNLP6XjiHQtSXwAAAfY"]
[Tue Jul 21 08:13:31.026398 2026] [security2:error] [pid 402041:tid 402059] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/else1.php"] [unique_id "al9UW4iENNLP6XjiHQtSYAABwA8"]
[Tue Jul 21 08:13:31.040046 2026] [security2:error] [pid 402041:tid 402129] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/tkikikoko.php"] [unique_id "al9UW4iENNLP6XjiHQtSYQAB1VU"]
[Tue Jul 21 08:13:31.053212 2026] [security2:error] [pid 402041:tid 402120] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/wp-Blogs.php"] [unique_id "al9UW4iENNLP6XjiHQtSYwAB2Ew"]
[Tue Jul 21 08:13:31.055839 2026] [security2:error] [pid 402041:tid 402075] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UW4iENNLP6XjiHQtSZAAB9R8"]
[Tue Jul 21 08:13:31.056005 2026] [security2:error] [pid 402041:tid 402275] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UW4iENNLP6XjiHQtSZAAB9R8"]
[Tue Jul 21 08:13:31.108263 2026] [security2:error] [pid 402041:tid 402089] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/wp-css.php"] [unique_id "al9UW4iENNLP6XjiHQtSZgABoi0"]
[Tue Jul 21 08:13:31.115059 2026] [security2:error] [pid 402041:tid 402203] [client 20.151.10.161:13208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wp-links.php"] [unique_id "al9UW4iENNLP6XjiHQtSZwAAAa0"]
[Tue Jul 21 08:13:31.129819 2026] [security2:error] [pid 402041:tid 402154] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/wp-explorer.php"] [unique_id "al9UW4iENNLP6XjiHQtSaAAB624"]
[Tue Jul 21 08:13:31.157542 2026] [security2:error] [pid 402041:tid 402050] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/akismet.php"] [unique_id "al9UW4iENNLP6XjiHQtSaQACDAY"]
[Tue Jul 21 08:13:31.176386 2026] [security2:error] [pid 402041:tid 402104] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/ace2.php"] [unique_id "al9UW4iENNLP6XjiHQtSawABpzw"]
[Tue Jul 21 08:13:31.201016 2026] [security2:error] [pid 402041:tid 402102] [remote 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.deiacakes.com"] [uri "/ms.php"] [unique_id "al9UW4iENNLP6XjiHQtSbQAB1jo"]
[Tue Jul 21 08:13:31.216627 2026] [security2:error] [pid 402041:tid 402200] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UW4iENNLP6XjiHQtSYgABqjU"]
[Tue Jul 21 08:13:31.459129 2026] [security2:error] [pid 402041:tid 402210] [client 20.151.10.161:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file5.php"] [unique_id "al9UW4iENNLP6XjiHQtSdAAAAbQ"]
[Tue Jul 21 08:13:31.597957 2026] [security2:error] [pid 402041:tid 402288] [client 20.151.10.161:13271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/solo1.php"] [unique_id "al9UW4iENNLP6XjiHQtSdgAAAgI"]
[Tue Jul 21 08:13:31.624260 2026] [security2:error] [pid 402041:tid 402048] [remote 192.249.127.213:54768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.127.249.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9UWoiENNLP6XjiHQtSQgAB9AQ"]
[Tue Jul 21 08:13:31.624481 2026] [security2:error] [pid 402041:tid 402274] [client 192.249.127.213:54768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9UWoiENNLP6XjiHQtSQgAB9AQ"]
[Tue Jul 21 08:13:31.880000 2026] [security2:error] [pid 402041:tid 402281] [client 38.100.221.102:19026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UW4iENNLP6XjiHQtSfwAAAfs"]
[Tue Jul 21 08:13:31.880769 2026] [security2:error] [pid 402041:tid 402281] [client 38.100.221.102:19026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UW4iENNLP6XjiHQtSfwAAAfs"]
[Tue Jul 21 08:13:31.953351 2026] [security2:error] [pid 402041:tid 402177] [client 20.226.60.151:48826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/coffexium.php"] [unique_id "al9UW4iENNLP6XjiHQtSgwAAAZM"]
[Tue Jul 21 08:13:32.069542 2026] [security2:error] [pid 402041:tid 402279] [client 87.116.180.198:27339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UXIiENNLP6XjiHQtShAAAAfk"]
[Tue Jul 21 08:13:32.073984 2026] [security2:error] [pid 402041:tid 402279] [client 87.116.180.198:27339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UXIiENNLP6XjiHQtShAAAAfk"]
[Tue Jul 21 08:13:32.101306 2026] [security2:error] [pid 402041:tid 402291] [client 20.151.10.161:13252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/sixxis.php"] [unique_id "al9UXIiENNLP6XjiHQtShQAAAgU"]
[Tue Jul 21 08:13:32.127686 2026] [security2:error] [pid 402041:tid 402223] [client 20.104.96.117:54102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/yas.php"] [unique_id "al9UXIiENNLP6XjiHQtShgAAAcE"]
[Tue Jul 21 08:13:32.464338 2026] [security2:error] [pid 402041:tid 402185] [client 20.151.10.161:13245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/2P.update.php"] [unique_id "al9UXIiENNLP6XjiHQtSkQAAAZs"]
[Tue Jul 21 08:13:32.755229 2026] [security2:error] [pid 402041:tid 402265] [client 20.151.10.161:13198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/a.php"] [unique_id "al9UXIiENNLP6XjiHQtSmAAAAes"]
[Tue Jul 21 08:13:32.805715 2026] [security2:error] [pid 402041:tid 402132] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UXIiENNLP6XjiHQtSoQABsFg"]
[Tue Jul 21 08:13:32.805851 2026] [security2:error] [pid 402041:tid 402206] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UXIiENNLP6XjiHQtSoQABsFg"]
[Tue Jul 21 08:13:33.030444 2026] [security2:error] [pid 402041:tid 402210] [client 20.151.10.161:13218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/k.php"] [unique_id "al9UXYiENNLP6XjiHQtSqgAAAbQ"]
[Tue Jul 21 08:13:33.445328 2026] [security2:error] [pid 402041:tid 402300] [client 20.151.10.161:13124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/w.php"] [unique_id "al9UXYiENNLP6XjiHQtSsgAAAg4"]
[Tue Jul 21 08:13:33.658910 2026] [security2:error] [pid 402041:tid 402268] [client 74.7.228.13:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.aede.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9UXYiENNLP6XjiHQtSwQAAAe4"]
[Tue Jul 21 08:13:33.660684 2026] [security2:error] [pid 402041:tid 402220] [client 74.7.228.13:53410] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.aede.com.br"] [uri "/robots.txt"] [unique_id "al9UXYiENNLP6XjiHQtSvwAAAb4"]
[Tue Jul 21 08:13:33.721734 2026] [security2:error] [pid 402041:tid 402278] [client 20.151.10.161:13126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/insc.php"] [unique_id "al9UXYiENNLP6XjiHQtSzwAAAfg"]
[Tue Jul 21 08:13:33.894266 2026] [security2:error] [pid 402041:tid 402253] [client 103.78.200.11:51490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UXYiENNLP6XjiHQtS2wAAAd8"]
[Tue Jul 21 08:13:33.894376 2026] [security2:error] [pid 402041:tid 402253] [client 103.78.200.11:51490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UXYiENNLP6XjiHQtS2wAAAd8"]
[Tue Jul 21 08:13:34.007181 2026] [security2:error] [pid 402041:tid 402230] [client 20.151.10.161:13211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9UXoiENNLP6XjiHQtS3gAAAcg"]
[Tue Jul 21 08:13:34.383211 2026] [security2:error] [pid 402041:tid 402051] [remote 199.189.225.40:52989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9UXoiENNLP6XjiHQtS6wAB7Ac"]
[Tue Jul 21 08:13:34.418373 2026] [security2:error] [pid 402041:tid 402232] [client 20.151.10.161:13297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/u.php"] [unique_id "al9UXoiENNLP6XjiHQtS7QAAAco"]
[Tue Jul 21 08:13:34.435493 2026] [security2:error] [pid 402041:tid 402200] [client 74.7.230.7:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "componentemais.com.br"] [uri "/index.php"] [unique_id "al9UXIiENNLP6XjiHQtSogAAAao"]
[Tue Jul 21 08:13:34.436161 2026] [security2:error] [pid 402041:tid 402275] [client 74.7.230.7:44888] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "componentemais.com.br"] [uri "/robots.txt"] [unique_id "al9UXIiENNLP6XjiHQtSnwAB9XI"]
[Tue Jul 21 08:13:34.477656 2026] [security2:error] [pid 402041:tid 402286] [client 102.206.115.33:62280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UXoiENNLP6XjiHQtS7gAAAgA"]
[Tue Jul 21 08:13:34.477799 2026] [security2:error] [pid 402041:tid 402286] [client 102.206.115.33:62280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UXoiENNLP6XjiHQtS7gAAAgA"]
[Tue Jul 21 08:13:34.557104 2026] [security2:error] [pid 402041:tid 402179] [client 20.197.192.193:44779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9UXoiENNLP6XjiHQtS8AAAAZU"]
[Tue Jul 21 08:13:34.599258 2026] [security2:error] [pid 402041:tid 402228] [client 20.104.96.117:54680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/file61.php"] [unique_id "al9UXoiENNLP6XjiHQtS8wAAAcY"]
[Tue Jul 21 08:13:34.615678 2026] [security2:error] [pid 402041:tid 402262] [client 20.104.96.117:62553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9UXoiENNLP6XjiHQtS9gAAAeg"]
[Tue Jul 21 08:13:34.653329 2026] [security2:error] [pid 402041:tid 402177] [client 20.226.60.151:48779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/core.php"] [unique_id "al9UXoiENNLP6XjiHQtS-AAAAZM"]
[Tue Jul 21 08:13:34.657465 2026] [security2:error] [pid 402041:tid 402204] [client 20.197.192.193:60981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9UXoiENNLP6XjiHQtS-QAAAa4"]
[Tue Jul 21 08:13:34.737623 2026] [security2:error] [pid 402041:tid 402213] [client 20.197.192.193:60958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/dp.php"] [unique_id "al9UXoiENNLP6XjiHQtS_QAAAbc"]
[Tue Jul 21 08:13:34.777673 2026] [security2:error] [pid 402041:tid 402224] [client 20.197.192.193:44784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/old.php"] [unique_id "al9UXoiENNLP6XjiHQtS_gAAAcI"]
[Tue Jul 21 08:13:34.795576 2026] [security2:error] [pid 402041:tid 402278] [client 20.151.10.161:13292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/sss.php"] [unique_id "al9UXoiENNLP6XjiHQtTAgAAAfg"]
[Tue Jul 21 08:13:34.858838 2026] [security2:error] [pid 402041:tid 402260] [client 20.197.192.193:44788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/ms-new.php"] [unique_id "al9UXoiENNLP6XjiHQtTAwAAAeY"]
[Tue Jul 21 08:13:34.965423 2026] [security2:error] [pid 402041:tid 402227] [client 20.197.192.193:44759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/track.php"] [unique_id "al9UXoiENNLP6XjiHQtTCAAAAcU"]
[Tue Jul 21 08:13:35.088421 2026] [security2:error] [pid 402041:tid 402225] [client 20.151.10.161:13222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/sss.php"] [unique_id "al9UX4iENNLP6XjiHQtTEAAAAcM"]
[Tue Jul 21 08:13:35.145437 2026] [security2:error] [pid 402041:tid 402189] [client 20.197.192.193:60929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/2352356666.php"] [unique_id "al9UX4iENNLP6XjiHQtTEQAAAZ8"]
[Tue Jul 21 08:13:35.214330 2026] [security2:error] [pid 402041:tid 402188] [client 154.208.47.43:46481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UX4iENNLP6XjiHQtTEwAAAZ4"]
[Tue Jul 21 08:13:35.214476 2026] [security2:error] [pid 402041:tid 402188] [client 154.208.47.43:46481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UX4iENNLP6XjiHQtTEwAAAZ4"]
[Tue Jul 21 08:13:35.329166 2026] [security2:error] [pid 402041:tid 402174] [client 20.197.192.193:44786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/pn.php"] [unique_id "al9UX4iENNLP6XjiHQtTFQAAAZA"]
[Tue Jul 21 08:13:35.378844 2026] [security2:error] [pid 402041:tid 402288] [client 20.151.10.161:13295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/c.php"] [unique_id "al9UX4iENNLP6XjiHQtTFwAAAgI"]
[Tue Jul 21 08:13:35.392843 2026] [security2:error] [pid 402041:tid 402200] [client 20.197.192.193:60950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9UX4iENNLP6XjiHQtTGAAAAao"]
[Tue Jul 21 08:13:35.444551 2026] [security2:error] [pid 402041:tid 402286] [client 20.197.192.193:44766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/dr.php"] [unique_id "al9UX4iENNLP6XjiHQtTHQAAAgA"]
[Tue Jul 21 08:13:35.481012 2026] [security2:error] [pid 402041:tid 402226] [client 20.197.192.193:44737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/2x.php"] [unique_id "al9UX4iENNLP6XjiHQtTHgAAAcQ"]
[Tue Jul 21 08:13:35.564217 2026] [security2:error] [pid 402041:tid 402281] [client 20.197.192.193:60933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/kq1.php"] [unique_id "al9UX4iENNLP6XjiHQtTIAAAAfs"]
[Tue Jul 21 08:13:35.623462 2026] [security2:error] [pid 402041:tid 402258] [client 20.197.192.193:60952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/zzz.php"] [unique_id "al9UX4iENNLP6XjiHQtTJAAAAeQ"]
[Tue Jul 21 08:13:35.644028 2026] [security2:error] [pid 402041:tid 402253] [client 111.93.58.162:42042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UX4iENNLP6XjiHQtTJQAAAd8"]
[Tue Jul 21 08:13:35.644133 2026] [security2:error] [pid 402041:tid 402253] [client 111.93.58.162:42042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UX4iENNLP6XjiHQtTJQAAAd8"]
[Tue Jul 21 08:13:35.672457 2026] [security2:error] [pid 402041:tid 402259] [client 20.197.192.193:60940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/wicked.php"] [unique_id "al9UX4iENNLP6XjiHQtTJgAAAeU"]
[Tue Jul 21 08:13:35.674330 2026] [security2:error] [pid 402041:tid 402215] [client 20.151.10.161:55903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9UX4iENNLP6XjiHQtTJwAAAbk"]
[Tue Jul 21 08:13:35.734992 2026] [security2:error] [pid 402041:tid 402270] [client 20.151.10.161:13123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/aa.php"] [unique_id "al9UX4iENNLP6XjiHQtTKAAAAfA"]
[Tue Jul 21 08:13:35.793444 2026] [security2:error] [pid 402041:tid 402263] [client 20.197.192.193:60990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/edit.php"] [unique_id "al9UX4iENNLP6XjiHQtTKQAAAek"]
[Tue Jul 21 08:13:35.974995 2026] [security2:error] [pid 402041:tid 402271] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UXoiENNLP6XjiHQtS9wAB8Ro"]
[Tue Jul 21 08:13:36.024548 2026] [security2:error] [pid 402041:tid 402187] [client 20.197.192.193:44748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/kua.php"] [unique_id "al9UYIiENNLP6XjiHQtTMgAAAZ0"]
[Tue Jul 21 08:13:36.076575 2026] [security2:error] [pid 402041:tid 402230] [client 20.151.10.161:13272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/100.php"] [unique_id "al9UYIiENNLP6XjiHQtTMwAAAcg"]
[Tue Jul 21 08:13:36.361793 2026] [security2:error] [pid 402041:tid 402287] [client 20.151.10.161:13194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/footer.php"] [unique_id "al9UYIiENNLP6XjiHQtTOgAAAgE"]
[Tue Jul 21 08:13:36.430107 2026] [security2:error] [pid 402041:tid 402289] [client 103.151.46.103:56824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UYIiENNLP6XjiHQtTPAAAAgM"]
[Tue Jul 21 08:13:36.430253 2026] [security2:error] [pid 402041:tid 402289] [client 103.151.46.103:56824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UYIiENNLP6XjiHQtTPAAAAgM"]
[Tue Jul 21 08:13:36.438204 2026] [security2:error] [pid 402041:tid 402205] [client 81.171.72.135:38204] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/"] [unique_id "al9UYIiENNLP6XjiHQtTPQAAAa8"]
[Tue Jul 21 08:13:36.440758 2026] [security2:error] [pid 402041:tid 402189] [client 81.171.72.135:38196] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/"] [unique_id "al9UYIiENNLP6XjiHQtTPgAAAZ8"]
[Tue Jul 21 08:13:36.440877 2026] [security2:error] [pid 402041:tid 402197] [client 81.171.72.135:38218] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/"] [unique_id "al9UYIiENNLP6XjiHQtTPwAAAac"]
[Tue Jul 21 08:13:36.534827 2026] [security2:error] [pid 402041:tid 402267] [client 187.125.243.197:59998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UYIiENNLP6XjiHQtTQwAAAe0"]
[Tue Jul 21 08:13:36.534974 2026] [security2:error] [pid 402041:tid 402267] [client 187.125.243.197:59998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UYIiENNLP6XjiHQtTQwAAAe0"]
[Tue Jul 21 08:13:36.568939 2026] [security2:error] [pid 402041:tid 402288] [client 20.197.192.193:60956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/ez.php"] [unique_id "al9UYIiENNLP6XjiHQtTRAAAAgI"]
[Tue Jul 21 08:13:36.624373 2026] [security2:error] [pid 402041:tid 402291] [client 91.148.244.131:44570] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/"] [unique_id "al9UYIiENNLP6XjiHQtTRgAAAgU"]
[Tue Jul 21 08:13:36.624861 2026] [security2:error] [pid 402041:tid 402222] [client 91.148.244.131:44580] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/"] [unique_id "al9UYIiENNLP6XjiHQtTRwAAAcA"]
[Tue Jul 21 08:13:36.627348 2026] [security2:error] [pid 402041:tid 402210] [client 91.148.244.131:44588] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/"] [unique_id "al9UYIiENNLP6XjiHQtTSAAAAbQ"]
[Tue Jul 21 08:13:36.689748 2026] [security2:error] [pid 402041:tid 402179] [client 20.151.10.161:13279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/users.php"] [unique_id "al9UYIiENNLP6XjiHQtTTwAAAZU"]
[Tue Jul 21 08:13:36.731296 2026] [security2:error] [pid 402041:tid 402258] [client 20.226.60.151:48800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/als.php"] [unique_id "al9UYIiENNLP6XjiHQtTUQAAAeQ"]
[Tue Jul 21 08:13:36.951972 2026] [security2:error] [pid 402041:tid 402165] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UYIiENNLP6XjiHQtTjwAB2nk"]
[Tue Jul 21 08:13:36.952125 2026] [security2:error] [pid 402041:tid 402248] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UYIiENNLP6XjiHQtTjwAB2nk"]
[Tue Jul 21 08:13:36.978707 2026] [security2:error] [pid 402041:tid 402249] [client 20.151.10.161:13278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/177.php"] [unique_id "al9UYIiENNLP6XjiHQtTkQAAAds"]
[Tue Jul 21 08:13:37.317401 2026] [security2:error] [pid 402041:tid 402182] [client 20.151.10.161:13185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/config.php"] [unique_id "al9UYYiENNLP6XjiHQtTrwAAAZg"]
[Tue Jul 21 08:13:37.365226 2026] [security2:error] [pid 402041:tid 402211] [client 20.197.192.193:60936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/fz.php"] [unique_id "al9UYYiENNLP6XjiHQtTsAAAAbU"]
[Tue Jul 21 08:13:37.403918 2026] [security2:error] [pid 402041:tid 402297] [client 81.171.72.135:38236] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/database_backup.sql"] [unique_id "al9UYYiENNLP6XjiHQtTsgAAAgs"]
[Tue Jul 21 08:13:37.404122 2026] [security2:error] [pid 402041:tid 402265] [client 81.171.72.135:38260] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/wp-admin/setup-config.php"] [unique_id "al9UYYiENNLP6XjiHQtTswAAAes"]
[Tue Jul 21 08:13:37.404700 2026] [security2:error] [pid 402041:tid 402298] [client 81.171.72.135:38250] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/storage/logs/laravel.log"] [unique_id "al9UYYiENNLP6XjiHQtTtAAAAgw"]
[Tue Jul 21 08:13:37.563716 2026] [security2:error] [pid 402041:tid 402254] [client 120.56.162.40:59183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UYYiENNLP6XjiHQtT-QAAAeA"]
[Tue Jul 21 08:13:37.563807 2026] [security2:error] [pid 402041:tid 402254] [client 120.56.162.40:59183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UYYiENNLP6XjiHQtT-QAAAeA"]
[Tue Jul 21 08:13:37.602820 2026] [autoindex:error] [pid 402041:tid 402171] [remote 57.141.18.125:31606] AH01276: Cannot serve directory /home3/factor11/aumentodevendas.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:13:37.643036 2026] [security2:error] [pid 402041:tid 402123] [remote 84.247.172.23:55722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rqracademy.com"] [uri "/wp-login.php"] [unique_id "al9UYYiENNLP6XjiHQtT-wAB508"]
[Tue Jul 21 08:13:37.767434 2026] [security2:error] [pid 402041:tid 402242] [client 91.148.244.131:44616] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/backup.zip"] [unique_id "al9UYYiENNLP6XjiHQtUAQAAAdQ"]
[Tue Jul 21 08:13:37.768728 2026] [security2:error] [pid 402041:tid 402253] [client 91.148.244.131:44590] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/config.php"] [unique_id "al9UYYiENNLP6XjiHQtUAwAAAd8"]
[Tue Jul 21 08:13:37.768903 2026] [security2:error] [pid 402041:tid 402183] [client 91.148.244.131:44596] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9UYYiENNLP6XjiHQtUAgAAAZk"]
[Tue Jul 21 08:13:37.788760 2026] [security2:error] [pid 402041:tid 402220] [client 20.151.10.161:13285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/gettest.php"] [unique_id "al9UYYiENNLP6XjiHQtUBAAAAb4"]
[Tue Jul 21 08:13:38.037217 2026] [security2:error] [pid 402041:tid 402175] [client 81.171.72.135:38228] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/config.xml"] [unique_id "al9UYoiENNLP6XjiHQtUDwAAAZE"]
[Tue Jul 21 08:13:38.154986 2026] [security2:error] [pid 402041:tid 402283] [client 150.129.202.39:65326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UYoiENNLP6XjiHQtUEwAAAf0"]
[Tue Jul 21 08:13:38.155094 2026] [security2:error] [pid 402041:tid 402283] [client 150.129.202.39:65326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UYoiENNLP6XjiHQtUEwAAAf0"]
[Tue Jul 21 08:13:38.161148 2026] [security2:error] [pid 402041:tid 402241] [client 20.151.10.161:13242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/min.php"] [unique_id "al9UYoiENNLP6XjiHQtUFAAAAdM"]
[Tue Jul 21 08:13:38.373401 2026] [security2:error] [pid 402041:tid 402212] [client 81.171.72.135:38270] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/backup.sql"] [unique_id "al9UYoiENNLP6XjiHQtUGQAAAbY"]
[Tue Jul 21 08:13:38.374975 2026] [security2:error] [pid 402041:tid 402173] [client 81.171.72.135:38286] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/database.sql"] [unique_id "al9UYoiENNLP6XjiHQtUGgAAAY8"]
[Tue Jul 21 08:13:38.552685 2026] [security2:error] [pid 402041:tid 402299] [client 65.21.113.253:42294] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UYoiENNLP6XjiHQtUGwAAAg0"]
[Tue Jul 21 08:13:38.575224 2026] [security2:error] [pid 402041:tid 402083] [remote 13.41.15.21:36226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.15.41.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedrocromo.com.br"] [uri "/wp-login.php"] [unique_id "al9UYoiENNLP6XjiHQtUIAACASc"]
[Tue Jul 21 08:13:38.581856 2026] [security2:error] [pid 402041:tid 402263] [client 20.197.192.193:44789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/la.php"] [unique_id "al9UYoiENNLP6XjiHQtUIQAAAek"]
[Tue Jul 21 08:13:38.583568 2026] [security2:error] [pid 402041:tid 402223] [client 20.151.10.161:13144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/edorxrr.php"] [unique_id "al9UYoiENNLP6XjiHQtUIgAAAcE"]
[Tue Jul 21 08:13:38.590485 2026] [security2:error] [pid 402041:tid 402204] [client 91.148.244.131:44612] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/actuator/heapdump"] [unique_id "al9UYoiENNLP6XjiHQtUIwAAAa4"]
[Tue Jul 21 08:13:38.773875 2026] [security2:error] [pid 402041:tid 402044] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UYoiENNLP6XjiHQtUJQAB0AA"]
[Tue Jul 21 08:13:38.774015 2026] [security2:error] [pid 402041:tid 402238] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UYoiENNLP6XjiHQtUJQAB0AA"]
[Tue Jul 21 08:13:38.865333 2026] [security2:error] [pid 402041:tid 402286] [client 20.226.60.151:49237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/simple.php"] [unique_id "al9UYoiENNLP6XjiHQtUKgAAAgA"]
[Tue Jul 21 08:13:38.910017 2026] [security2:error] [pid 402041:tid 402261] [client 91.148.244.131:44638] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/.svn/wc.db"] [unique_id "al9UYoiENNLP6XjiHQtUKwAAAec"]
[Tue Jul 21 08:13:38.912007 2026] [security2:error] [pid 402041:tid 402174] [client 91.148.244.131:44630] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9UYoiENNLP6XjiHQtULAAAAZA"]
[Tue Jul 21 08:13:38.912958 2026] [security2:error] [pid 402041:tid 402203] [client 91.148.244.131:44662] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/backup.tar.gz"] [unique_id "al9UYoiENNLP6XjiHQtULQAAAa0"]
[Tue Jul 21 08:13:38.913051 2026] [security2:error] [pid 402041:tid 402209] [client 91.148.244.131:44636] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/config.xml"] [unique_id "al9UYoiENNLP6XjiHQtULgAAAbM"]
[Tue Jul 21 08:13:38.931639 2026] [security2:error] [pid 402041:tid 402046] [remote 173.252.70.52:44930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.70.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9UYYiENNLP6XjiHQtUAAAB2wI"]
[Tue Jul 21 08:13:38.999550 2026] [security2:error] [pid 402041:tid 402210] [client 151.63.71.144:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9UYoiENNLP6XjiHQtUMQAAAbQ"]
[Tue Jul 21 08:13:38.999896 2026] [security2:error] [pid 402041:tid 402210] [client 151.63.71.144:56300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9UYoiENNLP6XjiHQtUMQAAAbQ"]
[Tue Jul 21 08:13:39.029533 2026] [security2:error] [pid 402041:tid 402260] [client 74.7.228.63:53916] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dscbrasil.com.br"] [uri "/index.php"] [unique_id "al9UYoiENNLP6XjiHQtULwAB5jU"]
[Tue Jul 21 08:13:39.035700 2026] [security2:error] [pid 402041:tid 402187] [client 81.171.72.135:38320] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/backup.tar.gz"] [unique_id "al9UY4iENNLP6XjiHQtUMgAAAZ0"]
[Tue Jul 21 08:13:39.035785 2026] [security2:error] [pid 402041:tid 402220] [client 81.171.72.135:38348] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/wp-config.php"] [unique_id "al9UY4iENNLP6XjiHQtUNAAAAb4"]
[Tue Jul 21 08:13:39.035831 2026] [security2:error] [pid 402041:tid 402195] [client 81.171.72.135:38314] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/dump.sql"] [unique_id "al9UY4iENNLP6XjiHQtUMwAAAaU"]
[Tue Jul 21 08:13:39.036822 2026] [security2:error] [pid 402041:tid 402259] [client 81.171.72.135:38370] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/backup.zip"] [unique_id "al9UY4iENNLP6XjiHQtUNQAAAeU"]
[Tue Jul 21 08:13:39.107892 2026] [security2:error] [pid 402041:tid 402298] [client 20.197.192.193:44794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9UY4iENNLP6XjiHQtUOQAAAgw"]
[Tue Jul 21 08:13:39.112015 2026] [security2:error] [pid 402041:tid 402176] [client 91.148.244.131:44654] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/config/production.json"] [unique_id "al9UY4iENNLP6XjiHQtUOgAAAZI"]
[Tue Jul 21 08:13:39.241413 2026] [security2:error] [pid 402041:tid 402235] [client 81.171.72.135:38334] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/.svn/wc.db"] [unique_id "al9UY4iENNLP6XjiHQtUQAAAAc0"]
[Tue Jul 21 08:13:39.319947 2026] [security2:error] [pid 402041:tid 402234] [client 20.151.10.161:13142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/hur.php"] [unique_id "al9UY4iENNLP6XjiHQtUQwAAAcw"]
[Tue Jul 21 08:13:39.352279 2026] [security2:error] [pid 402041:tid 402218] [client 20.197.192.193:44754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/inso.php"] [unique_id "al9UY4iENNLP6XjiHQtURQAAAbw"]
[Tue Jul 21 08:13:39.426213 2026] [security2:error] [pid 402041:tid 402254] [client 20.104.96.117:63444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9UY4iENNLP6XjiHQtUcAAAAeA"]
[Tue Jul 21 08:13:39.613242 2026] [security2:error] [pid 402041:tid 402282] [client 20.197.192.193:54112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/wpx.php"] [unique_id "al9UY4iENNLP6XjiHQtUegAAAfw"]
[Tue Jul 21 08:13:39.641244 2026] [security2:error] [pid 402041:tid 402294] [client 65.21.113.253:42304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UY4iENNLP6XjiHQtUPwAAAgg"]
[Tue Jul 21 08:13:39.733593 2026] [security2:error] [pid 402041:tid 402238] [client 20.151.10.161:13168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/zoro.php"] [unique_id "al9UY4iENNLP6XjiHQtUewAAAdA"]
[Tue Jul 21 08:13:39.970717 2026] [security2:error] [pid 402041:tid 402232] [client 117.210.135.0:64956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UY4iENNLP6XjiHQtUgwAAAco"]
[Tue Jul 21 08:13:39.970827 2026] [security2:error] [pid 402041:tid 402232] [client 117.210.135.0:64956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UY4iENNLP6XjiHQtUgwAAAco"]
[Tue Jul 21 08:13:40.000351 2026] [security2:error] [pid 402041:tid 402221] [client 81.171.72.135:38424] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/config.php"] [unique_id "al9UY4iENNLP6XjiHQtUhQAAAb8"]
[Tue Jul 21 08:13:40.000671 2026] [security2:error] [pid 402041:tid 402252] [client 81.171.72.135:38404] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/.env.production"] [unique_id "al9UZIiENNLP6XjiHQtUhgAAAd4"]
[Tue Jul 21 08:13:40.001485 2026] [security2:error] [pid 402041:tid 402213] [client 81.171.72.135:38420] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/actuator/heapdump"] [unique_id "al9UZIiENNLP6XjiHQtUhwAAAbc"]
[Tue Jul 21 08:13:40.003297 2026] [security2:error] [pid 402041:tid 402248] [client 81.171.72.135:38430] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/.git/HEAD"] [unique_id "al9UZIiENNLP6XjiHQtUiAAAAdo"]
[Tue Jul 21 08:13:40.068909 2026] [security2:error] [pid 402041:tid 402195] [client 20.151.10.161:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/coffexium.php"] [unique_id "al9UZIiENNLP6XjiHQtUjAAAAaU"]
[Tue Jul 21 08:13:40.203158 2026] [security2:error] [pid 402041:tid 402300] [client 81.171.72.135:38376] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/api/.env"] [unique_id "al9UZIiENNLP6XjiHQtUjQAAAg4"]
[Tue Jul 21 08:13:40.203522 2026] [security2:error] [pid 402041:tid 402257] [client 81.171.72.135:38392] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/.env"] [unique_id "al9UZIiENNLP6XjiHQtUjgAAAeM"]
[Tue Jul 21 08:13:40.260126 2026] [security2:error] [pid 402041:tid 402239] [client 20.197.192.193:44740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/berlin.php"] [unique_id "al9UZIiENNLP6XjiHQtUkgAAAdE"]
[Tue Jul 21 08:13:40.282997 2026] [security2:error] [pid 402041:tid 402283] [client 20.151.10.161:51004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file.php"] [unique_id "al9UZIiENNLP6XjiHQtUkwAAAf0"]
[Tue Jul 21 08:13:40.314249 2026] [security2:error] [pid 402041:tid 402180] [client 20.197.192.193:60964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/billur.php"] [unique_id "al9UZIiENNLP6XjiHQtUlwAAAZY"]
[Tue Jul 21 08:13:40.318166 2026] [security2:error] [pid 402041:tid 402202] [client 20.104.96.117:63060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/water.php"] [unique_id "al9UZIiENNLP6XjiHQtUmAAAAaw"]
[Tue Jul 21 08:13:40.387902 2026] [security2:error] [pid 402041:tid 402251] [client 20.151.10.161:13177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/app.php"] [unique_id "al9UZIiENNLP6XjiHQtUnQAAAd0"]
[Tue Jul 21 08:13:40.420393 2026] [security2:error] [pid 402041:tid 402184] [client 20.197.192.193:54093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/mimpi.php"] [unique_id "al9UZIiENNLP6XjiHQtUngAAAZo"]
[Tue Jul 21 08:13:40.699682 2026] [security2:error] [pid 402041:tid 402294] [client 20.151.10.161:13262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/core.php"] [unique_id "al9UZIiENNLP6XjiHQtUpgAAAgg"]
[Tue Jul 21 08:13:40.749308 2026] [security2:error] [pid 402041:tid 402224] [client 20.197.192.193:54131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/dp.php"] [unique_id "al9UZIiENNLP6XjiHQtUqAAAAcI"]
[Tue Jul 21 08:13:40.796285 2026] [security2:error] [pid 402041:tid 402253] [client 20.197.192.193:3181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9UZIiENNLP6XjiHQtUrAAAAd8"]
[Tue Jul 21 08:13:40.831339 2026] [security2:error] [pid 402041:tid 402094] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UZIiENNLP6XjiHQtUrgACCjI"]
[Tue Jul 21 08:13:40.831462 2026] [security2:error] [pid 402041:tid 402296] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UZIiENNLP6XjiHQtUrgACCjI"]
[Tue Jul 21 08:13:40.867591 2026] [security2:error] [pid 402041:tid 402209] [client 20.197.192.193:44765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/bootstrap.php"] [unique_id "al9UZIiENNLP6XjiHQtUsgAAAbM"]
[Tue Jul 21 08:13:40.970745 2026] [security2:error] [pid 402041:tid 402206] [client 20.197.192.193:60934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/wp-editor.php"] [unique_id "al9UZIiENNLP6XjiHQtUuAAAAbA"]
[Tue Jul 21 08:13:41.013409 2026] [security2:error] [pid 402041:tid 402211] [client 20.151.10.161:13306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/main.php"] [unique_id "al9UZYiENNLP6XjiHQtUugAAAbU"]
[Tue Jul 21 08:13:41.034137 2026] [security2:error] [pid 402041:tid 402182] [client 66.179.30.133:48064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "wenith.com.br"] [uri "/"] [unique_id "al9UZYiENNLP6XjiHQtUuwAAAZg"]
[Tue Jul 21 08:13:41.083990 2026] [security2:error] [pid 402041:tid 402265] [client 20.197.192.193:44753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/cro.php"] [unique_id "al9UZYiENNLP6XjiHQtUvQAAAes"]
[Tue Jul 21 08:13:41.202783 2026] [security2:error] [pid 402041:tid 402297] [client 20.197.192.193:54083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/cron-tab.php"] [unique_id "al9UZYiENNLP6XjiHQtUxgAAAgs"]
[Tue Jul 21 08:13:41.294511 2026] [security2:error] [pid 402041:tid 402230] [client 20.197.192.193:60969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/koiy.php"] [unique_id "al9UZYiENNLP6XjiHQtUyQAAAcg"]
[Tue Jul 21 08:13:41.345892 2026] [security2:error] [pid 402041:tid 402234] [client 20.151.10.161:13284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/init.php"] [unique_id "al9UZYiENNLP6XjiHQtUygAAAcw"]
[Tue Jul 21 08:13:41.404541 2026] [security2:error] [pid 402041:tid 402274] [client 20.197.192.193:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/hp2.php"] [unique_id "al9UZYiENNLP6XjiHQtUzQAAAfQ"]
[Tue Jul 21 08:13:41.486357 2026] [security2:error] [pid 402041:tid 402258] [client 20.197.192.193:44778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/hp3.php"] [unique_id "al9UZYiENNLP6XjiHQtUzwAAAeQ"]
[Tue Jul 21 08:13:41.489137 2026] [security2:error] [pid 402041:tid 402177] [client 103.78.200.11:51975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UZYiENNLP6XjiHQtU0AAAAZM"]
[Tue Jul 21 08:13:41.489689 2026] [security2:error] [pid 402041:tid 402177] [client 103.78.200.11:51975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UZYiENNLP6XjiHQtU0AAAAZM"]
[Tue Jul 21 08:13:41.524729 2026] [security2:error] [pid 402041:tid 402142] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UZYiENNLP6XjiHQtU0QAB2GI"]
[Tue Jul 21 08:13:41.524842 2026] [security2:error] [pid 402041:tid 402246] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UZYiENNLP6XjiHQtU0QAB2GI"]
[Tue Jul 21 08:13:41.580769 2026] [security2:error] [pid 402041:tid 402208] [client 20.197.192.193:44741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/aa1.php"] [unique_id "al9UZYiENNLP6XjiHQtU0wAAAbI"]
[Tue Jul 21 08:13:41.728190 2026] [security2:error] [pid 402041:tid 402276] [client 20.151.10.161:13281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/prekel.php"] [unique_id "al9UZYiENNLP6XjiHQtU2AAAAfY"]
[Tue Jul 21 08:13:41.845090 2026] [security2:error] [pid 402041:tid 402236] [client 20.197.192.193:44768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/acew67.php"] [unique_id "al9UZYiENNLP6XjiHQtU2wAAAc4"]
[Tue Jul 21 08:13:42.037767 2026] [security2:error] [pid 402041:tid 402185] [client 20.151.10.161:13225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/0.php"] [unique_id "al9UZoiENNLP6XjiHQtU4AAAAZs"]
[Tue Jul 21 08:13:42.093899 2026] [security2:error] [pid 402041:tid 402196] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UZYiENNLP6XjiHQtU3wABpg0"]
[Tue Jul 21 08:13:42.186216 2026] [security2:error] [pid 402041:tid 402206] [client 20.197.192.193:44739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/bscclapb.php"] [unique_id "al9UZoiENNLP6XjiHQtU4wAAAbA"]
[Tue Jul 21 08:13:42.317959 2026] [security2:error] [pid 402041:tid 402231] [client 66.179.30.133:48080] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "wenith.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9UZoiENNLP6XjiHQtU6wAAAck"]
[Tue Jul 21 08:13:42.375201 2026] [security2:error] [pid 402041:tid 402277] [client 20.197.192.193:54106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/else1.php"] [unique_id "al9UZoiENNLP6XjiHQtU7AAAAfc"]
[Tue Jul 21 08:13:42.397148 2026] [security2:error] [pid 402041:tid 402270] [client 38.100.221.102:18253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UZoiENNLP6XjiHQtU7QAAAfA"]
[Tue Jul 21 08:13:42.397257 2026] [security2:error] [pid 402041:tid 402270] [client 38.100.221.102:18253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UZoiENNLP6XjiHQtU7QAAAfA"]
[Tue Jul 21 08:13:42.438329 2026] [security2:error] [pid 402041:tid 402266] [client 20.151.10.161:13138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/BDKR28.php"] [unique_id "al9UZoiENNLP6XjiHQtU8AAAAew"]
[Tue Jul 21 08:13:42.450002 2026] [security2:error] [pid 402041:tid 402283] [client 20.197.192.193:60959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/tkikikoko.php"] [unique_id "al9UZoiENNLP6XjiHQtU8gAAAf0"]
[Tue Jul 21 08:13:42.481076 2026] [security2:error] [pid 402041:tid 402228] [client 20.197.192.193:44799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9UZoiENNLP6XjiHQtU9gAAAcY"]
[Tue Jul 21 08:13:42.546067 2026] [security2:error] [pid 402041:tid 402202] [client 20.197.192.193:60942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/wp-css.php"] [unique_id "al9UZoiENNLP6XjiHQtU-AAAAaw"]
[Tue Jul 21 08:13:42.579802 2026] [security2:error] [pid 402041:tid 402195] [client 20.226.60.151:48879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/init.php"] [unique_id "al9UZoiENNLP6XjiHQtU-wAAAaU"]
[Tue Jul 21 08:13:42.662916 2026] [security2:error] [pid 402041:tid 402174] [client 87.116.180.198:27386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UZoiENNLP6XjiHQtU_QAAAZA"]
[Tue Jul 21 08:13:42.663046 2026] [security2:error] [pid 402041:tid 402174] [client 87.116.180.198:27386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UZoiENNLP6XjiHQtU_QAAAZA"]
[Tue Jul 21 08:13:42.714040 2026] [security2:error] [pid 402041:tid 402184] [client 20.197.192.193:44773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/wp-explorer.php"] [unique_id "al9UZoiENNLP6XjiHQtU_wAAAZo"]
[Tue Jul 21 08:13:42.747712 2026] [security2:error] [pid 402041:tid 402254] [client 20.197.192.193:44785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/akismet.php"] [unique_id "al9UZoiENNLP6XjiHQtVAgAAAeA"]
[Tue Jul 21 08:13:42.783171 2026] [security2:error] [pid 402041:tid 402280] [client 20.197.192.193:60944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/ace2.php"] [unique_id "al9UZoiENNLP6XjiHQtVBQAAAfo"]
[Tue Jul 21 08:13:42.817586 2026] [security2:error] [pid 402041:tid 402222] [client 20.151.10.161:13309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/f35.update.php"] [unique_id "al9UZoiENNLP6XjiHQtVBgAAAcA"]
[Tue Jul 21 08:13:42.871667 2026] [security2:error] [pid 402041:tid 402204] [client 20.197.192.193:60974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/ms.php"] [unique_id "al9UZoiENNLP6XjiHQtVBwAAAa4"]
[Tue Jul 21 08:13:43.138830 2026] [security2:error] [pid 402041:tid 402181] [client 20.151.10.161:13147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/f900.php"] [unique_id "al9UZ4iENNLP6XjiHQtVDQAAAZc"]
[Tue Jul 21 08:13:43.531055 2026] [security2:error] [pid 402041:tid 402265] [client 198.54.129.60:34052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9UZ4iENNLP6XjiHQtVGgAAAes"]
[Tue Jul 21 08:13:43.531145 2026] [security2:error] [pid 402041:tid 402265] [client 198.54.129.60:34052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9UZ4iENNLP6XjiHQtVGgAAAes"]
[Tue Jul 21 08:13:43.568472 2026] [security2:error] [pid 402041:tid 402278] [client 20.151.10.161:13214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/xmrl.php"] [unique_id "al9UZ4iENNLP6XjiHQtVGwAAAfg"]
[Tue Jul 21 08:13:43.691266 2026] [security2:error] [pid 402041:tid 402255] [client 20.151.10.161:51078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9UZ4iENNLP6XjiHQtVHAAAAeE"]
[Tue Jul 21 08:13:43.792154 2026] [security2:error] [pid 402041:tid 402077] [remote 132.148.72.88:47674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9UZ4iENNLP6XjiHQtVIgACCyE"]
[Tue Jul 21 08:13:43.959054 2026] [security2:error] [pid 402041:tid 402098] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UZ4iENNLP6XjiHQtVJAABxjY"]
[Tue Jul 21 08:13:43.959240 2026] [security2:error] [pid 402041:tid 402228] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UZ4iENNLP6XjiHQtVJAABxjY"]
[Tue Jul 21 08:13:43.997206 2026] [security2:error] [pid 402041:tid 402272] [client 20.151.10.161:13239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/memberfuns.php"] [unique_id "al9UZ4iENNLP6XjiHQtVJQAAAfI"]
[Tue Jul 21 08:13:44.099931 2026] [security2:error] [pid 402041:tid 402206] [client 154.208.47.43:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UaIiENNLP6XjiHQtVKQAAAbA"]
[Tue Jul 21 08:13:44.100057 2026] [security2:error] [pid 402041:tid 402206] [client 154.208.47.43:46950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UaIiENNLP6XjiHQtVKQAAAbA"]
[Tue Jul 21 08:13:44.205706 2026] [security2:error] [pid 402041:tid 402274] [client 103.151.46.103:57306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UaIiENNLP6XjiHQtVKgAAAfQ"]
[Tue Jul 21 08:13:44.205840 2026] [security2:error] [pid 402041:tid 402274] [client 103.151.46.103:57306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UaIiENNLP6XjiHQtVKgAAAfQ"]
[Tue Jul 21 08:13:44.611490 2026] [security2:error] [pid 402041:tid 402192] [client 20.151.10.161:13261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/ms.php"] [unique_id "al9UaIiENNLP6XjiHQtVPgAAAaI"]
[Tue Jul 21 08:13:44.750118 2026] [security2:error] [pid 402041:tid 402183] [client 91.148.244.131:59804] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/user_secrets.yml"] [unique_id "al9UaIiENNLP6XjiHQtVQAAAAZk"]
[Tue Jul 21 08:13:44.750305 2026] [security2:error] [pid 402041:tid 402295] [client 91.148.244.131:59790] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9UaIiENNLP6XjiHQtVQQAAAgk"]
[Tue Jul 21 08:13:44.809857 2026] [security2:error] [pid 402041:tid 402196] [client 20.226.60.151:49372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/fpwch.php"] [unique_id "al9UaIiENNLP6XjiHQtVRAAAAaY"]
[Tue Jul 21 08:13:44.902037 2026] [security2:error] [pid 402041:tid 402186] [client 65.21.113.253:42304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UaIiENNLP6XjiHQtVOAAAAZw"]
[Tue Jul 21 08:13:44.952076 2026] [security2:error] [pid 402041:tid 402216] [client 91.148.244.131:59788] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/dump.sql"] [unique_id "al9UaIiENNLP6XjiHQtVSAAAAbo"]
[Tue Jul 21 08:13:44.952372 2026] [security2:error] [pid 402041:tid 402296] [client 91.148.244.131:59760] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/server.key"] [unique_id "al9UaIiENNLP6XjiHQtVSQAAAgo"]
[Tue Jul 21 08:13:45.001008 2026] [security2:error] [pid 402041:tid 402200] [client 91.148.244.131:59808] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/docker-compose.yml"] [unique_id "al9UaYiENNLP6XjiHQtVSgAAAao"]
[Tue Jul 21 08:13:45.023913 2026] [security2:error] [pid 402041:tid 402268] [client 20.151.10.161:51072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9UaYiENNLP6XjiHQtVSwAAAe4"]
[Tue Jul 21 08:13:45.025963 2026] [security2:error] [pid 402041:tid 402211] [client 20.151.10.161:13130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/zz.php"] [unique_id "al9UaYiENNLP6XjiHQtVTAAAAbU"]
[Tue Jul 21 08:13:45.030477 2026] [security2:error] [pid 402041:tid 402223] [client 102.206.115.33:58960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UaYiENNLP6XjiHQtVTQAAAcE"]
[Tue Jul 21 08:13:45.031126 2026] [security2:error] [pid 402041:tid 402223] [client 102.206.115.33:58960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UaYiENNLP6XjiHQtVTQAAAcE"]
[Tue Jul 21 08:13:45.153843 2026] [security2:error] [pid 402041:tid 402299] [client 91.148.244.131:59776] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/backup.sql"] [unique_id "al9UaYiENNLP6XjiHQtVUwAAAg0"]
[Tue Jul 21 08:13:45.173338 2026] [security2:error] [pid 402041:tid 402257] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UaYiENNLP6XjiHQtVUQAB4yk"]
[Tue Jul 21 08:13:45.264682 2026] [security2:error] [pid 402041:tid 402180] [client 20.104.96.117:63441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/ss.php"] [unique_id "al9UaYiENNLP6XjiHQtVVgAAAZY"]
[Tue Jul 21 08:13:45.402301 2026] [security2:error] [pid 402041:tid 402212] [client 20.151.10.161:13163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/for.php"] [unique_id "al9UaYiENNLP6XjiHQtVWgAAAbY"]
[Tue Jul 21 08:13:45.542873 2026] [security2:error] [pid 402041:tid 402262] [client 20.151.10.161:51086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/x.php"] [unique_id "al9UaYiENNLP6XjiHQtVWwAAAeg"]
[Tue Jul 21 08:13:45.679411 2026] [security2:error] [pid 402041:tid 402254] [client 20.151.10.161:13216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/yup.php"] [unique_id "al9UaYiENNLP6XjiHQtVYAAAAeA"]
[Tue Jul 21 08:13:45.700550 2026] [security2:error] [pid 402041:tid 402288] [client 74.7.175.188:45964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "polianamoreiraconsultoria.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9UaYiENNLP6XjiHQtVYQACAlk"]
[Tue Jul 21 08:13:45.716208 2026] [security2:error] [pid 402041:tid 402247] [client 61.1.167.83:51817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UaYiENNLP6XjiHQtVYwAAAdk"]
[Tue Jul 21 08:13:45.716356 2026] [security2:error] [pid 402041:tid 402247] [client 61.1.167.83:51817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UaYiENNLP6XjiHQtVYwAAAdk"]
[Tue Jul 21 08:13:45.772279 2026] [security2:error] [pid 402041:tid 402294] [client 91.148.244.131:59786] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/.env.production"] [unique_id "al9UaYiENNLP6XjiHQtVZQAAAgg"]
[Tue Jul 21 08:13:45.909392 2026] [security2:error] [pid 402041:tid 402253] [client 20.104.96.117:54105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/nano.php"] [unique_id "al9UaYiENNLP6XjiHQtVawAAAd8"]
[Tue Jul 21 08:13:46.068184 2026] [security2:error] [pid 402041:tid 402184] [client 74.7.230.44:34862] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "choppcontrol.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9UaoiENNLP6XjiHQtVbwABmgA"]
[Tue Jul 21 08:13:46.090663 2026] [security2:error] [pid 402041:tid 402230] [client 91.148.244.131:59834] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/database.sql"] [unique_id "al9UaoiENNLP6XjiHQtVcQAAAcg"]
[Tue Jul 21 08:13:46.090798 2026] [security2:error] [pid 402041:tid 402276] [client 91.148.244.131:59850] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/secrets.json"] [unique_id "al9UaoiENNLP6XjiHQtVcgAAAfY"]
[Tue Jul 21 08:13:46.092092 2026] [security2:error] [pid 402041:tid 402205] [client 91.148.244.131:59856] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/database_backup.sql"] [unique_id "al9UaoiENNLP6XjiHQtVcwAAAa8"]
[Tue Jul 21 08:13:46.092470 2026] [security2:error] [pid 402041:tid 402251] [client 91.148.244.131:59814] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/.npmrc"] [unique_id "al9UaoiENNLP6XjiHQtVdAAAAd0"]
[Tue Jul 21 08:13:46.110423 2026] [security2:error] [pid 402041:tid 402186] [client 20.151.10.161:13247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/wpxml.php"] [unique_id "al9UaoiENNLP6XjiHQtVdQAAAZw"]
[Tue Jul 21 08:13:46.134797 2026] [security2:error] [pid 402041:tid 402236] [client 20.226.60.151:48770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/domvf.php"] [unique_id "al9UaoiENNLP6XjiHQtVdgAAAc4"]
[Tue Jul 21 08:13:46.292689 2026] [security2:error] [pid 402041:tid 402289] [client 91.148.244.131:59822] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9UaoiENNLP6XjiHQtVewAAAgM"]
[Tue Jul 21 08:13:46.318131 2026] [security2:error] [pid 402041:tid 402216] [client 74.7.230.44:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "leandrovilelapereira1745948660963.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9UaoiENNLP6XjiHQtVfAABugI"]
[Tue Jul 21 08:13:46.386250 2026] [security2:error] [pid 402041:tid 402283] [client 20.151.10.161:13176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/fffm.php"] [unique_id "al9UaoiENNLP6XjiHQtVfwAAAf0"]
[Tue Jul 21 08:13:46.398069 2026] [security2:error] [pid 402041:tid 402233] [client 137.97.59.154:57958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UaoiENNLP6XjiHQtVgQAAAcs"]
[Tue Jul 21 08:13:46.398186 2026] [security2:error] [pid 402041:tid 402233] [client 137.97.59.154:57958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UaoiENNLP6XjiHQtVgQAAAcs"]
[Tue Jul 21 08:13:46.755025 2026] [security2:error] [pid 402041:tid 402239] [client 20.151.10.161:13223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/gecko.php"] [unique_id "al9UaoiENNLP6XjiHQtViQAAAdE"]
[Tue Jul 21 08:13:46.880257 2026] [security2:error] [pid 402041:tid 402202] [client 81.171.72.135:43122] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/user_secrets.yml"] [unique_id "al9UaoiENNLP6XjiHQtVigAAAaw"]
[Tue Jul 21 08:13:46.882854 2026] [security2:error] [pid 402041:tid 402278] [client 81.171.72.135:43136] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/docker-compose.yml"] [unique_id "al9UaoiENNLP6XjiHQtViwAAAfg"]
[Tue Jul 21 08:13:46.884537 2026] [security2:error] [pid 402041:tid 402206] [client 81.171.72.135:43154] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/phpinfo.php"] [unique_id "al9UaoiENNLP6XjiHQtVjgAAAbA"]
[Tue Jul 21 08:13:46.884660 2026] [security2:error] [pid 402041:tid 402281] [client 81.171.72.135:43138] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/etc/ssl/private/server.key"] [unique_id "al9UaoiENNLP6XjiHQtVjQAAAfs"]
[Tue Jul 21 08:13:46.893950 2026] [security2:error] [pid 402041:tid 402195] [client 20.151.10.161:51028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/cfile.php"] [unique_id "al9UaoiENNLP6XjiHQtVjwAAAaU"]
[Tue Jul 21 08:13:46.902600 2026] [security2:error] [pid 402041:tid 402204] [client 20.151.10.161:51109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/j260624_13.php"] [unique_id "al9UaoiENNLP6XjiHQtVkAAAAa4"]
[Tue Jul 21 08:13:46.914582 2026] [security2:error] [pid 402041:tid 402237] [client 91.148.244.131:59888] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/api/.env"] [unique_id "al9UaoiENNLP6XjiHQtVkQAAAc8"]
[Tue Jul 21 08:13:46.916602 2026] [security2:error] [pid 402041:tid 402274] [client 91.148.244.131:59896] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/.env"] [unique_id "al9UaoiENNLP6XjiHQtVkgAAAfQ"]
[Tue Jul 21 08:13:46.916994 2026] [security2:error] [pid 402041:tid 402177] [client 91.148.244.131:59894] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/.git/HEAD"] [unique_id "al9UaoiENNLP6XjiHQtVkwAAAZM"]
[Tue Jul 21 08:13:46.918805 2026] [security2:error] [pid 402041:tid 402292] [client 91.148.244.131:59868] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/phpinfo.php"] [unique_id "al9UaoiENNLP6XjiHQtVlAAAAgY"]
[Tue Jul 21 08:13:47.039620 2026] [security2:error] [pid 402041:tid 402174] [client 187.125.243.197:60459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ua4iENNLP6XjiHQtVmgAAAZA"]
[Tue Jul 21 08:13:47.039734 2026] [security2:error] [pid 402041:tid 402174] [client 187.125.243.197:60459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Ua4iENNLP6XjiHQtVmgAAAZA"]
[Tue Jul 21 08:13:47.050193 2026] [security2:error] [pid 402041:tid 402291] [client 20.151.10.161:13229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/a1.php"] [unique_id "al9Ua4iENNLP6XjiHQtVmwAAAgU"]
[Tue Jul 21 08:13:47.117256 2026] [security2:error] [pid 402041:tid 402218] [client 91.148.244.131:59924] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9Ua4iENNLP6XjiHQtVnAAAAbw"]
[Tue Jul 21 08:13:47.118919 2026] [security2:error] [pid 402041:tid 402242] [client 91.148.244.131:59870] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9Ua4iENNLP6XjiHQtVnQAAAdQ"]
[Tue Jul 21 08:13:47.362449 2026] [security2:error] [pid 402041:tid 402252] [client 20.151.10.161:13240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/k2.php"] [unique_id "al9Ua4iENNLP6XjiHQtVowAAAd4"]
[Tue Jul 21 08:13:47.414245 2026] [security2:error] [pid 402041:tid 402101] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ua4iENNLP6XjiHQtVpQABxDk"]
[Tue Jul 21 08:13:47.414380 2026] [security2:error] [pid 402041:tid 402226] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ua4iENNLP6XjiHQtVpQABxDk"]
[Tue Jul 21 08:13:47.455554 2026] [security2:error] [pid 402041:tid 402189] [client 20.104.96.117:62475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/min.php"] [unique_id "al9Ua4iENNLP6XjiHQtVqAAAAZ8"]
[Tue Jul 21 08:13:47.583321 2026] [security2:error] [pid 402041:tid 402175] [client 20.151.10.161:51079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/d62.php"] [unique_id "al9Ua4iENNLP6XjiHQtVqgAAAZE"]
[Tue Jul 21 08:13:47.741407 2026] [security2:error] [pid 402041:tid 402264] [client 20.151.10.161:13213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/82.php"] [unique_id "al9Ua4iENNLP6XjiHQtVrwAAAeo"]
[Tue Jul 21 08:13:47.849371 2026] [security2:error] [pid 402041:tid 402275] [client 81.171.72.135:43182] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/.ssh/id_ed25519"] [unique_id "al9Ua4iENNLP6XjiHQtVsgAAAfU"]
[Tue Jul 21 08:13:47.852257 2026] [security2:error] [pid 402041:tid 402266] [client 81.171.72.135:43198] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/.ssh/id_ecdsa"] [unique_id "al9Ua4iENNLP6XjiHQtVtAAAAew"]
[Tue Jul 21 08:13:47.852320 2026] [security2:error] [pid 402041:tid 402284] [client 81.171.72.135:43218] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/server.key"] [unique_id "al9Ua4iENNLP6XjiHQtVtQAAAf4"]
[Tue Jul 21 08:13:47.852350 2026] [security2:error] [pid 402041:tid 402180] [client 81.171.72.135:43164] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/config/production.json"] [unique_id "al9Ua4iENNLP6XjiHQtVswAAAZY"]
[Tue Jul 21 08:13:47.942199 2026] [security2:error] [pid 402041:tid 402178] [client 20.151.10.161:51128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/ups.php"] [unique_id "al9Ua4iENNLP6XjiHQtVtwAAAZQ"]
[Tue Jul 21 08:13:48.035742 2026] [security2:error] [pid 402041:tid 402195] [client 20.151.10.161:13125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/config.json.php"] [unique_id "al9UbIiENNLP6XjiHQtVuwAAAaU"]
[Tue Jul 21 08:13:48.053063 2026] [security2:error] [pid 402041:tid 402241] [client 81.171.72.135:43172] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/.vscode/sftp.json"] [unique_id "al9UbIiENNLP6XjiHQtVvAAAAdM"]
[Tue Jul 21 08:13:48.056136 2026] [security2:error] [pid 402041:tid 402188] [client 81.171.72.135:43204] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/.npmrc"] [unique_id "al9UbIiENNLP6XjiHQtVvQAAAZ4"]
[Tue Jul 21 08:13:48.056239 2026] [security2:error] [pid 402041:tid 402297] [client 81.171.72.135:43222] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/secrets.json"] [unique_id "al9UbIiENNLP6XjiHQtVvgAAAgs"]
[Tue Jul 21 08:13:48.317759 2026] [security2:error] [pid 402041:tid 402277] [client 120.56.162.40:59677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UbIiENNLP6XjiHQtVxQAAAfc"]
[Tue Jul 21 08:13:48.318140 2026] [security2:error] [pid 402041:tid 402277] [client 120.56.162.40:59677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UbIiENNLP6XjiHQtVxQAAAfc"]
[Tue Jul 21 08:13:48.379235 2026] [security2:error] [pid 402041:tid 402234] [client 94.23.188.223:52554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "unigein.com.br"] [uri "/robots.txt"] [unique_id "al9UbIiENNLP6XjiHQtVxgAAAcw"]
[Tue Jul 21 08:13:48.379345 2026] [security2:error] [pid 402041:tid 402234] [client 94.23.188.223:52554] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "unigein.com.br"] [uri "/robots.txt"] [unique_id "al9UbIiENNLP6XjiHQtVxgAAAcw"]
[Tue Jul 21 08:13:48.394330 2026] [security2:error] [pid 402041:tid 402260] [client 20.151.10.161:36553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/k.php"] [unique_id "al9UbIiENNLP6XjiHQtVxwAAAeY"]
[Tue Jul 21 08:13:48.421618 2026] [security2:error] [pid 402041:tid 402185] [client 20.104.96.117:62575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9UbIiENNLP6XjiHQtVyAAAAZs"]
[Tue Jul 21 08:13:48.450726 2026] [security2:error] [pid 402041:tid 402230] [client 20.151.10.161:13158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "consultecobertura.com.br.pedido-online.net"] [uri "/fpwch.php"] [unique_id "al9UbIiENNLP6XjiHQtVygAAAcg"]
[Tue Jul 21 08:13:48.608917 2026] [security2:error] [pid 402041:tid 402122] [remote 154.61.75.100:37684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/wp-login.php"] [unique_id "al9UbIiENNLP6XjiHQtV0QACDU4"]
[Tue Jul 21 08:13:48.674371 2026] [security2:error] [pid 402041:tid 402287] [client 150.129.202.39:64817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UbIiENNLP6XjiHQtV1wAAAgE"]
[Tue Jul 21 08:13:48.674499 2026] [security2:error] [pid 402041:tid 402287] [client 150.129.202.39:64817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UbIiENNLP6XjiHQtV1wAAAgE"]
[Tue Jul 21 08:13:48.823700 2026] [security2:error] [pid 402041:tid 402187] [client 81.171.72.135:43232] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/.bash_history"] [unique_id "al9UbIiENNLP6XjiHQtV3AAAAZ0"]
[Tue Jul 21 08:13:48.826972 2026] [security2:error] [pid 402041:tid 402265] [client 81.171.72.135:43270] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9UbIiENNLP6XjiHQtV3gAAAes"]
[Tue Jul 21 08:13:48.827031 2026] [security2:error] [pid 402041:tid 402300] [client 81.171.72.135:43244] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com"] [uri "/.ssh/id_rsa"] [unique_id "al9UbIiENNLP6XjiHQtV3QAAAg4"]
[Tue Jul 21 08:13:48.961322 2026] [security2:error] [pid 402041:tid 402186] [client 65.21.113.253:42304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UbIiENNLP6XjiHQtVzwAAAZw"]
[Tue Jul 21 08:13:49.028889 2026] [log_config:warn] [pid 400813:tid 401061] (32)Broken pipe: [client 38.240.49.93:49209] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:13:49.028934 2026] [log_config:warn] [pid 400813:tid 401061] (32)Broken pipe: [client 38.240.49.93:49209] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:13:49.120359 2026] [security2:error] [pid 402041:tid 402284] [client 20.151.10.161:51094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/k2.php"] [unique_id "al9UbYiENNLP6XjiHQtV4wAAAf4"]
[Tue Jul 21 08:13:49.361280 2026] [security2:error] [pid 402041:tid 402079] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UbYiENNLP6XjiHQtV7gABrCM"]
[Tue Jul 21 08:13:49.361439 2026] [security2:error] [pid 402041:tid 402202] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UbYiENNLP6XjiHQtV7gABrCM"]
[Tue Jul 21 08:13:49.538905 2026] [security2:error] [pid 402041:tid 402192] [client 20.151.10.161:51027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/class-wp.php"] [unique_id "al9UbYiENNLP6XjiHQtV9AAAAaI"]
[Tue Jul 21 08:13:49.573890 2026] [security2:error] [pid 402041:tid 402127] [remote 5.252.52.249:39470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mecdutos.com.br"] [uri "/wp-login.php"] [unique_id "al9UbYiENNLP6XjiHQtV-AABlVM"]
[Tue Jul 21 08:13:49.752281 2026] [security2:error] [pid 402041:tid 402277] [client 20.151.10.161:51106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/k3.php"] [unique_id "al9UbYiENNLP6XjiHQtV-QAAAfc"]
[Tue Jul 21 08:13:49.971868 2026] [security2:error] [pid 402041:tid 402200] [client 20.104.96.117:62490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9UbYiENNLP6XjiHQtWDQAAAao"]
[Tue Jul 21 08:13:50.016665 2026] [security2:error] [pid 402041:tid 402282] [client 142.44.225.247:44104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "unigein.com.br"] [uri "/"] [unique_id "al9UboiENNLP6XjiHQtWDgAAAfw"]
[Tue Jul 21 08:13:50.016751 2026] [security2:error] [pid 402041:tid 402282] [client 142.44.225.247:44104] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "unigein.com.br"] [uri "/"] [unique_id "al9UboiENNLP6XjiHQtWDgAAAfw"]
[Tue Jul 21 08:13:50.170134 2026] [security2:error] [pid 402041:tid 402210] [client 20.104.96.117:54711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/moon.php"] [unique_id "al9UboiENNLP6XjiHQtWFQAAAbQ"]
[Tue Jul 21 08:13:50.346250 2026] [security2:error] [pid 402041:tid 402247] [client 185.198.240.32:34963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mbarcondicionados.com.br"] [uri "/wp-login.php"] [unique_id "al9UbYiENNLP6XjiHQtV7QAAAdk"]
[Tue Jul 21 08:13:50.493146 2026] [security2:error] [pid 402041:tid 402221] [client 117.210.135.0:49245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UboiENNLP6XjiHQtWGQAAAb8"]
[Tue Jul 21 08:13:50.493718 2026] [security2:error] [pid 402041:tid 402221] [client 117.210.135.0:49245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UboiENNLP6XjiHQtWGQAAAb8"]
[Tue Jul 21 08:13:50.514916 2026] [security2:error] [pid 402041:tid 402288] [client 62.102.148.158:52602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9UboiENNLP6XjiHQtWGgAAAgI"]
[Tue Jul 21 08:13:50.514981 2026] [security2:error] [pid 402041:tid 402288] [client 62.102.148.158:52602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9UboiENNLP6XjiHQtWGgAAAgI"]
[Tue Jul 21 08:13:50.605546 2026] [security2:error] [pid 402041:tid 402173] [client 20.151.10.161:51053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/admin.php"] [unique_id "al9UboiENNLP6XjiHQtWLQAAAY8"]
[Tue Jul 21 08:13:50.830624 2026] [security2:error] [pid 402041:tid 402294] [client 20.151.10.161:36548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/k4.php"] [unique_id "al9UboiENNLP6XjiHQtWMgAAAgg"]
[Tue Jul 21 08:13:51.174060 2026] [security2:error] [pid 402041:tid 402220] [client 65.21.113.253:42304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UboiENNLP6XjiHQtWMQAAAb4"]
[Tue Jul 21 08:13:51.517356 2026] [security2:error] [pid 402041:tid 402150] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ub4iENNLP6XjiHQtWTAAB1Go"]
[Tue Jul 21 08:13:51.517537 2026] [security2:error] [pid 402041:tid 402242] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ub4iENNLP6XjiHQtWTAAB1Go"]
[Tue Jul 21 08:13:51.882903 2026] [security2:error] [pid 402041:tid 402212] [client 20.151.10.161:51070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/aa2.php"] [unique_id "al9Ub4iENNLP6XjiHQtWVwAAAbY"]
[Tue Jul 21 08:13:52.079927 2026] [security2:error] [pid 402041:tid 402243] [client 103.78.200.11:52461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UcIiENNLP6XjiHQtWWwAAAdU"]
[Tue Jul 21 08:13:52.080119 2026] [security2:error] [pid 402041:tid 402243] [client 103.78.200.11:52461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UcIiENNLP6XjiHQtWWwAAAdU"]
[Tue Jul 21 08:13:52.106620 2026] [security2:error] [pid 402041:tid 402173] [client 78.47.173.76:54378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9UcIiENNLP6XjiHQtWXAAAAY8"], referer: https://artetoner.com.br
[Tue Jul 21 08:13:52.172487 2026] [security2:error] [pid 402041:tid 402227] [client 20.104.96.117:62576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9UcIiENNLP6XjiHQtWXgAAAcU"]
[Tue Jul 21 08:13:52.212554 2026] [security2:error] [pid 402041:tid 402176] [client 20.226.60.151:48858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wp.php"] [unique_id "al9UcIiENNLP6XjiHQtWYAAAAZI"]
[Tue Jul 21 08:13:52.315016 2026] [security2:error] [pid 402041:tid 402280] [client 162.219.176.3:53636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9UcIiENNLP6XjiHQtWZAAAAfo"]
[Tue Jul 21 08:13:52.315093 2026] [security2:error] [pid 402041:tid 402280] [client 162.219.176.3:53636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9UcIiENNLP6XjiHQtWZAAAAfo"]
[Tue Jul 21 08:13:52.903105 2026] [security2:error] [pid 402041:tid 402278] [client 38.100.221.102:18133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UcIiENNLP6XjiHQtWdQAAAfg"]
[Tue Jul 21 08:13:52.903231 2026] [security2:error] [pid 402041:tid 402278] [client 38.100.221.102:18133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UcIiENNLP6XjiHQtWdQAAAfg"]
[Tue Jul 21 08:13:52.954238 2026] [security2:error] [pid 402041:tid 402296] [client 91.148.244.131:59968] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/wp-config.php"] [unique_id "al9UcIiENNLP6XjiHQtWeQAAAgo"]
[Tue Jul 21 08:13:52.954585 2026] [security2:error] [pid 402041:tid 402200] [client 91.148.244.131:59958] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9UcIiENNLP6XjiHQtWegAAAao"]
[Tue Jul 21 08:13:52.954686 2026] [security2:error] [pid 402041:tid 402297] [client 91.148.244.131:59938] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/.bash_history"] [unique_id "al9UcIiENNLP6XjiHQtWewAAAgs"]
[Tue Jul 21 08:13:52.955187 2026] [security2:error] [pid 402041:tid 402225] [client 91.148.244.131:59974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "brightcursos.com.bastarecomecar.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9UcIiENNLP6XjiHQtWfAAAAcM"]
[Tue Jul 21 08:13:52.983086 2026] [security2:error] [pid 402041:tid 402138] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UcIiENNLP6XjiHQtWfQACBF4"]
[Tue Jul 21 08:13:52.983236 2026] [security2:error] [pid 402041:tid 402290] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UcIiENNLP6XjiHQtWfQACBF4"]
[Tue Jul 21 08:13:52.991803 2026] [security2:error] [pid 402041:tid 402210] [client 20.151.10.161:55841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ccou.php"] [unique_id "al9UcIiENNLP6XjiHQtWfgAAAbQ"]
[Tue Jul 21 08:13:53.002136 2026] [security2:error] [pid 402041:tid 402185] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UcIiENNLP6XjiHQtWdAABmxs"]
[Tue Jul 21 08:13:53.155376 2026] [security2:error] [pid 402041:tid 402248] [client 20.104.96.117:54109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-info.php"] [unique_id "al9UcYiENNLP6XjiHQtWhAAAAdo"]
[Tue Jul 21 08:13:53.205870 2026] [security2:error] [pid 402041:tid 402265] [client 45.227.253.15:54154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.253.227.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clinic.bavos.com.br"] [uri "/index.php/jk"] [unique_id "al9UcYiENNLP6XjiHQtWhQAAAes"]
[Tue Jul 21 08:13:53.302826 2026] [security2:error] [pid 402041:tid 402260] [client 87.116.180.198:27355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UcYiENNLP6XjiHQtWiQAAAeY"]
[Tue Jul 21 08:13:53.302948 2026] [security2:error] [pid 402041:tid 402260] [client 87.116.180.198:27355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UcYiENNLP6XjiHQtWiQAAAeY"]
[Tue Jul 21 08:13:54.003936 2026] [security2:error] [pid 402041:tid 402262] [client 103.151.46.103:57780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UcoiENNLP6XjiHQtWlgAAAeg"]
[Tue Jul 21 08:13:54.004095 2026] [security2:error] [pid 402041:tid 402262] [client 103.151.46.103:57780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UcoiENNLP6XjiHQtWlgAAAeg"]
[Tue Jul 21 08:13:54.344231 2026] [security2:error] [pid 402041:tid 402175] [client 20.226.60.151:48875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/class.php"] [unique_id "al9UcoiENNLP6XjiHQtWngAAAZE"]
[Tue Jul 21 08:13:54.541318 2026] [security2:error] [pid 402041:tid 402182] [client 20.151.10.161:51126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/k5.php"] [unique_id "al9UcoiENNLP6XjiHQtWowAAAZg"]
[Tue Jul 21 08:13:54.730069 2026] [security2:error] [pid 402041:tid 402083] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UcoiENNLP6XjiHQtWqAABvic"]
[Tue Jul 21 08:13:54.730264 2026] [security2:error] [pid 402041:tid 402220] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UcoiENNLP6XjiHQtWqAABvic"]
[Tue Jul 21 08:13:54.901122 2026] [security2:error] [pid 402041:tid 402250] [client 154.208.47.43:47419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UcoiENNLP6XjiHQtWqQAAAdw"]
[Tue Jul 21 08:13:54.901250 2026] [security2:error] [pid 402041:tid 402250] [client 154.208.47.43:47419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UcoiENNLP6XjiHQtWqQAAAdw"]
[Tue Jul 21 08:13:55.584668 2026] [security2:error] [pid 402041:tid 402203] [client 102.206.115.33:63025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Uc4iENNLP6XjiHQtWvQAAAa0"]
[Tue Jul 21 08:13:55.584834 2026] [security2:error] [pid 402041:tid 402203] [client 102.206.115.33:63025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Uc4iENNLP6XjiHQtWvQAAAa0"]
[Tue Jul 21 08:13:55.630229 2026] [security2:error] [pid 402041:tid 402226] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Uc4iENNLP6XjiHQtWvAABxDU"]
[Tue Jul 21 08:13:55.968315 2026] [security2:error] [pid 402041:tid 402081] [remote 173.252.95.22:54446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Uc4iENNLP6XjiHQtWxQACACU"]
[Tue Jul 21 08:13:56.068952 2026] [security2:error] [pid 402041:tid 402263] [client 65.21.113.253:42304] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Uc4iENNLP6XjiHQtWwQAAAek"]
[Tue Jul 21 08:13:56.153416 2026] [autoindex:error] [pid 402041:tid 402258] [client 205.210.31.209:61664] AH01276: Cannot serve directory /home2/inlaud99/kenyetuquinha.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:13:56.184123 2026] [security2:error] [pid 402041:tid 402213] [client 20.104.96.117:58181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/2000.php"] [unique_id "al9UdIiENNLP6XjiHQtW1AAAAbc"]
[Tue Jul 21 08:13:56.486022 2026] [security2:error] [pid 402041:tid 402228] [client 142.44.220.77:46316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "criatividadepedagogica.com"] [uri "/robots.txt"] [unique_id "al9UdIiENNLP6XjiHQtW1gAAAcY"]
[Tue Jul 21 08:13:56.486147 2026] [security2:error] [pid 402041:tid 402228] [client 142.44.220.77:46316] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "criatividadepedagogica.com"] [uri "/robots.txt"] [unique_id "al9UdIiENNLP6XjiHQtW1gAAAcY"]
[Tue Jul 21 08:13:56.857118 2026] [autoindex:error] [pid 402041:tid 402214] [client 205.210.31.54:61432] AH01276: Cannot serve directory /home2/prove728/provendasfrios.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:13:56.865042 2026] [security2:error] [pid 402041:tid 402175] [client 14.97.58.74:7940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UdIiENNLP6XjiHQtW6AAAAZE"]
[Tue Jul 21 08:13:56.865178 2026] [security2:error] [pid 402041:tid 402175] [client 14.97.58.74:7940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UdIiENNLP6XjiHQtW6AAAAZE"]
[Tue Jul 21 08:13:56.936545 2026] [security2:error] [pid 402041:tid 402187] [client 20.226.60.151:48862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/echkm.php"] [unique_id "al9UdIiENNLP6XjiHQtW6wAAAZ0"]
[Tue Jul 21 08:13:57.361784 2026] [security2:error] [pid 402041:tid 402291] [client 134.122.94.138:60080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "accjbc.org"] [uri "/"] [unique_id "al9UdYiENNLP6XjiHQtW-AAAAgU"]
[Tue Jul 21 08:13:57.449026 2026] [security2:error] [pid 402041:tid 402120] [remote 119.195.102.159:44382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9UdYiENNLP6XjiHQtW-gAB4Ew"]
[Tue Jul 21 08:13:57.501571 2026] [security2:error] [pid 402041:tid 402298] [client 187.125.243.197:60922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UdYiENNLP6XjiHQtW-wAAAgw"]
[Tue Jul 21 08:13:57.501714 2026] [security2:error] [pid 402041:tid 402298] [client 187.125.243.197:60922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UdYiENNLP6XjiHQtW-wAAAgw"]
[Tue Jul 21 08:13:57.906331 2026] [security2:error] [pid 402041:tid 402154] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UdYiENNLP6XjiHQtXAwABwG4"]
[Tue Jul 21 08:13:57.906385 2026] [security2:error] [pid 402041:tid 402183] [client 142.44.228.22:33878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "criatividadepedagogica.com"] [uri "/"] [unique_id "al9UdYiENNLP6XjiHQtXBAAAAZk"]
[Tue Jul 21 08:13:57.906479 2026] [security2:error] [pid 402041:tid 402183] [client 142.44.228.22:33878] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "criatividadepedagogica.com"] [uri "/"] [unique_id "al9UdYiENNLP6XjiHQtXBAAAAZk"]
[Tue Jul 21 08:13:57.906532 2026] [security2:error] [pid 402041:tid 402222] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UdYiENNLP6XjiHQtXAwABwG4"]
[Tue Jul 21 08:13:57.950841 2026] [security2:error] [pid 402041:tid 402245] [client 20.104.96.117:62547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9UdYiENNLP6XjiHQtXBQAAAdc"]
[Tue Jul 21 08:13:58.222642 2026] [security2:error] [pid 402041:tid 402249] [client 115.134.11.136:49517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UdIiENNLP6XjiHQtW7AAAAds"]
[Tue Jul 21 08:13:58.891080 2026] [security2:error] [pid 402041:tid 402232] [client 82.102.18.190:33662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9UdoiENNLP6XjiHQtXIgAAAco"]
[Tue Jul 21 08:13:58.974133 2026] [security2:error] [pid 402041:tid 402257] [client 120.56.162.40:60175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UdoiENNLP6XjiHQtXIwAAAeM"]
[Tue Jul 21 08:13:58.974284 2026] [security2:error] [pid 402041:tid 402257] [client 120.56.162.40:60175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UdoiENNLP6XjiHQtXIwAAAeM"]
[Tue Jul 21 08:13:59.226274 2026] [security2:error] [pid 402041:tid 402215] [client 150.129.202.39:65231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ud4iENNLP6XjiHQtXJwAAAbk"]
[Tue Jul 21 08:13:59.226418 2026] [security2:error] [pid 402041:tid 402215] [client 150.129.202.39:65231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ud4iENNLP6XjiHQtXJwAAAbk"]
[Tue Jul 21 08:13:59.287081 2026] [security2:error] [pid 402041:tid 402246] [client 20.151.10.161:36566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/w.php"] [unique_id "al9Ud4iENNLP6XjiHQtXLQAAAdg"]
[Tue Jul 21 08:13:59.288917 2026] [security2:error] [pid 402041:tid 402211] [client 82.102.18.190:33678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ftp.moveisrafael.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ud4iENNLP6XjiHQtXLAAAAbU"]
[Tue Jul 21 08:13:59.320550 2026] [security2:error] [pid 402041:tid 402159] [remote 20.153.140.50:38022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Ud4iENNLP6XjiHQtXMgAB_XM"]
[Tue Jul 21 08:13:59.759697 2026] [security2:error] [pid 402041:tid 402234] [client 23.180.120.147:57298] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "www.gonzagahospitalar.com.br"] [uri "/"] [unique_id "al9Ud4iENNLP6XjiHQtXPQAAAcw"]
[Tue Jul 21 08:13:59.885697 2026] [security2:error] [pid 402041:tid 402218] [client 82.102.18.190:33692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Ud4iENNLP6XjiHQtXRQAAAbw"]
[Tue Jul 21 08:14:00.023671 2026] [security2:error] [pid 402041:tid 402088] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UeIiENNLP6XjiHQtXSgABryw"]
[Tue Jul 21 08:14:00.023791 2026] [security2:error] [pid 402041:tid 402205] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UeIiENNLP6XjiHQtXSgABryw"]
[Tue Jul 21 08:14:00.325769 2026] [security2:error] [pid 402041:tid 402188] [client 82.102.18.190:26685] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9UeIiENNLP6XjiHQtXUAAAAZ4"]
[Tue Jul 21 08:14:00.440333 2026] [security2:error] [pid 402041:tid 402261] [client 86.106.84.166:38058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9UeIiENNLP6XjiHQtXVAAAAec"]
[Tue Jul 21 08:14:00.440424 2026] [security2:error] [pid 402041:tid 402261] [client 86.106.84.166:38058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9UeIiENNLP6XjiHQtXVAAAAec"]
[Tue Jul 21 08:14:00.457259 2026] [security2:error] [pid 402041:tid 402269] [client 20.104.96.117:54706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/122.php"] [unique_id "al9UeIiENNLP6XjiHQtXVgAAAe8"]
[Tue Jul 21 08:14:00.727955 2026] [security2:error] [pid 402041:tid 402276] [client 82.102.18.190:33708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9UeIiENNLP6XjiHQtXWAAAAfY"]
[Tue Jul 21 08:14:00.846523 2026] [security2:error] [pid 402041:tid 402206] [client 20.151.10.161:51097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/fpwch.php"] [unique_id "al9UeIiENNLP6XjiHQtXXAAAAbA"]
[Tue Jul 21 08:14:01.005600 2026] [security2:error] [pid 402041:tid 402252] [client 23.180.120.147:57328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.gonzagahospitalar.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9UeYiENNLP6XjiHQtXYgAAAd4"]
[Tue Jul 21 08:14:01.019305 2026] [security2:error] [pid 402041:tid 402231] [client 117.210.135.0:49957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UeYiENNLP6XjiHQtXYwAAAck"]
[Tue Jul 21 08:14:01.019928 2026] [security2:error] [pid 402041:tid 402231] [client 117.210.135.0:49957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UeYiENNLP6XjiHQtXYwAAAck"]
[Tue Jul 21 08:14:01.130529 2026] [security2:error] [pid 402041:tid 402260] [client 82.102.18.190:33720] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9UeYiENNLP6XjiHQtXaQAAAeY"]
[Tue Jul 21 08:14:01.155796 2026] [security2:error] [pid 402041:tid 402204] [client 20.226.60.151:48887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/lib.php"] [unique_id "al9UeYiENNLP6XjiHQtXagAAAa4"]
[Tue Jul 21 08:14:01.478224 2026] [security2:error] [pid 402041:tid 402278] [client 20.104.96.117:63437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/albin.php"] [unique_id "al9UeYiENNLP6XjiHQtXcwAAAfg"]
[Tue Jul 21 08:14:01.522205 2026] [security2:error] [pid 402041:tid 402213] [client 82.102.18.190:33726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9UeYiENNLP6XjiHQtXdAAAAbc"]
[Tue Jul 21 08:14:01.920356 2026] [security2:error] [pid 402041:tid 402290] [client 82.102.18.190:2970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9UeYiENNLP6XjiHQtXfQAAAgQ"]
[Tue Jul 21 08:14:02.297840 2026] [security2:error] [pid 402041:tid 402142] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UeoiENNLP6XjiHQtXgwABuGI"]
[Tue Jul 21 08:14:02.298046 2026] [security2:error] [pid 402041:tid 402214] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UeoiENNLP6XjiHQtXgwABuGI"]
[Tue Jul 21 08:14:02.315881 2026] [security2:error] [pid 402041:tid 402277] [client 82.102.18.190:56552] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9UeoiENNLP6XjiHQtXhAAAAfc"]
[Tue Jul 21 08:14:02.484997 2026] [security2:error] [pid 402041:tid 402113] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UeoiENNLP6XjiHQtXigABtEU"]
[Tue Jul 21 08:14:02.485197 2026] [security2:error] [pid 402041:tid 402210] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UeoiENNLP6XjiHQtXigABtEU"]
[Tue Jul 21 08:14:02.505347 2026] [access_compat:error] [pid 402041:tid 402268] [client 162.241.63.68:37976] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:14:02.750098 2026] [security2:error] [pid 402041:tid 402238] [client 82.102.18.190:56560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9UeoiENNLP6XjiHQtXkQAAAdA"]
[Tue Jul 21 08:14:02.823968 2026] [security2:error] [pid 402041:tid 402221] [client 103.78.200.11:52941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UeoiENNLP6XjiHQtXlwAAAb8"]
[Tue Jul 21 08:14:02.824074 2026] [security2:error] [pid 402041:tid 402221] [client 103.78.200.11:52941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UeoiENNLP6XjiHQtXlwAAAb8"]
[Tue Jul 21 08:14:02.915759 2026] [security2:error] [pid 402041:tid 402215] [client 20.104.96.117:62539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/cilus.php"] [unique_id "al9UeoiENNLP6XjiHQtXmgAAAbk"]
[Tue Jul 21 08:14:03.057116 2026] [security2:error] [pid 402041:tid 402245] [client 20.151.10.161:51132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/w2025.php"] [unique_id "al9Ue4iENNLP6XjiHQtXpAAAAdc"]
[Tue Jul 21 08:14:03.151291 2026] [security2:error] [pid 402041:tid 402183] [client 82.102.18.190:23507] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Ue4iENNLP6XjiHQtXpQAAAZk"]
[Tue Jul 21 08:14:03.543998 2026] [security2:error] [pid 402041:tid 402287] [client 82.102.18.190:49495] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Ue4iENNLP6XjiHQtXrAAAAgE"]
[Tue Jul 21 08:14:03.586806 2026] [security2:error] [pid 402041:tid 402177] [client 38.100.221.102:18561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ue4iENNLP6XjiHQtXsAAAAZM"]
[Tue Jul 21 08:14:03.586920 2026] [security2:error] [pid 402041:tid 402177] [client 38.100.221.102:18561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ue4iENNLP6XjiHQtXsAAAAZM"]
[Tue Jul 21 08:14:03.922853 2026] [security2:error] [pid 402041:tid 402299] [client 87.116.180.198:13977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ue4iENNLP6XjiHQtXswAAAg0"]
[Tue Jul 21 08:14:03.924758 2026] [security2:error] [pid 402041:tid 402299] [client 87.116.180.198:13977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ue4iENNLP6XjiHQtXswAAAg0"]
[Tue Jul 21 08:14:03.934105 2026] [security2:error] [pid 402041:tid 402185] [client 82.102.18.190:37211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Ue4iENNLP6XjiHQtXtAAAAZs"]
[Tue Jul 21 08:14:03.964732 2026] [security2:error] [pid 402041:tid 402049] [remote 124.55.178.99:39912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powertronicseguranca.com"] [uri "/wp-login.php"] [unique_id "al9Ue4iENNLP6XjiHQtXtQABlQU"]
[Tue Jul 21 08:14:03.971767 2026] [security2:error] [pid 402041:tid 402175] [client 20.220.225.223:30893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/ez.php"] [unique_id "al9Ue4iENNLP6XjiHQtXtgAAAZE"]
[Tue Jul 21 08:14:04.071976 2026] [security2:error] [pid 402041:tid 402115] [remote 45.90.123.233:40638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9UfIiENNLP6XjiHQtXvgAB20c"]
[Tue Jul 21 08:14:04.100470 2026] [security2:error] [pid 402041:tid 402225] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ue4iENNLP6XjiHQtXtwABw3Q"]
[Tue Jul 21 08:14:04.171426 2026] [security2:error] [pid 402041:tid 402289] [client 20.104.96.117:58206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/mds.php"] [unique_id "al9UfIiENNLP6XjiHQtXwAAAAgM"]
[Tue Jul 21 08:14:04.334970 2026] [security2:error] [pid 402041:tid 402257] [client 82.102.18.190:56588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9UfIiENNLP6XjiHQtXwQAAAeM"]
[Tue Jul 21 08:14:04.523791 2026] [security2:error] [pid 402041:tid 402182] [client 103.151.46.103:58246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UfIiENNLP6XjiHQtXxgAAAZg"]
[Tue Jul 21 08:14:04.523936 2026] [security2:error] [pid 402041:tid 402182] [client 103.151.46.103:58246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UfIiENNLP6XjiHQtXxgAAAZg"]
[Tue Jul 21 08:14:04.725142 2026] [security2:error] [pid 402041:tid 402202] [client 82.102.18.190:10434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9UfIiENNLP6XjiHQtX0QAAAaw"]
[Tue Jul 21 08:14:04.867216 2026] [security2:error] [pid 402041:tid 402288] [client 154.208.47.43:47888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UfIiENNLP6XjiHQtX0gAAAgI"]
[Tue Jul 21 08:14:04.868116 2026] [security2:error] [pid 402041:tid 402288] [client 154.208.47.43:47888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UfIiENNLP6XjiHQtX0gAAAgI"]
[Tue Jul 21 08:14:05.070704 2026] [security2:error] [pid 402041:tid 402241] [client 20.220.225.223:30718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/fz.php"] [unique_id "al9UfYiENNLP6XjiHQtX1AAAAdM"]
[Tue Jul 21 08:14:05.120807 2026] [security2:error] [pid 402041:tid 402234] [client 82.102.18.190:48494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9UfYiENNLP6XjiHQtX2wAAAcw"]
[Tue Jul 21 08:14:05.515754 2026] [security2:error] [pid 402041:tid 402082] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UfYiENNLP6XjiHQtX4gACBCY"]
[Tue Jul 21 08:14:05.516254 2026] [security2:error] [pid 402041:tid 402290] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UfYiENNLP6XjiHQtX4gACBCY"]
[Tue Jul 21 08:14:05.516895 2026] [security2:error] [pid 402041:tid 402282] [client 82.102.18.190:56628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9UfYiENNLP6XjiHQtX4wAAAfw"]
[Tue Jul 21 08:14:05.911418 2026] [security2:error] [pid 402041:tid 402200] [client 82.102.18.190:56634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ftp.moveisrafael.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9UfYiENNLP6XjiHQtX8AAAAao"]
[Tue Jul 21 08:14:06.087316 2026] [security2:error] [pid 402041:tid 402261] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UfoiENNLP6XjiHQtX8wAB50M"]
[Tue Jul 21 08:14:06.114761 2026] [security2:error] [pid 402041:tid 402192] [client 102.206.115.33:60253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UfoiENNLP6XjiHQtX9gAAAaI"]
[Tue Jul 21 08:14:06.114863 2026] [security2:error] [pid 402041:tid 402192] [client 102.206.115.33:60253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UfoiENNLP6XjiHQtX9gAAAaI"]
[Tue Jul 21 08:14:06.166772 2026] [security2:error] [pid 402041:tid 402046] [remote 72.167.132.114:40984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/wp-login.php"] [unique_id "al9UfoiENNLP6XjiHQtX-wABswI"]
[Tue Jul 21 08:14:06.443291 2026] [security2:error] [pid 402041:tid 402202] [client 20.104.96.117:62499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/gptsh.php"] [unique_id "al9UfoiENNLP6XjiHQtX_QAAAaw"]
[Tue Jul 21 08:14:06.645882 2026] [security2:error] [pid 402041:tid 402245] [client 20.151.10.161:51037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/dr.php"] [unique_id "al9UfoiENNLP6XjiHQtYBgAAAdc"]
[Tue Jul 21 08:14:07.103084 2026] [security2:error] [pid 402041:tid 402106] [remote 159.65.81.207:45310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Uf4iENNLP6XjiHQtYEAAB-j4"]
[Tue Jul 21 08:14:07.435893 2026] [security2:error] [pid 402041:tid 402234] [client 115.134.11.136:50586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uf4iENNLP6XjiHQtYGQAAAcw"]
[Tue Jul 21 08:14:07.446899 2026] [security2:error] [pid 402041:tid 402251] [client 111.93.58.162:22046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Uf4iENNLP6XjiHQtYHgAAAd0"]
[Tue Jul 21 08:14:07.447017 2026] [security2:error] [pid 402041:tid 402251] [client 111.93.58.162:22046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Uf4iENNLP6XjiHQtYHgAAAd0"]
[Tue Jul 21 08:14:07.491948 2026] [security2:error] [pid 402041:tid 402243] [client 20.220.225.223:30857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/la.php"] [unique_id "al9Uf4iENNLP6XjiHQtYIgAAAdU"]
[Tue Jul 21 08:14:07.747386 2026] [security2:error] [pid 402041:tid 402203] [client 20.104.96.117:62505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/rithin.php"] [unique_id "al9Uf4iENNLP6XjiHQtYLAAAAa0"]
[Tue Jul 21 08:14:07.851642 2026] [security2:error] [pid 402041:tid 402262] [client 62.102.148.158:38682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Uf4iENNLP6XjiHQtYLwAAAeg"]
[Tue Jul 21 08:14:07.851777 2026] [security2:error] [pid 402041:tid 402262] [client 62.102.148.158:38682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Uf4iENNLP6XjiHQtYLwAAAeg"]
[Tue Jul 21 08:14:07.888887 2026] [security2:error] [pid 402041:tid 402288] [client 20.226.60.151:48878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/login.php"] [unique_id "al9Uf4iENNLP6XjiHQtYMAAAAgI"]
[Tue Jul 21 08:14:07.990676 2026] [security2:error] [pid 402041:tid 402263] [client 187.125.243.197:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Uf4iENNLP6XjiHQtYMQAAAek"]
[Tue Jul 21 08:14:07.990827 2026] [security2:error] [pid 402041:tid 402263] [client 187.125.243.197:61389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Uf4iENNLP6XjiHQtYMQAAAek"]
[Tue Jul 21 08:14:08.037486 2026] [security2:error] [pid 402041:tid 402176] [client 61.1.167.83:52366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UgIiENNLP6XjiHQtYMwAAAZI"]
[Tue Jul 21 08:14:08.037607 2026] [security2:error] [pid 402041:tid 402176] [client 61.1.167.83:52366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UgIiENNLP6XjiHQtYMwAAAZI"]
[Tue Jul 21 08:14:08.486640 2026] [security2:error] [pid 402041:tid 402164] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UgIiENNLP6XjiHQtYPAABj3g"]
[Tue Jul 21 08:14:08.486839 2026] [security2:error] [pid 402041:tid 402173] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UgIiENNLP6XjiHQtYPAABj3g"]
[Tue Jul 21 08:14:08.555203 2026] [security2:error] [pid 402041:tid 402183] [client 20.104.96.117:63064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-blink.php"] [unique_id "al9UgIiENNLP6XjiHQtYQAAAAZk"]
[Tue Jul 21 08:14:08.584085 2026] [security2:error] [pid 402041:tid 402163] [remote 185.27.20.235:55690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.20.27.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9UgIiENNLP6XjiHQtYQQABwHc"]
[Tue Jul 21 08:14:08.675103 2026] [security2:error] [pid 402041:tid 402175] [client 20.151.10.161:51008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/xamp.php"] [unique_id "al9UgIiENNLP6XjiHQtYQgAAAZE"]
[Tue Jul 21 08:14:08.908690 2026] [security2:error] [pid 402041:tid 402247] [client 151.63.71.144:58129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9UgIiENNLP6XjiHQtYTAAAAdk"]
[Tue Jul 21 08:14:08.909225 2026] [security2:error] [pid 402041:tid 402247] [client 151.63.71.144:58129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9UgIiENNLP6XjiHQtYTAAAAdk"]
[Tue Jul 21 08:14:09.051223 2026] [security2:error] [pid 402041:tid 402147] [remote 124.55.178.99:45576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9UgYiENNLP6XjiHQtYTwABsGc"]
[Tue Jul 21 08:14:09.109310 2026] [security2:error] [pid 402041:tid 402210] [client 20.151.10.161:51008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/bless.php"] [unique_id "al9UgYiENNLP6XjiHQtYUAAAAbQ"]
[Tue Jul 21 08:14:09.627721 2026] [security2:error] [pid 402041:tid 402188] [client 120.56.162.40:60679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UgYiENNLP6XjiHQtYYgAAAZ4"]
[Tue Jul 21 08:14:09.627883 2026] [security2:error] [pid 402041:tid 402188] [client 120.56.162.40:60679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UgYiENNLP6XjiHQtYYgAAAZ4"]
[Tue Jul 21 08:14:09.774929 2026] [security2:error] [pid 402041:tid 402295] [client 20.151.10.161:55826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file46.php"] [unique_id "al9UgYiENNLP6XjiHQtYZgAAAgk"]
[Tue Jul 21 08:14:09.780487 2026] [security2:error] [pid 402041:tid 402208] [client 20.104.96.117:54113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/zc-208.php"] [unique_id "al9UgYiENNLP6XjiHQtYaAAAAbI"]
[Tue Jul 21 08:14:09.859472 2026] [security2:error] [pid 402041:tid 402291] [client 150.129.202.39:64591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UgYiENNLP6XjiHQtYbgAAAgU"]
[Tue Jul 21 08:14:09.859583 2026] [security2:error] [pid 402041:tid 402291] [client 150.129.202.39:64591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UgYiENNLP6XjiHQtYbgAAAgU"]
[Tue Jul 21 08:14:10.140635 2026] [security2:error] [pid 402041:tid 402270] [client 20.151.10.161:51038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/eee.php"] [unique_id "al9UgoiENNLP6XjiHQtYcAAAAfA"]
[Tue Jul 21 08:14:10.623190 2026] [security2:error] [pid 402041:tid 402243] [client 20.151.10.161:55838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file25.php"] [unique_id "al9UgoiENNLP6XjiHQtYgwAAAdU"]
[Tue Jul 21 08:14:10.678546 2026] [security2:error] [pid 402041:tid 402247] [client 20.151.10.161:36565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/scxy.php"] [unique_id "al9UgoiENNLP6XjiHQtYhAAAAdk"]
[Tue Jul 21 08:14:10.720654 2026] [security2:error] [pid 402041:tid 402192] [client 20.104.96.117:54119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/sid4.php"] [unique_id "al9UgoiENNLP6XjiHQtYhQAAAaI"]
[Tue Jul 21 08:14:10.730195 2026] [security2:error] [pid 402041:tid 402067] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UgoiENNLP6XjiHQtYhgAB_Bc"]
[Tue Jul 21 08:14:10.730351 2026] [security2:error] [pid 402041:tid 402282] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UgoiENNLP6XjiHQtYhgAB_Bc"]
[Tue Jul 21 08:14:10.888744 2026] [security2:error] [pid 402041:tid 402139] [remote 119.195.102.159:53304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9UgoiENNLP6XjiHQtYjwABmV8"]
[Tue Jul 21 08:14:11.206856 2026] [security2:error] [pid 402041:tid 402074] [remote 104.207.45.89:34595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.45.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9Ug4iENNLP6XjiHQtYkwABmB4"]
[Tue Jul 21 08:14:11.370021 2026] [security2:error] [pid 402041:tid 402208] [client 20.151.10.161:55916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file48.php"] [unique_id "al9Ug4iENNLP6XjiHQtYmQAAAbI"]
[Tue Jul 21 08:14:11.531982 2026] [security2:error] [pid 402041:tid 402185] [client 20.104.96.117:54660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wmore1.php"] [unique_id "al9Ug4iENNLP6XjiHQtYqgAAAZs"]
[Tue Jul 21 08:14:11.582351 2026] [security2:error] [pid 402041:tid 402269] [client 117.210.135.0:50604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ug4iENNLP6XjiHQtYrAAAAe8"]
[Tue Jul 21 08:14:11.582495 2026] [security2:error] [pid 402041:tid 402269] [client 117.210.135.0:50604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ug4iENNLP6XjiHQtYrAAAAe8"]
[Tue Jul 21 08:14:11.963277 2026] [security2:error] [pid 402041:tid 402206] [client 20.151.10.161:51018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file6.php"] [unique_id "al9Ug4iENNLP6XjiHQtYtgAAAbA"]
[Tue Jul 21 08:14:11.998916 2026] [security2:error] [pid 402041:tid 402136] [remote 154.61.75.100:43584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/wp-login.php"] [unique_id "al9Ug4iENNLP6XjiHQtYtwABz1w"]
[Tue Jul 21 08:14:12.287745 2026] [security2:error] [pid 402041:tid 402284] [client 20.151.10.161:51040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/a2.php"] [unique_id "al9UhIiENNLP6XjiHQtYvgAAAf4"]
[Tue Jul 21 08:14:12.405392 2026] [security2:error] [pid 402041:tid 402221] [client 86.106.84.166:45818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9UhIiENNLP6XjiHQtYyAAAAb8"]
[Tue Jul 21 08:14:12.405549 2026] [security2:error] [pid 402041:tid 402221] [client 86.106.84.166:45818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9UhIiENNLP6XjiHQtYyAAAAb8"]
[Tue Jul 21 08:14:12.442160 2026] [security2:error] [pid 402041:tid 402258] [client 20.104.96.117:54697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/solo1.php"] [unique_id "al9UhIiENNLP6XjiHQtYzQAAAeQ"]
[Tue Jul 21 08:14:12.457005 2026] [security2:error] [pid 402041:tid 402283] [client 20.104.96.117:62519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/fffm.php"] [unique_id "al9UhIiENNLP6XjiHQtY0gAAAf0"]
[Tue Jul 21 08:14:12.589223 2026] [security2:error] [pid 402041:tid 402210] [client 74.7.244.26:49602] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "colegioperseveranca.com"] [uri "/index.php"] [unique_id "al9UgoiENNLP6XjiHQtYiQAAAbQ"]
[Tue Jul 21 08:14:12.636740 2026] [security2:error] [pid 402041:tid 402279] [client 20.151.10.161:50980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file15.php"] [unique_id "al9UhIiENNLP6XjiHQtY1QAAAfk"]
[Tue Jul 21 08:14:12.922837 2026] [security2:error] [pid 402041:tid 402115] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UhIiENNLP6XjiHQtY3wABt0c"]
[Tue Jul 21 08:14:12.922988 2026] [security2:error] [pid 402041:tid 402213] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UhIiENNLP6XjiHQtY3wABt0c"]
[Tue Jul 21 08:14:12.985288 2026] [security2:error] [pid 402041:tid 402222] [client 20.151.10.161:54962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/jp.php"] [unique_id "al9UhIiENNLP6XjiHQtY4QAAAcA"]
[Tue Jul 21 08:14:12.997435 2026] [security2:error] [pid 402041:tid 402160] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UhIiENNLP6XjiHQtY4gABn3Q"]
[Tue Jul 21 08:14:12.997663 2026] [security2:error] [pid 402041:tid 402189] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UhIiENNLP6XjiHQtY4gABn3Q"]
[Tue Jul 21 08:14:13.123998 2026] [security2:error] [pid 402041:tid 402077] [remote 45.3.49.225:45755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.49.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9UhIiENNLP6XjiHQtY4AABziE"]
[Tue Jul 21 08:14:13.505510 2026] [security2:error] [pid 402041:tid 402290] [client 20.151.10.161:50968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/f35.php"] [unique_id "al9UhYiENNLP6XjiHQtY8QAAAgQ"]
[Tue Jul 21 08:14:13.531616 2026] [security2:error] [pid 402041:tid 402285] [client 103.78.200.11:53423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UhYiENNLP6XjiHQtY9QAAAf8"]
[Tue Jul 21 08:14:13.531722 2026] [security2:error] [pid 402041:tid 402285] [client 103.78.200.11:53423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UhYiENNLP6XjiHQtY9QAAAf8"]
[Tue Jul 21 08:14:13.811716 2026] [security2:error] [pid 402041:tid 402184] [client 20.226.60.151:48839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/a2.php"] [unique_id "al9UhYiENNLP6XjiHQtY-QAAAZo"]
[Tue Jul 21 08:14:13.904770 2026] [security2:error] [pid 402041:tid 402208] [client 20.151.10.161:55878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-load.php"] [unique_id "al9UhYiENNLP6XjiHQtY-wAAAbI"]
[Tue Jul 21 08:14:13.976069 2026] [security2:error] [pid 402041:tid 402279] [client 20.104.96.117:54115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/cong.php"] [unique_id "al9UhYiENNLP6XjiHQtY_QAAAfk"]
[Tue Jul 21 08:14:14.261085 2026] [security2:error] [pid 402041:tid 402269] [client 20.151.10.161:50959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/xwpg.php"] [unique_id "al9UhoiENNLP6XjiHQtZBQAAAe8"]
[Tue Jul 21 08:14:14.556336 2026] [security2:error] [pid 402041:tid 402133] [remote 207.180.241.245:36868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9UhoiENNLP6XjiHQtZEQACCVk"]
[Tue Jul 21 08:14:14.657939 2026] [security2:error] [pid 402041:tid 402206] [client 20.151.10.161:51117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/FWAZ.php"] [unique_id "al9UhoiENNLP6XjiHQtZGAAAAbA"]
[Tue Jul 21 08:14:14.702755 2026] [security2:error] [pid 402041:tid 402220] [client 87.116.180.198:27193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UhoiENNLP6XjiHQtZGQAAAb4"]
[Tue Jul 21 08:14:14.702917 2026] [security2:error] [pid 402041:tid 402220] [client 87.116.180.198:27193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UhoiENNLP6XjiHQtZGQAAAb4"]
[Tue Jul 21 08:14:14.743957 2026] [security2:error] [pid 402041:tid 402177] [client 20.220.225.223:30894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/nhvoanpl.php"] [unique_id "al9UhoiENNLP6XjiHQtZGgAAAZM"]
[Tue Jul 21 08:14:14.875603 2026] [security2:error] [pid 402041:tid 402046] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UhoiENNLP6XjiHQtZIAAB2AI"]
[Tue Jul 21 08:14:14.875759 2026] [security2:error] [pid 402041:tid 402246] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UhoiENNLP6XjiHQtZIAAB2AI"]
[Tue Jul 21 08:14:14.970053 2026] [security2:error] [pid 402041:tid 402291] [client 20.151.10.161:51047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/waf.php"] [unique_id "al9UhoiENNLP6XjiHQtZIgAAAgU"]
[Tue Jul 21 08:14:15.053716 2026] [security2:error] [pid 402041:tid 402222] [client 38.100.221.102:17330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uh4iENNLP6XjiHQtZIwAAAcA"]
[Tue Jul 21 08:14:15.053856 2026] [security2:error] [pid 402041:tid 402222] [client 38.100.221.102:17330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uh4iENNLP6XjiHQtZIwAAAcA"]
[Tue Jul 21 08:14:15.361699 2026] [security2:error] [pid 402041:tid 402241] [client 154.208.47.43:48373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Uh4iENNLP6XjiHQtZLwAAAdM"]
[Tue Jul 21 08:14:15.361835 2026] [security2:error] [pid 402041:tid 402241] [client 154.208.47.43:48373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Uh4iENNLP6XjiHQtZLwAAAdM"]
[Tue Jul 21 08:14:15.366305 2026] [core:error] [pid 402041:tid 402169] [remote 57.141.18.75:61328] AH10244: invalid URI path (/%post_type%/6745/)
[Tue Jul 21 08:14:15.455690 2026] [security2:error] [pid 402041:tid 402226] [client 20.151.10.161:50956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/xstelth.php"] [unique_id "al9Uh4iENNLP6XjiHQtZMgAAAcQ"]
[Tue Jul 21 08:14:15.830853 2026] [security2:error] [pid 402041:tid 402243] [client 20.151.10.161:55908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-links.php"] [unique_id "al9Uh4iENNLP6XjiHQtZQQAAAdU"]
[Tue Jul 21 08:14:15.995163 2026] [security2:error] [pid 402041:tid 402260] [client 20.104.96.117:54677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/public/css.php"] [unique_id "al9Uh4iENNLP6XjiHQtZRgAAAeY"]
[Tue Jul 21 08:14:16.038706 2026] [security2:error] [pid 402041:tid 402178] [client 103.151.46.103:58733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UiIiENNLP6XjiHQtZRwAAAZQ"]
[Tue Jul 21 08:14:16.038821 2026] [security2:error] [pid 402041:tid 402178] [client 103.151.46.103:58733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UiIiENNLP6XjiHQtZRwAAAZQ"]
[Tue Jul 21 08:14:16.218439 2026] [security2:error] [pid 402041:tid 402075] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UiIiENNLP6XjiHQtZUAAB2R8"]
[Tue Jul 21 08:14:16.218687 2026] [security2:error] [pid 402041:tid 402247] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UiIiENNLP6XjiHQtZUAAB2R8"]
[Tue Jul 21 08:14:16.404585 2026] [security2:error] [pid 402041:tid 402284] [client 20.151.10.161:55920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9UiIiENNLP6XjiHQtZeQAAAf4"]
[Tue Jul 21 08:14:16.581902 2026] [security2:error] [pid 402041:tid 402265] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UiIiENNLP6XjiHQtZfwAB6yQ"]
[Tue Jul 21 08:14:16.681640 2026] [security2:error] [pid 402041:tid 402189] [client 102.206.115.33:61817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UiIiENNLP6XjiHQtZigAAAZ8"]
[Tue Jul 21 08:14:16.682158 2026] [security2:error] [pid 402041:tid 402189] [client 102.206.115.33:61817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UiIiENNLP6XjiHQtZigAAAZ8"]
[Tue Jul 21 08:14:16.863091 2026] [security2:error] [pid 402041:tid 402186] [client 20.104.96.117:63460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/dfre.php"] [unique_id "al9UiIiENNLP6XjiHQtZmwAAAZw"]
[Tue Jul 21 08:14:16.898464 2026] [security2:error] [pid 402041:tid 402289] [client 20.151.10.161:51005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/aaa.php"] [unique_id "al9UiIiENNLP6XjiHQtZnAAAAgM"]
[Tue Jul 21 08:14:16.985613 2026] [security2:error] [pid 402041:tid 402212] [client 20.104.96.117:62998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/output.php"] [unique_id "al9UiIiENNLP6XjiHQtZoAAAAbY"]
[Tue Jul 21 08:14:16.986775 2026] [security2:error] [pid 402041:tid 402226] [client 65.21.113.253:58588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UiIiENNLP6XjiHQtZlAAAAcQ"]
[Tue Jul 21 08:14:17.223953 2026] [security2:error] [pid 402041:tid 402175] [client 4.194.24.143:30218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/about/function.php"] [unique_id "al9UiYiENNLP6XjiHQtZtAAAAZE"]
[Tue Jul 21 08:14:17.709767 2026] [security2:error] [pid 402041:tid 402290] [client 65.21.113.253:58588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UiYiENNLP6XjiHQtZtQAAAgQ"]
[Tue Jul 21 08:14:17.780129 2026] [security2:error] [pid 402041:tid 402093] [remote 103.77.162.29:41916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.162.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9Uh4iENNLP6XjiHQtZPgACDDE"]
[Tue Jul 21 08:14:17.886389 2026] [security2:error] [pid 402041:tid 402236] [client 115.134.11.136:51476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UiYiENNLP6XjiHQtZxAAAAc4"]
[Tue Jul 21 08:14:18.075974 2026] [security2:error] [pid 402041:tid 402264] [client 14.97.58.74:39437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UioiENNLP6XjiHQtZyQAAAeo"]
[Tue Jul 21 08:14:18.076159 2026] [security2:error] [pid 402041:tid 402264] [client 14.97.58.74:39437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UioiENNLP6XjiHQtZyQAAAeo"]
[Tue Jul 21 08:14:18.322807 2026] [security2:error] [pid 402041:tid 402225] [client 4.194.24.143:25395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/admiin.php"] [unique_id "al9UioiENNLP6XjiHQtZ1wAAAcM"]
[Tue Jul 21 08:14:18.484996 2026] [security2:error] [pid 402041:tid 402287] [client 187.125.243.197:61856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UioiENNLP6XjiHQtZ2wAAAgE"]
[Tue Jul 21 08:14:18.485091 2026] [security2:error] [pid 402041:tid 402287] [client 187.125.243.197:61856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UioiENNLP6XjiHQtZ2wAAAgE"]
[Tue Jul 21 08:14:18.566577 2026] [security2:error] [pid 402041:tid 402274] [client 20.151.10.161:36550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/qterm.php"] [unique_id "al9UioiENNLP6XjiHQtZ3QAAAfQ"]
[Tue Jul 21 08:14:18.916730 2026] [security2:error] [pid 402041:tid 402254] [client 20.104.96.117:54120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-file-120.php"] [unique_id "al9UioiENNLP6XjiHQtZ6gAAAeA"]
[Tue Jul 21 08:14:19.000966 2026] [security2:error] [pid 402041:tid 402123] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ui4iENNLP6XjiHQtZ7AAB5E8"]
[Tue Jul 21 08:14:19.001162 2026] [security2:error] [pid 402041:tid 402258] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ui4iENNLP6XjiHQtZ7AAB5E8"]
[Tue Jul 21 08:14:19.252495 2026] [security2:error] [pid 402041:tid 402198] [client 20.226.60.151:48864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/d61.php"] [unique_id "al9Ui4iENNLP6XjiHQtZ8AAAAag"]
[Tue Jul 21 08:14:19.377463 2026] [security2:error] [pid 402041:tid 402188] [client 4.194.24.143:22336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/admin-main/class-wp-http-core.php"] [unique_id "al9Ui4iENNLP6XjiHQtZ9wAAAZ4"]
[Tue Jul 21 08:14:19.758663 2026] [security2:error] [pid 402041:tid 402272] [client 20.151.10.161:51135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/blurbs.php"] [unique_id "al9Ui4iENNLP6XjiHQtZ_wAAAfI"]
[Tue Jul 21 08:14:20.210981 2026] [security2:error] [pid 402041:tid 402288] [client 51.222.168.205:20848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "gtlocacoes.net"] [uri "/robots.txt"] [unique_id "al9UjIiENNLP6XjiHQtaDQAAAgI"]
[Tue Jul 21 08:14:20.211088 2026] [security2:error] [pid 402041:tid 402288] [client 51.222.168.205:20848] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gtlocacoes.net"] [uri "/robots.txt"] [unique_id "al9UjIiENNLP6XjiHQtaDQAAAgI"]
[Tue Jul 21 08:14:20.229180 2026] [security2:error] [pid 402041:tid 402052] [remote 57.141.18.31:24772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9Ui4iENNLP6XjiHQtZ7wABxAg"]
[Tue Jul 21 08:14:20.241140 2026] [security2:error] [pid 402041:tid 402209] [client 120.56.162.40:61188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UjIiENNLP6XjiHQtaDgAAAbM"]
[Tue Jul 21 08:14:20.241563 2026] [security2:error] [pid 402041:tid 402209] [client 120.56.162.40:61188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UjIiENNLP6XjiHQtaDgAAAbM"]
[Tue Jul 21 08:14:20.408794 2026] [security2:error] [pid 402041:tid 402244] [client 4.194.24.143:13374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/admin-post.php"] [unique_id "al9UjIiENNLP6XjiHQtaFAAAAdY"]
[Tue Jul 21 08:14:20.415663 2026] [security2:error] [pid 402041:tid 402291] [client 150.129.202.39:65411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UjIiENNLP6XjiHQtaFQAAAgU"]
[Tue Jul 21 08:14:20.415753 2026] [security2:error] [pid 402041:tid 402291] [client 150.129.202.39:65411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UjIiENNLP6XjiHQtaFQAAAgU"]
[Tue Jul 21 08:14:20.501436 2026] [security2:error] [pid 402041:tid 402249] [client 20.151.10.161:51115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/v543.php"] [unique_id "al9UjIiENNLP6XjiHQtaGwAAAds"]
[Tue Jul 21 08:14:20.771054 2026] [core:error] [pid 402041:tid 402230] [client 66.249.66.67:43415] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:14:20.771078 2026] [core:error] [pid 402041:tid 402230] [client 66.249.66.67:43415] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:14:20.805419 2026] [security2:error] [pid 402041:tid 402155] [remote 57.141.18.28:58520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9UjIiENNLP6XjiHQtaJAABum8"]
[Tue Jul 21 08:14:21.180559 2026] [security2:error] [pid 402041:tid 402211] [client 20.104.96.117:62516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/wp-happy.php"] [unique_id "al9UjYiENNLP6XjiHQtaNAAAAbU"]
[Tue Jul 21 08:14:21.378741 2026] [security2:error] [pid 402041:tid 402048] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UjYiENNLP6XjiHQtaOAAB9AQ"]
[Tue Jul 21 08:14:21.378968 2026] [security2:error] [pid 402041:tid 402274] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UjYiENNLP6XjiHQtaOAAB9AQ"]
[Tue Jul 21 08:14:21.449849 2026] [security2:error] [pid 402041:tid 402259] [client 4.194.24.143:25386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/admin.php"] [unique_id "al9UjYiENNLP6XjiHQtaPAAAAeU"]
[Tue Jul 21 08:14:21.514439 2026] [security2:error] [pid 402041:tid 402252] [client 20.104.96.117:54719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/special.php"] [unique_id "al9UjYiENNLP6XjiHQtaQwAAAd4"]
[Tue Jul 21 08:14:21.523422 2026] [security2:error] [pid 402041:tid 402204] [client 20.151.10.161:51123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/w3lls.php"] [unique_id "al9UjYiENNLP6XjiHQtaRwAAAa4"]
[Tue Jul 21 08:14:21.593173 2026] [security2:error] [pid 402041:tid 402176] [client 151.63.71.144:58671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9UjYiENNLP6XjiHQtaSgAAAZI"]
[Tue Jul 21 08:14:21.593273 2026] [security2:error] [pid 402041:tid 402176] [client 151.63.71.144:58671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9UjYiENNLP6XjiHQtaSgAAAZI"]
[Tue Jul 21 08:14:21.668303 2026] [security2:error] [pid 402041:tid 402237] [client 54.39.89.183:49356] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "gtlocacoes.net"] [uri "/"] [unique_id "al9UjYiENNLP6XjiHQtaTgAAAc8"]
[Tue Jul 21 08:14:21.668418 2026] [security2:error] [pid 402041:tid 402237] [client 54.39.89.183:49356] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gtlocacoes.net"] [uri "/"] [unique_id "al9UjYiENNLP6XjiHQtaTgAAAc8"]
[Tue Jul 21 08:14:21.795994 2026] [security2:error] [pid 402041:tid 402243] [client 198.54.129.60:39610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9UjYiENNLP6XjiHQtaUAAAAdU"]
[Tue Jul 21 08:14:21.796111 2026] [security2:error] [pid 402041:tid 402243] [client 198.54.129.60:39610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9UjYiENNLP6XjiHQtaUAAAAdU"]
[Tue Jul 21 08:14:22.078417 2026] [security2:error] [pid 402041:tid 402196] [client 117.210.135.0:51244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UjoiENNLP6XjiHQtaYwAAAaY"]
[Tue Jul 21 08:14:22.078575 2026] [security2:error] [pid 402041:tid 402196] [client 117.210.135.0:51244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UjoiENNLP6XjiHQtaYwAAAaY"]
[Tue Jul 21 08:14:22.100579 2026] [security2:error] [pid 402041:tid 402280] [client 20.197.192.193:61827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/dp.php"] [unique_id "al9UjoiENNLP6XjiHQtaZAAAAfo"]
[Tue Jul 21 08:14:22.594191 2026] [security2:error] [pid 402041:tid 402221] [client 51.68.235.235:47950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.pacodasrosas.com.br"] [uri "/robots.txt"] [unique_id "al9UjoiENNLP6XjiHQtacQAAAb8"]
[Tue Jul 21 08:14:22.594295 2026] [security2:error] [pid 402041:tid 402221] [client 51.68.235.235:47950] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.pacodasrosas.com.br"] [uri "/robots.txt"] [unique_id "al9UjoiENNLP6XjiHQtacQAAAb8"]
[Tue Jul 21 08:14:22.902074 2026] [security2:error] [pid 402041:tid 402205] [client 20.151.10.161:51125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-ws68.php"] [unique_id "al9UjoiENNLP6XjiHQtaewAAAa8"]
[Tue Jul 21 08:14:23.189543 2026] [security2:error] [pid 402041:tid 402282] [client 4.194.24.143:25406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/admin/function.php"] [unique_id "al9Uj4iENNLP6XjiHQtaiQAAAfw"]
[Tue Jul 21 08:14:23.415606 2026] [security2:error] [pid 402041:tid 402105] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uj4iENNLP6XjiHQtajQAB_z0"]
[Tue Jul 21 08:14:23.415757 2026] [security2:error] [pid 402041:tid 402285] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uj4iENNLP6XjiHQtajQAB_z0"]
[Tue Jul 21 08:14:23.547577 2026] [security2:error] [pid 402041:tid 402280] [client 114.119.142.135:60423] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "artetoner.com.br"] [uri "/default.htm"] [unique_id "al9Uj4iENNLP6XjiHQtalgAAAfo"], referer: http://artetoner.com.br/default.htm
[Tue Jul 21 08:14:23.787955 2026] [security2:error] [pid 402041:tid 402088] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uj4iENNLP6XjiHQtanQABrSw"]
[Tue Jul 21 08:14:23.788111 2026] [security2:error] [pid 402041:tid 402203] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uj4iENNLP6XjiHQtanQABrSw"]
[Tue Jul 21 08:14:23.947530 2026] [security2:error] [pid 402041:tid 402259] [client 20.151.10.161:51105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/xyn.php"] [unique_id "al9Uj4iENNLP6XjiHQtaoAAAAeU"]
[Tue Jul 21 08:14:24.045486 2026] [security2:error] [pid 402041:tid 402179] [client 91.148.244.131:42812] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/"] [unique_id "al9UkIiENNLP6XjiHQtaqAAAAZU"]
[Tue Jul 21 08:14:24.046028 2026] [security2:error] [pid 402041:tid 402191] [client 91.148.244.131:42804] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/"] [unique_id "al9UkIiENNLP6XjiHQtaqgAAAaE"]
[Tue Jul 21 08:14:24.046142 2026] [security2:error] [pid 402041:tid 402215] [client 91.148.244.131:42798] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/"] [unique_id "al9UkIiENNLP6XjiHQtaqQAAAbk"]
[Tue Jul 21 08:14:24.208842 2026] [security2:error] [pid 402041:tid 402226] [client 4.194.24.143:30235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/adminfuns.php"] [unique_id "al9UkIiENNLP6XjiHQtarwAAAcQ"]
[Tue Jul 21 08:14:24.216369 2026] [security2:error] [pid 402041:tid 402188] [client 20.104.96.117:62577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/fpr4.php"] [unique_id "al9UkIiENNLP6XjiHQtasAAAAZ4"]
[Tue Jul 21 08:14:24.325060 2026] [security2:error] [pid 402041:tid 402283] [client 103.78.200.11:53910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UkIiENNLP6XjiHQtasQAAAf0"]
[Tue Jul 21 08:14:24.325211 2026] [security2:error] [pid 402041:tid 402283] [client 103.78.200.11:53910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UkIiENNLP6XjiHQtasQAAAf0"]
[Tue Jul 21 08:14:24.460931 2026] [security2:error] [pid 402041:tid 402198] [client 20.151.10.161:36561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/green3.php"] [unique_id "al9UkIiENNLP6XjiHQtaswAAAag"]
[Tue Jul 21 08:14:24.505756 2026] [security2:error] [pid 402041:tid 402243] [client 74.7.175.157:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lucasteixeiradebarro1743738723554.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9UkIiENNLP6XjiHQtatQAB1WY"]
[Tue Jul 21 08:14:24.599261 2026] [security2:error] [pid 402041:tid 402202] [client 20.220.225.223:30696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/inso.php"] [unique_id "al9UkIiENNLP6XjiHQtauQAAAaw"]
[Tue Jul 21 08:14:24.711173 2026] [security2:error] [pid 402041:tid 402280] [client 20.104.96.117:63044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/as.php"] [unique_id "al9UkIiENNLP6XjiHQtavgAAAfo"]
[Tue Jul 21 08:14:24.741823 2026] [security2:error] [pid 402041:tid 402262] [client 74.249.245.134:15385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9UkIiENNLP6XjiHQtavwAAAeg"]
[Tue Jul 21 08:14:24.958533 2026] [security2:error] [pid 402041:tid 402210] [client 47.128.41.53:10674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cartoriodecurupira.com.br"] [uri "/robots.txt"] [unique_id "al9UkIiENNLP6XjiHQtaxQAAAbQ"]
[Tue Jul 21 08:14:25.012642 2026] [security2:error] [pid 402041:tid 402199] [client 20.151.10.161:36578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/ccs.php"] [unique_id "al9UkYiENNLP6XjiHQtaxgAAAak"]
[Tue Jul 21 08:14:25.223405 2026] [security2:error] [pid 402041:tid 402271] [client 3.145.12.153:49768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "quattrotech.com.br"] [uri "/robots.txt"] [unique_id "al9UkYiENNLP6XjiHQta0AAAAfE"]
[Tue Jul 21 08:14:25.269106 2026] [security2:error] [pid 402041:tid 402294] [client 38.100.221.102:17232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UkYiENNLP6XjiHQta0QAAAgg"]
[Tue Jul 21 08:14:25.269261 2026] [security2:error] [pid 402041:tid 402294] [client 38.100.221.102:17232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UkYiENNLP6XjiHQta0QAAAgg"]
[Tue Jul 21 08:14:25.276791 2026] [security2:error] [pid 402041:tid 402239] [client 4.194.24.143:22288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/administrator/components/com_associations/layouts/joomla/searchtools/mainhack.php"] [unique_id "al9UkYiENNLP6XjiHQta0gAAAdE"]
[Tue Jul 21 08:14:25.394126 2026] [security2:error] [pid 402041:tid 402244] [client 20.151.10.161:51108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/ccc.php"] [unique_id "al9UkYiENNLP6XjiHQta0wAAAdY"]
[Tue Jul 21 08:14:25.439576 2026] [security2:error] [pid 402041:tid 402220] [client 87.116.180.198:13987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UkYiENNLP6XjiHQta1AAAAb4"]
[Tue Jul 21 08:14:25.441915 2026] [security2:error] [pid 402041:tid 402220] [client 87.116.180.198:13987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UkYiENNLP6XjiHQta1AAAAb4"]
[Tue Jul 21 08:14:25.455331 2026] [security2:error] [pid 402041:tid 402213] [client 47.128.26.34:47786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nrfilmes.com"] [uri "/robots.txt"] [unique_id "al9UkYiENNLP6XjiHQta1gAAAbc"]
[Tue Jul 21 08:14:25.836629 2026] [security2:error] [pid 402041:tid 402284] [client 154.208.47.43:48843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UkYiENNLP6XjiHQta4QAAAf4"]
[Tue Jul 21 08:14:25.836797 2026] [security2:error] [pid 402041:tid 402284] [client 154.208.47.43:48843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UkYiENNLP6XjiHQta4QAAAf4"]
[Tue Jul 21 08:14:25.837872 2026] [security2:error] [pid 402041:tid 402286] [client 20.151.10.161:51114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/get.php"] [unique_id "al9UkYiENNLP6XjiHQta4gAAAgA"]
[Tue Jul 21 08:14:25.951675 2026] [security2:error] [pid 402041:tid 402065] [remote 162.19.246.208:39110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wp-login.php"] [unique_id "al9UkYiENNLP6XjiHQta4wAB6hU"]
[Tue Jul 21 08:14:26.026691 2026] [security2:error] [pid 402041:tid 402045] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UkoiENNLP6XjiHQta5QABpwE"]
[Tue Jul 21 08:14:26.026863 2026] [security2:error] [pid 402041:tid 402197] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UkoiENNLP6XjiHQta5QABpwE"]
[Tue Jul 21 08:14:26.311710 2026] [security2:error] [pid 402041:tid 402180] [client 162.219.176.3:39218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9UkoiENNLP6XjiHQta7wAAAZY"]
[Tue Jul 21 08:14:26.311856 2026] [security2:error] [pid 402041:tid 402180] [client 162.219.176.3:39218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9UkoiENNLP6XjiHQta7wAAAZY"]
[Tue Jul 21 08:14:26.375628 2026] [security2:error] [pid 402041:tid 402296] [client 4.194.24.143:13328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/ahax.php"] [unique_id "al9UkoiENNLP6XjiHQta8QAAAgo"]
[Tue Jul 21 08:14:26.743260 2026] [security2:error] [pid 402041:tid 402177] [client 20.151.10.161:36560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/images.php"] [unique_id "al9UkoiENNLP6XjiHQta-gAAAZM"]
[Tue Jul 21 08:14:26.893008 2026] [security2:error] [pid 402041:tid 402073] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UkoiENNLP6XjiHQta_gAB-B0"]
[Tue Jul 21 08:14:26.893178 2026] [security2:error] [pid 402041:tid 402278] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UkoiENNLP6XjiHQta_gAB-B0"]
[Tue Jul 21 08:14:27.038096 2026] [security2:error] [pid 402041:tid 402221] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UkoiENNLP6XjiHQta_wABv2w"]
[Tue Jul 21 08:14:27.188733 2026] [security2:error] [pid 402041:tid 402199] [client 102.206.115.33:59098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Uk4iENNLP6XjiHQtbAgAAAak"]
[Tue Jul 21 08:14:27.189128 2026] [security2:error] [pid 402041:tid 402199] [client 102.206.115.33:59098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Uk4iENNLP6XjiHQtbAgAAAak"]
[Tue Jul 21 08:14:27.408980 2026] [security2:error] [pid 402041:tid 402200] [client 4.194.24.143:13587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/ak.php"] [unique_id "al9Uk4iENNLP6XjiHQtbDAAAAao"]
[Tue Jul 21 08:14:27.828335 2026] [security2:error] [pid 402041:tid 402272] [client 20.151.10.161:51087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/alls.php"] [unique_id "al9Uk4iENNLP6XjiHQtbGgAAAfI"]
[Tue Jul 21 08:14:27.976162 2026] [security2:error] [pid 402041:tid 402258] [client 20.220.225.223:30680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/wpx.php"] [unique_id "al9Uk4iENNLP6XjiHQtbIQAAAeQ"]
[Tue Jul 21 08:14:28.272665 2026] [security2:error] [pid 402041:tid 402294] [client 74.249.245.134:15383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9UlIiENNLP6XjiHQtbKQAAAgg"]
[Tue Jul 21 08:14:28.444336 2026] [security2:error] [pid 402041:tid 402185] [client 115.134.11.136:51858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UlIiENNLP6XjiHQtbMQAAAZs"]
[Tue Jul 21 08:14:28.456112 2026] [security2:error] [pid 402041:tid 402225] [client 86.106.84.166:54422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9UlIiENNLP6XjiHQtbMgAAAcM"]
[Tue Jul 21 08:14:28.456206 2026] [security2:error] [pid 402041:tid 402225] [client 86.106.84.166:54422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9UlIiENNLP6XjiHQtbMgAAAcM"]
[Tue Jul 21 08:14:28.475300 2026] [security2:error] [pid 402041:tid 402235] [client 4.194.24.143:13809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/alfa-rex.php"] [unique_id "al9UlIiENNLP6XjiHQtbNAAAAc0"]
[Tue Jul 21 08:14:28.565566 2026] [security2:error] [pid 402041:tid 402260] [client 20.151.10.161:51092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/yyu.php"] [unique_id "al9UlIiENNLP6XjiHQtbNgAAAeY"]
[Tue Jul 21 08:14:28.831778 2026] [security2:error] [pid 402041:tid 402253] [client 20.104.96.117:54702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9UlIiENNLP6XjiHQtbPgAAAd8"]
[Tue Jul 21 08:14:28.864954 2026] [security2:error] [pid 402041:tid 402246] [client 20.197.192.193:3170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/old.php"] [unique_id "al9UlIiENNLP6XjiHQtbQwAAAdg"]
[Tue Jul 21 08:14:28.945204 2026] [security2:error] [pid 402041:tid 402233] [client 137.97.59.154:55355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UlIiENNLP6XjiHQtbSAAAAcs"]
[Tue Jul 21 08:14:28.945320 2026] [security2:error] [pid 402041:tid 402233] [client 137.97.59.154:55355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UlIiENNLP6XjiHQtbSAAAAcs"]
[Tue Jul 21 08:14:28.984465 2026] [security2:error] [pid 402041:tid 402192] [client 187.125.243.197:62321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UlIiENNLP6XjiHQtbSgAAAaI"]
[Tue Jul 21 08:14:28.986072 2026] [security2:error] [pid 402041:tid 402192] [client 187.125.243.197:62321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UlIiENNLP6XjiHQtbSgAAAaI"]
[Tue Jul 21 08:14:29.335276 2026] [security2:error] [pid 402041:tid 402210] [client 20.151.10.161:51089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/by.php"] [unique_id "al9UlYiENNLP6XjiHQtbVgAAAbQ"]
[Tue Jul 21 08:14:29.516794 2026] [security2:error] [pid 402041:tid 402114] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UlYiENNLP6XjiHQtbWwAB0UY"]
[Tue Jul 21 08:14:29.516997 2026] [security2:error] [pid 402041:tid 402239] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UlYiENNLP6XjiHQtbWwAB0UY"]
[Tue Jul 21 08:14:29.523090 2026] [security2:error] [pid 402041:tid 402280] [client 4.194.24.143:13343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/alfa.php"] [unique_id "al9UlYiENNLP6XjiHQtbXAAAAfo"]
[Tue Jul 21 08:14:29.884823 2026] [security2:error] [pid 402041:tid 402205] [client 91.148.244.131:42830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/config.php"] [unique_id "al9UlYiENNLP6XjiHQtbZgAAAa8"]
[Tue Jul 21 08:14:29.885021 2026] [security2:error] [pid 402041:tid 402176] [client 91.148.244.131:42826] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9UlYiENNLP6XjiHQtbaAAAAZI"]
[Tue Jul 21 08:14:29.885114 2026] [security2:error] [pid 402041:tid 402220] [client 91.148.244.131:42852] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/config.xml"] [unique_id "al9UlYiENNLP6XjiHQtbaQAAAb4"]
[Tue Jul 21 08:14:29.885167 2026] [security2:error] [pid 402041:tid 402262] [client 91.148.244.131:42846] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/.git/HEAD"] [unique_id "al9UlYiENNLP6XjiHQtbZwAAAeg"]
[Tue Jul 21 08:14:29.976732 2026] [security2:error] [pid 402041:tid 402200] [client 20.197.192.193:61873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/ms-new.php"] [unique_id "al9UlYiENNLP6XjiHQtbcQAAAao"]
[Tue Jul 21 08:14:30.112606 2026] [security2:error] [pid 402041:tid 402177] [client 45.8.19.188:48099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9UloiENNLP6XjiHQtbdwAAAZM"]
[Tue Jul 21 08:14:30.115808 2026] [security2:error] [pid 402041:tid 402184] [client 45.8.19.163:56829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9UloiENNLP6XjiHQtbeAAAAZo"]
[Tue Jul 21 08:14:30.131418 2026] [security2:error] [pid 402041:tid 402295] [client 51.68.111.241:16339] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fastpedidos.com.br"] [uri "/robots.txt"] [unique_id "al9UloiENNLP6XjiHQtbeQAAAgk"]
[Tue Jul 21 08:14:30.131531 2026] [security2:error] [pid 402041:tid 402295] [client 51.68.111.241:16339] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fastpedidos.com.br"] [uri "/robots.txt"] [unique_id "al9UloiENNLP6XjiHQtbeQAAAgk"]
[Tue Jul 21 08:14:30.608097 2026] [security2:error] [pid 402041:tid 402272] [client 4.194.24.143:52285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/amax.php"] [unique_id "al9UloiENNLP6XjiHQtbhAAAAfI"]
[Tue Jul 21 08:14:30.858598 2026] [security2:error] [pid 402041:tid 402175] [client 91.148.244.131:42886] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/docker-compose.yml"] [unique_id "al9UloiENNLP6XjiHQtbiAAAAZE"]
[Tue Jul 21 08:14:30.860464 2026] [security2:error] [pid 402041:tid 402239] [client 91.148.244.131:42900] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/phpinfo.php"] [unique_id "al9UloiENNLP6XjiHQtbiQAAAdE"]
[Tue Jul 21 08:14:30.861058 2026] [security2:error] [pid 402041:tid 402256] [client 91.148.244.131:42888] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/.env"] [unique_id "al9UloiENNLP6XjiHQtbigAAAeI"]
[Tue Jul 21 08:14:30.864319 2026] [security2:error] [pid 402041:tid 402174] [client 120.56.162.40:61681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UloiENNLP6XjiHQtbiwAAAZA"]
[Tue Jul 21 08:14:30.864394 2026] [security2:error] [pid 402041:tid 402174] [client 120.56.162.40:61681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UloiENNLP6XjiHQtbiwAAAZA"]
[Tue Jul 21 08:14:30.911277 2026] [security2:error] [pid 402041:tid 402212] [client 74.7.228.40:33924] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cinspeluz.com.br"] [uri "/index.php"] [unique_id "al9UloiENNLP6XjiHQtbcwABtko"]
[Tue Jul 21 08:14:30.963420 2026] [security2:error] [pid 402041:tid 402226] [client 20.151.10.161:51116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/FAQ.php"] [unique_id "al9UloiENNLP6XjiHQtblAAAAcQ"]
[Tue Jul 21 08:14:31.118880 2026] [security2:error] [pid 402041:tid 402183] [client 150.129.202.39:13423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ul4iENNLP6XjiHQtblwAAAZk"]
[Tue Jul 21 08:14:31.119044 2026] [security2:error] [pid 402041:tid 402183] [client 150.129.202.39:13423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ul4iENNLP6XjiHQtblwAAAZk"]
[Tue Jul 21 08:14:31.248195 2026] [security2:error] [pid 402041:tid 402187] [client 20.104.96.117:62510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/file88.php"] [unique_id "al9Ul4iENNLP6XjiHQtbmAAAAZ0"]
[Tue Jul 21 08:14:31.298719 2026] [security2:error] [pid 402041:tid 402253] [client 20.104.96.117:54112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/w1px.php"] [unique_id "al9Ul4iENNLP6XjiHQtbnQAAAd8"]
[Tue Jul 21 08:14:31.644098 2026] [security2:error] [pid 402041:tid 402237] [client 91.148.244.131:42922] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/.env.production"] [unique_id "al9Ul4iENNLP6XjiHQtbxAAAAc8"]
[Tue Jul 21 08:14:31.645618 2026] [security2:error] [pid 402041:tid 402258] [client 91.148.244.131:42940] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/user_secrets.yml"] [unique_id "al9Ul4iENNLP6XjiHQtbxQAAAeQ"]
[Tue Jul 21 08:14:31.647270 2026] [security2:error] [pid 402041:tid 402245] [client 91.148.244.131:42936] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9Ul4iENNLP6XjiHQtbxgAAAdc"]
[Tue Jul 21 08:14:31.647407 2026] [security2:error] [pid 402041:tid 402180] [client 91.148.244.131:42906] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/api/.env"] [unique_id "al9Ul4iENNLP6XjiHQtbxwAAAZY"]
[Tue Jul 21 08:14:31.671251 2026] [security2:error] [pid 402041:tid 402227] [client 4.194.24.143:13800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/archive.php"] [unique_id "al9Ul4iENNLP6XjiHQtbzQAAAcU"]
[Tue Jul 21 08:14:31.741380 2026] [security2:error] [pid 402041:tid 402218] [client 74.7.228.40:33928] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cinspeluz.com.br"] [uri "/index.php"] [unique_id "al9Ul4iENNLP6XjiHQtbwwABvBc"], referer: https://cinspeluz.com.br/robots.txt
[Tue Jul 21 08:14:31.848126 2026] [security2:error] [pid 402041:tid 402211] [client 91.148.244.131:42930] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/server.key"] [unique_id "al9Ul4iENNLP6XjiHQtb3wAAAbU"]
[Tue Jul 21 08:14:31.850186 2026] [security2:error] [pid 402041:tid 402277] [client 91.148.244.131:42948] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/config/production.json"] [unique_id "al9Ul4iENNLP6XjiHQtb4AAAAfc"]
[Tue Jul 21 08:14:31.923855 2026] [security2:error] [pid 402041:tid 402200] [client 74.249.245.134:15375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/wp.php"] [unique_id "al9Ul4iENNLP6XjiHQtb5QAAAao"]
[Tue Jul 21 08:14:31.991253 2026] [security2:error] [pid 402041:tid 402226] [client 74.7.175.187:44348] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.cinspeluz.com.br"] [uri "/index.php"] [unique_id "al9Ul4iENNLP6XjiHQtb4gABxAc"]
[Tue Jul 21 08:14:32.014195 2026] [security2:error] [pid 402041:tid 402144] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UmIiENNLP6XjiHQtb7AAB4WQ"]
[Tue Jul 21 08:14:32.014318 2026] [security2:error] [pid 402041:tid 402255] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UmIiENNLP6XjiHQtb7AAB4WQ"]
[Tue Jul 21 08:14:32.320172 2026] [security2:error] [pid 402041:tid 402246] [client 20.151.10.161:51134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/coffexium.php"] [unique_id "al9UmIiENNLP6XjiHQtb7wAAAdg"]
[Tue Jul 21 08:14:32.604352 2026] [security2:error] [pid 402041:tid 402187] [client 117.210.135.0:51879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UmIiENNLP6XjiHQtb-wAAAZ0"]
[Tue Jul 21 08:14:32.605106 2026] [security2:error] [pid 402041:tid 402187] [client 117.210.135.0:51879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UmIiENNLP6XjiHQtb-wAAAZ0"]
[Tue Jul 21 08:14:32.624765 2026] [security2:error] [pid 402041:tid 402229] [client 91.148.244.131:43016] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9UmIiENNLP6XjiHQtb_AAAAcc"]
[Tue Jul 21 08:14:32.625848 2026] [security2:error] [pid 402041:tid 402210] [client 91.148.244.131:42976] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/secrets.json"] [unique_id "al9UmIiENNLP6XjiHQtb_QAAAbQ"]
[Tue Jul 21 08:14:32.625896 2026] [security2:error] [pid 402041:tid 402288] [client 91.148.244.131:43002] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/.npmrc"] [unique_id "al9UmIiENNLP6XjiHQtb_gAAAgI"]
[Tue Jul 21 08:14:32.647799 2026] [security2:error] [pid 402041:tid 402251] [client 91.148.244.131:42964] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/.bash_history"] [unique_id "al9UmIiENNLP6XjiHQtb_wAAAd0"]
[Tue Jul 21 08:14:32.771888 2026] [security2:error] [pid 402041:tid 402192] [client 4.194.24.143:13787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/as.php"] [unique_id "al9UmIiENNLP6XjiHQtcAgAAAaI"]
[Tue Jul 21 08:14:32.826082 2026] [security2:error] [pid 402041:tid 402173] [client 91.148.244.131:42990] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/dump.sql"] [unique_id "al9UmIiENNLP6XjiHQtcAwAAAY8"]
[Tue Jul 21 08:14:33.027045 2026] [security2:error] [pid 402041:tid 402205] [client 20.220.225.223:30867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/berlin.php"] [unique_id "al9UmYiENNLP6XjiHQtcEwAAAa8"]
[Tue Jul 21 08:14:33.122704 2026] [security2:error] [pid 402041:tid 402238] [client 61.1.167.83:52905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UmYiENNLP6XjiHQtcFQAAAdA"]
[Tue Jul 21 08:14:33.122824 2026] [security2:error] [pid 402041:tid 402238] [client 61.1.167.83:52905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UmYiENNLP6XjiHQtcFQAAAdA"]
[Tue Jul 21 08:14:33.504465 2026] [security2:error] [pid 402041:tid 402296] [client 20.226.60.151:48787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/info.php"] [unique_id "al9UmYiENNLP6XjiHQtcIwAAAgo"]
[Tue Jul 21 08:14:33.597012 2026] [security2:error] [pid 402041:tid 402226] [client 91.148.244.131:54058] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/wp-config.php"] [unique_id "al9UmYiENNLP6XjiHQtcJwAAAcQ"]
[Tue Jul 21 08:14:33.599781 2026] [security2:error] [pid 402041:tid 402292] [client 91.148.244.131:54050] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/database.sql"] [unique_id "al9UmYiENNLP6XjiHQtcKwAAAgY"]
[Tue Jul 21 08:14:33.599781 2026] [security2:error] [pid 402041:tid 402191] [client 91.148.244.131:54048] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/database_backup.sql"] [unique_id "al9UmYiENNLP6XjiHQtcKQAAAaE"]
[Tue Jul 21 08:14:33.599872 2026] [security2:error] [pid 402041:tid 402284] [client 91.148.244.131:54094] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/backup.sql"] [unique_id "al9UmYiENNLP6XjiHQtcKgAAAf4"]
[Tue Jul 21 08:14:33.637755 2026] [security2:error] [pid 402041:tid 402203] [client 20.151.10.161:36568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/red.php"] [unique_id "al9UmYiENNLP6XjiHQtcLQAAAa0"]
[Tue Jul 21 08:14:33.664767 2026] [security2:error] [pid 402041:tid 402174] [client 20.104.96.117:54670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/yawa.php"] [unique_id "al9UmYiENNLP6XjiHQtcLgAAAZA"]
[Tue Jul 21 08:14:33.753228 2026] [security2:error] [pid 402041:tid 402258] [client 20.220.225.223:58427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/billur.php"] [unique_id "al9UmYiENNLP6XjiHQtcMQAAAeQ"]
[Tue Jul 21 08:14:33.754068 2026] [security2:error] [pid 402041:tid 402289] [client 103.151.46.103:59206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UmYiENNLP6XjiHQtcMAAAAgM"]
[Tue Jul 21 08:14:33.754212 2026] [security2:error] [pid 402041:tid 402289] [client 103.151.46.103:59206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UmYiENNLP6XjiHQtcMAAAAgM"]
[Tue Jul 21 08:14:33.802229 2026] [security2:error] [pid 402041:tid 402255] [client 91.148.244.131:54096] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/actuator/heapdump"] [unique_id "al9UmYiENNLP6XjiHQtcMgAAAeE"]
[Tue Jul 21 08:14:33.802229 2026] [security2:error] [pid 402041:tid 402208] [client 91.148.244.131:54086] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/backup.zip"] [unique_id "al9UmYiENNLP6XjiHQtcMwAAAbI"]
[Tue Jul 21 08:14:33.815209 2026] [security2:error] [pid 402041:tid 402254] [client 20.104.96.117:62531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/ccc.php"] [unique_id "al9UmYiENNLP6XjiHQtcNAAAAeA"]
[Tue Jul 21 08:14:33.826180 2026] [security2:error] [pid 402041:tid 402216] [client 4.194.24.143:13313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/asd.php"] [unique_id "al9UmYiENNLP6XjiHQtcNQAAAbo"]
[Tue Jul 21 08:14:33.886350 2026] [security2:error] [pid 402041:tid 402054] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UmYiENNLP6XjiHQtcOgABnwo"]
[Tue Jul 21 08:14:33.886485 2026] [security2:error] [pid 402041:tid 402189] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UmYiENNLP6XjiHQtcOgABnwo"]
[Tue Jul 21 08:14:33.987069 2026] [core:alert] [pid 402041:tid 402220] [client 57.141.18.124:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:14:34.044408 2026] [security2:error] [pid 402041:tid 402224] [client 20.197.192.193:57850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/track.php"] [unique_id "al9UmoiENNLP6XjiHQtcRwAAAcI"]
[Tue Jul 21 08:14:34.390338 2026] [security2:error] [pid 402041:tid 402253] [client 91.148.244.131:54124] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9UmoiENNLP6XjiHQtcVQAAAd8"]
[Tue Jul 21 08:14:34.391414 2026] [security2:error] [pid 402041:tid 402177] [client 91.148.244.131:54108] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/.svn/wc.db"] [unique_id "al9UmoiENNLP6XjiHQtcVgAAAZM"]
[Tue Jul 21 08:14:34.584911 2026] [security2:error] [pid 402041:tid 402160] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UmoiENNLP6XjiHQtcZAABuHQ"]
[Tue Jul 21 08:14:34.585068 2026] [security2:error] [pid 402041:tid 402214] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UmoiENNLP6XjiHQtcZAABuHQ"]
[Tue Jul 21 08:14:34.724408 2026] [security2:error] [pid 402041:tid 402189] [client 74.249.245.134:15159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/new.php"] [unique_id "al9UmoiENNLP6XjiHQtcZwAAAZ8"]
[Tue Jul 21 08:14:34.776270 2026] [security2:error] [pid 402041:tid 402258] [client 91.148.244.131:54136] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9UmoiENNLP6XjiHQtcaAAAAeQ"]
[Tue Jul 21 08:14:34.780698 2026] [security2:error] [pid 402041:tid 402289] [client 91.148.244.131:54148] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9UmoiENNLP6XjiHQtcaQAAAgM"]
[Tue Jul 21 08:14:34.889909 2026] [security2:error] [pid 402041:tid 402203] [client 4.194.24.143:52273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/assets/class-wp-http-client.php"] [unique_id "al9UmoiENNLP6XjiHQtcbQAAAa0"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 08:14:35.158323 2026] [security2:error] [pid 402041:tid 402281] [client 38.100.221.102:17734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Um4iENNLP6XjiHQtcewAAAfs"]
[Tue Jul 21 08:14:35.158491 2026] [security2:error] [pid 402041:tid 402281] [client 38.100.221.102:17734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Um4iENNLP6XjiHQtcewAAAfs"]
[Tue Jul 21 08:14:35.160866 2026] [security2:error] [pid 402041:tid 402275] [client 20.151.10.161:36602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9Um4iENNLP6XjiHQtcfAAAAfU"]
[Tue Jul 21 08:14:35.360971 2026] [security2:error] [pid 402041:tid 402290] [client 91.148.244.131:54172] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/backup.tar.gz"] [unique_id "al9Um4iENNLP6XjiHQtcgAAAAgQ"]
[Tue Jul 21 08:14:35.361882 2026] [security2:error] [pid 402041:tid 402235] [client 91.148.244.131:54170] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9Um4iENNLP6XjiHQtcgQAAAc0"]
[Tue Jul 21 08:14:35.415908 2026] [security2:error] [pid 402041:tid 402179] [client 20.104.96.117:54114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/js.php"] [unique_id "al9Um4iENNLP6XjiHQtchAAAAZU"]
[Tue Jul 21 08:14:35.451034 2026] [security2:error] [pid 402041:tid 402238] [client 103.78.200.11:54398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Um4iENNLP6XjiHQtchgAAAdA"]
[Tue Jul 21 08:14:35.451406 2026] [security2:error] [pid 402041:tid 402238] [client 103.78.200.11:54398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Um4iENNLP6XjiHQtchgAAAdA"]
[Tue Jul 21 08:14:35.484875 2026] [security2:error] [pid 402041:tid 402110] [remote 57.141.18.89:43508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9Um4iENNLP6XjiHQtchwABmkI"]
[Tue Jul 21 08:14:35.751156 2026] [security2:error] [pid 402041:tid 402248] [client 91.148.244.131:54212] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "perfex.bavos.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9Um4iENNLP6XjiHQtclAAAAdo"]
[Tue Jul 21 08:14:35.943952 2026] [security2:error] [pid 402041:tid 402257] [client 4.194.24.143:13621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/atomlib.php"] [unique_id "al9Um4iENNLP6XjiHQtcmQAAAeM"]
[Tue Jul 21 08:14:35.945017 2026] [security2:error] [pid 402041:tid 402250] [client 62.102.148.158:51874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Um4iENNLP6XjiHQtcmgAAAdw"]
[Tue Jul 21 08:14:35.945130 2026] [security2:error] [pid 402041:tid 402250] [client 62.102.148.158:51874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Um4iENNLP6XjiHQtcmgAAAdw"]
[Tue Jul 21 08:14:35.945409 2026] [security2:error] [pid 402041:tid 402206] [client 62.102.148.158:51864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Um4iENNLP6XjiHQtcmwAAAbA"]
[Tue Jul 21 08:14:35.945475 2026] [security2:error] [pid 402041:tid 402206] [client 62.102.148.158:51864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Um4iENNLP6XjiHQtcmwAAAbA"]
[Tue Jul 21 08:14:36.104060 2026] [security2:error] [pid 402041:tid 402296] [client 87.116.180.198:13925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UnIiENNLP6XjiHQtcoAAAAgo"]
[Tue Jul 21 08:14:36.108634 2026] [security2:error] [pid 402041:tid 402296] [client 87.116.180.198:13925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UnIiENNLP6XjiHQtcoAAAAgo"]
[Tue Jul 21 08:14:36.291636 2026] [security2:error] [pid 402041:tid 402268] [client 20.104.96.117:62558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/777.php"] [unique_id "al9UnIiENNLP6XjiHQtcpwAAAe4"]
[Tue Jul 21 08:14:36.348326 2026] [security2:error] [pid 402041:tid 402244] [client 154.208.47.43:49322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UnIiENNLP6XjiHQtcqQAAAdY"]
[Tue Jul 21 08:14:36.348454 2026] [security2:error] [pid 402041:tid 402244] [client 154.208.47.43:49322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UnIiENNLP6XjiHQtcqQAAAdY"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 08:14:36.825398 2026] [security2:error] [pid 402041:tid 402191] [client 20.151.10.161:36580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/footer.php"] [unique_id "al9UnIiENNLP6XjiHQtcvwAAAaE"]
[Tue Jul 21 08:14:36.854913 2026] [security2:error] [pid 402041:tid 402137] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UnIiENNLP6XjiHQtcwgAB_l0"]
[Tue Jul 21 08:14:36.855160 2026] [security2:error] [pid 402041:tid 402284] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UnIiENNLP6XjiHQtcwgAB_l0"]
[Tue Jul 21 08:14:37.017676 2026] [security2:error] [pid 402041:tid 402179] [client 4.194.24.143:13584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/autoload_classmap.php"] [unique_id "al9UnYiENNLP6XjiHQtcxAAAAZU"]
[Tue Jul 21 08:14:37.395637 2026] [security2:error] [pid 402041:tid 402118] [remote 207.180.241.245:49768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nocaminhodafe.com.br"] [uri "/wp-login.php"] [unique_id "al9UnYiENNLP6XjiHQtc0QABmUo"]
[Tue Jul 21 08:14:37.396597 2026] [security2:error] [pid 402041:tid 402204] [client 20.104.96.117:63068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/core.php"] [unique_id "al9UnYiENNLP6XjiHQtc0gAAAa4"]
[Tue Jul 21 08:14:37.481736 2026] [security2:error] [pid 402041:tid 402259] [client 20.220.225.223:30863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/mimpi.php"] [unique_id "al9UnYiENNLP6XjiHQtc1QAAAeU"]
[Tue Jul 21 08:14:37.509538 2026] [security2:error] [pid 402041:tid 402211] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UnYiENNLP6XjiHQtc1AABtQ8"]
[Tue Jul 21 08:14:37.613846 2026] [security2:error] [pid 402041:tid 402064] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UnYiENNLP6XjiHQtc2gAB4hQ"]
[Tue Jul 21 08:14:37.613982 2026] [security2:error] [pid 402041:tid 402256] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UnYiENNLP6XjiHQtc2gAB4hQ"]
[Tue Jul 21 08:14:37.709742 2026] [security2:error] [pid 402041:tid 402208] [client 102.206.115.33:59552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UnYiENNLP6XjiHQtc3gAAAbI"]
[Tue Jul 21 08:14:37.709879 2026] [security2:error] [pid 402041:tid 402208] [client 102.206.115.33:59552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UnYiENNLP6XjiHQtc3gAAAbI"]
[Tue Jul 21 08:14:37.946579 2026] [autoindex:error] [pid 402041:tid 402087] [remote 162.241.63.68:0] AH01276: Cannot serve directory /home2/anap6468/falarmelhor.com.br/indexing-test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:14:38.033224 2026] [security2:error] [pid 402041:tid 402230] [client 74.249.245.134:15117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/class-t.api.php"] [unique_id "al9UnoiENNLP6XjiHQtc6gAAAcg"]
[Tue Jul 21 08:14:38.048271 2026] [security2:error] [pid 402041:tid 402212] [client 4.194.24.143:13806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/av.php"] [unique_id "al9UnoiENNLP6XjiHQtc6wAAAbY"]
[Tue Jul 21 08:14:38.067719 2026] [security2:error] [pid 402041:tid 402262] [client 54.37.118.95:39628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "solucaomodular.com.br"] [uri "/robots.txt"] [unique_id "al9UnoiENNLP6XjiHQtc7AAAAeg"]
[Tue Jul 21 08:14:38.067806 2026] [security2:error] [pid 402041:tid 402262] [client 54.37.118.95:39628] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "solucaomodular.com.br"] [uri "/robots.txt"] [unique_id "al9UnoiENNLP6XjiHQtc7AAAAeg"]
[Tue Jul 21 08:14:38.085175 2026] [authz_core:error] [pid 402041:tid 402125] [remote 162.241.63.68:0] AH01630: client denied by server configuration: /home2/anap6468/falarmelhor.com.br/wp-content/uploads/code-execution.php
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 08:14:38.691023 2026] [security2:error] [pid 402041:tid 402252] [client 20.151.10.161:51080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-content/index.php"] [unique_id "al9UnoiENNLP6XjiHQtdAQAAAd4"]
[Tue Jul 21 08:14:38.831373 2026] [security2:error] [pid 402041:tid 402280] [client 198.54.129.60:52808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9UnoiENNLP6XjiHQtdBgAAAfo"]
[Tue Jul 21 08:14:38.831438 2026] [security2:error] [pid 402041:tid 402280] [client 198.54.129.60:52808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9UnoiENNLP6XjiHQtdBgAAAfo"]
[Tue Jul 21 08:14:39.073617 2026] [security2:error] [pid 402041:tid 402220] [client 4.194.24.143:21192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/b.php"] [unique_id "al9Un4iENNLP6XjiHQtdDgAAAb4"]
[Tue Jul 21 08:14:39.221832 2026] [security2:error] [pid 402041:tid 402209] [client 20.151.10.161:51131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/zoro.php"] [unique_id "al9Un4iENNLP6XjiHQtdEgAAAbM"]
[Tue Jul 21 08:14:39.232144 2026] [security2:error] [pid 402041:tid 402196] [client 20.220.225.223:30889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/dp.php"] [unique_id "al9Un4iENNLP6XjiHQtdEwAAAaY"]
[Tue Jul 21 08:14:39.435680 2026] [security2:error] [pid 402041:tid 402234] [client 20.197.192.193:3174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/2352356666.php"] [unique_id "al9Un4iENNLP6XjiHQtdGgAAAcw"]
[Tue Jul 21 08:14:39.456318 2026] [security2:error] [pid 402041:tid 402253] [client 187.125.243.197:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Un4iENNLP6XjiHQtdGwAAAd8"]
[Tue Jul 21 08:14:39.456407 2026] [security2:error] [pid 402041:tid 402253] [client 187.125.243.197:62789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Un4iENNLP6XjiHQtdGwAAAd8"]
[Tue Jul 21 08:14:39.486609 2026] [security2:error] [pid 402041:tid 402231] [client 111.93.58.162:64668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Un4iENNLP6XjiHQtdHAAAAck"]
[Tue Jul 21 08:14:39.486700 2026] [security2:error] [pid 402041:tid 402231] [client 111.93.58.162:64668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Un4iENNLP6XjiHQtdHAAAAck"]
[Tue Jul 21 08:14:39.502918 2026] [security2:error] [pid 402041:tid 402261] [client 51.222.168.81:55886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "solucaomodular.com.br"] [uri "/"] [unique_id "al9Un4iENNLP6XjiHQtdHQAAAec"]
[Tue Jul 21 08:14:39.502994 2026] [security2:error] [pid 402041:tid 402261] [client 51.222.168.81:55886] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "solucaomodular.com.br"] [uri "/"] [unique_id "al9Un4iENNLP6XjiHQtdHQAAAec"]
[Tue Jul 21 08:14:39.767978 2026] [security2:error] [pid 402041:tid 402146] [remote 154.61.75.100:54090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Un4iENNLP6XjiHQtdJQACDWY"]
[Tue Jul 21 08:14:40.005112 2026] [security2:error] [pid 402041:tid 402259] [client 20.151.10.161:36607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/admin.php"] [unique_id "al9UoIiENNLP6XjiHQtdLwAAAeU"]
[Tue Jul 21 08:14:40.028522 2026] [security2:error] [pid 402041:tid 402067] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UoIiENNLP6XjiHQtdMAAB3hc"]
[Tue Jul 21 08:14:40.028712 2026] [security2:error] [pid 402041:tid 402252] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UoIiENNLP6XjiHQtdMAAB3hc"]
[Tue Jul 21 08:14:40.107402 2026] [security2:error] [pid 402041:tid 402271] [client 4.194.24.143:13781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/backup.php"] [unique_id "al9UoIiENNLP6XjiHQtdMQAAAfE"]
[Tue Jul 21 08:14:40.217710 2026] [security2:error] [pid 402041:tid 402300] [client 115.134.11.136:52243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UoIiENNLP6XjiHQtdOAAAAg4"]
[Tue Jul 21 08:14:40.492111 2026] [security2:error] [pid 402041:tid 402192] [client 20.104.96.117:63088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/19.php"] [unique_id "al9UoIiENNLP6XjiHQtddQAAAaI"]
[Tue Jul 21 08:14:40.544094 2026] [security2:error] [pid 402041:tid 402072] [remote 97.74.87.194:55788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "murilomattos.com"] [uri "/wp-login.php"] [unique_id "al9UoIiENNLP6XjiHQtdgQAB4xw"]
[Tue Jul 21 08:14:40.659073 2026] [security2:error] [pid 402041:tid 402212] [client 62.102.148.158:40740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9UoIiENNLP6XjiHQtdlgAAAbY"]
[Tue Jul 21 08:14:40.659167 2026] [security2:error] [pid 402041:tid 402212] [client 62.102.148.158:40740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9UoIiENNLP6XjiHQtdlgAAAbY"]
[Tue Jul 21 08:14:40.732121 2026] [security2:error] [pid 402041:tid 402223] [client 20.151.10.161:51085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/greap.php"] [unique_id "al9UoIiENNLP6XjiHQtdxQAAAcE"]
[Tue Jul 21 08:14:40.808470 2026] [security2:error] [pid 402041:tid 402051] [remote 68.178.160.25:47642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9UoIiENNLP6XjiHQtdzAABlQc"]
[Tue Jul 21 08:14:40.954236 2026] [security2:error] [pid 402041:tid 402256] [client 20.226.60.151:48778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/11.php"] [unique_id "al9UoIiENNLP6XjiHQtd6AAAAeI"]
[Tue Jul 21 08:14:41.161894 2026] [security2:error] [pid 402041:tid 402242] [client 4.194.24.143:13799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/baio/class-wp-http-client.php"] [unique_id "al9UoYiENNLP6XjiHQteAgAAAdQ"]
[Tue Jul 21 08:14:41.308148 2026] [security2:error] [pid 402041:tid 402239] [client 20.151.10.161:51122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/177.php"] [unique_id "al9UoYiENNLP6XjiHQteIAAAAdE"]
[Tue Jul 21 08:14:41.321266 2026] [security2:error] [pid 402041:tid 402236] [client 20.220.225.223:30895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/bootstrap.php"] [unique_id "al9UoYiENNLP6XjiHQteJgAAAc4"]
[Tue Jul 21 08:14:41.511580 2026] [security2:error] [pid 402041:tid 402225] [client 120.56.162.40:62188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UoYiENNLP6XjiHQteTAAAAcM"]
[Tue Jul 21 08:14:41.511705 2026] [security2:error] [pid 402041:tid 402225] [client 120.56.162.40:62188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UoYiENNLP6XjiHQteTAAAAcM"]
[Tue Jul 21 08:14:41.690792 2026] [security2:error] [pid 402041:tid 402230] [client 20.151.10.161:36480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/199.php"] [unique_id "al9UoYiENNLP6XjiHQtebQAAAcg"]
[Tue Jul 21 08:14:41.730309 2026] [security2:error] [pid 402041:tid 402278] [client 150.129.202.39:65129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UoYiENNLP6XjiHQtecAAAAfg"]
[Tue Jul 21 08:14:41.730417 2026] [security2:error] [pid 402041:tid 402278] [client 150.129.202.39:65129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UoYiENNLP6XjiHQtecAAAAfg"]
[Tue Jul 21 08:14:41.959249 2026] [security2:error] [pid 402041:tid 402179] [client 65.21.113.253:34674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UoYiENNLP6XjiHQteSgAAAZU"]
[Tue Jul 21 08:14:42.047457 2026] [security2:error] [pid 402041:tid 402226] [client 20.151.10.161:36552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/file52.php"] [unique_id "al9UooiENNLP6XjiHQtejQAAAcQ"]
[Tue Jul 21 08:14:42.223089 2026] [security2:error] [pid 402041:tid 402244] [client 4.194.24.143:52278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/bak.php"] [unique_id "al9UooiENNLP6XjiHQteowAAAdY"]
[Tue Jul 21 08:14:42.406387 2026] [security2:error] [pid 402041:tid 402282] [client 20.151.10.161:51118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/122.php"] [unique_id "al9UooiENNLP6XjiHQtesQAAAfw"]
[Tue Jul 21 08:14:42.538211 2026] [security2:error] [pid 402041:tid 402157] [remote 129.212.177.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.177.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UooiENNLP6XjiHQtezwAB9HE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:14:42.588308 2026] [security2:error] [pid 402041:tid 402247] [client 20.104.96.117:63443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/for.php"] [unique_id "al9UooiENNLP6XjiHQte0gAAAdk"]
[Tue Jul 21 08:14:42.642350 2026] [security2:error] [pid 402041:tid 402131] [remote 129.212.177.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.177.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UooiENNLP6XjiHQtewgACCVc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:14:42.642442 2026] [security2:error] [pid 402041:tid 402100] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UooiENNLP6XjiHQte1wAB2zg"]
[Tue Jul 21 08:14:42.642555 2026] [security2:error] [pid 402041:tid 402249] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UooiENNLP6XjiHQte1wAB2zg"]
[Tue Jul 21 08:14:42.707021 2026] [security2:error] [pid 402041:tid 402121] [remote 129.212.177.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.177.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UooiENNLP6XjiHQte5AABnU0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:14:42.714397 2026] [security2:error] [pid 402041:tid 402208] [client 20.151.10.161:36487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/green1.php"] [unique_id "al9UooiENNLP6XjiHQte5wAAAbI"]
[Tue Jul 21 08:14:42.815226 2026] [autoindex:error] [pid 402041:tid 402188] [client 43.153.67.21:35634] AH01276: Cannot serve directory /home2/inlaud99/kenyetuquinha.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:14:42.837050 2026] [security2:error] [pid 402041:tid 402163] [remote 129.212.177.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.177.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UooiENNLP6XjiHQte-QAByHc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:14:42.872631 2026] [security2:error] [pid 402041:tid 402165] [remote 129.212.177.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.177.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UooiENNLP6XjiHQte_QABnXk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:14:42.990592 2026] [security2:error] [pid 402041:tid 402044] [remote 129.212.177.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.177.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UooiENNLP6XjiHQtfAwABvwA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:14:43.040250 2026] [security2:error] [pid 402041:tid 402102] [remote 129.212.177.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.177.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Uo4iENNLP6XjiHQtfCQABnTo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:14:43.082801 2026] [security2:error] [pid 402041:tid 402291] [client 20.151.10.161:36569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/biufile.php"] [unique_id "al9Uo4iENNLP6XjiHQtfCwAAAgU"]
[Tue Jul 21 08:14:43.142392 2026] [security2:error] [pid 402041:tid 402265] [client 117.210.135.0:52532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uo4iENNLP6XjiHQtfDQAAAes"]
[Tue Jul 21 08:14:43.142924 2026] [security2:error] [pid 402041:tid 402265] [client 117.210.135.0:52532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uo4iENNLP6XjiHQtfDQAAAes"]
[Tue Jul 21 08:14:43.147989 2026] [security2:error] [pid 402041:tid 402169] [remote 129.212.177.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.177.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Uo4iENNLP6XjiHQtfDgABkH0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:14:43.217516 2026] [security2:error] [pid 402041:tid 402147] [remote 129.212.177.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.177.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Uo4iENNLP6XjiHQtfEQABnWc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:14:43.247177 2026] [security2:error] [pid 402041:tid 402216] [client 4.194.24.143:13569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/bdkr28wp.php"] [unique_id "al9Uo4iENNLP6XjiHQtfFAAAAbo"]
[Tue Jul 21 08:14:43.412192 2026] [security2:error] [pid 402041:tid 402185] [client 74.249.245.134:15162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/plugins.php"] [unique_id "al9Uo4iENNLP6XjiHQtfGQAAAZs"]
[Tue Jul 21 08:14:43.460798 2026] [security2:error] [pid 402041:tid 402269] [client 45.77.127.195:49418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "solucoesdeti.com.br"] [uri "/.env"] [unique_id "al9Uo4iENNLP6XjiHQtfHQAAAe8"]
[Tue Jul 21 08:14:43.477619 2026] [security2:error] [pid 402041:tid 402173] [client 45.77.127.195:49410] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "solucoesdeti.com"] [uri "/.env"] [unique_id "al9Uo4iENNLP6XjiHQtfHgAAAY8"]
[Tue Jul 21 08:14:43.509144 2026] [security2:error] [pid 402041:tid 402109] [remote 129.212.177.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.177.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UooiENNLP6XjiHQteyQABnUE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:14:43.512372 2026] [security2:error] [pid 402041:tid 402112] [remote 129.212.177.110:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.177.212.129.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9UooiENNLP6XjiHQteywAB9UQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:14:43.627215 2026] [security2:error] [pid 402041:tid 402294] [client 20.151.10.161:51133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wpconf.php"] [unique_id "al9Uo4iENNLP6XjiHQtfKgAAAgg"]
[Tue Jul 21 08:14:44.000838 2026] [security2:error] [pid 402041:tid 402179] [client 20.104.96.117:63054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/inc.php"] [unique_id "al9Uo4iENNLP6XjiHQtfQQAAAZU"]
[Tue Jul 21 08:14:44.118327 2026] [security2:error] [pid 402041:tid 402213] [client 20.151.10.161:36499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/mosty.php"] [unique_id "al9UpIiENNLP6XjiHQtfSAAAAbc"]
[Tue Jul 21 08:14:44.257580 2026] [security2:error] [pid 402041:tid 402186] [client 45.77.127.195:49424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "solucoesdeti.com"] [uri "/.env"] [unique_id "al9UpIiENNLP6XjiHQtfVAAAAZw"]
[Tue Jul 21 08:14:44.328555 2026] [security2:error] [pid 402041:tid 402215] [client 4.194.24.143:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/bgymj.php"] [unique_id "al9UpIiENNLP6XjiHQtfWQAAAbk"]
[Tue Jul 21 08:14:44.341782 2026] [security2:error] [pid 402041:tid 402115] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UpIiENNLP6XjiHQtfWwAB20c"]
[Tue Jul 21 08:14:44.342018 2026] [security2:error] [pid 402041:tid 402249] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UpIiENNLP6XjiHQtfWwAB20c"]
[Tue Jul 21 08:14:44.431618 2026] [security2:error] [pid 402041:tid 402203] [client 20.151.10.161:51090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/dejavu.php"] [unique_id "al9UpIiENNLP6XjiHQtfZAAAAa0"]
[Tue Jul 21 08:14:44.943311 2026] [security2:error] [pid 402041:tid 402261] [client 45.77.127.195:49442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "solucoesdeti.com"] [uri "/conf/.env"] [unique_id "al9UpIiENNLP6XjiHQtfgQAAAec"]
[Tue Jul 21 08:14:44.992201 2026] [security2:error] [pid 402041:tid 402184] [client 20.151.10.161:36544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/aaf.php"] [unique_id "al9UpIiENNLP6XjiHQtfjgAAAZo"]
[Tue Jul 21 08:14:45.219471 2026] [security2:error] [pid 402041:tid 402101] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UpYiENNLP6XjiHQtfqQAB6Tk"]
[Tue Jul 21 08:14:45.219667 2026] [security2:error] [pid 402041:tid 402263] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UpYiENNLP6XjiHQtfqQAB6Tk"]
[Tue Jul 21 08:14:45.373020 2026] [security2:error] [pid 402041:tid 402176] [client 20.151.10.161:36594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/term.php"] [unique_id "al9UpYiENNLP6XjiHQtfuAAAAZI"]
[Tue Jul 21 08:14:45.391400 2026] [security2:error] [pid 402041:tid 402227] [client 4.194.24.143:21230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/biufile.php"] [unique_id "al9UpYiENNLP6XjiHQtfugAAAcU"]
[Tue Jul 21 08:14:45.654015 2026] [security2:error] [pid 402041:tid 402211] [client 20.197.192.193:63747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/pn.php"] [unique_id "al9UpYiENNLP6XjiHQtfygAAAbU"]
[Tue Jul 21 08:14:45.735210 2026] [security2:error] [pid 402041:tid 402214] [client 103.76.88.37:60029] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bahinternet.com.br.ciclododinheiro.com"] [uri "/.env"] [unique_id "al9UpYiENNLP6XjiHQtfzQAAAbg"]
[Tue Jul 21 08:14:45.787881 2026] [security2:error] [pid 402041:tid 402262] [client 38.100.221.102:17302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UpYiENNLP6XjiHQtfzwAAAeg"]
[Tue Jul 21 08:14:45.787995 2026] [security2:error] [pid 402041:tid 402262] [client 38.100.221.102:17302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UpYiENNLP6XjiHQtfzwAAAeg"]
[Tue Jul 21 08:14:45.856732 2026] [security2:error] [pid 402041:tid 402229] [client 20.151.10.161:51124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/ha.php"] [unique_id "al9UpYiENNLP6XjiHQtf0QAAAcc"]
[Tue Jul 21 08:14:45.978197 2026] [security2:error] [pid 402041:tid 402265] [client 20.220.225.223:30662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/wp-editor.php"] [unique_id "al9UpYiENNLP6XjiHQtf0wAAAes"]
[Tue Jul 21 08:14:46.070957 2026] [security2:error] [pid 402041:tid 402206] [client 103.78.200.11:54887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UpoiENNLP6XjiHQtf3gAAAbA"]
[Tue Jul 21 08:14:46.071067 2026] [security2:error] [pid 402041:tid 402206] [client 103.78.200.11:54887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UpoiENNLP6XjiHQtf3gAAAbA"]
[Tue Jul 21 08:14:46.211576 2026] [security2:error] [pid 402041:tid 402188] [client 74.249.245.134:15126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/jp.php"] [unique_id "al9UpoiENNLP6XjiHQtf6gAAAZ4"]
[Tue Jul 21 08:14:46.259162 2026] [security2:error] [pid 402041:tid 402226] [client 103.76.88.37:60127] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bahinternet.com.br"] [uri "/.env"] [unique_id "al9UpoiENNLP6XjiHQtf7AAAAcQ"]
[Tue Jul 21 08:14:46.311092 2026] [security2:error] [pid 402041:tid 402209] [client 20.151.10.161:51119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/hur.php"] [unique_id "al9UpoiENNLP6XjiHQtf7wAAAbM"]
[Tue Jul 21 08:14:46.441322 2026] [security2:error] [pid 402041:tid 402220] [client 4.194.24.143:22291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/bless.php"] [unique_id "al9UpoiENNLP6XjiHQtf8AAAAb4"]
[Tue Jul 21 08:14:46.600653 2026] [security2:error] [pid 402041:tid 402226] [client 20.104.96.117:62543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/ssla.php"] [unique_id "al9UpoiENNLP6XjiHQtf-AAAAcQ"]
[Tue Jul 21 08:14:46.844732 2026] [security2:error] [pid 402041:tid 402176] [client 87.116.180.198:27215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UpoiENNLP6XjiHQtf_wAAAZI"]
[Tue Jul 21 08:14:46.844876 2026] [security2:error] [pid 402041:tid 402176] [client 87.116.180.198:27215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UpoiENNLP6XjiHQtf_wAAAZI"]
[Tue Jul 21 08:14:46.884850 2026] [security2:error] [pid 402041:tid 402213] [client 20.151.10.161:36598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/h02ugyh.php"] [unique_id "al9UpoiENNLP6XjiHQtgAQAAAbc"]
[Tue Jul 21 08:14:46.937708 2026] [security2:error] [pid 402041:tid 402278] [client 154.208.47.43:55452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UpoiENNLP6XjiHQtgAwAAAfg"]
[Tue Jul 21 08:14:46.937876 2026] [security2:error] [pid 402041:tid 402242] [client 45.77.127.195:49450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "solucoesdeti.com"] [uri "/conf/.env"] [unique_id "al9UpoiENNLP6XjiHQtgAgAAAdQ"]
[Tue Jul 21 08:14:46.938086 2026] [security2:error] [pid 402041:tid 402278] [client 154.208.47.43:55452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UpoiENNLP6XjiHQtgAwAAAfg"]
[Tue Jul 21 08:14:47.024108 2026] [security2:error] [pid 402041:tid 402265] [client 20.226.60.151:48840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/v2.php"] [unique_id "al9Up4iENNLP6XjiHQtgBAAAAes"]
[Tue Jul 21 08:14:47.186021 2026] [security2:error] [pid 402041:tid 402223] [client 20.104.96.117:54137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9Up4iENNLP6XjiHQtgDgAAAcE"]
[Tue Jul 21 08:14:47.207146 2026] [security2:error] [pid 402041:tid 402208] [client 20.220.225.223:30717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/cro.php"] [unique_id "al9Up4iENNLP6XjiHQtgEAAAAbI"]
[Tue Jul 21 08:14:47.355525 2026] [security2:error] [pid 402041:tid 402263] [client 45.77.127.195:56002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "solucoesdeti.com"] [uri "/wp-content/.env"] [unique_id "al9Up4iENNLP6XjiHQtgEgAAAek"]
[Tue Jul 21 08:14:47.486272 2026] [security2:error] [pid 402041:tid 402222] [client 4.194.24.143:22397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/bolt.php"] [unique_id "al9Up4iENNLP6XjiHQtgFAAAAcA"]
[Tue Jul 21 08:14:47.646370 2026] [security2:error] [pid 402041:tid 402184] [client 20.151.10.161:36559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/seiso.php"] [unique_id "al9Up4iENNLP6XjiHQtgHwAAAZo"]
[Tue Jul 21 08:14:47.653538 2026] [security2:error] [pid 402041:tid 402231] [client 20.220.225.223:30693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/cron-tab.php"] [unique_id "al9Up4iENNLP6XjiHQtgIgAAAck"]
[Tue Jul 21 08:14:47.794799 2026] [security2:error] [pid 402041:tid 402124] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Up4iENNLP6XjiHQtgNAACBFA"]
[Tue Jul 21 08:14:47.794946 2026] [security2:error] [pid 402041:tid 402290] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Up4iENNLP6XjiHQtgNAACBFA"]
[Tue Jul 21 08:14:48.011262 2026] [security2:error] [pid 402041:tid 402270] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Up4iENNLP6XjiHQtgYAAB8DQ"]
[Tue Jul 21 08:14:48.187064 2026] [security2:error] [pid 402041:tid 402233] [client 86.106.84.166:48484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9UqIiENNLP6XjiHQtgkAAAAcs"]
[Tue Jul 21 08:14:48.187164 2026] [security2:error] [pid 402041:tid 402233] [client 86.106.84.166:48484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9UqIiENNLP6XjiHQtgkAAAAcs"]
[Tue Jul 21 08:14:48.297289 2026] [security2:error] [pid 402041:tid 402262] [client 102.206.115.33:60006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UqIiENNLP6XjiHQtglQAAAeg"]
[Tue Jul 21 08:14:48.297410 2026] [security2:error] [pid 402041:tid 402262] [client 102.206.115.33:60006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UqIiENNLP6XjiHQtglQAAAeg"]
[Tue Jul 21 08:14:48.303622 2026] [security2:error] [pid 402041:tid 402165] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UqIiENNLP6XjiHQtglgABwHk"]
[Tue Jul 21 08:14:48.303744 2026] [security2:error] [pid 402041:tid 402222] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UqIiENNLP6XjiHQtglgABwHk"]
[Tue Jul 21 08:14:48.399819 2026] [security2:error] [pid 402041:tid 402220] [client 86.106.84.166:43258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9UqIiENNLP6XjiHQtgpwAAAb4"]
[Tue Jul 21 08:14:48.401338 2026] [security2:error] [pid 402041:tid 402220] [client 86.106.84.166:43258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9UqIiENNLP6XjiHQtgpwAAAb4"]
[Tue Jul 21 08:14:48.402251 2026] [security2:error] [pid 402041:tid 402242] [client 20.151.10.161:36430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/155.php"] [unique_id "al9UqIiENNLP6XjiHQtgqAAAAdQ"]
[Tue Jul 21 08:14:48.488252 2026] [security2:error] [pid 402041:tid 402185] [client 20.104.96.117:62986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9UqIiENNLP6XjiHQtgrAAAAZs"]
[Tue Jul 21 08:14:48.545468 2026] [security2:error] [pid 402041:tid 402214] [client 4.194.24.143:21793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/bthil.php"] [unique_id "al9UqIiENNLP6XjiHQtgtAAAAbg"]
[Tue Jul 21 08:14:48.570649 2026] [security2:error] [pid 402041:tid 402103] [remote 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9UqIiENNLP6XjiHQtgtQACDDs"]
[Tue Jul 21 08:14:48.833241 2026] [security2:error] [pid 402041:tid 402237] [client 20.104.96.117:62470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.arielson.com.br"] [uri "/zc-131.php"] [unique_id "al9UqIiENNLP6XjiHQtgxwAAAc8"]
[Tue Jul 21 08:14:49.477744 2026] [security2:error] [pid 402041:tid 402260] [client 115.134.11.136:52630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UqYiENNLP6XjiHQtg4QAAAeY"]
[Tue Jul 21 08:14:49.617446 2026] [security2:error] [pid 402041:tid 402185] [client 20.151.10.161:36599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/ppp.php"] [unique_id "al9UqYiENNLP6XjiHQtg5AAAAZs"]
[Tue Jul 21 08:14:49.622324 2026] [security2:error] [pid 402041:tid 402199] [client 4.194.24.143:20814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/buy.php"] [unique_id "al9UqYiENNLP6XjiHQtg5QAAAak"]
[Tue Jul 21 08:14:49.857222 2026] [security2:error] [pid 402041:tid 402235] [client 20.197.192.193:63752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9UqYiENNLP6XjiHQtg8AAAAc0"]
[Tue Jul 21 08:14:49.949514 2026] [security2:error] [pid 402041:tid 402202] [client 187.125.243.197:63246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UqYiENNLP6XjiHQtg9wAAAaw"]
[Tue Jul 21 08:14:49.949877 2026] [security2:error] [pid 402041:tid 402202] [client 187.125.243.197:63246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UqYiENNLP6XjiHQtg9wAAAaw"]
[Tue Jul 21 08:14:49.954271 2026] [security2:error] [pid 402041:tid 402221] [client 74.249.245.134:15410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/error.php"] [unique_id "al9UqYiENNLP6XjiHQtg-AAAAb8"]
[Tue Jul 21 08:14:49.959025 2026] [security2:error] [pid 402041:tid 402245] [client 20.104.96.117:54128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/ss.php"] [unique_id "al9UqYiENNLP6XjiHQtg-QAAAdc"]
[Tue Jul 21 08:14:50.093341 2026] [security2:error] [pid 402041:tid 402175] [client 14.97.58.74:20790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UqoiENNLP6XjiHQtg_QAAAZE"]
[Tue Jul 21 08:14:50.093513 2026] [security2:error] [pid 402041:tid 402175] [client 14.97.58.74:20790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UqoiENNLP6XjiHQtg_QAAAZE"]
[Tue Jul 21 08:14:50.334546 2026] [security2:error] [pid 402041:tid 402183] [client 14.245.224.124:56762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9UqoiENNLP6XjiHQthAAAAAZk"]
[Tue Jul 21 08:14:50.334696 2026] [security2:error] [pid 402041:tid 402183] [client 14.245.224.124:56762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9UqoiENNLP6XjiHQthAAAAAZk"]
[Tue Jul 21 08:14:50.523462 2026] [security2:error] [pid 402041:tid 402188] [client 65.21.113.253:44832] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UqoiENNLP6XjiHQtg_AAAAZ4"]
[Tue Jul 21 08:14:50.529060 2026] [security2:error] [pid 402041:tid 402108] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UqoiENNLP6XjiHQthEQABrkA"]
[Tue Jul 21 08:14:50.529222 2026] [security2:error] [pid 402041:tid 402204] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UqoiENNLP6XjiHQthEQABrkA"]
[Tue Jul 21 08:14:50.650695 2026] [security2:error] [pid 402041:tid 402255] [client 4.194.24.143:21185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/byp.php"] [unique_id "al9UqoiENNLP6XjiHQthEwAAAeE"]
[Tue Jul 21 08:14:50.664854 2026] [security2:error] [pid 402041:tid 402288] [client 20.151.10.161:51081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/201.php"] [unique_id "al9UqoiENNLP6XjiHQthFAAAAgI"]
[Tue Jul 21 08:14:50.969475 2026] [security2:error] [pid 402041:tid 402233] [client 20.220.225.223:30683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/koiy.php"] [unique_id "al9UqoiENNLP6XjiHQthJQAAAcs"]
[Tue Jul 21 08:14:51.134436 2026] [security2:error] [pid 402041:tid 402291] [client 65.21.113.253:44846] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UqoiENNLP6XjiHQthFgAAAgU"]
[Tue Jul 21 08:14:51.342244 2026] [security2:error] [pid 402041:tid 402221] [client 20.151.10.161:36572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/ops.php"] [unique_id "al9Uq4iENNLP6XjiHQthLQAAAb8"]
[Tue Jul 21 08:14:51.700711 2026] [security2:error] [pid 402041:tid 402271] [client 4.194.24.143:13600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/bypass.php"] [unique_id "al9Uq4iENNLP6XjiHQthNwAAAfE"]
[Tue Jul 21 08:14:51.959167 2026] [security2:error] [pid 402041:tid 402279] [client 74.249.245.134:15123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Uq4iENNLP6XjiHQthRwAAAfk"]
[Tue Jul 21 08:14:52.113906 2026] [security2:error] [pid 402041:tid 402237] [client 120.56.162.40:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UrIiENNLP6XjiHQthUAAAAc8"]
[Tue Jul 21 08:14:52.114042 2026] [security2:error] [pid 402041:tid 402237] [client 120.56.162.40:62685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UrIiENNLP6XjiHQthUAAAAc8"]
[Tue Jul 21 08:14:52.352067 2026] [security2:error] [pid 402041:tid 402235] [client 20.151.10.161:36555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/ingfo.php"] [unique_id "al9UrIiENNLP6XjiHQthWgAAAc0"]
[Tue Jul 21 08:14:52.417136 2026] [security2:error] [pid 402041:tid 402223] [client 150.129.202.39:65255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UrIiENNLP6XjiHQthXgAAAcE"]
[Tue Jul 21 08:14:52.417211 2026] [security2:error] [pid 402041:tid 402223] [client 150.129.202.39:65255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UrIiENNLP6XjiHQthXgAAAcE"]
[Tue Jul 21 08:14:52.674149 2026] [security2:error] [pid 402041:tid 402256] [client 20.151.10.161:51088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/error_log.php"] [unique_id "al9UrIiENNLP6XjiHQthawAAAeI"]
[Tue Jul 21 08:14:52.720675 2026] [security2:error] [pid 402041:tid 402222] [client 20.220.225.223:30901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/hp2.php"] [unique_id "al9UrIiENNLP6XjiHQthbAAAAcA"]
[Tue Jul 21 08:14:52.740727 2026] [security2:error] [pid 402041:tid 402191] [client 4.194.24.143:20838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/cache.php"] [unique_id "al9UrIiENNLP6XjiHQthbQAAAaE"]
[Tue Jul 21 08:14:52.805705 2026] [security2:error] [pid 402041:tid 402254] [client 61.1.167.83:53460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UrIiENNLP6XjiHQthcwAAAeA"]
[Tue Jul 21 08:14:52.811546 2026] [security2:error] [pid 402041:tid 402254] [client 61.1.167.83:53460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UrIiENNLP6XjiHQthcwAAAeA"]
[Tue Jul 21 08:14:53.167738 2026] [security2:error] [pid 402041:tid 402253] [client 20.151.10.161:51127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/xenon1337.php"] [unique_id "al9UrYiENNLP6XjiHQthiwAAAd8"]
[Tue Jul 21 08:14:53.305415 2026] [security2:error] [pid 402041:tid 402153] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UrYiENNLP6XjiHQthjQABwm0"]
[Tue Jul 21 08:14:53.305589 2026] [security2:error] [pid 402041:tid 402224] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UrYiENNLP6XjiHQthjQABwm0"]
[Tue Jul 21 08:14:53.543647 2026] [security2:error] [pid 402041:tid 402256] [client 20.151.10.161:51113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/test11.php"] [unique_id "al9UrYiENNLP6XjiHQthmgAAAeI"]
[Tue Jul 21 08:14:53.632954 2026] [security2:error] [pid 402041:tid 402049] [remote 91.142.222.105:42960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "revistareflexopolitico.com.br"] [uri "/wp-login.php"] [unique_id "al9UrYiENNLP6XjiHQthnQAB9AU"]
[Tue Jul 21 08:14:53.737694 2026] [security2:error] [pid 402041:tid 402208] [client 117.210.135.0:53167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UrYiENNLP6XjiHQthpAAAAbI"]
[Tue Jul 21 08:14:53.737821 2026] [security2:error] [pid 402041:tid 402208] [client 117.210.135.0:53167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UrYiENNLP6XjiHQthpAAAAbI"]
[Tue Jul 21 08:14:53.775463 2026] [security2:error] [pid 402041:tid 402070] [remote 45.117.83.212:44798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9UrYiENNLP6XjiHQthpQAByxo"]
[Tue Jul 21 08:14:53.810805 2026] [security2:error] [pid 402041:tid 402173] [client 4.194.24.143:21789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/cc.php"] [unique_id "al9UrYiENNLP6XjiHQthpgAAAY8"]
[Tue Jul 21 08:14:53.824272 2026] [security2:error] [pid 402041:tid 402184] [client 20.151.10.161:36519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/koala.php"] [unique_id "al9UrYiENNLP6XjiHQthpwAAAZo"]
[Tue Jul 21 08:14:53.858406 2026] [security2:error] [pid 402041:tid 402198] [client 20.226.60.151:48868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/panel.php"] [unique_id "al9UrYiENNLP6XjiHQthqwAAAag"]
[Tue Jul 21 08:14:54.085909 2026] [security2:error] [pid 402041:tid 402246] [client 74.249.245.134:15121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/bless.php"] [unique_id "al9UroiENNLP6XjiHQthwQAAAdg"]
[Tue Jul 21 08:14:54.087428 2026] [security2:error] [pid 402041:tid 402281] [client 20.220.225.223:30666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/hp3.php"] [unique_id "al9UroiENNLP6XjiHQthwgAAAfs"]
[Tue Jul 21 08:14:54.437168 2026] [security2:error] [pid 402041:tid 402252] [client 20.151.10.161:36513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/mac.php"] [unique_id "al9UroiENNLP6XjiHQth3gAAAd4"]
[Tue Jul 21 08:14:54.481921 2026] [security2:error] [pid 402041:tid 402177] [client 20.104.96.117:54689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/min.php"] [unique_id "al9UroiENNLP6XjiHQth5AAAAZM"]
[Tue Jul 21 08:14:54.795748 2026] [security2:error] [pid 402041:tid 402291] [client 20.220.225.223:30660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/aa1.php"] [unique_id "al9UroiENNLP6XjiHQth7AAAAgU"]
[Tue Jul 21 08:14:54.825315 2026] [security2:error] [pid 402041:tid 402160] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UroiENNLP6XjiHQth7QABqXQ"]
[Tue Jul 21 08:14:54.825481 2026] [security2:error] [pid 402041:tid 402199] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UroiENNLP6XjiHQth7QABqXQ"]
[Tue Jul 21 08:14:54.827692 2026] [security2:error] [pid 402041:tid 402221] [client 86.106.84.166:41056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9UroiENNLP6XjiHQth7gAAAb8"]
[Tue Jul 21 08:14:54.827773 2026] [security2:error] [pid 402041:tid 402221] [client 86.106.84.166:41056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9UroiENNLP6XjiHQth7gAAAb8"]
[Tue Jul 21 08:14:54.840983 2026] [cgid:error] [pid 402041:tid 402285] [client 4.194.24.143:20822] AH01264: stderr from /home2/alanam00/public_html/cgi-bin: script not found or unable to stat
[Tue Jul 21 08:14:55.096166 2026] [security2:error] [pid 402041:tid 402254] [client 20.151.10.161:51110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9Ur4iENNLP6XjiHQth-gAAAeA"]
[Tue Jul 21 08:14:55.183150 2026] [security2:error] [pid 402041:tid 402286] [client 4.194.24.143:20822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9Ur4iENNLP6XjiHQth_gAAAgA"]
[Tue Jul 21 08:14:55.524249 2026] [security2:error] [pid 402041:tid 402103] [remote 207.180.241.245:39976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/wp-login.php"] [unique_id "al9Ur4iENNLP6XjiHQtiCQABjzs"]
[Tue Jul 21 08:14:55.530697 2026] [security2:error] [pid 402041:tid 402247] [client 20.151.10.161:36584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wefile.php"] [unique_id "al9Ur4iENNLP6XjiHQtiCwAAAdk"]
[Tue Jul 21 08:14:55.903049 2026] [security2:error] [pid 402041:tid 402148] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ur4iENNLP6XjiHQtiFAABn2g"]
[Tue Jul 21 08:14:55.903243 2026] [security2:error] [pid 402041:tid 402189] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ur4iENNLP6XjiHQtiFAABn2g"]
[Tue Jul 21 08:14:56.206470 2026] [security2:error] [pid 402041:tid 402263] [client 4.194.24.143:13314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/cgi-bin/class-wp-http-client.php"] [unique_id "al9UsIiENNLP6XjiHQtiHQAAAek"]
[Tue Jul 21 08:14:56.370369 2026] [security2:error] [pid 402041:tid 402206] [client 103.78.200.11:55362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UsIiENNLP6XjiHQtiHwAAAbA"]
[Tue Jul 21 08:14:56.370519 2026] [security2:error] [pid 402041:tid 402206] [client 103.78.200.11:55362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UsIiENNLP6XjiHQtiHwAAAbA"]
[Tue Jul 21 08:14:56.445583 2026] [security2:error] [pid 402041:tid 402181] [client 20.104.96.117:54671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9UsIiENNLP6XjiHQtiIAAAAZc"]
[Tue Jul 21 08:14:56.447477 2026] [security2:error] [pid 402041:tid 402279] [client 38.100.221.102:17769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UsIiENNLP6XjiHQtiIQAAAfk"]
[Tue Jul 21 08:14:56.447582 2026] [security2:error] [pid 402041:tid 402279] [client 38.100.221.102:17769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UsIiENNLP6XjiHQtiIQAAAfk"]
[Tue Jul 21 08:14:56.502790 2026] [security2:error] [pid 402041:tid 402182] [client 20.220.225.223:58368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/acew67.php"] [unique_id "al9UsIiENNLP6XjiHQtiJAAAAZg"]
[Tue Jul 21 08:14:56.538652 2026] [security2:error] [pid 402041:tid 402210] [client 74.249.245.134:15361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/storage/index.php"] [unique_id "al9UsIiENNLP6XjiHQtiJgAAAbQ"]
[Tue Jul 21 08:14:56.727954 2026] [security2:error] [pid 402041:tid 402069] [remote 41.186.86.12:34673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiasaudeplena.com.br.ciclododinheiro.com"] [uri "/wp-login.php"] [unique_id "al9UsIiENNLP6XjiHQtiQQAB_xk"]
[Tue Jul 21 08:14:56.734483 2026] [security2:error] [pid 402041:tid 402222] [client 20.197.192.193:57793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/dr.php"] [unique_id "al9UsIiENNLP6XjiHQtiWQAAAcA"]
[Tue Jul 21 08:14:56.947432 2026] [fcgid:warn] [pid 402041:tid 402288] (70014)End of file found: [client 66.132.172.177:42146] mod_fcgid: can't get data from http client
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 08:14:57.272022 2026] [security2:error] [pid 402041:tid 402272] [client 4.194.24.143:13607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/chosen.php"] [unique_id "al9UsYiENNLP6XjiHQtinQAAAfI"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Tue Jul 21 08:14:57.531294 2026] [security2:error] [pid 402041:tid 402204] [client 87.116.180.198:13826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UsYiENNLP6XjiHQtirgAAAa4"]
[Tue Jul 21 08:14:57.531437 2026] [security2:error] [pid 402041:tid 402204] [client 87.116.180.198:13826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UsYiENNLP6XjiHQtirgAAAa4"]
[Tue Jul 21 08:14:57.596724 2026] [security2:error] [pid 402041:tid 402058] [remote 47.128.57.76:43770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.reserveseulugar.com.br"] [uri "/o-que-fazer-em-goiania-neste-final-de-semana-dias-09-10-e-11-de-maio-de-2025/"] [unique_id "al9UsYiENNLP6XjiHQtitwAB1A4"]
[Tue Jul 21 08:14:57.656484 2026] [security2:error] [pid 402041:tid 402254] [client 20.151.10.161:36595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9UsYiENNLP6XjiHQtivAAAAeA"]
[Tue Jul 21 08:14:57.857806 2026] [security2:error] [pid 402041:tid 402215] [client 134.122.94.138:62406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "accjbc.org"] [uri "/login"] [unique_id "al9UsYiENNLP6XjiHQtivQAAAbk"]
[Tue Jul 21 08:14:57.914908 2026] [security2:error] [pid 402041:tid 402241] [client 74.249.245.134:15116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/g.php"] [unique_id "al9UsYiENNLP6XjiHQtivwAAAdM"]
[Tue Jul 21 08:14:57.944595 2026] [security2:error] [pid 402041:tid 402169] [remote 97.74.93.24:45720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojadedoces.com"] [uri "/wp-login.php"] [unique_id "al9UsYiENNLP6XjiHQtiwAACCn0"]
[Tue Jul 21 08:14:57.946914 2026] [security2:error] [pid 402041:tid 402295] [client 154.208.47.43:50222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UsYiENNLP6XjiHQtiwQAAAgk"]
[Tue Jul 21 08:14:57.947018 2026] [security2:error] [pid 402041:tid 402295] [client 154.208.47.43:50222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UsYiENNLP6XjiHQtiwQAAAgk"]
[Tue Jul 21 08:14:57.955018 2026] [security2:error] [pid 402041:tid 402249] [client 20.151.10.161:51082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/2P.php"] [unique_id "al9UsYiENNLP6XjiHQtiwgAAAds"]
[Tue Jul 21 08:14:58.035535 2026] [security2:error] [pid 402041:tid 402256] [client 20.220.225.223:30881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/bscclapb.php"] [unique_id "al9UsoiENNLP6XjiHQtiwwAAAeI"]
[Tue Jul 21 08:14:58.304322 2026] [security2:error] [pid 402041:tid 402264] [client 4.194.24.143:21779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/class-t.api.php"] [unique_id "al9UsoiENNLP6XjiHQtiywAAAeo"]
[Tue Jul 21 08:14:58.481254 2026] [security2:error] [pid 402041:tid 402272] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UsoiENNLP6XjiHQti0gAB8jU"]
[Tue Jul 21 08:14:58.675397 2026] [security2:error] [pid 402041:tid 402047] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UsoiENNLP6XjiHQti2AAB5wM"]
[Tue Jul 21 08:14:58.675558 2026] [security2:error] [pid 402041:tid 402261] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UsoiENNLP6XjiHQti2AAB5wM"]
[Tue Jul 21 08:14:58.836766 2026] [security2:error] [pid 402041:tid 402185] [client 102.206.115.33:58897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UsoiENNLP6XjiHQti3gAAAZs"]
[Tue Jul 21 08:14:58.836887 2026] [security2:error] [pid 402041:tid 402185] [client 102.206.115.33:58897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UsoiENNLP6XjiHQti3gAAAZs"]
[Tue Jul 21 08:14:58.918908 2026] [security2:error] [pid 402041:tid 402203] [client 20.104.96.117:54106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9UsoiENNLP6XjiHQti4AAAAa0"]
[Tue Jul 21 08:14:59.115307 2026] [security2:error] [pid 402041:tid 402065] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Us4iENNLP6XjiHQti4wAB9RU"]
[Tue Jul 21 08:14:59.115467 2026] [security2:error] [pid 402041:tid 402275] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9Us4iENNLP6XjiHQti4wAB9RU"]
[Tue Jul 21 08:14:59.269538 2026] [security2:error] [pid 402041:tid 402180] [client 20.151.10.161:51095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Us4iENNLP6XjiHQti8AAAAZY"]
[Tue Jul 21 08:14:59.427497 2026] [security2:error] [pid 402041:tid 402220] [client 4.194.24.143:13612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al9Us4iENNLP6XjiHQtjHgAAAb4"]
[Tue Jul 21 08:14:59.825682 2026] [security2:error] [pid 402041:tid 402238] [client 74.249.245.134:15136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/nf.php"] [unique_id "al9Us4iENNLP6XjiHQtjPwAAAdA"]
[Tue Jul 21 08:14:59.868352 2026] [security2:error] [pid 402041:tid 402290] [client 115.134.11.136:53019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Us4iENNLP6XjiHQtjPQAAAgQ"]
[Tue Jul 21 08:15:00.147155 2026] [security2:error] [pid 402041:tid 402283] [client 103.151.46.103:60642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UtIiENNLP6XjiHQtjRAAAAf0"]
[Tue Jul 21 08:15:00.147298 2026] [security2:error] [pid 402041:tid 402283] [client 103.151.46.103:60642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UtIiENNLP6XjiHQtjRAAAAf0"]
[Tue Jul 21 08:15:00.170512 2026] [security2:error] [pid 402041:tid 402191] [client 20.226.60.151:49362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/dex.php"] [unique_id "al9UtIiENNLP6XjiHQtjSAAAAaE"]
[Tue Jul 21 08:15:00.212173 2026] [security2:error] [pid 402041:tid 402242] [client 14.245.224.124:57292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9UtIiENNLP6XjiHQtjSQAAAdQ"]
[Tue Jul 21 08:15:00.212282 2026] [security2:error] [pid 402041:tid 402242] [client 14.245.224.124:57292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9UtIiENNLP6XjiHQtjSQAAAdQ"]
[Tue Jul 21 08:15:00.347362 2026] [security2:error] [pid 402041:tid 402288] [client 20.151.10.161:51102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9UtIiENNLP6XjiHQtjTwAAAgI"]
[Tue Jul 21 08:15:00.442437 2026] [security2:error] [pid 402041:tid 402195] [client 187.125.243.197:63716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UtIiENNLP6XjiHQtjUgAAAaU"]
[Tue Jul 21 08:15:00.442561 2026] [security2:error] [pid 402041:tid 402195] [client 187.125.243.197:63716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UtIiENNLP6XjiHQtjUgAAAaU"]
[Tue Jul 21 08:15:00.495474 2026] [security2:error] [pid 402041:tid 402299] [client 4.194.24.143:20837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/class-wp-http-client.php"] [unique_id "al9UtIiENNLP6XjiHQtjUwAAAg0"]
[Tue Jul 21 08:15:00.565973 2026] [security2:error] [pid 402041:tid 402292] [client 20.104.96.117:54674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9UtIiENNLP6XjiHQtjVgAAAgY"]
[Tue Jul 21 08:15:00.606045 2026] [security2:error] [pid 402041:tid 402260] [client 74.7.230.60:55042] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cloud9foils.murilomattos.com"] [uri "/cgi-sys/404.html"] [unique_id "al9UtIiENNLP6XjiHQtjWAAB5j4"]
[Tue Jul 21 08:15:00.606908 2026] [autoindex:error] [pid 402041:tid 402059] [remote 74.7.227.34:51100] AH01276: Cannot serve directory /home4/muril131/cloud9foils.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:15:00.775219 2026] [security2:error] [pid 402041:tid 402214] [client 14.97.58.74:38437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UtIiENNLP6XjiHQtjXwAAAbg"]
[Tue Jul 21 08:15:00.775365 2026] [security2:error] [pid 402041:tid 402214] [client 14.97.58.74:38437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UtIiENNLP6XjiHQtjXwAAAbg"]
[Tue Jul 21 08:15:01.002180 2026] [security2:error] [pid 402041:tid 402107] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UtYiENNLP6XjiHQtjZgABvj8"]
[Tue Jul 21 08:15:01.002330 2026] [security2:error] [pid 402041:tid 402220] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UtYiENNLP6XjiHQtjZgABvj8"]
[Tue Jul 21 08:15:01.466922 2026] [security2:error] [pid 402041:tid 402294] [client 20.104.96.117:63023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9UtYiENNLP6XjiHQtjewAAAgg"]
[Tue Jul 21 08:15:01.555605 2026] [security2:error] [pid 402041:tid 402261] [client 4.194.24.143:21787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/class.php"] [unique_id "al9UtYiENNLP6XjiHQtjfAAAAec"]
[Tue Jul 21 08:15:01.562018 2026] [security2:error] [pid 402041:tid 402143] [remote 119.195.102.159:42658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "manosorvetes.com.br"] [uri "/wp-login.php"] [unique_id "al9UtYiENNLP6XjiHQtjfQAB72M"]
[Tue Jul 21 08:15:01.926424 2026] [security2:error] [pid 402041:tid 402233] [client 74.249.245.134:15107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/xda.php"] [unique_id "al9UtYiENNLP6XjiHQtjiAAAAcs"]
[Tue Jul 21 08:15:02.144739 2026] [security2:error] [pid 402041:tid 402186] [client 59.184.68.205:60007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.68.184.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "darsenavogamarine.com"] [uri "/xmlrpc.php"] [unique_id "al9UtoiENNLP6XjiHQtjjgAAAZw"]
[Tue Jul 21 08:15:02.144911 2026] [security2:error] [pid 402041:tid 402186] [client 59.184.68.205:60007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "darsenavogamarine.com"] [uri "/xmlrpc.php"] [unique_id "al9UtoiENNLP6XjiHQtjjgAAAZw"]
[Tue Jul 21 08:15:02.263660 2026] [security2:error] [pid 402041:tid 402264] [client 173.252.95.13:41048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9UtoiENNLP6XjiHQtjnQAAAeo"]
[Tue Jul 21 08:15:02.485436 2026] [security2:error] [pid 402041:tid 402238] [client 20.226.60.151:48843] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "moadvogadas.com.br"] [uri "/1.php"] [unique_id "al9UtoiENNLP6XjiHQtjpQAAAdA"]
[Tue Jul 21 08:15:02.485573 2026] [security2:error] [pid 402041:tid 402238] [client 20.226.60.151:48843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/1.php"] [unique_id "al9UtoiENNLP6XjiHQtjpQAAAdA"]
[Tue Jul 21 08:15:02.622430 2026] [security2:error] [pid 402041:tid 402220] [client 4.194.24.143:2346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/classsmtps.php"] [unique_id "al9UtoiENNLP6XjiHQtjpwAAAb4"]
[Tue Jul 21 08:15:02.716359 2026] [core:error] [pid 402041:tid 402080] [remote 40.77.167.57:33832] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:02.716381 2026] [core:error] [pid 402041:tid 402080] [remote 40.77.167.57:33832] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:02.720638 2026] [security2:error] [pid 402041:tid 402228] [client 120.56.162.40:63194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UtoiENNLP6XjiHQtjqgAAAcY"]
[Tue Jul 21 08:15:02.721016 2026] [security2:error] [pid 402041:tid 402228] [client 120.56.162.40:63194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UtoiENNLP6XjiHQtjqgAAAcY"]
[Tue Jul 21 08:15:02.735353 2026] [access_compat:error] [pid 402041:tid 402178] [client 162.241.63.68:16292] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:15:02.751320 2026] [security2:error] [pid 402041:tid 402282] [client 65.21.113.253:39470] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UtoiENNLP6XjiHQtjoAAAAfw"]
[Tue Jul 21 08:15:02.837916 2026] [core:error] [pid 402041:tid 402169] [remote 40.77.167.57:33832] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:02.837941 2026] [core:error] [pid 402041:tid 402169] [remote 40.77.167.57:33832] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:02.884403 2026] [security2:error] [pid 402041:tid 402279] [client 173.252.95.37:62962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9UtoiENNLP6XjiHQtjsgAAAfk"]
[Tue Jul 21 08:15:02.900982 2026] [security2:error] [pid 402041:tid 402242] [client 20.151.10.161:36581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/bob.php"] [unique_id "al9UtoiENNLP6XjiHQtjswAAAdQ"]
[Tue Jul 21 08:15:02.961600 2026] [core:error] [pid 402041:tid 402144] [remote 40.77.167.57:33832] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:02.961625 2026] [core:error] [pid 402041:tid 402144] [remote 40.77.167.57:33832] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:03.050611 2026] [security2:error] [pid 402041:tid 402182] [client 20.220.225.223:30859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/else1.php"] [unique_id "al9Ut4iENNLP6XjiHQtjvAAAAZg"]
[Tue Jul 21 08:15:03.112873 2026] [security2:error] [pid 402041:tid 402278] [client 150.129.202.39:12862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ut4iENNLP6XjiHQtjvwAAAfg"]
[Tue Jul 21 08:15:03.112989 2026] [security2:error] [pid 402041:tid 402278] [client 150.129.202.39:12862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ut4iENNLP6XjiHQtjvwAAAfg"]
[Tue Jul 21 08:15:03.200710 2026] [security2:error] [pid 402041:tid 402227] [client 20.104.96.117:54715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/albin.php"] [unique_id "al9Ut4iENNLP6XjiHQtjxQAAAcU"]
[Tue Jul 21 08:15:03.290546 2026] [core:error] [pid 402041:tid 402067] [remote 40.77.167.57:33832] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:03.290569 2026] [core:error] [pid 402041:tid 402067] [remote 40.77.167.57:33832] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:03.317963 2026] [security2:error] [pid 402041:tid 402200] [client 103.112.99.135:62755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.99.112.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gradiente.com.br"] [uri "/"] [unique_id "al9UtoiENNLP6XjiHQtjnwAAAao"]
[Tue Jul 21 08:15:03.652523 2026] [security2:error] [pid 402041:tid 402214] [client 4.194.24.143:21201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/classwithtostring.php"] [unique_id "al9Ut4iENNLP6XjiHQtj3AAAAbg"]
[Tue Jul 21 08:15:03.910327 2026] [security2:error] [pid 402041:tid 402128] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Ut4iENNLP6XjiHQtj5wAB11Q"]
[Tue Jul 21 08:15:03.910474 2026] [security2:error] [pid 402041:tid 402245] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Ut4iENNLP6XjiHQtj5wAB11Q"]
[Tue Jul 21 08:15:03.954314 2026] [security2:error] [pid 402041:tid 402275] [client 74.249.245.134:15365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/shell.php"] [unique_id "al9Ut4iENNLP6XjiHQtj6wAAAfU"]
[Tue Jul 21 08:15:03.962398 2026] [security2:error] [pid 402041:tid 402241] [client 103.112.99.135:63009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.99.112.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gradiente.com.br"] [uri "/"] [unique_id "al9Ut4iENNLP6XjiHQtj7AAAAdM"]
[Tue Jul 21 08:15:04.118509 2026] [security2:error] [pid 402041:tid 402222] [client 20.104.96.117:54700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/cilus.php"] [unique_id "al9UuIiENNLP6XjiHQtj7wAAAcA"]
[Tue Jul 21 08:15:04.168818 2026] [security2:error] [pid 402041:tid 402278] [client 162.219.176.3:35572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9UuIiENNLP6XjiHQtj8AAAAfg"]
[Tue Jul 21 08:15:04.168930 2026] [security2:error] [pid 402041:tid 402278] [client 162.219.176.3:35572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9UuIiENNLP6XjiHQtj8AAAAfg"]
[Tue Jul 21 08:15:04.277723 2026] [security2:error] [pid 402041:tid 402204] [client 117.210.135.0:53807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UuIiENNLP6XjiHQtj8QAAAa4"]
[Tue Jul 21 08:15:04.277856 2026] [security2:error] [pid 402041:tid 402204] [client 117.210.135.0:53807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UuIiENNLP6XjiHQtj8QAAAa4"]
[Tue Jul 21 08:15:04.324933 2026] [security2:error] [pid 402041:tid 402205] [client 20.226.60.151:48880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/ms.php"] [unique_id "al9UuIiENNLP6XjiHQtj9gAAAa8"]
[Tue Jul 21 08:15:04.603132 2026] [security2:error] [pid 402041:tid 402180] [client 103.112.99.135:63147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.99.112.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gradiente.com.br"] [uri "/runtime/archive/cnm.php"] [unique_id "al9UuIiENNLP6XjiHQtj_QAAAZY"]
[Tue Jul 21 08:15:04.722597 2026] [security2:error] [pid 402041:tid 402260] [client 4.194.24.143:21786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/claude.php"] [unique_id "al9UuIiENNLP6XjiHQtj_wAAAeY"]
[Tue Jul 21 08:15:04.778595 2026] [security2:error] [pid 402041:tid 402185] [client 173.252.95.40:35596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9UuIiENNLP6XjiHQtkAAAAAZs"]
[Tue Jul 21 08:15:04.961217 2026] [security2:error] [pid 402041:tid 402220] [client 20.104.96.117:62990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/gptsh.php"] [unique_id "al9UuIiENNLP6XjiHQtkBgAAAb4"]
[Tue Jul 21 08:15:05.323449 2026] [security2:error] [pid 402041:tid 402245] [client 62.102.148.158:44788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9UuYiENNLP6XjiHQtkEAAAAdc"]
[Tue Jul 21 08:15:05.323559 2026] [security2:error] [pid 402041:tid 402245] [client 62.102.148.158:44788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9UuYiENNLP6XjiHQtkEAAAAdc"]
[Tue Jul 21 08:15:05.353657 2026] [security2:error] [pid 402041:tid 402053] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UuYiENNLP6XjiHQtkFAAB1gk"]
[Tue Jul 21 08:15:05.353822 2026] [security2:error] [pid 402041:tid 402244] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UuYiENNLP6XjiHQtkFAAB1gk"]
[Tue Jul 21 08:15:05.783919 2026] [security2:error] [pid 402041:tid 402294] [client 4.194.24.143:13602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/config.php"] [unique_id "al9UuYiENNLP6XjiHQtkGwAAAgg"]
[Tue Jul 21 08:15:06.033464 2026] [security2:error] [pid 402041:tid 402296] [client 20.104.96.117:54129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/rithin.php"] [unique_id "al9UuoiENNLP6XjiHQtkKAAAAgo"]
[Tue Jul 21 08:15:06.279059 2026] [security2:error] [pid 402041:tid 402263] [client 20.220.225.223:30891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/tkikikoko.php"] [unique_id "al9UuoiENNLP6XjiHQtkNQAAAek"]
[Tue Jul 21 08:15:06.292276 2026] [security2:error] [pid 402041:tid 402054] [remote 124.55.178.99:33048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caminhoneiro.giovanoniadv.com.br"] [uri "/wp-login.php"] [unique_id "al9UuoiENNLP6XjiHQtkNgAB-Ao"]
[Tue Jul 21 08:15:06.535913 2026] [security2:error] [pid 402041:tid 402051] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UuoiENNLP6XjiHQtkQwAB0Ac"]
[Tue Jul 21 08:15:06.536060 2026] [security2:error] [pid 402041:tid 402238] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UuoiENNLP6XjiHQtkQwAB0Ac"]
[Tue Jul 21 08:15:06.693410 2026] [security2:error] [pid 402041:tid 402243] [client 61.1.167.83:53953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UuoiENNLP6XjiHQtkRgAAAdU"]
[Tue Jul 21 08:15:06.693557 2026] [security2:error] [pid 402041:tid 402243] [client 61.1.167.83:53953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UuoiENNLP6XjiHQtkRgAAAdU"]
[Tue Jul 21 08:15:06.836426 2026] [security2:error] [pid 402041:tid 402242] [client 4.194.24.143:21184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/.dj/index.php"] [unique_id "al9UuoiENNLP6XjiHQtkSQAAAdQ"]
[Tue Jul 21 08:15:06.922994 2026] [security2:error] [pid 402041:tid 402233] [client 74.249.245.134:15167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/3.php"] [unique_id "al9UuoiENNLP6XjiHQtkTgAAAcs"]
[Tue Jul 21 08:15:07.146032 2026] [security2:error] [pid 402041:tid 402265] [client 38.100.221.102:18634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uu4iENNLP6XjiHQtkWAAAAes"]
[Tue Jul 21 08:15:07.148330 2026] [security2:error] [pid 402041:tid 402265] [client 38.100.221.102:18634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uu4iENNLP6XjiHQtkWAAAAes"]
[Tue Jul 21 08:15:07.312936 2026] [security2:error] [pid 402041:tid 402211] [client 74.249.245.134:15377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/mds.php"] [unique_id "al9Uu4iENNLP6XjiHQtkXAAAAbU"]
[Tue Jul 21 08:15:07.472146 2026] [core:error] [pid 402041:tid 402060] [remote 52.167.144.201:17427] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:07.472167 2026] [core:error] [pid 402041:tid 402060] [remote 52.167.144.201:17427] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:07.556380 2026] [security2:error] [pid 402041:tid 402255] [client 103.78.200.11:55847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uu4iENNLP6XjiHQtkYwAAAeE"]
[Tue Jul 21 08:15:07.556534 2026] [security2:error] [pid 402041:tid 402255] [client 103.78.200.11:55847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uu4iENNLP6XjiHQtkYwAAAeE"]
[Tue Jul 21 08:15:07.569208 2026] [security2:error] [pid 402041:tid 402162] [remote 124.55.178.99:49542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deals-ecomm.shop"] [uri "/wp-login.php"] [unique_id "al9Uu4iENNLP6XjiHQtkZAABqnY"]
[Tue Jul 21 08:15:07.712465 2026] [security2:error] [pid 402041:tid 402285] [client 116.212.131.65:56999] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "drajoanasiqueira.com"] [uri "/"] [unique_id "al9Uu4iENNLP6XjiHQtkaQAAAf8"]
[Tue Jul 21 08:15:07.836767 2026] [security2:error] [pid 402041:tid 402186] [client 20.104.96.117:63015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/fffm.php"] [unique_id "al9Uu4iENNLP6XjiHQtkbAAAAZw"]
[Tue Jul 21 08:15:07.918341 2026] [security2:error] [pid 402041:tid 402239] [client 154.208.47.43:50705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Uu4iENNLP6XjiHQtkcAAAAdE"]
[Tue Jul 21 08:15:07.918482 2026] [security2:error] [pid 402041:tid 402239] [client 154.208.47.43:50705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Uu4iENNLP6XjiHQtkcAAAAdE"]
[Tue Jul 21 08:15:08.248316 2026] [security2:error] [pid 402041:tid 402256] [client 4.194.24.143:13595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/.vscode/class-wp-http-client.php"] [unique_id "al9UvIiENNLP6XjiHQtkfgAAAeI"]
[Tue Jul 21 08:15:08.306051 2026] [security2:error] [pid 402041:tid 402191] [client 87.116.180.198:27170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UvIiENNLP6XjiHQtkggAAAaE"]
[Tue Jul 21 08:15:08.307571 2026] [security2:error] [pid 402041:tid 402191] [client 87.116.180.198:27170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UvIiENNLP6XjiHQtkggAAAaE"]
[Tue Jul 21 08:15:08.429082 2026] [autoindex:error] [pid 402041:tid 402299] [client 20.226.60.151:48831] AH01276: Cannot serve directory /home4/moadvo53/moadvogadas.com.br/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:15:08.448134 2026] [security2:error] [pid 402041:tid 402230] [client 20.151.10.161:51130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/crgio.php"] [unique_id "al9UvIiENNLP6XjiHQtkhQAAAcg"]
[Tue Jul 21 08:15:08.459637 2026] [security2:error] [pid 402041:tid 402222] [client 20.226.60.151:48850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/memberfuns.php"] [unique_id "al9UvIiENNLP6XjiHQtkiAAAAcA"]
[Tue Jul 21 08:15:08.487392 2026] [security2:error] [pid 402041:tid 402252] [client 74.249.245.134:15156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/archive.php"] [unique_id "al9UvIiENNLP6XjiHQtkjgAAAd4"]
[Tue Jul 21 08:15:08.571929 2026] [security2:error] [pid 402041:tid 402187] [client 20.220.225.223:58381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/wp-Blogs.php"] [unique_id "al9UvIiENNLP6XjiHQtkjwAAAZ0"]
[Tue Jul 21 08:15:08.618353 2026] [security2:error] [pid 402041:tid 402185] [client 20.104.96.117:63089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/dfre.php"] [unique_id "al9UvIiENNLP6XjiHQtkkAAAAZs"]
[Tue Jul 21 08:15:08.878625 2026] [security2:error] [pid 402041:tid 402226] [client 103.151.46.103:61170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UvIiENNLP6XjiHQtklQAAAcQ"]
[Tue Jul 21 08:15:08.878782 2026] [security2:error] [pid 402041:tid 402226] [client 103.151.46.103:61170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UvIiENNLP6XjiHQtklQAAAcQ"]
[Tue Jul 21 08:15:09.023417 2026] [security2:error] [pid 402041:tid 402259] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9UvIiENNLP6XjiHQtkmAAB5Us"]
[Tue Jul 21 08:15:09.231534 2026] [security2:error] [pid 402041:tid 402225] [client 20.226.60.151:49391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/0.php"] [unique_id "al9UvYiENNLP6XjiHQtknwAAAcM"]
[Tue Jul 21 08:15:09.317765 2026] [autoindex:error] [pid 402041:tid 402286] [client 4.194.24.143:20847] AH01276: Cannot serve directory /home2/alanam00/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:15:09.405640 2026] [security2:error] [pid 402041:tid 402091] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UvYiENNLP6XjiHQtkpQACBC8"]
[Tue Jul 21 08:15:09.405779 2026] [security2:error] [pid 402041:tid 402290] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UvYiENNLP6XjiHQtkpQACBC8"]
[Tue Jul 21 08:15:09.406496 2026] [autoindex:error] [pid 402041:tid 402261] [client 101.33.81.73:48112] AH01276: Cannot serve directory /home3/lianem44/ubaloc.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:15:09.413953 2026] [security2:error] [pid 402041:tid 402263] [client 102.206.115.33:60880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UvYiENNLP6XjiHQtkpwAAAek"]
[Tue Jul 21 08:15:09.414574 2026] [security2:error] [pid 402041:tid 402263] [client 102.206.115.33:60880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UvYiENNLP6XjiHQtkpwAAAek"]
[Tue Jul 21 08:15:09.666231 2026] [security2:error] [pid 402041:tid 402203] [client 4.194.24.143:20847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/.well-known/about.php"] [unique_id "al9UvYiENNLP6XjiHQtkrwAAAa0"]
[Tue Jul 21 08:15:09.784626 2026] [security2:error] [pid 402041:tid 402087] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UvYiENNLP6XjiHQtkswABmSs"]
[Tue Jul 21 08:15:09.784786 2026] [security2:error] [pid 402041:tid 402183] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UvYiENNLP6XjiHQtkswABmSs"]
[Tue Jul 21 08:15:09.839009 2026] [security2:error] [pid 402041:tid 402258] [client 74.249.245.134:15161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/amax.php"] [unique_id "al9UvYiENNLP6XjiHQtktAAAAeQ"]
[Tue Jul 21 08:15:10.149740 2026] [security2:error] [pid 402041:tid 402197] [client 14.245.224.124:57857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9UvoiENNLP6XjiHQtkugAAAac"]
[Tue Jul 21 08:15:10.149873 2026] [security2:error] [pid 402041:tid 402197] [client 14.245.224.124:57857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9UvoiENNLP6XjiHQtkugAAAac"]
[Tue Jul 21 08:15:10.319288 2026] [security2:error] [pid 402041:tid 402200] [client 20.220.225.223:30706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/wp-css.php"] [unique_id "al9UvoiENNLP6XjiHQtkwAAAAao"]
[Tue Jul 21 08:15:10.492141 2026] [security2:error] [pid 402041:tid 402235] [client 20.226.60.151:48785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/BDKR28.php"] [unique_id "al9UvoiENNLP6XjiHQtkwQAAAc0"]
[Tue Jul 21 08:15:10.635970 2026] [security2:error] [pid 402041:tid 402068] [remote 132.148.72.88:36748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9UvoiENNLP6XjiHQtkxgABzBg"]
[Tue Jul 21 08:15:10.741945 2026] [autoindex:error] [pid 402041:tid 402280] [client 4.194.24.143:20811] AH01276: Cannot serve directory /home2/alanam00/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:15:10.862829 2026] [security2:error] [pid 402041:tid 402238] [client 20.104.96.117:54675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/wp-happy.php"] [unique_id "al9UvoiENNLP6XjiHQtkzAAAAdA"]
[Tue Jul 21 08:15:10.935849 2026] [security2:error] [pid 402041:tid 402228] [client 187.125.243.197:64186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UvoiENNLP6XjiHQtkzgAAAcY"]
[Tue Jul 21 08:15:10.935986 2026] [security2:error] [pid 402041:tid 402228] [client 187.125.243.197:64186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UvoiENNLP6XjiHQtkzgAAAcY"]
[Tue Jul 21 08:15:11.344202 2026] [security2:error] [pid 402041:tid 402291] [client 14.97.58.74:55560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Uv4iENNLP6XjiHQtlBQAAAgU"]
[Tue Jul 21 08:15:11.344340 2026] [security2:error] [pid 402041:tid 402291] [client 14.97.58.74:55560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Uv4iENNLP6XjiHQtlBQAAAgU"]
[Tue Jul 21 08:15:11.453839 2026] [security2:error] [pid 402041:tid 402220] [client 4.194.24.143:20811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/.well-known/acme-challenge/muse.php"] [unique_id "al9Uv4iENNLP6XjiHQtlBgAAAb4"]
[Tue Jul 21 08:15:11.489735 2026] [security2:error] [pid 402041:tid 402084] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uv4iENNLP6XjiHQtlDwABlig"]
[Tue Jul 21 08:15:11.489883 2026] [security2:error] [pid 402041:tid 402180] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uv4iENNLP6XjiHQtlDwABlig"]
[Tue Jul 21 08:15:11.661623 2026] [security2:error] [pid 402041:tid 402224] [client 74.249.245.134:15371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/moon.php"] [unique_id "al9Uv4iENNLP6XjiHQtlGQAAAcI"]
[Tue Jul 21 08:15:11.706600 2026] [security2:error] [pid 402041:tid 402271] [client 20.226.60.151:48885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/green1.php"] [unique_id "al9Uv4iENNLP6XjiHQtlGgAAAfE"]
[Tue Jul 21 08:15:11.714984 2026] [security2:error] [pid 402041:tid 402199] [client 115.134.11.136:53422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UvoiENNLP6XjiHQtkvwAAAak"]
[Tue Jul 21 08:15:11.934139 2026] [security2:error] [pid 402041:tid 402261] [client 20.104.96.117:63065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/fpr4.php"] [unique_id "al9Uv4iENNLP6XjiHQtlMQAAAec"]
[Tue Jul 21 08:15:12.215811 2026] [core:error] [pid 402041:tid 402093] [remote 40.77.167.45:39808] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:12.215851 2026] [core:error] [pid 402041:tid 402093] [remote 40.77.167.45:39808] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:12.339914 2026] [core:error] [pid 402041:tid 402151] [remote 40.77.167.45:39808] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:12.339939 2026] [core:error] [pid 402041:tid 402151] [remote 40.77.167.45:39808] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:12.484435 2026] [security2:error] [pid 402041:tid 402187] [client 20.151.10.161:51074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/pucci.php"] [unique_id "al9UwIiENNLP6XjiHQtlRQAAAZ0"]
[Tue Jul 21 08:15:12.518596 2026] [security2:error] [pid 402041:tid 402250] [client 4.194.24.143:22339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/.well-known/bdkr28_61cohkhh.php"] [unique_id "al9UwIiENNLP6XjiHQtlRgAAAdw"]
[Tue Jul 21 08:15:12.881143 2026] [security2:error] [pid 402041:tid 402226] [client 20.226.60.151:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/nc4.php"] [unique_id "al9UwIiENNLP6XjiHQtlUgAAAcQ"]
[Tue Jul 21 08:15:12.898593 2026] [security2:error] [pid 402041:tid 402224] [client 74.249.245.134:15130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/ws83.php"] [unique_id "al9UwIiENNLP6XjiHQtlUwAAAcI"]
[Tue Jul 21 08:15:12.942811 2026] [security2:error] [pid 402041:tid 402106] [remote 154.61.75.100:35744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9UwIiENNLP6XjiHQtlVAABoD4"]
[Tue Jul 21 08:15:13.591096 2026] [security2:error] [pid 402041:tid 402228] [client 4.194.24.143:20805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/.well-known/class-wp-http-client.php"] [unique_id "al9UwYiENNLP6XjiHQtlYQAAAcY"]
[Tue Jul 21 08:15:13.633429 2026] [security2:error] [pid 402041:tid 402235] [client 150.129.202.39:64591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UwYiENNLP6XjiHQtlYgAAAc0"]
[Tue Jul 21 08:15:13.633585 2026] [security2:error] [pid 402041:tid 402235] [client 150.129.202.39:64591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UwYiENNLP6XjiHQtlYgAAAc0"]
[Tue Jul 21 08:15:14.146437 2026] [security2:error] [pid 402041:tid 402188] [client 74.249.245.134:15382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/CDX1.php"] [unique_id "al9UwoiENNLP6XjiHQtldAAAAZ4"]
[Tue Jul 21 08:15:14.150329 2026] [security2:error] [pid 402041:tid 402260] [client 20.104.96.117:54709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/file88.php"] [unique_id "al9UwoiENNLP6XjiHQtldQAAAeY"]
[Tue Jul 21 08:15:14.167162 2026] [security2:error] [pid 402041:tid 402255] [client 120.56.162.40:63696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UwoiENNLP6XjiHQtldgAAAeE"]
[Tue Jul 21 08:15:14.167275 2026] [security2:error] [pid 402041:tid 402255] [client 120.56.162.40:63696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UwoiENNLP6XjiHQtldgAAAeE"]
[Tue Jul 21 08:15:14.167785 2026] [security2:error] [pid 402041:tid 402216] [client 20.226.60.151:48835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/a1.php"] [unique_id "al9UwoiENNLP6XjiHQtldwAAAbo"]
[Tue Jul 21 08:15:14.242944 2026] [security2:error] [pid 402041:tid 402075] [remote 130.185.118.215:35384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "prissedermatologia.com.br"] [uri "/wp-login.php"] [unique_id "al9UwoiENNLP6XjiHQtleAAB5B8"]
[Tue Jul 21 08:15:14.568125 2026] [security2:error] [pid 402041:tid 402252] [client 20.25.53.149:0] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "al9UwoiENNLP6XjiHQtlhgAAAd4"]
[Tue Jul 21 08:15:14.569850 2026] [security2:error] [pid 402041:tid 402214] [client 20.25.53.149:49822] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/"] [unique_id "al9UwoiENNLP6XjiHQtlgwAAAbg"]
[Tue Jul 21 08:15:14.583118 2026] [security2:error] [pid 402041:tid 402057] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UwoiENNLP6XjiHQtliQAB9A0"]
[Tue Jul 21 08:15:14.583246 2026] [security2:error] [pid 402041:tid 402274] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UwoiENNLP6XjiHQtliQAB9A0"]
[Tue Jul 21 08:15:14.686535 2026] [security2:error] [pid 402041:tid 402290] [client 20.220.225.223:30658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/wp-explorer.php"] [unique_id "al9UwoiENNLP6XjiHQtligAAAgQ"]
[Tue Jul 21 08:15:14.705478 2026] [security2:error] [pid 402041:tid 402234] [client 20.197.192.193:54374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/kq1.php"] [unique_id "al9UwoiENNLP6XjiHQtliwAAAcw"]
[Tue Jul 21 08:15:14.720689 2026] [security2:error] [pid 402041:tid 402291] [client 4.194.24.143:2355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "al9UwoiENNLP6XjiHQtljQAAAgU"]
[Tue Jul 21 08:15:14.852309 2026] [security2:error] [pid 402041:tid 402119] [remote 103.28.36.200:33758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9UwYiENNLP6XjiHQtlaQAB0Us"]
[Tue Jul 21 08:15:14.852466 2026] [security2:error] [pid 402041:tid 402239] [client 103.28.36.200:33758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9UwYiENNLP6XjiHQtlaQAB0Us"]
[Tue Jul 21 08:15:14.977154 2026] [security2:error] [pid 402041:tid 402205] [client 117.210.135.0:54447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UwoiENNLP6XjiHQtlwAAAAa8"]
[Tue Jul 21 08:15:14.977253 2026] [security2:error] [pid 402041:tid 402205] [client 117.210.135.0:54447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UwoiENNLP6XjiHQtlwAAAAa8"]
[Tue Jul 21 08:15:15.321955 2026] [security2:error] [pid 402041:tid 402176] [client 74.249.245.134:31384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/inputs.php"] [unique_id "al9Uw4iENNLP6XjiHQtlzwAAAZI"]
[Tue Jul 21 08:15:15.562956 2026] [security2:error] [pid 402041:tid 402225] [client 15.235.98.144:53704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.odontoclinicms.com.br"] [uri "/robots.txt"] [unique_id "al9Uw4iENNLP6XjiHQtl1wAAAcM"]
[Tue Jul 21 08:15:15.563076 2026] [security2:error] [pid 402041:tid 402225] [client 15.235.98.144:53704] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.odontoclinicms.com.br"] [uri "/robots.txt"] [unique_id "al9Uw4iENNLP6XjiHQtl1wAAAcM"]
[Tue Jul 21 08:15:15.746868 2026] [security2:error] [pid 402041:tid 402292] [client 4.194.24.143:2306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/.well-known/index.php"] [unique_id "al9Uw4iENNLP6XjiHQtl2AAAAgY"]
[Tue Jul 21 08:15:15.916757 2026] [security2:error] [pid 402041:tid 402266] [client 20.220.225.223:58371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/akismet.php"] [unique_id "al9Uw4iENNLP6XjiHQtl4AAAAew"]
[Tue Jul 21 08:15:15.916920 2026] [security2:error] [pid 402041:tid 402082] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uw4iENNLP6XjiHQtl3wABliY"]
[Tue Jul 21 08:15:15.917115 2026] [security2:error] [pid 402041:tid 402180] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uw4iENNLP6XjiHQtl3wABliY"]
[Tue Jul 21 08:15:16.264649 2026] [security2:error] [pid 402041:tid 402221] [client 198.54.129.60:48532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9UxIiENNLP6XjiHQtl6AAAAb8"]
[Tue Jul 21 08:15:16.264759 2026] [security2:error] [pid 402041:tid 402221] [client 198.54.129.60:48532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9UxIiENNLP6XjiHQtl6AAAAb8"]
[Tue Jul 21 08:15:16.478672 2026] [security2:error] [pid 402041:tid 402186] [client 20.226.60.151:48794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/eee.php"] [unique_id "al9UxIiENNLP6XjiHQtl7wAAAZw"]
[Tue Jul 21 08:15:16.776095 2026] [security2:error] [pid 402041:tid 402230] [client 4.194.24.143:20545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/.well-known/ws.php"] [unique_id "al9UxIiENNLP6XjiHQtl9wAAAcg"]
[Tue Jul 21 08:15:16.839061 2026] [security2:error] [pid 402041:tid 402184] [client 74.7.241.147:39484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.learningsociety.com.br"] [uri "/index.php"] [unique_id "al9UxIiENNLP6XjiHQtl6QABmkc"]
[Tue Jul 21 08:15:16.973469 2026] [security2:error] [pid 402041:tid 402243] [client 142.44.225.16:49176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.odontoclinicms.com.br"] [uri "/"] [unique_id "al9UxIiENNLP6XjiHQtl_QAAAdU"]
[Tue Jul 21 08:15:16.973615 2026] [security2:error] [pid 402041:tid 402243] [client 142.44.225.16:49176] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.odontoclinicms.com.br"] [uri "/"] [unique_id "al9UxIiENNLP6XjiHQtl_QAAAdU"]
[Tue Jul 21 08:15:17.204160 2026] [security2:error] [pid 402041:tid 402166] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UxYiENNLP6XjiHQtmCQACDno"]
[Tue Jul 21 08:15:17.204385 2026] [security2:error] [pid 402041:tid 402300] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UxYiENNLP6XjiHQtmCQACDno"]
[Tue Jul 21 08:15:17.346438 2026] [security2:error] [pid 402041:tid 402275] [client 74.249.245.134:15138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/ms-edit.php"] [unique_id "al9UxYiENNLP6XjiHQtmDAAAAfU"]
[Tue Jul 21 08:15:17.375028 2026] [security2:error] [pid 402041:tid 402249] [client 74.7.241.145:60908] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "learningsociety.com.br"] [uri "/index.php"] [unique_id "al9UxIiENNLP6XjiHQtl_gAB2zY"]
[Tue Jul 21 08:15:17.547628 2026] [security2:error] [pid 402041:tid 402287] [client 65.21.113.253:46324] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UxYiENNLP6XjiHQtmBAAAAgE"]
[Tue Jul 21 08:15:17.621059 2026] [security2:error] [pid 402041:tid 402199] [client 74.7.241.147:39496] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "learningsociety.com.br"] [uri "/index.php"] [unique_id "al9UxYiENNLP6XjiHQtmCgABqUY"], referer: https://www.learningsociety.com.br/robots.txt
[Tue Jul 21 08:15:17.647509 2026] [security2:error] [pid 402041:tid 402204] [client 38.100.221.102:17904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UxYiENNLP6XjiHQtmFgAAAa4"]
[Tue Jul 21 08:15:17.647608 2026] [security2:error] [pid 402041:tid 402204] [client 38.100.221.102:17904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UxYiENNLP6XjiHQtmFgAAAa4"]
[Tue Jul 21 08:15:17.656421 2026] [security2:error] [pid 402041:tid 402288] [client 20.104.96.117:63069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/ccc.php"] [unique_id "al9UxYiENNLP6XjiHQtmFwAAAgI"]
[Tue Jul 21 08:15:17.812100 2026] [security2:error] [pid 402041:tid 402220] [client 4.194.24.143:21188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/.xa/class-wp-http-client.php"] [unique_id "al9UxYiENNLP6XjiHQtmGQAAAb4"]
[Tue Jul 21 08:15:17.928727 2026] [security2:error] [pid 402041:tid 402177] [client 103.78.200.11:56344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UxYiENNLP6XjiHQtmGgAAAZM"]
[Tue Jul 21 08:15:17.928884 2026] [security2:error] [pid 402041:tid 402177] [client 103.78.200.11:56344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UxYiENNLP6XjiHQtmGgAAAZM"]
[Tue Jul 21 08:15:18.182891 2026] [security2:error] [pid 402041:tid 402281] [client 20.226.60.151:48893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wp-aothait.php"] [unique_id "al9UxoiENNLP6XjiHQtmJAAAAfs"]
[Tue Jul 21 08:15:18.419327 2026] [security2:error] [pid 402041:tid 402289] [client 154.208.47.43:51247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UxoiENNLP6XjiHQtmKAAAAgM"]
[Tue Jul 21 08:15:18.419454 2026] [security2:error] [pid 402041:tid 402289] [client 154.208.47.43:51247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9UxoiENNLP6XjiHQtmKAAAAgM"]
[Tue Jul 21 08:15:18.634346 2026] [security2:error] [pid 402041:tid 402092] [remote 84.247.172.23:44990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-login.php"] [unique_id "al9UxoiENNLP6XjiHQtmMwAB3DA"]
[Tue Jul 21 08:15:18.848352 2026] [security2:error] [pid 402041:tid 402251] [client 4.194.24.143:26978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/0.php"] [unique_id "al9UxoiENNLP6XjiHQtmNAAAAd0"]
[Tue Jul 21 08:15:18.864793 2026] [security2:error] [pid 402041:tid 402279] [client 20.226.60.151:48769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/config.json.php"] [unique_id "al9UxoiENNLP6XjiHQtmNQAAAfk"]
[Tue Jul 21 08:15:18.867174 2026] [security2:error] [pid 402041:tid 402164] [remote 51.195.183.20:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "farmaciafarmula.com.br"] [uri "/robots.txt"] [unique_id "al9UxoiENNLP6XjiHQtmNgABvHg"]
[Tue Jul 21 08:15:18.867300 2026] [security2:error] [pid 402041:tid 402218] [client 51.195.183.20:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "farmaciafarmula.com.br"] [uri "/robots.txt"] [unique_id "al9UxoiENNLP6XjiHQtmNgABvHg"]
[Tue Jul 21 08:15:19.011003 2026] [security2:error] [pid 402041:tid 402239] [client 87.116.180.198:13855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ux4iENNLP6XjiHQtmPAAAAdE"]
[Tue Jul 21 08:15:19.011125 2026] [security2:error] [pid 402041:tid 402239] [client 87.116.180.198:13855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ux4iENNLP6XjiHQtmPAAAAdE"]
[Tue Jul 21 08:15:19.203450 2026] [security2:error] [pid 402041:tid 402246] [client 20.226.60.151:49358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9Ux4iENNLP6XjiHQtmSQAAAdg"]
[Tue Jul 21 08:15:19.500404 2026] [security2:error] [pid 402041:tid 402292] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Ux4iENNLP6XjiHQtmTgACBkE"]
[Tue Jul 21 08:15:19.516763 2026] [autoindex:error] [pid 402041:tid 402190] [client 200.160.3.217:53904] AH01276: Cannot serve directory /home4/serric15/voztricolor.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:15:19.646414 2026] [security2:error] [pid 402041:tid 402253] [client 20.226.60.151:49263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/k2.php"] [unique_id "al9Ux4iENNLP6XjiHQtmVgAAAd8"]
[Tue Jul 21 08:15:19.868902 2026] [security2:error] [pid 402041:tid 402268] [client 4.194.24.143:20591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/000.php"] [unique_id "al9Ux4iENNLP6XjiHQtmXQAAAe4"]
[Tue Jul 21 08:15:19.944185 2026] [security2:error] [pid 402041:tid 402184] [client 20.226.60.151:48798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9Ux4iENNLP6XjiHQtmYQAAAZo"]
[Tue Jul 21 08:15:20.135559 2026] [security2:error] [pid 402041:tid 402214] [client 102.206.115.33:61372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UyIiENNLP6XjiHQtmZAAAAbg"]
[Tue Jul 21 08:15:20.135744 2026] [security2:error] [pid 402041:tid 402214] [client 102.206.115.33:61372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UyIiENNLP6XjiHQtmZAAAAbg"]
[Tue Jul 21 08:15:20.261171 2026] [security2:error] [pid 402041:tid 402167] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UyIiENNLP6XjiHQtmbAACCHs"]
[Tue Jul 21 08:15:20.261303 2026] [security2:error] [pid 402041:tid 402294] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UyIiENNLP6XjiHQtmbAACCHs"]
[Tue Jul 21 08:15:20.490809 2026] [security2:error] [pid 402041:tid 402105] [remote 51.222.168.161:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "farmaciafarmula.com.br"] [uri "/"] [unique_id "al9UyIiENNLP6XjiHQtmcwAB0T0"]
[Tue Jul 21 08:15:20.491038 2026] [security2:error] [pid 402041:tid 402239] [client 51.222.168.161:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "farmaciafarmula.com.br"] [uri "/"] [unique_id "al9UyIiENNLP6XjiHQtmcwAB0T0"]
[Tue Jul 21 08:15:20.494684 2026] [security2:error] [pid 402041:tid 402064] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UyIiENNLP6XjiHQtmdAABpxQ"]
[Tue Jul 21 08:15:20.494826 2026] [security2:error] [pid 402041:tid 402197] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9UyIiENNLP6XjiHQtmdAABpxQ"]
[Tue Jul 21 08:15:20.678610 2026] [security2:error] [pid 402041:tid 402298] [client 20.226.60.151:48846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9UyIiENNLP6XjiHQtmfwAAAgw"]
[Tue Jul 21 08:15:20.765214 2026] [security2:error] [pid 402041:tid 402299] [client 14.245.224.124:58245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9UyIiENNLP6XjiHQtmhwAAAg0"]
[Tue Jul 21 08:15:20.765347 2026] [security2:error] [pid 402041:tid 402299] [client 14.245.224.124:58245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9UyIiENNLP6XjiHQtmhwAAAg0"]
[Tue Jul 21 08:15:20.849708 2026] [security2:error] [pid 402041:tid 402247] [client 115.134.11.136:53828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UyIiENNLP6XjiHQtmiAAAAdk"]
[Tue Jul 21 08:15:20.893293 2026] [security2:error] [pid 402041:tid 402257] [client 4.194.24.143:2305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/002.php"] [unique_id "al9UyIiENNLP6XjiHQtmiQAAAeM"]
[Tue Jul 21 08:15:21.114294 2026] [security2:error] [pid 402041:tid 402203] [client 20.226.60.151:48825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9UyYiENNLP6XjiHQtmjQAAAa0"]
[Tue Jul 21 08:15:21.410631 2026] [security2:error] [pid 402041:tid 402195] [client 187.125.243.197:64655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UyYiENNLP6XjiHQtmngAAAaU"]
[Tue Jul 21 08:15:21.410845 2026] [security2:error] [pid 402041:tid 402195] [client 187.125.243.197:64655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9UyYiENNLP6XjiHQtmngAAAaU"]
[Tue Jul 21 08:15:21.528299 2026] [security2:error] [pid 402041:tid 402287] [client 20.226.60.151:48791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/for.php"] [unique_id "al9UyYiENNLP6XjiHQtmqwAAAgE"]
[Tue Jul 21 08:15:21.623459 2026] [autoindex:error] [pid 402041:tid 402266] [client 162.14.66.219:43270] AH01276: Cannot serve directory /home2/reser379/megaroteiros.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:15:21.830758 2026] [security2:error] [pid 402041:tid 402191] [client 151.63.71.144:61956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9UyYiENNLP6XjiHQtm2AAAAaE"]
[Tue Jul 21 08:15:21.830883 2026] [security2:error] [pid 402041:tid 402191] [client 151.63.71.144:61956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9UyYiENNLP6XjiHQtm2AAAAaE"]
[Tue Jul 21 08:15:21.947667 2026] [security2:error] [pid 402041:tid 402239] [client 4.194.24.143:21717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/0x.php"] [unique_id "al9UyYiENNLP6XjiHQtm4QAAAdE"]
[Tue Jul 21 08:15:21.997315 2026] [security2:error] [pid 402041:tid 402073] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UyYiENNLP6XjiHQtm5AAB1x0"]
[Tue Jul 21 08:15:21.997504 2026] [security2:error] [pid 402041:tid 402245] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UyYiENNLP6XjiHQtm5AAB1x0"]
[Tue Jul 21 08:15:22.022622 2026] [security2:error] [pid 402041:tid 402268] [client 74.249.245.134:15417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/simple.php"] [unique_id "al9UyoiENNLP6XjiHQtm5wAAAe4"]
[Tue Jul 21 08:15:22.146216 2026] [security2:error] [pid 402041:tid 402243] [client 20.104.96.117:54093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/777.php"] [unique_id "al9UyoiENNLP6XjiHQtm6wAAAdU"]
[Tue Jul 21 08:15:22.312546 2026] [security2:error] [pid 402041:tid 402222] [client 20.226.60.151:48805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/raw.php"] [unique_id "al9UyoiENNLP6XjiHQtm9QAAAcA"]
[Tue Jul 21 08:15:22.691969 2026] [security2:error] [pid 402041:tid 402295] [client 65.21.113.253:46324] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9UyoiENNLP6XjiHQtm7wAAAgk"]
[Tue Jul 21 08:15:22.892689 2026] [security2:error] [pid 402041:tid 402251] [client 125.18.144.2:7649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UyoiENNLP6XjiHQtnCQAAAd0"]
[Tue Jul 21 08:15:22.892787 2026] [security2:error] [pid 402041:tid 402251] [client 125.18.144.2:7649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9UyoiENNLP6XjiHQtnCQAAAd0"]
[Tue Jul 21 08:15:23.040538 2026] [security2:error] [pid 402041:tid 402227] [client 4.194.24.143:21943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/0xd.php"] [unique_id "al9Uy4iENNLP6XjiHQtnDwAAAcU"]
[Tue Jul 21 08:15:23.407527 2026] [security2:error] [pid 402041:tid 402282] [client 114.119.135.57:46601] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.insp1.com.br"] [uri "/single-post/2020/03/11/Inicia%C3%A7%C3%A3o-ao-racioc%C3%ADnio-l%C3%B3gico-com-o-1%C2%BA-ano-do-INSP-J%C3%BAnior"] [unique_id "al9Uy4iENNLP6XjiHQtnGAAAAfw"], referer: https://www.insp1.com.br/inicio/page/11
[Tue Jul 21 08:15:23.517244 2026] [security2:error] [pid 402041:tid 402298] [client 74.249.245.134:15381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/404.php"] [unique_id "al9Uy4iENNLP6XjiHQtnGgAAAgw"]
[Tue Jul 21 08:15:23.700969 2026] [security2:error] [pid 402041:tid 402241] [client 185.213.175.37:30390] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.projetoflechas.org.br"] [uri "/"] [unique_id "al9Uy4iENNLP6XjiHQtnIgAAAdM"]
[Tue Jul 21 08:15:23.985305 2026] [security2:error] [pid 402041:tid 402229] [client 20.220.225.223:30709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/ace2.php"] [unique_id "al9Uy4iENNLP6XjiHQtnKwAAAcc"]
[Tue Jul 21 08:15:24.059543 2026] [security2:error] [pid 402041:tid 402233] [client 4.194.24.143:21727] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ecochamabrasil.com"] [uri "/1.php"] [unique_id "al9UzIiENNLP6XjiHQtnLgAAAcs"]
[Tue Jul 21 08:15:24.059649 2026] [security2:error] [pid 402041:tid 402233] [client 4.194.24.143:21727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/1.php"] [unique_id "al9UzIiENNLP6XjiHQtnLgAAAcs"]
[Tue Jul 21 08:15:24.247376 2026] [security2:error] [pid 402041:tid 402283] [client 150.129.202.39:65439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UzIiENNLP6XjiHQtnMQAAAf0"]
[Tue Jul 21 08:15:24.247509 2026] [security2:error] [pid 402041:tid 402283] [client 150.129.202.39:65439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UzIiENNLP6XjiHQtnMQAAAf0"]
[Tue Jul 21 08:15:24.259326 2026] [security2:error] [pid 402041:tid 402256] [client 120.56.162.40:64210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UzIiENNLP6XjiHQtnMgAAAeI"]
[Tue Jul 21 08:15:24.259426 2026] [security2:error] [pid 402041:tid 402256] [client 120.56.162.40:64210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UzIiENNLP6XjiHQtnMgAAAeI"]
[Tue Jul 21 08:15:24.624167 2026] [security2:error] [pid 402041:tid 402189] [client 141.11.107.74:60009] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "resultados.liranesuliano.com.br"] [uri "/"] [unique_id "al9UzIiENNLP6XjiHQtnPAAAAZ8"]
[Tue Jul 21 08:15:24.637411 2026] [security2:error] [pid 402041:tid 402242] [client 141.11.107.74:60013] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.liranesuliano.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9UzIiENNLP6XjiHQtnPgAAAdQ"]
[Tue Jul 21 08:15:24.637412 2026] [security2:error] [pid 402041:tid 402187] [client 141.11.107.74:60014] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.liranesuliano.com.br"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "al9UzIiENNLP6XjiHQtnPQAAAZ0"]
[Tue Jul 21 08:15:24.643324 2026] [security2:error] [pid 402041:tid 402224] [client 141.11.107.74:60040] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.liranesuliano.com.br"] [uri "/"] [unique_id "al9UzIiENNLP6XjiHQtnPwAAAcI"]
[Tue Jul 21 08:15:24.646026 2026] [security2:error] [pid 402041:tid 402257] [client 141.11.107.74:60026] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.liranesuliano.com.br"] [uri "/"] [unique_id "al9UzIiENNLP6XjiHQtnQAAAAeM"]
[Tue Jul 21 08:15:24.660637 2026] [security2:error] [pid 402041:tid 402292] [client 141.11.107.74:60054] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liranesuliano.com.br"] [uri "/"] [unique_id "al9UzIiENNLP6XjiHQtnQQAAAgY"]
[Tue Jul 21 08:15:24.666714 2026] [security2:error] [pid 402041:tid 402228] [client 141.11.107.74:60066] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.liranesuliano.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9UzIiENNLP6XjiHQtnQgAAAcY"]
[Tue Jul 21 08:15:24.674263 2026] [security2:error] [pid 402041:tid 402220] [client 141.11.107.74:60067] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.liranesuliano.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9UzIiENNLP6XjiHQtnQwAAAb4"]
[Tue Jul 21 08:15:24.681023 2026] [security2:error] [pid 402041:tid 402251] [client 141.11.107.74:60072] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ftp.liranesuliano.com.br"] [uri "/"] [unique_id "al9UzIiENNLP6XjiHQtnRQAAAd0"]
[Tue Jul 21 08:15:24.698351 2026] [security2:error] [pid 402041:tid 402234] [client 141.11.107.74:60092] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.liranesuliano.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9UzIiENNLP6XjiHQtnRgAAAcw"]
[Tue Jul 21 08:15:24.884165 2026] [security2:error] [pid 402041:tid 402210] [client 62.102.148.158:51748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9UzIiENNLP6XjiHQtnSwAAAbQ"]
[Tue Jul 21 08:15:24.884260 2026] [security2:error] [pid 402041:tid 402210] [client 62.102.148.158:51748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9UzIiENNLP6XjiHQtnSwAAAbQ"]
[Tue Jul 21 08:15:25.083988 2026] [autoindex:error] [pid 402041:tid 402239] [client 168.144.100.227:57344] AH01276: Cannot serve directory /home4/bcaccj52/accjbr.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://academiacatedra.com//wp-login.php
[Tue Jul 21 08:15:25.091170 2026] [security2:error] [pid 402041:tid 402255] [client 4.194.24.143:21941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/100.php"] [unique_id "al9UzYiENNLP6XjiHQtnVQAAAeE"]
[Tue Jul 21 08:15:25.160452 2026] [security2:error] [pid 402041:tid 402098] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UzYiENNLP6XjiHQtnVgABsTY"]
[Tue Jul 21 08:15:25.160612 2026] [security2:error] [pid 402041:tid 402207] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9UzYiENNLP6XjiHQtnVgABsTY"]
[Tue Jul 21 08:15:25.256845 2026] [security2:error] [pid 402041:tid 402280] [client 103.151.46.103:61665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UzYiENNLP6XjiHQtnWgAAAfo"]
[Tue Jul 21 08:15:25.256986 2026] [security2:error] [pid 402041:tid 402280] [client 103.151.46.103:61665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9UzYiENNLP6XjiHQtnWgAAAfo"]
[Tue Jul 21 08:15:25.475936 2026] [security2:error] [pid 402041:tid 402288] [client 117.210.135.0:55089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UzYiENNLP6XjiHQtnZgAAAgI"]
[Tue Jul 21 08:15:25.476046 2026] [security2:error] [pid 402041:tid 402288] [client 117.210.135.0:55089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UzYiENNLP6XjiHQtnZgAAAgI"]
[Tue Jul 21 08:15:25.504761 2026] [security2:error] [pid 402041:tid 402300] [client 74.249.245.134:15104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/file3.php"] [unique_id "al9UzYiENNLP6XjiHQtnZwAAAg4"]
[Tue Jul 21 08:15:26.048670 2026] [security2:error] [pid 402041:tid 402260] [client 20.220.225.223:58938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9UzoiENNLP6XjiHQtncwAAAeY"]
[Tue Jul 21 08:15:26.074959 2026] [autoindex:error] [pid 402041:tid 402089] [remote 43.161.234.148:0] AH01276: Cannot serve directory /home1/tavar035/brasilcertdigital.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://brasilcertdigital.online
[Tue Jul 21 08:15:26.115304 2026] [security2:error] [pid 402041:tid 402200] [client 4.194.24.143:21735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/12.php"] [unique_id "al9UzoiENNLP6XjiHQtndgAAAao"]
[Tue Jul 21 08:15:26.124239 2026] [security2:error] [pid 402041:tid 402250] [client 185.198.240.186:29153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9UzoiENNLP6XjiHQtndQAAAdw"]
[Tue Jul 21 08:15:26.143502 2026] [security2:error] [pid 402041:tid 402183] [client 20.220.225.223:30704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.lasferas.com"] [uri "/ms.php"] [unique_id "al9UzoiENNLP6XjiHQtndwAAAZk"]
[Tue Jul 21 08:15:26.351747 2026] [security2:error] [pid 402041:tid 402151] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UzoiENNLP6XjiHQtneQABrms"]
[Tue Jul 21 08:15:26.351868 2026] [security2:error] [pid 402041:tid 402204] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9UzoiENNLP6XjiHQtneQABrms"]
[Tue Jul 21 08:15:26.672276 2026] [core:error] [pid 402041:tid 402062] [remote 52.167.144.201:17807] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:26.672295 2026] [core:error] [pid 402041:tid 402062] [remote 52.167.144.201:17807] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:26.766235 2026] [security2:error] [pid 402041:tid 402186] [client 162.219.176.3:60894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9UzoiENNLP6XjiHQtnigAAAZw"]
[Tue Jul 21 08:15:26.766332 2026] [security2:error] [pid 402041:tid 402186] [client 162.219.176.3:60894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9UzoiENNLP6XjiHQtnigAAAZw"]
[Tue Jul 21 08:15:26.970051 2026] [security2:error] [pid 402041:tid 402230] [client 74.249.245.134:15366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/wp-mail.php"] [unique_id "al9UzoiENNLP6XjiHQtnjgAAAcg"]
[Tue Jul 21 08:15:27.130566 2026] [security2:error] [pid 402041:tid 402294] [client 20.104.96.117:63028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/for.php"] [unique_id "al9Uz4iENNLP6XjiHQtnlQAAAgg"]
[Tue Jul 21 08:15:27.171134 2026] [security2:error] [pid 402041:tid 402207] [client 4.194.24.143:21264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/123.php"] [unique_id "al9Uz4iENNLP6XjiHQtnlgAAAbE"]
[Tue Jul 21 08:15:27.857981 2026] [security2:error] [pid 402041:tid 402165] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uz4iENNLP6XjiHQtnpgAB23k"]
[Tue Jul 21 08:15:27.858120 2026] [security2:error] [pid 402041:tid 402249] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Uz4iENNLP6XjiHQtnpgAB23k"]
[Tue Jul 21 08:15:28.048282 2026] [security2:error] [pid 402041:tid 402292] [client 20.220.225.223:24246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9U0IiENNLP6XjiHQtnsAAAAgY"]
[Tue Jul 21 08:15:28.232776 2026] [security2:error] [pid 402041:tid 402200] [client 4.194.24.143:26987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/13.php"] [unique_id "al9U0IiENNLP6XjiHQtntAAAAao"]
[Tue Jul 21 08:15:28.241210 2026] [security2:error] [pid 402041:tid 402194] [client 38.100.221.102:18146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U0IiENNLP6XjiHQtntQAAAaQ"]
[Tue Jul 21 08:15:28.241598 2026] [security2:error] [pid 402041:tid 402194] [client 38.100.221.102:18146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U0IiENNLP6XjiHQtntQAAAaQ"]
[Tue Jul 21 08:15:28.451363 2026] [security2:error] [pid 402041:tid 402286] [client 74.249.245.134:15115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/about.php"] [unique_id "al9U0IiENNLP6XjiHQtntwAAAgA"]
[Tue Jul 21 08:15:28.695051 2026] [security2:error] [pid 402041:tid 402260] [client 103.78.200.11:56839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U0IiENNLP6XjiHQtnxQAAAeY"]
[Tue Jul 21 08:15:28.695223 2026] [security2:error] [pid 402041:tid 402260] [client 103.78.200.11:56839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U0IiENNLP6XjiHQtnxQAAAeY"]
[Tue Jul 21 08:15:28.926417 2026] [security2:error] [pid 402041:tid 402211] [client 154.208.47.43:51733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9U0IiENNLP6XjiHQtnxwAAAbU"]
[Tue Jul 21 08:15:28.926533 2026] [security2:error] [pid 402041:tid 402211] [client 154.208.47.43:51733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9U0IiENNLP6XjiHQtnxwAAAbU"]
[Tue Jul 21 08:15:29.098064 2026] [security2:error] [pid 402041:tid 402248] [client 173.252.95.5:60750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9U0YiENNLP6XjiHQtnzQAAAdo"]
[Tue Jul 21 08:15:29.301901 2026] [security2:error] [pid 402041:tid 402279] [client 4.194.24.143:26964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/133.php"] [unique_id "al9U0YiENNLP6XjiHQtn0QAAAfk"]
[Tue Jul 21 08:15:29.533582 2026] [security2:error] [pid 402041:tid 402258] [client 198.54.129.60:35154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9U0YiENNLP6XjiHQtn1QAAAeQ"]
[Tue Jul 21 08:15:29.533675 2026] [security2:error] [pid 402041:tid 402258] [client 198.54.129.60:35154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9U0YiENNLP6XjiHQtn1QAAAeQ"]
[Tue Jul 21 08:15:29.614306 2026] [security2:error] [pid 402041:tid 402254] [client 193.36.225.160:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lunarium.tec.br"] [uri "/"] [unique_id "al9U0YiENNLP6XjiHQtn1gAAAeA"]
[Tue Jul 21 08:15:29.736629 2026] [security2:error] [pid 402041:tid 402208] [client 87.116.180.198:14036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U0YiENNLP6XjiHQtn3gAAAbI"]
[Tue Jul 21 08:15:29.736738 2026] [security2:error] [pid 402041:tid 402208] [client 87.116.180.198:14036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U0YiENNLP6XjiHQtn3gAAAbI"]
[Tue Jul 21 08:15:29.926246 2026] [security2:error] [pid 402041:tid 402117] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9U0YiENNLP6XjiHQtn5QABkUk"]
[Tue Jul 21 08:15:29.926391 2026] [security2:error] [pid 402041:tid 402175] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9U0YiENNLP6XjiHQtn5QABkUk"]
[Tue Jul 21 08:15:30.140334 2026] [security2:error] [pid 402041:tid 402282] [client 193.36.225.160:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lunarium.tec.br"] [uri "/wp-includes/css/buttons.css"] [unique_id "al9U0oiENNLP6XjiHQtn6wAAAfw"]
[Tue Jul 21 08:15:30.193571 2026] [core:error] [pid 402041:tid 402247] [client 66.249.66.67:36501] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:30.193594 2026] [core:error] [pid 402041:tid 402247] [client 66.249.66.67:36501] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:30.339361 2026] [security2:error] [pid 402041:tid 402127] [remote 124.55.178.99:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fidellium.com"] [uri "/wp-login.php"] [unique_id "al9U0oiENNLP6XjiHQtn9QABz1M"]
[Tue Jul 21 08:15:30.402661 2026] [security2:error] [pid 402041:tid 402235] [client 4.194.24.143:21718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/155.php"] [unique_id "al9U0oiENNLP6XjiHQtn9wAAAc0"]
[Tue Jul 21 08:15:30.567855 2026] [security2:error] [pid 402041:tid 402178] [client 65.21.113.253:55852] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9U0oiENNLP6XjiHQtn7AAAAZQ"]
[Tue Jul 21 08:15:30.688596 2026] [security2:error] [pid 402041:tid 402283] [client 193.36.225.160:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lunarium.tec.br"] [uri "/media/system/js/core.js"] [unique_id "al9U0oiENNLP6XjiHQtoAAAAAf0"]
[Tue Jul 21 08:15:30.792878 2026] [security2:error] [pid 402041:tid 402186] [client 102.206.115.33:61830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U0oiENNLP6XjiHQtoBAAAAZw"]
[Tue Jul 21 08:15:30.793003 2026] [security2:error] [pid 402041:tid 402186] [client 102.206.115.33:61830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U0oiENNLP6XjiHQtoBAAAAZw"]
[Tue Jul 21 08:15:31.089090 2026] [security2:error] [pid 402041:tid 402085] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U04iENNLP6XjiHQtoBwABmyk"]
[Tue Jul 21 08:15:31.089268 2026] [security2:error] [pid 402041:tid 402185] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U04iENNLP6XjiHQtoBwABmyk"]
[Tue Jul 21 08:15:31.135560 2026] [security2:error] [pid 402041:tid 402144] [remote 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9U04iENNLP6XjiHQtoCAACBmQ"]
[Tue Jul 21 08:15:31.135700 2026] [security2:error] [pid 402041:tid 402292] [client 2001:4490:4431:194f:f9ce:baae:5f87:bb6b:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9U04iENNLP6XjiHQtoCAACBmQ"]
[Tue Jul 21 08:15:31.161601 2026] [security2:error] [pid 402041:tid 402187] [client 20.220.225.223:52621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9U04iENNLP6XjiHQtoCQAAAZ0"]
[Tue Jul 21 08:15:31.161879 2026] [security2:error] [pid 402041:tid 402206] [client 74.249.245.134:15132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/adminfuns.php"] [unique_id "al9U04iENNLP6XjiHQtoCgAAAbA"]
[Tue Jul 21 08:15:31.191131 2026] [security2:error] [pid 402041:tid 402233] [client 61.1.167.83:54479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U04iENNLP6XjiHQtoCwAAAcs"]
[Tue Jul 21 08:15:31.200973 2026] [security2:error] [pid 402041:tid 402233] [client 61.1.167.83:54479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U04iENNLP6XjiHQtoCwAAAcs"]
[Tue Jul 21 08:15:31.384118 2026] [security2:error] [pid 402041:tid 402262] [client 115.134.11.136:54227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U04iENNLP6XjiHQtoEgAAAeg"]
[Tue Jul 21 08:15:31.423602 2026] [security2:error] [pid 402041:tid 402189] [client 14.245.224.124:58632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9U04iENNLP6XjiHQtoFAAAAZ8"]
[Tue Jul 21 08:15:31.423705 2026] [security2:error] [pid 402041:tid 402189] [client 14.245.224.124:58632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9U04iENNLP6XjiHQtoFAAAAZ8"]
[Tue Jul 21 08:15:31.457758 2026] [security2:error] [pid 402041:tid 402257] [client 4.194.24.143:36535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/166.php"] [unique_id "al9U04iENNLP6XjiHQtoFQAAAeM"]
[Tue Jul 21 08:15:31.606004 2026] [security2:error] [pid 402041:tid 402253] [client 20.104.96.117:58225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/ssla.php"] [unique_id "al9U04iENNLP6XjiHQtoFwAAAd8"]
[Tue Jul 21 08:15:31.872740 2026] [security2:error] [pid 402041:tid 402278] [client 187.125.243.197:65122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9U04iENNLP6XjiHQtoIgAAAfg"]
[Tue Jul 21 08:15:31.872888 2026] [security2:error] [pid 402041:tid 402278] [client 187.125.243.197:65122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9U04iENNLP6XjiHQtoIgAAAfg"]
[Tue Jul 21 08:15:32.000740 2026] [security2:error] [pid 402041:tid 402184] [client 103.151.46.103:62167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U1IiENNLP6XjiHQtoJQAAAZo"]
[Tue Jul 21 08:15:32.000861 2026] [security2:error] [pid 402041:tid 402184] [client 103.151.46.103:62167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U1IiENNLP6XjiHQtoJQAAAZo"]
[Tue Jul 21 08:15:32.043657 2026] [security2:error] [pid 402041:tid 402241] [client 20.104.96.117:54662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dentistaguarulhos.com.br"] [uri "/zc-131.php"] [unique_id "al9U1IiENNLP6XjiHQtoJgAAAdM"]
[Tue Jul 21 08:15:32.388722 2026] [security2:error] [pid 402041:tid 402254] [client 34.26.234.193:52461] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oppbrazil.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9U1IiENNLP6XjiHQtoLwAAAeA"]
[Tue Jul 21 08:15:32.481961 2026] [security2:error] [pid 402041:tid 402125] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U1IiENNLP6XjiHQtoMAAB9VE"]
[Tue Jul 21 08:15:32.482131 2026] [security2:error] [pid 402041:tid 402275] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U1IiENNLP6XjiHQtoMAAB9VE"]
[Tue Jul 21 08:15:32.518639 2026] [security2:error] [pid 402041:tid 402265] [client 4.194.24.143:21011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/2.php"] [unique_id "al9U1IiENNLP6XjiHQtoMQAAAes"]
[Tue Jul 21 08:15:32.567938 2026] [security2:error] [pid 402041:tid 402199] [client 20.220.225.223:24223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9U1IiENNLP6XjiHQtoMgAAAak"]
[Tue Jul 21 08:15:32.852330 2026] [security2:error] [pid 402041:tid 402288] [client 125.18.144.2:22752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9U1IiENNLP6XjiHQtoPgAAAgI"]
[Tue Jul 21 08:15:32.852460 2026] [security2:error] [pid 402041:tid 402288] [client 125.18.144.2:22752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9U1IiENNLP6XjiHQtoPgAAAgI"]
[Tue Jul 21 08:15:32.886263 2026] [security2:error] [pid 402041:tid 402217] [client 34.26.234.193:63358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.234.26.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oppbrazil.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U1IiENNLP6XjiHQtoPwAAAbs"]
[Tue Jul 21 08:15:33.720944 2026] [security2:error] [pid 402041:tid 402182] [client 4.194.24.143:13387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/2026w.php"] [unique_id "al9U1YiENNLP6XjiHQtoVQAAAZg"]
[Tue Jul 21 08:15:33.964000 2026] [security2:error] [pid 402041:tid 402188] [client 20.10.88.201:22848] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arthromdcanada.online"] [uri "/robots.txt"] [unique_id "al9U1YiENNLP6XjiHQtoYQAAAZ4"]
[Tue Jul 21 08:15:34.141764 2026] [core:error] [pid 402041:tid 402199] [client 66.249.66.68:58427] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:34.141799 2026] [core:error] [pid 402041:tid 402199] [client 66.249.66.68:58427] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:15:34.250169 2026] [security2:error] [pid 402041:tid 402186] [client 74.249.245.134:15134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/php8.php"] [unique_id "al9U1oiENNLP6XjiHQtoZgAAAZw"]
[Tue Jul 21 08:15:34.289040 2026] [security2:error] [pid 402041:tid 402204] [client 20.220.225.223:24199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wander.php"] [unique_id "al9U1oiENNLP6XjiHQtoZwAAAa4"]
[Tue Jul 21 08:15:34.744678 2026] [security2:error] [pid 402041:tid 402270] [client 4.194.24.143:21920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/222.php"] [unique_id "al9U1oiENNLP6XjiHQtocgAAAfA"]
[Tue Jul 21 08:15:34.889976 2026] [security2:error] [pid 402041:tid 402295] [client 120.56.162.40:64728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U1oiENNLP6XjiHQtodgAAAgk"]
[Tue Jul 21 08:15:34.890292 2026] [security2:error] [pid 402041:tid 402295] [client 120.56.162.40:64728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U1oiENNLP6XjiHQtodgAAAgk"]
[Tue Jul 21 08:15:34.951570 2026] [security2:error] [pid 402041:tid 402228] [client 150.129.202.39:13058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U1oiENNLP6XjiHQtofQAAAcY"]
[Tue Jul 21 08:15:34.951666 2026] [security2:error] [pid 402041:tid 402228] [client 150.129.202.39:13058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U1oiENNLP6XjiHQtofQAAAcY"]
[Tue Jul 21 08:15:35.027203 2026] [security2:error] [pid 402041:tid 402216] [client 20.220.225.223:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/wander.php"] [unique_id "al9U14iENNLP6XjiHQtofgAAAbo"]
[Tue Jul 21 08:15:35.127532 2026] [security2:error] [pid 402041:tid 402054] [remote 72.167.132.114:35624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medoraldracena.com.br"] [uri "/wp-login.php"] [unique_id "al9U14iENNLP6XjiHQtogQACCgo"]
[Tue Jul 21 08:15:35.263080 2026] [security2:error] [pid 402041:tid 402116] [remote 45.117.83.212:52212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9U14iENNLP6XjiHQtogwACBUg"]
[Tue Jul 21 08:15:35.379266 2026] [security2:error] [pid 402041:tid 402220] [client 151.63.71.144:62502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9U14iENNLP6XjiHQtohAAAAb4"]
[Tue Jul 21 08:15:35.379434 2026] [security2:error] [pid 402041:tid 402220] [client 151.63.71.144:62502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9U14iENNLP6XjiHQtohAAAAb4"]
[Tue Jul 21 08:15:35.576608 2026] [security2:error] [pid 402041:tid 402222] [client 20.220.225.223:24195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/jga.php"] [unique_id "al9U14iENNLP6XjiHQtojgAAAcA"]
[Tue Jul 21 08:15:35.811286 2026] [security2:error] [pid 402041:tid 402229] [client 198.54.129.60:56756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9U14iENNLP6XjiHQtokgAAAcc"]
[Tue Jul 21 08:15:35.811427 2026] [security2:error] [pid 402041:tid 402229] [client 198.54.129.60:56756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9U14iENNLP6XjiHQtokgAAAcc"]
[Tue Jul 21 08:15:35.820436 2026] [security2:error] [pid 402041:tid 402195] [client 4.194.24.143:36482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/2p.php"] [unique_id "al9U14iENNLP6XjiHQtolQAAAaU"]
[Tue Jul 21 08:15:35.845779 2026] [security2:error] [pid 402041:tid 402098] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9U14iENNLP6XjiHQtomgAB1zY"]
[Tue Jul 21 08:15:35.845941 2026] [security2:error] [pid 402041:tid 402245] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9U14iENNLP6XjiHQtomgAB1zY"]
[Tue Jul 21 08:15:35.909057 2026] [security2:error] [pid 402041:tid 402255] [client 74.249.245.134:31360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/info.php"] [unique_id "al9U14iENNLP6XjiHQtonAAAAeE"]
[Tue Jul 21 08:15:35.909846 2026] [security2:error] [pid 402041:tid 402206] [client 62.102.148.158:51664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9U14iENNLP6XjiHQtonQAAAbA"]
[Tue Jul 21 08:15:35.909957 2026] [security2:error] [pid 402041:tid 402206] [client 62.102.148.158:51664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9U14iENNLP6XjiHQtonQAAAbA"]
[Tue Jul 21 08:15:36.047095 2026] [security2:error] [pid 402041:tid 402190] [client 117.210.135.0:55733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U2IiENNLP6XjiHQtopgAAAaA"]
[Tue Jul 21 08:15:36.047224 2026] [security2:error] [pid 402041:tid 402190] [client 117.210.135.0:55733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U2IiENNLP6XjiHQtopgAAAaA"]
[Tue Jul 21 08:15:36.822362 2026] [security2:error] [pid 402041:tid 402096] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U2IiENNLP6XjiHQto2wAB7DQ"]
[Tue Jul 21 08:15:36.822510 2026] [security2:error] [pid 402041:tid 402266] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U2IiENNLP6XjiHQto2wAB7DQ"]
[Tue Jul 21 08:15:36.840043 2026] [security2:error] [pid 402041:tid 402195] [client 20.220.225.223:52670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/jga.php"] [unique_id "al9U2IiENNLP6XjiHQto3gAAAaU"]
[Tue Jul 21 08:15:36.907041 2026] [security2:error] [pid 402041:tid 402178] [client 4.194.24.143:13385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/2p.update.php"] [unique_id "al9U2IiENNLP6XjiHQto4QAAAZQ"]
[Tue Jul 21 08:15:36.947805 2026] [security2:error] [pid 402041:tid 402080] [remote 124.55.178.99:44940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9U2IiENNLP6XjiHQto4gAB2SQ"]
[Tue Jul 21 08:15:37.646643 2026] [security2:error] [pid 402041:tid 402203] [client 74.7.241.128:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "nutrawidenews.com"] [uri "/cgi-sys/404.html"] [unique_id "al9U2YiENNLP6XjiHQtpBgAAAa0"]
[Tue Jul 21 08:15:37.648223 2026] [security2:error] [pid 402041:tid 402226] [client 74.7.241.128:51422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "nutrawidenews.com"] [uri "/robots.txt"] [unique_id "al9U2YiENNLP6XjiHQtpBAABxE4"]
[Tue Jul 21 08:15:37.756500 2026] [security2:error] [pid 402041:tid 402201] [client 20.197.192.193:61065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9U2YiENNLP6XjiHQtpCQAAAas"]
[Tue Jul 21 08:15:38.058099 2026] [security2:error] [pid 402041:tid 402175] [client 4.194.24.143:14256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/3pjcpmfsd8b.php"] [unique_id "al9U2oiENNLP6XjiHQtpFQAAAZE"]
[Tue Jul 21 08:15:38.287368 2026] [security2:error] [pid 402041:tid 402288] [client 74.249.245.134:31391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/edit.php"] [unique_id "al9U2oiENNLP6XjiHQtpIAAAAgI"]
[Tue Jul 21 08:15:38.547338 2026] [security2:error] [pid 402041:tid 402045] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U2oiENNLP6XjiHQtpKQAB6wE"]
[Tue Jul 21 08:15:38.547493 2026] [security2:error] [pid 402041:tid 402265] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U2oiENNLP6XjiHQtpKQAB6wE"]
[Tue Jul 21 08:15:38.896581 2026] [security2:error] [pid 402041:tid 402281] [client 38.100.221.102:17433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U2oiENNLP6XjiHQtpRAAAAfs"]
[Tue Jul 21 08:15:38.896694 2026] [security2:error] [pid 402041:tid 402281] [client 38.100.221.102:17433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U2oiENNLP6XjiHQtpRAAAAfs"]
[Tue Jul 21 08:15:39.111320 2026] [security2:error] [pid 402041:tid 402214] [client 4.194.24.143:21460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/403.php"] [unique_id "al9U24iENNLP6XjiHQtpVQAAAbg"]
[Tue Jul 21 08:15:39.218570 2026] [security2:error] [pid 402041:tid 402291] [client 20.197.192.193:52651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/wicked.php"] [unique_id "al9U24iENNLP6XjiHQtpWgAAAgU"]
[Tue Jul 21 08:15:39.220395 2026] [security2:error] [pid 402041:tid 402191] [client 20.220.225.223:24270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/x.php"] [unique_id "al9U24iENNLP6XjiHQtpWwAAAaE"]
[Tue Jul 21 08:15:39.266474 2026] [security2:error] [pid 402041:tid 402298] [client 20.197.192.193:63930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9U24iENNLP6XjiHQtpXwAAAgw"]
[Tue Jul 21 08:15:39.355632 2026] [security2:error] [pid 402041:tid 402251] [client 34.26.234.193:56146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.234.26.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oppbrazil.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U24iENNLP6XjiHQtpYgAAAd0"]
[Tue Jul 21 08:15:39.355725 2026] [security2:error] [pid 402041:tid 402251] [client 34.26.234.193:56146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oppbrazil.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U24iENNLP6XjiHQtpYgAAAd0"]
[Tue Jul 21 08:15:39.382623 2026] [security2:error] [pid 402041:tid 402176] [client 154.208.47.43:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9U24iENNLP6XjiHQtpZAAAAZI"]
[Tue Jul 21 08:15:39.382698 2026] [security2:error] [pid 402041:tid 402176] [client 154.208.47.43:52224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9U24iENNLP6XjiHQtpZAAAAZI"]
[Tue Jul 21 08:15:39.533951 2026] [security2:error] [pid 402041:tid 402223] [client 20.151.10.161:13280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9U24iENNLP6XjiHQtpaQAAAcE"]
[Tue Jul 21 08:15:39.577249 2026] [security2:error] [pid 402041:tid 402137] [remote 45.79.123.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wp-login.php"] [unique_id "al9U24iENNLP6XjiHQtpawAB2V0"]
[Tue Jul 21 08:15:39.769037 2026] [security2:error] [pid 402041:tid 402296] [client 74.249.245.134:15397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/166.php"] [unique_id "al9U24iENNLP6XjiHQtpdAAAAgo"]
[Tue Jul 21 08:15:40.033055 2026] [security2:error] [pid 402041:tid 402227] [client 20.220.225.223:55749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/x.php"] [unique_id "al9U3IiENNLP6XjiHQtpeAAAAcU"]
[Tue Jul 21 08:15:40.154047 2026] [security2:error] [pid 402041:tid 402289] [client 4.194.24.143:14106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/404.php"] [unique_id "al9U3IiENNLP6XjiHQtpfQAAAgM"]
[Tue Jul 21 08:15:40.246561 2026] [security2:error] [pid 402041:tid 402217] [client 103.78.200.11:57333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U3IiENNLP6XjiHQtphAAAAbs"]
[Tue Jul 21 08:15:40.246643 2026] [security2:error] [pid 402041:tid 402217] [client 103.78.200.11:57333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U3IiENNLP6XjiHQtphAAAAbs"]
[Tue Jul 21 08:15:40.398857 2026] [security2:error] [pid 402041:tid 402168] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9U3IiENNLP6XjiHQtphgABtHw"]
[Tue Jul 21 08:15:40.399042 2026] [security2:error] [pid 402041:tid 402210] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9U3IiENNLP6XjiHQtphgABtHw"]
[Tue Jul 21 08:15:40.446467 2026] [security2:error] [pid 402041:tid 402253] [client 87.116.180.198:13877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U3IiENNLP6XjiHQtphwAAAd8"]
[Tue Jul 21 08:15:40.446598 2026] [security2:error] [pid 402041:tid 402253] [client 87.116.180.198:13877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U3IiENNLP6XjiHQtphwAAAd8"]
[Tue Jul 21 08:15:40.796589 2026] [core:alert] [pid 402041:tid 402288] [client 69.171.230.3:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:15:40.993475 2026] [security2:error] [pid 402041:tid 402291] [client 74.7.241.157:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "vmccontabilidade.com.br"] [uri "/index.php"] [unique_id "al9U3IiENNLP6XjiHQtpjgAAAgU"]
[Tue Jul 21 08:15:40.994418 2026] [security2:error] [pid 402041:tid 402214] [client 74.7.241.157:39276] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "vmccontabilidade.com.br"] [uri "/robots.txt"] [unique_id "al9U3IiENNLP6XjiHQtpjAABuEY"]
[Tue Jul 21 08:15:41.188695 2026] [security2:error] [pid 402041:tid 402255] [client 4.194.24.143:13394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/4pjcpmfsd8b.php"] [unique_id "al9U3YiENNLP6XjiHQtppQAAAeE"]
[Tue Jul 21 08:15:41.261874 2026] [security2:error] [pid 402041:tid 402224] [client 20.151.10.161:13189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9U3YiENNLP6XjiHQtppgAAAcI"]
[Tue Jul 21 08:15:41.269378 2026] [security2:error] [pid 402041:tid 402199] [client 102.206.115.33:61978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U3YiENNLP6XjiHQtppwAAAak"]
[Tue Jul 21 08:15:41.269499 2026] [security2:error] [pid 402041:tid 402199] [client 102.206.115.33:61978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U3YiENNLP6XjiHQtppwAAAak"]
[Tue Jul 21 08:15:41.746291 2026] [core:alert] [pid 402041:tid 402226] [client 69.171.230.20:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:15:41.755390 2026] [security2:error] [pid 402041:tid 402143] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U3YiENNLP6XjiHQtpswABy2M"]
[Tue Jul 21 08:15:41.755535 2026] [security2:error] [pid 402041:tid 402233] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U3YiENNLP6XjiHQtpswABy2M"]
[Tue Jul 21 08:15:41.804283 2026] [security2:error] [pid 402041:tid 402242] [client 20.151.10.161:20443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9U3YiENNLP6XjiHQtptAAAAdQ"]
[Tue Jul 21 08:15:42.109211 2026] [security2:error] [pid 402041:tid 402130] [remote 209.97.182.179:37642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9U3oiENNLP6XjiHQtpvgAB31Y"]
[Tue Jul 21 08:15:42.151644 2026] [security2:error] [pid 402041:tid 402210] [client 14.245.224.124:59015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9U3oiENNLP6XjiHQtpvwAAAbQ"]
[Tue Jul 21 08:15:42.152195 2026] [security2:error] [pid 402041:tid 402210] [client 14.245.224.124:59015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9U3oiENNLP6XjiHQtpvwAAAbQ"]
[Tue Jul 21 08:15:42.235240 2026] [security2:error] [pid 402041:tid 402294] [client 4.194.24.143:21393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/666.php"] [unique_id "al9U3oiENNLP6XjiHQtpxgAAAgg"]
[Tue Jul 21 08:15:42.250785 2026] [security2:error] [pid 402041:tid 402292] [client 20.151.10.161:20365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9U3oiENNLP6XjiHQtpyAAAAgY"]
[Tue Jul 21 08:15:42.366516 2026] [security2:error] [pid 402041:tid 402200] [client 187.125.243.197:49214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9U3oiENNLP6XjiHQtpygAAAao"]
[Tue Jul 21 08:15:42.366905 2026] [security2:error] [pid 402041:tid 402200] [client 187.125.243.197:49214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9U3oiENNLP6XjiHQtpygAAAao"]
[Tue Jul 21 08:15:42.370125 2026] [security2:error] [pid 402041:tid 402214] [client 20.151.10.161:13296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/media.php"] [unique_id "al9U3oiENNLP6XjiHQtpywAAAbg"]
[Tue Jul 21 08:15:42.618243 2026] [security2:error] [pid 402041:tid 402230] [client 20.151.10.161:20452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/media.php"] [unique_id "al9U3oiENNLP6XjiHQtpzgAAAcg"]
[Tue Jul 21 08:15:42.635282 2026] [security2:error] [pid 402041:tid 402285] [client 74.249.245.134:15378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/8.php"] [unique_id "al9U3oiENNLP6XjiHQtpzwAAAf8"]
[Tue Jul 21 08:15:42.684158 2026] [core:alert] [pid 402041:tid 402199] [client 57.141.18.18:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:15:42.950496 2026] [security2:error] [pid 402041:tid 402174] [client 151.63.71.144:63045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9U3oiENNLP6XjiHQtp2wAAAZA"]
[Tue Jul 21 08:15:42.950899 2026] [security2:error] [pid 402041:tid 402174] [client 151.63.71.144:63045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9U3oiENNLP6XjiHQtp2wAAAZA"]
[Tue Jul 21 08:15:43.021726 2026] [security2:error] [pid 402041:tid 402146] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U34iENNLP6XjiHQtp3AABr2Y"]
[Tue Jul 21 08:15:43.021952 2026] [security2:error] [pid 402041:tid 402205] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U34iENNLP6XjiHQtp3AABr2Y"]
[Tue Jul 21 08:15:43.025521 2026] [security2:error] [pid 402041:tid 402226] [client 20.151.10.161:13287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/images.php"] [unique_id "al9U34iENNLP6XjiHQtp3QAAAcQ"]
[Tue Jul 21 08:15:43.162806 2026] [security2:error] [pid 402041:tid 402274] [client 20.151.10.161:20437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/images.php"] [unique_id "al9U34iENNLP6XjiHQtp4QAAAfQ"]
[Tue Jul 21 08:15:43.302426 2026] [security2:error] [pid 402041:tid 402262] [client 4.194.24.143:21399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/7.php"] [unique_id "al9U34iENNLP6XjiHQtp7gAAAeg"]
[Tue Jul 21 08:15:43.320277 2026] [security2:error] [pid 402041:tid 402244] [client 111.93.58.162:40948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9U34iENNLP6XjiHQtp7wAAAdY"]
[Tue Jul 21 08:15:43.320387 2026] [security2:error] [pid 402041:tid 402244] [client 111.93.58.162:40948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9U34iENNLP6XjiHQtp7wAAAdY"]
[Tue Jul 21 08:15:43.492250 2026] [security2:error] [pid 402041:tid 402292] [client 20.151.10.161:20356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/adminner.php"] [unique_id "al9U34iENNLP6XjiHQtp8wAAAgY"]
[Tue Jul 21 08:15:43.771100 2026] [security2:error] [pid 402041:tid 402202] [client 20.151.10.161:20466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/admin.php"] [unique_id "al9U34iENNLP6XjiHQtp_AAAAaw"]
[Tue Jul 21 08:15:44.026701 2026] [security2:error] [pid 402041:tid 402264] [client 20.197.192.193:61074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/wander.php"] [unique_id "al9U4IiENNLP6XjiHQtqBQAAAeo"]
[Tue Jul 21 08:15:44.111359 2026] [security2:error] [pid 402041:tid 402220] [client 20.151.10.161:13285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/adminner.php"] [unique_id "al9U4IiENNLP6XjiHQtqBgAAAb4"]
[Tue Jul 21 08:15:44.140521 2026] [security2:error] [pid 402041:tid 402188] [client 20.151.10.161:20430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/k.php"] [unique_id "al9U4IiENNLP6XjiHQtqCQAAAZ4"]
[Tue Jul 21 08:15:44.342227 2026] [security2:error] [pid 402041:tid 402218] [client 4.194.24.143:21428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/8.php"] [unique_id "al9U4IiENNLP6XjiHQtqGAAAAbw"]
[Tue Jul 21 08:15:44.447234 2026] [security2:error] [pid 402041:tid 402239] [client 20.151.10.161:20476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/x.php"] [unique_id "al9U4IiENNLP6XjiHQtqGgAAAdE"]
[Tue Jul 21 08:15:44.700876 2026] [security2:error] [pid 402041:tid 402299] [client 74.249.245.134:15367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/ws38.php"] [unique_id "al9U4IiENNLP6XjiHQtqGwAAAg0"]
[Tue Jul 21 08:15:44.792471 2026] [security2:error] [pid 402041:tid 402190] [client 20.151.10.161:20459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wss.php"] [unique_id "al9U4IiENNLP6XjiHQtqIAAAAaA"]
[Tue Jul 21 08:15:45.016912 2026] [security2:error] [pid 402041:tid 402215] [client 20.220.225.223:24222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9U4YiENNLP6XjiHQtqKAAAAbk"]
[Tue Jul 21 08:15:45.113501 2026] [security2:error] [pid 402041:tid 402242] [client 20.151.10.161:20419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/ty.php"] [unique_id "al9U4YiENNLP6XjiHQtqLQAAAdQ"]
[Tue Jul 21 08:15:45.173632 2026] [security2:error] [pid 402041:tid 402129] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/.env.old"] [unique_id "al9U4YiENNLP6XjiHQtqMgABs1U"]
[Tue Jul 21 08:15:45.183646 2026] [security2:error] [pid 402041:tid 402065] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/api/.env"] [unique_id "al9U4YiENNLP6XjiHQtqNgABsxU"]
[Tue Jul 21 08:15:45.372130 2026] [security2:error] [pid 402041:tid 402222] [client 4.194.24.143:21376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/87.php"] [unique_id "al9U4YiENNLP6XjiHQtqRQAAAcA"]
[Tue Jul 21 08:15:45.373037 2026] [security2:error] [pid 402041:tid 402046] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.env.bak"] [unique_id "al9U4YiENNLP6XjiHQtqRgABswI"]
[Tue Jul 21 08:15:45.373261 2026] [security2:error] [pid 402041:tid 402209] [client 34.32.127.230:58262] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/.env.bak"] [unique_id "al9U4YiENNLP6XjiHQtqRgABswI"]
[Tue Jul 21 08:15:45.477546 2026] [security2:error] [pid 402041:tid 402175] [client 20.151.10.161:20458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/155.php"] [unique_id "al9U4YiENNLP6XjiHQtqUwAAAZE"]
[Tue Jul 21 08:15:45.486101 2026] [security2:error] [pid 402041:tid 402229] [client 150.129.202.39:65327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U4YiENNLP6XjiHQtqVAAAAcc"]
[Tue Jul 21 08:15:45.486252 2026] [security2:error] [pid 402041:tid 402229] [client 150.129.202.39:65327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U4YiENNLP6XjiHQtqVAAAAcc"]
[Tue Jul 21 08:15:45.515393 2026] [security2:error] [pid 402041:tid 402176] [client 120.56.162.40:65243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U4YiENNLP6XjiHQtqVgAAAZI"]
[Tue Jul 21 08:15:45.515551 2026] [security2:error] [pid 402041:tid 402176] [client 120.56.162.40:65243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U4YiENNLP6XjiHQtqVgAAAZI"]
[Tue Jul 21 08:15:45.734184 2026] [security2:error] [pid 402041:tid 402187] [client 20.151.10.161:13251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/admin.php"] [unique_id "al9U4YiENNLP6XjiHQtqXwAAAZ0"]
[Tue Jul 21 08:15:45.745884 2026] [security2:error] [pid 402041:tid 402183] [client 20.220.225.223:58911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/tinyfilemanager.php"] [unique_id "al9U4YiENNLP6XjiHQtqYAAAAZk"]
[Tue Jul 21 08:15:45.905702 2026] [security2:error] [pid 402041:tid 402198] [client 20.151.10.161:20366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/ops.php"] [unique_id "al9U4YiENNLP6XjiHQtqaQAAAag"]
[Tue Jul 21 08:15:46.181622 2026] [security2:error] [pid 402041:tid 402178] [client 115.134.11.136:54663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U4oiENNLP6XjiHQtqcgAAAZQ"]
[Tue Jul 21 08:15:46.385270 2026] [security2:error] [pid 402041:tid 402264] [client 20.151.10.161:20359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/ingfo.php"] [unique_id "al9U4oiENNLP6XjiHQtqeAAAAeo"]
[Tue Jul 21 08:15:46.441446 2026] [security2:error] [pid 402041:tid 402240] [client 4.194.24.143:14018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/99.php"] [unique_id "al9U4oiENNLP6XjiHQtqfQAAAdI"]
[Tue Jul 21 08:15:46.468146 2026] [security2:error] [pid 402041:tid 402115] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9U4oiENNLP6XjiHQtqggABj0c"]
[Tue Jul 21 08:15:46.468279 2026] [security2:error] [pid 402041:tid 402173] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9U4oiENNLP6XjiHQtqggABj0c"]
[Tue Jul 21 08:15:46.548646 2026] [security2:error] [pid 402041:tid 402257] [client 74.249.245.134:15166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/a7.php"] [unique_id "al9U4oiENNLP6XjiHQtqgwAAAeM"]
[Tue Jul 21 08:15:46.609644 2026] [security2:error] [pid 402041:tid 402256] [client 117.210.135.0:56380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U4oiENNLP6XjiHQtqhAAAAeI"]
[Tue Jul 21 08:15:46.609741 2026] [security2:error] [pid 402041:tid 402256] [client 117.210.135.0:56380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U4oiENNLP6XjiHQtqhAAAAeI"]
[Tue Jul 21 08:15:46.772998 2026] [security2:error] [pid 402041:tid 402226] [client 20.151.10.161:20457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/error_log.php"] [unique_id "al9U4oiENNLP6XjiHQtqhgAAAcQ"]
[Tue Jul 21 08:15:46.839314 2026] [security2:error] [pid 402041:tid 402221] [client 103.151.46.103:62696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U4oiENNLP6XjiHQtqigAAAb8"]
[Tue Jul 21 08:15:46.839439 2026] [security2:error] [pid 402041:tid 402221] [client 103.151.46.103:62696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U4oiENNLP6XjiHQtqigAAAb8"]
[Tue Jul 21 08:15:47.135515 2026] [security2:error] [pid 402041:tid 402177] [client 20.151.10.161:20374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/ok.php"] [unique_id "al9U44iENNLP6XjiHQtqlAAAAZM"]
[Tue Jul 21 08:15:47.172969 2026] [security2:error] [pid 402041:tid 402251] [client 162.219.176.3:45170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9U44iENNLP6XjiHQtqlQAAAd0"]
[Tue Jul 21 08:15:47.173053 2026] [security2:error] [pid 402041:tid 402251] [client 162.219.176.3:45170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9U44iENNLP6XjiHQtqlQAAAd0"]
[Tue Jul 21 08:15:47.299396 2026] [security2:error] [pid 402041:tid 402134] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U44iENNLP6XjiHQtqlwABsFo"]
[Tue Jul 21 08:15:47.299638 2026] [security2:error] [pid 402041:tid 402206] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U44iENNLP6XjiHQtqlwABsFo"]
[Tue Jul 21 08:15:47.313128 2026] [security2:error] [pid 402041:tid 402270] [client 20.220.225.223:52663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/ee.php"] [unique_id "al9U44iENNLP6XjiHQtqmAAAAfA"]
[Tue Jul 21 08:15:47.466238 2026] [security2:error] [pid 402041:tid 402243] [client 4.194.24.143:14036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/a.php"] [unique_id "al9U44iENNLP6XjiHQtqngAAAdU"]
[Tue Jul 21 08:15:47.515788 2026] [security2:error] [pid 402041:tid 402215] [client 20.151.10.161:20474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/mac.php"] [unique_id "al9U44iENNLP6XjiHQtqogAAAbk"]
[Tue Jul 21 08:15:47.651058 2026] [security2:error] [pid 402041:tid 402090] [remote 47.128.120.87:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tavarescont.com.br"] [uri "/robots.txt"] [unique_id "al9U44iENNLP6XjiHQtqpgABpy4"]
[Tue Jul 21 08:15:47.867835 2026] [security2:error] [pid 402041:tid 402199] [client 20.151.10.161:20367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wefile.php"] [unique_id "al9U44iENNLP6XjiHQtqqQAAAak"]
[Tue Jul 21 08:15:48.168081 2026] [security2:error] [pid 402041:tid 402212] [client 20.151.10.161:13191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/k.php"] [unique_id "al9U5IiENNLP6XjiHQtqsQAAAbY"]
[Tue Jul 21 08:15:48.250188 2026] [proxy:error] [pid 402041:tid 402124] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:15:48.250227 2026] [proxy_http:error] [pid 402041:tid 402124] [remote 35.83.252.153:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:15:48.250858 2026] [proxy:error] [pid 402041:tid 402124] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:15:48.250892 2026] [proxy_http:error] [pid 402041:tid 402124] [remote 35.83.252.153:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:15:48.318866 2026] [security2:error] [pid 402041:tid 402259] [client 20.151.10.161:20455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9U5IiENNLP6XjiHQtqswAAAeU"]
[Tue Jul 21 08:15:48.515772 2026] [security2:error] [pid 402041:tid 402296] [client 4.194.24.143:14094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/a4.php"] [unique_id "al9U5IiENNLP6XjiHQtqvQAAAgo"]
[Tue Jul 21 08:15:48.810204 2026] [proxy:error] [pid 402041:tid 402059] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:15:48.810265 2026] [proxy_http:error] [pid 402041:tid 402059] [remote 35.83.252.153:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:15:48.810754 2026] [proxy:error] [pid 402041:tid 402059] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:15:48.810777 2026] [proxy_http:error] [pid 402041:tid 402059] [remote 35.83.252.153:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:15:48.976703 2026] [security2:error] [pid 402041:tid 402190] [client 167.114.139.90:64628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "klvviagens.com.br"] [uri "/robots.txt"] [unique_id "al9U5IiENNLP6XjiHQtqxgAAAaA"]
[Tue Jul 21 08:15:48.976827 2026] [security2:error] [pid 402041:tid 402190] [client 167.114.139.90:64628] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "klvviagens.com.br"] [uri "/robots.txt"] [unique_id "al9U5IiENNLP6XjiHQtqxgAAAaA"]
[Tue Jul 21 08:15:49.060892 2026] [security2:error] [pid 402041:tid 402260] [client 20.197.192.193:63925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/jga.php"] [unique_id "al9U5YiENNLP6XjiHQtqzwAAAeY"]
[Tue Jul 21 08:15:49.107950 2026] [security2:error] [pid 402041:tid 402197] [client 20.151.10.161:20427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9U5YiENNLP6XjiHQtq0AAAAac"]
[Tue Jul 21 08:15:49.171418 2026] [security2:error] [pid 402041:tid 402163] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.docker/config.json"] [unique_id "al9U5YiENNLP6XjiHQtq0wABl3c"]
[Tue Jul 21 08:15:49.171641 2026] [security2:error] [pid 402041:tid 402130] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "principiamatematica.com"] [uri "/graphql"] [unique_id "al9U5YiENNLP6XjiHQtq0gABl1Y"]
[Tue Jul 21 08:15:49.173039 2026] [security2:error] [pid 402041:tid 402157] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.env.example"] [unique_id "al9U5YiENNLP6XjiHQtq1AABl3E"]
[Tue Jul 21 08:15:49.173156 2026] [security2:error] [pid 402041:tid 402181] [client 34.32.127.230:58262] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/.env.example"] [unique_id "al9U5YiENNLP6XjiHQtq1AABl3E"]
[Tue Jul 21 08:15:49.207451 2026] [security2:error] [pid 402041:tid 402152] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.npmrc"] [unique_id "al9U5YiENNLP6XjiHQtq2AABl2w"]
[Tue Jul 21 08:15:49.221920 2026] [security2:error] [pid 402041:tid 402076] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U5YiENNLP6XjiHQtq2gAB8CA"]
[Tue Jul 21 08:15:49.222102 2026] [security2:error] [pid 402041:tid 402270] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U5YiENNLP6XjiHQtq2gAB8CA"]
[Tue Jul 21 08:15:49.238863 2026] [security2:error] [pid 402041:tid 402102] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/backend/.env"] [unique_id "al9U5YiENNLP6XjiHQtq2wABlzo"]
[Tue Jul 21 08:15:49.251058 2026] [security2:error] [pid 402041:tid 402096] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.continue/config.json"] [unique_id "al9U5YiENNLP6XjiHQtq3gABlzQ"]
[Tue Jul 21 08:15:49.251143 2026] [security2:error] [pid 402041:tid 402181] [client 34.32.127.230:58262] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/.continue/config.json"] [unique_id "al9U5YiENNLP6XjiHQtq3gABlzQ"]
[Tue Jul 21 08:15:49.383564 2026] [security2:error] [pid 402041:tid 402104] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "principiamatematica.com"] [uri "/api/graphql"] [unique_id "al9U5YiENNLP6XjiHQtq4AABuDw"]
[Tue Jul 21 08:15:49.393955 2026] [security2:error] [pid 402041:tid 402188] [client 20.220.225.223:52631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/blue.php"] [unique_id "al9U5YiENNLP6XjiHQtq4gAAAZ4"]
[Tue Jul 21 08:15:49.418994 2026] [security2:error] [pid 402041:tid 402105] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/config/.env"] [unique_id "al9U5YiENNLP6XjiHQtq5AABuD0"]
[Tue Jul 21 08:15:49.541723 2026] [security2:error] [pid 402041:tid 402207] [client 4.194.24.143:21416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/a7.php"] [unique_id "al9U5YiENNLP6XjiHQtq7QAAAbE"]
[Tue Jul 21 08:15:49.585347 2026] [security2:error] [pid 402041:tid 402057] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/id_dsa"] [unique_id "al9U5YiENNLP6XjiHQtq8wABuA0"]
[Tue Jul 21 08:15:49.607024 2026] [security2:error] [pid 402041:tid 402147] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "principiamatematica.com"] [uri "/v1/graphql"] [unique_id "al9U5YiENNLP6XjiHQtq9AABuGc"]
[Tue Jul 21 08:15:49.607189 2026] [security2:error] [pid 402041:tid 402117] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/__/firebase/init.json"] [unique_id "al9U5YiENNLP6XjiHQtq9gABuEk"]
[Tue Jul 21 08:15:49.607578 2026] [security2:error] [pid 402041:tid 402091] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/private-key"] [unique_id "al9U5YiENNLP6XjiHQtq-AABuC8"]
[Tue Jul 21 08:15:49.607649 2026] [security2:error] [pid 402041:tid 402214] [client 34.32.127.230:58262] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/private-key"] [unique_id "al9U5YiENNLP6XjiHQtq-AABuC8"]
[Tue Jul 21 08:15:49.773962 2026] [security2:error] [pid 402041:tid 402237] [client 103.78.200.11:57834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U5YiENNLP6XjiHQtq_wAAAc8"]
[Tue Jul 21 08:15:49.779414 2026] [security2:error] [pid 402041:tid 402237] [client 103.78.200.11:57834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U5YiENNLP6XjiHQtq_wAAAc8"]
[Tue Jul 21 08:15:49.789427 2026] [security2:error] [pid 402041:tid 402296] [client 20.151.10.161:20449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/like.php"] [unique_id "al9U5YiENNLP6XjiHQtrAQAAAgo"]
[Tue Jul 21 08:15:49.841950 2026] [security2:error] [pid 402041:tid 402281] [client 61.1.167.83:55013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U5YiENNLP6XjiHQtrBQAAAfs"]
[Tue Jul 21 08:15:49.842040 2026] [security2:error] [pid 402041:tid 402281] [client 61.1.167.83:55013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U5YiENNLP6XjiHQtrBQAAAfs"]
[Tue Jul 21 08:15:49.921352 2026] [security2:error] [pid 402041:tid 402285] [client 154.208.47.43:52726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9U5YiENNLP6XjiHQtrCQAAAf8"]
[Tue Jul 21 08:15:49.921520 2026] [security2:error] [pid 402041:tid 402285] [client 154.208.47.43:52726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9U5YiENNLP6XjiHQtrCQAAAf8"]
[Tue Jul 21 08:15:50.404537 2026] [security2:error] [pid 402041:tid 402247] [client 198.244.226.79:26008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "klvviagens.com.br"] [uri "/"] [unique_id "al9U5oiENNLP6XjiHQtrGQAAAdk"]
[Tue Jul 21 08:15:50.404692 2026] [security2:error] [pid 402041:tid 402247] [client 198.244.226.79:26008] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "klvviagens.com.br"] [uri "/"] [unique_id "al9U5oiENNLP6XjiHQtrGQAAAdk"]
[Tue Jul 21 08:15:50.473370 2026] [security2:error] [pid 402041:tid 402202] [client 20.151.10.161:20450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/.well-known/about.php"] [unique_id "al9U5oiENNLP6XjiHQtrGgAAAaw"]
[Tue Jul 21 08:15:50.487377 2026] [security2:error] [pid 402041:tid 402044] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/.openclaw/.env"] [unique_id "al9U5oiENNLP6XjiHQtrGwABuQA"]
[Tue Jul 21 08:15:50.492399 2026] [security2:error] [pid 402041:tid 402066] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/.ssh/id_rsa"] [unique_id "al9U5oiENNLP6XjiHQtrHAAB7BY"]
[Tue Jul 21 08:15:50.619029 2026] [security2:error] [pid 402041:tid 402208] [client 4.194.24.143:14101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/aa.php"] [unique_id "al9U5oiENNLP6XjiHQtrJQAAAbI"]
[Tue Jul 21 08:15:50.646578 2026] [security2:error] [pid 402041:tid 402073] [remote 67.207.94.191:43856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.94.207.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9U5oiENNLP6XjiHQtrJwAB6B0"]
[Tue Jul 21 08:15:50.675923 2026] [security2:error] [pid 402041:tid 402078] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/config.js"] [unique_id "al9U5oiENNLP6XjiHQtrMQAB6SI"]
[Tue Jul 21 08:15:50.676153 2026] [security2:error] [pid 402041:tid 402263] [client 34.32.127.230:58262] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/config.js"] [unique_id "al9U5oiENNLP6XjiHQtrMQAB6SI"]
[Tue Jul 21 08:15:50.679160 2026] [security2:error] [pid 402041:tid 402086] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.127.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/app_dev.php/_profiler"] [unique_id "al9U5oiENNLP6XjiHQtrLAAB6So"]
[Tue Jul 21 08:15:50.873107 2026] [security2:error] [pid 402041:tid 402054] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9U5oiENNLP6XjiHQtrNwAB_wo"]
[Tue Jul 21 08:15:50.873306 2026] [security2:error] [pid 402041:tid 402054] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9U5oiENNLP6XjiHQtrNwAB_wo"]
[Tue Jul 21 08:15:50.894774 2026] [security2:error] [pid 402041:tid 402084] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.127.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/i.php"] [unique_id "al9U5oiENNLP6XjiHQtrOAAB6Sg"]
[Tue Jul 21 08:15:50.910313 2026] [security2:error] [pid 402041:tid 402161] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.127.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/phpinfo.php"] [unique_id "al9U5oiENNLP6XjiHQtrOgAB6XU"]
[Tue Jul 21 08:15:50.957496 2026] [security2:error] [pid 402041:tid 402229] [client 20.151.10.161:20358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9U5oiENNLP6XjiHQtrPAAAAcc"]
[Tue Jul 21 08:15:51.101736 2026] [security2:error] [pid 402041:tid 402095] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/.env"] [unique_id "al9U54iENNLP6XjiHQtrQgAB6TM"]
[Tue Jul 21 08:15:51.140936 2026] [security2:error] [pid 402041:tid 402120] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.127.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/info.php"] [unique_id "al9U54iENNLP6XjiHQtrRAAB6Uw"]
[Tue Jul 21 08:15:51.160654 2026] [security2:error] [pid 402041:tid 402257] [client 87.116.180.198:13987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U54iENNLP6XjiHQtrRQAAAeM"]
[Tue Jul 21 08:15:51.162066 2026] [security2:error] [pid 402041:tid 402257] [client 87.116.180.198:13987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U54iENNLP6XjiHQtrRQAAAeM"]
[Tue Jul 21 08:15:51.479429 2026] [security2:error] [pid 402041:tid 402284] [client 20.220.225.223:58925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/wp-signup.php"] [unique_id "al9U54iENNLP6XjiHQtrUQAAAf4"]
[Tue Jul 21 08:15:51.503853 2026] [security2:error] [pid 402041:tid 402254] [client 74.7.244.14:39204] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "testovate.shop-officialstore.com"] [uri "/index.php"] [unique_id "al9U5YiENNLP6XjiHQtrCAAB4GQ"]
[Tue Jul 21 08:15:51.512130 2026] [security2:error] [pid 402041:tid 402137] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.ssh/config"] [unique_id "al9U54iENNLP6XjiHQtrUwAB7l0"]
[Tue Jul 21 08:15:51.522855 2026] [security2:error] [pid 402041:tid 402136] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/service-worker.js"] [unique_id "al9U54iENNLP6XjiHQtrVQABq1w"]
[Tue Jul 21 08:15:51.536011 2026] [security2:error] [pid 402041:tid 402158] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.127.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/app_dev.php"] [unique_id "al9U54iENNLP6XjiHQtrVwABq3I"]
[Tue Jul 21 08:15:51.553468 2026] [security2:error] [pid 402041:tid 402133] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/server-info"] [unique_id "al9U54iENNLP6XjiHQtrWQABq1k"]
[Tue Jul 21 08:15:51.587857 2026] [security2:error] [pid 402041:tid 402089] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.127.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/pi.php"] [unique_id "al9U54iENNLP6XjiHQtrXAABqy0"]
[Tue Jul 21 08:15:51.609823 2026] [security2:error] [pid 402041:tid 402264] [client 20.151.10.161:13214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/x.php"] [unique_id "al9U54iENNLP6XjiHQtrXwAAAeo"]
[Tue Jul 21 08:15:51.627081 2026] [security2:error] [pid 402041:tid 402217] [client 20.197.192.193:63886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/x.php"] [unique_id "al9U54iENNLP6XjiHQtrYwAAAbs"]
[Tue Jul 21 08:15:51.656780 2026] [security2:error] [pid 402041:tid 402090] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/privatekey.key"] [unique_id "al9U54iENNLP6XjiHQtrZAABqy4"]
[Tue Jul 21 08:15:51.675613 2026] [security2:error] [pid 402041:tid 402300] [client 4.194.24.143:14028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/aaa.php"] [unique_id "al9U54iENNLP6XjiHQtrZQAAAg4"]
[Tue Jul 21 08:15:51.763089 2026] [security2:error] [pid 402041:tid 402150] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/server-status"] [unique_id "al9U54iENNLP6XjiHQtrbgAB02o"]
[Tue Jul 21 08:15:51.771726 2026] [security2:error] [pid 402041:tid 402227] [client 20.151.10.161:20429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/pucci.php"] [unique_id "al9U54iENNLP6XjiHQtrcAAAAcU"]
[Tue Jul 21 08:15:51.778083 2026] [security2:error] [pid 402041:tid 402131] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/key.pem"] [unique_id "al9U54iENNLP6XjiHQtrcQAB01c"]
[Tue Jul 21 08:15:51.795302 2026] [security2:error] [pid 402041:tid 402139] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/.ssh/id_dsa"] [unique_id "al9U54iENNLP6XjiHQtrcwAB018"]
[Tue Jul 21 08:15:51.823648 2026] [security2:error] [pid 402041:tid 402177] [client 102.206.115.33:65516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U54iENNLP6XjiHQtrdAAAAZM"]
[Tue Jul 21 08:15:51.823765 2026] [security2:error] [pid 402041:tid 402177] [client 102.206.115.33:65516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U54iENNLP6XjiHQtrdAAAAZM"]
[Tue Jul 21 08:15:51.843842 2026] [security2:error] [pid 402041:tid 402297] [client 38.100.221.102:18695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U54iENNLP6XjiHQtreAAAAgs"]
[Tue Jul 21 08:15:51.843946 2026] [security2:error] [pid 402041:tid 402297] [client 38.100.221.102:18695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U54iENNLP6XjiHQtreAAAAgs"]
[Tue Jul 21 08:15:51.845063 2026] [security2:error] [pid 402041:tid 402142] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/laravel/.env"] [unique_id "al9U54iENNLP6XjiHQtrdwAB82I"]
[Tue Jul 21 08:15:51.881774 2026] [security2:error] [pid 402041:tid 402138] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/.hermes/.env"] [unique_id "al9U54iENNLP6XjiHQtreQAB814"]
[Tue Jul 21 08:15:51.985347 2026] [security2:error] [pid 402041:tid 402081] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/api/env"] [unique_id "al9U54iENNLP6XjiHQtrfgAB8yU"]
[Tue Jul 21 08:15:51.985506 2026] [security2:error] [pid 402041:tid 402273] [client 34.32.127.230:58262] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/api/env"] [unique_id "al9U54iENNLP6XjiHQtrfgAB8yU"]
[Tue Jul 21 08:15:52.042086 2026] [security2:error] [pid 402041:tid 402059] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/id_rsa"] [unique_id "al9U6IiENNLP6XjiHQtrggAB8w8"]
[Tue Jul 21 08:15:52.136697 2026] [security2:error] [pid 402041:tid 402100] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/auth.json"] [unique_id "al9U6IiENNLP6XjiHQtrhgAB8zg"]
[Tue Jul 21 08:15:52.151000 2026] [security2:error] [pid 402041:tid 402118] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/config/.env.php"] [unique_id "al9U6IiENNLP6XjiHQtrhwAB80o"]
[Tue Jul 21 08:15:52.187434 2026] [security2:error] [pid 402041:tid 402087] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/ssl/server.key"] [unique_id "al9U6IiENNLP6XjiHQtriAAB8ys"]
[Tue Jul 21 08:15:52.194956 2026] [security2:error] [pid 402041:tid 402163] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.ssh/authorized_keys"] [unique_id "al9U6IiENNLP6XjiHQtriQAB83c"]
[Tue Jul 21 08:15:52.326604 2026] [security2:error] [pid 402041:tid 402225] [client 20.197.192.193:52632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/edit.php"] [unique_id "al9U6IiENNLP6XjiHQtrkgAAAcM"]
[Tue Jul 21 08:15:52.363943 2026] [security2:error] [pid 402041:tid 402096] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.127.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/config.php.bak"] [unique_id "al9U6IiENNLP6XjiHQtrlAAB8zQ"]
[Tue Jul 21 08:15:52.375055 2026] [security2:error] [pid 402041:tid 402165] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U6IiENNLP6XjiHQtrlQAB-Xk"]
[Tue Jul 21 08:15:52.375210 2026] [security2:error] [pid 402041:tid 402279] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U6IiENNLP6XjiHQtrlQAB-Xk"]
[Tue Jul 21 08:15:52.394439 2026] [security2:error] [pid 402041:tid 402071] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "principiamatematica.com"] [uri "/docker-compose.yaml"] [unique_id "al9U6IiENNLP6XjiHQtrlgAB8xs"]
[Tue Jul 21 08:15:52.411809 2026] [security2:error] [pid 402041:tid 402143] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/.env.swp"] [unique_id "al9U6IiENNLP6XjiHQtrlwAB82M"]
[Tue Jul 21 08:15:52.530182 2026] [security2:error] [pid 402041:tid 402064] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.127.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/.env.php.bak"] [unique_id "al9U6IiENNLP6XjiHQtrngAB3RQ"]
[Tue Jul 21 08:15:52.578800 2026] [security2:error] [pid 402041:tid 402112] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.127.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/configuration.php.bak"] [unique_id "al9U6IiENNLP6XjiHQtrpAAB3UQ"]
[Tue Jul 21 08:15:52.659611 2026] [security2:error] [pid 402041:tid 402147] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.bash_profile"] [unique_id "al9U6IiENNLP6XjiHQtrqgAB3Wc"]
[Tue Jul 21 08:15:52.659723 2026] [security2:error] [pid 402041:tid 402251] [client 34.32.127.230:58262] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/.bash_profile"] [unique_id "al9U6IiENNLP6XjiHQtrqgAB3Wc"]
[Tue Jul 21 08:15:52.668348 2026] [security2:error] [pid 402041:tid 402292] [client 162.219.176.3:46938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9U6IiENNLP6XjiHQtrrAAAAgY"]
[Tue Jul 21 08:15:52.668444 2026] [security2:error] [pid 402041:tid 402292] [client 162.219.176.3:46938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9U6IiENNLP6XjiHQtrrAAAAgY"]
[Tue Jul 21 08:15:52.705173 2026] [security2:error] [pid 402041:tid 402211] [client 4.194.24.143:14219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/ab.php"] [unique_id "al9U6IiENNLP6XjiHQtrrgAAAbU"]
[Tue Jul 21 08:15:52.758223 2026] [security2:error] [pid 402041:tid 402218] [client 14.245.224.124:59420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9U6IiENNLP6XjiHQtrsgAAAbw"]
[Tue Jul 21 08:15:52.758385 2026] [security2:error] [pid 402041:tid 402218] [client 14.245.224.124:59420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9U6IiENNLP6XjiHQtrsgAAAbw"]
[Tue Jul 21 08:15:52.838569 2026] [security2:error] [pid 402041:tid 402213] [client 20.151.10.161:20414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wp-temp.php"] [unique_id "al9U6IiENNLP6XjiHQtruQAAAbc"]
[Tue Jul 21 08:15:52.843330 2026] [security2:error] [pid 402041:tid 402270] [client 20.220.225.223:52659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/csa.php"] [unique_id "al9U6IiENNLP6XjiHQtrugAAAfA"]
[Tue Jul 21 08:15:52.857576 2026] [security2:error] [pid 402041:tid 402128] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.127.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/test.php"] [unique_id "al9U6IiENNLP6XjiHQtruwAB61Q"]
[Tue Jul 21 08:15:52.865689 2026] [security2:error] [pid 402041:tid 402266] [client 187.125.243.197:49695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9U6IiENNLP6XjiHQtrvAAAAew"]
[Tue Jul 21 08:15:52.865811 2026] [security2:error] [pid 402041:tid 402266] [client 187.125.243.197:49695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9U6IiENNLP6XjiHQtrvAAAAew"]
[Tue Jul 21 08:15:52.868335 2026] [security2:error] [pid 402041:tid 402101] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/.env.backup"] [unique_id "al9U6IiENNLP6XjiHQtrvQAB6zk"]
[Tue Jul 21 08:15:52.943746 2026] [security2:error] [pid 402041:tid 402058] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/public/.env"] [unique_id "al9U6IiENNLP6XjiHQtrwwAB6w4"]
[Tue Jul 21 08:15:52.984365 2026] [security2:error] [pid 402041:tid 402122] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/web/.env"] [unique_id "al9U6IiENNLP6XjiHQtrxQAB604"]
[Tue Jul 21 08:15:52.988611 2026] [security2:error] [pid 402041:tid 402249] [client 20.220.225.223:24197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/ee.php"] [unique_id "al9U6IiENNLP6XjiHQtrxgAAAds"]
[Tue Jul 21 08:15:53.009238 2026] [security2:error] [pid 402041:tid 402228] [client 115.134.11.136:55011] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U6YiENNLP6XjiHQtrxwAAAcY"]
[Tue Jul 21 08:15:53.009380 2026] [security2:error] [pid 402041:tid 402228] [client 115.134.11.136:55011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U6YiENNLP6XjiHQtrxwAAAcY"]
[Tue Jul 21 08:15:53.069985 2026] [security2:error] [pid 402041:tid 402154] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "principiamatematica.com"] [uri "/wp-config.php.bak"] [unique_id "al9U6YiENNLP6XjiHQtryAAB624"]
[Tue Jul 21 08:15:53.099404 2026] [security2:error] [pid 402041:tid 402127] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "principiamatematica.com"] [uri "/wp-config.php.old"] [unique_id "al9U6YiENNLP6XjiHQtrygAB61M"]
[Tue Jul 21 08:15:53.128719 2026] [security2:error] [pid 402041:tid 402099] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.zshrc"] [unique_id "al9U6YiENNLP6XjiHQtrzAAB6zc"]
[Tue Jul 21 08:15:53.149211 2026] [security2:error] [pid 402041:tid 402094] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "principiamatematica.com"] [uri "/core/.env"] [unique_id "al9U6YiENNLP6XjiHQtrzQAB6zI"]
[Tue Jul 21 08:15:53.321396 2026] [security2:error] [pid 402041:tid 402078] [remote 72.167.132.114:59246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9U6YiENNLP6XjiHQtr2QABrSI"]
[Tue Jul 21 08:15:53.321656 2026] [security2:error] [pid 402041:tid 402203] [client 72.167.132.114:59246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9U6YiENNLP6XjiHQtr2QABrSI"]
[Tue Jul 21 08:15:53.477535 2026] [security2:error] [pid 402041:tid 402082] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "principiamatematica.com"] [uri "/.htpasswd"] [unique_id "al9U6YiENNLP6XjiHQtr5QABqCY"]
[Tue Jul 21 08:15:53.477675 2026] [security2:error] [pid 402041:tid 402198] [client 34.32.127.230:58262] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "principiamatematica.com"] [uri "/.htpasswd"] [unique_id "al9U6YiENNLP6XjiHQtr5QABqCY"]
[Tue Jul 21 08:15:53.478785 2026] [security2:error] [pid 402041:tid 402277] [client 20.151.10.161:20372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/xmu.php"] [unique_id "al9U6YiENNLP6XjiHQtr5gAAAfc"]
[Tue Jul 21 08:15:53.501711 2026] [security2:error] [pid 402041:tid 402161] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U6YiENNLP6XjiHQtr6QABvnU"]
[Tue Jul 21 08:15:53.501908 2026] [security2:error] [pid 402041:tid 402220] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U6YiENNLP6XjiHQtr6QABvnU"]
[Tue Jul 21 08:15:53.755609 2026] [security2:error] [pid 402041:tid 402285] [client 4.194.24.143:14056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/abc.php"] [unique_id "al9U6YiENNLP6XjiHQtr8QAAAf8"]
[Tue Jul 21 08:15:53.878568 2026] [security2:error] [pid 402041:tid 402254] [client 20.197.192.193:63895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/tinyfilemanager.php"] [unique_id "al9U6YiENNLP6XjiHQtr-gAAAeA"]
[Tue Jul 21 08:15:53.960453 2026] [security2:error] [pid 402041:tid 402287] [client 14.97.58.74:59811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9U6YiENNLP6XjiHQtsAAAAAgE"]
[Tue Jul 21 08:15:53.960597 2026] [security2:error] [pid 402041:tid 402287] [client 14.97.58.74:59811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9U6YiENNLP6XjiHQtsAAAAAgE"]
[Tue Jul 21 08:15:54.007964 2026] [security2:error] [pid 402041:tid 402255] [client 20.151.10.161:20379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9U6oiENNLP6XjiHQtsAwAAAeE"]
[Tue Jul 21 08:15:54.498459 2026] [security2:error] [pid 402041:tid 402282] [client 20.151.10.161:20446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/puc.php"] [unique_id "al9U6oiENNLP6XjiHQtsHQAAAfw"]
[Tue Jul 21 08:15:54.583348 2026] [security2:error] [pid 402041:tid 402176] [client 20.151.10.161:51076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-temp.php"] [unique_id "al9U6oiENNLP6XjiHQtsIAAAAZI"]
[Tue Jul 21 08:15:54.785891 2026] [security2:error] [pid 402041:tid 402185] [client 4.194.24.143:14119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/abcd.php"] [unique_id "al9U6oiENNLP6XjiHQtsJQAAAZs"]
[Tue Jul 21 08:15:54.842394 2026] [security2:error] [pid 402041:tid 402168] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.127.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9U6oiENNLP6XjiHQtsIgAB0Hw"], referer: https://principiamatematica.com/login
[Tue Jul 21 08:15:54.952316 2026] [security2:error] [pid 402041:tid 402244] [client 20.151.10.161:13297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wss.php"] [unique_id "al9U6oiENNLP6XjiHQtsLQAAAdY"]
[Tue Jul 21 08:15:54.994394 2026] [security2:error] [pid 402041:tid 402093] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.127.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9U6oiENNLP6XjiHQtsKAAB0DE"], referer: https://principiamatematica.com/wp-admin/
[Tue Jul 21 08:15:54.996964 2026] [security2:error] [pid 402041:tid 402233] [client 20.151.10.161:20380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/themes.php"] [unique_id "al9U6oiENNLP6XjiHQtsMgAAAcs"]
[Tue Jul 21 08:15:55.248907 2026] [security2:error] [pid 402041:tid 402268] [client 20.220.225.223:52628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/min.php"] [unique_id "al9U64iENNLP6XjiHQtsOwAAAe4"]
[Tue Jul 21 08:15:55.668197 2026] [security2:error] [pid 402041:tid 402213] [client 114.119.152.33:60619] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hometohomelondon.com"] [uri "/en/images/blog/4.jpg"] [unique_id "al9U64iENNLP6XjiHQtsTwAAAbc"], referer: https://hometohomelondon.com/en/blog/4
[Tue Jul 21 08:15:55.733486 2026] [security2:error] [pid 402041:tid 402275] [client 74.249.245.134:15368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/classsmtps.php"] [unique_id "al9U64iENNLP6XjiHQtsUgAAAfU"]
[Tue Jul 21 08:15:55.743273 2026] [security2:error] [pid 402041:tid 402240] [client 20.151.10.161:20417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/8.php"] [unique_id "al9U64iENNLP6XjiHQtsUwAAAdI"]
[Tue Jul 21 08:15:55.851385 2026] [security2:error] [pid 402041:tid 402222] [client 4.194.24.143:21431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/about.php"] [unique_id "al9U64iENNLP6XjiHQtsWAAAAcA"]
[Tue Jul 21 08:15:56.001650 2026] [security2:error] [pid 402041:tid 402266] [client 120.56.162.40:49378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U7IiENNLP6XjiHQtsYAAAAew"]
[Tue Jul 21 08:15:56.001777 2026] [security2:error] [pid 402041:tid 402266] [client 120.56.162.40:49378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U7IiENNLP6XjiHQtsYAAAAew"]
[Tue Jul 21 08:15:56.082858 2026] [security2:error] [pid 402041:tid 402289] [client 74.7.175.162:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "diogooliveiradecarva1782070115229.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9U7IiENNLP6XjiHQtsZAACA00"]
[Tue Jul 21 08:15:56.091904 2026] [security2:error] [pid 402041:tid 402287] [client 150.129.202.39:13011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U7IiENNLP6XjiHQtsZQAAAgE"]
[Tue Jul 21 08:15:56.092065 2026] [security2:error] [pid 402041:tid 402287] [client 150.129.202.39:13011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U7IiENNLP6XjiHQtsZQAAAgE"]
[Tue Jul 21 08:15:56.443367 2026] [security2:error] [pid 402041:tid 402268] [client 20.151.10.161:20370] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.gfacil.com.br"] [uri "/1.php"] [unique_id "al9U7IiENNLP6XjiHQtsbgAAAe4"]
[Tue Jul 21 08:15:56.443446 2026] [security2:error] [pid 402041:tid 402268] [client 20.151.10.161:20370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/1.php"] [unique_id "al9U7IiENNLP6XjiHQtsbgAAAe4"]
[Tue Jul 21 08:15:56.894418 2026] [security2:error] [pid 402041:tid 402181] [client 4.194.24.143:14041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp-info.php"] [unique_id "al9U7IiENNLP6XjiHQtsfQAAAZc"]
[Tue Jul 21 08:15:56.901196 2026] [security2:error] [pid 402041:tid 402243] [client 117.210.135.0:57021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U7IiENNLP6XjiHQtsfgAAAdU"]
[Tue Jul 21 08:15:56.901322 2026] [security2:error] [pid 402041:tid 402243] [client 117.210.135.0:57021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U7IiENNLP6XjiHQtsfgAAAdU"]
[Tue Jul 21 08:15:56.934587 2026] [security2:error] [pid 402041:tid 402126] [remote 34.32.127.230:58262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.127.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9U6oiENNLP6XjiHQtsJAAB0FI"], referer: https://principiamatematica.com/wp-admin/
[Tue Jul 21 08:15:57.040668 2026] [security2:error] [pid 402041:tid 402045] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9U7YiENNLP6XjiHQtshQABxQE"]
[Tue Jul 21 08:15:57.040828 2026] [security2:error] [pid 402041:tid 402227] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9U7YiENNLP6XjiHQtshQABxQE"]
[Tue Jul 21 08:15:57.159198 2026] [security2:error] [pid 402041:tid 402275] [client 62.102.148.158:49290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9U7YiENNLP6XjiHQtshwAAAfU"]
[Tue Jul 21 08:15:57.159330 2026] [security2:error] [pid 402041:tid 402275] [client 62.102.148.158:49290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9U7YiENNLP6XjiHQtshwAAAfU"]
[Tue Jul 21 08:15:57.416749 2026] [security2:error] [pid 402041:tid 402176] [client 20.151.10.161:20375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/100.php"] [unique_id "al9U7YiENNLP6XjiHQtsiwAAAZI"]
[Tue Jul 21 08:15:57.571447 2026] [security2:error] [pid 402041:tid 402178] [client 20.220.225.223:24283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/blue.php"] [unique_id "al9U7YiENNLP6XjiHQtslQAAAZQ"]
[Tue Jul 21 08:15:57.609935 2026] [security2:error] [pid 402041:tid 402279] [client 20.220.225.223:52653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/echkm.php"] [unique_id "al9U7YiENNLP6XjiHQtslgAAAfk"]
[Tue Jul 21 08:15:57.756295 2026] [security2:error] [pid 402041:tid 402143] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U7YiENNLP6XjiHQtsngACB2M"]
[Tue Jul 21 08:15:57.756465 2026] [security2:error] [pid 402041:tid 402293] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U7YiENNLP6XjiHQtsngACB2M"]
[Tue Jul 21 08:15:58.145881 2026] [security2:error] [pid 402041:tid 402208] [client 20.151.10.161:20460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/about.php"] [unique_id "al9U7oiENNLP6XjiHQtsrAAAAbI"]
[Tue Jul 21 08:15:58.300554 2026] [security2:error] [pid 402041:tid 402238] [client 4.194.24.143:21385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp-links-opml.php"] [unique_id "al9U7oiENNLP6XjiHQtsrgAAAdA"]
[Tue Jul 21 08:15:58.309540 2026] [security2:error] [pid 402041:tid 402286] [client 20.151.10.161:13250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/ty.php"] [unique_id "al9U7oiENNLP6XjiHQtsrwAAAgA"]
[Tue Jul 21 08:15:58.404940 2026] [security2:error] [pid 402041:tid 402296] [client 20.197.192.193:3757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/kua.php"] [unique_id "al9U7oiENNLP6XjiHQtstQAAAgo"]
[Tue Jul 21 08:15:58.577595 2026] [security2:error] [pid 402041:tid 402272] [client 49.13.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9U7oiENNLP6XjiHQts8QAB8iw"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:15:58.853314 2026] [security2:error] [pid 402041:tid 402244] [client 20.151.10.161:20423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/about.php"] [unique_id "al9U7oiENNLP6XjiHQts_AAAAdY"]
[Tue Jul 21 08:15:58.860334 2026] [security2:error] [pid 402041:tid 402205] [client 78.46.190.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9U7oiENNLP6XjiHQts-wABrwc"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:15:58.933455 2026] [security2:error] [pid 402041:tid 402266] [client 20.151.10.161:36420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9U7oiENNLP6XjiHQttAAAAAew"]
[Tue Jul 21 08:15:59.131828 2026] [security2:error] [pid 402041:tid 402178] [client 49.13.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9U74iENNLP6XjiHQttCgABlHI"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:15:59.335747 2026] [security2:error] [pid 402041:tid 402279] [client 4.194.24.143:14246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp-links.php"] [unique_id "al9U74iENNLP6XjiHQttLwAAAfk"]
[Tue Jul 21 08:15:59.403441 2026] [security2:error] [pid 402041:tid 402278] [client 78.46.190.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9U74iENNLP6XjiHQttMQAB-AE"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:15:59.467766 2026] [security2:error] [pid 402041:tid 402284] [client 20.151.10.161:20468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/admin.php"] [unique_id "al9U74iENNLP6XjiHQttOAAAAf4"]
[Tue Jul 21 08:15:59.491025 2026] [security2:error] [pid 402041:tid 402207] [client 91.92.47.112:27278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/wp-config.php"] [unique_id "al9U74iENNLP6XjiHQttOQAAAbE"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:15:59.492655 2026] [security2:error] [pid 402041:tid 402300] [client 91.92.47.112:27288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/config.php"] [unique_id "al9U74iENNLP6XjiHQttOgAAAg4"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:15:59.493938 2026] [security2:error] [pid 402041:tid 402092] [remote 212.80.9.235:41232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "knconteudo.com"] [uri "/wp-login.php"] [unique_id "al9U74iENNLP6XjiHQttOwABkDA"]
[Tue Jul 21 08:15:59.610301 2026] [security2:error] [pid 402041:tid 402241] [client 91.92.47.112:27328] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tabelionatoportoalegre.com.br"] [uri "/.env"] [unique_id "al9U74iENNLP6XjiHQttRgAAAdM"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:15:59.644780 2026] [security2:error] [pid 402041:tid 402203] [client 91.92.47.112:27268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/phpinfo.php"] [unique_id "al9U74iENNLP6XjiHQttRwAAAa0"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:15:59.898325 2026] [security2:error] [pid 402041:tid 402222] [client 20.151.10.161:36534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/puc.php"] [unique_id "al9U74iENNLP6XjiHQttTQAAAcA"]
[Tue Jul 21 08:15:59.903271 2026] [security2:error] [pid 402041:tid 402191] [client 20.151.10.161:20478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/admin.php"] [unique_id "al9U74iENNLP6XjiHQttTwAAAaE"]
[Tue Jul 21 08:15:59.988973 2026] [security2:error] [pid 402041:tid 402165] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U74iENNLP6XjiHQttUQABsHk"]
[Tue Jul 21 08:15:59.989094 2026] [security2:error] [pid 402041:tid 402206] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U74iENNLP6XjiHQttUQABsHk"]
[Tue Jul 21 08:16:00.006377 2026] [security2:error] [pid 402041:tid 402189] [client 20.197.192.193:61063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/ee.php"] [unique_id "al9U8IiENNLP6XjiHQttUgAAAZ8"]
[Tue Jul 21 08:16:00.070542 2026] [security2:error] [pid 402041:tid 402205] [client 20.151.10.161:13253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/155.php"] [unique_id "al9U8IiENNLP6XjiHQttVAAAAa8"]
[Tue Jul 21 08:16:00.090629 2026] [security2:error] [pid 402041:tid 402195] [client 38.100.221.102:18006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U8IiENNLP6XjiHQttVwAAAaU"]
[Tue Jul 21 08:16:00.090722 2026] [security2:error] [pid 402041:tid 402195] [client 38.100.221.102:18006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U8IiENNLP6XjiHQttVwAAAaU"]
[Tue Jul 21 08:16:00.293700 2026] [security2:error] [pid 402041:tid 402224] [client 20.151.10.161:20467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/edit.php"] [unique_id "al9U8IiENNLP6XjiHQttXgAAAcI"]
[Tue Jul 21 08:16:00.316291 2026] [proxy:error] [pid 402041:tid 402196] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:00.316360 2026] [proxy_http:error] [pid 402041:tid 402196] [client 209.38.43.81:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:00.317037 2026] [proxy:error] [pid 402041:tid 402196] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:00.317078 2026] [proxy_http:error] [pid 402041:tid 402196] [client 209.38.43.81:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:00.322581 2026] [security2:error] [pid 402041:tid 402107] [remote 159.65.81.207:39316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9U8IiENNLP6XjiHQttYAACAz8"]
[Tue Jul 21 08:16:00.332076 2026] [security2:error] [pid 402041:tid 402247] [client 74.249.245.134:15124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/rip.php"] [unique_id "al9U8IiENNLP6XjiHQttYQAAAdk"]
[Tue Jul 21 08:16:00.367415 2026] [security2:error] [pid 402041:tid 402186] [client 4.194.24.143:21556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp-load.php"] [unique_id "al9U8IiENNLP6XjiHQttYgAAAZw"]
[Tue Jul 21 08:16:00.425950 2026] [security2:error] [pid 402041:tid 402104] [remote 41.186.86.12:2335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9U8IiENNLP6XjiHQttZwABqDw"]
[Tue Jul 21 08:16:00.428629 2026] [security2:error] [pid 402041:tid 402234] [client 154.208.47.43:53217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9U8IiENNLP6XjiHQttaAAAAcw"]
[Tue Jul 21 08:16:00.428724 2026] [security2:error] [pid 402041:tid 402234] [client 154.208.47.43:53217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9U8IiENNLP6XjiHQttaAAAAcw"]
[Tue Jul 21 08:16:00.527356 2026] [security2:error] [pid 402041:tid 402221] [client 103.78.200.11:58333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U8IiENNLP6XjiHQttagAAAb8"]
[Tue Jul 21 08:16:00.527763 2026] [security2:error] [pid 402041:tid 402221] [client 103.78.200.11:58333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U8IiENNLP6XjiHQttagAAAb8"]
[Tue Jul 21 08:16:00.650060 2026] [security2:error] [pid 402041:tid 402204] [client 20.220.225.223:24251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-signup.php"] [unique_id "al9U8IiENNLP6XjiHQtteAAAAa4"]
[Tue Jul 21 08:16:00.750729 2026] [proxy:error] [pid 402041:tid 402182] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:00.750802 2026] [proxy_http:error] [pid 402041:tid 402182] [client 209.38.43.81:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.luizgustavogandraroc1782317692854.0711679.meusitehostgator.com.br/
[Tue Jul 21 08:16:00.751454 2026] [proxy:error] [pid 402041:tid 402182] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:00.751499 2026] [proxy_http:error] [pid 402041:tid 402182] [client 209.38.43.81:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.luizgustavogandraroc1782317692854.0711679.meusitehostgator.com.br/
[Tue Jul 21 08:16:00.758240 2026] [security2:error] [pid 402041:tid 402222] [client 20.220.225.223:55751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/mac.php"] [unique_id "al9U8IiENNLP6XjiHQttfQAAAcA"]
[Tue Jul 21 08:16:00.821883 2026] [security2:error] [pid 402041:tid 402271] [client 20.151.10.161:20454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9U8IiENNLP6XjiHQttfwAAAfE"]
[Tue Jul 21 08:16:00.877635 2026] [security2:error] [pid 402041:tid 402206] [client 20.151.10.161:51121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/themes.php"] [unique_id "al9U8IiENNLP6XjiHQttgAAAAbA"]
[Tue Jul 21 08:16:01.093757 2026] [security2:error] [pid 402041:tid 402167] [remote 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.hauptmann.com.br"] [uri "/wp-login.php"] [unique_id "al9U8YiENNLP6XjiHQtthgABmns"]
[Tue Jul 21 08:16:01.354365 2026] [security2:error] [pid 402041:tid 402140] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9U8YiENNLP6XjiHQttkAABtGA"]
[Tue Jul 21 08:16:01.354569 2026] [security2:error] [pid 402041:tid 402210] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9U8YiENNLP6XjiHQttkAABtGA"]
[Tue Jul 21 08:16:01.402612 2026] [security2:error] [pid 402041:tid 402214] [client 4.194.24.143:20452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp-login.php"] [unique_id "al9U8YiENNLP6XjiHQttkgAAAbg"]
[Tue Jul 21 08:16:01.421677 2026] [security2:error] [pid 402041:tid 402223] [client 91.92.47.112:27260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/info.php"] [unique_id "al9U74iENNLP6XjiHQttNAAAAcE"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:16:01.453697 2026] [security2:error] [pid 402041:tid 402253] [client 20.151.10.161:51103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/dx.php"] [unique_id "al9U8YiENNLP6XjiHQttlAAAAd8"]
[Tue Jul 21 08:16:01.509194 2026] [security2:error] [pid 402041:tid 402198] [client 20.151.10.161:20441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/f6.php"] [unique_id "al9U8YiENNLP6XjiHQttlgAAAag"]
[Tue Jul 21 08:16:01.847561 2026] [security2:error] [pid 402041:tid 402279] [client 87.116.180.198:27264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U8YiENNLP6XjiHQttpAAAAfk"]
[Tue Jul 21 08:16:01.852208 2026] [security2:error] [pid 402041:tid 402279] [client 87.116.180.198:27264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U8YiENNLP6XjiHQttpAAAAfk"]
[Tue Jul 21 08:16:02.038112 2026] [security2:error] [pid 402041:tid 402194] [client 74.249.245.134:15412] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.fernandohipolito.com.br"] [uri "/1.php"] [unique_id "al9U8oiENNLP6XjiHQttqAAAAaQ"]
[Tue Jul 21 08:16:02.038235 2026] [security2:error] [pid 402041:tid 402194] [client 74.249.245.134:15412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/1.php"] [unique_id "al9U8oiENNLP6XjiHQttqAAAAaQ"]
[Tue Jul 21 08:16:02.045436 2026] [security2:error] [pid 402041:tid 402174] [client 65.21.113.253:42382] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9U8YiENNLP6XjiHQttpQAAAZA"]
[Tue Jul 21 08:16:02.109059 2026] [security2:error] [pid 402041:tid 402191] [client 20.151.10.161:13255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/ops.php"] [unique_id "al9U8oiENNLP6XjiHQttqwAAAaE"]
[Tue Jul 21 08:16:02.174339 2026] [security2:error] [pid 402041:tid 402275] [client 20.220.225.223:52625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/samll.php"] [unique_id "al9U8oiENNLP6XjiHQttrQAAAfU"]
[Tue Jul 21 08:16:02.208187 2026] [security2:error] [pid 402041:tid 402244] [client 20.151.10.161:20398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/inputs.php"] [unique_id "al9U8oiENNLP6XjiHQttsAAAAdY"]
[Tue Jul 21 08:16:02.369332 2026] [security2:error] [pid 402041:tid 402197] [client 102.206.115.33:60323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U8oiENNLP6XjiHQtttAAAAac"]
[Tue Jul 21 08:16:02.369470 2026] [security2:error] [pid 402041:tid 402197] [client 102.206.115.33:60323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U8oiENNLP6XjiHQtttAAAAac"]
[Tue Jul 21 08:16:02.489011 2026] [security2:error] [pid 402041:tid 402259] [client 4.194.24.143:20457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp-mail.php"] [unique_id "al9U8oiENNLP6XjiHQtttgAAAeU"]
[Tue Jul 21 08:16:02.632365 2026] [security2:error] [pid 402041:tid 402180] [client 20.151.10.161:36591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/p.php"] [unique_id "al9U8oiENNLP6XjiHQtttwAAAZY"]
[Tue Jul 21 08:16:02.878020 2026] [security2:error] [pid 402041:tid 402066] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U8oiENNLP6XjiHQttxgABuRY"]
[Tue Jul 21 08:16:02.878183 2026] [security2:error] [pid 402041:tid 402215] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U8oiENNLP6XjiHQttxgABuRY"]
[Tue Jul 21 08:16:02.946189 2026] [security2:error] [pid 402041:tid 402288] [client 20.151.10.161:20383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/inputs.php"] [unique_id "al9U8oiENNLP6XjiHQttxwAAAgI"]
[Tue Jul 21 08:16:03.029509 2026] [access_compat:error] [pid 402041:tid 402221] [client 162.241.63.68:27782] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:16:03.178093 2026] [security2:error] [pid 402041:tid 402250] [client 65.21.113.253:42392] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9U8oiENNLP6XjiHQttvgAAAdw"]
[Tue Jul 21 08:16:03.193218 2026] [security2:error] [pid 402041:tid 402211] [client 65.21.113.253:42394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9U8oiENNLP6XjiHQttvAAAAbU"]
[Tue Jul 21 08:16:03.324361 2026] [security2:error] [pid 402041:tid 402177] [client 187.125.243.197:50168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9U84iENNLP6XjiHQtt0AAAAZM"]
[Tue Jul 21 08:16:03.324566 2026] [security2:error] [pid 402041:tid 402177] [client 187.125.243.197:50168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9U84iENNLP6XjiHQtt0AAAAZM"]
[Tue Jul 21 08:16:03.332424 2026] [security2:error] [pid 402041:tid 402208] [client 14.245.224.124:59824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9U84iENNLP6XjiHQtt0QAAAbI"]
[Tue Jul 21 08:16:03.332574 2026] [security2:error] [pid 402041:tid 402208] [client 14.245.224.124:59824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9U84iENNLP6XjiHQtt0QAAAbI"]
[Tue Jul 21 08:16:03.503161 2026] [security2:error] [pid 402041:tid 402216] [client 20.197.192.193:63917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/blue.php"] [unique_id "al9U84iENNLP6XjiHQtt2QAAAbo"]
[Tue Jul 21 08:16:03.532147 2026] [security2:error] [pid 402041:tid 402286] [client 4.194.24.143:52629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp-signin.php"] [unique_id "al9U84iENNLP6XjiHQtt2gAAAgA"]
[Tue Jul 21 08:16:03.533780 2026] [security2:error] [pid 402041:tid 402194] [client 20.151.10.161:13282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/ingfo.php"] [unique_id "al9U84iENNLP6XjiHQtt2wAAAaQ"]
[Tue Jul 21 08:16:03.588983 2026] [security2:error] [pid 402041:tid 402191] [client 20.151.10.161:20434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/av.php"] [unique_id "al9U84iENNLP6XjiHQtt3wAAAaE"]
[Tue Jul 21 08:16:04.017537 2026] [security2:error] [pid 402041:tid 402117] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U9IiENNLP6XjiHQtt8AABr0k"]
[Tue Jul 21 08:16:04.017676 2026] [security2:error] [pid 402041:tid 402205] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U9IiENNLP6XjiHQtt8AABr0k"]
[Tue Jul 21 08:16:04.018255 2026] [security2:error] [pid 402041:tid 402289] [client 20.151.10.161:51111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/bthil.php"] [unique_id "al9U9IiENNLP6XjiHQtt8QAAAgM"]
[Tue Jul 21 08:16:04.084065 2026] [security2:error] [pid 402041:tid 402204] [client 20.151.10.161:20469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/classwithtostring.php"] [unique_id "al9U9IiENNLP6XjiHQtt8wAAAa4"]
[Tue Jul 21 08:16:04.151284 2026] [security2:error] [pid 402041:tid 402196] [client 20.220.225.223:24203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/csa.php"] [unique_id "al9U9IiENNLP6XjiHQtt9AAAAaY"]
[Tue Jul 21 08:16:04.516530 2026] [security2:error] [pid 402041:tid 402246] [client 20.151.10.161:36428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/7.php"] [unique_id "al9U9IiENNLP6XjiHQtuAwAAAdg"]
[Tue Jul 21 08:16:04.554537 2026] [security2:error] [pid 402041:tid 402264] [client 4.194.24.143:1112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp-sigunq.php"] [unique_id "al9U9IiENNLP6XjiHQtuBQAAAeo"]
[Tue Jul 21 08:16:04.573427 2026] [security2:error] [pid 402041:tid 402268] [client 111.93.58.162:15068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9U9IiENNLP6XjiHQtuBgAAAe4"]
[Tue Jul 21 08:16:04.573582 2026] [security2:error] [pid 402041:tid 402268] [client 111.93.58.162:15068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9U9IiENNLP6XjiHQtuBgAAAe4"]
[Tue Jul 21 08:16:04.665113 2026] [security2:error] [pid 402041:tid 402217] [client 20.151.10.161:20360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9U9IiENNLP6XjiHQtuCAAAAbs"]
[Tue Jul 21 08:16:04.673285 2026] [security2:error] [pid 402041:tid 402175] [client 74.249.245.134:15164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/chosen.php"] [unique_id "al9U9IiENNLP6XjiHQtuCQAAAZE"]
[Tue Jul 21 08:16:04.830398 2026] [security2:error] [pid 402041:tid 402299] [client 20.151.10.161:36563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/8.php"] [unique_id "al9U9IiENNLP6XjiHQtuDAAAAg0"]
[Tue Jul 21 08:16:05.047857 2026] [security2:error] [pid 402041:tid 402195] [client 51.161.65.227:59492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bestsellerdigital.com.br"] [uri "/robots.txt"] [unique_id "al9U9YiENNLP6XjiHQtuEwAAAaU"]
[Tue Jul 21 08:16:05.047985 2026] [security2:error] [pid 402041:tid 402195] [client 51.161.65.227:59492] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bestsellerdigital.com.br"] [uri "/robots.txt"] [unique_id "al9U9YiENNLP6XjiHQtuEwAAAaU"]
[Tue Jul 21 08:16:05.121922 2026] [security2:error] [pid 402041:tid 402233] [client 20.151.10.161:20308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wp-blog.php"] [unique_id "al9U9YiENNLP6XjiHQtuFwAAAcs"]
[Tue Jul 21 08:16:05.249841 2026] [security2:error] [pid 402041:tid 402297] [client 115.134.11.136:55406] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U9YiENNLP6XjiHQtuGQAAAgs"]
[Tue Jul 21 08:16:05.338374 2026] [security2:error] [pid 402041:tid 402199] [client 20.151.10.161:36601] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/1.php"] [unique_id "al9U9YiENNLP6XjiHQtuGgAAAak"]
[Tue Jul 21 08:16:05.338498 2026] [security2:error] [pid 402041:tid 402199] [client 20.151.10.161:36601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/1.php"] [unique_id "al9U9YiENNLP6XjiHQtuGgAAAak"]
[Tue Jul 21 08:16:05.575895 2026] [security2:error] [pid 402041:tid 402270] [client 4.194.24.143:1099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp-the.php"] [unique_id "al9U9YiENNLP6XjiHQtuIgAAAfA"]
[Tue Jul 21 08:16:05.704808 2026] [security2:error] [pid 402041:tid 402284] [client 20.151.10.161:20471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9U9YiENNLP6XjiHQtuJwAAAf4"]
[Tue Jul 21 08:16:05.945469 2026] [security2:error] [pid 402041:tid 402218] [client 20.151.10.161:36562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/100.php"] [unique_id "al9U9YiENNLP6XjiHQtuLAAAAbw"]
[Tue Jul 21 08:16:06.121344 2026] [security2:error] [pid 402041:tid 402194] [client 20.151.10.161:20438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/adminfuns.php"] [unique_id "al9U9oiENNLP6XjiHQtuMQAAAaQ"]
[Tue Jul 21 08:16:06.202736 2026] [security2:error] [pid 402041:tid 402176] [client 20.151.10.161:13288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/error_log.php"] [unique_id "al9U9oiENNLP6XjiHQtuMwAAAZI"]
[Tue Jul 21 08:16:06.290767 2026] [security2:error] [pid 402041:tid 402228] [client 74.249.245.134:15149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/css.php"] [unique_id "al9U9oiENNLP6XjiHQtuNAAAAcY"]
[Tue Jul 21 08:16:06.419672 2026] [security2:error] [pid 402041:tid 402271] [client 20.151.10.161:20448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/goods.php"] [unique_id "al9U9oiENNLP6XjiHQtuNwAAAfE"]
[Tue Jul 21 08:16:06.455410 2026] [security2:error] [pid 402041:tid 402226] [client 54.39.136.247:54894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "bestsellerdigital.com.br"] [uri "/"] [unique_id "al9U9oiENNLP6XjiHQtuOAAAAcQ"]
[Tue Jul 21 08:16:06.455532 2026] [security2:error] [pid 402041:tid 402226] [client 54.39.136.247:54894] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bestsellerdigital.com.br"] [uri "/"] [unique_id "al9U9oiENNLP6XjiHQtuOAAAAcQ"]
[Tue Jul 21 08:16:06.528324 2026] [security2:error] [pid 402041:tid 402261] [client 20.151.10.161:51073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/about.php"] [unique_id "al9U9oiENNLP6XjiHQtuQQAAAec"]
[Tue Jul 21 08:16:06.612589 2026] [security2:error] [pid 402041:tid 402203] [client 150.129.202.39:64788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U9oiENNLP6XjiHQtuQgAAAa0"]
[Tue Jul 21 08:16:06.612735 2026] [security2:error] [pid 402041:tid 402203] [client 150.129.202.39:64788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U9oiENNLP6XjiHQtuQgAAAa0"]
[Tue Jul 21 08:16:06.628653 2026] [security2:error] [pid 402041:tid 402177] [client 120.56.162.40:49901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U9oiENNLP6XjiHQtuRAAAAZM"]
[Tue Jul 21 08:16:06.628775 2026] [security2:error] [pid 402041:tid 402177] [client 120.56.162.40:49901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U9oiENNLP6XjiHQtuRAAAAZM"]
[Tue Jul 21 08:16:06.666106 2026] [security2:error] [pid 402041:tid 402275] [client 4.194.24.143:1133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp-themes.php"] [unique_id "al9U9oiENNLP6XjiHQtuRQAAAfU"]
[Tue Jul 21 08:16:06.800487 2026] [security2:error] [pid 402041:tid 402247] [client 20.151.10.161:20354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/ms-edit.php"] [unique_id "al9U9oiENNLP6XjiHQtuTAAAAdk"]
[Tue Jul 21 08:16:07.003997 2026] [security2:error] [pid 402041:tid 402198] [client 86.106.84.166:54502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9U94iENNLP6XjiHQtuUwAAAag"]
[Tue Jul 21 08:16:07.004125 2026] [security2:error] [pid 402041:tid 402198] [client 86.106.84.166:54502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9U94iENNLP6XjiHQtuUwAAAag"]
[Tue Jul 21 08:16:07.037020 2026] [security2:error] [pid 402041:tid 402281] [client 20.151.10.161:13299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/ok.php"] [unique_id "al9U94iENNLP6XjiHQtuVwAAAfs"]
[Tue Jul 21 08:16:07.088265 2026] [security2:error] [pid 402041:tid 402291] [client 20.220.225.223:24273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/min.php"] [unique_id "al9U94iENNLP6XjiHQtuWAAAAgU"]
[Tue Jul 21 08:16:07.111396 2026] [security2:error] [pid 402041:tid 402187] [client 162.219.176.3:54608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9U94iENNLP6XjiHQtuXAAAAZ0"]
[Tue Jul 21 08:16:07.111504 2026] [security2:error] [pid 402041:tid 402187] [client 162.219.176.3:54608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9U94iENNLP6XjiHQtuXAAAAZ0"]
[Tue Jul 21 08:16:07.144850 2026] [security2:error] [pid 402041:tid 402248] [client 20.151.10.161:20416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/222.php"] [unique_id "al9U94iENNLP6XjiHQtuXQAAAdo"]
[Tue Jul 21 08:16:07.439900 2026] [security2:error] [pid 402041:tid 402255] [client 117.210.135.0:57661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U94iENNLP6XjiHQtuXwAAAeE"]
[Tue Jul 21 08:16:07.440026 2026] [security2:error] [pid 402041:tid 402255] [client 117.210.135.0:57661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U94iENNLP6XjiHQtuXwAAAeE"]
[Tue Jul 21 08:16:07.538455 2026] [security2:error] [pid 402041:tid 402217] [client 20.151.10.161:20402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9U94iENNLP6XjiHQtuYwAAAbs"]
[Tue Jul 21 08:16:07.543535 2026] [security2:error] [pid 402041:tid 402175] [client 20.151.10.161:13308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/mac.php"] [unique_id "al9U94iENNLP6XjiHQtuZAAAAZE"]
[Tue Jul 21 08:16:07.620521 2026] [security2:error] [pid 402041:tid 402168] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9U94iENNLP6XjiHQtuaAAB9Hw"]
[Tue Jul 21 08:16:07.620679 2026] [security2:error] [pid 402041:tid 402274] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9U94iENNLP6XjiHQtuaAAB9Hw"]
[Tue Jul 21 08:16:07.633725 2026] [security2:error] [pid 402041:tid 402238] [client 20.151.10.161:51099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/admin.php"] [unique_id "al9U94iENNLP6XjiHQtuagAAAdA"]
[Tue Jul 21 08:16:07.688985 2026] [security2:error] [pid 402041:tid 402231] [client 4.194.24.143:1110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp-trackback.php"] [unique_id "al9U94iENNLP6XjiHQtubAAAAck"]
[Tue Jul 21 08:16:08.095728 2026] [security2:error] [pid 402041:tid 402242] [client 20.151.10.161:20439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9U-IiENNLP6XjiHQtumAAAAdQ"]
[Tue Jul 21 08:16:08.110402 2026] [security2:error] [pid 402041:tid 402278] [client 20.151.10.161:13268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wefile.php"] [unique_id "al9U-IiENNLP6XjiHQtunQAAAfg"]
[Tue Jul 21 08:16:08.226728 2026] [security2:error] [pid 402041:tid 402101] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U-IiENNLP6XjiHQtupwABpzk"]
[Tue Jul 21 08:16:08.226860 2026] [security2:error] [pid 402041:tid 402197] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U-IiENNLP6XjiHQtupwABpzk"]
[Tue Jul 21 08:16:08.505779 2026] [security2:error] [pid 402041:tid 402227] [client 20.151.10.161:13196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9U-IiENNLP6XjiHQturwAAAcU"]
[Tue Jul 21 08:16:08.656983 2026] [security2:error] [pid 402041:tid 402268] [client 62.102.148.158:50996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9U-IiENNLP6XjiHQtuuQAAAe4"]
[Tue Jul 21 08:16:08.657084 2026] [security2:error] [pid 402041:tid 402268] [client 62.102.148.158:50996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9U-IiENNLP6XjiHQtuuQAAAe4"]
[Tue Jul 21 08:16:08.716307 2026] [security2:error] [pid 402041:tid 402221] [client 4.194.24.143:20449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp-user.php"] [unique_id "al9U-IiENNLP6XjiHQtuvAAAAb8"]
[Tue Jul 21 08:16:08.810761 2026] [security2:error] [pid 402041:tid 402264] [client 20.151.10.161:20382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/raw.php"] [unique_id "al9U-IiENNLP6XjiHQtuvgAAAeo"]
[Tue Jul 21 08:16:08.860130 2026] [security2:error] [pid 402041:tid 402296] [client 185.213.175.37:43876] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.roanalacerda.com.br"] [uri "/"] [unique_id "al9U-IiENNLP6XjiHQtuvwAAAgo"]
[Tue Jul 21 08:16:08.872219 2026] [security2:error] [pid 402041:tid 402279] [client 45.45.237.208:48030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "localizavistorias.com"] [uri "/wp-content/litespeed/js/8c27af1ea0465f758b057e85e4a4a857.js"] [unique_id "al9U-IiENNLP6XjiHQtuwQAAAfk"]
[Tue Jul 21 08:16:08.872347 2026] [security2:error] [pid 402041:tid 402279] [client 45.45.237.208:48030] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "localizavistorias.com"] [uri "/wp-content/litespeed/js/8c27af1ea0465f758b057e85e4a4a857.js"] [unique_id "al9U-IiENNLP6XjiHQtuwQAAAfk"]
[Tue Jul 21 08:16:09.008577 2026] [security2:error] [pid 402041:tid 402176] [client 20.197.192.193:47083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9U-YiENNLP6XjiHQtuxgAAAZI"]
[Tue Jul 21 08:16:09.025962 2026] [security2:error] [pid 402041:tid 402191] [client 20.197.192.193:3379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/ez.php"] [unique_id "al9U-YiENNLP6XjiHQtuxwAAAaE"]
[Tue Jul 21 08:16:09.043933 2026] [security2:error] [pid 402041:tid 402228] [client 61.1.167.83:55585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U-YiENNLP6XjiHQtuyAAAAcY"]
[Tue Jul 21 08:16:09.044060 2026] [security2:error] [pid 402041:tid 402228] [client 61.1.167.83:55585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U-YiENNLP6XjiHQtuyAAAAcY"]
[Tue Jul 21 08:16:09.058446 2026] [security2:error] [pid 402041:tid 402238] [client 20.197.192.193:47103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9U-YiENNLP6XjiHQtuygAAAdA"]
[Tue Jul 21 08:16:09.083994 2026] [security2:error] [pid 402041:tid 402231] [client 45.45.237.208:48052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "localizavistorias.com"] [uri "/.env"] [unique_id "al9U-YiENNLP6XjiHQtuzQAAAck"]
[Tue Jul 21 08:16:09.096567 2026] [security2:error] [pid 402041:tid 402226] [client 20.197.192.193:14881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/dp.php"] [unique_id "al9U-YiENNLP6XjiHQtuzgAAAcQ"]
[Tue Jul 21 08:16:09.131556 2026] [security2:error] [pid 402041:tid 402233] [client 20.197.192.193:47050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/old.php"] [unique_id "al9U-YiENNLP6XjiHQtu1AAAAcs"]
[Tue Jul 21 08:16:09.179069 2026] [security2:error] [pid 402041:tid 402230] [client 20.197.192.193:47067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/ms-new.php"] [unique_id "al9U-YiENNLP6XjiHQtu2AAAAcg"]
[Tue Jul 21 08:16:09.179578 2026] [security2:error] [pid 402041:tid 402219] [client 20.151.10.161:20426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/abcd.php"] [unique_id "al9U-YiENNLP6XjiHQtu2QAAAb0"]
[Tue Jul 21 08:16:09.212945 2026] [proxy:error] [pid 402041:tid 402203] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:09.213005 2026] [proxy_http:error] [pid 402041:tid 402203] [client 20.151.10.161:13258] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:09.213699 2026] [proxy:error] [pid 402041:tid 402203] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:09.213727 2026] [proxy_http:error] [pid 402041:tid 402203] [client 20.151.10.161:13258] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:09.232183 2026] [security2:error] [pid 402041:tid 402280] [client 74.249.245.134:15151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/php.php"] [unique_id "al9U-YiENNLP6XjiHQtu3AAAAfo"]
[Tue Jul 21 08:16:09.257774 2026] [security2:error] [pid 402041:tid 402184] [client 20.197.192.193:14860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/track.php"] [unique_id "al9U-YiENNLP6XjiHQtu3wAAAZo"]
[Tue Jul 21 08:16:09.312065 2026] [security2:error] [pid 402041:tid 402185] [client 20.197.192.193:14853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/2352356666.php"] [unique_id "al9U-YiENNLP6XjiHQtu4gAAAZs"]
[Tue Jul 21 08:16:09.368821 2026] [security2:error] [pid 402041:tid 402242] [client 20.151.10.161:36577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/edit.php"] [unique_id "al9U-YiENNLP6XjiHQtu4wAAAdQ"]
[Tue Jul 21 08:16:09.402391 2026] [security2:error] [pid 402041:tid 402186] [client 20.197.192.193:14872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/pn.php"] [unique_id "al9U-YiENNLP6XjiHQtu5gAAAZw"]
[Tue Jul 21 08:16:09.431698 2026] [security2:error] [pid 402041:tid 402199] [client 20.197.192.193:47072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/wp-wpbak.php"] [unique_id "al9U-YiENNLP6XjiHQtu6AAAAak"]
[Tue Jul 21 08:16:09.475858 2026] [security2:error] [pid 402041:tid 402270] [client 20.197.192.193:14849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/dr.php"] [unique_id "al9U-YiENNLP6XjiHQtu7AAAAfA"]
[Tue Jul 21 08:16:09.491762 2026] [security2:error] [pid 402041:tid 402281] [client 20.151.10.161:20462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/a1.php"] [unique_id "al9U-YiENNLP6XjiHQtu7QAAAfs"]
[Tue Jul 21 08:16:09.621995 2026] [security2:error] [pid 402041:tid 402263] [client 20.197.192.193:14850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/2x.php"] [unique_id "al9U-YiENNLP6XjiHQtu-gAAAek"]
[Tue Jul 21 08:16:09.710779 2026] [security2:error] [pid 402041:tid 402176] [client 45.45.237.208:48044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "localizavistorias.com"] [uri "/.env.local"] [unique_id "al9U-YiENNLP6XjiHQtvBAAAAZI"]
[Tue Jul 21 08:16:09.710914 2026] [security2:error] [pid 402041:tid 402176] [client 45.45.237.208:48044] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "localizavistorias.com"] [uri "/.env.local"] [unique_id "al9U-YiENNLP6XjiHQtvBAAAAZI"]
[Tue Jul 21 08:16:09.743302 2026] [security2:error] [pid 402041:tid 402240] [client 4.194.24.143:1116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp-ver.php"] [unique_id "al9U-YiENNLP6XjiHQtvCAAAAdI"]
[Tue Jul 21 08:16:09.788776 2026] [security2:error] [pid 402041:tid 402211] [client 20.197.192.193:14875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/kq1.php"] [unique_id "al9U-YiENNLP6XjiHQtvEAAAAbU"]
[Tue Jul 21 08:16:09.814237 2026] [security2:error] [pid 402041:tid 402283] [client 20.151.10.161:20464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9U-YiENNLP6XjiHQtvFAAAAf0"]
[Tue Jul 21 08:16:09.842548 2026] [security2:error] [pid 402041:tid 402246] [client 20.197.192.193:47044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/zzz.php"] [unique_id "al9U-YiENNLP6XjiHQtvFwAAAdg"]
[Tue Jul 21 08:16:09.884761 2026] [proxy:error] [pid 402041:tid 402263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:09.884848 2026] [proxy_http:error] [pid 402041:tid 402263] [client 20.151.10.161:13209] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:09.886072 2026] [proxy:error] [pid 402041:tid 402263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:09.886104 2026] [proxy_http:error] [pid 402041:tid 402263] [client 20.151.10.161:13209] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:09.903492 2026] [security2:error] [pid 402041:tid 402284] [client 20.197.192.193:47075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/wicked.php"] [unique_id "al9U-YiENNLP6XjiHQtvHAAAAf4"]
[Tue Jul 21 08:16:09.928531 2026] [security2:error] [pid 402041:tid 402297] [client 115.134.11.136:55406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U9YiENNLP6XjiHQtuGQAAAgs"]
[Tue Jul 21 08:16:09.943613 2026] [security2:error] [pid 402041:tid 402187] [client 20.197.192.193:47047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/edit.php"] [unique_id "al9U-YiENNLP6XjiHQtvIAAAAZ0"]
[Tue Jul 21 08:16:10.000824 2026] [security2:error] [pid 402041:tid 402221] [client 20.197.192.193:47071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/kua.php"] [unique_id "al9U-oiENNLP6XjiHQtvIQAAAb8"]
[Tue Jul 21 08:16:10.009121 2026] [security2:error] [pid 402041:tid 402277] [client 20.197.192.193:63916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/wp-signup.php"] [unique_id "al9U-oiENNLP6XjiHQtvJgAAAfc"]
[Tue Jul 21 08:16:10.018605 2026] [core:error] [pid 402041:tid 402296] [client 198.235.24.79:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:16:10.018622 2026] [core:error] [pid 402041:tid 402296] [client 198.235.24.79:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:16:10.052530 2026] [security2:error] [pid 402041:tid 402275] [client 20.197.192.193:47066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/ez.php"] [unique_id "al9U-oiENNLP6XjiHQtvKgAAAfU"]
[Tue Jul 21 08:16:10.096089 2026] [security2:error] [pid 402041:tid 402206] [client 20.197.192.193:14878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/fz.php"] [unique_id "al9U-oiENNLP6XjiHQtvLQAAAbA"]
[Tue Jul 21 08:16:10.102391 2026] [http2:info] [pid 411857:tid 411857] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 08:16:10.143742 2026] [security2:error] [pid 411857:tid 411990] [client 20.197.192.193:14901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/la.php"] [unique_id "al9U-i7ynBpLeKYztQOvOQAAAAE"]
[Tue Jul 21 08:16:10.173063 2026] [security2:error] [pid 402041:tid 402268] [client 20.197.192.193:14848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/nhvoanpl.php"] [unique_id "al9U-oiENNLP6XjiHQtvNAAAAe4"]
[Tue Jul 21 08:16:10.237510 2026] [security2:error] [pid 402041:tid 402192] [client 45.45.237.208:36236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "localizavistorias.com"] [uri "/openapi.json"] [unique_id "al9U-oiENNLP6XjiHQtvNgAAAaI"]
[Tue Jul 21 08:16:10.237638 2026] [security2:error] [pid 402041:tid 402192] [client 45.45.237.208:36236] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "localizavistorias.com"] [uri "/openapi.json"] [unique_id "al9U-oiENNLP6XjiHQtvNgAAAaI"]
[Tue Jul 21 08:16:10.249339 2026] [security2:error] [pid 402041:tid 402269] [client 45.45.237.208:36296] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "localizavistorias.com"] [uri "/web.config"] [unique_id "al9U-oiENNLP6XjiHQtvPAAAAe8"]
[Tue Jul 21 08:16:10.253983 2026] [security2:error] [pid 402041:tid 402173] [client 45.45.237.208:36338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "localizavistorias.com"] [uri "/.netrc"] [unique_id "al9U-oiENNLP6XjiHQtvPwAAAY8"]
[Tue Jul 21 08:16:10.253983 2026] [security2:error] [pid 402041:tid 402274] [client 45.45.237.208:36462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "localizavistorias.com"] [uri "/netlify.toml"] [unique_id "al9U-oiENNLP6XjiHQtvQAAAAfQ"]
[Tue Jul 21 08:16:10.254108 2026] [security2:error] [pid 402041:tid 402274] [client 45.45.237.208:36462] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "localizavistorias.com"] [uri "/netlify.toml"] [unique_id "al9U-oiENNLP6XjiHQtvQAAAAfQ"]
[Tue Jul 21 08:16:10.254108 2026] [security2:error] [pid 402041:tid 402173] [client 45.45.237.208:36338] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "localizavistorias.com"] [uri "/.netrc"] [unique_id "al9U-oiENNLP6XjiHQtvPwAAAY8"]
[Tue Jul 21 08:16:10.254426 2026] [security2:error] [pid 411857:tid 411999] [client 20.197.192.193:47079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/inso.php"] [unique_id "al9U-i7ynBpLeKYztQOvPAAAAAo"]
[Tue Jul 21 08:16:10.261169 2026] [security2:error] [pid 402041:tid 402252] [client 45.45.237.208:36354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "localizavistorias.com"] [uri "/terraform.tfstate"] [unique_id "al9U-oiENNLP6XjiHQtvUwAAAd4"]
[Tue Jul 21 08:16:10.261310 2026] [security2:error] [pid 402041:tid 402252] [client 45.45.237.208:36354] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "localizavistorias.com"] [uri "/terraform.tfstate"] [unique_id "al9U-oiENNLP6XjiHQtvUwAAAd4"]
[Tue Jul 21 08:16:10.262387 2026] [security2:error] [pid 402041:tid 402226] [client 45.45.237.208:36524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "localizavistorias.com"] [uri "/wp/.env"] [unique_id "al9U-oiENNLP6XjiHQtvZQAAAcQ"]
[Tue Jul 21 08:16:10.262548 2026] [security2:error] [pid 402041:tid 402226] [client 45.45.237.208:36524] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "localizavistorias.com"] [uri "/wp/.env"] [unique_id "al9U-oiENNLP6XjiHQtvZQAAAcQ"]
[Tue Jul 21 08:16:10.262932 2026] [security2:error] [pid 402041:tid 402281] [client 45.45.237.208:36290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "localizavistorias.com"] [uri "/wp-config.php.bak"] [unique_id "al9U-oiENNLP6XjiHQtvbQAAAfs"]
[Tue Jul 21 08:16:10.264625 2026] [security2:error] [pid 402041:tid 402292] [client 45.45.237.208:36070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "localizavistorias.com"] [uri "/laravel/.env"] [unique_id "al9U-oiENNLP6XjiHQtvVQAAAgY"]
[Tue Jul 21 08:16:10.264705 2026] [security2:error] [pid 402041:tid 402285] [client 45.45.237.208:36002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "localizavistorias.com"] [uri "/.env.old"] [unique_id "al9U-oiENNLP6XjiHQtvRAAAAf8"]
[Tue Jul 21 08:16:10.265014 2026] [security2:error] [pid 402041:tid 402298] [client 45.45.237.208:36038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "localizavistorias.com"] [uri "/app/.env"] [unique_id "al9U-oiENNLP6XjiHQtvSAAAAgw"]
[Tue Jul 21 08:16:10.266189 2026] [security2:error] [pid 402041:tid 402178] [client 45.45.237.208:36052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "localizavistorias.com"] [uri "/api/.env"] [unique_id "al9U-oiENNLP6XjiHQtvRwAAAZQ"]
[Tue Jul 21 08:16:10.266253 2026] [security2:error] [pid 402041:tid 402198] [client 45.45.237.208:36286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/wp-config.php"] [unique_id "al9U-oiENNLP6XjiHQtvbgAAAag"]
[Tue Jul 21 08:16:10.266451 2026] [security2:error] [pid 402041:tid 402295] [client 45.45.237.208:36044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "localizavistorias.com"] [uri "/backend/.env"] [unique_id "al9U-oiENNLP6XjiHQtvWQAAAgk"]
[Tue Jul 21 08:16:10.266966 2026] [security2:error] [pid 402041:tid 402216] [client 45.45.237.208:35984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "localizavistorias.com"] [uri "/.env.bak"] [unique_id "al9U-oiENNLP6XjiHQtvVgAAAbo"]
[Tue Jul 21 08:16:10.267632 2026] [security2:error] [pid 402041:tid 402256] [client 45.45.237.208:36056] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "localizavistorias.com"] [uri "/public/.env"] [unique_id "al9U-oiENNLP6XjiHQtvdQAAAeI"]
[Tue Jul 21 08:16:10.268945 2026] [security2:error] [pid 402041:tid 402242] [client 45.45.237.208:35996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "localizavistorias.com"] [uri "/.env.backup"] [unique_id "al9U-oiENNLP6XjiHQtvUgAAAdQ"]
[Tue Jul 21 08:16:10.469863 2026] [security2:error] [pid 402041:tid 402286] [client 20.197.192.193:47061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/wpx.php"] [unique_id "al9U-oiENNLP6XjiHQtvewAAAgA"]
[Tue Jul 21 08:16:10.485309 2026] [security2:error] [pid 411857:tid 412003] [client 20.220.225.223:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/abcd.php"] [unique_id "al9U-i7ynBpLeKYztQOvPwAAAA4"]
[Tue Jul 21 08:16:10.520440 2026] [security2:error] [pid 402041:tid 402206] [client 20.197.192.193:47056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/berlin.php"] [unique_id "al9U-oiENNLP6XjiHQtvhgAAAbA"]
[Tue Jul 21 08:16:10.558416 2026] [security2:error] [pid 402041:tid 402212] [client 20.197.192.193:47093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/billur.php"] [unique_id "al9U-oiENNLP6XjiHQtviwAAAbY"]
[Tue Jul 21 08:16:10.582406 2026] [security2:error] [pid 411857:tid 412005] [client 20.197.192.193:14873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/mimpi.php"] [unique_id "al9U-i7ynBpLeKYztQOvQAAAABA"]
[Tue Jul 21 08:16:10.588823 2026] [security2:error] [pid 411857:tid 412007] [client 20.151.10.161:20447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9U-i7ynBpLeKYztQOvQQAAABI"]
[Tue Jul 21 08:16:10.609312 2026] [security2:error] [pid 402041:tid 402220] [client 20.197.192.193:14898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/dp.php"] [unique_id "al9U-oiENNLP6XjiHQtvkAAAAb4"]
[Tue Jul 21 08:16:10.610343 2026] [security2:error] [pid 402041:tid 402231] [client 20.206.105.145:25485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9U-oiENNLP6XjiHQtvkQAAAck"]
[Tue Jul 21 08:16:10.667101 2026] [security2:error] [pid 411857:tid 412010] [client 20.197.192.193:14900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/bootstrap.php"] [unique_id "al9U-i7ynBpLeKYztQOvQwAAABU"]
[Tue Jul 21 08:16:10.671253 2026] [security2:error] [pid 402041:tid 402118] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U-oiENNLP6XjiHQtvlAAB-Uo"]
[Tue Jul 21 08:16:10.671376 2026] [security2:error] [pid 402041:tid 402279] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U-oiENNLP6XjiHQtvlAAB-Uo"]
[Tue Jul 21 08:16:10.718281 2026] [security2:error] [pid 402041:tid 402274] [client 20.151.10.161:13135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9U-oiENNLP6XjiHQtvlgAAAfQ"]
[Tue Jul 21 08:16:10.775673 2026] [security2:error] [pid 411857:tid 411992] [client 38.100.221.102:18667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U-i7ynBpLeKYztQOvRAAAAAM"]
[Tue Jul 21 08:16:10.775897 2026] [security2:error] [pid 411857:tid 411992] [client 38.100.221.102:18667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U-i7ynBpLeKYztQOvRAAAAAM"]
[Tue Jul 21 08:16:10.795537 2026] [security2:error] [pid 411857:tid 412004] [client 4.194.24.143:1121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp-ws68.php"] [unique_id "al9U-i7ynBpLeKYztQOvRQAAAA8"]
[Tue Jul 21 08:16:10.816379 2026] [security2:error] [pid 402041:tid 402292] [client 20.197.192.193:14573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/wp-editor.php"] [unique_id "al9U-oiENNLP6XjiHQtvmgAAAgY"]
[Tue Jul 21 08:16:10.828263 2026] [security2:error] [pid 411857:tid 411991] [client 154.208.47.43:53706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9U-i7ynBpLeKYztQOvRwAAAAI"]
[Tue Jul 21 08:16:10.828391 2026] [security2:error] [pid 411857:tid 411991] [client 154.208.47.43:53706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9U-i7ynBpLeKYztQOvRwAAAAI"]
[Tue Jul 21 08:16:10.939653 2026] [security2:error] [pid 402041:tid 402256] [client 20.197.192.193:14852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/cro.php"] [unique_id "al9U-oiENNLP6XjiHQtvnAAAAeI"]
[Tue Jul 21 08:16:10.987525 2026] [security2:error] [pid 402041:tid 402190] [client 20.151.10.161:20297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9U-oiENNLP6XjiHQtvoAAAAaA"]
[Tue Jul 21 08:16:11.026795 2026] [security2:error] [pid 402041:tid 402296] [client 20.197.192.193:47085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/cron-tab.php"] [unique_id "al9U-4iENNLP6XjiHQtvogAAAgo"]
[Tue Jul 21 08:16:11.070765 2026] [security2:error] [pid 402041:tid 402194] [client 54.39.89.4:42058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.hometohomelondon.com"] [uri "/robots.txt"] [unique_id "al9U-4iENNLP6XjiHQtvowAAAaQ"]
[Tue Jul 21 08:16:11.070894 2026] [security2:error] [pid 402041:tid 402194] [client 54.39.89.4:42058] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.hometohomelondon.com"] [uri "/robots.txt"] [unique_id "al9U-4iENNLP6XjiHQtvowAAAaQ"]
[Tue Jul 21 08:16:11.190394 2026] [security2:error] [pid 402041:tid 402240] [client 20.197.192.193:14868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/koiy.php"] [unique_id "al9U-4iENNLP6XjiHQtvqAAAAdI"]
[Tue Jul 21 08:16:11.222029 2026] [security2:error] [pid 411857:tid 412002] [client 103.78.200.11:58826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U-y7ynBpLeKYztQOvSAAAAA0"]
[Tue Jul 21 08:16:11.222155 2026] [security2:error] [pid 411857:tid 412002] [client 103.78.200.11:58826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U-y7ynBpLeKYztQOvSAAAAA0"]
[Tue Jul 21 08:16:11.224402 2026] [security2:error] [pid 402041:tid 402212] [client 20.197.192.193:14874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/hp2.php"] [unique_id "al9U-4iENNLP6XjiHQtvqgAAAbY"]
[Tue Jul 21 08:16:11.262491 2026] [security2:error] [pid 411857:tid 412028] [client 20.197.192.193:47059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/hp3.php"] [unique_id "al9U-y7ynBpLeKYztQOvSgAAACc"]
[Tue Jul 21 08:16:11.295399 2026] [security2:error] [pid 402041:tid 402221] [client 74.7.175.154:34342] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.regras.oscrias.com.br"] [uri "/robots.txt"] [unique_id "al9U-4iENNLP6XjiHQtvrAABv20"]
[Tue Jul 21 08:16:11.323992 2026] [security2:error] [pid 411857:tid 412034] [client 20.197.192.193:14877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/aa1.php"] [unique_id "al9U-y7ynBpLeKYztQOvTAAAAC0"]
[Tue Jul 21 08:16:11.335151 2026] [lsapi:warn] [pid 402041:tid 402183] [client 45.45.237.208:36498] [host localizavistorias.com] Backend log: PHP Warning:  filemtime(): stat failed for /home4/local331/public_html/wp-content/litespeed/js/404.js.tmp in /home4/local331/public_html/wp-content/plugins/litespeed-cache/src/optimizer.cls.php on line 109\n
[Tue Jul 21 08:16:11.427560 2026] [security2:error] [pid 411857:tid 412042] [client 20.197.192.193:14569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/acew67.php"] [unique_id "al9U-y7ynBpLeKYztQOvUQAAADU"]
[Tue Jul 21 08:16:11.458304 2026] [security2:error] [pid 411857:tid 412045] [client 20.197.192.193:14855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/bscclapb.php"] [unique_id "al9U-y7ynBpLeKYztQOvUgAAADg"]
[Tue Jul 21 08:16:11.538964 2026] [security2:error] [pid 411857:tid 412048] [client 20.197.192.193:14867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/else1.php"] [unique_id "al9U-y7ynBpLeKYztQOvVAAAADs"]
[Tue Jul 21 08:16:11.562115 2026] [security2:error] [pid 411857:tid 412050] [client 20.151.10.161:20394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/simple.php"] [unique_id "al9U-y7ynBpLeKYztQOvVQAAAD0"]
[Tue Jul 21 08:16:11.646013 2026] [security2:error] [pid 411857:tid 412053] [client 20.197.192.193:47068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/tkikikoko.php"] [unique_id "al9U-y7ynBpLeKYztQOvVgAAAEA"]
[Tue Jul 21 08:16:11.692993 2026] [security2:error] [pid 411857:tid 412056] [client 20.197.192.193:47092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/wp-Blogs.php"] [unique_id "al9U-y7ynBpLeKYztQOvVwAAAEM"]
[Tue Jul 21 08:16:11.801750 2026] [security2:error] [pid 402041:tid 402109] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9U-4iENNLP6XjiHQtvtQABtEE"]
[Tue Jul 21 08:16:11.801950 2026] [security2:error] [pid 402041:tid 402210] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9U-4iENNLP6XjiHQtvtQABtEE"]
[Tue Jul 21 08:16:11.884222 2026] [security2:error] [pid 411857:tid 412075] [client 20.151.10.161:36505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9U-y7ynBpLeKYztQOvXgAAAFY"]
[Tue Jul 21 08:16:11.890370 2026] [security2:error] [pid 402041:tid 402292] [client 4.194.24.143:21375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp.php"] [unique_id "al9U-4iENNLP6XjiHQtvtgAAAgY"]
[Tue Jul 21 08:16:11.931319 2026] [security2:error] [pid 402041:tid 402271] [client 20.197.192.193:47045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/wp-css.php"] [unique_id "al9U-4iENNLP6XjiHQtvuAAAAfE"]
[Tue Jul 21 08:16:12.041735 2026] [security2:error] [pid 402041:tid 402187] [client 115.134.11.136:55406] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U_IiENNLP6XjiHQtvuQAAAZ0"]
[Tue Jul 21 08:16:12.041908 2026] [security2:error] [pid 402041:tid 402187] [client 115.134.11.136:55406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U_IiENNLP6XjiHQtvuQAAAZ0"]
[Tue Jul 21 08:16:12.064448 2026] [security2:error] [pid 402041:tid 402268] [client 65.21.113.253:51968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9U-4iENNLP6XjiHQtvsAAAAe4"]
[Tue Jul 21 08:16:12.077729 2026] [security2:error] [pid 402041:tid 402217] [client 20.197.192.193:14860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/wp-explorer.php"] [unique_id "al9U_IiENNLP6XjiHQtvugAAAbs"]
[Tue Jul 21 08:16:12.104548 2026] [security2:error] [pid 402041:tid 402188] [client 20.206.105.145:25571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9U_IiENNLP6XjiHQtvuwAAAZ4"]
[Tue Jul 21 08:16:12.124211 2026] [proxy:error] [pid 402041:tid 402176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:12.124273 2026] [proxy_http:error] [pid 402041:tid 402176] [client 20.151.10.161:13302] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:12.124907 2026] [proxy:error] [pid 402041:tid 402176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:12.124935 2026] [proxy_http:error] [pid 402041:tid 402176] [client 20.151.10.161:13302] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:12.138169 2026] [security2:error] [pid 402041:tid 402194] [client 20.151.10.161:20364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/xxx.php"] [unique_id "al9U_IiENNLP6XjiHQtvvQAAAaQ"]
[Tue Jul 21 08:16:12.368002 2026] [security2:error] [pid 402041:tid 402244] [client 20.197.192.193:14876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/akismet.php"] [unique_id "al9U_IiENNLP6XjiHQtvwwAAAdY"]
[Tue Jul 21 08:16:12.499253 2026] [security2:error] [pid 402041:tid 402202] [client 20.151.10.161:20355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/hypo.php"] [unique_id "al9U_IiENNLP6XjiHQtvxQAAAaw"]
[Tue Jul 21 08:16:12.508482 2026] [security2:error] [pid 411857:tid 412086] [client 20.206.105.145:25556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/media.php"] [unique_id "al9U_C7ynBpLeKYztQOvYgAAAGE"]
[Tue Jul 21 08:16:12.584595 2026] [security2:error] [pid 411857:tid 412076] [client 87.116.180.198:13837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U_C7ynBpLeKYztQOvYwAAAFc"]
[Tue Jul 21 08:16:12.588151 2026] [security2:error] [pid 411857:tid 412076] [client 87.116.180.198:13837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U_C7ynBpLeKYztQOvYwAAAFc"]
[Tue Jul 21 08:16:12.605802 2026] [security2:error] [pid 402041:tid 402212] [client 20.197.192.193:14534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/ace2.php"] [unique_id "al9U_IiENNLP6XjiHQtvxwAAAbY"]
[Tue Jul 21 08:16:12.655020 2026] [security2:error] [pid 402041:tid 402221] [client 20.197.192.193:47087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/ms.php"] [unique_id "al9U_IiENNLP6XjiHQtvyAAAAb8"]
[Tue Jul 21 08:16:12.831048 2026] [security2:error] [pid 402041:tid 402282] [client 20.151.10.161:36582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/f6.php"] [unique_id "al9U_IiENNLP6XjiHQtvzQAAAfw"]
[Tue Jul 21 08:16:12.910421 2026] [security2:error] [pid 411857:tid 412080] [client 102.206.115.33:62997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U_C7ynBpLeKYztQOvZgAAAFs"]
[Tue Jul 21 08:16:12.910527 2026] [security2:error] [pid 411857:tid 412080] [client 102.206.115.33:62997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U_C7ynBpLeKYztQOvZgAAAFs"]
[Tue Jul 21 08:16:12.955975 2026] [security2:error] [pid 411857:tid 412089] [client 4.194.24.143:20419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp/002.php"] [unique_id "al9U_C7ynBpLeKYztQOvZwAAAGQ"]
[Tue Jul 21 08:16:13.044106 2026] [security2:error] [pid 411857:tid 412100] [client 20.220.225.223:55746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/xyn.php"] [unique_id "al9U_S7ynBpLeKYztQOvaQAAAG8"]
[Tue Jul 21 08:16:13.177252 2026] [security2:error] [pid 411857:tid 412101] [client 20.151.10.161:20313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/chosen.php"] [unique_id "al9U_S7ynBpLeKYztQOvagAAAHA"]
[Tue Jul 21 08:16:13.287695 2026] [security2:error] [pid 411857:tid 412031] [client 103.151.46.103:64151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U_S7ynBpLeKYztQOvbAAAACo"]
[Tue Jul 21 08:16:13.288039 2026] [security2:error] [pid 411857:tid 412031] [client 103.151.46.103:64151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9U_S7ynBpLeKYztQOvbAAAACo"]
[Tue Jul 21 08:16:13.363103 2026] [security2:error] [pid 411857:tid 412112] [client 20.197.192.193:13655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9U_S7ynBpLeKYztQOvbwAAAHs"]
[Tue Jul 21 08:16:13.421177 2026] [security2:error] [pid 411857:tid 411861] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U_S7ynBpLeKYztQOvcQAAdQI"]
[Tue Jul 21 08:16:13.421301 2026] [security2:error] [pid 411857:tid 412106] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U_S7ynBpLeKYztQOvcQAAdQI"]
[Tue Jul 21 08:16:13.562173 2026] [security2:error] [pid 402041:tid 402217] [client 20.151.10.161:13204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/like.php"] [unique_id "al9U_YiENNLP6XjiHQtv2AAAAbs"]
[Tue Jul 21 08:16:13.679408 2026] [security2:error] [pid 411857:tid 412001] [client 20.151.10.161:36542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/inputs.php"] [unique_id "al9U_S7ynBpLeKYztQOvdAAAAAw"]
[Tue Jul 21 08:16:13.819630 2026] [security2:error] [pid 402041:tid 402188] [client 187.125.243.197:50652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9U_YiENNLP6XjiHQtv3gAAAZ4"]
[Tue Jul 21 08:16:13.819760 2026] [security2:error] [pid 402041:tid 402188] [client 187.125.243.197:50652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9U_YiENNLP6XjiHQtv3gAAAZ4"]
[Tue Jul 21 08:16:13.862792 2026] [security2:error] [pid 411857:tid 412009] [client 20.151.10.161:20472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/file5.php"] [unique_id "al9U_S7ynBpLeKYztQOvdwAAABQ"]
[Tue Jul 21 08:16:13.951557 2026] [security2:error] [pid 411857:tid 411999] [client 14.245.224.124:60244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9U_S7ynBpLeKYztQOvegAAAAo"]
[Tue Jul 21 08:16:13.951714 2026] [security2:error] [pid 411857:tid 411999] [client 14.245.224.124:60244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9U_S7ynBpLeKYztQOvegAAAAo"]
[Tue Jul 21 08:16:14.037544 2026] [security2:error] [pid 402041:tid 402259] [client 65.21.113.253:51968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9U_YiENNLP6XjiHQtv2QAAAeU"]
[Tue Jul 21 08:16:14.041574 2026] [security2:error] [pid 411857:tid 412003] [client 4.194.24.143:21325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wp/wp-content/themes/extendable/mg2.php"] [unique_id "al9U_i7ynBpLeKYztQOvfAAAAA4"]
[Tue Jul 21 08:16:14.155433 2026] [security2:error] [pid 402041:tid 402138] [remote 20.153.140.50:34894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9U_oiENNLP6XjiHQtv4wAB1F4"]
[Tue Jul 21 08:16:14.294182 2026] [security2:error] [pid 402041:tid 402266] [client 74.249.245.134:15157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/aa.php"] [unique_id "al9U_oiENNLP6XjiHQtv5AAAAew"]
[Tue Jul 21 08:16:14.299159 2026] [security2:error] [pid 411857:tid 411991] [client 20.151.10.161:20295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/file.php"] [unique_id "al9U_i7ynBpLeKYztQOvfgAAAAI"]
[Tue Jul 21 08:16:14.311547 2026] [security2:error] [pid 411857:tid 412018] [client 20.151.10.161:36530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/av.php"] [unique_id "al9U_i7ynBpLeKYztQOvgAAAAB0"]
[Tue Jul 21 08:16:14.529776 2026] [security2:error] [pid 402041:tid 402154] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U_oiENNLP6XjiHQtv7QABr24"]
[Tue Jul 21 08:16:14.529938 2026] [security2:error] [pid 402041:tid 402205] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9U_oiENNLP6XjiHQtv7QABr24"]
[Tue Jul 21 08:16:14.584112 2026] [security2:error] [pid 411857:tid 412033] [client 20.151.10.161:20296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/aa2.php"] [unique_id "al9U_i7ynBpLeKYztQOvhAAAACw"]
[Tue Jul 21 08:16:14.673705 2026] [security2:error] [pid 411857:tid 412034] [client 20.206.105.145:25583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/images.php"] [unique_id "al9U_i7ynBpLeKYztQOvhQAAAC0"]
[Tue Jul 21 08:16:14.728935 2026] [security2:error] [pid 411857:tid 412045] [client 20.151.10.161:36492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/classwithtostring.php"] [unique_id "al9U_i7ynBpLeKYztQOvhwAAADg"]
[Tue Jul 21 08:16:14.838658 2026] [security2:error] [pid 402041:tid 402296] [client 20.220.225.223:24235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/echkm.php"] [unique_id "al9U_oiENNLP6XjiHQtv9QAAAgo"]
[Tue Jul 21 08:16:14.867464 2026] [security2:error] [pid 411857:tid 412040] [client 20.151.10.161:20431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/ccou.php"] [unique_id "al9U_i7ynBpLeKYztQOviAAAADM"]
[Tue Jul 21 08:16:15.063839 2026] [security2:error] [pid 411857:tid 412043] [client 4.194.24.143:1107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/ws.php"] [unique_id "al9U_y7ynBpLeKYztQOviwAAADY"]
[Tue Jul 21 08:16:15.098541 2026] [security2:error] [pid 411857:tid 412052] [client 20.197.192.193:12995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9U_y7ynBpLeKYztQOvjgAAAD8"]
[Tue Jul 21 08:16:15.184924 2026] [security2:error] [pid 402041:tid 402189] [client 20.151.10.161:20369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/dr.php"] [unique_id "al9U_4iENNLP6XjiHQtv_gAAAZ8"]
[Tue Jul 21 08:16:15.191879 2026] [security2:error] [pid 402041:tid 402202] [client 14.97.58.74:33566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9U_4iENNLP6XjiHQtv_wAAAaw"]
[Tue Jul 21 08:16:15.192029 2026] [security2:error] [pid 402041:tid 402202] [client 14.97.58.74:33566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9U_4iENNLP6XjiHQtv_wAAAaw"]
[Tue Jul 21 08:16:15.223070 2026] [security2:error] [pid 411857:tid 412054] [client 20.151.10.161:36567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9U_y7ynBpLeKYztQOvjwAAAEE"]
[Tue Jul 21 08:16:15.254898 2026] [security2:error] [pid 411857:tid 411865] [remote 45.150.79.142:41228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roha.life"] [uri "/wp-login.php"] [unique_id "al9U_i7ynBpLeKYztQOvfQAADwY"]
[Tue Jul 21 08:16:15.423576 2026] [security2:error] [pid 411857:tid 412057] [client 20.151.10.161:13197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/.well-known/about.php"] [unique_id "al9U_y7ynBpLeKYztQOvkQAAAEQ"]
[Tue Jul 21 08:16:15.489722 2026] [security2:error] [pid 402041:tid 402211] [client 20.151.10.161:20307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/file31.php"] [unique_id "al9U_4iENNLP6XjiHQtwBgAAAbU"]
[Tue Jul 21 08:16:15.845046 2026] [security2:error] [pid 411857:tid 412073] [client 20.151.10.161:20470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/file6.php"] [unique_id "al9U_y7ynBpLeKYztQOvlwAAAFQ"]
[Tue Jul 21 08:16:15.972018 2026] [security2:error] [pid 402041:tid 402210] [client 20.151.10.161:36549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-blog.php"] [unique_id "al9U_4iENNLP6XjiHQtwDQAAAbQ"]
[Tue Jul 21 08:16:16.093827 2026] [security2:error] [pid 402041:tid 402239] [client 4.194.24.143:52645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/wso.php"] [unique_id "al9VAIiENNLP6XjiHQtwFAAAAdE"]
[Tue Jul 21 08:16:16.146794 2026] [security2:error] [pid 402041:tid 402242] [client 20.151.10.161:20396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/file15.php"] [unique_id "al9VAIiENNLP6XjiHQtwFQAAAdQ"]
[Tue Jul 21 08:16:16.484845 2026] [security2:error] [pid 411857:tid 412094] [client 20.151.10.161:20397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/jp.php"] [unique_id "al9VAC7ynBpLeKYztQOvnwAAAGk"]
[Tue Jul 21 08:16:16.740919 2026] [security2:error] [pid 411857:tid 412102] [client 74.249.245.134:31386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/bolt.php"] [unique_id "al9VAC7ynBpLeKYztQOvowAAAHE"]
[Tue Jul 21 08:16:16.790418 2026] [security2:error] [pid 411857:tid 412105] [client 20.151.10.161:20288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/f35.php"] [unique_id "al9VAC7ynBpLeKYztQOvpAAAAHQ"]
[Tue Jul 21 08:16:16.799129 2026] [security2:error] [pid 402041:tid 402249] [client 65.21.113.253:51968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VAIiENNLP6XjiHQtwGwAAAds"]
[Tue Jul 21 08:16:16.882729 2026] [security2:error] [pid 402041:tid 402225] [client 20.206.105.145:25577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/adminner.php"] [unique_id "al9VAIiENNLP6XjiHQtwJAAAAcM"]
[Tue Jul 21 08:16:16.886292 2026] [security2:error] [pid 402041:tid 402261] [client 45.45.237.208:36472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "localizavistorias.com"] [uri "/graphql"] [unique_id "al9VAIiENNLP6XjiHQtwJQAAAec"]
[Tue Jul 21 08:16:16.886363 2026] [security2:error] [pid 402041:tid 402261] [client 45.45.237.208:36472] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "localizavistorias.com"] [uri "/graphql"] [unique_id "al9VAIiENNLP6XjiHQtwJQAAAec"]
[Tue Jul 21 08:16:17.005787 2026] [autoindex:error] [pid 411857:tid 411868] [remote 74.7.227.43:57754] AH01276: Cannot serve directory /home2/inlaud99/choppcontrol.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://sergechel.info
[Tue Jul 21 08:16:17.117484 2026] [security2:error] [pid 411857:tid 411993] [client 20.151.10.161:20418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wp-load.php"] [unique_id "al9VAS7ynBpLeKYztQOvqQAAAAQ"]
[Tue Jul 21 08:16:17.133061 2026] [security2:error] [pid 411857:tid 412106] [client 20.197.192.193:13645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/dp.php"] [unique_id "al9VAS7ynBpLeKYztQOvqgAAAHU"]
[Tue Jul 21 08:16:17.164140 2026] [security2:error] [pid 402041:tid 402208] [client 150.129.202.39:12934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VAYiENNLP6XjiHQtwKwAAAbI"]
[Tue Jul 21 08:16:17.164268 2026] [security2:error] [pid 402041:tid 402208] [client 150.129.202.39:12934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VAYiENNLP6XjiHQtwKwAAAbI"]
[Tue Jul 21 08:16:17.208127 2026] [security2:error] [pid 411857:tid 412098] [client 120.56.162.40:50410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VAS7ynBpLeKYztQOvrAAAAG0"]
[Tue Jul 21 08:16:17.208309 2026] [security2:error] [pid 411857:tid 412098] [client 120.56.162.40:50410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VAS7ynBpLeKYztQOvrAAAAG0"]
[Tue Jul 21 08:16:17.215786 2026] [security2:error] [pid 411857:tid 412107] [client 4.194.24.143:13511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/x.php"] [unique_id "al9VAS7ynBpLeKYztQOvrgAAAHY"]
[Tue Jul 21 08:16:17.364876 2026] [security2:error] [pid 411857:tid 411871] [remote 45.150.79.142:50502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9VAS7ynBpLeKYztQOvsgAAEAw"]
[Tue Jul 21 08:16:17.468043 2026] [security2:error] [pid 402041:tid 402216] [client 20.151.10.161:36583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9VAYiENNLP6XjiHQtwOwAAAbo"]
[Tue Jul 21 08:16:17.491128 2026] [security2:error] [pid 402041:tid 402194] [client 20.151.10.161:13248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9VAYiENNLP6XjiHQtwPQAAAaQ"]
[Tue Jul 21 08:16:17.790500 2026] [security2:error] [pid 411857:tid 412025] [client 20.206.105.145:25544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/admin.php"] [unique_id "al9VAS7ynBpLeKYztQOvuAAAACQ"]
[Tue Jul 21 08:16:17.827938 2026] [security2:error] [pid 411857:tid 412029] [client 20.151.10.161:20405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9VAS7ynBpLeKYztQOvuQAAACg"]
[Tue Jul 21 08:16:18.037426 2026] [security2:error] [pid 402041:tid 402227] [client 117.210.135.0:58309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VAoiENNLP6XjiHQtwRQAAAcU"]
[Tue Jul 21 08:16:18.037540 2026] [security2:error] [pid 402041:tid 402227] [client 117.210.135.0:58309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VAoiENNLP6XjiHQtwRQAAAcU"]
[Tue Jul 21 08:16:18.070794 2026] [security2:error] [pid 402041:tid 402278] [client 20.220.225.223:24211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/mac.php"] [unique_id "al9VAoiENNLP6XjiHQtwRgAAAfg"]
[Tue Jul 21 08:16:18.224244 2026] [security2:error] [pid 402041:tid 402110] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VAoiENNLP6XjiHQtwSwABz0I"]
[Tue Jul 21 08:16:18.224439 2026] [security2:error] [pid 402041:tid 402237] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VAoiENNLP6XjiHQtwSwABz0I"]
[Tue Jul 21 08:16:18.237880 2026] [security2:error] [pid 402041:tid 402177] [client 4.194.24.143:13560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/x86.php"] [unique_id "al9VAoiENNLP6XjiHQtwTAAAAZM"]
[Tue Jul 21 08:16:18.301623 2026] [security2:error] [pid 402041:tid 402281] [client 20.151.10.161:20293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wp-links.php"] [unique_id "al9VAoiENNLP6XjiHQtwTwAAAfs"]
[Tue Jul 21 08:16:18.424897 2026] [security2:error] [pid 402041:tid 402298] [client 134.122.94.138:64166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "accjbc.org"] [uri "/"] [unique_id "al9VAoiENNLP6XjiHQtwUAAAAgw"]
[Tue Jul 21 08:16:18.482808 2026] [security2:error] [pid 411857:tid 412047] [client 20.151.10.161:36596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/adminfuns.php"] [unique_id "al9VAi7ynBpLeKYztQOvvwAAADo"]
[Tue Jul 21 08:16:18.487573 2026] [security2:error] [pid 402041:tid 402054] [remote 173.252.95.58:64962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9VAYiENNLP6XjiHQtwPAABkgo"]
[Tue Jul 21 08:16:18.639053 2026] [security2:error] [pid 402041:tid 402178] [client 20.206.105.145:25487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/k.php"] [unique_id "al9VAoiENNLP6XjiHQtwWQAAAZQ"]
[Tue Jul 21 08:16:18.670394 2026] [security2:error] [pid 402041:tid 402213] [client 65.21.113.253:51968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VAoiENNLP6XjiHQtwSgAAAbc"]
[Tue Jul 21 08:16:18.706728 2026] [security2:error] [pid 411857:tid 411872] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VAi7ynBpLeKYztQOvxAAAQw0"]
[Tue Jul 21 08:16:18.706896 2026] [security2:error] [pid 411857:tid 412056] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VAi7ynBpLeKYztQOvxAAAQw0"]
[Tue Jul 21 08:16:18.850937 2026] [security2:error] [pid 411857:tid 411873] [remote 103.112.62.59:47448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.62.112.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "digitaclick.com"] [uri "/wp-login.php"] [unique_id "al9VAi7ynBpLeKYztQOvxQAAHg4"]
[Tue Jul 21 08:16:18.974240 2026] [security2:error] [pid 402041:tid 402226] [client 20.151.10.161:20338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/solo1.php"] [unique_id "al9VAoiENNLP6XjiHQtwXQAAAcQ"]
[Tue Jul 21 08:16:19.274903 2026] [security2:error] [pid 402041:tid 402292] [client 4.194.24.143:21366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/xa.php"] [unique_id "al9VA4iENNLP6XjiHQtwZAAAAgY"]
[Tue Jul 21 08:16:19.470640 2026] [security2:error] [pid 402041:tid 402233] [client 74.249.245.134:31394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/x.php"] [unique_id "al9VA4iENNLP6XjiHQtwZgAAAcs"]
[Tue Jul 21 08:16:19.525585 2026] [proxy:error] [pid 402041:tid 402239] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:19.525663 2026] [proxy_http:error] [pid 402041:tid 402239] [client 20.151.10.161:13263] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:19.526146 2026] [proxy:error] [pid 402041:tid 402239] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:19.526185 2026] [proxy_http:error] [pid 402041:tid 402239] [client 20.151.10.161:13263] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:19.683850 2026] [proxy:error] [pid 411857:tid 412069] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:19.683919 2026] [proxy_http:error] [pid 411857:tid 412069] [client 198.235.24.79:63434] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:19.684749 2026] [proxy:error] [pid 411857:tid 412069] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:19.684785 2026] [proxy_http:error] [pid 411857:tid 412069] [client 198.235.24.79:63434] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:19.740661 2026] [security2:error] [pid 411857:tid 412077] [client 20.151.10.161:20391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/sixxis.php"] [unique_id "al9VAy7ynBpLeKYztQOv0QAAAFg"]
[Tue Jul 21 08:16:20.155391 2026] [security2:error] [pid 411857:tid 411989] [client 223.181.60.88:22325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VAS7ynBpLeKYztQOvvAAAAAA"]
[Tue Jul 21 08:16:20.155541 2026] [security2:error] [pid 411857:tid 411989] [client 223.181.60.88:22325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VAS7ynBpLeKYztQOvvAAAAAA"]
[Tue Jul 21 08:16:20.179688 2026] [security2:error] [pid 402041:tid 402204] [client 20.151.10.161:20410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/2P.update.php"] [unique_id "al9VBIiENNLP6XjiHQtwcwAAAa4"]
[Tue Jul 21 08:16:20.263954 2026] [security2:error] [pid 411857:tid 412046] [client 198.54.129.60:36984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9VBC7ynBpLeKYztQOv0gAAADk"]
[Tue Jul 21 08:16:20.264067 2026] [security2:error] [pid 411857:tid 412046] [client 198.54.129.60:36984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9VBC7ynBpLeKYztQOv0gAAADk"]
[Tue Jul 21 08:16:20.313958 2026] [security2:error] [pid 402041:tid 402288] [client 4.194.24.143:13534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/xfun.php"] [unique_id "al9VBIiENNLP6XjiHQtweAAAAgI"]
[Tue Jul 21 08:16:20.355490 2026] [security2:error] [pid 402041:tid 402261] [client 20.151.10.161:36575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/goods.php"] [unique_id "al9VBIiENNLP6XjiHQtwegAAAec"]
[Tue Jul 21 08:16:20.654480 2026] [security2:error] [pid 411857:tid 412086] [client 20.206.105.145:25563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/x.php"] [unique_id "al9VBC7ynBpLeKYztQOv1AAAAGE"]
[Tue Jul 21 08:16:20.733366 2026] [security2:error] [pid 402041:tid 402192] [client 20.151.10.161:20335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/a.php"] [unique_id "al9VBIiENNLP6XjiHQtwgAAAAaI"]
[Tue Jul 21 08:16:20.748745 2026] [security2:error] [pid 411857:tid 412091] [client 20.220.225.223:24226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/samll.php"] [unique_id "al9VBC7ynBpLeKYztQOv1QAAAGY"]
[Tue Jul 21 08:16:21.183565 2026] [security2:error] [pid 402041:tid 402208] [client 134.122.94.138:65011] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "accjbc.org"] [uri "/.env"] [unique_id "al9VBYiENNLP6XjiHQtwhgAAAbI"]
[Tue Jul 21 08:16:21.196063 2026] [proxy:error] [pid 411857:tid 412112] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:21.196096 2026] [proxy_http:error] [pid 411857:tid 412112] [client 20.151.10.161:13264] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:21.196524 2026] [proxy:error] [pid 411857:tid 412112] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:21.196542 2026] [proxy_http:error] [pid 411857:tid 412112] [client 20.151.10.161:13264] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:21.307523 2026] [security2:error] [pid 411857:tid 412076] [client 38.100.221.102:17838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VBS7ynBpLeKYztQOv3gAAAFc"]
[Tue Jul 21 08:16:21.307627 2026] [security2:error] [pid 411857:tid 412076] [client 38.100.221.102:17838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VBS7ynBpLeKYztQOv3gAAAFc"]
[Tue Jul 21 08:16:21.343244 2026] [security2:error] [pid 411857:tid 412099] [client 4.194.24.143:13713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/xleet.php"] [unique_id "al9VBS7ynBpLeKYztQOv3wAAAG4"]
[Tue Jul 21 08:16:21.424308 2026] [security2:error] [pid 402041:tid 402162] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VBYiENNLP6XjiHQtwigABv3Y"]
[Tue Jul 21 08:16:21.424455 2026] [security2:error] [pid 402041:tid 402221] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VBYiENNLP6XjiHQtwigABv3Y"]
[Tue Jul 21 08:16:21.504429 2026] [security2:error] [pid 402041:tid 402284] [client 20.151.10.161:20363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/k.php"] [unique_id "al9VBYiENNLP6XjiHQtwjAAAAf4"]
[Tue Jul 21 08:16:21.725366 2026] [security2:error] [pid 411857:tid 411998] [client 20.151.10.161:36564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/ms-edit.php"] [unique_id "al9VBS7ynBpLeKYztQOv6AAAAAk"]
[Tue Jul 21 08:16:21.871979 2026] [security2:error] [pid 411857:tid 412104] [client 103.78.200.11:59453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VBS7ynBpLeKYztQOv6QAAAHM"]
[Tue Jul 21 08:16:21.872134 2026] [security2:error] [pid 411857:tid 412104] [client 103.78.200.11:59453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VBS7ynBpLeKYztQOv6QAAAHM"]
[Tue Jul 21 08:16:21.903719 2026] [security2:error] [pid 402041:tid 402287] [client 45.45.237.208:36540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/xmlrpc.php"] [unique_id "al9VBIiENNLP6XjiHQtwgQAAAgE"]
[Tue Jul 21 08:16:21.908951 2026] [security2:error] [pid 411857:tid 411878] [remote 57.141.18.79:44626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/rk-centro-automotivo/"] [unique_id "al9VBS7ynBpLeKYztQOv6gAAHBM"]
[Tue Jul 21 08:16:22.053250 2026] [security2:error] [pid 411857:tid 412002] [client 20.151.10.161:20352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/w.php"] [unique_id "al9VBi7ynBpLeKYztQOv6wAAAA0"]
[Tue Jul 21 08:16:22.273122 2026] [security2:error] [pid 411857:tid 411880] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VBi7ynBpLeKYztQOv8gAAIRU"]
[Tue Jul 21 08:16:22.273290 2026] [security2:error] [pid 411857:tid 412022] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VBi7ynBpLeKYztQOv8gAAIRU"]
[Tue Jul 21 08:16:22.365174 2026] [security2:error] [pid 402041:tid 402272] [client 20.151.10.161:20465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/insc.php"] [unique_id "al9VBoiENNLP6XjiHQtwoQAAAfI"]
[Tue Jul 21 08:16:22.400992 2026] [security2:error] [pid 411857:tid 412025] [client 4.194.24.143:13563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VBi7ynBpLeKYztQOv8wAAACQ"]
[Tue Jul 21 08:16:22.429270 2026] [security2:error] [pid 411857:tid 411991] [client 154.208.47.43:54243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VBi7ynBpLeKYztQOv9AAAAAI"]
[Tue Jul 21 08:16:22.429456 2026] [security2:error] [pid 411857:tid 411991] [client 154.208.47.43:54243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VBi7ynBpLeKYztQOv9AAAAAI"]
[Tue Jul 21 08:16:22.510962 2026] [security2:error] [pid 411857:tid 412049] [client 20.151.10.161:13270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/pucci.php"] [unique_id "al9VBi7ynBpLeKYztQOv9QAAADw"]
[Tue Jul 21 08:16:22.574304 2026] [security2:error] [pid 411857:tid 411881] [remote 85.208.96.200:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hauptmann.com.br"] [uri "/list-layout-full-width/"] [unique_id "al9VBi7ynBpLeKYztQOv9gAANhY"]
[Tue Jul 21 08:16:22.574496 2026] [security2:error] [pid 411857:tid 412043] [client 85.208.96.200:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hauptmann.com.br"] [uri "/list-layout-full-width/"] [unique_id "al9VBi7ynBpLeKYztQOv9gAANhY"]
[Tue Jul 21 08:16:22.619604 2026] [security2:error] [pid 402041:tid 402235] [client 65.21.113.253:51968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VBoiENNLP6XjiHQtwmQAAAc0"]
[Tue Jul 21 08:16:22.689460 2026] [security2:error] [pid 411857:tid 412055] [client 20.197.192.193:13640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/old.php"] [unique_id "al9VBi7ynBpLeKYztQOv9wAAAEI"]
[Tue Jul 21 08:16:22.785106 2026] [security2:error] [pid 411857:tid 412068] [client 20.151.10.161:20442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9VBi7ynBpLeKYztQOv_QAAAE8"]
[Tue Jul 21 08:16:23.136675 2026] [security2:error] [pid 411857:tid 412078] [client 20.151.10.161:20301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/u.php"] [unique_id "al9VBy7ynBpLeKYztQOv_gAAAFk"]
[Tue Jul 21 08:16:23.164382 2026] [security2:error] [pid 411857:tid 411989] [client 20.206.105.145:25595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wss.php"] [unique_id "al9VBy7ynBpLeKYztQOv_wAAAAA"]
[Tue Jul 21 08:16:23.319797 2026] [security2:error] [pid 411857:tid 412067] [client 185.213.175.37:33856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.rinettoar.com.br"] [uri "/.env"] [unique_id "al9VBy7ynBpLeKYztQOwAQAAAE4"]
[Tue Jul 21 08:16:23.319920 2026] [security2:error] [pid 411857:tid 412067] [client 185.213.175.37:33856] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.rinettoar.com.br"] [uri "/.env"] [unique_id "al9VBy7ynBpLeKYztQOwAQAAAE4"]
[Tue Jul 21 08:16:23.340189 2026] [proxy:error] [pid 411857:tid 412088] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:23.340270 2026] [proxy_http:error] [pid 411857:tid 412088] [client 20.151.10.161:13293] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:23.340921 2026] [proxy:error] [pid 411857:tid 412088] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:23.340957 2026] [proxy_http:error] [pid 411857:tid 412088] [client 20.151.10.161:13293] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:23.424951 2026] [security2:error] [pid 402041:tid 402219] [client 20.151.10.161:36532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/222.php"] [unique_id "al9VB4iENNLP6XjiHQtwsAAAAb0"]
[Tue Jul 21 08:16:23.466436 2026] [security2:error] [pid 411857:tid 412070] [client 102.206.115.33:60191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VBy7ynBpLeKYztQOwBAAAAFE"]
[Tue Jul 21 08:16:23.466705 2026] [security2:error] [pid 411857:tid 412070] [client 102.206.115.33:60191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VBy7ynBpLeKYztQOwBAAAAFE"]
[Tue Jul 21 08:16:23.473346 2026] [security2:error] [pid 402041:tid 402182] [client 20.151.10.161:20435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/sss.php"] [unique_id "al9VB4iENNLP6XjiHQtwsgAAAZg"]
[Tue Jul 21 08:16:23.479231 2026] [security2:error] [pid 402041:tid 402264] [client 4.194.24.143:21344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/xx.php"] [unique_id "al9VB4iENNLP6XjiHQtwswAAAeo"]
[Tue Jul 21 08:16:23.556544 2026] [security2:error] [pid 402041:tid 402234] [client 87.116.180.198:13854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VB4iENNLP6XjiHQtwtgAAAcw"]
[Tue Jul 21 08:16:23.556678 2026] [security2:error] [pid 402041:tid 402234] [client 87.116.180.198:13854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VB4iENNLP6XjiHQtwtgAAAcw"]
[Tue Jul 21 08:16:23.703155 2026] [security2:error] [pid 411857:tid 412075] [client 103.151.46.103:64641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VBy7ynBpLeKYztQOwCgAAAFY"]
[Tue Jul 21 08:16:23.703327 2026] [security2:error] [pid 411857:tid 412075] [client 103.151.46.103:64641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VBy7ynBpLeKYztQOwCgAAAFY"]
[Tue Jul 21 08:16:23.796029 2026] [security2:error] [pid 402041:tid 402222] [client 20.197.192.193:61059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/csa.php"] [unique_id "al9VB4iENNLP6XjiHQtwvAAAAcA"]
[Tue Jul 21 08:16:23.863887 2026] [security2:error] [pid 402041:tid 402244] [client 20.151.10.161:20390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/sss.php"] [unique_id "al9VB4iENNLP6XjiHQtwvwAAAdY"]
[Tue Jul 21 08:16:23.961743 2026] [security2:error] [pid 402041:tid 402246] [client 20.197.192.193:13007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/ms-new.php"] [unique_id "al9VB4iENNLP6XjiHQtwxAAAAdg"]
[Tue Jul 21 08:16:24.063678 2026] [security2:error] [pid 411857:tid 411997] [client 74.249.245.134:15362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/jga.php"] [unique_id "al9VCC7ynBpLeKYztQOwEAAAAAg"]
[Tue Jul 21 08:16:24.231979 2026] [security2:error] [pid 411857:tid 412098] [client 20.151.10.161:20395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/c.php"] [unique_id "al9VCC7ynBpLeKYztQOwEQAAAG0"]
[Tue Jul 21 08:16:24.286329 2026] [security2:error] [pid 402041:tid 402211] [client 187.125.243.197:51134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VCIiENNLP6XjiHQtwygAAAbU"]
[Tue Jul 21 08:16:24.286639 2026] [security2:error] [pid 402041:tid 402211] [client 187.125.243.197:51134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VCIiENNLP6XjiHQtwygAAAbU"]
[Tue Jul 21 08:16:24.302107 2026] [security2:error] [pid 411857:tid 412001] [client 20.197.192.193:13681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/track.php"] [unique_id "al9VCC7ynBpLeKYztQOwEgAAAAw"]
[Tue Jul 21 08:16:24.334439 2026] [proxy:error] [pid 411857:tid 412107] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:24.334498 2026] [proxy_http:error] [pid 411857:tid 412107] [client 20.151.10.161:13281] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:24.334965 2026] [proxy:error] [pid 411857:tid 412107] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:24.334989 2026] [proxy_http:error] [pid 411857:tid 412107] [client 20.151.10.161:13281] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:24.347685 2026] [security2:error] [pid 402041:tid 402092] [remote 68.178.160.25:59700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9VCIiENNLP6XjiHQtwzAAB-TA"]
[Tue Jul 21 08:16:24.537335 2026] [security2:error] [pid 411857:tid 412007] [client 4.194.24.143:6013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/xyn.php"] [unique_id "al9VCC7ynBpLeKYztQOwGAAAABI"]
[Tue Jul 21 08:16:24.600674 2026] [security2:error] [pid 411857:tid 412003] [client 45.45.237.208:58008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "localizavistorias.com"] [uri "/wp-json/wp/v2/pages/12"] [unique_id "al9VCC7ynBpLeKYztQOwGQAAAA4"]
[Tue Jul 21 08:16:24.600787 2026] [security2:error] [pid 411857:tid 412003] [client 45.45.237.208:58008] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "localizavistorias.com"] [uri "/wp-json/wp/v2/pages/12"] [unique_id "al9VCC7ynBpLeKYztQOwGQAAAA4"]
[Tue Jul 21 08:16:24.618671 2026] [security2:error] [pid 411857:tid 412015] [client 20.220.225.223:24224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/abcd.php"] [unique_id "al9VCC7ynBpLeKYztQOwGgAAABo"]
[Tue Jul 21 08:16:24.621551 2026] [security2:error] [pid 411857:tid 412102] [client 20.151.10.161:20400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/aa.php"] [unique_id "al9VCC7ynBpLeKYztQOwGwAAAHE"]
[Tue Jul 21 08:16:24.643677 2026] [security2:error] [pid 402041:tid 402283] [client 65.21.113.253:51968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VCIiENNLP6XjiHQtwyQAAAf0"]
[Tue Jul 21 08:16:24.687342 2026] [security2:error] [pid 402041:tid 402298] [client 14.245.224.124:60665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VCIiENNLP6XjiHQtw1AAAAgw"]
[Tue Jul 21 08:16:24.687475 2026] [security2:error] [pid 402041:tid 402298] [client 14.245.224.124:60665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VCIiENNLP6XjiHQtw1AAAAgw"]
[Tue Jul 21 08:16:24.779300 2026] [security2:error] [pid 411857:tid 412030] [client 20.220.225.223:58929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/byp8.php"] [unique_id "al9VCC7ynBpLeKYztQOwHQAAACk"]
[Tue Jul 21 08:16:24.966233 2026] [security2:error] [pid 411857:tid 411886] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VCC7ynBpLeKYztQOwIQAAJxs"]
[Tue Jul 21 08:16:24.966406 2026] [security2:error] [pid 411857:tid 412028] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VCC7ynBpLeKYztQOwIQAAJxs"]
[Tue Jul 21 08:16:24.983893 2026] [security2:error] [pid 411857:tid 412023] [client 20.151.10.161:20428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/100.php"] [unique_id "al9VCC7ynBpLeKYztQOwIgAAACI"]
[Tue Jul 21 08:16:25.058099 2026] [security2:error] [pid 402041:tid 402259] [client 20.151.10.161:13266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wp-temp.php"] [unique_id "al9VCYiENNLP6XjiHQtw2gAAAeU"]
[Tue Jul 21 08:16:25.074327 2026] [security2:error] [pid 411857:tid 411888] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VCS7ynBpLeKYztQOwJAAAMh0"]
[Tue Jul 21 08:16:25.074479 2026] [security2:error] [pid 411857:tid 412039] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VCS7ynBpLeKYztQOwJAAAMh0"]
[Tue Jul 21 08:16:25.180681 2026] [security2:error] [pid 402041:tid 402188] [client 20.197.192.193:13635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/2352356666.php"] [unique_id "al9VCYiENNLP6XjiHQtw3AAAAZ4"]
[Tue Jul 21 08:16:25.236103 2026] [security2:error] [pid 402041:tid 402272] [client 20.151.10.161:36539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9VCYiENNLP6XjiHQtw3gAAAfI"]
[Tue Jul 21 08:16:25.292368 2026] [security2:error] [pid 411857:tid 412049] [client 20.151.10.161:20326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/footer.php"] [unique_id "al9VCS7ynBpLeKYztQOwJgAAADw"]
[Tue Jul 21 08:16:25.568046 2026] [security2:error] [pid 411857:tid 412026] [client 4.194.24.143:13475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/y.php"] [unique_id "al9VCS7ynBpLeKYztQOwLAAAACU"]
[Tue Jul 21 08:16:25.780150 2026] [security2:error] [pid 411857:tid 412068] [client 20.151.10.161:20309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/users.php"] [unique_id "al9VCS7ynBpLeKYztQOwLgAAAE8"]
[Tue Jul 21 08:16:25.829895 2026] [security2:error] [pid 411857:tid 412066] [client 74.7.244.13:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "glezianefreitassoare1745944505873.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9VCS7ynBpLeKYztQOwLwAATSA"]
[Tue Jul 21 08:16:25.864229 2026] [security2:error] [pid 411857:tid 412038] [client 14.97.58.74:49466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VCS7ynBpLeKYztQOwMAAAADE"]
[Tue Jul 21 08:16:25.864360 2026] [security2:error] [pid 411857:tid 412038] [client 14.97.58.74:49466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VCS7ynBpLeKYztQOwMAAAADE"]
[Tue Jul 21 08:16:26.077683 2026] [security2:error] [pid 402041:tid 402215] [client 103.106.20.201:58207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VCIiENNLP6XjiHQtwxwAAAbk"]
[Tue Jul 21 08:16:26.077801 2026] [security2:error] [pid 402041:tid 402215] [client 103.106.20.201:58207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VCIiENNLP6XjiHQtwxwAAAbk"]
[Tue Jul 21 08:16:26.118008 2026] [security2:error] [pid 411857:tid 412090] [client 20.151.10.161:20316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/177.php"] [unique_id "al9VCi7ynBpLeKYztQOwPgAAAGU"]
[Tue Jul 21 08:16:26.123522 2026] [security2:error] [pid 411857:tid 412044] [client 20.197.192.193:3377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/la.php"] [unique_id "al9VCi7ynBpLeKYztQOwPwAAADc"]
[Tue Jul 21 08:16:26.214644 2026] [security2:error] [pid 411857:tid 412036] [client 20.151.10.161:36512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9VCi7ynBpLeKYztQOwQAAAAC8"]
[Tue Jul 21 08:16:26.274475 2026] [security2:error] [pid 411857:tid 412018] [client 115.134.11.136:56263] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VCS7ynBpLeKYztQOwNwAAAB0"]
[Tue Jul 21 08:16:26.274640 2026] [security2:error] [pid 411857:tid 412018] [client 115.134.11.136:56263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VCS7ynBpLeKYztQOwNwAAAB0"]
[Tue Jul 21 08:16:26.398832 2026] [proxy:error] [pid 411857:tid 412084] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:26.398911 2026] [proxy_http:error] [pid 411857:tid 412084] [client 20.151.10.161:13311] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:26.399522 2026] [proxy:error] [pid 411857:tid 412084] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:26.399549 2026] [proxy_http:error] [pid 411857:tid 412084] [client 20.151.10.161:13311] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:26.488386 2026] [security2:error] [pid 411857:tid 412113] [client 20.151.10.161:20353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/config.php"] [unique_id "al9VCi7ynBpLeKYztQOwRAAAAHw"]
[Tue Jul 21 08:16:26.641847 2026] [security2:error] [pid 411857:tid 412059] [client 4.194.24.143:13489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/z.php"] [unique_id "al9VCi7ynBpLeKYztQOwRQAAAEY"]
[Tue Jul 21 08:16:26.694826 2026] [security2:error] [pid 411857:tid 411997] [client 20.197.192.193:48745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9VCi7ynBpLeKYztQOwRwAAAAg"]
[Tue Jul 21 08:16:26.811337 2026] [security2:error] [pid 402041:tid 402222] [client 20.151.10.161:20318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/gettest.php"] [unique_id "al9VCoiENNLP6XjiHQtw9AAAAcA"]
[Tue Jul 21 08:16:27.064451 2026] [security2:error] [pid 402041:tid 402280] [client 65.21.113.253:51968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VCoiENNLP6XjiHQtw8QAAAfo"]
[Tue Jul 21 08:16:27.158041 2026] [security2:error] [pid 411857:tid 411992] [client 20.220.225.223:24302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/xyn.php"] [unique_id "al9VCy7ynBpLeKYztQOwSgAAAAM"]
[Tue Jul 21 08:16:27.243432 2026] [security2:error] [pid 411857:tid 412003] [client 20.206.105.145:25472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/ty.php"] [unique_id "al9VCy7ynBpLeKYztQOwSwAAAA4"]
[Tue Jul 21 08:16:27.243681 2026] [security2:error] [pid 402041:tid 402249] [client 20.151.10.161:20328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/min.php"] [unique_id "al9VC4iENNLP6XjiHQtw_AAAAds"]
[Tue Jul 21 08:16:27.253685 2026] [security2:error] [pid 402041:tid 402244] [client 74.249.245.134:15376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/k.php"] [unique_id "al9VC4iENNLP6XjiHQtw_QAAAdY"]
[Tue Jul 21 08:16:27.686522 2026] [security2:error] [pid 411857:tid 412102] [client 4.194.24.143:13498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ecochamabrasil.com"] [uri "/zk81cwqsdefault.php"] [unique_id "al9VCy7ynBpLeKYztQOwVAAAAHE"]
[Tue Jul 21 08:16:27.725360 2026] [security2:error] [pid 402041:tid 402252] [client 74.249.245.134:15114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/vx.php"] [unique_id "al9VC4iENNLP6XjiHQtxDQAAAd4"]
[Tue Jul 21 08:16:27.747520 2026] [security2:error] [pid 402041:tid 402297] [client 20.151.10.161:20477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/edorxrr.php"] [unique_id "al9VC4iENNLP6XjiHQtxDgAAAgs"]
[Tue Jul 21 08:16:27.857529 2026] [security2:error] [pid 402041:tid 402248] [client 150.129.202.39:12590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VC4iENNLP6XjiHQtxEAAAAdo"]
[Tue Jul 21 08:16:27.857667 2026] [security2:error] [pid 402041:tid 402248] [client 150.129.202.39:12590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VC4iENNLP6XjiHQtxEAAAAdo"]
[Tue Jul 21 08:16:27.865947 2026] [security2:error] [pid 411857:tid 412007] [client 120.56.162.40:50924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VCy7ynBpLeKYztQOwVgAAABI"]
[Tue Jul 21 08:16:27.866083 2026] [security2:error] [pid 411857:tid 412007] [client 120.56.162.40:50924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VCy7ynBpLeKYztQOwVgAAABI"]
[Tue Jul 21 08:16:27.896793 2026] [security2:error] [pid 411857:tid 412104] [client 20.151.10.161:13310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/xmu.php"] [unique_id "al9VCy7ynBpLeKYztQOwVwAAAHM"]
[Tue Jul 21 08:16:27.931645 2026] [security2:error] [pid 402041:tid 402206] [client 20.151.10.161:51098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp.php"] [unique_id "al9VC4iENNLP6XjiHQtxEwAAAbA"]
[Tue Jul 21 08:16:28.312635 2026] [security2:error] [pid 402041:tid 402190] [client 62.102.148.158:48680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9VDIiENNLP6XjiHQtxGQAAAaA"]
[Tue Jul 21 08:16:28.312745 2026] [security2:error] [pid 402041:tid 402190] [client 62.102.148.158:48680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9VDIiENNLP6XjiHQtxGQAAAaA"]
[Tue Jul 21 08:16:28.423344 2026] [security2:error] [pid 411857:tid 412037] [client 223.181.60.88:32717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VDC7ynBpLeKYztQOwXQAAADA"]
[Tue Jul 21 08:16:28.423565 2026] [security2:error] [pid 411857:tid 412037] [client 223.181.60.88:32717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VDC7ynBpLeKYztQOwXQAAADA"]
[Tue Jul 21 08:16:28.435792 2026] [security2:error] [pid 402041:tid 402216] [client 20.151.10.161:20406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/hur.php"] [unique_id "al9VDIiENNLP6XjiHQtxGgAAAbo"]
[Tue Jul 21 08:16:28.512524 2026] [security2:error] [pid 411857:tid 411896] [remote 45.150.79.142:33442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/wp-login.php"] [unique_id "al9VDC7ynBpLeKYztQOwYAAAayU"]
[Tue Jul 21 08:16:28.562292 2026] [security2:error] [pid 402041:tid 402178] [client 117.210.135.0:58949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VDIiENNLP6XjiHQtxHgAAAZQ"]
[Tue Jul 21 08:16:28.562387 2026] [security2:error] [pid 402041:tid 402178] [client 117.210.135.0:58949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VDIiENNLP6XjiHQtxHgAAAZQ"]
[Tue Jul 21 08:16:28.806121 2026] [security2:error] [pid 402041:tid 402127] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VDIiENNLP6XjiHQtxIwABzVM"]
[Tue Jul 21 08:16:28.806785 2026] [security2:error] [pid 402041:tid 402235] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VDIiENNLP6XjiHQtxIwABzVM"]
[Tue Jul 21 08:16:28.824579 2026] [security2:error] [pid 411857:tid 412086] [client 20.151.10.161:20298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/zoro.php"] [unique_id "al9VDC7ynBpLeKYztQOwagAAAGE"]
[Tue Jul 21 08:16:28.883796 2026] [security2:error] [pid 402041:tid 402199] [client 51.68.247.207:50516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/robots.txt"] [unique_id "al9VDIiENNLP6XjiHQtxKQAAAak"]
[Tue Jul 21 08:16:28.883931 2026] [security2:error] [pid 402041:tid 402199] [client 51.68.247.207:50516] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/robots.txt"] [unique_id "al9VDIiENNLP6XjiHQtxKQAAAak"]
[Tue Jul 21 08:16:29.003133 2026] [security2:error] [pid 411857:tid 412105] [client 20.151.10.161:36600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/abcd.php"] [unique_id "al9VDS7ynBpLeKYztQOwbgAAAHQ"]
[Tue Jul 21 08:16:29.163392 2026] [security2:error] [pid 411857:tid 412116] [client 20.151.10.161:20384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/coffexium.php"] [unique_id "al9VDS7ynBpLeKYztQOwcwAAAH8"]
[Tue Jul 21 08:16:29.178999 2026] [security2:error] [pid 411857:tid 411898] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VDS7ynBpLeKYztQOwdAAAZSc"]
[Tue Jul 21 08:16:29.179125 2026] [security2:error] [pid 411857:tid 412090] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VDS7ynBpLeKYztQOwdAAAZSc"]
[Tue Jul 21 08:16:29.181370 2026] [security2:error] [pid 411857:tid 412115] [client 74.249.245.134:15373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/ws77.php"] [unique_id "al9VDS7ynBpLeKYztQOwdQAAAH4"]
[Tue Jul 21 08:16:29.322444 2026] [security2:error] [pid 411857:tid 412043] [client 61.1.167.83:56131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VDS7ynBpLeKYztQOwdwAAADY"]
[Tue Jul 21 08:16:29.322588 2026] [security2:error] [pid 411857:tid 412043] [client 61.1.167.83:56131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VDS7ynBpLeKYztQOwdwAAADY"]
[Tue Jul 21 08:16:29.502460 2026] [security2:error] [pid 402041:tid 402255] [client 65.21.113.253:51968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VDYiENNLP6XjiHQtxKwAAAeE"]
[Tue Jul 21 08:16:29.526581 2026] [security2:error] [pid 402041:tid 402234] [client 20.151.10.161:13289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9VDYiENNLP6XjiHQtxMQAAAcw"]
[Tue Jul 21 08:16:29.616666 2026] [security2:error] [pid 411857:tid 412012] [client 20.151.10.161:20321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/app.php"] [unique_id "al9VDS7ynBpLeKYztQOwegAAABc"]
[Tue Jul 21 08:16:29.735110 2026] [security2:error] [pid 402041:tid 402202] [client 20.206.105.145:25490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/155.php"] [unique_id "al9VDYiENNLP6XjiHQtxNQAAAaw"]
[Tue Jul 21 08:16:29.751234 2026] [security2:error] [pid 402041:tid 402271] [client 86.106.84.166:48754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9VDYiENNLP6XjiHQtxNgAAAfE"]
[Tue Jul 21 08:16:29.751323 2026] [security2:error] [pid 402041:tid 402271] [client 86.106.84.166:48754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9VDYiENNLP6XjiHQtxNgAAAfE"]
[Tue Jul 21 08:16:30.126439 2026] [security2:error] [pid 402041:tid 402250] [client 20.197.192.193:13679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/pn.php"] [unique_id "al9VDoiENNLP6XjiHQtxPAAAAdw"]
[Tue Jul 21 08:16:30.269807 2026] [security2:error] [pid 402041:tid 402268] [client 20.151.10.161:20310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/core.php"] [unique_id "al9VDoiENNLP6XjiHQtxQAAAAe4"]
[Tue Jul 21 08:16:30.440258 2026] [security2:error] [pid 411857:tid 412107] [client 152.42.185.27:65178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.185.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bellascleaningsolutionsllc.com"] [uri "/xmlrpc.php"] [unique_id "al9VDi7ynBpLeKYztQOwfgAAAHY"], referer: https://beautycar-detail.ch//wp-login.php
[Tue Jul 21 08:16:30.475431 2026] [security2:error] [pid 402041:tid 402244] [client 142.44.228.165:57502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/"] [unique_id "al9VDoiENNLP6XjiHQtxQgAAAdY"]
[Tue Jul 21 08:16:30.475580 2026] [security2:error] [pid 402041:tid 402244] [client 142.44.228.165:57502] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/"] [unique_id "al9VDoiENNLP6XjiHQtxQgAAAdY"]
[Tue Jul 21 08:16:30.494438 2026] [security2:error] [pid 411857:tid 412032] [client 162.219.176.3:55626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9VDi7ynBpLeKYztQOwfwAAACs"]
[Tue Jul 21 08:16:30.494533 2026] [security2:error] [pid 411857:tid 412032] [client 162.219.176.3:55626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9VDi7ynBpLeKYztQOwfwAAACs"]
[Tue Jul 21 08:16:30.982654 2026] [security2:error] [pid 402041:tid 402246] [client 20.151.10.161:20388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/main.php"] [unique_id "al9VDoiENNLP6XjiHQtxSAAAAdg"]
[Tue Jul 21 08:16:31.133624 2026] [security2:error] [pid 411857:tid 412045] [client 74.249.245.134:15128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/2.php"] [unique_id "al9VDy7ynBpLeKYztQOwhAAAADg"]
[Tue Jul 21 08:16:31.252303 2026] [security2:error] [pid 402041:tid 402248] [client 20.151.10.161:36579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/a1.php"] [unique_id "al9VD4iENNLP6XjiHQtxUAAAAdo"]
[Tue Jul 21 08:16:31.491247 2026] [security2:error] [pid 411857:tid 412103] [client 20.151.10.161:13211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/puc.php"] [unique_id "al9VDy7ynBpLeKYztQOwhQAAAHI"]
[Tue Jul 21 08:16:31.493447 2026] [security2:error] [pid 402041:tid 402191] [client 65.21.113.253:51968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VD4iENNLP6XjiHQtxTAAAAaE"]
[Tue Jul 21 08:16:31.568265 2026] [security2:error] [pid 411857:tid 412038] [client 20.197.192.193:13632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9VDy7ynBpLeKYztQOwiQAAADE"]
[Tue Jul 21 08:16:31.829210 2026] [security2:error] [pid 411857:tid 412065] [client 20.151.10.161:20421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/init.php"] [unique_id "al9VDy7ynBpLeKYztQOwjQAAAEw"]
[Tue Jul 21 08:16:32.011163 2026] [security2:error] [pid 402041:tid 402241] [client 20.220.225.223:58908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/user.php"] [unique_id "al9VEIiENNLP6XjiHQtxWQAAAdM"]
[Tue Jul 21 08:16:32.054841 2026] [security2:error] [pid 402041:tid 402048] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VEIiENNLP6XjiHQtxWgABugQ"]
[Tue Jul 21 08:16:32.054963 2026] [security2:error] [pid 402041:tid 402216] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VEIiENNLP6XjiHQtxWgABugQ"]
[Tue Jul 21 08:16:32.121855 2026] [security2:error] [pid 402041:tid 402283] [client 38.100.221.102:18383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VEIiENNLP6XjiHQtxXQAAAf0"]
[Tue Jul 21 08:16:32.121960 2026] [security2:error] [pid 402041:tid 402283] [client 38.100.221.102:18383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VEIiENNLP6XjiHQtxXQAAAf0"]
[Tue Jul 21 08:16:32.136916 2026] [security2:error] [pid 411857:tid 412088] [client 20.197.192.193:3368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/inso.php"] [unique_id "al9VEC7ynBpLeKYztQOwkgAAAGM"]
[Tue Jul 21 08:16:32.460849 2026] [security2:error] [pid 411857:tid 412112] [client 20.151.10.161:20260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/prekel.php"] [unique_id "al9VEC7ynBpLeKYztQOwlQAAAHs"]
[Tue Jul 21 08:16:32.687439 2026] [security2:error] [pid 411857:tid 412109] [client 20.206.105.145:25479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/ops.php"] [unique_id "al9VEC7ynBpLeKYztQOwlgAAAHg"]
[Tue Jul 21 08:16:32.741188 2026] [security2:error] [pid 411857:tid 411903] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VEC7ynBpLeKYztQOwlwAAUyw"]
[Tue Jul 21 08:16:32.741383 2026] [security2:error] [pid 411857:tid 412072] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VEC7ynBpLeKYztQOwlwAAUyw"]
[Tue Jul 21 08:16:32.940762 2026] [security2:error] [pid 411857:tid 412095] [client 154.208.47.42:60645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VEC7ynBpLeKYztQOwnAAAAGo"]
[Tue Jul 21 08:16:32.940954 2026] [security2:error] [pid 411857:tid 412095] [client 154.208.47.42:60645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VEC7ynBpLeKYztQOwnAAAAGo"]
[Tue Jul 21 08:16:33.000956 2026] [security2:error] [pid 411857:tid 412043] [client 74.249.245.134:15118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/asd.php"] [unique_id "al9VES7ynBpLeKYztQOwnQAAADY"]
[Tue Jul 21 08:16:33.006375 2026] [security2:error] [pid 402041:tid 402266] [client 93.108.115.148:49462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.115.108.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homemsedutoronline.com"] [uri "/xmlrpc.php"] [unique_id "al9VEYiENNLP6XjiHQtxbAAAAew"]
[Tue Jul 21 08:16:33.006492 2026] [security2:error] [pid 402041:tid 402266] [client 93.108.115.148:49462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "homemsedutoronline.com"] [uri "/xmlrpc.php"] [unique_id "al9VEYiENNLP6XjiHQtxbAAAAew"]
[Tue Jul 21 08:16:33.154306 2026] [security2:error] [pid 402041:tid 402215] [client 20.151.10.161:20399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/0.php"] [unique_id "al9VEYiENNLP6XjiHQtxcQAAAbk"]
[Tue Jul 21 08:16:33.210533 2026] [security2:error] [pid 402041:tid 402221] [client 103.151.46.103:65121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VEYiENNLP6XjiHQtxcgAAAb8"]
[Tue Jul 21 08:16:33.210688 2026] [security2:error] [pid 402041:tid 402221] [client 103.151.46.103:65121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VEYiENNLP6XjiHQtxcgAAAb8"]
[Tue Jul 21 08:16:33.282842 2026] [security2:error] [pid 411857:tid 412079] [client 103.78.200.11:60108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VES7ynBpLeKYztQOwngAAAFo"]
[Tue Jul 21 08:16:33.284464 2026] [security2:error] [pid 411857:tid 412079] [client 103.78.200.11:60108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VES7ynBpLeKYztQOwngAAAFo"]
[Tue Jul 21 08:16:33.484589 2026] [security2:error] [pid 402041:tid 402264] [client 20.220.225.223:24293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/byp8.php"] [unique_id "al9VEYiENNLP6XjiHQtxdgAAAeo"]
[Tue Jul 21 08:16:33.741717 2026] [security2:error] [pid 411857:tid 412100] [client 20.206.105.145:25562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/ingfo.php"] [unique_id "al9VES7ynBpLeKYztQOwpAAAAG8"]
[Tue Jul 21 08:16:33.788065 2026] [security2:error] [pid 411857:tid 412015] [client 20.151.10.161:36432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9VES7ynBpLeKYztQOwpQAAABo"]
[Tue Jul 21 08:16:33.988300 2026] [security2:error] [pid 402041:tid 402182] [client 87.116.180.198:27270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VEYiENNLP6XjiHQtxggAAAZg"]
[Tue Jul 21 08:16:33.989542 2026] [security2:error] [pid 402041:tid 402182] [client 87.116.180.198:27270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VEYiENNLP6XjiHQtxggAAAZg"]
[Tue Jul 21 08:16:34.064848 2026] [security2:error] [pid 402041:tid 402251] [client 20.151.10.161:13242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/themes.php"] [unique_id "al9VEoiENNLP6XjiHQtxhAAAAd0"]
[Tue Jul 21 08:16:34.076637 2026] [security2:error] [pid 402041:tid 402275] [client 102.206.115.33:64630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VEoiENNLP6XjiHQtxhQAAAfU"]
[Tue Jul 21 08:16:34.076784 2026] [security2:error] [pid 402041:tid 402275] [client 102.206.115.33:64630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VEoiENNLP6XjiHQtxhQAAAfU"]
[Tue Jul 21 08:16:34.497374 2026] [security2:error] [pid 402041:tid 402192] [client 65.21.113.253:51968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VEoiENNLP6XjiHQtxgwAAAaI"]
[Tue Jul 21 08:16:34.590359 2026] [security2:error] [pid 411857:tid 412023] [client 74.249.245.134:15109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/default.php"] [unique_id "al9VEi7ynBpLeKYztQOwrQAAACI"]
[Tue Jul 21 08:16:34.728699 2026] [security2:error] [pid 402041:tid 402288] [client 103.106.20.201:59121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VEoiENNLP6XjiHQtxmQAAAgI"]
[Tue Jul 21 08:16:34.728802 2026] [security2:error] [pid 402041:tid 402288] [client 103.106.20.201:59121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VEoiENNLP6XjiHQtxmQAAAgI"]
[Tue Jul 21 08:16:34.763872 2026] [security2:error] [pid 411857:tid 412040] [client 187.125.243.197:51617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VEi7ynBpLeKYztQOwsAAAADM"]
[Tue Jul 21 08:16:34.764172 2026] [security2:error] [pid 411857:tid 412040] [client 187.125.243.197:51617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VEi7ynBpLeKYztQOwsAAAADM"]
[Tue Jul 21 08:16:34.816634 2026] [security2:error] [pid 411857:tid 412042] [client 20.220.225.223:24200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/user.php"] [unique_id "al9VEi7ynBpLeKYztQOwsQAAADU"]
[Tue Jul 21 08:16:34.899630 2026] [security2:error] [pid 411857:tid 412010] [client 20.151.10.161:20461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/BDKR28.php"] [unique_id "al9VEi7ynBpLeKYztQOwswAAABU"]
[Tue Jul 21 08:16:35.138556 2026] [security2:error] [pid 411857:tid 412071] [client 20.220.225.223:58909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/ops.php"] [unique_id "al9VEy7ynBpLeKYztQOwtgAAAFI"]
[Tue Jul 21 08:16:35.406192 2026] [security2:error] [pid 411857:tid 412019] [client 14.245.224.124:61096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VEy7ynBpLeKYztQOwvQAAAB4"]
[Tue Jul 21 08:16:35.406304 2026] [security2:error] [pid 411857:tid 412019] [client 14.245.224.124:61096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VEy7ynBpLeKYztQOwvQAAAB4"]
[Tue Jul 21 08:16:35.594612 2026] [security2:error] [pid 402041:tid 402259] [client 65.21.113.253:51968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VE4iENNLP6XjiHQtxowAAAeU"]
[Tue Jul 21 08:16:35.636665 2026] [security2:error] [pid 402041:tid 402047] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VE4iENNLP6XjiHQtxwwACBQM"]
[Tue Jul 21 08:16:35.636855 2026] [security2:error] [pid 402041:tid 402291] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VE4iENNLP6XjiHQtxwwACBQM"]
[Tue Jul 21 08:16:35.656278 2026] [security2:error] [pid 402041:tid 402069] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VE4iENNLP6XjiHQtxxAABpxk"]
[Tue Jul 21 08:16:35.656419 2026] [security2:error] [pid 402041:tid 402197] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VE4iENNLP6XjiHQtxxAABpxk"]
[Tue Jul 21 08:16:35.742051 2026] [security2:error] [pid 411857:tid 412080] [client 20.197.192.193:61061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/min.php"] [unique_id "al9VEy7ynBpLeKYztQOwwQAAAFs"]
[Tue Jul 21 08:16:35.792612 2026] [security2:error] [pid 411857:tid 412109] [client 74.249.245.134:31392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/gettest.php"] [unique_id "al9VEy7ynBpLeKYztQOwxAAAAHg"]
[Tue Jul 21 08:16:35.880610 2026] [security2:error] [pid 402041:tid 402296] [client 152.42.185.27:52575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.185.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bellascleaningsolutionsllc.com"] [uri "/blog//xmlrpc.php"] [unique_id "al9VE4iENNLP6XjiHQtxxgAAAgo"]
[Tue Jul 21 08:16:35.880732 2026] [security2:error] [pid 402041:tid 402296] [client 152.42.185.27:52575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bellascleaningsolutionsllc.com"] [uri "/blog//xmlrpc.php"] [unique_id "al9VE4iENNLP6XjiHQtxxgAAAgo"]
[Tue Jul 21 08:16:36.363959 2026] [proxy:error] [pid 411857:tid 412113] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:36.364034 2026] [proxy_http:error] [pid 411857:tid 412113] [client 20.151.10.161:13213] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:36.364564 2026] [proxy:error] [pid 411857:tid 412113] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:36.364591 2026] [proxy_http:error] [pid 411857:tid 412113] [client 20.151.10.161:13213] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:36.446037 2026] [security2:error] [pid 411857:tid 412018] [client 111.93.58.162:64210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VFC7ynBpLeKYztQOwywAAAB0"]
[Tue Jul 21 08:16:36.446200 2026] [security2:error] [pid 411857:tid 412018] [client 111.93.58.162:64210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VFC7ynBpLeKYztQOwywAAAB0"]
[Tue Jul 21 08:16:36.808270 2026] [security2:error] [pid 402041:tid 402208] [client 20.151.10.161:36551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9VFIiENNLP6XjiHQtx3wAAAbI"]
[Tue Jul 21 08:16:36.942871 2026] [security2:error] [pid 402041:tid 402300] [client 62.102.148.158:48684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9VFIiENNLP6XjiHQtx4QAAAg4"]
[Tue Jul 21 08:16:36.942987 2026] [security2:error] [pid 402041:tid 402300] [client 62.102.148.158:48684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9VFIiENNLP6XjiHQtx4QAAAg4"]
[Tue Jul 21 08:16:37.122568 2026] [security2:error] [pid 411857:tid 411912] [remote 185.191.171.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "androapkmod.com"] [uri "/playtv-geh/"] [unique_id "al9VFS7ynBpLeKYztQOw0QAAWjU"]
[Tue Jul 21 08:16:37.122742 2026] [security2:error] [pid 411857:tid 412079] [client 185.191.171.16:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "androapkmod.com"] [uri "/playtv-geh/"] [unique_id "al9VFS7ynBpLeKYztQOw0QAAWjU"]
[Tue Jul 21 08:16:37.141484 2026] [security2:error] [pid 402041:tid 402273] [client 62.102.148.158:48700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9VFYiENNLP6XjiHQtx5gAAAfM"]
[Tue Jul 21 08:16:37.141581 2026] [security2:error] [pid 402041:tid 402273] [client 62.102.148.158:48700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9VFYiENNLP6XjiHQtx5gAAAfM"]
[Tue Jul 21 08:16:37.191807 2026] [security2:error] [pid 411857:tid 412000] [client 20.151.10.161:20315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/f35.update.php"] [unique_id "al9VFS7ynBpLeKYztQOw0gAAAAs"]
[Tue Jul 21 08:16:37.229451 2026] [security2:error] [pid 402041:tid 402248] [client 20.206.105.145:25486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/error_log.php"] [unique_id "al9VFYiENNLP6XjiHQtx5wAAAdo"]
[Tue Jul 21 08:16:37.261170 2026] [security2:error] [pid 411857:tid 411999] [client 74.249.245.134:15388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/tfm.php"] [unique_id "al9VFS7ynBpLeKYztQOw0wAAAAo"]
[Tue Jul 21 08:16:37.376958 2026] [security2:error] [pid 402041:tid 402282] [client 20.151.10.161:36526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/gettest.php"] [unique_id "al9VFYiENNLP6XjiHQtx6wAAAfw"]
[Tue Jul 21 08:16:37.741893 2026] [security2:error] [pid 402041:tid 402279] [client 152.42.185.27:60906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.185.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bellascleaningsolutionsllc.com"] [uri "/blog//wp-login.php"] [unique_id "al9VFYiENNLP6XjiHQtx8AAAAfk"], referer: https://bellascleaningsolutionsllc.com//blog//wp-login.php
[Tue Jul 21 08:16:37.850742 2026] [security2:error] [pid 402041:tid 402287] [client 20.197.192.193:13660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/dr.php"] [unique_id "al9VFYiENNLP6XjiHQtx8QAAAgE"]
[Tue Jul 21 08:16:38.424985 2026] [security2:error] [pid 411857:tid 412023] [client 20.206.105.145:25558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/ok.php"] [unique_id "al9VFi7ynBpLeKYztQOw3wAAACI"]
[Tue Jul 21 08:16:38.443430 2026] [security2:error] [pid 411857:tid 411990] [client 115.134.11.136:56675] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VFi7ynBpLeKYztQOw4AAAAAE"]
[Tue Jul 21 08:16:38.482929 2026] [security2:error] [pid 402041:tid 402096] [remote 192.241.143.148:59504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agencia.aede.com.br"] [uri "/wp-login.php"] [unique_id "al9VFoiENNLP6XjiHQtx_AAB6TQ"]
[Tue Jul 21 08:16:38.483210 2026] [security2:error] [pid 411857:tid 412015] [client 120.56.162.40:51436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VFi7ynBpLeKYztQOw4QAAABo"]
[Tue Jul 21 08:16:38.483362 2026] [security2:error] [pid 411857:tid 412015] [client 120.56.162.40:51436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VFi7ynBpLeKYztQOw4QAAABo"]
[Tue Jul 21 08:16:38.571258 2026] [security2:error] [pid 402041:tid 402216] [client 150.129.202.39:64877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VFoiENNLP6XjiHQtx_wAAAbo"]
[Tue Jul 21 08:16:38.571371 2026] [security2:error] [pid 402041:tid 402216] [client 150.129.202.39:64877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VFoiENNLP6XjiHQtx_wAAAbo"]
[Tue Jul 21 08:16:38.597644 2026] [security2:error] [pid 411857:tid 412049] [client 20.151.10.161:51091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/simple.php"] [unique_id "al9VFi7ynBpLeKYztQOw4wAAADw"]
[Tue Jul 21 08:16:38.646405 2026] [security2:error] [pid 411857:tid 412035] [client 20.151.10.161:13290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/8.php"] [unique_id "al9VFi7ynBpLeKYztQOw5AAAAC4"]
[Tue Jul 21 08:16:38.827895 2026] [security2:error] [pid 402041:tid 402215] [client 74.249.245.134:15105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/ws81.php"] [unique_id "al9VFoiENNLP6XjiHQtyAgAAAbk"]
[Tue Jul 21 08:16:38.910645 2026] [security2:error] [pid 402041:tid 402266] [client 20.197.192.193:13659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/2x.php"] [unique_id "al9VFoiENNLP6XjiHQtyAwAAAew"]
[Tue Jul 21 08:16:39.099134 2026] [security2:error] [pid 411857:tid 412021] [client 117.210.135.0:59590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VFy7ynBpLeKYztQOw6AAAACA"]
[Tue Jul 21 08:16:39.099271 2026] [security2:error] [pid 411857:tid 412021] [client 117.210.135.0:59590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VFy7ynBpLeKYztQOw6AAAACA"]
[Tue Jul 21 08:16:39.185093 2026] [security2:error] [pid 411857:tid 411990] [client 115.134.11.136:56675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VFi7ynBpLeKYztQOw4AAAAAE"]
[Tue Jul 21 08:16:39.231621 2026] [security2:error] [pid 411857:tid 412096] [client 20.151.10.161:36494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/xxx.php"] [unique_id "al9VFy7ynBpLeKYztQOw6QAAAGs"]
[Tue Jul 21 08:16:39.298701 2026] [security2:error] [pid 411857:tid 412103] [client 20.206.105.145:25492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/mac.php"] [unique_id "al9VFy7ynBpLeKYztQOw6gAAAHI"]
[Tue Jul 21 08:16:39.443459 2026] [security2:error] [pid 411857:tid 411913] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VFy7ynBpLeKYztQOw6wAAVzY"]
[Tue Jul 21 08:16:39.443646 2026] [security2:error] [pid 411857:tid 412076] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VFy7ynBpLeKYztQOw6wAAVzY"]
[Tue Jul 21 08:16:39.635868 2026] [security2:error] [pid 402041:tid 402259] [client 223.181.60.88:24289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VF4iENNLP6XjiHQtyEAAAAeU"]
[Tue Jul 21 08:16:39.636793 2026] [security2:error] [pid 402041:tid 402259] [client 223.181.60.88:24289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VF4iENNLP6XjiHQtyEAAAAeU"]
[Tue Jul 21 08:16:39.691246 2026] [security2:error] [pid 402041:tid 402106] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VF4iENNLP6XjiHQtyEwAB7j4"]
[Tue Jul 21 08:16:39.691524 2026] [security2:error] [pid 402041:tid 402268] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VF4iENNLP6XjiHQtyEwAB7j4"]
[Tue Jul 21 08:16:39.701079 2026] [security2:error] [pid 402041:tid 402247] [client 74.249.245.134:15133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/222.php"] [unique_id "al9VF4iENNLP6XjiHQtyFAAAAdk"]
[Tue Jul 21 08:16:39.803440 2026] [security2:error] [pid 411857:tid 411915] [remote 192.241.143.148:59512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9VFy7ynBpLeKYztQOw8gAAADg"]
[Tue Jul 21 08:16:39.816074 2026] [security2:error] [pid 411857:tid 412091] [client 20.151.10.161:20456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/f900.php"] [unique_id "al9VFy7ynBpLeKYztQOw8wAAAGY"]
[Tue Jul 21 08:16:39.988708 2026] [security2:error] [pid 411857:tid 412093] [client 20.206.105.145:25582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wefile.php"] [unique_id "al9VFy7ynBpLeKYztQOw9gAAAGg"]
[Tue Jul 21 08:16:40.128297 2026] [security2:error] [pid 411857:tid 412084] [client 20.206.105.145:25476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9VGC7ynBpLeKYztQOw-AAAAF8"]
[Tue Jul 21 08:16:40.152088 2026] [security2:error] [pid 402041:tid 402249] [client 20.151.10.161:51101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/hypo.php"] [unique_id "al9VGIiENNLP6XjiHQtyGQAAAds"]
[Tue Jul 21 08:16:40.219334 2026] [security2:error] [pid 411857:tid 412113] [client 20.151.10.161:20473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/xmrl.php"] [unique_id "al9VGC7ynBpLeKYztQOw-wAAAHw"]
[Tue Jul 21 08:16:40.651524 2026] [security2:error] [pid 411857:tid 412009] [client 20.151.10.161:20387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/memberfuns.php"] [unique_id "al9VGC7ynBpLeKYztQOxAwAAABQ"]
[Tue Jul 21 08:16:40.887742 2026] [security2:error] [pid 411857:tid 411920] [remote 45.79.123.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onkosclinica.com"] [uri "/wp-login.php"] [unique_id "al9VGC7ynBpLeKYztQOxBwAAET0"]
[Tue Jul 21 08:16:40.923838 2026] [security2:error] [pid 402041:tid 402211] [client 20.151.10.161:13220] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.lasferas.com"] [uri "/1.php"] [unique_id "al9VGIiENNLP6XjiHQtyIQAAAbU"]
[Tue Jul 21 08:16:40.923941 2026] [security2:error] [pid 402041:tid 402211] [client 20.151.10.161:13220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/1.php"] [unique_id "al9VGIiENNLP6XjiHQtyIQAAAbU"]
[Tue Jul 21 08:16:41.027262 2026] [security2:error] [pid 402041:tid 402206] [client 20.151.10.161:20357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/ms.php"] [unique_id "al9VGYiENNLP6XjiHQtyJgAAAbA"]
[Tue Jul 21 08:16:41.097693 2026] [security2:error] [pid 411857:tid 412107] [client 20.151.10.161:36573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/chosen.php"] [unique_id "al9VGS7ynBpLeKYztQOxCQAAAHY"]
[Tue Jul 21 08:16:41.492276 2026] [security2:error] [pid 411857:tid 412075] [client 20.151.10.161:20303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/zz.php"] [unique_id "al9VGS7ynBpLeKYztQOxCgAAAFY"]
[Tue Jul 21 08:16:41.687185 2026] [security2:error] [pid 411857:tid 411998] [client 20.151.10.161:13260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/100.php"] [unique_id "al9VGS7ynBpLeKYztQOxDgAAAAk"]
[Tue Jul 21 08:16:41.815987 2026] [security2:error] [pid 402041:tid 402286] [client 20.151.10.161:20333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/for.php"] [unique_id "al9VGYiENNLP6XjiHQtyMAAAAgA"]
[Tue Jul 21 08:16:42.006107 2026] [security2:error] [pid 402041:tid 402277] [client 62.102.148.158:32892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9VGoiENNLP6XjiHQtyMQAAAfc"]
[Tue Jul 21 08:16:42.006208 2026] [security2:error] [pid 402041:tid 402277] [client 62.102.148.158:32892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9VGoiENNLP6XjiHQtyMQAAAfc"]
[Tue Jul 21 08:16:42.088048 2026] [security2:error] [pid 411857:tid 412096] [client 20.151.10.161:36592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/als.php"] [unique_id "al9VGi7ynBpLeKYztQOxHAAAAGs"]
[Tue Jul 21 08:16:42.125194 2026] [security2:error] [pid 411857:tid 412029] [client 20.206.105.145:25484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9VGi7ynBpLeKYztQOxHgAAACg"]
[Tue Jul 21 08:16:42.144604 2026] [security2:error] [pid 411857:tid 412060] [client 20.151.10.161:20332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/yup.php"] [unique_id "al9VGi7ynBpLeKYztQOxHwAAAEc"]
[Tue Jul 21 08:16:42.408831 2026] [security2:error] [pid 411857:tid 412067] [client 20.151.10.161:13292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/about.php"] [unique_id "al9VGi7ynBpLeKYztQOxIAAAAE4"]
[Tue Jul 21 08:16:42.449285 2026] [security2:error] [pid 402041:tid 402295] [client 172.233.156.91:60306] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "iotcaragua.com"] [uri "/wp-comments-post.php"] [unique_id "al9VF4iENNLP6XjiHQtyCAAAAgk"]
[Tue Jul 21 08:16:42.612955 2026] [security2:error] [pid 402041:tid 402256] [client 38.100.221.102:18822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VGoiENNLP6XjiHQtyPgAAAeI"]
[Tue Jul 21 08:16:42.613081 2026] [security2:error] [pid 402041:tid 402256] [client 38.100.221.102:18822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VGoiENNLP6XjiHQtyPgAAAeI"]
[Tue Jul 21 08:16:42.634074 2026] [security2:error] [pid 402041:tid 402295] [client 172.233.156.91:60306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "iotcaragua.com"] [uri "/wp-comments-post.php"] [unique_id "al9VF4iENNLP6XjiHQtyCAAAAgk"]
[Tue Jul 21 08:16:42.645190 2026] [security2:error] [pid 411857:tid 412108] [client 20.151.10.161:20361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/wpxml.php"] [unique_id "al9VGi7ynBpLeKYztQOxKgAAAHc"]
[Tue Jul 21 08:16:42.663178 2026] [security2:error] [pid 402041:tid 402199] [client 20.151.10.161:36557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/pol.php"] [unique_id "al9VGoiENNLP6XjiHQtyPwAAAak"]
[Tue Jul 21 08:16:42.741386 2026] [security2:error] [pid 402041:tid 402159] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VGoiENNLP6XjiHQtyQAABq3M"]
[Tue Jul 21 08:16:42.741580 2026] [security2:error] [pid 402041:tid 402201] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VGoiENNLP6XjiHQtyQAABq3M"]
[Tue Jul 21 08:16:42.942126 2026] [security2:error] [pid 402041:tid 402261] [client 74.249.245.134:31390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/t.php"] [unique_id "al9VGoiENNLP6XjiHQtyRgAAAec"]
[Tue Jul 21 08:16:43.137562 2026] [security2:error] [pid 411857:tid 412065] [client 65.21.113.253:56106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VGi7ynBpLeKYztQOxKwAAAEw"]
[Tue Jul 21 08:16:43.220864 2026] [security2:error] [pid 411857:tid 412000] [client 20.151.10.161:20294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/fffm.php"] [unique_id "al9VGy7ynBpLeKYztQOxNAAAAAs"]
[Tue Jul 21 08:16:43.237305 2026] [security2:error] [pid 411857:tid 411925] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VGy7ynBpLeKYztQOxNQAAcEI"]
[Tue Jul 21 08:16:43.237493 2026] [security2:error] [pid 411857:tid 412101] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VGy7ynBpLeKYztQOxNQAAcEI"]
[Tue Jul 21 08:16:43.288420 2026] [security2:error] [pid 411857:tid 411992] [client 20.151.10.161:13252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/about.php"] [unique_id "al9VGy7ynBpLeKYztQOxOAAAAAM"]
[Tue Jul 21 08:16:43.312654 2026] [security2:error] [pid 402041:tid 402264] [client 20.206.105.145:25478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/like.php"] [unique_id "al9VG4iENNLP6XjiHQtyTQAAAeo"]
[Tue Jul 21 08:16:43.505672 2026] [security2:error] [pid 411857:tid 412069] [client 154.208.47.43:55257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VGy7ynBpLeKYztQOxPAAAAFA"]
[Tue Jul 21 08:16:43.505850 2026] [security2:error] [pid 411857:tid 412069] [client 154.208.47.43:55257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VGy7ynBpLeKYztQOxPAAAAFA"]
[Tue Jul 21 08:16:43.509978 2026] [security2:error] [pid 411857:tid 412054] [client 103.78.200.11:60637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VGy7ynBpLeKYztQOxPQAAAEE"]
[Tue Jul 21 08:16:43.510111 2026] [security2:error] [pid 411857:tid 412054] [client 103.78.200.11:60637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VGy7ynBpLeKYztQOxPQAAAEE"]
[Tue Jul 21 08:16:43.540805 2026] [security2:error] [pid 402041:tid 402255] [client 20.151.10.161:36540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/file5.php"] [unique_id "al9VG4iENNLP6XjiHQtyUQAAAeE"]
[Tue Jul 21 08:16:43.572290 2026] [security2:error] [pid 402041:tid 402268] [client 20.151.10.161:20403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/gecko.php"] [unique_id "al9VG4iENNLP6XjiHQtyUgAAAe4"]
[Tue Jul 21 08:16:43.710162 2026] [security2:error] [pid 411857:tid 411993] [client 115.134.11.136:56675] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VGy7ynBpLeKYztQOxPgAAAAQ"]
[Tue Jul 21 08:16:43.710358 2026] [security2:error] [pid 411857:tid 411993] [client 115.134.11.136:56675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VGy7ynBpLeKYztQOxPgAAAAQ"]
[Tue Jul 21 08:16:43.909082 2026] [security2:error] [pid 402041:tid 402289] [client 20.151.10.161:13301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/admin.php"] [unique_id "al9VG4iENNLP6XjiHQtyWQAAAgM"]
[Tue Jul 21 08:16:44.085380 2026] [security2:error] [pid 402041:tid 402177] [client 20.151.10.161:20451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/a1.php"] [unique_id "al9VHIiENNLP6XjiHQtyWwAAAZM"]
[Tue Jul 21 08:16:44.175227 2026] [security2:error] [pid 402041:tid 402280] [client 20.206.105.145:25543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/.well-known/about.php"] [unique_id "al9VHIiENNLP6XjiHQtyXAAAAfo"]
[Tue Jul 21 08:16:44.260043 2026] [security2:error] [pid 402041:tid 402206] [client 20.151.10.161:36466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9VHIiENNLP6XjiHQtyZAAAAbA"]
[Tue Jul 21 08:16:44.538524 2026] [security2:error] [pid 411857:tid 412004] [client 20.151.10.161:13188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/admin.php"] [unique_id "al9VHC7ynBpLeKYztQOxSgAAAA8"]
[Tue Jul 21 08:16:44.641904 2026] [security2:error] [pid 402041:tid 402284] [client 20.151.10.161:20351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/k2.php"] [unique_id "al9VHIiENNLP6XjiHQtyagAAAf4"]
[Tue Jul 21 08:16:44.665457 2026] [security2:error] [pid 411857:tid 412007] [client 102.206.115.33:57483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VHC7ynBpLeKYztQOxSwAAABI"]
[Tue Jul 21 08:16:44.665588 2026] [security2:error] [pid 411857:tid 412007] [client 102.206.115.33:57483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VHC7ynBpLeKYztQOxSwAAABI"]
[Tue Jul 21 08:16:44.674430 2026] [security2:error] [pid 402041:tid 402251] [client 87.116.180.198:27382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VHIiENNLP6XjiHQtybAAAAd0"]
[Tue Jul 21 08:16:44.677985 2026] [security2:error] [pid 402041:tid 402251] [client 87.116.180.198:27382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VHIiENNLP6XjiHQtybAAAAd0"]
[Tue Jul 21 08:16:44.801829 2026] [core:error] [pid 411857:tid 412096] [client 151.243.236.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:16:44.801851 2026] [core:error] [pid 411857:tid 412096] [client 151.243.236.99:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:16:44.955008 2026] [security2:error] [pid 402041:tid 402297] [client 20.151.10.161:36586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/file.php"] [unique_id "al9VHIiENNLP6XjiHQtydAAAAgs"]
[Tue Jul 21 08:16:45.076334 2026] [security2:error] [pid 402041:tid 402272] [client 162.219.176.3:57060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9VHYiENNLP6XjiHQtydQAAAfI"]
[Tue Jul 21 08:16:45.076440 2026] [security2:error] [pid 402041:tid 402272] [client 162.219.176.3:57060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9VHYiENNLP6XjiHQtydQAAAfI"]
[Tue Jul 21 08:16:45.111951 2026] [security2:error] [pid 411857:tid 412081] [client 20.206.105.145:25546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9VHS7ynBpLeKYztQOxUwAAAFw"]
[Tue Jul 21 08:16:45.136265 2026] [security2:error] [pid 411857:tid 412099] [client 20.151.10.161:13256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/edit.php"] [unique_id "al9VHS7ynBpLeKYztQOxVAAAAG4"]
[Tue Jul 21 08:16:45.153203 2026] [security2:error] [pid 411857:tid 412062] [client 103.151.46.103:49284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VHS7ynBpLeKYztQOxVQAAAEk"]
[Tue Jul 21 08:16:45.153321 2026] [security2:error] [pid 411857:tid 412062] [client 103.151.46.103:49284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VHS7ynBpLeKYztQOxVQAAAEk"]
[Tue Jul 21 08:16:45.212653 2026] [security2:error] [pid 402041:tid 402235] [client 20.151.10.161:20411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/82.php"] [unique_id "al9VHYiENNLP6XjiHQtydgAAAc0"]
[Tue Jul 21 08:16:45.261880 2026] [security2:error] [pid 411857:tid 412046] [client 187.125.243.197:52110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VHS7ynBpLeKYztQOxWgAAADk"]
[Tue Jul 21 08:16:45.262891 2026] [security2:error] [pid 411857:tid 412046] [client 187.125.243.197:52110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VHS7ynBpLeKYztQOxWgAAADk"]
[Tue Jul 21 08:16:45.437501 2026] [security2:error] [pid 411857:tid 412010] [client 103.106.20.201:59738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VHS7ynBpLeKYztQOxXQAAABU"]
[Tue Jul 21 08:16:45.437612 2026] [security2:error] [pid 411857:tid 412010] [client 103.106.20.201:59738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VHS7ynBpLeKYztQOxXQAAABU"]
[Tue Jul 21 08:16:45.451851 2026] [security2:error] [pid 411857:tid 412078] [client 65.21.113.253:56106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VHS7ynBpLeKYztQOxTwAAAFk"]
[Tue Jul 21 08:16:45.505293 2026] [security2:error] [pid 402041:tid 402174] [client 20.151.10.161:13232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wp-content/admin.php"] [unique_id "al9VHYiENNLP6XjiHQtyfgAAAZA"]
[Tue Jul 21 08:16:45.521429 2026] [security2:error] [pid 411857:tid 412036] [client 20.151.10.161:36546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/cfile.php"] [unique_id "al9VHS7ynBpLeKYztQOxYAAAAC8"]
[Tue Jul 21 08:16:45.576050 2026] [security2:error] [pid 411857:tid 412115] [client 20.151.10.161:20306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/config.json.php"] [unique_id "al9VHS7ynBpLeKYztQOxYgAAAH4"]
[Tue Jul 21 08:16:45.912272 2026] [security2:error] [pid 402041:tid 402246] [client 20.151.10.161:13208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/f6.php"] [unique_id "al9VHYiENNLP6XjiHQtyhwAAAdg"]
[Tue Jul 21 08:16:45.919542 2026] [security2:error] [pid 402041:tid 402261] [client 20.151.10.161:20227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.gfacil.com.br"] [uri "/fpwch.php"] [unique_id "al9VHYiENNLP6XjiHQtyiAAAAec"]
[Tue Jul 21 08:16:46.020029 2026] [security2:error] [pid 402041:tid 402295] [client 14.245.224.124:61512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VHoiENNLP6XjiHQtyjAAAAgk"]
[Tue Jul 21 08:16:46.020134 2026] [security2:error] [pid 402041:tid 402295] [client 14.245.224.124:61512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VHoiENNLP6XjiHQtyjAAAAgk"]
[Tue Jul 21 08:16:46.164617 2026] [security2:error] [pid 411857:tid 411936] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VHi7ynBpLeKYztQOxZwAAWk0"]
[Tue Jul 21 08:16:46.164807 2026] [security2:error] [pid 411857:tid 412079] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VHi7ynBpLeKYztQOxZwAAWk0"]
[Tue Jul 21 08:16:46.327337 2026] [security2:error] [pid 411857:tid 412033] [client 20.151.10.161:13195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/inputs.php"] [unique_id "al9VHi7ynBpLeKYztQOxbAAAACw"]
[Tue Jul 21 08:16:46.486125 2026] [security2:error] [pid 411857:tid 411930] [remote 91.142.222.105:49644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9VHC7ynBpLeKYztQOxSQAAPUc"]
[Tue Jul 21 08:16:46.572969 2026] [security2:error] [pid 402041:tid 402237] [client 74.249.245.134:31366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/a.php"] [unique_id "al9VHoiENNLP6XjiHQtylgAAAc8"]
[Tue Jul 21 08:16:46.637066 2026] [security2:error] [pid 411857:tid 411939] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VHi7ynBpLeKYztQOxcAAAG1A"]
[Tue Jul 21 08:16:46.637278 2026] [security2:error] [pid 411857:tid 412016] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VHi7ynBpLeKYztQOxcAAAG1A"]
[Tue Jul 21 08:16:46.764336 2026] [security2:error] [pid 411857:tid 411940] [remote 167.71.218.184:58134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/wp-login.php"] [unique_id "al9VHi7ynBpLeKYztQOxcQAAf1E"]
[Tue Jul 21 08:16:46.832133 2026] [security2:error] [pid 402041:tid 402208] [client 20.151.10.161:13194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/inputs.php"] [unique_id "al9VHoiENNLP6XjiHQtymgAAAbI"]
[Tue Jul 21 08:16:47.090892 2026] [security2:error] [pid 411857:tid 412028] [client 20.151.10.161:51107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/class-wp.php"] [unique_id "al9VHy7ynBpLeKYztQOxdgAAACc"]
[Tue Jul 21 08:16:47.161595 2026] [security2:error] [pid 411857:tid 412111] [client 111.93.58.162:16580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VHy7ynBpLeKYztQOxdwAAAHo"]
[Tue Jul 21 08:16:47.161748 2026] [security2:error] [pid 411857:tid 412111] [client 111.93.58.162:16580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VHy7ynBpLeKYztQOxdwAAAHo"]
[Tue Jul 21 08:16:47.212211 2026] [security2:error] [pid 411857:tid 412052] [client 20.151.10.161:13215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/av.php"] [unique_id "al9VHy7ynBpLeKYztQOxeAAAAD8"]
[Tue Jul 21 08:16:47.247840 2026] [security2:error] [pid 402041:tid 402255] [client 61.1.167.83:56630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VH4iENNLP6XjiHQtynwAAAeE"]
[Tue Jul 21 08:16:47.277391 2026] [security2:error] [pid 402041:tid 402255] [client 61.1.167.83:56630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VH4iENNLP6XjiHQtynwAAAeE"]
[Tue Jul 21 08:16:47.375126 2026] [security2:error] [pid 402041:tid 402093] [remote 152.42.185.27:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.185.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.expertemrecheios.com"] [uri "/xmlrpc.php"] [unique_id "al9VH4iENNLP6XjiHQtyowABmTE"]
[Tue Jul 21 08:16:47.536509 2026] [core:alert] [pid 411857:tid 412037] [client 57.141.18.98:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:16:47.705779 2026] [security2:error] [pid 411857:tid 412049] [client 65.21.113.253:56106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VHy7ynBpLeKYztQOxeQAAADw"]
[Tue Jul 21 08:16:47.717168 2026] [rewrite:warn] [pid 411857:tid 411943] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:16:47.846719 2026] [security2:error] [pid 402041:tid 402180] [client 20.151.10.161:13184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/classwithtostring.php"] [unique_id "al9VH4iENNLP6XjiHQtyqgAAAZY"]
[Tue Jul 21 08:16:48.350637 2026] [security2:error] [pid 411857:tid 412080] [client 20.151.10.161:13167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9VIC7ynBpLeKYztQOxhQAAAFs"]
[Tue Jul 21 08:16:48.593071 2026] [proxy:error] [pid 411857:tid 412109] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:48.593147 2026] [proxy_http:error] [pid 411857:tid 412109] [client 198.235.24.241:65080] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:48.593847 2026] [proxy:error] [pid 411857:tid 412109] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:48.593885 2026] [proxy_http:error] [pid 411857:tid 412109] [client 198.235.24.241:65080] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:48.627312 2026] [security2:error] [pid 411857:tid 412115] [client 20.151.10.161:13126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wp-blog.php"] [unique_id "al9VIC7ynBpLeKYztQOxjAAAAH4"]
[Tue Jul 21 08:16:48.757907 2026] [security2:error] [pid 402041:tid 402153] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/.git/config"] [unique_id "al9VIIiENNLP6XjiHQtyxQABum0"]
[Tue Jul 21 08:16:48.800447 2026] [security2:error] [pid 402041:tid 402278] [client 20.206.105.145:25503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/pucci.php"] [unique_id "al9VIIiENNLP6XjiHQtyzAAAAfg"]
[Tue Jul 21 08:16:48.815085 2026] [security2:error] [pid 411857:tid 412074] [client 20.151.10.161:46072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9VIC7ynBpLeKYztQOxjgAAAFU"]
[Tue Jul 21 08:16:48.969347 2026] [rewrite:warn] [pid 411857:tid 411946] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:16:48.976583 2026] [proxy:error] [pid 411857:tid 412079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:48.976656 2026] [proxy_http:error] [pid 411857:tid 412079] [client 20.151.10.161:13304] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:48.977381 2026] [proxy:error] [pid 411857:tid 412079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:48.977425 2026] [proxy_http:error] [pid 411857:tid 412079] [client 20.151.10.161:13304] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:49.067974 2026] [security2:error] [pid 402041:tid 402067] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.git-credentials"] [unique_id "al9VIYiENNLP6XjiHQty1gABuhc"]
[Tue Jul 21 08:16:49.084619 2026] [security2:error] [pid 411857:tid 412094] [client 150.129.202.39:13299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VIS7ynBpLeKYztQOxlQAAAGk"]
[Tue Jul 21 08:16:49.084763 2026] [security2:error] [pid 411857:tid 412094] [client 150.129.202.39:13299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VIS7ynBpLeKYztQOxlQAAAGk"]
[Tue Jul 21 08:16:49.198853 2026] [security2:error] [pid 411857:tid 412017] [client 20.151.10.161:46046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9VIS7ynBpLeKYztQOxmQAAABw"]
[Tue Jul 21 08:16:49.225053 2026] [security2:error] [pid 411857:tid 412036] [client 120.56.162.40:51946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VIS7ynBpLeKYztQOxmgAAAC8"]
[Tue Jul 21 08:16:49.225179 2026] [security2:error] [pid 411857:tid 412036] [client 120.56.162.40:51946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VIS7ynBpLeKYztQOxmgAAAC8"]
[Tue Jul 21 08:16:49.226412 2026] [security2:error] [pid 402041:tid 402064] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "panel.gradiente.com"] [uri "/graphql"] [unique_id "al9VIYiENNLP6XjiHQty2gABuhQ"]
[Tue Jul 21 08:16:49.235929 2026] [security2:error] [pid 411857:tid 411948] [remote 68.178.160.25:40572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9VIS7ynBpLeKYztQOxmwAAZ1k"]
[Tue Jul 21 08:16:49.338801 2026] [security2:error] [pid 411857:tid 412064] [client 20.151.10.161:13261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wp-content/admin.php"] [unique_id "al9VIS7ynBpLeKYztQOxnQAAAEs"]
[Tue Jul 21 08:16:49.366253 2026] [security2:error] [pid 402041:tid 402105] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env"] [unique_id "al9VIYiENNLP6XjiHQty3gABuj0"]
[Tue Jul 21 08:16:49.405805 2026] [rewrite:warn] [pid 411857:tid 411949] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:16:49.454087 2026] [security2:error] [pid 402041:tid 402096] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "panel.gradiente.com"] [uri "/api/graphql"] [unique_id "al9VIYiENNLP6XjiHQty4AABujQ"]
[Tue Jul 21 08:16:49.557056 2026] [security2:error] [pid 411857:tid 412101] [client 65.21.113.253:56106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VIS7ynBpLeKYztQOxlAAAAHA"]
[Tue Jul 21 08:16:49.563963 2026] [security2:error] [pid 411857:tid 412002] [client 62.102.148.158:48948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9VIS7ynBpLeKYztQOxowAAAA0"]
[Tue Jul 21 08:16:49.564062 2026] [security2:error] [pid 411857:tid 412002] [client 62.102.148.158:48948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9VIS7ynBpLeKYztQOxowAAAA0"]
[Tue Jul 21 08:16:49.670553 2026] [security2:error] [pid 411857:tid 411997] [client 20.151.10.161:13187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/adminfuns.php"] [unique_id "al9VIS7ynBpLeKYztQOxpgAAAAg"]
[Tue Jul 21 08:16:49.674146 2026] [security2:error] [pid 402041:tid 402154] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "panel.gradiente.com"] [uri "/v1/graphql"] [unique_id "al9VIYiENNLP6XjiHQty7gABum4"]
[Tue Jul 21 08:16:49.675247 2026] [security2:error] [pid 402041:tid 402200] [client 74.249.245.134:15113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/a1.php"] [unique_id "al9VIYiENNLP6XjiHQty7wAAAao"]
[Tue Jul 21 08:16:49.684155 2026] [security2:error] [pid 402041:tid 402091] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/.env.production"] [unique_id "al9VIYiENNLP6XjiHQty8AABui8"]
[Tue Jul 21 08:16:49.774059 2026] [security2:error] [pid 411857:tid 412035] [client 20.151.10.161:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/x.php"] [unique_id "al9VIS7ynBpLeKYztQOxqgAAAC4"]
[Tue Jul 21 08:16:49.844921 2026] [rewrite:warn] [pid 411857:tid 411950] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:16:49.854781 2026] [security2:error] [pid 402041:tid 402170] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/.env.local"] [unique_id "al9VIYiENNLP6XjiHQty9wABun4"]
[Tue Jul 21 08:16:49.856625 2026] [security2:error] [pid 402041:tid 402106] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.backup"] [unique_id "al9VIYiENNLP6XjiHQty9gABuj4"]
[Tue Jul 21 08:16:49.943007 2026] [security2:error] [pid 402041:tid 402132] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.bak"] [unique_id "al9VIYiENNLP6XjiHQtzAAAB4Vg"]
[Tue Jul 21 08:16:49.973718 2026] [security2:error] [pid 402041:tid 402212] [client 20.220.225.223:52619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/term.php"] [unique_id "al9VIYiENNLP6XjiHQtzAwAAAbY"]
[Tue Jul 21 08:16:49.991624 2026] [security2:error] [pid 411857:tid 411952] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VIS7ynBpLeKYztQOxrQAAQFw"]
[Tue Jul 21 08:16:49.991788 2026] [security2:error] [pid 411857:tid 412053] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VIS7ynBpLeKYztQOxrQAAQFw"]
[Tue Jul 21 08:16:50.015185 2026] [security2:error] [pid 411857:tid 411993] [client 223.181.60.88:4442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VIi7ynBpLeKYztQOxrgAAAAQ"]
[Tue Jul 21 08:16:50.015302 2026] [security2:error] [pid 411857:tid 411993] [client 223.181.60.88:4442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VIi7ynBpLeKYztQOxrgAAAAQ"]
[Tue Jul 21 08:16:50.026661 2026] [security2:error] [pid 411857:tid 412037] [client 20.151.10.161:13192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/goods.php"] [unique_id "al9VIi7ynBpLeKYztQOxsAAAADA"]
[Tue Jul 21 08:16:50.034174 2026] [security2:error] [pid 411857:tid 412098] [client 117.210.135.0:60241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VIi7ynBpLeKYztQOxsQAAAG0"]
[Tue Jul 21 08:16:50.034865 2026] [security2:error] [pid 411857:tid 412098] [client 117.210.135.0:60241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VIi7ynBpLeKYztQOxsQAAAG0"]
[Tue Jul 21 08:16:50.053840 2026] [security2:error] [pid 402041:tid 402180] [client 20.206.105.145:25514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wp-temp.php"] [unique_id "al9VIoiENNLP6XjiHQtzCwAAAZY"]
[Tue Jul 21 08:16:50.077078 2026] [security2:error] [pid 402041:tid 402058] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/api/.env"] [unique_id "al9VIoiENNLP6XjiHQtzDAABow4"]
[Tue Jul 21 08:16:50.078966 2026] [security2:error] [pid 402041:tid 402075] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.old"] [unique_id "al9VIoiENNLP6XjiHQtzDQABox8"]
[Tue Jul 21 08:16:50.149484 2026] [security2:error] [pid 402041:tid 402061] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/backend/.env"] [unique_id "al9VIoiENNLP6XjiHQtzFgACARE"]
[Tue Jul 21 08:16:50.162017 2026] [security2:error] [pid 411857:tid 411953] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VIi7ynBpLeKYztQOxsgAAPl0"]
[Tue Jul 21 08:16:50.162176 2026] [security2:error] [pid 411857:tid 412051] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VIi7ynBpLeKYztQOxsgAAPl0"]
[Tue Jul 21 08:16:50.288150 2026] [security2:error] [pid 402041:tid 402078] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/config/.env"] [unique_id "al9VIoiENNLP6XjiHQtzHgABsSI"]
[Tue Jul 21 08:16:50.346032 2026] [security2:error] [pid 402041:tid 402223] [client 20.151.10.161:46047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/j260624_13.php"] [unique_id "al9VIoiENNLP6XjiHQtzIwAAAcE"]
[Tue Jul 21 08:16:50.425412 2026] [security2:error] [pid 402041:tid 402086] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/key.json"] [unique_id "al9VIoiENNLP6XjiHQtzKAABxio"]
[Tue Jul 21 08:16:50.425600 2026] [security2:error] [pid 402041:tid 402228] [client 34.155.146.79:34658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/key.json"] [unique_id "al9VIoiENNLP6XjiHQtzKAABxio"]
[Tue Jul 21 08:16:50.439949 2026] [security2:error] [pid 411857:tid 412073] [client 198.54.129.60:41280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9VIi7ynBpLeKYztQOxuwAAAFQ"]
[Tue Jul 21 08:16:50.440027 2026] [security2:error] [pid 411857:tid 412073] [client 198.54.129.60:41280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9VIi7ynBpLeKYztQOxuwAAAFQ"]
[Tue Jul 21 08:16:50.441839 2026] [security2:error] [pid 402041:tid 402094] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/firebase-adminsdk.json"] [unique_id "al9VIoiENNLP6XjiHQtzKwAB3zI"]
[Tue Jul 21 08:16:50.466551 2026] [security2:error] [pid 411857:tid 412044] [client 20.151.10.161:36514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/admin.php"] [unique_id "al9VIi7ynBpLeKYztQOxvAAAADc"]
[Tue Jul 21 08:16:50.566017 2026] [security2:error] [pid 411857:tid 412112] [client 20.151.10.161:13230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/ms-edit.php"] [unique_id "al9VIi7ynBpLeKYztQOxvQAAAHs"]
[Tue Jul 21 08:16:50.654583 2026] [authz_core:error] [pid 402041:tid 402063] [remote 34.155.146.79:34658] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Tue Jul 21 08:16:50.705476 2026] [security2:error] [pid 411857:tid 412062] [client 185.213.175.37:41826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.sinalogistica.com.br"] [uri "/"] [unique_id "al9VIi7ynBpLeKYztQOxwgAAAEk"]
[Tue Jul 21 08:16:50.705586 2026] [security2:error] [pid 411857:tid 412062] [client 185.213.175.37:41826] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.sinalogistica.com.br"] [uri "/"] [unique_id "al9VIi7ynBpLeKYztQOxwgAAAEk"]
[Tue Jul 21 08:16:50.751553 2026] [security2:error] [pid 402041:tid 402108] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/docker-compose.yaml"] [unique_id "al9VIoiENNLP6XjiHQtzPAABkUA"]
[Tue Jul 21 08:16:50.751709 2026] [security2:error] [pid 402041:tid 402089] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.svn/entries"] [unique_id "al9VIoiENNLP6XjiHQtzPQABkS0"]
[Tue Jul 21 08:16:50.751771 2026] [security2:error] [pid 402041:tid 402175] [client 34.155.146.79:34658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/docker-compose.yaml"] [unique_id "al9VIoiENNLP6XjiHQtzPAABkUA"]
[Tue Jul 21 08:16:50.839239 2026] [security2:error] [pid 402041:tid 402113] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.ssh/id_rsa"] [unique_id "al9VIoiENNLP6XjiHQtzQAAB60U"]
[Tue Jul 21 08:16:50.868166 2026] [security2:error] [pid 411857:tid 412059] [client 20.151.10.161:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/d62.php"] [unique_id "al9VIi7ynBpLeKYztQOxxgAAAEY"]
[Tue Jul 21 08:16:50.934292 2026] [security2:error] [pid 402041:tid 402149] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.ssh/id_dsa"] [unique_id "al9VIoiENNLP6XjiHQtzQwACDGk"]
[Tue Jul 21 08:16:50.977762 2026] [security2:error] [pid 402041:tid 402166] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/id_dsa"] [unique_id "al9VIoiENNLP6XjiHQtzTAAB53o"]
[Tue Jul 21 08:16:50.999705 2026] [security2:error] [pid 402041:tid 402145] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/id_rsa"] [unique_id "al9VIoiENNLP6XjiHQtzTwABvGU"]
[Tue Jul 21 08:16:51.202257 2026] [security2:error] [pid 402041:tid 402220] [client 20.151.10.161:13274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/222.php"] [unique_id "al9VI4iENNLP6XjiHQtzWwAAAb4"]
[Tue Jul 21 08:16:51.210399 2026] [security2:error] [pid 402041:tid 402139] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/key.pem"] [unique_id "al9VI4iENNLP6XjiHQtzXAABrV8"]
[Tue Jul 21 08:16:51.211312 2026] [security2:error] [pid 402041:tid 402126] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/privatekey.key"] [unique_id "al9VI4iENNLP6XjiHQtzXQABrVI"]
[Tue Jul 21 08:16:51.234255 2026] [security2:error] [pid 402041:tid 402136] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/private-key"] [unique_id "al9VI4iENNLP6XjiHQtzXgACClw"]
[Tue Jul 21 08:16:51.234399 2026] [security2:error] [pid 402041:tid 402296] [client 34.155.146.79:34658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/private-key"] [unique_id "al9VI4iENNLP6XjiHQtzXgACClw"]
[Tue Jul 21 08:16:51.313271 2026] [security2:error] [pid 411857:tid 412090] [client 62.102.148.158:48950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9VIy7ynBpLeKYztQOxygAAAGU"]
[Tue Jul 21 08:16:51.313349 2026] [security2:error] [pid 411857:tid 412090] [client 62.102.148.158:48950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9VIy7ynBpLeKYztQOxygAAAGU"]
[Tue Jul 21 08:16:51.410772 2026] [security2:error] [pid 402041:tid 402153] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9VI4iENNLP6XjiHQtzaQABxW0"]
[Tue Jul 21 08:16:51.435504 2026] [security2:error] [pid 402041:tid 402165] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/.continue/config.json"] [unique_id "al9VI4iENNLP6XjiHQtzbAABz3k"]
[Tue Jul 21 08:16:51.564032 2026] [security2:error] [pid 402041:tid 402067] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.hermes/.env"] [unique_id "al9VI4iENNLP6XjiHQtzdAABpRc"]
[Tue Jul 21 08:16:51.772827 2026] [security2:error] [pid 402041:tid 402167] [remote 217.182.128.41:41632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/wp-login.php"] [unique_id "al9VI4iENNLP6XjiHQtzgAABwns"]
[Tue Jul 21 08:16:51.866272 2026] [security2:error] [pid 402041:tid 402071] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.claude.json"] [unique_id "al9VI4iENNLP6XjiHQtzhgAB_xs"]
[Tue Jul 21 08:16:51.866398 2026] [security2:error] [pid 402041:tid 402285] [client 34.155.146.79:34658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/.claude.json"] [unique_id "al9VI4iENNLP6XjiHQtzhgAB_xs"]
[Tue Jul 21 08:16:51.955164 2026] [security2:error] [pid 402041:tid 402060] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "panel.gradiente.com"] [uri "/wp-config.php.bak"] [unique_id "al9VI4iENNLP6XjiHQtzigABpBA"]
[Tue Jul 21 08:16:51.963563 2026] [security2:error] [pid 402041:tid 402191] [client 20.151.10.161:13284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/cgi-bin/index.php"] [unique_id "al9VI4iENNLP6XjiHQtzjAAAAaE"]
[Tue Jul 21 08:16:51.981596 2026] [security2:error] [pid 402041:tid 402124] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "panel.gradiente.com"] [uri "/wp-config.php.old"] [unique_id "al9VI4iENNLP6XjiHQtzjQACCVA"]
[Tue Jul 21 08:16:52.079186 2026] [security2:error] [pid 411857:tid 412077] [client 152.59.34.51:64449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VJC7ynBpLeKYztQOx0gAAAFg"]
[Tue Jul 21 08:16:52.079348 2026] [security2:error] [pid 411857:tid 412077] [client 152.59.34.51:64449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VJC7ynBpLeKYztQOx0gAAAFg"]
[Tue Jul 21 08:16:52.161238 2026] [security2:error] [pid 411857:tid 412006] [client 65.21.113.253:56106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VIy7ynBpLeKYztQOxzgAAABE"]
[Tue Jul 21 08:16:52.210256 2026] [security2:error] [pid 402041:tid 402053] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/.env.php.bak"] [unique_id "al9VJIiENNLP6XjiHQtznwABwQk"]
[Tue Jul 21 08:16:52.255042 2026] [security2:error] [pid 402041:tid 402065] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/laravel/.env"] [unique_id "al9VJIiENNLP6XjiHQtzogABwRU"]
[Tue Jul 21 08:16:52.301295 2026] [security2:error] [pid 402041:tid 402084] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/configuration.php.bak"] [unique_id "al9VJIiENNLP6XjiHQtzpAABwSg"]
[Tue Jul 21 08:16:52.302578 2026] [security2:error] [pid 402041:tid 402070] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/core/.env"] [unique_id "al9VJIiENNLP6XjiHQtzpQABwRo"]
[Tue Jul 21 08:16:52.304790 2026] [security2:error] [pid 411857:tid 412027] [client 20.151.10.161:36558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/aa2.php"] [unique_id "al9VJC7ynBpLeKYztQOx1AAAACY"]
[Tue Jul 21 08:16:52.332908 2026] [security2:error] [pid 402041:tid 402122] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/config/.env.php"] [unique_id "al9VJIiENNLP6XjiHQtznAABwU4"]
[Tue Jul 21 08:16:52.369255 2026] [security2:error] [pid 402041:tid 402061] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/.env.dev"] [unique_id "al9VJIiENNLP6XjiHQtzqQAB9xE"]
[Tue Jul 21 08:16:52.369424 2026] [security2:error] [pid 402041:tid 402277] [client 34.155.146.79:34658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/.env.dev"] [unique_id "al9VJIiENNLP6XjiHQtzqQAB9xE"]
[Tue Jul 21 08:16:52.382471 2026] [security2:error] [pid 402041:tid 402057] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/config.php.bak"] [unique_id "al9VJIiENNLP6XjiHQtzqgABzQ0"]
[Tue Jul 21 08:16:52.404022 2026] [security2:error] [pid 402041:tid 402111] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.swp"] [unique_id "al9VJIiENNLP6XjiHQtzrAAB8EM"]
[Tue Jul 21 08:16:52.421940 2026] [security2:error] [pid 402041:tid 402066] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/public/.env"] [unique_id "al9VJIiENNLP6XjiHQtzrQAB7xY"]
[Tue Jul 21 08:16:52.431683 2026] [security2:error] [pid 402041:tid 402078] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/web/.env"] [unique_id "al9VJIiENNLP6XjiHQtzrgAB5CI"]
[Tue Jul 21 08:16:52.600975 2026] [security2:error] [pid 402041:tid 402185] [client 20.151.10.161:46035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/ups.php"] [unique_id "al9VJIiENNLP6XjiHQtzugAAAZs"]
[Tue Jul 21 08:16:52.658585 2026] [security2:error] [pid 402041:tid 402116] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/appsettings.json"] [unique_id "al9VJIiENNLP6XjiHQtzvwABq0g"]
[Tue Jul 21 08:16:52.708514 2026] [security2:error] [pid 402041:tid 402202] [client 20.206.105.145:25481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/xmu.php"] [unique_id "al9VJIiENNLP6XjiHQtzxQAAAaw"]
[Tue Jul 21 08:16:52.828209 2026] [proxy:error] [pid 402041:tid 402234] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:52.828282 2026] [proxy_http:error] [pid 402041:tid 402234] [client 20.151.10.161:13200] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:52.828717 2026] [proxy:error] [pid 402041:tid 402234] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:52.828746 2026] [proxy_http:error] [pid 402041:tid 402234] [client 20.151.10.161:13200] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:52.899324 2026] [security2:error] [pid 402041:tid 402051] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/web.config"] [unique_id "al9VJIiENNLP6XjiHQtz1AABxQc"]
[Tue Jul 21 08:16:53.067419 2026] [security2:error] [pid 402041:tid 402293] [client 20.197.192.193:62424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/berlin.php"] [unique_id "al9VJYiENNLP6XjiHQtz3gAAAgc"]
[Tue Jul 21 08:16:53.184880 2026] [security2:error] [pid 402041:tid 402231] [client 38.100.221.102:17445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VJYiENNLP6XjiHQtz6QAAAck"]
[Tue Jul 21 08:16:53.185022 2026] [security2:error] [pid 402041:tid 402231] [client 38.100.221.102:17445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VJYiENNLP6XjiHQtz6QAAAck"]
[Tue Jul 21 08:16:53.282451 2026] [security2:error] [pid 402041:tid 402177] [client 74.7.244.26:36910] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "colegioperseveranca.com"] [uri "/index.php"] [unique_id "al9VJYiENNLP6XjiHQtz5QABky4"]
[Tue Jul 21 08:16:53.407205 2026] [security2:error] [pid 402041:tid 402118] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VJYiENNLP6XjiHQtz_QABtko"]
[Tue Jul 21 08:16:53.407374 2026] [security2:error] [pid 402041:tid 402212] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VJYiENNLP6XjiHQtz_QABtko"]
[Tue Jul 21 08:16:53.528085 2026] [security2:error] [pid 402041:tid 402151] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/app/.env"] [unique_id "al9VJYiENNLP6XjiHQt0AAABo2s"]
[Tue Jul 21 08:16:53.588780 2026] [security2:error] [pid 402041:tid 402153] [remote 5.252.52.249:54810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9VJYiENNLP6XjiHQt0AQABt20"]
[Tue Jul 21 08:16:53.630121 2026] [security2:error] [pid 402041:tid 402077] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.production.bak"] [unique_id "al9VJYiENNLP6XjiHQt0BQACACE"]
[Tue Jul 21 08:16:53.632884 2026] [security2:error] [pid 402041:tid 402133] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/docker/.env"] [unique_id "al9VJYiENNLP6XjiHQt0BgABl1k"]
[Tue Jul 21 08:16:53.653537 2026] [security2:error] [pid 402041:tid 402198] [client 20.151.10.161:13217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/BDKR28WP.php"] [unique_id "al9VJYiENNLP6XjiHQt0BwAAAag"]
[Tue Jul 21 08:16:53.694147 2026] [security2:error] [pid 402041:tid 402059] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/staging/.env"] [unique_id "al9VJYiENNLP6XjiHQt0CAABtQ8"]
[Tue Jul 21 08:16:53.698114 2026] [security2:error] [pid 402041:tid 402165] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/production/.env"] [unique_id "al9VJYiENNLP6XjiHQt0CQABsXk"]
[Tue Jul 21 08:16:53.699755 2026] [security2:error] [pid 402041:tid 402100] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/dev/.env"] [unique_id "al9VJYiENNLP6XjiHQt0CgABsTg"]
[Tue Jul 21 08:16:53.699779 2026] [security2:error] [pid 402041:tid 402152] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/server/.env"] [unique_id "al9VJYiENNLP6XjiHQt0DAABsWw"]
[Tue Jul 21 08:16:53.699832 2026] [security2:error] [pid 402041:tid 402062] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/src/.env"] [unique_id "al9VJYiENNLP6XjiHQt0CwABsRI"]
[Tue Jul 21 08:16:53.700908 2026] [security2:error] [pid 402041:tid 402045] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/.env.prod.bak"] [unique_id "al9VJYiENNLP6XjiHQt0DQABsQE"]
[Tue Jul 21 08:16:53.710723 2026] [security2:error] [pid 402041:tid 402067] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/frontend/.env"] [unique_id "al9VJYiENNLP6XjiHQt0DwABmhc"]
[Tue Jul 21 08:16:53.718271 2026] [security2:error] [pid 402041:tid 402171] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VJYiENNLP6XjiHQt0EAABwX8"]
[Tue Jul 21 08:16:53.718372 2026] [security2:error] [pid 402041:tid 402223] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VJYiENNLP6XjiHQt0EAABwX8"]
[Tue Jul 21 08:16:53.723705 2026] [security2:error] [pid 402041:tid 402069] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/@fs/.env"] [unique_id "al9VJYiENNLP6XjiHQt0EQAB3xk"]
[Tue Jul 21 08:16:53.723802 2026] [security2:error] [pid 402041:tid 402253] [client 34.155.146.79:34658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/@fs/.env"] [unique_id "al9VJYiENNLP6XjiHQt0EQAB3xk"]
[Tue Jul 21 08:16:53.796973 2026] [security2:error] [pid 411857:tid 412021] [client 74.249.245.134:15372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/w.php"] [unique_id "al9VJS7ynBpLeKYztQOx4AAAACA"]
[Tue Jul 21 08:16:53.860102 2026] [security2:error] [pid 402041:tid 402064] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/@fs/root/.env"] [unique_id "al9VJYiENNLP6XjiHQt0FAAB7xQ"]
[Tue Jul 21 08:16:53.871025 2026] [security2:error] [pid 402041:tid 402105] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/gcp-credentials.json"] [unique_id "al9VJYiENNLP6XjiHQt0FgABnD0"]
[Tue Jul 21 08:16:53.871216 2026] [security2:error] [pid 402041:tid 402186] [client 34.155.146.79:34658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/gcp-credentials.json"] [unique_id "al9VJYiENNLP6XjiHQt0FgABnD0"]
[Tue Jul 21 08:16:53.889599 2026] [security2:error] [pid 402041:tid 402130] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/@fs/proc/self/environ"] [unique_id "al9VJYiENNLP6XjiHQt0FwAB6VY"]
[Tue Jul 21 08:16:53.889735 2026] [security2:error] [pid 402041:tid 402263] [client 34.155.146.79:34658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/@fs/proc/self/environ"] [unique_id "al9VJYiENNLP6XjiHQt0FwAB6VY"]
[Tue Jul 21 08:16:53.905088 2026] [security2:error] [pid 411857:tid 412016] [client 20.197.192.193:63932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/mac.php"] [unique_id "al9VJS7ynBpLeKYztQOx4QAAABs"]
[Tue Jul 21 08:16:53.941043 2026] [security2:error] [pid 402041:tid 402107] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/config/firebase-admin.json"] [unique_id "al9VJYiENNLP6XjiHQt0GwABnj8"]
[Tue Jul 21 08:16:53.963636 2026] [security2:error] [pid 402041:tid 402239] [client 154.208.47.43:55766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VJYiENNLP6XjiHQt0IQAAAdE"]
[Tue Jul 21 08:16:53.963767 2026] [security2:error] [pid 402041:tid 402239] [client 154.208.47.43:55766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VJYiENNLP6XjiHQt0IQAAAdE"]
[Tue Jul 21 08:16:54.111075 2026] [security2:error] [pid 402041:tid 402060] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/__/firebase/init.json"] [unique_id "al9VJoiENNLP6XjiHQt0JgAB5xA"]
[Tue Jul 21 08:16:54.126580 2026] [proxy:error] [pid 411857:tid 411991] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:54.126674 2026] [proxy_http:error] [pid 411857:tid 411991] [client 20.151.10.161:13193] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:54.127354 2026] [proxy:error] [pid 411857:tid 411991] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:54.127403 2026] [proxy_http:error] [pid 411857:tid 411991] [client 20.151.10.161:13193] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:54.205853 2026] [security2:error] [pid 402041:tid 402191] [client 103.78.200.11:61128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VJoiENNLP6XjiHQt0MgAAAaE"]
[Tue Jul 21 08:16:54.207095 2026] [security2:error] [pid 402041:tid 402191] [client 103.78.200.11:61128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VJoiENNLP6XjiHQt0MgAAAaE"]
[Tue Jul 21 08:16:54.215842 2026] [security2:error] [pid 411857:tid 412104] [client 65.21.113.253:56106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VJS7ynBpLeKYztQOx3gAAAHM"]
[Tue Jul 21 08:16:54.351639 2026] [security2:error] [pid 402041:tid 402251] [client 103.151.46.103:49935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VJoiENNLP6XjiHQt0NwAAAd0"]
[Tue Jul 21 08:16:54.351782 2026] [security2:error] [pid 402041:tid 402251] [client 103.151.46.103:49935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VJoiENNLP6XjiHQt0NwAAAd0"]
[Tue Jul 21 08:16:54.365415 2026] [security2:error] [pid 411857:tid 412091] [client 20.206.105.145:25509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9VJi7ynBpLeKYztQOx5wAAAGY"]
[Tue Jul 21 08:16:54.426904 2026] [security2:error] [pid 402041:tid 402061] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/.well-known/jwks.json"] [unique_id "al9VJoiENNLP6XjiHQt0QQABrRE"]
[Tue Jul 21 08:16:54.530249 2026] [security2:error] [pid 411857:tid 412089] [client 20.197.192.193:63887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/samll.php"] [unique_id "al9VJi7ynBpLeKYztQOx6QAAAGQ"]
[Tue Jul 21 08:16:54.586140 2026] [security2:error] [pid 402041:tid 402078] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/api/env"] [unique_id "al9VJoiENNLP6XjiHQt0RQABpiI"]
[Tue Jul 21 08:16:54.703659 2026] [security2:error] [pid 402041:tid 402195] [client 20.197.192.193:61098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/abcd.php"] [unique_id "al9VJoiENNLP6XjiHQt0UgAAAaU"]
[Tue Jul 21 08:16:54.733894 2026] [security2:error] [pid 402041:tid 402099] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/manifest.webmanifest"] [unique_id "al9VJoiENNLP6XjiHQt0UwAB0Dc"]
[Tue Jul 21 08:16:54.771483 2026] [security2:error] [pid 402041:tid 402266] [client 20.197.192.193:63913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/xyn.php"] [unique_id "al9VJoiENNLP6XjiHQt0VAAAAew"]
[Tue Jul 21 08:16:54.788683 2026] [security2:error] [pid 402041:tid 402208] [client 20.151.10.161:36510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/ccou.php"] [unique_id "al9VJoiENNLP6XjiHQt0VQAAAbI"]
[Tue Jul 21 08:16:54.826888 2026] [security2:error] [pid 402041:tid 402116] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/openapi.json"] [unique_id "al9VJoiENNLP6XjiHQt0XAACDUg"]
[Tue Jul 21 08:16:54.828379 2026] [proxy:error] [pid 402041:tid 402222] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:54.828481 2026] [proxy_http:error] [pid 402041:tid 402222] [client 20.151.10.161:13279] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:54.829197 2026] [proxy:error] [pid 402041:tid 402222] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:54.829251 2026] [proxy_http:error] [pid 402041:tid 402222] [client 20.151.10.161:13279] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:54.933676 2026] [security2:error] [pid 402041:tid 402095] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/health"] [unique_id "al9VJoiENNLP6XjiHQt0ZAAB1TM"]
[Tue Jul 21 08:16:54.984738 2026] [security2:error] [pid 411857:tid 412010] [client 20.197.192.193:63908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/byp8.php"] [unique_id "al9VJi7ynBpLeKYztQOx7AAAABU"]
[Tue Jul 21 08:16:55.055759 2026] [security2:error] [pid 402041:tid 402051] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/graphql"] [unique_id "al9VJ4iENNLP6XjiHQt0aAABogc"]
[Tue Jul 21 08:16:55.081540 2026] [security2:error] [pid 411857:tid 411964] [remote 119.195.102.159:59818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9VJy7ynBpLeKYztQOx7QAAI2g"]
[Tue Jul 21 08:16:55.081685 2026] [security2:error] [pid 411857:tid 412024] [client 119.195.102.159:59818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9VJy7ynBpLeKYztQOx7QAAI2g"]
[Tue Jul 21 08:16:55.094547 2026] [security2:error] [pid 411857:tid 412109] [client 20.151.10.161:46063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/k.php"] [unique_id "al9VJy7ynBpLeKYztQOx7gAAAHg"]
[Tue Jul 21 08:16:55.153271 2026] [security2:error] [pid 411857:tid 412070] [client 20.197.192.193:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/user.php"] [unique_id "al9VJy7ynBpLeKYztQOx8AAAAFE"]
[Tue Jul 21 08:16:55.172706 2026] [security2:error] [pid 402041:tid 402098] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/v1/graphql"] [unique_id "al9VJ4iENNLP6XjiHQt0cwABozY"]
[Tue Jul 21 08:16:55.191244 2026] [security2:error] [pid 402041:tid 402279] [client 20.151.10.161:13233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/raw.php"] [unique_id "al9VJ4iENNLP6XjiHQt0dAAAAfk"]
[Tue Jul 21 08:16:55.201806 2026] [security2:error] [pid 411857:tid 411989] [client 102.206.115.33:59891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VJy7ynBpLeKYztQOx8QAAAAA"]
[Tue Jul 21 08:16:55.202004 2026] [security2:error] [pid 411857:tid 411989] [client 102.206.115.33:59891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VJy7ynBpLeKYztQOx8QAAAAA"]
[Tue Jul 21 08:16:55.253916 2026] [security2:error] [pid 411857:tid 412074] [client 20.197.192.193:61096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/ops.php"] [unique_id "al9VJy7ynBpLeKYztQOx8gAAAFU"]
[Tue Jul 21 08:16:55.345439 2026] [security2:error] [pid 402041:tid 402289] [client 87.116.180.198:27357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VJ4iENNLP6XjiHQt0dwAAAgM"]
[Tue Jul 21 08:16:55.345586 2026] [security2:error] [pid 402041:tid 402289] [client 87.116.180.198:27357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VJ4iENNLP6XjiHQt0dwAAAgM"]
[Tue Jul 21 08:16:55.353907 2026] [security2:error] [pid 402041:tid 402198] [client 20.197.192.193:61091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/term.php"] [unique_id "al9VJ4iENNLP6XjiHQt0eQAAAag"]
[Tue Jul 21 08:16:55.477599 2026] [security2:error] [pid 402041:tid 402162] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/info.php"] [unique_id "al9VJ4iENNLP6XjiHQt0fgABwXY"]
[Tue Jul 21 08:16:55.478076 2026] [security2:error] [pid 402041:tid 402093] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/test.php"] [unique_id "al9VJ4iENNLP6XjiHQt0fwABwTE"]
[Tue Jul 21 08:16:55.479702 2026] [security2:error] [pid 402041:tid 402142] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/i.php"] [unique_id "al9VJ4iENNLP6XjiHQt0ggABwWI"]
[Tue Jul 21 08:16:55.483276 2026] [security2:error] [pid 402041:tid 402089] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/phpinfo.php"] [unique_id "al9VJ4iENNLP6XjiHQt0hAABwS0"]
[Tue Jul 21 08:16:55.516670 2026] [security2:error] [pid 402041:tid 402083] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/pi.php"] [unique_id "al9VJ4iENNLP6XjiHQt0iAABzSc"]
[Tue Jul 21 08:16:55.516854 2026] [security2:error] [pid 402041:tid 402235] [client 34.155.146.79:34658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/pi.php"] [unique_id "al9VJ4iENNLP6XjiHQt0iAABzSc"]
[Tue Jul 21 08:16:55.656822 2026] [security2:error] [pid 402041:tid 402256] [client 20.151.10.161:13276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/abcd.php"] [unique_id "al9VJ4iENNLP6XjiHQt0jAAAAeI"]
[Tue Jul 21 08:16:55.711844 2026] [security2:error] [pid 402041:tid 402047] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/app_dev.php"] [unique_id "al9VJ4iENNLP6XjiHQt0kgAB6wM"]
[Tue Jul 21 08:16:55.713182 2026] [security2:error] [pid 402041:tid 402141] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.gradiente.com"] [uri "/app_dev.php/_profiler"] [unique_id "al9VJ4iENNLP6XjiHQt0lgAB62E"]
[Tue Jul 21 08:16:55.713997 2026] [security2:error] [pid 402041:tid 402153] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.gradiente.com"] [uri "/_debugbar/open"] [unique_id "al9VJ4iENNLP6XjiHQt0lQAB620"]
[Tue Jul 21 08:16:55.763719 2026] [security2:error] [pid 402041:tid 402263] [client 187.125.243.197:52599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VJ4iENNLP6XjiHQt0mAAAAek"]
[Tue Jul 21 08:16:55.763884 2026] [security2:error] [pid 402041:tid 402263] [client 187.125.243.197:52599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VJ4iENNLP6XjiHQt0mAAAAek"]
[Tue Jul 21 08:16:55.799252 2026] [security2:error] [pid 411857:tid 412077] [client 20.197.192.193:63901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/ah25.php"] [unique_id "al9VJy7ynBpLeKYztQOx-wAAAFg"]
[Tue Jul 21 08:16:55.871435 2026] [security2:error] [pid 402041:tid 402133] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.gradiente.com"] [uri "/elmah.axd"] [unique_id "al9VJ4iENNLP6XjiHQt0mgABq1k"]
[Tue Jul 21 08:16:55.878019 2026] [security2:error] [pid 411857:tid 412056] [client 65.21.113.253:56106] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VJy7ynBpLeKYztQOx-AAAAEM"]
[Tue Jul 21 08:16:55.882739 2026] [security2:error] [pid 402041:tid 402087] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/trace.axd"] [unique_id "al9VJ4iENNLP6XjiHQt0mwAB1ys"]
[Tue Jul 21 08:16:56.010966 2026] [security2:error] [pid 402041:tid 402171] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/nginx_status"] [unique_id "al9VKIiENNLP6XjiHQt0pgABrH8"]
[Tue Jul 21 08:16:56.011156 2026] [security2:error] [pid 402041:tid 402202] [client 34.155.146.79:34658] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.gradiente.com"] [uri "/nginx_status"] [unique_id "al9VKIiENNLP6XjiHQt0pgABrH8"]
[Tue Jul 21 08:16:56.019672 2026] [security2:error] [pid 402041:tid 402064] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.gradiente.com"] [uri "/wp-json"] [unique_id "al9VKIiENNLP6XjiHQt0qQABrBQ"]
[Tue Jul 21 08:16:56.021174 2026] [access_compat:error] [pid 402041:tid 402100] [remote 34.155.146.79:34658] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 08:16:56.089792 2026] [security2:error] [pid 402041:tid 402130] [remote 34.155.146.79:34658] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "panel.gradiente.com"] [uri "/server-info"] [unique_id "al9VKIiENNLP6XjiHQt0rAACClY"]
[Tue Jul 21 08:16:56.100528 2026] [security2:error] [pid 411857:tid 412050] [client 20.151.10.161:13130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/a1.php"] [unique_id "al9VKC7ynBpLeKYztQOx_gAAAD0"]
[Tue Jul 21 08:16:56.134217 2026] [security2:error] [pid 411857:tid 412048] [client 103.106.20.201:60317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VKC7ynBpLeKYztQOx_wAAADs"]
[Tue Jul 21 08:16:56.134306 2026] [security2:error] [pid 411857:tid 412048] [client 103.106.20.201:60317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VKC7ynBpLeKYztQOx_wAAADs"]
[Tue Jul 21 08:16:56.334890 2026] [security2:error] [pid 411857:tid 412114] [client 20.197.192.193:61119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/8.php"] [unique_id "al9VKC7ynBpLeKYztQOyAgAAAH0"]
[Tue Jul 21 08:16:56.623692 2026] [security2:error] [pid 402041:tid 402124] [remote 173.252.82.20:46878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9VKIiENNLP6XjiHQt0vwABxVA"]
[Tue Jul 21 08:16:56.667565 2026] [security2:error] [pid 411857:tid 412041] [client 20.197.192.193:61109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/red.php"] [unique_id "al9VKC7ynBpLeKYztQOyBgAAADQ"]
[Tue Jul 21 08:16:56.675291 2026] [security2:error] [pid 411857:tid 411994] [client 115.134.11.136:57467] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VKC7ynBpLeKYztQOyBwAAAAU"]
[Tue Jul 21 08:16:56.675408 2026] [security2:error] [pid 411857:tid 411994] [client 115.134.11.136:57467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VKC7ynBpLeKYztQOyBwAAAAU"]
[Tue Jul 21 08:16:56.688338 2026] [security2:error] [pid 402041:tid 402132] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VKIiENNLP6XjiHQt0yQAB1Vg"]
[Tue Jul 21 08:16:56.688540 2026] [security2:error] [pid 402041:tid 402243] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VKIiENNLP6XjiHQt0yQAB1Vg"]
[Tue Jul 21 08:16:56.696056 2026] [security2:error] [pid 402041:tid 402272] [client 14.245.224.124:61947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VKIiENNLP6XjiHQt0ygAAAfI"]
[Tue Jul 21 08:16:56.696209 2026] [security2:error] [pid 402041:tid 402272] [client 14.245.224.124:61947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VKIiENNLP6XjiHQt0ygAAAfI"]
[Tue Jul 21 08:16:56.719287 2026] [security2:error] [pid 402041:tid 402204] [client 65.21.113.253:58748] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VKIiENNLP6XjiHQt0swAAAa4"]
[Tue Jul 21 08:16:56.877132 2026] [security2:error] [pid 402041:tid 402180] [client 20.197.192.193:61112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/fffm.php"] [unique_id "al9VKIiENNLP6XjiHQt0zwAAAZY"]
[Tue Jul 21 08:16:56.892557 2026] [security2:error] [pid 402041:tid 402282] [client 62.102.148.158:48964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9VKIiENNLP6XjiHQt00AAAAfw"]
[Tue Jul 21 08:16:56.892668 2026] [security2:error] [pid 402041:tid 402282] [client 62.102.148.158:48964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9VKIiENNLP6XjiHQt00AAAAfw"]
[Tue Jul 21 08:16:56.903115 2026] [security2:error] [pid 402041:tid 402212] [client 20.151.10.161:13216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9VKIiENNLP6XjiHQt00QAAAbY"]
[Tue Jul 21 08:16:57.084419 2026] [security2:error] [pid 411857:tid 412045] [client 20.197.192.193:61073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/ftde.php"] [unique_id "al9VKS7ynBpLeKYztQOyEAAAADg"]
[Tue Jul 21 08:16:57.090845 2026] [security2:error] [pid 402041:tid 402277] [client 20.151.10.161:45967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/k2.php"] [unique_id "al9VKYiENNLP6XjiHQt04wAAAfc"]
[Tue Jul 21 08:16:57.191835 2026] [security2:error] [pid 411857:tid 412103] [client 20.197.192.193:63872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/yup.php"] [unique_id "al9VKS7ynBpLeKYztQOyEwAAAHI"]
[Tue Jul 21 08:16:57.364361 2026] [security2:error] [pid 402041:tid 402200] [client 74.249.245.134:15394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/wp-good.php"] [unique_id "al9VKYiENNLP6XjiHQt07wAAAao"]
[Tue Jul 21 08:16:57.487181 2026] [security2:error] [pid 411857:tid 412076] [client 20.151.10.161:13305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9VKS7ynBpLeKYztQOyFQAAAFc"]
[Tue Jul 21 08:16:57.565888 2026] [security2:error] [pid 402041:tid 402054] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VKYiENNLP6XjiHQt09gABqwo"]
[Tue Jul 21 08:16:57.566036 2026] [security2:error] [pid 402041:tid 402201] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VKYiENNLP6XjiHQt09gABqwo"]
[Tue Jul 21 08:16:57.608529 2026] [security2:error] [pid 411857:tid 412066] [client 20.197.192.193:63915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/jj.php"] [unique_id "al9VKS7ynBpLeKYztQOyFgAAAE0"]
[Tue Jul 21 08:16:57.647772 2026] [security2:error] [pid 411857:tid 412082] [client 20.151.10.161:45987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/k3.php"] [unique_id "al9VKS7ynBpLeKYztQOyFwAAAF0"]
[Tue Jul 21 08:16:57.650340 2026] [security2:error] [pid 402041:tid 402241] [client 125.18.144.2:35043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VKYiENNLP6XjiHQt0-AAAAdM"]
[Tue Jul 21 08:16:57.650430 2026] [security2:error] [pid 402041:tid 402241] [client 125.18.144.2:35043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VKYiENNLP6XjiHQt0-AAAAdM"]
[Tue Jul 21 08:16:57.734101 2026] [security2:error] [pid 411857:tid 412063] [client 20.220.225.223:58935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/ah25.php"] [unique_id "al9VKS7ynBpLeKYztQOyGQAAAEo"]
[Tue Jul 21 08:16:57.786507 2026] [security2:error] [pid 411857:tid 411977] [remote 57.141.18.83:47116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemaph.xml"] [unique_id "al9VKS7ynBpLeKYztQOyGwAAAXU"]
[Tue Jul 21 08:16:57.985524 2026] [security2:error] [pid 402041:tid 402177] [client 20.151.10.161:36603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/dr.php"] [unique_id "al9VKYiENNLP6XjiHQt0_wAAAZM"]
[Tue Jul 21 08:16:58.056585 2026] [security2:error] [pid 402041:tid 402275] [client 20.151.10.161:13231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wp-content/BypassBest.php"] [unique_id "al9VKoiENNLP6XjiHQt1AwAAAfU"]
[Tue Jul 21 08:16:58.104702 2026] [security2:error] [pid 411857:tid 412112] [client 20.151.10.161:46061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/k4.php"] [unique_id "al9VKi7ynBpLeKYztQOyHAAAAHs"]
[Tue Jul 21 08:16:58.188150 2026] [security2:error] [pid 411857:tid 412105] [client 20.197.192.193:63879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/dragonshell.php"] [unique_id "al9VKi7ynBpLeKYztQOyHgAAAHQ"]
[Tue Jul 21 08:16:58.289152 2026] [security2:error] [pid 411857:tid 412062] [client 20.206.105.145:25538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/puc.php"] [unique_id "al9VKi7ynBpLeKYztQOyIQAAAEk"]
[Tue Jul 21 08:16:58.575165 2026] [security2:error] [pid 411857:tid 412051] [client 20.151.10.161:46022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/k5.php"] [unique_id "al9VKi7ynBpLeKYztQOyKQAAAD4"]
[Tue Jul 21 08:16:58.627175 2026] [security2:error] [pid 402041:tid 402155] [remote 81.173.115.7:44318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moadvogadas.com.br"] [uri "/wp-login.php"] [unique_id "al9VKoiENNLP6XjiHQt1CQABom8"]
[Tue Jul 21 08:16:58.710635 2026] [proxy:error] [pid 411857:tid 412011] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:58.710713 2026] [proxy_http:error] [pid 411857:tid 412011] [client 20.151.10.161:13121] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:58.711158 2026] [proxy:error] [pid 411857:tid 412011] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:58.711185 2026] [proxy_http:error] [pid 411857:tid 412011] [client 20.151.10.161:13121] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:58.735963 2026] [proxy:error] [pid 411857:tid 412087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:58.736019 2026] [proxy_http:error] [pid 411857:tid 412087] [client 143.244.57.88:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:58.736493 2026] [proxy:error] [pid 411857:tid 412087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:58.736517 2026] [proxy_http:error] [pid 411857:tid 412087] [client 143.244.57.88:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:58.764729 2026] [security2:error] [pid 402041:tid 402213] [client 20.197.192.193:63896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/wp-mt.php"] [unique_id "al9VKoiENNLP6XjiHQt1DAAAAbc"]
[Tue Jul 21 08:16:58.968160 2026] [security2:error] [pid 402041:tid 402259] [client 62.102.148.158:56466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9VKoiENNLP6XjiHQt1DgAAAeU"]
[Tue Jul 21 08:16:58.968301 2026] [security2:error] [pid 402041:tid 402259] [client 62.102.148.158:56466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9VKoiENNLP6XjiHQt1DgAAAeU"]
[Tue Jul 21 08:16:59.018624 2026] [proxy:error] [pid 411857:tid 412056] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:59.018707 2026] [proxy_http:error] [pid 411857:tid 412056] [client 143.244.57.88:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:59.019631 2026] [proxy:error] [pid 411857:tid 412056] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:59.019684 2026] [proxy_http:error] [pid 411857:tid 412056] [client 143.244.57.88:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:59.144513 2026] [security2:error] [pid 402041:tid 402218] [client 216.244.66.228:41340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lucaskotovicz.com"] [uri "/"] [unique_id "al9VK4iENNLP6XjiHQt1FAAAAbw"]
[Tue Jul 21 08:16:59.144631 2026] [security2:error] [pid 402041:tid 402218] [client 216.244.66.228:41340] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lucaskotovicz.com"] [uri "/"] [unique_id "al9VK4iENNLP6XjiHQt1FAAAAbw"]
[Tue Jul 21 08:16:59.145169 2026] [security2:error] [pid 402041:tid 402256] [client 20.151.10.161:46038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/w.php"] [unique_id "al9VK4iENNLP6XjiHQt1FQAAAeI"]
[Tue Jul 21 08:16:59.232610 2026] [security2:error] [pid 411857:tid 412048] [client 20.197.192.193:48734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/billur.php"] [unique_id "al9VKy7ynBpLeKYztQOyMgAAADs"]
[Tue Jul 21 08:16:59.270677 2026] [security2:error] [pid 411857:tid 412006] [client 20.151.10.161:13201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/simple.php"] [unique_id "al9VKy7ynBpLeKYztQOyMwAAABE"]
[Tue Jul 21 08:16:59.301045 2026] [security2:error] [pid 402041:tid 402292] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9VK4iENNLP6XjiHQt1GQAAAgY"]
[Tue Jul 21 08:16:59.539822 2026] [security2:error] [pid 402041:tid 402263] [client 20.151.10.161:36536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/xamp.php"] [unique_id "al9VK4iENNLP6XjiHQt1HQAAAek"]
[Tue Jul 21 08:16:59.550056 2026] [security2:error] [pid 402041:tid 402271] [client 20.197.192.193:47336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/ww.php"] [unique_id "al9VK4iENNLP6XjiHQt1HwAAAfE"]
[Tue Jul 21 08:16:59.592586 2026] [security2:error] [pid 411857:tid 412079] [client 143.244.57.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VKy7ynBpLeKYztQOyNQAAAFo"]
[Tue Jul 21 08:16:59.625542 2026] [security2:error] [pid 411857:tid 412054] [client 150.129.202.39:64742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VKy7ynBpLeKYztQOyNwAAAEE"]
[Tue Jul 21 08:16:59.625689 2026] [security2:error] [pid 411857:tid 412054] [client 150.129.202.39:64742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VKy7ynBpLeKYztQOyNwAAAEE"]
[Tue Jul 21 08:16:59.670111 2026] [security2:error] [pid 402041:tid 402137] [remote 45.178.80.57:49744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "alperembalagens.com.br"] [uri "/"] [unique_id "al9VK4iENNLP6XjiHQt1IQABzV0"]
[Tue Jul 21 08:16:59.788955 2026] [security2:error] [pid 402041:tid 402189] [client 20.151.10.161:46048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/fpwch.php"] [unique_id "al9VK4iENNLP6XjiHQt1JAAAAZ8"]
[Tue Jul 21 08:16:59.874675 2026] [proxy:error] [pid 411857:tid 412035] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:59.874765 2026] [proxy_http:error] [pid 411857:tid 412035] [client 143.244.57.88:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:59.875404 2026] [proxy:error] [pid 411857:tid 412035] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:16:59.875441 2026] [proxy_http:error] [pid 411857:tid 412035] [client 143.244.57.88:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:16:59.924485 2026] [security2:error] [pid 411857:tid 412027] [client 120.56.162.40:52460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VKy7ynBpLeKYztQOyPAAAACY"]
[Tue Jul 21 08:16:59.924631 2026] [security2:error] [pid 411857:tid 412027] [client 120.56.162.40:52460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VKy7ynBpLeKYztQOyPAAAACY"]
[Tue Jul 21 08:17:00.113281 2026] [security2:error] [pid 411857:tid 412102] [client 20.151.10.161:13278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/xxx.php"] [unique_id "al9VLC7ynBpLeKYztQOyPgAAAHE"]
[Tue Jul 21 08:17:00.157967 2026] [security2:error] [pid 411857:tid 412042] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9VLC7ynBpLeKYztQOyQAAAADU"]
[Tue Jul 21 08:17:00.163261 2026] [security2:error] [pid 411857:tid 412018] [client 117.210.135.0:60887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VLC7ynBpLeKYztQOyQQAAAB0"]
[Tue Jul 21 08:17:00.163393 2026] [security2:error] [pid 411857:tid 412018] [client 117.210.135.0:60887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VLC7ynBpLeKYztQOyQQAAAB0"]
[Tue Jul 21 08:17:00.281022 2026] [security2:error] [pid 411857:tid 411993] [client 20.197.192.193:63919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/cron.php"] [unique_id "al9VLC7ynBpLeKYztQOyQgAAAAQ"]
[Tue Jul 21 08:17:00.312819 2026] [security2:error] [pid 411857:tid 412110] [client 20.151.10.161:36485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/bless.php"] [unique_id "al9VLC7ynBpLeKYztQOyQwAAAHk"]
[Tue Jul 21 08:17:00.352959 2026] [security2:error] [pid 411857:tid 412001] [client 20.151.10.161:46051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/w2025.php"] [unique_id "al9VLC7ynBpLeKYztQOyRAAAAAw"]
[Tue Jul 21 08:17:00.441526 2026] [security2:error] [pid 411857:tid 412096] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9VLC7ynBpLeKYztQOyRQAAAGs"]
[Tue Jul 21 08:17:00.478985 2026] [autoindex:error] [pid 411857:tid 412007] [client 35.252.209.37:0] AH01276: Cannot serve directory /home1/asse7722/blog.findcomp.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:00.587302 2026] [security2:error] [pid 411857:tid 412099] [client 20.151.10.161:13124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/hypo.php"] [unique_id "al9VLC7ynBpLeKYztQOySgAAAG4"]
[Tue Jul 21 08:17:00.631878 2026] [security2:error] [pid 411857:tid 411987] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VLC7ynBpLeKYztQOyTQAAOH8"]
[Tue Jul 21 08:17:00.632043 2026] [security2:error] [pid 411857:tid 412045] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VLC7ynBpLeKYztQOyTQAAOH8"]
[Tue Jul 21 08:17:00.664563 2026] [security2:error] [pid 411857:tid 411859] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VLC7ynBpLeKYztQOyTwAAGAA"]
[Tue Jul 21 08:17:00.664834 2026] [security2:error] [pid 411857:tid 412013] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VLC7ynBpLeKYztQOyTwAAGAA"]
[Tue Jul 21 08:17:00.726946 2026] [security2:error] [pid 411857:tid 412046] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9VLC7ynBpLeKYztQOyUAAAADk"]
[Tue Jul 21 08:17:00.765560 2026] [security2:error] [pid 402041:tid 402199] [client 223.181.60.88:24329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VLIiENNLP6XjiHQt1MwAAAak"]
[Tue Jul 21 08:17:00.765759 2026] [security2:error] [pid 402041:tid 402199] [client 223.181.60.88:24329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VLIiENNLP6XjiHQt1MwAAAak"]
[Tue Jul 21 08:17:00.830387 2026] [security2:error] [pid 411857:tid 412112] [client 20.197.192.193:61087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/xxx.php"] [unique_id "al9VLC7ynBpLeKYztQOyUgAAAHs"]
[Tue Jul 21 08:17:01.008048 2026] [security2:error] [pid 402041:tid 402177] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9VLYiENNLP6XjiHQt1OgAAAZM"]
[Tue Jul 21 08:17:01.132450 2026] [security2:error] [pid 402041:tid 402268] [client 20.151.10.161:36590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/file46.php"] [unique_id "al9VLYiENNLP6XjiHQt1PgAAAe4"]
[Tue Jul 21 08:17:01.189972 2026] [proxy:error] [pid 402041:tid 402243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:17:01.190047 2026] [proxy_http:error] [pid 402041:tid 402243] [client 20.151.10.161:13240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:17:01.190677 2026] [proxy:error] [pid 402041:tid 402243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:17:01.190711 2026] [proxy_http:error] [pid 402041:tid 402243] [client 20.151.10.161:13240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:17:01.291279 2026] [security2:error] [pid 411857:tid 412071] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9VLS7ynBpLeKYztQOyWgAAAFI"]
[Tue Jul 21 08:17:01.484700 2026] [security2:error] [pid 411857:tid 412094] [client 20.151.10.161:46067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/scxy.php"] [unique_id "al9VLS7ynBpLeKYztQOyXQAAAGk"]
[Tue Jul 21 08:17:01.574289 2026] [security2:error] [pid 402041:tid 402213] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9VLYiENNLP6XjiHQt1SQAAAbc"]
[Tue Jul 21 08:17:01.701223 2026] [security2:error] [pid 402041:tid 402206] [client 35.252.209.37:57192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blog.findcomp.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9VLYiENNLP6XjiHQt1TgAAAbA"]
[Tue Jul 21 08:17:01.815108 2026] [security2:error] [pid 411857:tid 412056] [client 20.197.192.193:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/hunter.php"] [unique_id "al9VLS7ynBpLeKYztQOyYQAAAEM"]
[Tue Jul 21 08:17:01.856678 2026] [security2:error] [pid 402041:tid 402277] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9VLYiENNLP6XjiHQt1UQAAAfc"]
[Tue Jul 21 08:17:02.081483 2026] [security2:error] [pid 411857:tid 412030] [client 20.151.10.161:13176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/chosen.php"] [unique_id "al9VLi7ynBpLeKYztQOyZAAAACk"]
[Tue Jul 21 08:17:02.141002 2026] [security2:error] [pid 411857:tid 412041] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9VLi7ynBpLeKYztQOyZgAAADQ"]
[Tue Jul 21 08:17:02.423595 2026] [security2:error] [pid 402041:tid 402197] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9VLoiENNLP6XjiHQt1WQAAAac"]
[Tue Jul 21 08:17:02.431592 2026] [security2:error] [pid 411857:tid 412031] [client 35.252.209.37:57902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blog.findcomp.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9VLi7ynBpLeKYztQOyawAAACo"]
[Tue Jul 21 08:17:02.698290 2026] [proxy:error] [pid 411857:tid 411996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:17:02.698362 2026] [proxy_http:error] [pid 411857:tid 411996] [client 20.151.10.161:13128] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:17:02.698968 2026] [proxy:error] [pid 411857:tid 411996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:17:02.699007 2026] [proxy_http:error] [pid 411857:tid 411996] [client 20.151.10.161:13128] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:17:02.705260 2026] [security2:error] [pid 411857:tid 412037] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9VLi7ynBpLeKYztQOycQAAADA"]
[Tue Jul 21 08:17:02.757490 2026] [security2:error] [pid 411857:tid 412110] [client 74.249.245.134:15125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "mail.fernandohipolito.com.br"] [uri "/.info.php"] [unique_id "al9VLi7ynBpLeKYztQOycgAAAHk"]
[Tue Jul 21 08:17:02.877878 2026] [security2:error] [pid 411857:tid 412098] [client 20.197.192.193:61072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/we.php"] [unique_id "al9VLi7ynBpLeKYztQOycwAAAG0"]
[Tue Jul 21 08:17:02.976056 2026] [security2:error] [pid 402041:tid 402207] [client 152.59.34.51:65102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VLoiENNLP6XjiHQt1XwAAAbE"]
[Tue Jul 21 08:17:02.981117 2026] [security2:error] [pid 402041:tid 402207] [client 152.59.34.51:65102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VLoiENNLP6XjiHQt1XwAAAbE"]
[Tue Jul 21 08:17:02.988826 2026] [security2:error] [pid 411857:tid 412099] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9VLi7ynBpLeKYztQOydgAAAG4"]
[Tue Jul 21 08:17:03.083724 2026] [security2:error] [pid 411857:tid 412019] [client 20.151.10.161:46071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/FWAZ.php"] [unique_id "al9VLy7ynBpLeKYztQOyeQAAAB4"]
[Tue Jul 21 08:17:03.267642 2026] [security2:error] [pid 402041:tid 402249] [client 20.151.10.161:13223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/file5.php"] [unique_id "al9VL4iENNLP6XjiHQt1YwAAAds"]
[Tue Jul 21 08:17:03.271882 2026] [security2:error] [pid 402041:tid 402281] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9VL4iENNLP6XjiHQt1ZAAAAfs"]
[Tue Jul 21 08:17:03.308931 2026] [security2:error] [pid 411857:tid 412024] [client 20.220.225.223:58930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/8.php"] [unique_id "al9VLy7ynBpLeKYztQOyfwAAACM"]
[Tue Jul 21 08:17:03.415925 2026] [access_compat:error] [pid 411857:tid 412059] [client 162.241.63.68:27530] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:17:03.555740 2026] [security2:error] [pid 411857:tid 412077] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9VLy7ynBpLeKYztQOyiwAAAFg"]
[Tue Jul 21 08:17:03.653279 2026] [security2:error] [pid 411857:tid 412017] [client 20.151.10.161:13198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/file.php"] [unique_id "al9VLy7ynBpLeKYztQOyjAAAABw"]
[Tue Jul 21 08:17:03.666285 2026] [security2:error] [pid 411857:tid 412091] [client 38.100.221.102:19069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VLy7ynBpLeKYztQOyjgAAAGY"]
[Tue Jul 21 08:17:03.666395 2026] [security2:error] [pid 411857:tid 412091] [client 38.100.221.102:19069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VLy7ynBpLeKYztQOyjgAAAGY"]
[Tue Jul 21 08:17:03.690827 2026] [security2:error] [pid 411857:tid 412085] [client 20.197.192.193:63890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucaskotovicz.com"] [uri "/phpinfo.php1"] [unique_id "al9VLy7ynBpLeKYztQOykQAAAGA"]
[Tue Jul 21 08:17:03.838484 2026] [security2:error] [pid 411857:tid 412079] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9VLy7ynBpLeKYztQOykgAAAFo"]
[Tue Jul 21 08:17:03.961925 2026] [security2:error] [pid 402041:tid 402275] [client 162.219.176.3:56292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9VL4iENNLP6XjiHQt1bQAAAfU"]
[Tue Jul 21 08:17:03.962048 2026] [security2:error] [pid 402041:tid 402275] [client 162.219.176.3:56292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9VL4iENNLP6XjiHQt1bQAAAfU"]
[Tue Jul 21 08:17:04.079134 2026] [security2:error] [pid 411857:tid 411862] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VMC7ynBpLeKYztQOynAAAKwM"]
[Tue Jul 21 08:17:04.079330 2026] [security2:error] [pid 411857:tid 412032] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VMC7ynBpLeKYztQOynAAAKwM"]
[Tue Jul 21 08:17:04.119823 2026] [security2:error] [pid 411857:tid 412087] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9VMC7ynBpLeKYztQOynQAAAGI"]
[Tue Jul 21 08:17:04.170666 2026] [security2:error] [pid 411857:tid 412102] [client 136.144.19.1:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "naldoinvest.com.br"] [uri "/wp-login.php"] [unique_id "al9VLi7ynBpLeKYztQOycAAAcQI"]
[Tue Jul 21 08:17:04.179959 2026] [security2:error] [pid 411857:tid 411866] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VMC7ynBpLeKYztQOyngAAKQc"]
[Tue Jul 21 08:17:04.180131 2026] [security2:error] [pid 411857:tid 412030] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VMC7ynBpLeKYztQOyngAAKQc"]
[Tue Jul 21 08:17:04.306851 2026] [security2:error] [pid 402041:tid 402255] [client 20.151.10.161:36518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/eee.php"] [unique_id "al9VMIiENNLP6XjiHQt1cgAAAeE"]
[Tue Jul 21 08:17:04.396986 2026] [security2:error] [pid 411857:tid 412075] [client 154.208.47.43:56216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VMC7ynBpLeKYztQOyowAAAFY"]
[Tue Jul 21 08:17:04.397098 2026] [security2:error] [pid 411857:tid 412075] [client 154.208.47.43:56216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VMC7ynBpLeKYztQOyowAAAFY"]
[Tue Jul 21 08:17:04.418446 2026] [security2:error] [pid 411857:tid 412098] [client 143.244.57.88:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gabriellagoncalvesev1781726574055.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9VMC7ynBpLeKYztQOypAAAAG0"]
[Tue Jul 21 08:17:04.574733 2026] [security2:error] [pid 402041:tid 402287] [client 20.151.10.161:13185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/aa2.php"] [unique_id "al9VMIiENNLP6XjiHQt1ewAAAgE"]
[Tue Jul 21 08:17:04.582886 2026] [security2:error] [pid 411857:tid 412019] [client 74.249.245.134:31397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/item.php"] [unique_id "al9VMC7ynBpLeKYztQOyrQAAAB4"]
[Tue Jul 21 08:17:04.738525 2026] [security2:error] [pid 411857:tid 412012] [client 103.78.200.11:61604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VMC7ynBpLeKYztQOytAAAABc"]
[Tue Jul 21 08:17:04.739084 2026] [security2:error] [pid 411857:tid 412012] [client 103.78.200.11:61604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VMC7ynBpLeKYztQOytAAAABc"]
[Tue Jul 21 08:17:04.976536 2026] [security2:error] [pid 402041:tid 402205] [client 20.206.105.145:25590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/themes.php"] [unique_id "al9VMIiENNLP6XjiHQt1ggAAAa8"]
[Tue Jul 21 08:17:05.131091 2026] [security2:error] [pid 411857:tid 412023] [client 20.197.192.193:3342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/mimpi.php"] [unique_id "al9VMS7ynBpLeKYztQOytwAAACI"]
[Tue Jul 21 08:17:05.500607 2026] [security2:error] [pid 411857:tid 412013] [client 35.252.209.37:57725] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blog.findcomp.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9VMS7ynBpLeKYztQOyuQAAABg"]
[Tue Jul 21 08:17:05.712231 2026] [security2:error] [pid 402041:tid 402258] [client 102.206.115.33:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VMYiENNLP6XjiHQt1kQAAAeQ"]
[Tue Jul 21 08:17:05.712388 2026] [security2:error] [pid 402041:tid 402258] [client 102.206.115.33:62708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VMYiENNLP6XjiHQt1kQAAAeQ"]
[Tue Jul 21 08:17:05.748891 2026] [security2:error] [pid 402041:tid 402260] [client 65.21.113.253:35616] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VMYiENNLP6XjiHQt1iwAAAeY"]
[Tue Jul 21 08:17:05.922142 2026] [security2:error] [pid 411857:tid 412107] [client 20.151.10.161:13199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/ccou.php"] [unique_id "al9VMS7ynBpLeKYztQOywAAAAHY"]
[Tue Jul 21 08:17:06.060235 2026] [security2:error] [pid 411857:tid 412086] [client 87.116.180.198:27344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VMi7ynBpLeKYztQOyxQAAAGE"]
[Tue Jul 21 08:17:06.066260 2026] [security2:error] [pid 411857:tid 412086] [client 87.116.180.198:27344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VMi7ynBpLeKYztQOyxQAAAGE"]
[Tue Jul 21 08:17:06.245000 2026] [security2:error] [pid 411857:tid 411998] [client 187.125.243.197:53145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VMi7ynBpLeKYztQOyzgAAAAk"]
[Tue Jul 21 08:17:06.245141 2026] [security2:error] [pid 411857:tid 411998] [client 187.125.243.197:53145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VMi7ynBpLeKYztQOyzgAAAAk"]
[Tue Jul 21 08:17:06.297271 2026] [security2:error] [pid 402041:tid 402270] [client 61.1.167.83:57162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VMoiENNLP6XjiHQt1lwAAAfA"]
[Tue Jul 21 08:17:06.297395 2026] [security2:error] [pid 402041:tid 402270] [client 61.1.167.83:57162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VMoiENNLP6XjiHQt1lwAAAfA"]
[Tue Jul 21 08:17:06.373365 2026] [security2:error] [pid 402041:tid 402178] [client 20.220.225.223:58914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/red.php"] [unique_id "al9VMoiENNLP6XjiHQt1mgAAAZQ"]
[Tue Jul 21 08:17:06.401047 2026] [security2:error] [pid 411857:tid 412075] [client 74.249.245.134:15379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/albin.php"] [unique_id "al9VMi7ynBpLeKYztQOy1AAAAFY"]
[Tue Jul 21 08:17:06.559311 2026] [security2:error] [pid 402041:tid 402281] [client 20.206.105.145:25551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/8.php"] [unique_id "al9VMoiENNLP6XjiHQt1owAAAfs"]
[Tue Jul 21 08:17:06.577303 2026] [security2:error] [pid 402041:tid 402184] [client 45.132.227.202:37137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/wp-login.php"] [unique_id "al9VMoiENNLP6XjiHQt1mwAAAZo"]
[Tue Jul 21 08:17:06.948277 2026] [security2:error] [pid 411857:tid 412082] [client 20.151.10.161:13057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/dr.php"] [unique_id "al9VMi7ynBpLeKYztQOy2QAAAF0"]
[Tue Jul 21 08:17:06.953144 2026] [security2:error] [pid 402041:tid 402177] [client 20.151.10.161:45953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/qterm.php"] [unique_id "al9VMoiENNLP6XjiHQt1rAAAAZM"]
[Tue Jul 21 08:17:07.006012 2026] [security2:error] [pid 402041:tid 402296] [client 103.106.20.201:60903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VM4iENNLP6XjiHQt1rgAAAgo"]
[Tue Jul 21 08:17:07.006176 2026] [security2:error] [pid 402041:tid 402296] [client 103.106.20.201:60903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VM4iENNLP6XjiHQt1rgAAAgo"]
[Tue Jul 21 08:17:07.188900 2026] [security2:error] [pid 411857:tid 411883] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VMy7ynBpLeKYztQOy3QAABhg"]
[Tue Jul 21 08:17:07.189063 2026] [security2:error] [pid 411857:tid 411995] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VMy7ynBpLeKYztQOy3QAABhg"]
[Tue Jul 21 08:17:07.281572 2026] [security2:error] [pid 402041:tid 402208] [client 14.245.224.124:62367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VM4iENNLP6XjiHQt1swAAAbI"]
[Tue Jul 21 08:17:07.281709 2026] [security2:error] [pid 402041:tid 402208] [client 14.245.224.124:62367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VM4iENNLP6XjiHQt1swAAAbI"]
[Tue Jul 21 08:17:07.820647 2026] [security2:error] [pid 411857:tid 412108] [client 20.151.10.161:13259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/file31.php"] [unique_id "al9VMy7ynBpLeKYztQOy6QAAAHc"]
[Tue Jul 21 08:17:07.830145 2026] [security2:error] [pid 411857:tid 412110] [client 74.7.244.13:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.guiferreira.formaesplendida.com"] [uri "/index.php"] [unique_id "al9VMi7ynBpLeKYztQOy0wAAAHk"]
[Tue Jul 21 08:17:07.830883 2026] [security2:error] [pid 411857:tid 412042] [client 74.7.244.13:55216] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.guiferreira.formaesplendida.com"] [uri "/robots.txt"] [unique_id "al9VMi7ynBpLeKYztQOy0QAANRM"]
[Tue Jul 21 08:17:08.056686 2026] [security2:error] [pid 411857:tid 412099] [client 115.134.11.136:57896] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VNC7ynBpLeKYztQOy7QAAAG4"]
[Tue Jul 21 08:17:08.056902 2026] [security2:error] [pid 411857:tid 412099] [client 115.134.11.136:57896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VNC7ynBpLeKYztQOy7QAAAG4"]
[Tue Jul 21 08:17:08.165811 2026] [security2:error] [pid 402041:tid 402253] [client 103.151.46.103:50497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VNIiENNLP6XjiHQt1wAAAAd8"]
[Tue Jul 21 08:17:08.165918 2026] [security2:error] [pid 402041:tid 402253] [client 103.151.46.103:50497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VNIiENNLP6XjiHQt1wAAAAd8"]
[Tue Jul 21 08:17:08.295034 2026] [security2:error] [pid 411857:tid 412034] [client 14.97.58.74:52942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VNC7ynBpLeKYztQOy8QAAAC0"]
[Tue Jul 21 08:17:08.295232 2026] [security2:error] [pid 411857:tid 412034] [client 14.97.58.74:52942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VNC7ynBpLeKYztQOy8QAAAC0"]
[Tue Jul 21 08:17:08.401547 2026] [security2:error] [pid 402041:tid 402050] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VNIiENNLP6XjiHQt1wgABoAY"]
[Tue Jul 21 08:17:08.401691 2026] [security2:error] [pid 402041:tid 402190] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VNIiENNLP6XjiHQt1wgABoAY"]
[Tue Jul 21 08:17:08.453808 2026] [security2:error] [pid 411857:tid 412036] [client 74.7.244.13:55228] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "guiferreira.com.br"] [uri "/"] [unique_id "al9VNC7ynBpLeKYztQOy8gAALxw"], referer: https://www.guiferreira.formaesplendida.com/robots.txt
[Tue Jul 21 08:17:08.685867 2026] [security2:error] [pid 402041:tid 402277] [client 20.151.10.161:13147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/file6.php"] [unique_id "al9VNIiENNLP6XjiHQt1yQAAAfc"]
[Tue Jul 21 08:17:08.936349 2026] [security2:error] [pid 411857:tid 412004] [client 20.220.225.223:55750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/fffm.php"] [unique_id "al9VNC7ynBpLeKYztQOy_gAAAA8"]
[Tue Jul 21 08:17:09.248652 2026] [security2:error] [pid 411857:tid 412001] [client 20.151.10.161:13159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/file15.php"] [unique_id "al9VNS7ynBpLeKYztQOzBQAAAAw"]
[Tue Jul 21 08:17:09.535044 2026] [security2:error] [pid 411857:tid 412068] [client 20.151.10.161:45965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/blurbs.php"] [unique_id "al9VNS7ynBpLeKYztQOzCQAAAE8"]
[Tue Jul 21 08:17:09.595861 2026] [security2:error] [pid 411857:tid 412089] [client 20.151.10.161:13226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/jp.php"] [unique_id "al9VNS7ynBpLeKYztQOzDAAAAGQ"]
[Tue Jul 21 08:17:09.647697 2026] [security2:error] [pid 411857:tid 412044] [client 35.252.209.37:57592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blog.findcomp.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9VNS7ynBpLeKYztQOzEAAAADc"]
[Tue Jul 21 08:17:09.857023 2026] [security2:error] [pid 411857:tid 412071] [client 74.249.245.134:15389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/alfa.php"] [unique_id "al9VNS7ynBpLeKYztQOzEwAAAFI"]
[Tue Jul 21 08:17:09.928120 2026] [security2:error] [pid 402041:tid 402178] [client 20.197.192.193:12998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/zzz.php"] [unique_id "al9VNYiENNLP6XjiHQt13wAAAZQ"]
[Tue Jul 21 08:17:09.978239 2026] [security2:error] [pid 411857:tid 412074] [client 20.151.10.161:13234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/f35.php"] [unique_id "al9VNS7ynBpLeKYztQOzFgAAAFU"]
[Tue Jul 21 08:17:10.143266 2026] [security2:error] [pid 411857:tid 412077] [client 150.129.202.39:13355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VNi7ynBpLeKYztQOzGwAAAFg"]
[Tue Jul 21 08:17:10.143399 2026] [security2:error] [pid 411857:tid 412077] [client 150.129.202.39:13355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VNi7ynBpLeKYztQOzGwAAAFg"]
[Tue Jul 21 08:17:10.195330 2026] [security2:error] [pid 411857:tid 411999] [client 20.151.10.161:36493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/file25.php"] [unique_id "al9VNi7ynBpLeKYztQOzHAAAAAo"]
[Tue Jul 21 08:17:10.269649 2026] [security2:error] [pid 411857:tid 412099] [client 20.206.105.145:25539] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "fastpedidos.com.br"] [uri "/1.php"] [unique_id "al9VNi7ynBpLeKYztQOzHQAAAG4"]
[Tue Jul 21 08:17:10.269772 2026] [security2:error] [pid 411857:tid 412099] [client 20.206.105.145:25539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/1.php"] [unique_id "al9VNi7ynBpLeKYztQOzHQAAAG4"]
[Tue Jul 21 08:17:10.311347 2026] [security2:error] [pid 411857:tid 412063] [client 20.151.10.161:13262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wp-load.php"] [unique_id "al9VNi7ynBpLeKYztQOzIAAAAEo"]
[Tue Jul 21 08:17:10.554137 2026] [security2:error] [pid 402041:tid 402286] [client 120.56.162.40:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VNoiENNLP6XjiHQt16QAAAgA"]
[Tue Jul 21 08:17:10.554285 2026] [security2:error] [pid 402041:tid 402286] [client 120.56.162.40:52974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VNoiENNLP6XjiHQt16QAAAgA"]
[Tue Jul 21 08:17:10.692677 2026] [security2:error] [pid 411857:tid 412043] [client 117.210.135.0:61561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VNi7ynBpLeKYztQOzKAAAADY"]
[Tue Jul 21 08:17:10.693211 2026] [security2:error] [pid 411857:tid 412043] [client 117.210.135.0:61561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VNi7ynBpLeKYztQOzKAAAADY"]
[Tue Jul 21 08:17:10.719552 2026] [proxy:error] [pid 411857:tid 411997] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:17:10.719617 2026] [proxy_http:error] [pid 411857:tid 411997] [client 20.151.10.161:13183] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:17:10.720199 2026] [proxy:error] [pid 411857:tid 411997] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:17:10.720224 2026] [proxy_http:error] [pid 411857:tid 411997] [client 20.151.10.161:13183] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:17:10.999136 2026] [security2:error] [pid 402041:tid 402203] [client 20.220.225.223:52669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/ftde.php"] [unique_id "al9VNoiENNLP6XjiHQt18QAAAa0"]
[Tue Jul 21 08:17:11.080004 2026] [proxy:error] [pid 411857:tid 412032] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:17:11.080084 2026] [proxy_http:error] [pid 411857:tid 412032] [client 20.151.10.161:13291] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:17:11.080730 2026] [proxy:error] [pid 411857:tid 412032] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:17:11.080762 2026] [proxy_http:error] [pid 411857:tid 412032] [client 20.151.10.161:13291] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:17:11.306060 2026] [security2:error] [pid 402041:tid 402108] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VN4iENNLP6XjiHQt1-QABmEA"]
[Tue Jul 21 08:17:11.306219 2026] [security2:error] [pid 402041:tid 402182] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VN4iENNLP6XjiHQt1-QABmEA"]
[Tue Jul 21 08:17:11.483005 2026] [security2:error] [pid 402041:tid 402253] [client 20.151.10.161:13249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9VN4iENNLP6XjiHQt1_gAAAd8"]
[Tue Jul 21 08:17:11.566590 2026] [security2:error] [pid 402041:tid 402287] [client 74.249.245.134:15146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9VN4iENNLP6XjiHQt1_wAAAgE"]
[Tue Jul 21 08:17:11.588917 2026] [security2:error] [pid 402041:tid 402296] [client 223.181.60.88:9538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VN4iENNLP6XjiHQt2AQAAAgo"]
[Tue Jul 21 08:17:11.590641 2026] [security2:error] [pid 402041:tid 402296] [client 223.181.60.88:9538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VN4iENNLP6XjiHQt2AQAAAgo"]
[Tue Jul 21 08:17:11.686639 2026] [security2:error] [pid 411857:tid 411906] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VNy7ynBpLeKYztQOzNwAAMC8"]
[Tue Jul 21 08:17:11.686802 2026] [security2:error] [pid 411857:tid 412037] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VNy7ynBpLeKYztQOzNwAAMC8"]
[Tue Jul 21 08:17:11.837898 2026] [security2:error] [pid 402041:tid 402243] [client 20.151.10.161:13125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wp-links.php"] [unique_id "al9VN4iENNLP6XjiHQt2BgAAAdU"]
[Tue Jul 21 08:17:12.211565 2026] [security2:error] [pid 411857:tid 412068] [client 20.151.10.161:13241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/solo1.php"] [unique_id "al9VOC7ynBpLeKYztQOzPgAAAE8"]
[Tue Jul 21 08:17:12.272860 2026] [security2:error] [pid 402041:tid 402239] [client 20.206.105.145:25482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/100.php"] [unique_id "al9VOIiENNLP6XjiHQt2EQAAAdE"]
[Tue Jul 21 08:17:12.311541 2026] [security2:error] [pid 411857:tid 412060] [client 62.102.148.158:43956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9VOC7ynBpLeKYztQOzPwAAAEc"]
[Tue Jul 21 08:17:12.311633 2026] [security2:error] [pid 411857:tid 412060] [client 62.102.148.158:43956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9VOC7ynBpLeKYztQOzPwAAAEc"]
[Tue Jul 21 08:17:12.502831 2026] [security2:error] [pid 411857:tid 411909] [remote 162.243.80.244:44168] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hctreinamentos.net"] [uri "/.env"] [unique_id "al9VOC7ynBpLeKYztQOzQgAAXDI"]
[Tue Jul 21 08:17:12.580265 2026] [security2:error] [pid 402041:tid 402231] [client 20.151.10.161:13152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/sixxis.php"] [unique_id "al9VOIiENNLP6XjiHQt2GgAAAck"]
[Tue Jul 21 08:17:12.644051 2026] [security2:error] [pid 411857:tid 412024] [client 20.206.105.145:25488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/about.php"] [unique_id "al9VOC7ynBpLeKYztQOzRQAAACM"]
[Tue Jul 21 08:17:12.933728 2026] [security2:error] [pid 411857:tid 411908] [remote 173.252.87.10:41162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9VOC7ynBpLeKYztQOzSAAAbDE"]
[Tue Jul 21 08:17:12.989058 2026] [security2:error] [pid 402041:tid 402199] [client 20.220.225.223:38661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9VOIiENNLP6XjiHQt2JgAAAak"]
[Tue Jul 21 08:17:13.047022 2026] [security2:error] [pid 411857:tid 412109] [client 20.151.10.161:13061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/2P.update.php"] [unique_id "al9VOS7ynBpLeKYztQOzTAAAAHg"]
[Tue Jul 21 08:17:13.049658 2026] [security2:error] [pid 411857:tid 412110] [client 20.151.10.161:46077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/v543.php"] [unique_id "al9VOS7ynBpLeKYztQOzTQAAAHk"]
[Tue Jul 21 08:17:13.177748 2026] [security2:error] [pid 411857:tid 412099] [client 20.226.60.151:60348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9VOS7ynBpLeKYztQOzUwAAAG4"]
[Tue Jul 21 08:17:13.259043 2026] [security2:error] [pid 411857:tid 412051] [client 185.213.175.37:17774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.sscoenper.com.br"] [uri "/"] [unique_id "al9VOS7ynBpLeKYztQOzVAAAAD4"]
[Tue Jul 21 08:17:13.259155 2026] [security2:error] [pid 411857:tid 412051] [client 185.213.175.37:17774] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.sscoenper.com.br"] [uri "/"] [unique_id "al9VOS7ynBpLeKYztQOzVAAAAD4"]
[Tue Jul 21 08:17:13.307928 2026] [security2:error] [pid 402041:tid 402288] [client 20.206.105.145:25102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/about.php"] [unique_id "al9VOYiENNLP6XjiHQt2LQAAAgI"]
[Tue Jul 21 08:17:13.530876 2026] [security2:error] [pid 411857:tid 412041] [client 20.226.60.151:60309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9VOS7ynBpLeKYztQOzWgAAADQ"]
[Tue Jul 21 08:17:13.539634 2026] [security2:error] [pid 411857:tid 412028] [client 20.151.10.161:13122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/a.php"] [unique_id "al9VOS7ynBpLeKYztQOzWwAAACc"]
[Tue Jul 21 08:17:13.657112 2026] [security2:error] [pid 411857:tid 412093] [client 185.213.175.37:17782] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.ssvistorias.com.br"] [uri "/"] [unique_id "al9VOS7ynBpLeKYztQOzXwAAAGg"]
[Tue Jul 21 08:17:13.831891 2026] [security2:error] [pid 402041:tid 402210] [client 35.252.209.37:54227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blog.findcomp.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9VOYiENNLP6XjiHQt2NAAAAbQ"]
[Tue Jul 21 08:17:13.903338 2026] [security2:error] [pid 402041:tid 402157] [remote 49.13.1.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp-login.php"] [unique_id "al9VOYiENNLP6XjiHQt2NgABmHE"]
[Tue Jul 21 08:17:14.035239 2026] [security2:error] [pid 411857:tid 411996] [client 20.226.60.151:60327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/media.php"] [unique_id "al9VOi7ynBpLeKYztQOzZAAAAAc"]
[Tue Jul 21 08:17:14.125675 2026] [security2:error] [pid 411857:tid 412054] [client 65.21.113.253:49342] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VOS7ynBpLeKYztQOzYAAAAEE"]
[Tue Jul 21 08:17:14.171866 2026] [security2:error] [pid 411857:tid 412030] [client 20.151.10.161:13272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/k.php"] [unique_id "al9VOi7ynBpLeKYztQOzZwAAACk"]
[Tue Jul 21 08:17:14.377875 2026] [security2:error] [pid 411857:tid 412031] [client 38.100.221.102:17352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VOi7ynBpLeKYztQOzagAAACo"]
[Tue Jul 21 08:17:14.377965 2026] [security2:error] [pid 411857:tid 412031] [client 38.100.221.102:17352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VOi7ynBpLeKYztQOzagAAACo"]
[Tue Jul 21 08:17:14.412311 2026] [security2:error] [pid 411857:tid 411992] [client 20.226.60.151:60288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/images.php"] [unique_id "al9VOi7ynBpLeKYztQOzawAAAAM"]
[Tue Jul 21 08:17:14.476686 2026] [security2:error] [pid 411857:tid 412039] [client 20.206.105.145:25550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/admin.php"] [unique_id "al9VOi7ynBpLeKYztQOzbAAAADI"]
[Tue Jul 21 08:17:14.582248 2026] [security2:error] [pid 411857:tid 412081] [client 20.151.10.161:13203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/w.php"] [unique_id "al9VOi7ynBpLeKYztQOzbgAAAFw"]
[Tue Jul 21 08:17:14.599839 2026] [security2:error] [pid 402041:tid 402205] [client 20.226.60.151:52005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/gecko.php"] [unique_id "al9VOoiENNLP6XjiHQt2RQAAAa8"]
[Tue Jul 21 08:17:14.662826 2026] [security2:error] [pid 402041:tid 402164] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VOoiENNLP6XjiHQt2SQAB_ng"]
[Tue Jul 21 08:17:14.663006 2026] [security2:error] [pid 402041:tid 402284] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VOoiENNLP6XjiHQt2SQAB_ng"]
[Tue Jul 21 08:17:14.665945 2026] [security2:error] [pid 411857:tid 412046] [client 20.220.225.223:58940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/yup.php"] [unique_id "al9VOi7ynBpLeKYztQOzdQAAADk"]
[Tue Jul 21 08:17:14.878186 2026] [security2:error] [pid 411857:tid 411923] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VOi7ynBpLeKYztQOzewAAKEA"]
[Tue Jul 21 08:17:14.878361 2026] [security2:error] [pid 411857:tid 412029] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VOi7ynBpLeKYztQOzewAAKEA"]
[Tue Jul 21 08:17:14.885972 2026] [security2:error] [pid 402041:tid 402192] [client 154.208.47.43:56760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VOoiENNLP6XjiHQt2TgAAAaI"]
[Tue Jul 21 08:17:14.886192 2026] [security2:error] [pid 402041:tid 402192] [client 154.208.47.43:56760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VOoiENNLP6XjiHQt2TgAAAaI"]
[Tue Jul 21 08:17:14.978171 2026] [security2:error] [pid 402041:tid 402230] [client 20.151.10.161:13245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/insc.php"] [unique_id "al9VOoiENNLP6XjiHQt2UQAAAcg"]
[Tue Jul 21 08:17:15.013517 2026] [security2:error] [pid 402041:tid 402235] [client 20.220.225.223:38688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9VO4iENNLP6XjiHQt2VAAAAc0"]
[Tue Jul 21 08:17:15.329417 2026] [security2:error] [pid 402041:tid 402211] [client 20.151.10.161:13059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9VO4iENNLP6XjiHQt2XQAAAbU"]
[Tue Jul 21 08:17:15.407474 2026] [security2:error] [pid 411857:tid 411926] [remote 154.61.75.100:42372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "health-24.shop"] [uri "/wp-login.php"] [unique_id "al9VOy7ynBpLeKYztQOzgAAABUM"]
[Tue Jul 21 08:17:15.425122 2026] [security2:error] [pid 411857:tid 412051] [client 20.226.60.151:51978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/82.php"] [unique_id "al9VOy7ynBpLeKYztQOzgQAAAD4"]
[Tue Jul 21 08:17:15.443343 2026] [security2:error] [pid 411857:tid 412063] [client 74.249.245.134:15111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/av.php"] [unique_id "al9VOy7ynBpLeKYztQOzggAAAEo"]
[Tue Jul 21 08:17:15.467791 2026] [security2:error] [pid 411857:tid 412104] [client 103.78.200.11:62098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VOy7ynBpLeKYztQOzgwAAAHM"]
[Tue Jul 21 08:17:15.468293 2026] [security2:error] [pid 411857:tid 412104] [client 103.78.200.11:62098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VOy7ynBpLeKYztQOzgwAAAHM"]
[Tue Jul 21 08:17:15.738565 2026] [security2:error] [pid 411857:tid 412028] [client 20.226.60.151:60320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/admin.php"] [unique_id "al9VOy7ynBpLeKYztQOziQAAACc"]
[Tue Jul 21 08:17:15.853134 2026] [security2:error] [pid 411857:tid 412035] [client 20.151.10.161:13190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/u.php"] [unique_id "al9VOy7ynBpLeKYztQOzigAAAC4"]
[Tue Jul 21 08:17:15.923982 2026] [security2:error] [pid 402041:tid 402175] [client 20.220.225.223:38714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wander.php"] [unique_id "al9VO4iENNLP6XjiHQt2ZgAAAZE"]
[Tue Jul 21 08:17:16.058824 2026] [security2:error] [pid 411857:tid 411997] [client 20.226.60.151:60325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/adminner.php"] [unique_id "al9VPC7ynBpLeKYztQOzjgAAAAg"]
[Tue Jul 21 08:17:16.271305 2026] [security2:error] [pid 411857:tid 412017] [client 102.206.115.33:63953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VPC7ynBpLeKYztQOzkwAAABw"]
[Tue Jul 21 08:17:16.271427 2026] [security2:error] [pid 411857:tid 412017] [client 102.206.115.33:63953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VPC7ynBpLeKYztQOzkwAAABw"]
[Tue Jul 21 08:17:16.286998 2026] [security2:error] [pid 402041:tid 402234] [client 37.220.132.13:57182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.132.220.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/wp-login.php"] [unique_id "al9VPIiENNLP6XjiHQt2bQAAAcw"]
[Tue Jul 21 08:17:16.337325 2026] [security2:error] [pid 402041:tid 402227] [client 20.226.60.151:52001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/admin.php"] [unique_id "al9VPIiENNLP6XjiHQt2bwAAAcU"]
[Tue Jul 21 08:17:16.442602 2026] [security2:error] [pid 402041:tid 402217] [client 20.226.60.151:52007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/k.php"] [unique_id "al9VPIiENNLP6XjiHQt2cAAAAbs"]
[Tue Jul 21 08:17:16.450767 2026] [security2:error] [pid 402041:tid 402268] [client 20.206.105.145:25555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/admin.php"] [unique_id "al9VPIiENNLP6XjiHQt2cQAAAe4"]
[Tue Jul 21 08:17:16.479780 2026] [security2:error] [pid 402041:tid 402183] [client 20.151.10.161:13235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/sss.php"] [unique_id "al9VPIiENNLP6XjiHQt2cwAAAZk"]
[Tue Jul 21 08:17:16.605958 2026] [security2:error] [pid 411857:tid 412053] [client 20.226.60.151:60308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/blurbs.php"] [unique_id "al9VPC7ynBpLeKYztQOzlgAAAEA"]
[Tue Jul 21 08:17:16.724708 2026] [security2:error] [pid 411857:tid 412006] [client 87.116.180.198:27193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VPC7ynBpLeKYztQOzmQAAABE"]
[Tue Jul 21 08:17:16.724884 2026] [security2:error] [pid 411857:tid 412006] [client 87.116.180.198:27193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VPC7ynBpLeKYztQOzmQAAABE"]
[Tue Jul 21 08:17:16.754778 2026] [security2:error] [pid 411857:tid 412082] [client 20.226.60.151:51997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/bajah.php"] [unique_id "al9VPC7ynBpLeKYztQOzmgAAAF0"]
[Tue Jul 21 08:17:16.780839 2026] [security2:error] [pid 402041:tid 402296] [client 20.151.10.161:13265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/sss.php"] [unique_id "al9VPIiENNLP6XjiHQt2fQAAAgo"]
[Tue Jul 21 08:17:16.788096 2026] [security2:error] [pid 402041:tid 402253] [client 187.125.243.197:53899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VPIiENNLP6XjiHQt2fwAAAd8"]
[Tue Jul 21 08:17:16.788229 2026] [security2:error] [pid 402041:tid 402253] [client 187.125.243.197:53899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VPIiENNLP6XjiHQt2fwAAAd8"]
[Tue Jul 21 08:17:16.966735 2026] [security2:error] [pid 411857:tid 412026] [client 152.59.34.51:65523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VPC7ynBpLeKYztQOznQAAACU"]
[Tue Jul 21 08:17:16.966959 2026] [security2:error] [pid 411857:tid 412026] [client 152.59.34.51:65523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VPC7ynBpLeKYztQOznQAAACU"]
[Tue Jul 21 08:17:17.029935 2026] [security2:error] [pid 411857:tid 411934] [remote 45.3.45.99:10019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9VPC7ynBpLeKYztQOznAAAAks"]
[Tue Jul 21 08:17:17.056183 2026] [proxy:error] [pid 411857:tid 412007] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:17:17.056261 2026] [proxy_http:error] [pid 411857:tid 412007] [client 45.148.10.120:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:17:17.056931 2026] [proxy:error] [pid 411857:tid 412007] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:17:17.056959 2026] [proxy_http:error] [pid 411857:tid 412007] [client 45.148.10.120:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:17:17.057358 2026] [proxy:error] [pid 411857:tid 412081] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:17:17.057384 2026] [proxy_http:error] [pid 411857:tid 412081] [client 45.148.10.120:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:17:17.057840 2026] [proxy:error] [pid 411857:tid 412081] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:17:17.057861 2026] [proxy_http:error] [pid 411857:tid 412081] [client 45.148.10.120:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:17:17.171559 2026] [security2:error] [pid 402041:tid 402228] [client 20.151.10.161:13273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/c.php"] [unique_id "al9VPYiENNLP6XjiHQt2hQAAAcY"]
[Tue Jul 21 08:17:17.191822 2026] [security2:error] [pid 402041:tid 402226] [client 20.226.60.151:51981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/a.php"] [unique_id "al9VPYiENNLP6XjiHQt2hgAAAcQ"]
[Tue Jul 21 08:17:17.346125 2026] [security2:error] [pid 411857:tid 412114] [client 20.226.60.151:52017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/edit.php"] [unique_id "al9VPS7ynBpLeKYztQOzpAAAAH0"]
[Tue Jul 21 08:17:17.369834 2026] [security2:error] [pid 402041:tid 402284] [client 20.206.105.145:25559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/edit.php"] [unique_id "al9VPYiENNLP6XjiHQt2iQAAAf4"]
[Tue Jul 21 08:17:17.522583 2026] [security2:error] [pid 411857:tid 412103] [client 20.226.60.151:60323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/hosty.php"] [unique_id "al9VPS7ynBpLeKYztQOzqAAAAHI"]
[Tue Jul 21 08:17:17.650366 2026] [security2:error] [pid 411857:tid 411990] [client 103.106.20.201:61480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VPS7ynBpLeKYztQOzqgAAAAE"]
[Tue Jul 21 08:17:17.650500 2026] [security2:error] [pid 411857:tid 411990] [client 103.106.20.201:61480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VPS7ynBpLeKYztQOzqgAAAAE"]
[Tue Jul 21 08:17:17.707836 2026] [security2:error] [pid 411857:tid 412064] [client 20.151.10.161:13120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/aa.php"] [unique_id "al9VPS7ynBpLeKYztQOzrAAAAEs"]
[Tue Jul 21 08:17:17.748026 2026] [security2:error] [pid 402041:tid 402107] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VPYiENNLP6XjiHQt2lgAByD8"]
[Tue Jul 21 08:17:17.748192 2026] [security2:error] [pid 402041:tid 402230] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VPYiENNLP6XjiHQt2lgAByD8"]
[Tue Jul 21 08:17:17.869013 2026] [security2:error] [pid 411857:tid 412074] [client 103.151.46.103:50979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VPS7ynBpLeKYztQOzrgAAAFU"]
[Tue Jul 21 08:17:17.869132 2026] [security2:error] [pid 411857:tid 412074] [client 103.151.46.103:50979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VPS7ynBpLeKYztQOzrgAAAFU"]
[Tue Jul 21 08:17:17.876494 2026] [security2:error] [pid 402041:tid 402250] [client 14.245.224.124:62797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VPYiENNLP6XjiHQt2mQAAAdw"]
[Tue Jul 21 08:17:17.876644 2026] [security2:error] [pid 402041:tid 402250] [client 14.245.224.124:62797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VPYiENNLP6XjiHQt2mQAAAdw"]
[Tue Jul 21 08:17:17.909249 2026] [security2:error] [pid 411857:tid 412100] [client 20.151.10.161:36593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/file48.php"] [unique_id "al9VPS7ynBpLeKYztQOzrwAAAG8"]
[Tue Jul 21 08:17:18.179845 2026] [security2:error] [pid 411857:tid 411994] [client 20.226.60.151:51982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/k.php"] [unique_id "al9VPi7ynBpLeKYztQOzsgAAAAU"]
[Tue Jul 21 08:17:18.210180 2026] [security2:error] [pid 402041:tid 402251] [client 142.44.228.15:41776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "zohmfo.com"] [uri "/robots.txt"] [unique_id "al9VPoiENNLP6XjiHQt2oQAAAd0"]
[Tue Jul 21 08:17:18.210284 2026] [security2:error] [pid 402041:tid 402251] [client 142.44.228.15:41776] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "zohmfo.com"] [uri "/robots.txt"] [unique_id "al9VPoiENNLP6XjiHQt2oQAAAd0"]
[Tue Jul 21 08:17:18.313493 2026] [security2:error] [pid 411857:tid 412002] [client 45.148.10.120:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9VPi7ynBpLeKYztQOztgAAAA0"]
[Tue Jul 21 08:17:18.321080 2026] [security2:error] [pid 402041:tid 402209] [client 20.151.10.161:13295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/100.php"] [unique_id "al9VPoiENNLP6XjiHQt2owAAAbM"]
[Tue Jul 21 08:17:18.473809 2026] [security2:error] [pid 402041:tid 402227] [client 20.197.192.193:13686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/wicked.php"] [unique_id "al9VPoiENNLP6XjiHQt2qgAAAcU"]
[Tue Jul 21 08:17:18.549875 2026] [security2:error] [pid 402041:tid 402268] [client 20.226.60.151:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/aaa.php"] [unique_id "al9VPoiENNLP6XjiHQt2rgAAAe4"]
[Tue Jul 21 08:17:18.787780 2026] [security2:error] [pid 402041:tid 402196] [client 20.226.60.151:52012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/file5.php"] [unique_id "al9VPoiENNLP6XjiHQt2uQAAAaY"]
[Tue Jul 21 08:17:18.824604 2026] [security2:error] [pid 411857:tid 412112] [client 65.21.113.253:49342] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VPi7ynBpLeKYztQOztwAAAHs"]
[Tue Jul 21 08:17:18.923175 2026] [security2:error] [pid 411857:tid 412053] [client 35.252.209.37:62226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blog.findcomp.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9VPi7ynBpLeKYztQOzzwAAAEA"]
[Tue Jul 21 08:17:18.926911 2026] [security2:error] [pid 411857:tid 412037] [client 20.151.10.161:13294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/footer.php"] [unique_id "al9VPi7ynBpLeKYztQOz0AAAADA"]
[Tue Jul 21 08:17:18.939481 2026] [security2:error] [pid 402041:tid 402280] [client 111.93.58.162:7849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VPoiENNLP6XjiHQt2vgAAAfo"]
[Tue Jul 21 08:17:18.939618 2026] [security2:error] [pid 402041:tid 402280] [client 111.93.58.162:7849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VPoiENNLP6XjiHQt2vgAAAfo"]
[Tue Jul 21 08:17:18.976039 2026] [security2:error] [pid 411857:tid 412049] [client 20.151.10.161:45952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/w3lls.php"] [unique_id "al9VPi7ynBpLeKYztQOz0QAAADw"]
[Tue Jul 21 08:17:19.072454 2026] [security2:error] [pid 411857:tid 412082] [client 20.206.105.145:25585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9VPy7ynBpLeKYztQOz0wAAAF0"]
[Tue Jul 21 08:17:19.211653 2026] [security2:error] [pid 402041:tid 402285] [client 20.220.225.223:58913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/jj.php"] [unique_id "al9VP4iENNLP6XjiHQt2xgAAAf8"]
[Tue Jul 21 08:17:19.359189 2026] [security2:error] [pid 411857:tid 411946] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VPy7ynBpLeKYztQOz2gAAJFc"]
[Tue Jul 21 08:17:19.359413 2026] [security2:error] [pid 411857:tid 412025] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VPy7ynBpLeKYztQOz2gAAJFc"]
[Tue Jul 21 08:17:19.423385 2026] [security2:error] [pid 402041:tid 402185] [client 20.226.60.151:52006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/222.php"] [unique_id "al9VP4iENNLP6XjiHQt2zAAAAZs"]
[Tue Jul 21 08:17:19.434704 2026] [security2:error] [pid 411857:tid 412061] [client 20.151.10.161:13216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/users.php"] [unique_id "al9VPy7ynBpLeKYztQOz4QAAAEg"]
[Tue Jul 21 08:17:19.509134 2026] [proxy:error] [pid 411857:tid 412110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:17:19.509210 2026] [proxy_http:error] [pid 411857:tid 412110] [client 45.148.10.120:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:17:19.509917 2026] [proxy:error] [pid 411857:tid 412110] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:17:19.509955 2026] [proxy_http:error] [pid 411857:tid 412110] [client 45.148.10.120:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:17:19.602704 2026] [security2:error] [pid 411857:tid 411948] [remote 194.164.192.228:34970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9VPy7ynBpLeKYztQOz4wAAF1k"]
[Tue Jul 21 08:17:19.614552 2026] [security2:error] [pid 411857:tid 411949] [remote 104.207.48.107:41803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.48.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9VPy7ynBpLeKYztQOz5AAAI1o"]
[Tue Jul 21 08:17:19.627288 2026] [security2:error] [pid 411857:tid 412090] [client 20.226.60.151:51976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/test.php"] [unique_id "al9VPy7ynBpLeKYztQOz5gAAAGU"]
[Tue Jul 21 08:17:19.673635 2026] [security2:error] [pid 402041:tid 402271] [client 198.244.240.191:27452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "zohmfo.com"] [uri "/"] [unique_id "al9VP4iENNLP6XjiHQt20AAAAfE"]
[Tue Jul 21 08:17:19.673752 2026] [security2:error] [pid 402041:tid 402271] [client 198.244.240.191:27452] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "zohmfo.com"] [uri "/"] [unique_id "al9VP4iENNLP6XjiHQt20AAAAfE"]
[Tue Jul 21 08:17:19.849713 2026] [security2:error] [pid 411857:tid 411994] [client 20.151.10.161:13138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/177.php"] [unique_id "al9VPy7ynBpLeKYztQOz8gAAAAU"]
[Tue Jul 21 08:17:20.291176 2026] [security2:error] [pid 402041:tid 402240] [client 20.151.10.161:13142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/config.php"] [unique_id "al9VQIiENNLP6XjiHQt23wAAAdI"]
[Tue Jul 21 08:17:20.359222 2026] [security2:error] [pid 402041:tid 402263] [client 20.226.60.151:51999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/aaa.php"] [unique_id "al9VQIiENNLP6XjiHQt24AAAAek"]
[Tue Jul 21 08:17:20.521288 2026] [security2:error] [pid 411857:tid 412058] [client 20.197.192.193:13661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/edit.php"] [unique_id "al9VQC7ynBpLeKYztQOz_wAAAEU"]
[Tue Jul 21 08:17:20.689197 2026] [security2:error] [pid 411857:tid 412053] [client 20.151.10.161:13206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/gettest.php"] [unique_id "al9VQC7ynBpLeKYztQO0BgAAAEA"]
[Tue Jul 21 08:17:20.700428 2026] [security2:error] [pid 402041:tid 402258] [client 150.129.202.39:64886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VQIiENNLP6XjiHQt25QAAAeQ"]
[Tue Jul 21 08:17:20.700587 2026] [security2:error] [pid 402041:tid 402258] [client 150.129.202.39:64886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VQIiENNLP6XjiHQt25QAAAeQ"]
[Tue Jul 21 08:17:20.754350 2026] [security2:error] [pid 402041:tid 402050] [remote 45.79.123.44:55734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "meuflatnapraia.com.br"] [uri "/wp-login.php"] [unique_id "al9VQIiENNLP6XjiHQt25wAB7QY"]
[Tue Jul 21 08:17:20.864163 2026] [security2:error] [pid 411857:tid 411992] [client 20.226.60.151:60303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/11.php"] [unique_id "al9VQC7ynBpLeKYztQO0CAAAAAM"]
[Tue Jul 21 08:17:20.980615 2026] [security2:error] [pid 411857:tid 412068] [client 20.206.105.145:25489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/f6.php"] [unique_id "al9VQC7ynBpLeKYztQO0CQAAAE8"]
[Tue Jul 21 08:17:21.012662 2026] [security2:error] [pid 411857:tid 412107] [client 20.151.10.161:13186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/min.php"] [unique_id "al9VQS7ynBpLeKYztQO0CgAAAHY"]
[Tue Jul 21 08:17:21.125642 2026] [security2:error] [pid 402041:tid 402238] [client 120.56.162.40:53491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VQYiENNLP6XjiHQt27wAAAdA"]
[Tue Jul 21 08:17:21.125766 2026] [security2:error] [pid 402041:tid 402238] [client 120.56.162.40:53491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VQYiENNLP6XjiHQt27wAAAdA"]
[Tue Jul 21 08:17:21.197230 2026] [security2:error] [pid 411857:tid 411998] [client 117.210.135.0:62207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VQS7ynBpLeKYztQO0FAAAAAk"]
[Tue Jul 21 08:17:21.197387 2026] [security2:error] [pid 411857:tid 411998] [client 117.210.135.0:62207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VQS7ynBpLeKYztQO0FAAAAAk"]
[Tue Jul 21 08:17:21.402993 2026] [security2:error] [pid 411857:tid 411995] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9VQS7ynBpLeKYztQO0GgAAAAY"]
[Tue Jul 21 08:17:21.438123 2026] [security2:error] [pid 411857:tid 411990] [client 20.151.10.161:13165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/edorxrr.php"] [unique_id "al9VQS7ynBpLeKYztQO0HAAAAAE"]
[Tue Jul 21 08:17:21.560447 2026] [security2:error] [pid 411857:tid 411961] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VQS7ynBpLeKYztQO0HgAAaWU"]
[Tue Jul 21 08:17:21.560643 2026] [security2:error] [pid 411857:tid 412094] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VQS7ynBpLeKYztQO0HgAAaWU"]
[Tue Jul 21 08:17:21.686604 2026] [security2:error] [pid 411857:tid 411994] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VQS7ynBpLeKYztQO0JQAAAAU"]
[Tue Jul 21 08:17:21.866576 2026] [security2:error] [pid 411857:tid 412085] [client 20.220.225.223:24229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/term.php"] [unique_id "al9VQS7ynBpLeKYztQO0KgAAAGA"]
[Tue Jul 21 08:17:21.914042 2026] [security2:error] [pid 411857:tid 411970] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VQS7ynBpLeKYztQO0LAAAPW4"]
[Tue Jul 21 08:17:21.914238 2026] [security2:error] [pid 411857:tid 412050] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VQS7ynBpLeKYztQO0LAAAPW4"]
[Tue Jul 21 08:17:21.935439 2026] [security2:error] [pid 411857:tid 412065] [client 20.151.10.161:13132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/hur.php"] [unique_id "al9VQS7ynBpLeKYztQO0LQAAAEw"]
[Tue Jul 21 08:17:21.938328 2026] [security2:error] [pid 402041:tid 402287] [client 20.151.10.161:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-ws68.php"] [unique_id "al9VQYiENNLP6XjiHQt2_AAAAgE"]
[Tue Jul 21 08:17:22.046176 2026] [security2:error] [pid 411857:tid 412036] [client 20.197.192.193:13642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/kua.php"] [unique_id "al9VQi7ynBpLeKYztQO0LwAAAC8"]
[Tue Jul 21 08:17:22.069089 2026] [security2:error] [pid 411857:tid 412073] [client 115.134.11.136:58295] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VQi7ynBpLeKYztQO0MwAAAFQ"]
[Tue Jul 21 08:17:22.069208 2026] [security2:error] [pid 411857:tid 412073] [client 115.134.11.136:58295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VQi7ynBpLeKYztQO0MwAAAFQ"]
[Tue Jul 21 08:17:22.134058 2026] [security2:error] [pid 411857:tid 412021] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9VQi7ynBpLeKYztQO0NgAAACA"]
[Tue Jul 21 08:17:22.257758 2026] [security2:error] [pid 411857:tid 412054] [client 20.151.10.161:13228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/zoro.php"] [unique_id "al9VQi7ynBpLeKYztQO0PgAAAEE"]
[Tue Jul 21 08:17:22.305791 2026] [security2:error] [pid 411857:tid 412113] [client 74.249.245.134:15137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/gg.php"] [unique_id "al9VQi7ynBpLeKYztQO0PwAAAHw"]
[Tue Jul 21 08:17:22.328731 2026] [security2:error] [pid 411857:tid 412049] [client 20.226.60.151:60298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/mac.php"] [unique_id "al9VQi7ynBpLeKYztQO0QAAAADw"]
[Tue Jul 21 08:17:22.330842 2026] [security2:error] [pid 411857:tid 411972] [remote 209.15.113.204:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.113.15.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9VQi7ynBpLeKYztQO0NwAAGXA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:17:22.334668 2026] [security2:error] [pid 411857:tid 411974] [remote 209.15.113.204:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.113.15.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9VQi7ynBpLeKYztQO0OgAAP3I"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:17:22.343194 2026] [security2:error] [pid 411857:tid 411971] [remote 209.15.113.204:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.113.15.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9VQi7ynBpLeKYztQO0PQAAJ28"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:17:22.418368 2026] [security2:error] [pid 411857:tid 412092] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9VQi7ynBpLeKYztQO0RAAAAGc"]
[Tue Jul 21 08:17:22.530494 2026] [security2:error] [pid 402041:tid 402272] [client 20.220.225.223:52662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/dragonshell.php"] [unique_id "al9VQoiENNLP6XjiHQt3BAAAAfI"]
[Tue Jul 21 08:17:22.655311 2026] [security2:error] [pid 402041:tid 402284] [client 20.197.192.193:13017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/ez.php"] [unique_id "al9VQoiENNLP6XjiHQt3CwAAAf4"]
[Tue Jul 21 08:17:22.671015 2026] [rewrite:warn] [pid 402041:tid 402094] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:17:22.703066 2026] [security2:error] [pid 402041:tid 402271] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9VQoiENNLP6XjiHQt3DwAAAfE"]
[Tue Jul 21 08:17:22.707484 2026] [security2:error] [pid 411857:tid 411979] [remote 209.15.113.204:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.113.15.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9VQi7ynBpLeKYztQO0RwAARnc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:17:22.739212 2026] [security2:error] [pid 411857:tid 411981] [remote 209.15.113.204:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.113.15.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9VQi7ynBpLeKYztQO0SAAAInk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:17:22.772190 2026] [security2:error] [pid 411857:tid 412009] [client 20.151.10.161:13163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/coffexium.php"] [unique_id "al9VQi7ynBpLeKYztQO0SwAAABQ"]
[Tue Jul 21 08:17:22.987486 2026] [security2:error] [pid 402041:tid 402202] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9VQoiENNLP6XjiHQt3FwAAAaw"]
[Tue Jul 21 08:17:23.082402 2026] [security2:error] [pid 411857:tid 411980] [remote 209.15.113.204:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.113.15.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9VQy7ynBpLeKYztQO0UAAAKHg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:17:23.087133 2026] [security2:error] [pid 411857:tid 412013] [client 20.151.10.161:13157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/app.php"] [unique_id "al9VQy7ynBpLeKYztQO0UgAAABg"]
[Tue Jul 21 08:17:23.114091 2026] [security2:error] [pid 402041:tid 402095] [remote 104.207.56.66:12469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.56.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9VQ4iENNLP6XjiHQt3GgACBTM"]
[Tue Jul 21 08:17:23.119467 2026] [security2:error] [pid 411857:tid 411984] [remote 209.15.113.204:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.113.15.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9VQy7ynBpLeKYztQO0VgAAaXw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:17:23.146221 2026] [security2:error] [pid 411857:tid 412033] [client 20.206.105.145:25493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/inputs.php"] [unique_id "al9VQy7ynBpLeKYztQO0VwAAACw"]
[Tue Jul 21 08:17:23.186330 2026] [security2:error] [pid 411857:tid 411975] [remote 209.15.113.204:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.113.15.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9VQi7ynBpLeKYztQO0PAAAenM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:17:23.238934 2026] [security2:error] [pid 411857:tid 412074] [client 35.252.209.37:58915] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blog.findcomp.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9VQy7ynBpLeKYztQO0WwAAAFU"]
[Tue Jul 21 08:17:23.272486 2026] [security2:error] [pid 402041:tid 402233] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9VQ4iENNLP6XjiHQt3HwAAAcs"]
[Tue Jul 21 08:17:23.403578 2026] [security2:error] [pid 402041:tid 402281] [client 20.151.10.161:13153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/core.php"] [unique_id "al9VQ4iENNLP6XjiHQt3IAAAAfs"]
[Tue Jul 21 08:17:23.403984 2026] [security2:error] [pid 411857:tid 412064] [client 20.226.60.151:51979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/chosen.php"] [unique_id "al9VQy7ynBpLeKYztQO0XAAAAEs"]
[Tue Jul 21 08:17:23.451026 2026] [security2:error] [pid 411857:tid 412024] [client 65.21.113.253:49342] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VQi7ynBpLeKYztQO0TwAAACM"]
[Tue Jul 21 08:17:23.470991 2026] [security2:error] [pid 402041:tid 402242] [client 223.181.60.88:3384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VQ4iENNLP6XjiHQt3JAAAAdQ"]
[Tue Jul 21 08:17:23.471282 2026] [security2:error] [pid 402041:tid 402242] [client 223.181.60.88:3384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VQ4iENNLP6XjiHQt3JAAAAdQ"]
[Tue Jul 21 08:17:23.476539 2026] [security2:error] [pid 411857:tid 412085] [client 20.220.225.223:31180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/jga.php"] [unique_id "al9VQy7ynBpLeKYztQO0XgAAAGA"]
[Tue Jul 21 08:17:23.555776 2026] [security2:error] [pid 411857:tid 412078] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9VQy7ynBpLeKYztQO0YQAAAFk"]
[Tue Jul 21 08:17:23.560965 2026] [security2:error] [pid 411857:tid 411986] [remote 209.15.113.204:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.113.15.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9VQy7ynBpLeKYztQO0YgAAdX4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:17:23.738417 2026] [security2:error] [pid 411857:tid 411860] [remote 209.15.113.204:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.113.15.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9VQy7ynBpLeKYztQO0agAADQE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:17:23.837846 2026] [security2:error] [pid 411857:tid 411997] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9VQy7ynBpLeKYztQO0awAAAAg"]
[Tue Jul 21 08:17:23.950258 2026] [security2:error] [pid 411857:tid 412087] [client 20.151.10.161:13080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/main.php"] [unique_id "al9VQy7ynBpLeKYztQO0cQAAAGI"]
[Tue Jul 21 08:17:24.123888 2026] [security2:error] [pid 411857:tid 412028] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9VRC7ynBpLeKYztQO0dQAAACc"]
[Tue Jul 21 08:17:24.174889 2026] [security2:error] [pid 402041:tid 402274] [client 152.59.34.51:49573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VRIiENNLP6XjiHQt3LAAAAfQ"]
[Tue Jul 21 08:17:24.175024 2026] [security2:error] [pid 402041:tid 402274] [client 152.59.34.51:49573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VRIiENNLP6XjiHQt3LAAAAfQ"]
[Tue Jul 21 08:17:24.364271 2026] [security2:error] [pid 402041:tid 402225] [client 20.206.105.145:25575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/inputs.php"] [unique_id "al9VRIiENNLP6XjiHQt3MQAAAcM"]
[Tue Jul 21 08:17:24.406667 2026] [security2:error] [pid 411857:tid 412089] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9VRC7ynBpLeKYztQO0fwAAAGQ"]
[Tue Jul 21 08:17:24.521192 2026] [security2:error] [pid 411857:tid 412114] [client 20.151.10.161:13145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/init.php"] [unique_id "al9VRC7ynBpLeKYztQO0gwAAAH0"]
[Tue Jul 21 08:17:24.576495 2026] [security2:error] [pid 411857:tid 412012] [client 20.226.60.151:53317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/cream1.php"] [unique_id "al9VRC7ynBpLeKYztQO0hwAAABc"]
[Tue Jul 21 08:17:24.691219 2026] [security2:error] [pid 411857:tid 412084] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9VRC7ynBpLeKYztQO0jgAAAF8"]
[Tue Jul 21 08:17:24.977100 2026] [security2:error] [pid 402041:tid 402224] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9VRIiENNLP6XjiHQt3OAAAAcI"]
[Tue Jul 21 08:17:25.038193 2026] [security2:error] [pid 411857:tid 412099] [client 38.100.221.102:18704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VRS7ynBpLeKYztQO0kgAAAG4"]
[Tue Jul 21 08:17:25.038328 2026] [security2:error] [pid 411857:tid 412099] [client 38.100.221.102:18704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VRS7ynBpLeKYztQO0kgAAAG4"]
[Tue Jul 21 08:17:25.084728 2026] [security2:error] [pid 411857:tid 412070] [client 74.249.245.134:15398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/sql.php"] [unique_id "al9VRS7ynBpLeKYztQO0lQAAAFE"]
[Tue Jul 21 08:17:25.105743 2026] [security2:error] [pid 411857:tid 412046] [client 20.151.10.161:13058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/prekel.php"] [unique_id "al9VRS7ynBpLeKYztQO0lgAAADk"]
[Tue Jul 21 08:17:25.162547 2026] [security2:error] [pid 402041:tid 402160] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VRYiENNLP6XjiHQt3PgAB-HQ"]
[Tue Jul 21 08:17:25.162702 2026] [security2:error] [pid 402041:tid 402278] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VRYiENNLP6XjiHQt3PgAB-HQ"]
[Tue Jul 21 08:17:25.173928 2026] [security2:error] [pid 402041:tid 402223] [client 20.151.10.161:46068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/xyn.php"] [unique_id "al9VRYiENNLP6XjiHQt3QQAAAcE"]
[Tue Jul 21 08:17:25.261140 2026] [security2:error] [pid 402041:tid 402295] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9VRYiENNLP6XjiHQt3RQAAAgk"]
[Tue Jul 21 08:17:25.320123 2026] [security2:error] [pid 411857:tid 412007] [client 20.151.10.161:36491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/file6.php"] [unique_id "al9VRS7ynBpLeKYztQO0mgAAABI"]
[Tue Jul 21 08:17:25.401120 2026] [security2:error] [pid 411857:tid 412096] [client 154.208.47.43:57434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VRS7ynBpLeKYztQO0nQAAAGs"]
[Tue Jul 21 08:17:25.401248 2026] [security2:error] [pid 411857:tid 412096] [client 154.208.47.43:57434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VRS7ynBpLeKYztQO0nQAAAGs"]
[Tue Jul 21 08:17:25.408484 2026] [security2:error] [pid 411857:tid 412003] [client 20.226.60.151:48892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9VRS7ynBpLeKYztQO0ngAAAA4"]
[Tue Jul 21 08:17:25.431498 2026] [autoindex:error] [pid 402041:tid 402282] [client 20.226.60.151:60328] AH01276: Cannot serve directory /home1/advcel43/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:25.540649 2026] [security2:error] [pid 411857:tid 411874] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VRS7ynBpLeKYztQO0nwAALg8"]
[Tue Jul 21 08:17:25.540831 2026] [security2:error] [pid 411857:tid 412035] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VRS7ynBpLeKYztQO0nwAALg8"]
[Tue Jul 21 08:17:25.544610 2026] [security2:error] [pid 411857:tid 412087] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9VRS7ynBpLeKYztQO0oAAAAGI"]
[Tue Jul 21 08:17:25.566090 2026] [security2:error] [pid 411857:tid 412054] [client 20.151.10.161:13300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/0.php"] [unique_id "al9VRS7ynBpLeKYztQO0oQAAAEE"]
[Tue Jul 21 08:17:25.776432 2026] [security2:error] [pid 411857:tid 412026] [client 61.1.167.83:57709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VRS7ynBpLeKYztQO0rQAAACU"]
[Tue Jul 21 08:17:25.776528 2026] [security2:error] [pid 411857:tid 412026] [client 61.1.167.83:57709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VRS7ynBpLeKYztQO0rQAAACU"]
[Tue Jul 21 08:17:25.784440 2026] [autoindex:error] [pid 402041:tid 402218] [client 20.226.60.151:60328] AH01276: Cannot serve directory /home1/advcel43/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:25.791607 2026] [security2:error] [pid 411857:tid 412060] [client 115.134.11.136:58295] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VRS7ynBpLeKYztQO0rgAAAEc"]
[Tue Jul 21 08:17:25.791764 2026] [security2:error] [pid 411857:tid 412060] [client 115.134.11.136:58295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VRS7ynBpLeKYztQO0rgAAAEc"]
[Tue Jul 21 08:17:25.791822 2026] [security2:error] [pid 402041:tid 402200] [client 20.226.60.151:60328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/dr.php"] [unique_id "al9VRYiENNLP6XjiHQt3TgAAAao"]
[Tue Jul 21 08:17:25.830738 2026] [security2:error] [pid 402041:tid 402213] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9VRYiENNLP6XjiHQt3TwAAAbc"]
[Tue Jul 21 08:17:25.941927 2026] [security2:error] [pid 411857:tid 412059] [client 20.220.225.223:31168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/x.php"] [unique_id "al9VRS7ynBpLeKYztQO0sQAAAEY"]
[Tue Jul 21 08:17:26.115479 2026] [security2:error] [pid 402041:tid 402188] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9VRoiENNLP6XjiHQt3VgAAAZ4"]
[Tue Jul 21 08:17:26.190452 2026] [security2:error] [pid 411857:tid 412107] [client 20.151.10.161:13238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/BDKR28.php"] [unique_id "al9VRi7ynBpLeKYztQO0tgAAAHY"]
[Tue Jul 21 08:17:26.223063 2026] [security2:error] [pid 411857:tid 412090] [client 20.226.60.151:52007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/x.php"] [unique_id "al9VRi7ynBpLeKYztQO0uQAAAGU"]
[Tue Jul 21 08:17:26.400324 2026] [security2:error] [pid 411857:tid 412069] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9VRi7ynBpLeKYztQO0vAAAAFA"]
[Tue Jul 21 08:17:26.416335 2026] [security2:error] [pid 411857:tid 412112] [client 20.206.105.145:25570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/av.php"] [unique_id "al9VRi7ynBpLeKYztQO0vQAAAHs"]
[Tue Jul 21 08:17:26.625366 2026] [security2:error] [pid 402041:tid 402233] [client 20.226.60.151:60321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/155.php"] [unique_id "al9VRoiENNLP6XjiHQt3XgAAAcs"]
[Tue Jul 21 08:17:26.709147 2026] [security2:error] [pid 402041:tid 402173] [client 35.252.209.37:65339] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blog.findcomp.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9VRoiENNLP6XjiHQt3YAAAAY8"]
[Tue Jul 21 08:17:26.731862 2026] [security2:error] [pid 411857:tid 412042] [client 20.151.10.161:13222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/f35.update.php"] [unique_id "al9VRi7ynBpLeKYztQO0wgAAADU"]
[Tue Jul 21 08:17:26.839792 2026] [security2:error] [pid 411857:tid 412075] [client 20.226.60.151:60336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/ops.php"] [unique_id "al9VRi7ynBpLeKYztQO0xQAAAFY"]
[Tue Jul 21 08:17:26.844775 2026] [security2:error] [pid 411857:tid 412043] [client 102.206.115.33:59345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VRi7ynBpLeKYztQO0xgAAADY"]
[Tue Jul 21 08:17:26.844880 2026] [security2:error] [pid 411857:tid 412043] [client 102.206.115.33:59345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VRi7ynBpLeKYztQO0xgAAADY"]
[Tue Jul 21 08:17:26.847072 2026] [security2:error] [pid 411857:tid 412008] [client 20.151.10.161:46054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/green3.php"] [unique_id "al9VRi7ynBpLeKYztQO0xwAAABM"]
[Tue Jul 21 08:17:26.875444 2026] [security2:error] [pid 411857:tid 411877] [remote 13.41.15.21:46550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.15.41.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9VRi7ynBpLeKYztQO0yAAAahI"]
[Tue Jul 21 08:17:27.138065 2026] [security2:error] [pid 402041:tid 402226] [client 20.151.10.161:13221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/f900.php"] [unique_id "al9VR4iENNLP6XjiHQt3bQAAAcQ"]
[Tue Jul 21 08:17:27.138914 2026] [security2:error] [pid 411857:tid 412038] [client 20.226.60.151:60295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/file31.php"] [unique_id "al9VRy7ynBpLeKYztQO0zAAAADE"]
[Tue Jul 21 08:17:27.182216 2026] [security2:error] [pid 402041:tid 402246] [client 187.125.243.197:54481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VR4iENNLP6XjiHQt3bgAAAdg"]
[Tue Jul 21 08:17:27.182347 2026] [security2:error] [pid 402041:tid 402246] [client 187.125.243.197:54481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VR4iENNLP6XjiHQt3bgAAAdg"]
[Tue Jul 21 08:17:27.276143 2026] [security2:error] [pid 411857:tid 412044] [client 20.226.60.151:51991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/file6.php"] [unique_id "al9VRy7ynBpLeKYztQO00AAAADc"]
[Tue Jul 21 08:17:27.411636 2026] [security2:error] [pid 411857:tid 412041] [client 87.116.180.198:27241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VRy7ynBpLeKYztQO00wAAADQ"]
[Tue Jul 21 08:17:27.411777 2026] [security2:error] [pid 411857:tid 412041] [client 87.116.180.198:27241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VRy7ynBpLeKYztQO00wAAADQ"]
[Tue Jul 21 08:17:27.473822 2026] [security2:error] [pid 411857:tid 412049] [client 62.102.148.158:40228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9VRy7ynBpLeKYztQO01wAAADw"]
[Tue Jul 21 08:17:27.473956 2026] [security2:error] [pid 411857:tid 412049] [client 62.102.148.158:40228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9VRy7ynBpLeKYztQO01wAAADw"]
[Tue Jul 21 08:17:27.474739 2026] [autoindex:error] [pid 402041:tid 402207] [client 20.226.60.151:60292] AH01276: Cannot serve directory /home1/advcel43/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:27.483905 2026] [security2:error] [pid 402041:tid 402241] [client 20.226.60.151:60292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/adminfuns.php"] [unique_id "al9VR4iENNLP6XjiHQt3dgAAAdM"]
[Tue Jul 21 08:17:27.730418 2026] [security2:error] [pid 402041:tid 402204] [client 20.226.60.151:60324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/goods.php"] [unique_id "al9VR4iENNLP6XjiHQt3egAAAa4"]
[Tue Jul 21 08:17:27.784800 2026] [security2:error] [pid 402041:tid 402220] [client 20.151.10.161:13212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/xmrl.php"] [unique_id "al9VR4iENNLP6XjiHQt3ewAAAb4"]
[Tue Jul 21 08:17:27.827579 2026] [security2:error] [pid 402041:tid 402217] [client 20.226.60.151:48801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9VR4iENNLP6XjiHQt3fQAAAbs"]
[Tue Jul 21 08:17:27.920444 2026] [security2:error] [pid 411857:tid 412098] [client 20.226.60.151:52016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/100.php"] [unique_id "al9VRy7ynBpLeKYztQO05QAAAG0"]
[Tue Jul 21 08:17:27.924945 2026] [security2:error] [pid 402041:tid 402222] [client 62.102.148.158:56026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9VR4iENNLP6XjiHQt3gQAAAcA"]
[Tue Jul 21 08:17:27.925015 2026] [security2:error] [pid 402041:tid 402222] [client 62.102.148.158:56026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9VR4iENNLP6XjiHQt3gQAAAcA"]
[Tue Jul 21 08:17:28.004000 2026] [security2:error] [pid 411857:tid 412066] [client 20.226.60.151:60315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/about.php"] [unique_id "al9VSC7ynBpLeKYztQO06QAAAE0"]
[Tue Jul 21 08:17:28.129067 2026] [security2:error] [pid 411857:tid 412033] [client 20.226.60.151:51969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/about.php"] [unique_id "al9VSC7ynBpLeKYztQO08QAAACw"]
[Tue Jul 21 08:17:28.158945 2026] [security2:error] [pid 411857:tid 412062] [client 20.226.60.151:60291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/admin.php"] [unique_id "al9VSC7ynBpLeKYztQO08gAAAEk"]
[Tue Jul 21 08:17:28.182013 2026] [security2:error] [pid 411857:tid 412056] [client 20.226.60.151:60311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/admin.php"] [unique_id "al9VSC7ynBpLeKYztQO09wAAAEM"]
[Tue Jul 21 08:17:28.250306 2026] [security2:error] [pid 411857:tid 412070] [client 35.252.209.37:50662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blog.findcomp.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9VSC7ynBpLeKYztQO0-QAAAFE"]
[Tue Jul 21 08:17:28.260581 2026] [security2:error] [pid 411857:tid 412046] [client 20.226.60.151:53321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/themes.php"] [unique_id "al9VSC7ynBpLeKYztQO0-gAAADk"]
[Tue Jul 21 08:17:28.336069 2026] [security2:error] [pid 402041:tid 402097] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VSIiENNLP6XjiHQt3iAABxjU"]
[Tue Jul 21 08:17:28.336205 2026] [security2:error] [pid 402041:tid 402228] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VSIiENNLP6XjiHQt3iAABxjU"]
[Tue Jul 21 08:17:28.343799 2026] [autoindex:error] [pid 411857:tid 412065] [client 20.226.60.151:60337] AH01276: Cannot serve directory /home1/advcel43/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:28.393491 2026] [security2:error] [pid 411857:tid 412104] [client 103.106.20.201:62061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VSC7ynBpLeKYztQO1AQAAAHM"]
[Tue Jul 21 08:17:28.393629 2026] [security2:error] [pid 411857:tid 412104] [client 103.106.20.201:62061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VSC7ynBpLeKYztQO1AQAAAHM"]
[Tue Jul 21 08:17:28.402435 2026] [security2:error] [pid 411857:tid 412032] [client 103.151.46.103:51462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VSC7ynBpLeKYztQO1AgAAACs"]
[Tue Jul 21 08:17:28.403744 2026] [security2:error] [pid 411857:tid 412032] [client 103.151.46.103:51462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VSC7ynBpLeKYztQO1AgAAACs"]
[Tue Jul 21 08:17:28.405336 2026] [security2:error] [pid 402041:tid 402186] [client 20.151.10.161:36417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/a2.php"] [unique_id "al9VSIiENNLP6XjiHQt3iwAAAZw"]
[Tue Jul 21 08:17:28.515554 2026] [security2:error] [pid 411857:tid 412054] [client 20.151.10.161:13155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/memberfuns.php"] [unique_id "al9VSC7ynBpLeKYztQO1BAAAAEE"]
[Tue Jul 21 08:17:28.530773 2026] [security2:error] [pid 402041:tid 402180] [client 20.151.10.161:46070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/ccs.php"] [unique_id "al9VSIiENNLP6XjiHQt3jAAAAZY"]
[Tue Jul 21 08:17:28.645588 2026] [security2:error] [pid 411857:tid 412040] [client 14.245.224.124:63240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VSC7ynBpLeKYztQO1BgAAADM"]
[Tue Jul 21 08:17:28.645707 2026] [security2:error] [pid 411857:tid 412040] [client 14.245.224.124:63240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VSC7ynBpLeKYztQO1BgAAADM"]
[Tue Jul 21 08:17:28.805186 2026] [security2:error] [pid 411857:tid 411995] [client 65.21.113.253:49342] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VSC7ynBpLeKYztQO0_QAAAAY"]
[Tue Jul 21 08:17:28.932310 2026] [security2:error] [pid 402041:tid 402190] [client 74.7.244.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "osvaldodeoliveira1752865696437.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9VSIiENNLP6XjiHQt3kwABoDg"]
[Tue Jul 21 08:17:29.066490 2026] [security2:error] [pid 411857:tid 411895] [remote 124.55.178.99:45658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-login.php"] [unique_id "al9VSS7ynBpLeKYztQO1FgAAbSQ"]
[Tue Jul 21 08:17:29.197682 2026] [security2:error] [pid 411857:tid 412002] [client 103.78.200.11:62584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VSS7ynBpLeKYztQO1GgAAAA0"]
[Tue Jul 21 08:17:29.197784 2026] [security2:error] [pid 411857:tid 412002] [client 103.78.200.11:62584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VSS7ynBpLeKYztQO1GgAAAA0"]
[Tue Jul 21 08:17:29.240176 2026] [security2:error] [pid 411857:tid 412116] [client 20.206.105.145:25564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9VSS7ynBpLeKYztQO1HAAAAH8"]
[Tue Jul 21 08:17:29.283673 2026] [security2:error] [pid 402041:tid 402291] [client 20.151.10.161:13139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/ms.php"] [unique_id "al9VSYiENNLP6XjiHQt3mAAAAgU"]
[Tue Jul 21 08:17:29.382123 2026] [security2:error] [pid 411857:tid 412018] [client 35.252.209.37:63464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blog.findcomp.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9VSS7ynBpLeKYztQO1HwAAAB0"]
[Tue Jul 21 08:17:29.516414 2026] [security2:error] [pid 411857:tid 411898] [remote 41.186.86.12:18166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9VSS7ynBpLeKYztQO1IgAARic"]
[Tue Jul 21 08:17:29.537821 2026] [security2:error] [pid 411857:tid 412060] [client 111.93.58.162:24666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VSS7ynBpLeKYztQO1JAAAAEc"]
[Tue Jul 21 08:17:29.537948 2026] [security2:error] [pid 411857:tid 412060] [client 111.93.58.162:24666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VSS7ynBpLeKYztQO1JAAAAEc"]
[Tue Jul 21 08:17:29.808619 2026] [security2:error] [pid 411857:tid 412085] [client 20.226.60.151:60337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/.well-known/about.php"] [unique_id "al9VSS7ynBpLeKYztQO1MAAAAGA"]
[Tue Jul 21 08:17:29.871274 2026] [security2:error] [pid 411857:tid 412066] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VSS7ynBpLeKYztQO1IAAAAE0"]
[Tue Jul 21 08:17:29.947750 2026] [security2:error] [pid 402041:tid 402255] [client 20.151.10.161:13195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/zz.php"] [unique_id "al9VSYiENNLP6XjiHQt3pgAAAeE"]
[Tue Jul 21 08:17:29.997535 2026] [security2:error] [pid 411857:tid 412106] [client 20.220.225.223:52654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/wp-mt.php"] [unique_id "al9VSS7ynBpLeKYztQO1OAAAAHU"]
[Tue Jul 21 08:17:30.108408 2026] [security2:error] [pid 402041:tid 402147] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VSoiENNLP6XjiHQt3qAABmmc"]
[Tue Jul 21 08:17:30.108658 2026] [security2:error] [pid 402041:tid 402184] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VSoiENNLP6XjiHQt3qAABmmc"]
[Tue Jul 21 08:17:30.174413 2026] [security2:error] [pid 402041:tid 402266] [client 20.226.60.151:48775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/media.php"] [unique_id "al9VSoiENNLP6XjiHQt3qwAAAew"]
[Tue Jul 21 08:17:30.343958 2026] [security2:error] [pid 402041:tid 402177] [client 20.226.60.151:53322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9VSoiENNLP6XjiHQt3sQAAAZM"]
[Tue Jul 21 08:17:30.413774 2026] [security2:error] [pid 411857:tid 412101] [client 114.119.155.23:42831] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pacodasrosas.com.br"] [uri "/lojas/mineiro-delivery/"] [unique_id "al9VSi7ynBpLeKYztQO1QgAAAHA"], referer: https://pacodasrosas.com.br/lojas/page/3/
[Tue Jul 21 08:17:30.494019 2026] [security2:error] [pid 402041:tid 402181] [client 20.151.10.161:13086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/for.php"] [unique_id "al9VSoiENNLP6XjiHQt3tQAAAZc"]
[Tue Jul 21 08:17:30.621054 2026] [security2:error] [pid 402041:tid 402241] [client 35.252.209.37:64619] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "blog.findcomp.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9VSoiENNLP6XjiHQt3twAAAdM"]
[Tue Jul 21 08:17:30.675053 2026] [security2:error] [pid 411857:tid 412109] [client 20.151.10.161:46034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/ccc.php"] [unique_id "al9VSi7ynBpLeKYztQO1SAAAAHg"]
[Tue Jul 21 08:17:30.818008 2026] [security2:error] [pid 411857:tid 412094] [client 20.226.60.151:60290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/wefile.php"] [unique_id "al9VSi7ynBpLeKYztQO1UQAAAGk"]
[Tue Jul 21 08:17:30.911531 2026] [security2:error] [pid 402041:tid 402274] [client 74.249.245.134:31389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/up.php"] [unique_id "al9VSoiENNLP6XjiHQt3vAAAAfQ"]
[Tue Jul 21 08:17:31.025822 2026] [security2:error] [pid 411857:tid 412112] [client 20.220.225.223:31191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9VSy7ynBpLeKYztQO1VAAAAHs"]
[Tue Jul 21 08:17:31.033497 2026] [security2:error] [pid 402041:tid 402242] [client 47.128.97.213:50244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "anabeatrizpsicologa.com.br"] [uri "/robots.txt"] [unique_id "al9VS4iENNLP6XjiHQt3vwAAAdQ"]
[Tue Jul 21 08:17:31.204131 2026] [security2:error] [pid 402041:tid 402227] [client 150.129.202.39:65425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VS4iENNLP6XjiHQt3xQAAAcU"]
[Tue Jul 21 08:17:31.204229 2026] [security2:error] [pid 402041:tid 402227] [client 150.129.202.39:65425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VS4iENNLP6XjiHQt3xQAAAcU"]
[Tue Jul 21 08:17:31.434923 2026] [security2:error] [pid 411857:tid 412104] [client 20.226.60.151:60345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9VSy7ynBpLeKYztQO1XgAAAHM"]
[Tue Jul 21 08:17:31.490925 2026] [security2:error] [pid 411857:tid 411992] [client 20.151.10.161:13062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/yup.php"] [unique_id "al9VSy7ynBpLeKYztQO1XwAAAAM"]
[Tue Jul 21 08:17:31.513186 2026] [security2:error] [pid 411857:tid 412096] [client 20.220.225.223:58937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/ww.php"] [unique_id "al9VSy7ynBpLeKYztQO1YQAAAGs"]
[Tue Jul 21 08:17:31.611335 2026] [autoindex:error] [pid 411857:tid 412106] [client 20.226.60.151:52000] AH01276: Cannot serve directory /home1/advcel43/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:31.667054 2026] [security2:error] [pid 411857:tid 412084] [client 151.63.71.144:52120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9VSy7ynBpLeKYztQO1aAAAAF8"]
[Tue Jul 21 08:17:31.667252 2026] [security2:error] [pid 411857:tid 412084] [client 151.63.71.144:52120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9VSy7ynBpLeKYztQO1aAAAAF8"]
[Tue Jul 21 08:17:31.677162 2026] [autoindex:error] [pid 411857:tid 412050] [client 20.226.60.151:52000] AH01276: Cannot serve directory /home1/advcel43/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:31.702350 2026] [security2:error] [pid 411857:tid 412113] [client 20.226.60.151:52000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9VSy7ynBpLeKYztQO1bAAAAHw"]
[Tue Jul 21 08:17:31.705009 2026] [security2:error] [pid 411857:tid 412059] [client 120.56.162.40:53999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VSy7ynBpLeKYztQO1bgAAAEY"]
[Tue Jul 21 08:17:31.705099 2026] [security2:error] [pid 411857:tid 412059] [client 120.56.162.40:53999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VSy7ynBpLeKYztQO1bgAAAEY"]
[Tue Jul 21 08:17:31.728539 2026] [security2:error] [pid 402041:tid 402204] [client 117.210.135.0:62860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VS4iENNLP6XjiHQt31gAAAa4"]
[Tue Jul 21 08:17:31.729174 2026] [security2:error] [pid 402041:tid 402204] [client 117.210.135.0:62860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VS4iENNLP6XjiHQt31gAAAa4"]
[Tue Jul 21 08:17:31.842509 2026] [security2:error] [pid 402041:tid 402215] [client 20.226.60.151:52019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/8.php"] [unique_id "al9VS4iENNLP6XjiHQt32gAAAbk"]
[Tue Jul 21 08:17:31.918405 2026] [security2:error] [pid 411857:tid 412008] [client 20.226.60.151:60349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9VSy7ynBpLeKYztQO1dQAAABM"]
[Tue Jul 21 08:17:32.032312 2026] [security2:error] [pid 402041:tid 402105] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VTIiENNLP6XjiHQt33QAB8D0"]
[Tue Jul 21 08:17:32.032531 2026] [security2:error] [pid 402041:tid 402270] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VTIiENNLP6XjiHQt33QAB8D0"]
[Tue Jul 21 08:17:32.141891 2026] [security2:error] [pid 402041:tid 402250] [client 20.226.60.151:53346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/f6.php"] [unique_id "al9VTIiENNLP6XjiHQt34AAAAdw"]
[Tue Jul 21 08:17:32.194921 2026] [security2:error] [pid 411857:tid 412028] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VSy7ynBpLeKYztQO1bwAAACc"]
[Tue Jul 21 08:17:32.453749 2026] [security2:error] [pid 402041:tid 402057] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VTIiENNLP6XjiHQt36AAB-w0"]
[Tue Jul 21 08:17:32.453902 2026] [security2:error] [pid 402041:tid 402281] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VTIiENNLP6XjiHQt36AAB-w0"]
[Tue Jul 21 08:17:32.541547 2026] [security2:error] [pid 411857:tid 411997] [client 20.151.10.161:13219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/wpxml.php"] [unique_id "al9VTC7ynBpLeKYztQO1gAAAAAg"]
[Tue Jul 21 08:17:32.728400 2026] [security2:error] [pid 411857:tid 412071] [client 20.226.60.151:51989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/inputs.php"] [unique_id "al9VTC7ynBpLeKYztQO1hgAAAFI"]
[Tue Jul 21 08:17:32.847007 2026] [security2:error] [pid 402041:tid 402249] [client 20.197.192.193:60659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9VTIiENNLP6XjiHQt38wAAAds"]
[Tue Jul 21 08:17:33.026552 2026] [security2:error] [pid 411857:tid 412016] [client 20.220.225.223:24260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/ah25.php"] [unique_id "al9VTS7ynBpLeKYztQO1iwAAABs"]
[Tue Jul 21 08:17:33.051325 2026] [security2:error] [pid 411857:tid 412081] [client 74.249.245.134:15370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/66.php"] [unique_id "al9VTS7ynBpLeKYztQO1jQAAAFw"]
[Tue Jul 21 08:17:33.056937 2026] [security2:error] [pid 411857:tid 411921] [remote 45.90.123.233:50386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bestsellerdigital.com.br"] [uri "/wp-login.php"] [unique_id "al9VTS7ynBpLeKYztQO1jgAAaD4"]
[Tue Jul 21 08:17:33.096597 2026] [security2:error] [pid 402041:tid 402229] [client 20.151.10.161:36537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/file15.php"] [unique_id "al9VTYiENNLP6XjiHQt3-AAAAcc"]
[Tue Jul 21 08:17:33.113837 2026] [security2:error] [pid 402041:tid 402199] [client 20.151.10.161:46043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/get.php"] [unique_id "al9VTYiENNLP6XjiHQt3-QAAAak"]
[Tue Jul 21 08:17:33.309800 2026] [security2:error] [pid 411857:tid 412034] [client 20.151.10.161:13303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/fffm.php"] [unique_id "al9VTS7ynBpLeKYztQO1lQAAAC0"]
[Tue Jul 21 08:17:33.539545 2026] [security2:error] [pid 411857:tid 412058] [client 20.226.60.151:51992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/inputs.php"] [unique_id "al9VTS7ynBpLeKYztQO1nQAAAEU"]
[Tue Jul 21 08:17:33.618830 2026] [security2:error] [pid 411857:tid 412083] [client 20.220.225.223:38711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/ee.php"] [unique_id "al9VTS7ynBpLeKYztQO1nwAAAF4"]
[Tue Jul 21 08:17:33.799197 2026] [security2:error] [pid 411857:tid 412059] [client 20.197.192.193:60617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9VTS7ynBpLeKYztQO1pQAAAEY"]
[Tue Jul 21 08:17:33.840526 2026] [security2:error] [pid 411857:tid 412032] [client 20.206.105.145:25599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9VTS7ynBpLeKYztQO1pgAAACs"]
[Tue Jul 21 08:17:33.922958 2026] [security2:error] [pid 402041:tid 402189] [client 20.151.10.161:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/images.php"] [unique_id "al9VTYiENNLP6XjiHQt4CgAAAZ8"]
[Tue Jul 21 08:17:33.981151 2026] [security2:error] [pid 411857:tid 412006] [client 20.151.10.161:13148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/gecko.php"] [unique_id "al9VTS7ynBpLeKYztQO1qgAAABE"]
[Tue Jul 21 08:17:34.286553 2026] [security2:error] [pid 402041:tid 402222] [client 223.181.60.88:2952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VToiENNLP6XjiHQt4DwAAAcA"]
[Tue Jul 21 08:17:34.286671 2026] [security2:error] [pid 402041:tid 402222] [client 223.181.60.88:2952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VToiENNLP6XjiHQt4DwAAAcA"]
[Tue Jul 21 08:17:34.296922 2026] [security2:error] [pid 411857:tid 412097] [client 20.226.60.151:53312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/classwithtostring.php"] [unique_id "al9VTi7ynBpLeKYztQO1tQAAAGw"]
[Tue Jul 21 08:17:34.422621 2026] [security2:error] [pid 402041:tid 402176] [client 20.151.10.161:13225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/a1.php"] [unique_id "al9VToiENNLP6XjiHQt4FQAAAZI"]
[Tue Jul 21 08:17:34.470235 2026] [security2:error] [pid 411857:tid 411995] [client 20.197.192.193:13025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/fz.php"] [unique_id "al9VTi7ynBpLeKYztQO1ugAAAAY"]
[Tue Jul 21 08:17:34.537633 2026] [security2:error] [pid 402041:tid 402256] [client 20.220.225.223:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/cron.php"] [unique_id "al9VToiENNLP6XjiHQt4GgAAAeI"]
[Tue Jul 21 08:17:34.544450 2026] [security2:error] [pid 402041:tid 402279] [client 20.226.60.151:60316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9VToiENNLP6XjiHQt4GwAAAfk"]
[Tue Jul 21 08:17:34.763004 2026] [security2:error] [pid 411857:tid 412060] [client 20.226.60.151:60318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/wp-blog.php"] [unique_id "al9VTi7ynBpLeKYztQO1xAAAAEc"]
[Tue Jul 21 08:17:34.827045 2026] [security2:error] [pid 411857:tid 412019] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VTi7ynBpLeKYztQO1twAAAB4"]
[Tue Jul 21 08:17:34.885793 2026] [core:error] [pid 411857:tid 412000] [client 66.249.66.69:47753] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:17:34.885836 2026] [core:error] [pid 411857:tid 412000] [client 66.249.66.69:47753] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:17:34.898857 2026] [security2:error] [pid 411857:tid 412057] [client 20.226.60.151:48832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/images.php"] [unique_id "al9VTi7ynBpLeKYztQO1yQAAAEQ"]
[Tue Jul 21 08:17:34.948688 2026] [security2:error] [pid 402041:tid 402276] [client 20.151.10.161:13100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/k2.php"] [unique_id "al9VToiENNLP6XjiHQt4JAAAAfY"]
[Tue Jul 21 08:17:35.323723 2026] [security2:error] [pid 402041:tid 402238] [client 20.197.192.193:38913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/dp.php"] [unique_id "al9VT4iENNLP6XjiHQt4LAAAAdA"]
[Tue Jul 21 08:17:35.355498 2026] [security2:error] [pid 402041:tid 402290] [client 152.59.34.51:50014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VT4iENNLP6XjiHQt4LQAAAgQ"]
[Tue Jul 21 08:17:35.355627 2026] [security2:error] [pid 402041:tid 402290] [client 152.59.34.51:50014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VT4iENNLP6XjiHQt4LQAAAgQ"]
[Tue Jul 21 08:17:35.390607 2026] [autoindex:error] [pid 411857:tid 412054] [client 20.226.60.151:52229] AH01276: Cannot serve directory /home1/advcel43/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:35.403210 2026] [security2:error] [pid 411857:tid 412106] [client 20.226.60.151:52229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9VTy7ynBpLeKYztQO13wAAAHU"]
[Tue Jul 21 08:17:35.514823 2026] [security2:error] [pid 411857:tid 412049] [client 20.206.105.145:25121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wp-blog.php"] [unique_id "al9VTy7ynBpLeKYztQO14QAAADw"]
[Tue Jul 21 08:17:35.517855 2026] [security2:error] [pid 402041:tid 402220] [client 20.151.10.161:13298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/82.php"] [unique_id "al9VT4iENNLP6XjiHQt4MwAAAb4"]
[Tue Jul 21 08:17:35.555884 2026] [security2:error] [pid 411857:tid 412014] [client 20.151.10.161:51083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/jp.php"] [unique_id "al9VTy7ynBpLeKYztQO14gAAABk"]
[Tue Jul 21 08:17:35.665419 2026] [security2:error] [pid 402041:tid 402079] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VT4iENNLP6XjiHQt4NQAB0iM"]
[Tue Jul 21 08:17:35.665600 2026] [security2:error] [pid 402041:tid 402240] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VT4iENNLP6XjiHQt4NQAB0iM"]
[Tue Jul 21 08:17:35.702904 2026] [security2:error] [pid 402041:tid 402246] [client 38.100.221.102:18542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VT4iENNLP6XjiHQt4OQAAAdg"]
[Tue Jul 21 08:17:35.703304 2026] [security2:error] [pid 402041:tid 402246] [client 38.100.221.102:18542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VT4iENNLP6XjiHQt4OQAAAdg"]
[Tue Jul 21 08:17:35.877120 2026] [security2:error] [pid 402041:tid 402299] [client 20.151.10.161:46073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/alls.php"] [unique_id "al9VT4iENNLP6XjiHQt4RAAAAg0"]
[Tue Jul 21 08:17:36.065926 2026] [security2:error] [pid 411857:tid 412005] [client 20.220.225.223:38708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/blue.php"] [unique_id "al9VUC7ynBpLeKYztQO1-QAAABA"]
[Tue Jul 21 08:17:36.090116 2026] [security2:error] [pid 402041:tid 402275] [client 20.151.10.161:13137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/config.json.php"] [unique_id "al9VUIiENNLP6XjiHQt4TgAAAfU"]
[Tue Jul 21 08:17:36.174628 2026] [security2:error] [pid 402041:tid 402158] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VUIiENNLP6XjiHQt4UQAB8XI"]
[Tue Jul 21 08:17:36.174790 2026] [security2:error] [pid 402041:tid 402271] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VUIiENNLP6XjiHQt4UQAB8XI"]
[Tue Jul 21 08:17:36.175449 2026] [security2:error] [pid 402041:tid 402267] [client 154.208.47.43:58161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VUIiENNLP6XjiHQt4UgAAAe0"]
[Tue Jul 21 08:17:36.175560 2026] [security2:error] [pid 402041:tid 402267] [client 154.208.47.43:58161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VUIiENNLP6XjiHQt4UgAAAe0"]
[Tue Jul 21 08:17:36.220508 2026] [security2:error] [pid 411857:tid 412066] [client 74.249.245.134:15402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/666.php"] [unique_id "al9VUC7ynBpLeKYztQO1-wAAAE0"]
[Tue Jul 21 08:17:36.269370 2026] [security2:error] [pid 402041:tid 402245] [client 20.151.10.161:36501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/f35.php"] [unique_id "al9VUIiENNLP6XjiHQt4VwAAAdc"]
[Tue Jul 21 08:17:36.563567 2026] [security2:error] [pid 411857:tid 412071] [client 20.151.10.161:13257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.lasferas.com"] [uri "/fpwch.php"] [unique_id "al9VUC7ynBpLeKYztQO2AgAAAFI"]
[Tue Jul 21 08:17:36.639625 2026] [security2:error] [pid 411857:tid 412111] [client 20.197.192.193:13040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/la.php"] [unique_id "al9VUC7ynBpLeKYztQO2BAAAAHo"]
[Tue Jul 21 08:17:36.722850 2026] [security2:error] [pid 411857:tid 412056] [client 20.151.10.161:46004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/yyu.php"] [unique_id "al9VUC7ynBpLeKYztQO2BwAAAEM"]
[Tue Jul 21 08:17:36.789134 2026] [security2:error] [pid 411857:tid 412019] [client 20.151.10.161:36541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-load.php"] [unique_id "al9VUC7ynBpLeKYztQO2CwAAAB4"]
[Tue Jul 21 08:17:36.805752 2026] [security2:error] [pid 411857:tid 412057] [client 20.226.60.151:51996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/ms-edit.php"] [unique_id "al9VUC7ynBpLeKYztQO2DAAAAEQ"]
[Tue Jul 21 08:17:36.825732 2026] [security2:error] [pid 411857:tid 412093] [client 20.197.192.193:38930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/old.php"] [unique_id "al9VUC7ynBpLeKYztQO2DQAAAGg"]
[Tue Jul 21 08:17:37.071981 2026] [security2:error] [pid 411857:tid 412106] [client 20.206.105.145:25573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9VUS7ynBpLeKYztQO2HwAAAHU"]
[Tue Jul 21 08:17:37.100011 2026] [security2:error] [pid 411857:tid 411998] [client 162.219.176.3:60862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9VUS7ynBpLeKYztQO2IQAAAAk"]
[Tue Jul 21 08:17:37.100099 2026] [security2:error] [pid 411857:tid 411998] [client 162.219.176.3:60862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9VUS7ynBpLeKYztQO2IQAAAAk"]
[Tue Jul 21 08:17:37.209759 2026] [security2:error] [pid 411857:tid 412041] [client 20.197.192.193:60662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/ms-new.php"] [unique_id "al9VUS7ynBpLeKYztQO2KwAAADQ"]
[Tue Jul 21 08:17:37.249735 2026] [rewrite:warn] [pid 411857:tid 411979] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:17:37.305610 2026] [security2:error] [pid 411857:tid 412095] [client 20.151.10.161:36585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/xwpg.php"] [unique_id "al9VUS7ynBpLeKYztQO2NQAAAGo"]
[Tue Jul 21 08:17:37.333296 2026] [security2:error] [pid 402041:tid 402292] [client 103.151.46.103:51953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VUYiENNLP6XjiHQt4YAAAAgY"]
[Tue Jul 21 08:17:37.333851 2026] [security2:error] [pid 402041:tid 402292] [client 103.151.46.103:51953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VUYiENNLP6XjiHQt4YAAAAgY"]
[Tue Jul 21 08:17:37.394594 2026] [security2:error] [pid 411857:tid 412048] [client 20.197.192.193:60614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/track.php"] [unique_id "al9VUS7ynBpLeKYztQO2PgAAADs"]
[Tue Jul 21 08:17:37.400873 2026] [security2:error] [pid 411857:tid 411989] [client 20.220.225.223:38674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wp-signup.php"] [unique_id "al9VUS7ynBpLeKYztQO2QQAAAAA"]
[Tue Jul 21 08:17:37.481788 2026] [security2:error] [pid 411857:tid 412072] [client 20.197.192.193:13634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9VUS7ynBpLeKYztQO2RAAAAFM"]
[Tue Jul 21 08:17:37.558069 2026] [security2:error] [pid 411857:tid 412000] [client 102.206.115.33:65207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VUS7ynBpLeKYztQO2RQAAAAs"]
[Tue Jul 21 08:17:37.558223 2026] [security2:error] [pid 411857:tid 412000] [client 102.206.115.33:65207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VUS7ynBpLeKYztQO2RQAAAAs"]
[Tue Jul 21 08:17:37.610607 2026] [security2:error] [pid 411857:tid 412085] [client 20.151.10.161:45957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/by.php"] [unique_id "al9VUS7ynBpLeKYztQO2SgAAAGA"]
[Tue Jul 21 08:17:37.622541 2026] [security2:error] [pid 411857:tid 411995] [client 20.226.60.151:48870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/gecko.php"] [unique_id "al9VUS7ynBpLeKYztQO2TAAAAAY"]
[Tue Jul 21 08:17:37.669687 2026] [security2:error] [pid 411857:tid 412066] [client 187.125.243.197:54984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VUS7ynBpLeKYztQO2TQAAAE0"]
[Tue Jul 21 08:17:37.669845 2026] [security2:error] [pid 411857:tid 412066] [client 187.125.243.197:54984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VUS7ynBpLeKYztQO2TQAAAE0"]
[Tue Jul 21 08:17:37.702269 2026] [security2:error] [pid 411857:tid 412062] [client 20.197.192.193:38936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/2352356666.php"] [unique_id "al9VUS7ynBpLeKYztQO2TgAAAEk"]
[Tue Jul 21 08:17:37.706133 2026] [security2:error] [pid 411857:tid 412076] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VUS7ynBpLeKYztQO2NAAAAFc"]
[Tue Jul 21 08:17:37.836185 2026] [security2:error] [pid 411857:tid 412116] [client 103.78.200.11:63080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VUS7ynBpLeKYztQO2VQAAAH8"]
[Tue Jul 21 08:17:37.836360 2026] [security2:error] [pid 411857:tid 412116] [client 103.78.200.11:63080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VUS7ynBpLeKYztQO2VQAAAH8"]
[Tue Jul 21 08:17:37.888941 2026] [security2:error] [pid 411857:tid 412034] [client 20.197.192.193:12997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/inso.php"] [unique_id "al9VUS7ynBpLeKYztQO2WgAAAC0"]
[Tue Jul 21 08:17:37.896952 2026] [security2:error] [pid 411857:tid 412050] [client 74.7.241.181:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fnk.org.br"] [uri "/index.php"] [unique_id "al9VUS7ynBpLeKYztQO2KAAAAD0"]
[Tue Jul 21 08:17:37.897857 2026] [security2:error] [pid 411857:tid 412055] [client 74.7.241.181:33398] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fnk.org.br"] [uri "/robots.txt"] [unique_id "al9VUS7ynBpLeKYztQO2JQAAQnE"]
[Tue Jul 21 08:17:37.951935 2026] [security2:error] [pid 411857:tid 412065] [client 20.197.192.193:60658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/pn.php"] [unique_id "al9VUS7ynBpLeKYztQO2YAAAAEw"]
[Tue Jul 21 08:17:37.984541 2026] [security2:error] [pid 411857:tid 412113] [client 20.197.192.193:13664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/wpx.php"] [unique_id "al9VUS7ynBpLeKYztQO2YQAAAHw"]
[Tue Jul 21 08:17:38.084110 2026] [security2:error] [pid 411857:tid 412002] [client 87.116.180.198:14044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VUi7ynBpLeKYztQO2aQAAAA0"]
[Tue Jul 21 08:17:38.084236 2026] [security2:error] [pid 411857:tid 412002] [client 87.116.180.198:14044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VUi7ynBpLeKYztQO2aQAAAA0"]
[Tue Jul 21 08:17:38.155985 2026] [security2:error] [pid 411857:tid 412114] [client 20.197.192.193:13668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/berlin.php"] [unique_id "al9VUi7ynBpLeKYztQO2dAAAAH0"]
[Tue Jul 21 08:17:38.360544 2026] [security2:error] [pid 411857:tid 412023] [client 20.151.10.161:46065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/FAQ.php"] [unique_id "al9VUi7ynBpLeKYztQO2gAAAACI"]
[Tue Jul 21 08:17:38.509254 2026] [security2:error] [pid 411857:tid 412050] [client 20.206.105.145:25552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/adminfuns.php"] [unique_id "al9VUi7ynBpLeKYztQO2jAAAAD0"]
[Tue Jul 21 08:17:38.511788 2026] [security2:error] [pid 411857:tid 412084] [client 20.151.10.161:36531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/waf.php"] [unique_id "al9VUi7ynBpLeKYztQO2jQAAAF8"]
[Tue Jul 21 08:17:38.561210 2026] [security2:error] [pid 411857:tid 412083] [client 20.226.60.151:60341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9VUi7ynBpLeKYztQO2kQAAAF4"]
[Tue Jul 21 08:17:38.576986 2026] [security2:error] [pid 411857:tid 411992] [client 20.197.192.193:38930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-wpbak.php"] [unique_id "al9VUi7ynBpLeKYztQO2kgAAAAM"]
[Tue Jul 21 08:17:38.737546 2026] [security2:error] [pid 411857:tid 412041] [client 20.197.192.193:13006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/billur.php"] [unique_id "al9VUi7ynBpLeKYztQO2mQAAADQ"]
[Tue Jul 21 08:17:38.801780 2026] [security2:error] [pid 411857:tid 411876] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VUi7ynBpLeKYztQO2nAAAKRE"]
[Tue Jul 21 08:17:38.801906 2026] [security2:error] [pid 411857:tid 412030] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VUi7ynBpLeKYztQO2nAAAKRE"]
[Tue Jul 21 08:17:38.830765 2026] [autoindex:error] [pid 411857:tid 412032] [client 20.226.60.151:52252] AH01276: Cannot serve directory /home1/advcel43/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:38.840595 2026] [security2:error] [pid 411857:tid 412082] [client 20.226.60.151:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9VUi7ynBpLeKYztQO2oAAAAF0"]
[Tue Jul 21 08:17:38.926154 2026] [autoindex:error] [pid 411857:tid 411994] [client 20.226.60.151:52022] AH01276: Cannot serve directory /home1/advcel43/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:38.971729 2026] [autoindex:error] [pid 411857:tid 411991] [client 20.226.60.151:52022] AH01276: Cannot serve directory /home1/advcel43/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:38.985966 2026] [security2:error] [pid 411857:tid 412089] [client 20.226.60.151:52022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/abcd.php"] [unique_id "al9VUi7ynBpLeKYztQO2qgAAAGQ"]
[Tue Jul 21 08:17:38.995753 2026] [security2:error] [pid 411857:tid 412025] [client 20.206.105.145:25500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/goods.php"] [unique_id "al9VUi7ynBpLeKYztQO2qwAAACQ"]
[Tue Jul 21 08:17:39.040781 2026] [security2:error] [pid 411857:tid 412069] [client 20.197.192.193:13718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/mimpi.php"] [unique_id "al9VUy7ynBpLeKYztQO2rgAAAFA"]
[Tue Jul 21 08:17:39.067412 2026] [security2:error] [pid 411857:tid 411995] [client 20.226.60.151:48807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/82.php"] [unique_id "al9VUy7ynBpLeKYztQO2rwAAAAY"]
[Tue Jul 21 08:17:39.084290 2026] [security2:error] [pid 411857:tid 412061] [client 103.106.20.201:62640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VUy7ynBpLeKYztQO2sQAAAEg"]
[Tue Jul 21 08:17:39.084419 2026] [security2:error] [pid 411857:tid 412061] [client 103.106.20.201:62640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VUy7ynBpLeKYztQO2sQAAAEg"]
[Tue Jul 21 08:17:39.101747 2026] [security2:error] [pid 411857:tid 412110] [client 20.151.10.161:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/coffexium.php"] [unique_id "al9VUy7ynBpLeKYztQO2sgAAAHk"]
[Tue Jul 21 08:17:39.247741 2026] [security2:error] [pid 411857:tid 412105] [client 14.245.224.124:63672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VUy7ynBpLeKYztQO2vQAAAHQ"]
[Tue Jul 21 08:17:39.247840 2026] [security2:error] [pid 411857:tid 412105] [client 14.245.224.124:63672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VUy7ynBpLeKYztQO2vQAAAHQ"]
[Tue Jul 21 08:17:39.296466 2026] [security2:error] [pid 411857:tid 412043] [client 20.197.192.193:13684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/dp.php"] [unique_id "al9VUy7ynBpLeKYztQO2wQAAADY"]
[Tue Jul 21 08:17:39.346725 2026] [security2:error] [pid 411857:tid 412024] [client 20.226.60.151:60332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/file15.php"] [unique_id "al9VUy7ynBpLeKYztQO2wgAAACM"]
[Tue Jul 21 08:17:39.403687 2026] [security2:error] [pid 411857:tid 411996] [client 20.197.192.193:13013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/bootstrap.php"] [unique_id "al9VUy7ynBpLeKYztQO2xgAAAAc"]
[Tue Jul 21 08:17:39.470549 2026] [security2:error] [pid 411857:tid 412106] [client 20.197.192.193:13731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/wp-editor.php"] [unique_id "al9VUy7ynBpLeKYztQO2ywAAAHU"]
[Tue Jul 21 08:17:39.478878 2026] [security2:error] [pid 411857:tid 411993] [client 20.226.60.151:52004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/jp.php"] [unique_id "al9VUy7ynBpLeKYztQO2zAAAAAQ"]
[Tue Jul 21 08:17:39.493546 2026] [security2:error] [pid 411857:tid 412086] [client 20.151.10.161:36547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/xstelth.php"] [unique_id "al9VUy7ynBpLeKYztQO2zwAAAGE"]
[Tue Jul 21 08:17:39.518590 2026] [security2:error] [pid 411857:tid 412076] [client 20.226.60.151:51987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/f35.php"] [unique_id "al9VUy7ynBpLeKYztQO20gAAAFc"]
[Tue Jul 21 08:17:39.564647 2026] [security2:error] [pid 411857:tid 412051] [client 20.226.60.151:60331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/wp-load.php"] [unique_id "al9VUy7ynBpLeKYztQO21AAAAD4"]
[Tue Jul 21 08:17:39.568791 2026] [security2:error] [pid 411857:tid 412099] [client 20.197.192.193:13666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/cro.php"] [unique_id "al9VUy7ynBpLeKYztQO21QAAAG4"]
[Tue Jul 21 08:17:39.686235 2026] [security2:error] [pid 411857:tid 412068] [client 20.197.192.193:38921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/dr.php"] [unique_id "al9VUy7ynBpLeKYztQO23AAAAE8"]
[Tue Jul 21 08:17:39.799023 2026] [security2:error] [pid 411857:tid 412005] [client 20.206.105.145:25594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/ms-edit.php"] [unique_id "al9VUy7ynBpLeKYztQO25QAAABA"]
[Tue Jul 21 08:17:39.809444 2026] [security2:error] [pid 411857:tid 412028] [client 20.226.60.151:60301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/xyn.php"] [unique_id "al9VUy7ynBpLeKYztQO25gAAACc"]
[Tue Jul 21 08:17:39.954965 2026] [security2:error] [pid 411857:tid 412081] [client 74.249.245.134:15142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/byp.php"] [unique_id "al9VUy7ynBpLeKYztQO27gAAAFw"]
[Tue Jul 21 08:17:39.967110 2026] [security2:error] [pid 411857:tid 412069] [client 20.151.10.161:51104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-links.php"] [unique_id "al9VUy7ynBpLeKYztQO27wAAAFA"]
[Tue Jul 21 08:17:39.979402 2026] [autoindex:error] [pid 411857:tid 411997] [client 20.226.60.151:60299] AH01276: Cannot serve directory /home1/advcel43/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:40.021078 2026] [security2:error] [pid 411857:tid 412091] [client 20.226.60.151:48790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/admin.php"] [unique_id "al9VVC7ynBpLeKYztQO29gAAAGY"]
[Tue Jul 21 08:17:40.029489 2026] [security2:error] [pid 411857:tid 412010] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VUy7ynBpLeKYztQO21gAAABU"]
[Tue Jul 21 08:17:40.045339 2026] [autoindex:error] [pid 411857:tid 412104] [client 20.226.60.151:60299] AH01276: Cannot serve directory /home1/advcel43/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:40.051208 2026] [security2:error] [pid 411857:tid 412027] [client 20.226.60.151:60299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/ccc.php"] [unique_id "al9VVC7ynBpLeKYztQO2-AAAACY"]
[Tue Jul 21 08:17:40.158346 2026] [security2:error] [pid 411857:tid 412023] [client 20.226.60.151:52240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/w.php"] [unique_id "al9VVC7ynBpLeKYztQO2-wAAACI"]
[Tue Jul 21 08:17:40.197387 2026] [security2:error] [pid 411857:tid 412090] [client 111.93.58.162:41678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VVC7ynBpLeKYztQO2_QAAAGU"]
[Tue Jul 21 08:17:40.197528 2026] [security2:error] [pid 411857:tid 412090] [client 111.93.58.162:41678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VVC7ynBpLeKYztQO2_QAAAGU"]
[Tue Jul 21 08:17:40.325417 2026] [security2:error] [pid 411857:tid 412018] [client 20.220.225.223:24271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/8.php"] [unique_id "al9VVC7ynBpLeKYztQO3BQAAAB0"]
[Tue Jul 21 08:17:40.338400 2026] [security2:error] [pid 411857:tid 412024] [client 20.226.60.151:52024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9VVC7ynBpLeKYztQO3BgAAACM"]
[Tue Jul 21 08:17:40.379557 2026] [security2:error] [pid 411857:tid 412084] [client 20.197.192.193:13656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/cron-tab.php"] [unique_id "al9VVC7ynBpLeKYztQO3CAAAAF8"]
[Tue Jul 21 08:17:40.540603 2026] [security2:error] [pid 411857:tid 412086] [client 20.226.60.151:60326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/FWAZ.php"] [unique_id "al9VVC7ynBpLeKYztQO3EQAAAGE"]
[Tue Jul 21 08:17:40.616109 2026] [security2:error] [pid 411857:tid 412054] [client 20.197.192.193:38967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/2x.php"] [unique_id "al9VVC7ynBpLeKYztQO3FgAAAEE"]
[Tue Jul 21 08:17:40.724159 2026] [security2:error] [pid 411857:tid 411909] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VVC7ynBpLeKYztQO3GAAADzI"]
[Tue Jul 21 08:17:40.724341 2026] [security2:error] [pid 411857:tid 412004] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VVC7ynBpLeKYztQO3GAAADzI"]
[Tue Jul 21 08:17:40.728764 2026] [security2:error] [pid 411857:tid 412044] [client 20.206.105.145:25105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/222.php"] [unique_id "al9VVC7ynBpLeKYztQO3GgAAADc"]
[Tue Jul 21 08:17:40.775848 2026] [security2:error] [pid 411857:tid 412072] [client 62.102.148.158:38292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9VVC7ynBpLeKYztQO3IAAAAFM"]
[Tue Jul 21 08:17:40.775989 2026] [security2:error] [pid 411857:tid 412072] [client 62.102.148.158:38292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9VVC7ynBpLeKYztQO3IAAAAFM"]
[Tue Jul 21 08:17:40.776640 2026] [security2:error] [pid 411857:tid 412089] [client 20.151.10.161:36443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9VVC7ynBpLeKYztQO3IQAAAGQ"]
[Tue Jul 21 08:17:40.903666 2026] [security2:error] [pid 411857:tid 412110] [client 20.226.60.151:2896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/miru1.php"] [unique_id "al9VVC7ynBpLeKYztQO3JQAAAHk"]
[Tue Jul 21 08:17:41.005404 2026] [security2:error] [pid 411857:tid 412085] [client 74.249.245.134:15110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/date.php"] [unique_id "al9VVS7ynBpLeKYztQO3KwAAAGA"]
[Tue Jul 21 08:17:41.069029 2026] [security2:error] [pid 411857:tid 412022] [client 115.134.11.136:59120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VVS7ynBpLeKYztQO3LAAAACE"]
[Tue Jul 21 08:17:41.069211 2026] [security2:error] [pid 411857:tid 412022] [client 115.134.11.136:59120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VVS7ynBpLeKYztQO3LAAAACE"]
[Tue Jul 21 08:17:41.081267 2026] [security2:error] [pid 411857:tid 412090] [client 20.197.192.193:38957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/kq1.php"] [unique_id "al9VVS7ynBpLeKYztQO3LQAAAGU"]
[Tue Jul 21 08:17:41.087824 2026] [security2:error] [pid 411857:tid 412073] [client 20.226.60.151:52002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/aa.php"] [unique_id "al9VVS7ynBpLeKYztQO3MAAAAFQ"]
[Tue Jul 21 08:17:41.088402 2026] [security2:error] [pid 411857:tid 412062] [client 20.151.10.161:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/red.php"] [unique_id "al9VVS7ynBpLeKYztQO3MQAAAEk"]
[Tue Jul 21 08:17:41.118295 2026] [security2:error] [pid 411857:tid 412070] [client 20.226.60.151:51998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/122.php"] [unique_id "al9VVS7ynBpLeKYztQO3NAAAAFE"]
[Tue Jul 21 08:17:41.174287 2026] [security2:error] [pid 411857:tid 412060] [client 20.226.60.151:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/get.php"] [unique_id "al9VVS7ynBpLeKYztQO3OQAAAEc"]
[Tue Jul 21 08:17:41.203972 2026] [security2:error] [pid 411857:tid 412009] [client 20.197.192.193:38917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/zzz.php"] [unique_id "al9VVS7ynBpLeKYztQO3OgAAABQ"]
[Tue Jul 21 08:17:41.239325 2026] [security2:error] [pid 411857:tid 412078] [client 20.226.60.151:60348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/as.php"] [unique_id "al9VVS7ynBpLeKYztQO3PQAAAFk"]
[Tue Jul 21 08:17:41.300612 2026] [security2:error] [pid 411857:tid 412054] [client 20.197.192.193:60653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wicked.php"] [unique_id "al9VVS7ynBpLeKYztQO3RgAAAEE"]
[Tue Jul 21 08:17:41.361210 2026] [security2:error] [pid 411857:tid 412059] [client 20.197.192.193:60651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/edit.php"] [unique_id "al9VVS7ynBpLeKYztQO3RwAAAEY"]
[Tue Jul 21 08:17:41.429055 2026] [security2:error] [pid 411857:tid 412048] [client 20.197.192.193:13650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/koiy.php"] [unique_id "al9VVS7ynBpLeKYztQO3SQAAADs"]
[Tue Jul 21 08:17:41.490729 2026] [security2:error] [pid 411857:tid 412095] [client 20.226.60.151:53347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/ccou.php"] [unique_id "al9VVS7ynBpLeKYztQO3SgAAAGo"]
[Tue Jul 21 08:17:41.529082 2026] [core:error] [pid 411857:tid 411925] [remote 40.77.167.14:48015] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:17:41.529112 2026] [core:error] [pid 411857:tid 411925] [remote 40.77.167.14:48015] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:17:41.537479 2026] [security2:error] [pid 411857:tid 412058] [client 20.197.192.193:38954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/kua.php"] [unique_id "al9VVS7ynBpLeKYztQO3TAAAAEU"]
[Tue Jul 21 08:17:41.544142 2026] [security2:error] [pid 411857:tid 412068] [client 185.213.175.37:63290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.rinettoar.com.br"] [uri "/.env.bak"] [unique_id "al9VVS7ynBpLeKYztQO3TQAAAE8"]
[Tue Jul 21 08:17:41.699585 2026] [security2:error] [pid 411857:tid 412038] [client 150.129.202.39:64896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VVS7ynBpLeKYztQO3VgAAADE"]
[Tue Jul 21 08:17:41.699718 2026] [security2:error] [pid 411857:tid 412038] [client 150.129.202.39:64896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VVS7ynBpLeKYztQO3VgAAADE"]
[Tue Jul 21 08:17:41.731863 2026] [security2:error] [pid 411857:tid 412069] [client 193.148.56.61:52406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "northcomm.com.br"] [uri "/"] [unique_id "al9VVS7ynBpLeKYztQO3WAAAAFA"]
[Tue Jul 21 08:17:41.733711 2026] [security2:error] [pid 411857:tid 411992] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VVS7ynBpLeKYztQO3RAAAAAM"]
[Tue Jul 21 08:17:41.794416 2026] [security2:error] [pid 411857:tid 412027] [client 20.197.192.193:13692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/hp2.php"] [unique_id "al9VVS7ynBpLeKYztQO3YgAAACY"]
[Tue Jul 21 08:17:41.994231 2026] [security2:error] [pid 411857:tid 412116] [client 20.226.60.151:60310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/w3lls.php"] [unique_id "al9VVS7ynBpLeKYztQO3ZgAAAH8"]
[Tue Jul 21 08:17:42.035467 2026] [security2:error] [pid 411857:tid 412024] [client 20.197.192.193:60629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/ez.php"] [unique_id "al9VVi7ynBpLeKYztQO3ZwAAACM"]
[Tue Jul 21 08:17:42.124046 2026] [security2:error] [pid 411857:tid 412046] [client 193.148.56.61:52497] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "northcomm.com.br"] [uri "/"] [unique_id "al9VVi7ynBpLeKYztQO3bwAAADk"]
[Tue Jul 21 08:17:42.219176 2026] [security2:error] [pid 411857:tid 411997] [client 151.63.71.144:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9VVi7ynBpLeKYztQO3dgAAAAg"]
[Tue Jul 21 08:17:42.219876 2026] [security2:error] [pid 411857:tid 411997] [client 151.63.71.144:52664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9VVi7ynBpLeKYztQO3dgAAAAg"]
[Tue Jul 21 08:17:42.285786 2026] [security2:error] [pid 411857:tid 411993] [client 20.226.60.151:49375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/adminner.php"] [unique_id "al9VVi7ynBpLeKYztQO3fgAAAAQ"]
[Tue Jul 21 08:17:42.288215 2026] [security2:error] [pid 411857:tid 412056] [client 86.106.84.166:54856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9VVi7ynBpLeKYztQO3fwAAAEM"]
[Tue Jul 21 08:17:42.288333 2026] [security2:error] [pid 411857:tid 412056] [client 86.106.84.166:54856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9VVi7ynBpLeKYztQO3fwAAAEM"]
[Tue Jul 21 08:17:42.289181 2026] [security2:error] [pid 411857:tid 412089] [client 117.210.135.0:63520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VVi7ynBpLeKYztQO3gQAAAGQ"]
[Tue Jul 21 08:17:42.290132 2026] [security2:error] [pid 411857:tid 412089] [client 117.210.135.0:63520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VVi7ynBpLeKYztQO3gQAAAGQ"]
[Tue Jul 21 08:17:42.290330 2026] [core:error] [pid 411857:tid 411949] [remote 40.77.167.14:48015] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:17:42.290349 2026] [core:error] [pid 411857:tid 411949] [remote 40.77.167.14:48015] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:17:42.374603 2026] [security2:error] [pid 411857:tid 412081] [client 120.56.162.40:54507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VVi7ynBpLeKYztQO3iwAAAFw"]
[Tue Jul 21 08:17:42.374771 2026] [security2:error] [pid 411857:tid 412081] [client 120.56.162.40:54507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VVi7ynBpLeKYztQO3iwAAAFw"]
[Tue Jul 21 08:17:42.413089 2026] [core:error] [pid 411857:tid 411942] [remote 40.77.167.14:48015] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:17:42.413109 2026] [core:error] [pid 411857:tid 411942] [remote 40.77.167.14:48015] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:17:42.520438 2026] [security2:error] [pid 411857:tid 412073] [client 74.249.245.134:15143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/pomo.php"] [unique_id "al9VVi7ynBpLeKYztQO3kAAAAFQ"]
[Tue Jul 21 08:17:42.596361 2026] [security2:error] [pid 411857:tid 411940] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VVi7ynBpLeKYztQO3kgAAf1E"]
[Tue Jul 21 08:17:42.596560 2026] [security2:error] [pid 411857:tid 412116] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VVi7ynBpLeKYztQO3kgAAf1E"]
[Tue Jul 21 08:17:42.721839 2026] [security2:error] [pid 411857:tid 412076] [client 20.151.10.161:45990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9VVi7ynBpLeKYztQO3nQAAAFc"]
[Tue Jul 21 08:17:42.788377 2026] [security2:error] [pid 411857:tid 412113] [client 20.226.60.151:48830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/admin.php"] [unique_id "al9VVi7ynBpLeKYztQO3owAAAHw"]
[Tue Jul 21 08:17:42.801916 2026] [security2:error] [pid 411857:tid 411938] [remote 132.148.72.88:38000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9VVi7ynBpLeKYztQO3pAAAIk8"]
[Tue Jul 21 08:17:42.859095 2026] [security2:error] [pid 411857:tid 412011] [client 173.252.95.6:38454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9VVi7ynBpLeKYztQO3nAAAABY"]
[Tue Jul 21 08:17:43.062844 2026] [security2:error] [pid 411857:tid 411994] [client 20.197.192.193:60630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/fz.php"] [unique_id "al9VVy7ynBpLeKYztQO3sQAAAAU"]
[Tue Jul 21 08:17:43.093566 2026] [security2:error] [pid 411857:tid 412068] [client 20.226.60.151:53361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/test1.php"] [unique_id "al9VVy7ynBpLeKYztQO3swAAAE8"]
[Tue Jul 21 08:17:43.159393 2026] [security2:error] [pid 411857:tid 411974] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VVy7ynBpLeKYztQO3tgAAfXI"]
[Tue Jul 21 08:17:43.159689 2026] [security2:error] [pid 411857:tid 412114] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VVy7ynBpLeKYztQO3tgAAfXI"]
[Tue Jul 21 08:17:43.411174 2026] [security2:error] [pid 411857:tid 412094] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VVi7ynBpLeKYztQO3rQAAAGk"]
[Tue Jul 21 08:17:43.513753 2026] [security2:error] [pid 411857:tid 412057] [client 61.1.167.83:58209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VVy7ynBpLeKYztQO3ygAAAEQ"]
[Tue Jul 21 08:17:43.513918 2026] [security2:error] [pid 411857:tid 412057] [client 61.1.167.83:58209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VVy7ynBpLeKYztQO3ygAAAEQ"]
[Tue Jul 21 08:17:43.645726 2026] [security2:error] [pid 411857:tid 411870] [remote 13.41.15.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.15.41.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tavarescont.com.br"] [uri "/wp-login.php"] [unique_id "al9VVy7ynBpLeKYztQO36wAANgs"]
[Tue Jul 21 08:17:43.668998 2026] [security2:error] [pid 411857:tid 412012] [client 74.249.245.134:15403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/test1.php"] [unique_id "al9VVy7ynBpLeKYztQO37AAAABc"]
[Tue Jul 21 08:17:43.696909 2026] [security2:error] [pid 411857:tid 412106] [client 20.226.60.151:48865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/k.php"] [unique_id "al9VVy7ynBpLeKYztQO37QAAAHU"]
[Tue Jul 21 08:17:43.799131 2026] [security2:error] [pid 411857:tid 411997] [client 20.197.192.193:60634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/la.php"] [unique_id "al9VVy7ynBpLeKYztQO39gAAAAg"]
[Tue Jul 21 08:17:43.870470 2026] [security2:error] [pid 411857:tid 412098] [client 20.206.105.145:25572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9VVy7ynBpLeKYztQO3_AAAAG0"]
[Tue Jul 21 08:17:43.943330 2026] [security2:error] [pid 411857:tid 412028] [client 20.197.192.193:13705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/hp3.php"] [unique_id "al9VVy7ynBpLeKYztQO3_gAAACc"]
[Tue Jul 21 08:17:44.086655 2026] [security2:error] [pid 411857:tid 412022] [client 223.181.60.88:11842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VWC7ynBpLeKYztQO4AQAAACE"]
[Tue Jul 21 08:17:44.086975 2026] [security2:error] [pid 411857:tid 412022] [client 223.181.60.88:11842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VWC7ynBpLeKYztQO4AQAAACE"]
[Tue Jul 21 08:17:44.185527 2026] [security2:error] [pid 411857:tid 412069] [client 20.197.192.193:60669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/nhvoanpl.php"] [unique_id "al9VWC7ynBpLeKYztQO4EwAAAFA"]
[Tue Jul 21 08:17:44.217702 2026] [security2:error] [pid 411857:tid 412027] [client 162.219.176.3:56686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9VWC7ynBpLeKYztQO4FQAAACY"]
[Tue Jul 21 08:17:44.217798 2026] [security2:error] [pid 411857:tid 412027] [client 162.219.176.3:56686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9VWC7ynBpLeKYztQO4FQAAACY"]
[Tue Jul 21 08:17:44.309985 2026] [security2:error] [pid 411857:tid 411989] [client 20.226.60.151:53364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/database.php"] [unique_id "al9VWC7ynBpLeKYztQO4LwAAAAA"]
[Tue Jul 21 08:17:44.556536 2026] [security2:error] [pid 411857:tid 411992] [client 20.151.10.161:45999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/footer.php"] [unique_id "al9VWC7ynBpLeKYztQO4OAAAAAM"]
[Tue Jul 21 08:17:44.639310 2026] [security2:error] [pid 411857:tid 412003] [client 20.197.192.193:38946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/inso.php"] [unique_id "al9VWC7ynBpLeKYztQO4OwAAAA4"]
[Tue Jul 21 08:17:44.783468 2026] [security2:error] [pid 411857:tid 412092] [client 20.197.192.193:38915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wpx.php"] [unique_id "al9VWC7ynBpLeKYztQO4TQAAAGc"]
[Tue Jul 21 08:17:44.961622 2026] [security2:error] [pid 411857:tid 412086] [client 20.197.192.193:13652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/aa1.php"] [unique_id "al9VWC7ynBpLeKYztQO4VAAAAGE"]
[Tue Jul 21 08:17:45.010549 2026] [security2:error] [pid 411857:tid 411994] [client 20.151.10.161:36545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.hbodontologiaespecializada.com.br"] [uri "/aaa.php"] [unique_id "al9VWS7ynBpLeKYztQO4VQAAAAU"]
[Tue Jul 21 08:17:45.154506 2026] [security2:error] [pid 411857:tid 412018] [client 20.226.60.151:48776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/blurbs.php"] [unique_id "al9VWS7ynBpLeKYztQO4XgAAAB0"]
[Tue Jul 21 08:17:45.213004 2026] [security2:error] [pid 411857:tid 412025] [client 74.249.245.134:15150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/fw.php"] [unique_id "al9VWS7ynBpLeKYztQO4YQAAACQ"]
[Tue Jul 21 08:17:45.220888 2026] [security2:error] [pid 411857:tid 412080] [client 20.197.192.193:38939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/berlin.php"] [unique_id "al9VWS7ynBpLeKYztQO4YwAAAFs"]
[Tue Jul 21 08:17:45.225364 2026] [security2:error] [pid 411857:tid 412090] [client 20.226.60.151:51977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/file.php"] [unique_id "al9VWS7ynBpLeKYztQO4ZgAAAGU"]
[Tue Jul 21 08:17:45.254360 2026] [security2:error] [pid 411857:tid 412098] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VWC7ynBpLeKYztQO4TwAAAG0"]
[Tue Jul 21 08:17:45.450268 2026] [security2:error] [pid 411857:tid 412043] [client 152.59.34.51:50440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VWS7ynBpLeKYztQO4dgAAADY"]
[Tue Jul 21 08:17:45.450375 2026] [security2:error] [pid 411857:tid 412043] [client 152.59.34.51:50440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VWS7ynBpLeKYztQO4dgAAADY"]
[Tue Jul 21 08:17:45.602310 2026] [security2:error] [pid 411857:tid 412017] [client 20.197.192.193:13015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/acew67.php"] [unique_id "al9VWS7ynBpLeKYztQO4ewAAABw"]
[Tue Jul 21 08:17:45.661529 2026] [security2:error] [pid 411857:tid 412039] [client 20.197.192.193:60624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/billur.php"] [unique_id "al9VWS7ynBpLeKYztQO4fgAAADI"]
[Tue Jul 21 08:17:45.700344 2026] [security2:error] [pid 411857:tid 412013] [client 20.151.10.161:45971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-content/index.php"] [unique_id "al9VWS7ynBpLeKYztQO4fwAAABg"]
[Tue Jul 21 08:17:45.799217 2026] [core:error] [pid 411857:tid 411960] [remote 52.167.144.18:17708] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:17:45.799244 2026] [core:error] [pid 411857:tid 411960] [remote 52.167.144.18:17708] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:17:45.866124 2026] [security2:error] [pid 411857:tid 412101] [client 20.220.225.223:38670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/csa.php"] [unique_id "al9VWS7ynBpLeKYztQO4iwAAAHA"]
[Tue Jul 21 08:17:45.970853 2026] [security2:error] [pid 411857:tid 412114] [client 162.219.176.3:56690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9VWS7ynBpLeKYztQO4jwAAAH0"]
[Tue Jul 21 08:17:45.970971 2026] [security2:error] [pid 411857:tid 412114] [client 162.219.176.3:56690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9VWS7ynBpLeKYztQO4jwAAAH0"]
[Tue Jul 21 08:17:46.043711 2026] [security2:error] [pid 411857:tid 412067] [client 20.220.225.223:52642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/xxx.php"] [unique_id "al9VWi7ynBpLeKYztQO4kQAAAE4"]
[Tue Jul 21 08:17:46.080053 2026] [security2:error] [pid 411857:tid 412080] [client 20.197.192.193:38951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/mimpi.php"] [unique_id "al9VWi7ynBpLeKYztQO4kgAAAFs"]
[Tue Jul 21 08:17:46.089616 2026] [security2:error] [pid 411857:tid 412104] [client 74.249.245.134:15395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/fm.php"] [unique_id "al9VWi7ynBpLeKYztQO4lAAAAHM"]
[Tue Jul 21 08:17:46.149984 2026] [security2:error] [pid 411857:tid 411981] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VWi7ynBpLeKYztQO4mwAAIHk"]
[Tue Jul 21 08:17:46.150163 2026] [security2:error] [pid 411857:tid 412021] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VWi7ynBpLeKYztQO4mwAAIHk"]
[Tue Jul 21 08:17:46.195209 2026] [security2:error] [pid 411857:tid 412044] [client 20.206.105.145:25583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9VWi7ynBpLeKYztQO4nwAAADc"]
[Tue Jul 21 08:17:46.285428 2026] [security2:error] [pid 411857:tid 412043] [client 20.151.10.161:45985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/zoro.php"] [unique_id "al9VWi7ynBpLeKYztQO4qAAAADY"]
[Tue Jul 21 08:17:46.325279 2026] [security2:error] [pid 411857:tid 412033] [client 20.197.192.193:60640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/dp.php"] [unique_id "al9VWi7ynBpLeKYztQO4qgAAACw"]
[Tue Jul 21 08:17:46.395311 2026] [security2:error] [pid 411857:tid 412084] [client 38.100.221.102:18326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VWi7ynBpLeKYztQO4rQAAAF8"]
[Tue Jul 21 08:17:46.395711 2026] [security2:error] [pid 411857:tid 412084] [client 38.100.221.102:18326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VWi7ynBpLeKYztQO4rQAAAF8"]
[Tue Jul 21 08:17:46.419557 2026] [security2:error] [pid 411857:tid 412070] [client 20.220.225.223:24227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/red.php"] [unique_id "al9VWi7ynBpLeKYztQO4rgAAAFE"]
[Tue Jul 21 08:17:46.482400 2026] [security2:error] [pid 411857:tid 412023] [client 20.197.192.193:60641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/bootstrap.php"] [unique_id "al9VWi7ynBpLeKYztQO4tQAAACI"]
[Tue Jul 21 08:17:46.562551 2026] [security2:error] [pid 411857:tid 412103] [client 154.208.47.43:58794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VWi7ynBpLeKYztQO4tgAAAHI"]
[Tue Jul 21 08:17:46.562690 2026] [security2:error] [pid 411857:tid 412103] [client 154.208.47.43:58794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VWi7ynBpLeKYztQO4tgAAAHI"]
[Tue Jul 21 08:17:46.627547 2026] [security2:error] [pid 411857:tid 412085] [client 20.197.192.193:35869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-editor.php"] [unique_id "al9VWi7ynBpLeKYztQO4twAAAGA"]
[Tue Jul 21 08:17:46.725328 2026] [security2:error] [pid 411857:tid 412041] [client 20.197.192.193:13685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/bscclapb.php"] [unique_id "al9VWi7ynBpLeKYztQO4vQAAADQ"]
[Tue Jul 21 08:17:46.758649 2026] [security2:error] [pid 411857:tid 412058] [client 20.226.60.151:60351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/file.php"] [unique_id "al9VWi7ynBpLeKYztQO4vgAAAEU"]
[Tue Jul 21 08:17:46.805361 2026] [security2:error] [pid 411857:tid 412020] [client 20.197.192.193:60619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/cro.php"] [unique_id "al9VWi7ynBpLeKYztQO4xQAAAB8"]
[Tue Jul 21 08:17:46.805981 2026] [security2:error] [pid 411857:tid 411979] [remote 144.31.216.149:0] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 149.216.31.144.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/wp-comments-post.php"] [unique_id "al9VWS7ynBpLeKYztQO4fAAAb3c"], referer: https://confiancedigital.com/2024/05/03/hello-world/
[Tue Jul 21 08:17:46.806137 2026] [security2:error] [pid 411857:tid 412100] [client 144.31.216.149:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "confiancedigital.com"] [uri "/wp-comments-post.php"] [unique_id "al9VWS7ynBpLeKYztQO4fAAAb3c"], referer: https://confiancedigital.com/2024/05/03/hello-world/
[Tue Jul 21 08:17:46.848510 2026] [security2:error] [pid 411857:tid 411968] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VWi7ynBpLeKYztQO4xwAAMGw"]
[Tue Jul 21 08:17:46.848648 2026] [security2:error] [pid 411857:tid 412037] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VWi7ynBpLeKYztQO4xwAAMGw"]
[Tue Jul 21 08:17:46.849322 2026] [security2:error] [pid 411857:tid 412069] [client 20.197.192.193:48719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/wp-editor.php"] [unique_id "al9VWi7ynBpLeKYztQO4yAAAAFA"]
[Tue Jul 21 08:17:47.021621 2026] [security2:error] [pid 411857:tid 412061] [client 20.226.60.151:48803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/bajah.php"] [unique_id "al9VWy7ynBpLeKYztQO4zwAAAEg"]
[Tue Jul 21 08:17:47.188949 2026] [security2:error] [pid 411857:tid 411999] [client 20.197.192.193:35864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/cron-tab.php"] [unique_id "al9VWy7ynBpLeKYztQO41AAAAAo"]
[Tue Jul 21 08:17:47.209789 2026] [security2:error] [pid 411857:tid 412044] [client 74.249.245.134:15155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/ini.php"] [unique_id "al9VWy7ynBpLeKYztQO41QAAADc"]
[Tue Jul 21 08:17:47.271374 2026] [security2:error] [pid 411857:tid 412031] [client 20.151.10.161:46079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9VWy7ynBpLeKYztQO42AAAACo"]
[Tue Jul 21 08:17:47.389327 2026] [security2:error] [pid 411857:tid 412053] [client 20.226.60.151:60330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/777.php"] [unique_id "al9VWy7ynBpLeKYztQO44gAAAEA"]
[Tue Jul 21 08:17:47.588673 2026] [security2:error] [pid 411857:tid 412072] [client 20.197.192.193:60611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/koiy.php"] [unique_id "al9VWy7ynBpLeKYztQO47wAAAFM"]
[Tue Jul 21 08:17:47.641973 2026] [security2:error] [pid 411857:tid 412079] [client 20.220.225.223:52637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/hunter.php"] [unique_id "al9VWy7ynBpLeKYztQO48QAAAFo"]
[Tue Jul 21 08:17:47.743166 2026] [security2:error] [pid 411857:tid 412105] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VWy7ynBpLeKYztQO42gAAAHQ"]
[Tue Jul 21 08:17:47.827386 2026] [security2:error] [pid 411857:tid 412003] [client 173.252.95.62:36888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9VWy7ynBpLeKYztQO48gAAAA4"]
[Tue Jul 21 08:17:47.949753 2026] [security2:error] [pid 411857:tid 412010] [client 102.206.115.33:64962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VWy7ynBpLeKYztQO4_wAAABU"]
[Tue Jul 21 08:17:47.949933 2026] [security2:error] [pid 411857:tid 412010] [client 102.206.115.33:64962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VWy7ynBpLeKYztQO4_wAAABU"]
[Tue Jul 21 08:17:47.971942 2026] [security2:error] [pid 411857:tid 412066] [client 62.102.148.158:38294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9VWy7ynBpLeKYztQO5AQAAAE0"]
[Tue Jul 21 08:17:47.972052 2026] [security2:error] [pid 411857:tid 412066] [client 62.102.148.158:38294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9VWy7ynBpLeKYztQO5AQAAAE0"]
[Tue Jul 21 08:17:48.050122 2026] [security2:error] [pid 411857:tid 411991] [client 20.151.10.161:46037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/greap.php"] [unique_id "al9VXC7ynBpLeKYztQO5DAAAAAI"]
[Tue Jul 21 08:17:48.065744 2026] [security2:error] [pid 411857:tid 412094] [client 20.197.192.193:60661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/hp2.php"] [unique_id "al9VXC7ynBpLeKYztQO5DwAAAGk"]
[Tue Jul 21 08:17:48.076279 2026] [security2:error] [pid 411857:tid 412096] [client 20.206.105.145:25519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/raw.php"] [unique_id "al9VXC7ynBpLeKYztQO5EQAAAGs"]
[Tue Jul 21 08:17:48.159273 2026] [security2:error] [pid 411857:tid 412062] [client 187.125.243.197:55462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VXC7ynBpLeKYztQO5FgAAAEk"]
[Tue Jul 21 08:17:48.159412 2026] [security2:error] [pid 411857:tid 412062] [client 187.125.243.197:55462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VXC7ynBpLeKYztQO5FgAAAEk"]
[Tue Jul 21 08:17:48.205347 2026] [security2:error] [pid 411857:tid 412023] [client 198.54.129.60:54130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9VXC7ynBpLeKYztQO5FwAAACI"]
[Tue Jul 21 08:17:48.205459 2026] [security2:error] [pid 411857:tid 412023] [client 198.54.129.60:54130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9VXC7ynBpLeKYztQO5FwAAACI"]
[Tue Jul 21 08:17:48.522228 2026] [security2:error] [pid 411857:tid 412048] [client 103.151.46.103:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VXC7ynBpLeKYztQO5KAAAADs"]
[Tue Jul 21 08:17:48.522364 2026] [security2:error] [pid 411857:tid 412048] [client 103.151.46.103:52430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VXC7ynBpLeKYztQO5KAAAADs"]
[Tue Jul 21 08:17:48.604616 2026] [security2:error] [pid 411857:tid 412086] [client 20.197.192.193:60650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/hp3.php"] [unique_id "al9VXC7ynBpLeKYztQO5KwAAAGE"]
[Tue Jul 21 08:17:48.718269 2026] [security2:error] [pid 411857:tid 412000] [client 74.249.245.134:31419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/themes.php"] [unique_id "al9VXC7ynBpLeKYztQO5MgAAAAs"]
[Tue Jul 21 08:17:48.787267 2026] [security2:error] [pid 411857:tid 412103] [client 87.116.180.198:27361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VXC7ynBpLeKYztQO5NQAAAHI"]
[Tue Jul 21 08:17:48.787373 2026] [security2:error] [pid 411857:tid 412103] [client 87.116.180.198:27361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VXC7ynBpLeKYztQO5NQAAAHI"]
[Tue Jul 21 08:17:48.814485 2026] [security2:error] [pid 411857:tid 412100] [client 20.226.60.151:48829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/a.php"] [unique_id "al9VXC7ynBpLeKYztQO5OQAAAG8"]
[Tue Jul 21 08:17:48.848721 2026] [security2:error] [pid 411857:tid 411991] [client 20.226.60.151:51973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/ssixta.php"] [unique_id "al9VXC7ynBpLeKYztQO5PQAAAAI"]
[Tue Jul 21 08:17:48.881849 2026] [security2:error] [pid 411857:tid 412034] [client 20.151.10.161:45954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/177.php"] [unique_id "al9VXC7ynBpLeKYztQO5QgAAAC0"]
[Tue Jul 21 08:17:49.045922 2026] [security2:error] [pid 411857:tid 412070] [client 20.197.192.193:60666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/aa1.php"] [unique_id "al9VXS7ynBpLeKYztQO5RQAAAFE"]
[Tue Jul 21 08:17:49.128972 2026] [security2:error] [pid 411857:tid 412013] [client 20.206.105.145:25569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/abcd.php"] [unique_id "al9VXS7ynBpLeKYztQO5RwAAABg"]
[Tue Jul 21 08:17:49.293789 2026] [security2:error] [pid 411857:tid 411887] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VXS7ynBpLeKYztQO5TwAANhw"]
[Tue Jul 21 08:17:49.293962 2026] [security2:error] [pid 411857:tid 412043] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VXS7ynBpLeKYztQO5TwAANhw"]
[Tue Jul 21 08:17:49.296854 2026] [security2:error] [pid 411857:tid 412028] [client 20.220.225.223:58906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/we.php"] [unique_id "al9VXS7ynBpLeKYztQO5UAAAACc"]
[Tue Jul 21 08:17:49.358227 2026] [security2:error] [pid 411857:tid 412068] [client 20.197.192.193:38934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/acew67.php"] [unique_id "al9VXS7ynBpLeKYztQO5UgAAAE8"]
[Tue Jul 21 08:17:49.621932 2026] [security2:error] [pid 411857:tid 412061] [client 20.197.192.193:13020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/else1.php"] [unique_id "al9VXS7ynBpLeKYztQO5XQAAAEg"]
[Tue Jul 21 08:17:49.767702 2026] [security2:error] [pid 411857:tid 412060] [client 185.213.175.37:22542] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.thekingsdistribuidora.com.br"] [uri "/"] [unique_id "al9VXS7ynBpLeKYztQO5aQAAAEc"]
[Tue Jul 21 08:17:49.787823 2026] [security2:error] [pid 411857:tid 412099] [client 103.106.20.201:63215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VXS7ynBpLeKYztQO5bQAAAG4"]
[Tue Jul 21 08:17:49.787916 2026] [security2:error] [pid 411857:tid 412099] [client 103.106.20.201:63215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VXS7ynBpLeKYztQO5bQAAAG4"]
[Tue Jul 21 08:17:49.914174 2026] [security2:error] [pid 411857:tid 412071] [client 14.245.224.124:64102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VXS7ynBpLeKYztQO5cAAAAFI"]
[Tue Jul 21 08:17:49.914446 2026] [security2:error] [pid 411857:tid 412071] [client 14.245.224.124:64102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VXS7ynBpLeKYztQO5cAAAAFI"]
[Tue Jul 21 08:17:49.918049 2026] [security2:error] [pid 411857:tid 411984] [remote 188.253.17.6:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "confiancedigital.com"] [uri "/wp-comments-post.php"] [unique_id "al9VWy7ynBpLeKYztQO47gAAZ3w"], referer: https://confiancedigital.com/2024/05/03/hello-world/
[Tue Jul 21 08:17:50.001826 2026] [security2:error] [pid 411857:tid 412011] [client 20.151.10.161:46069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/199.php"] [unique_id "al9VXi7ynBpLeKYztQO5dQAAABY"]
[Tue Jul 21 08:17:50.025967 2026] [security2:error] [pid 411857:tid 412092] [client 188.253.17.6:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "confiancedigital.com"] [uri "/wp-comments-post.php"] [unique_id "al9VWy7ynBpLeKYztQO47gAAZ3w"], referer: https://confiancedigital.com/2024/05/03/hello-world/
[Tue Jul 21 08:17:50.095498 2026] [security2:error] [pid 411857:tid 412104] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VXS7ynBpLeKYztQO5YwAAAHM"]
[Tue Jul 21 08:17:50.174552 2026] [security2:error] [pid 411857:tid 412110] [client 103.78.200.11:63576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VXi7ynBpLeKYztQO5gAAAAHk"]
[Tue Jul 21 08:17:50.175190 2026] [security2:error] [pid 411857:tid 412110] [client 103.78.200.11:63576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VXi7ynBpLeKYztQO5gAAAAHk"]
[Tue Jul 21 08:17:50.338867 2026] [security2:error] [pid 411857:tid 412029] [client 20.226.60.151:60346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/1c.php"] [unique_id "al9VXi7ynBpLeKYztQO5hwAAACg"]
[Tue Jul 21 08:17:50.525546 2026] [security2:error] [pid 411857:tid 412042] [client 20.197.192.193:60649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/bscclapb.php"] [unique_id "al9VXi7ynBpLeKYztQO5iwAAADU"]
[Tue Jul 21 08:17:50.728140 2026] [security2:error] [pid 411857:tid 412034] [client 74.249.245.134:15163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/dropdown.php"] [unique_id "al9VXi7ynBpLeKYztQO5lwAAAC0"]
[Tue Jul 21 08:17:50.809986 2026] [security2:error] [pid 411857:tid 412060] [client 20.206.105.145:25568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/a1.php"] [unique_id "al9VXi7ynBpLeKYztQO5nAAAAEc"]
[Tue Jul 21 08:17:50.832696 2026] [security2:error] [pid 411857:tid 412033] [client 20.197.192.193:60638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/else1.php"] [unique_id "al9VXi7ynBpLeKYztQO5nQAAACw"]
[Tue Jul 21 08:17:50.874054 2026] [security2:error] [pid 411857:tid 412056] [client 111.93.58.162:60131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VXi7ynBpLeKYztQO5oAAAAEM"]
[Tue Jul 21 08:17:50.874211 2026] [security2:error] [pid 411857:tid 412056] [client 111.93.58.162:60131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VXi7ynBpLeKYztQO5oAAAAEM"]
[Tue Jul 21 08:17:50.961648 2026] [security2:error] [pid 411857:tid 412075] [client 115.134.11.136:59543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VXi7ynBpLeKYztQO5oQAAAFY"]
[Tue Jul 21 08:17:50.987279 2026] [security2:error] [pid 411857:tid 412014] [client 20.226.60.151:48784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/edit.php"] [unique_id "al9VXi7ynBpLeKYztQO5ogAAABk"]
[Tue Jul 21 08:17:51.270864 2026] [security2:error] [pid 411857:tid 412104] [client 20.151.10.161:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/file52.php"] [unique_id "al9VXy7ynBpLeKYztQO5rAAAAHM"]
[Tue Jul 21 08:17:51.349224 2026] [security2:error] [pid 411857:tid 412090] [client 20.206.105.145:25508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9VXy7ynBpLeKYztQO5sAAAAGU"]
[Tue Jul 21 08:17:51.365939 2026] [security2:error] [pid 411857:tid 411935] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VXy7ynBpLeKYztQO5sgAAFkw"]
[Tue Jul 21 08:17:51.366115 2026] [security2:error] [pid 411857:tid 412011] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VXy7ynBpLeKYztQO5sgAAFkw"]
[Tue Jul 21 08:17:51.371061 2026] [security2:error] [pid 411857:tid 412110] [client 20.226.60.151:48838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/hosty.php"] [unique_id "al9VXy7ynBpLeKYztQO5swAAAHk"]
[Tue Jul 21 08:17:51.440155 2026] [security2:error] [pid 411857:tid 411940] [remote 192.241.143.148:46312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9VXy7ynBpLeKYztQO5tgAAPVE"]
[Tue Jul 21 08:17:51.470291 2026] [security2:error] [pid 411857:tid 412079] [client 20.226.60.151:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/test2.php"] [unique_id "al9VXy7ynBpLeKYztQO5uAAAAFo"]
[Tue Jul 21 08:17:51.478684 2026] [security2:error] [pid 411857:tid 412006] [client 20.197.192.193:60664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/tkikikoko.php"] [unique_id "al9VXy7ynBpLeKYztQO5uQAAABE"]
[Tue Jul 21 08:17:51.753099 2026] [security2:error] [pid 411857:tid 412027] [client 20.197.192.193:35885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-Blogs.php"] [unique_id "al9VXy7ynBpLeKYztQO5wwAAACY"]
[Tue Jul 21 08:17:51.760355 2026] [security2:error] [pid 411857:tid 411990] [client 20.226.60.151:48811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/k.php"] [unique_id "al9VXy7ynBpLeKYztQO5xAAAAAE"]
[Tue Jul 21 08:17:52.015798 2026] [security2:error] [pid 411857:tid 412064] [client 20.206.105.145:25567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9VYC7ynBpLeKYztQO51wAAAEs"]
[Tue Jul 21 08:17:52.032242 2026] [security2:error] [pid 411857:tid 412096] [client 74.249.245.134:15393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/wp-links.php"] [unique_id "al9VYC7ynBpLeKYztQO52AAAAGs"]
[Tue Jul 21 08:17:52.053362 2026] [security2:error] [pid 411857:tid 412018] [client 20.197.192.193:35876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-css.php"] [unique_id "al9VYC7ynBpLeKYztQO52QAAAB0"]
[Tue Jul 21 08:17:52.117089 2026] [security2:error] [pid 411857:tid 412114] [client 20.197.192.193:60652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-explorer.php"] [unique_id "al9VYC7ynBpLeKYztQO53QAAAH0"]
[Tue Jul 21 08:17:52.143289 2026] [security2:error] [pid 411857:tid 412109] [client 20.197.192.193:60667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/akismet.php"] [unique_id "al9VYC7ynBpLeKYztQO53gAAAHg"]
[Tue Jul 21 08:17:52.206154 2026] [security2:error] [pid 411857:tid 412052] [client 20.197.192.193:38923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/ace2.php"] [unique_id "al9VYC7ynBpLeKYztQO54AAAAD8"]
[Tue Jul 21 08:17:52.261996 2026] [security2:error] [pid 411857:tid 412085] [client 20.226.60.151:48848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/aaa.php"] [unique_id "al9VYC7ynBpLeKYztQO54QAAAGA"]
[Tue Jul 21 08:17:52.264716 2026] [security2:error] [pid 411857:tid 412116] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VXy7ynBpLeKYztQO5xwAAAH8"]
[Tue Jul 21 08:17:52.273134 2026] [security2:error] [pid 411857:tid 412068] [client 150.129.202.39:64607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VYC7ynBpLeKYztQO54gAAAE8"]
[Tue Jul 21 08:17:52.273246 2026] [security2:error] [pid 411857:tid 412068] [client 150.129.202.39:64607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VYC7ynBpLeKYztQO54gAAAE8"]
[Tue Jul 21 08:17:52.273314 2026] [security2:error] [pid 411857:tid 412012] [client 20.197.192.193:60665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/ms.php"] [unique_id "al9VYC7ynBpLeKYztQO55AAAABc"]
[Tue Jul 21 08:17:52.395495 2026] [security2:error] [pid 411857:tid 412078] [client 20.226.60.151:48822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/file5.php"] [unique_id "al9VYC7ynBpLeKYztQO56wAAAFk"]
[Tue Jul 21 08:17:52.444525 2026] [security2:error] [pid 411857:tid 412066] [client 20.226.60.151:48800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/222.php"] [unique_id "al9VYC7ynBpLeKYztQO57AAAAE0"]
[Tue Jul 21 08:17:52.467440 2026] [security2:error] [pid 411857:tid 412022] [client 20.226.60.151:48851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/test.php"] [unique_id "al9VYC7ynBpLeKYztQO57QAAACE"]
[Tue Jul 21 08:17:52.516263 2026] [security2:error] [pid 411857:tid 412075] [client 115.134.11.136:59543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VXi7ynBpLeKYztQO5oQAAAFY"]
[Tue Jul 21 08:17:52.533045 2026] [security2:error] [pid 411857:tid 412063] [client 20.226.60.151:49352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/aaa.php"] [unique_id "al9VYC7ynBpLeKYztQO57gAAAEo"]
[Tue Jul 21 08:17:52.595668 2026] [security2:error] [pid 411857:tid 412100] [client 20.226.60.151:48841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/11.php"] [unique_id "al9VYC7ynBpLeKYztQO57wAAAG8"]
[Tue Jul 21 08:17:52.695725 2026] [security2:error] [pid 411857:tid 412115] [client 20.226.60.151:48771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/mac.php"] [unique_id "al9VYC7ynBpLeKYztQO58wAAAH4"]
[Tue Jul 21 08:17:52.741326 2026] [security2:error] [pid 411857:tid 412014] [client 117.210.135.0:64167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VYC7ynBpLeKYztQO59wAAABk"]
[Tue Jul 21 08:17:52.741994 2026] [security2:error] [pid 411857:tid 412014] [client 117.210.135.0:64167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VYC7ynBpLeKYztQO59wAAABk"]
[Tue Jul 21 08:17:52.770078 2026] [security2:error] [pid 411857:tid 412103] [client 20.220.225.223:52648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "3cengenharia.com"] [uri "/phpinfo.php1"] [unique_id "al9VYC7ynBpLeKYztQO5-QAAAHI"]
[Tue Jul 21 08:17:52.798196 2026] [security2:error] [pid 411857:tid 412038] [client 20.226.60.151:48773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/chosen.php"] [unique_id "al9VYC7ynBpLeKYztQO5_QAAADE"]
[Tue Jul 21 08:17:52.957246 2026] [security2:error] [pid 411857:tid 412051] [client 20.226.60.151:48786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/cream1.php"] [unique_id "al9VYC7ynBpLeKYztQO6BQAAAD4"]
[Tue Jul 21 08:17:52.965096 2026] [security2:error] [pid 411857:tid 412011] [client 120.56.162.40:55010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VYC7ynBpLeKYztQO6BgAAABY"]
[Tue Jul 21 08:17:52.965218 2026] [security2:error] [pid 411857:tid 412011] [client 120.56.162.40:55010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VYC7ynBpLeKYztQO6BgAAABY"]
[Tue Jul 21 08:17:52.979898 2026] [security2:error] [pid 411857:tid 412064] [client 20.197.192.193:13662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/tkikikoko.php"] [unique_id "al9VYC7ynBpLeKYztQO6BwAAAEs"]
[Tue Jul 21 08:17:53.133397 2026] [security2:error] [pid 411857:tid 412069] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VYC7ynBpLeKYztQO58gAAAFA"]
[Tue Jul 21 08:17:53.162009 2026] [security2:error] [pid 411857:tid 411862] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VYS7ynBpLeKYztQO6CwAARwM"]
[Tue Jul 21 08:17:53.162165 2026] [security2:error] [pid 411857:tid 412060] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VYS7ynBpLeKYztQO6CwAARwM"]
[Tue Jul 21 08:17:53.194122 2026] [autoindex:error] [pid 411857:tid 412007] [client 20.226.60.151:48874] AH01276: Cannot serve directory /home4/abbapr65/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:53.212501 2026] [autoindex:error] [pid 411857:tid 412062] [client 20.226.60.151:48874] AH01276: Cannot serve directory /home4/abbapr65/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:53.274259 2026] [security2:error] [pid 411857:tid 412109] [client 20.206.105.145:25506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9VYS7ynBpLeKYztQO6EwAAAHg"]
[Tue Jul 21 08:17:53.313722 2026] [security2:error] [pid 411857:tid 412095] [client 20.226.60.151:48874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/dr.php"] [unique_id "al9VYS7ynBpLeKYztQO6GAAAAGo"]
[Tue Jul 21 08:17:53.427423 2026] [core:alert] [pid 411857:tid 412012] [client 173.252.83.4:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:17:53.440225 2026] [security2:error] [pid 411857:tid 412028] [client 20.151.10.161:45899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/122.php"] [unique_id "al9VYS7ynBpLeKYztQO6IAAAACc"]
[Tue Jul 21 08:17:53.580445 2026] [security2:error] [pid 411857:tid 412050] [client 74.249.245.134:15390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/xmrlpc.php"] [unique_id "al9VYS7ynBpLeKYztQO6JAAAAD0"]
[Tue Jul 21 08:17:53.639763 2026] [security2:error] [pid 411857:tid 412066] [client 20.226.60.151:48806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/x.php"] [unique_id "al9VYS7ynBpLeKYztQO6JwAAAE0"]
[Tue Jul 21 08:17:53.797521 2026] [security2:error] [pid 411857:tid 411868] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VYS7ynBpLeKYztQO6LgAAJAk"]
[Tue Jul 21 08:17:53.797661 2026] [security2:error] [pid 411857:tid 412025] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VYS7ynBpLeKYztQO6LgAAJAk"]
[Tue Jul 21 08:17:53.839701 2026] [security2:error] [pid 411857:tid 412061] [client 20.226.60.151:48789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/155.php"] [unique_id "al9VYS7ynBpLeKYztQO6MgAAAEg"]
[Tue Jul 21 08:17:54.114547 2026] [security2:error] [pid 411857:tid 412059] [client 20.226.60.151:48837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/ops.php"] [unique_id "al9VYi7ynBpLeKYztQO6OQAAAEY"]
[Tue Jul 21 08:17:54.191855 2026] [security2:error] [pid 411857:tid 411996] [client 20.226.60.151:52014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/buy.php"] [unique_id "al9VYi7ynBpLeKYztQO6PAAAAAc"]
[Tue Jul 21 08:17:54.204354 2026] [core:alert] [pid 411857:tid 412099] [client 173.252.83.16:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:17:54.381173 2026] [security2:error] [pid 411857:tid 412071] [client 20.151.10.161:46076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/green1.php"] [unique_id "al9VYi7ynBpLeKYztQO6SQAAAFI"]
[Tue Jul 21 08:17:54.399133 2026] [security2:error] [pid 411857:tid 412021] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VYS7ynBpLeKYztQO6NgAAACA"]
[Tue Jul 21 08:17:54.645906 2026] [security2:error] [pid 411857:tid 412112] [client 20.197.192.193:13001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9VYi7ynBpLeKYztQO6UgAAAHs"]
[Tue Jul 21 08:17:54.843625 2026] [security2:error] [pid 411857:tid 411992] [client 223.181.60.88:16449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VYi7ynBpLeKYztQO6XQAAAAM"]
[Tue Jul 21 08:17:54.844286 2026] [security2:error] [pid 411857:tid 411992] [client 223.181.60.88:16449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VYi7ynBpLeKYztQO6XQAAAAM"]
[Tue Jul 21 08:17:54.959753 2026] [security2:error] [pid 411857:tid 412107] [client 74.249.245.134:15422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/htaccess.php"] [unique_id "al9VYi7ynBpLeKYztQO6ZAAAAHY"]
[Tue Jul 21 08:17:55.042734 2026] [core:alert] [pid 411857:tid 412100] [client 57.141.18.82:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:17:55.091517 2026] [security2:error] [pid 411857:tid 412076] [client 20.226.60.151:48772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/file31.php"] [unique_id "al9VYy7ynBpLeKYztQO6bAAAAFc"]
[Tue Jul 21 08:17:55.123437 2026] [security2:error] [pid 411857:tid 412015] [client 122.246.4.6:42247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.4.246.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "moratoadvogado.com"] [uri "/wp-comments-post.php"] [unique_id "al9VYS7ynBpLeKYztQO6LQAAABo"]
[Tue Jul 21 08:17:55.123579 2026] [security2:error] [pid 411857:tid 412015] [client 122.246.4.6:42247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "moratoadvogado.com"] [uri "/wp-comments-post.php"] [unique_id "al9VYS7ynBpLeKYztQO6LQAAABo"]
[Tue Jul 21 08:17:55.290926 2026] [security2:error] [pid 411857:tid 412103] [client 20.197.192.193:13671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/wp-css.php"] [unique_id "al9VYy7ynBpLeKYztQO6cwAAAHI"]
[Tue Jul 21 08:17:55.530430 2026] [security2:error] [pid 411857:tid 412060] [client 20.226.60.151:52015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/ssend.php"] [unique_id "al9VYy7ynBpLeKYztQO6gQAAAEc"]
[Tue Jul 21 08:17:55.530526 2026] [security2:error] [pid 411857:tid 412044] [client 20.151.10.161:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/biufile.php"] [unique_id "al9VYy7ynBpLeKYztQO6ggAAADc"]
[Tue Jul 21 08:17:55.894643 2026] [security2:error] [pid 411857:tid 412090] [client 20.226.60.151:48859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/file6.php"] [unique_id "al9VYy7ynBpLeKYztQO6kAAAAGU"]
[Tue Jul 21 08:17:55.978885 2026] [core:error] [pid 411857:tid 411918] [remote 52.167.144.18:22523] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:17:55.978906 2026] [core:error] [pid 411857:tid 411918] [remote 52.167.144.18:22523] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:17:56.103717 2026] [core:error] [pid 411857:tid 411900] [remote 52.167.144.18:22523] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:17:56.103743 2026] [core:error] [pid 411857:tid 411900] [remote 52.167.144.18:22523] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:17:56.149362 2026] [autoindex:error] [pid 411857:tid 412014] [client 20.226.60.151:48792] AH01276: Cannot serve directory /home4/abbapr65/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:56.181010 2026] [security2:error] [pid 411857:tid 412058] [client 20.226.60.151:48792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/adminfuns.php"] [unique_id "al9VZC7ynBpLeKYztQO6oQAAAEU"]
[Tue Jul 21 08:17:56.215781 2026] [security2:error] [pid 411857:tid 412037] [client 20.151.10.161:46040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wpconf.php"] [unique_id "al9VZC7ynBpLeKYztQO6ogAAADA"]
[Tue Jul 21 08:17:56.260433 2026] [security2:error] [pid 411857:tid 412027] [client 152.59.34.51:50881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VZC7ynBpLeKYztQO6pgAAACY"]
[Tue Jul 21 08:17:56.260550 2026] [security2:error] [pid 411857:tid 412027] [client 152.59.34.51:50881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VZC7ynBpLeKYztQO6pgAAACY"]
[Tue Jul 21 08:17:56.327157 2026] [security2:error] [pid 411857:tid 412099] [client 20.220.225.223:24236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/fffm.php"] [unique_id "al9VZC7ynBpLeKYztQO6qgAAAG4"]
[Tue Jul 21 08:17:56.331759 2026] [security2:error] [pid 411857:tid 412105] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VYy7ynBpLeKYztQO6jwAAAHQ"]
[Tue Jul 21 08:17:56.359951 2026] [security2:error] [pid 411857:tid 412081] [client 20.226.60.151:48833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/goods.php"] [unique_id "al9VZC7ynBpLeKYztQO6rwAAAFw"]
[Tue Jul 21 08:17:56.376030 2026] [security2:error] [pid 411857:tid 412011] [client 20.197.192.193:13050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/wp-explorer.php"] [unique_id "al9VZC7ynBpLeKYztQO6swAAABY"]
[Tue Jul 21 08:17:56.484198 2026] [security2:error] [pid 411857:tid 412006] [client 20.206.105.145:25477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/simple.php"] [unique_id "al9VZC7ynBpLeKYztQO6vQAAABE"]
[Tue Jul 21 08:17:56.608308 2026] [security2:error] [pid 411857:tid 411912] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VZC7ynBpLeKYztQO6wQAADzU"]
[Tue Jul 21 08:17:56.608478 2026] [security2:error] [pid 411857:tid 412004] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VZC7ynBpLeKYztQO6wQAADzU"]
[Tue Jul 21 08:17:56.720872 2026] [security2:error] [pid 411857:tid 412101] [client 204.12.208.18:60243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-content/edit.php"] [unique_id "al9VZC7ynBpLeKYztQO6wwAAAHA"], referer: https://mucareis.com.br/wp-content/edit.php
[Tue Jul 21 08:17:56.870965 2026] [security2:error] [pid 411857:tid 412074] [client 74.249.245.134:15129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/readme.php"] [unique_id "al9VZC7ynBpLeKYztQO6zAAAAFU"]
[Tue Jul 21 08:17:57.041846 2026] [security2:error] [pid 411857:tid 412038] [client 38.100.221.102:18686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VZS7ynBpLeKYztQO60AAAADE"]
[Tue Jul 21 08:17:57.041977 2026] [security2:error] [pid 411857:tid 412038] [client 38.100.221.102:18686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VZS7ynBpLeKYztQO60AAAADE"]
[Tue Jul 21 08:17:57.082208 2026] [security2:error] [pid 411857:tid 412005] [client 20.226.60.151:49376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/100.php"] [unique_id "al9VZS7ynBpLeKYztQO61QAAABA"]
[Tue Jul 21 08:17:57.114800 2026] [security2:error] [pid 411857:tid 412083] [client 154.208.47.43:59283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VZS7ynBpLeKYztQO61wAAAF4"]
[Tue Jul 21 08:17:57.114927 2026] [security2:error] [pid 411857:tid 412083] [client 154.208.47.43:59283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VZS7ynBpLeKYztQO61wAAAF4"]
[Tue Jul 21 08:17:57.379459 2026] [security2:error] [pid 411857:tid 411879] [remote 173.252.95.113:43046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9VZC7ynBpLeKYztQO6owAAchQ"]
[Tue Jul 21 08:17:57.397682 2026] [security2:error] [pid 411857:tid 412073] [client 20.226.60.151:48834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/about.php"] [unique_id "al9VZS7ynBpLeKYztQO63QAAAFQ"]
[Tue Jul 21 08:17:57.442082 2026] [security2:error] [pid 411857:tid 411972] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VZS7ynBpLeKYztQO63gAAK3A"]
[Tue Jul 21 08:17:57.442261 2026] [security2:error] [pid 411857:tid 412032] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VZS7ynBpLeKYztQO63gAAK3A"]
[Tue Jul 21 08:17:57.797671 2026] [security2:error] [pid 411857:tid 412006] [client 20.151.10.161:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/mosty.php"] [unique_id "al9VZS7ynBpLeKYztQO68gAAABE"]
[Tue Jul 21 08:17:57.801424 2026] [security2:error] [pid 411857:tid 412050] [client 20.226.60.151:49394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/about.php"] [unique_id "al9VZS7ynBpLeKYztQO68wAAAD0"]
[Tue Jul 21 08:17:58.088563 2026] [security2:error] [pid 411857:tid 412080] [client 103.78.200.11:64069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VZi7ynBpLeKYztQO7AgAAAFs"]
[Tue Jul 21 08:17:58.089228 2026] [security2:error] [pid 411857:tid 412080] [client 103.78.200.11:64069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VZi7ynBpLeKYztQO7AgAAAFs"]
[Tue Jul 21 08:17:58.135071 2026] [security2:error] [pid 411857:tid 412107] [client 20.206.105.145:25497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/xxx.php"] [unique_id "al9VZi7ynBpLeKYztQO7BgAAAHY"]
[Tue Jul 21 08:17:58.156428 2026] [security2:error] [pid 411857:tid 412072] [client 20.226.60.151:48842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/admin.php"] [unique_id "al9VZi7ynBpLeKYztQO7BwAAAFM"]
[Tue Jul 21 08:17:58.201768 2026] [security2:error] [pid 411857:tid 412101] [client 204.12.208.18:60270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-content/edit.php"] [unique_id "al9VZi7ynBpLeKYztQO7CQAAAHA"], referer: https://mucareis.com.br/wp-content/edit.php
[Tue Jul 21 08:17:58.248540 2026] [security2:error] [pid 411857:tid 412067] [client 20.151.10.161:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/dejavu.php"] [unique_id "al9VZi7ynBpLeKYztQO7CgAAAE4"]
[Tue Jul 21 08:17:58.410747 2026] [security2:error] [pid 411857:tid 412016] [client 20.197.192.193:13693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/akismet.php"] [unique_id "al9VZi7ynBpLeKYztQO7EAAAABs"]
[Tue Jul 21 08:17:58.440095 2026] [security2:error] [pid 411857:tid 412109] [client 102.206.115.33:58316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VZi7ynBpLeKYztQO7EQAAAHg"]
[Tue Jul 21 08:17:58.440275 2026] [security2:error] [pid 411857:tid 412109] [client 102.206.115.33:58316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VZi7ynBpLeKYztQO7EQAAAHg"]
[Tue Jul 21 08:17:58.479827 2026] [security2:error] [pid 411857:tid 412029] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VZi7ynBpLeKYztQO6_AAAACg"]
[Tue Jul 21 08:17:58.529129 2026] [security2:error] [pid 411857:tid 412058] [client 74.249.245.134:15120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/403.php"] [unique_id "al9VZi7ynBpLeKYztQO7FgAAAEU"]
[Tue Jul 21 08:17:58.561159 2026] [security2:error] [pid 411857:tid 412049] [client 20.220.225.223:24245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/ftde.php"] [unique_id "al9VZi7ynBpLeKYztQO7GAAAADw"]
[Tue Jul 21 08:17:58.636544 2026] [security2:error] [pid 411857:tid 412054] [client 187.125.243.197:55942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VZi7ynBpLeKYztQO7HQAAAEE"]
[Tue Jul 21 08:17:58.638020 2026] [security2:error] [pid 411857:tid 412054] [client 187.125.243.197:55942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VZi7ynBpLeKYztQO7HQAAAEE"]
[Tue Jul 21 08:17:58.759153 2026] [security2:error] [pid 411857:tid 412056] [client 20.226.60.151:48780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/admin.php"] [unique_id "al9VZi7ynBpLeKYztQO7IwAAAEM"]
[Tue Jul 21 08:17:58.879457 2026] [security2:error] [pid 411857:tid 412051] [client 20.151.10.161:46045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/aaf.php"] [unique_id "al9VZi7ynBpLeKYztQO7JwAAAD4"]
[Tue Jul 21 08:17:59.119375 2026] [security2:error] [pid 411857:tid 412024] [client 20.197.192.193:13665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/ace2.php"] [unique_id "al9VZy7ynBpLeKYztQO7NgAAACM"]
[Tue Jul 21 08:17:59.154313 2026] [security2:error] [pid 411857:tid 412093] [client 20.226.60.151:49385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/themes.php"] [unique_id "al9VZy7ynBpLeKYztQO7PQAAAGg"]
[Tue Jul 21 08:17:59.304777 2026] [security2:error] [pid 411857:tid 412022] [client 20.206.105.145:25496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/hypo.php"] [unique_id "al9VZy7ynBpLeKYztQO7QgAAACE"]
[Tue Jul 21 08:17:59.425268 2026] [security2:error] [pid 411857:tid 412039] [client 20.151.10.161:46055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/term.php"] [unique_id "al9VZy7ynBpLeKYztQO7RwAAADI"]
[Tue Jul 21 08:17:59.488052 2026] [security2:error] [pid 411857:tid 412105] [client 87.116.180.198:14075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VZy7ynBpLeKYztQO7SwAAAHQ"]
[Tue Jul 21 08:17:59.493646 2026] [security2:error] [pid 411857:tid 412105] [client 87.116.180.198:14075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VZy7ynBpLeKYztQO7SwAAAHQ"]
[Tue Jul 21 08:17:59.587801 2026] [autoindex:error] [pid 411857:tid 412077] [client 20.226.60.151:48849] AH01276: Cannot serve directory /home4/abbapr65/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:17:59.705038 2026] [security2:error] [pid 411857:tid 412114] [client 204.12.208.18:60301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-content/edit.php"] [unique_id "al9VZy7ynBpLeKYztQO7VwAAAH0"], referer: https://mucareis.com.br/wp-content/edit.php
[Tue Jul 21 08:17:59.827546 2026] [security2:error] [pid 411857:tid 412113] [client 20.226.60.151:60313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/item.php"] [unique_id "al9VZy7ynBpLeKYztQO7WgAAAHw"]
[Tue Jul 21 08:17:59.836802 2026] [security2:error] [pid 411857:tid 411977] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VZy7ynBpLeKYztQO7WwAALHU"]
[Tue Jul 21 08:17:59.836921 2026] [security2:error] [pid 411857:tid 412033] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VZy7ynBpLeKYztQO7WwAALHU"]
[Tue Jul 21 08:18:00.001549 2026] [security2:error] [pid 411857:tid 412094] [client 74.249.245.134:15407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/max.php"] [unique_id "al9VaC7ynBpLeKYztQO7YAAAAGk"]
[Tue Jul 21 08:18:00.133179 2026] [security2:error] [pid 411857:tid 412087] [client 115.134.11.136:59942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VaC7ynBpLeKYztQO7agAAAGI"]
[Tue Jul 21 08:18:00.133829 2026] [security2:error] [pid 411857:tid 412087] [client 115.134.11.136:59942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VaC7ynBpLeKYztQO7agAAAGI"]
[Tue Jul 21 08:18:00.149279 2026] [security2:error] [pid 411857:tid 412116] [client 198.54.129.60:34996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9VaC7ynBpLeKYztQO7bgAAAH8"]
[Tue Jul 21 08:18:00.149365 2026] [security2:error] [pid 411857:tid 412116] [client 198.54.129.60:34996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9VaC7ynBpLeKYztQO7bgAAAH8"]
[Tue Jul 21 08:18:00.224040 2026] [security2:error] [pid 411857:tid 411998] [client 173.252.95.9:55776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9VZi7ynBpLeKYztQO6_QAAAAk"]
[Tue Jul 21 08:18:00.383599 2026] [security2:error] [pid 411857:tid 411992] [client 20.151.10.161:45956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/ha.php"] [unique_id "al9VaC7ynBpLeKYztQO7eQAAAAM"]
[Tue Jul 21 08:18:00.385082 2026] [security2:error] [pid 411857:tid 412103] [client 20.206.105.145:25584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/chosen.php"] [unique_id "al9VaC7ynBpLeKYztQO7egAAAHI"]
[Tue Jul 21 08:18:00.464205 2026] [security2:error] [pid 411857:tid 412095] [client 20.226.60.151:52235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/ss.php"] [unique_id "al9VaC7ynBpLeKYztQO7fQAAAGo"]
[Tue Jul 21 08:18:00.490595 2026] [security2:error] [pid 411857:tid 412046] [client 20.197.192.193:13010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/ms.php"] [unique_id "al9VaC7ynBpLeKYztQO7fwAAADk"]
[Tue Jul 21 08:18:00.561491 2026] [security2:error] [pid 411857:tid 411994] [client 103.106.20.201:63808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VaC7ynBpLeKYztQO7gwAAAAU"]
[Tue Jul 21 08:18:00.561580 2026] [security2:error] [pid 411857:tid 411994] [client 103.106.20.201:63808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VaC7ynBpLeKYztQO7gwAAAAU"]
[Tue Jul 21 08:18:00.582961 2026] [security2:error] [pid 411857:tid 411990] [client 14.245.224.124:64533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VaC7ynBpLeKYztQO7hAAAAAE"]
[Tue Jul 21 08:18:00.583095 2026] [security2:error] [pid 411857:tid 411990] [client 14.245.224.124:64533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VaC7ynBpLeKYztQO7hAAAAAE"]
[Tue Jul 21 08:18:00.949372 2026] [security2:error] [pid 411857:tid 412001] [client 62.102.148.158:37446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9VaC7ynBpLeKYztQO7lgAAAAw"]
[Tue Jul 21 08:18:00.949500 2026] [security2:error] [pid 411857:tid 412001] [client 62.102.148.158:37446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9VaC7ynBpLeKYztQO7lgAAAAw"]
[Tue Jul 21 08:18:00.973478 2026] [security2:error] [pid 411857:tid 412099] [client 23.239.30.144:1362] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "br1102.hostgator.com.br"] [uri "/"] [unique_id "al9VaC7ynBpLeKYztQO7lwAAAG4"]
[Tue Jul 21 08:18:01.019340 2026] [security2:error] [pid 411857:tid 412081] [client 20.220.225.223:38703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/min.php"] [unique_id "al9VaS7ynBpLeKYztQO7mAAAAFw"]
[Tue Jul 21 08:18:01.043375 2026] [security2:error] [pid 411857:tid 412058] [client 69.171.230.4:63558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9VaC7ynBpLeKYztQO7kgAAAEU"]
[Tue Jul 21 08:18:01.271414 2026] [security2:error] [pid 411857:tid 412067] [client 20.151.10.161:45982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/hur.php"] [unique_id "al9VaS7ynBpLeKYztQO7qQAAAE4"]
[Tue Jul 21 08:18:01.284768 2026] [security2:error] [pid 411857:tid 412017] [client 20.206.105.145:25483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/file5.php"] [unique_id "al9VaS7ynBpLeKYztQO7qgAAABw"]
[Tue Jul 21 08:18:01.381086 2026] [security2:error] [pid 411857:tid 412095] [client 20.226.60.151:48849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/.well-known/about.php"] [unique_id "al9VaS7ynBpLeKYztQO7rwAAAGo"]
[Tue Jul 21 08:18:01.409258 2026] [security2:error] [pid 411857:tid 412054] [client 65.21.113.253:45600] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VaC7ynBpLeKYztQO7lQAAAEE"]
[Tue Jul 21 08:18:01.623967 2026] [security2:error] [pid 411857:tid 412105] [client 20.206.105.145:25499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/file.php"] [unique_id "al9VaS7ynBpLeKYztQO7ugAAAHQ"]
[Tue Jul 21 08:18:01.700119 2026] [security2:error] [pid 411857:tid 412036] [client 20.226.60.151:48872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9VaS7ynBpLeKYztQO7wwAAAC8"]
[Tue Jul 21 08:18:01.726781 2026] [security2:error] [pid 411857:tid 412063] [client 20.151.10.161:46074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/h02ugyh.php"] [unique_id "al9VaS7ynBpLeKYztQO7xgAAAEo"]
[Tue Jul 21 08:18:01.832882 2026] [security2:error] [pid 411857:tid 412076] [client 74.249.245.134:15140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/m.php"] [unique_id "al9VaS7ynBpLeKYztQO7xwAAAFc"]
[Tue Jul 21 08:18:01.958072 2026] [security2:error] [pid 411857:tid 412009] [client 185.213.175.37:60844] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.rinettoar.com.br"] [uri "/.env.backup"] [unique_id "al9VaS7ynBpLeKYztQO7yAAAABQ"]
[Tue Jul 21 08:18:02.013361 2026] [security2:error] [pid 411857:tid 411890] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vai7ynBpLeKYztQO7ywAALB8"]
[Tue Jul 21 08:18:02.013655 2026] [security2:error] [pid 411857:tid 412033] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vai7ynBpLeKYztQO7ywAALB8"]
[Tue Jul 21 08:18:02.159934 2026] [security2:error] [pid 411857:tid 412048] [client 74.7.241.136:55592] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.monteirosantosesilva.com.br"] [uri "/index.php"] [unique_id "al9Vai7ynBpLeKYztQO7zQAAOws"]
[Tue Jul 21 08:18:02.221517 2026] [security2:error] [pid 411857:tid 412047] [client 69.171.230.16:59506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Vai7ynBpLeKYztQO72QAAADo"]
[Tue Jul 21 08:18:02.221543 2026] [security2:error] [pid 411857:tid 412062] [client 20.226.60.151:48854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/wefile.php"] [unique_id "al9Vai7ynBpLeKYztQO72AAAAEk"]
[Tue Jul 21 08:18:02.233235 2026] [security2:error] [pid 411857:tid 411993] [client 65.21.113.253:39630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VaS7ynBpLeKYztQO7vgAAAAQ"]
[Tue Jul 21 08:18:02.276830 2026] [security2:error] [pid 411857:tid 412028] [client 20.151.10.161:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/seiso.php"] [unique_id "al9Vai7ynBpLeKYztQO73QAAACc"]
[Tue Jul 21 08:18:02.460114 2026] [security2:error] [pid 411857:tid 412022] [client 20.226.60.151:53358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/hypo.php"] [unique_id "al9Vai7ynBpLeKYztQO74wAAACE"]
[Tue Jul 21 08:18:02.627560 2026] [security2:error] [pid 411857:tid 412072] [client 74.7.241.136:55604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "monteirosantosesilva.com.br"] [uri "/index.php"] [unique_id "al9Vai7ynBpLeKYztQO75QAAUyQ"], referer: https://www.monteirosantosesilva.com.br/robots.txt
[Tue Jul 21 08:18:02.628057 2026] [security2:error] [pid 411857:tid 412109] [client 20.226.60.151:48828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9Vai7ynBpLeKYztQO76gAAAHg"]
[Tue Jul 21 08:18:02.653781 2026] [security2:error] [pid 411857:tid 412002] [client 137.97.59.154:16797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Vai7ynBpLeKYztQO76wAAAA0"]
[Tue Jul 21 08:18:02.653943 2026] [security2:error] [pid 411857:tid 412002] [client 137.97.59.154:16797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Vai7ynBpLeKYztQO76wAAAA0"]
[Tue Jul 21 08:18:02.857230 2026] [security2:error] [pid 411857:tid 412058] [client 150.129.202.39:64806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vai7ynBpLeKYztQO79wAAAEU"]
[Tue Jul 21 08:18:02.857348 2026] [security2:error] [pid 411857:tid 412058] [client 150.129.202.39:64806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vai7ynBpLeKYztQO79wAAAEU"]
[Tue Jul 21 08:18:02.898305 2026] [security2:error] [pid 411857:tid 412113] [client 20.151.10.161:45984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/155.php"] [unique_id "al9Vai7ynBpLeKYztQO7_AAAAHw"]
[Tue Jul 21 08:18:02.966269 2026] [autoindex:error] [pid 411857:tid 412096] [client 20.226.60.151:48795] AH01276: Cannot serve directory /home4/abbapr65/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:18:02.987185 2026] [security2:error] [pid 411857:tid 412009] [client 20.206.105.145:25137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/aa2.php"] [unique_id "al9Vai7ynBpLeKYztQO8BQAAABQ"]
[Tue Jul 21 08:18:03.081168 2026] [autoindex:error] [pid 411857:tid 412073] [client 20.226.60.151:48795] AH01276: Cannot serve directory /home4/abbapr65/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:18:03.100687 2026] [security2:error] [pid 411857:tid 412048] [client 20.226.60.151:48795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Vay7ynBpLeKYztQO8CgAAADs"]
[Tue Jul 21 08:18:03.221792 2026] [security2:error] [pid 411857:tid 412041] [client 62.102.148.158:37458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Vay7ynBpLeKYztQO8CwAAADQ"]
[Tue Jul 21 08:18:03.221916 2026] [security2:error] [pid 411857:tid 412041] [client 62.102.148.158:37458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Vay7ynBpLeKYztQO8CwAAADQ"]
[Tue Jul 21 08:18:03.226676 2026] [security2:error] [pid 411857:tid 412006] [client 61.1.167.83:58741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vay7ynBpLeKYztQO8DgAAABE"]
[Tue Jul 21 08:18:03.226793 2026] [security2:error] [pid 411857:tid 412006] [client 61.1.167.83:58741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vay7ynBpLeKYztQO8DgAAABE"]
[Tue Jul 21 08:18:03.226831 2026] [security2:error] [pid 411857:tid 412098] [client 20.226.60.151:48827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/8.php"] [unique_id "al9Vay7ynBpLeKYztQO8DQAAAG0"]
[Tue Jul 21 08:18:03.252794 2026] [security2:error] [pid 411857:tid 412054] [client 117.210.135.0:64810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vay7ynBpLeKYztQO8FAAAAEE"]
[Tue Jul 21 08:18:03.252958 2026] [security2:error] [pid 411857:tid 412054] [client 117.210.135.0:64810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vay7ynBpLeKYztQO8FAAAAEE"]
[Tue Jul 21 08:18:03.465749 2026] [security2:error] [pid 411857:tid 412109] [client 20.226.60.151:48799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/wp-content/admin.php"] [unique_id "al9Vay7ynBpLeKYztQO8IAAAAHg"]
[Tue Jul 21 08:18:03.600548 2026] [security2:error] [pid 411857:tid 412114] [client 20.226.60.151:52011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/users.php"] [unique_id "al9Vay7ynBpLeKYztQO8JAAAAH0"]
[Tue Jul 21 08:18:03.625554 2026] [security2:error] [pid 411857:tid 412064] [client 120.56.162.40:55525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vay7ynBpLeKYztQO8JQAAAEs"]
[Tue Jul 21 08:18:03.625836 2026] [security2:error] [pid 411857:tid 412064] [client 120.56.162.40:55525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vay7ynBpLeKYztQO8JQAAAEs"]
[Tue Jul 21 08:18:03.646411 2026] [security2:error] [pid 411857:tid 412058] [client 74.249.245.134:31385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/click.php"] [unique_id "al9Vay7ynBpLeKYztQO8JgAAAEU"]
[Tue Jul 21 08:18:03.779162 2026] [security2:error] [pid 411857:tid 411930] [remote 173.252.95.59:35844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Vay7ynBpLeKYztQO8LgAAckc"]
[Tue Jul 21 08:18:03.832352 2026] [security2:error] [pid 411857:tid 411921] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vay7ynBpLeKYztQO8MgAAPD4"]
[Tue Jul 21 08:18:03.832631 2026] [security2:error] [pid 411857:tid 412049] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vay7ynBpLeKYztQO8MgAAPD4"]
[Tue Jul 21 08:18:03.836226 2026] [access_compat:error] [pid 411857:tid 412071] [client 162.241.63.68:41500] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:18:03.927609 2026] [security2:error] [pid 411857:tid 412000] [client 20.226.60.151:48883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/f6.php"] [unique_id "al9Vay7ynBpLeKYztQO8NQAAAAs"]
[Tue Jul 21 08:18:03.994182 2026] [security2:error] [pid 411857:tid 412019] [client 65.21.113.253:39642] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vay7ynBpLeKYztQO8MwAAAB4"]
[Tue Jul 21 08:18:04.304463 2026] [security2:error] [pid 411857:tid 412007] [client 20.151.10.161:45968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/ppp.php"] [unique_id "al9VbC7ynBpLeKYztQO8SwAAABI"]
[Tue Jul 21 08:18:04.354958 2026] [security2:error] [pid 411857:tid 412074] [client 45.227.253.15:34280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.253.227.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "portal.fastpedidos.com.br"] [uri "/index.php/jk"] [unique_id "al9VbC7ynBpLeKYztQO8TgAAAFU"]
[Tue Jul 21 08:18:04.503925 2026] [security2:error] [pid 411857:tid 411950] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VbC7ynBpLeKYztQO8VQAAEFs"]
[Tue Jul 21 08:18:04.504126 2026] [security2:error] [pid 411857:tid 412005] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VbC7ynBpLeKYztQO8VQAAEFs"]
[Tue Jul 21 08:18:04.728389 2026] [security2:error] [pid 411857:tid 412092] [client 65.21.113.253:39630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VbC7ynBpLeKYztQO8RgAAAGc"]
[Tue Jul 21 08:18:04.742253 2026] [security2:error] [pid 411857:tid 412025] [client 20.226.60.151:52020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/177.php"] [unique_id "al9VbC7ynBpLeKYztQO8WQAAACQ"]
[Tue Jul 21 08:18:05.035122 2026] [security2:error] [pid 411857:tid 412083] [client 20.226.60.151:49355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/inputs.php"] [unique_id "al9VbS7ynBpLeKYztQO8bwAAAF4"]
[Tue Jul 21 08:18:05.067759 2026] [security2:error] [pid 411857:tid 412019] [client 20.206.105.145:25417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/ccou.php"] [unique_id "al9VbS7ynBpLeKYztQO8cAAAAB4"]
[Tue Jul 21 08:18:05.420300 2026] [security2:error] [pid 411857:tid 412015] [client 20.226.60.151:48852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/inputs.php"] [unique_id "al9VbS7ynBpLeKYztQO8fQAAABo"]
[Tue Jul 21 08:18:05.447636 2026] [security2:error] [pid 411857:tid 412034] [client 20.151.10.161:46026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/201.php"] [unique_id "al9VbS7ynBpLeKYztQO8fgAAAC0"]
[Tue Jul 21 08:18:05.494602 2026] [security2:error] [pid 411857:tid 412103] [client 223.181.60.88:5673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VbS7ynBpLeKYztQO8gAAAAHI"]
[Tue Jul 21 08:18:05.495301 2026] [security2:error] [pid 411857:tid 412103] [client 223.181.60.88:5673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VbS7ynBpLeKYztQO8gAAAAHI"]
[Tue Jul 21 08:18:05.684653 2026] [security2:error] [pid 411857:tid 412010] [client 20.226.60.151:48814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/classwithtostring.php"] [unique_id "al9VbS7ynBpLeKYztQO8jQAAABU"]
[Tue Jul 21 08:18:05.919042 2026] [security2:error] [pid 411857:tid 412003] [client 20.226.60.151:48770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9VbS7ynBpLeKYztQO8mAAAAA4"]
[Tue Jul 21 08:18:06.042586 2026] [security2:error] [pid 411857:tid 412081] [client 20.151.10.161:46029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/ops.php"] [unique_id "al9Vbi7ynBpLeKYztQO8ngAAAFw"]
[Tue Jul 21 08:18:06.178714 2026] [security2:error] [pid 411857:tid 412032] [client 20.226.60.151:48797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/wp-blog.php"] [unique_id "al9Vbi7ynBpLeKYztQO8owAAACs"]
[Tue Jul 21 08:18:06.312679 2026] [autoindex:error] [pid 411857:tid 412028] [client 20.226.60.151:48842] AH01276: Cannot serve directory /home4/abbapr65/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:18:06.342619 2026] [security2:error] [pid 411857:tid 412069] [client 20.226.60.151:48842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/wp-content/admin.php"] [unique_id "al9Vbi7ynBpLeKYztQO8rQAAAFA"]
[Tue Jul 21 08:18:06.476267 2026] [security2:error] [pid 411857:tid 412007] [client 20.151.10.161:45901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/ingfo.php"] [unique_id "al9Vbi7ynBpLeKYztQO8sgAAABI"]
[Tue Jul 21 08:18:06.588538 2026] [security2:error] [pid 411857:tid 412089] [client 20.226.60.151:48862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/ms-edit.php"] [unique_id "al9Vbi7ynBpLeKYztQO8tQAAAGQ"]
[Tue Jul 21 08:18:06.728503 2026] [security2:error] [pid 411857:tid 412037] [client 74.249.245.134:15360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/lv.php"] [unique_id "al9Vbi7ynBpLeKYztQO8ugAAADA"]
[Tue Jul 21 08:18:06.774193 2026] [security2:error] [pid 411857:tid 412073] [client 65.21.113.253:39630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vbi7ynBpLeKYztQO8rAAAAFQ"]
[Tue Jul 21 08:18:06.966851 2026] [security2:error] [pid 411857:tid 412001] [client 152.59.34.51:51319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Vbi7ynBpLeKYztQO8xwAAAAw"]
[Tue Jul 21 08:18:06.967064 2026] [security2:error] [pid 411857:tid 412001] [client 152.59.34.51:51319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Vbi7ynBpLeKYztQO8xwAAAAw"]
[Tue Jul 21 08:18:06.971393 2026] [security2:error] [pid 411857:tid 411867] [remote 132.148.72.88:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9Vbi7ynBpLeKYztQO8yAAAegg"]
[Tue Jul 21 08:18:07.077093 2026] [security2:error] [pid 411857:tid 411966] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Vby7ynBpLeKYztQO8ywAAe2o"]
[Tue Jul 21 08:18:07.077323 2026] [security2:error] [pid 411857:tid 412112] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Vby7ynBpLeKYztQO8ywAAe2o"]
[Tue Jul 21 08:18:07.383721 2026] [security2:error] [pid 411857:tid 412023] [client 20.206.105.145:25574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/dr.php"] [unique_id "al9Vby7ynBpLeKYztQO82gAAACI"]
[Tue Jul 21 08:18:07.412123 2026] [security2:error] [pid 411857:tid 412012] [client 20.226.60.151:48873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/cgi-bin/index.php"] [unique_id "al9Vby7ynBpLeKYztQO83QAAABc"]
[Tue Jul 21 08:18:07.510913 2026] [security2:error] [pid 411857:tid 412077] [client 38.100.221.102:18805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vby7ynBpLeKYztQO84gAAAFg"]
[Tue Jul 21 08:18:07.511047 2026] [security2:error] [pid 411857:tid 412077] [client 38.100.221.102:18805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vby7ynBpLeKYztQO84gAAAFg"]
[Tue Jul 21 08:18:07.619540 2026] [security2:error] [pid 411857:tid 412066] [client 154.208.47.43:59903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Vby7ynBpLeKYztQO85AAAAE0"]
[Tue Jul 21 08:18:07.619752 2026] [security2:error] [pid 411857:tid 412066] [client 154.208.47.43:59903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Vby7ynBpLeKYztQO85AAAAE0"]
[Tue Jul 21 08:18:07.694556 2026] [autoindex:error] [pid 411857:tid 412116] [client 20.226.60.151:48876] AH01276: Cannot serve directory /home4/abbapr65/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:18:07.719941 2026] [security2:error] [pid 411857:tid 412067] [client 20.226.60.151:48876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/BDKR28WP.php"] [unique_id "al9Vby7ynBpLeKYztQO86AAAAE4"]
[Tue Jul 21 08:18:07.777741 2026] [security2:error] [pid 411857:tid 412050] [client 20.151.10.161:45911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/error_log.php"] [unique_id "al9Vby7ynBpLeKYztQO87AAAAD0"]
[Tue Jul 21 08:18:08.049802 2026] [autoindex:error] [pid 411857:tid 412031] [client 20.226.60.151:48831] AH01276: Cannot serve directory /home4/abbapr65/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:18:08.069135 2026] [autoindex:error] [pid 411857:tid 412053] [client 20.226.60.151:48831] AH01276: Cannot serve directory /home4/abbapr65/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:18:08.074930 2026] [security2:error] [pid 411857:tid 412078] [client 20.226.60.151:48831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/abcd.php"] [unique_id "al9VcC7ynBpLeKYztQO8-wAAAFk"]
[Tue Jul 21 08:18:08.100690 2026] [security2:error] [pid 411857:tid 411877] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VcC7ynBpLeKYztQO8_AAAaBI"]
[Tue Jul 21 08:18:08.100836 2026] [security2:error] [pid 411857:tid 412093] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VcC7ynBpLeKYztQO8_AAAaBI"]
[Tue Jul 21 08:18:08.220521 2026] [security2:error] [pid 411857:tid 411886] [remote 208.109.9.173:33308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rqracademy.com"] [uri "/wp-login.php"] [unique_id "al9Vby7ynBpLeKYztQO80gAANBs"]
[Tue Jul 21 08:18:08.317354 2026] [security2:error] [pid 411857:tid 411993] [client 103.151.46.103:53405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VcC7ynBpLeKYztQO9BQAAAAQ"]
[Tue Jul 21 08:18:08.317500 2026] [security2:error] [pid 411857:tid 411993] [client 103.151.46.103:53405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VcC7ynBpLeKYztQO9BQAAAAQ"]
[Tue Jul 21 08:18:08.434056 2026] [security2:error] [pid 411857:tid 412032] [client 20.220.225.223:24265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/yup.php"] [unique_id "al9VcC7ynBpLeKYztQO9DQAAACs"]
[Tue Jul 21 08:18:08.526049 2026] [security2:error] [pid 411857:tid 412099] [client 162.219.176.3:38550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9VcC7ynBpLeKYztQO9EQAAAG4"]
[Tue Jul 21 08:18:08.526158 2026] [security2:error] [pid 411857:tid 412099] [client 162.219.176.3:38550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9VcC7ynBpLeKYztQO9EQAAAG4"]
[Tue Jul 21 08:18:08.631268 2026] [security2:error] [pid 411857:tid 412085] [client 65.21.113.253:39630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VcC7ynBpLeKYztQO8_gAAAGA"]
[Tue Jul 21 08:18:08.642012 2026] [security2:error] [pid 411857:tid 412077] [client 20.226.60.151:49346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/file15.php"] [unique_id "al9VcC7ynBpLeKYztQO9FAAAAFg"]
[Tue Jul 21 08:18:08.705640 2026] [security2:error] [pid 411857:tid 412020] [client 103.78.200.11:64560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VcC7ynBpLeKYztQO9FQAAAB8"]
[Tue Jul 21 08:18:08.705785 2026] [security2:error] [pid 411857:tid 412020] [client 103.78.200.11:64560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VcC7ynBpLeKYztQO9FQAAAB8"]
[Tue Jul 21 08:18:08.801673 2026] [security2:error] [pid 411857:tid 412069] [client 20.151.10.161:46049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/xenon1337.php"] [unique_id "al9VcC7ynBpLeKYztQO9GgAAAFA"]
[Tue Jul 21 08:18:08.914706 2026] [security2:error] [pid 411857:tid 412036] [client 20.206.105.145:25596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/file31.php"] [unique_id "al9VcC7ynBpLeKYztQO9KAAAAC8"]
[Tue Jul 21 08:18:08.937270 2026] [security2:error] [pid 411857:tid 412112] [client 102.206.115.33:59992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VcC7ynBpLeKYztQO9KwAAAHs"]
[Tue Jul 21 08:18:08.937422 2026] [security2:error] [pid 411857:tid 412112] [client 102.206.115.33:59992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VcC7ynBpLeKYztQO9KwAAAHs"]
[Tue Jul 21 08:18:09.100839 2026] [security2:error] [pid 411857:tid 412014] [client 187.125.243.197:56436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VcS7ynBpLeKYztQO9MQAAABk"]
[Tue Jul 21 08:18:09.101044 2026] [security2:error] [pid 411857:tid 412014] [client 187.125.243.197:56436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VcS7ynBpLeKYztQO9MQAAABk"]
[Tue Jul 21 08:18:09.320227 2026] [security2:error] [pid 411857:tid 412080] [client 74.249.245.134:15387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/cong.php"] [unique_id "al9VcS7ynBpLeKYztQO9OAAAAFs"]
[Tue Jul 21 08:18:09.549102 2026] [security2:error] [pid 411857:tid 412044] [client 20.151.10.161:45997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/test11.php"] [unique_id "al9VcS7ynBpLeKYztQO9RQAAADc"]
[Tue Jul 21 08:18:09.805498 2026] [security2:error] [pid 411857:tid 412020] [client 20.226.60.151:2930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/config.php"] [unique_id "al9VcS7ynBpLeKYztQO9SgAAAB8"]
[Tue Jul 21 08:18:09.975886 2026] [security2:error] [pid 411857:tid 412056] [client 20.226.60.151:64077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9VcS7ynBpLeKYztQO9UAAAAEM"]
[Tue Jul 21 08:18:09.988923 2026] [security2:error] [pid 411857:tid 412054] [client 20.226.60.151:48857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/jp.php"] [unique_id "al9VcS7ynBpLeKYztQO9UQAAAEE"]
[Tue Jul 21 08:18:10.129649 2026] [security2:error] [pid 411857:tid 412009] [client 87.116.180.198:27212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vci7ynBpLeKYztQO9VgAAABQ"]
[Tue Jul 21 08:18:10.129763 2026] [security2:error] [pid 411857:tid 412009] [client 87.116.180.198:27212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vci7ynBpLeKYztQO9VgAAABQ"]
[Tue Jul 21 08:18:10.283109 2026] [security2:error] [pid 411857:tid 412092] [client 20.206.105.145:25108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/file6.php"] [unique_id "al9Vci7ynBpLeKYztQO9XgAAAGc"]
[Tue Jul 21 08:18:10.361315 2026] [security2:error] [pid 411857:tid 411948] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vci7ynBpLeKYztQO9ZgAAfVk"]
[Tue Jul 21 08:18:10.361526 2026] [security2:error] [pid 411857:tid 412114] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vci7ynBpLeKYztQO9ZgAAfVk"]
[Tue Jul 21 08:18:10.388102 2026] [security2:error] [pid 411857:tid 412063] [client 20.151.10.161:46014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/koala.php"] [unique_id "al9Vci7ynBpLeKYztQO9ZwAAAEo"]
[Tue Jul 21 08:18:10.553633 2026] [security2:error] [pid 411857:tid 412113] [client 162.219.176.3:38554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Vci7ynBpLeKYztQO9cAAAAHw"]
[Tue Jul 21 08:18:10.553770 2026] [security2:error] [pid 411857:tid 412113] [client 162.219.176.3:38554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Vci7ynBpLeKYztQO9cAAAAHw"]
[Tue Jul 21 08:18:10.900048 2026] [security2:error] [pid 411857:tid 412099] [client 115.134.11.136:60347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vci7ynBpLeKYztQO9gAAAAG4"]
[Tue Jul 21 08:18:10.900846 2026] [security2:error] [pid 411857:tid 412099] [client 115.134.11.136:60347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vci7ynBpLeKYztQO9gAAAAG4"]
[Tue Jul 21 08:18:11.094371 2026] [security2:error] [pid 411857:tid 412021] [client 151.63.71.144:54288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Vcy7ynBpLeKYztQO9hgAAACA"]
[Tue Jul 21 08:18:11.094560 2026] [security2:error] [pid 411857:tid 412021] [client 151.63.71.144:54288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Vcy7ynBpLeKYztQO9hgAAACA"]
[Tue Jul 21 08:18:11.173990 2026] [security2:error] [pid 411857:tid 412011] [client 103.106.20.201:64388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vcy7ynBpLeKYztQO9jAAAABY"]
[Tue Jul 21 08:18:11.174103 2026] [security2:error] [pid 411857:tid 412011] [client 103.106.20.201:64388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vcy7ynBpLeKYztQO9jAAAABY"]
[Tue Jul 21 08:18:11.182551 2026] [security2:error] [pid 411857:tid 412066] [client 20.151.10.161:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/mac.php"] [unique_id "al9Vcy7ynBpLeKYztQO9jQAAAE0"]
[Tue Jul 21 08:18:11.206169 2026] [security2:error] [pid 411857:tid 412048] [client 14.245.224.124:64956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Vcy7ynBpLeKYztQO9jgAAADs"]
[Tue Jul 21 08:18:11.206281 2026] [security2:error] [pid 411857:tid 412048] [client 14.245.224.124:64956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Vcy7ynBpLeKYztQO9jgAAADs"]
[Tue Jul 21 08:18:11.243884 2026] [security2:error] [pid 411857:tid 411943] [remote 51.161.37.254:57298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "fnk.org.br"] [uri "/robots.txt"] [unique_id "al9Vcy7ynBpLeKYztQO9kAAAMVQ"]
[Tue Jul 21 08:18:11.244096 2026] [security2:error] [pid 411857:tid 412038] [client 51.161.37.254:57298] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fnk.org.br"] [uri "/robots.txt"] [unique_id "al9Vcy7ynBpLeKYztQO9kAAAMVQ"]
[Tue Jul 21 08:18:11.644305 2026] [security2:error] [pid 411857:tid 411989] [client 20.206.105.145:25592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/file15.php"] [unique_id "al9Vcy7ynBpLeKYztQO9nwAAAAA"]
[Tue Jul 21 08:18:11.776897 2026] [security2:error] [pid 411857:tid 412111] [client 20.151.10.161:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9Vcy7ynBpLeKYztQO9qAAAAHo"]
[Tue Jul 21 08:18:11.913167 2026] [security2:error] [pid 411857:tid 412012] [client 20.220.225.223:24219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/jj.php"] [unique_id "al9Vcy7ynBpLeKYztQO9rQAAABc"]
[Tue Jul 21 08:18:12.095475 2026] [security2:error] [pid 411857:tid 412104] [client 111.93.58.162:35114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VdC7ynBpLeKYztQO9twAAAHM"]
[Tue Jul 21 08:18:12.095592 2026] [security2:error] [pid 411857:tid 412104] [client 111.93.58.162:35114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VdC7ynBpLeKYztQO9twAAAHM"]
[Tue Jul 21 08:18:12.179768 2026] [security2:error] [pid 411857:tid 412048] [client 20.226.60.151:60340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/gettest.php"] [unique_id "al9VdC7ynBpLeKYztQO9uQAAADs"]
[Tue Jul 21 08:18:12.194945 2026] [security2:error] [pid 411857:tid 412038] [client 20.151.10.161:46016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wefile.php"] [unique_id "al9VdC7ynBpLeKYztQO9ugAAADE"]
[Tue Jul 21 08:18:12.470590 2026] [security2:error] [pid 411857:tid 411926] [remote 216.73.160.30:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-login.php"] [unique_id "al9Vcy7ynBpLeKYztQO9kgAAdEM"]
[Tue Jul 21 08:18:12.525842 2026] [security2:error] [pid 411857:tid 412071] [client 20.226.60.151:49230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/f35.php"] [unique_id "al9VdC7ynBpLeKYztQO9xAAAAFI"]
[Tue Jul 21 08:18:13.232838 2026] [security2:error] [pid 411857:tid 411863] [remote 54.39.136.47:36386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "fnk.org.br"] [uri "/"] [unique_id "al9VdS7ynBpLeKYztQO94gAAWQQ"]
[Tue Jul 21 08:18:13.232994 2026] [security2:error] [pid 411857:tid 412078] [client 54.39.136.47:36386] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fnk.org.br"] [uri "/"] [unique_id "al9VdS7ynBpLeKYztQO94gAAWQQ"]
[Tue Jul 21 08:18:13.233525 2026] [security2:error] [pid 411857:tid 411958] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VdS7ynBpLeKYztQO94QAAP2I"]
[Tue Jul 21 08:18:13.233665 2026] [security2:error] [pid 411857:tid 412052] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VdS7ynBpLeKYztQO94QAAP2I"]
[Tue Jul 21 08:18:13.324989 2026] [security2:error] [pid 411857:tid 412061] [client 62.102.148.158:58156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9VdS7ynBpLeKYztQO95QAAAEg"]
[Tue Jul 21 08:18:13.325097 2026] [security2:error] [pid 411857:tid 412061] [client 62.102.148.158:58156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9VdS7ynBpLeKYztQO95QAAAEg"]
[Tue Jul 21 08:18:13.421847 2026] [security2:error] [pid 411857:tid 412069] [client 20.151.10.161:46044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9VdS7ynBpLeKYztQO97QAAAFA"]
[Tue Jul 21 08:18:13.428172 2026] [security2:error] [pid 411857:tid 411991] [client 150.129.202.39:65473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VdS7ynBpLeKYztQO97gAAAAI"]
[Tue Jul 21 08:18:13.428308 2026] [security2:error] [pid 411857:tid 411991] [client 150.129.202.39:65473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VdS7ynBpLeKYztQO97gAAAAI"]
[Tue Jul 21 08:18:13.534585 2026] [security2:error] [pid 411857:tid 412043] [client 74.249.245.134:15369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/brand.php"] [unique_id "al9VdS7ynBpLeKYztQO98QAAADY"]
[Tue Jul 21 08:18:13.661675 2026] [security2:error] [pid 411857:tid 412083] [client 65.21.113.253:39630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VdS7ynBpLeKYztQO93wAAAF4"]
[Tue Jul 21 08:18:13.719161 2026] [security2:error] [pid 411857:tid 412014] [client 117.210.135.0:65464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VdS7ynBpLeKYztQO9-wAAABk"]
[Tue Jul 21 08:18:13.719257 2026] [security2:error] [pid 411857:tid 412014] [client 117.210.135.0:65464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VdS7ynBpLeKYztQO9-wAAABk"]
[Tue Jul 21 08:18:13.850805 2026] [security2:error] [pid 411857:tid 412105] [client 20.151.10.161:45900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/2P.php"] [unique_id "al9VdS7ynBpLeKYztQO-AAAAAHQ"]
[Tue Jul 21 08:18:14.062252 2026] [security2:error] [pid 411857:tid 412056] [client 20.206.105.145:25589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/jp.php"] [unique_id "al9Vdi7ynBpLeKYztQO-BQAAAEM"]
[Tue Jul 21 08:18:14.120355 2026] [security2:error] [pid 411857:tid 412050] [client 173.252.95.58:55968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Vdi7ynBpLeKYztQO-BgAAAD0"]
[Tue Jul 21 08:18:14.142796 2026] [security2:error] [pid 411857:tid 412094] [client 65.21.113.253:51226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VdS7ynBpLeKYztQO9-AAAAGk"]
[Tue Jul 21 08:18:14.342865 2026] [security2:error] [pid 411857:tid 412038] [client 120.56.162.40:56030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vdi7ynBpLeKYztQO-EAAAADE"]
[Tue Jul 21 08:18:14.342991 2026] [security2:error] [pid 411857:tid 412038] [client 120.56.162.40:56030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vdi7ynBpLeKYztQO-EAAAADE"]
[Tue Jul 21 08:18:14.434656 2026] [security2:error] [pid 411857:tid 411978] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vdi7ynBpLeKYztQO-FQAAZ3Y"]
[Tue Jul 21 08:18:14.434870 2026] [security2:error] [pid 411857:tid 412092] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vdi7ynBpLeKYztQO-FQAAZ3Y"]
[Tue Jul 21 08:18:14.576040 2026] [security2:error] [pid 411857:tid 412012] [client 74.7.244.58:46916] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.carolinadona.com"] [uri "/index.php"] [unique_id "al9VdS7ynBpLeKYztQO98AAAFww"]
[Tue Jul 21 08:18:14.668952 2026] [security2:error] [pid 411857:tid 412010] [client 20.226.60.151:48774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/wp-load.php"] [unique_id "al9Vdi7ynBpLeKYztQO-HQAAABU"]
[Tue Jul 21 08:18:14.687500 2026] [security2:error] [pid 411857:tid 412008] [client 20.151.10.161:45905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Vdi7ynBpLeKYztQO-HwAAABM"]
[Tue Jul 21 08:18:14.958166 2026] [security2:error] [pid 411857:tid 412093] [client 20.220.225.223:24275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/dragonshell.php"] [unique_id "al9Vdi7ynBpLeKYztQO-LgAAAGg"]
[Tue Jul 21 08:18:15.018893 2026] [security2:error] [pid 411857:tid 412065] [client 74.7.244.58:46918] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "carolinadona.com"] [uri "/index.php"] [unique_id "al9Vdi7ynBpLeKYztQO-LQAATAc"], referer: https://www.carolinadona.com/robots.txt
[Tue Jul 21 08:18:15.069164 2026] [security2:error] [pid 411857:tid 411997] [client 74.7.230.32:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "littlefreedom.au"] [uri "/cgi-sys/404.html"] [unique_id "al9Vdy7ynBpLeKYztQO-MgAAAAg"]
[Tue Jul 21 08:18:15.069682 2026] [security2:error] [pid 411857:tid 412095] [client 74.7.230.32:53866] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "littlefreedom.au"] [uri "/robots.txt"] [unique_id "al9Vdy7ynBpLeKYztQO-MAAAahU"]
[Tue Jul 21 08:18:15.095315 2026] [security2:error] [pid 411857:tid 412062] [client 20.226.60.151:64090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Vdy7ynBpLeKYztQO-NAAAAEk"]
[Tue Jul 21 08:18:15.197891 2026] [security2:error] [pid 411857:tid 411899] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Vdy7ynBpLeKYztQO-OgAAOyg"]
[Tue Jul 21 08:18:15.198037 2026] [security2:error] [pid 411857:tid 412048] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Vdy7ynBpLeKYztQO-OgAAOyg"]
[Tue Jul 21 08:18:15.240751 2026] [core:error] [pid 411857:tid 411984] [remote 52.167.144.18:17665] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:18:15.240775 2026] [core:error] [pid 411857:tid 411984] [remote 52.167.144.18:17665] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:18:15.299141 2026] [security2:error] [pid 411857:tid 412073] [client 20.206.105.145:25591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/f35.php"] [unique_id "al9Vdy7ynBpLeKYztQO-PQAAAFQ"]
[Tue Jul 21 08:18:15.466740 2026] [security2:error] [pid 411857:tid 412075] [client 20.151.10.161:46078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Vdy7ynBpLeKYztQO-RQAAAFY"]
[Tue Jul 21 08:18:16.163704 2026] [security2:error] [pid 411857:tid 412051] [client 223.181.60.88:25391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VeC7ynBpLeKYztQO-YwAAAD4"]
[Tue Jul 21 08:18:16.163878 2026] [security2:error] [pid 411857:tid 412051] [client 223.181.60.88:25391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VeC7ynBpLeKYztQO-YwAAAD4"]
[Tue Jul 21 08:18:16.209317 2026] [security2:error] [pid 411857:tid 412052] [client 20.197.192.193:48741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/cron-tab.php"] [unique_id "al9VeC7ynBpLeKYztQO-ZAAAAD8"]
[Tue Jul 21 08:18:16.220486 2026] [security2:error] [pid 411857:tid 411997] [client 20.151.10.161:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/bob.php"] [unique_id "al9VeC7ynBpLeKYztQO-ZQAAAAg"]
[Tue Jul 21 08:18:16.402981 2026] [security2:error] [pid 411857:tid 412068] [client 20.226.60.151:48813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xyn.php"] [unique_id "al9VeC7ynBpLeKYztQO-cQAAAE8"]
[Tue Jul 21 08:18:16.636436 2026] [security2:error] [pid 411857:tid 412002] [client 74.249.245.134:31300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/atomlib.php"] [unique_id "al9VeC7ynBpLeKYztQO-ewAAAA0"]
[Tue Jul 21 08:18:16.696511 2026] [security2:error] [pid 411857:tid 411994] [client 20.226.60.151:52003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/min.php"] [unique_id "al9VeC7ynBpLeKYztQO-fAAAAAU"]
[Tue Jul 21 08:18:16.746944 2026] [security2:error] [pid 411857:tid 411930] [remote 212.80.9.235:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9VeC7ynBpLeKYztQO-fQAAXEc"]
[Tue Jul 21 08:18:16.848479 2026] [security2:error] [pid 411857:tid 412003] [client 162.219.176.3:44336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9VeC7ynBpLeKYztQO-hwAAAA4"]
[Tue Jul 21 08:18:16.848583 2026] [security2:error] [pid 411857:tid 412003] [client 162.219.176.3:44336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9VeC7ynBpLeKYztQO-hwAAAA4"]
[Tue Jul 21 08:18:17.464773 2026] [security2:error] [pid 411857:tid 412016] [client 20.220.225.223:24295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/wp-mt.php"] [unique_id "al9VeS7ynBpLeKYztQO-owAAABs"]
[Tue Jul 21 08:18:17.469639 2026] [security2:error] [pid 411857:tid 412019] [client 65.21.113.253:51226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VeS7ynBpLeKYztQO-kwAAAB4"]
[Tue Jul 21 08:18:17.502609 2026] [security2:error] [pid 411857:tid 412101] [client 198.54.129.60:44750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9VeS7ynBpLeKYztQO-pQAAAHA"]
[Tue Jul 21 08:18:17.502728 2026] [security2:error] [pid 411857:tid 412101] [client 198.54.129.60:44750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9VeS7ynBpLeKYztQO-pQAAAHA"]
[Tue Jul 21 08:18:17.504701 2026] [security2:error] [pid 411857:tid 412089] [client 20.151.10.161:46056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/crgio.php"] [unique_id "al9VeS7ynBpLeKYztQO-pgAAAGQ"]
[Tue Jul 21 08:18:17.564722 2026] [security2:error] [pid 411857:tid 411941] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VeS7ynBpLeKYztQO-pwAAW1I"]
[Tue Jul 21 08:18:17.564895 2026] [security2:error] [pid 411857:tid 412080] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VeS7ynBpLeKYztQO-pwAAW1I"]
[Tue Jul 21 08:18:17.656875 2026] [security2:error] [pid 411857:tid 412075] [client 152.59.34.51:51769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VeS7ynBpLeKYztQO-rQAAAFY"]
[Tue Jul 21 08:18:17.656998 2026] [security2:error] [pid 411857:tid 412075] [client 152.59.34.51:51769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VeS7ynBpLeKYztQO-rQAAAFY"]
[Tue Jul 21 08:18:17.798942 2026] [security2:error] [pid 411857:tid 411996] [client 74.249.245.134:15153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/0x.php"] [unique_id "al9VeS7ynBpLeKYztQO-sAAAAAc"]
[Tue Jul 21 08:18:17.874176 2026] [autoindex:error] [pid 411857:tid 412053] [client 20.226.60.151:49368] AH01276: Cannot serve directory /home4/abbapr65/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:18:18.086548 2026] [security2:error] [pid 411857:tid 412058] [client 20.206.105.145:25541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wp-load.php"] [unique_id "al9Vei7ynBpLeKYztQO-vgAAAEU"]
[Tue Jul 21 08:18:18.100160 2026] [security2:error] [pid 411857:tid 412105] [client 38.100.221.102:17596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vei7ynBpLeKYztQO-vwAAAHQ"]
[Tue Jul 21 08:18:18.100328 2026] [security2:error] [pid 411857:tid 412105] [client 38.100.221.102:17596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vei7ynBpLeKYztQO-vwAAAHQ"]
[Tue Jul 21 08:18:18.113960 2026] [security2:error] [pid 411857:tid 412067] [client 154.208.47.43:60569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Vei7ynBpLeKYztQO-wAAAAE4"]
[Tue Jul 21 08:18:18.118640 2026] [security2:error] [pid 411857:tid 412067] [client 154.208.47.43:60569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Vei7ynBpLeKYztQO-wAAAAE4"]
[Tue Jul 21 08:18:18.183577 2026] [security2:error] [pid 411857:tid 412076] [client 20.151.10.161:45993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/pucci.php"] [unique_id "al9Vei7ynBpLeKYztQO-wwAAAFc"]
[Tue Jul 21 08:18:18.302695 2026] [log_config:warn] [pid 352421:tid 352640] (32)Broken pipe: [client 110.137.100.79:9261] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:18:18.302719 2026] [log_config:warn] [pid 352421:tid 352640] (32)Broken pipe: [client 110.137.100.79:9261] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:18:18.573920 2026] [autoindex:error] [pid 411857:tid 412083] [client 20.226.60.151:49368] AH01276: Cannot serve directory /home4/abbapr65/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:18:18.583219 2026] [security2:error] [pid 411857:tid 412016] [client 20.226.60.151:49368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/ccc.php"] [unique_id "al9Vei7ynBpLeKYztQO-1QAAABs"]
[Tue Jul 21 08:18:18.807877 2026] [security2:error] [pid 411857:tid 411971] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vei7ynBpLeKYztQO-4AAAGW8"]
[Tue Jul 21 08:18:18.808037 2026] [security2:error] [pid 411857:tid 412014] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vei7ynBpLeKYztQO-4AAAGW8"]
[Tue Jul 21 08:18:18.826821 2026] [security2:error] [pid 411857:tid 412045] [client 74.249.245.134:15158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/buy.php"] [unique_id "al9Vei7ynBpLeKYztQO-4QAAADg"]
[Tue Jul 21 08:18:18.874240 2026] [security2:error] [pid 411857:tid 412100] [client 103.151.46.103:53889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vei7ynBpLeKYztQO-5QAAAG8"]
[Tue Jul 21 08:18:18.875016 2026] [security2:error] [pid 411857:tid 412100] [client 103.151.46.103:53889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vei7ynBpLeKYztQO-5QAAAG8"]
[Tue Jul 21 08:18:19.384249 2026] [security2:error] [pid 411857:tid 412111] [client 185.191.171.7:16874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivaconcierge.com.br"] [uri "/en/_detalhes/mosquiteiro/page/2/"] [unique_id "al9Vey7ynBpLeKYztQO_CAAAAHo"]
[Tue Jul 21 08:18:19.384338 2026] [security2:error] [pid 411857:tid 412111] [client 185.191.171.7:16874] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vivaconcierge.com.br"] [uri "/en/_detalhes/mosquiteiro/page/2/"] [unique_id "al9Vey7ynBpLeKYztQO_CAAAAHo"]
[Tue Jul 21 08:18:19.510864 2026] [security2:error] [pid 411857:tid 411989] [client 102.206.115.33:61374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vey7ynBpLeKYztQO_DwAAAAA"]
[Tue Jul 21 08:18:19.512917 2026] [security2:error] [pid 411857:tid 411989] [client 102.206.115.33:61374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vey7ynBpLeKYztQO_DwAAAAA"]
[Tue Jul 21 08:18:19.569786 2026] [security2:error] [pid 411857:tid 412016] [client 187.125.243.197:56923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Vey7ynBpLeKYztQO_EgAAABs"]
[Tue Jul 21 08:18:19.569961 2026] [security2:error] [pid 411857:tid 412016] [client 187.125.243.197:56923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Vey7ynBpLeKYztQO_EgAAABs"]
[Tue Jul 21 08:18:19.574370 2026] [security2:error] [pid 411857:tid 412023] [client 103.78.200.11:65042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vey7ynBpLeKYztQO_EwAAACI"]
[Tue Jul 21 08:18:19.575045 2026] [security2:error] [pid 411857:tid 412023] [client 103.78.200.11:65042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vey7ynBpLeKYztQO_EwAAACI"]
[Tue Jul 21 08:18:19.611194 2026] [security2:error] [pid 411857:tid 412044] [client 20.151.10.161:46059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-temp.php"] [unique_id "al9Vey7ynBpLeKYztQO_FQAAADc"]
[Tue Jul 21 08:18:19.767289 2026] [security2:error] [pid 411857:tid 412100] [client 20.226.60.151:49364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/w.php"] [unique_id "al9Vey7ynBpLeKYztQO_HAAAAG8"]
[Tue Jul 21 08:18:20.011915 2026] [security2:error] [pid 411857:tid 412053] [client 20.220.225.223:24238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/ww.php"] [unique_id "al9VfC7ynBpLeKYztQO_KAAAAEA"]
[Tue Jul 21 08:18:20.142102 2026] [security2:error] [pid 411857:tid 412060] [client 216.244.66.244:36716] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nrfilmes.com"] [uri "/produtos/das-boot-3-temporada-completa-blu-ray-dublado-legendado/"] [unique_id "al9VfC7ynBpLeKYztQO_KwAAAEc"]
[Tue Jul 21 08:18:20.142275 2026] [security2:error] [pid 411857:tid 412060] [client 216.244.66.244:36716] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nrfilmes.com"] [uri "/produtos/das-boot-3-temporada-completa-blu-ray-dublado-legendado/"] [unique_id "al9VfC7ynBpLeKYztQO_KwAAAEc"]
[Tue Jul 21 08:18:20.486949 2026] [security2:error] [pid 411857:tid 412038] [client 65.21.113.253:51226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VfC7ynBpLeKYztQO_JwAAADE"]
[Tue Jul 21 08:18:20.704910 2026] [rewrite:warn] [pid 411857:tid 411897] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:20.756382 2026] [security2:error] [pid 411857:tid 412006] [client 20.220.225.223:24255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/cron.php"] [unique_id "al9VfC7ynBpLeKYztQO_TAAAABE"]
[Tue Jul 21 08:18:20.778439 2026] [security2:error] [pid 411857:tid 411993] [client 87.116.180.198:14008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VfC7ynBpLeKYztQO_UAAAAAQ"]
[Tue Jul 21 08:18:20.781396 2026] [security2:error] [pid 411857:tid 412084] [client 115.134.11.136:60746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VfC7ynBpLeKYztQO_UQAAAF8"]
[Tue Jul 21 08:18:20.782432 2026] [security2:error] [pid 411857:tid 412084] [client 115.134.11.136:60746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VfC7ynBpLeKYztQO_UQAAAF8"]
[Tue Jul 21 08:18:20.783060 2026] [security2:error] [pid 411857:tid 411993] [client 87.116.180.198:14008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VfC7ynBpLeKYztQO_UAAAAAQ"]
[Tue Jul 21 08:18:20.806065 2026] [security2:error] [pid 411857:tid 411994] [client 20.206.105.145:25526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9VfC7ynBpLeKYztQO_UgAAAAU"]
[Tue Jul 21 08:18:20.857786 2026] [security2:error] [pid 411857:tid 412017] [client 20.226.60.151:48810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9VfC7ynBpLeKYztQO_VAAAABw"]
[Tue Jul 21 08:18:20.890514 2026] [security2:error] [pid 411857:tid 411894] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VfC7ynBpLeKYztQO_WAAAGyM"]
[Tue Jul 21 08:18:20.890685 2026] [security2:error] [pid 411857:tid 412016] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VfC7ynBpLeKYztQO_WAAAGyM"]
[Tue Jul 21 08:18:20.902651 2026] [security2:error] [pid 411857:tid 412003] [client 20.151.10.161:45909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9VfC7ynBpLeKYztQO_WQAAAA4"]
[Tue Jul 21 08:18:20.924367 2026] [security2:error] [pid 411857:tid 412031] [client 20.226.60.151:51968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/dvjul.php"] [unique_id "al9VfC7ynBpLeKYztQO_WwAAACo"]
[Tue Jul 21 08:18:21.172216 2026] [security2:error] [pid 411857:tid 412035] [client 142.44.220.144:24380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "galetti.com.br"] [uri "/robots.txt"] [unique_id "al9VfS7ynBpLeKYztQO_YgAAAC4"]
[Tue Jul 21 08:18:21.172359 2026] [security2:error] [pid 411857:tid 412035] [client 142.44.220.144:24380] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "galetti.com.br"] [uri "/robots.txt"] [unique_id "al9VfS7ynBpLeKYztQO_YgAAAC4"]
[Tue Jul 21 08:18:21.431727 2026] [security2:error] [pid 411857:tid 412061] [client 20.197.192.193:62444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/koiy.php"] [unique_id "al9VfS7ynBpLeKYztQO_bAAAAEg"]
[Tue Jul 21 08:18:21.543877 2026] [security2:error] [pid 411857:tid 411997] [client 74.249.245.134:15363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/sx.php"] [unique_id "al9VfS7ynBpLeKYztQO_cgAAAAg"]
[Tue Jul 21 08:18:21.686267 2026] [security2:error] [pid 411857:tid 412007] [client 62.102.148.158:59832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9VfS7ynBpLeKYztQO_eQAAABI"]
[Tue Jul 21 08:18:21.686403 2026] [security2:error] [pid 411857:tid 412007] [client 62.102.148.158:59832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9VfS7ynBpLeKYztQO_eQAAABI"]
[Tue Jul 21 08:18:21.869572 2026] [security2:error] [pid 411857:tid 412052] [client 20.151.10.161:45895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/puc.php"] [unique_id "al9VfS7ynBpLeKYztQO_hAAAAD8"]
[Tue Jul 21 08:18:21.870973 2026] [security2:error] [pid 411857:tid 412078] [client 172.233.156.91:45822] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "hypehutdeals.com"] [uri "/wp-comments-post.php"] [unique_id "al9Vey7ynBpLeKYztQO_EQAAAFk"]
[Tue Jul 21 08:18:21.871494 2026] [security2:error] [pid 411857:tid 412083] [client 14.245.224.124:65380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VfS7ynBpLeKYztQO_hQAAAF4"]
[Tue Jul 21 08:18:21.871615 2026] [security2:error] [pid 411857:tid 412083] [client 14.245.224.124:65380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VfS7ynBpLeKYztQO_hQAAAF4"]
[Tue Jul 21 08:18:21.872208 2026] [security2:error] [pid 411857:tid 412044] [client 61.1.167.83:59313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VfS7ynBpLeKYztQO_ggAAADc"]
[Tue Jul 21 08:18:21.872322 2026] [security2:error] [pid 411857:tid 412044] [client 61.1.167.83:59313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VfS7ynBpLeKYztQO_ggAAADc"]
[Tue Jul 21 08:18:21.892131 2026] [security2:error] [pid 411857:tid 412086] [client 103.106.20.201:64969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VfS7ynBpLeKYztQO_hwAAAGE"]
[Tue Jul 21 08:18:21.892265 2026] [security2:error] [pid 411857:tid 412086] [client 103.106.20.201:64969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VfS7ynBpLeKYztQO_hwAAAGE"]
[Tue Jul 21 08:18:21.928252 2026] [security2:error] [pid 411857:tid 412078] [client 172.233.156.91:45822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "500"] [hostname "hypehutdeals.com"] [uri "/wp-comments-post.php"] [unique_id "al9Vey7ynBpLeKYztQO_EQAAAFk"]
[Tue Jul 21 08:18:22.124682 2026] [security2:error] [pid 411857:tid 412089] [client 65.21.113.253:51226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VfS7ynBpLeKYztQO_eAAAAGQ"]
[Tue Jul 21 08:18:22.417860 2026] [security2:error] [pid 411857:tid 412001] [client 20.226.60.151:48768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/FWAZ.php"] [unique_id "al9Vfi7ynBpLeKYztQO_mQAAAAw"]
[Tue Jul 21 08:18:22.451033 2026] [security2:error] [pid 411857:tid 412035] [client 20.226.60.151:64094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/xyn.php"] [unique_id "al9Vfi7ynBpLeKYztQO_mwAAAC4"]
[Tue Jul 21 08:18:22.489100 2026] [security2:error] [pid 411857:tid 412024] [client 156.59.198.136:40406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "seaportservicos.com.br"] [uri "/wp-content/uploads/2022/04/PPC-PROGRAMA-DE-PREVENCAO-DA-CORRUPCAO.pdf"] [unique_id "al9Vfi7ynBpLeKYztQO_nAAAACM"]
[Tue Jul 21 08:18:22.549687 2026] [security2:error] [pid 411857:tid 412025] [client 20.206.105.145:25587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wp-links.php"] [unique_id "al9Vfi7ynBpLeKYztQO_oQAAACQ"]
[Tue Jul 21 08:18:22.586188 2026] [security2:error] [pid 411857:tid 412042] [client 167.114.139.74:60304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "galetti.com.br"] [uri "/"] [unique_id "al9Vfi7ynBpLeKYztQO_qQAAADU"]
[Tue Jul 21 08:18:22.586289 2026] [security2:error] [pid 411857:tid 412042] [client 167.114.139.74:60304] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "galetti.com.br"] [uri "/"] [unique_id "al9Vfi7ynBpLeKYztQO_qQAAADU"]
[Tue Jul 21 08:18:22.982998 2026] [security2:error] [pid 411857:tid 412014] [client 20.151.10.161:45898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/themes.php"] [unique_id "al9Vfi7ynBpLeKYztQO_tgAAABk"]
[Tue Jul 21 08:18:23.141582 2026] [security2:error] [pid 411857:tid 412046] [client 65.21.113.253:48146] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vfi7ynBpLeKYztQO_rQAAADk"]
[Tue Jul 21 08:18:23.324467 2026] [security2:error] [pid 411857:tid 412017] [client 20.226.60.151:48871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/miru1.php"] [unique_id "al9Vfy7ynBpLeKYztQO_wAAAABw"]
[Tue Jul 21 08:18:23.734602 2026] [security2:error] [pid 411857:tid 412025] [client 20.220.225.223:24228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/xxx.php"] [unique_id "al9Vfy7ynBpLeKYztQO_0wAAACQ"]
[Tue Jul 21 08:18:23.949840 2026] [security2:error] [pid 411857:tid 411994] [client 150.129.202.39:12840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vfy7ynBpLeKYztQO_2QAAAAU"]
[Tue Jul 21 08:18:23.949949 2026] [security2:error] [pid 411857:tid 411994] [client 150.129.202.39:12840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vfy7ynBpLeKYztQO_2QAAAAU"]
[Tue Jul 21 08:18:24.080327 2026] [security2:error] [pid 411857:tid 411925] [remote 20.153.140.50:38694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tryhealth.shop"] [uri "/wp-login.php"] [unique_id "al9VgC7ynBpLeKYztQO_3gAAQ0I"]
[Tue Jul 21 08:18:24.158548 2026] [security2:error] [pid 411857:tid 412057] [client 20.206.105.145:25491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/solo1.php"] [unique_id "al9VgC7ynBpLeKYztQO_6QAAAEQ"]
[Tue Jul 21 08:18:24.229856 2026] [security2:error] [pid 411857:tid 412054] [client 20.226.60.151:48783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/aa.php"] [unique_id "al9VgC7ynBpLeKYztQO_7gAAAEE"]
[Tue Jul 21 08:18:24.250761 2026] [security2:error] [pid 411857:tid 412035] [client 117.210.135.0:49814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VgC7ynBpLeKYztQO_8AAAAC4"]
[Tue Jul 21 08:18:24.250888 2026] [security2:error] [pid 411857:tid 412035] [client 117.210.135.0:49814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VgC7ynBpLeKYztQO_8AAAAC4"]
[Tue Jul 21 08:18:24.559510 2026] [security2:error] [pid 411857:tid 411946] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VgC7ynBpLeKYztQO_9gAAOVc"]
[Tue Jul 21 08:18:24.559712 2026] [security2:error] [pid 411857:tid 412046] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VgC7ynBpLeKYztQO_9gAAOVc"]
[Tue Jul 21 08:18:24.638052 2026] [security2:error] [pid 411857:tid 411974] [remote 157.230.148.169:54146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.148.230.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9VgC7ynBpLeKYztQO__gAAfHI"]
[Tue Jul 21 08:18:24.828498 2026] [security2:error] [pid 411857:tid 412094] [client 162.219.176.3:40164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9VgC7ynBpLeKYztQPACQAAAGk"]
[Tue Jul 21 08:18:24.828601 2026] [security2:error] [pid 411857:tid 412094] [client 162.219.176.3:40164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9VgC7ynBpLeKYztQPACQAAAGk"]
[Tue Jul 21 08:18:24.945269 2026] [security2:error] [pid 411857:tid 412032] [client 74.249.245.134:31378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/article.php"] [unique_id "al9VgC7ynBpLeKYztQPAEQAAACs"]
[Tue Jul 21 08:18:24.979480 2026] [security2:error] [pid 411857:tid 412064] [client 120.56.162.40:56538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VgC7ynBpLeKYztQPAEwAAAEs"]
[Tue Jul 21 08:18:24.979635 2026] [security2:error] [pid 411857:tid 412064] [client 120.56.162.40:56538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VgC7ynBpLeKYztQPAEwAAAEs"]
[Tue Jul 21 08:18:24.993253 2026] [security2:error] [pid 411857:tid 412090] [client 20.226.60.151:48890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/122.php"] [unique_id "al9VgC7ynBpLeKYztQPAFAAAAGU"]
[Tue Jul 21 08:18:25.021671 2026] [security2:error] [pid 411857:tid 411976] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VgS7ynBpLeKYztQPAFQAATnQ"]
[Tue Jul 21 08:18:25.021899 2026] [security2:error] [pid 411857:tid 412067] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VgS7ynBpLeKYztQPAFQAATnQ"]
[Tue Jul 21 08:18:25.219090 2026] [security2:error] [pid 411857:tid 412008] [client 20.197.192.193:48744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/hp2.php"] [unique_id "al9VgS7ynBpLeKYztQPAGwAAABM"]
[Tue Jul 21 08:18:25.227679 2026] [security2:error] [pid 411857:tid 412054] [client 20.206.105.145:25557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/sixxis.php"] [unique_id "al9VgS7ynBpLeKYztQPAHQAAAEE"]
[Tue Jul 21 08:18:25.442505 2026] [security2:error] [pid 411857:tid 412052] [client 20.226.60.151:49369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/get.php"] [unique_id "al9VgS7ynBpLeKYztQPAJQAAAD8"]
[Tue Jul 21 08:18:25.622702 2026] [security2:error] [pid 411857:tid 412004] [client 20.226.60.151:49359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/as.php"] [unique_id "al9VgS7ynBpLeKYztQPAKAAAAA8"]
[Tue Jul 21 08:18:25.774426 2026] [security2:error] [pid 411857:tid 411992] [client 20.226.60.151:48891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/ccou.php"] [unique_id "al9VgS7ynBpLeKYztQPAMAAAAAM"]
[Tue Jul 21 08:18:25.886270 2026] [security2:error] [pid 411857:tid 411942] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VgS7ynBpLeKYztQPANwAAHFM"]
[Tue Jul 21 08:18:25.886508 2026] [security2:error] [pid 411857:tid 412017] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VgS7ynBpLeKYztQPANwAAHFM"]
[Tue Jul 21 08:18:25.971750 2026] [security2:error] [pid 411857:tid 412032] [client 20.226.60.151:48855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/w3lls.php"] [unique_id "al9VgS7ynBpLeKYztQPAQAAAACs"]
[Tue Jul 21 08:18:26.114704 2026] [security2:error] [pid 411857:tid 412062] [client 20.226.60.151:51983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/biufile.php"] [unique_id "al9Vgi7ynBpLeKYztQPARQAAAEk"]
[Tue Jul 21 08:18:26.199936 2026] [security2:error] [pid 411857:tid 411997] [client 74.249.245.134:59275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Vgi7ynBpLeKYztQPASAAAAAg"]
[Tue Jul 21 08:18:26.382417 2026] [security2:error] [pid 411857:tid 412077] [client 20.226.60.151:48888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/test1.php"] [unique_id "al9Vgi7ynBpLeKYztQPAUAAAAFg"]
[Tue Jul 21 08:18:26.593067 2026] [security2:error] [pid 411857:tid 412059] [client 20.226.60.151:49382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/database.php"] [unique_id "al9Vgi7ynBpLeKYztQPAVwAAAEY"]
[Tue Jul 21 08:18:26.629208 2026] [security2:error] [pid 411857:tid 411867] [remote 5.252.52.249:59208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-login.php"] [unique_id "al9Vgi7ynBpLeKYztQPAWAAAegg"]
[Tue Jul 21 08:18:26.654781 2026] [security2:error] [pid 411857:tid 412088] [client 20.226.60.151:48817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/file.php"] [unique_id "al9Vgi7ynBpLeKYztQPAWQAAAGM"]
[Tue Jul 21 08:18:26.688824 2026] [rewrite:warn] [pid 411857:tid 411859] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.808382 2026] [rewrite:warn] [pid 411857:tid 411933] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.814112 2026] [rewrite:warn] [pid 411857:tid 411981] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.817803 2026] [rewrite:warn] [pid 411857:tid 411978] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.817803 2026] [rewrite:warn] [pid 411857:tid 411897] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.830092 2026] [rewrite:warn] [pid 411857:tid 411894] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.835171 2026] [security2:error] [pid 411857:tid 411999] [client 20.226.60.151:49349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/file.php"] [unique_id "al9Vgi7ynBpLeKYztQPAbAAAAAo"]
[Tue Jul 21 08:18:26.893379 2026] [rewrite:warn] [pid 411857:tid 411873] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.893896 2026] [rewrite:warn] [pid 411857:tid 411886] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.899569 2026] [rewrite:warn] [pid 411857:tid 411878] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.899582 2026] [rewrite:warn] [pid 411857:tid 411967] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.910245 2026] [rewrite:warn] [pid 411857:tid 411947] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.910536 2026] [rewrite:warn] [pid 411857:tid 411903] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.910536 2026] [rewrite:warn] [pid 411857:tid 411895] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.916418 2026] [rewrite:warn] [pid 411857:tid 411861] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.916713 2026] [rewrite:warn] [pid 411857:tid 411866] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:18:26.926518 2026] [security2:error] [pid 411857:tid 412089] [client 14.97.58.74:59851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Vgi7ynBpLeKYztQPAegAAAGQ"]
[Tue Jul 21 08:18:26.926607 2026] [security2:error] [pid 411857:tid 412089] [client 14.97.58.74:59851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Vgi7ynBpLeKYztQPAegAAAGQ"]
[Tue Jul 21 08:18:26.980334 2026] [security2:error] [pid 411857:tid 412053] [client 20.226.60.151:49390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/777.php"] [unique_id "al9Vgi7ynBpLeKYztQPAewAAAEA"]
[Tue Jul 21 08:18:27.147295 2026] [security2:error] [pid 411857:tid 412065] [client 74.249.245.134:31375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/bootstrap.php"] [unique_id "al9Vgy7ynBpLeKYztQPAfgAAAEw"]
[Tue Jul 21 08:18:27.164798 2026] [security2:error] [pid 411857:tid 412067] [client 20.226.60.151:48820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/ssixta.php"] [unique_id "al9Vgy7ynBpLeKYztQPAfwAAAE4"]
[Tue Jul 21 08:18:27.249068 2026] [security2:error] [pid 411857:tid 412063] [client 20.226.60.151:48815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/1c.php"] [unique_id "al9Vgy7ynBpLeKYztQPAggAAAEo"]
[Tue Jul 21 08:18:27.430640 2026] [security2:error] [pid 411857:tid 412059] [client 162.219.176.3:40168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Vgy7ynBpLeKYztQPAjgAAAEY"]
[Tue Jul 21 08:18:27.430784 2026] [security2:error] [pid 411857:tid 412059] [client 162.219.176.3:40168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Vgy7ynBpLeKYztQPAjgAAAEY"]
[Tue Jul 21 08:18:27.470084 2026] [security2:error] [pid 411857:tid 411989] [client 20.226.60.151:48802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/test2.php"] [unique_id "al9Vgy7ynBpLeKYztQPAkAAAAAA"]
[Tue Jul 21 08:18:27.642542 2026] [security2:error] [pid 411857:tid 412055] [client 20.226.60.151:49367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/buy.php"] [unique_id "al9Vgy7ynBpLeKYztQPAlwAAAEI"]
[Tue Jul 21 08:18:27.870616 2026] [security2:error] [pid 411857:tid 412036] [client 20.226.60.151:60305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/av.php"] [unique_id "al9Vgy7ynBpLeKYztQPApAAAAC8"]
[Tue Jul 21 08:18:27.939989 2026] [security2:error] [pid 411857:tid 412097] [client 91.92.41.115:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "andreiapereiradossan1782652807342.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9Vgy7ynBpLeKYztQPAqQAAAGw"]
[Tue Jul 21 08:18:27.942279 2026] [security2:error] [pid 411857:tid 412042] [client 223.181.60.88:26777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Vgy7ynBpLeKYztQPAqgAAADU"]
[Tue Jul 21 08:18:27.942554 2026] [security2:error] [pid 411857:tid 412042] [client 223.181.60.88:26777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Vgy7ynBpLeKYztQPAqgAAADU"]
[Tue Jul 21 08:18:28.006023 2026] [security2:error] [pid 411857:tid 412100] [client 65.21.113.253:48146] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vgy7ynBpLeKYztQPAkgAAAG8"]
[Tue Jul 21 08:18:28.132213 2026] [security2:error] [pid 411857:tid 411885] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VhC7ynBpLeKYztQPArAAAVho"]
[Tue Jul 21 08:18:28.132429 2026] [security2:error] [pid 411857:tid 412075] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VhC7ynBpLeKYztQPArAAAVho"]
[Tue Jul 21 08:18:28.334875 2026] [security2:error] [pid 411857:tid 412023] [client 20.151.10.161:45977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/dx.php"] [unique_id "al9VhC7ynBpLeKYztQPAtQAAACI"]
[Tue Jul 21 08:18:28.361030 2026] [security2:error] [pid 411857:tid 412068] [client 20.206.105.145:25553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/2P.update.php"] [unique_id "al9VhC7ynBpLeKYztQPAtwAAAE8"]
[Tue Jul 21 08:18:28.553196 2026] [security2:error] [pid 411857:tid 412022] [client 154.208.47.43:61252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VhC7ynBpLeKYztQPAwgAAACE"]
[Tue Jul 21 08:18:28.553332 2026] [security2:error] [pid 411857:tid 412022] [client 154.208.47.43:61252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VhC7ynBpLeKYztQPAwgAAACE"]
[Tue Jul 21 08:18:28.589850 2026] [security2:error] [pid 411857:tid 412095] [client 152.59.34.51:52205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VhC7ynBpLeKYztQPAyAAAAGo"]
[Tue Jul 21 08:18:28.590016 2026] [security2:error] [pid 411857:tid 412095] [client 152.59.34.51:52205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VhC7ynBpLeKYztQPAyAAAAGo"]
[Tue Jul 21 08:18:28.646698 2026] [security2:error] [pid 411857:tid 412048] [client 20.226.60.151:48821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/ssend.php"] [unique_id "al9VhC7ynBpLeKYztQPAygAAADs"]
[Tue Jul 21 08:18:28.780596 2026] [security2:error] [pid 411857:tid 412029] [client 114.119.136.99:26943] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.foreverconfidence.com"] [uri "/before-after"] [unique_id "al9VhC7ynBpLeKYztQPAzwAAACg"], referer: https://foreverconfidence.com/
[Tue Jul 21 08:18:29.190565 2026] [security2:error] [pid 411857:tid 411965] [remote 91.92.41.115:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "andreiapereiradossan1782652807342.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9VhS7ynBpLeKYztQPA5gAAA2k"]
[Tue Jul 21 08:18:29.406018 2026] [security2:error] [pid 411857:tid 412088] [client 74.249.245.134:15141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/config-backup.php"] [unique_id "al9VhS7ynBpLeKYztQPA9AAAAGM"]
[Tue Jul 21 08:18:29.413821 2026] [security2:error] [pid 411857:tid 412057] [client 91.148.245.81:51162] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/"] [unique_id "al9VhS7ynBpLeKYztQPA9wAAAEQ"]
[Tue Jul 21 08:18:29.415224 2026] [security2:error] [pid 411857:tid 411990] [client 91.148.245.81:51174] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/"] [unique_id "al9VhS7ynBpLeKYztQPA-QAAAAE"]
[Tue Jul 21 08:18:29.488961 2026] [security2:error] [pid 411857:tid 412041] [client 103.151.46.103:54379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VhS7ynBpLeKYztQPA-wAAADQ"]
[Tue Jul 21 08:18:29.489624 2026] [security2:error] [pid 411857:tid 412041] [client 103.151.46.103:54379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VhS7ynBpLeKYztQPA-wAAADQ"]
[Tue Jul 21 08:18:29.507127 2026] [security2:error] [pid 411857:tid 412032] [client 38.100.221.102:17265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VhS7ynBpLeKYztQPA_AAAACs"]
[Tue Jul 21 08:18:29.507227 2026] [security2:error] [pid 411857:tid 412032] [client 38.100.221.102:17265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VhS7ynBpLeKYztQPA_AAAACs"]
[Tue Jul 21 08:18:29.528064 2026] [security2:error] [pid 411857:tid 411921] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VhS7ynBpLeKYztQPA_QAAIj4"]
[Tue Jul 21 08:18:29.528295 2026] [security2:error] [pid 411857:tid 412023] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VhS7ynBpLeKYztQPA_QAAIj4"]
[Tue Jul 21 08:18:29.669266 2026] [security2:error] [pid 411857:tid 412092] [client 20.226.60.151:48879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/item.php"] [unique_id "al9VhS7ynBpLeKYztQPBAgAAAGc"]
[Tue Jul 21 08:18:29.816125 2026] [security2:error] [pid 411857:tid 412053] [client 103.78.200.11:49153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VhS7ynBpLeKYztQPBBAAAAEA"]
[Tue Jul 21 08:18:29.816223 2026] [security2:error] [pid 411857:tid 412053] [client 103.78.200.11:49153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VhS7ynBpLeKYztQPBBAAAAEA"]
[Tue Jul 21 08:18:29.902749 2026] [security2:error] [pid 411857:tid 412005] [client 103.229.123.233:9367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.229.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VhS7ynBpLeKYztQPBCAAAABA"]
[Tue Jul 21 08:18:29.902875 2026] [security2:error] [pid 411857:tid 412005] [client 103.229.123.233:9367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "balmaxx.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VhS7ynBpLeKYztQPBCAAAABA"]
[Tue Jul 21 08:18:29.996058 2026] [security2:error] [pid 411857:tid 412100] [client 20.226.60.151:64027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/patie.php"] [unique_id "al9VhS7ynBpLeKYztQPBDwAAAG8"]
[Tue Jul 21 08:18:30.050533 2026] [security2:error] [pid 411857:tid 412074] [client 187.125.243.197:57430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Vhi7ynBpLeKYztQPBEgAAAFU"]
[Tue Jul 21 08:18:30.050624 2026] [security2:error] [pid 411857:tid 412074] [client 187.125.243.197:57430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Vhi7ynBpLeKYztQPBEgAAAFU"]
[Tue Jul 21 08:18:30.081199 2026] [security2:error] [pid 411857:tid 412077] [client 102.206.115.33:59447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vhi7ynBpLeKYztQPBFAAAAFg"]
[Tue Jul 21 08:18:30.081312 2026] [security2:error] [pid 411857:tid 412077] [client 102.206.115.33:59447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vhi7ynBpLeKYztQPBFAAAAFg"]
[Tue Jul 21 08:18:30.328009 2026] [security2:error] [pid 411857:tid 411992] [client 20.206.105.145:25520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/a.php"] [unique_id "al9Vhi7ynBpLeKYztQPBGAAAAAM"]
[Tue Jul 21 08:18:30.358257 2026] [security2:error] [pid 411857:tid 412013] [client 20.220.225.223:31214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/mac.php"] [unique_id "al9Vhi7ynBpLeKYztQPBGQAAABg"]
[Tue Jul 21 08:18:30.434105 2026] [security2:error] [pid 411857:tid 412086] [client 74.7.228.63:53076] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "edutakao.com.br"] [uri "/index.php"] [unique_id "al9VhS7ynBpLeKYztQPBAQAAYVA"]
[Tue Jul 21 08:18:30.471020 2026] [security2:error] [pid 411857:tid 412007] [client 20.226.60.151:48881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/ss.php"] [unique_id "al9Vhi7ynBpLeKYztQPBIwAAABI"]
[Tue Jul 21 08:18:30.555769 2026] [proxy:error] [pid 411857:tid 412089] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:18:30.555838 2026] [proxy_http:error] [pid 411857:tid 412089] [client 45.89.126.125:55943] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:18:30.556281 2026] [security2:error] [pid 411857:tid 412017] [client 91.148.245.81:51190] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9Vhi7ynBpLeKYztQPBKAAAABw"]
[Tue Jul 21 08:18:30.556976 2026] [proxy:error] [pid 411857:tid 412089] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:18:30.557019 2026] [proxy_http:error] [pid 411857:tid 412089] [client 45.89.126.125:55943] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:18:30.557296 2026] [security2:error] [pid 411857:tid 412040] [client 91.148.245.81:51204] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9Vhi7ynBpLeKYztQPBKgAAADM"]
[Tue Jul 21 08:18:30.557845 2026] [security2:error] [pid 411857:tid 412067] [client 91.148.245.81:51176] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/database.sql"] [unique_id "al9Vhi7ynBpLeKYztQPBKwAAAE4"]
[Tue Jul 21 08:18:30.559335 2026] [security2:error] [pid 411857:tid 412098] [client 91.148.245.81:51182] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9Vhi7ynBpLeKYztQPBLAAAAG0"]
[Tue Jul 21 08:18:30.561075 2026] [autoindex:error] [pid 411857:tid 412024] [client 45.89.126.125:55951] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/planamoveis.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:18:31.174216 2026] [security2:error] [pid 411857:tid 412006] [client 91.148.245.81:51274] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/.git/HEAD"] [unique_id "al9Vhy7ynBpLeKYztQPBOgAAABE"]
[Tue Jul 21 08:18:31.175437 2026] [security2:error] [pid 411857:tid 412114] [client 91.148.245.81:51218] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/.env.production"] [unique_id "al9Vhy7ynBpLeKYztQPBOwAAAH0"]
[Tue Jul 21 08:18:31.177473 2026] [security2:error] [pid 411857:tid 412039] [client 91.148.245.81:51222] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9Vhy7ynBpLeKYztQPBPAAAADI"]
[Tue Jul 21 08:18:31.177899 2026] [security2:error] [pid 411857:tid 412112] [client 91.148.245.81:51254] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/.env"] [unique_id "al9Vhy7ynBpLeKYztQPBPQAAAHs"]
[Tue Jul 21 08:18:31.377586 2026] [security2:error] [pid 411857:tid 412080] [client 91.148.245.81:51260] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9Vhy7ynBpLeKYztQPBQAAAAFs"]
[Tue Jul 21 08:18:31.377618 2026] [security2:error] [pid 411857:tid 412071] [client 91.148.245.81:51272] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9Vhy7ynBpLeKYztQPBQQAAAFI"]
[Tue Jul 21 08:18:31.378969 2026] [security2:error] [pid 411857:tid 412028] [client 91.148.245.81:51238] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/server.key"] [unique_id "al9Vhy7ynBpLeKYztQPBQgAAACc"]
[Tue Jul 21 08:18:31.399125 2026] [security2:error] [pid 411857:tid 411926] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vhy7ynBpLeKYztQPBRgAAbkM"]
[Tue Jul 21 08:18:31.399290 2026] [security2:error] [pid 411857:tid 412099] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vhy7ynBpLeKYztQPBRgAAbkM"]
[Tue Jul 21 08:18:31.462544 2026] [security2:error] [pid 411857:tid 412095] [client 87.116.180.198:27271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vhy7ynBpLeKYztQPBTQAAAGo"]
[Tue Jul 21 08:18:31.462666 2026] [security2:error] [pid 411857:tid 412095] [client 87.116.180.198:27271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vhy7ynBpLeKYztQPBTQAAAGo"]
[Tue Jul 21 08:18:31.604500 2026] [security2:error] [pid 411857:tid 412067] [client 20.226.60.151:51975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/coffexium.php"] [unique_id "al9Vhy7ynBpLeKYztQPBVAAAAE4"]
[Tue Jul 21 08:18:31.609724 2026] [security2:error] [pid 411857:tid 411990] [client 115.134.11.136:61179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vhy7ynBpLeKYztQPBVQAAAAE"]
[Tue Jul 21 08:18:31.611374 2026] [security2:error] [pid 411857:tid 411990] [client 115.134.11.136:61179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vhy7ynBpLeKYztQPBVQAAAAE"]
[Tue Jul 21 08:18:31.888882 2026] [security2:error] [pid 411857:tid 412027] [client 173.252.95.0:62642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Vhy7ynBpLeKYztQPBWAAAACY"]
[Tue Jul 21 08:18:31.925012 2026] [security2:error] [pid 411857:tid 412010] [client 114.119.129.82:63011] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.elitegeo.com.br"] [uri "/wp-content/uploads/2017/07/correction-inverted-nipple-palo-alto.jpg"] [unique_id "al9Vhy7ynBpLeKYztQPBXgAAABU"], referer: https://www.elitegeo.com.br/wp-content/uploads/2017/07/correction-inverted-nipple-palo-alto.jpg
[Tue Jul 21 08:18:32.033077 2026] [security2:error] [pid 411857:tid 412030] [client 20.220.225.223:38717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/samll.php"] [unique_id "al9ViC7ynBpLeKYztQPBZwAAACk"]
[Tue Jul 21 08:18:32.145866 2026] [security2:error] [pid 411857:tid 412109] [client 65.21.113.253:48146] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vhy7ynBpLeKYztQPBVwAAAHg"]
[Tue Jul 21 08:18:32.326513 2026] [security2:error] [pid 411857:tid 412077] [client 91.148.245.81:51290] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/user_secrets.yml"] [unique_id "al9ViC7ynBpLeKYztQPBbwAAAFg"]
[Tue Jul 21 08:18:32.327256 2026] [security2:error] [pid 411857:tid 412071] [client 91.148.245.81:51288] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/phpinfo.php"] [unique_id "al9ViC7ynBpLeKYztQPBcAAAAFI"]
[Tue Jul 21 08:18:32.327364 2026] [security2:error] [pid 411857:tid 412074] [client 91.148.245.81:51286] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/api/.env"] [unique_id "al9ViC7ynBpLeKYztQPBcQAAAFU"]
[Tue Jul 21 08:18:32.328566 2026] [security2:error] [pid 411857:tid 412060] [client 91.148.245.81:51318] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/config/production.json"] [unique_id "al9ViC7ynBpLeKYztQPBcgAAAEc"]
[Tue Jul 21 08:18:32.502067 2026] [security2:error] [pid 411857:tid 412103] [client 103.106.20.201:49168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ViC7ynBpLeKYztQPBdwAAAHI"]
[Tue Jul 21 08:18:32.502201 2026] [security2:error] [pid 411857:tid 412103] [client 103.106.20.201:49168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ViC7ynBpLeKYztQPBdwAAAHI"]
[Tue Jul 21 08:18:32.529217 2026] [security2:error] [pid 411857:tid 412076] [client 91.148.245.81:51328] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/docker-compose.yml"] [unique_id "al9ViC7ynBpLeKYztQPBewAAAFc"]
[Tue Jul 21 08:18:32.530028 2026] [security2:error] [pid 411857:tid 412080] [client 91.148.245.81:51316] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/database_backup.sql"] [unique_id "al9ViC7ynBpLeKYztQPBfQAAAFs"]
[Tue Jul 21 08:18:32.568692 2026] [security2:error] [pid 411857:tid 412028] [client 14.245.224.124:49703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ViC7ynBpLeKYztQPBfgAAACc"]
[Tue Jul 21 08:18:32.568918 2026] [security2:error] [pid 411857:tid 412028] [client 14.245.224.124:49703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ViC7ynBpLeKYztQPBfgAAACc"]
[Tue Jul 21 08:18:32.828592 2026] [security2:error] [pid 411857:tid 412095] [client 185.8.106.219:18644] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "transitoaberto.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9ViC7ynBpLeKYztQPBgwAAAGo"]
[Tue Jul 21 08:18:32.835757 2026] [security2:error] [pid 411857:tid 412027] [client 20.226.60.151:48845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/hypo.php"] [unique_id "al9ViC7ynBpLeKYztQPBhAAAACY"]
[Tue Jul 21 08:18:32.868488 2026] [security2:error] [pid 411857:tid 411999] [client 20.206.105.145:25480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/k.php"] [unique_id "al9ViC7ynBpLeKYztQPBhwAAAAo"]
[Tue Jul 21 08:18:33.020633 2026] [security2:error] [pid 411857:tid 411981] [remote 97.74.87.194:56330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "polycellassistencia.com.ocsdbodyboarding.com.br"] [uri "/wp-login.php"] [unique_id "al9ViS7ynBpLeKYztQPBkwAAYXk"]
[Tue Jul 21 08:18:33.379950 2026] [security2:error] [pid 411857:tid 412005] [client 65.21.113.253:48146] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ViC7ynBpLeKYztQPBiwAAABA"]
[Tue Jul 21 08:18:33.849612 2026] [security2:error] [pid 411857:tid 411999] [client 20.151.10.161:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/p.php"] [unique_id "al9ViS7ynBpLeKYztQPBuQAAAAo"]
[Tue Jul 21 08:18:33.922909 2026] [security2:error] [pid 411857:tid 412056] [client 20.226.60.151:64012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/aa.php"] [unique_id "al9ViS7ynBpLeKYztQPBvAAAAEM"]
[Tue Jul 21 08:18:34.149579 2026] [security2:error] [pid 411857:tid 412022] [client 185.8.106.219:51214] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "transitoaberto.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9Vii7ynBpLeKYztQPByQAAACE"]
[Tue Jul 21 08:18:34.312000 2026] [security2:error] [pid 411857:tid 412093] [client 74.249.245.134:31371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/goods.php"] [unique_id "al9Vii7ynBpLeKYztQPBywAAAGg"]
[Tue Jul 21 08:18:34.435681 2026] [security2:error] [pid 411857:tid 412077] [client 20.226.60.151:60314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/core.php"] [unique_id "al9Vii7ynBpLeKYztQPBzgAAAFg"]
[Tue Jul 21 08:18:34.453167 2026] [security2:error] [pid 411857:tid 411989] [client 150.129.202.39:64787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vii7ynBpLeKYztQPBzwAAAAA"]
[Tue Jul 21 08:18:34.453295 2026] [security2:error] [pid 411857:tid 411989] [client 150.129.202.39:64787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vii7ynBpLeKYztQPBzwAAAAA"]
[Tue Jul 21 08:18:34.505270 2026] [security2:error] [pid 411857:tid 412062] [client 20.206.105.145:25507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/w.php"] [unique_id "al9Vii7ynBpLeKYztQPB0AAAAEk"]
[Tue Jul 21 08:18:34.631619 2026] [security2:error] [pid 411857:tid 412075] [client 125.18.144.2:9892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Vii7ynBpLeKYztQPB2AAAAFY"]
[Tue Jul 21 08:18:34.631740 2026] [security2:error] [pid 411857:tid 412075] [client 125.18.144.2:9892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Vii7ynBpLeKYztQPB2AAAAFY"]
[Tue Jul 21 08:18:34.743210 2026] [security2:error] [pid 411857:tid 412114] [client 117.210.135.0:50486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vii7ynBpLeKYztQPB2wAAAH0"]
[Tue Jul 21 08:18:34.743339 2026] [security2:error] [pid 411857:tid 412114] [client 117.210.135.0:50486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vii7ynBpLeKYztQPB2wAAAH0"]
[Tue Jul 21 08:18:34.959018 2026] [security2:error] [pid 411857:tid 412048] [client 20.226.60.151:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/als.php"] [unique_id "al9Vii7ynBpLeKYztQPB4gAAADs"]
[Tue Jul 21 08:18:35.038969 2026] [security2:error] [pid 411857:tid 412058] [client 20.226.60.151:60344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/simple.php"] [unique_id "al9Viy7ynBpLeKYztQPB5AAAAEU"]
[Tue Jul 21 08:18:35.078535 2026] [security2:error] [pid 411857:tid 411966] [remote 207.180.241.245:47324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arterisplus.tryhealth.shop"] [uri "/wp-login.php"] [unique_id "al9Viy7ynBpLeKYztQPB5gAAY2o"]
[Tue Jul 21 08:18:35.149256 2026] [security2:error] [pid 411857:tid 412097] [client 20.226.60.151:60329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/init.php"] [unique_id "al9Viy7ynBpLeKYztQPB6wAAAGw"]
[Tue Jul 21 08:18:35.295483 2026] [security2:error] [pid 411857:tid 412002] [client 20.226.60.151:53357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/fpwch.php"] [unique_id "al9Viy7ynBpLeKYztQPB8AAAAA0"]
[Tue Jul 21 08:18:35.388360 2026] [security2:error] [pid 411857:tid 412081] [client 185.8.106.219:18668] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.transitoaberto.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9Viy7ynBpLeKYztQPB9gAAAFw"]
[Tue Jul 21 08:18:35.499151 2026] [security2:error] [pid 411857:tid 412110] [client 20.226.60.151:48796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/users.php"] [unique_id "al9Viy7ynBpLeKYztQPB-gAAAHk"]
[Tue Jul 21 08:18:35.541120 2026] [security2:error] [pid 411857:tid 411872] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Viy7ynBpLeKYztQPB_QAAVQ0"]
[Tue Jul 21 08:18:35.541281 2026] [security2:error] [pid 411857:tid 412074] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Viy7ynBpLeKYztQPB_QAAVQ0"]
[Tue Jul 21 08:18:35.605572 2026] [security2:error] [pid 411857:tid 412079] [client 120.56.162.40:57046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Viy7ynBpLeKYztQPCAQAAAFo"]
[Tue Jul 21 08:18:35.605738 2026] [security2:error] [pid 411857:tid 412079] [client 120.56.162.40:57046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Viy7ynBpLeKYztQPCAQAAAFo"]
[Tue Jul 21 08:18:35.656434 2026] [security2:error] [pid 411857:tid 412098] [client 20.226.60.151:52010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/domvf.php"] [unique_id "al9Viy7ynBpLeKYztQPCAgAAAG0"]
[Tue Jul 21 08:18:35.804741 2026] [security2:error] [pid 411857:tid 412075] [client 185.8.106.219:18686] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "transitoaberto.com.br"] [uri "/"] [unique_id "al9Viy7ynBpLeKYztQPCDQAAAFY"]
[Tue Jul 21 08:18:35.849697 2026] [security2:error] [pid 411857:tid 411891] [remote 159.65.81.207:50174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/wp-login.php"] [unique_id "al9Viy7ynBpLeKYztQPCDgAARyA"]
[Tue Jul 21 08:18:35.877328 2026] [security2:error] [pid 411857:tid 411983] [remote 103.28.36.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9Vii7ynBpLeKYztQPB3gAAUns"]
[Tue Jul 21 08:18:35.950206 2026] [security2:error] [pid 411857:tid 412061] [client 20.151.10.161:46041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/bthil.php"] [unique_id "al9Viy7ynBpLeKYztQPCEwAAAEg"]
[Tue Jul 21 08:18:35.995190 2026] [security2:error] [pid 411857:tid 411948] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Viy7ynBpLeKYztQPCFQAABVk"]
[Tue Jul 21 08:18:35.995398 2026] [security2:error] [pid 411857:tid 411994] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Viy7ynBpLeKYztQPCFQAABVk"]
[Tue Jul 21 08:18:36.247048 2026] [security2:error] [pid 411857:tid 412028] [client 61.1.167.83:59854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VjC7ynBpLeKYztQPCHgAAACc"]
[Tue Jul 21 08:18:36.247152 2026] [security2:error] [pid 411857:tid 412028] [client 61.1.167.83:59854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VjC7ynBpLeKYztQPCHgAAACc"]
[Tue Jul 21 08:18:36.291710 2026] [security2:error] [pid 411857:tid 412108] [client 20.226.60.151:60306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/wp.php"] [unique_id "al9VjC7ynBpLeKYztQPCIgAAAHc"]
[Tue Jul 21 08:18:36.437079 2026] [security2:error] [pid 411857:tid 411995] [client 74.249.245.134:15386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/init.php"] [unique_id "al9VjC7ynBpLeKYztQPCJgAAAAY"]
[Tue Jul 21 08:18:36.518377 2026] [security2:error] [pid 411857:tid 411925] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VjC7ynBpLeKYztQPCKQAAOEI"]
[Tue Jul 21 08:18:36.518591 2026] [security2:error] [pid 411857:tid 412045] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VjC7ynBpLeKYztQPCKQAAOEI"]
[Tue Jul 21 08:18:36.534120 2026] [security2:error] [pid 411857:tid 411950] [remote 216.73.216.184:11452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemape.xml"] [unique_id "al9VjC7ynBpLeKYztQPCJAAALVs"]
[Tue Jul 21 08:18:36.536918 2026] [security2:error] [pid 411857:tid 412043] [client 20.206.105.145:25475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/insc.php"] [unique_id "al9VjC7ynBpLeKYztQPCKgAAADY"]
[Tue Jul 21 08:18:36.838254 2026] [security2:error] [pid 411857:tid 412074] [client 20.226.60.151:52232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/class.php"] [unique_id "al9VjC7ynBpLeKYztQPCOQAAAFU"]
[Tue Jul 21 08:18:37.124741 2026] [security2:error] [pid 411857:tid 411946] [remote 20.153.140.50:56020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "links.principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9VjS7ynBpLeKYztQPCQgAARlc"]
[Tue Jul 21 08:18:37.185866 2026] [security2:error] [pid 411857:tid 412085] [client 20.226.60.151:60550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9VjS7ynBpLeKYztQPCRAAAAGA"]
[Tue Jul 21 08:18:37.468516 2026] [security2:error] [pid 411857:tid 412058] [client 20.226.60.151:64034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/xwpg.php"] [unique_id "al9VjS7ynBpLeKYztQPCUQAAAEU"]
[Tue Jul 21 08:18:37.496476 2026] [security2:error] [pid 411857:tid 412008] [client 20.226.60.151:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/echkm.php"] [unique_id "al9VjS7ynBpLeKYztQPCUwAAABM"]
[Tue Jul 21 08:18:37.651015 2026] [security2:error] [pid 411857:tid 412097] [client 20.197.192.193:3344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/hp3.php"] [unique_id "al9VjS7ynBpLeKYztQPCVAAAAGw"]
[Tue Jul 21 08:18:37.788140 2026] [security2:error] [pid 411857:tid 412017] [client 223.181.60.88:21656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VjS7ynBpLeKYztQPCWwAAABw"]
[Tue Jul 21 08:18:37.788653 2026] [security2:error] [pid 411857:tid 412017] [client 223.181.60.88:21656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VjS7ynBpLeKYztQPCWwAAABw"]
[Tue Jul 21 08:18:38.172213 2026] [security2:error] [pid 411857:tid 412068] [client 20.151.10.161:45939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/7.php"] [unique_id "al9Vji7ynBpLeKYztQPCZgAAAE8"]
[Tue Jul 21 08:18:38.230373 2026] [authz_core:error] [pid 411857:tid 412099] [client 74.249.245.134:15364] AH01630: client denied by server configuration: /home2/fer44417/fernandohipolito.com.br/php.ini
[Tue Jul 21 08:18:38.540630 2026] [security2:error] [pid 411857:tid 411999] [client 20.220.225.223:38702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/abcd.php"] [unique_id "al9Vji7ynBpLeKYztQPCfgAAAAo"]
[Tue Jul 21 08:18:38.543767 2026] [security2:error] [pid 411857:tid 412049] [client 74.249.245.134:15364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/settings.php"] [unique_id "al9Vji7ynBpLeKYztQPCfwAAADw"]
[Tue Jul 21 08:18:38.566919 2026] [security2:error] [pid 411857:tid 412101] [client 91.148.245.81:55988] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/wp-config.php"] [unique_id "al9Vji7ynBpLeKYztQPCgAAAAHA"]
[Tue Jul 21 08:18:38.568018 2026] [security2:error] [pid 411857:tid 412015] [client 91.148.245.81:56018] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/actuator/heapdump"] [unique_id "al9Vji7ynBpLeKYztQPCgQAAABo"]
[Tue Jul 21 08:18:38.568738 2026] [security2:error] [pid 411857:tid 412033] [client 91.148.245.81:56042] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/backup.zip"] [unique_id "al9Vji7ynBpLeKYztQPCggAAACw"]
[Tue Jul 21 08:18:38.569753 2026] [security2:error] [pid 411857:tid 412107] [client 91.148.245.81:56002] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/.svn/wc.db"] [unique_id "al9Vji7ynBpLeKYztQPCgwAAAHY"]
[Tue Jul 21 08:18:38.614647 2026] [security2:error] [pid 411857:tid 411913] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Vji7ynBpLeKYztQPChAAAXDY"]
[Tue Jul 21 08:18:38.614886 2026] [security2:error] [pid 411857:tid 412081] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Vji7ynBpLeKYztQPChAAAXDY"]
[Tue Jul 21 08:18:38.620021 2026] [security2:error] [pid 411857:tid 412080] [client 62.102.148.158:40476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Vji7ynBpLeKYztQPChQAAAFs"]
[Tue Jul 21 08:18:38.620112 2026] [security2:error] [pid 411857:tid 412080] [client 62.102.148.158:40476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Vji7ynBpLeKYztQPChQAAAFs"]
[Tue Jul 21 08:18:38.771066 2026] [security2:error] [pid 411857:tid 412116] [client 91.148.245.81:56046] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/secrets.json"] [unique_id "al9Vji7ynBpLeKYztQPCjAAAAH8"]
[Tue Jul 21 08:18:38.899297 2026] [security2:error] [pid 411857:tid 412044] [client 20.226.60.151:52259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/lib.php"] [unique_id "al9Vji7ynBpLeKYztQPClgAAADc"]
[Tue Jul 21 08:18:39.025523 2026] [security2:error] [pid 411857:tid 412052] [client 154.208.47.43:50029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Vjy7ynBpLeKYztQPCmAAAAD8"]
[Tue Jul 21 08:18:39.025686 2026] [security2:error] [pid 411857:tid 412052] [client 154.208.47.43:50029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Vjy7ynBpLeKYztQPCmAAAAD8"]
[Tue Jul 21 08:18:39.288427 2026] [security2:error] [pid 411857:tid 412027] [client 152.59.34.51:52645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Vjy7ynBpLeKYztQPCnQAAACY"]
[Tue Jul 21 08:18:39.288563 2026] [security2:error] [pid 411857:tid 412027] [client 152.59.34.51:52645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Vjy7ynBpLeKYztQPCnQAAACY"]
[Tue Jul 21 08:18:39.307457 2026] [security2:error] [pid 411857:tid 412115] [client 38.100.221.102:18678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vjy7ynBpLeKYztQPCngAAAH4"]
[Tue Jul 21 08:18:39.307631 2026] [security2:error] [pid 411857:tid 412115] [client 38.100.221.102:18678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vjy7ynBpLeKYztQPCngAAAH4"]
[Tue Jul 21 08:18:39.316216 2026] [security2:error] [pid 411857:tid 412035] [client 74.7.175.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rafaelapetry1781703969750.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9Vjy7ynBpLeKYztQPCnwAALkk"]
[Tue Jul 21 08:18:39.426859 2026] [security2:error] [pid 411857:tid 411958] [remote 46.105.28.235:60606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Vjy7ynBpLeKYztQPCqwAAR2I"]
[Tue Jul 21 08:18:39.429188 2026] [security2:error] [pid 411857:tid 411994] [client 20.226.60.151:51974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/login.php"] [unique_id "al9Vjy7ynBpLeKYztQPCrAAAAAU"]
[Tue Jul 21 08:18:39.477667 2026] [security2:error] [pid 411857:tid 412097] [client 20.206.105.145:25091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Vjy7ynBpLeKYztQPCrQAAAGw"]
[Tue Jul 21 08:18:39.543418 2026] [security2:error] [pid 411857:tid 412105] [client 114.119.138.67:29643] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "valordisruptivo.com.br"] [uri "/"] [unique_id "al9Vjy7ynBpLeKYztQPCtQAAAHQ"], referer: https://anchorurl.cloud/share/94111
[Tue Jul 21 08:18:39.660564 2026] [security2:error] [pid 411857:tid 412017] [client 20.226.60.151:48858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/177.php"] [unique_id "al9Vjy7ynBpLeKYztQPCtgAAABw"]
[Tue Jul 21 08:18:39.736774 2026] [security2:error] [pid 411857:tid 412084] [client 20.151.10.161:46023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/8.php"] [unique_id "al9Vjy7ynBpLeKYztQPCuAAAAF8"]
[Tue Jul 21 08:18:39.953617 2026] [security2:error] [pid 411857:tid 412057] [client 20.226.60.151:60333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/a2.php"] [unique_id "al9Vjy7ynBpLeKYztQPCxAAAAEQ"]
[Tue Jul 21 08:18:39.993924 2026] [security2:error] [pid 411857:tid 412043] [client 65.21.113.253:51562] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vjy7ynBpLeKYztQPCugAAADY"]
[Tue Jul 21 08:18:40.120134 2026] [security2:error] [pid 411857:tid 412039] [client 103.151.46.103:54865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VkC7ynBpLeKYztQPCyQAAADI"]
[Tue Jul 21 08:18:40.120260 2026] [security2:error] [pid 411857:tid 412039] [client 103.151.46.103:54865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VkC7ynBpLeKYztQPCyQAAADI"]
[Tue Jul 21 08:18:40.189260 2026] [security2:error] [pid 411857:tid 411859] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VkC7ynBpLeKYztQPCzAAAbQA"]
[Tue Jul 21 08:18:40.189379 2026] [security2:error] [pid 411857:tid 412098] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VkC7ynBpLeKYztQPCzAAAbQA"]
[Tue Jul 21 08:18:40.299358 2026] [security2:error] [pid 411857:tid 412092] [client 115.134.11.136:61576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VkC7ynBpLeKYztQPC0wAAAGc"]
[Tue Jul 21 08:18:40.300217 2026] [security2:error] [pid 411857:tid 412092] [client 115.134.11.136:61576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VkC7ynBpLeKYztQPC0wAAAGc"]
[Tue Jul 21 08:18:40.387985 2026] [security2:error] [pid 411857:tid 411996] [client 102.206.115.33:62089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VkC7ynBpLeKYztQPC1AAAAAc"]
[Tue Jul 21 08:18:40.388142 2026] [security2:error] [pid 411857:tid 411996] [client 102.206.115.33:62089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VkC7ynBpLeKYztQPC1AAAAAc"]
[Tue Jul 21 08:18:40.391887 2026] [security2:error] [pid 411857:tid 412041] [client 20.226.60.151:53329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/d61.php"] [unique_id "al9VkC7ynBpLeKYztQPC1QAAADQ"]
[Tue Jul 21 08:18:40.527800 2026] [security2:error] [pid 411857:tid 412033] [client 187.125.243.197:57939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VkC7ynBpLeKYztQPC3gAAACw"]
[Tue Jul 21 08:18:40.528622 2026] [security2:error] [pid 411857:tid 412033] [client 187.125.243.197:57939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VkC7ynBpLeKYztQPC3gAAACw"]
[Tue Jul 21 08:18:40.548130 2026] [security2:error] [pid 411857:tid 412058] [client 20.220.225.223:38686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/xyn.php"] [unique_id "al9VkC7ynBpLeKYztQPC3wAAAEU"]
[Tue Jul 21 08:18:40.581868 2026] [security2:error] [pid 411857:tid 412025] [client 103.78.200.11:49656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VkC7ynBpLeKYztQPC4AAAACQ"]
[Tue Jul 21 08:18:40.582005 2026] [security2:error] [pid 411857:tid 412025] [client 103.78.200.11:49656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VkC7ynBpLeKYztQPC4AAAACQ"]
[Tue Jul 21 08:18:40.704735 2026] [security2:error] [pid 411857:tid 412011] [client 173.252.95.54:38384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9VkC7ynBpLeKYztQPC4wAAABY"]
[Tue Jul 21 08:18:40.871830 2026] [security2:error] [pid 411857:tid 412084] [client 74.249.245.134:31409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/g.php"] [unique_id "al9VkC7ynBpLeKYztQPC5wAAAF8"]
[Tue Jul 21 08:18:40.922092 2026] [security2:error] [pid 411857:tid 412030] [client 20.226.60.151:48864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/config.php"] [unique_id "al9VkC7ynBpLeKYztQPC7gAAACk"]
[Tue Jul 21 08:18:40.950241 2026] [security2:error] [pid 411857:tid 412032] [client 91.92.41.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "andreiapereiradossan1782652807342.0721679.meusitehostgator.com.br"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9VkC7ynBpLeKYztQPC8gAAACs"]
[Tue Jul 21 08:18:41.067673 2026] [security2:error] [pid 411857:tid 412100] [client 20.226.60.151:52027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/info.php"] [unique_id "al9VkS7ynBpLeKYztQPC9AAAAG8"]
[Tue Jul 21 08:18:41.386635 2026] [security2:error] [pid 411857:tid 412115] [client 20.226.60.151:64091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/ops.php"] [unique_id "al9VkS7ynBpLeKYztQPC-gAAAH4"]
[Tue Jul 21 08:18:41.806299 2026] [security2:error] [pid 411857:tid 412015] [client 20.226.60.151:48856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/gettest.php"] [unique_id "al9VkS7ynBpLeKYztQPDMwAAABo"]
[Tue Jul 21 08:18:41.883320 2026] [security2:error] [pid 411857:tid 411911] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VkS7ynBpLeKYztQPDNwAAaTQ"]
[Tue Jul 21 08:18:41.883467 2026] [security2:error] [pid 411857:tid 412094] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VkS7ynBpLeKYztQPDNwAAaTQ"]
[Tue Jul 21 08:18:41.933702 2026] [security2:error] [pid 411857:tid 412012] [client 20.226.60.151:52008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/11.php"] [unique_id "al9VkS7ynBpLeKYztQPDPQAAABc"]
[Tue Jul 21 08:18:42.184156 2026] [security2:error] [pid 411857:tid 412071] [client 74.249.245.134:15145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/403.php"] [unique_id "al9Vki7ynBpLeKYztQPDewAAAFI"]
[Tue Jul 21 08:18:42.207822 2026] [security2:error] [pid 411857:tid 412049] [client 87.116.180.198:27386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vki7ynBpLeKYztQPDhAAAADw"]
[Tue Jul 21 08:18:42.207903 2026] [security2:error] [pid 411857:tid 412049] [client 87.116.180.198:27386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vki7ynBpLeKYztQPDhAAAADw"]
[Tue Jul 21 08:18:42.241839 2026] [security2:error] [pid 411857:tid 412083] [client 20.151.10.161:45941] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.cmpartners.com.br"] [uri "/1.php"] [unique_id "al9Vki7ynBpLeKYztQPDiwAAAF4"]
[Tue Jul 21 08:18:42.241964 2026] [security2:error] [pid 411857:tid 412083] [client 20.151.10.161:45941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/1.php"] [unique_id "al9Vki7ynBpLeKYztQPDiwAAAF4"]
[Tue Jul 21 08:18:42.368061 2026] [security2:error] [pid 411857:tid 412067] [client 20.226.60.151:60668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Vki7ynBpLeKYztQPDkwAAAE4"]
[Tue Jul 21 08:18:42.404483 2026] [security2:error] [pid 411857:tid 412105] [client 20.226.60.151:60307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/v2.php"] [unique_id "al9Vki7ynBpLeKYztQPDlwAAAHQ"]
[Tue Jul 21 08:18:42.788716 2026] [security2:error] [pid 411857:tid 412109] [client 20.226.60.151:49247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/min.php"] [unique_id "al9Vki7ynBpLeKYztQPDpwAAAHg"]
[Tue Jul 21 08:18:43.086202 2026] [security2:error] [pid 411857:tid 412049] [client 74.249.245.134:31393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.fernandohipolito.com.br"] [uri "/api.php"] [unique_id "al9Vky7ynBpLeKYztQPDtQAAADw"]
[Tue Jul 21 08:18:43.167158 2026] [security2:error] [pid 411857:tid 412096] [client 14.245.224.124:50138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Vky7ynBpLeKYztQPDugAAAGs"]
[Tue Jul 21 08:18:43.167250 2026] [security2:error] [pid 411857:tid 412096] [client 14.245.224.124:50138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Vky7ynBpLeKYztQPDugAAAGs"]
[Tue Jul 21 08:18:43.263761 2026] [security2:error] [pid 411857:tid 412066] [client 103.106.20.201:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vky7ynBpLeKYztQPDvQAAAE0"]
[Tue Jul 21 08:18:43.263929 2026] [security2:error] [pid 411857:tid 412066] [client 103.106.20.201:50008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vky7ynBpLeKYztQPDvQAAAE0"]
[Tue Jul 21 08:18:43.374621 2026] [security2:error] [pid 411857:tid 412099] [client 117.213.202.34:50433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vky7ynBpLeKYztQPDwAAAAG4"]
[Tue Jul 21 08:18:43.374809 2026] [security2:error] [pid 411857:tid 412099] [client 117.213.202.34:50433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vky7ynBpLeKYztQPDwAAAAG4"]
[Tue Jul 21 08:18:43.438759 2026] [security2:error] [pid 411857:tid 412105] [client 20.226.60.151:53369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/panel.php"] [unique_id "al9Vky7ynBpLeKYztQPDxwAAAHQ"]
[Tue Jul 21 08:18:43.920203 2026] [security2:error] [pid 411857:tid 411865] [remote 20.153.140.50:60984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-login.php"] [unique_id "al9Vky7ynBpLeKYztQPEFgAAQQY"]
[Tue Jul 21 08:18:43.977494 2026] [security2:error] [pid 411857:tid 412068] [client 20.206.105.145:25513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/u.php"] [unique_id "al9Vky7ynBpLeKYztQPEGwAAAE8"]
[Tue Jul 21 08:18:44.058637 2026] [security2:error] [pid 411857:tid 412061] [client 151.63.71.144:55897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9VlC7ynBpLeKYztQPEIQAAAEg"]
[Tue Jul 21 08:18:44.058771 2026] [security2:error] [pid 411857:tid 412061] [client 151.63.71.144:55897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9VlC7ynBpLeKYztQPEIQAAAEg"]
[Tue Jul 21 08:18:44.154996 2026] [security2:error] [pid 411857:tid 412015] [client 65.21.113.253:51562] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vky7ynBpLeKYztQPECQAAABo"]
[Tue Jul 21 08:18:44.204068 2026] [security2:error] [pid 411857:tid 412097] [client 20.226.60.151:53365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/dex.php"] [unique_id "al9VlC7ynBpLeKYztQPEMwAAAGw"]
[Tue Jul 21 08:18:44.395493 2026] [security2:error] [pid 411857:tid 411992] [client 20.226.60.151:52031] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "advcelsopinto.com.br"] [uri "/1.php"] [unique_id "al9VlC7ynBpLeKYztQPERAAAAAM"]
[Tue Jul 21 08:18:44.395631 2026] [security2:error] [pid 411857:tid 411992] [client 20.226.60.151:52031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/1.php"] [unique_id "al9VlC7ynBpLeKYztQPERAAAAAM"]
[Tue Jul 21 08:18:44.513568 2026] [security2:error] [pid 411857:tid 412053] [client 20.226.60.151:64116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/mac.php"] [unique_id "al9VlC7ynBpLeKYztQPEkwAAAEA"]
[Tue Jul 21 08:18:44.700932 2026] [security2:error] [pid 411857:tid 412040] [client 20.226.60.151:60302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/ms.php"] [unique_id "al9VlC7ynBpLeKYztQPEnAAAADM"]
[Tue Jul 21 08:18:44.709770 2026] [security2:error] [pid 411857:tid 412041] [client 20.226.60.151:48812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/dvjul.php"] [unique_id "al9VlC7ynBpLeKYztQPEnQAAADQ"]
[Tue Jul 21 08:18:44.805550 2026] [security2:error] [pid 411857:tid 412016] [client 91.148.245.81:32886] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/config.xml"] [unique_id "al9VlC7ynBpLeKYztQPEngAAABs"]
[Tue Jul 21 08:18:44.808544 2026] [security2:error] [pid 411857:tid 412109] [client 91.148.245.81:32900] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9VlC7ynBpLeKYztQPEnwAAAHg"]
[Tue Jul 21 08:18:44.810573 2026] [security2:error] [pid 411857:tid 412089] [client 91.148.245.81:32902] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9VlC7ynBpLeKYztQPEoAAAAGQ"]
[Tue Jul 21 08:18:44.810684 2026] [security2:error] [pid 411857:tid 412072] [client 91.148.245.81:32912] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/backup.tar.gz"] [unique_id "al9VlC7ynBpLeKYztQPEoQAAAFM"]
[Tue Jul 21 08:18:45.007713 2026] [security2:error] [pid 411857:tid 412036] [client 91.148.245.81:32924] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/dump.sql"] [unique_id "al9VlS7ynBpLeKYztQPErAAAAC8"]
[Tue Jul 21 08:18:45.011477 2026] [security2:error] [pid 411857:tid 412079] [client 150.129.202.39:64561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VlS7ynBpLeKYztQPErQAAAFo"]
[Tue Jul 21 08:18:45.011561 2026] [security2:error] [pid 411857:tid 412079] [client 150.129.202.39:64561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VlS7ynBpLeKYztQPErQAAAFo"]
[Tue Jul 21 08:18:45.012369 2026] [security2:error] [pid 411857:tid 412061] [client 91.148.245.81:32926] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/config.php"] [unique_id "al9VlS7ynBpLeKYztQPErgAAAEg"]
[Tue Jul 21 08:18:45.168377 2026] [security2:error] [pid 411857:tid 412047] [client 20.226.60.151:60626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/xyn.php"] [unique_id "al9VlS7ynBpLeKYztQPEtwAAADo"]
[Tue Jul 21 08:18:45.207352 2026] [autoindex:error] [pid 411857:tid 412101] [client 20.226.60.151:51986] AH01276: Cannot serve directory /home1/advcel43/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:18:45.221588 2026] [security2:error] [pid 411857:tid 412105] [client 20.226.60.151:51986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/memberfuns.php"] [unique_id "al9VlS7ynBpLeKYztQPEuAAAAHQ"]
[Tue Jul 21 08:18:45.257222 2026] [security2:error] [pid 411857:tid 412048] [client 117.210.135.0:51140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VlS7ynBpLeKYztQPEugAAADs"]
[Tue Jul 21 08:18:45.257381 2026] [security2:error] [pid 411857:tid 412048] [client 117.210.135.0:51140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VlS7ynBpLeKYztQPEugAAADs"]
[Tue Jul 21 08:18:45.287408 2026] [security2:error] [pid 411857:tid 412034] [client 20.220.225.223:38683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/byp8.php"] [unique_id "al9VlS7ynBpLeKYztQPEvAAAAC0"]
[Tue Jul 21 08:18:45.607888 2026] [security2:error] [pid 411857:tid 412093] [client 91.148.245.81:32938] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/backup.sql"] [unique_id "al9VlS7ynBpLeKYztQPEwgAAAGg"]
[Tue Jul 21 08:18:45.608858 2026] [security2:error] [pid 411857:tid 412077] [client 91.148.245.81:32944] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/.bash_history"] [unique_id "al9VlS7ynBpLeKYztQPEwwAAAFg"]
[Tue Jul 21 08:18:45.628124 2026] [security2:error] [pid 411857:tid 412041] [client 20.197.192.193:62401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/aa1.php"] [unique_id "al9VlS7ynBpLeKYztQPExgAAADQ"]
[Tue Jul 21 08:18:45.744268 2026] [security2:error] [pid 411857:tid 412060] [client 20.226.60.151:2911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/0.php"] [unique_id "al9VlS7ynBpLeKYztQPEzQAAAEc"]
[Tue Jul 21 08:18:45.843282 2026] [security2:error] [pid 411857:tid 412031] [client 86.106.84.166:33212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9VlS7ynBpLeKYztQPE0QAAACo"]
[Tue Jul 21 08:18:45.843399 2026] [security2:error] [pid 411857:tid 412031] [client 86.106.84.166:33212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9VlS7ynBpLeKYztQPE0QAAACo"]
[Tue Jul 21 08:18:45.958119 2026] [security2:error] [pid 411857:tid 412088] [client 20.226.60.151:52018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/BDKR28.php"] [unique_id "al9VlS7ynBpLeKYztQPE1gAAAGM"]
[Tue Jul 21 08:18:46.120599 2026] [security2:error] [pid 411857:tid 412047] [client 20.206.105.145:25504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/sss.php"] [unique_id "al9Vli7ynBpLeKYztQPE2wAAADo"]
[Tue Jul 21 08:18:46.127991 2026] [security2:error] [pid 411857:tid 412014] [client 85.204.70.100:42712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ffstrength.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Vli7ynBpLeKYztQPE3AAAABk"]
[Tue Jul 21 08:18:46.152686 2026] [security2:error] [pid 411857:tid 412037] [client 91.148.245.81:32958] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "toninedi.com.br.bomexito.com.br"] [uri "/.npmrc"] [unique_id "al9Vli7ynBpLeKYztQPE3wAAADA"]
[Tue Jul 21 08:18:46.202484 2026] [security2:error] [pid 411857:tid 412085] [client 120.56.162.40:57658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vli7ynBpLeKYztQPE4QAAAGA"]
[Tue Jul 21 08:18:46.202831 2026] [security2:error] [pid 411857:tid 412085] [client 120.56.162.40:57658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vli7ynBpLeKYztQPE4QAAAGA"]
[Tue Jul 21 08:18:46.219348 2026] [security2:error] [pid 411857:tid 412081] [client 20.226.60.151:60339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/green1.php"] [unique_id "al9Vli7ynBpLeKYztQPE5AAAAFw"]
[Tue Jul 21 08:18:46.263217 2026] [security2:error] [pid 411857:tid 412115] [client 20.226.60.151:53362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/nc4.php"] [unique_id "al9Vli7ynBpLeKYztQPE6QAAAH4"]
[Tue Jul 21 08:18:46.284801 2026] [security2:error] [pid 411857:tid 411960] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vli7ynBpLeKYztQPE6gAAa2Q"]
[Tue Jul 21 08:18:46.284995 2026] [security2:error] [pid 411857:tid 412096] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vli7ynBpLeKYztQPE6gAAa2Q"]
[Tue Jul 21 08:18:46.328115 2026] [security2:error] [pid 411857:tid 412114] [client 137.97.59.154:26825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Vli7ynBpLeKYztQPE6wAAAH0"]
[Tue Jul 21 08:18:46.328236 2026] [security2:error] [pid 411857:tid 412114] [client 137.97.59.154:26825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Vli7ynBpLeKYztQPE6wAAAH0"]
[Tue Jul 21 08:18:46.386735 2026] [security2:error] [pid 411857:tid 412093] [client 20.226.60.151:53333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/a1.php"] [unique_id "al9Vli7ynBpLeKYztQPE8AAAAGg"]
[Tue Jul 21 08:18:46.508706 2026] [security2:error] [pid 411857:tid 412109] [client 20.226.60.151:52247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/eee.php"] [unique_id "al9Vli7ynBpLeKYztQPE9QAAAHg"]
[Tue Jul 21 08:18:46.667492 2026] [security2:error] [pid 411857:tid 412084] [client 20.226.60.151:51970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/wp-aothait.php"] [unique_id "al9Vli7ynBpLeKYztQPE-QAAAF8"]
[Tue Jul 21 08:18:46.882761 2026] [security2:error] [pid 411857:tid 412072] [client 85.204.70.100:42724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ffstrength.com"] [uri "/xmlrpc.php"] [unique_id "al9Vli7ynBpLeKYztQPFAgAAAFM"]
[Tue Jul 21 08:18:46.899040 2026] [security2:error] [pid 411857:tid 412112] [client 20.226.60.151:53352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/config.json.php"] [unique_id "al9Vli7ynBpLeKYztQPFBQAAAHs"]
[Tue Jul 21 08:18:46.964480 2026] [security2:error] [pid 411857:tid 411970] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vli7ynBpLeKYztQPFCAAANG4"]
[Tue Jul 21 08:18:46.964671 2026] [security2:error] [pid 411857:tid 412041] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vli7ynBpLeKYztQPFCAAANG4"]
[Tue Jul 21 08:18:47.052865 2026] [security2:error] [pid 411857:tid 412078] [client 20.226.60.151:52243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9Vly7ynBpLeKYztQPFDQAAAFk"]
[Tue Jul 21 08:18:47.121100 2026] [security2:error] [pid 411857:tid 411867] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Vly7ynBpLeKYztQPFDwAAKAg"]
[Tue Jul 21 08:18:47.121304 2026] [security2:error] [pid 411857:tid 412029] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Vly7ynBpLeKYztQPFDwAAKAg"]
[Tue Jul 21 08:18:47.299937 2026] [security2:error] [pid 411857:tid 412054] [client 62.102.148.158:41504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Vly7ynBpLeKYztQPFFwAAAEE"]
[Tue Jul 21 08:18:47.300042 2026] [security2:error] [pid 411857:tid 412054] [client 62.102.148.158:41504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Vly7ynBpLeKYztQPFFwAAAEE"]
[Tue Jul 21 08:18:47.386298 2026] [security2:error] [pid 411857:tid 412081] [client 20.226.60.151:49379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/biufile.php"] [unique_id "al9Vly7ynBpLeKYztQPFHQAAAFw"]
[Tue Jul 21 08:18:47.447763 2026] [security2:error] [pid 411857:tid 412108] [client 20.226.60.151:52269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/k2.php"] [unique_id "al9Vly7ynBpLeKYztQPFIQAAAHc"]
[Tue Jul 21 08:18:47.536022 2026] [security2:error] [pid 411857:tid 412056] [client 47.128.20.2:51364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "seaportservicos.com.br"] [uri "/robots.txt"] [unique_id "al9Vly7ynBpLeKYztQPFJAAAAEM"]
[Tue Jul 21 08:18:47.643393 2026] [security2:error] [pid 411857:tid 412105] [client 69.171.230.39:62808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Vly7ynBpLeKYztQPFKgAAAHQ"]
[Tue Jul 21 08:18:47.793859 2026] [security2:error] [pid 411857:tid 412040] [client 20.226.60.151:60630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/patie.php"] [unique_id "al9Vly7ynBpLeKYztQPFMAAAADM"]
[Tue Jul 21 08:18:48.023504 2026] [security2:error] [pid 411857:tid 411991] [client 20.206.105.145:25117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/sss.php"] [unique_id "al9VmC7ynBpLeKYztQPFOQAAAAI"]
[Tue Jul 21 08:18:48.220420 2026] [security2:error] [pid 411857:tid 411989] [client 20.151.10.161:45981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/100.php"] [unique_id "al9VmC7ynBpLeKYztQPFQAAAAAA"]
[Tue Jul 21 08:18:48.230646 2026] [security2:error] [pid 411857:tid 412007] [client 87.199.196.160:52212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.196.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.murilomattos.com"] [uri "/wp-comments-post.php"] [unique_id "al9Vly7ynBpLeKYztQPFDgAAABI"], referer: https://www.murilomattos.com/product/36h-event/
[Tue Jul 21 08:18:48.230777 2026] [security2:error] [pid 411857:tid 412007] [client 87.199.196.160:52212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.murilomattos.com"] [uri "/wp-comments-post.php"] [unique_id "al9Vly7ynBpLeKYztQPFDgAAABI"], referer: https://www.murilomattos.com/product/36h-event/
[Tue Jul 21 08:18:48.481965 2026] [security2:error] [pid 411857:tid 412078] [client 223.181.60.88:7742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VmC7ynBpLeKYztQPFSAAAAFk"]
[Tue Jul 21 08:18:48.482125 2026] [security2:error] [pid 411857:tid 412078] [client 223.181.60.88:7742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VmC7ynBpLeKYztQPFSAAAAFk"]
[Tue Jul 21 08:18:48.575281 2026] [security2:error] [pid 411857:tid 412092] [client 20.226.60.151:51995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9VmC7ynBpLeKYztQPFSwAAAGc"]
[Tue Jul 21 08:18:48.803751 2026] [security2:error] [pid 411857:tid 412053] [client 20.226.60.151:64006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/mg.php"] [unique_id "al9VmC7ynBpLeKYztQPFUwAAAEA"]
[Tue Jul 21 08:18:49.083819 2026] [security2:error] [pid 411857:tid 411870] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VmS7ynBpLeKYztQPFYQAAOws"]
[Tue Jul 21 08:18:49.083964 2026] [security2:error] [pid 411857:tid 412048] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VmS7ynBpLeKYztQPFYQAAOws"]
[Tue Jul 21 08:18:49.394730 2026] [security2:error] [pid 411857:tid 412075] [client 91.92.47.112:56988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/settings.php"] [unique_id "al9VmS7ynBpLeKYztQPFZwAAAFY"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:18:49.405986 2026] [security2:error] [pid 411857:tid 411996] [client 91.92.47.112:57004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/db.php"] [unique_id "al9VmS7ynBpLeKYztQPFawAAAAc"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:18:49.501268 2026] [security2:error] [pid 411857:tid 412062] [client 91.92.47.112:57028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/database.php"] [unique_id "al9VmS7ynBpLeKYztQPFdQAAAEk"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:18:49.535533 2026] [security2:error] [pid 411857:tid 412045] [client 20.226.60.151:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9VmS7ynBpLeKYztQPFegAAADg"]
[Tue Jul 21 08:18:49.548164 2026] [security2:error] [pid 411857:tid 412070] [client 91.92.47.112:57042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "tabelionatoportoalegre.com.br"] [uri "/web.config"] [unique_id "al9VmS7ynBpLeKYztQPFewAAAFE"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:18:49.592777 2026] [security2:error] [pid 411857:tid 412063] [client 20.226.60.151:60544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/aa.php"] [unique_id "al9VmS7ynBpLeKYztQPFfgAAAEo"]
[Tue Jul 21 08:18:49.610396 2026] [security2:error] [pid 411857:tid 412043] [client 154.208.47.43:62919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VmS7ynBpLeKYztQPFhAAAADY"]
[Tue Jul 21 08:18:49.610536 2026] [security2:error] [pid 411857:tid 412043] [client 154.208.47.43:62919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VmS7ynBpLeKYztQPFhAAAADY"]
[Tue Jul 21 08:18:49.620772 2026] [security2:error] [pid 411857:tid 411999] [client 91.92.47.112:57072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "tabelionatoportoalegre.com.br"] [uri "/.env.bak"] [unique_id "al9VmS7ynBpLeKYztQPFhQAAAAo"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:18:49.670649 2026] [security2:error] [pid 411857:tid 412033] [client 20.197.192.193:3334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/acew67.php"] [unique_id "al9VmS7ynBpLeKYztQPFigAAACw"]
[Tue Jul 21 08:18:49.845679 2026] [security2:error] [pid 411857:tid 412101] [client 38.100.221.102:17377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VmS7ynBpLeKYztQPFjwAAAHA"]
[Tue Jul 21 08:18:49.845859 2026] [security2:error] [pid 411857:tid 412101] [client 38.100.221.102:17377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VmS7ynBpLeKYztQPFjwAAAHA"]
[Tue Jul 21 08:18:49.847305 2026] [security2:error] [pid 411857:tid 412090] [client 20.226.60.151:48887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/av.php"] [unique_id "al9VmS7ynBpLeKYztQPFkAAAAGU"]
[Tue Jul 21 08:18:49.963783 2026] [security2:error] [pid 411857:tid 412103] [client 185.213.175.37:6378] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.rinettoar.com.br"] [uri "/appsettings.json"] [unique_id "al9VmS7ynBpLeKYztQPFlgAAAHI"]
[Tue Jul 21 08:18:49.977013 2026] [security2:error] [pid 411857:tid 412048] [client 20.220.225.223:31182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/user.php"] [unique_id "al9VmS7ynBpLeKYztQPFlwAAADs"]
[Tue Jul 21 08:18:49.982549 2026] [security2:error] [pid 411857:tid 412004] [client 61.1.167.83:60387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VmS7ynBpLeKYztQPFmAAAAA8"]
[Tue Jul 21 08:18:49.982652 2026] [security2:error] [pid 411857:tid 412004] [client 61.1.167.83:60387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VmS7ynBpLeKYztQPFmAAAAA8"]
[Tue Jul 21 08:18:50.154085 2026] [security2:error] [pid 411857:tid 412002] [client 81.171.72.93:44876] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFpAAAAA0"]
[Tue Jul 21 08:18:50.154170 2026] [security2:error] [pid 411857:tid 412024] [client 81.171.72.93:44862] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFowAAACM"]
[Tue Jul 21 08:18:50.156038 2026] [security2:error] [pid 411857:tid 412095] [client 81.171.72.93:44882] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFpQAAAGo"]
[Tue Jul 21 08:18:50.157187 2026] [security2:error] [pid 411857:tid 412016] [client 81.171.72.93:44880] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFpwAAABs"]
[Tue Jul 21 08:18:50.157250 2026] [security2:error] [pid 411857:tid 412109] [client 81.171.72.135:39532] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFpgAAAHg"]
[Tue Jul 21 08:18:50.158280 2026] [security2:error] [pid 411857:tid 412049] [client 81.171.72.135:39530] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFqAAAADw"]
[Tue Jul 21 08:18:50.158355 2026] [security2:error] [pid 411857:tid 412039] [client 81.171.72.93:44884] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFqQAAADI"]
[Tue Jul 21 08:18:50.158611 2026] [security2:error] [pid 411857:tid 412008] [client 81.171.72.135:39546] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFqgAAABM"]
[Tue Jul 21 08:18:50.222754 2026] [core:error] [pid 411857:tid 412007] [client 66.249.66.67:51423] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:18:50.222778 2026] [core:error] [pid 411857:tid 412007] [client 66.249.66.67:51423] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:18:50.309762 2026] [security2:error] [pid 411857:tid 412042] [client 81.171.72.135:39572] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFrQAAADU"]
[Tue Jul 21 08:18:50.310353 2026] [security2:error] [pid 411857:tid 412032] [client 81.171.72.135:39560] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFrgAAACs"]
[Tue Jul 21 08:18:50.311008 2026] [security2:error] [pid 411857:tid 412110] [client 81.171.72.135:39582] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFrwAAAHk"]
[Tue Jul 21 08:18:50.412298 2026] [security2:error] [pid 411857:tid 412083] [client 81.171.74.60:49880] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFuwAAAF4"]
[Tue Jul 21 08:18:50.552030 2026] [security2:error] [pid 411857:tid 411990] [client 74.249.245.134:62324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/wp.php"] [unique_id "al9Vmi7ynBpLeKYztQPFwgAAAAE"]
[Tue Jul 21 08:18:50.560634 2026] [security2:error] [pid 411857:tid 412112] [client 81.171.72.93:44854] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFwwAAAHs"]
[Tue Jul 21 08:18:50.646452 2026] [security2:error] [pid 411857:tid 412108] [client 81.171.74.60:49904] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFyAAAAHc"]
[Tue Jul 21 08:18:50.647462 2026] [security2:error] [pid 411857:tid 412068] [client 81.171.74.60:49912] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFyQAAAE8"]
[Tue Jul 21 08:18:50.647471 2026] [security2:error] [pid 411857:tid 412053] [client 81.171.74.60:49894] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPFygAAAEA"]
[Tue Jul 21 08:18:50.662964 2026] [security2:error] [pid 411857:tid 412035] [client 103.151.46.103:55353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vmi7ynBpLeKYztQPFywAAAC4"]
[Tue Jul 21 08:18:50.663063 2026] [security2:error] [pid 411857:tid 412035] [client 103.151.46.103:55353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vmi7ynBpLeKYztQPFywAAAC4"]
[Tue Jul 21 08:18:50.726560 2026] [security2:error] [pid 411857:tid 412109] [client 20.151.10.161:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/about.php"] [unique_id "al9Vmi7ynBpLeKYztQPFzQAAAHg"]
[Tue Jul 21 08:18:50.738093 2026] [security2:error] [pid 411857:tid 412100] [client 115.134.11.136:62010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vmi7ynBpLeKYztQPFzwAAAG8"]
[Tue Jul 21 08:18:50.738244 2026] [security2:error] [pid 411857:tid 412100] [client 115.134.11.136:62010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vmi7ynBpLeKYztQPFzwAAAG8"]
[Tue Jul 21 08:18:50.782114 2026] [security2:error] [pid 411857:tid 412089] [client 81.171.72.93:44898] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/backup.sql"] [unique_id "al9Vmi7ynBpLeKYztQPF1QAAAGQ"]
[Tue Jul 21 08:18:50.782376 2026] [security2:error] [pid 411857:tid 412073] [client 81.171.72.93:44912] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/wp-config.php"] [unique_id "al9Vmi7ynBpLeKYztQPF1gAAAFQ"]
[Tue Jul 21 08:18:50.782376 2026] [security2:error] [pid 411857:tid 412022] [client 81.171.72.93:44894] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9Vmi7ynBpLeKYztQPF1wAAACE"]
[Tue Jul 21 08:18:50.783082 2026] [security2:error] [pid 411857:tid 412052] [client 81.171.72.93:44910] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/config.xml"] [unique_id "al9Vmi7ynBpLeKYztQPF2AAAAD8"]
[Tue Jul 21 08:18:50.799031 2026] [security2:error] [pid 411857:tid 412070] [client 20.220.225.223:24240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/we.php"] [unique_id "al9Vmi7ynBpLeKYztQPF2gAAAFE"]
[Tue Jul 21 08:18:50.800633 2026] [security2:error] [pid 411857:tid 412111] [client 81.171.72.135:39596] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9Vmi7ynBpLeKYztQPF2wAAAHo"]
[Tue Jul 21 08:18:50.801285 2026] [security2:error] [pid 411857:tid 411996] [client 81.171.72.135:39602] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9Vmi7ynBpLeKYztQPF3AAAAAc"]
[Tue Jul 21 08:18:50.802226 2026] [security2:error] [pid 411857:tid 412044] [client 81.171.72.135:39594] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/database_backup.sql"] [unique_id "al9Vmi7ynBpLeKYztQPF3wAAADc"]
[Tue Jul 21 08:18:50.802227 2026] [security2:error] [pid 411857:tid 411991] [client 81.171.72.135:39588] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9Vmi7ynBpLeKYztQPF3QAAAAI"]
[Tue Jul 21 08:18:50.803105 2026] [security2:error] [pid 411857:tid 412062] [client 81.171.72.93:44936] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9Vmi7ynBpLeKYztQPF4AAAAEk"]
[Tue Jul 21 08:18:50.803180 2026] [security2:error] [pid 411857:tid 412061] [client 81.171.72.93:44942] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/database.sql"] [unique_id "al9Vmi7ynBpLeKYztQPF4QAAAEg"]
[Tue Jul 21 08:18:50.806325 2026] [security2:error] [pid 411857:tid 412013] [client 81.171.72.93:44918] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/dump.sql"] [unique_id "al9Vmi7ynBpLeKYztQPF4gAAABg"]
[Tue Jul 21 08:18:50.806486 2026] [security2:error] [pid 411857:tid 412099] [client 81.171.72.93:44922] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/config.php"] [unique_id "al9Vmi7ynBpLeKYztQPF4wAAAG4"]
[Tue Jul 21 08:18:50.817431 2026] [security2:error] [pid 411857:tid 411995] [client 81.171.74.60:49862] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPF5QAAAAY"]
[Tue Jul 21 08:18:50.818115 2026] [security2:error] [pid 411857:tid 412071] [client 81.171.74.60:49874] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/"] [unique_id "al9Vmi7ynBpLeKYztQPF5gAAAFI"]
[Tue Jul 21 08:18:50.934737 2026] [security2:error] [pid 411857:tid 411964] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vmi7ynBpLeKYztQPF8AAAamg"]
[Tue Jul 21 08:18:50.934841 2026] [security2:error] [pid 411857:tid 412003] [client 20.226.60.151:60609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/xwpg.php"] [unique_id "al9Vmi7ynBpLeKYztQPF7wAAAA4"]
[Tue Jul 21 08:18:50.934905 2026] [security2:error] [pid 411857:tid 412095] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vmi7ynBpLeKYztQPF8AAAamg"]
[Tue Jul 21 08:18:50.936024 2026] [security2:error] [pid 411857:tid 412049] [client 81.171.72.135:39640] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9Vmi7ynBpLeKYztQPF8QAAADw"]
[Tue Jul 21 08:18:50.936309 2026] [security2:error] [pid 411857:tid 412039] [client 81.171.72.135:39636] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/server.key"] [unique_id "al9Vmi7ynBpLeKYztQPF8gAAADI"]
[Tue Jul 21 08:18:50.936867 2026] [security2:error] [pid 411857:tid 412088] [client 81.171.72.135:39618] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/.svn/wc.db"] [unique_id "al9Vmi7ynBpLeKYztQPF8wAAAGM"]
[Tue Jul 21 08:18:50.937352 2026] [security2:error] [pid 411857:tid 412084] [client 81.171.72.135:39620] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/phpinfo.php"] [unique_id "al9Vmi7ynBpLeKYztQPF9AAAAF8"]
[Tue Jul 21 08:18:50.988468 2026] [security2:error] [pid 411857:tid 412097] [client 102.206.115.33:62721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vmi7ynBpLeKYztQPF9QAAAGw"]
[Tue Jul 21 08:18:50.988901 2026] [security2:error] [pid 411857:tid 412097] [client 102.206.115.33:62721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vmi7ynBpLeKYztQPF9QAAAGw"]
[Tue Jul 21 08:18:50.998878 2026] [security2:error] [pid 411857:tid 412114] [client 187.125.243.197:58442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Vmi7ynBpLeKYztQPF9gAAAH0"]
[Tue Jul 21 08:18:50.998993 2026] [security2:error] [pid 411857:tid 412114] [client 187.125.243.197:58442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Vmi7ynBpLeKYztQPF9gAAAH0"]
[Tue Jul 21 08:18:51.060529 2026] [security2:error] [pid 411857:tid 412022] [client 20.226.60.151:52237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9Vmy7ynBpLeKYztQPGBAAAACE"]
[Tue Jul 21 08:18:51.069573 2026] [security2:error] [pid 411857:tid 412115] [client 81.171.74.60:49954] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9Vmy7ynBpLeKYztQPGCAAAAH4"]
[Tue Jul 21 08:18:51.073724 2026] [security2:error] [pid 411857:tid 412023] [client 81.171.74.60:49922] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9Vmy7ynBpLeKYztQPGCgAAACI"]
[Tue Jul 21 08:18:51.074194 2026] [security2:error] [pid 411857:tid 412009] [client 81.171.74.60:49918] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/wp-config.php"] [unique_id "al9Vmy7ynBpLeKYztQPGCwAAABQ"]
[Tue Jul 21 08:18:51.074663 2026] [security2:error] [pid 411857:tid 412014] [client 81.171.74.60:49938] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/.env.production"] [unique_id "al9Vmy7ynBpLeKYztQPGDAAAABk"]
[Tue Jul 21 08:18:51.099400 2026] [security2:error] [pid 411857:tid 412062] [client 85.204.70.100:42750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ffstrength.com"] [uri "/xmlrpc.php"] [unique_id "al9Vmy7ynBpLeKYztQPGDgAAAEk"]
[Tue Jul 21 08:18:51.099519 2026] [security2:error] [pid 411857:tid 412062] [client 85.204.70.100:42750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ffstrength.com"] [uri "/xmlrpc.php"] [unique_id "al9Vmy7ynBpLeKYztQPGDgAAAEk"]
[Tue Jul 21 08:18:51.202428 2026] [security2:error] [pid 411857:tid 412031] [client 20.226.60.151:64030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-post-data.php"] [unique_id "al9Vmy7ynBpLeKYztQPGEAAAACo"]
[Tue Jul 21 08:18:51.424578 2026] [security2:error] [pid 411857:tid 412101] [client 81.171.72.93:44960] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/.env"] [unique_id "al9Vmy7ynBpLeKYztQPGOQAAAHA"]
[Tue Jul 21 08:18:51.425864 2026] [security2:error] [pid 411857:tid 412082] [client 81.171.72.93:44988] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/config.xml"] [unique_id "al9Vmy7ynBpLeKYztQPGOgAAAF0"]
[Tue Jul 21 08:18:51.426469 2026] [security2:error] [pid 411857:tid 412093] [client 81.171.72.93:45008] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/database.sql"] [unique_id "al9Vmy7ynBpLeKYztQPGOwAAAGg"]
[Tue Jul 21 08:18:51.427461 2026] [security2:error] [pid 411857:tid 412066] [client 81.171.72.93:45018] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/api/.env"] [unique_id "al9Vmy7ynBpLeKYztQPGPAAAAE0"]
[Tue Jul 21 08:18:51.427913 2026] [security2:error] [pid 411857:tid 412000] [client 81.171.72.93:44986] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9Vmy7ynBpLeKYztQPGPQAAAAs"]
[Tue Jul 21 08:18:51.428104 2026] [security2:error] [pid 411857:tid 412056] [client 81.171.72.93:44956] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/backup.sql"] [unique_id "al9Vmy7ynBpLeKYztQPGPgAAAEM"]
[Tue Jul 21 08:18:51.429299 2026] [security2:error] [pid 411857:tid 412086] [client 81.171.72.93:45022] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9Vmy7ynBpLeKYztQPGPwAAAGE"]
[Tue Jul 21 08:18:51.430418 2026] [security2:error] [pid 411857:tid 412106] [client 81.171.72.93:45042] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9Vmy7ynBpLeKYztQPGQAAAAHU"]
[Tue Jul 21 08:18:51.437175 2026] [security2:error] [pid 411857:tid 412083] [client 81.171.72.135:39642] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9Vmy7ynBpLeKYztQPGQQAAAF4"]
[Tue Jul 21 08:18:51.440768 2026] [security2:error] [pid 411857:tid 412065] [client 81.171.72.135:39658] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9Vmy7ynBpLeKYztQPGQgAAAEw"]
[Tue Jul 21 08:18:51.442238 2026] [security2:error] [pid 411857:tid 412012] [client 81.171.72.135:39678] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/.git/HEAD"] [unique_id "al9Vmy7ynBpLeKYztQPGQwAAABc"]
[Tue Jul 21 08:18:51.442500 2026] [security2:error] [pid 411857:tid 412040] [client 81.171.72.135:39690] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/.env"] [unique_id "al9Vmy7ynBpLeKYztQPGRAAAADM"]
[Tue Jul 21 08:18:51.476489 2026] [security2:error] [pid 411857:tid 412095] [client 20.226.60.151:49371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/coffexium.php"] [unique_id "al9Vmy7ynBpLeKYztQPGRwAAAGo"]
[Tue Jul 21 08:18:51.564278 2026] [security2:error] [pid 411857:tid 412099] [client 81.171.72.135:39774] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/config/production.json"] [unique_id "al9Vmy7ynBpLeKYztQPGSwAAAG4"]
[Tue Jul 21 08:18:51.564326 2026] [security2:error] [pid 411857:tid 412013] [client 81.171.72.135:39740] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9Vmy7ynBpLeKYztQPGSgAAABg"]
[Tue Jul 21 08:18:51.564621 2026] [security2:error] [pid 411857:tid 412090] [client 81.171.72.135:39742] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/secrets.json"] [unique_id "al9Vmy7ynBpLeKYztQPGTAAAAGU"]
[Tue Jul 21 08:18:51.564689 2026] [security2:error] [pid 411857:tid 411995] [client 81.171.72.135:39710] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/.npmrc"] [unique_id "al9Vmy7ynBpLeKYztQPGTQAAAAY"]
[Tue Jul 21 08:18:51.626607 2026] [security2:error] [pid 411857:tid 412041] [client 81.171.72.93:44996] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/database_backup.sql"] [unique_id "al9Vmy7ynBpLeKYztQPGUgAAADQ"]
[Tue Jul 21 08:18:51.628521 2026] [security2:error] [pid 411857:tid 412076] [client 81.171.72.93:44976] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/api/.env"] [unique_id "al9Vmy7ynBpLeKYztQPGUwAAAFc"]
[Tue Jul 21 08:18:51.628521 2026] [security2:error] [pid 411857:tid 412037] [client 81.171.72.93:45038] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/backup.zip"] [unique_id "al9Vmy7ynBpLeKYztQPGVAAAADA"]
[Tue Jul 21 08:18:51.641329 2026] [security2:error] [pid 411857:tid 412077] [client 81.171.72.135:39684] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/api/.env"] [unique_id "al9Vmy7ynBpLeKYztQPGVQAAAFg"]
[Tue Jul 21 08:18:51.643772 2026] [security2:error] [pid 411857:tid 412080] [client 81.171.72.135:39698] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/phpinfo.php"] [unique_id "al9Vmy7ynBpLeKYztQPGVgAAAFs"]
[Tue Jul 21 08:18:51.645560 2026] [security2:error] [pid 411857:tid 411990] [client 81.171.72.135:39662] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/docker-compose.yml"] [unique_id "al9Vmy7ynBpLeKYztQPGVwAAAAE"]
[Tue Jul 21 08:18:51.667169 2026] [security2:error] [pid 411857:tid 412069] [client 20.226.60.151:51971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/for.php"] [unique_id "al9Vmy7ynBpLeKYztQPGWAAAAFA"]
[Tue Jul 21 08:18:51.715609 2026] [security2:error] [pid 411857:tid 412048] [client 81.171.74.60:49974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/backup.zip"] [unique_id "al9Vmy7ynBpLeKYztQPGWwAAADs"]
[Tue Jul 21 08:18:51.766360 2026] [security2:error] [pid 411857:tid 411999] [client 81.171.72.135:39760] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/docker-compose.yml"] [unique_id "al9Vmy7ynBpLeKYztQPGYgAAAAo"]
[Tue Jul 21 08:18:51.766501 2026] [security2:error] [pid 411857:tid 412047] [client 81.171.72.135:39724] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/.bash_history"] [unique_id "al9Vmy7ynBpLeKYztQPGYQAAADo"]
[Tue Jul 21 08:18:51.766777 2026] [security2:error] [pid 411857:tid 412071] [client 81.171.72.135:39726] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/user_secrets.yml"] [unique_id "al9Vmy7ynBpLeKYztQPGYwAAAFI"]
[Tue Jul 21 08:18:51.783270 2026] [security2:error] [pid 411857:tid 412084] [client 81.171.74.60:50000] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/backup.sql"] [unique_id "al9Vmy7ynBpLeKYztQPGZAAAAF8"]
[Tue Jul 21 08:18:51.784595 2026] [security2:error] [pid 411857:tid 412116] [client 81.171.74.60:50018] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/config.php"] [unique_id "al9Vmy7ynBpLeKYztQPGZQAAAH8"]
[Tue Jul 21 08:18:51.785300 2026] [security2:error] [pid 411857:tid 412097] [client 81.171.74.60:50004] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/config.xml"] [unique_id "al9Vmy7ynBpLeKYztQPGZgAAAGw"]
[Tue Jul 21 08:18:51.786794 2026] [security2:error] [pid 411857:tid 412021] [client 81.171.74.60:49998] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/dump.sql"] [unique_id "al9Vmy7ynBpLeKYztQPGZwAAACA"]
[Tue Jul 21 08:18:52.019702 2026] [security2:error] [pid 411857:tid 412034] [client 103.78.200.11:50161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VnC7ynBpLeKYztQPGcQAAAC0"]
[Tue Jul 21 08:18:52.019832 2026] [security2:error] [pid 411857:tid 412034] [client 103.78.200.11:50161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VnC7ynBpLeKYztQPGcQAAAC0"]
[Tue Jul 21 08:18:52.071548 2026] [security2:error] [pid 411857:tid 412106] [client 81.171.72.93:45062] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9VnC7ynBpLeKYztQPGcgAAAHU"]
[Tue Jul 21 08:18:52.072864 2026] [security2:error] [pid 411857:tid 412065] [client 81.171.72.93:45072] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/.svn/wc.db"] [unique_id "al9VnC7ynBpLeKYztQPGdAAAAEw"]
[Tue Jul 21 08:18:52.072933 2026] [security2:error] [pid 411857:tid 412083] [client 81.171.72.93:45046] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/backup.tar.gz"] [unique_id "al9VnC7ynBpLeKYztQPGcwAAAF4"]
[Tue Jul 21 08:18:52.075413 2026] [security2:error] [pid 411857:tid 412079] [client 81.171.72.135:39778] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9VnC7ynBpLeKYztQPGdQAAAFo"]
[Tue Jul 21 08:18:52.126240 2026] [security2:error] [pid 411857:tid 412077] [client 20.226.60.151:60297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "advcelsopinto.com.br"] [uri "/raw.php"] [unique_id "al9VnC7ynBpLeKYztQPGdwAAAFg"]
[Tue Jul 21 08:18:52.187159 2026] [security2:error] [pid 411857:tid 411995] [client 81.171.72.135:39782] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/backup.sql"] [unique_id "al9VnC7ynBpLeKYztQPGewAAAAY"]
[Tue Jul 21 08:18:52.195289 2026] [security2:error] [pid 411857:tid 412069] [client 20.206.105.145:25525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/c.php"] [unique_id "al9VnC7ynBpLeKYztQPGfQAAAFA"]
[Tue Jul 21 08:18:52.203784 2026] [security2:error] [pid 411857:tid 412045] [client 81.171.72.93:45014] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/actuator/heapdump"] [unique_id "al9VnC7ynBpLeKYztQPGfgAAADg"]
[Tue Jul 21 08:18:52.217152 2026] [security2:error] [pid 411857:tid 412109] [client 74.249.245.134:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/new.php"] [unique_id "al9VnC7ynBpLeKYztQPGfwAAAHg"]
[Tue Jul 21 08:18:52.244363 2026] [security2:error] [pid 411857:tid 412032] [client 62.102.148.158:59134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9VnC7ynBpLeKYztQPGggAAACs"]
[Tue Jul 21 08:18:52.244476 2026] [security2:error] [pid 411857:tid 412032] [client 62.102.148.158:59134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9VnC7ynBpLeKYztQPGggAAACs"]
[Tue Jul 21 08:18:52.265392 2026] [security2:error] [pid 411857:tid 412064] [client 81.171.72.135:39786] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/.env.production"] [unique_id "al9VnC7ynBpLeKYztQPGgwAAAEs"]
[Tue Jul 21 08:18:52.266954 2026] [security2:error] [pid 411857:tid 412037] [client 81.171.72.135:39788] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/server.key"] [unique_id "al9VnC7ynBpLeKYztQPGhAAAADA"]
[Tue Jul 21 08:18:52.269528 2026] [security2:error] [pid 411857:tid 412043] [client 81.171.72.135:39798] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/user_secrets.yml"] [unique_id "al9VnC7ynBpLeKYztQPGhQAAADY"]
[Tue Jul 21 08:18:52.273268 2026] [security2:error] [pid 411857:tid 412114] [client 81.171.72.93:45096] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9VnC7ynBpLeKYztQPGhgAAAH0"]
[Tue Jul 21 08:18:52.274683 2026] [security2:error] [pid 411857:tid 412068] [client 81.171.72.93:45086] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9VnC7ynBpLeKYztQPGhwAAAE8"]
[Tue Jul 21 08:18:52.277455 2026] [security2:error] [pid 411857:tid 412049] [client 81.171.72.135:39832] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/config/production.json"] [unique_id "al9VnC7ynBpLeKYztQPGiAAAADw"]
[Tue Jul 21 08:18:52.402269 2026] [security2:error] [pid 411857:tid 412052] [client 81.171.72.135:39888] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/dump.sql"] [unique_id "al9VnC7ynBpLeKYztQPGjgAAAD8"]
[Tue Jul 21 08:18:52.403248 2026] [security2:error] [pid 411857:tid 412048] [client 81.171.72.135:39846] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/config.xml"] [unique_id "al9VnC7ynBpLeKYztQPGjwAAADs"]
[Tue Jul 21 08:18:52.404281 2026] [security2:error] [pid 411857:tid 412060] [client 81.171.72.135:39856] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/config.php"] [unique_id "al9VnC7ynBpLeKYztQPGkAAAAEc"]
[Tue Jul 21 08:18:52.404451 2026] [security2:error] [pid 411857:tid 412074] [client 81.171.72.135:39900] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9VnC7ynBpLeKYztQPGkQAAAFU"]
[Tue Jul 21 08:18:52.420521 2026] [security2:error] [pid 411857:tid 411886] [remote 115.98.214.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.214.98.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VnC7ynBpLeKYztQPGkwAARRs"]
[Tue Jul 21 08:18:52.420825 2026] [security2:error] [pid 411857:tid 412058] [client 115.98.214.230:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "granicap.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VnC7ynBpLeKYztQPGkwAARRs"]
[Tue Jul 21 08:18:52.467198 2026] [security2:error] [pid 411857:tid 412110] [client 81.171.72.135:39834] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9VnC7ynBpLeKYztQPGlwAAAHk"]
[Tue Jul 21 08:18:52.468367 2026] [security2:error] [pid 411857:tid 412076] [client 81.171.72.135:39818] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/secrets.json"] [unique_id "al9VnC7ynBpLeKYztQPGmAAAAFc"]
[Tue Jul 21 08:18:52.692543 2026] [security2:error] [pid 411857:tid 412078] [client 81.171.72.93:45108] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/config.php"] [unique_id "al9VnC7ynBpLeKYztQPGnAAAAFk"]
[Tue Jul 21 08:18:52.737945 2026] [security2:error] [pid 411857:tid 412095] [client 81.171.74.60:49976] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/actuator/heapdump"] [unique_id "al9VnC7ynBpLeKYztQPGnQAAAGo"]
[Tue Jul 21 08:18:52.739462 2026] [security2:error] [pid 411857:tid 412008] [client 81.171.74.60:49990] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/dump.sql"] [unique_id "al9VnC7ynBpLeKYztQPGngAAABM"]
[Tue Jul 21 08:18:52.741207 2026] [security2:error] [pid 411857:tid 412088] [client 81.171.74.60:49960] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/.svn/wc.db"] [unique_id "al9VnC7ynBpLeKYztQPGoAAAAGM"]
[Tue Jul 21 08:18:52.741227 2026] [security2:error] [pid 411857:tid 412029] [client 81.171.74.60:49994] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/backup.tar.gz"] [unique_id "al9VnC7ynBpLeKYztQPGnwAAACg"]
[Tue Jul 21 08:18:52.757803 2026] [security2:error] [pid 411857:tid 412016] [client 20.226.60.151:64039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/pucci.php"] [unique_id "al9VnC7ynBpLeKYztQPGoQAAABs"]
[Tue Jul 21 08:18:52.826307 2026] [security2:error] [pid 411857:tid 412006] [client 81.171.72.93:45116] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/.git/HEAD"] [unique_id "al9VnC7ynBpLeKYztQPGpQAAABE"]
[Tue Jul 21 08:18:52.828932 2026] [security2:error] [pid 411857:tid 412053] [client 81.171.72.93:45126] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/.env"] [unique_id "al9VnC7ynBpLeKYztQPGpgAAAEA"]
[Tue Jul 21 08:18:52.867607 2026] [security2:error] [pid 411857:tid 412070] [client 87.116.180.198:27268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VnC7ynBpLeKYztQPGqAAAAFE"]
[Tue Jul 21 08:18:52.870318 2026] [security2:error] [pid 411857:tid 412070] [client 87.116.180.198:27268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VnC7ynBpLeKYztQPGqAAAAFE"]
[Tue Jul 21 08:18:52.916683 2026] [security2:error] [pid 411857:tid 412112] [client 81.171.72.93:45128] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/server.key"] [unique_id "al9VnC7ynBpLeKYztQPGrAAAAHs"]
[Tue Jul 21 08:18:52.920470 2026] [security2:error] [pid 411857:tid 412089] [client 81.171.72.93:45134] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/database_backup.sql"] [unique_id "al9VnC7ynBpLeKYztQPGrQAAAGQ"]
[Tue Jul 21 08:18:52.920894 2026] [security2:error] [pid 411857:tid 412024] [client 81.171.72.135:39940] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/.bash_history"] [unique_id "al9VnC7ynBpLeKYztQPGrwAAACM"]
[Tue Jul 21 08:18:52.920901 2026] [security2:error] [pid 411857:tid 411995] [client 81.171.72.135:39924] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/actuator/heapdump"] [unique_id "al9VnC7ynBpLeKYztQPGrgAAAAY"]
[Tue Jul 21 08:18:52.920913 2026] [security2:error] [pid 411857:tid 412069] [client 81.171.72.135:39922] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/.npmrc"] [unique_id "al9VnC7ynBpLeKYztQPGsAAAAFA"]
[Tue Jul 21 08:18:52.921782 2026] [security2:error] [pid 411857:tid 412109] [client 81.171.74.60:50064] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/database.sql"] [unique_id "al9VnC7ynBpLeKYztQPGsQAAAHg"]
[Tue Jul 21 08:18:52.923386 2026] [security2:error] [pid 411857:tid 412004] [client 81.171.74.60:50042] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/database_backup.sql"] [unique_id "al9VnC7ynBpLeKYztQPGtAAAAA8"]
[Tue Jul 21 08:18:52.923720 2026] [security2:error] [pid 411857:tid 412045] [client 81.171.74.60:50054] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/storage/logs/laravel.log"] [unique_id "al9VnC7ynBpLeKYztQPGtQAAADg"]
[Tue Jul 21 08:18:52.923974 2026] [security2:error] [pid 411857:tid 412111] [client 81.171.74.60:50030] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/wp-config.php"] [unique_id "al9VnC7ynBpLeKYztQPGtgAAAHo"]
[Tue Jul 21 08:18:53.029983 2026] [security2:error] [pid 411857:tid 411990] [client 81.171.72.93:45140] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/secrets.json"] [unique_id "al9VnS7ynBpLeKYztQPGvQAAAAE"]
[Tue Jul 21 08:18:53.031092 2026] [security2:error] [pid 411857:tid 412049] [client 81.171.72.135:39988] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9VnS7ynBpLeKYztQPGvgAAADw"]
[Tue Jul 21 08:18:53.031221 2026] [security2:error] [pid 411857:tid 411997] [client 81.171.72.135:40004] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/wp-config.php"] [unique_id "al9VnS7ynBpLeKYztQPGvwAAAAg"]
[Tue Jul 21 08:18:53.032128 2026] [security2:error] [pid 411857:tid 412113] [client 81.171.72.135:40002] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/database.sql"] [unique_id "al9VnS7ynBpLeKYztQPGwQAAAHw"]
[Tue Jul 21 08:18:53.032270 2026] [security2:error] [pid 411857:tid 411996] [client 81.171.72.135:39972] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/database_backup.sql"] [unique_id "al9VnS7ynBpLeKYztQPGwAAAAAc"]
[Tue Jul 21 08:18:53.100333 2026] [security2:error] [pid 411857:tid 412075] [client 20.151.10.161:46013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9VnS7ynBpLeKYztQPGwgAAAFY"]
[Tue Jul 21 08:18:53.106149 2026] [security2:error] [pid 411857:tid 412115] [client 81.171.72.135:45230] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/wp-config.php"] [unique_id "al9VnS7ynBpLeKYztQPGxAAAAH4"]
[Tue Jul 21 08:18:53.113351 2026] [security2:error] [pid 411857:tid 412073] [client 117.213.202.34:51123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VnS7ynBpLeKYztQPGxQAAAFQ"]
[Tue Jul 21 08:18:53.113497 2026] [security2:error] [pid 411857:tid 412073] [client 117.213.202.34:51123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VnS7ynBpLeKYztQPGxQAAAFQ"]
[Tue Jul 21 08:18:53.123690 2026] [security2:error] [pid 411857:tid 412037] [client 81.171.74.60:50032] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/backup.zip"] [unique_id "al9VnS7ynBpLeKYztQPGyAAAADA"]
[Tue Jul 21 08:18:53.124696 2026] [security2:error] [pid 411857:tid 412064] [client 81.171.74.60:50044] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/actuator/heapdump"] [unique_id "al9VnS7ynBpLeKYztQPGyQAAAEs"]
[Tue Jul 21 08:18:53.125608 2026] [security2:error] [pid 411857:tid 412097] [client 81.171.72.135:45226] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/backup.zip"] [unique_id "al9VnS7ynBpLeKYztQPGygAAAGw"]
[Tue Jul 21 08:18:53.126411 2026] [security2:error] [pid 411857:tid 412032] [client 81.171.74.60:50028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/.svn/wc.db"] [unique_id "al9VnS7ynBpLeKYztQPGywAAACs"]
[Tue Jul 21 08:18:53.130808 2026] [security2:error] [pid 411857:tid 411894] [remote 167.71.218.184:54280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "santotchay.com"] [uri "/wp-login.php"] [unique_id "al9VnS7ynBpLeKYztQPGzAAALCM"]
[Tue Jul 21 08:18:53.235269 2026] [security2:error] [pid 411857:tid 412007] [client 81.171.72.135:39956] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/backup.tar.gz"] [unique_id "al9VnS7ynBpLeKYztQPG0QAAABI"]
[Tue Jul 21 08:18:53.236957 2026] [security2:error] [pid 411857:tid 411991] [client 81.171.72.135:39990] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9VnS7ynBpLeKYztQPG0gAAAAI"]
[Tue Jul 21 08:18:53.239626 2026] [security2:error] [pid 411857:tid 412009] [client 81.171.72.135:39970] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/.env.production"] [unique_id "al9VnS7ynBpLeKYztQPG0wAAABQ"]
[Tue Jul 21 08:18:53.308279 2026] [security2:error] [pid 411857:tid 411995] [client 20.226.60.151:49222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/core.php"] [unique_id "al9VnS7ynBpLeKYztQPG1gAAAAY"]
[Tue Jul 21 08:18:53.449061 2026] [security2:error] [pid 411857:tid 412116] [client 81.171.72.93:50748] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/docker-compose.yml"] [unique_id "al9VnS7ynBpLeKYztQPG2gAAAH8"]
[Tue Jul 21 08:18:53.498775 2026] [security2:error] [pid 411857:tid 412097] [client 86.106.84.166:57044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9VnS7ynBpLeKYztQPG3gAAAGw"]
[Tue Jul 21 08:18:53.498909 2026] [security2:error] [pid 411857:tid 412097] [client 86.106.84.166:57044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9VnS7ynBpLeKYztQPG3gAAAGw"]
[Tue Jul 21 08:18:53.509452 2026] [security2:error] [pid 411857:tid 412041] [client 74.249.245.134:47090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/class-t.api.php"] [unique_id "al9VnS7ynBpLeKYztQPG4AAAADQ"]
[Tue Jul 21 08:18:53.552263 2026] [security2:error] [pid 411857:tid 412071] [client 81.171.72.135:45246] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/config.php"] [unique_id "al9VnS7ynBpLeKYztQPG5AAAAFI"]
[Tue Jul 21 08:18:53.553386 2026] [security2:error] [pid 411857:tid 412027] [client 81.171.72.135:45248] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/backup.sql"] [unique_id "al9VnS7ynBpLeKYztQPG5QAAACY"]
[Tue Jul 21 08:18:53.564515 2026] [security2:error] [pid 411857:tid 412047] [client 81.171.72.93:50780] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/phpinfo.php"] [unique_id "al9VnS7ynBpLeKYztQPG5gAAADo"]
[Tue Jul 21 08:18:53.665836 2026] [security2:error] [pid 411857:tid 411994] [client 81.171.72.135:45266] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9VnS7ynBpLeKYztQPG7wAAAAU"]
[Tue Jul 21 08:18:53.673968 2026] [security2:error] [pid 411857:tid 412034] [client 81.171.72.93:50788] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/config/production.json"] [unique_id "al9VnS7ynBpLeKYztQPG8AAAAC0"]
[Tue Jul 21 08:18:53.676451 2026] [security2:error] [pid 411857:tid 412106] [client 81.171.72.93:50790] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9VnS7ynBpLeKYztQPG8QAAAHU"]
[Tue Jul 21 08:18:53.740646 2026] [security2:error] [pid 411857:tid 412008] [client 81.171.72.135:45280] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/.svn/wc.db"] [unique_id "al9VnS7ynBpLeKYztQPG9gAAABM"]
[Tue Jul 21 08:18:53.740794 2026] [security2:error] [pid 411857:tid 412022] [client 81.171.72.135:45306] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/dump.sql"] [unique_id "al9VnS7ynBpLeKYztQPG9QAAACE"]
[Tue Jul 21 08:18:53.741919 2026] [security2:error] [pid 411857:tid 412021] [client 20.206.105.145:25588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/aa.php"] [unique_id "al9VnS7ynBpLeKYztQPG9wAAACA"]
[Tue Jul 21 08:18:53.755937 2026] [security2:error] [pid 411857:tid 412088] [client 81.171.72.135:45278] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/database.sql"] [unique_id "al9VnS7ynBpLeKYztQPG-AAAAGM"]
[Tue Jul 21 08:18:53.758950 2026] [security2:error] [pid 411857:tid 412080] [client 81.171.72.135:45270] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9VnS7ynBpLeKYztQPG-gAAAFs"]
[Tue Jul 21 08:18:53.770416 2026] [security2:error] [pid 411857:tid 412012] [client 20.220.225.223:24192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "realizzaresolucoes.com.br"] [uri "/phpinfo.php1"] [unique_id "al9VnS7ynBpLeKYztQPG-wAAABc"]
[Tue Jul 21 08:18:53.850780 2026] [security2:error] [pid 411857:tid 412064] [client 14.245.224.124:50582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VnS7ynBpLeKYztQPG_gAAAEs"]
[Tue Jul 21 08:18:53.850945 2026] [security2:error] [pid 411857:tid 412064] [client 14.245.224.124:50582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VnS7ynBpLeKYztQPG_gAAAEs"]
[Tue Jul 21 08:18:53.865632 2026] [security2:error] [pid 411857:tid 412009] [client 81.171.72.135:45374] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9VnS7ynBpLeKYztQPG_wAAABQ"]
[Tue Jul 21 08:18:53.870521 2026] [security2:error] [pid 411857:tid 412020] [client 81.171.72.135:45334] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/actuator/heapdump"] [unique_id "al9VnS7ynBpLeKYztQPHAAAAAB8"]
[Tue Jul 21 08:18:53.871799 2026] [security2:error] [pid 411857:tid 412042] [client 81.171.72.135:45322] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9VnS7ynBpLeKYztQPHAQAAADU"]
[Tue Jul 21 08:18:53.872023 2026] [security2:error] [pid 411857:tid 412025] [client 81.171.72.135:45356] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/backup.zip"] [unique_id "al9VnS7ynBpLeKYztQPHAgAAACQ"]
[Tue Jul 21 08:18:53.886007 2026] [security2:error] [pid 411857:tid 412069] [client 81.171.74.60:33494] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/backup.tar.gz"] [unique_id "al9VnS7ynBpLeKYztQPHAwAAAFA"]
[Tue Jul 21 08:18:53.886186 2026] [security2:error] [pid 411857:tid 412109] [client 81.171.74.60:33508] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/.ssh/id_ecdsa"] [unique_id "al9VnS7ynBpLeKYztQPHBAAAAHg"]
[Tue Jul 21 08:18:53.886853 2026] [security2:error] [pid 411857:tid 412024] [client 81.171.74.60:33528] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/.ssh/id_ed25519"] [unique_id "al9VnS7ynBpLeKYztQPHBQAAACM"]
[Tue Jul 21 08:18:53.888216 2026] [security2:error] [pid 411857:tid 412045] [client 81.171.74.60:33478] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/.ssh/id_rsa"] [unique_id "al9VnS7ynBpLeKYztQPHBgAAADg"]
[Tue Jul 21 08:18:54.041429 2026] [security2:error] [pid 411857:tid 412011] [client 103.106.20.201:50597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vni7ynBpLeKYztQPHDwAAABY"]
[Tue Jul 21 08:18:54.041584 2026] [security2:error] [pid 411857:tid 412011] [client 103.106.20.201:50597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vni7ynBpLeKYztQPHDwAAABY"]
[Tue Jul 21 08:18:54.070267 2026] [security2:error] [pid 411857:tid 412112] [client 81.171.72.135:45360] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/.env"] [unique_id "al9Vni7ynBpLeKYztQPHEAAAAHs"]
[Tue Jul 21 08:18:54.074622 2026] [security2:error] [pid 411857:tid 412029] [client 81.171.72.135:45340] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/.git/HEAD"] [unique_id "al9Vni7ynBpLeKYztQPHEQAAACg"]
[Tue Jul 21 08:18:54.092634 2026] [security2:error] [pid 411857:tid 412111] [client 81.171.74.60:33524] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/wp-admin/setup-config.php"] [unique_id "al9Vni7ynBpLeKYztQPHEgAAAHo"]
[Tue Jul 21 08:18:54.192388 2026] [security2:error] [pid 411857:tid 411996] [client 81.171.72.93:50808] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/dump.sql"] [unique_id "al9Vni7ynBpLeKYztQPHEwAAAAc"]
[Tue Jul 21 08:18:54.195647 2026] [security2:error] [pid 411857:tid 412035] [client 81.171.72.93:50824] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/.env.production"] [unique_id "al9Vni7ynBpLeKYztQPHFAAAAC4"]
[Tue Jul 21 08:18:54.306799 2026] [security2:error] [pid 411857:tid 412095] [client 81.171.72.93:50842] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/.npmrc"] [unique_id "al9Vni7ynBpLeKYztQPHGQAAAGo"]
[Tue Jul 21 08:18:54.308082 2026] [security2:error] [pid 411857:tid 412030] [client 81.171.72.93:50828] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/user_secrets.yml"] [unique_id "al9Vni7ynBpLeKYztQPHGgAAACk"]
[Tue Jul 21 08:18:54.311832 2026] [security2:error] [pid 411857:tid 412022] [client 20.226.60.151:60632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/ops.php"] [unique_id "al9Vni7ynBpLeKYztQPHGwAAACE"]
[Tue Jul 21 08:18:54.394766 2026] [security2:error] [pid 411857:tid 412027] [client 81.171.72.93:50844] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9Vni7ynBpLeKYztQPHHgAAACY"]
[Tue Jul 21 08:18:54.399031 2026] [security2:error] [pid 411857:tid 412071] [client 81.171.72.93:50854] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.dmkimoveis.com.br"] [uri "/.bash_history"] [unique_id "al9Vni7ynBpLeKYztQPHHwAAAFI"]
[Tue Jul 21 08:18:54.477035 2026] [security2:error] [pid 411857:tid 412036] [client 20.206.105.145:25511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/100.php"] [unique_id "al9Vni7ynBpLeKYztQPHJwAAAC8"]
[Tue Jul 21 08:18:54.498637 2026] [security2:error] [pid 411857:tid 412001] [client 81.171.72.135:45398] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.dmkimoveis.com.br"] [uri "/api/.env"] [unique_id "al9Vni7ynBpLeKYztQPHKAAAAAw"]
[Tue Jul 21 08:18:54.625128 2026] [security2:error] [pid 411857:tid 412101] [client 81.171.72.135:45428] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/backup.tar.gz"] [unique_id "al9Vni7ynBpLeKYztQPHTgAAAHA"]
[Tue Jul 21 08:18:54.626827 2026] [security2:error] [pid 411857:tid 411993] [client 81.171.72.135:45422] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.dmkimoveis.com.br"] [uri "/config.xml"] [unique_id "al9Vni7ynBpLeKYztQPHTwAAAAQ"]
[Tue Jul 21 08:18:54.673497 2026] [core:error] [pid 411857:tid 412075] [client 66.249.66.195:60509] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:18:54.673519 2026] [core:error] [pid 411857:tid 412075] [client 66.249.66.195:60509] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:18:54.673754 2026] [security2:error] [pid 411857:tid 412107] [client 20.197.192.193:3380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/bscclapb.php"] [unique_id "al9Vni7ynBpLeKYztQPHUgAAAHY"]
[Tue Jul 21 08:18:54.841158 2026] [security2:error] [pid 411857:tid 412095] [client 74.249.245.134:55823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/plugins.php"] [unique_id "al9Vni7ynBpLeKYztQPHdQAAAGo"]
[Tue Jul 21 08:18:55.010606 2026] [security2:error] [pid 411857:tid 411938] [remote 46.105.28.235:40602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nocaminhodafe.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vny7ynBpLeKYztQPHhQAAOk8"]
[Tue Jul 21 08:18:55.010783 2026] [security2:error] [pid 411857:tid 412047] [client 46.105.28.235:40602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nocaminhodafe.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vny7ynBpLeKYztQPHhQAAOk8"]
[Tue Jul 21 08:18:55.022889 2026] [security2:error] [pid 411857:tid 412086] [client 81.171.74.60:33566] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/.env"] [unique_id "al9Vny7ynBpLeKYztQPHiAAAAGE"]
[Tue Jul 21 08:18:55.023193 2026] [security2:error] [pid 411857:tid 412053] [client 81.171.74.60:33550] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/.git/HEAD"] [unique_id "al9Vny7ynBpLeKYztQPHigAAAEA"]
[Tue Jul 21 08:18:55.024794 2026] [security2:error] [pid 411857:tid 411991] [client 81.171.74.60:33588] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/api/.env"] [unique_id "al9Vny7ynBpLeKYztQPHiwAAAAI"]
[Tue Jul 21 08:18:55.024946 2026] [security2:error] [pid 411857:tid 411994] [client 81.171.74.60:33612] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9Vny7ynBpLeKYztQPHjAAAAAU"]
[Tue Jul 21 08:18:55.140623 2026] [security2:error] [pid 411857:tid 412109] [client 20.151.10.161:46030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/edit.php"] [unique_id "al9Vny7ynBpLeKYztQPHkwAAAHg"]
[Tue Jul 21 08:18:55.169367 2026] [security2:error] [pid 411857:tid 411899] [remote 38.242.157.30:46800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pomotionjustforyou.com"] [uri "/wp-login.php"] [unique_id "al9Vny7ynBpLeKYztQPHlgAARSg"]
[Tue Jul 21 08:18:55.226928 2026] [security2:error] [pid 411857:tid 412014] [client 81.171.74.60:33602] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/docker-compose.yml"] [unique_id "al9Vny7ynBpLeKYztQPHmgAAABk"]
[Tue Jul 21 08:18:55.226928 2026] [security2:error] [pid 411857:tid 412092] [client 81.171.74.60:33564] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/phpinfo.php"] [unique_id "al9Vny7ynBpLeKYztQPHmQAAAGc"]
[Tue Jul 21 08:18:55.229092 2026] [security2:error] [pid 411857:tid 412038] [client 81.171.74.60:33618] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/user_secrets.yml"] [unique_id "al9Vny7ynBpLeKYztQPHmwAAADE"]
[Tue Jul 21 08:18:55.498147 2026] [security2:error] [pid 411857:tid 412057] [client 74.249.245.134:58921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/jp.php"] [unique_id "al9Vny7ynBpLeKYztQPHygAAAEQ"]
[Tue Jul 21 08:18:55.522238 2026] [security2:error] [pid 411857:tid 412068] [client 150.129.202.39:65314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vny7ynBpLeKYztQPHywAAAE8"]
[Tue Jul 21 08:18:55.522394 2026] [security2:error] [pid 411857:tid 412068] [client 150.129.202.39:65314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vny7ynBpLeKYztQPHywAAAE8"]
[Tue Jul 21 08:18:55.522789 2026] [security2:error] [pid 411857:tid 412027] [client 20.226.60.151:48847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/als.php"] [unique_id "al9Vny7ynBpLeKYztQPHzAAAACY"]
[Tue Jul 21 08:18:55.633274 2026] [security2:error] [pid 411857:tid 412086] [client 20.226.60.151:64124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/black.php"] [unique_id "al9Vny7ynBpLeKYztQPH0wAAAGE"]
[Tue Jul 21 08:18:56.070613 2026] [security2:error] [pid 411857:tid 412004] [client 103.255.105.130:47845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VoC7ynBpLeKYztQPH5gAAAA8"]
[Tue Jul 21 08:18:56.070734 2026] [security2:error] [pid 411857:tid 412004] [client 103.255.105.130:47845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VoC7ynBpLeKYztQPH5gAAAA8"]
[Tue Jul 21 08:18:56.113656 2026] [security2:error] [pid 411857:tid 412083] [client 20.206.105.145:25097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/footer.php"] [unique_id "al9VoC7ynBpLeKYztQPH6wAAAF4"]
[Tue Jul 21 08:18:56.153028 2026] [security2:error] [pid 411857:tid 412038] [client 81.171.74.60:33664] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/config/production.json"] [unique_id "al9VoC7ynBpLeKYztQPH7QAAADE"]
[Tue Jul 21 08:18:56.153054 2026] [security2:error] [pid 411857:tid 412076] [client 81.171.74.60:33690] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/.env.production"] [unique_id "al9VoC7ynBpLeKYztQPH7gAAAFc"]
[Tue Jul 21 08:18:56.155285 2026] [security2:error] [pid 411857:tid 412010] [client 81.171.74.60:33666] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/.vscode/sftp.json"] [unique_id "al9VoC7ynBpLeKYztQPH8AAAABU"]
[Tue Jul 21 08:18:56.155531 2026] [security2:error] [pid 411857:tid 412081] [client 81.171.74.60:33678] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/etc/ssl/private/server.key"] [unique_id "al9VoC7ynBpLeKYztQPH7wAAAFw"]
[Tue Jul 21 08:18:56.334613 2026] [security2:error] [pid 411857:tid 412020] [client 117.210.135.0:51817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VoC7ynBpLeKYztQPH9QAAAB8"]
[Tue Jul 21 08:18:56.334764 2026] [security2:error] [pid 411857:tid 412020] [client 117.210.135.0:51817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VoC7ynBpLeKYztQPH9QAAAB8"]
[Tue Jul 21 08:18:56.354497 2026] [security2:error] [pid 411857:tid 412114] [client 81.171.74.60:33650] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/server.key"] [unique_id "al9VoC7ynBpLeKYztQPH9gAAAH0"]
[Tue Jul 21 08:18:56.354824 2026] [security2:error] [pid 411857:tid 412066] [client 81.171.74.60:33634] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/secrets.json"] [unique_id "al9VoC7ynBpLeKYztQPH9wAAAE0"]
[Tue Jul 21 08:18:56.356651 2026] [security2:error] [pid 411857:tid 412101] [client 81.171.74.60:33646] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/.npmrc"] [unique_id "al9VoC7ynBpLeKYztQPH-AAAAHA"]
[Tue Jul 21 08:18:56.660304 2026] [security2:error] [pid 411857:tid 412035] [client 20.226.60.151:64086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/zlece.php"] [unique_id "al9VoC7ynBpLeKYztQPIBAAAAC4"]
[Tue Jul 21 08:18:56.703734 2026] [security2:error] [pid 411857:tid 412068] [client 74.249.245.134:21428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/error.php"] [unique_id "al9VoC7ynBpLeKYztQPIBwAAAE8"]
[Tue Jul 21 08:18:56.766956 2026] [security2:error] [pid 411857:tid 411866] [remote 97.74.93.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9VoC7ynBpLeKYztQPICAAAWAc"], referer: http://assumaocontrole.com/
[Tue Jul 21 08:18:56.869523 2026] [security2:error] [pid 411857:tid 412061] [client 120.56.162.40:58423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VoC7ynBpLeKYztQPIDAAAAEg"]
[Tue Jul 21 08:18:56.869608 2026] [security2:error] [pid 411857:tid 412061] [client 120.56.162.40:58423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VoC7ynBpLeKYztQPIDAAAAEg"]
[Tue Jul 21 08:18:56.878139 2026] [security2:error] [pid 411857:tid 411892] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VoC7ynBpLeKYztQPIDQAAXCE"]
[Tue Jul 21 08:18:56.878320 2026] [security2:error] [pid 411857:tid 412081] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VoC7ynBpLeKYztQPIDQAAXCE"]
[Tue Jul 21 08:18:56.880966 2026] [security2:error] [pid 411857:tid 412036] [client 20.206.105.145:25518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/users.php"] [unique_id "al9VoC7ynBpLeKYztQPIDgAAAC8"]
[Tue Jul 21 08:18:56.899473 2026] [security2:error] [pid 411857:tid 412045] [client 20.226.60.151:60641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/mac.php"] [unique_id "al9VoC7ynBpLeKYztQPIEQAAADg"]
[Tue Jul 21 08:18:57.001655 2026] [security2:error] [pid 411857:tid 412088] [client 74.7.230.35:34464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pdvasimd.ongsolution.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9VoC7ynBpLeKYztQPIFgAAYy4"]
[Tue Jul 21 08:18:57.196500 2026] [security2:error] [pid 411857:tid 412020] [client 81.171.72.93:50914] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/phpinfo.php"] [unique_id "al9VoS7ynBpLeKYztQPIHAAAAB8"]
[Tue Jul 21 08:18:57.197754 2026] [security2:error] [pid 411857:tid 412115] [client 81.171.72.93:50868] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/docker-compose.yml"] [unique_id "al9VoS7ynBpLeKYztQPIHQAAAH4"]
[Tue Jul 21 08:18:57.198509 2026] [security2:error] [pid 411857:tid 412037] [client 81.171.72.93:50878] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/wp-config.php"] [unique_id "al9VoS7ynBpLeKYztQPIHgAAADA"]
[Tue Jul 21 08:18:57.199600 2026] [security2:error] [pid 411857:tid 412103] [client 81.171.72.93:50930] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/user_secrets.yml"] [unique_id "al9VoS7ynBpLeKYztQPIHwAAAHI"]
[Tue Jul 21 08:18:57.286903 2026] [security2:error] [pid 411857:tid 412094] [client 81.171.74.60:33720] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dmkimoveis.com.br.ciclododinheiro.com"] [uri "/.bash_history"] [unique_id "al9VoS7ynBpLeKYztQPIIwAAAGk"]
[Tue Jul 21 08:18:57.315618 2026] [security2:error] [pid 411857:tid 411962] [remote 198.244.168.140:37392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.conasss.com.br"] [uri "/robots.txt"] [unique_id "al9VoS7ynBpLeKYztQPIJAAAdmY"]
[Tue Jul 21 08:18:57.315836 2026] [security2:error] [pid 411857:tid 412107] [client 198.244.168.140:37392] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.conasss.com.br"] [uri "/robots.txt"] [unique_id "al9VoS7ynBpLeKYztQPIJAAAdmY"]
[Tue Jul 21 08:18:57.344626 2026] [security2:error] [pid 411857:tid 412062] [client 81.171.74.60:33768] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/server.key"] [unique_id "al9VoS7ynBpLeKYztQPIJQAAAEk"]
[Tue Jul 21 08:18:57.344892 2026] [security2:error] [pid 411857:tid 412047] [client 81.171.74.60:33738] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/api/.env"] [unique_id "al9VoS7ynBpLeKYztQPIJwAAADo"]
[Tue Jul 21 08:18:57.344894 2026] [security2:error] [pid 411857:tid 412083] [client 81.171.74.60:33754] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/config.php"] [unique_id "al9VoS7ynBpLeKYztQPIJgAAAF4"]
[Tue Jul 21 08:18:57.400225 2026] [security2:error] [pid 411857:tid 412099] [client 81.171.72.93:50900] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/backup.zip"] [unique_id "al9VoS7ynBpLeKYztQPIKwAAAG4"]
[Tue Jul 21 08:18:57.401135 2026] [security2:error] [pid 411857:tid 412063] [client 81.171.72.93:50928] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9VoS7ynBpLeKYztQPILQAAAEo"]
[Tue Jul 21 08:18:57.401251 2026] [security2:error] [pid 411857:tid 412014] [client 81.171.72.93:50886] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9VoS7ynBpLeKYztQPILAAAABk"]
[Tue Jul 21 08:18:57.518275 2026] [security2:error] [pid 411857:tid 412089] [client 20.226.60.151:49363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/simple.php"] [unique_id "al9VoS7ynBpLeKYztQPIMgAAAGQ"]
[Tue Jul 21 08:18:57.608501 2026] [security2:error] [pid 411857:tid 412024] [client 20.226.60.151:64078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/vssrs.php"] [unique_id "al9VoS7ynBpLeKYztQPINQAAACM"]
[Tue Jul 21 08:18:57.793255 2026] [security2:error] [pid 411857:tid 411986] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VoS7ynBpLeKYztQPIPwAAXH4"]
[Tue Jul 21 08:18:57.793259 2026] [security2:error] [pid 411857:tid 411914] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VoS7ynBpLeKYztQPIPgAAETc"]
[Tue Jul 21 08:18:57.793428 2026] [security2:error] [pid 411857:tid 412006] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VoS7ynBpLeKYztQPIPgAAETc"]
[Tue Jul 21 08:18:57.793428 2026] [security2:error] [pid 411857:tid 412081] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VoS7ynBpLeKYztQPIPwAAXH4"]
[Tue Jul 21 08:18:57.825677 2026] [security2:error] [pid 411857:tid 412061] [client 81.171.72.93:50946] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/server.key"] [unique_id "al9VoS7ynBpLeKYztQPIQQAAAEg"]
[Tue Jul 21 08:18:57.828884 2026] [security2:error] [pid 411857:tid 412067] [client 20.206.105.145:25103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/177.php"] [unique_id "al9VoS7ynBpLeKYztQPIQgAAAE4"]
[Tue Jul 21 08:18:57.978871 2026] [security2:error] [pid 411857:tid 411989] [client 81.171.74.60:33798] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9VoS7ynBpLeKYztQPISgAAAAA"]
[Tue Jul 21 08:18:57.986916 2026] [security2:error] [pid 411857:tid 412088] [client 81.171.74.60:33826] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/secrets.json"] [unique_id "al9VoS7ynBpLeKYztQPISwAAAGM"]
[Tue Jul 21 08:18:57.986989 2026] [security2:error] [pid 411857:tid 412000] [client 81.171.74.60:33788] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9VoS7ynBpLeKYztQPITAAAAAs"]
[Tue Jul 21 08:18:57.987342 2026] [security2:error] [pid 411857:tid 411993] [client 81.171.74.60:33810] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9VoS7ynBpLeKYztQPITQAAAAQ"]
[Tue Jul 21 08:18:58.049620 2026] [security2:error] [pid 411857:tid 412032] [client 81.171.72.93:50990] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/secrets.json"] [unique_id "al9Voi7ynBpLeKYztQPITgAAACs"]
[Tue Jul 21 08:18:58.052481 2026] [security2:error] [pid 411857:tid 412115] [client 81.171.72.93:50956] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/config/production.json"] [unique_id "al9Voi7ynBpLeKYztQPITwAAAH4"]
[Tue Jul 21 08:18:58.052805 2026] [security2:error] [pid 411857:tid 412020] [client 81.171.72.93:50968] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9Voi7ynBpLeKYztQPIUAAAAB8"]
[Tue Jul 21 08:18:58.053695 2026] [security2:error] [pid 411857:tid 412039] [client 81.171.72.93:50982] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/actuator/heapdump"] [unique_id "al9Voi7ynBpLeKYztQPIUQAAADI"]
[Tue Jul 21 08:18:58.109005 2026] [security2:error] [pid 411857:tid 412010] [client 20.226.60.151:49374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/init.php"] [unique_id "al9Voi7ynBpLeKYztQPIVwAAABU"]
[Tue Jul 21 08:18:58.139687 2026] [security2:error] [pid 411857:tid 411867] [remote 47.128.57.51:19964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.reserveseulugar.com.br"] [uri "/o-que-fazer-em-goiania-neste-final-de-semana-dias-09-10-e-11-de-maio-de-2025/"] [unique_id "al9Voi7ynBpLeKYztQPIXAAATwg"]
[Tue Jul 21 08:18:58.156414 2026] [security2:error] [pid 411857:tid 412107] [client 168.119.96.239:62940] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9Voi7ynBpLeKYztQPIXQAAAHY"], referer: https://artetoner.com.br
[Tue Jul 21 08:18:58.180743 2026] [security2:error] [pid 411857:tid 412004] [client 81.171.74.60:33780] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/config.xml"] [unique_id "al9Voi7ynBpLeKYztQPIXgAAAA8"]
[Tue Jul 21 08:18:58.190383 2026] [security2:error] [pid 411857:tid 412092] [client 81.171.74.60:33806] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/backup.sql"] [unique_id "al9Voi7ynBpLeKYztQPIYAAAAGc"]
[Tue Jul 21 08:18:58.217427 2026] [security2:error] [pid 411857:tid 412093] [client 20.151.10.161:46027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Voi7ynBpLeKYztQPIYgAAAGg"]
[Tue Jul 21 08:18:58.615849 2026] [security2:error] [pid 411857:tid 412097] [client 81.171.74.60:33838] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/.bash_history"] [unique_id "al9Voi7ynBpLeKYztQPIeAAAAGw"]
[Tue Jul 21 08:18:58.616918 2026] [security2:error] [pid 411857:tid 412114] [client 81.171.74.60:33830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/database_backup.sql"] [unique_id "al9Voi7ynBpLeKYztQPIeQAAAH0"]
[Tue Jul 21 08:18:58.620042 2026] [security2:error] [pid 411857:tid 412105] [client 81.171.74.60:33840] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/.env"] [unique_id "al9Voi7ynBpLeKYztQPIegAAAHQ"]
[Tue Jul 21 08:18:58.629805 2026] [security2:error] [pid 411857:tid 412014] [client 20.206.105.145:25126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/config.php"] [unique_id "al9Voi7ynBpLeKYztQPIewAAABk"]
[Tue Jul 21 08:18:58.660041 2026] [security2:error] [pid 411857:tid 412032] [client 20.226.60.151:48839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/fpwch.php"] [unique_id "al9Voi7ynBpLeKYztQPIfQAAACs"]
[Tue Jul 21 08:18:58.802714 2026] [security2:error] [pid 411857:tid 412095] [client 81.171.74.60:33898] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9Voi7ynBpLeKYztQPIhQAAAGo"]
[Tue Jul 21 08:18:58.810644 2026] [security2:error] [pid 411857:tid 412098] [client 74.249.245.134:42760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Voi7ynBpLeKYztQPIhgAAAG0"]
[Tue Jul 21 08:18:58.818078 2026] [security2:error] [pid 411857:tid 412063] [client 81.171.74.60:33874] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/.npmrc"] [unique_id "al9Voi7ynBpLeKYztQPIhwAAAEo"]
[Tue Jul 21 08:18:58.818325 2026] [security2:error] [pid 411857:tid 412099] [client 81.171.74.60:33856] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/.git/HEAD"] [unique_id "al9Voi7ynBpLeKYztQPIiAAAAG4"]
[Tue Jul 21 08:18:58.820951 2026] [security2:error] [pid 411857:tid 412082] [client 81.171.74.60:33872] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/phpinfo.php"] [unique_id "al9Voi7ynBpLeKYztQPIiQAAAF0"]
[Tue Jul 21 08:18:59.001602 2026] [security2:error] [pid 411857:tid 412057] [client 20.226.60.151:64087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wicked.php"] [unique_id "al9Voy7ynBpLeKYztQPIkwAAAEQ"]
[Tue Jul 21 08:18:59.175175 2026] [security2:error] [pid 411857:tid 412072] [client 20.226.60.151:49400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/domvf.php"] [unique_id "al9Voy7ynBpLeKYztQPImAAAAFM"]
[Tue Jul 21 08:18:59.232001 2026] [security2:error] [pid 411857:tid 412050] [client 20.206.105.145:25536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/gettest.php"] [unique_id "al9Voy7ynBpLeKYztQPInAAAAD0"]
[Tue Jul 21 08:18:59.298935 2026] [security2:error] [pid 411857:tid 412031] [client 20.151.10.161:45996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/f6.php"] [unique_id "al9Voy7ynBpLeKYztQPIoAAAACo"]
[Tue Jul 21 08:18:59.301352 2026] [security2:error] [pid 411857:tid 412054] [client 20.226.60.151:60581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/mg.php"] [unique_id "al9Voy7ynBpLeKYztQPIoQAAAEE"]
[Tue Jul 21 08:18:59.424711 2026] [security2:error] [pid 411857:tid 412013] [client 81.171.74.60:33912] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/docker-compose.yml"] [unique_id "al9Voy7ynBpLeKYztQPIpgAAABg"]
[Tue Jul 21 08:18:59.425011 2026] [security2:error] [pid 411857:tid 412064] [client 81.171.74.60:33918] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/database.sql"] [unique_id "al9Voy7ynBpLeKYztQPIpwAAAEs"]
[Tue Jul 21 08:18:59.425595 2026] [security2:error] [pid 411857:tid 412109] [client 81.171.74.60:33916] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9Voy7ynBpLeKYztQPIqQAAAHg"]
[Tue Jul 21 08:18:59.429552 2026] [security2:error] [pid 411857:tid 412028] [client 223.181.60.88:28620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Voy7ynBpLeKYztQPIrAAAACc"]
[Tue Jul 21 08:18:59.429645 2026] [security2:error] [pid 411857:tid 412028] [client 223.181.60.88:28620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Voy7ynBpLeKYztQPIrAAAACc"]
[Tue Jul 21 08:18:59.436403 2026] [security2:error] [pid 411857:tid 412079] [client 20.226.60.151:64109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/24.php"] [unique_id "al9Voy7ynBpLeKYztQPIrQAAAFo"]
[Tue Jul 21 08:18:59.446906 2026] [security2:error] [pid 411857:tid 412002] [client 74.7.244.13:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.areademembros.paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9Voi7ynBpLeKYztQPIaQAAAA0"]
[Tue Jul 21 08:18:59.447635 2026] [security2:error] [pid 411857:tid 412101] [client 74.7.244.13:51402] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.areademembros.paginadoproduto-oficial.com.br"] [uri "/robots.txt"] [unique_id "al9Voi7ynBpLeKYztQPIZwAAcEE"]
[Tue Jul 21 08:18:59.453584 2026] [security2:error] [pid 411857:tid 412094] [client 81.171.74.60:33948] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9Voy7ynBpLeKYztQPIrwAAAGk"]
[Tue Jul 21 08:18:59.583482 2026] [security2:error] [pid 411857:tid 412060] [client 20.226.60.151:48844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/wp.php"] [unique_id "al9Voy7ynBpLeKYztQPItgAAAEc"]
[Tue Jul 21 08:18:59.626771 2026] [security2:error] [pid 411857:tid 412083] [client 81.171.74.60:33952] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/config/production.json"] [unique_id "al9Voy7ynBpLeKYztQPIuwAAAF4"]
[Tue Jul 21 08:18:59.626802 2026] [security2:error] [pid 411857:tid 411876] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Voy7ynBpLeKYztQPIugAAdxE"]
[Tue Jul 21 08:18:59.626934 2026] [security2:error] [pid 411857:tid 412108] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Voy7ynBpLeKYztQPIugAAdxE"]
[Tue Jul 21 08:18:59.640776 2026] [security2:error] [pid 411857:tid 411931] [remote 54.39.136.45:63886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.conasss.com.br"] [uri "/inscricoes"] [unique_id "al9Voy7ynBpLeKYztQPIvgAAEUg"]
[Tue Jul 21 08:18:59.640931 2026] [security2:error] [pid 411857:tid 412006] [client 54.39.136.45:63886] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.conasss.com.br"] [uri "/inscricoes"] [unique_id "al9Voy7ynBpLeKYztQPIvgAAEUg"]
[Tue Jul 21 08:18:59.990187 2026] [security2:error] [pid 411857:tid 412097] [client 20.226.60.151:64029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/xacs.php"] [unique_id "al9Voy7ynBpLeKYztQPIygAAAGw"]
[Tue Jul 21 08:19:00.026383 2026] [security2:error] [pid 411857:tid 411996] [client 154.208.47.43:63711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VpC7ynBpLeKYztQPIzQAAAAc"]
[Tue Jul 21 08:19:00.026498 2026] [security2:error] [pid 411857:tid 411996] [client 154.208.47.43:63711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VpC7ynBpLeKYztQPIzQAAAAc"]
[Tue Jul 21 08:19:00.048832 2026] [security2:error] [pid 411857:tid 412038] [client 81.171.74.60:33984] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.dmkimoveis.com.br"] [uri "/user_secrets.yml"] [unique_id "al9VpC7ynBpLeKYztQPI0AAAADE"]
[Tue Jul 21 08:19:00.180272 2026] [security2:error] [pid 411857:tid 412063] [client 20.206.105.145:25104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/min.php"] [unique_id "al9VpC7ynBpLeKYztQPI2gAAAEo"]
[Tue Jul 21 08:19:00.210974 2026] [security2:error] [pid 411857:tid 412032] [client 74.7.175.164:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "areademembros.paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9VpC7ynBpLeKYztQPI1gAAACs"]
[Tue Jul 21 08:19:00.211195 2026] [security2:error] [pid 411857:tid 412079] [client 74.7.244.13:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "areademembros.paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9VpC7ynBpLeKYztQPI0wAAAFo"], referer: https://www.areademembros.paginadoproduto-oficial.com.br/robots.txt
[Tue Jul 21 08:19:00.211565 2026] [security2:error] [pid 411857:tid 412067] [client 74.7.175.164:33984] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "areademembros.paginadoproduto-oficial.com.br"] [uri "/robots.txt"] [unique_id "al9VpC7ynBpLeKYztQPI1AAATjg"]
[Tue Jul 21 08:19:00.211740 2026] [security2:error] [pid 411857:tid 412061] [client 74.7.244.13:51408] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "areademembros.paginadoproduto-oficial.com.br"] [uri "/robots.txt"] [unique_id "al9VpC7ynBpLeKYztQPI0QAASBY"], referer: https://www.areademembros.paginadoproduto-oficial.com.br/robots.txt
[Tue Jul 21 08:19:00.271587 2026] [security2:error] [pid 411857:tid 412088] [client 20.226.60.151:48840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/class.php"] [unique_id "al9VpC7ynBpLeKYztQPI4wAAAGM"]
[Tue Jul 21 08:19:00.674246 2026] [security2:error] [pid 411857:tid 412013] [client 20.226.60.151:49401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/echkm.php"] [unique_id "al9VpC7ynBpLeKYztQPI9gAAABg"]
[Tue Jul 21 08:19:00.700146 2026] [security2:error] [pid 411857:tid 412029] [client 74.7.244.13:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "areademembros.paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9VpC7ynBpLeKYztQPI6gAAACg"], referer: https://areademembros.paginadoproduto-oficial.com.br/robots.txt
[Tue Jul 21 08:19:00.700789 2026] [security2:error] [pid 411857:tid 412081] [client 74.7.244.13:51408] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "areademembros.paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9VpC7ynBpLeKYztQPI5QAAXFk"], referer: https://areademembros.paginadoproduto-oficial.com.br/robots.txt
[Tue Jul 21 08:19:00.701672 2026] [security2:error] [pid 411857:tid 412034] [client 74.7.175.164:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "areademembros.paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9VpC7ynBpLeKYztQPI6QAAAC0"], referer: https://areademembros.paginadoproduto-oficial.com.br/robots.txt
[Tue Jul 21 08:19:00.702388 2026] [security2:error] [pid 411857:tid 412083] [client 74.7.175.164:33984] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "areademembros.paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9VpC7ynBpLeKYztQPI5gAAXmo"], referer: https://areademembros.paginadoproduto-oficial.com.br/robots.txt
[Tue Jul 21 08:19:00.765187 2026] [core:alert] [pid 411857:tid 412115] [client 69.171.231.5:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:19:00.815285 2026] [security2:error] [pid 411857:tid 412101] [client 74.249.245.134:57001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/bless.php"] [unique_id "al9VpC7ynBpLeKYztQPI_QAAAHA"]
[Tue Jul 21 08:19:00.858933 2026] [security2:error] [pid 411857:tid 412047] [client 20.151.10.161:45933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/inputs.php"] [unique_id "al9VpC7ynBpLeKYztQPJAQAAADo"]
[Tue Jul 21 08:19:00.912215 2026] [security2:error] [pid 411857:tid 412025] [client 20.220.225.223:31183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/ops.php"] [unique_id "al9VpC7ynBpLeKYztQPJBQAAACQ"]
[Tue Jul 21 08:19:00.966289 2026] [security2:error] [pid 411857:tid 412068] [client 20.226.60.151:64014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/zildan.php"] [unique_id "al9VpC7ynBpLeKYztQPJBwAAAE8"]
[Tue Jul 21 08:19:00.974278 2026] [security2:error] [pid 411857:tid 412060] [client 20.206.105.145:25110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/edorxrr.php"] [unique_id "al9VpC7ynBpLeKYztQPJCAAAAEc"]
[Tue Jul 21 08:19:01.263079 2026] [security2:error] [pid 411857:tid 412050] [client 115.134.11.136:62436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VpS7ynBpLeKYztQPJEwAAAD0"]
[Tue Jul 21 08:19:01.263685 2026] [security2:error] [pid 411857:tid 412050] [client 115.134.11.136:62436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VpS7ynBpLeKYztQPJEwAAAD0"]
[Tue Jul 21 08:19:01.379625 2026] [security2:error] [pid 411857:tid 412011] [client 152.59.34.51:53657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VpS7ynBpLeKYztQPJGwAAABY"]
[Tue Jul 21 08:19:01.379797 2026] [security2:error] [pid 411857:tid 412011] [client 152.59.34.51:53657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VpS7ynBpLeKYztQPJGwAAABY"]
[Tue Jul 21 08:19:01.406344 2026] [security2:error] [pid 411857:tid 412029] [client 20.226.60.151:48793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/lib.php"] [unique_id "al9VpS7ynBpLeKYztQPJHAAAACg"]
[Tue Jul 21 08:19:01.481389 2026] [security2:error] [pid 411857:tid 412032] [client 102.206.115.33:61063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.115.206.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VpS7ynBpLeKYztQPJIQAAACs"]
[Tue Jul 21 08:19:01.482196 2026] [security2:error] [pid 411857:tid 412032] [client 102.206.115.33:61063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "produtoswendellcarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VpS7ynBpLeKYztQPJIQAAACs"]
[Tue Jul 21 08:19:01.498305 2026] [security2:error] [pid 411857:tid 412010] [client 38.100.221.102:17596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VpS7ynBpLeKYztQPJIgAAABU"]
[Tue Jul 21 08:19:01.498513 2026] [security2:error] [pid 411857:tid 412010] [client 38.100.221.102:17596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VpS7ynBpLeKYztQPJIgAAABU"]
[Tue Jul 21 08:19:01.560572 2026] [security2:error] [pid 411857:tid 412108] [client 187.125.243.197:58944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VpS7ynBpLeKYztQPJJQAAAHc"]
[Tue Jul 21 08:19:01.560765 2026] [security2:error] [pid 411857:tid 412108] [client 187.125.243.197:58944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VpS7ynBpLeKYztQPJJQAAAHc"]
[Tue Jul 21 08:19:01.682950 2026] [security2:error] [pid 411857:tid 411910] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VpS7ynBpLeKYztQPJKwAALTM"]
[Tue Jul 21 08:19:01.683129 2026] [security2:error] [pid 411857:tid 412034] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VpS7ynBpLeKYztQPJKwAALTM"]
[Tue Jul 21 08:19:01.701750 2026] [core:alert] [pid 411857:tid 412028] [client 69.171.231.114:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:19:01.732287 2026] [security2:error] [pid 411857:tid 412093] [client 20.226.60.151:64015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/csa.php"] [unique_id "al9VpS7ynBpLeKYztQPJMAAAAGg"]
[Tue Jul 21 08:19:01.855547 2026] [security2:error] [pid 411857:tid 412053] [client 103.78.200.11:50656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VpS7ynBpLeKYztQPJNgAAAEA"]
[Tue Jul 21 08:19:01.856176 2026] [security2:error] [pid 411857:tid 412053] [client 103.78.200.11:50656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VpS7ynBpLeKYztQPJNgAAAEA"]
[Tue Jul 21 08:19:01.862970 2026] [security2:error] [pid 411857:tid 412015] [client 20.226.60.151:48889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/login.php"] [unique_id "al9VpS7ynBpLeKYztQPJNwAAABo"]
[Tue Jul 21 08:19:02.099184 2026] [security2:error] [pid 411857:tid 412065] [client 20.226.60.151:60640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-post-data.php"] [unique_id "al9Vpi7ynBpLeKYztQPJPAAAAEw"]
[Tue Jul 21 08:19:02.138217 2026] [security2:error] [pid 411857:tid 412066] [client 61.1.167.83:60925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vpi7ynBpLeKYztQPJPwAAAE0"]
[Tue Jul 21 08:19:02.138352 2026] [security2:error] [pid 411857:tid 412066] [client 61.1.167.83:60925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vpi7ynBpLeKYztQPJPwAAAE0"]
[Tue Jul 21 08:19:02.173251 2026] [security2:error] [pid 411857:tid 412103] [client 20.226.60.151:48826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/a2.php"] [unique_id "al9Vpi7ynBpLeKYztQPJQgAAAHI"]
[Tue Jul 21 08:19:02.324764 2026] [security2:error] [pid 411857:tid 412032] [client 92.222.108.97:23508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "fastpedidos.com.br"] [uri "/robots.txt"] [unique_id "al9Vpi7ynBpLeKYztQPJSAAAACs"]
[Tue Jul 21 08:19:02.324876 2026] [security2:error] [pid 411857:tid 412032] [client 92.222.108.97:23508] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fastpedidos.com.br"] [uri "/robots.txt"] [unique_id "al9Vpi7ynBpLeKYztQPJSAAAACs"]
[Tue Jul 21 08:19:02.466996 2026] [security2:error] [pid 411857:tid 412115] [client 20.226.60.151:48777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/d61.php"] [unique_id "al9Vpi7ynBpLeKYztQPJUQAAAH4"]
[Tue Jul 21 08:19:02.582863 2026] [security2:error] [pid 411857:tid 411861] [remote 193.70.112.205:60836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9VpS7ynBpLeKYztQPJHQAAFAI"]
[Tue Jul 21 08:19:02.637623 2026] [security2:error] [pid 411857:tid 412028] [client 20.206.105.145:25146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/hur.php"] [unique_id "al9Vpi7ynBpLeKYztQPJVAAAACc"]
[Tue Jul 21 08:19:02.669069 2026] [core:alert] [pid 411857:tid 412112] [client 57.141.18.103:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:19:02.702494 2026] [security2:error] [pid 411857:tid 412037] [client 103.151.46.103:55851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vpi7ynBpLeKYztQPJWwAAADA"]
[Tue Jul 21 08:19:02.702623 2026] [security2:error] [pid 411857:tid 412037] [client 103.151.46.103:55851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vpi7ynBpLeKYztQPJWwAAADA"]
[Tue Jul 21 08:19:02.744062 2026] [security2:error] [pid 411857:tid 412000] [client 20.226.60.151:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/w3llscc.php"] [unique_id "al9Vpi7ynBpLeKYztQPJYQAAAAs"]
[Tue Jul 21 08:19:02.746998 2026] [security2:error] [pid 411857:tid 412021] [client 62.102.148.158:56316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Vpi7ynBpLeKYztQPJYgAAACA"]
[Tue Jul 21 08:19:02.747092 2026] [security2:error] [pid 411857:tid 412021] [client 62.102.148.158:56316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Vpi7ynBpLeKYztQPJYgAAACA"]
[Tue Jul 21 08:19:02.945068 2026] [security2:error] [pid 411857:tid 411993] [client 20.226.60.151:49347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/info.php"] [unique_id "al9Vpi7ynBpLeKYztQPJaQAAAAQ"]
[Tue Jul 21 08:19:02.981049 2026] [security2:error] [pid 411857:tid 412077] [client 20.151.10.161:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/av.php"] [unique_id "al9Vpi7ynBpLeKYztQPJbQAAAFg"]
[Tue Jul 21 08:19:03.285531 2026] [security2:error] [pid 411857:tid 412079] [client 20.226.60.151:60656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/pucci.php"] [unique_id "al9Vpy7ynBpLeKYztQPJeAAAAFo"]
[Tue Jul 21 08:19:03.376912 2026] [security2:error] [pid 411857:tid 412050] [client 74.249.245.134:48177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/storage/index.php"] [unique_id "al9Vpy7ynBpLeKYztQPJewAAAD0"]
[Tue Jul 21 08:19:03.458738 2026] [security2:error] [pid 411857:tid 412059] [client 20.226.60.151:49256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/11.php"] [unique_id "al9Vpy7ynBpLeKYztQPJgAAAAEY"]
[Tue Jul 21 08:19:03.640329 2026] [security2:error] [pid 411857:tid 412083] [client 87.116.180.198:27252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vpy7ynBpLeKYztQPJhQAAAF4"]
[Tue Jul 21 08:19:03.640480 2026] [security2:error] [pid 411857:tid 412083] [client 87.116.180.198:27252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vpy7ynBpLeKYztQPJhQAAAF4"]
[Tue Jul 21 08:19:03.667256 2026] [security2:error] [pid 411857:tid 412027] [client 74.7.244.34:37608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.orixmed.com.inlaudo.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Vpy7ynBpLeKYztQPJhgAAJng"]
[Tue Jul 21 08:19:03.687365 2026] [security2:error] [pid 411857:tid 412103] [client 117.213.202.34:51647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vpy7ynBpLeKYztQPJhwAAAHI"]
[Tue Jul 21 08:19:03.687533 2026] [security2:error] [pid 411857:tid 412103] [client 117.213.202.34:51647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vpy7ynBpLeKYztQPJhwAAAHI"]
[Tue Jul 21 08:19:03.698091 2026] [security2:error] [pid 411857:tid 412040] [client 81.171.72.93:33800] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/backup.tar.gz"] [unique_id "al9Vpy7ynBpLeKYztQPJiAAAADM"]
[Tue Jul 21 08:19:03.698686 2026] [security2:error] [pid 411857:tid 412048] [client 81.171.72.93:33768] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/.bash_history"] [unique_id "al9Vpy7ynBpLeKYztQPJiQAAADs"]
[Tue Jul 21 08:19:03.699918 2026] [security2:error] [pid 411857:tid 412053] [client 81.171.72.93:33812] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9Vpy7ynBpLeKYztQPJigAAAEA"]
[Tue Jul 21 08:19:03.700458 2026] [security2:error] [pid 411857:tid 412088] [client 81.171.72.93:33762] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9Vpy7ynBpLeKYztQPJiwAAAGM"]
[Tue Jul 21 08:19:03.760860 2026] [security2:error] [pid 411857:tid 412111] [client 20.226.60.151:48809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/v2.php"] [unique_id "al9Vpy7ynBpLeKYztQPJkAAAAHo"]
[Tue Jul 21 08:19:03.885867 2026] [security2:error] [pid 411857:tid 411991] [client 20.226.60.151:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wpx.php"] [unique_id "al9Vpy7ynBpLeKYztQPJkQAAAAI"]
[Tue Jul 21 08:19:03.901798 2026] [security2:error] [pid 411857:tid 412025] [client 81.171.72.93:33820] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/.npmrc"] [unique_id "al9Vpy7ynBpLeKYztQPJkwAAACQ"]
[Tue Jul 21 08:19:03.901896 2026] [security2:error] [pid 411857:tid 412044] [client 81.171.72.93:33784] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9Vpy7ynBpLeKYztQPJlAAAADc"]
[Tue Jul 21 08:19:03.902995 2026] [security2:error] [pid 411857:tid 412015] [client 81.171.72.93:33802] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/.svn/wc.db"] [unique_id "al9Vpy7ynBpLeKYztQPJlQAAABo"]
[Tue Jul 21 08:19:03.978257 2026] [security2:error] [pid 411857:tid 411990] [client 54.39.136.6:59644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "fastpedidos.com.br"] [uri "/"] [unique_id "al9Vpy7ynBpLeKYztQPJmQAAAAE"]
[Tue Jul 21 08:19:03.978369 2026] [security2:error] [pid 411857:tid 411990] [client 54.39.136.6:59644] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fastpedidos.com.br"] [uri "/"] [unique_id "al9Vpy7ynBpLeKYztQPJmQAAAAE"]
[Tue Jul 21 08:19:04.018737 2026] [security2:error] [pid 411857:tid 412046] [client 20.151.10.161:46060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/classwithtostring.php"] [unique_id "al9VqC7ynBpLeKYztQPJngAAADk"]
[Tue Jul 21 08:19:04.246724 2026] [security2:error] [pid 411857:tid 412101] [client 20.206.105.145:25566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/zoro.php"] [unique_id "al9VqC7ynBpLeKYztQPJqwAAAHA"]
[Tue Jul 21 08:19:04.284884 2026] [core:error] [pid 411857:tid 411967] [remote 34.182.235.64:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:19:04.284910 2026] [core:error] [pid 411857:tid 411967] [remote 34.182.235.64:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:19:04.289319 2026] [access_compat:error] [pid 411857:tid 412092] [client 162.241.63.68:17698] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:19:04.302019 2026] [security2:error] [pid 411857:tid 412060] [client 20.226.60.151:64112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-css.php"] [unique_id "al9VqC7ynBpLeKYztQPJrwAAAEc"]
[Tue Jul 21 08:19:04.327465 2026] [security2:error] [pid 411857:tid 412039] [client 81.171.72.93:33824] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/.env.production"] [unique_id "al9VqC7ynBpLeKYztQPJsAAAADI"]
[Tue Jul 21 08:19:04.334455 2026] [security2:error] [pid 411857:tid 412081] [client 20.226.60.151:49357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/panel.php"] [unique_id "al9VqC7ynBpLeKYztQPJsQAAAFw"]
[Tue Jul 21 08:19:04.444866 2026] [security2:error] [pid 411857:tid 411875] [remote 34.182.235.64:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.235.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.bomnegociopromotora.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VqC7ynBpLeKYztQPJtAAAehA"]
[Tue Jul 21 08:19:04.446452 2026] [security2:error] [pid 411857:tid 412049] [client 20.226.60.151:48861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/dex.php"] [unique_id "al9VqC7ynBpLeKYztQPJtQAAADw"]
[Tue Jul 21 08:19:04.528107 2026] [security2:error] [pid 411857:tid 412037] [client 81.171.72.93:33836] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.dmkimoveis.com.br"] [uri "/.git/HEAD"] [unique_id "al9VqC7ynBpLeKYztQPJtgAAADA"]
[Tue Jul 21 08:19:04.553476 2026] [security2:error] [pid 411857:tid 412002] [client 14.245.224.124:51048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VqC7ynBpLeKYztQPJtwAAAA0"]
[Tue Jul 21 08:19:04.553808 2026] [security2:error] [pid 411857:tid 412002] [client 14.245.224.124:51048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VqC7ynBpLeKYztQPJtwAAAA0"]
[Tue Jul 21 08:19:04.582945 2026] [security2:error] [pid 411857:tid 411969] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bomnegociopromotora.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9VqC7ynBpLeKYztQPJuwAANG0"]
[Tue Jul 21 08:19:04.641782 2026] [security2:error] [pid 411857:tid 412015] [client 20.226.60.151:48816] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "abbaprotect.com"] [uri "/1.php"] [unique_id "al9VqC7ynBpLeKYztQPJvwAAABo"]
[Tue Jul 21 08:19:04.641886 2026] [security2:error] [pid 411857:tid 412015] [client 20.226.60.151:48816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/1.php"] [unique_id "al9VqC7ynBpLeKYztQPJvwAAABo"]
[Tue Jul 21 08:19:04.707312 2026] [security2:error] [pid 411857:tid 411864] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bomnegociopromotora.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9VqC7ynBpLeKYztQPJwQAAOQU"]
[Tue Jul 21 08:19:04.718736 2026] [security2:error] [pid 411857:tid 412012] [client 20.226.60.151:64025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/ho.php"] [unique_id "al9VqC7ynBpLeKYztQPJwgAAABc"]
[Tue Jul 21 08:19:04.732591 2026] [security2:error] [pid 411857:tid 412076] [client 103.106.20.201:51181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VqC7ynBpLeKYztQPJwwAAAFc"]
[Tue Jul 21 08:19:04.732687 2026] [security2:error] [pid 411857:tid 412076] [client 103.106.20.201:51181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VqC7ynBpLeKYztQPJwwAAAFc"]
[Tue Jul 21 08:19:04.835835 2026] [security2:error] [pid 411857:tid 411896] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bomnegociopromotora.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9VqC7ynBpLeKYztQPJyQAAbyU"]
[Tue Jul 21 08:19:04.984072 2026] [security2:error] [pid 411857:tid 411977] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bomnegociopromotora.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9VqC7ynBpLeKYztQPJ0AAAWnU"]
[Tue Jul 21 08:19:05.004156 2026] [security2:error] [pid 411857:tid 412061] [client 20.226.60.151:48863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/ms.php"] [unique_id "al9VqS7ynBpLeKYztQPJ0QAAAEg"]
[Tue Jul 21 08:19:05.090864 2026] [security2:error] [pid 411857:tid 412088] [client 65.21.113.253:47522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VqC7ynBpLeKYztQPJwAAAAGM"]
[Tue Jul 21 08:19:05.113464 2026] [security2:error] [pid 411857:tid 411886] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bomnegociopromotora.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9VqS7ynBpLeKYztQPJ1gAAcBs"]
[Tue Jul 21 08:19:05.131345 2026] [security2:error] [pid 411857:tid 412034] [client 20.226.60.151:64003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/xy.php"] [unique_id "al9VqS7ynBpLeKYztQPJ1wAAAC0"]
[Tue Jul 21 08:19:05.238067 2026] [security2:error] [pid 411857:tid 411883] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bomnegociopromotora.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9VqS7ynBpLeKYztQPJ2AAAHxg"]
[Tue Jul 21 08:19:05.348896 2026] [security2:error] [pid 411857:tid 412060] [client 20.206.105.145:25494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/coffexium.php"] [unique_id "al9VqS7ynBpLeKYztQPJ2wAAAEc"]
[Tue Jul 21 08:19:05.380950 2026] [security2:error] [pid 411857:tid 411924] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bomnegociopromotora.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9VqS7ynBpLeKYztQPJ3gAAEUE"]
[Tue Jul 21 08:19:05.537960 2026] [security2:error] [pid 411857:tid 411985] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bomnegociopromotora.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9VqS7ynBpLeKYztQPJ5wAAB30"]
[Tue Jul 21 08:19:05.580879 2026] [security2:error] [pid 411857:tid 412057] [client 74.249.245.134:50980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/g.php"] [unique_id "al9VqS7ynBpLeKYztQPJ6QAAAEQ"]
[Tue Jul 21 08:19:05.666699 2026] [security2:error] [pid 411857:tid 411976] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bomnegociopromotora.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9VqS7ynBpLeKYztQPJ7wAAUXQ"]
[Tue Jul 21 08:19:05.753650 2026] [security2:error] [pid 411857:tid 411992] [client 62.102.148.158:48982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9VqS7ynBpLeKYztQPJ8gAAAAM"]
[Tue Jul 21 08:19:05.753756 2026] [security2:error] [pid 411857:tid 411992] [client 62.102.148.158:48982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9VqS7ynBpLeKYztQPJ8gAAAAM"]
[Tue Jul 21 08:19:05.790944 2026] [autoindex:error] [pid 411857:tid 412113] [client 20.226.60.151:49373] AH01276: Cannot serve directory /home4/abbapr65/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:19:05.796606 2026] [security2:error] [pid 411857:tid 412085] [client 20.151.10.161:45890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9VqS7ynBpLeKYztQPJ8wAAAGA"]
[Tue Jul 21 08:19:05.806860 2026] [security2:error] [pid 411857:tid 411956] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bomnegociopromotora.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9VqS7ynBpLeKYztQPJ9AAAQ2A"]
[Tue Jul 21 08:19:05.818634 2026] [security2:error] [pid 411857:tid 412015] [client 20.226.60.151:49373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/memberfuns.php"] [unique_id "al9VqS7ynBpLeKYztQPJ9QAAABo"]
[Tue Jul 21 08:19:05.937546 2026] [security2:error] [pid 411857:tid 411904] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bomnegociopromotora.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9VqS7ynBpLeKYztQPJ-wAAWy0"]
[Tue Jul 21 08:19:06.061634 2026] [security2:error] [pid 411857:tid 411915] [remote 34.182.235.64:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bomnegociopromotora.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Vqi7ynBpLeKYztQPKAAAASzg"]
[Tue Jul 21 08:19:06.117192 2026] [security2:error] [pid 411857:tid 412024] [client 150.129.202.39:12768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vqi7ynBpLeKYztQPKAwAAACM"]
[Tue Jul 21 08:19:06.117353 2026] [security2:error] [pid 411857:tid 412024] [client 150.129.202.39:12768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vqi7ynBpLeKYztQPKAwAAACM"]
[Tue Jul 21 08:19:06.210967 2026] [security2:error] [pid 411857:tid 412073] [client 20.206.105.145:25502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/app.php"] [unique_id "al9Vqi7ynBpLeKYztQPKCQAAAFQ"]
[Tue Jul 21 08:19:06.235965 2026] [security2:error] [pid 411857:tid 412097] [client 20.226.60.151:48996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/0.php"] [unique_id "al9Vqi7ynBpLeKYztQPKCgAAAGw"]
[Tue Jul 21 08:19:06.395991 2026] [security2:error] [pid 411857:tid 412107] [client 20.226.60.151:64013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/loader.php"] [unique_id "al9Vqi7ynBpLeKYztQPKDAAAAHY"]
[Tue Jul 21 08:19:06.573708 2026] [security2:error] [pid 411857:tid 412077] [client 20.226.60.151:48819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/BDKR28.php"] [unique_id "al9Vqi7ynBpLeKYztQPKFwAAAFg"]
[Tue Jul 21 08:19:06.685402 2026] [security2:error] [pid 411857:tid 412076] [client 125.18.144.2:61732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Vqi7ynBpLeKYztQPKGwAAAFc"]
[Tue Jul 21 08:19:06.685936 2026] [security2:error] [pid 411857:tid 412076] [client 125.18.144.2:61732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Vqi7ynBpLeKYztQPKGwAAAFc"]
[Tue Jul 21 08:19:06.855733 2026] [security2:error] [pid 411857:tid 412085] [client 20.226.60.151:48853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/green1.php"] [unique_id "al9Vqi7ynBpLeKYztQPKIQAAAGA"]
[Tue Jul 21 08:19:06.899829 2026] [security2:error] [pid 411857:tid 412101] [client 117.210.135.0:52478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vqi7ynBpLeKYztQPKJgAAAHA"]
[Tue Jul 21 08:19:06.899935 2026] [security2:error] [pid 411857:tid 412101] [client 117.210.135.0:52478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vqi7ynBpLeKYztQPKJgAAAHA"]
[Tue Jul 21 08:19:06.941517 2026] [security2:error] [pid 411857:tid 412082] [client 20.226.60.151:49378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/nc4.php"] [unique_id "al9Vqi7ynBpLeKYztQPKKQAAAF0"]
[Tue Jul 21 08:19:07.252056 2026] [security2:error] [pid 411857:tid 412079] [client 74.249.245.134:50966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/nf.php"] [unique_id "al9Vqy7ynBpLeKYztQPKNQAAAFo"]
[Tue Jul 21 08:19:07.393334 2026] [security2:error] [pid 411857:tid 412033] [client 65.21.113.253:47522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vqi7ynBpLeKYztQPKKAAAACw"]
[Tue Jul 21 08:19:07.399981 2026] [security2:error] [pid 411857:tid 411916] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vqy7ynBpLeKYztQPKNwAASzk"]
[Tue Jul 21 08:19:07.400155 2026] [security2:error] [pid 411857:tid 412064] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vqy7ynBpLeKYztQPKNwAASzk"]
[Tue Jul 21 08:19:07.534396 2026] [security2:error] [pid 411857:tid 412056] [client 120.56.162.40:58947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vqy7ynBpLeKYztQPKRAAAAEM"]
[Tue Jul 21 08:19:07.534713 2026] [security2:error] [pid 411857:tid 412056] [client 120.56.162.40:58947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vqy7ynBpLeKYztQPKRAAAAEM"]
[Tue Jul 21 08:19:07.681479 2026] [security2:error] [pid 411857:tid 412048] [client 20.226.60.151:49381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/a1.php"] [unique_id "al9Vqy7ynBpLeKYztQPKSAAAADs"]
[Tue Jul 21 08:19:07.808401 2026] [security2:error] [pid 411857:tid 412041] [client 20.226.60.151:49351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/eee.php"] [unique_id "al9Vqy7ynBpLeKYztQPKUAAAADQ"]
[Tue Jul 21 08:19:07.888283 2026] [security2:error] [pid 411857:tid 411990] [client 20.226.60.151:64048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/spadex.php"] [unique_id "al9Vqy7ynBpLeKYztQPKUgAAAAE"]
[Tue Jul 21 08:19:07.905058 2026] [security2:error] [pid 411857:tid 412014] [client 20.226.60.151:48860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/wp-aothait.php"] [unique_id "al9Vqy7ynBpLeKYztQPKUwAAABk"]
[Tue Jul 21 08:19:08.002144 2026] [security2:error] [pid 411857:tid 412072] [client 20.226.60.151:48808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/config.json.php"] [unique_id "al9VrC7ynBpLeKYztQPKWwAAAFM"]
[Tue Jul 21 08:19:08.047068 2026] [security2:error] [pid 411857:tid 412085] [client 185.213.175.37:7982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.rinettoar.com.br"] [uri "/secrets.json"] [unique_id "al9VrC7ynBpLeKYztQPKXgAAAGA"]
[Tue Jul 21 08:19:08.047160 2026] [security2:error] [pid 411857:tid 412085] [client 185.213.175.37:7982] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.rinettoar.com.br"] [uri "/secrets.json"] [unique_id "al9VrC7ynBpLeKYztQPKXgAAAGA"]
[Tue Jul 21 08:19:08.080017 2026] [security2:error] [pid 411857:tid 412100] [client 20.226.60.151:49383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9VrC7ynBpLeKYztQPKXwAAAG8"]
[Tue Jul 21 08:19:08.085670 2026] [security2:error] [pid 411857:tid 412102] [client 20.206.105.145:25116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/core.php"] [unique_id "al9VrC7ynBpLeKYztQPKYAAAAHE"]
[Tue Jul 21 08:19:08.108492 2026] [security2:error] [pid 411857:tid 412084] [client 20.226.60.151:49241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/k2.php"] [unique_id "al9VrC7ynBpLeKYztQPKYQAAAF8"]
[Tue Jul 21 08:19:08.234332 2026] [security2:error] [pid 411857:tid 412079] [client 20.226.60.151:48868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/uiuvs58l.php"] [unique_id "al9VrC7ynBpLeKYztQPKZQAAAFo"]
[Tue Jul 21 08:19:08.445765 2026] [security2:error] [pid 411857:tid 411908] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VrC7ynBpLeKYztQPKawAAdjE"]
[Tue Jul 21 08:19:08.446021 2026] [security2:error] [pid 411857:tid 412107] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VrC7ynBpLeKYztQPKawAAdjE"]
[Tue Jul 21 08:19:08.534849 2026] [security2:error] [pid 411857:tid 411913] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VrC7ynBpLeKYztQPKcAAARjY"]
[Tue Jul 21 08:19:08.535056 2026] [security2:error] [pid 411857:tid 412059] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VrC7ynBpLeKYztQPKcAAARjY"]
[Tue Jul 21 08:19:08.645294 2026] [security2:error] [pid 411857:tid 412036] [client 20.226.60.151:49395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/40p9ixjd.php"] [unique_id "al9VrC7ynBpLeKYztQPKcgAAAC8"]
[Tue Jul 21 08:19:08.754917 2026] [security2:error] [pid 411857:tid 412006] [client 20.226.60.151:60644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/black.php"] [unique_id "al9VrC7ynBpLeKYztQPKcwAAABE"]
[Tue Jul 21 08:19:08.935366 2026] [security2:error] [pid 411857:tid 412070] [client 20.226.60.151:49398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9VrC7ynBpLeKYztQPKeQAAAFE"]
[Tue Jul 21 08:19:09.136754 2026] [security2:error] [pid 411857:tid 411991] [client 20.226.60.151:64010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/2x.php"] [unique_id "al9VrS7ynBpLeKYztQPKgwAAAAI"]
[Tue Jul 21 08:19:09.287877 2026] [security2:error] [pid 411857:tid 411973] [remote 203.161.62.87:33188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.62.161.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9VrS7ynBpLeKYztQPKhwAAB3E"]
[Tue Jul 21 08:19:09.478403 2026] [security2:error] [pid 411857:tid 412067] [client 20.226.60.151:48823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/for.php"] [unique_id "al9VrS7ynBpLeKYztQPKkQAAAE4"]
[Tue Jul 21 08:19:09.623876 2026] [security2:error] [pid 411857:tid 412069] [client 20.226.60.151:64107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/ctex1.php"] [unique_id "al9VrS7ynBpLeKYztQPKmAAAAFA"]
[Tue Jul 21 08:19:09.697740 2026] [security2:error] [pid 411857:tid 412115] [client 20.226.60.151:49405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/raw.php"] [unique_id "al9VrS7ynBpLeKYztQPKnAAAAH4"]
[Tue Jul 21 08:19:09.793796 2026] [security2:error] [pid 411857:tid 412003] [client 74.249.245.134:43841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/xda.php"] [unique_id "al9VrS7ynBpLeKYztQPKngAAAA4"]
[Tue Jul 21 08:19:09.852260 2026] [security2:error] [pid 411857:tid 412072] [client 65.21.113.253:47522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VrS7ynBpLeKYztQPKiwAAAFM"]
[Tue Jul 21 08:19:10.073443 2026] [security2:error] [pid 411857:tid 411897] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Vri7ynBpLeKYztQPKqAAAACY"]
[Tue Jul 21 08:19:10.073612 2026] [security2:error] [pid 411857:tid 411989] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Vri7ynBpLeKYztQPKqAAAACY"]
[Tue Jul 21 08:19:10.182607 2026] [security2:error] [pid 411857:tid 412022] [client 223.181.60.88:19905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Vri7ynBpLeKYztQPKrQAAACE"]
[Tue Jul 21 08:19:10.182938 2026] [security2:error] [pid 411857:tid 412022] [client 223.181.60.88:19905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Vri7ynBpLeKYztQPKrQAAACE"]
[Tue Jul 21 08:19:10.219443 2026] [security2:error] [pid 411857:tid 412114] [client 20.226.60.151:64081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/edorxrr.php"] [unique_id "al9Vri7ynBpLeKYztQPKrgAAAH0"]
[Tue Jul 21 08:19:10.339991 2026] [security2:error] [pid 411857:tid 412076] [client 173.252.95.42:37432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Vri7ynBpLeKYztQPKswAAAFc"]
[Tue Jul 21 08:19:10.473973 2026] [security2:error] [pid 411857:tid 411953] [remote 207.180.241.245:50010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9Vri7ynBpLeKYztQPKuAAAZ10"]
[Tue Jul 21 08:19:10.477040 2026] [security2:error] [pid 411857:tid 412028] [client 154.208.47.43:64546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Vri7ynBpLeKYztQPKugAAACc"]
[Tue Jul 21 08:19:10.477148 2026] [security2:error] [pid 411857:tid 412028] [client 154.208.47.43:64546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Vri7ynBpLeKYztQPKugAAACc"]
[Tue Jul 21 08:19:10.542551 2026] [security2:error] [pid 411857:tid 412089] [client 20.206.105.145:25408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/main.php"] [unique_id "al9Vri7ynBpLeKYztQPKuwAAAGQ"]
[Tue Jul 21 08:19:10.654319 2026] [security2:error] [pid 411857:tid 412045] [client 20.151.10.161:45943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-blog.php"] [unique_id "al9Vri7ynBpLeKYztQPKxAAAADg"]
[Tue Jul 21 08:19:10.863013 2026] [security2:error] [pid 411857:tid 412108] [client 20.226.60.151:64019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/miru1.php"] [unique_id "al9Vri7ynBpLeKYztQPKyQAAAHc"]
[Tue Jul 21 08:19:10.913731 2026] [security2:error] [pid 411857:tid 412007] [client 38.100.221.102:17226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vri7ynBpLeKYztQPKzgAAABI"]
[Tue Jul 21 08:19:10.913850 2026] [security2:error] [pid 411857:tid 412007] [client 38.100.221.102:17226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vri7ynBpLeKYztQPKzgAAABI"]
[Tue Jul 21 08:19:11.079704 2026] [security2:error] [pid 411857:tid 412060] [client 65.21.113.253:47522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vri7ynBpLeKYztQPKywAAAEc"]
[Tue Jul 21 08:19:11.233249 2026] [security2:error] [pid 411857:tid 412037] [client 185.213.175.37:1474] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.transitoaberto.com.br"] [uri "/"] [unique_id "al9Vry7ynBpLeKYztQPK3AAAADA"]
[Tue Jul 21 08:19:11.322883 2026] [security2:error] [pid 411857:tid 412114] [client 74.7.241.128:45434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "mail.fusoesaquisicoes.com"] [uri "/cgi-sys/404.html"] [unique_id "al9Vry7ynBpLeKYztQPK3gAAfRg"]
[Tue Jul 21 08:19:11.355395 2026] [autoindex:error] [pid 411857:tid 412049] [client 37.27.51.131:50472] AH01276: Cannot serve directory /home4/bcaccj52/accjbc.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:19:11.489863 2026] [security2:error] [pid 411857:tid 412023] [client 20.226.60.151:64017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/sump1.php"] [unique_id "al9Vry7ynBpLeKYztQPK6AAAACI"]
[Tue Jul 21 08:19:11.662316 2026] [security2:error] [pid 411857:tid 412063] [client 205.185.113.241:40760] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "atilafagundes.com.br"] [uri "/"] [unique_id "al9Vry7ynBpLeKYztQPK8QAAAEo"]
[Tue Jul 21 08:19:11.705976 2026] [security2:error] [pid 411857:tid 412090] [client 115.134.11.136:62879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vry7ynBpLeKYztQPK8wAAAGU"]
[Tue Jul 21 08:19:11.706625 2026] [security2:error] [pid 411857:tid 412090] [client 115.134.11.136:62879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vry7ynBpLeKYztQPK8wAAAGU"]
[Tue Jul 21 08:19:11.753241 2026] [security2:error] [pid 411857:tid 412072] [client 152.59.34.51:54129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Vry7ynBpLeKYztQPK9QAAAFM"]
[Tue Jul 21 08:19:11.753372 2026] [security2:error] [pid 411857:tid 412072] [client 152.59.34.51:54129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Vry7ynBpLeKYztQPK9QAAAFM"]
[Tue Jul 21 08:19:11.824593 2026] [security2:error] [pid 411857:tid 412025] [client 74.249.245.134:44997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/shell.php"] [unique_id "al9Vry7ynBpLeKYztQPK9gAAACQ"]
[Tue Jul 21 08:19:11.854010 2026] [security2:error] [pid 411857:tid 411992] [client 103.151.46.103:56349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vry7ynBpLeKYztQPK9wAAAAM"]
[Tue Jul 21 08:19:11.854133 2026] [security2:error] [pid 411857:tid 411992] [client 103.151.46.103:56349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vry7ynBpLeKYztQPK9wAAAAM"]
[Tue Jul 21 08:19:11.932921 2026] [security2:error] [pid 411857:tid 412081] [client 20.226.60.151:60579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/zlece.php"] [unique_id "al9Vry7ynBpLeKYztQPK_AAAAFw"]
[Tue Jul 21 08:19:11.939636 2026] [security2:error] [pid 411857:tid 412000] [client 20.226.60.151:64050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/file5.php"] [unique_id "al9Vry7ynBpLeKYztQPK_QAAAAs"]
[Tue Jul 21 08:19:11.967823 2026] [security2:error] [pid 411857:tid 412047] [client 187.125.243.197:59442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Vry7ynBpLeKYztQPK_wAAADo"]
[Tue Jul 21 08:19:11.968787 2026] [security2:error] [pid 411857:tid 412047] [client 187.125.243.197:59442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Vry7ynBpLeKYztQPK_wAAADo"]
[Tue Jul 21 08:19:11.982615 2026] [security2:error] [pid 411857:tid 412006] [client 62.102.148.158:46182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Vry7ynBpLeKYztQPLAgAAABE"]
[Tue Jul 21 08:19:11.982706 2026] [security2:error] [pid 411857:tid 412006] [client 62.102.148.158:46182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Vry7ynBpLeKYztQPLAgAAABE"]
[Tue Jul 21 08:19:12.410446 2026] [security2:error] [pid 411857:tid 411881] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VsC7ynBpLeKYztQPLDgAAVhY"]
[Tue Jul 21 08:19:12.410638 2026] [security2:error] [pid 411857:tid 412075] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VsC7ynBpLeKYztQPLDgAAVhY"]
[Tue Jul 21 08:19:12.557792 2026] [security2:error] [pid 411857:tid 412029] [client 20.206.105.145:25533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/init.php"] [unique_id "al9VsC7ynBpLeKYztQPLFwAAACg"]
[Tue Jul 21 08:19:12.686531 2026] [security2:error] [pid 411857:tid 412088] [client 103.78.200.11:51156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.200.78.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VsC7ynBpLeKYztQPLHAAAAGM"]
[Tue Jul 21 08:19:12.686774 2026] [security2:error] [pid 411857:tid 412088] [client 103.78.200.11:51156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oficialwebsite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VsC7ynBpLeKYztQPLHAAAAGM"]
[Tue Jul 21 08:19:12.910352 2026] [security2:error] [pid 411857:tid 412071] [client 20.226.60.151:59285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/0xD.php"] [unique_id "al9VsC7ynBpLeKYztQPLIAAAAFI"]
[Tue Jul 21 08:19:13.551858 2026] [security2:error] [pid 411857:tid 412057] [client 20.226.60.151:59079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/fnstall.php"] [unique_id "al9VsS7ynBpLeKYztQPLPgAAAEQ"]
[Tue Jul 21 08:19:13.634357 2026] [security2:error] [pid 411857:tid 412049] [client 20.226.60.151:60667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/vssrs.php"] [unique_id "al9VsS7ynBpLeKYztQPLQgAAADw"]
[Tue Jul 21 08:19:13.934083 2026] [security2:error] [pid 411857:tid 411901] [remote 45.79.123.44:53814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-login.php"] [unique_id "al9VsS7ynBpLeKYztQPLSgAAeSo"]
[Tue Jul 21 08:19:14.317894 2026] [security2:error] [pid 411857:tid 412106] [client 117.213.202.34:52168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vsi7ynBpLeKYztQPLYwAAAHU"]
[Tue Jul 21 08:19:14.318042 2026] [security2:error] [pid 411857:tid 412106] [client 117.213.202.34:52168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vsi7ynBpLeKYztQPLYwAAAHU"]
[Tue Jul 21 08:19:14.347672 2026] [security2:error] [pid 411857:tid 412067] [client 65.21.113.253:47522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VsS7ynBpLeKYztQPLSAAAAE4"]
[Tue Jul 21 08:19:14.385152 2026] [security2:error] [pid 411857:tid 412080] [client 87.116.180.198:27373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vsi7ynBpLeKYztQPLZwAAAFs"]
[Tue Jul 21 08:19:14.385255 2026] [security2:error] [pid 411857:tid 412080] [client 87.116.180.198:27373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vsi7ynBpLeKYztQPLZwAAAFs"]
[Tue Jul 21 08:19:14.426506 2026] [security2:error] [pid 411857:tid 412034] [client 20.206.105.145:25505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/prekel.php"] [unique_id "al9Vsi7ynBpLeKYztQPLaAAAAC0"]
[Tue Jul 21 08:19:14.599846 2026] [security2:error] [pid 411857:tid 412045] [client 45.8.19.149:48311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeireirapiske.com.br"] [uri "/wp-login.php"] [unique_id "al9Vsi7ynBpLeKYztQPLbQAAADg"]
[Tue Jul 21 08:19:14.854545 2026] [security2:error] [pid 411857:tid 412077] [client 61.1.167.83:61432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vsi7ynBpLeKYztQPLeQAAAFg"]
[Tue Jul 21 08:19:14.854696 2026] [security2:error] [pid 411857:tid 412077] [client 61.1.167.83:61432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vsi7ynBpLeKYztQPLeQAAAFg"]
[Tue Jul 21 08:19:14.858453 2026] [security2:error] [pid 411857:tid 412079] [client 74.7.230.25:41932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cmpartners.com.br"] [uri "/index.php"] [unique_id "al9Vsi7ynBpLeKYztQPLcwAAWj4"]
[Tue Jul 21 08:19:14.871277 2026] [security2:error] [pid 411857:tid 412001] [client 20.226.60.151:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/acp.php"] [unique_id "al9Vsi7ynBpLeKYztQPLegAAAAw"]
[Tue Jul 21 08:19:15.033843 2026] [security2:error] [pid 411857:tid 412098] [client 20.151.10.161:46057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Vsy7ynBpLeKYztQPLgAAAAG0"]
[Tue Jul 21 08:19:15.356216 2026] [security2:error] [pid 411857:tid 412021] [client 74.249.245.134:21052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/3.php"] [unique_id "al9Vsy7ynBpLeKYztQPLjgAAACA"]
[Tue Jul 21 08:19:15.500691 2026] [security2:error] [pid 411857:tid 412035] [client 14.245.224.124:51503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Vsy7ynBpLeKYztQPLmwAAAC4"]
[Tue Jul 21 08:19:15.500800 2026] [security2:error] [pid 411857:tid 412035] [client 14.245.224.124:51503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Vsy7ynBpLeKYztQPLmwAAAC4"]
[Tue Jul 21 08:19:15.596198 2026] [security2:error] [pid 411857:tid 411992] [client 103.106.20.201:51767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vsy7ynBpLeKYztQPLoQAAAAM"]
[Tue Jul 21 08:19:15.596320 2026] [security2:error] [pid 411857:tid 411992] [client 103.106.20.201:51767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vsy7ynBpLeKYztQPLoQAAAAM"]
[Tue Jul 21 08:19:16.120673 2026] [security2:error] [pid 411857:tid 412093] [client 20.226.60.151:64060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/mosty.php"] [unique_id "al9VtC7ynBpLeKYztQPLrwAAAGg"]
[Tue Jul 21 08:19:16.312184 2026] [security2:error] [pid 411857:tid 412053] [client 198.54.129.60:43052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9VtC7ynBpLeKYztQPLtgAAAEA"]
[Tue Jul 21 08:19:16.312312 2026] [security2:error] [pid 411857:tid 412053] [client 198.54.129.60:43052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9VtC7ynBpLeKYztQPLtgAAAEA"]
[Tue Jul 21 08:19:16.345247 2026] [security2:error] [pid 411857:tid 412103] [client 20.206.105.145:25579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/0.php"] [unique_id "al9VtC7ynBpLeKYztQPLuQAAAHI"]
[Tue Jul 21 08:19:16.623004 2026] [security2:error] [pid 411857:tid 411903] [remote 185.115.217.185:51142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.217.115.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9VtC7ynBpLeKYztQPLwwAAEyw"]
[Tue Jul 21 08:19:16.691257 2026] [security2:error] [pid 411857:tid 412055] [client 150.129.202.39:65144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VtC7ynBpLeKYztQPLxwAAAEI"]
[Tue Jul 21 08:19:16.691368 2026] [security2:error] [pid 411857:tid 412055] [client 150.129.202.39:65144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VtC7ynBpLeKYztQPLxwAAAEI"]
[Tue Jul 21 08:19:16.919950 2026] [security2:error] [pid 411857:tid 412037] [client 20.226.60.151:64121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/6.php"] [unique_id "al9VtC7ynBpLeKYztQPL0wAAADA"]
[Tue Jul 21 08:19:16.987435 2026] [security2:error] [pid 411857:tid 412114] [client 74.249.245.134:34449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/mds.php"] [unique_id "al9VtC7ynBpLeKYztQPL1wAAAH0"]
[Tue Jul 21 08:19:17.107761 2026] [security2:error] [pid 411857:tid 412005] [client 162.219.176.3:47530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9VtS7ynBpLeKYztQPL3AAAABA"]
[Tue Jul 21 08:19:17.107898 2026] [security2:error] [pid 411857:tid 412005] [client 162.219.176.3:47530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9VtS7ynBpLeKYztQPL3AAAABA"]
[Tue Jul 21 08:19:17.223625 2026] [security2:error] [pid 411857:tid 412092] [client 65.21.113.253:47522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VtC7ynBpLeKYztQPLzQAAAGc"]
[Tue Jul 21 08:19:17.261528 2026] [security2:error] [pid 411857:tid 412057] [client 111.93.58.162:18797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VtS7ynBpLeKYztQPL4wAAAEQ"]
[Tue Jul 21 08:19:17.261717 2026] [security2:error] [pid 411857:tid 412057] [client 111.93.58.162:18797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9VtS7ynBpLeKYztQPL4wAAAEQ"]
[Tue Jul 21 08:19:17.381504 2026] [security2:error] [pid 411857:tid 412047] [client 117.210.135.0:53130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VtS7ynBpLeKYztQPL5wAAADo"]
[Tue Jul 21 08:19:17.381642 2026] [security2:error] [pid 411857:tid 412047] [client 117.210.135.0:53130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VtS7ynBpLeKYztQPL5wAAADo"]
[Tue Jul 21 08:19:17.606598 2026] [security2:error] [pid 411857:tid 411993] [client 20.151.10.161:45892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/adminfuns.php"] [unique_id "al9VtS7ynBpLeKYztQPL8AAAAAQ"]
[Tue Jul 21 08:19:17.963766 2026] [security2:error] [pid 411857:tid 412043] [client 20.197.192.193:62429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/tkikikoko.php"] [unique_id "al9VtS7ynBpLeKYztQPL_wAAADY"]
[Tue Jul 21 08:19:17.979726 2026] [security2:error] [pid 411857:tid 411952] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VtS7ynBpLeKYztQPMAAAAW1w"]
[Tue Jul 21 08:19:17.979883 2026] [security2:error] [pid 411857:tid 412080] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VtS7ynBpLeKYztQPMAAAAW1w"]
[Tue Jul 21 08:19:18.161086 2026] [security2:error] [pid 411857:tid 412015] [client 120.56.162.40:59449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vti7ynBpLeKYztQPMBwAAABo"]
[Tue Jul 21 08:19:18.161223 2026] [security2:error] [pid 411857:tid 412015] [client 120.56.162.40:59449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vti7ynBpLeKYztQPMBwAAABo"]
[Tue Jul 21 08:19:18.181279 2026] [security2:error] [pid 411857:tid 412024] [client 20.226.60.151:64125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9Vti7ynBpLeKYztQPMCQAAACM"]
[Tue Jul 21 08:19:18.237599 2026] [security2:error] [pid 411857:tid 412028] [client 20.206.105.145:25517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/BDKR28.php"] [unique_id "al9Vti7ynBpLeKYztQPMCgAAACc"]
[Tue Jul 21 08:19:18.537894 2026] [security2:error] [pid 411857:tid 412034] [client 20.197.192.193:48710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9Vti7ynBpLeKYztQPMJgAAAC0"]
[Tue Jul 21 08:19:18.625011 2026] [security2:error] [pid 411857:tid 412001] [client 20.197.192.193:62410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/wp-css.php"] [unique_id "al9Vti7ynBpLeKYztQPMKwAAAAw"]
[Tue Jul 21 08:19:18.782003 2026] [security2:error] [pid 411857:tid 412046] [client 20.197.192.193:48710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/wp-explorer.php"] [unique_id "al9Vti7ynBpLeKYztQPMRQAAADk"]
[Tue Jul 21 08:19:18.905472 2026] [security2:error] [pid 411857:tid 412007] [client 20.197.192.193:48721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/akismet.php"] [unique_id "al9Vti7ynBpLeKYztQPMUQAAABI"]
[Tue Jul 21 08:19:18.987182 2026] [security2:error] [pid 411857:tid 412093] [client 20.197.192.193:62430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/ace2.php"] [unique_id "al9Vti7ynBpLeKYztQPMWQAAAGg"]
[Tue Jul 21 08:19:19.027897 2026] [security2:error] [pid 411857:tid 412092] [client 74.249.245.134:47090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/archive.php"] [unique_id "al9Vty7ynBpLeKYztQPMXwAAAGc"]
[Tue Jul 21 08:19:19.066211 2026] [security2:error] [pid 411857:tid 411865] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Vty7ynBpLeKYztQPMYAAAWwY"]
[Tue Jul 21 08:19:19.066376 2026] [security2:error] [pid 411857:tid 412080] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Vty7ynBpLeKYztQPMYAAAWwY"]
[Tue Jul 21 08:19:19.101929 2026] [security2:error] [pid 411857:tid 412098] [client 20.197.192.193:3431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.lotfiimplantes.com.br"] [uri "/ms.php"] [unique_id "al9Vty7ynBpLeKYztQPMZQAAAG0"]
[Tue Jul 21 08:19:19.109645 2026] [security2:error] [pid 411857:tid 412071] [client 20.151.10.161:46062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/goods.php"] [unique_id "al9Vty7ynBpLeKYztQPMZgAAAFI"]
[Tue Jul 21 08:19:19.177613 2026] [security2:error] [pid 411857:tid 411918] [remote 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vty7ynBpLeKYztQPMaQAAETs"]
[Tue Jul 21 08:19:19.177731 2026] [security2:error] [pid 411857:tid 412006] [client 2409:40c2:4043:e3ee:b16a:dfb8:8b40:cafb:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "conquisteemcasa.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vty7ynBpLeKYztQPMaQAAETs"]
[Tue Jul 21 08:19:19.293642 2026] [security2:error] [pid 411857:tid 412031] [client 20.206.105.145:25529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/f35.update.php"] [unique_id "al9Vty7ynBpLeKYztQPMcgAAACo"]
[Tue Jul 21 08:19:19.677701 2026] [security2:error] [pid 411857:tid 412024] [client 20.206.105.145:25124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/f900.php"] [unique_id "al9Vty7ynBpLeKYztQPMpwAAACM"]
[Tue Jul 21 08:19:19.790778 2026] [security2:error] [pid 411857:tid 412006] [client 20.226.60.151:60549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wicked.php"] [unique_id "al9Vty7ynBpLeKYztQPMtQAAABE"]
[Tue Jul 21 08:19:19.977504 2026] [security2:error] [pid 411857:tid 412014] [client 20.226.60.151:64110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/qqqa.php"] [unique_id "al9Vty7ynBpLeKYztQPMzQAAABk"]
[Tue Jul 21 08:19:20.167020 2026] [security2:error] [pid 411857:tid 412001] [client 20.206.105.145:25109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/xmrl.php"] [unique_id "al9VuC7ynBpLeKYztQPM0wAAAAw"]
[Tue Jul 21 08:19:20.565019 2026] [security2:error] [pid 411857:tid 411960] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VuC7ynBpLeKYztQPM5wAAMmQ"]
[Tue Jul 21 08:19:20.565195 2026] [security2:error] [pid 411857:tid 412039] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VuC7ynBpLeKYztQPM5wAAMmQ"]
[Tue Jul 21 08:19:20.658040 2026] [security2:error] [pid 411857:tid 412080] [client 65.21.113.253:47522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VuC7ynBpLeKYztQPM1QAAAFs"]
[Tue Jul 21 08:19:20.901825 2026] [security2:error] [pid 411857:tid 412107] [client 20.206.105.145:25474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/memberfuns.php"] [unique_id "al9VuC7ynBpLeKYztQPM8wAAAHY"]
[Tue Jul 21 08:19:20.934402 2026] [security2:error] [pid 411857:tid 412083] [client 223.181.60.88:3060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VuC7ynBpLeKYztQPM9QAAAF4"]
[Tue Jul 21 08:19:20.934599 2026] [security2:error] [pid 411857:tid 412083] [client 223.181.60.88:3060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9VuC7ynBpLeKYztQPM9QAAAF4"]
[Tue Jul 21 08:19:21.019963 2026] [security2:error] [pid 411857:tid 412036] [client 154.208.47.43:65467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VuS7ynBpLeKYztQPM-wAAAC8"]
[Tue Jul 21 08:19:21.020074 2026] [security2:error] [pid 411857:tid 412036] [client 154.208.47.43:65467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9VuS7ynBpLeKYztQPM-wAAAC8"]
[Tue Jul 21 08:19:21.083248 2026] [security2:error] [pid 411857:tid 412114] [client 20.220.225.223:38671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/ah25.php"] [unique_id "al9VuS7ynBpLeKYztQPM_wAAAH0"]
[Tue Jul 21 08:19:21.191370 2026] [security2:error] [pid 411857:tid 411873] [remote 103.57.220.209:36256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.57.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goldentrips40.com"] [uri "/wp-login.php"] [unique_id "al9VuS7ynBpLeKYztQPNAwAASA4"]
[Tue Jul 21 08:19:21.230321 2026] [security2:error] [pid 411857:tid 412116] [client 74.249.245.134:53996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/amax.php"] [unique_id "al9VuS7ynBpLeKYztQPNCAAAAH8"]
[Tue Jul 21 08:19:21.325104 2026] [security2:error] [pid 411857:tid 412055] [client 65.21.113.253:50400] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VuC7ynBpLeKYztQPM8gAAAEI"]
[Tue Jul 21 08:19:21.342970 2026] [security2:error] [pid 411857:tid 412025] [client 20.226.60.151:64004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/aunmc.php"] [unique_id "al9VuS7ynBpLeKYztQPNCQAAACQ"]
[Tue Jul 21 08:19:21.510620 2026] [security2:error] [pid 411857:tid 412023] [client 38.100.221.102:18365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VuS7ynBpLeKYztQPNEQAAACI"]
[Tue Jul 21 08:19:21.510751 2026] [security2:error] [pid 411857:tid 412023] [client 38.100.221.102:18365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VuS7ynBpLeKYztQPNEQAAACI"]
[Tue Jul 21 08:19:22.001732 2026] [security2:error] [pid 411857:tid 411892] [remote 74.7.243.203:56178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giovanoniadv.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VuC7ynBpLeKYztQPM7AAANiE"], referer: https://giovanoniadv.com.br/category/uncategorized/
[Tue Jul 21 08:19:22.148323 2026] [security2:error] [pid 411857:tid 412076] [client 115.134.11.136:63318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vui7ynBpLeKYztQPNJwAAAFc"]
[Tue Jul 21 08:19:22.148790 2026] [security2:error] [pid 411857:tid 412076] [client 115.134.11.136:63318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vui7ynBpLeKYztQPNJwAAAFc"]
[Tue Jul 21 08:19:22.172423 2026] [security2:error] [pid 411857:tid 412069] [client 20.226.60.151:64067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/uoocf.php"] [unique_id "al9Vui7ynBpLeKYztQPNKAAAAFA"]
[Tue Jul 21 08:19:22.460976 2026] [security2:error] [pid 411857:tid 412049] [client 20.220.225.223:38719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/8.php"] [unique_id "al9Vui7ynBpLeKYztQPNZwAAADw"]
[Tue Jul 21 08:19:22.480718 2026] [security2:error] [pid 411857:tid 412055] [client 187.125.243.197:59942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Vui7ynBpLeKYztQPNaAAAAEI"]
[Tue Jul 21 08:19:22.480839 2026] [security2:error] [pid 411857:tid 412055] [client 187.125.243.197:59942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Vui7ynBpLeKYztQPNaAAAAEI"]
[Tue Jul 21 08:19:22.537027 2026] [security2:error] [pid 411857:tid 412080] [client 152.59.34.51:54574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Vui7ynBpLeKYztQPNbQAAAFs"]
[Tue Jul 21 08:19:22.537131 2026] [security2:error] [pid 411857:tid 412080] [client 152.59.34.51:54574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Vui7ynBpLeKYztQPNbQAAAFs"]
[Tue Jul 21 08:19:22.953974 2026] [security2:error] [pid 411857:tid 412001] [client 198.54.129.60:45160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Vui7ynBpLeKYztQPNgAAAAAw"]
[Tue Jul 21 08:19:22.954120 2026] [security2:error] [pid 411857:tid 412001] [client 198.54.129.60:45160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Vui7ynBpLeKYztQPNgAAAAAw"]
[Tue Jul 21 08:19:23.007043 2026] [security2:error] [pid 411857:tid 412029] [client 20.206.105.145:25537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/ms.php"] [unique_id "al9Vuy7ynBpLeKYztQPNhwAAACg"]
[Tue Jul 21 08:19:23.081923 2026] [security2:error] [pid 411857:tid 411955] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vuy7ynBpLeKYztQPNjAAAJ18"]
[Tue Jul 21 08:19:23.082046 2026] [security2:error] [pid 411857:tid 412028] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vuy7ynBpLeKYztQPNjAAAJ18"]
[Tue Jul 21 08:19:23.100057 2026] [security2:error] [pid 411857:tid 411921] [remote 103.28.36.106:47582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9Vuy7ynBpLeKYztQPNjQAAET4"]
[Tue Jul 21 08:19:23.424505 2026] [security2:error] [pid 411857:tid 412023] [client 91.92.47.112:45352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/portal/phpinfo.php"] [unique_id "al9Vuy7ynBpLeKYztQPNnAAAACI"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:19:23.446579 2026] [security2:error] [pid 411857:tid 412101] [client 20.151.10.161:45903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/ms-edit.php"] [unique_id "al9Vuy7ynBpLeKYztQPNnQAAAHA"]
[Tue Jul 21 08:19:23.477855 2026] [security2:error] [pid 411857:tid 412058] [client 91.92.47.112:45362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/server_info.php"] [unique_id "al9Vuy7ynBpLeKYztQPNoAAAAEU"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:19:23.482290 2026] [security2:error] [pid 411857:tid 412112] [client 91.92.47.112:45376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/php_info.php"] [unique_id "al9Vuy7ynBpLeKYztQPNoQAAAHs"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:19:23.516232 2026] [security2:error] [pid 411857:tid 412092] [client 91.92.47.112:45396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/functions.php"] [unique_id "al9Vuy7ynBpLeKYztQPNqgAAAGc"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:19:23.536965 2026] [security2:error] [pid 411857:tid 412057] [client 91.92.47.112:45406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/configuration.php"] [unique_id "al9Vuy7ynBpLeKYztQPNrQAAAEQ"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:19:23.565583 2026] [security2:error] [pid 411857:tid 412115] [client 20.226.60.151:59272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/iywwi.php"] [unique_id "al9Vuy7ynBpLeKYztQPNsQAAAH4"]
[Tue Jul 21 08:19:23.578943 2026] [security2:error] [pid 411857:tid 411958] [remote 156.59.198.136:20888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/wp-content/uploads/2025/09/photo21-2-780x780.webp"] [unique_id "al9Vuy7ynBpLeKYztQPNswAAfWI"], referer: https://powerflats.com.br/imoveis/flat-mobiliado-usa-practical-life-vila-nova-conceicao-sp/
[Tue Jul 21 08:19:23.592975 2026] [security2:error] [pid 411857:tid 412091] [client 91.92.47.112:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/index.php"] [unique_id "al9Vuy7ynBpLeKYztQPNtAAAAGY"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:19:23.608327 2026] [security2:error] [pid 411857:tid 412006] [client 91.92.47.112:45448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/phpinfo/info.php"] [unique_id "al9Vuy7ynBpLeKYztQPNvgAAABE"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:19:23.614554 2026] [security2:error] [pid 411857:tid 412064] [client 91.92.47.112:45454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/pinfo.php"] [unique_id "al9Vuy7ynBpLeKYztQPNvwAAAEs"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:19:23.649054 2026] [security2:error] [pid 411857:tid 412039] [client 91.92.47.112:45490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tabelionatoportoalegre.com.br"] [uri "/test.php"] [unique_id "al9Vuy7ynBpLeKYztQPNxwAAADI"], referer: http://tabelionatoportoalegre.com.br/
[Tue Jul 21 08:19:23.856548 2026] [security2:error] [pid 411857:tid 412045] [client 65.21.113.253:50400] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vuy7ynBpLeKYztQPNmgAAADg"]
[Tue Jul 21 08:19:23.862414 2026] [security2:error] [pid 411857:tid 412092] [client 74.249.245.134:59725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/moon.php"] [unique_id "al9Vuy7ynBpLeKYztQPNzgAAAGc"]
[Tue Jul 21 08:19:24.238937 2026] [security2:error] [pid 411857:tid 411867] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9VvC7ynBpLeKYztQPN8wAAAAg"]
[Tue Jul 21 08:19:24.320917 2026] [security2:error] [pid 411857:tid 412080] [client 20.206.105.145:25554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/zz.php"] [unique_id "al9VvC7ynBpLeKYztQPN_AAAAFs"]
[Tue Jul 21 08:19:24.477366 2026] [security2:error] [pid 411857:tid 411993] [client 103.151.46.103:56830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VvC7ynBpLeKYztQPODAAAAAQ"]
[Tue Jul 21 08:19:24.477498 2026] [security2:error] [pid 411857:tid 411993] [client 103.151.46.103:56830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VvC7ynBpLeKYztQPODAAAAAQ"]
[Tue Jul 21 08:19:24.718973 2026] [security2:error] [pid 411857:tid 411877] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9VvC7ynBpLeKYztQPOHAAAEhI"]
[Tue Jul 21 08:19:25.046464 2026] [security2:error] [pid 411857:tid 412114] [client 117.213.202.34:52709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VvS7ynBpLeKYztQPOKgAAAH0"]
[Tue Jul 21 08:19:25.046602 2026] [security2:error] [pid 411857:tid 412114] [client 117.213.202.34:52709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VvS7ynBpLeKYztQPOKgAAAH0"]
[Tue Jul 21 08:19:25.085982 2026] [security2:error] [pid 411857:tid 412041] [client 20.226.60.151:60562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/24.php"] [unique_id "al9VvS7ynBpLeKYztQPOLAAAADQ"]
[Tue Jul 21 08:19:25.117335 2026] [security2:error] [pid 411857:tid 412048] [client 87.116.180.198:27291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VvS7ynBpLeKYztQPOLgAAADs"]
[Tue Jul 21 08:19:25.117491 2026] [security2:error] [pid 411857:tid 412048] [client 87.116.180.198:27291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VvS7ynBpLeKYztQPOLgAAADs"]
[Tue Jul 21 08:19:25.561419 2026] [security2:error] [pid 411857:tid 411885] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/wp.php"] [unique_id "al9VvS7ynBpLeKYztQPOXgAAbho"]
[Tue Jul 21 08:19:25.655697 2026] [security2:error] [pid 411857:tid 411994] [client 20.226.60.151:64052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/gqgsa.php"] [unique_id "al9VvS7ynBpLeKYztQPObgAAAAU"]
[Tue Jul 21 08:19:25.731722 2026] [security2:error] [pid 411857:tid 412037] [client 65.21.113.253:50400] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VvS7ynBpLeKYztQPOMwAAADA"]
[Tue Jul 21 08:19:25.775041 2026] [security2:error] [pid 411857:tid 411961] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/new.php"] [unique_id "al9VvS7ynBpLeKYztQPOjgAAWmU"]
[Tue Jul 21 08:19:25.965447 2026] [security2:error] [pid 411857:tid 411874] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/class-t.api.php"] [unique_id "al9VvS7ynBpLeKYztQPOnAAAaQ8"]
[Tue Jul 21 08:19:26.192402 2026] [security2:error] [pid 411857:tid 412074] [client 103.106.20.201:52355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vvi7ynBpLeKYztQPOrQAAAFU"]
[Tue Jul 21 08:19:26.192534 2026] [security2:error] [pid 411857:tid 412074] [client 103.106.20.201:52355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vvi7ynBpLeKYztQPOrQAAAFU"]
[Tue Jul 21 08:19:26.201196 2026] [security2:error] [pid 411857:tid 411936] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/plugins.php"] [unique_id "al9Vvi7ynBpLeKYztQPOrgAAP00"]
[Tue Jul 21 08:19:26.235450 2026] [security2:error] [pid 411857:tid 412056] [client 14.245.224.124:51957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Vvi7ynBpLeKYztQPOrwAAAEM"]
[Tue Jul 21 08:19:26.235657 2026] [security2:error] [pid 411857:tid 412056] [client 14.245.224.124:51957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Vvi7ynBpLeKYztQPOrwAAAEM"]
[Tue Jul 21 08:19:26.335222 2026] [security2:error] [pid 411857:tid 412055] [client 162.219.176.3:49212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Vvi7ynBpLeKYztQPOtQAAAEI"]
[Tue Jul 21 08:19:26.335402 2026] [security2:error] [pid 411857:tid 412055] [client 162.219.176.3:49212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Vvi7ynBpLeKYztQPOtQAAAEI"]
[Tue Jul 21 08:19:26.392579 2026] [security2:error] [pid 411857:tid 411890] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/jp.php"] [unique_id "al9Vvi7ynBpLeKYztQPOtwAAVB8"]
[Tue Jul 21 08:19:26.497912 2026] [security2:error] [pid 411857:tid 411863] [remote 216.73.216.184:11452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapa.xml"] [unique_id "al9Vvi7ynBpLeKYztQPOwAAABAQ"]
[Tue Jul 21 08:19:26.580159 2026] [security2:error] [pid 411857:tid 411949] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/error.php"] [unique_id "al9Vvi7ynBpLeKYztQPOwgAAaVo"]
[Tue Jul 21 08:19:26.775678 2026] [security2:error] [pid 411857:tid 411934] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Vvi7ynBpLeKYztQPOzgAAB0s"]
[Tue Jul 21 08:19:26.965591 2026] [security2:error] [pid 411857:tid 411872] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/bless.php"] [unique_id "al9Vvi7ynBpLeKYztQPO0QAAIg0"]
[Tue Jul 21 08:19:27.097414 2026] [security2:error] [pid 411857:tid 412101] [client 20.151.10.161:46058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/222.php"] [unique_id "al9Vvy7ynBpLeKYztQPO3gAAAHA"]
[Tue Jul 21 08:19:27.104595 2026] [security2:error] [pid 411857:tid 412064] [client 20.226.60.151:64081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Vvy7ynBpLeKYztQPO4gAAAEs"]
[Tue Jul 21 08:19:27.145987 2026] [security2:error] [pid 411857:tid 411876] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/storage/index.php"] [unique_id "al9Vvy7ynBpLeKYztQPO5wAABBE"]
[Tue Jul 21 08:19:27.194492 2026] [security2:error] [pid 411857:tid 412060] [client 150.129.202.39:65091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vvy7ynBpLeKYztQPO7AAAAEc"]
[Tue Jul 21 08:19:27.194600 2026] [security2:error] [pid 411857:tid 412060] [client 150.129.202.39:65091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vvy7ynBpLeKYztQPO7AAAAEc"]
[Tue Jul 21 08:19:27.353950 2026] [security2:error] [pid 411857:tid 411976] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/g.php"] [unique_id "al9Vvy7ynBpLeKYztQPO_AAAbHQ"]
[Tue Jul 21 08:19:27.557250 2026] [security2:error] [pid 411857:tid 411936] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/nf.php"] [unique_id "al9Vvy7ynBpLeKYztQPPKgAACk0"]
[Tue Jul 21 08:19:27.737415 2026] [security2:error] [pid 411857:tid 411934] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/xda.php"] [unique_id "al9Vvy7ynBpLeKYztQPPRwAAAUs"]
[Tue Jul 21 08:19:27.827080 2026] [security2:error] [pid 411857:tid 412058] [client 20.226.60.151:64083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/elbzl.php"] [unique_id "al9Vvy7ynBpLeKYztQPPUgAAAEU"]
[Tue Jul 21 08:19:27.880720 2026] [security2:error] [pid 411857:tid 412031] [client 117.210.135.0:53782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vvy7ynBpLeKYztQPPVQAAACo"]
[Tue Jul 21 08:19:27.880839 2026] [security2:error] [pid 411857:tid 412031] [client 117.210.135.0:53782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vvy7ynBpLeKYztQPPVQAAACo"]
[Tue Jul 21 08:19:27.887022 2026] [security2:error] [pid 411857:tid 412095] [client 125.18.144.2:40230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Vvy7ynBpLeKYztQPPVgAAAGo"]
[Tue Jul 21 08:19:27.887109 2026] [security2:error] [pid 411857:tid 412095] [client 125.18.144.2:40230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Vvy7ynBpLeKYztQPPVgAAAGo"]
[Tue Jul 21 08:19:27.924267 2026] [security2:error] [pid 411857:tid 411977] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/shell.php"] [unique_id "al9Vvy7ynBpLeKYztQPPYgAAJnU"]
[Tue Jul 21 08:19:28.113385 2026] [security2:error] [pid 411857:tid 412048] [client 74.249.245.134:21949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/ws83.php"] [unique_id "al9VwC7ynBpLeKYztQPPeQAAADs"]
[Tue Jul 21 08:19:28.124494 2026] [security2:error] [pid 411857:tid 411946] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/3.php"] [unique_id "al9VwC7ynBpLeKYztQPPewAABlc"]
[Tue Jul 21 08:19:28.353830 2026] [security2:error] [pid 411857:tid 411867] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/mds.php"] [unique_id "al9VwC7ynBpLeKYztQPPhQAANwg"]
[Tue Jul 21 08:19:28.512824 2026] [security2:error] [pid 411857:tid 412030] [client 20.206.105.145:25434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/for.php"] [unique_id "al9VwC7ynBpLeKYztQPPjQAAACk"]
[Tue Jul 21 08:19:28.550649 2026] [security2:error] [pid 411857:tid 411983] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/archive.php"] [unique_id "al9VwC7ynBpLeKYztQPPkAAAVHs"]
[Tue Jul 21 08:19:28.563154 2026] [security2:error] [pid 411857:tid 411887] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VwC7ynBpLeKYztQPPkQAAZxw"]
[Tue Jul 21 08:19:28.563301 2026] [security2:error] [pid 411857:tid 412092] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VwC7ynBpLeKYztQPPkQAAZxw"]
[Tue Jul 21 08:19:28.698454 2026] [security2:error] [pid 411857:tid 412075] [client 20.226.60.151:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9VwC7ynBpLeKYztQPPlwAAAFY"]
[Tue Jul 21 08:19:28.733223 2026] [security2:error] [pid 411857:tid 411889] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/amax.php"] [unique_id "al9VwC7ynBpLeKYztQPPmAAAPB4"]
[Tue Jul 21 08:19:28.754484 2026] [security2:error] [pid 411857:tid 412021] [client 120.56.162.40:59951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VwC7ynBpLeKYztQPPmQAAACA"]
[Tue Jul 21 08:19:28.754597 2026] [security2:error] [pid 411857:tid 412021] [client 120.56.162.40:59951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VwC7ynBpLeKYztQPPmQAAACA"]
[Tue Jul 21 08:19:28.799867 2026] [security2:error] [pid 411857:tid 411871] [remote 39.97.110.217:49594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.110.97.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9VwC7ynBpLeKYztQPPmgAACww"]
[Tue Jul 21 08:19:28.915928 2026] [security2:error] [pid 411857:tid 411947] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/moon.php"] [unique_id "al9VwC7ynBpLeKYztQPPsQAAZ1g"]
[Tue Jul 21 08:19:29.110765 2026] [security2:error] [pid 411857:tid 411863] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/ws83.php"] [unique_id "al9VwS7ynBpLeKYztQPPvAAAVgQ"]
[Tue Jul 21 08:19:29.350359 2026] [security2:error] [pid 411857:tid 412084] [client 61.1.167.83:61944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VwS7ynBpLeKYztQPPxgAAAF8"]
[Tue Jul 21 08:19:29.350543 2026] [security2:error] [pid 411857:tid 412084] [client 61.1.167.83:61944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VwS7ynBpLeKYztQPPxgAAAF8"]
[Tue Jul 21 08:19:29.368730 2026] [autoindex:error] [pid 411857:tid 412039] [client 135.148.195.4:49359] AH01276: Cannot serve directory /home2/rodr9255/mrragrorepresentacoes.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:19:29.650492 2026] [security2:error] [pid 411857:tid 411927] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/CDX1.php"] [unique_id "al9VwS7ynBpLeKYztQPP0AAAEEQ"]
[Tue Jul 21 08:19:29.742474 2026] [security2:error] [pid 411857:tid 411950] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VwS7ynBpLeKYztQPP1gAAJ1s"]
[Tue Jul 21 08:19:29.742696 2026] [security2:error] [pid 411857:tid 412028] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VwS7ynBpLeKYztQPP1gAAJ1s"]
[Tue Jul 21 08:19:29.844091 2026] [security2:error] [pid 411857:tid 411920] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/inputs.php"] [unique_id "al9VwS7ynBpLeKYztQPP2QAABz0"]
[Tue Jul 21 08:19:29.940979 2026] [security2:error] [pid 411857:tid 412020] [client 20.151.10.161:45902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9VwS7ynBpLeKYztQPP3QAAAB8"]
[Tue Jul 21 08:19:30.023480 2026] [security2:error] [pid 411857:tid 411872] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/ms-edit.php"] [unique_id "al9Vwi7ynBpLeKYztQPP5AAAZg0"]
[Tue Jul 21 08:19:30.138761 2026] [security2:error] [pid 411857:tid 412058] [client 65.21.113.253:50400] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VwS7ynBpLeKYztQPP1QAAAEU"]
[Tue Jul 21 08:19:30.220124 2026] [security2:error] [pid 411857:tid 411910] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/simple.php"] [unique_id "al9Vwi7ynBpLeKYztQPP5gAAXzM"]
[Tue Jul 21 08:19:30.331042 2026] [http2:info] [pid 418108:tid 418108] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 08:19:30.402510 2026] [security2:error] [pid 411857:tid 411864] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/404.php"] [unique_id "al9Vwi7ynBpLeKYztQPP8AAAeAU"]
[Tue Jul 21 08:19:30.419386 2026] [security2:error] [pid 411857:tid 412001] [client 74.249.245.134:45363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/CDX1.php"] [unique_id "al9Vwi7ynBpLeKYztQPP8wAAAAw"]
[Tue Jul 21 08:19:30.572819 2026] [security2:error] [pid 411857:tid 412067] [client 65.21.113.253:54698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vwi7ynBpLeKYztQPP7QAAAE4"]
[Tue Jul 21 08:19:30.580163 2026] [security2:error] [pid 411857:tid 411893] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/file3.php"] [unique_id "al9Vwi7ynBpLeKYztQPP9wAATSI"]
[Tue Jul 21 08:19:30.782420 2026] [security2:error] [pid 411857:tid 411977] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/wp-mail.php"] [unique_id "al9Vwi7ynBpLeKYztQPP_AAATnU"]
[Tue Jul 21 08:19:30.968130 2026] [security2:error] [pid 411857:tid 411869] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/about.php"] [unique_id "al9Vwi7ynBpLeKYztQPQBQAADQo"]
[Tue Jul 21 08:19:31.125765 2026] [security2:error] [pid 411857:tid 411922] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Vwy7ynBpLeKYztQPQCwAAXz8"]
[Tue Jul 21 08:19:31.126041 2026] [security2:error] [pid 411857:tid 412084] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Vwy7ynBpLeKYztQPQCwAAXz8"]
[Tue Jul 21 08:19:31.268515 2026] [security2:error] [pid 411857:tid 411908] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/adminfuns.php"] [unique_id "al9Vwy7ynBpLeKYztQPQEAAAOzE"]
[Tue Jul 21 08:19:31.394833 2026] [security2:error] [pid 411857:tid 412083] [client 20.226.60.151:64037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/xyn.php"] [unique_id "al9Vwy7ynBpLeKYztQPQEgAAAF4"]
[Tue Jul 21 08:19:31.411367 2026] [security2:error] [pid 411857:tid 412103] [client 20.226.60.151:64080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/adjig.php"] [unique_id "al9Vwy7ynBpLeKYztQPQEwAAAHI"]
[Tue Jul 21 08:19:31.474309 2026] [security2:error] [pid 411857:tid 411958] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/php8.php"] [unique_id "al9Vwy7ynBpLeKYztQPQFwAAK2I"]
[Tue Jul 21 08:19:31.656275 2026] [security2:error] [pid 411857:tid 411940] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/info.php"] [unique_id "al9Vwy7ynBpLeKYztQPQIAAAflE"]
[Tue Jul 21 08:19:31.794837 2026] [security2:error] [pid 411857:tid 412005] [client 20.151.10.161:45988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Vwy7ynBpLeKYztQPQJAAAABA"]
[Tue Jul 21 08:19:31.815877 2026] [security2:error] [pid 411857:tid 412079] [client 74.249.245.134:58173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/inputs.php"] [unique_id "al9Vwy7ynBpLeKYztQPQJQAAAFo"]
[Tue Jul 21 08:19:31.834532 2026] [security2:error] [pid 411857:tid 412052] [client 223.181.60.88:30589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Vwy7ynBpLeKYztQPQJgAAAD8"]
[Tue Jul 21 08:19:31.834684 2026] [security2:error] [pid 411857:tid 412052] [client 223.181.60.88:30589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Vwy7ynBpLeKYztQPQJgAAAD8"]
[Tue Jul 21 08:19:32.016414 2026] [security2:error] [pid 411857:tid 412010] [client 20.226.60.151:60552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/xacs.php"] [unique_id "al9VxC7ynBpLeKYztQPQLQAAABU"]
[Tue Jul 21 08:19:32.054276 2026] [security2:error] [pid 411857:tid 412113] [client 38.100.221.102:17546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VxC7ynBpLeKYztQPQMAAAAHw"]
[Tue Jul 21 08:19:32.054397 2026] [security2:error] [pid 411857:tid 412113] [client 38.100.221.102:17546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VxC7ynBpLeKYztQPQMAAAAHw"]
[Tue Jul 21 08:19:32.067672 2026] [security2:error] [pid 411857:tid 412098] [client 20.206.105.145:25409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/yup.php"] [unique_id "al9VxC7ynBpLeKYztQPQMQAAAG0"]
[Tue Jul 21 08:19:32.193551 2026] [security2:error] [pid 411857:tid 412036] [client 65.21.113.253:54698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vwy7ynBpLeKYztQPQIwAAAC8"]
[Tue Jul 21 08:19:32.418964 2026] [security2:error] [pid 411857:tid 412106] [client 86.106.84.166:53300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9VxC7ynBpLeKYztQPQOgAAAHU"]
[Tue Jul 21 08:19:32.419089 2026] [security2:error] [pid 411857:tid 412106] [client 86.106.84.166:53300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9VxC7ynBpLeKYztQPQOgAAAHU"]
[Tue Jul 21 08:19:32.500148 2026] [security2:error] [pid 411857:tid 412114] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cristaofit.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9VxC7ynBpLeKYztQPQPQAAAH0"]
[Tue Jul 21 08:19:32.595603 2026] [security2:error] [pid 411857:tid 411889] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/edit.php"] [unique_id "al9VxC7ynBpLeKYztQPQRAAACh4"]
[Tue Jul 21 08:19:32.599923 2026] [security2:error] [pid 411857:tid 412073] [client 115.134.11.136:63765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VxC7ynBpLeKYztQPQRQAAAFQ"]
[Tue Jul 21 08:19:32.601130 2026] [security2:error] [pid 411857:tid 412073] [client 115.134.11.136:63765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VxC7ynBpLeKYztQPQRQAAAFQ"]
[Tue Jul 21 08:19:32.786094 2026] [security2:error] [pid 411857:tid 411874] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/166.php"] [unique_id "al9VxC7ynBpLeKYztQPQSgAABg8"]
[Tue Jul 21 08:19:32.893775 2026] [security2:error] [pid 411857:tid 412095] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cristaofit.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9VxC7ynBpLeKYztQPQTAAAAGo"]
[Tue Jul 21 08:19:32.956053 2026] [security2:error] [pid 418108:tid 418240] [client 187.125.243.197:60435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VxA0cxofL2J1zwYq-bAAAAQo"]
[Tue Jul 21 08:19:32.956223 2026] [security2:error] [pid 418108:tid 418240] [client 187.125.243.197:60435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9VxA0cxofL2J1zwYq-bAAAAQo"]
[Tue Jul 21 08:19:32.998841 2026] [security2:error] [pid 411857:tid 411925] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/8.php"] [unique_id "al9VxC7ynBpLeKYztQPQTgAAGEI"]
[Tue Jul 21 08:19:33.070352 2026] [security2:error] [pid 411857:tid 412054] [client 103.151.46.103:57312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VxS7ynBpLeKYztQPQUQAAAEE"]
[Tue Jul 21 08:19:33.070475 2026] [security2:error] [pid 411857:tid 412054] [client 103.151.46.103:57312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9VxS7ynBpLeKYztQPQUQAAAEE"]
[Tue Jul 21 08:19:33.292298 2026] [security2:error] [pid 411857:tid 412090] [client 152.59.34.51:55026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VxS7ynBpLeKYztQPQVQAAAGU"]
[Tue Jul 21 08:19:33.292509 2026] [security2:error] [pid 411857:tid 412090] [client 152.59.34.51:55026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9VxS7ynBpLeKYztQPQVQAAAGU"]
[Tue Jul 21 08:19:33.308926 2026] [security2:error] [pid 411857:tid 411978] [remote 41.186.86.12:12633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9VxS7ynBpLeKYztQPQVwAAEHY"]
[Tue Jul 21 08:19:33.311696 2026] [security2:error] [pid 411857:tid 412005] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cristaofit.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9VxS7ynBpLeKYztQPQWAAAABA"]
[Tue Jul 21 08:19:33.399505 2026] [security2:error] [pid 418108:tid 418253] [client 20.151.10.161:46053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp.php"] [unique_id "al9VxQ0cxofL2J1zwYq-cAAAARc"]
[Tue Jul 21 08:19:33.515210 2026] [security2:error] [pid 411857:tid 412073] [client 86.106.84.166:44856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9VxS7ynBpLeKYztQPQXAAAAFQ"]
[Tue Jul 21 08:19:33.515327 2026] [security2:error] [pid 411857:tid 412073] [client 86.106.84.166:44856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9VxS7ynBpLeKYztQPQXAAAAFQ"]
[Tue Jul 21 08:19:33.718885 2026] [security2:error] [pid 418108:tid 418314] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cristaofit.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9VxQ0cxofL2J1zwYq-dAAAAVQ"]
[Tue Jul 21 08:19:33.735864 2026] [security2:error] [pid 418108:tid 418315] [client 20.226.60.151:64008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/byp.php"] [unique_id "al9VxQ0cxofL2J1zwYq-dQAAAVU"]
[Tue Jul 21 08:19:33.849233 2026] [security2:error] [pid 411857:tid 411970] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VxS7ynBpLeKYztQPQZgAAOG4"]
[Tue Jul 21 08:19:33.849379 2026] [security2:error] [pid 411857:tid 412045] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VxS7ynBpLeKYztQPQZgAAOG4"]
[Tue Jul 21 08:19:34.042628 2026] [security2:error] [pid 411857:tid 412083] [client 74.249.245.134:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/ms-edit.php"] [unique_id "al9Vxi7ynBpLeKYztQPQawAAAF4"]
[Tue Jul 21 08:19:34.063845 2026] [security2:error] [pid 418108:tid 418312] [client 74.7.175.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "geovanebernich1781564101657.0721679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Vxg0cxofL2J1zwYq-eQABUjs"]
[Tue Jul 21 08:19:34.113374 2026] [security2:error] [pid 411857:tid 412093] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cristaofit.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Vxi7ynBpLeKYztQPQbQAAAGg"]
[Tue Jul 21 08:19:34.193743 2026] [security2:error] [pid 411857:tid 411898] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/ws38.php"] [unique_id "al9Vxi7ynBpLeKYztQPQcgAACic"]
[Tue Jul 21 08:19:34.299247 2026] [security2:error] [pid 411857:tid 412006] [client 74.7.241.185:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "joaogabrielsantossou1748363801234.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9Vxi7ynBpLeKYztQPQdQAAEUc"]
[Tue Jul 21 08:19:34.410243 2026] [security2:error] [pid 411857:tid 412039] [client 20.226.60.151:64098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/patie.php"] [unique_id "al9Vxi7ynBpLeKYztQPQewAAADI"]
[Tue Jul 21 08:19:34.511443 2026] [security2:error] [pid 411857:tid 412070] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cristaofit.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Vxi7ynBpLeKYztQPQfQAAAFE"]
[Tue Jul 21 08:19:34.538256 2026] [security2:error] [pid 418108:tid 418313] [client 20.226.60.151:60576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/zildan.php"] [unique_id "al9Vxg0cxofL2J1zwYq-ewAAAVM"]
[Tue Jul 21 08:19:34.651743 2026] [security2:error] [pid 411857:tid 412076] [client 65.21.113.253:54698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vxi7ynBpLeKYztQPQcQAAAFc"]
[Tue Jul 21 08:19:34.716619 2026] [security2:error] [pid 411857:tid 411991] [client 154.208.47.43:1448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Vxi7ynBpLeKYztQPQhAAAAAI"]
[Tue Jul 21 08:19:34.716781 2026] [security2:error] [pid 411857:tid 411991] [client 154.208.47.43:1448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Vxi7ynBpLeKYztQPQhAAAAAI"]
[Tue Jul 21 08:19:34.940439 2026] [security2:error] [pid 411857:tid 412098] [client 20.220.225.223:31123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/red.php"] [unique_id "al9Vxi7ynBpLeKYztQPQjgAAAG0"]
[Tue Jul 21 08:19:34.971010 2026] [security2:error] [pid 418108:tid 418326] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cristaofit.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Vxg0cxofL2J1zwYq-fgAAAWA"]
[Tue Jul 21 08:19:34.992322 2026] [security2:error] [pid 411857:tid 411920] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/a7.php"] [unique_id "al9Vxi7ynBpLeKYztQPQkAAAED0"]
[Tue Jul 21 08:19:35.109113 2026] [security2:error] [pid 411857:tid 412097] [client 20.206.105.145:25099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/wpxml.php"] [unique_id "al9Vxy7ynBpLeKYztQPQlwAAAGw"]
[Tue Jul 21 08:19:35.172103 2026] [security2:error] [pid 411857:tid 411934] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/classsmtps.php"] [unique_id "al9Vxy7ynBpLeKYztQPQmwAAMks"]
[Tue Jul 21 08:19:35.363543 2026] [security2:error] [pid 411857:tid 411928] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/rip.php"] [unique_id "al9Vxy7ynBpLeKYztQPQnQAAZ0U"]
[Tue Jul 21 08:19:35.379977 2026] [security2:error] [pid 411857:tid 412004] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cristaofit.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Vxy7ynBpLeKYztQPQngAAAA8"]
[Tue Jul 21 08:19:35.558306 2026] [security2:error] [pid 411857:tid 411864] [remote 74.249.245.134:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "climadek.com.br"] [uri "/1.php"] [unique_id "al9Vxy7ynBpLeKYztQPQpwAAJwU"]
[Tue Jul 21 08:19:35.558415 2026] [security2:error] [pid 411857:tid 411864] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/1.php"] [unique_id "al9Vxy7ynBpLeKYztQPQpwAAJwU"]
[Tue Jul 21 08:19:35.664262 2026] [security2:error] [pid 411857:tid 412062] [client 117.213.202.34:53286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vxy7ynBpLeKYztQPQrQAAAEk"]
[Tue Jul 21 08:19:35.664364 2026] [security2:error] [pid 411857:tid 412062] [client 117.213.202.34:53286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vxy7ynBpLeKYztQPQrQAAAEk"]
[Tue Jul 21 08:19:35.736245 2026] [security2:error] [pid 411857:tid 411876] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/chosen.php"] [unique_id "al9Vxy7ynBpLeKYztQPQrgAAXhE"]
[Tue Jul 21 08:19:35.798586 2026] [security2:error] [pid 411857:tid 412029] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cristaofit.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Vxy7ynBpLeKYztQPQsAAAACg"]
[Tue Jul 21 08:19:35.843467 2026] [security2:error] [pid 411857:tid 412000] [client 87.116.180.198:27342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vxy7ynBpLeKYztQPQsQAAAAs"]
[Tue Jul 21 08:19:35.844058 2026] [security2:error] [pid 411857:tid 412000] [client 87.116.180.198:27342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vxy7ynBpLeKYztQPQsQAAAAs"]
[Tue Jul 21 08:19:35.942899 2026] [security2:error] [pid 411857:tid 411866] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/css.php"] [unique_id "al9Vxy7ynBpLeKYztQPQtAAAAwc"]
[Tue Jul 21 08:19:36.103126 2026] [security2:error] [pid 418108:tid 418345] [client 74.249.245.134:44086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/simple.php"] [unique_id "al9VyA0cxofL2J1zwYq-iAAAAXM"]
[Tue Jul 21 08:19:36.183223 2026] [security2:error] [pid 411857:tid 412108] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cristaofit.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9VyC7ynBpLeKYztQPQwQAAAHc"]
[Tue Jul 21 08:19:36.196940 2026] [security2:error] [pid 411857:tid 411986] [remote 46.105.28.235:46354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kaducontractor.com"] [uri "/wp-login.php"] [unique_id "al9VyC7ynBpLeKYztQPQwwAAYH4"]
[Tue Jul 21 08:19:36.551974 2026] [security2:error] [pid 411857:tid 412028] [client 20.206.105.145:25530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/fffm.php"] [unique_id "al9VyC7ynBpLeKYztQPQ0gAAACc"]
[Tue Jul 21 08:19:36.575532 2026] [security2:error] [pid 418108:tid 418212] [remote 5.252.52.249:52828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/wp-login.php"] [unique_id "al9VyA0cxofL2J1zwYq-jwABbGU"]
[Tue Jul 21 08:19:36.580265 2026] [security2:error] [pid 418108:tid 418359] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cristaofit.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9VyA0cxofL2J1zwYq-kAAAAYE"]
[Tue Jul 21 08:19:36.658557 2026] [security2:error] [pid 411857:tid 412017] [client 14.245.224.124:52396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VyC7ynBpLeKYztQPQ1AAAABw"]
[Tue Jul 21 08:19:36.658701 2026] [security2:error] [pid 411857:tid 412017] [client 14.245.224.124:52396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9VyC7ynBpLeKYztQPQ1AAAABw"]
[Tue Jul 21 08:19:36.675608 2026] [security2:error] [pid 411857:tid 412073] [client 20.151.10.161:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/abcd.php"] [unique_id "al9VyC7ynBpLeKYztQPQ1wAAAFQ"]
[Tue Jul 21 08:19:36.698220 2026] [security2:error] [pid 411857:tid 412074] [client 65.21.113.253:54698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VyC7ynBpLeKYztQPQwgAAAFU"]
[Tue Jul 21 08:19:36.730303 2026] [security2:error] [pid 418108:tid 418350] [client 151.63.71.144:58980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9VyA0cxofL2J1zwYq-kQAAAXg"]
[Tue Jul 21 08:19:36.730480 2026] [security2:error] [pid 418108:tid 418350] [client 151.63.71.144:58980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9VyA0cxofL2J1zwYq-kQAAAXg"]
[Tue Jul 21 08:19:36.947500 2026] [security2:error] [pid 411857:tid 412007] [client 103.106.20.201:52942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VyC7ynBpLeKYztQPQ2gAAABI"]
[Tue Jul 21 08:19:36.947598 2026] [security2:error] [pid 411857:tid 412007] [client 103.106.20.201:52942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VyC7ynBpLeKYztQPQ2gAAABI"]
[Tue Jul 21 08:19:36.972500 2026] [security2:error] [pid 418108:tid 418365] [client 74.249.245.134:51041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/404.php"] [unique_id "al9VyA0cxofL2J1zwYq-kgAAAYc"]
[Tue Jul 21 08:19:37.003487 2026] [security2:error] [pid 411857:tid 412061] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cristaofit.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9VyS7ynBpLeKYztQPQ3AAAAEg"]
[Tue Jul 21 08:19:37.257608 2026] [security2:error] [pid 411857:tid 411913] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/php.php"] [unique_id "al9VyS7ynBpLeKYztQPQ6AAABDY"]
[Tue Jul 21 08:19:37.450956 2026] [security2:error] [pid 411857:tid 411940] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/aa.php"] [unique_id "al9VyS7ynBpLeKYztQPQ6gAAYFE"]
[Tue Jul 21 08:19:37.630728 2026] [security2:error] [pid 411857:tid 411946] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/bolt.php"] [unique_id "al9VyS7ynBpLeKYztQPQ7wAAFVc"]
[Tue Jul 21 08:19:37.781271 2026] [security2:error] [pid 411857:tid 412091] [client 150.129.202.39:12844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VyS7ynBpLeKYztQPQ8wAAAGY"]
[Tue Jul 21 08:19:37.781373 2026] [security2:error] [pid 411857:tid 412091] [client 150.129.202.39:12844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VyS7ynBpLeKYztQPQ8wAAAGY"]
[Tue Jul 21 08:19:37.821679 2026] [security2:error] [pid 411857:tid 411943] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/x.php"] [unique_id "al9VyS7ynBpLeKYztQPQ9gAALFQ"]
[Tue Jul 21 08:19:37.841529 2026] [security2:error] [pid 411857:tid 412047] [client 117.210.135.0:54415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VyS7ynBpLeKYztQPQ9wAAADo"]
[Tue Jul 21 08:19:37.841681 2026] [security2:error] [pid 411857:tid 412047] [client 117.210.135.0:54415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9VyS7ynBpLeKYztQPQ9wAAADo"]
[Tue Jul 21 08:19:38.024158 2026] [security2:error] [pid 411857:tid 411983] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/jga.php"] [unique_id "al9Vyi7ynBpLeKYztQPQ-wAAY3s"]
[Tue Jul 21 08:19:38.166554 2026] [security2:error] [pid 411857:tid 411889] [remote 74.7.243.203:56178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giovanoniadv.com.br"] [uri "/wp-login.php"] [unique_id "al9Vyi7ynBpLeKYztQPRAgAAdB4"], referer: https://giovanoniadv.com.br/wp-admin/
[Tue Jul 21 08:19:38.204713 2026] [security2:error] [pid 411857:tid 412075] [client 20.226.60.151:64045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9Vyi7ynBpLeKYztQPRBAAAAFY"]
[Tue Jul 21 08:19:38.221034 2026] [security2:error] [pid 411857:tid 411953] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/k.php"] [unique_id "al9Vyi7ynBpLeKYztQPRBQAAEl0"]
[Tue Jul 21 08:19:38.227231 2026] [security2:error] [pid 411857:tid 411961] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9Vyi7ynBpLeKYztQPRBgAAaGU"]
[Tue Jul 21 08:19:38.227371 2026] [security2:error] [pid 411857:tid 412093] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9Vyi7ynBpLeKYztQPRBgAAaGU"]
[Tue Jul 21 08:19:38.328321 2026] [security2:error] [pid 411857:tid 412111] [client 74.249.245.134:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/file3.php"] [unique_id "al9Vyi7ynBpLeKYztQPRDgAAAHo"]
[Tue Jul 21 08:19:38.423085 2026] [security2:error] [pid 411857:tid 411895] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/vx.php"] [unique_id "al9Vyi7ynBpLeKYztQPREgAAFiQ"]
[Tue Jul 21 08:19:38.497136 2026] [security2:error] [pid 418108:tid 418283] [client 125.18.144.2:59034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Vyg0cxofL2J1zwYq-mAAAATU"]
[Tue Jul 21 08:19:38.497270 2026] [security2:error] [pid 418108:tid 418283] [client 125.18.144.2:59034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Vyg0cxofL2J1zwYq-mAAAATU"]
[Tue Jul 21 08:19:38.612391 2026] [security2:error] [pid 411857:tid 411942] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/ws77.php"] [unique_id "al9Vyi7ynBpLeKYztQPRHAAALFM"]
[Tue Jul 21 08:19:38.678930 2026] [security2:error] [pid 411857:tid 412062] [client 65.21.113.253:54698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vyi7ynBpLeKYztQPRAwAAAEk"]
[Tue Jul 21 08:19:38.806793 2026] [security2:error] [pid 411857:tid 411899] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/2.php"] [unique_id "al9Vyi7ynBpLeKYztQPRIAAAWyg"]
[Tue Jul 21 08:19:39.041293 2026] [security2:error] [pid 411857:tid 411861] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/asd.php"] [unique_id "al9Vyy7ynBpLeKYztQPRKgAAVAI"]
[Tue Jul 21 08:19:39.095833 2026] [security2:error] [pid 411857:tid 411947] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vyy7ynBpLeKYztQPRLQAAQVg"]
[Tue Jul 21 08:19:39.095983 2026] [security2:error] [pid 411857:tid 412054] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vyy7ynBpLeKYztQPRLQAAQVg"]
[Tue Jul 21 08:19:39.224234 2026] [security2:error] [pid 411857:tid 411863] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/default.php"] [unique_id "al9Vyy7ynBpLeKYztQPRMQAAEgQ"]
[Tue Jul 21 08:19:39.397237 2026] [security2:error] [pid 411857:tid 412106] [client 120.56.162.40:60448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vyy7ynBpLeKYztQPRNQAAAHU"]
[Tue Jul 21 08:19:39.397355 2026] [security2:error] [pid 411857:tid 412106] [client 120.56.162.40:60448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vyy7ynBpLeKYztQPRNQAAAHU"]
[Tue Jul 21 08:19:39.404207 2026] [security2:error] [pid 411857:tid 411949] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/gettest.php"] [unique_id "al9Vyy7ynBpLeKYztQPRNgAATVo"]
[Tue Jul 21 08:19:39.494414 2026] [security2:error] [pid 418108:tid 418251] [client 61.1.167.83:62456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vyw0cxofL2J1zwYq-pwAAARU"]
[Tue Jul 21 08:19:39.494560 2026] [security2:error] [pid 418108:tid 418251] [client 61.1.167.83:62456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vyw0cxofL2J1zwYq-pwAAARU"]
[Tue Jul 21 08:19:39.588512 2026] [security2:error] [pid 418108:tid 418259] [client 20.206.105.145:25593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/gecko.php"] [unique_id "al9Vyw0cxofL2J1zwYq-qQAAAR0"]
[Tue Jul 21 08:19:39.624004 2026] [security2:error] [pid 411857:tid 411966] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/tfm.php"] [unique_id "al9Vyy7ynBpLeKYztQPROgAALmo"]
[Tue Jul 21 08:19:39.685735 2026] [security2:error] [pid 418108:tid 418255] [client 20.226.60.151:64017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/aa.php"] [unique_id "al9Vyw0cxofL2J1zwYq-qwAAARk"]
[Tue Jul 21 08:19:39.856681 2026] [security2:error] [pid 411857:tid 411926] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/ws81.php"] [unique_id "al9Vyy7ynBpLeKYztQPRWgAAPEM"]
[Tue Jul 21 08:19:39.865769 2026] [security2:error] [pid 418108:tid 418307] [client 20.151.10.161:45906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/a1.php"] [unique_id "al9Vyw0cxofL2J1zwYq-rgAAAU0"]
[Tue Jul 21 08:19:39.973687 2026] [security2:error] [pid 411857:tid 412091] [client 74.249.245.134:62834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/wp-mail.php"] [unique_id "al9Vyy7ynBpLeKYztQPRXAAAAGY"]
[Tue Jul 21 08:19:40.035386 2026] [security2:error] [pid 411857:tid 411960] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/222.php"] [unique_id "al9VzC7ynBpLeKYztQPRXgAAfmQ"]
[Tue Jul 21 08:19:40.212656 2026] [security2:error] [pid 411857:tid 411976] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/t.php"] [unique_id "al9VzC7ynBpLeKYztQPRZgAAEXQ"]
[Tue Jul 21 08:19:40.389826 2026] [security2:error] [pid 411857:tid 411957] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/a.php"] [unique_id "al9VzC7ynBpLeKYztQPRbAAAdGE"]
[Tue Jul 21 08:19:40.394122 2026] [security2:error] [pid 418108:tid 418219] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VzA0cxofL2J1zwYq-sQABUmw"]
[Tue Jul 21 08:19:40.394271 2026] [security2:error] [pid 418108:tid 418312] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9VzA0cxofL2J1zwYq-sQABUmw"]
[Tue Jul 21 08:19:40.422289 2026] [security2:error] [pid 411857:tid 412044] [client 62.102.148.158:59588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9VzC7ynBpLeKYztQPRbQAAADc"]
[Tue Jul 21 08:19:40.422421 2026] [security2:error] [pid 411857:tid 412044] [client 62.102.148.158:59588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9VzC7ynBpLeKYztQPRbQAAADc"]
[Tue Jul 21 08:19:40.573440 2026] [security2:error] [pid 411857:tid 412092] [client 65.21.113.253:54698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VzC7ynBpLeKYztQPRYQAAAGc"]
[Tue Jul 21 08:19:40.799850 2026] [security2:error] [pid 418108:tid 418332] [client 20.220.225.223:31190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/fffm.php"] [unique_id "al9VzA0cxofL2J1zwYq-tQAAAWY"]
[Tue Jul 21 08:19:40.886768 2026] [security2:error] [pid 411857:tid 411940] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/a1.php"] [unique_id "al9VzC7ynBpLeKYztQPRdgAATlE"]
[Tue Jul 21 08:19:41.019855 2026] [security2:error] [pid 411857:tid 412024] [client 198.54.129.60:46862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9VzS7ynBpLeKYztQPRfwAAACM"]
[Tue Jul 21 08:19:41.019990 2026] [security2:error] [pid 411857:tid 412024] [client 198.54.129.60:46862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9VzS7ynBpLeKYztQPRfwAAACM"]
[Tue Jul 21 08:19:41.356566 2026] [security2:error] [pid 411857:tid 411995] [client 198.54.129.60:37770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9VzS7ynBpLeKYztQPRiAAAAAY"]
[Tue Jul 21 08:19:41.356721 2026] [security2:error] [pid 411857:tid 411995] [client 198.54.129.60:37770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9VzS7ynBpLeKYztQPRiAAAAAY"]
[Tue Jul 21 08:19:41.379629 2026] [security2:error] [pid 411857:tid 411983] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/w.php"] [unique_id "al9VzS7ynBpLeKYztQPRiwAASXs"]
[Tue Jul 21 08:19:41.566777 2026] [security2:error] [pid 411857:tid 411861] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/wp-good.php"] [unique_id "al9VzS7ynBpLeKYztQPRpAAAUQI"]
[Tue Jul 21 08:19:41.589444 2026] [security2:error] [pid 411857:tid 412034] [client 74.249.245.134:48093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/about.php"] [unique_id "al9VzS7ynBpLeKYztQPRqAAAAC0"]
[Tue Jul 21 08:19:41.641757 2026] [security2:error] [pid 411857:tid 412114] [client 20.226.60.151:59304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9VzS7ynBpLeKYztQPRsQAAAH0"]
[Tue Jul 21 08:19:41.679981 2026] [security2:error] [pid 411857:tid 411949] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VzS7ynBpLeKYztQPRtAAAOlo"]
[Tue Jul 21 08:19:41.680119 2026] [security2:error] [pid 411857:tid 412047] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9VzS7ynBpLeKYztQPRtAAAOlo"]
[Tue Jul 21 08:19:41.822496 2026] [security2:error] [pid 418108:tid 418353] [client 20.226.60.151:60574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/csa.php"] [unique_id "al9VzQ0cxofL2J1zwYq-uwAAAXs"]
[Tue Jul 21 08:19:42.208345 2026] [security2:error] [pid 418108:tid 418327] [client 154.208.47.43:1921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Vzg0cxofL2J1zwYq-vwAAAWE"]
[Tue Jul 21 08:19:42.208513 2026] [security2:error] [pid 418108:tid 418327] [client 154.208.47.43:1921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Vzg0cxofL2J1zwYq-vwAAAWE"]
[Tue Jul 21 08:19:42.224874 2026] [security2:error] [pid 411857:tid 411935] [remote 74.249.245.134:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "climadek.com.br"] [uri "/.info.php"] [unique_id "al9Vzi7ynBpLeKYztQPRwAAAYEw"]
[Tue Jul 21 08:19:42.234701 2026] [security2:error] [pid 411857:tid 412022] [client 74.7.228.22:46804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.gradiente.com.br.gradiente.com"] [uri "/cgi-sys/404.html"] [unique_id "al9Vzi7ynBpLeKYztQPRwQAAIUU"]
[Tue Jul 21 08:19:42.241954 2026] [autoindex:error] [pid 411857:tid 411986] [remote 74.7.227.9:57464] AH01276: Cannot serve directory /home2/rica0429/gradiente.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:19:42.413119 2026] [security2:error] [pid 411857:tid 411952] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/item.php"] [unique_id "al9Vzi7ynBpLeKYztQPRygAAPFw"]
[Tue Jul 21 08:19:42.459796 2026] [security2:error] [pid 411857:tid 412086] [client 65.21.113.253:54698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9VzS7ynBpLeKYztQPRvAAAAGE"]
[Tue Jul 21 08:19:42.594032 2026] [security2:error] [pid 418108:tid 418356] [client 38.100.221.102:17161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vzg0cxofL2J1zwYq-wgAAAX4"]
[Tue Jul 21 08:19:42.594192 2026] [security2:error] [pid 418108:tid 418356] [client 38.100.221.102:17161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Vzg0cxofL2J1zwYq-wgAAAX4"]
[Tue Jul 21 08:19:42.594472 2026] [security2:error] [pid 411857:tid 411927] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/albin.php"] [unique_id "al9Vzi7ynBpLeKYztQPR0AAAY0Q"]
[Tue Jul 21 08:19:42.775281 2026] [security2:error] [pid 411857:tid 411903] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/alfa.php"] [unique_id "al9Vzi7ynBpLeKYztQPR1QAATSw"]
[Tue Jul 21 08:19:42.787532 2026] [security2:error] [pid 411857:tid 412079] [client 74.249.245.134:45313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/adminfuns.php"] [unique_id "al9Vzi7ynBpLeKYztQPR1wAAAFo"]
[Tue Jul 21 08:19:42.966340 2026] [security2:error] [pid 411857:tid 411973] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9Vzi7ynBpLeKYztQPR4wAANnE"]
[Tue Jul 21 08:19:43.143569 2026] [security2:error] [pid 411857:tid 411909] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/av.php"] [unique_id "al9Vzy7ynBpLeKYztQPR5QAAFTI"]
[Tue Jul 21 08:19:43.323547 2026] [security2:error] [pid 411857:tid 411960] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/gg.php"] [unique_id "al9Vzy7ynBpLeKYztQPR7wAAGWQ"]
[Tue Jul 21 08:19:43.340153 2026] [security2:error] [pid 411857:tid 412035] [client 198.54.129.60:37782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Vzy7ynBpLeKYztQPR8AAAAC4"]
[Tue Jul 21 08:19:43.340325 2026] [security2:error] [pid 411857:tid 412035] [client 198.54.129.60:37782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Vzy7ynBpLeKYztQPR8AAAAC4"]
[Tue Jul 21 08:19:43.461893 2026] [security2:error] [pid 418108:tid 418249] [client 187.125.243.197:60924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Vzw0cxofL2J1zwYq-xwAAARM"]
[Tue Jul 21 08:19:43.462010 2026] [security2:error] [pid 418108:tid 418249] [client 187.125.243.197:60924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Vzw0cxofL2J1zwYq-xwAAARM"]
[Tue Jul 21 08:19:43.502687 2026] [security2:error] [pid 411857:tid 411901] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/sql.php"] [unique_id "al9Vzy7ynBpLeKYztQPR9wAAYSo"]
[Tue Jul 21 08:19:43.628961 2026] [security2:error] [pid 411857:tid 412033] [client 20.206.105.145:25133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/a1.php"] [unique_id "al9Vzy7ynBpLeKYztQPR_QAAACw"]
[Tue Jul 21 08:19:43.675940 2026] [security2:error] [pid 418108:tid 418361] [client 103.151.46.103:57807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vzw0cxofL2J1zwYq-yQAAAYM"]
[Tue Jul 21 08:19:43.676555 2026] [security2:error] [pid 418108:tid 418361] [client 103.151.46.103:57807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Vzw0cxofL2J1zwYq-yQAAAYM"]
[Tue Jul 21 08:19:43.679523 2026] [security2:error] [pid 411857:tid 411885] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/up.php"] [unique_id "al9Vzy7ynBpLeKYztQPSAgAATBo"]
[Tue Jul 21 08:19:43.859376 2026] [security2:error] [pid 411857:tid 411869] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/66.php"] [unique_id "al9Vzy7ynBpLeKYztQPSBgAAKAo"]
[Tue Jul 21 08:19:44.084168 2026] [security2:error] [pid 411857:tid 411940] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/666.php"] [unique_id "al9V0C7ynBpLeKYztQPSEAAAU1E"]
[Tue Jul 21 08:19:44.114568 2026] [security2:error] [pid 411857:tid 412101] [client 152.59.34.51:55473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9V0C7ynBpLeKYztQPSEQAAAHA"]
[Tue Jul 21 08:19:44.114763 2026] [security2:error] [pid 411857:tid 412101] [client 152.59.34.51:55473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9V0C7ynBpLeKYztQPSEQAAAHA"]
[Tue Jul 21 08:19:44.278166 2026] [security2:error] [pid 411857:tid 411946] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/byp.php"] [unique_id "al9V0C7ynBpLeKYztQPSFgAAQFc"]
[Tue Jul 21 08:19:44.304349 2026] [security2:error] [pid 411857:tid 412011] [client 115.134.11.136:64210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V0C7ynBpLeKYztQPSFwAAABY"]
[Tue Jul 21 08:19:44.376050 2026] [security2:error] [pid 411857:tid 412016] [client 65.21.113.253:54698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Vzy7ynBpLeKYztQPSBwAAABs"]
[Tue Jul 21 08:19:44.456099 2026] [security2:error] [pid 411857:tid 411860] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/date.php"] [unique_id "al9V0C7ynBpLeKYztQPSHQAABQE"]
[Tue Jul 21 08:19:44.553779 2026] [security2:error] [pid 418108:tid 418265] [client 223.181.60.88:27949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9V0A0cxofL2J1zwYq-1AAAASM"]
[Tue Jul 21 08:19:44.554583 2026] [security2:error] [pid 418108:tid 418265] [client 223.181.60.88:27949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9V0A0cxofL2J1zwYq-1AAAASM"]
[Tue Jul 21 08:19:44.642304 2026] [security2:error] [pid 418108:tid 418204] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V0A0cxofL2J1zwYq-1QABOl0"]
[Tue Jul 21 08:19:44.642460 2026] [security2:error] [pid 418108:tid 418288] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V0A0cxofL2J1zwYq-1QABOl0"]
[Tue Jul 21 08:19:44.715996 2026] [security2:error] [pid 411857:tid 412115] [client 20.226.60.151:64071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/xwpg.php"] [unique_id "al9V0C7ynBpLeKYztQPSJQAAAH4"]
[Tue Jul 21 08:19:44.735116 2026] [security2:error] [pid 411857:tid 411862] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/pomo.php"] [unique_id "al9V0C7ynBpLeKYztQPSJgAAWgM"]
[Tue Jul 21 08:19:44.910473 2026] [security2:error] [pid 411857:tid 411984] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/test1.php"] [unique_id "al9V0C7ynBpLeKYztQPSLAAASHw"]
[Tue Jul 21 08:19:44.978522 2026] [security2:error] [pid 411857:tid 411991] [client 74.249.245.134:43219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/php8.php"] [unique_id "al9V0C7ynBpLeKYztQPSMgAAAAI"]
[Tue Jul 21 08:19:45.110368 2026] [security2:error] [pid 411857:tid 412067] [client 20.206.105.145:25521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/k2.php"] [unique_id "al9V0S7ynBpLeKYztQPSOAAAAE4"]
[Tue Jul 21 08:19:45.121026 2026] [security2:error] [pid 411857:tid 411887] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/fw.php"] [unique_id "al9V0S7ynBpLeKYztQPSOQAAIxw"]
[Tue Jul 21 08:19:45.124842 2026] [security2:error] [pid 411857:tid 412014] [client 20.226.60.151:64049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/root.php"] [unique_id "al9V0S7ynBpLeKYztQPSPAAAABk"]
[Tue Jul 21 08:19:45.125516 2026] [security2:error] [pid 411857:tid 411942] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9V0C7ynBpLeKYztQPSMQAATFM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:19:45.146336 2026] [security2:error] [pid 411857:tid 411978] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9V0C7ynBpLeKYztQPSMwAAR3Y"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:19:45.183093 2026] [security2:error] [pid 418108:tid 418165] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9V0Q0cxofL2J1zwYq-2QABLDY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:19:45.295332 2026] [security2:error] [pid 411857:tid 411895] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9V0S7ynBpLeKYztQPSPgAAOCQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:19:45.345182 2026] [security2:error] [pid 411857:tid 411925] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/fm.php"] [unique_id "al9V0S7ynBpLeKYztQPSPwAAb0I"]
[Tue Jul 21 08:19:45.372801 2026] [security2:error] [pid 418108:tid 418210] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9V0Q0cxofL2J1zwYq-2gABMGM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:19:45.509248 2026] [security2:error] [pid 418108:tid 418172] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9V0Q0cxofL2J1zwYq-2wABRD0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:19:45.549404 2026] [security2:error] [pid 418108:tid 418211] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9V0Q0cxofL2J1zwYq-3AABHGQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:19:45.567549 2026] [security2:error] [pid 411857:tid 411917] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/ini.php"] [unique_id "al9V0S7ynBpLeKYztQPSRwAAHTo"]
[Tue Jul 21 08:19:45.632273 2026] [security2:error] [pid 411857:tid 411979] [remote 68.178.160.25:53122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9V0S7ynBpLeKYztQPSSwAAanc"]
[Tue Jul 21 08:19:45.640190 2026] [security2:error] [pid 411857:tid 411899] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9V0S7ynBpLeKYztQPSTAAAeig"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:19:45.672116 2026] [security2:error] [pid 418108:tid 418214] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9V0Q0cxofL2J1zwYq-3QABRGc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:19:45.728483 2026] [security2:error] [pid 418108:tid 418217] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9V0Q0cxofL2J1zwYq-3gABHWo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:19:45.838807 2026] [security2:error] [pid 411857:tid 412073] [client 20.151.10.161:45893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9V0S7ynBpLeKYztQPSUgAAAFQ"]
[Tue Jul 21 08:19:46.009762 2026] [security2:error] [pid 418108:tid 418206] [remote 35.243.222.225:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.222.243.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9V0Q0cxofL2J1zwYq-2AABRF8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:19:46.058361 2026] [security2:error] [pid 411857:tid 411948] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/themes.php"] [unique_id "al9V0i7ynBpLeKYztQPSWgAATVk"]
[Tue Jul 21 08:19:46.159993 2026] [security2:error] [pid 418108:tid 418301] [client 20.226.60.151:64079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/sym403.php"] [unique_id "al9V0g0cxofL2J1zwYq-4gAAAUc"]
[Tue Jul 21 08:19:46.224694 2026] [security2:error] [pid 411857:tid 412088] [client 65.21.113.253:54698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V0S7ynBpLeKYztQPSUAAAAGM"]
[Tue Jul 21 08:19:46.237869 2026] [security2:error] [pid 411857:tid 411873] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/dropdown.php"] [unique_id "al9V0i7ynBpLeKYztQPSXQAAUw4"]
[Tue Jul 21 08:19:46.363905 2026] [security2:error] [pid 411857:tid 412030] [client 117.213.202.34:53816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V0i7ynBpLeKYztQPSYgAAACk"]
[Tue Jul 21 08:19:46.364036 2026] [security2:error] [pid 411857:tid 412030] [client 117.213.202.34:53816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V0i7ynBpLeKYztQPSYgAAACk"]
[Tue Jul 21 08:19:46.419827 2026] [security2:error] [pid 411857:tid 411928] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/wp-links.php"] [unique_id "al9V0i7ynBpLeKYztQPSZAAAe0U"]
[Tue Jul 21 08:19:46.483912 2026] [security2:error] [pid 411857:tid 412042] [client 74.249.245.134:48087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/info.php"] [unique_id "al9V0i7ynBpLeKYztQPSZQAAADU"]
[Tue Jul 21 08:19:46.538626 2026] [security2:error] [pid 411857:tid 412070] [client 87.116.180.198:27252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V0i7ynBpLeKYztQPSaAAAAFE"]
[Tue Jul 21 08:19:46.541982 2026] [security2:error] [pid 411857:tid 412070] [client 87.116.180.198:27252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V0i7ynBpLeKYztQPSaAAAAFE"]
[Tue Jul 21 08:19:46.574568 2026] [security2:error] [pid 418108:tid 418197] [remote 157.66.26.183:47610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9V0g0cxofL2J1zwYq-5gABS1Y"]
[Tue Jul 21 08:19:46.614767 2026] [security2:error] [pid 411857:tid 411952] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/xmrlpc.php"] [unique_id "al9V0i7ynBpLeKYztQPSbQAAfFw"]
[Tue Jul 21 08:19:46.794677 2026] [security2:error] [pid 411857:tid 411956] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/htaccess.php"] [unique_id "al9V0i7ynBpLeKYztQPSdQAAfmA"]
[Tue Jul 21 08:19:46.858300 2026] [security2:error] [pid 418108:tid 418304] [client 20.226.60.151:59291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/v543.php"] [unique_id "al9V0g0cxofL2J1zwYq-6AAAAUo"]
[Tue Jul 21 08:19:46.884036 2026] [security2:error] [pid 411857:tid 412031] [client 198.54.129.60:46878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9V0i7ynBpLeKYztQPSegAAACo"]
[Tue Jul 21 08:19:46.884142 2026] [security2:error] [pid 411857:tid 412031] [client 198.54.129.60:46878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9V0i7ynBpLeKYztQPSegAAACo"]
[Tue Jul 21 08:19:47.304107 2026] [security2:error] [pid 411857:tid 412007] [client 14.245.224.124:52841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9V0y7ynBpLeKYztQPSigAAABI"]
[Tue Jul 21 08:19:47.304308 2026] [security2:error] [pid 411857:tid 412007] [client 14.245.224.124:52841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9V0y7ynBpLeKYztQPSigAAABI"]
[Tue Jul 21 08:19:47.374580 2026] [security2:error] [pid 411857:tid 411864] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/readme.php"] [unique_id "al9V0y7ynBpLeKYztQPSjgAAQgU"]
[Tue Jul 21 08:19:47.555614 2026] [security2:error] [pid 411857:tid 411909] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/403.php"] [unique_id "al9V0y7ynBpLeKYztQPSkAAABTI"]
[Tue Jul 21 08:19:47.690215 2026] [security2:error] [pid 411857:tid 412077] [client 103.106.20.201:53525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V0y7ynBpLeKYztQPSlAAAAFg"]
[Tue Jul 21 08:19:47.690314 2026] [security2:error] [pid 411857:tid 412077] [client 103.106.20.201:53525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V0y7ynBpLeKYztQPSlAAAAFg"]
[Tue Jul 21 08:19:47.732314 2026] [security2:error] [pid 411857:tid 411896] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9V0y7ynBpLeKYztQPSmAAAGyU"]
[Tue Jul 21 08:19:47.732482 2026] [security2:error] [pid 411857:tid 412016] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9V0y7ynBpLeKYztQPSmAAAGyU"]
[Tue Jul 21 08:19:47.791983 2026] [security2:error] [pid 411857:tid 411922] [remote 199.189.225.40:55613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9V0y7ynBpLeKYztQPSmgAAaT8"]
[Tue Jul 21 08:19:47.863972 2026] [security2:error] [pid 411857:tid 412097] [client 185.213.175.37:42630] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.vitacorr.com.br"] [uri "/"] [unique_id "al9V0y7ynBpLeKYztQPSnAAAAGw"]
[Tue Jul 21 08:19:47.934827 2026] [security2:error] [pid 411857:tid 412011] [client 115.134.11.136:64210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V0C7ynBpLeKYztQPSFwAAABY"]
[Tue Jul 21 08:19:48.088405 2026] [security2:error] [pid 411857:tid 412030] [client 20.206.105.145:25561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/82.php"] [unique_id "al9V1C7ynBpLeKYztQPSowAAACk"]
[Tue Jul 21 08:19:48.151616 2026] [security2:error] [pid 411857:tid 412101] [client 162.219.176.3:42334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9V1C7ynBpLeKYztQPSpwAAAHA"]
[Tue Jul 21 08:19:48.151704 2026] [security2:error] [pid 411857:tid 412101] [client 162.219.176.3:42334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9V1C7ynBpLeKYztQPSpwAAAHA"]
[Tue Jul 21 08:19:48.237259 2026] [security2:error] [pid 411857:tid 412025] [client 20.226.60.151:64036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/sixxis.php"] [unique_id "al9V1C7ynBpLeKYztQPSqgAAACQ"]
[Tue Jul 21 08:19:48.241232 2026] [security2:error] [pid 411857:tid 411977] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/max.php"] [unique_id "al9V1C7ynBpLeKYztQPSqwAAB3U"]
[Tue Jul 21 08:19:48.300059 2026] [security2:error] [pid 411857:tid 412018] [client 150.129.202.39:65151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V1C7ynBpLeKYztQPSrAAAAB0"]
[Tue Jul 21 08:19:48.300262 2026] [security2:error] [pid 411857:tid 412018] [client 150.129.202.39:65151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V1C7ynBpLeKYztQPSrAAAAB0"]
[Tue Jul 21 08:19:48.355850 2026] [security2:error] [pid 418108:tid 418345] [client 198.244.226.196:49520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.hotelpordosolpolonini.com.br"] [uri "/robots.txt"] [unique_id "al9V1A0cxofL2J1zwYq-8wAAAXM"]
[Tue Jul 21 08:19:48.356024 2026] [security2:error] [pid 418108:tid 418345] [client 198.244.226.196:49520] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.hotelpordosolpolonini.com.br"] [uri "/robots.txt"] [unique_id "al9V1A0cxofL2J1zwYq-8wAAAXM"]
[Tue Jul 21 08:19:48.366886 2026] [security2:error] [pid 411857:tid 412031] [client 117.210.135.0:55080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V1C7ynBpLeKYztQPSrQAAACo"]
[Tue Jul 21 08:19:48.367114 2026] [security2:error] [pid 411857:tid 412031] [client 117.210.135.0:55080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V1C7ynBpLeKYztQPSrQAAACo"]
[Tue Jul 21 08:19:48.413202 2026] [security2:error] [pid 418108:tid 418189] [remote 54.39.210.155:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "marketingderua.com.br"] [uri "/ooh-nao-e-branding-apenas-onde-esta-a-performance/"] [unique_id "al9V1A0cxofL2J1zwYq-9AABcU4"]
[Tue Jul 21 08:19:48.413374 2026] [security2:error] [pid 418108:tid 418343] [client 54.39.210.155:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "marketingderua.com.br"] [uri "/ooh-nao-e-branding-apenas-onde-esta-a-performance/"] [unique_id "al9V1A0cxofL2J1zwYq-9AABcU4"]
[Tue Jul 21 08:19:48.434310 2026] [security2:error] [pid 411857:tid 411879] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/m.php"] [unique_id "al9V1C7ynBpLeKYztQPSsgAAbhQ"]
[Tue Jul 21 08:19:48.612458 2026] [security2:error] [pid 411857:tid 411923] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/click.php"] [unique_id "al9V1C7ynBpLeKYztQPSxQAAG0A"]
[Tue Jul 21 08:19:49.000892 2026] [security2:error] [pid 411857:tid 412050] [client 74.249.245.134:55223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/edit.php"] [unique_id "al9V1S7ynBpLeKYztQPS3QAAAD0"]
[Tue Jul 21 08:19:49.016064 2026] [security2:error] [pid 411857:tid 412059] [client 20.226.60.151:64105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/ops.php"] [unique_id "al9V1S7ynBpLeKYztQPS3gAAAEY"]
[Tue Jul 21 08:19:49.070345 2026] [security2:error] [pid 411857:tid 411994] [client 173.239.211.141:45455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9V1S7ynBpLeKYztQPS4AAAAAU"]
[Tue Jul 21 08:19:49.139738 2026] [security2:error] [pid 411857:tid 412101] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9V1S7ynBpLeKYztQPS4wAAAHA"]
[Tue Jul 21 08:19:49.151746 2026] [security2:error] [pid 418108:tid 418357] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9V1Q0cxofL2J1zwYq--AAAAX8"]
[Tue Jul 21 08:19:49.166403 2026] [security2:error] [pid 418108:tid 418366] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/dp.php"] [unique_id "al9V1Q0cxofL2J1zwYq--gAAAYg"]
[Tue Jul 21 08:19:49.187377 2026] [security2:error] [pid 418108:tid 418294] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/old.php"] [unique_id "al9V1Q0cxofL2J1zwYq--wAAAUA"]
[Tue Jul 21 08:19:49.190380 2026] [security2:error] [pid 418108:tid 418344] [client 111.93.58.162:14423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9V1Q0cxofL2J1zwYq-_AAAAXI"]
[Tue Jul 21 08:19:49.190480 2026] [security2:error] [pid 418108:tid 418344] [client 111.93.58.162:14423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9V1Q0cxofL2J1zwYq-_AAAAXI"]
[Tue Jul 21 08:19:49.198882 2026] [security2:error] [pid 411857:tid 411996] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/ms-new.php"] [unique_id "al9V1S7ynBpLeKYztQPS6gAAAAc"]
[Tue Jul 21 08:19:49.223108 2026] [security2:error] [pid 418108:tid 418363] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/track.php"] [unique_id "al9V1Q0cxofL2J1zwYq-_wAAAYU"]
[Tue Jul 21 08:19:49.245167 2026] [security2:error] [pid 418108:tid 418273] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/2352356666.php"] [unique_id "al9V1Q0cxofL2J1zwYq_AAAAASs"]
[Tue Jul 21 08:19:49.257669 2026] [security2:error] [pid 411857:tid 412042] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/pn.php"] [unique_id "al9V1S7ynBpLeKYztQPS7AAAADU"]
[Tue Jul 21 08:19:49.270402 2026] [security2:error] [pid 411857:tid 412018] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9V1S7ynBpLeKYztQPS7wAAAB0"]
[Tue Jul 21 08:19:49.295190 2026] [security2:error] [pid 418108:tid 418286] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/dr.php"] [unique_id "al9V1Q0cxofL2J1zwYq_AgAAATg"]
[Tue Jul 21 08:19:49.312987 2026] [security2:error] [pid 418108:tid 418282] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/2x.php"] [unique_id "al9V1Q0cxofL2J1zwYq_AwAAATQ"]
[Tue Jul 21 08:19:49.329186 2026] [security2:error] [pid 418108:tid 418242] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/kq1.php"] [unique_id "al9V1Q0cxofL2J1zwYq_BAAAAQw"]
[Tue Jul 21 08:19:49.344014 2026] [security2:error] [pid 411857:tid 412095] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/zzz.php"] [unique_id "al9V1S7ynBpLeKYztQPS9QAAAGo"]
[Tue Jul 21 08:19:49.362533 2026] [security2:error] [pid 418108:tid 418260] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/wicked.php"] [unique_id "al9V1Q0cxofL2J1zwYq_BwAAAR4"]
[Tue Jul 21 08:19:49.382667 2026] [security2:error] [pid 411857:tid 412008] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/edit.php"] [unique_id "al9V1S7ynBpLeKYztQPS-QAAABM"]
[Tue Jul 21 08:19:49.386354 2026] [security2:error] [pid 418108:tid 418269] [client 20.206.105.145:25106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/config.json.php"] [unique_id "al9V1Q0cxofL2J1zwYq_CAAAASc"]
[Tue Jul 21 08:19:49.398451 2026] [security2:error] [pid 418108:tid 418296] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/kua.php"] [unique_id "al9V1Q0cxofL2J1zwYq_CQAAAUI"]
[Tue Jul 21 08:19:49.420180 2026] [security2:error] [pid 411857:tid 412091] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/ez.php"] [unique_id "al9V1S7ynBpLeKYztQPS_AAAAGY"]
[Tue Jul 21 08:19:49.440637 2026] [security2:error] [pid 418108:tid 418265] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/fz.php"] [unique_id "al9V1Q0cxofL2J1zwYq_CgAAASM"]
[Tue Jul 21 08:19:49.466780 2026] [security2:error] [pid 411857:tid 412086] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/la.php"] [unique_id "al9V1S7ynBpLeKYztQPS_wAAAGE"]
[Tue Jul 21 08:19:49.466894 2026] [security2:error] [pid 411857:tid 412048] [client 185.213.175.37:42642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.vivaconcierge.com.br"] [uri "/"] [unique_id "al9V1S7ynBpLeKYztQPTAAAAADs"]
[Tue Jul 21 08:19:49.466971 2026] [security2:error] [pid 411857:tid 412048] [client 185.213.175.37:42642] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.vivaconcierge.com.br"] [uri "/"] [unique_id "al9V1S7ynBpLeKYztQPTAAAAADs"]
[Tue Jul 21 08:19:49.487397 2026] [security2:error] [pid 411857:tid 412097] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9V1S7ynBpLeKYztQPTAQAAAGw"]
[Tue Jul 21 08:19:49.501074 2026] [security2:error] [pid 411857:tid 412032] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/inso.php"] [unique_id "al9V1S7ynBpLeKYztQPTAgAAACs"]
[Tue Jul 21 08:19:49.513605 2026] [security2:error] [pid 418108:tid 418271] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/wpx.php"] [unique_id "al9V1Q0cxofL2J1zwYq_CwAAASk"]
[Tue Jul 21 08:19:49.538089 2026] [security2:error] [pid 411857:tid 411992] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/berlin.php"] [unique_id "al9V1S7ynBpLeKYztQPTAwAAAAM"]
[Tue Jul 21 08:19:49.551075 2026] [security2:error] [pid 411857:tid 412010] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/billur.php"] [unique_id "al9V1S7ynBpLeKYztQPTBAAAABU"]
[Tue Jul 21 08:19:49.570039 2026] [security2:error] [pid 411857:tid 412115] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/mimpi.php"] [unique_id "al9V1S7ynBpLeKYztQPTBQAAAH4"]
[Tue Jul 21 08:19:49.581754 2026] [security2:error] [pid 411857:tid 412059] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/dp.php"] [unique_id "al9V1S7ynBpLeKYztQPTBgAAAEY"]
[Tue Jul 21 08:19:49.596842 2026] [security2:error] [pid 411857:tid 411994] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/bootstrap.php"] [unique_id "al9V1S7ynBpLeKYztQPTBwAAAAU"]
[Tue Jul 21 08:19:49.608312 2026] [security2:error] [pid 411857:tid 412101] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/wp-editor.php"] [unique_id "al9V1S7ynBpLeKYztQPTCAAAAHA"]
[Tue Jul 21 08:19:49.627144 2026] [security2:error] [pid 418108:tid 418270] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/cro.php"] [unique_id "al9V1Q0cxofL2J1zwYq_DAAAASg"]
[Tue Jul 21 08:19:49.652161 2026] [security2:error] [pid 411857:tid 412054] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/cron-tab.php"] [unique_id "al9V1S7ynBpLeKYztQPTCQAAAEE"]
[Tue Jul 21 08:19:49.652747 2026] [security2:error] [pid 418108:tid 418190] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V1Q0cxofL2J1zwYq_DQABNU8"]
[Tue Jul 21 08:19:49.652860 2026] [security2:error] [pid 418108:tid 418283] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V1Q0cxofL2J1zwYq_DQABNU8"]
[Tue Jul 21 08:19:49.664645 2026] [security2:error] [pid 418108:tid 418281] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/koiy.php"] [unique_id "al9V1Q0cxofL2J1zwYq_DgAAATM"]
[Tue Jul 21 08:19:49.685591 2026] [security2:error] [pid 411857:tid 412007] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/hp2.php"] [unique_id "al9V1S7ynBpLeKYztQPTCgAAABI"]
[Tue Jul 21 08:19:49.697648 2026] [security2:error] [pid 418108:tid 418285] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/hp3.php"] [unique_id "al9V1Q0cxofL2J1zwYq_DwAAATc"]
[Tue Jul 21 08:19:49.710863 2026] [security2:error] [pid 418108:tid 418240] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/aa1.php"] [unique_id "al9V1Q0cxofL2J1zwYq_EAAAAQo"]
[Tue Jul 21 08:19:49.722345 2026] [security2:error] [pid 418108:tid 418251] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/acew67.php"] [unique_id "al9V1Q0cxofL2J1zwYq_EQAAARU"]
[Tue Jul 21 08:19:49.733867 2026] [security2:error] [pid 418108:tid 418253] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/bscclapb.php"] [unique_id "al9V1Q0cxofL2J1zwYq_EwAAARc"]
[Tue Jul 21 08:19:49.747654 2026] [security2:error] [pid 418108:tid 418306] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/else1.php"] [unique_id "al9V1Q0cxofL2J1zwYq_FQAAAUw"]
[Tue Jul 21 08:19:49.768353 2026] [security2:error] [pid 418108:tid 418314] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/tkikikoko.php"] [unique_id "al9V1Q0cxofL2J1zwYq_FgAAAVQ"]
[Tue Jul 21 08:19:49.775761 2026] [security2:error] [pid 418108:tid 418305] [client 51.195.215.35:17524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.hotelpordosolpolonini.com.br"] [uri "/"] [unique_id "al9V1Q0cxofL2J1zwYq_FwAAAUs"]
[Tue Jul 21 08:19:49.775853 2026] [security2:error] [pid 418108:tid 418305] [client 51.195.215.35:17524] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.hotelpordosolpolonini.com.br"] [uri "/"] [unique_id "al9V1Q0cxofL2J1zwYq_FwAAAUs"]
[Tue Jul 21 08:19:49.780474 2026] [security2:error] [pid 418108:tid 418317] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9V1Q0cxofL2J1zwYq_GAAAAVc"]
[Tue Jul 21 08:19:49.791836 2026] [security2:error] [pid 418108:tid 418315] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/wp-css.php"] [unique_id "al9V1Q0cxofL2J1zwYq_GQAAAVU"]
[Tue Jul 21 08:19:49.803675 2026] [security2:error] [pid 418108:tid 418303] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/wp-explorer.php"] [unique_id "al9V1Q0cxofL2J1zwYq_GgAAAUk"]
[Tue Jul 21 08:19:49.825769 2026] [security2:error] [pid 418108:tid 418311] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/akismet.php"] [unique_id "al9V1Q0cxofL2J1zwYq_GwAAAVE"]
[Tue Jul 21 08:19:49.843839 2026] [security2:error] [pid 411857:tid 411893] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/lv.php"] [unique_id "al9V1S7ynBpLeKYztQPTEgAABCI"]
[Tue Jul 21 08:19:49.850028 2026] [security2:error] [pid 411857:tid 412076] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/ace2.php"] [unique_id "al9V1S7ynBpLeKYztQPTEwAAAFc"]
[Tue Jul 21 08:19:49.896912 2026] [security2:error] [pid 411857:tid 412033] [client 86.106.84.166:51514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9V1S7ynBpLeKYztQPTFQAAACw"]
[Tue Jul 21 08:19:49.896997 2026] [security2:error] [pid 411857:tid 412033] [client 86.106.84.166:51514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9V1S7ynBpLeKYztQPTFQAAACw"]
[Tue Jul 21 08:19:49.915684 2026] [security2:error] [pid 418108:tid 418291] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.volyo.com.br"] [uri "/ms.php"] [unique_id "al9V1Q0cxofL2J1zwYq_HgAAAT0"]
[Tue Jul 21 08:19:50.018748 2026] [security2:error] [pid 418108:tid 418245] [client 120.56.162.40:60946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V1g0cxofL2J1zwYq_HwAAAQ8"]
[Tue Jul 21 08:19:50.018954 2026] [security2:error] [pid 418108:tid 418245] [client 120.56.162.40:60946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V1g0cxofL2J1zwYq_HwAAAQ8"]
[Tue Jul 21 08:19:50.046468 2026] [security2:error] [pid 411857:tid 411927] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/cong.php"] [unique_id "al9V1i7ynBpLeKYztQPTGAAAI0Q"]
[Tue Jul 21 08:19:50.067979 2026] [security2:error] [pid 411857:tid 412113] [client 216.73.161.164:61797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9V1S7ynBpLeKYztQPS3wAAAHw"]
[Tue Jul 21 08:19:50.235073 2026] [security2:error] [pid 411857:tid 412026] [client 173.239.211.122:22171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9V1S7ynBpLeKYztQPS4QAAACU"]
[Tue Jul 21 08:19:50.245920 2026] [security2:error] [pid 411857:tid 411918] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/brand.php"] [unique_id "al9V1i7ynBpLeKYztQPTGgAAETs"]
[Tue Jul 21 08:19:50.437160 2026] [security2:error] [pid 411857:tid 411955] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/atomlib.php"] [unique_id "al9V1i7ynBpLeKYztQPTKgAAPV8"]
[Tue Jul 21 08:19:50.644386 2026] [security2:error] [pid 411857:tid 411933] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/0x.php"] [unique_id "al9V1i7ynBpLeKYztQPTLgAAcEo"]
[Tue Jul 21 08:19:50.780774 2026] [security2:error] [pid 411857:tid 412025] [client 20.226.60.151:60567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/w3llscc.php"] [unique_id "al9V1i7ynBpLeKYztQPTMgAAACQ"]
[Tue Jul 21 08:19:50.824586 2026] [security2:error] [pid 411857:tid 411866] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/buy.php"] [unique_id "al9V1i7ynBpLeKYztQPTNAAAHQc"]
[Tue Jul 21 08:19:50.896644 2026] [security2:error] [pid 418108:tid 418250] [client 62.102.148.158:37266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9V1g0cxofL2J1zwYq_IwAAARQ"]
[Tue Jul 21 08:19:50.896745 2026] [security2:error] [pid 418108:tid 418250] [client 62.102.148.158:37266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9V1g0cxofL2J1zwYq_IwAAARQ"]
[Tue Jul 21 08:19:51.041393 2026] [security2:error] [pid 411857:tid 411882] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/sx.php"] [unique_id "al9V1y7ynBpLeKYztQPTQgAAExc"]
[Tue Jul 21 08:19:51.069371 2026] [security2:error] [pid 418108:tid 418181] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9V1w0cxofL2J1zwYq_JgABcUY"]
[Tue Jul 21 08:19:51.069515 2026] [security2:error] [pid 418108:tid 418343] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9V1w0cxofL2J1zwYq_JgABcUY"]
[Tue Jul 21 08:19:51.110930 2026] [security2:error] [pid 411857:tid 412034] [client 20.151.10.161:45926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9V1y7ynBpLeKYztQPTQwAAAC0"]
[Tue Jul 21 08:19:51.133455 2026] [security2:error] [pid 418108:tid 418348] [client 20.206.105.145:25431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fastpedidos.com.br"] [uri "/fpwch.php"] [unique_id "al9V1w0cxofL2J1zwYq_JwAAAXY"]
[Tue Jul 21 08:19:51.247273 2026] [security2:error] [pid 411857:tid 411963] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/article.php"] [unique_id "al9V1y7ynBpLeKYztQPTRAAAEWc"]
[Tue Jul 21 08:19:51.378968 2026] [security2:error] [pid 418108:tid 418116] [remote 97.74.93.24:58986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ellosemijoias.com.br"] [uri "/wp-login.php"] [unique_id "al9V1w0cxofL2J1zwYq_KgABXwU"]
[Tue Jul 21 08:19:51.381440 2026] [security2:error] [pid 418108:tid 418359] [client 74.249.245.134:50212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/166.php"] [unique_id "al9V1w0cxofL2J1zwYq_KwAAAYE"]
[Tue Jul 21 08:19:51.435335 2026] [security2:error] [pid 411857:tid 411905] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/bootstrap.php"] [unique_id "al9V1y7ynBpLeKYztQPTUQAAby4"]
[Tue Jul 21 08:19:51.493287 2026] [security2:error] [pid 418108:tid 418366] [client 20.226.60.151:64065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/mac.php"] [unique_id "al9V1w0cxofL2J1zwYq_LgAAAYg"]
[Tue Jul 21 08:19:51.502416 2026] [security2:error] [pid 411857:tid 412086] [client 61.1.167.83:62967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V1y7ynBpLeKYztQPTUwAAAGE"]
[Tue Jul 21 08:19:51.502523 2026] [security2:error] [pid 411857:tid 412086] [client 61.1.167.83:62967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V1y7ynBpLeKYztQPTUwAAAGE"]
[Tue Jul 21 08:19:51.638343 2026] [security2:error] [pid 411857:tid 411924] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/config-backup.php"] [unique_id "al9V1y7ynBpLeKYztQPTVQAACkE"]
[Tue Jul 21 08:19:51.828372 2026] [security2:error] [pid 411857:tid 411877] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/goods.php"] [unique_id "al9V1y7ynBpLeKYztQPTWAAABBI"]
[Tue Jul 21 08:19:51.932701 2026] [security2:error] [pid 411857:tid 412063] [client 54.39.203.50:58038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.chaveiroportao.com.br"] [uri "/robots.txt"] [unique_id "al9V1y7ynBpLeKYztQPTXgAAAEo"]
[Tue Jul 21 08:19:51.932782 2026] [security2:error] [pid 411857:tid 412063] [client 54.39.203.50:58038] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.chaveiroportao.com.br"] [uri "/robots.txt"] [unique_id "al9V1y7ynBpLeKYztQPTXgAAAEo"]
[Tue Jul 21 08:19:52.013501 2026] [security2:error] [pid 411857:tid 411862] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/init.php"] [unique_id "al9V2C7ynBpLeKYztQPTYQAAWgM"]
[Tue Jul 21 08:19:52.210136 2026] [authz_core:error] [pid 411857:tid 411946] [remote 74.249.245.134:0] AH01630: client denied by server configuration: /home4/serric15/climadek.com.br/license.txt
[Tue Jul 21 08:19:52.231548 2026] [security2:error] [pid 418108:tid 418133] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9V2A0cxofL2J1zwYq_NQABOBY"]
[Tue Jul 21 08:19:52.231727 2026] [security2:error] [pid 418108:tid 418286] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9V2A0cxofL2J1zwYq_NQABOBY"]
[Tue Jul 21 08:19:52.418267 2026] [authz_core:error] [pid 411857:tid 411942] [remote 74.249.245.134:0] AH01630: client denied by server configuration: /home4/serric15/climadek.com.br/php.ini
[Tue Jul 21 08:19:52.469286 2026] [security2:error] [pid 411857:tid 412101] [client 198.54.129.60:47044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9V2C7ynBpLeKYztQPTcwAAAHA"]
[Tue Jul 21 08:19:52.469359 2026] [security2:error] [pid 411857:tid 412101] [client 198.54.129.60:47044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9V2C7ynBpLeKYztQPTcwAAAHA"]
[Tue Jul 21 08:19:52.479714 2026] [security2:error] [pid 411857:tid 412025] [client 74.249.245.134:48482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/8.php"] [unique_id "al9V2C7ynBpLeKYztQPTdgAAACQ"]
[Tue Jul 21 08:19:52.611544 2026] [security2:error] [pid 411857:tid 411925] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/settings.php"] [unique_id "al9V2C7ynBpLeKYztQPTegAAdUI"]
[Tue Jul 21 08:19:52.672624 2026] [security2:error] [pid 411857:tid 412043] [client 154.208.47.43:2357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9V2C7ynBpLeKYztQPTfgAAADY"]
[Tue Jul 21 08:19:52.672730 2026] [security2:error] [pid 411857:tid 412043] [client 154.208.47.43:2357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9V2C7ynBpLeKYztQPTfgAAADY"]
[Tue Jul 21 08:19:52.847677 2026] [security2:error] [pid 411857:tid 412011] [client 65.21.113.253:57486] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V2C7ynBpLeKYztQPTcgAAABY"]
[Tue Jul 21 08:19:52.874584 2026] [security2:error] [pid 411857:tid 412031] [client 20.151.10.161:45876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/gettest.php"] [unique_id "al9V2C7ynBpLeKYztQPTgAAAACo"]
[Tue Jul 21 08:19:53.040072 2026] [security2:error] [pid 418108:tid 418269] [client 20.226.60.151:64009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/ip.php"] [unique_id "al9V2Q0cxofL2J1zwYq_PAAAASc"]
[Tue Jul 21 08:19:53.148551 2026] [security2:error] [pid 411857:tid 412072] [client 38.100.221.102:18447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V2S7ynBpLeKYztQPTjwAAAFM"]
[Tue Jul 21 08:19:53.149314 2026] [security2:error] [pid 411857:tid 412072] [client 38.100.221.102:18447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V2S7ynBpLeKYztQPTjwAAAFM"]
[Tue Jul 21 08:19:53.289456 2026] [security2:error] [pid 411857:tid 412035] [client 223.181.60.88:26042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9V2S7ynBpLeKYztQPTkwAAAC4"]
[Tue Jul 21 08:19:53.289733 2026] [security2:error] [pid 411857:tid 412035] [client 223.181.60.88:26042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9V2S7ynBpLeKYztQPTkwAAAC4"]
[Tue Jul 21 08:19:53.396046 2026] [autoindex:error] [pid 411857:tid 411938] [remote 185.8.106.168:54154] AH01276: Cannot serve directory /home2/eloisa13/tourcampos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:19:53.420097 2026] [security2:error] [pid 411857:tid 412045] [client 54.39.0.224:61500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.chaveiroportao.com.br"] [uri "/"] [unique_id "al9V2S7ynBpLeKYztQPTnwAAADg"]
[Tue Jul 21 08:19:53.420190 2026] [security2:error] [pid 411857:tid 412045] [client 54.39.0.224:61500] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.chaveiroportao.com.br"] [uri "/"] [unique_id "al9V2S7ynBpLeKYztQPTnwAAADg"]
[Tue Jul 21 08:19:53.465227 2026] [security2:error] [pid 411857:tid 412064] [client 20.226.60.151:64038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/mg.php"] [unique_id "al9V2S7ynBpLeKYztQPToAAAAEs"]
[Tue Jul 21 08:19:53.494479 2026] [security2:error] [pid 411857:tid 411863] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/g.php"] [unique_id "al9V2S7ynBpLeKYztQPTowAAIAQ"]
[Tue Jul 21 08:19:53.562476 2026] [autoindex:error] [pid 411857:tid 411990] [client 185.8.106.168:0] AH01276: Cannot serve directory /home2/eloisa13/tourcampos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:19:53.682547 2026] [security2:error] [pid 411857:tid 411950] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/403.php"] [unique_id "al9V2S7ynBpLeKYztQPTrAAAQls"]
[Tue Jul 21 08:19:53.917070 2026] [security2:error] [pid 411857:tid 412069] [client 187.125.243.197:61416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9V2S7ynBpLeKYztQPTwQAAAFA"]
[Tue Jul 21 08:19:53.917253 2026] [security2:error] [pid 411857:tid 412069] [client 187.125.243.197:61416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9V2S7ynBpLeKYztQPTwQAAAFA"]
[Tue Jul 21 08:19:54.338261 2026] [security2:error] [pid 411857:tid 412048] [client 103.151.46.103:58293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9V2i7ynBpLeKYztQPTzQAAADs"]
[Tue Jul 21 08:19:54.338540 2026] [security2:error] [pid 411857:tid 412048] [client 103.151.46.103:58293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9V2i7ynBpLeKYztQPTzQAAADs"]
[Tue Jul 21 08:19:54.376278 2026] [security2:error] [pid 411857:tid 412033] [client 74.249.245.134:50659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/ws38.php"] [unique_id "al9V2i7ynBpLeKYztQPTzwAAACw"]
[Tue Jul 21 08:19:54.388272 2026] [security2:error] [pid 411857:tid 411896] [remote 216.73.216.184:39364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9V2i7ynBpLeKYztQPT0AAAJCU"]
[Tue Jul 21 08:19:54.464103 2026] [security2:error] [pid 411857:tid 412016] [client 115.134.11.136:64670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V2i7ynBpLeKYztQPT1QAAABs"]
[Tue Jul 21 08:19:54.465072 2026] [security2:error] [pid 411857:tid 412016] [client 115.134.11.136:64670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V2i7ynBpLeKYztQPT1QAAABs"]
[Tue Jul 21 08:19:54.702779 2026] [security2:error] [pid 411857:tid 412035] [client 152.59.34.51:55916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9V2i7ynBpLeKYztQPT3QAAAC4"]
[Tue Jul 21 08:19:54.702890 2026] [security2:error] [pid 411857:tid 412035] [client 152.59.34.51:55916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9V2i7ynBpLeKYztQPT3QAAAC4"]
[Tue Jul 21 08:19:54.732326 2026] [security2:error] [pid 418108:tid 418302] [client 20.226.60.151:64089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-post-data.php"] [unique_id "al9V2g0cxofL2J1zwYq_UQAAAUg"]
[Tue Jul 21 08:19:54.743695 2026] [security2:error] [pid 411857:tid 411926] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/api.php"] [unique_id "al9V2i7ynBpLeKYztQPT3gAAFEM"]
[Tue Jul 21 08:19:55.237052 2026] [security2:error] [pid 411857:tid 412044] [client 20.226.60.151:64032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/kq1.php"] [unique_id "al9V2y7ynBpLeKYztQPT8gAAADc"]
[Tue Jul 21 08:19:55.312132 2026] [security2:error] [pid 411857:tid 412016] [client 20.151.10.161:46007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/simple.php"] [unique_id "al9V2y7ynBpLeKYztQPT9AAAABs"]
[Tue Jul 21 08:19:55.336788 2026] [security2:error] [pid 411857:tid 412115] [client 185.213.175.37:12092] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.wbapoiocontabil.com.br"] [uri "/"] [unique_id "al9V2y7ynBpLeKYztQPT9QAAAH4"]
[Tue Jul 21 08:19:55.381978 2026] [security2:error] [pid 418108:tid 418171] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V2w0cxofL2J1zwYq_VgABDzw"]
[Tue Jul 21 08:19:55.383097 2026] [security2:error] [pid 418108:tid 418245] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V2w0cxofL2J1zwYq_VgABDzw"]
[Tue Jul 21 08:19:55.561032 2026] [security2:error] [pid 418108:tid 418330] [client 20.220.225.223:43428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9V2w0cxofL2J1zwYq_WAAAAWQ"]
[Tue Jul 21 08:19:55.647713 2026] [security2:error] [pid 411857:tid 411887] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env"] [unique_id "al9V2y7ynBpLeKYztQPUCwAAfBw"]
[Tue Jul 21 08:19:55.648345 2026] [security2:error] [pid 411857:tid 411925] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env.backup"] [unique_id "al9V2y7ynBpLeKYztQPUDQAAfEI"]
[Tue Jul 21 08:19:55.648440 2026] [security2:error] [pid 411857:tid 411978] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env.bak"] [unique_id "al9V2y7ynBpLeKYztQPUCgAAfHY"]
[Tue Jul 21 08:19:55.774343 2026] [security2:error] [pid 411857:tid 412011] [client 74.249.245.134:60045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/a7.php"] [unique_id "al9V2y7ynBpLeKYztQPUIQAAABY"]
[Tue Jul 21 08:19:55.894507 2026] [security2:error] [pid 411857:tid 411979] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php;/style.css"] [unique_id "al9V2y7ynBpLeKYztQPULgAAfHc"]
[Tue Jul 21 08:19:55.894524 2026] [security2:error] [pid 411857:tid 411891] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.bak"] [unique_id "al9V2y7ynBpLeKYztQPULQAAfCA"]
[Tue Jul 21 08:19:55.896167 2026] [security2:error] [pid 411857:tid 411912] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env"] [unique_id "al9V2y7ynBpLeKYztQPUMQAAfDU"]
[Tue Jul 21 08:19:55.897771 2026] [security2:error] [pid 411857:tid 411890] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/wp-config.php"] [unique_id "al9V2y7ynBpLeKYztQPUKwAAfB8"]
[Tue Jul 21 08:19:55.977667 2026] [security2:error] [pid 411857:tid 412050] [client 20.226.60.151:60624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wpx.php"] [unique_id "al9V2y7ynBpLeKYztQPUPAAAAD0"]
[Tue Jul 21 08:19:56.172115 2026] [security2:error] [pid 411857:tid 412014] [client 20.226.60.151:64009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/pucci.php"] [unique_id "al9V3C7ynBpLeKYztQPUQgAAABk"]
[Tue Jul 21 08:19:56.642362 2026] [security2:error] [pid 418108:tid 418294] [client 20.151.10.161:46011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/xxx.php"] [unique_id "al9V3A0cxofL2J1zwYq_bQAAAUA"]
[Tue Jul 21 08:19:56.837516 2026] [security2:error] [pid 411857:tid 412048] [client 65.21.113.253:57486] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V3C7ynBpLeKYztQPURwAAADs"]
[Tue Jul 21 08:19:56.962181 2026] [security2:error] [pid 418108:tid 418297] [client 162.219.176.3:60130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9V3A0cxofL2J1zwYq_cAAAAUM"]
[Tue Jul 21 08:19:56.962299 2026] [security2:error] [pid 418108:tid 418297] [client 162.219.176.3:60130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9V3A0cxofL2J1zwYq_cAAAAUM"]
[Tue Jul 21 08:19:57.031134 2026] [security2:error] [pid 418108:tid 418252] [client 117.213.202.34:54337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V3Q0cxofL2J1zwYq_cQAAARY"]
[Tue Jul 21 08:19:57.031287 2026] [security2:error] [pid 418108:tid 418252] [client 117.213.202.34:54337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V3Q0cxofL2J1zwYq_cQAAARY"]
[Tue Jul 21 08:19:57.053772 2026] [security2:error] [pid 411857:tid 412103] [client 20.226.60.151:64121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/black.php"] [unique_id "al9V3S7ynBpLeKYztQPUWwAAAHI"]
[Tue Jul 21 08:19:57.185543 2026] [security2:error] [pid 411857:tid 412016] [client 20.151.10.161:46017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/hypo.php"] [unique_id "al9V3S7ynBpLeKYztQPUZAAAABs"]
[Tue Jul 21 08:19:57.297468 2026] [security2:error] [pid 411857:tid 412101] [client 87.116.180.198:14072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V3S7ynBpLeKYztQPUagAAAHA"]
[Tue Jul 21 08:19:57.297654 2026] [security2:error] [pid 411857:tid 412101] [client 87.116.180.198:14072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V3S7ynBpLeKYztQPUagAAAHA"]
[Tue Jul 21 08:19:57.387862 2026] [authz_core:error] [pid 411857:tid 412034] [client 103.215.74.26:0] AH01630: client denied by server configuration: /home4/chefdo14/atom-growth.com/.htpasswd
[Tue Jul 21 08:19:57.486913 2026] [security2:error] [pid 411857:tid 411963] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.ssh/id_rsa"] [unique_id "al9V3S7ynBpLeKYztQPUdQAAJmc"]
[Tue Jul 21 08:19:57.506158 2026] [security2:error] [pid 411857:tid 411901] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config/database.php"] [unique_id "al9V3S7ynBpLeKYztQPUegAAJio"]
[Tue Jul 21 08:19:57.506239 2026] [security2:error] [pid 411857:tid 411909] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config/app.php"] [unique_id "al9V3S7ynBpLeKYztQPUeAAAJjI"]
[Tue Jul 21 08:19:57.506261 2026] [security2:error] [pid 411857:tid 411877] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config/mail.php"] [unique_id "al9V3S7ynBpLeKYztQPUfAAAJhI"]
[Tue Jul 21 08:19:57.507268 2026] [security2:error] [pid 411857:tid 411871] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env"] [unique_id "al9V3S7ynBpLeKYztQPUgQAAJgw"]
[Tue Jul 21 08:19:57.507961 2026] [security2:error] [pid 411857:tid 411904] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/backup.sql"] [unique_id "al9V3S7ynBpLeKYztQPUfQAAJi0"]
[Tue Jul 21 08:19:57.507963 2026] [security2:error] [pid 411857:tid 411944] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/dump.sql"] [unique_id "al9V3S7ynBpLeKYztQPUfwAAJlU"]
[Tue Jul 21 08:19:57.507968 2026] [security2:error] [pid 411857:tid 411946] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/database.sql"] [unique_id "al9V3S7ynBpLeKYztQPUfgAAJlc"]
[Tue Jul 21 08:19:57.583777 2026] [security2:error] [pid 418108:tid 418305] [client 20.226.60.151:59095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/zlece.php"] [unique_id "al9V3Q0cxofL2J1zwYq_fQAAAUs"]
[Tue Jul 21 08:19:57.917383 2026] [security2:error] [pid 411857:tid 412045] [client 14.245.224.124:53285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9V3S7ynBpLeKYztQPUkwAAADg"]
[Tue Jul 21 08:19:57.917522 2026] [security2:error] [pid 411857:tid 412045] [client 14.245.224.124:53285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9V3S7ynBpLeKYztQPUkwAAADg"]
[Tue Jul 21 08:19:57.945858 2026] [security2:error] [pid 418108:tid 418335] [client 20.226.60.151:64076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9V3Q0cxofL2J1zwYq_hQAAAWk"]
[Tue Jul 21 08:19:58.018437 2026] [security2:error] [pid 411857:tid 412106] [client 151.63.71.144:60056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9V3i7ynBpLeKYztQPUlgAAAHU"]
[Tue Jul 21 08:19:58.018559 2026] [security2:error] [pid 411857:tid 412106] [client 151.63.71.144:60056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9V3i7ynBpLeKYztQPUlgAAAHU"]
[Tue Jul 21 08:19:58.206441 2026] [security2:error] [pid 411857:tid 412043] [client 74.249.245.134:62623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/classsmtps.php"] [unique_id "al9V3i7ynBpLeKYztQPUmwAAADY"]
[Tue Jul 21 08:19:58.210454 2026] [security2:error] [pid 411857:tid 412054] [client 20.226.60.151:64051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/vssrs.php"] [unique_id "al9V3i7ynBpLeKYztQPUnAAAAEE"]
[Tue Jul 21 08:19:58.312435 2026] [security2:error] [pid 411857:tid 412044] [client 20.151.10.161:45936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/chosen.php"] [unique_id "al9V3i7ynBpLeKYztQPUoQAAADc"]
[Tue Jul 21 08:19:58.354791 2026] [security2:error] [pid 411857:tid 411993] [client 103.106.20.201:54106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V3i7ynBpLeKYztQPUowAAAAQ"]
[Tue Jul 21 08:19:58.354993 2026] [security2:error] [pid 411857:tid 411993] [client 103.106.20.201:54106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V3i7ynBpLeKYztQPUowAAAAQ"]
[Tue Jul 21 08:19:58.368981 2026] [security2:error] [pid 411857:tid 411885] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9V3i7ynBpLeKYztQPUpAAAGxo"]
[Tue Jul 21 08:19:58.369198 2026] [security2:error] [pid 411857:tid 412016] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9V3i7ynBpLeKYztQPUpAAAGxo"]
[Tue Jul 21 08:19:58.525287 2026] [security2:error] [pid 411857:tid 412058] [client 162.219.176.3:37704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9V3i7ynBpLeKYztQPUrgAAAEU"]
[Tue Jul 21 08:19:58.525390 2026] [security2:error] [pid 411857:tid 412058] [client 162.219.176.3:37704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9V3i7ynBpLeKYztQPUrgAAAEU"]
[Tue Jul 21 08:19:58.831359 2026] [security2:error] [pid 411857:tid 412101] [client 65.21.113.253:57486] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V3i7ynBpLeKYztQPUngAAAHA"]
[Tue Jul 21 08:19:58.837620 2026] [security2:error] [pid 418108:tid 418346] [client 150.129.202.39:12739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V3g0cxofL2J1zwYq_lAAAAXQ"]
[Tue Jul 21 08:19:58.837754 2026] [security2:error] [pid 418108:tid 418346] [client 150.129.202.39:12739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V3g0cxofL2J1zwYq_lAAAAXQ"]
[Tue Jul 21 08:19:58.898457 2026] [security2:error] [pid 411857:tid 411912] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php"] [unique_id "al9V3i7ynBpLeKYztQPUugAAQzU"]
[Tue Jul 21 08:19:58.911829 2026] [security2:error] [pid 411857:tid 412021] [client 117.210.135.0:55735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V3i7ynBpLeKYztQPUwAAAACA"]
[Tue Jul 21 08:19:58.911937 2026] [security2:error] [pid 411857:tid 412021] [client 117.210.135.0:55735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V3i7ynBpLeKYztQPUwAAAACA"]
[Tue Jul 21 08:19:58.960020 2026] [security2:error] [pid 411857:tid 411971] [remote 57.141.18.119:44756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9V3i7ynBpLeKYztQPUywAAH28"]
[Tue Jul 21 08:19:59.004727 2026] [security2:error] [pid 411857:tid 411948] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env.backup"] [unique_id "al9V3y7ynBpLeKYztQPUzQAAJFk"]
[Tue Jul 21 08:19:59.028444 2026] [authz_core:error] [pid 411857:tid 411986] [remote 103.215.74.26:40804] AH01630: client denied by server configuration: /home4/chefdo14/atom-growth.com/.htpasswd
[Tue Jul 21 08:19:59.275976 2026] [security2:error] [pid 411857:tid 412041] [client 20.226.60.151:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wicked.php"] [unique_id "al9V3y7ynBpLeKYztQPU2wAAADQ"]
[Tue Jul 21 08:19:59.696025 2026] [security2:error] [pid 411857:tid 412044] [client 173.252.95.4:39080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9V3y7ynBpLeKYztQPU5gAAADc"]
[Tue Jul 21 08:19:59.745092 2026] [security2:error] [pid 411857:tid 411977] [remote 142.44.225.56:57096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "avermetais.com.br"] [uri "/drum/"] [unique_id "al9V3y7ynBpLeKYztQPU6QAAJHU"]
[Tue Jul 21 08:19:59.745259 2026] [security2:error] [pid 411857:tid 412025] [client 142.44.225.56:57096] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "avermetais.com.br"] [uri "/drum/"] [unique_id "al9V3y7ynBpLeKYztQPU6QAAJHU"]
[Tue Jul 21 08:19:59.877321 2026] [security2:error] [pid 418108:tid 418276] [client 111.93.58.162:34395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9V3w0cxofL2J1zwYq_pQAAAS4"]
[Tue Jul 21 08:19:59.877474 2026] [security2:error] [pid 418108:tid 418276] [client 111.93.58.162:34395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9V3w0cxofL2J1zwYq_pQAAAS4"]
[Tue Jul 21 08:19:59.922629 2026] [security2:error] [pid 411857:tid 412021] [client 74.249.245.134:62636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/rip.php"] [unique_id "al9V3y7ynBpLeKYztQPU8gAAACA"]
[Tue Jul 21 08:20:00.232388 2026] [security2:error] [pid 411857:tid 411880] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V4C7ynBpLeKYztQPU_AAAIhU"]
[Tue Jul 21 08:20:00.232643 2026] [security2:error] [pid 411857:tid 412023] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V4C7ynBpLeKYztQPU_AAAIhU"]
[Tue Jul 21 08:20:00.534051 2026] [security2:error] [pid 418108:tid 418314] [client 185.213.175.37:60212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "autodiscover.x45consultoria.com.br"] [uri "/"] [unique_id "al9V4A0cxofL2J1zwYq_tAAAAVQ"]
[Tue Jul 21 08:20:00.534145 2026] [security2:error] [pid 418108:tid 418314] [client 185.213.175.37:60212] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.x45consultoria.com.br"] [uri "/"] [unique_id "al9V4A0cxofL2J1zwYq_tAAAAVQ"]
[Tue Jul 21 08:20:00.728268 2026] [security2:error] [pid 411857:tid 412095] [client 120.56.162.40:61450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V4C7ynBpLeKYztQPVCgAAAGo"]
[Tue Jul 21 08:20:00.728392 2026] [security2:error] [pid 411857:tid 412095] [client 120.56.162.40:61450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V4C7ynBpLeKYztQPVCgAAAGo"]
[Tue Jul 21 08:20:00.775050 2026] [authz_core:error] [pid 411857:tid 412056] [client 103.215.74.26:0] AH01630: client denied by server configuration: /home4/chefdo14/atom-growth.com/.htpasswd
[Tue Jul 21 08:20:00.806326 2026] [security2:error] [pid 418108:tid 418326] [client 20.226.60.151:64021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/h02ugyh.php"] [unique_id "al9V4A0cxofL2J1zwYq_tgAAAWA"]
[Tue Jul 21 08:20:00.859083 2026] [security2:error] [pid 411857:tid 412011] [client 20.226.60.151:64039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/24.php"] [unique_id "al9V4C7ynBpLeKYztQPVEQAAABY"]
[Tue Jul 21 08:20:01.030289 2026] [security2:error] [pid 411857:tid 412039] [client 65.21.113.253:57486] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V4C7ynBpLeKYztQPVBwAAADI"]
[Tue Jul 21 08:20:01.165851 2026] [security2:error] [pid 418108:tid 418162] [remote 17.241.75.158:33510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.75.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9V4Q0cxofL2J1zwYq_ugABajM"]
[Tue Jul 21 08:20:01.834720 2026] [security2:error] [pid 411857:tid 411906] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9V4S7ynBpLeKYztQPVLwAAGS8"]
[Tue Jul 21 08:20:01.834925 2026] [security2:error] [pid 411857:tid 412014] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9V4S7ynBpLeKYztQPVLwAAGS8"]
[Tue Jul 21 08:20:02.009242 2026] [security2:error] [pid 418108:tid 418300] [client 20.226.60.151:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/xacs.php"] [unique_id "al9V4g0cxofL2J1zwYq_wgAAAUY"]
[Tue Jul 21 08:20:02.036288 2026] [security2:error] [pid 418108:tid 418345] [client 74.249.245.134:62616] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webmail.roanalacerda.com.br"] [uri "/1.php"] [unique_id "al9V4g0cxofL2J1zwYq_wwAAAXM"]
[Tue Jul 21 08:20:02.036457 2026] [security2:error] [pid 418108:tid 418345] [client 74.249.245.134:62616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/1.php"] [unique_id "al9V4g0cxofL2J1zwYq_wwAAAXM"]
[Tue Jul 21 08:20:02.140805 2026] [security2:error] [pid 411857:tid 411863] [remote 72.167.132.114:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/xmlrpc.php"] [unique_id "al9V4i7ynBpLeKYztQPVQAAAcgQ"]
[Tue Jul 21 08:20:02.142141 2026] [security2:error] [pid 411857:tid 412103] [client 72.167.132.114:55264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "supremaservices.net"] [uri "/xmlrpc.php"] [unique_id "al9V4i7ynBpLeKYztQPVQAAAcgQ"]
[Tue Jul 21 08:20:02.509189 2026] [authz_core:error] [pid 411857:tid 411890] [remote 103.215.74.26:40804] AH01630: client denied by server configuration: /home4/chefdo14/atom-growth.com/.htpasswd
[Tue Jul 21 08:20:02.685173 2026] [proxy:error] [pid 411857:tid 412059] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:20:02.685250 2026] [proxy_http:error] [pid 411857:tid 412059] [client 87.236.176.172:56251] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:20:02.685738 2026] [proxy:error] [pid 411857:tid 412059] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:20:02.685766 2026] [proxy_http:error] [pid 411857:tid 412059] [client 87.236.176.172:56251] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:20:02.778746 2026] [security2:error] [pid 411857:tid 411878] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9V4i7ynBpLeKYztQPVVQAALRM"]
[Tue Jul 21 08:20:02.778934 2026] [security2:error] [pid 411857:tid 412034] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9V4i7ynBpLeKYztQPVVQAALRM"]
[Tue Jul 21 08:20:02.939327 2026] [security2:error] [pid 418108:tid 418169] [remote 17.241.75.158:33510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.75.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9V4g0cxofL2J1zwYq_zQABWjo"]
[Tue Jul 21 08:20:03.092356 2026] [security2:error] [pid 411857:tid 411999] [client 65.21.113.253:57486] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V4i7ynBpLeKYztQPVUAAAAAo"]
[Tue Jul 21 08:20:03.098466 2026] [security2:error] [pid 411857:tid 412106] [client 20.226.60.151:64098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-temp.php"] [unique_id "al9V4y7ynBpLeKYztQPVYQAAAHU"]
[Tue Jul 21 08:20:03.494135 2026] [security2:error] [pid 411857:tid 412024] [client 154.208.47.43:2840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9V4y7ynBpLeKYztQPVdAAAACM"]
[Tue Jul 21 08:20:03.494303 2026] [security2:error] [pid 411857:tid 412024] [client 154.208.47.43:2840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9V4y7ynBpLeKYztQPVdAAAACM"]
[Tue Jul 21 08:20:03.690542 2026] [security2:error] [pid 411857:tid 412070] [client 38.100.221.102:18562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V4y7ynBpLeKYztQPVfgAAAFE"]
[Tue Jul 21 08:20:03.690720 2026] [security2:error] [pid 411857:tid 412070] [client 38.100.221.102:18562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V4y7ynBpLeKYztQPVfgAAAFE"]
[Tue Jul 21 08:20:03.691062 2026] [security2:error] [pid 411857:tid 412039] [client 20.226.60.151:64066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/zildan.php"] [unique_id "al9V4y7ynBpLeKYztQPVfwAAADI"]
[Tue Jul 21 08:20:03.736632 2026] [proxy:error] [pid 411857:tid 412034] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:20:03.736705 2026] [proxy_http:error] [pid 411857:tid 412034] [client 205.210.31.151:61306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:20:03.739379 2026] [proxy:error] [pid 411857:tid 412034] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:20:03.739449 2026] [proxy_http:error] [pid 411857:tid 412034] [client 205.210.31.151:61306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:20:03.895698 2026] [security2:error] [pid 411857:tid 412035] [client 65.21.113.253:57486] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V4y7ynBpLeKYztQPVbQAAAC4"]
[Tue Jul 21 08:20:03.908903 2026] [security2:error] [pid 411857:tid 411963] [remote 192.241.143.148:53232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/wp-login.php"] [unique_id "al9V4y7ynBpLeKYztQPViAAAGWc"]
[Tue Jul 21 08:20:04.005982 2026] [security2:error] [pid 418108:tid 418302] [client 185.213.175.37:60236] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.rinettoar.com.br"] [uri "/public/.git/HEAD"] [unique_id "al9V5A0cxofL2J1zwYq_3wAAAUg"]
[Tue Jul 21 08:20:04.058666 2026] [security2:error] [pid 411857:tid 412077] [client 223.181.60.88:29927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9V5C7ynBpLeKYztQPVkQAAAFg"]
[Tue Jul 21 08:20:04.058768 2026] [security2:error] [pid 411857:tid 412077] [client 223.181.60.88:29927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9V5C7ynBpLeKYztQPVkQAAAFg"]
[Tue Jul 21 08:20:04.114326 2026] [security2:error] [pid 418108:tid 418141] [remote 147.50.252.213:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "annaguimaraes.com.br"] [uri "/wp-login.php"] [unique_id "al9V5A0cxofL2J1zwYq_4AABJR4"]
[Tue Jul 21 08:20:04.136523 2026] [security2:error] [pid 411857:tid 412084] [client 20.226.60.151:50138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-css.php"] [unique_id "al9V5C7ynBpLeKYztQPVkwAAAF8"]
[Tue Jul 21 08:20:04.138998 2026] [qos:error] [pid 411857:tid 411880] [remote 57.141.18.110:60828] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.110, id=al9V5C7ynBpLeKYztQPVlAAAExU
[Tue Jul 21 08:20:04.252642 2026] [authz_core:error] [pid 411857:tid 412009] [client 103.215.74.26:0] AH01630: client denied by server configuration: /home4/chefdo14/atom-growth.com/.htpasswd, referer: https://www.google.com/
[Tue Jul 21 08:20:04.281796 2026] [security2:error] [pid 418108:tid 418259] [client 20.226.60.151:59283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/csa.php"] [unique_id "al9V5A0cxofL2J1zwYq_4wAAAR0"]
[Tue Jul 21 08:20:04.318450 2026] [access_compat:error] [pid 411857:tid 412058] [client 162.241.63.68:20122] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:20:04.389970 2026] [security2:error] [pid 411857:tid 411992] [client 187.125.243.197:61911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9V5C7ynBpLeKYztQPVoQAAAAM"]
[Tue Jul 21 08:20:04.390109 2026] [security2:error] [pid 411857:tid 411992] [client 187.125.243.197:61911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9V5C7ynBpLeKYztQPVoQAAAAM"]
[Tue Jul 21 08:20:04.394884 2026] [security2:error] [pid 418108:tid 418336] [client 20.226.60.151:59080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9V5A0cxofL2J1zwYq_5AAAAWo"]
[Tue Jul 21 08:20:04.479063 2026] [security2:error] [pid 418108:tid 418351] [client 20.226.60.151:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/w3llscc.php"] [unique_id "al9V5A0cxofL2J1zwYq_5wAAAXk"]
[Tue Jul 21 08:20:04.604872 2026] [security2:error] [pid 418108:tid 418316] [client 115.134.11.136:65113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V5A0cxofL2J1zwYq_6AAAAVY"]
[Tue Jul 21 08:20:04.605067 2026] [security2:error] [pid 418108:tid 418316] [client 115.134.11.136:65113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V5A0cxofL2J1zwYq_6AAAAVY"]
[Tue Jul 21 08:20:04.770823 2026] [security2:error] [pid 411857:tid 412058] [client 20.226.60.151:64092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wpx.php"] [unique_id "al9V5C7ynBpLeKYztQPVrAAAAEU"]
[Tue Jul 21 08:20:04.772761 2026] [security2:error] [pid 411857:tid 412020] [client 185.213.175.37:60238] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.rinettoar.com.br"] [uri "/backend/.git/HEAD"] [unique_id "al9V5C7ynBpLeKYztQPVrQAAAB8"]
[Tue Jul 21 08:20:04.866295 2026] [qos:error] [pid 418108:tid 418131] [remote 57.141.18.18:24698] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.18, id=al9V5A0cxofL2J1zwYq_6QABSxQ
[Tue Jul 21 08:20:04.892206 2026] [security2:error] [pid 411857:tid 412027] [client 74.249.245.134:55217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/chosen.php"] [unique_id "al9V5C7ynBpLeKYztQPVsQAAACY"]
[Tue Jul 21 08:20:04.909259 2026] [security2:error] [pid 411857:tid 412011] [client 103.151.46.103:58776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9V5C7ynBpLeKYztQPVswAAABY"]
[Tue Jul 21 08:20:04.909977 2026] [security2:error] [pid 411857:tid 412011] [client 103.151.46.103:58776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9V5C7ynBpLeKYztQPVswAAABY"]
[Tue Jul 21 08:20:04.918661 2026] [qos:error] [pid 411857:tid 411887] [remote 57.141.18.64:39724] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.64, id=al9V5C7ynBpLeKYztQPVtgAANBw
[Tue Jul 21 08:20:05.157274 2026] [qos:error] [pid 418108:tid 418121] [remote 57.141.18.28:52810] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.28, id=al9V5Q0cxofL2J1zwYq_7gABcgo
[Tue Jul 21 08:20:05.498899 2026] [security2:error] [pid 411857:tid 412021] [client 61.1.167.83:63484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V5S7ynBpLeKYztQPVxAAAACA"]
[Tue Jul 21 08:20:05.499020 2026] [security2:error] [pid 411857:tid 412021] [client 61.1.167.83:63484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V5S7ynBpLeKYztQPVxAAAACA"]
[Tue Jul 21 08:20:06.015946 2026] [security2:error] [pid 411857:tid 411942] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V5i7ynBpLeKYztQPV1gAAI1M"]
[Tue Jul 21 08:20:06.016133 2026] [security2:error] [pid 411857:tid 412024] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V5i7ynBpLeKYztQPV1gAAI1M"]
[Tue Jul 21 08:20:06.018926 2026] [authz_core:error] [pid 411857:tid 412055] [client 103.215.74.26:0] AH01630: client denied by server configuration: /home4/chefdo14/atom-growth.com/.htpasswd, referer: https://www.bing.com/
[Tue Jul 21 08:20:06.081973 2026] [security2:error] [pid 411857:tid 412090] [client 20.226.60.151:59320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9V5i7ynBpLeKYztQPV3wAAAGU"]
[Tue Jul 21 08:20:06.087356 2026] [security2:error] [pid 411857:tid 412068] [client 74.249.245.134:55195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/css.php"] [unique_id "al9V5i7ynBpLeKYztQPV4QAAAE8"]
[Tue Jul 21 08:20:06.113546 2026] [qos:error] [pid 411857:tid 411863] [remote 57.141.18.95:62046] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.95, id=al9V5i7ynBpLeKYztQPV4gAANAQ
[Tue Jul 21 08:20:06.162275 2026] [qos:error] [pid 418108:tid 418117] [remote 57.141.18.40:26328] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.40, id=al9V5g0cxofL2J1zwYq_9AABPAY
[Tue Jul 21 08:20:06.425915 2026] [security2:error] [pid 411857:tid 411961] [remote 72.167.132.114:43560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rqracademy.com"] [uri "/wp-login.php"] [unique_id "al9V5i7ynBpLeKYztQPV6QAAE2U"]
[Tue Jul 21 08:20:06.470349 2026] [security2:error] [pid 418108:tid 418293] [client 20.226.60.151:64021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-css.php"] [unique_id "al9V5g0cxofL2J1zwYq_-AAAAT8"]
[Tue Jul 21 08:20:07.090269 2026] [core:alert] [pid 411857:tid 412020] [client 57.141.18.81:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:20:07.215646 2026] [security2:error] [pid 411857:tid 411992] [client 65.21.113.253:41816] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V5y7ynBpLeKYztQPV-QAAAAM"]
[Tue Jul 21 08:20:07.606316 2026] [security2:error] [pid 411857:tid 411998] [client 74.249.245.134:43146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/php.php"] [unique_id "al9V5y7ynBpLeKYztQPWEQAAAAk"]
[Tue Jul 21 08:20:07.616611 2026] [core:error] [pid 418108:tid 418278] [client 167.99.54.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:20:07.616636 2026] [core:error] [pid 418108:tid 418278] [client 167.99.54.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:20:07.647342 2026] [security2:error] [pid 411857:tid 412016] [client 117.213.202.34:54870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V5y7ynBpLeKYztQPWFAAAABs"]
[Tue Jul 21 08:20:07.647480 2026] [security2:error] [pid 411857:tid 412016] [client 117.213.202.34:54870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V5y7ynBpLeKYztQPWFAAAABs"]
[Tue Jul 21 08:20:07.851284 2026] [security2:error] [pid 418108:tid 418250] [client 152.59.34.51:56364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9V5w0cxofL2J1zwYrABAAAARQ"]
[Tue Jul 21 08:20:07.851405 2026] [security2:error] [pid 418108:tid 418250] [client 152.59.34.51:56364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9V5w0cxofL2J1zwYrABAAAARQ"]
[Tue Jul 21 08:20:07.873474 2026] [security2:error] [pid 411857:tid 412075] [client 20.226.60.151:64031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/ho.php"] [unique_id "al9V5y7ynBpLeKYztQPWGwAAAFY"]
[Tue Jul 21 08:20:07.895194 2026] [security2:error] [pid 411857:tid 412015] [client 65.21.113.253:57486] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V5y7ynBpLeKYztQPWCwAAABo"]
[Tue Jul 21 08:20:07.934227 2026] [authz_core:error] [pid 411857:tid 412106] [client 103.215.74.26:0] AH01630: client denied by server configuration: /home4/chefdo14/atom-growth.com/.htpasswd, referer: https://duckduckgo.com/
[Tue Jul 21 08:20:07.943650 2026] [security2:error] [pid 411857:tid 412001] [client 162.219.176.3:37724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9V5y7ynBpLeKYztQPWJAAAAAw"]
[Tue Jul 21 08:20:07.943717 2026] [security2:error] [pid 411857:tid 412001] [client 162.219.176.3:37724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9V5y7ynBpLeKYztQPWJAAAAAw"]
[Tue Jul 21 08:20:08.044481 2026] [security2:error] [pid 411857:tid 412097] [client 87.116.180.198:14068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V6C7ynBpLeKYztQPWJgAAAGw"]
[Tue Jul 21 08:20:08.049074 2026] [security2:error] [pid 411857:tid 412097] [client 87.116.180.198:14068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V6C7ynBpLeKYztQPWJgAAAGw"]
[Tue Jul 21 08:20:08.375255 2026] [security2:error] [pid 411857:tid 411880] [remote 173.252.95.15:39894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9V6C7ynBpLeKYztQPWLgAAaBU"]
[Tue Jul 21 08:20:08.522136 2026] [security2:error] [pid 418108:tid 418334] [client 20.226.60.151:64072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/jj.php"] [unique_id "al9V6A0cxofL2J1zwYrACAAAAWg"]
[Tue Jul 21 08:20:08.980145 2026] [security2:error] [pid 411857:tid 412064] [client 74.249.245.134:56487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/aa.php"] [unique_id "al9V6C7ynBpLeKYztQPWQgAAAEs"]
[Tue Jul 21 08:20:09.011372 2026] [qos:error] [pid 418108:tid 418166] [remote 57.141.18.115:64642] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.115, id=al9V6Q0cxofL2J1zwYrADAABcDc
[Tue Jul 21 08:20:09.079860 2026] [security2:error] [pid 411857:tid 411943] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9V6S7ynBpLeKYztQPWRQAACVQ"]
[Tue Jul 21 08:20:09.079995 2026] [security2:error] [pid 411857:tid 411998] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9V6S7ynBpLeKYztQPWRQAACVQ"]
[Tue Jul 21 08:20:09.151682 2026] [security2:error] [pid 411857:tid 411994] [client 103.106.20.201:54701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V6S7ynBpLeKYztQPWRwAAAAU"]
[Tue Jul 21 08:20:09.151787 2026] [security2:error] [pid 411857:tid 411994] [client 103.106.20.201:54701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V6S7ynBpLeKYztQPWRwAAAAU"]
[Tue Jul 21 08:20:09.309132 2026] [security2:error] [pid 411857:tid 412001] [client 20.226.60.151:64020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/xy.php"] [unique_id "al9V6S7ynBpLeKYztQPWTAAAAAw"]
[Tue Jul 21 08:20:09.353319 2026] [security2:error] [pid 411857:tid 412027] [client 150.129.202.39:65181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V6S7ynBpLeKYztQPWTgAAACY"]
[Tue Jul 21 08:20:09.353525 2026] [security2:error] [pid 411857:tid 412027] [client 150.129.202.39:65181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V6S7ynBpLeKYztQPWTgAAACY"]
[Tue Jul 21 08:20:09.528434 2026] [security2:error] [pid 411857:tid 411999] [client 14.245.224.124:53751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9V6S7ynBpLeKYztQPWVQAAAAo"]
[Tue Jul 21 08:20:09.528572 2026] [security2:error] [pid 411857:tid 411999] [client 14.245.224.124:53751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9V6S7ynBpLeKYztQPWVQAAAAo"]
[Tue Jul 21 08:20:09.596180 2026] [security2:error] [pid 418108:tid 418201] [remote 20.153.140.50:56074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9V6Q0cxofL2J1zwYrADwABOVo"]
[Tue Jul 21 08:20:09.634701 2026] [security2:error] [pid 411857:tid 412068] [client 117.210.135.0:56385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V6S7ynBpLeKYztQPWWAAAAE8"]
[Tue Jul 21 08:20:09.634865 2026] [security2:error] [pid 411857:tid 412068] [client 117.210.135.0:56385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V6S7ynBpLeKYztQPWWAAAAE8"]
[Tue Jul 21 08:20:09.664674 2026] [security2:error] [pid 411857:tid 412008] [client 198.54.129.60:43174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9V6S7ynBpLeKYztQPWWgAAABM"]
[Tue Jul 21 08:20:09.664764 2026] [security2:error] [pid 411857:tid 412008] [client 198.54.129.60:43174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9V6S7ynBpLeKYztQPWWgAAABM"]
[Tue Jul 21 08:20:10.043678 2026] [security2:error] [pid 411857:tid 412063] [client 65.21.113.253:57486] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V6S7ynBpLeKYztQPWVwAAAEo"]
[Tue Jul 21 08:20:10.138241 2026] [security2:error] [pid 411857:tid 412112] [client 74.249.245.134:62775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/bolt.php"] [unique_id "al9V6i7ynBpLeKYztQPWaAAAAHs"]
[Tue Jul 21 08:20:10.150702 2026] [security2:error] [pid 411857:tid 411994] [client 20.226.60.151:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9V6i7ynBpLeKYztQPWaQAAAAU"]
[Tue Jul 21 08:20:10.363719 2026] [autoindex:error] [pid 411857:tid 412114] [client 43.134.38.171:34882] AH01276: Cannot serve directory /home2/adri0227/espacocomproposito.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:20:10.423907 2026] [core:error] [pid 411857:tid 412044] [client 167.99.54.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.imperdivelbestpromotionofthedaytodayonly.com/
[Tue Jul 21 08:20:10.423927 2026] [core:error] [pid 411857:tid 412044] [client 167.99.54.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.imperdivelbestpromotionofthedaytodayonly.com/
[Tue Jul 21 08:20:10.641962 2026] [security2:error] [pid 411857:tid 412097] [client 111.93.58.162:55645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9V6i7ynBpLeKYztQPWfAAAAGw"]
[Tue Jul 21 08:20:10.642100 2026] [security2:error] [pid 411857:tid 412097] [client 111.93.58.162:55645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9V6i7ynBpLeKYztQPWfAAAAGw"]
[Tue Jul 21 08:20:10.763492 2026] [security2:error] [pid 418108:tid 418367] [client 20.226.60.151:64073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/loader.php"] [unique_id "al9V6g0cxofL2J1zwYrAGQAAAYk"]
[Tue Jul 21 08:20:10.826562 2026] [security2:error] [pid 418108:tid 418281] [client 20.226.60.151:59273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/txets.php"] [unique_id "al9V6g0cxofL2J1zwYrAHAAAATM"]
[Tue Jul 21 08:20:10.939560 2026] [security2:error] [pid 418108:tid 418200] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V6g0cxofL2J1zwYrAIAABO1k"]
[Tue Jul 21 08:20:10.939734 2026] [security2:error] [pid 418108:tid 418289] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V6g0cxofL2J1zwYrAIAABO1k"]
[Tue Jul 21 08:20:10.981434 2026] [security2:error] [pid 418108:tid 418231] [remote 97.74.93.24:49956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/wp-login.php"] [unique_id "al9V6g0cxofL2J1zwYrAIQABQXg"]
[Tue Jul 21 08:20:11.308128 2026] [security2:error] [pid 411857:tid 411903] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/phpinfo.php"] [unique_id "al9V6y7ynBpLeKYztQPWmwAAWCw"]
[Tue Jul 21 08:20:11.312087 2026] [security2:error] [pid 411857:tid 411864] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/info.php"] [unique_id "al9V6y7ynBpLeKYztQPWogAAWAU"]
[Tue Jul 21 08:20:11.313862 2026] [security2:error] [pid 411857:tid 411982] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/opcache-status.php"] [unique_id "al9V6y7ynBpLeKYztQPWrQAAWHo"]
[Tue Jul 21 08:20:11.316438 2026] [security2:error] [pid 411857:tid 411887] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php"] [unique_id "al9V6y7ynBpLeKYztQPWxAAAWBw"]
[Tue Jul 21 08:20:11.330319 2026] [security2:error] [pid 411857:tid 419447] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php"] [unique_id "al9V6y7ynBpLeKYztQPW5wAAWII"]
[Tue Jul 21 08:20:11.394838 2026] [security2:error] [pid 411857:tid 419469] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env.copy"] [unique_id "al9V6y7ynBpLeKYztQPW9AAAWJc"]
[Tue Jul 21 08:20:11.395256 2026] [security2:error] [pid 411857:tid 419447] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env.local.backup"] [unique_id "al9V6y7ynBpLeKYztQPW8gAAWII"]
[Tue Jul 21 08:20:11.395273 2026] [security2:error] [pid 411857:tid 419468] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env.bak"] [unique_id "al9V6y7ynBpLeKYztQPW8wAAWJY"]
[Tue Jul 21 08:20:11.473600 2026] [security2:error] [pid 418108:tid 418307] [client 120.56.162.40:61966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V6w0cxofL2J1zwYrAaAAAAU0"]
[Tue Jul 21 08:20:11.473738 2026] [security2:error] [pid 418108:tid 418307] [client 120.56.162.40:61966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V6w0cxofL2J1zwYrAaAAAAU0"]
[Tue Jul 21 08:20:11.485113 2026] [security2:error] [pid 418108:tid 418344] [client 20.226.60.151:59317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/dex.php"] [unique_id "al9V6w0cxofL2J1zwYrAbwAAAXI"]
[Tue Jul 21 08:20:11.487635 2026] [qos:error] [pid 418108:tid 418275] [client 103.215.74.26:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9V6w0cxofL2J1zwYrAUgAAAS0
[Tue Jul 21 08:20:11.491450 2026] [qos:error] [pid 418108:tid 418266] [client 103.215.74.26:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9V6w0cxofL2J1zwYrAWQAAASQ
[Tue Jul 21 08:20:11.500676 2026] [qos:error] [pid 418108:tid 418258] [client 103.215.74.26:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9V6w0cxofL2J1zwYrAbgAAARw
[Tue Jul 21 08:20:11.501304 2026] [qos:error] [pid 418108:tid 418366] [client 103.215.74.26:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9V6w0cxofL2J1zwYrAcwAAAYg
[Tue Jul 21 08:20:11.501624 2026] [qos:error] [pid 418108:tid 418341] [client 103.215.74.26:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9V6w0cxofL2J1zwYrAWgAAAW8
[Tue Jul 21 08:20:11.501774 2026] [qos:error] [pid 418108:tid 418242] [client 103.215.74.26:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9V6w0cxofL2J1zwYrAdAAAAQw
[Tue Jul 21 08:20:11.674849 2026] [security2:error] [pid 411857:tid 412084] [client 65.21.113.253:57486] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V6y7ynBpLeKYztQPXFAAAAF8"]
[Tue Jul 21 08:20:11.699389 2026] [security2:error] [pid 411857:tid 412075] [client 74.249.245.134:43101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/x.php"] [unique_id "al9V6y7ynBpLeKYztQPXFwAAAFY"]
[Tue Jul 21 08:20:11.797680 2026] [security2:error] [pid 411857:tid 411994] [client 20.220.225.223:12321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9V6y7ynBpLeKYztQPXGgAAAAU"]
[Tue Jul 21 08:20:12.258284 2026] [security2:error] [pid 411857:tid 412058] [client 20.226.60.151:64067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/spadex.php"] [unique_id "al9V7C7ynBpLeKYztQPXKgAAAEU"]
[Tue Jul 21 08:20:12.325911 2026] [security2:error] [pid 411857:tid 411879] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/wp-login.php"] [unique_id "al9V6y7ynBpLeKYztQPWwwAAWBQ"]
[Tue Jul 21 08:20:12.408667 2026] [http2:info] [pid 419508:tid 419508] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 08:20:12.445617 2026] [security2:error] [pid 411857:tid 412080] [client 20.226.60.151:64073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/xpwer1.php"] [unique_id "al9V7C7ynBpLeKYztQPXLwAAAFs"]
[Tue Jul 21 08:20:12.556575 2026] [security2:error] [pid 418108:tid 418233] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9V7A0cxofL2J1zwYrAgwABbno"]
[Tue Jul 21 08:20:12.556825 2026] [security2:error] [pid 418108:tid 418340] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9V7A0cxofL2J1zwYrAgwABbno"]
[Tue Jul 21 08:20:12.801364 2026] [security2:error] [pid 411857:tid 411998] [client 65.21.113.253:43532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V7C7ynBpLeKYztQPXKwAAAAk"]
[Tue Jul 21 08:20:12.918109 2026] [security2:error] [pid 411857:tid 412098] [client 74.249.245.134:21666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/jga.php"] [unique_id "al9V7C7ynBpLeKYztQPXOwAAAG0"]
[Tue Jul 21 08:20:13.016679 2026] [security2:error] [pid 411857:tid 412063] [client 20.220.225.223:31187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/yup.php"] [unique_id "al9V7S7ynBpLeKYztQPXQAAAAEo"]
[Tue Jul 21 08:20:13.245406 2026] [security2:error] [pid 411857:tid 419454] [remote 45.79.123.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/wp-login.php"] [unique_id "al9V7S7ynBpLeKYztQPXRAAADog"]
[Tue Jul 21 08:20:13.335884 2026] [security2:error] [pid 419508:tid 419618] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9V7VcagwCeNbomjVv9PQABrW0"]
[Tue Jul 21 08:20:13.336394 2026] [security2:error] [pid 419508:tid 419668] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9V7VcagwCeNbomjVv9PQABrW0"]
[Tue Jul 21 08:20:13.336582 2026] [security2:error] [pid 418108:tid 418264] [client 62.102.148.158:36566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9V7Q0cxofL2J1zwYrAiAAAASI"]
[Tue Jul 21 08:20:13.336707 2026] [security2:error] [pid 418108:tid 418264] [client 62.102.148.158:36566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9V7Q0cxofL2J1zwYrAiAAAASI"]
[Tue Jul 21 08:20:13.476581 2026] [security2:error] [pid 418108:tid 418341] [client 20.226.60.151:64092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/flox.php"] [unique_id "al9V7Q0cxofL2J1zwYrAigAAAW8"]
[Tue Jul 21 08:20:13.483600 2026] [security2:error] [pid 411857:tid 412090] [client 20.226.60.151:60634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/ho.php"] [unique_id "al9V7S7ynBpLeKYztQPXSwAAAGU"]
[Tue Jul 21 08:20:13.697515 2026] [security2:error] [pid 418108:tid 418275] [client 162.219.176.3:42104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9V7Q0cxofL2J1zwYrAjgAAAS0"]
[Tue Jul 21 08:20:13.697634 2026] [security2:error] [pid 418108:tid 418275] [client 162.219.176.3:42104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9V7Q0cxofL2J1zwYrAjgAAAS0"]
[Tue Jul 21 08:20:13.765840 2026] [security2:error] [pid 419508:tid 419677] [client 154.208.47.43:3317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9V7VcagwCeNbomjVv9QwAAAbY"]
[Tue Jul 21 08:20:13.765990 2026] [security2:error] [pid 419508:tid 419677] [client 154.208.47.43:3317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9V7VcagwCeNbomjVv9QwAAAbY"]
[Tue Jul 21 08:20:13.913499 2026] [security2:error] [pid 419508:tid 419669] [client 20.220.225.223:38713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/jj.php"] [unique_id "al9V7VcagwCeNbomjVv9RAAAAa4"]
[Tue Jul 21 08:20:14.044135 2026] [security2:error] [pid 411857:tid 412062] [client 74.249.245.134:52114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/k.php"] [unique_id "al9V7i7ynBpLeKYztQPXVgAAAEk"]
[Tue Jul 21 08:20:14.304281 2026] [security2:error] [pid 418108:tid 418330] [client 20.226.60.151:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/popo.php"] [unique_id "al9V7g0cxofL2J1zwYrAlQAAAWQ"]
[Tue Jul 21 08:20:14.326770 2026] [security2:error] [pid 411857:tid 412064] [client 38.100.221.102:17857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V7i7ynBpLeKYztQPXWwAAAEs"]
[Tue Jul 21 08:20:14.326961 2026] [security2:error] [pid 411857:tid 412064] [client 38.100.221.102:17857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V7i7ynBpLeKYztQPXWwAAAEs"]
[Tue Jul 21 08:20:14.649870 2026] [security2:error] [pid 418108:tid 418322] [client 115.134.11.136:49177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V7g0cxofL2J1zwYrAlgAAAVw"]
[Tue Jul 21 08:20:14.650562 2026] [security2:error] [pid 418108:tid 418322] [client 115.134.11.136:49177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V7g0cxofL2J1zwYrAlgAAAVw"]
[Tue Jul 21 08:20:14.737985 2026] [security2:error] [pid 419508:tid 419664] [client 86.106.84.166:46336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9V7lcagwCeNbomjVv9SgAAAak"]
[Tue Jul 21 08:20:14.738105 2026] [security2:error] [pid 419508:tid 419664] [client 86.106.84.166:46336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9V7lcagwCeNbomjVv9SgAAAak"]
[Tue Jul 21 08:20:14.784569 2026] [security2:error] [pid 411857:tid 412077] [client 20.220.225.223:42133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/dp.php"] [unique_id "al9V7i7ynBpLeKYztQPXZwAAAFg"]
[Tue Jul 21 08:20:14.821124 2026] [security2:error] [pid 411857:tid 412092] [client 223.181.60.88:16693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9V7i7ynBpLeKYztQPXaAAAAGc"]
[Tue Jul 21 08:20:14.821242 2026] [security2:error] [pid 411857:tid 412092] [client 223.181.60.88:16693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9V7i7ynBpLeKYztQPXaAAAAGc"]
[Tue Jul 21 08:20:14.869358 2026] [security2:error] [pid 419508:tid 419684] [client 187.125.243.197:62409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9V7lcagwCeNbomjVv9SwAAAb0"]
[Tue Jul 21 08:20:14.870258 2026] [security2:error] [pid 419508:tid 419684] [client 187.125.243.197:62409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9V7lcagwCeNbomjVv9SwAAAb0"]
[Tue Jul 21 08:20:14.942921 2026] [security2:error] [pid 411857:tid 412000] [client 20.226.60.151:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/2x.php"] [unique_id "al9V7i7ynBpLeKYztQPXagAAAAs"]
[Tue Jul 21 08:20:15.104001 2026] [core:error] [pid 411857:tid 411886] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/public_html/.env)
[Tue Jul 21 08:20:15.104081 2026] [security2:error] [pid 411857:tid 411961] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/wp-config.php"] [unique_id "al9V7y7ynBpLeKYztQPXcwAAfWU"]
[Tue Jul 21 08:20:15.104600 2026] [security2:error] [pid 411857:tid 411961] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/config/database.php"] [unique_id "al9V7y7ynBpLeKYztQPXdAAAfWU"]
[Tue Jul 21 08:20:15.106481 2026] [security2:error] [pid 411857:tid 411943] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/application/database.php"] [unique_id "al9V7y7ynBpLeKYztQPXdQAAfVQ"]
[Tue Jul 21 08:20:15.106583 2026] [core:error] [pid 411857:tid 411879] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/laravel/.env)
[Tue Jul 21 08:20:15.107645 2026] [core:error] [pid 411857:tid 411896] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/home/ubuntu/.env)
[Tue Jul 21 08:20:15.108310 2026] [core:error] [pid 411857:tid 411976] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/api/.env)
[Tue Jul 21 08:20:15.191272 2026] [core:error] [pid 411857:tid 411976] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/app/.env)
[Tue Jul 21 08:20:15.192372 2026] [core:error] [pid 411857:tid 411879] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/backend/.env)
[Tue Jul 21 08:20:15.195672 2026] [core:error] [pid 411857:tid 411886] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/vhosts/.env)
[Tue Jul 21 08:20:15.197105 2026] [security2:error] [pid 411857:tid 412021] [client 74.249.245.134:62721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/vx.php"] [unique_id "al9V7y7ynBpLeKYztQPXgwAAACA"]
[Tue Jul 21 08:20:15.243616 2026] [core:error] [pid 411857:tid 411900] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/root/.env)
[Tue Jul 21 08:20:15.243702 2026] [core:error] [pid 411857:tid 411863] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/app/config/parameters.yml)
[Tue Jul 21 08:20:15.243705 2026] [core:error] [pid 411857:tid 411860] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/app/.env)
[Tue Jul 21 08:20:15.243768 2026] [core:error] [pid 411857:tid 411924] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/api/.env)
[Tue Jul 21 08:20:15.243846 2026] [core:error] [pid 411857:tid 411980] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/app/config/parameters.yml)
[Tue Jul 21 08:20:15.324663 2026] [core:error] [pid 411857:tid 411879] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/.env.local)
[Tue Jul 21 08:20:15.350594 2026] [security2:error] [pid 418108:tid 418364] [client 20.226.60.151:64117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/yas.php"] [unique_id "al9V7w0cxofL2J1zwYrAmwAAAYY"]
[Tue Jul 21 08:20:15.403031 2026] [security2:error] [pid 411857:tid 411876] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-content/uploads/wp-config.php.bak"] [unique_id "al9V7y7ynBpLeKYztQPXnAAAfRE"]
[Tue Jul 21 08:20:15.403374 2026] [security2:error] [pid 411857:tid 411876] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/xmlrpc.php"] [unique_id "al9V7y7ynBpLeKYztQPXngAAfRE"]
[Tue Jul 21 08:20:15.404007 2026] [security2:error] [pid 411857:tid 411903] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.orig"] [unique_id "al9V7y7ynBpLeKYztQPXowAAfSw"]
[Tue Jul 21 08:20:15.405098 2026] [security2:error] [pid 411857:tid 411863] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env.backup.swp"] [unique_id "al9V7y7ynBpLeKYztQPXmQAAfQQ"]
[Tue Jul 21 08:20:15.405098 2026] [security2:error] [pid 411857:tid 419455] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env.backup.copy"] [unique_id "al9V7y7ynBpLeKYztQPXnwAAfYk"]
[Tue Jul 21 08:20:15.406576 2026] [security2:error] [pid 411857:tid 419447] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env.backup.backup"] [unique_id "al9V7y7ynBpLeKYztQPXnQAAfYI"]
[Tue Jul 21 08:20:15.407238 2026] [security2:error] [pid 411857:tid 419447] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.dist"] [unique_id "al9V7y7ynBpLeKYztQPXpwAAfYI"]
[Tue Jul 21 08:20:15.412937 2026] [security2:error] [pid 411857:tid 411980] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/vendor/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9V7y7ynBpLeKYztQPXrgAAfXg"]
[Tue Jul 21 08:20:15.413279 2026] [security2:error] [pid 411857:tid 411980] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.bak"] [unique_id "al9V7y7ynBpLeKYztQPXrwAAfXg"]
[Tue Jul 21 08:20:15.464499 2026] [security2:error] [pid 411857:tid 411900] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/wp-config-backup.php"] [unique_id "al9V7y7ynBpLeKYztQPXtgAAfSk"]
[Tue Jul 21 08:20:15.465209 2026] [security2:error] [pid 411857:tid 411900] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php~"] [unique_id "al9V7y7ynBpLeKYztQPXtwAAfSk"]
[Tue Jul 21 08:20:15.465820 2026] [security2:error] [pid 411857:tid 411900] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.inc"] [unique_id "al9V7y7ynBpLeKYztQPXuAAAfSk"]
[Tue Jul 21 08:20:15.466193 2026] [security2:error] [pid 411857:tid 411900] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.old"] [unique_id "al9V7y7ynBpLeKYztQPXuQAAfSk"]
[Tue Jul 21 08:20:15.484830 2026] [security2:error] [pid 411857:tid 419447] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.orig"] [unique_id "al9V7y7ynBpLeKYztQPXvwAAfYI"]
[Tue Jul 21 08:20:15.485732 2026] [security2:error] [pid 411857:tid 419447] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.save"] [unique_id "al9V7y7ynBpLeKYztQPXwAAAfYI"]
[Tue Jul 21 08:20:15.494147 2026] [security2:error] [pid 411857:tid 411976] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.swp"] [unique_id "al9V7y7ynBpLeKYztQPXwgAAfXQ"]
[Tue Jul 21 08:20:15.510427 2026] [security2:error] [pid 411857:tid 411980] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.tmp"] [unique_id "al9V7y7ynBpLeKYztQPXxwAAfXg"]
[Tue Jul 21 08:20:15.528686 2026] [http2:info] [pid 411857:tid 412114] [client 103.215.74.26:40804] AH10178: h2_stream(411857-1604-615,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:20:15.535752 2026] [security2:error] [pid 411857:tid 419455] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.copy"] [unique_id "al9V7y7ynBpLeKYztQPX1AAAfYk"]
[Tue Jul 21 08:20:15.540396 2026] [security2:error] [pid 411857:tid 411863] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/wp-config.copy"] [unique_id "al9V7y7ynBpLeKYztQPX0wAAfQQ"]
[Tue Jul 21 08:20:15.603144 2026] [security2:error] [pid 411857:tid 411892] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.bkp"] [unique_id "al9V7y7ynBpLeKYztQPX5wAAfSE"]
[Tue Jul 21 08:20:15.603531 2026] [security2:error] [pid 411857:tid 411919] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/wp-config.old.php"] [unique_id "al9V7y7ynBpLeKYztQPX5gAAfTw"]
[Tue Jul 21 08:20:15.730787 2026] [security2:error] [pid 411857:tid 412015] [client 65.21.113.253:43532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V7y7ynBpLeKYztQPXfwAAABo"]
[Tue Jul 21 08:20:16.425289 2026] [security2:error] [pid 419508:tid 419728] [client 152.59.34.51:56833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9V8FcagwCeNbomjVv9ggAAAek"]
[Tue Jul 21 08:20:16.425519 2026] [security2:error] [pid 419508:tid 419728] [client 152.59.34.51:56833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9V8FcagwCeNbomjVv9ggAAAek"]
[Tue Jul 21 08:20:16.429233 2026] [security2:error] [pid 418108:tid 418319] [client 20.226.60.151:64126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/file61.php"] [unique_id "al9V8A0cxofL2J1zwYrApgAAAVk"]
[Tue Jul 21 08:20:16.653379 2026] [security2:error] [pid 411857:tid 419459] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V8C7ynBpLeKYztQPX9QAABo0"]
[Tue Jul 21 08:20:16.653551 2026] [security2:error] [pid 411857:tid 411995] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V8C7ynBpLeKYztQPX9QAABo0"]
[Tue Jul 21 08:20:16.717248 2026] [security2:error] [pid 419508:tid 419658] [client 20.220.225.223:49027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/old.php"] [unique_id "al9V8FcagwCeNbomjVv9iwAAAaM"]
[Tue Jul 21 08:20:16.985830 2026] [core:error] [pid 411857:tid 419469] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/.env.production)
[Tue Jul 21 08:20:16.985914 2026] [core:error] [pid 411857:tid 411929] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/home/admin/public_html/.env)
[Tue Jul 21 08:20:16.986181 2026] [core:error] [pid 411857:tid 411948] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/.env.local)
[Tue Jul 21 08:20:16.987235 2026] [core:error] [pid 411857:tid 411961] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/home/admin/web/public_html/.env)
[Tue Jul 21 08:20:16.991855 2026] [core:error] [pid 411857:tid 411943] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/var/www/html/.env)
[Tue Jul 21 08:20:16.992163 2026] [core:error] [pid 411857:tid 411971] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/var/www/.env)
[Tue Jul 21 08:20:17.000093 2026] [core:error] [pid 411857:tid 411956] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/opt/app/.env)
[Tue Jul 21 08:20:17.001603 2026] [core:error] [pid 411857:tid 411861] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/srv/www/.env)
[Tue Jul 21 08:20:17.029958 2026] [security2:error] [pid 419508:tid 419695] [client 74.249.245.134:61028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/ws77.php"] [unique_id "al9V8VcagwCeNbomjVv9mAAAAcg"]
[Tue Jul 21 08:20:17.084629 2026] [core:error] [pid 411857:tid 411871] [remote 103.215.74.26:40804] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/.env)
[Tue Jul 21 08:20:17.084644 2026] [security2:error] [pid 411857:tid 411929] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/var/www/html/wp-config.php"] [unique_id "al9V8S7ynBpLeKYztQPYDQAADEY"]
[Tue Jul 21 08:20:17.084702 2026] [core:error] [pid 411857:tid 419463] [remote 103.215.74.26:40804] AH10244: invalid URI path (/icons/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/var/www/html/.env)
[Tue Jul 21 08:20:17.084725 2026] [core:error] [pid 411857:tid 411896] [remote 103.215.74.26:40804] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/.env)
[Tue Jul 21 08:20:17.084787 2026] [core:error] [pid 411857:tid 411917] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/etc/passwd)
[Tue Jul 21 08:20:17.084787 2026] [core:error] [pid 411857:tid 411909] [remote 103.215.74.26:40804] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/etc/passwd)
[Tue Jul 21 08:20:17.084787 2026] [core:error] [pid 411857:tid 411868] [remote 103.215.74.26:40804] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/etc/passwd)
[Tue Jul 21 08:20:17.085059 2026] [security2:error] [pid 411857:tid 411929] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.php~"] [unique_id "al9V8S7ynBpLeKYztQPYFQAADEY"]
[Tue Jul 21 08:20:17.085202 2026] [core:error] [pid 411857:tid 411983] [remote 103.215.74.26:40804] AH10244: invalid URI path (/icons/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/etc/passwd)
[Tue Jul 21 08:20:17.085441 2026] [security2:error] [pid 411857:tid 411929] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.php.bak"] [unique_id "al9V8S7ynBpLeKYztQPYFgAADEY"]
[Tue Jul 21 08:20:17.085787 2026] [security2:error] [pid 411857:tid 411929] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.php.orig"] [unique_id "al9V8S7ynBpLeKYztQPYFwAADEY"]
[Tue Jul 21 08:20:17.085938 2026] [security2:error] [pid 411857:tid 419454] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.php.old"] [unique_id "al9V8S7ynBpLeKYztQPYGAAADIg"]
[Tue Jul 21 08:20:17.127005 2026] [security2:error] [pid 411857:tid 411939] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.php.save"] [unique_id "al9V8S7ynBpLeKYztQPYHgAADFA"]
[Tue Jul 21 08:20:17.127105 2026] [security2:error] [pid 411857:tid 411887] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.php.swp"] [unique_id "al9V8S7ynBpLeKYztQPYHwAADBw"]
[Tue Jul 21 08:20:17.127155 2026] [security2:error] [pid 411857:tid 419453] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/wp-content/uploads/wp-config.php"] [unique_id "al9V8S7ynBpLeKYztQPYHQAADIc"]
[Tue Jul 21 08:20:17.127347 2026] [security2:error] [pid 411857:tid 411939] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.php.tmp"] [unique_id "al9V8S7ynBpLeKYztQPYIAAADFA"]
[Tue Jul 21 08:20:17.127565 2026] [security2:error] [pid 411857:tid 411887] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.php.backup"] [unique_id "al9V8S7ynBpLeKYztQPYIQAADBw"]
[Tue Jul 21 08:20:17.128075 2026] [security2:error] [pid 411857:tid 411887] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9V8S7ynBpLeKYztQPYJAAADBw"]
[Tue Jul 21 08:20:17.208984 2026] [security2:error] [pid 411857:tid 419445] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/xmlrpc.php"] [unique_id "al9V8S7ynBpLeKYztQPYJgAADIA"]
[Tue Jul 21 08:20:17.209742 2026] [security2:error] [pid 411857:tid 419445] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.php-backup"] [unique_id "al9V8S7ynBpLeKYztQPYJwAADIA"]
[Tue Jul 21 08:20:17.210032 2026] [security2:error] [pid 411857:tid 419445] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.php.copy"] [unique_id "al9V8S7ynBpLeKYztQPYMAAADIA"]
[Tue Jul 21 08:20:17.210478 2026] [security2:error] [pid 411857:tid 419464] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.php.bkp"] [unique_id "al9V8S7ynBpLeKYztQPYMQAADJI"]
[Tue Jul 21 08:20:17.210497 2026] [security2:error] [pid 411857:tid 419446] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.php.1"] [unique_id "al9V8S7ynBpLeKYztQPYNAAADIE"]
[Tue Jul 21 08:20:17.210550 2026] [security2:error] [pid 411857:tid 411913] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/configuration.php.bak"] [unique_id "al9V8S7ynBpLeKYztQPYNQAADDY"]
[Tue Jul 21 08:20:17.210695 2026] [security2:error] [pid 411857:tid 411980] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/configuration.php~"] [unique_id "al9V8S7ynBpLeKYztQPYNwAADHg"]
[Tue Jul 21 08:20:17.211102 2026] [security2:error] [pid 411857:tid 411876] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/configuration.php.old"] [unique_id "al9V8S7ynBpLeKYztQPYOgAADBE"]
[Tue Jul 21 08:20:17.211180 2026] [security2:error] [pid 411857:tid 411865] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/wp-content/uploads/db.sql"] [unique_id "al9V8S7ynBpLeKYztQPYLgAADAY"]
[Tue Jul 21 08:20:17.211386 2026] [security2:error] [pid 411857:tid 411962] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/wp-content/uploads/backup.sql"] [unique_id "al9V8S7ynBpLeKYztQPYLAAADGY"]
[Tue Jul 21 08:20:17.211556 2026] [security2:error] [pid 411857:tid 411940] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/wp-content/uploads/database.sql"] [unique_id "al9V8S7ynBpLeKYztQPYLwAADFE"]
[Tue Jul 21 08:20:17.211688 2026] [security2:error] [pid 411857:tid 419465] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/configuration.php.orig"] [unique_id "al9V8S7ynBpLeKYztQPYPQAADJM"]
[Tue Jul 21 08:20:17.211724 2026] [security2:error] [pid 411857:tid 411980] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php"] [unique_id "al9V8S7ynBpLeKYztQPYPAAADHg"]
[Tue Jul 21 08:20:17.256697 2026] [security2:error] [pid 411857:tid 412034] [client 20.226.60.151:64041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/ctex1.php"] [unique_id "al9V8S7ynBpLeKYztQPYSQAAAC0"]
[Tue Jul 21 08:20:17.270678 2026] [security2:error] [pid 411857:tid 411863] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/xmlrpc.php"] [unique_id "al9V8S7ynBpLeKYztQPYSwAADAQ"]
[Tue Jul 21 08:20:17.280465 2026] [security2:error] [pid 411857:tid 411979] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/wp-content/uploads/dump.sql"] [unique_id "al9V8S7ynBpLeKYztQPYSgAADHc"]
[Tue Jul 21 08:20:17.294960 2026] [http2:info] [pid 411857:tid 412001] [client 103.215.74.26:40804] AH10178: h2_stream(411857-1604-785,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:20:17.296487 2026] [security2:error] [pid 411857:tid 411903] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/configuration.php.save"] [unique_id "al9V8S7ynBpLeKYztQPYTAAADCw"]
[Tue Jul 21 08:20:17.299846 2026] [security2:error] [pid 411857:tid 411932] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/wp-admin/setup-config.php"] [unique_id "al9V8S7ynBpLeKYztQPYTQAADEk"]
[Tue Jul 21 08:20:17.409852 2026] [security2:error] [pid 418108:tid 418268] [client 20.226.60.151:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/water.php"] [unique_id "al9V8Q0cxofL2J1zwYrAuwAAASY"]
[Tue Jul 21 08:20:17.479737 2026] [security2:error] [pid 411857:tid 412046] [client 103.151.46.103:59275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9V8S7ynBpLeKYztQPYcwAAADk"]
[Tue Jul 21 08:20:17.482475 2026] [security2:error] [pid 411857:tid 412046] [client 103.151.46.103:59275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9V8S7ynBpLeKYztQPYcwAAADk"]
[Tue Jul 21 08:20:17.584789 2026] [security2:error] [pid 411857:tid 412083] [client 65.21.113.253:43532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V8C7ynBpLeKYztQPYBAAAAF4"]
[Tue Jul 21 08:20:17.803060 2026] [security2:error] [pid 419508:tid 419761] [client 20.220.225.223:43446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/ms-new.php"] [unique_id "al9V8VcagwCeNbomjVv9swAAAgk"]
[Tue Jul 21 08:20:18.087567 2026] [security2:error] [pid 411857:tid 412063] [client 20.220.225.223:12589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9V8i7ynBpLeKYztQPYfQAAAEo"]
[Tue Jul 21 08:20:18.248424 2026] [security2:error] [pid 419508:tid 419751] [client 117.213.202.34:55398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V8lcagwCeNbomjVv9vAAAAf8"]
[Tue Jul 21 08:20:18.248595 2026] [security2:error] [pid 419508:tid 419751] [client 117.213.202.34:55398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V8lcagwCeNbomjVv9vAAAAf8"]
[Tue Jul 21 08:20:18.752988 2026] [security2:error] [pid 419508:tid 419659] [client 87.116.180.198:13969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V8lcagwCeNbomjVv9vwAAAaQ"]
[Tue Jul 21 08:20:18.756429 2026] [security2:error] [pid 419508:tid 419659] [client 87.116.180.198:13969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V8lcagwCeNbomjVv9vwAAAaQ"]
[Tue Jul 21 08:20:18.870058 2026] [security2:error] [pid 411857:tid 419450] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/configuration.php-backup"] [unique_id "al9V8i7ynBpLeKYztQPYjwAAaYQ"]
[Tue Jul 21 08:20:18.870161 2026] [security2:error] [pid 411857:tid 411912] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/configuration.php.copy"] [unique_id "al9V8i7ynBpLeKYztQPYjgAAaTU"]
[Tue Jul 21 08:20:18.870574 2026] [security2:error] [pid 411857:tid 419450] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/configuration.php.bkp"] [unique_id "al9V8i7ynBpLeKYztQPYkAAAaYQ"]
[Tue Jul 21 08:20:18.870823 2026] [security2:error] [pid 411857:tid 419451] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/configuration.php.1"] [unique_id "al9V8i7ynBpLeKYztQPYkQAAaYU"]
[Tue Jul 21 08:20:18.931289 2026] [security2:error] [pid 411857:tid 419454] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/settings.php.orig"] [unique_id "al9V8i7ynBpLeKYztQPYlAAAC4g"]
[Tue Jul 21 08:20:18.931326 2026] [security2:error] [pid 411857:tid 411943] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/settings.php.bak"] [unique_id "al9V8i7ynBpLeKYztQPYkwAAC1Q"]
[Tue Jul 21 08:20:18.931353 2026] [security2:error] [pid 411857:tid 411934] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/settings.php~"] [unique_id "al9V8i7ynBpLeKYztQPYlQAAC0s"]
[Tue Jul 21 08:20:18.931509 2026] [security2:error] [pid 411857:tid 411929] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/settings.php.old"] [unique_id "al9V8i7ynBpLeKYztQPYlgAAC0Y"]
[Tue Jul 21 08:20:18.933223 2026] [security2:error] [pid 411857:tid 411947] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9V8i7ynBpLeKYztQPYmAAAFVg"]
[Tue Jul 21 08:20:19.073260 2026] [security2:error] [pid 411857:tid 411941] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/settings.php.swp"] [unique_id "al9V8y7ynBpLeKYztQPYnAAATlI"]
[Tue Jul 21 08:20:19.073311 2026] [security2:error] [pid 411857:tid 411921] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/settings.php.save"] [unique_id "al9V8y7ynBpLeKYztQPYngAATj4"]
[Tue Jul 21 08:20:19.073353 2026] [security2:error] [pid 411857:tid 411878] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/settings.php.backup"] [unique_id "al9V8y7ynBpLeKYztQPYnQAAThM"]
[Tue Jul 21 08:20:19.073411 2026] [security2:error] [pid 411857:tid 411933] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/settings.php.bkp"] [unique_id "al9V8y7ynBpLeKYztQPYogAATko"]
[Tue Jul 21 08:20:19.073446 2026] [security2:error] [pid 411857:tid 419468] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/settings.php.copy"] [unique_id "al9V8y7ynBpLeKYztQPYmwAATpY"]
[Tue Jul 21 08:20:19.073485 2026] [security2:error] [pid 411857:tid 411902] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/settings.php-backup"] [unique_id "al9V8y7ynBpLeKYztQPYoQAATis"]
[Tue Jul 21 08:20:19.073528 2026] [security2:error] [pid 411857:tid 411887] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/settings.php.tmp"] [unique_id "al9V8y7ynBpLeKYztQPYnwAAThw"]
[Tue Jul 21 08:20:19.073698 2026] [security2:error] [pid 411857:tid 411941] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/settings.php.1"] [unique_id "al9V8y7ynBpLeKYztQPYowAATlI"]
[Tue Jul 21 08:20:19.073851 2026] [security2:error] [pid 411857:tid 411876] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/adminer.php"] [unique_id "al9V8y7ynBpLeKYztQPYpQAAThE"]
[Tue Jul 21 08:20:19.074222 2026] [security2:error] [pid 411857:tid 411941] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/dup-installer/main.installer.php"] [unique_id "al9V8y7ynBpLeKYztQPYqwAATlI"]
[Tue Jul 21 08:20:19.074560 2026] [security2:error] [pid 411857:tid 411936] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/database.php.bak"] [unique_id "al9V8y7ynBpLeKYztQPYsQAATk0"]
[Tue Jul 21 08:20:19.074564 2026] [security2:error] [pid 411857:tid 411941] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/database.php~"] [unique_id "al9V8y7ynBpLeKYztQPYtAAATlI"]
[Tue Jul 21 08:20:19.074714 2026] [security2:error] [pid 411857:tid 411941] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.bak"] [unique_id "al9V8y7ynBpLeKYztQPYtQAATlI"]
[Tue Jul 21 08:20:19.074749 2026] [security2:error] [pid 411857:tid 411936] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.old"] [unique_id "al9V8y7ynBpLeKYztQPYtgAATk0"]
[Tue Jul 21 08:20:19.074922 2026] [security2:error] [pid 411857:tid 411941] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "atom-growth.com"] [uri "/wp-config.php.swp"] [unique_id "al9V8y7ynBpLeKYztQPYtwAATlI"]
[Tue Jul 21 08:20:19.075363 2026] [security2:error] [pid 411857:tid 411941] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.php.bak"] [unique_id "al9V8y7ynBpLeKYztQPYuQAATlI"]
[Tue Jul 21 08:20:19.075675 2026] [security2:error] [pid 411857:tid 411967] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env.swp"] [unique_id "al9V8y7ynBpLeKYztQPYsgAATms"]
[Tue Jul 21 08:20:19.075685 2026] [security2:error] [pid 411857:tid 411876] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env.backup"] [unique_id "al9V8y7ynBpLeKYztQPYsAAAThE"]
[Tue Jul 21 08:20:19.075723 2026] [security2:error] [pid 411857:tid 411941] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.php.old"] [unique_id "al9V8y7ynBpLeKYztQPYugAATlI"]
[Tue Jul 21 08:20:19.075722 2026] [security2:error] [pid 411857:tid 411962] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env.orig"] [unique_id "al9V8y7ynBpLeKYztQPYswAATmY"]
[Tue Jul 21 08:20:19.075855 2026] [security2:error] [pid 411857:tid 411863] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env.local.bak"] [unique_id "al9V8y7ynBpLeKYztQPYrgAATgQ"]
[Tue Jul 21 08:20:19.075946 2026] [security2:error] [pid 411857:tid 411902] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.env.old"] [unique_id "al9V8y7ynBpLeKYztQPYrwAATis"]
[Tue Jul 21 08:20:19.092400 2026] [authz_core:error] [pid 411857:tid 412066] [client 103.215.74.26:0] AH01630: client denied by server configuration: /home4/chefdo14/atom-growth.com/error_log
[Tue Jul 21 08:20:19.208363 2026] [http2:info] [pid 411857:tid 412067] [client 103.215.74.26:40804] AH10178: h2_stream(411857-1604-957,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:20:19.209566 2026] [security2:error] [pid 411857:tid 419453] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php"] [unique_id "al9V8y7ynBpLeKYztQPYygAAToc"]
[Tue Jul 21 08:20:19.211204 2026] [security2:error] [pid 411857:tid 411924] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/database.yml.bak"] [unique_id "al9V8y7ynBpLeKYztQPYyAAATkE"]
[Tue Jul 21 08:20:19.211314 2026] [security2:error] [pid 411857:tid 411983] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/appsettings.json.bak"] [unique_id "al9V8y7ynBpLeKYztQPYyQAATns"]
[Tue Jul 21 08:20:19.213549 2026] [security2:error] [pid 411857:tid 411930] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/database.php.old"] [unique_id "al9V8y7ynBpLeKYztQPYzAAATkc"]
[Tue Jul 21 08:20:19.213801 2026] [security2:error] [pid 411857:tid 411909] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/wp-content/w3tc-config/master.php"] [unique_id "al9V8y7ynBpLeKYztQPY0AAATjI"]
[Tue Jul 21 08:20:19.213838 2026] [security2:error] [pid 411857:tid 411957] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/wp-links-opml.php"] [unique_id "al9V8y7ynBpLeKYztQPY0wAATmE"]
[Tue Jul 21 08:20:19.213864 2026] [security2:error] [pid 411857:tid 411901] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/wp-content/plugins/w3-total-cache/pub/opt/detect-post-info.php"] [unique_id "al9V8y7ynBpLeKYztQPY0QAATio"]
[Tue Jul 21 08:20:19.214141 2026] [security2:error] [pid 411857:tid 411930] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/database.php.orig"] [unique_id "al9V8y7ynBpLeKYztQPY2wAATkc"]
[Tue Jul 21 08:20:19.214339 2026] [security2:error] [pid 419508:tid 419745] [client 185.198.240.6:56327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dener.design"] [uri "/wp-login.php"] [unique_id "al9V81cagwCeNbomjVv9zgAAAfk"]
[Tue Jul 21 08:20:19.215001 2026] [security2:error] [pid 411857:tid 411868] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/settings.py.bak"] [unique_id "al9V8y7ynBpLeKYztQPYzwAATgk"]
[Tue Jul 21 08:20:19.215016 2026] [security2:error] [pid 411857:tid 411972] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/.htaccess.bak"] [unique_id "al9V8y7ynBpLeKYztQPY1gAATnA"]
[Tue Jul 21 08:20:19.237632 2026] [security2:error] [pid 419508:tid 419758] [client 14.245.224.124:54182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9V81cagwCeNbomjVv92gAAAgY"]
[Tue Jul 21 08:20:19.237728 2026] [security2:error] [pid 419508:tid 419758] [client 14.245.224.124:54182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9V81cagwCeNbomjVv92gAAAgY"]
[Tue Jul 21 08:20:19.409221 2026] [security2:error] [pid 411857:tid 412001] [client 65.21.113.253:43532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V8i7ynBpLeKYztQPYkgAAAAw"]
[Tue Jul 21 08:20:19.443422 2026] [security2:error] [pid 419508:tid 419722] [client 74.249.245.134:49231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/2.php"] [unique_id "al9V81cagwCeNbomjVv92wAAAeM"]
[Tue Jul 21 08:20:19.696652 2026] [security2:error] [pid 411857:tid 411931] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9V8y7ynBpLeKYztQPY5gAAYUg"]
[Tue Jul 21 08:20:19.696784 2026] [security2:error] [pid 411857:tid 412086] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9V8y7ynBpLeKYztQPY5gAAYUg"]
[Tue Jul 21 08:20:19.744744 2026] [core:error] [pid 419508:tid 419588] [remote 23.180.120.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:20:19.744768 2026] [core:error] [pid 419508:tid 419588] [remote 23.180.120.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:20:19.785660 2026] [security2:error] [pid 419508:tid 419756] [client 20.226.60.151:59278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/nano.php"] [unique_id "al9V81cagwCeNbomjVv93wAAAgQ"]
[Tue Jul 21 08:20:19.837336 2026] [security2:error] [pid 419508:tid 419688] [client 103.106.20.201:55284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V81cagwCeNbomjVv94QAAAcE"]
[Tue Jul 21 08:20:19.837461 2026] [security2:error] [pid 419508:tid 419688] [client 103.106.20.201:55284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V81cagwCeNbomjVv94QAAAcE"]
[Tue Jul 21 08:20:19.921870 2026] [security2:error] [pid 419508:tid 419693] [client 150.129.202.39:65390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V81cagwCeNbomjVv94gAAAcY"]
[Tue Jul 21 08:20:19.921991 2026] [security2:error] [pid 419508:tid 419693] [client 150.129.202.39:65390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V81cagwCeNbomjVv94gAAAcY"]
[Tue Jul 21 08:20:20.109707 2026] [security2:error] [pid 418108:tid 418312] [client 20.226.60.151:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/moon.php"] [unique_id "al9V9A0cxofL2J1zwYrAzAAAAVI"]
[Tue Jul 21 08:20:20.199290 2026] [security2:error] [pid 418108:tid 418284] [client 117.210.135.0:57052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V9A0cxofL2J1zwYrAzQAAATY"]
[Tue Jul 21 08:20:20.199909 2026] [security2:error] [pid 418108:tid 418284] [client 117.210.135.0:57052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V9A0cxofL2J1zwYrAzQAAATY"]
[Tue Jul 21 08:20:20.392173 2026] [security2:error] [pid 419508:tid 419682] [client 20.220.225.223:31181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/dragonshell.php"] [unique_id "al9V9FcagwCeNbomjVv96AAAAbs"]
[Tue Jul 21 08:20:20.486588 2026] [security2:error] [pid 411857:tid 412064] [client 20.226.60.151:59279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/edorxrr.php"] [unique_id "al9V9C7ynBpLeKYztQPY9QAAAEs"]
[Tue Jul 21 08:20:20.511891 2026] [security2:error] [pid 411857:tid 411859] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/database.php.tmp"] [unique_id "al9V9C7ynBpLeKYztQPY-AAAEAA"]
[Tue Jul 21 08:20:20.512085 2026] [security2:error] [pid 411857:tid 411939] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/database.php.save"] [unique_id "al9V9C7ynBpLeKYztQPY-QAAEFA"]
[Tue Jul 21 08:20:20.512114 2026] [security2:error] [pid 411857:tid 411892] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/database.php.swp"] [unique_id "al9V9C7ynBpLeKYztQPY-gAAECE"]
[Tue Jul 21 08:20:20.518089 2026] [security2:error] [pid 411857:tid 411861] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/database.php.backup"] [unique_id "al9V9C7ynBpLeKYztQPY-wAADwI"]
[Tue Jul 21 08:20:20.540091 2026] [security2:error] [pid 411857:tid 412066] [client 65.21.113.253:43532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V9C7ynBpLeKYztQPY7QAAAE0"]
[Tue Jul 21 08:20:20.728078 2026] [security2:error] [pid 411857:tid 411976] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/database.php.copy"] [unique_id "al9V9C7ynBpLeKYztQPY_wAAVnQ"]
[Tue Jul 21 08:20:20.728278 2026] [security2:error] [pid 411857:tid 411948] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/database.php.bkp"] [unique_id "al9V9C7ynBpLeKYztQPZAAAAVlk"]
[Tue Jul 21 08:20:20.731075 2026] [security2:error] [pid 411857:tid 411919] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/database.php.1"] [unique_id "al9V9C7ynBpLeKYztQPZAQAAWDw"]
[Tue Jul 21 08:20:20.731124 2026] [security2:error] [pid 411857:tid 411880] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9V9C7ynBpLeKYztQPZAgAAWBU"]
[Tue Jul 21 08:20:20.731269 2026] [security2:error] [pid 411857:tid 411973] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/database.php-backup"] [unique_id "al9V9C7ynBpLeKYztQPZAwAAWHE"]
[Tue Jul 21 08:20:20.803357 2026] [security2:error] [pid 419508:tid 419735] [client 20.220.225.223:43454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/track.php"] [unique_id "al9V9FcagwCeNbomjVv97wAAAfA"]
[Tue Jul 21 08:20:20.870256 2026] [security2:error] [pid 411857:tid 411912] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.inc.php.orig"] [unique_id "al9V9C7ynBpLeKYztQPZDQAAKzU"]
[Tue Jul 21 08:20:20.870263 2026] [security2:error] [pid 411857:tid 411977] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.inc.php.bak"] [unique_id "al9V9C7ynBpLeKYztQPZBgAAK3U"]
[Tue Jul 21 08:20:20.870304 2026] [security2:error] [pid 411857:tid 411943] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "atom-growth.com"] [uri "/wp-content/plugins/w3-total-cache/readme.txt"] [unique_id "al9V9C7ynBpLeKYztQPZEQAAK1Q"]
[Tue Jul 21 08:20:20.870334 2026] [security2:error] [pid 411857:tid 419459] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.inc.php.backup"] [unique_id "al9V9C7ynBpLeKYztQPZBwAAK40"]
[Tue Jul 21 08:20:20.870348 2026] [security2:error] [pid 411857:tid 411934] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "atom-growth.com"] [uri "/wp-content/plugins/wp-responsive-images/readme.txt"] [unique_id "al9V9C7ynBpLeKYztQPZEgAAK0s"]
[Tue Jul 21 08:20:20.870354 2026] [security2:error] [pid 411857:tid 411915] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.inc.php-backup"] [unique_id "al9V9C7ynBpLeKYztQPZCQAAKzg"]
[Tue Jul 21 08:20:20.870354 2026] [security2:error] [pid 411857:tid 411873] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.inc.php.copy"] [unique_id "al9V9C7ynBpLeKYztQPZCAAAKw4"]
[Tue Jul 21 08:20:20.870368 2026] [security2:error] [pid 411857:tid 411947] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "atom-growth.com"] [uri "/wp-content/plugins/perfmatters/readme.txt"] [unique_id "al9V9C7ynBpLeKYztQPZFAAAK1g"]
[Tue Jul 21 08:20:20.870399 2026] [security2:error] [pid 411857:tid 411906] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.inc.php.save"] [unique_id "al9V9C7ynBpLeKYztQPZDAAAKy8"]
[Tue Jul 21 08:20:20.870429 2026] [security2:error] [pid 411857:tid 411882] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.inc.php.old"] [unique_id "al9V9C7ynBpLeKYztQPZBQAAKxc"]
[Tue Jul 21 08:20:20.870444 2026] [security2:error] [pid 411857:tid 419450] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.inc.php~"] [unique_id "al9V9C7ynBpLeKYztQPZDgAAK4Q"]
[Tue Jul 21 08:20:20.870481 2026] [security2:error] [pid 411857:tid 411890] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.inc.php.tmp"] [unique_id "al9V9C7ynBpLeKYztQPZCwAAKx8"]
[Tue Jul 21 08:20:20.870496 2026] [security2:error] [pid 411857:tid 419462] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.inc.php.swp"] [unique_id "al9V9C7ynBpLeKYztQPZCgAAK5A"]
[Tue Jul 21 08:20:20.878258 2026] [security2:error] [pid 411857:tid 419469] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/wp-content/plugins/wp-automatic/inc/csv.php"] [unique_id "al9V9C7ynBpLeKYztQPZFQAAK5c"]
[Tue Jul 21 08:20:20.964241 2026] [http2:info] [pid 411857:tid 412071] [client 103.215.74.26:40804] AH10178: h2_stream(411857-1604-1051,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:20:20.965404 2026] [security2:error] [pid 411857:tid 411933] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php"] [unique_id "al9V9C7ynBpLeKYztQPZGAAAUko"]
[Tue Jul 21 08:20:21.007115 2026] [security2:error] [pid 411857:tid 411971] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.inc.php.1"] [unique_id "al9V9S7ynBpLeKYztQPZGwAANW8"]
[Tue Jul 21 08:20:21.007166 2026] [security2:error] [pid 411857:tid 411980] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config.inc.php.bkp"] [unique_id "al9V9S7ynBpLeKYztQPZGgAANXg"]
[Tue Jul 21 08:20:21.215509 2026] [security2:error] [pid 419508:tid 419724] [client 74.7.230.55:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9V9VcagwCeNbomjVv9-QAB5Xs"]
[Tue Jul 21 08:20:21.319714 2026] [security2:error] [pid 419508:tid 419734] [client 111.93.58.162:10888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9V9VcagwCeNbomjVv9_QAAAe8"]
[Tue Jul 21 08:20:21.320017 2026] [security2:error] [pid 419508:tid 419734] [client 111.93.58.162:10888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9V9VcagwCeNbomjVv9_QAAAe8"]
[Tue Jul 21 08:20:21.396376 2026] [security2:error] [pid 419508:tid 419679] [client 20.226.60.151:64119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-info.php"] [unique_id "al9V9VcagwCeNbomjVv9_wAAAbg"]
[Tue Jul 21 08:20:21.508991 2026] [security2:error] [pid 419508:tid 419633] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V9VcagwCeNbomjVv-AAABqXw"]
[Tue Jul 21 08:20:21.509151 2026] [security2:error] [pid 419508:tid 419664] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V9VcagwCeNbomjVv-AAABqXw"]
[Tue Jul 21 08:20:21.654258 2026] [security2:error] [pid 419508:tid 419678] [client 20.220.225.223:31184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wp-mt.php"] [unique_id "al9V9VcagwCeNbomjVv-AgAAAbc"]
[Tue Jul 21 08:20:21.982221 2026] [security2:error] [pid 418108:tid 418293] [client 61.1.167.83:64029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V9Q0cxofL2J1zwYrA0QAAAT8"]
[Tue Jul 21 08:20:21.982331 2026] [security2:error] [pid 418108:tid 418293] [client 61.1.167.83:64029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V9Q0cxofL2J1zwYrA0QAAAT8"]
[Tue Jul 21 08:20:22.173875 2026] [security2:error] [pid 411857:tid 412014] [client 120.56.162.40:62464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V9i7ynBpLeKYztQPZOwAAABk"]
[Tue Jul 21 08:20:22.173990 2026] [security2:error] [pid 411857:tid 412014] [client 120.56.162.40:62464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V9i7ynBpLeKYztQPZOwAAABk"]
[Tue Jul 21 08:20:22.212889 2026] [security2:error] [pid 411857:tid 411869] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9V9i7ynBpLeKYztQPZPQAAUgo"]
[Tue Jul 21 08:20:22.610556 2026] [security2:error] [pid 419508:tid 419655] [client 20.220.225.223:38718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/ww.php"] [unique_id "al9V9lcagwCeNbomjVv-CwAAAaA"]
[Tue Jul 21 08:20:23.141800 2026] [security2:error] [pid 419508:tid 419636] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9V91cagwCeNbomjVv-EAAB2H8"]
[Tue Jul 21 08:20:23.141975 2026] [security2:error] [pid 419508:tid 419711] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9V91cagwCeNbomjVv-EAAB2H8"]
[Tue Jul 21 08:20:23.308144 2026] [security2:error] [pid 411857:tid 411995] [client 65.21.113.253:43532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V9i7ynBpLeKYztQPZTQAAAAY"]
[Tue Jul 21 08:20:23.340318 2026] [security2:error] [pid 411857:tid 412063] [client 198.54.129.60:45776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9V9y7ynBpLeKYztQPZXQAAAEo"]
[Tue Jul 21 08:20:23.340519 2026] [security2:error] [pid 411857:tid 412063] [client 198.54.129.60:45776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9V9y7ynBpLeKYztQPZXQAAAEo"]
[Tue Jul 21 08:20:23.368076 2026] [security2:error] [pid 411857:tid 412000] [client 20.226.60.151:59297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/miru1.php"] [unique_id "al9V9y7ynBpLeKYztQPZXgAAAAs"]
[Tue Jul 21 08:20:23.439554 2026] [security2:error] [pid 419508:tid 419754] [client 74.249.245.134:59980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/asd.php"] [unique_id "al9V91cagwCeNbomjVv-FAAAAgI"]
[Tue Jul 21 08:20:23.494145 2026] [security2:error] [pid 419508:tid 419658] [client 47.128.24.119:33600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "issimastore.com"] [uri "/robots.txt"] [unique_id "al9V91cagwCeNbomjVv-FQAAAaM"]
[Tue Jul 21 08:20:23.773698 2026] [security2:error] [pid 411857:tid 411878] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9V9y7ynBpLeKYztQPZZAAAKBM"]
[Tue Jul 21 08:20:23.868589 2026] [security2:error] [pid 418108:tid 418208] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9V9w0cxofL2J1zwYrA2AABHWE"]
[Tue Jul 21 08:20:23.868771 2026] [security2:error] [pid 418108:tid 418259] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9V9w0cxofL2J1zwYrA2AABHWE"]
[Tue Jul 21 08:20:24.010329 2026] [security2:error] [pid 418108:tid 418255] [client 20.226.60.151:60580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/xy.php"] [unique_id "al9V-A0cxofL2J1zwYrA2gAAARk"]
[Tue Jul 21 08:20:24.131759 2026] [security2:error] [pid 411857:tid 419446] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/assets/.env"] [unique_id "al9V-C7ynBpLeKYztQPZcwAACYE"]
[Tue Jul 21 08:20:24.134776 2026] [security2:error] [pid 411857:tid 411879] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/assets-backup.sql"] [unique_id "al9V-C7ynBpLeKYztQPZdQAACRQ"]
[Tue Jul 21 08:20:24.242301 2026] [security2:error] [pid 419508:tid 419748] [client 20.226.60.151:64042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/sump1.php"] [unique_id "al9V-FcagwCeNbomjVv-KAAAAfw"]
[Tue Jul 21 08:20:24.334150 2026] [security2:error] [pid 419508:tid 419759] [client 154.208.47.43:3794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9V-FcagwCeNbomjVv-KQAAAgc"]
[Tue Jul 21 08:20:24.334438 2026] [security2:error] [pid 419508:tid 419759] [client 154.208.47.43:3794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9V-FcagwCeNbomjVv-KQAAAgc"]
[Tue Jul 21 08:20:24.966050 2026] [security2:error] [pid 419508:tid 419724] [client 38.100.221.102:18307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V-FcagwCeNbomjVv-MAAAAeU"]
[Tue Jul 21 08:20:24.966188 2026] [security2:error] [pid 419508:tid 419724] [client 38.100.221.102:18307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V-FcagwCeNbomjVv-MAAAAeU"]
[Tue Jul 21 08:20:25.123692 2026] [security2:error] [pid 411857:tid 412092] [client 115.134.11.136:49636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V-S7ynBpLeKYztQPZjgAAAGc"]
[Tue Jul 21 08:20:25.124122 2026] [security2:error] [pid 411857:tid 412092] [client 115.134.11.136:49636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V-S7ynBpLeKYztQPZjgAAAGc"]
[Tue Jul 21 08:20:25.231743 2026] [security2:error] [pid 411857:tid 412102] [client 8.229.228.188:54236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elitegeo.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9V-S7ynBpLeKYztQPZkQAAAHE"]
[Tue Jul 21 08:20:25.238159 2026] [security2:error] [pid 411857:tid 411896] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9V-S7ynBpLeKYztQPZkwAAcCU"]
[Tue Jul 21 08:20:25.422508 2026] [security2:error] [pid 419508:tid 419660] [client 187.125.243.197:62906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9V-VcagwCeNbomjVv-MgAAAaU"]
[Tue Jul 21 08:20:25.422622 2026] [security2:error] [pid 419508:tid 419660] [client 187.125.243.197:62906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9V-VcagwCeNbomjVv-MgAAAaU"]
[Tue Jul 21 08:20:25.513638 2026] [security2:error] [pid 418108:tid 418334] [client 223.181.60.88:13632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9V-Q0cxofL2J1zwYrA3gAAAWg"]
[Tue Jul 21 08:20:25.514425 2026] [security2:error] [pid 418108:tid 418334] [client 223.181.60.88:13632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9V-Q0cxofL2J1zwYrA3gAAAWg"]
[Tue Jul 21 08:20:25.596599 2026] [autoindex:error] [pid 419508:tid 419712] [client 35.233.163.26:52722] AH01276: Cannot serve directory /home1/leon6484/corretor.lumevisual.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:20:25.671757 2026] [security2:error] [pid 411857:tid 411938] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php"] [unique_id "al9V-S7ynBpLeKYztQPZmwAATU8"]
[Tue Jul 21 08:20:25.799420 2026] [security2:error] [pid 411857:tid 412015] [client 65.21.113.253:43532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V-S7ynBpLeKYztQPZlAAAABo"]
[Tue Jul 21 08:20:25.808040 2026] [security2:error] [pid 411857:tid 412016] [client 8.229.228.188:52983] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elitegeo.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9V-S7ynBpLeKYztQPZoAAAABs"]
[Tue Jul 21 08:20:26.271340 2026] [security2:error] [pid 411857:tid 412085] [client 20.220.225.223:38709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/cron.php"] [unique_id "al9V-i7ynBpLeKYztQPZsgAAAGA"]
[Tue Jul 21 08:20:26.388907 2026] [security2:error] [pid 411857:tid 412090] [client 8.229.228.188:49328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elitegeo.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9V-i7ynBpLeKYztQPZtAAAAGU"]
[Tue Jul 21 08:20:26.393094 2026] [security2:error] [pid 411857:tid 412102] [client 20.226.60.151:59302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/2000.php"] [unique_id "al9V-i7ynBpLeKYztQPZtQAAAHE"]
[Tue Jul 21 08:20:26.436746 2026] [security2:error] [pid 411857:tid 412053] [client 20.220.225.223:46818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/2352356666.php"] [unique_id "al9V-i7ynBpLeKYztQPZtwAAAEA"]
[Tue Jul 21 08:20:26.750198 2026] [security2:error] [pid 411857:tid 411882] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9V-i7ynBpLeKYztQPZvgAADhc"]
[Tue Jul 21 08:20:26.762209 2026] [security2:error] [pid 411857:tid 412004] [client 20.226.60.151:64104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/file5.php"] [unique_id "al9V-i7ynBpLeKYztQPZwAAAAA8"]
[Tue Jul 21 08:20:27.054640 2026] [proxy:error] [pid 411857:tid 419458] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:20:27.054681 2026] [proxy_http:error] [pid 411857:tid 419458] [remote 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:20:27.055351 2026] [proxy:error] [pid 411857:tid 419458] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:20:27.055378 2026] [proxy_http:error] [pid 411857:tid 419458] [remote 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:20:27.083851 2026] [security2:error] [pid 411857:tid 412025] [client 152.59.34.51:57299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9V-y7ynBpLeKYztQPZywAAACQ"]
[Tue Jul 21 08:20:27.083988 2026] [security2:error] [pid 411857:tid 412025] [client 152.59.34.51:57299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9V-y7ynBpLeKYztQPZywAAACQ"]
[Tue Jul 21 08:20:27.086234 2026] [security2:error] [pid 411857:tid 412035] [client 86.106.84.166:37306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9V-y7ynBpLeKYztQPZzAAAAC4"]
[Tue Jul 21 08:20:27.086315 2026] [security2:error] [pid 411857:tid 412035] [client 86.106.84.166:37306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9V-y7ynBpLeKYztQPZzAAAAC4"]
[Tue Jul 21 08:20:27.128000 2026] [security2:error] [pid 411857:tid 412085] [client 8.229.228.188:56404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elitegeo.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9V-y7ynBpLeKYztQPZzgAAAGA"]
[Tue Jul 21 08:20:27.150159 2026] [security2:error] [pid 411857:tid 419454] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php"] [unique_id "al9V-y7ynBpLeKYztQPZzwAAUog"]
[Tue Jul 21 08:20:27.325370 2026] [security2:error] [pid 411857:tid 411933] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V-y7ynBpLeKYztQPZ1wAAI0o"]
[Tue Jul 21 08:20:27.325677 2026] [security2:error] [pid 411857:tid 412024] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V-y7ynBpLeKYztQPZ1wAAI0o"]
[Tue Jul 21 08:20:27.354003 2026] [security2:error] [pid 411857:tid 411971] [remote 208.109.9.173:55080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thiagomartins.com"] [uri "/wp-login.php"] [unique_id "al9V-y7ynBpLeKYztQPZ2QAACm8"]
[Tue Jul 21 08:20:27.360583 2026] [security2:error] [pid 411857:tid 419448] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9V-y7ynBpLeKYztQPZ2wAAMoM"]
[Tue Jul 21 08:20:27.589867 2026] [security2:error] [pid 411857:tid 411996] [client 65.21.113.253:43532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V-y7ynBpLeKYztQPZzQAAAAc"]
[Tue Jul 21 08:20:27.867559 2026] [security2:error] [pid 419508:tid 419761] [client 35.233.163.26:52722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "corretor.lumevisual.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9V-1cagwCeNbomjVv-RgAAAgk"]
[Tue Jul 21 08:20:27.966330 2026] [security2:error] [pid 419508:tid 419727] [client 20.226.60.151:64109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/0xD.php"] [unique_id "al9V-1cagwCeNbomjVv-SQAAAeg"]
[Tue Jul 21 08:20:27.996136 2026] [security2:error] [pid 419508:tid 419762] [client 8.229.228.188:55646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elitegeo.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9V-1cagwCeNbomjVv-SwAAAgo"]
[Tue Jul 21 08:20:28.203543 2026] [security2:error] [pid 419508:tid 419745] [client 103.151.46.103:59775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9V_FcagwCeNbomjVv-TwAAAfk"]
[Tue Jul 21 08:20:28.204130 2026] [security2:error] [pid 419508:tid 419745] [client 103.151.46.103:59775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9V_FcagwCeNbomjVv-TwAAAfk"]
[Tue Jul 21 08:20:28.221391 2026] [security2:error] [pid 411857:tid 412066] [client 20.220.225.223:31122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/xxx.php"] [unique_id "al9V_C7ynBpLeKYztQPZ7AAAAE0"]
[Tue Jul 21 08:20:28.276822 2026] [security2:error] [pid 411857:tid 411956] [remote 159.223.41.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V_C7ynBpLeKYztQPZ7QAAAWA"]
[Tue Jul 21 08:20:28.434059 2026] [security2:error] [pid 419508:tid 419642] [client 35.233.163.26:58991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "corretor.lumevisual.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9V_FcagwCeNbomjVv-UwAAAZM"]
[Tue Jul 21 08:20:28.586774 2026] [proxy:error] [pid 411857:tid 411932] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:20:28.586830 2026] [proxy_http:error] [pid 411857:tid 411932] [remote 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:20:28.587232 2026] [proxy:error] [pid 411857:tid 411932] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:20:28.587252 2026] [proxy_http:error] [pid 411857:tid 411932] [remote 159.223.41.76:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:20:28.746588 2026] [security2:error] [pid 419508:tid 419607] [remote 49.13.1.223:40046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fgengenharia.eng.br"] [uri "/wp-login.php"] [unique_id "al9V_FcagwCeNbomjVv-YwABrWI"]
[Tue Jul 21 08:20:28.777369 2026] [security2:error] [pid 419508:tid 419675] [client 8.229.228.188:55688] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elitegeo.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9V_FcagwCeNbomjVv-ZAAAAbQ"]
[Tue Jul 21 08:20:28.833835 2026] [security2:error] [pid 419508:tid 419654] [client 117.213.202.34:56265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V_FcagwCeNbomjVv-ZQAAAZ8"]
[Tue Jul 21 08:20:28.833986 2026] [security2:error] [pid 419508:tid 419654] [client 117.213.202.34:56265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V_FcagwCeNbomjVv-ZQAAAZ8"]
[Tue Jul 21 08:20:28.888519 2026] [security2:error] [pid 411857:tid 411863] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9V_C7ynBpLeKYztQPZ-AAAQAQ"]
[Tue Jul 21 08:20:28.897013 2026] [security2:error] [pid 411857:tid 412090] [client 20.220.225.223:12601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/dp.php"] [unique_id "al9V_C7ynBpLeKYztQPZ-QAAAGU"]
[Tue Jul 21 08:20:28.917524 2026] [security2:error] [pid 411857:tid 411999] [client 35.233.163.26:58406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "corretor.lumevisual.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9V_C7ynBpLeKYztQPZ-gAAAAo"]
[Tue Jul 21 08:20:28.927300 2026] [security2:error] [pid 418108:tid 418246] [client 20.220.225.223:55231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/pn.php"] [unique_id "al9V_A0cxofL2J1zwYrA4wAAARA"]
[Tue Jul 21 08:20:28.938444 2026] [security2:error] [pid 411857:tid 411941] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php"] [unique_id "al9V_C7ynBpLeKYztQPZ_AAAcFI"]
[Tue Jul 21 08:20:29.019285 2026] [security2:error] [pid 411857:tid 412050] [client 20.226.60.151:64006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/fnstall.php"] [unique_id "al9V_S7ynBpLeKYztQPZ_gAAAD0"]
[Tue Jul 21 08:20:29.117477 2026] [security2:error] [pid 411857:tid 419456] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9V_S7ynBpLeKYztQPaAQAAD4o"]
[Tue Jul 21 08:20:29.195385 2026] [security2:error] [pid 411857:tid 419467] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9V_S7ynBpLeKYztQPaAwAAEJU"]
[Tue Jul 21 08:20:29.369329 2026] [security2:error] [pid 411857:tid 412092] [client 87.116.180.198:27383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V_S7ynBpLeKYztQPaBQAAAGc"]
[Tue Jul 21 08:20:29.369439 2026] [security2:error] [pid 411857:tid 412092] [client 87.116.180.198:27383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V_S7ynBpLeKYztQPaBQAAAGc"]
[Tue Jul 21 08:20:29.479196 2026] [security2:error] [pid 411857:tid 412094] [client 8.229.228.188:55695] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elitegeo.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9V_S7ynBpLeKYztQPaCgAAAGk"]
[Tue Jul 21 08:20:29.497596 2026] [security2:error] [pid 411857:tid 419453] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9V_S7ynBpLeKYztQPaCwAAa4c"]
[Tue Jul 21 08:20:29.527750 2026] [security2:error] [pid 419508:tid 419703] [client 35.233.163.26:55988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "corretor.lumevisual.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9V_VcagwCeNbomjVv-bgAAAdA"]
[Tue Jul 21 08:20:29.806592 2026] [security2:error] [pid 411857:tid 411868] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9V_S7ynBpLeKYztQPaEgAAAQk"]
[Tue Jul 21 08:20:29.842435 2026] [proxy:error] [pid 419508:tid 419609] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:20:29.842477 2026] [proxy_http:error] [pid 419508:tid 419609] [remote 185.93.89.147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:20:29.843244 2026] [proxy:error] [pid 419508:tid 419609] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:20:29.843268 2026] [proxy_http:error] [pid 419508:tid 419609] [remote 185.93.89.147:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:20:29.843340 2026] [security2:error] [pid 411857:tid 411987] [remote 35.221.29.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.29.221.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.wendelleite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V_S7ynBpLeKYztQPaEwAAbX8"]
[Tue Jul 21 08:20:29.848958 2026] [security2:error] [pid 419508:tid 419695] [client 14.245.224.124:54655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9V_VcagwCeNbomjVv-eAAAAcg"]
[Tue Jul 21 08:20:29.849052 2026] [security2:error] [pid 419508:tid 419695] [client 14.245.224.124:54655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9V_VcagwCeNbomjVv-eAAAAcg"]
[Tue Jul 21 08:20:29.886392 2026] [security2:error] [pid 411857:tid 412074] [client 65.21.113.253:43532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V_S7ynBpLeKYztQPaCQAAAFU"]
[Tue Jul 21 08:20:29.997651 2026] [security2:error] [pid 419508:tid 419722] [client 35.233.163.26:60002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "corretor.lumevisual.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9V_VcagwCeNbomjVv-fQAAAeM"]
[Tue Jul 21 08:20:30.024031 2026] [security2:error] [pid 419508:tid 419705] [client 62.102.148.158:45254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9V_lcagwCeNbomjVv-fgAAAdI"]
[Tue Jul 21 08:20:30.024122 2026] [security2:error] [pid 419508:tid 419705] [client 62.102.148.158:45254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9V_lcagwCeNbomjVv-fgAAAdI"]
[Tue Jul 21 08:20:30.072650 2026] [security2:error] [pid 418108:tid 418347] [client 20.226.60.151:60621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/loader.php"] [unique_id "al9V_g0cxofL2J1zwYrA6AAAAXU"]
[Tue Jul 21 08:20:30.080596 2026] [security2:error] [pid 419508:tid 419602] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.wendelleite.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9V_lcagwCeNbomjVv-fwAB1l0"]
[Tue Jul 21 08:20:30.109154 2026] [security2:error] [pid 411857:tid 411886] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9V_i7ynBpLeKYztQPaGAAASRs"]
[Tue Jul 21 08:20:30.167698 2026] [security2:error] [pid 419508:tid 419723] [client 8.229.228.188:50379] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elitegeo.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9V_lcagwCeNbomjVv-gQAAAeQ"]
[Tue Jul 21 08:20:30.334490 2026] [security2:error] [pid 411857:tid 411878] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.wendelleite.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9V_i7ynBpLeKYztQPaGwAAZRM"]
[Tue Jul 21 08:20:30.389401 2026] [security2:error] [pid 419508:tid 419515] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9V_lcagwCeNbomjVv-hAACAgY"]
[Tue Jul 21 08:20:30.389567 2026] [security2:error] [pid 419508:tid 419754] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9V_lcagwCeNbomjVv-hAACAgY"]
[Tue Jul 21 08:20:30.415417 2026] [security2:error] [pid 411857:tid 411921] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9V_i7ynBpLeKYztQPaHAAAcT4"]
[Tue Jul 21 08:20:30.420303 2026] [security2:error] [pid 419508:tid 419640] [client 150.129.202.39:64547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V_lcagwCeNbomjVv-hgAAAZE"]
[Tue Jul 21 08:20:30.420443 2026] [security2:error] [pid 419508:tid 419640] [client 150.129.202.39:64547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V_lcagwCeNbomjVv-hgAAAZE"]
[Tue Jul 21 08:20:30.496952 2026] [security2:error] [pid 411857:tid 411999] [client 35.233.163.26:57769] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "corretor.lumevisual.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9V_i7ynBpLeKYztQPaIAAAAAo"]
[Tue Jul 21 08:20:30.516964 2026] [security2:error] [pid 419508:tid 419749] [client 103.106.20.201:55862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V_lcagwCeNbomjVv-iAAAAf0"]
[Tue Jul 21 08:20:30.517594 2026] [security2:error] [pid 419508:tid 419749] [client 103.106.20.201:55862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V_lcagwCeNbomjVv-iAAAAf0"]
[Tue Jul 21 08:20:30.563811 2026] [security2:error] [pid 419508:tid 419517] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.wendelleite.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9V_lcagwCeNbomjVv-iQABtQg"]
[Tue Jul 21 08:20:30.635465 2026] [security2:error] [pid 411857:tid 411887] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php"] [unique_id "al9V_i7ynBpLeKYztQPaKAAADxw"]
[Tue Jul 21 08:20:30.719809 2026] [security2:error] [pid 411857:tid 411888] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9V_i7ynBpLeKYztQPaLAAAGh0"]
[Tue Jul 21 08:20:30.737473 2026] [security2:error] [pid 411857:tid 411900] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.wendelleite.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9V_i7ynBpLeKYztQPaLQAAZyk"]
[Tue Jul 21 08:20:30.815884 2026] [security2:error] [pid 411857:tid 412026] [client 20.226.60.151:59099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/122.php"] [unique_id "al9V_i7ynBpLeKYztQPaMAAAACU"]
[Tue Jul 21 08:20:30.849728 2026] [security2:error] [pid 411857:tid 419468] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9V_i7ynBpLeKYztQPaMQAAaZY"]
[Tue Jul 21 08:20:30.869109 2026] [security2:error] [pid 419508:tid 419544] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.wendelleite.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9V_lcagwCeNbomjVv-iwABxCM"]
[Tue Jul 21 08:20:30.878277 2026] [security2:error] [pid 411857:tid 412077] [client 65.21.113.253:43532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9V_i7ynBpLeKYztQPaHwAAAFg"]
[Tue Jul 21 08:20:30.886534 2026] [security2:error] [pid 411857:tid 412111] [client 35.233.163.26:64882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "corretor.lumevisual.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9V_i7ynBpLeKYztQPaMwAAAHo"]
[Tue Jul 21 08:20:31.027568 2026] [security2:error] [pid 411857:tid 411913] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9V_y7ynBpLeKYztQPaOQAATzY"]
[Tue Jul 21 08:20:31.031760 2026] [security2:error] [pid 411857:tid 411942] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.wendelleite.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9V_y7ynBpLeKYztQPaOwAAVlM"]
[Tue Jul 21 08:20:31.149282 2026] [security2:error] [pid 419508:tid 419762] [client 45.8.19.143:25399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luanaarruda.com"] [uri "/wp-login.php"] [unique_id "al9V_1cagwCeNbomjVv-jAAAAgo"]
[Tue Jul 21 08:20:31.187557 2026] [security2:error] [pid 411857:tid 411995] [client 74.249.245.134:49951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/default.php"] [unique_id "al9V_y7ynBpLeKYztQPaPQAAAAY"]
[Tue Jul 21 08:20:31.211833 2026] [security2:error] [pid 419508:tid 419731] [client 20.226.60.151:64100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/acp.php"] [unique_id "al9V_1cagwCeNbomjVv-jQAAAew"]
[Tue Jul 21 08:20:31.215676 2026] [security2:error] [pid 419508:tid 419545] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.wendelleite.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9V_1cagwCeNbomjVv-jgAB8SQ"]
[Tue Jul 21 08:20:31.240623 2026] [security2:error] [pid 418108:tid 418281] [client 8.229.228.188:52257] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elitegeo.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9V_w0cxofL2J1zwYrA6wAAATM"]
[Tue Jul 21 08:20:31.323509 2026] [security2:error] [pid 411857:tid 412106] [client 117.210.135.0:57732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V_y7ynBpLeKYztQPaQgAAAHU"]
[Tue Jul 21 08:20:31.323697 2026] [security2:error] [pid 411857:tid 412106] [client 117.210.135.0:57732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9V_y7ynBpLeKYztQPaQgAAAHU"]
[Tue Jul 21 08:20:31.334196 2026] [security2:error] [pid 411857:tid 411931] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9V_y7ynBpLeKYztQPaQwAASUg"]
[Tue Jul 21 08:20:31.382444 2026] [security2:error] [pid 411857:tid 411957] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.wendelleite.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9V_y7ynBpLeKYztQPaRAAAZWE"]
[Tue Jul 21 08:20:31.434648 2026] [security2:error] [pid 411857:tid 412016] [client 35.233.163.26:56947] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "corretor.lumevisual.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9V_y7ynBpLeKYztQPaRQAAABs"]
[Tue Jul 21 08:20:31.596244 2026] [security2:error] [pid 419508:tid 419527] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.wendelleite.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9V_1cagwCeNbomjVv-lgACDhI"]
[Tue Jul 21 08:20:31.643547 2026] [security2:error] [pid 411857:tid 419457] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9V_y7ynBpLeKYztQPaSwAAUos"]
[Tue Jul 21 08:20:31.733244 2026] [security2:error] [pid 411857:tid 411864] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.wendelleite.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9V_y7ynBpLeKYztQPaTAAAcAU"]
[Tue Jul 21 08:20:31.868078 2026] [security2:error] [pid 419508:tid 419536] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.wendelleite.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9V_1cagwCeNbomjVv-mgABrxs"]
[Tue Jul 21 08:20:31.937917 2026] [security2:error] [pid 419508:tid 419656] [client 35.233.163.26:52760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "corretor.lumevisual.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9V_1cagwCeNbomjVv-mwAAAaE"]
[Tue Jul 21 08:20:31.946625 2026] [security2:error] [pid 411857:tid 411896] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9V_y7ynBpLeKYztQPaTwAAVCU"]
[Tue Jul 21 08:20:32.015268 2026] [security2:error] [pid 419508:tid 419642] [client 103.255.105.130:26621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WAFcagwCeNbomjVv-ngAAAZM"]
[Tue Jul 21 08:20:32.015386 2026] [security2:error] [pid 419508:tid 419642] [client 103.255.105.130:26621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WAFcagwCeNbomjVv-ngAAAZM"]
[Tue Jul 21 08:20:32.083026 2026] [security2:error] [pid 411857:tid 411892] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WAC7ynBpLeKYztQPaVQAAFyE"]
[Tue Jul 21 08:20:32.083161 2026] [security2:error] [pid 411857:tid 412012] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WAC7ynBpLeKYztQPaVQAAFyE"]
[Tue Jul 21 08:20:32.207625 2026] [security2:error] [pid 411857:tid 412066] [client 195.49.128.211:63683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9V_i7ynBpLeKYztQPaGgAAAE0"]
[Tue Jul 21 08:20:32.207780 2026] [security2:error] [pid 411857:tid 412066] [client 195.49.128.211:63683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9V_i7ynBpLeKYztQPaGgAAAE0"]
[Tue Jul 21 08:20:32.229020 2026] [security2:error] [pid 411857:tid 411938] [remote 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.wendelleite.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9WAC7ynBpLeKYztQPaVgAAM08"]
[Tue Jul 21 08:20:32.253396 2026] [security2:error] [pid 411857:tid 411875] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9WAC7ynBpLeKYztQPaWQAAaBA"]
[Tue Jul 21 08:20:32.361144 2026] [security2:error] [pid 411857:tid 411859] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php"] [unique_id "al9WAC7ynBpLeKYztQPaWgAAfwA"]
[Tue Jul 21 08:20:32.425099 2026] [security2:error] [pid 411857:tid 412001] [client 35.233.163.26:64463] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "corretor.lumevisual.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9WAC7ynBpLeKYztQPaWwAAAAw"]
[Tue Jul 21 08:20:32.557288 2026] [security2:error] [pid 411857:tid 411948] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9WAC7ynBpLeKYztQPaXgAARVk"]
[Tue Jul 21 08:20:32.558795 2026] [security2:error] [pid 411857:tid 411880] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9WAC7ynBpLeKYztQPaXwAATxU"]
[Tue Jul 21 08:20:32.594724 2026] [security2:error] [pid 419508:tid 419710] [client 20.226.60.151:64091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/mosty.php"] [unique_id "al9WAFcagwCeNbomjVv-oQAAAdc"]
[Tue Jul 21 08:20:32.829717 2026] [security2:error] [pid 418108:tid 418258] [client 35.233.163.26:55693] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "corretor.lumevisual.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9WAA0cxofL2J1zwYrA7QAAARw"]
[Tue Jul 21 08:20:32.874155 2026] [security2:error] [pid 419508:tid 419661] [client 120.56.162.40:62971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WAFcagwCeNbomjVv-ogAAAaY"]
[Tue Jul 21 08:20:32.874267 2026] [security2:error] [pid 419508:tid 419661] [client 120.56.162.40:62971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WAFcagwCeNbomjVv-ogAAAaY"]
[Tue Jul 21 08:20:32.907130 2026] [security2:error] [pid 411857:tid 411934] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9WAC7ynBpLeKYztQPaaQAASUs"]
[Tue Jul 21 08:20:33.211264 2026] [security2:error] [pid 411857:tid 411915] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9WAS7ynBpLeKYztQPabgAAGzg"]
[Tue Jul 21 08:20:33.246832 2026] [security2:error] [pid 411857:tid 412018] [client 35.233.163.26:65015] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "corretor.lumevisual.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9WAS7ynBpLeKYztQPabwAAAB0"]
[Tue Jul 21 08:20:33.519617 2026] [security2:error] [pid 411857:tid 419462] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.raphaelicarolicitacoes.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9WAS7ynBpLeKYztQPacgAAJ5A"]
[Tue Jul 21 08:20:33.543185 2026] [security2:error] [pid 419508:tid 419704] [client 74.249.245.134:62498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/gettest.php"] [unique_id "al9WAVcagwCeNbomjVv-qgAAAdE"]
[Tue Jul 21 08:20:33.796484 2026] [security2:error] [pid 419508:tid 419625] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WAVcagwCeNbomjVv-rgAB1HQ"]
[Tue Jul 21 08:20:33.796645 2026] [security2:error] [pid 419508:tid 419707] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WAVcagwCeNbomjVv-rgAB1HQ"]
[Tue Jul 21 08:20:33.973217 2026] [security2:error] [pid 419508:tid 419750] [client 20.226.60.151:59305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/mds.php"] [unique_id "al9WAVcagwCeNbomjVv-sgAAAf4"]
[Tue Jul 21 08:20:34.223349 2026] [security2:error] [pid 411857:tid 411971] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php"] [unique_id "al9WAi7ynBpLeKYztQPafAAAMG8"]
[Tue Jul 21 08:20:34.315885 2026] [security2:error] [pid 419508:tid 419761] [client 20.226.60.151:64004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/6.php"] [unique_id "al9WAlcagwCeNbomjVv-uAAAAgk"]
[Tue Jul 21 08:20:34.321232 2026] [security2:error] [pid 419508:tid 419514] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WAlcagwCeNbomjVv-uQACCAU"]
[Tue Jul 21 08:20:34.323051 2026] [security2:error] [pid 419508:tid 419760] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WAlcagwCeNbomjVv-uQACCAU"]
[Tue Jul 21 08:20:34.330139 2026] [security2:error] [pid 419508:tid 419564] [remote 147.50.252.213:36466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/wp-login.php"] [unique_id "al9WAlcagwCeNbomjVv-ugAByTc"]
[Tue Jul 21 08:20:34.425962 2026] [security2:error] [pid 411857:tid 411980] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9WAi7ynBpLeKYztQPagQAAA3g"]
[Tue Jul 21 08:20:34.509907 2026] [security2:error] [pid 411857:tid 412026] [client 162.219.176.3:34488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9WAi7ynBpLeKYztQPaggAAACU"]
[Tue Jul 21 08:20:34.509991 2026] [security2:error] [pid 411857:tid 412026] [client 162.219.176.3:34488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9WAi7ynBpLeKYztQPaggAAACU"]
[Tue Jul 21 08:20:34.822453 2026] [security2:error] [pid 418108:tid 418332] [client 74.249.245.134:43488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/tfm.php"] [unique_id "al9WAg0cxofL2J1zwYrA9QAAAWY"]
[Tue Jul 21 08:20:34.921928 2026] [security2:error] [pid 411857:tid 412004] [client 154.208.47.43:4255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WAi7ynBpLeKYztQPaiQAAAA8"]
[Tue Jul 21 08:20:34.922068 2026] [security2:error] [pid 411857:tid 412004] [client 154.208.47.43:4255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WAi7ynBpLeKYztQPaiQAAAA8"]
[Tue Jul 21 08:20:35.176162 2026] [security2:error] [pid 419508:tid 419731] [client 20.226.60.151:64003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/32e17094cfindex.php"] [unique_id "al9WA1cagwCeNbomjVv-wgAAAew"]
[Tue Jul 21 08:20:35.516460 2026] [security2:error] [pid 411857:tid 412095] [client 20.226.60.151:64108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-blink.php"] [unique_id "al9WAy7ynBpLeKYztQPakwAAAGo"]
[Tue Jul 21 08:20:35.541514 2026] [security2:error] [pid 418108:tid 418345] [client 38.100.221.102:19082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WAw0cxofL2J1zwYrA-AAAAXM"]
[Tue Jul 21 08:20:35.541650 2026] [security2:error] [pid 418108:tid 418345] [client 38.100.221.102:19082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WAw0cxofL2J1zwYrA-AAAAXM"]
[Tue Jul 21 08:20:35.721119 2026] [security2:error] [pid 411857:tid 412014] [client 65.21.113.253:43532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WAy7ynBpLeKYztQPaiwAAABk"]
[Tue Jul 21 08:20:35.733774 2026] [security2:error] [pid 419508:tid 419677] [client 20.226.60.151:60628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/spadex.php"] [unique_id "al9WA1cagwCeNbomjVv-yQAAAbY"]
[Tue Jul 21 08:20:35.873199 2026] [security2:error] [pid 419508:tid 419660] [client 187.125.243.197:63397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WA1cagwCeNbomjVv-zgAAAaU"]
[Tue Jul 21 08:20:35.873322 2026] [security2:error] [pid 419508:tid 419660] [client 187.125.243.197:63397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WA1cagwCeNbomjVv-zgAAAaU"]
[Tue Jul 21 08:20:36.072869 2026] [security2:error] [pid 411857:tid 411863] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php"] [unique_id "al9WBC7ynBpLeKYztQPamwAAVQQ"]
[Tue Jul 21 08:20:36.346568 2026] [security2:error] [pid 411857:tid 411869] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9WBC7ynBpLeKYztQPaoQAALQo"]
[Tue Jul 21 08:20:36.351598 2026] [security2:error] [pid 411857:tid 411999] [client 20.226.60.151:64062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/zc-208.php"] [unique_id "al9WBC7ynBpLeKYztQPaogAAAAo"]
[Tue Jul 21 08:20:36.791979 2026] [security2:error] [pid 419508:tid 419655] [client 103.151.46.103:60292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WBFcagwCeNbomjVv-3QAAAaA"]
[Tue Jul 21 08:20:36.792951 2026] [security2:error] [pid 419508:tid 419655] [client 103.151.46.103:60292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WBFcagwCeNbomjVv-3QAAAaA"]
[Tue Jul 21 08:20:37.048039 2026] [security2:error] [pid 411857:tid 412073] [client 20.226.60.151:64045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/qqqa.php"] [unique_id "al9WBS7ynBpLeKYztQParQAAAFQ"]
[Tue Jul 21 08:20:37.081830 2026] [security2:error] [pid 418108:tid 418303] [client 115.134.11.136:50114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WBQ0cxofL2J1zwYrA-gAAAUk"]
[Tue Jul 21 08:20:37.082434 2026] [security2:error] [pid 418108:tid 418303] [client 115.134.11.136:50114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WBQ0cxofL2J1zwYrA-gAAAUk"]
[Tue Jul 21 08:20:37.155688 2026] [security2:error] [pid 419508:tid 419749] [client 20.226.60.151:60664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/2x.php"] [unique_id "al9WBVcagwCeNbomjVv-5AAAAf0"]
[Tue Jul 21 08:20:37.218670 2026] [security2:error] [pid 419508:tid 419665] [client 20.226.60.151:64115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/sid4.php"] [unique_id "al9WBVcagwCeNbomjVv-5QAAAao"]
[Tue Jul 21 08:20:37.369384 2026] [security2:error] [pid 418108:tid 418366] [client 74.249.245.134:44670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/ws81.php"] [unique_id "al9WBQ0cxofL2J1zwYrA_AAAAYg"]
[Tue Jul 21 08:20:37.406678 2026] [security2:error] [pid 419508:tid 419719] [client 223.181.60.88:7216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WBVcagwCeNbomjVv-6AAAAeA"]
[Tue Jul 21 08:20:37.406798 2026] [security2:error] [pid 419508:tid 419719] [client 223.181.60.88:7216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WBVcagwCeNbomjVv-6AAAAeA"]
[Tue Jul 21 08:20:37.773730 2026] [security2:error] [pid 418108:tid 418335] [client 20.226.60.151:64111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wmore1.php"] [unique_id "al9WBQ0cxofL2J1zwYrBAAAAAWk"]
[Tue Jul 21 08:20:37.919624 2026] [security2:error] [pid 419508:tid 419687] [client 152.59.34.51:57750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WBVcagwCeNbomjVv-8QAAAcA"]
[Tue Jul 21 08:20:37.919743 2026] [security2:error] [pid 419508:tid 419687] [client 152.59.34.51:57750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WBVcagwCeNbomjVv-8QAAAcA"]
[Tue Jul 21 08:20:37.976680 2026] [security2:error] [pid 411857:tid 411972] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php"] [unique_id "al9WBS7ynBpLeKYztQPavAAAL3A"]
[Tue Jul 21 08:20:38.148303 2026] [security2:error] [pid 419508:tid 419535] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WBlcagwCeNbomjVv-9AACDho"]
[Tue Jul 21 08:20:38.148525 2026] [security2:error] [pid 419508:tid 419766] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WBlcagwCeNbomjVv-9AACDho"]
[Tue Jul 21 08:20:38.248130 2026] [security2:error] [pid 411857:tid 412010] [client 20.226.60.151:59277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/solo1.php"] [unique_id "al9WBi7ynBpLeKYztQPavwAAABU"]
[Tue Jul 21 08:20:38.273359 2026] [security2:error] [pid 411857:tid 419465] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9WBi7ynBpLeKYztQPawAAAApM"]
[Tue Jul 21 08:20:38.434485 2026] [security2:error] [pid 411857:tid 412077] [client 65.21.113.253:43532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WBS7ynBpLeKYztQPatwAAAFg"]
[Tue Jul 21 08:20:38.589094 2026] [security2:error] [pid 411857:tid 412016] [client 20.226.60.151:64115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/aunmc.php"] [unique_id "al9WBi7ynBpLeKYztQPayQAAABs"]
[Tue Jul 21 08:20:38.955932 2026] [security2:error] [pid 411857:tid 411887] [remote 103.133.214.160:52936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.214.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9WBi7ynBpLeKYztQPazAAANRw"]
[Tue Jul 21 08:20:38.956133 2026] [security2:error] [pid 411857:tid 412042] [client 103.133.214.160:52936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9WBi7ynBpLeKYztQPazAAANRw"]
[Tue Jul 21 08:20:38.971861 2026] [security2:error] [pid 419508:tid 419703] [client 20.226.60.151:59092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/cong.php"] [unique_id "al9WBlcagwCeNbomjVv-_QAAAdA"]
[Tue Jul 21 08:20:39.196239 2026] [security2:error] [pid 419508:tid 419668] [client 61.1.167.83:64563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WB1cagwCeNbomjVv-_wAAAa0"]
[Tue Jul 21 08:20:39.196372 2026] [security2:error] [pid 419508:tid 419668] [client 61.1.167.83:64563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WB1cagwCeNbomjVv-_wAAAa0"]
[Tue Jul 21 08:20:39.450864 2026] [security2:error] [pid 411857:tid 412053] [client 117.213.202.34:56927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WBy7ynBpLeKYztQPa2wAAAEA"]
[Tue Jul 21 08:20:39.451035 2026] [security2:error] [pid 411857:tid 412053] [client 117.213.202.34:56927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WBy7ynBpLeKYztQPa2wAAAEA"]
[Tue Jul 21 08:20:39.491339 2026] [security2:error] [pid 411857:tid 411997] [client 65.21.113.253:37332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WBy7ynBpLeKYztQPa1AAAAAg"]
[Tue Jul 21 08:20:39.573441 2026] [security2:error] [pid 411857:tid 412093] [client 20.226.60.151:50149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/ctex1.php"] [unique_id "al9WBy7ynBpLeKYztQPa4AAAAGg"]
[Tue Jul 21 08:20:39.654209 2026] [security2:error] [pid 419508:tid 419700] [client 74.249.245.134:43482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/222.php"] [unique_id "al9WB1cagwCeNbomjVv_BQAAAc0"]
[Tue Jul 21 08:20:39.693111 2026] [security2:error] [pid 418108:tid 418295] [client 20.226.60.151:59290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/public/css.php"] [unique_id "al9WBw0cxofL2J1zwYrBBQAAAUE"]
[Tue Jul 21 08:20:39.924782 2026] [security2:error] [pid 419508:tid 419534] [remote 17.246.19.151:53148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.19.246.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9WBlcagwCeNbomjVv--wABpRk"]
[Tue Jul 21 08:20:40.005200 2026] [security2:error] [pid 411857:tid 411879] [remote 57.141.18.55:40654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapl.xml"] [unique_id "al9WBi7ynBpLeKYztQPazwAAChQ"]
[Tue Jul 21 08:20:40.076717 2026] [security2:error] [pid 411857:tid 412012] [client 87.116.180.198:27364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WCC7ynBpLeKYztQPa6AAAABc"]
[Tue Jul 21 08:20:40.076850 2026] [security2:error] [pid 411857:tid 412012] [client 87.116.180.198:27364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WCC7ynBpLeKYztQPa6AAAABc"]
[Tue Jul 21 08:20:40.084017 2026] [security2:error] [pid 419508:tid 419763] [client 20.226.60.151:59317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/uoocf.php"] [unique_id "al9WCFcagwCeNbomjVv_CQAAAgs"]
[Tue Jul 21 08:20:40.096897 2026] [security2:error] [pid 419508:tid 419727] [client 20.220.225.223:38712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/hunter.php"] [unique_id "al9WCFcagwCeNbomjVv_CwAAAeg"]
[Tue Jul 21 08:20:40.176759 2026] [security2:error] [pid 419508:tid 419760] [client 20.151.10.161:46025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/als.php"] [unique_id "al9WCFcagwCeNbomjVv_DAAAAgg"]
[Tue Jul 21 08:20:40.523889 2026] [security2:error] [pid 411857:tid 412029] [client 14.245.224.124:55119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WCC7ynBpLeKYztQPa7gAAACg"]
[Tue Jul 21 08:20:40.524069 2026] [security2:error] [pid 411857:tid 412029] [client 14.245.224.124:55119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WCC7ynBpLeKYztQPa7gAAACg"]
[Tue Jul 21 08:20:40.542842 2026] [security2:error] [pid 419508:tid 419723] [client 45.132.227.207:22859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiferreira.com.br"] [uri "/wp-login.php"] [unique_id "al9WCFcagwCeNbomjVv_DgAAAeQ"]
[Tue Jul 21 08:20:40.544179 2026] [security2:error] [pid 411857:tid 412091] [client 195.49.128.211:64342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WCC7ynBpLeKYztQPa8QAAAGY"]
[Tue Jul 21 08:20:40.544287 2026] [security2:error] [pid 411857:tid 412091] [client 195.49.128.211:64342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WCC7ynBpLeKYztQPa8QAAAGY"]
[Tue Jul 21 08:20:40.851530 2026] [security2:error] [pid 418108:tid 418360] [client 20.226.60.151:59270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/output.php"] [unique_id "al9WCA0cxofL2J1zwYrBCQAAAYI"]
[Tue Jul 21 08:20:40.936185 2026] [security2:error] [pid 411857:tid 412046] [client 150.129.202.39:65147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WCC7ynBpLeKYztQPa9AAAADk"]
[Tue Jul 21 08:20:40.936317 2026] [security2:error] [pid 411857:tid 412046] [client 150.129.202.39:65147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WCC7ynBpLeKYztQPa9AAAADk"]
[Tue Jul 21 08:20:41.051898 2026] [security2:error] [pid 419508:tid 419681] [client 20.220.225.223:12302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/old.php"] [unique_id "al9WCVcagwCeNbomjVv_GAAAAbo"]
[Tue Jul 21 08:20:41.070042 2026] [security2:error] [pid 411857:tid 411954] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WCS7ynBpLeKYztQPa-wAAOl4"]
[Tue Jul 21 08:20:41.070182 2026] [security2:error] [pid 411857:tid 412047] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WCS7ynBpLeKYztQPa-wAAOl4"]
[Tue Jul 21 08:20:41.238187 2026] [security2:error] [pid 419508:tid 419693] [client 117.210.135.0:58368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WCVcagwCeNbomjVv_HAAAAcY"]
[Tue Jul 21 08:20:41.238745 2026] [security2:error] [pid 419508:tid 419693] [client 117.210.135.0:58368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WCVcagwCeNbomjVv_HAAAAcY"]
[Tue Jul 21 08:20:41.261893 2026] [security2:error] [pid 411857:tid 411938] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/"] [unique_id "al9WCS7ynBpLeKYztQPa_wAAJ08"]
[Tue Jul 21 08:20:41.262017 2026] [security2:error] [pid 419508:tid 419676] [client 103.106.20.201:56440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WCVcagwCeNbomjVv_HQAAAbU"]
[Tue Jul 21 08:20:41.262209 2026] [security2:error] [pid 419508:tid 419676] [client 103.106.20.201:56440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WCVcagwCeNbomjVv_HQAAAbU"]
[Tue Jul 21 08:20:41.262251 2026] [security2:error] [pid 411857:tid 411875] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/"] [unique_id "al9WCS7ynBpLeKYztQPbAAAAJxA"]
[Tue Jul 21 08:20:41.263914 2026] [security2:error] [pid 411857:tid 411919] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/"] [unique_id "al9WCS7ynBpLeKYztQPbBgAAJzw"]
[Tue Jul 21 08:20:41.264597 2026] [security2:error] [pid 411857:tid 411874] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/"] [unique_id "al9WCS7ynBpLeKYztQPbBAAAJw8"]
[Tue Jul 21 08:20:41.399716 2026] [security2:error] [pid 411857:tid 411973] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/"] [unique_id "al9WCS7ynBpLeKYztQPbDwAAJ3E"]
[Tue Jul 21 08:20:41.401981 2026] [security2:error] [pid 411857:tid 411977] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/"] [unique_id "al9WCS7ynBpLeKYztQPbEgAAJ3U"]
[Tue Jul 21 08:20:41.482970 2026] [security2:error] [pid 411857:tid 412062] [client 65.21.113.253:37332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WCC7ynBpLeKYztQPa9gAAAEk"]
[Tue Jul 21 08:20:41.665739 2026] [security2:error] [pid 419508:tid 419594] [remote 17.246.19.151:53148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.19.246.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9WCVcagwCeNbomjVv_JgABxVU"]
[Tue Jul 21 08:20:41.814399 2026] [security2:error] [pid 411857:tid 412074] [client 216.73.160.194:54681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/wp-login.php"] [unique_id "al9WCS7ynBpLeKYztQPbHQAAAFU"]
[Tue Jul 21 08:20:42.013482 2026] [security2:error] [pid 418108:tid 418246] [client 20.220.225.223:49035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/wp-wpbak.php"] [unique_id "al9WCg0cxofL2J1zwYrBEAAAARA"]
[Tue Jul 21 08:20:42.047876 2026] [security2:error] [pid 419508:tid 419717] [client 20.226.60.151:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-file-120.php"] [unique_id "al9WClcagwCeNbomjVv_LgAAAd4"]
[Tue Jul 21 08:20:42.509916 2026] [security2:error] [pid 411857:tid 412012] [client 14.97.58.74:47906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WCi7ynBpLeKYztQPbLQAAABc"]
[Tue Jul 21 08:20:42.510057 2026] [security2:error] [pid 411857:tid 412012] [client 14.97.58.74:47906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WCi7ynBpLeKYztQPbLQAAABc"]
[Tue Jul 21 08:20:42.552465 2026] [autoindex:error] [pid 418108:tid 418276] [client 129.211.229.121:50434] AH01276: Cannot serve directory /home2/italom32/rota40.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:20:42.573595 2026] [security2:error] [pid 418108:tid 418204] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WCg0cxofL2J1zwYrBFQABLF0"]
[Tue Jul 21 08:20:42.573751 2026] [security2:error] [pid 418108:tid 418274] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WCg0cxofL2J1zwYrBFQABLF0"]
[Tue Jul 21 08:20:42.739077 2026] [security2:error] [pid 411857:tid 412046] [client 74.249.245.134:47121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/t.php"] [unique_id "al9WCi7ynBpLeKYztQPbNQAAADk"]
[Tue Jul 21 08:20:42.861243 2026] [security2:error] [pid 419508:tid 419687] [client 62.72.12.32:0] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "vidrosprovetro.com.br"] [uri "/index.php"] [unique_id "al9WCVcagwCeNbomjVv_IgABwD4"]
[Tue Jul 21 08:20:42.923843 2026] [security2:error] [pid 419508:tid 419654] [client 156.245.246.16:55213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.246.245.156.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cliente.appauto.com.br"] [uri "/index.php"] [unique_id "al9WCVcagwCeNbomjVv_KQAAAZ8"], referer: https://cliente.appauto.com.br
[Tue Jul 21 08:20:42.941282 2026] [security2:error] [pid 411857:tid 412099] [client 20.226.60.151:64071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/special.php"] [unique_id "al9WCi7ynBpLeKYztQPbOQAAAG4"]
[Tue Jul 21 08:20:43.204127 2026] [security2:error] [pid 411857:tid 411935] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/"] [unique_id "al9WCy7ynBpLeKYztQPbQgAAEUw"]
[Tue Jul 21 08:20:43.204292 2026] [security2:error] [pid 411857:tid 411940] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/"] [unique_id "al9WCy7ynBpLeKYztQPbQQAAEVE"]
[Tue Jul 21 08:20:43.208357 2026] [security2:error] [pid 411857:tid 419459] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/"] [unique_id "al9WCy7ynBpLeKYztQPbRAAAeI0"]
[Tue Jul 21 08:20:43.210893 2026] [security2:error] [pid 411857:tid 411865] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/api"] [unique_id "al9WCy7ynBpLeKYztQPbRgAAeAY"]
[Tue Jul 21 08:20:43.351257 2026] [security2:error] [pid 411857:tid 411863] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/api"] [unique_id "al9WCy7ynBpLeKYztQPbVwAAeAQ"]
[Tue Jul 21 08:20:43.352391 2026] [security2:error] [pid 411857:tid 411872] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/api"] [unique_id "al9WCy7ynBpLeKYztQPbWQAAeA0"]
[Tue Jul 21 08:20:43.468213 2026] [security2:error] [pid 419508:tid 419690] [client 120.56.162.40:63471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WC1cagwCeNbomjVv_QAAAAcM"]
[Tue Jul 21 08:20:43.468320 2026] [security2:error] [pid 419508:tid 419690] [client 120.56.162.40:63471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WC1cagwCeNbomjVv_QAAAAcM"]
[Tue Jul 21 08:20:43.515903 2026] [security2:error] [pid 411857:tid 412093] [client 20.226.60.151:64033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/as.php"] [unique_id "al9WCy7ynBpLeKYztQPbYQAAAGg"]
[Tue Jul 21 08:20:43.578173 2026] [security2:error] [pid 411857:tid 411999] [client 20.226.60.151:64126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/iywwi.php"] [unique_id "al9WCy7ynBpLeKYztQPbZAAAAAo"]
[Tue Jul 21 08:20:43.860981 2026] [security2:error] [pid 419508:tid 419665] [client 20.151.10.161:45854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/pol.php"] [unique_id "al9WC1cagwCeNbomjVv_SAAAAao"]
[Tue Jul 21 08:20:43.976705 2026] [security2:error] [pid 411857:tid 412066] [client 65.21.113.253:37332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WCy7ynBpLeKYztQPbYgAAAE0"]
[Tue Jul 21 08:20:44.019584 2026] [security2:error] [pid 411857:tid 411990] [client 20.220.225.223:31193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/we.php"] [unique_id "al9WDC7ynBpLeKYztQPbaQAAAAE"]
[Tue Jul 21 08:20:44.470550 2026] [security2:error] [pid 418108:tid 418165] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WDA0cxofL2J1zwYrBGwABFDY"]
[Tue Jul 21 08:20:44.470741 2026] [security2:error] [pid 418108:tid 418250] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WDA0cxofL2J1zwYrBGwABFDY"]
[Tue Jul 21 08:20:44.790676 2026] [security2:error] [pid 419508:tid 419580] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WDFcagwCeNbomjVv_TgABkkc"]
[Tue Jul 21 08:20:44.790865 2026] [security2:error] [pid 419508:tid 419641] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WDFcagwCeNbomjVv_TgABkkc"]
[Tue Jul 21 08:20:44.951552 2026] [security2:error] [pid 419508:tid 419675] [client 20.226.60.151:64002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9WDFcagwCeNbomjVv_VAAAAbQ"]
[Tue Jul 21 08:20:45.171654 2026] [security2:error] [pid 411857:tid 419447] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api"] [unique_id "al9WDS7ynBpLeKYztQPbhAAAZ4I"]
[Tue Jul 21 08:20:45.173546 2026] [security2:error] [pid 411857:tid 411901] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api"] [unique_id "al9WDS7ynBpLeKYztQPbhQAAZyo"]
[Tue Jul 21 08:20:45.214083 2026] [security2:error] [pid 411857:tid 411972] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api"] [unique_id "al9WDS7ynBpLeKYztQPbhwAAZ3A"]
[Tue Jul 21 08:20:45.215053 2026] [security2:error] [pid 411857:tid 411945] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api"] [unique_id "al9WDS7ynBpLeKYztQPbiQAAZ1Y"]
[Tue Jul 21 08:20:45.215076 2026] [security2:error] [pid 411857:tid 411886] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api"] [unique_id "al9WDS7ynBpLeKYztQPbjAAAZxs"]
[Tue Jul 21 08:20:45.215097 2026] [security2:error] [pid 411857:tid 411924] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api"] [unique_id "al9WDS7ynBpLeKYztQPbiAAAZ0E"]
[Tue Jul 21 08:20:45.215723 2026] [security2:error] [pid 411857:tid 419465] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/api/v1"] [unique_id "al9WDS7ynBpLeKYztQPbiwAAZ5M"]
[Tue Jul 21 08:20:45.435278 2026] [security2:error] [pid 419508:tid 419703] [client 20.226.60.151:64087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/gqgsa.php"] [unique_id "al9WDVcagwCeNbomjVv_XAAAAdA"]
[Tue Jul 21 08:20:45.629271 2026] [security2:error] [pid 419508:tid 419741] [client 198.54.129.60:47964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9WDVcagwCeNbomjVv_XQAAAfY"]
[Tue Jul 21 08:20:45.629384 2026] [security2:error] [pid 419508:tid 419741] [client 198.54.129.60:47964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9WDVcagwCeNbomjVv_XQAAAfY"]
[Tue Jul 21 08:20:46.088491 2026] [security2:error] [pid 419508:tid 419700] [client 20.151.10.161:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/file5.php"] [unique_id "al9WDlcagwCeNbomjVv_ZgAAAc0"]
[Tue Jul 21 08:20:46.088864 2026] [security2:error] [pid 419508:tid 419710] [client 38.100.221.102:18315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WDlcagwCeNbomjVv_ZwAAAdc"]
[Tue Jul 21 08:20:46.088971 2026] [security2:error] [pid 419508:tid 419710] [client 38.100.221.102:18315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WDlcagwCeNbomjVv_ZwAAAdc"]
[Tue Jul 21 08:20:46.222324 2026] [security2:error] [pid 419508:tid 419715] [client 20.220.225.223:12551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/ms-new.php"] [unique_id "al9WDlcagwCeNbomjVv_aAAAAdw"]
[Tue Jul 21 08:20:46.232638 2026] [security2:error] [pid 419508:tid 419660] [client 20.226.60.151:59297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/w1px.php"] [unique_id "al9WDlcagwCeNbomjVv_aQAAAaU"]
[Tue Jul 21 08:20:46.360857 2026] [security2:error] [pid 411857:tid 412010] [client 187.125.243.197:63896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WDi7ynBpLeKYztQPbpQAAABU"]
[Tue Jul 21 08:20:46.360989 2026] [security2:error] [pid 411857:tid 412010] [client 187.125.243.197:63896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WDi7ynBpLeKYztQPbpQAAABU"]
[Tue Jul 21 08:20:46.781300 2026] [security2:error] [pid 411857:tid 412037] [client 20.226.60.151:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/elbzl.php"] [unique_id "al9WDi7ynBpLeKYztQPbrgAAADA"]
[Tue Jul 21 08:20:46.950780 2026] [security2:error] [pid 411857:tid 412109] [client 20.151.10.161:45830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9WDi7ynBpLeKYztQPbtAAAAHg"]
[Tue Jul 21 08:20:47.083342 2026] [security2:error] [pid 411857:tid 412077] [client 65.21.113.253:37332] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WDi7ynBpLeKYztQPbqwAAAFg"]
[Tue Jul 21 08:20:47.146083 2026] [security2:error] [pid 411857:tid 411931] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/api/v1"] [unique_id "al9WDy7ynBpLeKYztQPbuwAAXEg"]
[Tue Jul 21 08:20:47.172039 2026] [security2:error] [pid 411857:tid 411957] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/api/v1"] [unique_id "al9WDy7ynBpLeKYztQPbvgAAXGE"]
[Tue Jul 21 08:20:47.183922 2026] [security2:error] [pid 411857:tid 419457] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api/v1"] [unique_id "al9WDy7ynBpLeKYztQPbxAAAXIs"]
[Tue Jul 21 08:20:47.184633 2026] [security2:error] [pid 411857:tid 411968] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api/v1"] [unique_id "al9WDy7ynBpLeKYztQPbxQAAXGw"]
[Tue Jul 21 08:20:47.223991 2026] [security2:error] [pid 411857:tid 411911] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api/v1"] [unique_id "al9WDy7ynBpLeKYztQPbyQAAXDQ"]
[Tue Jul 21 08:20:47.244221 2026] [autoindex:error] [pid 411857:tid 412015] [client 135.225.181.175:1280] AH01276: Cannot serve directory /home1/edua4721/trabalhista.eduardogoesadv.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:20:47.285299 2026] [security2:error] [pid 411857:tid 411894] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api/v1"] [unique_id "al9WDy7ynBpLeKYztQPbzAAAXCM"]
[Tue Jul 21 08:20:47.285422 2026] [security2:error] [pid 411857:tid 411896] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api/v1"] [unique_id "al9WDy7ynBpLeKYztQPbywAAXCU"]
[Tue Jul 21 08:20:47.285707 2026] [security2:error] [pid 411857:tid 411954] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api/v1"] [unique_id "al9WDy7ynBpLeKYztQPbzQAAXF4"]
[Tue Jul 21 08:20:47.556031 2026] [security2:error] [pid 419508:tid 419726] [client 20.226.60.151:64112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/adjig.php"] [unique_id "al9WD1cagwCeNbomjVv_fAAAAec"]
[Tue Jul 21 08:20:47.719233 2026] [security2:error] [pid 419508:tid 419679] [client 115.134.11.136:50673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WD1cagwCeNbomjVv_fQAAAbg"]
[Tue Jul 21 08:20:47.719364 2026] [security2:error] [pid 419508:tid 419679] [client 115.134.11.136:50673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WD1cagwCeNbomjVv_fQAAAbg"]
[Tue Jul 21 08:20:47.776273 2026] [security2:error] [pid 411857:tid 412068] [client 35.221.29.111:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.29.221.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WDy7ynBpLeKYztQPb3AAAAE8"]
[Tue Jul 21 08:20:47.847466 2026] [security2:error] [pid 411857:tid 412112] [client 74.249.245.134:49923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/a.php"] [unique_id "al9WDy7ynBpLeKYztQPb4AAAAHs"]
[Tue Jul 21 08:20:48.028015 2026] [security2:error] [pid 411857:tid 411991] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9WEC7ynBpLeKYztQPb4wAAAAI"]
[Tue Jul 21 08:20:48.200939 2026] [security2:error] [pid 419508:tid 419736] [client 223.181.60.88:1810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WEFcagwCeNbomjVv_gAAAAfE"]
[Tue Jul 21 08:20:48.201340 2026] [security2:error] [pid 419508:tid 419736] [client 223.181.60.88:1810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WEFcagwCeNbomjVv_gAAAAfE"]
[Tue Jul 21 08:20:48.267971 2026] [security2:error] [pid 419508:tid 419685] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9WEFcagwCeNbomjVv_gQAAAb4"]
[Tue Jul 21 08:20:48.457549 2026] [security2:error] [pid 411857:tid 412029] [client 103.151.46.103:60796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WEC7ynBpLeKYztQPb6QAAACg"]
[Tue Jul 21 08:20:48.457667 2026] [security2:error] [pid 411857:tid 412029] [client 103.151.46.103:60796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WEC7ynBpLeKYztQPb6QAAACg"]
[Tue Jul 21 08:20:48.506197 2026] [security2:error] [pid 419508:tid 419703] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9WEFcagwCeNbomjVv_hgAAAdA"]
[Tue Jul 21 08:20:48.534943 2026] [security2:error] [pid 419508:tid 419741] [client 20.151.10.161:46021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/file.php"] [unique_id "al9WEFcagwCeNbomjVv_iQAAAfY"]
[Tue Jul 21 08:20:48.596114 2026] [security2:error] [pid 411857:tid 412028] [client 20.226.60.151:59274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/byp.php"] [unique_id "al9WEC7ynBpLeKYztQPb7QAAACc"]
[Tue Jul 21 08:20:48.700695 2026] [security2:error] [pid 411857:tid 411875] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WEC7ynBpLeKYztQPb7gAALRA"]
[Tue Jul 21 08:20:48.700867 2026] [security2:error] [pid 411857:tid 412034] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WEC7ynBpLeKYztQPb7gAALRA"]
[Tue Jul 21 08:20:48.782296 2026] [security2:error] [pid 419508:tid 419704] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9WEFcagwCeNbomjVv_kAAAAdE"]
[Tue Jul 21 08:20:49.054882 2026] [security2:error] [pid 419508:tid 419649] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9WEVcagwCeNbomjVv_lAAAAZo"]
[Tue Jul 21 08:20:49.090112 2026] [security2:error] [pid 419508:tid 419750] [client 198.54.129.60:55710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9WEVcagwCeNbomjVv_lQAAAf4"]
[Tue Jul 21 08:20:49.090196 2026] [security2:error] [pid 419508:tid 419750] [client 198.54.129.60:55710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9WEVcagwCeNbomjVv_lQAAAf4"]
[Tue Jul 21 08:20:49.179689 2026] [security2:error] [pid 411857:tid 411873] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/api/v2"] [unique_id "al9WES7ynBpLeKYztQPb9AAAJA4"]
[Tue Jul 21 08:20:49.226512 2026] [security2:error] [pid 411857:tid 419469] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api/v2"] [unique_id "al9WES7ynBpLeKYztQPb_QAAMpc"]
[Tue Jul 21 08:20:49.227865 2026] [security2:error] [pid 411857:tid 411893] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api/v2"] [unique_id "al9WES7ynBpLeKYztQPcAAAAMiI"]
[Tue Jul 21 08:20:49.294321 2026] [security2:error] [pid 411857:tid 412002] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9WES7ynBpLeKYztQPcAgAAAA0"]
[Tue Jul 21 08:20:49.296859 2026] [security2:error] [pid 411857:tid 412094] [client 20.151.10.161:45918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/cfile.php"] [unique_id "al9WES7ynBpLeKYztQPcAwAAAGk"]
[Tue Jul 21 08:20:49.321495 2026] [security2:error] [pid 411857:tid 419448] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api/v2"] [unique_id "al9WES7ynBpLeKYztQPcBQAAMoM"]
[Tue Jul 21 08:20:49.323713 2026] [security2:error] [pid 411857:tid 411992] [client 20.226.60.151:64105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/yawa.php"] [unique_id "al9WES7ynBpLeKYztQPcCQAAAAM"]
[Tue Jul 21 08:20:49.323827 2026] [security2:error] [pid 411857:tid 411870] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/api/v2"] [unique_id "al9WES7ynBpLeKYztQPcBwAAMgs"]
[Tue Jul 21 08:20:49.325227 2026] [security2:error] [pid 411857:tid 419448] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/api/v2"] [unique_id "al9WES7ynBpLeKYztQPcBgAAMoM"]
[Tue Jul 21 08:20:49.427086 2026] [security2:error] [pid 419508:tid 419681] [client 20.226.60.151:64058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/js.php"] [unique_id "al9WEVcagwCeNbomjVv_pgAAAbo"]
[Tue Jul 21 08:20:49.595820 2026] [security2:error] [pid 419508:tid 419640] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9WEVcagwCeNbomjVv_qwAAAZE"]
[Tue Jul 21 08:20:49.700595 2026] [security2:error] [pid 419508:tid 419663] [client 20.151.10.161:46006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/class-wp.php"] [unique_id "al9WEVcagwCeNbomjVv_rgAAAag"]
[Tue Jul 21 08:20:49.849058 2026] [security2:error] [pid 419508:tid 419736] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9WEVcagwCeNbomjVv_rwAAAfE"]
[Tue Jul 21 08:20:50.013360 2026] [security2:error] [pid 419508:tid 419728] [client 74.249.245.134:59817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/a1.php"] [unique_id "al9WElcagwCeNbomjVv_sQAAAek"]
[Tue Jul 21 08:20:50.155329 2026] [security2:error] [pid 419508:tid 419670] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9WElcagwCeNbomjVv_tQAAAa8"]
[Tue Jul 21 08:20:50.263595 2026] [security2:error] [pid 418108:tid 418328] [client 20.226.60.151:64106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/ortasekerli1.php"] [unique_id "al9WEg0cxofL2J1zwYrBKwAAAWI"]
[Tue Jul 21 08:20:50.316387 2026] [security2:error] [pid 419508:tid 419717] [client 20.151.10.161:45923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9WElcagwCeNbomjVv_uAAAAd4"]
[Tue Jul 21 08:20:50.388988 2026] [security2:error] [pid 419508:tid 419651] [client 20.226.60.151:64044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/core.php"] [unique_id "al9WElcagwCeNbomjVv_ugAAAZw"]
[Tue Jul 21 08:20:50.405361 2026] [security2:error] [pid 411857:tid 411923] [remote 45.79.123.44:39632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9WEi7ynBpLeKYztQPcGQAATUA"]
[Tue Jul 21 08:20:50.425718 2026] [security2:error] [pid 419508:tid 419718] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9WElcagwCeNbomjVv_uwAAAd8"]
[Tue Jul 21 08:20:50.585313 2026] [security2:error] [pid 419508:tid 419566] [remote 104.131.116.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.116.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iducali.com.br"] [uri "/wp-login.php"] [unique_id "al9WElcagwCeNbomjVv_vAAB7zk"]
[Tue Jul 21 08:20:50.586589 2026] [security2:error] [pid 419508:tid 419654] [client 20.220.225.223:38679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/phpinfo.php1"] [unique_id "al9WElcagwCeNbomjVv_vQAAAZ8"]
[Tue Jul 21 08:20:50.720425 2026] [security2:error] [pid 411857:tid 412024] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9WEi7ynBpLeKYztQPcHwAAACM"]
[Tue Jul 21 08:20:50.832897 2026] [security2:error] [pid 419508:tid 419660] [client 20.151.10.161:46036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/aa2.php"] [unique_id "al9WElcagwCeNbomjVv_wwAAAaU"]
[Tue Jul 21 08:20:50.838971 2026] [security2:error] [pid 419508:tid 419698] [client 87.116.180.198:13895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WElcagwCeNbomjVv_xAAAAcs"]
[Tue Jul 21 08:20:50.839111 2026] [security2:error] [pid 419508:tid 419698] [client 87.116.180.198:13895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WElcagwCeNbomjVv_xAAAAcs"]
[Tue Jul 21 08:20:50.970055 2026] [security2:error] [pid 411857:tid 411937] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api/v2"] [unique_id "al9WEi7ynBpLeKYztQPcIgAAYU4"]
[Tue Jul 21 08:20:50.970055 2026] [security2:error] [pid 411857:tid 411981] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api/v2"] [unique_id "al9WEi7ynBpLeKYztQPcIQAAYXk"]
[Tue Jul 21 08:20:50.970122 2026] [security2:error] [pid 419508:tid 419765] [client 35.221.29.111:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9WElcagwCeNbomjVv_yQAAAg0"]
[Tue Jul 21 08:20:50.997489 2026] [security2:error] [pid 411857:tid 411929] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/api/v2"] [unique_id "al9WEi7ynBpLeKYztQPcJAAAJ0Y"]
[Tue Jul 21 08:20:51.016078 2026] [security2:error] [pid 411857:tid 411967] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/config"] [unique_id "al9WEy7ynBpLeKYztQPcJwAASGs"]
[Tue Jul 21 08:20:51.031227 2026] [security2:error] [pid 419508:tid 419733] [client 117.213.202.34:57449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WElcagwCeNbomjVv_sgAAAe4"]
[Tue Jul 21 08:20:51.031398 2026] [security2:error] [pid 419508:tid 419733] [client 117.213.202.34:57449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WElcagwCeNbomjVv_sgAAAe4"]
[Tue Jul 21 08:20:51.116039 2026] [security2:error] [pid 411857:tid 411876] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/config"] [unique_id "al9WEy7ynBpLeKYztQPcMgAASBE"]
[Tue Jul 21 08:20:51.117206 2026] [security2:error] [pid 411857:tid 411876] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/config"] [unique_id "al9WEy7ynBpLeKYztQPcNAAASBE"]
[Tue Jul 21 08:20:51.131763 2026] [security2:error] [pid 411857:tid 411993] [client 195.49.128.211:64919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WEy7ynBpLeKYztQPcOAAAAAQ"]
[Tue Jul 21 08:20:51.131873 2026] [security2:error] [pid 411857:tid 411993] [client 195.49.128.211:64919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WEy7ynBpLeKYztQPcOAAAAAQ"]
[Tue Jul 21 08:20:51.132869 2026] [security2:error] [pid 411857:tid 412107] [client 14.245.224.124:55556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WEy7ynBpLeKYztQPcOQAAAHY"]
[Tue Jul 21 08:20:51.133146 2026] [security2:error] [pid 411857:tid 412107] [client 14.245.224.124:55556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WEy7ynBpLeKYztQPcOQAAAHY"]
[Tue Jul 21 08:20:51.242039 2026] [security2:error] [pid 419508:tid 419693] [client 20.151.10.161:46064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/ccou.php"] [unique_id "al9WE1cagwCeNbomjVv_9wAAAcY"]
[Tue Jul 21 08:20:51.370369 2026] [security2:error] [pid 419508:tid 419640] [client 20.226.60.151:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/classwithtostring.php"] [unique_id "al9WE1cagwCeNbomjVv_-gAAAZE"]
[Tue Jul 21 08:20:51.499876 2026] [security2:error] [pid 419508:tid 419668] [client 150.129.202.39:64984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WE1cagwCeNbomjVv__gAAAa0"]
[Tue Jul 21 08:20:51.499999 2026] [security2:error] [pid 419508:tid 419668] [client 150.129.202.39:64984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WE1cagwCeNbomjVv__gAAAa0"]
[Tue Jul 21 08:20:51.779660 2026] [security2:error] [pid 419508:tid 419512] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WE1cagwCeNbomjVsABgAB6QM"]
[Tue Jul 21 08:20:51.779833 2026] [security2:error] [pid 419508:tid 419728] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WE1cagwCeNbomjVsABgAB6QM"]
[Tue Jul 21 08:20:51.819668 2026] [security2:error] [pid 411857:tid 412085] [client 117.210.135.0:59018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WEy7ynBpLeKYztQPcRAAAAGA"]
[Tue Jul 21 08:20:51.820305 2026] [security2:error] [pid 411857:tid 412085] [client 117.210.135.0:59018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WEy7ynBpLeKYztQPcRAAAAGA"]
[Tue Jul 21 08:20:52.006215 2026] [security2:error] [pid 411857:tid 412048] [client 103.106.20.201:57020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WFC7ynBpLeKYztQPcRwAAADs"]
[Tue Jul 21 08:20:52.006331 2026] [security2:error] [pid 411857:tid 412048] [client 103.106.20.201:57020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WFC7ynBpLeKYztQPcRwAAADs"]
[Tue Jul 21 08:20:52.130654 2026] [security2:error] [pid 419508:tid 419715] [client 20.226.60.151:59072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/19.php"] [unique_id "al9WFFcagwCeNbomjVsADgAAAdw"]
[Tue Jul 21 08:20:52.274891 2026] [security2:error] [pid 419508:tid 419765] [client 20.226.60.151:64084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/root.php"] [unique_id "al9WFFcagwCeNbomjVsADwAAAg0"]
[Tue Jul 21 08:20:52.284629 2026] [security2:error] [pid 411857:tid 412058] [client 20.151.10.161:45983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/dr.php"] [unique_id "al9WFC7ynBpLeKYztQPcTAAAAEU"]
[Tue Jul 21 08:20:52.773241 2026] [security2:error] [pid 411857:tid 412014] [client 20.151.10.161:46018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/xamp.php"] [unique_id "al9WFC7ynBpLeKYztQPcUwAAABk"]
[Tue Jul 21 08:20:52.792043 2026] [security2:error] [pid 411857:tid 411921] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config"] [unique_id "al9WFC7ynBpLeKYztQPcWQAAEj4"]
[Tue Jul 21 08:20:52.806663 2026] [security2:error] [pid 411857:tid 411889] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config"] [unique_id "al9WFC7ynBpLeKYztQPcWwAAEh4"]
[Tue Jul 21 08:20:52.812103 2026] [security2:error] [pid 419508:tid 419696] [client 20.226.60.151:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/sym403.php"] [unique_id "al9WFFcagwCeNbomjVsAHgAAAck"]
[Tue Jul 21 08:20:52.888508 2026] [security2:error] [pid 411857:tid 411916] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config"] [unique_id "al9WFC7ynBpLeKYztQPcYQAAEjk"]
[Tue Jul 21 08:20:52.891104 2026] [security2:error] [pid 411857:tid 411930] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config"] [unique_id "al9WFC7ynBpLeKYztQPcYwAAEkc"]
[Tue Jul 21 08:20:52.891334 2026] [security2:error] [pid 411857:tid 411887] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config"] [unique_id "al9WFC7ynBpLeKYztQPcYgAAEhw"]
[Tue Jul 21 08:20:52.891342 2026] [security2:error] [pid 411857:tid 411902] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/config"] [unique_id "al9WFC7ynBpLeKYztQPcZAAAEis"]
[Tue Jul 21 08:20:52.925044 2026] [security2:error] [pid 411857:tid 412033] [client 152.59.34.51:63437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WFC7ynBpLeKYztQPcZQAAACw"]
[Tue Jul 21 08:20:52.925118 2026] [security2:error] [pid 411857:tid 412033] [client 152.59.34.51:63437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WFC7ynBpLeKYztQPcZQAAACw"]
[Tue Jul 21 08:20:52.967522 2026] [security2:error] [pid 411857:tid 411888] [remote 103.215.74.26:40804] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "atom-growth.com"] [uri "/api/config"] [unique_id "al9WFC7ynBpLeKYztQPcaAAAcR0"]
[Tue Jul 21 08:20:53.070300 2026] [security2:error] [pid 411857:tid 419455] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WFS7ynBpLeKYztQPcbwAAY4k"]
[Tue Jul 21 08:20:53.070546 2026] [security2:error] [pid 411857:tid 412088] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WFS7ynBpLeKYztQPcbwAAY4k"]
[Tue Jul 21 08:20:53.131965 2026] [security2:error] [pid 419508:tid 419641] [client 20.226.60.151:59283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/inc.php"] [unique_id "al9WFVcagwCeNbomjVsAKwAAAZI"]
[Tue Jul 21 08:20:53.181396 2026] [security2:error] [pid 418108:tid 418294] [client 111.93.58.162:61792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WFQ0cxofL2J1zwYrBLwAAAUA"]
[Tue Jul 21 08:20:53.181555 2026] [security2:error] [pid 418108:tid 418294] [client 111.93.58.162:61792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WFQ0cxofL2J1zwYrBLwAAAUA"]
[Tue Jul 21 08:20:53.495992 2026] [security2:error] [pid 411857:tid 412040] [client 20.151.10.161:46009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/bless.php"] [unique_id "al9WFS7ynBpLeKYztQPcdwAAADM"]
[Tue Jul 21 08:20:53.571549 2026] [autoindex:error] [pid 418108:tid 418334] [client 147.185.132.90:62612] AH01276: Cannot serve directory /home2/bavosc49/drive.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:20:53.610859 2026] [security2:error] [pid 419508:tid 419692] [client 20.226.60.151:64033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/v543.php"] [unique_id "al9WFVcagwCeNbomjVsALgAAAcU"]
[Tue Jul 21 08:20:53.663781 2026] [security2:error] [pid 419508:tid 419717] [client 20.220.225.223:12599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/track.php"] [unique_id "al9WFVcagwCeNbomjVsAMAAAAd4"]
[Tue Jul 21 08:20:53.855853 2026] [security2:error] [pid 419508:tid 419739] [client 20.151.10.161:45995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/file46.php"] [unique_id "al9WFVcagwCeNbomjVsANQAAAfQ"]
[Tue Jul 21 08:20:54.122380 2026] [security2:error] [pid 411857:tid 412043] [client 20.226.60.151:64118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/sixxis.php"] [unique_id "al9WFi7ynBpLeKYztQPcgQAAADY"]
[Tue Jul 21 08:20:54.152390 2026] [security2:error] [pid 418108:tid 418325] [client 65.21.113.253:38122] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WFQ0cxofL2J1zwYrBMwAAAV8"]
[Tue Jul 21 08:20:54.180252 2026] [security2:error] [pid 418108:tid 418269] [client 120.56.162.40:63971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WFg0cxofL2J1zwYrBNgAAASc"]
[Tue Jul 21 08:20:54.180379 2026] [security2:error] [pid 418108:tid 418269] [client 120.56.162.40:63971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WFg0cxofL2J1zwYrBNgAAASc"]
[Tue Jul 21 08:20:54.572342 2026] [security2:error] [pid 419508:tid 419750] [client 20.151.10.161:45853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/eee.php"] [unique_id "al9WFlcagwCeNbomjVsAPwAAAf4"]
[Tue Jul 21 08:20:54.733446 2026] [security2:error] [pid 411857:tid 412054] [client 20.220.225.223:42135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/dr.php"] [unique_id "al9WFi7ynBpLeKYztQPcigAAAEE"]
[Tue Jul 21 08:20:54.904993 2026] [security2:error] [pid 411857:tid 412006] [client 20.226.60.151:59287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/ip.php"] [unique_id "al9WFi7ynBpLeKYztQPckAAAABE"]
[Tue Jul 21 08:20:55.078079 2026] [security2:error] [pid 419508:tid 419549] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WF1cagwCeNbomjVsARwAB_yg"]
[Tue Jul 21 08:20:55.078230 2026] [security2:error] [pid 419508:tid 419751] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WF1cagwCeNbomjVsARwAB_yg"]
[Tue Jul 21 08:20:55.282010 2026] [security2:error] [pid 418108:tid 418214] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WFw0cxofL2J1zwYrBOQABhGc"]
[Tue Jul 21 08:20:55.282345 2026] [security2:error] [pid 418108:tid 418362] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WFw0cxofL2J1zwYrBOQABhGc"]
[Tue Jul 21 08:20:55.297745 2026] [security2:error] [pid 419508:tid 419538] [remote 216.73.216.184:46703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9WF1cagwCeNbomjVsASAABuh0"]
[Tue Jul 21 08:20:55.324472 2026] [security2:error] [pid 418108:tid 418246] [client 20.151.10.161:45959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/file25.php"] [unique_id "al9WFw0cxofL2J1zwYrBOgAAARA"]
[Tue Jul 21 08:20:55.606499 2026] [security2:error] [pid 418108:tid 418314] [client 20.226.60.151:64044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/kq1.php"] [unique_id "al9WFw0cxofL2J1zwYrBPQAAAVQ"]
[Tue Jul 21 08:20:55.845051 2026] [security2:error] [pid 419508:tid 419754] [client 198.54.129.60:55742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9WF1cagwCeNbomjVsASgAAAgI"]
[Tue Jul 21 08:20:55.845138 2026] [security2:error] [pid 419508:tid 419754] [client 198.54.129.60:55742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9WF1cagwCeNbomjVsASgAAAgI"]
[Tue Jul 21 08:20:55.899518 2026] [security2:error] [pid 419508:tid 419726] [client 20.226.60.151:64028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9WF1cagwCeNbomjVsASwAAAec"]
[Tue Jul 21 08:20:55.986047 2026] [security2:error] [pid 419508:tid 419679] [client 20.220.225.223:12304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/2352356666.php"] [unique_id "al9WF1cagwCeNbomjVsATQAAAbg"]
[Tue Jul 21 08:20:56.106742 2026] [security2:error] [pid 411857:tid 412106] [client 20.226.60.151:59273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/fw/faiyy.php"] [unique_id "al9WGC7ynBpLeKYztQPcowAAAHU"]
[Tue Jul 21 08:20:56.230200 2026] [security2:error] [pid 411857:tid 412034] [client 154.208.47.43:5140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WGC7ynBpLeKYztQPcpQAAAC0"]
[Tue Jul 21 08:20:56.230437 2026] [security2:error] [pid 411857:tid 412034] [client 154.208.47.43:5140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WGC7ynBpLeKYztQPcpQAAAC0"]
[Tue Jul 21 08:20:56.704544 2026] [security2:error] [pid 419508:tid 419727] [client 115.134.11.136:51465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WGFcagwCeNbomjVsAUgAAAeg"]
[Tue Jul 21 08:20:56.705135 2026] [security2:error] [pid 419508:tid 419727] [client 115.134.11.136:51465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WGFcagwCeNbomjVsAUgAAAeg"]
[Tue Jul 21 08:20:56.768574 2026] [security2:error] [pid 411857:tid 412062] [client 38.100.221.102:18588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WGC7ynBpLeKYztQPcrgAAAEk"]
[Tue Jul 21 08:20:56.768672 2026] [security2:error] [pid 411857:tid 412062] [client 38.100.221.102:18588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WGC7ynBpLeKYztQPcrgAAAEk"]
[Tue Jul 21 08:20:56.793326 2026] [security2:error] [pid 411857:tid 412085] [client 20.226.60.151:64015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/h02ugyh.php"] [unique_id "al9WGC7ynBpLeKYztQPcrwAAAGA"]
[Tue Jul 21 08:20:56.800949 2026] [security2:error] [pid 419508:tid 419561] [remote 216.73.216.184:46703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9WGFcagwCeNbomjVsAUwABtTQ"]
[Tue Jul 21 08:20:56.814878 2026] [security2:error] [pid 419508:tid 419677] [client 187.125.243.197:64395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WGFcagwCeNbomjVsAVAAAAbY"]
[Tue Jul 21 08:20:56.815033 2026] [security2:error] [pid 419508:tid 419677] [client 187.125.243.197:64395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WGFcagwCeNbomjVsAVAAAAbY"]
[Tue Jul 21 08:20:57.391436 2026] [security2:error] [pid 419508:tid 419675] [client 74.249.245.134:53480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/w.php"] [unique_id "al9WGVcagwCeNbomjVsAXQAAAbQ"]
[Tue Jul 21 08:20:57.590177 2026] [security2:error] [pid 411857:tid 412057] [client 20.226.60.151:60654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/miru1.php"] [unique_id "al9WGS7ynBpLeKYztQPcuwAAAEQ"]
[Tue Jul 21 08:20:57.761132 2026] [security2:error] [pid 411857:tid 412038] [client 20.226.60.151:64101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-temp.php"] [unique_id "al9WGS7ynBpLeKYztQPcwAAAADE"]
[Tue Jul 21 08:20:57.817460 2026] [security2:error] [pid 411857:tid 412017] [client 61.1.167.83:65076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WGS7ynBpLeKYztQPcwgAAABw"]
[Tue Jul 21 08:20:57.817574 2026] [security2:error] [pid 411857:tid 412017] [client 61.1.167.83:65076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WGS7ynBpLeKYztQPcwgAAABw"]
[Tue Jul 21 08:20:58.196129 2026] [security2:error] [pid 419508:tid 419741] [client 223.181.60.88:20019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WGlcagwCeNbomjVsAZQAAAfY"]
[Tue Jul 21 08:20:58.197308 2026] [security2:error] [pid 419508:tid 419741] [client 223.181.60.88:20019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WGlcagwCeNbomjVsAZQAAAfY"]
[Tue Jul 21 08:20:58.572382 2026] [security2:error] [pid 419508:tid 419751] [client 20.226.60.151:59293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9WGlcagwCeNbomjVsAbQAAAf8"]
[Tue Jul 21 08:20:58.698704 2026] [security2:error] [pid 419508:tid 419735] [client 20.220.225.223:42149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/2x.php"] [unique_id "al9WGlcagwCeNbomjVsAdAAAAfA"]
[Tue Jul 21 08:20:59.439602 2026] [security2:error] [pid 411857:tid 411933] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WGy7ynBpLeKYztQPc2gAAHUo"]
[Tue Jul 21 08:20:59.439753 2026] [security2:error] [pid 411857:tid 412018] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WGy7ynBpLeKYztQPc2gAAHUo"]
[Tue Jul 21 08:20:59.468715 2026] [security2:error] [pid 419508:tid 419696] [client 152.59.34.51:58650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WG1cagwCeNbomjVsAgAAAAck"]
[Tue Jul 21 08:20:59.468857 2026] [security2:error] [pid 419508:tid 419696] [client 152.59.34.51:58650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WG1cagwCeNbomjVsAgAAAAck"]
[Tue Jul 21 08:20:59.991643 2026] [security2:error] [pid 419508:tid 419758] [client 114.119.154.103:45311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "avermetais.com.br"] [uri "/produto/astro-delux-120/"] [unique_id "al9WG1cagwCeNbomjVsAiAAAAgY"], referer: http://avermetais.com.br/produto/astro-delux-120/
[Tue Jul 21 08:21:00.442551 2026] [security2:error] [pid 411857:tid 412039] [client 20.226.60.151:64055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-content/cong.php"] [unique_id "al9WHC7ynBpLeKYztQPc5wAAADI"]
[Tue Jul 21 08:21:00.454189 2026] [security2:error] [pid 419508:tid 419616] [remote 209.97.182.179:44374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9WHFcagwCeNbomjVsAlQAB2Gs"]
[Tue Jul 21 08:21:00.454321 2026] [security2:error] [pid 419508:tid 419711] [client 209.97.182.179:44374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9WHFcagwCeNbomjVsAlQAB2Gs"]
[Tue Jul 21 08:21:00.456799 2026] [security2:error] [pid 418108:tid 418250] [client 198.54.129.60:55726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9WHA0cxofL2J1zwYrBTwAAARQ"]
[Tue Jul 21 08:21:00.456871 2026] [security2:error] [pid 418108:tid 418250] [client 198.54.129.60:55726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9WHA0cxofL2J1zwYrBTwAAARQ"]
[Tue Jul 21 08:21:00.458045 2026] [security2:error] [pid 419508:tid 419686] [client 74.249.245.134:59805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/wp-good.php"] [unique_id "al9WHFcagwCeNbomjVsAlgAAAb8"]
[Tue Jul 21 08:21:00.652900 2026] [security2:error] [pid 419508:tid 419619] [remote 192.241.143.148:44872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arthromdcanada.online"] [uri "/wp-login.php"] [unique_id "al9WHFcagwCeNbomjVsAmAACC24"]
[Tue Jul 21 08:21:00.667843 2026] [security2:error] [pid 419508:tid 419654] [client 117.213.202.34:57981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WHFcagwCeNbomjVsAmQAAAZ8"]
[Tue Jul 21 08:21:00.668009 2026] [security2:error] [pid 419508:tid 419654] [client 117.213.202.34:57981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WHFcagwCeNbomjVsAmQAAAZ8"]
[Tue Jul 21 08:21:01.034472 2026] [security2:error] [pid 411857:tid 412069] [client 20.151.10.161:45904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/file48.php"] [unique_id "al9WHS7ynBpLeKYztQPc8AAAAFA"]
[Tue Jul 21 08:21:01.267901 2026] [security2:error] [pid 411857:tid 412066] [client 20.220.225.223:42119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/kq1.php"] [unique_id "al9WHS7ynBpLeKYztQPc9gAAAE0"]
[Tue Jul 21 08:21:01.387208 2026] [security2:error] [pid 411857:tid 411956] [remote 97.74.87.194:38798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9WHS7ynBpLeKYztQPc-AAARWA"]
[Tue Jul 21 08:21:01.450552 2026] [security2:error] [pid 419508:tid 419726] [client 87.116.180.198:13936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WHVcagwCeNbomjVsAoAAAAec"]
[Tue Jul 21 08:21:01.454869 2026] [security2:error] [pid 419508:tid 419726] [client 87.116.180.198:13936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WHVcagwCeNbomjVsAoAAAAec"]
[Tue Jul 21 08:21:01.738021 2026] [security2:error] [pid 411857:tid 412099] [client 195.49.128.211:65493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WHS7ynBpLeKYztQPdAAAAAG4"]
[Tue Jul 21 08:21:01.738165 2026] [security2:error] [pid 411857:tid 412099] [client 195.49.128.211:65493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WHS7ynBpLeKYztQPdAAAAAG4"]
[Tue Jul 21 08:21:01.902526 2026] [security2:error] [pid 419508:tid 419697] [client 74.249.245.134:61973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "webmail.roanalacerda.com.br"] [uri "/.info.php"] [unique_id "al9WHVcagwCeNbomjVsAqQAAAco"]
[Tue Jul 21 08:21:02.000428 2026] [security2:error] [pid 411857:tid 412103] [client 150.129.202.39:13146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WHi7ynBpLeKYztQPdBQAAAHI"]
[Tue Jul 21 08:21:02.000585 2026] [security2:error] [pid 411857:tid 412103] [client 150.129.202.39:13146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WHi7ynBpLeKYztQPdBQAAAHI"]
[Tue Jul 21 08:21:02.329450 2026] [security2:error] [pid 419508:tid 419640] [client 117.210.135.0:59674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WHlcagwCeNbomjVsArQAAAZE"]
[Tue Jul 21 08:21:02.329656 2026] [security2:error] [pid 419508:tid 419640] [client 117.210.135.0:59674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WHlcagwCeNbomjVsArQAAAZE"]
[Tue Jul 21 08:21:02.385580 2026] [security2:error] [pid 419508:tid 419665] [client 14.245.224.124:56041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WHlcagwCeNbomjVsArgAAAao"]
[Tue Jul 21 08:21:02.385706 2026] [security2:error] [pid 419508:tid 419665] [client 14.245.224.124:56041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WHlcagwCeNbomjVsArgAAAao"]
[Tue Jul 21 08:21:02.386272 2026] [security2:error] [pid 418108:tid 418185] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WHg0cxofL2J1zwYrBWwABU0o"]
[Tue Jul 21 08:21:02.386410 2026] [security2:error] [pid 418108:tid 418313] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WHg0cxofL2J1zwYrBWwABU0o"]
[Tue Jul 21 08:21:02.746080 2026] [security2:error] [pid 419508:tid 419696] [client 103.106.20.201:57614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WHlcagwCeNbomjVsAsQAAAck"]
[Tue Jul 21 08:21:02.746188 2026] [security2:error] [pid 419508:tid 419696] [client 103.106.20.201:57614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WHlcagwCeNbomjVsAsQAAAck"]
[Tue Jul 21 08:21:02.801459 2026] [security2:error] [pid 418108:tid 418361] [client 91.148.244.131:44124] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/"] [unique_id "al9WHg0cxofL2J1zwYrBXQAAAYM"]
[Tue Jul 21 08:21:02.802837 2026] [security2:error] [pid 411857:tid 412094] [client 91.148.244.131:44108] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/"] [unique_id "al9WHi7ynBpLeKYztQPdEgAAAGk"]
[Tue Jul 21 08:21:02.803242 2026] [security2:error] [pid 419508:tid 419691] [client 91.148.244.131:44094] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/"] [unique_id "al9WHlcagwCeNbomjVsAsgAAAcQ"]
[Tue Jul 21 08:21:02.852551 2026] [security2:error] [pid 419508:tid 419734] [client 198.54.129.60:34620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9WHlcagwCeNbomjVsAswAAAe8"]
[Tue Jul 21 08:21:02.852657 2026] [security2:error] [pid 419508:tid 419734] [client 198.54.129.60:34620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9WHlcagwCeNbomjVsAswAAAe8"]
[Tue Jul 21 08:21:03.173565 2026] [security2:error] [pid 411857:tid 411997] [client 20.226.60.151:60659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/sump1.php"] [unique_id "al9WHy7ynBpLeKYztQPdLQAAAAg"]
[Tue Jul 21 08:21:03.284653 2026] [security2:error] [pid 419508:tid 419722] [client 62.102.148.158:53202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9WH1cagwCeNbomjVsAtgAAAeM"]
[Tue Jul 21 08:21:03.284823 2026] [security2:error] [pid 419508:tid 419722] [client 62.102.148.158:53202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9WH1cagwCeNbomjVsAtgAAAeM"]
[Tue Jul 21 08:21:03.506094 2026] [security2:error] [pid 419508:tid 419710] [client 20.226.60.151:64122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/ss.php"] [unique_id "al9WH1cagwCeNbomjVsAuQAAAdc"]
[Tue Jul 21 08:21:03.556630 2026] [security2:error] [pid 411857:tid 411900] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WHy7ynBpLeKYztQPdMwAAMik"]
[Tue Jul 21 08:21:03.556881 2026] [security2:error] [pid 411857:tid 412039] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WHy7ynBpLeKYztQPdMwAAMik"]
[Tue Jul 21 08:21:03.783539 2026] [security2:error] [pid 419508:tid 419660] [client 91.148.244.131:35840] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9WH1cagwCeNbomjVsAuwAAAaU"]
[Tue Jul 21 08:21:03.783972 2026] [security2:error] [pid 419508:tid 419730] [client 91.148.244.131:35854] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/.env.production"] [unique_id "al9WH1cagwCeNbomjVsAvAAAAes"]
[Tue Jul 21 08:21:03.784943 2026] [security2:error] [pid 419508:tid 419733] [client 91.148.244.131:35832] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9WH1cagwCeNbomjVsAvQAAAe4"]
[Tue Jul 21 08:21:03.785186 2026] [security2:error] [pid 419508:tid 419705] [client 91.148.244.131:35866] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9WH1cagwCeNbomjVsAvgAAAdI"]
[Tue Jul 21 08:21:04.321167 2026] [security2:error] [pid 419508:tid 419612] [remote 97.74.93.24:55936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-login.php"] [unique_id "al9WIFcagwCeNbomjVsAwwABw2c"]
[Tue Jul 21 08:21:04.427599 2026] [security2:error] [pid 419508:tid 419748] [client 20.226.60.151:64050] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-admin/js/widget/"] [unique_id "al9WIFcagwCeNbomjVsAxwAAAfw"]
[Tue Jul 21 08:21:04.620129 2026] [access_compat:error] [pid 411857:tid 412023] [client 162.241.63.68:28088] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:21:04.728557 2026] [autoindex:error] [pid 419508:tid 419726] [client 205.210.31.57:60604] AH01276: Cannot serve directory /home3/creant42/diegocarvalhodesigner.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:21:04.758360 2026] [security2:error] [pid 419508:tid 419663] [client 91.148.244.131:35922] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/api/.env"] [unique_id "al9WIFcagwCeNbomjVsAyQAAAag"]
[Tue Jul 21 08:21:04.758360 2026] [security2:error] [pid 411857:tid 412095] [client 91.148.244.131:35910] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/.env"] [unique_id "al9WIC7ynBpLeKYztQPdRwAAAGo"]
[Tue Jul 21 08:21:04.759147 2026] [security2:error] [pid 419508:tid 419658] [client 91.148.244.131:35880] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/.git/HEAD"] [unique_id "al9WIFcagwCeNbomjVsAygAAAaM"]
[Tue Jul 21 08:21:04.759526 2026] [security2:error] [pid 419508:tid 419760] [client 91.148.244.131:35912] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9WIFcagwCeNbomjVsAywAAAgg"]
[Tue Jul 21 08:21:04.865458 2026] [security2:error] [pid 419508:tid 419715] [client 120.56.162.40:64478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WIFcagwCeNbomjVsAzgAAAdw"]
[Tue Jul 21 08:21:04.865599 2026] [security2:error] [pid 419508:tid 419715] [client 120.56.162.40:64478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WIFcagwCeNbomjVsAzgAAAdw"]
[Tue Jul 21 08:21:04.996732 2026] [security2:error] [pid 419508:tid 419685] [client 3.77.67.4:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9WIFcagwCeNbomjVsA0QABvnY"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:21:05.315943 2026] [security2:error] [pid 411857:tid 412050] [client 20.226.60.151:60556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/file5.php"] [unique_id "al9WIS7ynBpLeKYztQPdUwAAAD0"]
[Tue Jul 21 08:21:05.558882 2026] [security2:error] [pid 411857:tid 412053] [client 3.77.67.4:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9WIS7ynBpLeKYztQPdVgAAQF4"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:21:05.698793 2026] [security2:error] [pid 419508:tid 419615] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WIVcagwCeNbomjVsA3gAB7mo"]
[Tue Jul 21 08:21:05.698992 2026] [security2:error] [pid 419508:tid 419733] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WIVcagwCeNbomjVsA3gAB7mo"]
[Tue Jul 21 08:21:05.699970 2026] [security2:error] [pid 419508:tid 419746] [client 49.13.167.123:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9WIVcagwCeNbomjVsA3QAB-jk"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:21:05.731921 2026] [security2:error] [pid 419508:tid 419764] [client 91.148.244.131:35980] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/user_secrets.yml"] [unique_id "al9WIVcagwCeNbomjVsA3wAAAgw"]
[Tue Jul 21 08:21:05.733787 2026] [security2:error] [pid 418108:tid 418356] [client 91.148.244.131:35938] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9WIQ0cxofL2J1zwYrBZQAAAX4"]
[Tue Jul 21 08:21:05.734357 2026] [security2:error] [pid 419508:tid 419660] [client 91.148.244.131:35954] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/docker-compose.yml"] [unique_id "al9WIVcagwCeNbomjVsA4AAAAaU"]
[Tue Jul 21 08:21:05.736732 2026] [security2:error] [pid 418108:tid 418189] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WIQ0cxofL2J1zwYrBZgABgk4"]
[Tue Jul 21 08:21:05.736918 2026] [security2:error] [pid 418108:tid 418360] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WIQ0cxofL2J1zwYrBZgABgk4"]
[Tue Jul 21 08:21:05.739029 2026] [security2:error] [pid 419508:tid 419730] [client 91.148.244.131:35932] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/phpinfo.php"] [unique_id "al9WIVcagwCeNbomjVsA4QAAAes"]
[Tue Jul 21 08:21:05.829345 2026] [security2:error] [pid 419508:tid 419661] [client 65.21.113.253:38246] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WIVcagwCeNbomjVsA3AAAAaY"]
[Tue Jul 21 08:21:05.921097 2026] [security2:error] [pid 411857:tid 412047] [client 49.13.167.123:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9WIS7ynBpLeKYztQPdXQAAOic"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:21:05.947870 2026] [security2:error] [pid 411857:tid 412042] [client 20.226.60.151:64007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/min.php"] [unique_id "al9WIS7ynBpLeKYztQPdXgAAADU"]
[Tue Jul 21 08:21:06.005859 2026] [security2:error] [pid 419508:tid 419763] [client 20.226.60.151:64013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-includes/css/index.php"] [unique_id "al9WIlcagwCeNbomjVsA5QAAAgs"]
[Tue Jul 21 08:21:06.049335 2026] [security2:error] [pid 418108:tid 418302] [client 125.18.144.2:22695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WIg0cxofL2J1zwYrBagAAAUg"]
[Tue Jul 21 08:21:06.049464 2026] [security2:error] [pid 418108:tid 418302] [client 125.18.144.2:22695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WIg0cxofL2J1zwYrBagAAAUg"]
[Tue Jul 21 08:21:06.387219 2026] [security2:error] [pid 411857:tid 412026] [client 20.151.10.161:46072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/file6.php"] [unique_id "al9WIi7ynBpLeKYztQPdZgAAACU"]
[Tue Jul 21 08:21:06.455439 2026] [security2:error] [pid 419508:tid 419760] [client 20.151.10.161:2984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.gradiente.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9WIlcagwCeNbomjVsA7wAAAgg"]
[Tue Jul 21 08:21:06.468096 2026] [security2:error] [pid 419508:tid 419659] [client 20.226.60.151:60594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/0xD.php"] [unique_id "al9WIlcagwCeNbomjVsA8AAAAaQ"]
[Tue Jul 21 08:21:06.701602 2026] [security2:error] [pid 411857:tid 412102] [client 91.148.244.131:35994] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9WIi7ynBpLeKYztQPdbAAAAHE"]
[Tue Jul 21 08:21:06.704909 2026] [security2:error] [pid 411857:tid 412020] [client 91.148.244.131:36020] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/.npmrc"] [unique_id "al9WIi7ynBpLeKYztQPdbQAAAB8"]
[Tue Jul 21 08:21:06.705000 2026] [security2:error] [pid 411857:tid 412029] [client 91.148.244.131:35992] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/server.key"] [unique_id "al9WIi7ynBpLeKYztQPdbgAAACg"]
[Tue Jul 21 08:21:06.705712 2026] [security2:error] [pid 419508:tid 419679] [client 91.148.244.131:35990] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/config/production.json"] [unique_id "al9WIlcagwCeNbomjVsA8gAAAbg"]
[Tue Jul 21 08:21:06.732957 2026] [security2:error] [pid 419508:tid 419753] [client 20.151.10.161:2743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.gradiente.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9WIlcagwCeNbomjVsA8wAAAgE"]
[Tue Jul 21 08:21:06.790282 2026] [security2:error] [pid 411857:tid 412071] [client 74.7.228.54:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.academiausina.com.br"] [uri "/index.php"] [unique_id "al9WIS7ynBpLeKYztQPdVwAAUno"]
[Tue Jul 21 08:21:07.005884 2026] [security2:error] [pid 419508:tid 419644] [client 20.151.10.161:2725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.gradiente.com"] [uri "/images.php"] [unique_id "al9WI1cagwCeNbomjVsA-wAAAZU"]
[Tue Jul 21 08:21:07.062803 2026] [security2:error] [pid 418108:tid 418245] [client 115.134.11.136:51920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WIw0cxofL2J1zwYrBbgAAAQ8"]
[Tue Jul 21 08:21:07.063637 2026] [security2:error] [pid 418108:tid 418245] [client 115.134.11.136:51920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WIw0cxofL2J1zwYrBbgAAAQ8"]
[Tue Jul 21 08:21:07.286350 2026] [security2:error] [pid 418108:tid 418310] [client 20.151.10.161:2732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.gradiente.com"] [uri "/for.php"] [unique_id "al9WIw0cxofL2J1zwYrBbwAAAVA"]
[Tue Jul 21 08:21:07.308886 2026] [security2:error] [pid 418108:tid 418269] [client 38.100.221.102:18932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WIw0cxofL2J1zwYrBcAAAASc"]
[Tue Jul 21 08:21:07.309088 2026] [security2:error] [pid 418108:tid 418269] [client 38.100.221.102:18932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WIw0cxofL2J1zwYrBcAAAASc"]
[Tue Jul 21 08:21:07.348266 2026] [security2:error] [pid 418108:tid 418355] [client 187.125.243.197:64888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WIw0cxofL2J1zwYrBcQAAAX0"]
[Tue Jul 21 08:21:07.348551 2026] [security2:error] [pid 418108:tid 418355] [client 187.125.243.197:64888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WIw0cxofL2J1zwYrBcQAAAX0"]
[Tue Jul 21 08:21:07.589727 2026] [security2:error] [pid 419508:tid 419765] [client 20.151.10.161:2693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.gradiente.com"] [uri "/2larp.php"] [unique_id "al9WI1cagwCeNbomjVsBAQAAAg0"]
[Tue Jul 21 08:21:07.674134 2026] [security2:error] [pid 419508:tid 419645] [client 91.148.244.131:36038] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/config.xml"] [unique_id "al9WI1cagwCeNbomjVsBAgAAAZY"]
[Tue Jul 21 08:21:07.675067 2026] [security2:error] [pid 419508:tid 419716] [client 91.148.244.131:36088] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/secrets.json"] [unique_id "al9WI1cagwCeNbomjVsBAwAAAd0"]
[Tue Jul 21 08:21:07.675067 2026] [security2:error] [pid 418108:tid 418363] [client 91.148.244.131:36062] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/.bash_history"] [unique_id "al9WIw0cxofL2J1zwYrBdQAAAYU"]
[Tue Jul 21 08:21:07.676181 2026] [security2:error] [pid 419508:tid 419700] [client 91.148.244.131:36076] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/config.php"] [unique_id "al9WI1cagwCeNbomjVsBBAAAAc0"]
[Tue Jul 21 08:21:07.874733 2026] [security2:error] [pid 418108:tid 418342] [client 20.151.10.161:2734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.gradiente.com"] [uri "/adminner.php"] [unique_id "al9WIw0cxofL2J1zwYrBdgAAAXA"]
[Tue Jul 21 08:21:07.877329 2026] [security2:error] [pid 419508:tid 419710] [client 91.148.244.131:36046] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/dump.sql"] [unique_id "al9WI1cagwCeNbomjVsBCwAAAdc"]
[Tue Jul 21 08:21:07.878917 2026] [security2:error] [pid 419508:tid 419750] [client 91.148.244.131:36094] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/database.sql"] [unique_id "al9WI1cagwCeNbomjVsBDAAAAf4"]
[Tue Jul 21 08:21:07.879111 2026] [security2:error] [pid 419508:tid 419722] [client 91.148.244.131:36078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/backup.sql"] [unique_id "al9WI1cagwCeNbomjVsBDQAAAeM"]
[Tue Jul 21 08:21:07.980276 2026] [security2:error] [pid 419508:tid 419686] [client 20.226.60.151:64034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/jj.php"] [unique_id "al9WI1cagwCeNbomjVsBDwAAAb8"]
[Tue Jul 21 08:21:08.152751 2026] [security2:error] [pid 419508:tid 419754] [client 20.151.10.161:2946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.gradiente.com"] [uri "/82.php"] [unique_id "al9WJFcagwCeNbomjVsBEAAAAgI"]
[Tue Jul 21 08:21:08.200380 2026] [security2:error] [pid 411857:tid 412099] [client 20.226.60.151:59268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9WJC7ynBpLeKYztQPdhwAAAG4"]
[Tue Jul 21 08:21:08.429438 2026] [security2:error] [pid 419508:tid 419760] [client 20.151.10.161:2972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "smtp.gradiente.com"] [uri "/kir.php"] [unique_id "al9WJFcagwCeNbomjVsBFAAAAgg"]
[Tue Jul 21 08:21:08.525084 2026] [security2:error] [pid 419508:tid 419753] [client 74.249.245.134:56436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/item.php"] [unique_id "al9WJFcagwCeNbomjVsBGAAAAgE"]
[Tue Jul 21 08:21:08.655180 2026] [security2:error] [pid 411857:tid 412055] [client 91.148.244.131:36102] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/database_backup.sql"] [unique_id "al9WJC7ynBpLeKYztQPdkQAAAEI"]
[Tue Jul 21 08:21:08.655787 2026] [security2:error] [pid 419508:tid 419659] [client 91.148.244.131:36112] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/backup.zip"] [unique_id "al9WJFcagwCeNbomjVsBGQAAAaQ"]
[Tue Jul 21 08:21:08.655969 2026] [security2:error] [pid 411857:tid 412103] [client 91.148.244.131:36126] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/actuator/heapdump"] [unique_id "al9WJC7ynBpLeKYztQPdkAAAAHI"]
[Tue Jul 21 08:21:08.657142 2026] [security2:error] [pid 419508:tid 419697] [client 91.148.244.131:36134] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/wp-config.php"] [unique_id "al9WJFcagwCeNbomjVsBGgAAAco"]
[Tue Jul 21 08:21:08.850138 2026] [security2:error] [pid 419508:tid 419533] [remote 216.73.216.184:46703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9WJFcagwCeNbomjVsBHAABkxg"]
[Tue Jul 21 08:21:08.857333 2026] [security2:error] [pid 419508:tid 419715] [client 91.148.244.131:36130] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/.svn/wc.db"] [unique_id "al9WJFcagwCeNbomjVsBHQAAAdw"]
[Tue Jul 21 08:21:08.859452 2026] [security2:error] [pid 419508:tid 419656] [client 91.148.244.131:36116] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/backup.tar.gz"] [unique_id "al9WJFcagwCeNbomjVsBHgAAAaE"]
[Tue Jul 21 08:21:08.859452 2026] [security2:error] [pid 419508:tid 419723] [client 91.148.244.131:36142] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9WJFcagwCeNbomjVsBHwAAAeQ"]
[Tue Jul 21 08:21:08.892005 2026] [security2:error] [pid 419508:tid 419728] [client 20.226.60.151:60599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/fnstall.php"] [unique_id "al9WJFcagwCeNbomjVsBIQAAAek"]
[Tue Jul 21 08:21:09.532110 2026] [security2:error] [pid 411857:tid 412081] [client 185.8.106.219:14790] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "siteecommerceshop.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9WJS7ynBpLeKYztQPdogAAAFw"]
[Tue Jul 21 08:21:09.638447 2026] [security2:error] [pid 419508:tid 419706] [client 91.148.244.131:36176] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "osantotchay.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9WJVcagwCeNbomjVsBJgAAAdM"]
[Tue Jul 21 08:21:09.904452 2026] [security2:error] [pid 411857:tid 412037] [client 20.226.60.151:59098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9WJS7ynBpLeKYztQPdrAAAADA"]
[Tue Jul 21 08:21:10.107103 2026] [security2:error] [pid 419508:tid 419635] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WJlcagwCeNbomjVsBLwAB134"]
[Tue Jul 21 08:21:10.107321 2026] [security2:error] [pid 419508:tid 419710] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WJlcagwCeNbomjVsBLwAB134"]
[Tue Jul 21 08:21:10.125926 2026] [security2:error] [pid 411857:tid 412003] [client 2.57.168.11:20037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.168.57.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9WJS7ynBpLeKYztQPdrgAAAA4"]
[Tue Jul 21 08:21:10.130654 2026] [security2:error] [pid 411857:tid 412034] [client 152.59.34.51:59105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WJi7ynBpLeKYztQPdsQAAAC0"]
[Tue Jul 21 08:21:10.130794 2026] [security2:error] [pid 411857:tid 412034] [client 152.59.34.51:59105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WJi7ynBpLeKYztQPdsQAAAC0"]
[Tue Jul 21 08:21:10.185887 2026] [security2:error] [pid 419508:tid 419689] [client 223.181.60.88:7195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WJlcagwCeNbomjVsBMQAAAcI"]
[Tue Jul 21 08:21:10.186778 2026] [security2:error] [pid 419508:tid 419689] [client 223.181.60.88:7195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WJlcagwCeNbomjVsBMQAAAcI"]
[Tue Jul 21 08:21:10.258138 2026] [security2:error] [pid 419508:tid 419681] [client 185.8.106.219:39804] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "siteecommerceshop.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9WJlcagwCeNbomjVsBMwAAAbo"]
[Tue Jul 21 08:21:10.522863 2026] [security2:error] [pid 419508:tid 419660] [client 65.21.113.253:38246] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WJlcagwCeNbomjVsBLAAAAaU"]
[Tue Jul 21 08:21:10.530360 2026] [security2:error] [pid 419508:tid 419693] [client 20.226.60.151:64012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al9WJlcagwCeNbomjVsBOAAAAcY"]
[Tue Jul 21 08:21:10.727514 2026] [security2:error] [pid 411857:tid 412097] [client 20.226.60.151:60666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/acp.php"] [unique_id "al9WJi7ynBpLeKYztQPdvQAAAGw"]
[Tue Jul 21 08:21:10.729706 2026] [security2:error] [pid 419508:tid 419690] [client 20.151.10.161:50693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9WJlcagwCeNbomjVsBOgAAAcM"]
[Tue Jul 21 08:21:10.749976 2026] [security2:error] [pid 411857:tid 412006] [client 103.151.46.103:61793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WJi7ynBpLeKYztQPdvgAAABE"]
[Tue Jul 21 08:21:10.750091 2026] [security2:error] [pid 411857:tid 412006] [client 103.151.46.103:61793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WJi7ynBpLeKYztQPdvgAAABE"]
[Tue Jul 21 08:21:11.109424 2026] [security2:error] [pid 419508:tid 419739] [client 20.151.10.161:50858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9WJ1cagwCeNbomjVsBQQAAAfQ"]
[Tue Jul 21 08:21:11.119201 2026] [security2:error] [pid 419508:tid 419723] [client 62.102.148.158:57174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9WJ1cagwCeNbomjVsBQgAAAeQ"]
[Tue Jul 21 08:21:11.119291 2026] [security2:error] [pid 419508:tid 419723] [client 62.102.148.158:57174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9WJ1cagwCeNbomjVsBQgAAAeQ"]
[Tue Jul 21 08:21:11.123854 2026] [security2:error] [pid 419508:tid 419668] [client 65.21.113.253:38246] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WJlcagwCeNbomjVsBPQAAAa0"]
[Tue Jul 21 08:21:11.323958 2026] [security2:error] [pid 419508:tid 419726] [client 117.213.202.34:58511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WJ1cagwCeNbomjVsBRAAAAec"]
[Tue Jul 21 08:21:11.324253 2026] [security2:error] [pid 419508:tid 419726] [client 117.213.202.34:58511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WJ1cagwCeNbomjVsBRAAAAec"]
[Tue Jul 21 08:21:11.672629 2026] [security2:error] [pid 411857:tid 411990] [client 20.151.10.161:50714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/media.php"] [unique_id "al9WJy7ynBpLeKYztQPd1wAAAAE"]
[Tue Jul 21 08:21:12.020740 2026] [security2:error] [pid 411857:tid 412111] [client 185.8.106.219:47936] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.siteecommerceshop.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9WKC7ynBpLeKYztQPd3AAAAHo"]
[Tue Jul 21 08:21:12.118777 2026] [security2:error] [pid 419508:tid 419675] [client 87.116.180.198:27211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WKFcagwCeNbomjVsBVQAAAbQ"]
[Tue Jul 21 08:21:12.122259 2026] [security2:error] [pid 419508:tid 419675] [client 87.116.180.198:27211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WKFcagwCeNbomjVsBVQAAAbQ"]
[Tue Jul 21 08:21:12.158597 2026] [security2:error] [pid 419508:tid 419686] [client 20.151.10.161:50877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/images.php"] [unique_id "al9WKFcagwCeNbomjVsBVgAAAb8"]
[Tue Jul 21 08:21:12.390927 2026] [security2:error] [pid 411857:tid 412014] [client 195.49.128.211:49696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WKC7ynBpLeKYztQPd5AAAABk"]
[Tue Jul 21 08:21:12.391030 2026] [security2:error] [pid 411857:tid 412014] [client 195.49.128.211:49696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WKC7ynBpLeKYztQPd5AAAABk"]
[Tue Jul 21 08:21:12.465239 2026] [security2:error] [pid 411857:tid 412043] [client 14.245.224.124:56488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WKC7ynBpLeKYztQPd5gAAADY"]
[Tue Jul 21 08:21:12.465362 2026] [security2:error] [pid 411857:tid 412043] [client 14.245.224.124:56488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WKC7ynBpLeKYztQPd5gAAADY"]
[Tue Jul 21 08:21:12.537298 2026] [security2:error] [pid 419508:tid 419727] [client 150.129.202.39:64729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WKFcagwCeNbomjVsBWwAAAeg"]
[Tue Jul 21 08:21:12.537464 2026] [security2:error] [pid 419508:tid 419727] [client 150.129.202.39:64729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WKFcagwCeNbomjVsBWwAAAeg"]
[Tue Jul 21 08:21:12.586546 2026] [security2:error] [pid 419508:tid 419710] [client 65.21.113.253:38246] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WKFcagwCeNbomjVsBVAAAAdc"]
[Tue Jul 21 08:21:12.673608 2026] [security2:error] [pid 411857:tid 412050] [client 20.226.60.151:60572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/mosty.php"] [unique_id "al9WKC7ynBpLeKYztQPd6QAAAD0"]
[Tue Jul 21 08:21:12.680885 2026] [security2:error] [pid 411857:tid 412086] [client 20.151.10.161:46061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/a2.php"] [unique_id "al9WKC7ynBpLeKYztQPd6gAAAGE"]
[Tue Jul 21 08:21:12.690234 2026] [security2:error] [pid 419508:tid 419682] [client 185.8.106.219:47946] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "siteecommerceshop.com"] [uri "/"] [unique_id "al9WKFcagwCeNbomjVsBXQAAAbs"]
[Tue Jul 21 08:21:12.753899 2026] [security2:error] [pid 419508:tid 419755] [client 20.151.10.161:50870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/adminner.php"] [unique_id "al9WKFcagwCeNbomjVsBXwAAAgM"]
[Tue Jul 21 08:21:12.802294 2026] [security2:error] [pid 419508:tid 419751] [client 117.210.135.0:60325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WKFcagwCeNbomjVsBYwAAAf8"]
[Tue Jul 21 08:21:12.802372 2026] [security2:error] [pid 419508:tid 419751] [client 117.210.135.0:60325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WKFcagwCeNbomjVsBYwAAAf8"]
[Tue Jul 21 08:21:12.881348 2026] [security2:error] [pid 419508:tid 419545] [remote 216.73.216.184:46703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemape.xml"] [unique_id "al9WKFcagwCeNbomjVsBZAAByiQ"]
[Tue Jul 21 08:21:13.029630 2026] [security2:error] [pid 411857:tid 412097] [client 20.226.60.151:59326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/txets.php"] [unique_id "al9WKS7ynBpLeKYztQPd7gAAAGw"]
[Tue Jul 21 08:21:13.036573 2026] [security2:error] [pid 419508:tid 419536] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WKVcagwCeNbomjVsBZgABohs"]
[Tue Jul 21 08:21:13.036707 2026] [security2:error] [pid 419508:tid 419657] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WKVcagwCeNbomjVsBZgABohs"]
[Tue Jul 21 08:21:13.200395 2026] [security2:error] [pid 411857:tid 412017] [client 20.151.10.161:50689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/admin.php"] [unique_id "al9WKS7ynBpLeKYztQPd8wAAABw"]
[Tue Jul 21 08:21:13.344106 2026] [security2:error] [pid 419508:tid 419726] [client 20.226.60.151:64110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/dex.php"] [unique_id "al9WKVcagwCeNbomjVsBaQAAAec"]
[Tue Jul 21 08:21:13.477972 2026] [security2:error] [pid 411857:tid 412053] [client 103.106.20.201:58369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WKS7ynBpLeKYztQPd-AAAAEA"]
[Tue Jul 21 08:21:13.478066 2026] [security2:error] [pid 411857:tid 412053] [client 103.106.20.201:58369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WKS7ynBpLeKYztQPd-AAAAEA"]
[Tue Jul 21 08:21:13.547569 2026] [security2:error] [pid 411857:tid 412022] [client 20.151.10.161:50719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/k.php"] [unique_id "al9WKS7ynBpLeKYztQPd-gAAACE"]
[Tue Jul 21 08:21:13.573417 2026] [core:alert] [pid 419508:tid 419638] [client 57.141.18.98:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:21:13.844431 2026] [security2:error] [pid 411857:tid 412020] [client 20.151.10.161:50694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/x.php"] [unique_id "al9WKS7ynBpLeKYztQPd_QAAAB8"]
[Tue Jul 21 08:21:13.846505 2026] [security2:error] [pid 419508:tid 419720] [client 20.226.60.151:64093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9WKVcagwCeNbomjVsBcgAAAeE"]
[Tue Jul 21 08:21:13.894769 2026] [security2:error] [pid 419508:tid 419651] [client 20.226.60.151:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/xpwer1.php"] [unique_id "al9WKVcagwCeNbomjVsBeAAAAZw"]
[Tue Jul 21 08:21:14.037727 2026] [security2:error] [pid 419508:tid 419574] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WKlcagwCeNbomjVsBegAB60E"]
[Tue Jul 21 08:21:14.037959 2026] [security2:error] [pid 419508:tid 419730] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WKlcagwCeNbomjVsBegAB60E"]
[Tue Jul 21 08:21:14.170801 2026] [security2:error] [pid 419508:tid 419711] [client 20.151.10.161:50871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wss.php"] [unique_id "al9WKlcagwCeNbomjVsBewAAAdg"]
[Tue Jul 21 08:21:14.384706 2026] [security2:error] [pid 419508:tid 419564] [remote 216.73.216.184:46703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9WKlcagwCeNbomjVsBfwAB4Dc"]
[Tue Jul 21 08:21:14.467250 2026] [security2:error] [pid 411857:tid 412101] [client 20.226.60.151:60568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/6.php"] [unique_id "al9WKi7ynBpLeKYztQPeBQAAAHA"]
[Tue Jul 21 08:21:14.485275 2026] [security2:error] [pid 419508:tid 419677] [client 65.21.113.253:38246] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WKlcagwCeNbomjVsBeQAAAbY"]
[Tue Jul 21 08:21:14.530424 2026] [security2:error] [pid 411857:tid 412044] [client 14.97.58.74:41483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WKi7ynBpLeKYztQPeBgAAADc"]
[Tue Jul 21 08:21:14.530537 2026] [security2:error] [pid 411857:tid 412044] [client 14.97.58.74:41483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WKi7ynBpLeKYztQPeBgAAADc"]
[Tue Jul 21 08:21:14.564473 2026] [security2:error] [pid 411857:tid 412081] [client 20.151.10.161:50744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/ty.php"] [unique_id "al9WKi7ynBpLeKYztQPeCAAAAFw"]
[Tue Jul 21 08:21:14.643689 2026] [security2:error] [pid 411857:tid 412100] [client 20.226.60.151:64011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/flox.php"] [unique_id "al9WKi7ynBpLeKYztQPeCQAAAG8"]
[Tue Jul 21 08:21:14.976797 2026] [security2:error] [pid 419508:tid 419753] [client 20.151.10.161:50846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/155.php"] [unique_id "al9WKlcagwCeNbomjVsBhQAAAgE"]
[Tue Jul 21 08:21:15.074383 2026] [security2:error] [pid 411857:tid 412091] [client 86.106.84.166:47848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9WKy7ynBpLeKYztQPeFQAAAGY"]
[Tue Jul 21 08:21:15.074488 2026] [security2:error] [pid 411857:tid 412091] [client 86.106.84.166:47848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9WKy7ynBpLeKYztQPeFQAAAGY"]
[Tue Jul 21 08:21:15.349486 2026] [security2:error] [pid 419508:tid 419736] [client 61.1.167.83:49204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WK1cagwCeNbomjVsBiAAAAfE"]
[Tue Jul 21 08:21:15.349715 2026] [security2:error] [pid 419508:tid 419736] [client 61.1.167.83:49204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WK1cagwCeNbomjVsBiAAAAfE"]
[Tue Jul 21 08:21:15.543791 2026] [security2:error] [pid 419508:tid 419682] [client 120.56.162.40:64981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WK1cagwCeNbomjVsBiwAAAbs"]
[Tue Jul 21 08:21:15.543975 2026] [security2:error] [pid 419508:tid 419682] [client 120.56.162.40:64981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WK1cagwCeNbomjVsBiwAAAbs"]
[Tue Jul 21 08:21:15.558113 2026] [security2:error] [pid 419508:tid 419723] [client 20.226.60.151:59306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/popo.php"] [unique_id "al9WK1cagwCeNbomjVsBjAAAAeQ"]
[Tue Jul 21 08:21:15.743396 2026] [security2:error] [pid 419508:tid 419642] [client 20.151.10.161:50700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/ops.php"] [unique_id "al9WK1cagwCeNbomjVsBjQAAAZM"]
[Tue Jul 21 08:21:15.839902 2026] [security2:error] [pid 411857:tid 411989] [client 202.179.75.202:38248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WKi7ynBpLeKYztQPeCgAAAAA"]
[Tue Jul 21 08:21:15.840028 2026] [security2:error] [pid 411857:tid 411989] [client 202.179.75.202:38248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WKi7ynBpLeKYztQPeCgAAAAA"]
[Tue Jul 21 08:21:16.163769 2026] [security2:error] [pid 419508:tid 419680] [client 20.151.10.161:50839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/ingfo.php"] [unique_id "al9WLFcagwCeNbomjVsBmAAAAbk"]
[Tue Jul 21 08:21:16.219285 2026] [security2:error] [pid 419508:tid 419577] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WLFcagwCeNbomjVsBnAABkEQ"]
[Tue Jul 21 08:21:16.219431 2026] [security2:error] [pid 419508:tid 419639] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WLFcagwCeNbomjVsBnAABkEQ"]
[Tue Jul 21 08:21:16.504003 2026] [security2:error] [pid 411857:tid 411894] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WLC7ynBpLeKYztQPeRAAAHyM"]
[Tue Jul 21 08:21:16.504140 2026] [security2:error] [pid 411857:tid 412020] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WLC7ynBpLeKYztQPeRAAAHyM"]
[Tue Jul 21 08:21:16.517149 2026] [security2:error] [pid 419508:tid 419706] [client 65.21.113.253:38246] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WLFcagwCeNbomjVsBlAAAAdM"]
[Tue Jul 21 08:21:16.517326 2026] [security2:error] [pid 419508:tid 419658] [client 20.226.60.151:59073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/yas.php"] [unique_id "al9WLFcagwCeNbomjVsBoAAAAaM"]
[Tue Jul 21 08:21:16.719080 2026] [security2:error] [pid 411857:tid 411927] [remote 51.79.215.219:54318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.215.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-login.php"] [unique_id "al9WKy7ynBpLeKYztQPeIwAAIkQ"]
[Tue Jul 21 08:21:17.007639 2026] [security2:error] [pid 411857:tid 412021] [client 20.151.10.161:45928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/file15.php"] [unique_id "al9WLS7ynBpLeKYztQPeUgAAACA"]
[Tue Jul 21 08:21:17.022614 2026] [security2:error] [pid 411857:tid 412030] [client 20.151.10.161:50712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/error_log.php"] [unique_id "al9WLS7ynBpLeKYztQPeUwAAACk"]
[Tue Jul 21 08:21:17.219553 2026] [security2:error] [pid 411857:tid 412027] [client 20.226.60.151:59301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9WLS7ynBpLeKYztQPeVQAAACY"]
[Tue Jul 21 08:21:17.381581 2026] [security2:error] [pid 411857:tid 411990] [client 198.54.129.60:48890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9WLS7ynBpLeKYztQPeVwAAAAE"]
[Tue Jul 21 08:21:17.381712 2026] [security2:error] [pid 411857:tid 411990] [client 198.54.129.60:48890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9WLS7ynBpLeKYztQPeVwAAAAE"]
[Tue Jul 21 08:21:17.537288 2026] [security2:error] [pid 419508:tid 419751] [client 162.219.176.3:35672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9WLVcagwCeNbomjVsBrQAAAf8"]
[Tue Jul 21 08:21:17.537368 2026] [security2:error] [pid 419508:tid 419751] [client 162.219.176.3:35672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9WLVcagwCeNbomjVsBrQAAAf8"]
[Tue Jul 21 08:21:17.634689 2026] [security2:error] [pid 419508:tid 419669] [client 20.151.10.161:50868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/ok.php"] [unique_id "al9WLVcagwCeNbomjVsBrwAAAa4"]
[Tue Jul 21 08:21:17.784147 2026] [security2:error] [pid 419508:tid 419736] [client 187.125.243.197:65390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WLVcagwCeNbomjVsBsQAAAfE"]
[Tue Jul 21 08:21:17.784873 2026] [security2:error] [pid 419508:tid 419736] [client 187.125.243.197:65390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WLVcagwCeNbomjVsBsQAAAfE"]
[Tue Jul 21 08:21:17.816809 2026] [security2:error] [pid 411857:tid 411991] [client 74.249.245.134:59777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/albin.php"] [unique_id "al9WLS7ynBpLeKYztQPeXQAAAAI"]
[Tue Jul 21 08:21:17.857787 2026] [security2:error] [pid 419508:tid 419656] [client 20.220.225.223:43422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/wicked.php"] [unique_id "al9WLVcagwCeNbomjVsBsgAAAaE"]
[Tue Jul 21 08:21:17.867018 2026] [security2:error] [pid 411857:tid 412054] [client 38.100.221.102:17590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WLS7ynBpLeKYztQPeXgAAAEE"]
[Tue Jul 21 08:21:17.867131 2026] [security2:error] [pid 411857:tid 412054] [client 38.100.221.102:17590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WLS7ynBpLeKYztQPeXgAAAEE"]
[Tue Jul 21 08:21:17.961629 2026] [security2:error] [pid 419508:tid 419638] [client 20.220.225.223:12582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9WLVcagwCeNbomjVsB3QAAAY8"]
[Tue Jul 21 08:21:18.305464 2026] [security2:error] [pid 411857:tid 412085] [client 115.134.11.136:52373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WLi7ynBpLeKYztQPeZAAAAGA"]
[Tue Jul 21 08:21:18.305761 2026] [security2:error] [pid 411857:tid 412085] [client 115.134.11.136:52373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WLi7ynBpLeKYztQPeZAAAAGA"]
[Tue Jul 21 08:21:18.487412 2026] [security2:error] [pid 411857:tid 412024] [client 20.151.10.161:50829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/mac.php"] [unique_id "al9WLi7ynBpLeKYztQPeZgAAACM"]
[Tue Jul 21 08:21:18.519707 2026] [security2:error] [pid 411857:tid 412001] [client 20.226.60.151:60563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9WLi7ynBpLeKYztQPeZwAAAAw"]
[Tue Jul 21 08:21:18.782095 2026] [security2:error] [pid 418108:tid 418313] [client 62.102.148.158:40036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9WLg0cxofL2J1zwYrBhwAAAVM"]
[Tue Jul 21 08:21:18.782201 2026] [security2:error] [pid 418108:tid 418313] [client 62.102.148.158:40036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9WLg0cxofL2J1zwYrBhwAAAVM"]
[Tue Jul 21 08:21:18.973554 2026] [security2:error] [pid 419508:tid 419658] [client 65.21.113.253:38246] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WLlcagwCeNbomjVsB9AAAAaM"]
[Tue Jul 21 08:21:19.108177 2026] [security2:error] [pid 411857:tid 412011] [client 20.220.225.223:4721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/edit.php"] [unique_id "al9WLy7ynBpLeKYztQPedAAAABY"]
[Tue Jul 21 08:21:19.305079 2026] [security2:error] [pid 419508:tid 419660] [client 20.151.10.161:50843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wefile.php"] [unique_id "al9WL1cagwCeNbomjVsCAAAAAaU"]
[Tue Jul 21 08:21:19.332228 2026] [security2:error] [pid 419508:tid 419734] [client 20.226.60.151:59282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/file61.php"] [unique_id "al9WL1cagwCeNbomjVsCAQAAAe8"]
[Tue Jul 21 08:21:19.697709 2026] [security2:error] [pid 411857:tid 412061] [client 20.151.10.161:50863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9WLy7ynBpLeKYztQPefgAAAEg"]
[Tue Jul 21 08:21:19.872599 2026] [security2:error] [pid 419508:tid 419730] [client 223.181.60.88:22898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WL1cagwCeNbomjVsCCQAAAes"]
[Tue Jul 21 08:21:19.872747 2026] [security2:error] [pid 419508:tid 419730] [client 223.181.60.88:22898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WL1cagwCeNbomjVsCCQAAAes"]
[Tue Jul 21 08:21:20.168840 2026] [security2:error] [pid 419508:tid 419607] [remote 185.27.20.235:54298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.20.27.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compressoresra.com.br"] [uri "/wp-login.php"] [unique_id "al9WMFcagwCeNbomjVsCDAAB3WI"]
[Tue Jul 21 08:21:20.356068 2026] [security2:error] [pid 419508:tid 419736] [client 20.226.60.151:59073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/albin.php"] [unique_id "al9WMFcagwCeNbomjVsCDQAAAfE"]
[Tue Jul 21 08:21:20.468430 2026] [security2:error] [pid 411857:tid 412066] [client 20.151.10.161:45897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/jp.php"] [unique_id "al9WMC7ynBpLeKYztQPejwAAAE0"]
[Tue Jul 21 08:21:20.674457 2026] [security2:error] [pid 419508:tid 419742] [client 20.151.10.161:50723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9WMFcagwCeNbomjVsCFAAAAfc"]
[Tue Jul 21 08:21:20.725952 2026] [security2:error] [pid 411857:tid 419458] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WMC7ynBpLeKYztQPelQAADow"]
[Tue Jul 21 08:21:20.726056 2026] [security2:error] [pid 411857:tid 412003] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WMC7ynBpLeKYztQPelQAADow"]
[Tue Jul 21 08:21:20.855824 2026] [security2:error] [pid 411857:tid 411965] [remote 104.244.79.40:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.79.244.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/wp-login.php"] [unique_id "al9WMC7ynBpLeKYztQPelwAAXWk"]
[Tue Jul 21 08:21:20.897692 2026] [security2:error] [pid 419508:tid 419650] [client 74.249.245.134:50288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/alfa.php"] [unique_id "al9WMFcagwCeNbomjVsCFQAAAZs"]
[Tue Jul 21 08:21:20.988535 2026] [security2:error] [pid 411857:tid 412024] [client 198.54.129.60:57316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9WMC7ynBpLeKYztQPemwAAACM"]
[Tue Jul 21 08:21:20.988644 2026] [security2:error] [pid 411857:tid 412024] [client 198.54.129.60:57316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9WMC7ynBpLeKYztQPemwAAACM"]
[Tue Jul 21 08:21:21.128019 2026] [security2:error] [pid 411857:tid 412002] [client 20.226.60.151:64043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/cilus.php"] [unique_id "al9WMS7ynBpLeKYztQPenQAAAA0"]
[Tue Jul 21 08:21:21.262421 2026] [security2:error] [pid 411857:tid 412050] [client 20.226.60.151:64094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/water.php"] [unique_id "al9WMS7ynBpLeKYztQPeoAAAAD0"]
[Tue Jul 21 08:21:21.528933 2026] [security2:error] [pid 419508:tid 419700] [client 103.151.46.103:62301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WMVcagwCeNbomjVsCHQAAAc0"]
[Tue Jul 21 08:21:21.529076 2026] [security2:error] [pid 419508:tid 419700] [client 103.151.46.103:62301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WMVcagwCeNbomjVsCHQAAAc0"]
[Tue Jul 21 08:21:21.748288 2026] [security2:error] [pid 418108:tid 418264] [client 202.179.75.202:38260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WMQ0cxofL2J1zwYrBkAAAASI"]
[Tue Jul 21 08:21:21.749168 2026] [security2:error] [pid 418108:tid 418264] [client 202.179.75.202:38260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WMQ0cxofL2J1zwYrBkAAAASI"]
[Tue Jul 21 08:21:21.798152 2026] [security2:error] [pid 411857:tid 412011] [client 20.151.10.161:50869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/like.php"] [unique_id "al9WMS7ynBpLeKYztQPeqAAAABY"]
[Tue Jul 21 08:21:21.842938 2026] [security2:error] [pid 411857:tid 412080] [client 117.213.202.34:59038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WMS7ynBpLeKYztQPeqQAAAFs"]
[Tue Jul 21 08:21:21.843046 2026] [security2:error] [pid 411857:tid 412080] [client 117.213.202.34:59038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WMS7ynBpLeKYztQPeqQAAAFs"]
[Tue Jul 21 08:21:21.898547 2026] [security2:error] [pid 411857:tid 412089] [client 20.226.60.151:64088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/nano.php"] [unique_id "al9WMS7ynBpLeKYztQPeqgAAAGQ"]
[Tue Jul 21 08:21:22.470846 2026] [security2:error] [pid 411857:tid 412105] [client 20.226.60.151:60575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/qqqa.php"] [unique_id "al9WMi7ynBpLeKYztQPetwAAAHQ"]
[Tue Jul 21 08:21:22.477010 2026] [security2:error] [pid 411857:tid 412044] [client 20.151.10.161:50875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/.well-known/about.php"] [unique_id "al9WMi7ynBpLeKYztQPeuAAAADc"]
[Tue Jul 21 08:21:22.697151 2026] [security2:error] [pid 411857:tid 412048] [client 20.151.10.161:45965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/f35.php"] [unique_id "al9WMi7ynBpLeKYztQPevAAAADs"]
[Tue Jul 21 08:21:22.746583 2026] [security2:error] [pid 419508:tid 419655] [client 87.116.180.198:13884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WMlcagwCeNbomjVsCLwAAAaA"]
[Tue Jul 21 08:21:22.746675 2026] [security2:error] [pid 419508:tid 419655] [client 87.116.180.198:13884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WMlcagwCeNbomjVsCLwAAAaA"]
[Tue Jul 21 08:21:22.995520 2026] [security2:error] [pid 419508:tid 419727] [client 14.245.224.124:57229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WMlcagwCeNbomjVsCOAAAAeg"]
[Tue Jul 21 08:21:22.995624 2026] [security2:error] [pid 419508:tid 419727] [client 14.245.224.124:57229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WMlcagwCeNbomjVsCOAAAAeg"]
[Tue Jul 21 08:21:23.079253 2026] [security2:error] [pid 411857:tid 412060] [client 195.49.128.211:50295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WMy7ynBpLeKYztQPewwAAAEc"]
[Tue Jul 21 08:21:23.079378 2026] [security2:error] [pid 411857:tid 412060] [client 195.49.128.211:50295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WMy7ynBpLeKYztQPewwAAAEc"]
[Tue Jul 21 08:21:23.081187 2026] [security2:error] [pid 411857:tid 412107] [client 150.129.202.39:65186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WMy7ynBpLeKYztQPexAAAAHY"]
[Tue Jul 21 08:21:23.081313 2026] [security2:error] [pid 411857:tid 412107] [client 150.129.202.39:65186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WMy7ynBpLeKYztQPexAAAAHY"]
[Tue Jul 21 08:21:23.091626 2026] [security2:error] [pid 411857:tid 412046] [client 20.151.10.161:50716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9WMy7ynBpLeKYztQPexQAAADk"]
[Tue Jul 21 08:21:23.208059 2026] [security2:error] [pid 419508:tid 419739] [client 74.249.245.134:43023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9WM1cagwCeNbomjVsCOwAAAfQ"]
[Tue Jul 21 08:21:23.274591 2026] [security2:error] [pid 411857:tid 412099] [client 20.226.60.151:64107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/moon.php"] [unique_id "al9WMy7ynBpLeKYztQPeyQAAAG4"]
[Tue Jul 21 08:21:23.370248 2026] [security2:error] [pid 411857:tid 412000] [client 117.210.135.0:60995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WMy7ynBpLeKYztQPe0AAAAAs"]
[Tue Jul 21 08:21:23.370344 2026] [security2:error] [pid 411857:tid 412000] [client 117.210.135.0:60995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WMy7ynBpLeKYztQPe0AAAAAs"]
[Tue Jul 21 08:21:23.671076 2026] [security2:error] [pid 419508:tid 419718] [client 20.226.60.151:64085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/gptsh.php"] [unique_id "al9WM1cagwCeNbomjVsCRwAAAd8"]
[Tue Jul 21 08:21:23.705257 2026] [security2:error] [pid 418108:tid 418146] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WMw0cxofL2J1zwYrBnAABVCM"]
[Tue Jul 21 08:21:23.705469 2026] [security2:error] [pid 418108:tid 418314] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WMw0cxofL2J1zwYrBnAABVCM"]
[Tue Jul 21 08:21:23.773471 2026] [security2:error] [pid 418108:tid 418347] [client 20.151.10.161:50862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/pucci.php"] [unique_id "al9WMw0cxofL2J1zwYrBnQAAAXU"]
[Tue Jul 21 08:21:23.882969 2026] [security2:error] [pid 419508:tid 419645] [client 216.244.66.247:34526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/robots.txt"] [unique_id "al9WM1cagwCeNbomjVsCSQAAAZY"]
[Tue Jul 21 08:21:23.883066 2026] [security2:error] [pid 419508:tid 419645] [client 216.244.66.247:34526] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "powerflats.com.br"] [uri "/robots.txt"] [unique_id "al9WM1cagwCeNbomjVsCSQAAAZY"]
[Tue Jul 21 08:21:23.891490 2026] [security2:error] [pid 419508:tid 419647] [client 152.59.34.51:59560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WM1cagwCeNbomjVsCSgAAAZg"]
[Tue Jul 21 08:21:23.900670 2026] [security2:error] [pid 419508:tid 419647] [client 152.59.34.51:59560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WM1cagwCeNbomjVsCSgAAAZg"]
[Tue Jul 21 08:21:24.079127 2026] [security2:error] [pid 411857:tid 412109] [client 198.54.129.60:34644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9WNC7ynBpLeKYztQPe4AAAAHg"]
[Tue Jul 21 08:21:24.079231 2026] [security2:error] [pid 411857:tid 412109] [client 198.54.129.60:34644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9WNC7ynBpLeKYztQPe4AAAAHg"]
[Tue Jul 21 08:21:24.307376 2026] [security2:error] [pid 418108:tid 418263] [client 103.106.20.201:59124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WNA0cxofL2J1zwYrBnwAAASE"]
[Tue Jul 21 08:21:24.307704 2026] [security2:error] [pid 418108:tid 418263] [client 103.106.20.201:59124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WNA0cxofL2J1zwYrBnwAAASE"]
[Tue Jul 21 08:21:24.311532 2026] [security2:error] [pid 411857:tid 412015] [client 20.226.60.151:64099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-info.php"] [unique_id "al9WNC7ynBpLeKYztQPe6AAAABo"]
[Tue Jul 21 08:21:24.426262 2026] [security2:error] [pid 411857:tid 412061] [client 20.151.10.161:50844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wp-temp.php"] [unique_id "al9WNC7ynBpLeKYztQPe6gAAAEg"]
[Tue Jul 21 08:21:24.505823 2026] [security2:error] [pid 419508:tid 419581] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WNFcagwCeNbomjVsCUAABskg"]
[Tue Jul 21 08:21:24.506023 2026] [security2:error] [pid 419508:tid 419673] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WNFcagwCeNbomjVsCUAABskg"]
[Tue Jul 21 08:21:24.786346 2026] [security2:error] [pid 419508:tid 419687] [client 20.220.225.223:12305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/dr.php"] [unique_id "al9WNFcagwCeNbomjVsCUwAAAcA"]
[Tue Jul 21 08:21:24.930895 2026] [security2:error] [pid 411857:tid 412044] [client 173.252.95.113:43848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9WNC7ynBpLeKYztQPe9gAAADc"]
[Tue Jul 21 08:21:24.977630 2026] [security2:error] [pid 411857:tid 412100] [client 20.226.60.151:64043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/2000.php"] [unique_id "al9WNC7ynBpLeKYztQPe-AAAAG8"]
[Tue Jul 21 08:21:25.223748 2026] [security2:error] [pid 411857:tid 412022] [client 111.93.58.162:60381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WNS7ynBpLeKYztQPe_AAAACE"]
[Tue Jul 21 08:21:25.223933 2026] [security2:error] [pid 411857:tid 412022] [client 111.93.58.162:60381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WNS7ynBpLeKYztQPe_AAAACE"]
[Tue Jul 21 08:21:25.351056 2026] [security2:error] [pid 411857:tid 412046] [client 20.151.10.161:50841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/xmu.php"] [unique_id "al9WNS7ynBpLeKYztQPfAQAAADk"]
[Tue Jul 21 08:21:25.391341 2026] [security2:error] [pid 418108:tid 418319] [client 20.226.60.151:64118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/rithin.php"] [unique_id "al9WNQ0cxofL2J1zwYrBpgAAAVk"]
[Tue Jul 21 08:21:25.654264 2026] [security2:error] [pid 418108:tid 418324] [client 20.206.105.145:20215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9WNQ0cxofL2J1zwYrBqQAAAV4"]
[Tue Jul 21 08:21:26.135820 2026] [security2:error] [pid 419508:tid 419643] [client 20.226.60.151:64054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/122.php"] [unique_id "al9WNlcagwCeNbomjVsCZAAAAZQ"]
[Tue Jul 21 08:21:26.153805 2026] [security2:error] [pid 419508:tid 419717] [client 20.226.60.151:60670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/aunmc.php"] [unique_id "al9WNlcagwCeNbomjVsCZQAAAd4"]
[Tue Jul 21 08:21:26.205522 2026] [security2:error] [pid 418108:tid 418280] [client 120.56.162.40:65490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WNg0cxofL2J1zwYrBrAAAATI"]
[Tue Jul 21 08:21:26.205853 2026] [security2:error] [pid 418108:tid 418280] [client 120.56.162.40:65490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WNg0cxofL2J1zwYrBrAAAATI"]
[Tue Jul 21 08:21:26.231877 2026] [security2:error] [pid 418108:tid 418242] [client 20.151.10.161:50713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9WNg0cxofL2J1zwYrBrQAAAQw"]
[Tue Jul 21 08:21:26.312681 2026] [security2:error] [pid 418108:tid 418249] [client 20.220.225.223:12292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/2x.php"] [unique_id "al9WNg0cxofL2J1zwYrBrgAAARM"]
[Tue Jul 21 08:21:26.568775 2026] [security2:error] [pid 419508:tid 419629] [remote 72.167.132.114:45704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9WNlcagwCeNbomjVsCbQAB6Hg"]
[Tue Jul 21 08:21:26.690052 2026] [security2:error] [pid 419508:tid 419730] [client 65.21.113.253:52084] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WNlcagwCeNbomjVsCZgAAAes"]
[Tue Jul 21 08:21:26.748996 2026] [security2:error] [pid 419508:tid 419576] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WNlcagwCeNbomjVsCbgAB9EM"]
[Tue Jul 21 08:21:26.749131 2026] [security2:error] [pid 419508:tid 419739] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WNlcagwCeNbomjVsCbgAB9EM"]
[Tue Jul 21 08:21:26.924499 2026] [security2:error] [pid 419508:tid 419726] [client 74.249.245.134:15048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/av.php"] [unique_id "al9WNlcagwCeNbomjVsCbwAAAec"]
[Tue Jul 21 08:21:27.015719 2026] [security2:error] [pid 411857:tid 412105] [client 20.220.225.223:55183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/kua.php"] [unique_id "al9WNy7ynBpLeKYztQPfHwAAAHQ"]
[Tue Jul 21 08:21:27.199191 2026] [security2:error] [pid 419508:tid 419636] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WN1cagwCeNbomjVsCmwAB338"]
[Tue Jul 21 08:21:27.199339 2026] [security2:error] [pid 419508:tid 419718] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WN1cagwCeNbomjVsCmwAB338"]
[Tue Jul 21 08:21:27.514933 2026] [security2:error] [pid 419508:tid 419658] [client 20.151.10.161:50817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/puc.php"] [unique_id "al9WN1cagwCeNbomjVsCswAAAaM"]
[Tue Jul 21 08:21:27.724510 2026] [security2:error] [pid 419508:tid 419732] [client 20.226.60.151:59318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/fffm.php"] [unique_id "al9WN1cagwCeNbomjVsCuAAAAe0"]
[Tue Jul 21 08:21:27.868005 2026] [security2:error] [pid 419508:tid 419679] [client 20.206.105.145:20117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9WN1cagwCeNbomjVsCugAAAbg"]
[Tue Jul 21 08:21:27.967261 2026] [security2:error] [pid 419508:tid 419753] [client 20.220.225.223:53781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/ez.php"] [unique_id "al9WN1cagwCeNbomjVsCvgAAAgE"]
[Tue Jul 21 08:21:28.086478 2026] [security2:error] [pid 418108:tid 418315] [client 115.134.11.136:52827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WOA0cxofL2J1zwYrBsgAAAVU"]
[Tue Jul 21 08:21:28.087500 2026] [security2:error] [pid 418108:tid 418315] [client 115.134.11.136:52827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WOA0cxofL2J1zwYrBsgAAAVU"]
[Tue Jul 21 08:21:28.255758 2026] [security2:error] [pid 419508:tid 419649] [client 187.125.243.197:49508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WOFcagwCeNbomjVsCxwAAAZo"]
[Tue Jul 21 08:21:28.256367 2026] [security2:error] [pid 419508:tid 419649] [client 187.125.243.197:49508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WOFcagwCeNbomjVsCxwAAAZo"]
[Tue Jul 21 08:21:28.346670 2026] [security2:error] [pid 411857:tid 412066] [client 74.249.245.134:15102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/gg.php"] [unique_id "al9WOC7ynBpLeKYztQPfNAAAAE0"]
[Tue Jul 21 08:21:28.358844 2026] [security2:error] [pid 411857:tid 412005] [client 162.219.176.3:53118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9WOC7ynBpLeKYztQPfNQAAABA"]
[Tue Jul 21 08:21:28.359031 2026] [security2:error] [pid 411857:tid 412005] [client 162.219.176.3:53118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9WOC7ynBpLeKYztQPfNQAAABA"]
[Tue Jul 21 08:21:28.474581 2026] [security2:error] [pid 419508:tid 419690] [client 38.100.221.102:18462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WOFcagwCeNbomjVsCygAAAcM"]
[Tue Jul 21 08:21:28.474976 2026] [security2:error] [pid 419508:tid 419690] [client 38.100.221.102:18462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WOFcagwCeNbomjVsCygAAAcM"]
[Tue Jul 21 08:21:28.482375 2026] [security2:error] [pid 411857:tid 412095] [client 20.151.10.161:50878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/themes.php"] [unique_id "al9WOC7ynBpLeKYztQPfOAAAAGo"]
[Tue Jul 21 08:21:29.244016 2026] [security2:error] [pid 419508:tid 419592] [remote 45.76.153.27:60556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.153.76.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inovasoulfigital.com"] [uri "/wp-login.php"] [unique_id "al9WOVcagwCeNbomjVsC2QABo1M"]
[Tue Jul 21 08:21:29.249212 2026] [security2:error] [pid 419508:tid 419722] [client 20.151.10.161:50864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/8.php"] [unique_id "al9WOVcagwCeNbomjVsC2gAAAeM"]
[Tue Jul 21 08:21:29.284125 2026] [core:error] [pid 418108:tid 418238] [remote 159.223.41.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:21:29.284167 2026] [core:error] [pid 418108:tid 418238] [remote 159.223.41.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:21:29.383805 2026] [security2:error] [pid 419508:tid 419754] [client 20.226.60.151:64122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/mds.php"] [unique_id "al9WOVcagwCeNbomjVsC2wAAAgI"]
[Tue Jul 21 08:21:29.810370 2026] [security2:error] [pid 419508:tid 419663] [client 20.151.10.161:50692] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "planamoveis.com.br"] [uri "/1.php"] [unique_id "al9WOVcagwCeNbomjVsC4AAAAag"]
[Tue Jul 21 08:21:29.810498 2026] [security2:error] [pid 419508:tid 419663] [client 20.151.10.161:50692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/1.php"] [unique_id "al9WOVcagwCeNbomjVsC4AAAAag"]
[Tue Jul 21 08:21:30.194342 2026] [security2:error] [pid 411857:tid 411859] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9WOi7ynBpLeKYztQPfYQAAUgA"]
[Tue Jul 21 08:21:30.283227 2026] [security2:error] [pid 418108:tid 418322] [client 20.151.10.161:10259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/100.php"] [unique_id "al9WOg0cxofL2J1zwYrBwAAAAVw"]
[Tue Jul 21 08:21:30.503437 2026] [security2:error] [pid 418108:tid 418230] [remote 159.223.41.76:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WOg0cxofL2J1zwYrBwgABEXc"]
[Tue Jul 21 08:21:30.675998 2026] [security2:error] [pid 419508:tid 419731] [client 223.181.60.88:32029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WOlcagwCeNbomjVsC7QAAAew"]
[Tue Jul 21 08:21:30.678723 2026] [security2:error] [pid 419508:tid 419731] [client 223.181.60.88:32029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WOlcagwCeNbomjVsC7QAAAew"]
[Tue Jul 21 08:21:30.806570 2026] [core:error] [pid 411857:tid 411880] [remote 159.223.41.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:21:30.806603 2026] [core:error] [pid 411857:tid 411880] [remote 159.223.41.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:21:30.963847 2026] [security2:error] [pid 418108:tid 418358] [client 198.54.129.60:48726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9WOg0cxofL2J1zwYrBxQAAAYA"]
[Tue Jul 21 08:21:30.963980 2026] [security2:error] [pid 418108:tid 418358] [client 198.54.129.60:48726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9WOg0cxofL2J1zwYrBxQAAAYA"]
[Tue Jul 21 08:21:31.107656 2026] [security2:error] [pid 419508:tid 419718] [client 20.226.60.151:64037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/dfre.php"] [unique_id "al9WO1cagwCeNbomjVsC9wAAAd8"]
[Tue Jul 21 08:21:31.115746 2026] [security2:error] [pid 411857:tid 411915] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9WOy7ynBpLeKYztQPfawAASzg"]
[Tue Jul 21 08:21:31.287908 2026] [security2:error] [pid 419508:tid 419763] [client 103.151.46.103:62822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WO1cagwCeNbomjVsC-wAAAgs"]
[Tue Jul 21 08:21:31.288153 2026] [security2:error] [pid 419508:tid 419763] [client 103.151.46.103:62822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WO1cagwCeNbomjVsC-wAAAgs"]
[Tue Jul 21 08:21:31.304003 2026] [security2:error] [pid 411857:tid 412116] [client 20.206.105.145:20195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/x.php"] [unique_id "al9WOy7ynBpLeKYztQPfcgAAAH8"]
[Tue Jul 21 08:21:31.337119 2026] [security2:error] [pid 419508:tid 419700] [client 20.226.60.151:60582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/uoocf.php"] [unique_id "al9WO1cagwCeNbomjVsC_QAAAc0"]
[Tue Jul 21 08:21:31.424337 2026] [security2:error] [pid 411857:tid 419448] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9WOy7ynBpLeKYztQPfdQAAF4M"]
[Tue Jul 21 08:21:31.477807 2026] [security2:error] [pid 419508:tid 419616] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WO1cagwCeNbomjVsDBwABkms"]
[Tue Jul 21 08:21:31.478093 2026] [security2:error] [pid 419508:tid 419641] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WO1cagwCeNbomjVsDBwABkms"]
[Tue Jul 21 08:21:31.494583 2026] [security2:error] [pid 419508:tid 419687] [client 20.151.10.161:46063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-load.php"] [unique_id "al9WO1cagwCeNbomjVsDCQAAAcA"]
[Tue Jul 21 08:21:31.587754 2026] [security2:error] [pid 419508:tid 419695] [client 20.151.10.161:50830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/about.php"] [unique_id "al9WO1cagwCeNbomjVsDDQAAAcg"]
[Tue Jul 21 08:21:31.712315 2026] [security2:error] [pid 411857:tid 412017] [client 152.59.34.51:28878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WOy7ynBpLeKYztQPfgAAAABw"]
[Tue Jul 21 08:21:31.712456 2026] [security2:error] [pid 411857:tid 412017] [client 152.59.34.51:28878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WOy7ynBpLeKYztQPfgAAAABw"]
[Tue Jul 21 08:21:31.733894 2026] [security2:error] [pid 411857:tid 411965] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9WOy7ynBpLeKYztQPfgQAAd2k"]
[Tue Jul 21 08:21:31.860204 2026] [security2:error] [pid 419508:tid 419749] [client 162.219.176.3:53132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9WO1cagwCeNbomjVsDFAAAAf0"]
[Tue Jul 21 08:21:31.860287 2026] [security2:error] [pid 419508:tid 419749] [client 162.219.176.3:53132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9WO1cagwCeNbomjVsDFAAAAf0"]
[Tue Jul 21 08:21:32.043903 2026] [security2:error] [pid 411857:tid 411961] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9WPC7ynBpLeKYztQPfgwAAMmU"]
[Tue Jul 21 08:21:32.300645 2026] [security2:error] [pid 419508:tid 419724] [client 20.151.10.161:10243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/about.php"] [unique_id "al9WPFcagwCeNbomjVsDHgAAAeU"]
[Tue Jul 21 08:21:32.379515 2026] [security2:error] [pid 411857:tid 411980] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9WPC7ynBpLeKYztQPfiQAAO3g"]
[Tue Jul 21 08:21:32.437482 2026] [security2:error] [pid 419508:tid 419731] [client 74.249.245.134:46501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/sql.php"] [unique_id "al9WPFcagwCeNbomjVsDIQAAAew"]
[Tue Jul 21 08:21:32.554924 2026] [security2:error] [pid 411857:tid 412037] [client 202.179.75.202:57396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WPC7ynBpLeKYztQPfiwAAADA"]
[Tue Jul 21 08:21:32.555039 2026] [security2:error] [pid 411857:tid 412037] [client 202.179.75.202:57396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WPC7ynBpLeKYztQPfiwAAADA"]
[Tue Jul 21 08:21:32.600938 2026] [security2:error] [pid 411857:tid 412032] [client 117.213.202.34:59572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WPC7ynBpLeKYztQPfjQAAACs"]
[Tue Jul 21 08:21:32.601026 2026] [security2:error] [pid 411857:tid 412032] [client 117.213.202.34:59572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WPC7ynBpLeKYztQPfjQAAACs"]
[Tue Jul 21 08:21:32.690119 2026] [security2:error] [pid 411857:tid 411933] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9WPC7ynBpLeKYztQPfjwAAXEo"]
[Tue Jul 21 08:21:32.778077 2026] [core:error] [pid 419508:tid 419718] [client 65.110.40.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:21:32.778096 2026] [core:error] [pid 419508:tid 419718] [client 65.110.40.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:21:32.787515 2026] [security2:error] [pid 419508:tid 419619] [remote 41.186.86.12:23498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9WPFcagwCeNbomjVsDKAACC24"]
[Tue Jul 21 08:21:32.972346 2026] [security2:error] [pid 419508:tid 419764] [client 20.151.10.161:50848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/admin.php"] [unique_id "al9WPFcagwCeNbomjVsDLgAAAgw"]
[Tue Jul 21 08:21:33.000999 2026] [security2:error] [pid 411857:tid 411923] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9WPC7ynBpLeKYztQPfmAAAYUA"]
[Tue Jul 21 08:21:33.268038 2026] [security2:error] [pid 411857:tid 412005] [client 69.171.230.1:49786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9WPS7ynBpLeKYztQPfmQAAABA"]
[Tue Jul 21 08:21:33.276590 2026] [security2:error] [pid 411857:tid 412097] [client 20.220.225.223:43406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/fz.php"] [unique_id "al9WPS7ynBpLeKYztQPfnAAAAGw"]
[Tue Jul 21 08:21:33.316347 2026] [security2:error] [pid 411857:tid 411929] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9WPS7ynBpLeKYztQPfnwAAfkY"]
[Tue Jul 21 08:21:33.319851 2026] [core:error] [pid 418108:tid 418263] [client 65.110.40.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:21:33.319879 2026] [core:error] [pid 418108:tid 418263] [client 65.110.40.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:21:33.320924 2026] [core:error] [pid 418108:tid 418286] [client 65.110.40.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:21:33.320969 2026] [core:error] [pid 418108:tid 418286] [client 65.110.40.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:21:33.344746 2026] [security2:error] [pid 411857:tid 412066] [client 87.116.180.198:14072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WPS7ynBpLeKYztQPfoAAAAE0"]
[Tue Jul 21 08:21:33.344928 2026] [security2:error] [pid 411857:tid 412066] [client 87.116.180.198:14072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WPS7ynBpLeKYztQPfoAAAAE0"]
[Tue Jul 21 08:21:33.592509 2026] [security2:error] [pid 411857:tid 412096] [client 150.129.202.39:65199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WPS7ynBpLeKYztQPfpQAAAGs"]
[Tue Jul 21 08:21:33.592639 2026] [security2:error] [pid 411857:tid 412096] [client 150.129.202.39:65199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WPS7ynBpLeKYztQPfpQAAAGs"]
[Tue Jul 21 08:21:33.626033 2026] [security2:error] [pid 411857:tid 411903] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9WPS7ynBpLeKYztQPfpgAAFSw"]
[Tue Jul 21 08:21:33.704384 2026] [security2:error] [pid 419508:tid 419674] [client 173.252.95.1:51208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9WPVcagwCeNbomjVsDOwAAAbM"]
[Tue Jul 21 08:21:33.711264 2026] [security2:error] [pid 418108:tid 418254] [client 20.226.60.151:59281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/wp-happy.php"] [unique_id "al9WPQ0cxofL2J1zwYrB0QAAARg"]
[Tue Jul 21 08:21:33.734612 2026] [security2:error] [pid 418108:tid 418326] [client 195.49.128.211:50881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WPQ0cxofL2J1zwYrB0gAAAWA"]
[Tue Jul 21 08:21:33.734796 2026] [security2:error] [pid 418108:tid 418326] [client 195.49.128.211:50881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WPQ0cxofL2J1zwYrB0gAAAWA"]
[Tue Jul 21 08:21:33.809780 2026] [security2:error] [pid 419508:tid 419663] [client 14.245.224.124:57849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WPVcagwCeNbomjVsDPQAAAag"]
[Tue Jul 21 08:21:33.809884 2026] [security2:error] [pid 419508:tid 419663] [client 14.245.224.124:57849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WPVcagwCeNbomjVsDPQAAAag"]
[Tue Jul 21 08:21:33.884436 2026] [security2:error] [pid 419508:tid 419660] [client 117.210.135.0:61658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WPVcagwCeNbomjVsDPwAAAaU"]
[Tue Jul 21 08:21:33.884572 2026] [security2:error] [pid 419508:tid 419660] [client 117.210.135.0:61658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WPVcagwCeNbomjVsDPwAAAaU"]
[Tue Jul 21 08:21:33.894109 2026] [security2:error] [pid 411857:tid 412031] [client 74.249.245.134:50290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/up.php"] [unique_id "al9WPS7ynBpLeKYztQPfrgAAACo"]
[Tue Jul 21 08:21:33.935066 2026] [security2:error] [pid 411857:tid 411884] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9WPS7ynBpLeKYztQPfsAAAcxk"]
[Tue Jul 21 08:21:33.954410 2026] [autoindex:error] [pid 418108:tid 418304] [client 186.202.163.107:51063] AH01276: Cannot serve directory /home2/italom32/rota40.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:21:33.992941 2026] [security2:error] [pid 411857:tid 412052] [client 154.208.47.43:6690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WPS7ynBpLeKYztQPfsQAAAD8"]
[Tue Jul 21 08:21:33.993062 2026] [security2:error] [pid 411857:tid 412052] [client 154.208.47.43:6690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WPS7ynBpLeKYztQPfsQAAAD8"]
[Tue Jul 21 08:21:34.041024 2026] [security2:error] [pid 419508:tid 419712] [client 20.151.10.161:10277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/admin.php"] [unique_id "al9WPlcagwCeNbomjVsDRAAAAdk"]
[Tue Jul 21 08:21:34.179507 2026] [security2:error] [pid 418108:tid 418319] [client 20.220.225.223:12592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/kq1.php"] [unique_id "al9WPg0cxofL2J1zwYrB1gAAAVk"]
[Tue Jul 21 08:21:34.245638 2026] [security2:error] [pid 411857:tid 411962] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9WPi7ynBpLeKYztQPftQAAd2Y"]
[Tue Jul 21 08:21:34.400016 2026] [security2:error] [pid 419508:tid 419596] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WPlcagwCeNbomjVsDSQABw1c"]
[Tue Jul 21 08:21:34.400194 2026] [security2:error] [pid 419508:tid 419690] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WPlcagwCeNbomjVsDSQABw1c"]
[Tue Jul 21 08:21:34.449833 2026] [security2:error] [pid 411857:tid 412074] [client 20.226.60.151:59325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-blink.php"] [unique_id "al9WPi7ynBpLeKYztQPfvAAAAFU"]
[Tue Jul 21 08:21:34.509687 2026] [security2:error] [pid 419508:tid 419678] [client 69.171.230.114:52338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9WPlcagwCeNbomjVsDSAAAAbc"]
[Tue Jul 21 08:21:34.553965 2026] [security2:error] [pid 411857:tid 411869] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9WPi7ynBpLeKYztQPfvgAAXwo"]
[Tue Jul 21 08:21:34.742957 2026] [security2:error] [pid 411857:tid 412035] [client 20.151.10.161:45989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/xwpg.php"] [unique_id "al9WPi7ynBpLeKYztQPfwAAAAC4"]
[Tue Jul 21 08:21:34.862823 2026] [security2:error] [pid 411857:tid 411974] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9WPi7ynBpLeKYztQPfxwAANnI"]
[Tue Jul 21 08:21:34.981200 2026] [security2:error] [pid 411857:tid 419447] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WPi7ynBpLeKYztQPfyAAAIoI"]
[Tue Jul 21 08:21:34.981330 2026] [security2:error] [pid 411857:tid 412023] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WPi7ynBpLeKYztQPfyAAAIoI"]
[Tue Jul 21 08:21:35.037795 2026] [security2:error] [pid 411857:tid 412053] [client 103.106.20.201:59729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WPy7ynBpLeKYztQPfywAAAEA"]
[Tue Jul 21 08:21:35.037968 2026] [security2:error] [pid 411857:tid 412053] [client 103.106.20.201:59729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WPy7ynBpLeKYztQPfywAAAEA"]
[Tue Jul 21 08:21:35.077882 2026] [security2:error] [pid 411857:tid 411953] [remote 103.57.220.209:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.57.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cristaofitsuplementos.com"] [uri "/wp-login.php"] [unique_id "al9WPy7ynBpLeKYztQPfzgAACl0"]
[Tue Jul 21 08:21:35.170421 2026] [security2:error] [pid 411857:tid 411950] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9WPy7ynBpLeKYztQPf0gAAEFs"]
[Tue Jul 21 08:21:35.316010 2026] [security2:error] [pid 411857:tid 412071] [client 69.171.230.38:55166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9WPy7ynBpLeKYztQPf0QAAAFI"]
[Tue Jul 21 08:21:35.413425 2026] [security2:error] [pid 419508:tid 419761] [client 20.151.10.161:50688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/edit.php"] [unique_id "al9WP1cagwCeNbomjVsDVwAAAgk"]
[Tue Jul 21 08:21:35.482168 2026] [security2:error] [pid 411857:tid 411924] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9WPy7ynBpLeKYztQPf1wAADkE"]
[Tue Jul 21 08:21:35.620413 2026] [security2:error] [pid 411857:tid 412095] [client 20.226.60.151:53164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/fpr4.php"] [unique_id "al9WPy7ynBpLeKYztQPf2QAAAGo"]
[Tue Jul 21 08:21:35.755253 2026] [security2:error] [pid 419508:tid 419735] [client 20.226.60.151:60625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/iywwi.php"] [unique_id "al9WP1cagwCeNbomjVsDXQAAAfA"]
[Tue Jul 21 08:21:35.789652 2026] [security2:error] [pid 411857:tid 411905] [remote 159.223.41.76:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.royalbsolutions.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9WPy7ynBpLeKYztQPf2gAAay4"]
[Tue Jul 21 08:21:35.868032 2026] [security2:error] [pid 419508:tid 419673] [client 14.97.58.74:14040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WP1cagwCeNbomjVsDXwAAAbI"]
[Tue Jul 21 08:21:35.868135 2026] [security2:error] [pid 419508:tid 419673] [client 14.97.58.74:14040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WP1cagwCeNbomjVsDXwAAAbI"]
[Tue Jul 21 08:21:35.914901 2026] [security2:error] [pid 419508:tid 419759] [client 20.220.225.223:49038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/la.php"] [unique_id "al9WP1cagwCeNbomjVsDYAAAAgc"]
[Tue Jul 21 08:21:36.306158 2026] [security2:error] [pid 418108:tid 418293] [client 65.21.113.253:57078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WQA0cxofL2J1zwYrB3wAAAT8"]
[Tue Jul 21 08:21:36.369885 2026] [security2:error] [pid 419508:tid 419628] [remote 57.141.18.46:33920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9WQFcagwCeNbomjVsDaQACCnc"]
[Tue Jul 21 08:21:36.773964 2026] [security2:error] [pid 419508:tid 419644] [client 74.7.230.41:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "simonevirginiacarnim1754067166991.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9WQFcagwCeNbomjVsDcQABlXs"]
[Tue Jul 21 08:21:36.864516 2026] [security2:error] [pid 419508:tid 419705] [client 20.220.225.223:12596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/zzz.php"] [unique_id "al9WQFcagwCeNbomjVsDdAAAAdI"]
[Tue Jul 21 08:21:36.877338 2026] [security2:error] [pid 419508:tid 419674] [client 120.56.162.40:49622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WQFcagwCeNbomjVsDdgAAAbM"]
[Tue Jul 21 08:21:36.877465 2026] [security2:error] [pid 419508:tid 419674] [client 120.56.162.40:49622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WQFcagwCeNbomjVsDdgAAAbM"]
[Tue Jul 21 08:21:37.046429 2026] [security2:error] [pid 418108:tid 418259] [client 20.151.10.161:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/waf.php"] [unique_id "al9WQQ0cxofL2J1zwYrB5gAAAR0"]
[Tue Jul 21 08:21:37.286721 2026] [security2:error] [pid 419508:tid 419605] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WQVcagwCeNbomjVsDgQAB8GA"]
[Tue Jul 21 08:21:37.287088 2026] [security2:error] [pid 419508:tid 419605] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WQVcagwCeNbomjVsDgQAB8GA"]
[Tue Jul 21 08:21:37.353442 2026] [security2:error] [pid 418108:tid 418292] [client 74.249.245.134:56049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/66.php"] [unique_id "al9WQQ0cxofL2J1zwYrB5wAAAT4"]
[Tue Jul 21 08:21:37.549040 2026] [security2:error] [pid 419508:tid 419751] [client 20.226.60.151:64007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/zc-208.php"] [unique_id "al9WQVcagwCeNbomjVsDjAAAAf8"]
[Tue Jul 21 08:21:37.572451 2026] [security2:error] [pid 419508:tid 419733] [client 20.206.105.145:20204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/j260624_13.php"] [unique_id "al9WQVcagwCeNbomjVsDjQAAAe4"]
[Tue Jul 21 08:21:37.800948 2026] [security2:error] [pid 419508:tid 419726] [client 20.206.105.145:20198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/d62.php"] [unique_id "al9WQVcagwCeNbomjVsDkwAAAec"]
[Tue Jul 21 08:21:37.831497 2026] [security2:error] [pid 419508:tid 419663] [client 20.226.60.151:59276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/file88.php"] [unique_id "al9WQVcagwCeNbomjVsDlAAAAag"]
[Tue Jul 21 08:21:37.898028 2026] [security2:error] [pid 419508:tid 419530] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WQVcagwCeNbomjVsDlwACCBU"]
[Tue Jul 21 08:21:37.898841 2026] [security2:error] [pid 419508:tid 419760] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WQVcagwCeNbomjVsDlwACCBU"]
[Tue Jul 21 08:21:37.988208 2026] [security2:error] [pid 419508:tid 419690] [client 20.206.105.145:20122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/ups.php"] [unique_id "al9WQVcagwCeNbomjVsDpAAAAcM"]
[Tue Jul 21 08:21:38.099075 2026] [security2:error] [pid 419508:tid 419763] [client 20.151.10.161:50816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9WQlcagwCeNbomjVsDpwAAAgs"]
[Tue Jul 21 08:21:38.168536 2026] [proxy:error] [pid 419508:tid 419528] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:21:38.168578 2026] [proxy_http:error] [pid 419508:tid 419528] [remote 43.228.157.40:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.shopmelhorcompraonline.com/
[Tue Jul 21 08:21:38.169162 2026] [proxy:error] [pid 419508:tid 419528] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:21:38.169192 2026] [proxy_http:error] [pid 419508:tid 419528] [remote 43.228.157.40:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.shopmelhorcompraonline.com/
[Tue Jul 21 08:21:38.259107 2026] [security2:error] [pid 418108:tid 418335] [client 198.54.129.60:48742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.129.54.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9WQg0cxofL2J1zwYrB6gAAAWk"]
[Tue Jul 21 08:21:38.259270 2026] [security2:error] [pid 418108:tid 418335] [client 198.54.129.60:48742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9WQg0cxofL2J1zwYrB6gAAAWk"]
[Tue Jul 21 08:21:38.494705 2026] [security2:error] [pid 411857:tid 412037] [client 20.220.225.223:55230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/nhvoanpl.php"] [unique_id "al9WQi7ynBpLeKYztQPf-gAAADA"]
[Tue Jul 21 08:21:38.545139 2026] [security2:error] [pid 419508:tid 419656] [client 115.134.11.136:53284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WQlcagwCeNbomjVsDrAAAAaE"]
[Tue Jul 21 08:21:38.545249 2026] [security2:error] [pid 419508:tid 419656] [client 115.134.11.136:53284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WQlcagwCeNbomjVsDrAAAAaE"]
[Tue Jul 21 08:21:38.561038 2026] [security2:error] [pid 411857:tid 412093] [client 20.151.10.161:10252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/f6.php"] [unique_id "al9WQi7ynBpLeKYztQPf_gAAAGg"]
[Tue Jul 21 08:21:38.637366 2026] [security2:error] [pid 419508:tid 419669] [client 162.219.176.3:53316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9WQlcagwCeNbomjVsDsgAAAa4"]
[Tue Jul 21 08:21:38.637467 2026] [security2:error] [pid 419508:tid 419669] [client 162.219.176.3:53316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9WQlcagwCeNbomjVsDsgAAAa4"]
[Tue Jul 21 08:21:38.696499 2026] [security2:error] [pid 411857:tid 412003] [client 20.226.60.151:60650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/gqgsa.php"] [unique_id "al9WQi7ynBpLeKYztQPf_wAAAA4"]
[Tue Jul 21 08:21:38.726551 2026] [security2:error] [pid 419508:tid 419641] [client 187.125.243.197:50015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WQlcagwCeNbomjVsDswAAAZI"]
[Tue Jul 21 08:21:38.726699 2026] [security2:error] [pid 419508:tid 419641] [client 187.125.243.197:50015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WQlcagwCeNbomjVsDswAAAZI"]
[Tue Jul 21 08:21:38.907442 2026] [security2:error] [pid 419508:tid 419684] [client 74.249.245.134:60668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/666.php"] [unique_id "al9WQlcagwCeNbomjVsDuAAAAb0"]
[Tue Jul 21 08:21:39.096570 2026] [security2:error] [pid 419508:tid 419680] [client 38.100.221.102:17377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WQ1cagwCeNbomjVsDvwAAAbk"]
[Tue Jul 21 08:21:39.096720 2026] [security2:error] [pid 419508:tid 419680] [client 38.100.221.102:17377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WQ1cagwCeNbomjVsDvwAAAbk"]
[Tue Jul 21 08:21:39.108099 2026] [security2:error] [pid 418108:tid 418340] [client 20.226.60.151:59277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/sid4.php"] [unique_id "al9WQw0cxofL2J1zwYrB7AAAAW4"]
[Tue Jul 21 08:21:39.188629 2026] [security2:error] [pid 418108:tid 418256] [client 154.208.47.43:7219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WQw0cxofL2J1zwYrB7QAAARo"]
[Tue Jul 21 08:21:39.189464 2026] [security2:error] [pid 418108:tid 418256] [client 154.208.47.43:7219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WQw0cxofL2J1zwYrB7QAAARo"]
[Tue Jul 21 08:21:39.235407 2026] [security2:error] [pid 418108:tid 418350] [client 20.151.10.161:50849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/inputs.php"] [unique_id "al9WQw0cxofL2J1zwYrB7gAAAXg"]
[Tue Jul 21 08:21:39.652292 2026] [security2:error] [pid 419508:tid 419696] [client 20.206.105.145:20121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/k.php"] [unique_id "al9WQ1cagwCeNbomjVsDxwAAAck"]
[Tue Jul 21 08:21:39.744131 2026] [security2:error] [pid 411857:tid 412075] [client 102.218.91.205:53530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.91.218.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jbms.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WQy7ynBpLeKYztQPgEAAAAFY"]
[Tue Jul 21 08:21:39.744349 2026] [security2:error] [pid 411857:tid 412075] [client 102.218.91.205:53530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jbms.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WQy7ynBpLeKYztQPgEAAAAFY"]
[Tue Jul 21 08:21:39.772895 2026] [security2:error] [pid 411857:tid 412109] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/ms-themes.php"] [unique_id "al9WQy7ynBpLeKYztQPgEQAAAHg"], referer: http://sobradoimoveis.com.br/ms-themes.php
[Tue Jul 21 08:21:39.817076 2026] [security2:error] [pid 419508:tid 419648] [client 20.226.60.151:60647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/elbzl.php"] [unique_id "al9WQ1cagwCeNbomjVsDzAAAAZk"]
[Tue Jul 21 08:21:40.386939 2026] [security2:error] [pid 419508:tid 419702] [client 20.226.60.151:50147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/adjig.php"] [unique_id "al9WRFcagwCeNbomjVsD0gAAAc8"]
[Tue Jul 21 08:21:40.395655 2026] [security2:error] [pid 419508:tid 419655] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/chosen.php"] [unique_id "al9WRFcagwCeNbomjVsD0wAAAaA"], referer: http://sobradoimoveis.com.br/chosen.php?p=
[Tue Jul 21 08:21:40.715596 2026] [security2:error] [pid 419508:tid 419642] [client 162.219.176.3:41952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9WRFcagwCeNbomjVsD2gAAAZM"]
[Tue Jul 21 08:21:40.715709 2026] [security2:error] [pid 419508:tid 419642] [client 162.219.176.3:41952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9WRFcagwCeNbomjVsD2gAAAZM"]
[Tue Jul 21 08:21:41.033648 2026] [security2:error] [pid 418108:tid 418247] [client 20.226.60.151:53182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/ccc.php"] [unique_id "al9WRQ0cxofL2J1zwYrB8gAAARE"]
[Tue Jul 21 08:21:41.060284 2026] [security2:error] [pid 419508:tid 419736] [client 103.151.46.103:63321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WRVcagwCeNbomjVsD4AAAAfE"]
[Tue Jul 21 08:21:41.060980 2026] [security2:error] [pid 419508:tid 419736] [client 103.151.46.103:63321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WRVcagwCeNbomjVsD4AAAAfE"]
[Tue Jul 21 08:21:41.108668 2026] [security2:error] [pid 419508:tid 419684] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/file.php"] [unique_id "al9WRVcagwCeNbomjVsD4QAAAb0"], referer: http://sobradoimoveis.com.br/file.php
[Tue Jul 21 08:21:41.340348 2026] [security2:error] [pid 411857:tid 411955] [remote 103.74.116.239:60944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.116.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9WRS7ynBpLeKYztQPgMgAAbl8"]
[Tue Jul 21 08:21:41.361480 2026] [security2:error] [pid 411857:tid 412083] [client 223.181.60.88:15504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WRS7ynBpLeKYztQPgMwAAAF4"]
[Tue Jul 21 08:21:41.361778 2026] [security2:error] [pid 411857:tid 412083] [client 223.181.60.88:15504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WRS7ynBpLeKYztQPgMwAAAF4"]
[Tue Jul 21 08:21:41.510781 2026] [security2:error] [pid 419508:tid 419716] [client 20.226.60.151:60589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/byp.php"] [unique_id "al9WRVcagwCeNbomjVsD5gAAAd0"]
[Tue Jul 21 08:21:41.603461 2026] [security2:error] [pid 419508:tid 419761] [client 20.226.60.151:59125] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-includes/l10n/"] [unique_id "al9WRVcagwCeNbomjVsD6AAAAgk"]
[Tue Jul 21 08:21:42.061594 2026] [security2:error] [pid 419508:tid 419683] [client 47.128.37.120:12208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "limetteodontologia.com.br"] [uri "/robots.txt"] [unique_id "al9WRlcagwCeNbomjVsD8gAAAbw"]
[Tue Jul 21 08:21:42.200473 2026] [security2:error] [pid 419508:tid 419558] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WRlcagwCeNbomjVsD9QABxTE"]
[Tue Jul 21 08:21:42.200700 2026] [security2:error] [pid 419508:tid 419692] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WRlcagwCeNbomjVsD9QABxTE"]
[Tue Jul 21 08:21:42.217183 2026] [security2:error] [pid 418108:tid 418310] [client 20.151.10.161:46077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/xstelth.php"] [unique_id "al9WRg0cxofL2J1zwYrB9QAAAVA"]
[Tue Jul 21 08:21:42.296897 2026] [security2:error] [pid 418108:tid 418269] [client 20.206.105.145:20098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/k2.php"] [unique_id "al9WRg0cxofL2J1zwYrB9gAAASc"]
[Tue Jul 21 08:21:42.309110 2026] [security2:error] [pid 411857:tid 411992] [client 20.151.10.161:50837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/inputs.php"] [unique_id "al9WRi7ynBpLeKYztQPgPgAAAAM"]
[Tue Jul 21 08:21:42.381989 2026] [security2:error] [pid 411857:tid 419467] [remote 159.65.81.207:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com.br"] [uri "/wp-login.php"] [unique_id "al9WRC7ynBpLeKYztQPgHAAAFpU"]
[Tue Jul 21 08:21:42.538495 2026] [security2:error] [pid 411857:tid 412088] [client 74.249.245.134:62338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/byp.php"] [unique_id "al9WRi7ynBpLeKYztQPgQwAAAGM"]
[Tue Jul 21 08:21:42.667605 2026] [security2:error] [pid 411857:tid 412045] [client 20.226.60.151:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/777.php"] [unique_id "al9WRi7ynBpLeKYztQPgRQAAADg"]
[Tue Jul 21 08:21:42.772890 2026] [security2:error] [pid 411857:tid 412075] [client 162.219.176.3:41958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9WRi7ynBpLeKYztQPgSQAAAFY"]
[Tue Jul 21 08:21:42.773006 2026] [security2:error] [pid 411857:tid 412075] [client 162.219.176.3:41958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9WRi7ynBpLeKYztQPgSQAAAFY"]
[Tue Jul 21 08:21:42.776928 2026] [security2:error] [pid 419508:tid 419702] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/flower.php"] [unique_id "al9WRlcagwCeNbomjVsD-QAAAc8"], referer: http://sobradoimoveis.com.br/flower.php
[Tue Jul 21 08:21:43.111592 2026] [security2:error] [pid 419508:tid 419708] [client 74.7.228.40:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "danielykuhn1782171336034.0711679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9WR1cagwCeNbomjVsEAQAB1Ws"]
[Tue Jul 21 08:21:43.324706 2026] [security2:error] [pid 418108:tid 418362] [client 117.213.202.34:60111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WRw0cxofL2J1zwYrB-gAAAYQ"]
[Tue Jul 21 08:21:43.325082 2026] [security2:error] [pid 418108:tid 418362] [client 117.213.202.34:60111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WRw0cxofL2J1zwYrB-gAAAYQ"]
[Tue Jul 21 08:21:43.455597 2026] [security2:error] [pid 419508:tid 419687] [client 202.179.75.202:56094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WR1cagwCeNbomjVsECgAAAcA"]
[Tue Jul 21 08:21:43.455707 2026] [security2:error] [pid 419508:tid 419687] [client 202.179.75.202:56094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WR1cagwCeNbomjVsECgAAAcA"]
[Tue Jul 21 08:21:43.494755 2026] [security2:error] [pid 419508:tid 419602] [remote 17.246.23.65:46262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.23.246.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9WRlcagwCeNbomjVsD9gAB8l0"]
[Tue Jul 21 08:21:43.524382 2026] [security2:error] [pid 419508:tid 419683] [client 20.226.60.151:59265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wmore1.php"] [unique_id "al9WR1cagwCeNbomjVsEDAAAAbw"]
[Tue Jul 21 08:21:43.529849 2026] [security2:error] [pid 411857:tid 412085] [client 74.7.228.56:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "diessicaramos1782359038231.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9WRy7ynBpLeKYztQPgWAAAYA4"]
[Tue Jul 21 08:21:43.722992 2026] [security2:error] [pid 419508:tid 419599] [remote 41.186.86.12:7173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roha.life"] [uri "/wp-login.php"] [unique_id "al9WR1cagwCeNbomjVsEDgACCVo"]
[Tue Jul 21 08:21:43.989702 2026] [security2:error] [pid 411857:tid 412038] [client 87.116.180.198:27356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WRy7ynBpLeKYztQPgYgAAADE"]
[Tue Jul 21 08:21:43.994301 2026] [security2:error] [pid 411857:tid 412038] [client 87.116.180.198:27356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WRy7ynBpLeKYztQPgYgAAADE"]
[Tue Jul 21 08:21:44.168644 2026] [security2:error] [pid 419508:tid 419696] [client 150.129.202.39:13170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WSFcagwCeNbomjVsEFQAAAck"]
[Tue Jul 21 08:21:44.168790 2026] [security2:error] [pid 419508:tid 419696] [client 150.129.202.39:13170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WSFcagwCeNbomjVsEFQAAAck"]
[Tue Jul 21 08:21:44.242193 2026] [proxy:error] [pid 419508:tid 419756] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:21:44.242245 2026] [proxy_http:error] [pid 419508:tid 419756] [client 195.96.139.240:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:21:44.243048 2026] [proxy:error] [pid 419508:tid 419756] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:21:44.243080 2026] [proxy_http:error] [pid 419508:tid 419756] [client 195.96.139.240:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:21:44.393286 2026] [security2:error] [pid 419508:tid 419644] [client 195.49.128.211:51470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WSFcagwCeNbomjVsEHQAAAZU"]
[Tue Jul 21 08:21:44.393405 2026] [security2:error] [pid 419508:tid 419644] [client 195.49.128.211:51470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WSFcagwCeNbomjVsEHQAAAZU"]
[Tue Jul 21 08:21:44.411459 2026] [security2:error] [pid 419508:tid 419693] [client 117.210.135.0:62325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WSFcagwCeNbomjVsEHgAAAcY"]
[Tue Jul 21 08:21:44.411617 2026] [security2:error] [pid 419508:tid 419693] [client 117.210.135.0:62325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WSFcagwCeNbomjVsEHgAAAcY"]
[Tue Jul 21 08:21:44.470538 2026] [security2:error] [pid 419508:tid 419679] [client 20.151.10.161:50696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/av.php"] [unique_id "al9WSFcagwCeNbomjVsEIAAAAbg"]
[Tue Jul 21 08:21:44.474373 2026] [security2:error] [pid 419508:tid 419642] [client 20.226.60.151:64023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/for.php"] [unique_id "al9WSFcagwCeNbomjVsEIQAAAZM"]
[Tue Jul 21 08:21:44.549025 2026] [security2:error] [pid 419508:tid 419705] [client 14.245.224.124:58296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WSFcagwCeNbomjVsEJQAAAdI"]
[Tue Jul 21 08:21:44.549116 2026] [security2:error] [pid 419508:tid 419705] [client 14.245.224.124:58296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WSFcagwCeNbomjVsEJQAAAdI"]
[Tue Jul 21 08:21:44.970609 2026] [security2:error] [pid 411857:tid 411999] [client 20.206.105.145:20118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/k3.php"] [unique_id "al9WSC7ynBpLeKYztQPgbQAAAAo"]
[Tue Jul 21 08:21:45.122415 2026] [security2:error] [pid 419508:tid 419561] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WSVcagwCeNbomjVsEMAAB3TQ"]
[Tue Jul 21 08:21:45.122539 2026] [security2:error] [pid 419508:tid 419716] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WSVcagwCeNbomjVsEMAAB3TQ"]
[Tue Jul 21 08:21:45.150640 2026] [security2:error] [pid 419508:tid 419757] [client 20.197.192.193:2839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9WSVcagwCeNbomjVsEMQAAAgU"]
[Tue Jul 21 08:21:45.263306 2026] [security2:error] [pid 419508:tid 419687] [client 20.226.60.151:50150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9WSVcagwCeNbomjVsEMwAAAcA"]
[Tue Jul 21 08:21:45.303055 2026] [security2:error] [pid 411857:tid 412020] [client 20.197.192.193:2863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9WSS7ynBpLeKYztQPgdQAAAB8"]
[Tue Jul 21 08:21:45.430031 2026] [security2:error] [pid 419508:tid 419613] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WSVcagwCeNbomjVsENAAB62g"]
[Tue Jul 21 08:21:45.430220 2026] [security2:error] [pid 419508:tid 419730] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WSVcagwCeNbomjVsENAAB62g"]
[Tue Jul 21 08:21:45.438345 2026] [security2:error] [pid 411857:tid 412022] [client 20.197.192.193:2858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/dp.php"] [unique_id "al9WSS7ynBpLeKYztQPgeAAAACE"]
[Tue Jul 21 08:21:45.485696 2026] [security2:error] [pid 418108:tid 418298] [client 20.197.192.193:2824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/old.php"] [unique_id "al9WSQ0cxofL2J1zwYrCAQAAAUQ"]
[Tue Jul 21 08:21:45.556199 2026] [security2:error] [pid 419508:tid 419692] [client 20.197.192.193:2388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/ms-new.php"] [unique_id "al9WSVcagwCeNbomjVsENwAAAcU"]
[Tue Jul 21 08:21:45.560307 2026] [security2:error] [pid 419508:tid 419672] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/gifclass.php"] [unique_id "al9WSVcagwCeNbomjVsEOAAAAbE"], referer: http://sobradoimoveis.com.br/gifclass.php#888xyz999
[Tue Jul 21 08:21:45.616774 2026] [security2:error] [pid 419508:tid 419639] [client 20.197.192.193:2765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/track.php"] [unique_id "al9WSVcagwCeNbomjVsEOQAAAZA"]
[Tue Jul 21 08:21:45.661763 2026] [security2:error] [pid 419508:tid 419704] [client 20.197.192.193:2780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/2352356666.php"] [unique_id "al9WSVcagwCeNbomjVsEPAAAAdE"]
[Tue Jul 21 08:21:45.685840 2026] [security2:error] [pid 419508:tid 419765] [client 65.21.113.253:38394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WSVcagwCeNbomjVsEMgAAAg0"]
[Tue Jul 21 08:21:45.699993 2026] [security2:error] [pid 419508:tid 419712] [client 20.197.192.193:2868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/pn.php"] [unique_id "al9WSVcagwCeNbomjVsEPQAAAdk"]
[Tue Jul 21 08:21:45.745136 2026] [security2:error] [pid 419508:tid 419748] [client 103.106.20.201:60310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WSVcagwCeNbomjVsEPgAAAfw"]
[Tue Jul 21 08:21:45.745229 2026] [security2:error] [pid 419508:tid 419748] [client 103.106.20.201:60310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WSVcagwCeNbomjVsEPgAAAfw"]
[Tue Jul 21 08:21:45.775192 2026] [security2:error] [pid 411857:tid 412087] [client 20.226.60.151:64099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/ssla.php"] [unique_id "al9WSS7ynBpLeKYztQPggAAAAGI"]
[Tue Jul 21 08:21:45.854426 2026] [security2:error] [pid 419508:tid 419764] [client 20.197.192.193:2859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9WSVcagwCeNbomjVsEQQAAAgw"]
[Tue Jul 21 08:21:45.965300 2026] [security2:error] [pid 419508:tid 419688] [client 20.197.192.193:2368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/dr.php"] [unique_id "al9WSVcagwCeNbomjVsERgAAAcE"]
[Tue Jul 21 08:21:46.098445 2026] [security2:error] [pid 411857:tid 412089] [client 62.102.148.158:41026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9WSi7ynBpLeKYztQPghQAAAGQ"]
[Tue Jul 21 08:21:46.098549 2026] [security2:error] [pid 411857:tid 412089] [client 62.102.148.158:41026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9WSi7ynBpLeKYztQPghQAAAGQ"]
[Tue Jul 21 08:21:46.100076 2026] [security2:error] [pid 419508:tid 419751] [client 20.226.60.151:64019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/solo1.php"] [unique_id "al9WSlcagwCeNbomjVsETwAAAf8"]
[Tue Jul 21 08:21:46.126319 2026] [security2:error] [pid 419508:tid 419715] [client 20.197.192.193:2841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/2x.php"] [unique_id "al9WSlcagwCeNbomjVsEUgAAAdw"]
[Tue Jul 21 08:21:46.210942 2026] [security2:error] [pid 419508:tid 419670] [client 20.197.192.193:2772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/kq1.php"] [unique_id "al9WSlcagwCeNbomjVsEVAAAAa8"]
[Tue Jul 21 08:21:46.340007 2026] [security2:error] [pid 418108:tid 418351] [client 20.197.192.193:2838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/zzz.php"] [unique_id "al9WSg0cxofL2J1zwYrCAwAAAXk"]
[Tue Jul 21 08:21:46.386926 2026] [security2:error] [pid 419508:tid 419758] [client 20.151.10.161:50836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/classwithtostring.php"] [unique_id "al9WSlcagwCeNbomjVsEVQAAAgY"]
[Tue Jul 21 08:21:46.465865 2026] [security2:error] [pid 419508:tid 419727] [client 20.197.192.193:2763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/wicked.php"] [unique_id "al9WSlcagwCeNbomjVsEVgAAAeg"]
[Tue Jul 21 08:21:46.549746 2026] [security2:error] [pid 419508:tid 419756] [client 111.93.58.162:32977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WSlcagwCeNbomjVsEXgAAAgQ"]
[Tue Jul 21 08:21:46.549850 2026] [security2:error] [pid 419508:tid 419756] [client 111.93.58.162:32977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WSlcagwCeNbomjVsEXgAAAgQ"]
[Tue Jul 21 08:21:46.599522 2026] [security2:error] [pid 419508:tid 419651] [client 20.197.192.193:2849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/edit.php"] [unique_id "al9WSlcagwCeNbomjVsEYAAAAZw"]
[Tue Jul 21 08:21:46.757540 2026] [security2:error] [pid 419508:tid 419639] [client 20.197.192.193:2828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/kua.php"] [unique_id "al9WSlcagwCeNbomjVsEYQAAAZA"]
[Tue Jul 21 08:21:46.834528 2026] [security2:error] [pid 419508:tid 419704] [client 20.226.60.151:64108] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-includes/assets/"] [unique_id "al9WSlcagwCeNbomjVsEZAAAAdE"]
[Tue Jul 21 08:21:46.955264 2026] [security2:error] [pid 411857:tid 412042] [client 216.73.160.31:49735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9WSi7ynBpLeKYztQPgjgAAADU"]
[Tue Jul 21 08:21:47.025860 2026] [security2:error] [pid 419508:tid 419658] [client 20.197.192.193:2767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/ez.php"] [unique_id "al9WS1cagwCeNbomjVsEbgAAAaM"]
[Tue Jul 21 08:21:47.084115 2026] [security2:error] [pid 411857:tid 412013] [client 20.226.60.151:64113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.seaportservicos.com.br"] [uri "/zc-131.php"] [unique_id "al9WSy7ynBpLeKYztQPglAAAABg"]
[Tue Jul 21 08:21:47.084470 2026] [security2:error] [pid 419508:tid 419719] [client 20.197.192.193:2818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/fz.php"] [unique_id "al9WS1cagwCeNbomjVsEbwAAAeA"]
[Tue Jul 21 08:21:47.110163 2026] [security2:error] [pid 419508:tid 419669] [client 20.197.192.193:2835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/la.php"] [unique_id "al9WS1cagwCeNbomjVsEcQAAAa4"]
[Tue Jul 21 08:21:47.110264 2026] [security2:error] [pid 419508:tid 419653] [client 152.59.34.51:60469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WS1cagwCeNbomjVsEcAAAAZ4"]
[Tue Jul 21 08:21:47.110374 2026] [security2:error] [pid 419508:tid 419653] [client 152.59.34.51:60469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WS1cagwCeNbomjVsEcAAAAZ4"]
[Tue Jul 21 08:21:47.124263 2026] [security2:error] [pid 411857:tid 412021] [client 20.197.192.193:2817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9WSy7ynBpLeKYztQPglgAAACA"]
[Tue Jul 21 08:21:47.176801 2026] [security2:error] [pid 411857:tid 412032] [client 20.197.192.193:2785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/inso.php"] [unique_id "al9WSy7ynBpLeKYztQPglwAAACs"]
[Tue Jul 21 08:21:47.237481 2026] [security2:error] [pid 411857:tid 412055] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/bless.php"] [unique_id "al9WSy7ynBpLeKYztQPgmAAAAEI"], referer: http://sobradoimoveis.com.br/bless.php#888xyz999
[Tue Jul 21 08:21:47.273161 2026] [security2:error] [pid 419508:tid 419722] [client 74.249.245.134:44124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/date.php"] [unique_id "al9WS1cagwCeNbomjVsEeQAAAeM"]
[Tue Jul 21 08:21:47.276410 2026] [security2:error] [pid 411857:tid 411998] [client 20.197.192.193:2768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/wpx.php"] [unique_id "al9WSy7ynBpLeKYztQPgmQAAAAk"]
[Tue Jul 21 08:21:47.348691 2026] [security2:error] [pid 418108:tid 418318] [client 20.197.192.193:2845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/berlin.php"] [unique_id "al9WSw0cxofL2J1zwYrCBgAAAVg"]
[Tue Jul 21 08:21:47.381998 2026] [security2:error] [pid 411857:tid 412101] [client 20.197.192.193:2786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/billur.php"] [unique_id "al9WSy7ynBpLeKYztQPgmgAAAHA"]
[Tue Jul 21 08:21:47.416129 2026] [security2:error] [pid 411857:tid 412028] [client 20.197.192.193:2836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/mimpi.php"] [unique_id "al9WSy7ynBpLeKYztQPgmwAAACc"]
[Tue Jul 21 08:21:47.453008 2026] [security2:error] [pid 419508:tid 419736] [client 20.197.192.193:2854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/dp.php"] [unique_id "al9WS1cagwCeNbomjVsEewAAAfE"]
[Tue Jul 21 08:21:47.508736 2026] [security2:error] [pid 419508:tid 419670] [client 20.197.192.193:2758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/bootstrap.php"] [unique_id "al9WS1cagwCeNbomjVsEgQAAAa8"]
[Tue Jul 21 08:21:47.527515 2026] [security2:error] [pid 419508:tid 419664] [client 120.56.162.40:50144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WS1cagwCeNbomjVsEggAAAak"]
[Tue Jul 21 08:21:47.527612 2026] [security2:error] [pid 419508:tid 419664] [client 120.56.162.40:50144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WS1cagwCeNbomjVsEggAAAak"]
[Tue Jul 21 08:21:47.541442 2026] [security2:error] [pid 419508:tid 419708] [client 20.197.192.193:2842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/wp-editor.php"] [unique_id "al9WS1cagwCeNbomjVsEhAAAAdU"]
[Tue Jul 21 08:21:47.630010 2026] [security2:error] [pid 419508:tid 419727] [client 20.197.192.193:2864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/cro.php"] [unique_id "al9WS1cagwCeNbomjVsEjQAAAeg"]
[Tue Jul 21 08:21:47.634457 2026] [security2:error] [pid 418108:tid 418278] [client 216.73.160.176:45821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9WSw0cxofL2J1zwYrCBwAAATA"]
[Tue Jul 21 08:21:47.645127 2026] [security2:error] [pid 419508:tid 419677] [client 65.21.113.253:38394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WS1cagwCeNbomjVsEcwAAAbY"]
[Tue Jul 21 08:21:47.667947 2026] [security2:error] [pid 411857:tid 412071] [client 20.197.192.193:2807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/cron-tab.php"] [unique_id "al9WSy7ynBpLeKYztQPgoQAAAFI"]
[Tue Jul 21 08:21:47.715128 2026] [security2:error] [pid 419508:tid 419703] [client 20.197.192.193:2861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/koiy.php"] [unique_id "al9WS1cagwCeNbomjVsEjgAAAdA"]
[Tue Jul 21 08:21:47.789703 2026] [security2:error] [pid 411857:tid 412097] [client 20.197.192.193:2788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/hp2.php"] [unique_id "al9WSy7ynBpLeKYztQPgpAAAAGw"]
[Tue Jul 21 08:21:47.817956 2026] [security2:error] [pid 418108:tid 418179] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WSw0cxofL2J1zwYrCCAABVkQ"]
[Tue Jul 21 08:21:47.818113 2026] [security2:error] [pid 418108:tid 418316] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WSw0cxofL2J1zwYrCCAABVkQ"]
[Tue Jul 21 08:21:47.900264 2026] [security2:error] [pid 419508:tid 419714] [client 20.197.192.193:2850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/hp3.php"] [unique_id "al9WS1cagwCeNbomjVsEjwAAAds"]
[Tue Jul 21 08:21:47.976947 2026] [security2:error] [pid 411857:tid 412073] [client 216.73.160.44:29001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9WSi7ynBpLeKYztQPgjwAAAFQ"]
[Tue Jul 21 08:21:48.114135 2026] [security2:error] [pid 411857:tid 412083] [client 20.197.192.193:2796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/aa1.php"] [unique_id "al9WTC7ynBpLeKYztQPgqgAAAF4"]
[Tue Jul 21 08:21:48.151854 2026] [security2:error] [pid 419508:tid 419647] [client 20.197.192.193:2840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/acew67.php"] [unique_id "al9WTFcagwCeNbomjVsEkwAAAZg"]
[Tue Jul 21 08:21:48.251361 2026] [security2:error] [pid 419508:tid 419672] [client 20.226.60.151:59272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/cong.php"] [unique_id "al9WTFcagwCeNbomjVsElAAAAbE"]
[Tue Jul 21 08:21:48.256835 2026] [security2:error] [pid 419508:tid 419639] [client 20.197.192.193:2762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/bscclapb.php"] [unique_id "al9WTFcagwCeNbomjVsElQAAAZA"]
[Tue Jul 21 08:21:48.478261 2026] [security2:error] [pid 419508:tid 419676] [client 20.197.192.193:2829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/else1.php"] [unique_id "al9WTFcagwCeNbomjVsEmgAAAbU"]
[Tue Jul 21 08:21:48.571759 2026] [security2:error] [pid 419508:tid 419762] [client 20.197.192.193:2875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/tkikikoko.php"] [unique_id "al9WTFcagwCeNbomjVsEnQAAAgo"]
[Tue Jul 21 08:21:48.623038 2026] [security2:error] [pid 418108:tid 418117] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WTA0cxofL2J1zwYrCDgABKgY"]
[Tue Jul 21 08:21:48.623225 2026] [security2:error] [pid 418108:tid 418272] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WTA0cxofL2J1zwYrCDgABKgY"]
[Tue Jul 21 08:21:48.642090 2026] [security2:error] [pid 411857:tid 412027] [client 216.73.160.190:33011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9WSy7ynBpLeKYztQPgoAAAACY"]
[Tue Jul 21 08:21:48.662929 2026] [security2:error] [pid 418108:tid 418277] [client 20.197.192.193:2770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9WTA0cxofL2J1zwYrCDwAAAS8"]
[Tue Jul 21 08:21:48.787925 2026] [security2:error] [pid 411857:tid 412049] [client 20.197.192.193:2760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/wp-css.php"] [unique_id "al9WTC7ynBpLeKYztQPgtgAAADw"]
[Tue Jul 21 08:21:48.846845 2026] [security2:error] [pid 419508:tid 419722] [client 20.197.192.193:2753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/wp-explorer.php"] [unique_id "al9WTFcagwCeNbomjVsEoQAAAeM"]
[Tue Jul 21 08:21:48.877241 2026] [security2:error] [pid 419508:tid 419754] [client 20.197.192.193:2821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/akismet.php"] [unique_id "al9WTFcagwCeNbomjVsEowAAAgI"]
[Tue Jul 21 08:21:48.906514 2026] [security2:error] [pid 419508:tid 419673] [client 20.197.192.193:2787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/ace2.php"] [unique_id "al9WTFcagwCeNbomjVsEpAAAAbI"]
[Tue Jul 21 08:21:48.950206 2026] [security2:error] [pid 419508:tid 419698] [client 20.197.192.193:2803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.garciaeventuraadvocacia.com.br"] [uri "/ms.php"] [unique_id "al9WTFcagwCeNbomjVsEpgAAAcs"]
[Tue Jul 21 08:21:48.976634 2026] [security2:error] [pid 411857:tid 412093] [client 115.134.11.136:53743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WTC7ynBpLeKYztQPgtwAAAGg"]
[Tue Jul 21 08:21:48.976760 2026] [security2:error] [pid 411857:tid 412093] [client 115.134.11.136:53743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WTC7ynBpLeKYztQPgtwAAAGg"]
[Tue Jul 21 08:21:49.064430 2026] [security2:error] [pid 418108:tid 418243] [client 154.208.47.43:7733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WTQ0cxofL2J1zwYrCEQAAAQ0"]
[Tue Jul 21 08:21:49.064567 2026] [security2:error] [pid 418108:tid 418243] [client 154.208.47.43:7733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WTQ0cxofL2J1zwYrCEQAAAQ0"]
[Tue Jul 21 08:21:49.105300 2026] [security2:error] [pid 411857:tid 411966] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WSy7ynBpLeKYztQPgpQAAYWo"]
[Tue Jul 21 08:21:49.105507 2026] [security2:error] [pid 411857:tid 412086] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WSy7ynBpLeKYztQPgpQAAYWo"]
[Tue Jul 21 08:21:49.272743 2026] [security2:error] [pid 418108:tid 418275] [client 187.125.243.197:50519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WTQ0cxofL2J1zwYrCEwAAAS0"]
[Tue Jul 21 08:21:49.273023 2026] [security2:error] [pid 418108:tid 418275] [client 187.125.243.197:50519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WTQ0cxofL2J1zwYrCEwAAAS0"]
[Tue Jul 21 08:21:49.386589 2026] [security2:error] [pid 411857:tid 412068] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/class-t.api.php"] [unique_id "al9WTS7ynBpLeKYztQPgvgAAAE8"], referer: http://sobradoimoveis.com.br/class-t.api.php#888xyz999
[Tue Jul 21 08:21:49.499325 2026] [log_config:warn] [pid 352421:tid 352618] (32)Broken pipe: [client 123.136.25.128:19633] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:21:49.499341 2026] [log_config:warn] [pid 352421:tid 352618] (32)Broken pipe: [client 123.136.25.128:19633] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:21:49.550771 2026] [security2:error] [pid 418108:tid 418252] [client 20.226.60.151:59270] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-includes/css/"] [unique_id "al9WTQ0cxofL2J1zwYrCFgAAARY"]
[Tue Jul 21 08:21:49.839454 2026] [security2:error] [pid 419508:tid 419665] [client 81.171.74.60:54800] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/"] [unique_id "al9WTVcagwCeNbomjVsEtQAAAao"]
[Tue Jul 21 08:21:49.841342 2026] [security2:error] [pid 419508:tid 419638] [client 81.171.74.60:54796] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/"] [unique_id "al9WTVcagwCeNbomjVsEtgAAAY8"]
[Tue Jul 21 08:21:49.842101 2026] [security2:error] [pid 419508:tid 419650] [client 81.171.74.60:54810] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/"] [unique_id "al9WTVcagwCeNbomjVsEtwAAAZs"]
[Tue Jul 21 08:21:50.014710 2026] [security2:error] [pid 419508:tid 419730] [client 20.151.10.161:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-links.php"] [unique_id "al9WTlcagwCeNbomjVsEuAAAAes"]
[Tue Jul 21 08:21:50.027162 2026] [security2:error] [pid 419508:tid 419668] [client 20.226.60.151:60596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/classwithtostring.php"] [unique_id "al9WTlcagwCeNbomjVsEuQAAAa0"]
[Tue Jul 21 08:21:50.039556 2026] [security2:error] [pid 411857:tid 412007] [client 20.151.10.161:50729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9WTi7ynBpLeKYztQPgxgAAABI"]
[Tue Jul 21 08:21:50.132172 2026] [security2:error] [pid 411857:tid 412052] [client 74.249.245.134:51268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/pomo.php"] [unique_id "al9WTi7ynBpLeKYztQPgygAAAD8"]
[Tue Jul 21 08:21:50.407628 2026] [security2:error] [pid 418108:tid 418241] [client 20.226.60.151:60661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/root.php"] [unique_id "al9WTg0cxofL2J1zwYrCGQAAAQs"]
[Tue Jul 21 08:21:50.471289 2026] [security2:error] [pid 419508:tid 419706] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/blurbs.php"] [unique_id "al9WTlcagwCeNbomjVsEwAAAAdM"], referer: http://sobradoimoveis.com.br/blurbs.php#888xyz999
[Tue Jul 21 08:21:50.550454 2026] [security2:error] [pid 419508:tid 419696] [client 20.226.60.151:60635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/sym403.php"] [unique_id "al9WTlcagwCeNbomjVsEwgAAAck"]
[Tue Jul 21 08:21:50.666142 2026] [security2:error] [pid 418108:tid 418294] [client 20.226.60.151:60547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/v543.php"] [unique_id "al9WTg0cxofL2J1zwYrCIAAAAUA"]
[Tue Jul 21 08:21:50.688145 2026] [security2:error] [pid 419508:tid 419645] [client 65.21.113.253:38394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WTlcagwCeNbomjVsEvQAAAZY"]
[Tue Jul 21 08:21:50.811824 2026] [security2:error] [pid 419508:tid 419748] [client 81.171.74.60:54824] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9WTlcagwCeNbomjVsEywAAAfw"]
[Tue Jul 21 08:21:50.813939 2026] [security2:error] [pid 411857:tid 412021] [client 81.171.74.60:54834] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9WTi7ynBpLeKYztQPg1gAAACA"]
[Tue Jul 21 08:21:50.815016 2026] [security2:error] [pid 419508:tid 419641] [client 81.171.74.60:54814] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9WTlcagwCeNbomjVsEzAAAAZI"]
[Tue Jul 21 08:21:50.815016 2026] [security2:error] [pid 418108:tid 418260] [client 81.171.74.60:54822] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9WTg0cxofL2J1zwYrCIgAAAR4"]
[Tue Jul 21 08:21:50.926846 2026] [security2:error] [pid 411857:tid 412028] [client 20.226.60.151:59304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/public/css.php"] [unique_id "al9WTi7ynBpLeKYztQPg2QAAACc"]
[Tue Jul 21 08:21:50.928414 2026] [security2:error] [pid 418108:tid 418334] [client 20.226.60.151:60631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/sixxis.php"] [unique_id "al9WTg0cxofL2J1zwYrCJAAAAWg"]
[Tue Jul 21 08:21:51.291015 2026] [security2:error] [pid 418108:tid 418329] [client 20.226.60.151:64116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/output.php"] [unique_id "al9WTw0cxofL2J1zwYrCJgAAAWM"]
[Tue Jul 21 08:21:51.699105 2026] [security2:error] [pid 419508:tid 419664] [client 38.100.221.102:18214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.221.100.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WT1cagwCeNbomjVsE1wAAAak"]
[Tue Jul 21 08:21:51.699288 2026] [security2:error] [pid 419508:tid 419664] [client 38.100.221.102:18214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WT1cagwCeNbomjVsE1wAAAak"]
[Tue Jul 21 08:21:51.788071 2026] [security2:error] [pid 411857:tid 412034] [client 81.171.74.60:54912] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/.env"] [unique_id "al9WTy7ynBpLeKYztQPg6gAAAC0"]
[Tue Jul 21 08:21:51.789558 2026] [security2:error] [pid 419508:tid 419714] [client 81.171.74.60:54926] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/api/.env"] [unique_id "al9WT1cagwCeNbomjVsE2AAAAds"]
[Tue Jul 21 08:21:51.792035 2026] [security2:error] [pid 411857:tid 412025] [client 81.171.74.60:54862] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/phpinfo.php"] [unique_id "al9WTy7ynBpLeKYztQPg6wAAACQ"]
[Tue Jul 21 08:21:51.990483 2026] [security2:error] [pid 419508:tid 419638] [client 81.171.74.60:54896] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/user_secrets.yml"] [unique_id "al9WT1cagwCeNbomjVsE3AAAAY8"]
[Tue Jul 21 08:21:51.991286 2026] [security2:error] [pid 419508:tid 419665] [client 81.171.74.60:54846] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/docker-compose.yml"] [unique_id "al9WT1cagwCeNbomjVsE3QAAAao"]
[Tue Jul 21 08:21:51.994781 2026] [security2:error] [pid 419508:tid 419716] [client 81.171.74.60:54876] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/.env.production"] [unique_id "al9WT1cagwCeNbomjVsE3gAAAd0"]
[Tue Jul 21 08:21:51.999546 2026] [security2:error] [pid 419508:tid 419668] [client 173.252.95.31:36832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9WT1cagwCeNbomjVsE2QAAAa0"]
[Tue Jul 21 08:21:52.063181 2026] [security2:error] [pid 419508:tid 419704] [client 20.226.60.151:50146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/ip.php"] [unique_id "al9WUFcagwCeNbomjVsE4AAAAdE"]
[Tue Jul 21 08:21:52.159044 2026] [security2:error] [pid 419508:tid 419703] [client 223.181.60.88:30778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WUFcagwCeNbomjVsE4QAAAdA"]
[Tue Jul 21 08:21:52.159220 2026] [security2:error] [pid 419508:tid 419703] [client 223.181.60.88:30778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WUFcagwCeNbomjVsE4QAAAdA"]
[Tue Jul 21 08:21:52.376194 2026] [security2:error] [pid 411857:tid 412011] [client 20.226.60.151:59320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-file-120.php"] [unique_id "al9WUC7ynBpLeKYztQPg9AAAABY"]
[Tue Jul 21 08:21:52.388096 2026] [security2:error] [pid 418108:tid 418360] [client 61.1.167.83:50469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUA0cxofL2J1zwYrCLAAAAYI"]
[Tue Jul 21 08:21:52.388196 2026] [security2:error] [pid 418108:tid 418360] [client 61.1.167.83:50469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUA0cxofL2J1zwYrCLAAAAYI"]
[Tue Jul 21 08:21:52.554301 2026] [security2:error] [pid 411857:tid 412083] [client 81.171.74.60:54892] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/.git/HEAD"] [unique_id "al9WUC7ynBpLeKYztQPg-QAAAF4"]
[Tue Jul 21 08:21:52.597045 2026] [security2:error] [pid 411857:tid 412088] [client 173.252.95.30:63516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9WUC7ynBpLeKYztQPg-gAAAGM"]
[Tue Jul 21 08:21:52.967136 2026] [security2:error] [pid 419508:tid 419695] [client 81.171.74.60:54942] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/config/production.json"] [unique_id "al9WUFcagwCeNbomjVsE8QAAAcg"]
[Tue Jul 21 08:21:52.968017 2026] [security2:error] [pid 419508:tid 419754] [client 81.171.74.60:54964] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/server.key"] [unique_id "al9WUFcagwCeNbomjVsE8gAAAgI"]
[Tue Jul 21 08:21:52.968217 2026] [security2:error] [pid 419508:tid 419728] [client 81.171.74.60:54980] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9WUFcagwCeNbomjVsE8wAAAek"]
[Tue Jul 21 08:21:52.968571 2026] [security2:error] [pid 411857:tid 412010] [client 81.171.74.60:54994] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/secrets.json"] [unique_id "al9WUC7ynBpLeKYztQPhAAAAABU"]
[Tue Jul 21 08:21:53.004432 2026] [security2:error] [pid 411857:tid 411981] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUS7ynBpLeKYztQPhBAAAVnk"]
[Tue Jul 21 08:21:53.004597 2026] [security2:error] [pid 411857:tid 412075] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUS7ynBpLeKYztQPhBAAAVnk"]
[Tue Jul 21 08:21:53.047137 2026] [security2:error] [pid 419508:tid 419751] [client 20.226.60.151:64057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/special.php"] [unique_id "al9WUVcagwCeNbomjVsE9AAAAf8"]
[Tue Jul 21 08:21:53.168676 2026] [security2:error] [pid 419508:tid 419729] [client 81.171.74.60:54948] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/.bash_history"] [unique_id "al9WUVcagwCeNbomjVsE9gAAAeo"]
[Tue Jul 21 08:21:53.274238 2026] [security2:error] [pid 411857:tid 412092] [client 152.59.34.51:60917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WUS7ynBpLeKYztQPhCAAAAGc"]
[Tue Jul 21 08:21:53.274423 2026] [security2:error] [pid 411857:tid 412092] [client 152.59.34.51:60917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WUS7ynBpLeKYztQPhCAAAAGc"]
[Tue Jul 21 08:21:53.320004 2026] [security2:error] [pid 419508:tid 419673] [client 65.21.113.253:38394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WUVcagwCeNbomjVsE9QAAAbI"]
[Tue Jul 21 08:21:53.489328 2026] [security2:error] [pid 419508:tid 419532] [remote 160.187.68.132:51694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/wp-login.php"] [unique_id "al9WUVcagwCeNbomjVsE-QAB_Bc"]
[Tue Jul 21 08:21:53.492884 2026] [security2:error] [pid 419508:tid 419732] [client 74.249.245.134:58831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/test1.php"] [unique_id "al9WUVcagwCeNbomjVsE-gAAAe0"]
[Tue Jul 21 08:21:53.636604 2026] [security2:error] [pid 411857:tid 412021] [client 20.206.105.145:20113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/k4.php"] [unique_id "al9WUS7ynBpLeKYztQPhEwAAACA"]
[Tue Jul 21 08:21:53.781967 2026] [security2:error] [pid 419508:tid 419724] [client 20.151.10.161:50853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wp-blog.php"] [unique_id "al9WUVcagwCeNbomjVsE_QAAAeU"]
[Tue Jul 21 08:21:53.817677 2026] [security2:error] [pid 419508:tid 419650] [client 20.220.225.223:34729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9WUVcagwCeNbomjVsE_gAAAZs"]
[Tue Jul 21 08:21:53.943557 2026] [security2:error] [pid 419508:tid 419733] [client 81.171.74.60:38802] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/wp-config.php"] [unique_id "al9WUVcagwCeNbomjVsFBAAAAe4"]
[Tue Jul 21 08:21:53.944496 2026] [security2:error] [pid 419508:tid 419727] [client 81.171.74.60:38818] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/.npmrc"] [unique_id "al9WUVcagwCeNbomjVsFBQAAAeg"]
[Tue Jul 21 08:21:53.945664 2026] [security2:error] [pid 419508:tid 419744] [client 81.171.74.60:38842] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/config.xml"] [unique_id "al9WUVcagwCeNbomjVsFBgAAAfg"]
[Tue Jul 21 08:21:53.947214 2026] [security2:error] [pid 419508:tid 419699] [client 81.171.74.60:38848] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/config.php"] [unique_id "al9WUVcagwCeNbomjVsFBwAAAcw"]
[Tue Jul 21 08:21:54.092215 2026] [security2:error] [pid 419508:tid 419668] [client 20.151.10.161:45989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9WUlcagwCeNbomjVsFCgAAAa0"]
[Tue Jul 21 08:21:54.141563 2026] [security2:error] [pid 419508:tid 419757] [client 20.226.60.151:59077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/as.php"] [unique_id "al9WUlcagwCeNbomjVsFCwAAAgU"]
[Tue Jul 21 08:21:54.147221 2026] [security2:error] [pid 419508:tid 419663] [client 81.171.74.60:38828] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/dump.sql"] [unique_id "al9WUlcagwCeNbomjVsFDAAAAag"]
[Tue Jul 21 08:21:54.148349 2026] [security2:error] [pid 419508:tid 419752] [client 81.171.74.60:38810] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/backup.sql"] [unique_id "al9WUlcagwCeNbomjVsFDQAAAgA"]
[Tue Jul 21 08:21:54.306218 2026] [security2:error] [pid 411857:tid 412001] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/akcc.php"] [unique_id "al9WUi7ynBpLeKYztQPhIAAAAAw"], referer: http://sobradoimoveis.com.br/akcc.php
[Tue Jul 21 08:21:54.342746 2026] [security2:error] [pid 418108:tid 418362] [client 202.179.75.202:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WUg0cxofL2J1zwYrCLgAAAYQ"]
[Tue Jul 21 08:21:54.342968 2026] [security2:error] [pid 418108:tid 418362] [client 202.179.75.202:59182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WUg0cxofL2J1zwYrCLgAAAYQ"]
[Tue Jul 21 08:21:54.351625 2026] [security2:error] [pid 411857:tid 411991] [client 62.102.148.158:52138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9WUi7ynBpLeKYztQPhIgAAAAI"]
[Tue Jul 21 08:21:54.351802 2026] [security2:error] [pid 411857:tid 411991] [client 62.102.148.158:52138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9WUi7ynBpLeKYztQPhIgAAAAI"]
[Tue Jul 21 08:21:54.421665 2026] [security2:error] [pid 419508:tid 419694] [client 173.252.95.24:56336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9WUVcagwCeNbomjVsE-AAAAcc"]
[Tue Jul 21 08:21:54.551927 2026] [security2:error] [pid 411857:tid 412114] [client 87.116.180.198:27257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUi7ynBpLeKYztQPhKQAAAH0"]
[Tue Jul 21 08:21:54.552053 2026] [security2:error] [pid 411857:tid 412114] [client 87.116.180.198:27257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUi7ynBpLeKYztQPhKQAAAH0"]
[Tue Jul 21 08:21:54.862469 2026] [security2:error] [pid 411857:tid 412061] [client 117.213.202.34:60645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUS7ynBpLeKYztQPhFQAAAEg"]
[Tue Jul 21 08:21:54.862640 2026] [security2:error] [pid 411857:tid 412061] [client 117.213.202.34:60645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUS7ynBpLeKYztQPhFQAAAEg"]
[Tue Jul 21 08:21:54.895809 2026] [security2:error] [pid 419508:tid 419671] [client 150.129.202.39:65053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUlcagwCeNbomjVsFEAAAAbA"]
[Tue Jul 21 08:21:54.895971 2026] [security2:error] [pid 419508:tid 419671] [client 150.129.202.39:65053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUlcagwCeNbomjVsFEAAAAbA"]
[Tue Jul 21 08:21:54.917524 2026] [security2:error] [pid 419508:tid 419658] [client 81.171.74.60:38912] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/backup.tar.gz"] [unique_id "al9WUlcagwCeNbomjVsFEQAAAaM"]
[Tue Jul 21 08:21:54.917911 2026] [security2:error] [pid 411857:tid 412000] [client 81.171.74.60:38926] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/database.sql"] [unique_id "al9WUi7ynBpLeKYztQPhLwAAAAs"]
[Tue Jul 21 08:21:54.920545 2026] [security2:error] [pid 419508:tid 419712] [client 81.171.74.60:38902] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/database_backup.sql"] [unique_id "al9WUlcagwCeNbomjVsFEgAAAdk"]
[Tue Jul 21 08:21:54.921244 2026] [security2:error] [pid 411857:tid 412040] [client 81.171.74.60:38878] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/backup.zip"] [unique_id "al9WUi7ynBpLeKYztQPhMAAAADM"]
[Tue Jul 21 08:21:54.950838 2026] [security2:error] [pid 411857:tid 412039] [client 103.151.46.103:63812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WUi7ynBpLeKYztQPhMgAAADI"]
[Tue Jul 21 08:21:54.950927 2026] [security2:error] [pid 411857:tid 412039] [client 103.151.46.103:63812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WUi7ynBpLeKYztQPhMgAAADI"]
[Tue Jul 21 08:21:54.965682 2026] [security2:error] [pid 418108:tid 418276] [client 117.210.135.0:62753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.135.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUg0cxofL2J1zwYrCMQAAAS4"]
[Tue Jul 21 08:21:54.965762 2026] [security2:error] [pid 418108:tid 418276] [client 117.210.135.0:62753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mastertork.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUg0cxofL2J1zwYrCMQAAAS4"]
[Tue Jul 21 08:21:55.004271 2026] [security2:error] [pid 411857:tid 412066] [client 195.49.128.211:52057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WUy7ynBpLeKYztQPhMwAAAE0"]
[Tue Jul 21 08:21:55.004405 2026] [security2:error] [pid 411857:tid 412066] [client 195.49.128.211:52057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WUy7ynBpLeKYztQPhMwAAAE0"]
[Tue Jul 21 08:21:55.059196 2026] [security2:error] [pid 419508:tid 419669] [client 173.252.95.16:49468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9WU1cagwCeNbomjVsFFwAAAa4"]
[Tue Jul 21 08:21:55.096016 2026] [security2:error] [pid 411857:tid 412109] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/abcd.php"] [unique_id "al9WUy7ynBpLeKYztQPhOQAAAHg"], referer: http://sobradoimoveis.com.br/abcd.php
[Tue Jul 21 08:21:55.112401 2026] [security2:error] [pid 411857:tid 412078] [client 20.151.10.161:45990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.cmpartners.com.br"] [uri "/aaa.php"] [unique_id "al9WUy7ynBpLeKYztQPhOgAAAFk"]
[Tue Jul 21 08:21:55.119032 2026] [security2:error] [pid 419508:tid 419719] [client 14.245.224.124:58738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WU1cagwCeNbomjVsFGAAAAeA"]
[Tue Jul 21 08:21:55.119165 2026] [security2:error] [pid 419508:tid 419719] [client 14.245.224.124:58738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WU1cagwCeNbomjVsFGAAAAeA"]
[Tue Jul 21 08:21:55.124941 2026] [security2:error] [pid 411857:tid 412011] [client 81.171.74.60:38894] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/actuator/heapdump"] [unique_id "al9WUy7ynBpLeKYztQPhOwAAABY"]
[Tue Jul 21 08:21:55.125069 2026] [security2:error] [pid 411857:tid 412103] [client 81.171.74.60:38870] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/.svn/wc.db"] [unique_id "al9WUy7ynBpLeKYztQPhPAAAAHI"]
[Tue Jul 21 08:21:55.265986 2026] [security2:error] [pid 418108:tid 418296] [client 178.136.43.241:28820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.43.136.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jandel.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUw0cxofL2J1zwYrCMgAAAUI"]
[Tue Jul 21 08:21:55.266219 2026] [security2:error] [pid 418108:tid 418296] [client 178.136.43.241:28820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jandel.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUw0cxofL2J1zwYrCMgAAAUI"]
[Tue Jul 21 08:21:55.274728 2026] [autoindex:error] [pid 418108:tid 418307] [client 205.210.31.59:62442] AH01276: Cannot serve directory /home1/bastar15/mirth.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:21:55.323057 2026] [security2:error] [pid 411857:tid 412050] [client 81.171.74.60:38854] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9WUy7ynBpLeKYztQPhQAAAAD0"]
[Tue Jul 21 08:21:55.347286 2026] [security2:error] [pid 411857:tid 412070] [client 151.63.71.144:49620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WUy7ynBpLeKYztQPhQQAAAFE"]
[Tue Jul 21 08:21:55.347543 2026] [security2:error] [pid 411857:tid 412070] [client 151.63.71.144:49620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WUy7ynBpLeKYztQPhQQAAAFE"]
[Tue Jul 21 08:21:55.751785 2026] [security2:error] [pid 411857:tid 412090] [client 81.171.74.60:38934] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9WUy7ynBpLeKYztQPhTwAAAGU"]
[Tue Jul 21 08:21:55.752849 2026] [security2:error] [pid 419508:tid 419732] [client 81.171.74.60:38950] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "look.dealspark.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9WU1cagwCeNbomjVsFHwAAAe0"]
[Tue Jul 21 08:21:55.845440 2026] [security2:error] [pid 418108:tid 418233] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WUw0cxofL2J1zwYrCOgABRHo"]
[Tue Jul 21 08:21:55.845633 2026] [security2:error] [pid 418108:tid 418298] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WUw0cxofL2J1zwYrCOgABRHo"]
[Tue Jul 21 08:21:55.916345 2026] [security2:error] [pid 418108:tid 418150] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUw0cxofL2J1zwYrCOwABXic"]
[Tue Jul 21 08:21:55.916532 2026] [security2:error] [pid 418108:tid 418324] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WUw0cxofL2J1zwYrCOwABXic"]
[Tue Jul 21 08:21:56.389325 2026] [security2:error] [pid 419508:tid 419730] [client 4.194.217.15:1357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/about/function.php"] [unique_id "al9WVFcagwCeNbomjVsFKAAAAes"]
[Tue Jul 21 08:21:56.432350 2026] [security2:error] [pid 419508:tid 419638] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/shelp.php"] [unique_id "al9WVFcagwCeNbomjVsFKQAAAY8"], referer: http://sobradoimoveis.com.br/shelp.php
[Tue Jul 21 08:21:56.443595 2026] [security2:error] [pid 418108:tid 418242] [client 20.226.60.151:59264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/cgi-bin/index.php"] [unique_id "al9WVA0cxofL2J1zwYrCPgAAAQw"]
[Tue Jul 21 08:21:56.452006 2026] [security2:error] [pid 419508:tid 419604] [remote 68.178.165.65:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WVFcagwCeNbomjVsFKgAB-F8"], referer: http://assumaocontrole.com/
[Tue Jul 21 08:21:56.489655 2026] [security2:error] [pid 419508:tid 419680] [client 103.106.20.201:60907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WVFcagwCeNbomjVsFKwAAAbk"]
[Tue Jul 21 08:21:56.489808 2026] [security2:error] [pid 419508:tid 419680] [client 103.106.20.201:60907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WVFcagwCeNbomjVsFKwAAAbk"]
[Tue Jul 21 08:21:56.676332 2026] [security2:error] [pid 419508:tid 419757] [client 20.151.10.161:50866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9WVFcagwCeNbomjVsFLgAAAgU"]
[Tue Jul 21 08:21:57.276041 2026] [security2:error] [pid 411857:tid 412091] [client 137.97.59.154:51927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WVS7ynBpLeKYztQPhcAAAAGY"]
[Tue Jul 21 08:21:57.276305 2026] [security2:error] [pid 411857:tid 412091] [client 137.97.59.154:51927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WVS7ynBpLeKYztQPhcAAAAGY"]
[Tue Jul 21 08:21:57.308416 2026] [security2:error] [pid 419508:tid 419685] [client 20.226.60.151:60648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/kq1.php"] [unique_id "al9WVVcagwCeNbomjVsFNQAAAb4"]
[Tue Jul 21 08:21:57.447295 2026] [security2:error] [pid 411857:tid 412064] [client 4.194.217.15:4103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/admiin.php"] [unique_id "al9WVS7ynBpLeKYztQPhcgAAAEs"]
[Tue Jul 21 08:21:57.651331 2026] [security2:error] [pid 419508:tid 419582] [remote 41.76.214.143:59048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9WVVcagwCeNbomjVsFNwABykk"]
[Tue Jul 21 08:21:57.837642 2026] [security2:error] [pid 411857:tid 412029] [client 20.226.60.151:64064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/w1px.php"] [unique_id "al9WVS7ynBpLeKYztQPhfAAAACg"]
[Tue Jul 21 08:21:57.913409 2026] [security2:error] [pid 419508:tid 419671] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9WVVcagwCeNbomjVsFOgAAAbA"]
[Tue Jul 21 08:21:58.003876 2026] [security2:error] [pid 411857:tid 419454] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WVi7ynBpLeKYztQPhgAAAAYg"]
[Tue Jul 21 08:21:58.004009 2026] [security2:error] [pid 411857:tid 411990] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WVi7ynBpLeKYztQPhgAAAAYg"]
[Tue Jul 21 08:21:58.123025 2026] [security2:error] [pid 411857:tid 412093] [client 120.56.162.40:50649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WVi7ynBpLeKYztQPhhwAAAGg"]
[Tue Jul 21 08:21:58.123164 2026] [security2:error] [pid 411857:tid 412093] [client 120.56.162.40:50649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WVi7ynBpLeKYztQPhhwAAAGg"]
[Tue Jul 21 08:21:58.200930 2026] [security2:error] [pid 411857:tid 412092] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WVi7ynBpLeKYztQPhiAAAAGc"]
[Tue Jul 21 08:21:58.267157 2026] [security2:error] [pid 419508:tid 419626] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WVlcagwCeNbomjVsFOwABwXU"]
[Tue Jul 21 08:21:58.268086 2026] [security2:error] [pid 419508:tid 419688] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WVlcagwCeNbomjVsFOwABwXU"]
[Tue Jul 21 08:21:58.370693 2026] [security2:error] [pid 418108:tid 418359] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/cord.php"] [unique_id "al9WVg0cxofL2J1zwYrCQgAAAYE"], referer: http://sobradoimoveis.com.br/cord.php
[Tue Jul 21 08:21:58.504480 2026] [security2:error] [pid 411857:tid 412081] [client 4.194.217.15:4144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/admin-main/class-wp-http-core.php"] [unique_id "al9WVi7ynBpLeKYztQPhjgAAAFw"]
[Tue Jul 21 08:21:58.518048 2026] [security2:error] [pid 411857:tid 412113] [client 74.249.245.134:51308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/fw.php"] [unique_id "al9WVi7ynBpLeKYztQPhkAAAAHw"]
[Tue Jul 21 08:21:58.642361 2026] [security2:error] [pid 411857:tid 411991] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9WVi7ynBpLeKYztQPhlwAAAAI"]
[Tue Jul 21 08:21:58.926462 2026] [security2:error] [pid 411857:tid 412067] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9WVi7ynBpLeKYztQPhngAAAE4"]
[Tue Jul 21 08:21:59.138197 2026] [security2:error] [pid 419508:tid 419655] [client 20.226.60.151:59081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/yawa.php"] [unique_id "al9WV1cagwCeNbomjVsFQQAAAaA"]
[Tue Jul 21 08:21:59.211434 2026] [security2:error] [pid 419508:tid 419729] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9WV1cagwCeNbomjVsFQgAAAeo"]
[Tue Jul 21 08:21:59.294709 2026] [security2:error] [pid 419508:tid 419595] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WV1cagwCeNbomjVsFQwABpVY"]
[Tue Jul 21 08:21:59.295102 2026] [security2:error] [pid 419508:tid 419660] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WV1cagwCeNbomjVsFQwABpVY"]
[Tue Jul 21 08:21:59.468114 2026] [security2:error] [pid 411857:tid 412030] [client 115.134.11.136:54200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WVy7ynBpLeKYztQPhqwAAACk"]
[Tue Jul 21 08:21:59.469021 2026] [security2:error] [pid 411857:tid 412030] [client 115.134.11.136:54200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WVy7ynBpLeKYztQPhqwAAACk"]
[Tue Jul 21 08:21:59.495121 2026] [security2:error] [pid 418108:tid 418313] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9WVw0cxofL2J1zwYrCRAAAAVM"]
[Tue Jul 21 08:21:59.573189 2026] [security2:error] [pid 419508:tid 419753] [client 4.194.217.15:4216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/admin-post.php"] [unique_id "al9WV1cagwCeNbomjVsFRAAAAgE"]
[Tue Jul 21 08:21:59.658244 2026] [security2:error] [pid 411857:tid 412078] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/dex.php"] [unique_id "al9WVy7ynBpLeKYztQPhsgAAAFk"], referer: http://sobradoimoveis.com.br/dex.php
[Tue Jul 21 08:21:59.729991 2026] [security2:error] [pid 419508:tid 419649] [client 187.125.243.197:51017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WV1cagwCeNbomjVsFRQAAAZo"]
[Tue Jul 21 08:21:59.730287 2026] [security2:error] [pid 419508:tid 419649] [client 187.125.243.197:51017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WV1cagwCeNbomjVsFRQAAAZo"]
[Tue Jul 21 08:21:59.780471 2026] [security2:error] [pid 419508:tid 419705] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9WV1cagwCeNbomjVsFRgAAAdI"]
[Tue Jul 21 08:21:59.992445 2026] [security2:error] [pid 411857:tid 412010] [client 20.226.60.151:59104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/js.php"] [unique_id "al9WVy7ynBpLeKYztQPhtAAAABU"]
[Tue Jul 21 08:22:00.064801 2026] [security2:error] [pid 419508:tid 419736] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9WWFcagwCeNbomjVsFSwAAAfE"]
[Tue Jul 21 08:22:00.353998 2026] [security2:error] [pid 419508:tid 419638] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9WWFcagwCeNbomjVsFTwAAAY8"]
[Tue Jul 21 08:22:00.504460 2026] [security2:error] [pid 419508:tid 419716] [client 20.151.10.161:50747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/adminfuns.php"] [unique_id "al9WWFcagwCeNbomjVsFUQAAAd0"]
[Tue Jul 21 08:22:00.633276 2026] [security2:error] [pid 411857:tid 412029] [client 4.194.217.15:4149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/admin.php"] [unique_id "al9WWC7ynBpLeKYztQPhwQAAACg"]
[Tue Jul 21 08:22:00.639805 2026] [security2:error] [pid 411857:tid 412038] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9WWC7ynBpLeKYztQPhwgAAADE"]
[Tue Jul 21 08:22:00.827983 2026] [security2:error] [pid 418108:tid 418344] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/zwso.php"] [unique_id "al9WWA0cxofL2J1zwYrCTAAAAXI"], referer: http://sobradoimoveis.com.br//zwso.php
[Tue Jul 21 08:22:00.929856 2026] [security2:error] [pid 419508:tid 419704] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9WWFcagwCeNbomjVsFVAAAAdE"]
[Tue Jul 21 08:22:00.944104 2026] [security2:error] [pid 419508:tid 419564] [remote 41.186.86.12:7933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "diskvidros.com.br"] [uri "/wp-login.php"] [unique_id "al9WWFcagwCeNbomjVsFVQABvDc"]
[Tue Jul 21 08:22:01.041004 2026] [security2:error] [pid 411857:tid 411876] [remote 216.73.216.184:18203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9WWS7ynBpLeKYztQPhyQAAIBE"]
[Tue Jul 21 08:22:01.214396 2026] [security2:error] [pid 419508:tid 419644] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9WWVcagwCeNbomjVsFWgAAAZU"]
[Tue Jul 21 08:22:01.502046 2026] [security2:error] [pid 418108:tid 418264] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9WWQ0cxofL2J1zwYrCTwAAASI"]
[Tue Jul 21 08:22:01.659702 2026] [security2:error] [pid 419508:tid 419719] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/bolt.php"] [unique_id "al9WWVcagwCeNbomjVsFYwAAAeA"], referer: http://sobradoimoveis.com.br/bolt.php
[Tue Jul 21 08:22:01.786024 2026] [security2:error] [pid 419508:tid 419755] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9WWVcagwCeNbomjVsFZQAAAgM"]
[Tue Jul 21 08:22:02.014505 2026] [security2:error] [pid 419508:tid 419581] [remote 188.164.197.230:49304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9WWlcagwCeNbomjVsFagAB3Eg"]
[Tue Jul 21 08:22:02.071353 2026] [security2:error] [pid 411857:tid 412065] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9WWi7ynBpLeKYztQPh1wAAAEw"]
[Tue Jul 21 08:22:02.356960 2026] [security2:error] [pid 419508:tid 419727] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9WWlcagwCeNbomjVsFcQAAAeg"]
[Tue Jul 21 08:22:02.402217 2026] [security2:error] [pid 419508:tid 419639] [client 20.226.60.151:59091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/core.php"] [unique_id "al9WWlcagwCeNbomjVsFcgAAAZA"]
[Tue Jul 21 08:22:02.445492 2026] [security2:error] [pid 418108:tid 418247] [client 4.194.217.15:4163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/admin/function.php"] [unique_id "al9WWg0cxofL2J1zwYrCVQAAARE"]
[Tue Jul 21 08:22:02.453126 2026] [security2:error] [pid 419508:tid 419718] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/cjfuns.php"] [unique_id "al9WWlcagwCeNbomjVsFcwAAAd8"], referer: http://sobradoimoveis.com.br/cjfuns.php
[Tue Jul 21 08:22:02.506015 2026] [security2:error] [pid 419508:tid 419711] [client 65.21.113.253:59764] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WWlcagwCeNbomjVsFawAAAdg"]
[Tue Jul 21 08:22:02.641827 2026] [security2:error] [pid 418108:tid 418302] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9WWg0cxofL2J1zwYrCVgAAAUg"]
[Tue Jul 21 08:22:02.673836 2026] [security2:error] [pid 419508:tid 419680] [client 74.249.245.134:52961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/fm.php"] [unique_id "al9WWlcagwCeNbomjVsFdQAAAbk"]
[Tue Jul 21 08:22:02.922387 2026] [security2:error] [pid 411857:tid 412043] [client 223.181.60.88:28281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WWi7ynBpLeKYztQPh6AAAADY"]
[Tue Jul 21 08:22:02.923056 2026] [security2:error] [pid 411857:tid 412043] [client 223.181.60.88:28281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WWi7ynBpLeKYztQPh6AAAADY"]
[Tue Jul 21 08:22:02.926343 2026] [security2:error] [pid 411857:tid 412099] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danieldefariassilva1745938199948.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9WWi7ynBpLeKYztQPh6QAAAG4"]
[Tue Jul 21 08:22:02.982470 2026] [security2:error] [pid 419508:tid 419511] [remote 69.5.20.170:40404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.20.5.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9WWlcagwCeNbomjVsFeAABzAI"]
[Tue Jul 21 08:22:02.991676 2026] [security2:error] [pid 418108:tid 418354] [client 103.151.46.103:64307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WWg0cxofL2J1zwYrCVwAAAXw"]
[Tue Jul 21 08:22:02.991790 2026] [security2:error] [pid 418108:tid 418354] [client 103.151.46.103:64307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WWg0cxofL2J1zwYrCVwAAAXw"]
[Tue Jul 21 08:22:03.237748 2026] [security2:error] [pid 419508:tid 419685] [client 20.226.60.151:59286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/19.php"] [unique_id "al9WW1cagwCeNbomjVsFfQAAAb4"]
[Tue Jul 21 08:22:03.247412 2026] [security2:error] [pid 419508:tid 419656] [client 20.220.225.223:42155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/wpx.php"] [unique_id "al9WW1cagwCeNbomjVsFfwAAAaE"]
[Tue Jul 21 08:22:03.249751 2026] [security2:error] [pid 419508:tid 419620] [remote 68.178.160.25:58334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9WW1cagwCeNbomjVsFfgAB-G8"]
[Tue Jul 21 08:22:03.477634 2026] [security2:error] [pid 419508:tid 419689] [client 4.194.217.15:1384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/adminfuns.php"] [unique_id "al9WW1cagwCeNbomjVsFgwAAAcI"]
[Tue Jul 21 08:22:03.679999 2026] [security2:error] [pid 419508:tid 419669] [client 20.151.10.161:50819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/goods.php"] [unique_id "al9WW1cagwCeNbomjVsFhgAAAa4"]
[Tue Jul 21 08:22:03.728459 2026] [security2:error] [pid 419508:tid 419616] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WW1cagwCeNbomjVsFhwABmGs"]
[Tue Jul 21 08:22:03.728607 2026] [security2:error] [pid 419508:tid 419647] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WW1cagwCeNbomjVsFhwABmGs"]
[Tue Jul 21 08:22:03.844263 2026] [security2:error] [pid 419508:tid 419757] [client 152.59.34.51:61373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WW1cagwCeNbomjVsFiAAAAgU"]
[Tue Jul 21 08:22:03.844369 2026] [security2:error] [pid 419508:tid 419757] [client 152.59.34.51:61373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WW1cagwCeNbomjVsFiAAAAgU"]
[Tue Jul 21 08:22:03.898125 2026] [security2:error] [pid 411857:tid 411996] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/ioxi-o.php"] [unique_id "al9WWy7ynBpLeKYztQPiCgAAAAc"], referer: http://sobradoimoveis.com.br/ioxi-o.php
[Tue Jul 21 08:22:03.977581 2026] [security2:error] [pid 411857:tid 412052] [client 20.226.60.151:59285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/inc.php"] [unique_id "al9WWy7ynBpLeKYztQPiDgAAAD8"]
[Tue Jul 21 08:22:04.082774 2026] [security2:error] [pid 411857:tid 419446] [remote 45.79.123.44:50230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-login.php"] [unique_id "al9WXC7ynBpLeKYztQPiEgAAFYE"]
[Tue Jul 21 08:22:04.486368 2026] [security2:error] [pid 419508:tid 419682] [client 117.213.202.34:61178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WXFcagwCeNbomjVsFiwAAAbs"]
[Tue Jul 21 08:22:04.486510 2026] [security2:error] [pid 419508:tid 419682] [client 117.213.202.34:61178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WXFcagwCeNbomjVsFiwAAAbs"]
[Tue Jul 21 08:22:04.668040 2026] [security2:error] [pid 411857:tid 412076] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/insc.php"] [unique_id "al9WXC7ynBpLeKYztQPiMAAAAFc"], referer: http://sobradoimoveis.com.br/insc.php
[Tue Jul 21 08:22:04.705289 2026] [security2:error] [pid 418108:tid 418269] [client 4.194.217.15:1344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/administrator/components/com_associations/layouts/joomla/searchtools/mainhack.php"] [unique_id "al9WXA0cxofL2J1zwYrCXwAAASc"]
[Tue Jul 21 08:22:04.931292 2026] [access_compat:error] [pid 411857:tid 412018] [client 162.241.63.68:45080] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:22:04.945402 2026] [security2:error] [pid 419508:tid 419650] [client 20.226.60.151:59083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-ppoxua4.php"] [unique_id "al9WXFcagwCeNbomjVsFkQAAAZs"]
[Tue Jul 21 08:22:04.967882 2026] [access_compat:error] [pid 419508:tid 419653] [client 162.241.63.68:45086] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:22:05.023449 2026] [security2:error] [pid 418108:tid 418307] [client 34.168.88.184:59813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.drjoaoguedes.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9WXQ0cxofL2J1zwYrCZAAAAU0"]
[Tue Jul 21 08:22:05.155061 2026] [security2:error] [pid 419508:tid 419758] [client 87.116.180.198:13856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WXVcagwCeNbomjVsFlQAAAgY"]
[Tue Jul 21 08:22:05.155231 2026] [security2:error] [pid 419508:tid 419758] [client 87.116.180.198:13856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WXVcagwCeNbomjVsFlQAAAgY"]
[Tue Jul 21 08:22:05.310574 2026] [security2:error] [pid 418108:tid 418336] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/classwithtostring.php"] [unique_id "al9WXQ0cxofL2J1zwYrCZgAAAWo"], referer: http://sobradoimoveis.com.br/classwithtostring.php
[Tue Jul 21 08:22:05.343254 2026] [security2:error] [pid 418108:tid 418258] [client 20.151.10.161:50821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/ms-edit.php"] [unique_id "al9WXQ0cxofL2J1zwYrCaAAAARw"]
[Tue Jul 21 08:22:05.517567 2026] [security2:error] [pid 419508:tid 419727] [client 202.179.75.202:44352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WXVcagwCeNbomjVsFngAAAeg"]
[Tue Jul 21 08:22:05.517679 2026] [security2:error] [pid 419508:tid 419727] [client 202.179.75.202:44352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WXVcagwCeNbomjVsFngAAAeg"]
[Tue Jul 21 08:22:05.653761 2026] [security2:error] [pid 419508:tid 419737] [client 195.49.128.211:52640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WXVcagwCeNbomjVsFoAAAAfI"]
[Tue Jul 21 08:22:05.653902 2026] [security2:error] [pid 419508:tid 419737] [client 195.49.128.211:52640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WXVcagwCeNbomjVsFoAAAAfI"]
[Tue Jul 21 08:22:05.661283 2026] [security2:error] [pid 411857:tid 412065] [client 150.129.202.39:64685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WXS7ynBpLeKYztQPiTAAAAEw"]
[Tue Jul 21 08:22:05.661421 2026] [security2:error] [pid 411857:tid 412065] [client 150.129.202.39:64685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WXS7ynBpLeKYztQPiTAAAAEw"]
[Tue Jul 21 08:22:05.731563 2026] [security2:error] [pid 419508:tid 419711] [client 4.194.217.15:4116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/ahax.php"] [unique_id "al9WXVcagwCeNbomjVsFogAAAdg"]
[Tue Jul 21 08:22:05.783484 2026] [security2:error] [pid 419508:tid 419666] [client 14.245.224.124:59192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WXVcagwCeNbomjVsFpAAAAas"]
[Tue Jul 21 08:22:05.783586 2026] [security2:error] [pid 419508:tid 419666] [client 14.245.224.124:59192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WXVcagwCeNbomjVsFpAAAAas"]
[Tue Jul 21 08:22:05.785572 2026] [security2:error] [pid 419508:tid 419703] [client 194.147.58.101:47960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/.env"] [unique_id "al9WXVcagwCeNbomjVsFpgAAAdA"]
[Tue Jul 21 08:22:05.790676 2026] [security2:error] [pid 411857:tid 412066] [client 194.147.58.101:47930] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "br1102.hostgator.com.br"] [uri "/.env.old"] [unique_id "al9WXS7ynBpLeKYztQPiVQAAAE0"]
[Tue Jul 21 08:22:05.837601 2026] [security2:error] [pid 411857:tid 412078] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/txets.php"] [unique_id "al9WXS7ynBpLeKYztQPiVgAAAFk"], referer: http://sobradoimoveis.com.br/txets.php
[Tue Jul 21 08:22:05.961692 2026] [security2:error] [pid 411857:tid 412083] [client 34.168.88.184:55634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.drjoaoguedes.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9WXS7ynBpLeKYztQPiWQAAAF4"]
[Tue Jul 21 08:22:06.042798 2026] [security2:error] [pid 411857:tid 412070] [client 20.220.225.223:42115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/berlin.php"] [unique_id "al9WXi7ynBpLeKYztQPiWwAAAFE"]
[Tue Jul 21 08:22:06.201506 2026] [security2:error] [pid 418108:tid 418348] [client 173.252.95.37:46746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9WXg0cxofL2J1zwYrCcQAAAXY"]
[Tue Jul 21 08:22:06.393474 2026] [security2:error] [pid 411857:tid 411980] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WXi7ynBpLeKYztQPiZAAAB3g"]
[Tue Jul 21 08:22:06.393642 2026] [security2:error] [pid 411857:tid 411996] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WXi7ynBpLeKYztQPiZAAAB3g"]
[Tue Jul 21 08:22:06.452539 2026] [security2:error] [pid 419508:tid 419585] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WXlcagwCeNbomjVsFsQAByEw"]
[Tue Jul 21 08:22:06.452750 2026] [security2:error] [pid 419508:tid 419695] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WXlcagwCeNbomjVsFsQAByEw"]
[Tue Jul 21 08:22:06.693826 2026] [security2:error] [pid 418108:tid 418288] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/goods.php"] [unique_id "al9WXg0cxofL2J1zwYrCdAAAATo"], referer: http://sobradoimoveis.com.br/goods.php
[Tue Jul 21 08:22:06.760044 2026] [security2:error] [pid 411857:tid 412104] [client 45.146.55.199:37095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lumerah.com.br"] [uri "/wp-login.php"] [unique_id "al9WXi7ynBpLeKYztQPiaAAAAHM"]
[Tue Jul 21 08:22:06.769252 2026] [security2:error] [pid 411857:tid 412077] [client 4.194.217.15:4118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/ak.php"] [unique_id "al9WXi7ynBpLeKYztQPiagAAAFg"]
[Tue Jul 21 08:22:06.801005 2026] [security2:error] [pid 419508:tid 419760] [client 20.220.225.223:20922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9WXlcagwCeNbomjVsFuwAAAgg"]
[Tue Jul 21 08:22:06.851896 2026] [security2:error] [pid 419508:tid 419733] [client 20.226.60.151:64090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-u3nxbvx.php"] [unique_id "al9WXlcagwCeNbomjVsFvQAAAe4"]
[Tue Jul 21 08:22:06.882692 2026] [security2:error] [pid 419508:tid 419717] [client 34.168.88.184:62135] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.drjoaoguedes.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9WXlcagwCeNbomjVsFvgAAAd4"]
[Tue Jul 21 08:22:07.174050 2026] [security2:error] [pid 411857:tid 412021] [client 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "marmorariasolare.com.br"] [uri "/.svn/wc.db"] [unique_id "al9WXy7ynBpLeKYztQPidAAAACA"]
[Tue Jul 21 08:22:07.184880 2026] [security2:error] [pid 419508:tid 419680] [client 20.151.10.161:50856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/222.php"] [unique_id "al9WX1cagwCeNbomjVsFxgAAAbk"]
[Tue Jul 21 08:22:07.251298 2026] [security2:error] [pid 419508:tid 419661] [client 103.106.20.201:61511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WX1cagwCeNbomjVsFxwAAAaY"]
[Tue Jul 21 08:22:07.252010 2026] [security2:error] [pid 419508:tid 419661] [client 103.106.20.201:61511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WX1cagwCeNbomjVsFxwAAAaY"]
[Tue Jul 21 08:22:07.528043 2026] [security2:error] [pid 411857:tid 412028] [client 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "marmorariasolare.com.br"] [uri "/.svn/entries"] [unique_id "al9WXy7ynBpLeKYztQPiegAAACc"]
[Tue Jul 21 08:22:07.709369 2026] [security2:error] [pid 419508:tid 419651] [client 34.168.88.184:62861] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.drjoaoguedes.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9WX1cagwCeNbomjVsFzwAAAZw"]
[Tue Jul 21 08:22:07.754562 2026] [security2:error] [pid 411857:tid 412081] [client 14.97.58.74:5815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WXy7ynBpLeKYztQPigwAAAFw"]
[Tue Jul 21 08:22:07.754706 2026] [security2:error] [pid 411857:tid 412081] [client 14.97.58.74:5815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WXy7ynBpLeKYztQPigwAAAFw"]
[Tue Jul 21 08:22:07.874630 2026] [security2:error] [pid 411857:tid 411991] [client 4.194.217.15:5504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/alfa-rex.php"] [unique_id "al9WXy7ynBpLeKYztQPihwAAAAI"]
[Tue Jul 21 08:22:07.951573 2026] [security2:error] [pid 411857:tid 412096] [client 20.226.60.151:64061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/ss.php"] [unique_id "al9WXy7ynBpLeKYztQPiiAAAAGs"]
[Tue Jul 21 08:22:07.971965 2026] [security2:error] [pid 419508:tid 419738] [client 20.220.225.223:20908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/dp.php"] [unique_id "al9WX1cagwCeNbomjVsF0QAAAfM"]
[Tue Jul 21 08:22:07.975106 2026] [security2:error] [pid 419508:tid 419644] [client 20.151.10.161:50857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9WX1cagwCeNbomjVsF0gAAAZU"]
[Tue Jul 21 08:22:08.027229 2026] [security2:error] [pid 418108:tid 418243] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/lufix.php"] [unique_id "al9WYA0cxofL2J1zwYrCeQAAAQ0"], referer: http://sobradoimoveis.com.br/lufix.php#lufix
[Tue Jul 21 08:22:08.250880 2026] [security2:error] [pid 419508:tid 419747] [client 35.189.200.13:62424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "daianapontes.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9WYFcagwCeNbomjVsF1AAAAfs"]
[Tue Jul 21 08:22:08.547897 2026] [security2:error] [pid 411857:tid 412091] [client 173.252.95.23:51172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9WYC7ynBpLeKYztQPikgAAAGY"]
[Tue Jul 21 08:22:08.594924 2026] [security2:error] [pid 411857:tid 412030] [client 34.168.88.184:62669] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.drjoaoguedes.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9WYC7ynBpLeKYztQPilwAAACk"]
[Tue Jul 21 08:22:08.625009 2026] [security2:error] [pid 411857:tid 412068] [client 20.206.105.145:20265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/k5.php"] [unique_id "al9WYC7ynBpLeKYztQPimAAAAE8"]
[Tue Jul 21 08:22:08.743198 2026] [security2:error] [pid 411857:tid 412098] [client 120.56.162.40:51151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WYC7ynBpLeKYztQPinAAAAG0"]
[Tue Jul 21 08:22:08.743330 2026] [security2:error] [pid 411857:tid 412098] [client 120.56.162.40:51151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WYC7ynBpLeKYztQPinAAAAG0"]
[Tue Jul 21 08:22:08.756567 2026] [security2:error] [pid 419508:tid 419611] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WYFcagwCeNbomjVsF2QABrmY"]
[Tue Jul 21 08:22:08.756720 2026] [security2:error] [pid 419508:tid 419669] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WYFcagwCeNbomjVsF2QABrmY"]
[Tue Jul 21 08:22:08.758671 2026] [security2:error] [pid 419508:tid 419755] [client 20.151.10.161:50820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9WYFcagwCeNbomjVsF2gAAAgM"]
[Tue Jul 21 08:22:08.827160 2026] [security2:error] [pid 411857:tid 412026] [client 31.171.130.20:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sobradoimoveis.com.br"] [uri "/style.php"] [unique_id "al9WYC7ynBpLeKYztQPinQAAACU"], referer: http://sobradoimoveis.com.br/style.php
[Tue Jul 21 08:22:08.835963 2026] [security2:error] [pid 419508:tid 419573] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WYFcagwCeNbomjVsF2wAB-kA"]
[Tue Jul 21 08:22:08.836080 2026] [security2:error] [pid 419508:tid 419746] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WYFcagwCeNbomjVsF2wAB-kA"]
[Tue Jul 21 08:22:08.918808 2026] [security2:error] [pid 411857:tid 412039] [client 74.7.175.156:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "osvaldoferreiramendo1748622464486.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9WYC7ynBpLeKYztQPingAAMgQ"]
[Tue Jul 21 08:22:08.977023 2026] [security2:error] [pid 418108:tid 418253] [client 4.194.217.15:1362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/alfa.php"] [unique_id "al9WYA0cxofL2J1zwYrCfwAAARc"]
[Tue Jul 21 08:22:09.108421 2026] [security2:error] [pid 411857:tid 412108] [client 35.189.200.13:51765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.200.189.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WYS7ynBpLeKYztQPipgAAAHc"]
[Tue Jul 21 08:22:09.108601 2026] [security2:error] [pid 419508:tid 419684] [client 162.219.176.3:48744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9WYVcagwCeNbomjVsF3wAAAb0"]
[Tue Jul 21 08:22:09.108660 2026] [security2:error] [pid 419508:tid 419684] [client 162.219.176.3:48744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9WYVcagwCeNbomjVsF3wAAAb0"]
[Tue Jul 21 08:22:09.371198 2026] [security2:error] [pid 419508:tid 419649] [client 34.168.88.184:64291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.drjoaoguedes.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9WYVcagwCeNbomjVsF4QAAAZo"]
[Tue Jul 21 08:22:09.483649 2026] [security2:error] [pid 418108:tid 418289] [client 173.252.95.7:46858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9WYA0cxofL2J1zwYrCfQAAATs"]
[Tue Jul 21 08:22:09.767872 2026] [security2:error] [pid 411857:tid 412093] [client 20.226.60.151:64062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/min.php"] [unique_id "al9WYS7ynBpLeKYztQPiuAAAAGg"]
[Tue Jul 21 08:22:09.879000 2026] [security2:error] [pid 418108:tid 418183] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WYQ0cxofL2J1zwYrCiAABbkg"]
[Tue Jul 21 08:22:09.879174 2026] [security2:error] [pid 418108:tid 418340] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WYQ0cxofL2J1zwYrCiAABbkg"]
[Tue Jul 21 08:22:09.933290 2026] [security2:error] [pid 411857:tid 412089] [client 115.134.11.136:54661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WYS7ynBpLeKYztQPiugAAAGQ"]
[Tue Jul 21 08:22:09.933418 2026] [security2:error] [pid 411857:tid 412089] [client 115.134.11.136:54661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WYS7ynBpLeKYztQPiugAAAGQ"]
[Tue Jul 21 08:22:10.036033 2026] [security2:error] [pid 419508:tid 419725] [client 4.194.217.15:3081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/amax.php"] [unique_id "al9WYlcagwCeNbomjVsF6wAAAeY"]
[Tue Jul 21 08:22:10.211801 2026] [security2:error] [pid 419508:tid 419752] [client 20.226.60.151:60615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9WYlcagwCeNbomjVsF8QAAAgA"]
[Tue Jul 21 08:22:10.255058 2026] [security2:error] [pid 419508:tid 419661] [client 34.168.88.184:60495] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.drjoaoguedes.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9WYlcagwCeNbomjVsF9AAAAaY"]
[Tue Jul 21 08:22:10.276987 2026] [security2:error] [pid 418108:tid 418350] [client 187.125.243.197:51515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WYg0cxofL2J1zwYrCiQAAAXg"]
[Tue Jul 21 08:22:10.277172 2026] [security2:error] [pid 418108:tid 418350] [client 187.125.243.197:51515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WYg0cxofL2J1zwYrCiQAAAXg"]
[Tue Jul 21 08:22:10.381428 2026] [security2:error] [pid 419508:tid 419678] [client 20.151.10.161:50697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/raw.php"] [unique_id "al9WYlcagwCeNbomjVsF9QAAAbc"]
[Tue Jul 21 08:22:10.574908 2026] [security2:error] [pid 411857:tid 412022] [client 20.220.225.223:42153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/billur.php"] [unique_id "al9WYi7ynBpLeKYztQPiyAAAACE"]
[Tue Jul 21 08:22:10.719907 2026] [security2:error] [pid 419508:tid 419671] [client 20.220.225.223:34730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/old.php"] [unique_id "al9WYlcagwCeNbomjVsF9wAAAbA"]
[Tue Jul 21 08:22:10.903948 2026] [security2:error] [pid 419508:tid 419754] [client 74.249.245.134:61144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/ini.php"] [unique_id "al9WYlcagwCeNbomjVsF_wAAAgI"]
[Tue Jul 21 08:22:10.925978 2026] [security2:error] [pid 419508:tid 419703] [client 154.208.47.42:60191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WYlcagwCeNbomjVsGAQAAAdA"]
[Tue Jul 21 08:22:10.926111 2026] [security2:error] [pid 419508:tid 419703] [client 154.208.47.42:60191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WYlcagwCeNbomjVsGAQAAAdA"]
[Tue Jul 21 08:22:10.937257 2026] [security2:error] [pid 419508:tid 419719] [client 20.151.10.161:10326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/abcd.php"] [unique_id "al9WYlcagwCeNbomjVsGAgAAAeA"]
[Tue Jul 21 08:22:11.076724 2026] [security2:error] [pid 411857:tid 412017] [client 4.194.217.15:4165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/archive.php"] [unique_id "al9WYy7ynBpLeKYztQPi1AAAABw"]
[Tue Jul 21 08:22:11.239648 2026] [security2:error] [pid 419508:tid 419681] [client 34.168.88.184:59079] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.drjoaoguedes.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9WY1cagwCeNbomjVsGDAAAAbo"]
[Tue Jul 21 08:22:11.442274 2026] [security2:error] [pid 418108:tid 418119] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9WYw0cxofL2J1zwYrClwABhgg"], referer: www.google.com
[Tue Jul 21 08:22:11.500485 2026] [security2:error] [pid 418108:tid 418145] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-plain.php"] [unique_id "al9WYw0cxofL2J1zwYrCmAABhCI"], referer: www.google.com
[Tue Jul 21 08:22:11.539329 2026] [security2:error] [pid 419508:tid 419520] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9WY1cagwCeNbomjVsGFQAB5gs"]
[Tue Jul 21 08:22:11.695649 2026] [core:error] [pid 419508:tid 419593] [remote 40.77.167.14:50347] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:11.695671 2026] [core:error] [pid 419508:tid 419593] [remote 40.77.167.14:50347] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:11.735255 2026] [security2:error] [pid 411857:tid 411990] [client 20.151.10.161:10271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/a1.php"] [unique_id "al9WYy7ynBpLeKYztQPi4wAAAAE"]
[Tue Jul 21 08:22:11.820325 2026] [core:error] [pid 419508:tid 419605] [remote 40.77.167.14:50347] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:11.820353 2026] [core:error] [pid 419508:tid 419605] [remote 40.77.167.14:50347] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:11.923557 2026] [security2:error] [pid 419508:tid 419747] [client 20.226.60.151:64113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9WY1cagwCeNbomjVsGHQAAAfs"]
[Tue Jul 21 08:22:11.974234 2026] [security2:error] [pid 419508:tid 419652] [client 74.249.245.134:21359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/themes.php"] [unique_id "al9WY1cagwCeNbomjVsGHwAAAZ0"]
[Tue Jul 21 08:22:12.072312 2026] [security2:error] [pid 411857:tid 412050] [client 34.168.88.184:54100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.drjoaoguedes.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9WZC7ynBpLeKYztQPi7gAAAD0"]
[Tue Jul 21 08:22:12.092573 2026] [security2:error] [pid 419508:tid 419518] [remote 54.39.203.139:15886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.sigmas.app.br"] [uri "/"] [unique_id "al9WZFcagwCeNbomjVsGIgABwQk"]
[Tue Jul 21 08:22:12.092780 2026] [security2:error] [pid 419508:tid 419688] [client 54.39.203.139:15886] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sigmas.app.br"] [uri "/"] [unique_id "al9WZFcagwCeNbomjVsGIgABwQk"]
[Tue Jul 21 08:22:12.107863 2026] [security2:error] [pid 419508:tid 419724] [client 4.194.217.15:5526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/as.php"] [unique_id "al9WZFcagwCeNbomjVsGIwAAAeU"]
[Tue Jul 21 08:22:12.317154 2026] [security2:error] [pid 411857:tid 412089] [client 20.151.10.161:10254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9WZC7ynBpLeKYztQPi8gAAAGQ"]
[Tue Jul 21 08:22:12.492840 2026] [security2:error] [pid 419508:tid 419715] [client 35.189.200.13:62596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.200.189.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WZFcagwCeNbomjVsGKgAAAdw"]
[Tue Jul 21 08:22:12.492982 2026] [security2:error] [pid 419508:tid 419715] [client 35.189.200.13:62596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WZFcagwCeNbomjVsGKgAAAdw"]
[Tue Jul 21 08:22:12.819512 2026] [security2:error] [pid 411857:tid 412003] [client 20.151.10.161:50876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9WZC7ynBpLeKYztQPi_AAAAA4"]
[Tue Jul 21 08:22:12.850642 2026] [security2:error] [pid 419508:tid 419717] [client 34.168.88.184:60278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.drjoaoguedes.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9WZFcagwCeNbomjVsGLwAAAd4"]
[Tue Jul 21 08:22:12.858390 2026] [security2:error] [pid 419508:tid 419684] [client 61.1.167.83:51213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WZFcagwCeNbomjVsGMAAAAb0"]
[Tue Jul 21 08:22:12.858522 2026] [security2:error] [pid 419508:tid 419684] [client 61.1.167.83:51213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WZFcagwCeNbomjVsGMAAAAb0"]
[Tue Jul 21 08:22:12.905562 2026] [security2:error] [pid 419508:tid 419640] [client 20.197.192.193:53169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9WZFcagwCeNbomjVsGMgAAAZE"]
[Tue Jul 21 08:22:13.210832 2026] [security2:error] [pid 419508:tid 419659] [client 4.194.217.15:4128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/asd.php"] [unique_id "al9WZVcagwCeNbomjVsGOwAAAaQ"]
[Tue Jul 21 08:22:13.293335 2026] [security2:error] [pid 418108:tid 418254] [client 20.151.10.161:50818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9WZQ0cxofL2J1zwYrCnAAAARg"]
[Tue Jul 21 08:22:13.335754 2026] [security2:error] [pid 418108:tid 418309] [client 74.249.245.134:62069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/dropdown.php"] [unique_id "al9WZQ0cxofL2J1zwYrCnQAAAU8"]
[Tue Jul 21 08:22:13.508204 2026] [security2:error] [pid 418108:tid 418124] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9WZQ0cxofL2J1zwYrCnwABHA0"], referer: www.google.com
[Tue Jul 21 08:22:13.521949 2026] [security2:error] [pid 419508:tid 419694] [client 20.226.60.151:64032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/autoload_classmap.php"] [unique_id "al9WZVcagwCeNbomjVsGPwAAAcc"]
[Tue Jul 21 08:22:13.523187 2026] [security2:error] [pid 411857:tid 412054] [client 20.220.225.223:41122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/mimpi.php"] [unique_id "al9WZS7ynBpLeKYztQPjCAAAAEE"]
[Tue Jul 21 08:22:13.660831 2026] [security2:error] [pid 419508:tid 419700] [client 65.21.113.253:46760] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WZVcagwCeNbomjVsGPgAAAc0"]
[Tue Jul 21 08:22:13.684020 2026] [security2:error] [pid 419508:tid 419745] [client 223.181.60.88:25206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WZVcagwCeNbomjVsGRAAAAfk"]
[Tue Jul 21 08:22:13.684242 2026] [security2:error] [pid 419508:tid 419745] [client 223.181.60.88:25206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WZVcagwCeNbomjVsGRAAAAfk"]
[Tue Jul 21 08:22:13.916021 2026] [security2:error] [pid 411857:tid 412087] [client 20.206.105.145:20183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/w.php"] [unique_id "al9WZS7ynBpLeKYztQPjEQAAAGI"]
[Tue Jul 21 08:22:14.105577 2026] [security2:error] [pid 419508:tid 419675] [client 20.151.10.161:50835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/simple.php"] [unique_id "al9WZlcagwCeNbomjVsGSwAAAbQ"]
[Tue Jul 21 08:22:14.265691 2026] [security2:error] [pid 411857:tid 412000] [client 4.194.217.15:4219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/assets/class-wp-http-client.php"] [unique_id "al9WZi7ynBpLeKYztQPjFgAAAAs"]
[Tue Jul 21 08:22:14.392213 2026] [security2:error] [pid 411857:tid 411895] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WZi7ynBpLeKYztQPjGAAAXyQ"]
[Tue Jul 21 08:22:14.392406 2026] [security2:error] [pid 411857:tid 412084] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WZi7ynBpLeKYztQPjGAAAXyQ"]
[Tue Jul 21 08:22:14.522193 2026] [security2:error] [pid 411857:tid 412056] [client 20.151.10.161:10267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/xxx.php"] [unique_id "al9WZi7ynBpLeKYztQPjGwAAAEM"]
[Tue Jul 21 08:22:14.527595 2026] [security2:error] [pid 419508:tid 419728] [client 20.226.60.151:59300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-link-zorm.php"] [unique_id "al9WZlcagwCeNbomjVsGUgAAAek"]
[Tue Jul 21 08:22:14.581943 2026] [security2:error] [pid 419508:tid 419695] [client 152.59.34.51:61825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WZlcagwCeNbomjVsGVAAAAcg"]
[Tue Jul 21 08:22:14.582050 2026] [security2:error] [pid 419508:tid 419695] [client 152.59.34.51:61825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WZlcagwCeNbomjVsGVAAAAcg"]
[Tue Jul 21 08:22:14.761956 2026] [security2:error] [pid 418108:tid 418285] [client 65.21.113.253:46772] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WZg0cxofL2J1zwYrCoQAAATc"]
[Tue Jul 21 08:22:14.858168 2026] [security2:error] [pid 419508:tid 419758] [client 103.151.46.103:64803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WZlcagwCeNbomjVsGWQAAAgY"]
[Tue Jul 21 08:22:14.858751 2026] [security2:error] [pid 419508:tid 419758] [client 103.151.46.103:64803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WZlcagwCeNbomjVsGWQAAAgY"]
[Tue Jul 21 08:22:14.874636 2026] [core:error] [pid 411857:tid 412024] [client 205.210.31.54:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:14.874659 2026] [core:error] [pid 411857:tid 412024] [client 205.210.31.54:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:14.913419 2026] [security2:error] [pid 419508:tid 419704] [client 20.151.10.161:10248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/hypo.php"] [unique_id "al9WZlcagwCeNbomjVsGXAAAAdE"]
[Tue Jul 21 08:22:14.937865 2026] [security2:error] [pid 419508:tid 419718] [client 74.249.245.134:58837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/wp-links.php"] [unique_id "al9WZlcagwCeNbomjVsGXQAAAd8"]
[Tue Jul 21 08:22:15.006780 2026] [security2:error] [pid 418108:tid 418317] [client 117.213.202.34:61712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WZw0cxofL2J1zwYrCpAAAAVc"]
[Tue Jul 21 08:22:15.006934 2026] [security2:error] [pid 418108:tid 418317] [client 117.213.202.34:61712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WZw0cxofL2J1zwYrCpAAAAVc"]
[Tue Jul 21 08:22:15.064682 2026] [security2:error] [pid 419508:tid 419651] [client 20.226.60.151:50119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/h02ugyh.php"] [unique_id "al9WZ1cagwCeNbomjVsGYAAAAZw"]
[Tue Jul 21 08:22:15.333959 2026] [security2:error] [pid 419508:tid 419672] [client 4.194.217.15:1385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/atomlib.php"] [unique_id "al9WZ1cagwCeNbomjVsGYwAAAbE"]
[Tue Jul 21 08:22:15.353295 2026] [security2:error] [pid 418108:tid 418245] [client 20.220.225.223:12293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/edit.php"] [unique_id "al9WZw0cxofL2J1zwYrCpQAAAQ8"]
[Tue Jul 21 08:22:15.507733 2026] [security2:error] [pid 418108:tid 418138] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/uftxssnr.php"] [unique_id "al9WZw0cxofL2J1zwYrCpgABQxs"], referer: www.google.com
[Tue Jul 21 08:22:15.537964 2026] [security2:error] [pid 418108:tid 418291] [client 20.197.192.193:53160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9WZw0cxofL2J1zwYrCqQAAAT0"]
[Tue Jul 21 08:22:15.675974 2026] [security2:error] [pid 418108:tid 418267] [client 20.151.10.161:10264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/chosen.php"] [unique_id "al9WZw0cxofL2J1zwYrCqwAAASU"]
[Tue Jul 21 08:22:15.708761 2026] [security2:error] [pid 411857:tid 412059] [client 87.116.180.198:27347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WZy7ynBpLeKYztQPjLwAAAEY"]
[Tue Jul 21 08:22:15.708888 2026] [security2:error] [pid 411857:tid 412059] [client 87.116.180.198:27347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WZy7ynBpLeKYztQPjLwAAAEY"]
[Tue Jul 21 08:22:16.243336 2026] [security2:error] [pid 419508:tid 419660] [client 20.220.225.223:53816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/dp.php"] [unique_id "al9WaFcagwCeNbomjVsGbQAAAaU"]
[Tue Jul 21 08:22:16.297860 2026] [security2:error] [pid 418108:tid 418328] [client 150.129.202.39:64861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WaA0cxofL2J1zwYrCrAAAAWI"]
[Tue Jul 21 08:22:16.298061 2026] [security2:error] [pid 418108:tid 418328] [client 150.129.202.39:64861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WaA0cxofL2J1zwYrCrAAAAWI"]
[Tue Jul 21 08:22:16.311597 2026] [security2:error] [pid 419508:tid 419671] [client 195.49.128.211:53227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WaFcagwCeNbomjVsGbgAAAbA"]
[Tue Jul 21 08:22:16.311830 2026] [security2:error] [pid 419508:tid 419671] [client 195.49.128.211:53227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WaFcagwCeNbomjVsGbgAAAbA"]
[Tue Jul 21 08:22:16.353470 2026] [security2:error] [pid 411857:tid 412082] [client 202.179.75.202:52318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WaC7ynBpLeKYztQPjOgAAAF0"]
[Tue Jul 21 08:22:16.353602 2026] [security2:error] [pid 411857:tid 412082] [client 202.179.75.202:52318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WaC7ynBpLeKYztQPjOgAAAF0"]
[Tue Jul 21 08:22:16.380668 2026] [security2:error] [pid 419508:tid 419703] [client 4.194.217.15:4222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/autoload_classmap.php"] [unique_id "al9WaFcagwCeNbomjVsGcQAAAdA"]
[Tue Jul 21 08:22:16.449355 2026] [security2:error] [pid 419508:tid 419731] [client 173.252.95.22:59144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9WaFcagwCeNbomjVsGcgAAAew"]
[Tue Jul 21 08:22:16.587994 2026] [security2:error] [pid 411857:tid 412022] [client 20.151.10.161:10354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/file5.php"] [unique_id "al9WaC7ynBpLeKYztQPjQgAAACE"]
[Tue Jul 21 08:22:16.608636 2026] [security2:error] [pid 419508:tid 419657] [client 14.245.224.124:59665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WaFcagwCeNbomjVsGdwAAAaI"]
[Tue Jul 21 08:22:16.608733 2026] [security2:error] [pid 419508:tid 419657] [client 14.245.224.124:59665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WaFcagwCeNbomjVsGdwAAAaI"]
[Tue Jul 21 08:22:16.676302 2026] [security2:error] [pid 418108:tid 418112] [remote 34.166.28.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.28.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9WaA0cxofL2J1zwYrCrgABDQE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:22:16.676526 2026] [security2:error] [pid 419508:tid 419590] [remote 34.166.28.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.28.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9WaFcagwCeNbomjVsGcwAB_VE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:22:16.683698 2026] [security2:error] [pid 418108:tid 418253] [client 20.226.60.151:64124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-link-szoppm.php"] [unique_id "al9WaA0cxofL2J1zwYrCrwAAARc"]
[Tue Jul 21 08:22:16.744073 2026] [security2:error] [pid 411857:tid 411914] [remote 34.166.28.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.28.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9WaC7ynBpLeKYztQPjQAAAfjc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:22:16.756521 2026] [security2:error] [pid 411857:tid 411861] [remote 34.166.28.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.28.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9WaC7ynBpLeKYztQPjQwAAfQI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:22:16.758977 2026] [security2:error] [pid 411857:tid 411991] [client 74.249.245.134:21363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/xmrlpc.php"] [unique_id "al9WaC7ynBpLeKYztQPjRgAAAAI"]
[Tue Jul 21 08:22:16.836758 2026] [core:error] [pid 419508:tid 419532] [remote 52.167.144.18:12736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:16.836779 2026] [core:error] [pid 419508:tid 419532] [remote 52.167.144.18:12736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:16.837144 2026] [core:error] [pid 419508:tid 419556] [remote 52.167.144.18:12736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:16.837165 2026] [core:error] [pid 419508:tid 419556] [remote 52.167.144.18:12736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:16.960310 2026] [core:error] [pid 419508:tid 419544] [remote 52.167.144.18:12736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:16.960330 2026] [core:error] [pid 419508:tid 419544] [remote 52.167.144.18:12736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:16.981775 2026] [security2:error] [pid 411857:tid 411947] [remote 34.166.28.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.28.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9WaC7ynBpLeKYztQPjSwAASVg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:22:17.068694 2026] [security2:error] [pid 419508:tid 419667] [client 20.151.10.161:50724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/file.php"] [unique_id "al9WaVcagwCeNbomjVsGfgAAAaw"]
[Tue Jul 21 08:22:17.084250 2026] [core:error] [pid 419508:tid 419542] [remote 52.167.144.18:12736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:17.084270 2026] [core:error] [pid 419508:tid 419542] [remote 52.167.144.18:12736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:17.163340 2026] [security2:error] [pid 419508:tid 419553] [remote 34.166.28.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.28.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9WaVcagwCeNbomjVsGhAAB3yw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:22:17.170876 2026] [security2:error] [pid 419508:tid 419528] [remote 34.166.28.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.28.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9WaVcagwCeNbomjVsGhQABsRM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:22:17.204946 2026] [security2:error] [pid 419508:tid 419625] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WaVcagwCeNbomjVsGhgABpnQ"]
[Tue Jul 21 08:22:17.205093 2026] [security2:error] [pid 419508:tid 419661] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WaVcagwCeNbomjVsGhgABpnQ"]
[Tue Jul 21 08:22:17.211113 2026] [core:error] [pid 419508:tid 419601] [remote 52.167.144.18:12736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:17.211131 2026] [core:error] [pid 419508:tid 419601] [remote 52.167.144.18:12736] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:17.245912 2026] [security2:error] [pid 419508:tid 419604] [remote 34.166.28.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.28.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9WaVcagwCeNbomjVsGiAAB6F8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:22:17.247454 2026] [security2:error] [pid 411857:tid 411870] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WaS7ynBpLeKYztQPjTwAAbgs"]
[Tue Jul 21 08:22:17.247568 2026] [security2:error] [pid 411857:tid 412099] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WaS7ynBpLeKYztQPjTwAAbgs"]
[Tue Jul 21 08:22:17.371658 2026] [security2:error] [pid 411857:tid 412078] [client 20.206.105.145:20216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/fpwch.php"] [unique_id "al9WaS7ynBpLeKYztQPjUQAAAFk"]
[Tue Jul 21 08:22:17.394275 2026] [security2:error] [pid 418108:tid 418210] [remote 34.166.28.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.28.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9WaQ0cxofL2J1zwYrCsAABbWM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:22:17.405248 2026] [security2:error] [pid 419508:tid 419536] [remote 34.166.28.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.28.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9WaVcagwCeNbomjVsGjgACAhs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:22:17.475557 2026] [security2:error] [pid 419508:tid 419626] [remote 34.166.28.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.28.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9WaVcagwCeNbomjVsGjwABzXU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:22:17.477408 2026] [security2:error] [pid 418108:tid 418127] [remote 34.166.28.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.28.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9WaQ0cxofL2J1zwYrCsQABFhA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:22:17.506486 2026] [security2:error] [pid 419508:tid 419644] [client 4.194.217.15:5550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/av.php"] [unique_id "al9WaVcagwCeNbomjVsGkQAAAZU"]
[Tue Jul 21 08:22:17.529595 2026] [security2:error] [pid 411857:tid 412111] [client 20.151.10.161:50690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/aa2.php"] [unique_id "al9WaS7ynBpLeKYztQPjVAAAAHo"]
[Tue Jul 21 08:22:17.590483 2026] [security2:error] [pid 419508:tid 419675] [client 74.249.245.134:21592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/htaccess.php"] [unique_id "al9WaVcagwCeNbomjVsGlAAAAbQ"]
[Tue Jul 21 08:22:17.645549 2026] [security2:error] [pid 419508:tid 419583] [remote 34.166.28.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.28.166.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9WaVcagwCeNbomjVsGlwACBUo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:22:17.956850 2026] [security2:error] [pid 418108:tid 418255] [client 20.220.225.223:12606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/kua.php"] [unique_id "al9WaQ0cxofL2J1zwYrCsgAAARk"]
[Tue Jul 21 08:22:18.011348 2026] [security2:error] [pid 411857:tid 412064] [client 103.106.20.201:62100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wai7ynBpLeKYztQPjXQAAAEs"]
[Tue Jul 21 08:22:18.011475 2026] [security2:error] [pid 411857:tid 412064] [client 103.106.20.201:62100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wai7ynBpLeKYztQPjXQAAAEs"]
[Tue Jul 21 08:22:18.322616 2026] [security2:error] [pid 411857:tid 411996] [client 20.151.10.161:50738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/ccou.php"] [unique_id "al9Wai7ynBpLeKYztQPjZwAAAAc"]
[Tue Jul 21 08:22:18.384891 2026] [security2:error] [pid 411857:tid 412009] [client 20.226.60.151:64069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/albin.php"] [unique_id "al9Wai7ynBpLeKYztQPjaQAAABQ"]
[Tue Jul 21 08:22:18.427648 2026] [security2:error] [pid 419508:tid 419653] [client 125.18.144.2:22839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WalcagwCeNbomjVsGowAAAZ4"]
[Tue Jul 21 08:22:18.427781 2026] [security2:error] [pid 419508:tid 419653] [client 125.18.144.2:22839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WalcagwCeNbomjVsGowAAAZ4"]
[Tue Jul 21 08:22:18.532126 2026] [security2:error] [pid 419508:tid 419715] [client 20.220.225.223:20964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/ms-new.php"] [unique_id "al9WalcagwCeNbomjVsGpAAAAdw"]
[Tue Jul 21 08:22:18.542042 2026] [security2:error] [pid 411857:tid 412103] [client 4.194.217.15:5505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/b.php"] [unique_id "al9Wai7ynBpLeKYztQPjcQAAAHI"]
[Tue Jul 21 08:22:18.837159 2026] [security2:error] [pid 418108:tid 418295] [client 162.219.176.3:45230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Wag0cxofL2J1zwYrCtgAAAUE"]
[Tue Jul 21 08:22:18.837256 2026] [security2:error] [pid 418108:tid 418295] [client 162.219.176.3:45230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Wag0cxofL2J1zwYrCtgAAAUE"]
[Tue Jul 21 08:22:18.971360 2026] [security2:error] [pid 419508:tid 419650] [client 20.151.10.161:50847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/dr.php"] [unique_id "al9WalcagwCeNbomjVsGpgAAAZs"]
[Tue Jul 21 08:22:19.250822 2026] [security2:error] [pid 411857:tid 412016] [client 20.220.225.223:43424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/bootstrap.php"] [unique_id "al9Way7ynBpLeKYztQPjpwAAABs"]
[Tue Jul 21 08:22:19.458631 2026] [security2:error] [pid 411857:tid 412077] [client 120.56.162.40:51670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Way7ynBpLeKYztQPjqgAAAFg"]
[Tue Jul 21 08:22:19.458783 2026] [security2:error] [pid 411857:tid 412077] [client 120.56.162.40:51670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Way7ynBpLeKYztQPjqgAAAFg"]
[Tue Jul 21 08:22:19.527966 2026] [security2:error] [pid 419508:tid 419562] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wa1cagwCeNbomjVsGrQABsTU"]
[Tue Jul 21 08:22:19.528169 2026] [security2:error] [pid 419508:tid 419672] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wa1cagwCeNbomjVsGrQABsTU"]
[Tue Jul 21 08:22:19.642111 2026] [security2:error] [pid 418108:tid 418322] [client 4.194.217.15:1392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/backup.php"] [unique_id "al9Waw0cxofL2J1zwYrCuwAAAVw"]
[Tue Jul 21 08:22:19.706216 2026] [security2:error] [pid 419508:tid 419761] [client 20.151.10.161:50845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/file31.php"] [unique_id "al9Wa1cagwCeNbomjVsGtgAAAgk"]
[Tue Jul 21 08:22:19.869878 2026] [security2:error] [pid 418108:tid 418310] [client 65.21.113.253:46772] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Waw0cxofL2J1zwYrCvAAAAVA"]
[Tue Jul 21 08:22:19.887846 2026] [security2:error] [pid 411857:tid 411993] [client 62.102.148.158:41366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Way7ynBpLeKYztQPjvgAAAAQ"]
[Tue Jul 21 08:22:19.887942 2026] [security2:error] [pid 411857:tid 411993] [client 62.102.148.158:41366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Way7ynBpLeKYztQPjvgAAAAQ"]
[Tue Jul 21 08:22:19.960136 2026] [security2:error] [pid 411857:tid 411978] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Way7ynBpLeKYztQPjwAAAEnY"]
[Tue Jul 21 08:22:19.960447 2026] [security2:error] [pid 411857:tid 412007] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9Way7ynBpLeKYztQPjwAAAEnY"]
[Tue Jul 21 08:22:20.084881 2026] [security2:error] [pid 419508:tid 419644] [client 20.151.10.161:50824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/file6.php"] [unique_id "al9WbFcagwCeNbomjVsGxQAAAZU"]
[Tue Jul 21 08:22:20.103320 2026] [security2:error] [pid 411857:tid 412074] [client 20.226.60.151:64026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/cilus.php"] [unique_id "al9WbC7ynBpLeKYztQPj0AAAAFU"]
[Tue Jul 21 08:22:20.390224 2026] [security2:error] [pid 411857:tid 412096] [client 115.134.11.136:55122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WbC7ynBpLeKYztQPj5AAAAGs"]
[Tue Jul 21 08:22:20.391143 2026] [security2:error] [pid 411857:tid 412096] [client 115.134.11.136:55122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WbC7ynBpLeKYztQPj5AAAAGs"]
[Tue Jul 21 08:22:20.540390 2026] [security2:error] [pid 418108:tid 418232] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WbA0cxofL2J1zwYrCywABNHk"]
[Tue Jul 21 08:22:20.540655 2026] [security2:error] [pid 418108:tid 418282] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WbA0cxofL2J1zwYrCywABNHk"]
[Tue Jul 21 08:22:20.584416 2026] [security2:error] [pid 419508:tid 419647] [client 20.151.10.161:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/file15.php"] [unique_id "al9WbFcagwCeNbomjVsGzAAAAZg"]
[Tue Jul 21 08:22:20.618422 2026] [security2:error] [pid 418108:tid 418298] [client 20.197.192.193:53142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/wander.php"] [unique_id "al9WbA0cxofL2J1zwYrCzAAAAUQ"]
[Tue Jul 21 08:22:20.684673 2026] [security2:error] [pid 418108:tid 418276] [client 4.194.217.15:4546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/baio/class-wp-http-client.php"] [unique_id "al9WbA0cxofL2J1zwYrCzQAAAS4"]
[Tue Jul 21 08:22:20.706220 2026] [security2:error] [pid 418108:tid 418312] [client 74.249.245.134:61882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/readme.php"] [unique_id "al9WbA0cxofL2J1zwYrCzwAAAVI"]
[Tue Jul 21 08:22:20.726183 2026] [security2:error] [pid 419508:tid 419657] [client 20.226.60.151:64052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/gptsh.php"] [unique_id "al9WbFcagwCeNbomjVsGzwAAAaI"]
[Tue Jul 21 08:22:20.747318 2026] [security2:error] [pid 411857:tid 412107] [client 187.125.243.197:52016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WbC7ynBpLeKYztQPj-AAAAHY"]
[Tue Jul 21 08:22:20.748167 2026] [security2:error] [pid 411857:tid 412107] [client 187.125.243.197:52016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WbC7ynBpLeKYztQPj-AAAAHY"]
[Tue Jul 21 08:22:20.800687 2026] [security2:error] [pid 411857:tid 412017] [client 20.226.60.151:59123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/rithin.php"] [unique_id "al9WbC7ynBpLeKYztQPj_AAAABw"]
[Tue Jul 21 08:22:20.829535 2026] [security2:error] [pid 411857:tid 411992] [client 20.206.105.145:20106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/w2025.php"] [unique_id "al9WbC7ynBpLeKYztQPj_QAAAAM"]
[Tue Jul 21 08:22:20.831902 2026] [security2:error] [pid 411857:tid 412081] [client 20.226.60.151:64059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/fffm.php"] [unique_id "al9WbC7ynBpLeKYztQPj_gAAAFw"]
[Tue Jul 21 08:22:20.918342 2026] [security2:error] [pid 418108:tid 418269] [client 154.208.47.42:61139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WbA0cxofL2J1zwYrC0AAAASc"]
[Tue Jul 21 08:22:20.918450 2026] [security2:error] [pid 418108:tid 418269] [client 154.208.47.42:61139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WbA0cxofL2J1zwYrC0AAAASc"]
[Tue Jul 21 08:22:21.004494 2026] [security2:error] [pid 411857:tid 412070] [client 20.151.10.161:50727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/jp.php"] [unique_id "al9WbS7ynBpLeKYztQPkBQAAAFE"]
[Tue Jul 21 08:22:21.019075 2026] [security2:error] [pid 419508:tid 419679] [client 20.226.60.151:64068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/dfre.php"] [unique_id "al9WbVcagwCeNbomjVsG0wAAAbg"]
[Tue Jul 21 08:22:21.067099 2026] [security2:error] [pid 411857:tid 412004] [client 20.226.60.151:60655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-temp.php"] [unique_id "al9WbS7ynBpLeKYztQPkCgAAAA8"]
[Tue Jul 21 08:22:21.351336 2026] [core:alert] [pid 418108:tid 418316] [client 57.141.18.111:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:22:21.642616 2026] [security2:error] [pid 418108:tid 418240] [client 65.21.113.253:46772] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WbQ0cxofL2J1zwYrC0QAAAQo"]
[Tue Jul 21 08:22:21.709532 2026] [security2:error] [pid 411857:tid 412009] [client 4.194.217.15:1182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/bak.php"] [unique_id "al9WbS7ynBpLeKYztQPkHgAAABQ"]
[Tue Jul 21 08:22:21.821671 2026] [security2:error] [pid 411857:tid 412052] [client 20.226.60.151:64095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/wp-happy.php"] [unique_id "al9WbS7ynBpLeKYztQPkIwAAAD8"]
[Tue Jul 21 08:22:22.005167 2026] [security2:error] [pid 418108:tid 418348] [client 20.151.10.161:50733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/f35.php"] [unique_id "al9Wbg0cxofL2J1zwYrC1gAAAXY"]
[Tue Jul 21 08:22:22.097113 2026] [security2:error] [pid 411857:tid 411873] [remote 216.73.216.184:18203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9Wbi7ynBpLeKYztQPkJwAAUg4"]
[Tue Jul 21 08:22:22.263758 2026] [security2:error] [pid 418108:tid 418297] [client 74.249.245.134:61875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/403.php"] [unique_id "al9Wbg0cxofL2J1zwYrC2AAAAUM"]
[Tue Jul 21 08:22:22.282537 2026] [security2:error] [pid 411857:tid 412028] [client 20.220.225.223:4729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/wp-editor.php"] [unique_id "al9Wbi7ynBpLeKYztQPkKgAAACc"]
[Tue Jul 21 08:22:22.335321 2026] [security2:error] [pid 419508:tid 419729] [client 20.226.60.151:59294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/fpr4.php"] [unique_id "al9WblcagwCeNbomjVsG6gAAAeo"]
[Tue Jul 21 08:22:22.739294 2026] [security2:error] [pid 419508:tid 419747] [client 4.194.217.15:4205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/bdkr28wp.php"] [unique_id "al9WblcagwCeNbomjVsG7gAAAfs"]
[Tue Jul 21 08:22:22.768007 2026] [security2:error] [pid 419508:tid 419693] [client 20.220.225.223:20883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/track.php"] [unique_id "al9WblcagwCeNbomjVsG7wAAAcY"]
[Tue Jul 21 08:22:22.784401 2026] [security2:error] [pid 419508:tid 419639] [client 20.226.60.151:64027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/file88.php"] [unique_id "al9WblcagwCeNbomjVsG8gAAAZA"]
[Tue Jul 21 08:22:22.897594 2026] [security2:error] [pid 419508:tid 419732] [client 20.226.60.151:59316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/ccc.php"] [unique_id "al9WblcagwCeNbomjVsG9QAAAe0"]
[Tue Jul 21 08:22:22.930247 2026] [security2:error] [pid 418108:tid 418268] [client 173.252.95.54:40888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Wbg0cxofL2J1zwYrC3QAAASY"]
[Tue Jul 21 08:22:23.172744 2026] [security2:error] [pid 418108:tid 418187] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/uftxssnr.php"] [unique_id "al9Wbw0cxofL2J1zwYrC3wABJUw"], referer: www.google.com
[Tue Jul 21 08:22:23.311576 2026] [security2:error] [pid 418108:tid 418328] [client 20.151.10.161:50695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wp-load.php"] [unique_id "al9Wbw0cxofL2J1zwYrC4QAAAWI"]
[Tue Jul 21 08:22:23.365212 2026] [security2:error] [pid 411857:tid 412054] [client 20.226.60.151:59113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/777.php"] [unique_id "al9Wby7ynBpLeKYztQPkPAAAAEE"]
[Tue Jul 21 08:22:23.398448 2026] [security2:error] [pid 419508:tid 419715] [client 20.206.105.145:20099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/scxy.php"] [unique_id "al9Wb1cagwCeNbomjVsG_QAAAdw"]
[Tue Jul 21 08:22:23.495942 2026] [security2:error] [pid 419508:tid 419716] [client 20.220.225.223:12319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/ez.php"] [unique_id "al9Wb1cagwCeNbomjVsG_gAAAd0"]
[Tue Jul 21 08:22:23.746941 2026] [security2:error] [pid 419508:tid 419646] [client 69.171.230.40:53218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Wb1cagwCeNbomjVsG_wAAAZc"]
[Tue Jul 21 08:22:23.775487 2026] [security2:error] [pid 419508:tid 419690] [client 4.194.217.15:4201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/bgymj.php"] [unique_id "al9Wb1cagwCeNbomjVsHBQAAAcM"]
[Tue Jul 21 08:22:23.932394 2026] [security2:error] [pid 411857:tid 412043] [client 20.226.60.151:59103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/for.php"] [unique_id "al9Wby7ynBpLeKYztQPkSgAAADY"]
[Tue Jul 21 08:22:24.319964 2026] [security2:error] [pid 411857:tid 412091] [client 223.181.60.88:26145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WcC7ynBpLeKYztQPkVAAAAGY"]
[Tue Jul 21 08:22:24.320161 2026] [security2:error] [pid 411857:tid 412091] [client 223.181.60.88:26145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WcC7ynBpLeKYztQPkVAAAAGY"]
[Tue Jul 21 08:22:24.403562 2026] [security2:error] [pid 418108:tid 418367] [client 65.21.113.253:46772] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Wbw0cxofL2J1zwYrC4wAAAYk"]
[Tue Jul 21 08:22:24.559468 2026] [security2:error] [pid 411857:tid 412052] [client 20.226.60.151:53181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/ssla.php"] [unique_id "al9WcC7ynBpLeKYztQPkXgAAAD8"]
[Tue Jul 21 08:22:24.602867 2026] [security2:error] [pid 411857:tid 412038] [client 20.151.10.161:50699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9WcC7ynBpLeKYztQPkYAAAADE"]
[Tue Jul 21 08:22:24.807782 2026] [security2:error] [pid 411857:tid 412032] [client 4.194.217.15:3594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/biufile.php"] [unique_id "al9WcC7ynBpLeKYztQPkZgAAACs"]
[Tue Jul 21 08:22:24.855896 2026] [security2:error] [pid 411857:tid 412028] [client 74.249.245.134:21286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/max.php"] [unique_id "al9WcC7ynBpLeKYztQPkagAAACc"]
[Tue Jul 21 08:22:25.097513 2026] [security2:error] [pid 411857:tid 411943] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WcS7ynBpLeKYztQPkbAAAXVQ"]
[Tue Jul 21 08:22:25.097755 2026] [security2:error] [pid 411857:tid 412082] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WcS7ynBpLeKYztQPkbAAAXVQ"]
[Tue Jul 21 08:22:25.129185 2026] [security2:error] [pid 418108:tid 418339] [client 20.220.225.223:20884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/2352356666.php"] [unique_id "al9WcQ0cxofL2J1zwYrC5wAAAW0"]
[Tue Jul 21 08:22:25.215047 2026] [security2:error] [pid 418108:tid 418320] [client 103.151.46.103:65308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WcQ0cxofL2J1zwYrC6AAAAVo"]
[Tue Jul 21 08:22:25.215219 2026] [security2:error] [pid 418108:tid 418320] [client 103.151.46.103:65308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WcQ0cxofL2J1zwYrC6AAAAVo"]
[Tue Jul 21 08:22:25.326478 2026] [security2:error] [pid 418108:tid 418289] [client 20.220.225.223:55174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/cro.php"] [unique_id "al9WcQ0cxofL2J1zwYrC6gAAATs"]
[Tue Jul 21 08:22:25.342033 2026] [security2:error] [pid 411857:tid 412115] [client 152.59.34.51:62282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WcS7ynBpLeKYztQPkcQAAAH4"]
[Tue Jul 21 08:22:25.342219 2026] [security2:error] [pid 411857:tid 412115] [client 152.59.34.51:62282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WcS7ynBpLeKYztQPkcQAAAH4"]
[Tue Jul 21 08:22:25.595016 2026] [security2:error] [pid 411857:tid 412039] [client 69.171.230.28:60300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9WcC7ynBpLeKYztQPkWQAAADI"]
[Tue Jul 21 08:22:25.604273 2026] [security2:error] [pid 411857:tid 411974] [remote 216.73.216.184:18203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9WcS7ynBpLeKYztQPkdgAANHI"]
[Tue Jul 21 08:22:25.678096 2026] [security2:error] [pid 419508:tid 419724] [client 117.213.202.34:62245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WcVcagwCeNbomjVsHKwAAAeU"]
[Tue Jul 21 08:22:25.678219 2026] [security2:error] [pid 419508:tid 419724] [client 117.213.202.34:62245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WcVcagwCeNbomjVsHKwAAAeU"]
[Tue Jul 21 08:22:25.731070 2026] [security2:error] [pid 418108:tid 418322] [client 20.220.225.223:12576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/fz.php"] [unique_id "al9WcQ0cxofL2J1zwYrC7AAAAVw"]
[Tue Jul 21 08:22:25.836714 2026] [security2:error] [pid 419508:tid 419715] [client 4.194.217.15:3606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/bless.php"] [unique_id "al9WcVcagwCeNbomjVsHLAAAAdw"]
[Tue Jul 21 08:22:25.867976 2026] [security2:error] [pid 419508:tid 419710] [client 20.151.10.161:10260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wp-links.php"] [unique_id "al9WcVcagwCeNbomjVsHOQAAAdc"]
[Tue Jul 21 08:22:26.172879 2026] [security2:error] [pid 411857:tid 412009] [client 20.226.60.151:59084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cursosonlinesiteoficial.com"] [uri "/zc-131.php"] [unique_id "al9Wci7ynBpLeKYztQPkigAAABQ"]
[Tue Jul 21 08:22:26.225605 2026] [security2:error] [pid 418108:tid 418269] [client 74.249.245.134:53004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/m.php"] [unique_id "al9Wcg0cxofL2J1zwYrDAQAAASc"]
[Tue Jul 21 08:22:26.243180 2026] [security2:error] [pid 418108:tid 418347] [client 65.21.113.253:46772] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WcQ0cxofL2J1zwYrC7QAAAXU"]
[Tue Jul 21 08:22:26.300738 2026] [core:error] [pid 419508:tid 419617] [remote 40.77.167.57:37354] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:26.300773 2026] [core:error] [pid 419508:tid 419617] [remote 40.77.167.57:37354] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:26.410999 2026] [security2:error] [pid 418108:tid 418345] [client 86.106.84.166:49022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.84.106.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Wcg0cxofL2J1zwYrDBQAAAXM"]
[Tue Jul 21 08:22:26.411094 2026] [security2:error] [pid 418108:tid 418345] [client 86.106.84.166:49022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Wcg0cxofL2J1zwYrDBQAAAXM"]
[Tue Jul 21 08:22:26.420691 2026] [security2:error] [pid 419508:tid 419683] [client 173.239.240.20:30041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-login.php"] [unique_id "al9WclcagwCeNbomjVsHQgAAAbw"]
[Tue Jul 21 08:22:26.424598 2026] [core:error] [pid 419508:tid 419517] [remote 40.77.167.57:37354] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:26.424616 2026] [core:error] [pid 419508:tid 419517] [remote 40.77.167.57:37354] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:22:26.432300 2026] [security2:error] [pid 418108:tid 418364] [client 87.116.180.198:27255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wcg0cxofL2J1zwYrDBgAAAYY"]
[Tue Jul 21 08:22:26.432402 2026] [security2:error] [pid 418108:tid 418364] [client 87.116.180.198:27255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wcg0cxofL2J1zwYrDBgAAAYY"]
[Tue Jul 21 08:22:26.867133 2026] [security2:error] [pid 418108:tid 418291] [client 4.194.217.15:5529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/bolt.php"] [unique_id "al9Wcg0cxofL2J1zwYrDDAAAAT0"]
[Tue Jul 21 08:22:26.896397 2026] [security2:error] [pid 419508:tid 419713] [client 150.129.202.39:64880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WclcagwCeNbomjVsHRwAAAdo"]
[Tue Jul 21 08:22:26.896515 2026] [security2:error] [pid 419508:tid 419713] [client 150.129.202.39:64880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WclcagwCeNbomjVsHRwAAAdo"]
[Tue Jul 21 08:22:26.950132 2026] [security2:error] [pid 418108:tid 418270] [client 195.49.128.211:53811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Wcg0cxofL2J1zwYrDDQAAASg"]
[Tue Jul 21 08:22:26.950291 2026] [security2:error] [pid 418108:tid 418270] [client 195.49.128.211:53811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Wcg0cxofL2J1zwYrDDQAAASg"]
[Tue Jul 21 08:22:27.012974 2026] [security2:error] [pid 411857:tid 412059] [client 14.245.224.124:60124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Wcy7ynBpLeKYztQPkmAAAAEY"]
[Tue Jul 21 08:22:27.013096 2026] [security2:error] [pid 411857:tid 412059] [client 14.245.224.124:60124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Wcy7ynBpLeKYztQPkmAAAAEY"]
[Tue Jul 21 08:22:27.128245 2026] [security2:error] [pid 411857:tid 412071] [client 69.171.230.27:47978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Wcy7ynBpLeKYztQPkoAAAAFI"]
[Tue Jul 21 08:22:27.170577 2026] [security2:error] [pid 419508:tid 419682] [client 202.179.75.202:44562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Wc1cagwCeNbomjVsHTgAAAbs"]
[Tue Jul 21 08:22:27.170750 2026] [security2:error] [pid 419508:tid 419682] [client 202.179.75.202:44562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Wc1cagwCeNbomjVsHTgAAAbs"]
[Tue Jul 21 08:22:27.332690 2026] [security2:error] [pid 411857:tid 411959] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wcy7ynBpLeKYztQPkogAAGmM"]
[Tue Jul 21 08:22:27.332964 2026] [security2:error] [pid 411857:tid 411959] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wcy7ynBpLeKYztQPkogAAGmM"]
[Tue Jul 21 08:22:27.386608 2026] [security2:error] [pid 419508:tid 419738] [client 20.226.60.151:60648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9Wc1cagwCeNbomjVsHUAAAAfM"]
[Tue Jul 21 08:22:27.495316 2026] [security2:error] [pid 411857:tid 412054] [client 20.220.225.223:53821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/cron-tab.php"] [unique_id "al9Wcy7ynBpLeKYztQPkqQAAAEE"]
[Tue Jul 21 08:22:27.602454 2026] [security2:error] [pid 419508:tid 419607] [remote 97.74.93.24:39712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fremetexlondrina.com.br"] [uri "/wp-login.php"] [unique_id "al9Wc1cagwCeNbomjVsHVgAByGI"]
[Tue Jul 21 08:22:27.721587 2026] [security2:error] [pid 419508:tid 419689] [client 20.206.105.145:20119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/FWAZ.php"] [unique_id "al9Wc1cagwCeNbomjVsHWQAAAcI"]
[Tue Jul 21 08:22:27.906696 2026] [security2:error] [pid 411857:tid 419466] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9Wcy7ynBpLeKYztQPksQAAUZQ"]
[Tue Jul 21 08:22:27.906842 2026] [security2:error] [pid 411857:tid 412070] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9Wcy7ynBpLeKYztQPksQAAUZQ"]
[Tue Jul 21 08:22:27.984653 2026] [security2:error] [pid 419508:tid 419666] [client 4.194.217.15:4120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/bthil.php"] [unique_id "al9Wc1cagwCeNbomjVsHXAAAAas"]
[Tue Jul 21 08:22:28.301097 2026] [security2:error] [pid 419508:tid 419727] [client 20.151.10.161:50825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/solo1.php"] [unique_id "al9WdFcagwCeNbomjVsHXwAAAeg"]
[Tue Jul 21 08:22:28.503683 2026] [security2:error] [pid 419508:tid 419691] [client 20.220.225.223:53785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/koiy.php"] [unique_id "al9WdFcagwCeNbomjVsHYAAAAcQ"]
[Tue Jul 21 08:22:28.611432 2026] [security2:error] [pid 411857:tid 411906] [remote 216.73.216.184:18203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9WdC7ynBpLeKYztQPkwgAAEi8"]
[Tue Jul 21 08:22:28.718252 2026] [security2:error] [pid 419508:tid 419690] [client 103.106.20.201:62741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WdFcagwCeNbomjVsHYgAAAcM"]
[Tue Jul 21 08:22:28.718369 2026] [security2:error] [pid 419508:tid 419690] [client 103.106.20.201:62741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WdFcagwCeNbomjVsHYgAAAcM"]
[Tue Jul 21 08:22:28.794938 2026] [security2:error] [pid 418108:tid 418305] [client 157.85.206.185:7707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.206.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.brwmarcas.com.br"] [uri "/gestaolancamentos/wp-login.php"] [unique_id "al9WdA0cxofL2J1zwYrDFAAAAUs"]
[Tue Jul 21 08:22:28.907987 2026] [security2:error] [pid 419508:tid 419644] [client 74.249.245.134:61851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/click.php"] [unique_id "al9WdFcagwCeNbomjVsHZQAAAZU"]
[Tue Jul 21 08:22:29.037032 2026] [security2:error] [pid 419508:tid 419694] [client 125.18.144.2:41863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WdVcagwCeNbomjVsHaAAAAcc"]
[Tue Jul 21 08:22:29.037146 2026] [security2:error] [pid 419508:tid 419694] [client 125.18.144.2:41863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WdVcagwCeNbomjVsHaAAAAcc"]
[Tue Jul 21 08:22:29.053738 2026] [security2:error] [pid 419508:tid 419711] [client 4.194.217.15:1165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/buy.php"] [unique_id "al9WdVcagwCeNbomjVsHagAAAdg"]
[Tue Jul 21 08:22:29.105879 2026] [security2:error] [pid 419508:tid 419746] [client 204.12.208.18:64582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inspiracaoecommerce.factorial.studio"] [uri "/wp-includes/js1faeae/index.php"] [unique_id "al9WdVcagwCeNbomjVsHawAAAfo"], referer: https://inspiracaoecommerce.factorial.studio/wp-includes/js1faeae/index.php
[Tue Jul 21 08:22:29.235668 2026] [security2:error] [pid 418108:tid 418115] [remote 198.244.242.61:36988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "financasparaempreendedoras.com.br"] [uri "/robots.txt"] [unique_id "al9WdQ0cxofL2J1zwYrDFQABfwQ"]
[Tue Jul 21 08:22:29.235895 2026] [security2:error] [pid 418108:tid 418357] [client 198.244.242.61:36988] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "financasparaempreendedoras.com.br"] [uri "/robots.txt"] [unique_id "al9WdQ0cxofL2J1zwYrDFQABfwQ"]
[Tue Jul 21 08:22:29.565750 2026] [security2:error] [pid 419508:tid 419733] [client 20.220.225.223:20865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/pn.php"] [unique_id "al9WdVcagwCeNbomjVsHdAAAAe4"]
[Tue Jul 21 08:22:29.615326 2026] [security2:error] [pid 418108:tid 418256] [client 204.12.208.18:64589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-includes/adc37af5/edit.php"] [unique_id "al9WdQ0cxofL2J1zwYrDFgAAARo"], referer: https://aumentodevendas.factorial.studio/wp-includes/adc37af5/edit.php
[Tue Jul 21 08:22:29.687452 2026] [security2:error] [pid 419508:tid 419653] [client 20.151.10.161:50822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/sixxis.php"] [unique_id "al9WdVcagwCeNbomjVsHdwAAAZ4"]
[Tue Jul 21 08:22:29.690406 2026] [security2:error] [pid 419508:tid 419625] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WdVcagwCeNbomjVsHeAABvXQ"]
[Tue Jul 21 08:22:29.690554 2026] [security2:error] [pid 419508:tid 419684] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WdVcagwCeNbomjVsHeAABvXQ"]
[Tue Jul 21 08:22:29.705717 2026] [security2:error] [pid 419508:tid 419643] [client 204.12.208.18:64591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inspiracaoecommerce.factorial.studio"] [uri "/wp-includes/js1faeae/index.php"] [unique_id "al9WdVcagwCeNbomjVsHeQAAAZQ"], referer: https://inspiracaoecommerce.factorial.studio/wp-includes/js1faeae/index.php
[Tue Jul 21 08:22:30.018898 2026] [security2:error] [pid 419508:tid 419705] [client 61.1.167.83:51737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WdlcagwCeNbomjVsHfAAAAdI"]
[Tue Jul 21 08:22:30.019083 2026] [security2:error] [pid 419508:tid 419705] [client 61.1.167.83:51737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WdlcagwCeNbomjVsHfAAAAdI"]
[Tue Jul 21 08:22:30.072877 2026] [security2:error] [pid 418108:tid 418329] [client 120.56.162.40:52178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wdg0cxofL2J1zwYrDGQAAAWM"]
[Tue Jul 21 08:22:30.073011 2026] [security2:error] [pid 418108:tid 418329] [client 120.56.162.40:52178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wdg0cxofL2J1zwYrDGQAAAWM"]
[Tue Jul 21 08:22:30.109919 2026] [security2:error] [pid 411857:tid 412028] [client 51.68.111.241:26249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tabelionatoportoalegre.com.br"] [uri "/robots.txt"] [unique_id "al9Wdi7ynBpLeKYztQPk2AAAACc"]
[Tue Jul 21 08:22:30.110066 2026] [security2:error] [pid 411857:tid 412028] [client 51.68.111.241:26249] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tabelionatoportoalegre.com.br"] [uri "/robots.txt"] [unique_id "al9Wdi7ynBpLeKYztQPk2AAAACc"]
[Tue Jul 21 08:22:30.119664 2026] [security2:error] [pid 419508:tid 419736] [client 4.194.217.15:4111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/byp.php"] [unique_id "al9WdlcagwCeNbomjVsHfQAAAfE"]
[Tue Jul 21 08:22:30.180741 2026] [security2:error] [pid 419508:tid 419762] [client 204.12.208.18:64601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-includes/adc37af5/edit.php"] [unique_id "al9WdlcagwCeNbomjVsHfwAAAgo"], referer: https://aumentodevendas.factorial.studio/wp-includes/adc37af5/edit.php
[Tue Jul 21 08:22:30.261778 2026] [security2:error] [pid 419508:tid 419666] [client 204.12.208.18:64603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inspiracaoecommerce.factorial.studio"] [uri "/wp-includes/js1faeae/index.php"] [unique_id "al9WdlcagwCeNbomjVsHgAAAAas"], referer: https://inspiracaoecommerce.factorial.studio/wp-includes/js1faeae/index.php
[Tue Jul 21 08:22:30.273327 2026] [security2:error] [pid 419508:tid 419601] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WdlcagwCeNbomjVsHgQABwlw"]
[Tue Jul 21 08:22:30.273635 2026] [security2:error] [pid 419508:tid 419689] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WdlcagwCeNbomjVsHgQABwlw"]
[Tue Jul 21 08:22:30.404578 2026] [security2:error] [pid 418108:tid 418355] [client 20.220.225.223:53796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/hp2.php"] [unique_id "al9Wdg0cxofL2J1zwYrDGwAAAX0"]
[Tue Jul 21 08:22:30.651044 2026] [security2:error] [pid 418108:tid 418279] [client 20.151.10.161:10263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/2P.update.php"] [unique_id "al9Wdg0cxofL2J1zwYrDHAAAATE"]
[Tue Jul 21 08:22:30.744769 2026] [security2:error] [pid 419508:tid 419757] [client 204.12.208.18:64610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-includes/adc37af5/edit.php"] [unique_id "al9WdlcagwCeNbomjVsHkgAAAgU"], referer: https://aumentodevendas.factorial.studio/wp-includes/adc37af5/edit.php
[Tue Jul 21 08:22:30.763061 2026] [security2:error] [pid 419508:tid 419564] [remote 51.161.37.140:29272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "financasparaempreendedoras.com.br"] [uri "/"] [unique_id "al9WdlcagwCeNbomjVsHkwABkDc"]
[Tue Jul 21 08:22:30.763210 2026] [security2:error] [pid 419508:tid 419639] [client 51.161.37.140:29272] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "financasparaempreendedoras.com.br"] [uri "/"] [unique_id "al9WdlcagwCeNbomjVsHkwABkDc"]
[Tue Jul 21 08:22:30.918651 2026] [security2:error] [pid 411857:tid 412090] [client 115.134.11.136:55585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wdi7ynBpLeKYztQPk6AAAAGU"]
[Tue Jul 21 08:22:30.919821 2026] [security2:error] [pid 411857:tid 412090] [client 115.134.11.136:55585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wdi7ynBpLeKYztQPk6AAAAGU"]
[Tue Jul 21 08:22:31.152946 2026] [security2:error] [pid 419508:tid 419755] [client 4.194.217.15:3627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/bypass.php"] [unique_id "al9Wd1cagwCeNbomjVsHlgAAAgM"]
[Tue Jul 21 08:22:31.153941 2026] [security2:error] [pid 411857:tid 411859] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Wdy7ynBpLeKYztQPk8AAARAA"]
[Tue Jul 21 08:22:31.154139 2026] [security2:error] [pid 411857:tid 412057] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Wdy7ynBpLeKYztQPk8AAARAA"]
[Tue Jul 21 08:22:31.284941 2026] [security2:error] [pid 411857:tid 411993] [client 187.125.243.197:52517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Wdy7ynBpLeKYztQPk8wAAAAQ"]
[Tue Jul 21 08:22:31.285133 2026] [security2:error] [pid 411857:tid 411993] [client 187.125.243.197:52517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Wdy7ynBpLeKYztQPk8wAAAAQ"]
[Tue Jul 21 08:22:31.512327 2026] [security2:error] [pid 411857:tid 412092] [client 20.197.192.193:53127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/jga.php"] [unique_id "al9Wdy7ynBpLeKYztQPk9wAAAGc"]
[Tue Jul 21 08:22:31.867220 2026] [security2:error] [pid 419508:tid 419754] [client 20.220.225.223:20867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/wp-wpbak.php"] [unique_id "al9Wd1cagwCeNbomjVsHogAAAgI"]
[Tue Jul 21 08:22:31.954947 2026] [security2:error] [pid 418108:tid 418291] [client 20.151.10.161:50741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/a.php"] [unique_id "al9Wdw0cxofL2J1zwYrDJQAAAT0"]
[Tue Jul 21 08:22:32.004598 2026] [security2:error] [pid 411857:tid 412100] [client 157.85.206.185:9426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.206.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.brwmarcas.com.br"] [uri "/gestaolancamentos/wp-login.php"] [unique_id "al9WeC7ynBpLeKYztQPlAAAAAG8"]
[Tue Jul 21 08:22:32.182720 2026] [security2:error] [pid 411857:tid 412108] [client 4.194.217.15:3641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/cache.php"] [unique_id "al9WeC7ynBpLeKYztQPlBQAAAHc"]
[Tue Jul 21 08:22:32.456852 2026] [security2:error] [pid 419508:tid 419712] [client 20.220.225.223:34750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/dr.php"] [unique_id "al9WeFcagwCeNbomjVsHqQAAAdk"]
[Tue Jul 21 08:22:32.591693 2026] [security2:error] [pid 411857:tid 412094] [client 20.206.105.145:20160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/qterm.php"] [unique_id "al9WeC7ynBpLeKYztQPlDQAAAGk"]
[Tue Jul 21 08:22:32.787115 2026] [security2:error] [pid 418108:tid 418293] [client 204.12.208.18:64632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.atracta.factorial.studio"] [uri "/wp-content/qq15e11d/edit.php"] [unique_id "al9WeA0cxofL2J1zwYrDKwAAAT8"], referer: https://www.atracta.factorial.studio/wp-content/qq15e11d/edit.php
[Tue Jul 21 08:22:33.125997 2026] [security2:error] [pid 411857:tid 419458] [remote 216.73.216.184:18203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9WeS7ynBpLeKYztQPlFwAAJIw"]
[Tue Jul 21 08:22:33.248035 2026] [security2:error] [pid 419508:tid 419703] [client 4.194.217.15:1157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/cc.php"] [unique_id "al9WeVcagwCeNbomjVsHsAAAAdA"]
[Tue Jul 21 08:22:33.325987 2026] [security2:error] [pid 419508:tid 419569] [remote 45.79.123.44:41634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bellascleaningsolutionsllc.com"] [uri "/wp-login.php"] [unique_id "al9WeVcagwCeNbomjVsHsQAB3Tw"]
[Tue Jul 21 08:22:33.463853 2026] [security2:error] [pid 411857:tid 412099] [client 204.12.208.18:64651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.atracta.factorial.studio"] [uri "/wp-content/qq15e11d/edit.php"] [unique_id "al9WeS7ynBpLeKYztQPlHQAAAG4"], referer: https://www.atracta.factorial.studio/wp-content/qq15e11d/edit.php
[Tue Jul 21 08:22:33.593091 2026] [security2:error] [pid 419508:tid 419730] [client 74.249.245.134:61838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/lv.php"] [unique_id "al9WeVcagwCeNbomjVsHuQAAAes"]
[Tue Jul 21 08:22:33.601103 2026] [security2:error] [pid 411857:tid 411866] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "al9WeS7ynBpLeKYztQPlHwAAKAc"]
[Tue Jul 21 08:22:33.819490 2026] [security2:error] [pid 411857:tid 412106] [client 20.151.10.161:50874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/k.php"] [unique_id "al9WeS7ynBpLeKYztQPlJAAAAHU"]
[Tue Jul 21 08:22:34.058985 2026] [security2:error] [pid 418108:tid 418343] [client 20.220.225.223:12008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/la.php"] [unique_id "al9Weg0cxofL2J1zwYrDLgAAAXE"]
[Tue Jul 21 08:22:34.112604 2026] [security2:error] [pid 419508:tid 419646] [client 204.12.208.18:64663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.atracta.factorial.studio"] [uri "/wp-content/qq15e11d/edit.php"] [unique_id "al9WelcagwCeNbomjVsHvQAAAZc"], referer: https://www.atracta.factorial.studio/wp-content/qq15e11d/edit.php
[Tue Jul 21 08:22:34.227673 2026] [security2:error] [pid 418108:tid 418209] [remote 47.128.34.22:32864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alperembalagens.com.br"] [uri "/registercadastro"] [unique_id "al9Weg0cxofL2J1zwYrDLwABbmI"]
[Tue Jul 21 08:22:34.326935 2026] [cgid:error] [pid 411857:tid 412026] [client 4.194.217.15:3586] AH01264: stderr from /home3/eltonf08/efrelectronics.com/cgi-bin: script not found or unable to stat
[Tue Jul 21 08:22:34.683884 2026] [security2:error] [pid 411857:tid 412030] [client 4.194.217.15:3586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9Wei7ynBpLeKYztQPlPAAAACk"]
[Tue Jul 21 08:22:34.691146 2026] [security2:error] [pid 418108:tid 418238] [remote 192.241.143.148:49332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/wp-login.php"] [unique_id "al9Weg0cxofL2J1zwYrDMgABGn8"]
[Tue Jul 21 08:22:35.233902 2026] [security2:error] [pid 418108:tid 418362] [client 20.151.10.161:50751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/w.php"] [unique_id "al9Wew0cxofL2J1zwYrDNQAAAYQ"]
[Tue Jul 21 08:22:35.478985 2026] [security2:error] [pid 419508:tid 419696] [client 65.21.113.253:48730] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9We1cagwCeNbomjVsH0AAAAck"]
[Tue Jul 21 08:22:35.621110 2026] [security2:error] [pid 419508:tid 419688] [client 223.181.60.88:27983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9We1cagwCeNbomjVsH1gAAAcE"]
[Tue Jul 21 08:22:35.621281 2026] [security2:error] [pid 419508:tid 419688] [client 223.181.60.88:27983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9We1cagwCeNbomjVsH1gAAAcE"]
[Tue Jul 21 08:22:35.682942 2026] [security2:error] [pid 418108:tid 418230] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al9Wew0cxofL2J1zwYrDOAABZXc"]
[Tue Jul 21 08:22:35.730870 2026] [security2:error] [pid 419508:tid 419675] [client 4.194.217.15:12577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/cgi-bin/class-wp-http-client.php"] [unique_id "al9We1cagwCeNbomjVsH3gAAAbQ"]
[Tue Jul 21 08:22:35.871487 2026] [security2:error] [pid 411857:tid 411966] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "al9Wey7ynBpLeKYztQPlUQAAYGo"]
[Tue Jul 21 08:22:35.964537 2026] [security2:error] [pid 419508:tid 419725] [client 152.59.34.51:62734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9We1cagwCeNbomjVsH4QAAAeY"]
[Tue Jul 21 08:22:35.964656 2026] [security2:error] [pid 419508:tid 419725] [client 152.59.34.51:62734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9We1cagwCeNbomjVsH4QAAAeY"]
[Tue Jul 21 08:22:35.980577 2026] [security2:error] [pid 411857:tid 412054] [client 103.151.46.103:49524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Wey7ynBpLeKYztQPlVAAAAEE"]
[Tue Jul 21 08:22:35.980712 2026] [security2:error] [pid 411857:tid 412054] [client 103.151.46.103:49524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Wey7ynBpLeKYztQPlVAAAAEE"]
[Tue Jul 21 08:22:35.993226 2026] [security2:error] [pid 419508:tid 419531] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9We1cagwCeNbomjVsH4gABuxY"]
[Tue Jul 21 08:22:35.993410 2026] [security2:error] [pid 419508:tid 419682] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9We1cagwCeNbomjVsH4gABuxY"]
[Tue Jul 21 08:22:36.058077 2026] [security2:error] [pid 411857:tid 419451] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "al9WfC7ynBpLeKYztQPlWQAAZYU"]
[Tue Jul 21 08:22:36.229731 2026] [security2:error] [pid 419508:tid 419714] [client 20.151.10.161:50701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/insc.php"] [unique_id "al9WfFcagwCeNbomjVsH6wAAAds"]
[Tue Jul 21 08:22:36.326951 2026] [security2:error] [pid 419508:tid 419652] [client 20.226.60.151:60607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9WfFcagwCeNbomjVsH7AAAAZ0"]
[Tue Jul 21 08:22:36.347259 2026] [security2:error] [pid 419508:tid 419746] [client 117.213.202.34:62778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WfFcagwCeNbomjVsH7QAAAfo"]
[Tue Jul 21 08:22:36.347581 2026] [security2:error] [pid 419508:tid 419746] [client 117.213.202.34:62778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WfFcagwCeNbomjVsH7QAAAfo"]
[Tue Jul 21 08:22:36.639925 2026] [security2:error] [pid 411857:tid 419456] [remote 216.73.216.184:18203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemape.xml"] [unique_id "al9WfC7ynBpLeKYztQPlYQAAY4o"]
[Tue Jul 21 08:22:36.755024 2026] [security2:error] [pid 411857:tid 412045] [client 4.194.217.15:4218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/chosen.php"] [unique_id "al9WfC7ynBpLeKYztQPlZQAAADg"]
[Tue Jul 21 08:22:36.786100 2026] [security2:error] [pid 418108:tid 418254] [client 20.220.225.223:34721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/2x.php"] [unique_id "al9WfA0cxofL2J1zwYrDOgAAARg"]
[Tue Jul 21 08:22:36.917738 2026] [security2:error] [pid 419508:tid 419644] [client 185.8.106.219:19282] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ssvistorias.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9WfFcagwCeNbomjVsH9QAAAZU"]
[Tue Jul 21 08:22:37.070537 2026] [security2:error] [pid 419508:tid 419660] [client 20.151.10.161:10323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9WfVcagwCeNbomjVsH-gAAAaU"]
[Tue Jul 21 08:22:37.210746 2026] [security2:error] [pid 419508:tid 419662] [client 87.116.180.198:14077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WfVcagwCeNbomjVsH-wAAAac"]
[Tue Jul 21 08:22:37.210893 2026] [security2:error] [pid 419508:tid 419662] [client 87.116.180.198:14077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WfVcagwCeNbomjVsH-wAAAac"]
[Tue Jul 21 08:22:37.626493 2026] [security2:error] [pid 411857:tid 412042] [client 195.49.128.211:54405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WfS7ynBpLeKYztQPlbgAAADU"]
[Tue Jul 21 08:22:37.626607 2026] [security2:error] [pid 411857:tid 412042] [client 195.49.128.211:54405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WfS7ynBpLeKYztQPlbgAAADU"]
[Tue Jul 21 08:22:37.639910 2026] [security2:error] [pid 419508:tid 419700] [client 150.129.202.39:64693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WfVcagwCeNbomjVsH_QAAAc0"]
[Tue Jul 21 08:22:37.640084 2026] [security2:error] [pid 419508:tid 419700] [client 150.129.202.39:64693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WfVcagwCeNbomjVsH_QAAAc0"]
[Tue Jul 21 08:22:37.825397 2026] [security2:error] [pid 419508:tid 419678] [client 4.194.217.15:4189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/class-t.api.php"] [unique_id "al9WfVcagwCeNbomjVsIAAAAAbc"]
[Tue Jul 21 08:22:37.839497 2026] [security2:error] [pid 411857:tid 412011] [client 185.8.106.219:12700] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ssvistorias.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9WfS7ynBpLeKYztQPldgAAABY"]
[Tue Jul 21 08:22:37.851484 2026] [security2:error] [pid 419508:tid 419606] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WfVcagwCeNbomjVsIAQABz2E"]
[Tue Jul 21 08:22:37.851639 2026] [security2:error] [pid 419508:tid 419702] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WfVcagwCeNbomjVsIAQABz2E"]
[Tue Jul 21 08:22:37.946856 2026] [security2:error] [pid 418108:tid 418351] [client 20.151.10.161:50742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/u.php"] [unique_id "al9WfQ0cxofL2J1zwYrDPAAAAXk"]
[Tue Jul 21 08:22:38.008979 2026] [security2:error] [pid 411857:tid 412102] [client 74.249.245.134:62041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/cong.php"] [unique_id "al9Wfi7ynBpLeKYztQPldwAAAHE"]
[Tue Jul 21 08:22:38.057003 2026] [security2:error] [pid 419508:tid 419713] [client 202.179.75.202:60698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WflcagwCeNbomjVsIAgAAAdo"]
[Tue Jul 21 08:22:38.057090 2026] [security2:error] [pid 419508:tid 419713] [client 202.179.75.202:60698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WflcagwCeNbomjVsIAgAAAdo"]
[Tue Jul 21 08:22:38.094013 2026] [security2:error] [pid 411857:tid 412116] [client 20.206.105.145:20181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/blurbs.php"] [unique_id "al9Wfi7ynBpLeKYztQPlfAAAAH8"]
[Tue Jul 21 08:22:38.184362 2026] [security2:error] [pid 411857:tid 412063] [client 20.220.225.223:20888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/kq1.php"] [unique_id "al9Wfi7ynBpLeKYztQPlfgAAAEo"]
[Tue Jul 21 08:22:38.577440 2026] [security2:error] [pid 418108:tid 418225] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9Wfg0cxofL2J1zwYrDPQABLnI"]
[Tue Jul 21 08:22:38.577613 2026] [security2:error] [pid 418108:tid 418276] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9Wfg0cxofL2J1zwYrDPQABLnI"]
[Tue Jul 21 08:22:38.666045 2026] [autoindex:error] [pid 419508:tid 419684] [client 104.248.9.162:0] AH01276: Cannot serve directory /home2/andr9968/artemcamadas.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:22:38.679127 2026] [security2:error] [pid 418108:tid 418324] [client 14.245.224.124:60608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Wfg0cxofL2J1zwYrDPgAAAV4"]
[Tue Jul 21 08:22:38.679228 2026] [security2:error] [pid 418108:tid 418324] [client 14.245.224.124:60608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Wfg0cxofL2J1zwYrDPgAAAV4"]
[Tue Jul 21 08:22:38.826100 2026] [security2:error] [pid 419508:tid 419765] [client 20.197.192.193:53164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/x.php"] [unique_id "al9WflcagwCeNbomjVsICAAAAg0"]
[Tue Jul 21 08:22:38.872923 2026] [security2:error] [pid 411857:tid 412112] [client 45.132.227.203:44291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9Wfi7ynBpLeKYztQPliAAAAHs"]
[Tue Jul 21 08:22:38.873519 2026] [security2:error] [pid 411857:tid 412073] [client 185.251.19.64:48223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9Wfi7ynBpLeKYztQPlhwAAAFQ"]
[Tue Jul 21 08:22:38.928440 2026] [security2:error] [pid 418108:tid 418278] [client 4.194.217.15:12594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al9Wfg0cxofL2J1zwYrDQAAAATA"]
[Tue Jul 21 08:22:38.985258 2026] [security2:error] [pid 419508:tid 419706] [client 20.151.10.161:10265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/sss.php"] [unique_id "al9WflcagwCeNbomjVsICwAAAdM"]
[Tue Jul 21 08:22:39.227022 2026] [security2:error] [pid 419508:tid 419651] [client 20.220.225.223:55220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/hp3.php"] [unique_id "al9Wf1cagwCeNbomjVsIEQAAAZw"]
[Tue Jul 21 08:22:39.430257 2026] [security2:error] [pid 419508:tid 419677] [client 103.106.20.201:63335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wf1cagwCeNbomjVsIEwAAAbY"]
[Tue Jul 21 08:22:39.430394 2026] [security2:error] [pid 419508:tid 419677] [client 103.106.20.201:63335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wf1cagwCeNbomjVsIEwAAAbY"]
[Tue Jul 21 08:22:39.459115 2026] [security2:error] [pid 419508:tid 419762] [client 20.151.10.161:10318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/sss.php"] [unique_id "al9Wf1cagwCeNbomjVsIFAAAAgo"]
[Tue Jul 21 08:22:39.570021 2026] [security2:error] [pid 418108:tid 418347] [client 128.127.105.184:49344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Wfw0cxofL2J1zwYrDQgAAAXU"]
[Tue Jul 21 08:22:39.570142 2026] [security2:error] [pid 418108:tid 418347] [client 128.127.105.184:49344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Wfw0cxofL2J1zwYrDQgAAAXU"]
[Tue Jul 21 08:22:39.668342 2026] [security2:error] [pid 411857:tid 412072] [client 125.18.144.2:60026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Wfy7ynBpLeKYztQPllgAAAFM"]
[Tue Jul 21 08:22:39.668484 2026] [security2:error] [pid 411857:tid 412072] [client 125.18.144.2:60026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Wfy7ynBpLeKYztQPllgAAAFM"]
[Tue Jul 21 08:22:39.775223 2026] [security2:error] [pid 419508:tid 419746] [client 20.197.192.193:53129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9Wf1cagwCeNbomjVsIFgAAAfo"]
[Tue Jul 21 08:22:39.877062 2026] [security2:error] [pid 418108:tid 418312] [client 45.132.227.195:61707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9Wfg0cxofL2J1zwYrDPwAAAVI"]
[Tue Jul 21 08:22:39.977939 2026] [security2:error] [pid 411857:tid 412020] [client 4.194.217.15:3098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/class-wp-http-client.php"] [unique_id "al9Wfy7ynBpLeKYztQPlnQAAAB8"]
[Tue Jul 21 08:22:40.048014 2026] [security2:error] [pid 419508:tid 419689] [client 185.8.106.219:19294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.ssvistorias.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9WgFcagwCeNbomjVsIGwAAAcI"]
[Tue Jul 21 08:22:40.117799 2026] [security2:error] [pid 419508:tid 419711] [client 20.220.225.223:42763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/zzz.php"] [unique_id "al9WgFcagwCeNbomjVsIHAAAAdg"]
[Tue Jul 21 08:22:40.142603 2026] [security2:error] [pid 419508:tid 419763] [client 20.151.10.161:50867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/c.php"] [unique_id "al9WgFcagwCeNbomjVsIHQAAAgs"]
[Tue Jul 21 08:22:40.149255 2026] [security2:error] [pid 419508:tid 419600] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WgFcagwCeNbomjVsIHgACDFs"]
[Tue Jul 21 08:22:40.149394 2026] [security2:error] [pid 419508:tid 419764] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WgFcagwCeNbomjVsIHgACDFs"]
[Tue Jul 21 08:22:40.185549 2026] [security2:error] [pid 419508:tid 419693] [client 74.249.245.134:50005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/brand.php"] [unique_id "al9WgFcagwCeNbomjVsIHwAAAcY"]
[Tue Jul 21 08:22:40.751477 2026] [security2:error] [pid 411857:tid 412065] [client 120.56.162.40:52687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WgC7ynBpLeKYztQPlrAAAAEw"]
[Tue Jul 21 08:22:40.751604 2026] [security2:error] [pid 411857:tid 412065] [client 120.56.162.40:52687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WgC7ynBpLeKYztQPlrAAAAEw"]
[Tue Jul 21 08:22:41.012967 2026] [security2:error] [pid 411857:tid 412075] [client 4.194.217.15:4545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/class.php"] [unique_id "al9WgS7ynBpLeKYztQPltAAAAFY"]
[Tue Jul 21 08:22:41.018126 2026] [security2:error] [pid 411857:tid 412030] [client 20.151.10.161:50842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/aa.php"] [unique_id "al9WgS7ynBpLeKYztQPltQAAACk"]
[Tue Jul 21 08:22:41.127978 2026] [security2:error] [pid 419508:tid 419633] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WgVcagwCeNbomjVsIJAABpXw"]
[Tue Jul 21 08:22:41.128140 2026] [security2:error] [pid 419508:tid 419660] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WgVcagwCeNbomjVsIJAABpXw"]
[Tue Jul 21 08:22:41.419059 2026] [security2:error] [pid 419508:tid 419748] [client 115.134.11.136:56049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WgVcagwCeNbomjVsIKQAAAfw"]
[Tue Jul 21 08:22:41.419217 2026] [security2:error] [pid 419508:tid 419748] [client 115.134.11.136:56049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WgVcagwCeNbomjVsIKQAAAfw"]
[Tue Jul 21 08:22:41.486381 2026] [security2:error] [pid 419508:tid 419658] [client 20.220.225.223:20899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/wicked.php"] [unique_id "al9WgVcagwCeNbomjVsIKgAAAaM"]
[Tue Jul 21 08:22:41.503985 2026] [security2:error] [pid 419508:tid 419728] [client 20.151.10.161:10261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/100.php"] [unique_id "al9WgVcagwCeNbomjVsILAAAAek"]
[Tue Jul 21 08:22:41.509513 2026] [security2:error] [pid 418108:tid 418290] [client 185.8.106.219:19296] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ssvistorias.com.br"] [uri "/"] [unique_id "al9WgQ0cxofL2J1zwYrDSAAAATw"]
[Tue Jul 21 08:22:41.538337 2026] [security2:error] [pid 419508:tid 419702] [client 74.249.245.134:45007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/atomlib.php"] [unique_id "al9WgVcagwCeNbomjVsILQAAAc8"]
[Tue Jul 21 08:22:41.655199 2026] [security2:error] [pid 419508:tid 419716] [client 109.248.148.246:59330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9WgVcagwCeNbomjVsILwAAAd0"]
[Tue Jul 21 08:22:41.655296 2026] [security2:error] [pid 419508:tid 419716] [client 109.248.148.246:59330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9WgVcagwCeNbomjVsILwAAAd0"]
[Tue Jul 21 08:22:41.716974 2026] [security2:error] [pid 419508:tid 419650] [client 187.125.243.197:53032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WgVcagwCeNbomjVsIMQAAAZs"]
[Tue Jul 21 08:22:41.717093 2026] [security2:error] [pid 419508:tid 419650] [client 187.125.243.197:53032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WgVcagwCeNbomjVsIMQAAAZs"]
[Tue Jul 21 08:22:41.791495 2026] [security2:error] [pid 419508:tid 419515] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WgVcagwCeNbomjVsIMgAB7gY"]
[Tue Jul 21 08:22:41.791637 2026] [security2:error] [pid 419508:tid 419733] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WgVcagwCeNbomjVsIMgAB7gY"]
[Tue Jul 21 08:22:41.875903 2026] [security2:error] [pid 419508:tid 419697] [client 20.206.105.145:20105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/v543.php"] [unique_id "al9WgVcagwCeNbomjVsINgAAAco"]
[Tue Jul 21 08:22:41.991020 2026] [security2:error] [pid 419508:tid 419685] [client 20.151.10.161:10246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/footer.php"] [unique_id "al9WgVcagwCeNbomjVsIOAAAAb4"]
[Tue Jul 21 08:22:42.095078 2026] [security2:error] [pid 419508:tid 419653] [client 4.194.217.15:4171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/classsmtps.php"] [unique_id "al9WglcagwCeNbomjVsIPAAAAZ4"]
[Tue Jul 21 08:22:42.479230 2026] [security2:error] [pid 419508:tid 419758] [client 20.151.10.161:50748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/users.php"] [unique_id "al9WglcagwCeNbomjVsIQAAAAgY"]
[Tue Jul 21 08:22:42.494405 2026] [security2:error] [pid 419508:tid 419655] [client 20.206.105.145:20214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/w3lls.php"] [unique_id "al9WglcagwCeNbomjVsIQQAAAaA"]
[Tue Jul 21 08:22:42.585954 2026] [security2:error] [pid 411857:tid 412072] [client 20.220.225.223:4689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/aa1.php"] [unique_id "al9Wgi7ynBpLeKYztQPl0AAAAFM"]
[Tue Jul 21 08:22:42.897079 2026] [security2:error] [pid 418108:tid 418275] [client 20.151.10.161:10272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/177.php"] [unique_id "al9Wgg0cxofL2J1zwYrDUAAAAS0"]
[Tue Jul 21 08:22:43.130941 2026] [security2:error] [pid 411857:tid 412029] [client 4.194.217.15:4170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/classwithtostring.php"] [unique_id "al9Wgy7ynBpLeKYztQPl3AAAACg"]
[Tue Jul 21 08:22:43.174545 2026] [security2:error] [pid 419508:tid 419720] [client 20.151.10.161:50852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/config.php"] [unique_id "al9Wg1cagwCeNbomjVsITQAAAeE"]
[Tue Jul 21 08:22:43.186445 2026] [security2:error] [pid 418108:tid 418291] [client 74.7.228.32:43900] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.confiancedigital.com"] [uri "/index.php"] [unique_id "al9Wgg0cxofL2J1zwYrDSwABPQ8"]
[Tue Jul 21 08:22:43.218509 2026] [security2:error] [pid 419508:tid 419660] [client 74.249.245.134:62044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/0x.php"] [unique_id "al9Wg1cagwCeNbomjVsITgAAAaU"]
[Tue Jul 21 08:22:43.527404 2026] [security2:error] [pid 419508:tid 419638] [client 20.151.10.161:50704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/gettest.php"] [unique_id "al9Wg1cagwCeNbomjVsIeAAAAY8"]
[Tue Jul 21 08:22:43.578429 2026] [security2:error] [pid 419508:tid 419757] [client 20.220.225.223:43405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/acew67.php"] [unique_id "al9Wg1cagwCeNbomjVsIfAAAAgU"]
[Tue Jul 21 08:22:43.602027 2026] [security2:error] [pid 411857:tid 411878] [remote 45.79.123.44:34610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "frsadvocacia.net"] [uri "/xmlrpc.php"] [unique_id "al9Wgy7ynBpLeKYztQPl4wAANBM"]
[Tue Jul 21 08:22:43.602222 2026] [security2:error] [pid 411857:tid 412041] [client 45.79.123.44:34610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "frsadvocacia.net"] [uri "/xmlrpc.php"] [unique_id "al9Wgy7ynBpLeKYztQPl4wAANBM"]
[Tue Jul 21 08:22:43.615522 2026] [security2:error] [pid 419508:tid 419696] [client 65.21.113.253:54986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Wg1cagwCeNbomjVsITAAAAck"]
[Tue Jul 21 08:22:43.919894 2026] [security2:error] [pid 418108:tid 418252] [client 20.151.10.161:50823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/min.php"] [unique_id "al9Wgw0cxofL2J1zwYrDVAAAARY"]
[Tue Jul 21 08:22:44.171262 2026] [security2:error] [pid 411857:tid 411994] [client 4.194.217.15:1177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/claude.php"] [unique_id "al9WhC7ynBpLeKYztQPl8AAAAAU"]
[Tue Jul 21 08:22:44.261496 2026] [security2:error] [pid 418108:tid 418321] [client 20.151.10.161:50745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/edorxrr.php"] [unique_id "al9WhA0cxofL2J1zwYrDVwAAAVs"]
[Tue Jul 21 08:22:44.307163 2026] [security2:error] [pid 419508:tid 419600] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/"] [unique_id "al9WhFcagwCeNbomjVsIsgABsFs"]
[Tue Jul 21 08:22:44.308797 2026] [security2:error] [pid 419508:tid 419624] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/"] [unique_id "al9WhFcagwCeNbomjVsIswACAnM"]
[Tue Jul 21 08:22:44.313710 2026] [security2:error] [pid 419508:tid 419512] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/"] [unique_id "al9WhFcagwCeNbomjVsItAAB8gM"]
[Tue Jul 21 08:22:44.314356 2026] [security2:error] [pid 411857:tid 411919] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/"] [unique_id "al9WhC7ynBpLeKYztQPl8gAAJjw"]
[Tue Jul 21 08:22:44.315048 2026] [security2:error] [pid 419508:tid 419610] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/"] [unique_id "al9WhFcagwCeNbomjVsItQABnGU"]
[Tue Jul 21 08:22:44.320404 2026] [security2:error] [pid 418108:tid 418130] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/"] [unique_id "al9WhA0cxofL2J1zwYrDWQABHhM"]
[Tue Jul 21 08:22:44.320486 2026] [security2:error] [pid 419508:tid 419598] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/"] [unique_id "al9WhFcagwCeNbomjVsItgABq1k"]
[Tue Jul 21 08:22:44.321057 2026] [security2:error] [pid 419508:tid 419598] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/"] [unique_id "al9WhFcagwCeNbomjVsItwAB0lk"]
[Tue Jul 21 08:22:44.323582 2026] [security2:error] [pid 418108:tid 418270] [client 81.171.72.93:42562] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/"] [unique_id "al9WhA0cxofL2J1zwYrDWgAAASg"]
[Tue Jul 21 08:22:44.324636 2026] [security2:error] [pid 419508:tid 419668] [client 81.171.72.93:42544] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/"] [unique_id "al9WhFcagwCeNbomjVsIuAAAAa0"]
[Tue Jul 21 08:22:44.325749 2026] [security2:error] [pid 419508:tid 419643] [client 81.171.72.93:42548] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/"] [unique_id "al9WhFcagwCeNbomjVsIuQAAAZQ"]
[Tue Jul 21 08:22:44.327017 2026] [security2:error] [pid 419508:tid 419633] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/"] [unique_id "al9WhFcagwCeNbomjVsIugABtnw"]
[Tue Jul 21 08:22:44.328833 2026] [security2:error] [pid 419508:tid 419667] [client 81.171.72.135:53206] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/"] [unique_id "al9WhFcagwCeNbomjVsIuwAAAaw"]
[Tue Jul 21 08:22:44.329523 2026] [security2:error] [pid 411857:tid 412026] [client 81.171.72.135:53190] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/"] [unique_id "al9WhC7ynBpLeKYztQPl9AAAACU"]
[Tue Jul 21 08:22:44.346562 2026] [security2:error] [pid 418108:tid 418346] [client 213.152.186.163:46880] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9WhA0cxofL2J1zwYrDWwAAAXQ"]
[Tue Jul 21 08:22:44.346791 2026] [security2:error] [pid 418108:tid 418346] [client 213.152.186.163:46880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9WhA0cxofL2J1zwYrDWwAAAXQ"]
[Tue Jul 21 08:22:44.470142 2026] [security2:error] [pid 418108:tid 418163] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/"] [unique_id "al9WhA0cxofL2J1zwYrDXQABcTQ"]
[Tue Jul 21 08:22:44.473020 2026] [security2:error] [pid 418108:tid 418215] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/"] [unique_id "al9WhA0cxofL2J1zwYrDXgABQWg"]
[Tue Jul 21 08:22:44.476981 2026] [security2:error] [pid 418108:tid 418123] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/"] [unique_id "al9WhA0cxofL2J1zwYrDXwABNQw"]
[Tue Jul 21 08:22:44.562332 2026] [security2:error] [pid 411857:tid 411892] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9WhC7ynBpLeKYztQPl9wAAdyE"]
[Tue Jul 21 08:22:44.576303 2026] [security2:error] [pid 411857:tid 412074] [client 20.220.225.223:55179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/bscclapb.php"] [unique_id "al9WhC7ynBpLeKYztQPl-AAAAFU"]
[Tue Jul 21 08:22:44.657177 2026] [security2:error] [pid 419508:tid 419764] [client 20.151.10.161:50854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/hur.php"] [unique_id "al9WhFcagwCeNbomjVsIxQAAAgw"]
[Tue Jul 21 08:22:44.753576 2026] [security2:error] [pid 411857:tid 411986] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9WhC7ynBpLeKYztQPmAAAALX4"]
[Tue Jul 21 08:22:44.764201 2026] [security2:error] [pid 419508:tid 419645] [client 20.151.10.161:51157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9WhFcagwCeNbomjVsIxwAAAZY"]
[Tue Jul 21 08:22:44.797903 2026] [security2:error] [pid 418108:tid 418224] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9WhA0cxofL2J1zwYrDYgABSHE"]
[Tue Jul 21 08:22:44.846278 2026] [security2:error] [pid 419508:tid 419634] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9WhFcagwCeNbomjVsIyQAB7H0"]
[Tue Jul 21 08:22:44.905447 2026] [security2:error] [pid 419508:tid 419595] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/config.xml"] [unique_id "al9WhFcagwCeNbomjVsIywACAVY"]
[Tue Jul 21 08:22:44.907132 2026] [security2:error] [pid 411857:tid 419467] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/backup.sql"] [unique_id "al9WhC7ynBpLeKYztQPmBAAAYJU"]
[Tue Jul 21 08:22:44.907185 2026] [security2:error] [pid 411857:tid 411914] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9WhC7ynBpLeKYztQPmBQAADjc"]
[Tue Jul 21 08:22:44.908393 2026] [security2:error] [pid 419508:tid 419543] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/database.sql"] [unique_id "al9WhFcagwCeNbomjVsIzAAB2iI"]
[Tue Jul 21 08:22:44.911888 2026] [security2:error] [pid 419508:tid 419560] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/dump.sql"] [unique_id "al9WhFcagwCeNbomjVsIzgABpTM"]
[Tue Jul 21 08:22:44.926518 2026] [security2:error] [pid 419508:tid 419586] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/.env.production"] [unique_id "al9WhFcagwCeNbomjVsI0AAB3k0"]
[Tue Jul 21 08:22:44.927586 2026] [security2:error] [pid 419508:tid 419554] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/user_secrets.yml"] [unique_id "al9WhFcagwCeNbomjVsI0QABpy0"]
[Tue Jul 21 08:22:44.936873 2026] [security2:error] [pid 419508:tid 419576] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9WhFcagwCeNbomjVsI0gAB_kM"]
[Tue Jul 21 08:22:44.971094 2026] [security2:error] [pid 419508:tid 419664] [client 81.171.72.93:42574] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9WhFcagwCeNbomjVsI0wAAAak"]
[Tue Jul 21 08:22:44.973502 2026] [security2:error] [pid 419508:tid 419748] [client 81.171.72.135:53238] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9WhFcagwCeNbomjVsI1AAAAfw"]
[Tue Jul 21 08:22:44.973652 2026] [security2:error] [pid 419508:tid 419700] [client 81.171.72.135:53220] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9WhFcagwCeNbomjVsI1QAAAc0"]
[Tue Jul 21 08:22:44.973874 2026] [security2:error] [pid 419508:tid 419712] [client 81.171.72.135:53218] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/database_backup.sql"] [unique_id "al9WhFcagwCeNbomjVsI1gAAAdk"]
[Tue Jul 21 08:22:44.975418 2026] [security2:error] [pid 411857:tid 411989] [client 81.171.72.93:42570] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9WhC7ynBpLeKYztQPmBgAAAAA"]
[Tue Jul 21 08:22:44.975691 2026] [security2:error] [pid 419508:tid 419749] [client 81.171.72.93:42584] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/.env.production"] [unique_id "al9WhFcagwCeNbomjVsI1wAAAf0"]
[Tue Jul 21 08:22:44.976070 2026] [security2:error] [pid 419508:tid 419658] [client 81.171.72.135:53232] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/wp-config.php"] [unique_id "al9WhFcagwCeNbomjVsI2AAAAaM"]
[Tue Jul 21 08:22:44.976772 2026] [security2:error] [pid 419508:tid 419683] [client 81.171.72.93:42594] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9WhFcagwCeNbomjVsI2QAAAbw"]
[Tue Jul 21 08:22:44.987679 2026] [security2:error] [pid 418108:tid 418134] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/server.key"] [unique_id "al9WhA0cxofL2J1zwYrDZAABIxc"]
[Tue Jul 21 08:22:44.992916 2026] [security2:error] [pid 418108:tid 418296] [client 20.151.10.161:10256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/zoro.php"] [unique_id "al9WhA0cxofL2J1zwYrDZQAAAUI"]
[Tue Jul 21 08:22:45.008837 2026] [security2:error] [pid 419508:tid 419703] [client 74.249.245.134:21040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/buy.php"] [unique_id "al9WhVcagwCeNbomjVsI2gAAAdA"]
[Tue Jul 21 08:22:45.018850 2026] [security2:error] [pid 419508:tid 419659] [client 61.1.167.83:52239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WhVcagwCeNbomjVsI2wAAAaQ"]
[Tue Jul 21 08:22:45.018966 2026] [security2:error] [pid 419508:tid 419659] [client 61.1.167.83:52239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WhVcagwCeNbomjVsI2wAAAaQ"]
[Tue Jul 21 08:22:45.037647 2026] [security2:error] [pid 419508:tid 419539] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/.env"] [unique_id "al9WhVcagwCeNbomjVsI3AAB4B4"]
[Tue Jul 21 08:22:45.062730 2026] [security2:error] [pid 419508:tid 419618] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/database_backup.sql"] [unique_id "al9WhVcagwCeNbomjVsI3QACAG0"]
[Tue Jul 21 08:22:45.068872 2026] [security2:error] [pid 418108:tid 418164] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9WhQ0cxofL2J1zwYrDZgABfTU"]
[Tue Jul 21 08:22:45.069548 2026] [security2:error] [pid 419508:tid 419589] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/.env.production"] [unique_id "al9WhVcagwCeNbomjVsI3gABt1A"]
[Tue Jul 21 08:22:45.073222 2026] [security2:error] [pid 419508:tid 419623] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9WhVcagwCeNbomjVsI3wABm3I"]
[Tue Jul 21 08:22:45.098820 2026] [security2:error] [pid 419508:tid 419597] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9WhVcagwCeNbomjVsI4AAB31g"]
[Tue Jul 21 08:22:45.102826 2026] [security2:error] [pid 411857:tid 411861] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9WhS7ynBpLeKYztQPmBwAAaQI"]
[Tue Jul 21 08:22:45.110807 2026] [security2:error] [pid 419508:tid 419733] [client 20.151.10.161:51175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9WhVcagwCeNbomjVsI4QAAAe4"]
[Tue Jul 21 08:22:45.124131 2026] [security2:error] [pid 411857:tid 411915] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/user_secrets.yml"] [unique_id "al9WhS7ynBpLeKYztQPmCAAAbDg"]
[Tue Jul 21 08:22:45.124675 2026] [security2:error] [pid 419508:tid 419555] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/config/production.json"] [unique_id "al9WhVcagwCeNbomjVsI4gACBy4"]
[Tue Jul 21 08:22:45.178369 2026] [security2:error] [pid 418108:tid 418177] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/.npmrc"] [unique_id "al9WhQ0cxofL2J1zwYrDZwABJEI"]
[Tue Jul 21 08:22:45.235981 2026] [security2:error] [pid 419508:tid 419612] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/.git/HEAD"] [unique_id "al9WhVcagwCeNbomjVsI5AABnGc"]
[Tue Jul 21 08:22:45.240114 2026] [security2:error] [pid 419508:tid 419705] [client 20.220.225.223:34749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/edit.php"] [unique_id "al9WhVcagwCeNbomjVsI5QAAAdI"]
[Tue Jul 21 08:22:45.245982 2026] [security2:error] [pid 418108:tid 418362] [client 4.194.217.15:4166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/config.php"] [unique_id "al9WhQ0cxofL2J1zwYrDaAAAAYQ"]
[Tue Jul 21 08:22:45.260331 2026] [security2:error] [pid 419508:tid 419567] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/config.php"] [unique_id "al9WhVcagwCeNbomjVsI5gABlDo"]
[Tue Jul 21 08:22:45.291262 2026] [security2:error] [pid 419508:tid 419588] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9WhVcagwCeNbomjVsI5wAB5k8"]
[Tue Jul 21 08:22:45.301748 2026] [security2:error] [pid 411857:tid 411873] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/.env.production"] [unique_id "al9WhS7ynBpLeKYztQPmDQAAUw4"]
[Tue Jul 21 08:22:45.304384 2026] [security2:error] [pid 419508:tid 419622] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/.env"] [unique_id "al9WhVcagwCeNbomjVsI6AABnXE"]
[Tue Jul 21 08:22:45.320827 2026] [security2:error] [pid 411857:tid 411870] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9WhS7ynBpLeKYztQPmDwAAXgs"]
[Tue Jul 21 08:22:45.359488 2026] [security2:error] [pid 419508:tid 419721] [client 20.151.10.161:50718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/coffexium.php"] [unique_id "al9WhVcagwCeNbomjVsI6QAAAeI"]
[Tue Jul 21 08:22:45.369654 2026] [security2:error] [pid 418108:tid 418176] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/database_backup.sql"] [unique_id "al9WhQ0cxofL2J1zwYrDawABgEE"]
[Tue Jul 21 08:22:45.424990 2026] [security2:error] [pid 419508:tid 419584] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/server.key"] [unique_id "al9WhVcagwCeNbomjVsI6gABx0s"]
[Tue Jul 21 08:22:45.439747 2026] [security2:error] [pid 411857:tid 419458] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/.env"] [unique_id "al9WhS7ynBpLeKYztQPmEQAAJIw"]
[Tue Jul 21 08:22:45.449057 2026] [security2:error] [pid 419508:tid 419632] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/api/.env"] [unique_id "al9WhVcagwCeNbomjVsI6wAB1Xs"]
[Tue Jul 21 08:22:45.449766 2026] [security2:error] [pid 418108:tid 418197] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/database_backup.sql"] [unique_id "al9WhQ0cxofL2J1zwYrDbAABX1Y"]
[Tue Jul 21 08:22:45.465023 2026] [security2:error] [pid 418108:tid 418132] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/secrets.json"] [unique_id "al9WhQ0cxofL2J1zwYrDbQABYRU"]
[Tue Jul 21 08:22:45.468632 2026] [security2:error] [pid 419508:tid 419593] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/backup.zip"] [unique_id "al9WhVcagwCeNbomjVsI7QABrFQ"]
[Tue Jul 21 08:22:45.469000 2026] [security2:error] [pid 419508:tid 419520] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/actuator/heapdump"] [unique_id "al9WhVcagwCeNbomjVsI7gABtgs"]
[Tue Jul 21 08:22:45.480747 2026] [security2:error] [pid 419508:tid 419605] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/.svn/wc.db"] [unique_id "al9WhVcagwCeNbomjVsI7wACBGA"]
[Tue Jul 21 08:22:45.492794 2026] [security2:error] [pid 411857:tid 411891] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/secrets.json"] [unique_id "al9WhS7ynBpLeKYztQPmFAAAHyA"]
[Tue Jul 21 08:22:45.499891 2026] [security2:error] [pid 419508:tid 419518] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/phpinfo.php"] [unique_id "al9WhVcagwCeNbomjVsI8AABlQk"]
[Tue Jul 21 08:22:45.512646 2026] [security2:error] [pid 411857:tid 419469] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9WhS7ynBpLeKYztQPmFQAAGZc"]
[Tue Jul 21 08:22:45.543996 2026] [security2:error] [pid 418108:tid 418342] [client 20.197.192.193:53155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/ee.php"] [unique_id "al9WhQ0cxofL2J1zwYrDbwAAAXA"]
[Tue Jul 21 08:22:45.592673 2026] [security2:error] [pid 419508:tid 419758] [client 81.171.72.93:42612] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/api/.env"] [unique_id "al9WhVcagwCeNbomjVsI8gAAAgY"]
[Tue Jul 21 08:22:45.597343 2026] [security2:error] [pid 418108:tid 418331] [client 81.171.72.93:42614] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/.env"] [unique_id "al9WhQ0cxofL2J1zwYrDcAAAAWU"]
[Tue Jul 21 08:22:45.598265 2026] [security2:error] [pid 419508:tid 419701] [client 81.171.72.93:42600] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9WhVcagwCeNbomjVsI8wAAAc4"]
[Tue Jul 21 08:22:45.598693 2026] [security2:error] [pid 418108:tid 418248] [client 81.171.72.93:42606] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/.git/HEAD"] [unique_id "al9WhQ0cxofL2J1zwYrDcQAAARI"]
[Tue Jul 21 08:22:45.604118 2026] [security2:error] [pid 419508:tid 419689] [client 81.171.72.135:53248] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/actuator/heapdump"] [unique_id "al9WhVcagwCeNbomjVsI9AAAAcI"]
[Tue Jul 21 08:22:45.605259 2026] [security2:error] [pid 419508:tid 419655] [client 81.171.72.135:53252] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/backup.zip"] [unique_id "al9WhVcagwCeNbomjVsI9QAAAaA"]
[Tue Jul 21 08:22:45.605263 2026] [security2:error] [pid 419508:tid 419552] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9WhVcagwCeNbomjVsI9gABxis"]
[Tue Jul 21 08:22:45.605359 2026] [security2:error] [pid 411857:tid 412013] [client 81.171.72.135:53278] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/config.php"] [unique_id "al9WhS7ynBpLeKYztQPmFgAAABg"]
[Tue Jul 21 08:22:45.606143 2026] [security2:error] [pid 411857:tid 411987] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/.git/HEAD"] [unique_id "al9WhS7ynBpLeKYztQPmFwAAKH8"]
[Tue Jul 21 08:22:45.606251 2026] [security2:error] [pid 419508:tid 419763] [client 81.171.72.135:53286] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/.svn/wc.db"] [unique_id "al9WhVcagwCeNbomjVsI9wAAAgs"]
[Tue Jul 21 08:22:45.611908 2026] [security2:error] [pid 419508:tid 419521] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/config.php"] [unique_id "al9WhVcagwCeNbomjVsI-AABkAw"]
[Tue Jul 21 08:22:45.632073 2026] [security2:error] [pid 419508:tid 419550] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/.svn/wc.db"] [unique_id "al9WhVcagwCeNbomjVsI-gABlik"]
[Tue Jul 21 08:22:45.637519 2026] [security2:error] [pid 419508:tid 419516] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/config/production.json"] [unique_id "al9WhVcagwCeNbomjVsI-wABywc"]
[Tue Jul 21 08:22:45.642410 2026] [security2:error] [pid 419508:tid 419614] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/docker-compose.yml"] [unique_id "al9WhVcagwCeNbomjVsI_AAB9Gk"]
[Tue Jul 21 08:22:45.655138 2026] [security2:error] [pid 419508:tid 419526] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/actuator/heapdump"] [unique_id "al9WhVcagwCeNbomjVsI_QAB6RE"]
[Tue Jul 21 08:22:45.658119 2026] [security2:error] [pid 411857:tid 411866] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9WhS7ynBpLeKYztQPmGAAAfgc"]
[Tue Jul 21 08:22:45.658119 2026] [security2:error] [pid 419508:tid 419529] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/.bash_history"] [unique_id "al9WhVcagwCeNbomjVsI_gACDhQ"]
[Tue Jul 21 08:22:45.662157 2026] [security2:error] [pid 418108:tid 418154] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9WhQ0cxofL2J1zwYrDdAABXis"]
[Tue Jul 21 08:22:45.670562 2026] [security2:error] [pid 411857:tid 411965] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/config.xml"] [unique_id "al9WhS7ynBpLeKYztQPmGQAAT2k"]
[Tue Jul 21 08:22:45.671711 2026] [security2:error] [pid 411857:tid 412081] [client 20.151.10.161:51172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/media.php"] [unique_id "al9WhS7ynBpLeKYztQPmGgAAAFw"]
[Tue Jul 21 08:22:45.683498 2026] [security2:error] [pid 411857:tid 411890] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/dump.sql"] [unique_id "al9WhS7ynBpLeKYztQPmGwAAYx8"]
[Tue Jul 21 08:22:45.704123 2026] [security2:error] [pid 411857:tid 419448] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/backup.sql"] [unique_id "al9WhS7ynBpLeKYztQPmHAAAdYM"]
[Tue Jul 21 08:22:45.728961 2026] [security2:error] [pid 411857:tid 412064] [client 20.151.10.161:10284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/app.php"] [unique_id "al9WhS7ynBpLeKYztQPmHgAAAEs"]
[Tue Jul 21 08:22:45.751499 2026] [security2:error] [pid 418108:tid 418114] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/.env"] [unique_id "al9WhQ0cxofL2J1zwYrDdwABFQM"]
[Tue Jul 21 08:22:45.794518 2026] [security2:error] [pid 418108:tid 418338] [client 81.171.72.93:42646] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/phpinfo.php"] [unique_id "al9WhQ0cxofL2J1zwYrDeQAAAWw"]
[Tue Jul 21 08:22:45.795503 2026] [security2:error] [pid 411857:tid 411925] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/backup.sql"] [unique_id "al9WhS7ynBpLeKYztQPmIAAACkI"]
[Tue Jul 21 08:22:45.796397 2026] [security2:error] [pid 419508:tid 419628] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/dump.sql"] [unique_id "al9WhVcagwCeNbomjVsI_wAB_nc"]
[Tue Jul 21 08:22:45.797950 2026] [security2:error] [pid 418108:tid 418310] [client 81.171.72.93:42624] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/server.key"] [unique_id "al9WhQ0cxofL2J1zwYrDegAAAVA"]
[Tue Jul 21 08:22:45.799433 2026] [security2:error] [pid 419508:tid 419663] [client 81.171.72.93:42640] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/docker-compose.yml"] [unique_id "al9WhVcagwCeNbomjVsJAAAAAag"]
[Tue Jul 21 08:22:45.802081 2026] [security2:error] [pid 419508:tid 419509] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/database.sql"] [unique_id "al9WhVcagwCeNbomjVsJAQABxAA"]
[Tue Jul 21 08:22:45.806371 2026] [security2:error] [pid 411857:tid 412004] [client 81.171.72.135:53250] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/backup.tar.gz"] [unique_id "al9WhS7ynBpLeKYztQPmIQAAAA8"]
[Tue Jul 21 08:22:45.808106 2026] [security2:error] [pid 419508:tid 419711] [client 81.171.72.135:53284] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9WhVcagwCeNbomjVsJAgAAAdg"]
[Tue Jul 21 08:22:45.820061 2026] [security2:error] [pid 411857:tid 411883] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/api/.env"] [unique_id "al9WhS7ynBpLeKYztQPmIwAAPBg"]
[Tue Jul 21 08:22:45.828311 2026] [security2:error] [pid 419508:tid 419548] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/database_backup.sql"] [unique_id "al9WhVcagwCeNbomjVsJAwABvCc"]
[Tue Jul 21 08:22:45.844389 2026] [security2:error] [pid 419508:tid 419617] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/.npmrc"] [unique_id "al9WhVcagwCeNbomjVsJBAABwGw"]
[Tue Jul 21 08:22:45.844389 2026] [security2:error] [pid 418108:tid 418142] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/config.php"] [unique_id "al9WhQ0cxofL2J1zwYrDewABDx8"]
[Tue Jul 21 08:22:45.845157 2026] [security2:error] [pid 411857:tid 411933] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/phpinfo.php"] [unique_id "al9WhS7ynBpLeKYztQPmJAAAFEo"]
[Tue Jul 21 08:22:45.850004 2026] [security2:error] [pid 419508:tid 419527] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/dump.sql"] [unique_id "al9WhVcagwCeNbomjVsJBgAB0BI"]
[Tue Jul 21 08:22:45.852798 2026] [security2:error] [pid 419508:tid 419524] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/docker-compose.yml"] [unique_id "al9WhVcagwCeNbomjVsJBwABsQ8"]
[Tue Jul 21 08:22:45.858898 2026] [security2:error] [pid 419508:tid 419517] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/backup.sql"] [unique_id "al9WhVcagwCeNbomjVsJCAABpAg"]
[Tue Jul 21 08:22:45.874004 2026] [security2:error] [pid 411857:tid 411865] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/phpinfo.php"] [unique_id "al9WhS7ynBpLeKYztQPmJQAAAQY"]
[Tue Jul 21 08:22:45.927505 2026] [security2:error] [pid 418108:tid 418137] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/backup.zip"] [unique_id "al9WhQ0cxofL2J1zwYrDfgABJxo"]
[Tue Jul 21 08:22:45.983589 2026] [security2:error] [pid 411857:tid 411932] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/secrets.json"] [unique_id "al9WhS7ynBpLeKYztQPmKAAAFkk"]
[Tue Jul 21 08:22:45.986605 2026] [security2:error] [pid 418108:tid 418128] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/backup.tar.gz"] [unique_id "al9WhQ0cxofL2J1zwYrDgAABVxE"]
[Tue Jul 21 08:22:46.008031 2026] [security2:error] [pid 411857:tid 411912] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/user_secrets.yml"] [unique_id "al9Whi7ynBpLeKYztQPmKQAATDU"]
[Tue Jul 21 08:22:46.021653 2026] [security2:error] [pid 419508:tid 419530] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/actuator/heapdump"] [unique_id "al9WhlcagwCeNbomjVsJCwAB3xU"]
[Tue Jul 21 08:22:46.032494 2026] [security2:error] [pid 419508:tid 419587] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/.env.production"] [unique_id "al9WhlcagwCeNbomjVsJDAACB04"]
[Tue Jul 21 08:22:46.032721 2026] [security2:error] [pid 419508:tid 419592] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/database.sql"] [unique_id "al9WhlcagwCeNbomjVsJDQAB5VM"]
[Tue Jul 21 08:22:46.037923 2026] [security2:error] [pid 419508:tid 419549] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/.svn/wc.db"] [unique_id "al9WhlcagwCeNbomjVsJDgABjyg"]
[Tue Jul 21 08:22:46.040616 2026] [security2:error] [pid 419508:tid 419510] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/.env"] [unique_id "al9WhlcagwCeNbomjVsJDwABtQE"]
[Tue Jul 21 08:22:46.046729 2026] [security2:error] [pid 419508:tid 419607] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9WhlcagwCeNbomjVsJEAAB62I"]
[Tue Jul 21 08:22:46.046729 2026] [security2:error] [pid 418108:tid 418166] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9Whg0cxofL2J1zwYrDgQABOjc"]
[Tue Jul 21 08:22:46.055503 2026] [security2:error] [pid 411857:tid 411949] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/user_secrets.yml"] [unique_id "al9Whi7ynBpLeKYztQPmKgAAPVo"]
[Tue Jul 21 08:22:46.120678 2026] [security2:error] [pid 418108:tid 418226] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9Whg0cxofL2J1zwYrDggABZnM"]
[Tue Jul 21 08:22:46.154302 2026] [security2:error] [pid 418108:tid 418328] [client 20.151.10.161:10283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/core.php"] [unique_id "al9Whg0cxofL2J1zwYrDgwAAAWI"]
[Tue Jul 21 08:22:46.172760 2026] [security2:error] [pid 411857:tid 411967] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/actuator/heapdump"] [unique_id "al9Whi7ynBpLeKYztQPmKwAAcms"]
[Tue Jul 21 08:22:46.180222 2026] [security2:error] [pid 419508:tid 419544] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/server.key"] [unique_id "al9WhlcagwCeNbomjVsJFAABviM"]
[Tue Jul 21 08:22:46.196029 2026] [security2:error] [pid 419508:tid 419590] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/config/production.json"] [unique_id "al9WhlcagwCeNbomjVsJFgAB8VE"]
[Tue Jul 21 08:22:46.215022 2026] [security2:error] [pid 419508:tid 419546] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/api/.env"] [unique_id "al9WhlcagwCeNbomjVsJGAABnCU"]
[Tue Jul 21 08:22:46.215753 2026] [security2:error] [pid 419508:tid 419666] [client 20.226.60.151:60553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/jj.php"] [unique_id "al9WhlcagwCeNbomjVsJGQAAAas"]
[Tue Jul 21 08:22:46.225998 2026] [security2:error] [pid 419508:tid 419528] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9WhlcagwCeNbomjVsJGwABuhM"]
[Tue Jul 21 08:22:46.226015 2026] [security2:error] [pid 418108:tid 418136] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/.git/HEAD"] [unique_id "al9Whg0cxofL2J1zwYrDhAABaxk"]
[Tue Jul 21 08:22:46.226333 2026] [security2:error] [pid 419508:tid 419541] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9WhlcagwCeNbomjVsJGgAB4iA"]
[Tue Jul 21 08:22:46.230530 2026] [security2:error] [pid 419508:tid 419765] [client 81.171.72.93:42662] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/secrets.json"] [unique_id "al9WhlcagwCeNbomjVsJHAAAAg0"]
[Tue Jul 21 08:22:46.231088 2026] [security2:error] [pid 419508:tid 419556] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9WhlcagwCeNbomjVsJHQABxy8"]
[Tue Jul 21 08:22:46.238345 2026] [security2:error] [pid 419508:tid 419601] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9WhlcagwCeNbomjVsJHgAB-1w"]
[Tue Jul 21 08:22:46.254737 2026] [security2:error] [pid 419508:tid 419697] [client 81.171.72.135:53306] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/dump.sql"] [unique_id "al9WhlcagwCeNbomjVsJHwAAAco"]
[Tue Jul 21 08:22:46.255255 2026] [security2:error] [pid 418108:tid 418359] [client 81.171.72.135:53292] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9Whg0cxofL2J1zwYrDhQAAAYE"]
[Tue Jul 21 08:22:46.256485 2026] [security2:error] [pid 418108:tid 418268] [client 81.171.72.135:53310] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/user_secrets.yml"] [unique_id "al9Whg0cxofL2J1zwYrDhgAAASY"]
[Tue Jul 21 08:22:46.263324 2026] [security2:error] [pid 419508:tid 419553] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/backup.zip"] [unique_id "al9WhlcagwCeNbomjVsJIAABlyw"]
[Tue Jul 21 08:22:46.275564 2026] [security2:error] [pid 419508:tid 419542] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9WhlcagwCeNbomjVsJIQABrCE"]
[Tue Jul 21 08:22:46.298626 2026] [security2:error] [pid 419508:tid 419752] [client 4.194.217.15:1207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/.dj/index.php"] [unique_id "al9WhlcagwCeNbomjVsJIgAAAgA"]
[Tue Jul 21 08:22:46.315441 2026] [security2:error] [pid 418108:tid 418120] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9Whg0cxofL2J1zwYrDhwABgwk"]
[Tue Jul 21 08:22:46.324227 2026] [security2:error] [pid 411857:tid 419465] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/backup.tar.gz"] [unique_id "al9Whi7ynBpLeKYztQPmLQAAF5M"]
[Tue Jul 21 08:22:46.363031 2026] [security2:error] [pid 411857:tid 411941] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9Whi7ynBpLeKYztQPmLwAAZFI"]
[Tue Jul 21 08:22:46.373732 2026] [security2:error] [pid 411857:tid 411884] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/backup.zip"] [unique_id "al9Whi7ynBpLeKYztQPmMAAARxk"]
[Tue Jul 21 08:22:46.373955 2026] [security2:error] [pid 418108:tid 418167] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9Whg0cxofL2J1zwYrDiQABHTg"]
[Tue Jul 21 08:22:46.385320 2026] [security2:error] [pid 419508:tid 419596] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/secrets.json"] [unique_id "al9WhlcagwCeNbomjVsJIwACBFc"]
[Tue Jul 21 08:22:46.401293 2026] [security2:error] [pid 419508:tid 419720] [client 223.181.60.88:23441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WhlcagwCeNbomjVsJJAAAAeE"]
[Tue Jul 21 08:22:46.401609 2026] [security2:error] [pid 419508:tid 419720] [client 223.181.60.88:23441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WhlcagwCeNbomjVsJJAAAAeE"]
[Tue Jul 21 08:22:46.409579 2026] [security2:error] [pid 419508:tid 419536] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9WhlcagwCeNbomjVsJJQABvxs"]
[Tue Jul 21 08:22:46.413893 2026] [security2:error] [pid 419508:tid 419625] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/phpinfo.php"] [unique_id "al9WhlcagwCeNbomjVsJJgAB23Q"]
[Tue Jul 21 08:22:46.414930 2026] [security2:error] [pid 411857:tid 411869] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/.npmrc"] [unique_id "al9Whi7ynBpLeKYztQPmMQAALwo"]
[Tue Jul 21 08:22:46.415687 2026] [security2:error] [pid 419508:tid 419583] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/docker-compose.yml"] [unique_id "al9WhlcagwCeNbomjVsJJwABlUo"]
[Tue Jul 21 08:22:46.416143 2026] [security2:error] [pid 419508:tid 419533] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/backup.tar.gz"] [unique_id "al9WhlcagwCeNbomjVsJKAAB5Bg"]
[Tue Jul 21 08:22:46.418081 2026] [security2:error] [pid 419508:tid 419668] [client 81.171.72.93:42688] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9WhlcagwCeNbomjVsJKQAAAa0"]
[Tue Jul 21 08:22:46.422957 2026] [security2:error] [pid 419508:tid 419519] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/api/.env"] [unique_id "al9WhlcagwCeNbomjVsJKgAB1go"]
[Tue Jul 21 08:22:46.425913 2026] [security2:error] [pid 419508:tid 419741] [client 81.171.72.93:42704] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/config/production.json"] [unique_id "al9WhlcagwCeNbomjVsJKwAAAfY"]
[Tue Jul 21 08:22:46.426037 2026] [security2:error] [pid 411857:tid 412102] [client 81.171.72.93:42684] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/.npmrc"] [unique_id "al9Whi7ynBpLeKYztQPmMgAAAHE"]
[Tue Jul 21 08:22:46.426202 2026] [security2:error] [pid 418108:tid 418290] [client 81.171.72.135:53312] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/backup.sql"] [unique_id "al9Whg0cxofL2J1zwYrDiwAAATw"]
[Tue Jul 21 08:22:46.431499 2026] [security2:error] [pid 418108:tid 418233] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/.bash_history"] [unique_id "al9Whg0cxofL2J1zwYrDjAABPXo"]
[Tue Jul 21 08:22:46.434208 2026] [security2:error] [pid 419508:tid 419652] [client 81.171.72.93:42710] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/.bash_history"] [unique_id "al9WhlcagwCeNbomjVsJLAAAAZ0"]
[Tue Jul 21 08:22:46.456165 2026] [security2:error] [pid 419508:tid 419679] [client 81.171.72.135:53324] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/.bash_history"] [unique_id "al9WhlcagwCeNbomjVsJLQAAAbg"]
[Tue Jul 21 08:22:46.457044 2026] [security2:error] [pid 418108:tid 418263] [client 81.171.72.135:53322] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/server.key"] [unique_id "al9Whg0cxofL2J1zwYrDjQAAASE"]
[Tue Jul 21 08:22:46.457069 2026] [security2:error] [pid 418108:tid 418353] [client 81.171.72.135:53318] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/config/production.json"] [unique_id "al9Whg0cxofL2J1zwYrDjgAAAXs"]
[Tue Jul 21 08:22:46.457114 2026] [security2:error] [pid 411857:tid 411964] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/.npmrc"] [unique_id "al9Whi7ynBpLeKYztQPmNAAANWg"]
[Tue Jul 21 08:22:46.459807 2026] [security2:error] [pid 419508:tid 419701] [client 20.151.10.161:50728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/main.php"] [unique_id "al9WhlcagwCeNbomjVsJLwAAAc4"]
[Tue Jul 21 08:22:46.469225 2026] [security2:error] [pid 411857:tid 411923] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/.svn/wc.db"] [unique_id "al9Whi7ynBpLeKYztQPmNQAABEA"]
[Tue Jul 21 08:22:46.505456 2026] [security2:error] [pid 418108:tid 418150] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/docker-compose.yml"] [unique_id "al9Whg0cxofL2J1zwYrDjwABbSc"]
[Tue Jul 21 08:22:46.522230 2026] [security2:error] [pid 419508:tid 419626] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9WhlcagwCeNbomjVsJMAABxnU"]
[Tue Jul 21 08:22:46.551462 2026] [security2:error] [pid 411857:tid 411966] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/.bash_history"] [unique_id "al9Whi7ynBpLeKYztQPmOAAAb2o"]
[Tue Jul 21 08:22:46.564215 2026] [security2:error] [pid 419508:tid 419545] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/server.key"] [unique_id "al9WhlcagwCeNbomjVsJMgACCyQ"]
[Tue Jul 21 08:22:46.566131 2026] [security2:error] [pid 419508:tid 419639] [client 20.220.225.223:20886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/kua.php"] [unique_id "al9WhlcagwCeNbomjVsJNAAAAZA"]
[Tue Jul 21 08:22:46.566189 2026] [security2:error] [pid 419508:tid 419558] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/config.php"] [unique_id "al9WhlcagwCeNbomjVsJMwABljE"]
[Tue Jul 21 08:22:46.576160 2026] [security2:error] [pid 411857:tid 411943] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/config.xml"] [unique_id "al9Whi7ynBpLeKYztQPmOQAAO1Q"]
[Tue Jul 21 08:22:46.577306 2026] [security2:error] [pid 411857:tid 411970] [remote 91.148.245.81:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.10db.com.br"] [uri "/backup.tar.gz"] [unique_id "al9Whi7ynBpLeKYztQPmOgAARm4"]
[Tue Jul 21 08:22:46.603640 2026] [security2:error] [pid 411857:tid 411956] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/.git/HEAD"] [unique_id "al9Whi7ynBpLeKYztQPmRAAAIWA"]
[Tue Jul 21 08:22:46.604243 2026] [security2:error] [pid 419508:tid 419602] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.10db.com.br"] [uri "/.bash_history"] [unique_id "al9WhlcagwCeNbomjVsJNQACDl0"]
[Tue Jul 21 08:22:46.621163 2026] [security2:error] [pid 419508:tid 419725] [client 81.171.72.93:42672] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/user_secrets.yml"] [unique_id "al9WhlcagwCeNbomjVsJNgAAAeY"]
[Tue Jul 21 08:22:46.623583 2026] [security2:error] [pid 419508:tid 419564] [remote 81.171.72.135:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.10db.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9WhlcagwCeNbomjVsJNwABpTc"]
[Tue Jul 21 08:22:46.626749 2026] [security2:error] [pid 418108:tid 418293] [client 20.151.10.161:51159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/images.php"] [unique_id "al9Whg0cxofL2J1zwYrDkAAAAT8"]
[Tue Jul 21 08:22:46.630840 2026] [security2:error] [pid 419508:tid 419643] [client 81.171.72.93:42686] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/config.xml"] [unique_id "al9WhlcagwCeNbomjVsJOAAAAZQ"]
[Tue Jul 21 08:22:46.632764 2026] [security2:error] [pid 419508:tid 419750] [client 20.206.105.145:20221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-ws68.php"] [unique_id "al9WhlcagwCeNbomjVsJOQAAAf4"]
[Tue Jul 21 08:22:46.645075 2026] [security2:error] [pid 411857:tid 411894] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Whi7ynBpLeKYztQPmYwAAfyM"]
[Tue Jul 21 08:22:46.645192 2026] [security2:error] [pid 411857:tid 412116] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Whi7ynBpLeKYztQPmYwAAfyM"]
[Tue Jul 21 08:22:46.660506 2026] [security2:error] [pid 411857:tid 419466] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9Whi7ynBpLeKYztQPmZAAAIJQ"]
[Tue Jul 21 08:22:46.715449 2026] [security2:error] [pid 419508:tid 419547] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/config/production.json"] [unique_id "al9WhlcagwCeNbomjVsJOwABoyY"]
[Tue Jul 21 08:22:46.722947 2026] [security2:error] [pid 418108:tid 418320] [client 103.151.46.103:50125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Whg0cxofL2J1zwYrDkQAAAVo"]
[Tue Jul 21 08:22:46.723810 2026] [security2:error] [pid 418108:tid 418320] [client 103.151.46.103:50125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Whg0cxofL2J1zwYrDkQAAAVo"]
[Tue Jul 21 08:22:46.743291 2026] [security2:error] [pid 418108:tid 418203] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9Whg0cxofL2J1zwYrDkwABHlw"]
[Tue Jul 21 08:22:46.753964 2026] [security2:error] [pid 419508:tid 419562] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/database.sql"] [unique_id "al9WhlcagwCeNbomjVsJPAABwDU"]
[Tue Jul 21 08:22:46.853236 2026] [security2:error] [pid 419508:tid 419627] [remote 91.148.244.131:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.10db.com.br"] [uri "/config.xml"] [unique_id "al9WhlcagwCeNbomjVsJPQAByXY"]
[Tue Jul 21 08:22:46.874672 2026] [security2:error] [pid 419508:tid 419689] [client 65.21.113.253:54986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WhlcagwCeNbomjVsJLgAAAcI"]
[Tue Jul 21 08:22:47.022439 2026] [security2:error] [pid 419508:tid 419734] [client 20.151.10.161:50709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/init.php"] [unique_id "al9Wh1cagwCeNbomjVsJPgAAAe8"]
[Tue Jul 21 08:22:47.049638 2026] [security2:error] [pid 419508:tid 419755] [client 81.171.72.135:53340] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/secrets.json"] [unique_id "al9Wh1cagwCeNbomjVsJPwAAAgM"]
[Tue Jul 21 08:22:47.051716 2026] [security2:error] [pid 419508:tid 419678] [client 81.171.72.93:42726] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/dump.sql"] [unique_id "al9Wh1cagwCeNbomjVsJQAAAAbc"]
[Tue Jul 21 08:22:47.054421 2026] [security2:error] [pid 419508:tid 419726] [client 81.171.72.93:42732] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/wp-config.php"] [unique_id "al9Wh1cagwCeNbomjVsJQgAAAec"]
[Tue Jul 21 08:22:47.055880 2026] [security2:error] [pid 419508:tid 419757] [client 81.171.72.93:42712] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/backup.sql"] [unique_id "al9Wh1cagwCeNbomjVsJRAAAAgU"]
[Tue Jul 21 08:22:47.127736 2026] [security2:error] [pid 418108:tid 418335] [client 81.171.72.135:53388] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/.git/HEAD"] [unique_id "al9Whw0cxofL2J1zwYrDlAAAAWk"]
[Tue Jul 21 08:22:47.153962 2026] [security2:error] [pid 418108:tid 418303] [client 117.213.202.34:63311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Whw0cxofL2J1zwYrDlQAAAUk"]
[Tue Jul 21 08:22:47.154070 2026] [security2:error] [pid 418108:tid 418303] [client 117.213.202.34:63311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Whw0cxofL2J1zwYrDlQAAAUk"]
[Tue Jul 21 08:22:47.331279 2026] [security2:error] [pid 419508:tid 419733] [client 152.59.34.51:63216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Wh1cagwCeNbomjVsJSAAAAe4"]
[Tue Jul 21 08:22:47.331475 2026] [security2:error] [pid 419508:tid 419733] [client 152.59.34.51:63216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Wh1cagwCeNbomjVsJSAAAAe4"]
[Tue Jul 21 08:22:47.421980 2026] [security2:error] [pid 411857:tid 412072] [client 20.151.10.161:50743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/prekel.php"] [unique_id "al9Why7ynBpLeKYztQPmiQAAAFM"]
[Tue Jul 21 08:22:47.524430 2026] [security2:error] [pid 419508:tid 419740] [client 81.171.72.93:42738] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/database.sql"] [unique_id "al9Wh1cagwCeNbomjVsJSwAAAfU"]
[Tue Jul 21 08:22:47.580130 2026] [security2:error] [pid 411857:tid 412015] [client 20.220.225.223:34745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/ez.php"] [unique_id "al9Why7ynBpLeKYztQPmigAAABo"]
[Tue Jul 21 08:22:47.681370 2026] [security2:error] [pid 419508:tid 419720] [client 81.171.72.135:53406] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/.npmrc"] [unique_id "al9Wh1cagwCeNbomjVsJTQAAAeE"]
[Tue Jul 21 08:22:47.682049 2026] [security2:error] [pid 419508:tid 419756] [client 81.171.72.135:53408] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/.env"] [unique_id "al9Wh1cagwCeNbomjVsJTgAAAgQ"]
[Tue Jul 21 08:22:47.692208 2026] [security2:error] [pid 419508:tid 419686] [client 81.171.72.93:42806] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/database_backup.sql"] [unique_id "al9Wh1cagwCeNbomjVsJTwAAAb8"]
[Tue Jul 21 08:22:47.692703 2026] [security2:error] [pid 419508:tid 419714] [client 81.171.72.93:42792] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/config.php"] [unique_id "al9Wh1cagwCeNbomjVsJUAAAAds"]
[Tue Jul 21 08:22:47.692731 2026] [security2:error] [pid 411857:tid 412083] [client 81.171.72.93:42818] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/backup.tar.gz"] [unique_id "al9Why7ynBpLeKYztQPmjgAAAF4"]
[Tue Jul 21 08:22:47.720315 2026] [security2:error] [pid 419508:tid 419741] [client 4.194.217.15:4158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/.vscode/class-wp-http-client.php"] [unique_id "al9Wh1cagwCeNbomjVsJUQAAAfY"]
[Tue Jul 21 08:22:47.728338 2026] [security2:error] [pid 411857:tid 412066] [client 81.171.72.93:42786] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/backup.zip"] [unique_id "al9Why7ynBpLeKYztQPmkAAAAE0"]
[Tue Jul 21 08:22:47.755111 2026] [security2:error] [pid 411857:tid 412078] [client 81.171.72.135:53426] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9Why7ynBpLeKYztQPmkgAAAFk"]
[Tue Jul 21 08:22:47.760373 2026] [security2:error] [pid 411857:tid 412111] [client 81.171.72.135:53436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9Why7ynBpLeKYztQPmlAAAAHo"]
[Tue Jul 21 08:22:47.782432 2026] [security2:error] [pid 419508:tid 419652] [client 20.151.10.161:50708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/0.php"] [unique_id "al9Wh1cagwCeNbomjVsJUgAAAZ0"]
[Tue Jul 21 08:22:47.917134 2026] [security2:error] [pid 418108:tid 418340] [client 87.116.180.198:27150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Whw0cxofL2J1zwYrDmAAAAW4"]
[Tue Jul 21 08:22:47.920159 2026] [security2:error] [pid 418108:tid 418340] [client 87.116.180.198:27150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Whw0cxofL2J1zwYrDmAAAAW4"]
[Tue Jul 21 08:22:47.998305 2026] [security2:error] [pid 411857:tid 411996] [client 20.151.10.161:51195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/adminner.php"] [unique_id "al9Why7ynBpLeKYztQPmmAAAAAc"]
[Tue Jul 21 08:22:48.164279 2026] [security2:error] [pid 419508:tid 419709] [client 151.63.71.144:52294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WiFcagwCeNbomjVsJVQAAAdY"]
[Tue Jul 21 08:22:48.164484 2026] [security2:error] [pid 419508:tid 419709] [client 151.63.71.144:52294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WiFcagwCeNbomjVsJVQAAAdY"]
[Tue Jul 21 08:22:48.187380 2026] [security2:error] [pid 418108:tid 418257] [client 20.151.10.161:50717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/BDKR28.php"] [unique_id "al9WiA0cxofL2J1zwYrDnAAAARs"]
[Tue Jul 21 08:22:48.231222 2026] [security2:error] [pid 411857:tid 412001] [client 150.129.202.39:64604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WiC7ynBpLeKYztQPmmwAAAAw"]
[Tue Jul 21 08:22:48.231448 2026] [security2:error] [pid 411857:tid 412001] [client 150.129.202.39:64604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WiC7ynBpLeKYztQPmmwAAAAw"]
[Tue Jul 21 08:22:48.266397 2026] [security2:error] [pid 418108:tid 418153] [remote 74.7.242.37:53148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/xmlrpc.php"] [unique_id "al9WiA0cxofL2J1zwYrDmwABESo"], referer: https://buyonlinetodayatadiscount.net/category/category-1/
[Tue Jul 21 08:22:48.316117 2026] [security2:error] [pid 411857:tid 412109] [client 195.49.128.211:54995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WiC7ynBpLeKYztQPmoAAAAHg"]
[Tue Jul 21 08:22:48.316394 2026] [security2:error] [pid 411857:tid 412109] [client 195.49.128.211:54995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WiC7ynBpLeKYztQPmoAAAAHg"]
[Tue Jul 21 08:22:48.325193 2026] [security2:error] [pid 418108:tid 418262] [client 81.171.72.135:53446] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9WiA0cxofL2J1zwYrDnQAAASA"]
[Tue Jul 21 08:22:48.328024 2026] [security2:error] [pid 419508:tid 419729] [client 81.171.72.135:53448] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/phpinfo.php"] [unique_id "al9WiFcagwCeNbomjVsJWAAAAeo"]
[Tue Jul 21 08:22:48.341356 2026] [security2:error] [pid 411857:tid 411871] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WiC7ynBpLeKYztQPmogAAPQw"]
[Tue Jul 21 08:22:48.341750 2026] [security2:error] [pid 411857:tid 411871] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WiC7ynBpLeKYztQPmogAAPQw"]
[Tue Jul 21 08:22:48.342860 2026] [security2:error] [pid 411857:tid 412057] [client 14.245.224.124:61065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WiC7ynBpLeKYztQPmowAAAEQ"]
[Tue Jul 21 08:22:48.342977 2026] [security2:error] [pid 411857:tid 412057] [client 14.245.224.124:61065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WiC7ynBpLeKYztQPmowAAAEQ"]
[Tue Jul 21 08:22:48.398477 2026] [security2:error] [pid 411857:tid 412012] [client 81.171.72.135:53454] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/api/.env"] [unique_id "al9WiC7ynBpLeKYztQPmpAAAABc"]
[Tue Jul 21 08:22:48.399409 2026] [security2:error] [pid 418108:tid 418360] [client 81.171.72.135:53484] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/config.xml"] [unique_id "al9WiA0cxofL2J1zwYrDngAAAYI"]
[Tue Jul 21 08:22:48.400776 2026] [security2:error] [pid 418108:tid 418279] [client 20.206.105.145:20100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/xyn.php"] [unique_id "al9WiA0cxofL2J1zwYrDnwAAATE"]
[Tue Jul 21 08:22:48.488028 2026] [security2:error] [pid 418108:tid 418265] [client 81.171.72.93:42866] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9WiA0cxofL2J1zwYrDogAAASM"]
[Tue Jul 21 08:22:48.495450 2026] [security2:error] [pid 419508:tid 419725] [client 81.171.72.93:42834] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/.svn/wc.db"] [unique_id "al9WiFcagwCeNbomjVsJWQAAAeY"]
[Tue Jul 21 08:22:48.496322 2026] [security2:error] [pid 418108:tid 418299] [client 81.171.72.93:42848] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/actuator/heapdump"] [unique_id "al9WiA0cxofL2J1zwYrDowAAAUU"]
[Tue Jul 21 08:22:48.498319 2026] [security2:error] [pid 418108:tid 418363] [client 81.171.72.93:42826] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9WiA0cxofL2J1zwYrDpAAAAYU"]
[Tue Jul 21 08:22:48.500211 2026] [security2:error] [pid 411857:tid 412074] [client 20.151.10.161:51171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/admin.php"] [unique_id "al9WiC7ynBpLeKYztQPmpwAAAFU"]
[Tue Jul 21 08:22:48.529066 2026] [security2:error] [pid 419508:tid 419766] [client 81.171.72.135:53468] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/docker-compose.yml"] [unique_id "al9WiFcagwCeNbomjVsJWgAAAg4"]
[Tue Jul 21 08:22:48.530624 2026] [security2:error] [pid 418108:tid 418329] [client 81.171.72.135:53470] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/database.sql"] [unique_id "al9WiA0cxofL2J1zwYrDpQAAAWM"]
[Tue Jul 21 08:22:48.551612 2026] [security2:error] [pid 419508:tid 419712] [client 20.151.10.161:10302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/f35.update.php"] [unique_id "al9WiFcagwCeNbomjVsJXwAAAdk"]
[Tue Jul 21 08:22:48.552505 2026] [security2:error] [pid 419508:tid 419664] [client 20.220.225.223:34696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/fz.php"] [unique_id "al9WiFcagwCeNbomjVsJYAAAAak"]
[Tue Jul 21 08:22:48.703382 2026] [security2:error] [pid 418108:tid 418296] [client 81.171.72.93:42850] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "10db.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9WiA0cxofL2J1zwYrDpwAAAUI"]
[Tue Jul 21 08:22:48.766968 2026] [security2:error] [pid 419508:tid 419650] [client 74.249.245.134:21036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/sx.php"] [unique_id "al9WiFcagwCeNbomjVsJYQAAAZs"]
[Tue Jul 21 08:22:48.773596 2026] [autoindex:error] [pid 418108:tid 418362] [client 4.194.217.15:4164] AH01276: Cannot serve directory /home3/eltonf08/efrelectronics.com/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:22:48.957771 2026] [security2:error] [pid 419508:tid 419730] [client 20.151.10.161:50778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/k.php"] [unique_id "al9WiFcagwCeNbomjVsJYwAAAes"]
[Tue Jul 21 08:22:48.960242 2026] [security2:error] [pid 419508:tid 419734] [client 20.151.10.161:50703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/f900.php"] [unique_id "al9WiFcagwCeNbomjVsJZAAAAe8"]
[Tue Jul 21 08:22:48.987448 2026] [security2:error] [pid 419508:tid 419658] [client 202.179.75.202:60402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WiFcagwCeNbomjVsJZQAAAaM"]
[Tue Jul 21 08:22:48.987577 2026] [security2:error] [pid 419508:tid 419658] [client 202.179.75.202:60402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WiFcagwCeNbomjVsJZQAAAaM"]
[Tue Jul 21 08:22:49.116793 2026] [security2:error] [pid 418108:tid 418304] [client 4.194.217.15:4164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/.well-known/about.php"] [unique_id "al9WiQ0cxofL2J1zwYrDqQAAAUo"]
[Tue Jul 21 08:22:49.164239 2026] [security2:error] [pid 419508:tid 419682] [client 81.171.72.135:53510] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9WiVcagwCeNbomjVsJaAAAAbs"]
[Tue Jul 21 08:22:49.164566 2026] [security2:error] [pid 411857:tid 412073] [client 81.171.72.135:53520] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.10db.com.br"] [uri "/.env.production"] [unique_id "al9WiS7ynBpLeKYztQPmswAAAFQ"]
[Tue Jul 21 08:22:49.203191 2026] [security2:error] [pid 411857:tid 411989] [client 20.220.225.223:53769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/else1.php"] [unique_id "al9WiS7ynBpLeKYztQPmtAAAAAA"]
[Tue Jul 21 08:22:49.291332 2026] [security2:error] [pid 419508:tid 419511] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WiVcagwCeNbomjVsJbQAB5wI"]
[Tue Jul 21 08:22:49.291567 2026] [security2:error] [pid 419508:tid 419726] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WiVcagwCeNbomjVsJbQAB5wI"]
[Tue Jul 21 08:22:49.302840 2026] [security2:error] [pid 419508:tid 419563] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/"] [unique_id "al9WiVcagwCeNbomjVsJcAACCTY"]
[Tue Jul 21 08:22:49.304833 2026] [security2:error] [pid 419508:tid 419603] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/"] [unique_id "al9WiVcagwCeNbomjVsJcQAB8l4"]
[Tue Jul 21 08:22:49.309371 2026] [security2:error] [pid 419508:tid 419616] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/"] [unique_id "al9WiVcagwCeNbomjVsJcwABnGs"]
[Tue Jul 21 08:22:49.441395 2026] [security2:error] [pid 418108:tid 418349] [client 20.151.10.161:10332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/xmrl.php"] [unique_id "al9WiQ0cxofL2J1zwYrDqwAAAXc"]
[Tue Jul 21 08:22:49.573321 2026] [security2:error] [pid 419508:tid 419620] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9WiVcagwCeNbomjVsJdgAB1G8"]
[Tue Jul 21 08:22:49.576878 2026] [security2:error] [pid 419508:tid 419525] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9WiVcagwCeNbomjVsJdwAB-hA"]
[Tue Jul 21 08:22:49.605739 2026] [security2:error] [pid 411857:tid 412099] [client 20.151.10.161:51724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/x.php"] [unique_id "al9WiS7ynBpLeKYztQPmugAAAG4"]
[Tue Jul 21 08:22:49.755570 2026] [security2:error] [pid 411857:tid 412020] [client 20.151.10.161:50715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/memberfuns.php"] [unique_id "al9WiS7ynBpLeKYztQPmvAAAAB8"]
[Tue Jul 21 08:22:49.761367 2026] [security2:error] [pid 419508:tid 419566] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9WiVcagwCeNbomjVsJegACATk"]
[Tue Jul 21 08:22:49.768425 2026] [security2:error] [pid 419508:tid 419615] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/.git/HEAD"] [unique_id "al9WiVcagwCeNbomjVsJewAB3mo"]
[Tue Jul 21 08:22:49.917252 2026] [security2:error] [pid 419508:tid 419630] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/config.xml"] [unique_id "al9WiVcagwCeNbomjVsJfAABp3k"]
[Tue Jul 21 08:22:49.928885 2026] [security2:error] [pid 419508:tid 419572] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9WiVcagwCeNbomjVsJfQABlD8"]
[Tue Jul 21 08:22:50.105190 2026] [security2:error] [pid 419508:tid 419606] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/phpinfo.php"] [unique_id "al9WilcagwCeNbomjVsJfwABqGE"]
[Tue Jul 21 08:22:50.115287 2026] [security2:error] [pid 419508:tid 419691] [client 20.151.10.161:10273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/ms.php"] [unique_id "al9WilcagwCeNbomjVsJgAAAAcQ"]
[Tue Jul 21 08:22:50.119995 2026] [security2:error] [pid 419508:tid 419540] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/docker-compose.yml"] [unique_id "al9WilcagwCeNbomjVsJgQAB5h8"]
[Tue Jul 21 08:22:50.135636 2026] [security2:error] [pid 419508:tid 419681] [client 103.106.20.201:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.20.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WilcagwCeNbomjVsJggAAAbo"]
[Tue Jul 21 08:22:50.135753 2026] [security2:error] [pid 419508:tid 419681] [client 103.106.20.201:63958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WilcagwCeNbomjVsJggAAAbo"]
[Tue Jul 21 08:22:50.172677 2026] [security2:error] [pid 419508:tid 419750] [client 65.21.113.253:54986] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WiVcagwCeNbomjVsJfgAAAf4"]
[Tue Jul 21 08:22:50.183167 2026] [security2:error] [pid 411857:tid 412070] [client 20.197.192.193:52247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/blue.php"] [unique_id "al9Wii7ynBpLeKYztQPmwQAAAFE"]
[Tue Jul 21 08:22:50.227541 2026] [autoindex:error] [pid 419508:tid 419660] [client 4.194.217.15:3616] AH01276: Cannot serve directory /home3/eltonf08/efrelectronics.com/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:22:50.291888 2026] [security2:error] [pid 418108:tid 418169] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/.env"] [unique_id "al9Wig0cxofL2J1zwYrDsAABdjo"]
[Tue Jul 21 08:22:50.300682 2026] [security2:error] [pid 418108:tid 418159] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/api/.env"] [unique_id "al9Wig0cxofL2J1zwYrDsQABczA"]
[Tue Jul 21 08:22:50.311011 2026] [security2:error] [pid 419508:tid 419599] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/.env.production"] [unique_id "al9WilcagwCeNbomjVsJhgABzVo"]
[Tue Jul 21 08:22:50.330185 2026] [security2:error] [pid 418108:tid 418287] [client 20.151.10.161:51190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wss.php"] [unique_id "al9Wig0cxofL2J1zwYrDsgAAATk"]
[Tue Jul 21 08:22:50.348299 2026] [security2:error] [pid 419508:tid 419701] [client 14.97.58.74:10301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WilcagwCeNbomjVsJhwAAAc4"]
[Tue Jul 21 08:22:50.348567 2026] [security2:error] [pid 419508:tid 419701] [client 14.97.58.74:10301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WilcagwCeNbomjVsJhwAAAc4"]
[Tue Jul 21 08:22:50.406510 2026] [security2:error] [pid 411857:tid 412084] [client 20.151.10.161:10281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/zz.php"] [unique_id "al9Wii7ynBpLeKYztQPmxQAAAF8"]
[Tue Jul 21 08:22:50.484979 2026] [security2:error] [pid 419508:tid 419600] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9WilcagwCeNbomjVsJiQABvVs"]
[Tue Jul 21 08:22:50.489042 2026] [security2:error] [pid 419508:tid 419624] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/server.key"] [unique_id "al9WilcagwCeNbomjVsJigAByXM"]
[Tue Jul 21 08:22:50.501694 2026] [security2:error] [pid 419508:tid 419512] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/config/production.json"] [unique_id "al9WilcagwCeNbomjVsJiwACBwM"]
[Tue Jul 21 08:22:50.615090 2026] [security2:error] [pid 419508:tid 419610] [remote 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WilcagwCeNbomjVsJjQAB72U"]
[Tue Jul 21 08:22:50.615372 2026] [security2:error] [pid 419508:tid 419734] [client 2401:4900:8fdf:abbb:71be:3077:ad34:abd4:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "royalbsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al9WilcagwCeNbomjVsJjQAB72U"]
[Tue Jul 21 08:22:50.636670 2026] [security2:error] [pid 419508:tid 419635] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/user_secrets.yml"] [unique_id "al9WilcagwCeNbomjVsJjgABxX4"]
[Tue Jul 21 08:22:50.673939 2026] [security2:error] [pid 418108:tid 418199] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9Wig0cxofL2J1zwYrDswABOlg"]
[Tue Jul 21 08:22:50.677449 2026] [security2:error] [pid 418108:tid 418170] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/secrets.json"] [unique_id "al9Wig0cxofL2J1zwYrDtAABZjs"]
[Tue Jul 21 08:22:50.677822 2026] [security2:error] [pid 418108:tid 418267] [client 74.249.245.134:21005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/article.php"] [unique_id "al9Wig0cxofL2J1zwYrDtQAAASU"]
[Tue Jul 21 08:22:50.694324 2026] [security2:error] [pid 419508:tid 419633] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/.npmrc"] [unique_id "al9WilcagwCeNbomjVsJkAAB8Xw"]
[Tue Jul 21 08:22:50.767640 2026] [security2:error] [pid 419508:tid 419705] [client 20.206.105.145:20170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/green3.php"] [unique_id "al9WilcagwCeNbomjVsJkQAAAdI"]
[Tue Jul 21 08:22:50.805368 2026] [security2:error] [pid 419508:tid 419765] [client 20.151.10.161:50710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/for.php"] [unique_id "al9WilcagwCeNbomjVsJlAAAAg0"]
[Tue Jul 21 08:22:50.826218 2026] [security2:error] [pid 419508:tid 419608] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/.bash_history"] [unique_id "al9WilcagwCeNbomjVsJlQAByGM"]
[Tue Jul 21 08:22:50.861896 2026] [security2:error] [pid 419508:tid 419523] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/config.php"] [unique_id "al9WilcagwCeNbomjVsJlgACBQ4"]
[Tue Jul 21 08:22:50.865474 2026] [security2:error] [pid 419508:tid 419531] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/dump.sql"] [unique_id "al9WilcagwCeNbomjVsJlwABwhY"]
[Tue Jul 21 08:22:50.884078 2026] [security2:error] [pid 419508:tid 419634] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/backup.sql"] [unique_id "al9WilcagwCeNbomjVsJmAAByn0"]
[Tue Jul 21 08:22:50.927830 2026] [security2:error] [pid 419508:tid 419760] [client 4.194.217.15:3616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/.well-known/acme-challenge/muse.php"] [unique_id "al9WilcagwCeNbomjVsJnQAAAgg"]
[Tue Jul 21 08:22:51.015892 2026] [security2:error] [pid 419508:tid 419586] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/database.sql"] [unique_id "al9Wi1cagwCeNbomjVsJnwABtk0"]
[Tue Jul 21 08:22:51.050658 2026] [security2:error] [pid 418108:tid 418205] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/database_backup.sql"] [unique_id "al9Wiw0cxofL2J1zwYrDuAABE14"]
[Tue Jul 21 08:22:51.076269 2026] [security2:error] [pid 419508:tid 419554] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/actuator/heapdump"] [unique_id "al9Wi1cagwCeNbomjVsJoAABlS0"]
[Tue Jul 21 08:22:51.080373 2026] [security2:error] [pid 418108:tid 418272] [client 20.151.10.161:51198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/ty.php"] [unique_id "al9Wiw0cxofL2J1zwYrDuQAAASo"]
[Tue Jul 21 08:22:51.192046 2026] [security2:error] [pid 411857:tid 411965] [remote 20.153.140.50:51408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9Wiy7ynBpLeKYztQPmzwAAFGk"]
[Tue Jul 21 08:22:51.206441 2026] [security2:error] [pid 419508:tid 419576] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/.svn/wc.db"] [unique_id "al9Wi1cagwCeNbomjVsJoQAB20M"]
[Tue Jul 21 08:22:51.269244 2026] [security2:error] [pid 419508:tid 419573] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9Wi1cagwCeNbomjVsJogABt0A"]
[Tue Jul 21 08:22:51.347860 2026] [security2:error] [pid 419508:tid 419758] [client 20.151.10.161:10253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/yup.php"] [unique_id "al9Wi1cagwCeNbomjVsJowAAAgY"]
[Tue Jul 21 08:22:51.375528 2026] [security2:error] [pid 411857:tid 412043] [client 120.56.162.40:53197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wiy7ynBpLeKYztQPm0QAAADY"]
[Tue Jul 21 08:22:51.375680 2026] [security2:error] [pid 411857:tid 412043] [client 120.56.162.40:53197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wiy7ynBpLeKYztQPm0QAAADY"]
[Tue Jul 21 08:22:51.395769 2026] [security2:error] [pid 419508:tid 419618] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9Wi1cagwCeNbomjVsJpwABwW0"]
[Tue Jul 21 08:22:51.410822 2026] [security2:error] [pid 411857:tid 419448] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/backup.zip"] [unique_id "al9Wiy7ynBpLeKYztQPm0gAAYYM"]
[Tue Jul 21 08:22:51.589401 2026] [security2:error] [pid 411857:tid 411925] [remote 81.171.74.60:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.10db.com.br"] [uri "/backup.tar.gz"] [unique_id "al9Wiy7ynBpLeKYztQPm1QAAeEI"]
[Tue Jul 21 08:22:51.639498 2026] [security2:error] [pid 419508:tid 419711] [client 20.151.10.161:50827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/wpxml.php"] [unique_id "al9Wi1cagwCeNbomjVsJqgAAAdg"]
[Tue Jul 21 08:22:51.689217 2026] [security2:error] [pid 418108:tid 418289] [client 20.151.10.161:50781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/155.php"] [unique_id "al9Wiw0cxofL2J1zwYrDuwAAATs"]
[Tue Jul 21 08:22:51.875067 2026] [security2:error] [pid 419508:tid 419589] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wi1cagwCeNbomjVsJrAABo1A"]
[Tue Jul 21 08:22:51.875242 2026] [security2:error] [pid 419508:tid 419658] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wi1cagwCeNbomjVsJrAABo1A"]
[Tue Jul 21 08:22:51.931785 2026] [security2:error] [pid 419508:tid 419720] [client 115.134.11.136:56508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wi1cagwCeNbomjVsJrgAAAeE"]
[Tue Jul 21 08:22:51.932449 2026] [security2:error] [pid 419508:tid 419720] [client 115.134.11.136:56508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wi1cagwCeNbomjVsJrgAAAeE"]
[Tue Jul 21 08:22:51.955242 2026] [security2:error] [pid 411857:tid 412026] [client 4.194.217.15:3640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/.well-known/bdkr28_61cohkhh.php"] [unique_id "al9Wiy7ynBpLeKYztQPm2gAAACU"]
[Tue Jul 21 08:22:52.050212 2026] [security2:error] [pid 419508:tid 419757] [client 20.226.60.151:60605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9WjFcagwCeNbomjVsJsAAAAgU"]
[Tue Jul 21 08:22:52.056509 2026] [security2:error] [pid 411857:tid 412105] [client 20.197.192.193:53134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/wp-signup.php"] [unique_id "al9WjC7ynBpLeKYztQPm3gAAAHQ"]
[Tue Jul 21 08:22:52.058670 2026] [security2:error] [pid 418108:tid 418270] [client 20.151.10.161:50787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/ops.php"] [unique_id "al9WjA0cxofL2J1zwYrDvQAAASg"]
[Tue Jul 21 08:22:52.151543 2026] [security2:error] [pid 419508:tid 419651] [client 20.151.10.161:50861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/fffm.php"] [unique_id "al9WjFcagwCeNbomjVsJsQAAAZw"]
[Tue Jul 21 08:22:52.186737 2026] [security2:error] [pid 419508:tid 419761] [client 20.220.225.223:12544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/inso.php"] [unique_id "al9WjFcagwCeNbomjVsJsgAAAgk"]
[Tue Jul 21 08:22:52.206205 2026] [security2:error] [pid 411857:tid 412097] [client 187.125.243.197:53771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WjC7ynBpLeKYztQPm4QAAAGw"]
[Tue Jul 21 08:22:52.206379 2026] [security2:error] [pid 411857:tid 412097] [client 187.125.243.197:53771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WjC7ynBpLeKYztQPm4QAAAGw"]
[Tue Jul 21 08:22:52.388445 2026] [security2:error] [pid 411857:tid 412072] [client 20.197.192.193:53120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/csa.php"] [unique_id "al9WjC7ynBpLeKYztQPm6AAAAFM"]
[Tue Jul 21 08:22:52.429868 2026] [security2:error] [pid 419508:tid 419659] [client 154.208.47.42:63116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WjFcagwCeNbomjVsJtQAAAaQ"]
[Tue Jul 21 08:22:52.430014 2026] [security2:error] [pid 419508:tid 419659] [client 154.208.47.42:63116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WjFcagwCeNbomjVsJtQAAAaQ"]
[Tue Jul 21 08:22:52.440528 2026] [security2:error] [pid 418108:tid 418182] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WjA0cxofL2J1zwYrDvgABaUc"]
[Tue Jul 21 08:22:52.440702 2026] [security2:error] [pid 418108:tid 418335] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WjA0cxofL2J1zwYrDvgABaUc"]
[Tue Jul 21 08:22:52.517258 2026] [security2:error] [pid 419508:tid 419741] [client 20.151.10.161:50763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/ingfo.php"] [unique_id "al9WjFcagwCeNbomjVsJvAAAAfY"]
[Tue Jul 21 08:22:52.526211 2026] [security2:error] [pid 419508:tid 419685] [client 20.151.10.161:10244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/gecko.php"] [unique_id "al9WjFcagwCeNbomjVsJvQAAAb4"]
[Tue Jul 21 08:22:52.788277 2026] [security2:error] [pid 419508:tid 419758] [client 109.248.148.246:51372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9WjFcagwCeNbomjVsJvgAAAgY"]
[Tue Jul 21 08:22:52.788440 2026] [security2:error] [pid 419508:tid 419758] [client 109.248.148.246:51372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9WjFcagwCeNbomjVsJvgAAAgY"]
[Tue Jul 21 08:22:52.859972 2026] [security2:error] [pid 419508:tid 419639] [client 20.151.10.161:50749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/a1.php"] [unique_id "al9WjFcagwCeNbomjVsJwQAAAZA"]
[Tue Jul 21 08:22:52.974305 2026] [security2:error] [pid 411857:tid 412076] [client 20.151.10.161:50756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/error_log.php"] [unique_id "al9WjC7ynBpLeKYztQPm7wAAAFc"]
[Tue Jul 21 08:22:53.033670 2026] [security2:error] [pid 419508:tid 419678] [client 4.194.217.15:4176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/.well-known/class-wp-http-client.php"] [unique_id "al9WjVcagwCeNbomjVsJywAAAbc"]
[Tue Jul 21 08:22:53.219624 2026] [security2:error] [pid 411857:tid 412106] [client 20.206.105.145:20171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/ccs.php"] [unique_id "al9WjS7ynBpLeKYztQPm8gAAAHU"]
[Tue Jul 21 08:22:53.240296 2026] [security2:error] [pid 418108:tid 418295] [client 20.151.10.161:50860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/k2.php"] [unique_id "al9WjQ0cxofL2J1zwYrDwAAAAUE"]
[Tue Jul 21 08:22:53.259206 2026] [security2:error] [pid 419508:tid 419662] [client 74.249.245.134:21037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/bootstrap.php"] [unique_id "al9WjVcagwCeNbomjVsJzQAAAac"]
[Tue Jul 21 08:22:53.615009 2026] [security2:error] [pid 419508:tid 419700] [client 20.151.10.161:10346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/82.php"] [unique_id "al9WjVcagwCeNbomjVsJ0QAAAc0"]
[Tue Jul 21 08:22:53.711929 2026] [security2:error] [pid 419508:tid 419749] [client 20.151.10.161:50788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/ok.php"] [unique_id "al9WjVcagwCeNbomjVsJ0gAAAf0"]
[Tue Jul 21 08:22:53.888699 2026] [security2:error] [pid 411857:tid 412060] [client 109.248.148.246:54740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9WjS7ynBpLeKYztQPm_gAAAEc"]
[Tue Jul 21 08:22:53.888791 2026] [security2:error] [pid 411857:tid 412060] [client 109.248.148.246:54740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9WjS7ynBpLeKYztQPm_gAAAEc"]
[Tue Jul 21 08:22:53.927560 2026] [security2:error] [pid 418108:tid 418257] [client 20.220.225.223:41145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/tkikikoko.php"] [unique_id "al9WjQ0cxofL2J1zwYrDxAAAARs"]
[Tue Jul 21 08:22:53.933889 2026] [security2:error] [pid 411857:tid 412036] [client 20.151.10.161:10255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/config.json.php"] [unique_id "al9WjS7ynBpLeKYztQPm_wAAAC8"]
[Tue Jul 21 08:22:54.049748 2026] [rewrite:warn] [pid 419508:tid 419584] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:22:54.096473 2026] [security2:error] [pid 411857:tid 412065] [client 4.194.217.15:1719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "al9Wji7ynBpLeKYztQPnAgAAAEw"]
[Tue Jul 21 08:22:54.156021 2026] [security2:error] [pid 418108:tid 418262] [client 20.151.10.161:50753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/mac.php"] [unique_id "al9Wjg0cxofL2J1zwYrDxwAAASA"]
[Tue Jul 21 08:22:54.162467 2026] [security2:error] [pid 411857:tid 412084] [client 216.73.160.175:31057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9WjS7ynBpLeKYztQPnAQAAAF8"]
[Tue Jul 21 08:22:54.291603 2026] [security2:error] [pid 411857:tid 412027] [client 20.151.10.161:10279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "planamoveis.com.br"] [uri "/fpwch.php"] [unique_id "al9Wji7ynBpLeKYztQPnBQAAACY"]
[Tue Jul 21 08:22:54.571841 2026] [security2:error] [pid 419508:tid 419666] [client 20.151.10.161:51156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wefile.php"] [unique_id "al9WjlcagwCeNbomjVsJ2wAAAas"]
[Tue Jul 21 08:22:54.748453 2026] [security2:error] [pid 418108:tid 418265] [client 20.206.105.145:20210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/ccc.php"] [unique_id "al9Wjg0cxofL2J1zwYrDyQAAASM"]
[Tue Jul 21 08:22:54.809184 2026] [security2:error] [pid 411857:tid 412095] [client 20.220.225.223:42159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/wp-Blogs.php"] [unique_id "al9Wji7ynBpLeKYztQPnCwAAAGo"]
[Tue Jul 21 08:22:54.970246 2026] [security2:error] [pid 419508:tid 419651] [client 20.197.192.193:52278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/min.php"] [unique_id "al9WjlcagwCeNbomjVsJ3QAAAZw"]
[Tue Jul 21 08:22:55.143932 2026] [security2:error] [pid 419508:tid 419747] [client 4.194.217.15:3602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/.well-known/index.php"] [unique_id "al9Wj1cagwCeNbomjVsJ4AAAAfs"]
[Tue Jul 21 08:22:55.287504 2026] [security2:error] [pid 411857:tid 412058] [client 20.151.10.161:51194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9Wjy7ynBpLeKYztQPnEgAAAEU"]
[Tue Jul 21 08:22:55.466924 2026] [security2:error] [pid 411857:tid 419462] [remote 160.187.68.132:46128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wp-login.php"] [unique_id "al9Wjy7ynBpLeKYztQPnFAAAIJA"]
[Tue Jul 21 08:22:55.821711 2026] [autoindex:error] [pid 411857:tid 412104] [client 20.151.10.161:51136] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:22:55.938804 2026] [security2:error] [pid 419508:tid 419724] [client 20.206.105.145:20200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/get.php"] [unique_id "al9Wj1cagwCeNbomjVsJ5gAAAeU"]
[Tue Jul 21 08:22:56.016275 2026] [security2:error] [pid 411857:tid 412038] [client 20.220.225.223:53817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/wp-css.php"] [unique_id "al9WkC7ynBpLeKYztQPnIQAAADE"]
[Tue Jul 21 08:22:56.145083 2026] [autoindex:error] [pid 411857:tid 412072] [client 20.151.10.161:51136] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:22:56.169396 2026] [security2:error] [pid 419508:tid 419655] [client 4.194.217.15:1169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/.well-known/ws.php"] [unique_id "al9WkFcagwCeNbomjVsJ7AAAAaA"]
[Tue Jul 21 08:22:56.283483 2026] [security2:error] [pid 411857:tid 412017] [client 20.151.10.161:51136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9WkC7ynBpLeKYztQPnKAAAABw"]
[Tue Jul 21 08:22:56.351064 2026] [security2:error] [pid 418108:tid 418324] [client 20.151.10.161:37626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9WkA0cxofL2J1zwYrD0AAAAV4"]
[Tue Jul 21 08:22:56.460589 2026] [security2:error] [pid 419508:tid 419758] [client 65.21.113.253:56574] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Wj1cagwCeNbomjVsJ6AAAAgY"]
[Tue Jul 21 08:22:56.717365 2026] [security2:error] [pid 411857:tid 412076] [client 20.197.192.193:52249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/echkm.php"] [unique_id "al9WkC7ynBpLeKYztQPnLgAAAFc"]
[Tue Jul 21 08:22:56.864103 2026] [security2:error] [pid 419508:tid 419668] [client 103.151.46.103:50636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WkFcagwCeNbomjVsJ9AAAAa0"]
[Tue Jul 21 08:22:56.864226 2026] [security2:error] [pid 419508:tid 419668] [client 103.151.46.103:50636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WkFcagwCeNbomjVsJ9AAAAa0"]
[Tue Jul 21 08:22:56.894719 2026] [security2:error] [pid 411857:tid 412087] [client 61.1.167.83:52749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WkC7ynBpLeKYztQPnMgAAAGI"]
[Tue Jul 21 08:22:56.894884 2026] [security2:error] [pid 411857:tid 412087] [client 61.1.167.83:52749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WkC7ynBpLeKYztQPnMgAAAGI"]
[Tue Jul 21 08:22:56.996592 2026] [security2:error] [pid 411857:tid 412070] [client 20.220.225.223:43450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/wp-explorer.php"] [unique_id "al9WkC7ynBpLeKYztQPnNAAAAFE"]
[Tue Jul 21 08:22:57.038068 2026] [security2:error] [pid 419508:tid 419647] [client 20.151.10.161:37522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9WkVcagwCeNbomjVsJ9QAAAZg"]
[Tue Jul 21 08:22:57.133650 2026] [security2:error] [pid 418108:tid 418284] [client 223.181.60.88:4136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WkQ0cxofL2J1zwYrD0wAAATY"]
[Tue Jul 21 08:22:57.136047 2026] [security2:error] [pid 418108:tid 418284] [client 223.181.60.88:4136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WkQ0cxofL2J1zwYrD0wAAATY"]
[Tue Jul 21 08:22:57.231280 2026] [security2:error] [pid 418108:tid 418258] [client 4.194.217.15:1168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/.xa/class-wp-http-client.php"] [unique_id "al9WkQ0cxofL2J1zwYrD1AAAARw"]
[Tue Jul 21 08:22:57.295848 2026] [security2:error] [pid 411857:tid 411894] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WkS7ynBpLeKYztQPnOQAAPiM"]
[Tue Jul 21 08:22:57.296071 2026] [security2:error] [pid 411857:tid 412051] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WkS7ynBpLeKYztQPnOQAAPiM"]
[Tue Jul 21 08:22:57.488439 2026] [security2:error] [pid 418108:tid 418338] [client 20.151.10.161:37596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/x.php"] [unique_id "al9WkQ0cxofL2J1zwYrD1gAAAWw"]
[Tue Jul 21 08:22:57.615524 2026] [security2:error] [pid 419508:tid 419734] [client 20.220.225.223:55175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/akismet.php"] [unique_id "al9WkVcagwCeNbomjVsJ-wAAAe8"]
[Tue Jul 21 08:22:57.727470 2026] [security2:error] [pid 411857:tid 412002] [client 20.226.60.151:60601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/txets.php"] [unique_id "al9WkS7ynBpLeKYztQPnQAAAAA0"]
[Tue Jul 21 08:22:57.741756 2026] [security2:error] [pid 411857:tid 412086] [client 20.206.105.145:20180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/images.php"] [unique_id "al9WkS7ynBpLeKYztQPnQQAAAGE"]
[Tue Jul 21 08:22:57.782836 2026] [security2:error] [pid 419508:tid 419687] [client 117.213.202.34:63844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WkVcagwCeNbomjVsJ_AAAAcA"]
[Tue Jul 21 08:22:57.783010 2026] [security2:error] [pid 419508:tid 419687] [client 117.213.202.34:63844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WkVcagwCeNbomjVsJ_AAAAcA"]
[Tue Jul 21 08:22:57.919049 2026] [security2:error] [pid 419508:tid 419651] [client 20.151.10.161:37572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/j260624_13.php"] [unique_id "al9WkVcagwCeNbomjVsJ_wAAAZw"]
[Tue Jul 21 08:22:58.156341 2026] [security2:error] [pid 419508:tid 419760] [client 74.249.245.134:60808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/config-backup.php"] [unique_id "al9WklcagwCeNbomjVsKAQAAAgg"]
[Tue Jul 21 08:22:58.292614 2026] [security2:error] [pid 419508:tid 419737] [client 4.194.217.15:1690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/0.php"] [unique_id "al9WklcagwCeNbomjVsKBQAAAfI"]
[Tue Jul 21 08:22:58.519692 2026] [security2:error] [pid 418108:tid 418345] [client 87.116.180.198:27142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wkg0cxofL2J1zwYrD3QAAAXM"]
[Tue Jul 21 08:22:58.519822 2026] [security2:error] [pid 418108:tid 418345] [client 87.116.180.198:27142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wkg0cxofL2J1zwYrD3QAAAXM"]
[Tue Jul 21 08:22:58.551938 2026] [security2:error] [pid 419508:tid 419715] [client 213.152.186.163:60860] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9WklcagwCeNbomjVsKCQAAAdw"]
[Tue Jul 21 08:22:58.552044 2026] [security2:error] [pid 419508:tid 419715] [client 213.152.186.163:60860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9WklcagwCeNbomjVsKCQAAAdw"]
[Tue Jul 21 08:22:58.556858 2026] [security2:error] [pid 411857:tid 412074] [client 20.197.192.193:53148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/mac.php"] [unique_id "al9Wki7ynBpLeKYztQPnUQAAAFU"]
[Tue Jul 21 08:22:58.644023 2026] [security2:error] [pid 419508:tid 419685] [client 20.151.10.161:37625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/d62.php"] [unique_id "al9WklcagwCeNbomjVsKCgAAAb4"]
[Tue Jul 21 08:22:58.740392 2026] [security2:error] [pid 411857:tid 412077] [client 213.152.186.163:39478] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Wki7ynBpLeKYztQPnUwAAAFg"]
[Tue Jul 21 08:22:58.740491 2026] [security2:error] [pid 411857:tid 412077] [client 213.152.186.163:39478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Wki7ynBpLeKYztQPnUwAAAFg"]
[Tue Jul 21 08:22:58.760388 2026] [security2:error] [pid 419508:tid 419740] [client 65.21.113.253:56574] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WklcagwCeNbomjVsKBgAAAfU"]
[Tue Jul 21 08:22:58.766403 2026] [security2:error] [pid 411857:tid 412022] [client 20.220.225.223:20909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/la.php"] [unique_id "al9Wki7ynBpLeKYztQPnVAAAACE"]
[Tue Jul 21 08:22:58.812679 2026] [security2:error] [pid 418108:tid 418194] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wkg0cxofL2J1zwYrD3wABOlM"]
[Tue Jul 21 08:22:58.812890 2026] [security2:error] [pid 418108:tid 418288] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wkg0cxofL2J1zwYrD3wABOlM"]
[Tue Jul 21 08:22:58.856698 2026] [security2:error] [pid 411857:tid 412108] [client 150.129.202.39:13269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wki7ynBpLeKYztQPnVwAAAHc"]
[Tue Jul 21 08:22:58.856835 2026] [security2:error] [pid 411857:tid 412108] [client 150.129.202.39:13269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wki7ynBpLeKYztQPnVwAAAHc"]
[Tue Jul 21 08:22:58.959609 2026] [security2:error] [pid 419508:tid 419718] [client 195.49.128.211:55579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WklcagwCeNbomjVsKDgAAAd8"]
[Tue Jul 21 08:22:58.959756 2026] [security2:error] [pid 419508:tid 419718] [client 195.49.128.211:55579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WklcagwCeNbomjVsKDgAAAd8"]
[Tue Jul 21 08:22:58.971945 2026] [security2:error] [pid 419508:tid 419729] [client 20.151.10.161:51741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/like.php"] [unique_id "al9WklcagwCeNbomjVsKDwAAAeo"]
[Tue Jul 21 08:22:59.190776 2026] [security2:error] [pid 411857:tid 412104] [client 20.151.10.161:37587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/ups.php"] [unique_id "al9Wky7ynBpLeKYztQPnYgAAAHM"]
[Tue Jul 21 08:22:59.261891 2026] [security2:error] [pid 411857:tid 412107] [client 20.151.10.161:51141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/.well-known/about.php"] [unique_id "al9Wky7ynBpLeKYztQPnZAAAAHY"]
[Tue Jul 21 08:22:59.272446 2026] [security2:error] [pid 419508:tid 419656] [client 14.245.224.124:61536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Wk1cagwCeNbomjVsKEwAAAaE"]
[Tue Jul 21 08:22:59.272686 2026] [security2:error] [pid 419508:tid 419656] [client 14.245.224.124:61536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Wk1cagwCeNbomjVsKEwAAAaE"]
[Tue Jul 21 08:22:59.330606 2026] [security2:error] [pid 419508:tid 419709] [client 4.194.217.15:3624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/000.php"] [unique_id "al9Wk1cagwCeNbomjVsKFAAAAdY"]
[Tue Jul 21 08:22:59.335318 2026] [security2:error] [pid 419508:tid 419646] [client 20.226.60.151:56921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Wk1cagwCeNbomjVsKFQAAAZc"]
[Tue Jul 21 08:22:59.622606 2026] [security2:error] [pid 411857:tid 412017] [client 20.197.192.193:52276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/samll.php"] [unique_id "al9Wky7ynBpLeKYztQPnaAAAABw"]
[Tue Jul 21 08:22:59.642110 2026] [security2:error] [pid 411857:tid 412015] [client 20.206.105.145:20220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/alls.php"] [unique_id "al9Wky7ynBpLeKYztQPnaQAAABo"]
[Tue Jul 21 08:22:59.650945 2026] [security2:error] [pid 411857:tid 412033] [client 65.21.113.253:56578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Wky7ynBpLeKYztQPnXwAAACw"]
[Tue Jul 21 08:22:59.677262 2026] [security2:error] [pid 419508:tid 419716] [client 20.226.60.151:60630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/dex.php"] [unique_id "al9Wk1cagwCeNbomjVsKGgAAAd0"]
[Tue Jul 21 08:22:59.731099 2026] [security2:error] [pid 411857:tid 412005] [client 20.226.60.151:56861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Wky7ynBpLeKYztQPnbAAAABA"]
[Tue Jul 21 08:22:59.755004 2026] [security2:error] [pid 419508:tid 419703] [client 20.151.10.161:50782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Wk1cagwCeNbomjVsKHwAAAdA"]
[Tue Jul 21 08:22:59.787686 2026] [security2:error] [pid 411857:tid 412083] [client 20.226.60.151:56873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/media.php"] [unique_id "al9Wky7ynBpLeKYztQPnbgAAAF4"]
[Tue Jul 21 08:22:59.883874 2026] [security2:error] [pid 411857:tid 412034] [client 202.179.75.202:50796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Wky7ynBpLeKYztQPncQAAAC0"]
[Tue Jul 21 08:22:59.884002 2026] [security2:error] [pid 411857:tid 412034] [client 202.179.75.202:50796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Wky7ynBpLeKYztQPncQAAAC0"]
[Tue Jul 21 08:22:59.897209 2026] [security2:error] [pid 418108:tid 418223] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9Wkw0cxofL2J1zwYrD4gABDXA"]
[Tue Jul 21 08:22:59.897322 2026] [security2:error] [pid 418108:tid 418243] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9Wkw0cxofL2J1zwYrD4gABDXA"]
[Tue Jul 21 08:23:00.017782 2026] [security2:error] [pid 419508:tid 419696] [client 20.226.60.151:56940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/images.php"] [unique_id "al9WlFcagwCeNbomjVsKIQAAAck"]
[Tue Jul 21 08:23:00.147957 2026] [security2:error] [pid 418108:tid 418311] [client 20.151.10.161:37526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/k.php"] [unique_id "al9WlA0cxofL2J1zwYrD5AAAAVE"]
[Tue Jul 21 08:23:00.166422 2026] [security2:error] [pid 411857:tid 419446] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Wky7ynBpLeKYztQPncgAAKIE"]
[Tue Jul 21 08:23:00.166589 2026] [security2:error] [pid 411857:tid 412029] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Wky7ynBpLeKYztQPncgAAKIE"]
[Tue Jul 21 08:23:00.203529 2026] [autoindex:error] [pid 419508:tid 419726] [client 20.151.10.161:51173] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:00.361079 2026] [security2:error] [pid 419508:tid 419684] [client 4.194.217.15:1685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/002.php"] [unique_id "al9WlFcagwCeNbomjVsKJwAAAb0"]
[Tue Jul 21 08:23:00.441006 2026] [security2:error] [pid 419508:tid 419692] [client 20.226.60.151:56914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/gecko.php"] [unique_id "al9WlFcagwCeNbomjVsKKwAAAcU"]
[Tue Jul 21 08:23:00.510771 2026] [security2:error] [pid 419508:tid 419651] [client 20.197.192.193:52280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/abcd.php"] [unique_id "al9WlFcagwCeNbomjVsKLgAAAZw"]
[Tue Jul 21 08:23:00.532508 2026] [autoindex:error] [pid 419508:tid 419666] [client 20.151.10.161:51173] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:00.669608 2026] [security2:error] [pid 411857:tid 412019] [client 152.59.34.51:63672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WlC7ynBpLeKYztQPneQAAAB4"]
[Tue Jul 21 08:23:00.671254 2026] [security2:error] [pid 419508:tid 419682] [client 20.151.10.161:51173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/pucci.php"] [unique_id "al9WlFcagwCeNbomjVsKMwAAAbs"]
[Tue Jul 21 08:23:00.678806 2026] [security2:error] [pid 411857:tid 412019] [client 152.59.34.51:63672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WlC7ynBpLeKYztQPneQAAAB4"]
[Tue Jul 21 08:23:00.731050 2026] [security2:error] [pid 419508:tid 419677] [client 20.151.10.161:37623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/k2.php"] [unique_id "al9WlFcagwCeNbomjVsKNgAAAbY"]
[Tue Jul 21 08:23:01.069791 2026] [autoindex:error] [pid 419508:tid 419678] [client 20.151.10.161:51152] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:01.071904 2026] [security2:error] [pid 411857:tid 412009] [client 20.151.10.161:37630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/k3.php"] [unique_id "al9WlS7ynBpLeKYztQPngQAAABQ"]
[Tue Jul 21 08:23:01.091680 2026] [security2:error] [pid 419508:tid 419764] [client 20.226.60.151:56959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/82.php"] [unique_id "al9WlVcagwCeNbomjVsKPQAAAgw"]
[Tue Jul 21 08:23:01.217764 2026] [security2:error] [pid 419508:tid 419754] [client 137.97.59.154:24899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WlVcagwCeNbomjVsKQAAAAgI"]
[Tue Jul 21 08:23:01.217915 2026] [security2:error] [pid 419508:tid 419754] [client 137.97.59.154:24899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WlVcagwCeNbomjVsKQAAAAgI"]
[Tue Jul 21 08:23:01.255590 2026] [security2:error] [pid 419508:tid 419656] [client 20.220.225.223:20901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/nhvoanpl.php"] [unique_id "al9WlVcagwCeNbomjVsKQQAAAaE"]
[Tue Jul 21 08:23:01.368787 2026] [autoindex:error] [pid 419508:tid 419766] [client 20.151.10.161:51152] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:01.372823 2026] [security2:error] [pid 419508:tid 419758] [client 20.151.10.161:37574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/k4.php"] [unique_id "al9WlVcagwCeNbomjVsKQwAAAgY"]
[Tue Jul 21 08:23:01.392498 2026] [security2:error] [pid 419508:tid 419751] [client 4.194.217.15:1704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/0x.php"] [unique_id "al9WlVcagwCeNbomjVsKRAAAAf8"]
[Tue Jul 21 08:23:01.507634 2026] [security2:error] [pid 419508:tid 419716] [client 20.151.10.161:51152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-temp.php"] [unique_id "al9WlVcagwCeNbomjVsKRgAAAd0"]
[Tue Jul 21 08:23:01.577393 2026] [security2:error] [pid 419508:tid 419749] [client 34.73.118.223:59954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oppbrazil.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9WlVcagwCeNbomjVsKSgAAAf0"]
[Tue Jul 21 08:23:01.624141 2026] [security2:error] [pid 419508:tid 419703] [client 107.189.6.149:62666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "triviaodontologia.com.br"] [uri "/"] [unique_id "al9WlVcagwCeNbomjVsKSwAAAdA"]
[Tue Jul 21 08:23:01.691800 2026] [security2:error] [pid 418108:tid 418255] [client 20.151.10.161:37610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/k5.php"] [unique_id "al9WlQ0cxofL2J1zwYrD6AAAARk"]
[Tue Jul 21 08:23:01.824336 2026] [security2:error] [pid 419508:tid 419668] [client 107.189.6.149:62665] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "triviaodontologia.com.br"] [uri "/"] [unique_id "al9WlVcagwCeNbomjVsKTQAAAa0"]
[Tue Jul 21 08:23:01.843542 2026] [security2:error] [pid 419508:tid 419649] [client 20.226.60.151:60629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/xpwer1.php"] [unique_id "al9WlVcagwCeNbomjVsKTgAAAZo"]
[Tue Jul 21 08:23:01.882107 2026] [autoindex:error] [pid 419508:tid 419683] [client 20.151.10.161:50808] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:01.908527 2026] [security2:error] [pid 411857:tid 412110] [client 20.226.60.151:56931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/admin.php"] [unique_id "al9WlS7ynBpLeKYztQPnkQAAAHk"]
[Tue Jul 21 08:23:02.000167 2026] [security2:error] [pid 419508:tid 419684] [client 20.151.10.161:37577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/w.php"] [unique_id "al9WlVcagwCeNbomjVsKVAAAAb0"]
[Tue Jul 21 08:23:02.018380 2026] [security2:error] [pid 418108:tid 418305] [client 107.189.6.149:62691] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "triviaodontologia.com.br"] [uri "/"] [unique_id "al9Wlg0cxofL2J1zwYrD7AAAAUs"]
[Tue Jul 21 08:23:02.050143 2026] [security2:error] [pid 419508:tid 419699] [client 120.56.162.40:53668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.162.56.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WllcagwCeNbomjVsKVgAAAcw"]
[Tue Jul 21 08:23:02.050337 2026] [security2:error] [pid 419508:tid 419699] [client 120.56.162.40:53668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WllcagwCeNbomjVsKVgAAAcw"]
[Tue Jul 21 08:23:02.192068 2026] [security2:error] [pid 418108:tid 418334] [client 20.206.105.145:20185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/yyu.php"] [unique_id "al9Wlg0cxofL2J1zwYrD7gAAAWg"]
[Tue Jul 21 08:23:02.210341 2026] [security2:error] [pid 419508:tid 419721] [client 34.73.118.223:61775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.118.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oppbrazil.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WllcagwCeNbomjVsKWgAAAeI"]
[Tue Jul 21 08:23:02.277373 2026] [security2:error] [pid 418108:tid 418357] [client 20.151.10.161:37615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/fpwch.php"] [unique_id "al9Wlg0cxofL2J1zwYrD8AAAAX8"]
[Tue Jul 21 08:23:02.281019 2026] [security2:error] [pid 419508:tid 419741] [client 20.151.10.161:50808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/xmu.php"] [unique_id "al9WllcagwCeNbomjVsKWwAAAfY"]
[Tue Jul 21 08:23:02.401492 2026] [security2:error] [pid 411857:tid 412073] [client 65.21.113.253:56578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WlS7ynBpLeKYztQPnkAAAAFQ"]
[Tue Jul 21 08:23:02.413544 2026] [security2:error] [pid 419508:tid 419690] [client 107.189.6.149:62715] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "triviaodontologia.com.br"] [uri "/"] [unique_id "al9WllcagwCeNbomjVsKXAAAAcM"]
[Tue Jul 21 08:23:02.434936 2026] [security2:error] [pid 419508:tid 419702] [client 115.134.11.136:56975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WllcagwCeNbomjVsKXgAAAc8"]
[Tue Jul 21 08:23:02.435694 2026] [security2:error] [pid 419508:tid 419702] [client 115.134.11.136:56975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WllcagwCeNbomjVsKXgAAAc8"]
[Tue Jul 21 08:23:02.497620 2026] [security2:error] [pid 419508:tid 419747] [client 4.194.217.15:12602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/0xd.php"] [unique_id "al9WllcagwCeNbomjVsKXwAAAfs"]
[Tue Jul 21 08:23:02.583527 2026] [security2:error] [pid 411857:tid 412101] [client 20.151.10.161:37571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/w2025.php"] [unique_id "al9Wli7ynBpLeKYztQPnmwAAAHA"]
[Tue Jul 21 08:23:02.623433 2026] [security2:error] [pid 418108:tid 418119] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wlg0cxofL2J1zwYrD8gABdAg"]
[Tue Jul 21 08:23:02.623612 2026] [security2:error] [pid 418108:tid 418346] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wlg0cxofL2J1zwYrD8gABdAg"]
[Tue Jul 21 08:23:02.673755 2026] [security2:error] [pid 411857:tid 412020] [client 20.151.10.161:50803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9Wli7ynBpLeKYztQPnnAAAAB8"]
[Tue Jul 21 08:23:02.713853 2026] [security2:error] [pid 419508:tid 419740] [client 187.125.243.197:54389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WllcagwCeNbomjVsKYwAAAfU"]
[Tue Jul 21 08:23:02.714724 2026] [security2:error] [pid 419508:tid 419740] [client 187.125.243.197:54389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WllcagwCeNbomjVsKYwAAAfU"]
[Tue Jul 21 08:23:02.802820 2026] [security2:error] [pid 419508:tid 419708] [client 20.226.60.151:60663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/flox.php"] [unique_id "al9WllcagwCeNbomjVsKaAAAAdU"]
[Tue Jul 21 08:23:02.937803 2026] [security2:error] [pid 411857:tid 412081] [client 20.151.10.161:37515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/scxy.php"] [unique_id "al9Wli7ynBpLeKYztQPnpgAAAFw"]
[Tue Jul 21 08:23:03.023877 2026] [security2:error] [pid 419508:tid 419596] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Wl1cagwCeNbomjVsKcQAB11c"]
[Tue Jul 21 08:23:03.024046 2026] [security2:error] [pid 419508:tid 419710] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Wl1cagwCeNbomjVsKcQAB11c"]
[Tue Jul 21 08:23:03.144326 2026] [security2:error] [pid 411857:tid 412045] [client 154.208.47.42:63906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Wly7ynBpLeKYztQPnqwAAADg"]
[Tue Jul 21 08:23:03.144485 2026] [security2:error] [pid 411857:tid 412045] [client 154.208.47.42:63906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9Wly7ynBpLeKYztQPnqwAAADg"]
[Tue Jul 21 08:23:03.243167 2026] [security2:error] [pid 411857:tid 412041] [client 20.151.10.161:50772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/puc.php"] [unique_id "al9Wly7ynBpLeKYztQPnrQAAADQ"]
[Tue Jul 21 08:23:03.324726 2026] [security2:error] [pid 419508:tid 419686] [client 20.197.192.193:53179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/xyn.php"] [unique_id "al9Wl1cagwCeNbomjVsKdAAAAb8"]
[Tue Jul 21 08:23:03.396577 2026] [security2:error] [pid 419508:tid 419749] [client 20.226.60.151:60546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/popo.php"] [unique_id "al9Wl1cagwCeNbomjVsKdQAAAf0"]
[Tue Jul 21 08:23:03.468232 2026] [security2:error] [pid 419508:tid 419703] [client 20.206.105.145:20192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/by.php"] [unique_id "al9Wl1cagwCeNbomjVsKdgAAAdA"]
[Tue Jul 21 08:23:03.474222 2026] [security2:error] [pid 418108:tid 418262] [client 20.151.10.161:37595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/FWAZ.php"] [unique_id "al9Wlw0cxofL2J1zwYrD9gAAASA"]
[Tue Jul 21 08:23:03.542061 2026] [security2:error] [pid 419508:tid 419660] [client 4.194.217.15:1699] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "efrelectronics.com"] [uri "/1.php"] [unique_id "al9Wl1cagwCeNbomjVsKdwAAAaU"]
[Tue Jul 21 08:23:03.542174 2026] [security2:error] [pid 419508:tid 419660] [client 4.194.217.15:1699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/1.php"] [unique_id "al9Wl1cagwCeNbomjVsKdwAAAaU"]
[Tue Jul 21 08:23:03.558609 2026] [security2:error] [pid 419508:tid 419648] [client 74.249.245.134:52520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/goods.php"] [unique_id "al9Wl1cagwCeNbomjVsKeAAAAZk"]
[Tue Jul 21 08:23:03.674468 2026] [security2:error] [pid 418108:tid 418358] [client 20.151.10.161:50780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/themes.php"] [unique_id "al9Wlw0cxofL2J1zwYrD-gAAAYA"]
[Tue Jul 21 08:23:03.708582 2026] [security2:error] [pid 419508:tid 419625] [remote 45.79.123.44:56834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cavilhaslufra.com.br"] [uri "/wp-login.php"] [unique_id "al9Wl1cagwCeNbomjVsKewAB_nQ"]
[Tue Jul 21 08:23:03.791199 2026] [security2:error] [pid 411857:tid 412109] [client 20.226.60.151:60548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/yas.php"] [unique_id "al9Wly7ynBpLeKYztQPntQAAAHg"]
[Tue Jul 21 08:23:03.798595 2026] [security2:error] [pid 411857:tid 412088] [client 20.220.225.223:34742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/inso.php"] [unique_id "al9Wly7ynBpLeKYztQPntgAAAGM"]
[Tue Jul 21 08:23:03.879133 2026] [security2:error] [pid 411857:tid 412066] [client 65.21.113.253:56578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Wly7ynBpLeKYztQPnrwAAAE0"]
[Tue Jul 21 08:23:03.883498 2026] [security2:error] [pid 419508:tid 419736] [client 20.151.10.161:37517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/qterm.php"] [unique_id "al9Wl1cagwCeNbomjVsKfAAAAfE"]
[Tue Jul 21 08:23:03.904317 2026] [security2:error] [pid 418108:tid 418246] [client 20.226.60.151:56877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/adminner.php"] [unique_id "al9Wlw0cxofL2J1zwYrEAAAAARA"]
[Tue Jul 21 08:23:04.060860 2026] [security2:error] [pid 418108:tid 418331] [client 20.197.192.193:53173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/byp8.php"] [unique_id "al9WmA0cxofL2J1zwYrEAQAAAWU"]
[Tue Jul 21 08:23:04.084941 2026] [autoindex:error] [pid 411857:tid 412031] [client 20.151.10.161:50773] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:04.201547 2026] [security2:error] [pid 411857:tid 412075] [client 20.226.60.151:50053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/file61.php"] [unique_id "al9WmC7ynBpLeKYztQPnvQAAAFY"]
[Tue Jul 21 08:23:04.293492 2026] [security2:error] [pid 419508:tid 419765] [client 20.151.10.161:37528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/blurbs.php"] [unique_id "al9WmFcagwCeNbomjVsKfQAAAg0"]
[Tue Jul 21 08:23:04.340653 2026] [security2:error] [pid 419508:tid 419695] [client 20.226.60.151:56907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/admin.php"] [unique_id "al9WmFcagwCeNbomjVsKfgAAAcg"]
[Tue Jul 21 08:23:04.359124 2026] [security2:error] [pid 411857:tid 412062] [client 20.151.10.161:50773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/8.php"] [unique_id "al9WmC7ynBpLeKYztQPnwAAAAEk"]
[Tue Jul 21 08:23:04.480597 2026] [security2:error] [pid 419508:tid 419682] [client 20.197.192.193:53144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/user.php"] [unique_id "al9WmFcagwCeNbomjVsKgQAAAbs"]
[Tue Jul 21 08:23:04.616286 2026] [security2:error] [pid 419508:tid 419702] [client 20.151.10.161:37589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/v543.php"] [unique_id "al9WmFcagwCeNbomjVsKgwAAAc8"]
[Tue Jul 21 08:23:04.627533 2026] [security2:error] [pid 411857:tid 412009] [client 4.194.217.15:12585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/100.php"] [unique_id "al9WmC7ynBpLeKYztQPnxQAAABQ"]
[Tue Jul 21 08:23:04.693393 2026] [security2:error] [pid 411857:tid 412059] [client 20.226.60.151:56835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/k.php"] [unique_id "al9WmC7ynBpLeKYztQPnywAAAEY"]
[Tue Jul 21 08:23:04.816429 2026] [security2:error] [pid 419508:tid 419747] [client 20.226.60.151:60620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/water.php"] [unique_id "al9WmFcagwCeNbomjVsKhAAAAfs"]
[Tue Jul 21 08:23:04.933671 2026] [security2:error] [pid 419508:tid 419652] [client 20.151.10.161:37586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/w3lls.php"] [unique_id "al9WmFcagwCeNbomjVsKhQAAAZ0"]
[Tue Jul 21 08:23:04.993270 2026] [security2:error] [pid 411857:tid 412043] [client 65.21.113.253:56578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WmC7ynBpLeKYztQPnxAAAADY"]
[Tue Jul 21 08:23:05.010843 2026] [security2:error] [pid 419508:tid 419731] [client 20.220.225.223:12318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/wpx.php"] [unique_id "al9WmVcagwCeNbomjVsKhgAAAew"]
[Tue Jul 21 08:23:05.229066 2026] [security2:error] [pid 419508:tid 419655] [client 20.151.10.161:51139] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "aizenpower.shop-officialstore.com"] [uri "/1.php"] [unique_id "al9WmVcagwCeNbomjVsKigAAAaA"]
[Tue Jul 21 08:23:05.229186 2026] [security2:error] [pid 419508:tid 419655] [client 20.151.10.161:51139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/1.php"] [unique_id "al9WmVcagwCeNbomjVsKigAAAaA"]
[Tue Jul 21 08:23:05.243707 2026] [security2:error] [pid 418108:tid 418317] [client 20.151.10.161:37579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-ws68.php"] [unique_id "al9WmQ0cxofL2J1zwYrECgAAAVc"]
[Tue Jul 21 08:23:05.398507 2026] [access_compat:error] [pid 419508:tid 419757] [client 162.241.63.68:46418] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:23:05.504058 2026] [security2:error] [pid 411857:tid 412007] [client 20.226.60.151:50126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/nano.php"] [unique_id "al9WmS7ynBpLeKYztQPn2AAAABI"]
[Tue Jul 21 08:23:05.527155 2026] [security2:error] [pid 419508:tid 419754] [client 128.127.105.184:38602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9WmVcagwCeNbomjVsKjgAAAgI"]
[Tue Jul 21 08:23:05.527242 2026] [security2:error] [pid 419508:tid 419754] [client 128.127.105.184:38602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9WmVcagwCeNbomjVsKjgAAAgI"]
[Tue Jul 21 08:23:05.565078 2026] [security2:error] [pid 411857:tid 412073] [client 20.151.10.161:37591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/xyn.php"] [unique_id "al9WmS7ynBpLeKYztQPn2QAAAFQ"]
[Tue Jul 21 08:23:05.590433 2026] [security2:error] [pid 419508:tid 419691] [client 20.151.10.161:51740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/100.php"] [unique_id "al9WmVcagwCeNbomjVsKjwAAAcQ"]
[Tue Jul 21 08:23:05.694240 2026] [security2:error] [pid 419508:tid 419680] [client 4.194.217.15:3626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/12.php"] [unique_id "al9WmVcagwCeNbomjVsKkwAAAbk"]
[Tue Jul 21 08:23:05.757765 2026] [security2:error] [pid 419508:tid 419751] [client 20.206.105.145:20107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/FAQ.php"] [unique_id "al9WmVcagwCeNbomjVsKlgAAAf8"]
[Tue Jul 21 08:23:05.846729 2026] [security2:error] [pid 419508:tid 419724] [client 20.151.10.161:37605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/green3.php"] [unique_id "al9WmVcagwCeNbomjVsKlwAAAeU"]
[Tue Jul 21 08:23:06.040965 2026] [security2:error] [pid 419508:tid 419647] [client 20.151.10.161:50792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/about.php"] [unique_id "al9WmlcagwCeNbomjVsKnwAAAZg"]
[Tue Jul 21 08:23:06.121489 2026] [security2:error] [pid 411857:tid 412017] [client 20.151.10.161:37523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/ccs.php"] [unique_id "al9Wmi7ynBpLeKYztQPn4gAAABw"]
[Tue Jul 21 08:23:06.209946 2026] [security2:error] [pid 419508:tid 419739] [client 20.226.60.151:56945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/blurbs.php"] [unique_id "al9WmlcagwCeNbomjVsKpAAAAfQ"]
[Tue Jul 21 08:23:06.370446 2026] [security2:error] [pid 419508:tid 419720] [client 20.151.10.161:50796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/about.php"] [unique_id "al9WmlcagwCeNbomjVsKqAAAAeE"]
[Tue Jul 21 08:23:06.371451 2026] [security2:error] [pid 419508:tid 419684] [client 20.220.225.223:4688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/ace2.php"] [unique_id "al9WmlcagwCeNbomjVsKqQAAAb0"]
[Tue Jul 21 08:23:06.405823 2026] [security2:error] [pid 419508:tid 419687] [client 20.151.10.161:37599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/ccc.php"] [unique_id "al9WmlcagwCeNbomjVsKqgAAAcA"]
[Tue Jul 21 08:23:06.622241 2026] [security2:error] [pid 419508:tid 419669] [client 20.220.225.223:20870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/wpx.php"] [unique_id "al9WmlcagwCeNbomjVsKrgAAAa4"]
[Tue Jul 21 08:23:06.680340 2026] [security2:error] [pid 419508:tid 419674] [client 20.151.10.161:51150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/admin.php"] [unique_id "al9WmlcagwCeNbomjVsKsAAAAbM"]
[Tue Jul 21 08:23:06.724075 2026] [security2:error] [pid 419508:tid 419692] [client 4.194.217.15:1171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/123.php"] [unique_id "al9WmlcagwCeNbomjVsKswAAAcU"]
[Tue Jul 21 08:23:06.744333 2026] [rewrite:warn] [pid 419508:tid 419562] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:06.747224 2026] [security2:error] [pid 419508:tid 419677] [client 20.151.10.161:37603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/get.php"] [unique_id "al9WmlcagwCeNbomjVsKtQAAAbY"]
[Tue Jul 21 08:23:06.776205 2026] [security2:error] [pid 411857:tid 412087] [client 65.21.113.253:56578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Wmi7ynBpLeKYztQPn6AAAAGI"]
[Tue Jul 21 08:23:06.889674 2026] [security2:error] [pid 418108:tid 418249] [client 20.226.60.151:56903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/bajah.php"] [unique_id "al9Wmg0cxofL2J1zwYrEEgAAARM"]
[Tue Jul 21 08:23:06.991780 2026] [security2:error] [pid 419508:tid 419735] [client 20.151.10.161:50762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/admin.php"] [unique_id "al9WmlcagwCeNbomjVsKuAAAAfA"]
[Tue Jul 21 08:23:07.089189 2026] [security2:error] [pid 419508:tid 419673] [client 20.151.10.161:37594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/images.php"] [unique_id "al9Wm1cagwCeNbomjVsKvgAAAbI"]
[Tue Jul 21 08:23:07.346685 2026] [security2:error] [pid 419508:tid 419762] [client 20.151.10.161:51196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/edit.php"] [unique_id "al9Wm1cagwCeNbomjVsKwgAAAgo"]
[Tue Jul 21 08:23:07.367575 2026] [security2:error] [pid 419508:tid 419709] [client 20.226.60.151:60573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/moon.php"] [unique_id "al9Wm1cagwCeNbomjVsKwwAAAdY"]
[Tue Jul 21 08:23:07.547445 2026] [security2:error] [pid 419508:tid 419738] [client 20.226.60.151:56929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/a.php"] [unique_id "al9Wm1cagwCeNbomjVsKxgAAAfM"]
[Tue Jul 21 08:23:07.560049 2026] [security2:error] [pid 418108:tid 418211] [remote 81.173.115.7:38552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Wmw0cxofL2J1zwYrEFgABL2Q"]
[Tue Jul 21 08:23:07.638931 2026] [security2:error] [pid 419508:tid 419711] [client 20.220.225.223:20921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/berlin.php"] [unique_id "al9Wm1cagwCeNbomjVsKxwAAAdg"]
[Tue Jul 21 08:23:07.699989 2026] [security2:error] [pid 419508:tid 419749] [client 20.151.10.161:50775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-content/admin.php"] [unique_id "al9Wm1cagwCeNbomjVsKyQAAAf0"]
[Tue Jul 21 08:23:07.767151 2026] [security2:error] [pid 419508:tid 419642] [client 4.194.217.15:3615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/13.php"] [unique_id "al9Wm1cagwCeNbomjVsKygAAAZM"]
[Tue Jul 21 08:23:07.878518 2026] [security2:error] [pid 419508:tid 419739] [client 20.151.10.161:37621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/alls.php"] [unique_id "al9Wm1cagwCeNbomjVsKzgAAAfQ"]
[Tue Jul 21 08:23:07.952397 2026] [security2:error] [pid 419508:tid 419557] [remote 100.42.189.89:58046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Wm1cagwCeNbomjVsKzwAB7jA"]
[Tue Jul 21 08:23:07.971860 2026] [security2:error] [pid 419508:tid 419613] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wm1cagwCeNbomjVsK0AABpWg"]
[Tue Jul 21 08:23:07.972035 2026] [security2:error] [pid 419508:tid 419660] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wm1cagwCeNbomjVsK0AABpWg"]
[Tue Jul 21 08:23:07.989995 2026] [security2:error] [pid 411857:tid 412078] [client 223.181.60.88:33207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Wmy7ynBpLeKYztQPoBwAAAFk"]
[Tue Jul 21 08:23:07.991713 2026] [security2:error] [pid 411857:tid 412078] [client 223.181.60.88:33207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Wmy7ynBpLeKYztQPoBwAAAFk"]
[Tue Jul 21 08:23:08.174040 2026] [security2:error] [pid 411857:tid 411993] [client 20.151.10.161:51181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/f6.php"] [unique_id "al9WnC7ynBpLeKYztQPoCgAAAAQ"]
[Tue Jul 21 08:23:08.179997 2026] [security2:error] [pid 419508:tid 419658] [client 34.73.118.223:52355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.118.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oppbrazil.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WnFcagwCeNbomjVsK0wAAAaM"]
[Tue Jul 21 08:23:08.180134 2026] [security2:error] [pid 419508:tid 419658] [client 34.73.118.223:52355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oppbrazil.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WnFcagwCeNbomjVsK0wAAAaM"]
[Tue Jul 21 08:23:08.280731 2026] [security2:error] [pid 419508:tid 419765] [client 20.226.60.151:56948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/edit.php"] [unique_id "al9WnFcagwCeNbomjVsK1QAAAg0"]
[Tue Jul 21 08:23:08.282595 2026] [security2:error] [pid 418108:tid 418339] [client 20.220.225.223:20918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/billur.php"] [unique_id "al9WnA0cxofL2J1zwYrEGgAAAW0"]
[Tue Jul 21 08:23:08.389924 2026] [security2:error] [pid 419508:tid 419724] [client 152.59.34.51:64207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WnFcagwCeNbomjVsK2QAAAeU"]
[Tue Jul 21 08:23:08.398148 2026] [security2:error] [pid 419508:tid 419724] [client 152.59.34.51:64207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WnFcagwCeNbomjVsK2QAAAeU"]
[Tue Jul 21 08:23:08.404453 2026] [security2:error] [pid 419508:tid 419760] [client 20.151.10.161:37618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/yyu.php"] [unique_id "al9WnFcagwCeNbomjVsK2gAAAgg"]
[Tue Jul 21 08:23:08.441012 2026] [security2:error] [pid 418108:tid 418129] [remote 217.182.128.41:43398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Wmw0cxofL2J1zwYrEFAABJhI"]
[Tue Jul 21 08:23:08.479250 2026] [security2:error] [pid 418108:tid 418270] [client 20.151.10.161:50784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/inputs.php"] [unique_id "al9WnA0cxofL2J1zwYrEHwAAASg"]
[Tue Jul 21 08:23:08.655483 2026] [security2:error] [pid 419508:tid 419668] [client 61.1.167.83:53262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WnFcagwCeNbomjVsK3QAAAa0"]
[Tue Jul 21 08:23:08.655619 2026] [security2:error] [pid 419508:tid 419668] [client 61.1.167.83:53262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WnFcagwCeNbomjVsK3QAAAa0"]
[Tue Jul 21 08:23:08.768081 2026] [security2:error] [pid 411857:tid 412024] [client 65.21.113.253:56578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WnC7ynBpLeKYztQPoDQAAACM"]
[Tue Jul 21 08:23:08.800655 2026] [security2:error] [pid 419508:tid 419721] [client 4.194.217.15:1172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/133.php"] [unique_id "al9WnFcagwCeNbomjVsK3wAAAeI"]
[Tue Jul 21 08:23:08.921329 2026] [security2:error] [pid 411857:tid 412092] [client 128.127.105.184:54818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9WnC7ynBpLeKYztQPoGgAAAGc"]
[Tue Jul 21 08:23:08.921452 2026] [security2:error] [pid 411857:tid 412092] [client 128.127.105.184:54818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9WnC7ynBpLeKYztQPoGgAAAGc"]
[Tue Jul 21 08:23:08.936638 2026] [security2:error] [pid 418108:tid 418334] [client 20.151.10.161:51187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/inputs.php"] [unique_id "al9WnA0cxofL2J1zwYrEIQAAAWg"]
[Tue Jul 21 08:23:08.968024 2026] [security2:error] [pid 419508:tid 419692] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WnFcagwCeNbomjVsK3gAAAcU"]
[Tue Jul 21 08:23:09.028545 2026] [security2:error] [pid 419508:tid 419727] [client 20.226.60.151:63306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/hosty.php"] [unique_id "al9WnVcagwCeNbomjVsK4gAAAeg"]
[Tue Jul 21 08:23:09.100211 2026] [security2:error] [pid 411857:tid 412006] [client 87.116.180.198:14018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WnS7ynBpLeKYztQPoHQAAABE"]
[Tue Jul 21 08:23:09.100335 2026] [security2:error] [pid 411857:tid 412006] [client 87.116.180.198:14018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WnS7ynBpLeKYztQPoHQAAABE"]
[Tue Jul 21 08:23:09.170638 2026] [security2:error] [pid 411857:tid 412114] [client 20.151.10.161:37540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/by.php"] [unique_id "al9WnS7ynBpLeKYztQPoHgAAAH0"]
[Tue Jul 21 08:23:09.340915 2026] [security2:error] [pid 411857:tid 411923] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WnS7ynBpLeKYztQPoIAAABkA"]
[Tue Jul 21 08:23:09.341353 2026] [security2:error] [pid 411857:tid 411995] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WnS7ynBpLeKYztQPoIAAABkA"]
[Tue Jul 21 08:23:09.354231 2026] [security2:error] [pid 419508:tid 419757] [client 20.151.10.161:51163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/av.php"] [unique_id "al9WnVcagwCeNbomjVsK5AAAAgU"]
[Tue Jul 21 08:23:09.414658 2026] [security2:error] [pid 411857:tid 412085] [client 20.220.225.223:20881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/mimpi.php"] [unique_id "al9WnS7ynBpLeKYztQPoJwAAAGA"]
[Tue Jul 21 08:23:09.450270 2026] [security2:error] [pid 419508:tid 419647] [client 117.213.202.34:64376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WnFcagwCeNbomjVsK2wAAAZg"]
[Tue Jul 21 08:23:09.450475 2026] [security2:error] [pid 419508:tid 419647] [client 117.213.202.34:64376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WnFcagwCeNbomjVsK2wAAAZg"]
[Tue Jul 21 08:23:09.452836 2026] [security2:error] [pid 419508:tid 419758] [client 103.151.46.103:51137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WnVcagwCeNbomjVsK6AAAAgY"]
[Tue Jul 21 08:23:09.452978 2026] [security2:error] [pid 419508:tid 419758] [client 103.151.46.103:51137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9WnVcagwCeNbomjVsK6AAAAgY"]
[Tue Jul 21 08:23:09.484370 2026] [security2:error] [pid 411857:tid 412099] [client 20.226.60.151:60609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-info.php"] [unique_id "al9WnS7ynBpLeKYztQPoKQAAAG4"]
[Tue Jul 21 08:23:09.490892 2026] [security2:error] [pid 411857:tid 412055] [client 20.206.105.145:20169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/coffexium.php"] [unique_id "al9WnS7ynBpLeKYztQPoKgAAAEI"]
[Tue Jul 21 08:23:09.614163 2026] [security2:error] [pid 419508:tid 419764] [client 195.49.128.211:56166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WnVcagwCeNbomjVsK6QAAAgw"]
[Tue Jul 21 08:23:09.614313 2026] [security2:error] [pid 419508:tid 419764] [client 195.49.128.211:56166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WnVcagwCeNbomjVsK6QAAAgw"]
[Tue Jul 21 08:23:09.681945 2026] [security2:error] [pid 419508:tid 419685] [client 150.129.202.39:12773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WnVcagwCeNbomjVsK6gAAAb4"]
[Tue Jul 21 08:23:09.682087 2026] [security2:error] [pid 419508:tid 419685] [client 150.129.202.39:12773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WnVcagwCeNbomjVsK6gAAAb4"]
[Tue Jul 21 08:23:09.741514 2026] [security2:error] [pid 419508:tid 419751] [client 20.151.10.161:51182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/classwithtostring.php"] [unique_id "al9WnVcagwCeNbomjVsK6wAAAf8"]
[Tue Jul 21 08:23:09.849138 2026] [security2:error] [pid 418108:tid 418354] [client 4.194.217.15:4217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/155.php"] [unique_id "al9WnQ0cxofL2J1zwYrEJwAAAXw"]
[Tue Jul 21 08:23:09.873364 2026] [security2:error] [pid 411857:tid 412013] [client 20.226.60.151:56844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/k.php"] [unique_id "al9WnS7ynBpLeKYztQPoMQAAABg"]
[Tue Jul 21 08:23:10.038782 2026] [security2:error] [pid 418108:tid 418262] [client 20.151.10.161:50765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9Wng0cxofL2J1zwYrEKQAAASA"]
[Tue Jul 21 08:23:10.103024 2026] [security2:error] [pid 419508:tid 419563] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9WnlcagwCeNbomjVsK7gABjzY"]
[Tue Jul 21 08:23:10.103170 2026] [security2:error] [pid 419508:tid 419638] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9WnlcagwCeNbomjVsK7gABjzY"]
[Tue Jul 21 08:23:10.187071 2026] [security2:error] [pid 418108:tid 418281] [client 14.245.224.124:62013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Wng0cxofL2J1zwYrELQAAATM"]
[Tue Jul 21 08:23:10.187666 2026] [security2:error] [pid 418108:tid 418281] [client 14.245.224.124:62013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Wng0cxofL2J1zwYrELQAAATM"]
[Tue Jul 21 08:23:10.241986 2026] [security2:error] [pid 411857:tid 412004] [client 20.151.10.161:37545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/FAQ.php"] [unique_id "al9Wni7ynBpLeKYztQPoOgAAAA8"]
[Tue Jul 21 08:23:10.326864 2026] [security2:error] [pid 419508:tid 419694] [client 74.249.245.134:21410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/init.php"] [unique_id "al9WnlcagwCeNbomjVsK8AAAAcc"]
[Tue Jul 21 08:23:10.393877 2026] [security2:error] [pid 419508:tid 419642] [client 20.151.10.161:50794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-blog.php"] [unique_id "al9WnlcagwCeNbomjVsK8QAAAZM"]
[Tue Jul 21 08:23:10.580826 2026] [security2:error] [pid 419508:tid 419603] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WnlcagwCeNbomjVsK8wAB_V4"]
[Tue Jul 21 08:23:10.581003 2026] [security2:error] [pid 419508:tid 419749] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WnlcagwCeNbomjVsK8wAB_V4"]
[Tue Jul 21 08:23:10.731088 2026] [security2:error] [pid 419508:tid 419711] [client 202.179.75.202:50434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WnlcagwCeNbomjVsK-AAAAdg"]
[Tue Jul 21 08:23:10.731255 2026] [security2:error] [pid 419508:tid 419711] [client 202.179.75.202:50434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WnlcagwCeNbomjVsK-AAAAdg"]
[Tue Jul 21 08:23:10.746966 2026] [security2:error] [pid 419508:tid 419736] [client 20.226.60.151:56898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/aaa.php"] [unique_id "al9WnlcagwCeNbomjVsK-QAAAfE"]
[Tue Jul 21 08:23:10.829075 2026] [autoindex:error] [pid 419508:tid 419671] [client 20.151.10.161:51764] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:10.877668 2026] [security2:error] [pid 419508:tid 419739] [client 4.194.217.15:12560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/166.php"] [unique_id "al9WnlcagwCeNbomjVsK_QAAAfQ"]
[Tue Jul 21 08:23:10.929212 2026] [security2:error] [pid 419508:tid 419688] [client 20.220.225.223:20891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/dp.php"] [unique_id "al9WnlcagwCeNbomjVsK_gAAAcE"]
[Tue Jul 21 08:23:11.103019 2026] [security2:error] [pid 419508:tid 419722] [client 20.151.10.161:51764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-content/admin.php"] [unique_id "al9Wn1cagwCeNbomjVsK_wAAAeM"]
[Tue Jul 21 08:23:11.211721 2026] [security2:error] [pid 419508:tid 419704] [client 20.220.225.223:12602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/berlin.php"] [unique_id "al9Wn1cagwCeNbomjVsLAQAAAdE"]
[Tue Jul 21 08:23:11.235197 2026] [security2:error] [pid 419508:tid 419760] [client 20.151.10.161:37442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/coffexium.php"] [unique_id "al9Wn1cagwCeNbomjVsLAgAAAgg"]
[Tue Jul 21 08:23:11.352065 2026] [security2:error] [pid 411857:tid 412044] [client 20.226.60.151:56879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/file5.php"] [unique_id "al9Wny7ynBpLeKYztQPoSgAAADc"]
[Tue Jul 21 08:23:11.371257 2026] [security2:error] [pid 419508:tid 419687] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WnlcagwCeNbomjVsK_AAAAcA"]
[Tue Jul 21 08:23:11.522831 2026] [security2:error] [pid 419508:tid 419756] [client 20.151.10.161:50771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/adminfuns.php"] [unique_id "al9Wn1cagwCeNbomjVsLBwAAAgQ"]
[Tue Jul 21 08:23:11.769717 2026] [security2:error] [pid 419508:tid 419717] [client 14.97.58.74:42758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Wn1cagwCeNbomjVsLDQAAAd4"]
[Tue Jul 21 08:23:11.769830 2026] [security2:error] [pid 419508:tid 419717] [client 14.97.58.74:42758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Wn1cagwCeNbomjVsLDQAAAd4"]
[Tue Jul 21 08:23:11.831440 2026] [security2:error] [pid 411857:tid 411897] [remote 100.42.189.89:36242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wny7ynBpLeKYztQPoUgAAWSY"]
[Tue Jul 21 08:23:11.831589 2026] [security2:error] [pid 411857:tid 412078] [client 100.42.189.89:36242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wny7ynBpLeKYztQPoUgAAWSY"]
[Tue Jul 21 08:23:11.931441 2026] [security2:error] [pid 419508:tid 419662] [client 4.194.217.15:1196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/2.php"] [unique_id "al9Wn1cagwCeNbomjVsLEAAAAac"]
[Tue Jul 21 08:23:11.939361 2026] [security2:error] [pid 411857:tid 412043] [client 20.151.10.161:50809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/goods.php"] [unique_id "al9Wny7ynBpLeKYztQPoVQAAADY"]
[Tue Jul 21 08:23:11.976617 2026] [security2:error] [pid 419508:tid 419758] [client 20.151.10.161:37556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/red.php"] [unique_id "al9Wn1cagwCeNbomjVsLEQAAAgY"]
[Tue Jul 21 08:23:12.068248 2026] [security2:error] [pid 419508:tid 419646] [client 20.226.60.151:56937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/222.php"] [unique_id "al9WoFcagwCeNbomjVsLFwAAAZc"]
[Tue Jul 21 08:23:12.222597 2026] [security2:error] [pid 411857:tid 412067] [client 20.197.192.193:62920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9WoC7ynBpLeKYztQPoWQAAAE4"]
[Tue Jul 21 08:23:12.258919 2026] [security2:error] [pid 419508:tid 419642] [client 20.151.10.161:51735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/ms-edit.php"] [unique_id "al9WoFcagwCeNbomjVsLGQAAAZM"]
[Tue Jul 21 08:23:12.261240 2026] [security2:error] [pid 411857:tid 412052] [client 20.226.60.151:56880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/test.php"] [unique_id "al9WoC7ynBpLeKYztQPoWgAAAD8"]
[Tue Jul 21 08:23:12.263301 2026] [security2:error] [pid 419508:tid 419725] [client 20.197.192.193:3044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9WoFcagwCeNbomjVsLGgAAAeY"]
[Tue Jul 21 08:23:12.322478 2026] [security2:error] [pid 419508:tid 419701] [client 20.197.192.193:3046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/dp.php"] [unique_id "al9WoFcagwCeNbomjVsLHAAAAc4"]
[Tue Jul 21 08:23:12.369270 2026] [security2:error] [pid 411857:tid 412114] [client 20.197.192.193:62929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/old.php"] [unique_id "al9WoC7ynBpLeKYztQPoXAAAAH0"]
[Tue Jul 21 08:23:12.449673 2026] [security2:error] [pid 419508:tid 419716] [client 20.220.225.223:12575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/billur.php"] [unique_id "al9WoFcagwCeNbomjVsLHQAAAd0"]
[Tue Jul 21 08:23:12.479702 2026] [security2:error] [pid 419508:tid 419742] [client 20.197.192.193:3037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/ms-new.php"] [unique_id "al9WoFcagwCeNbomjVsLHgAAAfc"]
[Tue Jul 21 08:23:12.489855 2026] [security2:error] [pid 419508:tid 419730] [client 20.226.60.151:56955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/aaa.php"] [unique_id "al9WoFcagwCeNbomjVsLHwAAAes"]
[Tue Jul 21 08:23:12.550170 2026] [security2:error] [pid 419508:tid 419660] [client 20.151.10.161:51169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/222.php"] [unique_id "al9WoFcagwCeNbomjVsLIwAAAaU"]
[Tue Jul 21 08:23:12.555609 2026] [security2:error] [pid 411857:tid 412073] [client 20.197.192.193:3022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/track.php"] [unique_id "al9WoC7ynBpLeKYztQPoYQAAAFQ"]
[Tue Jul 21 08:23:12.630225 2026] [security2:error] [pid 411857:tid 412038] [client 20.197.192.193:3043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/2352356666.php"] [unique_id "al9WoC7ynBpLeKYztQPoYwAAADE"]
[Tue Jul 21 08:23:12.711656 2026] [security2:error] [pid 418108:tid 418284] [client 20.197.192.193:62943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/pn.php"] [unique_id "al9WoA0cxofL2J1zwYrENwAAATY"]
[Tue Jul 21 08:23:12.731535 2026] [security2:error] [pid 418108:tid 418310] [client 20.197.192.193:3008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9WoA0cxofL2J1zwYrEOAAAAVA"]
[Tue Jul 21 08:23:12.734885 2026] [security2:error] [pid 419508:tid 419739] [client 20.151.10.161:37578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9WoFcagwCeNbomjVsLJQAAAfQ"]
[Tue Jul 21 08:23:12.748532 2026] [security2:error] [pid 419508:tid 419745] [client 20.197.192.193:3019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/dr.php"] [unique_id "al9WoFcagwCeNbomjVsLJgAAAfk"]
[Tue Jul 21 08:23:12.763224 2026] [security2:error] [pid 419508:tid 419765] [client 20.197.192.193:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/2x.php"] [unique_id "al9WoFcagwCeNbomjVsLJwAAAg0"]
[Tue Jul 21 08:23:12.792705 2026] [security2:error] [pid 411857:tid 412020] [client 20.197.192.193:3009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/kq1.php"] [unique_id "al9WoC7ynBpLeKYztQPoZgAAAB8"]
[Tue Jul 21 08:23:12.794689 2026] [security2:error] [pid 419508:tid 419684] [client 20.220.225.223:20930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/bootstrap.php"] [unique_id "al9WoFcagwCeNbomjVsLKQAAAb0"]
[Tue Jul 21 08:23:12.835025 2026] [security2:error] [pid 411857:tid 412005] [client 20.226.60.151:56846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/11.php"] [unique_id "al9WoC7ynBpLeKYztQPoaAAAABA"]
[Tue Jul 21 08:23:12.838557 2026] [security2:error] [pid 411857:tid 412115] [client 20.151.10.161:50757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/cgi-bin/index.php"] [unique_id "al9WoC7ynBpLeKYztQPoaQAAAH4"]
[Tue Jul 21 08:23:12.843007 2026] [security2:error] [pid 411857:tid 412093] [client 20.197.192.193:62939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/zzz.php"] [unique_id "al9WoC7ynBpLeKYztQPoagAAAGg"]
[Tue Jul 21 08:23:12.868876 2026] [security2:error] [pid 411857:tid 412025] [client 20.197.192.193:62919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/wicked.php"] [unique_id "al9WoC7ynBpLeKYztQPobAAAACQ"]
[Tue Jul 21 08:23:12.884140 2026] [security2:error] [pid 419508:tid 419713] [client 20.197.192.193:1469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/edit.php"] [unique_id "al9WoFcagwCeNbomjVsLLQAAAdo"]
[Tue Jul 21 08:23:12.906982 2026] [security2:error] [pid 419508:tid 419668] [client 20.197.192.193:62914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/kua.php"] [unique_id "al9WoFcagwCeNbomjVsLLwAAAa0"]
[Tue Jul 21 08:23:12.957893 2026] [security2:error] [pid 419508:tid 419671] [client 4.194.217.15:4131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/2026w.php"] [unique_id "al9WoFcagwCeNbomjVsLMQAAAbA"]
[Tue Jul 21 08:23:12.991339 2026] [security2:error] [pid 419508:tid 419756] [client 20.197.192.193:62957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/ez.php"] [unique_id "al9WoFcagwCeNbomjVsLMwAAAgQ"]
[Tue Jul 21 08:23:13.084591 2026] [security2:error] [pid 419508:tid 419675] [client 20.197.192.193:62973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/fz.php"] [unique_id "al9WoVcagwCeNbomjVsLNwAAAbQ"]
[Tue Jul 21 08:23:13.107708 2026] [security2:error] [pid 411857:tid 412015] [client 20.197.192.193:62942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/la.php"] [unique_id "al9WoS7ynBpLeKYztQPocgAAABo"]
[Tue Jul 21 08:23:13.114972 2026] [security2:error] [pid 419508:tid 419702] [client 74.7.228.63:46502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "2ndmile.com.br.claritycare.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9WoVcagwCeNbomjVsLOAABzx8"]
[Tue Jul 21 08:23:13.127830 2026] [security2:error] [pid 419508:tid 419690] [client 20.226.60.151:56899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/mac.php"] [unique_id "al9WoVcagwCeNbomjVsLOQAAAcM"]
[Tue Jul 21 08:23:13.154760 2026] [security2:error] [pid 419508:tid 419717] [client 20.197.192.193:1448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9WoVcagwCeNbomjVsLOgAAAd4"]
[Tue Jul 21 08:23:13.157674 2026] [security2:error] [pid 419508:tid 419692] [client 187.125.243.197:54907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WoVcagwCeNbomjVsLOwAAAcU"]
[Tue Jul 21 08:23:13.158491 2026] [security2:error] [pid 419508:tid 419692] [client 187.125.243.197:54907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WoVcagwCeNbomjVsLOwAAAcU"]
[Tue Jul 21 08:23:13.177321 2026] [autoindex:error] [pid 419508:tid 419754] [client 20.151.10.161:50806] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:13.210567 2026] [security2:error] [pid 418108:tid 418348] [client 20.197.192.193:62932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/inso.php"] [unique_id "al9WoQ0cxofL2J1zwYrEOgAAAXY"]
[Tue Jul 21 08:23:13.232737 2026] [security2:error] [pid 418108:tid 418318] [client 20.197.192.193:3040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/wpx.php"] [unique_id "al9WoQ0cxofL2J1zwYrEOwAAAVg"]
[Tue Jul 21 08:23:13.261867 2026] [security2:error] [pid 419508:tid 419656] [client 20.197.192.193:62915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/berlin.php"] [unique_id "al9WoVcagwCeNbomjVsLPgAAAaE"]
[Tue Jul 21 08:23:13.278681 2026] [security2:error] [pid 411857:tid 412030] [client 20.197.192.193:3023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/billur.php"] [unique_id "al9WoS7ynBpLeKYztQPodQAAACk"]
[Tue Jul 21 08:23:13.298245 2026] [security2:error] [pid 419508:tid 419710] [client 20.197.192.193:62922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/mimpi.php"] [unique_id "al9WoVcagwCeNbomjVsLPwAAAdc"]
[Tue Jul 21 08:23:13.322002 2026] [security2:error] [pid 411857:tid 412098] [client 20.197.192.193:3042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/dp.php"] [unique_id "al9WoS7ynBpLeKYztQPodgAAAG0"]
[Tue Jul 21 08:23:13.378897 2026] [security2:error] [pid 419508:tid 419640] [client 20.197.192.193:1461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/bootstrap.php"] [unique_id "al9WoVcagwCeNbomjVsLQgAAAZE"]
[Tue Jul 21 08:23:13.389909 2026] [security2:error] [pid 419508:tid 419698] [client 20.226.60.151:56906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/chosen.php"] [unique_id "al9WoVcagwCeNbomjVsLQwAAAcs"]
[Tue Jul 21 08:23:13.395020 2026] [security2:error] [pid 419508:tid 419687] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WoFcagwCeNbomjVsLLgAAAcA"]
[Tue Jul 21 08:23:13.413114 2026] [security2:error] [pid 419508:tid 419609] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WoVcagwCeNbomjVsLRQABk2Q"]
[Tue Jul 21 08:23:13.413279 2026] [security2:error] [pid 419508:tid 419642] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WoVcagwCeNbomjVsLRQABk2Q"]
[Tue Jul 21 08:23:13.440374 2026] [security2:error] [pid 419508:tid 419644] [client 20.197.192.193:62920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/wp-editor.php"] [unique_id "al9WoVcagwCeNbomjVsLRgAAAZU"]
[Tue Jul 21 08:23:13.461318 2026] [security2:error] [pid 419508:tid 419726] [client 20.151.10.161:50806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/BDKR28WP.php"] [unique_id "al9WoVcagwCeNbomjVsLRwAAAec"]
[Tue Jul 21 08:23:13.516120 2026] [security2:error] [pid 418108:tid 418317] [client 20.220.225.223:11969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/mimpi.php"] [unique_id "al9WoQ0cxofL2J1zwYrEPAAAAVc"]
[Tue Jul 21 08:23:13.520034 2026] [security2:error] [pid 411857:tid 412064] [client 20.197.192.193:3031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/cro.php"] [unique_id "al9WoS7ynBpLeKYztQPoeQAAAEs"]
[Tue Jul 21 08:23:13.561933 2026] [security2:error] [pid 411857:tid 412051] [client 20.197.192.193:62958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/cron-tab.php"] [unique_id "al9WoS7ynBpLeKYztQPoewAAAD4"]
[Tue Jul 21 08:23:13.604799 2026] [security2:error] [pid 419508:tid 419694] [client 115.134.11.136:57437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WoVcagwCeNbomjVsLSwAAAcc"]
[Tue Jul 21 08:23:13.605579 2026] [security2:error] [pid 419508:tid 419694] [client 115.134.11.136:57437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WoVcagwCeNbomjVsLSwAAAcc"]
[Tue Jul 21 08:23:13.612571 2026] [security2:error] [pid 419508:tid 419672] [client 20.197.192.193:3028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/koiy.php"] [unique_id "al9WoVcagwCeNbomjVsLTAAAAbE"]
[Tue Jul 21 08:23:13.616826 2026] [security2:error] [pid 419508:tid 419737] [client 154.208.47.42:64374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WoVcagwCeNbomjVsLTgAAAfI"]
[Tue Jul 21 08:23:13.616910 2026] [security2:error] [pid 419508:tid 419737] [client 154.208.47.42:64374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WoVcagwCeNbomjVsLTgAAAfI"]
[Tue Jul 21 08:23:13.647414 2026] [security2:error] [pid 419508:tid 419703] [client 20.197.192.193:3038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/hp2.php"] [unique_id "al9WoVcagwCeNbomjVsLTwAAAdA"]
[Tue Jul 21 08:23:13.652070 2026] [security2:error] [pid 411857:tid 411887] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WoS7ynBpLeKYztQPofQAAOBw"]
[Tue Jul 21 08:23:13.652227 2026] [security2:error] [pid 411857:tid 412045] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WoS7ynBpLeKYztQPofQAAOBw"]
[Tue Jul 21 08:23:13.686989 2026] [security2:error] [pid 419508:tid 419745] [client 20.197.192.193:62928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/hp3.php"] [unique_id "al9WoVcagwCeNbomjVsLUQAAAfk"]
[Tue Jul 21 08:23:13.701275 2026] [security2:error] [pid 419508:tid 419722] [client 20.197.192.193:62944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/aa1.php"] [unique_id "al9WoVcagwCeNbomjVsLUgAAAeM"]
[Tue Jul 21 08:23:13.722650 2026] [security2:error] [pid 419508:tid 419688] [client 20.197.192.193:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/acew67.php"] [unique_id "al9WoVcagwCeNbomjVsLUwAAAcE"]
[Tue Jul 21 08:23:13.739173 2026] [security2:error] [pid 411857:tid 412088] [client 20.197.192.193:3048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/bscclapb.php"] [unique_id "al9WoS7ynBpLeKYztQPofwAAAGM"]
[Tue Jul 21 08:23:13.760189 2026] [security2:error] [pid 411857:tid 411990] [client 20.197.192.193:3017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/else1.php"] [unique_id "al9WoS7ynBpLeKYztQPogAAAAAE"]
[Tue Jul 21 08:23:13.779415 2026] [security2:error] [pid 419508:tid 419667] [client 20.197.192.193:62965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/tkikikoko.php"] [unique_id "al9WoVcagwCeNbomjVsLVAAAAaw"]
[Tue Jul 21 08:23:13.796251 2026] [security2:error] [pid 418108:tid 418315] [client 20.197.192.193:62924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9WoQ0cxofL2J1zwYrEPQAAAVU"]
[Tue Jul 21 08:23:13.802618 2026] [security2:error] [pid 419508:tid 419713] [client 20.151.10.161:37513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/footer.php"] [unique_id "al9WoVcagwCeNbomjVsLVQAAAdo"]
[Tue Jul 21 08:23:13.809651 2026] [security2:error] [pid 419508:tid 419741] [client 20.197.192.193:62945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/wp-css.php"] [unique_id "al9WoVcagwCeNbomjVsLVgAAAfY"]
[Tue Jul 21 08:23:13.822870 2026] [security2:error] [pid 419508:tid 419677] [client 20.197.192.193:62967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/wp-explorer.php"] [unique_id "al9WoVcagwCeNbomjVsLVwAAAbY"]
[Tue Jul 21 08:23:13.853688 2026] [autoindex:error] [pid 419508:tid 419715] [client 20.151.10.161:51148] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:13.854930 2026] [security2:error] [pid 419508:tid 419658] [client 20.197.192.193:1454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/akismet.php"] [unique_id "al9WoVcagwCeNbomjVsLWQAAAaM"]
[Tue Jul 21 08:23:13.860746 2026] [security2:error] [pid 419508:tid 419721] [client 20.220.225.223:55191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.bomtempo.eng.br"] [uri "/ms.php"] [unique_id "al9WoVcagwCeNbomjVsLWgAAAeI"]
[Tue Jul 21 08:23:13.888176 2026] [security2:error] [pid 419508:tid 419659] [client 20.197.192.193:62949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/ace2.php"] [unique_id "al9WoVcagwCeNbomjVsLXQAAAaQ"]
[Tue Jul 21 08:23:13.923047 2026] [security2:error] [pid 411857:tid 412011] [client 20.197.192.193:62950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "canelapart.com.br"] [uri "/ms.php"] [unique_id "al9WoS7ynBpLeKYztQPoggAAABY"]
[Tue Jul 21 08:23:13.956361 2026] [security2:error] [pid 419508:tid 419712] [client 20.226.60.151:50174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/2000.php"] [unique_id "al9WoVcagwCeNbomjVsLYAAAAdk"]
[Tue Jul 21 08:23:13.995728 2026] [security2:error] [pid 419508:tid 419719] [client 4.194.217.15:3643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/222.php"] [unique_id "al9WoVcagwCeNbomjVsLYQAAAeA"]
[Tue Jul 21 08:23:14.150531 2026] [authz_core:error] [pid 419508:tid 419662] [client 20.151.10.161:51148] AH01630: client denied by server configuration: /home1/ofic8899/aizenpower.shop-officialstore.com/wp-content/uploads/index.php
[Tue Jul 21 08:23:14.291432 2026] [security2:error] [pid 419508:tid 419764] [client 20.151.10.161:51148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/raw.php"] [unique_id "al9WolcagwCeNbomjVsLZQAAAgw"]
[Tue Jul 21 08:23:14.303411 2026] [security2:error] [pid 419508:tid 419624] [remote 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produto-express.com"] [uri "/interface/modules/custom_modules/oe-module-ehi-exporter/src/ExportResult.php"] [unique_id "al9WolcagwCeNbomjVsLZgACBnM"]
[Tue Jul 21 08:23:14.544283 2026] [rewrite:warn] [pid 419508:tid 419610] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.574800 2026] [security2:error] [pid 419508:tid 419700] [client 20.151.10.161:42947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/abcd.php"] [unique_id "al9WolcagwCeNbomjVsLbQAAAc0"]
[Tue Jul 21 08:23:14.623249 2026] [security2:error] [pid 419508:tid 419512] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/phpinfo.php"] [unique_id "al9WolcagwCeNbomjVsLaAAB1AM"]
[Tue Jul 21 08:23:14.642287 2026] [security2:error] [pid 419508:tid 419742] [client 20.226.60.151:63343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/cream1.php"] [unique_id "al9WolcagwCeNbomjVsLcAAAAfc"]
[Tue Jul 21 08:23:14.704308 2026] [rewrite:warn] [pid 419508:tid 419608] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.705391 2026] [rewrite:warn] [pid 419508:tid 419523] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.708217 2026] [rewrite:warn] [pid 418108:tid 418187] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.708748 2026] [rewrite:warn] [pid 419508:tid 419531] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.711725 2026] [rewrite:warn] [pid 411857:tid 419464] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.809369 2026] [rewrite:warn] [pid 419508:tid 419586] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.837592 2026] [rewrite:warn] [pid 419508:tid 419554] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.838198 2026] [rewrite:warn] [pid 411857:tid 411860] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.839888 2026] [rewrite:warn] [pid 419508:tid 419543] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.841465 2026] [rewrite:warn] [pid 419508:tid 419576] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.841780 2026] [rewrite:warn] [pid 419508:tid 419618] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.841782 2026] [rewrite:warn] [pid 419508:tid 419573] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.841797 2026] [rewrite:warn] [pid 419508:tid 419539] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.844136 2026] [rewrite:warn] [pid 418108:tid 418158] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:23:14.906420 2026] [security2:error] [pid 419508:tid 419721] [client 20.151.10.161:51183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/a1.php"] [unique_id "al9WolcagwCeNbomjVsLgAAAAeI"]
[Tue Jul 21 08:23:15.048260 2026] [security2:error] [pid 418108:tid 418272] [client 20.151.10.161:37570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-content/index.php"] [unique_id "al9Wow0cxofL2J1zwYrERAAAASo"]
[Tue Jul 21 08:23:15.097551 2026] [security2:error] [pid 419508:tid 419733] [client 4.194.217.15:4223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/2p.php"] [unique_id "al9Wo1cagwCeNbomjVsLhQAAAe4"]
[Tue Jul 21 08:23:15.273213 2026] [security2:error] [pid 411857:tid 412085] [client 20.151.10.161:51745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9Woy7ynBpLeKYztQPomgAAAGA"]
[Tue Jul 21 08:23:15.459645 2026] [security2:error] [pid 419508:tid 419717] [client 20.220.225.223:34739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/wp-editor.php"] [unique_id "al9Wo1cagwCeNbomjVsLiQAAAd4"]
[Tue Jul 21 08:23:15.499606 2026] [security2:error] [pid 411857:tid 412101] [client 109.248.148.246:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Woy7ynBpLeKYztQPongAAAHA"]
[Tue Jul 21 08:23:15.499691 2026] [security2:error] [pid 411857:tid 412101] [client 109.248.148.246:51626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Woy7ynBpLeKYztQPongAAAHA"]
[Tue Jul 21 08:23:15.546634 2026] [security2:error] [pid 411857:tid 412033] [client 20.151.10.161:37607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/zoro.php"] [unique_id "al9Woy7ynBpLeKYztQPonwAAACw"]
[Tue Jul 21 08:23:15.581986 2026] [security2:error] [pid 419508:tid 419727] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Wo1cagwCeNbomjVsLhAAAAeg"]
[Tue Jul 21 08:23:15.615442 2026] [security2:error] [pid 419508:tid 419708] [client 20.151.10.161:51138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9Wo1cagwCeNbomjVsLjAAAAdU"]
[Tue Jul 21 08:23:15.655079 2026] [security2:error] [pid 419508:tid 419758] [client 20.220.225.223:12552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/dp.php"] [unique_id "al9Wo1cagwCeNbomjVsLjQAAAgY"]
[Tue Jul 21 08:23:15.961411 2026] [security2:error] [pid 419508:tid 419687] [client 87.58.197.199:60071] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "tecnoturbo.com.br"] [uri "/"] [unique_id "al9Wo1cagwCeNbomjVsLkwAAAcA"]
[Tue Jul 21 08:23:15.980804 2026] [security2:error] [pid 419508:tid 419661] [client 20.151.10.161:50768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-content/BypassBest.php"] [unique_id "al9Wo1cagwCeNbomjVsLlAAAAaY"]
[Tue Jul 21 08:23:16.071838 2026] [security2:error] [pid 411857:tid 412047] [client 20.206.105.145:20226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/red.php"] [unique_id "al9WpC7ynBpLeKYztQPoqQAAADo"]
[Tue Jul 21 08:23:16.137323 2026] [security2:error] [pid 411857:tid 412083] [client 20.151.10.161:37628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/admin.php"] [unique_id "al9WpC7ynBpLeKYztQPorAAAAF4"]
[Tue Jul 21 08:23:16.192205 2026] [security2:error] [pid 419508:tid 419710] [client 4.194.217.15:1669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/2p.update.php"] [unique_id "al9WpFcagwCeNbomjVsLmwAAAdc"]
[Tue Jul 21 08:23:16.193212 2026] [security2:error] [pid 411857:tid 412041] [client 109.248.148.246:42564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9WpC7ynBpLeKYztQPorwAAADQ"]
[Tue Jul 21 08:23:16.193309 2026] [security2:error] [pid 411857:tid 412041] [client 109.248.148.246:42564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9WpC7ynBpLeKYztQPorwAAADQ"]
[Tue Jul 21 08:23:16.299687 2026] [authz_core:error] [pid 419508:tid 419703] [client 20.226.60.151:0] AH01630: client denied by server configuration: /home3/cur37674/osantotchay.com.br/wp-content/uploads/index.php
[Tue Jul 21 08:23:16.392130 2026] [security2:error] [pid 419508:tid 419642] [client 74.249.245.134:61942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/settings.php"] [unique_id "al9WpFcagwCeNbomjVsLpQAAAZM"]
[Tue Jul 21 08:23:16.393031 2026] [autoindex:error] [pid 419508:tid 419750] [client 20.226.60.151:0] AH01276: Cannot serve directory /home3/cur37674/osantotchay.com.br/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:16.428691 2026] [security2:error] [pid 418108:tid 418319] [client 20.151.10.161:51176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/simple.php"] [unique_id "al9WpA0cxofL2J1zwYrESAAAAVk"]
[Tue Jul 21 08:23:16.511174 2026] [security2:error] [pid 419508:tid 419741] [client 20.151.10.161:37604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/greap.php"] [unique_id "al9WpFcagwCeNbomjVsLpgAAAfY"]
[Tue Jul 21 08:23:16.869265 2026] [security2:error] [pid 418108:tid 418263] [client 20.151.10.161:37520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/177.php"] [unique_id "al9WpA0cxofL2J1zwYrESgAAASE"]
[Tue Jul 21 08:23:16.959520 2026] [security2:error] [pid 419508:tid 419735] [client 20.151.10.161:51167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/xxx.php"] [unique_id "al9WpFcagwCeNbomjVsLrAAAAfA"]
[Tue Jul 21 08:23:17.028836 2026] [security2:error] [pid 419508:tid 419747] [client 20.226.60.151:56919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/dr.php"] [unique_id "al9WpVcagwCeNbomjVsLrQAAAfs"]
[Tue Jul 21 08:23:17.145160 2026] [security2:error] [pid 411857:tid 412095] [client 20.220.225.223:12585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/bootstrap.php"] [unique_id "al9WpS7ynBpLeKYztQPowAAAAGo"]
[Tue Jul 21 08:23:17.196464 2026] [security2:error] [pid 419508:tid 419662] [client 20.151.10.161:37609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/199.php"] [unique_id "al9WpVcagwCeNbomjVsL9AAAAac"]
[Tue Jul 21 08:23:17.240707 2026] [security2:error] [pid 411857:tid 411993] [client 20.151.10.161:51742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/hypo.php"] [unique_id "al9WpS7ynBpLeKYztQPowQAAAAQ"]
[Tue Jul 21 08:23:17.280223 2026] [security2:error] [pid 418108:tid 418261] [client 4.194.217.15:1376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/3pjcpmfsd8b.php"] [unique_id "al9WpQ0cxofL2J1zwYrESwAAAR8"]
[Tue Jul 21 08:23:17.440552 2026] [autoindex:error] [pid 419508:tid 419762] [client 20.206.105.145:20202] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:17.463291 2026] [security2:error] [pid 419508:tid 419751] [client 20.206.105.145:20202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9WpVcagwCeNbomjVsL_wAAAf8"]
[Tue Jul 21 08:23:17.504796 2026] [security2:error] [pid 419508:tid 419691] [client 20.151.10.161:37516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/file52.php"] [unique_id "al9WpVcagwCeNbomjVsMAAAAAcQ"]
[Tue Jul 21 08:23:17.657380 2026] [autoindex:error] [pid 418108:tid 418306] [client 20.151.10.161:51185] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:17.690894 2026] [security2:error] [pid 419508:tid 419754] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WpVcagwCeNbomjVsL8wAAAgI"]
[Tue Jul 21 08:23:17.790641 2026] [security2:error] [pid 419508:tid 419690] [client 20.151.10.161:37511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/122.php"] [unique_id "al9WpVcagwCeNbomjVsMBQAAAcM"]
[Tue Jul 21 08:23:17.932719 2026] [security2:error] [pid 418108:tid 418320] [client 20.151.10.161:51185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/chosen.php"] [unique_id "al9WpQ0cxofL2J1zwYrETwAAAVo"]
[Tue Jul 21 08:23:17.998823 2026] [security2:error] [pid 419508:tid 419692] [client 128.127.105.184:48820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9WpVcagwCeNbomjVsMCAAAAcU"]
[Tue Jul 21 08:23:17.998931 2026] [security2:error] [pid 419508:tid 419692] [client 128.127.105.184:48820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9WpVcagwCeNbomjVsMCAAAAcU"]
[Tue Jul 21 08:23:18.079201 2026] [security2:error] [pid 419508:tid 419694] [client 74.249.245.134:21155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/g.php"] [unique_id "al9WplcagwCeNbomjVsMCwAAAcc"]
[Tue Jul 21 08:23:18.132564 2026] [security2:error] [pid 419508:tid 419714] [client 20.151.10.161:37597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/green1.php"] [unique_id "al9WplcagwCeNbomjVsMDgAAAds"]
[Tue Jul 21 08:23:18.136826 2026] [security2:error] [pid 411857:tid 411859] [remote 62.60.130.128:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "caetanodemoraeszanga1751206926735.0711679.meusitehostgator.com.br"] [uri "/"] [unique_id "al9Wpi7ynBpLeKYztQPozgAATAA"]
[Tue Jul 21 08:23:18.281105 2026] [security2:error] [pid 411857:tid 412052] [client 185.8.106.219:56362] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "supremaservices.net"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9Wpi7ynBpLeKYztQPo0gAAAD8"]
[Tue Jul 21 08:23:18.289568 2026] [security2:error] [pid 411857:tid 412096] [client 20.226.60.151:56872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/x.php"] [unique_id "al9Wpi7ynBpLeKYztQPo0wAAAGs"]
[Tue Jul 21 08:23:18.365920 2026] [autoindex:error] [pid 419508:tid 419741] [client 20.151.10.161:50776] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:18.398117 2026] [security2:error] [pid 411857:tid 419467] [remote 62.60.130.128:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "caetanodemoraeszanga1751206926735.0711679.meusitehostgator.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9Wpi7ynBpLeKYztQPo1QAAH5U"]
[Tue Jul 21 08:23:18.403278 2026] [security2:error] [pid 419508:tid 419711] [client 4.194.217.15:1712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/403.php"] [unique_id "al9WplcagwCeNbomjVsMFgAAAdg"]
[Tue Jul 21 08:23:18.484756 2026] [security2:error] [pid 419508:tid 419668] [client 20.226.60.151:60623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/122.php"] [unique_id "al9WplcagwCeNbomjVsMGAAAAa0"]
[Tue Jul 21 08:23:18.640692 2026] [security2:error] [pid 419508:tid 419671] [client 20.151.10.161:50776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/file5.php"] [unique_id "al9WplcagwCeNbomjVsMGQAAAbA"]
[Tue Jul 21 08:23:18.674967 2026] [security2:error] [pid 418108:tid 418156] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wpg0cxofL2J1zwYrEUQABQC0"]
[Tue Jul 21 08:23:18.675100 2026] [security2:error] [pid 418108:tid 418294] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wpg0cxofL2J1zwYrEUQABQC0"]
[Tue Jul 21 08:23:18.692648 2026] [security2:error] [pid 419508:tid 419681] [client 20.151.10.161:37576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/biufile.php"] [unique_id "al9WplcagwCeNbomjVsMGgAAAbo"]
[Tue Jul 21 08:23:18.708538 2026] [security2:error] [pid 419508:tid 419759] [client 223.181.60.88:26849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WplcagwCeNbomjVsMGwAAAgc"]
[Tue Jul 21 08:23:18.709421 2026] [security2:error] [pid 419508:tid 419759] [client 223.181.60.88:26849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WplcagwCeNbomjVsMGwAAAgc"]
[Tue Jul 21 08:23:18.854744 2026] [security2:error] [pid 419508:tid 419669] [client 151.63.71.144:53896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WplcagwCeNbomjVsMHgAAAa4"]
[Tue Jul 21 08:23:18.854869 2026] [security2:error] [pid 419508:tid 419669] [client 151.63.71.144:53896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WplcagwCeNbomjVsMHgAAAa4"]
[Tue Jul 21 08:23:18.953428 2026] [security2:error] [pid 411857:tid 412115] [client 20.151.10.161:51174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/file.php"] [unique_id "al9Wpi7ynBpLeKYztQPo3QAAAH4"]
[Tue Jul 21 08:23:18.973139 2026] [security2:error] [pid 419508:tid 419675] [client 20.220.225.223:58932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9WplcagwCeNbomjVsMHwAAAbQ"]
[Tue Jul 21 08:23:19.107201 2026] [security2:error] [pid 418108:tid 418321] [client 117.213.202.34:64906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wpw0cxofL2J1zwYrEUgAAAVs"]
[Tue Jul 21 08:23:19.107361 2026] [security2:error] [pid 418108:tid 418321] [client 117.213.202.34:64906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wpw0cxofL2J1zwYrEUgAAAVs"]
[Tue Jul 21 08:23:19.121385 2026] [security2:error] [pid 419508:tid 419662] [client 20.151.10.161:37518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wpconf.php"] [unique_id "al9Wp1cagwCeNbomjVsMIAAAAac"]
[Tue Jul 21 08:23:19.317379 2026] [security2:error] [pid 419508:tid 419751] [client 20.151.10.161:50777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/aa2.php"] [unique_id "al9Wp1cagwCeNbomjVsMJAAAAf8"]
[Tue Jul 21 08:23:19.318747 2026] [security2:error] [pid 419508:tid 419680] [client 20.226.60.151:56951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/155.php"] [unique_id "al9Wp1cagwCeNbomjVsMJQAAAbk"]
[Tue Jul 21 08:23:19.339542 2026] [autoindex:error] [pid 419508:tid 419762] [client 20.206.105.145:20176] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:19.366313 2026] [security2:error] [pid 419508:tid 419709] [client 20.206.105.145:20176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/footer.php"] [unique_id "al9Wp1cagwCeNbomjVsMJgAAAdY"]
[Tue Jul 21 08:23:19.463886 2026] [security2:error] [pid 419508:tid 419648] [client 20.151.10.161:37456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/mosty.php"] [unique_id "al9Wp1cagwCeNbomjVsMKgAAAZk"]
[Tue Jul 21 08:23:19.518203 2026] [security2:error] [pid 419508:tid 419755] [client 4.194.217.15:4548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/404.php"] [unique_id "al9Wp1cagwCeNbomjVsMKwAAAgM"]
[Tue Jul 21 08:23:19.627567 2026] [security2:error] [pid 419508:tid 419659] [client 152.59.34.51:64874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Wp1cagwCeNbomjVsMLAAAAaQ"]
[Tue Jul 21 08:23:19.627678 2026] [security2:error] [pid 419508:tid 419659] [client 152.59.34.51:64874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Wp1cagwCeNbomjVsMLAAAAaQ"]
[Tue Jul 21 08:23:19.702217 2026] [security2:error] [pid 411857:tid 412004] [client 74.249.245.134:50600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/403.php"] [unique_id "al9Wpy7ynBpLeKYztQPo6AAAAA8"]
[Tue Jul 21 08:23:19.716435 2026] [security2:error] [pid 419508:tid 419708] [client 87.116.180.198:27303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.180.116.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wp1cagwCeNbomjVsMLQAAAdU"]
[Tue Jul 21 08:23:19.719127 2026] [security2:error] [pid 419508:tid 419708] [client 87.116.180.198:27303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tecnoturbo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wp1cagwCeNbomjVsMLQAAAdU"]
[Tue Jul 21 08:23:19.729138 2026] [security2:error] [pid 411857:tid 411990] [client 20.226.60.151:56834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/ops.php"] [unique_id "al9Wpy7ynBpLeKYztQPo6QAAAAE"]
[Tue Jul 21 08:23:19.760186 2026] [security2:error] [pid 411857:tid 412061] [client 20.151.10.161:37575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/dejavu.php"] [unique_id "al9Wpy7ynBpLeKYztQPo6gAAAEg"]
[Tue Jul 21 08:23:19.761491 2026] [security2:error] [pid 419508:tid 419750] [client 20.151.10.161:51762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/ccou.php"] [unique_id "al9Wp1cagwCeNbomjVsMLgAAAf4"]
[Tue Jul 21 08:23:19.767304 2026] [security2:error] [pid 419508:tid 419719] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Wp1cagwCeNbomjVsMIgAAAeA"]
[Tue Jul 21 08:23:19.864537 2026] [security2:error] [pid 419508:tid 419634] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wp1cagwCeNbomjVsMMAABxX0"]
[Tue Jul 21 08:23:19.864714 2026] [security2:error] [pid 419508:tid 419692] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wp1cagwCeNbomjVsMMAABxX0"]
[Tue Jul 21 08:23:20.053510 2026] [security2:error] [pid 419508:tid 419665] [client 20.226.60.151:56887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/file31.php"] [unique_id "al9WqFcagwCeNbomjVsMNAAAAao"]
[Tue Jul 21 08:23:20.072707 2026] [security2:error] [pid 411857:tid 412100] [client 20.151.10.161:37620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/aaf.php"] [unique_id "al9WqC7ynBpLeKYztQPo8QAAAG8"]
[Tue Jul 21 08:23:20.226453 2026] [security2:error] [pid 419508:tid 419729] [client 185.8.106.219:42466] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "supremaservices.net"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9WqFcagwCeNbomjVsMOAAAAeo"]
[Tue Jul 21 08:23:20.242419 2026] [security2:error] [pid 419508:tid 419765] [client 195.49.128.211:56753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WqFcagwCeNbomjVsMOQAAAg0"]
[Tue Jul 21 08:23:20.242522 2026] [security2:error] [pid 419508:tid 419765] [client 195.49.128.211:56753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WqFcagwCeNbomjVsMOQAAAg0"]
[Tue Jul 21 08:23:20.299753 2026] [security2:error] [pid 419508:tid 419734] [client 20.151.10.161:50769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/dr.php"] [unique_id "al9WqFcagwCeNbomjVsMOgAAAe8"]
[Tue Jul 21 08:23:20.325657 2026] [security2:error] [pid 419508:tid 419751] [client 20.226.60.151:56916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/file6.php"] [unique_id "al9WqFcagwCeNbomjVsMPAAAAf8"]
[Tue Jul 21 08:23:20.351588 2026] [security2:error] [pid 411857:tid 412029] [client 20.151.10.161:37450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/term.php"] [unique_id "al9WqC7ynBpLeKYztQPo9AAAACg"]
[Tue Jul 21 08:23:20.497908 2026] [security2:error] [pid 411857:tid 419448] [remote 185.8.106.219:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "expertemrecheios.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9WqC7ynBpLeKYztQPo-gAAB4M"]
[Tue Jul 21 08:23:20.563994 2026] [security2:error] [pid 419508:tid 419663] [client 4.194.217.15:4199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/4pjcpmfsd8b.php"] [unique_id "al9WqFcagwCeNbomjVsMPwAAAag"]
[Tue Jul 21 08:23:20.606878 2026] [security2:error] [pid 419508:tid 419543] [remote 216.73.216.184:6076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemape.xml"] [unique_id "al9WqFcagwCeNbomjVsMQQACBiI"]
[Tue Jul 21 08:23:20.642430 2026] [security2:error] [pid 418108:tid 418357] [client 20.151.10.161:37608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/ha.php"] [unique_id "al9WqA0cxofL2J1zwYrEVwAAAX8"]
[Tue Jul 21 08:23:20.673521 2026] [security2:error] [pid 419508:tid 419755] [client 20.151.10.161:51158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/file31.php"] [unique_id "al9WqFcagwCeNbomjVsMQwAAAgM"]
[Tue Jul 21 08:23:20.674799 2026] [security2:error] [pid 419508:tid 419576] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9WqFcagwCeNbomjVsMRAABkkM"]
[Tue Jul 21 08:23:20.674943 2026] [security2:error] [pid 419508:tid 419641] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9WqFcagwCeNbomjVsMRAABkkM"]
[Tue Jul 21 08:23:20.820821 2026] [security2:error] [pid 419508:tid 419672] [client 20.226.60.151:60639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/mds.php"] [unique_id "al9WqFcagwCeNbomjVsMRwAAAbE"]
[Tue Jul 21 08:23:20.866172 2026] [security2:error] [pid 418108:tid 418340] [client 61.1.167.83:53768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WqA0cxofL2J1zwYrEWAAAAW4"]
[Tue Jul 21 08:23:20.866378 2026] [security2:error] [pid 418108:tid 418340] [client 61.1.167.83:53768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WqA0cxofL2J1zwYrEWAAAAW4"]
[Tue Jul 21 08:23:20.933660 2026] [security2:error] [pid 419508:tid 419736] [client 20.151.10.161:37611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/hur.php"] [unique_id "al9WqFcagwCeNbomjVsMSwAAAfE"]
[Tue Jul 21 08:23:20.994495 2026] [security2:error] [pid 419508:tid 419707] [client 14.245.224.124:62489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WqFcagwCeNbomjVsMTgAAAdQ"]
[Tue Jul 21 08:23:20.994607 2026] [security2:error] [pid 419508:tid 419707] [client 14.245.224.124:62489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WqFcagwCeNbomjVsMTgAAAdQ"]
[Tue Jul 21 08:23:21.030560 2026] [security2:error] [pid 419508:tid 419703] [client 185.8.106.219:56370] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.supremaservices.net"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9WqVcagwCeNbomjVsMTwAAAdA"]
[Tue Jul 21 08:23:21.100306 2026] [security2:error] [pid 411857:tid 411911] [remote 185.8.106.219:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "expertemrecheios.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9WqS7ynBpLeKYztQPpAgAADTQ"], referer: http://expertemrecheios.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Tue Jul 21 08:23:21.124693 2026] [autoindex:error] [pid 419508:tid 419741] [client 20.226.60.151:0] AH01276: Cannot serve directory /home3/cur37674/osantotchay.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:21.134491 2026] [security2:error] [pid 419508:tid 419726] [client 20.151.10.161:51719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/file6.php"] [unique_id "al9WqVcagwCeNbomjVsMUwAAAec"]
[Tue Jul 21 08:23:21.139749 2026] [security2:error] [pid 418108:tid 418274] [client 20.226.60.151:56936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/adminfuns.php"] [unique_id "al9WqQ0cxofL2J1zwYrEWwAAASw"]
[Tue Jul 21 08:23:21.213068 2026] [security2:error] [pid 419508:tid 419660] [client 20.151.10.161:37476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/h02ugyh.php"] [unique_id "al9WqVcagwCeNbomjVsMVAAAAaU"]
[Tue Jul 21 08:23:21.310510 2026] [security2:error] [pid 411857:tid 411933] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WqS7ynBpLeKYztQPpCAAAQEo"]
[Tue Jul 21 08:23:21.310996 2026] [security2:error] [pid 411857:tid 412053] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WqS7ynBpLeKYztQPpCAAAQEo"]
[Tue Jul 21 08:23:21.370020 2026] [security2:error] [pid 411857:tid 412020] [client 20.226.60.151:56867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/goods.php"] [unique_id "al9WqS7ynBpLeKYztQPpCgAAAB8"]
[Tue Jul 21 08:23:21.406958 2026] [security2:error] [pid 411857:tid 419457] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/phpinfo.php"] [unique_id "al9WqS7ynBpLeKYztQPpCwAAXYs"]
[Tue Jul 21 08:23:21.514466 2026] [security2:error] [pid 419508:tid 419713] [client 20.151.10.161:51733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/file15.php"] [unique_id "al9WqVcagwCeNbomjVsMWAAAAdo"]
[Tue Jul 21 08:23:21.539823 2026] [security2:error] [pid 411857:tid 412099] [client 20.151.10.161:37631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/seiso.php"] [unique_id "al9WqS7ynBpLeKYztQPpDwAAAG4"]
[Tue Jul 21 08:23:21.555739 2026] [security2:error] [pid 411857:tid 412021] [client 202.179.75.202:60224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WqS7ynBpLeKYztQPpEAAAACA"]
[Tue Jul 21 08:23:21.555869 2026] [security2:error] [pid 411857:tid 412021] [client 202.179.75.202:60224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WqS7ynBpLeKYztQPpEAAAACA"]
[Tue Jul 21 08:23:21.595136 2026] [security2:error] [pid 419508:tid 419612] [remote 185.8.106.219:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.expertemrecheios.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9WqVcagwCeNbomjVsMWgAB5mc"]
[Tue Jul 21 08:23:21.623682 2026] [security2:error] [pid 419508:tid 419756] [client 4.194.217.15:4550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/666.php"] [unique_id "al9WqVcagwCeNbomjVsMXAAAAgQ"]
[Tue Jul 21 08:23:21.686919 2026] [security2:error] [pid 411857:tid 411937] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/portal/.env"] [unique_id "al9WqS7ynBpLeKYztQPpEQAAZU4"]
[Tue Jul 21 08:23:21.724307 2026] [security2:error] [pid 419508:tid 419658] [client 20.226.60.151:63302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/100.php"] [unique_id "al9WqVcagwCeNbomjVsMXgAAAaM"]
[Tue Jul 21 08:23:21.731695 2026] [security2:error] [pid 419508:tid 419716] [client 150.129.202.39:65158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WqVcagwCeNbomjVsMYAAAAd0"]
[Tue Jul 21 08:23:21.731871 2026] [security2:error] [pid 419508:tid 419716] [client 150.129.202.39:65158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WqVcagwCeNbomjVsMYAAAAd0"]
[Tue Jul 21 08:23:21.735453 2026] [security2:error] [pid 419508:tid 419647] [client 74.249.245.134:45382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.roanalacerda.com.br"] [uri "/api.php"] [unique_id "al9WqVcagwCeNbomjVsMYQAAAZg"]
[Tue Jul 21 08:23:21.862635 2026] [security2:error] [pid 419508:tid 419760] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WqVcagwCeNbomjVsMVQAAAgg"]
[Tue Jul 21 08:23:21.898055 2026] [security2:error] [pid 419508:tid 419751] [client 20.151.10.161:51150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/jp.php"] [unique_id "al9WqVcagwCeNbomjVsMYgAAAf8"]
[Tue Jul 21 08:23:21.904191 2026] [security2:error] [pid 419508:tid 419680] [client 20.151.10.161:37525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/155.php"] [unique_id "al9WqVcagwCeNbomjVsMYwAAAbk"]
[Tue Jul 21 08:23:21.932506 2026] [security2:error] [pid 411857:tid 411882] [remote 185.8.106.219:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "expertemrecheios.com"] [uri "/"] [unique_id "al9WqS7ynBpLeKYztQPpFgAAOhc"]
[Tue Jul 21 08:23:21.968457 2026] [security2:error] [pid 411857:tid 411979] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/env/.env"] [unique_id "al9WqS7ynBpLeKYztQPpGAAAKXc"]
[Tue Jul 21 08:23:22.009806 2026] [security2:error] [pid 419508:tid 419640] [client 20.226.60.151:56934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/about.php"] [unique_id "al9WqlcagwCeNbomjVsMZgAAAZE"]
[Tue Jul 21 08:23:22.011934 2026] [security2:error] [pid 419508:tid 419709] [client 20.220.225.223:20866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/cro.php"] [unique_id "al9WqlcagwCeNbomjVsMZwAAAdY"]
[Tue Jul 21 08:23:22.065599 2026] [security2:error] [pid 419508:tid 419721] [client 185.8.106.219:53722] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "supremaservices.net"] [uri "/"] [unique_id "al9WqlcagwCeNbomjVsMaAAAAeI"]
[Tue Jul 21 08:23:22.098062 2026] [security2:error] [pid 411857:tid 412006] [client 74.7.241.131:52714] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "constaraempreendimentos.com.br.ciclododinheiro.com"] [uri "/index.php"] [unique_id "al9WqS7ynBpLeKYztQPpBwAAEUk"]
[Tue Jul 21 08:23:22.178436 2026] [security2:error] [pid 418108:tid 418298] [client 20.197.192.193:52236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/term.php"] [unique_id "al9Wqg0cxofL2J1zwYrEXgAAAUQ"]
[Tue Jul 21 08:23:22.240121 2026] [security2:error] [pid 419508:tid 419650] [client 20.226.60.151:56838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/about.php"] [unique_id "al9WqlcagwCeNbomjVsMbAAAAZs"]
[Tue Jul 21 08:23:22.280324 2026] [security2:error] [pid 419508:tid 419642] [client 20.151.10.161:50760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/f35.php"] [unique_id "al9WqlcagwCeNbomjVsMbgAAAZM"]
[Tue Jul 21 08:23:22.282506 2026] [security2:error] [pid 411857:tid 411923] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/api/.env"] [unique_id "al9Wqi7ynBpLeKYztQPpHAAAU0A"]
[Tue Jul 21 08:23:22.288145 2026] [security2:error] [pid 419508:tid 419750] [client 20.220.225.223:12584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/wp-editor.php"] [unique_id "al9WqlcagwCeNbomjVsMbwAAAf4"]
[Tue Jul 21 08:23:22.404828 2026] [security2:error] [pid 418108:tid 418362] [client 111.93.58.162:59451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Wqg0cxofL2J1zwYrEXwAAAYQ"]
[Tue Jul 21 08:23:22.405001 2026] [security2:error] [pid 418108:tid 418362] [client 111.93.58.162:59451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Wqg0cxofL2J1zwYrEXwAAAYQ"]
[Tue Jul 21 08:23:22.589885 2026] [security2:error] [pid 419508:tid 419677] [client 20.226.60.151:63298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/admin.php"] [unique_id "al9WqlcagwCeNbomjVsMdAAAAbY"]
[Tue Jul 21 08:23:22.622638 2026] [security2:error] [pid 411857:tid 419460] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/app/.env"] [unique_id "al9Wqi7ynBpLeKYztQPpIgAAY44"]
[Tue Jul 21 08:23:22.724337 2026] [security2:error] [pid 419508:tid 419671] [client 20.151.10.161:51168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-load.php"] [unique_id "al9WqlcagwCeNbomjVsMdQAAAbA"]
[Tue Jul 21 08:23:22.763481 2026] [security2:error] [pid 419508:tid 419646] [client 4.194.217.15:3599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/7.php"] [unique_id "al9WqlcagwCeNbomjVsMdgAAAZc"]
[Tue Jul 21 08:23:22.962704 2026] [security2:error] [pid 411857:tid 411938] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/dev/.env"] [unique_id "al9Wqi7ynBpLeKYztQPpJwAAGk8"]
[Tue Jul 21 08:23:23.003975 2026] [security2:error] [pid 419508:tid 419655] [client 20.226.60.151:62355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/admin.php"] [unique_id "al9Wq1cagwCeNbomjVsMeQAAAaA"]
[Tue Jul 21 08:23:23.079892 2026] [autoindex:error] [pid 419508:tid 419684] [client 20.151.10.161:51145] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:23.093908 2026] [security2:error] [pid 419508:tid 419733] [client 20.220.225.223:20907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/cron-tab.php"] [unique_id "al9Wq1cagwCeNbomjVsMfwAAAe4"]
[Tue Jul 21 08:23:23.265598 2026] [security2:error] [pid 411857:tid 411918] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/new/.env"] [unique_id "al9Wqy7ynBpLeKYztQPpKwAAcTs"]
[Tue Jul 21 08:23:23.310767 2026] [security2:error] [pid 411857:tid 412044] [client 20.151.10.161:37521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/ppp.php"] [unique_id "al9Wqy7ynBpLeKYztQPpLAAAADc"]
[Tue Jul 21 08:23:23.415303 2026] [autoindex:error] [pid 419508:tid 419756] [client 20.151.10.161:51145] AH01276: Cannot serve directory /home1/ofic8899/aizenpower.shop-officialstore.com/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:23.550269 2026] [autoindex:error] [pid 411857:tid 412028] [client 20.206.105.145:20115] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:23.566229 2026] [security2:error] [pid 419508:tid 419639] [client 20.151.10.161:51145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9Wq1cagwCeNbomjVsMhQAAAZA"]
[Tue Jul 21 08:23:23.568094 2026] [security2:error] [pid 411857:tid 412037] [client 20.206.105.145:20115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-content/index.php"] [unique_id "al9Wqy7ynBpLeKYztQPpNQAAADA"]
[Tue Jul 21 08:23:23.631838 2026] [security2:error] [pid 419508:tid 419727] [client 187.125.243.197:55408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Wq1cagwCeNbomjVsMhwAAAeg"]
[Tue Jul 21 08:23:23.631961 2026] [security2:error] [pid 419508:tid 419727] [client 187.125.243.197:55408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Wq1cagwCeNbomjVsMhwAAAeg"]
[Tue Jul 21 08:23:23.817126 2026] [security2:error] [pid 419508:tid 419716] [client 4.194.217.15:1711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/8.php"] [unique_id "al9Wq1cagwCeNbomjVsMigAAAd0"]
[Tue Jul 21 08:23:23.902592 2026] [security2:error] [pid 419508:tid 419709] [client 20.151.10.161:51191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wp-links.php"] [unique_id "al9Wq1cagwCeNbomjVsMiwAAAdY"]
[Tue Jul 21 08:23:24.032311 2026] [security2:error] [pid 419508:tid 419704] [client 115.134.11.136:57899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WrFcagwCeNbomjVsMjQAAAdE"]
[Tue Jul 21 08:23:24.033103 2026] [security2:error] [pid 419508:tid 419704] [client 115.134.11.136:57899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WrFcagwCeNbomjVsMjQAAAdE"]
[Tue Jul 21 08:23:24.088521 2026] [security2:error] [pid 419508:tid 419663] [client 20.226.60.151:56881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/themes.php"] [unique_id "al9WrFcagwCeNbomjVsMjgAAAag"]
[Tue Jul 21 08:23:24.127877 2026] [security2:error] [pid 411857:tid 411998] [client 154.208.47.42:64842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.47.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WrC7ynBpLeKYztQPpQAAAAAk"]
[Tue Jul 21 08:23:24.128072 2026] [security2:error] [pid 411857:tid 411998] [client 154.208.47.42:64842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fit4me.store"] [uri "/xmlrpc.php"] [unique_id "al9WrC7ynBpLeKYztQPpQAAAAAk"]
[Tue Jul 21 08:23:24.129095 2026] [security2:error] [pid 419508:tid 419588] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WrFcagwCeNbomjVsMkQABmU8"]
[Tue Jul 21 08:23:24.129271 2026] [security2:error] [pid 419508:tid 419648] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WrFcagwCeNbomjVsMkQABmU8"]
[Tue Jul 21 08:23:24.304702 2026] [security2:error] [pid 411857:tid 412039] [client 20.220.225.223:20920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/koiy.php"] [unique_id "al9WrC7ynBpLeKYztQPpRwAAADI"]
[Tue Jul 21 08:23:24.322391 2026] [security2:error] [pid 411857:tid 412093] [client 20.197.192.193:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/ah25.php"] [unique_id "al9WrC7ynBpLeKYztQPpSgAAAGg"]
[Tue Jul 21 08:23:24.358776 2026] [security2:error] [pid 411857:tid 411877] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WrC7ynBpLeKYztQPpTAAAYRI"]
[Tue Jul 21 08:23:24.359715 2026] [security2:error] [pid 411857:tid 412086] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WrC7ynBpLeKYztQPpTAAAYRI"]
[Tue Jul 21 08:23:24.386603 2026] [security2:error] [pid 411857:tid 412017] [client 20.220.225.223:58934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9WrC7ynBpLeKYztQPpTQAAABw"]
[Tue Jul 21 08:23:24.391164 2026] [security2:error] [pid 411857:tid 412087] [client 20.151.10.161:51758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/solo1.php"] [unique_id "al9WrC7ynBpLeKYztQPpTgAAAGI"]
[Tue Jul 21 08:23:24.414298 2026] [security2:error] [pid 419508:tid 419762] [client 152.58.32.157:22131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.32.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthsmart.shop"] [uri "/xmlrpc.php"] [unique_id "al9WrFcagwCeNbomjVsMkgAAAgo"]
[Tue Jul 21 08:23:24.414436 2026] [security2:error] [pid 419508:tid 419762] [client 152.58.32.157:22131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthsmart.shop"] [uri "/xmlrpc.php"] [unique_id "al9WrFcagwCeNbomjVsMkgAAAgo"]
[Tue Jul 21 08:23:24.460313 2026] [autoindex:error] [pid 411857:tid 412067] [client 20.226.60.151:0] AH01276: Cannot serve directory /home3/cur37674/osantotchay.com.br/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:24.465389 2026] [security2:error] [pid 419508:tid 419754] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Wq1cagwCeNbomjVsMjAAAAgI"]
[Tue Jul 21 08:23:24.501440 2026] [security2:error] [pid 411857:tid 412014] [client 20.226.60.151:63329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/.well-known/about.php"] [unique_id "al9WrC7ynBpLeKYztQPpVgAAABk"]
[Tue Jul 21 08:23:24.673693 2026] [security2:error] [pid 418108:tid 418287] [client 20.226.60.151:56840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9WrA0cxofL2J1zwYrEZwAAATk"]
[Tue Jul 21 08:23:24.701643 2026] [security2:error] [pid 419508:tid 419745] [client 20.151.10.161:50783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/sixxis.php"] [unique_id "al9WrFcagwCeNbomjVsMmgAAAfk"]
[Tue Jul 21 08:23:24.801846 2026] [security2:error] [pid 419508:tid 419651] [client 20.226.60.151:56871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/wefile.php"] [unique_id "al9WrFcagwCeNbomjVsMngAAAZw"]
[Tue Jul 21 08:23:24.862139 2026] [security2:error] [pid 411857:tid 412072] [client 4.194.217.15:4141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/87.php"] [unique_id "al9WrC7ynBpLeKYztQPpXAAAAFM"]
[Tue Jul 21 08:23:24.996414 2026] [security2:error] [pid 418108:tid 418341] [client 20.151.10.161:51146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/2P.update.php"] [unique_id "al9WrA0cxofL2J1zwYrEaAAAAW8"]
[Tue Jul 21 08:23:25.264964 2026] [security2:error] [pid 419508:tid 419735] [client 20.220.225.223:20873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/hp2.php"] [unique_id "al9WrVcagwCeNbomjVsMowAAAfA"]
[Tue Jul 21 08:23:25.341557 2026] [security2:error] [pid 418108:tid 418328] [client 20.151.10.161:51774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/a.php"] [unique_id "al9WrQ0cxofL2J1zwYrEbAAAAWI"]
[Tue Jul 21 08:23:25.470399 2026] [security2:error] [pid 419508:tid 419731] [client 20.226.60.151:56836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9WrVcagwCeNbomjVsMpwAAAew"]
[Tue Jul 21 08:23:25.594763 2026] [security2:error] [pid 411857:tid 411928] [remote 68.178.160.25:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naldoinvest.com.br"] [uri "/wp-login.php"] [unique_id "al9WrS7ynBpLeKYztQPpZQAAJkU"]
[Tue Jul 21 08:23:25.624870 2026] [security2:error] [pid 419508:tid 419733] [client 20.151.10.161:51155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/k.php"] [unique_id "al9WrVcagwCeNbomjVsMqQAAAe4"]
[Tue Jul 21 08:23:25.662602 2026] [security2:error] [pid 419508:tid 419702] [client 20.226.60.151:60578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-blink.php"] [unique_id "al9WrVcagwCeNbomjVsMqgAAAc8"]
[Tue Jul 21 08:23:25.748883 2026] [security2:error] [pid 411857:tid 412012] [client 152.58.32.157:18348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.32.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthsmart.shop"] [uri "/xmlrpc.php"] [unique_id "al9WrS7ynBpLeKYztQPpagAAABc"]
[Tue Jul 21 08:23:25.748987 2026] [security2:error] [pid 411857:tid 412012] [client 152.58.32.157:18348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthsmart.shop"] [uri "/xmlrpc.php"] [unique_id "al9WrS7ynBpLeKYztQPpagAAABc"]
[Tue Jul 21 08:23:25.816703 2026] [security2:error] [pid 411857:tid 412043] [client 128.127.105.184:40006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9WrS7ynBpLeKYztQPpbAAAADY"]
[Tue Jul 21 08:23:25.816788 2026] [security2:error] [pid 411857:tid 412043] [client 128.127.105.184:40006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9WrS7ynBpLeKYztQPpbAAAADY"]
[Tue Jul 21 08:23:25.897282 2026] [security2:error] [pid 419508:tid 419652] [client 4.194.217.15:4188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/99.php"] [unique_id "al9WrVcagwCeNbomjVsMrAAAAZ0"]
[Tue Jul 21 08:23:25.972463 2026] [security2:error] [pid 411857:tid 412058] [client 20.151.10.161:51160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/w.php"] [unique_id "al9WrS7ynBpLeKYztQPpcgAAAEU"]
[Tue Jul 21 08:23:26.071257 2026] [autoindex:error] [pid 411857:tid 412002] [client 20.226.60.151:0] AH01276: Cannot serve directory /home3/cur37674/osantotchay.com.br/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:26.236163 2026] [autoindex:error] [pid 419508:tid 419727] [client 20.226.60.151:56950] AH01276: Cannot serve directory /home3/cur37674/osantotchay.com.br/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:26.302592 2026] [security2:error] [pid 418108:tid 418301] [client 20.151.10.161:51189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/insc.php"] [unique_id "al9Wrg0cxofL2J1zwYrEbgAAAUc"]
[Tue Jul 21 08:23:26.341590 2026] [security2:error] [pid 419508:tid 419716] [client 20.226.60.151:56950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9WrlcagwCeNbomjVsMtQAAAd0"]
[Tue Jul 21 08:23:26.430239 2026] [security2:error] [pid 418108:tid 418359] [client 20.151.10.161:37529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/201.php"] [unique_id "al9Wrg0cxofL2J1zwYrEbwAAAYE"]
[Tue Jul 21 08:23:26.459834 2026] [security2:error] [pid 411857:tid 412062] [client 103.151.46.103:52218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Wri7ynBpLeKYztQPpfQAAAEk"]
[Tue Jul 21 08:23:26.459987 2026] [security2:error] [pid 411857:tid 412062] [client 103.151.46.103:52218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Wri7ynBpLeKYztQPpfQAAAEk"]
[Tue Jul 21 08:23:26.536604 2026] [security2:error] [pid 419508:tid 419647] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WrlcagwCeNbomjVsMsAAAAZg"]
[Tue Jul 21 08:23:26.723918 2026] [security2:error] [pid 411857:tid 412073] [client 20.151.10.161:50761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Wri7ynBpLeKYztQPpgQAAAFQ"]
[Tue Jul 21 08:23:26.941495 2026] [security2:error] [pid 419508:tid 419690] [client 4.194.217.15:12545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/a.php"] [unique_id "al9WrlcagwCeNbomjVsMuwAAAcM"]
[Tue Jul 21 08:23:27.078764 2026] [security2:error] [pid 411857:tid 412020] [client 20.226.60.151:56939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/8.php"] [unique_id "al9Wry7ynBpLeKYztQPpjAAAAB8"]
[Tue Jul 21 08:23:27.119192 2026] [core:alert] [pid 411857:tid 412018] [client 57.141.18.75:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:23:27.241501 2026] [security2:error] [pid 411857:tid 411922] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/_phpinfo.php"] [unique_id "al9Wry7ynBpLeKYztQPpkQAAND8"]
[Tue Jul 21 08:23:27.247870 2026] [security2:error] [pid 411857:tid 412111] [client 20.151.10.161:50800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/u.php"] [unique_id "al9Wry7ynBpLeKYztQPpkgAAAHo"]
[Tue Jul 21 08:23:27.300251 2026] [security2:error] [pid 411857:tid 412092] [client 20.220.225.223:20927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/hp3.php"] [unique_id "al9Wry7ynBpLeKYztQPplQAAAGc"]
[Tue Jul 21 08:23:27.361147 2026] [security2:error] [pid 411857:tid 412112] [client 20.220.225.223:12307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/cro.php"] [unique_id "al9Wry7ynBpLeKYztQPplgAAAHs"]
[Tue Jul 21 08:23:27.385242 2026] [security2:error] [pid 418108:tid 418291] [client 20.226.60.151:56870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Wrw0cxofL2J1zwYrEcwAAAT0"]
[Tue Jul 21 08:23:27.504182 2026] [security2:error] [pid 419508:tid 419651] [client 20.226.60.151:60584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/zc-208.php"] [unique_id "al9Wr1cagwCeNbomjVsMxwAAAZw"]
[Tue Jul 21 08:23:27.545446 2026] [security2:error] [pid 419508:tid 419738] [client 20.151.10.161:51186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/sss.php"] [unique_id "al9Wr1cagwCeNbomjVsMyAAAAfM"]
[Tue Jul 21 08:23:27.836485 2026] [security2:error] [pid 411857:tid 412060] [client 20.151.10.161:50789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/sss.php"] [unique_id "al9Wry7ynBpLeKYztQPpogAAAEc"]
[Tue Jul 21 08:23:27.895958 2026] [security2:error] [pid 418108:tid 418365] [client 3.146.221.110:34350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "serbetoadv.com"] [uri "/robots.txt"] [unique_id "al9Wrw0cxofL2J1zwYrEdQAAAYc"]
[Tue Jul 21 08:23:27.896765 2026] [security2:error] [pid 419508:tid 419689] [client 3.146.221.110:34358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "serbetoadv.com"] [uri "/robots.txt"] [unique_id "al9Wr1cagwCeNbomjVsMywAAAcI"]
[Tue Jul 21 08:23:27.971905 2026] [security2:error] [pid 418108:tid 418253] [client 20.206.105.145:20140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/zoro.php"] [unique_id "al9Wrw0cxofL2J1zwYrEdgAAARc"]
[Tue Jul 21 08:23:27.985016 2026] [security2:error] [pid 411857:tid 412098] [client 4.194.217.15:4211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/a4.php"] [unique_id "al9Wry7ynBpLeKYztQPppAAAAG0"]
[Tue Jul 21 08:23:28.095535 2026] [security2:error] [pid 411857:tid 411954] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/_profiler/phpinfo/info.php"] [unique_id "al9WsC7ynBpLeKYztQPppgAAJl4"]
[Tue Jul 21 08:23:28.133019 2026] [security2:error] [pid 419508:tid 419735] [client 3.146.221.110:44292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "serbetoadv.com"] [uri "/"] [unique_id "al9WsFcagwCeNbomjVsM0QAAAfA"]
[Tue Jul 21 08:23:28.155568 2026] [security2:error] [pid 411857:tid 412025] [client 20.151.10.161:50786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/c.php"] [unique_id "al9WsC7ynBpLeKYztQPppwAAACQ"]
[Tue Jul 21 08:23:28.184414 2026] [security2:error] [pid 419508:tid 419720] [client 3.146.221.110:34372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "serbetoadv.com"] [uri "/ads.txt"] [unique_id "al9WsFcagwCeNbomjVsM0gAAAeE"]
[Tue Jul 21 08:23:28.217592 2026] [security2:error] [pid 411857:tid 411996] [client 109.248.148.246:35696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9WsC7ynBpLeKYztQPpqgAAAAc"]
[Tue Jul 21 08:23:28.217683 2026] [security2:error] [pid 411857:tid 411996] [client 109.248.148.246:35696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9WsC7ynBpLeKYztQPpqgAAAAc"]
[Tue Jul 21 08:23:28.294064 2026] [security2:error] [pid 419508:tid 419669] [client 20.226.60.151:56863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/f6.php"] [unique_id "al9WsFcagwCeNbomjVsM0wAAAa4"]
[Tue Jul 21 08:23:28.451324 2026] [security2:error] [pid 418108:tid 418243] [client 20.151.10.161:51170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/aa.php"] [unique_id "al9WsA0cxofL2J1zwYrEdwAAAQ0"]
[Tue Jul 21 08:23:28.456419 2026] [security2:error] [pid 411857:tid 411878] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/_profiler/phpinfo/phpinfo.php"] [unique_id "al9WsC7ynBpLeKYztQPprwAATBM"]
[Tue Jul 21 08:23:28.622803 2026] [security2:error] [pid 419508:tid 419685] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WsFcagwCeNbomjVsM0AAAAb4"]
[Tue Jul 21 08:23:28.627673 2026] [security2:error] [pid 419508:tid 419713] [client 20.197.192.193:53154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/8.php"] [unique_id "al9WsFcagwCeNbomjVsM2gAAAdo"]
[Tue Jul 21 08:23:28.733277 2026] [security2:error] [pid 411857:tid 412023] [client 20.151.10.161:50755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/100.php"] [unique_id "al9WsC7ynBpLeKYztQPptQAAACI"]
[Tue Jul 21 08:23:29.013263 2026] [security2:error] [pid 411857:tid 411989] [client 3.146.221.110:44298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.serbetoadv.com"] [uri "/"] [unique_id "al9WsS7ynBpLeKYztQPpuwAAAAA"]
[Tue Jul 21 08:23:29.048008 2026] [security2:error] [pid 411857:tid 412022] [client 4.194.217.15:1190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/a7.php"] [unique_id "al9WsS7ynBpLeKYztQPpvAAAACE"]
[Tue Jul 21 08:23:29.052573 2026] [security2:error] [pid 418108:tid 418313] [client 20.151.10.161:50812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/footer.php"] [unique_id "al9WsQ0cxofL2J1zwYrEeQAAAVM"]
[Tue Jul 21 08:23:29.203672 2026] [security2:error] [pid 419508:tid 419729] [client 20.220.225.223:34748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/aa1.php"] [unique_id "al9WsVcagwCeNbomjVsM3wAAAeo"]
[Tue Jul 21 08:23:29.337169 2026] [security2:error] [pid 418108:tid 418347] [client 20.151.10.161:50814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/users.php"] [unique_id "al9WsQ0cxofL2J1zwYrEewAAAXU"]
[Tue Jul 21 08:23:29.340131 2026] [security2:error] [pid 419508:tid 419513] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WsVcagwCeNbomjVsM4QACDQQ"]
[Tue Jul 21 08:23:29.340396 2026] [security2:error] [pid 419508:tid 419765] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WsVcagwCeNbomjVsM4QACDQQ"]
[Tue Jul 21 08:23:29.461182 2026] [security2:error] [pid 419508:tid 419691] [client 20.226.60.151:50141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/sid4.php"] [unique_id "al9WsVcagwCeNbomjVsM4wAAAcQ"]
[Tue Jul 21 08:23:29.657003 2026] [security2:error] [pid 419508:tid 419687] [client 20.151.10.161:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/177.php"] [unique_id "al9WsVcagwCeNbomjVsM6AAAAcA"]
[Tue Jul 21 08:23:29.788063 2026] [security2:error] [pid 411857:tid 412057] [client 117.213.202.34:65438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WsS7ynBpLeKYztQPpywAAAEQ"]
[Tue Jul 21 08:23:29.788185 2026] [security2:error] [pid 411857:tid 412057] [client 117.213.202.34:65438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WsS7ynBpLeKYztQPpywAAAEQ"]
[Tue Jul 21 08:23:29.828409 2026] [security2:error] [pid 418108:tid 418314] [client 223.181.60.88:28071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WsQ0cxofL2J1zwYrEfAAAAVQ"]
[Tue Jul 21 08:23:29.828536 2026] [security2:error] [pid 418108:tid 418314] [client 223.181.60.88:28071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WsQ0cxofL2J1zwYrEfAAAAVQ"]
[Tue Jul 21 08:23:29.857801 2026] [security2:error] [pid 419508:tid 419728] [client 20.226.60.151:56933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/inputs.php"] [unique_id "al9WsVcagwCeNbomjVsM6wAAAek"]
[Tue Jul 21 08:23:29.879268 2026] [security2:error] [pid 411857:tid 411892] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/awstats/.env"] [unique_id "al9WsS7ynBpLeKYztQPpzAAAZyE"]
[Tue Jul 21 08:23:29.925692 2026] [security2:error] [pid 411857:tid 412046] [client 20.220.225.223:12592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/cron-tab.php"] [unique_id "al9WsS7ynBpLeKYztQPp0AAAADk"]
[Tue Jul 21 08:23:29.961363 2026] [security2:error] [pid 411857:tid 412113] [client 152.59.34.51:65335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WsS7ynBpLeKYztQPp0QAAAHw"]
[Tue Jul 21 08:23:29.961482 2026] [security2:error] [pid 411857:tid 412113] [client 152.59.34.51:65335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WsS7ynBpLeKYztQPp0QAAAHw"]
[Tue Jul 21 08:23:29.969504 2026] [security2:error] [pid 411857:tid 411990] [client 20.151.10.161:50801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/config.php"] [unique_id "al9WsS7ynBpLeKYztQPp0gAAAAE"]
[Tue Jul 21 08:23:30.086699 2026] [security2:error] [pid 419508:tid 419653] [client 4.194.217.15:4207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/aa.php"] [unique_id "al9WslcagwCeNbomjVsM7QAAAZ4"]
[Tue Jul 21 08:23:30.226006 2026] [security2:error] [pid 411857:tid 411986] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/conf/.env"] [unique_id "al9Wsi7ynBpLeKYztQPp1wAAL34"]
[Tue Jul 21 08:23:30.263873 2026] [security2:error] [pid 419508:tid 419707] [client 20.206.105.145:20213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/admin.php"] [unique_id "al9WslcagwCeNbomjVsM7gAAAdQ"]
[Tue Jul 21 08:23:30.300235 2026] [security2:error] [pid 418108:tid 418334] [client 20.151.10.161:50798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/gettest.php"] [unique_id "al9Wsg0cxofL2J1zwYrEfwAAAWg"]
[Tue Jul 21 08:23:30.404047 2026] [security2:error] [pid 419508:tid 419556] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WslcagwCeNbomjVsM8QAB4C8"]
[Tue Jul 21 08:23:30.404961 2026] [security2:error] [pid 419508:tid 419719] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WslcagwCeNbomjVsM8QAB4C8"]
[Tue Jul 21 08:23:30.460836 2026] [security2:error] [pid 419508:tid 419708] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WsVcagwCeNbomjVsM7AAAAdU"]
[Tue Jul 21 08:23:30.551427 2026] [autoindex:error] [pid 411857:tid 411993] [client 20.226.60.151:0] AH01276: Cannot serve directory /home2/mar56142/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:30.571596 2026] [security2:error] [pid 411857:tid 412043] [client 20.226.60.151:60616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wmore1.php"] [unique_id "al9Wsi7ynBpLeKYztQPp3QAAADY"]
[Tue Jul 21 08:23:30.612833 2026] [security2:error] [pid 419508:tid 419683] [client 20.151.10.161:51714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/min.php"] [unique_id "al9WslcagwCeNbomjVsM9wAAAbw"]
[Tue Jul 21 08:23:30.726517 2026] [security2:error] [pid 419508:tid 419661] [client 20.226.60.151:63328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/inputs.php"] [unique_id "al9WslcagwCeNbomjVsM_QAAAaY"]
[Tue Jul 21 08:23:30.737309 2026] [security2:error] [pid 419508:tid 419697] [client 20.197.192.193:51957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/red.php"] [unique_id "al9WslcagwCeNbomjVsM_gAAAco"]
[Tue Jul 21 08:23:30.911775 2026] [security2:error] [pid 411857:tid 411994] [client 150.129.202.39:64687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wsi7ynBpLeKYztQPp4QAAAAU"]
[Tue Jul 21 08:23:30.911921 2026] [security2:error] [pid 411857:tid 411994] [client 150.129.202.39:64687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wsi7ynBpLeKYztQPp4QAAAAU"]
[Tue Jul 21 08:23:30.919637 2026] [security2:error] [pid 419508:tid 419665] [client 20.151.10.161:51147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/edorxrr.php"] [unique_id "al9WslcagwCeNbomjVsNAQAAAao"]
[Tue Jul 21 08:23:30.921541 2026] [security2:error] [pid 411857:tid 412024] [client 173.252.95.2:44126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Wsi7ynBpLeKYztQPp4gAAACM"]
[Tue Jul 21 08:23:30.944981 2026] [security2:error] [pid 419508:tid 419671] [client 195.49.128.211:57340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WslcagwCeNbomjVsNAgAAAbA"]
[Tue Jul 21 08:23:30.945085 2026] [security2:error] [pid 419508:tid 419671] [client 195.49.128.211:57340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WslcagwCeNbomjVsNAgAAAbA"]
[Tue Jul 21 08:23:31.115328 2026] [security2:error] [pid 411857:tid 412035] [client 4.194.217.15:1164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/aaa.php"] [unique_id "al9Wsy7ynBpLeKYztQPp5gAAAC4"]
[Tue Jul 21 08:23:31.197591 2026] [security2:error] [pid 419508:tid 419541] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Ws1cagwCeNbomjVsNBwABzyA"]
[Tue Jul 21 08:23:31.197819 2026] [security2:error] [pid 419508:tid 419702] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Ws1cagwCeNbomjVsNBwABzyA"]
[Tue Jul 21 08:23:31.198281 2026] [security2:error] [pid 419508:tid 419639] [client 20.151.10.161:51727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/hur.php"] [unique_id "al9Ws1cagwCeNbomjVsNCAAAAZA"]
[Tue Jul 21 08:23:31.550362 2026] [security2:error] [pid 411857:tid 412033] [client 20.151.10.161:51752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/zoro.php"] [unique_id "al9Wsy7ynBpLeKYztQPp7QAAACw"]
[Tue Jul 21 08:23:31.665434 2026] [security2:error] [pid 418108:tid 418340] [client 20.151.10.161:37543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/ops.php"] [unique_id "al9Wsw0cxofL2J1zwYrEhAAAAW4"]
[Tue Jul 21 08:23:31.700119 2026] [security2:error] [pid 419508:tid 419734] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Ws1cagwCeNbomjVsNCQAAAe8"]
[Tue Jul 21 08:23:31.841710 2026] [security2:error] [pid 411857:tid 412086] [client 20.151.10.161:51165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/coffexium.php"] [unique_id "al9Wsy7ynBpLeKYztQPp8gAAAGE"]
[Tue Jul 21 08:23:31.867065 2026] [security2:error] [pid 418108:tid 418247] [client 14.245.224.124:62967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Wsw0cxofL2J1zwYrEiQAAARE"]
[Tue Jul 21 08:23:31.867159 2026] [security2:error] [pid 418108:tid 418247] [client 14.245.224.124:62967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Wsw0cxofL2J1zwYrEiQAAARE"]
[Tue Jul 21 08:23:31.941955 2026] [security2:error] [pid 418108:tid 418273] [client 20.226.60.151:56883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Wsw0cxofL2J1zwYrEigAAASs"]
[Tue Jul 21 08:23:31.982107 2026] [security2:error] [pid 418108:tid 418147] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9Wsw0cxofL2J1zwYrEiwABLCQ"]
[Tue Jul 21 08:23:31.982247 2026] [security2:error] [pid 418108:tid 418274] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9Wsw0cxofL2J1zwYrEiwABLCQ"]
[Tue Jul 21 08:23:32.211273 2026] [security2:error] [pid 419508:tid 419638] [client 20.226.60.151:60641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/solo1.php"] [unique_id "al9WtFcagwCeNbomjVsNGAAAAY8"]
[Tue Jul 21 08:23:32.212169 2026] [security2:error] [pid 419508:tid 419716] [client 4.194.217.15:12548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/ab.php"] [unique_id "al9WtFcagwCeNbomjVsNGQAAAd0"]
[Tue Jul 21 08:23:32.240152 2026] [security2:error] [pid 419508:tid 419690] [client 20.197.192.193:53128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/fffm.php"] [unique_id "al9WtFcagwCeNbomjVsNGgAAAcM"]
[Tue Jul 21 08:23:32.251891 2026] [security2:error] [pid 419508:tid 419730] [client 20.151.10.161:51721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/app.php"] [unique_id "al9WtFcagwCeNbomjVsNGwAAAes"]
[Tue Jul 21 08:23:32.472246 2026] [security2:error] [pid 411857:tid 412083] [client 202.179.75.202:60700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WtC7ynBpLeKYztQPp_QAAAF4"]
[Tue Jul 21 08:23:32.472404 2026] [security2:error] [pid 411857:tid 412083] [client 202.179.75.202:60700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WtC7ynBpLeKYztQPp_QAAAF4"]
[Tue Jul 21 08:23:32.592722 2026] [security2:error] [pid 419508:tid 419719] [client 20.151.10.161:51712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/core.php"] [unique_id "al9WtFcagwCeNbomjVsNIAAAAeA"]
[Tue Jul 21 08:23:32.608439 2026] [security2:error] [pid 419508:tid 419648] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WtFcagwCeNbomjVsNEwAAAZk"]
[Tue Jul 21 08:23:32.655312 2026] [security2:error] [pid 419508:tid 419650] [client 20.220.225.223:34725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/acew67.php"] [unique_id "al9WtFcagwCeNbomjVsNIQAAAZs"]
[Tue Jul 21 08:23:32.932526 2026] [security2:error] [pid 419508:tid 419684] [client 20.151.10.161:51732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/main.php"] [unique_id "al9WtFcagwCeNbomjVsNJQAAAb0"]
[Tue Jul 21 08:23:32.967419 2026] [security2:error] [pid 418108:tid 418296] [client 14.97.58.74:9501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WtA0cxofL2J1zwYrElQAAAUI"]
[Tue Jul 21 08:23:32.967550 2026] [security2:error] [pid 418108:tid 418296] [client 14.97.58.74:9501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WtA0cxofL2J1zwYrElQAAAUI"]
[Tue Jul 21 08:23:33.259268 2026] [security2:error] [pid 411857:tid 412032] [client 4.194.217.15:4560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/abc.php"] [unique_id "al9WtS7ynBpLeKYztQPqBwAAACs"]
[Tue Jul 21 08:23:33.309218 2026] [security2:error] [pid 411857:tid 412036] [client 20.151.10.161:51192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/init.php"] [unique_id "al9WtS7ynBpLeKYztQPqCAAAAC8"]
[Tue Jul 21 08:23:33.523095 2026] [autoindex:error] [pid 419508:tid 419696] [client 20.226.60.151:0] AH01276: Cannot serve directory /home2/mar56142/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:33.532369 2026] [security2:error] [pid 419508:tid 419735] [client 20.226.60.151:50055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/cong.php"] [unique_id "al9WtVcagwCeNbomjVsNKwAAAfA"]
[Tue Jul 21 08:23:33.608115 2026] [security2:error] [pid 419508:tid 419697] [client 20.151.10.161:51188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/prekel.php"] [unique_id "al9WtVcagwCeNbomjVsNLQAAAco"]
[Tue Jul 21 08:23:33.723900 2026] [proxy:error] [pid 418108:tid 418318] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:23:33.723951 2026] [proxy_http:error] [pid 418108:tid 418318] [client 165.232.128.192:34292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:23:33.724524 2026] [proxy:error] [pid 418108:tid 418318] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:23:33.724545 2026] [proxy_http:error] [pid 418108:tid 418318] [client 165.232.128.192:34292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:23:33.755483 2026] [security2:error] [pid 418108:tid 418245] [client 143.244.57.121:9354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9WtQ0cxofL2J1zwYrEowAAAQ8"]
[Tue Jul 21 08:23:33.756866 2026] [security2:error] [pid 418108:tid 418258] [client 20.197.192.193:53170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/ftde.php"] [unique_id "al9WtQ0cxofL2J1zwYrEpAAAARw"]
[Tue Jul 21 08:23:34.117827 2026] [proxy:error] [pid 411857:tid 412114] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:23:34.117917 2026] [proxy_http:error] [pid 411857:tid 412114] [client 165.232.128.192:34300] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.cromosolucoes.com.br/
[Tue Jul 21 08:23:34.118523 2026] [proxy:error] [pid 411857:tid 412114] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:23:34.118558 2026] [proxy_http:error] [pid 411857:tid 412114] [client 165.232.128.192:34300] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.cromosolucoes.com.br/
[Tue Jul 21 08:23:34.124085 2026] [security2:error] [pid 419508:tid 419658] [client 187.125.243.197:55912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WtlcagwCeNbomjVsNNQAAAaM"]
[Tue Jul 21 08:23:34.124210 2026] [security2:error] [pid 419508:tid 419658] [client 187.125.243.197:55912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WtlcagwCeNbomjVsNNQAAAaM"]
[Tue Jul 21 08:23:34.139849 2026] [security2:error] [pid 411857:tid 412035] [client 20.151.10.161:51197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/0.php"] [unique_id "al9Wti7ynBpLeKYztQPqIAAAAC4"]
[Tue Jul 21 08:23:34.172404 2026] [security2:error] [pid 411857:tid 412059] [client 143.244.57.121:43726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.nextfitjourney.com"] [uri "/xmlrpc.php"] [unique_id "al9Wti7ynBpLeKYztQPqIQAAAEY"]
[Tue Jul 21 08:23:34.388437 2026] [security2:error] [pid 419508:tid 419756] [client 4.194.217.15:4193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/abcd.php"] [unique_id "al9WtlcagwCeNbomjVsNNwAAAgQ"]
[Tue Jul 21 08:23:34.457918 2026] [security2:error] [pid 418108:tid 418350] [client 115.134.11.136:58370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wtg0cxofL2J1zwYrErgAAAXg"]
[Tue Jul 21 08:23:34.458660 2026] [security2:error] [pid 418108:tid 418350] [client 115.134.11.136:58370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wtg0cxofL2J1zwYrErgAAAXg"]
[Tue Jul 21 08:23:34.463483 2026] [security2:error] [pid 419508:tid 419765] [client 20.220.225.223:12563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/koiy.php"] [unique_id "al9WtlcagwCeNbomjVsNOQAAAg0"]
[Tue Jul 21 08:23:34.552985 2026] [security2:error] [pid 419508:tid 419706] [client 20.151.10.161:51718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/BDKR28.php"] [unique_id "al9WtlcagwCeNbomjVsNOwAAAdM"]
[Tue Jul 21 08:23:34.672920 2026] [security2:error] [pid 411857:tid 411938] [remote 51.68.107.159:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "digiterapia.com.br"] [uri "/robots.txt"] [unique_id "al9Wti7ynBpLeKYztQPqKAAAIU8"]
[Tue Jul 21 08:23:34.673113 2026] [security2:error] [pid 411857:tid 412022] [client 51.68.107.159:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "digiterapia.com.br"] [uri "/robots.txt"] [unique_id "al9Wti7ynBpLeKYztQPqKAAAIU8"]
[Tue Jul 21 08:23:34.694527 2026] [security2:error] [pid 419508:tid 419674] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WtlcagwCeNbomjVsNNgAAAbM"]
[Tue Jul 21 08:23:34.883629 2026] [security2:error] [pid 418108:tid 418177] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wtg0cxofL2J1zwYrErwABhUI"]
[Tue Jul 21 08:23:34.883843 2026] [security2:error] [pid 418108:tid 418363] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wtg0cxofL2J1zwYrErwABhUI"]
[Tue Jul 21 08:23:34.906242 2026] [security2:error] [pid 411857:tid 412116] [client 20.151.10.161:51730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/f35.update.php"] [unique_id "al9Wti7ynBpLeKYztQPqLwAAAH8"]
[Tue Jul 21 08:23:34.984084 2026] [proxy:error] [pid 419508:tid 419640] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:23:34.984128 2026] [proxy_http:error] [pid 419508:tid 419640] [client 165.232.128.192:49428] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:23:34.984796 2026] [proxy:error] [pid 419508:tid 419640] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:23:34.984834 2026] [proxy_http:error] [pid 419508:tid 419640] [client 165.232.128.192:49428] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:23:34.985118 2026] [security2:error] [pid 419508:tid 419568] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WtlcagwCeNbomjVsNRAACBTs"]
[Tue Jul 21 08:23:34.985236 2026] [security2:error] [pid 419508:tid 419757] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WtlcagwCeNbomjVsNRAACBTs"]
[Tue Jul 21 08:23:35.016673 2026] [security2:error] [pid 419508:tid 419714] [client 20.226.60.151:56847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9Wt1cagwCeNbomjVsNRgAAAds"]
[Tue Jul 21 08:23:35.020600 2026] [security2:error] [pid 419508:tid 419645] [client 143.244.57.121:43736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Wt1cagwCeNbomjVsNRwAAAZY"]
[Tue Jul 21 08:23:35.059842 2026] [security2:error] [pid 419508:tid 419642] [client 20.220.225.223:34736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/bscclapb.php"] [unique_id "al9Wt1cagwCeNbomjVsNSAAAAZM"]
[Tue Jul 21 08:23:35.174538 2026] [autoindex:error] [pid 419508:tid 419707] [client 20.226.60.151:0] AH01276: Cannot serve directory /home2/mar56142/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:35.181235 2026] [security2:error] [pid 411857:tid 411918] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/cron/.env"] [unique_id "al9Wty7ynBpLeKYztQPqMQAAQzs"]
[Tue Jul 21 08:23:35.184053 2026] [security2:error] [pid 418108:tid 418243] [client 20.226.60.151:50054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/public/css.php"] [unique_id "al9Wtw0cxofL2J1zwYrEsgAAAQ0"]
[Tue Jul 21 08:23:35.197080 2026] [security2:error] [pid 411857:tid 412018] [client 20.151.10.161:51770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/f900.php"] [unique_id "al9Wty7ynBpLeKYztQPqMwAAAB0"]
[Tue Jul 21 08:23:35.418991 2026] [security2:error] [pid 411857:tid 412087] [client 4.194.217.15:10001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/about.php"] [unique_id "al9Wty7ynBpLeKYztQPqNgAAAGI"]
[Tue Jul 21 08:23:35.447795 2026] [security2:error] [pid 419508:tid 419666] [client 143.244.57.121:43742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Wt1cagwCeNbomjVsNTQAAAas"]
[Tue Jul 21 08:23:35.526150 2026] [security2:error] [pid 411857:tid 412030] [client 20.151.10.161:50799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/xmrl.php"] [unique_id "al9Wty7ynBpLeKYztQPqOwAAACk"]
[Tue Jul 21 08:23:35.696677 2026] [security2:error] [pid 419508:tid 419596] [remote 217.182.128.41:58050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Wt1cagwCeNbomjVsNUwAB_lc"]
[Tue Jul 21 08:23:35.879784 2026] [security2:error] [pid 418108:tid 418268] [client 143.244.57.121:43756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Wtw0cxofL2J1zwYrEtgAAASY"]
[Tue Jul 21 08:23:35.905755 2026] [security2:error] [pid 419508:tid 419735] [client 20.151.10.161:42952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/memberfuns.php"] [unique_id "al9Wt1cagwCeNbomjVsNVwAAAfA"]
[Tue Jul 21 08:23:35.955588 2026] [security2:error] [pid 419508:tid 419644] [client 20.206.105.145:20111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/greap.php"] [unique_id "al9Wt1cagwCeNbomjVsNWQAAAZU"]
[Tue Jul 21 08:23:36.320177 2026] [security2:error] [pid 418108:tid 418293] [client 143.244.57.121:43760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9WuA0cxofL2J1zwYrEuQAAAT8"]
[Tue Jul 21 08:23:36.361272 2026] [security2:error] [pid 418108:tid 418305] [client 20.151.10.161:51754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/ms.php"] [unique_id "al9WuA0cxofL2J1zwYrEugAAAUs"]
[Tue Jul 21 08:23:36.447058 2026] [security2:error] [pid 419508:tid 419665] [client 4.194.217.15:10040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp-info.php"] [unique_id "al9WuFcagwCeNbomjVsNYwAAAao"]
[Tue Jul 21 08:23:36.552350 2026] [security2:error] [pid 419508:tid 419740] [client 20.220.225.223:20913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/else1.php"] [unique_id "al9WuFcagwCeNbomjVsNZwAAAfU"]
[Tue Jul 21 08:23:36.673979 2026] [security2:error] [pid 419508:tid 419672] [client 20.151.10.161:42983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/zz.php"] [unique_id "al9WuFcagwCeNbomjVsNbAAAAbE"]
[Tue Jul 21 08:23:36.695705 2026] [security2:error] [pid 419508:tid 419564] [remote 43.228.157.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.157.228.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dees.ind.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9WuFcagwCeNbomjVsNbgABwDc"], referer: www.google.com
[Tue Jul 21 08:23:36.703477 2026] [security2:error] [pid 419508:tid 419558] [remote 43.228.157.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.157.228.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dees.ind.br"] [uri "/wp-plain.php"] [unique_id "al9WuFcagwCeNbomjVsNbwAB2zE"], referer: www.google.com
[Tue Jul 21 08:23:36.714497 2026] [security2:error] [pid 419508:tid 419537] [remote 43.228.157.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.157.228.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dees.ind.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9WuFcagwCeNbomjVsNcQAB3Rw"]
[Tue Jul 21 08:23:36.751180 2026] [security2:error] [pid 411857:tid 412089] [client 143.244.57.121:43766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9WuC7ynBpLeKYztQPqUAAAAGQ"]
[Tue Jul 21 08:23:36.852712 2026] [security2:error] [pid 419508:tid 419729] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WuFcagwCeNbomjVsNYAAAAeo"]
[Tue Jul 21 08:23:36.884764 2026] [security2:error] [pid 419508:tid 419613] [remote 43.228.157.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.157.228.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dees.ind.br"] [uri "/rzqyybyf.php"] [unique_id "al9WuFcagwCeNbomjVsNdwAB6Wg"], referer: www.google.com
[Tue Jul 21 08:23:37.006254 2026] [security2:error] [pid 419508:tid 419715] [client 20.220.225.223:12564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/hp2.php"] [unique_id "al9WuVcagwCeNbomjVsNeAAAAdw"]
[Tue Jul 21 08:23:37.123684 2026] [security2:error] [pid 419508:tid 419683] [client 20.151.10.161:50758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/for.php"] [unique_id "al9WuVcagwCeNbomjVsNewAAAbw"]
[Tue Jul 21 08:23:37.185366 2026] [security2:error] [pid 419508:tid 419694] [client 143.244.57.121:43772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9WuVcagwCeNbomjVsNfAAAAcc"]
[Tue Jul 21 08:23:37.229984 2026] [security2:error] [pid 419508:tid 419603] [remote 43.228.157.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.157.228.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dees.ind.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9WuVcagwCeNbomjVsNgAACAV4"], referer: www.google.com
[Tue Jul 21 08:23:37.251150 2026] [security2:error] [pid 411857:tid 412002] [client 20.151.10.161:37475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/ingfo.php"] [unique_id "al9WuS7ynBpLeKYztQPqVwAAAA0"]
[Tue Jul 21 08:23:37.333992 2026] [security2:error] [pid 419508:tid 419746] [client 20.197.192.193:52287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/yup.php"] [unique_id "al9WuVcagwCeNbomjVsNhgAAAfo"]
[Tue Jul 21 08:23:37.408385 2026] [security2:error] [pid 419508:tid 419658] [client 20.151.10.161:51151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/yup.php"] [unique_id "al9WuVcagwCeNbomjVsNhwAAAaM"]
[Tue Jul 21 08:23:37.415610 2026] [security2:error] [pid 419508:tid 419519] [remote 43.228.157.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.157.228.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dees.ind.br"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "al9WuVcagwCeNbomjVsNiAAB2Ao"]
[Tue Jul 21 08:23:37.465859 2026] [security2:error] [pid 419508:tid 419659] [client 159.223.41.76:61823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9WuVcagwCeNbomjVsNiQAAAaQ"]
[Tue Jul 21 08:23:37.570613 2026] [security2:error] [pid 419508:tid 419758] [client 20.226.60.151:56839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/wp-blog.php"] [unique_id "al9WuVcagwCeNbomjVsNjAAAAgY"]
[Tue Jul 21 08:23:37.600902 2026] [security2:error] [pid 419508:tid 419754] [client 143.244.57.121:43776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9WuVcagwCeNbomjVsNjQAAAgI"]
[Tue Jul 21 08:23:37.743080 2026] [security2:error] [pid 418108:tid 418352] [client 47.128.63.15:12430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9WuQ0cxofL2J1zwYrEwAAAAXo"]
[Tue Jul 21 08:23:37.782195 2026] [security2:error] [pid 419508:tid 419730] [client 20.151.10.161:51725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/wpxml.php"] [unique_id "al9WuVcagwCeNbomjVsNlQAAAes"]
[Tue Jul 21 08:23:37.817713 2026] [security2:error] [pid 411857:tid 412042] [client 4.194.217.15:4198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp-links-opml.php"] [unique_id "al9WuS7ynBpLeKYztQPqXwAAADU"]
[Tue Jul 21 08:23:37.931722 2026] [security2:error] [pid 419508:tid 419609] [remote 43.228.157.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.157.228.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dees.ind.br"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al9WuVcagwCeNbomjVsNmQAB-WQ"]
[Tue Jul 21 08:23:38.015157 2026] [security2:error] [pid 411857:tid 412101] [client 143.244.57.121:43790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Wui7ynBpLeKYztQPqYQAAAHA"]
[Tue Jul 21 08:23:38.063750 2026] [security2:error] [pid 418108:tid 418344] [client 20.226.60.151:60579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/output.php"] [unique_id "al9Wug0cxofL2J1zwYrEwgAAAXI"]
[Tue Jul 21 08:23:38.149959 2026] [security2:error] [pid 419508:tid 419694] [client 159.223.41.76:63410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brwmarcas.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WulcagwCeNbomjVsNngAAAcc"]
[Tue Jul 21 08:23:38.430025 2026] [security2:error] [pid 411857:tid 412022] [client 143.244.57.121:43796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Wui7ynBpLeKYztQPqZgAAACE"]
[Tue Jul 21 08:23:38.452260 2026] [security2:error] [pid 418108:tid 418114] [remote 43.228.157.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.157.228.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dees.ind.br"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "al9Wug0cxofL2J1zwYrExgABRAM"]
[Tue Jul 21 08:23:38.480213 2026] [security2:error] [pid 419508:tid 419735] [client 20.151.10.161:51715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/fffm.php"] [unique_id "al9WulcagwCeNbomjVsNowAAAfA"]
[Tue Jul 21 08:23:38.647493 2026] [security2:error] [pid 419508:tid 419538] [remote 43.228.157.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.157.228.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dees.ind.br"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "al9WulcagwCeNbomjVsNqAAB2h0"]
[Tue Jul 21 08:23:38.736070 2026] [autoindex:error] [pid 418108:tid 418281] [client 20.226.60.151:0] AH01276: Cannot serve directory /home3/cur37674/osantotchay.com.br/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:38.750707 2026] [security2:error] [pid 419508:tid 419658] [client 20.220.225.223:20877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/tkikikoko.php"] [unique_id "al9WulcagwCeNbomjVsNrgAAAaM"]
[Tue Jul 21 08:23:38.833495 2026] [security2:error] [pid 419508:tid 419711] [client 20.151.10.161:42944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/gecko.php"] [unique_id "al9WulcagwCeNbomjVsNrwAAAdg"]
[Tue Jul 21 08:23:38.845572 2026] [security2:error] [pid 419508:tid 419756] [client 143.244.57.121:43798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9WulcagwCeNbomjVsNsQAAAgQ"]
[Tue Jul 21 08:23:38.881106 2026] [security2:error] [pid 411857:tid 412091] [client 4.194.217.15:1674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp-links.php"] [unique_id "al9Wui7ynBpLeKYztQPqbAAAAGY"]
[Tue Jul 21 08:23:38.905952 2026] [security2:error] [pid 419508:tid 419696] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WulcagwCeNbomjVsNogAAAck"]
[Tue Jul 21 08:23:38.984722 2026] [security2:error] [pid 419508:tid 419707] [client 61.1.167.83:54328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WulcagwCeNbomjVsNtAAAAdQ"]
[Tue Jul 21 08:23:38.984870 2026] [security2:error] [pid 419508:tid 419707] [client 61.1.167.83:54328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WulcagwCeNbomjVsNtAAAAdQ"]
[Tue Jul 21 08:23:39.063277 2026] [security2:error] [pid 419508:tid 419670] [client 20.206.105.145:20177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/177.php"] [unique_id "al9Wu1cagwCeNbomjVsNtgAAAa8"]
[Tue Jul 21 08:23:39.139650 2026] [security2:error] [pid 419508:tid 419706] [client 103.151.46.103:52733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Wu1cagwCeNbomjVsNuAAAAdM"]
[Tue Jul 21 08:23:39.139759 2026] [security2:error] [pid 419508:tid 419706] [client 103.151.46.103:52733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Wu1cagwCeNbomjVsNuAAAAdM"]
[Tue Jul 21 08:23:39.192131 2026] [security2:error] [pid 419508:tid 419714] [client 159.223.41.76:64346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Wu1cagwCeNbomjVsNugAAAds"]
[Tue Jul 21 08:23:39.200639 2026] [core:error] [pid 419508:tid 419512] [remote 52.167.144.18:17603] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:23:39.200658 2026] [core:error] [pid 419508:tid 419512] [remote 52.167.144.18:17603] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:23:39.234213 2026] [security2:error] [pid 419508:tid 419741] [client 20.151.10.161:37616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/error_log.php"] [unique_id "al9Wu1cagwCeNbomjVsNvAAAAfY"]
[Tue Jul 21 08:23:39.252231 2026] [security2:error] [pid 419508:tid 419656] [client 143.244.57.121:43804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9Wu1cagwCeNbomjVsNvQAAAaE"]
[Tue Jul 21 08:23:39.254697 2026] [security2:error] [pid 419508:tid 419716] [client 20.226.60.151:56833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Wu1cagwCeNbomjVsNvgAAAd0"]
[Tue Jul 21 08:23:39.412958 2026] [security2:error] [pid 418108:tid 418310] [client 20.151.10.161:51149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/a1.php"] [unique_id "al9Wuw0cxofL2J1zwYrEzAAAAVA"]
[Tue Jul 21 08:23:39.660854 2026] [security2:error] [pid 418108:tid 418338] [client 143.244.57.121:43808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9Wuw0cxofL2J1zwYrEzQAAAWw"]
[Tue Jul 21 08:23:39.866315 2026] [security2:error] [pid 411857:tid 412092] [client 159.223.41.76:65495] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Wuy7ynBpLeKYztQPqdAAAAGc"]
[Tue Jul 21 08:23:39.921323 2026] [security2:error] [pid 419508:tid 419757] [client 20.220.225.223:12548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/hp3.php"] [unique_id "al9Wu1cagwCeNbomjVsNyAAAAgU"]
[Tue Jul 21 08:23:39.922529 2026] [security2:error] [pid 411857:tid 412057] [client 4.194.217.15:4555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp-load.php"] [unique_id "al9Wuy7ynBpLeKYztQPqdwAAAEQ"]
[Tue Jul 21 08:23:40.014245 2026] [security2:error] [pid 419508:tid 419725] [client 20.226.60.151:60613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-file-120.php"] [unique_id "al9WvFcagwCeNbomjVsNywAAAeY"]
[Tue Jul 21 08:23:40.036663 2026] [security2:error] [pid 419508:tid 419722] [client 20.151.10.161:50805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/k2.php"] [unique_id "al9WvFcagwCeNbomjVsNzAAAAeM"]
[Tue Jul 21 08:23:40.046646 2026] [security2:error] [pid 419508:tid 419523] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WvFcagwCeNbomjVsNzQACAQ4"]
[Tue Jul 21 08:23:40.046800 2026] [security2:error] [pid 419508:tid 419753] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WvFcagwCeNbomjVsNzQACAQ4"]
[Tue Jul 21 08:23:40.085718 2026] [security2:error] [pid 419508:tid 419673] [client 143.244.57.121:52508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9WvFcagwCeNbomjVsN0AAAAbI"]
[Tue Jul 21 08:23:40.171974 2026] [security2:error] [pid 419508:tid 419766] [client 20.151.10.161:37619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/xenon1337.php"] [unique_id "al9WvFcagwCeNbomjVsN0QAAAg4"]
[Tue Jul 21 08:23:40.405115 2026] [security2:error] [pid 411857:tid 412088] [client 20.151.10.161:51180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/82.php"] [unique_id "al9WvC7ynBpLeKYztQPqfQAAAGM"]
[Tue Jul 21 08:23:40.493434 2026] [security2:error] [pid 419508:tid 419694] [client 117.213.202.34:49588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WvFcagwCeNbomjVsN1QAAAcc"]
[Tue Jul 21 08:23:40.493572 2026] [security2:error] [pid 419508:tid 419694] [client 117.213.202.34:49588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WvFcagwCeNbomjVsN1QAAAcc"]
[Tue Jul 21 08:23:40.501640 2026] [security2:error] [pid 419508:tid 419740] [client 143.244.57.121:52510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9WvFcagwCeNbomjVsN1wAAAfU"]
[Tue Jul 21 08:23:40.518304 2026] [security2:error] [pid 411857:tid 412001] [client 20.197.192.193:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/jj.php"] [unique_id "al9WvC7ynBpLeKYztQPqfwAAAAw"]
[Tue Jul 21 08:23:40.524568 2026] [security2:error] [pid 418108:tid 418245] [client 20.226.60.151:60545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/special.php"] [unique_id "al9WvA0cxofL2J1zwYrEzgAAAQ8"]
[Tue Jul 21 08:23:40.554468 2026] [security2:error] [pid 411857:tid 412041] [client 159.223.41.76:49901] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9WvC7ynBpLeKYztQPqgAAAADQ"]
[Tue Jul 21 08:23:40.669422 2026] [security2:error] [pid 419508:tid 419727] [client 20.151.10.161:37592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/test11.php"] [unique_id "al9WvFcagwCeNbomjVsN2QAAAeg"]
[Tue Jul 21 08:23:40.678796 2026] [security2:error] [pid 419508:tid 419714] [client 20.220.225.223:20885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/wp-Blogs.php"] [unique_id "al9WvFcagwCeNbomjVsN2gAAAds"]
[Tue Jul 21 08:23:40.729754 2026] [proxy:error] [pid 419508:tid 419750] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:23:40.729830 2026] [proxy_http:error] [pid 419508:tid 419750] [client 165.232.128.192:59464] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.cromosolucoes.com.br/
[Tue Jul 21 08:23:40.730351 2026] [proxy:error] [pid 419508:tid 419750] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:23:40.730374 2026] [proxy_http:error] [pid 419508:tid 419750] [client 165.232.128.192:59464] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.cromosolucoes.com.br/
[Tue Jul 21 08:23:40.736500 2026] [security2:error] [pid 419508:tid 419656] [client 20.151.10.161:51731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/config.json.php"] [unique_id "al9WvFcagwCeNbomjVsN3AAAAaE"]
[Tue Jul 21 08:23:40.744901 2026] [security2:error] [pid 419508:tid 419667] [client 152.59.34.51:49404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WvFcagwCeNbomjVsN3gAAAaw"]
[Tue Jul 21 08:23:40.744987 2026] [security2:error] [pid 419508:tid 419667] [client 152.59.34.51:49404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9WvFcagwCeNbomjVsN3gAAAaw"]
[Tue Jul 21 08:23:40.749985 2026] [core:error] [pid 418108:tid 418142] [remote 2.57.122.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:23:40.750011 2026] [core:error] [pid 418108:tid 418142] [remote 2.57.122.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:23:40.871540 2026] [security2:error] [pid 411857:tid 419446] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WvC7ynBpLeKYztQPqiQAAL4E"]
[Tue Jul 21 08:23:40.871729 2026] [security2:error] [pid 411857:tid 412036] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WvC7ynBpLeKYztQPqiQAAL4E"]
[Tue Jul 21 08:23:40.925255 2026] [security2:error] [pid 411857:tid 412037] [client 143.244.57.121:52522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nextfitjourney.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9WvC7ynBpLeKYztQPqjgAAADA"]
[Tue Jul 21 08:23:40.964578 2026] [security2:error] [pid 419508:tid 419657] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WvFcagwCeNbomjVsN1gAAAaI"]
[Tue Jul 21 08:23:40.965250 2026] [security2:error] [pid 419508:tid 419745] [client 20.151.10.161:37510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/koala.php"] [unique_id "al9WvFcagwCeNbomjVsN4QAAAfk"]
[Tue Jul 21 08:23:41.026160 2026] [security2:error] [pid 411857:tid 412035] [client 20.220.225.223:12598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/aa1.php"] [unique_id "al9WvS7ynBpLeKYztQPqkwAAAC4"]
[Tue Jul 21 08:23:41.049625 2026] [security2:error] [pid 418108:tid 418348] [client 223.181.60.88:7225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WvQ0cxofL2J1zwYrE0QAAAXY"]
[Tue Jul 21 08:23:41.049960 2026] [security2:error] [pid 418108:tid 418348] [client 223.181.60.88:7225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9WvQ0cxofL2J1zwYrE0QAAAXY"]
[Tue Jul 21 08:23:41.063173 2026] [security2:error] [pid 419508:tid 419699] [client 20.151.10.161:51161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aizenpower.shop-officialstore.com"] [uri "/fpwch.php"] [unique_id "al9WvVcagwCeNbomjVsN4wAAAcw"]
[Tue Jul 21 08:23:41.099682 2026] [security2:error] [pid 419508:tid 419671] [client 20.226.60.151:56952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/ms-edit.php"] [unique_id "al9WvVcagwCeNbomjVsN5AAAAbA"]
[Tue Jul 21 08:23:41.206252 2026] [security2:error] [pid 419508:tid 419758] [client 4.194.217.15:12598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp-login.php"] [unique_id "al9WvVcagwCeNbomjVsN4gAAAgY"]
[Tue Jul 21 08:23:41.243497 2026] [security2:error] [pid 411857:tid 412078] [client 20.151.10.161:37511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/mac.php"] [unique_id "al9WvS7ynBpLeKYztQPqmAAAAFk"]
[Tue Jul 21 08:23:41.245739 2026] [security2:error] [pid 419508:tid 419683] [client 159.223.41.76:50830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9WvVcagwCeNbomjVsN6AAAAbw"]
[Tue Jul 21 08:23:41.354910 2026] [security2:error] [pid 419508:tid 419739] [client 141.255.164.66:33024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "pedido-online.net"] [uri "/"] [unique_id "al9WvVcagwCeNbomjVsN6gAAAfQ"]
[Tue Jul 21 08:23:41.410720 2026] [security2:error] [pid 411857:tid 412042] [client 20.220.225.223:20902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/wp-css.php"] [unique_id "al9WvS7ynBpLeKYztQPqmwAAADU"]
[Tue Jul 21 08:23:41.488906 2026] [security2:error] [pid 418108:tid 418179] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/cron/.env"] [unique_id "al9WvQ0cxofL2J1zwYrE0gABR0Q"]
[Tue Jul 21 08:23:41.491020 2026] [security2:error] [pid 419508:tid 419645] [client 150.129.202.39:64553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WvVcagwCeNbomjVsN7QAAAZY"]
[Tue Jul 21 08:23:41.491136 2026] [security2:error] [pid 419508:tid 419645] [client 150.129.202.39:64553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WvVcagwCeNbomjVsN7QAAAZY"]
[Tue Jul 21 08:23:41.530744 2026] [security2:error] [pid 411857:tid 412021] [client 20.151.10.161:37613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9WvS7ynBpLeKYztQPqngAAACA"]
[Tue Jul 21 08:23:41.648762 2026] [security2:error] [pid 419508:tid 419715] [client 195.49.128.211:57926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WvVcagwCeNbomjVsN8AAAAdw"]
[Tue Jul 21 08:23:41.648928 2026] [security2:error] [pid 419508:tid 419715] [client 195.49.128.211:57926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WvVcagwCeNbomjVsN8AAAAdw"]
[Tue Jul 21 08:23:41.783780 2026] [security2:error] [pid 419508:tid 419546] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9WvVcagwCeNbomjVsN9AABzSU"]
[Tue Jul 21 08:23:41.783893 2026] [security2:error] [pid 419508:tid 419700] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9WvVcagwCeNbomjVsN9AABzSU"]
[Tue Jul 21 08:23:41.933118 2026] [security2:error] [pid 411857:tid 412062] [client 159.223.41.76:51711] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9WvS7ynBpLeKYztQPqogAAAEk"]
[Tue Jul 21 08:23:41.941057 2026] [security2:error] [pid 419508:tid 419711] [client 20.206.105.145:20123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/199.php"] [unique_id "al9WvVcagwCeNbomjVsN9QAAAdg"]
[Tue Jul 21 08:23:42.031442 2026] [security2:error] [pid 411857:tid 412077] [client 14.245.224.124:63432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Wvi7ynBpLeKYztQPqqQAAAFg"]
[Tue Jul 21 08:23:42.031560 2026] [security2:error] [pid 411857:tid 412077] [client 14.245.224.124:63432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Wvi7ynBpLeKYztQPqqQAAAFg"]
[Tue Jul 21 08:23:42.070316 2026] [security2:error] [pid 418108:tid 418117] [remote 20.153.140.50:54616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9Wvg0cxofL2J1zwYrE0wABEwY"]
[Tue Jul 21 08:23:42.074777 2026] [security2:error] [pid 411857:tid 412090] [client 20.151.10.161:37461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wefile.php"] [unique_id "al9Wvi7ynBpLeKYztQPqqwAAAGU"]
[Tue Jul 21 08:23:42.259547 2026] [security2:error] [pid 419508:tid 419670] [client 20.220.225.223:34702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/wp-explorer.php"] [unique_id "al9WvlcagwCeNbomjVsN_AAAAa8"]
[Tue Jul 21 08:23:42.294794 2026] [security2:error] [pid 419508:tid 419756] [client 4.194.217.15:9994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp-mail.php"] [unique_id "al9WvlcagwCeNbomjVsN_gAAAgQ"]
[Tue Jul 21 08:23:42.616910 2026] [autoindex:error] [pid 419508:tid 419652] [client 43.131.36.84:46362] AH01276: Cannot serve directory /home2/luisur31/unimundoconsultoria.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:42.617591 2026] [security2:error] [pid 419508:tid 419737] [client 159.223.41.76:52554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9WvlcagwCeNbomjVsOCQAAAfI"]
[Tue Jul 21 08:23:42.643925 2026] [security2:error] [pid 418108:tid 418363] [client 20.151.10.161:37559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Wvg0cxofL2J1zwYrE2gAAAYU"]
[Tue Jul 21 08:23:42.646289 2026] [security2:error] [pid 419508:tid 419555] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WvlcagwCeNbomjVsOCgABxy4"]
[Tue Jul 21 08:23:42.646430 2026] [security2:error] [pid 419508:tid 419694] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WvlcagwCeNbomjVsOCgABxy4"]
[Tue Jul 21 08:23:42.919633 2026] [security2:error] [pid 411857:tid 411990] [client 20.151.10.161:37581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/2P.php"] [unique_id "al9Wvi7ynBpLeKYztQPqtQAAAAE"]
[Tue Jul 21 08:23:42.978327 2026] [security2:error] [pid 419508:tid 419703] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WvlcagwCeNbomjVsOAwAAAdA"]
[Tue Jul 21 08:23:43.266733 2026] [security2:error] [pid 418108:tid 418263] [client 20.151.10.161:37514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Wvw0cxofL2J1zwYrE2wAAASE"]
[Tue Jul 21 08:23:43.307127 2026] [security2:error] [pid 418108:tid 418311] [client 159.223.41.76:53519] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9Wvw0cxofL2J1zwYrE3QAAAVE"]
[Tue Jul 21 08:23:43.400189 2026] [security2:error] [pid 419508:tid 419680] [client 20.220.225.223:34698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/akismet.php"] [unique_id "al9Wv1cagwCeNbomjVsOHAAAAbk"]
[Tue Jul 21 08:23:43.427926 2026] [security2:error] [pid 419508:tid 419644] [client 4.194.217.15:1695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp-signin.php"] [unique_id "al9Wv1cagwCeNbomjVsOHQAAAZU"]
[Tue Jul 21 08:23:43.560406 2026] [security2:error] [pid 419508:tid 419695] [client 65.21.113.253:46854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Wv1cagwCeNbomjVsOGwAAAcg"]
[Tue Jul 21 08:23:43.620669 2026] [security2:error] [pid 419508:tid 419764] [client 20.151.10.161:37505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Wv1cagwCeNbomjVsOIQAAAgw"]
[Tue Jul 21 08:23:43.815657 2026] [security2:error] [pid 419508:tid 419622] [remote 119.195.102.159:40294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "manual.fernandohipolito.com.br"] [uri "/wp-login.php"] [unique_id "al9WvlcagwCeNbomjVsODgABt3E"]
[Tue Jul 21 08:23:43.915306 2026] [security2:error] [pid 419508:tid 419728] [client 20.151.10.161:37624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/bob.php"] [unique_id "al9Wv1cagwCeNbomjVsOKAAAAek"]
[Tue Jul 21 08:23:43.992751 2026] [security2:error] [pid 419508:tid 419671] [client 159.223.41.76:57361] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Wv1cagwCeNbomjVsOKwAAAbA"]
[Tue Jul 21 08:23:44.089749 2026] [security2:error] [pid 419508:tid 419727] [client 202.179.75.202:47872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WwFcagwCeNbomjVsOLAAAAeg"]
[Tue Jul 21 08:23:44.090162 2026] [security2:error] [pid 419508:tid 419727] [client 202.179.75.202:47872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9WwFcagwCeNbomjVsOLAAAAeg"]
[Tue Jul 21 08:23:44.098308 2026] [security2:error] [pid 419508:tid 419745] [client 20.226.60.151:60667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/as.php"] [unique_id "al9WwFcagwCeNbomjVsOLQAAAfk"]
[Tue Jul 21 08:23:44.496522 2026] [security2:error] [pid 419508:tid 419752] [client 4.194.217.15:1146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp-sigunq.php"] [unique_id "al9WwFcagwCeNbomjVsONgAAAgA"]
[Tue Jul 21 08:23:44.505183 2026] [security2:error] [pid 419508:tid 419733] [client 20.220.225.223:34699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/ace2.php"] [unique_id "al9WwFcagwCeNbomjVsONwAAAe4"]
[Tue Jul 21 08:23:44.613038 2026] [security2:error] [pid 411857:tid 412078] [client 187.125.243.197:56408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WwC7ynBpLeKYztQPq0QAAAFk"]
[Tue Jul 21 08:23:44.613142 2026] [security2:error] [pid 411857:tid 412078] [client 187.125.243.197:56408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9WwC7ynBpLeKYztQPq0QAAAFk"]
[Tue Jul 21 08:23:44.682610 2026] [security2:error] [pid 418108:tid 418268] [client 159.223.41.76:58204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9WwA0cxofL2J1zwYrE4QAAASY"]
[Tue Jul 21 08:23:44.775346 2026] [security2:error] [pid 418108:tid 418270] [client 20.206.105.145:20222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/file52.php"] [unique_id "al9WwA0cxofL2J1zwYrE4gAAASg"]
[Tue Jul 21 08:23:44.802427 2026] [security2:error] [pid 419508:tid 419690] [client 20.151.10.161:37519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/crgio.php"] [unique_id "al9WwFcagwCeNbomjVsOQgAAAcM"]
[Tue Jul 21 08:23:44.935179 2026] [security2:error] [pid 419508:tid 419593] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/cron/.env"] [unique_id "al9WwFcagwCeNbomjVsOQwACAVQ"]
[Tue Jul 21 08:23:44.967689 2026] [security2:error] [pid 418108:tid 418303] [client 20.220.225.223:12338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/acew67.php"] [unique_id "al9WwA0cxofL2J1zwYrE5AAAAUk"]
[Tue Jul 21 08:23:45.097362 2026] [security2:error] [pid 411857:tid 412033] [client 20.151.10.161:37470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/pucci.php"] [unique_id "al9WwS7ynBpLeKYztQPq1wAAACw"]
[Tue Jul 21 08:23:45.213753 2026] [security2:error] [pid 419508:tid 419749] [client 65.21.113.253:46854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WwFcagwCeNbomjVsOQAAAAf0"]
[Tue Jul 21 08:23:45.305399 2026] [security2:error] [pid 411857:tid 412022] [client 20.220.225.223:34720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tialica.com.br.bililica.com"] [uri "/ms.php"] [unique_id "al9WwS7ynBpLeKYztQPq2QAAACE"]
[Tue Jul 21 08:23:45.349174 2026] [security2:error] [pid 419508:tid 419584] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/www/.env"] [unique_id "al9WwVcagwCeNbomjVsORwAB9ks"]
[Tue Jul 21 08:23:45.370909 2026] [security2:error] [pid 418108:tid 418295] [client 159.223.41.76:59001] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9WwQ0cxofL2J1zwYrE5wAAAUE"]
[Tue Jul 21 08:23:45.554472 2026] [security2:error] [pid 419508:tid 419764] [client 4.194.217.15:1727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp-the.php"] [unique_id "al9WwVcagwCeNbomjVsOSwAAAgw"]
[Tue Jul 21 08:23:45.566759 2026] [security2:error] [pid 411857:tid 411982] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WwS7ynBpLeKYztQPq3QAASXo"]
[Tue Jul 21 08:23:45.567023 2026] [security2:error] [pid 411857:tid 412062] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WwS7ynBpLeKYztQPq3QAASXo"]
[Tue Jul 21 08:23:45.655959 2026] [security2:error] [pid 411857:tid 419454] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WwS7ynBpLeKYztQPq3wAAH4g"]
[Tue Jul 21 08:23:45.656160 2026] [security2:error] [pid 411857:tid 412020] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WwS7ynBpLeKYztQPq3wAAH4g"]
[Tue Jul 21 08:23:45.735696 2026] [security2:error] [pid 418108:tid 418357] [client 20.151.10.161:37530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-temp.php"] [unique_id "al9WwQ0cxofL2J1zwYrE7gAAAX8"]
[Tue Jul 21 08:23:45.929069 2026] [security2:error] [pid 419508:tid 419536] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/docker/.env"] [unique_id "al9WwVcagwCeNbomjVsOUgAB3Rs"]
[Tue Jul 21 08:23:46.051032 2026] [security2:error] [pid 418108:tid 418344] [client 20.226.60.151:63311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Wwg0cxofL2J1zwYrE9AAAAXI"]
[Tue Jul 21 08:23:46.057520 2026] [security2:error] [pid 418108:tid 418248] [client 159.223.41.76:59895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Wwg0cxofL2J1zwYrE9QAAARI"]
[Tue Jul 21 08:23:46.281930 2026] [security2:error] [pid 419508:tid 419549] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/docker/app/.env"] [unique_id "al9WwlcagwCeNbomjVsOVQAB6Cg"]
[Tue Jul 21 08:23:46.528259 2026] [security2:error] [pid 419508:tid 419739] [client 20.151.10.161:37567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9WwlcagwCeNbomjVsOWQAAAfQ"]
[Tue Jul 21 08:23:46.579264 2026] [security2:error] [pid 411857:tid 412051] [client 4.194.217.15:1700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp-themes.php"] [unique_id "al9Wwi7ynBpLeKYztQPq7AAAAD4"]
[Tue Jul 21 08:23:46.583294 2026] [security2:error] [pid 411857:tid 412012] [client 115.134.11.136:58844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wwi7ynBpLeKYztQPq7QAAABc"]
[Tue Jul 21 08:23:46.584036 2026] [security2:error] [pid 411857:tid 412012] [client 115.134.11.136:58844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wwi7ynBpLeKYztQPq7QAAABc"]
[Tue Jul 21 08:23:46.658909 2026] [security2:error] [pid 419508:tid 419614] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/env.backup"] [unique_id "al9WwlcagwCeNbomjVsOWgABmWk"]
[Tue Jul 21 08:23:46.744493 2026] [security2:error] [pid 419508:tid 419640] [client 159.223.41.76:60897] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9WwlcagwCeNbomjVsOXQAAAZE"]
[Tue Jul 21 08:23:46.813792 2026] [security2:error] [pid 419508:tid 419663] [client 20.151.10.161:37548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/puc.php"] [unique_id "al9WwlcagwCeNbomjVsOXgAAAag"]
[Tue Jul 21 08:23:46.851863 2026] [security2:error] [pid 419508:tid 419702] [client 20.197.192.193:53126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/dragonshell.php"] [unique_id "al9WwlcagwCeNbomjVsOYAAAAc8"]
[Tue Jul 21 08:23:46.964220 2026] [security2:error] [pid 419508:tid 419715] [client 20.220.225.223:12587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/bscclapb.php"] [unique_id "al9WwlcagwCeNbomjVsOYgAAAdw"]
[Tue Jul 21 08:23:47.114616 2026] [security2:error] [pid 419508:tid 419685] [client 20.151.10.161:37508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/themes.php"] [unique_id "al9Ww1cagwCeNbomjVsOZgAAAb4"]
[Tue Jul 21 08:23:47.336208 2026] [security2:error] [pid 418108:tid 418310] [client 20.197.192.193:52230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/wp-mt.php"] [unique_id "al9Www0cxofL2J1zwYrE_gAAAVA"]
[Tue Jul 21 08:23:47.410590 2026] [security2:error] [pid 418108:tid 418312] [client 20.151.10.161:37564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/dx.php"] [unique_id "al9Www0cxofL2J1zwYrE_wAAAVI"]
[Tue Jul 21 08:23:47.429312 2026] [security2:error] [pid 419508:tid 419695] [client 159.223.41.76:61833] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9Ww1cagwCeNbomjVsOcAAAAcg"]
[Tue Jul 21 08:23:47.472939 2026] [security2:error] [pid 419508:tid 419722] [client 65.21.113.253:46854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WwlcagwCeNbomjVsOYwAAAeM"]
[Tue Jul 21 08:23:47.642250 2026] [security2:error] [pid 418108:tid 418323] [client 4.194.217.15:3899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp-trackback.php"] [unique_id "al9Www0cxofL2J1zwYrFAgAAAV0"]
[Tue Jul 21 08:23:47.716601 2026] [security2:error] [pid 411857:tid 412009] [client 103.151.46.103:53234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Wwy7ynBpLeKYztQPq_QAAABQ"]
[Tue Jul 21 08:23:47.717623 2026] [security2:error] [pid 411857:tid 412009] [client 103.151.46.103:53234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Wwy7ynBpLeKYztQPq_QAAABQ"]
[Tue Jul 21 08:23:47.720680 2026] [security2:error] [pid 419508:tid 419672] [client 20.151.10.161:37601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/p.php"] [unique_id "al9Ww1cagwCeNbomjVsOcwAAAbE"]
[Tue Jul 21 08:23:47.760926 2026] [security2:error] [pid 419508:tid 419742] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Ww1cagwCeNbomjVsObwAAAfc"]
[Tue Jul 21 08:23:47.845231 2026] [security2:error] [pid 419508:tid 419736] [client 125.18.144.2:25533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Ww1cagwCeNbomjVsOdwAAAfE"]
[Tue Jul 21 08:23:47.845383 2026] [security2:error] [pid 419508:tid 419736] [client 125.18.144.2:25533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Ww1cagwCeNbomjVsOdwAAAfE"]
[Tue Jul 21 08:23:48.117282 2026] [security2:error] [pid 419508:tid 419643] [client 159.223.41.76:62660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9WxFcagwCeNbomjVsOfgAAAZQ"]
[Tue Jul 21 08:23:48.147833 2026] [security2:error] [pid 418108:tid 418328] [client 20.151.10.161:37527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/bthil.php"] [unique_id "al9WxA0cxofL2J1zwYrFBQAAAWI"]
[Tue Jul 21 08:23:48.430990 2026] [security2:error] [pid 419508:tid 419638] [client 20.151.10.161:37532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/7.php"] [unique_id "al9WxFcagwCeNbomjVsOhQAAAY8"]
[Tue Jul 21 08:23:48.674468 2026] [security2:error] [pid 419508:tid 419568] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/xampp/phpinfo.php"] [unique_id "al9WxFcagwCeNbomjVsOiQABxzs"]
[Tue Jul 21 08:23:48.708372 2026] [security2:error] [pid 419508:tid 419702] [client 20.151.10.161:37585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/8.php"] [unique_id "al9WxFcagwCeNbomjVsOigAAAc8"]
[Tue Jul 21 08:23:48.725777 2026] [security2:error] [pid 418108:tid 418301] [client 4.194.217.15:1726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp-user.php"] [unique_id "al9WxA0cxofL2J1zwYrFCAAAAUc"]
[Tue Jul 21 08:23:48.802806 2026] [security2:error] [pid 419508:tid 419725] [client 159.223.41.76:63468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9WxFcagwCeNbomjVsOiwAAAeY"]
[Tue Jul 21 08:23:49.005542 2026] [security2:error] [pid 419508:tid 419766] [client 20.197.192.193:46146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9WxVcagwCeNbomjVsOjwAAAg4"]
[Tue Jul 21 08:23:49.009101 2026] [security2:error] [pid 411857:tid 412053] [client 20.151.10.161:37484] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "betoperroygrill.com.br"] [uri "/1.php"] [unique_id "al9WxS7ynBpLeKYztQPrCwAAAEA"]
[Tue Jul 21 08:23:49.009532 2026] [security2:error] [pid 411857:tid 412053] [client 20.151.10.161:37484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/1.php"] [unique_id "al9WxS7ynBpLeKYztQPrCwAAAEA"]
[Tue Jul 21 08:23:49.316988 2026] [security2:error] [pid 418108:tid 418319] [client 20.151.10.161:37582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/100.php"] [unique_id "al9WxQ0cxofL2J1zwYrFDgAAAVk"]
[Tue Jul 21 08:23:49.419439 2026] [security2:error] [pid 419508:tid 419595] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/lara/info.php"] [unique_id "al9WxVcagwCeNbomjVsOlgAB9VY"]
[Tue Jul 21 08:23:49.495645 2026] [security2:error] [pid 418108:tid 418353] [client 159.223.41.76:64418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "brwmarcas.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9WxQ0cxofL2J1zwYrFEAAAAXs"]
[Tue Jul 21 08:23:49.522667 2026] [security2:error] [pid 419508:tid 419677] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WxVcagwCeNbomjVsOkAAAAbY"]
[Tue Jul 21 08:23:49.599915 2026] [security2:error] [pid 411857:tid 412105] [client 20.151.10.161:37534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/about.php"] [unique_id "al9WxS7ynBpLeKYztQPrEgAAAHQ"]
[Tue Jul 21 08:23:49.605003 2026] [security2:error] [pid 419508:tid 419687] [client 20.226.60.151:60611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9WxVcagwCeNbomjVsOmAAAAcA"]
[Tue Jul 21 08:23:49.797623 2026] [security2:error] [pid 419508:tid 419750] [client 20.197.192.193:52282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/ww.php"] [unique_id "al9WxVcagwCeNbomjVsOmwAAAf4"]
[Tue Jul 21 08:23:49.797811 2026] [security2:error] [pid 419508:tid 419670] [client 4.194.217.15:3878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp-ver.php"] [unique_id "al9WxVcagwCeNbomjVsOnAAAAa8"]
[Tue Jul 21 08:23:49.929821 2026] [security2:error] [pid 419508:tid 419761] [client 20.151.10.161:37584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/admin.php"] [unique_id "al9WxVcagwCeNbomjVsOoAAAAgk"]
[Tue Jul 21 08:23:50.293934 2026] [security2:error] [pid 419508:tid 419702] [client 20.206.105.145:20191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/122.php"] [unique_id "al9WxlcagwCeNbomjVsOqwAAAc8"]
[Tue Jul 21 08:23:50.366373 2026] [security2:error] [pid 411857:tid 412047] [client 20.151.10.161:37547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/edit.php"] [unique_id "al9Wxi7ynBpLeKYztQPrIQAAADo"]
[Tue Jul 21 08:23:50.435332 2026] [autoindex:error] [pid 419508:tid 419725] [client 20.226.60.151:0] AH01276: Cannot serve directory /home3/cur37674/osantotchay.com.br/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:50.647713 2026] [security2:error] [pid 418108:tid 418267] [client 20.226.60.151:56874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Wxg0cxofL2J1zwYrFFQAAASU"]
[Tue Jul 21 08:23:50.664496 2026] [security2:error] [pid 419508:tid 419697] [client 20.151.10.161:37509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9WxlcagwCeNbomjVsOsgAAAco"]
[Tue Jul 21 08:23:50.715148 2026] [security2:error] [pid 418108:tid 418235] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wxg0cxofL2J1zwYrFFgABc3w"]
[Tue Jul 21 08:23:50.715307 2026] [security2:error] [pid 418108:tid 418345] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wxg0cxofL2J1zwYrFFgABc3w"]
[Tue Jul 21 08:23:50.812526 2026] [autoindex:error] [pid 411857:tid 411999] [client 20.226.60.151:0] AH01276: Cannot serve directory /home3/cur37674/osantotchay.com.br/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:50.833949 2026] [security2:error] [pid 411857:tid 412088] [client 89.238.167.134:55732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Wxi7ynBpLeKYztQPrMQAAAGM"]
[Tue Jul 21 08:23:50.834035 2026] [security2:error] [pid 411857:tid 412088] [client 89.238.167.134:55732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Wxi7ynBpLeKYztQPrMQAAAGM"]
[Tue Jul 21 08:23:50.850974 2026] [authz_core:error] [pid 411857:tid 412072] [client 20.226.60.151:0] AH01630: client denied by server configuration: /home3/cur37674/osantotchay.com.br/wp-content/uploads/index.php
[Tue Jul 21 08:23:50.874586 2026] [security2:error] [pid 418108:tid 418335] [client 20.226.60.151:56885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/abcd.php"] [unique_id "al9Wxg0cxofL2J1zwYrFGgAAAWk"]
[Tue Jul 21 08:23:50.915765 2026] [security2:error] [pid 411857:tid 412055] [client 4.194.217.15:1094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp-ws68.php"] [unique_id "al9Wxi7ynBpLeKYztQPrNwAAAEI"]
[Tue Jul 21 08:23:50.963230 2026] [security2:error] [pid 411857:tid 412076] [client 20.151.10.161:37471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/f6.php"] [unique_id "al9Wxi7ynBpLeKYztQPrOAAAAFc"]
[Tue Jul 21 08:23:51.026025 2026] [security2:error] [pid 411857:tid 411993] [client 20.220.225.223:12558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/else1.php"] [unique_id "al9Wxy7ynBpLeKYztQPrPwAAAAQ"]
[Tue Jul 21 08:23:51.050698 2026] [security2:error] [pid 419508:tid 419719] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WxlcagwCeNbomjVsOtQAAAeA"]
[Tue Jul 21 08:23:51.157997 2026] [security2:error] [pid 419508:tid 419723] [client 20.226.60.151:56876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/file15.php"] [unique_id "al9Wx1cagwCeNbomjVsOuAAAAeQ"]
[Tue Jul 21 08:23:51.225705 2026] [security2:error] [pid 411857:tid 412103] [client 117.213.202.34:50143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wxy7ynBpLeKYztQPrSgAAAHI"]
[Tue Jul 21 08:23:51.225848 2026] [security2:error] [pid 411857:tid 412103] [client 117.213.202.34:50143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wxy7ynBpLeKYztQPrSgAAAHI"]
[Tue Jul 21 08:23:51.243099 2026] [security2:error] [pid 419508:tid 419672] [client 20.151.10.161:37379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/inputs.php"] [unique_id "al9Wx1cagwCeNbomjVsOugAAAbE"]
[Tue Jul 21 08:23:51.405250 2026] [security2:error] [pid 411857:tid 412038] [client 152.59.34.51:49867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Wxy7ynBpLeKYztQPrWAAAADE"]
[Tue Jul 21 08:23:51.405345 2026] [security2:error] [pid 411857:tid 412038] [client 152.59.34.51:49867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Wxy7ynBpLeKYztQPrWAAAADE"]
[Tue Jul 21 08:23:51.418042 2026] [security2:error] [pid 411857:tid 411885] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wxy7ynBpLeKYztQPrWQAAXho"]
[Tue Jul 21 08:23:51.418238 2026] [security2:error] [pid 411857:tid 412083] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wxy7ynBpLeKYztQPrWQAAXho"]
[Tue Jul 21 08:23:51.545149 2026] [security2:error] [pid 418108:tid 418282] [client 20.151.10.161:37580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/av.php"] [unique_id "al9Wxw0cxofL2J1zwYrFHAAAATQ"]
[Tue Jul 21 08:23:51.567977 2026] [security2:error] [pid 419508:tid 419764] [client 20.226.60.151:56915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/jp.php"] [unique_id "al9Wx1cagwCeNbomjVsOvwAAAgw"]
[Tue Jul 21 08:23:51.590042 2026] [security2:error] [pid 419508:tid 419742] [client 65.21.113.253:46854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Wx1cagwCeNbomjVsOtwAAAfc"]
[Tue Jul 21 08:23:51.716601 2026] [security2:error] [pid 419508:tid 419639] [client 223.181.60.88:12327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Wx1cagwCeNbomjVsOwAAAAZA"]
[Tue Jul 21 08:23:51.716793 2026] [security2:error] [pid 419508:tid 419639] [client 223.181.60.88:12327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Wx1cagwCeNbomjVsOwAAAAZA"]
[Tue Jul 21 08:23:51.825809 2026] [security2:error] [pid 419508:tid 419714] [client 20.226.60.151:56947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/f35.php"] [unique_id "al9Wx1cagwCeNbomjVsOwgAAAds"]
[Tue Jul 21 08:23:51.874840 2026] [security2:error] [pid 419508:tid 419727] [client 20.151.10.161:37565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Wx1cagwCeNbomjVsOwwAAAeg"]
[Tue Jul 21 08:23:51.919991 2026] [security2:error] [pid 419508:tid 419735] [client 20.206.105.145:20146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/green1.php"] [unique_id "al9Wx1cagwCeNbomjVsOxAAAAfA"]
[Tue Jul 21 08:23:52.001138 2026] [security2:error] [pid 419508:tid 419740] [client 150.129.202.39:65282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WyFcagwCeNbomjVsOxwAAAfU"]
[Tue Jul 21 08:23:52.001301 2026] [security2:error] [pid 419508:tid 419740] [client 150.129.202.39:65282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WyFcagwCeNbomjVsOxwAAAfU"]
[Tue Jul 21 08:23:52.010070 2026] [security2:error] [pid 418108:tid 418283] [client 4.194.217.15:3858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp.php"] [unique_id "al9WyA0cxofL2J1zwYrFIQAAATU"]
[Tue Jul 21 08:23:52.189152 2026] [security2:error] [pid 419508:tid 419638] [client 20.151.10.161:37536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9WyFcagwCeNbomjVsOzQAAAY8"]
[Tue Jul 21 08:23:52.270642 2026] [security2:error] [pid 419508:tid 419671] [client 195.49.128.211:58513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WyFcagwCeNbomjVsOzgAAAbA"]
[Tue Jul 21 08:23:52.270833 2026] [security2:error] [pid 419508:tid 419671] [client 195.49.128.211:58513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9WyFcagwCeNbomjVsOzgAAAbA"]
[Tue Jul 21 08:23:52.302802 2026] [security2:error] [pid 419508:tid 419597] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9WyFcagwCeNbomjVsOzwABlFg"]
[Tue Jul 21 08:23:52.303040 2026] [security2:error] [pid 419508:tid 419643] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9WyFcagwCeNbomjVsOzwABlFg"]
[Tue Jul 21 08:23:52.621602 2026] [security2:error] [pid 411857:tid 412050] [client 20.151.10.161:37412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-blog.php"] [unique_id "al9WyC7ynBpLeKYztQPrbQAAAD0"]
[Tue Jul 21 08:23:52.670564 2026] [security2:error] [pid 419508:tid 419750] [client 47.128.52.229:40368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "insp1.com.br"] [uri "/robots.txt"] [unique_id "al9WyFcagwCeNbomjVsO1QAAAf4"]
[Tue Jul 21 08:23:52.939664 2026] [security2:error] [pid 418108:tid 418228] [remote 81.173.115.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/wp-login.php"] [unique_id "al9WyA0cxofL2J1zwYrFJAABEXU"]
[Tue Jul 21 08:23:52.981390 2026] [security2:error] [pid 419508:tid 419728] [client 14.245.224.124:63897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WyFcagwCeNbomjVsO2gAAAek"]
[Tue Jul 21 08:23:52.981503 2026] [security2:error] [pid 419508:tid 419728] [client 14.245.224.124:63897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9WyFcagwCeNbomjVsO2gAAAek"]
[Tue Jul 21 08:23:53.033698 2026] [security2:error] [pid 419508:tid 419725] [client 4.194.217.15:4747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp/002.php"] [unique_id "al9WyVcagwCeNbomjVsO3QAAAeY"]
[Tue Jul 21 08:23:53.111299 2026] [security2:error] [pid 419508:tid 419680] [client 20.151.10.161:37588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9WyVcagwCeNbomjVsO3gAAAbk"]
[Tue Jul 21 08:23:53.278942 2026] [security2:error] [pid 419508:tid 419522] [remote 216.73.216.116:15367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roha.life"] [uri "/wp-login.php"] [unique_id "al9WyFcagwCeNbomjVsO2QABzQ0"]
[Tue Jul 21 08:23:53.337778 2026] [security2:error] [pid 419508:tid 419711] [client 20.226.60.151:56954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/wp-load.php"] [unique_id "al9WyVcagwCeNbomjVsO4wAAAdg"]
[Tue Jul 21 08:23:53.379503 2026] [security2:error] [pid 411857:tid 411939] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WyS7ynBpLeKYztQPrdgAACVA"]
[Tue Jul 21 08:23:53.379640 2026] [security2:error] [pid 411857:tid 411998] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9WyS7ynBpLeKYztQPrdgAACVA"]
[Tue Jul 21 08:23:53.434323 2026] [security2:error] [pid 419508:tid 419685] [client 65.21.113.253:46854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WyFcagwCeNbomjVsO2wAAAb4"]
[Tue Jul 21 08:23:53.596615 2026] [security2:error] [pid 419508:tid 419676] [client 20.206.105.145:20223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/biufile.php"] [unique_id "al9WyVcagwCeNbomjVsO7AAAAbU"]
[Tue Jul 21 08:23:53.662139 2026] [security2:error] [pid 419508:tid 419697] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WyVcagwCeNbomjVsO3wAAAco"]
[Tue Jul 21 08:23:53.718853 2026] [security2:error] [pid 411857:tid 412014] [client 213.152.186.163:38730] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9WyS7ynBpLeKYztQPrfgAAABk"]
[Tue Jul 21 08:23:53.718955 2026] [security2:error] [pid 411857:tid 412014] [client 213.152.186.163:38730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9WyS7ynBpLeKYztQPrfgAAABk"]
[Tue Jul 21 08:23:53.776129 2026] [security2:error] [pid 419508:tid 419674] [client 20.151.10.161:37554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/adminfuns.php"] [unique_id "al9WyVcagwCeNbomjVsO8gAAAbM"]
[Tue Jul 21 08:23:53.882567 2026] [security2:error] [pid 411857:tid 419461] [remote 124.55.178.99:56532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fisiopelvicafloripa.com.br"] [uri "/wp-login.php"] [unique_id "al9WyS7ynBpLeKYztQPrgQAAVI8"]
[Tue Jul 21 08:23:54.091849 2026] [security2:error] [pid 419508:tid 419761] [client 4.194.217.15:1117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wp/wp-content/themes/extendable/mg2.php"] [unique_id "al9WylcagwCeNbomjVsO9wAAAgk"]
[Tue Jul 21 08:23:54.137476 2026] [security2:error] [pid 411857:tid 411999] [client 20.151.10.161:37553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/goods.php"] [unique_id "al9Wyi7ynBpLeKYztQPrhQAAAAo"]
[Tue Jul 21 08:23:54.436011 2026] [security2:error] [pid 419508:tid 419717] [client 20.151.10.161:37598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/ms-edit.php"] [unique_id "al9WylcagwCeNbomjVsO-gAAAd4"]
[Tue Jul 21 08:23:54.534260 2026] [security2:error] [pid 418108:tid 418309] [client 20.226.60.151:56957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/xyn.php"] [unique_id "al9Wyg0cxofL2J1zwYrFKQAAAU8"]
[Tue Jul 21 08:23:54.582314 2026] [security2:error] [pid 419508:tid 419733] [client 111.93.58.162:41590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WylcagwCeNbomjVsO-wAAAe4"]
[Tue Jul 21 08:23:54.582463 2026] [security2:error] [pid 419508:tid 419733] [client 111.93.58.162:41590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9WylcagwCeNbomjVsO-wAAAe4"]
[Tue Jul 21 08:23:54.725884 2026] [security2:error] [pid 419508:tid 419766] [client 20.197.192.193:52262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/cron.php"] [unique_id "al9WylcagwCeNbomjVsPAQAAAg4"]
[Tue Jul 21 08:23:54.754705 2026] [security2:error] [pid 411857:tid 411993] [client 20.151.10.161:37561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/222.php"] [unique_id "al9Wyi7ynBpLeKYztQPrjwAAAAQ"]
[Tue Jul 21 08:23:54.937581 2026] [security2:error] [pid 419508:tid 419723] [client 103.147.32.194:62398] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jorgecostaadvogados.com"] [uri "/"] [unique_id "al9WyVcagwCeNbomjVsO8QAAAeQ"]
[Tue Jul 21 08:23:55.085075 2026] [security2:error] [pid 419508:tid 419650] [client 202.179.75.202:38322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Wy1cagwCeNbomjVsPCQAAAZs"]
[Tue Jul 21 08:23:55.085220 2026] [security2:error] [pid 419508:tid 419650] [client 202.179.75.202:38322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Wy1cagwCeNbomjVsPCQAAAZs"]
[Tue Jul 21 08:23:55.088127 2026] [security2:error] [pid 419508:tid 419701] [client 187.125.243.197:56905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Wy1cagwCeNbomjVsPCgAAAc4"]
[Tue Jul 21 08:23:55.088224 2026] [security2:error] [pid 419508:tid 419701] [client 187.125.243.197:56905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Wy1cagwCeNbomjVsPCgAAAc4"]
[Tue Jul 21 08:23:55.124898 2026] [security2:error] [pid 418108:tid 418329] [client 4.194.217.15:3885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/ws.php"] [unique_id "al9Wyw0cxofL2J1zwYrFKgAAAWM"]
[Tue Jul 21 08:23:55.169109 2026] [security2:error] [pid 419508:tid 419656] [client 20.151.10.161:37478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Wy1cagwCeNbomjVsPDAAAAaE"]
[Tue Jul 21 08:23:55.661702 2026] [security2:error] [pid 419508:tid 419727] [client 65.21.113.253:46854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Wy1cagwCeNbomjVsPFQAAAeg"]
[Tue Jul 21 08:23:55.691988 2026] [security2:error] [pid 418108:tid 418240] [client 20.151.10.161:37507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Wyw0cxofL2J1zwYrFNAAAAQo"]
[Tue Jul 21 08:23:55.743534 2026] [security2:error] [pid 419508:tid 419679] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Wy1cagwCeNbomjVsPEAAAAbg"]
[Tue Jul 21 08:23:55.824081 2026] [security2:error] [pid 419508:tid 419733] [client 34.76.2.141:56767] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "geracaosemtelinha.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Wy1cagwCeNbomjVsPHQAAAe4"]
[Tue Jul 21 08:23:56.140900 2026] [security2:error] [pid 419508:tid 419694] [client 103.147.32.194:62667] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jorgecostaadvogados.com"] [uri "/wp-json/batch/v1"] [unique_id "al9WzFcagwCeNbomjVsPIgAAAcc"]
[Tue Jul 21 08:23:56.190211 2026] [security2:error] [pid 419508:tid 419698] [client 4.194.217.15:1592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/wso.php"] [unique_id "al9WzFcagwCeNbomjVsPIwAAAcs"]
[Tue Jul 21 08:23:56.219421 2026] [security2:error] [pid 418108:tid 418341] [client 109.248.148.246:47304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9WzA0cxofL2J1zwYrFNwAAAW8"]
[Tue Jul 21 08:23:56.219521 2026] [security2:error] [pid 418108:tid 418341] [client 109.248.148.246:47304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9WzA0cxofL2J1zwYrFNwAAAW8"]
[Tue Jul 21 08:23:56.283785 2026] [security2:error] [pid 411857:tid 411919] [remote 142.93.10.93:36654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cezaretto.com.br"] [uri "/wp-login.php"] [unique_id "al9Wyy7ynBpLeKYztQPrlgAALzw"]
[Tue Jul 21 08:23:56.356796 2026] [security2:error] [pid 419508:tid 419681] [client 20.151.10.161:37562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp.php"] [unique_id "al9WzFcagwCeNbomjVsPKwAAAbo"]
[Tue Jul 21 08:23:56.402896 2026] [security2:error] [pid 418108:tid 418199] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WzA0cxofL2J1zwYrFOAABalg"]
[Tue Jul 21 08:23:56.403183 2026] [security2:error] [pid 418108:tid 418336] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WzA0cxofL2J1zwYrFOAABalg"]
[Tue Jul 21 08:23:56.674181 2026] [lsapi:warn] [pid 419508:tid 419606] [remote 193.186.4.238:47653] [host goldentrips40.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/gold0682/public_html/wp-content/plugins/wp-rocket/inc/Engine/Optimization/AssetsLocalCache.php on line 112\n, referer: https://www.google.com/
[Tue Jul 21 08:23:56.674212 2026] [lsapi:warn] [pid 419508:tid 419606] [remote 193.186.4.238:47653] [host goldentrips40.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/gold0682/public_html/wp-content/plugins/wp-rocket/inc/Engine/Optimization/AssetsLocalCache.php on line 112\n, referer: https://www.google.com/
[Tue Jul 21 08:23:56.777621 2026] [security2:error] [pid 411857:tid 412102] [client 20.206.105.145:20120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wpconf.php"] [unique_id "al9WzC7ynBpLeKYztQPrqwAAAHE"]
[Tue Jul 21 08:23:56.822934 2026] [security2:error] [pid 419508:tid 419653] [client 20.151.10.161:37492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/abcd.php"] [unique_id "al9WzFcagwCeNbomjVsPMQAAAZ4"]
[Tue Jul 21 08:23:57.126439 2026] [security2:error] [pid 411857:tid 412095] [client 20.197.192.193:51940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/xxx.php"] [unique_id "al9WzS7ynBpLeKYztQPrrgAAAGo"]
[Tue Jul 21 08:23:57.212087 2026] [security2:error] [pid 411857:tid 412062] [client 213.152.186.163:38300] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9WzS7ynBpLeKYztQPrsQAAAEk"]
[Tue Jul 21 08:23:57.212244 2026] [security2:error] [pid 411857:tid 412062] [client 213.152.186.163:38300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9WzS7ynBpLeKYztQPrsQAAAEk"]
[Tue Jul 21 08:23:57.213902 2026] [security2:error] [pid 418108:tid 418367] [client 20.151.10.161:37614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/a1.php"] [unique_id "al9WzQ0cxofL2J1zwYrFPgAAAYk"]
[Tue Jul 21 08:23:57.296488 2026] [security2:error] [pid 418108:tid 418259] [client 4.194.217.15:4767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/x.php"] [unique_id "al9WzQ0cxofL2J1zwYrFPwAAAR0"]
[Tue Jul 21 08:23:57.392914 2026] [security2:error] [pid 418108:tid 418363] [client 20.226.60.151:50118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/w1px.php"] [unique_id "al9WzQ0cxofL2J1zwYrFQAAAAYU"]
[Tue Jul 21 08:23:57.543521 2026] [security2:error] [pid 418108:tid 418328] [client 61.1.167.83:54858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WzQ0cxofL2J1zwYrFQQAAAWI"]
[Tue Jul 21 08:23:57.543657 2026] [security2:error] [pid 418108:tid 418328] [client 61.1.167.83:54858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WzQ0cxofL2J1zwYrFQQAAAWI"]
[Tue Jul 21 08:23:57.570064 2026] [security2:error] [pid 419508:tid 419715] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9WzFcagwCeNbomjVsPJAAB3HM"]
[Tue Jul 21 08:23:57.784978 2026] [security2:error] [pid 419508:tid 419706] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WzVcagwCeNbomjVsPOgAAAdM"]
[Tue Jul 21 08:23:58.007870 2026] [security2:error] [pid 419508:tid 419638] [client 65.21.113.253:46854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9WzVcagwCeNbomjVsPPAAAAY8"]
[Tue Jul 21 08:23:58.014507 2026] [autoindex:error] [pid 418108:tid 418253] [client 20.226.60.151:0] AH01276: Cannot serve directory /home3/cur37674/osantotchay.com.br/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:58.030481 2026] [security2:error] [pid 418108:tid 418191] [remote 45.76.153.27:43292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.153.76.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9Wzg0cxofL2J1zwYrFSAABh1A"]
[Tue Jul 21 08:23:58.104664 2026] [security2:error] [pid 419508:tid 419748] [client 20.151.10.161:37506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9WzlcagwCeNbomjVsPSAAAAfw"]
[Tue Jul 21 08:23:58.118191 2026] [autoindex:error] [pid 419508:tid 419746] [client 20.226.60.151:56856] AH01276: Cannot serve directory /home3/cur37674/osantotchay.com.br/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:23:58.355230 2026] [security2:error] [pid 418108:tid 418311] [client 103.151.46.103:53727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Wzg0cxofL2J1zwYrFSwAAAVE"]
[Tue Jul 21 08:23:58.355449 2026] [security2:error] [pid 418108:tid 418311] [client 103.151.46.103:53727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Wzg0cxofL2J1zwYrFSwAAAVE"]
[Tue Jul 21 08:23:58.390669 2026] [security2:error] [pid 419508:tid 419646] [client 4.194.217.15:3773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/x86.php"] [unique_id "al9WzlcagwCeNbomjVsPTAAAAZc"]
[Tue Jul 21 08:23:58.546908 2026] [security2:error] [pid 419508:tid 419693] [client 20.197.192.193:53163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/hunter.php"] [unique_id "al9WzlcagwCeNbomjVsPUwAAAcY"]
[Tue Jul 21 08:23:58.578902 2026] [security2:error] [pid 419508:tid 419687] [client 20.226.60.151:56856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/ccc.php"] [unique_id "al9WzlcagwCeNbomjVsPVwAAAcA"]
[Tue Jul 21 08:23:58.767789 2026] [security2:error] [pid 419508:tid 419677] [client 115.134.11.136:59292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WzlcagwCeNbomjVsPXAAAAbY"]
[Tue Jul 21 08:23:58.767953 2026] [security2:error] [pid 419508:tid 419677] [client 115.134.11.136:59292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WzlcagwCeNbomjVsPXAAAAbY"]
[Tue Jul 21 08:23:59.115410 2026] [security2:error] [pid 419508:tid 419703] [client 34.76.2.141:55762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "geracaosemtelinha.com.br"] [uri "/xmlrpc.php"] [unique_id "al9WzlcagwCeNbomjVsPXgAAAdA"]
[Tue Jul 21 08:23:59.496867 2026] [security2:error] [pid 411857:tid 412098] [client 20.226.60.151:62383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/w.php"] [unique_id "al9Wzy7ynBpLeKYztQPrzwAAAG0"]
[Tue Jul 21 08:23:59.659500 2026] [security2:error] [pid 418108:tid 418271] [client 4.194.217.15:9793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/xa.php"] [unique_id "al9Wzw0cxofL2J1zwYrFTgAAASk"]
[Tue Jul 21 08:23:59.675589 2026] [security2:error] [pid 411857:tid 412031] [client 34.76.2.141:54009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "geracaosemtelinha.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Wzy7ynBpLeKYztQPr0QAAACo"]
[Tue Jul 21 08:23:59.851049 2026] [security2:error] [pid 419508:tid 419643] [client 65.21.113.253:46854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Wz1cagwCeNbomjVsPZgAAAZQ"]
[Tue Jul 21 08:23:59.946282 2026] [security2:error] [pid 411857:tid 412099] [client 20.206.105.145:20101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/mosty.php"] [unique_id "al9Wzy7ynBpLeKYztQPr2AAAAG4"]
[Tue Jul 21 08:23:59.979372 2026] [security2:error] [pid 411857:tid 412060] [client 20.151.10.161:37537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9Wzy7ynBpLeKYztQPr2QAAAEc"]
[Tue Jul 21 08:24:00.191310 2026] [security2:error] [pid 419508:tid 419751] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9W0FcagwCeNbomjVsPdgAAAf8"]
[Tue Jul 21 08:24:00.242429 2026] [security2:error] [pid 411857:tid 412007] [client 34.76.2.141:63107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "geracaosemtelinha.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W0C7ynBpLeKYztQPr3QAAABI"]
[Tue Jul 21 08:24:00.747646 2026] [security2:error] [pid 419508:tid 419684] [client 34.76.2.141:57154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "geracaosemtelinha.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W0FcagwCeNbomjVsPhgAAAb0"]
[Tue Jul 21 08:24:00.963504 2026] [security2:error] [pid 411857:tid 412095] [client 20.151.10.161:37455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/gettest.php"] [unique_id "al9W0C7ynBpLeKYztQPr8AAAAGo"]
[Tue Jul 21 08:24:01.197051 2026] [security2:error] [pid 418108:tid 418358] [client 20.197.192.193:53141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/we.php"] [unique_id "al9W0Q0cxofL2J1zwYrFUgAAAYA"]
[Tue Jul 21 08:24:01.367829 2026] [security2:error] [pid 419508:tid 419559] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/lara/phpinfo.php"] [unique_id "al9W0VcagwCeNbomjVsQFgABtDI"]
[Tue Jul 21 08:24:01.480878 2026] [security2:error] [pid 419508:tid 419552] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W0VcagwCeNbomjVsQHAABlis"]
[Tue Jul 21 08:24:01.481129 2026] [security2:error] [pid 419508:tid 419645] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W0VcagwCeNbomjVsQHAABlis"]
[Tue Jul 21 08:24:01.482008 2026] [security2:error] [pid 419508:tid 419717] [client 20.226.60.151:56854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9W0VcagwCeNbomjVsQHQAAAd4"]
[Tue Jul 21 08:24:01.535707 2026] [security2:error] [pid 418108:tid 418298] [client 20.151.10.161:37546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/simple.php"] [unique_id "al9W0Q0cxofL2J1zwYrFXAAAAUQ"]
[Tue Jul 21 08:24:01.649638 2026] [security2:error] [pid 418108:tid 418285] [client 4.194.217.15:1543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/xfun.php"] [unique_id "al9W0Q0cxofL2J1zwYrFXwAAATc"]
[Tue Jul 21 08:24:01.709742 2026] [security2:error] [pid 419508:tid 419750] [client 20.197.192.193:5585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9W0VcagwCeNbomjVsQIgAAAf4"]
[Tue Jul 21 08:24:01.773100 2026] [security2:error] [pid 419508:tid 419595] [remote 45.76.153.27:43296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.153.76.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9W0VcagwCeNbomjVsQJQABwFY"]
[Tue Jul 21 08:24:01.898833 2026] [security2:error] [pid 419508:tid 419633] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W0VcagwCeNbomjVsQLQABqHw"]
[Tue Jul 21 08:24:01.898974 2026] [security2:error] [pid 419508:tid 419663] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W0VcagwCeNbomjVsQLQABqHw"]
[Tue Jul 21 08:24:01.931012 2026] [security2:error] [pid 419508:tid 419747] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9W0VcagwCeNbomjVsQGgAAAfs"]
[Tue Jul 21 08:24:01.952192 2026] [security2:error] [pid 411857:tid 411999] [client 20.151.10.161:37482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/xxx.php"] [unique_id "al9W0S7ynBpLeKYztQPsAAAAAAo"]
[Tue Jul 21 08:24:02.023938 2026] [security2:error] [pid 418108:tid 418327] [client 117.213.202.34:50688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W0g0cxofL2J1zwYrFYQAAAWE"]
[Tue Jul 21 08:24:02.024074 2026] [security2:error] [pid 418108:tid 418327] [client 117.213.202.34:50688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W0g0cxofL2J1zwYrFYQAAAWE"]
[Tue Jul 21 08:24:02.031688 2026] [security2:error] [pid 418108:tid 418310] [client 89.238.167.134:44846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9W0g0cxofL2J1zwYrFYgAAAVA"]
[Tue Jul 21 08:24:02.031805 2026] [security2:error] [pid 418108:tid 418310] [client 89.238.167.134:44846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9W0g0cxofL2J1zwYrFYgAAAVA"]
[Tue Jul 21 08:24:02.189913 2026] [security2:error] [pid 419508:tid 419692] [client 152.59.34.51:33680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9W0lcagwCeNbomjVsQNAAAAcU"]
[Tue Jul 21 08:24:02.190060 2026] [security2:error] [pid 419508:tid 419692] [client 152.59.34.51:33680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9W0lcagwCeNbomjVsQNAAAAcU"]
[Tue Jul 21 08:24:02.249953 2026] [security2:error] [pid 418108:tid 418318] [client 20.206.105.145:20145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/dejavu.php"] [unique_id "al9W0g0cxofL2J1zwYrFZQAAAVg"]
[Tue Jul 21 08:24:02.454357 2026] [security2:error] [pid 419508:tid 419753] [client 20.151.10.161:37440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/hypo.php"] [unique_id "al9W0lcagwCeNbomjVsQNQAAAgE"]
[Tue Jul 21 08:24:02.487696 2026] [security2:error] [pid 418108:tid 418279] [client 173.252.95.59:58682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9W0g0cxofL2J1zwYrFZgAAATE"]
[Tue Jul 21 08:24:02.555372 2026] [security2:error] [pid 419508:tid 419643] [client 150.129.202.39:64748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W0lcagwCeNbomjVsQUAAAAZQ"]
[Tue Jul 21 08:24:02.555474 2026] [security2:error] [pid 419508:tid 419643] [client 150.129.202.39:64748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W0lcagwCeNbomjVsQUAAAAZQ"]
[Tue Jul 21 08:24:02.820487 2026] [security2:error] [pid 418108:tid 418256] [client 45.227.253.15:50128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.253.227.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gratech.bavos.com.br"] [uri "/index.php/jk"] [unique_id "al9W0g0cxofL2J1zwYrFaAAAARo"]
[Tue Jul 21 08:24:02.869961 2026] [security2:error] [pid 418108:tid 418219] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9W0g0cxofL2J1zwYrFaQABgWw"]
[Tue Jul 21 08:24:02.870172 2026] [security2:error] [pid 418108:tid 418359] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9W0g0cxofL2J1zwYrFaQABgWw"]
[Tue Jul 21 08:24:02.918674 2026] [security2:error] [pid 419508:tid 419667] [client 195.49.128.211:59102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9W0lcagwCeNbomjVsQXQAAAaw"]
[Tue Jul 21 08:24:02.918811 2026] [security2:error] [pid 419508:tid 419667] [client 195.49.128.211:59102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9W0lcagwCeNbomjVsQXQAAAaw"]
[Tue Jul 21 08:24:03.403667 2026] [security2:error] [pid 418108:tid 418349] [client 20.151.10.161:37524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/chosen.php"] [unique_id "al9W0w0cxofL2J1zwYrFawAAAXc"]
[Tue Jul 21 08:24:03.688035 2026] [security2:error] [pid 419508:tid 419693] [client 14.245.224.124:64379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9W01cagwCeNbomjVsQbAAAAcY"]
[Tue Jul 21 08:24:03.688243 2026] [security2:error] [pid 419508:tid 419693] [client 14.245.224.124:64379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9W01cagwCeNbomjVsQbAAAAcY"]
[Tue Jul 21 08:24:03.702130 2026] [security2:error] [pid 419508:tid 419714] [client 20.226.60.151:60574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/yawa.php"] [unique_id "al9W01cagwCeNbomjVsQbQAAAds"]
[Tue Jul 21 08:24:03.777399 2026] [security2:error] [pid 411857:tid 412075] [client 168.119.53.160:11356] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9W0y7ynBpLeKYztQPsIQAAAFY"], referer: https://artetoner.com.br
[Tue Jul 21 08:24:03.880709 2026] [security2:error] [pid 411857:tid 412035] [client 20.151.10.161:37535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/als.php"] [unique_id "al9W0y7ynBpLeKYztQPsIwAAAC4"]
[Tue Jul 21 08:24:04.021658 2026] [security2:error] [pid 419508:tid 419513] [remote 176.29.79.28:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.79.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9W1FcagwCeNbomjVsQdAABlAQ"]
[Tue Jul 21 08:24:04.021806 2026] [security2:error] [pid 419508:tid 419643] [client 176.29.79.28:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cinsofe.com"] [uri "/xmlrpc.php"] [unique_id "al9W1FcagwCeNbomjVsQdAABlAQ"]
[Tue Jul 21 08:24:04.043561 2026] [security2:error] [pid 419508:tid 419675] [client 4.194.217.15:1545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/xleet.php"] [unique_id "al9W1FcagwCeNbomjVsQdgAAAbQ"]
[Tue Jul 21 08:24:04.060457 2026] [security2:error] [pid 419508:tid 419715] [client 20.206.105.145:20165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/aaf.php"] [unique_id "al9W1FcagwCeNbomjVsQdwAAAdw"]
[Tue Jul 21 08:24:04.067525 2026] [security2:error] [pid 419508:tid 419628] [remote 192.241.143.148:56484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9W1FcagwCeNbomjVsQeAABsnc"]
[Tue Jul 21 08:24:04.207473 2026] [security2:error] [pid 411857:tid 412048] [client 20.151.10.161:37512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/pol.php"] [unique_id "al9W1C7ynBpLeKYztQPsLAAAADs"]
[Tue Jul 21 08:24:04.215122 2026] [security2:error] [pid 419508:tid 419639] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9W01cagwCeNbomjVsQbwAAAZA"]
[Tue Jul 21 08:24:04.399614 2026] [security2:error] [pid 419508:tid 419755] [client 20.220.225.223:12580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/tkikikoko.php"] [unique_id "al9W1FcagwCeNbomjVsQewAAAgM"]
[Tue Jul 21 08:24:04.474069 2026] [security2:error] [pid 419508:tid 419667] [client 20.226.60.151:56908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/FWAZ.php"] [unique_id "al9W1FcagwCeNbomjVsQfAAAAaw"]
[Tue Jul 21 08:24:04.496068 2026] [security2:error] [pid 419508:tid 419680] [client 20.151.10.161:37443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/file5.php"] [unique_id "al9W1FcagwCeNbomjVsQfQAAAbk"]
[Tue Jul 21 08:24:04.912285 2026] [security2:error] [pid 419508:tid 419515] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/lara/phpinfo.php"] [unique_id "al9W1FcagwCeNbomjVsQggAB_wY"]
[Tue Jul 21 08:24:04.930548 2026] [security2:error] [pid 419508:tid 419766] [client 20.151.10.161:37454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9W1FcagwCeNbomjVsQgwAAAg4"]
[Tue Jul 21 08:24:05.227604 2026] [security2:error] [pid 419508:tid 419653] [client 20.151.10.161:37479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/file.php"] [unique_id "al9W1VcagwCeNbomjVsQiQAAAZ4"]
[Tue Jul 21 08:24:05.253154 2026] [security2:error] [pid 419508:tid 419647] [client 4.194.217.15:9837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/xmlrpc.php"] [unique_id "al9W1VcagwCeNbomjVsQigAAAZg"]
[Tue Jul 21 08:24:05.581647 2026] [security2:error] [pid 411857:tid 412102] [client 187.125.243.197:57395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9W1S7ynBpLeKYztQPsPwAAAHE"]
[Tue Jul 21 08:24:05.581759 2026] [security2:error] [pid 411857:tid 412102] [client 187.125.243.197:57395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9W1S7ynBpLeKYztQPsPwAAAHE"]
[Tue Jul 21 08:24:05.877531 2026] [access_compat:error] [pid 411857:tid 412061] [client 162.241.63.68:14250] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:24:05.950440 2026] [security2:error] [pid 419508:tid 419655] [client 20.151.10.161:37504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/cfile.php"] [unique_id "al9W1VcagwCeNbomjVsQlgAAAaA"]
[Tue Jul 21 08:24:06.187959 2026] [security2:error] [pid 411857:tid 411999] [client 202.179.75.202:37848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9W1i7ynBpLeKYztQPsTQAAAAo"]
[Tue Jul 21 08:24:06.188066 2026] [security2:error] [pid 411857:tid 411999] [client 202.179.75.202:37848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9W1i7ynBpLeKYztQPsTQAAAAo"]
[Tue Jul 21 08:24:06.334147 2026] [security2:error] [pid 419508:tid 419703] [client 65.21.113.253:36992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9W1VcagwCeNbomjVsQkwAAAdA"]
[Tue Jul 21 08:24:06.466070 2026] [security2:error] [pid 419508:tid 419710] [client 20.151.10.161:37549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/class-wp.php"] [unique_id "al9W1lcagwCeNbomjVsQnwAAAdc"]
[Tue Jul 21 08:24:06.652725 2026] [core:error] [pid 419508:tid 419541] [remote 52.167.144.18:17445] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:24:06.652750 2026] [core:error] [pid 419508:tid 419541] [remote 52.167.144.18:17445] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:24:06.841320 2026] [security2:error] [pid 411857:tid 412084] [client 20.151.10.161:37551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/admin.php"] [unique_id "al9W1i7ynBpLeKYztQPsUwAAAF8"]
[Tue Jul 21 08:24:06.967248 2026] [security2:error] [pid 419508:tid 419692] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9W1lcagwCeNbomjVsQpQABxXk"]
[Tue Jul 21 08:24:07.060469 2026] [security2:error] [pid 418108:tid 418252] [client 213.152.186.163:57230] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9W1w0cxofL2J1zwYrFwgAAARY"]
[Tue Jul 21 08:24:07.060573 2026] [security2:error] [pid 418108:tid 418252] [client 213.152.186.163:57230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9W1w0cxofL2J1zwYrFwgAAARY"]
[Tue Jul 21 08:24:07.063971 2026] [security2:error] [pid 418108:tid 418254] [client 20.226.60.151:60656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/js.php"] [unique_id "al9W1w0cxofL2J1zwYrFwwAAARg"]
[Tue Jul 21 08:24:07.092282 2026] [security2:error] [pid 419508:tid 419585] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W11cagwCeNbomjVsQrAABr0w"]
[Tue Jul 21 08:24:07.092427 2026] [security2:error] [pid 419508:tid 419670] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W11cagwCeNbomjVsQrAABr0w"]
[Tue Jul 21 08:24:07.282397 2026] [security2:error] [pid 419508:tid 419673] [client 115.134.11.136:59721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W11cagwCeNbomjVsQtQAAAbI"]
[Tue Jul 21 08:24:07.282599 2026] [security2:error] [pid 419508:tid 419673] [client 115.134.11.136:59721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W11cagwCeNbomjVsQtQAAAbI"]
[Tue Jul 21 08:24:07.287541 2026] [security2:error] [pid 418108:tid 418298] [client 20.226.60.151:60617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/core.php"] [unique_id "al9W1w0cxofL2J1zwYrFxAAAAUQ"]
[Tue Jul 21 08:24:07.305362 2026] [core:error] [pid 419508:tid 419625] [remote 52.167.144.18:17445] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:24:07.305484 2026] [core:error] [pid 419508:tid 419625] [remote 52.167.144.18:17445] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:24:07.353101 2026] [security2:error] [pid 418108:tid 418276] [client 20.226.60.151:60560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/19.php"] [unique_id "al9W1w0cxofL2J1zwYrFxQAAAS4"]
[Tue Jul 21 08:24:07.390316 2026] [security2:error] [pid 418108:tid 418274] [client 65.21.113.253:58680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9W1g0cxofL2J1zwYrFwQAAASw"]
[Tue Jul 21 08:24:07.433166 2026] [core:error] [pid 419508:tid 419599] [remote 52.167.144.18:17445] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:24:07.433192 2026] [core:error] [pid 419508:tid 419599] [remote 52.167.144.18:17445] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:24:07.437842 2026] [security2:error] [pid 419508:tid 419662] [client 20.226.60.151:50135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/inc.php"] [unique_id "al9W11cagwCeNbomjVsQuQAAAac"]
[Tue Jul 21 08:24:07.500540 2026] [security2:error] [pid 411857:tid 412044] [client 20.151.10.161:37555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/aa2.php"] [unique_id "al9W1y7ynBpLeKYztQPsXAAAADc"]
[Tue Jul 21 08:24:07.814646 2026] [security2:error] [pid 419508:tid 419750] [client 20.151.10.161:37533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/ccou.php"] [unique_id "al9W11cagwCeNbomjVsQxQAAAf4"]
[Tue Jul 21 08:24:08.039506 2026] [security2:error] [pid 418108:tid 418337] [client 20.226.60.151:50170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9W2A0cxofL2J1zwYrFygAAAWs"]
[Tue Jul 21 08:24:08.125292 2026] [security2:error] [pid 411857:tid 412110] [client 20.151.10.161:37463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/dr.php"] [unique_id "al9W2C7ynBpLeKYztQPsZgAAAHk"]
[Tue Jul 21 08:24:08.449794 2026] [security2:error] [pid 419508:tid 419702] [client 4.194.217.15:9803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/xx.php"] [unique_id "al9W2FcagwCeNbomjVsQygAAAc8"]
[Tue Jul 21 08:24:08.454081 2026] [security2:error] [pid 419508:tid 419760] [client 20.151.10.161:37457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/xamp.php"] [unique_id "al9W2FcagwCeNbomjVsQywAAAgg"]
[Tue Jul 21 08:24:08.467262 2026] [security2:error] [pid 418108:tid 418366] [client 65.21.113.253:58680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9W1w0cxofL2J1zwYrFyQAAAYg"]
[Tue Jul 21 08:24:08.850796 2026] [security2:error] [pid 419508:tid 419676] [client 20.151.10.161:37452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/bless.php"] [unique_id "al9W2FcagwCeNbomjVsQ0AAAAbU"]
[Tue Jul 21 08:24:09.131856 2026] [security2:error] [pid 418108:tid 418312] [client 65.21.113.253:58680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9W2A0cxofL2J1zwYrFzgAAAVI"]
[Tue Jul 21 08:24:09.153214 2026] [security2:error] [pid 411857:tid 411998] [client 20.151.10.161:37409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/file46.php"] [unique_id "al9W2S7ynBpLeKYztQPsdQAAAAk"]
[Tue Jul 21 08:24:09.181272 2026] [security2:error] [pid 419508:tid 419552] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9W2VcagwCeNbomjVsQ0wABlCs"]
[Tue Jul 21 08:24:09.408987 2026] [security2:error] [pid 418108:tid 418279] [client 20.206.105.145:20116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/term.php"] [unique_id "al9W2Q0cxofL2J1zwYrF0gAAATE"]
[Tue Jul 21 08:24:09.458022 2026] [security2:error] [pid 411857:tid 412012] [client 20.151.10.161:37451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/eee.php"] [unique_id "al9W2S7ynBpLeKYztQPsewAAABc"]
[Tue Jul 21 08:24:09.612542 2026] [security2:error] [pid 418108:tid 418154] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9W2Q0cxofL2J1zwYrF1QABHCs"]
[Tue Jul 21 08:24:09.771716 2026] [security2:error] [pid 418108:tid 418266] [client 20.226.60.151:60554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9W2Q0cxofL2J1zwYrF1gAAASQ"]
[Tue Jul 21 08:24:09.787394 2026] [security2:error] [pid 419508:tid 419595] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/media.php"] [unique_id "al9W2VcagwCeNbomjVsQ2wABkFY"]
[Tue Jul 21 08:24:09.825325 2026] [security2:error] [pid 419508:tid 419684] [client 20.151.10.161:37472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/file25.php"] [unique_id "al9W2VcagwCeNbomjVsQ3AAAAb0"]
[Tue Jul 21 08:24:09.951601 2026] [security2:error] [pid 418108:tid 418113] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/images.php"] [unique_id "al9W2Q0cxofL2J1zwYrF2wABEAI"]
[Tue Jul 21 08:24:10.000519 2026] [security2:error] [pid 419508:tid 419728] [client 20.197.192.193:51904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bomexito.com.br"] [uri "/phpinfo.php1"] [unique_id "al9W2VcagwCeNbomjVsQ4AAAAek"]
[Tue Jul 21 08:24:10.100947 2026] [security2:error] [pid 418108:tid 418142] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/adminner.php"] [unique_id "al9W2g0cxofL2J1zwYrF3QABHR8"]
[Tue Jul 21 08:24:10.155761 2026] [security2:error] [pid 411857:tid 412001] [client 20.151.10.161:37467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/file48.php"] [unique_id "al9W2i7ynBpLeKYztQPshAAAAAw"]
[Tue Jul 21 08:24:10.161054 2026] [security2:error] [pid 419508:tid 419687] [client 4.194.217.15:3523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/xyn.php"] [unique_id "al9W2lcagwCeNbomjVsQ4wAAAcA"]
[Tue Jul 21 08:24:10.280230 2026] [security2:error] [pid 418108:tid 418179] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/admin.php"] [unique_id "al9W2g0cxofL2J1zwYrF3gABhUQ"]
[Tue Jul 21 08:24:10.480390 2026] [security2:error] [pid 419508:tid 419725] [client 20.151.10.161:37490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/file6.php"] [unique_id "al9W2lcagwCeNbomjVsQ5QAAAeY"]
[Tue Jul 21 08:24:10.484898 2026] [security2:error] [pid 418108:tid 418160] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/k.php"] [unique_id "al9W2g0cxofL2J1zwYrF4QABezE"]
[Tue Jul 21 08:24:10.594267 2026] [security2:error] [pid 418108:tid 418349] [client 65.21.113.253:58680] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9W2g0cxofL2J1zwYrF3AAAAXc"]
[Tue Jul 21 08:24:10.626168 2026] [security2:error] [pid 418108:tid 418166] [remote 216.73.216.184:20439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9W2g0cxofL2J1zwYrF4gABPTc"]
[Tue Jul 21 08:24:10.654324 2026] [security2:error] [pid 419508:tid 419610] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/x.php"] [unique_id "al9W2lcagwCeNbomjVsQ6QACCGU"]
[Tue Jul 21 08:24:10.745979 2026] [security2:error] [pid 419508:tid 419689] [client 20.220.225.223:11975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9W2lcagwCeNbomjVsQ6wAAAcI"]
[Tue Jul 21 08:24:10.809291 2026] [security2:error] [pid 418108:tid 418213] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wss.php"] [unique_id "al9W2g0cxofL2J1zwYrF4wABU2Y"]
[Tue Jul 21 08:24:10.834802 2026] [security2:error] [pid 419508:tid 419695] [client 20.151.10.161:37602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/a2.php"] [unique_id "al9W2lcagwCeNbomjVsQ7AAAAcg"]
[Tue Jul 21 08:24:10.972835 2026] [security2:error] [pid 418108:tid 418120] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/ty.php"] [unique_id "al9W2g0cxofL2J1zwYrF5QABGQk"]
[Tue Jul 21 08:24:11.139883 2026] [security2:error] [pid 418108:tid 418167] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/155.php"] [unique_id "al9W2w0cxofL2J1zwYrF5gABYjg"]
[Tue Jul 21 08:24:11.175573 2026] [security2:error] [pid 419508:tid 419670] [client 20.151.10.161:37531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/file15.php"] [unique_id "al9W21cagwCeNbomjVsQ8wAAAa8"]
[Tue Jul 21 08:24:11.311507 2026] [security2:error] [pid 418108:tid 418136] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/ops.php"] [unique_id "al9W2w0cxofL2J1zwYrF5wABbRk"]
[Tue Jul 21 08:24:11.404824 2026] [security2:error] [pid 411857:tid 412092] [client 20.226.60.151:56866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/miru1.php"] [unique_id "al9W2y7ynBpLeKYztQPsngAAAGc"]
[Tue Jul 21 08:24:11.472742 2026] [security2:error] [pid 419508:tid 419578] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/ingfo.php"] [unique_id "al9W21cagwCeNbomjVsQ9AABs0U"]
[Tue Jul 21 08:24:11.479861 2026] [security2:error] [pid 411857:tid 412007] [client 20.151.10.161:37473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/jp.php"] [unique_id "al9W2y7ynBpLeKYztQPsnwAAABI"]
[Tue Jul 21 08:24:11.629053 2026] [security2:error] [pid 418108:tid 418148] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/error_log.php"] [unique_id "al9W2w0cxofL2J1zwYrF6AABJiU"]
[Tue Jul 21 08:24:11.645194 2026] [security2:error] [pid 411857:tid 412033] [client 103.151.46.103:54217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9W2y7ynBpLeKYztQPsowAAACw"]
[Tue Jul 21 08:24:11.645361 2026] [security2:error] [pid 411857:tid 412033] [client 103.151.46.103:54217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9W2y7ynBpLeKYztQPsowAAACw"]
[Tue Jul 21 08:24:11.678735 2026] [security2:error] [pid 411857:tid 412002] [client 20.226.60.151:50056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/ss.php"] [unique_id "al9W2y7ynBpLeKYztQPspAAAAA0"]
[Tue Jul 21 08:24:11.776949 2026] [security2:error] [pid 419508:tid 419675] [client 20.151.10.161:37612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/f35.php"] [unique_id "al9W21cagwCeNbomjVsQ-QAAAbQ"]
[Tue Jul 21 08:24:11.780058 2026] [security2:error] [pid 418108:tid 418233] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/ok.php"] [unique_id "al9W2w0cxofL2J1zwYrF6QABc3o"]
[Tue Jul 21 08:24:11.822229 2026] [security2:error] [pid 419508:tid 419655] [client 185.8.106.219:11424] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "moadvogadas.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9W21cagwCeNbomjVsQ-gAAAaA"]
[Tue Jul 21 08:24:11.930379 2026] [security2:error] [pid 418108:tid 418139] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/mac.php"] [unique_id "al9W2w0cxofL2J1zwYrF6gABKBw"]
[Tue Jul 21 08:24:11.957036 2026] [security2:error] [pid 418108:tid 418303] [client 74.7.175.154:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dimasandrade1752092812156.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9W2w0cxofL2J1zwYrF6wABSVw"]
[Tue Jul 21 08:24:12.060466 2026] [security2:error] [pid 411857:tid 412042] [client 20.151.10.161:37494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-load.php"] [unique_id "al9W3C7ynBpLeKYztQPsqAAAADU"]
[Tue Jul 21 08:24:12.097328 2026] [security2:error] [pid 418108:tid 418153] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wefile.php"] [unique_id "al9W3A0cxofL2J1zwYrF7QABaSo"]
[Tue Jul 21 08:24:12.115724 2026] [security2:error] [pid 411857:tid 411906] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W3C7ynBpLeKYztQPsqgAAVi8"]
[Tue Jul 21 08:24:12.115905 2026] [security2:error] [pid 411857:tid 412075] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W3C7ynBpLeKYztQPsqgAAVi8"]
[Tue Jul 21 08:24:12.197511 2026] [security2:error] [pid 411857:tid 412105] [client 20.206.105.145:20135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/ha.php"] [unique_id "al9W3C7ynBpLeKYztQPsrAAAAHQ"]
[Tue Jul 21 08:24:12.272821 2026] [security2:error] [pid 419508:tid 419579] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9W3FcagwCeNbomjVsRCAAB3kY"]
[Tue Jul 21 08:24:12.375992 2026] [security2:error] [pid 419508:tid 419725] [client 20.151.10.161:37400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/xwpg.php"] [unique_id "al9W3FcagwCeNbomjVsRCgAAAeY"]
[Tue Jul 21 08:24:12.412476 2026] [security2:error] [pid 411857:tid 412003] [client 185.8.106.219:29554] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "moadvogadas.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9W3C7ynBpLeKYztQPsrgAAAA4"]
[Tue Jul 21 08:24:12.420871 2026] [security2:error] [pid 411857:tid 411987] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W3C7ynBpLeKYztQPsrwAANn8"]
[Tue Jul 21 08:24:12.421017 2026] [security2:error] [pid 411857:tid 412043] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W3C7ynBpLeKYztQPsrwAANn8"]
[Tue Jul 21 08:24:12.460544 2026] [autoindex:error] [pid 418108:tid 418235] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:12.663801 2026] [autoindex:error] [pid 418108:tid 418231] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:12.983981 2026] [security2:error] [pid 419508:tid 419735] [client 20.151.10.161:37629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/waf.php"] [unique_id "al9W3FcagwCeNbomjVsREgAAAfA"]
[Tue Jul 21 08:24:13.081794 2026] [security2:error] [pid 419508:tid 419753] [client 89.238.167.134:37450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9W3VcagwCeNbomjVsRFAAAAgE"]
[Tue Jul 21 08:24:13.081891 2026] [security2:error] [pid 419508:tid 419753] [client 89.238.167.134:37450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9W3VcagwCeNbomjVsRFAAAAgE"]
[Tue Jul 21 08:24:13.107481 2026] [security2:error] [pid 418108:tid 418293] [client 150.129.202.39:65089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W3Q0cxofL2J1zwYrF9AAAAT8"]
[Tue Jul 21 08:24:13.107607 2026] [security2:error] [pid 418108:tid 418293] [client 150.129.202.39:65089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W3Q0cxofL2J1zwYrF9AAAAT8"]
[Tue Jul 21 08:24:13.216986 2026] [core:error] [pid 419508:tid 419564] [remote 40.77.167.57:37322] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:24:13.217007 2026] [core:error] [pid 419508:tid 419564] [remote 40.77.167.57:37322] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:24:13.324967 2026] [security2:error] [pid 411857:tid 412070] [client 20.151.10.161:37552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/xstelth.php"] [unique_id "al9W3S7ynBpLeKYztQPsvwAAAFE"]
[Tue Jul 21 08:24:13.384629 2026] [security2:error] [pid 419508:tid 419718] [client 20.226.60.151:50114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/min.php"] [unique_id "al9W3VcagwCeNbomjVsRGAAAAd8"]
[Tue Jul 21 08:24:13.433100 2026] [security2:error] [pid 411857:tid 412115] [client 4.194.217.15:3737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/y.php"] [unique_id "al9W3S7ynBpLeKYztQPswQAAAH4"]
[Tue Jul 21 08:24:13.438432 2026] [security2:error] [pid 418108:tid 418265] [client 20.197.195.24:56433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9W3Q0cxofL2J1zwYrF9QAAASM"]
[Tue Jul 21 08:24:13.460235 2026] [security2:error] [pid 411857:tid 419457] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9W3S7ynBpLeKYztQPswwAAZos"]
[Tue Jul 21 08:24:13.460383 2026] [security2:error] [pid 411857:tid 412091] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9W3S7ynBpLeKYztQPswwAAZos"]
[Tue Jul 21 08:24:13.513115 2026] [security2:error] [pid 411857:tid 412001] [client 20.206.105.145:20267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/hur.php"] [unique_id "al9W3S7ynBpLeKYztQPsxAAAAAw"]
[Tue Jul 21 08:24:13.541305 2026] [security2:error] [pid 411857:tid 412079] [client 20.197.195.24:56440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9W3S7ynBpLeKYztQPsxQAAAFo"]
[Tue Jul 21 08:24:13.555124 2026] [security2:error] [pid 419508:tid 419649] [client 195.49.128.211:59695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9W3VcagwCeNbomjVsRGgAAAZo"]
[Tue Jul 21 08:24:13.555259 2026] [security2:error] [pid 419508:tid 419649] [client 195.49.128.211:59695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9W3VcagwCeNbomjVsRGgAAAZo"]
[Tue Jul 21 08:24:13.565628 2026] [security2:error] [pid 419508:tid 419672] [client 20.197.195.24:17011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/media.php"] [unique_id "al9W3VcagwCeNbomjVsRGwAAAbE"]
[Tue Jul 21 08:24:13.576599 2026] [security2:error] [pid 411857:tid 412108] [client 20.197.195.24:18303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9W3C7ynBpLeKYztQPssgAAAHc"]
[Tue Jul 21 08:24:13.598920 2026] [security2:error] [pid 419508:tid 419639] [client 117.213.202.34:51233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W3FcagwCeNbomjVsRDQAAAZA"]
[Tue Jul 21 08:24:13.599072 2026] [security2:error] [pid 419508:tid 419639] [client 117.213.202.34:51233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W3FcagwCeNbomjVsRDQAAAZA"]
[Tue Jul 21 08:24:13.626860 2026] [security2:error] [pid 419508:tid 419668] [client 20.197.195.24:16992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/images.php"] [unique_id "al9W3VcagwCeNbomjVsRHAAAAa0"]
[Tue Jul 21 08:24:13.638378 2026] [security2:error] [pid 419508:tid 419613] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9W3VcagwCeNbomjVsRHQABlGg"]
[Tue Jul 21 08:24:13.657402 2026] [security2:error] [pid 419508:tid 419708] [client 20.151.10.161:37453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-links.php"] [unique_id "al9W3VcagwCeNbomjVsRHgAAAdU"]
[Tue Jul 21 08:24:13.695862 2026] [security2:error] [pid 419508:tid 419681] [client 20.197.195.24:56986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/gecko.php"] [unique_id "al9W3VcagwCeNbomjVsRHwAAAbo"]
[Tue Jul 21 08:24:13.733486 2026] [security2:error] [pid 419508:tid 419655] [client 20.197.195.24:56420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/82.php"] [unique_id "al9W3VcagwCeNbomjVsRIgAAAaA"]
[Tue Jul 21 08:24:13.768887 2026] [security2:error] [pid 419508:tid 419738] [client 20.197.195.24:56395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/admin.php"] [unique_id "al9W3VcagwCeNbomjVsRJAAAAfM"]
[Tue Jul 21 08:24:13.800480 2026] [security2:error] [pid 419508:tid 419746] [client 20.197.195.24:16065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/adminner.php"] [unique_id "al9W3VcagwCeNbomjVsRJQAAAfo"]
[Tue Jul 21 08:24:13.812538 2026] [security2:error] [pid 419508:tid 419638] [client 20.197.195.24:17013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/admin.php"] [unique_id "al9W3VcagwCeNbomjVsRJgAAAY8"]
[Tue Jul 21 08:24:13.838149 2026] [security2:error] [pid 419508:tid 419667] [client 20.197.195.24:56961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/k.php"] [unique_id "al9W3VcagwCeNbomjVsRJwAAAaw"]
[Tue Jul 21 08:24:13.937244 2026] [security2:error] [pid 419508:tid 419710] [client 20.151.10.161:37465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9W3VcagwCeNbomjVsRKQAAAdc"]
[Tue Jul 21 08:24:13.939049 2026] [security2:error] [pid 419508:tid 419717] [client 20.197.195.24:16963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/blurbs.php"] [unique_id "al9W3VcagwCeNbomjVsRKgAAAd4"]
[Tue Jul 21 08:24:14.034618 2026] [security2:error] [pid 419508:tid 419750] [client 20.197.195.24:16991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/bajah.php"] [unique_id "al9W3lcagwCeNbomjVsRLgAAAf4"]
[Tue Jul 21 08:24:14.087510 2026] [security2:error] [pid 418108:tid 418352] [client 20.197.195.24:17002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/a.php"] [unique_id "al9W3g0cxofL2J1zwYrF-AAAAXo"]
[Tue Jul 21 08:24:14.103604 2026] [security2:error] [pid 418108:tid 418299] [client 20.197.195.24:17015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/edit.php"] [unique_id "al9W3g0cxofL2J1zwYrF-QAAAUU"]
[Tue Jul 21 08:24:14.134127 2026] [security2:error] [pid 419508:tid 419684] [client 14.245.224.124:64853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9W3lcagwCeNbomjVsRMAAAAb0"]
[Tue Jul 21 08:24:14.134250 2026] [security2:error] [pid 419508:tid 419684] [client 14.245.224.124:64853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9W3lcagwCeNbomjVsRMAAAAb0"]
[Tue Jul 21 08:24:14.158570 2026] [security2:error] [pid 411857:tid 412000] [client 20.197.195.24:56975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/hosty.php"] [unique_id "al9W3i7ynBpLeKYztQPsywAAAAs"]
[Tue Jul 21 08:24:14.191077 2026] [security2:error] [pid 419508:tid 419737] [client 185.8.106.219:11436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.moadvogadas.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9W3lcagwCeNbomjVsRMgAAAfI"]
[Tue Jul 21 08:24:14.222881 2026] [security2:error] [pid 411857:tid 412111] [client 20.197.195.24:56992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/k.php"] [unique_id "al9W3i7ynBpLeKYztQPszQAAAHo"]
[Tue Jul 21 08:24:14.242798 2026] [security2:error] [pid 418108:tid 418309] [client 20.197.195.24:18319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9W3g0cxofL2J1zwYrF-gAAAU8"]
[Tue Jul 21 08:24:14.259428 2026] [security2:error] [pid 418108:tid 418248] [client 20.197.195.24:17023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/aaa.php"] [unique_id "al9W3g0cxofL2J1zwYrF-wAAARI"]
[Tue Jul 21 08:24:14.266910 2026] [security2:error] [pid 418108:tid 418170] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/like.php"] [unique_id "al9W3g0cxofL2J1zwYrF_AABSjs"]
[Tue Jul 21 08:24:14.286107 2026] [security2:error] [pid 418108:tid 418274] [client 20.197.195.24:17012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/file5.php"] [unique_id "al9W3g0cxofL2J1zwYrF_gAAASw"]
[Tue Jul 21 08:24:14.306123 2026] [security2:error] [pid 418108:tid 418278] [client 20.197.195.24:56979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/222.php"] [unique_id "al9W3g0cxofL2J1zwYrGAAAAATA"]
[Tue Jul 21 08:24:14.323197 2026] [security2:error] [pid 419508:tid 419703] [client 20.197.195.24:17021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/test.php"] [unique_id "al9W3lcagwCeNbomjVsRNQAAAdA"]
[Tue Jul 21 08:24:14.325197 2026] [security2:error] [pid 419508:tid 419734] [client 20.151.10.161:37395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betoperroygrill.com.br"] [uri "/aaa.php"] [unique_id "al9W3lcagwCeNbomjVsRNgAAAe8"]
[Tue Jul 21 08:24:14.338877 2026] [security2:error] [pid 419508:tid 419723] [client 20.197.195.24:56987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/aaa.php"] [unique_id "al9W3lcagwCeNbomjVsRNwAAAeQ"]
[Tue Jul 21 08:24:14.379892 2026] [security2:error] [pid 411857:tid 412089] [client 20.197.195.24:16967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/11.php"] [unique_id "al9W3i7ynBpLeKYztQPszwAAAGQ"]
[Tue Jul 21 08:24:14.407943 2026] [security2:error] [pid 411857:tid 412025] [client 20.197.195.24:6477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/mac.php"] [unique_id "al9W3i7ynBpLeKYztQPs0AAAACQ"]
[Tue Jul 21 08:24:14.416770 2026] [security2:error] [pid 419508:tid 419510] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/.well-known/about.php"] [unique_id "al9W3lcagwCeNbomjVsROAABtwE"]
[Tue Jul 21 08:24:14.431564 2026] [security2:error] [pid 419508:tid 419754] [client 20.197.195.24:56981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/chosen.php"] [unique_id "al9W3lcagwCeNbomjVsROQAAAgI"]
[Tue Jul 21 08:24:14.447399 2026] [security2:error] [pid 419508:tid 419688] [client 20.197.195.24:57002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/cream1.php"] [unique_id "al9W3lcagwCeNbomjVsROgAAAcE"]
[Tue Jul 21 08:24:14.528627 2026] [security2:error] [pid 419508:tid 419639] [client 20.197.192.193:5959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/dp.php"] [unique_id "al9W3lcagwCeNbomjVsRPwAAAZA"]
[Tue Jul 21 08:24:14.564222 2026] [security2:error] [pid 419508:tid 419708] [client 20.226.60.151:60646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9W3lcagwCeNbomjVsRQQAAAdU"]
[Tue Jul 21 08:24:14.634838 2026] [security2:error] [pid 419508:tid 419748] [client 20.197.195.24:61147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/media.php"] [unique_id "al9W3lcagwCeNbomjVsRQgAAAfw"]
[Tue Jul 21 08:24:14.764350 2026] [security2:error] [pid 419508:tid 419685] [client 20.206.105.145:20166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/h02ugyh.php"] [unique_id "al9W3lcagwCeNbomjVsRRAAAAb4"]
[Tue Jul 21 08:24:14.854565 2026] [security2:error] [pid 418108:tid 418209] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9W3g0cxofL2J1zwYrGAQABXGI"]
[Tue Jul 21 08:24:14.883680 2026] [security2:error] [pid 418108:tid 418285] [client 20.220.225.223:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/x.php"] [unique_id "al9W3g0cxofL2J1zwYrGAgAAATc"]
[Tue Jul 21 08:24:14.903451 2026] [security2:error] [pid 419508:tid 419721] [client 185.8.106.219:11450] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "moadvogadas.com"] [uri "/"] [unique_id "al9W3lcagwCeNbomjVsRSAAAAeI"]
[Tue Jul 21 08:24:15.083964 2026] [autoindex:error] [pid 419508:tid 419522] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:15.089354 2026] [security2:error] [pid 411857:tid 412083] [client 20.197.195.24:18303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/images.php"] [unique_id "al9W3y7ynBpLeKYztQPs2wAAAF4"]
[Tue Jul 21 08:24:15.120162 2026] [security2:error] [pid 411857:tid 412073] [client 152.59.34.51:50791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9W3y7ynBpLeKYztQPs3QAAAFQ"]
[Tue Jul 21 08:24:15.120250 2026] [security2:error] [pid 411857:tid 412073] [client 152.59.34.51:50791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9W3y7ynBpLeKYztQPs3QAAAFQ"]
[Tue Jul 21 08:24:15.139585 2026] [security2:error] [pid 419508:tid 419733] [client 20.197.195.24:57016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/dr.php"] [unique_id "al9W31cagwCeNbomjVsRTQAAAe4"]
[Tue Jul 21 08:24:15.143926 2026] [security2:error] [pid 419508:tid 419759] [client 151.63.71.144:56873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9W31cagwCeNbomjVsRTgAAAgc"]
[Tue Jul 21 08:24:15.144272 2026] [security2:error] [pid 419508:tid 419759] [client 151.63.71.144:56873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9W31cagwCeNbomjVsRTgAAAgc"]
[Tue Jul 21 08:24:15.201435 2026] [security2:error] [pid 419508:tid 419700] [client 74.7.230.33:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "leilagonzagajuren1782586610843.0711679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9W31cagwCeNbomjVsRUAABzVc"]
[Tue Jul 21 08:24:15.309934 2026] [security2:error] [pid 419508:tid 419760] [client 20.197.195.24:61070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/gecko.php"] [unique_id "al9W31cagwCeNbomjVsRVAAAAgg"]
[Tue Jul 21 08:24:15.340826 2026] [security2:error] [pid 418108:tid 418281] [client 20.226.60.151:60606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9W3w0cxofL2J1zwYrGBAAAATM"]
[Tue Jul 21 08:24:15.368142 2026] [autoindex:error] [pid 419508:tid 419590] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:15.401438 2026] [security2:error] [pid 419508:tid 419684] [client 20.197.195.24:56423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/x.php"] [unique_id "al9W31cagwCeNbomjVsRVQAAAb0"]
[Tue Jul 21 08:24:15.518536 2026] [security2:error] [pid 419508:tid 419631] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/pucci.php"] [unique_id "al9W31cagwCeNbomjVsRWwACBHo"]
[Tue Jul 21 08:24:15.523866 2026] [security2:error] [pid 419508:tid 419766] [client 20.197.195.24:57007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/155.php"] [unique_id "al9W31cagwCeNbomjVsRXAAAAg4"]
[Tue Jul 21 08:24:15.642113 2026] [security2:error] [pid 419508:tid 419678] [client 20.197.195.24:56395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/ops.php"] [unique_id "al9W31cagwCeNbomjVsRXgAAAbc"]
[Tue Jul 21 08:24:15.681975 2026] [autoindex:error] [pid 419508:tid 419521] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:15.828871 2026] [security2:error] [pid 418108:tid 418333] [client 20.197.195.24:16964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/file31.php"] [unique_id "al9W3w0cxofL2J1zwYrGCwAAAWc"]
[Tue Jul 21 08:24:15.871714 2026] [autoindex:error] [pid 419508:tid 419572] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:15.943567 2026] [security2:error] [pid 411857:tid 412043] [client 20.197.195.24:16995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/file6.php"] [unique_id "al9W3y7ynBpLeKYztQPs6QAAADY"]
[Tue Jul 21 08:24:16.016523 2026] [security2:error] [pid 419508:tid 419679] [client 187.125.243.197:57892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9W4FcagwCeNbomjVsRYwAAAbg"]
[Tue Jul 21 08:24:16.016653 2026] [security2:error] [pid 419508:tid 419679] [client 187.125.243.197:57892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9W4FcagwCeNbomjVsRYwAAAbg"]
[Tue Jul 21 08:24:16.040706 2026] [security2:error] [pid 419508:tid 419580] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-temp.php"] [unique_id "al9W4FcagwCeNbomjVsRZAABokc"]
[Tue Jul 21 08:24:16.135864 2026] [security2:error] [pid 411857:tid 412039] [client 20.226.60.151:60576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9W4C7ynBpLeKYztQPs7AAAADI"]
[Tue Jul 21 08:24:16.162758 2026] [core:error] [pid 419508:tid 419628] [remote 40.77.167.14:50313] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:24:16.162779 2026] [core:error] [pid 419508:tid 419628] [remote 40.77.167.14:50313] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:24:16.220085 2026] [autoindex:error] [pid 419508:tid 419575] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:16.229950 2026] [security2:error] [pid 419508:tid 419665] [client 114.119.138.99:48505] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "benattiodontologia.com.br"] [uri "/dentes-amarelados-6-maneiras-de-evitar-este-mal"] [unique_id "al9W4FcagwCeNbomjVsRbQAAAao"], referer: https://benattiodontologia.com.br/dentes-amarelados-6-maneiras-de-evitar-este-mal
[Tue Jul 21 08:24:16.274524 2026] [security2:error] [pid 419508:tid 419685] [client 20.226.60.151:60564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9W4FcagwCeNbomjVsRbgAAAb4"]
[Tue Jul 21 08:24:16.393076 2026] [security2:error] [pid 419508:tid 419731] [client 20.197.195.24:57008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/adminfuns.php"] [unique_id "al9W4FcagwCeNbomjVsRcgAAAew"]
[Tue Jul 21 08:24:16.431683 2026] [security2:error] [pid 419508:tid 419733] [client 20.197.195.24:56388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/goods.php"] [unique_id "al9W4FcagwCeNbomjVsRcwAAAe4"]
[Tue Jul 21 08:24:16.444781 2026] [security2:error] [pid 419508:tid 419607] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/xmu.php"] [unique_id "al9W4FcagwCeNbomjVsRdAACB2I"]
[Tue Jul 21 08:24:16.460151 2026] [security2:error] [pid 419508:tid 419726] [client 20.197.195.24:16987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/100.php"] [unique_id "al9W4FcagwCeNbomjVsRdgAAAec"]
[Tue Jul 21 08:24:16.480569 2026] [security2:error] [pid 411857:tid 411998] [client 20.197.195.24:57001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/about.php"] [unique_id "al9W4C7ynBpLeKYztQPs8QAAAAk"]
[Tue Jul 21 08:24:16.500841 2026] [security2:error] [pid 419508:tid 419747] [client 20.197.195.24:56401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/about.php"] [unique_id "al9W4FcagwCeNbomjVsRdwAAAfs"]
[Tue Jul 21 08:24:16.510926 2026] [security2:error] [pid 419508:tid 419666] [client 20.197.195.24:16984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/admin.php"] [unique_id "al9W4FcagwCeNbomjVsReAAAAas"]
[Tue Jul 21 08:24:16.530964 2026] [security2:error] [pid 419508:tid 419689] [client 20.197.195.24:56389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/admin.php"] [unique_id "al9W4FcagwCeNbomjVsRegAAAcI"]
[Tue Jul 21 08:24:16.556115 2026] [security2:error] [pid 419508:tid 419706] [client 20.197.195.24:56418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/themes.php"] [unique_id "al9W4FcagwCeNbomjVsRewAAAdM"]
[Tue Jul 21 08:24:16.563431 2026] [security2:error] [pid 419508:tid 419737] [client 20.226.60.151:60544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/albin.php"] [unique_id "al9W4FcagwCeNbomjVsRfAAAAfI"]
[Tue Jul 21 08:24:16.600068 2026] [security2:error] [pid 419508:tid 419647] [client 20.197.195.24:61153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/82.php"] [unique_id "al9W4FcagwCeNbomjVsRfwAAAZg"]
[Tue Jul 21 08:24:16.853696 2026] [security2:error] [pid 419508:tid 419653] [client 20.226.60.151:56949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/aa.php"] [unique_id "al9W4FcagwCeNbomjVsRggAAAZ4"]
[Tue Jul 21 08:24:16.891102 2026] [security2:error] [pid 419508:tid 419700] [client 202.179.75.202:52650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9W4FcagwCeNbomjVsRhAAAAc0"]
[Tue Jul 21 08:24:16.891206 2026] [security2:error] [pid 419508:tid 419700] [client 202.179.75.202:52650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9W4FcagwCeNbomjVsRhAAAAc0"]
[Tue Jul 21 08:24:16.978873 2026] [security2:error] [pid 419508:tid 419621] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9W4FcagwCeNbomjVsRiAABwXA"]
[Tue Jul 21 08:24:17.051883 2026] [security2:error] [pid 419508:tid 419693] [client 20.226.60.151:60612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/cilus.php"] [unique_id "al9W4VcagwCeNbomjVsRigAAAcY"]
[Tue Jul 21 08:24:17.128051 2026] [security2:error] [pid 419508:tid 419549] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/puc.php"] [unique_id "al9W4VcagwCeNbomjVsRjAABoig"]
[Tue Jul 21 08:24:17.142044 2026] [security2:error] [pid 419508:tid 419708] [client 20.206.105.145:20193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/seiso.php"] [unique_id "al9W4VcagwCeNbomjVsRjQAAAdU"]
[Tue Jul 21 08:24:17.173470 2026] [security2:error] [pid 419508:tid 419662] [client 20.197.195.24:56406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/.well-known/about.php"] [unique_id "al9W4VcagwCeNbomjVsRlQAAAac"]
[Tue Jul 21 08:24:17.283417 2026] [security2:error] [pid 419508:tid 419599] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/themes.php"] [unique_id "al9W4VcagwCeNbomjVsRowAB6lo"]
[Tue Jul 21 08:24:17.434646 2026] [security2:error] [pid 411857:tid 412091] [client 20.197.195.24:6475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9W4S7ynBpLeKYztQPs_QAAAGY"]
[Tue Jul 21 08:24:17.447290 2026] [autoindex:error] [pid 419508:tid 419573] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:17.481619 2026] [security2:error] [pid 411857:tid 412001] [client 20.197.195.24:17016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wefile.php"] [unique_id "al9W4S7ynBpLeKYztQPs_gAAAAw"]
[Tue Jul 21 08:24:17.539894 2026] [security2:error] [pid 419508:tid 419737] [client 20.197.195.24:56967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9W4VcagwCeNbomjVsRygAAAfI"]
[Tue Jul 21 08:24:17.607529 2026] [security2:error] [pid 411857:tid 412004] [client 65.21.113.253:51826] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9W4S7ynBpLeKYztQPs-AAAAA8"]
[Tue Jul 21 08:24:17.615305 2026] [security2:error] [pid 419508:tid 419556] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/8.php"] [unique_id "al9W4VcagwCeNbomjVsRzQABmC8"]
[Tue Jul 21 08:24:17.704726 2026] [security2:error] [pid 419508:tid 419591] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W4VcagwCeNbomjVsRzgABnlI"]
[Tue Jul 21 08:24:17.704921 2026] [security2:error] [pid 419508:tid 419653] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W4VcagwCeNbomjVsRzgABnlI"]
[Tue Jul 21 08:24:17.705456 2026] [security2:error] [pid 419508:tid 419759] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9W4VcagwCeNbomjVsRrgACB2E"]
[Tue Jul 21 08:24:17.765941 2026] [security2:error] [pid 419508:tid 419615] [remote 20.151.10.161:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "expertemrecheios.com"] [uri "/1.php"] [unique_id "al9W4VcagwCeNbomjVsR0gACBWo"]
[Tue Jul 21 08:24:17.766033 2026] [security2:error] [pid 419508:tid 419615] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/1.php"] [unique_id "al9W4VcagwCeNbomjVsR0gACBWo"]
[Tue Jul 21 08:24:18.001130 2026] [security2:error] [pid 419508:tid 419672] [client 20.197.195.24:56972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9W4lcagwCeNbomjVsR1QAAAbE"]
[Tue Jul 21 08:24:18.085377 2026] [security2:error] [pid 419508:tid 419542] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/100.php"] [unique_id "al9W4lcagwCeNbomjVsR1wAB1SE"]
[Tue Jul 21 08:24:18.100004 2026] [security2:error] [pid 419508:tid 419738] [client 20.197.195.24:56390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/8.php"] [unique_id "al9W4lcagwCeNbomjVsR2AAAAfM"]
[Tue Jul 21 08:24:18.132229 2026] [security2:error] [pid 419508:tid 419662] [client 20.197.195.24:16073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-content/admin.php"] [unique_id "al9W4lcagwCeNbomjVsR2QAAAac"]
[Tue Jul 21 08:24:18.161934 2026] [security2:error] [pid 419508:tid 419645] [client 115.134.11.136:60199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W4lcagwCeNbomjVsR2gAAAZY"]
[Tue Jul 21 08:24:18.162776 2026] [security2:error] [pid 419508:tid 419645] [client 115.134.11.136:60199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W4lcagwCeNbomjVsR2gAAAZY"]
[Tue Jul 21 08:24:18.179662 2026] [security2:error] [pid 419508:tid 419681] [client 20.226.60.151:60642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/gptsh.php"] [unique_id "al9W4lcagwCeNbomjVsR3AAAAbo"]
[Tue Jul 21 08:24:18.199854 2026] [security2:error] [pid 419508:tid 419721] [client 20.197.195.24:56445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/f6.php"] [unique_id "al9W4lcagwCeNbomjVsR3QAAAeI"]
[Tue Jul 21 08:24:18.218955 2026] [security2:error] [pid 419508:tid 419717] [client 20.197.195.24:56964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/inputs.php"] [unique_id "al9W4lcagwCeNbomjVsR4AAAAd4"]
[Tue Jul 21 08:24:18.250963 2026] [security2:error] [pid 419508:tid 419651] [client 20.197.195.24:16965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/inputs.php"] [unique_id "al9W4lcagwCeNbomjVsR4gAAAZw"]
[Tue Jul 21 08:24:18.252438 2026] [security2:error] [pid 419508:tid 419603] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/about.php"] [unique_id "al9W4lcagwCeNbomjVsR4wABu14"]
[Tue Jul 21 08:24:18.306472 2026] [security2:error] [pid 411857:tid 412028] [client 20.197.195.24:56434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/classwithtostring.php"] [unique_id "al9W4i7ynBpLeKYztQPtCAAAACc"]
[Tue Jul 21 08:24:18.406722 2026] [security2:error] [pid 419508:tid 419706] [client 20.197.195.24:57012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9W4lcagwCeNbomjVsR5gAAAdM"]
[Tue Jul 21 08:24:18.444768 2026] [security2:error] [pid 419508:tid 419565] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/about.php"] [unique_id "al9W4lcagwCeNbomjVsR5wABoDg"]
[Tue Jul 21 08:24:18.488254 2026] [security2:error] [pid 419508:tid 419726] [client 20.197.195.24:16971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-blog.php"] [unique_id "al9W4lcagwCeNbomjVsR6QAAAec"]
[Tue Jul 21 08:24:18.552593 2026] [security2:error] [pid 419508:tid 419757] [client 213.152.186.163:44072] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9W4lcagwCeNbomjVsR7gAAAgU"]
[Tue Jul 21 08:24:18.552683 2026] [security2:error] [pid 419508:tid 419757] [client 213.152.186.163:44072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9W4lcagwCeNbomjVsR7gAAAgU"]
[Tue Jul 21 08:24:18.594717 2026] [security2:error] [pid 419508:tid 419590] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/admin.php"] [unique_id "al9W4lcagwCeNbomjVsR8AABoVE"]
[Tue Jul 21 08:24:18.799581 2026] [security2:error] [pid 419508:tid 419521] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/admin.php"] [unique_id "al9W4lcagwCeNbomjVsR9gABsww"]
[Tue Jul 21 08:24:18.832276 2026] [proxy:error] [pid 419508:tid 419572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:24:18.832358 2026] [proxy_http:error] [pid 419508:tid 419572] [remote 87.236.176.233:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.infoalert.com.br:2095
[Tue Jul 21 08:24:18.833223 2026] [proxy:error] [pid 419508:tid 419572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:24:18.833270 2026] [proxy_http:error] [pid 419508:tid 419572] [remote 87.236.176.233:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.infoalert.com.br:2095
[Tue Jul 21 08:24:18.951463 2026] [security2:error] [pid 418108:tid 418251] [client 20.197.195.24:16985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-content/admin.php"] [unique_id "al9W4g0cxofL2J1zwYrGEQAAARU"]
[Tue Jul 21 08:24:19.037197 2026] [security2:error] [pid 411857:tid 412063] [client 20.206.105.145:20168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/155.php"] [unique_id "al9W4y7ynBpLeKYztQPtDwAAAEo"]
[Tue Jul 21 08:24:19.074558 2026] [security2:error] [pid 419508:tid 419580] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/edit.php"] [unique_id "al9W41cagwCeNbomjVsR-QABr0c"]
[Tue Jul 21 08:24:19.151114 2026] [security2:error] [pid 419508:tid 419753] [client 223.181.60.88:29686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9W41cagwCeNbomjVsR-gAAAgE"]
[Tue Jul 21 08:24:19.151234 2026] [security2:error] [pid 419508:tid 419753] [client 223.181.60.88:29686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9W41cagwCeNbomjVsR-gAAAgE"]
[Tue Jul 21 08:24:19.301041 2026] [security2:error] [pid 419508:tid 419699] [client 20.197.195.24:16064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/ms-edit.php"] [unique_id "al9W41cagwCeNbomjVsR_gAAAcw"]
[Tue Jul 21 08:24:19.363228 2026] [security2:error] [pid 419508:tid 419607] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-content/admin.php"] [unique_id "al9W41cagwCeNbomjVsSAgABu2I"]
[Tue Jul 21 08:24:19.368630 2026] [security2:error] [pid 419508:tid 419661] [client 20.197.195.24:56996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/cgi-bin/index.php"] [unique_id "al9W41cagwCeNbomjVsSBQAAAaY"]
[Tue Jul 21 08:24:19.465730 2026] [security2:error] [pid 419508:tid 419734] [client 20.226.60.151:60555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/rithin.php"] [unique_id "al9W41cagwCeNbomjVsSCAAAAe8"]
[Tue Jul 21 08:24:19.544489 2026] [security2:error] [pid 419508:tid 419621] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/f6.php"] [unique_id "al9W41cagwCeNbomjVsSCwABwHA"]
[Tue Jul 21 08:24:19.693199 2026] [security2:error] [pid 419508:tid 419592] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/inputs.php"] [unique_id "al9W41cagwCeNbomjVsSEAAB5FM"]
[Tue Jul 21 08:24:19.719347 2026] [security2:error] [pid 419508:tid 419642] [client 20.197.195.24:56994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/BDKR28WP.php"] [unique_id "al9W41cagwCeNbomjVsSEgAAAZM"]
[Tue Jul 21 08:24:19.889986 2026] [security2:error] [pid 419508:tid 419587] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/inputs.php"] [unique_id "al9W41cagwCeNbomjVsSFgABtU4"]
[Tue Jul 21 08:24:20.045302 2026] [security2:error] [pid 419508:tid 419634] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/av.php"] [unique_id "al9W5FcagwCeNbomjVsSGQABs30"]
[Tue Jul 21 08:24:20.096210 2026] [security2:error] [pid 418108:tid 418353] [client 103.151.46.103:54707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9W5A0cxofL2J1zwYrGGgAAAXs"]
[Tue Jul 21 08:24:20.135788 2026] [security2:error] [pid 418108:tid 418345] [client 20.197.195.24:18348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/admin.php"] [unique_id "al9W5A0cxofL2J1zwYrGGwAAAXM"]
[Tue Jul 21 08:24:20.156463 2026] [security2:error] [pid 419508:tid 419553] [remote 114.34.90.9:43330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9W5FcagwCeNbomjVsSHAACDiw"]
[Tue Jul 21 08:24:20.205649 2026] [security2:error] [pid 419508:tid 419516] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/classwithtostring.php"] [unique_id "al9W5FcagwCeNbomjVsSHgAB7gc"]
[Tue Jul 21 08:24:20.358403 2026] [security2:error] [pid 419508:tid 419731] [client 20.197.195.24:57019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/abcd.php"] [unique_id "al9W5FcagwCeNbomjVsSIAAAAew"]
[Tue Jul 21 08:24:20.382479 2026] [security2:error] [pid 419508:tid 419625] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9W5FcagwCeNbomjVsSIQAB1XQ"]
[Tue Jul 21 08:24:20.390011 2026] [security2:error] [pid 419508:tid 419666] [client 20.226.60.151:62352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/122.php"] [unique_id "al9W5FcagwCeNbomjVsSIwAAAas"]
[Tue Jul 21 08:24:20.531729 2026] [security2:error] [pid 419508:tid 419618] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-blog.php"] [unique_id "al9W5FcagwCeNbomjVsSJwABnG0"]
[Tue Jul 21 08:24:20.633777 2026] [security2:error] [pid 418108:tid 418125] [remote 216.73.216.184:20439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9W5A0cxofL2J1zwYrGHQABOg4"]
[Tue Jul 21 08:24:20.695748 2026] [autoindex:error] [pid 419508:tid 419630] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:20.871996 2026] [security2:error] [pid 419508:tid 419636] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-content/admin.php"] [unique_id "al9W5FcagwCeNbomjVsSLwACB38"]
[Tue Jul 21 08:24:21.025566 2026] [security2:error] [pid 419508:tid 419616] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/adminfuns.php"] [unique_id "al9W5VcagwCeNbomjVsSPgABxms"]
[Tue Jul 21 08:24:21.072311 2026] [security2:error] [pid 411857:tid 412039] [client 20.197.195.24:56980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/file15.php"] [unique_id "al9W5S7ynBpLeKYztQPtKwAAADI"]
[Tue Jul 21 08:24:21.215517 2026] [security2:error] [pid 418108:tid 418353] [client 103.151.46.103:54707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9W5A0cxofL2J1zwYrGGgAAAXs"]
[Tue Jul 21 08:24:21.216176 2026] [security2:error] [pid 419508:tid 419520] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/goods.php"] [unique_id "al9W5VcagwCeNbomjVsSQgAB7As"]
[Tue Jul 21 08:24:21.286686 2026] [security2:error] [pid 419508:tid 419665] [client 20.197.195.24:56443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/jp.php"] [unique_id "al9W5VcagwCeNbomjVsSQwAAAao"]
[Tue Jul 21 08:24:21.466008 2026] [security2:error] [pid 419508:tid 419566] [remote 20.75.217.64:10268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/wp-login.php"] [unique_id "al9W5VcagwCeNbomjVsSRgAB2zk"]
[Tue Jul 21 08:24:21.561595 2026] [security2:error] [pid 411857:tid 411960] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/lara/phpinfo.php"] [unique_id "al9W5S7ynBpLeKYztQPtMgAAZWQ"]
[Tue Jul 21 08:24:21.633003 2026] [security2:error] [pid 419508:tid 419699] [client 20.197.195.24:16077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/f35.php"] [unique_id "al9W5VcagwCeNbomjVsSRwAAAcw"]
[Tue Jul 21 08:24:21.856207 2026] [security2:error] [pid 419508:tid 419602] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/ms-edit.php"] [unique_id "al9W5VcagwCeNbomjVsSSgABvF0"]
[Tue Jul 21 08:24:21.903689 2026] [security2:error] [pid 419508:tid 419706] [client 20.226.60.151:60614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/fffm.php"] [unique_id "al9W5VcagwCeNbomjVsSTQAAAdM"]
[Tue Jul 21 08:24:21.923557 2026] [security2:error] [pid 419508:tid 419638] [client 20.197.195.24:56414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-load.php"] [unique_id "al9W5VcagwCeNbomjVsSTwAAAY8"]
[Tue Jul 21 08:24:21.954643 2026] [security2:error] [pid 419508:tid 419723] [client 20.197.195.24:16092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/xyn.php"] [unique_id "al9W5VcagwCeNbomjVsSUgAAAeQ"]
[Tue Jul 21 08:24:22.081834 2026] [security2:error] [pid 411857:tid 412070] [client 20.206.105.145:20207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/ppp.php"] [unique_id "al9W5i7ynBpLeKYztQPtOAAAAFE"]
[Tue Jul 21 08:24:22.154424 2026] [security2:error] [pid 419508:tid 419547] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/222.php"] [unique_id "al9W5lcagwCeNbomjVsSWgACDiY"]
[Tue Jul 21 08:24:22.199139 2026] [security2:error] [pid 419508:tid 419675] [client 185.198.243.55:33505] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "shop-officialstore.com"] [uri "/000.php"] [unique_id "al9W5lcagwCeNbomjVsSWwAAAbQ"]
[Tue Jul 21 08:24:22.296362 2026] [security2:error] [pid 418108:tid 418299] [client 20.197.195.24:3536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/adminner.php"] [unique_id "al9W5g0cxofL2J1zwYrGJgAAAUU"]
[Tue Jul 21 08:24:22.348016 2026] [security2:error] [pid 419508:tid 419595] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/cgi-bin/index.php"] [unique_id "al9W5lcagwCeNbomjVsSXAABllY"]
[Tue Jul 21 08:24:22.538283 2026] [autoindex:error] [pid 419508:tid 419550] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:22.642444 2026] [security2:error] [pid 418108:tid 418276] [client 20.197.195.24:57023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/ccc.php"] [unique_id "al9W5g0cxofL2J1zwYrGKQAAAS4"]
[Tue Jul 21 08:24:22.689290 2026] [security2:error] [pid 419508:tid 419557] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/BDKR28WP.php"] [unique_id "al9W5lcagwCeNbomjVsSZQABrzA"]
[Tue Jul 21 08:24:22.921558 2026] [security2:error] [pid 419508:tid 419604] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W5lcagwCeNbomjVsSZgAB7F8"]
[Tue Jul 21 08:24:22.921705 2026] [security2:error] [pid 419508:tid 419731] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W5lcagwCeNbomjVsSZgAB7F8"]
[Tue Jul 21 08:24:22.960739 2026] [security2:error] [pid 419508:tid 419559] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W5lcagwCeNbomjVsSZwAB5jI"]
[Tue Jul 21 08:24:22.960912 2026] [security2:error] [pid 419508:tid 419725] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W5lcagwCeNbomjVsSZwAB5jI"]
[Tue Jul 21 08:24:22.963035 2026] [security2:error] [pid 419508:tid 419721] [client 185.198.243.75:56009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "shop-officialstore.com"] [uri "/wp-admin/css/index.php"] [unique_id "al9W5lcagwCeNbomjVsSaAAAAeI"]
[Tue Jul 21 08:24:23.040718 2026] [security2:error] [pid 411857:tid 412055] [client 20.197.195.24:56999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/w.php"] [unique_id "al9W5y7ynBpLeKYztQPtRgAAAEI"]
[Tue Jul 21 08:24:23.136960 2026] [security2:error] [pid 411857:tid 412028] [client 20.197.195.24:18259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/admin.php"] [unique_id "al9W5y7ynBpLeKYztQPtSQAAACc"]
[Tue Jul 21 08:24:23.198841 2026] [security2:error] [pid 419508:tid 419647] [client 20.197.195.24:16973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9W51cagwCeNbomjVsSbgAAAZg"]
[Tue Jul 21 08:24:23.388977 2026] [core:error] [pid 419508:tid 419556] [remote 40.77.167.57:33805] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:24:23.389003 2026] [core:error] [pid 419508:tid 419556] [remote 40.77.167.57:33805] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:24:23.411366 2026] [autoindex:error] [pid 419508:tid 419591] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:23.414499 2026] [security2:error] [pid 411857:tid 411999] [client 117.213.202.34:51794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W5y7ynBpLeKYztQPtTAAAAAo"]
[Tue Jul 21 08:24:23.414653 2026] [security2:error] [pid 411857:tid 411999] [client 117.213.202.34:51794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W5y7ynBpLeKYztQPtTAAAAAo"]
[Tue Jul 21 08:24:23.437882 2026] [security2:error] [pid 411857:tid 412005] [client 20.197.195.24:6522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/FWAZ.php"] [unique_id "al9W5y7ynBpLeKYztQPtTgAAABA"]
[Tue Jul 21 08:24:23.579332 2026] [autoindex:error] [pid 419508:tid 419613] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:23.626061 2026] [security2:error] [pid 411857:tid 412019] [client 152.59.34.51:51249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9W5y7ynBpLeKYztQPtUQAAAB4"]
[Tue Jul 21 08:24:23.626186 2026] [security2:error] [pid 411857:tid 412019] [client 152.59.34.51:51249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9W5y7ynBpLeKYztQPtUQAAAB4"]
[Tue Jul 21 08:24:23.640406 2026] [security2:error] [pid 418108:tid 418337] [client 20.197.195.24:56991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/miru1.php"] [unique_id "al9W5w0cxofL2J1zwYrGLAAAAWs"]
[Tue Jul 21 08:24:23.646924 2026] [security2:error] [pid 419508:tid 419699] [client 150.129.202.39:65440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W51cagwCeNbomjVsSeAAAAcw"]
[Tue Jul 21 08:24:23.647083 2026] [security2:error] [pid 419508:tid 419699] [client 150.129.202.39:65440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W51cagwCeNbomjVsSeAAAAcw"]
[Tue Jul 21 08:24:23.665509 2026] [security2:error] [pid 411857:tid 412044] [client 20.197.195.24:17010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/aa.php"] [unique_id "al9W5y7ynBpLeKYztQPtVAAAADc"]
[Tue Jul 21 08:24:23.747700 2026] [security2:error] [pid 418108:tid 418327] [client 185.198.243.51:62275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "shop-officialstore.com"] [uri "/wp-content/plugins/index.php"] [unique_id "al9W5w0cxofL2J1zwYrGLgAAAWE"]
[Tue Jul 21 08:24:23.755717 2026] [security2:error] [pid 419508:tid 419645] [client 20.197.195.24:56966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/122.php"] [unique_id "al9W51cagwCeNbomjVsSegAAAZY"]
[Tue Jul 21 08:24:23.816451 2026] [security2:error] [pid 418108:tid 418308] [client 20.197.195.24:16120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/get.php"] [unique_id "al9W5w0cxofL2J1zwYrGLwAAAU4"]
[Tue Jul 21 08:24:23.851750 2026] [security2:error] [pid 411857:tid 412013] [client 20.197.195.24:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/as.php"] [unique_id "al9W5y7ynBpLeKYztQPtVwAAABg"]
[Tue Jul 21 08:24:23.853105 2026] [security2:error] [pid 419508:tid 419542] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/raw.php"] [unique_id "al9W51cagwCeNbomjVsSgAABvSE"]
[Tue Jul 21 08:24:23.882548 2026] [security2:error] [pid 418108:tid 418366] [client 20.197.195.24:16090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/ccou.php"] [unique_id "al9W5w0cxofL2J1zwYrGMAAAAYg"]
[Tue Jul 21 08:24:23.912574 2026] [security2:error] [pid 419508:tid 419696] [client 20.197.195.24:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/w3lls.php"] [unique_id "al9W51cagwCeNbomjVsSgQAAAck"]
[Tue Jul 21 08:24:23.962218 2026] [security2:error] [pid 419508:tid 419665] [client 20.197.192.193:46150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/old.php"] [unique_id "al9W51cagwCeNbomjVsSgwAAAao"]
[Tue Jul 21 08:24:24.015538 2026] [security2:error] [pid 411857:tid 412106] [client 20.197.195.24:17022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/test1.php"] [unique_id "al9W6C7ynBpLeKYztQPtWwAAAHU"]
[Tue Jul 21 08:24:24.018426 2026] [security2:error] [pid 418108:tid 418192] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9W6A0cxofL2J1zwYrGMQABUFE"]
[Tue Jul 21 08:24:24.018596 2026] [security2:error] [pid 418108:tid 418310] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9W6A0cxofL2J1zwYrGMQABUFE"]
[Tue Jul 21 08:24:24.047264 2026] [security2:error] [pid 419508:tid 419594] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/abcd.php"] [unique_id "al9W6FcagwCeNbomjVsShQAB7FU"]
[Tue Jul 21 08:24:24.112742 2026] [security2:error] [pid 419508:tid 419654] [client 20.197.195.24:56412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/database.php"] [unique_id "al9W6FcagwCeNbomjVsShwAAAZ8"]
[Tue Jul 21 08:24:24.183792 2026] [security2:error] [pid 419508:tid 419675] [client 195.49.128.211:60281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9W6FcagwCeNbomjVsSjgAAAbQ"]
[Tue Jul 21 08:24:24.183925 2026] [security2:error] [pid 419508:tid 419675] [client 195.49.128.211:60281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9W6FcagwCeNbomjVsSjgAAAbQ"]
[Tue Jul 21 08:24:24.198546 2026] [security2:error] [pid 419508:tid 419527] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/a1.php"] [unique_id "al9W6FcagwCeNbomjVsSjwACCxI"]
[Tue Jul 21 08:24:24.283937 2026] [security2:error] [pid 418108:tid 418348] [client 20.197.195.24:56983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/file.php"] [unique_id "al9W6A0cxofL2J1zwYrGNAAAAXY"]
[Tue Jul 21 08:24:24.325842 2026] [security2:error] [pid 419508:tid 419668] [client 173.239.240.14:53279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.escoladaseguranca.com.br"] [uri "/wp-login.php"] [unique_id "al9W51cagwCeNbomjVsSbAAAAa0"], referer: https://www.google.com/search?q=wordpress
[Tue Jul 21 08:24:24.326749 2026] [security2:error] [pid 419508:tid 419647] [client 20.226.60.151:50113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/dfre.php"] [unique_id "al9W6FcagwCeNbomjVsSkwAAAZg"]
[Tue Jul 21 08:24:24.354130 2026] [security2:error] [pid 419508:tid 419522] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9W6FcagwCeNbomjVsSlAAB3g0"]
[Tue Jul 21 08:24:24.355794 2026] [security2:error] [pid 411857:tid 411973] [remote 41.186.86.12:58265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9W6C7ynBpLeKYztQPtYwAARnE"]
[Tue Jul 21 08:24:24.370749 2026] [security2:error] [pid 411857:tid 412065] [client 20.197.195.24:16997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/file.php"] [unique_id "al9W6C7ynBpLeKYztQPtZAAAAEw"]
[Tue Jul 21 08:24:24.505878 2026] [security2:error] [pid 418108:tid 418258] [client 20.220.225.223:12303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/wp-css.php"] [unique_id "al9W6A0cxofL2J1zwYrGNgAAARw"]
[Tue Jul 21 08:24:24.539489 2026] [security2:error] [pid 419508:tid 419631] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9W6FcagwCeNbomjVsSlgAB0Ho"]
[Tue Jul 21 08:24:24.572785 2026] [security2:error] [pid 419508:tid 419735] [client 20.197.195.24:56963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/777.php"] [unique_id "al9W6FcagwCeNbomjVsSlwAAAfA"]
[Tue Jul 21 08:24:24.637174 2026] [security2:error] [pid 411857:tid 412101] [client 45.89.242.132:65461] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "shop-officialstore.com"] [uri "/wp-content/index.php"] [unique_id "al9W6C7ynBpLeKYztQPtagAAAHA"]
[Tue Jul 21 08:24:24.710506 2026] [security2:error] [pid 411857:tid 412023] [client 20.197.195.24:3557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/k.php"] [unique_id "al9W6C7ynBpLeKYztQPtbAAAACI"]
[Tue Jul 21 08:24:24.736994 2026] [security2:error] [pid 419508:tid 419597] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-content/BypassBest.php"] [unique_id "al9W6FcagwCeNbomjVsSmAACBVg"]
[Tue Jul 21 08:24:25.070665 2026] [security2:error] [pid 419508:tid 419580] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/simple.php"] [unique_id "al9W6VcagwCeNbomjVsSngAByEc"]
[Tue Jul 21 08:24:25.073429 2026] [security2:error] [pid 418108:tid 418246] [client 20.197.195.24:16122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/ssixta.php"] [unique_id "al9W6Q0cxofL2J1zwYrGOwAAARA"]
[Tue Jul 21 08:24:25.154821 2026] [security2:error] [pid 419508:tid 419766] [client 14.245.224.124:65332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9W6VcagwCeNbomjVsSoQAAAg4"]
[Tue Jul 21 08:24:25.154967 2026] [security2:error] [pid 419508:tid 419766] [client 14.245.224.124:65332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9W6VcagwCeNbomjVsSoQAAAg4"]
[Tue Jul 21 08:24:25.160580 2026] [security2:error] [pid 419508:tid 419693] [client 20.206.105.145:20126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/201.php"] [unique_id "al9W6VcagwCeNbomjVsSogAAAcY"]
[Tue Jul 21 08:24:25.239913 2026] [security2:error] [pid 419508:tid 419510] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/xxx.php"] [unique_id "al9W6VcagwCeNbomjVsSpQABuAE"]
[Tue Jul 21 08:24:25.384683 2026] [security2:error] [pid 419508:tid 419662] [client 109.248.148.246:34974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9W6VcagwCeNbomjVsSqwAAAac"]
[Tue Jul 21 08:24:25.384830 2026] [security2:error] [pid 419508:tid 419662] [client 109.248.148.246:34974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9W6VcagwCeNbomjVsSqwAAAac"]
[Tue Jul 21 08:24:25.529770 2026] [security2:error] [pid 419508:tid 419759] [client 20.197.195.24:57021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/1c.php"] [unique_id "al9W6VcagwCeNbomjVsSrAAAAgc"]
[Tue Jul 21 08:24:25.540584 2026] [security2:error] [pid 419508:tid 419628] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/hypo.php"] [unique_id "al9W6VcagwCeNbomjVsSrQABzXc"]
[Tue Jul 21 08:24:25.564963 2026] [security2:error] [pid 419508:tid 419737] [client 109.248.148.246:56452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9W6VcagwCeNbomjVsSsAAAAfI"]
[Tue Jul 21 08:24:25.565051 2026] [security2:error] [pid 419508:tid 419737] [client 109.248.148.246:56452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9W6VcagwCeNbomjVsSsAAAAfI"]
[Tue Jul 21 08:24:25.587282 2026] [security2:error] [pid 419508:tid 419699] [client 20.197.195.24:16071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/test2.php"] [unique_id "al9W6VcagwCeNbomjVsSsgAAAcw"]
[Tue Jul 21 08:24:25.626988 2026] [security2:error] [pid 418108:tid 418269] [client 20.197.195.24:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/buy.php"] [unique_id "al9W6Q0cxofL2J1zwYrGPgAAASc"]
[Tue Jul 21 08:24:25.744153 2026] [autoindex:error] [pid 419508:tid 419592] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:25.766517 2026] [security2:error] [pid 419508:tid 419684] [client 20.197.195.24:56989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/ssend.php"] [unique_id "al9W6VcagwCeNbomjVsStwAAAb0"]
[Tue Jul 21 08:24:25.882707 2026] [autoindex:error] [pid 411857:tid 411997] [client 3.151.194.164:48710] AH01276: Cannot serve directory /home3/agroci73/purityox.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:25.916414 2026] [security2:error] [pid 419508:tid 419634] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/chosen.php"] [unique_id "al9W6VcagwCeNbomjVsSuQABt30"]
[Tue Jul 21 08:24:25.994848 2026] [security2:error] [pid 411857:tid 412094] [client 20.197.195.24:18302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/blurbs.php"] [unique_id "al9W6S7ynBpLeKYztQPtfwAAAGk"]
[Tue Jul 21 08:24:26.045993 2026] [proxy:error] [pid 411857:tid 412018] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:24:26.046070 2026] [proxy_http:error] [pid 411857:tid 412018] [client 146.190.160.169:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:24:26.047143 2026] [proxy:error] [pid 411857:tid 412018] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:24:26.047178 2026] [proxy_http:error] [pid 411857:tid 412018] [client 146.190.160.169:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:24:26.062896 2026] [security2:error] [pid 411857:tid 412111] [client 185.198.243.52:46011] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "shop-officialstore.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9W6i7ynBpLeKYztQPtgwAAAHo"]
[Tue Jul 21 08:24:26.076793 2026] [autoindex:error] [pid 419508:tid 419553] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:26.122763 2026] [security2:error] [pid 411857:tid 412071] [client 20.197.195.24:56425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/item.php"] [unique_id "al9W6i7ynBpLeKYztQPthQAAAFI"]
[Tue Jul 21 08:24:26.139294 2026] [security2:error] [pid 411857:tid 411992] [client 20.197.195.24:3553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/bajah.php"] [unique_id "al9W6i7ynBpLeKYztQPthgAAAAM"]
[Tue Jul 21 08:24:26.175392 2026] [security2:error] [pid 419508:tid 419718] [client 20.197.195.24:56962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/ss.php"] [unique_id "al9W6lcagwCeNbomjVsSuwAAAd8"]
[Tue Jul 21 08:24:26.227369 2026] [security2:error] [pid 419508:tid 419575] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/file5.php"] [unique_id "al9W6lcagwCeNbomjVsSvAABn0I"]
[Tue Jul 21 08:24:26.287354 2026] [security2:error] [pid 419508:tid 419766] [client 20.197.195.24:56985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/hypo.php"] [unique_id "al9W6lcagwCeNbomjVsSvQAAAg4"]
[Tue Jul 21 08:24:26.337295 2026] [security2:error] [pid 418108:tid 418268] [client 20.197.195.24:18297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/a.php"] [unique_id "al9W6g0cxofL2J1zwYrGQgAAASY"]
[Tue Jul 21 08:24:26.377298 2026] [security2:error] [pid 411857:tid 411916] [remote 216.73.216.184:63718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9W6i7ynBpLeKYztQPtjQAANzk"]
[Tue Jul 21 08:24:26.385127 2026] [security2:error] [pid 419508:tid 419728] [client 20.197.195.24:56990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/users.php"] [unique_id "al9W6lcagwCeNbomjVsSvgAAAek"]
[Tue Jul 21 08:24:26.459243 2026] [security2:error] [pid 419508:tid 419717] [client 20.197.195.24:3535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/edit.php"] [unique_id "al9W6lcagwCeNbomjVsSwQAAAd4"]
[Tue Jul 21 08:24:26.477820 2026] [security2:error] [pid 419508:tid 419763] [client 187.125.243.197:58394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9W6lcagwCeNbomjVsSwgAAAgs"]
[Tue Jul 21 08:24:26.477936 2026] [security2:error] [pid 419508:tid 419763] [client 187.125.243.197:58394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9W6lcagwCeNbomjVsSwgAAAgs"]
[Tue Jul 21 08:24:26.483199 2026] [security2:error] [pid 411857:tid 412081] [client 20.197.195.24:16961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/177.php"] [unique_id "al9W6i7ynBpLeKYztQPtjwAAAFw"]
[Tue Jul 21 08:24:26.493983 2026] [proxy:error] [pid 419508:tid 419689] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:24:26.494048 2026] [proxy_http:error] [pid 419508:tid 419689] [client 146.190.160.169:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.1d98c21924c34f68a9a01782261404569.0711679.meusitehostgator.com.br/
[Tue Jul 21 08:24:26.494675 2026] [proxy:error] [pid 419508:tid 419689] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:24:26.494701 2026] [proxy_http:error] [pid 419508:tid 419689] [client 146.190.160.169:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.1d98c21924c34f68a9a01782261404569.0711679.meusitehostgator.com.br/
[Tue Jul 21 08:24:26.518185 2026] [security2:error] [pid 419508:tid 419625] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/file.php"] [unique_id "al9W6lcagwCeNbomjVsSxQABtXQ"]
[Tue Jul 21 08:24:26.518185 2026] [security2:error] [pid 411857:tid 412103] [client 20.197.195.24:56397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/config.php"] [unique_id "al9W6i7ynBpLeKYztQPtkQAAAHI"]
[Tue Jul 21 08:24:26.564016 2026] [security2:error] [pid 419508:tid 419686] [client 20.197.195.24:13857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/hosty.php"] [unique_id "al9W6lcagwCeNbomjVsSxwAAAb8"]
[Tue Jul 21 08:24:26.569975 2026] [security2:error] [pid 419508:tid 419723] [client 20.197.195.24:56430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/gettest.php"] [unique_id "al9W6lcagwCeNbomjVsSyQAAAeQ"]
[Tue Jul 21 08:24:26.605309 2026] [security2:error] [pid 419508:tid 419700] [client 20.197.195.24:16067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/min.php"] [unique_id "al9W6lcagwCeNbomjVsSygAAAc0"]
[Tue Jul 21 08:24:26.616085 2026] [security2:error] [pid 419508:tid 419737] [client 20.197.195.24:56411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/dvjul.php"] [unique_id "al9W6lcagwCeNbomjVsSywAAAfI"]
[Tue Jul 21 08:24:26.647539 2026] [security2:error] [pid 419508:tid 419758] [client 173.252.95.42:55136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9W6lcagwCeNbomjVsSzAAAAgY"]
[Tue Jul 21 08:24:26.649521 2026] [security2:error] [pid 411857:tid 412016] [client 20.197.195.24:16070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/biufile.php"] [unique_id "al9W6i7ynBpLeKYztQPtmAAAABs"]
[Tue Jul 21 08:24:26.652661 2026] [security2:error] [pid 411857:tid 412020] [client 20.226.60.151:60622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-happy.php"] [unique_id "al9W6i7ynBpLeKYztQPtmQAAAB8"]
[Tue Jul 21 08:24:26.666171 2026] [security2:error] [pid 419508:tid 419511] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/aa2.php"] [unique_id "al9W6lcagwCeNbomjVsSzQABqwI"]
[Tue Jul 21 08:24:26.680931 2026] [security2:error] [pid 418108:tid 418270] [client 20.197.195.24:57006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/av.php"] [unique_id "al9W6g0cxofL2J1zwYrGQwAAASg"]
[Tue Jul 21 08:24:26.735030 2026] [security2:error] [pid 419508:tid 419698] [client 20.197.195.24:61178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/k.php"] [unique_id "al9W6lcagwCeNbomjVsSzwAAAcs"]
[Tue Jul 21 08:24:26.756234 2026] [security2:error] [pid 411857:tid 412042] [client 20.197.195.24:56446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/coffexium.php"] [unique_id "al9W6i7ynBpLeKYztQPtnAAAADU"]
[Tue Jul 21 08:24:26.949635 2026] [security2:error] [pid 418108:tid 418253] [client 20.197.195.24:16084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/core.php"] [unique_id "al9W6g0cxofL2J1zwYrGRAAAARc"]
[Tue Jul 21 08:24:27.028195 2026] [security2:error] [pid 419508:tid 419696] [client 173.239.240.25:44143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.escoladaseguranca.com.br"] [uri "/wp-login.php"] [unique_id "al9W6lcagwCeNbomjVsS0wAAAck"], referer: https://www.google.com/
[Tue Jul 21 08:24:27.068669 2026] [security2:error] [pid 419508:tid 419618] [remote 84.247.172.23:37190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9W61cagwCeNbomjVsS2AABj20"]
[Tue Jul 21 08:24:27.117571 2026] [security2:error] [pid 419508:tid 419695] [client 20.197.195.24:56404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/als.php"] [unique_id "al9W61cagwCeNbomjVsS2QAAAcg"]
[Tue Jul 21 08:24:27.175286 2026] [security2:error] [pid 419508:tid 419617] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/ccou.php"] [unique_id "al9W61cagwCeNbomjVsS4AABxmw"]
[Tue Jul 21 08:24:27.226756 2026] [security2:error] [pid 411857:tid 412098] [client 20.197.195.24:61161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/aaa.php"] [unique_id "al9W6y7ynBpLeKYztQPtowAAAG0"]
[Tue Jul 21 08:24:27.243903 2026] [security2:error] [pid 411857:tid 412054] [client 20.197.195.24:16968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/simple.php"] [unique_id "al9W6y7ynBpLeKYztQPtpAAAAEE"]
[Tue Jul 21 08:24:27.326300 2026] [security2:error] [pid 419508:tid 419616] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/dr.php"] [unique_id "al9W61cagwCeNbomjVsS4gAB4Gs"]
[Tue Jul 21 08:24:27.413849 2026] [security2:error] [pid 419508:tid 419713] [client 20.197.195.24:18334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/file5.php"] [unique_id "al9W61cagwCeNbomjVsS5wAAAdo"]
[Tue Jul 21 08:24:27.556242 2026] [security2:error] [pid 419508:tid 419700] [client 20.197.195.24:56426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/init.php"] [unique_id "al9W61cagwCeNbomjVsS7QAAAc0"]
[Tue Jul 21 08:24:27.617947 2026] [security2:error] [pid 419508:tid 419737] [client 20.197.195.24:56396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/fpwch.php"] [unique_id "al9W61cagwCeNbomjVsS7gAAAfI"]
[Tue Jul 21 08:24:27.665612 2026] [security2:error] [pid 419508:tid 419520] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/file31.php"] [unique_id "al9W61cagwCeNbomjVsS8QAByws"]
[Tue Jul 21 08:24:27.672098 2026] [security2:error] [pid 419508:tid 419720] [client 20.197.195.24:56399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/domvf.php"] [unique_id "al9W61cagwCeNbomjVsS9AAAAeE"]
[Tue Jul 21 08:24:27.703161 2026] [security2:error] [pid 419508:tid 419645] [client 20.197.195.24:16966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp.php"] [unique_id "al9W61cagwCeNbomjVsS9QAAAZY"]
[Tue Jul 21 08:24:27.742709 2026] [security2:error] [pid 419508:tid 419685] [client 20.197.195.24:16970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/class.php"] [unique_id "al9W61cagwCeNbomjVsS9gAAAb4"]
[Tue Jul 21 08:24:27.748463 2026] [proxy:error] [pid 419508:tid 419734] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:24:27.748594 2026] [proxy_http:error] [pid 419508:tid 419734] [client 205.210.31.30:65386] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:24:27.749098 2026] [proxy:error] [pid 419508:tid 419734] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:24:27.749119 2026] [proxy_http:error] [pid 419508:tid 419734] [client 205.210.31.30:65386] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:24:27.773287 2026] [security2:error] [pid 419508:tid 419706] [client 20.197.195.24:17003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/echkm.php"] [unique_id "al9W61cagwCeNbomjVsS-AAAAdM"]
[Tue Jul 21 08:24:27.786971 2026] [security2:error] [pid 419508:tid 419638] [client 20.197.195.24:56438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/lib.php"] [unique_id "al9W61cagwCeNbomjVsS-QAAAY8"]
[Tue Jul 21 08:24:27.813246 2026] [security2:error] [pid 419508:tid 419745] [client 20.197.195.24:16990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/login.php"] [unique_id "al9W61cagwCeNbomjVsS-gAAAfk"]
[Tue Jul 21 08:24:27.851927 2026] [security2:error] [pid 419508:tid 419682] [client 20.197.195.24:16969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/a2.php"] [unique_id "al9W61cagwCeNbomjVsS-wAAAbs"]
[Tue Jul 21 08:24:27.854692 2026] [security2:error] [pid 419508:tid 419755] [client 202.179.75.202:52982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9W61cagwCeNbomjVsS_AAAAgM"]
[Tue Jul 21 08:24:27.854785 2026] [security2:error] [pid 419508:tid 419755] [client 202.179.75.202:52982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9W61cagwCeNbomjVsS_AAAAgM"]
[Tue Jul 21 08:24:27.868414 2026] [security2:error] [pid 419508:tid 419654] [client 20.197.195.24:56407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/d61.php"] [unique_id "al9W61cagwCeNbomjVsS_gAAAZ8"]
[Tue Jul 21 08:24:27.893990 2026] [security2:error] [pid 419508:tid 419602] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/file6.php"] [unique_id "al9W61cagwCeNbomjVsS_wABmV0"]
[Tue Jul 21 08:24:27.904260 2026] [security2:error] [pid 419508:tid 419719] [client 20.197.195.24:56419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/info.php"] [unique_id "al9W61cagwCeNbomjVsTAAAAAeA"]
[Tue Jul 21 08:24:27.943915 2026] [security2:error] [pid 419508:tid 419707] [client 20.197.195.24:56984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/11.php"] [unique_id "al9W61cagwCeNbomjVsTAQAAAdQ"]
[Tue Jul 21 08:24:27.955835 2026] [security2:error] [pid 418108:tid 418293] [client 20.197.195.24:17009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/v2.php"] [unique_id "al9W6w0cxofL2J1zwYrGSQAAAT8"]
[Tue Jul 21 08:24:27.979737 2026] [security2:error] [pid 419508:tid 419766] [client 20.197.195.24:6446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/panel.php"] [unique_id "al9W61cagwCeNbomjVsTBwAAAg4"]
[Tue Jul 21 08:24:27.999991 2026] [security2:error] [pid 419508:tid 419675] [client 20.197.195.24:56974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/dex.php"] [unique_id "al9W61cagwCeNbomjVsTCAAAAbQ"]
[Tue Jul 21 08:24:28.003509 2026] [security2:error] [pid 418108:tid 418353] [client 20.197.195.24:18366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/222.php"] [unique_id "al9W7A0cxofL2J1zwYrGSwAAAXs"]
[Tue Jul 21 08:24:28.041409 2026] [security2:error] [pid 419508:tid 419729] [client 20.197.195.24:16114] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "vidalivredasdividas.com"] [uri "/1.php"] [unique_id "al9W7FcagwCeNbomjVsTCwAAAeo"]
[Tue Jul 21 08:24:28.041512 2026] [security2:error] [pid 419508:tid 419729] [client 20.197.195.24:16114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/1.php"] [unique_id "al9W7FcagwCeNbomjVsTCwAAAeo"]
[Tue Jul 21 08:24:28.042796 2026] [security2:error] [pid 419508:tid 419547] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/file15.php"] [unique_id "al9W7FcagwCeNbomjVsTDAABtSY"]
[Tue Jul 21 08:24:28.136775 2026] [security2:error] [pid 419508:tid 419700] [client 20.197.195.24:56976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/ms.php"] [unique_id "al9W7FcagwCeNbomjVsTDwAAAc0"]
[Tue Jul 21 08:24:28.195131 2026] [security2:error] [pid 419508:tid 419550] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/jp.php"] [unique_id "al9W7FcagwCeNbomjVsTFAAByyk"]
[Tue Jul 21 08:24:28.224877 2026] [security2:error] [pid 419508:tid 419763] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9W7FcagwCeNbomjVsTDgACC2U"]
[Tue Jul 21 08:24:28.311142 2026] [security2:error] [pid 418108:tid 418358] [client 20.197.195.24:18251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/test.php"] [unique_id "al9W7A0cxofL2J1zwYrGTAAAAYA"]
[Tue Jul 21 08:24:28.335216 2026] [security2:error] [pid 418108:tid 418273] [client 20.220.225.223:12569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/wp-explorer.php"] [unique_id "al9W7A0cxofL2J1zwYrGTQAAASs"]
[Tue Jul 21 08:24:28.344518 2026] [security2:error] [pid 419508:tid 419563] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/f35.php"] [unique_id "al9W7FcagwCeNbomjVsTFwABqzY"]
[Tue Jul 21 08:24:28.430670 2026] [security2:error] [pid 419508:tid 419526] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W7FcagwCeNbomjVsTGQABvRE"]
[Tue Jul 21 08:24:28.430866 2026] [security2:error] [pid 419508:tid 419684] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W7FcagwCeNbomjVsTGQABvRE"]
[Tue Jul 21 08:24:28.493762 2026] [security2:error] [pid 419508:tid 419537] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-load.php"] [unique_id "al9W7FcagwCeNbomjVsTHAAB7xw"]
[Tue Jul 21 08:24:28.544002 2026] [security2:error] [pid 419508:tid 419682] [client 20.197.195.24:17018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/memberfuns.php"] [unique_id "al9W7FcagwCeNbomjVsTHQAAAbs"]
[Tue Jul 21 08:24:28.719613 2026] [security2:error] [pid 419508:tid 419754] [client 20.197.195.24:16986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/0.php"] [unique_id "al9W7FcagwCeNbomjVsTQQAAAgI"]
[Tue Jul 21 08:24:28.746127 2026] [autoindex:error] [pid 419508:tid 419587] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:28.779509 2026] [security2:error] [pid 418108:tid 418252] [client 20.197.195.24:56977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/BDKR28.php"] [unique_id "al9W7A0cxofL2J1zwYrGUQAAARY"]
[Tue Jul 21 08:24:28.782721 2026] [security2:error] [pid 418108:tid 418307] [client 20.206.105.145:20237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/ops.php"] [unique_id "al9W7A0cxofL2J1zwYrGUgAAAU0"]
[Tue Jul 21 08:24:28.864243 2026] [security2:error] [pid 419508:tid 419729] [client 20.197.195.24:16101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/green1.php"] [unique_id "al9W7FcagwCeNbomjVsTSAAAAeo"]
[Tue Jul 21 08:24:28.874148 2026] [security2:error] [pid 418108:tid 418247] [client 20.220.225.223:19285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9W7A0cxofL2J1zwYrGUwAAARE"]
[Tue Jul 21 08:24:28.913059 2026] [security2:error] [pid 418108:tid 418276] [client 20.197.195.24:6497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/nc4.php"] [unique_id "al9W7A0cxofL2J1zwYrGVAAAAS4"]
[Tue Jul 21 08:24:28.951707 2026] [security2:error] [pid 419508:tid 419647] [client 20.197.195.24:16976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/a1.php"] [unique_id "al9W7FcagwCeNbomjVsTTAAAAZg"]
[Tue Jul 21 08:24:28.977399 2026] [security2:error] [pid 419508:tid 419698] [client 20.197.195.24:16988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/eee.php"] [unique_id "al9W7FcagwCeNbomjVsTTQAAAcs"]
[Tue Jul 21 08:24:28.996374 2026] [autoindex:error] [pid 419508:tid 419625] [remote 20.151.10.161:0] AH01276: Cannot serve directory /home4/exper055/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:29.037194 2026] [security2:error] [pid 418108:tid 418280] [client 109.248.148.246:34694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9W7Q0cxofL2J1zwYrGVQAAATI"]
[Tue Jul 21 08:24:29.037281 2026] [security2:error] [pid 418108:tid 418280] [client 109.248.148.246:34694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9W7Q0cxofL2J1zwYrGVQAAATI"]
[Tue Jul 21 08:24:29.044156 2026] [security2:error] [pid 419508:tid 419653] [client 115.134.11.136:60660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W7VcagwCeNbomjVsTUQAAAZ4"]
[Tue Jul 21 08:24:29.047037 2026] [security2:error] [pid 419508:tid 419653] [client 115.134.11.136:60660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W7VcagwCeNbomjVsTUQAAAZ4"]
[Tue Jul 21 08:24:29.055041 2026] [security2:error] [pid 419508:tid 419651] [client 20.197.195.24:57011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/wp-aothait.php"] [unique_id "al9W7VcagwCeNbomjVsTUgAAAZw"]
[Tue Jul 21 08:24:29.099696 2026] [security2:error] [pid 419508:tid 419763] [client 20.197.195.24:16989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/config.json.php"] [unique_id "al9W7VcagwCeNbomjVsTUwAAAgs"]
[Tue Jul 21 08:24:29.106874 2026] [security2:error] [pid 419508:tid 419657] [client 20.197.195.24:61173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/aaa.php"] [unique_id "al9W7VcagwCeNbomjVsTVAAAAaI"]
[Tue Jul 21 08:24:29.149497 2026] [security2:error] [pid 419508:tid 419618] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9W7VcagwCeNbomjVsTVwABlm0"]
[Tue Jul 21 08:24:29.164689 2026] [security2:error] [pid 419508:tid 419656] [client 20.197.195.24:56391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9W7VcagwCeNbomjVsTXAAAAaE"]
[Tue Jul 21 08:24:29.218351 2026] [security2:error] [pid 419508:tid 419706] [client 20.197.195.24:6482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/k2.php"] [unique_id "al9W7VcagwCeNbomjVsTXQAAAdM"]
[Tue Jul 21 08:24:29.250818 2026] [security2:error] [pid 418108:tid 418337] [client 20.197.195.24:56403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/uiuvs58l.php"] [unique_id "al9W7Q0cxofL2J1zwYrGVwAAAWs"]
[Tue Jul 21 08:24:29.279726 2026] [security2:error] [pid 418108:tid 418317] [client 213.152.186.163:49916] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9W7Q0cxofL2J1zwYrGWAAAAVc"]
[Tue Jul 21 08:24:29.279943 2026] [security2:error] [pid 418108:tid 418317] [client 213.152.186.163:49916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9W7Q0cxofL2J1zwYrGWAAAAVc"]
[Tue Jul 21 08:24:29.290477 2026] [security2:error] [pid 419508:tid 419682] [client 20.197.195.24:17005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/40p9ixjd.php"] [unique_id "al9W7VcagwCeNbomjVsTZAAAAbs"]
[Tue Jul 21 08:24:29.314519 2026] [security2:error] [pid 419508:tid 419546] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wp-links.php"] [unique_id "al9W7VcagwCeNbomjVsTZwAB3yU"]
[Tue Jul 21 08:24:29.326865 2026] [security2:error] [pid 419508:tid 419693] [client 20.197.195.24:16074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9W7VcagwCeNbomjVsTaAAAAcY"]
[Tue Jul 21 08:24:29.367167 2026] [security2:error] [pid 419508:tid 419764] [client 20.197.195.24:56392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/for.php"] [unique_id "al9W7VcagwCeNbomjVsTagAAAgw"]
[Tue Jul 21 08:24:29.436198 2026] [security2:error] [pid 419508:tid 419659] [client 20.197.195.24:16126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vidalivredasdividas.com"] [uri "/raw.php"] [unique_id "al9W7VcagwCeNbomjVsTbAAAAaQ"]
[Tue Jul 21 08:24:29.488128 2026] [security2:error] [pid 419508:tid 419754] [client 89.238.167.134:43366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9W7VcagwCeNbomjVsTbgAAAgI"]
[Tue Jul 21 08:24:29.488217 2026] [security2:error] [pid 419508:tid 419754] [client 89.238.167.134:43366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9W7VcagwCeNbomjVsTbgAAAgI"]
[Tue Jul 21 08:24:29.525188 2026] [security2:error] [pid 419508:tid 419520] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/solo1.php"] [unique_id "al9W7VcagwCeNbomjVsTbwABwAs"]
[Tue Jul 21 08:24:29.535695 2026] [security2:error] [pid 418108:tid 418326] [client 20.226.60.151:56850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/get.php"] [unique_id "al9W7Q0cxofL2J1zwYrGWQAAAWA"]
[Tue Jul 21 08:24:29.739589 2026] [security2:error] [pid 419508:tid 419547] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/sixxis.php"] [unique_id "al9W7VcagwCeNbomjVsTdAABoCY"]
[Tue Jul 21 08:24:29.887746 2026] [security2:error] [pid 419508:tid 419624] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/2P.update.php"] [unique_id "al9W7VcagwCeNbomjVsTdwABtXM"]
[Tue Jul 21 08:24:30.036842 2026] [security2:error] [pid 419508:tid 419550] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/a.php"] [unique_id "al9W7lcagwCeNbomjVsTegAB3Ck"]
[Tue Jul 21 08:24:30.212912 2026] [security2:error] [pid 419508:tid 419763] [client 20.220.225.223:12309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/akismet.php"] [unique_id "al9W7lcagwCeNbomjVsTfQAAAgs"]
[Tue Jul 21 08:24:30.300936 2026] [security2:error] [pid 419508:tid 419526] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/k.php"] [unique_id "al9W7lcagwCeNbomjVsTgQABkxE"]
[Tue Jul 21 08:24:30.388543 2026] [security2:error] [pid 419508:tid 419656] [client 20.220.225.223:19276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9W7lcagwCeNbomjVsThwAAAaE"]
[Tue Jul 21 08:24:30.450321 2026] [security2:error] [pid 419508:tid 419611] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/w.php"] [unique_id "al9W7lcagwCeNbomjVsTiAABj2Y"]
[Tue Jul 21 08:24:30.452625 2026] [security2:error] [pid 418108:tid 418277] [client 20.197.195.24:18357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/11.php"] [unique_id "al9W7g0cxofL2J1zwYrGZwAAAS8"]
[Tue Jul 21 08:24:30.599575 2026] [security2:error] [pid 419508:tid 419594] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/insc.php"] [unique_id "al9W7lcagwCeNbomjVsTjQAB-VU"]
[Tue Jul 21 08:24:30.635797 2026] [security2:error] [pid 419508:tid 419764] [client 213.152.186.163:49932] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9W7lcagwCeNbomjVsTjgAAAgw"]
[Tue Jul 21 08:24:30.635894 2026] [security2:error] [pid 419508:tid 419764] [client 213.152.186.163:49932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9W7lcagwCeNbomjVsTjgAAAgw"]
[Tue Jul 21 08:24:30.748758 2026] [security2:error] [pid 419508:tid 419632] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9W7lcagwCeNbomjVsTkgAB3ns"]
[Tue Jul 21 08:24:30.752152 2026] [security2:error] [pid 418108:tid 418275] [client 74.7.175.156:44114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.cownnex.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9W7g0cxofL2J1zwYrGawABLWU"]
[Tue Jul 21 08:24:30.917725 2026] [security2:error] [pid 419508:tid 419565] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/u.php"] [unique_id "al9W7lcagwCeNbomjVsTmAABwjg"]
[Tue Jul 21 08:24:31.066001 2026] [security2:error] [pid 419508:tid 419603] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/sss.php"] [unique_id "al9W71cagwCeNbomjVsTmwABoF4"]
[Tue Jul 21 08:24:31.121700 2026] [security2:error] [pid 418108:tid 418349] [client 20.206.105.145:20179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/ingfo.php"] [unique_id "al9W7w0cxofL2J1zwYrGbAAAAXc"]
[Tue Jul 21 08:24:31.218515 2026] [security2:error] [pid 419508:tid 419510] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/sss.php"] [unique_id "al9W71cagwCeNbomjVsToAABzQE"]
[Tue Jul 21 08:24:31.260511 2026] [proxy:error] [pid 419508:tid 419690] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:24:31.260614 2026] [proxy_http:error] [pid 419508:tid 419690] [client 87.236.176.81:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:24:31.262531 2026] [proxy:error] [pid 419508:tid 419690] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:24:31.262608 2026] [proxy_http:error] [pid 419508:tid 419690] [client 87.236.176.81:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:24:31.285914 2026] [autoindex:error] [pid 418108:tid 418180] [remote 74.7.227.38:55454] AH01276: Cannot serve directory /home2/luc15241/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:31.392585 2026] [security2:error] [pid 419508:tid 419607] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/c.php"] [unique_id "al9W71cagwCeNbomjVsTpwAB4WI"]
[Tue Jul 21 08:24:31.476805 2026] [security2:error] [pid 418108:tid 418116] [remote 173.252.87.43:49434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9W7w0cxofL2J1zwYrGbwABUwU"]
[Tue Jul 21 08:24:31.541532 2026] [security2:error] [pid 419508:tid 419592] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/aa.php"] [unique_id "al9W71cagwCeNbomjVsTqgABnlM"]
[Tue Jul 21 08:24:31.561474 2026] [security2:error] [pid 419508:tid 419684] [client 20.197.195.24:61076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/mac.php"] [unique_id "al9W71cagwCeNbomjVsTqwAAAb0"]
[Tue Jul 21 08:24:31.691900 2026] [security2:error] [pid 419508:tid 419558] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/100.php"] [unique_id "al9W71cagwCeNbomjVsTrQABvjE"]
[Tue Jul 21 08:24:31.749604 2026] [security2:error] [pid 418108:tid 418279] [client 103.151.46.103:55201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9W7w0cxofL2J1zwYrGdwAAATE"]
[Tue Jul 21 08:24:31.749725 2026] [security2:error] [pid 418108:tid 418279] [client 103.151.46.103:55201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9W7w0cxofL2J1zwYrGdwAAATE"]
[Tue Jul 21 08:24:31.836005 2026] [security2:error] [pid 419508:tid 419665] [client 20.226.60.151:60653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/fpr4.php"] [unique_id "al9W71cagwCeNbomjVsTrwAAAao"]
[Tue Jul 21 08:24:31.858705 2026] [security2:error] [pid 419508:tid 419540] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/footer.php"] [unique_id "al9W71cagwCeNbomjVsTsAABoR8"]
[Tue Jul 21 08:24:32.157807 2026] [security2:error] [pid 419508:tid 419638] [client 20.220.225.223:19655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/dp.php"] [unique_id "al9W8FcagwCeNbomjVsTtQAAAY8"]
[Tue Jul 21 08:24:32.251816 2026] [security2:error] [pid 419508:tid 419764] [client 20.197.192.193:5621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/ms-new.php"] [unique_id "al9W8FcagwCeNbomjVsTuQAAAgw"]
[Tue Jul 21 08:24:32.556603 2026] [security2:error] [pid 419508:tid 419634] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/users.php"] [unique_id "al9W8FcagwCeNbomjVsTwQACB30"]
[Tue Jul 21 08:24:32.706836 2026] [security2:error] [pid 419508:tid 419587] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/177.php"] [unique_id "al9W8FcagwCeNbomjVsTwwABzU4"]
[Tue Jul 21 08:24:32.857039 2026] [security2:error] [pid 419508:tid 419553] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/config.php"] [unique_id "al9W8FcagwCeNbomjVsTxAAB9iw"]
[Tue Jul 21 08:24:32.879239 2026] [security2:error] [pid 419508:tid 419604] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/laravel/info.php"] [unique_id "al9W8FcagwCeNbomjVsTxQAB0F8"]
[Tue Jul 21 08:24:33.028372 2026] [security2:error] [pid 419508:tid 419561] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/gettest.php"] [unique_id "al9W8VcagwCeNbomjVsTyQAB8DQ"]
[Tue Jul 21 08:24:33.206027 2026] [security2:error] [pid 419508:tid 419694] [client 173.239.240.14:23761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "escoladaseguranca.com.br"] [uri "/wp-login.php"] [unique_id "al9W8VcagwCeNbomjVsTzAAAAcc"]
[Tue Jul 21 08:24:33.212270 2026] [security2:error] [pid 419508:tid 419516] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/min.php"] [unique_id "al9W8VcagwCeNbomjVsTzQABngc"]
[Tue Jul 21 08:24:33.398726 2026] [security2:error] [pid 419508:tid 419618] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/edorxrr.php"] [unique_id "al9W8VcagwCeNbomjVsT0AAByW0"]
[Tue Jul 21 08:24:33.404578 2026] [security2:error] [pid 419508:tid 419672] [client 20.220.225.223:12568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/ace2.php"] [unique_id "al9W8VcagwCeNbomjVsT0QAAAbE"]
[Tue Jul 21 08:24:33.450512 2026] [security2:error] [pid 419508:tid 419535] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W8VcagwCeNbomjVsT0gABuxo"]
[Tue Jul 21 08:24:33.450694 2026] [security2:error] [pid 419508:tid 419682] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W8VcagwCeNbomjVsT0gABuxo"]
[Tue Jul 21 08:24:33.549511 2026] [security2:error] [pid 419508:tid 419549] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/hur.php"] [unique_id "al9W8VcagwCeNbomjVsT1wABmSg"]
[Tue Jul 21 08:24:33.695303 2026] [security2:error] [pid 419508:tid 419766] [client 20.206.105.145:20259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/error_log.php"] [unique_id "al9W8VcagwCeNbomjVsT2wAAAg4"]
[Tue Jul 21 08:24:33.699867 2026] [security2:error] [pid 419508:tid 419530] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/zoro.php"] [unique_id "al9W8VcagwCeNbomjVsT3AAB6RU"]
[Tue Jul 21 08:24:33.703111 2026] [security2:error] [pid 419508:tid 419523] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W8VcagwCeNbomjVsT3QACAw4"]
[Tue Jul 21 08:24:33.703230 2026] [security2:error] [pid 419508:tid 419755] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W8VcagwCeNbomjVsT3QACAw4"]
[Tue Jul 21 08:24:33.741766 2026] [security2:error] [pid 418108:tid 418276] [client 109.248.148.246:34708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9W8Q0cxofL2J1zwYrGjQAAAS4"]
[Tue Jul 21 08:24:33.741860 2026] [security2:error] [pid 418108:tid 418276] [client 109.248.148.246:34708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9W8Q0cxofL2J1zwYrGjQAAAS4"]
[Tue Jul 21 08:24:33.848580 2026] [security2:error] [pid 419508:tid 419531] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/coffexium.php"] [unique_id "al9W8VcagwCeNbomjVsT4AACBxY"]
[Tue Jul 21 08:24:33.996716 2026] [security2:error] [pid 419508:tid 419617] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/app.php"] [unique_id "al9W8VcagwCeNbomjVsT4gABw2w"]
[Tue Jul 21 08:24:34.008745 2026] [core:alert] [pid 419508:tid 419737] [client 57.141.18.81:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:24:34.087996 2026] [security2:error] [pid 419508:tid 419763] [client 117.213.202.34:52346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W8lcagwCeNbomjVsT6AAAAgs"]
[Tue Jul 21 08:24:34.088098 2026] [security2:error] [pid 419508:tid 419763] [client 117.213.202.34:52346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W8lcagwCeNbomjVsT6AAAAgs"]
[Tue Jul 21 08:24:34.160833 2026] [security2:error] [pid 419508:tid 419520] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/core.php"] [unique_id "al9W8lcagwCeNbomjVsT6gABvQs"]
[Tue Jul 21 08:24:34.165685 2026] [security2:error] [pid 419508:tid 419723] [client 20.197.195.24:61094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/chosen.php"] [unique_id "al9W8lcagwCeNbomjVsT6wAAAeQ"]
[Tue Jul 21 08:24:34.208726 2026] [security2:error] [pid 419508:tid 419638] [client 150.129.202.39:65129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W8lcagwCeNbomjVsT8QAAAY8"]
[Tue Jul 21 08:24:34.208861 2026] [security2:error] [pid 419508:tid 419638] [client 150.129.202.39:65129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W8lcagwCeNbomjVsT8QAAAY8"]
[Tue Jul 21 08:24:34.308449 2026] [security2:error] [pid 418108:tid 418250] [client 20.220.225.223:19673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/old.php"] [unique_id "al9W8g0cxofL2J1zwYrGkgAAARQ"]
[Tue Jul 21 08:24:34.310364 2026] [security2:error] [pid 419508:tid 419599] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/main.php"] [unique_id "al9W8lcagwCeNbomjVsT9AABm1o"]
[Tue Jul 21 08:24:34.508107 2026] [security2:error] [pid 419508:tid 419612] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/init.php"] [unique_id "al9W8lcagwCeNbomjVsT_AACA2c"]
[Tue Jul 21 08:24:34.575032 2026] [security2:error] [pid 419508:tid 419526] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9W8lcagwCeNbomjVsUAAAB8xE"]
[Tue Jul 21 08:24:34.575171 2026] [security2:error] [pid 419508:tid 419738] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9W8lcagwCeNbomjVsUAAAB8xE"]
[Tue Jul 21 08:24:34.627465 2026] [security2:error] [pid 419508:tid 419578] [remote 203.161.62.87:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.62.161.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9W8lcagwCeNbomjVsUAgACBUU"]
[Tue Jul 21 08:24:34.668808 2026] [security2:error] [pid 419508:tid 419676] [client 151.63.71.144:57989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9W8lcagwCeNbomjVsUBAAAAbU"]
[Tue Jul 21 08:24:34.668939 2026] [security2:error] [pid 419508:tid 419676] [client 151.63.71.144:57989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9W8lcagwCeNbomjVsUBAAAAbU"]
[Tue Jul 21 08:24:34.697779 2026] [security2:error] [pid 419508:tid 419591] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/prekel.php"] [unique_id "al9W8lcagwCeNbomjVsUBQABn1I"]
[Tue Jul 21 08:24:34.797911 2026] [security2:error] [pid 419508:tid 419739] [client 195.49.128.211:60864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9W8lcagwCeNbomjVsUCgAAAfQ"]
[Tue Jul 21 08:24:34.798022 2026] [security2:error] [pid 419508:tid 419739] [client 195.49.128.211:60864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9W8lcagwCeNbomjVsUCgAAAfQ"]
[Tue Jul 21 08:24:34.854130 2026] [autoindex:error] [pid 419508:tid 419763] [client 43.160.219.206:41610] AH01276: Cannot serve directory /home2/luc15241/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:34.964666 2026] [autoindex:error] [pid 419508:tid 419656] [client 49.51.50.147:60892] AH01276: Cannot serve directory /home1/taina869/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:34.968023 2026] [security2:error] [pid 419508:tid 419611] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/0.php"] [unique_id "al9W8lcagwCeNbomjVsUDQABj2Y"]
[Tue Jul 21 08:24:35.141522 2026] [security2:error] [pid 419508:tid 419632] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/BDKR28.php"] [unique_id "al9W81cagwCeNbomjVsUFAACDns"]
[Tue Jul 21 08:24:35.180808 2026] [security2:error] [pid 419508:tid 419707] [client 74.7.228.55:36614] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.creantivedesign.com.br.creantivedesign.com"] [uri "/cgi-sys/404.html"] [unique_id "al9W81cagwCeNbomjVsUFgAB1DI"]
[Tue Jul 21 08:24:35.322530 2026] [security2:error] [pid 419508:tid 419565] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/f35.update.php"] [unique_id "al9W81cagwCeNbomjVsUGgAB3jg"]
[Tue Jul 21 08:24:35.382270 2026] [security2:error] [pid 419508:tid 419745] [client 128.127.105.184:43738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9W81cagwCeNbomjVsUGwAAAfk"]
[Tue Jul 21 08:24:35.382409 2026] [security2:error] [pid 419508:tid 419745] [client 128.127.105.184:43738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9W81cagwCeNbomjVsUGwAAAfk"]
[Tue Jul 21 08:24:35.518724 2026] [security2:error] [pid 419508:tid 419510] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/f900.php"] [unique_id "al9W81cagwCeNbomjVsUHwABkwE"]
[Tue Jul 21 08:24:35.666614 2026] [security2:error] [pid 419508:tid 419609] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/xmrl.php"] [unique_id "al9W81cagwCeNbomjVsUJgAB3GQ"]
[Tue Jul 21 08:24:35.810360 2026] [autoindex:error] [pid 419508:tid 419592] [remote 74.7.241.22:43338] AH01276: Cannot serve directory /home3/creant42/creantivedesign.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:35.815298 2026] [security2:error] [pid 419508:tid 419580] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/memberfuns.php"] [unique_id "al9W81cagwCeNbomjVsUKgAB30c"]
[Tue Jul 21 08:24:35.926408 2026] [security2:error] [pid 419508:tid 419706] [client 20.197.195.24:18345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/cream1.php"] [unique_id "al9W81cagwCeNbomjVsULgAAAdM"]
[Tue Jul 21 08:24:35.975708 2026] [security2:error] [pid 419508:tid 419540] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/ms.php"] [unique_id "al9W81cagwCeNbomjVsULwABtx8"]
[Tue Jul 21 08:24:36.111450 2026] [security2:error] [pid 419508:tid 419656] [client 14.245.224.124:49694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9W9FcagwCeNbomjVsUMQAAAaE"]
[Tue Jul 21 08:24:36.112031 2026] [security2:error] [pid 419508:tid 419656] [client 14.245.224.124:49694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9W9FcagwCeNbomjVsUMQAAAaE"]
[Tue Jul 21 08:24:36.174619 2026] [security2:error] [pid 419508:tid 419628] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/zz.php"] [unique_id "al9W9FcagwCeNbomjVsUNQAB6Xc"]
[Tue Jul 21 08:24:36.342855 2026] [security2:error] [pid 419508:tid 419527] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/for.php"] [unique_id "al9W9FcagwCeNbomjVsUOgAB2RI"]
[Tue Jul 21 08:24:36.514947 2026] [security2:error] [pid 419508:tid 419634] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/yup.php"] [unique_id "al9W9FcagwCeNbomjVsUPgACBX0"]
[Tue Jul 21 08:24:36.640219 2026] [security2:error] [pid 419508:tid 419679] [client 14.97.58.74:40027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9W9FcagwCeNbomjVsUQAAAAbg"]
[Tue Jul 21 08:24:36.640355 2026] [security2:error] [pid 419508:tid 419679] [client 14.97.58.74:40027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9W9FcagwCeNbomjVsUQAAAAbg"]
[Tue Jul 21 08:24:36.698308 2026] [security2:error] [pid 419508:tid 419604] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/wpxml.php"] [unique_id "al9W9FcagwCeNbomjVsURgAB0F8"]
[Tue Jul 21 08:24:36.846244 2026] [security2:error] [pid 419508:tid 419625] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/fffm.php"] [unique_id "al9W9FcagwCeNbomjVsUSgACC3Q"]
[Tue Jul 21 08:24:36.996521 2026] [security2:error] [pid 419508:tid 419650] [client 187.125.243.197:58903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9W9FcagwCeNbomjVsUUAAAAZs"]
[Tue Jul 21 08:24:36.996678 2026] [security2:error] [pid 419508:tid 419650] [client 187.125.243.197:58903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9W9FcagwCeNbomjVsUUAAAAZs"]
[Tue Jul 21 08:24:37.006867 2026] [security2:error] [pid 419508:tid 419630] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/gecko.php"] [unique_id "al9W9VcagwCeNbomjVsUUQAB8Hk"]
[Tue Jul 21 08:24:37.194764 2026] [security2:error] [pid 419508:tid 419549] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/a1.php"] [unique_id "al9W9VcagwCeNbomjVsUVAAByCg"]
[Tue Jul 21 08:24:37.253303 2026] [security2:error] [pid 419508:tid 419753] [client 36.95.145.2:36854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.145.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carrosselbuique.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W9FcagwCeNbomjVsUMAAAAgE"]
[Tue Jul 21 08:24:37.253438 2026] [security2:error] [pid 419508:tid 419753] [client 36.95.145.2:36854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carrosselbuique.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W9FcagwCeNbomjVsUMAAAAgE"]
[Tue Jul 21 08:24:37.368134 2026] [security2:error] [pid 419508:tid 419511] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/k2.php"] [unique_id "al9W9VcagwCeNbomjVsUVgABtAI"]
[Tue Jul 21 08:24:37.570976 2026] [security2:error] [pid 419508:tid 419530] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/82.php"] [unique_id "al9W9VcagwCeNbomjVsUWQAB6hU"]
[Tue Jul 21 08:24:37.578375 2026] [autoindex:error] [pid 419508:tid 419745] [client 20.197.195.24:18301] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:37.599675 2026] [autoindex:error] [pid 419508:tid 419757] [client 20.197.195.24:18301] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:37.634420 2026] [security2:error] [pid 419508:tid 419764] [client 20.197.195.24:18301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/dr.php"] [unique_id "al9W9VcagwCeNbomjVsUWwAAAgw"]
[Tue Jul 21 08:24:37.759911 2026] [security2:error] [pid 419508:tid 419531] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/config.json.php"] [unique_id "al9W9VcagwCeNbomjVsUXwABwBY"]
[Tue Jul 21 08:24:37.763954 2026] [security2:error] [pid 419508:tid 419640] [client 20.220.225.223:12561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.multicarsc.com.br"] [uri "/ms.php"] [unique_id "al9W9VcagwCeNbomjVsUYAAAAZE"]
[Tue Jul 21 08:24:37.852599 2026] [security2:error] [pid 418108:tid 418261] [client 115.134.11.136:61082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W9Q0cxofL2J1zwYrGsAAAAR8"]
[Tue Jul 21 08:24:37.853410 2026] [security2:error] [pid 418108:tid 418261] [client 115.134.11.136:61082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W9Q0cxofL2J1zwYrGsAAAAR8"]
[Tue Jul 21 08:24:37.926416 2026] [security2:error] [pid 419508:tid 419703] [client 91.92.41.115:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9W9VcagwCeNbomjVsUZQAAAdA"]
[Tue Jul 21 08:24:37.973731 2026] [security2:error] [pid 418108:tid 418314] [client 20.226.60.151:60608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/file88.php"] [unique_id "al9W9Q0cxofL2J1zwYrGtAAAAVQ"]
[Tue Jul 21 08:24:38.127537 2026] [security2:error] [pid 419508:tid 419585] [remote 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "expertemrecheios.com"] [uri "/fpwch.php"] [unique_id "al9W9lcagwCeNbomjVsUZwABqkw"]
[Tue Jul 21 08:24:38.344802 2026] [security2:error] [pid 419508:tid 419766] [client 109.248.148.246:43784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9W9lcagwCeNbomjVsUbgAAAg4"]
[Tue Jul 21 08:24:38.344960 2026] [security2:error] [pid 419508:tid 419766] [client 109.248.148.246:43784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9W9lcagwCeNbomjVsUbgAAAg4"]
[Tue Jul 21 08:24:38.510975 2026] [security2:error] [pid 418108:tid 418291] [client 65.21.113.253:49390] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9W9g0cxofL2J1zwYrGtgAAAT0"]
[Tue Jul 21 08:24:38.804926 2026] [security2:error] [pid 419508:tid 419681] [client 202.179.75.202:58846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9W9lcagwCeNbomjVsUdwAAAbo"]
[Tue Jul 21 08:24:38.810407 2026] [security2:error] [pid 419508:tid 419681] [client 202.179.75.202:58846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9W9lcagwCeNbomjVsUdwAAAbo"]
[Tue Jul 21 08:24:38.869584 2026] [security2:error] [pid 419508:tid 419653] [client 36.95.145.2:57862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.145.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carrosselbuique.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W9lcagwCeNbomjVsUeAAAAZ4"]
[Tue Jul 21 08:24:38.869684 2026] [security2:error] [pid 419508:tid 419653] [client 36.95.145.2:57862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carrosselbuique.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W9lcagwCeNbomjVsUeAAAAZ4"]
[Tue Jul 21 08:24:38.898638 2026] [security2:error] [pid 418108:tid 418355] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9W9g0cxofL2J1zwYrGuwABfRc"]
[Tue Jul 21 08:24:38.936074 2026] [security2:error] [pid 419508:tid 419698] [client 20.197.195.24:18344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/x.php"] [unique_id "al9W9lcagwCeNbomjVsUegAAAcs"]
[Tue Jul 21 08:24:39.178628 2026] [security2:error] [pid 419508:tid 419578] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W91cagwCeNbomjVsUfQACBUU"]
[Tue Jul 21 08:24:39.178855 2026] [security2:error] [pid 419508:tid 419757] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W91cagwCeNbomjVsUfQACBUU"]
[Tue Jul 21 08:24:39.323027 2026] [security2:error] [pid 418108:tid 418247] [client 20.206.105.145:20139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/xenon1337.php"] [unique_id "al9W9w0cxofL2J1zwYrGxAAAARE"]
[Tue Jul 21 08:24:39.773704 2026] [security2:error] [pid 418108:tid 418345] [client 65.21.113.253:50604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9W9w0cxofL2J1zwYrGwwAAAXM"]
[Tue Jul 21 08:24:39.883499 2026] [security2:error] [pid 419508:tid 419707] [client 20.206.105.145:20164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/test11.php"] [unique_id "al9W91cagwCeNbomjVsUiQAAAdQ"]
[Tue Jul 21 08:24:40.640412 2026] [security2:error] [pid 419508:tid 419565] [remote 216.73.216.184:45338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemape.xml"] [unique_id "al9W-FcagwCeNbomjVsUmAACBTg"]
[Tue Jul 21 08:24:41.152043 2026] [security2:error] [pid 419508:tid 419685] [client 20.226.60.151:56925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/as.php"] [unique_id "al9W-VcagwCeNbomjVsUowAAAb4"]
[Tue Jul 21 08:24:41.518658 2026] [security2:error] [pid 418108:tid 418233] [remote 41.186.86.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/wp-login.php"] [unique_id "al9W-Q0cxofL2J1zwYrG3wABIno"]
[Tue Jul 21 08:24:41.545933 2026] [security2:error] [pid 419508:tid 419749] [client 103.151.46.103:55679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9W-VcagwCeNbomjVsUqQAAAf0"]
[Tue Jul 21 08:24:41.546040 2026] [security2:error] [pid 419508:tid 419749] [client 103.151.46.103:55679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9W-VcagwCeNbomjVsUqQAAAf0"]
[Tue Jul 21 08:24:41.560938 2026] [security2:error] [pid 419508:tid 419742] [client 20.197.195.24:61130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/155.php"] [unique_id "al9W-VcagwCeNbomjVsUqgAAAfc"]
[Tue Jul 21 08:24:42.016255 2026] [security2:error] [pid 418108:tid 418159] [remote 209.42.18.223:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "franciscaco.com.br"] [uri "/wp-login.php"] [unique_id "al9W-Q0cxofL2J1zwYrG6QABgTA"]
[Tue Jul 21 08:24:42.203666 2026] [security2:error] [pid 418108:tid 418269] [client 185.8.106.219:28400] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "odontoclinicms.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9W-g0cxofL2J1zwYrG8QAAASc"]
[Tue Jul 21 08:24:42.534536 2026] [security2:error] [pid 418108:tid 418208] [remote 202.51.202.242:52064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9W-g0cxofL2J1zwYrG9gABOmE"]
[Tue Jul 21 08:24:43.092361 2026] [security2:error] [pid 418108:tid 418291] [client 20.206.105.145:20158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/koala.php"] [unique_id "al9W-w0cxofL2J1zwYrG_AAAAT0"]
[Tue Jul 21 08:24:43.124606 2026] [security2:error] [pid 418108:tid 418325] [client 65.21.113.253:50604] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9W-g0cxofL2J1zwYrG9wAAAV8"]
[Tue Jul 21 08:24:43.176345 2026] [qos:error] [pid 419508:tid 419630] [remote 57.141.18.85:23428] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.85, id=al9W-1cagwCeNbomjVsUyAAB6Hk
[Tue Jul 21 08:24:43.193211 2026] [security2:error] [pid 419508:tid 419735] [client 20.197.195.24:3544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/ops.php"] [unique_id "al9W-1cagwCeNbomjVsUyQAAAfA"]
[Tue Jul 21 08:24:43.293779 2026] [security2:error] [pid 418108:tid 418282] [client 185.8.106.219:57310] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "odontoclinicms.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9W-w0cxofL2J1zwYrHAgAAATQ"]
[Tue Jul 21 08:24:43.915549 2026] [security2:error] [pid 419508:tid 419546] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W-1cagwCeNbomjVsU1wAB3CU"]
[Tue Jul 21 08:24:43.915735 2026] [security2:error] [pid 419508:tid 419715] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W-1cagwCeNbomjVsU1wAB3CU"]
[Tue Jul 21 08:24:44.398640 2026] [security2:error] [pid 418108:tid 418141] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W_A0cxofL2J1zwYrHEQABbh4"]
[Tue Jul 21 08:24:44.398800 2026] [security2:error] [pid 418108:tid 418340] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W_A0cxofL2J1zwYrHEQABbh4"]
[Tue Jul 21 08:24:44.411854 2026] [security2:error] [pid 418108:tid 418266] [client 65.21.113.253:50590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9W_A0cxofL2J1zwYrHDwAAASQ"]
[Tue Jul 21 08:24:44.427847 2026] [security2:error] [pid 419508:tid 419708] [client 20.197.192.193:5624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/track.php"] [unique_id "al9W_FcagwCeNbomjVsU4wAAAdU"]
[Tue Jul 21 08:24:44.483944 2026] [security2:error] [pid 419508:tid 419698] [client 185.198.240.183:59229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mbarcondicionados.com.br"] [uri "/wp-login.php"] [unique_id "al9W_FcagwCeNbomjVsU5AAAAcs"]
[Tue Jul 21 08:24:44.508095 2026] [qos:error] [pid 418108:tid 418188] [remote 57.141.18.50:24576] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.50, id=al9W_A0cxofL2J1zwYrHEwABbE0
[Tue Jul 21 08:24:44.526745 2026] [qos:error] [pid 419508:tid 419599] [remote 57.141.18.63:53234] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.63, id=al9W_FcagwCeNbomjVsU5QAB5Vo
[Tue Jul 21 08:24:44.544474 2026] [security2:error] [pid 419508:tid 419520] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/.vscode/.env"] [unique_id "al9W_FcagwCeNbomjVsU5gAB_Qs"]
[Tue Jul 21 08:24:44.603672 2026] [security2:error] [pid 419508:tid 419707] [client 185.8.106.219:28404] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.odontoclinicms.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9W_FcagwCeNbomjVsU6wAAAdQ"]
[Tue Jul 21 08:24:44.727979 2026] [security2:error] [pid 419508:tid 419728] [client 117.213.202.34:52905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W_FcagwCeNbomjVsU7AAAAek"]
[Tue Jul 21 08:24:44.728124 2026] [security2:error] [pid 419508:tid 419728] [client 117.213.202.34:52905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W_FcagwCeNbomjVsU7AAAAek"]
[Tue Jul 21 08:24:44.794260 2026] [security2:error] [pid 419508:tid 419660] [client 150.129.202.39:65349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W_FcagwCeNbomjVsU7QAAAaU"]
[Tue Jul 21 08:24:44.794397 2026] [security2:error] [pid 419508:tid 419660] [client 150.129.202.39:65349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9W_FcagwCeNbomjVsU7QAAAaU"]
[Tue Jul 21 08:24:44.846158 2026] [qos:error] [pid 418108:tid 418210] [remote 57.141.18.2:41816] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.2, id=al9W_A0cxofL2J1zwYrHFQABD2M
[Tue Jul 21 08:24:45.009423 2026] [qos:error] [pid 418108:tid 418146] [remote 57.141.18.95:58464] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.95, id=al9W_Q0cxofL2J1zwYrHGQABQyM
[Tue Jul 21 08:24:45.122173 2026] [security2:error] [pid 418108:tid 418192] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9W_Q0cxofL2J1zwYrHGwABIVE"]
[Tue Jul 21 08:24:45.122301 2026] [security2:error] [pid 418108:tid 418263] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9W_Q0cxofL2J1zwYrHGwABIVE"]
[Tue Jul 21 08:24:45.453259 2026] [security2:error] [pid 419508:tid 419640] [client 195.49.128.211:61453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9W_VcagwCeNbomjVsU9AAAAZE"]
[Tue Jul 21 08:24:45.453373 2026] [security2:error] [pid 419508:tid 419640] [client 195.49.128.211:61453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9W_VcagwCeNbomjVsU9AAAAZE"]
[Tue Jul 21 08:24:45.514728 2026] [security2:error] [pid 418108:tid 418241] [client 20.197.195.24:18341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/file31.php"] [unique_id "al9W_Q0cxofL2J1zwYrHHwAAAQs"]
[Tue Jul 21 08:24:45.654422 2026] [security2:error] [pid 419508:tid 419708] [client 20.197.192.193:5992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/2352356666.php"] [unique_id "al9W_VcagwCeNbomjVsU_AAAAdU"]
[Tue Jul 21 08:24:45.660916 2026] [security2:error] [pid 418108:tid 418262] [client 65.21.113.253:50590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9W_Q0cxofL2J1zwYrHHAAAASA"]
[Tue Jul 21 08:24:45.682428 2026] [security2:error] [pid 419508:tid 419648] [client 185.8.106.219:28412] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "odontoclinicms.com.br"] [uri "/"] [unique_id "al9W_VcagwCeNbomjVsU_QAAAZk"]
[Tue Jul 21 08:24:46.347069 2026] [qos:error] [pid 418108:tid 418202] [remote 57.141.18.63:53244] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.63, id=al9W_g0cxofL2J1zwYrHKQABVFs
[Tue Jul 21 08:24:46.543289 2026] [qos:error] [pid 419508:tid 419534] [remote 57.141.18.89:52318] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.89, id=al9W_lcagwCeNbomjVsVCAAB7Bk
[Tue Jul 21 08:24:46.578508 2026] [security2:error] [pid 419508:tid 419615] [remote 20.153.140.50:57586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9W_lcagwCeNbomjVsVCQAB1Go"]
[Tue Jul 21 08:24:46.759589 2026] [qos:error] [pid 419508:tid 419565] [remote 57.141.18.4:38520] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.4, id=al9W_lcagwCeNbomjVsVDgABwDg
[Tue Jul 21 08:24:46.946484 2026] [qos:error] [pid 419508:tid 419510] [remote 57.141.18.43:58684] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.43, id=al9W_lcagwCeNbomjVsVEgAB2wE
[Tue Jul 21 08:24:46.971245 2026] [qos:error] [pid 419508:tid 419594] [remote 57.141.18.66:26836] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.66, id=al9W_lcagwCeNbomjVsVEwACDlU
[Tue Jul 21 08:24:47.065931 2026] [qos:error] [pid 419508:tid 419592] [remote 57.141.18.5:57492] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.5, id=al9W_1cagwCeNbomjVsVFAAB31M
[Tue Jul 21 08:24:47.117581 2026] [security2:error] [pid 418108:tid 418250] [client 14.245.224.124:50207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9W_w0cxofL2J1zwYrHMgAAARQ"]
[Tue Jul 21 08:24:47.117677 2026] [security2:error] [pid 418108:tid 418250] [client 14.245.224.124:50207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9W_w0cxofL2J1zwYrHMgAAARQ"]
[Tue Jul 21 08:24:47.196407 2026] [security2:error] [pid 419508:tid 419716] [client 36.95.145.2:57878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.145.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carrosselbuique.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9W_1cagwCeNbomjVsVGAAAAd0"]
[Tue Jul 21 08:24:47.196472 2026] [security2:error] [pid 419508:tid 419716] [client 36.95.145.2:57878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carrosselbuique.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9W_1cagwCeNbomjVsVGAAAAd0"]
[Tue Jul 21 08:24:47.370576 2026] [security2:error] [pid 418108:tid 418302] [client 137.97.59.154:55159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9W_w0cxofL2J1zwYrHNAAAAUg"]
[Tue Jul 21 08:24:47.370778 2026] [security2:error] [pid 418108:tid 418302] [client 137.97.59.154:55159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9W_w0cxofL2J1zwYrHNAAAAUg"]
[Tue Jul 21 08:24:47.474722 2026] [security2:error] [pid 418108:tid 418286] [client 187.125.243.197:59407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9W_w0cxofL2J1zwYrHNQAAATg"]
[Tue Jul 21 08:24:47.474892 2026] [security2:error] [pid 418108:tid 418286] [client 187.125.243.197:59407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9W_w0cxofL2J1zwYrHNQAAATg"]
[Tue Jul 21 08:24:47.735248 2026] [security2:error] [pid 418108:tid 418266] [client 20.197.195.24:61168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/file6.php"] [unique_id "al9W_w0cxofL2J1zwYrHOgAAASQ"]
[Tue Jul 21 08:24:47.880003 2026] [security2:error] [pid 418108:tid 418322] [client 20.220.225.223:19293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/ms-new.php"] [unique_id "al9W_w0cxofL2J1zwYrHOwAAAVw"]
[Tue Jul 21 08:24:48.123149 2026] [qos:error] [pid 418108:tid 418156] [remote 57.141.18.82:47156] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.82, id=al9XAA0cxofL2J1zwYrHPwABWi0
[Tue Jul 21 08:24:48.133890 2026] [security2:error] [pid 419508:tid 419638] [client 20.226.60.151:50134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/ccc.php"] [unique_id "al9XAFcagwCeNbomjVsVJgAAAY8"]
[Tue Jul 21 08:24:48.248535 2026] [proxy:error] [pid 419508:tid 419642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:24:48.248610 2026] [proxy_http:error] [pid 419508:tid 419642] [client 147.182.235.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:24:48.249222 2026] [proxy:error] [pid 419508:tid 419642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:24:48.249252 2026] [proxy_http:error] [pid 419508:tid 419642] [client 147.182.235.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:24:48.329148 2026] [qos:error] [pid 419508:tid 419587] [remote 57.141.18.82:47172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.82, id=al9XAFcagwCeNbomjVsVLAABsE4
[Tue Jul 21 08:24:48.688643 2026] [proxy:error] [pid 418108:tid 418292] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:24:48.688709 2026] [proxy_http:error] [pid 418108:tid 418292] [client 147.182.235.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.iuripinheiro1748254358078.0711679.meusitehostgator.com.br/
[Tue Jul 21 08:24:48.689450 2026] [proxy:error] [pid 418108:tid 418292] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:24:48.689485 2026] [proxy_http:error] [pid 418108:tid 418292] [client 147.182.235.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.iuripinheiro1748254358078.0711679.meusitehostgator.com.br/
[Tue Jul 21 08:24:48.721370 2026] [security2:error] [pid 419508:tid 419533] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9XAFcagwCeNbomjVsVLgABsRg"]
[Tue Jul 21 08:24:48.876118 2026] [security2:error] [pid 419508:tid 419630] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9XAFcagwCeNbomjVsVMwABxHk"]
[Tue Jul 21 08:24:49.029000 2026] [security2:error] [pid 418108:tid 418263] [client 65.21.113.253:50590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XAA0cxofL2J1zwYrHRwAAASE"]
[Tue Jul 21 08:24:49.129197 2026] [autoindex:error] [pid 418108:tid 418313] [client 20.197.195.24:18241] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:49.138462 2026] [security2:error] [pid 418108:tid 418268] [client 20.197.195.24:18241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/adminfuns.php"] [unique_id "al9XAQ0cxofL2J1zwYrHTAAAASY"]
[Tue Jul 21 08:24:49.179521 2026] [security2:error] [pid 418108:tid 418294] [client 36.95.145.2:35274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.145.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carrosselbuique.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "al9XAQ0cxofL2J1zwYrHTQAAAUA"]
[Tue Jul 21 08:24:49.179593 2026] [security2:error] [pid 418108:tid 418294] [client 36.95.145.2:35274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carrosselbuique.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "al9XAQ0cxofL2J1zwYrHTQAAAUA"]
[Tue Jul 21 08:24:49.282761 2026] [qos:error] [pid 419508:tid 419717] [client 162.241.63.68:34502] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9XAVcagwCeNbomjVsVOQAAAd4
[Tue Jul 21 08:24:49.617537 2026] [security2:error] [pid 419508:tid 419677] [client 202.179.75.202:53080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XAVcagwCeNbomjVsVQgAAAbY"]
[Tue Jul 21 08:24:49.617663 2026] [security2:error] [pid 419508:tid 419677] [client 202.179.75.202:53080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XAVcagwCeNbomjVsVQgAAAbY"]
[Tue Jul 21 08:24:49.618781 2026] [security2:error] [pid 419508:tid 419516] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/dp.php"] [unique_id "al9XAVcagwCeNbomjVsVQwAByAc"]
[Tue Jul 21 08:24:49.706565 2026] [security2:error] [pid 418108:tid 418246] [client 115.134.11.136:61567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XAQ0cxofL2J1zwYrHVAAAARA"]
[Tue Jul 21 08:24:49.706778 2026] [security2:error] [pid 418108:tid 418333] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XAQ0cxofL2J1zwYrHUQABZ0U"]
[Tue Jul 21 08:24:49.707251 2026] [security2:error] [pid 418108:tid 418246] [client 115.134.11.136:61567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XAQ0cxofL2J1zwYrHVAAAARA"]
[Tue Jul 21 08:24:49.717658 2026] [security2:error] [pid 419508:tid 419724] [client 89.238.167.134:59028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9XAVcagwCeNbomjVsVRgAAAeU"]
[Tue Jul 21 08:24:49.717754 2026] [security2:error] [pid 419508:tid 419724] [client 89.238.167.134:59028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9XAVcagwCeNbomjVsVRgAAAeU"]
[Tue Jul 21 08:24:49.741075 2026] [security2:error] [pid 419508:tid 419648] [client 20.206.105.145:20108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/mac.php"] [unique_id "al9XAVcagwCeNbomjVsVRwAAAZk"]
[Tue Jul 21 08:24:49.779852 2026] [security2:error] [pid 419508:tid 419636] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/old.php"] [unique_id "al9XAVcagwCeNbomjVsVSgABxH8"]
[Tue Jul 21 08:24:49.921934 2026] [security2:error] [pid 418108:tid 418358] [client 20.197.195.24:3556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/goods.php"] [unique_id "al9XAQ0cxofL2J1zwYrHVQAAAYA"]
[Tue Jul 21 08:24:49.954191 2026] [security2:error] [pid 419508:tid 419546] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/ms-new.php"] [unique_id "al9XAVcagwCeNbomjVsVTwAB3iU"]
[Tue Jul 21 08:24:49.956421 2026] [security2:error] [pid 419508:tid 419560] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XAVcagwCeNbomjVsVUAAB1TM"]
[Tue Jul 21 08:24:49.956554 2026] [security2:error] [pid 419508:tid 419708] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XAVcagwCeNbomjVsVUAAB1TM"]
[Tue Jul 21 08:24:49.985654 2026] [security2:error] [pid 419508:tid 419585] [remote 41.186.86.12:63381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9XAVcagwCeNbomjVsVUQAB7Ew"]
[Tue Jul 21 08:24:50.130445 2026] [security2:error] [pid 419508:tid 419601] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/track.php"] [unique_id "al9XAlcagwCeNbomjVsVUwABwFw"]
[Tue Jul 21 08:24:50.302314 2026] [security2:error] [pid 419508:tid 419544] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/2352356666.php"] [unique_id "al9XAlcagwCeNbomjVsVVgACDiM"]
[Tue Jul 21 08:24:50.470948 2026] [security2:error] [pid 419508:tid 419520] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/pn.php"] [unique_id "al9XAlcagwCeNbomjVsVWAABkws"]
[Tue Jul 21 08:24:50.701957 2026] [security2:error] [pid 419508:tid 419586] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9XAlcagwCeNbomjVsVWwABuE0"]
[Tue Jul 21 08:24:50.798236 2026] [security2:error] [pid 419508:tid 419672] [client 54.39.136.198:64362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "moratoadvogado.com"] [uri "/robots.txt"] [unique_id "al9XAlcagwCeNbomjVsVXAAAAbE"]
[Tue Jul 21 08:24:50.798377 2026] [security2:error] [pid 419508:tid 419672] [client 54.39.136.198:64362] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "moratoadvogado.com"] [uri "/robots.txt"] [unique_id "al9XAlcagwCeNbomjVsVXAAAAbE"]
[Tue Jul 21 08:24:50.861637 2026] [security2:error] [pid 419508:tid 419716] [client 20.226.60.151:60626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/777.php"] [unique_id "al9XAlcagwCeNbomjVsVYAAAAd0"]
[Tue Jul 21 08:24:50.862666 2026] [security2:error] [pid 419508:tid 419578] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/dr.php"] [unique_id "al9XAlcagwCeNbomjVsVYQAB2UU"]
[Tue Jul 21 08:24:50.922417 2026] [security2:error] [pid 419508:tid 419742] [client 20.197.195.24:18328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/100.php"] [unique_id "al9XAlcagwCeNbomjVsVYwAAAfc"]
[Tue Jul 21 08:24:51.021313 2026] [security2:error] [pid 419508:tid 419539] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/2x.php"] [unique_id "al9XA1cagwCeNbomjVsVZAACDB4"]
[Tue Jul 21 08:24:51.192926 2026] [security2:error] [pid 419508:tid 419523] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/kq1.php"] [unique_id "al9XA1cagwCeNbomjVsVaQABsg4"]
[Tue Jul 21 08:24:51.353259 2026] [security2:error] [pid 419508:tid 419532] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/zzz.php"] [unique_id "al9XA1cagwCeNbomjVsVbQAB-Rc"]
[Tue Jul 21 08:24:51.451597 2026] [security2:error] [pid 418108:tid 418287] [client 65.21.113.253:50590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XAw0cxofL2J1zwYrHaQAAATk"]
[Tue Jul 21 08:24:51.471218 2026] [security2:error] [pid 419508:tid 419647] [client 20.197.195.24:13870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/about.php"] [unique_id "al9XA1cagwCeNbomjVsVcAAAAZg"]
[Tue Jul 21 08:24:51.502184 2026] [security2:error] [pid 419508:tid 419547] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/wicked.php"] [unique_id "al9XA1cagwCeNbomjVsVcQAB1CY"]
[Tue Jul 21 08:24:51.548794 2026] [security2:error] [pid 419508:tid 419642] [client 20.197.195.24:3554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/about.php"] [unique_id "al9XA1cagwCeNbomjVsVcgAAAZM"]
[Tue Jul 21 08:24:51.576873 2026] [security2:error] [pid 419508:tid 419677] [client 20.197.195.24:18263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/admin.php"] [unique_id "al9XA1cagwCeNbomjVsVdAAAAbY"]
[Tue Jul 21 08:24:51.605415 2026] [security2:error] [pid 418108:tid 418297] [client 20.197.195.24:13883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/admin.php"] [unique_id "al9XAw0cxofL2J1zwYrHbQAAAUM"]
[Tue Jul 21 08:24:51.670805 2026] [security2:error] [pid 419508:tid 419534] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/edit.php"] [unique_id "al9XA1cagwCeNbomjVsVdQABjxk"]
[Tue Jul 21 08:24:51.708795 2026] [security2:error] [pid 419508:tid 419672] [client 20.197.195.24:3538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/themes.php"] [unique_id "al9XA1cagwCeNbomjVsVdgAAAbE"]
[Tue Jul 21 08:24:51.856164 2026] [security2:error] [pid 419508:tid 419615] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/kua.php"] [unique_id "al9XA1cagwCeNbomjVsVeQABsGo"]
[Tue Jul 21 08:24:51.956340 2026] [autoindex:error] [pid 419508:tid 419703] [client 20.197.195.24:18275] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:52.017843 2026] [security2:error] [pid 419508:tid 419510] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/ez.php"] [unique_id "al9XBFcagwCeNbomjVsVgAABxAE"]
[Tue Jul 21 08:24:52.180076 2026] [security2:error] [pid 419508:tid 419594] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/fz.php"] [unique_id "al9XBFcagwCeNbomjVsVgQAB3lU"]
[Tue Jul 21 08:24:52.208704 2026] [security2:error] [pid 418108:tid 418289] [client 142.44.233.218:39014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "moratoadvogado.com"] [uri "/"] [unique_id "al9XBA0cxofL2J1zwYrHcwAAATs"]
[Tue Jul 21 08:24:52.208826 2026] [security2:error] [pid 418108:tid 418289] [client 142.44.233.218:39014] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "moratoadvogado.com"] [uri "/"] [unique_id "al9XBA0cxofL2J1zwYrHcwAAATs"]
[Tue Jul 21 08:24:52.339124 2026] [security2:error] [pid 419508:tid 419613] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/la.php"] [unique_id "al9XBFcagwCeNbomjVsViAABymg"]
[Tue Jul 21 08:24:52.476262 2026] [security2:error] [pid 419508:tid 419765] [client 172.245.89.35:54172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "nbmnews.com"] [uri "/"] [unique_id "al9XBFcagwCeNbomjVsVjwAAAg0"]
[Tue Jul 21 08:24:52.489500 2026] [security2:error] [pid 419508:tid 419597] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9XBFcagwCeNbomjVsVkQAB1Fg"]
[Tue Jul 21 08:24:52.585160 2026] [security2:error] [pid 418108:tid 418311] [client 20.220.225.223:19656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/track.php"] [unique_id "al9XBA0cxofL2J1zwYrHfQAAAVE"]
[Tue Jul 21 08:24:52.638432 2026] [security2:error] [pid 419508:tid 419607] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/inso.php"] [unique_id "al9XBFcagwCeNbomjVsVlAABj2I"]
[Tue Jul 21 08:24:52.805146 2026] [security2:error] [pid 419508:tid 419628] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/wpx.php"] [unique_id "al9XBFcagwCeNbomjVsVmAACAXc"]
[Tue Jul 21 08:24:52.868264 2026] [security2:error] [pid 419508:tid 419712] [client 20.197.195.24:18275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/.well-known/about.php"] [unique_id "al9XBFcagwCeNbomjVsVmwAAAdk"]
[Tue Jul 21 08:24:52.877952 2026] [security2:error] [pid 419508:tid 419660] [client 65.21.113.253:42678] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XBFcagwCeNbomjVsVjAAAAaU"]
[Tue Jul 21 08:24:52.955450 2026] [security2:error] [pid 419508:tid 419533] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/berlin.php"] [unique_id "al9XBFcagwCeNbomjVsVogAB3hg"]
[Tue Jul 21 08:24:53.059216 2026] [security2:error] [pid 419508:tid 419752] [client 20.226.60.151:60658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/for.php"] [unique_id "al9XBVcagwCeNbomjVsVpQAAAgA"]
[Tue Jul 21 08:24:53.120208 2026] [security2:error] [pid 419508:tid 419630] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/billur.php"] [unique_id "al9XBVcagwCeNbomjVsVpwAB6nk"]
[Tue Jul 21 08:24:53.241888 2026] [security2:error] [pid 419508:tid 419625] [remote 173.252.87.1:38076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9XBVcagwCeNbomjVsVqgAB1XQ"]
[Tue Jul 21 08:24:53.280161 2026] [security2:error] [pid 418108:tid 418291] [client 20.197.195.24:12887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9XBQ0cxofL2J1zwYrHhQAAAT0"]
[Tue Jul 21 08:24:53.300124 2026] [security2:error] [pid 419508:tid 419635] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/mimpi.php"] [unique_id "al9XBVcagwCeNbomjVsVqwAB1H4"]
[Tue Jul 21 08:24:53.397823 2026] [security2:error] [pid 419508:tid 419645] [client 20.197.195.24:18320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wefile.php"] [unique_id "al9XBVcagwCeNbomjVsVrAAAAZY"]
[Tue Jul 21 08:24:53.467010 2026] [security2:error] [pid 419508:tid 419571] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/dp.php"] [unique_id "al9XBVcagwCeNbomjVsVrwABmz4"]
[Tue Jul 21 08:24:53.536002 2026] [security2:error] [pid 418108:tid 418282] [client 20.197.195.24:3552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9XBQ0cxofL2J1zwYrHhgAAATQ"]
[Tue Jul 21 08:24:53.624083 2026] [security2:error] [pid 419508:tid 419516] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/bootstrap.php"] [unique_id "al9XBVcagwCeNbomjVsVtAAB6Ac"]
[Tue Jul 21 08:24:53.700074 2026] [autoindex:error] [pid 419508:tid 419728] [client 20.197.195.24:61116] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:53.762057 2026] [autoindex:error] [pid 419508:tid 419660] [client 20.197.195.24:61116] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:53.768643 2026] [security2:error] [pid 419508:tid 419675] [client 20.197.195.24:61116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9XBVcagwCeNbomjVsVuwAAAbQ"]
[Tue Jul 21 08:24:53.773283 2026] [security2:error] [pid 419508:tid 419620] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/wp-editor.php"] [unique_id "al9XBVcagwCeNbomjVsVvAACDG8"]
[Tue Jul 21 08:24:53.812653 2026] [security2:error] [pid 419508:tid 419735] [client 20.220.225.223:52623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/blue.php"] [unique_id "al9XBVcagwCeNbomjVsVvwAAAfA"]
[Tue Jul 21 08:24:53.936744 2026] [security2:error] [pid 419508:tid 419585] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/cro.php"] [unique_id "al9XBVcagwCeNbomjVsVwQAB5Ew"]
[Tue Jul 21 08:24:53.956612 2026] [security2:error] [pid 419508:tid 419677] [client 20.197.195.24:18292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/8.php"] [unique_id "al9XBVcagwCeNbomjVsVwgAAAbY"]
[Tue Jul 21 08:24:54.091988 2026] [security2:error] [pid 419508:tid 419530] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/cron-tab.php"] [unique_id "al9XBlcagwCeNbomjVsVyQAB-RU"]
[Tue Jul 21 08:24:54.384125 2026] [security2:error] [pid 419508:tid 419631] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XBlcagwCeNbomjVsVzwAB8Xo"]
[Tue Jul 21 08:24:54.384315 2026] [security2:error] [pid 419508:tid 419736] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XBlcagwCeNbomjVsVzwAB8Xo"]
[Tue Jul 21 08:24:54.413740 2026] [security2:error] [pid 419508:tid 419758] [client 20.197.195.24:61091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9XBlcagwCeNbomjVsV0gAAAgY"]
[Tue Jul 21 08:24:54.477094 2026] [security2:error] [pid 418108:tid 418358] [client 65.21.113.253:50590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XBg0cxofL2J1zwYrHiQAAAYA"]
[Tue Jul 21 08:24:54.650388 2026] [security2:error] [pid 419508:tid 419662] [client 213.152.186.163:53586] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9XBlcagwCeNbomjVsV2QAAAac"]
[Tue Jul 21 08:24:54.650481 2026] [security2:error] [pid 419508:tid 419662] [client 213.152.186.163:53586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9XBlcagwCeNbomjVsV2QAAAac"]
[Tue Jul 21 08:24:54.662708 2026] [security2:error] [pid 419508:tid 419586] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/koiy.php"] [unique_id "al9XBlcagwCeNbomjVsV2gAB2U0"]
[Tue Jul 21 08:24:54.804364 2026] [security2:error] [pid 418108:tid 418345] [client 20.197.195.24:61060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/f6.php"] [unique_id "al9XBg0cxofL2J1zwYrHkAAAAXM"]
[Tue Jul 21 08:24:54.857985 2026] [security2:error] [pid 419508:tid 419578] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/hp2.php"] [unique_id "al9XBlcagwCeNbomjVsV3wACCkU"]
[Tue Jul 21 08:24:55.021400 2026] [security2:error] [pid 419508:tid 419539] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/hp3.php"] [unique_id "al9XB1cagwCeNbomjVsV4QABoB4"]
[Tue Jul 21 08:24:55.035718 2026] [security2:error] [pid 419508:tid 419523] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XB1cagwCeNbomjVsV4wABmA4"]
[Tue Jul 21 08:24:55.035866 2026] [security2:error] [pid 419508:tid 419647] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XB1cagwCeNbomjVsV4wABmA4"]
[Tue Jul 21 08:24:55.037186 2026] [autoindex:error] [pid 418108:tid 418215] [remote 74.7.242.32:60704] AH01276: Cannot serve directory /home2/divmax55/forrosemcuritiba.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:24:55.068671 2026] [security2:error] [pid 419508:tid 419613] [remote 41.76.214.143:41030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "volyoaudiobooks.com"] [uri "/wp-login.php"] [unique_id "al9XB1cagwCeNbomjVsV9gABvmg"]
[Tue Jul 21 08:24:55.088178 2026] [security2:error] [pid 418108:tid 418286] [client 74.7.241.167:40956] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "forrosemcuritiba.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9XBw0cxofL2J1zwYrHlQABOBg"]
[Tue Jul 21 08:24:55.092164 2026] [security2:error] [pid 418108:tid 418299] [client 20.197.195.24:61157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/inputs.php"] [unique_id "al9XBw0cxofL2J1zwYrHlgAAAUU"]
[Tue Jul 21 08:24:55.317559 2026] [security2:error] [pid 418108:tid 418266] [client 34.0.33.167:41732] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bylaisguimaraes.online"] [uri "/default.html"] [unique_id "al9XBw0cxofL2J1zwYrHmAAAASQ"]
[Tue Jul 21 08:24:55.377882 2026] [security2:error] [pid 419508:tid 419549] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/aa1.php"] [unique_id "al9XB1cagwCeNbomjVsWHwAB6Cg"]
[Tue Jul 21 08:24:55.413676 2026] [security2:error] [pid 419508:tid 419657] [client 150.129.202.39:64881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XB1cagwCeNbomjVsWJQAAAaI"]
[Tue Jul 21 08:24:55.413790 2026] [security2:error] [pid 419508:tid 419657] [client 150.129.202.39:64881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XB1cagwCeNbomjVsWJQAAAaI"]
[Tue Jul 21 08:24:55.457801 2026] [security2:error] [pid 418108:tid 418302] [client 65.21.113.253:50590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XBg0cxofL2J1zwYrHkwAAAUg"]
[Tue Jul 21 08:24:55.474043 2026] [security2:error] [pid 419508:tid 419675] [client 20.197.192.193:5617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/pn.php"] [unique_id "al9XB1cagwCeNbomjVsWKAAAAbQ"]
[Tue Jul 21 08:24:55.512679 2026] [security2:error] [pid 418108:tid 418351] [client 20.206.105.145:20152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9XBw0cxofL2J1zwYrHnAAAAXk"]
[Tue Jul 21 08:24:55.621221 2026] [security2:error] [pid 419508:tid 419602] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/acew67.php"] [unique_id "al9XB1cagwCeNbomjVsWLAAByF0"]
[Tue Jul 21 08:24:55.664268 2026] [security2:error] [pid 419508:tid 419518] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XB1cagwCeNbomjVsWLwABxQk"]
[Tue Jul 21 08:24:55.664436 2026] [security2:error] [pid 419508:tid 419692] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XB1cagwCeNbomjVsWLwABxQk"]
[Tue Jul 21 08:24:55.720986 2026] [security2:error] [pid 419508:tid 419749] [client 34.0.33.167:41744] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "bylaisguimaraes.online"] [uri "/cgi-sys/404.html"] [unique_id "al9XB1cagwCeNbomjVsWMgAAAf0"]
[Tue Jul 21 08:24:55.770217 2026] [security2:error] [pid 419508:tid 419557] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/bscclapb.php"] [unique_id "al9XB1cagwCeNbomjVsWNAAB-TA"]
[Tue Jul 21 08:24:55.798810 2026] [security2:error] [pid 418108:tid 418194] [remote 68.178.160.25:56926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medoraldracena.com.br"] [uri "/wp-login.php"] [unique_id "al9XBw0cxofL2J1zwYrHoAABXVM"]
[Tue Jul 21 08:24:55.919720 2026] [security2:error] [pid 419508:tid 419615] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/else1.php"] [unique_id "al9XB1cagwCeNbomjVsWPQAB22o"]
[Tue Jul 21 08:24:55.969735 2026] [security2:error] [pid 419508:tid 419731] [client 20.197.195.24:3518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/inputs.php"] [unique_id "al9XB1cagwCeNbomjVsWPwAAAew"]
[Tue Jul 21 08:24:56.063782 2026] [security2:error] [pid 419508:tid 419687] [client 195.49.128.211:62040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XCFcagwCeNbomjVsWRwAAAcA"]
[Tue Jul 21 08:24:56.063928 2026] [security2:error] [pid 419508:tid 419687] [client 195.49.128.211:62040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XCFcagwCeNbomjVsWRwAAAcA"]
[Tue Jul 21 08:24:56.082599 2026] [security2:error] [pid 419508:tid 419613] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/tkikikoko.php"] [unique_id "al9XCFcagwCeNbomjVsWSAAB5Wg"]
[Tue Jul 21 08:24:56.128332 2026] [security2:error] [pid 419508:tid 419653] [client 34.0.33.167:41756] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "bylaisguimaraes.online"] [uri "/cgi-sys/404.html"] [unique_id "al9XCFcagwCeNbomjVsWTQAAAZ4"]
[Tue Jul 21 08:24:56.260088 2026] [security2:error] [pid 419508:tid 419597] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9XCFcagwCeNbomjVsWUAABj1g"]
[Tue Jul 21 08:24:56.328694 2026] [security2:error] [pid 419508:tid 419648] [client 20.226.60.151:60569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/ssla.php"] [unique_id "al9XCFcagwCeNbomjVsWUQAAAZk"]
[Tue Jul 21 08:24:56.413768 2026] [security2:error] [pid 418108:tid 418329] [client 117.213.202.34:53471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XBw0cxofL2J1zwYrHmwAAAWM"]
[Tue Jul 21 08:24:56.413986 2026] [security2:error] [pid 418108:tid 418329] [client 117.213.202.34:53471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XBw0cxofL2J1zwYrHmwAAAWM"]
[Tue Jul 21 08:24:56.424275 2026] [security2:error] [pid 419508:tid 419569] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/wp-css.php"] [unique_id "al9XCFcagwCeNbomjVsWVAABuDw"]
[Tue Jul 21 08:24:56.442711 2026] [security2:error] [pid 419508:tid 419717] [client 20.197.195.24:3523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/classwithtostring.php"] [unique_id "al9XCFcagwCeNbomjVsWVQAAAd4"]
[Tue Jul 21 08:24:56.491427 2026] [security2:error] [pid 419508:tid 419723] [client 20.197.192.193:5615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9XCFcagwCeNbomjVsWWAAAAeQ"]
[Tue Jul 21 08:24:56.496945 2026] [security2:error] [pid 418108:tid 418320] [client 65.21.113.253:50590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XCA0cxofL2J1zwYrHpAAAAVo"]
[Tue Jul 21 08:24:56.598059 2026] [security2:error] [pid 419508:tid 419592] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/wp-explorer.php"] [unique_id "al9XCFcagwCeNbomjVsWWQABoFM"]
[Tue Jul 21 08:24:56.747964 2026] [security2:error] [pid 419508:tid 419551] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/akismet.php"] [unique_id "al9XCFcagwCeNbomjVsWXwABlio"]
[Tue Jul 21 08:24:56.906416 2026] [security2:error] [pid 419508:tid 419561] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/ace2.php"] [unique_id "al9XCFcagwCeNbomjVsWYgAB_zQ"]
[Tue Jul 21 08:24:57.067373 2026] [security2:error] [pid 419508:tid 419609] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.tavarescont.com.br"] [uri "/ms.php"] [unique_id "al9XCVcagwCeNbomjVsWZAAB_mQ"]
[Tue Jul 21 08:24:57.106470 2026] [security2:error] [pid 419508:tid 419540] [remote 173.252.87.4:49050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.gfacil.com.br"] [uri "/index.php"] [unique_id "al9XCVcagwCeNbomjVsWZQAB8R8"]
[Tue Jul 21 08:24:57.240376 2026] [security2:error] [pid 418108:tid 418251] [client 65.21.113.253:50590] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XCA0cxofL2J1zwYrHqAAAARU"]
[Tue Jul 21 08:24:57.543772 2026] [security2:error] [pid 418108:tid 418321] [client 20.197.195.24:18244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9XCQ0cxofL2J1zwYrHrAAAAVs"]
[Tue Jul 21 08:24:57.832407 2026] [security2:error] [pid 418108:tid 418347] [client 14.97.58.74:64747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XCQ0cxofL2J1zwYrHrgAAAXU"]
[Tue Jul 21 08:24:57.832511 2026] [security2:error] [pid 418108:tid 418347] [client 14.97.58.74:64747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XCQ0cxofL2J1zwYrHrgAAAXU"]
[Tue Jul 21 08:24:57.938037 2026] [security2:error] [pid 418108:tid 418313] [client 187.125.243.197:59902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XCQ0cxofL2J1zwYrHsQAAAVM"]
[Tue Jul 21 08:24:57.938146 2026] [security2:error] [pid 418108:tid 418313] [client 187.125.243.197:59902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XCQ0cxofL2J1zwYrHsQAAAVM"]
[Tue Jul 21 08:24:57.952759 2026] [rewrite:warn] [pid 419508:tid 419516] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:24:58.038445 2026] [security2:error] [pid 418108:tid 418263] [client 14.245.224.124:50684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XCg0cxofL2J1zwYrHtAAAASE"]
[Tue Jul 21 08:24:58.038539 2026] [security2:error] [pid 418108:tid 418263] [client 14.245.224.124:50684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XCg0cxofL2J1zwYrHtAAAASE"]
[Tue Jul 21 08:24:58.407357 2026] [security2:error] [pid 419508:tid 419725] [client 109.248.148.246:41516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9XClcagwCeNbomjVsWfAAAAeY"]
[Tue Jul 21 08:24:58.407491 2026] [security2:error] [pid 419508:tid 419725] [client 109.248.148.246:41516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9XClcagwCeNbomjVsWfAAAAeY"]
[Tue Jul 21 08:24:58.599196 2026] [security2:error] [pid 418108:tid 418115] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/js/.env"] [unique_id "al9XCg0cxofL2J1zwYrHuQABKwQ"]
[Tue Jul 21 08:24:58.892001 2026] [security2:error] [pid 418108:tid 418355] [client 20.197.195.24:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wp-blog.php"] [unique_id "al9XCg0cxofL2J1zwYrHvAAAAX0"]
[Tue Jul 21 08:24:59.291075 2026] [security2:error] [pid 418108:tid 418226] [remote 45.150.79.142:42294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9XCw0cxofL2J1zwYrHvwABhnM"]
[Tue Jul 21 08:24:59.587207 2026] [security2:error] [pid 419508:tid 419664] [client 103.151.46.103:56167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XC1cagwCeNbomjVsWkAAAAak"]
[Tue Jul 21 08:24:59.587346 2026] [security2:error] [pid 419508:tid 419664] [client 103.151.46.103:56167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XC1cagwCeNbomjVsWkAAAAak"]
[Tue Jul 21 08:24:59.709015 2026] [security2:error] [pid 419508:tid 419766] [client 20.226.60.151:60577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/zc-131.php"] [unique_id "al9XC1cagwCeNbomjVsWkgAAAg4"]
[Tue Jul 21 08:24:59.853246 2026] [security2:error] [pid 419508:tid 419749] [client 223.181.60.88:21431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XC1cagwCeNbomjVsWlwAAAf0"]
[Tue Jul 21 08:24:59.853563 2026] [security2:error] [pid 419508:tid 419749] [client 223.181.60.88:21431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XC1cagwCeNbomjVsWlwAAAf0"]
[Tue Jul 21 08:24:59.952692 2026] [security2:error] [pid 419508:tid 419707] [client 34.76.2.141:60376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "x45consultoria.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9XC1cagwCeNbomjVsWmAAAAdQ"]
[Tue Jul 21 08:25:00.118862 2026] [security2:error] [pid 418108:tid 418322] [client 20.206.105.145:20205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wefile.php"] [unique_id "al9XDA0cxofL2J1zwYrHxgAAAVw"]
[Tue Jul 21 08:25:00.361777 2026] [security2:error] [pid 418108:tid 418315] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XDA0cxofL2J1zwYrHxwABVTE"]
[Tue Jul 21 08:25:00.582581 2026] [autoindex:error] [pid 419508:tid 419691] [client 20.197.195.24:3526] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:00.593168 2026] [security2:error] [pid 419508:tid 419704] [client 20.197.195.24:3526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9XDFcagwCeNbomjVsWpAAAAdE"]
[Tue Jul 21 08:25:00.611770 2026] [security2:error] [pid 418108:tid 418362] [client 202.179.75.202:39966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XDA0cxofL2J1zwYrHyQAAAYQ"]
[Tue Jul 21 08:25:00.612067 2026] [security2:error] [pid 418108:tid 418362] [client 202.179.75.202:39966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XDA0cxofL2J1zwYrHyQAAAYQ"]
[Tue Jul 21 08:25:00.996425 2026] [security2:error] [pid 418108:tid 418136] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XDA0cxofL2J1zwYrH0wABNhk"]
[Tue Jul 21 08:25:00.996540 2026] [security2:error] [pid 418108:tid 418284] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XDA0cxofL2J1zwYrH0wABNhk"]
[Tue Jul 21 08:25:01.467547 2026] [security2:error] [pid 419508:tid 419662] [client 20.226.60.151:56865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/w3lls.php"] [unique_id "al9XDVcagwCeNbomjVsWsQAAAac"]
[Tue Jul 21 08:25:01.522608 2026] [security2:error] [pid 419508:tid 419651] [client 115.134.11.136:62037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XDVcagwCeNbomjVsWswAAAZw"]
[Tue Jul 21 08:25:01.523420 2026] [security2:error] [pid 419508:tid 419651] [client 115.134.11.136:62037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XDVcagwCeNbomjVsWswAAAZw"]
[Tue Jul 21 08:25:01.564636 2026] [security2:error] [pid 419508:tid 419703] [client 89.238.167.134:57978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9XDVcagwCeNbomjVsWtAAAAdA"]
[Tue Jul 21 08:25:01.564777 2026] [security2:error] [pid 419508:tid 419703] [client 89.238.167.134:57978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9XDVcagwCeNbomjVsWtAAAAdA"]
[Tue Jul 21 08:25:01.642800 2026] [security2:error] [pid 419508:tid 419643] [client 20.197.195.24:3530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/ms-edit.php"] [unique_id "al9XDVcagwCeNbomjVsWuAAAAZQ"]
[Tue Jul 21 08:25:01.958055 2026] [security2:error] [pid 419508:tid 419640] [client 103.151.46.103:56684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XDVcagwCeNbomjVsWvQAAAZE"]
[Tue Jul 21 08:25:01.958546 2026] [security2:error] [pid 419508:tid 419640] [client 103.151.46.103:56684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XDVcagwCeNbomjVsWvQAAAZE"]
[Tue Jul 21 08:25:02.085947 2026] [security2:error] [pid 419508:tid 419742] [client 74.7.244.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jaimilsonvieirasanto1782080431823.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9XDlcagwCeNbomjVsWwQAB9wE"]
[Tue Jul 21 08:25:02.770876 2026] [security2:error] [pid 419508:tid 419650] [client 20.220.225.223:19662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/2352356666.php"] [unique_id "al9XDlcagwCeNbomjVsWzAAAAZs"]
[Tue Jul 21 08:25:03.289560 2026] [security2:error] [pid 418108:tid 418345] [client 190.92.174.183:53394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XDw0cxofL2J1zwYrH6QAAAXM"]
[Tue Jul 21 08:25:03.289784 2026] [security2:error] [pid 418108:tid 418345] [client 190.92.174.183:53394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XDw0cxofL2J1zwYrH6QAAAXM"]
[Tue Jul 21 08:25:03.341607 2026] [security2:error] [pid 419508:tid 419647] [client 20.197.192.193:5598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/dr.php"] [unique_id "al9XD1cagwCeNbomjVsW1QAAAZg"]
[Tue Jul 21 08:25:03.634627 2026] [security2:error] [pid 418108:tid 418272] [client 34.76.2.141:60556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "x45consultoria.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XDg0cxofL2J1zwYrH5QAAASo"]
[Tue Jul 21 08:25:03.793668 2026] [security2:error] [pid 418108:tid 418296] [client 20.197.195.24:18347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9XDw0cxofL2J1zwYrH8AAAAUI"]
[Tue Jul 21 08:25:03.923007 2026] [security2:error] [pid 419508:tid 419728] [client 190.92.174.183:53396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XD1cagwCeNbomjVsW3gAAAek"]
[Tue Jul 21 08:25:03.923114 2026] [security2:error] [pid 419508:tid 419728] [client 190.92.174.183:53396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XD1cagwCeNbomjVsW3gAAAek"]
[Tue Jul 21 08:25:04.436116 2026] [autoindex:error] [pid 419508:tid 419691] [client 20.197.195.24:61158] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:04.445257 2026] [security2:error] [pid 419508:tid 419737] [client 20.197.195.24:61158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9XEFcagwCeNbomjVsW5gAAAfI"]
[Tue Jul 21 08:25:04.692923 2026] [autoindex:error] [pid 418108:tid 418362] [client 20.197.195.24:18332] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:04.710557 2026] [security2:error] [pid 418108:tid 418288] [client 20.226.60.151:63313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/test1.php"] [unique_id "al9XEA0cxofL2J1zwYrH-gAAATo"]
[Tue Jul 21 08:25:04.821845 2026] [autoindex:error] [pid 418108:tid 418312] [client 20.197.195.24:18332] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:04.826916 2026] [security2:error] [pid 418108:tid 418320] [client 20.197.195.24:18332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/abcd.php"] [unique_id "al9XEA0cxofL2J1zwYrH_QAAAVo"]
[Tue Jul 21 08:25:04.875725 2026] [security2:error] [pid 419508:tid 419628] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XEFcagwCeNbomjVsW8wABmnc"]
[Tue Jul 21 08:25:04.875906 2026] [security2:error] [pid 419508:tid 419649] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XEFcagwCeNbomjVsW8wABmnc"]
[Tue Jul 21 08:25:04.956548 2026] [autoindex:error] [pid 419508:tid 419709] [client 190.92.174.183:53400] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/ceramicasantoaugusto.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:04.969965 2026] [security2:error] [pid 419508:tid 419551] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/laravel/.env"] [unique_id "al9XEFcagwCeNbomjVsW9QABkyo"]
[Tue Jul 21 08:25:05.107654 2026] [security2:error] [pid 419508:tid 419766] [client 185.213.175.37:4992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "azusacorretora.com.br"] [uri "/.env"] [unique_id "al9XEVcagwCeNbomjVsW-gAAAg4"]
[Tue Jul 21 08:25:05.591353 2026] [security2:error] [pid 419508:tid 419662] [client 20.197.195.24:18252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/file15.php"] [unique_id "al9XEVcagwCeNbomjVsXAAAAAac"]
[Tue Jul 21 08:25:05.597535 2026] [security2:error] [pid 419508:tid 419728] [client 190.92.174.183:53400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9XEVcagwCeNbomjVsXAQAAAek"]
[Tue Jul 21 08:25:05.597610 2026] [security2:error] [pid 419508:tid 419728] [client 190.92.174.183:53400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9XEVcagwCeNbomjVsXAQAAAek"]
[Tue Jul 21 08:25:05.643183 2026] [security2:error] [pid 419508:tid 419584] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XEVcagwCeNbomjVsXAwABnEs"]
[Tue Jul 21 08:25:05.643351 2026] [security2:error] [pid 419508:tid 419651] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XEVcagwCeNbomjVsXAwABnEs"]
[Tue Jul 21 08:25:05.731384 2026] [security2:error] [pid 419508:tid 419635] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/laravel/core/.env"] [unique_id "al9XEVcagwCeNbomjVsXBAAB3X4"]
[Tue Jul 21 08:25:05.957364 2026] [security2:error] [pid 419508:tid 419646] [client 150.129.202.39:13172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XEVcagwCeNbomjVsXDAAAAZc"]
[Tue Jul 21 08:25:05.957490 2026] [security2:error] [pid 419508:tid 419646] [client 150.129.202.39:13172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XEVcagwCeNbomjVsXDAAAAZc"]
[Tue Jul 21 08:25:06.121622 2026] [security2:error] [pid 418108:tid 418324] [client 20.220.225.223:58925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/wp-signup.php"] [unique_id "al9XEg0cxofL2J1zwYrIDQAAAV4"]
[Tue Jul 21 08:25:06.147841 2026] [security2:error] [pid 418108:tid 418361] [client 117.213.202.34:54033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XEg0cxofL2J1zwYrIDgAAAYM"]
[Tue Jul 21 08:25:06.148032 2026] [security2:error] [pid 418108:tid 418361] [client 117.213.202.34:54033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XEg0cxofL2J1zwYrIDgAAAYM"]
[Tue Jul 21 08:25:06.197456 2026] [access_compat:error] [pid 419508:tid 419660] [client 162.241.63.68:53362] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:25:06.200073 2026] [security2:error] [pid 419508:tid 419671] [client 20.220.225.223:19305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/pn.php"] [unique_id "al9XElcagwCeNbomjVsXEgAAAbA"]
[Tue Jul 21 08:25:06.210034 2026] [security2:error] [pid 419508:tid 419620] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XElcagwCeNbomjVsXEwAB8m8"]
[Tue Jul 21 08:25:06.210135 2026] [security2:error] [pid 419508:tid 419737] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XElcagwCeNbomjVsXEwAB8m8"]
[Tue Jul 21 08:25:06.278864 2026] [security2:error] [pid 419508:tid 419560] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/mail/.env"] [unique_id "al9XElcagwCeNbomjVsXFAACADM"]
[Tue Jul 21 08:25:06.342913 2026] [security2:error] [pid 419508:tid 419650] [client 190.92.174.183:53412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9XElcagwCeNbomjVsXFQAAAZs"]
[Tue Jul 21 08:25:06.343084 2026] [security2:error] [pid 419508:tid 419650] [client 190.92.174.183:53412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9XElcagwCeNbomjVsXFQAAAZs"]
[Tue Jul 21 08:25:06.519143 2026] [security2:error] [pid 419508:tid 419701] [client 20.226.60.151:56928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/database.php"] [unique_id "al9XElcagwCeNbomjVsXFwAAAc4"]
[Tue Jul 21 08:25:06.537598 2026] [autoindex:error] [pid 418108:tid 418339] [client 20.206.105.145:20250] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:06.623523 2026] [security2:error] [pid 419508:tid 419655] [client 20.197.195.24:61126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/jp.php"] [unique_id "al9XElcagwCeNbomjVsXGwAAAaA"]
[Tue Jul 21 08:25:06.644052 2026] [security2:error] [pid 418108:tid 418291] [client 195.49.128.211:62632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XEg0cxofL2J1zwYrIFgAAAT0"]
[Tue Jul 21 08:25:06.644227 2026] [security2:error] [pid 418108:tid 418291] [client 195.49.128.211:62632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XEg0cxofL2J1zwYrIFgAAAT0"]
[Tue Jul 21 08:25:06.825463 2026] [security2:error] [pid 419508:tid 419636] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/mailer/.env"] [unique_id "al9XElcagwCeNbomjVsXHwACCn8"]
[Tue Jul 21 08:25:07.063792 2026] [security2:error] [pid 419508:tid 419708] [client 20.197.195.24:18298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/f35.php"] [unique_id "al9XE1cagwCeNbomjVsXIgAAAdU"]
[Tue Jul 21 08:25:07.071016 2026] [security2:error] [pid 419508:tid 419546] [remote 167.71.132.111:57966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.132.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-login.php"] [unique_id "al9XE1cagwCeNbomjVsXIwABsSU"]
[Tue Jul 21 08:25:07.254266 2026] [security2:error] [pid 419508:tid 419695] [client 89.238.167.134:33720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9XE1cagwCeNbomjVsXKQAAAcg"]
[Tue Jul 21 08:25:07.254374 2026] [security2:error] [pid 419508:tid 419695] [client 89.238.167.134:33720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9XE1cagwCeNbomjVsXKQAAAcg"]
[Tue Jul 21 08:25:07.326194 2026] [security2:error] [pid 419508:tid 419640] [client 20.226.60.151:63342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/file.php"] [unique_id "al9XE1cagwCeNbomjVsXKgAAAZE"]
[Tue Jul 21 08:25:07.427736 2026] [security2:error] [pid 419508:tid 419766] [client 223.181.60.88:1875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XE1cagwCeNbomjVsXLQAAAg4"]
[Tue Jul 21 08:25:07.427930 2026] [security2:error] [pid 419508:tid 419766] [client 223.181.60.88:1875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XE1cagwCeNbomjVsXLQAAAg4"]
[Tue Jul 21 08:25:07.840981 2026] [security2:error] [pid 419508:tid 419642] [client 20.197.195.24:61061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wp-load.php"] [unique_id "al9XE1cagwCeNbomjVsXOAAAAZM"]
[Tue Jul 21 08:25:07.923915 2026] [security2:error] [pid 418108:tid 418327] [client 20.226.60.151:56911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/file.php"] [unique_id "al9XEw0cxofL2J1zwYrIJAAAAWE"]
[Tue Jul 21 08:25:08.084217 2026] [security2:error] [pid 419508:tid 419740] [client 190.92.174.183:53418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9XE1cagwCeNbomjVsXJQAAAfU"]
[Tue Jul 21 08:25:08.084369 2026] [security2:error] [pid 419508:tid 419740] [client 190.92.174.183:53418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9XE1cagwCeNbomjVsXJQAAAfU"]
[Tue Jul 21 08:25:08.242931 2026] [autoindex:error] [pid 418108:tid 418357] [client 20.206.105.145:20250] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:08.248695 2026] [security2:error] [pid 418108:tid 418320] [client 20.206.105.145:20250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9XFA0cxofL2J1zwYrIKwAAAVo"]
[Tue Jul 21 08:25:08.351693 2026] [security2:error] [pid 419508:tid 419660] [client 65.21.113.253:34034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XE1cagwCeNbomjVsXOQAAAaU"]
[Tue Jul 21 08:25:08.385621 2026] [security2:error] [pid 418108:tid 418367] [client 20.226.60.151:56958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/777.php"] [unique_id "al9XFA0cxofL2J1zwYrILgAAAYk"]
[Tue Jul 21 08:25:08.402518 2026] [security2:error] [pid 419508:tid 419647] [client 14.245.224.124:51152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XFFcagwCeNbomjVsXSAAAAZg"]
[Tue Jul 21 08:25:08.402653 2026] [security2:error] [pid 419508:tid 419647] [client 14.245.224.124:51152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XFFcagwCeNbomjVsXSAAAAZg"]
[Tue Jul 21 08:25:08.433886 2026] [security2:error] [pid 418108:tid 418249] [client 187.125.243.197:60413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XFA0cxofL2J1zwYrILwAAARM"]
[Tue Jul 21 08:25:08.434262 2026] [security2:error] [pid 418108:tid 418249] [client 187.125.243.197:60413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XFA0cxofL2J1zwYrILwAAARM"]
[Tue Jul 21 08:25:08.470897 2026] [security2:error] [pid 418108:tid 418338] [client 74.7.175.182:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "darsenavogamarine.com"] [uri "/index.php"] [unique_id "al9XEw0cxofL2J1zwYrIIQAAAWw"]
[Tue Jul 21 08:25:08.471946 2026] [security2:error] [pid 419508:tid 419665] [client 74.7.175.182:60946] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "darsenavogamarine.com"] [uri "/robots.txt"] [unique_id "al9XE1cagwCeNbomjVsXNAABqkg"]
[Tue Jul 21 08:25:08.496760 2026] [security2:error] [pid 419508:tid 419742] [client 20.220.225.223:19286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9XFFcagwCeNbomjVsXSwAAAfc"]
[Tue Jul 21 08:25:08.585685 2026] [security2:error] [pid 419508:tid 419717] [client 103.255.105.130:19938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XFFcagwCeNbomjVsXTAAAAd4"]
[Tue Jul 21 08:25:08.585835 2026] [security2:error] [pid 419508:tid 419717] [client 103.255.105.130:19938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XFFcagwCeNbomjVsXTAAAAd4"]
[Tue Jul 21 08:25:08.762476 2026] [security2:error] [pid 419508:tid 419735] [client 190.92.174.183:53428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9XFFcagwCeNbomjVsXUQAAAfA"]
[Tue Jul 21 08:25:08.762615 2026] [security2:error] [pid 419508:tid 419735] [client 190.92.174.183:53428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9XFFcagwCeNbomjVsXUQAAAfA"]
[Tue Jul 21 08:25:08.890238 2026] [security2:error] [pid 419508:tid 419557] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/nginx/.env"] [unique_id "al9XFFcagwCeNbomjVsXUwACDjA"]
[Tue Jul 21 08:25:08.968238 2026] [security2:error] [pid 418108:tid 418311] [client 128.127.105.184:32946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9XFA0cxofL2J1zwYrINAAAAVE"]
[Tue Jul 21 08:25:08.968368 2026] [security2:error] [pid 418108:tid 418311] [client 128.127.105.184:32946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9XFA0cxofL2J1zwYrINAAAAVE"]
[Tue Jul 21 08:25:08.972331 2026] [security2:error] [pid 418108:tid 418294] [client 20.197.195.24:61107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/xyn.php"] [unique_id "al9XFA0cxofL2J1zwYrINQAAAUA"]
[Tue Jul 21 08:25:08.992874 2026] [security2:error] [pid 418108:tid 418290] [client 20.226.60.151:63323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/ssixta.php"] [unique_id "al9XFA0cxofL2J1zwYrINgAAATw"]
[Tue Jul 21 08:25:09.318255 2026] [security2:error] [pid 418108:tid 418261] [client 20.226.60.151:56837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/1c.php"] [unique_id "al9XFQ0cxofL2J1zwYrIOAAAAR8"]
[Tue Jul 21 08:25:09.333585 2026] [security2:error] [pid 418108:tid 418346] [client 115.134.11.136:62458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XFQ0cxofL2J1zwYrIOQAAAXQ"]
[Tue Jul 21 08:25:09.333873 2026] [security2:error] [pid 418108:tid 418346] [client 115.134.11.136:62458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XFQ0cxofL2J1zwYrIOQAAAXQ"]
[Tue Jul 21 08:25:09.394212 2026] [security2:error] [pid 418108:tid 418332] [client 190.92.174.183:53432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9XFQ0cxofL2J1zwYrIOwAAAWY"]
[Tue Jul 21 08:25:09.394342 2026] [security2:error] [pid 418108:tid 418332] [client 190.92.174.183:53432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9XFQ0cxofL2J1zwYrIOwAAAWY"]
[Tue Jul 21 08:25:09.505889 2026] [security2:error] [pid 418108:tid 418240] [client 20.226.60.151:63296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/test2.php"] [unique_id "al9XFQ0cxofL2J1zwYrIQQAAAQo"]
[Tue Jul 21 08:25:09.858075 2026] [security2:error] [pid 419508:tid 419758] [client 20.226.60.151:63310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/buy.php"] [unique_id "al9XFVcagwCeNbomjVsXXgAAAgY"]
[Tue Jul 21 08:25:09.863041 2026] [security2:error] [pid 419508:tid 419708] [client 20.206.105.145:20206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/2P.php"] [unique_id "al9XFVcagwCeNbomjVsXXwAAAdU"]
[Tue Jul 21 08:25:09.863776 2026] [rewrite:warn] [pid 418108:tid 418232] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:25:10.031249 2026] [security2:error] [pid 419508:tid 419721] [client 190.92.174.183:53444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/wp-site/xmlrpc.php"] [unique_id "al9XFlcagwCeNbomjVsXYgAAAeI"]
[Tue Jul 21 08:25:10.031366 2026] [security2:error] [pid 419508:tid 419721] [client 190.92.174.183:53444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/wp-site/xmlrpc.php"] [unique_id "al9XFlcagwCeNbomjVsXYgAAAeI"]
[Tue Jul 21 08:25:10.515506 2026] [security2:error] [pid 419508:tid 419677] [client 20.226.60.151:56848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/ssend.php"] [unique_id "al9XFlcagwCeNbomjVsXawAAAbY"]
[Tue Jul 21 08:25:10.663795 2026] [security2:error] [pid 418108:tid 418337] [client 190.92.174.183:53456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9XFg0cxofL2J1zwYrISAAAAWs"]
[Tue Jul 21 08:25:10.663987 2026] [security2:error] [pid 418108:tid 418337] [client 190.92.174.183:53456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9XFg0cxofL2J1zwYrISAAAAWs"]
[Tue Jul 21 08:25:10.997103 2026] [security2:error] [pid 419508:tid 419662] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XFlcagwCeNbomjVsXcQABp1I"]
[Tue Jul 21 08:25:11.158725 2026] [autoindex:error] [pid 419508:tid 419642] [client 20.197.195.24:61148] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:11.319757 2026] [security2:error] [pid 419508:tid 419752] [client 202.179.75.202:47710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XF1cagwCeNbomjVsXdgAAAgA"]
[Tue Jul 21 08:25:11.319977 2026] [security2:error] [pid 419508:tid 419752] [client 202.179.75.202:47710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XF1cagwCeNbomjVsXdgAAAgA"]
[Tue Jul 21 08:25:11.379659 2026] [security2:error] [pid 419508:tid 419701] [client 213.152.186.163:37052] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9XF1cagwCeNbomjVsXdAAAAc4"]
[Tue Jul 21 08:25:11.379764 2026] [security2:error] [pid 419508:tid 419701] [client 213.152.186.163:37052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9XF1cagwCeNbomjVsXdAAAAc4"]
[Tue Jul 21 08:25:11.459822 2026] [security2:error] [pid 419508:tid 419709] [client 20.226.60.151:56956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/item.php"] [unique_id "al9XF1cagwCeNbomjVsXewAAAdY"]
[Tue Jul 21 08:25:11.587922 2026] [autoindex:error] [pid 419508:tid 419749] [client 20.197.195.24:61148] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:11.601399 2026] [security2:error] [pid 419508:tid 419650] [client 20.197.195.24:61148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/ccc.php"] [unique_id "al9XF1cagwCeNbomjVsXgwAAAZs"]
[Tue Jul 21 08:25:11.614729 2026] [security2:error] [pid 419508:tid 419725] [client 190.92.174.183:53462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.ceramicasantoaugusto.com.br"] [uri "/wp-login.php"] [unique_id "al9XF1cagwCeNbomjVsXhAAAAeY"]
[Tue Jul 21 08:25:11.728159 2026] [security2:error] [pid 419508:tid 419589] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XF1cagwCeNbomjVsXhwAB8VA"]
[Tue Jul 21 08:25:11.728312 2026] [security2:error] [pid 419508:tid 419736] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XF1cagwCeNbomjVsXhwAB8VA"]
[Tue Jul 21 08:25:12.261694 2026] [security2:error] [pid 419508:tid 419704] [client 20.197.195.24:61068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/w.php"] [unique_id "al9XGFcagwCeNbomjVsXmQAAAdE"]
[Tue Jul 21 08:25:12.398555 2026] [security2:error] [pid 419508:tid 419662] [client 20.226.60.151:62368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/ss.php"] [unique_id "al9XGFcagwCeNbomjVsXnAAAAac"]
[Tue Jul 21 08:25:12.457057 2026] [security2:error] [pid 419508:tid 419679] [client 103.151.46.103:57187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XGFcagwCeNbomjVsXngAAAbg"]
[Tue Jul 21 08:25:12.457714 2026] [security2:error] [pid 419508:tid 419679] [client 103.151.46.103:57187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XGFcagwCeNbomjVsXngAAAbg"]
[Tue Jul 21 08:25:12.676928 2026] [security2:error] [pid 419508:tid 419731] [client 20.226.60.151:56895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/hypo.php"] [unique_id "al9XGFcagwCeNbomjVsXpQAAAew"]
[Tue Jul 21 08:25:12.845357 2026] [security2:error] [pid 419508:tid 419707] [client 20.197.195.24:18260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9XGFcagwCeNbomjVsXqwAAAdQ"]
[Tue Jul 21 08:25:13.056312 2026] [security2:error] [pid 418108:tid 418249] [client 20.226.60.151:62347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/users.php"] [unique_id "al9XGQ0cxofL2J1zwYrIXAAAARM"]
[Tue Jul 21 08:25:13.145059 2026] [security2:error] [pid 419508:tid 419650] [client 65.21.113.253:34034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XGFcagwCeNbomjVsXqAAAAZs"]
[Tue Jul 21 08:25:13.199109 2026] [security2:error] [pid 418108:tid 418321] [client 20.226.60.151:62343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/177.php"] [unique_id "al9XGQ0cxofL2J1zwYrIXwAAAVs"]
[Tue Jul 21 08:25:13.267748 2026] [security2:error] [pid 419508:tid 419700] [client 20.226.60.151:56864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/config.php"] [unique_id "al9XGVcagwCeNbomjVsXsQAAAc0"]
[Tue Jul 21 08:25:13.287179 2026] [security2:error] [pid 419508:tid 419665] [client 20.226.60.151:63330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/gettest.php"] [unique_id "al9XGVcagwCeNbomjVsXsgAAAao"]
[Tue Jul 21 08:25:13.552828 2026] [security2:error] [pid 419508:tid 419671] [client 20.226.60.151:56842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/min.php"] [unique_id "al9XGVcagwCeNbomjVsXuQAAAbA"]
[Tue Jul 21 08:25:13.939894 2026] [security2:error] [pid 418108:tid 418313] [client 20.226.60.151:63309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/dvjul.php"] [unique_id "al9XGQ0cxofL2J1zwYrIZAAAAVM"]
[Tue Jul 21 08:25:14.220110 2026] [security2:error] [pid 419508:tid 419614] [remote 194.164.192.228:40852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/wp-login.php"] [unique_id "al9XGlcagwCeNbomjVsXxQABqWk"]
[Tue Jul 21 08:25:14.262500 2026] [security2:error] [pid 418108:tid 418349] [client 20.197.195.24:3540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/FWAZ.php"] [unique_id "al9XGg0cxofL2J1zwYrIawAAAXc"]
[Tue Jul 21 08:25:14.512376 2026] [security2:error] [pid 419508:tid 419712] [client 20.206.105.145:20283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/.well-known/about.php"] [unique_id "al9XGlcagwCeNbomjVsXxgAAAdk"]
[Tue Jul 21 08:25:14.598156 2026] [security2:error] [pid 419508:tid 419705] [client 109.248.148.246:33650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9XGlcagwCeNbomjVsXywAAAdI"]
[Tue Jul 21 08:25:14.598245 2026] [security2:error] [pid 419508:tid 419705] [client 109.248.148.246:33650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9XGlcagwCeNbomjVsXywAAAdI"]
[Tue Jul 21 08:25:14.667005 2026] [security2:error] [pid 418108:tid 418189] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/public/.env"] [unique_id "al9XGg0cxofL2J1zwYrIbQABZU4"]
[Tue Jul 21 08:25:14.781607 2026] [security2:error] [pid 419508:tid 419736] [client 20.226.60.151:56943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/biufile.php"] [unique_id "al9XGlcagwCeNbomjVsXzQAAAfE"]
[Tue Jul 21 08:25:14.811864 2026] [security2:error] [pid 419508:tid 419702] [client 45.15.246.123:24912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "3d-surgery.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XGVcagwCeNbomjVsXswAAAc8"]
[Tue Jul 21 08:25:15.247720 2026] [security2:error] [pid 418108:tid 418290] [client 110.235.216.172:49620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.216.235.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jornalbrasileiro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XGg0cxofL2J1zwYrIagAAATw"]
[Tue Jul 21 08:25:15.247824 2026] [security2:error] [pid 418108:tid 418290] [client 110.235.216.172:49620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jornalbrasileiro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XGg0cxofL2J1zwYrIagAAATw"]
[Tue Jul 21 08:25:15.343648 2026] [security2:error] [pid 419508:tid 419640] [client 65.21.113.253:34034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XG1cagwCeNbomjVsX1AAAAZE"]
[Tue Jul 21 08:25:15.410992 2026] [security2:error] [pid 419508:tid 419585] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XG1cagwCeNbomjVsX2AABy0w"]
[Tue Jul 21 08:25:15.411185 2026] [security2:error] [pid 419508:tid 419698] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XG1cagwCeNbomjVsX2AABy0w"]
[Tue Jul 21 08:25:15.499226 2026] [security2:error] [pid 418108:tid 418180] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/site/.env"] [unique_id "al9XGw0cxofL2J1zwYrIdwABGkU"]
[Tue Jul 21 08:25:15.592768 2026] [security2:error] [pid 418108:tid 418366] [client 20.197.195.24:18354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/miru1.php"] [unique_id "al9XGw0cxofL2J1zwYrIfAAAAYg"]
[Tue Jul 21 08:25:15.702827 2026] [security2:error] [pid 418108:tid 418345] [client 45.15.246.123:24944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "3d-surgery.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XGw0cxofL2J1zwYrIegAAAXM"]
[Tue Jul 21 08:25:15.761295 2026] [security2:error] [pid 419508:tid 419704] [client 109.248.148.246:57310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9XG1cagwCeNbomjVsX4QAAAdE"]
[Tue Jul 21 08:25:15.761417 2026] [security2:error] [pid 419508:tid 419704] [client 109.248.148.246:57310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9XG1cagwCeNbomjVsX4QAAAdE"]
[Tue Jul 21 08:25:15.796022 2026] [security2:error] [pid 419508:tid 419716] [client 176.29.225.240:39195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.225.29.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XGVcagwCeNbomjVsXvQAAAd0"]
[Tue Jul 21 08:25:15.796210 2026] [security2:error] [pid 419508:tid 419716] [client 176.29.225.240:39195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jaypi.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XGVcagwCeNbomjVsXvQAAAd0"]
[Tue Jul 21 08:25:16.065168 2026] [security2:error] [pid 418108:tid 418152] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/xampp/.env"] [unique_id "al9XHA0cxofL2J1zwYrIgQABOik"]
[Tue Jul 21 08:25:16.079752 2026] [security2:error] [pid 419508:tid 419761] [client 89.238.167.134:47616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9XHFcagwCeNbomjVsX5gAAAgk"]
[Tue Jul 21 08:25:16.079844 2026] [security2:error] [pid 419508:tid 419761] [client 89.238.167.134:47616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9XHFcagwCeNbomjVsX5gAAAgk"]
[Tue Jul 21 08:25:16.187436 2026] [security2:error] [pid 419508:tid 419740] [client 20.206.105.145:20148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9XHFcagwCeNbomjVsX6AAAAfU"]
[Tue Jul 21 08:25:16.283827 2026] [security2:error] [pid 418108:tid 418169] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XHA0cxofL2J1zwYrIhwABHTo"]
[Tue Jul 21 08:25:16.284070 2026] [security2:error] [pid 418108:tid 418259] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XHA0cxofL2J1zwYrIhwABHTo"]
[Tue Jul 21 08:25:16.518580 2026] [security2:error] [pid 419508:tid 419643] [client 20.226.60.151:56868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/av.php"] [unique_id "al9XHFcagwCeNbomjVsX7AAAAZQ"]
[Tue Jul 21 08:25:16.637548 2026] [security2:error] [pid 419508:tid 419691] [client 150.129.202.39:64874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XHFcagwCeNbomjVsX8QAAAcQ"]
[Tue Jul 21 08:25:16.637677 2026] [security2:error] [pid 419508:tid 419691] [client 150.129.202.39:64874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XHFcagwCeNbomjVsX8QAAAcQ"]
[Tue Jul 21 08:25:16.750111 2026] [security2:error] [pid 418108:tid 418329] [client 117.213.202.34:54578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XHA0cxofL2J1zwYrIigAAAWM"]
[Tue Jul 21 08:25:16.750289 2026] [security2:error] [pid 418108:tid 418329] [client 117.213.202.34:54578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XHA0cxofL2J1zwYrIigAAAWM"]
[Tue Jul 21 08:25:16.762797 2026] [security2:error] [pid 419508:tid 419634] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XHFcagwCeNbomjVsX9wACBn0"]
[Tue Jul 21 08:25:16.762928 2026] [security2:error] [pid 419508:tid 419758] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XHFcagwCeNbomjVsX9wACBn0"]
[Tue Jul 21 08:25:16.788027 2026] [security2:error] [pid 419508:tid 419742] [client 20.220.225.223:58908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/csa.php"] [unique_id "al9XHFcagwCeNbomjVsX-AAAAfc"]
[Tue Jul 21 08:25:16.909679 2026] [security2:error] [pid 419508:tid 419665] [client 20.197.195.24:61167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/aa.php"] [unique_id "al9XHFcagwCeNbomjVsX-QAAAao"]
[Tue Jul 21 08:25:16.967648 2026] [security2:error] [pid 418108:tid 418348] [client 89.238.167.134:45196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9XHA0cxofL2J1zwYrIjgAAAXY"]
[Tue Jul 21 08:25:16.967747 2026] [security2:error] [pid 418108:tid 418348] [client 89.238.167.134:45196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9XHA0cxofL2J1zwYrIjgAAAXY"]
[Tue Jul 21 08:25:17.217471 2026] [security2:error] [pid 419508:tid 419662] [client 109.248.148.246:57318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9XHVcagwCeNbomjVsX_wAAAac"]
[Tue Jul 21 08:25:17.217555 2026] [security2:error] [pid 419508:tid 419662] [client 109.248.148.246:57318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9XHVcagwCeNbomjVsX_wAAAac"]
[Tue Jul 21 08:25:17.293123 2026] [security2:error] [pid 418108:tid 418321] [client 195.49.128.211:63456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XHQ0cxofL2J1zwYrIkQAAAVs"]
[Tue Jul 21 08:25:17.293375 2026] [security2:error] [pid 418108:tid 418321] [client 195.49.128.211:63456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XHQ0cxofL2J1zwYrIkQAAAVs"]
[Tue Jul 21 08:25:17.375949 2026] [security2:error] [pid 419508:tid 419642] [client 20.226.60.151:56888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/coffexium.php"] [unique_id "al9XHVcagwCeNbomjVsYAwAAAZM"]
[Tue Jul 21 08:25:17.443439 2026] [security2:error] [pid 418108:tid 418287] [client 151.63.71.144:60132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XHQ0cxofL2J1zwYrIkwAAATk"]
[Tue Jul 21 08:25:17.443608 2026] [security2:error] [pid 418108:tid 418287] [client 151.63.71.144:60132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XHQ0cxofL2J1zwYrIkwAAATk"]
[Tue Jul 21 08:25:17.646970 2026] [security2:error] [pid 419508:tid 419735] [client 20.197.195.24:61088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/122.php"] [unique_id "al9XHVcagwCeNbomjVsYMAAAAfA"]
[Tue Jul 21 08:25:17.736111 2026] [security2:error] [pid 419508:tid 419716] [client 65.21.113.253:34034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XHVcagwCeNbomjVsYAQAAAd0"]
[Tue Jul 21 08:25:18.019012 2026] [security2:error] [pid 419508:tid 419587] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/main/.env"] [unique_id "al9XHlcagwCeNbomjVsYSAAB5U4"]
[Tue Jul 21 08:25:18.070643 2026] [security2:error] [pid 419508:tid 419695] [client 20.197.195.24:61136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/get.php"] [unique_id "al9XHlcagwCeNbomjVsYSQAAAcg"]
[Tue Jul 21 08:25:18.134756 2026] [security2:error] [pid 419508:tid 419703] [client 223.181.60.88:8199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XHlcagwCeNbomjVsYSwAAAdA"]
[Tue Jul 21 08:25:18.135047 2026] [security2:error] [pid 419508:tid 419703] [client 223.181.60.88:8199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XHlcagwCeNbomjVsYSwAAAdA"]
[Tue Jul 21 08:25:18.488526 2026] [security2:error] [pid 419508:tid 419677] [client 20.197.195.24:3542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/as.php"] [unique_id "al9XHlcagwCeNbomjVsYVQAAAbY"]
[Tue Jul 21 08:25:18.628532 2026] [security2:error] [pid 419508:tid 419585] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/node_modules/.env"] [unique_id "al9XHlcagwCeNbomjVsYWAABj0w"]
[Tue Jul 21 08:25:18.788315 2026] [security2:error] [pid 419508:tid 419655] [client 20.220.225.223:19315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/dr.php"] [unique_id "al9XHlcagwCeNbomjVsYXAAAAaA"]
[Tue Jul 21 08:25:18.882690 2026] [security2:error] [pid 419508:tid 419680] [client 115.134.11.136:62941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XHlcagwCeNbomjVsYYAAAAbk"]
[Tue Jul 21 08:25:18.883397 2026] [security2:error] [pid 419508:tid 419680] [client 115.134.11.136:62941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XHlcagwCeNbomjVsYYAAAAbk"]
[Tue Jul 21 08:25:18.888120 2026] [security2:error] [pid 419508:tid 419766] [client 20.197.195.24:18253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/ccou.php"] [unique_id "al9XHlcagwCeNbomjVsYYQAAAg4"]
[Tue Jul 21 08:25:18.901617 2026] [security2:error] [pid 419508:tid 419679] [client 187.125.243.197:60910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XHlcagwCeNbomjVsYYgAAAbg"]
[Tue Jul 21 08:25:18.901750 2026] [security2:error] [pid 419508:tid 419679] [client 187.125.243.197:60910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XHlcagwCeNbomjVsYYgAAAbg"]
[Tue Jul 21 08:25:19.095150 2026] [security2:error] [pid 418108:tid 418282] [client 103.255.105.130:32319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XHw0cxofL2J1zwYrIpAAAATQ"]
[Tue Jul 21 08:25:19.095246 2026] [security2:error] [pid 418108:tid 418282] [client 103.255.105.130:32319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XHw0cxofL2J1zwYrIpAAAATQ"]
[Tue Jul 21 08:25:19.377293 2026] [security2:error] [pid 419508:tid 419723] [client 20.197.195.24:3580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/w3lls.php"] [unique_id "al9XH1cagwCeNbomjVsYcAAAAeQ"]
[Tue Jul 21 08:25:19.424222 2026] [security2:error] [pid 419508:tid 419639] [client 14.245.224.124:51657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XH1cagwCeNbomjVsYdAAAAZA"]
[Tue Jul 21 08:25:19.424371 2026] [security2:error] [pid 419508:tid 419639] [client 14.245.224.124:51657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XH1cagwCeNbomjVsYdAAAAZA"]
[Tue Jul 21 08:25:19.448658 2026] [security2:error] [pid 419508:tid 419515] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/kyc/.env"] [unique_id "al9XH1cagwCeNbomjVsYdQABowY"]
[Tue Jul 21 08:25:20.166660 2026] [security2:error] [pid 419508:tid 419699] [client 20.197.195.24:12870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/test1.php"] [unique_id "al9XIFcagwCeNbomjVsYgAAAAcw"]
[Tue Jul 21 08:25:20.198458 2026] [security2:error] [pid 419508:tid 419707] [client 65.21.113.253:34034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XH1cagwCeNbomjVsYfAAAAdQ"]
[Tue Jul 21 08:25:20.223189 2026] [security2:error] [pid 419508:tid 419595] [remote 142.44.225.229:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "marketingderua.com.br"] [uri "/tipos-de-midia-ooh-painel-led-indoor-e-mobiliario-urbano/"] [unique_id "al9XIFcagwCeNbomjVsYgQAB61Y"]
[Tue Jul 21 08:25:20.223404 2026] [security2:error] [pid 419508:tid 419730] [client 142.44.225.229:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "marketingderua.com.br"] [uri "/tipos-de-midia-ooh-painel-led-indoor-e-mobiliario-urbano/"] [unique_id "al9XIFcagwCeNbomjVsYgQAB61Y"]
[Tue Jul 21 08:25:20.316529 2026] [security2:error] [pid 418108:tid 418266] [client 36.95.145.2:56866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.145.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carrosselbuique.com.br"] [uri "/wp-login.php"] [unique_id "al9XIA0cxofL2J1zwYrIrQAAASQ"]
[Tue Jul 21 08:25:20.618962 2026] [security2:error] [pid 419508:tid 419701] [client 20.197.195.24:61104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/database.php"] [unique_id "al9XIFcagwCeNbomjVsYiwAAAc4"]
[Tue Jul 21 08:25:20.621993 2026] [security2:error] [pid 419508:tid 419679] [client 20.226.60.151:63358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/core.php"] [unique_id "al9XIFcagwCeNbomjVsYjAAAAbg"]
[Tue Jul 21 08:25:20.793218 2026] [security2:error] [pid 419508:tid 419534] [remote 8.217.108.67:3284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/wp-login.php"] [unique_id "al9XIFcagwCeNbomjVsYkAABmBk"]
[Tue Jul 21 08:25:20.838256 2026] [security2:error] [pid 418108:tid 418337] [client 152.59.34.51:53698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XIA0cxofL2J1zwYrIuAAAAWs"]
[Tue Jul 21 08:25:20.838353 2026] [security2:error] [pid 418108:tid 418337] [client 152.59.34.51:53698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XIA0cxofL2J1zwYrIuAAAAWs"]
[Tue Jul 21 08:25:20.907344 2026] [security2:error] [pid 419508:tid 419716] [client 20.220.225.223:19319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/2x.php"] [unique_id "al9XIFcagwCeNbomjVsYlgAAAd0"]
[Tue Jul 21 08:25:20.945440 2026] [security2:error] [pid 418108:tid 418359] [client 20.206.105.145:20201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/bob.php"] [unique_id "al9XIA0cxofL2J1zwYrIuQAAAYE"]
[Tue Jul 21 08:25:21.206669 2026] [security2:error] [pid 419508:tid 419724] [client 20.197.195.24:3541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/file.php"] [unique_id "al9XIVcagwCeNbomjVsYmgAAAeU"]
[Tue Jul 21 08:25:21.402332 2026] [security2:error] [pid 419508:tid 419712] [client 185.198.240.93:56447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-login.php"] [unique_id "al9XIVcagwCeNbomjVsYngAAAdk"]
[Tue Jul 21 08:25:21.411751 2026] [security2:error] [pid 419508:tid 419629] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/prod/.env"] [unique_id "al9XIVcagwCeNbomjVsYnwAB23g"]
[Tue Jul 21 08:25:21.451619 2026] [security2:error] [pid 418108:tid 418342] [client 61.1.167.83:57104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XIQ0cxofL2J1zwYrIvQAAAXA"]
[Tue Jul 21 08:25:21.451765 2026] [security2:error] [pid 418108:tid 418342] [client 61.1.167.83:57104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XIQ0cxofL2J1zwYrIvQAAAXA"]
[Tue Jul 21 08:25:21.611474 2026] [security2:error] [pid 418108:tid 418365] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XIQ0cxofL2J1zwYrIvgABh0k"]
[Tue Jul 21 08:25:21.682130 2026] [security2:error] [pid 418108:tid 418191] [remote 47.128.115.116:16822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mdbroraima.org.br"] [uri "/mais-medicos/"] [unique_id "al9XIQ0cxofL2J1zwYrIwAABFFA"]
[Tue Jul 21 08:25:22.099166 2026] [security2:error] [pid 419508:tid 419547] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/.env.bak"] [unique_id "al9XIlcagwCeNbomjVsYrAABpSY"]
[Tue Jul 21 08:25:22.117514 2026] [security2:error] [pid 419508:tid 419674] [client 20.226.60.151:63303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/als.php"] [unique_id "al9XIlcagwCeNbomjVsYrQAAAbM"]
[Tue Jul 21 08:25:22.237762 2026] [security2:error] [pid 419508:tid 419677] [client 202.179.75.202:50160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XIlcagwCeNbomjVsYswAAAbY"]
[Tue Jul 21 08:25:22.237856 2026] [security2:error] [pid 419508:tid 419677] [client 202.179.75.202:50160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XIlcagwCeNbomjVsYswAAAbY"]
[Tue Jul 21 08:25:22.264258 2026] [security2:error] [pid 418108:tid 418331] [client 20.197.195.24:12868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/file.php"] [unique_id "al9XIg0cxofL2J1zwYrIywAAAWU"]
[Tue Jul 21 08:25:22.364690 2026] [security2:error] [pid 419508:tid 419537] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XIlcagwCeNbomjVsYtAABkxw"]
[Tue Jul 21 08:25:22.364852 2026] [security2:error] [pid 419508:tid 419642] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XIlcagwCeNbomjVsYtAABkxw"]
[Tue Jul 21 08:25:23.131837 2026] [security2:error] [pid 418108:tid 418345] [client 20.197.195.24:18342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/777.php"] [unique_id "al9XIw0cxofL2J1zwYrI9AAAAXM"]
[Tue Jul 21 08:25:23.207055 2026] [security2:error] [pid 419508:tid 419628] [remote 104.210.56.225:60033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.56.210.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9XI1cagwCeNbomjVsYyAAB2Xc"]
[Tue Jul 21 08:25:23.611298 2026] [security2:error] [pid 419508:tid 419660] [client 20.197.195.24:3547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/ssixta.php"] [unique_id "al9XI1cagwCeNbomjVsYzwAAAaU"]
[Tue Jul 21 08:25:24.064486 2026] [security2:error] [pid 419508:tid 419754] [client 103.151.46.103:57675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XJFcagwCeNbomjVsY2QAAAgI"]
[Tue Jul 21 08:25:24.065155 2026] [security2:error] [pid 419508:tid 419754] [client 103.151.46.103:57675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XJFcagwCeNbomjVsY2QAAAgI"]
[Tue Jul 21 08:25:24.102460 2026] [security2:error] [pid 418108:tid 418170] [remote 69.171.234.28:41820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9XIg0cxofL2J1zwYrI8AABSTs"]
[Tue Jul 21 08:25:24.134641 2026] [security2:error] [pid 418108:tid 418254] [client 20.197.195.24:3475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/1c.php"] [unique_id "al9XJA0cxofL2J1zwYrI-wAAARg"]
[Tue Jul 21 08:25:24.219668 2026] [security2:error] [pid 419508:tid 419766] [client 20.226.60.151:56852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/simple.php"] [unique_id "al9XJFcagwCeNbomjVsY2wAAAg4"]
[Tue Jul 21 08:25:24.692546 2026] [security2:error] [pid 418108:tid 418292] [client 20.197.195.24:12892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/test2.php"] [unique_id "al9XJA0cxofL2J1zwYrJAwAAAT4"]
[Tue Jul 21 08:25:25.056034 2026] [security2:error] [pid 419508:tid 419675] [client 20.197.195.24:3534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/buy.php"] [unique_id "al9XJVcagwCeNbomjVsY8AAAAbQ"]
[Tue Jul 21 08:25:25.183415 2026] [security2:error] [pid 418108:tid 418360] [client 20.220.225.223:55749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/min.php"] [unique_id "al9XJQ0cxofL2J1zwYrJBwAAAYI"]
[Tue Jul 21 08:25:25.554523 2026] [security2:error] [pid 419508:tid 419737] [client 20.226.60.151:62361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/init.php"] [unique_id "al9XJVcagwCeNbomjVsY-AAAAfI"]
[Tue Jul 21 08:25:25.605172 2026] [security2:error] [pid 419508:tid 419674] [client 65.21.113.253:34034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XJVcagwCeNbomjVsY8wAAAbM"]
[Tue Jul 21 08:25:26.004570 2026] [security2:error] [pid 419508:tid 419709] [client 20.197.192.193:5969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/kq1.php"] [unique_id "al9XJlcagwCeNbomjVsZAgAAAdY"]
[Tue Jul 21 08:25:26.034460 2026] [security2:error] [pid 418108:tid 418232] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XJg0cxofL2J1zwYrJHQABdXk"]
[Tue Jul 21 08:25:26.034628 2026] [security2:error] [pid 418108:tid 418347] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XJg0cxofL2J1zwYrJHQABdXk"]
[Tue Jul 21 08:25:26.240086 2026] [autoindex:error] [pid 419508:tid 419749] [client 20.206.105.145:20112] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:26.366796 2026] [autoindex:error] [pid 419508:tid 419658] [client 20.206.105.145:20112] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:26.373940 2026] [security2:error] [pid 419508:tid 419643] [client 20.206.105.145:20112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/crgio.php"] [unique_id "al9XJlcagwCeNbomjVsZCgAAAZQ"]
[Tue Jul 21 08:25:26.402253 2026] [security2:error] [pid 419508:tid 419665] [client 185.8.106.219:31348] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "deals-ecomm.shop"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9XJlcagwCeNbomjVsZCwAAAao"]
[Tue Jul 21 08:25:26.446431 2026] [security2:error] [pid 419508:tid 419680] [client 20.197.195.24:18333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/ssend.php"] [unique_id "al9XJlcagwCeNbomjVsZDQAAAbk"]
[Tue Jul 21 08:25:26.585638 2026] [security2:error] [pid 419508:tid 419687] [client 89.238.167.134:45544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9XJlcagwCeNbomjVsZEAAAAcA"]
[Tue Jul 21 08:25:26.585732 2026] [security2:error] [pid 419508:tid 419687] [client 89.238.167.134:45544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9XJlcagwCeNbomjVsZEAAAAcA"]
[Tue Jul 21 08:25:26.708772 2026] [security2:error] [pid 418108:tid 418247] [client 89.238.167.134:45560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9XJg0cxofL2J1zwYrJNAAAARE"]
[Tue Jul 21 08:25:26.708880 2026] [security2:error] [pid 418108:tid 418247] [client 89.238.167.134:45560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9XJg0cxofL2J1zwYrJNAAAARE"]
[Tue Jul 21 08:25:26.889585 2026] [security2:error] [pid 418108:tid 418152] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XJg0cxofL2J1zwYrJOQABHSk"]
[Tue Jul 21 08:25:26.889754 2026] [security2:error] [pid 418108:tid 418259] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XJg0cxofL2J1zwYrJOQABHSk"]
[Tue Jul 21 08:25:27.169579 2026] [security2:error] [pid 419508:tid 419674] [client 20.197.195.24:13830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/item.php"] [unique_id "al9XJ1cagwCeNbomjVsZIgAAAbM"]
[Tue Jul 21 08:25:27.204902 2026] [security2:error] [pid 419508:tid 419728] [client 185.8.106.219:5942] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "deals-ecomm.shop"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9XJ1cagwCeNbomjVsZIwAAAek"]
[Tue Jul 21 08:25:27.295711 2026] [security2:error] [pid 419508:tid 419746] [client 150.129.202.39:64760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XJ1cagwCeNbomjVsZJAAAAfo"]
[Tue Jul 21 08:25:27.296080 2026] [security2:error] [pid 419508:tid 419746] [client 150.129.202.39:64760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XJ1cagwCeNbomjVsZJAAAAfo"]
[Tue Jul 21 08:25:27.308535 2026] [security2:error] [pid 419508:tid 419600] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XJ1cagwCeNbomjVsZJQAB9Vs"]
[Tue Jul 21 08:25:27.308827 2026] [security2:error] [pid 419508:tid 419740] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XJ1cagwCeNbomjVsZJQAB9Vs"]
[Tue Jul 21 08:25:27.433040 2026] [security2:error] [pid 419508:tid 419675] [client 117.213.202.34:55122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XJ1cagwCeNbomjVsZJgAAAbQ"]
[Tue Jul 21 08:25:27.433262 2026] [security2:error] [pid 419508:tid 419675] [client 117.213.202.34:55122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XJ1cagwCeNbomjVsZJgAAAbQ"]
[Tue Jul 21 08:25:27.460239 2026] [security2:error] [pid 419508:tid 419766] [client 20.197.192.193:5586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/zzz.php"] [unique_id "al9XJ1cagwCeNbomjVsZJwAAAg4"]
[Tue Jul 21 08:25:27.640095 2026] [security2:error] [pid 419508:tid 419644] [client 20.226.60.151:63352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/fpwch.php"] [unique_id "al9XJ1cagwCeNbomjVsZKwAAAZU"]
[Tue Jul 21 08:25:27.715390 2026] [security2:error] [pid 419508:tid 419754] [client 65.21.113.253:34034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XJ1cagwCeNbomjVsZKAAAAgI"]
[Tue Jul 21 08:25:27.787735 2026] [security2:error] [pid 419508:tid 419684] [client 20.197.195.24:61114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/ss.php"] [unique_id "al9XJ1cagwCeNbomjVsZLgAAAb0"]
[Tue Jul 21 08:25:28.005405 2026] [security2:error] [pid 419508:tid 419724] [client 195.49.128.211:64185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XKFcagwCeNbomjVsZNAAAAeU"]
[Tue Jul 21 08:25:28.005558 2026] [security2:error] [pid 419508:tid 419724] [client 195.49.128.211:64185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XKFcagwCeNbomjVsZNAAAAeU"]
[Tue Jul 21 08:25:28.045103 2026] [security2:error] [pid 418108:tid 418276] [client 20.197.195.24:18300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/hypo.php"] [unique_id "al9XKA0cxofL2J1zwYrJSgAAAS4"]
[Tue Jul 21 08:25:28.505209 2026] [security2:error] [pid 419508:tid 419621] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "login.gradiente.com"] [uri "/.git/config"] [unique_id "al9XKFcagwCeNbomjVsZQgABl3A"]
[Tue Jul 21 08:25:28.530767 2026] [security2:error] [pid 419508:tid 419626] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/.aws/credentials"] [unique_id "al9XKFcagwCeNbomjVsZRwABl3U"]
[Tue Jul 21 08:25:28.596482 2026] [security2:error] [pid 418108:tid 418355] [client 20.197.195.24:18295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/users.php"] [unique_id "al9XKA0cxofL2J1zwYrJVgAAAX0"]
[Tue Jul 21 08:25:28.689277 2026] [security2:error] [pid 418108:tid 418347] [client 20.206.105.145:20163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/pucci.php"] [unique_id "al9XKA0cxofL2J1zwYrJWgAAAXU"]
[Tue Jul 21 08:25:28.709279 2026] [security2:error] [pid 419508:tid 419711] [client 185.8.106.219:31364] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.deals-ecomm.shop"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9XKFcagwCeNbomjVsZUAAAAdg"]
[Tue Jul 21 08:25:28.757914 2026] [security2:error] [pid 419508:tid 419700] [client 20.220.225.223:52665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/echkm.php"] [unique_id "al9XKFcagwCeNbomjVsZUQAAAc0"]
[Tue Jul 21 08:25:28.793008 2026] [security2:error] [pid 418108:tid 418331] [client 223.181.60.88:5703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XKA0cxofL2J1zwYrJWwAAAWU"]
[Tue Jul 21 08:25:28.793247 2026] [security2:error] [pid 418108:tid 418331] [client 223.181.60.88:5703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XKA0cxofL2J1zwYrJWwAAAWU"]
[Tue Jul 21 08:25:28.870553 2026] [security2:error] [pid 419508:tid 419564] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "login.gradiente.com"] [uri "/.git-credentials"] [unique_id "al9XKFcagwCeNbomjVsZVAABlzc"]
[Tue Jul 21 08:25:28.894688 2026] [security2:error] [pid 419508:tid 419676] [client 20.226.60.151:63318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/domvf.php"] [unique_id "al9XKFcagwCeNbomjVsZVgAAAbU"]
[Tue Jul 21 08:25:29.093422 2026] [security2:error] [pid 419508:tid 419728] [client 14.245.224.124:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XKVcagwCeNbomjVsZWQAAAek"]
[Tue Jul 21 08:25:29.094139 2026] [security2:error] [pid 419508:tid 419728] [client 14.245.224.124:52122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XKVcagwCeNbomjVsZWQAAAek"]
[Tue Jul 21 08:25:29.286892 2026] [security2:error] [pid 419508:tid 419613] [remote 100.42.189.89:59024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrsolar.org.br"] [uri "/wp-login.php"] [unique_id "al9XKVcagwCeNbomjVsZYgACCmg"]
[Tue Jul 21 08:25:29.348216 2026] [security2:error] [pid 419508:tid 419754] [client 185.8.106.219:31366] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "deals-ecomm.shop"] [uri "/"] [unique_id "al9XKVcagwCeNbomjVsZYwAAAgI"]
[Tue Jul 21 08:25:29.420269 2026] [security2:error] [pid 419508:tid 419684] [client 187.125.243.197:61412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XKVcagwCeNbomjVsZZAAAAb0"]
[Tue Jul 21 08:25:29.420664 2026] [security2:error] [pid 419508:tid 419684] [client 187.125.243.197:61412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XKVcagwCeNbomjVsZZAAAAb0"]
[Tue Jul 21 08:25:29.459951 2026] [security2:error] [pid 419508:tid 419674] [client 115.134.11.136:63401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XKVcagwCeNbomjVsZaAAAAbM"]
[Tue Jul 21 08:25:29.460753 2026] [security2:error] [pid 419508:tid 419674] [client 115.134.11.136:63401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XKVcagwCeNbomjVsZaAAAAbM"]
[Tue Jul 21 08:25:29.619937 2026] [security2:error] [pid 418108:tid 418322] [client 20.197.195.24:61064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/177.php"] [unique_id "al9XKQ0cxofL2J1zwYrJYgAAAVw"]
[Tue Jul 21 08:25:29.674377 2026] [security2:error] [pid 419508:tid 419716] [client 111.93.58.162:47667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XKVcagwCeNbomjVsZbgAAAd0"]
[Tue Jul 21 08:25:29.674525 2026] [security2:error] [pid 419508:tid 419716] [client 111.93.58.162:47667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XKVcagwCeNbomjVsZbgAAAd0"]
[Tue Jul 21 08:25:29.850998 2026] [security2:error] [pid 419508:tid 419672] [client 152.59.34.51:54210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XKVcagwCeNbomjVsZeAAAAbE"]
[Tue Jul 21 08:25:29.851112 2026] [security2:error] [pid 419508:tid 419672] [client 152.59.34.51:54210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XKVcagwCeNbomjVsZeAAAAbE"]
[Tue Jul 21 08:25:30.070052 2026] [security2:error] [pid 419508:tid 419693] [client 65.21.113.253:34034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XKVcagwCeNbomjVsZbQAAAcY"]
[Tue Jul 21 08:25:30.177187 2026] [security2:error] [pid 419508:tid 419540] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.env"] [unique_id "al9XKlcagwCeNbomjVsZjAABtR8"]
[Tue Jul 21 08:25:30.187401 2026] [security2:error] [pid 419508:tid 419709] [client 20.226.60.151:56912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/wp.php"] [unique_id "al9XKlcagwCeNbomjVsZjQAAAdY"]
[Tue Jul 21 08:25:30.312306 2026] [security2:error] [pid 419508:tid 419529] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "login.gradiente.com"] [uri "/graphql"] [unique_id "al9XKlcagwCeNbomjVsZkwABwxQ"]
[Tue Jul 21 08:25:30.363418 2026] [security2:error] [pid 419508:tid 419576] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.env.backup"] [unique_id "al9XKlcagwCeNbomjVsZlQACCkM"]
[Tue Jul 21 08:25:30.391895 2026] [security2:error] [pid 419508:tid 419614] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/.env.bak"] [unique_id "al9XKlcagwCeNbomjVsZmQABzmk"]
[Tue Jul 21 08:25:30.393418 2026] [security2:error] [pid 419508:tid 419635] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/api/.env"] [unique_id "al9XKlcagwCeNbomjVsZlwABzn4"]
[Tue Jul 21 08:25:30.404139 2026] [security2:error] [pid 419508:tid 419516] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.env.old"] [unique_id "al9XKlcagwCeNbomjVsZmgABqgc"]
[Tue Jul 21 08:25:30.514167 2026] [security2:error] [pid 418108:tid 418259] [client 20.197.195.24:18273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/config.php"] [unique_id "al9XKg0cxofL2J1zwYrJaAAAAR0"]
[Tue Jul 21 08:25:30.530794 2026] [security2:error] [pid 419508:tid 419536] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/backend/.env"] [unique_id "al9XKlcagwCeNbomjVsZngABuRs"]
[Tue Jul 21 08:25:30.531015 2026] [security2:error] [pid 419508:tid 419680] [client 34.35.143.238:44666] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/backend/.env"] [unique_id "al9XKlcagwCeNbomjVsZngABuRs"]
[Tue Jul 21 08:25:30.565210 2026] [security2:error] [pid 419508:tid 419582] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/config/.env"] [unique_id "al9XKlcagwCeNbomjVsZoAABj0k"]
[Tue Jul 21 08:25:30.650470 2026] [security2:error] [pid 419508:tid 419572] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "login.gradiente.com"] [uri "/api/graphql"] [unique_id "al9XKlcagwCeNbomjVsZowAB5T8"]
[Tue Jul 21 08:25:30.835081 2026] [security2:error] [pid 419508:tid 419593] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "login.gradiente.com"] [uri "/secrets.yml"] [unique_id "al9XKlcagwCeNbomjVsZrAACAFQ"]
[Tue Jul 21 08:25:30.857424 2026] [security2:error] [pid 419508:tid 419570] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/credentials.json"] [unique_id "al9XKlcagwCeNbomjVsZsgABlj0"]
[Tue Jul 21 08:25:30.857576 2026] [security2:error] [pid 419508:tid 419645] [client 34.35.143.238:44666] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/credentials.json"] [unique_id "al9XKlcagwCeNbomjVsZsgABlj0"]
[Tue Jul 21 08:25:30.996742 2026] [security2:error] [pid 419508:tid 419600] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "login.gradiente.com"] [uri "/v1/graphql"] [unique_id "al9XKlcagwCeNbomjVsZtgABsVs"]
[Tue Jul 21 08:25:31.036268 2026] [security2:error] [pid 419508:tid 419575] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/.npmrc"] [unique_id "al9XK1cagwCeNbomjVsZtwACCEI"]
[Tue Jul 21 08:25:31.036438 2026] [security2:error] [pid 419508:tid 419760] [client 34.35.143.238:44666] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/.npmrc"] [unique_id "al9XK1cagwCeNbomjVsZtwACCEI"]
[Tue Jul 21 08:25:31.074991 2026] [security2:error] [pid 419508:tid 419731] [client 20.226.60.151:56932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/class.php"] [unique_id "al9XK1cagwCeNbomjVsZugAAAew"]
[Tue Jul 21 08:25:31.137369 2026] [security2:error] [pid 419508:tid 419562] [remote 45.79.123.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "annaguimaraes.com.br"] [uri "/wp-login.php"] [unique_id "al9XK1cagwCeNbomjVsZvgAB3jU"]
[Tue Jul 21 08:25:31.199250 2026] [security2:error] [pid 419508:tid 419605] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/.boto"] [unique_id "al9XK1cagwCeNbomjVsZwQABpWA"]
[Tue Jul 21 08:25:31.199901 2026] [authz_core:error] [pid 419508:tid 419573] [remote 34.35.143.238:44666] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Tue Jul 21 08:25:31.282585 2026] [security2:error] [pid 418108:tid 418359] [client 20.197.195.24:61075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/gettest.php"] [unique_id "al9XKw0cxofL2J1zwYrJcQAAAYE"]
[Tue Jul 21 08:25:31.543608 2026] [security2:error] [pid 419508:tid 419581] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.ssh/id_rsa"] [unique_id "al9XK1cagwCeNbomjVsZ0AABw0g"]
[Tue Jul 21 08:25:31.604349 2026] [security2:error] [pid 419508:tid 419569] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.ssh/id_dsa"] [unique_id "al9XK1cagwCeNbomjVsZ1QABlDw"]
[Tue Jul 21 08:25:31.816343 2026] [security2:error] [pid 419508:tid 419619] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/id_rsa"] [unique_id "al9XK1cagwCeNbomjVsZ3AAB224"]
[Tue Jul 21 08:25:31.921506 2026] [security2:error] [pid 419508:tid 419597] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/id_dsa"] [unique_id "al9XK1cagwCeNbomjVsZ5QAB8lg"]
[Tue Jul 21 08:25:31.921534 2026] [security2:error] [pid 419508:tid 419692] [client 20.197.195.24:18306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/min.php"] [unique_id "al9XK1cagwCeNbomjVsZ6AAAAcU"]
[Tue Jul 21 08:25:31.965463 2026] [security2:error] [pid 419508:tid 419556] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/id_ecdsa"] [unique_id "al9XK1cagwCeNbomjVsZ7AABly8"]
[Tue Jul 21 08:25:31.965660 2026] [security2:error] [pid 419508:tid 419646] [client 34.35.143.238:44666] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/id_ecdsa"] [unique_id "al9XK1cagwCeNbomjVsZ7AABly8"]
[Tue Jul 21 08:25:32.180749 2026] [security2:error] [pid 419508:tid 419514] [remote 62.210.185.4:34304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.185.210.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9XLFcagwCeNbomjVsZ8gABzgU"]
[Tue Jul 21 08:25:32.218324 2026] [security2:error] [pid 418108:tid 418332] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XLA0cxofL2J1zwYrJeAABZiA"]
[Tue Jul 21 08:25:32.253202 2026] [security2:error] [pid 419508:tid 419730] [client 65.21.113.253:34034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XLFcagwCeNbomjVsZ8AAAAes"]
[Tue Jul 21 08:25:32.269928 2026] [security2:error] [pid 419508:tid 419710] [client 109.248.148.246:48498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9XLFcagwCeNbomjVsZ8wAAAdc"]
[Tue Jul 21 08:25:32.270092 2026] [security2:error] [pid 419508:tid 419710] [client 109.248.148.246:48498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9XLFcagwCeNbomjVsZ8wAAAdc"]
[Tue Jul 21 08:25:32.325012 2026] [security2:error] [pid 418108:tid 418313] [client 20.226.60.151:56843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/echkm.php"] [unique_id "al9XLA0cxofL2J1zwYrJggAAAVM"]
[Tue Jul 21 08:25:32.425388 2026] [security2:error] [pid 419508:tid 419625] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/key.pem"] [unique_id "al9XLFcagwCeNbomjVsZ_AABk3Q"]
[Tue Jul 21 08:25:32.441891 2026] [security2:error] [pid 419508:tid 419628] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/privatekey.key"] [unique_id "al9XLFcagwCeNbomjVsZ_QAB2Hc"]
[Tue Jul 21 08:25:32.550442 2026] [security2:error] [pid 419508:tid 419565] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9XLFcagwCeNbomjVsaCwABpzg"]
[Tue Jul 21 08:25:32.599476 2026] [security2:error] [pid 418108:tid 418285] [client 20.226.60.151:63340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/lib.php"] [unique_id "al9XLA0cxofL2J1zwYrJhQAAATc"]
[Tue Jul 21 08:25:32.753810 2026] [security2:error] [pid 418108:tid 418266] [client 74.7.175.130:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "larissafurlanetodoss1782582169770.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9XLA0cxofL2J1zwYrJigABJFc"]
[Tue Jul 21 08:25:32.891395 2026] [security2:error] [pid 419508:tid 419560] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.hermes/.env"] [unique_id "al9XLFcagwCeNbomjVsaGQACBzM"]
[Tue Jul 21 08:25:32.916885 2026] [security2:error] [pid 419508:tid 419736] [client 20.220.225.223:19271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/kq1.php"] [unique_id "al9XLFcagwCeNbomjVsaHgAAAfE"]
[Tue Jul 21 08:25:32.946970 2026] [autoindex:error] [pid 419508:tid 419665] [client 20.206.105.145:20233] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:32.953073 2026] [security2:error] [pid 418108:tid 418335] [client 20.220.225.223:52632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/mac.php"] [unique_id "al9XLA0cxofL2J1zwYrJjQAAAWk"]
[Tue Jul 21 08:25:32.967562 2026] [autoindex:error] [pid 419508:tid 419735] [client 20.206.105.145:20233] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:32.984932 2026] [security2:error] [pid 419508:tid 419680] [client 20.206.105.145:20233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-temp.php"] [unique_id "al9XLFcagwCeNbomjVsaIwAAAbk"]
[Tue Jul 21 08:25:33.036847 2026] [security2:error] [pid 419508:tid 419587] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XLVcagwCeNbomjVsaJQABxU4"]
[Tue Jul 21 08:25:33.037097 2026] [security2:error] [pid 419508:tid 419692] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XLVcagwCeNbomjVsaJQABxU4"]
[Tue Jul 21 08:25:33.233166 2026] [security2:error] [pid 419508:tid 419636] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/.claude.json"] [unique_id "al9XLVcagwCeNbomjVsaLwAB138"]
[Tue Jul 21 08:25:33.299092 2026] [security2:error] [pid 418108:tid 418272] [client 202.179.75.202:40954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XLQ0cxofL2J1zwYrJkgAAASo"]
[Tue Jul 21 08:25:33.299246 2026] [security2:error] [pid 418108:tid 418272] [client 202.179.75.202:40954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XLQ0cxofL2J1zwYrJkgAAASo"]
[Tue Jul 21 08:25:33.485727 2026] [security2:error] [pid 419508:tid 419542] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "login.gradiente.com"] [uri "/wp-config.php.bak"] [unique_id "al9XLVcagwCeNbomjVsaPgABxiE"]
[Tue Jul 21 08:25:33.525763 2026] [security2:error] [pid 418108:tid 418273] [client 20.197.195.24:18309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/dvjul.php"] [unique_id "al9XLQ0cxofL2J1zwYrJlAAAASs"]
[Tue Jul 21 08:25:33.567081 2026] [security2:error] [pid 419508:tid 419662] [client 20.226.60.151:56869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/login.php"] [unique_id "al9XLVcagwCeNbomjVsaRAAAAac"]
[Tue Jul 21 08:25:33.595599 2026] [security2:error] [pid 419508:tid 419651] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "produto-express.com"] [uri "/index.php"] [unique_id "al9XLVcagwCeNbomjVsaQAABnEo"]
[Tue Jul 21 08:25:33.610622 2026] [security2:error] [pid 419508:tid 419512] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "login.gradiente.com"] [uri "/wp-config.php.old"] [unique_id "al9XLVcagwCeNbomjVsaRwABpQM"]
[Tue Jul 21 08:25:33.694015 2026] [security2:error] [pid 419508:tid 419581] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/laravel/.env"] [unique_id "al9XLVcagwCeNbomjVsaTgAB9Ug"]
[Tue Jul 21 08:25:33.783735 2026] [security2:error] [pid 419508:tid 419634] [remote 84.247.172.23:60512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9XLVcagwCeNbomjVsaUQABpn0"]
[Tue Jul 21 08:25:33.784849 2026] [security2:error] [pid 419508:tid 419649] [client 47.128.39.194:58700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "meuflatnapraia.com.br"] [uri "/robots.txt"] [unique_id "al9XLVcagwCeNbomjVsaUgAAAZo"]
[Tue Jul 21 08:25:33.874435 2026] [security2:error] [pid 419508:tid 419569] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/config/.env.php"] [unique_id "al9XLVcagwCeNbomjVsaVQABrTw"]
[Tue Jul 21 08:25:33.890186 2026] [security2:error] [pid 419508:tid 419615] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/.env.php.bak"] [unique_id "al9XLVcagwCeNbomjVsaVgAB5Go"]
[Tue Jul 21 08:25:33.912792 2026] [security2:error] [pid 419508:tid 419541] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/config.php.bak"] [unique_id "al9XLVcagwCeNbomjVsaWAABwyA"]
[Tue Jul 21 08:25:33.934737 2026] [security2:error] [pid 419508:tid 419574] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/core/.env"] [unique_id "al9XLVcagwCeNbomjVsaWQABtkE"]
[Tue Jul 21 08:25:33.940443 2026] [security2:error] [pid 419508:tid 419606] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/configuration.php.bak"] [unique_id "al9XLVcagwCeNbomjVsaWwABtmE"]
[Tue Jul 21 08:25:33.965192 2026] [security2:error] [pid 419508:tid 419597] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.env.swp"] [unique_id "al9XLVcagwCeNbomjVsaXwABlFg"]
[Tue Jul 21 08:25:34.028702 2026] [security2:error] [pid 419508:tid 419594] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/public/.env"] [unique_id "al9XLlcagwCeNbomjVsaYwAByFU"]
[Tue Jul 21 08:25:34.049641 2026] [security2:error] [pid 419508:tid 419548] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/web/.env"] [unique_id "al9XLlcagwCeNbomjVsaZAAB8Cc"]
[Tue Jul 21 08:25:34.170156 2026] [security2:error] [pid 419508:tid 419556] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/application.yml"] [unique_id "al9XLlcagwCeNbomjVsaZwABxS8"]
[Tue Jul 21 08:25:34.177879 2026] [security2:error] [pid 418108:tid 418249] [client 20.197.195.24:18250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/biufile.php"] [unique_id "al9XLg0cxofL2J1zwYrJnAAAARM"]
[Tue Jul 21 08:25:34.528006 2026] [security2:error] [pid 419508:tid 419618] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/appsettings.Development.json"] [unique_id "al9XLlcagwCeNbomjVsafwAB520"]
[Tue Jul 21 08:25:34.581586 2026] [autoindex:error] [pid 419508:tid 419710] [client 185.213.175.37:39442] AH01276: Cannot serve directory /home2/marc8022/bagepart.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:34.617878 2026] [security2:error] [pid 419508:tid 419737] [client 103.151.46.103:58168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XLlcagwCeNbomjVsahwAAAfI"]
[Tue Jul 21 08:25:34.617987 2026] [security2:error] [pid 419508:tid 419737] [client 103.151.46.103:58168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XLlcagwCeNbomjVsahwAAAfI"]
[Tue Jul 21 08:25:34.666948 2026] [security2:error] [pid 419508:tid 419536] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/web.config"] [unique_id "al9XLlcagwCeNbomjVsakAABnBs"]
[Tue Jul 21 08:25:34.918592 2026] [security2:error] [pid 419508:tid 419560] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/local.settings.json"] [unique_id "al9XLlcagwCeNbomjVsamQABmjM"]
[Tue Jul 21 08:25:35.015031 2026] [security2:error] [pid 419508:tid 419535] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/.env.development"] [unique_id "al9XL1cagwCeNbomjVsaoQABwxo"]
[Tue Jul 21 08:25:35.015202 2026] [security2:error] [pid 419508:tid 419690] [client 34.35.143.238:44666] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/.env.development"] [unique_id "al9XL1cagwCeNbomjVsaoQABwxo"]
[Tue Jul 21 08:25:35.019673 2026] [security2:error] [pid 419508:tid 419570] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "login.gradiente.com"] [uri "/.streamlit/secrets.toml"] [unique_id "al9XL1cagwCeNbomjVsaogABtj0"]
[Tue Jul 21 08:25:35.081765 2026] [security2:error] [pid 419508:tid 419676] [client 65.21.113.253:34034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XLlcagwCeNbomjVsajwAAAbU"]
[Tue Jul 21 08:25:35.370912 2026] [security2:error] [pid 419508:tid 419608] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/src/.env"] [unique_id "al9XL1cagwCeNbomjVsaswAB92M"]
[Tue Jul 21 08:25:35.389046 2026] [security2:error] [pid 419508:tid 419530] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/app/.env"] [unique_id "al9XL1cagwCeNbomjVsatgAB9hU"]
[Tue Jul 21 08:25:35.389178 2026] [security2:error] [pid 419508:tid 419741] [client 34.35.143.238:44666] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/app/.env"] [unique_id "al9XL1cagwCeNbomjVsatgAB9hU"]
[Tue Jul 21 08:25:35.469598 2026] [security2:error] [pid 418108:tid 418261] [client 128.127.105.184:50560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9XLw0cxofL2J1zwYrJpgAAAR8"]
[Tue Jul 21 08:25:35.469716 2026] [security2:error] [pid 418108:tid 418261] [client 128.127.105.184:50560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9XLw0cxofL2J1zwYrJpgAAAR8"]
[Tue Jul 21 08:25:35.500035 2026] [security2:error] [pid 418108:tid 418271] [client 20.197.195.24:61056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/av.php"] [unique_id "al9XLw0cxofL2J1zwYrJpwAAASk"]
[Tue Jul 21 08:25:35.596302 2026] [security2:error] [pid 418108:tid 418240] [client 34.168.88.184:53446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.88.168.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dsoler.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XLw0cxofL2J1zwYrJqwAAAQo"]
[Tue Jul 21 08:25:35.642188 2026] [security2:error] [pid 419508:tid 419542] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/frontend/.env"] [unique_id "al9XL1cagwCeNbomjVsavwABqCE"]
[Tue Jul 21 08:25:35.688446 2026] [security2:error] [pid 418108:tid 418131] [remote 216.73.216.184:16188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemape.xml"] [unique_id "al9XLw0cxofL2J1zwYrJrQABbRQ"]
[Tue Jul 21 08:25:35.721752 2026] [security2:error] [pid 419508:tid 419526] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/production/.env"] [unique_id "al9XL1cagwCeNbomjVsaxwABrhE"]
[Tue Jul 21 08:25:35.721935 2026] [security2:error] [pid 419508:tid 419669] [client 34.35.143.238:44666] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/production/.env"] [unique_id "al9XL1cagwCeNbomjVsaxwABrhE"]
[Tue Jul 21 08:25:35.722252 2026] [security2:error] [pid 419508:tid 419567] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/dev/.env"] [unique_id "al9XL1cagwCeNbomjVsaxgABrjo"]
[Tue Jul 21 08:25:35.735432 2026] [security2:error] [pid 419508:tid 419583] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/docker/.env"] [unique_id "al9XL1cagwCeNbomjVsaygABkko"]
[Tue Jul 21 08:25:35.763289 2026] [security2:error] [pid 419508:tid 419621] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/server/.env"] [unique_id "al9XL1cagwCeNbomjVsazAABp3A"]
[Tue Jul 21 08:25:35.763343 2026] [security2:error] [pid 419508:tid 419512] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/staging/.env"] [unique_id "al9XL1cagwCeNbomjVsazQABpwM"]
[Tue Jul 21 08:25:35.773096 2026] [security2:error] [pid 419508:tid 419602] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.env.prod.bak"] [unique_id "al9XL1cagwCeNbomjVsazwABqV0"]
[Tue Jul 21 08:25:35.773097 2026] [security2:error] [pid 419508:tid 419581] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.env.production.bak"] [unique_id "al9XL1cagwCeNbomjVsa0AABqUg"]
[Tue Jul 21 08:25:35.782063 2026] [security2:error] [pid 419508:tid 419629] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/@fs/.env"] [unique_id "al9XL1cagwCeNbomjVsa0gAB1Xg"]
[Tue Jul 21 08:25:35.877938 2026] [security2:error] [pid 419508:tid 419541] [remote 34.35.143.238:44666] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/@fs/root/.env"] [unique_id "al9XL1cagwCeNbomjVsa2QABpiA"]
[Tue Jul 21 08:25:36.007087 2026] [security2:error] [pid 419508:tid 419553] [remote 34.35.143.238:44666] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "login.gradiente.com"] [uri "/@fs/proc/self/environ"] [unique_id "al9XMFcagwCeNbomjVsa4wAB_Sw"]
[Tue Jul 21 08:25:36.334704 2026] [security2:error] [pid 419508:tid 419644] [client 34.168.88.184:58983] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dsoler.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9XMFcagwCeNbomjVsa7gAAAZU"]
[Tue Jul 21 08:25:36.444912 2026] [security2:error] [pid 419508:tid 419692] [client 20.197.195.24:18350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/coffexium.php"] [unique_id "al9XMFcagwCeNbomjVsa7wAAAcU"]
[Tue Jul 21 08:25:36.597520 2026] [autoindex:error] [pid 418108:tid 418314] [client 20.206.105.145:20154] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:36.603388 2026] [security2:error] [pid 419508:tid 419554] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XMFcagwCeNbomjVsa8QABjy0"]
[Tue Jul 21 08:25:36.603576 2026] [security2:error] [pid 419508:tid 419638] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XMFcagwCeNbomjVsa8QABjy0"]
[Tue Jul 21 08:25:36.611218 2026] [security2:error] [pid 418108:tid 418322] [client 20.206.105.145:20154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9XMA0cxofL2J1zwYrJugAAAVw"]
[Tue Jul 21 08:25:36.713116 2026] [security2:error] [pid 419508:tid 419760] [client 20.226.60.151:56855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/a2.php"] [unique_id "al9XMFcagwCeNbomjVsa9wAAAgg"]
[Tue Jul 21 08:25:36.955187 2026] [security2:error] [pid 418108:tid 418288] [client 20.197.195.24:61087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/core.php"] [unique_id "al9XMA0cxofL2J1zwYrJwQAAATo"]
[Tue Jul 21 08:25:37.048757 2026] [security2:error] [pid 418108:tid 418160] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/config.js"] [unique_id "al9XMQ0cxofL2J1zwYrJwgABcTE"]
[Tue Jul 21 08:25:37.048942 2026] [security2:error] [pid 418108:tid 418343] [client 34.35.143.238:55272] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/config.js"] [unique_id "al9XMQ0cxofL2J1zwYrJwgABcTE"]
[Tue Jul 21 08:25:37.049307 2026] [security2:error] [pid 418108:tid 418160] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/firebase-config.json"] [unique_id "al9XMQ0cxofL2J1zwYrJxQABcTE"]
[Tue Jul 21 08:25:37.051059 2026] [security2:error] [pid 418108:tid 418233] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "login.gradiente.com"] [uri "/__/firebase/init.json"] [unique_id "al9XMQ0cxofL2J1zwYrJxwABcXo"]
[Tue Jul 21 08:25:37.112030 2026] [security2:error] [pid 419508:tid 419639] [client 34.168.88.184:51733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dsoler.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9XMVcagwCeNbomjVsbAAAAAZA"]
[Tue Jul 21 08:25:37.295176 2026] [security2:error] [pid 419508:tid 419766] [client 20.197.195.24:3525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/als.php"] [unique_id "al9XMVcagwCeNbomjVsbAwAAAg4"]
[Tue Jul 21 08:25:37.410131 2026] [security2:error] [pid 418108:tid 418161] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "login.gradiente.com"] [uri "/runtime-config.js"] [unique_id "al9XMQ0cxofL2J1zwYrJ2QABbjI"]
[Tue Jul 21 08:25:37.500046 2026] [security2:error] [pid 418108:tid 418172] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XMQ0cxofL2J1zwYrJ3gABKz0"]
[Tue Jul 21 08:25:37.500265 2026] [security2:error] [pid 418108:tid 418273] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XMQ0cxofL2J1zwYrJ3gABKz0"]
[Tue Jul 21 08:25:37.775031 2026] [security2:error] [pid 419508:tid 419599] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XMVcagwCeNbomjVsbDgAB5Fo"]
[Tue Jul 21 08:25:37.775162 2026] [security2:error] [pid 419508:tid 419723] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XMVcagwCeNbomjVsbDgAB5Fo"]
[Tue Jul 21 08:25:37.784589 2026] [security2:error] [pid 418108:tid 418129] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/openapi.json"] [unique_id "al9XMQ0cxofL2J1zwYrJ6wABPhI"]
[Tue Jul 21 08:25:37.805802 2026] [security2:error] [pid 418108:tid 418202] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/api/openapi.json"] [unique_id "al9XMQ0cxofL2J1zwYrJ7AABC1s"]
[Tue Jul 21 08:25:37.806021 2026] [security2:error] [pid 418108:tid 418241] [client 34.35.143.238:55272] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/api/openapi.json"] [unique_id "al9XMQ0cxofL2J1zwYrJ7AABC1s"]
[Tue Jul 21 08:25:37.945658 2026] [security2:error] [pid 418108:tid 418249] [client 34.168.88.184:64743] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dsoler.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9XMQ0cxofL2J1zwYrJ7gAAARM"]
[Tue Jul 21 08:25:38.014724 2026] [security2:error] [pid 419508:tid 419720] [client 20.197.195.24:61118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/simple.php"] [unique_id "al9XMlcagwCeNbomjVsbFQAAAeE"]
[Tue Jul 21 08:25:38.024932 2026] [security2:error] [pid 419508:tid 419664] [client 117.213.202.34:55739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XMlcagwCeNbomjVsbFgAAAak"]
[Tue Jul 21 08:25:38.025076 2026] [security2:error] [pid 419508:tid 419664] [client 117.213.202.34:55739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XMlcagwCeNbomjVsbFgAAAak"]
[Tue Jul 21 08:25:38.039438 2026] [security2:error] [pid 419508:tid 419679] [client 150.129.202.39:12936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XMlcagwCeNbomjVsbFwAAAbg"]
[Tue Jul 21 08:25:38.039569 2026] [security2:error] [pid 419508:tid 419679] [client 150.129.202.39:12936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XMlcagwCeNbomjVsbFwAAAbg"]
[Tue Jul 21 08:25:38.046078 2026] [security2:error] [pid 418108:tid 418261] [client 213.152.186.163:44716] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9XMg0cxofL2J1zwYrJ8AAAAR8"]
[Tue Jul 21 08:25:38.046165 2026] [security2:error] [pid 418108:tid 418261] [client 213.152.186.163:44716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9XMg0cxofL2J1zwYrJ8AAAAR8"]
[Tue Jul 21 08:25:38.078391 2026] [security2:error] [pid 418108:tid 418158] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/api/account"] [unique_id "al9XMg0cxofL2J1zwYrJ9AABWy8"]
[Tue Jul 21 08:25:38.100803 2026] [security2:error] [pid 418108:tid 418182] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/api/health"] [unique_id "al9XMg0cxofL2J1zwYrJ9wABVkc"]
[Tue Jul 21 08:25:38.134612 2026] [security2:error] [pid 418108:tid 418204] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/sw.js"] [unique_id "al9XMg0cxofL2J1zwYrJ-QABUV0"]
[Tue Jul 21 08:25:38.134790 2026] [security2:error] [pid 418108:tid 418311] [client 34.35.143.238:55272] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/sw.js"] [unique_id "al9XMg0cxofL2J1zwYrJ-QABUV0"]
[Tue Jul 21 08:25:38.378831 2026] [security2:error] [pid 419508:tid 419738] [client 65.21.113.253:34034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XMlcagwCeNbomjVsbGAAAAfM"]
[Tue Jul 21 08:25:38.435100 2026] [security2:error] [pid 418108:tid 418246] [client 74.7.228.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "isabelaalvessantos1782474467182.0721679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9XMg0cxofL2J1zwYrKBQABEAo"]
[Tue Jul 21 08:25:38.624584 2026] [security2:error] [pid 418108:tid 418240] [client 195.49.128.211:64770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XMg0cxofL2J1zwYrKFAAAAQo"]
[Tue Jul 21 08:25:38.624720 2026] [security2:error] [pid 418108:tid 418240] [client 195.49.128.211:64770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XMg0cxofL2J1zwYrKFAAAAQo"]
[Tue Jul 21 08:25:38.720323 2026] [security2:error] [pid 419508:tid 419656] [client 34.168.88.184:49398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dsoler.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9XMlcagwCeNbomjVsbIwAAAaE"]
[Tue Jul 21 08:25:38.763954 2026] [security2:error] [pid 418108:tid 418118] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/info.php"] [unique_id "al9XMg0cxofL2J1zwYrKFgABDwc"]
[Tue Jul 21 08:25:38.776079 2026] [security2:error] [pid 418108:tid 418207] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/phpinfo.php"] [unique_id "al9XMg0cxofL2J1zwYrKFwABhGA"]
[Tue Jul 21 08:25:38.819224 2026] [security2:error] [pid 418108:tid 418174] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/pi.php"] [unique_id "al9XMg0cxofL2J1zwYrKGgABGj8"]
[Tue Jul 21 08:25:38.854275 2026] [security2:error] [pid 418108:tid 418151] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/i.php"] [unique_id "al9XMg0cxofL2J1zwYrKHQABfig"]
[Tue Jul 21 08:25:38.859799 2026] [security2:error] [pid 418108:tid 418230] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/test.php"] [unique_id "al9XMg0cxofL2J1zwYrKHwABfnc"]
[Tue Jul 21 08:25:39.099796 2026] [security2:error] [pid 418108:tid 418191] [remote 45.146.55.182:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mecanicanogueira.com.br"] [uri "/wp-login.php"] [unique_id "al9XMg0cxofL2J1zwYrKJQABZ1A"]
[Tue Jul 21 08:25:39.123301 2026] [security2:error] [pid 418108:tid 418228] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/app_dev.php/_profiler"] [unique_id "al9XMw0cxofL2J1zwYrKKQABiHU"]
[Tue Jul 21 08:25:39.135795 2026] [security2:error] [pid 418108:tid 418134] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/app_dev.php"] [unique_id "al9XMw0cxofL2J1zwYrKKwABGBc"]
[Tue Jul 21 08:25:39.151276 2026] [security2:error] [pid 419508:tid 419650] [client 213.152.186.163:40410] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9XM1cagwCeNbomjVsbKAAAAZs"]
[Tue Jul 21 08:25:39.151374 2026] [security2:error] [pid 419508:tid 419650] [client 213.152.186.163:40410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9XM1cagwCeNbomjVsbKAAAAZs"]
[Tue Jul 21 08:25:39.162803 2026] [security2:error] [pid 418108:tid 418177] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/__debug__/"] [unique_id "al9XMw0cxofL2J1zwYrKLAABSUI"]
[Tue Jul 21 08:25:39.192973 2026] [security2:error] [pid 418108:tid 418258] [client 20.197.195.24:18293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/init.php"] [unique_id "al9XMw0cxofL2J1zwYrKLwAAARw"]
[Tue Jul 21 08:25:39.222823 2026] [security2:error] [pid 418108:tid 418132] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/elmah.axd"] [unique_id "al9XMw0cxofL2J1zwYrKMwABQxU"]
[Tue Jul 21 08:25:39.231781 2026] [security2:error] [pid 418108:tid 418123] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "login.gradiente.com"] [uri "/trace.axd"] [unique_id "al9XMw0cxofL2J1zwYrKNQABMgw"]
[Tue Jul 21 08:25:39.241695 2026] [security2:error] [pid 418108:tid 418164] [remote 34.35.143.238:55272] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/server-info"] [unique_id "al9XMw0cxofL2J1zwYrKNwABKzU"]
[Tue Jul 21 08:25:39.245453 2026] [security2:error] [pid 419508:tid 419700] [client 20.220.225.223:19273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9XM1cagwCeNbomjVsbKwAAAc0"]
[Tue Jul 21 08:25:39.288587 2026] [access_compat:error] [pid 418108:tid 418186] [remote 34.35.143.238:55272] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 08:25:39.423123 2026] [security2:error] [pid 418108:tid 418126] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/website/.env"] [unique_id "al9XMw0cxofL2J1zwYrKOAABRw8"]
[Tue Jul 21 08:25:39.431744 2026] [security2:error] [pid 418108:tid 418302] [client 20.206.105.145:20141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/puc.php"] [unique_id "al9XMw0cxofL2J1zwYrKOQAAAUg"]
[Tue Jul 21 08:25:39.456793 2026] [security2:error] [pid 418108:tid 418269] [client 89.238.167.134:39086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9XMw0cxofL2J1zwYrKOgAAASc"]
[Tue Jul 21 08:25:39.456904 2026] [security2:error] [pid 418108:tid 418269] [client 89.238.167.134:39086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9XMw0cxofL2J1zwYrKOgAAASc"]
[Tue Jul 21 08:25:39.495661 2026] [security2:error] [pid 419508:tid 419766] [client 34.168.88.184:65182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dsoler.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9XM1cagwCeNbomjVsbLQAAAg4"]
[Tue Jul 21 08:25:39.520809 2026] [security2:error] [pid 419508:tid 419640] [client 141.255.164.66:47338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "novoar.net.br"] [uri "/"] [unique_id "al9XM1cagwCeNbomjVsbLgAAAZE"]
[Tue Jul 21 08:25:39.649422 2026] [security2:error] [pid 419508:tid 419683] [client 223.181.60.88:9723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XM1cagwCeNbomjVsbMgAAAbw"]
[Tue Jul 21 08:25:39.650740 2026] [security2:error] [pid 419508:tid 419683] [client 223.181.60.88:9723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XM1cagwCeNbomjVsbMgAAAbw"]
[Tue Jul 21 08:25:39.677373 2026] [security2:error] [pid 418108:tid 418271] [client 20.220.225.223:19311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9XMw0cxofL2J1zwYrKSgAAASk"]
[Tue Jul 21 08:25:39.892330 2026] [security2:error] [pid 419508:tid 419713] [client 187.125.243.197:61911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XM1cagwCeNbomjVsbOQAAAdo"]
[Tue Jul 21 08:25:39.892444 2026] [security2:error] [pid 419508:tid 419713] [client 187.125.243.197:61911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XM1cagwCeNbomjVsbOQAAAdo"]
[Tue Jul 21 08:25:40.031833 2026] [security2:error] [pid 418108:tid 418160] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/development/.env"] [unique_id "al9XNA0cxofL2J1zwYrKVgABFjE"]
[Tue Jul 21 08:25:40.193933 2026] [security2:error] [pid 418108:tid 418291] [client 20.226.60.151:63345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/d61.php"] [unique_id "al9XNA0cxofL2J1zwYrKWgAAAT0"]
[Tue Jul 21 08:25:40.244512 2026] [security2:error] [pid 418108:tid 418287] [client 115.134.11.136:63853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.11.134.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XNA0cxofL2J1zwYrKXAAAATk"]
[Tue Jul 21 08:25:40.245156 2026] [security2:error] [pid 418108:tid 418287] [client 115.134.11.136:63853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "daianapontes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XNA0cxofL2J1zwYrKXAAAATk"]
[Tue Jul 21 08:25:40.254269 2026] [security2:error] [pid 419508:tid 419690] [client 34.168.88.184:59582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dsoler.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9XNFcagwCeNbomjVsbQgAAAcM"]
[Tue Jul 21 08:25:40.280403 2026] [security2:error] [pid 418108:tid 418352] [client 20.220.225.223:19657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/dp.php"] [unique_id "al9XNA0cxofL2J1zwYrKYAAAAXo"]
[Tue Jul 21 08:25:40.328450 2026] [security2:error] [pid 419508:tid 419710] [client 61.1.167.83:57630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XNFcagwCeNbomjVsbRQAAAdc"]
[Tue Jul 21 08:25:40.328665 2026] [security2:error] [pid 419508:tid 419710] [client 61.1.167.83:57630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XNFcagwCeNbomjVsbRQAAAdc"]
[Tue Jul 21 08:25:40.375484 2026] [core:alert] [pid 418108:tid 418285] [client 57.141.18.91:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:25:40.657100 2026] [security2:error] [pid 418108:tid 418224] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/backend/.env"] [unique_id "al9XNA0cxofL2J1zwYrKaAABP3E"]
[Tue Jul 21 08:25:40.837771 2026] [security2:error] [pid 419508:tid 419692] [client 14.245.224.124:52602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XNFcagwCeNbomjVsbTwAAAcU"]
[Tue Jul 21 08:25:40.837891 2026] [security2:error] [pid 419508:tid 419692] [client 14.245.224.124:52602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XNFcagwCeNbomjVsbTwAAAcU"]
[Tue Jul 21 08:25:40.978400 2026] [security2:error] [pid 418108:tid 418307] [client 34.168.88.184:56314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dsoler.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9XNA0cxofL2J1zwYrKawAAAU0"]
[Tue Jul 21 08:25:41.048739 2026] [security2:error] [pid 419508:tid 419649] [client 213.152.186.163:40420] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9XNVcagwCeNbomjVsbVwAAAZo"]
[Tue Jul 21 08:25:41.048841 2026] [security2:error] [pid 419508:tid 419649] [client 213.152.186.163:40420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9XNVcagwCeNbomjVsbVwAAAZo"]
[Tue Jul 21 08:25:41.173882 2026] [security2:error] [pid 419508:tid 419752] [client 20.206.105.145:20203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/themes.php"] [unique_id "al9XNVcagwCeNbomjVsbWwAAAgA"]
[Tue Jul 21 08:25:41.261727 2026] [security2:error] [pid 418108:tid 418290] [client 20.220.225.223:19970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/old.php"] [unique_id "al9XNQ0cxofL2J1zwYrKcQAAATw"]
[Tue Jul 21 08:25:41.479455 2026] [security2:error] [pid 418108:tid 418261] [client 14.97.58.74:62051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XNA0cxofL2J1zwYrKYgAAAR8"]
[Tue Jul 21 08:25:41.479607 2026] [security2:error] [pid 418108:tid 418261] [client 14.97.58.74:62051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XNA0cxofL2J1zwYrKYgAAAR8"]
[Tue Jul 21 08:25:41.672890 2026] [security2:error] [pid 418108:tid 418301] [client 34.168.88.184:51997] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dsoler.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9XNQ0cxofL2J1zwYrKdgAAAUc"]
[Tue Jul 21 08:25:41.792280 2026] [security2:error] [pid 418108:tid 418312] [client 114.119.137.174:29791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carrosselbuique.com.br"] [uri "/sp_revisao-de-geografia-simulado-dezembro-2020"] [unique_id "al9XNQ0cxofL2J1zwYrKeAAAAVI"], referer: https://carrosselbuique.com.br/8o-ano/
[Tue Jul 21 08:25:41.842262 2026] [security2:error] [pid 418108:tid 418172] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/api/shared/config/.env"] [unique_id "al9XNQ0cxofL2J1zwYrKeQABLj0"]
[Tue Jul 21 08:25:41.969298 2026] [security2:error] [pid 419508:tid 419730] [client 20.197.195.24:18248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/fpwch.php"] [unique_id "al9XNVcagwCeNbomjVsbgwAAAes"]
[Tue Jul 21 08:25:42.084738 2026] [security2:error] [pid 419508:tid 419712] [client 152.59.34.51:54699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XNlcagwCeNbomjVsbhwAAAdk"]
[Tue Jul 21 08:25:42.084865 2026] [security2:error] [pid 419508:tid 419712] [client 152.59.34.51:54699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XNlcagwCeNbomjVsbhwAAAdk"]
[Tue Jul 21 08:25:42.375502 2026] [security2:error] [pid 419508:tid 419689] [client 34.168.88.184:54531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dsoler.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9XNlcagwCeNbomjVsblAAAAcI"]
[Tue Jul 21 08:25:42.676590 2026] [security2:error] [pid 419508:tid 419759] [client 20.220.225.223:19281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/ms-new.php"] [unique_id "al9XNlcagwCeNbomjVsbmQAAAgc"]
[Tue Jul 21 08:25:42.824604 2026] [security2:error] [pid 419508:tid 419537] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XNlcagwCeNbomjVsbmwABmxw"]
[Tue Jul 21 08:25:42.982167 2026] [security2:error] [pid 419508:tid 419648] [client 20.206.105.145:19905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/dx.php"] [unique_id "al9XNlcagwCeNbomjVsbpAAAAZk"]
[Tue Jul 21 08:25:42.999038 2026] [security2:error] [pid 419508:tid 419652] [client 20.220.225.223:52637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/samll.php"] [unique_id "al9XNlcagwCeNbomjVsbpQAAAZ0"]
[Tue Jul 21 08:25:43.068222 2026] [security2:error] [pid 418108:tid 418313] [client 20.220.225.223:19648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/track.php"] [unique_id "al9XNw0cxofL2J1zwYrKqgAAAVM"]
[Tue Jul 21 08:25:43.069856 2026] [security2:error] [pid 419508:tid 419665] [client 34.168.88.184:52093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dsoler.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9XN1cagwCeNbomjVsbpwAAAao"]
[Tue Jul 21 08:25:43.122235 2026] [security2:error] [pid 419508:tid 419663] [client 20.197.195.24:12896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/domvf.php"] [unique_id "al9XN1cagwCeNbomjVsbqAAAAag"]
[Tue Jul 21 08:25:43.368055 2026] [security2:error] [pid 418108:tid 418347] [client 20.226.60.151:63317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/info.php"] [unique_id "al9XNw0cxofL2J1zwYrKvQAAAXU"]
[Tue Jul 21 08:25:43.590068 2026] [security2:error] [pid 419508:tid 419764] [client 213.152.186.163:40714] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9XN1cagwCeNbomjVsbuAAAAgw"]
[Tue Jul 21 08:25:43.590181 2026] [security2:error] [pid 419508:tid 419764] [client 213.152.186.163:40714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9XN1cagwCeNbomjVsbuAAAAgw"]
[Tue Jul 21 08:25:43.686176 2026] [security2:error] [pid 419508:tid 419678] [client 20.220.225.223:19287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/2352356666.php"] [unique_id "al9XN1cagwCeNbomjVsbuwAAAbc"]
[Tue Jul 21 08:25:43.705713 2026] [security2:error] [pid 419508:tid 419626] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XN1cagwCeNbomjVsbvAACDXU"]
[Tue Jul 21 08:25:43.705956 2026] [security2:error] [pid 419508:tid 419765] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XN1cagwCeNbomjVsbvAACDXU"]
[Tue Jul 21 08:25:43.774874 2026] [security2:error] [pid 418108:tid 418278] [client 34.168.88.184:60761] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "dsoler.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9XNw0cxofL2J1zwYrKxAAAATA"]
[Tue Jul 21 08:25:44.228000 2026] [security2:error] [pid 419508:tid 419649] [client 202.179.75.202:44808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XOFcagwCeNbomjVsbywAAAZo"]
[Tue Jul 21 08:25:44.228474 2026] [security2:error] [pid 419508:tid 419649] [client 202.179.75.202:44808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XOFcagwCeNbomjVsbywAAAZo"]
[Tue Jul 21 08:25:44.382835 2026] [security2:error] [pid 418108:tid 418356] [client 20.220.225.223:19726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/pn.php"] [unique_id "al9XOA0cxofL2J1zwYrKyQAAAX4"]
[Tue Jul 21 08:25:44.411379 2026] [security2:error] [pid 419508:tid 419647] [client 20.206.105.145:20275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/p.php"] [unique_id "al9XOFcagwCeNbomjVsbzgAAAZg"]
[Tue Jul 21 08:25:44.444912 2026] [security2:error] [pid 418108:tid 418164] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/api/shared/.env"] [unique_id "al9XOA0cxofL2J1zwYrKywABETU"]
[Tue Jul 21 08:25:44.555909 2026] [security2:error] [pid 419508:tid 419663] [client 20.226.60.151:56905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/11.php"] [unique_id "al9XOFcagwCeNbomjVsb1gAAAag"]
[Tue Jul 21 08:25:44.957997 2026] [security2:error] [pid 419508:tid 419692] [client 141.11.107.74:51435] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "carrosselbuique.com.br"] [uri "/"] [unique_id "al9XOFcagwCeNbomjVsb4gAAAcU"]
[Tue Jul 21 08:25:44.974010 2026] [security2:error] [pid 419508:tid 419740] [client 141.11.107.74:51436] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.carrosselbuique.com.br"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "al9XOFcagwCeNbomjVsb5AAAAfU"]
[Tue Jul 21 08:25:44.978777 2026] [security2:error] [pid 419508:tid 419689] [client 141.11.107.74:51439] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.carrosselbuique.com.br"] [uri "/"] [unique_id "al9XOFcagwCeNbomjVsb5gAAAcI"]
[Tue Jul 21 08:25:44.987111 2026] [security2:error] [pid 419508:tid 419651] [client 141.11.107.74:51449] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.carrosselbuique.com.br"] [uri "/"] [unique_id "al9XOFcagwCeNbomjVsb6AAAAZw"]
[Tue Jul 21 08:25:44.990234 2026] [security2:error] [pid 419508:tid 419766] [client 141.11.107.74:51456] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9XOFcagwCeNbomjVsb6QAAAg4"]
[Tue Jul 21 08:25:45.001021 2026] [security2:error] [pid 419508:tid 419678] [client 141.11.107.74:51464] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.carrosselbuique.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9XOFcagwCeNbomjVsb6gAAAbc"]
[Tue Jul 21 08:25:45.001628 2026] [security2:error] [pid 418108:tid 418360] [client 141.11.107.74:51473] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.carrosselbuique.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9XOA0cxofL2J1zwYrK0QAAAYI"]
[Tue Jul 21 08:25:45.014762 2026] [security2:error] [pid 419508:tid 419696] [client 141.11.107.74:51480] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.carrosselbuique.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9XOVcagwCeNbomjVsb7AAAAck"]
[Tue Jul 21 08:25:45.031580 2026] [security2:error] [pid 418108:tid 418335] [client 20.220.225.223:19314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9XOQ0cxofL2J1zwYrK0gAAAWk"]
[Tue Jul 21 08:25:45.487536 2026] [security2:error] [pid 419508:tid 419670] [client 20.220.225.223:19675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/dr.php"] [unique_id "al9XOVcagwCeNbomjVsb9QAAAa8"]
[Tue Jul 21 08:25:45.566955 2026] [security2:error] [pid 419508:tid 419746] [client 20.197.195.24:18270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wp.php"] [unique_id "al9XOVcagwCeNbomjVscAAAAAfo"]
[Tue Jul 21 08:25:45.633175 2026] [security2:error] [pid 419508:tid 419717] [client 20.220.225.223:19650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/wicked.php"] [unique_id "al9XOVcagwCeNbomjVscAgAAAd4"]
[Tue Jul 21 08:25:45.828623 2026] [security2:error] [pid 419508:tid 419676] [client 20.220.225.223:19973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/2x.php"] [unique_id "al9XOVcagwCeNbomjVscCgAAAbU"]
[Tue Jul 21 08:25:45.890512 2026] [autoindex:error] [pid 419508:tid 419739] [client 20.206.105.145:20209] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:45.913416 2026] [security2:error] [pid 419508:tid 419707] [client 20.206.105.145:20209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/bthil.php"] [unique_id "al9XOVcagwCeNbomjVscEAAAAdQ"]
[Tue Jul 21 08:25:46.540154 2026] [security2:error] [pid 418108:tid 418298] [client 20.197.195.24:61123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/class.php"] [unique_id "al9XOg0cxofL2J1zwYrK6AAAAUQ"]
[Tue Jul 21 08:25:46.599749 2026] [security2:error] [pid 418108:tid 418355] [client 20.220.225.223:19279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/kq1.php"] [unique_id "al9XOg0cxofL2J1zwYrK6QAAAX0"]
[Tue Jul 21 08:25:46.703859 2026] [security2:error] [pid 419508:tid 419720] [client 89.238.167.134:53644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9XOlcagwCeNbomjVscOgAAAeE"]
[Tue Jul 21 08:25:46.703948 2026] [security2:error] [pid 419508:tid 419720] [client 89.238.167.134:53644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9XOlcagwCeNbomjVscOgAAAeE"]
[Tue Jul 21 08:25:46.811877 2026] [security2:error] [pid 419508:tid 419700] [client 20.206.105.145:20124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/7.php"] [unique_id "al9XOlcagwCeNbomjVscQQAAAc0"]
[Tue Jul 21 08:25:46.939017 2026] [security2:error] [pid 419508:tid 419714] [client 20.226.60.151:56941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/v2.php"] [unique_id "al9XOlcagwCeNbomjVscRAAAAds"]
[Tue Jul 21 08:25:47.542226 2026] [security2:error] [pid 419508:tid 419765] [client 20.206.105.145:20128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/8.php"] [unique_id "al9XO1cagwCeNbomjVscVwAAAg0"]
[Tue Jul 21 08:25:47.966624 2026] [security2:error] [pid 419508:tid 419648] [client 20.220.225.223:19312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/zzz.php"] [unique_id "al9XO1cagwCeNbomjVscZAAAAZk"]
[Tue Jul 21 08:25:48.146389 2026] [security2:error] [pid 418108:tid 418233] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XPA0cxofL2J1zwYrLAwABaXo"]
[Tue Jul 21 08:25:48.146537 2026] [security2:error] [pid 418108:tid 418335] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XPA0cxofL2J1zwYrLAwABaXo"]
[Tue Jul 21 08:25:48.360710 2026] [security2:error] [pid 418108:tid 418276] [client 20.197.195.24:18289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/echkm.php"] [unique_id "al9XPA0cxofL2J1zwYrLBwAAAS4"]
[Tue Jul 21 08:25:48.393803 2026] [security2:error] [pid 419508:tid 419512] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XPFcagwCeNbomjVsccQAB1wM"]
[Tue Jul 21 08:25:48.393963 2026] [security2:error] [pid 419508:tid 419710] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XPFcagwCeNbomjVsccQAB1wM"]
[Tue Jul 21 08:25:48.413236 2026] [security2:error] [pid 419508:tid 419684] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XO1cagwCeNbomjVscTwABvTI"]
[Tue Jul 21 08:25:48.564155 2026] [security2:error] [pid 418108:tid 418318] [client 150.129.202.39:64911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XPA0cxofL2J1zwYrLCAAAAVg"]
[Tue Jul 21 08:25:48.564344 2026] [security2:error] [pid 418108:tid 418318] [client 150.129.202.39:64911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XPA0cxofL2J1zwYrLCAAAAVg"]
[Tue Jul 21 08:25:48.675197 2026] [security2:error] [pid 419508:tid 419645] [client 117.213.202.34:56602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XPFcagwCeNbomjVsccwAAAZY"]
[Tue Jul 21 08:25:48.675326 2026] [security2:error] [pid 419508:tid 419645] [client 117.213.202.34:56602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XPFcagwCeNbomjVsccwAAAZY"]
[Tue Jul 21 08:25:48.769521 2026] [security2:error] [pid 419508:tid 419717] [client 20.206.105.145:20174] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.tamoiomix.com.br"] [uri "/1.php"] [unique_id "al9XPFcagwCeNbomjVsceAAAAd4"]
[Tue Jul 21 08:25:48.769645 2026] [security2:error] [pid 419508:tid 419717] [client 20.206.105.145:20174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/1.php"] [unique_id "al9XPFcagwCeNbomjVsceAAAAd4"]
[Tue Jul 21 08:25:49.064494 2026] [security2:error] [pid 419508:tid 419736] [client 20.197.195.24:3529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/lib.php"] [unique_id "al9XPVcagwCeNbomjVscewAAAfE"]
[Tue Jul 21 08:25:49.243303 2026] [security2:error] [pid 418108:tid 418270] [client 195.49.128.211:65356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XPQ0cxofL2J1zwYrLDAAAASg"]
[Tue Jul 21 08:25:49.243428 2026] [security2:error] [pid 418108:tid 418270] [client 195.49.128.211:65356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XPQ0cxofL2J1zwYrLDAAAASg"]
[Tue Jul 21 08:25:49.580684 2026] [security2:error] [pid 418108:tid 418208] [remote 67.207.94.191:64704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.94.207.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiapleno.com"] [uri "/wp-login.php"] [unique_id "al9XPQ0cxofL2J1zwYrLEAABVmE"]
[Tue Jul 21 08:25:49.688059 2026] [security2:error] [pid 418108:tid 418263] [client 128.127.105.184:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9XPQ0cxofL2J1zwYrLEwAAASE"]
[Tue Jul 21 08:25:49.688165 2026] [security2:error] [pid 418108:tid 418263] [client 128.127.105.184:59178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9XPQ0cxofL2J1zwYrLEwAAASE"]
[Tue Jul 21 08:25:49.718633 2026] [security2:error] [pid 419508:tid 419730] [client 151.63.71.144:61716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XPVcagwCeNbomjVscjAAAAes"]
[Tue Jul 21 08:25:49.718747 2026] [security2:error] [pid 419508:tid 419730] [client 151.63.71.144:61716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XPVcagwCeNbomjVscjAAAAes"]
[Tue Jul 21 08:25:49.981788 2026] [security2:error] [pid 419508:tid 419759] [client 20.197.195.24:61154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/login.php"] [unique_id "al9XPVcagwCeNbomjVsckQAAAgc"]
[Tue Jul 21 08:25:50.076457 2026] [security2:error] [pid 419508:tid 419658] [client 20.197.195.24:3524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/a2.php"] [unique_id "al9XPlcagwCeNbomjVsclQAAAaM"]
[Tue Jul 21 08:25:50.117751 2026] [security2:error] [pid 419508:tid 419665] [client 20.220.225.223:52666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/abcd.php"] [unique_id "al9XPlcagwCeNbomjVsclgAAAao"]
[Tue Jul 21 08:25:50.202988 2026] [security2:error] [pid 418108:tid 418299] [client 20.226.60.151:56862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/panel.php"] [unique_id "al9XPg0cxofL2J1zwYrLGQAAAUU"]
[Tue Jul 21 08:25:50.356925 2026] [security2:error] [pid 419508:tid 419650] [client 223.181.60.88:26950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XPlcagwCeNbomjVscnwAAAZs"]
[Tue Jul 21 08:25:50.358533 2026] [security2:error] [pid 419508:tid 419650] [client 223.181.60.88:26950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XPlcagwCeNbomjVscnwAAAZs"]
[Tue Jul 21 08:25:50.391300 2026] [security2:error] [pid 418108:tid 418355] [client 187.125.243.197:62411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XPg0cxofL2J1zwYrLHwAAAX0"]
[Tue Jul 21 08:25:50.391507 2026] [security2:error] [pid 418108:tid 418355] [client 187.125.243.197:62411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XPg0cxofL2J1zwYrLHwAAAX0"]
[Tue Jul 21 08:25:50.824966 2026] [security2:error] [pid 419508:tid 419543] [remote 198.244.183.63:59870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "porondeeuestive.com.br"] [uri "/robots.txt"] [unique_id "al9XPlcagwCeNbomjVscrAABnyI"]
[Tue Jul 21 08:25:50.825139 2026] [security2:error] [pid 419508:tid 419654] [client 198.244.183.63:59870] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "porondeeuestive.com.br"] [uri "/robots.txt"] [unique_id "al9XPlcagwCeNbomjVscrAABnyI"]
[Tue Jul 21 08:25:50.880124 2026] [security2:error] [pid 418108:tid 418298] [client 125.18.144.2:15382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XPg0cxofL2J1zwYrLLAAAAUQ"]
[Tue Jul 21 08:25:50.880248 2026] [security2:error] [pid 418108:tid 418298] [client 125.18.144.2:15382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XPg0cxofL2J1zwYrLLAAAAUQ"]
[Tue Jul 21 08:25:50.896804 2026] [security2:error] [pid 418108:tid 418338] [client 20.220.225.223:19669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/wicked.php"] [unique_id "al9XPg0cxofL2J1zwYrLLQAAAWw"]
[Tue Jul 21 08:25:51.252546 2026] [security2:error] [pid 419508:tid 419639] [client 20.197.195.24:61098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/d61.php"] [unique_id "al9XP1cagwCeNbomjVscsgAAAZA"]
[Tue Jul 21 08:25:51.294738 2026] [security2:error] [pid 418108:tid 418247] [client 20.206.105.145:20278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/100.php"] [unique_id "al9XPw0cxofL2J1zwYrLMwAAARE"]
[Tue Jul 21 08:25:51.716223 2026] [security2:error] [pid 419508:tid 419740] [client 20.220.225.223:19284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/edit.php"] [unique_id "al9XP1cagwCeNbomjVscuQAAAfU"]
[Tue Jul 21 08:25:51.743306 2026] [security2:error] [pid 419508:tid 419742] [client 14.245.224.124:53096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XP1cagwCeNbomjVscugAAAfc"]
[Tue Jul 21 08:25:51.743467 2026] [security2:error] [pid 419508:tid 419742] [client 14.245.224.124:53096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XP1cagwCeNbomjVscugAAAfc"]
[Tue Jul 21 08:25:52.005905 2026] [security2:error] [pid 418108:tid 418138] [remote 124.55.178.99:33754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/wp-login.php"] [unique_id "al9XQA0cxofL2J1zwYrLOgABUhs"]
[Tue Jul 21 08:25:52.210485 2026] [security2:error] [pid 419508:tid 419714] [client 20.197.195.24:18337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/info.php"] [unique_id "al9XQFcagwCeNbomjVscxAAAAds"]
[Tue Jul 21 08:25:52.379043 2026] [security2:error] [pid 419508:tid 419554] [remote 54.39.210.118:31364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "porondeeuestive.com.br"] [uri "/"] [unique_id "al9XQFcagwCeNbomjVscyAABxi0"]
[Tue Jul 21 08:25:52.379286 2026] [security2:error] [pid 419508:tid 419693] [client 54.39.210.118:31364] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "porondeeuestive.com.br"] [uri "/"] [unique_id "al9XQFcagwCeNbomjVscyAABxi0"]
[Tue Jul 21 08:25:52.706588 2026] [security2:error] [pid 419508:tid 419757] [client 152.59.34.51:55151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XQFcagwCeNbomjVsc0AAAAgU"]
[Tue Jul 21 08:25:52.711256 2026] [security2:error] [pid 419508:tid 419757] [client 152.59.34.51:55151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XQFcagwCeNbomjVsc0AAAAgU"]
[Tue Jul 21 08:25:52.831779 2026] [security2:error] [pid 418108:tid 418339] [client 20.197.195.24:61117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/11.php"] [unique_id "al9XQA0cxofL2J1zwYrLSgAAAW0"]
[Tue Jul 21 08:25:53.176136 2026] [security2:error] [pid 419508:tid 419689] [client 20.226.60.151:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/dex.php"] [unique_id "al9XQVcagwCeNbomjVsc2QAAAcI"]
[Tue Jul 21 08:25:53.270712 2026] [security2:error] [pid 418108:tid 418324] [client 20.197.195.24:18280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/v2.php"] [unique_id "al9XQQ0cxofL2J1zwYrLUgAAAV4"]
[Tue Jul 21 08:25:53.372596 2026] [security2:error] [pid 418108:tid 418286] [client 20.220.225.223:55751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/xyn.php"] [unique_id "al9XQQ0cxofL2J1zwYrLWgAAATg"]
[Tue Jul 21 08:25:53.373525 2026] [security2:error] [pid 418108:tid 418173] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XQQ0cxofL2J1zwYrLWQABHT4"]
[Tue Jul 21 08:25:53.373806 2026] [security2:error] [pid 418108:tid 418259] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XQQ0cxofL2J1zwYrLWQABHT4"]
[Tue Jul 21 08:25:53.797574 2026] [security2:error] [pid 419508:tid 419688] [client 128.127.105.184:37394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9XQVcagwCeNbomjVsc7gAAAcE"]
[Tue Jul 21 08:25:53.797715 2026] [security2:error] [pid 419508:tid 419688] [client 128.127.105.184:37394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9XQVcagwCeNbomjVsc7gAAAcE"]
[Tue Jul 21 08:25:54.051591 2026] [security2:error] [pid 419508:tid 419700] [client 20.197.195.24:3459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/panel.php"] [unique_id "al9XQlcagwCeNbomjVsc_QAAAc0"]
[Tue Jul 21 08:25:54.378882 2026] [security2:error] [pid 419508:tid 419561] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XQlcagwCeNbomjVsdCQABsjQ"]
[Tue Jul 21 08:25:54.379025 2026] [security2:error] [pid 419508:tid 419673] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XQlcagwCeNbomjVsdCQABsjQ"]
[Tue Jul 21 08:25:54.673129 2026] [security2:error] [pid 419508:tid 419764] [client 20.206.105.145:20156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/about.php"] [unique_id "al9XQlcagwCeNbomjVsdFgAAAgw"]
[Tue Jul 21 08:25:54.713867 2026] [core:error] [pid 419508:tid 419575] [remote 52.167.144.204:3573] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:25:54.713891 2026] [core:error] [pid 419508:tid 419575] [remote 52.167.144.204:3573] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:25:54.963422 2026] [security2:error] [pid 419508:tid 419704] [client 20.226.60.151:63346] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "osantotchay.com.br"] [uri "/1.php"] [unique_id "al9XQlcagwCeNbomjVsdIQAAAdE"]
[Tue Jul 21 08:25:54.963564 2026] [security2:error] [pid 419508:tid 419704] [client 20.226.60.151:63346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/1.php"] [unique_id "al9XQlcagwCeNbomjVsdIQAAAdE"]
[Tue Jul 21 08:25:55.053923 2026] [security2:error] [pid 419508:tid 419710] [client 89.238.167.134:42682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9XQ1cagwCeNbomjVsdKgAAAdc"]
[Tue Jul 21 08:25:55.054042 2026] [security2:error] [pid 419508:tid 419710] [client 89.238.167.134:42682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9XQ1cagwCeNbomjVsdKgAAAdc"]
[Tue Jul 21 08:25:55.118072 2026] [security2:error] [pid 419508:tid 419651] [client 202.179.75.202:51506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XQ1cagwCeNbomjVsdLQAAAZw"]
[Tue Jul 21 08:25:55.118173 2026] [security2:error] [pid 419508:tid 419651] [client 202.179.75.202:51506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XQ1cagwCeNbomjVsdLQAAAZw"]
[Tue Jul 21 08:25:55.192532 2026] [security2:error] [pid 418108:tid 418354] [client 20.197.195.24:61110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/dex.php"] [unique_id "al9XQw0cxofL2J1zwYrLcQAAAXw"]
[Tue Jul 21 08:25:55.719563 2026] [security2:error] [pid 418108:tid 418234] [remote 100.42.189.89:37144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compressoresra.com.br"] [uri "/wp-login.php"] [unique_id "al9XQw0cxofL2J1zwYrLeAABQ3s"]
[Tue Jul 21 08:25:55.770842 2026] [security2:error] [pid 419508:tid 419699] [client 20.220.225.223:19660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/kua.php"] [unique_id "al9XQ1cagwCeNbomjVsdUAAAAcw"]
[Tue Jul 21 08:25:55.838658 2026] [security2:error] [pid 419508:tid 419698] [client 20.197.195.24:61151] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "christianlins.com.br"] [uri "/1.php"] [unique_id "al9XQ1cagwCeNbomjVsdUQAAAcs"]
[Tue Jul 21 08:25:55.838789 2026] [security2:error] [pid 419508:tid 419698] [client 20.197.195.24:61151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/1.php"] [unique_id "al9XQ1cagwCeNbomjVsdUQAAAcs"]
[Tue Jul 21 08:25:55.970983 2026] [security2:error] [pid 418108:tid 418273] [client 168.144.242.191:53798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.242.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vivaconcierge.com.br"] [uri "/wp-login.php"] [unique_id "al9XQg0cxofL2J1zwYrLbQAAASs"], referer: https://www.google.com/
[Tue Jul 21 08:25:56.322083 2026] [security2:error] [pid 418108:tid 418169] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/.env.old"] [unique_id "al9XRA0cxofL2J1zwYrLfQABITo"]
[Tue Jul 21 08:25:56.361716 2026] [security2:error] [pid 419508:tid 419683] [client 20.226.60.151:62351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/ms.php"] [unique_id "al9XRFcagwCeNbomjVsdWQAAAbw"]
[Tue Jul 21 08:25:56.374879 2026] [security2:error] [pid 419508:tid 419586] [remote 91.142.222.105:44382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9XRFcagwCeNbomjVsdWgABxU0"]
[Tue Jul 21 08:25:56.722515 2026] [security2:error] [pid 418108:tid 418256] [client 20.220.225.223:19677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/edit.php"] [unique_id "al9XRA0cxofL2J1zwYrLhAAAARo"]
[Tue Jul 21 08:25:56.971116 2026] [security2:error] [pid 419508:tid 419647] [client 89.238.167.134:38612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9XRFcagwCeNbomjVsdYgAAAZg"]
[Tue Jul 21 08:25:56.971209 2026] [security2:error] [pid 419508:tid 419647] [client 89.238.167.134:38612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9XRFcagwCeNbomjVsdYgAAAZg"]
[Tue Jul 21 08:25:56.985211 2026] [security2:error] [pid 418108:tid 418314] [client 20.220.225.223:19972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/ez.php"] [unique_id "al9XRA0cxofL2J1zwYrLhwAAAVQ"]
[Tue Jul 21 08:25:57.129547 2026] [security2:error] [pid 418108:tid 418331] [client 20.197.195.24:3457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/ms.php"] [unique_id "al9XRQ0cxofL2J1zwYrLjgAAAWU"]
[Tue Jul 21 08:25:57.287851 2026] [security2:error] [pid 419508:tid 419658] [client 20.206.105.145:20122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/admin.php"] [unique_id "al9XRVcagwCeNbomjVsdaQAAAaM"]
[Tue Jul 21 08:25:57.292508 2026] [security2:error] [pid 419508:tid 419625] [remote 114.34.90.9:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp/wp-login.php"] [unique_id "al9XRVcagwCeNbomjVsdaAAB2nQ"]
[Tue Jul 21 08:25:57.790303 2026] [security2:error] [pid 418108:tid 418347] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XRQ0cxofL2J1zwYrLmQABdQE"]
[Tue Jul 21 08:25:57.858795 2026] [autoindex:error] [pid 419508:tid 419670] [client 20.197.195.24:3522] AH01276: Cannot serve directory /home2/chri2452/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:57.933846 2026] [security2:error] [pid 419508:tid 419728] [client 20.220.225.223:19327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/kua.php"] [unique_id "al9XRVcagwCeNbomjVsddgAAAek"]
[Tue Jul 21 08:25:58.180719 2026] [security2:error] [pid 419508:tid 419642] [client 168.144.242.191:53997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.242.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vivaconcierge.com.br"] [uri "/wp-login.php"] [unique_id "al9XRlcagwCeNbomjVsdfAAAAZM"], referer: https://wordpress.org/
[Tue Jul 21 08:25:58.287720 2026] [security2:error] [pid 419508:tid 419759] [client 20.220.225.223:52651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/byp8.php"] [unique_id "al9XRlcagwCeNbomjVsdfwAAAgc"]
[Tue Jul 21 08:25:58.540447 2026] [security2:error] [pid 419508:tid 419733] [client 20.197.195.24:3522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/memberfuns.php"] [unique_id "al9XRlcagwCeNbomjVsdhwAAAe4"]
[Tue Jul 21 08:25:58.693543 2026] [security2:error] [pid 419508:tid 419549] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XRlcagwCeNbomjVsdjgACCig"]
[Tue Jul 21 08:25:58.693667 2026] [security2:error] [pid 419508:tid 419762] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XRlcagwCeNbomjVsdjgACCig"]
[Tue Jul 21 08:25:58.811005 2026] [security2:error] [pid 418108:tid 418252] [client 5.31.193.106:29959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9XRQ0cxofL2J1zwYrLkwAAARY"]
[Tue Jul 21 08:25:58.979724 2026] [security2:error] [pid 419508:tid 419540] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XRlcagwCeNbomjVsdkgACAx8"]
[Tue Jul 21 08:25:58.979914 2026] [security2:error] [pid 419508:tid 419755] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XRlcagwCeNbomjVsdkgACAx8"]
[Tue Jul 21 08:25:59.106521 2026] [security2:error] [pid 419508:tid 419736] [client 65.21.113.253:40654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XRlcagwCeNbomjVsdigAAAfE"]
[Tue Jul 21 08:25:59.159658 2026] [security2:error] [pid 419508:tid 419714] [client 150.129.202.39:12911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XR1cagwCeNbomjVsdkwAAAds"]
[Tue Jul 21 08:25:59.159781 2026] [security2:error] [pid 419508:tid 419714] [client 150.129.202.39:12911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XR1cagwCeNbomjVsdkwAAAds"]
[Tue Jul 21 08:25:59.331810 2026] [security2:error] [pid 418108:tid 418321] [client 20.197.195.24:61059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/0.php"] [unique_id "al9XRw0cxofL2J1zwYrLrgAAAVs"]
[Tue Jul 21 08:25:59.389924 2026] [security2:error] [pid 418108:tid 418271] [client 117.213.202.34:57142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XRw0cxofL2J1zwYrLsAAAASk"]
[Tue Jul 21 08:25:59.390082 2026] [security2:error] [pid 418108:tid 418271] [client 117.213.202.34:57142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XRw0cxofL2J1zwYrLsAAAASk"]
[Tue Jul 21 08:25:59.399016 2026] [autoindex:error] [pid 418108:tid 418291] [client 20.226.60.151:62350] AH01276: Cannot serve directory /home3/cur37674/osantotchay.com.br/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:25:59.428428 2026] [security2:error] [pid 418108:tid 418256] [client 20.226.60.151:62350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/memberfuns.php"] [unique_id "al9XRw0cxofL2J1zwYrLswAAARo"]
[Tue Jul 21 08:25:59.428891 2026] [security2:error] [pid 418108:tid 418162] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/crm/.env"] [unique_id "al9XRw0cxofL2J1zwYrLsgABRTM"]
[Tue Jul 21 08:25:59.643579 2026] [security2:error] [pid 418108:tid 418286] [client 20.220.225.223:19297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/ez.php"] [unique_id "al9XRw0cxofL2J1zwYrLtgAAATg"]
[Tue Jul 21 08:25:59.857202 2026] [security2:error] [pid 418108:tid 418324] [client 195.49.128.211:49565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XRw0cxofL2J1zwYrLtwAAAV4"]
[Tue Jul 21 08:25:59.857340 2026] [security2:error] [pid 418108:tid 418324] [client 195.49.128.211:49565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XRw0cxofL2J1zwYrLtwAAAV4"]
[Tue Jul 21 08:26:00.130249 2026] [security2:error] [pid 418108:tid 418134] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/local/.env"] [unique_id "al9XSA0cxofL2J1zwYrLugABRBc"]
[Tue Jul 21 08:26:00.335659 2026] [security2:error] [pid 419508:tid 419525] [remote 159.65.81.207:58826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tempex.com.br"] [uri "/wp-login.php"] [unique_id "al9XSFcagwCeNbomjVsdvgAB1hA"]
[Tue Jul 21 08:26:00.345012 2026] [security2:error] [pid 418108:tid 418350] [client 20.197.195.24:18274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/BDKR28.php"] [unique_id "al9XSA0cxofL2J1zwYrLvAAAAXg"]
[Tue Jul 21 08:26:00.363758 2026] [security2:error] [pid 418108:tid 418329] [client 20.206.105.145:20104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/edit.php"] [unique_id "al9XSA0cxofL2J1zwYrLvQAAAWM"]
[Tue Jul 21 08:26:00.581599 2026] [security2:error] [pid 418108:tid 418259] [client 152.59.34.51:55625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XSA0cxofL2J1zwYrLwAAAAR0"]
[Tue Jul 21 08:26:00.581704 2026] [security2:error] [pid 418108:tid 418259] [client 152.59.34.51:55625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XSA0cxofL2J1zwYrLwAAAAR0"]
[Tue Jul 21 08:26:00.833508 2026] [security2:error] [pid 419508:tid 419692] [client 187.125.243.197:62908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XSFcagwCeNbomjVsd1wAAAcU"]
[Tue Jul 21 08:26:00.833641 2026] [security2:error] [pid 419508:tid 419692] [client 187.125.243.197:62908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XSFcagwCeNbomjVsd1wAAAcU"]
[Tue Jul 21 08:26:01.076873 2026] [security2:error] [pid 418108:tid 418269] [client 223.181.60.88:2181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XSQ0cxofL2J1zwYrLyQAAASc"]
[Tue Jul 21 08:26:01.076965 2026] [security2:error] [pid 418108:tid 418269] [client 223.181.60.88:2181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XSQ0cxofL2J1zwYrLyQAAASc"]
[Tue Jul 21 08:26:01.279473 2026] [security2:error] [pid 419508:tid 419689] [client 20.226.60.151:62390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/0.php"] [unique_id "al9XSVcagwCeNbomjVsd3wAAAcI"]
[Tue Jul 21 08:26:01.304937 2026] [security2:error] [pid 418108:tid 418290] [client 20.220.225.223:19265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/fz.php"] [unique_id "al9XSQ0cxofL2J1zwYrLywAAATw"]
[Tue Jul 21 08:26:01.584951 2026] [proxy:error] [pid 419508:tid 419671] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:26:01.585025 2026] [proxy_http:error] [pid 419508:tid 419671] [client 64.23.178.201:37056] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:26:01.586100 2026] [proxy:error] [pid 419508:tid 419671] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:26:01.586137 2026] [proxy_http:error] [pid 419508:tid 419671] [client 64.23.178.201:37056] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:26:01.641825 2026] [security2:error] [pid 419508:tid 419755] [client 14.97.58.74:31096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XSVcagwCeNbomjVsd7QAAAgM"]
[Tue Jul 21 08:26:01.641969 2026] [security2:error] [pid 419508:tid 419755] [client 14.97.58.74:31096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XSVcagwCeNbomjVsd7QAAAgM"]
[Tue Jul 21 08:26:01.791249 2026] [security2:error] [pid 419508:tid 419748] [client 20.197.195.24:62551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/green1.php"] [unique_id "al9XSVcagwCeNbomjVsd7wAAAfw"]
[Tue Jul 21 08:26:01.938374 2026] [security2:error] [pid 419508:tid 419759] [client 20.197.195.24:3546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/nc4.php"] [unique_id "al9XSVcagwCeNbomjVsd-wAAAgc"]
[Tue Jul 21 08:26:01.979663 2026] [proxy:error] [pid 419508:tid 419712] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:26:01.979738 2026] [proxy_http:error] [pid 419508:tid 419712] [client 64.23.178.201:37062] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.conhecaonordeste.com.br/
[Tue Jul 21 08:26:01.980434 2026] [proxy:error] [pid 419508:tid 419712] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:26:01.980472 2026] [proxy_http:error] [pid 419508:tid 419712] [client 64.23.178.201:37062] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.conhecaonordeste.com.br/
[Tue Jul 21 08:26:02.003427 2026] [security2:error] [pid 419508:tid 419731] [client 20.197.195.24:61062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/a1.php"] [unique_id "al9XSlcagwCeNbomjVsd_gAAAew"]
[Tue Jul 21 08:26:02.018026 2026] [security2:error] [pid 419508:tid 419742] [client 65.21.113.253:40654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XSVcagwCeNbomjVsd5wAAAfc"]
[Tue Jul 21 08:26:02.123852 2026] [security2:error] [pid 419508:tid 419581] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/core/.env"] [unique_id "al9XSlcagwCeNbomjVseBgABuUg"]
[Tue Jul 21 08:26:02.195577 2026] [security2:error] [pid 419508:tid 419683] [client 20.206.105.145:20197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9XSlcagwCeNbomjVseBwAAAbw"]
[Tue Jul 21 08:26:02.230745 2026] [security2:error] [pid 419508:tid 419691] [client 20.197.195.24:13852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/eee.php"] [unique_id "al9XSlcagwCeNbomjVseCgAAAcQ"]
[Tue Jul 21 08:26:02.565554 2026] [security2:error] [pid 419508:tid 419651] [client 213.152.186.163:42002] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9XSlcagwCeNbomjVseFAAAAZw"]
[Tue Jul 21 08:26:02.565645 2026] [security2:error] [pid 419508:tid 419651] [client 213.152.186.163:42002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9XSlcagwCeNbomjVseFAAAAZw"]
[Tue Jul 21 08:26:02.647303 2026] [security2:error] [pid 418108:tid 418284] [client 14.245.224.124:53598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XSg0cxofL2J1zwYrL2gAAATY"]
[Tue Jul 21 08:26:02.647451 2026] [security2:error] [pid 418108:tid 418284] [client 14.245.224.124:53598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XSg0cxofL2J1zwYrL2gAAATY"]
[Tue Jul 21 08:26:02.673827 2026] [security2:error] [pid 418108:tid 418328] [client 20.226.60.151:56884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/BDKR28.php"] [unique_id "al9XSg0cxofL2J1zwYrL3QAAAWI"]
[Tue Jul 21 08:26:02.705804 2026] [security2:error] [pid 419508:tid 419746] [client 61.1.167.83:58221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XSlcagwCeNbomjVseHQAAAfo"]
[Tue Jul 21 08:26:02.705900 2026] [security2:error] [pid 419508:tid 419746] [client 61.1.167.83:58221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XSlcagwCeNbomjVseHQAAAfo"]
[Tue Jul 21 08:26:02.761359 2026] [proxy:error] [pid 419508:tid 419763] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:26:02.761400 2026] [proxy_http:error] [pid 419508:tid 419763] [client 64.23.178.201:37666] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:26:02.761984 2026] [proxy:error] [pid 419508:tid 419763] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:26:02.762008 2026] [proxy_http:error] [pid 419508:tid 419763] [client 64.23.178.201:37666] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:26:03.352319 2026] [security2:error] [pid 418108:tid 418365] [client 20.226.60.151:5058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/green1.php"] [unique_id "al9XSw0cxofL2J1zwYrL4wAAAYc"]
[Tue Jul 21 08:26:03.707360 2026] [security2:error] [pid 418108:tid 418293] [client 20.197.195.24:61146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/wp-aothait.php"] [unique_id "al9XSw0cxofL2J1zwYrL6gAAAT8"]
[Tue Jul 21 08:26:04.024245 2026] [security2:error] [pid 419508:tid 419545] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XTFcagwCeNbomjVseSAABkSQ"]
[Tue Jul 21 08:26:04.024461 2026] [security2:error] [pid 419508:tid 419640] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XTFcagwCeNbomjVseSAABkSQ"]
[Tue Jul 21 08:26:04.046889 2026] [security2:error] [pid 419508:tid 419614] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/apps/.env"] [unique_id "al9XTFcagwCeNbomjVseSQABsmk"]
[Tue Jul 21 08:26:04.048973 2026] [security2:error] [pid 419508:tid 419656] [client 20.197.195.24:3460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/config.json.php"] [unique_id "al9XTFcagwCeNbomjVseSgAAAaE"]
[Tue Jul 21 08:26:04.336710 2026] [security2:error] [pid 419508:tid 419682] [client 20.226.60.151:5096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/nc4.php"] [unique_id "al9XTFcagwCeNbomjVseTQAAAbs"]
[Tue Jul 21 08:26:04.497415 2026] [security2:error] [pid 419508:tid 419692] [client 65.21.113.253:40654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XS1cagwCeNbomjVseRQAAAcU"]
[Tue Jul 21 08:26:04.594106 2026] [security2:error] [pid 419508:tid 419675] [client 20.197.195.24:18290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9XTFcagwCeNbomjVseVgAAAbQ"]
[Tue Jul 21 08:26:04.737789 2026] [security2:error] [pid 419508:tid 419740] [client 20.226.60.151:62341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/a1.php"] [unique_id "al9XTFcagwCeNbomjVseWQAAAfU"]
[Tue Jul 21 08:26:04.833967 2026] [security2:error] [pid 419508:tid 419571] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/application/.env"] [unique_id "al9XTFcagwCeNbomjVseWgAB0D4"]
[Tue Jul 21 08:26:05.094559 2026] [security2:error] [pid 418108:tid 418336] [client 20.226.60.151:56893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/eee.php"] [unique_id "al9XTQ0cxofL2J1zwYrL7wAAAWo"]
[Tue Jul 21 08:26:05.098546 2026] [security2:error] [pid 418108:tid 418242] [client 20.197.195.24:18271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/k2.php"] [unique_id "al9XTQ0cxofL2J1zwYrL8AAAAQw"]
[Tue Jul 21 08:26:05.111981 2026] [security2:error] [pid 418108:tid 418238] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XTQ0cxofL2J1zwYrL8QABLH8"]
[Tue Jul 21 08:26:05.112117 2026] [security2:error] [pid 418108:tid 418274] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XTQ0cxofL2J1zwYrL8QABLH8"]
[Tue Jul 21 08:26:05.167092 2026] [security2:error] [pid 418108:tid 418366] [client 20.220.225.223:19668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/fz.php"] [unique_id "al9XTQ0cxofL2J1zwYrL8gAAAYg"]
[Tue Jul 21 08:26:05.227369 2026] [security2:error] [pid 418108:tid 418276] [client 213.152.186.163:45578] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9XTQ0cxofL2J1zwYrL9QAAAS4"]
[Tue Jul 21 08:26:05.227462 2026] [security2:error] [pid 418108:tid 418276] [client 213.152.186.163:45578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9XTQ0cxofL2J1zwYrL9QAAAS4"]
[Tue Jul 21 08:26:05.348801 2026] [security2:error] [pid 419508:tid 419560] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/web/.env"] [unique_id "al9XTVcagwCeNbomjVseZQABzDM"]
[Tue Jul 21 08:26:05.437116 2026] [security2:error] [pid 419508:tid 419676] [client 185.198.240.188:26787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9XTVcagwCeNbomjVseaAAAAbU"]
[Tue Jul 21 08:26:05.443596 2026] [security2:error] [pid 419508:tid 419755] [client 185.198.240.206:35863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9XTVcagwCeNbomjVseaQAAAgM"]
[Tue Jul 21 08:26:05.493513 2026] [security2:error] [pid 419508:tid 419687] [client 20.197.195.24:61164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9XTVcagwCeNbomjVsebQAAAcA"]
[Tue Jul 21 08:26:05.744491 2026] [security2:error] [pid 419508:tid 419739] [client 20.197.195.24:62490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9XTVcagwCeNbomjVsedAAAAfQ"]
[Tue Jul 21 08:26:05.755523 2026] [security2:error] [pid 418108:tid 418354] [client 20.10.88.201:7619] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "weightloss-review.shop"] [uri "/robots.txt"] [unique_id "al9XTQ0cxofL2J1zwYrL-QAAAXw"]
[Tue Jul 21 08:26:05.807001 2026] [security2:error] [pid 418108:tid 418301] [client 20.226.60.151:56902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/wp-aothait.php"] [unique_id "al9XTQ0cxofL2J1zwYrL-gAAAUc"]
[Tue Jul 21 08:26:05.815180 2026] [security2:error] [pid 418108:tid 418245] [client 20.206.105.145:20134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/f6.php"] [unique_id "al9XTQ0cxofL2J1zwYrL-wAAAQ8"]
[Tue Jul 21 08:26:05.984641 2026] [security2:error] [pid 419508:tid 419696] [client 202.179.75.202:57256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XTVcagwCeNbomjVseeAAAAck"]
[Tue Jul 21 08:26:05.984801 2026] [security2:error] [pid 419508:tid 419696] [client 202.179.75.202:57256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XTVcagwCeNbomjVseeAAAAck"]
[Tue Jul 21 08:26:06.089149 2026] [security2:error] [pid 418108:tid 418332] [client 20.197.195.24:61141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9XTg0cxofL2J1zwYrL_QAAAWY"]
[Tue Jul 21 08:26:06.107080 2026] [security2:error] [pid 418108:tid 418241] [client 20.226.60.151:63349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/config.json.php"] [unique_id "al9XTg0cxofL2J1zwYrL_gAAAQs"]
[Tue Jul 21 08:26:06.456747 2026] [security2:error] [pid 418108:tid 418292] [client 20.226.60.151:56858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9XTg0cxofL2J1zwYrMAwAAAT4"]
[Tue Jul 21 08:26:06.578142 2026] [access_compat:error] [pid 419508:tid 419720] [client 162.241.63.68:30670] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:26:06.641203 2026] [security2:error] [pid 419508:tid 419660] [client 20.197.195.24:18362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/for.php"] [unique_id "al9XTlcagwCeNbomjVsejgAAAaU"]
[Tue Jul 21 08:26:06.916241 2026] [security2:error] [pid 419508:tid 419757] [client 65.21.113.253:40654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XTlcagwCeNbomjVsehQAAAgU"]
[Tue Jul 21 08:26:06.954280 2026] [security2:error] [pid 419508:tid 419697] [client 20.226.60.151:5091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/k2.php"] [unique_id "al9XTlcagwCeNbomjVsekAAAAco"]
[Tue Jul 21 08:26:07.154322 2026] [security2:error] [pid 419508:tid 419642] [client 20.226.60.151:62354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9XT1cagwCeNbomjVselwAAAZM"]
[Tue Jul 21 08:26:07.330743 2026] [security2:error] [pid 419508:tid 419750] [client 20.220.225.223:58943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/user.php"] [unique_id "al9XT1cagwCeNbomjVsemgAAAf4"]
[Tue Jul 21 08:26:07.376023 2026] [security2:error] [pid 419508:tid 419734] [client 20.226.60.151:56878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9XT1cagwCeNbomjVsemwAAAe8"]
[Tue Jul 21 08:26:07.400272 2026] [proxy:error] [pid 419508:tid 419766] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:26:07.400349 2026] [proxy_http:error] [pid 419508:tid 419766] [client 64.23.178.201:37768] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.conhecaonordeste.com.br/
[Tue Jul 21 08:26:07.400994 2026] [proxy:error] [pid 419508:tid 419766] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:26:07.401023 2026] [proxy_http:error] [pid 419508:tid 419766] [client 64.23.178.201:37768] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.conhecaonordeste.com.br/
[Tue Jul 21 08:26:07.530857 2026] [security2:error] [pid 419508:tid 419681] [client 20.226.60.151:62338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9XT1cagwCeNbomjVseoQAAAbo"]
[Tue Jul 21 08:26:08.045251 2026] [security2:error] [pid 419508:tid 419651] [client 20.226.60.151:56891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/for.php"] [unique_id "al9XUFcagwCeNbomjVsergAAAZw"]
[Tue Jul 21 08:26:08.413847 2026] [security2:error] [pid 419508:tid 419707] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XUFcagwCeNbomjVsetAAB1BU"]
[Tue Jul 21 08:26:08.436284 2026] [security2:error] [pid 419508:tid 419692] [client 20.197.195.24:3463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "christianlins.com.br"] [uri "/raw.php"] [unique_id "al9XUFcagwCeNbomjVseuAAAAcU"]
[Tue Jul 21 08:26:08.483779 2026] [security2:error] [pid 419508:tid 419720] [client 20.226.60.151:5115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "osantotchay.com.br"] [uri "/raw.php"] [unique_id "al9XUFcagwCeNbomjVseuwAAAeE"]
[Tue Jul 21 08:26:08.546016 2026] [security2:error] [pid 418108:tid 418136] [remote 185.191.171.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "androapkmod.com"] [uri "/matchmaker-choose-your-story/"] [unique_id "al9XUA0cxofL2J1zwYrMGwABfxk"]
[Tue Jul 21 08:26:08.546224 2026] [security2:error] [pid 418108:tid 418357] [client 185.191.171.16:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "androapkmod.com"] [uri "/matchmaker-choose-your-story/"] [unique_id "al9XUA0cxofL2J1zwYrMGwABfxk"]
[Tue Jul 21 08:26:08.697898 2026] [security2:error] [pid 418108:tid 418166] [remote 199.189.225.40:55095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiferreira.com.br"] [uri "/wp-login.php"] [unique_id "al9XUA0cxofL2J1zwYrMHQABCjc"]
[Tue Jul 21 08:26:08.750314 2026] [security2:error] [pid 419508:tid 419572] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/info.php"] [unique_id "al9XUFcagwCeNbomjVsewwACBT8"]
[Tue Jul 21 08:26:08.787794 2026] [security2:error] [pid 418108:tid 418358] [client 103.151.46.103:59645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XUA0cxofL2J1zwYrMHgAAAYA"]
[Tue Jul 21 08:26:08.787921 2026] [security2:error] [pid 418108:tid 418358] [client 103.151.46.103:59645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XUA0cxofL2J1zwYrMHgAAAYA"]
[Tue Jul 21 08:26:09.283059 2026] [security2:error] [pid 419508:tid 419601] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XUVcagwCeNbomjVse0AAB-1w"]
[Tue Jul 21 08:26:09.283502 2026] [security2:error] [pid 419508:tid 419601] [remote 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XUVcagwCeNbomjVse0AAB-1w"]
[Tue Jul 21 08:26:09.379607 2026] [security2:error] [pid 419508:tid 419688] [client 65.21.113.253:40654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XUFcagwCeNbomjVsexAAAAcE"]
[Tue Jul 21 08:26:09.530539 2026] [security2:error] [pid 419508:tid 419621] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XUVcagwCeNbomjVse1wACAHA"]
[Tue Jul 21 08:26:09.530744 2026] [security2:error] [pid 419508:tid 419752] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XUVcagwCeNbomjVse1wACAHA"]
[Tue Jul 21 08:26:09.612219 2026] [security2:error] [pid 419508:tid 419535] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/dashboard/phpinfo.php"] [unique_id "al9XUVcagwCeNbomjVse2QAB0ho"]
[Tue Jul 21 08:26:09.749882 2026] [security2:error] [pid 419508:tid 419696] [client 142.132.180.39:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9XUVcagwCeNbomjVse3QAByUE"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:26:09.762580 2026] [security2:error] [pid 419508:tid 419759] [client 65.21.113.253:37608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XUVcagwCeNbomjVse1QAAAgc"]
[Tue Jul 21 08:26:09.803925 2026] [security2:error] [pid 419508:tid 419766] [client 150.129.202.39:65128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XUVcagwCeNbomjVse3wAAAg4"]
[Tue Jul 21 08:26:09.804062 2026] [security2:error] [pid 419508:tid 419766] [client 150.129.202.39:65128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XUVcagwCeNbomjVse3wAAAg4"]
[Tue Jul 21 08:26:09.947221 2026] [security2:error] [pid 418108:tid 418311] [client 20.220.225.223:52658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/ops.php"] [unique_id "al9XUQ0cxofL2J1zwYrMKAAAAVE"]
[Tue Jul 21 08:26:10.075421 2026] [security2:error] [pid 419508:tid 419704] [client 117.213.202.34:57686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XUlcagwCeNbomjVse4wAAAdE"]
[Tue Jul 21 08:26:10.079074 2026] [security2:error] [pid 419508:tid 419704] [client 117.213.202.34:57686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XUlcagwCeNbomjVse4wAAAdE"]
[Tue Jul 21 08:26:10.300491 2026] [security2:error] [pid 419508:tid 419679] [client 142.132.180.39:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9XUlcagwCeNbomjVse6QABuBw"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:26:10.438450 2026] [security2:error] [pid 419508:tid 419640] [client 195.49.128.211:50180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XUlcagwCeNbomjVse6wAAAZE"]
[Tue Jul 21 08:26:10.438606 2026] [security2:error] [pid 419508:tid 419640] [client 195.49.128.211:50180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XUlcagwCeNbomjVse6wAAAZE"]
[Tue Jul 21 08:26:10.842417 2026] [security2:error] [pid 418108:tid 418261] [client 20.206.105.145:20242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/inputs.php"] [unique_id "al9XUg0cxofL2J1zwYrMNQAAAR8"]
[Tue Jul 21 08:26:11.348979 2026] [security2:error] [pid 418108:tid 418117] [remote 157.66.26.183:40366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9XUg0cxofL2J1zwYrMLAABGQY"]
[Tue Jul 21 08:26:11.349332 2026] [security2:error] [pid 418108:tid 418255] [client 157.66.26.183:40366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9XUg0cxofL2J1zwYrMLAABGQY"]
[Tue Jul 21 08:26:11.400844 2026] [security2:error] [pid 419508:tid 419644] [client 187.125.243.197:63412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XU1cagwCeNbomjVse_AAAAZU"]
[Tue Jul 21 08:26:11.401213 2026] [security2:error] [pid 419508:tid 419644] [client 187.125.243.197:63412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XU1cagwCeNbomjVse_AAAAZU"]
[Tue Jul 21 08:26:11.810678 2026] [security2:error] [pid 419508:tid 419739] [client 65.21.113.253:37608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XU1cagwCeNbomjVse-gAAAfQ"]
[Tue Jul 21 08:26:11.867124 2026] [security2:error] [pid 418108:tid 418245] [client 223.181.60.88:8448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XUw0cxofL2J1zwYrMOwAAAQ8"]
[Tue Jul 21 08:26:11.867242 2026] [security2:error] [pid 418108:tid 418245] [client 223.181.60.88:8448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XUw0cxofL2J1zwYrMOwAAAQ8"]
[Tue Jul 21 08:26:12.161757 2026] [security2:error] [pid 419508:tid 419522] [remote 8.217.108.67:32416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9XVFcagwCeNbomjVsfEQAB5g0"]
[Tue Jul 21 08:26:12.287332 2026] [security2:error] [pid 419508:tid 419764] [client 103.255.105.130:47019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XVFcagwCeNbomjVsfFAAAAgw"]
[Tue Jul 21 08:26:12.287979 2026] [security2:error] [pid 419508:tid 419764] [client 103.255.105.130:47019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XVFcagwCeNbomjVsfFAAAAgw"]
[Tue Jul 21 08:26:12.606548 2026] [security2:error] [pid 419508:tid 419707] [client 49.13.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9XVFcagwCeNbomjVsfGQAB1GE"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:26:13.058321 2026] [security2:error] [pid 419508:tid 419549] [remote 5.252.52.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexandrevitor1781543539748.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XVVcagwCeNbomjVsfIgACBSg"]
[Tue Jul 21 08:26:13.058455 2026] [security2:error] [pid 419508:tid 419757] [client 5.252.52.249:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alexandrevitor1781543539748.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XVVcagwCeNbomjVsfIgACBSg"]
[Tue Jul 21 08:26:13.073413 2026] [security2:error] [pid 419508:tid 419722] [client 34.38.144.36:62497] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "revistareflexopolitico.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9XVVcagwCeNbomjVsfIwAAAeM"]
[Tue Jul 21 08:26:13.143232 2026] [security2:error] [pid 419508:tid 419509] [remote 103.255.134.61:36744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psooffshore.com.br"] [uri "/wp-login.php"] [unique_id "al9XVFcagwCeNbomjVsfEAABnAA"]
[Tue Jul 21 08:26:13.182794 2026] [security2:error] [pid 418108:tid 418268] [client 49.13.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9XVQ0cxofL2J1zwYrMSwABJmM"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:26:13.358036 2026] [security2:error] [pid 419508:tid 419671] [client 14.245.224.124:54072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XVVcagwCeNbomjVsfLgAAAbA"]
[Tue Jul 21 08:26:13.358202 2026] [security2:error] [pid 419508:tid 419671] [client 14.245.224.124:54072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XVVcagwCeNbomjVsfLgAAAbA"]
[Tue Jul 21 08:26:13.488183 2026] [security2:error] [pid 419508:tid 419748] [client 109.248.148.246:59596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9XVVcagwCeNbomjVsfMQAAAfw"]
[Tue Jul 21 08:26:13.488276 2026] [security2:error] [pid 419508:tid 419748] [client 109.248.148.246:59596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9XVVcagwCeNbomjVsfMQAAAfw"]
[Tue Jul 21 08:26:13.503510 2026] [security2:error] [pid 419508:tid 419687] [client 65.21.113.253:40654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XVVcagwCeNbomjVsfKQAAAcA"]
[Tue Jul 21 08:26:13.583200 2026] [security2:error] [pid 419508:tid 419700] [client 65.21.113.253:37608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XVVcagwCeNbomjVsfJAAAAc0"]
[Tue Jul 21 08:26:13.603651 2026] [security2:error] [pid 418108:tid 418353] [client 20.220.225.223:58929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/term.php"] [unique_id "al9XVQ0cxofL2J1zwYrMUAAAAXs"]
[Tue Jul 21 08:26:13.951343 2026] [security2:error] [pid 419508:tid 419723] [client 34.76.253.85:53197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "patacureshop.siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XVVcagwCeNbomjVsfNgAAAeQ"]
[Tue Jul 21 08:26:14.044341 2026] [security2:error] [pid 419508:tid 419584] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/admin/server_info.php"] [unique_id "al9XVlcagwCeNbomjVsfPQACDEs"]
[Tue Jul 21 08:26:14.086139 2026] [authz_core:error] [pid 418108:tid 418240] [client 34.38.144.36:0] AH01630: client denied by server configuration: /home1/rondo837/public_html/sites/revistareflexopolitico.com.br/xmlrpc.php
[Tue Jul 21 08:26:14.414587 2026] [security2:error] [pid 418108:tid 418326] [client 34.76.253.85:62310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "patacureshop.siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XVg0cxofL2J1zwYrMXAAAAWA"]
[Tue Jul 21 08:26:14.716694 2026] [security2:error] [pid 418108:tid 418149] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XVg0cxofL2J1zwYrMZAABFSY"]
[Tue Jul 21 08:26:14.716864 2026] [security2:error] [pid 418108:tid 418251] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XVg0cxofL2J1zwYrMZAABFSY"]
[Tue Jul 21 08:26:14.876195 2026] [security2:error] [pid 418108:tid 418345] [client 34.76.253.85:52157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "patacureshop.siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XVg0cxofL2J1zwYrMZgAAAXM"]
[Tue Jul 21 08:26:15.089796 2026] [security2:error] [pid 418108:tid 418284] [client 152.59.34.51:56087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XVw0cxofL2J1zwYrMaQAAATY"]
[Tue Jul 21 08:26:15.089946 2026] [security2:error] [pid 418108:tid 418284] [client 152.59.34.51:56087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XVw0cxofL2J1zwYrMaQAAATY"]
[Tue Jul 21 08:26:15.330182 2026] [security2:error] [pid 419508:tid 419651] [client 34.76.253.85:54077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "patacureshop.siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XV1cagwCeNbomjVsfTAAAAZw"]
[Tue Jul 21 08:26:15.353997 2026] [security2:error] [pid 418108:tid 418279] [client 20.206.105.145:20215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/av.php"] [unique_id "al9XVw0cxofL2J1zwYrMbAAAATE"]
[Tue Jul 21 08:26:15.767356 2026] [security2:error] [pid 418108:tid 418361] [client 34.76.253.85:52242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "patacureshop.siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XVw0cxofL2J1zwYrMcQAAAYM"]
[Tue Jul 21 08:26:15.818156 2026] [security2:error] [pid 419508:tid 419645] [client 5.31.193.106:29959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9XV1cagwCeNbomjVsfVAAAAZY"]
[Tue Jul 21 08:26:15.836232 2026] [security2:error] [pid 418108:tid 418138] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XVw0cxofL2J1zwYrMcgABNRs"]
[Tue Jul 21 08:26:15.836487 2026] [security2:error] [pid 418108:tid 418283] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XVw0cxofL2J1zwYrMcgABNRs"]
[Tue Jul 21 08:26:15.855048 2026] [security2:error] [pid 419508:tid 419688] [client 65.21.113.253:37608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XV1cagwCeNbomjVsfUQAAAcE"]
[Tue Jul 21 08:26:15.995038 2026] [security2:error] [pid 419508:tid 419681] [client 103.151.46.103:60154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XV1cagwCeNbomjVsfWwAAAbo"]
[Tue Jul 21 08:26:15.995170 2026] [security2:error] [pid 419508:tid 419681] [client 103.151.46.103:60154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XV1cagwCeNbomjVsfWwAAAbo"]
[Tue Jul 21 08:26:16.090540 2026] [security2:error] [pid 419508:tid 419516] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/server_info.php"] [unique_id "al9XWFcagwCeNbomjVsfXgABtwc"]
[Tue Jul 21 08:26:16.356636 2026] [security2:error] [pid 418108:tid 418241] [client 34.76.253.85:58368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "patacureshop.siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XWA0cxofL2J1zwYrMeQAAAQs"]
[Tue Jul 21 08:26:16.624144 2026] [security2:error] [pid 419508:tid 419763] [client 20.220.225.223:19324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/la.php"] [unique_id "al9XWFcagwCeNbomjVsfaAAAAgs"]
[Tue Jul 21 08:26:16.759353 2026] [security2:error] [pid 419508:tid 419591] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/app_dev.php/_profiler/phpinfo"] [unique_id "al9XWFcagwCeNbomjVsfawACAVI"]
[Tue Jul 21 08:26:16.804659 2026] [security2:error] [pid 418108:tid 418309] [client 34.76.253.85:64232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "patacureshop.siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XWA0cxofL2J1zwYrMfwAAAU8"]
[Tue Jul 21 08:26:16.875995 2026] [security2:error] [pid 419508:tid 419723] [client 202.179.75.202:52540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XWFcagwCeNbomjVsfbQAAAeQ"]
[Tue Jul 21 08:26:16.876098 2026] [security2:error] [pid 419508:tid 419723] [client 202.179.75.202:52540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XWFcagwCeNbomjVsfbQAAAeQ"]
[Tue Jul 21 08:26:17.002219 2026] [security2:error] [pid 418108:tid 418363] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9XWQ0cxofL2J1zwYrMggAAAYU"]
[Tue Jul 21 08:26:17.269135 2026] [security2:error] [pid 419508:tid 419642] [client 34.76.253.85:52232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "patacureshop.siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XWVcagwCeNbomjVsfdwAAAZM"]
[Tue Jul 21 08:26:17.277644 2026] [security2:error] [pid 419508:tid 419670] [client 20.206.105.145:20217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/classwithtostring.php"] [unique_id "al9XWVcagwCeNbomjVsfegAAAa8"]
[Tue Jul 21 08:26:17.297420 2026] [security2:error] [pid 418108:tid 418248] [client 143.244.57.90:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XWQ0cxofL2J1zwYrMjAAAARI"]
[Tue Jul 21 08:26:17.360830 2026] [security2:error] [pid 419508:tid 419587] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/test.php"] [unique_id "al9XWVcagwCeNbomjVsffAACCE4"]
[Tue Jul 21 08:26:17.558603 2026] [authz_core:error] [pid 418108:tid 418310] [client 34.38.144.36:58630] AH01630: client denied by server configuration: /home1/rondo837/public_html/sites/revistareflexopolitico.com.br/xmlrpc.php
[Tue Jul 21 08:26:17.739169 2026] [security2:error] [pid 419508:tid 419728] [client 34.76.253.85:50444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "patacureshop.siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XWVcagwCeNbomjVsfhQAAAek"]
[Tue Jul 21 08:26:17.766832 2026] [security2:error] [pid 418108:tid 418256] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9XWQ0cxofL2J1zwYrMkgAAARo"]
[Tue Jul 21 08:26:17.773254 2026] [security2:error] [pid 419508:tid 419738] [client 61.1.167.83:58738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XWVcagwCeNbomjVsfiQAAAfM"]
[Tue Jul 21 08:26:17.773405 2026] [security2:error] [pid 419508:tid 419738] [client 61.1.167.83:58738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XWVcagwCeNbomjVsfiQAAAfM"]
[Tue Jul 21 08:26:17.849484 2026] [authz_core:error] [pid 418108:tid 418291] [client 34.38.144.36:58630] AH01630: client denied by server configuration: /home1/rondo837/public_html/sites/revistareflexopolitico.com.br/xmlrpc.php
[Tue Jul 21 08:26:18.034532 2026] [security2:error] [pid 419508:tid 419717] [client 65.21.113.253:37608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XWVcagwCeNbomjVsfhAAAAd4"]
[Tue Jul 21 08:26:18.053336 2026] [security2:error] [pid 419508:tid 419719] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9XWlcagwCeNbomjVsfkwAAAeA"]
[Tue Jul 21 08:26:18.228508 2026] [security2:error] [pid 419508:tid 419724] [client 34.76.253.85:62017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "patacureshop.siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XWlcagwCeNbomjVsfmQAAAeU"]
[Tue Jul 21 08:26:18.306638 2026] [security2:error] [pid 419508:tid 419620] [remote 31.40.206.10:42318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.206.40.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-login.php"] [unique_id "al9XWlcagwCeNbomjVsfnQAB928"]
[Tue Jul 21 08:26:18.339997 2026] [security2:error] [pid 418108:tid 418325] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9XWg0cxofL2J1zwYrMlgAAAV8"]
[Tue Jul 21 08:26:18.587718 2026] [security2:error] [pid 419508:tid 419664] [client 20.220.225.223:19316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9XWlcagwCeNbomjVsfpAAAAak"]
[Tue Jul 21 08:26:18.626943 2026] [security2:error] [pid 419508:tid 419638] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9XWlcagwCeNbomjVsfpgAAAY8"]
[Tue Jul 21 08:26:18.704702 2026] [security2:error] [pid 419508:tid 419677] [client 34.76.253.85:52278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "patacureshop.siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XWlcagwCeNbomjVsfpwAAAbY"]
[Tue Jul 21 08:26:18.879945 2026] [security2:error] [pid 418108:tid 418312] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XWg0cxofL2J1zwYrMnAABUj4"]
[Tue Jul 21 08:26:18.911820 2026] [security2:error] [pid 419508:tid 419673] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9XWlcagwCeNbomjVsfrwAAAbI"]
[Tue Jul 21 08:26:19.196452 2026] [security2:error] [pid 419508:tid 419727] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9XW1cagwCeNbomjVsftQAAAeg"]
[Tue Jul 21 08:26:19.313712 2026] [security2:error] [pid 418108:tid 418343] [client 34.76.253.85:50693] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "patacureshop.siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XWw0cxofL2J1zwYrMngAAAXE"]
[Tue Jul 21 08:26:19.313838 2026] [security2:error] [pid 418108:tid 418343] [client 34.76.253.85:50693] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "patacureshop.siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XWw0cxofL2J1zwYrMngAAAXE"]
[Tue Jul 21 08:26:19.313857 2026] [security2:error] [pid 418108:tid 418343] [client 34.76.253.85:50693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "patacureshop.siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XWw0cxofL2J1zwYrMngAAAXE"]
[Tue Jul 21 08:26:19.480505 2026] [security2:error] [pid 419508:tid 419655] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9XW1cagwCeNbomjVsftwAAAaA"]
[Tue Jul 21 08:26:19.577032 2026] [security2:error] [pid 419508:tid 419708] [client 20.220.225.223:52652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/ah25.php"] [unique_id "al9XW1cagwCeNbomjVsfugAAAdU"]
[Tue Jul 21 08:26:19.766557 2026] [security2:error] [pid 419508:tid 419735] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9XW1cagwCeNbomjVsfwAAAAfA"]
[Tue Jul 21 08:26:19.934868 2026] [security2:error] [pid 419508:tid 419526] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XW1cagwCeNbomjVsfxAABsxE"]
[Tue Jul 21 08:26:19.935050 2026] [security2:error] [pid 419508:tid 419674] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XW1cagwCeNbomjVsfxAABsxE"]
[Tue Jul 21 08:26:19.982784 2026] [security2:error] [pid 419508:tid 419750] [client 65.21.113.253:37608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XW1cagwCeNbomjVsfuAAAAf4"]
[Tue Jul 21 08:26:20.034656 2026] [security2:error] [pid 419508:tid 419704] [client 74.7.230.58:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "italomelobarbosa1782508671509.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9XXFcagwCeNbomjVsfxgAB0XM"]
[Tue Jul 21 08:26:20.044037 2026] [security2:error] [pid 418108:tid 418111] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XXA0cxofL2J1zwYrMqAABLgA"]
[Tue Jul 21 08:26:20.044159 2026] [security2:error] [pid 418108:tid 418276] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XXA0cxofL2J1zwYrMqAABLgA"]
[Tue Jul 21 08:26:20.051335 2026] [security2:error] [pid 419508:tid 419656] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9XXFcagwCeNbomjVsfxwAAAaE"]
[Tue Jul 21 08:26:20.338030 2026] [security2:error] [pid 418108:tid 418359] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9XXA0cxofL2J1zwYrMqQAAAYE"]
[Tue Jul 21 08:26:20.482219 2026] [security2:error] [pid 419508:tid 419753] [client 150.129.202.39:64894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XXFcagwCeNbomjVsf0wAAAgE"]
[Tue Jul 21 08:26:20.482366 2026] [security2:error] [pid 419508:tid 419753] [client 150.129.202.39:64894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XXFcagwCeNbomjVsf0wAAAgE"]
[Tue Jul 21 08:26:20.494600 2026] [security2:error] [pid 418108:tid 418118] [remote 93.123.109.103:0] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "marmorariasolare.com.br"] [uri "/server-info"] [unique_id "al9XXA0cxofL2J1zwYrMrQABMgc"]
[Tue Jul 21 08:26:20.629411 2026] [security2:error] [pid 419508:tid 419664] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9XXFcagwCeNbomjVsf1QAAAak"]
[Tue Jul 21 08:26:20.915960 2026] [security2:error] [pid 418108:tid 418289] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9XXA0cxofL2J1zwYrMtQAAATs"]
[Tue Jul 21 08:26:20.978624 2026] [security2:error] [pid 418108:tid 418241] [client 195.49.128.211:50769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XXA0cxofL2J1zwYrMtgAAAQs"]
[Tue Jul 21 08:26:20.978747 2026] [security2:error] [pid 418108:tid 418241] [client 195.49.128.211:50769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XXA0cxofL2J1zwYrMtgAAAQs"]
[Tue Jul 21 08:26:21.058620 2026] [security2:error] [pid 418108:tid 418181] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/server-info.php"] [unique_id "al9XXQ0cxofL2J1zwYrMtwABI0Y"]
[Tue Jul 21 08:26:21.199154 2026] [security2:error] [pid 418108:tid 418260] [client 20.220.225.223:19653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9XXQ0cxofL2J1zwYrMuAAAAR4"]
[Tue Jul 21 08:26:21.201048 2026] [security2:error] [pid 419508:tid 419739] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9XXVcagwCeNbomjVsf4gAAAfQ"]
[Tue Jul 21 08:26:21.484401 2026] [security2:error] [pid 419508:tid 419649] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9XXVcagwCeNbomjVsf6QAAAZo"]
[Tue Jul 21 08:26:21.711114 2026] [security2:error] [pid 419508:tid 419721] [client 117.213.202.34:58231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XXFcagwCeNbomjVsf2AAAAeI"]
[Tue Jul 21 08:26:21.711245 2026] [security2:error] [pid 419508:tid 419721] [client 117.213.202.34:58231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XXFcagwCeNbomjVsf2AAAAeI"]
[Tue Jul 21 08:26:21.733833 2026] [security2:error] [pid 419508:tid 419701] [client 20.197.192.193:6003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/kua.php"] [unique_id "al9XXVcagwCeNbomjVsf7gAAAc4"]
[Tue Jul 21 08:26:21.775998 2026] [security2:error] [pid 419508:tid 419713] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9XXVcagwCeNbomjVsf8wAAAdo"]
[Tue Jul 21 08:26:21.790805 2026] [security2:error] [pid 418108:tid 418302] [client 187.125.243.197:63907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XXQ0cxofL2J1zwYrMvQAAAUg"]
[Tue Jul 21 08:26:21.790950 2026] [security2:error] [pid 418108:tid 418302] [client 187.125.243.197:63907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XXQ0cxofL2J1zwYrMvQAAAUg"]
[Tue Jul 21 08:26:21.826369 2026] [security2:error] [pid 418108:tid 418234] [remote 93.123.109.103:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.109.123.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/secured/phpinfo.php"] [unique_id "al9XXQ0cxofL2J1zwYrMvgABh3s"]
[Tue Jul 21 08:26:22.062237 2026] [security2:error] [pid 418108:tid 418313] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.omaroramapadron1781989710990.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9XXg0cxofL2J1zwYrMwAAAAVM"]
[Tue Jul 21 08:26:22.481143 2026] [security2:error] [pid 419508:tid 419675] [client 65.21.113.253:37608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XXlcagwCeNbomjVsf-AAAAbQ"]
[Tue Jul 21 08:26:22.562714 2026] [security2:error] [pid 419508:tid 419740] [client 223.181.60.88:17569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XXlcagwCeNbomjVsf_gAAAfU"]
[Tue Jul 21 08:26:22.562834 2026] [security2:error] [pid 419508:tid 419740] [client 223.181.60.88:17569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XXlcagwCeNbomjVsf_gAAAfU"]
[Tue Jul 21 08:26:22.986275 2026] [security2:error] [pid 419508:tid 419652] [client 103.255.105.130:64510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XXlcagwCeNbomjVsgBwAAAZ0"]
[Tue Jul 21 08:26:22.986408 2026] [security2:error] [pid 419508:tid 419652] [client 103.255.105.130:64510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XXlcagwCeNbomjVsgBwAAAZ0"]
[Tue Jul 21 08:26:23.094953 2026] [security2:error] [pid 419508:tid 419653] [client 152.59.34.51:50006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XX1cagwCeNbomjVsgCgAAAZ4"]
[Tue Jul 21 08:26:23.095036 2026] [security2:error] [pid 419508:tid 419653] [client 152.59.34.51:50006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XX1cagwCeNbomjVsgCgAAAZ4"]
[Tue Jul 21 08:26:23.414379 2026] [security2:error] [pid 418108:tid 418158] [remote 45.90.123.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "printcom.com.br"] [uri "/wp-login.php"] [unique_id "al9XXw0cxofL2J1zwYrM0QABRC8"]
[Tue Jul 21 08:26:23.622919 2026] [security2:error] [pid 419508:tid 419762] [client 49.144.66.253:30911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XX1cagwCeNbomjVsgEAAAAgo"]
[Tue Jul 21 08:26:23.623094 2026] [security2:error] [pid 419508:tid 419762] [client 49.144.66.253:30911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XX1cagwCeNbomjVsgEAAAAgo"]
[Tue Jul 21 08:26:23.897948 2026] [security2:error] [pid 419508:tid 419713] [client 20.220.225.223:19689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/inso.php"] [unique_id "al9XX1cagwCeNbomjVsgHAAAAdo"]
[Tue Jul 21 08:26:23.963372 2026] [security2:error] [pid 419508:tid 419725] [client 14.245.224.124:54557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XX1cagwCeNbomjVsgHQAAAeY"]
[Tue Jul 21 08:26:23.963500 2026] [security2:error] [pid 419508:tid 419725] [client 14.245.224.124:54557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XX1cagwCeNbomjVsgHQAAAeY"]
[Tue Jul 21 08:26:24.508826 2026] [security2:error] [pid 419508:tid 419714] [client 65.21.113.253:37608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XYFcagwCeNbomjVsgHwAAAds"]
[Tue Jul 21 08:26:24.663823 2026] [security2:error] [pid 419508:tid 419510] [remote 57.141.18.11:51874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9XYFcagwCeNbomjVsgLgAB3AE"]
[Tue Jul 21 08:26:24.814102 2026] [security2:error] [pid 419508:tid 419673] [client 122.10.17.49:45074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/index.php/User/doLogin"] [unique_id "al9XX1cagwCeNbomjVsgFwAAAbI"]
[Tue Jul 21 08:26:25.002032 2026] [security2:error] [pid 419508:tid 419518] [remote 69.171.234.4:47916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9XYFcagwCeNbomjVsgMAABqgk"]
[Tue Jul 21 08:26:25.094857 2026] [security2:error] [pid 419508:tid 419761] [client 122.10.17.49:45220] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "okdbrasil.com.br"] [uri "/"] [unique_id "al9XYVcagwCeNbomjVsgOgAAAgk"]
[Tue Jul 21 08:26:25.379562 2026] [security2:error] [pid 418108:tid 418112] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XYQ0cxofL2J1zwYrM3wABPAE"]
[Tue Jul 21 08:26:25.379741 2026] [security2:error] [pid 418108:tid 418290] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XYQ0cxofL2J1zwYrM3wABPAE"]
[Tue Jul 21 08:26:25.380248 2026] [security2:error] [pid 419508:tid 419734] [client 65.21.113.253:44742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XYFcagwCeNbomjVsgNwAAAe8"]
[Tue Jul 21 08:26:25.481873 2026] [security2:error] [pid 419508:tid 419700] [client 122.10.17.49:44992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "union select md5(999999999) as id from"] [severity "CRITICAL"] [tag "SQLi"] [hostname "okdbrasil.com.br"] [uri "/upgrade/detail.jsp/login/LoginSSO.jsp"] [unique_id "al9XYVcagwCeNbomjVsgQgAAAc0"]
[Tue Jul 21 08:26:25.511976 2026] [security2:error] [pid 419508:tid 419697] [client 20.206.105.145:20194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9XYVcagwCeNbomjVsgQwAAAco"]
[Tue Jul 21 08:26:25.989422 2026] [security2:error] [pid 419508:tid 419726] [client 122.10.17.49:44996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:fileNames[]. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:fileNames[]"] [severity "CRITICAL"] [hostname "okdbrasil.com.br"] [uri "/export/classroom-course-statistics"] [unique_id "al9XYVcagwCeNbomjVsgTgAAAec"]
[Tue Jul 21 08:26:25.990665 2026] [security2:error] [pid 419508:tid 419661] [client 122.10.17.49:45182] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "okdbrasil.com.br"] [uri "/_vti_bin/shtml.exe/_vti_rpc"] [unique_id "al9XYVcagwCeNbomjVsgTwAAAaY"]
[Tue Jul 21 08:26:26.115715 2026] [security2:error] [pid 419508:tid 419718] [client 122.10.17.49:45052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/public/index.php"] [unique_id "al9XYlcagwCeNbomjVsgUgAAAd8"]
[Tue Jul 21 08:26:26.490023 2026] [security2:error] [pid 419508:tid 419749] [client 122.10.17.49:44992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/wp-content/plugins/dhtmlxspreadsheet/codebase/spreadsheet.php"] [unique_id "al9XYlcagwCeNbomjVsgWwAAAf0"]
[Tue Jul 21 08:26:26.508536 2026] [security2:error] [pid 418108:tid 418311] [client 122.10.17.49:45400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/wp-content/plugins/wp-ecommerce-shop-styling/includes/dompdf/dompdf.php"] [unique_id "al9XYg0cxofL2J1zwYrM5QAAAVE"]
[Tue Jul 21 08:26:26.545018 2026] [security2:error] [pid 419508:tid 419551] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XYlcagwCeNbomjVsgXgABryo"]
[Tue Jul 21 08:26:26.545184 2026] [security2:error] [pid 419508:tid 419670] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XYlcagwCeNbomjVsgXgABryo"]
[Tue Jul 21 08:26:26.710438 2026] [security2:error] [pid 419508:tid 419717] [client 122.10.17.49:44996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/index.php"] [unique_id "al9XYlcagwCeNbomjVsgYgAAAd4"]
[Tue Jul 21 08:26:26.762776 2026] [security2:error] [pid 419508:tid 419706] [client 122.10.17.49:45372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/wp-content/plugins/abstract-submission/dompdf-0.5.1/dompdf.php"] [unique_id "al9XYlcagwCeNbomjVsgYwAAAdM"]
[Tue Jul 21 08:26:27.157535 2026] [security2:error] [pid 419508:tid 419565] [remote 72.167.132.114:40892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9XY1cagwCeNbomjVsgbgAB1zg"]
[Tue Jul 21 08:26:27.268989 2026] [security2:error] [pid 419508:tid 419735] [client 122.10.17.49:45138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "okdbrasil.com.br"] [uri "/axis2-admin/login"] [unique_id "al9XY1cagwCeNbomjVsgcQAAAfA"]
[Tue Jul 21 08:26:27.353858 2026] [security2:error] [pid 418108:tid 418365] [client 20.220.225.223:19667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/wpx.php"] [unique_id "al9XYw0cxofL2J1zwYrM8AAAAYc"]
[Tue Jul 21 08:26:27.530586 2026] [security2:error] [pid 419508:tid 419656] [client 122.10.17.49:45380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/wp-content/plugins/blogtopdf/dompdf/dompdf.php"] [unique_id "al9XY1cagwCeNbomjVsgeQAAAaE"]
[Tue Jul 21 08:26:27.532454 2026] [security2:error] [pid 419508:tid 419651] [client 122.10.17.49:45132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "okdbrasil.com.br"] [uri "/index.php"] [unique_id "al9XY1cagwCeNbomjVsgfAAAAZw"]
[Tue Jul 21 08:26:27.627579 2026] [security2:error] [pid 419508:tid 419727] [client 65.21.113.253:44742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XY1cagwCeNbomjVsgbwAAAeg"]
[Tue Jul 21 08:26:27.851486 2026] [security2:error] [pid 418108:tid 418272] [client 122.10.17.49:45048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:ostype. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:ostype"] [severity "CRITICAL"] [hostname "okdbrasil.com.br"] [uri "/vpn/user/download/client"] [unique_id "al9XYw0cxofL2J1zwYrM-AAAASo"]
[Tue Jul 21 08:26:27.854475 2026] [security2:error] [pid 418108:tid 418358] [client 20.220.225.223:58938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/8.php"] [unique_id "al9XYw0cxofL2J1zwYrM-QAAAYA"]
[Tue Jul 21 08:26:27.905414 2026] [security2:error] [pid 419508:tid 419738] [client 202.179.75.202:37102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XY1cagwCeNbomjVsgggAAAfM"]
[Tue Jul 21 08:26:27.905515 2026] [security2:error] [pid 419508:tid 419738] [client 202.179.75.202:37102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XY1cagwCeNbomjVsgggAAAfM"]
[Tue Jul 21 08:26:28.164975 2026] [security2:error] [pid 419508:tid 419700] [client 122.10.17.49:52220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/backupmgt/localJob.php"] [unique_id "al9XZFcagwCeNbomjVsgiwAAAc0"]
[Tue Jul 21 08:26:28.482591 2026] [security2:error] [pid 419508:tid 419705] [client 122.10.17.49:45024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "okdbrasil.com.br"] [uri "/zentao/user-login.html"] [unique_id "al9XZFcagwCeNbomjVsgkwAAAdI"], referer: https://okdbrasil.com.br/zentao/user-login.html
[Tue Jul 21 08:26:28.667631 2026] [security2:error] [pid 418108:tid 418319] [client 103.151.46.103:60635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XZA0cxofL2J1zwYrNBQAAAVk"]
[Tue Jul 21 08:26:28.668270 2026] [security2:error] [pid 418108:tid 418319] [client 103.151.46.103:60635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XZA0cxofL2J1zwYrNBQAAAVk"]
[Tue Jul 21 08:26:29.132454 2026] [security2:error] [pid 418108:tid 418356] [client 122.10.17.49:45478] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "okdbrasil.com.br"] [uri "/weaver/org.apache.xmlrpc.webserver.XmlRpcServlet"] [unique_id "al9XZQ0cxofL2J1zwYrNDAAAAX4"]
[Tue Jul 21 08:26:29.188754 2026] [security2:error] [pid 419508:tid 419739] [client 122.10.17.49:45586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/bitrix/rk.php"] [unique_id "al9XZVcagwCeNbomjVsgrQAAAfQ"]
[Tue Jul 21 08:26:29.388627 2026] [security2:error] [pid 418108:tid 418362] [client 122.10.17.49:45584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/bitrix/rk.php"] [unique_id "al9XZQ0cxofL2J1zwYrNDQAAAYQ"]
[Tue Jul 21 08:26:29.405519 2026] [security2:error] [pid 419508:tid 419753] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XZVcagwCeNbomjVsgrwACAWA"]
[Tue Jul 21 08:26:29.627153 2026] [security2:error] [pid 419508:tid 419665] [client 122.10.17.49:45134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "okdbrasil.com.br"] [uri "/axis2/axis2-admin/login"] [unique_id "al9XZVcagwCeNbomjVsgtAAAAao"]
[Tue Jul 21 08:26:29.763065 2026] [security2:error] [pid 419508:tid 419755] [client 122.10.17.49:45574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/bitrix/redirect.php"] [unique_id "al9XZVcagwCeNbomjVsguwAAAgM"]
[Tue Jul 21 08:26:29.765418 2026] [security2:error] [pid 419508:tid 419649] [client 122.10.17.49:44994] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "okdbrasil.com.br"] [uri "/_vti_bin/shtml.dll/_vti_rpc"] [unique_id "al9XZVcagwCeNbomjVsgvAAAAZo"]
[Tue Jul 21 08:26:29.773589 2026] [security2:error] [pid 419508:tid 419671] [client 122.10.17.49:45110] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "okdbrasil.com.br"] [uri "/WEB_VMS/LEVEL15/"] [unique_id "al9XZVcagwCeNbomjVsgvQAAAbA"]
[Tue Jul 21 08:26:29.774491 2026] [security2:error] [pid 418108:tid 418280] [client 66.187.5.19:50744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "alphax.shop-officialstore.com"] [uri "/.env"] [unique_id "al9XZQ0cxofL2J1zwYrNEgAAATI"]
[Tue Jul 21 08:26:29.877634 2026] [security2:error] [pid 419508:tid 419651] [client 122.10.17.49:45154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/index.php"] [unique_id "al9XZVcagwCeNbomjVsgvwAAAZw"]
[Tue Jul 21 08:26:30.053843 2026] [security2:error] [pid 419508:tid 419735] [client 65.21.113.253:44742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XZVcagwCeNbomjVsgswAAAfA"]
[Tue Jul 21 08:26:30.134575 2026] [security2:error] [pid 418108:tid 418309] [client 66.187.5.19:50744] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "alphax.shop-officialstore.com"] [uri "/.env.local"] [unique_id "al9XZg0cxofL2J1zwYrNGwAAAU8"]
[Tue Jul 21 08:26:30.502411 2026] [security2:error] [pid 418108:tid 418176] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XZg0cxofL2J1zwYrNIQABIUE"]
[Tue Jul 21 08:26:30.502544 2026] [security2:error] [pid 418108:tid 418263] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XZg0cxofL2J1zwYrNIQABIUE"]
[Tue Jul 21 08:26:30.517206 2026] [security2:error] [pid 419508:tid 419562] [remote 54.38.147.228:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "compranawebprodutos.com"] [uri "/robots.txt"] [unique_id "al9XZlcagwCeNbomjVsgyQAB_jU"]
[Tue Jul 21 08:26:30.517450 2026] [security2:error] [pid 419508:tid 419750] [client 54.38.147.228:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "compranawebprodutos.com"] [uri "/robots.txt"] [unique_id "al9XZlcagwCeNbomjVsgyQAB_jU"]
[Tue Jul 21 08:26:30.576191 2026] [security2:error] [pid 419508:tid 419660] [client 213.152.186.163:43534] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9XZlcagwCeNbomjVsgywAAAaU"]
[Tue Jul 21 08:26:30.576304 2026] [security2:error] [pid 419508:tid 419660] [client 213.152.186.163:43534] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9XZlcagwCeNbomjVsgywAAAaU"]
[Tue Jul 21 08:26:30.576325 2026] [security2:error] [pid 419508:tid 419660] [client 213.152.186.163:43534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9XZlcagwCeNbomjVsgywAAAaU"]
[Tue Jul 21 08:26:30.603845 2026] [security2:error] [pid 418108:tid 418198] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XZg0cxofL2J1zwYrNIwABVVc"]
[Tue Jul 21 08:26:30.604076 2026] [security2:error] [pid 418108:tid 418315] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XZg0cxofL2J1zwYrNIwABVVc"]
[Tue Jul 21 08:26:30.757719 2026] [security2:error] [pid 418108:tid 418273] [client 61.1.167.83:59276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XZg0cxofL2J1zwYrNJQAAASs"]
[Tue Jul 21 08:26:30.757869 2026] [security2:error] [pid 418108:tid 418273] [client 61.1.167.83:59276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XZg0cxofL2J1zwYrNJQAAASs"]
[Tue Jul 21 08:26:30.983133 2026] [security2:error] [pid 418108:tid 418337] [client 122.10.17.49:45170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/dompdf.php"] [unique_id "al9XZg0cxofL2J1zwYrNJgAAAWs"]
[Tue Jul 21 08:26:30.992672 2026] [core:error] [pid 419508:tid 419536] [remote 74.7.175.169:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:26:30.992691 2026] [core:error] [pid 419508:tid 419536] [remote 74.7.175.169:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:26:30.992942 2026] [security2:error] [pid 419508:tid 419755] [client 74.7.175.169:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.compranawebprodutos.com"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "al9XZlcagwCeNbomjVsg2QACAxs"]
[Tue Jul 21 08:26:30.993971 2026] [security2:error] [pid 418108:tid 418268] [client 150.129.202.39:13086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XZg0cxofL2J1zwYrNJwAAASY"]
[Tue Jul 21 08:26:30.994102 2026] [security2:error] [pid 418108:tid 418268] [client 150.129.202.39:13086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XZg0cxofL2J1zwYrNJwAAASY"]
[Tue Jul 21 08:26:31.023540 2026] [security2:error] [pid 419508:tid 419656] [client 66.187.5.19:50752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alphax.shop-officialstore.com"] [uri "/.env.production"] [unique_id "al9XZ1cagwCeNbomjVsg2gAAAaE"]
[Tue Jul 21 08:26:31.023641 2026] [security2:error] [pid 419508:tid 419656] [client 66.187.5.19:50752] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alphax.shop-officialstore.com"] [uri "/.env.production"] [unique_id "al9XZ1cagwCeNbomjVsg2gAAAaE"]
[Tue Jul 21 08:26:31.106745 2026] [security2:error] [pid 419508:tid 419676] [client 122.10.17.49:45196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/includes/dompdf/dompdf.php"] [unique_id "al9XZ1cagwCeNbomjVsg2wAAAbU"]
[Tue Jul 21 08:26:31.357317 2026] [security2:error] [pid 419508:tid 419752] [client 20.206.105.145:20161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-blog.php"] [unique_id "al9XZ1cagwCeNbomjVsg5wAAAgA"]
[Tue Jul 21 08:26:31.366522 2026] [security2:error] [pid 419508:tid 419683] [client 122.10.17.49:45256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/wp-content/plugins/buddypress-component-stats/lib/dompdf/dompdf.php"] [unique_id "al9XZ1cagwCeNbomjVsg6AAAAbw"]
[Tue Jul 21 08:26:31.469546 2026] [security2:error] [pid 419508:tid 419652] [client 117.213.202.34:58784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XZ1cagwCeNbomjVsg6gAAAZ0"]
[Tue Jul 21 08:26:31.469687 2026] [security2:error] [pid 419508:tid 419652] [client 117.213.202.34:58784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XZ1cagwCeNbomjVsg6gAAAZ0"]
[Tue Jul 21 08:26:31.486467 2026] [security2:error] [pid 418108:tid 418253] [client 141.11.107.74:49379] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.ibericaladrilhos.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9XZw0cxofL2J1zwYrNLQAAARc"]
[Tue Jul 21 08:26:31.497476 2026] [security2:error] [pid 418108:tid 418295] [client 141.11.107.74:49383] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ibericaladrilhos.com.br"] [uri "/"] [unique_id "al9XZw0cxofL2J1zwYrNLgAAAUE"]
[Tue Jul 21 08:26:31.512051 2026] [security2:error] [pid 419508:tid 419714] [client 141.11.107.74:49387] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.ibericaladrilhos.com.br"] [uri "/"] [unique_id "al9XZ1cagwCeNbomjVsg6wAAAds"]
[Tue Jul 21 08:26:31.515878 2026] [security2:error] [pid 419508:tid 419687] [client 141.11.107.74:49392] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.ibericaladrilhos.com.br"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "al9XZ1cagwCeNbomjVsg7AAAAcA"]
[Tue Jul 21 08:26:31.518357 2026] [security2:error] [pid 419508:tid 419712] [client 141.11.107.74:49393] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/"] [unique_id "al9XZ1cagwCeNbomjVsg7QAAAdk"]
[Tue Jul 21 08:26:31.524119 2026] [security2:error] [pid 419508:tid 419750] [client 141.11.107.74:49398] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.ibericaladrilhos.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9XZ1cagwCeNbomjVsg7gAAAf4"]
[Tue Jul 21 08:26:31.596742 2026] [security2:error] [pid 418108:tid 418258] [client 195.49.128.211:51370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XZw0cxofL2J1zwYrNMQAAARw"]
[Tue Jul 21 08:26:31.596863 2026] [security2:error] [pid 418108:tid 418258] [client 195.49.128.211:51370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XZw0cxofL2J1zwYrNMQAAARw"]
[Tue Jul 21 08:26:31.680877 2026] [security2:error] [pid 419508:tid 419698] [client 122.10.17.49:45518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/bitrix/rk.php"] [unique_id "al9XZ1cagwCeNbomjVsg8wAAAcs"]
[Tue Jul 21 08:26:31.685941 2026] [security2:error] [pid 418108:tid 418317] [client 122.10.17.49:45428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/wp-content/plugins/gboutique/library/dompdf/dompdf.php"] [unique_id "al9XZw0cxofL2J1zwYrNMgAAAVc"]
[Tue Jul 21 08:26:31.691964 2026] [security2:error] [pid 419508:tid 419736] [client 122.10.17.49:45570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/bitrix/redirect.php"] [unique_id "al9XZ1cagwCeNbomjVsg9AAAAfE"]
[Tue Jul 21 08:26:31.749754 2026] [security2:error] [pid 419508:tid 419715] [client 122.10.17.49:45558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/bitrix/redirect.php"] [unique_id "al9XZ1cagwCeNbomjVsg9wAAAdw"]
[Tue Jul 21 08:26:31.806985 2026] [security2:error] [pid 418108:tid 418266] [client 20.220.225.223:52649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/red.php"] [unique_id "al9XZw0cxofL2J1zwYrNMwAAASQ"]
[Tue Jul 21 08:26:32.096375 2026] [security2:error] [pid 418108:tid 418329] [client 66.187.5.19:50792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "alphax.shop-officialstore.com"] [uri "/.env.backup"] [unique_id "al9XaA0cxofL2J1zwYrNOQAAAWM"]
[Tue Jul 21 08:26:32.258832 2026] [security2:error] [pid 419508:tid 419684] [client 122.10.17.49:45240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/bitrix/redirect.php"] [unique_id "al9XaFcagwCeNbomjVshCAAAAb0"]
[Tue Jul 21 08:26:32.267186 2026] [security2:error] [pid 418108:tid 418316] [client 66.187.5.19:50792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "alphax.shop-officialstore.com"] [uri "/.env.bak"] [unique_id "al9XaA0cxofL2J1zwYrNPQAAAVY"]
[Tue Jul 21 08:26:32.288761 2026] [security2:error] [pid 419508:tid 419667] [client 187.125.243.197:64412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XaFcagwCeNbomjVshCwAAAaw"]
[Tue Jul 21 08:26:32.288876 2026] [security2:error] [pid 419508:tid 419667] [client 187.125.243.197:64412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XaFcagwCeNbomjVshCwAAAaw"]
[Tue Jul 21 08:26:32.335405 2026] [security2:error] [pid 418108:tid 418362] [client 122.10.17.49:45048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/bitrix/redirect.php"] [unique_id "al9XaA0cxofL2J1zwYrNPgAAAYQ"]
[Tue Jul 21 08:26:32.391086 2026] [security2:error] [pid 419508:tid 419746] [client 122.10.17.49:45510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/bitrix/rk.php"] [unique_id "al9XaFcagwCeNbomjVshEgAAAfo"]
[Tue Jul 21 08:26:32.487344 2026] [security2:error] [pid 419508:tid 419640] [client 122.10.17.49:45014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/bitrix/redirect.php"] [unique_id "al9XaFcagwCeNbomjVshFQAAAZE"]
[Tue Jul 21 08:26:32.522668 2026] [security2:error] [pid 419508:tid 419653] [client 65.21.113.253:44742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XaFcagwCeNbomjVshAAAAAZ4"]
[Tue Jul 21 08:26:32.642404 2026] [security2:error] [pid 419508:tid 419724] [client 20.220.225.223:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/fffm.php"] [unique_id "al9XaFcagwCeNbomjVshGQAAAeU"]
[Tue Jul 21 08:26:32.728852 2026] [security2:error] [pid 418108:tid 418343] [client 152.59.34.51:57038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XaA0cxofL2J1zwYrNRAAAAXE"]
[Tue Jul 21 08:26:32.728988 2026] [security2:error] [pid 418108:tid 418343] [client 152.59.34.51:57038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XaA0cxofL2J1zwYrNRAAAAXE"]
[Tue Jul 21 08:26:32.764210 2026] [security2:error] [pid 418108:tid 418260] [client 122.10.17.49:52302] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "okdbrasil.com.br"] [uri "/tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx"] [unique_id "al9XaA0cxofL2J1zwYrNRQAAAR4"]
[Tue Jul 21 08:26:32.971304 2026] [security2:error] [pid 419508:tid 419686] [client 122.10.17.49:45630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/bitrix/tools/track_mail_click.php"] [unique_id "al9XaFcagwCeNbomjVshHQAAAb8"]
[Tue Jul 21 08:26:33.092587 2026] [security2:error] [pid 419508:tid 419764] [client 122.10.17.49:45282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/index.php"] [unique_id "al9XaVcagwCeNbomjVshIQAAAgw"]
[Tue Jul 21 08:26:33.102326 2026] [security2:error] [pid 418108:tid 418245] [client 66.187.5.19:50840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alphax.shop-officialstore.com"] [uri "/.ssh/id_rsa"] [unique_id "al9XaQ0cxofL2J1zwYrNSgAAAQ8"]
[Tue Jul 21 08:26:33.102437 2026] [security2:error] [pid 418108:tid 418245] [client 66.187.5.19:50840] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alphax.shop-officialstore.com"] [uri "/.ssh/id_rsa"] [unique_id "al9XaQ0cxofL2J1zwYrNSgAAAQ8"]
[Tue Jul 21 08:26:33.224810 2026] [security2:error] [pid 419508:tid 419679] [client 122.10.17.49:45274] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "okdbrasil.com.br"] [uri "/wp-content/plugins/advanced-text-widget/readme.txt"] [unique_id "al9XaVcagwCeNbomjVshJQAAAbg"]
[Tue Jul 21 08:26:33.288163 2026] [security2:error] [pid 419508:tid 419721] [client 223.181.60.88:26327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XaVcagwCeNbomjVshJgAAAeI"]
[Tue Jul 21 08:26:33.288181 2026] [security2:error] [pid 418108:tid 418340] [client 122.10.17.49:45438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/scripts/setup.php"] [unique_id "al9XaQ0cxofL2J1zwYrNTQAAAW4"]
[Tue Jul 21 08:26:33.288913 2026] [security2:error] [pid 419508:tid 419721] [client 223.181.60.88:26327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XaVcagwCeNbomjVshJgAAAeI"]
[Tue Jul 21 08:26:33.395938 2026] [security2:error] [pid 419508:tid 419739] [client 65.21.113.253:44742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XaFcagwCeNbomjVshHwAAAfQ"]
[Tue Jul 21 08:26:33.666524 2026] [security2:error] [pid 419508:tid 419732] [client 122.10.17.49:52226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/wp-content/plugins/web-portal-lite-client-portal-secure-file-sharing-private-messaging/includes/libs/pdf/dompdf.php"] [unique_id "al9XaVcagwCeNbomjVshMAAAAe0"]
[Tue Jul 21 08:26:33.674598 2026] [security2:error] [pid 419508:tid 419661] [client 122.10.17.49:45412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/wp-content/plugins/post-pdf-export/dompdf/dompdf.php"] [unique_id "al9XaVcagwCeNbomjVshMgAAAaY"]
[Tue Jul 21 08:26:33.677769 2026] [security2:error] [pid 419508:tid 419649] [client 66.187.5.19:50846] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "alphax.shop-officialstore.com"] [uri "/.ssh/id_dsa"] [unique_id "al9XaVcagwCeNbomjVshMwAAAZo"]
[Tue Jul 21 08:26:33.738842 2026] [security2:error] [pid 419508:tid 419712] [client 137.97.59.154:14025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XaVcagwCeNbomjVshNQAAAdk"]
[Tue Jul 21 08:26:33.738956 2026] [security2:error] [pid 419508:tid 419712] [client 137.97.59.154:14025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XaVcagwCeNbomjVshNQAAAdk"]
[Tue Jul 21 08:26:33.793172 2026] [security2:error] [pid 419508:tid 419759] [client 20.220.225.223:19267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/berlin.php"] [unique_id "al9XaVcagwCeNbomjVshNwAAAgc"]
[Tue Jul 21 08:26:33.801435 2026] [security2:error] [pid 418108:tid 418291] [client 35.195.0.115:51657] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rgagestaodecondominios.adm.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9XaQ0cxofL2J1zwYrNTwAAAT0"]
[Tue Jul 21 08:26:33.846911 2026] [security2:error] [pid 419508:tid 419724] [client 66.187.5.19:50846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alphax.shop-officialstore.com"] [uri "/.ssh/id_ed25519"] [unique_id "al9XaVcagwCeNbomjVshOgAAAeU"]
[Tue Jul 21 08:26:33.847054 2026] [security2:error] [pid 419508:tid 419724] [client 66.187.5.19:50846] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alphax.shop-officialstore.com"] [uri "/.ssh/id_ed25519"] [unique_id "al9XaVcagwCeNbomjVshOgAAAeU"]
[Tue Jul 21 08:26:33.995410 2026] [security2:error] [pid 419508:tid 419642] [client 89.238.167.134:40444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9XaVcagwCeNbomjVshPgAAAZM"]
[Tue Jul 21 08:26:33.995515 2026] [security2:error] [pid 419508:tid 419642] [client 89.238.167.134:40444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9XaVcagwCeNbomjVshPgAAAZM"]
[Tue Jul 21 08:26:34.030648 2026] [security2:error] [pid 418108:tid 418279] [client 151.63.71.144:63829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Xag0cxofL2J1zwYrNUAAAATE"]
[Tue Jul 21 08:26:34.030781 2026] [security2:error] [pid 418108:tid 418279] [client 151.63.71.144:63829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Xag0cxofL2J1zwYrNUAAAATE"]
[Tue Jul 21 08:26:34.160335 2026] [security2:error] [pid 418108:tid 418263] [client 66.187.5.19:50870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alphax.shop-officialstore.com"] [uri "/config/env.js"] [unique_id "al9Xag0cxofL2J1zwYrNUQAAASE"]
[Tue Jul 21 08:26:34.160444 2026] [security2:error] [pid 418108:tid 418263] [client 66.187.5.19:50870] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alphax.shop-officialstore.com"] [uri "/config/env.js"] [unique_id "al9Xag0cxofL2J1zwYrNUQAAASE"]
[Tue Jul 21 08:26:34.184752 2026] [security2:error] [pid 419508:tid 419694] [client 122.10.17.49:45602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/bitrix/rk.php"] [unique_id "al9XalcagwCeNbomjVshRAAAAcc"]
[Tue Jul 21 08:26:34.331141 2026] [security2:error] [pid 419508:tid 419622] [remote 119.195.102.159:40834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9XalcagwCeNbomjVshRgAB6XE"]
[Tue Jul 21 08:26:34.342073 2026] [security2:error] [pid 419508:tid 419692] [client 49.144.66.253:31305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XalcagwCeNbomjVshRwAAAcU"]
[Tue Jul 21 08:26:34.342171 2026] [security2:error] [pid 419508:tid 419692] [client 49.144.66.253:31305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XalcagwCeNbomjVshRwAAAcU"]
[Tue Jul 21 08:26:34.379057 2026] [security2:error] [pid 419508:tid 419706] [client 14.245.224.124:55037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XalcagwCeNbomjVshTQAAAdM"]
[Tue Jul 21 08:26:34.379264 2026] [security2:error] [pid 419508:tid 419706] [client 14.245.224.124:55037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XalcagwCeNbomjVshTQAAAdM"]
[Tue Jul 21 08:26:34.440490 2026] [security2:error] [pid 419508:tid 419674] [client 122.10.17.49:52254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/bitrix/redirect.php"] [unique_id "al9XalcagwCeNbomjVshUAAAAbM"]
[Tue Jul 21 08:26:34.537618 2026] [security2:error] [pid 419508:tid 419673] [client 20.220.225.223:19665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/billur.php"] [unique_id "al9XalcagwCeNbomjVshVAAAAbI"]
[Tue Jul 21 08:26:34.611508 2026] [security2:error] [pid 419508:tid 419736] [client 35.195.0.115:60618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.0.195.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rgagestaodecondominios.adm.br"] [uri "/xmlrpc.php"] [unique_id "al9XalcagwCeNbomjVshVQAAAfE"]
[Tue Jul 21 08:26:34.738148 2026] [security2:error] [pid 419508:tid 419691] [client 185.213.175.37:13852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "azusacorretora.com.br"] [uri "/.env.bak"] [unique_id "al9XalcagwCeNbomjVshVwAAAcQ"]
[Tue Jul 21 08:26:35.176536 2026] [security2:error] [pid 419508:tid 419519] [remote 47.128.34.241:19492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alperembalagens.com.br"] [uri "/registercadastro"] [unique_id "al9Xa1cagwCeNbomjVshYQABwwo"]
[Tue Jul 21 08:26:35.200673 2026] [security2:error] [pid 419508:tid 419732] [client 65.21.113.253:44742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XalcagwCeNbomjVshVgAAAe0"]
[Tue Jul 21 08:26:35.265361 2026] [autoindex:error] [pid 419508:tid 419761] [client 20.206.105.145:20182] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:26:35.278877 2026] [security2:error] [pid 419508:tid 419713] [client 20.206.105.145:20182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Xa1cagwCeNbomjVshZAAAAdo"]
[Tue Jul 21 08:26:35.335024 2026] [security2:error] [pid 419508:tid 419709] [client 122.10.17.49:52246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/wp-content/plugins/advanced-text-widget/advancedtext.php"] [unique_id "al9Xa1cagwCeNbomjVshZQAAAdY"]
[Tue Jul 21 08:26:35.486795 2026] [security2:error] [pid 419508:tid 419750] [client 213.152.186.163:43538] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Xa1cagwCeNbomjVshawAAAf4"]
[Tue Jul 21 08:26:35.486928 2026] [security2:error] [pid 419508:tid 419750] [client 213.152.186.163:43538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Xa1cagwCeNbomjVshawAAAf4"]
[Tue Jul 21 08:26:35.787351 2026] [security2:error] [pid 419508:tid 419596] [remote 72.167.132.114:48052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "formaesplendida.com"] [uri "/wp-login.php"] [unique_id "al9Xa1cagwCeNbomjVshbgAB81c"]
[Tue Jul 21 08:26:35.819400 2026] [security2:error] [pid 419508:tid 419717] [client 66.187.5.19:50896] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "alphax.shop-officialstore.com"] [uri "/web.config"] [unique_id "al9Xa1cagwCeNbomjVshcAAAAd4"]
[Tue Jul 21 08:26:35.982092 2026] [security2:error] [pid 419508:tid 419554] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Xa1cagwCeNbomjVshdgABqS0"]
[Tue Jul 21 08:26:35.982303 2026] [security2:error] [pid 419508:tid 419664] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Xa1cagwCeNbomjVshdgABqS0"]
[Tue Jul 21 08:26:35.987603 2026] [security2:error] [pid 419508:tid 419705] [client 66.187.5.19:50896] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "alphax.shop-officialstore.com"] [uri "/.svn/entries"] [unique_id "al9Xa1cagwCeNbomjVshegAAAdI"]
[Tue Jul 21 08:26:36.013665 2026] [security2:error] [pid 419508:tid 419658] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Xa1cagwCeNbomjVshbwAAAaM"]
[Tue Jul 21 08:26:36.303187 2026] [security2:error] [pid 419508:tid 419632] [remote 57.141.18.125:36940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapb.xml"] [unique_id "al9XbFcagwCeNbomjVshkAABpns"]
[Tue Jul 21 08:26:36.465878 2026] [security2:error] [pid 419508:tid 419741] [client 20.206.105.145:48356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.v2passessoria.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9XbFcagwCeNbomjVshmQAAAfY"]
[Tue Jul 21 08:26:36.868484 2026] [security2:error] [pid 419508:tid 419546] [remote 91.142.222.105:48416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9XbFcagwCeNbomjVshowABsyU"]
[Tue Jul 21 08:26:36.936044 2026] [security2:error] [pid 419508:tid 419672] [client 122.10.17.49:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/general/index/UploadFile.php"] [unique_id "al9XbFcagwCeNbomjVshpQAAAbE"]
[Tue Jul 21 08:26:36.936650 2026] [security2:error] [pid 419508:tid 419658] [client 66.187.5.19:50918] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "alphax.shop-officialstore.com"] [uri "/.git/config"] [unique_id "al9XbFcagwCeNbomjVshpgAAAaM"]
[Tue Jul 21 08:26:36.969703 2026] [security2:error] [pid 418108:tid 418354] [client 20.220.225.223:19309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/mimpi.php"] [unique_id "al9XbA0cxofL2J1zwYrNxgAAAXw"]
[Tue Jul 21 08:26:37.191564 2026] [security2:error] [pid 419508:tid 419647] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XbFcagwCeNbomjVshnwAAAZg"]
[Tue Jul 21 08:26:37.205321 2026] [security2:error] [pid 418108:tid 418243] [client 109.248.148.246:39064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9XbQ0cxofL2J1zwYrOAgAAAQ0"]
[Tue Jul 21 08:26:37.205449 2026] [security2:error] [pid 418108:tid 418243] [client 109.248.148.246:39064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9XbQ0cxofL2J1zwYrOAgAAAQ0"]
[Tue Jul 21 08:26:37.248998 2026] [security2:error] [pid 419508:tid 419518] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XbVcagwCeNbomjVshvAABrAk"]
[Tue Jul 21 08:26:37.249242 2026] [security2:error] [pid 419508:tid 419667] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XbVcagwCeNbomjVshvAABrAk"]
[Tue Jul 21 08:26:37.348855 2026] [security2:error] [pid 419508:tid 419699] [client 103.151.46.103:61131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XbVcagwCeNbomjVshwQAAAcw"]
[Tue Jul 21 08:26:37.349002 2026] [security2:error] [pid 419508:tid 419699] [client 103.151.46.103:61131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XbVcagwCeNbomjVshwQAAAcw"]
[Tue Jul 21 08:26:37.546460 2026] [security2:error] [pid 419508:tid 419759] [client 66.187.5.19:50920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.5.187.66.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphax.shop-officialstore.com"] [uri "/info.php"] [unique_id "al9XbVcagwCeNbomjVshwwAAAgc"]
[Tue Jul 21 08:26:38.091606 2026] [security2:error] [pid 419508:tid 419703] [client 47.128.38.26:11890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivaconcierge.com.br"] [uri "/robots.txt"] [unique_id "al9XblcagwCeNbomjVsh0wAAAdA"]
[Tue Jul 21 08:26:38.172018 2026] [autoindex:error] [pid 419508:tid 419658] [client 87.236.176.161:0] AH01276: Cannot serve directory /home2/jurand34/jurandirdasilvafigue1777856711000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:26:38.432510 2026] [security2:error] [pid 418108:tid 418345] [client 66.187.5.19:50036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.5.187.66.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphax.shop-officialstore.com"] [uri "/test.php"] [unique_id "al9Xbg0cxofL2J1zwYrODAAAAXM"]
[Tue Jul 21 08:26:38.463182 2026] [security2:error] [pid 419508:tid 419627] [remote 148.113.130.86:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "compranawebprodutos.com"] [uri "/"] [unique_id "al9XblcagwCeNbomjVsh2wABknY"]
[Tue Jul 21 08:26:38.463331 2026] [security2:error] [pid 419508:tid 419641] [client 148.113.130.86:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "compranawebprodutos.com"] [uri "/"] [unique_id "al9XblcagwCeNbomjVsh2wABknY"]
[Tue Jul 21 08:26:38.474049 2026] [security2:error] [pid 419508:tid 419739] [client 122.10.17.49:52472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/backupmgt/pre_connect_check.php"] [unique_id "al9XblcagwCeNbomjVsh3QAAAfQ"]
[Tue Jul 21 08:26:38.851638 2026] [security2:error] [pid 418108:tid 418335] [client 122.10.17.49:52464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/lcms/index.php"] [unique_id "al9Xbg0cxofL2J1zwYrOOAAAAWk"]
[Tue Jul 21 08:26:39.018912 2026] [security2:error] [pid 419508:tid 419761] [client 202.179.75.202:47548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Xb1cagwCeNbomjVsh6AAAAgk"]
[Tue Jul 21 08:26:39.019024 2026] [security2:error] [pid 419508:tid 419761] [client 202.179.75.202:47548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Xb1cagwCeNbomjVsh6AAAAgk"]
[Tue Jul 21 08:26:39.598614 2026] [security2:error] [pid 419508:tid 419674] [client 65.21.113.253:58660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Xb1cagwCeNbomjVsh8wAAAbM"]
[Tue Jul 21 08:26:40.071249 2026] [security2:error] [pid 418108:tid 418274] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xbw0cxofL2J1zwYrOPwABLBw"]
[Tue Jul 21 08:26:40.277764 2026] [security2:error] [pid 419508:tid 419701] [client 20.206.105.145:20137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/adminfuns.php"] [unique_id "al9XcFcagwCeNbomjVsiKAAAAc4"]
[Tue Jul 21 08:26:40.305227 2026] [security2:error] [pid 419508:tid 419733] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Xb1cagwCeNbomjVsh_gAAAe4"]
[Tue Jul 21 08:26:40.628866 2026] [security2:error] [pid 419508:tid 419670] [client 35.195.0.115:55952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.0.195.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rgagestaodecondominios.adm.br"] [uri "/xmlrpc.php"] [unique_id "al9XcFcagwCeNbomjVsiOAAAAa8"]
[Tue Jul 21 08:26:40.628968 2026] [security2:error] [pid 419508:tid 419670] [client 35.195.0.115:55952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rgagestaodecondominios.adm.br"] [uri "/xmlrpc.php"] [unique_id "al9XcFcagwCeNbomjVsiOAAAAa8"]
[Tue Jul 21 08:26:41.076148 2026] [security2:error] [pid 419508:tid 419558] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XcVcagwCeNbomjVsiTAAB3zE"]
[Tue Jul 21 08:26:41.076311 2026] [security2:error] [pid 419508:tid 419718] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XcVcagwCeNbomjVsiTAAB3zE"]
[Tue Jul 21 08:26:41.156755 2026] [security2:error] [pid 419508:tid 419707] [client 122.10.17.49:52406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.17.10.122.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "okdbrasil.com.br"] [uri "/images/logo/logo-eoffice.php"] [unique_id "al9XcVcagwCeNbomjVsiUQAAAdQ"]
[Tue Jul 21 08:26:41.162381 2026] [security2:error] [pid 419508:tid 419579] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XcVcagwCeNbomjVsiUAABvUY"]
[Tue Jul 21 08:26:41.162529 2026] [security2:error] [pid 419508:tid 419684] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XcVcagwCeNbomjVsiUAABvUY"]
[Tue Jul 21 08:26:41.767911 2026] [security2:error] [pid 419508:tid 419755] [client 150.129.202.39:12559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XcVcagwCeNbomjVsiaQAAAgM"]
[Tue Jul 21 08:26:41.768062 2026] [security2:error] [pid 419508:tid 419755] [client 150.129.202.39:12559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XcVcagwCeNbomjVsiaQAAAgM"]
[Tue Jul 21 08:26:41.816347 2026] [core:error] [pid 419508:tid 419595] [remote 2.57.122.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:26:41.816365 2026] [core:error] [pid 419508:tid 419595] [remote 2.57.122.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:26:41.914732 2026] [security2:error] [pid 419508:tid 419729] [client 20.206.105.145:20218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/goods.php"] [unique_id "al9XcVcagwCeNbomjVsidAAAAeo"]
[Tue Jul 21 08:26:42.201623 2026] [security2:error] [pid 419508:tid 419722] [client 117.213.202.34:59330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XclcagwCeNbomjVsihAAAAeM"]
[Tue Jul 21 08:26:42.201779 2026] [security2:error] [pid 419508:tid 419722] [client 117.213.202.34:59330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XclcagwCeNbomjVsihAAAAeM"]
[Tue Jul 21 08:26:42.252819 2026] [security2:error] [pid 419508:tid 419714] [client 195.49.128.211:51966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XclcagwCeNbomjVsiiAAAAds"]
[Tue Jul 21 08:26:42.252913 2026] [security2:error] [pid 419508:tid 419714] [client 195.49.128.211:51966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XclcagwCeNbomjVsiiAAAAds"]
[Tue Jul 21 08:26:42.281918 2026] [security2:error] [pid 419508:tid 419685] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XcVcagwCeNbomjVsicAAAAb4"]
[Tue Jul 21 08:26:42.700761 2026] [security2:error] [pid 419508:tid 419741] [client 5.31.193.106:58563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9XclcagwCeNbomjVsiqQAAAfY"]
[Tue Jul 21 08:26:42.785278 2026] [security2:error] [pid 418108:tid 418300] [client 187.125.243.197:64911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Xcg0cxofL2J1zwYrOXQAAAUY"]
[Tue Jul 21 08:26:42.785670 2026] [security2:error] [pid 418108:tid 418300] [client 187.125.243.197:64911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Xcg0cxofL2J1zwYrOXQAAAUY"]
[Tue Jul 21 08:26:42.904891 2026] [security2:error] [pid 419508:tid 419728] [client 61.1.167.83:59792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XclcagwCeNbomjVsi0QAAAek"]
[Tue Jul 21 08:26:42.905041 2026] [security2:error] [pid 419508:tid 419728] [client 61.1.167.83:59792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XclcagwCeNbomjVsi0QAAAek"]
[Tue Jul 21 08:26:43.420284 2026] [security2:error] [pid 419508:tid 419707] [client 152.59.34.51:57523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Xc1cagwCeNbomjVsi5gAAAdQ"]
[Tue Jul 21 08:26:43.420420 2026] [security2:error] [pid 419508:tid 419707] [client 152.59.34.51:57523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Xc1cagwCeNbomjVsi5gAAAdQ"]
[Tue Jul 21 08:26:43.950062 2026] [security2:error] [pid 418108:tid 418359] [client 185.8.106.219:13312] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "houseincorporacoes.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9Xcw0cxofL2J1zwYrOagAAAYE"]
[Tue Jul 21 08:26:44.199616 2026] [security2:error] [pid 419508:tid 419699] [client 14.97.58.74:32823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XdFcagwCeNbomjVsjCwAAAcw"]
[Tue Jul 21 08:26:44.199791 2026] [security2:error] [pid 419508:tid 419699] [client 14.97.58.74:32823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XdFcagwCeNbomjVsjCwAAAcw"]
[Tue Jul 21 08:26:44.256550 2026] [security2:error] [pid 418108:tid 418332] [client 223.181.60.88:8552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XdA0cxofL2J1zwYrOcAAAAWY"]
[Tue Jul 21 08:26:44.257272 2026] [security2:error] [pid 418108:tid 418332] [client 223.181.60.88:8552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XdA0cxofL2J1zwYrOcAAAAWY"]
[Tue Jul 21 08:26:44.310647 2026] [security2:error] [pid 419508:tid 419748] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Xc1cagwCeNbomjVsi9AAAAfw"]
[Tue Jul 21 08:26:44.516356 2026] [security2:error] [pid 418108:tid 418294] [client 20.220.225.223:19659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/dp.php"] [unique_id "al9XdA0cxofL2J1zwYrOdwAAAUA"]
[Tue Jul 21 08:26:44.517518 2026] [security2:error] [pid 418108:tid 418354] [client 185.8.106.219:14326] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "houseincorporacoes.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9XdA0cxofL2J1zwYrOeAAAAXw"]
[Tue Jul 21 08:26:44.740152 2026] [security2:error] [pid 418108:tid 418248] [client 20.220.225.223:58940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/ftde.php"] [unique_id "al9XdA0cxofL2J1zwYrOeQAAARI"]
[Tue Jul 21 08:26:44.878451 2026] [security2:error] [pid 418108:tid 418274] [client 66.187.5.19:50090] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "alphax.shop-officialstore.com"] [uri "/firebase-adminsdk.json"] [unique_id "al9XdA0cxofL2J1zwYrOfwAAASw"]
[Tue Jul 21 08:26:45.025586 2026] [security2:error] [pid 419508:tid 419673] [client 20.65.195.17:38332] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.72"] [uri "/index.cgi"] [unique_id "al9XdVcagwCeNbomjVsjKQAAAbI"]
[Tue Jul 21 08:26:45.209248 2026] [security2:error] [pid 418108:tid 418310] [client 49.144.66.253:31664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XdQ0cxofL2J1zwYrOgQAAAVA"]
[Tue Jul 21 08:26:45.209377 2026] [security2:error] [pid 418108:tid 418310] [client 49.144.66.253:31664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XdQ0cxofL2J1zwYrOgQAAAVA"]
[Tue Jul 21 08:26:45.682742 2026] [security2:error] [pid 418108:tid 418313] [client 14.245.224.124:55516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XdQ0cxofL2J1zwYrOhAAAAVM"]
[Tue Jul 21 08:26:45.682856 2026] [security2:error] [pid 418108:tid 418313] [client 14.245.224.124:55516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XdQ0cxofL2J1zwYrOhAAAAVM"]
[Tue Jul 21 08:26:45.952530 2026] [security2:error] [pid 419508:tid 419706] [client 185.8.106.219:13328] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.houseincorporacoes.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9XdVcagwCeNbomjVsjQwAAAdM"]
[Tue Jul 21 08:26:46.081334 2026] [security2:error] [pid 419508:tid 419649] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XdVcagwCeNbomjVsjOwAAAZo"]
[Tue Jul 21 08:26:46.117008 2026] [security2:error] [pid 419508:tid 419748] [client 20.206.105.145:20184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/ms-edit.php"] [unique_id "al9XdlcagwCeNbomjVsjRwAAAfw"]
[Tue Jul 21 08:26:46.172705 2026] [security2:error] [pid 419508:tid 419763] [client 20.220.225.223:19652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/bootstrap.php"] [unique_id "al9XdlcagwCeNbomjVsjSAAAAgs"]
[Tue Jul 21 08:26:46.265897 2026] [security2:error] [pid 419508:tid 419705] [client 66.187.5.19:50124] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "alphax.shop-officialstore.com"] [uri "/appsettings.json"] [unique_id "al9XdlcagwCeNbomjVsjSgAAAdI"]
[Tue Jul 21 08:26:46.608763 2026] [security2:error] [pid 419508:tid 419555] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XdlcagwCeNbomjVsjUQAB9S4"]
[Tue Jul 21 08:26:46.608987 2026] [security2:error] [pid 419508:tid 419740] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XdlcagwCeNbomjVsjUQAB9S4"]
[Tue Jul 21 08:26:46.777751 2026] [security2:error] [pid 419508:tid 419720] [client 185.8.106.219:13330] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "houseincorporacoes.com"] [uri "/"] [unique_id "al9XdlcagwCeNbomjVsjUgAAAeE"]
[Tue Jul 21 08:26:47.377999 2026] [core:alert] [pid 419508:tid 419733] [client 57.141.18.0:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:26:47.937716 2026] [security2:error] [pid 418108:tid 418182] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xdw0cxofL2J1zwYrOlgABH0c"]
[Tue Jul 21 08:26:47.937878 2026] [security2:error] [pid 418108:tid 418261] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xdw0cxofL2J1zwYrOlgABH0c"]
[Tue Jul 21 08:26:48.005768 2026] [security2:error] [pid 419508:tid 419766] [client 66.187.5.19:34964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alphax.shop-officialstore.com"] [uri "/api/settings"] [unique_id "al9XeFcagwCeNbomjVsjcQAAAg4"]
[Tue Jul 21 08:26:48.005889 2026] [security2:error] [pid 419508:tid 419766] [client 66.187.5.19:34964] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alphax.shop-officialstore.com"] [uri "/api/settings"] [unique_id "al9XeFcagwCeNbomjVsjcQAAAg4"]
[Tue Jul 21 08:26:48.065674 2026] [security2:error] [pid 419508:tid 419761] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Xd1cagwCeNbomjVsjagAAAgk"]
[Tue Jul 21 08:26:48.126093 2026] [security2:error] [pid 419508:tid 419688] [client 185.213.175.37:43854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "azusacorretora.com.br"] [uri "/wp-content/uploads/2022/04/Design-sem-nome-150x150.png"] [unique_id "al9XeFcagwCeNbomjVsjeQAAAcE"]
[Tue Jul 21 08:26:48.126180 2026] [security2:error] [pid 419508:tid 419688] [client 185.213.175.37:43854] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "azusacorretora.com.br"] [uri "/wp-content/uploads/2022/04/Design-sem-nome-150x150.png"] [unique_id "al9XeFcagwCeNbomjVsjeQAAAcE"]
[Tue Jul 21 08:26:48.288689 2026] [security2:error] [pid 419508:tid 419674] [client 185.213.175.37:43860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XeFcagwCeNbomjVsjeAAAAbM"]
[Tue Jul 21 08:26:48.780428 2026] [security2:error] [pid 419508:tid 419723] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xd1cagwCeNbomjVsjbwAAAeQ"]
[Tue Jul 21 08:26:48.879558 2026] [security2:error] [pid 419508:tid 419725] [client 47.128.34.87:47394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oficialwebsite.com.br"] [uri "/robots.txt"] [unique_id "al9XeFcagwCeNbomjVsjjQAAAeY"]
[Tue Jul 21 08:26:49.209592 2026] [security2:error] [pid 419508:tid 419675] [client 20.220.225.223:19295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/wp-editor.php"] [unique_id "al9XeVcagwCeNbomjVsjmAAAAbQ"]
[Tue Jul 21 08:26:49.242765 2026] [security2:error] [pid 419508:tid 419656] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9XeVcagwCeNbomjVsjmQAAAaE"]
[Tue Jul 21 08:26:49.670345 2026] [security2:error] [pid 419508:tid 419753] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9XeVcagwCeNbomjVsjowAAAgE"]
[Tue Jul 21 08:26:50.043702 2026] [security2:error] [pid 419508:tid 419658] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XeVcagwCeNbomjVsjogAAAaM"]
[Tue Jul 21 08:26:50.051187 2026] [security2:error] [pid 419508:tid 419684] [client 202.179.75.202:53872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XelcagwCeNbomjVsjpwAAAb0"]
[Tue Jul 21 08:26:50.051313 2026] [security2:error] [pid 419508:tid 419684] [client 202.179.75.202:53872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XelcagwCeNbomjVsjpwAAAb0"]
[Tue Jul 21 08:26:50.091616 2026] [fcgid:warn] [pid 419508:tid 419741] (70014)End of file found: [client 66.132.172.141:52356] mod_fcgid: can't get data from http client
[Tue Jul 21 08:26:50.169564 2026] [security2:error] [pid 418108:tid 418276] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Xeg0cxofL2J1zwYrOowAAAS4"]
[Tue Jul 21 08:26:50.600690 2026] [security2:error] [pid 418108:tid 418332] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xeg0cxofL2J1zwYrOpAABZjM"]
[Tue Jul 21 08:26:50.644509 2026] [security2:error] [pid 419508:tid 419760] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9XelcagwCeNbomjVsjuQAAAgg"]
[Tue Jul 21 08:26:51.053626 2026] [security2:error] [pid 419508:tid 419734] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Xe1cagwCeNbomjVsjwgAAAe8"]
[Tue Jul 21 08:26:51.389946 2026] [security2:error] [pid 418108:tid 418339] [client 20.220.225.223:19307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/cro.php"] [unique_id "al9Xew0cxofL2J1zwYrOqwAAAW0"]
[Tue Jul 21 08:26:51.451403 2026] [security2:error] [pid 418108:tid 418249] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Xew0cxofL2J1zwYrOrAAAARM"]
[Tue Jul 21 08:26:51.597373 2026] [security2:error] [pid 419508:tid 419557] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xe1cagwCeNbomjVsj0AAB9DA"]
[Tue Jul 21 08:26:51.597522 2026] [security2:error] [pid 419508:tid 419739] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xe1cagwCeNbomjVsj0AAB9DA"]
[Tue Jul 21 08:26:51.651605 2026] [security2:error] [pid 418108:tid 418183] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Xew0cxofL2J1zwYrOrgABZ0g"]
[Tue Jul 21 08:26:51.651780 2026] [security2:error] [pid 418108:tid 418333] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Xew0cxofL2J1zwYrOrgABZ0g"]
[Tue Jul 21 08:26:52.010130 2026] [security2:error] [pid 419508:tid 419658] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9XfFcagwCeNbomjVsj2wAAAaM"]
[Tue Jul 21 08:26:52.041611 2026] [security2:error] [pid 419508:tid 419718] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Xe1cagwCeNbomjVsjzgAAAd8"]
[Tue Jul 21 08:26:52.420538 2026] [security2:error] [pid 419508:tid 419727] [client 150.129.202.39:64937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XfFcagwCeNbomjVsj6gAAAeg"]
[Tue Jul 21 08:26:52.420674 2026] [security2:error] [pid 419508:tid 419727] [client 150.129.202.39:64937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XfFcagwCeNbomjVsj6gAAAeg"]
[Tue Jul 21 08:26:52.448994 2026] [security2:error] [pid 419508:tid 419742] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9XfFcagwCeNbomjVsj6wAAAfc"]
[Tue Jul 21 08:26:52.449808 2026] [security2:error] [pid 419508:tid 419683] [client 20.220.225.223:19664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/cron-tab.php"] [unique_id "al9XfFcagwCeNbomjVsj7AAAAbw"]
[Tue Jul 21 08:26:52.762785 2026] [security2:error] [pid 419508:tid 419694] [client 117.213.202.34:59880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XfFcagwCeNbomjVsj8AAAAcc"]
[Tue Jul 21 08:26:52.762941 2026] [security2:error] [pid 419508:tid 419694] [client 117.213.202.34:59880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XfFcagwCeNbomjVsj8AAAAcc"]
[Tue Jul 21 08:26:52.813851 2026] [security2:error] [pid 419508:tid 419725] [client 173.252.95.42:48772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9XfFcagwCeNbomjVsj8gAAAeY"]
[Tue Jul 21 08:26:52.852501 2026] [security2:error] [pid 418108:tid 418365] [client 20.206.105.145:20175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/222.php"] [unique_id "al9XfA0cxofL2J1zwYrOuwAAAYc"]
[Tue Jul 21 08:26:52.874505 2026] [security2:error] [pid 418108:tid 418328] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9XfA0cxofL2J1zwYrOvAAAAWI"]
[Tue Jul 21 08:26:52.959486 2026] [security2:error] [pid 418108:tid 418268] [client 195.49.128.211:52562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XfA0cxofL2J1zwYrOvQAAASY"]
[Tue Jul 21 08:26:52.959602 2026] [security2:error] [pid 418108:tid 418268] [client 195.49.128.211:52562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XfA0cxofL2J1zwYrOvQAAASY"]
[Tue Jul 21 08:26:53.260301 2026] [security2:error] [pid 419508:tid 419682] [client 187.125.243.197:65413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XfVcagwCeNbomjVsj_gAAAbs"]
[Tue Jul 21 08:26:53.260414 2026] [security2:error] [pid 419508:tid 419682] [client 187.125.243.197:65413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XfVcagwCeNbomjVsj_gAAAbs"]
[Tue Jul 21 08:26:53.280710 2026] [security2:error] [pid 419508:tid 419678] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9XfVcagwCeNbomjVsj_wAAAbc"]
[Tue Jul 21 08:26:53.424021 2026] [security2:error] [pid 419508:tid 419713] [client 20.220.225.223:19661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/koiy.php"] [unique_id "al9XfVcagwCeNbomjVskBQAAAdo"]
[Tue Jul 21 08:26:53.521259 2026] [security2:error] [pid 418108:tid 418321] [client 173.252.95.6:48506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9XfQ0cxofL2J1zwYrOwwAAAVs"]
[Tue Jul 21 08:26:53.698124 2026] [security2:error] [pid 418108:tid 418285] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9XfQ0cxofL2J1zwYrOxAAAATc"]
[Tue Jul 21 08:26:53.730076 2026] [security2:error] [pid 419508:tid 419738] [client 74.7.228.20:46434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "adriadnebarbosa.com"] [uri "/robots.txt"] [unique_id "al9XfVcagwCeNbomjVskCQAB8wQ"]
[Tue Jul 21 08:26:53.904032 2026] [security2:error] [pid 419508:tid 419657] [client 74.7.228.20:46434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "adriadnebarbosa.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al9XfVcagwCeNbomjVskEQABogo"], referer: https://adriadnebarbosa.com/robots.txt
[Tue Jul 21 08:26:54.143361 2026] [security2:error] [pid 419508:tid 419660] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9XflcagwCeNbomjVskFgAAAaU"]
[Tue Jul 21 08:26:54.276451 2026] [security2:error] [pid 419508:tid 419750] [client 152.59.34.51:18325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XflcagwCeNbomjVskGgAAAf4"]
[Tue Jul 21 08:26:54.276627 2026] [security2:error] [pid 419508:tid 419750] [client 152.59.34.51:18325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XflcagwCeNbomjVskGgAAAf4"]
[Tue Jul 21 08:26:54.520249 2026] [security2:error] [pid 419508:tid 419674] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XflcagwCeNbomjVskFAAAAbM"]
[Tue Jul 21 08:26:54.652193 2026] [security2:error] [pid 419508:tid 419537] [remote 124.55.178.99:37776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/wp-login.php"] [unique_id "al9XflcagwCeNbomjVskJAAB5hw"]
[Tue Jul 21 08:26:54.757239 2026] [security2:error] [pid 418108:tid 418269] [client 173.252.95.36:34438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Xfg0cxofL2J1zwYrOywAAASc"]
[Tue Jul 21 08:26:54.838128 2026] [security2:error] [pid 419508:tid 419752] [client 61.1.167.83:60302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XflcagwCeNbomjVskKwAAAgA"]
[Tue Jul 21 08:26:54.838227 2026] [security2:error] [pid 419508:tid 419752] [client 61.1.167.83:60302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XflcagwCeNbomjVskKwAAAgA"]
[Tue Jul 21 08:26:54.851605 2026] [security2:error] [pid 419508:tid 419758] [client 111.93.58.162:50133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XflcagwCeNbomjVskLAAAAgY"]
[Tue Jul 21 08:26:54.851753 2026] [security2:error] [pid 419508:tid 419758] [client 111.93.58.162:50133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XflcagwCeNbomjVskLAAAAgY"]
[Tue Jul 21 08:26:55.195542 2026] [autoindex:error] [pid 418108:tid 418367] [client 192.71.2.57:55329] AH01276: Cannot serve directory /home2/italom32/condominiogreenvillage.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:26:55.279400 2026] [security2:error] [pid 419508:tid 419662] [client 223.181.60.88:1506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Xf1cagwCeNbomjVskMgAAAac"]
[Tue Jul 21 08:26:55.279533 2026] [security2:error] [pid 419508:tid 419662] [client 223.181.60.88:1506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Xf1cagwCeNbomjVskMgAAAac"]
[Tue Jul 21 08:26:55.581576 2026] [security2:error] [pid 419508:tid 419699] [client 20.220.225.223:19318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/hp2.php"] [unique_id "al9Xf1cagwCeNbomjVskUgAAAcw"]
[Tue Jul 21 08:26:55.781705 2026] [security2:error] [pid 419508:tid 419711] [client 82.102.18.188:57770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moradanow.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Xf1cagwCeNbomjVskVQAAAdg"]
[Tue Jul 21 08:26:55.922022 2026] [security2:error] [pid 419508:tid 419716] [client 66.187.5.19:35004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alphax.shop-officialstore.com"] [uri "/app/.git/HEAD"] [unique_id "al9Xf1cagwCeNbomjVskWgAAAd0"]
[Tue Jul 21 08:26:55.922108 2026] [security2:error] [pid 419508:tid 419716] [client 66.187.5.19:35004] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "alphax.shop-officialstore.com"] [uri "/app/.git/HEAD"] [unique_id "al9Xf1cagwCeNbomjVskWgAAAd0"]
[Tue Jul 21 08:26:56.182207 2026] [security2:error] [pid 419508:tid 419661] [client 82.102.18.188:62494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moradanow.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XgFcagwCeNbomjVskYAAAAaY"]
[Tue Jul 21 08:26:56.207266 2026] [security2:error] [pid 419508:tid 419765] [client 14.245.224.124:56000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XgFcagwCeNbomjVskYQAAAg0"]
[Tue Jul 21 08:26:56.207402 2026] [security2:error] [pid 419508:tid 419765] [client 14.245.224.124:56000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XgFcagwCeNbomjVskYQAAAg0"]
[Tue Jul 21 08:26:56.235153 2026] [security2:error] [pid 419508:tid 419749] [client 49.144.66.253:32133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XgFcagwCeNbomjVskYwAAAf0"]
[Tue Jul 21 08:26:56.235251 2026] [security2:error] [pid 419508:tid 419749] [client 49.144.66.253:32133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XgFcagwCeNbomjVskYwAAAf0"]
[Tue Jul 21 08:26:56.954883 2026] [security2:error] [pid 419508:tid 419686] [client 82.102.18.188:57796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moradanow.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9XgFcagwCeNbomjVskcwAAAb8"]
[Tue Jul 21 08:26:56.956490 2026] [security2:error] [pid 419508:tid 419758] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XgFcagwCeNbomjVskaAAAAgY"]
[Tue Jul 21 08:26:57.280317 2026] [security2:error] [pid 419508:tid 419565] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XgVcagwCeNbomjVskfAACCTg"]
[Tue Jul 21 08:26:57.280518 2026] [security2:error] [pid 419508:tid 419761] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XgVcagwCeNbomjVskfAACCTg"]
[Tue Jul 21 08:26:57.350206 2026] [security2:error] [pid 419508:tid 419718] [client 82.102.18.188:7085] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moradanow.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9XgVcagwCeNbomjVskfgAAAd8"]
[Tue Jul 21 08:26:57.446489 2026] [security2:error] [pid 419508:tid 419657] [client 20.206.105.145:20257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9XgVcagwCeNbomjVskhgAAAaI"]
[Tue Jul 21 08:26:57.513221 2026] [security2:error] [pid 419508:tid 419671] [client 20.220.225.223:19277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/hp3.php"] [unique_id "al9XgVcagwCeNbomjVskiAAAAbA"]
[Tue Jul 21 08:26:57.744418 2026] [security2:error] [pid 419508:tid 419708] [client 82.102.18.188:57814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moradanow.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9XgVcagwCeNbomjVskiwAAAdU"]
[Tue Jul 21 08:26:58.128202 2026] [security2:error] [pid 419508:tid 419709] [client 82.102.18.188:57818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moradanow.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9XglcagwCeNbomjVsklQAAAdY"]
[Tue Jul 21 08:26:58.246131 2026] [security2:error] [pid 418108:tid 418205] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Xgg0cxofL2J1zwYrO6AABPV4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:58.247590 2026] [security2:error] [pid 419508:tid 419532] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9XglcagwCeNbomjVsklAACCBc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:58.524028 2026] [security2:error] [pid 419508:tid 419666] [client 82.102.18.188:57824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moradanow.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9XglcagwCeNbomjVsknQAAAas"]
[Tue Jul 21 08:26:58.621890 2026] [security2:error] [pid 418108:tid 418166] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xgg0cxofL2J1zwYrO8QABMjc"]
[Tue Jul 21 08:26:58.622036 2026] [security2:error] [pid 418108:tid 418280] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xgg0cxofL2J1zwYrO8QABMjc"]
[Tue Jul 21 08:26:58.772709 2026] [security2:error] [pid 419508:tid 419620] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9XglcagwCeNbomjVskowAB528"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:58.907232 2026] [security2:error] [pid 419508:tid 419663] [client 82.102.18.188:57838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moradanow.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9XglcagwCeNbomjVskpAAAAag"]
[Tue Jul 21 08:26:58.941206 2026] [security2:error] [pid 419508:tid 419734] [client 195.49.128.211:61584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XglcagwCeNbomjVskpQAAAe8"]
[Tue Jul 21 08:26:58.941357 2026] [security2:error] [pid 419508:tid 419734] [client 195.49.128.211:61584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XglcagwCeNbomjVskpQAAAe8"]
[Tue Jul 21 08:26:58.977080 2026] [security2:error] [pid 419508:tid 419550] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9XglcagwCeNbomjVskpgACDik"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:59.011331 2026] [security2:error] [pid 419508:tid 419641] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XglcagwCeNbomjVsknwAAAZI"]
[Tue Jul 21 08:26:59.020307 2026] [security2:error] [pid 419508:tid 419575] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Xg1cagwCeNbomjVskrAABnkI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:59.179967 2026] [security2:error] [pid 419508:tid 419561] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Xg1cagwCeNbomjVskrwABtjQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:59.237077 2026] [security2:error] [pid 418108:tid 418221] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Xgw0cxofL2J1zwYrO9AABcG4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:59.244543 2026] [security2:error] [pid 418108:tid 418113] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Xgg0cxofL2J1zwYrO6QABcAI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:59.248781 2026] [security2:error] [pid 419508:tid 419628] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9XglcagwCeNbomjVskkwAB2Hc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:59.298221 2026] [security2:error] [pid 418108:tid 418263] [client 82.102.18.188:57844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moradanow.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Xgw0cxofL2J1zwYrO9QAAASE"]
[Tue Jul 21 08:26:59.368740 2026] [security2:error] [pid 419508:tid 419697] [client 103.151.46.103:62116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Xg1cagwCeNbomjVsksAAAAco"]
[Tue Jul 21 08:26:59.369421 2026] [security2:error] [pid 419508:tid 419697] [client 103.151.46.103:62116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Xg1cagwCeNbomjVsksAAAAco"]
[Tue Jul 21 08:26:59.402625 2026] [security2:error] [pid 419508:tid 419622] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Xg1cagwCeNbomjVsksQAB-3E"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:59.652413 2026] [security2:error] [pid 418108:tid 418308] [client 20.220.225.223:19688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/aa1.php"] [unique_id "al9Xgw0cxofL2J1zwYrO-AAAAU4"]
[Tue Jul 21 08:26:59.692802 2026] [security2:error] [pid 419508:tid 419699] [client 82.102.18.188:25794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moradanow.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Xg1cagwCeNbomjVskuAAAAcw"]
[Tue Jul 21 08:26:59.758897 2026] [security2:error] [pid 419508:tid 419578] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Xg1cagwCeNbomjVskugABuEU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:59.760761 2026] [security2:error] [pid 419508:tid 419613] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Xg1cagwCeNbomjVskuwAB3Gg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:59.773514 2026] [security2:error] [pid 418108:tid 418140] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Xgw0cxofL2J1zwYrO-QABax0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:59.844206 2026] [security2:error] [pid 419508:tid 419638] [client 5.31.193.106:58722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Xg1cagwCeNbomjVskuQAAAY8"]
[Tue Jul 21 08:26:59.935594 2026] [security2:error] [pid 419508:tid 419538] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Xg1cagwCeNbomjVskwQABxR0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:59.961752 2026] [security2:error] [pid 418108:tid 418135] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Xgw0cxofL2J1zwYrO-gABZRg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:59.963961 2026] [security2:error] [pid 418108:tid 418226] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Xgw0cxofL2J1zwYrO-wABU3M"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:26:59.977441 2026] [security2:error] [pid 419508:tid 419536] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Xg1cagwCeNbomjVskwgAB4xs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:27:00.077894 2026] [security2:error] [pid 419508:tid 419730] [client 82.102.18.188:57854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moradanow.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9XhFcagwCeNbomjVskyQAAAes"]
[Tue Jul 21 08:27:00.164116 2026] [security2:error] [pid 419508:tid 419608] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9XhFcagwCeNbomjVskywABs2M"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:27:00.177733 2026] [security2:error] [pid 419508:tid 419517] [remote 41.128.143.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.143.128.41.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9XhFcagwCeNbomjVskzAAB1gg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:27:00.474213 2026] [security2:error] [pid 419508:tid 419665] [client 82.102.18.188:50249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moradanow.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9XhFcagwCeNbomjVskzwAAAao"]
[Tue Jul 21 08:27:00.577409 2026] [security2:error] [pid 419508:tid 419718] [client 20.220.225.223:19308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/acew67.php"] [unique_id "al9XhFcagwCeNbomjVsk1QAAAd8"]
[Tue Jul 21 08:27:00.793696 2026] [autoindex:error] [pid 419508:tid 419717] [client 20.206.105.145:20234] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:27:00.850733 2026] [security2:error] [pid 419508:tid 419734] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XhFcagwCeNbomjVskzQAAAe8"]
[Tue Jul 21 08:27:00.862188 2026] [security2:error] [pid 419508:tid 419639] [client 82.102.18.188:57874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moradanow.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9XhFcagwCeNbomjVsk3QAAAZA"]
[Tue Jul 21 08:27:01.142625 2026] [security2:error] [pid 419508:tid 419688] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XhVcagwCeNbomjVsk4QABwQ8"]
[Tue Jul 21 08:27:01.233467 2026] [security2:error] [pid 419508:tid 419740] [client 202.179.75.202:43938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XhVcagwCeNbomjVsk6gAAAfU"]
[Tue Jul 21 08:27:01.233612 2026] [security2:error] [pid 419508:tid 419740] [client 202.179.75.202:43938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XhVcagwCeNbomjVsk6gAAAfU"]
[Tue Jul 21 08:27:01.251684 2026] [security2:error] [pid 418108:tid 418300] [client 82.102.18.188:57888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moradanow.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9XhQ0cxofL2J1zwYrPAgAAAUY"]
[Tue Jul 21 08:27:01.530571 2026] [security2:error] [pid 419508:tid 419669] [client 185.213.175.37:38722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "azusacorretora.com.br"] [uri "/.env.backup"] [unique_id "al9XhVcagwCeNbomjVsk7AAAAa4"]
[Tue Jul 21 08:27:01.637670 2026] [security2:error] [pid 418108:tid 418260] [client 82.102.18.188:57894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moradanow.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9XhQ0cxofL2J1zwYrPBQAAAR4"]
[Tue Jul 21 08:27:01.876794 2026] [security2:error] [pid 419508:tid 419752] [client 20.220.225.223:19678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/bscclapb.php"] [unique_id "al9XhVcagwCeNbomjVsk9wAAAgA"]
[Tue Jul 21 08:27:02.037893 2026] [security2:error] [pid 419508:tid 419701] [client 20.206.105.145:20234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9XhlcagwCeNbomjVsk-wAAAc4"]
[Tue Jul 21 08:27:02.144318 2026] [security2:error] [pid 419508:tid 419512] [remote 117.203.198.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.198.203.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XhlcagwCeNbomjVslAwABsgM"]
[Tue Jul 21 08:27:02.144459 2026] [security2:error] [pid 419508:tid 419673] [client 117.203.198.67:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arenaalphaville.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XhlcagwCeNbomjVslAwABsgM"]
[Tue Jul 21 08:27:02.219895 2026] [security2:error] [pid 419508:tid 419619] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XhlcagwCeNbomjVslBQAByW4"]
[Tue Jul 21 08:27:02.220063 2026] [security2:error] [pid 419508:tid 419696] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XhlcagwCeNbomjVslBQAByW4"]
[Tue Jul 21 08:27:02.571231 2026] [security2:error] [pid 419508:tid 419646] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XhlcagwCeNbomjVslBAAAAZc"]
[Tue Jul 21 08:27:02.893363 2026] [security2:error] [pid 419508:tid 419757] [client 20.220.225.223:19290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/else1.php"] [unique_id "al9XhlcagwCeNbomjVslFQAAAgU"]
[Tue Jul 21 08:27:03.015392 2026] [security2:error] [pid 419508:tid 419706] [client 150.129.202.39:64762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xh1cagwCeNbomjVslGQAAAdM"]
[Tue Jul 21 08:27:03.015514 2026] [security2:error] [pid 419508:tid 419706] [client 150.129.202.39:64762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xh1cagwCeNbomjVslGQAAAdM"]
[Tue Jul 21 08:27:03.371386 2026] [security2:error] [pid 419508:tid 419678] [client 127.0.0.1:15210] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al9Xh1cagwCeNbomjVslIgAAAbc"]
[Tue Jul 21 08:27:03.371493 2026] [security2:error] [pid 418108:tid 418327] [client 74.7.228.47:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.brasilcertdigital.online"] [uri "/robots.txt"] [unique_id "al9Xhw0cxofL2J1zwYrPDgABYWE"]
[Tue Jul 21 08:27:03.451986 2026] [security2:error] [pid 419508:tid 419750] [client 74.249.245.134:55546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Xh1cagwCeNbomjVslJQAAAf4"]
[Tue Jul 21 08:27:03.481636 2026] [security2:error] [pid 419508:tid 419694] [client 117.213.202.34:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xh1cagwCeNbomjVslKQAAAcc"]
[Tue Jul 21 08:27:03.481750 2026] [security2:error] [pid 419508:tid 419694] [client 117.213.202.34:60424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xh1cagwCeNbomjVslKQAAAcc"]
[Tue Jul 21 08:27:03.570012 2026] [security2:error] [pid 419508:tid 419714] [client 89.238.167.134:42624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Xh1cagwCeNbomjVslLAAAAds"]
[Tue Jul 21 08:27:03.570148 2026] [security2:error] [pid 419508:tid 419714] [client 89.238.167.134:42624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Xh1cagwCeNbomjVslLAAAAds"]
[Tue Jul 21 08:27:03.577676 2026] [security2:error] [pid 419508:tid 419705] [client 195.49.128.211:53158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Xh1cagwCeNbomjVslLQAAAdI"]
[Tue Jul 21 08:27:03.577786 2026] [security2:error] [pid 419508:tid 419705] [client 195.49.128.211:53158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Xh1cagwCeNbomjVslLQAAAdI"]
[Tue Jul 21 08:27:03.666106 2026] [security2:error] [pid 419508:tid 419713] [client 151.63.71.144:65426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Xh1cagwCeNbomjVslMgAAAdo"]
[Tue Jul 21 08:27:03.666217 2026] [security2:error] [pid 419508:tid 419713] [client 151.63.71.144:65426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Xh1cagwCeNbomjVslMgAAAdo"]
[Tue Jul 21 08:27:03.742829 2026] [security2:error] [pid 419508:tid 419716] [client 187.125.243.197:49519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Xh1cagwCeNbomjVslNgAAAd0"]
[Tue Jul 21 08:27:03.742964 2026] [security2:error] [pid 419508:tid 419716] [client 187.125.243.197:49519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Xh1cagwCeNbomjVslNgAAAd0"]
[Tue Jul 21 08:27:03.796581 2026] [security2:error] [pid 419508:tid 419718] [client 74.7.228.21:47780] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.phenoman.shop-officialstore.com"] [uri "/index.php"] [unique_id "al9XhlcagwCeNbomjVslEwAB32Y"]
[Tue Jul 21 08:27:04.268306 2026] [security2:error] [pid 418108:tid 418347] [client 20.220.225.223:19748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/tkikikoko.php"] [unique_id "al9XiA0cxofL2J1zwYrPEgAAAXU"]
[Tue Jul 21 08:27:04.364106 2026] [security2:error] [pid 419508:tid 419668] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Xh1cagwCeNbomjVslOQAAAa0"]
[Tue Jul 21 08:27:04.497630 2026] [security2:error] [pid 419508:tid 419673] [client 74.7.228.21:47790] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "phenoman.shop-officialstore.com"] [uri "/index.php"] [unique_id "al9XiFcagwCeNbomjVslQwABsh8"], referer: https://www.phenoman.shop-officialstore.com/robots.txt
[Tue Jul 21 08:27:04.585972 2026] [security2:error] [pid 419508:tid 419534] [remote 91.142.222.105:46474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "companhiatop.com.br"] [uri "/wp-login.php"] [unique_id "al9XiFcagwCeNbomjVslRQACBhk"]
[Tue Jul 21 08:27:04.842491 2026] [autoindex:error] [pid 418108:tid 418334] [client 20.206.105.145:20200] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:27:04.871510 2026] [autoindex:error] [pid 418108:tid 418325] [client 20.206.105.145:20200] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:27:04.904736 2026] [security2:error] [pid 418108:tid 418358] [client 20.206.105.145:20200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp.php"] [unique_id "al9XiA0cxofL2J1zwYrPGgAAAYA"]
[Tue Jul 21 08:27:05.319868 2026] [security2:error] [pid 419508:tid 419727] [client 74.249.245.134:55543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9XiVcagwCeNbomjVslTwAAAeg"]
[Tue Jul 21 08:27:05.390925 2026] [security2:error] [pid 419508:tid 419740] [client 20.220.225.223:19649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9XiVcagwCeNbomjVslUwAAAfU"]
[Tue Jul 21 08:27:05.599379 2026] [security2:error] [pid 419508:tid 419733] [client 103.255.105.130:61612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XiVcagwCeNbomjVslVwAAAe4"]
[Tue Jul 21 08:27:05.599501 2026] [security2:error] [pid 419508:tid 419733] [client 103.255.105.130:61612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XiVcagwCeNbomjVslVwAAAe4"]
[Tue Jul 21 08:27:06.122302 2026] [security2:error] [pid 419508:tid 419728] [client 65.21.113.253:47404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XiVcagwCeNbomjVslXAAAAek"]
[Tue Jul 21 08:27:06.239292 2026] [security2:error] [pid 419508:tid 419648] [client 20.220.225.223:19323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/wp-css.php"] [unique_id "al9XilcagwCeNbomjVslZwAAAZk"]
[Tue Jul 21 08:27:06.249036 2026] [autoindex:error] [pid 419508:tid 419718] [client 54.164.167.77:4275] AH01276: Cannot serve directory /home2/bavosc49/one.bavos.com.br/public/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:27:06.442948 2026] [security2:error] [pid 419508:tid 419647] [client 223.181.60.88:16666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XilcagwCeNbomjVslbwAAAZg"]
[Tue Jul 21 08:27:06.443785 2026] [security2:error] [pid 419508:tid 419647] [client 223.181.60.88:16666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XilcagwCeNbomjVslbwAAAZg"]
[Tue Jul 21 08:27:06.673799 2026] [security2:error] [pid 419508:tid 419691] [client 49.144.66.253:32513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XilcagwCeNbomjVslcgAAAcQ"]
[Tue Jul 21 08:27:06.673942 2026] [security2:error] [pid 419508:tid 419691] [client 49.144.66.253:32513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XilcagwCeNbomjVslcgAAAcQ"]
[Tue Jul 21 08:27:06.682887 2026] [security2:error] [pid 419508:tid 419672] [client 14.245.224.124:56478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XilcagwCeNbomjVslcwAAAbE"]
[Tue Jul 21 08:27:06.683018 2026] [security2:error] [pid 419508:tid 419672] [client 14.245.224.124:56478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XilcagwCeNbomjVslcwAAAbE"]
[Tue Jul 21 08:27:06.907017 2026] [security2:error] [pid 419508:tid 419690] [client 20.206.105.145:20098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/abcd.php"] [unique_id "al9XilcagwCeNbomjVslfgAAAcM"]
[Tue Jul 21 08:27:07.045010 2026] [access_compat:error] [pid 418108:tid 418331] [client 162.241.63.68:48668] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:27:07.097688 2026] [security2:error] [pid 419508:tid 419551] [remote 104.244.79.40:52506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.79.244.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sogastro.com.br"] [uri "/wp-login.php"] [unique_id "al9Xi1cagwCeNbomjVslgwABvyo"]
[Tue Jul 21 08:27:07.466641 2026] [security2:error] [pid 418108:tid 418256] [client 61.1.167.83:60818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xiw0cxofL2J1zwYrPMAAAARo"]
[Tue Jul 21 08:27:07.466770 2026] [security2:error] [pid 418108:tid 418256] [client 61.1.167.83:60818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xiw0cxofL2J1zwYrPMAAAARo"]
[Tue Jul 21 08:27:07.887879 2026] [security2:error] [pid 419508:tid 419571] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Xi1cagwCeNbomjVslkwAB0D4"]
[Tue Jul 21 08:27:07.888140 2026] [security2:error] [pid 419508:tid 419703] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Xi1cagwCeNbomjVslkwAB0D4"]
[Tue Jul 21 08:27:08.223024 2026] [security2:error] [pid 419508:tid 419693] [client 128.127.105.184:54006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9XjFcagwCeNbomjVslnQAAAcY"]
[Tue Jul 21 08:27:08.223171 2026] [security2:error] [pid 419508:tid 419693] [client 128.127.105.184:54006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9XjFcagwCeNbomjVslnQAAAcY"]
[Tue Jul 21 08:27:08.983095 2026] [security2:error] [pid 418108:tid 418252] [client 128.127.105.184:54018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9XjA0cxofL2J1zwYrPUgAAARY"]
[Tue Jul 21 08:27:08.983225 2026] [security2:error] [pid 418108:tid 418252] [client 128.127.105.184:54018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9XjA0cxofL2J1zwYrPUgAAARY"]
[Tue Jul 21 08:27:08.983855 2026] [security2:error] [pid 419508:tid 419761] [client 195.49.128.211:62145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XjFcagwCeNbomjVslvAAAAgk"]
[Tue Jul 21 08:27:08.983957 2026] [security2:error] [pid 419508:tid 419761] [client 195.49.128.211:62145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XjFcagwCeNbomjVslvAAAAgk"]
[Tue Jul 21 08:27:09.320727 2026] [security2:error] [pid 419508:tid 419521] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XjVcagwCeNbomjVslwgAB9gw"]
[Tue Jul 21 08:27:09.320887 2026] [security2:error] [pid 419508:tid 419741] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XjVcagwCeNbomjVslwgAB9gw"]
[Tue Jul 21 08:27:09.352756 2026] [security2:error] [pid 419508:tid 419740] [client 20.220.225.223:19974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/wp-explorer.php"] [unique_id "al9XjVcagwCeNbomjVslxAAAAfU"]
[Tue Jul 21 08:27:09.758923 2026] [security2:error] [pid 419508:tid 419764] [client 20.206.105.145:20171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/a1.php"] [unique_id "al9XjVcagwCeNbomjVsl0wAAAgw"]
[Tue Jul 21 08:27:09.919705 2026] [security2:error] [pid 418108:tid 418159] [remote 192.249.127.213:37616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.127.249.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kaducontractor.com"] [uri "/wp-login.php"] [unique_id "al9XjA0cxofL2J1zwYrPTAABbjA"]
[Tue Jul 21 08:27:10.508494 2026] [security2:error] [pid 419508:tid 419698] [client 114.119.150.86:55799] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "madeireirapiske.com.br"] [uri "/catalogo/v6/"] [unique_id "al9XjlcagwCeNbomjVsl-AAAAcs"], referer: https://madeireirapiske.com.br/wp-sitemap-posts-us_portfolio-1.xml
[Tue Jul 21 08:27:10.815225 2026] [security2:error] [pid 419508:tid 419715] [client 20.220.225.223:19708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/akismet.php"] [unique_id "al9XjlcagwCeNbomjVsmAAAAAdw"]
[Tue Jul 21 08:27:11.269923 2026] [security2:error] [pid 418108:tid 418260] [client 103.151.46.103:62612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Xjw0cxofL2J1zwYrP3gAAAR4"]
[Tue Jul 21 08:27:11.270033 2026] [security2:error] [pid 418108:tid 418260] [client 103.151.46.103:62612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Xjw0cxofL2J1zwYrP3gAAAR4"]
[Tue Jul 21 08:27:11.319574 2026] [security2:error] [pid 418108:tid 418329] [client 89.238.167.134:33356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Xjw0cxofL2J1zwYrP3wAAAWM"]
[Tue Jul 21 08:27:11.319675 2026] [security2:error] [pid 418108:tid 418329] [client 89.238.167.134:33356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Xjw0cxofL2J1zwYrP3wAAAWM"]
[Tue Jul 21 08:27:11.354835 2026] [security2:error] [pid 419508:tid 419718] [client 114.119.157.96:33879] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tempex.com.br"] [uri "/author/tempexadmin/"] [unique_id "al9Xj1cagwCeNbomjVsmBwAAAd8"], referer: https://www.tempex.com.br/2019/07/
[Tue Jul 21 08:27:11.521580 2026] [security2:error] [pid 419508:tid 419688] [client 122.176.100.127:54368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Xj1cagwCeNbomjVsmCgAAAcE"]
[Tue Jul 21 08:27:11.521735 2026] [security2:error] [pid 419508:tid 419688] [client 122.176.100.127:54368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Xj1cagwCeNbomjVsmCgAAAcE"]
[Tue Jul 21 08:27:11.651000 2026] [security2:error] [pid 419508:tid 419730] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xj1cagwCeNbomjVsmCwAB6wg"]
[Tue Jul 21 08:27:11.677423 2026] [security2:error] [pid 419508:tid 419703] [client 173.252.95.33:59784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Xj1cagwCeNbomjVsmDQAAAdA"]
[Tue Jul 21 08:27:12.004105 2026] [security2:error] [pid 418108:tid 418281] [client 20.220.225.223:19681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chaveiroportao.com.br"] [uri "/ace2.php"] [unique_id "al9XkA0cxofL2J1zwYrP7gAAATM"]
[Tue Jul 21 08:27:12.049490 2026] [security2:error] [pid 418108:tid 418316] [client 202.179.75.202:44480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XkA0cxofL2J1zwYrP7wAAAVY"]
[Tue Jul 21 08:27:12.049640 2026] [security2:error] [pid 418108:tid 418316] [client 202.179.75.202:44480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XkA0cxofL2J1zwYrP7wAAAVY"]
[Tue Jul 21 08:27:12.317934 2026] [security2:error] [pid 419508:tid 419682] [client 51.89.129.49:60464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ejemconsultoria.com.br"] [uri "/robots.txt"] [unique_id "al9XkFcagwCeNbomjVsmHQAAAbs"]
[Tue Jul 21 08:27:12.318046 2026] [security2:error] [pid 419508:tid 419682] [client 51.89.129.49:60464] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ejemconsultoria.com.br"] [uri "/robots.txt"] [unique_id "al9XkFcagwCeNbomjVsmHQAAAbs"]
[Tue Jul 21 08:27:12.338759 2026] [security2:error] [pid 418108:tid 418309] [client 20.206.105.145:20183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9XkA0cxofL2J1zwYrP9AAAAU8"]
[Tue Jul 21 08:27:12.381730 2026] [security2:error] [pid 419508:tid 419610] [remote 38.242.157.30:38598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9XkFcagwCeNbomjVsmHwABr2U"]
[Tue Jul 21 08:27:12.534443 2026] [security2:error] [pid 419508:tid 419585] [remote 176.31.139.24:28902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "geohistorianiteroi.com"] [uri "/robots.txt"] [unique_id "al9XkFcagwCeNbomjVsmIgAB2Ew"]
[Tue Jul 21 08:27:12.534586 2026] [security2:error] [pid 419508:tid 419711] [client 176.31.139.24:28902] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "geohistorianiteroi.com"] [uri "/robots.txt"] [unique_id "al9XkFcagwCeNbomjVsmIgAB2Ew"]
[Tue Jul 21 08:27:12.642274 2026] [security2:error] [pid 419508:tid 419662] [client 213.152.186.163:48326] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9XkFcagwCeNbomjVsmJQAAAac"]
[Tue Jul 21 08:27:12.642389 2026] [security2:error] [pid 419508:tid 419662] [client 213.152.186.163:48326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9XkFcagwCeNbomjVsmJQAAAac"]
[Tue Jul 21 08:27:12.745192 2026] [security2:error] [pid 418108:tid 418158] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XkA0cxofL2J1zwYrP_AABNi8"]
[Tue Jul 21 08:27:12.745399 2026] [security2:error] [pid 418108:tid 418284] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XkA0cxofL2J1zwYrP_AABNi8"]
[Tue Jul 21 08:27:12.776155 2026] [security2:error] [pid 419508:tid 419663] [client 87.58.197.199:54448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "guiapleno.com"] [uri "/"] [unique_id "al9XkFcagwCeNbomjVsmJwAAAag"]
[Tue Jul 21 08:27:13.323486 2026] [security2:error] [pid 419508:tid 419747] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XkFcagwCeNbomjVsmKQAAAfs"]
[Tue Jul 21 08:27:13.727931 2026] [security2:error] [pid 418108:tid 418342] [client 51.161.65.220:47568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ejemconsultoria.com.br"] [uri "/"] [unique_id "al9XkQ0cxofL2J1zwYrQAwAAAXA"]
[Tue Jul 21 08:27:13.728052 2026] [security2:error] [pid 418108:tid 418342] [client 51.161.65.220:47568] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ejemconsultoria.com.br"] [uri "/"] [unique_id "al9XkQ0cxofL2J1zwYrQAwAAAXA"]
[Tue Jul 21 08:27:13.729264 2026] [security2:error] [pid 419508:tid 419701] [client 150.129.202.39:13429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XkVcagwCeNbomjVsmNgAAAc4"]
[Tue Jul 21 08:27:13.729392 2026] [security2:error] [pid 419508:tid 419701] [client 150.129.202.39:13429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XkVcagwCeNbomjVsmNgAAAc4"]
[Tue Jul 21 08:27:13.791202 2026] [security2:error] [pid 419508:tid 419567] [remote 114.34.90.9:46036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/wp-login.php"] [unique_id "al9XkVcagwCeNbomjVsmOAAB6zo"]
[Tue Jul 21 08:27:14.117310 2026] [security2:error] [pid 419508:tid 419543] [remote 142.44.220.160:22880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "geohistorianiteroi.com"] [uri "/"] [unique_id "al9XklcagwCeNbomjVsmQQAB2SI"]
[Tue Jul 21 08:27:14.117508 2026] [security2:error] [pid 419508:tid 419712] [client 142.44.220.160:22880] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "geohistorianiteroi.com"] [uri "/"] [unique_id "al9XklcagwCeNbomjVsmQQAB2SI"]
[Tue Jul 21 08:27:14.162981 2026] [security2:error] [pid 419508:tid 419674] [client 117.213.202.34:60976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XklcagwCeNbomjVsmRQAAAbM"]
[Tue Jul 21 08:27:14.163124 2026] [security2:error] [pid 419508:tid 419674] [client 117.213.202.34:60976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XklcagwCeNbomjVsmRQAAAbM"]
[Tue Jul 21 08:27:14.185424 2026] [security2:error] [pid 419508:tid 419752] [client 195.49.128.211:53754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XklcagwCeNbomjVsmRgAAAgA"]
[Tue Jul 21 08:27:14.185576 2026] [security2:error] [pid 419508:tid 419752] [client 195.49.128.211:53754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XklcagwCeNbomjVsmRgAAAgA"]
[Tue Jul 21 08:27:14.200234 2026] [security2:error] [pid 419508:tid 419693] [client 187.125.243.197:50026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XklcagwCeNbomjVsmRwAAAcY"]
[Tue Jul 21 08:27:14.200343 2026] [security2:error] [pid 419508:tid 419693] [client 187.125.243.197:50026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XklcagwCeNbomjVsmRwAAAcY"]
[Tue Jul 21 08:27:14.543025 2026] [security2:error] [pid 419508:tid 419671] [client 20.197.192.193:5630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/fz.php"] [unique_id "al9XklcagwCeNbomjVsmTwAAAbA"]
[Tue Jul 21 08:27:15.571565 2026] [security2:error] [pid 419508:tid 419758] [client 20.206.105.145:20211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9Xk1cagwCeNbomjVsmegAAAgY"]
[Tue Jul 21 08:27:15.795504 2026] [security2:error] [pid 419508:tid 419764] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Xk1cagwCeNbomjVsmZAAAAgw"]
[Tue Jul 21 08:27:16.154264 2026] [security2:error] [pid 419508:tid 419650] [client 20.220.225.223:52653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/jj.php"] [unique_id "al9XlFcagwCeNbomjVsmgQAAAZs"]
[Tue Jul 21 08:27:16.232211 2026] [security2:error] [pid 419508:tid 419736] [client 111.93.58.162:17715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XlFcagwCeNbomjVsmhgAAAfE"]
[Tue Jul 21 08:27:16.232333 2026] [security2:error] [pid 419508:tid 419736] [client 111.93.58.162:17715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XlFcagwCeNbomjVsmhgAAAfE"]
[Tue Jul 21 08:27:16.370182 2026] [security2:error] [pid 419508:tid 419738] [client 89.238.167.134:33376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9XlFcagwCeNbomjVsmhwAAAfM"]
[Tue Jul 21 08:27:16.370274 2026] [security2:error] [pid 419508:tid 419738] [client 89.238.167.134:33376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9XlFcagwCeNbomjVsmhwAAAfM"]
[Tue Jul 21 08:27:16.370945 2026] [security2:error] [pid 418108:tid 418265] [client 89.238.167.134:33384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9XlA0cxofL2J1zwYrQMgAAASM"]
[Tue Jul 21 08:27:16.371013 2026] [security2:error] [pid 418108:tid 418265] [client 89.238.167.134:33384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9XlA0cxofL2J1zwYrQMgAAASM"]
[Tue Jul 21 08:27:17.244225 2026] [security2:error] [pid 418108:tid 418351] [client 14.245.224.124:57144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XlQ0cxofL2J1zwYrQPgAAAXk"]
[Tue Jul 21 08:27:17.244373 2026] [security2:error] [pid 418108:tid 418351] [client 14.245.224.124:57144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XlQ0cxofL2J1zwYrQPgAAAXk"]
[Tue Jul 21 08:27:17.260871 2026] [security2:error] [pid 419508:tid 419654] [client 223.181.60.88:28970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XlVcagwCeNbomjVsmlgAAAZ8"]
[Tue Jul 21 08:27:17.261034 2026] [security2:error] [pid 419508:tid 419654] [client 223.181.60.88:28970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XlVcagwCeNbomjVsmlgAAAZ8"]
[Tue Jul 21 08:27:17.764023 2026] [security2:error] [pid 419508:tid 419646] [client 49.144.66.253:32948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XlVcagwCeNbomjVsmogAAAZc"]
[Tue Jul 21 08:27:17.764120 2026] [security2:error] [pid 419508:tid 419646] [client 49.144.66.253:32948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XlVcagwCeNbomjVsmogAAAZc"]
[Tue Jul 21 08:27:17.839969 2026] [security2:error] [pid 419508:tid 419734] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XlVcagwCeNbomjVsmngAAAe8"]
[Tue Jul 21 08:27:17.904375 2026] [security2:error] [pid 418108:tid 418287] [client 51.68.236.68:16233] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "siteecommerceshop.com"] [uri "/robots.txt"] [unique_id "al9XlQ0cxofL2J1zwYrQcgAAATk"]
[Tue Jul 21 08:27:17.904503 2026] [security2:error] [pid 418108:tid 418287] [client 51.68.236.68:16233] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "siteecommerceshop.com"] [uri "/robots.txt"] [unique_id "al9XlQ0cxofL2J1zwYrQcgAAATk"]
[Tue Jul 21 08:27:18.155388 2026] [security2:error] [pid 419508:tid 419548] [remote 154.61.75.100:34090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9XllcagwCeNbomjVsmrgAB1yc"]
[Tue Jul 21 08:27:18.387183 2026] [security2:error] [pid 418108:tid 418267] [client 20.206.105.145:20178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/gettest.php"] [unique_id "al9Xlg0cxofL2J1zwYrQiAAAASU"]
[Tue Jul 21 08:27:18.549993 2026] [security2:error] [pid 418108:tid 418210] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Xlg0cxofL2J1zwYrQiwABJGM"]
[Tue Jul 21 08:27:18.550138 2026] [security2:error] [pid 418108:tid 418266] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Xlg0cxofL2J1zwYrQiwABJGM"]
[Tue Jul 21 08:27:18.903029 2026] [security2:error] [pid 418108:tid 418291] [client 74.249.245.134:54937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/wp.php"] [unique_id "al9Xlg0cxofL2J1zwYrQmwAAAT0"]
[Tue Jul 21 08:27:19.513875 2026] [security2:error] [pid 419508:tid 419686] [client 195.49.128.211:62871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Xl1cagwCeNbomjVsnMwAAAb8"]
[Tue Jul 21 08:27:19.513989 2026] [security2:error] [pid 419508:tid 419686] [client 195.49.128.211:62871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Xl1cagwCeNbomjVsnMwAAAb8"]
[Tue Jul 21 08:27:19.527969 2026] [security2:error] [pid 419508:tid 419598] [remote 185.8.106.219:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vidrosprovetro.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9Xl1cagwCeNbomjVsnNQABkFk"]
[Tue Jul 21 08:27:19.637454 2026] [security2:error] [pid 419508:tid 419683] [client 20.220.225.223:52239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/dragonshell.php"] [unique_id "al9Xl1cagwCeNbomjVsnOQAAAbw"]
[Tue Jul 21 08:27:20.126943 2026] [security2:error] [pid 419508:tid 419636] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XmFcagwCeNbomjVsndwABxX8"]
[Tue Jul 21 08:27:20.127134 2026] [security2:error] [pid 419508:tid 419692] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XmFcagwCeNbomjVsndwABxX8"]
[Tue Jul 21 08:27:20.246119 2026] [security2:error] [pid 419508:tid 419655] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Xl1cagwCeNbomjVsnbwAAAaA"]
[Tue Jul 21 08:27:21.373385 2026] [security2:error] [pid 419508:tid 419584] [remote 192.241.143.148:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9XmVcagwCeNbomjVsn-wAB80s"]
[Tue Jul 21 08:27:21.428330 2026] [security2:error] [pid 419508:tid 419638] [client 61.1.167.83:61363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XmVcagwCeNbomjVsn_wAAAY8"]
[Tue Jul 21 08:27:21.428466 2026] [security2:error] [pid 419508:tid 419638] [client 61.1.167.83:61363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XmVcagwCeNbomjVsn_wAAAY8"]
[Tue Jul 21 08:27:21.807556 2026] [security2:error] [pid 419508:tid 419520] [remote 185.8.106.219:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vidrosprovetro.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9XmVcagwCeNbomjVsoFAAB2Qs"], referer: http://vidrosprovetro.com.br/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Tue Jul 21 08:27:21.823091 2026] [security2:error] [pid 419508:tid 419734] [client 20.206.105.145:20198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/simple.php"] [unique_id "al9XmVcagwCeNbomjVsoFgAAAe8"]
[Tue Jul 21 08:27:21.978532 2026] [security2:error] [pid 418108:tid 418325] [client 103.151.46.103:63114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XmQ0cxofL2J1zwYrQ9wAAAV8"]
[Tue Jul 21 08:27:21.978672 2026] [security2:error] [pid 418108:tid 418325] [client 103.151.46.103:63114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XmQ0cxofL2J1zwYrQ9wAAAV8"]
[Tue Jul 21 08:27:22.141738 2026] [security2:error] [pid 419508:tid 419731] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XmlcagwCeNbomjVsoHwAB7EI"]
[Tue Jul 21 08:27:22.246900 2026] [security2:error] [pid 419508:tid 419752] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XmVcagwCeNbomjVsoEgAAAgA"]
[Tue Jul 21 08:27:22.356485 2026] [security2:error] [pid 419508:tid 419552] [remote 185.8.106.219:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.vidrosprovetro.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9XmlcagwCeNbomjVsoQgABtSs"]
[Tue Jul 21 08:27:22.755292 2026] [security2:error] [pid 419508:tid 419683] [client 122.176.100.127:54965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9XmlcagwCeNbomjVsobwAAAbw"]
[Tue Jul 21 08:27:22.755431 2026] [security2:error] [pid 419508:tid 419683] [client 122.176.100.127:54965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9XmlcagwCeNbomjVsobwAAAbw"]
[Tue Jul 21 08:27:22.916905 2026] [security2:error] [pid 419508:tid 419659] [client 202.179.75.202:36536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XmlcagwCeNbomjVsofgAAAaQ"]
[Tue Jul 21 08:27:22.917047 2026] [security2:error] [pid 419508:tid 419659] [client 202.179.75.202:36536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XmlcagwCeNbomjVsofgAAAaQ"]
[Tue Jul 21 08:27:23.105235 2026] [security2:error] [pid 419508:tid 419670] [client 5.31.193.106:58571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9XmVcagwCeNbomjVsoDgAAAa8"]
[Tue Jul 21 08:27:23.332695 2026] [security2:error] [pid 419508:tid 419629] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Xm1cagwCeNbomjVsooQACCng"]
[Tue Jul 21 08:27:23.332861 2026] [security2:error] [pid 419508:tid 419762] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Xm1cagwCeNbomjVsooQACCng"]
[Tue Jul 21 08:27:23.388735 2026] [security2:error] [pid 419508:tid 419740] [client 74.249.245.134:55488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/new.php"] [unique_id "al9Xm1cagwCeNbomjVsoowAAAfU"]
[Tue Jul 21 08:27:23.505574 2026] [security2:error] [pid 419508:tid 419614] [remote 185.8.106.219:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vidrosprovetro.com.br"] [uri "/"] [unique_id "al9Xm1cagwCeNbomjVsoqgABv2k"]
[Tue Jul 21 08:27:23.978416 2026] [security2:error] [pid 418108:tid 418311] [client 20.220.225.223:19695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/billur.php"] [unique_id "al9Xmw0cxofL2J1zwYrRKwAAAVE"]
[Tue Jul 21 08:27:24.256073 2026] [security2:error] [pid 419508:tid 419638] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Xm1cagwCeNbomjVsosgAAAY8"]
[Tue Jul 21 08:27:24.406299 2026] [security2:error] [pid 419508:tid 419694] [client 150.129.202.39:64792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XnFcagwCeNbomjVsoygAAAcc"]
[Tue Jul 21 08:27:24.406445 2026] [security2:error] [pid 419508:tid 419694] [client 150.129.202.39:64792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XnFcagwCeNbomjVsoygAAAcc"]
[Tue Jul 21 08:27:24.717190 2026] [security2:error] [pid 419508:tid 419534] [remote 217.182.128.41:48100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-login.php"] [unique_id "al9XnFcagwCeNbomjVso8AABwRk"]
[Tue Jul 21 08:27:24.767242 2026] [security2:error] [pid 419508:tid 419762] [client 187.125.243.197:50525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XnFcagwCeNbomjVso9gAAAgo"]
[Tue Jul 21 08:27:24.767353 2026] [security2:error] [pid 419508:tid 419762] [client 187.125.243.197:50525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XnFcagwCeNbomjVso9gAAAgo"]
[Tue Jul 21 08:27:24.830887 2026] [security2:error] [pid 419508:tid 419718] [client 195.49.128.211:54357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XnFcagwCeNbomjVso9wAAAd8"]
[Tue Jul 21 08:27:24.831008 2026] [security2:error] [pid 419508:tid 419718] [client 195.49.128.211:54357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XnFcagwCeNbomjVso9wAAAd8"]
[Tue Jul 21 08:27:24.846552 2026] [security2:error] [pid 419508:tid 419559] [remote 41.76.214.143:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/wp-login.php"] [unique_id "al9XnFcagwCeNbomjVso-QABsDI"]
[Tue Jul 21 08:27:24.866405 2026] [security2:error] [pid 419508:tid 419701] [client 117.213.202.34:61536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XnFcagwCeNbomjVso_AAAAc4"]
[Tue Jul 21 08:27:24.866530 2026] [security2:error] [pid 419508:tid 419701] [client 117.213.202.34:61536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XnFcagwCeNbomjVso_AAAAc4"]
[Tue Jul 21 08:27:25.099748 2026] [security2:error] [pid 419508:tid 419715] [client 20.220.225.223:58905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/wp-mt.php"] [unique_id "al9XnVcagwCeNbomjVspBAAAAdw"]
[Tue Jul 21 08:27:26.235127 2026] [security2:error] [pid 419508:tid 419662] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XnVcagwCeNbomjVspHgAAAac"]
[Tue Jul 21 08:27:26.596122 2026] [security2:error] [pid 418108:tid 418325] [client 128.127.105.184:39012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Xng0cxofL2J1zwYrRPgAAAV8"]
[Tue Jul 21 08:27:26.596218 2026] [security2:error] [pid 418108:tid 418325] [client 128.127.105.184:39012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Xng0cxofL2J1zwYrRPgAAAV8"]
[Tue Jul 21 08:27:26.736752 2026] [security2:error] [pid 419508:tid 419556] [remote 72.167.132.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samilacalculos.com.br"] [uri "/wp-login.php"] [unique_id "al9XnlcagwCeNbomjVspeQABkS8"]
[Tue Jul 21 08:27:27.106613 2026] [security2:error] [pid 418108:tid 418313] [client 20.206.105.145:20173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/xxx.php"] [unique_id "al9Xnw0cxofL2J1zwYrRTQAAAVM"]
[Tue Jul 21 08:27:27.630711 2026] [security2:error] [pid 419508:tid 419524] [remote 124.55.178.99:56844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9Xn1cagwCeNbomjVsp6gAB7g8"]
[Tue Jul 21 08:27:27.998718 2026] [security2:error] [pid 419508:tid 419682] [client 223.181.60.88:33183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Xn1cagwCeNbomjVsp9gAAAbs"]
[Tue Jul 21 08:27:27.998994 2026] [security2:error] [pid 419508:tid 419682] [client 223.181.60.88:33183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Xn1cagwCeNbomjVsp9gAAAbs"]
[Tue Jul 21 08:27:27.999249 2026] [security2:error] [pid 419508:tid 419654] [client 20.206.105.145:20103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/hypo.php"] [unique_id "al9Xn1cagwCeNbomjVsp9wAAAZ8"]
[Tue Jul 21 08:27:28.165596 2026] [autoindex:error] [pid 419508:tid 419644] [client 20.206.105.145:20187] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:27:28.179316 2026] [security2:error] [pid 419508:tid 419670] [client 20.206.105.145:20187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/chosen.php"] [unique_id "al9XoFcagwCeNbomjVsp_AAAAa8"]
[Tue Jul 21 08:27:28.220363 2026] [autoindex:error] [pid 419508:tid 419647] [client 20.206.105.145:20132] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:27:28.232015 2026] [security2:error] [pid 419508:tid 419731] [client 20.206.105.145:20132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/als.php"] [unique_id "al9XoFcagwCeNbomjVsp_gAAAew"]
[Tue Jul 21 08:27:28.235057 2026] [security2:error] [pid 419508:tid 419640] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Xn1cagwCeNbomjVsp9AAAAZE"]
[Tue Jul 21 08:27:28.253571 2026] [security2:error] [pid 419508:tid 419746] [client 20.206.105.145:20049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/pol.php"] [unique_id "al9XoFcagwCeNbomjVsqAAAAAfo"]
[Tue Jul 21 08:27:28.270023 2026] [security2:error] [pid 419508:tid 419726] [client 20.206.105.145:20125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/file5.php"] [unique_id "al9XoFcagwCeNbomjVsqAgAAAec"]
[Tue Jul 21 08:27:28.294246 2026] [security2:error] [pid 419508:tid 419677] [client 20.206.105.145:20226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9XoFcagwCeNbomjVsqBAAAAbY"]
[Tue Jul 21 08:27:28.308031 2026] [security2:error] [pid 419508:tid 419760] [client 103.255.105.130:36860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XoFcagwCeNbomjVsqBQAAAgg"]
[Tue Jul 21 08:27:28.308138 2026] [security2:error] [pid 419508:tid 419760] [client 103.255.105.130:36860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XoFcagwCeNbomjVsqBQAAAgg"]
[Tue Jul 21 08:27:28.343037 2026] [security2:error] [pid 419508:tid 419747] [client 20.206.105.145:20118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/file.php"] [unique_id "al9XoFcagwCeNbomjVsqCQAAAfs"]
[Tue Jul 21 08:27:28.457169 2026] [rewrite:warn] [pid 418108:tid 418216] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:27:28.496365 2026] [security2:error] [pid 419508:tid 419757] [client 20.206.105.145:20284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/cfile.php"] [unique_id "al9XoFcagwCeNbomjVsqCwAAAgU"]
[Tue Jul 21 08:27:28.589754 2026] [security2:error] [pid 419508:tid 419698] [client 49.144.66.253:33368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XoFcagwCeNbomjVsqDAAAAcs"]
[Tue Jul 21 08:27:28.589896 2026] [security2:error] [pid 419508:tid 419698] [client 49.144.66.253:33368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XoFcagwCeNbomjVsqDAAAAcs"]
[Tue Jul 21 08:27:28.666222 2026] [security2:error] [pid 419508:tid 419639] [client 14.245.224.124:57839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XoFcagwCeNbomjVsqDwAAAZA"]
[Tue Jul 21 08:27:28.666457 2026] [security2:error] [pid 419508:tid 419639] [client 14.245.224.124:57839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XoFcagwCeNbomjVsqDwAAAZA"]
[Tue Jul 21 08:27:28.913731 2026] [security2:error] [pid 419508:tid 419730] [client 20.206.105.145:20264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/class-wp.php"] [unique_id "al9XoFcagwCeNbomjVsqGgAAAes"]
[Tue Jul 21 08:27:28.919846 2026] [security2:error] [pid 419508:tid 419517] [remote 65.111.20.58:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "climadek.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9XoFcagwCeNbomjVsqGwACDAg"]
[Tue Jul 21 08:27:29.104417 2026] [security2:error] [pid 418108:tid 418153] [remote 130.51.180.8:53046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9XoQ0cxofL2J1zwYrRXwABiSo"]
[Tue Jul 21 08:27:29.104682 2026] [security2:error] [pid 418108:tid 418367] [client 130.51.180.8:53046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9XoQ0cxofL2J1zwYrRXwABiSo"]
[Tue Jul 21 08:27:29.174261 2026] [security2:error] [pid 419508:tid 419522] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XoVcagwCeNbomjVsqRAABlA0"]
[Tue Jul 21 08:27:29.174506 2026] [security2:error] [pid 419508:tid 419643] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XoVcagwCeNbomjVsqRAABlA0"]
[Tue Jul 21 08:27:29.909599 2026] [security2:error] [pid 419508:tid 419658] [client 109.248.148.246:35518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9XoVcagwCeNbomjVsqhQAAAaM"]
[Tue Jul 21 08:27:29.909705 2026] [security2:error] [pid 419508:tid 419658] [client 109.248.148.246:35518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9XoVcagwCeNbomjVsqhQAAAaM"]
[Tue Jul 21 08:27:30.062329 2026] [security2:error] [pid 419508:tid 419757] [client 195.49.128.211:63452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XolcagwCeNbomjVsqmgAAAgU"]
[Tue Jul 21 08:27:30.062424 2026] [security2:error] [pid 419508:tid 419757] [client 195.49.128.211:63452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XolcagwCeNbomjVsqmgAAAgU"]
[Tue Jul 21 08:27:30.265620 2026] [security2:error] [pid 419508:tid 419519] [remote 119.195.102.159:45082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9XolcagwCeNbomjVsqtQACAwo"]
[Tue Jul 21 08:27:30.285266 2026] [security2:error] [pid 419508:tid 419723] [client 109.248.148.246:35528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9XolcagwCeNbomjVsqtgAAAeQ"]
[Tue Jul 21 08:27:30.285367 2026] [security2:error] [pid 419508:tid 419723] [client 109.248.148.246:35528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9XolcagwCeNbomjVsqtgAAAeQ"]
[Tue Jul 21 08:27:30.353910 2026] [security2:error] [pid 418108:tid 418322] [client 20.206.105.145:20253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/admin.php"] [unique_id "al9Xog0cxofL2J1zwYrRbAAAAVw"]
[Tue Jul 21 08:27:30.738175 2026] [security2:error] [pid 419508:tid 419717] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XolcagwCeNbomjVsqrQAAAd4"]
[Tue Jul 21 08:27:30.819013 2026] [authz_core:error] [pid 419508:tid 419558] [remote 65.111.20.58:0] AH01630: client denied by server configuration: /home4/serric15/climadek.com.br/xmlrpc.php
[Tue Jul 21 08:27:30.952932 2026] [security2:error] [pid 419508:tid 419556] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XolcagwCeNbomjVsq-wABqy8"]
[Tue Jul 21 08:27:30.953042 2026] [security2:error] [pid 419508:tid 419666] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XolcagwCeNbomjVsq-wABqy8"]
[Tue Jul 21 08:27:31.599939 2026] [security2:error] [pid 419508:tid 419674] [client 173.252.95.38:61874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Xo1cagwCeNbomjVsrJAAAAbM"]
[Tue Jul 21 08:27:32.027701 2026] [security2:error] [pid 418108:tid 418254] [client 20.220.225.223:52631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/ww.php"] [unique_id "al9XpA0cxofL2J1zwYrRegAAARg"]
[Tue Jul 21 08:27:32.042796 2026] [security2:error] [pid 419508:tid 419721] [client 122.176.100.127:55440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9XpFcagwCeNbomjVsrNAAAAeI"]
[Tue Jul 21 08:27:32.251804 2026] [security2:error] [pid 419508:tid 419643] [client 74.249.245.134:54940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/class-t.api.php"] [unique_id "al9XpFcagwCeNbomjVsrQgAAAZQ"]
[Tue Jul 21 08:27:32.754105 2026] [security2:error] [pid 419508:tid 419734] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XpFcagwCeNbomjVsrbgAB72g"]
[Tue Jul 21 08:27:32.764209 2026] [security2:error] [pid 419508:tid 419651] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XpFcagwCeNbomjVsrSAAAAZw"]
[Tue Jul 21 08:27:32.945211 2026] [security2:error] [pid 419508:tid 419638] [client 128.127.105.184:43512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9XpFcagwCeNbomjVsrgwAAAY8"]
[Tue Jul 21 08:27:32.945310 2026] [security2:error] [pid 419508:tid 419638] [client 128.127.105.184:43512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9XpFcagwCeNbomjVsrgwAAAY8"]
[Tue Jul 21 08:27:33.073438 2026] [security2:error] [pid 419508:tid 419721] [client 122.176.100.127:55440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9XpFcagwCeNbomjVsrNAAAAeI"]
[Tue Jul 21 08:27:33.709869 2026] [security2:error] [pid 419508:tid 419672] [client 20.220.225.223:58919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/cron.php"] [unique_id "al9XpVcagwCeNbomjVsrnQAAAbE"]
[Tue Jul 21 08:27:33.764078 2026] [security2:error] [pid 418108:tid 418258] [client 202.179.75.202:39764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XpQ0cxofL2J1zwYrRlQAAARw"]
[Tue Jul 21 08:27:33.764230 2026] [security2:error] [pid 418108:tid 418258] [client 202.179.75.202:39764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XpQ0cxofL2J1zwYrRlQAAARw"]
[Tue Jul 21 08:27:33.847670 2026] [security2:error] [pid 419508:tid 419615] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XpVcagwCeNbomjVsrnwABlmo"]
[Tue Jul 21 08:27:33.847826 2026] [security2:error] [pid 419508:tid 419645] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XpVcagwCeNbomjVsrnwABlmo"]
[Tue Jul 21 08:27:33.931362 2026] [security2:error] [pid 419508:tid 419762] [client 5.31.193.106:1792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9XpVcagwCeNbomjVsrngAAAgo"]
[Tue Jul 21 08:27:34.195985 2026] [security2:error] [pid 419508:tid 419687] [client 61.1.167.83:61897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XplcagwCeNbomjVsrqAAAAcA"]
[Tue Jul 21 08:27:34.202789 2026] [security2:error] [pid 419508:tid 419687] [client 61.1.167.83:61897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XplcagwCeNbomjVsrqAAAAcA"]
[Tue Jul 21 08:27:34.390890 2026] [security2:error] [pid 419508:tid 419739] [client 20.206.105.145:20245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/aa2.php"] [unique_id "al9XplcagwCeNbomjVsrrgAAAfQ"]
[Tue Jul 21 08:27:34.679911 2026] [security2:error] [pid 418108:tid 418301] [client 20.206.105.145:20113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/ccou.php"] [unique_id "al9Xpg0cxofL2J1zwYrRnQAAAUc"]
[Tue Jul 21 08:27:34.748129 2026] [security2:error] [pid 418108:tid 418359] [client 20.206.105.145:20195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/dr.php"] [unique_id "al9Xpg0cxofL2J1zwYrRoAAAAYE"]
[Tue Jul 21 08:27:34.791850 2026] [security2:error] [pid 419508:tid 419717] [client 20.206.105.145:20204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/xamp.php"] [unique_id "al9XplcagwCeNbomjVsrtgAAAd4"]
[Tue Jul 21 08:27:34.850479 2026] [security2:error] [pid 419508:tid 419741] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XplcagwCeNbomjVsrrQAAAfY"]
[Tue Jul 21 08:27:34.855900 2026] [security2:error] [pid 418108:tid 418345] [client 20.206.105.145:20119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/bless.php"] [unique_id "al9Xpg0cxofL2J1zwYrRoQAAAXM"]
[Tue Jul 21 08:27:35.035313 2026] [security2:error] [pid 418108:tid 418283] [client 114.119.147.181:49649] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "northcomm.com.br"] [uri "/wp-includes/css/dist/format-library/style.min.css"] [unique_id "al9Xpw0cxofL2J1zwYrRpQAAATU"], referer: https://northcomm.com.br/wp-includes/css/dist/format-library/?SD
[Tue Jul 21 08:27:35.053835 2026] [security2:error] [pid 419508:tid 419732] [client 150.129.202.39:13111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xp1cagwCeNbomjVsrvQAAAe0"]
[Tue Jul 21 08:27:35.053953 2026] [security2:error] [pid 419508:tid 419732] [client 150.129.202.39:13111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xp1cagwCeNbomjVsrvQAAAe0"]
[Tue Jul 21 08:27:35.270265 2026] [security2:error] [pid 419508:tid 419652] [client 187.125.243.197:51027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Xp1cagwCeNbomjVsrwQAAAZ0"]
[Tue Jul 21 08:27:35.270435 2026] [security2:error] [pid 419508:tid 419652] [client 187.125.243.197:51027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Xp1cagwCeNbomjVsrwQAAAZ0"]
[Tue Jul 21 08:27:35.330632 2026] [authz_core:error] [pid 419508:tid 419514] [remote 65.111.20.58:0] AH01630: client denied by server configuration: /home4/serric15/climadek.com.br/xmlrpc.php
[Tue Jul 21 08:27:35.453390 2026] [security2:error] [pid 419508:tid 419719] [client 195.49.128.211:54951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Xp1cagwCeNbomjVsrxwAAAeA"]
[Tue Jul 21 08:27:35.453579 2026] [security2:error] [pid 419508:tid 419719] [client 195.49.128.211:54951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Xp1cagwCeNbomjVsrxwAAAeA"]
[Tue Jul 21 08:27:35.646704 2026] [security2:error] [pid 419508:tid 419755] [client 20.206.105.145:20133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/file46.php"] [unique_id "al9Xp1cagwCeNbomjVsrywAAAgM"]
[Tue Jul 21 08:27:35.646888 2026] [security2:error] [pid 419508:tid 419648] [client 117.213.202.34:62095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xp1cagwCeNbomjVsrygAAAZk"]
[Tue Jul 21 08:27:35.647074 2026] [security2:error] [pid 419508:tid 419648] [client 117.213.202.34:62095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xp1cagwCeNbomjVsrygAAAZk"]
[Tue Jul 21 08:27:35.904445 2026] [security2:error] [pid 419508:tid 419628] [remote 47.86.33.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9XplcagwCeNbomjVsruAAB0Hc"]
[Tue Jul 21 08:27:36.087644 2026] [security2:error] [pid 419508:tid 419676] [client 141.11.107.74:55056] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "tamoiomix.com.br"] [uri "/"] [unique_id "al9XqFcagwCeNbomjVsr1AAAAbU"]
[Tue Jul 21 08:27:36.138469 2026] [security2:error] [pid 419508:tid 419695] [client 4.204.201.85:6384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9XqFcagwCeNbomjVsr1QAAAcg"]
[Tue Jul 21 08:27:36.196942 2026] [security2:error] [pid 419508:tid 419660] [client 185.251.19.70:58345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9XqFcagwCeNbomjVsr1wAAAaU"]
[Tue Jul 21 08:27:36.214414 2026] [security2:error] [pid 419508:tid 419694] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9Xp1cagwCeNbomjVsrzQABx1g"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:36.249407 2026] [security2:error] [pid 419508:tid 419640] [client 141.11.107.74:55240] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.tamoiomix.com.br"] [uri "/"] [unique_id "al9XqFcagwCeNbomjVsr2AAAAZE"]
[Tue Jul 21 08:27:36.300324 2026] [security2:error] [pid 419508:tid 419761] [client 141.11.107.74:55278] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.tamoiomix.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9XqFcagwCeNbomjVsr2QAAAgk"]
[Tue Jul 21 08:27:36.344345 2026] [security2:error] [pid 419508:tid 419675] [client 141.11.107.74:55293] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.tamoiomix.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9XqFcagwCeNbomjVsr3wAAAbQ"]
[Tue Jul 21 08:27:36.354851 2026] [security2:error] [pid 419508:tid 419647] [client 185.251.19.79:25201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9XqFcagwCeNbomjVsr1gAAAZg"]
[Tue Jul 21 08:27:36.363183 2026] [security2:error] [pid 419508:tid 419661] [client 141.11.107.74:55304] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.tamoiomix.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9XqFcagwCeNbomjVsr4gAAAaY"]
[Tue Jul 21 08:27:36.394731 2026] [security2:error] [pid 419508:tid 419657] [client 74.249.245.134:55535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/plugins.php"] [unique_id "al9XqFcagwCeNbomjVsr5AAAAaI"]
[Tue Jul 21 08:27:36.449340 2026] [security2:error] [pid 419508:tid 419753] [client 4.204.201.85:55736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9XqFcagwCeNbomjVsr5gAAAgE"]
[Tue Jul 21 08:27:36.553356 2026] [security2:error] [pid 419508:tid 419671] [client 141.11.107.74:55417] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.tamoiomix.com.br"] [uri "/"] [unique_id "al9XqFcagwCeNbomjVsr6wAAAbA"]
[Tue Jul 21 08:27:36.672369 2026] [security2:error] [pid 419508:tid 419708] [client 74.7.175.187:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/index.php"] [unique_id "al9XplcagwCeNbomjVsrpgAAAdU"]
[Tue Jul 21 08:27:36.673317 2026] [security2:error] [pid 418108:tid 418348] [client 74.7.175.187:48296] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/robots.txt"] [unique_id "al9Xpg0cxofL2J1zwYrRmQABdg8"]
[Tue Jul 21 08:27:36.756194 2026] [security2:error] [pid 419508:tid 419652] [client 4.204.201.85:55681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/media.php"] [unique_id "al9XqFcagwCeNbomjVsr8gAAAZ0"]
[Tue Jul 21 08:27:36.894604 2026] [security2:error] [pid 419508:tid 419688] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XqFcagwCeNbomjVsr5QAAAcE"]
[Tue Jul 21 08:27:37.046523 2026] [security2:error] [pid 419508:tid 419719] [client 4.204.201.85:6382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/images.php"] [unique_id "al9XqVcagwCeNbomjVssBAAAAeA"]
[Tue Jul 21 08:27:37.181964 2026] [security2:error] [pid 419508:tid 419649] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XqFcagwCeNbomjVsr8wABmmI"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:37.348149 2026] [security2:error] [pid 418108:tid 418247] [client 4.204.201.85:55720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/gecko.php"] [unique_id "al9XqQ0cxofL2J1zwYrRvAAAARE"]
[Tue Jul 21 08:27:37.495485 2026] [security2:error] [pid 418108:tid 418286] [client 14.97.58.74:53881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XqQ0cxofL2J1zwYrRvQAAATg"]
[Tue Jul 21 08:27:37.495613 2026] [security2:error] [pid 418108:tid 418286] [client 14.97.58.74:53881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XqQ0cxofL2J1zwYrRvQAAATg"]
[Tue Jul 21 08:27:37.495907 2026] [security2:error] [pid 419508:tid 419567] [remote 199.189.225.40:62519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9XqVcagwCeNbomjVssIQABwzo"]
[Tue Jul 21 08:27:37.664608 2026] [security2:error] [pid 418108:tid 418340] [client 4.204.201.85:6366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/82.php"] [unique_id "al9XqQ0cxofL2J1zwYrRwAAAAW4"]
[Tue Jul 21 08:27:37.687026 2026] [security2:error] [pid 419508:tid 419645] [client 20.197.192.193:5996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9XqVcagwCeNbomjVssJwAAAZY"]
[Tue Jul 21 08:27:37.945651 2026] [security2:error] [pid 418108:tid 418312] [client 4.204.201.85:6375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/admin.php"] [unique_id "al9XqQ0cxofL2J1zwYrRxAAAAVI"]
[Tue Jul 21 08:27:38.155018 2026] [security2:error] [pid 419508:tid 419709] [client 20.220.225.223:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/xxx.php"] [unique_id "al9XqlcagwCeNbomjVssOQAAAdY"]
[Tue Jul 21 08:27:38.190413 2026] [security2:error] [pid 419508:tid 419640] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XqVcagwCeNbomjVssLAABkTI"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:38.208444 2026] [security2:error] [pid 419508:tid 419708] [client 20.220.225.223:19299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/mimpi.php"] [unique_id "al9XqlcagwCeNbomjVssPwAAAdU"]
[Tue Jul 21 08:27:38.236418 2026] [security2:error] [pid 419508:tid 419662] [client 4.204.201.85:55694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/adminner.php"] [unique_id "al9XqlcagwCeNbomjVssQAAAAac"]
[Tue Jul 21 08:27:38.521022 2026] [security2:error] [pid 418108:tid 418287] [client 4.204.201.85:55726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/admin.php"] [unique_id "al9Xqg0cxofL2J1zwYrRywAAATk"]
[Tue Jul 21 08:27:38.864807 2026] [security2:error] [pid 419508:tid 419693] [client 223.181.60.88:3673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XqlcagwCeNbomjVssSQAAAcY"]
[Tue Jul 21 08:27:38.865038 2026] [security2:error] [pid 419508:tid 419693] [client 223.181.60.88:3673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XqlcagwCeNbomjVssSQAAAcY"]
[Tue Jul 21 08:27:38.877115 2026] [security2:error] [pid 419508:tid 419734] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XqlcagwCeNbomjVssQwAAAe8"]
[Tue Jul 21 08:27:38.937931 2026] [security2:error] [pid 419508:tid 419742] [client 20.206.105.145:20254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/eee.php"] [unique_id "al9XqlcagwCeNbomjVssTAAAAfc"]
[Tue Jul 21 08:27:38.938916 2026] [security2:error] [pid 419508:tid 419721] [client 4.204.201.85:55527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/k.php"] [unique_id "al9XqlcagwCeNbomjVssTQAAAeI"]
[Tue Jul 21 08:27:38.985307 2026] [security2:error] [pid 419508:tid 419757] [client 14.245.224.124:58285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XqlcagwCeNbomjVssTwAAAgU"]
[Tue Jul 21 08:27:38.985810 2026] [security2:error] [pid 419508:tid 419757] [client 14.245.224.124:58285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XqlcagwCeNbomjVssTwAAAgU"]
[Tue Jul 21 08:27:39.143214 2026] [security2:error] [pid 419508:tid 419715] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XqlcagwCeNbomjVssSAAB3FY"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:39.301760 2026] [security2:error] [pid 419508:tid 419643] [client 4.204.201.85:55680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/blurbs.php"] [unique_id "al9Xq1cagwCeNbomjVssVgAAAZQ"]
[Tue Jul 21 08:27:39.326110 2026] [security2:error] [pid 419508:tid 419682] [client 74.7.175.156:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "casaejardimperfeito.com.br"] [uri "/index.php"] [unique_id "al9XqVcagwCeNbomjVssJgAAAbs"]
[Tue Jul 21 08:27:39.327159 2026] [security2:error] [pid 418108:tid 418268] [client 74.7.175.156:53546] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "casaejardimperfeito.com.br"] [uri "/robots.txt"] [unique_id "al9XqQ0cxofL2J1zwYrRwQABJls"]
[Tue Jul 21 08:27:39.409971 2026] [security2:error] [pid 419508:tid 419699] [client 74.249.245.134:55526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/jp.php"] [unique_id "al9Xq1cagwCeNbomjVssVwAAAcw"]
[Tue Jul 21 08:27:39.454427 2026] [security2:error] [pid 419508:tid 419573] [remote 216.73.160.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-login.php"] [unique_id "al9Xq1cagwCeNbomjVssWQABlUA"]
[Tue Jul 21 08:27:39.526135 2026] [security2:error] [pid 418108:tid 418283] [client 109.248.148.246:35416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Xqw0cxofL2J1zwYrR1QAAATU"]
[Tue Jul 21 08:27:39.526232 2026] [security2:error] [pid 418108:tid 418283] [client 109.248.148.246:35416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Xqw0cxofL2J1zwYrR1QAAATU"]
[Tue Jul 21 08:27:39.564107 2026] [security2:error] [pid 419508:tid 419655] [client 20.220.225.223:19264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/dp.php"] [unique_id "al9Xq1cagwCeNbomjVssXwAAAaA"]
[Tue Jul 21 08:27:39.585587 2026] [security2:error] [pid 419508:tid 419704] [client 49.144.66.253:33757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Xq1cagwCeNbomjVssYAAAAdE"]
[Tue Jul 21 08:27:39.585727 2026] [security2:error] [pid 419508:tid 419704] [client 49.144.66.253:33757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Xq1cagwCeNbomjVssYAAAAdE"]
[Tue Jul 21 08:27:39.619373 2026] [security2:error] [pid 419508:tid 419647] [client 4.204.201.85:6351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/bajah.php"] [unique_id "al9Xq1cagwCeNbomjVssYgAAAZg"]
[Tue Jul 21 08:27:39.816927 2026] [security2:error] [pid 419508:tid 419548] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Xq1cagwCeNbomjVssZwABtyc"]
[Tue Jul 21 08:27:39.817163 2026] [security2:error] [pid 419508:tid 419678] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Xq1cagwCeNbomjVssZwABtyc"]
[Tue Jul 21 08:27:39.957002 2026] [security2:error] [pid 419508:tid 419674] [client 4.204.201.85:6380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/a.php"] [unique_id "al9Xq1cagwCeNbomjVssawAAAbM"]
[Tue Jul 21 08:27:40.100578 2026] [security2:error] [pid 419508:tid 419672] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9Xq1cagwCeNbomjVssZAABsSI"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:40.278073 2026] [security2:error] [pid 419508:tid 419718] [client 4.204.201.85:55520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/edit.php"] [unique_id "al9XrFcagwCeNbomjVsscQAAAd8"]
[Tue Jul 21 08:27:40.333040 2026] [autoindex:error] [pid 419508:tid 419726] [client 98.91.173.173:7643] AH01276: Cannot serve directory /home1/guiiaz25/oliveiraearaujoadv.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:27:40.570375 2026] [security2:error] [pid 419508:tid 419763] [client 195.49.128.211:64034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XrFcagwCeNbomjVssfQAAAgs"]
[Tue Jul 21 08:27:40.570555 2026] [security2:error] [pid 419508:tid 419763] [client 195.49.128.211:64034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XrFcagwCeNbomjVssfQAAAgs"]
[Tue Jul 21 08:27:40.574771 2026] [security2:error] [pid 419508:tid 419738] [client 4.204.201.85:6381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/hosty.php"] [unique_id "al9XrFcagwCeNbomjVssfgAAAfM"]
[Tue Jul 21 08:27:40.594524 2026] [core:error] [pid 419508:tid 419581] [remote 2.57.122.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:27:40.594550 2026] [core:error] [pid 419508:tid 419581] [remote 2.57.122.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:27:40.688740 2026] [security2:error] [pid 419508:tid 419757] [client 20.197.192.193:5568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/inso.php"] [unique_id "al9XrFcagwCeNbomjVsshAAAAgU"]
[Tue Jul 21 08:27:40.862351 2026] [security2:error] [pid 419508:tid 419723] [client 4.204.201.85:6399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/k.php"] [unique_id "al9XrFcagwCeNbomjVssiQAAAeQ"]
[Tue Jul 21 08:27:40.935320 2026] [security2:error] [pid 419508:tid 419742] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XrFcagwCeNbomjVssfAAB9xU"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:40.976095 2026] [security2:error] [pid 419508:tid 419659] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XrFcagwCeNbomjVssdwAAAaQ"]
[Tue Jul 21 08:27:40.982406 2026] [security2:error] [pid 419508:tid 419665] [client 20.206.105.145:20219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/file25.php"] [unique_id "al9XrFcagwCeNbomjVsskgAAAao"]
[Tue Jul 21 08:27:41.165033 2026] [security2:error] [pid 419508:tid 419762] [client 4.204.201.85:55725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/aaa.php"] [unique_id "al9XrVcagwCeNbomjVssoQAAAgo"]
[Tue Jul 21 08:27:41.222306 2026] [security2:error] [pid 419508:tid 419661] [client 20.220.225.223:55750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/hunter.php"] [unique_id "al9XrVcagwCeNbomjVssowAAAaY"]
[Tue Jul 21 08:27:41.492358 2026] [security2:error] [pid 418108:tid 418335] [client 4.204.201.85:55733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/file5.php"] [unique_id "al9XrQ0cxofL2J1zwYrR7AAAAWk"]
[Tue Jul 21 08:27:41.677691 2026] [security2:error] [pid 419508:tid 419749] [client 20.10.88.227:1729] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealthonline.shop"] [uri "/robots.txt"] [unique_id "al9XrVcagwCeNbomjVssuAAAAf0"]
[Tue Jul 21 08:27:41.707951 2026] [security2:error] [pid 418108:tid 418214] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XrQ0cxofL2J1zwYrR_gABZ2c"]
[Tue Jul 21 08:27:41.708110 2026] [security2:error] [pid 418108:tid 418333] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XrQ0cxofL2J1zwYrR_gABZ2c"]
[Tue Jul 21 08:27:41.803632 2026] [security2:error] [pid 419508:tid 419717] [client 4.204.201.85:55503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/222.php"] [unique_id "al9XrVcagwCeNbomjVssvQAAAd4"]
[Tue Jul 21 08:27:41.808511 2026] [security2:error] [pid 419508:tid 419706] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XrVcagwCeNbomjVssrAAB00U"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:42.059728 2026] [security2:error] [pid 418108:tid 418183] [remote 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.sbbarrosadvocacia.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Xrg0cxofL2J1zwYrSCAABSUg"]
[Tue Jul 21 08:27:42.116787 2026] [security2:error] [pid 419508:tid 419699] [client 4.204.201.85:55698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/test.php"] [unique_id "al9XrlcagwCeNbomjVssxgAAAcw"]
[Tue Jul 21 08:27:42.227721 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.227822 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.227961 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228007 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228054 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228172 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228264 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228348 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228381 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228422 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228463 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228503 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228543 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228582 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228622 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228664 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228704 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228745 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228785 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228848 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228891 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228931 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.228970 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229009 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229050 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229090 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229130 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229170 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229259 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229313 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229353 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229394 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229456 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229490 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229530 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229571 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229608 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229652 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229714 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229752 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229817 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229879 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229921 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229929 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.229974 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230016 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230056 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230097 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230151 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230195 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230235 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230281 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230325 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230367 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230409 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230450 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230492 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230534 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230575 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230617 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230661 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230702 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230743 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230798 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230872 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230914 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.230964 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231006 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231047 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231092 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231138 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231180 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231229 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231277 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231326 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231367 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231408 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231450 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231491 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231532 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231573 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231614 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231655 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231696 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231736 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231777 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231825 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231880 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231920 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.231962 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.232007 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.232049 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.232101 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.232143 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.232195 2026] [lsapi:warn] [pid 419508:tid 419704] [client 162.241.63.68:45752] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:27:42.433937 2026] [security2:error] [pid 418108:tid 418264] [client 4.204.201.85:55528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/aaa.php"] [unique_id "al9Xrg0cxofL2J1zwYrSDQAAASI"]
[Tue Jul 21 08:27:42.564926 2026] [security2:error] [pid 418108:tid 418253] [client 122.176.100.127:55918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Xrg0cxofL2J1zwYrSEAAAARc"]
[Tue Jul 21 08:27:42.565061 2026] [security2:error] [pid 418108:tid 418253] [client 122.176.100.127:55918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Xrg0cxofL2J1zwYrSEAAAARc"]
[Tue Jul 21 08:27:42.749498 2026] [security2:error] [pid 418108:tid 418329] [client 4.204.201.85:55741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/11.php"] [unique_id "al9Xrg0cxofL2J1zwYrSEQAAAWM"]
[Tue Jul 21 08:27:42.785222 2026] [security2:error] [pid 419508:tid 419663] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XrlcagwCeNbomjVssygABqEc"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:42.976751 2026] [security2:error] [pid 419508:tid 419766] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XrlcagwCeNbomjVsszgAAAg4"]
[Tue Jul 21 08:27:43.044013 2026] [security2:error] [pid 418108:tid 418350] [client 4.204.201.85:6313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/mac.php"] [unique_id "al9Xrw0cxofL2J1zwYrSFAAAAXg"]
[Tue Jul 21 08:27:43.214572 2026] [security2:error] [pid 418108:tid 418134] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xrw0cxofL2J1zwYrSFgABWRc"]
[Tue Jul 21 08:27:43.214761 2026] [security2:error] [pid 418108:tid 418319] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xrw0cxofL2J1zwYrSFgABWRc"]
[Tue Jul 21 08:27:43.320580 2026] [security2:error] [pid 418108:tid 418250] [client 4.204.201.85:55719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/chosen.php"] [unique_id "al9Xrw0cxofL2J1zwYrSFwAAARQ"]
[Tue Jul 21 08:27:43.388312 2026] [security2:error] [pid 419508:tid 419654] [client 74.7.244.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "atauanhendler1781570886700.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9Xr1cagwCeNbomjVss7AABn2I"]
[Tue Jul 21 08:27:43.623311 2026] [security2:error] [pid 419508:tid 419673] [client 4.204.201.85:6346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/cream1.php"] [unique_id "al9Xr1cagwCeNbomjVss9AAAAbI"]
[Tue Jul 21 08:27:43.670626 2026] [security2:error] [pid 418108:tid 418306] [client 74.249.245.134:54919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/error.php"] [unique_id "al9Xrw0cxofL2J1zwYrSGwAAAUw"]
[Tue Jul 21 08:27:43.740848 2026] [security2:error] [pid 419508:tid 419719] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9Xr1cagwCeNbomjVss6gAB4Bo"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:43.927777 2026] [security2:error] [pid 418108:tid 418241] [client 20.220.225.223:52629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/we.php"] [unique_id "al9Xrw0cxofL2J1zwYrSHAAAAQs"]
[Tue Jul 21 08:27:44.091384 2026] [security2:error] [pid 418108:tid 418324] [client 114.119.157.4:23503] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "startonesite.com.br"] [uri "/9613tjpd1000wj7054"] [unique_id "al9XsA0cxofL2J1zwYrSHwAAAV4"], referer: https://startonesite.com.br/9613tjpd1000wj7054
[Tue Jul 21 08:27:44.110053 2026] [security2:error] [pid 419508:tid 419606] [remote 188.164.197.230:33166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9XsFcagwCeNbomjVstAwAB3mE"]
[Tue Jul 21 08:27:44.110238 2026] [security2:error] [pid 419508:tid 419717] [client 188.164.197.230:33166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9XsFcagwCeNbomjVstAwAB3mE"]
[Tue Jul 21 08:27:44.219077 2026] [security2:error] [pid 419508:tid 419695] [client 4.204.201.85:55690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/dr.php"] [unique_id "al9XsFcagwCeNbomjVstCgAAAcg"]
[Tue Jul 21 08:27:44.382531 2026] [security2:error] [pid 419508:tid 419602] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XsFcagwCeNbomjVstDgACA10"]
[Tue Jul 21 08:27:44.382683 2026] [security2:error] [pid 419508:tid 419755] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XsFcagwCeNbomjVstDgACA10"]
[Tue Jul 21 08:27:44.543894 2026] [security2:error] [pid 419508:tid 419731] [client 4.204.201.85:6371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/x.php"] [unique_id "al9XsFcagwCeNbomjVstFAAAAew"]
[Tue Jul 21 08:27:44.569646 2026] [security2:error] [pid 418108:tid 418186] [remote 34.178.75.226:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.75.178.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.sbbarrosadvocacia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xrg0cxofL2J1zwYrSDwABV0s"]
[Tue Jul 21 08:27:44.637881 2026] [security2:error] [pid 419508:tid 419691] [client 114.119.150.186:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.imobiliariasobrado.com.br"] [uri "/index.php/imovel/sobrado-geminado-3-quartos-com-garagem-10700m2-venda-vila-nova-joinville-sc-v46135"] [unique_id "al9XsFcagwCeNbomjVstFgAAAcQ"], referer: https://www.imobiliariasobrado.com.br/index.php
[Tue Jul 21 08:27:44.671310 2026] [security2:error] [pid 418108:tid 418347] [client 202.179.75.202:37074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XsA0cxofL2J1zwYrSIQAAAXU"]
[Tue Jul 21 08:27:44.671470 2026] [security2:error] [pid 418108:tid 418347] [client 202.179.75.202:37074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XsA0cxofL2J1zwYrSIQAAAXU"]
[Tue Jul 21 08:27:44.683964 2026] [security2:error] [pid 419508:tid 419747] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XsFcagwCeNbomjVstCAAB-3Q"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:44.827436 2026] [security2:error] [pid 418108:tid 418273] [client 4.204.201.85:55706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/155.php"] [unique_id "al9XsA0cxofL2J1zwYrSJAAAASs"]
[Tue Jul 21 08:27:45.033922 2026] [security2:error] [pid 419508:tid 419705] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XsFcagwCeNbomjVstFQAAAdI"]
[Tue Jul 21 08:27:45.086039 2026] [security2:error] [pid 419508:tid 419724] [client 151.63.71.144:51225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XsVcagwCeNbomjVstIgAAAeU"]
[Tue Jul 21 08:27:45.086200 2026] [security2:error] [pid 419508:tid 419724] [client 151.63.71.144:51225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XsVcagwCeNbomjVstIgAAAeU"]
[Tue Jul 21 08:27:45.307022 2026] [security2:error] [pid 419508:tid 419524] [remote 124.55.178.99:40742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/wp-login.php"] [unique_id "al9XsVcagwCeNbomjVstLQABlw8"]
[Tue Jul 21 08:27:45.329659 2026] [security2:error] [pid 419508:tid 419733] [client 4.204.201.85:55493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/ops.php"] [unique_id "al9XsVcagwCeNbomjVstLgAAAe4"]
[Tue Jul 21 08:27:45.333195 2026] [security2:error] [pid 419508:tid 419706] [client 74.249.245.134:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/classwithtostring.php"] [unique_id "al9XsVcagwCeNbomjVstLwAAAdM"]
[Tue Jul 21 08:27:45.536212 2026] [security2:error] [pid 419508:tid 419709] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XsVcagwCeNbomjVstIwAB1iU"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:45.557921 2026] [security2:error] [pid 419508:tid 419577] [remote 20.75.217.64:9758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9XsVcagwCeNbomjVstMwACBUQ"]
[Tue Jul 21 08:27:45.706224 2026] [security2:error] [pid 419508:tid 419648] [client 4.204.201.85:55529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/file31.php"] [unique_id "al9XsVcagwCeNbomjVstNgAAAZk"]
[Tue Jul 21 08:27:45.741513 2026] [security2:error] [pid 419508:tid 419685] [client 150.129.202.39:65105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XsVcagwCeNbomjVstOQAAAb4"]
[Tue Jul 21 08:27:45.741641 2026] [security2:error] [pid 419508:tid 419685] [client 150.129.202.39:65105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XsVcagwCeNbomjVstOQAAAb4"]
[Tue Jul 21 08:27:45.743737 2026] [security2:error] [pid 419508:tid 419680] [client 187.125.243.197:51517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XsVcagwCeNbomjVstOgAAAbk"]
[Tue Jul 21 08:27:45.744085 2026] [security2:error] [pid 419508:tid 419680] [client 187.125.243.197:51517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XsVcagwCeNbomjVstOgAAAbk"]
[Tue Jul 21 08:27:45.967038 2026] [security2:error] [pid 418108:tid 418159] [remote 57.141.18.0:26040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/rk-centro-automotivo/"] [unique_id "al9XsQ0cxofL2J1zwYrSLgABVjA"]
[Tue Jul 21 08:27:46.088602 2026] [security2:error] [pid 418108:tid 418279] [client 195.49.128.211:55551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Xsg0cxofL2J1zwYrSMAAAATE"]
[Tue Jul 21 08:27:46.088776 2026] [security2:error] [pid 418108:tid 418279] [client 195.49.128.211:55551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Xsg0cxofL2J1zwYrSMAAAATE"]
[Tue Jul 21 08:27:46.104724 2026] [security2:error] [pid 419508:tid 419765] [client 4.204.201.85:55696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/file6.php"] [unique_id "al9XslcagwCeNbomjVstQAAAAg0"]
[Tue Jul 21 08:27:46.448354 2026] [security2:error] [pid 418108:tid 418352] [client 20.220.225.223:19651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/bootstrap.php"] [unique_id "al9Xsg0cxofL2J1zwYrSOAAAAXo"]
[Tue Jul 21 08:27:46.467602 2026] [security2:error] [pid 418108:tid 418256] [client 109.248.148.246:35420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Xsg0cxofL2J1zwYrSOgAAARo"]
[Tue Jul 21 08:27:46.467689 2026] [security2:error] [pid 418108:tid 418256] [client 109.248.148.246:35420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Xsg0cxofL2J1zwYrSOgAAARo"]
[Tue Jul 21 08:27:46.514998 2026] [security2:error] [pid 419508:tid 419675] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XslcagwCeNbomjVstQwABtB4"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:46.599655 2026] [security2:error] [pid 418108:tid 418357] [client 4.204.201.85:55545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/adminfuns.php"] [unique_id "al9Xsg0cxofL2J1zwYrSPAAAAX8"]
[Tue Jul 21 08:27:46.914739 2026] [security2:error] [pid 418108:tid 418301] [client 4.204.201.85:55511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/goods.php"] [unique_id "al9Xsg0cxofL2J1zwYrSRAAAAUc"]
[Tue Jul 21 08:27:47.064724 2026] [security2:error] [pid 419508:tid 419766] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XslcagwCeNbomjVstUAAAAg4"]
[Tue Jul 21 08:27:47.191360 2026] [security2:error] [pid 418108:tid 418326] [client 20.206.105.145:20096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/file48.php"] [unique_id "al9Xsw0cxofL2J1zwYrSSQAAAWA"]
[Tue Jul 21 08:27:47.210556 2026] [security2:error] [pid 418108:tid 418246] [client 74.249.245.134:54920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/bless.php"] [unique_id "al9Xsw0cxofL2J1zwYrSSwAAARA"]
[Tue Jul 21 08:27:47.248310 2026] [security2:error] [pid 419508:tid 419642] [client 117.213.202.34:62650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XslcagwCeNbomjVstRgAAAZM"]
[Tue Jul 21 08:27:47.248469 2026] [security2:error] [pid 419508:tid 419642] [client 117.213.202.34:62650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XslcagwCeNbomjVstRgAAAZM"]
[Tue Jul 21 08:27:47.315356 2026] [security2:error] [pid 418108:tid 418321] [client 4.204.201.85:55701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/100.php"] [unique_id "al9Xsw0cxofL2J1zwYrSTAAAAVs"]
[Tue Jul 21 08:27:47.359002 2026] [security2:error] [pid 419508:tid 419738] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XslcagwCeNbomjVstVgAB818"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:47.458045 2026] [security2:error] [pid 418108:tid 418249] [client 141.255.164.66:48650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "pedrocromo.com.br"] [uri "/"] [unique_id "al9Xsw0cxofL2J1zwYrSTwAAARM"]
[Tue Jul 21 08:27:47.663617 2026] [security2:error] [pid 419508:tid 419758] [client 4.204.201.85:6398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/about.php"] [unique_id "al9Xs1cagwCeNbomjVstXgAAAgY"]
[Tue Jul 21 08:27:47.700769 2026] [security2:error] [pid 418108:tid 418236] [remote 34.178.75.226:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.75.178.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.sbbarrosadvocacia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xsw0cxofL2J1zwYrSUwABV30"]
[Tue Jul 21 08:27:47.700931 2026] [security2:error] [pid 418108:tid 418317] [client 34.178.75.226:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.sbbarrosadvocacia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xsw0cxofL2J1zwYrSUwABV30"]
[Tue Jul 21 08:27:47.975960 2026] [security2:error] [pid 419508:tid 419667] [client 4.204.201.85:6394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/about.php"] [unique_id "al9Xs1cagwCeNbomjVstaAAAAaw"]
[Tue Jul 21 08:27:48.083251 2026] [security2:error] [pid 419508:tid 419708] [client 111.93.58.162:7867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XtFcagwCeNbomjVstagAAAdU"]
[Tue Jul 21 08:27:48.083424 2026] [security2:error] [pid 419508:tid 419708] [client 111.93.58.162:7867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XtFcagwCeNbomjVstagAAAdU"]
[Tue Jul 21 08:27:48.192734 2026] [security2:error] [pid 419508:tid 419652] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9Xs1cagwCeNbomjVstYgABnVI"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:48.257418 2026] [security2:error] [pid 419508:tid 419665] [client 4.204.201.85:55695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/admin.php"] [unique_id "al9XtFcagwCeNbomjVstbgAAAao"]
[Tue Jul 21 08:27:48.332870 2026] [security2:error] [pid 418108:tid 418267] [client 152.59.34.51:60768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XtA0cxofL2J1zwYrSWQAAASU"]
[Tue Jul 21 08:27:48.332986 2026] [security2:error] [pid 418108:tid 418267] [client 152.59.34.51:60768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XtA0cxofL2J1zwYrSWQAAASU"]
[Tue Jul 21 08:27:48.587558 2026] [security2:error] [pid 419508:tid 419664] [client 4.204.201.85:55502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/admin.php"] [unique_id "al9XtFcagwCeNbomjVstcwAAAak"]
[Tue Jul 21 08:27:48.591859 2026] [security2:error] [pid 418108:tid 418161] [remote 20.153.140.50:45618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zooparquevet.com.br"] [uri "/wp-login.php"] [unique_id "al9XtA0cxofL2J1zwYrSWwABFjI"]
[Tue Jul 21 08:27:48.886677 2026] [security2:error] [pid 419508:tid 419760] [client 4.204.201.85:55501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/themes.php"] [unique_id "al9XtFcagwCeNbomjVstegAAAgg"]
[Tue Jul 21 08:27:49.045722 2026] [security2:error] [pid 419508:tid 419678] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XtFcagwCeNbomjVstdQABtwI"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:49.098425 2026] [security2:error] [pid 419508:tid 419753] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XtFcagwCeNbomjVstdAAAAgE"]
[Tue Jul 21 08:27:49.303583 2026] [security2:error] [pid 418108:tid 418275] [client 74.249.245.134:55492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/storage/index.php"] [unique_id "al9XtQ0cxofL2J1zwYrShQAAAS0"]
[Tue Jul 21 08:27:49.519546 2026] [security2:error] [pid 419508:tid 419721] [client 4.204.201.85:6372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/.well-known/about.php"] [unique_id "al9XtVcagwCeNbomjVstjAAAAeI"]
[Tue Jul 21 08:27:49.715609 2026] [security2:error] [pid 419508:tid 419732] [client 14.245.224.124:58711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XtVcagwCeNbomjVstkQAAAe0"]
[Tue Jul 21 08:27:49.715722 2026] [security2:error] [pid 419508:tid 419732] [client 14.245.224.124:58711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XtVcagwCeNbomjVstkQAAAe0"]
[Tue Jul 21 08:27:49.866688 2026] [security2:error] [pid 419508:tid 419642] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XtVcagwCeNbomjVstigABk2A"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:49.880446 2026] [security2:error] [pid 419508:tid 419648] [client 20.206.105.145:20185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/file6.php"] [unique_id "al9XtVcagwCeNbomjVstlgAAAZk"]
[Tue Jul 21 08:27:49.922853 2026] [security2:error] [pid 418108:tid 418256] [client 4.204.201.85:6363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9XtQ0cxofL2J1zwYrSiwAAARo"]
[Tue Jul 21 08:27:50.164057 2026] [security2:error] [pid 419508:tid 419723] [client 61.1.167.83:62441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XtlcagwCeNbomjVstnAAAAeQ"]
[Tue Jul 21 08:27:50.164222 2026] [security2:error] [pid 419508:tid 419723] [client 61.1.167.83:62441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XtlcagwCeNbomjVstnAAAAeQ"]
[Tue Jul 21 08:27:50.251080 2026] [security2:error] [pid 419508:tid 419704] [client 4.204.201.85:55507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/wefile.php"] [unique_id "al9XtlcagwCeNbomjVstnwAAAdE"]
[Tue Jul 21 08:27:50.484602 2026] [security2:error] [pid 418108:tid 418132] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Xtg0cxofL2J1zwYrSkQABHBU"]
[Tue Jul 21 08:27:50.484761 2026] [security2:error] [pid 418108:tid 418258] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Xtg0cxofL2J1zwYrSkQABHBU"]
[Tue Jul 21 08:27:50.571873 2026] [security2:error] [pid 418108:tid 418253] [client 4.204.201.85:6296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9Xtg0cxofL2J1zwYrSkgAAARc"]
[Tue Jul 21 08:27:50.594778 2026] [security2:error] [pid 418108:tid 418338] [client 213.152.186.163:56656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Xtg0cxofL2J1zwYrSkwAAAWw"]
[Tue Jul 21 08:27:50.594895 2026] [security2:error] [pid 418108:tid 418338] [client 213.152.186.163:56656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Xtg0cxofL2J1zwYrSkwAAAWw"]
[Tue Jul 21 08:27:50.822544 2026] [security2:error] [pid 419508:tid 419720] [client 223.181.60.88:16473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XtlcagwCeNbomjVstugAAAeE"]
[Tue Jul 21 08:27:50.823312 2026] [security2:error] [pid 419508:tid 419720] [client 223.181.60.88:16473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XtlcagwCeNbomjVstugAAAeE"]
[Tue Jul 21 08:27:50.855473 2026] [security2:error] [pid 419508:tid 419691] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XtlcagwCeNbomjVstsAABxEk"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:51.024159 2026] [security2:error] [pid 419508:tid 419658] [client 49.144.66.253:30063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Xt1cagwCeNbomjVstvwAAAaM"]
[Tue Jul 21 08:27:51.024335 2026] [security2:error] [pid 419508:tid 419658] [client 49.144.66.253:30063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Xt1cagwCeNbomjVstvwAAAaM"]
[Tue Jul 21 08:27:51.069025 2026] [security2:error] [pid 418108:tid 418359] [client 85.239.241.169:54522] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "br1102.hostgator.com.br"] [uri "/wp-content/plugins/wsecure/wsecure-config.php"] [unique_id "al9Xtw0cxofL2J1zwYrSnAAAAYE"]
[Tue Jul 21 08:27:51.147398 2026] [security2:error] [pid 419508:tid 419722] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XtlcagwCeNbomjVstuAAAAeM"]
[Tue Jul 21 08:27:51.202108 2026] [security2:error] [pid 419508:tid 419656] [client 195.49.128.211:64617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Xt1cagwCeNbomjVstwQAAAaE"]
[Tue Jul 21 08:27:51.202299 2026] [security2:error] [pid 419508:tid 419656] [client 195.49.128.211:64617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Xt1cagwCeNbomjVstwQAAAaE"]
[Tue Jul 21 08:27:51.235253 2026] [security2:error] [pid 418108:tid 418306] [client 4.204.201.85:55713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Xtw0cxofL2J1zwYrSnQAAAUw"]
[Tue Jul 21 08:27:51.622402 2026] [security2:error] [pid 419508:tid 419648] [client 4.204.201.85:55488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/8.php"] [unique_id "al9Xt1cagwCeNbomjVst0gAAAZk"]
[Tue Jul 21 08:27:51.814658 2026] [security2:error] [pid 419508:tid 419739] [client 74.249.245.134:54963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/g.php"] [unique_id "al9Xt1cagwCeNbomjVst0wAAAfQ"]
[Tue Jul 21 08:27:51.824285 2026] [security2:error] [pid 419508:tid 419738] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9Xt1cagwCeNbomjVstxwAB82I"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:51.936086 2026] [security2:error] [pid 418108:tid 418322] [client 20.206.105.145:20186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/a2.php"] [unique_id "al9Xtw0cxofL2J1zwYrSpQAAAVw"]
[Tue Jul 21 08:27:51.941044 2026] [security2:error] [pid 419508:tid 419659] [client 4.204.201.85:6392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Xt1cagwCeNbomjVst1wAAAaQ"]
[Tue Jul 21 08:27:52.305536 2026] [security2:error] [pid 419508:tid 419742] [client 4.204.201.85:55692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/f6.php"] [unique_id "al9XuFcagwCeNbomjVst3AAAAfc"]
[Tue Jul 21 08:27:52.368891 2026] [security2:error] [pid 418108:tid 418257] [client 20.197.192.193:5591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wpx.php"] [unique_id "al9XuA0cxofL2J1zwYrSqAAAARs"]
[Tue Jul 21 08:27:52.404079 2026] [security2:error] [pid 419508:tid 419627] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XuFcagwCeNbomjVst3wABu3Y"]
[Tue Jul 21 08:27:52.404252 2026] [security2:error] [pid 419508:tid 419682] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XuFcagwCeNbomjVst3wABu3Y"]
[Tue Jul 21 08:27:52.667866 2026] [security2:error] [pid 419508:tid 419747] [client 4.204.201.85:6347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/inputs.php"] [unique_id "al9XuFcagwCeNbomjVst5QAAAfs"]
[Tue Jul 21 08:27:52.790523 2026] [security2:error] [pid 419508:tid 419664] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XuFcagwCeNbomjVst3gABqVc"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:53.024229 2026] [rewrite:warn] [pid 419508:tid 419552] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:27:53.046319 2026] [security2:error] [pid 419508:tid 419669] [client 4.204.201.85:6370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/inputs.php"] [unique_id "al9XuVcagwCeNbomjVst8wAAAa4"]
[Tue Jul 21 08:27:53.154659 2026] [security2:error] [pid 419508:tid 419672] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XuFcagwCeNbomjVst5gAAAbE"]
[Tue Jul 21 08:27:53.394099 2026] [security2:error] [pid 418108:tid 418277] [client 4.204.201.85:55737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/classwithtostring.php"] [unique_id "al9XuQ0cxofL2J1zwYrS7wAAAS8"]
[Tue Jul 21 08:27:53.468637 2026] [security2:error] [pid 419508:tid 419733] [client 91.148.245.81:59406] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/"] [unique_id "al9XuVcagwCeNbomjVsuAQAAAe4"]
[Tue Jul 21 08:27:53.468852 2026] [security2:error] [pid 419508:tid 419740] [client 91.148.245.81:59410] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/"] [unique_id "al9XuVcagwCeNbomjVsuAAAAAfU"]
[Tue Jul 21 08:27:53.469694 2026] [security2:error] [pid 419508:tid 419706] [client 91.148.245.81:59416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/"] [unique_id "al9XuVcagwCeNbomjVsuAgAAAdM"]
[Tue Jul 21 08:27:53.471199 2026] [security2:error] [pid 419508:tid 419718] [client 91.148.244.131:48104] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/"] [unique_id "al9XuVcagwCeNbomjVsuAwAAAd8"]
[Tue Jul 21 08:27:53.474736 2026] [security2:error] [pid 419508:tid 419689] [client 91.148.244.131:48086] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/"] [unique_id "al9XuVcagwCeNbomjVsuBAAAAcI"]
[Tue Jul 21 08:27:53.474745 2026] [security2:error] [pid 419508:tid 419697] [client 91.148.244.131:48096] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/"] [unique_id "al9XuVcagwCeNbomjVsuBQAAAco"]
[Tue Jul 21 08:27:53.475293 2026] [security2:error] [pid 419508:tid 419657] [client 5.31.193.106:58598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9XuVcagwCeNbomjVst_QAAAaI"]
[Tue Jul 21 08:27:53.621192 2026] [security2:error] [pid 419508:tid 419622] [remote 119.195.102.159:48978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9XuVcagwCeNbomjVsuCQABp3E"]
[Tue Jul 21 08:27:53.678530 2026] [security2:error] [pid 418108:tid 418362] [client 4.204.201.85:6374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9XuQ0cxofL2J1zwYrS8wAAAYQ"]
[Tue Jul 21 08:27:53.746047 2026] [security2:error] [pid 418108:tid 418154] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XuQ0cxofL2J1zwYrS9AABFis"]
[Tue Jul 21 08:27:53.746235 2026] [security2:error] [pid 418108:tid 418252] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XuQ0cxofL2J1zwYrS9AABFis"]
[Tue Jul 21 08:27:53.755108 2026] [security2:error] [pid 419508:tid 419752] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XuVcagwCeNbomjVst_gACAHI"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:53.979567 2026] [security2:error] [pid 418108:tid 418327] [client 4.204.201.85:55717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/wp-blog.php"] [unique_id "al9XuQ0cxofL2J1zwYrS9wAAAWE"]
[Tue Jul 21 08:27:54.104235 2026] [security2:error] [pid 418108:tid 418310] [client 109.248.148.246:42552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Xug0cxofL2J1zwYrS-gAAAVA"]
[Tue Jul 21 08:27:54.104339 2026] [security2:error] [pid 418108:tid 418310] [client 109.248.148.246:42552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Xug0cxofL2J1zwYrS-gAAAVA"]
[Tue Jul 21 08:27:54.182419 2026] [security2:error] [pid 419508:tid 419698] [client 122.176.100.127:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9XulcagwCeNbomjVsuEgAAAcs"]
[Tue Jul 21 08:27:54.182614 2026] [security2:error] [pid 419508:tid 419698] [client 122.176.100.127:56387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9XulcagwCeNbomjVsuEgAAAcs"]
[Tue Jul 21 08:27:54.191536 2026] [core:alert] [pid 418108:tid 418248] [client 57.141.18.86:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:27:54.217860 2026] [security2:error] [pid 419508:tid 419611] [remote 65.111.20.58:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XulcagwCeNbomjVsuEwAB-2Y"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:54.218011 2026] [security2:error] [pid 419508:tid 419747] [client 65.111.20.58:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9XulcagwCeNbomjVsuEwAB-2Y"], referer: https://climadek.com.br//wp-login.php
[Tue Jul 21 08:27:54.232929 2026] [rewrite:warn] [pid 419508:tid 419584] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:27:54.246799 2026] [autoindex:error] [pid 419508:tid 419595] [remote 74.7.227.139:45802] AH01276: Cannot serve directory /home3/eslang81/sistema/notificacoes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:27:54.288602 2026] [security2:error] [pid 418108:tid 418157] [remote 4.205.168.44:35188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Xug0cxofL2J1zwYrS_gABbS4"]
[Tue Jul 21 08:27:54.364619 2026] [security2:error] [pid 418108:tid 418312] [client 74.7.175.143:50016] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "notificacoes.esidiomass.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Xug0cxofL2J1zwYrS_wABUjQ"]
[Tue Jul 21 08:27:54.371707 2026] [security2:error] [pid 419508:tid 419716] [client 20.206.105.145:20097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/file15.php"] [unique_id "al9XulcagwCeNbomjVsuFwAAAd0"]
[Tue Jul 21 08:27:54.411131 2026] [security2:error] [pid 419508:tid 419666] [client 4.204.201.85:55510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9XulcagwCeNbomjVsuGgAAAas"]
[Tue Jul 21 08:27:54.442855 2026] [security2:error] [pid 419508:tid 419762] [client 91.148.244.131:48148] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9XulcagwCeNbomjVsuHAAAAgo"]
[Tue Jul 21 08:27:54.444860 2026] [security2:error] [pid 418108:tid 418293] [client 91.148.244.131:48116] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/storage/logs/laravel.log"] [unique_id "al9Xug0cxofL2J1zwYrTAAAAAT8"]
[Tue Jul 21 08:27:54.445396 2026] [security2:error] [pid 419508:tid 419727] [client 91.148.244.131:48106] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/.env.production"] [unique_id "al9XulcagwCeNbomjVsuHQAAAeg"]
[Tue Jul 21 08:27:54.448282 2026] [security2:error] [pid 418108:tid 418323] [client 91.148.244.131:48132] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/wp-admin/setup-config.php"] [unique_id "al9Xug0cxofL2J1zwYrTAQAAAV0"]
[Tue Jul 21 08:27:54.566040 2026] [security2:error] [pid 419508:tid 419726] [client 89.238.167.134:53950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9XulcagwCeNbomjVsuIQAAAec"]
[Tue Jul 21 08:27:54.566133 2026] [security2:error] [pid 419508:tid 419726] [client 89.238.167.134:53950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9XulcagwCeNbomjVsuIQAAAec"]
[Tue Jul 21 08:27:54.653209 2026] [security2:error] [pid 419508:tid 419691] [client 91.148.245.81:59428] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/etc/ssl/private/server.key"] [unique_id "al9XulcagwCeNbomjVsuJgAAAcQ"]
[Tue Jul 21 08:27:54.655038 2026] [security2:error] [pid 419508:tid 419640] [client 91.148.245.81:59434] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/.env.production"] [unique_id "al9XulcagwCeNbomjVsuJwAAAZE"]
[Tue Jul 21 08:27:54.656607 2026] [security2:error] [pid 418108:tid 418269] [client 91.148.245.81:59418] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9Xug0cxofL2J1zwYrTBQAAASc"]
[Tue Jul 21 08:27:54.656608 2026] [security2:error] [pid 419508:tid 419674] [client 91.148.245.81:59438] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/storage/logs/laravel.log"] [unique_id "al9XulcagwCeNbomjVsuKAAAAbM"]
[Tue Jul 21 08:27:54.707476 2026] [security2:error] [pid 419508:tid 419741] [client 4.204.201.85:55728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/ms-edit.php"] [unique_id "al9XulcagwCeNbomjVsuKgAAAfY"]
[Tue Jul 21 08:27:54.946512 2026] [security2:error] [pid 419508:tid 419515] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XulcagwCeNbomjVsuLwABrwY"]
[Tue Jul 21 08:27:54.946709 2026] [security2:error] [pid 419508:tid 419670] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XulcagwCeNbomjVsuLwABrwY"]
[Tue Jul 21 08:27:54.983350 2026] [security2:error] [pid 419508:tid 419647] [client 4.204.201.85:6352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9XulcagwCeNbomjVsuMAAAAZg"]
[Tue Jul 21 08:27:54.990497 2026] [security2:error] [pid 419508:tid 419650] [client 20.220.225.223:19750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/wp-editor.php"] [unique_id "al9XulcagwCeNbomjVsuMQAAAZs"]
[Tue Jul 21 08:27:55.122252 2026] [security2:error] [pid 419508:tid 419715] [client 74.249.245.134:54938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/nf.php"] [unique_id "al9Xu1cagwCeNbomjVsuNQAAAdw"]
[Tue Jul 21 08:27:55.186643 2026] [security2:error] [pid 419508:tid 419725] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XulcagwCeNbomjVsuKQAAAeY"]
[Tue Jul 21 08:27:55.404987 2026] [security2:error] [pid 419508:tid 419713] [client 4.204.201.85:55541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Xu1cagwCeNbomjVsuPwAAAdo"]
[Tue Jul 21 08:27:55.416720 2026] [security2:error] [pid 419508:tid 419652] [client 91.148.244.131:48208] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/server.key"] [unique_id "al9Xu1cagwCeNbomjVsuQAAAAZ0"]
[Tue Jul 21 08:27:55.418777 2026] [security2:error] [pid 418108:tid 418360] [client 91.148.244.131:48172] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/etc/ssl/private/server.key"] [unique_id "al9Xuw0cxofL2J1zwYrTCgAAAYI"]
[Tue Jul 21 08:27:55.418975 2026] [security2:error] [pid 419508:tid 419659] [client 91.148.244.131:48196] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/config/production.json"] [unique_id "al9Xu1cagwCeNbomjVsuQQAAAaQ"]
[Tue Jul 21 08:27:55.419456 2026] [security2:error] [pid 418108:tid 418290] [client 91.148.244.131:48166] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/.vscode/sftp.json"] [unique_id "al9Xuw0cxofL2J1zwYrTCwAAATw"]
[Tue Jul 21 08:27:55.439863 2026] [security2:error] [pid 418108:tid 418263] [client 202.179.75.202:36980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Xuw0cxofL2J1zwYrTDAAAASE"]
[Tue Jul 21 08:27:55.439991 2026] [security2:error] [pid 418108:tid 418263] [client 202.179.75.202:36980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Xuw0cxofL2J1zwYrTDAAAASE"]
[Tue Jul 21 08:27:55.483876 2026] [security2:error] [pid 418108:tid 418329] [client 20.220.225.223:52636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oticapersona.com.br"] [uri "/phpinfo.php1"] [unique_id "al9Xuw0cxofL2J1zwYrTDQAAAWM"]
[Tue Jul 21 08:27:55.618394 2026] [security2:error] [pid 419508:tid 419680] [client 151.63.71.144:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Xu1cagwCeNbomjVsuRQAAAbk"]
[Tue Jul 21 08:27:55.618543 2026] [security2:error] [pid 419508:tid 419680] [client 151.63.71.144:51766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Xu1cagwCeNbomjVsuRQAAAbk"]
[Tue Jul 21 08:27:55.622797 2026] [security2:error] [pid 419508:tid 419639] [client 91.148.244.131:48150] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/api/.env"] [unique_id "al9Xu1cagwCeNbomjVsuRgAAAZA"]
[Tue Jul 21 08:27:55.622797 2026] [security2:error] [pid 418108:tid 418253] [client 91.148.244.131:48180] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/.npmrc"] [unique_id "al9Xuw0cxofL2J1zwYrTDgAAARc"]
[Tue Jul 21 08:27:55.623071 2026] [security2:error] [pid 419508:tid 419667] [client 91.148.244.131:48162] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/secrets.json"] [unique_id "al9Xu1cagwCeNbomjVsuRwAAAaw"]
[Tue Jul 21 08:27:56.105472 2026] [security2:error] [pid 418108:tid 418285] [client 4.204.201.85:55505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/abcd.php"] [unique_id "al9XvA0cxofL2J1zwYrTGAAAATc"]
[Tue Jul 21 08:27:56.108310 2026] [security2:error] [pid 418108:tid 418215] [remote 20.153.140.50:34158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9XvA0cxofL2J1zwYrTGQABTWg"]
[Tue Jul 21 08:27:56.170171 2026] [security2:error] [pid 418108:tid 418127] [remote 20.153.140.50:34162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/wp-login.php"] [unique_id "al9XvA0cxofL2J1zwYrTHgABJhA"]
[Tue Jul 21 08:27:56.195085 2026] [security2:error] [pid 419508:tid 419757] [client 187.125.243.197:52026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XvFcagwCeNbomjVsuUwAAAgU"]
[Tue Jul 21 08:27:56.196062 2026] [security2:error] [pid 419508:tid 419757] [client 187.125.243.197:52026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XvFcagwCeNbomjVsuUwAAAgU"]
[Tue Jul 21 08:27:56.197152 2026] [security2:error] [pid 419508:tid 419729] [client 150.129.202.39:64787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XvFcagwCeNbomjVsuUgAAAeo"]
[Tue Jul 21 08:27:56.197356 2026] [security2:error] [pid 419508:tid 419729] [client 150.129.202.39:64787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XvFcagwCeNbomjVsuUgAAAeo"]
[Tue Jul 21 08:27:56.388213 2026] [security2:error] [pid 419508:tid 419697] [client 91.148.244.131:48224] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/.git/HEAD"] [unique_id "al9XvFcagwCeNbomjVsuXAAAAco"]
[Tue Jul 21 08:27:56.392637 2026] [security2:error] [pid 419508:tid 419725] [client 4.204.201.85:6365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/file15.php"] [unique_id "al9XvFcagwCeNbomjVsubAAAAeY"]
[Tue Jul 21 08:27:56.393156 2026] [security2:error] [pid 418108:tid 418364] [client 91.148.244.131:48214] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/.ssh/id_ed25519"] [unique_id "al9XvA0cxofL2J1zwYrTHwAAAYY"]
[Tue Jul 21 08:27:56.393414 2026] [security2:error] [pid 418108:tid 418262] [client 91.148.244.131:48230] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/docker-compose.yml"] [unique_id "al9XvA0cxofL2J1zwYrTIAAAASA"]
[Tue Jul 21 08:27:56.394298 2026] [security2:error] [pid 418108:tid 418336] [client 91.148.244.131:48242] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/.env"] [unique_id "al9XvA0cxofL2J1zwYrTIQAAAWo"]
[Tue Jul 21 08:27:56.591725 2026] [security2:error] [pid 418108:tid 418315] [client 91.148.244.131:48250] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/.ssh/id_rsa"] [unique_id "al9XvA0cxofL2J1zwYrTIgAAAVU"]
[Tue Jul 21 08:27:56.597893 2026] [security2:error] [pid 418108:tid 418317] [client 91.148.244.131:48238] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/phpinfo.php"] [unique_id "al9XvA0cxofL2J1zwYrTIwAAAVc"]
[Tue Jul 21 08:27:56.640835 2026] [security2:error] [pid 419508:tid 419732] [client 91.148.245.81:59452] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/dump.sql"] [unique_id "al9XvFcagwCeNbomjVsueAAAAe0"]
[Tue Jul 21 08:27:56.641063 2026] [security2:error] [pid 418108:tid 418347] [client 91.148.245.81:59456] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/config.php"] [unique_id "al9XvA0cxofL2J1zwYrTJAAAAXU"]
[Tue Jul 21 08:27:56.643046 2026] [security2:error] [pid 418108:tid 418292] [client 91.148.245.81:59470] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/config.xml"] [unique_id "al9XvA0cxofL2J1zwYrTJQAAAT4"]
[Tue Jul 21 08:27:56.643135 2026] [security2:error] [pid 419508:tid 419720] [client 91.148.245.81:59482] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/backup.sql"] [unique_id "al9XvFcagwCeNbomjVsueQAAAeE"]
[Tue Jul 21 08:27:56.680810 2026] [security2:error] [pid 419508:tid 419673] [client 4.204.201.85:55700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/jp.php"] [unique_id "al9XvFcagwCeNbomjVsufQAAAbI"]
[Tue Jul 21 08:27:56.714916 2026] [security2:error] [pid 419508:tid 419712] [client 195.49.128.211:56150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XvFcagwCeNbomjVsuggAAAdk"]
[Tue Jul 21 08:27:56.715010 2026] [security2:error] [pid 419508:tid 419712] [client 195.49.128.211:56150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9XvFcagwCeNbomjVsuggAAAdk"]
[Tue Jul 21 08:27:56.822710 2026] [security2:error] [pid 419508:tid 419691] [client 117.213.202.34:63204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XvFcagwCeNbomjVsujQAAAcQ"]
[Tue Jul 21 08:27:56.822912 2026] [security2:error] [pid 419508:tid 419691] [client 117.213.202.34:63204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XvFcagwCeNbomjVsujQAAAcQ"]
[Tue Jul 21 08:27:56.843114 2026] [security2:error] [pid 419508:tid 419753] [client 91.148.245.81:59494] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/database.sql"] [unique_id "al9XvFcagwCeNbomjVsujgAAAgE"]
[Tue Jul 21 08:27:57.033005 2026] [security2:error] [pid 418108:tid 418327] [client 4.204.201.85:22219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/f35.php"] [unique_id "al9XvQ0cxofL2J1zwYrTKwAAAWE"]
[Tue Jul 21 08:27:57.328640 2026] [security2:error] [pid 418108:tid 418339] [client 4.204.201.85:55729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/wp-load.php"] [unique_id "al9XvQ0cxofL2J1zwYrTMQAAAW0"]
[Tue Jul 21 08:27:57.361255 2026] [security2:error] [pid 419508:tid 419640] [client 91.148.244.131:48276] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/backup.sql"] [unique_id "al9XvVcagwCeNbomjVsuoAAAAZE"]
[Tue Jul 21 08:27:57.367747 2026] [security2:error] [pid 418108:tid 418331] [client 91.148.244.131:48268] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/.ssh/id_ecdsa"] [unique_id "al9XvQ0cxofL2J1zwYrTMgAAAWU"]
[Tue Jul 21 08:27:57.368723 2026] [security2:error] [pid 418108:tid 418340] [client 91.148.244.131:48298] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/config.xml"] [unique_id "al9XvQ0cxofL2J1zwYrTMwAAAW4"]
[Tue Jul 21 08:27:57.438671 2026] [security2:error] [pid 418108:tid 418275] [client 91.148.245.81:59508] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/wp-config.php"] [unique_id "al9XvQ0cxofL2J1zwYrTNQAAAS0"]
[Tue Jul 21 08:27:57.438970 2026] [security2:error] [pid 418108:tid 418349] [client 91.148.245.81:59520] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/backup.zip"] [unique_id "al9XvQ0cxofL2J1zwYrTNgAAAXc"]
[Tue Jul 21 08:27:57.439089 2026] [security2:error] [pid 418108:tid 418333] [client 91.148.245.81:59506] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/actuator/heapdump"] [unique_id "al9XvQ0cxofL2J1zwYrTNwAAAWc"]
[Tue Jul 21 08:27:57.444474 2026] [security2:error] [pid 418108:tid 418354] [client 91.148.245.81:59524] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/database_backup.sql"] [unique_id "al9XvQ0cxofL2J1zwYrTOAAAAXw"]
[Tue Jul 21 08:27:57.569695 2026] [security2:error] [pid 418108:tid 418279] [client 91.148.244.131:48290] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/.svn/wc.db"] [unique_id "al9XvQ0cxofL2J1zwYrTOQAAATE"]
[Tue Jul 21 08:27:57.571762 2026] [security2:error] [pid 419508:tid 419705] [client 91.148.244.131:48300] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/backup.tar.gz"] [unique_id "al9XvVcagwCeNbomjVsuogAAAdI"]
[Tue Jul 21 08:27:57.622982 2026] [security2:error] [pid 419508:tid 419730] [client 91.148.244.131:48256] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/config.php"] [unique_id "al9XvVcagwCeNbomjVsupAAAAes"]
[Tue Jul 21 08:27:57.648793 2026] [security2:error] [pid 418108:tid 418256] [client 4.204.201.85:55718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/xyn.php"] [unique_id "al9XvQ0cxofL2J1zwYrTOgAAARo"]
[Tue Jul 21 08:27:57.711592 2026] [security2:error] [pid 419508:tid 419671] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XvVcagwCeNbomjVsumQAAAbA"]
[Tue Jul 21 08:27:57.766001 2026] [security2:error] [pid 419508:tid 419649] [client 91.148.244.131:48252] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/dump.sql"] [unique_id "al9XvVcagwCeNbomjVsurQAAAZo"]
[Tue Jul 21 08:27:58.125859 2026] [security2:error] [pid 419508:tid 419761] [client 20.206.105.145:20099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/jp.php"] [unique_id "al9XvlcagwCeNbomjVsutQAAAgk"]
[Tue Jul 21 08:27:58.188080 2026] [security2:error] [pid 419508:tid 419582] [remote 41.186.86.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9XvlcagwCeNbomjVsutwAB0Uk"]
[Tue Jul 21 08:27:58.250481 2026] [security2:error] [pid 419508:tid 419644] [client 4.204.201.85:55532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/ccc.php"] [unique_id "al9XvlcagwCeNbomjVsuvAAAAZU"]
[Tue Jul 21 08:27:58.360242 2026] [security2:error] [pid 419508:tid 419678] [client 91.148.244.131:48316] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/database.sql"] [unique_id "al9XvlcagwCeNbomjVsuwAAAAbc"]
[Tue Jul 21 08:27:58.362659 2026] [security2:error] [pid 418108:tid 418290] [client 91.148.244.131:48332] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/user_secrets.yml"] [unique_id "al9Xvg0cxofL2J1zwYrTQwAAATw"]
[Tue Jul 21 08:27:58.363048 2026] [security2:error] [pid 419508:tid 419655] [client 91.148.244.131:48328] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/database_backup.sql"] [unique_id "al9XvlcagwCeNbomjVsuwQAAAaA"]
[Tue Jul 21 08:27:58.363205 2026] [security2:error] [pid 418108:tid 418263] [client 91.148.244.131:48314] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/wp-config.php"] [unique_id "al9Xvg0cxofL2J1zwYrTRAAAASE"]
[Tue Jul 21 08:27:58.407257 2026] [security2:error] [pid 418108:tid 418363] [client 91.148.245.81:59594] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/.svn/wc.db"] [unique_id "al9Xvg0cxofL2J1zwYrTRQAAAYU"]
[Tue Jul 21 08:27:58.409441 2026] [security2:error] [pid 418108:tid 418253] [client 91.148.245.81:59550] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/server.key"] [unique_id "al9Xvg0cxofL2J1zwYrTRwAAARc"]
[Tue Jul 21 08:27:58.409443 2026] [security2:error] [pid 419508:tid 419667] [client 91.148.245.81:59592] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/backup.tar.gz"] [unique_id "al9XvlcagwCeNbomjVsuwgAAAaw"]
[Tue Jul 21 08:27:58.409683 2026] [security2:error] [pid 418108:tid 418250] [client 91.148.245.81:59584] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/wp-admin/setup-config.php"] [unique_id "al9Xvg0cxofL2J1zwYrTRgAAARQ"]
[Tue Jul 21 08:27:58.555934 2026] [security2:error] [pid 419508:tid 419728] [client 4.204.201.85:6339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/w.php"] [unique_id "al9XvlcagwCeNbomjVsuxgAAAek"]
[Tue Jul 21 08:27:58.561581 2026] [security2:error] [pid 419508:tid 419663] [client 91.148.244.131:48312] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/actuator/heapdump"] [unique_id "al9XvlcagwCeNbomjVsuxwAAAag"]
[Tue Jul 21 08:27:58.610928 2026] [security2:error] [pid 418108:tid 418245] [client 91.148.245.81:59564] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/config/production.json"] [unique_id "al9Xvg0cxofL2J1zwYrTSAAAAQ8"]
[Tue Jul 21 08:27:58.613352 2026] [security2:error] [pid 418108:tid 418366] [client 91.148.245.81:59572] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/.git/HEAD"] [unique_id "al9Xvg0cxofL2J1zwYrTSQAAAYg"]
[Tue Jul 21 08:27:58.613352 2026] [security2:error] [pid 419508:tid 419734] [client 91.148.245.81:59558] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/.vscode/sftp.json"] [unique_id "al9XvlcagwCeNbomjVsuyAAAAe8"]
[Tue Jul 21 08:27:58.699014 2026] [security2:error] [pid 419508:tid 419766] [client 89.238.167.134:36790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9XvlcagwCeNbomjVsuygAAAg4"]
[Tue Jul 21 08:27:58.699139 2026] [security2:error] [pid 419508:tid 419766] [client 89.238.167.134:36790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9XvlcagwCeNbomjVsuygAAAg4"]
[Tue Jul 21 08:27:58.791271 2026] [security2:error] [pid 418108:tid 418360] [client 14.97.58.74:23879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Xvg0cxofL2J1zwYrTSwAAAYI"]
[Tue Jul 21 08:27:58.791424 2026] [security2:error] [pid 418108:tid 418360] [client 14.97.58.74:23879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Xvg0cxofL2J1zwYrTSwAAAYI"]
[Tue Jul 21 08:27:58.846852 2026] [security2:error] [pid 419508:tid 419642] [client 4.204.201.85:21082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9XvlcagwCeNbomjVsu0AAAAZM"]
[Tue Jul 21 08:27:59.080115 2026] [security2:error] [pid 418108:tid 418300] [client 74.249.245.134:55538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/xda.php"] [unique_id "al9Xvw0cxofL2J1zwYrTTwAAAUY"]
[Tue Jul 21 08:27:59.153896 2026] [autoindex:error] [pid 419508:tid 419657] [client 44.220.233.148:47751] AH01276: Cannot serve directory /home3/alpere66/oficial.alperembalagens.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:27:59.155183 2026] [security2:error] [pid 418108:tid 418262] [client 91.148.244.131:48382] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/backup.zip"] [unique_id "al9Xvw0cxofL2J1zwYrTUAAAASA"]
[Tue Jul 21 08:27:59.156659 2026] [security2:error] [pid 419508:tid 419741] [client 91.148.244.131:48358] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "campanha.factorial.studio"] [uri "/.bash_history"] [unique_id "al9Xv1cagwCeNbomjVsu1gAAAfY"]
[Tue Jul 21 08:27:59.179496 2026] [security2:error] [pid 419508:tid 419685] [client 4.204.201.85:6397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/FWAZ.php"] [unique_id "al9Xv1cagwCeNbomjVsu1wAAAb4"]
[Tue Jul 21 08:27:59.218569 2026] [security2:error] [pid 418108:tid 418338] [client 152.59.34.51:61313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Xvw0cxofL2J1zwYrTUgAAAWw"]
[Tue Jul 21 08:27:59.218653 2026] [security2:error] [pid 418108:tid 418338] [client 152.59.34.51:61313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Xvw0cxofL2J1zwYrTUgAAAWw"]
[Tue Jul 21 08:27:59.472539 2026] [security2:error] [pid 418108:tid 418277] [client 4.204.201.85:55540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/miru1.php"] [unique_id "al9Xvw0cxofL2J1zwYrTVQAAAS8"]
[Tue Jul 21 08:27:59.769554 2026] [security2:error] [pid 419508:tid 419704] [client 4.204.201.85:6378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/aa.php"] [unique_id "al9Xv1cagwCeNbomjVsu-wAAAdE"]
[Tue Jul 21 08:27:59.848822 2026] [security2:error] [pid 419508:tid 419688] [client 20.220.225.223:19658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/cro.php"] [unique_id "al9Xv1cagwCeNbomjVsu_gAAAcE"]
[Tue Jul 21 08:28:00.069066 2026] [security2:error] [pid 419508:tid 419658] [client 4.204.201.85:55515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/122.php"] [unique_id "al9XwFcagwCeNbomjVsvAwAAAaM"]
[Tue Jul 21 08:28:00.107106 2026] [security2:error] [pid 419508:tid 419690] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Xv1cagwCeNbomjVsu-QAAAcM"]
[Tue Jul 21 08:28:00.389106 2026] [security2:error] [pid 419508:tid 419694] [client 91.148.245.81:59660] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/secrets.json"] [unique_id "al9XwFcagwCeNbomjVsvCQAAAcc"]
[Tue Jul 21 08:28:00.390065 2026] [security2:error] [pid 418108:tid 418331] [client 91.148.245.81:59616] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/.npmrc"] [unique_id "al9XwA0cxofL2J1zwYrTXQAAAWU"]
[Tue Jul 21 08:28:00.390284 2026] [security2:error] [pid 419508:tid 419749] [client 91.148.245.81:59668] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/.bash_history"] [unique_id "al9XwFcagwCeNbomjVsvCgAAAf0"]
[Tue Jul 21 08:28:00.390915 2026] [security2:error] [pid 418108:tid 418340] [client 91.148.245.81:59632] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/phpinfo.php"] [unique_id "al9XwA0cxofL2J1zwYrTXgAAAW4"]
[Tue Jul 21 08:28:00.448908 2026] [security2:error] [pid 418108:tid 418247] [client 4.204.201.85:6333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/get.php"] [unique_id "al9XwA0cxofL2J1zwYrTYQAAARE"]
[Tue Jul 21 08:28:00.521936 2026] [security2:error] [pid 418108:tid 418278] [client 14.245.224.124:59201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XwA0cxofL2J1zwYrTYwAAATA"]
[Tue Jul 21 08:28:00.522096 2026] [security2:error] [pid 418108:tid 418278] [client 14.245.224.124:59201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9XwA0cxofL2J1zwYrTYwAAATA"]
[Tue Jul 21 08:28:00.592963 2026] [security2:error] [pid 419508:tid 419710] [client 91.148.245.81:59648] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/api/.env"] [unique_id "al9XwFcagwCeNbomjVsvEAAAAdc"]
[Tue Jul 21 08:28:00.593302 2026] [security2:error] [pid 419508:tid 419663] [client 91.148.245.81:59664] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/.env"] [unique_id "al9XwFcagwCeNbomjVsvEQAAAag"]
[Tue Jul 21 08:28:00.593707 2026] [security2:error] [pid 419508:tid 419643] [client 91.148.245.81:59612] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/docker-compose.yml"] [unique_id "al9XwFcagwCeNbomjVsvEgAAAZQ"]
[Tue Jul 21 08:28:00.629117 2026] [security2:error] [pid 419508:tid 419678] [client 223.181.60.88:2436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XwFcagwCeNbomjVsvFAAAAbc"]
[Tue Jul 21 08:28:00.630285 2026] [security2:error] [pid 419508:tid 419678] [client 223.181.60.88:2436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9XwFcagwCeNbomjVsvFAAAAbc"]
[Tue Jul 21 08:28:00.737152 2026] [security2:error] [pid 419508:tid 419662] [client 4.204.201.85:22217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/as.php"] [unique_id "al9XwFcagwCeNbomjVsvFgAAAac"]
[Tue Jul 21 08:28:00.787422 2026] [security2:error] [pid 419508:tid 419697] [client 85.204.70.102:37635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "turismodecamposdojordao.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9XwFcagwCeNbomjVsvGAAAAco"]
[Tue Jul 21 08:28:01.050235 2026] [security2:error] [pid 418108:tid 418261] [client 4.204.201.85:6310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/ccou.php"] [unique_id "al9XwQ0cxofL2J1zwYrTZwAAAR8"]
[Tue Jul 21 08:28:01.106877 2026] [security2:error] [pid 419508:tid 419548] [remote 45.79.123.44:35884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9XwVcagwCeNbomjVsvIwABvSc"]
[Tue Jul 21 08:28:01.176790 2026] [security2:error] [pid 418108:tid 418129] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XwQ0cxofL2J1zwYrTagABcBI"]
[Tue Jul 21 08:28:01.177015 2026] [security2:error] [pid 418108:tid 418342] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9XwQ0cxofL2J1zwYrTagABcBI"]
[Tue Jul 21 08:28:01.321494 2026] [security2:error] [pid 419508:tid 419696] [client 61.1.167.83:62970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XwVcagwCeNbomjVsvJwAAAck"]
[Tue Jul 21 08:28:01.321655 2026] [security2:error] [pid 419508:tid 419696] [client 61.1.167.83:62970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XwVcagwCeNbomjVsvJwAAAck"]
[Tue Jul 21 08:28:01.350084 2026] [security2:error] [pid 418108:tid 418263] [client 4.204.201.85:6395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/w3lls.php"] [unique_id "al9XwQ0cxofL2J1zwYrTbwAAASE"]
[Tue Jul 21 08:28:01.356151 2026] [security2:error] [pid 419508:tid 419714] [client 91.148.245.81:59692] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/.ssh/id_ed25519"] [unique_id "al9XwVcagwCeNbomjVsvKAAAAds"]
[Tue Jul 21 08:28:01.358207 2026] [security2:error] [pid 419508:tid 419698] [client 91.148.245.81:59678] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/.ssh/id_rsa"] [unique_id "al9XwVcagwCeNbomjVsvKQAAAcs"]
[Tue Jul 21 08:28:01.359716 2026] [security2:error] [pid 419508:tid 419665] [client 91.148.245.81:59730] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/user_secrets.yml"] [unique_id "al9XwVcagwCeNbomjVsvKgAAAao"]
[Tue Jul 21 08:28:01.360488 2026] [security2:error] [pid 418108:tid 418287] [client 91.148.245.81:59726] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/.ssh/id_ecdsa"] [unique_id "al9XwQ0cxofL2J1zwYrTcAAAATk"]
[Tue Jul 21 08:28:01.546364 2026] [security2:error] [pid 419508:tid 419719] [client 85.204.70.102:54312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "turismodecamposdojordao.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XwVcagwCeNbomjVsvLwAAAeA"]
[Tue Jul 21 08:28:01.654746 2026] [security2:error] [pid 419508:tid 419658] [client 4.204.201.85:55704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/test1.php"] [unique_id "al9XwVcagwCeNbomjVsvMgAAAaM"]
[Tue Jul 21 08:28:01.745002 2026] [security2:error] [pid 419508:tid 419671] [client 195.49.128.211:65198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XwVcagwCeNbomjVsvNAAAAbA"]
[Tue Jul 21 08:28:01.745224 2026] [security2:error] [pid 419508:tid 419671] [client 195.49.128.211:65198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XwVcagwCeNbomjVsvNAAAAbA"]
[Tue Jul 21 08:28:01.982282 2026] [security2:error] [pid 418108:tid 418250] [client 49.144.66.253:30463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XwQ0cxofL2J1zwYrTdAAAARQ"]
[Tue Jul 21 08:28:01.982422 2026] [security2:error] [pid 418108:tid 418250] [client 49.144.66.253:30463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XwQ0cxofL2J1zwYrTdAAAARQ"]
[Tue Jul 21 08:28:01.984259 2026] [security2:error] [pid 419508:tid 419718] [client 4.204.201.85:55512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/database.php"] [unique_id "al9XwVcagwCeNbomjVsvVwAAAd8"]
[Tue Jul 21 08:28:02.293090 2026] [security2:error] [pid 418108:tid 418366] [client 4.204.201.85:55548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/file.php"] [unique_id "al9Xwg0cxofL2J1zwYrTdwAAAYg"]
[Tue Jul 21 08:28:02.565884 2026] [security2:error] [pid 419508:tid 419640] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XwlcagwCeNbomjVsvYgAAAZE"]
[Tue Jul 21 08:28:02.630553 2026] [security2:error] [pid 419508:tid 419732] [client 4.204.201.85:6330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/file.php"] [unique_id "al9XwlcagwCeNbomjVsveAAAAe0"]
[Tue Jul 21 08:28:02.734581 2026] [security2:error] [pid 418108:tid 418353] [client 213.152.186.163:55836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Xwg0cxofL2J1zwYrTfwAAAXs"]
[Tue Jul 21 08:28:02.734698 2026] [security2:error] [pid 418108:tid 418353] [client 213.152.186.163:55836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Xwg0cxofL2J1zwYrTfwAAAXs"]
[Tue Jul 21 08:28:02.948367 2026] [security2:error] [pid 419508:tid 419666] [client 4.204.201.85:21098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/777.php"] [unique_id "al9XwlcagwCeNbomjVsvjwAAAas"]
[Tue Jul 21 08:28:03.084270 2026] [security2:error] [pid 419508:tid 419537] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xw1cagwCeNbomjVsvlAAB2xw"]
[Tue Jul 21 08:28:03.084484 2026] [security2:error] [pid 419508:tid 419714] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xw1cagwCeNbomjVsvlAAB2xw"]
[Tue Jul 21 08:28:03.251403 2026] [security2:error] [pid 419508:tid 419726] [client 4.204.201.85:55743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/ssixta.php"] [unique_id "al9Xw1cagwCeNbomjVsvswAAAec"]
[Tue Jul 21 08:28:03.426931 2026] [security2:error] [pid 419508:tid 419761] [client 122.176.100.127:56864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Xw1cagwCeNbomjVsvwwAAAgk"]
[Tue Jul 21 08:28:03.427122 2026] [security2:error] [pid 419508:tid 419761] [client 122.176.100.127:56864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Xw1cagwCeNbomjVsvwwAAAgk"]
[Tue Jul 21 08:28:03.541640 2026] [security2:error] [pid 419508:tid 419710] [client 4.204.201.85:55691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/1c.php"] [unique_id "al9Xw1cagwCeNbomjVsvywAAAdc"]
[Tue Jul 21 08:28:03.826295 2026] [security2:error] [pid 419508:tid 419676] [client 4.204.201.85:55538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/test2.php"] [unique_id "al9Xw1cagwCeNbomjVsv2gAAAbU"]
[Tue Jul 21 08:28:04.086435 2026] [security2:error] [pid 419508:tid 419704] [client 20.206.105.145:20115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/f35.php"] [unique_id "al9XxFcagwCeNbomjVsv5AAAAdE"]
[Tue Jul 21 08:28:04.148920 2026] [security2:error] [pid 419508:tid 419648] [client 213.152.186.163:43992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9XxFcagwCeNbomjVsv6gAAAZk"]
[Tue Jul 21 08:28:04.149012 2026] [security2:error] [pid 419508:tid 419648] [client 213.152.186.163:43992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9XxFcagwCeNbomjVsv6gAAAZk"]
[Tue Jul 21 08:28:04.185786 2026] [security2:error] [pid 419508:tid 419755] [client 4.204.201.85:55504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/buy.php"] [unique_id "al9XxFcagwCeNbomjVsv6wAAAgM"]
[Tue Jul 21 08:28:04.357108 2026] [security2:error] [pid 419508:tid 419635] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XxFcagwCeNbomjVsv8AABy34"]
[Tue Jul 21 08:28:04.357281 2026] [security2:error] [pid 419508:tid 419698] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XxFcagwCeNbomjVsv8AABy34"]
[Tue Jul 21 08:28:04.427342 2026] [security2:error] [pid 419508:tid 419671] [client 85.204.70.102:54314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "turismodecamposdojordao.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XxFcagwCeNbomjVsv8gAAAbA"]
[Tue Jul 21 08:28:04.427492 2026] [security2:error] [pid 419508:tid 419671] [client 85.204.70.102:54314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "turismodecamposdojordao.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XxFcagwCeNbomjVsv8gAAAbA"]
[Tue Jul 21 08:28:04.477426 2026] [security2:error] [pid 419508:tid 419715] [client 4.204.201.85:55514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/ssend.php"] [unique_id "al9XxFcagwCeNbomjVsv9QAAAdw"]
[Tue Jul 21 08:28:04.480399 2026] [security2:error] [pid 419508:tid 419660] [client 103.151.46.103:65106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XxFcagwCeNbomjVsv9gAAAaU"]
[Tue Jul 21 08:28:04.480540 2026] [security2:error] [pid 419508:tid 419660] [client 103.151.46.103:65106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XxFcagwCeNbomjVsv9gAAAaU"]
[Tue Jul 21 08:28:04.780877 2026] [security2:error] [pid 419508:tid 419638] [client 4.204.201.85:6276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/item.php"] [unique_id "al9XxFcagwCeNbomjVsv_AAAAY8"]
[Tue Jul 21 08:28:04.888297 2026] [security2:error] [pid 418108:tid 418332] [client 74.249.245.134:54941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/shell.php"] [unique_id "al9XxA0cxofL2J1zwYrTjQAAAWY"]
[Tue Jul 21 08:28:04.996774 2026] [security2:error] [pid 419508:tid 419700] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XxFcagwCeNbomjVsv9wAAAc0"]
[Tue Jul 21 08:28:05.072873 2026] [security2:error] [pid 419508:tid 419674] [client 4.204.201.85:55537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/ss.php"] [unique_id "al9XxVcagwCeNbomjVswCQAAAbM"]
[Tue Jul 21 08:28:05.092785 2026] [security2:error] [pid 418108:tid 418333] [client 128.127.105.184:33104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9XxQ0cxofL2J1zwYrTkAAAAWc"]
[Tue Jul 21 08:28:05.092892 2026] [security2:error] [pid 418108:tid 418333] [client 128.127.105.184:33104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9XxQ0cxofL2J1zwYrTkAAAAWc"]
[Tue Jul 21 08:28:05.285850 2026] [security2:error] [pid 418108:tid 418257] [client 213.152.186.163:55844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9XxQ0cxofL2J1zwYrTkQAAARs"]
[Tue Jul 21 08:28:05.285945 2026] [security2:error] [pid 418108:tid 418257] [client 213.152.186.163:55844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9XxQ0cxofL2J1zwYrTkQAAARs"]
[Tue Jul 21 08:28:05.423333 2026] [security2:error] [pid 418108:tid 418340] [client 4.204.201.85:6343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/hypo.php"] [unique_id "al9XxQ0cxofL2J1zwYrTkgAAAW4"]
[Tue Jul 21 08:28:05.475555 2026] [security2:error] [pid 419508:tid 419697] [client 213.152.186.163:43994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9XxVcagwCeNbomjVswFAAAAco"]
[Tue Jul 21 08:28:05.475661 2026] [security2:error] [pid 419508:tid 419697] [client 213.152.186.163:43994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9XxVcagwCeNbomjVswFAAAAco"]
[Tue Jul 21 08:28:05.509077 2026] [security2:error] [pid 419508:tid 419608] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XxVcagwCeNbomjVswFQAB6mM"]
[Tue Jul 21 08:28:05.509334 2026] [security2:error] [pid 419508:tid 419729] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9XxVcagwCeNbomjVswFQAB6mM"]
[Tue Jul 21 08:28:05.728848 2026] [security2:error] [pid 419508:tid 419752] [client 4.204.201.85:6376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/users.php"] [unique_id "al9XxVcagwCeNbomjVswHwAAAgA"]
[Tue Jul 21 08:28:06.095789 2026] [security2:error] [pid 419508:tid 419689] [client 4.204.201.85:55711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/177.php"] [unique_id "al9XxlcagwCeNbomjVswKAAAAcI"]
[Tue Jul 21 08:28:06.363863 2026] [security2:error] [pid 419508:tid 419734] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XxlcagwCeNbomjVswLgAAAe8"]
[Tue Jul 21 08:28:06.416574 2026] [security2:error] [pid 419508:tid 419669] [client 4.204.201.85:55684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/config.php"] [unique_id "al9XxlcagwCeNbomjVswMAAAAa4"]
[Tue Jul 21 08:28:06.442452 2026] [security2:error] [pid 419508:tid 419764] [client 202.179.75.202:32882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XxlcagwCeNbomjVswMgAAAgw"]
[Tue Jul 21 08:28:06.442581 2026] [security2:error] [pid 419508:tid 419764] [client 202.179.75.202:32882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XxlcagwCeNbomjVswMgAAAgw"]
[Tue Jul 21 08:28:06.659804 2026] [security2:error] [pid 419508:tid 419685] [client 187.125.243.197:52530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XxlcagwCeNbomjVswNwAAAb4"]
[Tue Jul 21 08:28:06.660243 2026] [security2:error] [pid 419508:tid 419685] [client 187.125.243.197:52530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9XxlcagwCeNbomjVswNwAAAb4"]
[Tue Jul 21 08:28:06.735011 2026] [security2:error] [pid 419508:tid 419641] [client 4.204.201.85:6393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/gettest.php"] [unique_id "al9XxlcagwCeNbomjVswOgAAAZI"]
[Tue Jul 21 08:28:06.758835 2026] [security2:error] [pid 419508:tid 419728] [client 150.129.202.39:13297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XxlcagwCeNbomjVswOwAAAek"]
[Tue Jul 21 08:28:06.758940 2026] [security2:error] [pid 419508:tid 419728] [client 150.129.202.39:13297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XxlcagwCeNbomjVswOwAAAek"]
[Tue Jul 21 08:28:06.790933 2026] [security2:error] [pid 419508:tid 419695] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9XxlcagwCeNbomjVswPQAAAcg"]
[Tue Jul 21 08:28:07.056686 2026] [security2:error] [pid 419508:tid 419704] [client 4.204.201.85:6317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/min.php"] [unique_id "al9Xx1cagwCeNbomjVswRAAAAdE"]
[Tue Jul 21 08:28:07.226687 2026] [security2:error] [pid 418108:tid 418280] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Xxw0cxofL2J1zwYrTpAAAATI"]
[Tue Jul 21 08:28:07.354947 2026] [security2:error] [pid 418108:tid 418287] [client 4.204.201.85:55542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/dvjul.php"] [unique_id "al9Xxw0cxofL2J1zwYrTpQAAATk"]
[Tue Jul 21 08:28:07.356437 2026] [security2:error] [pid 419508:tid 419725] [client 195.49.128.211:56747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Xx1cagwCeNbomjVswSQAAAeY"]
[Tue Jul 21 08:28:07.356587 2026] [security2:error] [pid 419508:tid 419725] [client 195.49.128.211:56747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Xx1cagwCeNbomjVswSQAAAeY"]
[Tue Jul 21 08:28:07.400376 2026] [security2:error] [pid 419508:tid 419659] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XxlcagwCeNbomjVswQAAAAaQ"]
[Tue Jul 21 08:28:07.532135 2026] [security2:error] [pid 419508:tid 419653] [client 117.213.202.34:63758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xx1cagwCeNbomjVswTAAAAZ4"]
[Tue Jul 21 08:28:07.532322 2026] [security2:error] [pid 419508:tid 419653] [client 117.213.202.34:63758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Xx1cagwCeNbomjVswTAAAAZ4"]
[Tue Jul 21 08:28:07.567396 2026] [access_compat:error] [pid 419508:tid 419753] [client 162.241.63.68:29060] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:28:07.632985 2026] [security2:error] [pid 419508:tid 419715] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Xx1cagwCeNbomjVswTwAAAdw"]
[Tue Jul 21 08:28:07.667943 2026] [security2:error] [pid 419508:tid 419690] [client 4.204.201.85:6349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/biufile.php"] [unique_id "al9Xx1cagwCeNbomjVswUQAAAcM"]
[Tue Jul 21 08:28:07.759253 2026] [security2:error] [pid 418108:tid 418321] [client 20.206.105.145:20106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-load.php"] [unique_id "al9Xxw0cxofL2J1zwYrTqAAAAVs"]
[Tue Jul 21 08:28:07.796668 2026] [security2:error] [pid 418108:tid 418359] [client 128.127.105.184:36396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Xxw0cxofL2J1zwYrTqgAAAYE"]
[Tue Jul 21 08:28:07.796782 2026] [security2:error] [pid 418108:tid 418359] [client 128.127.105.184:36396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Xxw0cxofL2J1zwYrTqgAAAYE"]
[Tue Jul 21 08:28:08.081235 2026] [security2:error] [pid 419508:tid 419656] [client 4.204.201.85:22254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/av.php"] [unique_id "al9XyFcagwCeNbomjVswWQAAAaE"]
[Tue Jul 21 08:28:08.084109 2026] [security2:error] [pid 418108:tid 418250] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9XyA0cxofL2J1zwYrTrAAAARQ"]
[Tue Jul 21 08:28:08.369272 2026] [security2:error] [pid 418108:tid 418281] [client 4.204.201.85:6385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/coffexium.php"] [unique_id "al9XyA0cxofL2J1zwYrTswAAATM"]
[Tue Jul 21 08:28:08.485147 2026] [security2:error] [pid 419508:tid 419741] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9XyFcagwCeNbomjVswXgAAAfY"]
[Tue Jul 21 08:28:08.668697 2026] [security2:error] [pid 418108:tid 418315] [client 4.204.201.85:6278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/core.php"] [unique_id "al9XyA0cxofL2J1zwYrTuwAAAVU"]
[Tue Jul 21 08:28:08.751749 2026] [security2:error] [pid 418108:tid 418338] [client 74.249.245.134:55551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/3.php"] [unique_id "al9XyA0cxofL2J1zwYrTvAAAAWw"]
[Tue Jul 21 08:28:08.832445 2026] [security2:error] [pid 418108:tid 418317] [client 20.220.225.223:19685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/cron-tab.php"] [unique_id "al9XyA0cxofL2J1zwYrTwQAAAVc"]
[Tue Jul 21 08:28:08.858222 2026] [security2:error] [pid 419508:tid 419651] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9XyFcagwCeNbomjVswZQAAAZw"]
[Tue Jul 21 08:28:08.965192 2026] [security2:error] [pid 419508:tid 419682] [client 4.204.201.85:6318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/als.php"] [unique_id "al9XyFcagwCeNbomjVswZgAAAbs"]
[Tue Jul 21 08:28:09.182637 2026] [security2:error] [pid 419508:tid 419750] [client 89.238.167.134:53208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9XyVcagwCeNbomjVswagAAAf4"]
[Tue Jul 21 08:28:09.182743 2026] [security2:error] [pid 419508:tid 419750] [client 89.238.167.134:53208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9XyVcagwCeNbomjVswagAAAf4"]
[Tue Jul 21 08:28:09.188250 2026] [security2:error] [pid 419508:tid 419731] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XyFcagwCeNbomjVswYgAAAew"]
[Tue Jul 21 08:28:09.195179 2026] [security2:error] [pid 419508:tid 419761] [client 151.63.71.144:52312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XyVcagwCeNbomjVswawAAAgk"]
[Tue Jul 21 08:28:09.195703 2026] [security2:error] [pid 419508:tid 419761] [client 151.63.71.144:52312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9XyVcagwCeNbomjVswawAAAgk"]
[Tue Jul 21 08:28:09.233292 2026] [security2:error] [pid 418108:tid 418358] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9XyQ0cxofL2J1zwYrTwwAAAYA"]
[Tue Jul 21 08:28:09.263818 2026] [security2:error] [pid 419508:tid 419706] [client 4.204.201.85:55530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/simple.php"] [unique_id "al9XyVcagwCeNbomjVswbgAAAdM"]
[Tue Jul 21 08:28:09.446810 2026] [security2:error] [pid 419508:tid 419662] [client 128.127.105.184:53380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9XyVcagwCeNbomjVswcgAAAac"]
[Tue Jul 21 08:28:09.446918 2026] [security2:error] [pid 419508:tid 419662] [client 128.127.105.184:53380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9XyVcagwCeNbomjVswcgAAAac"]
[Tue Jul 21 08:28:09.453335 2026] [security2:error] [pid 418108:tid 418249] [client 111.93.58.162:42057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XyQ0cxofL2J1zwYrTxgAAARM"]
[Tue Jul 21 08:28:09.453491 2026] [security2:error] [pid 418108:tid 418249] [client 111.93.58.162:42057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XyQ0cxofL2J1zwYrTxgAAARM"]
[Tue Jul 21 08:28:09.568661 2026] [security2:error] [pid 419508:tid 419720] [client 4.204.201.85:6295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/init.php"] [unique_id "al9XyVcagwCeNbomjVswcwAAAeE"]
[Tue Jul 21 08:28:09.634480 2026] [security2:error] [pid 419508:tid 419697] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9XyVcagwCeNbomjVswdQAAAco"]
[Tue Jul 21 08:28:09.680287 2026] [security2:error] [pid 418108:tid 418273] [client 152.59.34.51:61794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XyQ0cxofL2J1zwYrTyAAAASs"]
[Tue Jul 21 08:28:09.680413 2026] [security2:error] [pid 418108:tid 418273] [client 152.59.34.51:61794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9XyQ0cxofL2J1zwYrTyAAAASs"]
[Tue Jul 21 08:28:09.859713 2026] [security2:error] [pid 418108:tid 418272] [client 4.204.201.85:6299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/fpwch.php"] [unique_id "al9XyQ0cxofL2J1zwYrTywAAASo"]
[Tue Jul 21 08:28:10.090487 2026] [security2:error] [pid 419508:tid 419725] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9XylcagwCeNbomjVswewAAAeY"]
[Tue Jul 21 08:28:10.170010 2026] [security2:error] [pid 419508:tid 419753] [client 4.204.201.85:1899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/domvf.php"] [unique_id "al9XylcagwCeNbomjVswfQAAAgE"]
[Tue Jul 21 08:28:10.407255 2026] [security2:error] [pid 419508:tid 419715] [client 45.146.54.47:54071] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fisiopelvicafloripa.com.br"] [uri "/.env"] [unique_id "al9XylcagwCeNbomjVswgwAAAdw"]
[Tue Jul 21 08:28:10.495352 2026] [security2:error] [pid 419508:tid 419683] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9XylcagwCeNbomjVswhAAAAbw"]
[Tue Jul 21 08:28:10.510356 2026] [security2:error] [pid 418108:tid 418261] [client 4.204.201.85:21076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/wp.php"] [unique_id "al9Xyg0cxofL2J1zwYrT1AAAAR8"]
[Tue Jul 21 08:28:10.828175 2026] [security2:error] [pid 419508:tid 419663] [client 4.204.201.85:55727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/class.php"] [unique_id "al9XylcagwCeNbomjVswjgAAAag"]
[Tue Jul 21 08:28:10.876923 2026] [security2:error] [pid 419508:tid 419734] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9XylcagwCeNbomjVswkAAAAe8"]
[Tue Jul 21 08:28:11.139211 2026] [security2:error] [pid 419508:tid 419649] [client 4.204.201.85:55683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/echkm.php"] [unique_id "al9Xy1cagwCeNbomjVswlQAAAZo"]
[Tue Jul 21 08:28:11.285389 2026] [security2:error] [pid 419508:tid 419685] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Xy1cagwCeNbomjVswmQAAAb4"]
[Tue Jul 21 08:28:11.394306 2026] [security2:error] [pid 419508:tid 419694] [client 223.181.60.88:30586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Xy1cagwCeNbomjVswnQAAAcc"]
[Tue Jul 21 08:28:11.394959 2026] [security2:error] [pid 419508:tid 419694] [client 223.181.60.88:30586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Xy1cagwCeNbomjVswnQAAAcc"]
[Tue Jul 21 08:28:11.441654 2026] [security2:error] [pid 419508:tid 419740] [client 74.249.245.134:55500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/mds.php"] [unique_id "al9Xy1cagwCeNbomjVswnwAAAfU"]
[Tue Jul 21 08:28:11.472160 2026] [security2:error] [pid 419508:tid 419668] [client 4.204.201.85:6321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/lib.php"] [unique_id "al9Xy1cagwCeNbomjVswoAAAAa0"]
[Tue Jul 21 08:28:11.631681 2026] [security2:error] [pid 419508:tid 419699] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Xy1cagwCeNbomjVswlAAAAcw"]
[Tue Jul 21 08:28:11.696638 2026] [security2:error] [pid 418108:tid 418231] [remote 207.180.241.245:47454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Xyw0cxofL2J1zwYrT3gABQXg"]
[Tue Jul 21 08:28:11.776586 2026] [security2:error] [pid 419508:tid 419676] [client 4.204.201.85:55740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/login.php"] [unique_id "al9Xy1cagwCeNbomjVswpAAAAbU"]
[Tue Jul 21 08:28:11.783055 2026] [security2:error] [pid 419508:tid 419682] [client 14.245.224.124:59696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Xy1cagwCeNbomjVswpQAAAbs"]
[Tue Jul 21 08:28:11.783371 2026] [security2:error] [pid 419508:tid 419682] [client 14.245.224.124:59696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Xy1cagwCeNbomjVswpQAAAbs"]
[Tue Jul 21 08:28:11.857441 2026] [security2:error] [pid 418108:tid 418171] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Xyw0cxofL2J1zwYrT3wABYDw"]
[Tue Jul 21 08:28:11.857613 2026] [security2:error] [pid 418108:tid 418326] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Xyw0cxofL2J1zwYrT3wABYDw"]
[Tue Jul 21 08:28:12.080783 2026] [security2:error] [pid 419508:tid 419752] [client 4.204.201.85:6369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/a2.php"] [unique_id "al9XzFcagwCeNbomjVswrQAAAgA"]
[Tue Jul 21 08:28:12.343253 2026] [security2:error] [pid 419508:tid 419717] [client 195.49.128.211:49400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XzFcagwCeNbomjVswsQAAAd4"]
[Tue Jul 21 08:28:12.343431 2026] [security2:error] [pid 419508:tid 419717] [client 195.49.128.211:49400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9XzFcagwCeNbomjVswsQAAAd4"]
[Tue Jul 21 08:28:12.354687 2026] [security2:error] [pid 419508:tid 419670] [client 20.206.105.145:20222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/xwpg.php"] [unique_id "al9XzFcagwCeNbomjVswswAAAa8"]
[Tue Jul 21 08:28:12.390735 2026] [security2:error] [pid 419508:tid 419654] [client 4.204.201.85:55723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/d61.php"] [unique_id "al9XzFcagwCeNbomjVswuAAAAZ8"]
[Tue Jul 21 08:28:12.700865 2026] [security2:error] [pid 418108:tid 418321] [client 4.204.201.85:55544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/info.php"] [unique_id "al9XzA0cxofL2J1zwYrT5QAAAVs"]
[Tue Jul 21 08:28:12.879789 2026] [security2:error] [pid 419508:tid 419645] [client 49.144.66.253:30894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XzFcagwCeNbomjVswwwAAAZY"]
[Tue Jul 21 08:28:12.879924 2026] [security2:error] [pid 419508:tid 419645] [client 49.144.66.253:30894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9XzFcagwCeNbomjVswwwAAAZY"]
[Tue Jul 21 08:28:12.880797 2026] [security2:error] [pid 419508:tid 419700] [client 20.220.225.223:19321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/koiy.php"] [unique_id "al9XzFcagwCeNbomjVswxAAAAc0"]
[Tue Jul 21 08:28:13.011347 2026] [security2:error] [pid 419508:tid 419728] [client 4.204.201.85:55526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/11.php"] [unique_id "al9XzVcagwCeNbomjVswzAAAAek"]
[Tue Jul 21 08:28:13.297039 2026] [security2:error] [pid 419508:tid 419676] [client 4.204.201.85:6285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/v2.php"] [unique_id "al9XzVcagwCeNbomjVsw0gAAAbU"]
[Tue Jul 21 08:28:13.338881 2026] [security2:error] [pid 419508:tid 419669] [client 5.31.193.106:1836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9XzVcagwCeNbomjVsw0QAAAa4"]
[Tue Jul 21 08:28:13.395011 2026] [security2:error] [pid 419508:tid 419727] [client 109.248.148.246:35858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9XzVcagwCeNbomjVsw1QAAAeg"]
[Tue Jul 21 08:28:13.395149 2026] [security2:error] [pid 419508:tid 419727] [client 109.248.148.246:35858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9XzVcagwCeNbomjVsw1QAAAeg"]
[Tue Jul 21 08:28:13.500419 2026] [security2:error] [pid 419508:tid 419725] [client 213.152.186.163:55404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9XzVcagwCeNbomjVsw4AAAAeY"]
[Tue Jul 21 08:28:13.500538 2026] [security2:error] [pid 419508:tid 419725] [client 213.152.186.163:55404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9XzVcagwCeNbomjVsw4AAAAeY"]
[Tue Jul 21 08:28:13.533722 2026] [proxy:error] [pid 418108:tid 418159] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:28:13.533761 2026] [proxy_http:error] [pid 418108:tid 418159] [remote 185.247.137.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.infoalert.com.br:2052
[Tue Jul 21 08:28:13.534413 2026] [proxy:error] [pid 418108:tid 418159] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:28:13.534445 2026] [proxy_http:error] [pid 418108:tid 418159] [remote 185.247.137.137:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.infoalert.com.br:2052
[Tue Jul 21 08:28:13.563606 2026] [security2:error] [pid 418108:tid 418291] [client 47.90.200.158:56534] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestsellerdigital.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9XzQ0cxofL2J1zwYrT7wAAAT0"]
[Tue Jul 21 08:28:13.582565 2026] [security2:error] [pid 419508:tid 419760] [client 4.204.201.85:6338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/panel.php"] [unique_id "al9XzVcagwCeNbomjVsw4QAAAgg"]
[Tue Jul 21 08:28:13.680579 2026] [security2:error] [pid 419508:tid 419726] [client 61.1.167.83:63502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XzVcagwCeNbomjVsw4wAAAec"]
[Tue Jul 21 08:28:13.680693 2026] [security2:error] [pid 419508:tid 419726] [client 61.1.167.83:63502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XzVcagwCeNbomjVsw4wAAAec"]
[Tue Jul 21 08:28:13.748503 2026] [security2:error] [pid 419508:tid 419594] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XzVcagwCeNbomjVsw5gACA1U"]
[Tue Jul 21 08:28:13.748712 2026] [security2:error] [pid 419508:tid 419755] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XzVcagwCeNbomjVsw5gACA1U"]
[Tue Jul 21 08:28:13.818164 2026] [security2:error] [pid 419508:tid 419654] [client 47.90.200.158:56541] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestsellerdigital.com.br"] [uri "/"] [unique_id "al9XzVcagwCeNbomjVsw6wAAAZ8"]
[Tue Jul 21 08:28:13.873730 2026] [security2:error] [pid 419508:tid 419693] [client 4.204.201.85:55543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/dex.php"] [unique_id "al9XzVcagwCeNbomjVsw7wAAAcY"]
[Tue Jul 21 08:28:13.907700 2026] [security2:error] [pid 418108:tid 418360] [client 122.176.100.127:57331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9XzQ0cxofL2J1zwYrT9wAAAYI"]
[Tue Jul 21 08:28:13.907845 2026] [security2:error] [pid 418108:tid 418360] [client 122.176.100.127:57331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9XzQ0cxofL2J1zwYrT9wAAAYI"]
[Tue Jul 21 08:28:14.079720 2026] [security2:error] [pid 419508:tid 419638] [client 47.90.200.158:56545] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestsellerdigital.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9XzlcagwCeNbomjVsw9AAAAY8"]
[Tue Jul 21 08:28:14.081946 2026] [security2:error] [pid 419508:tid 419757] [client 74.249.245.134:55522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/archive.php"] [unique_id "al9XzlcagwCeNbomjVsw9QAAAgU"]
[Tue Jul 21 08:28:14.144830 2026] [security2:error] [pid 419508:tid 419639] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9XzVcagwCeNbomjVsw4gAAAZA"]
[Tue Jul 21 08:28:14.223512 2026] [security2:error] [pid 419508:tid 419745] [client 4.204.201.85:22214] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "hvrtecnologia.com.br"] [uri "/1.php"] [unique_id "al9XzlcagwCeNbomjVsw9gAAAfk"]
[Tue Jul 21 08:28:14.223626 2026] [security2:error] [pid 419508:tid 419745] [client 4.204.201.85:22214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/1.php"] [unique_id "al9XzlcagwCeNbomjVsw9gAAAfk"]
[Tue Jul 21 08:28:14.435117 2026] [security2:error] [pid 418108:tid 418241] [client 47.90.200.158:56553] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestsellerdigital.com.br"] [uri "/"] [unique_id "al9Xzg0cxofL2J1zwYrT-QAAAQs"]
[Tue Jul 21 08:28:14.575410 2026] [security2:error] [pid 419508:tid 419735] [client 4.204.201.85:22239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/ms.php"] [unique_id "al9XzlcagwCeNbomjVsw_gAAAfA"]
[Tue Jul 21 08:28:14.652235 2026] [security2:error] [pid 419508:tid 419640] [client 103.151.46.103:49276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XzlcagwCeNbomjVsxAgAAAZE"]
[Tue Jul 21 08:28:14.652375 2026] [security2:error] [pid 419508:tid 419640] [client 103.151.46.103:49276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9XzlcagwCeNbomjVsxAgAAAZE"]
[Tue Jul 21 08:28:14.680210 2026] [security2:error] [pid 418108:tid 418329] [client 47.90.200.158:56558] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestsellerdigital.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9Xzg0cxofL2J1zwYrUAwAAAWM"]
[Tue Jul 21 08:28:14.828776 2026] [security2:error] [pid 419508:tid 419572] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XzlcagwCeNbomjVsxCAABtz8"]
[Tue Jul 21 08:28:14.828958 2026] [security2:error] [pid 419508:tid 419678] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9XzlcagwCeNbomjVsxCAABtz8"]
[Tue Jul 21 08:28:14.925663 2026] [security2:error] [pid 418108:tid 418335] [client 47.90.200.158:56560] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestsellerdigital.com.br"] [uri "/"] [unique_id "al9Xzg0cxofL2J1zwYrUBgAAAWk"]
[Tue Jul 21 08:28:14.985177 2026] [security2:error] [pid 418108:tid 418204] [remote 150.95.80.135:43318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.80.95.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Xzg0cxofL2J1zwYrUBwABhl0"]
[Tue Jul 21 08:28:15.009909 2026] [security2:error] [pid 419508:tid 419697] [client 4.204.201.85:55693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/memberfuns.php"] [unique_id "al9Xz1cagwCeNbomjVsxFQAAAco"]
[Tue Jul 21 08:28:15.191307 2026] [security2:error] [pid 419508:tid 419726] [client 47.90.200.158:56563] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestsellerdigital.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9Xz1cagwCeNbomjVsxHgAAAec"]
[Tue Jul 21 08:28:15.400454 2026] [security2:error] [pid 419508:tid 419689] [client 4.204.201.85:55710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/0.php"] [unique_id "al9Xz1cagwCeNbomjVsxJAAAAcI"]
[Tue Jul 21 08:28:15.442102 2026] [security2:error] [pid 419508:tid 419647] [client 47.90.200.158:56566] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "bestsellerdigital.com.br"] [uri "/"] [unique_id "al9Xz1cagwCeNbomjVsxJgAAAZg"]
[Tue Jul 21 08:28:15.604371 2026] [security2:error] [pid 419508:tid 419741] [client 213.152.186.163:55454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Xz1cagwCeNbomjVsxNAAAAfY"]
[Tue Jul 21 08:28:15.604468 2026] [security2:error] [pid 419508:tid 419741] [client 213.152.186.163:55454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Xz1cagwCeNbomjVsxNAAAAfY"]
[Tue Jul 21 08:28:15.705877 2026] [security2:error] [pid 419508:tid 419716] [client 4.204.201.85:55707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/BDKR28.php"] [unique_id "al9Xz1cagwCeNbomjVsxOgAAAd0"]
[Tue Jul 21 08:28:15.728731 2026] [security2:error] [pid 419508:tid 419649] [client 128.127.105.184:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Xz1cagwCeNbomjVsxOwAAAZo"]
[Tue Jul 21 08:28:15.728832 2026] [security2:error] [pid 419508:tid 419649] [client 128.127.105.184:53386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Xz1cagwCeNbomjVsxOwAAAZo"]
[Tue Jul 21 08:28:15.925488 2026] [security2:error] [pid 418108:tid 418280] [client 74.249.245.134:54943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/amax.php"] [unique_id "al9Xzw0cxofL2J1zwYrUFAAAATI"]
[Tue Jul 21 08:28:15.994932 2026] [security2:error] [pid 418108:tid 418295] [client 4.204.201.85:55742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/green1.php"] [unique_id "al9Xzw0cxofL2J1zwYrUFQAAAUE"]
[Tue Jul 21 08:28:16.091167 2026] [security2:error] [pid 419508:tid 419608] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9X0FcagwCeNbomjVsxQgABzWM"]
[Tue Jul 21 08:28:16.091352 2026] [security2:error] [pid 419508:tid 419700] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9X0FcagwCeNbomjVsxQgABzWM"]
[Tue Jul 21 08:28:16.164883 2026] [security2:error] [pid 419508:tid 419692] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Xz1cagwCeNbomjVsxNQAAAcU"]
[Tue Jul 21 08:28:16.284858 2026] [security2:error] [pid 419508:tid 419695] [client 4.204.201.85:22257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/nc4.php"] [unique_id "al9X0FcagwCeNbomjVsxQwAAAcg"]
[Tue Jul 21 08:28:16.590746 2026] [security2:error] [pid 418108:tid 418363] [client 4.204.201.85:6336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/a1.php"] [unique_id "al9X0A0cxofL2J1zwYrUHwAAAYU"]
[Tue Jul 21 08:28:16.874546 2026] [security2:error] [pid 418108:tid 418345] [client 4.204.201.85:6387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/eee.php"] [unique_id "al9X0A0cxofL2J1zwYrUIgAAAXM"]
[Tue Jul 21 08:28:17.210952 2026] [security2:error] [pid 419508:tid 419720] [client 187.125.243.197:53050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9X0VcagwCeNbomjVsxWwAAAeE"]
[Tue Jul 21 08:28:17.211123 2026] [security2:error] [pid 419508:tid 419720] [client 187.125.243.197:53050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9X0VcagwCeNbomjVsxWwAAAeE"]
[Tue Jul 21 08:28:17.219744 2026] [security2:error] [pid 418108:tid 418313] [client 4.204.201.85:6314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/wp-aothait.php"] [unique_id "al9X0Q0cxofL2J1zwYrULQAAAVM"]
[Tue Jul 21 08:28:17.246299 2026] [security2:error] [pid 419508:tid 419674] [client 34.76.247.13:65282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "jurencosmetics.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9X0VcagwCeNbomjVsxYgAAAbM"]
[Tue Jul 21 08:28:17.264397 2026] [autoindex:error] [pid 419508:tid 419766] [client 20.206.105.145:20110] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:28:17.332819 2026] [autoindex:error] [pid 419508:tid 419727] [client 20.206.105.145:20110] AH01276: Cannot serve directory /home2/tamoio74/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:28:17.428860 2026] [security2:error] [pid 419508:tid 419714] [client 202.179.75.202:49442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9X0VcagwCeNbomjVsxagAAAds"]
[Tue Jul 21 08:28:17.428987 2026] [security2:error] [pid 419508:tid 419714] [client 202.179.75.202:49442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9X0VcagwCeNbomjVsxagAAAds"]
[Tue Jul 21 08:28:17.437138 2026] [security2:error] [pid 419508:tid 419742] [client 150.129.202.39:12760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X0VcagwCeNbomjVsxawAAAfc"]
[Tue Jul 21 08:28:17.437252 2026] [security2:error] [pid 419508:tid 419742] [client 150.129.202.39:12760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X0VcagwCeNbomjVsxawAAAfc"]
[Tue Jul 21 08:28:17.501665 2026] [security2:error] [pid 419508:tid 419723] [client 4.204.201.85:6286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/config.json.php"] [unique_id "al9X0VcagwCeNbomjVsxbQAAAeQ"]
[Tue Jul 21 08:28:17.771787 2026] [security2:error] [pid 419508:tid 419737] [client 151.63.71.144:52855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9X0VcagwCeNbomjVsxdgAAAfI"]
[Tue Jul 21 08:28:17.771968 2026] [security2:error] [pid 419508:tid 419737] [client 151.63.71.144:52855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9X0VcagwCeNbomjVsxdgAAAfI"]
[Tue Jul 21 08:28:17.822165 2026] [security2:error] [pid 419508:tid 419725] [client 43.160.242.90:57184] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X0VcagwCeNbomjVsxbAAAAeY"]
[Tue Jul 21 08:28:17.824877 2026] [security2:error] [pid 419508:tid 419645] [client 4.204.201.85:6386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9X0VcagwCeNbomjVsxdwAAAZY"]
[Tue Jul 21 08:28:18.046584 2026] [security2:error] [pid 419508:tid 419639] [client 195.49.128.211:57350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9X0lcagwCeNbomjVsxegAAAZA"]
[Tue Jul 21 08:28:18.046763 2026] [security2:error] [pid 419508:tid 419639] [client 195.49.128.211:57350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9X0lcagwCeNbomjVsxegAAAZA"]
[Tue Jul 21 08:28:18.047656 2026] [security2:error] [pid 418108:tid 418334] [client 34.76.247.13:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.247.76.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jurencosmetics.com"] [uri "/xmlrpc.php"] [unique_id "al9X0g0cxofL2J1zwYrUMAAAAWg"]
[Tue Jul 21 08:28:18.124022 2026] [security2:error] [pid 418108:tid 418254] [client 117.213.202.34:64300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X0g0cxofL2J1zwYrUMQAAARg"]
[Tue Jul 21 08:28:18.124243 2026] [security2:error] [pid 418108:tid 418254] [client 117.213.202.34:64300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X0g0cxofL2J1zwYrUMQAAARg"]
[Tue Jul 21 08:28:18.158953 2026] [security2:error] [pid 419508:tid 419741] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X0VcagwCeNbomjVsxdAAAAfY"]
[Tue Jul 21 08:28:18.166009 2026] [security2:error] [pid 419508:tid 419695] [client 4.204.201.85:55525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/k2.php"] [unique_id "al9X0lcagwCeNbomjVsxhQAAAcg"]
[Tue Jul 21 08:28:18.499211 2026] [security2:error] [pid 419508:tid 419725] [client 43.160.242.90:57184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X0VcagwCeNbomjVsxbAAAAeY"]
[Tue Jul 21 08:28:18.538680 2026] [security2:error] [pid 419508:tid 419732] [client 4.204.201.85:55492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9X0lcagwCeNbomjVsxjwAAAe0"]
[Tue Jul 21 08:28:18.896191 2026] [security2:error] [pid 419508:tid 419688] [client 4.204.201.85:55491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9X0lcagwCeNbomjVsxmQAAAcE"]
[Tue Jul 21 08:28:19.198560 2026] [security2:error] [pid 419508:tid 419708] [client 4.204.201.85:6290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9X01cagwCeNbomjVsxqAAAAdU"]
[Tue Jul 21 08:28:19.205501 2026] [security2:error] [pid 418108:tid 418251] [client 20.197.192.193:6000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/billur.php"] [unique_id "al9X0w0cxofL2J1zwYrUPAAAARU"]
[Tue Jul 21 08:28:19.279163 2026] [security2:error] [pid 419508:tid 419706] [client 20.206.105.145:20110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/waf.php"] [unique_id "al9X01cagwCeNbomjVsxrQAAAdM"]
[Tue Jul 21 08:28:19.296801 2026] [security2:error] [pid 419508:tid 419669] [client 74.249.245.134:55548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/moon.php"] [unique_id "al9X01cagwCeNbomjVsxrgAAAa4"]
[Tue Jul 21 08:28:19.510449 2026] [security2:error] [pid 419508:tid 419640] [client 4.204.201.85:6307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/for.php"] [unique_id "al9X01cagwCeNbomjVsxuAAAAZE"]
[Tue Jul 21 08:28:19.936161 2026] [security2:error] [pid 419508:tid 419760] [client 4.204.201.85:6323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hvrtecnologia.com.br"] [uri "/raw.php"] [unique_id "al9X01cagwCeNbomjVsxyAAAAgg"]
[Tue Jul 21 08:28:19.948795 2026] [security2:error] [pid 419508:tid 419697] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X01cagwCeNbomjVsxyQAAAco"]
[Tue Jul 21 08:28:20.056417 2026] [security2:error] [pid 419508:tid 419638] [client 152.59.34.51:62282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9X1FcagwCeNbomjVsxygAAAY8"]
[Tue Jul 21 08:28:20.056597 2026] [security2:error] [pid 419508:tid 419638] [client 152.59.34.51:62282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9X1FcagwCeNbomjVsxygAAAY8"]
[Tue Jul 21 08:28:20.131416 2026] [security2:error] [pid 419508:tid 419716] [client 43.160.242.90:36748] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X1FcagwCeNbomjVsxywAAAd0"]
[Tue Jul 21 08:28:20.152746 2026] [security2:error] [pid 419508:tid 419718] [client 14.97.58.74:60488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X1FcagwCeNbomjVsxzwAAAd8"]
[Tue Jul 21 08:28:20.152895 2026] [security2:error] [pid 419508:tid 419718] [client 14.97.58.74:60488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X1FcagwCeNbomjVsxzwAAAd8"]
[Tue Jul 21 08:28:20.195801 2026] [security2:error] [pid 419508:tid 419716] [client 43.160.242.90:36748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X1FcagwCeNbomjVsxywAAAd0"]
[Tue Jul 21 08:28:20.219655 2026] [security2:error] [pid 419508:tid 419652] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X01cagwCeNbomjVsxuwAAAZ0"]
[Tue Jul 21 08:28:20.288649 2026] [security2:error] [pid 419508:tid 419717] [client 74.7.175.172:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "formaesplendida.com"] [uri "/index.php"] [unique_id "al9X1FcagwCeNbomjVsx0wAAAd4"]
[Tue Jul 21 08:28:20.289032 2026] [security2:error] [pid 419508:tid 419729] [client 74.7.175.172:48976] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "formaesplendida.com"] [uri "/robots.txt"] [unique_id "al9X1FcagwCeNbomjVsxzQAAAeo"]
[Tue Jul 21 08:28:20.404835 2026] [security2:error] [pid 419508:tid 419722] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9X1FcagwCeNbomjVsx5gAAAeM"]
[Tue Jul 21 08:28:20.862625 2026] [security2:error] [pid 419508:tid 419697] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9X1FcagwCeNbomjVsx-wAAAco"]
[Tue Jul 21 08:28:21.300320 2026] [security2:error] [pid 419508:tid 419720] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9X1VcagwCeNbomjVsyCQAAAeE"]
[Tue Jul 21 08:28:21.440460 2026] [security2:error] [pid 419508:tid 419524] [remote 154.61.75.100:54830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9X1FcagwCeNbomjVsx6gACDA8"]
[Tue Jul 21 08:28:21.746093 2026] [security2:error] [pid 419508:tid 419675] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9X1VcagwCeNbomjVsyGQAAAbQ"]
[Tue Jul 21 08:28:21.801276 2026] [security2:error] [pid 419508:tid 419745] [client 43.160.242.90:36762] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X1VcagwCeNbomjVsyGgAAAfk"]
[Tue Jul 21 08:28:21.879240 2026] [security2:error] [pid 419508:tid 419745] [client 43.160.242.90:36762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X1VcagwCeNbomjVsyGgAAAfk"]
[Tue Jul 21 08:28:21.964034 2026] [security2:error] [pid 418108:tid 418345] [client 14.245.224.124:60137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9X1Q0cxofL2J1zwYrUXAAAAXM"]
[Tue Jul 21 08:28:21.964119 2026] [security2:error] [pid 418108:tid 418345] [client 14.245.224.124:60137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9X1Q0cxofL2J1zwYrUXAAAAXM"]
[Tue Jul 21 08:28:22.149874 2026] [security2:error] [pid 418108:tid 418266] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9X1g0cxofL2J1zwYrUYAAAASQ"]
[Tue Jul 21 08:28:22.212094 2026] [security2:error] [pid 419508:tid 419669] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X1VcagwCeNbomjVsyFwAAAa4"]
[Tue Jul 21 08:28:22.276332 2026] [security2:error] [pid 418108:tid 418366] [client 20.206.105.145:20138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/xstelth.php"] [unique_id "al9X1g0cxofL2J1zwYrUYwAAAYg"]
[Tue Jul 21 08:28:22.290038 2026] [security2:error] [pid 419508:tid 419689] [client 223.181.60.88:10607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9X1lcagwCeNbomjVsyKQAAAcI"]
[Tue Jul 21 08:28:22.290752 2026] [security2:error] [pid 419508:tid 419689] [client 223.181.60.88:10607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9X1lcagwCeNbomjVsyKQAAAcI"]
[Tue Jul 21 08:28:22.382438 2026] [security2:error] [pid 418108:tid 418314] [client 74.7.244.9:37476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.x.arcoll.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9X1g0cxofL2J1zwYrUZgABVHU"]
[Tue Jul 21 08:28:22.476311 2026] [security2:error] [pid 419508:tid 419630] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9X1lcagwCeNbomjVsyMAABpHk"]
[Tue Jul 21 08:28:22.476469 2026] [security2:error] [pid 419508:tid 419659] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9X1lcagwCeNbomjVsyMAABpHk"]
[Tue Jul 21 08:28:22.583922 2026] [security2:error] [pid 419508:tid 419766] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9X1lcagwCeNbomjVsyNAAAAg4"]
[Tue Jul 21 08:28:22.892687 2026] [security2:error] [pid 418108:tid 418254] [client 195.49.128.211:49986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X1g0cxofL2J1zwYrUbAAAARg"]
[Tue Jul 21 08:28:22.892843 2026] [security2:error] [pid 418108:tid 418254] [client 195.49.128.211:49986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X1g0cxofL2J1zwYrUbAAAARg"]
[Tue Jul 21 08:28:22.976043 2026] [security2:error] [pid 419508:tid 419713] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9X1lcagwCeNbomjVsyRgAAAdo"]
[Tue Jul 21 08:28:23.076107 2026] [security2:error] [pid 419508:tid 419723] [client 74.249.245.134:55537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/ws83.php"] [unique_id "al9X11cagwCeNbomjVsyRwAAAeQ"]
[Tue Jul 21 08:28:23.196908 2026] [security2:error] [pid 419508:tid 419663] [client 103.151.46.103:49864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9X11cagwCeNbomjVsySAAAAag"]
[Tue Jul 21 08:28:23.197001 2026] [security2:error] [pid 419508:tid 419663] [client 103.151.46.103:49864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9X11cagwCeNbomjVsySAAAAag"]
[Tue Jul 21 08:28:23.292912 2026] [security2:error] [pid 419508:tid 419733] [client 34.76.247.13:51511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.247.76.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jurencosmetics.com"] [uri "/xmlrpc.php"] [unique_id "al9X11cagwCeNbomjVsyTwAAAe4"]
[Tue Jul 21 08:28:23.293037 2026] [security2:error] [pid 419508:tid 419733] [client 34.76.247.13:51511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jurencosmetics.com"] [uri "/xmlrpc.php"] [unique_id "al9X11cagwCeNbomjVsyTwAAAe4"]
[Tue Jul 21 08:28:23.384665 2026] [security2:error] [pid 419508:tid 419730] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9X11cagwCeNbomjVsyUQAAAes"]
[Tue Jul 21 08:28:23.494238 2026] [security2:error] [pid 419508:tid 419729] [client 43.160.242.90:36772] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X11cagwCeNbomjVsyVwAAAeo"]
[Tue Jul 21 08:28:23.553560 2026] [security2:error] [pid 419508:tid 419729] [client 43.160.242.90:36772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X11cagwCeNbomjVsyVwAAAeo"]
[Tue Jul 21 08:28:23.584167 2026] [security2:error] [pid 419508:tid 419668] [client 74.7.175.141:58114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "x.arcoll.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9X11cagwCeNbomjVsyWgABrQQ"]
[Tue Jul 21 08:28:23.849836 2026] [security2:error] [pid 419508:tid 419672] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9X11cagwCeNbomjVsyYQAAAbE"]
[Tue Jul 21 08:28:23.894756 2026] [security2:error] [pid 418108:tid 418289] [client 49.144.66.253:31330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9X1w0cxofL2J1zwYrUdwAAATs"]
[Tue Jul 21 08:28:23.894899 2026] [security2:error] [pid 418108:tid 418289] [client 49.144.66.253:31330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9X1w0cxofL2J1zwYrUdwAAATs"]
[Tue Jul 21 08:28:24.204323 2026] [security2:error] [pid 419508:tid 419677] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X11cagwCeNbomjVsyYAAAAbY"]
[Tue Jul 21 08:28:24.249341 2026] [security2:error] [pid 419508:tid 419683] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9X2FcagwCeNbomjVsydQAAAbw"]
[Tue Jul 21 08:28:24.412169 2026] [security2:error] [pid 419508:tid 419678] [client 122.176.100.127:57805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9X2FcagwCeNbomjVsyeQAAAbc"]
[Tue Jul 21 08:28:24.412325 2026] [security2:error] [pid 419508:tid 419678] [client 122.176.100.127:57805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9X2FcagwCeNbomjVsyeQAAAbc"]
[Tue Jul 21 08:28:24.427304 2026] [security2:error] [pid 419508:tid 419589] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X2FcagwCeNbomjVsygwACDVA"]
[Tue Jul 21 08:28:24.427495 2026] [security2:error] [pid 419508:tid 419765] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X2FcagwCeNbomjVsygwACDVA"]
[Tue Jul 21 08:28:24.626714 2026] [security2:error] [pid 418108:tid 418356] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9X2A0cxofL2J1zwYrUegAAAX4"]
[Tue Jul 21 08:28:24.775409 2026] [core:error] [pid 419508:tid 419686] [client 66.249.66.68:56091] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:28:24.775433 2026] [core:error] [pid 419508:tid 419686] [client 66.249.66.68:56091] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:28:25.109169 2026] [security2:error] [pid 419508:tid 419745] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9X2VcagwCeNbomjVsyogAAAfk"]
[Tue Jul 21 08:28:25.163445 2026] [security2:error] [pid 419508:tid 419663] [client 43.160.242.90:36788] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X2VcagwCeNbomjVsypAAAAag"]
[Tue Jul 21 08:28:25.218412 2026] [security2:error] [pid 419508:tid 419663] [client 43.160.242.90:36788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X2VcagwCeNbomjVsypAAAAag"]
[Tue Jul 21 08:28:25.311387 2026] [security2:error] [pid 418108:tid 418127] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X2Q0cxofL2J1zwYrUgQABRRA"]
[Tue Jul 21 08:28:25.311576 2026] [security2:error] [pid 418108:tid 418299] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X2Q0cxofL2J1zwYrUgQABRRA"]
[Tue Jul 21 08:28:25.968187 2026] [security2:error] [pid 419508:tid 419535] [remote 192.241.143.148:60770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X2VcagwCeNbomjVsysgAB_xo"]
[Tue Jul 21 08:28:25.968366 2026] [security2:error] [pid 419508:tid 419751] [client 192.241.143.148:60770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X2VcagwCeNbomjVsysgAB_xo"]
[Tue Jul 21 08:28:26.115055 2026] [security2:error] [pid 418108:tid 418328] [client 20.206.105.145:20167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-links.php"] [unique_id "al9X2g0cxofL2J1zwYrUiAAAAWI"]
[Tue Jul 21 08:28:26.192888 2026] [security2:error] [pid 419508:tid 419728] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X2VcagwCeNbomjVsysQAAAek"]
[Tue Jul 21 08:28:26.491675 2026] [security2:error] [pid 419508:tid 419623] [remote 57.141.18.37:58662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9X2lcagwCeNbomjVsyvQABp3I"]
[Tue Jul 21 08:28:26.623752 2026] [security2:error] [pid 418108:tid 418359] [client 185.213.175.37:23890] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bagepart.com.br"] [uri "/cgi-sys/images/favicons/favicon-76.png"] [unique_id "al9X2g0cxofL2J1zwYrUjgAAAYE"]
[Tue Jul 21 08:28:26.653057 2026] [security2:error] [pid 418108:tid 418195] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9X2g0cxofL2J1zwYrUkQABDFQ"]
[Tue Jul 21 08:28:26.653219 2026] [security2:error] [pid 418108:tid 418242] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9X2g0cxofL2J1zwYrUkQABDFQ"]
[Tue Jul 21 08:28:26.659907 2026] [security2:error] [pid 418108:tid 418315] [client 185.213.175.37:23904] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bagepart.com.br"] [uri "/cgi-sys/images/favicons/favicon-32.png"] [unique_id "al9X2g0cxofL2J1zwYrUkgAAAVU"]
[Tue Jul 21 08:28:26.828213 2026] [security2:error] [pid 419508:tid 419680] [client 43.160.242.90:36804] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X2lcagwCeNbomjVsyzAAAAbk"]
[Tue Jul 21 08:28:26.830088 2026] [security2:error] [pid 419508:tid 419692] [client 20.197.192.193:5594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/mimpi.php"] [unique_id "al9X2lcagwCeNbomjVsyzQAAAcU"]
[Tue Jul 21 08:28:26.844416 2026] [security2:error] [pid 418108:tid 418355] [client 185.213.175.37:23972] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bagepart.com.br"] [uri "/cgi-sys/images/favicons/favicon-96.png"] [unique_id "al9X2g0cxofL2J1zwYrUnAAAAX0"]
[Tue Jul 21 08:28:26.885645 2026] [security2:error] [pid 419508:tid 419680] [client 43.160.242.90:36804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X2lcagwCeNbomjVsyzAAAAbk"]
[Tue Jul 21 08:28:26.974102 2026] [security2:error] [pid 418108:tid 418358] [client 173.252.95.112:62930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9X2g0cxofL2J1zwYrUnQAAAYA"]
[Tue Jul 21 08:28:27.692993 2026] [security2:error] [pid 419508:tid 419657] [client 187.125.243.197:53774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9X21cagwCeNbomjVsy4wAAAaI"]
[Tue Jul 21 08:28:27.693180 2026] [security2:error] [pid 419508:tid 419657] [client 187.125.243.197:53774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9X21cagwCeNbomjVsy4wAAAaI"]
[Tue Jul 21 08:28:28.108897 2026] [security2:error] [pid 419508:tid 419737] [client 150.129.202.39:65296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X3FcagwCeNbomjVsy5wAAAfI"]
[Tue Jul 21 08:28:28.109003 2026] [security2:error] [pid 419508:tid 419737] [client 150.129.202.39:65296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X3FcagwCeNbomjVsy5wAAAfI"]
[Tue Jul 21 08:28:28.160247 2026] [security2:error] [pid 419508:tid 419726] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X21cagwCeNbomjVsy5AAAAec"]
[Tue Jul 21 08:28:28.300374 2026] [security2:error] [pid 418108:tid 418336] [client 202.179.75.202:50182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9X3A0cxofL2J1zwYrUqgAAAWo"]
[Tue Jul 21 08:28:28.300523 2026] [security2:error] [pid 418108:tid 418336] [client 202.179.75.202:50182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9X3A0cxofL2J1zwYrUqgAAAWo"]
[Tue Jul 21 08:28:28.309096 2026] [security2:error] [pid 418108:tid 418153] [remote 46.105.28.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9X3A0cxofL2J1zwYrUqwABPyo"]
[Tue Jul 21 08:28:28.309377 2026] [security2:error] [pid 418108:tid 418293] [client 46.105.28.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9X3A0cxofL2J1zwYrUqwABPyo"]
[Tue Jul 21 08:28:28.337238 2026] [security2:error] [pid 419508:tid 419717] [client 213.152.186.163:43468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9X3FcagwCeNbomjVsy7wAAAd4"]
[Tue Jul 21 08:28:28.337355 2026] [security2:error] [pid 419508:tid 419717] [client 213.152.186.163:43468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9X3FcagwCeNbomjVsy7wAAAd4"]
[Tue Jul 21 08:28:28.411951 2026] [security2:error] [pid 418108:tid 418349] [client 20.206.105.145:20149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9X3A0cxofL2J1zwYrUrAAAAXc"]
[Tue Jul 21 08:28:28.502952 2026] [security2:error] [pid 419508:tid 419714] [client 43.160.242.90:36810] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X3FcagwCeNbomjVsy8QAAAds"]
[Tue Jul 21 08:28:28.564712 2026] [security2:error] [pid 419508:tid 419714] [client 43.160.242.90:36810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X3FcagwCeNbomjVsy8QAAAds"]
[Tue Jul 21 08:28:28.732680 2026] [security2:error] [pid 419508:tid 419704] [client 195.49.128.211:57950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9X3FcagwCeNbomjVsy-QAAAdE"]
[Tue Jul 21 08:28:28.732792 2026] [security2:error] [pid 419508:tid 419704] [client 195.49.128.211:57950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9X3FcagwCeNbomjVsy-QAAAdE"]
[Tue Jul 21 08:28:28.792159 2026] [security2:error] [pid 419508:tid 419701] [client 74.249.245.134:55489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/CDX1.php"] [unique_id "al9X3FcagwCeNbomjVsy-wAAAc4"]
[Tue Jul 21 08:28:28.850832 2026] [security2:error] [pid 418108:tid 418270] [client 117.213.202.34:64853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X3A0cxofL2J1zwYrUwQAAASg"]
[Tue Jul 21 08:28:28.851020 2026] [security2:error] [pid 418108:tid 418270] [client 117.213.202.34:64853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X3A0cxofL2J1zwYrUwQAAASg"]
[Tue Jul 21 08:28:29.778052 2026] [security2:error] [pid 418108:tid 418313] [client 20.206.105.145:20100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tamoiomix.com.br"] [uri "/aaa.php"] [unique_id "al9X3Q0cxofL2J1zwYrU5QAAAVM"]
[Tue Jul 21 08:28:30.177735 2026] [security2:error] [pid 418108:tid 418242] [client 43.160.242.90:33854] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X3g0cxofL2J1zwYrU5wAAAQw"]
[Tue Jul 21 08:28:30.237116 2026] [security2:error] [pid 418108:tid 418242] [client 43.160.242.90:33854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "darsenavogamarine.com"] [uri "/wp-comments-post.php"] [unique_id "al9X3g0cxofL2J1zwYrU5wAAAQw"]
[Tue Jul 21 08:28:30.369822 2026] [security2:error] [pid 418108:tid 418278] [client 61.1.167.83:64021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X3g0cxofL2J1zwYrU6QAAATA"]
[Tue Jul 21 08:28:30.370110 2026] [security2:error] [pid 418108:tid 418278] [client 61.1.167.83:64021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X3g0cxofL2J1zwYrU6QAAATA"]
[Tue Jul 21 08:28:30.399560 2026] [security2:error] [pid 419508:tid 419651] [client 128.127.105.184:60732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9X3lcagwCeNbomjVszNAAAAZw"]
[Tue Jul 21 08:28:30.399688 2026] [security2:error] [pid 419508:tid 419651] [client 128.127.105.184:60732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9X3lcagwCeNbomjVszNAAAAZw"]
[Tue Jul 21 08:28:30.401053 2026] [security2:error] [pid 419508:tid 419731] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X3VcagwCeNbomjVszKQAAAew"]
[Tue Jul 21 08:28:30.691922 2026] [security2:error] [pid 419508:tid 419732] [client 152.59.34.51:62757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9X3lcagwCeNbomjVszNgAAAe0"]
[Tue Jul 21 08:28:30.692049 2026] [security2:error] [pid 419508:tid 419732] [client 152.59.34.51:62757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9X3lcagwCeNbomjVszNgAAAe0"]
[Tue Jul 21 08:28:30.984876 2026] [security2:error] [pid 419508:tid 419690] [client 137.97.59.154:12536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X3lcagwCeNbomjVszPAAAAcM"]
[Tue Jul 21 08:28:30.985003 2026] [security2:error] [pid 419508:tid 419690] [client 137.97.59.154:12536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X3lcagwCeNbomjVszPAAAAcM"]
[Tue Jul 21 08:28:31.353000 2026] [security2:error] [pid 419508:tid 419702] [client 185.198.240.106:22095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "voweltravel.com.br"] [uri "/wp-login.php"] [unique_id "al9X31cagwCeNbomjVszRgAAAc8"]
[Tue Jul 21 08:28:31.527000 2026] [security2:error] [pid 419508:tid 419633] [remote 46.105.28.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp/wp-login.php"] [unique_id "al9X31cagwCeNbomjVszRwABwXw"]
[Tue Jul 21 08:28:31.660320 2026] [security2:error] [pid 418108:tid 418344] [client 109.248.148.246:58136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9X3w0cxofL2J1zwYrU-QAAAXI"]
[Tue Jul 21 08:28:31.660444 2026] [security2:error] [pid 418108:tid 418344] [client 109.248.148.246:58136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9X3w0cxofL2J1zwYrU-QAAAXI"]
[Tue Jul 21 08:28:32.308576 2026] [security2:error] [pid 418108:tid 418327] [client 185.213.175.37:24042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "balaodevoo.com.br"] [uri "/contate-nos"] [unique_id "al9X4A0cxofL2J1zwYrVBQAAAWE"]
[Tue Jul 21 08:28:32.308679 2026] [security2:error] [pid 418108:tid 418327] [client 185.213.175.37:24042] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "balaodevoo.com.br"] [uri "/contate-nos"] [unique_id "al9X4A0cxofL2J1zwYrVBQAAAWE"]
[Tue Jul 21 08:28:32.374164 2026] [security2:error] [pid 418108:tid 418303] [client 185.213.175.37:24110] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "balaodevoo.iflyballoon.com.br"] [uri "/balloon4business"] [unique_id "al9X4A0cxofL2J1zwYrVCAAAAUk"]
[Tue Jul 21 08:28:32.374480 2026] [security2:error] [pid 418108:tid 418298] [client 185.213.175.37:24074] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "balaodevoo.iflyballoon.com.br"] [uri "/eventos.a5d0e210.js"] [unique_id "al9X4A0cxofL2J1zwYrVCQAAAUQ"]
[Tue Jul 21 08:28:32.416500 2026] [security2:error] [pid 419508:tid 419665] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X31cagwCeNbomjVszVgAAAao"]
[Tue Jul 21 08:28:32.447671 2026] [security2:error] [pid 419508:tid 419748] [client 185.213.175.37:24200] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "balaodevoo.com.br"] [uri "/turismo-e-eventos"] [unique_id "al9X4FcagwCeNbomjVszawAAAfw"]
[Tue Jul 21 08:28:32.468404 2026] [security2:error] [pid 419508:tid 419722] [client 185.213.175.37:24142] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "balaodevoo.iflyballoon.com.br"] [uri "/seja-um-balonista"] [unique_id "al9X4FcagwCeNbomjVszbQAAAeM"]
[Tue Jul 21 08:28:32.469906 2026] [security2:error] [pid 419508:tid 419729] [client 185.213.175.37:24192] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "balaodevoo.com.br"] [uri "/eventos.a5d0e210.js"] [unique_id "al9X4FcagwCeNbomjVszbgAAAeo"]
[Tue Jul 21 08:28:32.794881 2026] [security2:error] [pid 419508:tid 419747] [client 14.245.224.124:60619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9X4FcagwCeNbomjVszcgAAAfs"]
[Tue Jul 21 08:28:32.796635 2026] [security2:error] [pid 419508:tid 419747] [client 14.245.224.124:60619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9X4FcagwCeNbomjVszcgAAAfs"]
[Tue Jul 21 08:28:32.898776 2026] [security2:error] [pid 419508:tid 419615] [remote 35.252.209.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.209.252.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bomnegociopromotora.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X4FcagwCeNbomjVszdwABkGo"]
[Tue Jul 21 08:28:33.132770 2026] [security2:error] [pid 418108:tid 418159] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9X4Q0cxofL2J1zwYrVFQABLzA"]
[Tue Jul 21 08:28:33.132967 2026] [security2:error] [pid 418108:tid 418277] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9X4Q0cxofL2J1zwYrVFQABLzA"]
[Tue Jul 21 08:28:33.159023 2026] [security2:error] [pid 419508:tid 419540] [remote 35.252.209.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bomnegociopromotora.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9X4VcagwCeNbomjVszfAAB3x8"]
[Tue Jul 21 08:28:33.238770 2026] [security2:error] [pid 418108:tid 418359] [client 223.181.60.88:23685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9X4Q0cxofL2J1zwYrVFgAAAYE"]
[Tue Jul 21 08:28:33.240045 2026] [security2:error] [pid 418108:tid 418359] [client 223.181.60.88:23685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9X4Q0cxofL2J1zwYrVFgAAAYE"]
[Tue Jul 21 08:28:33.507082 2026] [security2:error] [pid 418108:tid 418278] [client 195.49.128.211:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X4Q0cxofL2J1zwYrVGAAAATA"]
[Tue Jul 21 08:28:33.507225 2026] [security2:error] [pid 418108:tid 418278] [client 195.49.128.211:50568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X4Q0cxofL2J1zwYrVGAAAATA"]
[Tue Jul 21 08:28:33.562456 2026] [security2:error] [pid 419508:tid 419523] [remote 35.252.209.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bomnegociopromotora.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9X4VcagwCeNbomjVszhgACCA4"]
[Tue Jul 21 08:28:33.730946 2026] [security2:error] [pid 418108:tid 418322] [client 103.151.46.103:50408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9X4Q0cxofL2J1zwYrVGQAAAVw"]
[Tue Jul 21 08:28:33.731066 2026] [security2:error] [pid 418108:tid 418322] [client 103.151.46.103:50408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9X4Q0cxofL2J1zwYrVGQAAAVw"]
[Tue Jul 21 08:28:33.819257 2026] [security2:error] [pid 419508:tid 419746] [client 74.249.245.134:54929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/inputs.php"] [unique_id "al9X4VcagwCeNbomjVszigAAAfo"]
[Tue Jul 21 08:28:34.050359 2026] [security2:error] [pid 419508:tid 419568] [remote 35.252.209.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bomnegociopromotora.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9X4lcagwCeNbomjVszlgABuzs"]
[Tue Jul 21 08:28:34.334856 2026] [security2:error] [pid 419508:tid 419570] [remote 35.252.209.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bomnegociopromotora.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9X4lcagwCeNbomjVszlwABlT0"]
[Tue Jul 21 08:28:34.394910 2026] [security2:error] [pid 419508:tid 419566] [remote 45.150.79.142:52136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/wp-login.php"] [unique_id "al9X4lcagwCeNbomjVszmQAB4Tk"]
[Tue Jul 21 08:28:34.463264 2026] [security2:error] [pid 419508:tid 419755] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X4VcagwCeNbomjVszkwAAAgM"]
[Tue Jul 21 08:28:34.634472 2026] [security2:error] [pid 419508:tid 419573] [remote 35.252.209.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bomnegociopromotora.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9X4lcagwCeNbomjVszpAAB7kA"]
[Tue Jul 21 08:28:34.866600 2026] [security2:error] [pid 419508:tid 419641] [client 49.144.66.253:31725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9X4lcagwCeNbomjVszpgAAAZI"]
[Tue Jul 21 08:28:34.866754 2026] [security2:error] [pid 419508:tid 419641] [client 49.144.66.253:31725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9X4lcagwCeNbomjVszpgAAAZI"]
[Tue Jul 21 08:28:34.895973 2026] [security2:error] [pid 418108:tid 418290] [client 122.176.100.127:58267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9X4g0cxofL2J1zwYrVHwAAATw"]
[Tue Jul 21 08:28:34.896114 2026] [security2:error] [pid 418108:tid 418290] [client 122.176.100.127:58267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9X4g0cxofL2J1zwYrVHwAAATw"]
[Tue Jul 21 08:28:35.136917 2026] [security2:error] [pid 419508:tid 419607] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X41cagwCeNbomjVszsAABv2I"]
[Tue Jul 21 08:28:35.137115 2026] [security2:error] [pid 419508:tid 419686] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X41cagwCeNbomjVszsAABv2I"]
[Tue Jul 21 08:28:35.187103 2026] [autoindex:error] [pid 419508:tid 419677] [client 43.153.19.83:42316] AH01276: Cannot serve directory /home1/domusc58/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:28:35.196456 2026] [security2:error] [pid 419508:tid 419601] [remote 35.252.209.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bomnegociopromotora.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9X41cagwCeNbomjVsztAAB5lw"]
[Tue Jul 21 08:28:35.425157 2026] [security2:error] [pid 419508:tid 419564] [remote 35.252.209.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bomnegociopromotora.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9X41cagwCeNbomjVszxAAB5zc"]
[Tue Jul 21 08:28:35.510619 2026] [security2:error] [pid 418108:tid 418234] [remote 97.74.87.194:48604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "growe-ag.jaypi.com.br"] [uri "/wp-login.php"] [unique_id "al9X4w0cxofL2J1zwYrVJwABZ3s"]
[Tue Jul 21 08:28:35.663294 2026] [security2:error] [pid 419508:tid 419556] [remote 35.252.209.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bomnegociopromotora.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9X41cagwCeNbomjVszzQABmi8"]
[Tue Jul 21 08:28:35.765082 2026] [security2:error] [pid 419508:tid 419533] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X41cagwCeNbomjVszzgACDRg"]
[Tue Jul 21 08:28:35.765279 2026] [security2:error] [pid 419508:tid 419765] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X41cagwCeNbomjVszzgACDRg"]
[Tue Jul 21 08:28:35.913748 2026] [security2:error] [pid 419508:tid 419535] [remote 35.252.209.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bomnegociopromotora.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9X41cagwCeNbomjVsz0AAB3ho"]
[Tue Jul 21 08:28:36.193457 2026] [security2:error] [pid 419508:tid 419579] [remote 35.252.209.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bomnegociopromotora.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9X5FcagwCeNbomjVsz1QACCUY"]
[Tue Jul 21 08:28:36.320645 2026] [security2:error] [pid 419508:tid 419756] [client 213.152.186.163:43470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9X5FcagwCeNbomjVsz2AAAAgQ"]
[Tue Jul 21 08:28:36.320750 2026] [security2:error] [pid 419508:tid 419756] [client 213.152.186.163:43470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9X5FcagwCeNbomjVsz2AAAAgQ"]
[Tue Jul 21 08:28:36.398665 2026] [security2:error] [pid 419508:tid 419552] [remote 35.252.209.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bomnegociopromotora.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9X5FcagwCeNbomjVsz2QABmCs"]
[Tue Jul 21 08:28:36.700470 2026] [security2:error] [pid 419508:tid 419742] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X5FcagwCeNbomjVsz1gAAAfc"]
[Tue Jul 21 08:28:36.712801 2026] [security2:error] [pid 419508:tid 419610] [remote 35.252.209.37:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bomnegociopromotora.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9X5FcagwCeNbomjVsz4gABtGU"]
[Tue Jul 21 08:28:37.149916 2026] [security2:error] [pid 419508:tid 419551] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9X5VcagwCeNbomjVsz6AABxSo"]
[Tue Jul 21 08:28:37.150067 2026] [security2:error] [pid 419508:tid 419692] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9X5VcagwCeNbomjVsz6AABxSo"]
[Tue Jul 21 08:28:37.264688 2026] [security2:error] [pid 418108:tid 418362] [client 5.31.193.106:1792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9X4w0cxofL2J1zwYrVKQAAAYQ"]
[Tue Jul 21 08:28:37.953980 2026] [security2:error] [pid 418108:tid 418196] [remote 47.86.33.52:60016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oferta.happynbox.com.br"] [uri "/wp-login.php"] [unique_id "al9X5Q0cxofL2J1zwYrVPQABfFU"]
[Tue Jul 21 08:28:38.153847 2026] [security2:error] [pid 419508:tid 419649] [client 187.125.243.197:54393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9X5lcagwCeNbomjVsz-gAAAZo"]
[Tue Jul 21 08:28:38.153956 2026] [security2:error] [pid 419508:tid 419649] [client 187.125.243.197:54393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9X5lcagwCeNbomjVsz-gAAAZo"]
[Tue Jul 21 08:28:38.322983 2026] [security2:error] [pid 419508:tid 419531] [remote 154.61.75.100:39018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9X5lcagwCeNbomjVs0AAACBxY"]
[Tue Jul 21 08:28:38.323266 2026] [security2:error] [pid 419508:tid 419759] [client 154.61.75.100:39018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9X5lcagwCeNbomjVs0AAACBxY"]
[Tue Jul 21 08:28:38.613745 2026] [security2:error] [pid 419508:tid 419516] [remote 49.13.1.223:36454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9X5lcagwCeNbomjVs0BQAB0Qc"]
[Tue Jul 21 08:28:38.613965 2026] [security2:error] [pid 419508:tid 419704] [client 49.13.1.223:36454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9X5lcagwCeNbomjVs0BQAB0Qc"]
[Tue Jul 21 08:28:38.745639 2026] [security2:error] [pid 419508:tid 419673] [client 150.129.202.39:13228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X5lcagwCeNbomjVs0BwAAAbI"]
[Tue Jul 21 08:28:38.745783 2026] [security2:error] [pid 419508:tid 419673] [client 150.129.202.39:13228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X5lcagwCeNbomjVs0BwAAAbI"]
[Tue Jul 21 08:28:38.764747 2026] [security2:error] [pid 419508:tid 419752] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X5lcagwCeNbomjVsz_gAAAgA"]
[Tue Jul 21 08:28:39.180474 2026] [security2:error] [pid 419508:tid 419695] [client 202.179.75.202:40324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9X51cagwCeNbomjVs0EQAAAcg"]
[Tue Jul 21 08:28:39.180598 2026] [security2:error] [pid 419508:tid 419695] [client 202.179.75.202:40324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9X51cagwCeNbomjVs0EQAAAcg"]
[Tue Jul 21 08:28:39.289179 2026] [security2:error] [pid 419508:tid 419638] [client 195.49.128.211:58545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9X51cagwCeNbomjVs0FQAAAY8"]
[Tue Jul 21 08:28:39.289376 2026] [security2:error] [pid 419508:tid 419638] [client 195.49.128.211:58545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9X51cagwCeNbomjVs0FQAAAY8"]
[Tue Jul 21 08:28:39.537810 2026] [security2:error] [pid 419508:tid 419661] [client 117.213.202.34:65406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X51cagwCeNbomjVs0FwAAAaY"]
[Tue Jul 21 08:28:39.537997 2026] [security2:error] [pid 419508:tid 419661] [client 117.213.202.34:65406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X51cagwCeNbomjVs0FwAAAaY"]
[Tue Jul 21 08:28:40.092309 2026] [security2:error] [pid 419508:tid 419621] [remote 117.0.21.154:44516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dener.design"] [uri "/wp-login.php"] [unique_id "al9X6FcagwCeNbomjVs0HgABk3A"]
[Tue Jul 21 08:28:40.920276 2026] [security2:error] [pid 418108:tid 418321] [client 65.21.113.253:32934] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X6A0cxofL2J1zwYrVYAAAAVs"]
[Tue Jul 21 08:28:40.996601 2026] [security2:error] [pid 418108:tid 418163] [remote 104.207.45.8:13751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.45.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9X6A0cxofL2J1zwYrVZAABSzQ"]
[Tue Jul 21 08:28:41.370338 2026] [security2:error] [pid 418108:tid 418352] [client 152.59.34.51:63251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9X6Q0cxofL2J1zwYrVawAAAXo"]
[Tue Jul 21 08:28:41.370525 2026] [security2:error] [pid 418108:tid 418352] [client 152.59.34.51:63251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9X6Q0cxofL2J1zwYrVawAAAXo"]
[Tue Jul 21 08:28:41.416559 2026] [security2:error] [pid 418108:tid 418228] [remote 81.173.115.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deiacakes.com"] [uri "/wp-login.php"] [unique_id "al9X6Q0cxofL2J1zwYrVbAABUXU"]
[Tue Jul 21 08:28:41.536824 2026] [security2:error] [pid 418108:tid 418325] [client 111.93.58.162:30616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X6Q0cxofL2J1zwYrVbQAAAV8"]
[Tue Jul 21 08:28:41.536972 2026] [security2:error] [pid 418108:tid 418325] [client 111.93.58.162:30616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X6Q0cxofL2J1zwYrVbQAAAV8"]
[Tue Jul 21 08:28:41.580225 2026] [security2:error] [pid 419508:tid 419657] [client 20.197.192.193:46148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/dp.php"] [unique_id "al9X6VcagwCeNbomjVs0MwAAAaI"]
[Tue Jul 21 08:28:41.673580 2026] [security2:error] [pid 419508:tid 419749] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X6VcagwCeNbomjVs0LAAAAf0"]
[Tue Jul 21 08:28:41.717845 2026] [security2:error] [pid 418108:tid 418250] [client 20.104.96.117:46548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9X6A0cxofL2J1zwYrVXgAAARQ"]
[Tue Jul 21 08:28:41.944832 2026] [security2:error] [pid 419508:tid 419638] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/index.php"] [unique_id "al9X6VcagwCeNbomjVs0QQAAAY8"]
[Tue Jul 21 08:28:41.945498 2026] [security2:error] [pid 419508:tid 419692] [client 20.10.88.227:2305] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/robots.txt"] [unique_id "al9X6VcagwCeNbomjVs0PgAAAcU"]
[Tue Jul 21 08:28:42.171909 2026] [security2:error] [pid 418108:tid 418334] [client 59.184.181.113:50395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.181.184.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9X6g0cxofL2J1zwYrVcQAAAWg"]
[Tue Jul 21 08:28:42.172132 2026] [security2:error] [pid 418108:tid 418334] [client 59.184.181.113:50395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9X6g0cxofL2J1zwYrVcQAAAWg"]
[Tue Jul 21 08:28:42.214598 2026] [security2:error] [pid 419508:tid 419725] [client 20.104.96.117:46582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9X6lcagwCeNbomjVs0SQAAAeY"]
[Tue Jul 21 08:28:42.589130 2026] [security2:error] [pid 419508:tid 419740] [client 20.104.96.117:46519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/xyn.php"] [unique_id "al9X6lcagwCeNbomjVs0VwAAAfU"]
[Tue Jul 21 08:28:42.826996 2026] [security2:error] [pid 419508:tid 419670] [client 89.238.167.134:60596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9X6lcagwCeNbomjVs0XwAAAa8"]
[Tue Jul 21 08:28:42.827098 2026] [security2:error] [pid 419508:tid 419670] [client 89.238.167.134:60596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9X6lcagwCeNbomjVs0XwAAAa8"]
[Tue Jul 21 08:28:42.950369 2026] [security2:error] [pid 419508:tid 419755] [client 20.104.96.117:46522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/patie.php"] [unique_id "al9X6lcagwCeNbomjVs0ZAAAAgM"]
[Tue Jul 21 08:28:42.961830 2026] [security2:error] [pid 418108:tid 418279] [client 213.152.186.163:45044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9X6g0cxofL2J1zwYrVgQAAATE"]
[Tue Jul 21 08:28:42.961957 2026] [security2:error] [pid 418108:tid 418279] [client 213.152.186.163:45044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9X6g0cxofL2J1zwYrVgQAAATE"]
[Tue Jul 21 08:28:43.263646 2026] [security2:error] [pid 419508:tid 419709] [client 20.104.96.117:46502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/aa.php"] [unique_id "al9X61cagwCeNbomjVs0aQAAAdY"]
[Tue Jul 21 08:28:43.509985 2026] [security2:error] [pid 419508:tid 419702] [client 89.238.167.134:45026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9X61cagwCeNbomjVs0bQAAAc8"]
[Tue Jul 21 08:28:43.510087 2026] [security2:error] [pid 419508:tid 419702] [client 89.238.167.134:45026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9X61cagwCeNbomjVs0bQAAAc8"]
[Tue Jul 21 08:28:43.512388 2026] [security2:error] [pid 419508:tid 419646] [client 14.245.224.124:61083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9X61cagwCeNbomjVs0bgAAAZc"]
[Tue Jul 21 08:28:43.512670 2026] [security2:error] [pid 419508:tid 419646] [client 14.245.224.124:61083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9X61cagwCeNbomjVs0bgAAAZc"]
[Tue Jul 21 08:28:43.607894 2026] [security2:error] [pid 419508:tid 419648] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X61cagwCeNbomjVs0ZwAAAZk"]
[Tue Jul 21 08:28:43.643754 2026] [security2:error] [pid 419508:tid 419641] [client 20.104.96.117:46571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/xwpg.php"] [unique_id "al9X61cagwCeNbomjVs0cQAAAZI"]
[Tue Jul 21 08:28:43.806323 2026] [security2:error] [pid 419508:tid 419663] [client 74.249.245.134:54925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/ms-edit.php"] [unique_id "al9X61cagwCeNbomjVs0dQAAAag"]
[Tue Jul 21 08:28:43.973169 2026] [security2:error] [pid 418108:tid 418127] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9X6w0cxofL2J1zwYrVjQABZxA"]
[Tue Jul 21 08:28:43.973278 2026] [security2:error] [pid 418108:tid 418333] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9X6w0cxofL2J1zwYrVjQABZxA"]
[Tue Jul 21 08:28:43.989509 2026] [security2:error] [pid 419508:tid 419665] [client 20.104.96.117:46489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/ops.php"] [unique_id "al9X61cagwCeNbomjVs0fQAAAao"]
[Tue Jul 21 08:28:44.090019 2026] [security2:error] [pid 419508:tid 419701] [client 195.49.128.211:51156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X7FcagwCeNbomjVs0gQAAAc4"]
[Tue Jul 21 08:28:44.090165 2026] [security2:error] [pid 419508:tid 419701] [client 195.49.128.211:51156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X7FcagwCeNbomjVs0gQAAAc4"]
[Tue Jul 21 08:28:44.155057 2026] [security2:error] [pid 418108:tid 418271] [client 223.181.60.88:7994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9X7A0cxofL2J1zwYrVjwAAASk"]
[Tue Jul 21 08:28:44.155186 2026] [security2:error] [pid 418108:tid 418271] [client 223.181.60.88:7994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9X7A0cxofL2J1zwYrVjwAAASk"]
[Tue Jul 21 08:28:44.362094 2026] [security2:error] [pid 419508:tid 419653] [client 103.151.46.103:50896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9X7FcagwCeNbomjVs0jAAAAZ4"]
[Tue Jul 21 08:28:44.362270 2026] [security2:error] [pid 419508:tid 419653] [client 103.151.46.103:50896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9X7FcagwCeNbomjVs0jAAAAZ4"]
[Tue Jul 21 08:28:44.458467 2026] [security2:error] [pid 419508:tid 419764] [client 20.104.96.117:46499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/mac.php"] [unique_id "al9X7FcagwCeNbomjVs0kQAAAgw"]
[Tue Jul 21 08:28:44.874185 2026] [security2:error] [pid 419508:tid 419659] [client 20.104.96.117:46577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/mg.php"] [unique_id "al9X7FcagwCeNbomjVs0lwAAAaQ"]
[Tue Jul 21 08:28:45.429911 2026] [security2:error] [pid 419508:tid 419696] [client 20.104.96.117:46521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-post-data.php"] [unique_id "al9X7VcagwCeNbomjVs0oAAAAck"]
[Tue Jul 21 08:28:45.485067 2026] [security2:error] [pid 419508:tid 419698] [client 122.176.100.127:58746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9X7VcagwCeNbomjVs0pQAAAcs"]
[Tue Jul 21 08:28:45.485149 2026] [security2:error] [pid 419508:tid 419698] [client 122.176.100.127:58746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9X7VcagwCeNbomjVs0pQAAAcs"]
[Tue Jul 21 08:28:45.583401 2026] [security2:error] [pid 419508:tid 419749] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X7VcagwCeNbomjVs0ngAAAf0"]
[Tue Jul 21 08:28:45.828375 2026] [security2:error] [pid 419508:tid 419712] [client 49.144.66.253:32177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9X7VcagwCeNbomjVs0rwAAAdk"]
[Tue Jul 21 08:28:45.828529 2026] [security2:error] [pid 419508:tid 419712] [client 49.144.66.253:32177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9X7VcagwCeNbomjVs0rwAAAdk"]
[Tue Jul 21 08:28:45.880200 2026] [security2:error] [pid 419508:tid 419601] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X7VcagwCeNbomjVs0sQABqlw"]
[Tue Jul 21 08:28:45.880350 2026] [security2:error] [pid 419508:tid 419665] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X7VcagwCeNbomjVs0sQABqlw"]
[Tue Jul 21 08:28:45.930415 2026] [security2:error] [pid 419508:tid 419725] [client 20.104.96.117:46580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/pucci.php"] [unique_id "al9X7VcagwCeNbomjVs0sgAAAeY"]
[Tue Jul 21 08:28:46.235258 2026] [security2:error] [pid 418108:tid 418199] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X7g0cxofL2J1zwYrVugABfFg"]
[Tue Jul 21 08:28:46.235391 2026] [security2:error] [pid 418108:tid 418354] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X7g0cxofL2J1zwYrVugABfFg"]
[Tue Jul 21 08:28:46.299117 2026] [security2:error] [pid 418108:tid 418290] [client 20.104.96.117:46509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/black.php"] [unique_id "al9X7g0cxofL2J1zwYrVuwAAATw"]
[Tue Jul 21 08:28:46.478134 2026] [security2:error] [pid 418108:tid 418174] [remote 66.249.74.165:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "nerdshoppe.com.br"] [uri "/robots.txt"] [unique_id "al9X7g0cxofL2J1zwYrVvwABhj8"]
[Tue Jul 21 08:28:46.618871 2026] [security2:error] [pid 418108:tid 418308] [client 20.104.96.117:46578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/zlece.php"] [unique_id "al9X7g0cxofL2J1zwYrVwwAAAU4"]
[Tue Jul 21 08:28:46.670059 2026] [proxy:error] [pid 418108:tid 418112] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:28:46.670099 2026] [proxy_http:error] [pid 418108:tid 418112] [remote 74.7.175.152:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:28:46.670602 2026] [proxy:error] [pid 418108:tid 418112] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:28:46.670621 2026] [proxy_http:error] [pid 418108:tid 418112] [remote 74.7.175.152:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:28:46.923969 2026] [security2:error] [pid 419508:tid 419619] [remote 66.249.74.165:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "nerdshoppe.com.br"] [uri "/wp-content/uploads/2024/02/pexels-flavien-beauvais-13456715-scaled.jpg"] [unique_id "al9X7lcagwCeNbomjVs0zAABkW4"]
[Tue Jul 21 08:28:46.973946 2026] [security2:error] [pid 419508:tid 419659] [client 20.104.96.117:46585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/vssrs.php"] [unique_id "al9X7lcagwCeNbomjVs0zgAAAaQ"]
[Tue Jul 21 08:28:47.240355 2026] [security2:error] [pid 419508:tid 419649] [client 89.238.167.134:45040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9X71cagwCeNbomjVs01QAAAZo"]
[Tue Jul 21 08:28:47.240458 2026] [security2:error] [pid 419508:tid 419649] [client 89.238.167.134:45040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9X71cagwCeNbomjVs01QAAAZo"]
[Tue Jul 21 08:28:47.300229 2026] [security2:error] [pid 419508:tid 419735] [client 20.104.96.117:62703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wicked.php"] [unique_id "al9X71cagwCeNbomjVs02QAAAfA"]
[Tue Jul 21 08:28:47.568213 2026] [security2:error] [pid 419508:tid 419650] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X71cagwCeNbomjVs00AAAAZs"]
[Tue Jul 21 08:28:47.616857 2026] [security2:error] [pid 418108:tid 418316] [client 20.104.96.117:46472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/24.php"] [unique_id "al9X7w0cxofL2J1zwYrV2gAAAVY"]
[Tue Jul 21 08:28:47.675042 2026] [security2:error] [pid 419508:tid 419602] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9X71cagwCeNbomjVs05QABmV0"]
[Tue Jul 21 08:28:47.675229 2026] [security2:error] [pid 419508:tid 419648] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9X71cagwCeNbomjVs05QABmV0"]
[Tue Jul 21 08:28:47.974693 2026] [security2:error] [pid 418108:tid 418271] [client 20.104.96.117:46470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/xacs.php"] [unique_id "al9X7w0cxofL2J1zwYrV6AAAASk"]
[Tue Jul 21 08:28:48.308318 2026] [security2:error] [pid 419508:tid 419692] [client 20.104.96.117:46574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/zildan.php"] [unique_id "al9X8FcagwCeNbomjVs08QAAAcU"]
[Tue Jul 21 08:28:48.604960 2026] [security2:error] [pid 418108:tid 418359] [client 187.125.243.197:54923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9X8A0cxofL2J1zwYrV8wAAAYE"]
[Tue Jul 21 08:28:48.605052 2026] [security2:error] [pid 418108:tid 418359] [client 187.125.243.197:54923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9X8A0cxofL2J1zwYrV8wAAAYE"]
[Tue Jul 21 08:28:48.743401 2026] [security2:error] [pid 419508:tid 419670] [client 20.104.96.117:46561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/csa.php"] [unique_id "al9X8FcagwCeNbomjVs0_wAAAa8"]
[Tue Jul 21 08:28:49.084954 2026] [security2:error] [pid 419508:tid 419645] [client 74.249.245.134:54923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/simple.php"] [unique_id "al9X8VcagwCeNbomjVs1IgAAAZY"]
[Tue Jul 21 08:28:49.350078 2026] [security2:error] [pid 419508:tid 419752] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X8FcagwCeNbomjVs1EQAAAgA"]
[Tue Jul 21 08:28:49.361752 2026] [security2:error] [pid 418108:tid 418344] [client 20.104.96.117:46479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/w3llscc.php"] [unique_id "al9X8Q0cxofL2J1zwYrWAgAAAXI"]
[Tue Jul 21 08:28:49.384630 2026] [security2:error] [pid 419508:tid 419683] [client 150.129.202.39:64847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X8VcagwCeNbomjVs1LQAAAbw"]
[Tue Jul 21 08:28:49.384772 2026] [security2:error] [pid 419508:tid 419683] [client 150.129.202.39:64847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X8VcagwCeNbomjVs1LQAAAbw"]
[Tue Jul 21 08:28:49.540447 2026] [security2:error] [pid 418108:tid 418300] [client 20.220.225.223:19687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/hp3.php"] [unique_id "al9X8Q0cxofL2J1zwYrWAwAAAUY"]
[Tue Jul 21 08:28:49.629640 2026] [security2:error] [pid 419508:tid 419575] [remote 194.164.170.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.170.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fidellium.com"] [uri "/wp-login.php"] [unique_id "al9X8FcagwCeNbomjVs09AABnkI"]
[Tue Jul 21 08:28:49.913898 2026] [security2:error] [pid 419508:tid 419658] [client 195.49.128.211:59146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9X8VcagwCeNbomjVs1PQAAAaM"]
[Tue Jul 21 08:28:49.914037 2026] [security2:error] [pid 419508:tid 419658] [client 195.49.128.211:59146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9X8VcagwCeNbomjVs1PQAAAaM"]
[Tue Jul 21 08:28:50.036803 2026] [security2:error] [pid 419508:tid 419723] [client 20.104.96.117:46565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wpx.php"] [unique_id "al9X8lcagwCeNbomjVs1PwAAAeQ"]
[Tue Jul 21 08:28:50.076602 2026] [security2:error] [pid 419508:tid 419685] [client 202.179.75.202:35224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9X8lcagwCeNbomjVs1QQAAAb4"]
[Tue Jul 21 08:28:50.076714 2026] [security2:error] [pid 419508:tid 419685] [client 202.179.75.202:35224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9X8lcagwCeNbomjVs1QQAAAb4"]
[Tue Jul 21 08:28:50.313903 2026] [security2:error] [pid 419508:tid 419649] [client 117.213.202.34:49566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X8lcagwCeNbomjVs1RwAAAZo"]
[Tue Jul 21 08:28:50.314139 2026] [security2:error] [pid 419508:tid 419649] [client 117.213.202.34:49566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X8lcagwCeNbomjVs1RwAAAZo"]
[Tue Jul 21 08:28:50.489397 2026] [security2:error] [pid 419508:tid 419752] [client 109.248.148.246:57312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9X8lcagwCeNbomjVs1SwAAAgA"]
[Tue Jul 21 08:28:50.489509 2026] [security2:error] [pid 419508:tid 419752] [client 109.248.148.246:57312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9X8lcagwCeNbomjVs1SwAAAgA"]
[Tue Jul 21 08:28:50.666982 2026] [security2:error] [pid 419508:tid 419587] [remote 167.71.132.111:40524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.132.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "odontoclinicms.com.br"] [uri "/wp-login.php"] [unique_id "al9X8lcagwCeNbomjVs1VgAB504"]
[Tue Jul 21 08:28:50.680081 2026] [security2:error] [pid 419508:tid 419719] [client 61.1.167.83:64550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X8lcagwCeNbomjVs1WAAAAeA"]
[Tue Jul 21 08:28:50.680240 2026] [security2:error] [pid 419508:tid 419719] [client 61.1.167.83:64550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X8lcagwCeNbomjVs1WAAAAeA"]
[Tue Jul 21 08:28:50.703403 2026] [security2:error] [pid 419508:tid 419641] [client 128.127.105.184:55562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9X8lcagwCeNbomjVs1WQAAAZI"]
[Tue Jul 21 08:28:50.703508 2026] [security2:error] [pid 419508:tid 419641] [client 128.127.105.184:55562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9X8lcagwCeNbomjVs1WQAAAZI"]
[Tue Jul 21 08:28:50.831171 2026] [security2:error] [pid 419508:tid 419531] [remote 168.119.138.253:36682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.138.119.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9X8VcagwCeNbomjVs1MAAB9hY"]
[Tue Jul 21 08:28:51.097465 2026] [security2:error] [pid 419508:tid 419735] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X8lcagwCeNbomjVs1UgAAAfA"]
[Tue Jul 21 08:28:51.111663 2026] [security2:error] [pid 419508:tid 419712] [client 20.104.96.117:46515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-css.php"] [unique_id "al9X81cagwCeNbomjVs1agAAAdk"]
[Tue Jul 21 08:28:51.267350 2026] [security2:error] [pid 419508:tid 419671] [client 74.7.244.9:33872] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "choppon24h.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9X81cagwCeNbomjVs1dgABsGs"]
[Tue Jul 21 08:28:51.426017 2026] [security2:error] [pid 418108:tid 418359] [client 109.248.148.246:57326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9X8w0cxofL2J1zwYrWHgAAAYE"]
[Tue Jul 21 08:28:51.426092 2026] [security2:error] [pid 418108:tid 418359] [client 109.248.148.246:57326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9X8w0cxofL2J1zwYrWHgAAAYE"]
[Tue Jul 21 08:28:51.713523 2026] [security2:error] [pid 419508:tid 419668] [client 89.238.167.134:53112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9X81cagwCeNbomjVs1iwAAAa0"]
[Tue Jul 21 08:28:51.713619 2026] [security2:error] [pid 419508:tid 419668] [client 89.238.167.134:53112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9X81cagwCeNbomjVs1iwAAAa0"]
[Tue Jul 21 08:28:51.774110 2026] [security2:error] [pid 419508:tid 419764] [client 20.220.225.223:19691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/aa1.php"] [unique_id "al9X81cagwCeNbomjVs1jQAAAgw"]
[Tue Jul 21 08:28:52.059787 2026] [security2:error] [pid 419508:tid 419700] [client 20.104.96.117:62697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/ho.php"] [unique_id "al9X9FcagwCeNbomjVs1lwAAAc0"]
[Tue Jul 21 08:28:52.153276 2026] [security2:error] [pid 419508:tid 419669] [client 152.59.34.51:63735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9X9FcagwCeNbomjVs1nQAAAa4"]
[Tue Jul 21 08:28:52.157934 2026] [security2:error] [pid 419508:tid 419669] [client 152.59.34.51:63735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9X9FcagwCeNbomjVs1nQAAAa4"]
[Tue Jul 21 08:28:52.182148 2026] [security2:error] [pid 418108:tid 418272] [client 103.255.105.130:46801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X9A0cxofL2J1zwYrWJQAAASo"]
[Tue Jul 21 08:28:52.182308 2026] [security2:error] [pid 418108:tid 418272] [client 103.255.105.130:46801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X9A0cxofL2J1zwYrWJQAAASo"]
[Tue Jul 21 08:28:52.646717 2026] [security2:error] [pid 419508:tid 419760] [client 59.184.181.113:51116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.181.184.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9X9FcagwCeNbomjVs1tgAAAgg"]
[Tue Jul 21 08:28:52.646893 2026] [security2:error] [pid 419508:tid 419760] [client 59.184.181.113:51116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9X9FcagwCeNbomjVs1tgAAAgg"]
[Tue Jul 21 08:28:52.849065 2026] [security2:error] [pid 419508:tid 419660] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X9FcagwCeNbomjVs1qgAAAaU"]
[Tue Jul 21 08:28:53.716328 2026] [security2:error] [pid 419508:tid 419654] [client 20.104.96.117:46478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/xy.php"] [unique_id "al9X9VcagwCeNbomjVs2BQAAAZ8"]
[Tue Jul 21 08:28:53.941701 2026] [security2:error] [pid 418108:tid 418321] [client 20.197.192.193:5963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/bootstrap.php"] [unique_id "al9X9Q0cxofL2J1zwYrWUgAAAVs"]
[Tue Jul 21 08:28:54.080486 2026] [security2:error] [pid 419508:tid 419682] [client 14.245.224.124:61539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9X9lcagwCeNbomjVs2EAAAAbs"]
[Tue Jul 21 08:28:54.080604 2026] [security2:error] [pid 419508:tid 419682] [client 14.245.224.124:61539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9X9lcagwCeNbomjVs2EAAAAbs"]
[Tue Jul 21 08:28:54.636123 2026] [security2:error] [pid 419508:tid 419719] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X9lcagwCeNbomjVs2EQAAAeA"]
[Tue Jul 21 08:28:54.638497 2026] [security2:error] [pid 418108:tid 418155] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9X9g0cxofL2J1zwYrWWwABUCw"]
[Tue Jul 21 08:28:54.638669 2026] [security2:error] [pid 418108:tid 418310] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9X9g0cxofL2J1zwYrWWwABUCw"]
[Tue Jul 21 08:28:54.704856 2026] [security2:error] [pid 419508:tid 419723] [client 213.152.186.163:36866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9X9lcagwCeNbomjVs2JQAAAeQ"]
[Tue Jul 21 08:28:54.704961 2026] [security2:error] [pid 419508:tid 419723] [client 213.152.186.163:36866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9X9lcagwCeNbomjVs2JQAAAeQ"]
[Tue Jul 21 08:28:54.707208 2026] [security2:error] [pid 419508:tid 419668] [client 195.49.128.211:51740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X9lcagwCeNbomjVs2JgAAAa0"]
[Tue Jul 21 08:28:54.707314 2026] [security2:error] [pid 419508:tid 419668] [client 195.49.128.211:51740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X9lcagwCeNbomjVs2JgAAAa0"]
[Tue Jul 21 08:28:54.744825 2026] [security2:error] [pid 419508:tid 419717] [client 74.249.245.134:55544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/404.php"] [unique_id "al9X9lcagwCeNbomjVs2KAAAAd4"]
[Tue Jul 21 08:28:54.933752 2026] [security2:error] [pid 419508:tid 419724] [client 223.181.60.88:29003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9X9lcagwCeNbomjVs2MwAAAeU"]
[Tue Jul 21 08:28:54.933844 2026] [security2:error] [pid 419508:tid 419724] [client 223.181.60.88:29003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9X9lcagwCeNbomjVs2MwAAAeU"]
[Tue Jul 21 08:28:55.008423 2026] [security2:error] [pid 418108:tid 418125] [remote 20.153.140.50:40858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9X9w0cxofL2J1zwYrWXgABdw4"]
[Tue Jul 21 08:28:55.483163 2026] [security2:error] [pid 419508:tid 419728] [client 20.104.96.117:46586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/loader.php"] [unique_id "al9X91cagwCeNbomjVs2bAAAAek"]
[Tue Jul 21 08:28:55.652477 2026] [security2:error] [pid 419508:tid 419725] [client 20.197.192.193:5580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wp-editor.php"] [unique_id "al9X91cagwCeNbomjVs2bQAAAeY"]
[Tue Jul 21 08:28:55.965490 2026] [security2:error] [pid 418108:tid 418299] [client 122.176.100.127:59206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9X9w0cxofL2J1zwYrWawAAAUU"]
[Tue Jul 21 08:28:55.965763 2026] [security2:error] [pid 418108:tid 418299] [client 122.176.100.127:59206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9X9w0cxofL2J1zwYrWawAAAUU"]
[Tue Jul 21 08:28:56.259731 2026] [security2:error] [pid 418108:tid 418187] [remote 192.241.143.148:48166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/wp-login.php"] [unique_id "al9X-A0cxofL2J1zwYrWcAABeEw"]
[Tue Jul 21 08:28:56.608779 2026] [security2:error] [pid 418108:tid 418195] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X-A0cxofL2J1zwYrWeAABdVQ"]
[Tue Jul 21 08:28:56.608951 2026] [security2:error] [pid 418108:tid 418347] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X-A0cxofL2J1zwYrWeAABdVQ"]
[Tue Jul 21 08:28:56.676282 2026] [security2:error] [pid 419508:tid 419730] [client 5.31.193.106:29975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9X-FcagwCeNbomjVs2ggAAAes"]
[Tue Jul 21 08:28:56.711675 2026] [security2:error] [pid 419508:tid 419696] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X-FcagwCeNbomjVs2egAAAck"]
[Tue Jul 21 08:28:56.718040 2026] [security2:error] [pid 419508:tid 419625] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X-FcagwCeNbomjVs2iAACBXQ"]
[Tue Jul 21 08:28:56.718186 2026] [security2:error] [pid 419508:tid 419757] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X-FcagwCeNbomjVs2iAACBXQ"]
[Tue Jul 21 08:28:56.718625 2026] [security2:error] [pid 419508:tid 419739] [client 49.144.66.253:32576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9X-FcagwCeNbomjVs2iQAAAfQ"]
[Tue Jul 21 08:28:56.718712 2026] [security2:error] [pid 419508:tid 419739] [client 49.144.66.253:32576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9X-FcagwCeNbomjVs2iQAAAfQ"]
[Tue Jul 21 08:28:56.866845 2026] [security2:error] [pid 419508:tid 419603] [remote 45.90.123.233:57650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9X-FcagwCeNbomjVs2kAACB14"]
[Tue Jul 21 08:28:56.867018 2026] [security2:error] [pid 419508:tid 419759] [client 45.90.123.233:57650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9X-FcagwCeNbomjVs2kAACB14"]
[Tue Jul 21 08:28:56.972448 2026] [security2:error] [pid 418108:tid 418324] [client 103.151.46.103:51392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9X-A0cxofL2J1zwYrWfAAAAV4"]
[Tue Jul 21 08:28:56.972534 2026] [security2:error] [pid 418108:tid 418324] [client 103.151.46.103:51392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9X-A0cxofL2J1zwYrWfAAAAV4"]
[Tue Jul 21 08:28:58.052820 2026] [security2:error] [pid 418108:tid 418242] [client 204.12.208.18:54821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-includes/admin.php"] [unique_id "al9X-g0cxofL2J1zwYrWhQAAAQw"], referer: https://leoamaraldev.com.br/wp-includes/admin.php
[Tue Jul 21 08:28:58.162983 2026] [security2:error] [pid 419508:tid 419515] [remote 54.39.0.119:22606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "pacodasrosas.com.br"] [uri "/robots.txt"] [unique_id "al9X-lcagwCeNbomjVs2uQAB2gY"]
[Tue Jul 21 08:28:58.163166 2026] [security2:error] [pid 419508:tid 419713] [client 54.39.0.119:22606] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pacodasrosas.com.br"] [uri "/robots.txt"] [unique_id "al9X-lcagwCeNbomjVs2uQAB2gY"]
[Tue Jul 21 08:28:58.179651 2026] [security2:error] [pid 418108:tid 418205] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9X-g0cxofL2J1zwYrWiAABLF4"]
[Tue Jul 21 08:28:58.179766 2026] [security2:error] [pid 418108:tid 418274] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9X-g0cxofL2J1zwYrWiAABLF4"]
[Tue Jul 21 08:28:58.265910 2026] [security2:error] [pid 418108:tid 418284] [client 20.104.96.117:46518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/spadex.php"] [unique_id "al9X-g0cxofL2J1zwYrWiQAAATY"]
[Tue Jul 21 08:28:59.099000 2026] [security2:error] [pid 419508:tid 419676] [client 187.125.243.197:55428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9X-1cagwCeNbomjVs21AAAAbU"]
[Tue Jul 21 08:28:59.099394 2026] [security2:error] [pid 419508:tid 419676] [client 187.125.243.197:55428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9X-1cagwCeNbomjVs21AAAAbU"]
[Tue Jul 21 08:28:59.105886 2026] [autoindex:error] [pid 419508:tid 419604] [remote 74.7.243.130:56080] AH01276: Cannot serve directory /home4/dralul00/idumed.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:28:59.373956 2026] [security2:error] [pid 419508:tid 419714] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X-lcagwCeNbomjVs20AAAAds"]
[Tue Jul 21 08:28:59.722258 2026] [security2:error] [pid 419508:tid 419670] [client 74.7.228.1:54644] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.idumed.com.br.dralulmabhering.com"] [uri "/cgi-sys/404.html"] [unique_id "al9X-1cagwCeNbomjVs26gABrzY"]
[Tue Jul 21 08:28:59.742341 2026] [security2:error] [pid 419508:tid 419657] [client 204.12.208.18:54862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-includes/admin.php"] [unique_id "al9X-1cagwCeNbomjVs26wAAAaI"], referer: https://leoamaraldev.com.br/wp-includes/admin.php
[Tue Jul 21 08:28:59.763585 2026] [security2:error] [pid 418108:tid 418217] [remote 15.235.98.55:57324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "pacodasrosas.com.br"] [uri "/"] [unique_id "al9X-w0cxofL2J1zwYrWmwABZWo"]
[Tue Jul 21 08:28:59.763745 2026] [security2:error] [pid 418108:tid 418331] [client 15.235.98.55:57324] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pacodasrosas.com.br"] [uri "/"] [unique_id "al9X-w0cxofL2J1zwYrWmwABZWo"]
[Tue Jul 21 08:29:00.102756 2026] [security2:error] [pid 419508:tid 419554] [remote 18.61.192.253:50970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "monicamirandapereira1751478737000.bellarthconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "al9X_FcagwCeNbomjVs28gACBS0"]
[Tue Jul 21 08:29:00.185974 2026] [security2:error] [pid 419508:tid 419673] [client 109.248.148.246:34214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9X_FcagwCeNbomjVs29wAAAbI"]
[Tue Jul 21 08:29:00.186036 2026] [security2:error] [pid 419508:tid 419673] [client 109.248.148.246:34214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9X_FcagwCeNbomjVs29wAAAbI"]
[Tue Jul 21 08:29:00.204590 2026] [security2:error] [pid 419508:tid 419741] [client 150.129.202.39:65158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X_FcagwCeNbomjVs2-QAAAfY"]
[Tue Jul 21 08:29:00.204687 2026] [security2:error] [pid 419508:tid 419741] [client 150.129.202.39:65158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X_FcagwCeNbomjVs2-QAAAfY"]
[Tue Jul 21 08:29:00.670379 2026] [security2:error] [pid 418108:tid 418322] [client 195.49.128.211:59759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9X_A0cxofL2J1zwYrWtAAAAVw"]
[Tue Jul 21 08:29:00.670488 2026] [security2:error] [pid 418108:tid 418322] [client 195.49.128.211:59759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9X_A0cxofL2J1zwYrWtAAAAVw"]
[Tue Jul 21 08:29:00.694836 2026] [core:alert] [pid 419508:tid 419679] [client 57.141.18.91:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:29:00.981307 2026] [security2:error] [pid 419508:tid 419708] [client 117.213.202.34:50137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X_FcagwCeNbomjVs3GwAAAdU"]
[Tue Jul 21 08:29:00.981458 2026] [security2:error] [pid 419508:tid 419708] [client 117.213.202.34:50137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9X_FcagwCeNbomjVs3GwAAAdU"]
[Tue Jul 21 08:29:01.152883 2026] [security2:error] [pid 419508:tid 419730] [client 202.179.75.202:60972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9X_VcagwCeNbomjVs3IQAAAes"]
[Tue Jul 21 08:29:01.152999 2026] [security2:error] [pid 419508:tid 419730] [client 202.179.75.202:60972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9X_VcagwCeNbomjVs3IQAAAes"]
[Tue Jul 21 08:29:01.269994 2026] [security2:error] [pid 418108:tid 418210] [remote 154.61.75.100:50172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rosisestefanoadvocacia.guiiaz.com.br"] [uri "/wp-login.php"] [unique_id "al9X_Q0cxofL2J1zwYrWugABCmM"]
[Tue Jul 21 08:29:01.338371 2026] [security2:error] [pid 419508:tid 419657] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9X_FcagwCeNbomjVs3FgAAAaI"]
[Tue Jul 21 08:29:01.604978 2026] [security2:error] [pid 419508:tid 419638] [client 204.12.208.18:54913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "leoamaraldev.com.br"] [uri "/wp-includes/admin.php"] [unique_id "al9X_VcagwCeNbomjVs3KAAAAY8"], referer: https://leoamaraldev.com.br/wp-includes/admin.php
[Tue Jul 21 08:29:01.693973 2026] [security2:error] [pid 418108:tid 418338] [client 20.197.192.193:6008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/cro.php"] [unique_id "al9X_Q0cxofL2J1zwYrWvwAAAWw"]
[Tue Jul 21 08:29:01.809403 2026] [security2:error] [pid 419508:tid 419676] [client 20.104.96.117:46514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/2x.php"] [unique_id "al9X_VcagwCeNbomjVs3LwAAAbU"]
[Tue Jul 21 08:29:02.663634 2026] [security2:error] [pid 418108:tid 418290] [client 74.7.241.141:43434] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.ellosemijoias.com.br.startonesite.com.br"] [uri "/index.php"] [unique_id "al9X_g0cxofL2J1zwYrWxgABPBw"]
[Tue Jul 21 08:29:02.709090 2026] [security2:error] [pid 419508:tid 419704] [client 59.184.181.113:51627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.181.184.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9X_lcagwCeNbomjVs3PQAAAdE"]
[Tue Jul 21 08:29:02.709359 2026] [security2:error] [pid 419508:tid 419704] [client 59.184.181.113:51627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9X_lcagwCeNbomjVs3PQAAAdE"]
[Tue Jul 21 08:29:02.797318 2026] [security2:error] [pid 419508:tid 419702] [client 14.97.58.74:61596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X_lcagwCeNbomjVs3PwAAAc8"]
[Tue Jul 21 08:29:02.797462 2026] [security2:error] [pid 419508:tid 419702] [client 14.97.58.74:61596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9X_lcagwCeNbomjVs3PwAAAc8"]
[Tue Jul 21 08:29:03.049665 2026] [security2:error] [pid 419508:tid 419643] [client 152.59.34.51:52894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9X_1cagwCeNbomjVs3RwAAAZQ"]
[Tue Jul 21 08:29:03.049791 2026] [security2:error] [pid 419508:tid 419643] [client 152.59.34.51:52894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9X_1cagwCeNbomjVs3RwAAAZQ"]
[Tue Jul 21 08:29:03.675335 2026] [security2:error] [pid 419508:tid 419710] [client 74.7.228.41:60834] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.cacosmeticosclub.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9X_1cagwCeNbomjVs3VgAB11E"]
[Tue Jul 21 08:29:03.869579 2026] [security2:error] [pid 419508:tid 419737] [client 20.197.192.193:5608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/cron-tab.php"] [unique_id "al9X_1cagwCeNbomjVs3XAAAAfI"]
[Tue Jul 21 08:29:04.102387 2026] [security2:error] [pid 418108:tid 418112] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/phpinfo.php"] [unique_id "al9YAA0cxofL2J1zwYrW1AABVgE"], referer: http://www.vidrosprovetro.com.br/phpinfo.php
[Tue Jul 21 08:29:04.515994 2026] [security2:error] [pid 419508:tid 419658] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YAFcagwCeNbomjVs3YAAAAaM"]
[Tue Jul 21 08:29:04.991542 2026] [security2:error] [pid 419508:tid 419524] [remote 216.73.216.116:17339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roha.life"] [uri "/xmlrpc.php"] [unique_id "al9YAFcagwCeNbomjVs3bAABxA8"]
[Tue Jul 21 08:29:05.021620 2026] [security2:error] [pid 419508:tid 419584] [remote 81.173.115.7:45808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9YAVcagwCeNbomjVs3cwABpUs"]
[Tue Jul 21 08:29:05.240391 2026] [security2:error] [pid 419508:tid 419682] [client 195.49.128.211:52321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YAVcagwCeNbomjVs3eQAAAbs"]
[Tue Jul 21 08:29:05.240528 2026] [security2:error] [pid 419508:tid 419682] [client 195.49.128.211:52321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YAVcagwCeNbomjVs3eQAAAbs"]
[Tue Jul 21 08:29:05.319917 2026] [security2:error] [pid 419508:tid 419548] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YAVcagwCeNbomjVs3ewACCic"]
[Tue Jul 21 08:29:05.320257 2026] [security2:error] [pid 419508:tid 419762] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YAVcagwCeNbomjVs3ewACCic"]
[Tue Jul 21 08:29:05.418903 2026] [security2:error] [pid 419508:tid 419734] [client 14.245.224.124:62057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YAVcagwCeNbomjVs3fQAAAe8"]
[Tue Jul 21 08:29:05.419020 2026] [security2:error] [pid 419508:tid 419734] [client 14.245.224.124:62057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YAVcagwCeNbomjVs3fQAAAe8"]
[Tue Jul 21 08:29:05.992449 2026] [security2:error] [pid 419508:tid 419726] [client 20.220.225.223:19275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/acew67.php"] [unique_id "al9YAVcagwCeNbomjVs3iwAAAec"]
[Tue Jul 21 08:29:06.060135 2026] [security2:error] [pid 419508:tid 419696] [client 223.181.60.88:33067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YAlcagwCeNbomjVs3jwAAAck"]
[Tue Jul 21 08:29:06.060392 2026] [security2:error] [pid 419508:tid 419696] [client 223.181.60.88:33067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YAlcagwCeNbomjVs3jwAAAck"]
[Tue Jul 21 08:29:06.230101 2026] [security2:error] [pid 419508:tid 419658] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YAVcagwCeNbomjVs3iAAAAaM"]
[Tue Jul 21 08:29:06.454420 2026] [security2:error] [pid 419508:tid 419643] [client 122.176.100.127:59678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YAlcagwCeNbomjVs3mgAAAZQ"]
[Tue Jul 21 08:29:06.454523 2026] [security2:error] [pid 419508:tid 419643] [client 122.176.100.127:59678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YAlcagwCeNbomjVs3mgAAAZQ"]
[Tue Jul 21 08:29:06.625619 2026] [security2:error] [pid 419508:tid 419528] [remote 41.186.86.12:50450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9YAlcagwCeNbomjVs3oQABnxM"]
[Tue Jul 21 08:29:06.745894 2026] [security2:error] [pid 418108:tid 418346] [client 154.92.130.89:4285] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://:"] [hostname "oticapersona.com.br"] [uri "/"] [unique_id "al9YAg0cxofL2J1zwYrW4gAAAXQ"]
[Tue Jul 21 08:29:07.182637 2026] [security2:error] [pid 418108:tid 418173] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YAw0cxofL2J1zwYrW6AABMT4"]
[Tue Jul 21 08:29:07.182805 2026] [security2:error] [pid 418108:tid 418279] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YAw0cxofL2J1zwYrW6AABMT4"]
[Tue Jul 21 08:29:07.244975 2026] [security2:error] [pid 419508:tid 419693] [client 20.220.225.223:19699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/bscclapb.php"] [unique_id "al9YA1cagwCeNbomjVs3tQAAAcY"]
[Tue Jul 21 08:29:07.315078 2026] [security2:error] [pid 419508:tid 419677] [client 103.151.46.103:51891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YA1cagwCeNbomjVs3tgAAAbY"]
[Tue Jul 21 08:29:07.315346 2026] [security2:error] [pid 419508:tid 419677] [client 103.151.46.103:51891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YA1cagwCeNbomjVs3tgAAAbY"]
[Tue Jul 21 08:29:07.369868 2026] [security2:error] [pid 418108:tid 418189] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YAw0cxofL2J1zwYrW6gABaU4"]
[Tue Jul 21 08:29:07.370109 2026] [security2:error] [pid 418108:tid 418335] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YAw0cxofL2J1zwYrW6gABaU4"]
[Tue Jul 21 08:29:07.445938 2026] [security2:error] [pid 419508:tid 419688] [client 20.151.10.161:4906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitoaberto.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9YA1cagwCeNbomjVs3wAAAAcE"]
[Tue Jul 21 08:29:07.670041 2026] [security2:error] [pid 418108:tid 418284] [client 49.144.66.253:32971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YAw0cxofL2J1zwYrW8QAAATY"]
[Tue Jul 21 08:29:07.670139 2026] [security2:error] [pid 418108:tid 418284] [client 49.144.66.253:32971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YAw0cxofL2J1zwYrW8QAAATY"]
[Tue Jul 21 08:29:07.722347 2026] [security2:error] [pid 419508:tid 419685] [client 20.151.10.161:4898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitoaberto.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9YA1cagwCeNbomjVs3xQAAAb4"]
[Tue Jul 21 08:29:07.726608 2026] [security2:error] [pid 419508:tid 419608] [remote 167.71.218.184:47532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "izabelreck.com"] [uri "/wp-login.php"] [unique_id "al9YA1cagwCeNbomjVs3xgAB12M"]
[Tue Jul 21 08:29:07.729224 2026] [security2:error] [pid 419508:tid 419699] [client 103.253.27.80:63127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.27.253.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9YAlcagwCeNbomjVs3nAAAAcw"]
[Tue Jul 21 08:29:07.928773 2026] [access_compat:error] [pid 419508:tid 419754] [client 162.241.63.68:56976] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:29:08.001656 2026] [security2:error] [pid 419508:tid 419638] [client 20.151.10.161:4234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitoaberto.com.br"] [uri "/images.php"] [unique_id "al9YBFcagwCeNbomjVs3zAAAAY8"]
[Tue Jul 21 08:29:08.020437 2026] [security2:error] [pid 419508:tid 419660] [client 61.1.167.83:65069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YBFcagwCeNbomjVs3zQAAAaU"]
[Tue Jul 21 08:29:08.020597 2026] [security2:error] [pid 419508:tid 419660] [client 61.1.167.83:65069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YBFcagwCeNbomjVs3zQAAAaU"]
[Tue Jul 21 08:29:08.149659 2026] [security2:error] [pid 419508:tid 419649] [client 20.197.192.193:6001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/koiy.php"] [unique_id "al9YBFcagwCeNbomjVs30gAAAZo"]
[Tue Jul 21 08:29:08.286495 2026] [security2:error] [pid 419508:tid 419677] [client 20.151.10.161:4886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitoaberto.com.br"] [uri "/for.php"] [unique_id "al9YBFcagwCeNbomjVs31wAAAbY"]
[Tue Jul 21 08:29:08.563258 2026] [security2:error] [pid 419508:tid 419688] [client 20.151.10.161:4871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitoaberto.com.br"] [uri "/2larp.php"] [unique_id "al9YBFcagwCeNbomjVs33AAAAcE"]
[Tue Jul 21 08:29:08.720399 2026] [security2:error] [pid 418108:tid 418171] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YBA0cxofL2J1zwYrW-gABSjw"]
[Tue Jul 21 08:29:08.720538 2026] [security2:error] [pid 418108:tid 418304] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YBA0cxofL2J1zwYrW-gABSjw"]
[Tue Jul 21 08:29:08.855410 2026] [security2:error] [pid 418108:tid 418351] [client 20.151.10.161:4914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitoaberto.com.br"] [uri "/adminner.php"] [unique_id "al9YBA0cxofL2J1zwYrW-wAAAXk"]
[Tue Jul 21 08:29:08.975964 2026] [security2:error] [pid 419508:tid 419717] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YBFcagwCeNbomjVs32wAAAd4"]
[Tue Jul 21 08:29:09.130342 2026] [security2:error] [pid 418108:tid 418257] [client 20.151.10.161:4235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitoaberto.com.br"] [uri "/82.php"] [unique_id "al9YBQ0cxofL2J1zwYrW_gAAARs"]
[Tue Jul 21 08:29:09.210560 2026] [security2:error] [pid 418108:tid 418301] [client 18.193.252.127:32088] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9YBQ0cxofL2J1zwYrW_wAAAUc"], referer: https://artetoner.com.br
[Tue Jul 21 08:29:09.412294 2026] [security2:error] [pid 419508:tid 419657] [client 20.151.10.161:4232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "transitoaberto.com.br"] [uri "/kir.php"] [unique_id "al9YBVcagwCeNbomjVs36gAAAaI"]
[Tue Jul 21 08:29:09.496733 2026] [security2:error] [pid 419508:tid 419555] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/test.php"] [unique_id "al9YBVcagwCeNbomjVs37QAB1y4"], referer: http://www.vidrosprovetro.com.br/test.php
[Tue Jul 21 08:29:09.535386 2026] [security2:error] [pid 419508:tid 419646] [client 20.104.96.117:62670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/ctex1.php"] [unique_id "al9YBVcagwCeNbomjVs37gAAAZc"]
[Tue Jul 21 08:29:09.579473 2026] [security2:error] [pid 419508:tid 419660] [client 187.125.243.197:55936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YBVcagwCeNbomjVs38QAAAaU"]
[Tue Jul 21 08:29:09.579586 2026] [security2:error] [pid 419508:tid 419660] [client 187.125.243.197:55936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YBVcagwCeNbomjVs38QAAAaU"]
[Tue Jul 21 08:29:10.189733 2026] [security2:error] [pid 419508:tid 419535] [remote 41.186.86.12:31659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9YBlcagwCeNbomjVs3_QABmho"]
[Tue Jul 21 08:29:10.246673 2026] [security2:error] [pid 419508:tid 419671] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9YBlcagwCeNbomjVs3_wAAAbA"]
[Tue Jul 21 08:29:10.291930 2026] [security2:error] [pid 419508:tid 419518] [remote 41.76.214.143:48120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9YBlcagwCeNbomjVs4AAABxQk"]
[Tue Jul 21 08:29:10.482682 2026] [core:error] [pid 419508:tid 419620] [remote 185.247.137.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpanel.getveltrixhealth.com:8880
[Tue Jul 21 08:29:10.482702 2026] [core:error] [pid 419508:tid 419620] [remote 185.247.137.27:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpanel.getveltrixhealth.com:8880
[Tue Jul 21 08:29:10.531130 2026] [security2:error] [pid 419508:tid 419704] [client 143.244.57.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YBlcagwCeNbomjVs4BAAAAdE"]
[Tue Jul 21 08:29:10.976957 2026] [security2:error] [pid 419508:tid 419725] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9YBlcagwCeNbomjVs4FAAAAeY"]
[Tue Jul 21 08:29:11.021021 2026] [security2:error] [pid 419508:tid 419730] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YBlcagwCeNbomjVs4BQAAAes"]
[Tue Jul 21 08:29:11.128580 2026] [security2:error] [pid 418108:tid 418281] [client 150.129.202.39:64892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YBw0cxofL2J1zwYrXDgAAATM"]
[Tue Jul 21 08:29:11.128720 2026] [security2:error] [pid 418108:tid 418281] [client 150.129.202.39:64892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YBw0cxofL2J1zwYrXDgAAATM"]
[Tue Jul 21 08:29:11.260578 2026] [security2:error] [pid 419508:tid 419765] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9YB1cagwCeNbomjVs4GAAAAg0"]
[Tue Jul 21 08:29:11.332601 2026] [security2:error] [pid 418108:tid 418329] [client 195.49.128.211:60364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YBw0cxofL2J1zwYrXEAAAAWM"]
[Tue Jul 21 08:29:11.332848 2026] [security2:error] [pid 418108:tid 418329] [client 195.49.128.211:60364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YBw0cxofL2J1zwYrXEAAAAWM"]
[Tue Jul 21 08:29:11.545771 2026] [security2:error] [pid 418108:tid 418244] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9YBw0cxofL2J1zwYrXEQAAAQ4"]
[Tue Jul 21 08:29:11.732325 2026] [security2:error] [pid 419508:tid 419643] [client 20.104.96.117:46550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/edorxrr.php"] [unique_id "al9YB1cagwCeNbomjVs4IQAAAZQ"]
[Tue Jul 21 08:29:11.743067 2026] [security2:error] [pid 419508:tid 419676] [client 117.213.202.34:50684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YB1cagwCeNbomjVs4IgAAAbU"]
[Tue Jul 21 08:29:11.743210 2026] [security2:error] [pid 419508:tid 419676] [client 117.213.202.34:50684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YB1cagwCeNbomjVs4IgAAAbU"]
[Tue Jul 21 08:29:11.824147 2026] [security2:error] [pid 419508:tid 419709] [client 185.213.175.37:8476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "azusacorretora.com.br"] [uri "/api/config"] [unique_id "al9YB1cagwCeNbomjVs4JwAAAdY"]
[Tue Jul 21 08:29:11.824268 2026] [security2:error] [pid 419508:tid 419709] [client 185.213.175.37:8476] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "azusacorretora.com.br"] [uri "/api/config"] [unique_id "al9YB1cagwCeNbomjVs4JwAAAdY"]
[Tue Jul 21 08:29:11.830557 2026] [security2:error] [pid 419508:tid 419704] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9YB1cagwCeNbomjVs4KAAAAdE"]
[Tue Jul 21 08:29:11.993199 2026] [security2:error] [pid 419508:tid 419671] [client 202.179.75.202:49662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YB1cagwCeNbomjVs4LgAAAbA"]
[Tue Jul 21 08:29:11.993343 2026] [security2:error] [pid 419508:tid 419671] [client 202.179.75.202:49662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YB1cagwCeNbomjVs4LgAAAbA"]
[Tue Jul 21 08:29:12.116437 2026] [security2:error] [pid 419508:tid 419664] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9YCFcagwCeNbomjVs4MgAAAak"]
[Tue Jul 21 08:29:12.401335 2026] [security2:error] [pid 419508:tid 419691] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9YCFcagwCeNbomjVs4NQAAAcQ"]
[Tue Jul 21 08:29:12.686287 2026] [security2:error] [pid 419508:tid 419712] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9YCFcagwCeNbomjVs4PQAAAdk"]
[Tue Jul 21 08:29:12.779507 2026] [security2:error] [pid 419508:tid 419689] [client 20.104.96.117:62601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/miru1.php"] [unique_id "al9YCFcagwCeNbomjVs4QAAAAcI"]
[Tue Jul 21 08:29:12.970909 2026] [security2:error] [pid 418108:tid 418267] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9YCA0cxofL2J1zwYrXGwAAASU"]
[Tue Jul 21 08:29:13.131170 2026] [security2:error] [pid 418108:tid 418326] [client 20.104.96.117:46532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/sump1.php"] [unique_id "al9YCQ0cxofL2J1zwYrXHAAAAWA"]
[Tue Jul 21 08:29:13.225303 2026] [security2:error] [pid 418108:tid 418322] [client 59.184.181.113:52102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.181.184.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9YCQ0cxofL2J1zwYrXHQAAAVw"]
[Tue Jul 21 08:29:13.225452 2026] [security2:error] [pid 418108:tid 418322] [client 59.184.181.113:52102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9YCQ0cxofL2J1zwYrXHQAAAVw"]
[Tue Jul 21 08:29:13.264403 2026] [security2:error] [pid 419508:tid 419741] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9YCVcagwCeNbomjVs4SAAAAfY"]
[Tue Jul 21 08:29:13.486107 2026] [security2:error] [pid 418108:tid 418305] [client 14.97.58.74:12360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YCQ0cxofL2J1zwYrXHwAAAUs"]
[Tue Jul 21 08:29:13.486253 2026] [security2:error] [pid 418108:tid 418305] [client 14.97.58.74:12360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YCQ0cxofL2J1zwYrXHwAAAUs"]
[Tue Jul 21 08:29:13.552195 2026] [security2:error] [pid 419508:tid 419690] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9YCVcagwCeNbomjVs4TwAAAcM"]
[Tue Jul 21 08:29:13.720662 2026] [security2:error] [pid 418108:tid 418291] [client 20.104.96.117:46477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/file5.php"] [unique_id "al9YCQ0cxofL2J1zwYrXIAAAAT0"]
[Tue Jul 21 08:29:13.824330 2026] [security2:error] [pid 419508:tid 419687] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YCVcagwCeNbomjVs4SwAAAcA"]
[Tue Jul 21 08:29:13.835979 2026] [security2:error] [pid 419508:tid 419712] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9YCVcagwCeNbomjVs4VQAAAdk"]
[Tue Jul 21 08:29:14.031839 2026] [security2:error] [pid 419508:tid 419692] [client 20.197.192.193:46145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/hp2.php"] [unique_id "al9YClcagwCeNbomjVs4WwAAAcU"]
[Tue Jul 21 08:29:14.121492 2026] [security2:error] [pid 419508:tid 419661] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9YClcagwCeNbomjVs4XAAAAaY"]
[Tue Jul 21 08:29:14.272710 2026] [security2:error] [pid 419508:tid 419682] [client 20.220.225.223:19663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/else1.php"] [unique_id "al9YClcagwCeNbomjVs4XgAAAbs"]
[Tue Jul 21 08:29:14.406186 2026] [security2:error] [pid 419508:tid 419668] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9YClcagwCeNbomjVs4ZQAAAa0"]
[Tue Jul 21 08:29:14.442663 2026] [security2:error] [pid 419508:tid 419702] [client 20.104.96.117:46530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/0xD.php"] [unique_id "al9YClcagwCeNbomjVs4ZgAAAc8"]
[Tue Jul 21 08:29:14.695345 2026] [security2:error] [pid 419508:tid 419660] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9YClcagwCeNbomjVs4bwAAAaU"]
[Tue Jul 21 08:29:14.981364 2026] [security2:error] [pid 419508:tid 419687] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9YClcagwCeNbomjVs4dQAAAcA"]
[Tue Jul 21 08:29:15.266365 2026] [security2:error] [pid 419508:tid 419708] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lucasrochadesousa1782909857000.lucasrochadesousa1782841306000.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9YC1cagwCeNbomjVs4fQAAAdU"]
[Tue Jul 21 08:29:15.570587 2026] [security2:error] [pid 419508:tid 419695] [client 20.104.96.117:46579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/fnstall.php"] [unique_id "al9YC1cagwCeNbomjVs4gwAAAcg"]
[Tue Jul 21 08:29:15.604663 2026] [security2:error] [pid 419508:tid 419722] [client 54.39.0.4:16624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.zooparquevet.com.br"] [uri "/robots.txt"] [unique_id "al9YC1cagwCeNbomjVs4hAAAAeM"]
[Tue Jul 21 08:29:15.604798 2026] [security2:error] [pid 419508:tid 419722] [client 54.39.0.4:16624] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.zooparquevet.com.br"] [uri "/robots.txt"] [unique_id "al9YC1cagwCeNbomjVs4hAAAAeM"]
[Tue Jul 21 08:29:15.664753 2026] [security2:error] [pid 418108:tid 418289] [client 14.245.224.124:62510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YCw0cxofL2J1zwYrXLwAAATs"]
[Tue Jul 21 08:29:15.664895 2026] [security2:error] [pid 418108:tid 418289] [client 14.245.224.124:62510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YCw0cxofL2J1zwYrXLwAAATs"]
[Tue Jul 21 08:29:15.803498 2026] [security2:error] [pid 419508:tid 419754] [client 74.249.245.134:54935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/wp-mail.php"] [unique_id "al9YC1cagwCeNbomjVs4iQAAAgI"]
[Tue Jul 21 08:29:15.866781 2026] [security2:error] [pid 419508:tid 419733] [client 195.49.128.211:52913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YC1cagwCeNbomjVs4jQAAAe4"]
[Tue Jul 21 08:29:15.866936 2026] [security2:error] [pid 419508:tid 419733] [client 195.49.128.211:52913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YC1cagwCeNbomjVs4jQAAAe4"]
[Tue Jul 21 08:29:15.960660 2026] [security2:error] [pid 418108:tid 418143] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YCw0cxofL2J1zwYrXMgABSiA"]
[Tue Jul 21 08:29:15.960870 2026] [security2:error] [pid 418108:tid 418304] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YCw0cxofL2J1zwYrXMgABSiA"]
[Tue Jul 21 08:29:16.115791 2026] [security2:error] [pid 418108:tid 418287] [client 20.104.96.117:46485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/acp.php"] [unique_id "al9YDA0cxofL2J1zwYrXNQAAATk"]
[Tue Jul 21 08:29:16.447511 2026] [security2:error] [pid 418108:tid 418339] [client 20.104.96.117:46526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/mosty.php"] [unique_id "al9YDA0cxofL2J1zwYrXOwAAAW0"]
[Tue Jul 21 08:29:16.919122 2026] [security2:error] [pid 419508:tid 419746] [client 122.176.100.127:60143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YDFcagwCeNbomjVs4qwAAAfo"]
[Tue Jul 21 08:29:16.919311 2026] [security2:error] [pid 419508:tid 419746] [client 122.176.100.127:60143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YDFcagwCeNbomjVs4qwAAAfo"]
[Tue Jul 21 08:29:16.989328 2026] [security2:error] [pid 419508:tid 419709] [client 51.195.183.3:15242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.zooparquevet.com.br"] [uri "/"] [unique_id "al9YDFcagwCeNbomjVs4rQAAAdY"]
[Tue Jul 21 08:29:16.989417 2026] [security2:error] [pid 419508:tid 419709] [client 51.195.183.3:15242] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.zooparquevet.com.br"] [uri "/"] [unique_id "al9YDFcagwCeNbomjVs4rQAAAdY"]
[Tue Jul 21 08:29:17.008759 2026] [security2:error] [pid 419508:tid 419754] [client 20.104.96.117:46490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/6.php"] [unique_id "al9YDVcagwCeNbomjVs4rgAAAgI"]
[Tue Jul 21 08:29:17.049137 2026] [security2:error] [pid 419508:tid 419739] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YDFcagwCeNbomjVs4nQAAAfQ"]
[Tue Jul 21 08:29:17.309405 2026] [security2:error] [pid 418108:tid 418313] [client 223.181.60.88:3066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YDQ0cxofL2J1zwYrXQwAAAVM"]
[Tue Jul 21 08:29:17.309658 2026] [security2:error] [pid 418108:tid 418313] [client 223.181.60.88:3066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YDQ0cxofL2J1zwYrXQwAAAVM"]
[Tue Jul 21 08:29:17.381566 2026] [proxy:error] [pid 419508:tid 419609] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:29:17.381636 2026] [proxy_http:error] [pid 419508:tid 419609] [remote 198.235.24.55:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:29:17.383279 2026] [proxy:error] [pid 419508:tid 419609] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:29:17.383343 2026] [proxy_http:error] [pid 419508:tid 419609] [remote 198.235.24.55:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:29:17.410541 2026] [security2:error] [pid 419508:tid 419588] [remote 45.79.123.44:42988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteoficialgs.com"] [uri "/wp-login.php"] [unique_id "al9YDVcagwCeNbomjVs4tgAB9k8"]
[Tue Jul 21 08:29:17.463485 2026] [security2:error] [pid 419508:tid 419727] [client 103.151.46.103:52389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YDVcagwCeNbomjVs4uQAAAeg"]
[Tue Jul 21 08:29:17.464264 2026] [security2:error] [pid 419508:tid 419727] [client 103.151.46.103:52389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YDVcagwCeNbomjVs4uQAAAeg"]
[Tue Jul 21 08:29:17.465855 2026] [security2:error] [pid 418108:tid 418244] [client 20.197.192.193:5596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/hp3.php"] [unique_id "al9YDQ0cxofL2J1zwYrXRQAAAQ4"]
[Tue Jul 21 08:29:17.534735 2026] [security2:error] [pid 419508:tid 419752] [client 20.104.96.117:46491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9YDVcagwCeNbomjVs4ugAAAgA"]
[Tue Jul 21 08:29:17.663361 2026] [security2:error] [pid 419508:tid 419511] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YDVcagwCeNbomjVs4vQAB1QI"]
[Tue Jul 21 08:29:17.663588 2026] [security2:error] [pid 419508:tid 419708] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YDVcagwCeNbomjVs4vQAB1QI"]
[Tue Jul 21 08:29:17.696052 2026] [security2:error] [pid 418108:tid 418259] [client 5.31.193.106:29999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YDQ0cxofL2J1zwYrXSAAAAR0"]
[Tue Jul 21 08:29:17.733353 2026] [security2:error] [pid 419508:tid 419766] [client 20.220.225.223:19719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/tkikikoko.php"] [unique_id "al9YDVcagwCeNbomjVs4vwAAAg4"]
[Tue Jul 21 08:29:18.049767 2026] [security2:error] [pid 419508:tid 419620] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YDlcagwCeNbomjVs4xwABsm8"]
[Tue Jul 21 08:29:18.049980 2026] [security2:error] [pid 419508:tid 419673] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YDlcagwCeNbomjVs4xwABsm8"]
[Tue Jul 21 08:29:18.122297 2026] [security2:error] [pid 419508:tid 419643] [client 20.104.96.117:46495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/qqqa.php"] [unique_id "al9YDlcagwCeNbomjVs4yAAAAZQ"]
[Tue Jul 21 08:29:18.280158 2026] [security2:error] [pid 419508:tid 419646] [client 74.249.245.134:55519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/about.php"] [unique_id "al9YDlcagwCeNbomjVs4zAAAAZc"]
[Tue Jul 21 08:29:18.354071 2026] [security2:error] [pid 419508:tid 419521] [remote 47.128.50.155:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bomnegociopromotora.com.br"] [uri "/robots.txt"] [unique_id "al9YDlcagwCeNbomjVs4zgAB0gw"]
[Tue Jul 21 08:29:18.568053 2026] [security2:error] [pid 418108:tid 418267] [client 20.104.96.117:46589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/aunmc.php"] [unique_id "al9YDg0cxofL2J1zwYrXUQAAASU"]
[Tue Jul 21 08:29:18.579833 2026] [security2:error] [pid 419508:tid 419739] [client 49.144.66.253:33350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YDlcagwCeNbomjVs40QAAAfQ"]
[Tue Jul 21 08:29:18.580002 2026] [security2:error] [pid 419508:tid 419739] [client 49.144.66.253:33350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YDlcagwCeNbomjVs40QAAAfQ"]
[Tue Jul 21 08:29:18.610774 2026] [security2:error] [pid 419508:tid 419551] [remote 161.35.162.136:58196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.162.35.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agrocibus.com.br"] [uri "/wp-login.php"] [unique_id "al9YDlcagwCeNbomjVs40wAB9yo"]
[Tue Jul 21 08:29:18.842268 2026] [security2:error] [pid 419508:tid 419692] [client 213.152.186.163:51078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9YDlcagwCeNbomjVs42gAAAcU"]
[Tue Jul 21 08:29:18.842407 2026] [security2:error] [pid 419508:tid 419692] [client 213.152.186.163:51078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9YDlcagwCeNbomjVs42gAAAcU"]
[Tue Jul 21 08:29:18.938233 2026] [security2:error] [pid 418108:tid 418327] [client 20.104.96.117:46525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/uoocf.php"] [unique_id "al9YDg0cxofL2J1zwYrXVAAAAWE"]
[Tue Jul 21 08:29:19.115301 2026] [security2:error] [pid 419508:tid 419703] [client 65.21.113.253:45420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YDlcagwCeNbomjVs41AAAAdA"]
[Tue Jul 21 08:29:19.219871 2026] [security2:error] [pid 418108:tid 418352] [client 20.104.96.117:46557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/iywwi.php"] [unique_id "al9YDw0cxofL2J1zwYrXWAAAAXo"]
[Tue Jul 21 08:29:19.280630 2026] [security2:error] [pid 418108:tid 418206] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YDw0cxofL2J1zwYrXWQABX18"]
[Tue Jul 21 08:29:19.280901 2026] [security2:error] [pid 418108:tid 418325] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YDw0cxofL2J1zwYrXWQABX18"]
[Tue Jul 21 08:29:19.506492 2026] [security2:error] [pid 418108:tid 418290] [client 20.104.96.117:46569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/gqgsa.php"] [unique_id "al9YDw0cxofL2J1zwYrXWgAAATw"]
[Tue Jul 21 08:29:19.816426 2026] [security2:error] [pid 418108:tid 418308] [client 20.104.96.117:46464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/elbzl.php"] [unique_id "al9YDw0cxofL2J1zwYrXXwAAAU4"]
[Tue Jul 21 08:29:19.981515 2026] [security2:error] [pid 419508:tid 419714] [client 74.249.245.134:54936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/adminfuns.php"] [unique_id "al9YD1cagwCeNbomjVs47QAAAds"]
[Tue Jul 21 08:29:20.013122 2026] [security2:error] [pid 418108:tid 418154] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEA0cxofL2J1zwYrXZQABXSs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:20.053100 2026] [security2:error] [pid 419508:tid 419753] [client 20.220.225.223:19975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9YEFcagwCeNbomjVs47wAAAgE"]
[Tue Jul 21 08:29:20.055049 2026] [security2:error] [pid 419508:tid 419646] [client 187.125.243.197:56448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YEFcagwCeNbomjVs48AAAAZc"]
[Tue Jul 21 08:29:20.055159 2026] [security2:error] [pid 419508:tid 419646] [client 187.125.243.197:56448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YEFcagwCeNbomjVs48AAAAZc"]
[Tue Jul 21 08:29:20.103430 2026] [security2:error] [pid 418108:tid 418177] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YDw0cxofL2J1zwYrXYQABIUI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:20.151743 2026] [security2:error] [pid 419508:tid 419566] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEFcagwCeNbomjVs49QABwjk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:20.215216 2026] [security2:error] [pid 418108:tid 418283] [client 184.154.139.38:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "fidellium.com"] [uri "/index.php"] [unique_id "al9YEA0cxofL2J1zwYrXZAABNX8"]
[Tue Jul 21 08:29:20.220345 2026] [security2:error] [pid 419508:tid 419692] [client 20.104.96.117:46500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/adjig.php"] [unique_id "al9YEFcagwCeNbomjVs49gAAAcU"]
[Tue Jul 21 08:29:20.275123 2026] [security2:error] [pid 419508:tid 419664] [client 85.208.96.209:33400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivaconcierge.com.br"] [uri "/robots.txt"] [unique_id "al9YEFcagwCeNbomjVs49wAAAak"]
[Tue Jul 21 08:29:20.275354 2026] [security2:error] [pid 419508:tid 419664] [client 85.208.96.209:33400] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vivaconcierge.com.br"] [uri "/robots.txt"] [unique_id "al9YEFcagwCeNbomjVs49wAAAak"]
[Tue Jul 21 08:29:20.298548 2026] [security2:error] [pid 418108:tid 418219] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEA0cxofL2J1zwYrXawABG2w"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:20.316907 2026] [security2:error] [pid 418108:tid 418280] [client 185.213.175.37:26052] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "balaodevoo.com.br"] [uri "/sua-marca-no-balco-.2491c146.js"] [unique_id "al9YEA0cxofL2J1zwYrXbAAAATI"]
[Tue Jul 21 08:29:20.358391 2026] [security2:error] [pid 418108:tid 418185] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEA0cxofL2J1zwYrXbQABdko"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:20.386182 2026] [security2:error] [pid 419508:tid 419660] [client 185.213.175.37:26084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "balaodevoo.com.br"] [uri "/inflaveis-.f6d4e1fc.js"] [unique_id "al9YEFcagwCeNbomjVs4_AAAAaU"]
[Tue Jul 21 08:29:20.386288 2026] [security2:error] [pid 419508:tid 419660] [client 185.213.175.37:26084] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "balaodevoo.com.br"] [uri "/inflaveis-.f6d4e1fc.js"] [unique_id "al9YEFcagwCeNbomjVs4_AAAAaU"]
[Tue Jul 21 08:29:20.488055 2026] [security2:error] [pid 419508:tid 419624] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEFcagwCeNbomjVs5AAAB0HM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:20.542770 2026] [security2:error] [pid 418108:tid 418270] [client 185.213.175.37:26152] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "balaodevoo.com.br"] [uri "/balloonday.a50b0216.js"] [unique_id "al9YEA0cxofL2J1zwYrXdQAAASg"]
[Tue Jul 21 08:29:20.542892 2026] [security2:error] [pid 418108:tid 418270] [client 185.213.175.37:26152] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "balaodevoo.com.br"] [uri "/balloonday.a50b0216.js"] [unique_id "al9YEA0cxofL2J1zwYrXdQAAASg"]
[Tue Jul 21 08:29:20.596930 2026] [security2:error] [pid 419508:tid 419734] [client 20.104.96.117:46484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/byp.php"] [unique_id "al9YEFcagwCeNbomjVs5BAAAAe8"]
[Tue Jul 21 08:29:20.612309 2026] [security2:error] [pid 418108:tid 418236] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEA0cxofL2J1zwYrXeAABEX0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:20.850778 2026] [security2:error] [pid 419508:tid 419529] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEFcagwCeNbomjVs5DQAB4xQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:20.868371 2026] [security2:error] [pid 418108:tid 418228] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEA0cxofL2J1zwYrXeQABC3U"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:20.956837 2026] [security2:error] [pid 419508:tid 419558] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YD1cagwCeNbomjVs46wAB_TE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:21.125456 2026] [security2:error] [pid 418108:tid 418201] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEQ0cxofL2J1zwYrXewABPlo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:21.128721 2026] [security2:error] [pid 418108:tid 418125] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEQ0cxofL2J1zwYrXfAABQw4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:21.150732 2026] [security2:error] [pid 419508:tid 419751] [client 20.104.96.117:46555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9YEVcagwCeNbomjVs5EwAAAf8"]
[Tue Jul 21 08:29:21.194933 2026] [security2:error] [pid 418108:tid 418128] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEQ0cxofL2J1zwYrXfgABXhE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:21.227768 2026] [security2:error] [pid 419508:tid 419600] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEVcagwCeNbomjVs5FgABy1s"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:21.375448 2026] [security2:error] [pid 418108:tid 418161] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEQ0cxofL2J1zwYrXgQABHTI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:21.406605 2026] [security2:error] [pid 419508:tid 419604] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEVcagwCeNbomjVs5GQABqV8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:21.475654 2026] [security2:error] [pid 418108:tid 418240] [client 74.249.245.134:37727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/php8.php"] [unique_id "al9YEQ0cxofL2J1zwYrXgwAAAQo"]
[Tue Jul 21 08:29:21.490495 2026] [security2:error] [pid 419508:tid 419586] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEVcagwCeNbomjVs5GgABu00"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:21.532346 2026] [security2:error] [pid 419508:tid 419580] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEVcagwCeNbomjVs5HQABxEc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:21.562589 2026] [security2:error] [pid 418108:tid 418332] [client 143.244.57.92:43014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9YEQ0cxofL2J1zwYrXhgAAAWY"]
[Tue Jul 21 08:29:21.789648 2026] [security2:error] [pid 418108:tid 418311] [client 20.104.96.117:46498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/classwithtostring.php"] [unique_id "al9YEQ0cxofL2J1zwYrXiQAAAVE"]
[Tue Jul 21 08:29:21.796125 2026] [security2:error] [pid 419508:tid 419734] [client 20.197.192.193:46149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/aa1.php"] [unique_id "al9YEVcagwCeNbomjVs5JgAAAe8"]
[Tue Jul 21 08:29:21.813911 2026] [security2:error] [pid 419508:tid 419714] [client 150.129.202.39:13342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YEVcagwCeNbomjVs5KAAAAds"]
[Tue Jul 21 08:29:21.814006 2026] [security2:error] [pid 419508:tid 419714] [client 150.129.202.39:13342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YEVcagwCeNbomjVs5KAAAAds"]
[Tue Jul 21 08:29:21.850029 2026] [security2:error] [pid 418108:tid 418224] [remote 84.8.104.116:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.104.8.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YEQ0cxofL2J1zwYrXiwABR3E"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:29:21.903989 2026] [security2:error] [pid 419508:tid 419697] [client 195.49.128.211:60968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YEVcagwCeNbomjVs5LgAAAco"]
[Tue Jul 21 08:29:21.904095 2026] [security2:error] [pid 419508:tid 419697] [client 195.49.128.211:60968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YEVcagwCeNbomjVs5LgAAAco"]
[Tue Jul 21 08:29:22.003225 2026] [security2:error] [pid 419508:tid 419642] [client 185.191.171.13:17776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivaconcierge.com.br"] [uri "/en/imoveis/casa-divina/"] [unique_id "al9YElcagwCeNbomjVs5MAAAAZM"]
[Tue Jul 21 08:29:22.003380 2026] [security2:error] [pid 419508:tid 419642] [client 185.191.171.13:17776] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vivaconcierge.com.br"] [uri "/en/imoveis/casa-divina/"] [unique_id "al9YElcagwCeNbomjVs5MAAAAZM"]
[Tue Jul 21 08:29:22.082170 2026] [security2:error] [pid 419508:tid 419746] [client 20.104.96.117:46512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/root.php"] [unique_id "al9YElcagwCeNbomjVs5MgAAAfo"]
[Tue Jul 21 08:29:22.299505 2026] [security2:error] [pid 418108:tid 418242] [client 47.128.115.113:59242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mdbroraima.org.br"] [uri "/robots.txt"] [unique_id "al9YEg0cxofL2J1zwYrXlAAAAQw"]
[Tue Jul 21 08:29:22.369945 2026] [security2:error] [pid 419508:tid 419748] [client 117.213.202.34:51235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YElcagwCeNbomjVs5OQAAAfw"]
[Tue Jul 21 08:29:22.370098 2026] [security2:error] [pid 419508:tid 419748] [client 117.213.202.34:51235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YElcagwCeNbomjVs5OQAAAfw"]
[Tue Jul 21 08:29:22.388146 2026] [security2:error] [pid 419508:tid 419752] [client 143.244.57.92:60532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YElcagwCeNbomjVs5PAAAAgA"]
[Tue Jul 21 08:29:22.493034 2026] [security2:error] [pid 419508:tid 419660] [client 20.104.96.117:62698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/sym403.php"] [unique_id "al9YElcagwCeNbomjVs5PgAAAaU"]
[Tue Jul 21 08:29:22.501309 2026] [security2:error] [pid 418108:tid 418309] [client 74.249.245.134:54926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/info.php"] [unique_id "al9YEg0cxofL2J1zwYrXlwAAAU8"]
[Tue Jul 21 08:29:22.782165 2026] [security2:error] [pid 419508:tid 419734] [client 20.104.96.117:46588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/v543.php"] [unique_id "al9YElcagwCeNbomjVs5RQAAAe8"]
[Tue Jul 21 08:29:22.793484 2026] [security2:error] [pid 418108:tid 418353] [client 89.238.167.134:39248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9YEg0cxofL2J1zwYrXmQAAAXs"]
[Tue Jul 21 08:29:22.793600 2026] [security2:error] [pid 418108:tid 418353] [client 89.238.167.134:39248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9YEg0cxofL2J1zwYrXmQAAAXs"]
[Tue Jul 21 08:29:23.096518 2026] [security2:error] [pid 419508:tid 419739] [client 213.152.186.163:56546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9YE1cagwCeNbomjVs5TQAAAfQ"]
[Tue Jul 21 08:29:23.096653 2026] [security2:error] [pid 419508:tid 419739] [client 213.152.186.163:56546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9YE1cagwCeNbomjVs5TQAAAfQ"]
[Tue Jul 21 08:29:23.149427 2026] [security2:error] [pid 419508:tid 419765] [client 20.104.96.117:62669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/sixxis.php"] [unique_id "al9YE1cagwCeNbomjVs5UAAAAg0"]
[Tue Jul 21 08:29:23.315356 2026] [security2:error] [pid 419508:tid 419598] [remote 41.186.86.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amandamorau.adv.br"] [uri "/wp-login.php"] [unique_id "al9YE1cagwCeNbomjVs5XwAB61k"]
[Tue Jul 21 08:29:23.499089 2026] [security2:error] [pid 419508:tid 419668] [client 172.234.129.144:50584] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "nrfilmes.com"] [uri "/wp-json/batch/v1"] [unique_id "al9YE1cagwCeNbomjVs5YwAAAa0"]
[Tue Jul 21 08:29:23.589046 2026] [security2:error] [pid 418108:tid 418323] [client 202.179.75.202:44068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YEw0cxofL2J1zwYrXngAAAV0"]
[Tue Jul 21 08:29:23.589166 2026] [security2:error] [pid 418108:tid 418323] [client 202.179.75.202:44068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YEw0cxofL2J1zwYrXngAAAV0"]
[Tue Jul 21 08:29:23.621968 2026] [security2:error] [pid 418108:tid 418280] [client 20.104.96.117:46481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/ip.php"] [unique_id "al9YEw0cxofL2J1zwYrXnwAAATI"]
[Tue Jul 21 08:29:23.623081 2026] [security2:error] [pid 419508:tid 419766] [client 172.234.129.144:50584] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "nrfilmes.com"] [uri "/"] [unique_id "al9YE1cagwCeNbomjVs5ZQAAAg4"]
[Tue Jul 21 08:29:23.640232 2026] [security2:error] [pid 418108:tid 418350] [client 74.249.245.134:55516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/edit.php"] [unique_id "al9YEw0cxofL2J1zwYrXoAAAAXg"]
[Tue Jul 21 08:29:23.746710 2026] [security2:error] [pid 418108:tid 418205] [remote 57.141.18.116:60736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9YEw0cxofL2J1zwYrXpAABG14"]
[Tue Jul 21 08:29:23.892136 2026] [security2:error] [pid 418108:tid 418289] [client 59.184.181.113:52532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.181.184.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9YEw0cxofL2J1zwYrXpgAAATs"]
[Tue Jul 21 08:29:23.893260 2026] [security2:error] [pid 418108:tid 418289] [client 59.184.181.113:52532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9YEw0cxofL2J1zwYrXpgAAATs"]
[Tue Jul 21 08:29:24.075322 2026] [security2:error] [pid 419508:tid 419690] [client 111.93.58.162:30328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YFFcagwCeNbomjVs5cAAAAcM"]
[Tue Jul 21 08:29:24.075457 2026] [security2:error] [pid 419508:tid 419690] [client 111.93.58.162:30328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YFFcagwCeNbomjVs5cAAAAcM"]
[Tue Jul 21 08:29:24.218170 2026] [security2:error] [pid 419508:tid 419649] [client 20.104.96.117:46583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/kq1.php"] [unique_id "al9YFFcagwCeNbomjVs5cgAAAZo"]
[Tue Jul 21 08:29:24.521480 2026] [security2:error] [pid 419508:tid 419766] [client 74.249.245.134:55527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/166.php"] [unique_id "al9YFFcagwCeNbomjVs5fQAAAg4"]
[Tue Jul 21 08:29:24.578486 2026] [security2:error] [pid 418108:tid 418227] [remote 114.34.90.9:45612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9YFA0cxofL2J1zwYrXqgABQnQ"]
[Tue Jul 21 08:29:24.620517 2026] [security2:error] [pid 418108:tid 418333] [client 152.59.34.51:65398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YFA0cxofL2J1zwYrXqwAAAWc"]
[Tue Jul 21 08:29:24.620627 2026] [security2:error] [pid 418108:tid 418333] [client 152.59.34.51:65398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YFA0cxofL2J1zwYrXqwAAAWc"]
[Tue Jul 21 08:29:24.814687 2026] [security2:error] [pid 419508:tid 419618] [remote 45.79.123.44:49176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "link.aede.com.br"] [uri "/wp-login.php"] [unique_id "al9YFFcagwCeNbomjVs5hQABu20"]
[Tue Jul 21 08:29:24.947278 2026] [security2:error] [pid 419508:tid 419527] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/info.php"] [unique_id "al9YFFcagwCeNbomjVs5hwACCBI"], referer: http://www.vidrosprovetro.com.br/info.php
[Tue Jul 21 08:29:25.116383 2026] [security2:error] [pid 418108:tid 418211] [remote 45.79.123.44:35018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9YFQ0cxofL2J1zwYrXsQABamQ"]
[Tue Jul 21 08:29:25.496357 2026] [security2:error] [pid 418108:tid 418327] [client 20.104.96.117:46494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9YFQ0cxofL2J1zwYrXuAAAAWE"]
[Tue Jul 21 08:29:26.178920 2026] [security2:error] [pid 418108:tid 418334] [client 143.244.57.92:60552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YFg0cxofL2J1zwYrXzwAAAWg"]
[Tue Jul 21 08:29:26.179042 2026] [security2:error] [pid 418108:tid 418334] [client 143.244.57.92:60552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "horiclinicaguarulhos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YFg0cxofL2J1zwYrXzwAAAWg"]
[Tue Jul 21 08:29:26.281965 2026] [security2:error] [pid 418108:tid 418297] [client 74.249.245.134:37717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/8.php"] [unique_id "al9YFg0cxofL2J1zwYrX0wAAAUM"]
[Tue Jul 21 08:29:26.430030 2026] [security2:error] [pid 418108:tid 418294] [client 204.12.208.18:55371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.erp.bavos.com.br"] [uri "/wp-includes/x6f55a1/index.php"] [unique_id "al9YFg0cxofL2J1zwYrX2gAAAUA"], referer: https://www.erp.bavos.com.br/wp-includes/x6f55a1/index.php
[Tue Jul 21 08:29:26.440444 2026] [security2:error] [pid 418108:tid 418348] [client 195.49.128.211:53500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YFg0cxofL2J1zwYrX2wAAAXY"]
[Tue Jul 21 08:29:26.440546 2026] [security2:error] [pid 418108:tid 418348] [client 195.49.128.211:53500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YFg0cxofL2J1zwYrX2wAAAXY"]
[Tue Jul 21 08:29:26.461693 2026] [security2:error] [pid 418108:tid 418252] [client 14.245.224.124:62993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YFg0cxofL2J1zwYrX3AAAARY"]
[Tue Jul 21 08:29:26.461802 2026] [security2:error] [pid 418108:tid 418252] [client 14.245.224.124:62993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YFg0cxofL2J1zwYrX3AAAARY"]
[Tue Jul 21 08:29:26.545778 2026] [security2:error] [pid 418108:tid 418222] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YFg0cxofL2J1zwYrX3QABLG8"]
[Tue Jul 21 08:29:26.545955 2026] [security2:error] [pid 418108:tid 418274] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YFg0cxofL2J1zwYrX3QABLG8"]
[Tue Jul 21 08:29:26.597956 2026] [security2:error] [pid 418108:tid 418327] [client 128.127.105.184:34744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9YFg0cxofL2J1zwYrX4gAAAWE"]
[Tue Jul 21 08:29:26.598039 2026] [security2:error] [pid 418108:tid 418327] [client 128.127.105.184:34744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9YFg0cxofL2J1zwYrX4gAAAWE"]
[Tue Jul 21 08:29:26.645982 2026] [security2:error] [pid 418108:tid 418244] [client 204.12.208.18:55378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "booking.bavos.com.br"] [uri "/wp-content/wp77a29b/index.php"] [unique_id "al9YFg0cxofL2J1zwYrX4wAAAQ4"], referer: https://booking.bavos.com.br/wp-content/wp77a29b/index.php
[Tue Jul 21 08:29:26.746316 2026] [security2:error] [pid 418108:tid 418337] [client 204.12.208.18:55380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clinic.bavos.com.br"] [uri "/wp-content/xb9ac88/index.php"] [unique_id "al9YFg0cxofL2J1zwYrX5wAAAWs"], referer: https://clinic.bavos.com.br/wp-content/xb9ac88/index.php
[Tue Jul 21 08:29:26.815580 2026] [security2:error] [pid 418108:tid 418361] [client 103.151.46.103:52874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YFg0cxofL2J1zwYrX6AAAAYM"]
[Tue Jul 21 08:29:26.815712 2026] [security2:error] [pid 418108:tid 418361] [client 103.151.46.103:52874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YFg0cxofL2J1zwYrX6AAAAYM"]
[Tue Jul 21 08:29:26.817580 2026] [security2:error] [pid 418108:tid 418248] [client 20.104.96.117:62612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/h02ugyh.php"] [unique_id "al9YFg0cxofL2J1zwYrX6QAAARI"]
[Tue Jul 21 08:29:26.960822 2026] [security2:error] [pid 418108:tid 418352] [client 128.201.99.135:54502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.99.201.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9YFg0cxofL2J1zwYrYEQAAAXo"]
[Tue Jul 21 08:29:26.960924 2026] [security2:error] [pid 418108:tid 418352] [client 128.201.99.135:54502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jorgecostaadvogados.com"] [uri "/xmlrpc.php"] [unique_id "al9YFg0cxofL2J1zwYrYEQAAAXo"]
[Tue Jul 21 08:29:26.965894 2026] [security2:error] [pid 418108:tid 418298] [client 204.12.208.18:55385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "davinci.bavos.com.br"] [uri "/wp-includes/im7e7a13/index.php"] [unique_id "al9YFg0cxofL2J1zwYrYEgAAAUQ"], referer: https://davinci.bavos.com.br/wp-includes/im7e7a13/index.php
[Tue Jul 21 08:29:26.966066 2026] [security2:error] [pid 418108:tid 418305] [client 204.12.208.18:55383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dash.bavos.com.br"] [uri "/wp-content/xc33b01/index.php"] [unique_id "al9YFg0cxofL2J1zwYrYEwAAAUs"], referer: https://dash.bavos.com.br/wp-content/xc33b01/index.php
[Tue Jul 21 08:29:26.993618 2026] [security2:error] [pid 418108:tid 418299] [client 204.12.208.18:55391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.erp.bavos.com.br"] [uri "/wp-includes/x6f55a1/index.php"] [unique_id "al9YFg0cxofL2J1zwYrYFgAAAUU"], referer: https://www.erp.bavos.com.br/wp-includes/x6f55a1/index.php
[Tue Jul 21 08:29:27.102160 2026] [security2:error] [pid 418108:tid 418357] [client 204.12.208.18:55390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drive.bavos.com.br"] [uri "/wp-content/jsdb3fca/index.php"] [unique_id "al9YFw0cxofL2J1zwYrYIgAAAX8"], referer: https://drive.bavos.com.br/wp-content/jsdb3fca/index.php
[Tue Jul 21 08:29:27.200622 2026] [security2:error] [pid 418108:tid 418345] [client 204.12.208.18:55393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finance.bavos.com.br"] [uri "/wp-includes/pldb3fca/index.php"] [unique_id "al9YFw0cxofL2J1zwYrYKgAAAXM"], referer: https://finance.bavos.com.br/wp-includes/pldb3fca/index.php
[Tue Jul 21 08:29:27.213221 2026] [security2:error] [pid 418108:tid 418312] [client 204.12.208.18:55397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "booking.bavos.com.br"] [uri "/wp-content/wp77a29b/index.php"] [unique_id "al9YFw0cxofL2J1zwYrYKwAAAVI"], referer: https://booking.bavos.com.br/wp-content/wp77a29b/index.php
[Tue Jul 21 08:29:27.316716 2026] [security2:error] [pid 418108:tid 418247] [client 204.12.208.18:55398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clinic.bavos.com.br"] [uri "/wp-content/xb9ac88/index.php"] [unique_id "al9YFw0cxofL2J1zwYrYLgAAARE"], referer: https://clinic.bavos.com.br/wp-content/xb9ac88/index.php
[Tue Jul 21 08:29:27.337979 2026] [security2:error] [pid 418108:tid 418248] [client 204.12.208.18:55396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.bavos.com.br"] [uri "/wp-includes/jsdb3fca/index.php"] [unique_id "al9YFw0cxofL2J1zwYrYLwAAARI"], referer: https://forms.bavos.com.br/wp-includes/jsdb3fca/index.php
[Tue Jul 21 08:29:27.401756 2026] [security2:error] [pid 418108:tid 418367] [client 122.176.100.127:60620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YFw0cxofL2J1zwYrYMQAAAYk"]
[Tue Jul 21 08:29:27.401926 2026] [security2:error] [pid 418108:tid 418367] [client 122.176.100.127:60620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YFw0cxofL2J1zwYrYMQAAAYk"]
[Tue Jul 21 08:29:27.453220 2026] [security2:error] [pid 418108:tid 418245] [client 109.248.148.246:58058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9YFw0cxofL2J1zwYrYNAAAAQ8"]
[Tue Jul 21 08:29:27.453315 2026] [security2:error] [pid 418108:tid 418245] [client 109.248.148.246:58058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9YFw0cxofL2J1zwYrYNAAAAQ8"]
[Tue Jul 21 08:29:27.501247 2026] [security2:error] [pid 418108:tid 418346] [client 61.1.167.83:49230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YFw0cxofL2J1zwYrYNwAAAXQ"]
[Tue Jul 21 08:29:27.501328 2026] [security2:error] [pid 418108:tid 418346] [client 61.1.167.83:49230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YFw0cxofL2J1zwYrYNwAAAXQ"]
[Tue Jul 21 08:29:27.558413 2026] [security2:error] [pid 418108:tid 418287] [client 204.12.208.18:55408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.erp.bavos.com.br"] [uri "/wp-includes/x6f55a1/index.php"] [unique_id "al9YFw0cxofL2J1zwYrYOAAAATk"], referer: https://www.erp.bavos.com.br/wp-includes/x6f55a1/index.php
[Tue Jul 21 08:29:27.558636 2026] [security2:error] [pid 418108:tid 418315] [client 204.12.208.18:55406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "davinci.bavos.com.br"] [uri "/wp-includes/im7e7a13/index.php"] [unique_id "al9YFw0cxofL2J1zwYrYOQAAAVU"], referer: https://davinci.bavos.com.br/wp-includes/im7e7a13/index.php
[Tue Jul 21 08:29:27.560066 2026] [security2:error] [pid 418108:tid 418313] [client 204.12.208.18:55407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dash.bavos.com.br"] [uri "/wp-content/xc33b01/index.php"] [unique_id "al9YFw0cxofL2J1zwYrYOgAAAVM"], referer: https://dash.bavos.com.br/wp-content/xc33b01/index.php
[Tue Jul 21 08:29:27.634256 2026] [security2:error] [pid 418108:tid 418334] [client 204.12.208.18:55401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gratech.bavos.com.br"] [uri "/wp-includes/br627f88/index.php"] [unique_id "al9YFw0cxofL2J1zwYrYPwAAAWg"], referer: https://gratech.bavos.com.br/wp-includes/br627f88/index.php
[Tue Jul 21 08:29:27.696165 2026] [security2:error] [pid 418108:tid 418326] [client 204.12.208.18:55410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drive.bavos.com.br"] [uri "/wp-content/jsdb3fca/index.php"] [unique_id "al9YFw0cxofL2J1zwYrYQQAAAWA"], referer: https://drive.bavos.com.br/wp-content/jsdb3fca/index.php
[Tue Jul 21 08:29:27.891305 2026] [security2:error] [pid 418108:tid 418327] [client 204.12.208.18:55412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finance.bavos.com.br"] [uri "/wp-includes/pldb3fca/index.php"] [unique_id "al9YFw0cxofL2J1zwYrYRwAAAWE"], referer: https://finance.bavos.com.br/wp-includes/pldb3fca/index.php
[Tue Jul 21 08:29:27.891415 2026] [security2:error] [pid 418108:tid 418311] [client 204.12.208.18:55413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "booking.bavos.com.br"] [uri "/wp-content/wp77a29b/index.php"] [unique_id "al9YFw0cxofL2J1zwYrYRgAAAVE"], referer: https://booking.bavos.com.br/wp-content/wp77a29b/index.php
[Tue Jul 21 08:29:27.936154 2026] [security2:error] [pid 418108:tid 418305] [client 204.12.208.18:55415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "clinic.bavos.com.br"] [uri "/wp-content/xb9ac88/index.php"] [unique_id "al9YFw0cxofL2J1zwYrYSAAAAUs"], referer: https://clinic.bavos.com.br/wp-content/xb9ac88/index.php
[Tue Jul 21 08:29:27.970324 2026] [security2:error] [pid 418108:tid 418349] [client 204.12.208.18:55417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.bavos.com.br"] [uri "/wp-includes/jsdb3fca/index.php"] [unique_id "al9YFw0cxofL2J1zwYrYTQAAAXc"], referer: https://forms.bavos.com.br/wp-includes/jsdb3fca/index.php
[Tue Jul 21 08:29:28.020521 2026] [security2:error] [pid 418108:tid 418280] [client 20.197.192.193:5986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/acew67.php"] [unique_id "al9YGA0cxofL2J1zwYrYUQAAATI"]
[Tue Jul 21 08:29:28.131599 2026] [security2:error] [pid 418108:tid 418151] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YGA0cxofL2J1zwYrYVQABHig"]
[Tue Jul 21 08:29:28.131764 2026] [security2:error] [pid 418108:tid 418260] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YGA0cxofL2J1zwYrYVQABHig"]
[Tue Jul 21 08:29:28.247846 2026] [security2:error] [pid 418108:tid 418257] [client 204.12.208.18:55421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "davinci.bavos.com.br"] [uri "/wp-includes/im7e7a13/index.php"] [unique_id "al9YGA0cxofL2J1zwYrYVwAAARs"], referer: https://davinci.bavos.com.br/wp-includes/im7e7a13/index.php
[Tue Jul 21 08:29:28.248266 2026] [security2:error] [pid 418108:tid 418285] [client 204.12.208.18:55422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dash.bavos.com.br"] [uri "/wp-content/xc33b01/index.php"] [unique_id "al9YGA0cxofL2J1zwYrYWAAAATc"], referer: https://dash.bavos.com.br/wp-content/xc33b01/index.php
[Tue Jul 21 08:29:28.372307 2026] [security2:error] [pid 418108:tid 418304] [client 204.12.208.18:55427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gratech.bavos.com.br"] [uri "/wp-includes/br627f88/index.php"] [unique_id "al9YGA0cxofL2J1zwYrYXQAAAUo"], referer: https://gratech.bavos.com.br/wp-includes/br627f88/index.php
[Tue Jul 21 08:29:28.385266 2026] [security2:error] [pid 418108:tid 418345] [client 204.12.208.18:55430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drive.bavos.com.br"] [uri "/wp-content/jsdb3fca/index.php"] [unique_id "al9YGA0cxofL2J1zwYrYXgAAAXM"], referer: https://drive.bavos.com.br/wp-content/jsdb3fca/index.php
[Tue Jul 21 08:29:28.385854 2026] [security2:error] [pid 418108:tid 418244] [client 223.181.60.88:10728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YGA0cxofL2J1zwYrYXwAAAQ4"]
[Tue Jul 21 08:29:28.385963 2026] [security2:error] [pid 418108:tid 418244] [client 223.181.60.88:10728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YGA0cxofL2J1zwYrYXwAAAQ4"]
[Tue Jul 21 08:29:28.513686 2026] [security2:error] [pid 418108:tid 418343] [client 204.12.208.18:55433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "finance.bavos.com.br"] [uri "/wp-includes/pldb3fca/index.php"] [unique_id "al9YGA0cxofL2J1zwYrYYwAAAXE"], referer: https://finance.bavos.com.br/wp-includes/pldb3fca/index.php
[Tue Jul 21 08:29:28.670662 2026] [security2:error] [pid 418108:tid 418362] [client 20.197.192.193:5574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/bscclapb.php"] [unique_id "al9YGA0cxofL2J1zwYrYagAAAYQ"]
[Tue Jul 21 08:29:28.706606 2026] [security2:error] [pid 418108:tid 418339] [client 204.12.208.18:55429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/wp-content/qq47ff83/index.php"] [unique_id "al9YGA0cxofL2J1zwYrYbAAAAW0"], referer: https://ia.bavos.com.br/wp-content/qq47ff83/index.php
[Tue Jul 21 08:29:28.728402 2026] [security2:error] [pid 418108:tid 418256] [client 184.154.139.38:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "fidellium.com"] [uri "/wp-content/uploads/elementor/google-fonts/css/roboto.css"] [unique_id "al9YGA0cxofL2J1zwYrYbQABGho"]
[Tue Jul 21 08:29:28.774838 2026] [security2:error] [pid 418108:tid 418321] [client 204.12.208.18:55434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "forms.bavos.com.br"] [uri "/wp-includes/jsdb3fca/index.php"] [unique_id "al9YGA0cxofL2J1zwYrYbwAAAVs"], referer: https://forms.bavos.com.br/wp-includes/jsdb3fca/index.php
[Tue Jul 21 08:29:28.823135 2026] [security2:error] [pid 418108:tid 418227] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YGA0cxofL2J1zwYrYcAABPHQ"]
[Tue Jul 21 08:29:28.823281 2026] [security2:error] [pid 418108:tid 418290] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YGA0cxofL2J1zwYrYcAABPHQ"]
[Tue Jul 21 08:29:28.910801 2026] [security2:error] [pid 418108:tid 418348] [client 141.11.107.74:60691] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.vivaconcierge.com.br"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "al9YGA0cxofL2J1zwYrYcQAAAXY"]
[Tue Jul 21 08:29:28.916767 2026] [security2:error] [pid 418108:tid 418361] [client 141.11.107.74:60695] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.vivaconcierge.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9YGA0cxofL2J1zwYrYcwAAAYM"]
[Tue Jul 21 08:29:28.916769 2026] [security2:error] [pid 418108:tid 418337] [client 141.11.107.74:60694] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.vivaconcierge.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9YGA0cxofL2J1zwYrYcgAAAWs"]
[Tue Jul 21 08:29:28.935283 2026] [security2:error] [pid 418108:tid 418327] [client 141.11.107.74:60696] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "vivaconcierge.com.br"] [uri "/"] [unique_id "al9YGA0cxofL2J1zwYrYdAAAAWE"]
[Tue Jul 21 08:29:28.966310 2026] [security2:error] [pid 418108:tid 418311] [client 141.11.107.74:60697] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.vivaconcierge.com.br"] [uri "/"] [unique_id "al9YGA0cxofL2J1zwYrYdQAAAVE"]
[Tue Jul 21 08:29:28.987069 2026] [security2:error] [pid 418108:tid 418265] [client 141.11.107.74:60699] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.vivaconcierge.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9YGA0cxofL2J1zwYrYdwAAASM"]
[Tue Jul 21 08:29:29.003588 2026] [security2:error] [pid 418108:tid 418305] [client 141.11.107.74:60702] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.vivaconcierge.com.br"] [uri "/"] [unique_id "al9YGQ0cxofL2J1zwYrYeAAAAUs"]
[Tue Jul 21 08:29:29.065041 2026] [security2:error] [pid 418108:tid 418331] [client 74.249.245.134:55521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/ws38.php"] [unique_id "al9YGQ0cxofL2J1zwYrYeQAAAWU"]
[Tue Jul 21 08:29:29.091650 2026] [security2:error] [pid 418108:tid 418286] [client 20.197.192.193:5572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/else1.php"] [unique_id "al9YGQ0cxofL2J1zwYrYegAAATg"]
[Tue Jul 21 08:29:29.166340 2026] [security2:error] [pid 418108:tid 418241] [client 141.11.107.74:60753] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ftp.vivaconcierge.com.br"] [uri "/"] [unique_id "al9YGQ0cxofL2J1zwYrYfgAAAQs"]
[Tue Jul 21 08:29:29.193560 2026] [security2:error] [pid 418108:tid 418251] [client 204.12.208.18:55443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gratech.bavos.com.br"] [uri "/wp-includes/br627f88/index.php"] [unique_id "al9YGQ0cxofL2J1zwYrYggAAARU"], referer: https://gratech.bavos.com.br/wp-includes/br627f88/index.php
[Tue Jul 21 08:29:29.351161 2026] [security2:error] [pid 418108:tid 418349] [client 49.144.66.253:33737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YGQ0cxofL2J1zwYrYiAAAAXc"]
[Tue Jul 21 08:29:29.351413 2026] [security2:error] [pid 418108:tid 418349] [client 49.144.66.253:33737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YGQ0cxofL2J1zwYrYiAAAAXc"]
[Tue Jul 21 08:29:29.455350 2026] [security2:error] [pid 418108:tid 418255] [client 204.12.208.18:55452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/wp-content/qq47ff83/index.php"] [unique_id "al9YGQ0cxofL2J1zwYrYiQAAARk"], referer: https://ia.bavos.com.br/wp-content/qq47ff83/index.php
[Tue Jul 21 08:29:29.525400 2026] [security2:error] [pid 418108:tid 418335] [client 20.104.96.117:46496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-temp.php"] [unique_id "al9YGQ0cxofL2J1zwYrYiwAAAWk"]
[Tue Jul 21 08:29:29.553559 2026] [security2:error] [pid 418108:tid 418252] [client 204.12.208.18:55438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perfex.bavos.com.br"] [uri "/wp-content/xbdbd8c/index.php"] [unique_id "al9YGQ0cxofL2J1zwYrYjgAAARY"], referer: https://perfex.bavos.com.br/wp-content/xbdbd8c/index.php
[Tue Jul 21 08:29:29.553961 2026] [security2:error] [pid 418108:tid 418254] [client 204.12.208.18:55439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juridic.bavos.com.br"] [uri "/wp-content/x2d6601/index.php"] [unique_id "al9YGQ0cxofL2J1zwYrYjwAAARg"], referer: https://juridic.bavos.com.br/wp-content/x2d6601/index.php
[Tue Jul 21 08:29:29.654377 2026] [security2:error] [pid 418108:tid 418269] [client 184.154.139.38:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fidellium.com"] [uri "/wp-content/uploads/elementor/css/post-2549.css"] [unique_id "al9YGQ0cxofL2J1zwYrYlwABJyY"]
[Tue Jul 21 08:29:29.745864 2026] [security2:error] [pid 418108:tid 418362] [client 74.7.175.165:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rdmengenhariaeletrica.bomexito.com.br"] [uri "/robots.txt"] [unique_id "al9YGQ0cxofL2J1zwYrYngAAAYQ"]
[Tue Jul 21 08:29:29.747569 2026] [security2:error] [pid 418108:tid 418293] [client 74.7.175.165:45080] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rdmengenhariaeletrica.bomexito.com.br"] [uri "/robots.txt"] [unique_id "al9YGQ0cxofL2J1zwYrYmgABP2M"]
[Tue Jul 21 08:29:29.782569 2026] [security2:error] [pid 418108:tid 418321] [client 34.76.2.141:52868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9YGQ0cxofL2J1zwYrYoQAAAVs"]
[Tue Jul 21 08:29:29.820967 2026] [security2:error] [pid 418108:tid 418222] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YGQ0cxofL2J1zwYrYogABDm8"]
[Tue Jul 21 08:29:29.821135 2026] [security2:error] [pid 418108:tid 418244] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YGQ0cxofL2J1zwYrYogABDm8"]
[Tue Jul 21 08:29:30.340357 2026] [security2:error] [pid 418108:tid 418296] [client 204.12.208.18:55473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/wp-content/qq47ff83/index.php"] [unique_id "al9YGg0cxofL2J1zwYrYswAAAUI"], referer: https://ia.bavos.com.br/wp-content/qq47ff83/index.php
[Tue Jul 21 08:29:30.402371 2026] [security2:error] [pid 418108:tid 418328] [client 204.12.208.18:55475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perfex.bavos.com.br"] [uri "/wp-content/xbdbd8c/index.php"] [unique_id "al9YGg0cxofL2J1zwYrYtgAAAWI"], referer: https://perfex.bavos.com.br/wp-content/xbdbd8c/index.php
[Tue Jul 21 08:29:30.507680 2026] [security2:error] [pid 418108:tid 418146] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/php.php"] [unique_id "al9YGg0cxofL2J1zwYrYuAABGSM"], referer: http://www.vidrosprovetro.com.br/php.php
[Tue Jul 21 08:29:30.575072 2026] [security2:error] [pid 418108:tid 418316] [client 204.12.208.18:55478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juridic.bavos.com.br"] [uri "/wp-content/x2d6601/index.php"] [unique_id "al9YGg0cxofL2J1zwYrYvAAAAVY"], referer: https://juridic.bavos.com.br/wp-content/x2d6601/index.php
[Tue Jul 21 08:29:30.583895 2026] [security2:error] [pid 418108:tid 418304] [client 187.125.243.197:56952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YGg0cxofL2J1zwYrYvQAAAUo"]
[Tue Jul 21 08:29:30.584038 2026] [security2:error] [pid 418108:tid 418304] [client 187.125.243.197:56952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YGg0cxofL2J1zwYrYvQAAAUo"]
[Tue Jul 21 08:29:30.641121 2026] [security2:error] [pid 418108:tid 418240] [client 34.76.2.141:62142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.2.76.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YGg0cxofL2J1zwYrYwgAAAQo"]
[Tue Jul 21 08:29:30.669844 2026] [security2:error] [pid 418108:tid 418226] [remote 45.79.123.44:53098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YGg0cxofL2J1zwYrYxAABKXM"]
[Tue Jul 21 08:29:30.669970 2026] [security2:error] [pid 418108:tid 418271] [client 45.79.123.44:53098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YGg0cxofL2J1zwYrYxAABKXM"]
[Tue Jul 21 08:29:30.859748 2026] [security2:error] [pid 418108:tid 418270] [client 151.63.71.144:56649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.71.63.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YGg0cxofL2J1zwYrYywAAASg"]
[Tue Jul 21 08:29:30.860181 2026] [security2:error] [pid 418108:tid 418270] [client 151.63.71.144:56649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YGg0cxofL2J1zwYrYywAAASg"]
[Tue Jul 21 08:29:31.136122 2026] [security2:error] [pid 418108:tid 418256] [client 204.12.208.18:55498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "perfex.bavos.com.br"] [uri "/wp-content/xbdbd8c/index.php"] [unique_id "al9YGw0cxofL2J1zwYrY0AAAARo"], referer: https://perfex.bavos.com.br/wp-content/xbdbd8c/index.php
[Tue Jul 21 08:29:31.225421 2026] [security2:error] [pid 418108:tid 418350] [client 20.197.192.193:5569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/tkikikoko.php"] [unique_id "al9YGw0cxofL2J1zwYrY1QAAAXg"]
[Tue Jul 21 08:29:31.383916 2026] [security2:error] [pid 418108:tid 418244] [client 204.12.208.18:55502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juridic.bavos.com.br"] [uri "/wp-content/x2d6601/index.php"] [unique_id "al9YGw0cxofL2J1zwYrY3QAAAQ4"], referer: https://juridic.bavos.com.br/wp-content/x2d6601/index.php
[Tue Jul 21 08:29:31.458516 2026] [security2:error] [pid 418108:tid 418334] [client 34.76.2.141:57039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9YGw0cxofL2J1zwYrY3wAAAWg"]
[Tue Jul 21 08:29:32.274625 2026] [security2:error] [pid 418108:tid 418252] [client 34.76.2.141:61763] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9YHA0cxofL2J1zwYrY9gAAARY"]
[Tue Jul 21 08:29:32.355371 2026] [security2:error] [pid 418108:tid 418337] [client 74.249.245.134:54933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/a7.php"] [unique_id "al9YHA0cxofL2J1zwYrY-QAAAWs"]
[Tue Jul 21 08:29:32.547863 2026] [security2:error] [pid 418108:tid 418262] [client 195.49.128.211:61571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YHA0cxofL2J1zwYrY_wAAASA"]
[Tue Jul 21 08:29:32.548041 2026] [security2:error] [pid 418108:tid 418262] [client 195.49.128.211:61571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YHA0cxofL2J1zwYrY_wAAASA"]
[Tue Jul 21 08:29:32.682006 2026] [security2:error] [pid 418108:tid 418345] [client 20.104.96.117:62665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9YHA0cxofL2J1zwYrZAQAAAXM"]
[Tue Jul 21 08:29:33.104990 2026] [security2:error] [pid 418108:tid 418240] [client 34.76.2.141:55401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9YHQ0cxofL2J1zwYrZEAAAAQo"]
[Tue Jul 21 08:29:33.152366 2026] [security2:error] [pid 418108:tid 418254] [client 117.213.202.34:51791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YHQ0cxofL2J1zwYrZEgAAARg"]
[Tue Jul 21 08:29:33.152526 2026] [security2:error] [pid 418108:tid 418254] [client 117.213.202.34:51791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YHQ0cxofL2J1zwYrZEgAAARg"]
[Tue Jul 21 08:29:33.194738 2026] [security2:error] [pid 418108:tid 418256] [client 184.154.139.38:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fidellium.com"] [uri "/wp-content/uploads/elementor/css/post-261.css"] [unique_id "al9YHQ0cxofL2J1zwYrZEwABGl8"]
[Tue Jul 21 08:29:33.439170 2026] [security2:error] [pid 418108:tid 418346] [client 150.129.202.39:12710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YHQ0cxofL2J1zwYrZIQAAAXQ"]
[Tue Jul 21 08:29:33.439288 2026] [security2:error] [pid 418108:tid 418346] [client 150.129.202.39:12710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YHQ0cxofL2J1zwYrZIQAAAXQ"]
[Tue Jul 21 08:29:33.913662 2026] [security2:error] [pid 418108:tid 418266] [client 34.76.2.141:57713] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9YHQ0cxofL2J1zwYrZLwAAASQ"]
[Tue Jul 21 08:29:34.402797 2026] [security2:error] [pid 418108:tid 418345] [client 59.184.181.113:52924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.181.184.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9YHg0cxofL2J1zwYrZOwAAAXM"]
[Tue Jul 21 08:29:34.402958 2026] [security2:error] [pid 418108:tid 418345] [client 59.184.181.113:52924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9YHg0cxofL2J1zwYrZOwAAAXM"]
[Tue Jul 21 08:29:34.678872 2026] [security2:error] [pid 418108:tid 418293] [client 125.18.144.2:44304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YHg0cxofL2J1zwYrZQwAAAT8"]
[Tue Jul 21 08:29:34.678979 2026] [security2:error] [pid 418108:tid 418293] [client 125.18.144.2:44304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YHg0cxofL2J1zwYrZQwAAAT8"]
[Tue Jul 21 08:29:34.693840 2026] [security2:error] [pid 418108:tid 418275] [client 202.179.75.202:46988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YHg0cxofL2J1zwYrZRQAAAS0"]
[Tue Jul 21 08:29:34.693984 2026] [security2:error] [pid 418108:tid 418275] [client 202.179.75.202:46988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YHg0cxofL2J1zwYrZRQAAAS0"]
[Tue Jul 21 08:29:34.728666 2026] [security2:error] [pid 418108:tid 418260] [client 34.76.2.141:59065] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9YHg0cxofL2J1zwYrZRgAAAR4"]
[Tue Jul 21 08:29:34.869701 2026] [security2:error] [pid 418108:tid 418362] [client 184.154.139.38:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fidellium.com"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "al9YHg0cxofL2J1zwYrZUAABhBY"]
[Tue Jul 21 08:29:35.357567 2026] [security2:error] [pid 418108:tid 418343] [client 184.154.139.38:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fidellium.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al9YHw0cxofL2J1zwYrZYAABcQw"]
[Tue Jul 21 08:29:35.368409 2026] [security2:error] [pid 418108:tid 418347] [client 152.59.34.51:49030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YHw0cxofL2J1zwYrZYQAAAXU"]
[Tue Jul 21 08:29:35.368539 2026] [security2:error] [pid 418108:tid 418347] [client 152.59.34.51:49030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YHw0cxofL2J1zwYrZYQAAAXU"]
[Tue Jul 21 08:29:35.549621 2026] [security2:error] [pid 418108:tid 418349] [client 34.76.2.141:57644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9YHw0cxofL2J1zwYrZbAAAAXc"]
[Tue Jul 21 08:29:35.668003 2026] [security2:error] [pid 418108:tid 418361] [client 20.104.96.117:62672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9YHw0cxofL2J1zwYrZbQAAAYM"]
[Tue Jul 21 08:29:35.997394 2026] [security2:error] [pid 418108:tid 418248] [client 184.154.139.38:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fidellium.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "al9YHw0cxofL2J1zwYrZeAABEiM"]
[Tue Jul 21 08:29:36.059041 2026] [security2:error] [pid 418108:tid 418346] [client 20.220.225.223:19286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/wp-explorer.php"] [unique_id "al9YIA0cxofL2J1zwYrZfAAAAXQ"]
[Tue Jul 21 08:29:36.189898 2026] [security2:error] [pid 418108:tid 418193] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/php_info.php"] [unique_id "al9YIA0cxofL2J1zwYrZggABgVI"], referer: http://www.vidrosprovetro.com.br/php_info.php
[Tue Jul 21 08:29:36.387020 2026] [security2:error] [pid 418108:tid 418365] [client 20.104.96.117:46572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/jj.php"] [unique_id "al9YIA0cxofL2J1zwYrZiAAAAYc"]
[Tue Jul 21 08:29:36.464286 2026] [security2:error] [pid 418108:tid 418261] [client 34.76.2.141:60748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9YIA0cxofL2J1zwYrZigAAAR8"]
[Tue Jul 21 08:29:36.493009 2026] [security2:error] [pid 418108:tid 418367] [client 184.154.139.38:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fidellium.com"] [uri "/readme.html"] [unique_id "al9YIA0cxofL2J1zwYrZiwABiTs"]
[Tue Jul 21 08:29:36.913780 2026] [security2:error] [pid 418108:tid 418352] [client 74.249.245.134:55509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/classsmtps.php"] [unique_id "al9YIA0cxofL2J1zwYrZmAAAAXo"]
[Tue Jul 21 08:29:36.955978 2026] [http2:info] [pid 462418:tid 462418] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 08:29:37.021779 2026] [security2:error] [pid 418108:tid 418322] [client 195.49.128.211:54087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YIQ0cxofL2J1zwYrZmgAAAVw"]
[Tue Jul 21 08:29:37.021892 2026] [security2:error] [pid 418108:tid 418322] [client 195.49.128.211:54087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YIQ0cxofL2J1zwYrZmgAAAVw"]
[Tue Jul 21 08:29:37.053769 2026] [security2:error] [pid 462418:tid 462550] [client 213.152.186.163:42894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9YISIybD14CLOJBaR0hQAAAAI"]
[Tue Jul 21 08:29:37.053884 2026] [security2:error] [pid 462418:tid 462550] [client 213.152.186.163:42894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9YISIybD14CLOJBaR0hQAAAAI"]
[Tue Jul 21 08:29:37.094597 2026] [security2:error] [pid 418108:tid 418356] [client 109.248.148.246:38990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9YIQ0cxofL2J1zwYrZnQAAAX4"]
[Tue Jul 21 08:29:37.094716 2026] [security2:error] [pid 418108:tid 418356] [client 109.248.148.246:38990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9YIQ0cxofL2J1zwYrZnQAAAX4"]
[Tue Jul 21 08:29:37.191292 2026] [security2:error] [pid 462418:tid 462546] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YISIybD14CLOJBaR0iQAABX8"]
[Tue Jul 21 08:29:37.191457 2026] [security2:error] [pid 462418:tid 462553] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YISIybD14CLOJBaR0iQAABX8"]
[Tue Jul 21 08:29:37.272869 2026] [security2:error] [pid 418108:tid 418266] [client 185.213.175.37:48666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "azusacorretora.com.br"] [uri "/.git/HEAD"] [unique_id "al9YIQ0cxofL2J1zwYrZogAAASQ"]
[Tue Jul 21 08:29:37.273047 2026] [security2:error] [pid 418108:tid 418266] [client 185.213.175.37:48666] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "azusacorretora.com.br"] [uri "/.git/HEAD"] [unique_id "al9YIQ0cxofL2J1zwYrZogAAASQ"]
[Tue Jul 21 08:29:37.277767 2026] [security2:error] [pid 418108:tid 418244] [client 34.76.2.141:58886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9YIQ0cxofL2J1zwYrZowAAAQ4"]
[Tue Jul 21 08:29:37.355888 2026] [security2:error] [pid 418108:tid 418263] [client 103.151.46.103:53364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YIQ0cxofL2J1zwYrZpAAAASE"]
[Tue Jul 21 08:29:37.356145 2026] [security2:error] [pid 418108:tid 418263] [client 103.151.46.103:53364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YIQ0cxofL2J1zwYrZpAAAASE"]
[Tue Jul 21 08:29:37.469534 2026] [security2:error] [pid 418108:tid 418302] [client 20.104.96.117:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9YIQ0cxofL2J1zwYrZqAAAAUg"]
[Tue Jul 21 08:29:37.498357 2026] [autoindex:error] [pid 418108:tid 418367] [client 136.117.203.248:0] AH01276: Cannot serve directory /home1/evanir58/despensanatural.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:29:37.933462 2026] [qos:error] [pid 418108:tid 418114] [remote 57.141.18.32:38616] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.32, id=al9YIQ0cxofL2J1zwYrZtgABGQM
[Tue Jul 21 08:29:37.975140 2026] [security2:error] [pid 418108:tid 418270] [client 122.176.100.127:61095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YIQ0cxofL2J1zwYrZuAAAASg"]
[Tue Jul 21 08:29:37.975300 2026] [security2:error] [pid 418108:tid 418270] [client 122.176.100.127:61095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YIQ0cxofL2J1zwYrZuAAAASg"]
[Tue Jul 21 08:29:38.111427 2026] [security2:error] [pid 418108:tid 418352] [client 34.76.2.141:51185] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9YIg0cxofL2J1zwYrZvgAAAXo"]
[Tue Jul 21 08:29:38.195089 2026] [qos:error] [pid 418108:tid 418215] [remote 57.141.18.82:63028] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.82, id=al9YIg0cxofL2J1zwYrZvwABDGg
[Tue Jul 21 08:29:38.267681 2026] [qos:error] [pid 418108:tid 418188] [remote 57.141.18.125:43558] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.125, id=al9YIg0cxofL2J1zwYrZwAABU00
[Tue Jul 21 08:29:38.295223 2026] [security2:error] [pid 418108:tid 418359] [client 136.117.203.248:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.203.117.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "despensanatural.com.br.evanirluziadacosta1781720432299.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YIg0cxofL2J1zwYrZwgAAAYE"]
[Tue Jul 21 08:29:38.354319 2026] [security2:error] [pid 462418:tid 462421] [remote 167.71.132.111:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.132.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9YIiIybD14CLOJBaR0lAAAIQI"]
[Tue Jul 21 08:29:38.357213 2026] [security2:error] [pid 418108:tid 418234] [remote 216.38.28.47:58728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.28.38.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9YIg0cxofL2J1zwYrZwwABdXs"]
[Tue Jul 21 08:29:38.394720 2026] [security2:error] [pid 462418:tid 462577] [client 14.245.224.124:63526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YIiIybD14CLOJBaR0lQAAAB0"]
[Tue Jul 21 08:29:38.394846 2026] [security2:error] [pid 462418:tid 462577] [client 14.245.224.124:63526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YIiIybD14CLOJBaR0lQAAAB0"]
[Tue Jul 21 08:29:38.459074 2026] [security2:error] [pid 462418:tid 462582] [client 20.104.96.117:62615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/txets.php"] [unique_id "al9YIiIybD14CLOJBaR0lgAAACI"]
[Tue Jul 21 08:29:38.597480 2026] [security2:error] [pid 418108:tid 418144] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YIg0cxofL2J1zwYrZyQABIyE"]
[Tue Jul 21 08:29:38.597614 2026] [security2:error] [pid 418108:tid 418265] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YIg0cxofL2J1zwYrZyQABIyE"]
[Tue Jul 21 08:29:38.685886 2026] [security2:error] [pid 418108:tid 418267] [client 136.117.203.248:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "despensanatural.com.br.evanirluziadacosta1781720432299.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9YIg0cxofL2J1zwYrZzAAAASU"]
[Tue Jul 21 08:29:38.943834 2026] [security2:error] [pid 462418:tid 462580] [client 223.181.60.88:4208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YIiIybD14CLOJBaR0ngAAACA"]
[Tue Jul 21 08:29:38.944019 2026] [security2:error] [pid 462418:tid 462580] [client 223.181.60.88:4208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YIiIybD14CLOJBaR0ngAAACA"]
[Tue Jul 21 08:29:38.949836 2026] [security2:error] [pid 462418:tid 462586] [client 34.76.2.141:62195] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9YIiIybD14CLOJBaR0nwAAACY"]
[Tue Jul 21 08:29:38.975202 2026] [security2:error] [pid 462418:tid 462602] [client 109.248.148.246:43584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9YIiIybD14CLOJBaR0oAAAADY"]
[Tue Jul 21 08:29:38.975298 2026] [security2:error] [pid 462418:tid 462602] [client 109.248.148.246:43584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9YIiIybD14CLOJBaR0oAAAADY"]
[Tue Jul 21 08:29:39.080349 2026] [security2:error] [pid 418108:tid 418337] [client 136.117.203.248:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "despensanatural.com.br.evanirluziadacosta1781720432299.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9YIw0cxofL2J1zwYrZ0wAAAWs"]
[Tue Jul 21 08:29:39.081646 2026] [security2:error] [pid 462418:tid 462605] [client 20.104.96.117:62714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/dex.php"] [unique_id "al9YIyIybD14CLOJBaR0ogAAADk"]
[Tue Jul 21 08:29:39.367489 2026] [security2:error] [pid 418108:tid 418319] [client 89.238.167.134:34256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9YIw0cxofL2J1zwYrZ2AAAAVk"]
[Tue Jul 21 08:29:39.367649 2026] [security2:error] [pid 418108:tid 418319] [client 89.238.167.134:34256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9YIw0cxofL2J1zwYrZ2AAAAVk"]
[Tue Jul 21 08:29:39.508197 2026] [security2:error] [pid 462418:tid 462625] [client 20.104.96.117:46560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/xpwer1.php"] [unique_id "al9YIyIybD14CLOJBaR0qAAAAE0"]
[Tue Jul 21 08:29:39.523141 2026] [security2:error] [pid 462418:tid 462626] [client 136.117.203.248:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "despensanatural.com.br.evanirluziadacosta1781720432299.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9YIyIybD14CLOJBaR0qQAAAE4"]
[Tue Jul 21 08:29:39.578402 2026] [security2:error] [pid 418108:tid 418151] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YIw0cxofL2J1zwYrZ2gABfig"]
[Tue Jul 21 08:29:39.578598 2026] [security2:error] [pid 418108:tid 418356] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YIw0cxofL2J1zwYrZ2gABfig"]
[Tue Jul 21 08:29:39.669397 2026] [qos:error] [pid 462418:tid 462428] [remote 57.141.18.51:24452] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.51, id=al9YIyIybD14CLOJBaR0rQAATwk
[Tue Jul 21 08:29:39.714794 2026] [qos:error] [pid 462418:tid 462429] [remote 57.141.18.15:28172] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.15, id=al9YIyIybD14CLOJBaR0rgAAUwo
[Tue Jul 21 08:29:39.804982 2026] [security2:error] [pid 462418:tid 462614] [client 34.76.2.141:65226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9YIyIybD14CLOJBaR0rwAAAEI"]
[Tue Jul 21 08:29:39.922828 2026] [security2:error] [pid 462418:tid 462646] [client 136.117.203.248:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "despensanatural.com.br.evanirluziadacosta1781720432299.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9YIyIybD14CLOJBaR0sQAAAGI"]
[Tue Jul 21 08:29:40.010322 2026] [security2:error] [pid 462418:tid 462649] [client 20.104.96.117:46547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/flox.php"] [unique_id "al9YJCIybD14CLOJBaR0sgAAAGU"]
[Tue Jul 21 08:29:40.089719 2026] [security2:error] [pid 418108:tid 418302] [client 213.152.186.163:37984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9YJA0cxofL2J1zwYrZ5AAAAUg"]
[Tue Jul 21 08:29:40.089860 2026] [security2:error] [pid 418108:tid 418302] [client 213.152.186.163:37984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9YJA0cxofL2J1zwYrZ5AAAAUg"]
[Tue Jul 21 08:29:40.160804 2026] [security2:error] [pid 418108:tid 418315] [client 5.31.193.106:58621] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YJA0cxofL2J1zwYrZ5wAAAVU"]
[Tue Jul 21 08:29:40.160941 2026] [security2:error] [pid 418108:tid 418315] [client 5.31.193.106:58621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YJA0cxofL2J1zwYrZ5wAAAVU"]
[Tue Jul 21 08:29:40.244805 2026] [qos:error] [pid 418108:tid 418156] [remote 57.141.18.10:39346] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.10, id=al9YJA0cxofL2J1zwYrZ6AABSy0
[Tue Jul 21 08:29:40.307736 2026] [security2:error] [pid 418108:tid 418133] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YJA0cxofL2J1zwYrZ6QABHxY"]
[Tue Jul 21 08:29:40.308043 2026] [security2:error] [pid 418108:tid 418261] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YJA0cxofL2J1zwYrZ6QABHxY"]
[Tue Jul 21 08:29:40.399468 2026] [security2:error] [pid 418108:tid 418265] [client 136.117.203.248:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "despensanatural.com.br.evanirluziadacosta1781720432299.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9YJA0cxofL2J1zwYrZ6wAAASM"]
[Tue Jul 21 08:29:40.526526 2026] [security2:error] [pid 418108:tid 418316] [client 20.104.96.117:64236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/popo.php"] [unique_id "al9YJA0cxofL2J1zwYrZ7AAAAVY"]
[Tue Jul 21 08:29:40.539875 2026] [security2:error] [pid 462418:tid 462664] [client 49.144.66.253:30027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YJCIybD14CLOJBaR0uQAAAHQ"]
[Tue Jul 21 08:29:40.539993 2026] [security2:error] [pid 462418:tid 462664] [client 49.144.66.253:30027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YJCIybD14CLOJBaR0uQAAAHQ"]
[Tue Jul 21 08:29:40.636070 2026] [security2:error] [pid 418108:tid 418367] [client 34.76.2.141:56741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9YJA0cxofL2J1zwYrZ8QAAAYk"]
[Tue Jul 21 08:29:40.958400 2026] [security2:error] [pid 462418:tid 462674] [client 136.117.203.248:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "despensanatural.com.br.evanirluziadacosta1781720432299.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9YJCIybD14CLOJBaR0vwAAAH4"]
[Tue Jul 21 08:29:41.106068 2026] [security2:error] [pid 418108:tid 418298] [client 20.104.96.117:46507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/yas.php"] [unique_id "al9YJQ0cxofL2J1zwYrZ_wAAAUQ"]
[Tue Jul 21 08:29:41.109760 2026] [security2:error] [pid 462418:tid 462548] [client 187.125.243.197:57454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YJSIybD14CLOJBaR0wwAAAAA"]
[Tue Jul 21 08:29:41.109869 2026] [security2:error] [pid 462418:tid 462548] [client 187.125.243.197:57454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YJSIybD14CLOJBaR0wwAAAAA"]
[Tue Jul 21 08:29:41.370117 2026] [security2:error] [pid 462418:tid 462570] [client 136.117.203.248:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "despensanatural.com.br.evanirluziadacosta1781720432299.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9YJSIybD14CLOJBaR0xgAAABY"]
[Tue Jul 21 08:29:41.378161 2026] [security2:error] [pid 418108:tid 418253] [client 47.128.60.210:56660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "draanacarlalima.com.br"] [uri "/robots.txt"] [unique_id "al9YJQ0cxofL2J1zwYraBAAAARc"]
[Tue Jul 21 08:29:41.472538 2026] [security2:error] [pid 462418:tid 462553] [client 34.76.2.141:54506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9YJSIybD14CLOJBaR0yQAAAAU"]
[Tue Jul 21 08:29:41.797955 2026] [security2:error] [pid 418108:tid 418352] [client 136.117.203.248:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "despensanatural.com.br.evanirluziadacosta1781720432299.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9YJQ0cxofL2J1zwYraDQAAAXo"]
[Tue Jul 21 08:29:41.862877 2026] [security2:error] [pid 462418:tid 462434] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/i.php"] [unique_id "al9YJSIybD14CLOJBaR00AAAIw8"], referer: http://www.vidrosprovetro.com.br/i.php
[Tue Jul 21 08:29:42.191356 2026] [security2:error] [pid 462418:tid 462580] [client 136.117.203.248:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "despensanatural.com.br.evanirluziadacosta1781720432299.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9YJiIybD14CLOJBaR02AAAACA"]
[Tue Jul 21 08:29:42.225837 2026] [security2:error] [pid 462418:tid 462604] [client 20.104.96.117:62611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/file61.php"] [unique_id "al9YJiIybD14CLOJBaR02QAAADg"]
[Tue Jul 21 08:29:42.339371 2026] [security2:error] [pid 418108:tid 418266] [client 34.76.2.141:62545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9YJg0cxofL2J1zwYraGgAAASQ"]
[Tue Jul 21 08:29:42.513621 2026] [security2:error] [pid 462418:tid 462613] [client 20.220.225.223:19268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/akismet.php"] [unique_id "al9YJiIybD14CLOJBaR02wAAAEE"]
[Tue Jul 21 08:29:42.596754 2026] [security2:error] [pid 418108:tid 418275] [client 136.117.203.248:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "despensanatural.com.br.evanirluziadacosta1781720432299.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9YJg0cxofL2J1zwYraHgAAAS0"]
[Tue Jul 21 08:29:42.876548 2026] [security2:error] [pid 418108:tid 418357] [client 51.222.168.53:23482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "atividadessprontas.online"] [uri "/robots.txt"] [unique_id "al9YJg0cxofL2J1zwYraJAAAAX8"]
[Tue Jul 21 08:29:42.876677 2026] [security2:error] [pid 418108:tid 418357] [client 51.222.168.53:23482] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "atividadessprontas.online"] [uri "/robots.txt"] [unique_id "al9YJg0cxofL2J1zwYraJAAAAX8"]
[Tue Jul 21 08:29:42.896251 2026] [security2:error] [pid 462418:tid 462587] [client 20.104.96.117:46549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/water.php"] [unique_id "al9YJiIybD14CLOJBaR03wAAACc"]
[Tue Jul 21 08:29:43.011779 2026] [security2:error] [pid 418108:tid 418284] [client 136.117.203.248:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "despensanatural.com.br.evanirluziadacosta1781720432299.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9YJw0cxofL2J1zwYraKAAAATY"]
[Tue Jul 21 08:29:43.109357 2026] [security2:error] [pid 462418:tid 462615] [client 195.49.128.211:62171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YJyIybD14CLOJBaR04wAAAEM"]
[Tue Jul 21 08:29:43.109515 2026] [security2:error] [pid 462418:tid 462615] [client 195.49.128.211:62171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YJyIybD14CLOJBaR04wAAAEM"]
[Tue Jul 21 08:29:43.202115 2026] [security2:error] [pid 418108:tid 418313] [client 34.76.2.141:51219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seaportservicos.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9YJw0cxofL2J1zwYraKwAAAVM"]
[Tue Jul 21 08:29:43.221328 2026] [security2:error] [pid 462418:tid 462612] [client 150.129.202.39:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YJyIybD14CLOJBaR06wAAAEA"]
[Tue Jul 21 08:29:43.221486 2026] [security2:error] [pid 462418:tid 462612] [client 150.129.202.39:65480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YJyIybD14CLOJBaR06wAAAEA"]
[Tue Jul 21 08:29:43.230965 2026] [security2:error] [pid 462418:tid 462630] [client 74.7.230.22:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bio.deiacakes.com"] [uri "/index.php"] [unique_id "al9YJyIybD14CLOJBaR05gAAUhU"]
[Tue Jul 21 08:29:43.434947 2026] [security2:error] [pid 418108:tid 418297] [client 20.104.96.117:46471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/nano.php"] [unique_id "al9YJw0cxofL2J1zwYraLwAAAUM"]
[Tue Jul 21 08:29:43.436706 2026] [security2:error] [pid 462418:tid 462653] [client 136.117.203.248:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "despensanatural.com.br.evanirluziadacosta1781720432299.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9YJyIybD14CLOJBaR08QAAAGk"]
[Tue Jul 21 08:29:43.777165 2026] [security2:error] [pid 418108:tid 418296] [client 117.213.202.34:52341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YJw0cxofL2J1zwYraNgAAAUI"]
[Tue Jul 21 08:29:43.777306 2026] [security2:error] [pid 418108:tid 418296] [client 117.213.202.34:52341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YJw0cxofL2J1zwYraNgAAAUI"]
[Tue Jul 21 08:29:44.060608 2026] [security2:error] [pid 418108:tid 418338] [client 20.104.96.117:46556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/moon.php"] [unique_id "al9YKA0cxofL2J1zwYraPAAAAWw"]
[Tue Jul 21 08:29:44.116634 2026] [security2:error] [pid 418108:tid 418302] [client 74.7.230.25:60242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "dantonio.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9YKA0cxofL2J1zwYraPQABSBQ"]
[Tue Jul 21 08:29:44.290720 2026] [security2:error] [pid 418108:tid 418281] [client 51.222.168.60:15874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "atividadessprontas.online"] [uri "/"] [unique_id "al9YKA0cxofL2J1zwYraRQAAATM"]
[Tue Jul 21 08:29:44.290882 2026] [security2:error] [pid 418108:tid 418281] [client 51.222.168.60:15874] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "atividadessprontas.online"] [uri "/"] [unique_id "al9YKA0cxofL2J1zwYraRQAAATM"]
[Tue Jul 21 08:29:44.771015 2026] [security2:error] [pid 462418:tid 462568] [client 20.104.96.117:46591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-info.php"] [unique_id "al9YKCIybD14CLOJBaR1BAAAABQ"]
[Tue Jul 21 08:29:44.839846 2026] [security2:error] [pid 462418:tid 462570] [client 20.197.192.193:5578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9YKCIybD14CLOJBaR1BQAAABY"]
[Tue Jul 21 08:29:44.849438 2026] [security2:error] [pid 418108:tid 418154] [remote 34.74.242.206:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sejabarbara.com.br"] [uri "/robots.txt"] [unique_id "al9YKA0cxofL2J1zwYraTAABgSs"]
[Tue Jul 21 08:29:44.849581 2026] [security2:error] [pid 418108:tid 418359] [client 34.74.242.206:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sejabarbara.com.br"] [uri "/robots.txt"] [unique_id "al9YKA0cxofL2J1zwYraTAABgSs"]
[Tue Jul 21 08:29:44.892343 2026] [security2:error] [pid 462418:tid 462451] [remote 195.26.244.42:50424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9YKCIybD14CLOJBaR1BgAAcyA"]
[Tue Jul 21 08:29:45.154199 2026] [qos:error] [pid 462418:tid 462453] [remote 57.141.18.17:22118] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.17, id=al9YKSIybD14CLOJBaR1CAAAGyI
[Tue Jul 21 08:29:45.272793 2026] [security2:error] [pid 462418:tid 462454] [remote 34.74.242.206:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sejabarbara.com.br"] [uri "/"] [unique_id "al9YKSIybD14CLOJBaR1CwAAJSM"]
[Tue Jul 21 08:29:45.273113 2026] [security2:error] [pid 462418:tid 462585] [client 34.74.242.206:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sejabarbara.com.br"] [uri "/"] [unique_id "al9YKSIybD14CLOJBaR1CwAAJSM"]
[Tue Jul 21 08:29:45.293008 2026] [security2:error] [pid 462418:tid 462561] [client 59.184.181.113:53326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.181.184.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9YKSIybD14CLOJBaR1DAAAAA0"]
[Tue Jul 21 08:29:45.293194 2026] [security2:error] [pid 462418:tid 462561] [client 59.184.181.113:53326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9YKSIybD14CLOJBaR1DAAAAA0"]
[Tue Jul 21 08:29:45.341385 2026] [security2:error] [pid 462418:tid 462548] [client 61.1.167.83:49756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YKSIybD14CLOJBaR1DwAAAAA"]
[Tue Jul 21 08:29:45.341557 2026] [security2:error] [pid 462418:tid 462548] [client 61.1.167.83:49756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YKSIybD14CLOJBaR1DwAAAAA"]
[Tue Jul 21 08:29:45.516911 2026] [security2:error] [pid 418108:tid 418241] [client 111.93.58.162:59711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YKQ0cxofL2J1zwYraVAAAAQs"]
[Tue Jul 21 08:29:45.517038 2026] [security2:error] [pid 418108:tid 418241] [client 111.93.58.162:59711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YKQ0cxofL2J1zwYraVAAAAQs"]
[Tue Jul 21 08:29:45.534291 2026] [security2:error] [pid 418108:tid 418264] [client 107.161.92.6:57044] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.aronconsultoria.com"] [uri "/"] [unique_id "al9YKQ0cxofL2J1zwYraVQAAASI"]
[Tue Jul 21 08:29:45.590144 2026] [security2:error] [pid 418108:tid 418319] [client 202.179.75.202:54954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YKQ0cxofL2J1zwYraWgAAAVk"]
[Tue Jul 21 08:29:45.590271 2026] [security2:error] [pid 418108:tid 418319] [client 202.179.75.202:54954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YKQ0cxofL2J1zwYraWgAAAVk"]
[Tue Jul 21 08:29:45.942952 2026] [security2:error] [pid 462418:tid 462613] [client 20.104.96.117:46573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/2000.php"] [unique_id "al9YKSIybD14CLOJBaR1FAAAAEE"]
[Tue Jul 21 08:29:46.175343 2026] [security2:error] [pid 418108:tid 418297] [client 152.59.34.51:49986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YKg0cxofL2J1zwYraZgAAAUM"]
[Tue Jul 21 08:29:46.175445 2026] [security2:error] [pid 418108:tid 418297] [client 152.59.34.51:49986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YKg0cxofL2J1zwYraZgAAAUM"]
[Tue Jul 21 08:29:47.034552 2026] [security2:error] [pid 462418:tid 462640] [client 20.104.96.117:46503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/122.php"] [unique_id "al9YKyIybD14CLOJBaR1KwAAAFw"]
[Tue Jul 21 08:29:47.179199 2026] [core:error] [pid 418108:tid 418302] [client 143.110.155.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:29:47.179293 2026] [core:error] [pid 418108:tid 418302] [client 143.110.155.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:29:47.179361 2026] [security2:error] [pid 418108:tid 418187] [remote 91.142.222.105:41974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colegioperseveranca.com"] [uri "/wp-login.php"] [unique_id "al9YKg0cxofL2J1zwYraZQABI0w"]
[Tue Jul 21 08:29:47.454061 2026] [security2:error] [pid 462418:tid 462568] [client 20.197.192.193:46171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wp-css.php"] [unique_id "al9YKyIybD14CLOJBaR1MwAAABQ"]
[Tue Jul 21 08:29:47.536793 2026] [security2:error] [pid 462418:tid 462463] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/pi.php"] [unique_id "al9YKyIybD14CLOJBaR1NAAACiw"], referer: http://www.vidrosprovetro.com.br/pi.php
[Tue Jul 21 08:29:47.573895 2026] [security2:error] [pid 418108:tid 418297] [client 20.104.96.117:62692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/mds.php"] [unique_id "al9YKw0cxofL2J1zwYrahAAAAUM"]
[Tue Jul 21 08:29:47.635337 2026] [security2:error] [pid 418108:tid 418347] [client 195.49.128.211:54671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YKw0cxofL2J1zwYrahQAAAXU"]
[Tue Jul 21 08:29:47.635476 2026] [security2:error] [pid 418108:tid 418347] [client 195.49.128.211:54671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YKw0cxofL2J1zwYrahQAAAXU"]
[Tue Jul 21 08:29:47.878565 2026] [security2:error] [pid 462418:tid 462467] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YKyIybD14CLOJBaR1OAAACTA"]
[Tue Jul 21 08:29:47.878772 2026] [security2:error] [pid 462418:tid 462557] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YKyIybD14CLOJBaR1OAAACTA"]
[Tue Jul 21 08:29:47.925647 2026] [security2:error] [pid 462418:tid 462566] [client 14.245.224.124:63967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YKyIybD14CLOJBaR1OQAAABI"]
[Tue Jul 21 08:29:47.925765 2026] [security2:error] [pid 462418:tid 462566] [client 14.245.224.124:63967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YKyIybD14CLOJBaR1OQAAABI"]
[Tue Jul 21 08:29:47.986529 2026] [security2:error] [pid 418108:tid 418356] [client 74.249.245.134:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/rip.php"] [unique_id "al9YKw0cxofL2J1zwYrajwAAAX4"]
[Tue Jul 21 08:29:48.431701 2026] [security2:error] [pid 418108:tid 418255] [client 122.176.100.127:61570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YLA0cxofL2J1zwYralQAAARk"]
[Tue Jul 21 08:29:48.431889 2026] [security2:error] [pid 418108:tid 418255] [client 122.176.100.127:61570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YLA0cxofL2J1zwYralQAAARk"]
[Tue Jul 21 08:29:48.623603 2026] [security2:error] [pid 418108:tid 418315] [client 20.104.96.117:62668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-blink.php"] [unique_id "al9YLA0cxofL2J1zwYramwAAAVU"]
[Tue Jul 21 08:29:48.702488 2026] [security2:error] [pid 418108:tid 418360] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arthromdcanada.online"] [uri "/index.php"] [unique_id "al9YLA0cxofL2J1zwYranAAAAYI"]
[Tue Jul 21 08:29:48.711180 2026] [security2:error] [pid 462418:tid 462580] [client 20.10.88.227:2309] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arthromdcanada.online"] [uri "/robots.txt"] [unique_id "al9YLCIybD14CLOJBaR1PgAAACA"]
[Tue Jul 21 08:29:48.822539 2026] [security2:error] [pid 462418:tid 462674] [client 103.151.46.103:53856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YLCIybD14CLOJBaR1QAAAAH4"]
[Tue Jul 21 08:29:48.822732 2026] [security2:error] [pid 462418:tid 462674] [client 103.151.46.103:53856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YLCIybD14CLOJBaR1QAAAAH4"]
[Tue Jul 21 08:29:49.136575 2026] [security2:error] [pid 418108:tid 418170] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YLQ0cxofL2J1zwYrapQABWjs"]
[Tue Jul 21 08:29:49.136794 2026] [security2:error] [pid 418108:tid 418320] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YLQ0cxofL2J1zwYrapQABWjs"]
[Tue Jul 21 08:29:49.659023 2026] [security2:error] [pid 418108:tid 418264] [client 85.204.70.100:40686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grupotecc.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9YLQ0cxofL2J1zwYrargAAASI"]
[Tue Jul 21 08:29:50.046397 2026] [security2:error] [pid 418108:tid 418323] [client 223.181.60.88:32771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YLg0cxofL2J1zwYraugAAAV0"]
[Tue Jul 21 08:29:50.046755 2026] [security2:error] [pid 418108:tid 418323] [client 223.181.60.88:32771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YLg0cxofL2J1zwYraugAAAV0"]
[Tue Jul 21 08:29:50.140018 2026] [security2:error] [pid 418108:tid 418315] [client 20.197.192.193:5962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wp-explorer.php"] [unique_id "al9YLg0cxofL2J1zwYrauwAAAVU"]
[Tue Jul 21 08:29:50.307151 2026] [security2:error] [pid 418108:tid 418114] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YLg0cxofL2J1zwYravAABDgM"]
[Tue Jul 21 08:29:50.307390 2026] [security2:error] [pid 418108:tid 418244] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YLg0cxofL2J1zwYravAABDgM"]
[Tue Jul 21 08:29:50.510910 2026] [security2:error] [pid 462418:tid 462610] [client 20.104.96.117:62706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/zc-208.php"] [unique_id "al9YLiIybD14CLOJBaR1UQAAAD4"]
[Tue Jul 21 08:29:50.822071 2026] [security2:error] [pid 462418:tid 462473] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YLiIybD14CLOJBaR1VgAAdTY"]
[Tue Jul 21 08:29:50.822213 2026] [security2:error] [pid 462418:tid 462665] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YLiIybD14CLOJBaR1VgAAdTY"]
[Tue Jul 21 08:29:51.033551 2026] [security2:error] [pid 462418:tid 462550] [client 20.104.96.117:62699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/sid4.php"] [unique_id "al9YLyIybD14CLOJBaR1WQAAAAI"]
[Tue Jul 21 08:29:51.183150 2026] [autoindex:error] [pid 418108:tid 418316] [client 85.204.70.114:44476] AH01276: Cannot serve directory /home1/guiiaz25/werneckepereiraadvogados.guiiaz.com.br/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:29:51.390749 2026] [security2:error] [pid 462418:tid 462670] [client 65.21.113.253:51878] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YLiIybD14CLOJBaR1VwAAAHo"]
[Tue Jul 21 08:29:51.512731 2026] [autoindex:error] [pid 462418:tid 462572] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/onkosc80/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:29:51.581795 2026] [security2:error] [pid 462418:tid 462565] [client 187.125.243.197:57954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YLyIybD14CLOJBaR1YgAAABE"]
[Tue Jul 21 08:29:51.581971 2026] [security2:error] [pid 462418:tid 462565] [client 187.125.243.197:57954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YLyIybD14CLOJBaR1YgAAABE"]
[Tue Jul 21 08:29:51.587101 2026] [core:error] [pid 418108:tid 418267] [client 143.110.155.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.autoq.com.br/
[Tue Jul 21 08:29:51.587125 2026] [core:error] [pid 418108:tid 418267] [client 143.110.155.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.autoq.com.br/
[Tue Jul 21 08:29:51.698450 2026] [security2:error] [pid 418108:tid 418365] [client 49.144.66.253:30434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YLw0cxofL2J1zwYra2gAAAYc"]
[Tue Jul 21 08:29:51.698583 2026] [security2:error] [pid 418108:tid 418365] [client 49.144.66.253:30434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YLw0cxofL2J1zwYra2gAAAYc"]
[Tue Jul 21 08:29:51.732640 2026] [security2:error] [pid 418108:tid 418321] [client 143.244.57.90:58394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9YLw0cxofL2J1zwYra2wAAAVs"]
[Tue Jul 21 08:29:51.815155 2026] [security2:error] [pid 418108:tid 418310] [client 20.104.96.117:62673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wmore1.php"] [unique_id "al9YLw0cxofL2J1zwYra3wAAAVA"]
[Tue Jul 21 08:29:52.141409 2026] [security2:error] [pid 462418:tid 462597] [client 143.244.57.90:56764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YMCIybD14CLOJBaR1bQAAADE"]
[Tue Jul 21 08:29:52.323632 2026] [security2:error] [pid 462418:tid 462479] [remote 74.7.228.41:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "andreacardosodeolive1781638783978.0721679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9YMCIybD14CLOJBaR1bgAAODw"]
[Tue Jul 21 08:29:52.331633 2026] [security2:error] [pid 462418:tid 462480] [remote 97.74.87.194:33470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "growe-ag.jaypi.com.br"] [uri "/wp-login.php"] [unique_id "al9YMCIybD14CLOJBaR1bwAAJT0"]
[Tue Jul 21 08:29:52.411976 2026] [security2:error] [pid 462418:tid 462481] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/config.phpinfo"] [unique_id "al9YMCIybD14CLOJBaR1cAAANz4"], referer: http://www.vidrosprovetro.com.br/config.phpinfo
[Tue Jul 21 08:29:52.424137 2026] [security2:error] [pid 418108:tid 418335] [client 85.204.70.100:40688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grupotecc.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YMA0cxofL2J1zwYra7gAAAWk"]
[Tue Jul 21 08:29:52.424281 2026] [security2:error] [pid 418108:tid 418335] [client 85.204.70.100:40688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grupotecc.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YMA0cxofL2J1zwYra7gAAAWk"]
[Tue Jul 21 08:29:52.526935 2026] [security2:error] [pid 462418:tid 462605] [client 20.104.96.117:46541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/solo1.php"] [unique_id "al9YMCIybD14CLOJBaR1cgAAADk"]
[Tue Jul 21 08:29:53.154826 2026] [security2:error] [pid 462418:tid 462653] [client 143.244.57.90:58404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9YMSIybD14CLOJBaR1ggAAAGk"]
[Tue Jul 21 08:29:53.353577 2026] [autoindex:error] [pid 418108:tid 418321] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/onkosc80/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:29:53.573514 2026] [security2:error] [pid 418108:tid 418255] [client 143.244.57.90:2518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9YMQ0cxofL2J1zwYrbBgAAARk"]
[Tue Jul 21 08:29:53.636415 2026] [security2:error] [pid 462418:tid 462665] [client 20.104.96.117:46511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/cong.php"] [unique_id "al9YMSIybD14CLOJBaR1owAAAHU"]
[Tue Jul 21 08:29:53.726206 2026] [security2:error] [pid 462418:tid 462649] [client 195.49.128.211:62804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YMSIybD14CLOJBaR1pQAAAGU"]
[Tue Jul 21 08:29:53.726417 2026] [security2:error] [pid 462418:tid 462649] [client 195.49.128.211:62804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YMSIybD14CLOJBaR1pQAAAGU"]
[Tue Jul 21 08:29:53.823572 2026] [security2:error] [pid 462418:tid 462667] [client 65.21.113.253:51878] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YMSIybD14CLOJBaR1jAAAAHc"]
[Tue Jul 21 08:29:53.987974 2026] [security2:error] [pid 462418:tid 462578] [client 143.244.57.90:58416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9YMSIybD14CLOJBaR1qwAAAB4"]
[Tue Jul 21 08:29:54.219213 2026] [security2:error] [pid 418108:tid 418111] [remote 68.178.160.25:49994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9YMg0cxofL2J1zwYrbFwABSAA"]
[Tue Jul 21 08:29:54.395946 2026] [security2:error] [pid 462418:tid 462590] [client 143.244.57.90:58420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9YMiIybD14CLOJBaR1tQAAACo"]
[Tue Jul 21 08:29:54.423249 2026] [autoindex:error] [pid 462418:tid 462591] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/onkosc80/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:29:54.526320 2026] [security2:error] [pid 462418:tid 462670] [client 117.213.202.34:52888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YMiIybD14CLOJBaR1uQAAAHo"]
[Tue Jul 21 08:29:54.526453 2026] [security2:error] [pid 462418:tid 462670] [client 117.213.202.34:52888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YMiIybD14CLOJBaR1uQAAAHo"]
[Tue Jul 21 08:29:54.695029 2026] [security2:error] [pid 462418:tid 462548] [client 20.104.96.117:46527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/public/css.php"] [unique_id "al9YMiIybD14CLOJBaR1uwAAAAA"]
[Tue Jul 21 08:29:54.762766 2026] [security2:error] [pid 462418:tid 462602] [client 20.220.225.223:19283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/ace2.php"] [unique_id "al9YMiIybD14CLOJBaR1vQAAADY"]
[Tue Jul 21 08:29:54.808352 2026] [security2:error] [pid 462418:tid 462603] [client 143.244.57.90:58424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9YMiIybD14CLOJBaR1wAAAADc"]
[Tue Jul 21 08:29:54.911576 2026] [security2:error] [pid 418108:tid 418250] [client 150.129.202.39:13245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YMg0cxofL2J1zwYrbKAAAARQ"]
[Tue Jul 21 08:29:54.911719 2026] [security2:error] [pid 418108:tid 418250] [client 150.129.202.39:13245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YMg0cxofL2J1zwYrbKAAAARQ"]
[Tue Jul 21 08:29:55.220332 2026] [security2:error] [pid 418108:tid 418335] [client 143.244.57.90:58438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9YMw0cxofL2J1zwYrbMQAAAWk"]
[Tue Jul 21 08:29:55.327876 2026] [security2:error] [pid 462418:tid 462625] [client 20.197.192.193:46167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/akismet.php"] [unique_id "al9YMyIybD14CLOJBaR1ygAAAE0"]
[Tue Jul 21 08:29:55.470092 2026] [security2:error] [pid 418108:tid 418322] [client 59.184.181.113:53704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.181.184.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9YMw0cxofL2J1zwYrbPgAAAVw"]
[Tue Jul 21 08:29:55.470251 2026] [security2:error] [pid 418108:tid 418322] [client 59.184.181.113:53704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "umapsicologiaqueprovoca.com"] [uri "/xmlrpc.php"] [unique_id "al9YMw0cxofL2J1zwYrbPgAAAVw"]
[Tue Jul 21 08:29:55.642473 2026] [security2:error] [pid 418108:tid 418316] [client 143.244.57.90:12300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9YMw0cxofL2J1zwYrbQQAAAVY"]
[Tue Jul 21 08:29:55.775404 2026] [security2:error] [pid 462418:tid 462634] [client 65.21.113.253:51878] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YMyIybD14CLOJBaR1yAAAAFY"]
[Tue Jul 21 08:29:56.050221 2026] [security2:error] [pid 462418:tid 462664] [client 143.244.57.90:58458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9YNCIybD14CLOJBaR11QAAAHQ"]
[Tue Jul 21 08:29:56.340190 2026] [security2:error] [pid 418108:tid 418326] [client 20.104.96.117:46483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/output.php"] [unique_id "al9YNA0cxofL2J1zwYrbUwAAAWA"]
[Tue Jul 21 08:29:56.357126 2026] [security2:error] [pid 418108:tid 418278] [client 137.97.59.154:12346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YNA0cxofL2J1zwYrbVAAAATA"]
[Tue Jul 21 08:29:56.357377 2026] [security2:error] [pid 418108:tid 418278] [client 137.97.59.154:12346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YNA0cxofL2J1zwYrbVAAAATA"]
[Tue Jul 21 08:29:56.468778 2026] [security2:error] [pid 462418:tid 462570] [client 143.244.57.90:56871] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9YNCIybD14CLOJBaR13gAAABY"]
[Tue Jul 21 08:29:56.478274 2026] [security2:error] [pid 462418:tid 462595] [client 172.233.130.176:37600] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "tecnoturbo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9YMyIybD14CLOJBaR1xAAAAC8"]
[Tue Jul 21 08:29:56.523220 2026] [security2:error] [pid 462418:tid 462550] [client 202.179.75.202:57358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YNCIybD14CLOJBaR13wAAAAI"]
[Tue Jul 21 08:29:56.523378 2026] [security2:error] [pid 462418:tid 462550] [client 202.179.75.202:57358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YNCIybD14CLOJBaR13wAAAAI"]
[Tue Jul 21 08:29:56.546310 2026] [security2:error] [pid 462418:tid 462595] [client 172.233.130.176:37600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "tecnoturbo.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9YMyIybD14CLOJBaR1xAAAAC8"]
[Tue Jul 21 08:29:56.791541 2026] [core:error] [pid 418108:tid 418257] [client 66.249.66.67:37951] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:29:56.791565 2026] [core:error] [pid 418108:tid 418257] [client 66.249.66.67:37951] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:29:56.890058 2026] [security2:error] [pid 462418:tid 462666] [client 143.244.57.90:58468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9YNCIybD14CLOJBaR15wAAAHY"]
[Tue Jul 21 08:29:56.975775 2026] [security2:error] [pid 462418:tid 462657] [client 152.59.34.51:50467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YNCIybD14CLOJBaR16wAAAG0"]
[Tue Jul 21 08:29:56.975896 2026] [security2:error] [pid 462418:tid 462657] [client 152.59.34.51:50467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YNCIybD14CLOJBaR16wAAAG0"]
[Tue Jul 21 08:29:57.284714 2026] [security2:error] [pid 418108:tid 418255] [client 20.104.96.117:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-file-120.php"] [unique_id "al9YNQ0cxofL2J1zwYrbbgAAARk"]
[Tue Jul 21 08:29:57.314859 2026] [security2:error] [pid 418108:tid 418263] [client 143.244.57.90:16001] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9YNQ0cxofL2J1zwYrbcgAAASE"]
[Tue Jul 21 08:29:57.705214 2026] [security2:error] [pid 418108:tid 418185] [remote 68.178.160.25:34124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/wp-login.php"] [unique_id "al9YNQ0cxofL2J1zwYrbeAABUEo"]
[Tue Jul 21 08:29:57.735184 2026] [security2:error] [pid 418108:tid 418340] [client 143.244.57.90:58474] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9YNQ0cxofL2J1zwYrbegAAAW4"]
[Tue Jul 21 08:29:58.011101 2026] [proxy_http:error] [pid 462418:tid 462534] (70008)Partial results are valid but processing is incomplete: [remote 69.171.231.20:35478] AH01110: error reading response
[Tue Jul 21 08:29:58.022585 2026] [security2:error] [pid 462418:tid 462554] [client 65.21.113.253:51878] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YNSIybD14CLOJBaR18AAAAAY"]
[Tue Jul 21 08:29:58.144745 2026] [security2:error] [pid 462418:tid 462612] [client 143.244.57.90:58486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "portal.cbpcontabilidade.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9YNiIybD14CLOJBaR19wAAAEA"]
[Tue Jul 21 08:29:58.281330 2026] [security2:error] [pid 418108:tid 418241] [client 195.49.128.211:55261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YNg0cxofL2J1zwYrbtAAAAQs"]
[Tue Jul 21 08:29:58.281515 2026] [security2:error] [pid 418108:tid 418241] [client 195.49.128.211:55261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YNg0cxofL2J1zwYrbtAAAAQs"]
[Tue Jul 21 08:29:58.526840 2026] [security2:error] [pid 418108:tid 418206] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/admin/phpinfo.php"] [unique_id "al9YNg0cxofL2J1zwYrbvQABIV8"], referer: http://www.vidrosprovetro.com.br/admin/phpinfo.php
[Tue Jul 21 08:29:58.528902 2026] [security2:error] [pid 418108:tid 418294] [client 20.104.96.117:46551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/special.php"] [unique_id "al9YNg0cxofL2J1zwYrbvgAAAUA"]
[Tue Jul 21 08:29:58.567689 2026] [security2:error] [pid 462418:tid 462536] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YNiIybD14CLOJBaR1-wAASnU"]
[Tue Jul 21 08:29:58.567795 2026] [security2:error] [pid 462418:tid 462622] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YNiIybD14CLOJBaR1-wAASnU"]
[Tue Jul 21 08:29:58.578867 2026] [proxy_http:error] [pid 462418:tid 462537] (70008)Partial results are valid but processing is incomplete: [remote 69.171.231.5:62554] AH01110: error reading response
[Tue Jul 21 08:29:58.820640 2026] [security2:error] [pid 418108:tid 418316] [client 20.220.225.223:19266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.madmoholding.com.br"] [uri "/ms.php"] [unique_id "al9YNg0cxofL2J1zwYrbxgAAAVY"]
[Tue Jul 21 08:29:58.961394 2026] [security2:error] [pid 418108:tid 418280] [client 122.176.100.127:62048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YNg0cxofL2J1zwYrbzwAAATI"]
[Tue Jul 21 08:29:58.961479 2026] [security2:error] [pid 418108:tid 418280] [client 122.176.100.127:62048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YNg0cxofL2J1zwYrbzwAAATI"]
[Tue Jul 21 08:29:58.979352 2026] [security2:error] [pid 418108:tid 418300] [client 14.245.224.124:64443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YNg0cxofL2J1zwYrb0AAAAUY"]
[Tue Jul 21 08:29:58.979467 2026] [security2:error] [pid 418108:tid 418300] [client 14.245.224.124:64443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YNg0cxofL2J1zwYrb0AAAAUY"]
[Tue Jul 21 08:29:59.575252 2026] [proxy:error] [pid 418108:tid 418257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:29:59.575336 2026] [proxy_http:error] [pid 418108:tid 418257] [client 165.227.121.218:41146] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:29:59.576043 2026] [proxy:error] [pid 418108:tid 418257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:29:59.576080 2026] [proxy_http:error] [pid 418108:tid 418257] [client 165.227.121.218:41146] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:29:59.603951 2026] [security2:error] [pid 462418:tid 462540] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YNyIybD14CLOJBaR2CAAAGHk"]
[Tue Jul 21 08:29:59.604155 2026] [security2:error] [pid 462418:tid 462572] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YNyIybD14CLOJBaR2CAAAGHk"]
[Tue Jul 21 08:29:59.810198 2026] [proxy:error] [pid 462418:tid 462574] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:29:59.810251 2026] [proxy_http:error] [pid 462418:tid 462574] [client 165.227.121.218:41158] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.hometohomelondon.com/
[Tue Jul 21 08:29:59.810728 2026] [proxy:error] [pid 462418:tid 462574] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:29:59.810759 2026] [proxy_http:error] [pid 462418:tid 462574] [client 165.227.121.218:41158] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.hometohomelondon.com/
[Tue Jul 21 08:29:59.812620 2026] [security2:error] [pid 462418:tid 462579] [client 20.104.96.117:46535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/as.php"] [unique_id "al9YNyIybD14CLOJBaR2DgAAAB8"]
[Tue Jul 21 08:29:59.829425 2026] [security2:error] [pid 462418:tid 462543] [remote 147.50.252.213:39706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caminhoneiro.giovanoniadv.com.br"] [uri "/wp-login.php"] [unique_id "al9YNyIybD14CLOJBaR2DwAAe3w"]
[Tue Jul 21 08:29:59.924831 2026] [security2:error] [pid 418108:tid 418225] [remote 49.13.1.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/wp-login.php"] [unique_id "al9YNw0cxofL2J1zwYrcAwABF3I"]
[Tue Jul 21 08:30:00.515557 2026] [security2:error] [pid 462418:tid 462618] [client 109.248.148.246:47800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9YOCIybD14CLOJBaR2FQAAAEY"]
[Tue Jul 21 08:30:00.515662 2026] [security2:error] [pid 462418:tid 462618] [client 109.248.148.246:47800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9YOCIybD14CLOJBaR2FQAAAEY"]
[Tue Jul 21 08:30:00.547667 2026] [security2:error] [pid 418108:tid 418367] [client 31.57.219.92:16722] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "northcomm.com.br"] [uri "/"] [unique_id "al9YOA0cxofL2J1zwYrcEgAAAYk"]
[Tue Jul 21 08:30:00.875682 2026] [security2:error] [pid 418108:tid 418186] [remote 20.75.217.64:9893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autoq.com.br"] [uri "/wp-login.php"] [unique_id "al9YNw0cxofL2J1zwYrcAAABS0s"]
[Tue Jul 21 08:30:00.920102 2026] [proxy:error] [pid 418108:tid 418365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:30:00.920140 2026] [proxy_http:error] [pid 418108:tid 418365] [client 165.227.121.218:58276] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:30:00.920584 2026] [proxy:error] [pid 418108:tid 418365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:30:00.920611 2026] [proxy_http:error] [pid 418108:tid 418365] [client 165.227.121.218:58276] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:30:00.924664 2026] [security2:error] [pid 462418:tid 462546] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YOCIybD14CLOJBaR2GgAAQH8"]
[Tue Jul 21 08:30:00.924775 2026] [security2:error] [pid 462418:tid 462612] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YOCIybD14CLOJBaR2GgAAQH8"]
[Tue Jul 21 08:30:01.166121 2026] [security2:error] [pid 418108:tid 418336] [client 223.181.60.88:21401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YOQ0cxofL2J1zwYrcHwAAAWo"]
[Tue Jul 21 08:30:01.166411 2026] [security2:error] [pid 418108:tid 418336] [client 223.181.60.88:21401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YOQ0cxofL2J1zwYrcHwAAAWo"]
[Tue Jul 21 08:30:01.172092 2026] [security2:error] [pid 418108:tid 418343] [client 20.104.96.117:46562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9YOQ0cxofL2J1zwYrcIAAAAXE"]
[Tue Jul 21 08:30:01.387101 2026] [security2:error] [pid 418108:tid 418185] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YOQ0cxofL2J1zwYrcIQABgUo"]
[Tue Jul 21 08:30:01.387275 2026] [security2:error] [pid 418108:tid 418359] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YOQ0cxofL2J1zwYrcIQABgUo"]
[Tue Jul 21 08:30:01.996564 2026] [security2:error] [pid 418108:tid 418335] [client 61.1.167.83:50404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YOQ0cxofL2J1zwYrcMgAAAWk"]
[Tue Jul 21 08:30:01.998311 2026] [security2:error] [pid 418108:tid 418335] [client 61.1.167.83:50404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YOQ0cxofL2J1zwYrcMgAAAWk"]
[Tue Jul 21 08:30:02.029304 2026] [security2:error] [pid 462418:tid 462652] [client 65.21.113.253:51878] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YOSIybD14CLOJBaR2IgAAAGg"]
[Tue Jul 21 08:30:02.057270 2026] [security2:error] [pid 418108:tid 418316] [client 187.125.243.197:58451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YOg0cxofL2J1zwYrcNAAAAVY"]
[Tue Jul 21 08:30:02.057478 2026] [security2:error] [pid 418108:tid 418316] [client 187.125.243.197:58451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YOg0cxofL2J1zwYrcNAAAAVY"]
[Tue Jul 21 08:30:02.255282 2026] [security2:error] [pid 418108:tid 418324] [client 20.104.96.117:62715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/w1px.php"] [unique_id "al9YOg0cxofL2J1zwYrcNgAAAV4"]
[Tue Jul 21 08:30:02.306746 2026] [security2:error] [pid 418108:tid 418261] [client 103.151.46.103:54342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YOg0cxofL2J1zwYrcNwAAAR8"]
[Tue Jul 21 08:30:02.307036 2026] [security2:error] [pid 418108:tid 418261] [client 103.151.46.103:54342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YOg0cxofL2J1zwYrcNwAAAR8"]
[Tue Jul 21 08:30:02.505501 2026] [security2:error] [pid 418108:tid 418216] [remote 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9YOg0cxofL2J1zwYrcPQABQGk"]
[Tue Jul 21 08:30:02.548871 2026] [security2:error] [pid 462418:tid 462574] [client 49.144.66.253:30892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YOiIybD14CLOJBaR2PAAAABo"]
[Tue Jul 21 08:30:02.549018 2026] [security2:error] [pid 462418:tid 462574] [client 49.144.66.253:30892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YOiIybD14CLOJBaR2PAAAABo"]
[Tue Jul 21 08:30:02.683241 2026] [security2:error] [pid 462418:tid 462602] [client 74.249.245.134:54917] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ftp.bcsenepol.com.br"] [uri "/1.php"] [unique_id "al9YOiIybD14CLOJBaR2PwAAADY"]
[Tue Jul 21 08:30:02.683372 2026] [security2:error] [pid 462418:tid 462602] [client 74.249.245.134:54917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/1.php"] [unique_id "al9YOiIybD14CLOJBaR2PwAAADY"]
[Tue Jul 21 08:30:02.826425 2026] [security2:error] [pid 418108:tid 418359] [client 20.104.96.117:62702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/yawa.php"] [unique_id "al9YOg0cxofL2J1zwYrcQQAAAYE"]
[Tue Jul 21 08:30:02.985585 2026] [core:error] [pid 462418:tid 462441] [remote 40.77.167.10:37698] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:30:02.985613 2026] [core:error] [pid 462418:tid 462441] [remote 40.77.167.10:37698] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:30:02.989822 2026] [security2:error] [pid 418108:tid 418172] [remote 192.241.143.148:35544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9YOg0cxofL2J1zwYrcQwABcT0"]
[Tue Jul 21 08:30:03.181317 2026] [security2:error] [pid 462418:tid 462613] [client 20.104.96.117:46570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/js.php"] [unique_id "al9YOyIybD14CLOJBaR2TAAAAEE"]
[Tue Jul 21 08:30:03.591891 2026] [security2:error] [pid 462418:tid 462619] [client 20.104.96.117:62676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/core.php"] [unique_id "al9YOyIybD14CLOJBaR2UwAAAEc"]
[Tue Jul 21 08:30:03.884674 2026] [security2:error] [pid 462418:tid 462578] [client 20.104.96.117:46524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/19.php"] [unique_id "al9YOyIybD14CLOJBaR2agAAAB4"]
[Tue Jul 21 08:30:04.040646 2026] [security2:error] [pid 418108:tid 418302] [client 5.31.193.106:1792] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YOg0cxofL2J1zwYrcQAAAAUg"]
[Tue Jul 21 08:30:04.040776 2026] [security2:error] [pid 418108:tid 418302] [client 5.31.193.106:1792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YOg0cxofL2J1zwYrcQAAAAUg"]
[Tue Jul 21 08:30:04.098591 2026] [proxy:error] [pid 462418:tid 462572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:30:04.098629 2026] [proxy_http:error] [pid 462418:tid 462572] [client 165.227.121.218:58372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.hometohomelondon.com/
[Tue Jul 21 08:30:04.099061 2026] [proxy:error] [pid 462418:tid 462572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:30:04.099084 2026] [proxy_http:error] [pid 462418:tid 462572] [client 165.227.121.218:58372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.hometohomelondon.com/
[Tue Jul 21 08:30:04.356784 2026] [security2:error] [pid 462418:tid 462602] [client 20.104.96.117:46540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/inc.php"] [unique_id "al9YPCIybD14CLOJBaR2dwAAADY"]
[Tue Jul 21 08:30:04.363067 2026] [security2:error] [pid 462418:tid 462575] [client 195.49.128.211:63635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YPCIybD14CLOJBaR2eAAAABs"]
[Tue Jul 21 08:30:04.363295 2026] [security2:error] [pid 462418:tid 462575] [client 195.49.128.211:63635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YPCIybD14CLOJBaR2eAAAABs"]
[Tue Jul 21 08:30:04.521688 2026] [security2:error] [pid 418108:tid 418260] [client 150.129.202.39:12544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YPA0cxofL2J1zwYrcWgAAAR4"]
[Tue Jul 21 08:30:04.521843 2026] [security2:error] [pid 418108:tid 418260] [client 150.129.202.39:12544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YPA0cxofL2J1zwYrcWgAAAR4"]
[Tue Jul 21 08:30:04.827688 2026] [security2:error] [pid 462418:tid 462672] [client 20.104.96.117:46501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9YPCIybD14CLOJBaR2ewAAAHw"]
[Tue Jul 21 08:30:05.156395 2026] [security2:error] [pid 418108:tid 418321] [client 20.104.96.117:62634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9YPQ0cxofL2J1zwYrcZgAAAVs"]
[Tue Jul 21 08:30:05.261399 2026] [security2:error] [pid 462418:tid 462566] [client 117.213.202.34:53455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YPSIybD14CLOJBaR2fQAAABI"]
[Tue Jul 21 08:30:05.261662 2026] [security2:error] [pid 462418:tid 462566] [client 117.213.202.34:53455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YPSIybD14CLOJBaR2fQAAABI"]
[Tue Jul 21 08:30:05.476836 2026] [security2:error] [pid 418108:tid 418310] [client 20.104.96.117:46473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/ss.php"] [unique_id "al9YPQ0cxofL2J1zwYrcbgAAAVA"]
[Tue Jul 21 08:30:05.854624 2026] [security2:error] [pid 462418:tid 462636] [client 81.19.208.84:56950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.208.19.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YPSIybD14CLOJBaR2jQAAAFg"]
[Tue Jul 21 08:30:05.854821 2026] [security2:error] [pid 462418:tid 462636] [client 81.19.208.84:56950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3d-surgery.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YPSIybD14CLOJBaR2jQAAAFg"]
[Tue Jul 21 08:30:05.960453 2026] [security2:error] [pid 418108:tid 418270] [client 20.104.96.117:46523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/min.php"] [unique_id "al9YPQ0cxofL2J1zwYrcdAAAASg"]
[Tue Jul 21 08:30:06.505187 2026] [security2:error] [pid 418108:tid 418321] [client 20.104.96.117:62621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9YPg0cxofL2J1zwYrciAAAAVs"]
[Tue Jul 21 08:30:06.833688 2026] [security2:error] [pid 418108:tid 418294] [client 125.18.144.2:29206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YPg0cxofL2J1zwYrckQAAAUA"]
[Tue Jul 21 08:30:06.833851 2026] [security2:error] [pid 418108:tid 418294] [client 125.18.144.2:29206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YPg0cxofL2J1zwYrckQAAAUA"]
[Tue Jul 21 08:30:07.025178 2026] [security2:error] [pid 462418:tid 462554] [client 20.104.96.117:62658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9YPyIybD14CLOJBaR29wAAAAY"]
[Tue Jul 21 08:30:07.300536 2026] [security2:error] [pid 462418:tid 462635] [client 202.179.75.202:57820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YPyIybD14CLOJBaR2-QAAAFc"]
[Tue Jul 21 08:30:07.300774 2026] [security2:error] [pid 462418:tid 462635] [client 202.179.75.202:57820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YPyIybD14CLOJBaR2-QAAAFc"]
[Tue Jul 21 08:30:07.527441 2026] [security2:error] [pid 462418:tid 462636] [client 20.104.96.117:46505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9YPyIybD14CLOJBaR2_QAAAFg"]
[Tue Jul 21 08:30:07.583065 2026] [security2:error] [pid 462418:tid 462592] [client 152.59.34.51:26004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YPyIybD14CLOJBaR2_wAAACw"]
[Tue Jul 21 08:30:07.583181 2026] [security2:error] [pid 462418:tid 462592] [client 152.59.34.51:26004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YPyIybD14CLOJBaR2_wAAACw"]
[Tue Jul 21 08:30:07.629527 2026] [core:alert] [pid 418108:tid 418328] [client 57.141.18.37:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:30:07.901075 2026] [security2:error] [pid 462418:tid 462628] [client 20.104.96.117:46480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9YPyIybD14CLOJBaR3AwAAAFA"]
[Tue Jul 21 08:30:07.903383 2026] [security2:error] [pid 462418:tid 462469] [remote 188.164.197.230:54170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9YPiIybD14CLOJBaR28wAAOTI"]
[Tue Jul 21 08:30:08.384490 2026] [access_compat:error] [pid 418108:tid 418360] [client 162.241.63.68:39110] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:30:08.407235 2026] [security2:error] [pid 418108:tid 418322] [client 74.249.245.134:55512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/chosen.php"] [unique_id "al9YQA0cxofL2J1zwYrcsgAAAVw"]
[Tue Jul 21 08:30:08.487520 2026] [security2:error] [pid 462418:tid 462567] [client 20.104.96.117:62702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/albin.php"] [unique_id "al9YQCIybD14CLOJBaR3CgAAABM"]
[Tue Jul 21 08:30:08.854449 2026] [security2:error] [pid 418108:tid 418250] [client 195.49.128.211:55847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YQA0cxofL2J1zwYrcuAAAARQ"]
[Tue Jul 21 08:30:08.854594 2026] [security2:error] [pid 418108:tid 418250] [client 195.49.128.211:55847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YQA0cxofL2J1zwYrcuAAAARQ"]
[Tue Jul 21 08:30:09.151926 2026] [security2:error] [pid 462418:tid 462491] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YQSIybD14CLOJBaR3EQAAUUg"]
[Tue Jul 21 08:30:09.152124 2026] [security2:error] [pid 462418:tid 462629] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YQSIybD14CLOJBaR3EQAAUUg"]
[Tue Jul 21 08:30:09.183124 2026] [security2:error] [pid 418108:tid 418318] [client 103.151.46.103:54842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YQQ0cxofL2J1zwYrcvQAAAVg"]
[Tue Jul 21 08:30:09.183258 2026] [security2:error] [pid 418108:tid 418318] [client 103.151.46.103:54842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YQQ0cxofL2J1zwYrcvQAAAVg"]
[Tue Jul 21 08:30:09.220623 2026] [security2:error] [pid 462418:tid 462666] [client 20.104.96.117:46468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/cilus.php"] [unique_id "al9YQSIybD14CLOJBaR3EgAAAHY"]
[Tue Jul 21 08:30:09.430353 2026] [security2:error] [pid 462418:tid 462553] [client 14.245.224.124:64935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YQSIybD14CLOJBaR3GgAAAAU"]
[Tue Jul 21 08:30:09.430435 2026] [security2:error] [pid 462418:tid 462553] [client 14.245.224.124:64935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YQSIybD14CLOJBaR3GgAAAAU"]
[Tue Jul 21 08:30:09.502582 2026] [security2:error] [pid 462418:tid 462618] [client 122.176.100.127:62520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YQSIybD14CLOJBaR3GwAAAEY"]
[Tue Jul 21 08:30:09.502934 2026] [security2:error] [pid 462418:tid 462618] [client 122.176.100.127:62520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YQSIybD14CLOJBaR3GwAAAEY"]
[Tue Jul 21 08:30:09.761506 2026] [security2:error] [pid 462418:tid 462636] [client 20.104.96.117:62640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/gptsh.php"] [unique_id "al9YQSIybD14CLOJBaR3HgAAAFg"]
[Tue Jul 21 08:30:10.122106 2026] [security2:error] [pid 462418:tid 462478] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YQiIybD14CLOJBaR3IwAAczs"]
[Tue Jul 21 08:30:10.122268 2026] [security2:error] [pid 462418:tid 462663] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YQiIybD14CLOJBaR3IwAAczs"]
[Tue Jul 21 08:30:10.272627 2026] [security2:error] [pid 462418:tid 462611] [client 20.104.96.117:62682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/rithin.php"] [unique_id "al9YQiIybD14CLOJBaR3JAAAAD8"]
[Tue Jul 21 08:30:10.619495 2026] [security2:error] [pid 462418:tid 462496] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/pinfo.php"] [unique_id "al9YQiIybD14CLOJBaR3KQAAXk0"], referer: http://www.vidrosprovetro.com.br/pinfo.php
[Tue Jul 21 08:30:10.928628 2026] [security2:error] [pid 462418:tid 462572] [client 20.104.96.117:46466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/fffm.php"] [unique_id "al9YQiIybD14CLOJBaR3LgAAABg"]
[Tue Jul 21 08:30:11.141725 2026] [core:alert] [pid 462418:tid 462585] [client 66.249.66.74:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:30:11.569743 2026] [security2:error] [pid 418108:tid 418324] [client 20.104.96.117:46529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/dfre.php"] [unique_id "al9YQw0cxofL2J1zwYrc6gAAAV4"]
[Tue Jul 21 08:30:11.768972 2026] [security2:error] [pid 418108:tid 418189] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YQw0cxofL2J1zwYrc7AABKE4"]
[Tue Jul 21 08:30:11.769151 2026] [security2:error] [pid 418108:tid 418270] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YQw0cxofL2J1zwYrc7AABKE4"]
[Tue Jul 21 08:30:11.809880 2026] [security2:error] [pid 462418:tid 462595] [client 223.181.60.88:1801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YQyIybD14CLOJBaR3OwAAAC8"]
[Tue Jul 21 08:30:11.810023 2026] [security2:error] [pid 462418:tid 462595] [client 223.181.60.88:1801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YQyIybD14CLOJBaR3OwAAAC8"]
[Tue Jul 21 08:30:11.902918 2026] [security2:error] [pid 462418:tid 462632] [client 216.73.160.20:52259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/wp-login.php"] [unique_id "al9YQiIybD14CLOJBaR3LQAAAFQ"]
[Tue Jul 21 08:30:11.938857 2026] [security2:error] [pid 418108:tid 418119] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YQw0cxofL2J1zwYrc8AABMQg"]
[Tue Jul 21 08:30:11.939028 2026] [security2:error] [pid 418108:tid 418279] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YQw0cxofL2J1zwYrc8AABMQg"]
[Tue Jul 21 08:30:12.099596 2026] [security2:error] [pid 462418:tid 462615] [client 20.104.96.117:46513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/wp-happy.php"] [unique_id "al9YRCIybD14CLOJBaR3PgAAAEM"]
[Tue Jul 21 08:30:12.531358 2026] [security2:error] [pid 462418:tid 462665] [client 187.125.243.197:58950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YRCIybD14CLOJBaR3RgAAAHU"]
[Tue Jul 21 08:30:12.531493 2026] [security2:error] [pid 462418:tid 462665] [client 187.125.243.197:58950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YRCIybD14CLOJBaR3RgAAAHU"]
[Tue Jul 21 08:30:12.681935 2026] [security2:error] [pid 462418:tid 462663] [client 20.104.96.117:46510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/fpr4.php"] [unique_id "al9YRCIybD14CLOJBaR3SQAAAHM"]
[Tue Jul 21 08:30:13.079313 2026] [proxy:error] [pid 418108:tid 418341] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:30:13.079386 2026] [proxy_http:error] [pid 418108:tid 418341] [client 85.204.70.98:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:30:13.080242 2026] [proxy:error] [pid 418108:tid 418341] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:30:13.080286 2026] [proxy_http:error] [pid 418108:tid 418341] [client 85.204.70.98:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:30:13.108198 2026] [security2:error] [pid 462418:tid 462670] [client 20.104.96.117:46469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/file88.php"] [unique_id "al9YRSIybD14CLOJBaR3UAAAAHo"]
[Tue Jul 21 08:30:13.288232 2026] [security2:error] [pid 462418:tid 462508] [remote 207.180.241.245:35120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinculampe.com.br"] [uri "/wp-login.php"] [unique_id "al9YRSIybD14CLOJBaR3UwAAH1k"]
[Tue Jul 21 08:30:13.380373 2026] [proxy:error] [pid 462418:tid 462668] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:30:13.380453 2026] [proxy_http:error] [pid 462418:tid 462668] [client 85.204.70.98:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:30:13.381534 2026] [proxy:error] [pid 462418:tid 462668] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:30:13.381584 2026] [proxy_http:error] [pid 462418:tid 462668] [client 85.204.70.98:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:30:13.544582 2026] [security2:error] [pid 462418:tid 462580] [client 141.11.107.74:60145] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "gssbrasil.com.br"] [uri "/"] [unique_id "al9YRSIybD14CLOJBaR3WgAAACA"]
[Tue Jul 21 08:30:13.546175 2026] [security2:error] [pid 462418:tid 462649] [client 141.11.107.74:60147] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.gssbrasil.com.br"] [uri "/"] [unique_id "al9YRSIybD14CLOJBaR3WwAAAGU"]
[Tue Jul 21 08:30:13.599939 2026] [security2:error] [pid 418108:tid 418357] [client 141.11.107.74:60151] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.gssbrasil.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9YRQ0cxofL2J1zwYrdDwAAAX8"]
[Tue Jul 21 08:30:13.612695 2026] [security2:error] [pid 462418:tid 462599] [client 141.11.107.74:60154] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ftp.gssbrasil.com.br"] [uri "/"] [unique_id "al9YRSIybD14CLOJBaR3XgAAADM"]
[Tue Jul 21 08:30:13.623073 2026] [security2:error] [pid 462418:tid 462666] [client 141.11.107.74:60158] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.gssbrasil.com.br"] [uri "/"] [unique_id "al9YRSIybD14CLOJBaR3XwAAAHY"]
[Tue Jul 21 08:30:13.662533 2026] [security2:error] [pid 418108:tid 418277] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9YRQ0cxofL2J1zwYrdEgAAAS8"]
[Tue Jul 21 08:30:13.838511 2026] [security2:error] [pid 418108:tid 418282] [client 20.104.96.117:46467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/ccc.php"] [unique_id "al9YRQ0cxofL2J1zwYrdFwAAATQ"]
[Tue Jul 21 08:30:13.940790 2026] [security2:error] [pid 462418:tid 462566] [client 85.204.70.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YRSIybD14CLOJBaR3YgAAABI"]
[Tue Jul 21 08:30:14.053914 2026] [security2:error] [pid 462418:tid 462651] [client 49.144.66.253:31343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YRiIybD14CLOJBaR3ZQAAAGc"]
[Tue Jul 21 08:30:14.054001 2026] [security2:error] [pid 462418:tid 462651] [client 49.144.66.253:31343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YRiIybD14CLOJBaR3ZQAAAGc"]
[Tue Jul 21 08:30:14.217711 2026] [proxy:error] [pid 418108:tid 418250] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:30:14.217785 2026] [proxy_http:error] [pid 418108:tid 418250] [client 85.204.70.98:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:30:14.218641 2026] [proxy:error] [pid 418108:tid 418250] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:30:14.218674 2026] [proxy_http:error] [pid 418108:tid 418250] [client 85.204.70.98:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:30:14.251174 2026] [security2:error] [pid 462418:tid 462553] [client 20.104.96.117:62595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/777.php"] [unique_id "al9YRiIybD14CLOJBaR3agAAAAU"]
[Tue Jul 21 08:30:14.500038 2026] [security2:error] [pid 418108:tid 418340] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9YRg0cxofL2J1zwYrdJgAAAW4"]
[Tue Jul 21 08:30:14.681031 2026] [security2:error] [pid 418108:tid 418111] [remote 68.178.160.25:55130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9YRg0cxofL2J1zwYrdKwABHAA"]
[Tue Jul 21 08:30:14.723989 2026] [security2:error] [pid 418108:tid 418315] [client 20.104.96.117:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/for.php"] [unique_id "al9YRg0cxofL2J1zwYrdLwAAAVU"]
[Tue Jul 21 08:30:14.778085 2026] [security2:error] [pid 462418:tid 462663] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9YRiIybD14CLOJBaR3bQAAAHM"]
[Tue Jul 21 08:30:15.057887 2026] [security2:error] [pid 418108:tid 418357] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9YRw0cxofL2J1zwYrdNAAAAX8"]
[Tue Jul 21 08:30:15.158365 2026] [security2:error] [pid 462418:tid 462643] [client 150.129.202.39:13201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YRyIybD14CLOJBaR3dAAAAF8"]
[Tue Jul 21 08:30:15.158518 2026] [security2:error] [pid 462418:tid 462643] [client 150.129.202.39:13201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YRyIybD14CLOJBaR3dAAAAF8"]
[Tue Jul 21 08:30:15.248941 2026] [security2:error] [pid 462418:tid 462572] [client 20.104.96.117:46534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/ssla.php"] [unique_id "al9YRyIybD14CLOJBaR3dQAAABg"]
[Tue Jul 21 08:30:15.266569 2026] [security2:error] [pid 462418:tid 462652] [client 195.49.128.211:64350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YRyIybD14CLOJBaR3dgAAAGg"]
[Tue Jul 21 08:30:15.266761 2026] [security2:error] [pid 462418:tid 462652] [client 195.49.128.211:64350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YRyIybD14CLOJBaR3dgAAAGg"]
[Tue Jul 21 08:30:15.340908 2026] [security2:error] [pid 418108:tid 418331] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9YRw0cxofL2J1zwYrdOQAAAWU"]
[Tue Jul 21 08:30:15.619408 2026] [security2:error] [pid 462418:tid 462674] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9YRyIybD14CLOJBaR3egAAAH4"]
[Tue Jul 21 08:30:15.657761 2026] [security2:error] [pid 462418:tid 462548] [client 20.104.96.117:46474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.onkosclinica.com.br"] [uri "/zc-131.php"] [unique_id "al9YRyIybD14CLOJBaR3fAAAAAA"]
[Tue Jul 21 08:30:15.895199 2026] [security2:error] [pid 462418:tid 462666] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9YRyIybD14CLOJBaR3fwAAAHY"]
[Tue Jul 21 08:30:16.003780 2026] [security2:error] [pid 462418:tid 462675] [client 117.213.202.34:54009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YRyIybD14CLOJBaR3gAAAAH8"]
[Tue Jul 21 08:30:16.003983 2026] [security2:error] [pid 462418:tid 462675] [client 117.213.202.34:54009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YRyIybD14CLOJBaR3gAAAAH8"]
[Tue Jul 21 08:30:16.167536 2026] [security2:error] [pid 462418:tid 462554] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9YSCIybD14CLOJBaR3hAAAAAY"]
[Tue Jul 21 08:30:16.442132 2026] [security2:error] [pid 462418:tid 462557] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9YSCIybD14CLOJBaR3igAAAAk"]
[Tue Jul 21 08:30:16.482780 2026] [security2:error] [pid 418108:tid 418173] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/phpinfo2.php"] [unique_id "al9YSA0cxofL2J1zwYrdRQABHj4"], referer: http://www.vidrosprovetro.com.br/phpinfo2.php
[Tue Jul 21 08:30:16.716966 2026] [security2:error] [pid 418108:tid 418305] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9YSA0cxofL2J1zwYrdTQAAAUs"]
[Tue Jul 21 08:30:16.990947 2026] [security2:error] [pid 462418:tid 462550] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9YSCIybD14CLOJBaR3jgAAAAI"]
[Tue Jul 21 08:30:17.267198 2026] [security2:error] [pid 462418:tid 462611] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9YSSIybD14CLOJBaR3kQAAAD8"]
[Tue Jul 21 08:30:17.302907 2026] [security2:error] [pid 462418:tid 462570] [client 128.127.105.184:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9YSSIybD14CLOJBaR3kgAAABY"]
[Tue Jul 21 08:30:17.303148 2026] [security2:error] [pid 462418:tid 462570] [client 128.127.105.184:56322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9YSSIybD14CLOJBaR3kgAAABY"]
[Tue Jul 21 08:30:17.540052 2026] [security2:error] [pid 462418:tid 462614] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9YSSIybD14CLOJBaR3lAAAAEI"]
[Tue Jul 21 08:30:17.734739 2026] [security2:error] [pid 418108:tid 418336] [client 103.255.105.130:45143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YSQ0cxofL2J1zwYrdZQAAAWo"]
[Tue Jul 21 08:30:17.734911 2026] [security2:error] [pid 418108:tid 418336] [client 103.255.105.130:45143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YSQ0cxofL2J1zwYrdZQAAAWo"]
[Tue Jul 21 08:30:17.812738 2026] [security2:error] [pid 462418:tid 462612] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9YSSIybD14CLOJBaR3oAAAAEA"]
[Tue Jul 21 08:30:18.093308 2026] [security2:error] [pid 462418:tid 462631] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9YSiIybD14CLOJBaR3ogAAAFM"]
[Tue Jul 21 08:30:18.116355 2026] [security2:error] [pid 462418:tid 462644] [client 202.179.75.202:57602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YSiIybD14CLOJBaR3owAAAGA"]
[Tue Jul 21 08:30:18.116503 2026] [security2:error] [pid 462418:tid 462644] [client 202.179.75.202:57602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YSiIybD14CLOJBaR3owAAAGA"]
[Tue Jul 21 08:30:18.252207 2026] [security2:error] [pid 462418:tid 462632] [client 216.244.66.199:43092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.brlead.com.br"] [uri "/"] [unique_id "al9YSiIybD14CLOJBaR3pgAAAFQ"]
[Tue Jul 21 08:30:18.252309 2026] [security2:error] [pid 462418:tid 462632] [client 216.244.66.199:43092] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.brlead.com.br"] [uri "/"] [unique_id "al9YSiIybD14CLOJBaR3pgAAAFQ"]
[Tue Jul 21 08:30:18.366780 2026] [security2:error] [pid 462418:tid 462636] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9YSiIybD14CLOJBaR3qAAAAFg"]
[Tue Jul 21 08:30:18.417418 2026] [security2:error] [pid 418108:tid 418346] [client 152.59.34.51:51431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YSg0cxofL2J1zwYrdcQAAAXQ"]
[Tue Jul 21 08:30:18.417566 2026] [security2:error] [pid 418108:tid 418346] [client 152.59.34.51:51431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YSg0cxofL2J1zwYrdcQAAAXQ"]
[Tue Jul 21 08:30:18.500475 2026] [security2:error] [pid 462418:tid 462543] [remote 84.247.172.23:53818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lp.agenciawats.com.br"] [uri "/wp-login.php"] [unique_id "al9YSiIybD14CLOJBaR3qQAAQXw"]
[Tue Jul 21 08:30:18.641051 2026] [security2:error] [pid 462418:tid 462576] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9YSiIybD14CLOJBaR3qwAAABw"]
[Tue Jul 21 08:30:18.949608 2026] [security2:error] [pid 418108:tid 418240] [client 74.249.245.134:55493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/css.php"] [unique_id "al9YSg0cxofL2J1zwYrddwAAAQo"]
[Tue Jul 21 08:30:18.986491 2026] [security2:error] [pid 462418:tid 462663] [client 74.7.241.169:37692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "abracandocores.org"] [uri "/robots.txt"] [unique_id "al9YSiIybD14CLOJBaR3swAAc3A"]
[Tue Jul 21 08:30:19.112092 2026] [security2:error] [pid 462418:tid 462565] [client 74.7.241.169:37692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "abracandocores.org"] [uri "/cgi-sys/404.html"] [unique_id "al9YSyIybD14CLOJBaR3tAAAEXo"], referer: https://abracandocores.org/robots.txt
[Tue Jul 21 08:30:19.506130 2026] [security2:error] [pid 462418:tid 462642] [client 195.49.128.211:56435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YSyIybD14CLOJBaR3ugAAAF4"]
[Tue Jul 21 08:30:19.506281 2026] [security2:error] [pid 462418:tid 462642] [client 195.49.128.211:56435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YSyIybD14CLOJBaR3ugAAAF4"]
[Tue Jul 21 08:30:19.844537 2026] [security2:error] [pid 418108:tid 418151] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YSw0cxofL2J1zwYrdggABeCg"]
[Tue Jul 21 08:30:19.844688 2026] [security2:error] [pid 418108:tid 418350] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YSw0cxofL2J1zwYrdggABeCg"]
[Tue Jul 21 08:30:19.909792 2026] [security2:error] [pid 418108:tid 418318] [client 103.151.46.103:55337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YSw0cxofL2J1zwYrdhgAAAVg"]
[Tue Jul 21 08:30:19.910480 2026] [security2:error] [pid 418108:tid 418318] [client 103.151.46.103:55337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YSw0cxofL2J1zwYrdhgAAAVg"]
[Tue Jul 21 08:30:20.019114 2026] [security2:error] [pid 462418:tid 462674] [client 122.176.100.127:63012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YTCIybD14CLOJBaR3vwAAAH4"]
[Tue Jul 21 08:30:20.019271 2026] [security2:error] [pid 462418:tid 462674] [client 122.176.100.127:63012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YTCIybD14CLOJBaR3vwAAAH4"]
[Tue Jul 21 08:30:20.612882 2026] [security2:error] [pid 418108:tid 418232] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YTA0cxofL2J1zwYrdmAABLnk"]
[Tue Jul 21 08:30:20.613011 2026] [security2:error] [pid 418108:tid 418276] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YTA0cxofL2J1zwYrdmAABLnk"]
[Tue Jul 21 08:30:21.173598 2026] [security2:error] [pid 462418:tid 462552] [client 14.245.224.124:65456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YTSIybD14CLOJBaR3zAAAAAQ"]
[Tue Jul 21 08:30:21.173717 2026] [security2:error] [pid 462418:tid 462552] [client 14.245.224.124:65456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YTSIybD14CLOJBaR3zAAAAAQ"]
[Tue Jul 21 08:30:21.546886 2026] [security2:error] [pid 418108:tid 418357] [client 61.1.167.83:51161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YTQ0cxofL2J1zwYrdpgAAAX8"]
[Tue Jul 21 08:30:21.547029 2026] [security2:error] [pid 418108:tid 418357] [client 61.1.167.83:51161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YTQ0cxofL2J1zwYrdpgAAAX8"]
[Tue Jul 21 08:30:21.645287 2026] [security2:error] [pid 462418:tid 462550] [client 74.249.245.134:55513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/php.php"] [unique_id "al9YTSIybD14CLOJBaR30AAAAAI"]
[Tue Jul 21 08:30:22.053147 2026] [security2:error] [pid 462418:tid 462426] [remote 154.61.75.100:46532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9YTiIybD14CLOJBaR31QAANwc"]
[Tue Jul 21 08:30:22.533312 2026] [security2:error] [pid 462418:tid 462605] [client 223.181.60.88:13952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YTiIybD14CLOJBaR32gAAADk"]
[Tue Jul 21 08:30:22.533464 2026] [security2:error] [pid 462418:tid 462605] [client 223.181.60.88:13952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YTiIybD14CLOJBaR32gAAADk"]
[Tue Jul 21 08:30:22.540604 2026] [security2:error] [pid 418108:tid 418193] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YTg0cxofL2J1zwYrdtQABRlI"]
[Tue Jul 21 08:30:22.540768 2026] [security2:error] [pid 418108:tid 418300] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YTg0cxofL2J1zwYrdtQABRlI"]
[Tue Jul 21 08:30:22.560051 2026] [security2:error] [pid 418108:tid 418145] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/php_version.php"] [unique_id "al9YTg0cxofL2J1zwYrdtgABiCI"], referer: http://www.vidrosprovetro.com.br/php_version.php
[Tue Jul 21 08:30:22.706150 2026] [security2:error] [pid 462418:tid 462429] [remote 104.207.49.44:32397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.49.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9YTiIybD14CLOJBaR32wAAJAo"]
[Tue Jul 21 08:30:22.938802 2026] [security2:error] [pid 462418:tid 462554] [client 95.9.212.45:58903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.212.9.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "julianaschiavon.com"] [uri "/xmlrpc.php"] [unique_id "al9YTiIybD14CLOJBaR33QAAAAY"]
[Tue Jul 21 08:30:22.938908 2026] [security2:error] [pid 462418:tid 462554] [client 95.9.212.45:58903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "julianaschiavon.com"] [uri "/xmlrpc.php"] [unique_id "al9YTiIybD14CLOJBaR33QAAAAY"]
[Tue Jul 21 08:30:22.990641 2026] [security2:error] [pid 462418:tid 462600] [client 187.125.243.197:59452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YTiIybD14CLOJBaR33gAAADQ"]
[Tue Jul 21 08:30:22.991945 2026] [security2:error] [pid 462418:tid 462600] [client 187.125.243.197:59452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YTiIybD14CLOJBaR33gAAADQ"]
[Tue Jul 21 08:30:23.215595 2026] [security2:error] [pid 418108:tid 418171] [remote 5.182.209.54:33012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/xmlrpc.php"] [unique_id "al9YTw0cxofL2J1zwYrdwAABVDw"]
[Tue Jul 21 08:30:23.215867 2026] [security2:error] [pid 418108:tid 418314] [client 5.182.209.54:33012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rlvmultiofertas.com"] [uri "/xmlrpc.php"] [unique_id "al9YTw0cxofL2J1zwYrdwAABVDw"]
[Tue Jul 21 08:30:23.225196 2026] [security2:error] [pid 418108:tid 418223] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YTw0cxofL2J1zwYrdwQABY3A"]
[Tue Jul 21 08:30:23.225343 2026] [security2:error] [pid 418108:tid 418329] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YTw0cxofL2J1zwYrdwQABY3A"]
[Tue Jul 21 08:30:23.348703 2026] [security2:error] [pid 462418:tid 462439] [remote 57.141.18.22:34684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapf.xml"] [unique_id "al9YTyIybD14CLOJBaR34gAAKBQ"]
[Tue Jul 21 08:30:23.410637 2026] [security2:error] [pid 418108:tid 418210] [remote 45.117.83.212:44438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "frsadvocacia.net"] [uri "/wp-login.php"] [unique_id "al9YTw0cxofL2J1zwYrdxQABcGM"]
[Tue Jul 21 08:30:23.583643 2026] [autoindex:error] [pid 462418:tid 462629] [client 198.235.24.23:65012] AH01276: Cannot serve directory /home3/conec645/conectarpessoas.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:30:24.223195 2026] [security2:error] [pid 418108:tid 418289] [client 74.249.245.134:55523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/aa.php"] [unique_id "al9YUA0cxofL2J1zwYrd1gAAATs"]
[Tue Jul 21 08:30:24.575634 2026] [security2:error] [pid 462418:tid 462619] [client 49.144.66.253:31728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YUCIybD14CLOJBaR37gAAAEc"]
[Tue Jul 21 08:30:24.575755 2026] [security2:error] [pid 462418:tid 462619] [client 49.144.66.253:31728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YUCIybD14CLOJBaR37gAAAEc"]
[Tue Jul 21 08:30:25.112767 2026] [security2:error] [pid 418108:tid 418180] [remote 65.111.22.132:25399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9YUA0cxofL2J1zwYrd4gABRkU"]
[Tue Jul 21 08:30:25.629828 2026] [security2:error] [pid 418108:tid 418314] [client 195.49.128.211:64949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YUQ0cxofL2J1zwYrd7wAAAVQ"]
[Tue Jul 21 08:30:25.629956 2026] [security2:error] [pid 418108:tid 418314] [client 195.49.128.211:64949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YUQ0cxofL2J1zwYrd7wAAAVQ"]
[Tue Jul 21 08:30:25.770707 2026] [security2:error] [pid 418108:tid 418336] [client 150.129.202.39:12537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YUQ0cxofL2J1zwYrd9QAAAWo"]
[Tue Jul 21 08:30:25.770882 2026] [security2:error] [pid 418108:tid 418336] [client 150.129.202.39:12537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YUQ0cxofL2J1zwYrd9QAAAWo"]
[Tue Jul 21 08:30:25.781733 2026] [security2:error] [pid 418108:tid 418360] [client 127.0.0.1:53280] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al9YUQ0cxofL2J1zwYrd9AAAAYI"]
[Tue Jul 21 08:30:25.781820 2026] [security2:error] [pid 462418:tid 462603] [client 74.7.230.36:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.chefiabarbearia.com.br"] [uri "/robots.txt"] [unique_id "al9YUSIybD14CLOJBaR39gAANxI"]
[Tue Jul 21 08:30:26.518576 2026] [security2:error] [pid 418108:tid 418201] [remote 45.119.213.111:53478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.213.119.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-login.php"] [unique_id "al9YUg0cxofL2J1zwYreAgABQ1o"]
[Tue Jul 21 08:30:26.755768 2026] [security2:error] [pid 418108:tid 418247] [client 117.213.202.34:54604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YUg0cxofL2J1zwYreDAAAARE"]
[Tue Jul 21 08:30:26.755918 2026] [security2:error] [pid 418108:tid 418247] [client 117.213.202.34:54604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YUg0cxofL2J1zwYreDAAAARE"]
[Tue Jul 21 08:30:27.113721 2026] [security2:error] [pid 462418:tid 462602] [client 74.249.245.134:54912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/bolt.php"] [unique_id "al9YUyIybD14CLOJBaR4DQAAADY"]
[Tue Jul 21 08:30:27.833526 2026] [security2:error] [pid 418108:tid 418302] [client 74.7.228.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.triaxion.com.br.hoterplast.com.br"] [uri "/index.php"] [unique_id "al9YUw0cxofL2J1zwYreJAAAAUg"]
[Tue Jul 21 08:30:27.834171 2026] [security2:error] [pid 418108:tid 418342] [client 74.7.228.3:45074] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.triaxion.com.br.hoterplast.com.br"] [uri "/robots.txt"] [unique_id "al9YUw0cxofL2J1zwYreIQABcF0"]
[Tue Jul 21 08:30:28.275577 2026] [security2:error] [pid 418108:tid 418334] [client 14.97.58.74:62281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YVA0cxofL2J1zwYreKgAAAWg"]
[Tue Jul 21 08:30:28.275992 2026] [security2:error] [pid 418108:tid 418334] [client 14.97.58.74:62281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YVA0cxofL2J1zwYreKgAAAWg"]
[Tue Jul 21 08:30:28.453436 2026] [security2:error] [pid 462418:tid 462640] [client 74.249.245.134:55496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/x.php"] [unique_id "al9YVCIybD14CLOJBaR4PwAAAFw"]
[Tue Jul 21 08:30:28.499213 2026] [security2:error] [pid 462418:tid 462512] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/version.php"] [unique_id "al9YVCIybD14CLOJBaR4QAAAKF0"], referer: http://www.vidrosprovetro.com.br/version.php
[Tue Jul 21 08:30:29.111282 2026] [security2:error] [pid 418108:tid 418308] [client 202.179.75.202:52490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YVQ0cxofL2J1zwYrePAAAAU4"]
[Tue Jul 21 08:30:29.111402 2026] [security2:error] [pid 418108:tid 418308] [client 202.179.75.202:52490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YVQ0cxofL2J1zwYrePAAAAU4"]
[Tue Jul 21 08:30:30.088113 2026] [security2:error] [pid 418108:tid 418301] [client 195.49.128.211:57032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YVg0cxofL2J1zwYreTgAAAUc"]
[Tue Jul 21 08:30:30.088259 2026] [security2:error] [pid 418108:tid 418301] [client 195.49.128.211:57032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YVg0cxofL2J1zwYreTgAAAUc"]
[Tue Jul 21 08:30:30.456893 2026] [security2:error] [pid 462418:tid 462533] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YViIybD14CLOJBaR4WQAASXI"]
[Tue Jul 21 08:30:30.457081 2026] [security2:error] [pid 462418:tid 462621] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YViIybD14CLOJBaR4WQAASXI"]
[Tue Jul 21 08:30:30.517163 2026] [security2:error] [pid 418108:tid 418336] [client 122.176.100.127:63511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YVg0cxofL2J1zwYreVgAAAWo"]
[Tue Jul 21 08:30:30.517315 2026] [security2:error] [pid 418108:tid 418336] [client 122.176.100.127:63511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YVg0cxofL2J1zwYreVgAAAWo"]
[Tue Jul 21 08:30:30.527877 2026] [security2:error] [pid 418108:tid 418346] [client 103.151.46.103:55833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YVg0cxofL2J1zwYreVwAAAXQ"]
[Tue Jul 21 08:30:30.529394 2026] [security2:error] [pid 418108:tid 418346] [client 103.151.46.103:55833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YVg0cxofL2J1zwYreVwAAAXQ"]
[Tue Jul 21 08:30:30.993786 2026] [security2:error] [pid 462418:tid 462601] [client 14.245.224.124:49782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YViIybD14CLOJBaR4XwAAADU"]
[Tue Jul 21 08:30:30.993908 2026] [security2:error] [pid 462418:tid 462601] [client 14.245.224.124:49782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YViIybD14CLOJBaR4XwAAADU"]
[Tue Jul 21 08:30:31.055550 2026] [security2:error] [pid 418108:tid 418230] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YVw0cxofL2J1zwYreYAABInc"]
[Tue Jul 21 08:30:31.055794 2026] [security2:error] [pid 418108:tid 418264] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YVw0cxofL2J1zwYreYAABInc"]
[Tue Jul 21 08:30:31.081578 2026] [security2:error] [pid 462418:tid 462570] [client 152.59.34.51:11624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YVyIybD14CLOJBaR4YAAAABY"]
[Tue Jul 21 08:30:31.081695 2026] [security2:error] [pid 462418:tid 462570] [client 152.59.34.51:11624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YVyIybD14CLOJBaR4YAAAABY"]
[Tue Jul 21 08:30:32.661877 2026] [security2:error] [pid 418108:tid 418301] [client 74.249.245.134:55542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/jga.php"] [unique_id "al9YWA0cxofL2J1zwYrefgAAAUc"]
[Tue Jul 21 08:30:33.053150 2026] [security2:error] [pid 462418:tid 462534] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YWSIybD14CLOJBaR4bAAAZ3M"]
[Tue Jul 21 08:30:33.053309 2026] [security2:error] [pid 462418:tid 462651] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YWSIybD14CLOJBaR4bAAAZ3M"]
[Tue Jul 21 08:30:33.309483 2026] [security2:error] [pid 418108:tid 418281] [client 5.31.193.106:29991] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YWQ0cxofL2J1zwYrejAAAATM"]
[Tue Jul 21 08:30:33.309897 2026] [security2:error] [pid 418108:tid 418281] [client 5.31.193.106:29991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YWQ0cxofL2J1zwYrejAAAATM"]
[Tue Jul 21 08:30:33.420913 2026] [security2:error] [pid 418108:tid 418328] [client 223.181.60.88:8030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YWQ0cxofL2J1zwYrejgAAAWI"]
[Tue Jul 21 08:30:33.421663 2026] [security2:error] [pid 418108:tid 418328] [client 223.181.60.88:8030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YWQ0cxofL2J1zwYrejgAAAWI"]
[Tue Jul 21 08:30:33.584466 2026] [security2:error] [pid 462418:tid 462607] [client 187.125.243.197:59966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YWSIybD14CLOJBaR4cwAAADs"]
[Tue Jul 21 08:30:33.584592 2026] [security2:error] [pid 462418:tid 462607] [client 187.125.243.197:59966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YWSIybD14CLOJBaR4cwAAADs"]
[Tue Jul 21 08:30:33.684261 2026] [security2:error] [pid 418108:tid 418336] [client 65.21.113.253:36422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YWQ0cxofL2J1zwYreiwAAAWo"]
[Tue Jul 21 08:30:33.971915 2026] [security2:error] [pid 418108:tid 418201] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YWQ0cxofL2J1zwYrelQABIlo"]
[Tue Jul 21 08:30:33.972118 2026] [security2:error] [pid 418108:tid 418264] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YWQ0cxofL2J1zwYrelQABIlo"]
[Tue Jul 21 08:30:34.512473 2026] [security2:error] [pid 418108:tid 418232] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/server-info.php"] [unique_id "al9YWg0cxofL2J1zwYrengABRnk"], referer: http://www.vidrosprovetro.com.br/server-info.php
[Tue Jul 21 08:30:34.986211 2026] [security2:error] [pid 462418:tid 462590] [client 74.249.245.134:54932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/k.php"] [unique_id "al9YWiIybD14CLOJBaR4iwAAACo"]
[Tue Jul 21 08:30:35.624384 2026] [security2:error] [pid 462418:tid 462649] [client 49.144.66.253:32157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YWyIybD14CLOJBaR4lQAAAGU"]
[Tue Jul 21 08:30:35.624490 2026] [security2:error] [pid 462418:tid 462649] [client 49.144.66.253:32157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YWyIybD14CLOJBaR4lQAAAGU"]
[Tue Jul 21 08:30:35.961365 2026] [autoindex:error] [pid 418108:tid 418332] [client 43.155.157.239:58082] AH01276: Cannot serve directory /home2/onfiel33/lucaskotovicz.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:30:36.198389 2026] [security2:error] [pid 418108:tid 418327] [client 195.49.128.211:49179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YXA0cxofL2J1zwYreuQAAAWE"]
[Tue Jul 21 08:30:36.198509 2026] [security2:error] [pid 418108:tid 418327] [client 195.49.128.211:49179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YXA0cxofL2J1zwYreuQAAAWE"]
[Tue Jul 21 08:30:36.220504 2026] [security2:error] [pid 462418:tid 462580] [client 61.1.167.83:51733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YXCIybD14CLOJBaR4nwAAACA"]
[Tue Jul 21 08:30:36.220642 2026] [security2:error] [pid 462418:tid 462580] [client 61.1.167.83:51733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YXCIybD14CLOJBaR4nwAAACA"]
[Tue Jul 21 08:30:36.427779 2026] [security2:error] [pid 418108:tid 418316] [client 65.21.113.253:36422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YWw0cxofL2J1zwYresgAAAVY"]
[Tue Jul 21 08:30:36.503108 2026] [security2:error] [pid 462418:tid 462566] [client 150.129.202.39:65384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YXCIybD14CLOJBaR4vAAAABI"]
[Tue Jul 21 08:30:36.503198 2026] [security2:error] [pid 462418:tid 462566] [client 150.129.202.39:65384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YXCIybD14CLOJBaR4vAAAABI"]
[Tue Jul 21 08:30:36.624108 2026] [security2:error] [pid 462418:tid 462450] [remote 199.189.225.40:56931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-login.php"] [unique_id "al9YXCIybD14CLOJBaR4xAAAah8"]
[Tue Jul 21 08:30:37.253531 2026] [security2:error] [pid 462418:tid 462657] [client 74.249.245.134:55504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/vx.php"] [unique_id "al9YXSIybD14CLOJBaR40wAAAG0"]
[Tue Jul 21 08:30:38.211153 2026] [security2:error] [pid 418108:tid 418114] [remote 41.186.86.12:55578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9YXg0cxofL2J1zwYre2QABHgM"]
[Tue Jul 21 08:30:38.329738 2026] [security2:error] [pid 462418:tid 462651] [client 117.213.202.34:55217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YXSIybD14CLOJBaR41gAAAGc"]
[Tue Jul 21 08:30:38.330016 2026] [security2:error] [pid 462418:tid 462651] [client 117.213.202.34:55217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YXSIybD14CLOJBaR41gAAAGc"]
[Tue Jul 21 08:30:38.988531 2026] [security2:error] [pid 462418:tid 462571] [client 14.97.58.74:13321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YXiIybD14CLOJBaR46QAAABc"]
[Tue Jul 21 08:30:38.988660 2026] [security2:error] [pid 462418:tid 462571] [client 14.97.58.74:13321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YXiIybD14CLOJBaR46QAAABc"]
[Tue Jul 21 08:30:39.939155 2026] [security2:error] [pid 462418:tid 462652] [client 152.59.34.51:52392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YXyIybD14CLOJBaR49AAAAGg"]
[Tue Jul 21 08:30:39.939282 2026] [security2:error] [pid 462418:tid 462652] [client 152.59.34.51:52392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YXyIybD14CLOJBaR49AAAAGg"]
[Tue Jul 21 08:30:40.032692 2026] [security2:error] [pid 462418:tid 462559] [client 202.179.75.202:38040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YYCIybD14CLOJBaR49gAAAAs"]
[Tue Jul 21 08:30:40.032843 2026] [security2:error] [pid 462418:tid 462559] [client 202.179.75.202:38040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YYCIybD14CLOJBaR49gAAAAs"]
[Tue Jul 21 08:30:40.319870 2026] [security2:error] [pid 462418:tid 462492] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/env.php"] [unique_id "al9YYCIybD14CLOJBaR4-AAAb0k"], referer: http://www.vidrosprovetro.com.br/env.php
[Tue Jul 21 08:30:40.666368 2026] [security2:error] [pid 418108:tid 418355] [client 195.49.128.211:57619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YYA0cxofL2J1zwYre-wAAAX0"]
[Tue Jul 21 08:30:40.666475 2026] [security2:error] [pid 418108:tid 418355] [client 195.49.128.211:57619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YYA0cxofL2J1zwYre-wAAAX0"]
[Tue Jul 21 08:30:40.962241 2026] [security2:error] [pid 462418:tid 462620] [client 122.176.100.127:64023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YYCIybD14CLOJBaR5AgAAAEg"]
[Tue Jul 21 08:30:40.962345 2026] [security2:error] [pid 462418:tid 462620] [client 122.176.100.127:64023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YYCIybD14CLOJBaR5AgAAAEg"]
[Tue Jul 21 08:30:41.019986 2026] [security2:error] [pid 418108:tid 418328] [client 103.151.46.103:56319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YYQ0cxofL2J1zwYrfBgAAAWI"]
[Tue Jul 21 08:30:41.020113 2026] [security2:error] [pid 418108:tid 418328] [client 103.151.46.103:56319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YYQ0cxofL2J1zwYrfBgAAAWI"]
[Tue Jul 21 08:30:41.119884 2026] [security2:error] [pid 462418:tid 462506] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YYSIybD14CLOJBaR5BAAAY1c"]
[Tue Jul 21 08:30:41.120074 2026] [security2:error] [pid 462418:tid 462647] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YYSIybD14CLOJBaR5BAAAY1c"]
[Tue Jul 21 08:30:41.510860 2026] [security2:error] [pid 418108:tid 418301] [client 74.249.245.134:37714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/ws77.php"] [unique_id "al9YYQ0cxofL2J1zwYrfEQAAAUc"]
[Tue Jul 21 08:30:41.530881 2026] [security2:error] [pid 462418:tid 462521] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YYSIybD14CLOJBaR5CgAAAWY"]
[Tue Jul 21 08:30:41.531000 2026] [security2:error] [pid 462418:tid 462549] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YYSIybD14CLOJBaR5CgAAAWY"]
[Tue Jul 21 08:30:41.546250 2026] [security2:error] [pid 418108:tid 418303] [client 173.239.240.33:55351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9YYQ0cxofL2J1zwYrfEgAAAUk"]
[Tue Jul 21 08:30:41.915293 2026] [security2:error] [pid 418108:tid 418311] [client 14.245.224.124:50258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YYQ0cxofL2J1zwYrfGwAAAVE"]
[Tue Jul 21 08:30:41.916121 2026] [security2:error] [pid 418108:tid 418311] [client 14.245.224.124:50258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YYQ0cxofL2J1zwYrfGwAAAVE"]
[Tue Jul 21 08:30:43.457824 2026] [autoindex:error] [pid 418108:tid 418317] [client 129.204.188.64:46362] AH01276: Cannot serve directory /home1/imperd48/ussabinooffers.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:30:43.614029 2026] [security2:error] [pid 462418:tid 462534] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YYyIybD14CLOJBaR5bgAAPnM"]
[Tue Jul 21 08:30:43.614146 2026] [security2:error] [pid 462418:tid 462610] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YYyIybD14CLOJBaR5bgAAPnM"]
[Tue Jul 21 08:30:44.037229 2026] [security2:error] [pid 418108:tid 418283] [client 187.125.243.197:60470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YZA0cxofL2J1zwYrfPAAAATU"]
[Tue Jul 21 08:30:44.037946 2026] [security2:error] [pid 418108:tid 418283] [client 187.125.243.197:60470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YZA0cxofL2J1zwYrfPAAAATU"]
[Tue Jul 21 08:30:44.781305 2026] [security2:error] [pid 418108:tid 418216] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YZA0cxofL2J1zwYrfTQABhmk"]
[Tue Jul 21 08:30:44.781458 2026] [security2:error] [pid 418108:tid 418364] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YZA0cxofL2J1zwYrfTQABhmk"]
[Tue Jul 21 08:30:44.809327 2026] [security2:error] [pid 462418:tid 462658] [client 89.238.167.134:54164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9YZCIybD14CLOJBaR5jwAAAG4"]
[Tue Jul 21 08:30:44.809422 2026] [security2:error] [pid 462418:tid 462658] [client 89.238.167.134:54164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9YZCIybD14CLOJBaR5jwAAAG4"]
[Tue Jul 21 08:30:45.744167 2026] [security2:error] [pid 462418:tid 462670] [client 74.249.245.134:54955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/2.php"] [unique_id "al9YZSIybD14CLOJBaR5oAAAAHo"]
[Tue Jul 21 08:30:46.084243 2026] [security2:error] [pid 462418:tid 462440] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/init.php"] [unique_id "al9YZiIybD14CLOJBaR5pQAANxU"], referer: http://www.vidrosprovetro.com.br/init.php
[Tue Jul 21 08:30:46.207985 2026] [security2:error] [pid 462418:tid 462473] [remote 156.67.31.167:36762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9YZSIybD14CLOJBaR5lQAAZTY"]
[Tue Jul 21 08:30:46.553729 2026] [security2:error] [pid 462418:tid 462598] [client 91.148.245.81:39124] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/"] [unique_id "al9YZiIybD14CLOJBaR5qwAAADI"]
[Tue Jul 21 08:30:46.679523 2026] [security2:error] [pid 418108:tid 418366] [client 49.144.66.253:32591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YZg0cxofL2J1zwYrfYgAAAYg"]
[Tue Jul 21 08:30:46.679604 2026] [security2:error] [pid 418108:tid 418366] [client 49.144.66.253:32591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YZg0cxofL2J1zwYrfYgAAAYg"]
[Tue Jul 21 08:30:46.853179 2026] [security2:error] [pid 418108:tid 418243] [client 195.49.128.211:49806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YZg0cxofL2J1zwYrfZAAAAQ0"]
[Tue Jul 21 08:30:46.853299 2026] [security2:error] [pid 418108:tid 418243] [client 195.49.128.211:49806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YZg0cxofL2J1zwYrfZAAAAQ0"]
[Tue Jul 21 08:30:47.149800 2026] [security2:error] [pid 462418:tid 462657] [client 150.129.202.39:12536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YZyIybD14CLOJBaR5tAAAAG0"]
[Tue Jul 21 08:30:47.149937 2026] [security2:error] [pid 462418:tid 462657] [client 150.129.202.39:12536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YZyIybD14CLOJBaR5tAAAAG0"]
[Tue Jul 21 08:30:47.527392 2026] [security2:error] [pid 462418:tid 462587] [client 91.148.245.81:39152] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/config.php"] [unique_id "al9YZyIybD14CLOJBaR5uwAAACc"]
[Tue Jul 21 08:30:47.528328 2026] [security2:error] [pid 418108:tid 418286] [client 91.148.245.81:39162] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9YZw0cxofL2J1zwYrfbAAAATg"]
[Tue Jul 21 08:30:47.529239 2026] [security2:error] [pid 462418:tid 462634] [client 91.148.245.81:39140] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9YZyIybD14CLOJBaR5vAAAAFY"]
[Tue Jul 21 08:30:47.529838 2026] [security2:error] [pid 462418:tid 462558] [client 91.148.245.81:39168] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/database.sql"] [unique_id "al9YZyIybD14CLOJBaR5vQAAAAo"]
[Tue Jul 21 08:30:48.119413 2026] [security2:error] [pid 418108:tid 418260] [client 117.213.202.34:55967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YaA0cxofL2J1zwYrfdgAAAR4"]
[Tue Jul 21 08:30:48.119544 2026] [security2:error] [pid 418108:tid 418260] [client 117.213.202.34:55967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YaA0cxofL2J1zwYrfdgAAAR4"]
[Tue Jul 21 08:30:48.426871 2026] [security2:error] [pid 462418:tid 462585] [client 61.1.167.83:52251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YaCIybD14CLOJBaR5yAAAACU"]
[Tue Jul 21 08:30:48.439119 2026] [security2:error] [pid 462418:tid 462585] [client 61.1.167.83:52251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YaCIybD14CLOJBaR5yAAAACU"]
[Tue Jul 21 08:30:48.505091 2026] [security2:error] [pid 462418:tid 462601] [client 91.148.245.81:39198] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/user_secrets.yml"] [unique_id "al9YaCIybD14CLOJBaR5ygAAADU"]
[Tue Jul 21 08:30:48.505853 2026] [security2:error] [pid 462418:tid 462584] [client 91.148.245.81:39186] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9YaCIybD14CLOJBaR5ywAAACQ"]
[Tue Jul 21 08:30:48.508334 2026] [security2:error] [pid 418108:tid 418327] [client 91.148.245.81:39218] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9YaA0cxofL2J1zwYrffgAAAWE"]
[Tue Jul 21 08:30:48.508935 2026] [security2:error] [pid 418108:tid 418287] [client 91.148.245.81:39232] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/config.xml"] [unique_id "al9YaA0cxofL2J1zwYrffwAAATk"]
[Tue Jul 21 08:30:48.708232 2026] [security2:error] [pid 462418:tid 462598] [client 91.148.245.81:39210] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9YaCIybD14CLOJBaR50QAAADI"]
[Tue Jul 21 08:30:48.709111 2026] [security2:error] [pid 418108:tid 418297] [client 91.148.245.81:39248] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/.git/HEAD"] [unique_id "al9YaA0cxofL2J1zwYrfggAAAUM"]
[Tue Jul 21 08:30:48.711733 2026] [security2:error] [pid 462418:tid 462668] [client 91.148.245.81:39172] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/.env"] [unique_id "al9YaCIybD14CLOJBaR50gAAAHg"]
[Tue Jul 21 08:30:48.818469 2026] [security2:error] [pid 462418:tid 462579] [client 74.249.245.134:55539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/asd.php"] [unique_id "al9YaCIybD14CLOJBaR51AAAAB8"]
[Tue Jul 21 08:30:49.489850 2026] [security2:error] [pid 462418:tid 462558] [client 91.148.245.81:39260] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/phpinfo.php"] [unique_id "al9YaSIybD14CLOJBaR52wAAAAo"]
[Tue Jul 21 08:30:49.490176 2026] [security2:error] [pid 418108:tid 418269] [client 91.148.245.81:39252] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/dump.sql"] [unique_id "al9YaQ0cxofL2J1zwYrfiQAAASc"]
[Tue Jul 21 08:30:49.490648 2026] [security2:error] [pid 462418:tid 462617] [client 91.148.245.81:39306] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/docker-compose.yml"] [unique_id "al9YaSIybD14CLOJBaR53AAAAEU"]
[Tue Jul 21 08:30:49.494789 2026] [security2:error] [pid 462418:tid 462612] [client 91.148.245.81:39282] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/api/.env"] [unique_id "al9YaSIybD14CLOJBaR53QAAAEA"]
[Tue Jul 21 08:30:49.672948 2026] [security2:error] [pid 462418:tid 462651] [client 111.93.58.162:29133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YaSIybD14CLOJBaR53wAAAGc"]
[Tue Jul 21 08:30:49.673036 2026] [security2:error] [pid 462418:tid 462651] [client 111.93.58.162:29133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YaSIybD14CLOJBaR53wAAAGc"]
[Tue Jul 21 08:30:49.696151 2026] [security2:error] [pid 462418:tid 462566] [client 91.148.245.81:39256] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/.env.production"] [unique_id "al9YaSIybD14CLOJBaR54AAAABI"]
[Tue Jul 21 08:30:49.696678 2026] [security2:error] [pid 462418:tid 462639] [client 91.148.245.81:39294] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/config/production.json"] [unique_id "al9YaSIybD14CLOJBaR54QAAAFs"]
[Tue Jul 21 08:30:50.393138 2026] [proxy:error] [pid 462418:tid 462478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:30:50.393175 2026] [proxy_http:error] [pid 462418:tid 462478] [remote 74.7.175.144:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:30:50.393632 2026] [proxy:error] [pid 462418:tid 462478] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:30:50.393651 2026] [proxy_http:error] [pid 462418:tid 462478] [remote 74.7.175.144:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:30:50.467482 2026] [security2:error] [pid 418108:tid 418353] [client 91.148.245.81:39308] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/database_backup.sql"] [unique_id "al9Yag0cxofL2J1zwYrfmQAAAXs"]
[Tue Jul 21 08:30:50.470183 2026] [security2:error] [pid 418108:tid 418337] [client 91.148.245.81:39354] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/actuator/heapdump"] [unique_id "al9Yag0cxofL2J1zwYrfmgAAAWs"]
[Tue Jul 21 08:30:50.470796 2026] [security2:error] [pid 418108:tid 418264] [client 91.148.245.81:39338] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9Yag0cxofL2J1zwYrfmwAAASI"]
[Tue Jul 21 08:30:50.473359 2026] [security2:error] [pid 462418:tid 462630] [client 91.148.245.81:39370] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/server.key"] [unique_id "al9YaiIybD14CLOJBaR59AAAAFI"]
[Tue Jul 21 08:30:50.479580 2026] [security2:error] [pid 462418:tid 462559] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YaiIybD14CLOJBaR59QAAAAs"]
[Tue Jul 21 08:30:50.673992 2026] [security2:error] [pid 462418:tid 462659] [client 91.148.245.81:39324] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/secrets.json"] [unique_id "al9YaiIybD14CLOJBaR59wAAAG8"]
[Tue Jul 21 08:30:50.676158 2026] [security2:error] [pid 418108:tid 418365] [client 152.59.34.51:50013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Yag0cxofL2J1zwYrfnAAAAYc"]
[Tue Jul 21 08:30:50.676296 2026] [security2:error] [pid 418108:tid 418365] [client 152.59.34.51:50013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Yag0cxofL2J1zwYrfnAAAAYc"]
[Tue Jul 21 08:30:50.871493 2026] [security2:error] [pid 462418:tid 462602] [client 91.148.245.81:39386] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/wp-config.php"] [unique_id "al9YaiIybD14CLOJBaR5-gAAADY"]
[Tue Jul 21 08:30:50.874312 2026] [security2:error] [pid 462418:tid 462555] [client 91.148.245.81:39394] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/backup.zip"] [unique_id "al9YaiIybD14CLOJBaR5-wAAAAc"]
[Tue Jul 21 08:30:50.934059 2026] [security2:error] [pid 462418:tid 462587] [client 202.179.75.202:39052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YaiIybD14CLOJBaR5_gAAACc"]
[Tue Jul 21 08:30:50.934175 2026] [security2:error] [pid 462418:tid 462587] [client 202.179.75.202:39052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YaiIybD14CLOJBaR5_gAAACc"]
[Tue Jul 21 08:30:50.959784 2026] [security2:error] [pid 418108:tid 418356] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Yag0cxofL2J1zwYrfpQAAAX4"]
[Tue Jul 21 08:30:51.401277 2026] [security2:error] [pid 418108:tid 418260] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Yaw0cxofL2J1zwYrfqQAAAR4"]
[Tue Jul 21 08:30:51.426768 2026] [security2:error] [pid 462418:tid 462487] [remote 132.148.72.88:60668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9YayIybD14CLOJBaR6BwAAMkQ"]
[Tue Jul 21 08:30:51.450639 2026] [security2:error] [pid 462418:tid 462601] [client 91.148.245.81:39420] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/backup.sql"] [unique_id "al9YayIybD14CLOJBaR6CAAAADU"]
[Tue Jul 21 08:30:51.455145 2026] [security2:error] [pid 462418:tid 462584] [client 91.148.245.81:39424] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9YayIybD14CLOJBaR6CQAAACQ"]
[Tue Jul 21 08:30:51.472311 2026] [security2:error] [pid 462418:tid 462651] [client 122.176.100.127:64525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YayIybD14CLOJBaR6CwAAAGc"]
[Tue Jul 21 08:30:51.472397 2026] [security2:error] [pid 462418:tid 462651] [client 122.176.100.127:64525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YayIybD14CLOJBaR6CwAAAGc"]
[Tue Jul 21 08:30:51.552897 2026] [security2:error] [pid 462418:tid 462512] [remote 132.148.72.88:45550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bellascleaningsolutionsllc.com"] [uri "/wp-login.php"] [unique_id "al9YayIybD14CLOJBaR6DAAAJV0"]
[Tue Jul 21 08:30:51.636184 2026] [security2:error] [pid 462418:tid 462575] [client 103.151.46.103:56818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YayIybD14CLOJBaR6DQAAABs"]
[Tue Jul 21 08:30:51.636330 2026] [security2:error] [pid 462418:tid 462575] [client 103.151.46.103:56818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YayIybD14CLOJBaR6DQAAABs"]
[Tue Jul 21 08:30:51.740703 2026] [security2:error] [pid 418108:tid 418233] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Yaw0cxofL2J1zwYrfrQABDHo"]
[Tue Jul 21 08:30:51.740893 2026] [security2:error] [pid 418108:tid 418242] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Yaw0cxofL2J1zwYrfrQABDHo"]
[Tue Jul 21 08:30:51.811159 2026] [security2:error] [pid 418108:tid 418314] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Yaw0cxofL2J1zwYrfsAAAAVQ"]
[Tue Jul 21 08:30:51.925781 2026] [security2:error] [pid 462418:tid 462670] [client 74.249.245.134:37706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/default.php"] [unique_id "al9YayIybD14CLOJBaR6EQAAAHo"]
[Tue Jul 21 08:30:52.043023 2026] [security2:error] [pid 418108:tid 418221] [remote 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YbA0cxofL2J1zwYrftAABaG4"]
[Tue Jul 21 08:30:52.043225 2026] [security2:error] [pid 418108:tid 418334] [client 2409:40e2:20a9:56cd:69a0:a2e9:cf39:b84c:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YbA0cxofL2J1zwYrftAABaG4"]
[Tue Jul 21 08:30:52.227394 2026] [security2:error] [pid 462418:tid 462550] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9YbCIybD14CLOJBaR6FAAAAAI"]
[Tue Jul 21 08:30:52.298972 2026] [security2:error] [pid 462418:tid 462570] [client 195.49.128.211:58212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YayIybD14CLOJBaR6BAAAABY"]
[Tue Jul 21 08:30:52.299233 2026] [security2:error] [pid 462418:tid 462570] [client 195.49.128.211:58212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YayIybD14CLOJBaR6BAAAABY"]
[Tue Jul 21 08:30:52.479920 2026] [security2:error] [pid 462418:tid 462603] [client 91.148.245.81:39408] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/backup.tar.gz"] [unique_id "al9YbCIybD14CLOJBaR6FwAAADc"]
[Tue Jul 21 08:30:52.650459 2026] [security2:error] [pid 462418:tid 462599] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9YbCIybD14CLOJBaR6GwAAADM"]
[Tue Jul 21 08:30:52.730253 2026] [security2:error] [pid 462418:tid 462555] [client 14.245.224.124:50766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YbCIybD14CLOJBaR6HAAAAAc"]
[Tue Jul 21 08:30:52.730525 2026] [security2:error] [pid 462418:tid 462555] [client 14.245.224.124:50766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YbCIybD14CLOJBaR6HAAAAAc"]
[Tue Jul 21 08:30:52.793776 2026] [security2:error] [pid 462418:tid 462515] [remote 119.195.102.159:56434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9YbCIybD14CLOJBaR6HgAAfmA"]
[Tue Jul 21 08:30:52.913849 2026] [security2:error] [pid 418108:tid 418191] [remote 176.65.132.57:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.vidrosprovetro.com.br"] [uri "/.env"] [unique_id "al9YbA0cxofL2J1zwYrfwQABNFA"], referer: http://www.vidrosprovetro.com.br/.env
[Tue Jul 21 08:30:53.046786 2026] [security2:error] [pid 418108:tid 418362] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9YbQ0cxofL2J1zwYrfxQAAAYQ"]
[Tue Jul 21 08:30:53.401256 2026] [security2:error] [pid 462418:tid 462607] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YbSIybD14CLOJBaR6JAAAADs"]
[Tue Jul 21 08:30:53.521270 2026] [security2:error] [pid 462418:tid 462651] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9YbSIybD14CLOJBaR6JgAAAGc"]
[Tue Jul 21 08:30:53.811762 2026] [security2:error] [pid 462418:tid 462628] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9YbSIybD14CLOJBaR6KQAAAFA"]
[Tue Jul 21 08:30:53.898924 2026] [security2:error] [pid 418108:tid 418335] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9YbQ0cxofL2J1zwYrf0gAAAWk"]
[Tue Jul 21 08:30:54.162632 2026] [security2:error] [pid 462418:tid 462461] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YbiIybD14CLOJBaR6LwAARyo"]
[Tue Jul 21 08:30:54.162767 2026] [security2:error] [pid 462418:tid 462619] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YbiIybD14CLOJBaR6LwAARyo"]
[Tue Jul 21 08:30:54.243329 2026] [security2:error] [pid 462418:tid 462612] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9YbiIybD14CLOJBaR6MQAAAEA"]
[Tue Jul 21 08:30:54.331275 2026] [security2:error] [pid 462418:tid 462654] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9YbiIybD14CLOJBaR6MwAAAGo"]
[Tue Jul 21 08:30:54.526700 2026] [security2:error] [pid 462418:tid 462570] [client 187.125.243.197:60970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YbiIybD14CLOJBaR6OQAAABY"]
[Tue Jul 21 08:30:54.526820 2026] [security2:error] [pid 462418:tid 462570] [client 187.125.243.197:60970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YbiIybD14CLOJBaR6OQAAABY"]
[Tue Jul 21 08:30:54.613636 2026] [security2:error] [pid 462418:tid 462568] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9YbiIybD14CLOJBaR6PQAAABQ"]
[Tue Jul 21 08:30:54.759575 2026] [security2:error] [pid 462418:tid 462562] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9YbiIybD14CLOJBaR6QQAAAA4"]
[Tue Jul 21 08:30:54.826425 2026] [security2:error] [pid 462418:tid 462638] [client 213.152.186.163:37180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9YbiIybD14CLOJBaR6RAAAAFo"]
[Tue Jul 21 08:30:54.826556 2026] [security2:error] [pid 462418:tid 462638] [client 213.152.186.163:37180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9YbiIybD14CLOJBaR6RAAAAFo"]
[Tue Jul 21 08:30:55.004914 2026] [security2:error] [pid 418108:tid 418357] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Ybw0cxofL2J1zwYrf5QAAAX8"]
[Tue Jul 21 08:30:55.061862 2026] [security2:error] [pid 418108:tid 418340] [client 223.181.60.88:25533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Ybw0cxofL2J1zwYrf5wAAAW4"]
[Tue Jul 21 08:30:55.062924 2026] [security2:error] [pid 418108:tid 418340] [client 223.181.60.88:25533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Ybw0cxofL2J1zwYrf5wAAAW4"]
[Tue Jul 21 08:30:55.181250 2026] [security2:error] [pid 418108:tid 418352] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Ybw0cxofL2J1zwYrf6gAAAXo"]
[Tue Jul 21 08:30:55.407464 2026] [security2:error] [pid 418108:tid 418256] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Ybw0cxofL2J1zwYrf7QAAARo"]
[Tue Jul 21 08:30:55.518093 2026] [security2:error] [pid 418108:tid 418168] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ybw0cxofL2J1zwYrf7wABhTk"]
[Tue Jul 21 08:30:55.518301 2026] [security2:error] [pid 418108:tid 418363] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Ybw0cxofL2J1zwYrf7wABhTk"]
[Tue Jul 21 08:30:55.583344 2026] [security2:error] [pid 418108:tid 418318] [client 74.249.245.134:54962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/gettest.php"] [unique_id "al9Ybw0cxofL2J1zwYrf9AAAAVg"]
[Tue Jul 21 08:30:55.625324 2026] [security2:error] [pid 418108:tid 418244] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Ybw0cxofL2J1zwYrf9QAAAQ4"]
[Tue Jul 21 08:30:55.854968 2026] [security2:error] [pid 418108:tid 418299] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Ybw0cxofL2J1zwYrf-QAAAUU"]
[Tue Jul 21 08:30:56.040036 2026] [security2:error] [pid 462418:tid 462627] [client 5.31.193.106:58599] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YcCIybD14CLOJBaR6TAAAAE8"]
[Tue Jul 21 08:30:56.042134 2026] [security2:error] [pid 462418:tid 462627] [client 5.31.193.106:58599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YcCIybD14CLOJBaR6TAAAAE8"]
[Tue Jul 21 08:30:56.279104 2026] [security2:error] [pid 418108:tid 418338] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9YcA0cxofL2J1zwYrgAgAAAWw"]
[Tue Jul 21 08:30:56.703117 2026] [security2:error] [pid 462418:tid 462652] [client 91.148.245.81:36794] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9YcCIybD14CLOJBaR6UwAAAGg"]
[Tue Jul 21 08:30:56.703232 2026] [security2:error] [pid 418108:tid 418336] [client 91.148.245.81:36782] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/.npmrc"] [unique_id "al9YcA0cxofL2J1zwYrgCgAAAWo"]
[Tue Jul 21 08:30:56.704263 2026] [security2:error] [pid 462418:tid 462675] [client 91.148.245.81:36780] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/.bash_history"] [unique_id "al9YcCIybD14CLOJBaR6VAAAAH8"]
[Tue Jul 21 08:30:56.704491 2026] [security2:error] [pid 418108:tid 418346] [client 91.148.245.81:36806] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adms2.com.br"] [uri "/.svn/wc.db"] [unique_id "al9YcA0cxofL2J1zwYrgCwAAAXQ"]
[Tue Jul 21 08:30:56.722900 2026] [security2:error] [pid 462418:tid 462659] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9YcCIybD14CLOJBaR6VQAAAG8"]
[Tue Jul 21 08:30:57.126342 2026] [security2:error] [pid 418108:tid 418317] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9YcQ0cxofL2J1zwYrgEwAAAVc"]
[Tue Jul 21 08:30:57.413180 2026] [security2:error] [pid 418108:tid 418262] [client 195.49.128.211:50429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YcQ0cxofL2J1zwYrgGQAAASA"]
[Tue Jul 21 08:30:57.413331 2026] [security2:error] [pid 418108:tid 418262] [client 195.49.128.211:50429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YcQ0cxofL2J1zwYrgGQAAASA"]
[Tue Jul 21 08:30:57.496793 2026] [security2:error] [pid 418108:tid 418139] [remote 202.51.202.242:58746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/wp-login.php"] [unique_id "al9YcQ0cxofL2J1zwYrgGgABhxw"]
[Tue Jul 21 08:30:57.548671 2026] [security2:error] [pid 418108:tid 418352] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9YcQ0cxofL2J1zwYrgGwAAAXo"]
[Tue Jul 21 08:30:57.585431 2026] [security2:error] [pid 462418:tid 462568] [client 49.144.66.253:33014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YcSIybD14CLOJBaR6YQAAABQ"]
[Tue Jul 21 08:30:57.585574 2026] [security2:error] [pid 462418:tid 462568] [client 49.144.66.253:33014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YcSIybD14CLOJBaR6YQAAABQ"]
[Tue Jul 21 08:30:57.735505 2026] [security2:error] [pid 462418:tid 462614] [client 150.129.202.39:64717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YcSIybD14CLOJBaR6ZgAAAEI"]
[Tue Jul 21 08:30:57.735618 2026] [security2:error] [pid 462418:tid 462614] [client 150.129.202.39:64717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YcSIybD14CLOJBaR6ZgAAAEI"]
[Tue Jul 21 08:30:57.960920 2026] [security2:error] [pid 462418:tid 462567] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9YcSIybD14CLOJBaR6ZwAAABM"]
[Tue Jul 21 08:30:58.131493 2026] [security2:error] [pid 418108:tid 418309] [client 74.249.245.134:37655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/tfm.php"] [unique_id "al9Ycg0cxofL2J1zwYrgJQAAAU8"]
[Tue Jul 21 08:30:58.372627 2026] [security2:error] [pid 462418:tid 462659] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9YciIybD14CLOJBaR6bwAAAG8"]
[Tue Jul 21 08:30:58.468477 2026] [security2:error] [pid 418108:tid 418334] [client 89.238.167.134:36900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Ycg0cxofL2J1zwYrgKQAAAWg"]
[Tue Jul 21 08:30:58.468573 2026] [security2:error] [pid 418108:tid 418334] [client 89.238.167.134:36900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Ycg0cxofL2J1zwYrgKQAAAWg"]
[Tue Jul 21 08:30:58.583003 2026] [security2:error] [pid 462418:tid 462601] [client 117.213.202.34:56764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YciIybD14CLOJBaR6dAAAADU"]
[Tue Jul 21 08:30:58.583137 2026] [security2:error] [pid 462418:tid 462601] [client 117.213.202.34:56764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YciIybD14CLOJBaR6dAAAADU"]
[Tue Jul 21 08:30:59.064153 2026] [security2:error] [pid 418108:tid 418117] [remote 176.65.132.57:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.vidrosprovetro.com.br"] [uri "/.env.bak"] [unique_id "al9Ycw0cxofL2J1zwYrgMgABXAY"], referer: http://www.vidrosprovetro.com.br/.env.bak
[Tue Jul 21 08:31:00.132852 2026] [security2:error] [pid 418108:tid 418267] [client 74.249.245.134:55514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/ws81.php"] [unique_id "al9YdA0cxofL2J1zwYrgQgAAASU"]
[Tue Jul 21 08:31:00.477646 2026] [security2:error] [pid 462418:tid 462639] [client 137.97.59.154:46307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YdCIybD14CLOJBaR6jAAAAFs"]
[Tue Jul 21 08:31:00.477788 2026] [security2:error] [pid 462418:tid 462639] [client 137.97.59.154:46307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YdCIybD14CLOJBaR6jAAAAFs"]
[Tue Jul 21 08:31:01.070648 2026] [security2:error] [pid 418108:tid 418360] [client 61.1.167.83:52790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YdQ0cxofL2J1zwYrgUAAAAYI"]
[Tue Jul 21 08:31:01.070761 2026] [security2:error] [pid 418108:tid 418360] [client 61.1.167.83:52790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YdQ0cxofL2J1zwYrgUAAAAYI"]
[Tue Jul 21 08:31:01.445004 2026] [security2:error] [pid 462418:tid 462675] [client 152.59.34.51:41401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YdSIybD14CLOJBaR6kwAAAH8"]
[Tue Jul 21 08:31:01.445168 2026] [security2:error] [pid 462418:tid 462675] [client 152.59.34.51:41401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YdSIybD14CLOJBaR6kwAAAH8"]
[Tue Jul 21 08:31:01.646430 2026] [security2:error] [pid 418108:tid 418293] [client 20.197.192.193:5609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9YdQ0cxofL2J1zwYrgWAAAAT8"]
[Tue Jul 21 08:31:01.801605 2026] [security2:error] [pid 462418:tid 462632] [client 195.49.128.211:58814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YdSIybD14CLOJBaR6lwAAAFQ"]
[Tue Jul 21 08:31:01.801716 2026] [security2:error] [pid 462418:tid 462632] [client 195.49.128.211:58814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YdSIybD14CLOJBaR6lwAAAFQ"]
[Tue Jul 21 08:31:01.959969 2026] [security2:error] [pid 418108:tid 418326] [client 122.176.100.127:65037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YdQ0cxofL2J1zwYrgYQAAAWA"]
[Tue Jul 21 08:31:01.960083 2026] [security2:error] [pid 418108:tid 418326] [client 122.176.100.127:65037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YdQ0cxofL2J1zwYrgYQAAAWA"]
[Tue Jul 21 08:31:01.999810 2026] [security2:error] [pid 462418:tid 462673] [client 20.197.192.193:5988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9YdSIybD14CLOJBaR6nAAAAH0"]
[Tue Jul 21 08:31:02.362542 2026] [security2:error] [pid 418108:tid 418112] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Ydg0cxofL2J1zwYrgZgABRQE"]
[Tue Jul 21 08:31:02.362712 2026] [security2:error] [pid 418108:tid 418299] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Ydg0cxofL2J1zwYrgZgABRQE"]
[Tue Jul 21 08:31:02.364704 2026] [security2:error] [pid 462418:tid 462630] [client 202.179.75.202:44040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YdiIybD14CLOJBaR6oAAAAFI"]
[Tue Jul 21 08:31:02.364807 2026] [security2:error] [pid 462418:tid 462630] [client 202.179.75.202:44040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YdiIybD14CLOJBaR6oAAAAFI"]
[Tue Jul 21 08:31:02.848999 2026] [security2:error] [pid 418108:tid 418354] [client 20.197.192.193:65181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Ydg0cxofL2J1zwYrgbgAAAXw"]
[Tue Jul 21 08:31:03.186588 2026] [security2:error] [pid 462418:tid 462651] [client 74.7.175.144:47274] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "darlifeitoza.online"] [uri "/index.php"] [unique_id "al9YdiIybD14CLOJBaR6qQAAZzU"]
[Tue Jul 21 08:31:03.554541 2026] [security2:error] [pid 462418:tid 462438] [remote 45.3.45.68:24095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9YdiIybD14CLOJBaR6pQAAdxM"]
[Tue Jul 21 08:31:03.643499 2026] [security2:error] [pid 418108:tid 418365] [client 14.245.224.124:51261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Ydw0cxofL2J1zwYrgfQAAAYc"]
[Tue Jul 21 08:31:03.643652 2026] [security2:error] [pid 418108:tid 418365] [client 14.245.224.124:51261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Ydw0cxofL2J1zwYrgfQAAAYc"]
[Tue Jul 21 08:31:03.700510 2026] [security2:error] [pid 418108:tid 418352] [client 74.249.245.134:37732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/222.php"] [unique_id "al9Ydw0cxofL2J1zwYrgfgAAAXo"]
[Tue Jul 21 08:31:04.370477 2026] [security2:error] [pid 462418:tid 462598] [client 213.152.186.163:41860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YeCIybD14CLOJBaR6vgAAADI"]
[Tue Jul 21 08:31:04.370575 2026] [security2:error] [pid 462418:tid 462598] [client 213.152.186.163:41860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YeCIybD14CLOJBaR6vgAAADI"]
[Tue Jul 21 08:31:04.661238 2026] [security2:error] [pid 462418:tid 462459] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YeCIybD14CLOJBaR6xAAAUig"]
[Tue Jul 21 08:31:04.661402 2026] [security2:error] [pid 462418:tid 462630] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YeCIybD14CLOJBaR6xAAAUig"]
[Tue Jul 21 08:31:04.884035 2026] [security2:error] [pid 418108:tid 418168] [remote 20.153.140.50:58466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/xmlrpc.php"] [unique_id "al9YeA0cxofL2J1zwYrgkgABYDk"]
[Tue Jul 21 08:31:04.884210 2026] [security2:error] [pid 418108:tid 418326] [client 20.153.140.50:58466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "supremaservices.net"] [uri "/xmlrpc.php"] [unique_id "al9YeA0cxofL2J1zwYrgkgABYDk"]
[Tue Jul 21 08:31:04.967057 2026] [security2:error] [pid 418108:tid 418310] [client 187.125.243.197:61465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YeA0cxofL2J1zwYrglwAAAVA"]
[Tue Jul 21 08:31:04.967185 2026] [security2:error] [pid 418108:tid 418310] [client 187.125.243.197:61465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YeA0cxofL2J1zwYrglwAAAVA"]
[Tue Jul 21 08:31:05.104037 2026] [security2:error] [pid 462418:tid 462566] [client 103.151.46.103:57308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YeSIybD14CLOJBaR60AAAABI"]
[Tue Jul 21 08:31:05.104142 2026] [security2:error] [pid 462418:tid 462566] [client 103.151.46.103:57308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YeSIybD14CLOJBaR60AAAABI"]
[Tue Jul 21 08:31:05.387604 2026] [security2:error] [pid 462418:tid 462586] [client 74.7.241.175:55920] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "vanessaglowhair.com.startonesite.com.br"] [uri "/index.php"] [unique_id "al9YeSIybD14CLOJBaR60gAAJmo"]
[Tue Jul 21 08:31:05.518715 2026] [security2:error] [pid 462418:tid 462467] [remote 97.74.87.194:33360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moneyclass.com.br"] [uri "/wp-login.php"] [unique_id "al9YeSIybD14CLOJBaR61AAAZjA"]
[Tue Jul 21 08:31:05.603010 2026] [security2:error] [pid 462418:tid 462625] [client 74.249.245.134:54969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/t.php"] [unique_id "al9YeSIybD14CLOJBaR61QAAAE0"]
[Tue Jul 21 08:31:05.784684 2026] [security2:error] [pid 462418:tid 462591] [client 89.238.167.134:46606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9YeSIybD14CLOJBaR61gAAACs"]
[Tue Jul 21 08:31:05.784805 2026] [security2:error] [pid 462418:tid 462591] [client 89.238.167.134:46606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9YeSIybD14CLOJBaR61gAAACs"]
[Tue Jul 21 08:31:05.824806 2026] [security2:error] [pid 418108:tid 418256] [client 89.238.167.134:36916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9YeQ0cxofL2J1zwYrgrQAAARo"]
[Tue Jul 21 08:31:05.824922 2026] [security2:error] [pid 418108:tid 418256] [client 89.238.167.134:36916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9YeQ0cxofL2J1zwYrgrQAAARo"]
[Tue Jul 21 08:31:05.871735 2026] [security2:error] [pid 462418:tid 462555] [client 74.7.175.148:58410] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.vanessaglowhair.com"] [uri "/index.php"] [unique_id "al9YeSIybD14CLOJBaR61wAAB1E"]
[Tue Jul 21 08:31:06.542073 2026] [security2:error] [pid 462418:tid 462668] [client 173.252.95.37:44522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9YeiIybD14CLOJBaR63QAAAHg"]
[Tue Jul 21 08:31:06.745822 2026] [security2:error] [pid 462418:tid 462670] [client 223.181.60.88:17633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YeiIybD14CLOJBaR65QAAAHo"]
[Tue Jul 21 08:31:06.746399 2026] [security2:error] [pid 462418:tid 462670] [client 223.181.60.88:17633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YeiIybD14CLOJBaR65QAAAHo"]
[Tue Jul 21 08:31:06.789190 2026] [security2:error] [pid 462418:tid 462517] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YeiIybD14CLOJBaR65gAAZGI"]
[Tue Jul 21 08:31:06.789349 2026] [security2:error] [pid 462418:tid 462648] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YeiIybD14CLOJBaR65gAAZGI"]
[Tue Jul 21 08:31:07.287464 2026] [security2:error] [pid 462418:tid 462661] [client 69.171.230.38:48316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9YeyIybD14CLOJBaR66gAAAHE"]
[Tue Jul 21 08:31:07.350783 2026] [security2:error] [pid 462418:tid 462558] [client 173.252.95.20:63524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9YeyIybD14CLOJBaR66wAAAAo"]
[Tue Jul 21 08:31:07.483219 2026] [security2:error] [pid 462418:tid 462650] [client 74.249.245.134:55498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/a.php"] [unique_id "al9YeyIybD14CLOJBaR67QAAAGY"]
[Tue Jul 21 08:31:07.552987 2026] [security2:error] [pid 462418:tid 462566] [client 173.252.95.17:52426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9YeyIybD14CLOJBaR67AAAABI"]
[Tue Jul 21 08:31:07.668313 2026] [mpm_event:notice] [pid 131539:tid 131539] AH00493: SIGUSR1 received.  Doing graceful restart
[Tue Jul 21 08:31:07.774677 2026] [security2:error] [pid 462418:tid 462586] [client 65.21.113.253:56214] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YeyIybD14CLOJBaR67gAAACY"]
[Tue Jul 21 08:31:08.024901 2026] [security2:error] [pid 418108:tid 418356] [client 195.49.128.211:51051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YfA0cxofL2J1zwYrg1AAAAX4"]
[Tue Jul 21 08:31:08.025004 2026] [security2:error] [pid 418108:tid 418356] [client 195.49.128.211:51051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YfA0cxofL2J1zwYrg1AAAAX4"]
[Tue Jul 21 08:31:08.306188 2026] [security2:error] [pid 418108:tid 418354] [client 45.8.19.173:59125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9YfA0cxofL2J1zwYrg1QAAAXw"]
[Tue Jul 21 08:31:08.329265 2026] [security2:error] [pid 462418:tid 462577] [client 150.129.202.39:65091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YfCIybD14CLOJBaR67wAAAB0"]
[Tue Jul 21 08:31:08.329543 2026] [security2:error] [pid 462418:tid 462577] [client 150.129.202.39:65091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YfCIybD14CLOJBaR67wAAAB0"]
[Tue Jul 21 08:31:08.873006 2026] [:notice] [pid 402022:tid 402022] [host root@br1102.hostgator.com.br] mod_lsapi:  Selfstarter 402022 stopped
[Tue Jul 21 08:31:10.907444 2026] [security2:error] [pid 418108:tid 418141] [remote 202.51.202.242:38274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9Yfg0cxofL2J1zwYrg1gABNh4"]
[Tue Jul 21 08:31:11.477172 2026] [lsapi:notice] [pid 131539:tid 131539] mod_lsapi:  version 1.1-92
[Tue Jul 21 08:31:11.484638 2026] [:notice] [pid 465548:tid 465548] [host root@br1102.hostgator.com.br] mod_lsapi:  Selfstarter 465548 started
[Tue Jul 21 08:31:11.499326 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oppbrazil.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.500994 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: locadoracmd.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.506860 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbc.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.519046 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbr.com.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.534136 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: metodoatracaoconsciente.com.vanderleiasilva.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.537182 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sofiagheller1782846626000.argentajoias.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.537670 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sofiagheller1782846537000.argentajoias.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.543917 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: getveltrixhealth.com.shopmelhorcompraonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.546262 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: adloop.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.546884 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: contafic.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.547525 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: climadek.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.547971 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lojacasacosta.com.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.548584 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: voztricolor.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.549099 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arenaalphaville.com.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.549556 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rioclaroimovel.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.550025 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marketingderua.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.550710 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tabelionatoportoalegre.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.551349 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: learningsociety.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.551820 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: clubmarketplace.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.552415 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arenaalphaville.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.552824 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: app.itqmogiguacu.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.553262 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lp.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.553846 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.554472 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.meupsiquiatraonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.554877 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: empresas.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.555274 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: dizi.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.556125 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rdgoseguros.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.556552 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: diziseguros.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.562627 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rilicitacoes.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.563194 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rilicitacoes.com.br.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.563810 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: espaconeuroascensao.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.564430 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: espaconeuroascensao.com.br.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.568571 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sscoenper.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.569009 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ssvistorias.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.569423 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rastreamentobh.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.570005 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: locamotobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.570475 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: companhiatop.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.571068 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: acheservicos.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.571485 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aluguelmotobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.571906 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aluguelcarrobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.579181 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: patihipopressivo.com.patyhipopressivo.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.579618 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: patihipopressivo.com.br.patyhipopressivo.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.584045 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyer.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.584613 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyerapp.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.585071 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.585481 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vespnutricao.com.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.586093 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.com.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.586537 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.602250 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lojinhadoprofessor.lojinhadaprofessora.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.607666 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: leonardodossantoshen1782739753000.metropollitano.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.610352 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: unoperformancedigital.com.br.karenvieiramarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.610981 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jbms.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.611413 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: benti.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.611806 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: yuribenassi.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.612178 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: wbapoiocontabil.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.612524 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: movimenti.com.br.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.622259 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sigescala.com.sigescala.meusitehostgator.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.637574 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vivenciarempauta.vivenciarempauta.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.645368 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: 3d-surgery.3d-surgery.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.645989 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vivafinanceiras.com.br.vivafinanceira.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.651892 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: academycont.com.goldentrips40.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.655036 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: trendsol.com.br.fusoesaquisicoes.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.657275 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: libertysolutions.figempreendimentos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.659546 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: naturofarma.com.br.farmaciafarmula.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.660060 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: farmacianaturofarma.com.br.farmaciafarmula.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.661108 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: meuamordevoltaa.estriasnuncamaiss.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.662230 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atividadessprontas.online.estriasnuncamaiss.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.669360 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: esidiomass.com.br.eslanguageschool.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.669721 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: porondeeuestive.com.br.eslanguageschool.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.680060 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: deniltoncostasilva1748033966000.samanenergia.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.684140 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: santotchay.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.684510 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: santotchay.com.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.685025 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: osantotchay.com.br.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.685512 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oinglesdescomplicado.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.685860 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: brasilmotoeletrica.com.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.693140 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: thenexbr.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.712149 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: c5liberdades.store.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.712621 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtoswendell.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.712975 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtosnapromo.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.714270 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: c5liberdades.com.br.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.723951 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtosnapromo.com.br.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.730218 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: weddinglarissaefelipe.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.733618 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtoswendellcarvalho.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.735077 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: exclusivepromotiontoday.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.742455 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pandie.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.743040 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guarushop.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.743647 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guarushop2.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.744161 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olhobionico.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.744525 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pandoradango.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.745013 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guiadeoferta.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.745587 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fofoqueironews.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.746181 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: reidocouro.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.746792 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bloquetebrasil.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.747386 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: protetordegraxa.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.751686 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atom-growth.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.752551 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atom-growth.com.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.753281 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: confiancedigital.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.753857 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: buddyclub.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.754625 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gotavitaoriginal.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.755396 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: motoboyjaguariuna.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.756566 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jandiraemdestaque.com.br.jornaldagrandesp.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.778505 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbc.com.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.785543 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.787861 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sociooculto.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.788691 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: exnova.tech.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.790272 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.store.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.790707 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marlonbarreto.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.791103 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.791514 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atilafagundes.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.791953 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: suaconsulta.fun.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.793131 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: escolhasaudavel.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.793908 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinicius-schneider.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.794468 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sociooculto.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.794955 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olimposolar.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.795501 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nextfitjourney.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.796315 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: themaisonhommes.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.796698 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tamojuntomidias.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.797155 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gustvoferraritrader.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.797709 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marlonbarreto.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.798301 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: escolhasaudavel.shop.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.798734 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atilafagundes.online.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.799157 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinicius-schneider.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.799838 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mariabonfim1762105378000.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.800407 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gustvoferraritrader.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.802489 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: flowwshop.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.803174 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agmiz.com.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.803804 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: comecx.online.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.804322 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: flowwshop.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.805606 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.findcomp.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.806249 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: importeicomponentes.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.810621 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aede.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.811284 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: suora.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.812111 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: condmidia.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.812761 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: recowmenda.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.813342 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: valeuefalou.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.813882 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: trilhasdafe.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.814476 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bergsantana.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.815071 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: shyoftherock.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.815618 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pegueaestrada.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.816239 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nocaminhodafe.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.816770 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arielson.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.817186 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: amareloturquesa.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.817543 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: terraluna.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.817908 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: zooparquevet.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.818403 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nosnaestrada.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.961731 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fusoesaquisicoes.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:11.995709 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conairmfg.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.000625 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.033941 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: revistareflexopolitico.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.034800 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ethanslowell.com.infoalert.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.037248 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: evolvaa.online.evolia.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.039441 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bracks.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.044495 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: raimundol.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.047904 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conhecaonordeste.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.048285 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: overkotz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.048637 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lucaskotovicz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.049051 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: kotovicz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.052360 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agendazap.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.053582 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ebookswl.com.wendelleite.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.055707 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: empacta.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.056799 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: inovaeditorial.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.057588 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: volyoaudiobooks.com.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.061349 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: slapingles.com.teacheraleff.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.061662 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: speakinglikeapro.teacheraleff.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.062011 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: brasilcertdigital.tavarescont.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.065684 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: wenith.com.br.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.066250 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783665345000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.066786 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783664968000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.067350 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783664932000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.067754 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783569474000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.074519 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: solarisimplementos.com.solarisimplementos.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.076719 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: madmoholding.saojorgesiderurgia.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.081074 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: evolvaa.com.evolia.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.083136 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sulmov.com.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.083502 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: expovilhena.com.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.083925 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tinybooks.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.084322 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: planamoveis.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.084693 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: paulakaoana.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.085044 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: expovilhena.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.085383 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: muskintranet.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.085720 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: infonetelecom.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.086109 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agendamasutti.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.086452 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: politicabrasil.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.086770 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: acerteaquestao.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.087132 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mavieloeducacao.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.087513 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: noticiasrondonia.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.087862 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jornalbrasileiro.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.088217 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mavieloperformance.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.088550 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ceramicasantoaugusto.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.090386 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mrragrorepresentacoes.com.mrragrorepresentacoesltda.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.098449 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aprendizadosemlimites.store.peticoesvencedorasofc.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.105783 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gabivet24h.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.106607 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blessoriginal.com.br.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.107477 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marmorariasolare.com.br.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.150718 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: institutonwa.nwalouwacom.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.151254 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: deniansantos.com.nwalouwacom.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.151585 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fitconecta.academiausina.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.152291 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinculampe.com.br.academiausina.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.157289 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: camilajung.mktcouple.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.158170 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mixpedido.mixpdv.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.158597 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guianordestino.mixpdv.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.163697 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sulprimesc.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.164684 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: zyveria.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.165495 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: multicarsc.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.165850 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marquemarketing360.com.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.166359 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pontodooleomecanica.com.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.166680 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: capitalautocentermecanica.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.171184 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.171783 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.store.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.172217 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.online.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.198312 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rcv.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.198621 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rtdi.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.198985 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rego.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.199361 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: forte.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.199710 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: claret.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.200057 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: portali.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.200407 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mcstilo.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.200751 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: joaorocha.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.201130 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: emonteiro.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.201508 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: robertinho.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.201878 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: parqueprado.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.202287 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: asrealestate.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.202637 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lopeslascasas.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.203017 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rstlimoveis.com.br.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.203588 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: residencialvilaliviero.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.210782 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aengenhariadolucro.com.br.infoalert.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.245882 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: beautyline2.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.246663 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: thejapanway.com.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.247671 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: shopbestdaily.com.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.249141 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oferta.roncostop.com.br.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.249503 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: artix.locaiestetica.com.br.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.249885 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: camillasandrini1772124780000.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.270387 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: potencialilimitado.com.br.alzirarhein.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.278175 2026] [log_config:warn] [pid 462418:tid 462441] (32)Broken pipe: [remote 57.141.18.58:42890] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:12.278219 2026] [log_config:warn] [pid 462418:tid 462441] (32)Broken pipe: [remote 57.141.18.58:42890] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:12.281803 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.291905 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: triviaodontologi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.295839 2026] [log_config:warn] [pid 462418:tid 462451] (32)Broken pipe: [remote 57.141.18.108:26934] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:12.295862 2026] [log_config:warn] [pid 462418:tid 462451] (32)Broken pipe: [remote 57.141.18.108:26934] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:12.323517 2026] [log_config:warn] [pid 418108:tid 418175] (32)Broken pipe: [remote 57.141.18.84:34806] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:12.323542 2026] [log_config:warn] [pid 418108:tid 418175] (32)Broken pipe: [remote 57.141.18.84:34806] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:12.368964 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mastercatu.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.376745 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.473803 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 08:31:12.495029 2026] [qos:notice] [pid 131539:tid 131539] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Tue Jul 21 08:31:12.824166 2026] [http2:info] [pid 131539:tid 131539] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Tue Jul 21 08:31:12.830118 2026] [mpm_event:notice] [pid 131539:tid 131539] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Tue Jul 21 08:31:12.830131 2026] [core:notice] [pid 131539:tid 131539] AH00094: Command line: '/usr/sbin/httpd'
[Tue Jul 21 08:31:13.264808 2026] [log_config:warn] [pid 418108:tid 418173] (32)Broken pipe: [remote 57.141.18.31:55738] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:13.264840 2026] [log_config:warn] [pid 418108:tid 418173] (32)Broken pipe: [remote 57.141.18.31:55738] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:13.320199 2026] [log_config:warn] [pid 462418:tid 462528] (32)Broken pipe: [remote 57.141.18.24:57420] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:13.320241 2026] [log_config:warn] [pid 462418:tid 462528] (32)Broken pipe: [remote 57.141.18.24:57420] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:13.906572 2026] [http2:info] [pid 465652:tid 465652] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 08:31:13.933974 2026] [security2:error] [pid 465652:tid 465782] [client 89.238.167.134:46608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9YgTzTqJoBC2Mw28-ogwAAAIU"]
[Tue Jul 21 08:31:13.933998 2026] [security2:error] [pid 465652:tid 465796] [client 20.197.192.193:43798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9YgTzTqJoBC2Mw28-oiQAAAJM"]
[Tue Jul 21 08:31:13.934036 2026] [security2:error] [pid 465652:tid 465784] [client 74.249.245.134:37687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/a1.php"] [unique_id "al9YgTzTqJoBC2Mw28-ohwAAAIc"]
[Tue Jul 21 08:31:13.934077 2026] [security2:error] [pid 465652:tid 465782] [client 89.238.167.134:46608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9YgTzTqJoBC2Mw28-ogwAAAIU"]
[Tue Jul 21 08:31:13.967938 2026] [log_config:warn] [pid 418108:tid 418367] (32)Broken pipe: [client 74.7.227.11:37086] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log, referer: https://rkcentroautomotivoo.com.br/?path=//sys/bus/node/devices/node0/cpu8/node0/memory7/subsystem/devices/memory2/subsystem/devices/memory11/subsystem/devices/memory6
[Tue Jul 21 08:31:13.967954 2026] [log_config:warn] [pid 418108:tid 418367] (32)Broken pipe: [client 74.7.227.11:37086] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log, referer: https://rkcentroautomotivoo.com.br/?path=//sys/bus/node/devices/node0/cpu8/node0/memory7/subsystem/devices/memory2/subsystem/devices/memory11/subsystem/devices/memory6
[Tue Jul 21 08:31:14.078916 2026] [security2:error] [pid 465652:tid 465666] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-opAAAwg0"]
[Tue Jul 21 08:31:14.079425 2026] [security2:error] [pid 465652:tid 465843] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-opAAAwg0"]
[Tue Jul 21 08:31:14.079629 2026] [core:error] [pid 465652:tid 465669] [remote 52.167.144.209:15710] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:31:14.079642 2026] [core:error] [pid 465652:tid 465669] [remote 52.167.144.209:15710] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:31:14.093980 2026] [security2:error] [pid 465652:tid 465683] [remote 132.148.72.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produto-express.com"] [uri "/wp-login.php"] [unique_id "al9YgjzTqJoBC2Mw28-ovQAAqh4"]
[Tue Jul 21 08:31:14.124278 2026] [core:alert] [pid 465652:tid 465883] [client 57.141.18.104:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:31:14.153784 2026] [access_compat:error] [pid 465652:tid 465894] [client 162.241.63.68:14998] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:31:14.247920 2026] [security2:error] [pid 465652:tid 465814] [client 130.210.6.241:59390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.6.210.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "accjbc.com"] [uri "/wp-login.php"] [unique_id "al9YgjzTqJoBC2Mw28-o1gAAAKU"], referer: https://t.co/
[Tue Jul 21 08:31:14.284601 2026] [security2:error] [pid 465652:tid 465802] [client 49.144.66.253:33417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o2QAAAJk"]
[Tue Jul 21 08:31:14.284827 2026] [security2:error] [pid 465652:tid 465802] [client 49.144.66.253:33417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o2QAAAJk"]
[Tue Jul 21 08:31:14.302959 2026] [security2:error] [pid 465652:tid 465691] [remote 72.167.132.114:49814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "domuscondominios.com.br"] [uri "/wp-login.php"] [unique_id "al9YgjzTqJoBC2Mw28-o2gAAoiY"]
[Tue Jul 21 08:31:14.310789 2026] [log_config:warn] [pid 462418:tid 462502] (32)Broken pipe: [remote 57.141.18.99:50812] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:14.310822 2026] [log_config:warn] [pid 462418:tid 462502] (32)Broken pipe: [remote 57.141.18.99:50812] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:14.360497 2026] [security2:error] [pid 465652:tid 465844] [client 202.179.75.202:37812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o3gAAAMM"]
[Tue Jul 21 08:31:14.360664 2026] [security2:error] [pid 465652:tid 465844] [client 202.179.75.202:37812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o3gAAAMM"]
[Tue Jul 21 08:31:14.394961 2026] [security2:error] [pid 465652:tid 465833] [client 195.49.128.211:59382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o4QAAALg"]
[Tue Jul 21 08:31:14.395168 2026] [security2:error] [pid 465652:tid 465833] [client 195.49.128.211:59382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o4QAAALg"]
[Tue Jul 21 08:31:14.441182 2026] [security2:error] [pid 465652:tid 465861] [client 14.245.224.124:51763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o5AAAANQ"]
[Tue Jul 21 08:31:14.441330 2026] [security2:error] [pid 465652:tid 465861] [client 14.245.224.124:51763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o5AAAANQ"]
[Tue Jul 21 08:31:14.530322 2026] [security2:error] [pid 465652:tid 465837] [client 122.176.100.127:65532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o6QAAALw"]
[Tue Jul 21 08:31:14.530578 2026] [security2:error] [pid 465652:tid 465837] [client 122.176.100.127:65532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o6QAAALw"]
[Tue Jul 21 08:31:14.605036 2026] [security2:error] [pid 465652:tid 465698] [remote 45.79.123.44:40752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/wp-login.php"] [unique_id "al9YgjzTqJoBC2Mw28-o7AAAsC0"]
[Tue Jul 21 08:31:14.640425 2026] [security2:error] [pid 465652:tid 465816] [client 14.97.58.74:63934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o7wAAAKc"]
[Tue Jul 21 08:31:14.640546 2026] [security2:error] [pid 465652:tid 465816] [client 14.97.58.74:63934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o7wAAAKc"]
[Tue Jul 21 08:31:14.644054 2026] [security2:error] [pid 465652:tid 465806] [client 117.213.202.34:57380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o7gAAAJ0"]
[Tue Jul 21 08:31:14.644162 2026] [security2:error] [pid 465652:tid 465806] [client 117.213.202.34:57380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o7gAAAJ0"]
[Tue Jul 21 08:31:14.681782 2026] [security2:error] [pid 465652:tid 465801] [client 65.21.113.253:56222] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YgjzTqJoBC2Mw28-ozQAAAJg"]
[Tue Jul 21 08:31:14.805677 2026] [security2:error] [pid 465652:tid 465904] [client 74.249.245.134:37713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/w.php"] [unique_id "al9YgjzTqJoBC2Mw28-o9gAAAP8"]
[Tue Jul 21 08:31:14.835233 2026] [security2:error] [pid 465652:tid 465907] [client 130.210.6.241:59857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.6.210.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "accjbc.com"] [uri "/wp-login.php"] [unique_id "al9YgjzTqJoBC2Mw28-o9wAAAQI"]
[Tue Jul 21 08:31:14.866018 2026] [security2:error] [pid 465652:tid 465818] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o-gAAAKk"]
[Tue Jul 21 08:31:14.875346 2026] [security2:error] [pid 465652:tid 465836] [client 61.1.167.83:53304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o_AAAALs"]
[Tue Jul 21 08:31:14.875465 2026] [security2:error] [pid 465652:tid 465836] [client 61.1.167.83:53304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YgjzTqJoBC2Mw28-o_AAAALs"]
[Tue Jul 21 08:31:14.949390 2026] [security2:error] [pid 465652:tid 465853] [client 185.198.240.31:54095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dener.design"] [uri "/wp-login.php"] [unique_id "al9YgjzTqJoBC2Mw28-o_QAAAMw"]
[Tue Jul 21 08:31:15.222952 2026] [security2:error] [pid 465652:tid 465707] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YgzzTqJoBC2Mw28-pBAAAtzY"]
[Tue Jul 21 08:31:15.223135 2026] [security2:error] [pid 465652:tid 465832] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YgzzTqJoBC2Mw28-pBAAAtzY"]
[Tue Jul 21 08:31:15.301946 2026] [log_config:warn] [pid 418108:tid 418130] (32)Broken pipe: [remote 57.141.18.56:57724] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:15.301970 2026] [log_config:warn] [pid 418108:tid 418130] (32)Broken pipe: [remote 57.141.18.56:57724] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:15.359865 2026] [log_config:warn] [pid 462418:tid 462516] (32)Broken pipe: [remote 57.141.18.0:27664] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:15.359892 2026] [log_config:warn] [pid 462418:tid 462516] (32)Broken pipe: [remote 57.141.18.0:27664] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:15.411821 2026] [security2:error] [pid 465652:tid 465882] [client 47.128.50.97:52304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pacodasrosas.com.br"] [uri "/robots.txt"] [unique_id "al9YgzzTqJoBC2Mw28-pEAAAAOk"]
[Tue Jul 21 08:31:15.429110 2026] [security2:error] [pid 465652:tid 465865] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9YgzzTqJoBC2Mw28-pEQAAANg"]
[Tue Jul 21 08:31:15.505626 2026] [security2:error] [pid 465652:tid 465790] [client 20.197.192.193:5964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/dp.php"] [unique_id "al9YgzzTqJoBC2Mw28-pFAAAAI0"]
[Tue Jul 21 08:31:15.509231 2026] [security2:error] [pid 465652:tid 465801] [client 74.249.245.134:54918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/wp-good.php"] [unique_id "al9YgzzTqJoBC2Mw28-pFQAAAJg"]
[Tue Jul 21 08:31:15.513435 2026] [security2:error] [pid 465652:tid 465712] [remote 103.161.172.221:60130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "robertaramos.com.br"] [uri "/wp-login.php"] [unique_id "al9YgzzTqJoBC2Mw28-pFgAAszs"]
[Tue Jul 21 08:31:15.538220 2026] [security2:error] [pid 465652:tid 465827] [client 5.31.193.106:1854] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YgzzTqJoBC2Mw28-pFwAAALI"]
[Tue Jul 21 08:31:15.545015 2026] [security2:error] [pid 465652:tid 465827] [client 5.31.193.106:1854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YgzzTqJoBC2Mw28-pFwAAALI"]
[Tue Jul 21 08:31:15.596681 2026] [security2:error] [pid 465652:tid 465803] [client 187.125.243.197:61966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YgzzTqJoBC2Mw28-pGAAAAJo"]
[Tue Jul 21 08:31:15.596984 2026] [security2:error] [pid 465652:tid 465803] [client 187.125.243.197:61966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YgzzTqJoBC2Mw28-pGAAAAJo"]
[Tue Jul 21 08:31:15.881131 2026] [security2:error] [pid 465652:tid 465866] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9YgzzTqJoBC2Mw28-pIQAAANk"]
[Tue Jul 21 08:31:16.280857 2026] [log_config:warn] [pid 462418:tid 462527] (32)Broken pipe: [remote 57.141.18.96:39958] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:16.280885 2026] [log_config:warn] [pid 462418:tid 462527] (32)Broken pipe: [remote 57.141.18.96:39958] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:16.289290 2026] [security2:error] [pid 465652:tid 465807] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9YhDzTqJoBC2Mw28-pLQAAAJ4"]
[Tue Jul 21 08:31:16.305669 2026] [log_config:warn] [pid 418108:tid 418210] (32)Broken pipe: [remote 57.141.18.109:32962] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:16.305695 2026] [log_config:warn] [pid 418108:tid 418210] (32)Broken pipe: [remote 57.141.18.109:32962] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:16.355096 2026] [security2:error] [pid 465652:tid 465815] [client 168.119.96.239:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9YhDzTqJoBC2Mw28-pKwAApkM"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:31:16.399543 2026] [security2:error] [pid 465652:tid 465819] [client 213.152.186.163:52500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YhDzTqJoBC2Mw28-pOAAAAKo"]
[Tue Jul 21 08:31:16.399635 2026] [security2:error] [pid 465652:tid 465819] [client 213.152.186.163:52500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YhDzTqJoBC2Mw28-pOAAAAKo"]
[Tue Jul 21 08:31:16.476090 2026] [security2:error] [pid 465652:tid 465849] [client 20.197.195.24:17062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9YhDzTqJoBC2Mw28-pQAAAAMg"]
[Tue Jul 21 08:31:16.568181 2026] [security2:error] [pid 465652:tid 465892] [client 168.119.96.239:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9YhDzTqJoBC2Mw28-pRAAA80w"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:31:16.584979 2026] [security2:error] [pid 465652:tid 465786] [client 45.8.19.168:58537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9YgjzTqJoBC2Mw28-o6gAAAIk"]
[Tue Jul 21 08:31:16.623101 2026] [autoindex:error] [pid 465652:tid 465730] [remote 179.165.184.52:65531] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/
[Tue Jul 21 08:31:16.696939 2026] [security2:error] [pid 465652:tid 465896] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9YhDzTqJoBC2Mw28-pSAAAAPc"]
[Tue Jul 21 08:31:16.713972 2026] [log_config:warn] [pid 462418:tid 462556] (32)Broken pipe: [client 89.198.81.14:57984] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:16.713991 2026] [log_config:warn] [pid 462418:tid 462556] (32)Broken pipe: [client 89.198.81.14:57984] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:16.785594 2026] [autoindex:error] [pid 465652:tid 465734] [remote 179.165.184.52:65531] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/?pag=chamada_consulta
[Tue Jul 21 08:31:16.926031 2026] [security2:error] [pid 465652:tid 465837] [client 65.21.113.253:56222] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YhDzTqJoBC2Mw28-pPgAAALw"]
[Tue Jul 21 08:31:17.104469 2026] [security2:error] [pid 465652:tid 465866] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9YhTzTqJoBC2Mw28-pWgAAANk"]
[Tue Jul 21 08:31:17.185555 2026] [security2:error] [pid 465652:tid 465831] [client 152.59.34.51:53903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YhTzTqJoBC2Mw28-pXAAAALY"]
[Tue Jul 21 08:31:17.185664 2026] [security2:error] [pid 465652:tid 465831] [client 152.59.34.51:53903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YhTzTqJoBC2Mw28-pXAAAALY"]
[Tue Jul 21 08:31:17.590174 2026] [security2:error] [pid 465652:tid 465817] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9YhTzTqJoBC2Mw28-pcQAAAKg"]
[Tue Jul 21 08:31:17.600459 2026] [security2:error] [pid 465652:tid 465861] [client 20.197.195.24:57866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9YhTzTqJoBC2Mw28-pcgAAANQ"]
[Tue Jul 21 08:31:17.690186 2026] [security2:error] [pid 465652:tid 465832] [client 142.132.180.39:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9YhTzTqJoBC2Mw28-pdAAAt18"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:31:18.058176 2026] [security2:error] [pid 465652:tid 465896] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9YhjzTqJoBC2Mw28-phQAAAPc"]
[Tue Jul 21 08:31:18.249648 2026] [security2:error] [pid 465652:tid 465898] [client 142.132.180.39:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9YhjzTqJoBC2Mw28-phwAA-WU"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:31:18.293622 2026] [log_config:warn] [pid 418108:tid 418176] (32)Broken pipe: [remote 57.141.18.121:62488] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:18.293647 2026] [log_config:warn] [pid 418108:tid 418176] (32)Broken pipe: [remote 57.141.18.121:62488] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:18.304474 2026] [log_config:warn] [pid 418108:tid 418349] (32)Broken pipe: [client 162.241.63.68:19736] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:18.304498 2026] [log_config:warn] [pid 418108:tid 418349] (32)Broken pipe: [client 162.241.63.68:19736] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:18.439840 2026] [security2:error] [pid 465652:tid 465818] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9YhjzTqJoBC2Mw28-piwAAAKk"]
[Tue Jul 21 08:31:18.637138 2026] [security2:error] [pid 465652:tid 465828] [client 195.49.128.211:51664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YhjzTqJoBC2Mw28-plgAAALM"]
[Tue Jul 21 08:31:18.637305 2026] [security2:error] [pid 465652:tid 465828] [client 195.49.128.211:51664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YhjzTqJoBC2Mw28-plgAAALM"]
[Tue Jul 21 08:31:18.849124 2026] [security2:error] [pid 465652:tid 465857] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9YhjzTqJoBC2Mw28-pmgAAANA"]
[Tue Jul 21 08:31:18.936725 2026] [security2:error] [pid 465652:tid 465862] [client 20.197.192.193:43777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/wander.php"] [unique_id "al9YhjzTqJoBC2Mw28-pnAAAANU"]
[Tue Jul 21 08:31:18.985575 2026] [security2:error] [pid 465652:tid 465902] [client 150.129.202.39:65227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YhjzTqJoBC2Mw28-pngAAAP0"]
[Tue Jul 21 08:31:18.985703 2026] [security2:error] [pid 465652:tid 465902] [client 150.129.202.39:65227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YhjzTqJoBC2Mw28-pngAAAP0"]
[Tue Jul 21 08:31:19.050321 2026] [security2:error] [pid 465652:tid 465867] [client 65.21.113.253:56222] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YhjzTqJoBC2Mw28-plQAAANo"]
[Tue Jul 21 08:31:19.096334 2026] [security2:error] [pid 465652:tid 465769] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YhzzTqJoBC2Mw28-pqwAAoHQ"]
[Tue Jul 21 08:31:19.096521 2026] [security2:error] [pid 465652:tid 465809] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YhzzTqJoBC2Mw28-pqwAAoHQ"]
[Tue Jul 21 08:31:19.274181 2026] [log_config:warn] [pid 462418:tid 462543] (32)Broken pipe: [remote 57.141.18.82:22890] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:19.274213 2026] [log_config:warn] [pid 462418:tid 462543] (32)Broken pipe: [remote 57.141.18.82:22890] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:19.274462 2026] [security2:error] [pid 465652:tid 465770] [remote 176.65.132.57:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.132.65.176.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vidrosprovetro.com.br"] [uri "/app_dev.php/_profiler/open"] [unique_id "al9YhzzTqJoBC2Mw28-prwAA83U"], referer: http://www.vidrosprovetro.com.br/app_dev.php/_profiler/open?file-app/config/parameters.yml
[Tue Jul 21 08:31:19.288756 2026] [log_config:warn] [pid 462418:tid 462664] (32)Broken pipe: [client 162.241.63.68:19750] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:19.288778 2026] [log_config:warn] [pid 462418:tid 462664] (32)Broken pipe: [client 162.241.63.68:19750] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:19.296647 2026] [security2:error] [pid 465652:tid 465806] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9YhzzTqJoBC2Mw28-psAAAAJ0"]
[Tue Jul 21 08:31:19.379605 2026] [security2:error] [pid 465652:tid 465820] [client 74.249.245.134:54934] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "ftp.bcsenepol.com.br"] [uri "/.info.php"] [unique_id "al9YhzzTqJoBC2Mw28-ptgAAAKs"]
[Tue Jul 21 08:31:19.513896 2026] [security2:error] [pid 465652:tid 465894] [client 216.73.160.189:62655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9YhzzTqJoBC2Mw28-ptAAAAPU"]
[Tue Jul 21 08:31:19.521323 2026] [security2:error] [pid 465652:tid 465904] [client 216.73.160.174:25293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9YhzzTqJoBC2Mw28-ptQAAAP8"]
[Tue Jul 21 08:31:19.582266 2026] [security2:error] [pid 465652:tid 465796] [client 216.73.160.190:58071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9YhzzTqJoBC2Mw28-pvgAAAJM"]
[Tue Jul 21 08:31:19.650527 2026] [security2:error] [pid 465652:tid 465829] [client 20.197.192.193:5599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/old.php"] [unique_id "al9YhzzTqJoBC2Mw28-pwwAAALQ"]
[Tue Jul 21 08:31:19.679563 2026] [security2:error] [pid 465652:tid 465786] [client 49.144.66.253:29716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YhzzTqJoBC2Mw28-pxAAAAIk"]
[Tue Jul 21 08:31:19.679669 2026] [security2:error] [pid 465652:tid 465786] [client 49.144.66.253:29716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YhzzTqJoBC2Mw28-pxAAAAIk"]
[Tue Jul 21 08:31:19.716736 2026] [security2:error] [pid 465652:tid 465851] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9YhzzTqJoBC2Mw28-pyQAAAMo"]
[Tue Jul 21 08:31:19.856525 2026] [security2:error] [pid 465652:tid 465862] [client 20.197.195.24:57908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/media.php"] [unique_id "al9YhzzTqJoBC2Mw28-pzAAAANU"]
[Tue Jul 21 08:31:19.924925 2026] [security2:error] [pid 465652:tid 465783] [client 117.213.202.34:57986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YhzzTqJoBC2Mw28-p0AAAAIY"]
[Tue Jul 21 08:31:19.925060 2026] [security2:error] [pid 465652:tid 465783] [client 117.213.202.34:57986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YhzzTqJoBC2Mw28-p0AAAAIY"]
[Tue Jul 21 08:31:20.140198 2026] [security2:error] [pid 465652:tid 465849] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9YiDzTqJoBC2Mw28-p2gAAAMg"]
[Tue Jul 21 08:31:20.276649 2026] [log_config:warn] [pid 462418:tid 462536] (32)Broken pipe: [remote 57.141.18.69:48382] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:20.276673 2026] [log_config:warn] [pid 462418:tid 462536] (32)Broken pipe: [remote 57.141.18.69:48382] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:20.288226 2026] [log_config:warn] [pid 418108:tid 418331] (32)Broken pipe: [client 162.241.63.68:19742] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:20.288249 2026] [log_config:warn] [pid 418108:tid 418331] (32)Broken pipe: [client 162.241.63.68:19742] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:20.305305 2026] [log_config:warn] [pid 418108:tid 418223] (32)Broken pipe: [remote 57.141.18.42:21748] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:20.305327 2026] [log_config:warn] [pid 418108:tid 418223] (32)Broken pipe: [remote 57.141.18.42:21748] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:20.314842 2026] [log_config:warn] [pid 462418:tid 462538] (32)Broken pipe: [remote 57.141.18.73:31448] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:20.314867 2026] [log_config:warn] [pid 462418:tid 462538] (32)Broken pipe: [remote 57.141.18.73:31448] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:20.317180 2026] [log_config:warn] [pid 418108:tid 418292] (32)Broken pipe: [client 162.241.63.68:19752] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:20.317209 2026] [log_config:warn] [pid 418108:tid 418292] (32)Broken pipe: [client 162.241.63.68:19752] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:20.432322 2026] [security2:error] [pid 465652:tid 465903] [client 216.73.160.38:50369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9YhzzTqJoBC2Mw28-ptwAAAP4"]
[Tue Jul 21 08:31:20.432434 2026] [security2:error] [pid 465652:tid 465905] [client 223.181.60.88:29947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YiDzTqJoBC2Mw28-p5QAAAQA"]
[Tue Jul 21 08:31:20.432588 2026] [security2:error] [pid 465652:tid 465905] [client 223.181.60.88:29947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YiDzTqJoBC2Mw28-p5QAAAQA"]
[Tue Jul 21 08:31:20.627076 2026] [security2:error] [pid 465652:tid 465659] [remote 45.117.83.212:58096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-login.php"] [unique_id "al9YiDzTqJoBC2Mw28-p7gAArAY"]
[Tue Jul 21 08:31:20.841012 2026] [security2:error] [pid 465652:tid 465803] [client 65.21.113.253:56222] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YiDzTqJoBC2Mw28-p5AAAAJo"]
[Tue Jul 21 08:31:21.332929 2026] [security2:error] [pid 465652:tid 465699] [remote 65.111.1.8:39501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.1.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9YiTzTqJoBC2Mw28-qEAAAyS4"]
[Tue Jul 21 08:31:21.355939 2026] [log_config:warn] [pid 462418:tid 462522] (32)Broken pipe: [remote 57.141.18.25:55832] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:21.355963 2026] [log_config:warn] [pid 462418:tid 462522] (32)Broken pipe: [remote 57.141.18.25:55832] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:21.361555 2026] [log_config:warn] [pid 418108:tid 418135] (32)Broken pipe: [remote 57.141.18.114:53106] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:21.361578 2026] [log_config:warn] [pid 418108:tid 418135] (32)Broken pipe: [remote 57.141.18.114:53106] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:21.595350 2026] [security2:error] [pid 465652:tid 465811] [client 111.93.58.162:15751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YiTzTqJoBC2Mw28-qFAAAAKI"]
[Tue Jul 21 08:31:21.595478 2026] [security2:error] [pid 465652:tid 465811] [client 111.93.58.162:15751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YiTzTqJoBC2Mw28-qFAAAAKI"]
[Tue Jul 21 08:31:22.003277 2026] [security2:error] [pid 465652:tid 465851] [client 20.197.195.24:18696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/images.php"] [unique_id "al9YijzTqJoBC2Mw28-qJgAAAMo"]
[Tue Jul 21 08:31:22.012607 2026] [security2:error] [pid 465652:tid 465709] [remote 124.55.178.99:44720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tempex.com.br"] [uri "/wp-login.php"] [unique_id "al9YijzTqJoBC2Mw28-qJwAA_jg"]
[Tue Jul 21 08:31:22.228251 2026] [security2:error] [pid 465652:tid 465815] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9YijzTqJoBC2Mw28-qLwAAAKY"]
[Tue Jul 21 08:31:22.257426 2026] [log_config:warn] [pid 462418:tid 462641] (32)Broken pipe: [client 162.241.63.68:19754] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:22.257449 2026] [log_config:warn] [pid 462418:tid 462641] (32)Broken pipe: [client 162.241.63.68:19754] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:22.298240 2026] [log_config:warn] [pid 462418:tid 462513] (32)Broken pipe: [remote 57.141.18.65:31094] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:22.298263 2026] [log_config:warn] [pid 462418:tid 462513] (32)Broken pipe: [remote 57.141.18.65:31094] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:22.300465 2026] [log_config:warn] [pid 462418:tid 462484] (32)Broken pipe: [remote 57.141.18.123:27614] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:22.300486 2026] [log_config:warn] [pid 462418:tid 462484] (32)Broken pipe: [remote 57.141.18.123:27614] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:22.302140 2026] [log_config:warn] [pid 462418:tid 462546] (32)Broken pipe: [remote 57.141.18.80:64382] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:22.302164 2026] [log_config:warn] [pid 462418:tid 462546] (32)Broken pipe: [remote 57.141.18.80:64382] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:22.333223 2026] [log_config:warn] [pid 462418:tid 462633] (32)Broken pipe: [client 162.241.63.68:19770] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:22.333244 2026] [log_config:warn] [pid 462418:tid 462633] (32)Broken pipe: [client 162.241.63.68:19770] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:22.373000 2026] [security2:error] [pid 465652:tid 465832] [client 125.230.64.132:26359] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "sphawks.com.br"] [uri "/wp-content/uploads/2014/03/icon_fliker.png"] [unique_id "al9YijzTqJoBC2Mw28-qPAAAALc"]
[Tue Jul 21 08:31:22.517942 2026] [security2:error] [pid 465652:tid 465878] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YijzTqJoBC2Mw28-qPwAAAOU"]
[Tue Jul 21 08:31:22.800579 2026] [security2:error] [pid 465652:tid 465896] [client 69.171.230.16:38208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9YijzTqJoBC2Mw28-qUQAAAPc"]
[Tue Jul 21 08:31:22.925587 2026] [security2:error] [pid 465652:tid 465885] [client 122.176.100.127:49654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YijzTqJoBC2Mw28-qVAAAAOw"]
[Tue Jul 21 08:31:22.925679 2026] [security2:error] [pid 465652:tid 465885] [client 122.176.100.127:49654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YijzTqJoBC2Mw28-qVAAAAOw"]
[Tue Jul 21 08:31:22.993217 2026] [security2:error] [pid 465652:tid 465784] [client 37.220.132.13:63103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.132.220.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "girassollimpeza.com.br"] [uri "/wp-login.php"] [unique_id "al9YijzTqJoBC2Mw28-qVgAAAIc"], referer: https://t.co/
[Tue Jul 21 08:31:22.999851 2026] [security2:error] [pid 465652:tid 465862] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9YijzTqJoBC2Mw28-qVwAAANU"]
[Tue Jul 21 08:31:23.051125 2026] [security2:error] [pid 465652:tid 465895] [client 195.49.128.211:59995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YizzTqJoBC2Mw28-qWgAAAPY"]
[Tue Jul 21 08:31:23.051326 2026] [security2:error] [pid 465652:tid 465895] [client 195.49.128.211:59995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YizzTqJoBC2Mw28-qWgAAAPY"]
[Tue Jul 21 08:31:23.162410 2026] [security2:error] [pid 465652:tid 465725] [remote 119.195.102.159:52984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9YizzTqJoBC2Mw28-qWwAAukg"]
[Tue Jul 21 08:31:23.261188 2026] [log_config:warn] [pid 418108:tid 418148] (32)Broken pipe: [remote 57.141.18.78:34172] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:23.261220 2026] [log_config:warn] [pid 418108:tid 418148] (32)Broken pipe: [remote 57.141.18.78:34172] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:23.264164 2026] [log_config:warn] [pid 462418:tid 462537] (32)Broken pipe: [remote 57.141.18.44:26152] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:23.264186 2026] [log_config:warn] [pid 462418:tid 462537] (32)Broken pipe: [remote 57.141.18.44:26152] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:23.285243 2026] [security2:error] [pid 465652:tid 465825] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9YizzTqJoBC2Mw28-qYQAAALA"]
[Tue Jul 21 08:31:23.296573 2026] [log_config:warn] [pid 418108:tid 418172] (32)Broken pipe: [remote 57.141.18.66:30976] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:23.296596 2026] [log_config:warn] [pid 418108:tid 418172] (32)Broken pipe: [remote 57.141.18.66:30976] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:23.300321 2026] [log_config:warn] [pid 418108:tid 418230] (32)Broken pipe: [remote 57.141.18.67:52668] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:23.300345 2026] [log_config:warn] [pid 418108:tid 418230] (32)Broken pipe: [remote 57.141.18.67:52668] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:23.319820 2026] [log_config:warn] [pid 462418:tid 462621] (32)Broken pipe: [client 162.241.63.68:19784] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:23.319842 2026] [log_config:warn] [pid 462418:tid 462621] (32)Broken pipe: [client 162.241.63.68:19784] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:23.340835 2026] [log_config:warn] [pid 462418:tid 462656] (32)Broken pipe: [client 162.241.63.68:19790] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:23.340859 2026] [log_config:warn] [pid 462418:tid 462656] (32)Broken pipe: [client 162.241.63.68:19790] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:23.345901 2026] [log_config:warn] [pid 462418:tid 462518] (32)Broken pipe: [remote 57.141.18.124:24924] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:23.345924 2026] [log_config:warn] [pid 462418:tid 462518] (32)Broken pipe: [remote 57.141.18.124:24924] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:23.429620 2026] [security2:error] [pid 465652:tid 465830] [client 37.220.132.13:63614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.132.220.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "girassollimpeza.com.br"] [uri "/wp-login.php"] [unique_id "al9YizzTqJoBC2Mw28-qaAAAALU"]
[Tue Jul 21 08:31:23.567887 2026] [security2:error] [pid 465652:tid 465822] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9YizzTqJoBC2Mw28-qaQAAAK0"]
[Tue Jul 21 08:31:23.581109 2026] [security2:error] [pid 465652:tid 465730] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YizzTqJoBC2Mw28-qagAAlU0"]
[Tue Jul 21 08:31:23.581272 2026] [security2:error] [pid 465652:tid 465798] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YizzTqJoBC2Mw28-qagAAlU0"]
[Tue Jul 21 08:31:23.589734 2026] [log_config:warn] [pid 418108:tid 418306] (32)Broken pipe: [client 103.138.47.34:40462] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:23.589746 2026] [log_config:warn] [pid 418108:tid 418306] (32)Broken pipe: [client 103.138.47.34:40462] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:23.718795 2026] [security2:error] [pid 465652:tid 465905] [client 20.197.192.193:65197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/jga.php"] [unique_id "al9YizzTqJoBC2Mw28-qbgAAAQA"]
[Tue Jul 21 08:31:23.786508 2026] [security2:error] [pid 465652:tid 465874] [client 65.21.113.253:56222] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YizzTqJoBC2Mw28-qZgAAAOE"]
[Tue Jul 21 08:31:23.852647 2026] [security2:error] [pid 465652:tid 465866] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9YizzTqJoBC2Mw28-qdQAAANk"]
[Tue Jul 21 08:31:23.880527 2026] [security2:error] [pid 465652:tid 465896] [client 74.249.245.134:54931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/item.php"] [unique_id "al9YizzTqJoBC2Mw28-qewAAAPc"]
[Tue Jul 21 08:31:24.138069 2026] [security2:error] [pid 465652:tid 465851] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9YjDzTqJoBC2Mw28-qfAAAAMo"]
[Tue Jul 21 08:31:24.141892 2026] [security2:error] [pid 465652:tid 465839] [client 202.179.75.202:58148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YjDzTqJoBC2Mw28-qfQAAAL4"]
[Tue Jul 21 08:31:24.142276 2026] [security2:error] [pid 465652:tid 465839] [client 202.179.75.202:58148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YjDzTqJoBC2Mw28-qfQAAAL4"]
[Tue Jul 21 08:31:24.220934 2026] [security2:error] [pid 465652:tid 465804] [client 128.127.105.184:50432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9YjDzTqJoBC2Mw28-qfgAAAJs"]
[Tue Jul 21 08:31:24.221008 2026] [security2:error] [pid 465652:tid 465804] [client 128.127.105.184:50432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9YjDzTqJoBC2Mw28-qfgAAAJs"]
[Tue Jul 21 08:31:24.335776 2026] [log_config:warn] [pid 462418:tid 462533] (32)Broken pipe: [remote 57.141.18.95:26632] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:24.335800 2026] [log_config:warn] [pid 462418:tid 462533] (32)Broken pipe: [remote 57.141.18.95:26632] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:24.423356 2026] [security2:error] [pid 465652:tid 465783] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9YjDzTqJoBC2Mw28-qjQAAAIY"]
[Tue Jul 21 08:31:24.671137 2026] [security2:error] [pid 465652:tid 465744] [remote 199.189.225.40:55589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ryancastroweb.com"] [uri "/wp-login.php"] [unique_id "al9YjDzTqJoBC2Mw28-qmgAAvVs"]
[Tue Jul 21 08:31:24.719901 2026] [security2:error] [pid 465652:tid 465831] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9YjDzTqJoBC2Mw28-qmwAAALY"]
[Tue Jul 21 08:31:24.974305 2026] [security2:error] [pid 465652:tid 465872] [client 152.59.34.51:54399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YjDzTqJoBC2Mw28-qqAAAAN8"]
[Tue Jul 21 08:31:24.974399 2026] [security2:error] [pid 465652:tid 465872] [client 152.59.34.51:54399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YjDzTqJoBC2Mw28-qqAAAAN8"]
[Tue Jul 21 08:31:25.004316 2026] [security2:error] [pid 465652:tid 465843] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9YjTzTqJoBC2Mw28-qqgAAAMI"]
[Tue Jul 21 08:31:25.006358 2026] [security2:error] [pid 465652:tid 465854] [client 37.220.132.13:63803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.132.220.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "girassollimpeza.com.br"] [uri "/wp-login.php"] [unique_id "al9YjTzTqJoBC2Mw28-qqwAAAM0"], referer: https://www.google.com/
[Tue Jul 21 08:31:25.143632 2026] [security2:error] [pid 465652:tid 465796] [client 173.252.95.40:59698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9YjTzTqJoBC2Mw28-qrAAAAJM"]
[Tue Jul 21 08:31:25.263321 2026] [log_config:warn] [pid 418108:tid 418231] (32)Broken pipe: [remote 57.141.18.50:21538] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:25.263348 2026] [log_config:warn] [pid 418108:tid 418231] (32)Broken pipe: [remote 57.141.18.50:21538] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:25.278279 2026] [log_config:warn] [pid 418108:tid 418160] (32)Broken pipe: [remote 57.141.18.86:30354] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:25.278306 2026] [log_config:warn] [pid 418108:tid 418160] (32)Broken pipe: [remote 57.141.18.86:30354] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:25.290558 2026] [security2:error] [pid 465652:tid 465909] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9YjTzTqJoBC2Mw28-qrgAAAQQ"]
[Tue Jul 21 08:31:25.476538 2026] [security2:error] [pid 465652:tid 465782] [client 14.245.224.124:52248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YjTzTqJoBC2Mw28-qtwAAAIU"]
[Tue Jul 21 08:31:25.476639 2026] [security2:error] [pid 465652:tid 465782] [client 14.245.224.124:52248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YjTzTqJoBC2Mw28-qtwAAAIU"]
[Tue Jul 21 08:31:25.574266 2026] [security2:error] [pid 465652:tid 465794] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9YjTzTqJoBC2Mw28-quwAAAJE"]
[Tue Jul 21 08:31:25.722402 2026] [security2:error] [pid 465652:tid 465755] [remote 176.65.132.57:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "www.vidrosprovetro.com.br"] [uri "/web/dump-6-18-15.sql"] [unique_id "al9YjTzTqJoBC2Mw28-qwQAAhmY"], referer: http://www.vidrosprovetro.com.br/web/dump-6-18-15.sql
[Tue Jul 21 08:31:25.740156 2026] [security2:error] [pid 465652:tid 465856] [client 103.151.46.103:58290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YjTzTqJoBC2Mw28-qwgAAAM8"]
[Tue Jul 21 08:31:25.740507 2026] [security2:error] [pid 465652:tid 465856] [client 103.151.46.103:58290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YjTzTqJoBC2Mw28-qwgAAAM8"]
[Tue Jul 21 08:31:25.747552 2026] [security2:error] [pid 465652:tid 465882] [client 61.1.167.83:53815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YjTzTqJoBC2Mw28-qwwAAAOk"]
[Tue Jul 21 08:31:25.747701 2026] [security2:error] [pid 465652:tid 465882] [client 61.1.167.83:53815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YjTzTqJoBC2Mw28-qwwAAAOk"]
[Tue Jul 21 08:31:25.760863 2026] [security2:error] [pid 465652:tid 465762] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YjTzTqJoBC2Mw28-qxAAAum0"]
[Tue Jul 21 08:31:25.761022 2026] [security2:error] [pid 465652:tid 465835] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YjTzTqJoBC2Mw28-qxAAAum0"]
[Tue Jul 21 08:31:25.793405 2026] [log_config:warn] [pid 418108:tid 418288] (32)Broken pipe: [client 105.168.26.10:35506] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:25.793424 2026] [log_config:warn] [pid 418108:tid 418288] (32)Broken pipe: [client 105.168.26.10:35506] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:25.798181 2026] [core:error] [pid 465652:tid 465746] [remote 52.167.144.204:3522] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:31:25.798196 2026] [core:error] [pid 465652:tid 465746] [remote 52.167.144.204:3522] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:31:25.857112 2026] [security2:error] [pid 465652:tid 465786] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9YjTzTqJoBC2Mw28-qywAAAIk"]
[Tue Jul 21 08:31:25.984514 2026] [security2:error] [pid 465652:tid 465808] [client 187.125.243.197:62474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YjTzTqJoBC2Mw28-q0AAAAJ8"]
[Tue Jul 21 08:31:25.984987 2026] [security2:error] [pid 465652:tid 465808] [client 187.125.243.197:62474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YjTzTqJoBC2Mw28-q0AAAAJ8"]
[Tue Jul 21 08:31:26.141020 2026] [security2:error] [pid 465652:tid 465880] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9YjjzTqJoBC2Mw28-q0wAAAOc"]
[Tue Jul 21 08:31:26.436605 2026] [security2:error] [pid 465652:tid 465865] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9YjjzTqJoBC2Mw28-q4QAAANg"]
[Tue Jul 21 08:31:26.720919 2026] [security2:error] [pid 465652:tid 465794] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9YjjzTqJoBC2Mw28-q6wAAAJE"]
[Tue Jul 21 08:31:26.959498 2026] [security2:error] [pid 465652:tid 465771] [remote 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "printcom.com.br"] [uri "/wp-login.php"] [unique_id "al9YjjzTqJoBC2Mw28-q-AAAhXY"]
[Tue Jul 21 08:31:27.005302 2026] [security2:error] [pid 465652:tid 465822] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9YjzzTqJoBC2Mw28-q-gAAAK0"]
[Tue Jul 21 08:31:27.296239 2026] [security2:error] [pid 465652:tid 465880] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ildaaugustamonteiroa1782828152376.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9YjzzTqJoBC2Mw28-rBQAAAOc"]
[Tue Jul 21 08:31:27.298625 2026] [log_config:warn] [pid 462418:tid 462433] (32)Broken pipe: [remote 57.141.18.90:28744] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:27.298651 2026] [log_config:warn] [pid 462418:tid 462433] (32)Broken pipe: [remote 57.141.18.90:28744] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:27.309722 2026] [log_config:warn] [pid 462418:tid 462466] (32)Broken pipe: [remote 57.141.18.96:25486] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:27.309747 2026] [log_config:warn] [pid 462418:tid 462466] (32)Broken pipe: [remote 57.141.18.96:25486] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:27.316512 2026] [log_config:warn] [pid 462418:tid 462460] (32)Broken pipe: [remote 57.141.18.18:58194] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:27.316549 2026] [log_config:warn] [pid 462418:tid 462460] (32)Broken pipe: [remote 57.141.18.18:58194] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:27.379148 2026] [security2:error] [pid 465652:tid 465821] [client 20.197.195.24:57912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/gecko.php"] [unique_id "al9YjzzTqJoBC2Mw28-rBwAAAKw"]
[Tue Jul 21 08:31:27.471569 2026] [log_config:warn] [pid 462418:tid 462637] (32)Broken pipe: [client 69.160.24.14:59089] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:27.471587 2026] [log_config:warn] [pid 462418:tid 462637] (32)Broken pipe: [client 69.160.24.14:59089] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:27.542803 2026] [security2:error] [pid 465652:tid 465835] [client 223.181.60.88:1334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YjzzTqJoBC2Mw28-rEwAAALo"]
[Tue Jul 21 08:31:27.542933 2026] [security2:error] [pid 465652:tid 465835] [client 223.181.60.88:1334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YjzzTqJoBC2Mw28-rEwAAALo"]
[Tue Jul 21 08:31:28.142692 2026] [security2:error] [pid 465652:tid 465696] [remote 68.178.160.25:56582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9YkDzTqJoBC2Mw28-rJwAA9Cs"]
[Tue Jul 21 08:31:28.187950 2026] [security2:error] [pid 465652:tid 465838] [client 173.252.95.20:44420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9YkDzTqJoBC2Mw28-rKAAAAL0"]
[Tue Jul 21 08:31:28.736371 2026] [security2:error] [pid 465652:tid 465702] [remote 195.63.31.240:20317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9YkDzTqJoBC2Mw28-rOwAAmzE"]
[Tue Jul 21 08:31:28.819246 2026] [security2:error] [pid 465652:tid 465901] [client 128.127.105.184:58592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9YkDzTqJoBC2Mw28-rPAAAAPw"]
[Tue Jul 21 08:31:28.819434 2026] [security2:error] [pid 465652:tid 465901] [client 128.127.105.184:58592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9YkDzTqJoBC2Mw28-rPAAAAPw"]
[Tue Jul 21 08:31:29.004109 2026] [security2:error] [pid 465652:tid 465903] [client 173.252.95.27:64644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9YkDzTqJoBC2Mw28-rPQAAAP4"]
[Tue Jul 21 08:31:29.263101 2026] [security2:error] [pid 465652:tid 465827] [client 195.49.128.211:52276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YkTzTqJoBC2Mw28-rSgAAALI"]
[Tue Jul 21 08:31:29.263331 2026] [security2:error] [pid 465652:tid 465827] [client 195.49.128.211:52276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YkTzTqJoBC2Mw28-rSgAAALI"]
[Tue Jul 21 08:31:29.600122 2026] [security2:error] [pid 465652:tid 465867] [client 150.129.202.39:65353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YkTzTqJoBC2Mw28-rZAAAANo"]
[Tue Jul 21 08:31:29.600208 2026] [security2:error] [pid 465652:tid 465867] [client 150.129.202.39:65353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YkTzTqJoBC2Mw28-rZAAAANo"]
[Tue Jul 21 08:31:29.857647 2026] [security2:error] [pid 465652:tid 465722] [remote 110.37.104.77:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.104.37.110.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YkTzTqJoBC2Mw28-rcQAA4UU"]
[Tue Jul 21 08:31:29.857769 2026] [security2:error] [pid 465652:tid 465874] [client 110.37.104.77:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "academiausina.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YkTzTqJoBC2Mw28-rcQAA4UU"]
[Tue Jul 21 08:31:30.282723 2026] [log_config:warn] [pid 462418:tid 462475] (32)Broken pipe: [remote 57.141.18.67:35238] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:30.282747 2026] [log_config:warn] [pid 462418:tid 462475] (32)Broken pipe: [remote 57.141.18.67:35238] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:30.299224 2026] [security2:error] [pid 465652:tid 465820] [client 74.249.245.134:55547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/albin.php"] [unique_id "al9YkjzTqJoBC2Mw28-rfwAAAKs"]
[Tue Jul 21 08:31:30.362177 2026] [log_config:warn] [pid 462418:tid 462464] (32)Broken pipe: [remote 57.141.18.2:56504] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:30.362197 2026] [log_config:warn] [pid 462418:tid 462464] (32)Broken pipe: [remote 57.141.18.2:56504] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:30.409248 2026] [security2:error] [pid 465652:tid 465888] [client 49.144.66.253:30106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YkjzTqJoBC2Mw28-rjQAAAO8"]
[Tue Jul 21 08:31:30.409367 2026] [security2:error] [pid 465652:tid 465888] [client 49.144.66.253:30106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YkjzTqJoBC2Mw28-rjQAAAO8"]
[Tue Jul 21 08:31:30.529088 2026] [security2:error] [pid 465652:tid 465831] [client 20.197.192.193:65176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/x.php"] [unique_id "al9YkjzTqJoBC2Mw28-rmwAAALY"]
[Tue Jul 21 08:31:30.558310 2026] [security2:error] [pid 465652:tid 465815] [client 173.252.95.42:61916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9YkjzTqJoBC2Mw28-rnQAAAKY"]
[Tue Jul 21 08:31:30.618490 2026] [security2:error] [pid 465652:tid 465804] [client 117.213.202.34:58602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YkjzTqJoBC2Mw28-rowAAAJs"]
[Tue Jul 21 08:31:30.618622 2026] [security2:error] [pid 465652:tid 465804] [client 117.213.202.34:58602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YkjzTqJoBC2Mw28-rowAAAJs"]
[Tue Jul 21 08:31:30.858383 2026] [security2:error] [pid 465652:tid 465903] [client 74.7.175.141:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "trilhadodesenvolvimento.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9YkjzTqJoBC2Mw28-rtAAAAP4"]
[Tue Jul 21 08:31:30.860490 2026] [security2:error] [pid 465652:tid 465844] [client 74.7.175.141:40914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "trilhadodesenvolvimento.com.br"] [uri "/robots.txt"] [unique_id "al9YkjzTqJoBC2Mw28-rsgAAwwI"]
[Tue Jul 21 08:31:31.129151 2026] [security2:error] [pid 465652:tid 465836] [client 20.197.195.24:57931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/82.php"] [unique_id "al9YkzzTqJoBC2Mw28-rvQAAALs"]
[Tue Jul 21 08:31:31.333423 2026] [log_config:warn] [pid 462418:tid 462454] (32)Broken pipe: [remote 57.141.18.12:46282] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:31.333449 2026] [log_config:warn] [pid 462418:tid 462454] (32)Broken pipe: [remote 57.141.18.12:46282] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:31.335032 2026] [log_config:warn] [pid 462418:tid 462496] (32)Broken pipe: [remote 57.141.18.88:27592] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:31.335051 2026] [log_config:warn] [pid 462418:tid 462496] (32)Broken pipe: [remote 57.141.18.88:27592] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:31.555828 2026] [security2:error] [pid 465652:tid 465863] [client 20.197.192.193:65162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9YkzzTqJoBC2Mw28-ryAAAANY"]
[Tue Jul 21 08:31:31.724967 2026] [security2:error] [pid 465652:tid 465903] [client 89.238.167.134:44170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9YkzzTqJoBC2Mw28-r0gAAAP4"]
[Tue Jul 21 08:31:31.725062 2026] [security2:error] [pid 465652:tid 465903] [client 89.238.167.134:44170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9YkzzTqJoBC2Mw28-r0gAAAP4"]
[Tue Jul 21 08:31:31.728046 2026] [security2:error] [pid 465652:tid 465890] [client 20.197.192.193:46163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/ms-new.php"] [unique_id "al9YkzzTqJoBC2Mw28-r0wAAAPE"]
[Tue Jul 21 08:31:32.335278 2026] [security2:error] [pid 465652:tid 465801] [client 103.255.105.130:30527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YlDzTqJoBC2Mw28-r4gAAAJg"]
[Tue Jul 21 08:31:32.335542 2026] [security2:error] [pid 465652:tid 465801] [client 103.255.105.130:30527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YlDzTqJoBC2Mw28-r4gAAAJg"]
[Tue Jul 21 08:31:32.367235 2026] [security2:error] [pid 465652:tid 465831] [client 20.197.192.193:65169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9YlDzTqJoBC2Mw28-r4wAAALY"]
[Tue Jul 21 08:31:32.746293 2026] [security2:error] [pid 465652:tid 465830] [client 87.199.199.98:55368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "madeireirapiske.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9YlDzTqJoBC2Mw28-r6gAAALU"], referer: https://madeireirapiske.com.br/2017/07/21/primeiros-passos-com-o-wordpress/
[Tue Jul 21 08:31:32.746384 2026] [security2:error] [pid 465652:tid 465830] [client 87.199.199.98:55368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "madeireirapiske.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9YlDzTqJoBC2Mw28-r6gAAALU"], referer: https://madeireirapiske.com.br/2017/07/21/primeiros-passos-com-o-wordpress/
[Tue Jul 21 08:31:33.264566 2026] [security2:error] [pid 465652:tid 465784] [client 20.197.192.193:65204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9YlTzTqJoBC2Mw28-r9AAAAIc"]
[Tue Jul 21 08:31:33.274585 2026] [log_config:warn] [pid 462418:tid 462486] (32)Broken pipe: [remote 57.141.18.96:25500] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:33.274607 2026] [log_config:warn] [pid 462418:tid 462486] (32)Broken pipe: [remote 57.141.18.96:25500] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:33.275114 2026] [log_config:warn] [pid 462418:tid 462509] (32)Broken pipe: [remote 57.141.18.84:63712] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:33.275133 2026] [log_config:warn] [pid 462418:tid 462509] (32)Broken pipe: [remote 57.141.18.84:63712] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:33.287761 2026] [log_config:warn] [pid 418108:tid 418115] (32)Broken pipe: [remote 57.141.18.112:59854] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:33.287785 2026] [log_config:warn] [pid 418108:tid 418115] (32)Broken pipe: [remote 57.141.18.112:59854] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:33.377249 2026] [security2:error] [pid 465652:tid 465909] [client 20.197.192.193:6003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/track.php"] [unique_id "al9YlTzTqJoBC2Mw28-r-wAAAQQ"]
[Tue Jul 21 08:31:33.381713 2026] [security2:error] [pid 465652:tid 465714] [remote 207.46.13.111:32109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "robertinhoimoveis.com.br"] [uri "/video.php/casino895/que-hora-que-o-cruzeiro-joga/index.html"] [unique_id "al9YlTzTqJoBC2Mw28-r_AAAij0"]
[Tue Jul 21 08:31:33.391866 2026] [security2:error] [pid 465652:tid 465863] [client 122.176.100.127:50164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YlTzTqJoBC2Mw28-r_QAAANY"]
[Tue Jul 21 08:31:33.391942 2026] [security2:error] [pid 465652:tid 465863] [client 122.176.100.127:50164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YlTzTqJoBC2Mw28-r_QAAANY"]
[Tue Jul 21 08:31:33.717601 2026] [security2:error] [pid 465652:tid 465844] [client 195.49.128.211:60590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YlTzTqJoBC2Mw28-sBQAAAMM"]
[Tue Jul 21 08:31:33.717716 2026] [security2:error] [pid 465652:tid 465844] [client 195.49.128.211:60590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YlTzTqJoBC2Mw28-sBQAAAMM"]
[Tue Jul 21 08:31:33.733007 2026] [security2:error] [pid 465652:tid 465905] [client 152.59.34.51:54895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YlTzTqJoBC2Mw28-sBwAAAQA"]
[Tue Jul 21 08:31:33.733091 2026] [security2:error] [pid 465652:tid 465905] [client 152.59.34.51:54895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YlTzTqJoBC2Mw28-sBwAAAQA"]
[Tue Jul 21 08:31:33.950822 2026] [security2:error] [pid 465652:tid 465899] [client 20.197.195.24:57964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9YlTzTqJoBC2Mw28-sDAAAAPo"]
[Tue Jul 21 08:31:33.969955 2026] [security2:error] [pid 465652:tid 465858] [client 103.151.46.103:58786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YlTzTqJoBC2Mw28-sDQAAANE"]
[Tue Jul 21 08:31:33.970066 2026] [security2:error] [pid 465652:tid 465858] [client 103.151.46.103:58786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YlTzTqJoBC2Mw28-sDQAAANE"]
[Tue Jul 21 08:31:34.206641 2026] [security2:error] [pid 465652:tid 465712] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YljzTqJoBC2Mw28-sEgAA9Ts"]
[Tue Jul 21 08:31:34.206775 2026] [security2:error] [pid 465652:tid 465894] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YljzTqJoBC2Mw28-sEgAA9Ts"]
[Tue Jul 21 08:31:34.277509 2026] [security2:error] [pid 465652:tid 465796] [client 109.248.148.246:43582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9YljzTqJoBC2Mw28-sFgAAAJM"]
[Tue Jul 21 08:31:34.277679 2026] [security2:error] [pid 465652:tid 465796] [client 109.248.148.246:43582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9YljzTqJoBC2Mw28-sFgAAAJM"]
[Tue Jul 21 08:31:34.632650 2026] [autoindex:error] [pid 465652:tid 465890] [client 100.50.152.193:35287] AH01276: Cannot serve directory /home2/estru297/home2/estru297/public_html/os/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:31:34.894481 2026] [log_config:warn] [pid 462418:tid 462629] (32)Broken pipe: [client 125.167.57.59:1365] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:34.894497 2026] [log_config:warn] [pid 462418:tid 462629] (32)Broken pipe: [client 125.167.57.59:1365] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:34.937476 2026] [http2:info] [pid 466512:tid 466512] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 08:31:34.991405 2026] [security2:error] [pid 466512:tid 466643] [client 89.238.167.134:47598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9YliKGokixMSfKDOfPFgAAAhU"]
[Tue Jul 21 08:31:34.991531 2026] [security2:error] [pid 466512:tid 466643] [client 89.238.167.134:47598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9YliKGokixMSfKDOfPFgAAAhU"]
[Tue Jul 21 08:31:35.002192 2026] [security2:error] [pid 465652:tid 465832] [client 173.252.95.24:37558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9YlzzTqJoBC2Mw28-sbAAAALc"]
[Tue Jul 21 08:31:35.159245 2026] [security2:error] [pid 465652:tid 465884] [client 202.179.75.202:43990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YlzzTqJoBC2Mw28-sbwAAAOs"]
[Tue Jul 21 08:31:35.159357 2026] [security2:error] [pid 465652:tid 465884] [client 202.179.75.202:43990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YlzzTqJoBC2Mw28-sbwAAAOs"]
[Tue Jul 21 08:31:35.271519 2026] [security2:error] [pid 465652:tid 465792] [client 213.152.186.163:47796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9YlzzTqJoBC2Mw28-sdQAAAI8"]
[Tue Jul 21 08:31:35.271636 2026] [security2:error] [pid 465652:tid 465792] [client 213.152.186.163:47796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9YlzzTqJoBC2Mw28-sdQAAAI8"]
[Tue Jul 21 08:31:35.306970 2026] [log_config:warn] [pid 462418:tid 462483] (32)Broken pipe: [remote 57.141.18.93:38882] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:35.306992 2026] [log_config:warn] [pid 462418:tid 462483] (32)Broken pipe: [remote 57.141.18.93:38882] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:35.440097 2026] [security2:error] [pid 466512:tid 466650] [client 20.197.192.193:43802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/ee.php"] [unique_id "al9YlyKGokixMSfKDOfPGQAAAhw"]
[Tue Jul 21 08:31:35.448179 2026] [log_config:warn] [pid 462418:tid 462611] (32)Broken pipe: [client 51.89.224.108:42594] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:35.448208 2026] [log_config:warn] [pid 462418:tid 462611] (32)Broken pipe: [client 51.89.224.108:42594] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:35.716857 2026] [security2:error] [pid 466512:tid 466651] [client 14.245.224.124:52724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YlyKGokixMSfKDOfPHQAAAh0"]
[Tue Jul 21 08:31:35.716976 2026] [security2:error] [pid 466512:tid 466651] [client 14.245.224.124:52724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YlyKGokixMSfKDOfPHQAAAh0"]
[Tue Jul 21 08:31:35.801255 2026] [security2:error] [pid 465652:tid 465895] [client 216.73.161.177:25835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9YlzzTqJoBC2Mw28-sfwAAAPY"]
[Tue Jul 21 08:31:35.931353 2026] [security2:error] [pid 465652:tid 465891] [client 20.197.195.24:3892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9YlzzTqJoBC2Mw28-snAAAAPI"]
[Tue Jul 21 08:31:36.033523 2026] [security2:error] [pid 466512:tid 466663] [client 185.213.175.37:23546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "beautyline.com.br"] [uri "/"] [unique_id "al9YmCKGokixMSfKDOfPJwAAAik"]
[Tue Jul 21 08:31:36.033639 2026] [security2:error] [pid 466512:tid 466663] [client 185.213.175.37:23546] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "beautyline.com.br"] [uri "/"] [unique_id "al9YmCKGokixMSfKDOfPJwAAAik"]
[Tue Jul 21 08:31:36.217472 2026] [security2:error] [pid 466512:tid 466678] [client 20.197.195.24:16013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9YmCKGokixMSfKDOfPKAAAAjg"]
[Tue Jul 21 08:31:36.262646 2026] [log_config:warn] [pid 462418:tid 462457] (32)Broken pipe: [remote 57.141.18.1:20242] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:36.262671 2026] [log_config:warn] [pid 462418:tid 462457] (32)Broken pipe: [remote 57.141.18.1:20242] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:36.277337 2026] [security2:error] [pid 465652:tid 465686] [remote 202.51.202.242:58580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9YmDzTqJoBC2Mw28-sswAAlCE"]
[Tue Jul 21 08:31:36.287502 2026] [security2:error] [pid 465652:tid 465769] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YmDzTqJoBC2Mw28-stQAAj3Q"]
[Tue Jul 21 08:31:36.287880 2026] [security2:error] [pid 465652:tid 465792] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YmDzTqJoBC2Mw28-stQAAj3Q"]
[Tue Jul 21 08:31:36.387480 2026] [security2:error] [pid 465652:tid 465872] [client 20.197.195.24:16028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/media.php"] [unique_id "al9YmDzTqJoBC2Mw28-sugAAAN8"]
[Tue Jul 21 08:31:36.497083 2026] [security2:error] [pid 465652:tid 465854] [client 20.197.195.24:3909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/images.php"] [unique_id "al9YmDzTqJoBC2Mw28-svQAAAM0"]
[Tue Jul 21 08:31:36.519842 2026] [security2:error] [pid 465652:tid 465836] [client 187.125.243.197:62974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YmDzTqJoBC2Mw28-svwAAALs"]
[Tue Jul 21 08:31:36.519940 2026] [security2:error] [pid 465652:tid 465836] [client 187.125.243.197:62974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YmDzTqJoBC2Mw28-svwAAALs"]
[Tue Jul 21 08:31:36.536850 2026] [security2:error] [pid 466512:tid 466696] [client 20.197.192.193:5983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/2352356666.php"] [unique_id "al9YmCKGokixMSfKDOfPNQAAAko"]
[Tue Jul 21 08:31:36.640542 2026] [security2:error] [pid 465652:tid 465905] [client 173.239.211.137:37237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9YlzzTqJoBC2Mw28-sgAAAAQA"]
[Tue Jul 21 08:31:36.798582 2026] [security2:error] [pid 465652:tid 465803] [client 216.73.161.165:62221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9YlzzTqJoBC2Mw28-sfgAAAJo"]
[Tue Jul 21 08:31:36.989556 2026] [security2:error] [pid 465652:tid 465848] [client 5.31.193.106:58567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YlzzTqJoBC2Mw28-shQAAAMc"]
[Tue Jul 21 08:31:36.989684 2026] [security2:error] [pid 465652:tid 465848] [client 5.31.193.106:58567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YlzzTqJoBC2Mw28-shQAAAMc"]
[Tue Jul 21 08:31:37.034357 2026] [security2:error] [pid 466512:tid 466715] [client 20.197.195.24:16012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/gecko.php"] [unique_id "al9YmSKGokixMSfKDOfPPQAAAl0"]
[Tue Jul 21 08:31:37.035380 2026] [security2:error] [pid 466512:tid 466717] [client 89.238.167.134:44172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9YmSKGokixMSfKDOfPPgAAAl8"]
[Tue Jul 21 08:31:37.035449 2026] [security2:error] [pid 466512:tid 466717] [client 89.238.167.134:44172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9YmSKGokixMSfKDOfPPgAAAl8"]
[Tue Jul 21 08:31:37.314702 2026] [log_config:warn] [pid 418108:tid 418153] (32)Broken pipe: [remote 57.141.18.69:26720] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:37.314725 2026] [log_config:warn] [pid 418108:tid 418153] (32)Broken pipe: [remote 57.141.18.69:26720] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:37.362145 2026] [log_config:warn] [pid 462418:tid 462530] (32)Broken pipe: [remote 57.141.18.85:41784] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:37.362168 2026] [log_config:warn] [pid 462418:tid 462530] (32)Broken pipe: [remote 57.141.18.85:41784] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:37.368258 2026] [log_config:warn] [pid 462418:tid 462521] (32)Broken pipe: [remote 57.141.18.22:31976] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:37.368279 2026] [log_config:warn] [pid 462418:tid 462521] (32)Broken pipe: [remote 57.141.18.22:31976] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:37.476104 2026] [security2:error] [pid 466512:tid 466732] [client 20.197.195.24:18694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/adminner.php"] [unique_id "al9YmSKGokixMSfKDOfPSAAAAm4"]
[Tue Jul 21 08:31:37.905775 2026] [security2:error] [pid 466512:tid 466745] [client 20.197.195.24:17035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9YmSKGokixMSfKDOfPTAAAAns"]
[Tue Jul 21 08:31:38.117525 2026] [security2:error] [pid 466512:tid 466761] [client 20.197.195.24:17064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/k.php"] [unique_id "al9YmiKGokixMSfKDOfPUwAAAos"]
[Tue Jul 21 08:31:38.174054 2026] [security2:error] [pid 465652:tid 465904] [client 61.1.167.83:54328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YmjzTqJoBC2Mw28-s9AAAAP8"]
[Tue Jul 21 08:31:38.174259 2026] [security2:error] [pid 465652:tid 465904] [client 61.1.167.83:54328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YmjzTqJoBC2Mw28-s9AAAAP8"]
[Tue Jul 21 08:31:38.290494 2026] [log_config:warn] [pid 462418:tid 462469] (32)Broken pipe: [remote 57.141.18.86:32510] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:38.290519 2026] [log_config:warn] [pid 462418:tid 462469] (32)Broken pipe: [remote 57.141.18.86:32510] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:38.317800 2026] [log_config:warn] [pid 418108:tid 418199] (32)Broken pipe: [remote 57.141.18.33:24778] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:38.317831 2026] [log_config:warn] [pid 418108:tid 418199] (32)Broken pipe: [remote 57.141.18.33:24778] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:38.325155 2026] [security2:error] [pid 465652:tid 465796] [client 20.197.195.24:57896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/blurbs.php"] [unique_id "al9YmjzTqJoBC2Mw28-s9QAAAJM"]
[Tue Jul 21 08:31:38.347773 2026] [log_config:warn] [pid 418108:tid 418150] (32)Broken pipe: [remote 57.141.18.18:36426] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:38.347807 2026] [log_config:warn] [pid 418108:tid 418150] (32)Broken pipe: [remote 57.141.18.18:36426] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:38.395508 2026] [security2:error] [pid 466512:tid 466765] [client 20.197.192.193:6006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/pn.php"] [unique_id "al9YmiKGokixMSfKDOfPVAAAAo8"]
[Tue Jul 21 08:31:38.758735 2026] [security2:error] [pid 465652:tid 465870] [client 20.197.195.24:17041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/bajah.php"] [unique_id "al9YmjzTqJoBC2Mw28-s_AAAAN0"]
[Tue Jul 21 08:31:39.217948 2026] [security2:error] [pid 465652:tid 465835] [client 20.197.195.24:15705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/82.php"] [unique_id "al9YmzzTqJoBC2Mw28-tBAAAALo"]
[Tue Jul 21 08:31:39.278446 2026] [security2:error] [pid 466512:tid 466663] [client 20.197.192.193:43808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/blue.php"] [unique_id "al9YmyKGokixMSfKDOfPZQAAAik"]
[Tue Jul 21 08:31:39.285663 2026] [log_config:warn] [pid 418108:tid 418181] (32)Broken pipe: [remote 57.141.18.5:34632] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:39.285685 2026] [log_config:warn] [pid 418108:tid 418181] (32)Broken pipe: [remote 57.141.18.5:34632] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:39.289386 2026] [log_config:warn] [pid 462418:tid 462485] (32)Broken pipe: [remote 57.141.18.91:36068] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:39.289408 2026] [log_config:warn] [pid 462418:tid 462485] (32)Broken pipe: [remote 57.141.18.91:36068] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:39.355854 2026] [log_config:warn] [pid 462418:tid 462504] (32)Broken pipe: [remote 57.141.18.64:35238] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:39.355878 2026] [log_config:warn] [pid 462418:tid 462504] (32)Broken pipe: [remote 57.141.18.64:35238] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:39.831476 2026] [security2:error] [pid 465652:tid 465840] [client 20.197.195.24:17059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/a.php"] [unique_id "al9YmzzTqJoBC2Mw28-tDwAAAL8"]
[Tue Jul 21 08:31:39.952771 2026] [security2:error] [pid 466512:tid 466683] [client 195.49.128.211:52893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YmyKGokixMSfKDOfPagAAAj0"]
[Tue Jul 21 08:31:39.952916 2026] [security2:error] [pid 466512:tid 466683] [client 195.49.128.211:52893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YmyKGokixMSfKDOfPagAAAj0"]
[Tue Jul 21 08:31:39.997809 2026] [security2:error] [pid 465652:tid 465801] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/config/config.php.bak"] [unique_id "al9YmzzTqJoBC2Mw28-tEQAAAJg"]
[Tue Jul 21 08:31:40.290121 2026] [security2:error] [pid 465652:tid 465812] [client 150.129.202.39:65175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YnDzTqJoBC2Mw28-tHwAAAKM"]
[Tue Jul 21 08:31:40.290322 2026] [security2:error] [pid 465652:tid 465812] [client 150.129.202.39:65175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YnDzTqJoBC2Mw28-tHwAAAKM"]
[Tue Jul 21 08:31:40.297856 2026] [security2:error] [pid 465652:tid 465661] [remote 216.73.217.5:50247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.vanessaglowhair.com"] [uri "/xmlrpc.php"] [unique_id "al9YmjzTqJoBC2Mw28-s_wAAsAg"]
[Tue Jul 21 08:31:40.298399 2026] [log_config:warn] [pid 462418:tid 462427] (32)Broken pipe: [remote 57.141.18.80:64512] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:40.298415 2026] [log_config:warn] [pid 462418:tid 462427] (32)Broken pipe: [remote 57.141.18.80:64512] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:40.628065 2026] [security2:error] [pid 466512:tid 466707] [client 20.197.195.24:3885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/admin.php"] [unique_id "al9YnCKGokixMSfKDOfPcAAAAlU"]
[Tue Jul 21 08:31:40.657911 2026] [security2:error] [pid 465652:tid 465754] [remote 45.117.83.212:39312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wp-login.php"] [unique_id "al9YnDzTqJoBC2Mw28-tLgAAhmU"]
[Tue Jul 21 08:31:40.844939 2026] [security2:error] [pid 465652:tid 465877] [client 20.197.192.193:65170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/wp-signup.php"] [unique_id "al9YnDzTqJoBC2Mw28-tMgAAAOQ"]
[Tue Jul 21 08:31:40.931804 2026] [security2:error] [pid 465652:tid 465843] [client 20.206.105.145:25473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9YnDzTqJoBC2Mw28-tNQAAAMI"]
[Tue Jul 21 08:31:41.150427 2026] [security2:error] [pid 466512:tid 466714] [client 20.197.192.193:46203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9YnSKGokixMSfKDOfPdgAAAlw"]
[Tue Jul 21 08:31:41.192791 2026] [security2:error] [pid 465652:tid 465840] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/config/config.php.old"] [unique_id "al9YnTzTqJoBC2Mw28-tPAAAAL8"]
[Tue Jul 21 08:31:41.259681 2026] [log_config:warn] [pid 418108:tid 418159] (32)Broken pipe: [remote 57.141.18.104:26748] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:41.259704 2026] [log_config:warn] [pid 418108:tid 418159] (32)Broken pipe: [remote 57.141.18.104:26748] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:41.290579 2026] [log_config:warn] [pid 462418:tid 462436] (32)Broken pipe: [remote 57.141.18.23:59340] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:41.290607 2026] [log_config:warn] [pid 462418:tid 462436] (32)Broken pipe: [remote 57.141.18.23:59340] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:41.433476 2026] [security2:error] [pid 465652:tid 465830] [client 117.213.202.34:59211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YnTzTqJoBC2Mw28-tQQAAALU"]
[Tue Jul 21 08:31:41.433649 2026] [security2:error] [pid 465652:tid 465830] [client 117.213.202.34:59211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YnTzTqJoBC2Mw28-tQQAAALU"]
[Tue Jul 21 08:31:41.505759 2026] [security2:error] [pid 465652:tid 465851] [client 20.197.195.24:57904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/edit.php"] [unique_id "al9YnTzTqJoBC2Mw28-tQgAAAMo"]
[Tue Jul 21 08:31:41.705788 2026] [security2:error] [pid 465652:tid 465854] [client 49.144.66.253:32660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YnTzTqJoBC2Mw28-tTgAAAM0"]
[Tue Jul 21 08:31:41.705929 2026] [security2:error] [pid 465652:tid 465854] [client 49.144.66.253:32660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YnTzTqJoBC2Mw28-tTgAAAM0"]
[Tue Jul 21 08:31:41.818894 2026] [security2:error] [pid 466512:tid 466733] [client 20.197.195.24:3955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/adminner.php"] [unique_id "al9YnSKGokixMSfKDOfPewAAAm8"]
[Tue Jul 21 08:31:41.836302 2026] [security2:error] [pid 465652:tid 465809] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/config/config.php.save"] [unique_id "al9YnTzTqJoBC2Mw28-tVAAAAKA"]
[Tue Jul 21 08:31:42.219233 2026] [security2:error] [pid 465652:tid 465867] [client 20.197.192.193:65200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/wander.php"] [unique_id "al9YnjzTqJoBC2Mw28-tXwAAANo"]
[Tue Jul 21 08:31:42.287103 2026] [log_config:warn] [pid 418108:tid 418129] (32)Broken pipe: [remote 43.135.147.64:48830] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log, referer: https://arielson.com.br/shop/?filtering=1&filter_product_cat=283,129
[Tue Jul 21 08:31:42.287127 2026] [log_config:warn] [pid 418108:tid 418129] (32)Broken pipe: [remote 43.135.147.64:48830] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log, referer: https://arielson.com.br/shop/?filtering=1&filter_product_cat=283,129
[Tue Jul 21 08:31:42.296476 2026] [log_config:warn] [pid 462418:tid 462465] (32)Broken pipe: [remote 57.141.18.88:35792] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:42.296501 2026] [log_config:warn] [pid 462418:tid 462465] (32)Broken pipe: [remote 57.141.18.88:35792] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:42.343009 2026] [log_config:warn] [pid 462418:tid 462456] (32)Broken pipe: [remote 57.141.18.30:55434] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:42.343047 2026] [log_config:warn] [pid 462418:tid 462456] (32)Broken pipe: [remote 57.141.18.30:55434] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:42.512130 2026] [security2:error] [pid 466512:tid 466750] [client 20.197.195.24:3854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/admin.php"] [unique_id "al9YniKGokixMSfKDOfPggAAAoA"]
[Tue Jul 21 08:31:42.608230 2026] [security2:error] [pid 465652:tid 465783] [client 223.181.60.88:13920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YnjzTqJoBC2Mw28-tZAAAAIY"]
[Tue Jul 21 08:31:42.608422 2026] [security2:error] [pid 465652:tid 465783] [client 223.181.60.88:13920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YnjzTqJoBC2Mw28-tZAAAAIY"]
[Tue Jul 21 08:31:42.691121 2026] [security2:error] [pid 465652:tid 465861] [client 20.197.195.24:57981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/hosty.php"] [unique_id "al9YnjzTqJoBC2Mw28-tZwAAANQ"]
[Tue Jul 21 08:31:42.779916 2026] [security2:error] [pid 465652:tid 465871] [client 20.197.192.193:43813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/csa.php"] [unique_id "al9YnjzTqJoBC2Mw28-tbQAAAN4"]
[Tue Jul 21 08:31:42.872299 2026] [security2:error] [pid 465652:tid 465821] [client 111.93.58.162:46816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YnjzTqJoBC2Mw28-tcwAAAKw"]
[Tue Jul 21 08:31:42.872453 2026] [security2:error] [pid 465652:tid 465821] [client 111.93.58.162:46816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YnjzTqJoBC2Mw28-tcwAAAKw"]
[Tue Jul 21 08:31:42.927958 2026] [security2:error] [pid 465652:tid 465889] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/config/config.php.orig"] [unique_id "al9YnjzTqJoBC2Mw28-tdAAAAPA"]
[Tue Jul 21 08:31:42.974628 2026] [security2:error] [pid 465652:tid 465787] [client 20.197.192.193:43790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/jga.php"] [unique_id "al9YnjzTqJoBC2Mw28-tdQAAAIo"]
[Tue Jul 21 08:31:43.442933 2026] [security2:error] [pid 465652:tid 465828] [client 20.197.195.24:6272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/k.php"] [unique_id "al9YnzzTqJoBC2Mw28-tgQAAALM"]
[Tue Jul 21 08:31:43.490732 2026] [security2:error] [pid 465652:tid 465872] [client 20.197.195.24:57951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/k.php"] [unique_id "al9YnzzTqJoBC2Mw28-thAAAAN8"]
[Tue Jul 21 08:31:43.855230 2026] [security2:error] [pid 466512:tid 466729] [client 122.176.100.127:50665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YnyKGokixMSfKDOfPkQAAAms"]
[Tue Jul 21 08:31:43.855420 2026] [security2:error] [pid 466512:tid 466729] [client 122.176.100.127:50665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YnyKGokixMSfKDOfPkQAAAms"]
[Tue Jul 21 08:31:43.901687 2026] [autoindex:error] [pid 466512:tid 466664] [client 43.157.170.13:35058] AH01276: Cannot serve directory /home4/bcaccj52/accjbc.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:31:43.945563 2026] [security2:error] [pid 466512:tid 466668] [client 20.206.105.145:25588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9YnyKGokixMSfKDOfPlwAAAi4"]
[Tue Jul 21 08:31:44.269529 2026] [log_config:warn] [pid 462418:tid 462541] (32)Broken pipe: [remote 74.7.227.54:34204] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log, referer: https://arielson.com.br/coursos/?duration=medium%2CextraLong&filter_course-category=397,453,115&filter_course-tag=130%2C455%2C454%2C249%2C134&filtering=1&level=all_levels&orderby=course_title_az
[Tue Jul 21 08:31:44.269553 2026] [log_config:warn] [pid 462418:tid 462541] (32)Broken pipe: [remote 74.7.227.54:34204] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log, referer: https://arielson.com.br/coursos/?duration=medium%2CextraLong&filter_course-category=397,453,115&filter_course-tag=130%2C455%2C454%2C249%2C134&filtering=1&level=all_levels&orderby=course_title_az
[Tue Jul 21 08:31:44.320493 2026] [security2:error] [pid 465652:tid 465904] [client 195.49.128.211:61182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YoDzTqJoBC2Mw28-tmAAAAP8"]
[Tue Jul 21 08:31:44.320675 2026] [security2:error] [pid 465652:tid 465904] [client 195.49.128.211:61182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YoDzTqJoBC2Mw28-tmAAAAP8"]
[Tue Jul 21 08:31:44.324996 2026] [log_config:warn] [pid 418108:tid 418195] (32)Broken pipe: [remote 57.141.18.12:20300] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:44.325021 2026] [log_config:warn] [pid 418108:tid 418195] (32)Broken pipe: [remote 57.141.18.12:20300] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:44.374306 2026] [security2:error] [pid 466512:tid 466660] [client 20.197.195.24:57872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/aaa.php"] [unique_id "al9YoCKGokixMSfKDOfPnQAAAiY"]
[Tue Jul 21 08:31:44.375793 2026] [security2:error] [pid 466512:tid 466673] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/config/config.php.txt"] [unique_id "al9YoCKGokixMSfKDOfPngAAAjM"]
[Tue Jul 21 08:31:44.621969 2026] [log_config:warn] [pid 419508:tid 419731] (32)Broken pipe: [client 200.95.220.226:22143] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:44.621993 2026] [log_config:warn] [pid 419508:tid 419731] (32)Broken pipe: [client 200.95.220.226:22143] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:44.628727 2026] [security2:error] [pid 465652:tid 465792] [client 103.151.46.103:59289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YoDzTqJoBC2Mw28-tmwAAAI8"]
[Tue Jul 21 08:31:44.628886 2026] [security2:error] [pid 465652:tid 465792] [client 103.151.46.103:59289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YoDzTqJoBC2Mw28-tmwAAAI8"]
[Tue Jul 21 08:31:44.672803 2026] [security2:error] [pid 466512:tid 466693] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YoCKGokixMSfKDOfPoQAAAkc"]
[Tue Jul 21 08:31:44.712739 2026] [security2:error] [pid 466512:tid 466694] [client 20.197.195.24:3867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/blurbs.php"] [unique_id "al9YoCKGokixMSfKDOfPogAAAkg"]
[Tue Jul 21 08:31:44.813126 2026] [security2:error] [pid 465652:tid 465842] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/nextcloud/config/config.php.bak"] [unique_id "al9YoDzTqJoBC2Mw28-tpgAAAME"]
[Tue Jul 21 08:31:44.837170 2026] [security2:error] [pid 465652:tid 465703] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YoDzTqJoBC2Mw28-tqAAA7jI"]
[Tue Jul 21 08:31:44.837328 2026] [security2:error] [pid 465652:tid 465887] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YoDzTqJoBC2Mw28-tqAAA7jI"]
[Tue Jul 21 08:31:45.086260 2026] [security2:error] [pid 465652:tid 465855] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9YoTzTqJoBC2Mw28-tsgAAAM4"]
[Tue Jul 21 08:31:45.275688 2026] [log_config:warn] [pid 418108:tid 418136] (32)Broken pipe: [remote 57.141.18.43:27058] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:45.275714 2026] [log_config:warn] [pid 418108:tid 418136] (32)Broken pipe: [remote 57.141.18.43:27058] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:45.303011 2026] [log_config:warn] [pid 462418:tid 462421] (32)Broken pipe: [remote 57.141.18.100:41754] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:45.303036 2026] [log_config:warn] [pid 462418:tid 462421] (32)Broken pipe: [remote 57.141.18.100:41754] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:45.360740 2026] [security2:error] [pid 466512:tid 466713] [client 20.197.192.193:65159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/min.php"] [unique_id "al9YoSKGokixMSfKDOfPrgAAAls"]
[Tue Jul 21 08:31:45.501180 2026] [security2:error] [pid 465652:tid 465801] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9YoTzTqJoBC2Mw28-tuwAAAJg"]
[Tue Jul 21 08:31:45.757034 2026] [security2:error] [pid 465652:tid 465821] [client 20.197.195.24:17056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/file5.php"] [unique_id "al9YoTzTqJoBC2Mw28-tvwAAAKw"]
[Tue Jul 21 08:31:45.825559 2026] [security2:error] [pid 466512:tid 466723] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/cloud/config/config.php.bak"] [unique_id "al9YoSKGokixMSfKDOfPsAAAAmU"]
[Tue Jul 21 08:31:45.869678 2026] [security2:error] [pid 466512:tid 466687] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9YoSKGokixMSfKDOfPsgAAAkE"]
[Tue Jul 21 08:31:45.922809 2026] [core:error] [pid 465652:tid 465731] [remote 198.235.24.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpanel.produto-express.com/
[Tue Jul 21 08:31:45.922841 2026] [core:error] [pid 465652:tid 465731] [remote 198.235.24.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpanel.produto-express.com/
[Tue Jul 21 08:31:45.993362 2026] [security2:error] [pid 465652:tid 465832] [client 14.245.224.124:53191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YoTzTqJoBC2Mw28-tywAAALc"]
[Tue Jul 21 08:31:45.993466 2026] [security2:error] [pid 465652:tid 465832] [client 14.245.224.124:53191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YoTzTqJoBC2Mw28-tywAAALc"]
[Tue Jul 21 08:31:46.016645 2026] [security2:error] [pid 465652:tid 465856] [client 202.179.75.202:37604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YojzTqJoBC2Mw28-tzAAAAM8"]
[Tue Jul 21 08:31:46.016747 2026] [security2:error] [pid 465652:tid 465856] [client 202.179.75.202:37604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YojzTqJoBC2Mw28-tzAAAAM8"]
[Tue Jul 21 08:31:46.086097 2026] [security2:error] [pid 465652:tid 465878] [client 20.206.105.145:25539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/media.php"] [unique_id "al9YojzTqJoBC2Mw28-tzQAAAOU"]
[Tue Jul 21 08:31:46.195252 2026] [security2:error] [pid 466512:tid 466731] [client 20.197.195.24:3844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/bajah.php"] [unique_id "al9YoiKGokixMSfKDOfPtAAAAm0"]
[Tue Jul 21 08:31:46.284843 2026] [log_config:warn] [pid 418108:tid 418132] (32)Broken pipe: [remote 57.141.18.10:22980] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:46.284868 2026] [log_config:warn] [pid 418108:tid 418132] (32)Broken pipe: [remote 57.141.18.10:22980] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:46.292486 2026] [security2:error] [pid 465652:tid 465848] [client 152.59.34.51:55372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YojzTqJoBC2Mw28-t1AAAAMc"]
[Tue Jul 21 08:31:46.292657 2026] [security2:error] [pid 465652:tid 465848] [client 152.59.34.51:55372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YojzTqJoBC2Mw28-t1AAAAMc"]
[Tue Jul 21 08:31:46.316544 2026] [log_config:warn] [pid 462418:tid 462455] (32)Broken pipe: [remote 57.141.18.54:34784] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:46.316569 2026] [log_config:warn] [pid 462418:tid 462455] (32)Broken pipe: [remote 57.141.18.54:34784] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:46.334973 2026] [log_config:warn] [pid 462418:tid 462476] (32)Broken pipe: [remote 57.141.18.75:50300] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:46.334997 2026] [log_config:warn] [pid 462418:tid 462476] (32)Broken pipe: [remote 57.141.18.75:50300] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:46.347660 2026] [security2:error] [pid 465652:tid 465861] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9YojzTqJoBC2Mw28-t1gAAANQ"]
[Tue Jul 21 08:31:46.600790 2026] [security2:error] [pid 465652:tid 465863] [client 173.252.95.35:34574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9YojzTqJoBC2Mw28-t2QAAANY"]
[Tue Jul 21 08:31:46.772500 2026] [security2:error] [pid 465652:tid 465908] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9YojzTqJoBC2Mw28-t4gAAAQM"]
[Tue Jul 21 08:31:46.858372 2026] [security2:error] [pid 465652:tid 465754] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YojzTqJoBC2Mw28-t7QAAvmU"]
[Tue Jul 21 08:31:46.858541 2026] [security2:error] [pid 465652:tid 465839] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YojzTqJoBC2Mw28-t7QAAvmU"]
[Tue Jul 21 08:31:46.976161 2026] [security2:error] [pid 466512:tid 466750] [client 187.125.243.197:63476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YoiKGokixMSfKDOfPvQAAAoA"]
[Tue Jul 21 08:31:46.976323 2026] [security2:error] [pid 466512:tid 466750] [client 187.125.243.197:63476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YoiKGokixMSfKDOfPvQAAAoA"]
[Tue Jul 21 08:31:46.979347 2026] [security2:error] [pid 465652:tid 465842] [client 20.197.195.24:17068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/222.php"] [unique_id "al9YojzTqJoBC2Mw28-t8QAAAME"]
[Tue Jul 21 08:31:47.201706 2026] [security2:error] [pid 465652:tid 465848] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9YozzTqJoBC2Mw28-t8wAAAMc"]
[Tue Jul 21 08:31:47.271523 2026] [security2:error] [pid 465652:tid 465814] [client 20.206.105.145:25555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/images.php"] [unique_id "al9YozzTqJoBC2Mw28-t9gAAAKU"]
[Tue Jul 21 08:31:47.408777 2026] [security2:error] [pid 466512:tid 466758] [client 20.197.195.24:3894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/a.php"] [unique_id "al9YoyKGokixMSfKDOfPygAAAog"]
[Tue Jul 21 08:31:47.627632 2026] [security2:error] [pid 466512:tid 466664] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9YoyKGokixMSfKDOfP0AAAAio"]
[Tue Jul 21 08:31:47.933782 2026] [security2:error] [pid 466512:tid 466679] [client 20.197.195.24:17044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/test.php"] [unique_id "al9YoyKGokixMSfKDOfP1wAAAjk"]
[Tue Jul 21 08:31:48.071481 2026] [security2:error] [pid 466512:tid 466689] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9YpCKGokixMSfKDOfP2gAAAkM"]
[Tue Jul 21 08:31:48.251433 2026] [security2:error] [pid 466512:tid 466685] [client 20.197.192.193:65154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/echkm.php"] [unique_id "al9YpCKGokixMSfKDOfP3QAAAj8"]
[Tue Jul 21 08:31:48.295451 2026] [log_config:warn] [pid 418108:tid 418261] (32)Broken pipe: [client 181.232.231.142:43626] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:48.295475 2026] [log_config:warn] [pid 418108:tid 418261] (32)Broken pipe: [client 181.232.231.142:43626] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:48.326789 2026] [autoindex:error] [pid 466512:tid 466691] [client 198.235.24.177:0] AH01276: Cannot serve directory /home4/dralul00/idumed.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:31:48.531525 2026] [security2:error] [pid 466512:tid 466716] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9YpCKGokixMSfKDOfP5gAAAl4"]
[Tue Jul 21 08:31:48.673772 2026] [security2:error] [pid 465652:tid 465808] [client 20.197.195.24:17060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/aaa.php"] [unique_id "al9YpDzTqJoBC2Mw28-uDAAAAJ8"]
[Tue Jul 21 08:31:48.991420 2026] [security2:error] [pid 465652:tid 465820] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9YpDzTqJoBC2Mw28-uEwAAAKs"]
[Tue Jul 21 08:31:49.373961 2026] [security2:error] [pid 466512:tid 466715] [client 223.181.60.88:1896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YpSKGokixMSfKDOfP6QAAAl0"]
[Tue Jul 21 08:31:49.374112 2026] [security2:error] [pid 466512:tid 466715] [client 223.181.60.88:1896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YpSKGokixMSfKDOfP6QAAAl0"]
[Tue Jul 21 08:31:49.379300 2026] [security2:error] [pid 466512:tid 466727] [client 20.197.195.24:15742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/edit.php"] [unique_id "al9YpSKGokixMSfKDOfP6gAAAmk"]
[Tue Jul 21 08:31:49.382772 2026] [security2:error] [pid 466512:tid 466698] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9YpSKGokixMSfKDOfP6wAAAkw"]
[Tue Jul 21 08:31:49.538645 2026] [security2:error] [pid 465652:tid 465857] [client 20.197.195.24:17074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/11.php"] [unique_id "al9YpTzTqJoBC2Mw28-uIwAAANA"]
[Tue Jul 21 08:31:49.552553 2026] [security2:error] [pid 465652:tid 465827] [client 20.197.192.193:65189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/mac.php"] [unique_id "al9YpTzTqJoBC2Mw28-uJAAAALI"]
[Tue Jul 21 08:31:49.661712 2026] [security2:error] [pid 466512:tid 466748] [client 128.127.105.184:43742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9YpSKGokixMSfKDOfP9gAAAn4"]
[Tue Jul 21 08:31:49.661873 2026] [security2:error] [pid 466512:tid 466748] [client 128.127.105.184:43742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9YpSKGokixMSfKDOfP9gAAAn4"]
[Tue Jul 21 08:31:49.825291 2026] [security2:error] [pid 466512:tid 466740] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9YpSKGokixMSfKDOfP9wAAAnY"]
[Tue Jul 21 08:31:49.984603 2026] [security2:error] [pid 466512:tid 466758] [client 20.206.105.145:25487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/adminner.php"] [unique_id "al9YpSKGokixMSfKDOfP-gAAAog"]
[Tue Jul 21 08:31:50.307637 2026] [security2:error] [pid 466512:tid 466645] [client 20.197.195.24:57891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/mac.php"] [unique_id "al9YpiKGokixMSfKDOfP_gAAAhc"]
[Tue Jul 21 08:31:50.378208 2026] [security2:error] [pid 465652:tid 465854] [client 128.127.105.184:43750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9YpjzTqJoBC2Mw28-uOgAAAM0"]
[Tue Jul 21 08:31:50.378318 2026] [security2:error] [pid 465652:tid 465854] [client 128.127.105.184:43750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9YpjzTqJoBC2Mw28-uOgAAAM0"]
[Tue Jul 21 08:31:50.454242 2026] [security2:error] [pid 466512:tid 466747] [client 61.1.167.83:54860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YpiKGokixMSfKDOfQAgAAAn0"]
[Tue Jul 21 08:31:50.454361 2026] [security2:error] [pid 466512:tid 466747] [client 61.1.167.83:54860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YpiKGokixMSfKDOfQAgAAAn0"]
[Tue Jul 21 08:31:50.478209 2026] [security2:error] [pid 466512:tid 466651] [client 20.197.192.193:43811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/samll.php"] [unique_id "al9YpiKGokixMSfKDOfQAwAAAh0"]
[Tue Jul 21 08:31:50.500613 2026] [security2:error] [pid 466512:tid 466749] [client 20.206.105.145:25528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/admin.php"] [unique_id "al9YpiKGokixMSfKDOfQBAAAAn8"]
[Tue Jul 21 08:31:50.598207 2026] [security2:error] [pid 465652:tid 465865] [client 195.49.128.211:53511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YpjzTqJoBC2Mw28-uQwAAANg"]
[Tue Jul 21 08:31:50.598315 2026] [security2:error] [pid 465652:tid 465865] [client 195.49.128.211:53511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YpjzTqJoBC2Mw28-uQwAAANg"]
[Tue Jul 21 08:31:50.821479 2026] [security2:error] [pid 466512:tid 466691] [client 20.197.192.193:43812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/abcd.php"] [unique_id "al9YpiKGokixMSfKDOfQOwAAAkU"]
[Tue Jul 21 08:31:50.850489 2026] [security2:error] [pid 466512:tid 466648] [client 150.129.202.39:65320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YpiKGokixMSfKDOfQPAAAAho"]
[Tue Jul 21 08:31:50.850596 2026] [security2:error] [pid 466512:tid 466648] [client 150.129.202.39:65320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YpiKGokixMSfKDOfQPAAAAho"]
[Tue Jul 21 08:31:51.169067 2026] [security2:error] [pid 466512:tid 466717] [client 20.197.195.24:3967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/hosty.php"] [unique_id "al9YpyKGokixMSfKDOfQSwAAAl8"]
[Tue Jul 21 08:31:51.176881 2026] [security2:error] [pid 465652:tid 465701] [remote 144.126.207.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.207.126.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YpzzTqJoBC2Mw28-uUAAAsDA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:31:51.182058 2026] [security2:error] [pid 466512:tid 466622] [remote 144.126.207.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.207.126.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YpyKGokixMSfKDOfQTAACI20"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:31:51.185369 2026] [security2:error] [pid 466512:tid 466623] [remote 144.126.207.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.207.126.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YpyKGokixMSfKDOfQTQACIW4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:31:51.192147 2026] [security2:error] [pid 465652:tid 465795] [client 20.197.192.193:65174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/x.php"] [unique_id "al9YpzzTqJoBC2Mw28-uUgAAAJI"]
[Tue Jul 21 08:31:51.215037 2026] [security2:error] [pid 466512:tid 466624] [remote 144.126.207.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.207.126.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YpyKGokixMSfKDOfQTgACRm8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:31:51.404484 2026] [security2:error] [pid 466512:tid 466674] [client 20.197.195.24:57924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/chosen.php"] [unique_id "al9YpyKGokixMSfKDOfQlwAAAjQ"]
[Tue Jul 21 08:31:51.416511 2026] [security2:error] [pid 466512:tid 466600] [remote 144.126.207.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.207.126.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YpyKGokixMSfKDOfQtQACa1c"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:31:51.454693 2026] [security2:error] [pid 466512:tid 466596] [remote 144.126.207.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.207.126.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YpyKGokixMSfKDOfQ3QACaVM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:31:51.489803 2026] [security2:error] [pid 466512:tid 466680] [client 20.172.67.176:43152] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.70"] [uri "/index.cgi"] [unique_id "al9YpyKGokixMSfKDOfQ6QAAAjo"]
[Tue Jul 21 08:31:51.668222 2026] [security2:error] [pid 466512:tid 466588] [remote 144.126.207.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.207.126.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YpyKGokixMSfKDOfQ7wACWEs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:31:51.774041 2026] [security2:error] [pid 466512:tid 466605] [remote 144.126.207.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.207.126.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YpyKGokixMSfKDOfQ8QACkFw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:31:51.776092 2026] [security2:error] [pid 465652:tid 465711] [remote 144.126.207.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.207.126.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YpzzTqJoBC2Mw28-upQAA-Do"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:31:51.942790 2026] [security2:error] [pid 466512:tid 466604] [remote 49.13.1.223:37248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9YpyKGokixMSfKDOfQ8gACdFs"]
[Tue Jul 21 08:31:52.072310 2026] [security2:error] [pid 466512:tid 466607] [remote 144.126.207.166:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.207.126.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9YqCKGokixMSfKDOfQ8wACGl4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:31:52.110092 2026] [security2:error] [pid 465652:tid 465835] [client 117.213.202.34:59813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YqDzTqJoBC2Mw28-urQAAALo"]
[Tue Jul 21 08:31:52.110343 2026] [security2:error] [pid 465652:tid 465835] [client 117.213.202.34:59813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YqDzTqJoBC2Mw28-urQAAALo"]
[Tue Jul 21 08:31:52.209005 2026] [security2:error] [pid 466512:tid 466735] [client 49.144.66.253:30918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YqCKGokixMSfKDOfQ-QAAAnE"]
[Tue Jul 21 08:31:52.209142 2026] [security2:error] [pid 466512:tid 466735] [client 49.144.66.253:30918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YqCKGokixMSfKDOfQ-QAAAnE"]
[Tue Jul 21 08:31:52.217950 2026] [security2:error] [pid 466512:tid 466682] [client 20.206.105.145:25580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/k.php"] [unique_id "al9YqCKGokixMSfKDOfQ-wAAAjw"]
[Tue Jul 21 08:31:52.299868 2026] [security2:error] [pid 466512:tid 466685] [client 20.197.195.24:17039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/cream1.php"] [unique_id "al9YqCKGokixMSfKDOfQ_gAAAj8"]
[Tue Jul 21 08:31:52.499882 2026] [proxy:error] [pid 465652:tid 465800] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:31:52.499920 2026] [proxy_http:error] [pid 465652:tid 465800] [client 20.197.195.24:57972] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:31:52.500487 2026] [proxy:error] [pid 465652:tid 465800] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:31:52.500511 2026] [proxy_http:error] [pid 465652:tid 465800] [client 20.197.195.24:57972] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:31:52.629071 2026] [proxy:error] [pid 466512:tid 466730] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:31:52.629117 2026] [proxy_http:error] [pid 466512:tid 466730] [client 20.197.195.24:57954] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:31:52.629646 2026] [proxy:error] [pid 466512:tid 466730] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:31:52.629668 2026] [proxy_http:error] [pid 466512:tid 466730] [client 20.197.195.24:57954] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:31:53.171554 2026] [security2:error] [pid 466512:tid 466680] [client 20.197.192.193:65211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9YqSKGokixMSfKDOfRGAAAAjo"]
[Tue Jul 21 08:31:53.342259 2026] [security2:error] [pid 465652:tid 465857] [client 20.206.105.145:25592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/x.php"] [unique_id "al9YqTzTqJoBC2Mw28-uxAAAANA"]
[Tue Jul 21 08:31:53.400935 2026] [security2:error] [pid 465652:tid 465784] [client 20.197.195.24:57914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/dr.php"] [unique_id "al9YqTzTqJoBC2Mw28-uxQAAAIc"]
[Tue Jul 21 08:31:53.447610 2026] [security2:error] [pid 466512:tid 466659] [client 125.18.144.2:64032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YqSKGokixMSfKDOfRHQAAAiU"]
[Tue Jul 21 08:31:53.447744 2026] [security2:error] [pid 466512:tid 466659] [client 125.18.144.2:64032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YqSKGokixMSfKDOfRHQAAAiU"]
[Tue Jul 21 08:31:53.569789 2026] [log_config:warn] [pid 462418:tid 462592] (32)Broken pipe: [client 206.0.219.26:42044] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:53.569818 2026] [log_config:warn] [pid 462418:tid 462592] (32)Broken pipe: [client 206.0.219.26:42044] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:54.344452 2026] [security2:error] [pid 466512:tid 466712] [client 122.176.100.127:51171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YqiKGokixMSfKDOfRJgAAAlo"]
[Tue Jul 21 08:31:54.344664 2026] [security2:error] [pid 466512:tid 466712] [client 122.176.100.127:51171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YqiKGokixMSfKDOfRJgAAAlo"]
[Tue Jul 21 08:31:54.601669 2026] [security2:error] [pid 466512:tid 466663] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9YqiKGokixMSfKDOfRKgAAAik"]
[Tue Jul 21 08:31:54.677358 2026] [security2:error] [pid 466512:tid 466749] [client 20.197.195.24:17047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/x.php"] [unique_id "al9YqiKGokixMSfKDOfRLQAAAn8"]
[Tue Jul 21 08:31:54.710191 2026] [security2:error] [pid 465652:tid 465870] [client 20.197.195.24:3901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/k.php"] [unique_id "al9YqjzTqJoBC2Mw28-u1AAAAN0"]
[Tue Jul 21 08:31:54.733324 2026] [security2:error] [pid 466512:tid 466615] [remote 116.179.37.141:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9YqiKGokixMSfKDOfRKQACKmY"], referer: https://androapkmod.com/tag/real-steel-boxing-champions-dinheiro-infinito-download/
[Tue Jul 21 08:31:54.877454 2026] [security2:error] [pid 465652:tid 465892] [client 85.204.70.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YqjzTqJoBC2Mw28-u3AAAAPM"]
[Tue Jul 21 08:31:54.989759 2026] [security2:error] [pid 465652:tid 465889] [client 195.49.128.211:61966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YqjzTqJoBC2Mw28-u4AAAAPA"]
[Tue Jul 21 08:31:54.989874 2026] [security2:error] [pid 465652:tid 465889] [client 195.49.128.211:61966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YqjzTqJoBC2Mw28-u4AAAAPA"]
[Tue Jul 21 08:31:55.024903 2026] [security2:error] [pid 465652:tid 465833] [client 20.206.105.145:25563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wss.php"] [unique_id "al9YqzzTqJoBC2Mw28-u4QAAALg"]
[Tue Jul 21 08:31:55.250373 2026] [security2:error] [pid 465652:tid 465871] [client 152.59.34.51:55862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YqzzTqJoBC2Mw28-u5QAAAN4"]
[Tue Jul 21 08:31:55.250517 2026] [security2:error] [pid 465652:tid 465871] [client 152.59.34.51:55862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YqzzTqJoBC2Mw28-u5QAAAN4"]
[Tue Jul 21 08:31:55.281024 2026] [log_config:warn] [pid 419508:tid 419703] (32)Broken pipe: [client 37.215.37.28:5968] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:31:55.281048 2026] [log_config:warn] [pid 419508:tid 419703] (32)Broken pipe: [client 37.215.37.28:5968] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:31:55.307319 2026] [security2:error] [pid 466512:tid 466740] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9YqyKGokixMSfKDOfROwAAAnY"]
[Tue Jul 21 08:31:55.344501 2026] [security2:error] [pid 466512:tid 466717] [client 65.21.113.253:42724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YqiKGokixMSfKDOfRMAAAAl8"]
[Tue Jul 21 08:31:55.464103 2026] [security2:error] [pid 465652:tid 465665] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YqzzTqJoBC2Mw28-u6wAAjww"]
[Tue Jul 21 08:31:55.464288 2026] [security2:error] [pid 465652:tid 465792] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YqzzTqJoBC2Mw28-u6wAAjww"]
[Tue Jul 21 08:31:55.579973 2026] [security2:error] [pid 465652:tid 465820] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9YqzzTqJoBC2Mw28-u7AAAAKs"]
[Tue Jul 21 08:31:55.627559 2026] [security2:error] [pid 465652:tid 465832] [client 20.197.195.24:16052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/aaa.php"] [unique_id "al9YqzzTqJoBC2Mw28-u8QAAALc"]
[Tue Jul 21 08:31:55.843784 2026] [security2:error] [pid 466512:tid 466727] [client 14.245.224.124:53781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YqyKGokixMSfKDOfRRQAAAmk"]
[Tue Jul 21 08:31:55.843896 2026] [security2:error] [pid 466512:tid 466727] [client 14.245.224.124:53781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YqyKGokixMSfKDOfRRQAAAmk"]
[Tue Jul 21 08:31:55.852488 2026] [security2:error] [pid 465652:tid 465856] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9YqzzTqJoBC2Mw28-u-wAAAM8"]
[Tue Jul 21 08:31:55.969334 2026] [security2:error] [pid 465652:tid 465814] [client 20.206.105.145:25482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/ty.php"] [unique_id "al9YqzzTqJoBC2Mw28-u_QAAAKU"]
[Tue Jul 21 08:31:56.124337 2026] [security2:error] [pid 466512:tid 466710] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9YrCKGokixMSfKDOfRSQAAAlg"]
[Tue Jul 21 08:31:56.397938 2026] [security2:error] [pid 465652:tid 465899] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9YrDzTqJoBC2Mw28-vBAAAAPo"]
[Tue Jul 21 08:31:56.670499 2026] [security2:error] [pid 466512:tid 466686] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9YrCKGokixMSfKDOfRTgAAAkA"]
[Tue Jul 21 08:31:56.826699 2026] [security2:error] [pid 466512:tid 466763] [client 202.179.75.202:42164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YrCKGokixMSfKDOfRTwAAAo0"]
[Tue Jul 21 08:31:56.827091 2026] [security2:error] [pid 466512:tid 466763] [client 202.179.75.202:42164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YrCKGokixMSfKDOfRTwAAAo0"]
[Tue Jul 21 08:31:56.942938 2026] [security2:error] [pid 466512:tid 466693] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9YrCKGokixMSfKDOfRUgAAAkc"]
[Tue Jul 21 08:31:56.984091 2026] [proxy:error] [pid 466512:tid 466664] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:31:56.984146 2026] [proxy_http:error] [pid 466512:tid 466664] [client 87.236.176.133:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:31:56.984595 2026] [proxy:error] [pid 466512:tid 466664] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:31:56.984616 2026] [proxy_http:error] [pid 466512:tid 466664] [client 87.236.176.133:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:31:56.998367 2026] [security2:error] [pid 465652:tid 465890] [client 5.38.115.39:60850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9YqzzTqJoBC2Mw28-u-gAAAPE"]
[Tue Jul 21 08:31:56.998490 2026] [security2:error] [pid 465652:tid 465890] [client 5.38.115.39:60850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9YqzzTqJoBC2Mw28-u-gAAAPE"]
[Tue Jul 21 08:31:57.214407 2026] [security2:error] [pid 466512:tid 466742] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9YrSKGokixMSfKDOfRVwAAAng"]
[Tue Jul 21 08:31:57.381592 2026] [security2:error] [pid 466512:tid 466642] [client 20.197.195.24:57937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/155.php"] [unique_id "al9YrSKGokixMSfKDOfRWgAAAhQ"]
[Tue Jul 21 08:31:57.387223 2026] [security2:error] [pid 466512:tid 466635] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YrSKGokixMSfKDOfRWwACJno"]
[Tue Jul 21 08:31:57.387377 2026] [security2:error] [pid 466512:tid 466660] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YrSKGokixMSfKDOfRWwACJno"]
[Tue Jul 21 08:31:57.486986 2026] [security2:error] [pid 466512:tid 466747] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9YrSKGokixMSfKDOfRXwAAAn0"]
[Tue Jul 21 08:31:57.522391 2026] [security2:error] [pid 466512:tid 466677] [client 187.125.243.197:63980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YrSKGokixMSfKDOfRYgAAAjc"]
[Tue Jul 21 08:31:57.522506 2026] [security2:error] [pid 466512:tid 466677] [client 187.125.243.197:63980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YrSKGokixMSfKDOfRYgAAAjc"]
[Tue Jul 21 08:31:57.695730 2026] [security2:error] [pid 465652:tid 465906] [client 20.197.195.24:15696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file5.php"] [unique_id "al9YrTzTqJoBC2Mw28-vFwAAAQE"]
[Tue Jul 21 08:31:57.783261 2026] [security2:error] [pid 465652:tid 465809] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9YrTzTqJoBC2Mw28-vGQAAAKA"]
[Tue Jul 21 08:31:57.911617 2026] [security2:error] [pid 466512:tid 466683] [client 20.206.105.145:25486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/155.php"] [unique_id "al9YrSKGokixMSfKDOfRaAAAAj0"]
[Tue Jul 21 08:31:58.056584 2026] [security2:error] [pid 465652:tid 465786] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9YrjzTqJoBC2Mw28-vIQAAAIk"]
[Tue Jul 21 08:31:58.057063 2026] [security2:error] [pid 466512:tid 466710] [client 213.152.186.163:51974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9YriKGokixMSfKDOfRawAAAlg"]
[Tue Jul 21 08:31:58.057163 2026] [security2:error] [pid 466512:tid 466710] [client 213.152.186.163:51974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9YriKGokixMSfKDOfRawAAAlg"]
[Tue Jul 21 08:31:58.331708 2026] [security2:error] [pid 465652:tid 465816] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9YrjzTqJoBC2Mw28-vIwAAAKc"]
[Tue Jul 21 08:31:58.354410 2026] [security2:error] [pid 466512:tid 466732] [client 20.197.195.24:6358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/222.php"] [unique_id "al9YriKGokixMSfKDOfRbwAAAm4"]
[Tue Jul 21 08:31:58.604024 2026] [security2:error] [pid 466512:tid 466661] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9YriKGokixMSfKDOfReAAAAic"]
[Tue Jul 21 08:31:58.728722 2026] [security2:error] [pid 466512:tid 466737] [client 5.31.193.106:1796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YriKGokixMSfKDOfRewAAAnM"]
[Tue Jul 21 08:31:58.728868 2026] [security2:error] [pid 466512:tid 466737] [client 5.31.193.106:1796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YriKGokixMSfKDOfRewAAAnM"]
[Tue Jul 21 08:31:58.739467 2026] [security2:error] [pid 466512:tid 466657] [client 213.152.186.163:53974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9YriKGokixMSfKDOfRfAAAAiM"]
[Tue Jul 21 08:31:58.739580 2026] [security2:error] [pid 466512:tid 466657] [client 213.152.186.163:53974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9YriKGokixMSfKDOfRfAAAAiM"]
[Tue Jul 21 08:31:58.832203 2026] [security2:error] [pid 466512:tid 466718] [client 20.206.105.145:25595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/ops.php"] [unique_id "al9YriKGokixMSfKDOfRfgAAAmA"]
[Tue Jul 21 08:31:58.876352 2026] [security2:error] [pid 466512:tid 466682] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9YriKGokixMSfKDOfRfwAAAjw"]
[Tue Jul 21 08:31:59.150034 2026] [security2:error] [pid 466512:tid 466687] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9YryKGokixMSfKDOfRjQAAAkE"]
[Tue Jul 21 08:31:59.215509 2026] [security2:error] [pid 466512:tid 466666] [client 35.229.94.153:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "extrapro21.com"] [uri "/xmlrpc.php"] [unique_id "al9YryKGokixMSfKDOfRigACLC4"]
[Tue Jul 21 08:31:59.304352 2026] [security2:error] [pid 466512:tid 466748] [client 20.197.195.24:6332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/test.php"] [unique_id "al9YryKGokixMSfKDOfRjwAAAn4"]
[Tue Jul 21 08:31:59.375339 2026] [proxy:error] [pid 466512:tid 466550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:31:59.375384 2026] [proxy_http:error] [pid 466512:tid 466550] [remote 74.7.244.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:31:59.376950 2026] [proxy:error] [pid 466512:tid 466550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:31:59.376995 2026] [proxy_http:error] [pid 466512:tid 466550] [remote 74.7.244.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:31:59.423665 2026] [security2:error] [pid 465652:tid 465898] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.eloisanakelnakashima1782224349661.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9YrzzTqJoBC2Mw28-vOAAAAPk"]
[Tue Jul 21 08:31:59.468286 2026] [security2:error] [pid 465652:tid 465674] [remote 35.229.94.153:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "extrapro21.com"] [uri "/xmlrpc.php"] [unique_id "al9YrzzTqJoBC2Mw28-vNgAAtBU"]
[Tue Jul 21 08:31:59.559538 2026] [security2:error] [pid 466512:tid 466642] [client 65.21.113.253:42724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YryKGokixMSfKDOfRiQAAAhQ"]
[Tue Jul 21 08:31:59.649255 2026] [security2:error] [pid 466512:tid 466730] [client 20.197.195.24:17082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/ops.php"] [unique_id "al9YryKGokixMSfKDOfRlwAAAmw"]
[Tue Jul 21 08:31:59.707725 2026] [security2:error] [pid 466512:tid 466646] [client 35.229.94.153:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "extrapro21.com"] [uri "/xmlrpc.php"] [unique_id "al9YryKGokixMSfKDOfRlgACGC8"]
[Tue Jul 21 08:31:59.892585 2026] [security2:error] [pid 465652:tid 465859] [client 35.229.94.153:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "extrapro21.com"] [uri "/xmlrpc.php"] [unique_id "al9YrzzTqJoBC2Mw28-vQAAA0js"]
[Tue Jul 21 08:32:00.188879 2026] [security2:error] [pid 465652:tid 465831] [client 223.181.60.88:30569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YsDzTqJoBC2Mw28-vSwAAALY"]
[Tue Jul 21 08:32:00.189160 2026] [security2:error] [pid 465652:tid 465831] [client 223.181.60.88:30569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YsDzTqJoBC2Mw28-vSwAAALY"]
[Tue Jul 21 08:32:00.479664 2026] [security2:error] [pid 466512:tid 466668] [client 35.229.94.153:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "extrapro21.assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YsCKGokixMSfKDOfRnAACLgw"]
[Tue Jul 21 08:32:00.507332 2026] [security2:error] [pid 465652:tid 465883] [client 20.197.195.24:3966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/aaa.php"] [unique_id "al9YsDzTqJoBC2Mw28-vUAAAAOo"]
[Tue Jul 21 08:32:00.673094 2026] [security2:error] [pid 466512:tid 466680] [client 20.197.195.24:18727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/file31.php"] [unique_id "al9YsCKGokixMSfKDOfRnwAAAjo"]
[Tue Jul 21 08:32:00.706676 2026] [security2:error] [pid 466512:tid 466743] [client 20.206.105.145:25583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/ingfo.php"] [unique_id "al9YsCKGokixMSfKDOfRoAAAAnk"]
[Tue Jul 21 08:32:01.197524 2026] [security2:error] [pid 465652:tid 465787] [client 195.49.128.211:54129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YsTzTqJoBC2Mw28-vZQAAAIo"]
[Tue Jul 21 08:32:01.197679 2026] [security2:error] [pid 465652:tid 465787] [client 195.49.128.211:54129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YsTzTqJoBC2Mw28-vZQAAAIo"]
[Tue Jul 21 08:32:01.427223 2026] [security2:error] [pid 466512:tid 466695] [client 20.197.195.24:16005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/11.php"] [unique_id "al9YsSKGokixMSfKDOfRrwAAAkk"]
[Tue Jul 21 08:32:01.471749 2026] [security2:error] [pid 466512:tid 466716] [client 65.21.113.253:42724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YsCKGokixMSfKDOfRqQAAAl4"]
[Tue Jul 21 08:32:01.495580 2026] [security2:error] [pid 466512:tid 466742] [client 20.197.192.193:65155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/ee.php"] [unique_id "al9YsSKGokixMSfKDOfRsAAAAng"]
[Tue Jul 21 08:32:01.503409 2026] [security2:error] [pid 466512:tid 466759] [client 150.129.202.39:65067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YsSKGokixMSfKDOfRsQAAAok"]
[Tue Jul 21 08:32:01.503522 2026] [security2:error] [pid 466512:tid 466759] [client 150.129.202.39:65067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YsSKGokixMSfKDOfRsQAAAok"]
[Tue Jul 21 08:32:01.755798 2026] [security2:error] [pid 465652:tid 465859] [client 20.206.105.145:25533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/error_log.php"] [unique_id "al9YsTzTqJoBC2Mw28-vcwAAANI"]
[Tue Jul 21 08:32:01.852941 2026] [security2:error] [pid 465652:tid 465841] [client 20.197.195.24:17026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/file6.php"] [unique_id "al9YsTzTqJoBC2Mw28-veQAAAMA"]
[Tue Jul 21 08:32:01.904343 2026] [security2:error] [pid 466512:tid 466655] [client 128.127.105.184:60706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9YsSKGokixMSfKDOfRtAAAAiE"]
[Tue Jul 21 08:32:01.904473 2026] [security2:error] [pid 466512:tid 466655] [client 128.127.105.184:60706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9YsSKGokixMSfKDOfRtAAAAiE"]
[Tue Jul 21 08:32:02.264987 2026] [security2:error] [pid 465652:tid 465864] [client 20.197.195.24:3882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/mac.php"] [unique_id "al9YsjzTqJoBC2Mw28-vgQAAANc"]
[Tue Jul 21 08:32:02.679225 2026] [security2:error] [pid 466512:tid 466642] [client 4.194.24.143:5800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/about/function.php"] [unique_id "al9YsiKGokixMSfKDOfRyAAAAhQ"]
[Tue Jul 21 08:32:02.784044 2026] [security2:error] [pid 465652:tid 465795] [client 117.213.202.34:60419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YsjzTqJoBC2Mw28-vpQAAAJI"]
[Tue Jul 21 08:32:02.784223 2026] [security2:error] [pid 465652:tid 465795] [client 117.213.202.34:60419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YsjzTqJoBC2Mw28-vpQAAAJI"]
[Tue Jul 21 08:32:02.897999 2026] [proxy:error] [pid 466512:tid 466680] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:02.898071 2026] [proxy_http:error] [pid 466512:tid 466680] [client 20.197.195.24:18691] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:02.898585 2026] [proxy:error] [pid 466512:tid 466680] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:02.898614 2026] [proxy_http:error] [pid 466512:tid 466680] [client 20.197.195.24:18691] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:02.975405 2026] [security2:error] [pid 465652:tid 465878] [client 34.168.233.46:50830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.233.168.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "camilajung.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YsjzTqJoBC2Mw28-vqAAAAOU"]
[Tue Jul 21 08:32:02.975528 2026] [security2:error] [pid 465652:tid 465878] [client 34.168.233.46:50830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "camilajung.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YsjzTqJoBC2Mw28-vqAAAAOU"]
[Tue Jul 21 08:32:03.104756 2026] [security2:error] [pid 466512:tid 466724] [client 213.152.186.163:53982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9YsyKGokixMSfKDOfR0AAAAmY"]
[Tue Jul 21 08:32:03.104897 2026] [security2:error] [pid 466512:tid 466724] [client 213.152.186.163:53982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9YsyKGokixMSfKDOfR0AAAAmY"]
[Tue Jul 21 08:32:03.348523 2026] [security2:error] [pid 466512:tid 466717] [client 61.1.167.83:55380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YsyKGokixMSfKDOfR1AAAAl8"]
[Tue Jul 21 08:32:03.348707 2026] [security2:error] [pid 466512:tid 466717] [client 61.1.167.83:55380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YsyKGokixMSfKDOfR1AAAAl8"]
[Tue Jul 21 08:32:03.388349 2026] [security2:error] [pid 466512:tid 466659] [client 49.144.66.253:31362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YsyKGokixMSfKDOfR1QAAAiU"]
[Tue Jul 21 08:32:03.388487 2026] [security2:error] [pid 466512:tid 466659] [client 49.144.66.253:31362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YsyKGokixMSfKDOfR1QAAAiU"]
[Tue Jul 21 08:32:03.711583 2026] [security2:error] [pid 466512:tid 466718] [client 4.194.24.143:5774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/admiin.php"] [unique_id "al9YsyKGokixMSfKDOfR2QAAAmA"]
[Tue Jul 21 08:32:03.917011 2026] [security2:error] [pid 466512:tid 466691] [client 20.197.195.24:6303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/chosen.php"] [unique_id "al9YsyKGokixMSfKDOfR3QAAAkU"]
[Tue Jul 21 08:32:04.171212 2026] [security2:error] [pid 466512:tid 466682] [client 111.93.58.162:13779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YtCKGokixMSfKDOfR4QAAAjw"]
[Tue Jul 21 08:32:04.171535 2026] [security2:error] [pid 466512:tid 466682] [client 111.93.58.162:13779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YtCKGokixMSfKDOfR4QAAAjw"]
[Tue Jul 21 08:32:04.252461 2026] [security2:error] [pid 466512:tid 466678] [client 65.21.113.253:42724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YsyKGokixMSfKDOfR3AAAAjg"]
[Tue Jul 21 08:32:04.582146 2026] [security2:error] [pid 465652:tid 465800] [client 20.206.105.145:25485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/ok.php"] [unique_id "al9YtDzTqJoBC2Mw28-vwgAAAJc"]
[Tue Jul 21 08:32:04.757774 2026] [security2:error] [pid 466512:tid 466662] [client 4.194.24.143:8852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/admin-main/class-wp-http-core.php"] [unique_id "al9YtCKGokixMSfKDOfR8AAAAig"]
[Tue Jul 21 08:32:04.806857 2026] [security2:error] [pid 465652:tid 465876] [client 122.176.100.127:51669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YtDzTqJoBC2Mw28-vyAAAAOM"]
[Tue Jul 21 08:32:04.806995 2026] [security2:error] [pid 465652:tid 465876] [client 122.176.100.127:51669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YtDzTqJoBC2Mw28-vyAAAAOM"]
[Tue Jul 21 08:32:04.924825 2026] [security2:error] [pid 466512:tid 466763] [client 20.197.195.24:57858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/adminfuns.php"] [unique_id "al9YtCKGokixMSfKDOfR8wAAAo0"]
[Tue Jul 21 08:32:05.014986 2026] [security2:error] [pid 465652:tid 465870] [client 213.152.186.163:53992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9YtTzTqJoBC2Mw28-vyQAAAN0"]
[Tue Jul 21 08:32:05.015077 2026] [security2:error] [pid 465652:tid 465870] [client 213.152.186.163:53992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9YtTzTqJoBC2Mw28-vyQAAAN0"]
[Tue Jul 21 08:32:05.095841 2026] [security2:error] [pid 465652:tid 465898] [client 20.197.195.24:6363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/cream1.php"] [unique_id "al9YtTzTqJoBC2Mw28-vywAAAPk"]
[Tue Jul 21 08:32:05.355593 2026] [security2:error] [pid 465652:tid 465859] [client 74.249.245.134:54940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9YtTzTqJoBC2Mw28-v1QAAANI"]
[Tue Jul 21 08:32:05.519176 2026] [security2:error] [pid 465652:tid 465786] [client 109.248.148.246:42604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9YtTzTqJoBC2Mw28-v1wAAAIk"]
[Tue Jul 21 08:32:05.519269 2026] [security2:error] [pid 465652:tid 465786] [client 109.248.148.246:42604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9YtTzTqJoBC2Mw28-v1wAAAIk"]
[Tue Jul 21 08:32:05.609889 2026] [security2:error] [pid 465652:tid 465868] [client 195.49.128.211:62735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YtTzTqJoBC2Mw28-v2AAAANs"]
[Tue Jul 21 08:32:05.609990 2026] [security2:error] [pid 465652:tid 465868] [client 195.49.128.211:62735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YtTzTqJoBC2Mw28-v2AAAANs"]
[Tue Jul 21 08:32:05.802260 2026] [security2:error] [pid 466512:tid 466655] [client 4.194.24.143:17035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/admin-post.php"] [unique_id "al9YtSKGokixMSfKDOfSPQAAAiE"]
[Tue Jul 21 08:32:06.004405 2026] [security2:error] [pid 466512:tid 466651] [client 65.21.113.253:42724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YtSKGokixMSfKDOfSAwAAAh0"]
[Tue Jul 21 08:32:06.094027 2026] [security2:error] [pid 466512:tid 466649] [client 20.197.195.24:17043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/goods.php"] [unique_id "al9YtiKGokixMSfKDOfSRgAAAhs"]
[Tue Jul 21 08:32:06.159390 2026] [security2:error] [pid 466512:tid 466638] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YtiKGokixMSfKDOfSSAACZn0"]
[Tue Jul 21 08:32:06.159546 2026] [security2:error] [pid 466512:tid 466724] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YtiKGokixMSfKDOfSSAACZn0"]
[Tue Jul 21 08:32:06.339243 2026] [security2:error] [pid 465652:tid 465884] [client 20.206.105.145:25587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/mac.php"] [unique_id "al9YtjzTqJoBC2Mw28-v5wAAAOs"]
[Tue Jul 21 08:32:06.432256 2026] [autoindex:error] [pid 465652:tid 465816] [client 20.197.195.24:6376] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:06.441926 2026] [security2:error] [pid 465652:tid 465877] [client 5.38.115.39:61515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9YtjzTqJoBC2Mw28-v7wAAAOQ"]
[Tue Jul 21 08:32:06.442027 2026] [security2:error] [pid 465652:tid 465877] [client 5.38.115.39:61515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9YtjzTqJoBC2Mw28-v7wAAAOQ"]
[Tue Jul 21 08:32:06.483303 2026] [autoindex:error] [pid 465652:tid 465854] [client 20.197.195.24:6376] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:06.497866 2026] [security2:error] [pid 466512:tid 466708] [client 14.245.224.124:54866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YtiKGokixMSfKDOfSTQAAAlY"]
[Tue Jul 21 08:32:06.497951 2026] [security2:error] [pid 466512:tid 466708] [client 14.245.224.124:54866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YtiKGokixMSfKDOfSTQAAAlY"]
[Tue Jul 21 08:32:06.510635 2026] [security2:error] [pid 465652:tid 465839] [client 20.197.195.24:6376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/dr.php"] [unique_id "al9YtjzTqJoBC2Mw28-v8QAAAL4"]
[Tue Jul 21 08:32:06.697182 2026] [security2:error] [pid 465652:tid 465842] [client 152.59.34.51:56346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YtjzTqJoBC2Mw28-v8wAAAME"]
[Tue Jul 21 08:32:06.697303 2026] [security2:error] [pid 465652:tid 465842] [client 152.59.34.51:56346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YtjzTqJoBC2Mw28-v8wAAAME"]
[Tue Jul 21 08:32:06.826158 2026] [security2:error] [pid 466512:tid 466716] [client 4.194.24.143:5803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/admin.php"] [unique_id "al9YtiKGokixMSfKDOfSUwAAAl4"]
[Tue Jul 21 08:32:07.217861 2026] [autoindex:error] [pid 466512:tid 466653] [client 66.249.72.2:63204] AH01276: Cannot serve directory /home2/cla35313/reidocouro.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:07.328365 2026] [security2:error] [pid 465652:tid 465895] [client 20.197.195.24:16062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/x.php"] [unique_id "al9YtzzTqJoBC2Mw28-wAgAAAPY"]
[Tue Jul 21 08:32:07.563979 2026] [security2:error] [pid 466512:tid 466680] [client 104.28.166.173:43109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.166.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "izabelreck.com"] [uri "/xmlrpc.php"] [unique_id "al9YtSKGokixMSfKDOfR-wAAAjo"]
[Tue Jul 21 08:32:07.564260 2026] [security2:error] [pid 466512:tid 466680] [client 104.28.166.173:43109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "izabelreck.com"] [uri "/xmlrpc.php"] [unique_id "al9YtSKGokixMSfKDOfR-wAAAjo"]
[Tue Jul 21 08:32:07.745034 2026] [security2:error] [pid 466512:tid 466761] [client 202.179.75.202:49272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YtyKGokixMSfKDOfSZAAAAos"]
[Tue Jul 21 08:32:07.745140 2026] [security2:error] [pid 466512:tid 466761] [client 202.179.75.202:49272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YtyKGokixMSfKDOfSZAAAAos"]
[Tue Jul 21 08:32:07.819943 2026] [security2:error] [pid 466512:tid 466699] [client 65.21.113.253:42724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YtyKGokixMSfKDOfSXQAAAk0"]
[Tue Jul 21 08:32:07.821507 2026] [security2:error] [pid 466512:tid 466695] [client 103.151.46.103:60280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YtyKGokixMSfKDOfSaAAAAkk"]
[Tue Jul 21 08:32:07.821602 2026] [security2:error] [pid 466512:tid 466695] [client 103.151.46.103:60280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YtyKGokixMSfKDOfSaAAAAkk"]
[Tue Jul 21 08:32:07.955355 2026] [security2:error] [pid 466512:tid 466585] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YtyKGokixMSfKDOfSbAACcUg"]
[Tue Jul 21 08:32:07.955537 2026] [security2:error] [pid 466512:tid 466735] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YtyKGokixMSfKDOfSbAACcUg"]
[Tue Jul 21 08:32:08.030037 2026] [security2:error] [pid 465652:tid 465790] [client 187.125.243.197:64486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YuDzTqJoBC2Mw28-wFgAAAI0"]
[Tue Jul 21 08:32:08.030166 2026] [security2:error] [pid 465652:tid 465790] [client 187.125.243.197:64486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YuDzTqJoBC2Mw28-wFgAAAI0"]
[Tue Jul 21 08:32:08.049886 2026] [security2:error] [pid 465652:tid 465817] [client 20.197.195.24:57898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/100.php"] [unique_id "al9YuDzTqJoBC2Mw28-wFwAAAKg"]
[Tue Jul 21 08:32:08.592938 2026] [security2:error] [pid 465652:tid 465794] [client 4.194.24.143:17055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/admin/function.php"] [unique_id "al9YuDzTqJoBC2Mw28-wIgAAAJE"]
[Tue Jul 21 08:32:08.698704 2026] [security2:error] [pid 466512:tid 466718] [client 20.206.105.145:25565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wefile.php"] [unique_id "al9YuCKGokixMSfKDOfScwAAAmA"]
[Tue Jul 21 08:32:08.914168 2026] [security2:error] [pid 465652:tid 465877] [client 20.197.195.24:6310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/155.php"] [unique_id "al9YuDzTqJoBC2Mw28-wJgAAAOQ"]
[Tue Jul 21 08:32:08.989465 2026] [security2:error] [pid 466512:tid 466525] [remote 45.79.123.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "printcom.com.br"] [uri "/wp-login.php"] [unique_id "al9YuCKGokixMSfKDOfSfQACGAw"]
[Tue Jul 21 08:32:09.096412 2026] [security2:error] [pid 466512:tid 466758] [client 20.197.195.24:57868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/about.php"] [unique_id "al9YuSKGokixMSfKDOfSfwAAAog"]
[Tue Jul 21 08:32:09.202488 2026] [security2:error] [pid 466512:tid 466653] [client 34.168.233.46:50072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.233.168.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caminhoneiro.giovanoniadv.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YuSKGokixMSfKDOfSgQAAAh8"]
[Tue Jul 21 08:32:09.202587 2026] [security2:error] [pid 466512:tid 466653] [client 34.168.233.46:50072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "caminhoneiro.giovanoniadv.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YuSKGokixMSfKDOfSgQAAAh8"]
[Tue Jul 21 08:32:09.475355 2026] [security2:error] [pid 466512:tid 466698] [client 20.197.192.193:46152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/2x.php"] [unique_id "al9YuSKGokixMSfKDOfSiQAAAkw"]
[Tue Jul 21 08:32:09.547679 2026] [security2:error] [pid 466512:tid 466647] [client 173.252.95.6:60072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9YuSKGokixMSfKDOfSjAAAAhk"]
[Tue Jul 21 08:32:09.584104 2026] [security2:error] [pid 466512:tid 466642] [client 20.197.192.193:46152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/kq1.php"] [unique_id "al9YuSKGokixMSfKDOfSjwAAAhQ"]
[Tue Jul 21 08:32:09.619292 2026] [security2:error] [pid 466512:tid 466662] [client 4.194.24.143:8504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/adminfuns.php"] [unique_id "al9YuSKGokixMSfKDOfSkgAAAig"]
[Tue Jul 21 08:32:09.849572 2026] [security2:error] [pid 466512:tid 466682] [client 65.21.113.253:42724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YuSKGokixMSfKDOfShQAAAjw"]
[Tue Jul 21 08:32:09.892208 2026] [security2:error] [pid 466512:tid 466723] [client 20.197.195.24:6308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ops.php"] [unique_id "al9YuSKGokixMSfKDOfSmAAAAmU"]
[Tue Jul 21 08:32:10.253865 2026] [log_config:warn] [pid 462418:tid 462624] (32)Broken pipe: [client 179.108.135.175:62838] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:32:10.253885 2026] [log_config:warn] [pid 462418:tid 462624] (32)Broken pipe: [client 179.108.135.175:62838] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:32:10.706971 2026] [security2:error] [pid 466512:tid 466750] [client 20.197.192.193:5611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/zzz.php"] [unique_id "al9YuiKGokixMSfKDOfSoQAAAoA"]
[Tue Jul 21 08:32:10.871513 2026] [security2:error] [pid 465652:tid 465824] [client 4.194.24.143:8269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/administrator/components/com_associations/layouts/joomla/searchtools/mainhack.php"] [unique_id "al9YujzTqJoBC2Mw28-wQwAAAK8"]
[Tue Jul 21 08:32:10.873114 2026] [security2:error] [pid 466512:tid 466655] [client 223.181.60.88:14139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YuiKGokixMSfKDOfSowAAAiE"]
[Tue Jul 21 08:32:10.873403 2026] [security2:error] [pid 466512:tid 466655] [client 223.181.60.88:14139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YuiKGokixMSfKDOfSowAAAiE"]
[Tue Jul 21 08:32:10.876556 2026] [security2:error] [pid 466512:tid 466686] [client 20.197.195.24:17081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/about.php"] [unique_id "al9YuiKGokixMSfKDOfSpQAAAkA"]
[Tue Jul 21 08:32:10.972589 2026] [security2:error] [pid 466512:tid 466743] [client 152.59.181.104:40412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YuiKGokixMSfKDOfSogAAAnk"]
[Tue Jul 21 08:32:10.972792 2026] [security2:error] [pid 466512:tid 466743] [client 152.59.181.104:40412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YuiKGokixMSfKDOfSogAAAnk"]
[Tue Jul 21 08:32:11.353408 2026] [security2:error] [pid 466512:tid 466660] [client 20.197.195.24:6286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file31.php"] [unique_id "al9YuyKGokixMSfKDOfSrAAAAiY"]
[Tue Jul 21 08:32:11.773684 2026] [security2:error] [pid 466512:tid 466715] [client 195.49.128.211:54744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YuyKGokixMSfKDOfSsgAAAl0"]
[Tue Jul 21 08:32:11.773825 2026] [security2:error] [pid 466512:tid 466715] [client 195.49.128.211:54744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YuyKGokixMSfKDOfSsgAAAl0"]
[Tue Jul 21 08:32:11.903019 2026] [security2:error] [pid 465652:tid 465901] [client 4.194.24.143:8283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/ahax.php"] [unique_id "al9YuzzTqJoBC2Mw28-wWQAAAPw"]
[Tue Jul 21 08:32:11.928451 2026] [security2:error] [pid 466512:tid 466562] [remote 192.241.143.148:42514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9YuyKGokixMSfKDOfSswACLTE"]
[Tue Jul 21 08:32:11.952519 2026] [security2:error] [pid 466512:tid 466678] [client 65.21.113.253:42724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YuyKGokixMSfKDOfSrwAAAjg"]
[Tue Jul 21 08:32:12.182016 2026] [security2:error] [pid 466512:tid 466759] [client 150.129.202.39:13392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YvCKGokixMSfKDOfSuAAAAok"]
[Tue Jul 21 08:32:12.182136 2026] [security2:error] [pid 466512:tid 466759] [client 150.129.202.39:13392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YvCKGokixMSfKDOfSuAAAAok"]
[Tue Jul 21 08:32:12.426684 2026] [security2:error] [pid 465652:tid 465749] [remote 68.178.160.25:47232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spazziojardins.com"] [uri "/wp-login.php"] [unique_id "al9YvDzTqJoBC2Mw28-wYQAA82A"]
[Tue Jul 21 08:32:12.539927 2026] [security2:error] [pid 466512:tid 466734] [client 20.197.195.24:17036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9YvCKGokixMSfKDOfSugAAAnA"]
[Tue Jul 21 08:32:12.828271 2026] [security2:error] [pid 466512:tid 466686] [client 20.206.105.145:25488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9YvCKGokixMSfKDOfSwwAAAkA"]
[Tue Jul 21 08:32:12.935926 2026] [security2:error] [pid 466512:tid 466645] [client 4.194.24.143:8472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/ak.php"] [unique_id "al9YvCKGokixMSfKDOfSxwAAAhc"]
[Tue Jul 21 08:32:13.237781 2026] [security2:error] [pid 465652:tid 465832] [client 20.197.195.24:15684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file6.php"] [unique_id "al9YvTzTqJoBC2Mw28-wcQAAALc"]
[Tue Jul 21 08:32:13.502396 2026] [security2:error] [pid 466512:tid 466651] [client 117.213.202.34:61023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YvSKGokixMSfKDOfS0gAAAh0"]
[Tue Jul 21 08:32:13.502512 2026] [security2:error] [pid 466512:tid 466651] [client 117.213.202.34:61023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YvSKGokixMSfKDOfS0gAAAh0"]
[Tue Jul 21 08:32:13.535609 2026] [security2:error] [pid 466512:tid 466678] [client 20.197.195.24:17065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/admin.php"] [unique_id "al9YvSKGokixMSfKDOfS0wAAAjg"]
[Tue Jul 21 08:32:13.793638 2026] [security2:error] [pid 466512:tid 466729] [client 65.21.113.253:42724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YvSKGokixMSfKDOfSzAAAAms"]
[Tue Jul 21 08:32:13.999203 2026] [security2:error] [pid 466512:tid 466689] [client 4.194.24.143:8487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/alfa-rex.php"] [unique_id "al9YvSKGokixMSfKDOfS3gAAAkM"]
[Tue Jul 21 08:32:14.072904 2026] [security2:error] [pid 466512:tid 466647] [client 49.144.66.253:31722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YviKGokixMSfKDOfS4AAAAhk"]
[Tue Jul 21 08:32:14.073011 2026] [security2:error] [pid 466512:tid 466647] [client 49.144.66.253:31722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YviKGokixMSfKDOfS4AAAAhk"]
[Tue Jul 21 08:32:14.208624 2026] [security2:error] [pid 465652:tid 465819] [client 20.197.195.24:17025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/themes.php"] [unique_id "al9YvjzTqJoBC2Mw28-wfwAAAKo"]
[Tue Jul 21 08:32:14.632949 2026] [security2:error] [pid 466512:tid 466692] [client 125.18.144.2:29028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YviKGokixMSfKDOfS6AAAAkY"]
[Tue Jul 21 08:32:14.633064 2026] [security2:error] [pid 466512:tid 466692] [client 125.18.144.2:29028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YviKGokixMSfKDOfS6AAAAkY"]
[Tue Jul 21 08:32:14.638932 2026] [access_compat:error] [pid 465652:tid 465900] [client 162.241.63.68:32038] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:32:14.805687 2026] [autoindex:error] [pid 465652:tid 465788] [client 20.197.195.24:3905] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:14.817009 2026] [security2:error] [pid 465652:tid 465855] [client 20.197.195.24:3905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/adminfuns.php"] [unique_id "al9YvjzTqJoBC2Mw28-wkwAAAM4"]
[Tue Jul 21 08:32:14.972441 2026] [proxy:error] [pid 465652:tid 465782] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:14.972516 2026] [proxy_http:error] [pid 465652:tid 465782] [client 20.197.195.24:18692] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:14.973578 2026] [proxy:error] [pid 465652:tid 465782] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:14.973608 2026] [proxy_http:error] [pid 465652:tid 465782] [client 20.197.195.24:18692] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:15.033873 2026] [security2:error] [pid 465652:tid 465800] [client 61.1.167.83:55905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YvzzTqJoBC2Mw28-wmAAAAJc"]
[Tue Jul 21 08:32:15.034037 2026] [security2:error] [pid 465652:tid 465800] [client 61.1.167.83:55905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YvzzTqJoBC2Mw28-wmAAAAJc"]
[Tue Jul 21 08:32:15.063486 2026] [security2:error] [pid 465652:tid 465905] [client 4.194.24.143:8256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/alfa.php"] [unique_id "al9YvzzTqJoBC2Mw28-wmQAAAQA"]
[Tue Jul 21 08:32:15.374977 2026] [security2:error] [pid 465652:tid 465790] [client 122.176.100.127:52179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YvzzTqJoBC2Mw28-wpAAAAI0"]
[Tue Jul 21 08:32:15.375265 2026] [security2:error] [pid 465652:tid 465790] [client 122.176.100.127:52179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YvzzTqJoBC2Mw28-wpAAAAI0"]
[Tue Jul 21 08:32:15.794724 2026] [security2:error] [pid 466512:tid 466734] [client 20.197.192.193:65205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/blue.php"] [unique_id "al9YvyKGokixMSfKDOfS-QAAAnA"]
[Tue Jul 21 08:32:15.954310 2026] [security2:error] [pid 465652:tid 465780] [remote 20.153.140.50:52262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.site"] [uri "/wp-login.php"] [unique_id "al9YvzzTqJoBC2Mw28-wrQABAX8"]
[Tue Jul 21 08:32:16.115027 2026] [security2:error] [pid 466512:tid 466712] [client 45.132.227.201:47639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/wp-login.php"] [unique_id "al9YwCKGokixMSfKDOfS_QAAAlo"]
[Tue Jul 21 08:32:16.121668 2026] [security2:error] [pid 465652:tid 465787] [client 4.194.24.143:8449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/amax.php"] [unique_id "al9YwDzTqJoBC2Mw28-wrwAAAIo"]
[Tue Jul 21 08:32:16.124565 2026] [proxy:error] [pid 466512:tid 466677] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:16.124611 2026] [proxy_http:error] [pid 466512:tid 466677] [client 20.197.195.24:57876] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:16.125035 2026] [proxy:error] [pid 466512:tid 466677] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:16.125061 2026] [proxy_http:error] [pid 466512:tid 466677] [client 20.197.195.24:57876] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:16.152631 2026] [security2:error] [pid 466512:tid 466661] [client 20.197.195.24:3926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/goods.php"] [unique_id "al9YwCKGokixMSfKDOfS_wAAAic"]
[Tue Jul 21 08:32:16.182161 2026] [security2:error] [pid 466512:tid 466708] [client 74.7.241.161:52686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.docs.tainux.io"] [uri "/cgi-sys/404.html"] [unique_id "al9YwCKGokixMSfKDOfTAAACVlE"]
[Tue Jul 21 08:32:16.263853 2026] [security2:error] [pid 466512:tid 466668] [client 195.49.128.211:63336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YwCKGokixMSfKDOfTAgAAAi4"]
[Tue Jul 21 08:32:16.264067 2026] [security2:error] [pid 466512:tid 466668] [client 195.49.128.211:63336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YwCKGokixMSfKDOfTAgAAAi4"]
[Tue Jul 21 08:32:16.377165 2026] [security2:error] [pid 466512:tid 466699] [client 103.151.46.103:60769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YwCKGokixMSfKDOfTBQAAAk0"]
[Tue Jul 21 08:32:16.377298 2026] [security2:error] [pid 466512:tid 466699] [client 103.151.46.103:60769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YwCKGokixMSfKDOfTBQAAAk0"]
[Tue Jul 21 08:32:16.487907 2026] [security2:error] [pid 466512:tid 466674] [client 20.197.192.193:5185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wicked.php"] [unique_id "al9YwCKGokixMSfKDOfTCAAAAjQ"]
[Tue Jul 21 08:32:16.719294 2026] [security2:error] [pid 466512:tid 466670] [client 152.59.34.51:56829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YwCKGokixMSfKDOfTCwAAAjA"]
[Tue Jul 21 08:32:16.719409 2026] [security2:error] [pid 466512:tid 466670] [client 152.59.34.51:56829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YwCKGokixMSfKDOfTCwAAAjA"]
[Tue Jul 21 08:32:16.742763 2026] [security2:error] [pid 465652:tid 465670] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YwDzTqJoBC2Mw28-wuQAA3RE"]
[Tue Jul 21 08:32:16.742916 2026] [security2:error] [pid 465652:tid 465870] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YwDzTqJoBC2Mw28-wuQAA3RE"]
[Tue Jul 21 08:32:16.832032 2026] [security2:error] [pid 466512:tid 466686] [client 5.38.115.39:15125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9YwCKGokixMSfKDOfTEAAAAkA"]
[Tue Jul 21 08:32:16.832154 2026] [security2:error] [pid 466512:tid 466686] [client 5.38.115.39:15125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9YwCKGokixMSfKDOfTEAAAAkA"]
[Tue Jul 21 08:32:16.833799 2026] [security2:error] [pid 465652:tid 465879] [client 20.206.105.145:25484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9YwDzTqJoBC2Mw28-wwgAAAOY"]
[Tue Jul 21 08:32:17.052690 2026] [security2:error] [pid 465652:tid 465866] [client 20.197.195.24:57980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/.well-known/about.php"] [unique_id "al9YwTzTqJoBC2Mw28-wxgAAANk"]
[Tue Jul 21 08:32:17.159370 2026] [security2:error] [pid 465652:tid 465902] [client 4.194.24.143:4476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/archive.php"] [unique_id "al9YwTzTqJoBC2Mw28-wxwAAAP0"]
[Tue Jul 21 08:32:17.207395 2026] [security2:error] [pid 465652:tid 465814] [client 14.245.224.124:55377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YwTzTqJoBC2Mw28-wyQAAAKU"]
[Tue Jul 21 08:32:17.207529 2026] [security2:error] [pid 465652:tid 465814] [client 14.245.224.124:55377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YwTzTqJoBC2Mw28-wyQAAAKU"]
[Tue Jul 21 08:32:17.360146 2026] [security2:error] [pid 466512:tid 466745] [client 20.197.195.24:57910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9YwSKGokixMSfKDOfTHAAAAns"]
[Tue Jul 21 08:32:17.482593 2026] [security2:error] [pid 466512:tid 466762] [client 65.21.113.253:42724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YwCKGokixMSfKDOfTEwAAAow"]
[Tue Jul 21 08:32:17.659484 2026] [security2:error] [pid 465652:tid 465797] [client 20.197.195.24:53572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/100.php"] [unique_id "al9YwTzTqJoBC2Mw28-w0AAAAJQ"]
[Tue Jul 21 08:32:17.852775 2026] [security2:error] [pid 466512:tid 466642] [client 20.197.195.24:57975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/wefile.php"] [unique_id "al9YwSKGokixMSfKDOfTHwAAAhQ"]
[Tue Jul 21 08:32:18.133564 2026] [security2:error] [pid 466512:tid 466650] [client 20.197.192.193:46153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/edit.php"] [unique_id "al9YwiKGokixMSfKDOfTIgAAAhw"]
[Tue Jul 21 08:32:18.193838 2026] [security2:error] [pid 466512:tid 466725] [client 4.194.24.143:8488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/as.php"] [unique_id "al9YwiKGokixMSfKDOfTIwAAAmc"]
[Tue Jul 21 08:32:18.369509 2026] [security2:error] [pid 466512:tid 466677] [client 20.197.195.24:6337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/about.php"] [unique_id "al9YwiKGokixMSfKDOfTJAAAAjc"]
[Tue Jul 21 08:32:18.487221 2026] [security2:error] [pid 465652:tid 465690] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YwjzTqJoBC2Mw28-w5wAA9CU"]
[Tue Jul 21 08:32:18.487347 2026] [security2:error] [pid 465652:tid 465893] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YwjzTqJoBC2Mw28-w5wAA9CU"]
[Tue Jul 21 08:32:18.498254 2026] [security2:error] [pid 465652:tid 465839] [client 187.125.243.197:64982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YwjzTqJoBC2Mw28-w6AAAAL4"]
[Tue Jul 21 08:32:18.498368 2026] [security2:error] [pid 465652:tid 465839] [client 187.125.243.197:64982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YwjzTqJoBC2Mw28-w6AAAAL4"]
[Tue Jul 21 08:32:18.718133 2026] [security2:error] [pid 466512:tid 466732] [client 20.197.195.24:18730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9YwiKGokixMSfKDOfTKgAAAm4"]
[Tue Jul 21 08:32:18.798582 2026] [security2:error] [pid 465652:tid 465816] [client 202.179.75.202:46192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YwjzTqJoBC2Mw28-w7gAAAKc"]
[Tue Jul 21 08:32:18.798706 2026] [security2:error] [pid 465652:tid 465816] [client 202.179.75.202:46192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YwjzTqJoBC2Mw28-w7gAAAKc"]
[Tue Jul 21 08:32:19.088025 2026] [security2:error] [pid 466512:tid 466653] [client 20.206.105.145:25558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/like.php"] [unique_id "al9YwyKGokixMSfKDOfTNgAAAh8"]
[Tue Jul 21 08:32:19.223634 2026] [security2:error] [pid 465652:tid 465869] [client 4.194.24.143:30175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/asd.php"] [unique_id "al9YwzzTqJoBC2Mw28-w9gAAANw"]
[Tue Jul 21 08:32:19.242746 2026] [security2:error] [pid 465652:tid 465898] [client 20.197.195.24:6339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/about.php"] [unique_id "al9YwzzTqJoBC2Mw28-w9wAAAPk"]
[Tue Jul 21 08:32:19.270654 2026] [proxy:error] [pid 466512:tid 466655] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:19.270754 2026] [proxy_http:error] [pid 466512:tid 466655] [client 20.197.195.24:18726] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:19.272787 2026] [proxy:error] [pid 466512:tid 466655] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:19.272871 2026] [proxy_http:error] [pid 466512:tid 466655] [client 20.197.195.24:18726] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:19.424109 2026] [security2:error] [pid 465652:tid 465850] [client 20.206.105.145:25552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/.well-known/about.php"] [unique_id "al9YwzzTqJoBC2Mw28-w-wAAAMk"]
[Tue Jul 21 08:32:19.453502 2026] [security2:error] [pid 466512:tid 466716] [client 65.21.113.253:42724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YwiKGokixMSfKDOfTMwAAAl4"]
[Tue Jul 21 08:32:19.503860 2026] [proxy:error] [pid 465652:tid 465860] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:19.503945 2026] [proxy_http:error] [pid 465652:tid 465860] [client 20.197.195.24:57862] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:19.504737 2026] [proxy:error] [pid 465652:tid 465860] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:19.504784 2026] [proxy_http:error] [pid 465652:tid 465860] [client 20.197.195.24:57862] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:19.668920 2026] [security2:error] [pid 466512:tid 466670] [client 5.31.193.106:1820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YwyKGokixMSfKDOfTRQAAAjA"]
[Tue Jul 21 08:32:19.669032 2026] [security2:error] [pid 466512:tid 466670] [client 5.31.193.106:1820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YwyKGokixMSfKDOfTRQAAAjA"]
[Tue Jul 21 08:32:19.870963 2026] [security2:error] [pid 466512:tid 466642] [client 20.197.195.24:17045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9YwyKGokixMSfKDOfTSwAAAhQ"]
[Tue Jul 21 08:32:20.002292 2026] [security2:error] [pid 466512:tid 466734] [client 20.197.195.24:57946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/8.php"] [unique_id "al9YxCKGokixMSfKDOfTTQAAAnA"]
[Tue Jul 21 08:32:20.169783 2026] [security2:error] [pid 466512:tid 466755] [client 20.197.195.24:3847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/admin.php"] [unique_id "al9YxCKGokixMSfKDOfTUQAAAoU"]
[Tue Jul 21 08:32:20.257983 2026] [security2:error] [pid 466512:tid 466671] [client 4.194.24.143:8877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/assets/class-wp-http-client.php"] [unique_id "al9YxCKGokixMSfKDOfTUgAAAjE"]
[Tue Jul 21 08:32:20.356575 2026] [security2:error] [pid 465652:tid 465833] [client 20.197.195.24:57969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9YxDzTqJoBC2Mw28-xDwAAALg"]
[Tue Jul 21 08:32:20.360871 2026] [security2:error] [pid 466512:tid 466664] [client 20.206.105.145:25542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9YxCKGokixMSfKDOfTVAAAAio"]
[Tue Jul 21 08:32:20.531615 2026] [security2:error] [pid 466512:tid 466768] [client 20.197.195.24:6294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/admin.php"] [unique_id "al9YxCKGokixMSfKDOfTWAAAApI"]
[Tue Jul 21 08:32:20.783240 2026] [security2:error] [pid 465652:tid 465864] [client 20.197.195.24:17073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/f6.php"] [unique_id "al9YxDzTqJoBC2Mw28-xFgAAANc"]
[Tue Jul 21 08:32:20.801666 2026] [core:alert] [pid 466512:tid 466720] [client 57.141.18.93:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:32:20.963084 2026] [security2:error] [pid 466512:tid 466653] [client 173.252.95.12:37166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9YxCKGokixMSfKDOfTZQAAAh8"]
[Tue Jul 21 08:32:21.078674 2026] [security2:error] [pid 465652:tid 465692] [remote 67.20.76.238:27766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.76.20.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9YxDzTqJoBC2Mw28-xBwAAoyc"]
[Tue Jul 21 08:32:21.099039 2026] [security2:error] [pid 465652:tid 465834] [client 34.53.191.165:53725] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "triaxion.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9YxTzTqJoBC2Mw28-xHgAAALk"]
[Tue Jul 21 08:32:21.211900 2026] [security2:error] [pid 466512:tid 466753] [client 20.197.195.24:17071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/inputs.php"] [unique_id "al9YxSKGokixMSfKDOfTaQAAAoM"]
[Tue Jul 21 08:32:21.265172 2026] [security2:error] [pid 466512:tid 466707] [client 20.197.195.24:6397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/themes.php"] [unique_id "al9YxSKGokixMSfKDOfTagAAAlU"]
[Tue Jul 21 08:32:21.295739 2026] [security2:error] [pid 466512:tid 466655] [client 4.194.24.143:8480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/atomlib.php"] [unique_id "al9YxSKGokixMSfKDOfTawAAAiE"]
[Tue Jul 21 08:32:21.304787 2026] [security2:error] [pid 466512:tid 466686] [client 65.21.113.253:42724] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9YxCKGokixMSfKDOfTYwAAAkA"]
[Tue Jul 21 08:32:21.509748 2026] [security2:error] [pid 466512:tid 466676] [client 20.197.192.193:5601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/kua.php"] [unique_id "al9YxSKGokixMSfKDOfTbgAAAjY"]
[Tue Jul 21 08:32:21.566211 2026] [security2:error] [pid 465652:tid 465839] [client 20.197.195.24:6643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/inputs.php"] [unique_id "al9YxTzTqJoBC2Mw28-xKAAAAL4"]
[Tue Jul 21 08:32:21.603960 2026] [autoindex:error] [pid 465652:tid 465848] [client 20.197.195.24:6356] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:21.712075 2026] [log_config:warn] [pid 419508:tid 419674] (32)Broken pipe: [client 186.219.143.42:13492] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:32:21.712093 2026] [log_config:warn] [pid 419508:tid 419674] (32)Broken pipe: [client 186.219.143.42:13492] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:32:21.787842 2026] [security2:error] [pid 466512:tid 466724] [client 20.197.195.24:57869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/classwithtostring.php"] [unique_id "al9YxSKGokixMSfKDOfTdAAAAmY"]
[Tue Jul 21 08:32:21.932108 2026] [security2:error] [pid 465652:tid 465831] [client 34.53.191.165:49755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.191.53.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triaxion.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YxTzTqJoBC2Mw28-xMAAAALY"]
[Tue Jul 21 08:32:21.958761 2026] [security2:error] [pid 465652:tid 465908] [client 20.197.195.24:6356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/.well-known/about.php"] [unique_id "al9YxTzTqJoBC2Mw28-xMQAAAQM"]
[Tue Jul 21 08:32:22.069151 2026] [security2:error] [pid 465652:tid 465740] [remote 68.178.160.25:46256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9YxjzTqJoBC2Mw28-xNQAAilc"]
[Tue Jul 21 08:32:22.127028 2026] [security2:error] [pid 466512:tid 466687] [client 20.197.195.24:57935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9YxiKGokixMSfKDOfTegAAAkE"]
[Tue Jul 21 08:32:22.241967 2026] [security2:error] [pid 466512:tid 466718] [client 223.181.60.88:5904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YxiKGokixMSfKDOfTfgAAAmA"]
[Tue Jul 21 08:32:22.242270 2026] [security2:error] [pid 466512:tid 466718] [client 223.181.60.88:5904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9YxiKGokixMSfKDOfTfgAAAmA"]
[Tue Jul 21 08:32:22.303923 2026] [security2:error] [pid 466512:tid 466698] [client 20.197.192.193:5585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/ez.php"] [unique_id "al9YxiKGokixMSfKDOfTgAAAAkw"]
[Tue Jul 21 08:32:22.326870 2026] [security2:error] [pid 466512:tid 466754] [client 4.194.24.143:4426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9YxiKGokixMSfKDOfTgQAAAoQ"]
[Tue Jul 21 08:32:22.342586 2026] [security2:error] [pid 466512:tid 466733] [client 20.197.195.24:18712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/wp-blog.php"] [unique_id "al9YxiKGokixMSfKDOfTggAAAm8"]
[Tue Jul 21 08:32:22.392677 2026] [security2:error] [pid 466512:tid 466719] [client 195.49.128.211:55360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YxiKGokixMSfKDOfTgwAAAmE"]
[Tue Jul 21 08:32:22.392821 2026] [security2:error] [pid 466512:tid 466719] [client 195.49.128.211:55360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9YxiKGokixMSfKDOfTgwAAAmE"]
[Tue Jul 21 08:32:22.569723 2026] [proxy:error] [pid 465652:tid 465897] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:22.569800 2026] [proxy_http:error] [pid 465652:tid 465897] [client 20.197.195.24:18715] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:22.570380 2026] [proxy:error] [pid 465652:tid 465897] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:22.570406 2026] [proxy_http:error] [pid 465652:tid 465897] [client 20.197.195.24:18715] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:22.744202 2026] [security2:error] [pid 466512:tid 466655] [client 20.206.105.145:25117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/pucci.php"] [unique_id "al9YxiKGokixMSfKDOfTjgAAAiE"]
[Tue Jul 21 08:32:22.765497 2026] [security2:error] [pid 466512:tid 466730] [client 150.129.202.39:12686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YxiKGokixMSfKDOfTkQAAAmw"]
[Tue Jul 21 08:32:22.765807 2026] [security2:error] [pid 466512:tid 466730] [client 150.129.202.39:12686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YxiKGokixMSfKDOfTkQAAAmw"]
[Tue Jul 21 08:32:23.012081 2026] [security2:error] [pid 466512:tid 466734] [client 20.197.195.24:57893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9YxyKGokixMSfKDOfTlwAAAnA"]
[Tue Jul 21 08:32:23.072652 2026] [security2:error] [pid 465652:tid 465890] [client 20.197.195.24:3880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9YxzzTqJoBC2Mw28-xQwAAAPE"]
[Tue Jul 21 08:32:23.166964 2026] [security2:error] [pid 466512:tid 466725] [client 20.197.195.24:57915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/ms-edit.php"] [unique_id "al9YxyKGokixMSfKDOfTmgAAAmc"]
[Tue Jul 21 08:32:23.316487 2026] [security2:error] [pid 466512:tid 466600] [remote 5.202.15.246:34544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.15.202.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiasaudeplena.com.br.ciclododinheiro.com"] [uri "/wp-login.php"] [unique_id "al9YxyKGokixMSfKDOfTngACa1c"]
[Tue Jul 21 08:32:23.359402 2026] [security2:error] [pid 465652:tid 465808] [client 4.194.24.143:4472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/av.php"] [unique_id "al9YxzzTqJoBC2Mw28-xTAAAAJ8"]
[Tue Jul 21 08:32:23.625711 2026] [security2:error] [pid 466512:tid 466728] [client 152.59.181.104:58393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YxyKGokixMSfKDOfTowAAAmo"]
[Tue Jul 21 08:32:23.625865 2026] [security2:error] [pid 466512:tid 466728] [client 152.59.181.104:58393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YxyKGokixMSfKDOfTowAAAmo"]
[Tue Jul 21 08:32:23.826673 2026] [security2:error] [pid 466512:tid 466679] [client 20.197.192.193:5992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/fz.php"] [unique_id "al9YxyKGokixMSfKDOfTqAAAAjk"]
[Tue Jul 21 08:32:23.914638 2026] [security2:error] [pid 466512:tid 466718] [client 20.197.195.24:57959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9YxyKGokixMSfKDOfTqQAAAmA"]
[Tue Jul 21 08:32:24.131855 2026] [security2:error] [pid 466512:tid 466739] [client 20.197.192.193:43806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/byp8.php"] [unique_id "al9YyCKGokixMSfKDOfTqgAAAnU"]
[Tue Jul 21 08:32:24.185777 2026] [security2:error] [pid 466512:tid 466670] [client 117.213.202.34:61625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YyCKGokixMSfKDOfTrQAAAjA"]
[Tue Jul 21 08:32:24.186776 2026] [security2:error] [pid 466512:tid 466670] [client 117.213.202.34:61625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YyCKGokixMSfKDOfTrQAAAjA"]
[Tue Jul 21 08:32:24.211457 2026] [security2:error] [pid 465652:tid 465891] [client 20.197.195.24:3939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wefile.php"] [unique_id "al9YyDzTqJoBC2Mw28-xVQAAAPI"]
[Tue Jul 21 08:32:24.222943 2026] [proxy:error] [pid 465652:tid 465859] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:24.222989 2026] [proxy_http:error] [pid 465652:tid 465859] [client 20.197.195.24:17069] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:24.223481 2026] [proxy:error] [pid 465652:tid 465859] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:24.223503 2026] [proxy_http:error] [pid 465652:tid 465859] [client 20.197.195.24:17069] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:24.399308 2026] [security2:error] [pid 466512:tid 466731] [client 4.194.24.143:8840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/b.php"] [unique_id "al9YyCKGokixMSfKDOfTsQAAAm0"]
[Tue Jul 21 08:32:24.614430 2026] [security2:error] [pid 465652:tid 465834] [client 20.197.195.24:57963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9YyDzTqJoBC2Mw28-xWwAAALk"]
[Tue Jul 21 08:32:24.980294 2026] [security2:error] [pid 465652:tid 465839] [client 128.127.105.184:57108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9YyDzTqJoBC2Mw28-xYQAAAL4"]
[Tue Jul 21 08:32:24.980418 2026] [security2:error] [pid 465652:tid 465839] [client 128.127.105.184:57108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9YyDzTqJoBC2Mw28-xYQAAAL4"]
[Tue Jul 21 08:32:25.000861 2026] [proxy:error] [pid 465652:tid 465832] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:25.000941 2026] [proxy_http:error] [pid 465652:tid 465832] [client 20.197.195.24:17055] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:25.001540 2026] [proxy:error] [pid 465652:tid 465832] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:25.001564 2026] [proxy_http:error] [pid 465652:tid 465832] [client 20.197.195.24:17055] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:25.008596 2026] [security2:error] [pid 465652:tid 465826] [client 49.144.66.253:32107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YyTzTqJoBC2Mw28-xYwAAALE"]
[Tue Jul 21 08:32:25.008724 2026] [security2:error] [pid 465652:tid 465826] [client 49.144.66.253:32107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9YyTzTqJoBC2Mw28-xYwAAALE"]
[Tue Jul 21 08:32:25.079328 2026] [security2:error] [pid 466512:tid 466750] [client 20.197.195.24:15699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9YySKGokixMSfKDOfTwAAAAoA"]
[Tue Jul 21 08:32:25.264949 2026] [security2:error] [pid 465652:tid 465857] [client 14.97.58.74:49184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YyTzTqJoBC2Mw28-xaQAAANA"]
[Tue Jul 21 08:32:25.265181 2026] [security2:error] [pid 465652:tid 465857] [client 14.97.58.74:49184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YyTzTqJoBC2Mw28-xaQAAANA"]
[Tue Jul 21 08:32:25.427845 2026] [security2:error] [pid 466512:tid 466725] [client 4.194.24.143:4452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/backup.php"] [unique_id "al9YySKGokixMSfKDOfTywAAAmc"]
[Tue Jul 21 08:32:25.460211 2026] [security2:error] [pid 466512:tid 466717] [client 20.206.105.145:25566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wp-temp.php"] [unique_id "al9YySKGokixMSfKDOfTzAAAAl8"]
[Tue Jul 21 08:32:25.486667 2026] [security2:error] [pid 466512:tid 466652] [client 156.245.246.131:63549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.246.245.156.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/index.php"] [unique_id "al9YyCKGokixMSfKDOfTsgAAAh4"], referer: https://tracyacademy.com.br
[Tue Jul 21 08:32:25.817829 2026] [security2:error] [pid 465652:tid 465849] [client 122.176.100.127:52679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YyTzTqJoBC2Mw28-xbQAAAMg"]
[Tue Jul 21 08:32:25.817979 2026] [security2:error] [pid 465652:tid 465849] [client 122.176.100.127:52679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9YyTzTqJoBC2Mw28-xbQAAAMg"]
[Tue Jul 21 08:32:25.841033 2026] [security2:error] [pid 465652:tid 465848] [client 216.73.160.175:41219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9YyTzTqJoBC2Mw28-xbgAAAMc"]
[Tue Jul 21 08:32:26.010052 2026] [security2:error] [pid 466512:tid 466739] [client 34.53.191.165:52959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.191.53.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triaxion.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YyiKGokixMSfKDOfT2QAAAnU"]
[Tue Jul 21 08:32:26.010214 2026] [security2:error] [pid 466512:tid 466739] [client 34.53.191.165:52959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "triaxion.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YyiKGokixMSfKDOfT2QAAAnU"]
[Tue Jul 21 08:32:26.053619 2026] [proxy:error] [pid 465652:tid 465846] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:26.053710 2026] [proxy_http:error] [pid 465652:tid 465846] [client 20.197.195.24:57929] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:26.054700 2026] [proxy:error] [pid 465652:tid 465846] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:26.054741 2026] [proxy_http:error] [pid 465652:tid 465846] [client 20.197.195.24:57929] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:26.067885 2026] [security2:error] [pid 466512:tid 466651] [client 20.197.192.193:65179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/user.php"] [unique_id "al9YyiKGokixMSfKDOfT2gAAAh0"]
[Tue Jul 21 08:32:26.294161 2026] [autoindex:error] [pid 466512:tid 466757] [client 20.197.195.24:16025] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:26.407438 2026] [autoindex:error] [pid 466512:tid 466644] [client 20.197.195.24:16025] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:26.416293 2026] [security2:error] [pid 466512:tid 466708] [client 20.197.195.24:16025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9YyiKGokixMSfKDOfT4gAAAlY"]
[Tue Jul 21 08:32:26.502033 2026] [security2:error] [pid 466512:tid 466663] [client 4.194.24.143:8878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/baio/class-wp-http-client.php"] [unique_id "al9YyiKGokixMSfKDOfT4wAAAik"]
[Tue Jul 21 08:32:26.509676 2026] [security2:error] [pid 466512:tid 466585] [remote 159.65.81.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "falarmelhor.com.br"] [uri "/wp-login.php"] [unique_id "al9YySKGokixMSfKDOfTzgACGkg"]
[Tue Jul 21 08:32:26.851753 2026] [security2:error] [pid 466512:tid 466672] [client 195.49.128.211:63933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YyiKGokixMSfKDOfT7QAAAjI"]
[Tue Jul 21 08:32:26.851890 2026] [security2:error] [pid 466512:tid 466672] [client 195.49.128.211:63933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9YyiKGokixMSfKDOfT7QAAAjI"]
[Tue Jul 21 08:32:26.909905 2026] [security2:error] [pid 466512:tid 466767] [client 20.197.195.24:6381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/8.php"] [unique_id "al9YyiKGokixMSfKDOfT7gAAApE"]
[Tue Jul 21 08:32:27.102999 2026] [security2:error] [pid 466512:tid 466730] [client 103.151.46.103:61266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YyyKGokixMSfKDOfT8wAAAmw"]
[Tue Jul 21 08:32:27.103108 2026] [security2:error] [pid 466512:tid 466730] [client 103.151.46.103:61266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9YyyKGokixMSfKDOfT8wAAAmw"]
[Tue Jul 21 08:32:27.170993 2026] [security2:error] [pid 466512:tid 466728] [client 20.197.195.24:18713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/abcd.php"] [unique_id "al9YyyKGokixMSfKDOfT9AAAAmo"]
[Tue Jul 21 08:32:27.367265 2026] [security2:error] [pid 466512:tid 466525] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YyyKGokixMSfKDOfT-AACjAw"]
[Tue Jul 21 08:32:27.367522 2026] [security2:error] [pid 466512:tid 466762] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9YyyKGokixMSfKDOfT-AACjAw"]
[Tue Jul 21 08:32:27.459601 2026] [security2:error] [pid 466512:tid 466737] [client 20.197.195.24:6346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9YyyKGokixMSfKDOfT-gAAAnM"]
[Tue Jul 21 08:32:27.554450 2026] [security2:error] [pid 466512:tid 466694] [client 5.38.115.39:62567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9YyyKGokixMSfKDOfT_AAAAkg"]
[Tue Jul 21 08:32:27.558787 2026] [security2:error] [pid 466512:tid 466652] [client 4.194.24.143:8266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/bak.php"] [unique_id "al9YyyKGokixMSfKDOfT_QAAAh4"]
[Tue Jul 21 08:32:27.560022 2026] [security2:error] [pid 466512:tid 466694] [client 5.38.115.39:62567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9YyyKGokixMSfKDOfT_AAAAkg"]
[Tue Jul 21 08:32:27.925738 2026] [security2:error] [pid 466512:tid 466719] [client 14.245.224.124:55861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YyyKGokixMSfKDOfUCgAAAmE"]
[Tue Jul 21 08:32:27.925834 2026] [security2:error] [pid 466512:tid 466719] [client 14.245.224.124:55861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9YyyKGokixMSfKDOfUCgAAAmE"]
[Tue Jul 21 08:32:28.143126 2026] [security2:error] [pid 466512:tid 466755] [client 20.197.195.24:57947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/file15.php"] [unique_id "al9YzCKGokixMSfKDOfUEAAAAoU"]
[Tue Jul 21 08:32:28.432211 2026] [security2:error] [pid 466512:tid 466724] [client 20.197.195.24:3877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/f6.php"] [unique_id "al9YzCKGokixMSfKDOfUEgAAAmY"]
[Tue Jul 21 08:32:28.591065 2026] [security2:error] [pid 466512:tid 466712] [client 4.194.24.143:17043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/bdkr28wp.php"] [unique_id "al9YzCKGokixMSfKDOfUFQAAAlo"]
[Tue Jul 21 08:32:28.619834 2026] [security2:error] [pid 466512:tid 466743] [client 20.197.192.193:43814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/wp-signup.php"] [unique_id "al9YzCKGokixMSfKDOfUFgAAAnk"]
[Tue Jul 21 08:32:28.688609 2026] [security2:error] [pid 466512:tid 466757] [client 152.59.34.51:57319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YzCKGokixMSfKDOfUFwAAAoc"]
[Tue Jul 21 08:32:28.692671 2026] [security2:error] [pid 466512:tid 466757] [client 152.59.34.51:57319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9YzCKGokixMSfKDOfUFwAAAoc"]
[Tue Jul 21 08:32:28.821098 2026] [security2:error] [pid 465652:tid 465688] [remote 34.78.192.119:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "concielo.com.br"] [uri "/"] [unique_id "al9YzDzTqJoBC2Mw28-xmgAA6SM"]
[Tue Jul 21 08:32:28.934355 2026] [security2:error] [pid 466512:tid 466656] [client 5.31.193.106:58561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YzCKGokixMSfKDOfUHQAAAiI"]
[Tue Jul 21 08:32:28.934518 2026] [security2:error] [pid 466512:tid 466656] [client 5.31.193.106:58561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9YzCKGokixMSfKDOfUHQAAAiI"]
[Tue Jul 21 08:32:28.984827 2026] [security2:error] [pid 465652:tid 465801] [client 20.197.195.24:16035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/inputs.php"] [unique_id "al9YzDzTqJoBC2Mw28-xoAAAAJg"]
[Tue Jul 21 08:32:29.024440 2026] [security2:error] [pid 466512:tid 466758] [client 187.125.243.197:65482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YzSKGokixMSfKDOfUIAAAAog"]
[Tue Jul 21 08:32:29.024544 2026] [security2:error] [pid 466512:tid 466758] [client 187.125.243.197:65482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9YzSKGokixMSfKDOfUIAAAAog"]
[Tue Jul 21 08:32:29.053570 2026] [security2:error] [pid 465652:tid 465657] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YzTzTqJoBC2Mw28-xogAAuQQ"]
[Tue Jul 21 08:32:29.053796 2026] [security2:error] [pid 465652:tid 465834] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9YzTzTqJoBC2Mw28-xogAAuQQ"]
[Tue Jul 21 08:32:29.266443 2026] [security2:error] [pid 465652:tid 465826] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9YzTzTqJoBC2Mw28-xpAAAALE"]
[Tue Jul 21 08:32:29.278362 2026] [security2:error] [pid 466512:tid 466694] [client 20.197.195.24:15693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/inputs.php"] [unique_id "al9YzSKGokixMSfKDOfUJQAAAkg"]
[Tue Jul 21 08:32:29.462249 2026] [core:error] [pid 466512:tid 466560] [remote 52.167.144.209:15735] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:32:29.462279 2026] [core:error] [pid 466512:tid 466560] [remote 52.167.144.209:15735] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:32:29.571249 2026] [security2:error] [pid 465652:tid 465845] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9YzTzTqJoBC2Mw28-xqQAAAMQ"]
[Tue Jul 21 08:32:29.624026 2026] [security2:error] [pid 466512:tid 466647] [client 4.194.24.143:8865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/bgymj.php"] [unique_id "al9YzSKGokixMSfKDOfUMAAAAhk"]
[Tue Jul 21 08:32:29.654419 2026] [security2:error] [pid 466512:tid 466652] [client 202.179.75.202:48038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YzSKGokixMSfKDOfUMQAAAh4"]
[Tue Jul 21 08:32:29.654535 2026] [security2:error] [pid 466512:tid 466652] [client 202.179.75.202:48038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9YzSKGokixMSfKDOfUMQAAAh4"]
[Tue Jul 21 08:32:29.770309 2026] [security2:error] [pid 465652:tid 465791] [client 20.197.195.24:57900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/jp.php"] [unique_id "al9YzTzTqJoBC2Mw28-xqwAAAI4"]
[Tue Jul 21 08:32:29.831028 2026] [security2:error] [pid 466512:tid 466650] [client 61.1.167.83:56421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YzSKGokixMSfKDOfUNAAAAhw"]
[Tue Jul 21 08:32:29.831144 2026] [security2:error] [pid 466512:tid 466650] [client 61.1.167.83:56421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9YzSKGokixMSfKDOfUNAAAAhw"]
[Tue Jul 21 08:32:29.875267 2026] [security2:error] [pid 465652:tid 465849] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/xyn.php"] [unique_id "al9YzTzTqJoBC2Mw28-xrAAAAMg"]
[Tue Jul 21 08:32:29.984161 2026] [security2:error] [pid 466512:tid 466724] [client 20.197.195.24:16055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/classwithtostring.php"] [unique_id "al9YzSKGokixMSfKDOfURAAAAmY"]
[Tue Jul 21 08:32:30.043897 2026] [security2:error] [pid 466512:tid 466760] [client 20.197.192.193:65184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/ops.php"] [unique_id "al9YziKGokixMSfKDOfURwAAAoo"]
[Tue Jul 21 08:32:30.087523 2026] [core:error] [pid 466512:tid 466551] [remote 52.167.144.209:15735] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:32:30.087541 2026] [core:error] [pid 466512:tid 466551] [remote 52.167.144.209:15735] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:32:30.182393 2026] [security2:error] [pid 466512:tid 466669] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/patie.php"] [unique_id "al9YziKGokixMSfKDOfUTgAAAi8"]
[Tue Jul 21 08:32:30.301082 2026] [security2:error] [pid 466512:tid 466744] [client 20.206.105.145:25547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/xmu.php"] [unique_id "al9YziKGokixMSfKDOfUWQAAAno"]
[Tue Jul 21 08:32:30.462434 2026] [security2:error] [pid 465652:tid 465844] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/aa.php"] [unique_id "al9YzjzTqJoBC2Mw28-xugAAAMM"]
[Tue Jul 21 08:32:30.645797 2026] [security2:error] [pid 466512:tid 466685] [client 74.7.175.150:47686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.patacureshop.siteecommerceshop.com"] [uri "/index.php"] [unique_id "al9YziKGokixMSfKDOfUWAACPwY"]
[Tue Jul 21 08:32:30.698587 2026] [security2:error] [pid 466512:tid 466754] [client 4.194.24.143:8866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/biufile.php"] [unique_id "al9YziKGokixMSfKDOfUZQAAAoQ"]
[Tue Jul 21 08:32:30.804169 2026] [security2:error] [pid 465652:tid 465787] [client 20.197.192.193:65168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/csa.php"] [unique_id "al9YzjzTqJoBC2Mw28-xwAAAAIo"]
[Tue Jul 21 08:32:30.848034 2026] [security2:error] [pid 466512:tid 466745] [client 20.197.195.24:6319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9YziKGokixMSfKDOfUZgAAAns"]
[Tue Jul 21 08:32:30.934493 2026] [security2:error] [pid 465652:tid 465850] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/xwpg.php"] [unique_id "al9YzjzTqJoBC2Mw28-xxQAAAMk"]
[Tue Jul 21 08:32:31.238545 2026] [security2:error] [pid 465652:tid 465868] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/ops.php"] [unique_id "al9YzzzTqJoBC2Mw28-xzAAAANs"]
[Tue Jul 21 08:32:31.392111 2026] [security2:error] [pid 466512:tid 466650] [client 20.197.195.24:6352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-blog.php"] [unique_id "al9YzyKGokixMSfKDOfUbAAAAhw"]
[Tue Jul 21 08:32:31.511067 2026] [security2:error] [pid 466512:tid 466727] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/mac.php"] [unique_id "al9YzyKGokixMSfKDOfUcwAAAmk"]
[Tue Jul 21 08:32:31.570719 2026] [security2:error] [pid 465652:tid 465897] [client 102.209.137.222:64471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.137.209.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9YzzzTqJoBC2Mw28-xzgAAAPg"]
[Tue Jul 21 08:32:31.570976 2026] [security2:error] [pid 465652:tid 465897] [client 102.209.137.222:64471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9YzzzTqJoBC2Mw28-xzgAAAPg"]
[Tue Jul 21 08:32:31.725886 2026] [security2:error] [pid 465652:tid 465861] [client 4.194.24.143:17026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/bless.php"] [unique_id "al9YzzzTqJoBC2Mw28-x0gAAANQ"]
[Tue Jul 21 08:32:31.777471 2026] [security2:error] [pid 465652:tid 465797] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/mg.php"] [unique_id "al9YzzzTqJoBC2Mw28-x1QAAAJQ"]
[Tue Jul 21 08:32:31.796681 2026] [security2:error] [pid 466512:tid 466734] [client 74.249.245.134:54939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/gg.php"] [unique_id "al9YzyKGokixMSfKDOfUewAAAnA"]
[Tue Jul 21 08:32:31.887752 2026] [security2:error] [pid 466512:tid 466712] [client 51.222.168.112:26928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.reabfit.com.br"] [uri "/robots.txt"] [unique_id "al9YzyKGokixMSfKDOfUfQAAAlo"]
[Tue Jul 21 08:32:31.887892 2026] [security2:error] [pid 466512:tid 466712] [client 51.222.168.112:26928] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.reabfit.com.br"] [uri "/robots.txt"] [unique_id "al9YzyKGokixMSfKDOfUfQAAAlo"]
[Tue Jul 21 08:32:31.936429 2026] [security2:error] [pid 466512:tid 466688] [client 74.7.241.189:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.roseoliveirarose.com.br"] [uri "/index.php"] [unique_id "al9YzyKGokixMSfKDOfUdwAAAkI"]
[Tue Jul 21 08:32:31.936996 2026] [security2:error] [pid 466512:tid 466735] [client 74.7.241.189:38262] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.roseoliveirarose.com.br"] [uri "/robots.txt"] [unique_id "al9YzyKGokixMSfKDOfUdQAAAnE"]
[Tue Jul 21 08:32:31.998599 2026] [security2:error] [pid 466512:tid 466687] [client 20.197.195.24:57925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/f35.php"] [unique_id "al9YzyKGokixMSfKDOfUgQAAAkE"]
[Tue Jul 21 08:32:32.009269 2026] [autoindex:error] [pid 466512:tid 466692] [client 20.197.195.24:15689] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:32.017721 2026] [security2:error] [pid 466512:tid 466707] [client 20.197.195.24:15689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Y0CKGokixMSfKDOfUggAAAlU"]
[Tue Jul 21 08:32:32.051532 2026] [security2:error] [pid 466512:tid 466713] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-post-data.php"] [unique_id "al9Y0CKGokixMSfKDOfUhAAAAls"]
[Tue Jul 21 08:32:32.365901 2026] [security2:error] [pid 466512:tid 466759] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/pucci.php"] [unique_id "al9Y0CKGokixMSfKDOfUjQAAAok"]
[Tue Jul 21 08:32:32.420370 2026] [security2:error] [pid 465652:tid 465885] [client 20.197.192.193:43811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/min.php"] [unique_id "al9Y0DzTqJoBC2Mw28-x4AAAAOw"]
[Tue Jul 21 08:32:32.511698 2026] [security2:error] [pid 465652:tid 465803] [client 20.197.195.24:15721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ms-edit.php"] [unique_id "al9Y0DzTqJoBC2Mw28-x4wAAAJo"]
[Tue Jul 21 08:32:32.653653 2026] [security2:error] [pid 466512:tid 466726] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/black.php"] [unique_id "al9Y0CKGokixMSfKDOfUlQAAAmg"]
[Tue Jul 21 08:32:32.789092 2026] [security2:error] [pid 466512:tid 466682] [client 4.194.24.143:4471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/bolt.php"] [unique_id "al9Y0CKGokixMSfKDOfUlwAAAjw"]
[Tue Jul 21 08:32:32.820000 2026] [autoindex:error] [pid 465652:tid 465747] [remote 179.165.184.52:65531] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/?pag=aluno_chamada
[Tue Jul 21 08:32:32.935892 2026] [security2:error] [pid 466512:tid 466765] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/zlece.php"] [unique_id "al9Y0CKGokixMSfKDOfUmwAAAo8"]
[Tue Jul 21 08:32:33.009790 2026] [security2:error] [pid 466512:tid 466752] [client 195.49.128.211:55977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Y0SKGokixMSfKDOfUnAAAAoI"]
[Tue Jul 21 08:32:33.009891 2026] [security2:error] [pid 466512:tid 466752] [client 195.49.128.211:55977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Y0SKGokixMSfKDOfUnAAAAoI"]
[Tue Jul 21 08:32:33.109256 2026] [security2:error] [pid 466512:tid 466688] [client 20.206.105.145:25475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9Y0SKGokixMSfKDOfUoAAAAkI"]
[Tue Jul 21 08:32:33.156705 2026] [security2:error] [pid 466512:tid 466742] [client 173.252.95.37:44170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Y0SKGokixMSfKDOfUoQAAAng"]
[Tue Jul 21 08:32:33.194437 2026] [security2:error] [pid 466512:tid 466704] [client 20.197.195.24:6650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/wp-load.php"] [unique_id "al9Y0SKGokixMSfKDOfUogAAAlI"]
[Tue Jul 21 08:32:33.223092 2026] [security2:error] [pid 466512:tid 466678] [client 89.238.167.134:55686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Y0SKGokixMSfKDOfUowAAAjg"]
[Tue Jul 21 08:32:33.223177 2026] [security2:error] [pid 466512:tid 466678] [client 89.238.167.134:55686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Y0SKGokixMSfKDOfUowAAAjg"]
[Tue Jul 21 08:32:33.229207 2026] [security2:error] [pid 465652:tid 465849] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/vssrs.php"] [unique_id "al9Y0TzTqJoBC2Mw28-x8wAAAMg"]
[Tue Jul 21 08:32:33.278609 2026] [security2:error] [pid 466512:tid 466687] [client 198.244.242.252:21046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.reabfit.com.br"] [uri "/"] [unique_id "al9Y0SKGokixMSfKDOfUpAAAAkE"]
[Tue Jul 21 08:32:33.278840 2026] [security2:error] [pid 466512:tid 466687] [client 198.244.242.252:21046] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.reabfit.com.br"] [uri "/"] [unique_id "al9Y0SKGokixMSfKDOfUpAAAAkE"]
[Tue Jul 21 08:32:33.311330 2026] [security2:error] [pid 466512:tid 466692] [client 213.152.186.163:48566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Y0SKGokixMSfKDOfUpQAAAkY"]
[Tue Jul 21 08:32:33.311597 2026] [security2:error] [pid 466512:tid 466692] [client 213.152.186.163:48566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Y0SKGokixMSfKDOfUpQAAAkY"]
[Tue Jul 21 08:32:33.346915 2026] [core:error] [pid 466512:tid 466615] [remote 52.167.144.173:15014] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:32:33.346945 2026] [core:error] [pid 466512:tid 466615] [remote 52.167.144.173:15014] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:32:33.397354 2026] [security2:error] [pid 465652:tid 465827] [client 20.197.192.193:43778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/term.php"] [unique_id "al9Y0TzTqJoBC2Mw28-x9wAAALI"]
[Tue Jul 21 08:32:33.437910 2026] [security2:error] [pid 465652:tid 465804] [client 150.129.202.39:13139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y0TzTqJoBC2Mw28-x-gAAAJs"]
[Tue Jul 21 08:32:33.438035 2026] [security2:error] [pid 465652:tid 465804] [client 150.129.202.39:13139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y0TzTqJoBC2Mw28-x-gAAAJs"]
[Tue Jul 21 08:32:33.482847 2026] [security2:error] [pid 466512:tid 466698] [client 20.197.195.24:57920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/xyn.php"] [unique_id "al9Y0SKGokixMSfKDOfUqgAAAkw"]
[Tue Jul 21 08:32:33.482904 2026] [security2:error] [pid 466512:tid 466759] [client 20.197.195.24:6389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Y0SKGokixMSfKDOfUqwAAAok"]
[Tue Jul 21 08:32:33.508785 2026] [security2:error] [pid 466512:tid 466683] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wicked.php"] [unique_id "al9Y0SKGokixMSfKDOfUrAAAAj0"]
[Tue Jul 21 08:32:33.580830 2026] [security2:error] [pid 466512:tid 466758] [client 20.197.192.193:43786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/echkm.php"] [unique_id "al9Y0SKGokixMSfKDOfUrwAAAog"]
[Tue Jul 21 08:32:33.663757 2026] [security2:error] [pid 466512:tid 466681] [client 152.59.181.104:58973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Y0SKGokixMSfKDOfUsAAAAjs"]
[Tue Jul 21 08:32:33.663907 2026] [security2:error] [pid 466512:tid 466681] [client 152.59.181.104:58973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Y0SKGokixMSfKDOfUsAAAAjs"]
[Tue Jul 21 08:32:33.732842 2026] [proxy:error] [pid 466512:tid 466645] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:33.732919 2026] [proxy_http:error] [pid 466512:tid 466645] [client 20.197.195.24:57861] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:33.733496 2026] [proxy:error] [pid 466512:tid 466645] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:33.733522 2026] [proxy_http:error] [pid 466512:tid 466645] [client 20.197.195.24:57861] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:33.798646 2026] [security2:error] [pid 465652:tid 465850] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/24.php"] [unique_id "al9Y0TzTqJoBC2Mw28-yAQAAAMk"]
[Tue Jul 21 08:32:33.812344 2026] [security2:error] [pid 466512:tid 466737] [client 4.194.24.143:5798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/bthil.php"] [unique_id "al9Y0SKGokixMSfKDOfUtwAAAnM"]
[Tue Jul 21 08:32:33.877150 2026] [security2:error] [pid 466512:tid 466720] [client 223.181.60.88:5730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Y0SKGokixMSfKDOfUuwAAAmI"]
[Tue Jul 21 08:32:33.877260 2026] [security2:error] [pid 466512:tid 466720] [client 223.181.60.88:5730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Y0SKGokixMSfKDOfUuwAAAmI"]
[Tue Jul 21 08:32:34.020951 2026] [autoindex:error] [pid 465652:tid 465855] [client 20.197.195.24:3935] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:34.063614 2026] [proxy:error] [pid 465652:tid 465835] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:34.063680 2026] [proxy_http:error] [pid 465652:tid 465835] [client 20.197.195.24:17048] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:34.064447 2026] [proxy:error] [pid 465652:tid 465835] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:34.064487 2026] [proxy_http:error] [pid 465652:tid 465835] [client 20.197.195.24:17048] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:34.089881 2026] [security2:error] [pid 466512:tid 466768] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/xacs.php"] [unique_id "al9Y0iKGokixMSfKDOfUwQAAApI"]
[Tue Jul 21 08:32:34.220261 2026] [security2:error] [pid 466512:tid 466743] [client 20.197.195.24:17072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/ccc.php"] [unique_id "al9Y0iKGokixMSfKDOfUxAAAAnk"]
[Tue Jul 21 08:32:34.279726 2026] [security2:error] [pid 465652:tid 465806] [client 20.197.195.24:3935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Y0jzTqJoBC2Mw28-yCwAAAJ0"]
[Tue Jul 21 08:32:34.371671 2026] [security2:error] [pid 465652:tid 465851] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/zildan.php"] [unique_id "al9Y0jzTqJoBC2Mw28-yEAAAAMo"]
[Tue Jul 21 08:32:34.497918 2026] [security2:error] [pid 466512:tid 466690] [client 20.206.105.145:25596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/puc.php"] [unique_id "al9Y0iKGokixMSfKDOfUygAAAkQ"]
[Tue Jul 21 08:32:34.505870 2026] [security2:error] [pid 466512:tid 466759] [client 20.197.195.24:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/w.php"] [unique_id "al9Y0iKGokixMSfKDOfUywAAAok"]
[Tue Jul 21 08:32:34.662278 2026] [security2:error] [pid 466512:tid 466683] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/csa.php"] [unique_id "al9Y0iKGokixMSfKDOfUzgAAAj0"]
[Tue Jul 21 08:32:34.704030 2026] [security2:error] [pid 465652:tid 465838] [client 117.213.202.34:62235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y0jzTqJoBC2Mw28-yGAAAAL0"]
[Tue Jul 21 08:32:34.704221 2026] [security2:error] [pid 465652:tid 465838] [client 117.213.202.34:62235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y0jzTqJoBC2Mw28-yGAAAAL0"]
[Tue Jul 21 08:32:34.867004 2026] [security2:error] [pid 465652:tid 465815] [client 4.194.24.143:15745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/buy.php"] [unique_id "al9Y0jzTqJoBC2Mw28-yGgAAAKY"]
[Tue Jul 21 08:32:34.880446 2026] [security2:error] [pid 466512:tid 466643] [client 20.197.195.24:57901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Y0iKGokixMSfKDOfU0AAAAhU"]
[Tue Jul 21 08:32:34.954355 2026] [security2:error] [pid 466512:tid 466754] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/w3llscc.php"] [unique_id "al9Y0iKGokixMSfKDOfU0gAAAoQ"]
[Tue Jul 21 08:32:34.978998 2026] [autoindex:error] [pid 465652:tid 465742] [remote 179.165.184.52:65531] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/?pag=chamada_consulta&modal=chamada&chamada=469
[Tue Jul 21 08:32:35.145209 2026] [security2:error] [pid 465652:tid 465908] [client 20.197.195.24:57943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/FWAZ.php"] [unique_id "al9Y0zzTqJoBC2Mw28-yJgAAAQM"]
[Tue Jul 21 08:32:35.244311 2026] [security2:error] [pid 465652:tid 465856] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wpx.php"] [unique_id "al9Y0zzTqJoBC2Mw28-yKAAAAM8"]
[Tue Jul 21 08:32:35.318233 2026] [autoindex:error] [pid 465652:tid 465847] [client 20.197.195.24:3950] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:35.356710 2026] [autoindex:error] [pid 465652:tid 465823] [client 20.197.195.24:3950] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:35.364799 2026] [security2:error] [pid 465652:tid 465849] [client 20.197.195.24:3950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/abcd.php"] [unique_id "al9Y0zzTqJoBC2Mw28-yLAAAAMg"]
[Tue Jul 21 08:32:35.407820 2026] [security2:error] [pid 466512:tid 466659] [client 20.197.195.24:6273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file15.php"] [unique_id "al9Y0yKGokixMSfKDOfU2QAAAiU"]
[Tue Jul 21 08:32:35.437774 2026] [security2:error] [pid 466512:tid 466650] [client 20.197.195.24:6369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/jp.php"] [unique_id "al9Y0yKGokixMSfKDOfU2gAAAhw"]
[Tue Jul 21 08:32:35.483100 2026] [security2:error] [pid 465652:tid 465827] [client 20.197.195.24:3946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/f35.php"] [unique_id "al9Y0zzTqJoBC2Mw28-yMQAAALI"]
[Tue Jul 21 08:32:35.511429 2026] [security2:error] [pid 465652:tid 465874] [client 20.197.192.193:43802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/mac.php"] [unique_id "al9Y0zzTqJoBC2Mw28-yMgAAAOE"]
[Tue Jul 21 08:32:35.536685 2026] [security2:error] [pid 465652:tid 465852] [client 20.197.195.24:6572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/miru1.php"] [unique_id "al9Y0zzTqJoBC2Mw28-yNAAAAMs"]
[Tue Jul 21 08:32:35.543227 2026] [security2:error] [pid 465652:tid 465870] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-css.php"] [unique_id "al9Y0zzTqJoBC2Mw28-yNQAAAN0"]
[Tue Jul 21 08:32:35.668257 2026] [security2:error] [pid 466512:tid 466701] [client 20.197.195.24:2206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-load.php"] [unique_id "al9Y0yKGokixMSfKDOfU3gAAAk8"]
[Tue Jul 21 08:32:35.779439 2026] [security2:error] [pid 466512:tid 466744] [client 20.197.195.24:18735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/aa.php"] [unique_id "al9Y0yKGokixMSfKDOfU3wAAAno"]
[Tue Jul 21 08:32:35.792324 2026] [security2:error] [pid 466512:tid 466656] [client 125.18.144.2:61222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y0yKGokixMSfKDOfU4AAAAiI"]
[Tue Jul 21 08:32:35.792440 2026] [security2:error] [pid 466512:tid 466656] [client 125.18.144.2:61222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y0yKGokixMSfKDOfU4AAAAiI"]
[Tue Jul 21 08:32:35.828380 2026] [security2:error] [pid 465652:tid 465796] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/ho.php"] [unique_id "al9Y0zzTqJoBC2Mw28-yOQAAAJM"]
[Tue Jul 21 08:32:35.872321 2026] [security2:error] [pid 465652:tid 465906] [client 49.144.66.253:32560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Y0zzTqJoBC2Mw28-yOgAAAQE"]
[Tue Jul 21 08:32:35.872491 2026] [security2:error] [pid 465652:tid 465906] [client 49.144.66.253:32560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Y0zzTqJoBC2Mw28-yOgAAAQE"]
[Tue Jul 21 08:32:35.891412 2026] [security2:error] [pid 466512:tid 466660] [client 4.194.24.143:15759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/byp.php"] [unique_id "al9Y0yKGokixMSfKDOfU5AAAAiY"]
[Tue Jul 21 08:32:36.138237 2026] [security2:error] [pid 466512:tid 466734] [client 20.197.195.24:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/122.php"] [unique_id "al9Y1CKGokixMSfKDOfU5QAAAnA"]
[Tue Jul 21 08:32:36.342330 2026] [security2:error] [pid 466512:tid 466714] [client 122.176.100.127:53194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Y1CKGokixMSfKDOfU6QAAAlw"]
[Tue Jul 21 08:32:36.342619 2026] [security2:error] [pid 466512:tid 466714] [client 122.176.100.127:53194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Y1CKGokixMSfKDOfU6QAAAlw"]
[Tue Jul 21 08:32:36.371509 2026] [security2:error] [pid 465652:tid 465798] [client 20.197.195.24:57923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/get.php"] [unique_id "al9Y1DzTqJoBC2Mw28-yQwAAAJU"]
[Tue Jul 21 08:32:36.447339 2026] [security2:error] [pid 466512:tid 466743] [client 20.197.195.24:6541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/as.php"] [unique_id "al9Y1CKGokixMSfKDOfU6wAAAnk"]
[Tue Jul 21 08:32:36.523674 2026] [security2:error] [pid 465652:tid 465853] [client 20.197.195.24:57927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/ccou.php"] [unique_id "al9Y1DzTqJoBC2Mw28-yRwAAAMw"]
[Tue Jul 21 08:32:36.617071 2026] [security2:error] [pid 465652:tid 465820] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/xy.php"] [unique_id "al9Y1DzTqJoBC2Mw28-ySgAAAKs"]
[Tue Jul 21 08:32:36.655721 2026] [security2:error] [pid 466512:tid 466698] [client 20.206.105.145:25550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/themes.php"] [unique_id "al9Y1CKGokixMSfKDOfU9AAAAkw"]
[Tue Jul 21 08:32:36.741460 2026] [security2:error] [pid 466512:tid 466689] [client 20.197.195.24:60615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/w3lls.php"] [unique_id "al9Y1CKGokixMSfKDOfU-AAAAkM"]
[Tue Jul 21 08:32:36.880817 2026] [security2:error] [pid 466512:tid 466754] [client 20.197.195.24:57944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/test1.php"] [unique_id "al9Y1CKGokixMSfKDOfU-wAAAoQ"]
[Tue Jul 21 08:32:36.910634 2026] [security2:error] [pid 465652:tid 465806] [client 4.194.24.143:8858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/bypass.php"] [unique_id "al9Y1DzTqJoBC2Mw28-yTAAAAJ0"]
[Tue Jul 21 08:32:36.919374 2026] [security2:error] [pid 466512:tid 466693] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/loader.php"] [unique_id "al9Y1CKGokixMSfKDOfU_AAAAkc"]
[Tue Jul 21 08:32:36.928032 2026] [security2:error] [pid 466512:tid 466645] [client 85.204.70.92:36648] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Y1CKGokixMSfKDOfU_QAAAhc"]
[Tue Jul 21 08:32:37.051216 2026] [security2:error] [pid 466512:tid 466764] [client 20.197.195.24:57892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/database.php"] [unique_id "al9Y1SKGokixMSfKDOfU_wAAAo4"]
[Tue Jul 21 08:32:37.090251 2026] [security2:error] [pid 466512:tid 466682] [client 74.249.245.134:37729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/sql.php"] [unique_id "al9Y1SKGokixMSfKDOfVAQAAAjw"]
[Tue Jul 21 08:32:37.209990 2026] [security2:error] [pid 466512:tid 466727] [client 20.197.195.24:3908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/xyn.php"] [unique_id "al9Y1SKGokixMSfKDOfVAwAAAmk"]
[Tue Jul 21 08:32:37.226528 2026] [security2:error] [pid 466512:tid 466744] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/spadex.php"] [unique_id "al9Y1SKGokixMSfKDOfVBQAAAno"]
[Tue Jul 21 08:32:37.387895 2026] [security2:error] [pid 466512:tid 466700] [client 20.197.195.24:18737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/file.php"] [unique_id "al9Y1SKGokixMSfKDOfVBwAAAk4"]
[Tue Jul 21 08:32:37.414860 2026] [security2:error] [pid 466512:tid 466737] [client 195.49.128.211:64527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y1SKGokixMSfKDOfVCAAAAnM"]
[Tue Jul 21 08:32:37.414983 2026] [security2:error] [pid 466512:tid 466737] [client 195.49.128.211:64527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y1SKGokixMSfKDOfVCAAAAnM"]
[Tue Jul 21 08:32:37.433096 2026] [security2:error] [pid 466512:tid 466699] [client 20.197.192.193:65180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/samll.php"] [unique_id "al9Y1SKGokixMSfKDOfVCQAAAk0"]
[Tue Jul 21 08:32:37.500927 2026] [security2:error] [pid 466512:tid 466725] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/2x.php"] [unique_id "al9Y1SKGokixMSfKDOfVDAAAAmc"]
[Tue Jul 21 08:32:37.766991 2026] [security2:error] [pid 465652:tid 465790] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/ctex1.php"] [unique_id "al9Y1TzTqJoBC2Mw28-yWgAAAI0"]
[Tue Jul 21 08:32:37.772569 2026] [security2:error] [pid 466512:tid 466746] [client 103.151.46.103:61755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Y1SKGokixMSfKDOfVEwAAAnw"]
[Tue Jul 21 08:32:37.772715 2026] [security2:error] [pid 466512:tid 466746] [client 103.151.46.103:61755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Y1SKGokixMSfKDOfVEwAAAnw"]
[Tue Jul 21 08:32:37.790194 2026] [security2:error] [pid 466512:tid 466687] [client 20.197.195.24:57965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/file.php"] [unique_id "al9Y1SKGokixMSfKDOfVFAAAAkE"]
[Tue Jul 21 08:32:37.829073 2026] [security2:error] [pid 466512:tid 466692] [client 20.197.195.24:17057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/777.php"] [unique_id "al9Y1SKGokixMSfKDOfVFQAAAkY"]
[Tue Jul 21 08:32:37.862228 2026] [security2:error] [pid 466512:tid 466757] [client 20.197.195.24:57960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/ssixta.php"] [unique_id "al9Y1SKGokixMSfKDOfVFgAAAoc"]
[Tue Jul 21 08:32:37.957660 2026] [security2:error] [pid 465652:tid 465834] [client 20.197.195.24:6601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/1c.php"] [unique_id "al9Y1TzTqJoBC2Mw28-yXQAAALk"]
[Tue Jul 21 08:32:37.962810 2026] [security2:error] [pid 466512:tid 466732] [client 4.194.24.143:5794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/cache.php"] [unique_id "al9Y1SKGokixMSfKDOfVGAAAAm4"]
[Tue Jul 21 08:32:38.048362 2026] [security2:error] [pid 466512:tid 466759] [client 20.197.195.24:6620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/test2.php"] [unique_id "al9Y1iKGokixMSfKDOfVGQAAAok"]
[Tue Jul 21 08:32:38.064677 2026] [security2:error] [pid 465652:tid 465761] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Y1jzTqJoBC2Mw28-yXwAAnGw"]
[Tue Jul 21 08:32:38.064788 2026] [security2:error] [pid 465652:tid 465805] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Y1jzTqJoBC2Mw28-yXwAAnGw"]
[Tue Jul 21 08:32:38.070398 2026] [security2:error] [pid 466512:tid 466648] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/edorxrr.php"] [unique_id "al9Y1iKGokixMSfKDOfVGwAAAho"]
[Tue Jul 21 08:32:38.100462 2026] [autoindex:error] [pid 465652:tid 465893] [client 20.197.195.24:15741] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:38.160855 2026] [security2:error] [pid 466512:tid 466734] [client 5.38.115.39:63085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Y1iKGokixMSfKDOfVHQAAAnA"]
[Tue Jul 21 08:32:38.160970 2026] [security2:error] [pid 466512:tid 466734] [client 5.38.115.39:63085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Y1iKGokixMSfKDOfVHQAAAnA"]
[Tue Jul 21 08:32:38.223098 2026] [security2:error] [pid 466512:tid 466683] [client 20.197.195.24:17060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/buy.php"] [unique_id "al9Y1iKGokixMSfKDOfVHwAAAj0"]
[Tue Jul 21 08:32:38.354770 2026] [security2:error] [pid 465652:tid 465832] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/miru1.php"] [unique_id "al9Y1jzTqJoBC2Mw28-yZQAAALc"]
[Tue Jul 21 08:32:38.629356 2026] [security2:error] [pid 466512:tid 466713] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/sump1.php"] [unique_id "al9Y1iKGokixMSfKDOfVIwAAAls"]
[Tue Jul 21 08:32:38.665936 2026] [security2:error] [pid 466512:tid 466681] [client 20.197.195.24:17080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/ssend.php"] [unique_id "al9Y1iKGokixMSfKDOfVJQAAAjs"]
[Tue Jul 21 08:32:38.722283 2026] [security2:error] [pid 466512:tid 466724] [client 85.204.70.92:36662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y1SKGokixMSfKDOfVEQAAAmY"]
[Tue Jul 21 08:32:38.735734 2026] [security2:error] [pid 466512:tid 466703] [client 14.245.224.124:56334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Y1iKGokixMSfKDOfVJgAAAlE"]
[Tue Jul 21 08:32:38.736046 2026] [security2:error] [pid 466512:tid 466703] [client 14.245.224.124:56334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Y1iKGokixMSfKDOfVJgAAAlE"]
[Tue Jul 21 08:32:38.860681 2026] [security2:error] [pid 466512:tid 466731] [client 20.197.195.24:57863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/item.php"] [unique_id "al9Y1iKGokixMSfKDOfVKAAAAm0"]
[Tue Jul 21 08:32:38.903662 2026] [security2:error] [pid 465652:tid 465884] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/file5.php"] [unique_id "al9Y1jzTqJoBC2Mw28-ybQAAAOs"]
[Tue Jul 21 08:32:38.974809 2026] [security2:error] [pid 465652:tid 465846] [client 20.197.192.193:5612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/la.php"] [unique_id "al9Y1jzTqJoBC2Mw28-ybgAAAMU"]
[Tue Jul 21 08:32:38.984702 2026] [security2:error] [pid 466512:tid 466762] [client 152.59.34.51:57805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Y1iKGokixMSfKDOfVKwAAAow"]
[Tue Jul 21 08:32:38.984831 2026] [security2:error] [pid 466512:tid 466762] [client 152.59.34.51:57805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Y1iKGokixMSfKDOfVKwAAAow"]
[Tue Jul 21 08:32:38.993219 2026] [security2:error] [pid 466512:tid 466693] [client 4.194.24.143:4433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/cc.php"] [unique_id "al9Y1iKGokixMSfKDOfVLAAAAkc"]
[Tue Jul 21 08:32:39.012835 2026] [security2:error] [pid 465652:tid 465865] [client 20.197.195.24:57953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/ss.php"] [unique_id "al9Y1zzTqJoBC2Mw28-ycAAAANg"]
[Tue Jul 21 08:32:39.036036 2026] [security2:error] [pid 465652:tid 465827] [client 212.32.69.197:20183] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rgagestaodecondominios.adm.br"] [uri "/.env"] [unique_id "al9Y1zzTqJoBC2Mw28-ycQAAALI"]
[Tue Jul 21 08:32:39.045810 2026] [autoindex:error] [pid 465652:tid 465785] [client 20.197.195.24:15741] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:39.187522 2026] [security2:error] [pid 465652:tid 465874] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/0xD.php"] [unique_id "al9Y1zzTqJoBC2Mw28-ydAAAAOE"]
[Tue Jul 21 08:32:39.220744 2026] [core:error] [pid 466512:tid 466606] [remote 52.167.144.204:3539] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:32:39.220765 2026] [core:error] [pid 466512:tid 466606] [remote 52.167.144.204:3539] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:32:39.374425 2026] [security2:error] [pid 466512:tid 466649] [client 20.197.195.24:57973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/hypo.php"] [unique_id "al9Y1yKGokixMSfKDOfVNQAAAhs"]
[Tue Jul 21 08:32:39.473767 2026] [security2:error] [pid 465652:tid 465811] [client 187.125.243.197:49600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Y1zzTqJoBC2Mw28-yegAAAKI"]
[Tue Jul 21 08:32:39.473883 2026] [security2:error] [pid 465652:tid 465811] [client 187.125.243.197:49600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Y1zzTqJoBC2Mw28-yegAAAKI"]
[Tue Jul 21 08:32:39.473928 2026] [security2:error] [pid 466512:tid 466748] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/fnstall.php"] [unique_id "al9Y1yKGokixMSfKDOfVOAAAAn4"]
[Tue Jul 21 08:32:39.501237 2026] [security2:error] [pid 465652:tid 465818] [client 20.197.195.24:15741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ccc.php"] [unique_id "al9Y1zzTqJoBC2Mw28-yfAAAAKk"]
[Tue Jul 21 08:32:39.572054 2026] [security2:error] [pid 465652:tid 465764] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Y1zzTqJoBC2Mw28-yfQAAw28"]
[Tue Jul 21 08:32:39.572165 2026] [security2:error] [pid 465652:tid 465844] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Y1zzTqJoBC2Mw28-yfQAAw28"]
[Tue Jul 21 08:32:39.731075 2026] [security2:error] [pid 466512:tid 466587] [remote 130.185.118.215:37492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rustikusboxingschool.com"] [uri "/wp-login.php"] [unique_id "al9Y1yKGokixMSfKDOfVPwACJ0o"]
[Tue Jul 21 08:32:39.915691 2026] [security2:error] [pid 466512:tid 466759] [client 74.249.245.134:37719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/up.php"] [unique_id "al9Y1yKGokixMSfKDOfVQAAAAok"]
[Tue Jul 21 08:32:40.031779 2026] [security2:error] [pid 465652:tid 465817] [client 20.197.192.193:65213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/abcd.php"] [unique_id "al9Y2DzTqJoBC2Mw28-yiQAAAKg"]
[Tue Jul 21 08:32:40.053607 2026] [cgid:error] [pid 466512:tid 466745] [client 4.194.24.143:17068] AH01264: stderr from /home4/juliob58/wbapoiocontabil.com.br/cgi-bin: script not found or unable to stat
[Tue Jul 21 08:32:40.175460 2026] [security2:error] [pid 466512:tid 466741] [client 89.238.167.134:56788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Y2CKGokixMSfKDOfVRQAAAnc"]
[Tue Jul 21 08:32:40.175593 2026] [security2:error] [pid 466512:tid 466741] [client 89.238.167.134:56788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9Y2CKGokixMSfKDOfVRQAAAnc"]
[Tue Jul 21 08:32:40.237351 2026] [security2:error] [pid 465652:tid 465851] [client 20.197.195.24:57870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/users.php"] [unique_id "al9Y2DzTqJoBC2Mw28-yjQAAAMo"]
[Tue Jul 21 08:32:40.406512 2026] [security2:error] [pid 466512:tid 466758] [client 4.194.24.143:17068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9Y2CKGokixMSfKDOfVSQAAAog"]
[Tue Jul 21 08:32:40.471666 2026] [security2:error] [pid 465652:tid 465837] [client 20.197.195.24:16009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/w.php"] [unique_id "al9Y2DzTqJoBC2Mw28-ylQAAALw"]
[Tue Jul 21 08:32:40.499770 2026] [security2:error] [pid 465652:tid 465881] [client 20.197.192.193:5974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9Y2DzTqJoBC2Mw28-ylgAAAOg"]
[Tue Jul 21 08:32:40.540559 2026] [security2:error] [pid 465652:tid 465784] [client 202.179.75.202:49096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Y2DzTqJoBC2Mw28-ylwAAAIc"]
[Tue Jul 21 08:32:40.540654 2026] [security2:error] [pid 465652:tid 465784] [client 202.179.75.202:49096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Y2DzTqJoBC2Mw28-ylwAAAIc"]
[Tue Jul 21 08:32:40.611108 2026] [security2:error] [pid 466512:tid 466713] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/acp.php"] [unique_id "al9Y2CKGokixMSfKDOfVTAAAAls"]
[Tue Jul 21 08:32:40.909819 2026] [security2:error] [pid 465652:tid 465805] [client 20.197.195.24:6529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/177.php"] [unique_id "al9Y2DzTqJoBC2Mw28-ynwAAAJw"]
[Tue Jul 21 08:32:41.191951 2026] [security2:error] [pid 466512:tid 466727] [client 85.204.70.92:14625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y2SKGokixMSfKDOfVVQAAAmk"]
[Tue Jul 21 08:32:41.192065 2026] [security2:error] [pid 466512:tid 466727] [client 85.204.70.92:14625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.tabelionatoportoalegre.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y2SKGokixMSfKDOfVVQAAAmk"]
[Tue Jul 21 08:32:41.412688 2026] [security2:error] [pid 466512:tid 466715] [client 20.197.192.193:5953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/inso.php"] [unique_id "al9Y2SKGokixMSfKDOfVWwAAAl0"]
[Tue Jul 21 08:32:41.433463 2026] [security2:error] [pid 466512:tid 466664] [client 128.127.105.184:33214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Y2SKGokixMSfKDOfVXAAAAio"]
[Tue Jul 21 08:32:41.433544 2026] [security2:error] [pid 466512:tid 466664] [client 128.127.105.184:33214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Y2SKGokixMSfKDOfVXAAAAio"]
[Tue Jul 21 08:32:41.441853 2026] [security2:error] [pid 466512:tid 466762] [client 4.194.24.143:4458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/cgi-bin/class-wp-http-client.php"] [unique_id "al9Y2SKGokixMSfKDOfVXQAAAow"]
[Tue Jul 21 08:32:41.552829 2026] [security2:error] [pid 466512:tid 466742] [client 109.248.148.246:44436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Y2SKGokixMSfKDOfVYQAAAng"]
[Tue Jul 21 08:32:41.552928 2026] [security2:error] [pid 466512:tid 466742] [client 109.248.148.246:44436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9Y2SKGokixMSfKDOfVYQAAAng"]
[Tue Jul 21 08:32:41.688675 2026] [security2:error] [pid 466512:tid 466704] [client 20.197.195.24:3947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Y2SKGokixMSfKDOfVYgAAAlI"]
[Tue Jul 21 08:32:41.813907 2026] [security2:error] [pid 466512:tid 466707] [client 20.206.105.145:25477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/8.php"] [unique_id "al9Y2SKGokixMSfKDOfVZQAAAlU"]
[Tue Jul 21 08:32:42.088747 2026] [security2:error] [pid 466512:tid 466698] [client 20.197.195.24:17076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/config.php"] [unique_id "al9Y2iKGokixMSfKDOfVagAAAkw"]
[Tue Jul 21 08:32:42.114419 2026] [security2:error] [pid 466512:tid 466734] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/mosty.php"] [unique_id "al9Y2iKGokixMSfKDOfVawAAAnA"]
[Tue Jul 21 08:32:42.257841 2026] [security2:error] [pid 465652:tid 465816] [client 74.249.245.134:55545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/66.php"] [unique_id "al9Y2jzTqJoBC2Mw28-yrQAAAKc"]
[Tue Jul 21 08:32:42.382165 2026] [security2:error] [pid 465652:tid 465899] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/6.php"] [unique_id "al9Y2jzTqJoBC2Mw28-yrgAAAPo"]
[Tue Jul 21 08:32:42.384955 2026] [security2:error] [pid 466512:tid 466719] [client 102.209.137.222:65152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.137.209.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9Y2iKGokixMSfKDOfVbwAAAmE"]
[Tue Jul 21 08:32:42.385080 2026] [security2:error] [pid 466512:tid 466719] [client 102.209.137.222:65152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9Y2iKGokixMSfKDOfVbwAAAmE"]
[Tue Jul 21 08:32:42.464480 2026] [security2:error] [pid 466512:tid 466741] [client 4.194.24.143:8453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/chosen.php"] [unique_id "al9Y2iKGokixMSfKDOfVcgAAAnc"]
[Tue Jul 21 08:32:42.707213 2026] [security2:error] [pid 465652:tid 465850] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9Y2jzTqJoBC2Mw28-yswAAAMk"]
[Tue Jul 21 08:32:42.713677 2026] [security2:error] [pid 466512:tid 466645] [client 20.197.195.24:15711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/FWAZ.php"] [unique_id "al9Y2iKGokixMSfKDOfVdAAAAhc"]
[Tue Jul 21 08:32:42.956058 2026] [proxy:error] [pid 465652:tid 465862] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:42.956131 2026] [proxy_http:error] [pid 465652:tid 465862] [client 195.96.139.68:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:42.956626 2026] [proxy:error] [pid 465652:tid 465862] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:42.956654 2026] [proxy_http:error] [pid 465652:tid 465862] [client 195.96.139.68:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:42.989146 2026] [security2:error] [pid 466512:tid 466655] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/qqqa.php"] [unique_id "al9Y2iKGokixMSfKDOfVewAAAiE"]
[Tue Jul 21 08:32:43.531779 2026] [security2:error] [pid 465652:tid 465813] [client 4.194.24.143:6794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/class-t.api.php"] [unique_id "al9Y2zzTqJoBC2Mw28-y-AAAAKQ"]
[Tue Jul 21 08:32:43.555878 2026] [security2:error] [pid 465652:tid 465797] [client 20.197.192.193:5627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wpx.php"] [unique_id "al9Y2zzTqJoBC2Mw28-y-QAAAJQ"]
[Tue Jul 21 08:32:43.691200 2026] [security2:error] [pid 465652:tid 465822] [client 195.49.128.211:56593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Y2zzTqJoBC2Mw28-zGgAAAK0"]
[Tue Jul 21 08:32:43.691314 2026] [security2:error] [pid 465652:tid 465822] [client 195.49.128.211:56593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Y2zzTqJoBC2Mw28-zGgAAAK0"]
[Tue Jul 21 08:32:43.735062 2026] [security2:error] [pid 466512:tid 466723] [client 223.181.60.88:32758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Y2yKGokixMSfKDOfVjQAAAmU"]
[Tue Jul 21 08:32:43.735152 2026] [security2:error] [pid 466512:tid 466723] [client 223.181.60.88:32758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Y2yKGokixMSfKDOfVjQAAAmU"]
[Tue Jul 21 08:32:43.759403 2026] [security2:error] [pid 465652:tid 465859] [client 20.206.105.145:25489] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "trueproducoes.com.br"] [uri "/1.php"] [unique_id "al9Y2zzTqJoBC2Mw28-zHAAAANI"]
[Tue Jul 21 08:32:43.759481 2026] [security2:error] [pid 465652:tid 465859] [client 20.206.105.145:25489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/1.php"] [unique_id "al9Y2zzTqJoBC2Mw28-zHAAAANI"]
[Tue Jul 21 08:32:43.762920 2026] [core:error] [pid 465652:tid 465756] [remote 52.167.144.173:14981] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:32:43.762954 2026] [core:error] [pid 465652:tid 465756] [remote 52.167.144.173:14981] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:32:43.789869 2026] [security2:error] [pid 466512:tid 466756] [client 20.197.195.24:18698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/gettest.php"] [unique_id "al9Y2yKGokixMSfKDOfVjwAAAoY"]
[Tue Jul 21 08:32:43.896021 2026] [security2:error] [pid 465652:tid 465800] [client 109.248.148.246:47196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Y2zzTqJoBC2Mw28-zJQAAAJc"]
[Tue Jul 21 08:32:43.896094 2026] [security2:error] [pid 465652:tid 465800] [client 109.248.148.246:47196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Y2zzTqJoBC2Mw28-zJQAAAJc"]
[Tue Jul 21 08:32:43.903682 2026] [core:error] [pid 465652:tid 465694] [remote 52.167.144.173:14981] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:32:43.903708 2026] [core:error] [pid 465652:tid 465694] [remote 52.167.144.173:14981] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:32:43.953392 2026] [security2:error] [pid 465652:tid 465839] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/aunmc.php"] [unique_id "al9Y2zzTqJoBC2Mw28-zKQAAAL4"]
[Tue Jul 21 08:32:43.988908 2026] [security2:error] [pid 466512:tid 466666] [client 74.249.245.134:55537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/666.php"] [unique_id "al9Y2yKGokixMSfKDOfVlAAAAiw"]
[Tue Jul 21 08:32:44.030740 2026] [core:error] [pid 465652:tid 465687] [remote 52.167.144.173:14981] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:32:44.030755 2026] [core:error] [pid 465652:tid 465687] [remote 52.167.144.173:14981] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:32:44.081234 2026] [security2:error] [pid 466512:tid 466700] [client 150.129.202.39:13407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y3CKGokixMSfKDOfVmAAAAk4"]
[Tue Jul 21 08:32:44.081353 2026] [security2:error] [pid 466512:tid 466700] [client 150.129.202.39:13407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y3CKGokixMSfKDOfVmAAAAk4"]
[Tue Jul 21 08:32:44.259457 2026] [security2:error] [pid 466512:tid 466734] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/uoocf.php"] [unique_id "al9Y3CKGokixMSfKDOfVmwAAAnA"]
[Tue Jul 21 08:32:44.352543 2026] [security2:error] [pid 465652:tid 465858] [client 89.238.167.134:56806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Y3DzTqJoBC2Mw28-zMQAAANE"]
[Tue Jul 21 08:32:44.352706 2026] [security2:error] [pid 465652:tid 465858] [client 89.238.167.134:56806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Y3DzTqJoBC2Mw28-zMQAAANE"]
[Tue Jul 21 08:32:44.459678 2026] [security2:error] [pid 466512:tid 466747] [client 20.197.192.193:5989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/berlin.php"] [unique_id "al9Y3CKGokixMSfKDOfVpQAAAn0"]
[Tue Jul 21 08:32:44.541320 2026] [security2:error] [pid 466512:tid 466726] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/iywwi.php"] [unique_id "al9Y3CKGokixMSfKDOfVqwAAAmg"]
[Tue Jul 21 08:32:44.591759 2026] [security2:error] [pid 465652:tid 465888] [client 4.194.24.143:8833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9Y3DzTqJoBC2Mw28-zOgAAAO8"]
[Tue Jul 21 08:32:44.667682 2026] [security2:error] [pid 466512:tid 466674] [client 20.197.195.24:3853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/miru1.php"] [unique_id "al9Y3CKGokixMSfKDOfVrgAAAjQ"]
[Tue Jul 21 08:32:44.823169 2026] [security2:error] [pid 466512:tid 466649] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/gqgsa.php"] [unique_id "al9Y3CKGokixMSfKDOfVwQAAAhs"]
[Tue Jul 21 08:32:45.074395 2026] [security2:error] [pid 465652:tid 465908] [client 152.59.181.104:59400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Y3TzTqJoBC2Mw28-zdQAAAQM"]
[Tue Jul 21 08:32:45.074507 2026] [security2:error] [pid 465652:tid 465908] [client 152.59.181.104:59400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Y3TzTqJoBC2Mw28-zdQAAAQM"]
[Tue Jul 21 08:32:45.104453 2026] [security2:error] [pid 465652:tid 465835] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/elbzl.php"] [unique_id "al9Y3TzTqJoBC2Mw28-zdgAAALo"]
[Tue Jul 21 08:32:45.326083 2026] [security2:error] [pid 465652:tid 465851] [client 20.206.105.145:25573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/100.php"] [unique_id "al9Y3TzTqJoBC2Mw28-zewAAAMo"]
[Tue Jul 21 08:32:45.377982 2026] [security2:error] [pid 466512:tid 466746] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/adjig.php"] [unique_id "al9Y3SKGokixMSfKDOfVxgAAAnw"]
[Tue Jul 21 08:32:45.415348 2026] [security2:error] [pid 466512:tid 466661] [client 20.197.195.24:3842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/aa.php"] [unique_id "al9Y3SKGokixMSfKDOfVxwAAAic"]
[Tue Jul 21 08:32:45.491771 2026] [security2:error] [pid 466512:tid 466751] [client 117.213.202.34:62846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y3SKGokixMSfKDOfVyQAAAoE"]
[Tue Jul 21 08:32:45.491895 2026] [security2:error] [pid 466512:tid 466751] [client 117.213.202.34:62846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y3SKGokixMSfKDOfVyQAAAoE"]
[Tue Jul 21 08:32:45.667676 2026] [security2:error] [pid 466512:tid 466730] [client 4.194.24.143:8471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/class-wp-http-client.php"] [unique_id "al9Y3SKGokixMSfKDOfVywAAAmw"]
[Tue Jul 21 08:32:45.775209 2026] [security2:error] [pid 465652:tid 465705] [remote 173.252.87.43:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Y3TzTqJoBC2Mw28-zgwAA1DQ"]
[Tue Jul 21 08:32:45.926340 2026] [security2:error] [pid 466512:tid 466685] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/byp.php"] [unique_id "al9Y3SKGokixMSfKDOfVzgAAAj8"]
[Tue Jul 21 08:32:45.938021 2026] [security2:error] [pid 466512:tid 466706] [client 74.249.245.134:54951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/byp.php"] [unique_id "al9Y3SKGokixMSfKDOfVzwAAAlQ"]
[Tue Jul 21 08:32:46.048790 2026] [security2:error] [pid 466512:tid 466680] [client 20.197.195.24:6293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/122.php"] [unique_id "al9Y3iKGokixMSfKDOfV0QAAAjo"]
[Tue Jul 21 08:32:46.210008 2026] [security2:error] [pid 466512:tid 466722] [client 51.68.111.243:17281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "agmiz.com.br"] [uri "/robots.txt"] [unique_id "al9Y3iKGokixMSfKDOfV1wAAAmQ"]
[Tue Jul 21 08:32:46.210117 2026] [security2:error] [pid 466512:tid 466722] [client 51.68.111.243:17281] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "agmiz.com.br"] [uri "/robots.txt"] [unique_id "al9Y3iKGokixMSfKDOfV1wAAAmQ"]
[Tue Jul 21 08:32:46.217829 2026] [security2:error] [pid 466512:tid 466720] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9Y3iKGokixMSfKDOfV2AAAAmI"]
[Tue Jul 21 08:32:46.488561 2026] [security2:error] [pid 465652:tid 465897] [client 14.97.58.74:18235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y3jzTqJoBC2Mw28-ztgAAAPg"]
[Tue Jul 21 08:32:46.488660 2026] [security2:error] [pid 465652:tid 465897] [client 14.97.58.74:18235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y3jzTqJoBC2Mw28-ztgAAAPg"]
[Tue Jul 21 08:32:46.490642 2026] [security2:error] [pid 466512:tid 466715] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Y3iKGokixMSfKDOfV3wAAAl0"]
[Tue Jul 21 08:32:46.499099 2026] [security2:error] [pid 466512:tid 466628] [remote 5.182.209.54:35260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-login.php"] [unique_id "al9Y3iKGokixMSfKDOfV4AACUXM"]
[Tue Jul 21 08:32:46.698904 2026] [security2:error] [pid 465652:tid 465801] [client 4.194.24.143:5797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/class.php"] [unique_id "al9Y3jzTqJoBC2Mw28-zyAAAAJg"]
[Tue Jul 21 08:32:46.740218 2026] [security2:error] [pid 466512:tid 466698] [client 20.197.195.24:57860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/min.php"] [unique_id "al9Y3iKGokixMSfKDOfV5gAAAkw"]
[Tue Jul 21 08:32:46.764458 2026] [security2:error] [pid 466512:tid 466667] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/root.php"] [unique_id "al9Y3iKGokixMSfKDOfV5wAAAi0"]
[Tue Jul 21 08:32:46.764801 2026] [security2:error] [pid 466512:tid 466743] [client 61.1.167.83:56924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y3iKGokixMSfKDOfV6QAAAnk"]
[Tue Jul 21 08:32:46.764881 2026] [security2:error] [pid 466512:tid 466743] [client 61.1.167.83:56924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y3iKGokixMSfKDOfV6QAAAnk"]
[Tue Jul 21 08:32:46.809871 2026] [security2:error] [pid 465652:tid 465881] [client 122.176.100.127:53700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Y3jzTqJoBC2Mw28-zygAAAOg"]
[Tue Jul 21 08:32:46.809963 2026] [security2:error] [pid 465652:tid 465881] [client 122.176.100.127:53700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Y3jzTqJoBC2Mw28-zygAAAOg"]
[Tue Jul 21 08:32:46.902847 2026] [security2:error] [pid 466512:tid 466768] [client 49.144.66.253:33044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Y3iKGokixMSfKDOfV7AAAApI"]
[Tue Jul 21 08:32:46.902942 2026] [security2:error] [pid 466512:tid 466768] [client 49.144.66.253:33044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Y3iKGokixMSfKDOfV7AAAApI"]
[Tue Jul 21 08:32:47.047204 2026] [security2:error] [pid 466512:tid 466657] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/sym403.php"] [unique_id "al9Y3yKGokixMSfKDOfV7wAAAiM"]
[Tue Jul 21 08:32:47.059301 2026] [security2:error] [pid 466512:tid 466742] [client 20.197.195.24:15681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/get.php"] [unique_id "al9Y3yKGokixMSfKDOfV8AAAAng"]
[Tue Jul 21 08:32:47.129552 2026] [security2:error] [pid 466512:tid 466687] [client 20.197.192.193:5969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/billur.php"] [unique_id "al9Y3yKGokixMSfKDOfV8wAAAkE"]
[Tue Jul 21 08:32:47.349073 2026] [security2:error] [pid 465652:tid 465873] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/v543.php"] [unique_id "al9Y3zzTqJoBC2Mw28-z1QAAAOA"]
[Tue Jul 21 08:32:47.422723 2026] [security2:error] [pid 466512:tid 466678] [client 20.197.195.24:53525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/as.php"] [unique_id "al9Y3yKGokixMSfKDOfV-AAAAjg"]
[Tue Jul 21 08:32:47.554501 2026] [security2:error] [pid 466512:tid 466672] [client 109.248.148.246:44438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Y3yKGokixMSfKDOfV_gAAAjI"]
[Tue Jul 21 08:32:47.554576 2026] [security2:error] [pid 466512:tid 466672] [client 109.248.148.246:44438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Y3yKGokixMSfKDOfV_gAAAjI"]
[Tue Jul 21 08:32:47.629070 2026] [security2:error] [pid 465652:tid 465811] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/sixxis.php"] [unique_id "al9Y3zzTqJoBC2Mw28-z2QAAAKI"]
[Tue Jul 21 08:32:47.746639 2026] [security2:error] [pid 466512:tid 466685] [client 4.194.24.143:4421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/classsmtps.php"] [unique_id "al9Y3yKGokixMSfKDOfWCAAAAj8"]
[Tue Jul 21 08:32:47.797394 2026] [security2:error] [pid 465652:tid 465679] [remote 97.74.87.194:60746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moneyclass.com.br"] [uri "/wp-login.php"] [unique_id "al9Y3zzTqJoBC2Mw28-z3QAApxo"]
[Tue Jul 21 08:32:47.917929 2026] [security2:error] [pid 466512:tid 466762] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/ip.php"] [unique_id "al9Y3yKGokixMSfKDOfWDQAAAow"]
[Tue Jul 21 08:32:48.020436 2026] [security2:error] [pid 466512:tid 466731] [client 195.49.128.211:65125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y4CKGokixMSfKDOfWDwAAAm0"]
[Tue Jul 21 08:32:48.020537 2026] [security2:error] [pid 466512:tid 466731] [client 195.49.128.211:65125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y4CKGokixMSfKDOfWDwAAAm0"]
[Tue Jul 21 08:32:48.198746 2026] [security2:error] [pid 465652:tid 465880] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/kq1.php"] [unique_id "al9Y4DzTqJoBC2Mw28-z5QAAAOc"]
[Tue Jul 21 08:32:48.429468 2026] [security2:error] [pid 466512:tid 466714] [client 20.197.195.24:17079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/dvjul.php"] [unique_id "al9Y4CKGokixMSfKDOfWFAAAAlw"]
[Tue Jul 21 08:32:48.433640 2026] [security2:error] [pid 466512:tid 466716] [client 20.197.195.24:3864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ccou.php"] [unique_id "al9Y4CKGokixMSfKDOfWFQAAAl4"]
[Tue Jul 21 08:32:48.508520 2026] [security2:error] [pid 466512:tid 466669] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9Y4CKGokixMSfKDOfWFgAAAi8"]
[Tue Jul 21 08:32:48.523464 2026] [security2:error] [pid 466512:tid 466660] [client 103.151.46.103:62248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Y4CKGokixMSfKDOfWGAAAAiY"]
[Tue Jul 21 08:32:48.524221 2026] [security2:error] [pid 466512:tid 466660] [client 103.151.46.103:62248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Y4CKGokixMSfKDOfWGAAAAiY"]
[Tue Jul 21 08:32:48.687761 2026] [security2:error] [pid 465652:tid 465674] [remote 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Y4DzTqJoBC2Mw28-z6gAA4xU"]
[Tue Jul 21 08:32:48.687908 2026] [security2:error] [pid 465652:tid 465876] [client 2c0f:f888:a980:8587:34fe:839a:120:14a:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9Y4DzTqJoBC2Mw28-z6gAA4xU"]
[Tue Jul 21 08:32:48.777540 2026] [security2:error] [pid 466512:tid 466651] [client 4.194.24.143:5766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Y4CKGokixMSfKDOfWIQAAAh0"]
[Tue Jul 21 08:32:48.806659 2026] [security2:error] [pid 466512:tid 466684] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/h02ugyh.php"] [unique_id "al9Y4CKGokixMSfKDOfWIgAAAj4"]
[Tue Jul 21 08:32:48.944550 2026] [security2:error] [pid 466512:tid 466667] [client 152.59.34.51:52905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Y4CKGokixMSfKDOfWIwAAAi0"]
[Tue Jul 21 08:32:48.944704 2026] [security2:error] [pid 466512:tid 466667] [client 152.59.34.51:52905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Y4CKGokixMSfKDOfWIwAAAi0"]
[Tue Jul 21 08:32:49.176123 2026] [security2:error] [pid 466512:tid 466687] [client 5.38.115.39:23732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Y4SKGokixMSfKDOfWJwAAAkE"]
[Tue Jul 21 08:32:49.180583 2026] [security2:error] [pid 466512:tid 466687] [client 5.38.115.39:23732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Y4SKGokixMSfKDOfWJwAAAkE"]
[Tue Jul 21 08:32:49.307582 2026] [security2:error] [pid 466512:tid 466682] [client 14.245.224.124:56860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Y4SKGokixMSfKDOfWKwAAAjw"]
[Tue Jul 21 08:32:49.307780 2026] [security2:error] [pid 466512:tid 466682] [client 14.245.224.124:56860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Y4SKGokixMSfKDOfWKwAAAjw"]
[Tue Jul 21 08:32:49.634961 2026] [security2:error] [pid 465652:tid 465787] [client 20.197.195.24:18690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/biufile.php"] [unique_id "al9Y4TzTqJoBC2Mw28-z9QAAAIo"]
[Tue Jul 21 08:32:49.764380 2026] [security2:error] [pid 466512:tid 466705] [client 20.197.195.24:15701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/w3lls.php"] [unique_id "al9Y4SKGokixMSfKDOfWMQAAAlM"]
[Tue Jul 21 08:32:49.786901 2026] [security2:error] [pid 466512:tid 466642] [client 74.249.245.134:55497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/date.php"] [unique_id "al9Y4SKGokixMSfKDOfWMwAAAhQ"]
[Tue Jul 21 08:32:49.794860 2026] [security2:error] [pid 465652:tid 465821] [client 20.206.105.145:25510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/about.php"] [unique_id "al9Y4TzTqJoBC2Mw28-z-gAAAKw"]
[Tue Jul 21 08:32:49.809062 2026] [security2:error] [pid 465652:tid 465843] [client 4.194.24.143:4478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/claude.php"] [unique_id "al9Y4TzTqJoBC2Mw28-z-wAAAMI"]
[Tue Jul 21 08:32:49.923251 2026] [security2:error] [pid 465652:tid 465680] [remote 20.153.140.50:44338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/wp-login.php"] [unique_id "al9Y4TzTqJoBC2Mw28-z_QAA3xs"]
[Tue Jul 21 08:32:49.966111 2026] [security2:error] [pid 465652:tid 465834] [client 187.125.243.197:50110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Y4TzTqJoBC2Mw28-z_gAAALk"]
[Tue Jul 21 08:32:49.966949 2026] [security2:error] [pid 465652:tid 465834] [client 187.125.243.197:50110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Y4TzTqJoBC2Mw28-z_gAAALk"]
[Tue Jul 21 08:32:49.967684 2026] [security2:error] [pid 466512:tid 466551] [remote 91.142.222.105:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-login.php"] [unique_id "al9Y4SKGokixMSfKDOfWNQACJSY"]
[Tue Jul 21 08:32:50.129780 2026] [security2:error] [pid 466512:tid 466552] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Y4iKGokixMSfKDOfWNgACSSc"]
[Tue Jul 21 08:32:50.129948 2026] [security2:error] [pid 466512:tid 466695] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Y4iKGokixMSfKDOfWNgACSSc"]
[Tue Jul 21 08:32:50.284419 2026] [security2:error] [pid 465652:tid 465875] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-temp.php"] [unique_id "al9Y4jzTqJoBC2Mw28-0CwAAAOI"]
[Tue Jul 21 08:32:50.550858 2026] [security2:error] [pid 466512:tid 466762] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9Y4iKGokixMSfKDOfWOAAAAow"]
[Tue Jul 21 08:32:50.643446 2026] [security2:error] [pid 466512:tid 466646] [client 20.197.195.24:53617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/test1.php"] [unique_id "al9Y4iKGokixMSfKDOfWOQAAAhg"]
[Tue Jul 21 08:32:50.859131 2026] [security2:error] [pid 465652:tid 465836] [client 4.194.24.143:5823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/config.php"] [unique_id "al9Y4jzTqJoBC2Mw28-0FAAAALs"]
[Tue Jul 21 08:32:51.129238 2026] [security2:error] [pid 466512:tid 466710] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9Y4yKGokixMSfKDOfWRwAAAlg"]
[Tue Jul 21 08:32:51.182746 2026] [security2:error] [pid 465652:tid 465824] [client 74.7.175.164:46120] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "casafreitasvinhos.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Y4zzTqJoBC2Mw28-0FgAArzQ"]
[Tue Jul 21 08:32:51.217853 2026] [security2:error] [pid 466512:tid 466727] [client 213.152.186.163:41386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Y4yKGokixMSfKDOfWSAAAAmk"]
[Tue Jul 21 08:32:51.217937 2026] [security2:error] [pid 466512:tid 466727] [client 213.152.186.163:41386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Y4yKGokixMSfKDOfWSAAAAmk"]
[Tue Jul 21 08:32:51.395512 2026] [security2:error] [pid 465652:tid 465811] [client 202.179.75.202:60712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Y4zzTqJoBC2Mw28-0HAAAAKI"]
[Tue Jul 21 08:32:51.395620 2026] [security2:error] [pid 465652:tid 465811] [client 202.179.75.202:60712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Y4zzTqJoBC2Mw28-0HAAAAKI"]
[Tue Jul 21 08:32:51.402619 2026] [security2:error] [pid 466512:tid 466655] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/jj.php"] [unique_id "al9Y4yKGokixMSfKDOfWTQAAAiE"]
[Tue Jul 21 08:32:51.407183 2026] [security2:error] [pid 466512:tid 466723] [client 20.197.195.24:6627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/av.php"] [unique_id "al9Y4yKGokixMSfKDOfWTgAAAmU"]
[Tue Jul 21 08:32:51.573167 2026] [security2:error] [pid 466512:tid 466684] [client 20.197.195.24:6298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/database.php"] [unique_id "al9Y4yKGokixMSfKDOfWUAAAAj4"]
[Tue Jul 21 08:32:51.669252 2026] [security2:error] [pid 465652:tid 465845] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9Y4zzTqJoBC2Mw28-0HQAAAMQ"]
[Tue Jul 21 08:32:51.919232 2026] [security2:error] [pid 466512:tid 466738] [client 4.194.24.143:8229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/.dj/index.php"] [unique_id "al9Y4yKGokixMSfKDOfWVwAAAnQ"]
[Tue Jul 21 08:32:51.968246 2026] [security2:error] [pid 465652:tid 465866] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/txets.php"] [unique_id "al9Y4zzTqJoBC2Mw28-0IwAAANk"]
[Tue Jul 21 08:32:52.203785 2026] [security2:error] [pid 465652:tid 465817] [client 20.197.195.24:2248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file.php"] [unique_id "al9Y5DzTqJoBC2Mw28-0JwAAAKg"]
[Tue Jul 21 08:32:52.249184 2026] [security2:error] [pid 466512:tid 466675] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/dex.php"] [unique_id "al9Y5CKGokixMSfKDOfWWwAAAjU"]
[Tue Jul 21 08:32:52.403048 2026] [security2:error] [pid 466512:tid 466754] [client 185.191.171.8:24170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tecnoturbo.com.br"] [uri "/robots.txt"] [unique_id "al9Y5CKGokixMSfKDOfWYAAAAoQ"]
[Tue Jul 21 08:32:52.403211 2026] [security2:error] [pid 466512:tid 466754] [client 185.191.171.8:24170] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tecnoturbo.com.br"] [uri "/robots.txt"] [unique_id "al9Y5CKGokixMSfKDOfWYAAAAoQ"]
[Tue Jul 21 08:32:52.541924 2026] [security2:error] [pid 466512:tid 466705] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/xpwer1.php"] [unique_id "al9Y5CKGokixMSfKDOfWYQAAAlM"]
[Tue Jul 21 08:32:52.611430 2026] [security2:error] [pid 466512:tid 466715] [client 20.206.105.145:25594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/about.php"] [unique_id "al9Y5CKGokixMSfKDOfWYgAAAl0"]
[Tue Jul 21 08:32:52.678092 2026] [security2:error] [pid 466512:tid 466674] [client 74.249.245.134:55506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/pomo.php"] [unique_id "al9Y5CKGokixMSfKDOfWZAAAAjQ"]
[Tue Jul 21 08:32:52.824131 2026] [security2:error] [pid 466512:tid 466752] [client 20.197.195.24:6359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/file.php"] [unique_id "al9Y5CKGokixMSfKDOfWZgAAAoI"]
[Tue Jul 21 08:32:52.825040 2026] [security2:error] [pid 465652:tid 465837] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/flox.php"] [unique_id "al9Y5DzTqJoBC2Mw28-0NAAAALw"]
[Tue Jul 21 08:32:52.886542 2026] [security2:error] [pid 466512:tid 466664] [client 20.197.195.24:6646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/coffexium.php"] [unique_id "al9Y5CKGokixMSfKDOfWaAAAAio"]
[Tue Jul 21 08:32:52.886868 2026] [security2:error] [pid 465652:tid 465820] [client 65.21.113.253:53808] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Y5DzTqJoBC2Mw28-0LQAAAKs"]
[Tue Jul 21 08:32:52.913501 2026] [security2:error] [pid 465652:tid 465809] [client 185.191.171.8:24176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tecnoturbo.com.br"] [uri "/"] [unique_id "al9Y5DzTqJoBC2Mw28-0NgAAAKA"]
[Tue Jul 21 08:32:52.913654 2026] [security2:error] [pid 465652:tid 465809] [client 185.191.171.8:24176] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tecnoturbo.com.br"] [uri "/"] [unique_id "al9Y5DzTqJoBC2Mw28-0NgAAAKA"]
[Tue Jul 21 08:32:53.106535 2026] [security2:error] [pid 466512:tid 466644] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/popo.php"] [unique_id "al9Y5SKGokixMSfKDOfWbAAAAhY"]
[Tue Jul 21 08:32:53.303464 2026] [security2:error] [pid 466512:tid 466760] [client 4.194.24.143:8879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/.vscode/class-wp-http-client.php"] [unique_id "al9Y5SKGokixMSfKDOfWbgAAAoo"]
[Tue Jul 21 08:32:53.388448 2026] [security2:error] [pid 466512:tid 466657] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/yas.php"] [unique_id "al9Y5SKGokixMSfKDOfWcQAAAiM"]
[Tue Jul 21 08:32:53.615905 2026] [security2:error] [pid 466512:tid 466723] [client 20.197.195.24:17042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/core.php"] [unique_id "al9Y5SKGokixMSfKDOfWewAAAmU"]
[Tue Jul 21 08:32:53.669486 2026] [security2:error] [pid 466512:tid 466684] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/file61.php"] [unique_id "al9Y5SKGokixMSfKDOfWfAAAAj4"]
[Tue Jul 21 08:32:53.691945 2026] [security2:error] [pid 465652:tid 465798] [client 20.197.195.24:3922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/777.php"] [unique_id "al9Y5TzTqJoBC2Mw28-0PgAAAJU"]
[Tue Jul 21 08:32:53.942363 2026] [security2:error] [pid 466512:tid 466687] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/water.php"] [unique_id "al9Y5SKGokixMSfKDOfWhAAAAkE"]
[Tue Jul 21 08:32:53.984795 2026] [security2:error] [pid 466512:tid 466678] [client 20.197.195.24:57976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/als.php"] [unique_id "al9Y5SKGokixMSfKDOfWhQAAAjg"]
[Tue Jul 21 08:32:54.216921 2026] [security2:error] [pid 465652:tid 465834] [client 102.209.137.222:49319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.137.209.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9Y5jzTqJoBC2Mw28-0SwAAALk"]
[Tue Jul 21 08:32:54.217069 2026] [security2:error] [pid 465652:tid 465834] [client 102.209.137.222:49319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9Y5jzTqJoBC2Mw28-0SwAAALk"]
[Tue Jul 21 08:32:54.249513 2026] [security2:error] [pid 466512:tid 466708] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/nano.php"] [unique_id "al9Y5iKGokixMSfKDOfWiQAAAlY"]
[Tue Jul 21 08:32:54.304626 2026] [security2:error] [pid 466512:tid 466734] [client 195.49.128.211:57208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Y5iKGokixMSfKDOfWigAAAnA"]
[Tue Jul 21 08:32:54.304851 2026] [security2:error] [pid 466512:tid 466734] [client 195.49.128.211:57208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Y5iKGokixMSfKDOfWigAAAnA"]
[Tue Jul 21 08:32:54.310434 2026] [security2:error] [pid 466512:tid 466741] [client 20.197.195.24:57925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/simple.php"] [unique_id "al9Y5iKGokixMSfKDOfWiwAAAnc"]
[Tue Jul 21 08:32:54.346469 2026] [autoindex:error] [pid 466512:tid 466668] [client 4.194.24.143:52784] AH01276: Cannot serve directory /home4/juliob58/wbapoiocontabil.com.br/.well-known/: No matching DirectoryIndex (paginafacil.php,default.html,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:54.465804 2026] [security2:error] [pid 466512:tid 466597] [remote 199.189.225.40:62907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "trconsultcontabilidade.com"] [uri "/wp-login.php"] [unique_id "al9Y5iKGokixMSfKDOfWjgACFVQ"]
[Tue Jul 21 08:32:54.522731 2026] [security2:error] [pid 466512:tid 466718] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/moon.php"] [unique_id "al9Y5iKGokixMSfKDOfWkQAAAmA"]
[Tue Jul 21 08:32:54.574078 2026] [security2:error] [pid 466512:tid 466715] [client 20.197.195.24:17053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/init.php"] [unique_id "al9Y5iKGokixMSfKDOfWkgAAAl0"]
[Tue Jul 21 08:32:54.690931 2026] [security2:error] [pid 466512:tid 466694] [client 4.194.24.143:52784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Y5iKGokixMSfKDOfWlAAAAkg"]
[Tue Jul 21 08:32:54.750393 2026] [security2:error] [pid 465652:tid 465852] [client 20.197.195.24:3958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ssixta.php"] [unique_id "al9Y5jzTqJoBC2Mw28-0UwAAAMs"]
[Tue Jul 21 08:32:54.830910 2026] [security2:error] [pid 465652:tid 465906] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-info.php"] [unique_id "al9Y5jzTqJoBC2Mw28-0VgAAAQE"]
[Tue Jul 21 08:32:54.930296 2026] [security2:error] [pid 465652:tid 465862] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/index.php"] [unique_id "al9Y5jzTqJoBC2Mw28-0VwAAANU"]
[Tue Jul 21 08:32:54.931103 2026] [security2:error] [pid 465652:tid 465824] [client 20.10.88.227:2369] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/robots.txt"] [unique_id "al9Y5jzTqJoBC2Mw28-0VAAAAK8"]
[Tue Jul 21 08:32:54.981434 2026] [security2:error] [pid 465652:tid 465854] [client 20.197.192.193:65173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/8.php"] [unique_id "al9Y5jzTqJoBC2Mw28-0XgAAAM0"]
[Tue Jul 21 08:32:54.985962 2026] [security2:error] [pid 466512:tid 466758] [client 150.129.202.39:13345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y5iKGokixMSfKDOfWmwAAAog"]
[Tue Jul 21 08:32:54.986064 2026] [security2:error] [pid 466512:tid 466758] [client 150.129.202.39:13345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y5iKGokixMSfKDOfWmwAAAog"]
[Tue Jul 21 08:32:55.111352 2026] [security2:error] [pid 466512:tid 466666] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/2000.php"] [unique_id "al9Y5yKGokixMSfKDOfWogAAAiw"]
[Tue Jul 21 08:32:55.176962 2026] [security2:error] [pid 466512:tid 466697] [client 20.197.195.24:16041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/1c.php"] [unique_id "al9Y5yKGokixMSfKDOfWowAAAks"]
[Tue Jul 21 08:32:55.317406 2026] [security2:error] [pid 466512:tid 466695] [client 223.181.60.88:2476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Y5yKGokixMSfKDOfWpAAAAkk"]
[Tue Jul 21 08:32:55.317612 2026] [security2:error] [pid 466512:tid 466695] [client 223.181.60.88:2476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Y5yKGokixMSfKDOfWpAAAAkk"]
[Tue Jul 21 08:32:55.376439 2026] [security2:error] [pid 466512:tid 466630] [remote 104.207.50.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "alphafix.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Y5yKGokixMSfKDOfWqAACGnU"]
[Tue Jul 21 08:32:55.410054 2026] [security2:error] [pid 466512:tid 466690] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/122.php"] [unique_id "al9Y5yKGokixMSfKDOfWqQAAAkQ"]
[Tue Jul 21 08:32:55.535619 2026] [security2:error] [pid 466512:tid 466767] [client 20.197.195.24:6373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/test2.php"] [unique_id "al9Y5yKGokixMSfKDOfWrgAAApE"]
[Tue Jul 21 08:32:55.712494 2026] [security2:error] [pid 466512:tid 466719] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/mds.php"] [unique_id "al9Y5yKGokixMSfKDOfWsAAAAmE"]
[Tue Jul 21 08:32:55.725944 2026] [autoindex:error] [pid 466512:tid 466751] [client 4.194.24.143:8842] AH01276: Cannot serve directory /home4/juliob58/wbapoiocontabil.com.br/.well-known/acme-challenge/: No matching DirectoryIndex (paginafacil.php,default.html,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:32:55.783798 2026] [security2:error] [pid 466512:tid 466759] [client 20.197.195.24:6318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/buy.php"] [unique_id "al9Y5yKGokixMSfKDOfWswAAAok"]
[Tue Jul 21 08:32:55.909214 2026] [security2:error] [pid 466512:tid 466717] [client 20.197.192.193:5588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/mimpi.php"] [unique_id "al9Y5yKGokixMSfKDOfWuAAAAl8"]
[Tue Jul 21 08:32:55.989039 2026] [security2:error] [pid 465652:tid 465814] [client 20.197.195.24:57916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/fpwch.php"] [unique_id "al9Y5zzTqJoBC2Mw28-0awAAAKU"]
[Tue Jul 21 08:32:55.996311 2026] [security2:error] [pid 466512:tid 466722] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-blink.php"] [unique_id "al9Y5yKGokixMSfKDOfWugAAAmQ"]
[Tue Jul 21 08:32:56.141837 2026] [security2:error] [pid 466512:tid 466714] [client 152.59.181.104:59825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Y6CKGokixMSfKDOfWwAAAAlw"]
[Tue Jul 21 08:32:56.141987 2026] [security2:error] [pid 466512:tid 466714] [client 152.59.181.104:59825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Y6CKGokixMSfKDOfWwAAAAlw"]
[Tue Jul 21 08:32:56.157485 2026] [security2:error] [pid 466512:tid 466681] [client 20.197.195.24:6379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ssend.php"] [unique_id "al9Y6CKGokixMSfKDOfWwQAAAjs"]
[Tue Jul 21 08:32:56.205611 2026] [security2:error] [pid 466512:tid 466715] [client 20.197.192.193:5575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/dp.php"] [unique_id "al9Y6CKGokixMSfKDOfWwgAAAl0"]
[Tue Jul 21 08:32:56.247807 2026] [security2:error] [pid 465652:tid 465897] [client 20.197.195.24:3916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/item.php"] [unique_id "al9Y6DzTqJoBC2Mw28-0cwAAAPg"]
[Tue Jul 21 08:32:56.271293 2026] [security2:error] [pid 465652:tid 465800] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/zc-208.php"] [unique_id "al9Y6DzTqJoBC2Mw28-0dAAAAJc"]
[Tue Jul 21 08:32:56.342977 2026] [security2:error] [pid 465652:tid 465822] [client 20.197.192.193:5576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/bootstrap.php"] [unique_id "al9Y6DzTqJoBC2Mw28-0dQAAAK0"]
[Tue Jul 21 08:32:56.427396 2026] [security2:error] [pid 465652:tid 465805] [client 20.197.192.193:5968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wp-editor.php"] [unique_id "al9Y6DzTqJoBC2Mw28-0dwAAAJw"]
[Tue Jul 21 08:32:56.437920 2026] [security2:error] [pid 466512:tid 466766] [client 4.194.24.143:8842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/.well-known/acme-challenge/muse.php"] [unique_id "al9Y6CKGokixMSfKDOfWxgAAApA"]
[Tue Jul 21 08:32:56.463194 2026] [security2:error] [pid 466512:tid 466664] [client 20.197.195.24:3865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ss.php"] [unique_id "al9Y6CKGokixMSfKDOfWxwAAAio"]
[Tue Jul 21 08:32:56.497977 2026] [security2:error] [pid 465652:tid 465843] [client 20.197.192.193:5577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/cro.php"] [unique_id "al9Y6DzTqJoBC2Mw28-0eQAAAMI"]
[Tue Jul 21 08:32:56.544062 2026] [security2:error] [pid 466512:tid 466721] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/sid4.php"] [unique_id "al9Y6CKGokixMSfKDOfWyQAAAmM"]
[Tue Jul 21 08:32:56.581297 2026] [security2:error] [pid 466512:tid 466744] [client 20.197.192.193:5987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/cron-tab.php"] [unique_id "al9Y6CKGokixMSfKDOfWygAAAno"]
[Tue Jul 21 08:32:56.643072 2026] [security2:error] [pid 465652:tid 465856] [client 20.197.192.193:5606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/koiy.php"] [unique_id "al9Y6DzTqJoBC2Mw28-0fgAAAM8"]
[Tue Jul 21 08:32:56.757291 2026] [security2:error] [pid 466512:tid 466665] [client 20.197.192.193:46178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/hp2.php"] [unique_id "al9Y6CKGokixMSfKDOfWywAAAis"]
[Tue Jul 21 08:32:56.771960 2026] [security2:error] [pid 466512:tid 466758] [client 20.197.195.24:6342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/hypo.php"] [unique_id "al9Y6CKGokixMSfKDOfWzAAAAog"]
[Tue Jul 21 08:32:56.827525 2026] [security2:error] [pid 466512:tid 466716] [client 20.206.105.145:25557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/admin.php"] [unique_id "al9Y6CKGokixMSfKDOfWzQAAAl4"]
[Tue Jul 21 08:32:56.923107 2026] [proxy:error] [pid 466512:tid 466702] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:56.923154 2026] [proxy_http:error] [pid 466512:tid 466702] [client 198.235.24.130:61696] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:56.923876 2026] [proxy:error] [pid 466512:tid 466702] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:32:56.923905 2026] [proxy_http:error] [pid 466512:tid 466702] [client 198.235.24.130:61696] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:32:57.006886 2026] [security2:error] [pid 465652:tid 465864] [client 125.18.144.2:36558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y6TzTqJoBC2Mw28-0hAAAANc"]
[Tue Jul 21 08:32:57.007013 2026] [security2:error] [pid 465652:tid 465864] [client 125.18.144.2:36558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y6TzTqJoBC2Mw28-0hAAAANc"]
[Tue Jul 21 08:32:57.092660 2026] [security2:error] [pid 465652:tid 465873] [client 20.197.195.24:6316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/users.php"] [unique_id "al9Y6TzTqJoBC2Mw28-0iAAAAOA"]
[Tue Jul 21 08:32:57.098734 2026] [security2:error] [pid 466512:tid 466684] [client 117.213.202.34:63452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y6CKGokixMSfKDOfWvwAAAj4"]
[Tue Jul 21 08:32:57.098839 2026] [security2:error] [pid 466512:tid 466684] [client 117.213.202.34:63452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y6CKGokixMSfKDOfWvwAAAj4"]
[Tue Jul 21 08:32:57.152295 2026] [security2:error] [pid 466512:tid 466695] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wmore1.php"] [unique_id "al9Y6SKGokixMSfKDOfW1AAAAkk"]
[Tue Jul 21 08:32:57.278259 2026] [security2:error] [pid 466512:tid 466655] [client 109.248.148.246:45724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Y6SKGokixMSfKDOfW1gAAAiE"]
[Tue Jul 21 08:32:57.278432 2026] [security2:error] [pid 466512:tid 466655] [client 109.248.148.246:45724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Y6SKGokixMSfKDOfW1gAAAiE"]
[Tue Jul 21 08:32:57.279186 2026] [security2:error] [pid 465652:tid 465849] [client 122.176.100.127:54387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Y6TzTqJoBC2Mw28-0igAAAMg"]
[Tue Jul 21 08:32:57.279727 2026] [security2:error] [pid 465652:tid 465849] [client 122.176.100.127:54387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Y6TzTqJoBC2Mw28-0igAAAMg"]
[Tue Jul 21 08:32:57.426014 2026] [security2:error] [pid 466512:tid 466653] [client 20.197.195.24:18729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/domvf.php"] [unique_id "al9Y6SKGokixMSfKDOfW2AAAAh8"]
[Tue Jul 21 08:32:57.431553 2026] [security2:error] [pid 466512:tid 466704] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/solo1.php"] [unique_id "al9Y6SKGokixMSfKDOfW2QAAAlI"]
[Tue Jul 21 08:32:57.496314 2026] [security2:error] [pid 465652:tid 465874] [client 4.194.24.143:17036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/.well-known/bdkr28_61cohkhh.php"] [unique_id "al9Y6TzTqJoBC2Mw28-0jgAAAOE"]
[Tue Jul 21 08:32:57.525407 2026] [security2:error] [pid 466512:tid 466706] [client 20.197.192.193:5600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/hp3.php"] [unique_id "al9Y6SKGokixMSfKDOfW2wAAAlQ"]
[Tue Jul 21 08:32:57.538711 2026] [security2:error] [pid 465652:tid 465865] [client 74.249.245.134:37722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/test1.php"] [unique_id "al9Y6TzTqJoBC2Mw28-0jwAAANg"]
[Tue Jul 21 08:32:57.821762 2026] [security2:error] [pid 466512:tid 466682] [client 20.197.195.24:57903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/wp.php"] [unique_id "al9Y6SKGokixMSfKDOfW5QAAAjw"]
[Tue Jul 21 08:32:57.896436 2026] [security2:error] [pid 466512:tid 466672] [client 20.197.192.193:43809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/red.php"] [unique_id "al9Y6SKGokixMSfKDOfW5gAAAjI"]
[Tue Jul 21 08:32:57.903571 2026] [security2:error] [pid 466512:tid 466712] [client 49.144.66.253:33440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Y6SKGokixMSfKDOfW5wAAAlo"]
[Tue Jul 21 08:32:57.903651 2026] [security2:error] [pid 466512:tid 466712] [client 49.144.66.253:33440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Y6SKGokixMSfKDOfW5wAAAlo"]
[Tue Jul 21 08:32:58.022869 2026] [security2:error] [pid 466512:tid 466705] [client 20.197.195.24:3932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/177.php"] [unique_id "al9Y6iKGokixMSfKDOfW6gAAAlM"]
[Tue Jul 21 08:32:58.322026 2026] [security2:error] [pid 466512:tid 466675] [client 20.197.195.24:57967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/class.php"] [unique_id "al9Y6iKGokixMSfKDOfW8gAAAjU"]
[Tue Jul 21 08:32:58.373184 2026] [security2:error] [pid 465652:tid 465788] [client 20.197.192.193:5573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/aa1.php"] [unique_id "al9Y6jzTqJoBC2Mw28-0oQAAAIs"]
[Tue Jul 21 08:32:58.431510 2026] [security2:error] [pid 465652:tid 465894] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/cong.php"] [unique_id "al9Y6jzTqJoBC2Mw28-0ogAAAPU"]
[Tue Jul 21 08:32:58.489630 2026] [security2:error] [pid 466512:tid 466535] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Y6iKGokixMSfKDOfW8wACjxY"]
[Tue Jul 21 08:32:58.514935 2026] [security2:error] [pid 465652:tid 465854] [client 31.40.204.182:46504] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.204.40.31.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "privatesafesale.com"] [uri "/wp-comments-post.php"] [unique_id "al9Y6jzTqJoBC2Mw28-0nwAAAM0"], referer: https://privatesafesale.com/2026/06/24/hello-world/
[Tue Jul 21 08:32:58.515086 2026] [security2:error] [pid 465652:tid 465854] [client 31.40.204.182:46504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "privatesafesale.com"] [uri "/wp-comments-post.php"] [unique_id "al9Y6jzTqJoBC2Mw28-0nwAAAM0"], referer: https://privatesafesale.com/2026/06/24/hello-world/
[Tue Jul 21 08:32:58.521614 2026] [security2:error] [pid 465652:tid 465866] [client 20.197.192.193:65203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/byp8.php"] [unique_id "al9Y6jzTqJoBC2Mw28-0owAAANk"]
[Tue Jul 21 08:32:58.533289 2026] [security2:error] [pid 465652:tid 465909] [client 4.194.24.143:15656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/.well-known/class-wp-http-client.php"] [unique_id "al9Y6jzTqJoBC2Mw28-0pAAAAQQ"]
[Tue Jul 21 08:32:58.596460 2026] [security2:error] [pid 466512:tid 466665] [client 128.127.105.184:55482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Y6iKGokixMSfKDOfW9QAAAis"]
[Tue Jul 21 08:32:58.596545 2026] [security2:error] [pid 466512:tid 466665] [client 128.127.105.184:55482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Y6iKGokixMSfKDOfW9QAAAis"]
[Tue Jul 21 08:32:58.599248 2026] [security2:error] [pid 466512:tid 466656] [client 195.49.128.211:49338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y6iKGokixMSfKDOfW9gAAAiI"]
[Tue Jul 21 08:32:58.601779 2026] [security2:error] [pid 466512:tid 466656] [client 195.49.128.211:49338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y6iKGokixMSfKDOfW9gAAAiI"]
[Tue Jul 21 08:32:58.664031 2026] [security2:error] [pid 466512:tid 466662] [client 20.197.195.24:6611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/echkm.php"] [unique_id "al9Y6iKGokixMSfKDOfW-wAAAig"]
[Tue Jul 21 08:32:58.808817 2026] [security2:error] [pid 466512:tid 466703] [client 89.238.167.134:39440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Y6iKGokixMSfKDOfXAgAAAlE"]
[Tue Jul 21 08:32:58.808891 2026] [security2:error] [pid 466512:tid 466703] [client 89.238.167.134:39440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Y6iKGokixMSfKDOfXAgAAAlE"]
[Tue Jul 21 08:32:58.828482 2026] [security2:error] [pid 466512:tid 466746] [client 74.249.245.134:37715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/fw.php"] [unique_id "al9Y6iKGokixMSfKDOfXAwAAAnw"]
[Tue Jul 21 08:32:58.866036 2026] [security2:error] [pid 466512:tid 466728] [client 20.197.195.24:15687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/config.php"] [unique_id "al9Y6iKGokixMSfKDOfXBgAAAmo"]
[Tue Jul 21 08:32:58.986622 2026] [security2:error] [pid 466512:tid 466671] [client 20.197.195.24:18697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/lib.php"] [unique_id "al9Y6iKGokixMSfKDOfXCAAAAjE"]
[Tue Jul 21 08:32:59.000868 2026] [security2:error] [pid 466512:tid 466695] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/public/css.php"] [unique_id "al9Y6iKGokixMSfKDOfXCQAAAkk"]
[Tue Jul 21 08:32:59.038079 2026] [security2:error] [pid 465652:tid 465876] [client 103.151.46.103:62739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Y6zzTqJoBC2Mw28-0twAAAOM"]
[Tue Jul 21 08:32:59.038203 2026] [security2:error] [pid 465652:tid 465876] [client 103.151.46.103:62739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Y6zzTqJoBC2Mw28-0twAAAOM"]
[Tue Jul 21 08:32:59.053985 2026] [security2:error] [pid 466512:tid 466655] [client 20.197.192.193:5592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/acew67.php"] [unique_id "al9Y6yKGokixMSfKDOfXCgAAAiE"]
[Tue Jul 21 08:32:59.287222 2026] [security2:error] [pid 465652:tid 465903] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/output.php"] [unique_id "al9Y6zzTqJoBC2Mw28-0vQAAAP4"]
[Tue Jul 21 08:32:59.423017 2026] [security2:error] [pid 466512:tid 466687] [client 20.197.195.24:3911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/gettest.php"] [unique_id "al9Y6yKGokixMSfKDOfXDwAAAkE"]
[Tue Jul 21 08:32:59.439281 2026] [security2:error] [pid 466512:tid 466653] [client 104.207.50.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "alphafix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y6yKGokixMSfKDOfXDQACHwU"]
[Tue Jul 21 08:32:59.561928 2026] [security2:error] [pid 465652:tid 465856] [client 4.194.24.143:8198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "al9Y6zzTqJoBC2Mw28-0vwAAAM8"]
[Tue Jul 21 08:32:59.591021 2026] [security2:error] [pid 466512:tid 466706] [client 20.197.195.24:17038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/login.php"] [unique_id "al9Y6yKGokixMSfKDOfXEAAAAlQ"]
[Tue Jul 21 08:32:59.619568 2026] [security2:error] [pid 465652:tid 465846] [client 20.197.195.24:6366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/min.php"] [unique_id "al9Y6zzTqJoBC2Mw28-0wQAAAMU"]
[Tue Jul 21 08:32:59.655730 2026] [security2:error] [pid 466512:tid 466666] [client 5.38.115.39:64126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Y6yKGokixMSfKDOfXEwAAAiw"]
[Tue Jul 21 08:32:59.655835 2026] [security2:error] [pid 466512:tid 466666] [client 5.38.115.39:64126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Y6yKGokixMSfKDOfXEwAAAiw"]
[Tue Jul 21 08:32:59.777791 2026] [security2:error] [pid 466512:tid 466719] [client 104.207.50.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "alphafix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y6yKGokixMSfKDOfXFgACYW0"]
[Tue Jul 21 08:32:59.910809 2026] [security2:error] [pid 466512:tid 466682] [client 20.197.195.24:57971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/a2.php"] [unique_id "al9Y6yKGokixMSfKDOfXGgAAAjw"]
[Tue Jul 21 08:32:59.970432 2026] [security2:error] [pid 466512:tid 466722] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-file-120.php"] [unique_id "al9Y6yKGokixMSfKDOfXHAAAAmQ"]
[Tue Jul 21 08:32:59.976961 2026] [security2:error] [pid 466512:tid 466643] [client 20.206.105.145:25598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/admin.php"] [unique_id "al9Y6yKGokixMSfKDOfXHQAAAhU"]
[Tue Jul 21 08:32:59.999016 2026] [security2:error] [pid 465652:tid 465680] [remote 49.13.1.223:60036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "escoladaseguranca.com.br"] [uri "/wp-login.php"] [unique_id "al9Y6zzTqJoBC2Mw28-0zAAA6Rs"]
[Tue Jul 21 08:33:00.113585 2026] [security2:error] [pid 466512:tid 466654] [client 104.207.50.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "alphafix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y7CKGokixMSfKDOfXHgACICk"]
[Tue Jul 21 08:33:00.149703 2026] [security2:error] [pid 465652:tid 465825] [client 14.245.224.124:57400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Y7DzTqJoBC2Mw28-0zQAAALA"]
[Tue Jul 21 08:33:00.149830 2026] [security2:error] [pid 465652:tid 465825] [client 14.245.224.124:57400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Y7DzTqJoBC2Mw28-0zQAAALA"]
[Tue Jul 21 08:33:00.186259 2026] [security2:error] [pid 466512:tid 466707] [client 89.238.167.134:39446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Y7CKGokixMSfKDOfXIAAAAlU"]
[Tue Jul 21 08:33:00.186366 2026] [security2:error] [pid 466512:tid 466707] [client 89.238.167.134:39446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9Y7CKGokixMSfKDOfXIAAAAlU"]
[Tue Jul 21 08:33:00.203076 2026] [security2:error] [pid 465652:tid 465901] [client 20.197.192.193:43790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/fffm.php"] [unique_id "al9Y7DzTqJoBC2Mw28-0zgAAAPw"]
[Tue Jul 21 08:33:00.379382 2026] [security2:error] [pid 465652:tid 465890] [client 20.197.195.24:18688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/d61.php"] [unique_id "al9Y7DzTqJoBC2Mw28-01AAAAPE"]
[Tue Jul 21 08:33:00.426345 2026] [security2:error] [pid 466512:tid 466664] [client 187.125.243.197:50612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Y7CKGokixMSfKDOfXJAAAAio"]
[Tue Jul 21 08:33:00.426456 2026] [security2:error] [pid 466512:tid 466664] [client 187.125.243.197:50612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Y7CKGokixMSfKDOfXJAAAAio"]
[Tue Jul 21 08:33:00.572998 2026] [security2:error] [pid 466512:tid 466721] [client 20.197.192.193:46181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/bscclapb.php"] [unique_id "al9Y7CKGokixMSfKDOfXJwAAAmM"]
[Tue Jul 21 08:33:00.589378 2026] [security2:error] [pid 465652:tid 465830] [client 4.194.24.143:52782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/.well-known/index.php"] [unique_id "al9Y7DzTqJoBC2Mw28-02AAAALU"]
[Tue Jul 21 08:33:00.595656 2026] [security2:error] [pid 465652:tid 465835] [client 213.152.186.163:39856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Y7DzTqJoBC2Mw28-02gAAALo"]
[Tue Jul 21 08:33:00.595731 2026] [security2:error] [pid 465652:tid 465835] [client 213.152.186.163:39856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Y7DzTqJoBC2Mw28-02gAAALo"]
[Tue Jul 21 08:33:00.625389 2026] [security2:error] [pid 465652:tid 465788] [client 20.197.195.24:57922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/info.php"] [unique_id "al9Y7DzTqJoBC2Mw28-02wAAAIs"]
[Tue Jul 21 08:33:00.649999 2026] [security2:error] [pid 465652:tid 465666] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Y7DzTqJoBC2Mw28-03AAAqQ0"]
[Tue Jul 21 08:33:00.650149 2026] [security2:error] [pid 465652:tid 465818] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Y7DzTqJoBC2Mw28-03AAAqQ0"]
[Tue Jul 21 08:33:00.659057 2026] [security2:error] [pid 465652:tid 465894] [client 89.238.167.134:39452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Y7DzTqJoBC2Mw28-03gAAAPU"]
[Tue Jul 21 08:33:00.659187 2026] [security2:error] [pid 465652:tid 465894] [client 89.238.167.134:39452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Y7DzTqJoBC2Mw28-03gAAAPU"]
[Tue Jul 21 08:33:00.711497 2026] [security2:error] [pid 465652:tid 465909] [client 74.249.245.134:55511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/fm.php"] [unique_id "al9Y7DzTqJoBC2Mw28-04gAAAQQ"]
[Tue Jul 21 08:33:00.751156 2026] [security2:error] [pid 465652:tid 465853] [client 20.197.195.24:18724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/11.php"] [unique_id "al9Y7DzTqJoBC2Mw28-05QAAAMw"]
[Tue Jul 21 08:33:00.779145 2026] [security2:error] [pid 465652:tid 465658] [remote 45.79.123.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produto-express.com"] [uri "/wp-login.php"] [unique_id "al9Y7DzTqJoBC2Mw28-05wAA0gU"]
[Tue Jul 21 08:33:00.958993 2026] [security2:error] [pid 466512:tid 466768] [client 20.197.195.24:3912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/dvjul.php"] [unique_id "al9Y7CKGokixMSfKDOfXNAAAApI"]
[Tue Jul 21 08:33:01.034040 2026] [security2:error] [pid 466512:tid 466746] [client 20.197.192.193:48327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/ftde.php"] [unique_id "al9Y7SKGokixMSfKDOfXNQAAAnw"]
[Tue Jul 21 08:33:01.048106 2026] [security2:error] [pid 466512:tid 466727] [client 104.207.50.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "alphafix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y7CKGokixMSfKDOfXMwACaXQ"]
[Tue Jul 21 08:33:01.100597 2026] [security2:error] [pid 466512:tid 466645] [client 74.249.245.134:43380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Y7SKGokixMSfKDOfXNwAAAhc"]
[Tue Jul 21 08:33:01.219455 2026] [security2:error] [pid 465652:tid 465841] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/special.php"] [unique_id "al9Y7TzTqJoBC2Mw28-07gAAAMA"]
[Tue Jul 21 08:33:01.235485 2026] [security2:error] [pid 465652:tid 465842] [client 20.197.195.24:6628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/v2.php"] [unique_id "al9Y7TzTqJoBC2Mw28-08AAAAME"]
[Tue Jul 21 08:33:01.289273 2026] [security2:error] [pid 466512:tid 466667] [remote 104.207.50.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "alphafix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y7CKGokixMSfKDOfXKAACj0A"]
[Tue Jul 21 08:33:01.394083 2026] [security2:error] [pid 466512:tid 466689] [client 20.197.195.24:6623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/panel.php"] [unique_id "al9Y7SKGokixMSfKDOfXOwAAAkM"]
[Tue Jul 21 08:33:01.420508 2026] [security2:error] [pid 465652:tid 465875] [client 74.7.241.128:56030] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.mateusantt.com.br.mateusdespachante.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9Y7TzTqJoBC2Mw28-09QAA4jQ"]
[Tue Jul 21 08:33:01.435191 2026] [security2:error] [pid 466512:tid 466667] [client 104.207.50.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "alphafix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y7SKGokixMSfKDOfXOQACLU4"]
[Tue Jul 21 08:33:01.504073 2026] [security2:error] [pid 466512:tid 466704] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/as.php"] [unique_id "al9Y7SKGokixMSfKDOfXPAAAAlI"]
[Tue Jul 21 08:33:01.643582 2026] [security2:error] [pid 466512:tid 466709] [client 4.194.24.143:5796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/.well-known/ws.php"] [unique_id "al9Y7SKGokixMSfKDOfXQAAAAlc"]
[Tue Jul 21 08:33:01.736141 2026] [security2:error] [pid 466512:tid 466670] [client 20.197.195.24:17046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/dex.php"] [unique_id "al9Y7SKGokixMSfKDOfXQgAAAjA"]
[Tue Jul 21 08:33:01.773035 2026] [security2:error] [pid 466512:tid 466755] [client 20.197.195.24:3851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/biufile.php"] [unique_id "al9Y7SKGokixMSfKDOfXRQAAAoU"]
[Tue Jul 21 08:33:01.785340 2026] [security2:error] [pid 466512:tid 466734] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Y7SKGokixMSfKDOfXSAAAAnA"]
[Tue Jul 21 08:33:01.788079 2026] [security2:error] [pid 466512:tid 466653] [client 104.207.50.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "alphafix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y7SKGokixMSfKDOfXQQACH0w"]
[Tue Jul 21 08:33:01.888664 2026] [security2:error] [pid 466512:tid 466723] [client 20.197.195.24:18714] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/1.php"] [unique_id "al9Y7SKGokixMSfKDOfXSgAAAmU"]
[Tue Jul 21 08:33:01.888772 2026] [security2:error] [pid 466512:tid 466723] [client 20.197.195.24:18714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/1.php"] [unique_id "al9Y7SKGokixMSfKDOfXSgAAAmU"]
[Tue Jul 21 08:33:02.071471 2026] [security2:error] [pid 466512:tid 466712] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/w1px.php"] [unique_id "al9Y7iKGokixMSfKDOfXTAAAAlo"]
[Tue Jul 21 08:33:02.127615 2026] [security2:error] [pid 466512:tid 466679] [client 20.104.96.117:62656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Y7iKGokixMSfKDOfXTwAAAjk"]
[Tue Jul 21 08:33:02.139638 2026] [security2:error] [pid 466512:tid 466643] [client 104.207.50.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "alphafix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y7iKGokixMSfKDOfXSwACFXI"]
[Tue Jul 21 08:33:02.168055 2026] [security2:error] [pid 465652:tid 465856] [client 202.179.75.202:42928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Y7jzTqJoBC2Mw28-0_AAAAM8"]
[Tue Jul 21 08:33:02.168162 2026] [security2:error] [pid 465652:tid 465856] [client 202.179.75.202:42928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Y7jzTqJoBC2Mw28-0_AAAAM8"]
[Tue Jul 21 08:33:02.210076 2026] [security2:error] [pid 466512:tid 466654] [client 20.197.192.193:5980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/else1.php"] [unique_id "al9Y7iKGokixMSfKDOfXUgAAAiA"]
[Tue Jul 21 08:33:02.353331 2026] [security2:error] [pid 465652:tid 465850] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/yawa.php"] [unique_id "al9Y7jzTqJoBC2Mw28-1AgAAAMk"]
[Tue Jul 21 08:33:02.484633 2026] [security2:error] [pid 466512:tid 466652] [client 20.197.195.24:64250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/av.php"] [unique_id "al9Y7iKGokixMSfKDOfXVQAAAh4"]
[Tue Jul 21 08:33:02.627797 2026] [security2:error] [pid 465652:tid 465786] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/js.php"] [unique_id "al9Y7jzTqJoBC2Mw28-1CgAAAIk"]
[Tue Jul 21 08:33:02.656674 2026] [security2:error] [pid 465652:tid 465845] [client 20.206.105.145:25568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/edit.php"] [unique_id "al9Y7jzTqJoBC2Mw28-1CwAAAMQ"]
[Tue Jul 21 08:33:02.662129 2026] [security2:error] [pid 465652:tid 465824] [client 20.104.96.117:62689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Y7jzTqJoBC2Mw28-1DAAAAK8"]
[Tue Jul 21 08:33:02.699515 2026] [security2:error] [pid 466512:tid 466715] [client 4.194.24.143:8254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/.xa/class-wp-http-client.php"] [unique_id "al9Y7iKGokixMSfKDOfXWAAAAl0"]
[Tue Jul 21 08:33:02.702662 2026] [security2:error] [pid 466512:tid 466644] [client 104.207.50.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "alphafix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y7iKGokixMSfKDOfXVgACFjo"]
[Tue Jul 21 08:33:02.752381 2026] [security2:error] [pid 465652:tid 465889] [client 20.197.195.24:17051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/ms.php"] [unique_id "al9Y7jzTqJoBC2Mw28-1DgAAAPA"]
[Tue Jul 21 08:33:02.905624 2026] [security2:error] [pid 466512:tid 466657] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/core.php"] [unique_id "al9Y7iKGokixMSfKDOfXXAAAAiM"]
[Tue Jul 21 08:33:02.922649 2026] [security2:error] [pid 466512:tid 466514] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Y7iKGokixMSfKDOfXXgACJwE"]
[Tue Jul 21 08:33:02.961901 2026] [security2:error] [pid 466512:tid 466711] [client 20.104.96.117:64205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/xyn.php"] [unique_id "al9Y7iKGokixMSfKDOfXYAAAAlk"]
[Tue Jul 21 08:33:03.043604 2026] [security2:error] [pid 466512:tid 466702] [client 104.207.50.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "alphafix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y7iKGokixMSfKDOfXXwACUE0"]
[Tue Jul 21 08:33:03.070895 2026] [security2:error] [pid 466512:tid 466754] [client 103.138.211.203:55745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.211.138.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jpglow.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y7iKGokixMSfKDOfXXQAAAoQ"]
[Tue Jul 21 08:33:03.071048 2026] [security2:error] [pid 466512:tid 466754] [client 103.138.211.203:55745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jpglow.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y7iKGokixMSfKDOfXXQAAAoQ"]
[Tue Jul 21 08:33:03.194334 2026] [proxy:error] [pid 466512:tid 466669] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:33:03.194416 2026] [proxy_http:error] [pid 466512:tid 466669] [client 20.197.195.24:18739] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:33:03.195140 2026] [proxy:error] [pid 466512:tid 466669] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:33:03.195168 2026] [proxy_http:error] [pid 466512:tid 466669] [client 20.197.195.24:18739] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:33:03.219576 2026] [security2:error] [pid 465652:tid 465872] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/19.php"] [unique_id "al9Y7zzTqJoBC2Mw28-1GwAAAN8"]
[Tue Jul 21 08:33:03.286957 2026] [security2:error] [pid 466512:tid 466586] [remote 104.207.50.251:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "alphafix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y7yKGokixMSfKDOfXZQACREk"]
[Tue Jul 21 08:33:03.287251 2026] [security2:error] [pid 466512:tid 466586] [remote 104.207.50.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "alphafix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y7yKGokixMSfKDOfXZQACREk"]
[Tue Jul 21 08:33:03.291309 2026] [security2:error] [pid 466512:tid 466667] [client 20.197.192.193:6004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/tkikikoko.php"] [unique_id "al9Y7yKGokixMSfKDOfXZgAAAi0"]
[Tue Jul 21 08:33:03.382212 2026] [security2:error] [pid 466512:tid 466584] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/x.php"] [unique_id "al9Y7yKGokixMSfKDOfXaAACk0c"]
[Tue Jul 21 08:33:03.458506 2026] [security2:error] [pid 465652:tid 465908] [client 5.31.193.106:30007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Y7zzTqJoBC2Mw28-1JAAAAQM"]
[Tue Jul 21 08:33:03.458638 2026] [security2:error] [pid 465652:tid 465908] [client 5.31.193.106:30007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Y7zzTqJoBC2Mw28-1JAAAAQM"]
[Tue Jul 21 08:33:03.493927 2026] [security2:error] [pid 466512:tid 466658] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/inc.php"] [unique_id "al9Y7yKGokixMSfKDOfXagAAAiQ"]
[Tue Jul 21 08:33:03.506146 2026] [security2:error] [pid 465652:tid 465782] [client 20.104.96.117:46568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/patie.php"] [unique_id "al9Y7zzTqJoBC2Mw28-1JQAAAIU"]
[Tue Jul 21 08:33:03.575378 2026] [security2:error] [pid 465652:tid 465841] [client 20.197.195.24:6573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/memberfuns.php"] [unique_id "al9Y7zzTqJoBC2Mw28-1JwAAAMA"]
[Tue Jul 21 08:33:03.593872 2026] [security2:error] [pid 466512:tid 466580] [remote 104.207.50.251:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "alphafix.com.br"] [uri "/wp-login.php"] [unique_id "al9Y7yKGokixMSfKDOfXbAACVEM"], referer: https://alphafix.com.br//wp-login.php
[Tue Jul 21 08:33:03.594045 2026] [security2:error] [pid 466512:tid 466706] [client 104.207.50.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "alphafix.com.br"] [uri "/wp-login.php"] [unique_id "al9Y7yKGokixMSfKDOfXbAACVEM"], referer: https://alphafix.com.br//wp-login.php
[Tue Jul 21 08:33:03.757906 2026] [security2:error] [pid 466512:tid 466620] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/j260624_13.php"] [unique_id "al9Y7yKGokixMSfKDOfXdAACh2s"]
[Tue Jul 21 08:33:03.768361 2026] [security2:error] [pid 466512:tid 466741] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9Y7yKGokixMSfKDOfXdgAAAnc"]
[Tue Jul 21 08:33:03.768389 2026] [security2:error] [pid 466512:tid 466700] [client 4.194.24.143:8232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/0.php"] [unique_id "al9Y7yKGokixMSfKDOfXdQAAAk4"]
[Tue Jul 21 08:33:03.773656 2026] [security2:error] [pid 466512:tid 466640] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/d62.php"] [unique_id "al9Y7yKGokixMSfKDOfXdwACf38"]
[Tue Jul 21 08:33:03.788755 2026] [security2:error] [pid 466512:tid 466560] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/ups.php"] [unique_id "al9Y7yKGokixMSfKDOfXeQACLi8"]
[Tue Jul 21 08:33:03.791469 2026] [security2:error] [pid 466512:tid 466723] [client 20.104.96.117:46509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/aa.php"] [unique_id "al9Y7yKGokixMSfKDOfXegAAAmU"]
[Tue Jul 21 08:33:03.803075 2026] [security2:error] [pid 466512:tid 466601] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/k.php"] [unique_id "al9Y7yKGokixMSfKDOfXewACPFg"]
[Tue Jul 21 08:33:03.896716 2026] [security2:error] [pid 465652:tid 465903] [client 20.197.195.24:17033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/0.php"] [unique_id "al9Y7zzTqJoBC2Mw28-1LAAAAP4"]
[Tue Jul 21 08:33:04.041966 2026] [security2:error] [pid 466512:tid 466674] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9Y8CKGokixMSfKDOfXgQAAAjQ"]
[Tue Jul 21 08:33:04.102168 2026] [security2:error] [pid 466512:tid 466747] [client 20.104.96.117:62608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/xwpg.php"] [unique_id "al9Y8CKGokixMSfKDOfXggAAAn0"]
[Tue Jul 21 08:33:04.349439 2026] [security2:error] [pid 466512:tid 466592] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/k2.php"] [unique_id "al9Y8CKGokixMSfKDOfXhAACGE8"]
[Tue Jul 21 08:33:04.351480 2026] [security2:error] [pid 466512:tid 466713] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/ss.php"] [unique_id "al9Y8CKGokixMSfKDOfXhQAAAls"]
[Tue Jul 21 08:33:04.387570 2026] [security2:error] [pid 466512:tid 466549] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/k3.php"] [unique_id "al9Y8CKGokixMSfKDOfXhgACeSQ"]
[Tue Jul 21 08:33:04.633508 2026] [security2:error] [pid 465652:tid 465865] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/min.php"] [unique_id "al9Y8DzTqJoBC2Mw28-1OAAAANg"]
[Tue Jul 21 08:33:04.721900 2026] [security2:error] [pid 465652:tid 465829] [client 20.104.96.117:62630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/ops.php"] [unique_id "al9Y8DzTqJoBC2Mw28-1OQAAALQ"]
[Tue Jul 21 08:33:04.809269 2026] [security2:error] [pid 465652:tid 465850] [client 4.194.24.143:8211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/000.php"] [unique_id "al9Y8DzTqJoBC2Mw28-1OwAAAMk"]
[Tue Jul 21 08:33:04.817802 2026] [security2:error] [pid 466512:tid 466562] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/k4.php"] [unique_id "al9Y8CKGokixMSfKDOfXkAACIzE"]
[Tue Jul 21 08:33:04.861886 2026] [security2:error] [pid 466512:tid 466596] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/k5.php"] [unique_id "al9Y8CKGokixMSfKDOfXkgACTFM"]
[Tue Jul 21 08:33:04.904213 2026] [security2:error] [pid 466512:tid 466526] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/w.php"] [unique_id "al9Y8CKGokixMSfKDOfXkwACWQ0"]
[Tue Jul 21 08:33:04.952643 2026] [security2:error] [pid 465652:tid 465860] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9Y8DzTqJoBC2Mw28-1QgAAANM"]
[Tue Jul 21 08:33:04.958255 2026] [security2:error] [pid 466512:tid 466699] [client 195.49.128.211:57825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Y8CKGokixMSfKDOfXlgAAAk0"]
[Tue Jul 21 08:33:04.958414 2026] [security2:error] [pid 466512:tid 466699] [client 195.49.128.211:57825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Y8CKGokixMSfKDOfXlgAAAk0"]
[Tue Jul 21 08:33:05.096600 2026] [security2:error] [pid 466512:tid 466645] [client 20.104.96.117:62626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/mac.php"] [unique_id "al9Y8SKGokixMSfKDOfXmQAAAhc"]
[Tue Jul 21 08:33:05.233603 2026] [security2:error] [pid 465652:tid 465894] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9Y8TzTqJoBC2Mw28-1SQAAAPU"]
[Tue Jul 21 08:33:05.267945 2026] [security2:error] [pid 466512:tid 466602] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/fpwch.php"] [unique_id "al9Y8SKGokixMSfKDOfXmgACPlk"]
[Tue Jul 21 08:33:05.516243 2026] [security2:error] [pid 465652:tid 465851] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9Y8TzTqJoBC2Mw28-1TwAAAMo"]
[Tue Jul 21 08:33:05.654496 2026] [security2:error] [pid 466512:tid 466757] [client 20.104.96.117:46499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/mg.php"] [unique_id "al9Y8SKGokixMSfKDOfXpQAAAoc"]
[Tue Jul 21 08:33:05.687761 2026] [security2:error] [pid 465652:tid 465907] [client 150.129.202.39:13062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.202.129.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y8TzTqJoBC2Mw28-1UgAAAQI"]
[Tue Jul 21 08:33:05.687903 2026] [security2:error] [pid 465652:tid 465907] [client 150.129.202.39:13062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drapatriciavarella.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y8TzTqJoBC2Mw28-1UgAAAQI"]
[Tue Jul 21 08:33:05.701687 2026] [security2:error] [pid 465652:tid 465838] [client 20.197.192.193:46200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9Y8TzTqJoBC2Mw28-1UwAAAL0"]
[Tue Jul 21 08:33:05.825975 2026] [security2:error] [pid 466512:tid 466749] [client 74.249.245.134:55990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Y8SKGokixMSfKDOfXrgAAAn8"]
[Tue Jul 21 08:33:05.871000 2026] [security2:error] [pid 465652:tid 465837] [client 4.194.24.143:5820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/002.php"] [unique_id "al9Y8TzTqJoBC2Mw28-1VQAAALw"]
[Tue Jul 21 08:33:05.914643 2026] [security2:error] [pid 465652:tid 465800] [client 20.206.105.145:25571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Y8TzTqJoBC2Mw28-1VwAAAJc"]
[Tue Jul 21 08:33:05.957460 2026] [security2:error] [pid 466512:tid 466680] [client 185.213.175.37:61968] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bcsenepol.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y8SKGokixMSfKDOfXqAAAAjo"]
[Tue Jul 21 08:33:06.146670 2026] [security2:error] [pid 466512:tid 466647] [client 20.197.195.24:57911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/BDKR28.php"] [unique_id "al9Y8iKGokixMSfKDOfXsQAAAhk"]
[Tue Jul 21 08:33:06.259392 2026] [security2:error] [pid 466512:tid 466705] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9Y8iKGokixMSfKDOfXswAAAlM"]
[Tue Jul 21 08:33:06.338535 2026] [security2:error] [pid 466512:tid 466724] [client 20.104.96.117:46518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-post-data.php"] [unique_id "al9Y8iKGokixMSfKDOfXtQAAAmY"]
[Tue Jul 21 08:33:06.386101 2026] [security2:error] [pid 465652:tid 465879] [client 223.181.60.88:13504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Y8jzTqJoBC2Mw28-1YAAAAOY"]
[Tue Jul 21 08:33:06.387399 2026] [security2:error] [pid 465652:tid 465879] [client 223.181.60.88:13504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Y8jzTqJoBC2Mw28-1YAAAAOY"]
[Tue Jul 21 08:33:06.420912 2026] [security2:error] [pid 466512:tid 466673] [client 61.1.167.83:57486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y8iKGokixMSfKDOfXtwAAAjM"]
[Tue Jul 21 08:33:06.421005 2026] [security2:error] [pid 466512:tid 466673] [client 61.1.167.83:57486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y8iKGokixMSfKDOfXtwAAAjM"]
[Tue Jul 21 08:33:06.467649 2026] [security2:error] [pid 466512:tid 466694] [client 20.197.195.24:53520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/coffexium.php"] [unique_id "al9Y8iKGokixMSfKDOfXuQAAAkg"]
[Tue Jul 21 08:33:06.541941 2026] [security2:error] [pid 466512:tid 466762] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/albin.php"] [unique_id "al9Y8iKGokixMSfKDOfXvAAAAow"]
[Tue Jul 21 08:33:06.722701 2026] [security2:error] [pid 466512:tid 466579] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/w2025.php"] [unique_id "al9Y8iKGokixMSfKDOfXvwACeUI"]
[Tue Jul 21 08:33:06.746610 2026] [security2:error] [pid 466512:tid 466573] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/scxy.php"] [unique_id "al9Y8iKGokixMSfKDOfXwAACejw"]
[Tue Jul 21 08:33:06.754238 2026] [security2:error] [pid 466512:tid 466764] [client 74.7.230.39:54542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "governess.com.br"] [uri "/index.php"] [unique_id "al9Y8iKGokixMSfKDOfXvgACjkY"]
[Tue Jul 21 08:33:06.762428 2026] [security2:error] [pid 466512:tid 466536] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/FWAZ.php"] [unique_id "al9Y8iKGokixMSfKDOfXwQACNRc"]
[Tue Jul 21 08:33:06.805244 2026] [security2:error] [pid 466512:tid 466624] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/qterm.php"] [unique_id "al9Y8iKGokixMSfKDOfXwwACNm8"]
[Tue Jul 21 08:33:06.822514 2026] [security2:error] [pid 466512:tid 466715] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/cilus.php"] [unique_id "al9Y8iKGokixMSfKDOfXxAAAAl0"]
[Tue Jul 21 08:33:06.873211 2026] [security2:error] [pid 466512:tid 466633] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/blurbs.php"] [unique_id "al9Y8iKGokixMSfKDOfXxwACXng"]
[Tue Jul 21 08:33:06.882536 2026] [security2:error] [pid 466512:tid 466698] [client 20.197.195.24:6302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/core.php"] [unique_id "al9Y8iKGokixMSfKDOfXyAAAAkw"]
[Tue Jul 21 08:33:06.895967 2026] [security2:error] [pid 465652:tid 465903] [client 4.194.24.143:5821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/0x.php"] [unique_id "al9Y8jzTqJoBC2Mw28-1ZwAAAP4"]
[Tue Jul 21 08:33:06.976713 2026] [security2:error] [pid 466512:tid 466541] [remote 119.195.102.159:45160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Y8iKGokixMSfKDOfXywACYBw"]
[Tue Jul 21 08:33:07.003121 2026] [security2:error] [pid 465652:tid 465842] [client 117.213.202.34:64064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y8jzTqJoBC2Mw28-1aQAAAME"]
[Tue Jul 21 08:33:07.003248 2026] [security2:error] [pid 465652:tid 465842] [client 117.213.202.34:64064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y8jzTqJoBC2Mw28-1aQAAAME"]
[Tue Jul 21 08:33:07.009347 2026] [security2:error] [pid 466512:tid 466649] [client 20.197.195.24:6336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/als.php"] [unique_id "al9Y8yKGokixMSfKDOfXzAAAAhs"]
[Tue Jul 21 08:33:07.045651 2026] [security2:error] [pid 466512:tid 466727] [client 74.249.245.134:55526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/ini.php"] [unique_id "al9Y8yKGokixMSfKDOfXzQAAAmk"]
[Tue Jul 21 08:33:07.095933 2026] [security2:error] [pid 466512:tid 466684] [client 20.197.195.24:6283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/simple.php"] [unique_id "al9Y8yKGokixMSfKDOfXzwAAAj4"]
[Tue Jul 21 08:33:07.122799 2026] [security2:error] [pid 466512:tid 466648] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/gptsh.php"] [unique_id "al9Y8yKGokixMSfKDOfX0QAAAho"]
[Tue Jul 21 08:33:07.237020 2026] [security2:error] [pid 466512:tid 466626] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/v543.php"] [unique_id "al9Y8yKGokixMSfKDOfX0wACkXE"]
[Tue Jul 21 08:33:07.324790 2026] [security2:error] [pid 466512:tid 466666] [client 20.197.195.24:3964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/init.php"] [unique_id "al9Y8yKGokixMSfKDOfX1AAAAiw"]
[Tue Jul 21 08:33:07.339756 2026] [security2:error] [pid 465652:tid 465901] [client 20.104.96.117:46553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/pucci.php"] [unique_id "al9Y8zzTqJoBC2Mw28-1bwAAAPw"]
[Tue Jul 21 08:33:07.398200 2026] [security2:error] [pid 465652:tid 465829] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/rithin.php"] [unique_id "al9Y8zzTqJoBC2Mw28-1cAAAALQ"]
[Tue Jul 21 08:33:07.426343 2026] [security2:error] [pid 466512:tid 466630] [remote 103.161.172.221:42846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Y8yKGokixMSfKDOfX1wACI3U"]
[Tue Jul 21 08:33:07.671998 2026] [security2:error] [pid 466512:tid 466680] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/fffm.php"] [unique_id "al9Y8yKGokixMSfKDOfX3AAAAjo"]
[Tue Jul 21 08:33:07.719795 2026] [security2:error] [pid 466512:tid 466604] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/w3lls.php"] [unique_id "al9Y8yKGokixMSfKDOfX3QACYVs"]
[Tue Jul 21 08:33:07.780031 2026] [security2:error] [pid 465652:tid 465834] [client 122.176.100.127:55003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Y8zzTqJoBC2Mw28-1dAAAALk"]
[Tue Jul 21 08:33:07.780143 2026] [security2:error] [pid 465652:tid 465834] [client 122.176.100.127:55003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Y8zzTqJoBC2Mw28-1dAAAALk"]
[Tue Jul 21 08:33:07.780668 2026] [security2:error] [pid 466512:tid 466701] [client 111.93.58.162:54719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y8yKGokixMSfKDOfX3gAAAk8"]
[Tue Jul 21 08:33:07.780748 2026] [security2:error] [pid 466512:tid 466701] [client 111.93.58.162:54719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y8yKGokixMSfKDOfX3gAAAk8"]
[Tue Jul 21 08:33:07.820233 2026] [security2:error] [pid 466512:tid 466731] [client 152.59.181.104:46144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Y8yKGokixMSfKDOfX4gAAAm0"]
[Tue Jul 21 08:33:07.820321 2026] [security2:error] [pid 466512:tid 466731] [client 152.59.181.104:46144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Y8yKGokixMSfKDOfX4gAAAm0"]
[Tue Jul 21 08:33:07.855519 2026] [security2:error] [pid 465652:tid 465889] [client 74.249.245.134:47315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/wp.php"] [unique_id "al9Y8zzTqJoBC2Mw28-1dwAAAPA"]
[Tue Jul 21 08:33:07.895553 2026] [security2:error] [pid 466512:tid 466724] [client 20.104.96.117:62672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/black.php"] [unique_id "al9Y8yKGokixMSfKDOfX4wAAAmY"]
[Tue Jul 21 08:33:07.922547 2026] [security2:error] [pid 466512:tid 466700] [client 4.194.24.143:8250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/0xd.php"] [unique_id "al9Y8yKGokixMSfKDOfX5AAAAk4"]
[Tue Jul 21 08:33:08.058015 2026] [proxy:error] [pid 465652:tid 465862] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:33:08.058083 2026] [proxy_http:error] [pid 465652:tid 465862] [client 185.247.137.195:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:33:08.058630 2026] [proxy:error] [pid 465652:tid 465862] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:33:08.058654 2026] [proxy_http:error] [pid 465652:tid 465862] [client 185.247.137.195:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:33:08.163135 2026] [security2:error] [pid 466512:tid 466646] [client 20.197.192.193:43806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/user.php"] [unique_id "al9Y9CKGokixMSfKDOfX6gAAAhg"]
[Tue Jul 21 08:33:08.370926 2026] [security2:error] [pid 465652:tid 465809] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/dfre.php"] [unique_id "al9Y9DzTqJoBC2Mw28-1hAAAAKA"]
[Tue Jul 21 08:33:08.400699 2026] [security2:error] [pid 466512:tid 466661] [client 20.104.96.117:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/zlece.php"] [unique_id "al9Y9CKGokixMSfKDOfX7wAAAic"]
[Tue Jul 21 08:33:08.546393 2026] [security2:error] [pid 466512:tid 466660] [client 20.197.195.24:16004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/fpwch.php"] [unique_id "al9Y9CKGokixMSfKDOfX9QAAAiY"]
[Tue Jul 21 08:33:08.565680 2026] [security2:error] [pid 466512:tid 466557] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-ws68.php"] [unique_id "al9Y9CKGokixMSfKDOfX9gACPiw"]
[Tue Jul 21 08:33:08.642278 2026] [security2:error] [pid 466512:tid 466636] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/xyn.php"] [unique_id "al9Y9CKGokixMSfKDOfX_QACF3s"]
[Tue Jul 21 08:33:08.723063 2026] [security2:error] [pid 466512:tid 466767] [client 20.104.96.117:62635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/vssrs.php"] [unique_id "al9Y9CKGokixMSfKDOfX_gAAApE"]
[Tue Jul 21 08:33:08.773516 2026] [security2:error] [pid 466512:tid 466606] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/green3.php"] [unique_id "al9Y9CKGokixMSfKDOfYAAACLF0"]
[Tue Jul 21 08:33:08.906416 2026] [security2:error] [pid 466512:tid 466565] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/ccs.php"] [unique_id "al9Y9CKGokixMSfKDOfYAQACLTQ"]
[Tue Jul 21 08:33:08.922578 2026] [security2:error] [pid 466512:tid 466542] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/ccc.php"] [unique_id "al9Y9CKGokixMSfKDOfYAgACSh0"]
[Tue Jul 21 08:33:08.938029 2026] [security2:error] [pid 466512:tid 466564] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/get.php"] [unique_id "al9Y9CKGokixMSfKDOfYAwACHzM"]
[Tue Jul 21 08:33:08.947306 2026] [security2:error] [pid 465652:tid 465838] [client 4.194.24.143:15639] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "wbapoiocontabil.com.br"] [uri "/1.php"] [unique_id "al9Y9DzTqJoBC2Mw28-1iwAAAL0"]
[Tue Jul 21 08:33:08.947383 2026] [security2:error] [pid 465652:tid 465838] [client 4.194.24.143:15639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/1.php"] [unique_id "al9Y9DzTqJoBC2Mw28-1iwAAAL0"]
[Tue Jul 21 08:33:08.950759 2026] [security2:error] [pid 465652:tid 465821] [client 49.144.66.253:29748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Y9DzTqJoBC2Mw28-1jAAAAKw"]
[Tue Jul 21 08:33:08.950842 2026] [security2:error] [pid 465652:tid 465821] [client 49.144.66.253:29748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Y9DzTqJoBC2Mw28-1jAAAAKw"]
[Tue Jul 21 08:33:08.963052 2026] [security2:error] [pid 466512:tid 466582] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/images.php"] [unique_id "al9Y9CKGokixMSfKDOfYBAAChUU"]
[Tue Jul 21 08:33:08.998623 2026] [security2:error] [pid 466512:tid 466535] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/alls.php"] [unique_id "al9Y9CKGokixMSfKDOfYBQACLhY"]
[Tue Jul 21 08:33:09.017586 2026] [security2:error] [pid 466512:tid 466572] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/yyu.php"] [unique_id "al9Y9SKGokixMSfKDOfYBgACfzs"]
[Tue Jul 21 08:33:09.022942 2026] [security2:error] [pid 466512:tid 466750] [client 20.104.96.117:62610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wicked.php"] [unique_id "al9Y9SKGokixMSfKDOfYBwAAAoA"]
[Tue Jul 21 08:33:09.034410 2026] [security2:error] [pid 466512:tid 466609] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/by.php"] [unique_id "al9Y9SKGokixMSfKDOfYCAACdmA"]
[Tue Jul 21 08:33:09.145442 2026] [security2:error] [pid 466512:tid 466679] [client 20.220.225.223:50246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Y9SKGokixMSfKDOfYDwAAAjk"]
[Tue Jul 21 08:33:09.279865 2026] [security2:error] [pid 466512:tid 466704] [client 195.49.128.211:49946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y9SKGokixMSfKDOfYEQAAAlI"]
[Tue Jul 21 08:33:09.280043 2026] [security2:error] [pid 466512:tid 466704] [client 195.49.128.211:49946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y9SKGokixMSfKDOfYEQAAAlI"]
[Tue Jul 21 08:33:09.312945 2026] [security2:error] [pid 465652:tid 465798] [client 20.206.105.145:25519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/f6.php"] [unique_id "al9Y9TzTqJoBC2Mw28-1kgAAAJU"]
[Tue Jul 21 08:33:09.365562 2026] [security2:error] [pid 466512:tid 466574] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/FAQ.php"] [unique_id "al9Y9SKGokixMSfKDOfYFAACKT0"]
[Tue Jul 21 08:33:09.386336 2026] [security2:error] [pid 465652:tid 465815] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/wp-happy.php"] [unique_id "al9Y9TzTqJoBC2Mw28-1lAAAAKY"]
[Tue Jul 21 08:33:09.454937 2026] [security2:error] [pid 466512:tid 466652] [client 20.104.96.117:46559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/24.php"] [unique_id "al9Y9SKGokixMSfKDOfYGAAAAh4"]
[Tue Jul 21 08:33:09.607887 2026] [security2:error] [pid 466512:tid 466711] [client 20.197.195.24:6398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/domvf.php"] [unique_id "al9Y9SKGokixMSfKDOfYHAAAAlk"]
[Tue Jul 21 08:33:09.619604 2026] [security2:error] [pid 466512:tid 466554] [remote 84.247.172.23:37404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-login.php"] [unique_id "al9Y9SKGokixMSfKDOfYHQACUSk"]
[Tue Jul 21 08:33:09.678201 2026] [security2:error] [pid 465652:tid 465875] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/fpr4.php"] [unique_id "al9Y9TzTqJoBC2Mw28-1nAAAAOI"]
[Tue Jul 21 08:33:09.713616 2026] [security2:error] [pid 465652:tid 465864] [client 20.197.192.193:5568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wp-css.php"] [unique_id "al9Y9TzTqJoBC2Mw28-1ngAAANc"]
[Tue Jul 21 08:33:09.726946 2026] [security2:error] [pid 465652:tid 465899] [client 20.197.192.193:48320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/ops.php"] [unique_id "al9Y9TzTqJoBC2Mw28-1nwAAAPo"]
[Tue Jul 21 08:33:09.754332 2026] [security2:error] [pid 466512:tid 466718] [client 20.197.195.24:57958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/green1.php"] [unique_id "al9Y9SKGokixMSfKDOfYIQAAAmA"]
[Tue Jul 21 08:33:09.945397 2026] [security2:error] [pid 465652:tid 465893] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/file88.php"] [unique_id "al9Y9TzTqJoBC2Mw28-1pQAAAPQ"]
[Tue Jul 21 08:33:09.999723 2026] [security2:error] [pid 466512:tid 466697] [client 4.194.24.143:8462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/100.php"] [unique_id "al9Y9SKGokixMSfKDOfYJQAAAks"]
[Tue Jul 21 08:33:10.102929 2026] [security2:error] [pid 466512:tid 466587] [remote 87.106.67.224:33826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.67.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Y9SKGokixMSfKDOfYDQACI0o"]
[Tue Jul 21 08:33:10.107686 2026] [security2:error] [pid 465652:tid 465850] [client 20.104.96.117:62700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/xacs.php"] [unique_id "al9Y9jzTqJoBC2Mw28-1rgAAAMk"]
[Tue Jul 21 08:33:10.175097 2026] [security2:error] [pid 466512:tid 466744] [client 5.38.115.39:64648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Y9iKGokixMSfKDOfYJwAAAno"]
[Tue Jul 21 08:33:10.175217 2026] [security2:error] [pid 466512:tid 466744] [client 5.38.115.39:64648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Y9iKGokixMSfKDOfYJwAAAno"]
[Tue Jul 21 08:33:10.212818 2026] [security2:error] [pid 466512:tid 466690] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/ccc.php"] [unique_id "al9Y9iKGokixMSfKDOfYKgAAAkQ"]
[Tue Jul 21 08:33:10.216737 2026] [security2:error] [pid 466512:tid 466575] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/coffexium.php"] [unique_id "al9Y9iKGokixMSfKDOfYKwACgz4"]
[Tue Jul 21 08:33:10.232318 2026] [security2:error] [pid 466512:tid 466617] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/red.php"] [unique_id "al9Y9iKGokixMSfKDOfYLAACkmg"]
[Tue Jul 21 08:33:10.239885 2026] [security2:error] [pid 466512:tid 466767] [client 74.249.245.134:55967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/new.php"] [unique_id "al9Y9iKGokixMSfKDOfYLQAAApE"]
[Tue Jul 21 08:33:10.318110 2026] [security2:error] [pid 466512:tid 466612] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9Y9iKGokixMSfKDOfYMAACV2M"]
[Tue Jul 21 08:33:10.420633 2026] [security2:error] [pid 465652:tid 465889] [client 20.197.192.193:43797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/term.php"] [unique_id "al9Y9jzTqJoBC2Mw28-1tQAAAPA"]
[Tue Jul 21 08:33:10.449857 2026] [security2:error] [pid 465652:tid 465835] [client 20.104.96.117:64221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/zildan.php"] [unique_id "al9Y9jzTqJoBC2Mw28-1tgAAALo"]
[Tue Jul 21 08:33:10.506964 2026] [security2:error] [pid 465652:tid 465862] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/777.php"] [unique_id "al9Y9jzTqJoBC2Mw28-1uQAAANU"]
[Tue Jul 21 08:33:10.786262 2026] [security2:error] [pid 466512:tid 466704] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/for.php"] [unique_id "al9Y9iKGokixMSfKDOfYNwAAAlI"]
[Tue Jul 21 08:33:10.803119 2026] [security2:error] [pid 466512:tid 466589] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/footer.php"] [unique_id "al9Y9iKGokixMSfKDOfYOAACNEw"]
[Tue Jul 21 08:33:10.909093 2026] [security2:error] [pid 465652:tid 465854] [client 14.245.224.124:57906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Y9jzTqJoBC2Mw28-1wgAAAM0"]
[Tue Jul 21 08:33:10.909191 2026] [security2:error] [pid 465652:tid 465854] [client 14.245.224.124:57906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Y9jzTqJoBC2Mw28-1wgAAAM0"]
[Tue Jul 21 08:33:10.910412 2026] [security2:error] [pid 466512:tid 466663] [client 187.125.243.197:51113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Y9iKGokixMSfKDOfYPQAAAik"]
[Tue Jul 21 08:33:10.910534 2026] [security2:error] [pid 466512:tid 466663] [client 187.125.243.197:51113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Y9iKGokixMSfKDOfYPQAAAik"]
[Tue Jul 21 08:33:10.947853 2026] [security2:error] [pid 465652:tid 465823] [client 20.197.192.193:5621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/wp-explorer.php"] [unique_id "al9Y9jzTqJoBC2Mw28-1xAAAAK4"]
[Tue Jul 21 08:33:10.988935 2026] [security2:error] [pid 466512:tid 466664] [client 20.104.96.117:64226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/csa.php"] [unique_id "al9Y9iKGokixMSfKDOfYPgAAAio"]
[Tue Jul 21 08:33:11.027603 2026] [security2:error] [pid 466512:tid 466756] [client 4.194.24.143:8199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/12.php"] [unique_id "al9Y9yKGokixMSfKDOfYPwAAAoY"]
[Tue Jul 21 08:33:11.052866 2026] [security2:error] [pid 466512:tid 466673] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/ssla.php"] [unique_id "al9Y9yKGokixMSfKDOfYQQAAAjM"]
[Tue Jul 21 08:33:11.171573 2026] [security2:error] [pid 465652:tid 465672] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Y9zzTqJoBC2Mw28-1ygAA1BM"]
[Tue Jul 21 08:33:11.171704 2026] [security2:error] [pid 465652:tid 465861] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Y9zzTqJoBC2Mw28-1ygAA1BM"]
[Tue Jul 21 08:33:11.188940 2026] [security2:error] [pid 466512:tid 466741] [client 20.197.195.24:6564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/nc4.php"] [unique_id "al9Y9yKGokixMSfKDOfYRwAAAnc"]
[Tue Jul 21 08:33:11.347005 2026] [security2:error] [pid 465652:tid 465871] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sefacil.com.br"] [uri "/zc-131.php"] [unique_id "al9Y9zzTqJoBC2Mw28-1ywAAAN4"]
[Tue Jul 21 08:33:11.422594 2026] [security2:error] [pid 466512:tid 466661] [client 20.206.105.145:25554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/inputs.php"] [unique_id "al9Y9yKGokixMSfKDOfYTQAAAic"]
[Tue Jul 21 08:33:11.471380 2026] [security2:error] [pid 466512:tid 466540] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-content/index.php"] [unique_id "al9Y9yKGokixMSfKDOfYTgACWRs"]
[Tue Jul 21 08:33:11.528305 2026] [security2:error] [pid 466512:tid 466514] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/zoro.php"] [unique_id "al9Y9yKGokixMSfKDOfYTwACUQE"]
[Tue Jul 21 08:33:11.530457 2026] [security2:error] [pid 466512:tid 466699] [client 74.249.245.134:20823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/class-t.api.php"] [unique_id "al9Y9yKGokixMSfKDOfYUAAAAk0"]
[Tue Jul 21 08:33:11.655277 2026] [security2:error] [pid 466512:tid 466763] [client 20.197.192.193:5973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/akismet.php"] [unique_id "al9Y9yKGokixMSfKDOfYUQAAAo0"]
[Tue Jul 21 08:33:11.676159 2026] [security2:error] [pid 466512:tid 466716] [client 74.249.245.134:54929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/themes.php"] [unique_id "al9Y9yKGokixMSfKDOfYUgAAAl4"]
[Tue Jul 21 08:33:11.715462 2026] [security2:error] [pid 466512:tid 466742] [client 103.151.46.103:63223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Y9yKGokixMSfKDOfYUwAAAng"]
[Tue Jul 21 08:33:11.715614 2026] [security2:error] [pid 466512:tid 466742] [client 103.151.46.103:63223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Y9yKGokixMSfKDOfYUwAAAng"]
[Tue Jul 21 08:33:11.901598 2026] [security2:error] [pid 466512:tid 466590] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/admin.php"] [unique_id "al9Y9yKGokixMSfKDOfYWQACF00"]
[Tue Jul 21 08:33:11.969524 2026] [security2:error] [pid 466512:tid 466739] [client 20.104.96.117:46585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/w3llscc.php"] [unique_id "al9Y9yKGokixMSfKDOfYWgAAAnU"]
[Tue Jul 21 08:33:11.979565 2026] [security2:error] [pid 466512:tid 466525] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/greap.php"] [unique_id "al9Y9yKGokixMSfKDOfYWwACWAw"]
[Tue Jul 21 08:33:12.041727 2026] [security2:error] [pid 466512:tid 466598] [remote 20.153.140.50:37750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Y-CKGokixMSfKDOfYXQACW1U"]
[Tue Jul 21 08:33:12.050768 2026] [security2:error] [pid 466512:tid 466586] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/177.php"] [unique_id "al9Y-CKGokixMSfKDOfYXgACiUk"]
[Tue Jul 21 08:33:12.060491 2026] [security2:error] [pid 466512:tid 466718] [client 4.194.24.143:8863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/123.php"] [unique_id "al9Y-CKGokixMSfKDOfYXwAAAmA"]
[Tue Jul 21 08:33:12.069071 2026] [security2:error] [pid 466512:tid 466584] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/199.php"] [unique_id "al9Y-CKGokixMSfKDOfYYAACLUc"]
[Tue Jul 21 08:33:12.118892 2026] [security2:error] [pid 466512:tid 466658] [client 20.197.195.24:3875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp.php"] [unique_id "al9Y-CKGokixMSfKDOfYYQAAAiQ"]
[Tue Jul 21 08:33:12.144129 2026] [security2:error] [pid 466512:tid 466666] [client 20.197.195.24:57882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/a1.php"] [unique_id "al9Y-CKGokixMSfKDOfYYgAAAiw"]
[Tue Jul 21 08:33:12.179404 2026] [security2:error] [pid 466512:tid 466580] [remote 207.180.241.245:54342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9Y-CKGokixMSfKDOfYYwAChUM"]
[Tue Jul 21 08:33:12.309965 2026] [security2:error] [pid 466512:tid 466585] [remote 154.61.75.100:47354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/wp-login.php"] [unique_id "al9Y9yKGokixMSfKDOfYSQACVEg"]
[Tue Jul 21 08:33:12.455297 2026] [security2:error] [pid 466512:tid 466516] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/file52.php"] [unique_id "al9Y-CKGokixMSfKDOfYaQACSAM"]
[Tue Jul 21 08:33:12.470849 2026] [security2:error] [pid 466512:tid 466547] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/122.php"] [unique_id "al9Y-CKGokixMSfKDOfYagACViI"]
[Tue Jul 21 08:33:12.487190 2026] [security2:error] [pid 466512:tid 466546] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/green1.php"] [unique_id "al9Y-CKGokixMSfKDOfYawACfCE"]
[Tue Jul 21 08:33:12.502719 2026] [security2:error] [pid 466512:tid 466620] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/biufile.php"] [unique_id "al9Y-CKGokixMSfKDOfYbQACKms"]
[Tue Jul 21 08:33:12.519060 2026] [security2:error] [pid 466512:tid 466640] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wpconf.php"] [unique_id "al9Y-CKGokixMSfKDOfYbgACJX8"]
[Tue Jul 21 08:33:12.534415 2026] [security2:error] [pid 466512:tid 466560] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/mosty.php"] [unique_id "al9Y-CKGokixMSfKDOfYbwACMy8"]
[Tue Jul 21 08:33:12.548627 2026] [security2:error] [pid 466512:tid 466601] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/dejavu.php"] [unique_id "al9Y-CKGokixMSfKDOfYcAACGFg"]
[Tue Jul 21 08:33:12.563715 2026] [security2:error] [pid 466512:tid 466595] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/aaf.php"] [unique_id "al9Y-CKGokixMSfKDOfYcQACIFI"]
[Tue Jul 21 08:33:12.575017 2026] [security2:error] [pid 465652:tid 465673] [remote 45.79.123.44:46732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/wp-login.php"] [unique_id "al9Y-DzTqJoBC2Mw28-12gAAnxQ"]
[Tue Jul 21 08:33:12.581862 2026] [security2:error] [pid 466512:tid 466592] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/term.php"] [unique_id "al9Y-CKGokixMSfKDOfYcgACjE8"]
[Tue Jul 21 08:33:13.000902 2026] [security2:error] [pid 465652:tid 465794] [client 74.249.245.134:55488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/dropdown.php"] [unique_id "al9Y-TzTqJoBC2Mw28-14AAAAJE"]
[Tue Jul 21 08:33:13.004330 2026] [security2:error] [pid 465652:tid 465893] [client 20.197.195.24:57907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/eee.php"] [unique_id "al9Y-TzTqJoBC2Mw28-14QAAAPQ"]
[Tue Jul 21 08:33:13.022644 2026] [security2:error] [pid 466512:tid 466677] [client 20.197.192.193:65205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/yup.php"] [unique_id "al9Y-SKGokixMSfKDOfYdQAAAjc"]
[Tue Jul 21 08:33:13.081610 2026] [security2:error] [pid 466512:tid 466741] [client 202.179.75.202:42614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Y-SKGokixMSfKDOfYdgAAAnc"]
[Tue Jul 21 08:33:13.081717 2026] [security2:error] [pid 466512:tid 466741] [client 202.179.75.202:42614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Y-SKGokixMSfKDOfYdgAAAnc"]
[Tue Jul 21 08:33:13.121313 2026] [security2:error] [pid 466512:tid 466764] [client 4.194.24.143:17041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/13.php"] [unique_id "al9Y-SKGokixMSfKDOfYdwAAAo4"]
[Tue Jul 21 08:33:13.348561 2026] [security2:error] [pid 465652:tid 465806] [client 20.104.96.117:46546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wpx.php"] [unique_id "al9Y-TzTqJoBC2Mw28-16gAAAJ0"]
[Tue Jul 21 08:33:13.462822 2026] [security2:error] [pid 465652:tid 465791] [client 190.171.84.255:18212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "geracaosemtelinha.com.br"] [uri "/wp-login.php"] [unique_id "al9Y-TzTqJoBC2Mw28-17AAAjm8"], referer: https://geracaosemtelinha.com.br/wp-login.php?redirect_to=https%3A%2F%2Fgeracaosemtelinha.com.br%2Fwp-admin%2F&reauth=1
[Tue Jul 21 08:33:13.903572 2026] [security2:error] [pid 465652:tid 465826] [client 20.206.105.145:25490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/inputs.php"] [unique_id "al9Y-TzTqJoBC2Mw28-18wAAALE"]
[Tue Jul 21 08:33:14.167440 2026] [security2:error] [pid 465652:tid 465886] [client 4.194.24.143:8892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/133.php"] [unique_id "al9Y-jzTqJoBC2Mw28-19gAAAO0"]
[Tue Jul 21 08:33:14.230340 2026] [security2:error] [pid 466512:tid 466753] [client 20.104.96.117:62713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-css.php"] [unique_id "al9Y-iKGokixMSfKDOfYhAAAAoM"]
[Tue Jul 21 08:33:14.247768 2026] [security2:error] [pid 466512:tid 466669] [client 74.249.245.134:37701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/wp-links.php"] [unique_id "al9Y-iKGokixMSfKDOfYhQAAAi8"]
[Tue Jul 21 08:33:14.375480 2026] [security2:error] [pid 465652:tid 465852] [client 20.197.195.24:3944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/class.php"] [unique_id "al9Y-jzTqJoBC2Mw28-1-wAAAMs"]
[Tue Jul 21 08:33:14.381028 2026] [security2:error] [pid 465652:tid 465834] [client 20.197.192.193:6012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/ace2.php"] [unique_id "al9Y-jzTqJoBC2Mw28-1_AAAALk"]
[Tue Jul 21 08:33:14.398772 2026] [security2:error] [pid 466512:tid 466710] [client 20.206.105.145:25541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/av.php"] [unique_id "al9Y-iKGokixMSfKDOfYiAAAAlg"]
[Tue Jul 21 08:33:14.680954 2026] [security2:error] [pid 465652:tid 465871] [client 20.197.195.24:57883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/wp-aothait.php"] [unique_id "al9Y-jzTqJoBC2Mw28-2AgAAAN4"]
[Tue Jul 21 08:33:14.685530 2026] [access_compat:error] [pid 466512:tid 466750] [client 162.241.63.68:11140] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:33:14.769114 2026] [security2:error] [pid 466512:tid 466679] [client 20.104.96.117:62719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/ho.php"] [unique_id "al9Y-iKGokixMSfKDOfYjgAAAjk"]
[Tue Jul 21 08:33:14.944748 2026] [log_config:warn] [pid 418108:tid 418294] (32)Broken pipe: [client 177.124.23.255:57217] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:33:14.944763 2026] [log_config:warn] [pid 418108:tid 418294] (32)Broken pipe: [client 177.124.23.255:57217] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:33:15.060093 2026] [security2:error] [pid 466512:tid 466683] [client 20.197.192.193:5976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.guiferreira.com.br"] [uri "/ms.php"] [unique_id "al9Y-yKGokixMSfKDOfYmAAAAj0"]
[Tue Jul 21 08:33:15.212891 2026] [security2:error] [pid 466512:tid 466647] [client 4.194.24.143:16754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/155.php"] [unique_id "al9Y-yKGokixMSfKDOfYngAAAhk"]
[Tue Jul 21 08:33:15.611043 2026] [security2:error] [pid 466512:tid 466665] [client 20.104.96.117:62623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/xy.php"] [unique_id "al9Y-yKGokixMSfKDOfYpwAAAis"]
[Tue Jul 21 08:33:15.682664 2026] [security2:error] [pid 466512:tid 466735] [client 195.49.128.211:58442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Y-yKGokixMSfKDOfYqAAAAnE"]
[Tue Jul 21 08:33:15.682833 2026] [security2:error] [pid 466512:tid 466735] [client 195.49.128.211:58442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Y-yKGokixMSfKDOfYqAAAAnE"]
[Tue Jul 21 08:33:15.780572 2026] [security2:error] [pid 466512:tid 466687] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y-yKGokixMSfKDOfYrAAAAkE"]
[Tue Jul 21 08:33:15.975658 2026] [security2:error] [pid 466512:tid 466733] [client 74.249.245.134:55515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/xmrlpc.php"] [unique_id "al9Y-yKGokixMSfKDOfYuQAAAm8"]
[Tue Jul 21 08:33:16.090577 2026] [security2:error] [pid 465652:tid 465877] [client 20.104.96.117:46581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/loader.php"] [unique_id "al9Y_DzTqJoBC2Mw28-2GAAAAOQ"]
[Tue Jul 21 08:33:16.098508 2026] [security2:error] [pid 465652:tid 465875] [client 223.181.60.88:20262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Y_DzTqJoBC2Mw28-2GgAAAOI"]
[Tue Jul 21 08:33:16.098642 2026] [security2:error] [pid 465652:tid 465875] [client 223.181.60.88:20262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Y_DzTqJoBC2Mw28-2GgAAAOI"]
[Tue Jul 21 08:33:16.164199 2026] [security2:error] [pid 466512:tid 466672] [client 20.206.105.145:25107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Y_CKGokixMSfKDOfYvwAAAjI"]
[Tue Jul 21 08:33:16.189776 2026] [security2:error] [pid 465652:tid 465883] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Y_DzTqJoBC2Mw28-2HAAAAOo"]
[Tue Jul 21 08:33:16.264327 2026] [security2:error] [pid 466512:tid 466666] [client 4.194.24.143:8880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/166.php"] [unique_id "al9Y_CKGokixMSfKDOfYwQAAAiw"]
[Tue Jul 21 08:33:16.504363 2026] [security2:error] [pid 466512:tid 466694] [client 20.197.195.24:16020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/echkm.php"] [unique_id "al9Y_CKGokixMSfKDOfYxQAAAkg"]
[Tue Jul 21 08:33:16.590126 2026] [security2:error] [pid 465652:tid 465896] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Y_DzTqJoBC2Mw28-2HwAAAPc"]
[Tue Jul 21 08:33:16.720635 2026] [security2:error] [pid 465652:tid 465880] [client 20.104.96.117:62694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/spadex.php"] [unique_id "al9Y_DzTqJoBC2Mw28-2IQAAAOc"]
[Tue Jul 21 08:33:17.002193 2026] [security2:error] [pid 466512:tid 466762] [client 74.249.245.134:51416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/plugins.php"] [unique_id "al9Y_SKGokixMSfKDOfYywAAAow"]
[Tue Jul 21 08:33:17.011953 2026] [security2:error] [pid 466512:tid 466604] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/ha.php"] [unique_id "al9Y_SKGokixMSfKDOfYzAACgls"]
[Tue Jul 21 08:33:17.047650 2026] [security2:error] [pid 466512:tid 466692] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Y_SKGokixMSfKDOfYzgAAAkY"]
[Tue Jul 21 08:33:17.076948 2026] [security2:error] [pid 466512:tid 466538] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/hur.php"] [unique_id "al9Y_SKGokixMSfKDOfYzwACFBk"]
[Tue Jul 21 08:33:17.092531 2026] [security2:error] [pid 466512:tid 466594] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/h02ugyh.php"] [unique_id "al9Y_SKGokixMSfKDOfY0AACGVE"]
[Tue Jul 21 08:33:17.107188 2026] [security2:error] [pid 466512:tid 466523] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/seiso.php"] [unique_id "al9Y_SKGokixMSfKDOfY0gACfgo"]
[Tue Jul 21 08:33:17.162069 2026] [security2:error] [pid 466512:tid 466557] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/155.php"] [unique_id "al9Y_SKGokixMSfKDOfY1AACXyw"]
[Tue Jul 21 08:33:17.177160 2026] [security2:error] [pid 466512:tid 466576] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/ppp.php"] [unique_id "al9Y_SKGokixMSfKDOfY1QACij8"]
[Tue Jul 21 08:33:17.215739 2026] [security2:error] [pid 466512:tid 466637] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/201.php"] [unique_id "al9Y_SKGokixMSfKDOfY1wACKHw"]
[Tue Jul 21 08:33:17.231094 2026] [security2:error] [pid 466512:tid 466607] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/ops.php"] [unique_id "al9Y_SKGokixMSfKDOfY2AACJ14"]
[Tue Jul 21 08:33:17.246788 2026] [security2:error] [pid 466512:tid 466532] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/ingfo.php"] [unique_id "al9Y_SKGokixMSfKDOfY2QACTBM"]
[Tue Jul 21 08:33:17.279547 2026] [security2:error] [pid 466512:tid 466716] [client 20.197.195.24:6605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/config.json.php"] [unique_id "al9Y_SKGokixMSfKDOfY2gAAAl4"]
[Tue Jul 21 08:33:17.288979 2026] [security2:error] [pid 466512:tid 466636] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/error_log.php"] [unique_id "al9Y_SKGokixMSfKDOfY2wACeHs"]
[Tue Jul 21 08:33:17.293579 2026] [security2:error] [pid 466512:tid 466654] [client 4.194.24.143:16718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/2.php"] [unique_id "al9Y_SKGokixMSfKDOfY3AAAAiA"]
[Tue Jul 21 08:33:17.297675 2026] [security2:error] [pid 466512:tid 466711] [client 20.104.96.117:46506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/2x.php"] [unique_id "al9Y_SKGokixMSfKDOfY3QAAAlk"]
[Tue Jul 21 08:33:17.304783 2026] [security2:error] [pid 466512:tid 466606] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/xenon1337.php"] [unique_id "al9Y_SKGokixMSfKDOfY3gACJl0"]
[Tue Jul 21 08:33:17.367788 2026] [security2:error] [pid 466512:tid 466565] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/test11.php"] [unique_id "al9Y_SKGokixMSfKDOfY3wACPjQ"]
[Tue Jul 21 08:33:17.431577 2026] [security2:error] [pid 466512:tid 466564] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/koala.php"] [unique_id "al9Y_SKGokixMSfKDOfY4QACcTM"]
[Tue Jul 21 08:33:17.433114 2026] [security2:error] [pid 466512:tid 466735] [client 20.197.195.24:3943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/lib.php"] [unique_id "al9Y_SKGokixMSfKDOfY4gAAAnE"]
[Tue Jul 21 08:33:17.435502 2026] [security2:error] [pid 466512:tid 466655] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Y_SKGokixMSfKDOfY4wAAAiE"]
[Tue Jul 21 08:33:17.470494 2026] [security2:error] [pid 466512:tid 466582] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/mac.php"] [unique_id "al9Y_SKGokixMSfKDOfY5AACQUU"]
[Tue Jul 21 08:33:17.486284 2026] [security2:error] [pid 466512:tid 466535] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9Y_SKGokixMSfKDOfY5QACgxY"]
[Tue Jul 21 08:33:17.500776 2026] [security2:error] [pid 466512:tid 466572] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wefile.php"] [unique_id "al9Y_SKGokixMSfKDOfY5gACajs"]
[Tue Jul 21 08:33:17.556559 2026] [security2:error] [pid 465652:tid 465853] [client 20.197.192.193:43805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/ah25.php"] [unique_id "al9Y_TzTqJoBC2Mw28-2LQAAAMw"]
[Tue Jul 21 08:33:17.568397 2026] [security2:error] [pid 465652:tid 465828] [client 74.249.245.134:54914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/htaccess.php"] [unique_id "al9Y_TzTqJoBC2Mw28-2LgAAALM"]
[Tue Jul 21 08:33:17.684554 2026] [security2:error] [pid 466512:tid 466683] [client 117.213.202.34:64678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y_SKGokixMSfKDOfY7wAAAj0"]
[Tue Jul 21 08:33:17.684690 2026] [security2:error] [pid 466512:tid 466683] [client 117.213.202.34:64678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Y_SKGokixMSfKDOfY7wAAAj0"]
[Tue Jul 21 08:33:17.717822 2026] [security2:error] [pid 466512:tid 466621] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9Y_SKGokixMSfKDOfY8AACgGw"]
[Tue Jul 21 08:33:17.774025 2026] [security2:error] [pid 466512:tid 466537] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/2P.php"] [unique_id "al9Y_SKGokixMSfKDOfY8QACLhg"]
[Tue Jul 21 08:33:17.819880 2026] [security2:error] [pid 466512:tid 466622] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/.well-known/about.php"] [unique_id "al9Y_SKGokixMSfKDOfY8wACOW0"]
[Tue Jul 21 08:33:17.841490 2026] [security2:error] [pid 466512:tid 466712] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Y_SKGokixMSfKDOfY9AAAAlo"]
[Tue Jul 21 08:33:17.855401 2026] [security2:error] [pid 466512:tid 466554] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9Y_SKGokixMSfKDOfY9QACcCk"]
[Tue Jul 21 08:33:17.870946 2026] [security2:error] [pid 466512:tid 466513] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/bob.php"] [unique_id "al9Y_SKGokixMSfKDOfY9gACkAA"]
[Tue Jul 21 08:33:17.962753 2026] [security2:error] [pid 466512:tid 466666] [client 20.104.96.117:46590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/ctex1.php"] [unique_id "al9Y_SKGokixMSfKDOfY-gAAAiw"]
[Tue Jul 21 08:33:18.051644 2026] [security2:error] [pid 466512:tid 466600] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/crgio.php"] [unique_id "al9Y_iKGokixMSfKDOfY_gACSFc"]
[Tue Jul 21 08:33:18.097776 2026] [security2:error] [pid 466512:tid 466577] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/pucci.php"] [unique_id "al9Y_iKGokixMSfKDOfZAAACVkA"]
[Tue Jul 21 08:33:18.257184 2026] [security2:error] [pid 466512:tid 466733] [client 122.176.100.127:55515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Y_iKGokixMSfKDOfZCQAAAm8"]
[Tue Jul 21 08:33:18.257418 2026] [security2:error] [pid 466512:tid 466733] [client 122.176.100.127:55515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Y_iKGokixMSfKDOfZCQAAAm8"]
[Tue Jul 21 08:33:18.268339 2026] [security2:error] [pid 465652:tid 465906] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Y_jzTqJoBC2Mw28-2OAAAAQE"]
[Tue Jul 21 08:33:18.334980 2026] [security2:error] [pid 466512:tid 466741] [client 20.197.195.24:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9Y_iKGokixMSfKDOfZDgAAAnc"]
[Tue Jul 21 08:33:18.336731 2026] [security2:error] [pid 466512:tid 466589] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-temp.php"] [unique_id "al9Y_iKGokixMSfKDOfZDwACXEw"]
[Tue Jul 21 08:33:18.351842 2026] [security2:error] [pid 465652:tid 465851] [client 4.194.24.143:8492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/2026w.php"] [unique_id "al9Y_jzTqJoBC2Mw28-2OQAAAMo"]
[Tue Jul 21 08:33:18.372438 2026] [security2:error] [pid 465652:tid 465818] [client 125.18.144.2:6403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y_jzTqJoBC2Mw28-2OgAAAKk"]
[Tue Jul 21 08:33:18.372693 2026] [security2:error] [pid 465652:tid 465818] [client 125.18.144.2:6403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y_jzTqJoBC2Mw28-2OgAAAKk"]
[Tue Jul 21 08:33:18.422131 2026] [security2:error] [pid 466512:tid 466610] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9Y_iKGokixMSfKDOfZEgACUWE"]
[Tue Jul 21 08:33:18.422672 2026] [security2:error] [pid 466512:tid 466716] [client 20.220.225.223:50889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Y_iKGokixMSfKDOfZEwAAAl4"]
[Tue Jul 21 08:33:18.483014 2026] [security2:error] [pid 466512:tid 466627] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/puc.php"] [unique_id "al9Y_iKGokixMSfKDOfZFAACWXI"]
[Tue Jul 21 08:33:18.505718 2026] [security2:error] [pid 466512:tid 466567] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/themes.php"] [unique_id "al9Y_iKGokixMSfKDOfZFgACTjY"]
[Tue Jul 21 08:33:18.520567 2026] [security2:error] [pid 466512:tid 466550] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/dx.php"] [unique_id "al9Y_iKGokixMSfKDOfZFwACSyU"]
[Tue Jul 21 08:33:18.530124 2026] [security2:error] [pid 466512:tid 466657] [client 34.74.242.206:1571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.linkmaster.net.br"] [uri "/robots.txt"] [unique_id "al9Y_iKGokixMSfKDOfZGAAAAiM"]
[Tue Jul 21 08:33:18.530254 2026] [security2:error] [pid 466512:tid 466657] [client 34.74.242.206:1571] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.linkmaster.net.br"] [uri "/robots.txt"] [unique_id "al9Y_iKGokixMSfKDOfZGAAAAiM"]
[Tue Jul 21 08:33:18.535668 2026] [security2:error] [pid 466512:tid 466571] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/p.php"] [unique_id "al9Y_iKGokixMSfKDOfZGQACcTo"]
[Tue Jul 21 08:33:18.586567 2026] [security2:error] [pid 466512:tid 466709] [client 20.104.96.117:62599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/edorxrr.php"] [unique_id "al9Y_iKGokixMSfKDOfZHwAAAlc"]
[Tue Jul 21 08:33:18.597939 2026] [security2:error] [pid 466512:tid 466590] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/bthil.php"] [unique_id "al9Y_iKGokixMSfKDOfZIAACiU0"]
[Tue Jul 21 08:33:18.641646 2026] [security2:error] [pid 466512:tid 466593] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/7.php"] [unique_id "al9Y_iKGokixMSfKDOfZJgACLVA"]
[Tue Jul 21 08:33:18.684101 2026] [security2:error] [pid 466512:tid 466742] [client 185.213.175.37:16258] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "beezar.com.br"] [uri "/beezar.4fa85460.js"] [unique_id "al9Y_iKGokixMSfKDOfZJwAAAng"]
[Tue Jul 21 08:33:18.693023 2026] [security2:error] [pid 466512:tid 466739] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Y_iKGokixMSfKDOfZKAAAAnU"]
[Tue Jul 21 08:33:18.714667 2026] [security2:error] [pid 466512:tid 466580] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/8.php"] [unique_id "al9Y_iKGokixMSfKDOfZKwACW0M"]
[Tue Jul 21 08:33:18.743543 2026] [security2:error] [pid 466512:tid 466534] [remote 20.206.105.145:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "oportunity.serri.com.br"] [uri "/1.php"] [unique_id "al9Y_iKGokixMSfKDOfZLgACgBU"]
[Tue Jul 21 08:33:18.743635 2026] [security2:error] [pid 466512:tid 466534] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/1.php"] [unique_id "al9Y_iKGokixMSfKDOfZLgACgBU"]
[Tue Jul 21 08:33:18.766758 2026] [security2:error] [pid 466512:tid 466668] [client 34.74.242.206:1577] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.linkmaster.net.br"] [uri "/"] [unique_id "al9Y_iKGokixMSfKDOfZLwAAAi4"]
[Tue Jul 21 08:33:18.766864 2026] [security2:error] [pid 466512:tid 466668] [client 34.74.242.206:1577] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.linkmaster.net.br"] [uri "/"] [unique_id "al9Y_iKGokixMSfKDOfZLwAAAi4"]
[Tue Jul 21 08:33:18.789501 2026] [security2:error] [pid 466512:tid 466585] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/100.php"] [unique_id "al9Y_iKGokixMSfKDOfZMAACZEg"]
[Tue Jul 21 08:33:18.831753 2026] [security2:error] [pid 466512:tid 466522] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/about.php"] [unique_id "al9Y_iKGokixMSfKDOfZMgACdAk"]
[Tue Jul 21 08:33:18.851915 2026] [security2:error] [pid 466512:tid 466516] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/admin.php"] [unique_id "al9Y_iKGokixMSfKDOfZMwACOQM"]
[Tue Jul 21 08:33:18.872708 2026] [security2:error] [pid 466512:tid 466547] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/edit.php"] [unique_id "al9Y_iKGokixMSfKDOfZNQACcCI"]
[Tue Jul 21 08:33:18.902713 2026] [security2:error] [pid 466512:tid 466546] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Y_iKGokixMSfKDOfZNgACMiE"]
[Tue Jul 21 08:33:18.941493 2026] [security2:error] [pid 466512:tid 466724] [client 20.197.195.24:18704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/k2.php"] [unique_id "al9Y_iKGokixMSfKDOfZNwAAAmY"]
[Tue Jul 21 08:33:19.055686 2026] [security2:error] [pid 466512:tid 466643] [client 74.249.245.134:55529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/readme.php"] [unique_id "al9Y_yKGokixMSfKDOfZOwAAAhU"]
[Tue Jul 21 08:33:19.124961 2026] [security2:error] [pid 466512:tid 466601] [remote 199.189.225.40:63413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rgagestaodecondominios.adm.br"] [uri "/wp-login.php"] [unique_id "al9Y_yKGokixMSfKDOfZPwACi1g"]
[Tue Jul 21 08:33:19.172481 2026] [security2:error] [pid 466512:tid 466673] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Y_yKGokixMSfKDOfZQQAAAjM"]
[Tue Jul 21 08:33:19.214641 2026] [security2:error] [pid 465652:tid 465872] [client 20.104.96.117:62649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/miru1.php"] [unique_id "al9Y_zzTqJoBC2Mw28-2RwAAAN8"]
[Tue Jul 21 08:33:19.340410 2026] [security2:error] [pid 466512:tid 466762] [client 20.197.195.24:17052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9Y_yKGokixMSfKDOfZQwAAAow"]
[Tue Jul 21 08:33:19.374710 2026] [security2:error] [pid 466512:tid 466680] [client 4.194.24.143:8458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/222.php"] [unique_id "al9Y_yKGokixMSfKDOfZRAAAAjo"]
[Tue Jul 21 08:33:19.438605 2026] [security2:error] [pid 465652:tid 465813] [client 20.197.195.24:3903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/login.php"] [unique_id "al9Y_zzTqJoBC2Mw28-2SgAAAKQ"]
[Tue Jul 21 08:33:19.470393 2026] [security2:error] [pid 466512:tid 466660] [client 152.59.181.104:60704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Y_yKGokixMSfKDOfZRgAAAiY"]
[Tue Jul 21 08:33:19.470593 2026] [security2:error] [pid 466512:tid 466660] [client 152.59.181.104:60704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Y_yKGokixMSfKDOfZRgAAAiY"]
[Tue Jul 21 08:33:19.499927 2026] [security2:error] [pid 465652:tid 465847] [client 128.127.105.184:46906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Y_zzTqJoBC2Mw28-2TQAAAMY"]
[Tue Jul 21 08:33:19.500009 2026] [security2:error] [pid 465652:tid 465847] [client 128.127.105.184:46906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Y_zzTqJoBC2Mw28-2TQAAAMY"]
[Tue Jul 21 08:33:19.565626 2026] [security2:error] [pid 465652:tid 465881] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Y_zzTqJoBC2Mw28-2UAAAAOg"]
[Tue Jul 21 08:33:19.869769 2026] [security2:error] [pid 466512:tid 466698] [client 20.104.96.117:62671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/sump1.php"] [unique_id "al9Y_yKGokixMSfKDOfZSwAAAkw"]
[Tue Jul 21 08:33:19.960643 2026] [security2:error] [pid 466512:tid 466703] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Y_yKGokixMSfKDOfZTAAAAlE"]
[Tue Jul 21 08:33:19.963873 2026] [security2:error] [pid 465652:tid 465885] [client 195.49.128.211:50546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y_zzTqJoBC2Mw28-2VgAAAOw"]
[Tue Jul 21 08:33:19.963958 2026] [security2:error] [pid 465652:tid 465885] [client 195.49.128.211:50546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Y_zzTqJoBC2Mw28-2VgAAAOw"]
[Tue Jul 21 08:33:20.042662 2026] [security2:error] [pid 466512:tid 466769] [client 20.197.195.24:17086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9ZACKGokixMSfKDOfZTQAAApM"]
[Tue Jul 21 08:33:20.273594 2026] [security2:error] [pid 465652:tid 465803] [client 103.151.46.103:63717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZADzTqJoBC2Mw28-2XgAAAJo"]
[Tue Jul 21 08:33:20.273769 2026] [security2:error] [pid 465652:tid 465803] [client 103.151.46.103:63717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZADzTqJoBC2Mw28-2XgAAAJo"]
[Tue Jul 21 08:33:20.334028 2026] [security2:error] [pid 465652:tid 465874] [client 74.249.245.134:55538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/403.php"] [unique_id "al9ZADzTqJoBC2Mw28-2YAAAAOE"]
[Tue Jul 21 08:33:20.396174 2026] [security2:error] [pid 466512:tid 466700] [client 49.144.66.253:30158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZACKGokixMSfKDOfZUwAAAk4"]
[Tue Jul 21 08:33:20.396340 2026] [security2:error] [pid 466512:tid 466700] [client 49.144.66.253:30158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZACKGokixMSfKDOfZUwAAAk4"]
[Tue Jul 21 08:33:20.397029 2026] [security2:error] [pid 466512:tid 466709] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9ZACKGokixMSfKDOfZVAAAAlc"]
[Tue Jul 21 08:33:20.400448 2026] [security2:error] [pid 466512:tid 466657] [client 4.194.24.143:8448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/2p.php"] [unique_id "al9ZACKGokixMSfKDOfZVQAAAiM"]
[Tue Jul 21 08:33:20.421414 2026] [log_config:warn] [pid 418108:tid 418324] (32)Broken pipe: [client 186.219.143.42:13146] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 08:33:20.421428 2026] [log_config:warn] [pid 418108:tid 418324] (32)Broken pipe: [client 186.219.143.42:13146] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 08:33:20.646370 2026] [security2:error] [pid 466512:tid 466710] [client 20.197.195.24:53556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/a2.php"] [unique_id "al9ZACKGokixMSfKDOfZWAAAAlg"]
[Tue Jul 21 08:33:20.701740 2026] [security2:error] [pid 465652:tid 465886] [client 20.197.195.24:57877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9ZADzTqJoBC2Mw28-2awAAAO0"]
[Tue Jul 21 08:33:20.789486 2026] [security2:error] [pid 466512:tid 466602] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/f6.php"] [unique_id "al9ZACKGokixMSfKDOfZWwACgFk"]
[Tue Jul 21 08:33:20.795978 2026] [security2:error] [pid 465652:tid 465883] [client 5.38.115.39:14730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZADzTqJoBC2Mw28-2bgAAAOo"]
[Tue Jul 21 08:33:20.806356 2026] [security2:error] [pid 465652:tid 465883] [client 5.38.115.39:14730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZADzTqJoBC2Mw28-2bgAAAOo"]
[Tue Jul 21 08:33:20.831805 2026] [security2:error] [pid 466512:tid 466599] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/inputs.php"] [unique_id "al9ZACKGokixMSfKDOfZYAACIVY"]
[Tue Jul 21 08:33:20.848066 2026] [security2:error] [pid 466512:tid 466679] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9ZACKGokixMSfKDOfZYQAAAjk"]
[Tue Jul 21 08:33:20.851619 2026] [security2:error] [pid 466512:tid 466734] [client 20.104.96.117:46470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/file5.php"] [unique_id "al9ZACKGokixMSfKDOfZYgAAAnA"]
[Tue Jul 21 08:33:20.860112 2026] [security2:error] [pid 466512:tid 466570] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/av.php"] [unique_id "al9ZACKGokixMSfKDOfZYwACUzk"]
[Tue Jul 21 08:33:20.864212 2026] [security2:error] [pid 466512:tid 466701] [client 74.249.245.134:48995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/jp.php"] [unique_id "al9ZACKGokixMSfKDOfZZAAAAk8"]
[Tue Jul 21 08:33:20.876972 2026] [security2:error] [pid 466512:tid 466568] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/classwithtostring.php"] [unique_id "al9ZACKGokixMSfKDOfZZQACLDc"]
[Tue Jul 21 08:33:20.893111 2026] [security2:error] [pid 466512:tid 466603] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9ZACKGokixMSfKDOfZZgACe1o"]
[Tue Jul 21 08:33:20.909031 2026] [security2:error] [pid 466512:tid 466625] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-blog.php"] [unique_id "al9ZACKGokixMSfKDOfZZwACHXA"]
[Tue Jul 21 08:33:20.963452 2026] [security2:error] [pid 466512:tid 466579] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9ZACKGokixMSfKDOfZagACYUI"]
[Tue Jul 21 08:33:20.978845 2026] [security2:error] [pid 466512:tid 466573] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/adminfuns.php"] [unique_id "al9ZACKGokixMSfKDOfZawACfDw"]
[Tue Jul 21 08:33:21.072771 2026] [security2:error] [pid 466512:tid 466583] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/goods.php"] [unique_id "al9ZASKGokixMSfKDOfZbAACaEY"]
[Tue Jul 21 08:33:21.425103 2026] [security2:error] [pid 466512:tid 466743] [client 187.125.243.197:51619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZASKGokixMSfKDOfZbwAAAnk"]
[Tue Jul 21 08:33:21.425311 2026] [security2:error] [pid 466512:tid 466743] [client 187.125.243.197:51619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZASKGokixMSfKDOfZbwAAAnk"]
[Tue Jul 21 08:33:21.433182 2026] [security2:error] [pid 466512:tid 466691] [client 4.194.24.143:8455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/2p.update.php"] [unique_id "al9ZASKGokixMSfKDOfZcAAAAkU"]
[Tue Jul 21 08:33:21.567541 2026] [security2:error] [pid 465652:tid 465905] [client 74.249.245.134:54919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/max.php"] [unique_id "al9ZATzTqJoBC2Mw28-2egAAAQA"]
[Tue Jul 21 08:33:21.634967 2026] [security2:error] [pid 466512:tid 466717] [client 20.197.195.24:57874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/for.php"] [unique_id "al9ZASKGokixMSfKDOfZcgAAAl8"]
[Tue Jul 21 08:33:21.678744 2026] [security2:error] [pid 466512:tid 466605] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZASKGokixMSfKDOfZdQACJlw"]
[Tue Jul 21 08:33:21.678908 2026] [security2:error] [pid 466512:tid 466660] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZASKGokixMSfKDOfZdQACJlw"]
[Tue Jul 21 08:33:21.712490 2026] [security2:error] [pid 466512:tid 466690] [client 14.245.224.124:58387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZASKGokixMSfKDOfZdwAAAkQ"]
[Tue Jul 21 08:33:21.712627 2026] [security2:error] [pid 466512:tid 466690] [client 14.245.224.124:58387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZASKGokixMSfKDOfZdwAAAkQ"]
[Tue Jul 21 08:33:21.778823 2026] [security2:error] [pid 466512:tid 466692] [client 20.104.96.117:46479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/0xD.php"] [unique_id "al9ZASKGokixMSfKDOfZeAAAAkY"]
[Tue Jul 21 08:33:21.802051 2026] [security2:error] [pid 466512:tid 466703] [client 20.197.195.24:6278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/d61.php"] [unique_id "al9ZASKGokixMSfKDOfZeQAAAlE"]
[Tue Jul 21 08:33:22.110241 2026] [security2:error] [pid 465652:tid 465855] [client 20.197.195.24:6556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.cmpartners.com.br"] [uri "/raw.php"] [unique_id "al9ZAjzTqJoBC2Mw28-2gAAAAM4"]
[Tue Jul 21 08:33:22.232447 2026] [security2:error] [pid 466512:tid 466624] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/ms-edit.php"] [unique_id "al9ZAiKGokixMSfKDOfZfQACI28"]
[Tue Jul 21 08:33:22.247777 2026] [security2:error] [pid 466512:tid 466597] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/222.php"] [unique_id "al9ZAiKGokixMSfKDOfZfgACQVQ"]
[Tue Jul 21 08:33:22.274505 2026] [security2:error] [pid 465652:tid 465832] [client 47.128.127.247:13418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fremetexlondrina.com.br"] [uri "/robots.txt"] [unique_id "al9ZAjzTqJoBC2Mw28-2hQAAALc"]
[Tue Jul 21 08:33:22.337867 2026] [security2:error] [pid 466512:tid 466662] [client 20.206.105.145:25536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9ZAiKGokixMSfKDOfZgQAAAig"]
[Tue Jul 21 08:33:22.466129 2026] [security2:error] [pid 466512:tid 466728] [client 4.194.24.143:8483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/3pjcpmfsd8b.php"] [unique_id "al9ZAiKGokixMSfKDOfZhAAAAmo"]
[Tue Jul 21 08:33:22.509867 2026] [security2:error] [pid 465652:tid 465879] [client 74.249.245.134:37746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/m.php"] [unique_id "al9ZAjzTqJoBC2Mw28-2iwAAAOY"]
[Tue Jul 21 08:33:22.510676 2026] [security2:error] [pid 466512:tid 466633] [remote 47.128.114.97:20396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mdbroraima.org.br"] [uri "/mais-medicos/"] [unique_id "al9ZAiKGokixMSfKDOfZhQACPXg"]
[Tue Jul 21 08:33:22.705878 2026] [security2:error] [pid 465652:tid 465808] [client 74.7.230.11:33136] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "stephaniemarinho.online"] [uri "/cgi-sys/404.html"] [unique_id "al9ZAjzTqJoBC2Mw28-2jgAAn2Q"]
[Tue Jul 21 08:33:23.106858 2026] [security2:error] [pid 465652:tid 465869] [client 20.220.225.223:50301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/dp.php"] [unique_id "al9ZAzzTqJoBC2Mw28-2oQAAANw"]
[Tue Jul 21 08:33:23.145732 2026] [security2:error] [pid 466512:tid 466719] [client 20.104.96.117:62679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/fnstall.php"] [unique_id "al9ZAyKGokixMSfKDOfZjwAAAmE"]
[Tue Jul 21 08:33:23.413748 2026] [security2:error] [pid 465652:tid 465901] [client 5.31.193.106:1844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZAzzTqJoBC2Mw28-2pwAAAPw"]
[Tue Jul 21 08:33:23.413885 2026] [security2:error] [pid 465652:tid 465901] [client 5.31.193.106:1844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZAzzTqJoBC2Mw28-2pwAAAPw"]
[Tue Jul 21 08:33:23.529307 2026] [security2:error] [pid 465652:tid 465835] [client 4.194.24.143:8497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/403.php"] [unique_id "al9ZAzzTqJoBC2Mw28-2qAAAALo"]
[Tue Jul 21 08:33:23.713465 2026] [security2:error] [pid 466512:tid 466691] [client 20.197.192.193:43817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/jj.php"] [unique_id "al9ZAyKGokixMSfKDOfZlwAAAkU"]
[Tue Jul 21 08:33:23.758518 2026] [security2:error] [pid 465652:tid 465852] [client 20.197.195.24:3859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/info.php"] [unique_id "al9ZAzzTqJoBC2Mw28-2rgAAAMs"]
[Tue Jul 21 08:33:23.834731 2026] [security2:error] [pid 466512:tid 466714] [client 74.249.245.134:54916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/click.php"] [unique_id "al9ZAyKGokixMSfKDOfZmwAAAlw"]
[Tue Jul 21 08:33:23.912027 2026] [security2:error] [pid 466512:tid 466545] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9ZAyKGokixMSfKDOfZnAACXSA"]
[Tue Jul 21 08:33:23.986517 2026] [security2:error] [pid 466512:tid 466637] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9ZAyKGokixMSfKDOfZogACF3w"]
[Tue Jul 21 08:33:23.997010 2026] [security2:error] [pid 466512:tid 466752] [client 202.179.75.202:45300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZAyKGokixMSfKDOfZowAAAoI"]
[Tue Jul 21 08:33:23.997098 2026] [security2:error] [pid 466512:tid 466752] [client 202.179.75.202:45300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZAyKGokixMSfKDOfZowAAAoI"]
[Tue Jul 21 08:33:24.138219 2026] [security2:error] [pid 466512:tid 466542] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp.php"] [unique_id "al9ZBCKGokixMSfKDOfZqgACQR0"]
[Tue Jul 21 08:33:24.188284 2026] [security2:error] [pid 466512:tid 466582] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/abcd.php"] [unique_id "al9ZBCKGokixMSfKDOfZrAAChEU"]
[Tue Jul 21 08:33:24.226200 2026] [security2:error] [pid 466512:tid 466535] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/a1.php"] [unique_id "al9ZBCKGokixMSfKDOfZrQACShY"]
[Tue Jul 21 08:33:24.241502 2026] [security2:error] [pid 466512:tid 466572] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9ZBCKGokixMSfKDOfZrgACZTs"]
[Tue Jul 21 08:33:24.356653 2026] [security2:error] [pid 465652:tid 465823] [client 20.104.96.117:62617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/acp.php"] [unique_id "al9ZBDzTqJoBC2Mw28-2twAAAK4"]
[Tue Jul 21 08:33:24.596517 2026] [security2:error] [pid 466512:tid 466759] [client 4.194.24.143:5772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/404.php"] [unique_id "al9ZBCKGokixMSfKDOfZtgAAAok"]
[Tue Jul 21 08:33:24.756697 2026] [security2:error] [pid 466512:tid 466679] [client 20.197.195.24:6345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/11.php"] [unique_id "al9ZBCKGokixMSfKDOfZuQAAAjk"]
[Tue Jul 21 08:33:24.775855 2026] [security2:error] [pid 466512:tid 466713] [client 65.21.113.253:47542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZBCKGokixMSfKDOfZtwAAAls"]
[Tue Jul 21 08:33:24.928536 2026] [security2:error] [pid 466512:tid 466726] [client 61.1.167.83:57973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZBCKGokixMSfKDOfZwgAAAmg"]
[Tue Jul 21 08:33:24.928969 2026] [security2:error] [pid 466512:tid 466726] [client 61.1.167.83:57973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZBCKGokixMSfKDOfZwgAAAmg"]
[Tue Jul 21 08:33:25.010505 2026] [security2:error] [pid 466512:tid 466686] [client 74.249.245.134:55520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/lv.php"] [unique_id "al9ZBSKGokixMSfKDOfZxAAAAkA"]
[Tue Jul 21 08:33:25.294312 2026] [security2:error] [pid 465652:tid 465784] [client 20.104.96.117:46516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/mosty.php"] [unique_id "al9ZBTzTqJoBC2Mw28-2wwAAAIc"]
[Tue Jul 21 08:33:25.590193 2026] [security2:error] [pid 466512:tid 466698] [client 20.197.195.24:6383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/v2.php"] [unique_id "al9ZBSKGokixMSfKDOfZ0gAAAkw"]
[Tue Jul 21 08:33:25.763052 2026] [security2:error] [pid 465652:tid 465855] [client 4.194.24.143:17059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/4pjcpmfsd8b.php"] [unique_id "al9ZBTzTqJoBC2Mw28-2zAAAAM4"]
[Tue Jul 21 08:33:25.827702 2026] [security2:error] [pid 466512:tid 466657] [client 20.220.225.223:50271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/old.php"] [unique_id "al9ZBSKGokixMSfKDOfZ2gAAAiM"]
[Tue Jul 21 08:33:25.895759 2026] [core:error] [pid 466512:tid 466600] [remote 195.96.139.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpcalendars.getveltrixhealth.com:2095
[Tue Jul 21 08:33:25.895786 2026] [core:error] [pid 466512:tid 466600] [remote 195.96.139.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpcalendars.getveltrixhealth.com:2095
[Tue Jul 21 08:33:25.955892 2026] [security2:error] [pid 466512:tid 466684] [client 65.21.113.253:47556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZBSKGokixMSfKDOfZzwAAAj4"]
[Tue Jul 21 08:33:26.002617 2026] [security2:error] [pid 466512:tid 466699] [client 20.104.96.117:46552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/6.php"] [unique_id "al9ZBiKGokixMSfKDOfZ3wAAAk0"]
[Tue Jul 21 08:33:26.076646 2026] [security2:error] [pid 466512:tid 466662] [client 74.7.230.8:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "jessicarodriguesdasi1743307774296.0721679.myhostgator.site"] [uri "/robots.txt"] [unique_id "al9ZBiKGokixMSfKDOfZ4gACKGQ"]
[Tue Jul 21 08:33:26.249065 2026] [security2:error] [pid 466512:tid 466738] [client 74.249.245.134:48994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/error.php"] [unique_id "al9ZBiKGokixMSfKDOfZ4wAAAnQ"]
[Tue Jul 21 08:33:26.323363 2026] [security2:error] [pid 466512:tid 466612] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9ZBiKGokixMSfKDOfZ5AACT2M"]
[Tue Jul 21 08:33:26.337150 2026] [security2:error] [pid 466512:tid 466713] [client 20.197.195.24:6287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/panel.php"] [unique_id "al9ZBiKGokixMSfKDOfZ5QAAAls"]
[Tue Jul 21 08:33:26.375280 2026] [security2:error] [pid 466512:tid 466561] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/gettest.php"] [unique_id "al9ZBiKGokixMSfKDOfZ5wACVjA"]
[Tue Jul 21 08:33:26.413237 2026] [security2:error] [pid 466512:tid 466742] [client 195.49.128.211:59059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZBiKGokixMSfKDOfZ6QAAAng"]
[Tue Jul 21 08:33:26.413353 2026] [security2:error] [pid 466512:tid 466742] [client 195.49.128.211:59059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZBiKGokixMSfKDOfZ6QAAAng"]
[Tue Jul 21 08:33:26.448977 2026] [security2:error] [pid 466512:tid 466628] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/simple.php"] [unique_id "al9ZBiKGokixMSfKDOfZ7AACaHM"]
[Tue Jul 21 08:33:26.464341 2026] [security2:error] [pid 466512:tid 466533] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/xxx.php"] [unique_id "al9ZBiKGokixMSfKDOfZ7QACfBQ"]
[Tue Jul 21 08:33:26.479656 2026] [security2:error] [pid 466512:tid 466610] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/hypo.php"] [unique_id "al9ZBiKGokixMSfKDOfZ7wACM2E"]
[Tue Jul 21 08:33:26.531392 2026] [security2:error] [pid 465652:tid 465877] [client 20.197.195.24:3924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/dex.php"] [unique_id "al9ZBjzTqJoBC2Mw28-22QAAAOQ"]
[Tue Jul 21 08:33:26.635675 2026] [security2:error] [pid 465652:tid 465836] [client 20.104.96.117:62712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9ZBjzTqJoBC2Mw28-22wAAALs"]
[Tue Jul 21 08:33:26.768562 2026] [security2:error] [pid 466512:tid 466695] [client 74.249.245.134:54928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/cong.php"] [unique_id "al9ZBiKGokixMSfKDOfZ8QAAAkk"]
[Tue Jul 21 08:33:26.772090 2026] [security2:error] [pid 465652:tid 465848] [client 20.206.105.145:25102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wp-blog.php"] [unique_id "al9ZBjzTqJoBC2Mw28-23gAAAMc"]
[Tue Jul 21 08:33:26.790063 2026] [security2:error] [pid 466512:tid 466674] [client 4.194.24.143:8571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/666.php"] [unique_id "al9ZBiKGokixMSfKDOfZ8gAAAjQ"]
[Tue Jul 21 08:33:26.922301 2026] [security2:error] [pid 465652:tid 465763] [remote 117.0.21.154:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9ZBjzTqJoBC2Mw28-24AAAz24"]
[Tue Jul 21 08:33:27.107478 2026] [security2:error] [pid 465652:tid 465811] [client 20.104.96.117:46561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/qqqa.php"] [unique_id "al9ZBzzTqJoBC2Mw28-25AAAAKI"]
[Tue Jul 21 08:33:27.252841 2026] [security2:error] [pid 465652:tid 465794] [client 223.181.60.88:18696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZBzzTqJoBC2Mw28-26wAAAJE"]
[Tue Jul 21 08:33:27.253464 2026] [security2:error] [pid 465652:tid 465794] [client 223.181.60.88:18696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZBzzTqJoBC2Mw28-26wAAAJE"]
[Tue Jul 21 08:33:27.428549 2026] [security2:error] [pid 466512:tid 466571] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/chosen.php"] [unique_id "al9ZByKGokixMSfKDOfZ-gACfTo"]
[Tue Jul 21 08:33:27.468532 2026] [security2:error] [pid 465652:tid 465728] [remote 41.186.86.12:39767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moldurasbrilhante.com.br"] [uri "/wp-login.php"] [unique_id "al9ZBzzTqJoBC2Mw28-29AAA50s"]
[Tue Jul 21 08:33:27.472919 2026] [security2:error] [pid 466512:tid 466714] [client 20.197.195.24:16002] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bastarecomecar.com.br"] [uri "/1.php"] [unique_id "al9ZByKGokixMSfKDOfZ_AAAAlw"]
[Tue Jul 21 08:33:27.473007 2026] [security2:error] [pid 466512:tid 466714] [client 20.197.195.24:16002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/1.php"] [unique_id "al9ZByKGokixMSfKDOfZ_AAAAlw"]
[Tue Jul 21 08:33:27.573933 2026] [security2:error] [pid 466512:tid 466540] [remote 20.153.140.50:45856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9ZByKGokixMSfKDOfZ_QACFBs"]
[Tue Jul 21 08:33:27.660290 2026] [core:alert] [pid 465652:tid 465861] [client 57.141.18.72:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:33:27.692727 2026] [security2:error] [pid 466512:tid 466584] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/als.php"] [unique_id "al9ZByKGokixMSfKDOfaAQACXkc"]
[Tue Jul 21 08:33:27.821248 2026] [security2:error] [pid 466512:tid 466749] [client 4.194.24.143:61002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/7.php"] [unique_id "al9ZByKGokixMSfKDOfaAgAAAn8"]
[Tue Jul 21 08:33:27.853009 2026] [security2:error] [pid 465652:tid 465821] [client 74.249.245.134:33324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/classwithtostring.php"] [unique_id "al9ZBzzTqJoBC2Mw28-2_gAAAKw"]
[Tue Jul 21 08:33:27.884971 2026] [security2:error] [pid 465652:tid 465798] [client 20.104.96.117:46526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/aunmc.php"] [unique_id "al9ZBzzTqJoBC2Mw28-3AAAAAJU"]
[Tue Jul 21 08:33:27.963578 2026] [rewrite:warn] [pid 465652:tid 465654] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:33:28.036382 2026] [security2:error] [pid 465652:tid 465691] [remote 74.7.242.8:34748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.242.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.votacao.agendaclique.com.br"] [uri "/public/index.php"] [unique_id "al9ZBzzTqJoBC2Mw28-2_wAA8iY"], referer: https://www.votacao.agendaclique.com.br/
[Tue Jul 21 08:33:28.143391 2026] [security2:error] [pid 465652:tid 465808] [client 20.197.195.24:3948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/ms.php"] [unique_id "al9ZCDzTqJoBC2Mw28-3EAAAAJ8"]
[Tue Jul 21 08:33:28.188096 2026] [security2:error] [pid 465652:tid 465876] [client 74.7.244.32:46334] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.votacao.agendaclique.com.br"] [uri "/public/index.php"] [unique_id "al9ZCDzTqJoBC2Mw28-3EgAA4xA"]
[Tue Jul 21 08:33:28.263137 2026] [security2:error] [pid 466512:tid 466677] [client 117.213.202.34:65284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZCCKGokixMSfKDOfaBgAAAjc"]
[Tue Jul 21 08:33:28.263434 2026] [security2:error] [pid 466512:tid 466677] [client 117.213.202.34:65284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZCCKGokixMSfKDOfaBgAAAjc"]
[Tue Jul 21 08:33:28.305115 2026] [security2:error] [pid 466512:tid 466593] [remote 152.53.111.131:51880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9ZCCKGokixMSfKDOfaBwACG1A"]
[Tue Jul 21 08:33:28.305440 2026] [security2:error] [pid 466512:tid 466649] [client 152.53.111.131:51880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9ZCCKGokixMSfKDOfaBwACG1A"]
[Tue Jul 21 08:33:28.364836 2026] [security2:error] [pid 466512:tid 466580] [remote 57.141.18.94:31002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.mdbroraima.org.br"] [uri "/"] [unique_id "al9ZCCKGokixMSfKDOfaCAACTkM"]
[Tue Jul 21 08:33:28.397705 2026] [security2:error] [pid 465652:tid 465829] [client 20.104.96.117:64209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/uoocf.php"] [unique_id "al9ZCDzTqJoBC2Mw28-3FgAAALQ"]
[Tue Jul 21 08:33:28.463278 2026] [security2:error] [pid 466512:tid 466534] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/pol.php"] [unique_id "al9ZCCKGokixMSfKDOfaCQACihU"]
[Tue Jul 21 08:33:28.556832 2026] [autoindex:error] [pid 466512:tid 466667] [client 20.197.195.24:53618] AH01276: Cannot serve directory /home1/bastar15/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:33:28.566326 2026] [security2:error] [pid 466512:tid 466653] [client 20.197.195.24:53618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/memberfuns.php"] [unique_id "al9ZCCKGokixMSfKDOfaEQAAAh8"]
[Tue Jul 21 08:33:28.638419 2026] [security2:error] [pid 466512:tid 466601] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/file5.php"] [unique_id "al9ZCCKGokixMSfKDOfaFwACKFg"]
[Tue Jul 21 08:33:28.715382 2026] [security2:error] [pid 465652:tid 465857] [client 122.176.100.127:56025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZCDzTqJoBC2Mw28-3HAAAANA"]
[Tue Jul 21 08:33:28.715679 2026] [security2:error] [pid 465652:tid 465857] [client 122.176.100.127:56025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZCDzTqJoBC2Mw28-3HAAAANA"]
[Tue Jul 21 08:33:28.878625 2026] [security2:error] [pid 466512:tid 466763] [client 4.194.24.143:8864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/8.php"] [unique_id "al9ZCCKGokixMSfKDOfaHgAAAo0"]
[Tue Jul 21 08:33:28.994874 2026] [security2:error] [pid 465652:tid 465803] [client 14.97.58.74:23945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZCDzTqJoBC2Mw28-3IgAAAJo"]
[Tue Jul 21 08:33:28.994989 2026] [security2:error] [pid 465652:tid 465803] [client 14.97.58.74:23945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZCDzTqJoBC2Mw28-3IgAAAJo"]
[Tue Jul 21 08:33:29.067259 2026] [security2:error] [pid 465652:tid 465796] [client 20.197.192.193:65201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/8.php"] [unique_id "al9ZCTzTqJoBC2Mw28-3KAAAAJM"]
[Tue Jul 21 08:33:29.155250 2026] [security2:error] [pid 466512:tid 466569] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9ZCSKGokixMSfKDOfaIwACIjg"]
[Tue Jul 21 08:33:29.194592 2026] [security2:error] [pid 466512:tid 466691] [client 20.104.96.117:46548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/iywwi.php"] [unique_id "al9ZCSKGokixMSfKDOfaJAAAAkU"]
[Tue Jul 21 08:33:29.203309 2026] [security2:error] [pid 466512:tid 466733] [client 20.197.195.24:15726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/0.php"] [unique_id "al9ZCSKGokixMSfKDOfaJQAAAm8"]
[Tue Jul 21 08:33:29.287316 2026] [security2:error] [pid 466512:tid 466549] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/file.php"] [unique_id "al9ZCSKGokixMSfKDOfaJgACkSQ"]
[Tue Jul 21 08:33:29.349642 2026] [security2:error] [pid 465652:tid 465854] [client 74.249.245.134:55508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/brand.php"] [unique_id "al9ZCTzTqJoBC2Mw28-3LQAAAM0"]
[Tue Jul 21 08:33:29.909097 2026] [security2:error] [pid 465652:tid 465790] [client 4.194.24.143:5787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/87.php"] [unique_id "al9ZCTzTqJoBC2Mw28-3NwAAAI0"]
[Tue Jul 21 08:33:29.919712 2026] [security2:error] [pid 466512:tid 466654] [client 20.104.96.117:62712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/gqgsa.php"] [unique_id "al9ZCSKGokixMSfKDOfaKwAAAiA"]
[Tue Jul 21 08:33:30.066554 2026] [security2:error] [pid 466512:tid 466526] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/cfile.php"] [unique_id "al9ZCiKGokixMSfKDOfaMAACFw0"]
[Tue Jul 21 08:33:30.103788 2026] [security2:error] [pid 466512:tid 466619] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/class-wp.php"] [unique_id "al9ZCiKGokixMSfKDOfaNQACTmo"]
[Tue Jul 21 08:33:30.130187 2026] [security2:error] [pid 466512:tid 466751] [client 20.197.195.24:6325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/BDKR28.php"] [unique_id "al9ZCiKGokixMSfKDOfaNgAAAoE"]
[Tue Jul 21 08:33:30.177723 2026] [security2:error] [pid 466512:tid 466723] [client 74.249.245.134:46997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/bless.php"] [unique_id "al9ZCiKGokixMSfKDOfaNwAAAmU"]
[Tue Jul 21 08:33:30.341727 2026] [security2:error] [pid 465652:tid 465843] [client 20.197.195.24:6684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9ZCjzTqJoBC2Mw28-3PQAAAMI"]
[Tue Jul 21 08:33:30.377855 2026] [security2:error] [pid 465652:tid 465851] [client 152.59.181.104:61127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZCjzTqJoBC2Mw28-3PgAAAMo"]
[Tue Jul 21 08:33:30.378015 2026] [security2:error] [pid 465652:tid 465851] [client 152.59.181.104:61127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZCjzTqJoBC2Mw28-3PgAAAMo"]
[Tue Jul 21 08:33:30.427673 2026] [security2:error] [pid 466512:tid 466631] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/admin.php"] [unique_id "al9ZCiKGokixMSfKDOfaOQACanY"]
[Tue Jul 21 08:33:30.443800 2026] [security2:error] [pid 466512:tid 466602] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/aa2.php"] [unique_id "al9ZCiKGokixMSfKDOfaOgACPlk"]
[Tue Jul 21 08:33:30.473491 2026] [security2:error] [pid 466512:tid 466614] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/ccou.php"] [unique_id "al9ZCiKGokixMSfKDOfaOwACPWU"]
[Tue Jul 21 08:33:30.558666 2026] [security2:error] [pid 466512:tid 466709] [client 195.49.128.211:51144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZCiKGokixMSfKDOfaPAAAAlc"]
[Tue Jul 21 08:33:30.558836 2026] [security2:error] [pid 466512:tid 466709] [client 195.49.128.211:51144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZCiKGokixMSfKDOfaPAAAAlc"]
[Tue Jul 21 08:33:30.607342 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.607508 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.607627 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.607694 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.607772 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.607906 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608012 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608056 2026] [security2:error] [pid 466512:tid 466657] [client 65.21.113.253:47556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZCiKGokixMSfKDOfaNAAAAiM"]
[Tue Jul 21 08:33:30.608076 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608160 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608239 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608304 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608363 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608428 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608488 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608546 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608604 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608662 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608720 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608779 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608844 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608906 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.608967 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.609026 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.609088 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.609147 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.609219 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.609278 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.609336 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.609458 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.609519 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.609581 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.609663 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.609721 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.609801 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.609877 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.609922 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.610012 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.610188 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.610272 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.610338 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.610398 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.610459 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.610517 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.610586 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.610681 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.610741 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.610803 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.610872 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.610932 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.610991 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611049 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611109 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611183 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611242 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611300 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611361 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611421 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611480 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611543 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611602 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611660 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611735 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611797 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611888 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.611953 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612017 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612062 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612109 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612149 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612209 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612250 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612290 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612329 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612368 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612409 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612447 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612486 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612528 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612568 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612606 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612646 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612688 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612730 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612769 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612825 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612869 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.612928 2026] [lsapi:warn] [pid 466512:tid 466562] [remote 57.141.18.0:35536] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:33:30.623661 2026] [security2:error] [pid 465652:tid 465881] [client 20.197.195.24:6374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/green1.php"] [unique_id "al9ZCjzTqJoBC2Mw28-3RAAAAOg"]
[Tue Jul 21 08:33:30.784689 2026] [security2:error] [pid 465652:tid 465832] [client 49.144.66.253:30612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZCjzTqJoBC2Mw28-3RwAAALc"]
[Tue Jul 21 08:33:30.784794 2026] [security2:error] [pid 465652:tid 465832] [client 49.144.66.253:30612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZCjzTqJoBC2Mw28-3RwAAALc"]
[Tue Jul 21 08:33:30.824779 2026] [security2:error] [pid 466512:tid 466682] [client 103.151.46.103:64212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZCiKGokixMSfKDOfaSwAAAjw"]
[Tue Jul 21 08:33:30.825193 2026] [security2:error] [pid 466512:tid 466682] [client 103.151.46.103:64212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZCiKGokixMSfKDOfaSwAAAjw"]
[Tue Jul 21 08:33:30.943996 2026] [security2:error] [pid 465652:tid 465871] [client 4.194.24.143:5818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/99.php"] [unique_id "al9ZCjzTqJoBC2Mw28-3SwAAAN4"]
[Tue Jul 21 08:33:31.169465 2026] [security2:error] [pid 466512:tid 466672] [client 20.220.225.223:50296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/ms-new.php"] [unique_id "al9ZCyKGokixMSfKDOfaUwAAAjI"]
[Tue Jul 21 08:33:31.207665 2026] [security2:error] [pid 466512:tid 466767] [client 20.197.192.193:65188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/dragonshell.php"] [unique_id "al9ZCyKGokixMSfKDOfaVAAAApE"]
[Tue Jul 21 08:33:31.338045 2026] [security2:error] [pid 466512:tid 466625] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/dr.php"] [unique_id "al9ZCyKGokixMSfKDOfaVQACO3A"]
[Tue Jul 21 08:33:31.356720 2026] [security2:error] [pid 466512:tid 466551] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/xamp.php"] [unique_id "al9ZCyKGokixMSfKDOfaVgACQyY"]
[Tue Jul 21 08:33:31.385101 2026] [security2:error] [pid 465652:tid 465873] [client 74.249.245.134:55548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/atomlib.php"] [unique_id "al9ZCzzTqJoBC2Mw28-3UgAAAOA"]
[Tue Jul 21 08:33:31.431151 2026] [security2:error] [pid 466512:tid 466652] [client 5.38.115.39:49328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZCyKGokixMSfKDOfaVwAAAh4"]
[Tue Jul 21 08:33:31.431411 2026] [security2:error] [pid 466512:tid 466652] [client 5.38.115.39:49328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZCyKGokixMSfKDOfaVwAAAh4"]
[Tue Jul 21 08:33:31.558238 2026] [autoindex:error] [pid 466512:tid 466765] [client 43.165.2.110:59330] AH01276: Cannot serve directory /home2/lari0640/lararmstore.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:33:31.825122 2026] [security2:error] [pid 466512:tid 466700] [client 20.104.96.117:62667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/elbzl.php"] [unique_id "al9ZCyKGokixMSfKDOfaXgAAAk4"]
[Tue Jul 21 08:33:31.899844 2026] [security2:error] [pid 466512:tid 466649] [client 74.249.245.134:41893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/storage/index.php"] [unique_id "al9ZCyKGokixMSfKDOfaYAAAAhs"]
[Tue Jul 21 08:33:31.903663 2026] [security2:error] [pid 465652:tid 465824] [client 20.197.195.24:53543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/nc4.php"] [unique_id "al9ZCzzTqJoBC2Mw28-3WQAAAK8"]
[Tue Jul 21 08:33:31.919965 2026] [security2:error] [pid 465652:tid 465853] [client 187.125.243.197:52120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZCzzTqJoBC2Mw28-3WgAAAMw"]
[Tue Jul 21 08:33:31.920093 2026] [security2:error] [pid 465652:tid 465853] [client 187.125.243.197:52120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZCzzTqJoBC2Mw28-3WgAAAMw"]
[Tue Jul 21 08:33:32.016388 2026] [security2:error] [pid 465652:tid 465806] [client 4.194.24.143:8523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/a.php"] [unique_id "al9ZDDzTqJoBC2Mw28-3WwAAAJ0"]
[Tue Jul 21 08:33:32.205906 2026] [security2:error] [pid 466512:tid 466573] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZDCKGokixMSfKDOfaYwACJzw"]
[Tue Jul 21 08:33:32.206035 2026] [security2:error] [pid 466512:tid 466661] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZDCKGokixMSfKDOfaYwACJzw"]
[Tue Jul 21 08:33:32.207129 2026] [security2:error] [pid 466512:tid 466583] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/bless.php"] [unique_id "al9ZDCKGokixMSfKDOfaZAACTUY"]
[Tue Jul 21 08:33:32.265985 2026] [core:error] [pid 466512:tid 466624] [remote 52.167.144.209:14663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:32.266020 2026] [core:error] [pid 466512:tid 466624] [remote 52.167.144.209:14663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:32.316716 2026] [security2:error] [pid 466512:tid 466683] [client 20.197.195.24:6756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9ZDCKGokixMSfKDOfaZwAAAj0"]
[Tue Jul 21 08:33:32.389854 2026] [core:error] [pid 466512:tid 466597] [remote 52.167.144.209:14663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:32.389874 2026] [core:error] [pid 466512:tid 466597] [remote 52.167.144.209:14663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:32.421958 2026] [security2:error] [pid 466512:tid 466751] [client 14.245.224.124:58863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZDCKGokixMSfKDOfaaQAAAoE"]
[Tue Jul 21 08:33:32.422075 2026] [security2:error] [pid 466512:tid 466751] [client 14.245.224.124:58863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZDCKGokixMSfKDOfaaQAAAoE"]
[Tue Jul 21 08:33:32.429418 2026] [security2:error] [pid 465652:tid 465870] [client 152.59.34.51:61162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZDDzTqJoBC2Mw28-3YgAAAN0"]
[Tue Jul 21 08:33:32.431092 2026] [security2:error] [pid 465652:tid 465870] [client 152.59.34.51:61162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZDDzTqJoBC2Mw28-3YgAAAN0"]
[Tue Jul 21 08:33:32.729100 2026] [security2:error] [pid 466512:tid 466670] [client 74.249.245.134:37699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/0x.php"] [unique_id "al9ZDCKGokixMSfKDOfacQAAAjA"]
[Tue Jul 21 08:33:32.884659 2026] [security2:error] [pid 466512:tid 466685] [client 20.104.96.117:62701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/adjig.php"] [unique_id "al9ZDCKGokixMSfKDOfadQAAAj8"]
[Tue Jul 21 08:33:33.087360 2026] [core:error] [pid 466512:tid 466594] [remote 52.167.144.209:14663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:33.087386 2026] [core:error] [pid 466512:tid 466594] [remote 52.167.144.209:14663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:33.097715 2026] [security2:error] [pid 465652:tid 465825] [client 4.194.24.143:8871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/a4.php"] [unique_id "al9ZDTzTqJoBC2Mw28-3bwAAALA"]
[Tue Jul 21 08:33:33.221391 2026] [security2:error] [pid 466512:tid 466756] [client 172.233.172.167:43012] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "prissedermatologia.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9ZDSKGokixMSfKDOfafQAAAoY"]
[Tue Jul 21 08:33:33.227285 2026] [security2:error] [pid 466512:tid 466719] [client 20.197.195.24:15740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/a1.php"] [unique_id "al9ZDSKGokixMSfKDOfafgAAAmE"]
[Tue Jul 21 08:33:33.315918 2026] [security2:error] [pid 466512:tid 466707] [client 20.197.192.193:65213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/wp-mt.php"] [unique_id "al9ZDSKGokixMSfKDOfagQAAAlU"]
[Tue Jul 21 08:33:33.334615 2026] [security2:error] [pid 466512:tid 466659] [client 172.233.172.167:43012] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "prissedermatologia.com.br"] [uri "/"] [unique_id "al9ZDSKGokixMSfKDOfaggAAAiU"]
[Tue Jul 21 08:33:33.832934 2026] [security2:error] [pid 466512:tid 466698] [client 20.104.96.117:46498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/byp.php"] [unique_id "al9ZDSKGokixMSfKDOfakAAAAkw"]
[Tue Jul 21 08:33:34.081748 2026] [security2:error] [pid 466512:tid 466682] [client 156.196.210.35:13986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.210.196.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gestaofranquias.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZDSKGokixMSfKDOfaeQAAAjw"]
[Tue Jul 21 08:33:34.081903 2026] [security2:error] [pid 466512:tid 466682] [client 156.196.210.35:13986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "gestaofranquias.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZDSKGokixMSfKDOfaeQAAAjw"]
[Tue Jul 21 08:33:34.127638 2026] [security2:error] [pid 466512:tid 466572] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/file46.php"] [unique_id "al9ZDiKGokixMSfKDOfalgACPTs"]
[Tue Jul 21 08:33:34.129362 2026] [security2:error] [pid 466512:tid 466649] [client 4.194.24.143:8902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/a7.php"] [unique_id "al9ZDiKGokixMSfKDOfalwAAAhs"]
[Tue Jul 21 08:33:34.137372 2026] [security2:error] [pid 466512:tid 466718] [client 20.197.195.24:6777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/media.php"] [unique_id "al9ZDiKGokixMSfKDOfamAAAAmA"]
[Tue Jul 21 08:33:34.150432 2026] [security2:error] [pid 466512:tid 466655] [client 20.197.195.24:53588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/eee.php"] [unique_id "al9ZDiKGokixMSfKDOfamQAAAiE"]
[Tue Jul 21 08:33:34.336747 2026] [security2:error] [pid 466512:tid 466742] [client 213.152.186.163:41744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZDiKGokixMSfKDOfangAAAng"]
[Tue Jul 21 08:33:34.336958 2026] [security2:error] [pid 466512:tid 466742] [client 213.152.186.163:41744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZDiKGokixMSfKDOfangAAAng"]
[Tue Jul 21 08:33:34.337795 2026] [security2:error] [pid 466512:tid 466670] [client 74.249.245.134:54913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/buy.php"] [unique_id "al9ZDiKGokixMSfKDOfanwAAAjA"]
[Tue Jul 21 08:33:34.350118 2026] [security2:error] [pid 466512:tid 466563] [remote 202.51.202.242:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9ZDiKGokixMSfKDOfaoAACNjI"]
[Tue Jul 21 08:33:34.350367 2026] [security2:error] [pid 466512:tid 466676] [client 202.51.202.242:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9ZDiKGokixMSfKDOfaoAACNjI"]
[Tue Jul 21 08:33:34.458109 2026] [security2:error] [pid 466512:tid 466697] [client 74.249.245.134:41832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/g.php"] [unique_id "al9ZDiKGokixMSfKDOfapgAAAks"]
[Tue Jul 21 08:33:34.665521 2026] [security2:error] [pid 466512:tid 466664] [client 20.220.225.223:50901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/track.php"] [unique_id "al9ZDiKGokixMSfKDOfarAAAAio"]
[Tue Jul 21 08:33:34.740089 2026] [security2:error] [pid 466512:tid 466548] [remote 156.239.147.29:45699] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "cartoriodecurupira.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "al9ZDiKGokixMSfKDOfarQACRSM"], referer: https://cartoriodecurupira.com.br/emissao-de-segunda-via-de-certidoes-pelo-crc/
[Tue Jul 21 08:33:34.811700 2026] [security2:error] [pid 465652:tid 465875] [client 20.104.96.117:46490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9ZDjzTqJoBC2Mw28-3hgAAAOI"]
[Tue Jul 21 08:33:34.824089 2026] [security2:error] [pid 466512:tid 466708] [client 202.179.75.202:47954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZDiKGokixMSfKDOfasQAAAlY"]
[Tue Jul 21 08:33:34.824240 2026] [security2:error] [pid 466512:tid 466708] [client 202.179.75.202:47954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZDiKGokixMSfKDOfasQAAAlY"]
[Tue Jul 21 08:33:34.912980 2026] [security2:error] [pid 465652:tid 465785] [client 20.197.192.193:43782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/ww.php"] [unique_id "al9ZDjzTqJoBC2Mw28-3iQAAAIg"]
[Tue Jul 21 08:33:34.951767 2026] [security2:error] [pid 465652:tid 465849] [client 20.197.195.24:6317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/wp-aothait.php"] [unique_id "al9ZDjzTqJoBC2Mw28-3igAAAMg"]
[Tue Jul 21 08:33:35.207642 2026] [security2:error] [pid 465652:tid 465888] [client 4.194.24.143:8529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/aa.php"] [unique_id "al9ZDzzTqJoBC2Mw28-3jQAAAO8"]
[Tue Jul 21 08:33:35.261089 2026] [security2:error] [pid 466512:tid 466656] [client 65.21.113.253:47556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZDiKGokixMSfKDOfarwAAAiI"]
[Tue Jul 21 08:33:35.283360 2026] [security2:error] [pid 466512:tid 466535] [remote 45.3.36.209:13665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.36.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9ZDiKGokixMSfKDOfalQACJxY"]
[Tue Jul 21 08:33:35.317289 2026] [security2:error] [pid 466512:tid 466553] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/eee.php"] [unique_id "al9ZDyKGokixMSfKDOfatgACRCg"]
[Tue Jul 21 08:33:35.336440 2026] [security2:error] [pid 466512:tid 466587] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/file25.php"] [unique_id "al9ZDyKGokixMSfKDOfatwACFEo"]
[Tue Jul 21 08:33:35.377083 2026] [security2:error] [pid 466512:tid 466575] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/file48.php"] [unique_id "al9ZDyKGokixMSfKDOfauAACOT4"]
[Tue Jul 21 08:33:35.442822 2026] [security2:error] [pid 466512:tid 466617] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/file6.php"] [unique_id "al9ZDyKGokixMSfKDOfauwACGGg"]
[Tue Jul 21 08:33:35.462287 2026] [security2:error] [pid 466512:tid 466600] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/a2.php"] [unique_id "al9ZDyKGokixMSfKDOfavAACLVc"]
[Tue Jul 21 08:33:35.478000 2026] [security2:error] [pid 466512:tid 466621] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/file15.php"] [unique_id "al9ZDyKGokixMSfKDOfavQACg2w"]
[Tue Jul 21 08:33:35.508733 2026] [security2:error] [pid 466512:tid 466613] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/jp.php"] [unique_id "al9ZDyKGokixMSfKDOfavgACdWQ"]
[Tue Jul 21 08:33:35.551093 2026] [security2:error] [pid 466512:tid 466554] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/f35.php"] [unique_id "al9ZDyKGokixMSfKDOfavwACRik"]
[Tue Jul 21 08:33:35.568079 2026] [security2:error] [pid 466512:tid 466612] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-load.php"] [unique_id "al9ZDyKGokixMSfKDOfawAACgmM"]
[Tue Jul 21 08:33:35.583210 2026] [security2:error] [pid 466512:tid 466561] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/xwpg.php"] [unique_id "al9ZDyKGokixMSfKDOfawQACXDA"]
[Tue Jul 21 08:33:35.681387 2026] [security2:error] [pid 466512:tid 466669] [client 20.197.195.24:3852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/config.json.php"] [unique_id "al9ZDyKGokixMSfKDOfaxgAAAi8"]
[Tue Jul 21 08:33:35.711990 2026] [security2:error] [pid 466512:tid 466682] [client 20.104.96.117:64232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/classwithtostring.php"] [unique_id "al9ZDyKGokixMSfKDOfaxwAAAjw"]
[Tue Jul 21 08:33:35.765138 2026] [security2:error] [pid 466512:tid 466743] [client 20.197.195.24:6361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9ZDyKGokixMSfKDOfayAAAAnk"]
[Tue Jul 21 08:33:35.781336 2026] [security2:error] [pid 466512:tid 466649] [client 20.197.192.193:43823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/red.php"] [unique_id "al9ZDyKGokixMSfKDOfayQAAAhs"]
[Tue Jul 21 08:33:35.781589 2026] [security2:error] [pid 465652:tid 465906] [client 20.197.195.24:6320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/k2.php"] [unique_id "al9ZDzzTqJoBC2Mw28-3lQAAAQE"]
[Tue Jul 21 08:33:35.836573 2026] [security2:error] [pid 465652:tid 465898] [client 20.197.195.24:3885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9ZDzzTqJoBC2Mw28-3lwAAAPk"]
[Tue Jul 21 08:33:36.090524 2026] [security2:error] [pid 466512:tid 466670] [client 20.197.195.24:6299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9ZECKGokixMSfKDOfa1AAAAjA"]
[Tue Jul 21 08:33:36.261362 2026] [security2:error] [pid 466512:tid 466724] [client 4.194.24.143:8573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/aaa.php"] [unique_id "al9ZECKGokixMSfKDOfa1gAAAmY"]
[Tue Jul 21 08:33:36.310548 2026] [security2:error] [pid 466512:tid 466755] [client 74.249.245.134:54937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/sx.php"] [unique_id "al9ZECKGokixMSfKDOfa1wAAAoU"]
[Tue Jul 21 08:33:36.632837 2026] [security2:error] [pid 466512:tid 466767] [client 20.197.195.24:6762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/images.php"] [unique_id "al9ZECKGokixMSfKDOfa3wAAApE"]
[Tue Jul 21 08:33:36.799668 2026] [security2:error] [pid 466512:tid 466681] [client 74.249.245.134:50734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/nf.php"] [unique_id "al9ZECKGokixMSfKDOfa5AAAAjs"]
[Tue Jul 21 08:33:37.004714 2026] [security2:error] [pid 466512:tid 466752] [client 20.104.96.117:62592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/root.php"] [unique_id "al9ZESKGokixMSfKDOfa6AAAAoI"]
[Tue Jul 21 08:33:37.052947 2026] [security2:error] [pid 466512:tid 466720] [client 195.49.128.211:59677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZESKGokixMSfKDOfa6gAAAmI"]
[Tue Jul 21 08:33:37.053043 2026] [security2:error] [pid 466512:tid 466720] [client 195.49.128.211:59677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZESKGokixMSfKDOfa6gAAAmI"]
[Tue Jul 21 08:33:37.261035 2026] [security2:error] [pid 466512:tid 466577] [remote 65.111.8.102:63117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9ZESKGokixMSfKDOfa6wACREA"]
[Tue Jul 21 08:33:37.292376 2026] [security2:error] [pid 466512:tid 466741] [client 4.194.24.143:8930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/ab.php"] [unique_id "al9ZESKGokixMSfKDOfa7QAAAnc"]
[Tue Jul 21 08:33:37.342904 2026] [security2:error] [pid 466512:tid 466705] [client 198.12.69.94:54178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.69.12.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "privatesafesale.com"] [uri "/wp-comments-post.php"] [unique_id "al9ZESKGokixMSfKDOfa6QAAAlM"], referer: https://privatesafesale.com/2026/06/24/hello-world/
[Tue Jul 21 08:33:37.343113 2026] [security2:error] [pid 466512:tid 466705] [client 198.12.69.94:54178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "privatesafesale.com"] [uri "/wp-comments-post.php"] [unique_id "al9ZESKGokixMSfKDOfa6QAAAlM"], referer: https://privatesafesale.com/2026/06/24/hello-world/
[Tue Jul 21 08:33:37.402185 2026] [security2:error] [pid 466512:tid 466754] [client 20.197.192.193:65167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/cron.php"] [unique_id "al9ZESKGokixMSfKDOfa7gAAAoQ"]
[Tue Jul 21 08:33:37.485345 2026] [security2:error] [pid 466512:tid 466768] [client 20.197.195.24:3903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9ZESKGokixMSfKDOfa8AAAApI"]
[Tue Jul 21 08:33:37.619505 2026] [security2:error] [pid 466512:tid 466649] [client 20.104.96.117:62710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/sym403.php"] [unique_id "al9ZESKGokixMSfKDOfa8gAAAhs"]
[Tue Jul 21 08:33:38.264624 2026] [security2:error] [pid 466512:tid 466664] [client 20.104.96.117:46586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/v543.php"] [unique_id "al9ZEiKGokixMSfKDOfa-AAAAio"]
[Tue Jul 21 08:33:38.316949 2026] [security2:error] [pid 465652:tid 465907] [client 4.194.24.143:61038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/abc.php"] [unique_id "al9ZEjzTqJoBC2Mw28-3vAAAAQI"]
[Tue Jul 21 08:33:38.398196 2026] [security2:error] [pid 466512:tid 466644] [client 20.220.225.223:50275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/2352356666.php"] [unique_id "al9ZEiKGokixMSfKDOfa-wAAAhY"]
[Tue Jul 21 08:33:38.534262 2026] [security2:error] [pid 466512:tid 466567] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/waf.php"] [unique_id "al9ZEiKGokixMSfKDOfbAAACGjY"]
[Tue Jul 21 08:33:38.553277 2026] [security2:error] [pid 466512:tid 466716] [client 20.197.192.193:43786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/xxx.php"] [unique_id "al9ZEiKGokixMSfKDOfbAgAAAl4"]
[Tue Jul 21 08:33:38.562545 2026] [security2:error] [pid 466512:tid 466668] [client 20.206.105.145:25101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9ZEiKGokixMSfKDOfbBAAAAi4"]
[Tue Jul 21 08:33:38.679497 2026] [security2:error] [pid 466512:tid 466735] [client 74.249.245.134:47372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/xda.php"] [unique_id "al9ZEiKGokixMSfKDOfbDQAAAnE"]
[Tue Jul 21 08:33:38.958632 2026] [security2:error] [pid 466512:tid 466671] [client 117.213.202.34:49520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZEiKGokixMSfKDOfbDgAAAjE"]
[Tue Jul 21 08:33:38.958764 2026] [security2:error] [pid 466512:tid 466671] [client 117.213.202.34:49520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZEiKGokixMSfKDOfbDgAAAjE"]
[Tue Jul 21 08:33:39.128601 2026] [security2:error] [pid 466512:tid 466585] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/xstelth.php"] [unique_id "al9ZEyKGokixMSfKDOfbFQACQkg"]
[Tue Jul 21 08:33:39.168669 2026] [security2:error] [pid 466512:tid 466560] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-links.php"] [unique_id "al9ZEyKGokixMSfKDOfbFwACPS8"]
[Tue Jul 21 08:33:39.205329 2026] [security2:error] [pid 465652:tid 465863] [client 213.152.186.163:46656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9ZEzzTqJoBC2Mw28-3yAAAANY"]
[Tue Jul 21 08:33:39.205456 2026] [security2:error] [pid 465652:tid 465863] [client 213.152.186.163:46656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9ZEzzTqJoBC2Mw28-3yAAAANY"]
[Tue Jul 21 08:33:39.212724 2026] [security2:error] [pid 466512:tid 466516] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9ZEyKGokixMSfKDOfbGQACIQM"]
[Tue Jul 21 08:33:39.217342 2026] [security2:error] [pid 466512:tid 466657] [client 20.197.195.24:6659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/gecko.php"] [unique_id "al9ZEyKGokixMSfKDOfbGgAAAiM"]
[Tue Jul 21 08:33:39.231751 2026] [security2:error] [pid 465652:tid 465791] [client 223.181.60.88:30121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZEzzTqJoBC2Mw28-3ygAAAI4"]
[Tue Jul 21 08:33:39.232108 2026] [security2:error] [pid 465652:tid 465791] [client 223.181.60.88:30121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZEzzTqJoBC2Mw28-3ygAAAI4"]
[Tue Jul 21 08:33:39.259150 2026] [security2:error] [pid 466512:tid 466751] [client 74.249.245.134:54953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/article.php"] [unique_id "al9ZEyKGokixMSfKDOfbHgAAAoE"]
[Tue Jul 21 08:33:39.269089 2026] [security2:error] [pid 466512:tid 466601] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oportunity.serri.com.br"] [uri "/aaa.php"] [unique_id "al9ZEyKGokixMSfKDOfbIAACKFg"]
[Tue Jul 21 08:33:39.272271 2026] [security2:error] [pid 465652:tid 465857] [client 122.176.100.127:56531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZEzzTqJoBC2Mw28-3zQAAANA"]
[Tue Jul 21 08:33:39.272439 2026] [security2:error] [pid 465652:tid 465857] [client 122.176.100.127:56531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZEzzTqJoBC2Mw28-3zQAAANA"]
[Tue Jul 21 08:33:39.339598 2026] [security2:error] [pid 466512:tid 466698] [client 4.194.24.143:8910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/abcd.php"] [unique_id "al9ZEyKGokixMSfKDOfbJQAAAkw"]
[Tue Jul 21 08:33:39.384331 2026] [security2:error] [pid 466512:tid 466763] [client 20.197.192.193:65200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/hunter.php"] [unique_id "al9ZEyKGokixMSfKDOfbJgAAAo0"]
[Tue Jul 21 08:33:39.442498 2026] [security2:error] [pid 466512:tid 466673] [client 20.197.195.24:53514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/for.php"] [unique_id "al9ZEyKGokixMSfKDOfbJwAAAjM"]
[Tue Jul 21 08:33:39.508442 2026] [security2:error] [pid 466512:tid 466730] [client 20.104.96.117:62698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/sixxis.php"] [unique_id "al9ZEyKGokixMSfKDOfbKAAAAmw"]
[Tue Jul 21 08:33:39.671451 2026] [security2:error] [pid 465652:tid 465893] [client 103.255.105.130:39940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZEzzTqJoBC2Mw28-31QAAAPQ"]
[Tue Jul 21 08:33:39.671568 2026] [security2:error] [pid 465652:tid 465893] [client 103.255.105.130:39940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZEzzTqJoBC2Mw28-31QAAAPQ"]
[Tue Jul 21 08:33:39.891930 2026] [security2:error] [pid 465652:tid 465859] [client 20.197.195.24:6758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/82.php"] [unique_id "al9ZEzzTqJoBC2Mw28-33AAAANI"]
[Tue Jul 21 08:33:40.238561 2026] [security2:error] [pid 465652:tid 465844] [client 20.197.195.24:6736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/admin.php"] [unique_id "al9ZFDzTqJoBC2Mw28-34wAAAMM"]
[Tue Jul 21 08:33:40.405401 2026] [security2:error] [pid 466512:tid 466725] [client 4.194.24.143:8944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/about.php"] [unique_id "al9ZFCKGokixMSfKDOfbNQAAAmc"]
[Tue Jul 21 08:33:40.407281 2026] [security2:error] [pid 466512:tid 466714] [client 74.249.245.134:55274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/shell.php"] [unique_id "al9ZFCKGokixMSfKDOfbNgAAAlw"]
[Tue Jul 21 08:33:40.453606 2026] [security2:error] [pid 466512:tid 466671] [client 20.104.96.117:62691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/ip.php"] [unique_id "al9ZFCKGokixMSfKDOfbNwAAAjE"]
[Tue Jul 21 08:33:40.495589 2026] [security2:error] [pid 466512:tid 466632] [remote 38.242.157.30:33234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nutrawidenews.com"] [uri "/wp-login.php"] [unique_id "al9ZFCKGokixMSfKDOfbOwACjnc"]
[Tue Jul 21 08:33:40.655934 2026] [security2:error] [pid 465652:tid 465899] [client 20.220.225.223:20873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9ZFDzTqJoBC2Mw28-36wAAAPo"]
[Tue Jul 21 08:33:40.971966 2026] [security2:error] [pid 466512:tid 466691] [client 20.197.195.24:15703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bastarecomecar.com.br"] [uri "/raw.php"] [unique_id "al9ZFCKGokixMSfKDOfbQgAAAkU"]
[Tue Jul 21 08:33:41.306542 2026] [security2:error] [pid 466512:tid 466750] [client 195.49.128.211:51748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZFSKGokixMSfKDOfbRwAAAoA"]
[Tue Jul 21 08:33:41.306750 2026] [security2:error] [pid 466512:tid 466750] [client 195.49.128.211:51748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZFSKGokixMSfKDOfbRwAAAoA"]
[Tue Jul 21 08:33:41.358439 2026] [security2:error] [pid 466512:tid 466702] [client 20.220.225.223:50895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/pn.php"] [unique_id "al9ZFSKGokixMSfKDOfbSQAAAlA"]
[Tue Jul 21 08:33:41.431706 2026] [security2:error] [pid 465652:tid 465892] [client 103.151.46.103:64699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZFTzTqJoBC2Mw28-39gAAAPM"]
[Tue Jul 21 08:33:41.431824 2026] [security2:error] [pid 465652:tid 465892] [client 103.151.46.103:64699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZFTzTqJoBC2Mw28-39gAAAPM"]
[Tue Jul 21 08:33:41.435836 2026] [security2:error] [pid 465652:tid 465816] [client 4.194.24.143:5785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp-info.php"] [unique_id "al9ZFTzTqJoBC2Mw28-39wAAAKc"]
[Tue Jul 21 08:33:41.463534 2026] [security2:error] [pid 466512:tid 466647] [client 152.59.181.104:61559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZFSKGokixMSfKDOfbSgAAAhk"]
[Tue Jul 21 08:33:41.463625 2026] [security2:error] [pid 466512:tid 466647] [client 152.59.181.104:61559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZFSKGokixMSfKDOfbSgAAAhk"]
[Tue Jul 21 08:33:41.548396 2026] [security2:error] [pid 465652:tid 465674] [remote 152.53.111.131:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/wp-login.php"] [unique_id "al9ZFTzTqJoBC2Mw28-3-AAAxRU"]
[Tue Jul 21 08:33:41.571317 2026] [security2:error] [pid 465652:tid 465829] [client 49.144.66.253:31036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZFTzTqJoBC2Mw28-3-QAAALQ"]
[Tue Jul 21 08:33:41.571443 2026] [security2:error] [pid 465652:tid 465829] [client 49.144.66.253:31036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZFTzTqJoBC2Mw28-3-QAAALQ"]
[Tue Jul 21 08:33:41.654660 2026] [security2:error] [pid 466512:tid 466767] [client 20.104.96.117:46464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/kq1.php"] [unique_id "al9ZFSKGokixMSfKDOfbTQAAApE"]
[Tue Jul 21 08:33:41.874375 2026] [security2:error] [pid 466512:tid 466680] [client 20.197.195.24:6779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/adminner.php"] [unique_id "al9ZFSKGokixMSfKDOfbUgAAAjo"]
[Tue Jul 21 08:33:42.176178 2026] [security2:error] [pid 466512:tid 466756] [client 5.38.115.39:6389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZFiKGokixMSfKDOfbVQAAAoY"]
[Tue Jul 21 08:33:42.176288 2026] [security2:error] [pid 466512:tid 466756] [client 5.38.115.39:6389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZFiKGokixMSfKDOfbVQAAAoY"]
[Tue Jul 21 08:33:42.296337 2026] [security2:error] [pid 465652:tid 465894] [client 20.104.96.117:46478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9ZFjzTqJoBC2Mw28-4BAAAAPU"]
[Tue Jul 21 08:33:42.403091 2026] [security2:error] [pid 465652:tid 465870] [client 187.125.243.197:52623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZFjzTqJoBC2Mw28-4BgAAAN0"]
[Tue Jul 21 08:33:42.403232 2026] [security2:error] [pid 465652:tid 465870] [client 187.125.243.197:52623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZFjzTqJoBC2Mw28-4BgAAAN0"]
[Tue Jul 21 08:33:42.789730 2026] [security2:error] [pid 466512:tid 466599] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZFiKGokixMSfKDOfbYAACT1Y"]
[Tue Jul 21 08:33:42.789871 2026] [security2:error] [pid 466512:tid 466701] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZFiKGokixMSfKDOfbYAACT1Y"]
[Tue Jul 21 08:33:42.825007 2026] [security2:error] [pid 466512:tid 466728] [client 4.194.24.143:8916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp-links-opml.php"] [unique_id "al9ZFiKGokixMSfKDOfbYQAAAmo"]
[Tue Jul 21 08:33:42.852092 2026] [security2:error] [pid 466512:tid 466570] [remote 124.55.178.99:51412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9ZFiKGokixMSfKDOfbZAACNjk"]
[Tue Jul 21 08:33:42.973373 2026] [security2:error] [pid 465652:tid 465818] [client 20.197.195.24:6686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/admin.php"] [unique_id "al9ZFjzTqJoBC2Mw28-4FAAAAKk"]
[Tue Jul 21 08:33:43.071697 2026] [security2:error] [pid 466512:tid 466691] [client 14.245.224.124:59321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZFyKGokixMSfKDOfbZwAAAkU"]
[Tue Jul 21 08:33:43.071821 2026] [security2:error] [pid 466512:tid 466691] [client 14.245.224.124:59321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZFyKGokixMSfKDOfbZwAAAkU"]
[Tue Jul 21 08:33:43.118182 2026] [security2:error] [pid 465652:tid 465805] [client 74.249.245.134:41810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/3.php"] [unique_id "al9ZFzzTqJoBC2Mw28-4FwAAAJw"]
[Tue Jul 21 08:33:43.119210 2026] [security2:error] [pid 465652:tid 465790] [client 20.104.96.117:46539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/h02ugyh.php"] [unique_id "al9ZFzzTqJoBC2Mw28-4GAAAAI0"]
[Tue Jul 21 08:33:43.119382 2026] [security2:error] [pid 466512:tid 466682] [client 152.59.34.51:62030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZFyKGokixMSfKDOfbaQAAAjw"]
[Tue Jul 21 08:33:43.119465 2026] [security2:error] [pid 466512:tid 466682] [client 152.59.34.51:62030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZFyKGokixMSfKDOfbaQAAAjw"]
[Tue Jul 21 08:33:43.623688 2026] [security2:error] [pid 465652:tid 465845] [client 61.1.167.83:58536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZFzzTqJoBC2Mw28-4NwAAAMQ"]
[Tue Jul 21 08:33:43.623786 2026] [security2:error] [pid 465652:tid 465845] [client 61.1.167.83:58536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZFzzTqJoBC2Mw28-4NwAAAMQ"]
[Tue Jul 21 08:33:43.793760 2026] [security2:error] [pid 466512:tid 466646] [client 20.197.195.24:6726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/k.php"] [unique_id "al9ZFyKGokixMSfKDOfbdgAAAhg"]
[Tue Jul 21 08:33:43.885353 2026] [security2:error] [pid 465652:tid 465794] [client 20.206.105.145:25579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/adminfuns.php"] [unique_id "al9ZFzzTqJoBC2Mw28-4RAAAAJE"]
[Tue Jul 21 08:33:43.896517 2026] [security2:error] [pid 466512:tid 466734] [client 4.194.24.143:8933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp-links.php"] [unique_id "al9ZFyKGokixMSfKDOfbdwAAAnA"]
[Tue Jul 21 08:33:44.171798 2026] [security2:error] [pid 466512:tid 466764] [client 74.249.245.134:55532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/bootstrap.php"] [unique_id "al9ZGCKGokixMSfKDOfbeAAAAo4"]
[Tue Jul 21 08:33:44.220544 2026] [security2:error] [pid 465652:tid 465807] [client 20.197.195.24:6671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/blurbs.php"] [unique_id "al9ZGDzTqJoBC2Mw28-4TAAAAJ4"]
[Tue Jul 21 08:33:44.284065 2026] [core:error] [pid 465652:tid 465756] [remote 52.167.144.173:17877] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:44.284095 2026] [core:error] [pid 465652:tid 465756] [remote 52.167.144.173:17877] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:44.284986 2026] [security2:error] [pid 465652:tid 465817] [client 20.104.96.117:46521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-temp.php"] [unique_id "al9ZGDzTqJoBC2Mw28-4UAAAAKg"]
[Tue Jul 21 08:33:44.445031 2026] [security2:error] [pid 465652:tid 465891] [client 20.197.195.24:6776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/bajah.php"] [unique_id "al9ZGDzTqJoBC2Mw28-4WgAAAPI"]
[Tue Jul 21 08:33:44.528369 2026] [security2:error] [pid 465652:tid 465832] [client 20.197.195.24:6687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/a.php"] [unique_id "al9ZGDzTqJoBC2Mw28-4WwAAALc"]
[Tue Jul 21 08:33:44.544464 2026] [security2:error] [pid 465652:tid 465899] [client 20.197.195.24:56260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/edit.php"] [unique_id "al9ZGDzTqJoBC2Mw28-4XAAAAPo"]
[Tue Jul 21 08:33:44.628836 2026] [security2:error] [pid 466512:tid 466662] [client 20.104.96.117:46589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9ZGCKGokixMSfKDOfbgAAAAig"]
[Tue Jul 21 08:33:44.681673 2026] [security2:error] [pid 466512:tid 466768] [client 20.220.225.223:20912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9ZGCKGokixMSfKDOfbgQAAApI"]
[Tue Jul 21 08:33:44.757828 2026] [security2:error] [pid 466512:tid 466701] [client 20.197.195.24:6689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/hosty.php"] [unique_id "al9ZGCKGokixMSfKDOfbhAAAAk8"]
[Tue Jul 21 08:33:44.838527 2026] [security2:error] [pid 466512:tid 466684] [client 74.7.230.19:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "enosarneiro1751472729000.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9ZGCKGokixMSfKDOfbhwACPgc"]
[Tue Jul 21 08:33:44.941141 2026] [security2:error] [pid 466512:tid 466747] [client 4.194.24.143:8917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp-load.php"] [unique_id "al9ZGCKGokixMSfKDOfbigAAAn0"]
[Tue Jul 21 08:33:45.004033 2026] [core:error] [pid 465652:tid 465744] [remote 52.167.144.173:17877] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:45.004058 2026] [core:error] [pid 465652:tid 465744] [remote 52.167.144.173:17877] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:45.038617 2026] [security2:error] [pid 466512:tid 466755] [client 20.197.195.24:6675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/k.php"] [unique_id "al9ZGSKGokixMSfKDOfbiwAAAoU"]
[Tue Jul 21 08:33:45.117469 2026] [security2:error] [pid 466512:tid 466597] [remote 45.3.35.90:44917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.35.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9ZGSKGokixMSfKDOfbjQACS1Q"]
[Tue Jul 21 08:33:45.152014 2026] [security2:error] [pid 465652:tid 465808] [client 20.197.195.24:6768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/aaa.php"] [unique_id "al9ZGTzTqJoBC2Mw28-4agAAAJ8"]
[Tue Jul 21 08:33:45.156093 2026] [security2:error] [pid 466512:tid 466643] [client 20.220.225.223:50272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/wp-wpbak.php"] [unique_id "al9ZGSKGokixMSfKDOfbjgAAAhU"]
[Tue Jul 21 08:33:45.242418 2026] [security2:error] [pid 466512:tid 466754] [client 20.197.195.24:6685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/file5.php"] [unique_id "al9ZGSKGokixMSfKDOfbkAAAAoQ"]
[Tue Jul 21 08:33:45.296425 2026] [security2:error] [pid 465652:tid 465831] [client 91.148.245.81:45160] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/"] [unique_id "al9ZGTzTqJoBC2Mw28-4bQAAALY"]
[Tue Jul 21 08:33:45.297296 2026] [security2:error] [pid 466512:tid 466647] [client 91.148.245.81:45166] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/"] [unique_id "al9ZGSKGokixMSfKDOfbkgAAAhk"]
[Tue Jul 21 08:33:45.297800 2026] [security2:error] [pid 466512:tid 466695] [client 91.148.245.81:45168] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/"] [unique_id "al9ZGSKGokixMSfKDOfbkwAAAkk"]
[Tue Jul 21 08:33:45.307440 2026] [security2:error] [pid 466512:tid 466686] [client 81.171.74.60:42732] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/"] [unique_id "al9ZGSKGokixMSfKDOfblAAAAkA"]
[Tue Jul 21 08:33:45.440689 2026] [security2:error] [pid 466512:tid 466769] [client 20.197.195.24:6664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/222.php"] [unique_id "al9ZGSKGokixMSfKDOfblQAAApM"]
[Tue Jul 21 08:33:45.705366 2026] [security2:error] [pid 466512:tid 466764] [client 20.197.195.24:6765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/test.php"] [unique_id "al9ZGSKGokixMSfKDOfblwAAAo4"]
[Tue Jul 21 08:33:45.720613 2026] [security2:error] [pid 465652:tid 465815] [client 202.179.75.202:39124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZGTzTqJoBC2Mw28-4cwAAAKY"]
[Tue Jul 21 08:33:45.720729 2026] [security2:error] [pid 465652:tid 465815] [client 202.179.75.202:39124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZGTzTqJoBC2Mw28-4cwAAAKY"]
[Tue Jul 21 08:33:46.164147 2026] [security2:error] [pid 466512:tid 466665] [client 20.104.96.117:46575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9ZGiKGokixMSfKDOfbowAAAis"]
[Tue Jul 21 08:33:46.173539 2026] [security2:error] [pid 465652:tid 465785] [client 4.194.24.143:61018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp-login.php"] [unique_id "al9ZGjzTqJoBC2Mw28-4eQAAAIg"]
[Tue Jul 21 08:33:46.366982 2026] [security2:error] [pid 466512:tid 466726] [client 20.197.195.24:56262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/aaa.php"] [unique_id "al9ZGiKGokixMSfKDOfbqAAAAmg"]
[Tue Jul 21 08:33:46.430771 2026] [security2:error] [pid 465652:tid 465894] [client 81.171.74.60:42748] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/.git/HEAD"] [unique_id "al9ZGjzTqJoBC2Mw28-4gAAAAPU"]
[Tue Jul 21 08:33:46.431314 2026] [security2:error] [pid 466512:tid 466662] [client 81.171.74.60:42760] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9ZGiKGokixMSfKDOfbqwAAAig"]
[Tue Jul 21 08:33:46.432912 2026] [security2:error] [pid 466512:tid 466768] [client 81.171.74.60:42750] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9ZGiKGokixMSfKDOfbrAAAApI"]
[Tue Jul 21 08:33:46.433155 2026] [security2:error] [pid 466512:tid 466762] [client 81.171.74.60:42764] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/user_secrets.yml"] [unique_id "al9ZGiKGokixMSfKDOfbrQAAAow"]
[Tue Jul 21 08:33:46.441603 2026] [security2:error] [pid 466512:tid 466670] [client 91.148.245.81:45174] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9ZGiKGokixMSfKDOfbrgAAAjA"]
[Tue Jul 21 08:33:46.444548 2026] [security2:error] [pid 466512:tid 466685] [client 20.220.225.223:50298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/dr.php"] [unique_id "al9ZGiKGokixMSfKDOfbrwAAAj8"]
[Tue Jul 21 08:33:46.447012 2026] [security2:error] [pid 466512:tid 466728] [client 91.148.245.81:45208] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/user_secrets.yml"] [unique_id "al9ZGiKGokixMSfKDOfbsAAAAmo"]
[Tue Jul 21 08:33:46.447184 2026] [security2:error] [pid 466512:tid 466722] [client 91.148.245.81:45194] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9ZGiKGokixMSfKDOfbsQAAAmQ"]
[Tue Jul 21 08:33:46.448680 2026] [security2:error] [pid 466512:tid 466676] [client 91.148.245.81:45188] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/database_backup.sql"] [unique_id "al9ZGiKGokixMSfKDOfbsgAAAjY"]
[Tue Jul 21 08:33:46.482413 2026] [security2:error] [pid 465652:tid 465841] [client 20.197.192.193:65161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/we.php"] [unique_id "al9ZGjzTqJoBC2Mw28-4gQAAAMA"]
[Tue Jul 21 08:33:46.483469 2026] [security2:error] [pid 465652:tid 465854] [client 20.151.10.161:65478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9ZGjzTqJoBC2Mw28-4ggAAAM0"]
[Tue Jul 21 08:33:46.615282 2026] [security2:error] [pid 465652:tid 465880] [client 20.104.96.117:62688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/jj.php"] [unique_id "al9ZGjzTqJoBC2Mw28-4hAAAAOc"]
[Tue Jul 21 08:33:46.858750 2026] [security2:error] [pid 465652:tid 465690] [remote 173.252.87.34:47300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9ZGjzTqJoBC2Mw28-4iAAAoyU"]
[Tue Jul 21 08:33:47.085777 2026] [security2:error] [pid 466512:tid 466720] [client 20.197.192.193:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "promotrend.com.br"] [uri "/phpinfo.php1"] [unique_id "al9ZGyKGokixMSfKDOfbugAAAmI"]
[Tue Jul 21 08:33:47.204758 2026] [security2:error] [pid 466512:tid 466699] [client 20.104.96.117:46489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9ZGyKGokixMSfKDOfbvAAAAk0"]
[Tue Jul 21 08:33:47.229863 2026] [security2:error] [pid 466512:tid 466739] [client 4.194.24.143:8854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp-mail.php"] [unique_id "al9ZGyKGokixMSfKDOfbvQAAAnU"]
[Tue Jul 21 08:33:47.236319 2026] [security2:error] [pid 466512:tid 466688] [client 20.197.195.24:6713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/11.php"] [unique_id "al9ZGyKGokixMSfKDOfbvgAAAkI"]
[Tue Jul 21 08:33:47.303666 2026] [security2:error] [pid 466512:tid 466716] [client 109.248.148.246:56898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9ZGyKGokixMSfKDOfbwAAAAl4"]
[Tue Jul 21 08:33:47.303891 2026] [security2:error] [pid 466512:tid 466716] [client 109.248.148.246:56898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9ZGyKGokixMSfKDOfbwAAAAl4"]
[Tue Jul 21 08:33:47.410992 2026] [security2:error] [pid 465652:tid 465819] [client 91.148.245.81:45244] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/.env"] [unique_id "al9ZGzzTqJoBC2Mw28-4kgAAAKo"]
[Tue Jul 21 08:33:47.413231 2026] [security2:error] [pid 466512:tid 466700] [client 91.148.245.81:45234] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9ZGyKGokixMSfKDOfbwQAAAk4"]
[Tue Jul 21 08:33:47.413434 2026] [security2:error] [pid 465652:tid 465855] [client 91.148.245.81:45210] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/config.php"] [unique_id "al9ZGzzTqJoBC2Mw28-4kwAAAM4"]
[Tue Jul 21 08:33:47.413542 2026] [security2:error] [pid 466512:tid 466653] [client 91.148.245.81:45218] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9ZGyKGokixMSfKDOfbwgAAAh8"]
[Tue Jul 21 08:33:47.416659 2026] [security2:error] [pid 466512:tid 466725] [client 20.151.10.161:65441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9ZGyKGokixMSfKDOfbwwAAAmc"]
[Tue Jul 21 08:33:47.521354 2026] [security2:error] [pid 465652:tid 465821] [client 20.104.96.117:46502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/txets.php"] [unique_id "al9ZGzzTqJoBC2Mw28-4lwAAAKw"]
[Tue Jul 21 08:33:47.627620 2026] [security2:error] [pid 466512:tid 466705] [client 195.49.128.211:60292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZGyKGokixMSfKDOfbxAAAAlM"]
[Tue Jul 21 08:33:47.627787 2026] [security2:error] [pid 466512:tid 466705] [client 195.49.128.211:60292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZGyKGokixMSfKDOfbxAAAAlM"]
[Tue Jul 21 08:33:47.947539 2026] [security2:error] [pid 466512:tid 466763] [client 20.206.105.145:25577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/goods.php"] [unique_id "al9ZGyKGokixMSfKDOfbyAAAAo0"]
[Tue Jul 21 08:33:48.002301 2026] [security2:error] [pid 466512:tid 466666] [client 20.151.10.161:65516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/media.php"] [unique_id "al9ZHCKGokixMSfKDOfbyQAAAiw"]
[Tue Jul 21 08:33:48.134061 2026] [security2:error] [pid 466512:tid 466747] [client 74.249.245.134:55531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/config-backup.php"] [unique_id "al9ZHCKGokixMSfKDOfbzAAAAn0"]
[Tue Jul 21 08:33:48.141094 2026] [security2:error] [pid 466512:tid 466702] [client 20.104.96.117:46580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/dex.php"] [unique_id "al9ZHCKGokixMSfKDOfbzQAAAlA"]
[Tue Jul 21 08:33:48.282095 2026] [security2:error] [pid 466512:tid 466704] [client 4.194.24.143:64771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp-signin.php"] [unique_id "al9ZHCKGokixMSfKDOfbzgAAAlI"]
[Tue Jul 21 08:33:48.385944 2026] [security2:error] [pid 466512:tid 466662] [client 91.148.245.81:45274] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/phpinfo.php"] [unique_id "al9ZHCKGokixMSfKDOfb0AAAAig"]
[Tue Jul 21 08:33:48.387069 2026] [security2:error] [pid 465652:tid 465816] [client 91.148.245.81:45268] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/api/.env"] [unique_id "al9ZHDzTqJoBC2Mw28-4ogAAAKc"]
[Tue Jul 21 08:33:48.388079 2026] [security2:error] [pid 466512:tid 466768] [client 91.148.245.81:45278] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/backup.sql"] [unique_id "al9ZHCKGokixMSfKDOfb0QAAApI"]
[Tue Jul 21 08:33:48.388365 2026] [security2:error] [pid 466512:tid 466762] [client 91.148.245.81:45280] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/.git/HEAD"] [unique_id "al9ZHCKGokixMSfKDOfb0gAAAow"]
[Tue Jul 21 08:33:48.405026 2026] [security2:error] [pid 465652:tid 465783] [client 20.197.195.24:6749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/mac.php"] [unique_id "al9ZHDzTqJoBC2Mw28-4pAAAAIY"]
[Tue Jul 21 08:33:48.571092 2026] [security2:error] [pid 466512:tid 466707] [client 20.151.10.161:65499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/images.php"] [unique_id "al9ZHCKGokixMSfKDOfb1AAAAlU"]
[Tue Jul 21 08:33:48.589027 2026] [security2:error] [pid 466512:tid 466685] [client 91.148.245.81:45290] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/dump.sql"] [unique_id "al9ZHCKGokixMSfKDOfb1QAAAj8"]
[Tue Jul 21 08:33:48.591864 2026] [security2:error] [pid 466512:tid 466670] [client 91.148.245.81:45252] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/docker-compose.yml"] [unique_id "al9ZHCKGokixMSfKDOfb1gAAAjA"]
[Tue Jul 21 08:33:48.672114 2026] [security2:error] [pid 466512:tid 466767] [client 20.104.96.117:46481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/xpwer1.php"] [unique_id "al9ZHCKGokixMSfKDOfb2wAAApE"]
[Tue Jul 21 08:33:48.690756 2026] [core:error] [pid 466512:tid 466607] [remote 52.167.144.204:3566] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:48.690779 2026] [core:error] [pid 466512:tid 466607] [remote 52.167.144.204:3566] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:48.817338 2026] [core:error] [pid 466512:tid 466565] [remote 52.167.144.204:3566] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:48.817358 2026] [core:error] [pid 466512:tid 466565] [remote 52.167.144.204:3566] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:48.860071 2026] [security2:error] [pid 466512:tid 466755] [client 223.181.60.88:11332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZHCKGokixMSfKDOfb3gAAAoU"]
[Tue Jul 21 08:33:48.860195 2026] [security2:error] [pid 466512:tid 466755] [client 223.181.60.88:11332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZHCKGokixMSfKDOfb3gAAAoU"]
[Tue Jul 21 08:33:48.873041 2026] [security2:error] [pid 466512:tid 466721] [client 20.151.10.161:65471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/adminner.php"] [unique_id "al9ZHCKGokixMSfKDOfb3wAAAmM"]
[Tue Jul 21 08:33:48.944108 2026] [security2:error] [pid 466512:tid 466740] [client 20.220.225.223:20905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/dp.php"] [unique_id "al9ZHCKGokixMSfKDOfb5AAAAnY"]
[Tue Jul 21 08:33:49.184831 2026] [security2:error] [pid 466512:tid 466666] [client 20.104.96.117:46512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/flox.php"] [unique_id "al9ZHSKGokixMSfKDOfb5wAAAiw"]
[Tue Jul 21 08:33:49.322146 2026] [security2:error] [pid 465652:tid 465883] [client 20.151.10.161:65520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/admin.php"] [unique_id "al9ZHTzTqJoBC2Mw28-4tQAAAOo"]
[Tue Jul 21 08:33:49.329323 2026] [security2:error] [pid 465652:tid 465882] [client 4.194.24.143:8566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp-sigunq.php"] [unique_id "al9ZHTzTqJoBC2Mw28-4tgAAAOk"]
[Tue Jul 21 08:33:49.358033 2026] [security2:error] [pid 466512:tid 466709] [client 91.148.245.81:45336] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9ZHSKGokixMSfKDOfb6QAAAlc"]
[Tue Jul 21 08:33:49.358033 2026] [security2:error] [pid 465652:tid 465841] [client 91.148.245.81:45324] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/actuator/heapdump"] [unique_id "al9ZHTzTqJoBC2Mw28-4twAAAMA"]
[Tue Jul 21 08:33:49.359995 2026] [security2:error] [pid 466512:tid 466763] [client 91.148.245.81:45292] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/backup.tar.gz"] [unique_id "al9ZHSKGokixMSfKDOfb6gAAAo0"]
[Tue Jul 21 08:33:49.360789 2026] [security2:error] [pid 466512:tid 466684] [client 91.148.245.81:45334] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/.svn/wc.db"] [unique_id "al9ZHSKGokixMSfKDOfb6wAAAj4"]
[Tue Jul 21 08:33:49.439914 2026] [security2:error] [pid 466512:tid 466697] [client 20.197.195.24:56311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/chosen.php"] [unique_id "al9ZHSKGokixMSfKDOfb7wAAAks"]
[Tue Jul 21 08:33:49.561644 2026] [security2:error] [pid 466512:tid 466673] [client 91.148.245.81:45302] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/database.sql"] [unique_id "al9ZHSKGokixMSfKDOfb8gAAAjM"]
[Tue Jul 21 08:33:49.561724 2026] [security2:error] [pid 466512:tid 466726] [client 91.148.245.81:45346] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/wp-config.php"] [unique_id "al9ZHSKGokixMSfKDOfb8QAAAmg"]
[Tue Jul 21 08:33:49.562662 2026] [security2:error] [pid 466512:tid 466727] [client 91.148.245.81:45316] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9ZHSKGokixMSfKDOfb8wAAAmk"]
[Tue Jul 21 08:33:49.668115 2026] [security2:error] [pid 465652:tid 465801] [client 20.151.10.161:65438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/k.php"] [unique_id "al9ZHTzTqJoBC2Mw28-4wgAAAJg"]
[Tue Jul 21 08:33:49.698512 2026] [security2:error] [pid 465652:tid 465855] [client 20.104.96.117:62619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/popo.php"] [unique_id "al9ZHTzTqJoBC2Mw28-4wwAAAM4"]
[Tue Jul 21 08:33:49.735903 2026] [security2:error] [pid 466512:tid 466718] [client 122.176.100.127:57035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZHSKGokixMSfKDOfb9AAAAmA"]
[Tue Jul 21 08:33:49.736026 2026] [security2:error] [pid 466512:tid 466718] [client 122.176.100.127:57035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZHSKGokixMSfKDOfb9AAAAmA"]
[Tue Jul 21 08:33:49.987857 2026] [security2:error] [pid 466512:tid 466664] [client 20.151.10.161:65417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/x.php"] [unique_id "al9ZHSKGokixMSfKDOfb9QAAAio"]
[Tue Jul 21 08:33:50.232764 2026] [security2:error] [pid 466512:tid 466653] [client 109.248.148.246:44054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9ZHiKGokixMSfKDOfb_wAAAh8"]
[Tue Jul 21 08:33:50.232870 2026] [security2:error] [pid 466512:tid 466653] [client 109.248.148.246:44054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9ZHiKGokixMSfKDOfb_wAAAh8"]
[Tue Jul 21 08:33:50.263875 2026] [security2:error] [pid 466512:tid 466725] [client 20.151.10.161:65502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wss.php"] [unique_id "al9ZHiKGokixMSfKDOfcAAAAAmc"]
[Tue Jul 21 08:33:50.280796 2026] [security2:error] [pid 465652:tid 465818] [client 111.93.58.162:55158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.58.93.111.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZHjzTqJoBC2Mw28-4zAAAAKk"]
[Tue Jul 21 08:33:50.281092 2026] [security2:error] [pid 465652:tid 465818] [client 111.93.58.162:55158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZHjzTqJoBC2Mw28-4zAAAAKk"]
[Tue Jul 21 08:33:50.353535 2026] [security2:error] [pid 465652:tid 465844] [client 4.194.24.143:8540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp-the.php"] [unique_id "al9ZHjzTqJoBC2Mw28-4zwAAAMM"]
[Tue Jul 21 08:33:50.496367 2026] [security2:error] [pid 465652:tid 465877] [client 91.148.245.81:45386] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/config/production.json"] [unique_id "al9ZHjzTqJoBC2Mw28-40AAAAOQ"]
[Tue Jul 21 08:33:50.498350 2026] [security2:error] [pid 465652:tid 465858] [client 91.148.245.81:45402] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/.env.production"] [unique_id "al9ZHjzTqJoBC2Mw28-40QAAANE"]
[Tue Jul 21 08:33:50.499312 2026] [security2:error] [pid 466512:tid 466649] [client 91.148.245.81:45396] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/backup.zip"] [unique_id "al9ZHiKGokixMSfKDOfcBAAAAhs"]
[Tue Jul 21 08:33:50.499567 2026] [security2:error] [pid 466512:tid 466740] [client 91.148.245.81:45418] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9ZHiKGokixMSfKDOfcAwAAAnY"]
[Tue Jul 21 08:33:50.565641 2026] [security2:error] [pid 466512:tid 466674] [client 20.151.10.161:63683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/ty.php"] [unique_id "al9ZHiKGokixMSfKDOfcBQAAAjQ"]
[Tue Jul 21 08:33:50.637321 2026] [security2:error] [pid 466512:tid 466709] [client 20.104.96.117:46491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/yas.php"] [unique_id "al9ZHiKGokixMSfKDOfcDQAAAlc"]
[Tue Jul 21 08:33:50.674039 2026] [security2:error] [pid 466512:tid 466684] [client 20.206.105.145:25481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/ms-edit.php"] [unique_id "al9ZHiKGokixMSfKDOfcDgAAAj4"]
[Tue Jul 21 08:33:50.700117 2026] [security2:error] [pid 466512:tid 466700] [client 91.148.245.81:45388] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/server.key"] [unique_id "al9ZHiKGokixMSfKDOfcDwAAAk4"]
[Tue Jul 21 08:33:50.702451 2026] [security2:error] [pid 466512:tid 466692] [client 91.148.245.81:45360] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9ZHiKGokixMSfKDOfcEQAAAkY"]
[Tue Jul 21 08:33:50.702543 2026] [security2:error] [pid 466512:tid 466668] [client 91.148.245.81:45374] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/secrets.json"] [unique_id "al9ZHiKGokixMSfKDOfcEAAAAi4"]
[Tue Jul 21 08:33:50.705783 2026] [security2:error] [pid 465652:tid 465811] [client 117.213.202.34:50144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZHTzTqJoBC2Mw28-4xAAAAKI"]
[Tue Jul 21 08:33:50.705905 2026] [security2:error] [pid 465652:tid 465811] [client 117.213.202.34:50144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZHTzTqJoBC2Mw28-4xAAAAKI"]
[Tue Jul 21 08:33:50.964638 2026] [security2:error] [pid 466512:tid 466765] [client 20.197.195.24:6734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/cream1.php"] [unique_id "al9ZHiKGokixMSfKDOfcFwAAAo8"]
[Tue Jul 21 08:33:50.973516 2026] [security2:error] [pid 466512:tid 466695] [client 20.104.96.117:46471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/file61.php"] [unique_id "al9ZHiKGokixMSfKDOfcGAAAAkk"]
[Tue Jul 21 08:33:51.058365 2026] [security2:error] [pid 465652:tid 465890] [client 74.249.245.134:53079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/mds.php"] [unique_id "al9ZHzzTqJoBC2Mw28-42QAAAPE"]
[Tue Jul 21 08:33:51.108063 2026] [security2:error] [pid 466512:tid 466707] [client 20.151.10.161:65445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/155.php"] [unique_id "al9ZHyKGokixMSfKDOfcGQAAAlU"]
[Tue Jul 21 08:33:51.405664 2026] [security2:error] [pid 466512:tid 466718] [client 4.194.24.143:8532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp-themes.php"] [unique_id "al9ZHyKGokixMSfKDOfcHgAAAmA"]
[Tue Jul 21 08:33:51.474447 2026] [security2:error] [pid 465652:tid 465896] [client 91.148.245.81:45470] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/.npmrc"] [unique_id "al9ZHzzTqJoBC2Mw28-43wAAAPc"]
[Tue Jul 21 08:33:51.475645 2026] [security2:error] [pid 466512:tid 466664] [client 91.148.245.81:45446] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/.bash_history"] [unique_id "al9ZHyKGokixMSfKDOfcIAAAAio"]
[Tue Jul 21 08:33:51.478289 2026] [security2:error] [pid 466512:tid 466696] [client 91.148.245.81:45456] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "inonebrasil.com.br"] [uri "/config.xml"] [unique_id "al9ZHyKGokixMSfKDOfcIQAAAko"]
[Tue Jul 21 08:33:51.607465 2026] [security2:error] [pid 466512:tid 466642] [client 20.104.96.117:46472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/water.php"] [unique_id "al9ZHyKGokixMSfKDOfcIwAAAhQ"]
[Tue Jul 21 08:33:51.671859 2026] [security2:error] [pid 466512:tid 466751] [client 20.151.10.161:65509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/ops.php"] [unique_id "al9ZHyKGokixMSfKDOfcKAAAAoE"]
[Tue Jul 21 08:33:51.882523 2026] [security2:error] [pid 466512:tid 466680] [client 195.49.128.211:52339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZHyKGokixMSfKDOfcKQAAAjo"]
[Tue Jul 21 08:33:51.882673 2026] [security2:error] [pid 466512:tid 466680] [client 195.49.128.211:52339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZHyKGokixMSfKDOfcKQAAAjo"]
[Tue Jul 21 08:33:52.031915 2026] [security2:error] [pid 466512:tid 466655] [client 103.151.46.103:65192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZICKGokixMSfKDOfcKgAAAiE"]
[Tue Jul 21 08:33:52.032071 2026] [security2:error] [pid 466512:tid 466655] [client 103.151.46.103:65192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZICKGokixMSfKDOfcKgAAAiE"]
[Tue Jul 21 08:33:52.062415 2026] [security2:error] [pid 466512:tid 466763] [client 20.206.105.145:25532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/222.php"] [unique_id "al9ZICKGokixMSfKDOfcKwAAAo0"]
[Tue Jul 21 08:33:52.108073 2026] [security2:error] [pid 466512:tid 466766] [client 20.220.225.223:50302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/2x.php"] [unique_id "al9ZICKGokixMSfKDOfcLQAAApA"]
[Tue Jul 21 08:33:52.113062 2026] [authz_core:error] [pid 466512:tid 466684] [client 20.197.195.24:6773] AH01630: client denied by server configuration: /home2/hg4int84/public_html/wp-content/uploads/index.php
[Tue Jul 21 08:33:52.143641 2026] [autoindex:error] [pid 466512:tid 466728] [client 20.197.195.24:6773] AH01276: Cannot serve directory /home2/hg4int84/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:33:52.148572 2026] [security2:error] [pid 466512:tid 466658] [client 20.197.195.24:6773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/dr.php"] [unique_id "al9ZICKGokixMSfKDOfcLwAAAiQ"]
[Tue Jul 21 08:33:52.236539 2026] [security2:error] [pid 465652:tid 465870] [client 74.249.245.134:55495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/goods.php"] [unique_id "al9ZIDzTqJoBC2Mw28-46gAAAN0"]
[Tue Jul 21 08:33:52.261146 2026] [security2:error] [pid 466512:tid 466691] [client 81.171.74.60:42780] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/database_backup.sql"] [unique_id "al9ZICKGokixMSfKDOfcNAAAAkU"]
[Tue Jul 21 08:33:52.261925 2026] [security2:error] [pid 465652:tid 465882] [client 81.171.74.60:42812] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/api/.env"] [unique_id "al9ZIDzTqJoBC2Mw28-46wAAAOk"]
[Tue Jul 21 08:33:52.261925 2026] [security2:error] [pid 466512:tid 466651] [client 81.171.74.60:42802] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/.env"] [unique_id "al9ZICKGokixMSfKDOfcNQAAAh0"]
[Tue Jul 21 08:33:52.262429 2026] [security2:error] [pid 465652:tid 465888] [client 81.171.74.60:42776] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/.env.production"] [unique_id "al9ZIDzTqJoBC2Mw28-47AAAAO8"]
[Tue Jul 21 08:33:52.334838 2026] [security2:error] [pid 466512:tid 466643] [client 109.248.148.246:56154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9ZICKGokixMSfKDOfcNgAAAhU"]
[Tue Jul 21 08:33:52.334973 2026] [security2:error] [pid 466512:tid 466643] [client 109.248.148.246:56154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9ZICKGokixMSfKDOfcNgAAAhU"]
[Tue Jul 21 08:33:52.459030 2026] [security2:error] [pid 466512:tid 466700] [client 4.194.24.143:8555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp-trackback.php"] [unique_id "al9ZICKGokixMSfKDOfcOAAAAk4"]
[Tue Jul 21 08:33:52.463303 2026] [security2:error] [pid 466512:tid 466678] [client 81.171.74.60:42796] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9ZICKGokixMSfKDOfcOQAAAjg"]
[Tue Jul 21 08:33:52.465017 2026] [security2:error] [pid 466512:tid 466742] [client 81.171.74.60:42792] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/config/production.json"] [unique_id "al9ZICKGokixMSfKDOfcOgAAAng"]
[Tue Jul 21 08:33:52.507844 2026] [security2:error] [pid 466512:tid 466656] [client 49.144.66.253:31434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZICKGokixMSfKDOfcOwAAAiI"]
[Tue Jul 21 08:33:52.507984 2026] [security2:error] [pid 466512:tid 466656] [client 49.144.66.253:31434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZICKGokixMSfKDOfcOwAAAiI"]
[Tue Jul 21 08:33:52.524490 2026] [authz_core:error] [pid 465652:tid 465859] [client 162.241.63.68:21198] AH01630: client denied by server configuration: /home3/ocamin36/public_html/.user.ini
[Tue Jul 21 08:33:52.546087 2026] [security2:error] [pid 466512:tid 466686] [client 20.151.10.161:65440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/ingfo.php"] [unique_id "al9ZICKGokixMSfKDOfcPAAAAkA"]
[Tue Jul 21 08:33:52.591373 2026] [security2:error] [pid 466512:tid 466708] [client 152.59.181.104:61986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZICKGokixMSfKDOfcPgAAAlY"]
[Tue Jul 21 08:33:52.591523 2026] [security2:error] [pid 466512:tid 466708] [client 152.59.181.104:61986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZICKGokixMSfKDOfcPgAAAlY"]
[Tue Jul 21 08:33:52.654656 2026] [security2:error] [pid 466512:tid 466761] [client 20.104.96.117:46494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/nano.php"] [unique_id "al9ZICKGokixMSfKDOfcPwAAAos"]
[Tue Jul 21 08:33:52.856411 2026] [security2:error] [pid 466512:tid 466696] [client 187.125.243.197:53175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZICKGokixMSfKDOfcRAAAAko"]
[Tue Jul 21 08:33:52.856513 2026] [security2:error] [pid 466512:tid 466696] [client 187.125.243.197:53175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZICKGokixMSfKDOfcRAAAAko"]
[Tue Jul 21 08:33:52.983586 2026] [security2:error] [pid 465652:tid 465864] [client 20.104.96.117:62607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/moon.php"] [unique_id "al9ZIDzTqJoBC2Mw28-4-gAAANc"]
[Tue Jul 21 08:33:53.001791 2026] [security2:error] [pid 466512:tid 466754] [client 5.38.115.39:50468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZISKGokixMSfKDOfcRQAAAoQ"]
[Tue Jul 21 08:33:53.001903 2026] [security2:error] [pid 466512:tid 466754] [client 5.38.115.39:50468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZISKGokixMSfKDOfcRQAAAoQ"]
[Tue Jul 21 08:33:53.236519 2026] [security2:error] [pid 465652:tid 465842] [client 81.171.74.60:50124] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/server.key"] [unique_id "al9ZITzTqJoBC2Mw28-4_wAAAME"]
[Tue Jul 21 08:33:53.236519 2026] [security2:error] [pid 465652:tid 465789] [client 81.171.74.60:50132] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/secrets.json"] [unique_id "al9ZITzTqJoBC2Mw28-5AAAAAIw"]
[Tue Jul 21 08:33:53.237464 2026] [security2:error] [pid 465652:tid 465881] [client 81.171.74.60:50122] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9ZITzTqJoBC2Mw28-5AQAAAOg"]
[Tue Jul 21 08:33:53.237932 2026] [security2:error] [pid 466512:tid 466756] [client 81.171.74.60:50126] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/.npmrc"] [unique_id "al9ZISKGokixMSfKDOfcTQAAAoY"]
[Tue Jul 21 08:33:53.250019 2026] [security2:error] [pid 466512:tid 466763] [client 20.220.225.223:50254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/kq1.php"] [unique_id "al9ZISKGokixMSfKDOfcTgAAAo0"]
[Tue Jul 21 08:33:53.300569 2026] [security2:error] [pid 466512:tid 466621] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZISKGokixMSfKDOfcUAACG2w"]
[Tue Jul 21 08:33:53.300799 2026] [security2:error] [pid 466512:tid 466649] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZISKGokixMSfKDOfcUAACG2w"]
[Tue Jul 21 08:33:53.438696 2026] [security2:error] [pid 466512:tid 466690] [client 81.171.74.60:50142] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/phpinfo.php"] [unique_id "al9ZISKGokixMSfKDOfcUwAAAkQ"]
[Tue Jul 21 08:33:53.438700 2026] [security2:error] [pid 466512:tid 466751] [client 81.171.74.60:50148] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/.bash_history"] [unique_id "al9ZISKGokixMSfKDOfcVAAAAoE"]
[Tue Jul 21 08:33:53.438989 2026] [security2:error] [pid 465652:tid 465823] [client 81.171.74.60:50136] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/docker-compose.yml"] [unique_id "al9ZITzTqJoBC2Mw28-5BgAAAK4"]
[Tue Jul 21 08:33:53.527961 2026] [security2:error] [pid 466512:tid 466749] [client 4.194.24.143:8396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp-user.php"] [unique_id "al9ZISKGokixMSfKDOfcVgAAAn8"]
[Tue Jul 21 08:33:53.654647 2026] [security2:error] [pid 465652:tid 465848] [client 20.104.96.117:62661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-info.php"] [unique_id "al9ZITzTqJoBC2Mw28-5CAAAAMc"]
[Tue Jul 21 08:33:53.724717 2026] [security2:error] [pid 465652:tid 465892] [client 20.206.105.145:25578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9ZITzTqJoBC2Mw28-5CwAAAPM"]
[Tue Jul 21 08:33:53.788357 2026] [security2:error] [pid 465652:tid 465783] [client 114.119.140.13:38557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "diskvidros.com.br"] [uri "/"] [unique_id "al9ZITzTqJoBC2Mw28-5DQAAAIY"], referer: http://diskvidros.com.br?page_id=12
[Tue Jul 21 08:33:53.832781 2026] [security2:error] [pid 465652:tid 465838] [client 152.59.34.51:2038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZITzTqJoBC2Mw28-5DgAAAL0"]
[Tue Jul 21 08:33:53.832906 2026] [security2:error] [pid 465652:tid 465838] [client 152.59.34.51:2038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZITzTqJoBC2Mw28-5DgAAAL0"]
[Tue Jul 21 08:33:53.876674 2026] [core:error] [pid 465652:tid 465764] [remote 52.167.144.209:14671] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:53.876696 2026] [core:error] [pid 465652:tid 465764] [remote 52.167.144.209:14671] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:53.905429 2026] [security2:error] [pid 466512:tid 466704] [client 14.245.224.124:59783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZISKGokixMSfKDOfcYgAAAlI"]
[Tue Jul 21 08:33:53.905608 2026] [security2:error] [pid 466512:tid 466704] [client 14.245.224.124:59783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZISKGokixMSfKDOfcYgAAAlI"]
[Tue Jul 21 08:33:54.003488 2026] [core:error] [pid 465652:tid 465657] [remote 52.167.144.209:14671] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:54.003516 2026] [core:error] [pid 465652:tid 465657] [remote 52.167.144.209:14671] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:33:54.025386 2026] [security2:error] [pid 466512:tid 466678] [client 81.171.74.60:50162] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9ZIiKGokixMSfKDOfcYwAAAjg"]
[Tue Jul 21 08:33:54.056622 2026] [security2:error] [pid 465652:tid 465867] [client 81.171.74.60:50174] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/backup.zip"] [unique_id "al9ZIjzTqJoBC2Mw28-5EgAAANo"]
[Tue Jul 21 08:33:54.058552 2026] [security2:error] [pid 466512:tid 466765] [client 81.171.74.60:50182] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/wp-config.php"] [unique_id "al9ZIiKGokixMSfKDOfcZAAAAo8"]
[Tue Jul 21 08:33:54.059076 2026] [security2:error] [pid 465652:tid 465811] [client 81.171.74.60:50194] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9ZIjzTqJoBC2Mw28-5EwAAAKI"]
[Tue Jul 21 08:33:54.218914 2026] [security2:error] [pid 466512:tid 466685] [client 20.197.195.24:56294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/x.php"] [unique_id "al9ZIiKGokixMSfKDOfcZQAAAj8"]
[Tue Jul 21 08:33:54.227402 2026] [security2:error] [pid 465652:tid 465837] [client 81.171.74.60:50190] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/actuator/heapdump"] [unique_id "al9ZIjzTqJoBC2Mw28-5FwAAALw"]
[Tue Jul 21 08:33:54.460964 2026] [security2:error] [pid 465652:tid 465806] [client 20.151.10.161:65472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/error_log.php"] [unique_id "al9ZIjzTqJoBC2Mw28-5HwAAAJ0"]
[Tue Jul 21 08:33:54.484811 2026] [security2:error] [pid 466512:tid 466548] [remote 45.3.50.44:62317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.50.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9ZIiKGokixMSfKDOfcZwACIyM"]
[Tue Jul 21 08:33:54.551953 2026] [security2:error] [pid 465652:tid 465884] [client 4.194.24.143:64823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp-ver.php"] [unique_id "al9ZIjzTqJoBC2Mw28-5IQAAAOs"]
[Tue Jul 21 08:33:54.744990 2026] [security2:error] [pid 465652:tid 465861] [client 20.104.96.117:46577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/2000.php"] [unique_id "al9ZIjzTqJoBC2Mw28-5JAAAANQ"]
[Tue Jul 21 08:33:55.022759 2026] [security2:error] [pid 465652:tid 465864] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZIzzTqJoBC2Mw28-5MAAAANc"]
[Tue Jul 21 08:33:55.023284 2026] [security2:error] [pid 465652:tid 465859] [client 81.171.74.60:50224] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/dump.sql"] [unique_id "al9ZIzzTqJoBC2Mw28-5MQAAANI"]
[Tue Jul 21 08:33:55.024202 2026] [security2:error] [pid 466512:tid 466764] [client 81.171.74.60:50204] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/backup.tar.gz"] [unique_id "al9ZIyKGokixMSfKDOfcbgAAAo4"]
[Tue Jul 21 08:33:55.024244 2026] [security2:error] [pid 466512:tid 466688] [client 81.171.74.60:50216] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9ZIyKGokixMSfKDOfcbwAAAkI"]
[Tue Jul 21 08:33:55.025787 2026] [security2:error] [pid 465652:tid 465825] [client 81.171.74.60:50258] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/.svn/wc.db"] [unique_id "al9ZIzzTqJoBC2Mw28-5MgAAALA"]
[Tue Jul 21 08:33:55.170938 2026] [security2:error] [pid 465652:tid 465876] [client 20.104.96.117:62598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/122.php"] [unique_id "al9ZIzzTqJoBC2Mw28-5NAAAAOM"]
[Tue Jul 21 08:33:55.224771 2026] [security2:error] [pid 466512:tid 466740] [client 81.171.74.60:50246] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/backup.sql"] [unique_id "al9ZIyKGokixMSfKDOfccAAAAnY"]
[Tue Jul 21 08:33:55.225304 2026] [security2:error] [pid 466512:tid 466739] [client 81.171.74.60:50254] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/config.php"] [unique_id "al9ZIyKGokixMSfKDOfccQAAAnU"]
[Tue Jul 21 08:33:55.225327 2026] [security2:error] [pid 465652:tid 465886] [client 81.171.74.60:50236] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/config.xml"] [unique_id "al9ZIzzTqJoBC2Mw28-5NgAAAO0"]
[Tue Jul 21 08:33:55.247082 2026] [security2:error] [pid 466512:tid 466692] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZISKGokixMSfKDOfcXgACRhE"]
[Tue Jul 21 08:33:55.355990 2026] [security2:error] [pid 465652:tid 465893] [client 5.31.193.106:29998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZIzzTqJoBC2Mw28-5OgAAAPQ"]
[Tue Jul 21 08:33:55.356188 2026] [security2:error] [pid 465652:tid 465893] [client 5.31.193.106:29998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZIzzTqJoBC2Mw28-5OgAAAPQ"]
[Tue Jul 21 08:33:55.441974 2026] [security2:error] [pid 466512:tid 466662] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9ZIyKGokixMSfKDOfceAAAAig"]
[Tue Jul 21 08:33:55.459116 2026] [security2:error] [pid 466512:tid 466651] [client 20.104.96.117:46528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/mds.php"] [unique_id "al9ZIyKGokixMSfKDOfceQAAAh0"]
[Tue Jul 21 08:33:55.609540 2026] [security2:error] [pid 465652:tid 465784] [client 4.194.24.143:64805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp-ws68.php"] [unique_id "al9ZIzzTqJoBC2Mw28-5PQAAAIc"]
[Tue Jul 21 08:33:55.726385 2026] [security2:error] [pid 465652:tid 465785] [client 74.7.175.165:59532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bubaby.com.br"] [uri "/index.php"] [unique_id "al9ZIjzTqJoBC2Mw28-5IAAAiA8"]
[Tue Jul 21 08:33:55.807099 2026] [security2:error] [pid 465652:tid 465827] [client 20.104.96.117:46514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-blink.php"] [unique_id "al9ZIzzTqJoBC2Mw28-5QQAAALI"]
[Tue Jul 21 08:33:55.816615 2026] [security2:error] [pid 466512:tid 466676] [client 81.171.74.60:50272] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9ZIyKGokixMSfKDOfcfwAAAjY"]
[Tue Jul 21 08:33:55.826214 2026] [security2:error] [pid 466512:tid 466661] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9ZIyKGokixMSfKDOfcgAAAAic"]
[Tue Jul 21 08:33:55.841090 2026] [security2:error] [pid 466512:tid 466644] [client 20.220.225.223:50273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/zzz.php"] [unique_id "al9ZIyKGokixMSfKDOfcggAAAhY"]
[Tue Jul 21 08:33:55.850137 2026] [security2:error] [pid 466512:tid 466700] [client 20.197.195.24:6738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/155.php"] [unique_id "al9ZIyKGokixMSfKDOfchAAAAk4"]
[Tue Jul 21 08:33:56.193290 2026] [security2:error] [pid 466512:tid 466708] [client 81.171.74.60:50278] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "teste.inonebrasil.com.br"] [uri "/database.sql"] [unique_id "al9ZJCKGokixMSfKDOfchwAAAlY"]
[Tue Jul 21 08:33:56.200442 2026] [security2:error] [pid 466512:tid 466769] [client 20.104.96.117:46492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/zc-208.php"] [unique_id "al9ZJCKGokixMSfKDOfciAAAApM"]
[Tue Jul 21 08:33:56.221349 2026] [security2:error] [pid 466512:tid 466646] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9ZJCKGokixMSfKDOfciQAAAhg"]
[Tue Jul 21 08:33:56.313048 2026] [security2:error] [pid 465652:tid 465838] [client 20.151.10.161:65412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/ok.php"] [unique_id "al9ZJDzTqJoBC2Mw28-5RwAAAL0"]
[Tue Jul 21 08:33:56.502977 2026] [security2:error] [pid 465652:tid 465811] [client 20.104.96.117:46542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/sid4.php"] [unique_id "al9ZJDzTqJoBC2Mw28-5TAAAAKI"]
[Tue Jul 21 08:33:56.616685 2026] [security2:error] [pid 466512:tid 466753] [client 202.179.75.202:46096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZJCKGokixMSfKDOfckAAAAoM"]
[Tue Jul 21 08:33:56.616904 2026] [security2:error] [pid 466512:tid 466753] [client 202.179.75.202:46096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZJCKGokixMSfKDOfckAAAAoM"]
[Tue Jul 21 08:33:56.653649 2026] [security2:error] [pid 465652:tid 465837] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9ZJDzTqJoBC2Mw28-5TgAAALw"]
[Tue Jul 21 08:33:56.676355 2026] [security2:error] [pid 465652:tid 465798] [client 4.194.24.143:17076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp.php"] [unique_id "al9ZJDzTqJoBC2Mw28-5TwAAAJU"]
[Tue Jul 21 08:33:56.843835 2026] [autoindex:error] [pid 466512:tid 466709] [client 20.104.96.117:46517] AH01276: Cannot serve directory /home1/oticap05/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:33:57.059665 2026] [security2:error] [pid 466512:tid 466751] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9ZJSKGokixMSfKDOfcmAAAAoE"]
[Tue Jul 21 08:33:57.118032 2026] [security2:error] [pid 466512:tid 466762] [client 20.104.96.117:46517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wmore1.php"] [unique_id "al9ZJSKGokixMSfKDOfcmQAAAow"]
[Tue Jul 21 08:33:57.329868 2026] [security2:error] [pid 466512:tid 466747] [client 20.197.195.24:6657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/ops.php"] [unique_id "al9ZJSKGokixMSfKDOfcnQAAAn0"]
[Tue Jul 21 08:33:57.412651 2026] [security2:error] [pid 466512:tid 466650] [client 20.104.96.117:46574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/solo1.php"] [unique_id "al9ZJSKGokixMSfKDOfcnwAAAhw"]
[Tue Jul 21 08:33:57.449751 2026] [security2:error] [pid 465652:tid 465883] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9ZJTzTqJoBC2Mw28-5WgAAAOo"]
[Tue Jul 21 08:33:57.722568 2026] [autoindex:error] [pid 465652:tid 465860] [client 20.104.96.117:46486] AH01276: Cannot serve directory /home1/oticap05/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:33:57.737534 2026] [security2:error] [pid 466512:tid 466691] [client 4.194.24.143:8530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp/002.php"] [unique_id "al9ZJSKGokixMSfKDOfcpgAAAkU"]
[Tue Jul 21 08:33:57.919622 2026] [security2:error] [pid 466512:tid 466670] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9ZJSKGokixMSfKDOfcqwAAAjA"]
[Tue Jul 21 08:33:57.996412 2026] [security2:error] [pid 465652:tid 465819] [client 20.104.96.117:46486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/cong.php"] [unique_id "al9ZJTzTqJoBC2Mw28-5ZgAAAKo"]
[Tue Jul 21 08:33:58.024426 2026] [security2:error] [pid 465652:tid 465840] [client 20.151.10.161:65408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/mac.php"] [unique_id "al9ZJjzTqJoBC2Mw28-5aAAAAL8"]
[Tue Jul 21 08:33:58.264399 2026] [security2:error] [pid 466512:tid 466686] [client 195.49.128.211:60907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZJiKGokixMSfKDOfcswAAAkA"]
[Tue Jul 21 08:33:58.264605 2026] [security2:error] [pid 466512:tid 466686] [client 195.49.128.211:60907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZJiKGokixMSfKDOfcswAAAkA"]
[Tue Jul 21 08:33:58.340288 2026] [security2:error] [pid 465652:tid 465818] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9ZJjzTqJoBC2Mw28-5awAAAKk"]
[Tue Jul 21 08:33:58.402565 2026] [security2:error] [pid 466512:tid 466703] [client 20.151.10.161:65409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wefile.php"] [unique_id "al9ZJiKGokixMSfKDOfctQAAAlE"]
[Tue Jul 21 08:33:58.419734 2026] [security2:error] [pid 465652:tid 465792] [client 20.197.195.24:56286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/file31.php"] [unique_id "al9ZJjzTqJoBC2Mw28-5bAAAAI8"]
[Tue Jul 21 08:33:58.431737 2026] [security2:error] [pid 466512:tid 466692] [client 103.55.146.40:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.146.55.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZJSKGokixMSfKDOfcnAAAAkY"]
[Tue Jul 21 08:33:58.431896 2026] [security2:error] [pid 466512:tid 466692] [client 103.55.146.40:59060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joaomarcosdesign.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZJSKGokixMSfKDOfcnAAAAkY"]
[Tue Jul 21 08:33:58.517419 2026] [security2:error] [pid 465652:tid 465821] [client 74.249.245.134:54921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/init.php"] [unique_id "al9ZJjzTqJoBC2Mw28-5cAAAAKw"]
[Tue Jul 21 08:33:58.594664 2026] [autoindex:error] [pid 466512:tid 466649] [client 20.104.96.117:46504] AH01276: Cannot serve directory /home1/oticap05/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:33:58.663382 2026] [security2:error] [pid 465652:tid 465881] [client 93.152.221.65:63626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "governess.com.br"] [uri "/wp-login.php"] [unique_id "al9ZJjzTqJoBC2Mw28-5cwAAAOg"]
[Tue Jul 21 08:33:58.781041 2026] [security2:error] [pid 465652:tid 465847] [client 4.194.24.143:8536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wp/wp-content/themes/extendable/mg2.php"] [unique_id "al9ZJjzTqJoBC2Mw28-5dQAAAMY"]
[Tue Jul 21 08:33:58.797474 2026] [security2:error] [pid 466512:tid 466728] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9ZJiKGokixMSfKDOfcwQAAAmo"]
[Tue Jul 21 08:33:58.851292 2026] [security2:error] [pid 465652:tid 465660] [remote 20.153.140.50:45888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ZJjzTqJoBC2Mw28-5dgAAjAc"]
[Tue Jul 21 08:33:58.852913 2026] [security2:error] [pid 466512:tid 466668] [client 20.151.10.161:65507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9ZJiKGokixMSfKDOfcwgAAAi4"]
[Tue Jul 21 08:33:58.886962 2026] [security2:error] [pid 466512:tid 466713] [client 20.104.96.117:46504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/public/css.php"] [unique_id "al9ZJiKGokixMSfKDOfcwwAAAls"]
[Tue Jul 21 08:33:58.959598 2026] [security2:error] [pid 466512:tid 466747] [client 74.249.245.134:16452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/archive.php"] [unique_id "al9ZJiKGokixMSfKDOfcxQAAAn0"]
[Tue Jul 21 08:33:59.186895 2026] [security2:error] [pid 465652:tid 465799] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9ZJzzTqJoBC2Mw28-5fQAAAJY"]
[Tue Jul 21 08:33:59.230615 2026] [security2:error] [pid 465652:tid 465879] [client 47.128.60.61:14610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "rustikusboxingschool.com"] [uri "/robots.txt"] [unique_id "al9ZJzzTqJoBC2Mw28-5fgAAAOY"]
[Tue Jul 21 08:33:59.267471 2026] [security2:error] [pid 466512:tid 466644] [client 20.206.105.145:25472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9ZJyKGokixMSfKDOfcygAAAhY"]
[Tue Jul 21 08:33:59.365681 2026] [autoindex:error] [pid 465652:tid 465838] [client 20.151.10.161:63040] AH01276: Cannot serve directory /home3/chave482/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:33:59.539564 2026] [security2:error] [pid 465652:tid 465850] [client 147.93.168.177:58256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.168.93.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "coroneldimas.mg"] [uri "/wp-login.php"] [unique_id "al9ZJzzTqJoBC2Mw28-5gwAAAMk"]
[Tue Jul 21 08:33:59.552592 2026] [security2:error] [pid 466512:tid 466727] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9ZJyKGokixMSfKDOfczAAAAmk"]
[Tue Jul 21 08:33:59.651637 2026] [security2:error] [pid 465652:tid 465891] [client 93.152.221.65:63768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "governess.com.br"] [uri "/administrator/"] [unique_id "al9ZJzzTqJoBC2Mw28-5iQAAAPI"]
[Tue Jul 21 08:33:59.655806 2026] [security2:error] [pid 466512:tid 466647] [client 20.197.195.24:6662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/file6.php"] [unique_id "al9ZJyKGokixMSfKDOfc0AAAAhk"]
[Tue Jul 21 08:33:59.701743 2026] [autoindex:error] [pid 465652:tid 465794] [client 20.151.10.161:63040] AH01276: Cannot serve directory /home3/chave482/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:33:59.815842 2026] [security2:error] [pid 466512:tid 466723] [client 4.194.24.143:8948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/ws.php"] [unique_id "al9ZJyKGokixMSfKDOfc0wAAAmU"]
[Tue Jul 21 08:33:59.839389 2026] [security2:error] [pid 465652:tid 465871] [client 20.151.10.161:63040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9ZJzzTqJoBC2Mw28-5jQAAAN4"]
[Tue Jul 21 08:33:59.958211 2026] [security2:error] [pid 465652:tid 465896] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9ZJzzTqJoBC2Mw28-5jgAAAPc"]
[Tue Jul 21 08:34:00.134755 2026] [autoindex:error] [pid 466512:tid 466678] [client 20.197.195.24:6683] AH01276: Cannot serve directory /home2/hg4int84/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:00.290064 2026] [security2:error] [pid 465652:tid 465809] [client 20.104.96.117:46544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/output.php"] [unique_id "al9ZKDzTqJoBC2Mw28-5mgAAAKA"]
[Tue Jul 21 08:34:00.295345 2026] [security2:error] [pid 466512:tid 466670] [client 122.176.100.127:57531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZKCKGokixMSfKDOfc2wAAAjA"]
[Tue Jul 21 08:34:00.296963 2026] [security2:error] [pid 466512:tid 466670] [client 122.176.100.127:57531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZKCKGokixMSfKDOfc2wAAAjA"]
[Tue Jul 21 08:34:00.361457 2026] [security2:error] [pid 466512:tid 466681] [client 20.197.195.24:6683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/adminfuns.php"] [unique_id "al9ZKCKGokixMSfKDOfc3AAAAjs"]
[Tue Jul 21 08:34:00.411289 2026] [security2:error] [pid 466512:tid 466765] [client 117.213.202.34:50746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZKCKGokixMSfKDOfc3QAAAo8"]
[Tue Jul 21 08:34:00.411438 2026] [security2:error] [pid 466512:tid 466765] [client 117.213.202.34:50746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZKCKGokixMSfKDOfc3QAAAo8"]
[Tue Jul 21 08:34:00.566667 2026] [security2:error] [pid 465652:tid 465864] [client 20.197.195.24:6771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/goods.php"] [unique_id "al9ZKDzTqJoBC2Mw28-5nAAAANc"]
[Tue Jul 21 08:34:00.706465 2026] [security2:error] [pid 465652:tid 465806] [client 223.181.60.88:32057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZKDzTqJoBC2Mw28-5nwAAAJ0"]
[Tue Jul 21 08:34:00.706792 2026] [security2:error] [pid 465652:tid 465806] [client 223.181.60.88:32057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZKDzTqJoBC2Mw28-5nwAAAJ0"]
[Tue Jul 21 08:34:00.864834 2026] [security2:error] [pid 465652:tid 465832] [client 20.197.195.24:6760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/100.php"] [unique_id "al9ZKDzTqJoBC2Mw28-5owAAALc"]
[Tue Jul 21 08:34:00.988273 2026] [security2:error] [pid 466512:tid 466672] [client 4.194.24.143:8538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/wso.php"] [unique_id "al9ZKCKGokixMSfKDOfc6AAAAjI"]
[Tue Jul 21 08:34:01.090720 2026] [security2:error] [pid 466512:tid 466660] [client 137.97.59.154:65445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZKSKGokixMSfKDOfc6QAAAiY"]
[Tue Jul 21 08:34:01.090921 2026] [security2:error] [pid 466512:tid 466660] [client 137.97.59.154:65445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZKSKGokixMSfKDOfc6QAAAiY"]
[Tue Jul 21 08:34:01.150038 2026] [security2:error] [pid 466512:tid 466658] [client 109.248.148.246:55002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9ZKSKGokixMSfKDOfc7AAAAiQ"]
[Tue Jul 21 08:34:01.150147 2026] [security2:error] [pid 466512:tid 466658] [client 109.248.148.246:55002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9ZKSKGokixMSfKDOfc7AAAAiQ"]
[Tue Jul 21 08:34:01.182277 2026] [security2:error] [pid 465652:tid 465813] [client 74.249.245.134:51516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/amax.php"] [unique_id "al9ZKTzTqJoBC2Mw28-5qgAAAKQ"]
[Tue Jul 21 08:34:01.200886 2026] [security2:error] [pid 465652:tid 465847] [client 20.206.105.145:25599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/raw.php"] [unique_id "al9ZKTzTqJoBC2Mw28-5rAAAAMY"]
[Tue Jul 21 08:34:01.353465 2026] [security2:error] [pid 466512:tid 466767] [client 20.197.195.24:6746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/about.php"] [unique_id "al9ZKSKGokixMSfKDOfc7wAAApE"]
[Tue Jul 21 08:34:01.443640 2026] [security2:error] [pid 465652:tid 465838] [client 20.151.10.161:65455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/like.php"] [unique_id "al9ZKTzTqJoBC2Mw28-5tAAAAL0"]
[Tue Jul 21 08:34:01.489889 2026] [security2:error] [pid 465652:tid 465829] [client 20.197.192.193:43824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/ftde.php"] [unique_id "al9ZKTzTqJoBC2Mw28-5tQAAALQ"]
[Tue Jul 21 08:34:01.889282 2026] [security2:error] [pid 465652:tid 465658] [remote 8.217.108.67:54974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9ZKTzTqJoBC2Mw28-5yQABBAU"]
[Tue Jul 21 08:34:01.906023 2026] [security2:error] [pid 465652:tid 465812] [client 20.197.195.24:6679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/about.php"] [unique_id "al9ZKTzTqJoBC2Mw28-5ygAAAKM"]
[Tue Jul 21 08:34:01.945769 2026] [security2:error] [pid 466512:tid 466656] [client 20.206.105.145:25480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/abcd.php"] [unique_id "al9ZKSKGokixMSfKDOfc9gAAAiI"]
[Tue Jul 21 08:34:02.031658 2026] [security2:error] [pid 465652:tid 465713] [remote 104.207.33.106:37393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9ZKTzTqJoBC2Mw28-5xwAA4Dw"]
[Tue Jul 21 08:34:02.043860 2026] [security2:error] [pid 465652:tid 465809] [client 20.220.225.223:50899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/wicked.php"] [unique_id "al9ZKjzTqJoBC2Mw28-5ywAAAKA"]
[Tue Jul 21 08:34:02.057648 2026] [security2:error] [pid 466512:tid 466697] [client 20.104.96.117:46557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-file-120.php"] [unique_id "al9ZKiKGokixMSfKDOfc9wAAAks"]
[Tue Jul 21 08:34:02.069539 2026] [security2:error] [pid 466512:tid 466714] [client 4.194.24.143:8438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/x.php"] [unique_id "al9ZKiKGokixMSfKDOfc-AAAAlw"]
[Tue Jul 21 08:34:02.429233 2026] [authz_core:error] [pid 465652:tid 465881] [client 74.249.245.134:37750] AH01630: client denied by server configuration: /var/www/html/php.ini
[Tue Jul 21 08:34:02.511458 2026] [security2:error] [pid 466512:tid 466718] [client 20.197.195.24:6759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/admin.php"] [unique_id "al9ZKiKGokixMSfKDOfc_AAAAmA"]
[Tue Jul 21 08:34:02.518972 2026] [security2:error] [pid 466512:tid 466723] [client 195.49.128.211:52939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZKiKGokixMSfKDOfc_QAAAmU"]
[Tue Jul 21 08:34:02.519108 2026] [security2:error] [pid 466512:tid 466723] [client 195.49.128.211:52939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZKiKGokixMSfKDOfc_QAAAmU"]
[Tue Jul 21 08:34:02.559074 2026] [security2:error] [pid 466512:tid 466657] [client 20.197.195.24:56256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/admin.php"] [unique_id "al9ZKiKGokixMSfKDOfc_gAAAiM"]
[Tue Jul 21 08:34:02.592675 2026] [security2:error] [pid 465652:tid 465787] [client 61.1.167.83:59067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZKjzTqJoBC2Mw28-53gAAAIo"]
[Tue Jul 21 08:34:02.592788 2026] [security2:error] [pid 465652:tid 465787] [client 61.1.167.83:59067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZKjzTqJoBC2Mw28-53gAAAIo"]
[Tue Jul 21 08:34:02.610365 2026] [security2:error] [pid 466512:tid 466761] [client 20.197.195.24:6701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/themes.php"] [unique_id "al9ZKiKGokixMSfKDOfc_wAAAos"]
[Tue Jul 21 08:34:02.672486 2026] [autoindex:error] [pid 466512:tid 466703] [client 20.197.195.24:6774] AH01276: Cannot serve directory /home2/hg4int84/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:02.694509 2026] [security2:error] [pid 466512:tid 466646] [client 103.151.46.103:49357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZKiKGokixMSfKDOfdAQAAAhg"]
[Tue Jul 21 08:34:02.694632 2026] [security2:error] [pid 466512:tid 466646] [client 103.151.46.103:49357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZKiKGokixMSfKDOfdAQAAAhg"]
[Tue Jul 21 08:34:02.695790 2026] [security2:error] [pid 466512:tid 466720] [client 20.151.10.161:65494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/.well-known/about.php"] [unique_id "al9ZKiKGokixMSfKDOfdAgAAAmI"]
[Tue Jul 21 08:34:02.726372 2026] [security2:error] [pid 465652:tid 465868] [client 74.249.245.134:37750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/settings.php"] [unique_id "al9ZKjzTqJoBC2Mw28-55gAAANs"]
[Tue Jul 21 08:34:02.767140 2026] [security2:error] [pid 465652:tid 465820] [client 20.206.105.145:25562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/a1.php"] [unique_id "al9ZKjzTqJoBC2Mw28-55wAAAKs"]
[Tue Jul 21 08:34:03.154052 2026] [security2:error] [pid 465652:tid 465846] [client 4.194.24.143:8906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/x86.php"] [unique_id "al9ZKzzTqJoBC2Mw28-59AAAAMU"]
[Tue Jul 21 08:34:03.425782 2026] [rewrite:warn] [pid 466512:tid 466578] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:34:03.443535 2026] [security2:error] [pid 466512:tid 466573] [remote 202.51.202.242:49172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "precisosolucao.com.br"] [uri "/wp-login.php"] [unique_id "al9ZKyKGokixMSfKDOfdEwACTTw"]
[Tue Jul 21 08:34:03.558392 2026] [security2:error] [pid 465652:tid 465817] [client 20.104.96.117:46497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/special.php"] [unique_id "al9ZKzzTqJoBC2Mw28-5_gAAAKg"]
[Tue Jul 21 08:34:03.620322 2026] [security2:error] [pid 465652:tid 465907] [client 20.220.225.223:50248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/edit.php"] [unique_id "al9ZKzzTqJoBC2Mw28-6AAAAAQI"]
[Tue Jul 21 08:34:03.647211 2026] [security2:error] [pid 466512:tid 466661] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZKyKGokixMSfKDOfdFAACJwc"]
[Tue Jul 21 08:34:03.656577 2026] [security2:error] [pid 465652:tid 465856] [client 187.125.243.197:53887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZKzzTqJoBC2Mw28-6AwAAAM8"]
[Tue Jul 21 08:34:03.656695 2026] [security2:error] [pid 465652:tid 465856] [client 187.125.243.197:53887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZKzzTqJoBC2Mw28-6AwAAAM8"]
[Tue Jul 21 08:34:03.695481 2026] [security2:error] [pid 466512:tid 466751] [client 5.38.115.39:51042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZKyKGokixMSfKDOfdHAAAAoE"]
[Tue Jul 21 08:34:03.695625 2026] [security2:error] [pid 466512:tid 466751] [client 5.38.115.39:51042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZKyKGokixMSfKDOfdHAAAAoE"]
[Tue Jul 21 08:34:03.755357 2026] [security2:error] [pid 465652:tid 465807] [client 49.144.66.253:31815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZKzzTqJoBC2Mw28-6CAAAAJ4"]
[Tue Jul 21 08:34:03.755819 2026] [security2:error] [pid 465652:tid 465807] [client 49.144.66.253:31815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZKzzTqJoBC2Mw28-6CAAAAJ4"]
[Tue Jul 21 08:34:03.854274 2026] [security2:error] [pid 466512:tid 466603] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZKyKGokixMSfKDOfdHwACaFo"]
[Tue Jul 21 08:34:03.854439 2026] [security2:error] [pid 466512:tid 466726] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZKyKGokixMSfKDOfdHwACaFo"]
[Tue Jul 21 08:34:03.936835 2026] [security2:error] [pid 465652:tid 465825] [client 20.151.10.161:65433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9ZKzzTqJoBC2Mw28-6KAAAALA"]
[Tue Jul 21 08:34:04.168625 2026] [security2:error] [pid 465652:tid 465806] [client 20.206.105.145:25478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9ZLDzTqJoBC2Mw28-6LQAAAJ0"]
[Tue Jul 21 08:34:04.186783 2026] [security2:error] [pid 466512:tid 466708] [client 4.194.24.143:8422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/xa.php"] [unique_id "al9ZLCKGokixMSfKDOfdIQAAAlY"]
[Tue Jul 21 08:34:04.721307 2026] [security2:error] [pid 465652:tid 465876] [client 14.245.224.124:60242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZLDzTqJoBC2Mw28-6VAAAAOM"]
[Tue Jul 21 08:34:04.721424 2026] [security2:error] [pid 465652:tid 465876] [client 14.245.224.124:60242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZLDzTqJoBC2Mw28-6VAAAAOM"]
[Tue Jul 21 08:34:04.797637 2026] [security2:error] [pid 465652:tid 465809] [client 152.59.34.51:63010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZLDzTqJoBC2Mw28-6VQAAAKA"]
[Tue Jul 21 08:34:04.797768 2026] [security2:error] [pid 465652:tid 465809] [client 152.59.34.51:63010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZLDzTqJoBC2Mw28-6VQAAAKA"]
[Tue Jul 21 08:34:05.160272 2026] [security2:error] [pid 466512:tid 466728] [client 20.220.225.223:20889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/ms-new.php"] [unique_id "al9ZLSKGokixMSfKDOfdMQAAAmo"]
[Tue Jul 21 08:34:05.243698 2026] [security2:error] [pid 465652:tid 465829] [client 4.194.24.143:60996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/xfun.php"] [unique_id "al9ZLTzTqJoBC2Mw28-6XQAAALQ"]
[Tue Jul 21 08:34:05.301117 2026] [autoindex:error] [pid 466512:tid 466690] [client 20.151.10.161:63688] AH01276: Cannot serve directory /home3/chave482/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:05.312319 2026] [security2:error] [pid 465652:tid 465799] [client 20.206.105.145:25508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9ZLTzTqJoBC2Mw28-6XgAAAJY"]
[Tue Jul 21 08:34:05.623807 2026] [autoindex:error] [pid 466512:tid 466651] [client 20.151.10.161:63688] AH01276: Cannot serve directory /home3/chave482/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:05.769041 2026] [security2:error] [pid 466512:tid 466676] [client 20.197.195.24:6774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/.well-known/about.php"] [unique_id "al9ZLSKGokixMSfKDOfdPwAAAjY"]
[Tue Jul 21 08:34:05.774554 2026] [security2:error] [pid 466512:tid 466643] [client 20.151.10.161:63688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/pucci.php"] [unique_id "al9ZLSKGokixMSfKDOfdQAAAAhU"]
[Tue Jul 21 08:34:05.979479 2026] [security2:error] [pid 466512:tid 466726] [client 20.104.96.117:62614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/as.php"] [unique_id "al9ZLSKGokixMSfKDOfdSgAAAmg"]
[Tue Jul 21 08:34:06.221282 2026] [security2:error] [pid 466512:tid 466757] [client 20.206.105.145:25498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9ZLiKGokixMSfKDOfdTQAAAoc"]
[Tue Jul 21 08:34:06.345350 2026] [security2:error] [pid 466512:tid 466669] [client 4.194.24.143:8519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/xleet.php"] [unique_id "al9ZLiKGokixMSfKDOfdUQAAAi8"]
[Tue Jul 21 08:34:06.373603 2026] [security2:error] [pid 465652:tid 465859] [client 20.220.225.223:20892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/track.php"] [unique_id "al9ZLjzTqJoBC2Mw28-6dQAAANI"]
[Tue Jul 21 08:34:06.667959 2026] [security2:error] [pid 466512:tid 466764] [client 20.197.195.24:6745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9ZLiKGokixMSfKDOfdVgAAAo4"]
[Tue Jul 21 08:34:06.733681 2026] [security2:error] [pid 466512:tid 466654] [client 109.248.148.246:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9ZLiKGokixMSfKDOfdVwAAAiA"]
[Tue Jul 21 08:34:06.733786 2026] [security2:error] [pid 466512:tid 466654] [client 109.248.148.246:55016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9ZLiKGokixMSfKDOfdVwAAAiA"]
[Tue Jul 21 08:34:06.759909 2026] [autoindex:error] [pid 465652:tid 465865] [client 20.151.10.161:65411] AH01276: Cannot serve directory /home3/chave482/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:07.114955 2026] [security2:error] [pid 466512:tid 466739] [client 74.249.245.134:55249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/moon.php"] [unique_id "al9ZLyKGokixMSfKDOfdXAAAAnU"]
[Tue Jul 21 08:34:07.148246 2026] [security2:error] [pid 465652:tid 465843] [client 20.220.225.223:34729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/2352356666.php"] [unique_id "al9ZLzzTqJoBC2Mw28-6hQAAAMI"]
[Tue Jul 21 08:34:07.193735 2026] [security2:error] [pid 466512:tid 466728] [client 20.220.225.223:50376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/kua.php"] [unique_id "al9ZLyKGokixMSfKDOfdXQAAAmo"]
[Tue Jul 21 08:34:07.289426 2026] [security2:error] [pid 465652:tid 465876] [client 128.127.105.184:53758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9ZLzzTqJoBC2Mw28-6hwAAAOM"]
[Tue Jul 21 08:34:07.289722 2026] [security2:error] [pid 465652:tid 465876] [client 128.127.105.184:53758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9ZLzzTqJoBC2Mw28-6hwAAAOM"]
[Tue Jul 21 08:34:07.319800 2026] [security2:error] [pid 465652:tid 465803] [client 20.104.96.117:46482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9ZLzzTqJoBC2Mw28-6igAAAJo"]
[Tue Jul 21 08:34:07.388272 2026] [security2:error] [pid 466512:tid 466750] [client 4.194.24.143:8514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZLyKGokixMSfKDOfdXgAAAoA"]
[Tue Jul 21 08:34:07.410863 2026] [security2:error] [pid 466512:tid 466692] [client 65.21.113.253:34284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZLiKGokixMSfKDOfdWQAAAkY"]
[Tue Jul 21 08:34:07.526255 2026] [security2:error] [pid 466512:tid 466651] [client 20.197.195.24:6783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/wefile.php"] [unique_id "al9ZLyKGokixMSfKDOfdZQAAAh0"]
[Tue Jul 21 08:34:07.529582 2026] [autoindex:error] [pid 465652:tid 465838] [client 20.151.10.161:65411] AH01276: Cannot serve directory /home3/chave482/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:07.659067 2026] [security2:error] [pid 465652:tid 465851] [client 202.179.75.202:58870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZLzzTqJoBC2Mw28-6kgAAAMo"]
[Tue Jul 21 08:34:07.659180 2026] [security2:error] [pid 465652:tid 465851] [client 202.179.75.202:58870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZLzzTqJoBC2Mw28-6kgAAAMo"]
[Tue Jul 21 08:34:07.673429 2026] [security2:error] [pid 465652:tid 465837] [client 20.151.10.161:65411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wp-temp.php"] [unique_id "al9ZLzzTqJoBC2Mw28-6kwAAALw"]
[Tue Jul 21 08:34:07.808378 2026] [security2:error] [pid 466512:tid 466676] [client 20.197.195.24:6665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9ZLyKGokixMSfKDOfdZgAAAjY"]
[Tue Jul 21 08:34:08.014304 2026] [autoindex:error] [pid 466512:tid 466699] [client 20.197.195.24:56274] AH01276: Cannot serve directory /home2/hg4int84/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:08.092641 2026] [autoindex:error] [pid 466512:tid 466704] [client 20.197.195.24:56274] AH01276: Cannot serve directory /home2/hg4int84/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:08.128420 2026] [security2:error] [pid 466512:tid 466751] [client 20.197.195.24:56274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9ZMCKGokixMSfKDOfdbgAAAoE"]
[Tue Jul 21 08:34:08.171752 2026] [security2:error] [pid 465652:tid 465875] [client 20.197.195.24:6672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/8.php"] [unique_id "al9ZMDzTqJoBC2Mw28-6mwAAAOI"]
[Tue Jul 21 08:34:08.241354 2026] [security2:error] [pid 466512:tid 466682] [client 20.197.195.24:6667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/wp-content/admin.php"] [unique_id "al9ZMCKGokixMSfKDOfdcQAAAjw"]
[Tue Jul 21 08:34:08.307607 2026] [security2:error] [pid 465652:tid 465894] [client 20.206.105.145:25551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/simple.php"] [unique_id "al9ZMDzTqJoBC2Mw28-6nwAAAPU"]
[Tue Jul 21 08:34:08.470122 2026] [security2:error] [pid 465652:tid 465860] [client 4.194.24.143:8575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/xx.php"] [unique_id "al9ZMDzTqJoBC2Mw28-6oQAAANM"]
[Tue Jul 21 08:34:08.500422 2026] [security2:error] [pid 466512:tid 466761] [client 20.197.195.24:6733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/f6.php"] [unique_id "al9ZMCKGokixMSfKDOfdeQAAAos"]
[Tue Jul 21 08:34:08.709932 2026] [security2:error] [pid 465652:tid 465825] [client 20.197.195.24:6676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/inputs.php"] [unique_id "al9ZMDzTqJoBC2Mw28-6qgAAALA"]
[Tue Jul 21 08:34:08.739211 2026] [security2:error] [pid 466512:tid 466663] [client 20.197.195.24:6727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/inputs.php"] [unique_id "al9ZMCKGokixMSfKDOfdhQAAAik"]
[Tue Jul 21 08:34:08.809139 2026] [security2:error] [pid 466512:tid 466690] [client 20.197.195.24:56289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/classwithtostring.php"] [unique_id "al9ZMCKGokixMSfKDOfdhwAAAkQ"]
[Tue Jul 21 08:34:08.862801 2026] [security2:error] [pid 466512:tid 466683] [client 195.49.128.211:61519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZMCKGokixMSfKDOfdiAAAAj0"]
[Tue Jul 21 08:34:08.862902 2026] [security2:error] [pid 466512:tid 466683] [client 195.49.128.211:61519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZMCKGokixMSfKDOfdiAAAAj0"]
[Tue Jul 21 08:34:08.889620 2026] [security2:error] [pid 466512:tid 466750] [client 20.197.195.24:6725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9ZMCKGokixMSfKDOfdiQAAAoA"]
[Tue Jul 21 08:34:09.095297 2026] [security2:error] [pid 466512:tid 466651] [client 20.220.225.223:50378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/ez.php"] [unique_id "al9ZMSKGokixMSfKDOfdjgAAAh0"]
[Tue Jul 21 08:34:09.269955 2026] [autoindex:error] [pid 466512:tid 466656] [client 20.151.10.161:65456] AH01276: Cannot serve directory /home3/chave482/public_html/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:09.508286 2026] [security2:error] [pid 465652:tid 465847] [client 20.104.96.117:46549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/w1px.php"] [unique_id "al9ZMTzTqJoBC2Mw28-6tAAAAMY"]
[Tue Jul 21 08:34:09.540269 2026] [security2:error] [pid 466512:tid 466700] [client 4.194.24.143:8568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/xyn.php"] [unique_id "al9ZMSKGokixMSfKDOfdmwAAAk4"]
[Tue Jul 21 08:34:09.562604 2026] [security2:error] [pid 466512:tid 466752] [client 20.151.10.161:65456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/xmu.php"] [unique_id "al9ZMSKGokixMSfKDOfdngAAAoI"]
[Tue Jul 21 08:34:10.597220 2026] [security2:error] [pid 465652:tid 465851] [client 4.194.24.143:8959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/y.php"] [unique_id "al9ZMjzTqJoBC2Mw28-6zQAAAMo"]
[Tue Jul 21 08:34:10.599277 2026] [security2:error] [pid 466512:tid 466656] [client 20.206.105.145:25476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/xxx.php"] [unique_id "al9ZMiKGokixMSfKDOfdtAAAAiI"]
[Tue Jul 21 08:34:10.604146 2026] [security2:error] [pid 466512:tid 466743] [client 20.220.225.223:50379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/fz.php"] [unique_id "al9ZMiKGokixMSfKDOfdtQAAAnk"]
[Tue Jul 21 08:34:10.725226 2026] [security2:error] [pid 466512:tid 466690] [client 122.176.100.127:58044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZMiKGokixMSfKDOfdtwAAAkQ"]
[Tue Jul 21 08:34:10.725348 2026] [security2:error] [pid 466512:tid 466690] [client 122.176.100.127:58044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZMiKGokixMSfKDOfdtwAAAkQ"]
[Tue Jul 21 08:34:10.994823 2026] [security2:error] [pid 466512:tid 466752] [client 20.104.96.117:62706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/yawa.php"] [unique_id "al9ZMiKGokixMSfKDOfdvwAAAoI"]
[Tue Jul 21 08:34:11.142918 2026] [security2:error] [pid 466512:tid 466646] [client 207.175.122.57:53432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "bomtempo.eng.br"] [uri "/"] [unique_id "al9ZMyKGokixMSfKDOfdxgAAAhg"]
[Tue Jul 21 08:34:11.143718 2026] [security2:error] [pid 465652:tid 465894] [client 34.156.229.209:49430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "bomtempo.eng.br"] [uri "/"] [unique_id "al9ZMzzTqJoBC2Mw28-61QAAAPU"]
[Tue Jul 21 08:34:11.166766 2026] [security2:error] [pid 465652:tid 465908] [client 62.60.130.128:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ensinoja.com.br.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/"] [unique_id "al9ZMzzTqJoBC2Mw28-62AAAAQM"]
[Tue Jul 21 08:34:11.199360 2026] [security2:error] [pid 465652:tid 465907] [client 117.213.202.34:51345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZMzzTqJoBC2Mw28-62QAAAQI"]
[Tue Jul 21 08:34:11.199480 2026] [security2:error] [pid 465652:tid 465907] [client 117.213.202.34:51345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZMzzTqJoBC2Mw28-62QAAAQI"]
[Tue Jul 21 08:34:11.400375 2026] [security2:error] [pid 465652:tid 465819] [client 62.60.130.128:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ensinoja.com.br.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9ZMzzTqJoBC2Mw28-63AAAAKo"]
[Tue Jul 21 08:34:11.443415 2026] [security2:error] [pid 466512:tid 466670] [client 20.151.10.161:65518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9ZMyKGokixMSfKDOfdzgAAAjA"]
[Tue Jul 21 08:34:11.461566 2026] [security2:error] [pid 466512:tid 466750] [client 89.238.167.134:32942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9ZMyKGokixMSfKDOfdzwAAAoA"]
[Tue Jul 21 08:34:11.461663 2026] [security2:error] [pid 466512:tid 466750] [client 89.238.167.134:32942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9ZMyKGokixMSfKDOfdzwAAAoA"]
[Tue Jul 21 08:34:11.464739 2026] [security2:error] [pid 466512:tid 466658] [client 20.206.105.145:25479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/hypo.php"] [unique_id "al9ZMyKGokixMSfKDOfd0AAAAiQ"]
[Tue Jul 21 08:34:11.656174 2026] [security2:error] [pid 466512:tid 466740] [client 4.194.24.143:8442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/z.php"] [unique_id "al9ZMyKGokixMSfKDOfd1wAAAnY"]
[Tue Jul 21 08:34:11.681292 2026] [security2:error] [pid 466512:tid 466717] [client 223.181.60.88:5591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZMyKGokixMSfKDOfd2QAAAl8"]
[Tue Jul 21 08:34:11.681469 2026] [security2:error] [pid 466512:tid 466717] [client 223.181.60.88:5591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZMyKGokixMSfKDOfd2QAAAl8"]
[Tue Jul 21 08:34:11.732134 2026] [security2:error] [pid 465652:tid 465846] [client 137.97.59.154:21389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.59.97.137.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZMzzTqJoBC2Mw28-63wAAAMU"]
[Tue Jul 21 08:34:11.732255 2026] [security2:error] [pid 465652:tid 465846] [client 137.97.59.154:21389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZMzzTqJoBC2Mw28-63wAAAMU"]
[Tue Jul 21 08:34:11.801269 2026] [security2:error] [pid 466512:tid 466663] [client 65.21.113.253:34284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZMyKGokixMSfKDOfdygAAAik"]
[Tue Jul 21 08:34:11.853831 2026] [security2:error] [pid 466512:tid 466662] [client 20.104.96.117:46511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/js.php"] [unique_id "al9ZMyKGokixMSfKDOfd2wAAAig"]
[Tue Jul 21 08:34:11.959283 2026] [security2:error] [pid 466512:tid 466704] [client 20.197.195.24:6699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/wp-blog.php"] [unique_id "al9ZMyKGokixMSfKDOfd3AAAAlI"]
[Tue Jul 21 08:34:12.090119 2026] [autoindex:error] [pid 466512:tid 466669] [client 20.197.195.24:6755] AH01276: Cannot serve directory /home2/hg4int84/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:12.100751 2026] [security2:error] [pid 466512:tid 466678] [client 20.197.195.24:6755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/wp-content/admin.php"] [unique_id "al9ZNCKGokixMSfKDOfd4gAAAjg"]
[Tue Jul 21 08:34:12.146642 2026] [security2:error] [pid 466512:tid 466652] [client 74.249.245.134:9346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/ws83.php"] [unique_id "al9ZNCKGokixMSfKDOfd4wAAAh4"]
[Tue Jul 21 08:34:12.157897 2026] [security2:error] [pid 466512:tid 466761] [client 20.197.195.24:6735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/ms-edit.php"] [unique_id "al9ZNCKGokixMSfKDOfd5gAAAos"]
[Tue Jul 21 08:34:12.180848 2026] [security2:error] [pid 465652:tid 465818] [client 20.220.225.223:50269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/la.php"] [unique_id "al9ZNDzTqJoBC2Mw28-65wAAAKk"]
[Tue Jul 21 08:34:12.205300 2026] [security2:error] [pid 466512:tid 466764] [client 20.197.195.24:6775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/cgi-bin/index.php"] [unique_id "al9ZNCKGokixMSfKDOfd5wAAAo4"]
[Tue Jul 21 08:34:12.265332 2026] [security2:error] [pid 466512:tid 466653] [client 89.238.167.134:32956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9ZNCKGokixMSfKDOfd6QAAAh8"]
[Tue Jul 21 08:34:12.265454 2026] [security2:error] [pid 466512:tid 466653] [client 89.238.167.134:32956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9ZNCKGokixMSfKDOfd6QAAAh8"]
[Tue Jul 21 08:34:12.356541 2026] [security2:error] [pid 466512:tid 466681] [client 20.104.96.117:46540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/core.php"] [unique_id "al9ZNCKGokixMSfKDOfd6gAAAjs"]
[Tue Jul 21 08:34:12.591028 2026] [autoindex:error] [pid 466512:tid 466670] [client 20.197.195.24:6678] AH01276: Cannot serve directory /home2/hg4int84/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:12.600544 2026] [security2:error] [pid 466512:tid 466750] [client 20.197.195.24:6678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/BDKR28WP.php"] [unique_id "al9ZNCKGokixMSfKDOfeAwAAAoA"]
[Tue Jul 21 08:34:12.720642 2026] [security2:error] [pid 466512:tid 466760] [client 4.194.24.143:61049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbapoiocontabil.com.br"] [uri "/zk81cwqsdefault.php"] [unique_id "al9ZNCKGokixMSfKDOfeDgAAAoo"]
[Tue Jul 21 08:34:12.724497 2026] [security2:error] [pid 466512:tid 466666] [client 20.206.105.145:25501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/chosen.php"] [unique_id "al9ZNCKGokixMSfKDOfeDwAAAiw"]
[Tue Jul 21 08:34:12.752941 2026] [security2:error] [pid 466512:tid 466668] [client 20.104.96.117:46519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/19.php"] [unique_id "al9ZNCKGokixMSfKDOfeEQAAAi4"]
[Tue Jul 21 08:34:12.889286 2026] [autoindex:error] [pid 466512:tid 466715] [client 20.197.195.24:56280] AH01276: Cannot serve directory /home2/hg4int84/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:12.918012 2026] [authz_core:error] [pid 466512:tid 466676] [client 20.197.195.24:56280] AH01630: client denied by server configuration: /home2/hg4int84/public_html/wp-content/uploads/index.php
[Tue Jul 21 08:34:12.935140 2026] [security2:error] [pid 466512:tid 466747] [client 20.197.195.24:56280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/abcd.php"] [unique_id "al9ZNCKGokixMSfKDOfeFwAAAn0"]
[Tue Jul 21 08:34:13.005849 2026] [security2:error] [pid 465652:tid 465873] [client 20.197.195.24:56267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/file15.php"] [unique_id "al9ZNTzTqJoBC2Mw28-6-wAAAOA"]
[Tue Jul 21 08:34:13.201740 2026] [security2:error] [pid 465652:tid 465896] [client 20.197.195.24:6715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/jp.php"] [unique_id "al9ZNTzTqJoBC2Mw28-6_wAAAPc"]
[Tue Jul 21 08:34:13.240537 2026] [security2:error] [pid 466512:tid 466740] [client 195.49.128.211:53541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZNSKGokixMSfKDOfeNAAAAnY"]
[Tue Jul 21 08:34:13.240629 2026] [security2:error] [pid 466512:tid 466740] [client 195.49.128.211:53541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZNSKGokixMSfKDOfeNAAAAnY"]
[Tue Jul 21 08:34:13.299864 2026] [security2:error] [pid 465652:tid 465836] [client 20.104.96.117:46503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/inc.php"] [unique_id "al9ZNTzTqJoBC2Mw28-7BAAAALs"]
[Tue Jul 21 08:34:13.450505 2026] [security2:error] [pid 466512:tid 466765] [client 62.60.130.128:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ensinoja.com.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/"] [unique_id "al9ZNSKGokixMSfKDOfeNQAAAo8"]
[Tue Jul 21 08:34:13.508065 2026] [security2:error] [pid 466512:tid 466696] [client 20.220.225.223:50261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/nhvoanpl.php"] [unique_id "al9ZNSKGokixMSfKDOfeOQAAAko"]
[Tue Jul 21 08:34:13.647905 2026] [security2:error] [pid 466512:tid 466728] [client 20.197.195.24:6719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/f35.php"] [unique_id "al9ZNSKGokixMSfKDOfeRAAAAmo"]
[Tue Jul 21 08:34:13.657235 2026] [security2:error] [pid 466512:tid 466719] [client 65.21.113.253:34284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZNSKGokixMSfKDOfeLwAAAmE"]
[Tue Jul 21 08:34:13.660741 2026] [security2:error] [pid 466512:tid 466692] [client 20.206.105.145:25584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/file5.php"] [unique_id "al9ZNSKGokixMSfKDOfeRQAAAkY"]
[Tue Jul 21 08:34:13.696676 2026] [security2:error] [pid 465652:tid 465859] [client 20.220.225.223:20926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/pn.php"] [unique_id "al9ZNTzTqJoBC2Mw28-7DgAAANI"]
[Tue Jul 21 08:34:13.699930 2026] [security2:error] [pid 466512:tid 466739] [client 62.60.130.128:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ensinoja.com.franklucasdasilvagom1748259140823.0711679.meusitehostgator.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9ZNSKGokixMSfKDOfeRgAAAnU"]
[Tue Jul 21 08:34:13.790368 2026] [security2:error] [pid 465652:tid 465893] [client 20.104.96.117:46551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9ZNTzTqJoBC2Mw28-7FQAAAPQ"]
[Tue Jul 21 08:34:13.805410 2026] [security2:error] [pid 465652:tid 465747] [remote 81.173.115.7:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ZNTzTqJoBC2Mw28-7FgAA2l4"]
[Tue Jul 21 08:34:13.817105 2026] [security2:error] [pid 466512:tid 466684] [client 187.125.243.197:54464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZNSKGokixMSfKDOfeSQAAAj4"]
[Tue Jul 21 08:34:13.817499 2026] [security2:error] [pid 466512:tid 466684] [client 187.125.243.197:54464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZNSKGokixMSfKDOfeSQAAAj4"]
[Tue Jul 21 08:34:14.130738 2026] [security2:error] [pid 465652:tid 465792] [client 20.104.96.117:46578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9ZNjzTqJoBC2Mw28-7GQAAAI8"]
[Tue Jul 21 08:34:14.214810 2026] [security2:error] [pid 465652:tid 465842] [client 20.197.195.24:6680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/wp-load.php"] [unique_id "al9ZNjzTqJoBC2Mw28-7GgAAAME"]
[Tue Jul 21 08:34:14.229212 2026] [security2:error] [pid 466512:tid 466663] [client 20.220.225.223:50261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/inso.php"] [unique_id "al9ZNiKGokixMSfKDOfeSwAAAik"]
[Tue Jul 21 08:34:14.311887 2026] [security2:error] [pid 466512:tid 466759] [client 49.144.66.253:32202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZNiKGokixMSfKDOfeUQAAAok"]
[Tue Jul 21 08:34:14.312065 2026] [security2:error] [pid 466512:tid 466759] [client 49.144.66.253:32202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZNiKGokixMSfKDOfeUQAAAok"]
[Tue Jul 21 08:34:14.322213 2026] [security2:error] [pid 466512:tid 466690] [client 20.206.105.145:25514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/file.php"] [unique_id "al9ZNiKGokixMSfKDOfeUgAAAkQ"]
[Tue Jul 21 08:34:14.415879 2026] [security2:error] [pid 466512:tid 466583] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZNiKGokixMSfKDOfeVgACfUY"]
[Tue Jul 21 08:34:14.416034 2026] [security2:error] [pid 466512:tid 466747] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZNiKGokixMSfKDOfeVgACfUY"]
[Tue Jul 21 08:34:14.436020 2026] [security2:error] [pid 465652:tid 465897] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZNjzTqJoBC2Mw28-7GwAA-E4"]
[Tue Jul 21 08:34:14.539077 2026] [security2:error] [pid 465652:tid 465899] [client 20.104.96.117:62616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/ss.php"] [unique_id "al9ZNjzTqJoBC2Mw28-7IwAAAPo"]
[Tue Jul 21 08:34:14.737231 2026] [security2:error] [pid 465652:tid 465865] [client 5.38.115.39:51580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZNjzTqJoBC2Mw28-7KwAAANg"]
[Tue Jul 21 08:34:14.737379 2026] [security2:error] [pid 465652:tid 465865] [client 5.38.115.39:51580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZNjzTqJoBC2Mw28-7KwAAANg"]
[Tue Jul 21 08:34:14.790532 2026] [security2:error] [pid 465652:tid 465873] [client 20.197.195.24:6763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xyn.php"] [unique_id "al9ZNjzTqJoBC2Mw28-7LwAAAOA"]
[Tue Jul 21 08:34:14.848071 2026] [security2:error] [pid 466512:tid 466653] [client 74.249.245.134:54974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/g.php"] [unique_id "al9ZNiKGokixMSfKDOfeXQAAAh8"]
[Tue Jul 21 08:34:14.921760 2026] [access_compat:error] [pid 466512:tid 466664] [client 162.241.63.68:30544] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:34:15.144374 2026] [autoindex:error] [pid 466512:tid 466746] [client 20.197.195.24:6740] AH01276: Cannot serve directory /home2/hg4int84/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:15.208136 2026] [autoindex:error] [pid 466512:tid 466719] [client 20.197.195.24:6740] AH01276: Cannot serve directory /home2/hg4int84/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:15.213287 2026] [security2:error] [pid 466512:tid 466698] [client 20.197.195.24:6740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/ccc.php"] [unique_id "al9ZNyKGokixMSfKDOfeZwAAAkw"]
[Tue Jul 21 08:34:15.349126 2026] [security2:error] [pid 466512:tid 466684] [client 20.104.96.117:46496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/min.php"] [unique_id "al9ZNyKGokixMSfKDOfeawAAAj4"]
[Tue Jul 21 08:34:15.484320 2026] [security2:error] [pid 465652:tid 465838] [client 152.59.34.51:63499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZNzzTqJoBC2Mw28-7XQAAAL0"]
[Tue Jul 21 08:34:15.484438 2026] [security2:error] [pid 465652:tid 465838] [client 152.59.34.51:63499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZNzzTqJoBC2Mw28-7XQAAAL0"]
[Tue Jul 21 08:34:15.502146 2026] [security2:error] [pid 465652:tid 465793] [client 20.220.225.223:34740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9ZNzzTqJoBC2Mw28-7XgAAAJA"]
[Tue Jul 21 08:34:15.558760 2026] [security2:error] [pid 466512:tid 466670] [client 14.245.224.124:60694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZNyKGokixMSfKDOfebgAAAjA"]
[Tue Jul 21 08:34:15.558877 2026] [security2:error] [pid 466512:tid 466670] [client 14.245.224.124:60694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZNyKGokixMSfKDOfebgAAAjA"]
[Tue Jul 21 08:34:15.629824 2026] [security2:error] [pid 465652:tid 465846] [client 20.197.195.24:6690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/w.php"] [unique_id "al9ZNzzTqJoBC2Mw28-7agAAAMU"]
[Tue Jul 21 08:34:15.642088 2026] [security2:error] [pid 465652:tid 465886] [client 20.197.195.24:56263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9ZNzzTqJoBC2Mw28-7awAAAO0"]
[Tue Jul 21 08:34:15.654219 2026] [security2:error] [pid 466512:tid 466728] [client 65.21.113.253:34284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZNyKGokixMSfKDOfeYgAAAmo"]
[Tue Jul 21 08:34:15.655882 2026] [security2:error] [pid 466512:tid 466759] [client 20.197.195.24:6752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/FWAZ.php"] [unique_id "al9ZNyKGokixMSfKDOfecAAAAok"]
[Tue Jul 21 08:34:15.676753 2026] [security2:error] [pid 466512:tid 466647] [client 20.197.195.24:6761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/miru1.php"] [unique_id "al9ZNyKGokixMSfKDOfecQAAAhk"]
[Tue Jul 21 08:34:15.701457 2026] [security2:error] [pid 465652:tid 465839] [client 20.197.195.24:6769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/aa.php"] [unique_id "al9ZNzzTqJoBC2Mw28-7cQAAAL4"]
[Tue Jul 21 08:34:15.741504 2026] [security2:error] [pid 465652:tid 465792] [client 20.197.195.24:56219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/122.php"] [unique_id "al9ZNzzTqJoBC2Mw28-7dQAAAI8"]
[Tue Jul 21 08:34:15.774028 2026] [security2:error] [pid 466512:tid 466747] [client 20.206.105.145:25559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/aa2.php"] [unique_id "al9ZNyKGokixMSfKDOfedAAAAn0"]
[Tue Jul 21 08:34:15.823510 2026] [security2:error] [pid 466512:tid 466681] [client 5.31.193.106:1800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZNyKGokixMSfKDOfefQAAAjs"]
[Tue Jul 21 08:34:15.835081 2026] [security2:error] [pid 466512:tid 466681] [client 5.31.193.106:1800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZNyKGokixMSfKDOfefQAAAjs"]
[Tue Jul 21 08:34:15.842207 2026] [security2:error] [pid 465652:tid 465825] [client 185.213.175.37:41192] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bcsenepol.com.br"] [uri "/2015/08/01/benefits-of-iyengar-yoga/"] [unique_id "al9ZNzzTqJoBC2Mw28-7eQAAALA"]
[Tue Jul 21 08:34:15.880177 2026] [security2:error] [pid 466512:tid 466690] [client 78.47.98.55:58392] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9ZNyKGokixMSfKDOfeggAAAkQ"], referer: https://artetoner.com.br
[Tue Jul 21 08:34:15.914520 2026] [security2:error] [pid 466512:tid 466718] [client 20.197.195.24:6712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/get.php"] [unique_id "al9ZNyKGokixMSfKDOfegwAAAmA"]
[Tue Jul 21 08:34:15.999445 2026] [security2:error] [pid 466512:tid 466662] [client 185.213.175.37:41246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bcsenepol.com.br"] [uri "/2015/06/01/amazing-video-post/"] [unique_id "al9ZNyKGokixMSfKDOfehgAAAig"]
[Tue Jul 21 08:34:15.999577 2026] [security2:error] [pid 466512:tid 466662] [client 185.213.175.37:41246] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bcsenepol.com.br"] [uri "/2015/06/01/amazing-video-post/"] [unique_id "al9ZNyKGokixMSfKDOfehgAAAig"]
[Tue Jul 21 08:34:16.022002 2026] [security2:error] [pid 465652:tid 465896] [client 74.7.175.150:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.onkosclinica.com"] [uri "/index.php"] [unique_id "al9ZNjzTqJoBC2Mw28-7PQAAAPc"]
[Tue Jul 21 08:34:16.022899 2026] [security2:error] [pid 465652:tid 465830] [client 74.7.175.150:56110] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.onkosclinica.com"] [uri "/robots.txt"] [unique_id "al9ZNjzTqJoBC2Mw28-7OwAAtS0"]
[Tue Jul 21 08:34:16.135316 2026] [security2:error] [pid 465652:tid 465828] [client 20.206.105.145:21966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9ZODzTqJoBC2Mw28-7jAAAALM"]
[Tue Jul 21 08:34:16.204162 2026] [security2:error] [pid 466512:tid 466760] [client 20.197.195.24:6663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/as.php"] [unique_id "al9ZOCKGokixMSfKDOfeigAAAoo"]
[Tue Jul 21 08:34:16.285021 2026] [security2:error] [pid 465652:tid 465843] [client 103.151.46.103:49913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZODzTqJoBC2Mw28-7kgAAAMI"]
[Tue Jul 21 08:34:16.285173 2026] [security2:error] [pid 465652:tid 465843] [client 103.151.46.103:49913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZODzTqJoBC2Mw28-7kgAAAMI"]
[Tue Jul 21 08:34:16.285465 2026] [security2:error] [pid 466512:tid 466767] [client 20.104.96.117:46508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9ZOCKGokixMSfKDOfekAAAApE"]
[Tue Jul 21 08:34:16.394205 2026] [security2:error] [pid 466512:tid 466673] [client 20.206.105.145:25545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/ccou.php"] [unique_id "al9ZOCKGokixMSfKDOfesAAAAjM"]
[Tue Jul 21 08:34:16.485838 2026] [security2:error] [pid 465652:tid 465849] [client 20.151.10.161:65469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/puc.php"] [unique_id "al9ZODzTqJoBC2Mw28-7mgAAAMg"]
[Tue Jul 21 08:34:16.563400 2026] [security2:error] [pid 465652:tid 465877] [client 94.183.27.167:51006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.27.183.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "manosorvetes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZODzTqJoBC2Mw28-7mQAAAOQ"]
[Tue Jul 21 08:34:16.563586 2026] [security2:error] [pid 465652:tid 465877] [client 94.183.27.167:51006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "manosorvetes.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZODzTqJoBC2Mw28-7mQAAAOQ"]
[Tue Jul 21 08:34:16.632208 2026] [security2:error] [pid 466512:tid 466647] [client 20.197.195.24:6704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/ccou.php"] [unique_id "al9ZOCKGokixMSfKDOfesgAAAhk"]
[Tue Jul 21 08:34:16.650509 2026] [security2:error] [pid 465652:tid 465838] [client 20.104.96.117:62707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9ZODzTqJoBC2Mw28-7pQAAAL0"]
[Tue Jul 21 08:34:16.661207 2026] [security2:error] [pid 466512:tid 466747] [client 20.197.195.24:56261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/w3lls.php"] [unique_id "al9ZOCKGokixMSfKDOfeswAAAn0"]
[Tue Jul 21 08:34:16.683455 2026] [security2:error] [pid 466512:tid 466757] [client 20.197.195.24:6711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/test1.php"] [unique_id "al9ZOCKGokixMSfKDOfetgAAAoc"]
[Tue Jul 21 08:34:16.739453 2026] [security2:error] [pid 466512:tid 466731] [client 20.197.195.24:6692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/database.php"] [unique_id "al9ZOCKGokixMSfKDOfetwAAAm0"]
[Tue Jul 21 08:34:16.778590 2026] [security2:error] [pid 466512:tid 466701] [client 20.197.195.24:56317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/file.php"] [unique_id "al9ZOCKGokixMSfKDOfeuQAAAk8"]
[Tue Jul 21 08:34:16.853659 2026] [security2:error] [pid 466512:tid 466691] [client 20.197.195.24:56211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/file.php"] [unique_id "al9ZOCKGokixMSfKDOfe6AAAAkU"]
[Tue Jul 21 08:34:16.987440 2026] [security2:error] [pid 466512:tid 466664] [client 173.239.240.19:25807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "misterhempbrasil.com.br"] [uri "/wp-login.php"] [unique_id "al9ZOCKGokixMSfKDOfe4QAAAio"]
[Tue Jul 21 08:34:17.021458 2026] [security2:error] [pid 466512:tid 466734] [client 20.197.195.24:6695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/777.php"] [unique_id "al9ZOSKGokixMSfKDOfe7AAAAnA"]
[Tue Jul 21 08:34:17.141708 2026] [security2:error] [pid 465652:tid 465895] [client 20.104.96.117:62684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9ZOTzTqJoBC2Mw28-7sAAAAPY"]
[Tue Jul 21 08:34:17.142235 2026] [autoindex:error] [pid 465652:tid 465794] [client 34.203.201.194:42008] AH01276: Cannot serve directory /home1/imperd48/sabino-tracker.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:17.199662 2026] [security2:error] [pid 465652:tid 465846] [client 20.220.225.223:20922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/dr.php"] [unique_id "al9ZOTzTqJoBC2Mw28-7sQAAAMU"]
[Tue Jul 21 08:34:17.270538 2026] [autoindex:error] [pid 466512:tid 466673] [client 34.203.201.194:57372] AH01276: Cannot serve directory /home1/imperd48/sabino-tracker.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:17.281345 2026] [security2:error] [pid 465652:tid 465783] [client 152.59.181.104:62726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZOTzTqJoBC2Mw28-7sgAAAIY"]
[Tue Jul 21 08:34:17.281552 2026] [security2:error] [pid 465652:tid 465783] [client 152.59.181.104:62726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZOTzTqJoBC2Mw28-7sgAAAIY"]
[Tue Jul 21 08:34:17.501183 2026] [security2:error] [pid 466512:tid 466698] [client 65.21.113.253:34284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZOCKGokixMSfKDOfe6wAAAkw"]
[Tue Jul 21 08:34:17.515641 2026] [security2:error] [pid 466512:tid 466682] [client 74.249.245.134:44870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/CDX1.php"] [unique_id "al9ZOSKGokixMSfKDOffAwAAAjw"]
[Tue Jul 21 08:34:17.519563 2026] [security2:error] [pid 465652:tid 465806] [client 20.197.195.24:6724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/ssixta.php"] [unique_id "al9ZOTzTqJoBC2Mw28-7uAAAAJ0"]
[Tue Jul 21 08:34:17.676783 2026] [security2:error] [pid 466512:tid 466694] [client 20.206.105.145:25567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/dr.php"] [unique_id "al9ZOSKGokixMSfKDOffBwAAAkg"]
[Tue Jul 21 08:34:17.705029 2026] [security2:error] [pid 466512:tid 466724] [client 20.197.195.24:6706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/1c.php"] [unique_id "al9ZOSKGokixMSfKDOffCAAAAmY"]
[Tue Jul 21 08:34:17.827641 2026] [security2:error] [pid 466512:tid 466764] [client 20.197.195.24:6782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/test2.php"] [unique_id "al9ZOSKGokixMSfKDOffDQAAAo4"]
[Tue Jul 21 08:34:17.967821 2026] [security2:error] [pid 465652:tid 465884] [client 20.197.195.24:6666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/buy.php"] [unique_id "al9ZOTzTqJoBC2Mw28-7vQAAAOs"]
[Tue Jul 21 08:34:17.993261 2026] [security2:error] [pid 466512:tid 466714] [client 20.104.96.117:62596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9ZOSKGokixMSfKDOffGgAAAlw"]
[Tue Jul 21 08:34:18.272477 2026] [security2:error] [pid 465652:tid 465786] [client 74.249.245.134:55507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/403.php"] [unique_id "al9ZOjzTqJoBC2Mw28-7yAAAAIk"]
[Tue Jul 21 08:34:18.279783 2026] [security2:error] [pid 466512:tid 466659] [client 20.197.195.24:6753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/ssend.php"] [unique_id "al9ZOiKGokixMSfKDOffNwAAAiU"]
[Tue Jul 21 08:34:18.385301 2026] [security2:error] [pid 465652:tid 465838] [client 20.197.195.24:56220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/item.php"] [unique_id "al9ZOjzTqJoBC2Mw28-73QAAAL0"]
[Tue Jul 21 08:34:18.483900 2026] [security2:error] [pid 465652:tid 465837] [client 20.197.195.24:6717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/ss.php"] [unique_id "al9ZOjzTqJoBC2Mw28-7-wAAALw"]
[Tue Jul 21 08:34:18.606641 2026] [security2:error] [pid 466512:tid 466728] [client 20.197.195.24:56282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/hypo.php"] [unique_id "al9ZOiKGokixMSfKDOffrwAAAmo"]
[Tue Jul 21 08:34:18.647112 2026] [security2:error] [pid 465652:tid 465786] [client 20.104.96.117:46505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/albin.php"] [unique_id "al9ZOjzTqJoBC2Mw28-7_wAAAIk"]
[Tue Jul 21 08:34:18.728587 2026] [security2:error] [pid 465652:tid 465810] [client 74.249.245.134:54925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ftp.bcsenepol.com.br"] [uri "/api.php"] [unique_id "al9ZOjzTqJoBC2Mw28-8AwAAAKE"]
[Tue Jul 21 08:34:18.754733 2026] [security2:error] [pid 465652:tid 465843] [client 20.220.225.223:50881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/wpx.php"] [unique_id "al9ZOjzTqJoBC2Mw28-8BAAAAMI"]
[Tue Jul 21 08:34:18.783206 2026] [security2:error] [pid 466512:tid 466663] [client 202.179.75.202:33370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZOiKGokixMSfKDOffsgAAAik"]
[Tue Jul 21 08:34:18.783326 2026] [security2:error] [pid 466512:tid 466663] [client 202.179.75.202:33370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZOiKGokixMSfKDOffsgAAAik"]
[Tue Jul 21 08:34:18.963207 2026] [security2:error] [pid 465652:tid 465804] [client 20.206.105.145:25093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/file31.php"] [unique_id "al9ZOjzTqJoBC2Mw28-8CwAAAJs"]
[Tue Jul 21 08:34:19.041729 2026] [security2:error] [pid 466512:tid 466670] [client 20.197.195.24:6682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/users.php"] [unique_id "al9ZOyKGokixMSfKDOfftwAAAjA"]
[Tue Jul 21 08:34:19.158904 2026] [security2:error] [pid 465652:tid 465821] [client 212.32.69.197:63807] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "porondeeuestive.com.br"] [uri "/.env"] [unique_id "al9ZOzzTqJoBC2Mw28-8EgAAAKw"]
[Tue Jul 21 08:34:19.307010 2026] [security2:error] [pid 466512:tid 466658] [client 20.104.96.117:46466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/cilus.php"] [unique_id "al9ZOyKGokixMSfKDOffuwAAAiQ"]
[Tue Jul 21 08:34:19.382861 2026] [security2:error] [pid 465652:tid 465892] [client 20.206.105.145:21987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9ZOzzTqJoBC2Mw28-8FgAAAPM"]
[Tue Jul 21 08:34:19.467358 2026] [security2:error] [pid 465652:tid 465803] [client 20.197.195.24:6681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/177.php"] [unique_id "al9ZOzzTqJoBC2Mw28-8GQAAAJo"]
[Tue Jul 21 08:34:19.509006 2026] [security2:error] [pid 466512:tid 466678] [client 195.49.128.211:62134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZOyKGokixMSfKDOffvgAAAjg"]
[Tue Jul 21 08:34:19.509119 2026] [security2:error] [pid 466512:tid 466678] [client 195.49.128.211:62134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZOyKGokixMSfKDOffvgAAAjg"]
[Tue Jul 21 08:34:19.551195 2026] [security2:error] [pid 466512:tid 466724] [client 20.220.225.223:34719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/2x.php"] [unique_id "al9ZOyKGokixMSfKDOffvwAAAmY"]
[Tue Jul 21 08:34:19.619064 2026] [security2:error] [pid 466512:tid 466761] [client 65.21.113.253:34284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZOyKGokixMSfKDOffuQAAAos"]
[Tue Jul 21 08:34:19.765143 2026] [security2:error] [pid 465652:tid 465909] [client 20.104.96.117:46500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/gptsh.php"] [unique_id "al9ZOzzTqJoBC2Mw28-8JAAAAQQ"]
[Tue Jul 21 08:34:19.900404 2026] [security2:error] [pid 465652:tid 465844] [client 20.197.195.24:6696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/config.php"] [unique_id "al9ZOzzTqJoBC2Mw28-8JgAAAMM"]
[Tue Jul 21 08:34:19.956380 2026] [security2:error] [pid 466512:tid 466670] [client 20.206.105.145:25144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/file6.php"] [unique_id "al9ZOyKGokixMSfKDOffwQAAAjA"]
[Tue Jul 21 08:34:20.342366 2026] [security2:error] [pid 465652:tid 465882] [client 20.104.96.117:46507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/rithin.php"] [unique_id "al9ZPDzTqJoBC2Mw28-8MAAAAOk"]
[Tue Jul 21 08:34:20.553473 2026] [security2:error] [pid 466512:tid 466690] [client 20.197.195.24:6693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/gettest.php"] [unique_id "al9ZPCKGokixMSfKDOffzAAAAkQ"]
[Tue Jul 21 08:34:20.801684 2026] [security2:error] [pid 466512:tid 466728] [client 20.206.105.145:25517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/file15.php"] [unique_id "al9ZPCKGokixMSfKDOff0QAAAmo"]
[Tue Jul 21 08:34:20.860075 2026] [security2:error] [pid 466512:tid 466755] [client 20.206.105.145:22002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/x.php"] [unique_id "al9ZPCKGokixMSfKDOff1wAAAoU"]
[Tue Jul 21 08:34:20.933238 2026] [security2:error] [pid 465652:tid 465858] [client 20.197.195.24:56313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/min.php"] [unique_id "al9ZPDzTqJoBC2Mw28-8PAAAANE"]
[Tue Jul 21 08:34:20.981315 2026] [security2:error] [pid 466512:tid 466717] [client 20.197.195.24:56273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/dvjul.php"] [unique_id "al9ZPCKGokixMSfKDOff2QAAAl8"]
[Tue Jul 21 08:34:21.037748 2026] [security2:error] [pid 466512:tid 466719] [client 20.104.96.117:46488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/fffm.php"] [unique_id "al9ZPSKGokixMSfKDOff2wAAAmE"]
[Tue Jul 21 08:34:21.151031 2026] [security2:error] [pid 466512:tid 466706] [client 104.28.249.138:41040] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "somoszeroum.com.br"] [uri "/.git-credentials"] [unique_id "al9ZPSKGokixMSfKDOff4gAAAlQ"]
[Tue Jul 21 08:34:21.170077 2026] [security2:error] [pid 465652:tid 465792] [client 104.28.249.138:41053] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "somoszeroum.com.br"] [uri "/z9x8c7v6b5-debug-trigger-somoszeroum.com.br"] [unique_id "al9ZPTzTqJoBC2Mw28-8RAAAAI8"]
[Tue Jul 21 08:34:21.239688 2026] [security2:error] [pid 465652:tid 465795] [client 122.176.100.127:58540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZPTzTqJoBC2Mw28-8SAAAAJI"]
[Tue Jul 21 08:34:21.239920 2026] [security2:error] [pid 465652:tid 465795] [client 122.176.100.127:58540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZPTzTqJoBC2Mw28-8SAAAAJI"]
[Tue Jul 21 08:34:21.316013 2026] [security2:error] [pid 466512:tid 466664] [client 61.1.167.83:59606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZPSKGokixMSfKDOff6gAAAio"]
[Tue Jul 21 08:34:21.316215 2026] [security2:error] [pid 466512:tid 466664] [client 61.1.167.83:59606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZPSKGokixMSfKDOff6gAAAio"]
[Tue Jul 21 08:34:21.408944 2026] [security2:error] [pid 466512:tid 466721] [client 20.197.195.24:6730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/biufile.php"] [unique_id "al9ZPSKGokixMSfKDOff6wAAAmM"]
[Tue Jul 21 08:34:21.451134 2026] [security2:error] [pid 465652:tid 465786] [client 20.104.96.117:46480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/dfre.php"] [unique_id "al9ZPTzTqJoBC2Mw28-8SwAAAIk"]
[Tue Jul 21 08:34:21.540982 2026] [security2:error] [pid 466512:tid 466593] [remote 54.64.35.240:44922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.35.64.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9ZPCKGokixMSfKDOffywACeVA"]
[Tue Jul 21 08:34:21.603441 2026] [security2:error] [pid 466512:tid 466526] [remote 159.65.81.207:54532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "voweltravel.com.br"] [uri "/wp-login.php"] [unique_id "al9ZPSKGokixMSfKDOff8gACNQ0"]
[Tue Jul 21 08:34:21.656122 2026] [security2:error] [pid 465652:tid 465784] [client 223.181.60.88:1290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZPTzTqJoBC2Mw28-8TQAAAIc"]
[Tue Jul 21 08:34:21.656324 2026] [security2:error] [pid 465652:tid 465784] [client 223.181.60.88:1290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZPTzTqJoBC2Mw28-8TQAAAIc"]
[Tue Jul 21 08:34:21.691717 2026] [security2:error] [pid 466512:tid 466663] [client 117.213.202.34:51951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZPSKGokixMSfKDOff-AAAAik"]
[Tue Jul 21 08:34:21.691930 2026] [security2:error] [pid 466512:tid 466663] [client 117.213.202.34:51951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZPSKGokixMSfKDOff-AAAAik"]
[Tue Jul 21 08:34:21.767375 2026] [security2:error] [pid 466512:tid 466573] [remote 97.74.87.194:43584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "growe-ag.jaypi.com.br"] [uri "/wp-login.php"] [unique_id "al9ZPSKGokixMSfKDOfgCgACdjw"]
[Tue Jul 21 08:34:21.791665 2026] [security2:error] [pid 466512:tid 466764] [client 20.104.96.117:46527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/wp-happy.php"] [unique_id "al9ZPSKGokixMSfKDOfgCwAAAo4"]
[Tue Jul 21 08:34:21.832859 2026] [security2:error] [pid 466512:tid 466734] [client 65.21.113.253:34284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZPSKGokixMSfKDOff6QAAAnA"]
[Tue Jul 21 08:34:22.013096 2026] [security2:error] [pid 466512:tid 466668] [client 20.197.195.24:6718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/av.php"] [unique_id "al9ZPiKGokixMSfKDOfgEAAAAi4"]
[Tue Jul 21 08:34:22.186274 2026] [security2:error] [pid 465652:tid 465879] [client 20.206.105.145:25502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/jp.php"] [unique_id "al9ZPjzTqJoBC2Mw28-8YgAAAOY"]
[Tue Jul 21 08:34:22.192323 2026] [security2:error] [pid 465652:tid 465906] [client 20.104.96.117:46565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/fpr4.php"] [unique_id "al9ZPjzTqJoBC2Mw28-8YwAAAQE"]
[Tue Jul 21 08:34:22.306418 2026] [security2:error] [pid 465652:tid 465788] [client 14.97.58.74:37696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZPjzTqJoBC2Mw28-8aQAAAIs"]
[Tue Jul 21 08:34:22.306647 2026] [security2:error] [pid 465652:tid 465788] [client 14.97.58.74:37696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZPjzTqJoBC2Mw28-8aQAAAIs"]
[Tue Jul 21 08:34:22.633370 2026] [security2:error] [pid 465652:tid 465697] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZPjzTqJoBC2Mw28-8bQAAyCw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:22.716559 2026] [security2:error] [pid 465652:tid 465795] [client 20.104.96.117:46485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/file88.php"] [unique_id "al9ZPjzTqJoBC2Mw28-8cwAAAJI"]
[Tue Jul 21 08:34:22.744758 2026] [security2:error] [pid 465652:tid 465747] [remote 154.61.75.100:58592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carrosselbuique.com.br"] [uri "/wp-login.php"] [unique_id "al9ZPjzTqJoBC2Mw28-8dQAAlV4"]
[Tue Jul 21 08:34:22.780133 2026] [security2:error] [pid 465652:tid 465753] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZPjzTqJoBC2Mw28-8eAAAiWQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:22.829351 2026] [security2:error] [pid 466512:tid 466759] [client 20.197.195.24:6714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/coffexium.php"] [unique_id "al9ZPiKGokixMSfKDOfgHAAAAok"]
[Tue Jul 21 08:34:22.903356 2026] [security2:error] [pid 466512:tid 466735] [client 20.206.105.145:25553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/f35.php"] [unique_id "al9ZPiKGokixMSfKDOfgJAAAAnE"]
[Tue Jul 21 08:34:22.935004 2026] [security2:error] [pid 466512:tid 466764] [client 20.197.192.193:65161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/jj.php"] [unique_id "al9ZPiKGokixMSfKDOfgKAAAAo4"]
[Tue Jul 21 08:34:23.126417 2026] [security2:error] [pid 466512:tid 466747] [client 20.104.96.117:46531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/ccc.php"] [unique_id "al9ZPyKGokixMSfKDOfgMQAAAn0"]
[Tue Jul 21 08:34:23.126839 2026] [security2:error] [pid 465652:tid 465837] [client 114.119.153.84:35243] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "odontoclinicms.com.br"] [uri "/category/science/"] [unique_id "al9ZPzzTqJoBC2Mw28-8ggAAALw"], referer: https://odontoclinicms.com.br/regular-dental-care-make-your-smile-brighter/
[Tue Jul 21 08:34:23.354209 2026] [security2:error] [pid 466512:tid 466731] [client 20.197.195.24:6729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/core.php"] [unique_id "al9ZPyKGokixMSfKDOfgOQAAAm0"]
[Tue Jul 21 08:34:23.404078 2026] [security2:error] [pid 466512:tid 466663] [client 20.206.105.145:25513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wp-load.php"] [unique_id "al9ZPyKGokixMSfKDOfgOwAAAik"]
[Tue Jul 21 08:34:23.464140 2026] [security2:error] [pid 465652:tid 465782] [client 20.220.225.223:34715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/kq1.php"] [unique_id "al9ZPzzTqJoBC2Mw28-8ngAAAIU"]
[Tue Jul 21 08:34:23.497306 2026] [security2:error] [pid 465652:tid 465825] [client 213.152.186.163:58174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZPzzTqJoBC2Mw28-8nwAAALA"]
[Tue Jul 21 08:34:23.497413 2026] [security2:error] [pid 465652:tid 465825] [client 213.152.186.163:58174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZPzzTqJoBC2Mw28-8nwAAALA"]
[Tue Jul 21 08:34:23.509762 2026] [security2:error] [pid 465652:tid 465866] [client 20.197.192.193:65215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/dragonshell.php"] [unique_id "al9ZPzzTqJoBC2Mw28-8oAAAANk"]
[Tue Jul 21 08:34:23.512102 2026] [security2:error] [pid 465652:tid 465895] [client 20.104.96.117:62681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/777.php"] [unique_id "al9ZPzzTqJoBC2Mw28-8oQAAAPY"]
[Tue Jul 21 08:34:23.574592 2026] [security2:error] [pid 465652:tid 465879] [client 185.213.175.37:18484] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "beezar.com.br"] [uri "/localizacao.b9fb93bd.js"] [unique_id "al9ZPzzTqJoBC2Mw28-8ogAAAOY"]
[Tue Jul 21 08:34:23.616392 2026] [security2:error] [pid 466512:tid 466621] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZPyKGokixMSfKDOfgQQACSmw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:23.617680 2026] [security2:error] [pid 465652:tid 465759] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZPjzTqJoBC2Mw28-8bwAAymo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:23.633409 2026] [proxy:error] [pid 465652:tid 465890] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:23.633469 2026] [proxy_http:error] [pid 465652:tid 465890] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:23.634237 2026] [proxy:error] [pid 465652:tid 465890] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:23.634274 2026] [proxy_http:error] [pid 465652:tid 465890] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:23.694262 2026] [security2:error] [pid 465652:tid 465666] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZPjzTqJoBC2Mw28-8agAA6A0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:23.782500 2026] [security2:error] [pid 465652:tid 465824] [client 185.213.175.37:18500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "beezar.com.br"] [uri "/sitemap.xml"] [unique_id "al9ZPzzTqJoBC2Mw28-8qwAAAK8"]
[Tue Jul 21 08:34:23.782587 2026] [security2:error] [pid 465652:tid 465824] [client 185.213.175.37:18500] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "beezar.com.br"] [uri "/sitemap.xml"] [unique_id "al9ZPzzTqJoBC2Mw28-8qwAAAK8"]
[Tue Jul 21 08:34:23.789482 2026] [security2:error] [pid 465652:tid 465692] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZPzzTqJoBC2Mw28-8rQAApSc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:23.852364 2026] [security2:error] [pid 466512:tid 466645] [client 195.49.128.211:54140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZPyKGokixMSfKDOfgSQAAAhc"]
[Tue Jul 21 08:34:23.852470 2026] [security2:error] [pid 466512:tid 466645] [client 195.49.128.211:54140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZPyKGokixMSfKDOfgSQAAAhc"]
[Tue Jul 21 08:34:23.853683 2026] [security2:error] [pid 466512:tid 466690] [client 65.21.113.253:34284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZPyKGokixMSfKDOfgOAAAAkQ"]
[Tue Jul 21 08:34:23.970268 2026] [security2:error] [pid 465652:tid 465872] [client 20.197.195.24:6747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/als.php"] [unique_id "al9ZPzzTqJoBC2Mw28-8sQAAAN8"]
[Tue Jul 21 08:34:24.016364 2026] [security2:error] [pid 465652:tid 465889] [client 20.104.96.117:62642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/for.php"] [unique_id "al9ZQDzTqJoBC2Mw28-8sgAAAPA"]
[Tue Jul 21 08:34:24.020852 2026] [security2:error] [pid 466512:tid 466598] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZQCKGokixMSfKDOfgTwACjlU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:24.085356 2026] [security2:error] [pid 465652:tid 465766] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZQDzTqJoBC2Mw28-8tAAAtXE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:24.104518 2026] [security2:error] [pid 465652:tid 465674] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZQDzTqJoBC2Mw28-8twAAxBU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:24.243850 2026] [security2:error] [pid 465652:tid 465750] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZQDzTqJoBC2Mw28-8vQAAw2E"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:24.283372 2026] [security2:error] [pid 466512:tid 466765] [client 187.125.243.197:54994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZQCKGokixMSfKDOfgVAAAAo8"]
[Tue Jul 21 08:34:24.283542 2026] [security2:error] [pid 466512:tid 466765] [client 187.125.243.197:54994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZQCKGokixMSfKDOfgVAAAAo8"]
[Tue Jul 21 08:34:24.415397 2026] [security2:error] [pid 466512:tid 466669] [client 20.104.96.117:64192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/ssla.php"] [unique_id "al9ZQCKGokixMSfKDOfgVwAAAi8"]
[Tue Jul 21 08:34:24.467312 2026] [security2:error] [pid 466512:tid 466516] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZQCKGokixMSfKDOfgWQACJAM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:24.480208 2026] [security2:error] [pid 465652:tid 465763] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZQDzTqJoBC2Mw28-8xQAAnG4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:24.496516 2026] [security2:error] [pid 465652:tid 465678] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZQDzTqJoBC2Mw28-8xgAAnRk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:24.517046 2026] [security2:error] [pid 466512:tid 466746] [client 20.197.195.24:56269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/simple.php"] [unique_id "al9ZQCKGokixMSfKDOfgXAAAAnw"]
[Tue Jul 21 08:34:24.568959 2026] [security2:error] [pid 465652:tid 465831] [client 20.151.10.161:65426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/themes.php"] [unique_id "al9ZQDzTqJoBC2Mw28-8xwAAALY"]
[Tue Jul 21 08:34:24.599461 2026] [security2:error] [pid 466512:tid 466767] [client 104.28.249.138:41074] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "somoszeroum.com.br"] [uri "/graphql"] [unique_id "al9ZQCKGokixMSfKDOfgXQAAApE"]
[Tue Jul 21 08:34:24.659076 2026] [security2:error] [pid 465652:tid 465691] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZQDzTqJoBC2Mw28-8ygAA6SY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:24.755977 2026] [security2:error] [pid 466512:tid 466659] [client 20.197.195.24:56196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/init.php"] [unique_id "al9ZQCKGokixMSfKDOfgYAAAAiU"]
[Tue Jul 21 08:34:24.794576 2026] [security2:error] [pid 466512:tid 466664] [client 20.220.225.223:50888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/berlin.php"] [unique_id "al9ZQCKGokixMSfKDOfgYQAAAio"]
[Tue Jul 21 08:34:24.864206 2026] [security2:error] [pid 466512:tid 466640] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZQCKGokixMSfKDOfgYwACSn8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:24.897218 2026] [security2:error] [pid 465652:tid 465685] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZQDzTqJoBC2Mw28-80QAA3CA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:24.932572 2026] [security2:error] [pid 466512:tid 466555] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZQCKGokixMSfKDOfgZQACTyo"]
[Tue Jul 21 08:34:24.932713 2026] [security2:error] [pid 466512:tid 466701] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZQCKGokixMSfKDOfgZQACTyo"]
[Tue Jul 21 08:34:24.953768 2026] [security2:error] [pid 465652:tid 465815] [client 104.28.249.138:41048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "somoszeroum.com.br"] [uri "/.env"] [unique_id "al9ZQDzTqJoBC2Mw28-80gAAAKY"]
[Tue Jul 21 08:34:24.961335 2026] [security2:error] [pid 466512:tid 466716] [client 20.104.96.117:46547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.oticapersona.com.br"] [uri "/zc-131.php"] [unique_id "al9ZQCKGokixMSfKDOfgZgAAAl4"]
[Tue Jul 21 08:34:25.062751 2026] [security2:error] [pid 465652:tid 465774] [remote 160.191.89.47:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.89.191.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ZQTzTqJoBC2Mw28-80wAAink"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:34:25.121000 2026] [security2:error] [pid 466512:tid 466747] [client 5.38.115.39:52089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZQSKGokixMSfKDOfgaQAAAn0"]
[Tue Jul 21 08:34:25.121127 2026] [security2:error] [pid 466512:tid 466747] [client 5.38.115.39:52089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZQSKGokixMSfKDOfgaQAAAn0"]
[Tue Jul 21 08:34:25.130068 2026] [security2:error] [pid 466512:tid 466690] [client 20.197.195.24:56310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/fpwch.php"] [unique_id "al9ZQSKGokixMSfKDOfgagAAAkQ"]
[Tue Jul 21 08:34:25.221040 2026] [security2:error] [pid 466512:tid 466717] [client 20.206.105.145:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9ZQSKGokixMSfKDOfgcAAAAl8"]
[Tue Jul 21 08:34:25.227363 2026] [security2:error] [pid 466512:tid 466740] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZQSKGokixMSfKDOfgawACdkY"]
[Tue Jul 21 08:34:25.437930 2026] [security2:error] [pid 466512:tid 466704] [client 49.144.66.253:32643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZQSKGokixMSfKDOfgeAAAAlI"]
[Tue Jul 21 08:34:25.438182 2026] [security2:error] [pid 466512:tid 466704] [client 49.144.66.253:32643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZQSKGokixMSfKDOfgeAAAAlI"]
[Tue Jul 21 08:34:25.443900 2026] [security2:error] [pid 465652:tid 465899] [client 20.197.195.24:56319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/domvf.php"] [unique_id "al9ZQTzTqJoBC2Mw28-83QAAAPo"]
[Tue Jul 21 08:34:25.483360 2026] [security2:error] [pid 466512:tid 466743] [client 74.249.245.134:32485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/inputs.php"] [unique_id "al9ZQSKGokixMSfKDOfgeQAAAnk"]
[Tue Jul 21 08:34:25.874543 2026] [security2:error] [pid 465652:tid 465861] [client 20.206.105.145:25507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9ZQTzTqJoBC2Mw28-85AAAANQ"]
[Tue Jul 21 08:34:25.970770 2026] [security2:error] [pid 466512:tid 466725] [client 104.28.249.138:41081] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "somoszeroum.com.br"] [uri "/api/graphql"] [unique_id "al9ZQSKGokixMSfKDOfgigAAAmc"]
[Tue Jul 21 08:34:26.114661 2026] [security2:error] [pid 466512:tid 466684] [client 20.197.195.24:6739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/wp.php"] [unique_id "al9ZQiKGokixMSfKDOfgiwAAAj4"]
[Tue Jul 21 08:34:26.161360 2026] [security2:error] [pid 465652:tid 465865] [client 103.151.46.103:50444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZQjzTqJoBC2Mw28-86wAAANg"]
[Tue Jul 21 08:34:26.161468 2026] [security2:error] [pid 465652:tid 465865] [client 103.151.46.103:50444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZQjzTqJoBC2Mw28-86wAAANg"]
[Tue Jul 21 08:34:26.265314 2026] [security2:error] [pid 466512:tid 466746] [client 152.59.34.51:64009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZQiKGokixMSfKDOfgjgAAAnw"]
[Tue Jul 21 08:34:26.265567 2026] [security2:error] [pid 466512:tid 466746] [client 152.59.34.51:64009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZQiKGokixMSfKDOfgjgAAAnw"]
[Tue Jul 21 08:34:26.300925 2026] [security2:error] [pid 465652:tid 465780] [remote 192.241.143.148:58064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ffstrength.com"] [uri "/wp-login.php"] [unique_id "al9ZQjzTqJoBC2Mw28-87QAAtH8"]
[Tue Jul 21 08:34:26.378035 2026] [security2:error] [pid 465652:tid 465830] [client 14.245.224.124:61149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZQjzTqJoBC2Mw28-87wAAALU"]
[Tue Jul 21 08:34:26.378258 2026] [security2:error] [pid 465652:tid 465830] [client 14.245.224.124:61149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZQjzTqJoBC2Mw28-87wAAALU"]
[Tue Jul 21 08:34:26.470405 2026] [security2:error] [pid 466512:tid 466690] [client 20.197.195.24:6716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/class.php"] [unique_id "al9ZQiKGokixMSfKDOfgkAAAAkQ"]
[Tue Jul 21 08:34:26.532866 2026] [security2:error] [pid 465652:tid 465860] [client 20.206.105.145:25149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wp-links.php"] [unique_id "al9ZQjzTqJoBC2Mw28-8-AAAANM"]
[Tue Jul 21 08:34:26.623360 2026] [security2:error] [pid 466512:tid 466717] [client 20.220.225.223:34704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/zzz.php"] [unique_id "al9ZQiKGokixMSfKDOfgkQAAAl8"]
[Tue Jul 21 08:34:26.840801 2026] [proxy:error] [pid 465652:tid 465815] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:26.840900 2026] [proxy_http:error] [pid 465652:tid 465815] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:26.842356 2026] [proxy:error] [pid 465652:tid 465815] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:26.842405 2026] [proxy_http:error] [pid 465652:tid 465815] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:26.940561 2026] [security2:error] [pid 466512:tid 466669] [client 20.197.195.24:56272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/echkm.php"] [unique_id "al9ZQiKGokixMSfKDOfglgAAAi8"]
[Tue Jul 21 08:34:26.957163 2026] [security2:error] [pid 466512:tid 466743] [client 20.206.105.145:21970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/j260624_13.php"] [unique_id "al9ZQiKGokixMSfKDOfgmAAAAnk"]
[Tue Jul 21 08:34:26.998978 2026] [security2:error] [pid 465652:tid 465876] [client 104.28.249.138:41351] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "somoszeroum.com.br"] [uri "/.env.bak"] [unique_id "al9ZQjzTqJoBC2Mw28-9DQAAAOM"]
[Tue Jul 21 08:34:27.086193 2026] [security2:error] [pid 466512:tid 466686] [client 20.197.192.193:65194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/wp-mt.php"] [unique_id "al9ZQyKGokixMSfKDOfgmwAAAkA"]
[Tue Jul 21 08:34:27.136677 2026] [security2:error] [pid 466512:tid 466738] [client 20.197.195.24:56200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/lib.php"] [unique_id "al9ZQyKGokixMSfKDOfgnAAAAnQ"]
[Tue Jul 21 08:34:27.356016 2026] [security2:error] [pid 465652:tid 465811] [client 104.28.249.138:41047] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "somoszeroum.com.br"] [uri "/.env.old"] [unique_id "al9ZQzzTqJoBC2Mw28-9DwAAAKI"]
[Tue Jul 21 08:34:27.564953 2026] [security2:error] [pid 465652:tid 465889] [client 173.239.240.73:20771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/wp-login.php"] [unique_id "al9ZQjzTqJoBC2Mw28-8-QAAAPA"]
[Tue Jul 21 08:34:27.590775 2026] [security2:error] [pid 465652:tid 465867] [client 20.206.105.145:39271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9ZQzzTqJoBC2Mw28-9FQAAANo"]
[Tue Jul 21 08:34:27.620047 2026] [security2:error] [pid 466512:tid 466747] [client 20.197.195.24:6700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/login.php"] [unique_id "al9ZQyKGokixMSfKDOfgpwAAAn0"]
[Tue Jul 21 08:34:27.767217 2026] [security2:error] [pid 465652:tid 465804] [client 20.206.105.145:25572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/solo1.php"] [unique_id "al9ZQzzTqJoBC2Mw28-9FwAAAJs"]
[Tue Jul 21 08:34:27.780820 2026] [security2:error] [pid 465652:tid 465812] [client 104.28.249.138:41048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "somoszeroum.com.br"] [uri "/.env.backup"] [unique_id "al9ZQzzTqJoBC2Mw28-9GAAAAKM"]
[Tue Jul 21 08:34:27.891229 2026] [security2:error] [pid 465652:tid 465845] [client 104.28.249.138:41092] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "somoszeroum.com.br"] [uri "/v1/graphql"] [unique_id "al9ZQzzTqJoBC2Mw28-9GgAAAMQ"]
[Tue Jul 21 08:34:27.977368 2026] [security2:error] [pid 466512:tid 466681] [client 20.220.225.223:34703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/wicked.php"] [unique_id "al9ZQyKGokixMSfKDOfgrgAAAjs"]
[Tue Jul 21 08:34:27.981963 2026] [security2:error] [pid 466512:tid 466669] [client 20.197.195.24:6721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/a2.php"] [unique_id "al9ZQyKGokixMSfKDOfgrwAAAi8"]
[Tue Jul 21 08:34:28.127756 2026] [security2:error] [pid 466512:tid 466761] [client 104.28.249.138:41068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "somoszeroum.com.br"] [uri "/api/.env"] [unique_id "al9ZRCKGokixMSfKDOfgsAAAAos"]
[Tue Jul 21 08:34:28.309621 2026] [security2:error] [pid 465652:tid 465799] [client 104.28.249.138:41093] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "somoszeroum.com.br"] [uri "/backend/.env"] [unique_id "al9ZRDzTqJoBC2Mw28-9IAAAAJY"]
[Tue Jul 21 08:34:28.326718 2026] [proxy:error] [pid 466512:tid 466760] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:28.326831 2026] [proxy_http:error] [pid 466512:tid 466760] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:28.328648 2026] [proxy:error] [pid 466512:tid 466760] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:28.328710 2026] [proxy_http:error] [pid 466512:tid 466760] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:28.363328 2026] [security2:error] [pid 466512:tid 466659] [client 20.220.225.223:50288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/billur.php"] [unique_id "al9ZRCKGokixMSfKDOfgtAAAAiU"]
[Tue Jul 21 08:34:28.435263 2026] [security2:error] [pid 466512:tid 466684] [client 152.59.181.104:63164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZRCKGokixMSfKDOfgtwAAAj4"]
[Tue Jul 21 08:34:28.435381 2026] [security2:error] [pid 466512:tid 466684] [client 152.59.181.104:63164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZRCKGokixMSfKDOfgtwAAAj4"]
[Tue Jul 21 08:34:28.439645 2026] [security2:error] [pid 466512:tid 466587] [remote 72.167.132.114:41494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roha.life"] [uri "/wp-login.php"] [unique_id "al9ZRCKGokixMSfKDOfgtgACZ0o"]
[Tue Jul 21 08:34:28.540734 2026] [security2:error] [pid 465652:tid 465882] [client 104.28.249.138:41107] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "somoszeroum.com.br"] [uri "/config/.env"] [unique_id "al9ZRDzTqJoBC2Mw28-9JwAAAOk"]
[Tue Jul 21 08:34:28.639558 2026] [security2:error] [pid 466512:tid 466756] [client 20.197.195.24:56278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/d61.php"] [unique_id "al9ZRCKGokixMSfKDOfgvwAAAoY"]
[Tue Jul 21 08:34:28.727512 2026] [security2:error] [pid 465652:tid 465794] [client 104.28.249.138:41048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "somoszeroum.com.br"] [uri "/service-account.json"] [unique_id "al9ZRDzTqJoBC2Mw28-9KgAAAJE"]
[Tue Jul 21 08:34:28.727603 2026] [security2:error] [pid 465652:tid 465794] [client 104.28.249.138:41048] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "somoszeroum.com.br"] [uri "/service-account.json"] [unique_id "al9ZRDzTqJoBC2Mw28-9KgAAAJE"]
[Tue Jul 21 08:34:28.979857 2026] [security2:error] [pid 465652:tid 465832] [client 20.197.195.24:6656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/info.php"] [unique_id "al9ZRDzTqJoBC2Mw28-9LgAAALc"]
[Tue Jul 21 08:34:29.063238 2026] [proxy:error] [pid 465652:tid 465823] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:29.063305 2026] [proxy_http:error] [pid 465652:tid 465823] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:29.063753 2026] [proxy:error] [pid 465652:tid 465823] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:29.063775 2026] [proxy_http:error] [pid 465652:tid 465823] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:29.141864 2026] [security2:error] [pid 466512:tid 466638] [remote 100.42.189.89:35818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ZRSKGokixMSfKDOfgyQACbH0"]
[Tue Jul 21 08:34:29.170907 2026] [security2:error] [pid 465652:tid 465782] [client 20.197.195.24:56277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/11.php"] [unique_id "al9ZRTzTqJoBC2Mw28-9MwAAAIU"]
[Tue Jul 21 08:34:29.198872 2026] [security2:error] [pid 466512:tid 466760] [client 20.206.105.145:39295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/x.php"] [unique_id "al9ZRSKGokixMSfKDOfgygAAAoo"]
[Tue Jul 21 08:34:29.529137 2026] [security2:error] [pid 465652:tid 465811] [client 213.152.186.163:58932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9ZRTzTqJoBC2Mw28-9OQAAAKI"]
[Tue Jul 21 08:34:29.529250 2026] [security2:error] [pid 465652:tid 465811] [client 213.152.186.163:58932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9ZRTzTqJoBC2Mw28-9OQAAAKI"]
[Tue Jul 21 08:34:29.660652 2026] [security2:error] [pid 466512:tid 466659] [client 202.179.75.202:36302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZRSKGokixMSfKDOfgzwAAAiU"]
[Tue Jul 21 08:34:29.660765 2026] [security2:error] [pid 466512:tid 466659] [client 202.179.75.202:36302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZRSKGokixMSfKDOfgzwAAAiU"]
[Tue Jul 21 08:34:29.778292 2026] [proxy:error] [pid 465652:tid 465872] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:29.778359 2026] [proxy_http:error] [pid 465652:tid 465872] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:29.778799 2026] [proxy:error] [pid 465652:tid 465872] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:29.778828 2026] [proxy_http:error] [pid 465652:tid 465872] [client 2.57.122.202:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:29.903280 2026] [security2:error] [pid 465652:tid 465845] [client 20.197.195.24:56307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/v2.php"] [unique_id "al9ZRTzTqJoBC2Mw28-9QwAAAMQ"]
[Tue Jul 21 08:34:30.164369 2026] [security2:error] [pid 465652:tid 465858] [client 195.49.128.211:62758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZRjzTqJoBC2Mw28-9SQAAANE"]
[Tue Jul 21 08:34:30.164487 2026] [security2:error] [pid 465652:tid 465858] [client 195.49.128.211:62758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZRjzTqJoBC2Mw28-9SQAAANE"]
[Tue Jul 21 08:34:30.282444 2026] [security2:error] [pid 466512:tid 466717] [client 74.249.245.134:33333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/ms-edit.php"] [unique_id "al9ZRiKGokixMSfKDOfg1gAAAl8"]
[Tue Jul 21 08:34:30.463069 2026] [security2:error] [pid 465652:tid 465900] [client 20.206.105.145:22096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/d62.php"] [unique_id "al9ZRjzTqJoBC2Mw28-9TwAAAPs"]
[Tue Jul 21 08:34:30.464521 2026] [security2:error] [pid 465652:tid 465821] [client 20.206.105.145:39241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/j260624_13.php"] [unique_id "al9ZRjzTqJoBC2Mw28-9UAAAAKw"]
[Tue Jul 21 08:34:30.551412 2026] [security2:error] [pid 465652:tid 465794] [client 20.197.195.24:6742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/panel.php"] [unique_id "al9ZRjzTqJoBC2Mw28-9UgAAAJE"]
[Tue Jul 21 08:34:30.720706 2026] [security2:error] [pid 466512:tid 466743] [client 20.206.105.145:25548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/sixxis.php"] [unique_id "al9ZRiKGokixMSfKDOfg2QAAAnk"]
[Tue Jul 21 08:34:30.774514 2026] [security2:error] [pid 466512:tid 466761] [client 20.197.195.24:6754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/dex.php"] [unique_id "al9ZRiKGokixMSfKDOfg2wAAAos"]
[Tue Jul 21 08:34:31.093351 2026] [security2:error] [pid 466512:tid 466693] [client 20.197.195.24:56270] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "4inteligencia.com"] [uri "/1.php"] [unique_id "al9ZRyKGokixMSfKDOfg5AAAAkc"]
[Tue Jul 21 08:34:31.093475 2026] [security2:error] [pid 466512:tid 466693] [client 20.197.195.24:56270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/1.php"] [unique_id "al9ZRyKGokixMSfKDOfg5AAAAkc"]
[Tue Jul 21 08:34:31.122651 2026] [security2:error] [pid 466512:tid 466741] [client 20.206.105.145:25576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/2P.update.php"] [unique_id "al9ZRyKGokixMSfKDOfg5QAAAnc"]
[Tue Jul 21 08:34:31.236800 2026] [security2:error] [pid 466512:tid 466731] [client 20.206.105.145:38928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/d62.php"] [unique_id "al9ZRyKGokixMSfKDOfg6AAAAm0"]
[Tue Jul 21 08:34:31.376717 2026] [security2:error] [pid 466512:tid 466647] [client 20.197.192.193:43798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/ww.php"] [unique_id "al9ZRyKGokixMSfKDOfg6gAAAhk"]
[Tue Jul 21 08:34:31.605373 2026] [security2:error] [pid 465652:tid 465811] [client 20.206.105.145:38932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ups.php"] [unique_id "al9ZRzzTqJoBC2Mw28-9YwAAAKI"]
[Tue Jul 21 08:34:31.707295 2026] [security2:error] [pid 466512:tid 466712] [client 122.176.100.127:59054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZRyKGokixMSfKDOfg8AAAAlo"]
[Tue Jul 21 08:34:31.707412 2026] [security2:error] [pid 466512:tid 466712] [client 122.176.100.127:59054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZRyKGokixMSfKDOfg8AAAAlo"]
[Tue Jul 21 08:34:31.778136 2026] [security2:error] [pid 466512:tid 466695] [client 20.197.195.24:6691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/ms.php"] [unique_id "al9ZRyKGokixMSfKDOfg8QAAAkk"]
[Tue Jul 21 08:34:32.251702 2026] [security2:error] [pid 466512:tid 466734] [client 117.213.202.34:52552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZSCKGokixMSfKDOfg_wAAAnA"]
[Tue Jul 21 08:34:32.251836 2026] [security2:error] [pid 466512:tid 466734] [client 117.213.202.34:52552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZSCKGokixMSfKDOfg_wAAAnA"]
[Tue Jul 21 08:34:32.343620 2026] [security2:error] [pid 465652:tid 465793] [client 128.127.105.184:47420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9ZSDzTqJoBC2Mw28-9cAAAAJA"]
[Tue Jul 21 08:34:32.343785 2026] [security2:error] [pid 465652:tid 465793] [client 128.127.105.184:47420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9ZSDzTqJoBC2Mw28-9cAAAAJA"]
[Tue Jul 21 08:34:32.359785 2026] [security2:error] [pid 466512:tid 466733] [client 223.181.60.88:4955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZSCKGokixMSfKDOfhAAAAAm8"]
[Tue Jul 21 08:34:32.360043 2026] [security2:error] [pid 466512:tid 466733] [client 223.181.60.88:4955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZSCKGokixMSfKDOfhAAAAAm8"]
[Tue Jul 21 08:34:32.364729 2026] [autoindex:error] [pid 465652:tid 465835] [client 20.151.10.161:65446] AH01276: Cannot serve directory /home3/chave482/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:32.605541 2026] [security2:error] [pid 465652:tid 465817] [client 20.206.105.145:25530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/a.php"] [unique_id "al9ZSDzTqJoBC2Mw28-9dAAAAKg"]
[Tue Jul 21 08:34:32.615132 2026] [security2:error] [pid 466512:tid 466765] [client 20.206.105.145:39243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k.php"] [unique_id "al9ZSCKGokixMSfKDOfhBQAAAo8"]
[Tue Jul 21 08:34:32.636474 2026] [security2:error] [pid 465652:tid 465798] [client 20.151.10.161:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/8.php"] [unique_id "al9ZSDzTqJoBC2Mw28-9dQAAAJU"]
[Tue Jul 21 08:34:32.894400 2026] [security2:error] [pid 466512:tid 466746] [client 103.255.105.130:55316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZSCKGokixMSfKDOfhBwAAAnw"]
[Tue Jul 21 08:34:32.894537 2026] [security2:error] [pid 466512:tid 466746] [client 103.255.105.130:55316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZSCKGokixMSfKDOfhBwAAAnw"]
[Tue Jul 21 08:34:33.067710 2026] [security2:error] [pid 465652:tid 465898] [client 20.220.225.223:50259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/mimpi.php"] [unique_id "al9ZSTzTqJoBC2Mw28-9hQAAAPk"]
[Tue Jul 21 08:34:33.342329 2026] [autoindex:error] [pid 466512:tid 466653] [client 20.197.195.24:6732] AH01276: Cannot serve directory /home2/hg4int84/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:33.382775 2026] [security2:error] [pid 466512:tid 466769] [client 128.127.105.184:37516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9ZSSKGokixMSfKDOfhDAAAApM"]
[Tue Jul 21 08:34:33.382936 2026] [security2:error] [pid 466512:tid 466769] [client 128.127.105.184:37516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9ZSSKGokixMSfKDOfhDAAAApM"]
[Tue Jul 21 08:34:33.434781 2026] [security2:error] [pid 466512:tid 466684] [client 20.206.105.145:38922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k2.php"] [unique_id "al9ZSSKGokixMSfKDOfhDQAAAj4"]
[Tue Jul 21 08:34:33.646895 2026] [security2:error] [pid 466512:tid 466764] [client 20.197.195.24:6732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/memberfuns.php"] [unique_id "al9ZSSKGokixMSfKDOfhGAAAAo4"]
[Tue Jul 21 08:34:33.784223 2026] [core:alert] [pid 466512:tid 466671] [client 57.141.18.67:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:34:34.303655 2026] [security2:error] [pid 465652:tid 465909] [client 20.206.105.145:25495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/k.php"] [unique_id "al9ZSjzTqJoBC2Mw28-9mQAAAQQ"]
[Tue Jul 21 08:34:34.336073 2026] [security2:error] [pid 466512:tid 466760] [client 20.206.105.145:39279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k3.php"] [unique_id "al9ZSiKGokixMSfKDOfhJQAAAoo"]
[Tue Jul 21 08:34:34.383713 2026] [security2:error] [pid 466512:tid 466693] [client 20.197.195.24:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/0.php"] [unique_id "al9ZSiKGokixMSfKDOfhJwAAAkc"]
[Tue Jul 21 08:34:34.516932 2026] [security2:error] [pid 466512:tid 466761] [client 195.49.128.211:54737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZSiKGokixMSfKDOfhKAAAAos"]
[Tue Jul 21 08:34:34.517035 2026] [security2:error] [pid 466512:tid 466761] [client 195.49.128.211:54737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZSiKGokixMSfKDOfhKAAAAos"]
[Tue Jul 21 08:34:34.753313 2026] [security2:error] [pid 466512:tid 466716] [client 187.125.243.197:55506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZSiKGokixMSfKDOfhMgAAAl4"]
[Tue Jul 21 08:34:34.753475 2026] [security2:error] [pid 466512:tid 466716] [client 187.125.243.197:55506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZSiKGokixMSfKDOfhMgAAAl4"]
[Tue Jul 21 08:34:35.223379 2026] [security2:error] [pid 466512:tid 466717] [client 20.197.195.24:56245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/BDKR28.php"] [unique_id "al9ZSyKGokixMSfKDOfhNAAAAl8"]
[Tue Jul 21 08:34:35.449348 2026] [security2:error] [pid 466512:tid 466579] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZSyKGokixMSfKDOfhOAACTEI"]
[Tue Jul 21 08:34:35.449489 2026] [security2:error] [pid 466512:tid 466698] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZSyKGokixMSfKDOfhOAACTEI"]
[Tue Jul 21 08:34:35.456739 2026] [security2:error] [pid 466512:tid 466725] [client 20.206.105.145:39274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k4.php"] [unique_id "al9ZSyKGokixMSfKDOfhOQAAAmc"]
[Tue Jul 21 08:34:35.469856 2026] [security2:error] [pid 466512:tid 466695] [client 213.152.186.163:49768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9ZSyKGokixMSfKDOfhOwAAAkk"]
[Tue Jul 21 08:34:35.469961 2026] [security2:error] [pid 466512:tid 466695] [client 213.152.186.163:49768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9ZSyKGokixMSfKDOfhOwAAAkk"]
[Tue Jul 21 08:34:35.765747 2026] [security2:error] [pid 466512:tid 466525] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.gitlab-ci.yml"] [unique_id "al9ZSyKGokixMSfKDOfhRAACkww"]
[Tue Jul 21 08:34:35.765978 2026] [security2:error] [pid 466512:tid 466769] [client 34.39.41.71:45120] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.gitlab-ci.yml"] [unique_id "al9ZSyKGokixMSfKDOfhRAACkww"]
[Tue Jul 21 08:34:35.854944 2026] [security2:error] [pid 466512:tid 466766] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZSyKGokixMSfKDOfhSQACkGo"]
[Tue Jul 21 08:34:35.866350 2026] [security2:error] [pid 466512:tid 466765] [client 5.38.115.39:52612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZSyKGokixMSfKDOfhTwAAAo8"]
[Tue Jul 21 08:34:35.866468 2026] [security2:error] [pid 466512:tid 466765] [client 5.38.115.39:52612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZSyKGokixMSfKDOfhTwAAAo8"]
[Tue Jul 21 08:34:36.009629 2026] [security2:error] [pid 466512:tid 466587] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.github/workflows/deploy.yml"] [unique_id "al9ZTCKGokixMSfKDOfhVgACk0o"]
[Tue Jul 21 08:34:36.009752 2026] [security2:error] [pid 466512:tid 466769] [client 34.39.41.71:45120] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.github/workflows/deploy.yml"] [unique_id "al9ZTCKGokixMSfKDOfhVgACk0o"]
[Tue Jul 21 08:34:36.227320 2026] [security2:error] [pid 466512:tid 466717] [client 20.206.105.145:25414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/w.php"] [unique_id "al9ZTCKGokixMSfKDOfhiQAAAl8"]
[Tue Jul 21 08:34:36.406695 2026] [security2:error] [pid 466512:tid 466599] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "app.institutocrismonteiro.com.br"] [uri "/graphql"] [unique_id "al9ZTCKGokixMSfKDOfhjAACTFY"]
[Tue Jul 21 08:34:36.427842 2026] [security2:error] [pid 466512:tid 466566] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.env.old"] [unique_id "al9ZTCKGokixMSfKDOfhjgACRTU"]
[Tue Jul 21 08:34:36.463428 2026] [security2:error] [pid 465652:tid 465824] [client 20.197.195.24:56314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/green1.php"] [unique_id "al9ZTDzTqJoBC2Mw28-9wAAAAK8"]
[Tue Jul 21 08:34:36.478043 2026] [security2:error] [pid 466512:tid 466580] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.env.backup"] [unique_id "al9ZTCKGokixMSfKDOfhkQACSUM"]
[Tue Jul 21 08:34:36.481314 2026] [security2:error] [pid 466512:tid 466575] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.env"] [unique_id "al9ZTCKGokixMSfKDOfhkwACST4"]
[Tue Jul 21 08:34:36.481442 2026] [security2:error] [pid 466512:tid 466556] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.env.bak"] [unique_id "al9ZTCKGokixMSfKDOfhlAACSSs"]
[Tue Jul 21 08:34:36.533325 2026] [security2:error] [pid 466512:tid 466586] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/backend/.env"] [unique_id "al9ZTCKGokixMSfKDOfhlwACSUk"]
[Tue Jul 21 08:34:36.533626 2026] [security2:error] [pid 466512:tid 466629] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/api/.env"] [unique_id "al9ZTCKGokixMSfKDOfhlgACSXQ"]
[Tue Jul 21 08:34:36.533876 2026] [security2:error] [pid 466512:tid 466536] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/config/.env"] [unique_id "al9ZTCKGokixMSfKDOfhmgACSRc"]
[Tue Jul 21 08:34:36.542654 2026] [security2:error] [pid 465652:tid 465899] [client 49.144.66.253:33132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZTDzTqJoBC2Mw28-9wQAAAPo"]
[Tue Jul 21 08:34:36.542742 2026] [security2:error] [pid 465652:tid 465899] [client 49.144.66.253:33132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZTDzTqJoBC2Mw28-9wQAAAPo"]
[Tue Jul 21 08:34:36.574526 2026] [security2:error] [pid 465652:tid 465903] [client 20.206.105.145:22004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/ups.php"] [unique_id "al9ZTDzTqJoBC2Mw28-9wgAAAP4"]
[Tue Jul 21 08:34:36.623463 2026] [security2:error] [pid 466512:tid 466601] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "app.institutocrismonteiro.com.br"] [uri "/api/graphql"] [unique_id "al9ZTCKGokixMSfKDOfhngACfVg"]
[Tue Jul 21 08:34:36.746165 2026] [security2:error] [pid 466512:tid 466602] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/firebase-adminsdk.json"] [unique_id "al9ZTCKGokixMSfKDOfhpgACH1k"]
[Tue Jul 21 08:34:36.746362 2026] [security2:error] [pid 466512:tid 466653] [client 34.39.41.71:45120] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.institutocrismonteiro.com.br"] [uri "/firebase-adminsdk.json"] [unique_id "al9ZTCKGokixMSfKDOfhpgACH1k"]
[Tue Jul 21 08:34:36.765658 2026] [security2:error] [pid 466512:tid 466524] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.npmrc"] [unique_id "al9ZTCKGokixMSfKDOfhqQACHws"]
[Tue Jul 21 08:34:36.771122 2026] [security2:error] [pid 466512:tid 466756] [client 89.238.167.134:41442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZTCKGokixMSfKDOfhrAAAAoY"]
[Tue Jul 21 08:34:36.771207 2026] [security2:error] [pid 466512:tid 466756] [client 89.238.167.134:41442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZTCKGokixMSfKDOfhrAAAAoY"]
[Tue Jul 21 08:34:36.804340 2026] [authz_core:error] [pid 466512:tid 466614] [remote 34.39.41.71:45120] AH01630: client denied by server configuration: /home1/pedid516/app.institutocrismonteiro.com.br/.htpasswd
[Tue Jul 21 08:34:36.840043 2026] [security2:error] [pid 466512:tid 466621] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "app.institutocrismonteiro.com.br"] [uri "/v1/graphql"] [unique_id "al9ZTCKGokixMSfKDOfhsgACH2w"]
[Tue Jul 21 08:34:36.997122 2026] [security2:error] [pid 466512:tid 466716] [client 20.197.192.193:65191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/cron.php"] [unique_id "al9ZTCKGokixMSfKDOfhvwAAAl4"]
[Tue Jul 21 08:34:36.997190 2026] [security2:error] [pid 466512:tid 466537] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9ZTCKGokixMSfKDOfhvgACdxg"]
[Tue Jul 21 08:34:37.023581 2026] [security2:error] [pid 466512:tid 466754] [client 20.206.105.145:39269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/k5.php"] [unique_id "al9ZTSKGokixMSfKDOfhxgAAAoQ"]
[Tue Jul 21 08:34:37.037180 2026] [security2:error] [pid 466512:tid 466579] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.ssh/id_dsa"] [unique_id "al9ZTSKGokixMSfKDOfhxwACd0I"]
[Tue Jul 21 08:34:37.050055 2026] [security2:error] [pid 465652:tid 465804] [client 74.249.245.134:33393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/simple.php"] [unique_id "al9ZTTzTqJoBC2Mw28-9yQAAAJs"]
[Tue Jul 21 08:34:37.064107 2026] [security2:error] [pid 466512:tid 466523] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/id_rsa"] [unique_id "al9ZTSKGokixMSfKDOfhyQACdwo"]
[Tue Jul 21 08:34:37.071864 2026] [security2:error] [pid 466512:tid 466722] [client 14.245.224.124:61604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZTSKGokixMSfKDOfhygAAAmQ"]
[Tue Jul 21 08:34:37.071984 2026] [security2:error] [pid 466512:tid 466722] [client 14.245.224.124:61604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZTSKGokixMSfKDOfhygAAAmQ"]
[Tue Jul 21 08:34:37.090460 2026] [security2:error] [pid 466512:tid 466559] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/id_dsa"] [unique_id "al9ZTSKGokixMSfKDOfhzgACdy4"]
[Tue Jul 21 08:34:37.121693 2026] [qos:error] [pid 466512:tid 466530] [remote 57.141.18.0:47136] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.0, id=al9ZTSKGokixMSfKDOfh0AACYBE
[Tue Jul 21 08:34:37.204778 2026] [security2:error] [pid 465652:tid 465822] [client 20.197.195.24:56290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/nc4.php"] [unique_id "al9ZTTzTqJoBC2Mw28-9ywAAAK0"]
[Tue Jul 21 08:34:37.291138 2026] [security2:error] [pid 466512:tid 466534] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/key.pem"] [unique_id "al9ZTSKGokixMSfKDOfh1wACWRU"]
[Tue Jul 21 08:34:37.299579 2026] [security2:error] [pid 466512:tid 466542] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/privatekey.key"] [unique_id "al9ZTSKGokixMSfKDOfh2gACWR0"]
[Tue Jul 21 08:34:37.313548 2026] [security2:error] [pid 466512:tid 466593] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/private-key"] [unique_id "al9ZTSKGokixMSfKDOfh2wACWVA"]
[Tue Jul 21 08:34:37.315410 2026] [security2:error] [pid 466512:tid 466711] [client 34.39.41.71:45120] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.institutocrismonteiro.com.br"] [uri "/private-key"] [unique_id "al9ZTSKGokixMSfKDOfh2wACWVA"]
[Tue Jul 21 08:34:37.320070 2026] [security2:error] [pid 466512:tid 466525] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/ssl/server.key"] [unique_id "al9ZTSKGokixMSfKDOfh3AACWQw"]
[Tue Jul 21 08:34:37.357506 2026] [security2:error] [pid 466512:tid 466611] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.openclaw/.env"] [unique_id "al9ZTSKGokixMSfKDOfh3gACWWI"]
[Tue Jul 21 08:34:37.547108 2026] [security2:error] [pid 466512:tid 466623] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.hermes/.env"] [unique_id "al9ZTSKGokixMSfKDOfh4wACH24"]
[Tue Jul 21 08:34:37.586997 2026] [security2:error] [pid 466512:tid 466566] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.aider.conf.yml"] [unique_id "al9ZTSKGokixMSfKDOfh5gACHzU"]
[Tue Jul 21 08:34:37.671077 2026] [security2:error] [pid 466512:tid 466586] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.claude/settings.json"] [unique_id "al9ZTSKGokixMSfKDOfh7AACH0k"]
[Tue Jul 21 08:34:37.752342 2026] [security2:error] [pid 466512:tid 466659] [client 20.206.105.145:39287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/w.php"] [unique_id "al9ZTSKGokixMSfKDOfh8QAAAiU"]
[Tue Jul 21 08:34:37.846109 2026] [security2:error] [pid 466512:tid 466601] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "app.institutocrismonteiro.com.br"] [uri "/wp-config.php.old"] [unique_id "al9ZTSKGokixMSfKDOfh9QACdlg"]
[Tue Jul 21 08:34:37.846532 2026] [security2:error] [pid 466512:tid 466540] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "app.institutocrismonteiro.com.br"] [uri "/wp-config.php.bak"] [unique_id "al9ZTSKGokixMSfKDOfh9gACdhs"]
[Tue Jul 21 08:34:37.888102 2026] [security2:error] [pid 466512:tid 466722] [client 20.197.195.24:6710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/a1.php"] [unique_id "al9ZTSKGokixMSfKDOfh-QAAAmQ"]
[Tue Jul 21 08:34:37.918505 2026] [security2:error] [pid 466512:tid 466725] [client 20.220.225.223:50891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/dp.php"] [unique_id "al9ZTSKGokixMSfKDOfh-gAAAmc"]
[Tue Jul 21 08:34:37.941564 2026] [security2:error] [pid 466512:tid 466585] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/core/.env"] [unique_id "al9ZTSKGokixMSfKDOfh_QACL0g"]
[Tue Jul 21 08:34:37.941563 2026] [security2:error] [pid 466512:tid 466522] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/laravel/.env"] [unique_id "al9ZTSKGokixMSfKDOfh_AACLwk"]
[Tue Jul 21 08:34:38.010669 2026] [security2:error] [pid 466512:tid 466565] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/config.php.bak"] [unique_id "al9ZTiKGokixMSfKDOfiBQACLzQ"]
[Tue Jul 21 08:34:38.103334 2026] [security2:error] [pid 466512:tid 466614] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.env.swp"] [unique_id "al9ZTiKGokixMSfKDOfiCQACL2U"]
[Tue Jul 21 08:34:38.103712 2026] [security2:error] [pid 466512:tid 466632] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/configuration.php.bak"] [unique_id "al9ZTiKGokixMSfKDOfiCAACL3c"]
[Tue Jul 21 08:34:38.133944 2026] [security2:error] [pid 466512:tid 466630] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/public/.env"] [unique_id "al9ZTiKGokixMSfKDOfiCgACL3U"]
[Tue Jul 21 08:34:38.133981 2026] [security2:error] [pid 466512:tid 466607] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/web/.env"] [unique_id "al9ZTiKGokixMSfKDOfiCwACL14"]
[Tue Jul 21 08:34:38.158662 2026] [qos:error] [pid 466512:tid 466634] [remote 57.141.18.72:46380] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.72, id=al9ZTiKGokixMSfKDOfiDgACTnk
[Tue Jul 21 08:34:38.169128 2026] [security2:error] [pid 466512:tid 466673] [client 20.206.105.145:21959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/k.php"] [unique_id "al9ZTiKGokixMSfKDOfiDwAAAjM"]
[Tue Jul 21 08:34:38.213067 2026] [security2:error] [pid 466512:tid 466756] [client 20.197.195.24:6694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/eee.php"] [unique_id "al9ZTiKGokixMSfKDOfiEQAAAoY"]
[Tue Jul 21 08:34:38.221315 2026] [security2:error] [pid 466512:tid 466600] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/config.json"] [unique_id "al9ZTiKGokixMSfKDOfiEwACL1c"]
[Tue Jul 21 08:34:38.303399 2026] [security2:error] [pid 465652:tid 465838] [client 5.31.193.106:1816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZTjzTqJoBC2Mw28-93AAAAL0"]
[Tue Jul 21 08:34:38.303623 2026] [security2:error] [pid 465652:tid 465838] [client 5.31.193.106:1816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZTjzTqJoBC2Mw28-93AAAAL0"]
[Tue Jul 21 08:34:38.307600 2026] [security2:error] [pid 466512:tid 466748] [client 152.59.34.51:64553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZTiKGokixMSfKDOfiFwAAAn4"]
[Tue Jul 21 08:34:38.307757 2026] [security2:error] [pid 466512:tid 466748] [client 152.59.34.51:64553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZTiKGokixMSfKDOfiFwAAAn4"]
[Tue Jul 21 08:34:38.314021 2026] [security2:error] [pid 466512:tid 466754] [client 128.127.105.184:47434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZTiKGokixMSfKDOfiGAAAAoQ"]
[Tue Jul 21 08:34:38.314179 2026] [security2:error] [pid 466512:tid 466754] [client 128.127.105.184:47434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZTiKGokixMSfKDOfiGAAAAoQ"]
[Tue Jul 21 08:34:38.354601 2026] [qos:error] [pid 466512:tid 466579] [remote 57.141.18.91:56442] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.91, id=al9ZTiKGokixMSfKDOfiGwACH0I
[Tue Jul 21 08:34:38.372480 2026] [security2:error] [pid 466512:tid 466553] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/settings.json"] [unique_id "al9ZTiKGokixMSfKDOfiHwACLyg"]
[Tue Jul 21 08:34:38.372767 2026] [security2:error] [pid 466512:tid 466669] [client 34.39.41.71:45120] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.institutocrismonteiro.com.br"] [uri "/settings.json"] [unique_id "al9ZTiKGokixMSfKDOfiHwACLyg"]
[Tue Jul 21 08:34:38.450363 2026] [security2:error] [pid 466512:tid 466678] [client 20.151.10.161:65470] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.chaveiroportao.com.br"] [uri "/1.php"] [unique_id "al9ZTiKGokixMSfKDOfiIQAAAjg"]
[Tue Jul 21 08:34:38.450489 2026] [security2:error] [pid 466512:tid 466678] [client 20.151.10.161:65470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/1.php"] [unique_id "al9ZTiKGokixMSfKDOfiIQAAAjg"]
[Tue Jul 21 08:34:38.465434 2026] [security2:error] [pid 466512:tid 466664] [client 20.206.105.145:38941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/fpwch.php"] [unique_id "al9ZTiKGokixMSfKDOfiIgAAAio"]
[Tue Jul 21 08:34:38.501588 2026] [security2:error] [pid 466512:tid 466741] [client 20.206.105.145:39265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/w2025.php"] [unique_id "al9ZTiKGokixMSfKDOfiJQAAAnc"]
[Tue Jul 21 08:34:38.540781 2026] [security2:error] [pid 465652:tid 465878] [client 20.206.105.145:39270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/scxy.php"] [unique_id "al9ZTjzTqJoBC2Mw28-94gAAAOU"]
[Tue Jul 21 08:34:38.562802 2026] [security2:error] [pid 465652:tid 465850] [client 20.197.195.24:6677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/wp-aothait.php"] [unique_id "al9ZTjzTqJoBC2Mw28-95AAAAMk"]
[Tue Jul 21 08:34:38.562859 2026] [qos:error] [pid 465652:tid 465703] [remote 57.141.18.64:28250] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.64, id=al9ZTjzTqJoBC2Mw28-94wAApjI
[Tue Jul 21 08:34:38.590897 2026] [security2:error] [pid 466512:tid 466691] [client 74.249.245.134:53132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/404.php"] [unique_id "al9ZTiKGokixMSfKDOfiKgAAAkU"]
[Tue Jul 21 08:34:38.637654 2026] [security2:error] [pid 466512:tid 466611] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/runtime-config.js"] [unique_id "al9ZTiKGokixMSfKDOfiMgACL2I"]
[Tue Jul 21 08:34:38.652987 2026] [security2:error] [pid 466512:tid 466555] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/manifest.webmanifest"] [unique_id "al9ZTiKGokixMSfKDOfiMwACLyo"]
[Tue Jul 21 08:34:38.702610 2026] [security2:error] [pid 466512:tid 466753] [client 20.206.105.145:39282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/FWAZ.php"] [unique_id "al9ZTiKGokixMSfKDOfiNgAAAoM"]
[Tue Jul 21 08:34:38.735802 2026] [qos:error] [pid 465652:tid 465722] [remote 57.141.18.90:23460] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.90, id=al9ZTjzTqJoBC2Mw28-96QAAi0U
[Tue Jul 21 08:34:38.758325 2026] [security2:error] [pid 466512:tid 466700] [client 20.206.105.145:39250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/qterm.php"] [unique_id "al9ZTiKGokixMSfKDOfiOgAAAk4"]
[Tue Jul 21 08:34:38.855661 2026] [autoindex:error] [pid 466512:tid 466623] [remote 198.235.24.169:0] AH01276: Cannot serve directory /home2/andr9968/confeitariaemcamadas.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:38.872198 2026] [security2:error] [pid 465652:tid 465802] [client 20.206.105.145:39286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/blurbs.php"] [unique_id "al9ZTjzTqJoBC2Mw28-97QAAAJk"]
[Tue Jul 21 08:34:38.888661 2026] [security2:error] [pid 465652:tid 465879] [client 20.197.195.24:56241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/config.json.php"] [unique_id "al9ZTjzTqJoBC2Mw28-97wAAAOY"]
[Tue Jul 21 08:34:38.895222 2026] [security2:error] [pid 466512:tid 466580] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/api/v1/env"] [unique_id "al9ZTiKGokixMSfKDOfiQwACL0M"]
[Tue Jul 21 08:34:38.895519 2026] [security2:error] [pid 466512:tid 466669] [client 34.39.41.71:45120] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.institutocrismonteiro.com.br"] [uri "/api/v1/env"] [unique_id "al9ZTiKGokixMSfKDOfiQwACL0M"]
[Tue Jul 21 08:34:38.943901 2026] [security2:error] [pid 466512:tid 466573] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/config/.env.php"] [unique_id "al9ZTSKGokixMSfKDOfh_wACLzw"]
[Tue Jul 21 08:34:38.944361 2026] [security2:error] [pid 466512:tid 466638] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/.env.php.bak"] [unique_id "al9ZTSKGokixMSfKDOfh_gACL30"]
[Tue Jul 21 08:34:38.956516 2026] [security2:error] [pid 465652:tid 465851] [client 20.206.105.145:39294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/v543.php"] [unique_id "al9ZTjzTqJoBC2Mw28-98QAAAMo"]
[Tue Jul 21 08:34:38.985333 2026] [security2:error] [pid 466512:tid 466760] [client 20.206.105.145:39268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/w3lls.php"] [unique_id "al9ZTiKGokixMSfKDOfiRgAAAoo"]
[Tue Jul 21 08:34:39.011046 2026] [security2:error] [pid 466512:tid 466668] [client 20.206.105.145:38927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-ws68.php"] [unique_id "al9ZTyKGokixMSfKDOfiRwAAAi4"]
[Tue Jul 21 08:34:39.069040 2026] [security2:error] [pid 465652:tid 465822] [client 20.197.195.24:56291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9ZTzzTqJoBC2Mw28-99gAAAK0"]
[Tue Jul 21 08:34:39.079049 2026] [qos:error] [pid 465652:tid 465778] [remote 57.141.18.10:34688] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.10, id=al9ZTzzTqJoBC2Mw28-99wAAxX0
[Tue Jul 21 08:34:39.102056 2026] [security2:error] [pid 465652:tid 465849] [client 20.197.195.24:56292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/k2.php"] [unique_id "al9ZTzzTqJoBC2Mw28-9-AAAAMg"]
[Tue Jul 21 08:34:39.137224 2026] [security2:error] [pid 466512:tid 466647] [client 20.206.105.145:39249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xyn.php"] [unique_id "al9ZTyKGokixMSfKDOfiSwAAAhk"]
[Tue Jul 21 08:34:39.140607 2026] [security2:error] [pid 466512:tid 466730] [client 20.220.225.223:50264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/bootstrap.php"] [unique_id "al9ZTyKGokixMSfKDOfiTAAAAmw"]
[Tue Jul 21 08:34:39.157669 2026] [security2:error] [pid 466512:tid 466767] [client 20.197.195.24:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/uiuvs58l.php"] [unique_id "al9ZTyKGokixMSfKDOfiTgAAApE"]
[Tue Jul 21 08:34:39.171128 2026] [security2:error] [pid 466512:tid 466601] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/info.php"] [unique_id "al9ZTyKGokixMSfKDOfiTwACbVg"]
[Tue Jul 21 08:34:39.171578 2026] [security2:error] [pid 465652:tid 465867] [client 20.206.105.145:39245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/green3.php"] [unique_id "al9ZTzzTqJoBC2Mw28-9-QAAANo"]
[Tue Jul 21 08:34:39.172849 2026] [security2:error] [pid 466512:tid 466587] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/actuator"] [unique_id "al9ZTyKGokixMSfKDOfiUQACbUo"]
[Tue Jul 21 08:34:39.183601 2026] [security2:error] [pid 466512:tid 466585] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/phpinfo.php"] [unique_id "al9ZTyKGokixMSfKDOfiVAACbUg"]
[Tue Jul 21 08:34:39.197020 2026] [security2:error] [pid 466512:tid 466522] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/pi.php"] [unique_id "al9ZTyKGokixMSfKDOfiVQACbQk"]
[Tue Jul 21 08:34:39.202369 2026] [security2:error] [pid 465652:tid 465835] [client 20.197.195.24:6781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/40p9ixjd.php"] [unique_id "al9ZTzzTqJoBC2Mw28-9-gAAALo"]
[Tue Jul 21 08:34:39.218769 2026] [security2:error] [pid 466512:tid 466602] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/test.php"] [unique_id "al9ZTyKGokixMSfKDOfiVgACbVk"]
[Tue Jul 21 08:34:39.235067 2026] [security2:error] [pid 465652:tid 465793] [client 20.197.195.24:6728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9ZTzzTqJoBC2Mw28-9_gAAAJA"]
[Tue Jul 21 08:34:39.235890 2026] [security2:error] [pid 465652:tid 465792] [client 20.206.105.145:39242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ccs.php"] [unique_id "al9ZTzzTqJoBC2Mw28-9_wAAAI8"]
[Tue Jul 21 08:34:39.262546 2026] [security2:error] [pid 466512:tid 466541] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/i.php"] [unique_id "al9ZTyKGokixMSfKDOfiVwACixw"]
[Tue Jul 21 08:34:39.266471 2026] [security2:error] [pid 465652:tid 465798] [client 20.197.195.24:6660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/for.php"] [unique_id "al9ZTzzTqJoBC2Mw28--AAAAAJU"]
[Tue Jul 21 08:34:39.287855 2026] [security2:error] [pid 465652:tid 465900] [client 20.197.195.24:56275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/raw.php"] [unique_id "al9ZTzzTqJoBC2Mw28--AQAAAPs"]
[Tue Jul 21 08:34:39.308668 2026] [security2:error] [pid 466512:tid 466765] [client 20.10.88.201:62531] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealth.shop"] [uri "/robots.txt"] [unique_id "al9ZTyKGokixMSfKDOfiWAAAAo8"]
[Tue Jul 21 08:34:39.375045 2026] [security2:error] [pid 466512:tid 466614] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/app_dev.php"] [unique_id "al9ZTyKGokixMSfKDOfiWgACUmU"]
[Tue Jul 21 08:34:39.379138 2026] [security2:error] [pid 466512:tid 466632] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/app_dev.php/_profiler"] [unique_id "al9ZTyKGokixMSfKDOfiXAACUnc"]
[Tue Jul 21 08:34:39.450023 2026] [security2:error] [pid 466512:tid 466621] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/server-status"] [unique_id "al9ZTyKGokixMSfKDOfiYgACUmw"]
[Tue Jul 21 08:34:39.450023 2026] [security2:error] [pid 466512:tid 466600] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.institutocrismonteiro.com.br"] [uri "/trace.axd"] [unique_id "al9ZTyKGokixMSfKDOfiYQACUlc"]
[Tue Jul 21 08:34:39.522737 2026] [security2:error] [pid 466512:tid 466595] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "app.institutocrismonteiro.com.br"] [uri "/server-info"] [unique_id "al9ZTyKGokixMSfKDOfiZAACUlI"]
[Tue Jul 21 08:34:39.548474 2026] [security2:error] [pid 465652:tid 465874] [client 20.206.105.145:25585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/insc.php"] [unique_id "al9ZTzzTqJoBC2Mw28--DAAAAOE"]
[Tue Jul 21 08:34:39.579335 2026] [security2:error] [pid 466512:tid 466746] [client 152.59.181.104:63614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZTyKGokixMSfKDOfiZwAAAnw"]
[Tue Jul 21 08:34:39.579460 2026] [security2:error] [pid 466512:tid 466746] [client 152.59.181.104:63614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZTyKGokixMSfKDOfiZwAAAnw"]
[Tue Jul 21 08:34:39.608414 2026] [security2:error] [pid 465652:tid 465824] [client 20.206.105.145:38972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ccc.php"] [unique_id "al9ZTzzTqJoBC2Mw28--FQAAAK8"]
[Tue Jul 21 08:34:39.783688 2026] [security2:error] [pid 466512:tid 466764] [client 103.151.46.103:50929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZTyKGokixMSfKDOfidQAAAo4"]
[Tue Jul 21 08:34:39.784206 2026] [security2:error] [pid 466512:tid 466764] [client 103.151.46.103:50929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZTyKGokixMSfKDOfidQAAAo4"]
[Tue Jul 21 08:34:39.853313 2026] [security2:error] [pid 465652:tid 465849] [client 20.206.105.145:39292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/get.php"] [unique_id "al9ZTzzTqJoBC2Mw28--HQAAAMg"]
[Tue Jul 21 08:34:39.919562 2026] [security2:error] [pid 465652:tid 465786] [client 20.206.105.145:39293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/images.php"] [unique_id "al9ZTzzTqJoBC2Mw28--UgAAAIk"]
[Tue Jul 21 08:34:39.944873 2026] [qos:error] [pid 466512:tid 466560] [remote 57.141.18.25:50826] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.25, id=al9ZTyKGokixMSfKDOfikAACVS8
[Tue Jul 21 08:34:39.967368 2026] [security2:error] [pid 466512:tid 466760] [client 20.206.105.145:39120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/alls.php"] [unique_id "al9ZTyKGokixMSfKDOfikgAAAoo"]
[Tue Jul 21 08:34:39.978998 2026] [security2:error] [pid 466512:tid 466766] [client 20.206.105.145:38930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/yyu.php"] [unique_id "al9ZTyKGokixMSfKDOfikwAAApA"]
[Tue Jul 21 08:34:40.084154 2026] [security2:error] [pid 466512:tid 466702] [client 20.206.105.145:39109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/by.php"] [unique_id "al9ZUCKGokixMSfKDOfimgAAAlA"]
[Tue Jul 21 08:34:40.173959 2026] [security2:error] [pid 466512:tid 466746] [client 20.197.192.193:65166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/xxx.php"] [unique_id "al9ZUCKGokixMSfKDOfimwAAAnw"]
[Tue Jul 21 08:34:40.177409 2026] [qos:error] [pid 466512:tid 466636] [remote 57.141.18.119:22496] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.119, id=al9ZUCKGokixMSfKDOfinAACT3s
[Tue Jul 21 08:34:40.255913 2026] [security2:error] [pid 466512:tid 466662] [client 74.249.245.134:47985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/file3.php"] [unique_id "al9ZUCKGokixMSfKDOfioQAAAig"]
[Tue Jul 21 08:34:40.325332 2026] [security2:error] [pid 466512:tid 466695] [client 20.206.105.145:39234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/FAQ.php"] [unique_id "al9ZUCKGokixMSfKDOfipAAAAkk"]
[Tue Jul 21 08:34:40.481552 2026] [security2:error] [pid 465652:tid 465899] [client 20.220.225.223:50247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/wp-editor.php"] [unique_id "al9ZUDzTqJoBC2Mw28--YAAAAPo"]
[Tue Jul 21 08:34:40.575379 2026] [security2:error] [pid 466512:tid 466678] [client 202.179.75.202:43150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZUCKGokixMSfKDOfiqQAAAjg"]
[Tue Jul 21 08:34:40.575494 2026] [security2:error] [pid 466512:tid 466678] [client 202.179.75.202:43150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZUCKGokixMSfKDOfiqQAAAjg"]
[Tue Jul 21 08:34:40.599974 2026] [qos:error] [pid 466512:tid 466559] [remote 57.141.18.18:57086] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.18, id=al9ZUCKGokixMSfKDOfiqgACMy4
[Tue Jul 21 08:34:40.612221 2026] [security2:error] [pid 466512:tid 466720] [client 20.206.105.145:39233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/coffexium.php"] [unique_id "al9ZUCKGokixMSfKDOfirQAAAmI"]
[Tue Jul 21 08:34:40.697980 2026] [security2:error] [pid 466512:tid 466669] [client 61.1.167.83:60125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZUCKGokixMSfKDOfisAAAAi8"]
[Tue Jul 21 08:34:40.700003 2026] [security2:error] [pid 466512:tid 466669] [client 61.1.167.83:60125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZUCKGokixMSfKDOfisAAAAi8"]
[Tue Jul 21 08:34:40.738044 2026] [security2:error] [pid 466512:tid 466647] [client 20.206.105.145:39262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/red.php"] [unique_id "al9ZUCKGokixMSfKDOfisQAAAhk"]
[Tue Jul 21 08:34:40.768021 2026] [proxy:error] [pid 466512:tid 466653] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:40.768086 2026] [proxy_http:error] [pid 466512:tid 466653] [client 20.206.105.145:39236] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:40.768524 2026] [proxy:error] [pid 466512:tid 466653] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:40.768545 2026] [proxy_http:error] [pid 466512:tid 466653] [client 20.206.105.145:39236] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:40.804867 2026] [security2:error] [pid 465652:tid 465796] [client 20.206.105.145:39256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9ZUDzTqJoBC2Mw28--fQAAAJM"]
[Tue Jul 21 08:34:40.805996 2026] [security2:error] [pid 466512:tid 466711] [client 195.49.128.211:63603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZUCKGokixMSfKDOfiswAAAlk"]
[Tue Jul 21 08:34:40.806125 2026] [security2:error] [pid 466512:tid 466711] [client 195.49.128.211:63603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZUCKGokixMSfKDOfiswAAAlk"]
[Tue Jul 21 08:34:40.830034 2026] [proxy:error] [pid 465652:tid 465822] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:40.830098 2026] [proxy_http:error] [pid 465652:tid 465822] [client 20.206.105.145:39261] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:40.830638 2026] [proxy:error] [pid 465652:tid 465822] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:40.830663 2026] [proxy_http:error] [pid 465652:tid 465822] [client 20.206.105.145:39261] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:40.856945 2026] [security2:error] [pid 465652:tid 465869] [client 20.206.105.145:38916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/footer.php"] [unique_id "al9ZUDzTqJoBC2Mw28--ggAAANw"]
[Tue Jul 21 08:34:40.874407 2026] [proxy:error] [pid 466512:tid 466658] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:40.874471 2026] [proxy_http:error] [pid 466512:tid 466658] [client 20.206.105.145:39272] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:40.874918 2026] [proxy:error] [pid 466512:tid 466658] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:40.874941 2026] [proxy_http:error] [pid 466512:tid 466658] [client 20.206.105.145:39272] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:40.924283 2026] [security2:error] [pid 466512:tid 466664] [client 20.206.105.145:39261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/index.php"] [unique_id "al9ZUCKGokixMSfKDOfiugAAAio"]
[Tue Jul 21 08:34:40.975762 2026] [security2:error] [pid 466512:tid 466660] [client 20.206.105.145:39288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/zoro.php"] [unique_id "al9ZUCKGokixMSfKDOfiuwAAAiY"]
[Tue Jul 21 08:34:41.032327 2026] [security2:error] [pid 466512:tid 466753] [client 20.206.105.145:38947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/admin.php"] [unique_id "al9ZUSKGokixMSfKDOfivQAAAoM"]
[Tue Jul 21 08:34:41.096517 2026] [security2:error] [pid 466512:tid 466742] [client 20.206.105.145:39285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/greap.php"] [unique_id "al9ZUSKGokixMSfKDOfiwgAAAng"]
[Tue Jul 21 08:34:41.112368 2026] [security2:error] [pid 466512:tid 466658] [client 20.206.105.145:38931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/177.php"] [unique_id "al9ZUSKGokixMSfKDOfi0gAAAiQ"]
[Tue Jul 21 08:34:41.173832 2026] [security2:error] [pid 466512:tid 466761] [client 20.206.105.145:39277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/199.php"] [unique_id "al9ZUSKGokixMSfKDOfi1AAAAos"]
[Tue Jul 21 08:34:41.176070 2026] [qos:error] [pid 466512:tid 466573] [remote 57.141.18.14:29908] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.14, id=al9ZUSKGokixMSfKDOfi1QACRTw
[Tue Jul 21 08:34:41.235507 2026] [security2:error] [pid 466512:tid 466742] [client 20.206.105.145:39246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file52.php"] [unique_id "al9ZUSKGokixMSfKDOfi1wAAAng"]
[Tue Jul 21 08:34:41.291986 2026] [security2:error] [pid 465652:tid 465811] [client 20.206.105.145:39267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/122.php"] [unique_id "al9ZUTzTqJoBC2Mw28--sgAAAKI"]
[Tue Jul 21 08:34:41.428700 2026] [security2:error] [pid 466512:tid 466662] [client 20.206.105.145:39275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/green1.php"] [unique_id "al9ZUSKGokixMSfKDOfi3gAAAig"]
[Tue Jul 21 08:34:41.568833 2026] [security2:error] [pid 466512:tid 466653] [client 213.152.186.163:39358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9ZUSKGokixMSfKDOfi4AAAAh8"]
[Tue Jul 21 08:34:41.568925 2026] [security2:error] [pid 466512:tid 466653] [client 213.152.186.163:39358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9ZUSKGokixMSfKDOfi4AAAAh8"]
[Tue Jul 21 08:34:41.852250 2026] [security2:error] [pid 466512:tid 466673] [client 20.206.105.145:39291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/biufile.php"] [unique_id "al9ZUSKGokixMSfKDOfi4wAAAjM"]
[Tue Jul 21 08:34:42.178240 2026] [security2:error] [pid 466512:tid 466681] [client 122.176.100.127:59551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZUiKGokixMSfKDOfi6QAAAjs"]
[Tue Jul 21 08:34:42.178430 2026] [security2:error] [pid 466512:tid 466681] [client 122.176.100.127:59551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZUiKGokixMSfKDOfi6QAAAjs"]
[Tue Jul 21 08:34:42.187410 2026] [qos:error] [pid 465652:tid 465676] [remote 57.141.18.75:33794] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.75, id=al9ZUjzTqJoBC2Mw28--7QAArRc
[Tue Jul 21 08:34:42.198635 2026] [security2:error] [pid 466512:tid 466722] [client 20.151.10.161:65477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/100.php"] [unique_id "al9ZUiKGokixMSfKDOfi6wAAAmQ"]
[Tue Jul 21 08:34:42.223645 2026] [autoindex:error] [pid 466512:tid 466682] [client 43.159.143.190:33962] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/planamoveis.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:42.288454 2026] [security2:error] [pid 465652:tid 465830] [client 20.206.105.145:38920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wpconf.php"] [unique_id "al9ZUjzTqJoBC2Mw28--7gAAALU"]
[Tue Jul 21 08:34:42.431277 2026] [security2:error] [pid 466512:tid 466645] [client 20.206.105.145:21955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/k2.php"] [unique_id "al9ZUiKGokixMSfKDOfi9gAAAhc"]
[Tue Jul 21 08:34:42.616198 2026] [security2:error] [pid 466512:tid 466673] [client 20.206.105.145:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/mosty.php"] [unique_id "al9ZUiKGokixMSfKDOfjAQAAAjM"]
[Tue Jul 21 08:34:42.628442 2026] [security2:error] [pid 465652:tid 465784] [client 20.197.192.193:65202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/hunter.php"] [unique_id "al9ZUjzTqJoBC2Mw28-_AAAAAIc"]
[Tue Jul 21 08:34:42.695749 2026] [security2:error] [pid 466512:tid 466702] [client 20.206.105.145:25090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9ZUiKGokixMSfKDOfjBAAAAlA"]
[Tue Jul 21 08:34:42.763174 2026] [security2:error] [pid 466512:tid 466749] [client 74.249.245.134:56663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/wp-mail.php"] [unique_id "al9ZUiKGokixMSfKDOfjBgAAAn8"]
[Tue Jul 21 08:34:42.922701 2026] [security2:error] [pid 466512:tid 466612] [remote 8.217.108.67:51144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9ZUiKGokixMSfKDOfjCQACKGM"]
[Tue Jul 21 08:34:43.032712 2026] [security2:error] [pid 466512:tid 466764] [client 117.213.202.34:53160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZUyKGokixMSfKDOfjDAAAAo4"]
[Tue Jul 21 08:34:43.032862 2026] [security2:error] [pid 466512:tid 466764] [client 117.213.202.34:53160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZUyKGokixMSfKDOfjDAAAAo4"]
[Tue Jul 21 08:34:43.242034 2026] [security2:error] [pid 466512:tid 466653] [client 20.206.105.145:38921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/dejavu.php"] [unique_id "al9ZUyKGokixMSfKDOfjEAAAAh8"]
[Tue Jul 21 08:34:43.352377 2026] [security2:error] [pid 466512:tid 466658] [client 223.181.60.88:1994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZUyKGokixMSfKDOfjEgAAAiQ"]
[Tue Jul 21 08:34:43.352564 2026] [security2:error] [pid 466512:tid 466658] [client 223.181.60.88:1994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZUyKGokixMSfKDOfjEgAAAiQ"]
[Tue Jul 21 08:34:43.455389 2026] [security2:error] [pid 465652:tid 465891] [client 14.97.58.74:5959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZUzzTqJoBC2Mw28-_EQAAAPI"]
[Tue Jul 21 08:34:43.455762 2026] [security2:error] [pid 465652:tid 465891] [client 14.97.58.74:5959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZUzzTqJoBC2Mw28-_EQAAAPI"]
[Tue Jul 21 08:34:43.915465 2026] [qos:error] [pid 465652:tid 465747] [remote 57.141.18.114:41866] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.114, id=al9ZUzzTqJoBC2Mw28-_GwAA9l4
[Tue Jul 21 08:34:43.945669 2026] [security2:error] [pid 466512:tid 466552] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/wp-login.php"] [unique_id "al9ZUiKGokixMSfKDOfjCAACOyc"], referer: https://app.institutocrismonteiro.com.br/login
[Tue Jul 21 08:34:44.074373 2026] [security2:error] [pid 466512:tid 466695] [client 20.206.105.145:39258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/aaf.php"] [unique_id "al9ZVCKGokixMSfKDOfjJwAAAkk"]
[Tue Jul 21 08:34:44.285177 2026] [security2:error] [pid 466512:tid 466765] [client 74.249.245.134:20646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/about.php"] [unique_id "al9ZVCKGokixMSfKDOfjNQAAAo8"]
[Tue Jul 21 08:34:44.285491 2026] [security2:error] [pid 466512:tid 466634] [remote 34.39.41.71:45120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "app.institutocrismonteiro.com.br"] [uri "/wp-login.php"] [unique_id "al9ZUyKGokixMSfKDOfjDgACO3k"], referer: https://app.institutocrismonteiro.com.br/wp-admin/
[Tue Jul 21 08:34:44.359972 2026] [security2:error] [pid 465652:tid 465805] [client 20.206.105.145:21988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/k3.php"] [unique_id "al9ZVDzTqJoBC2Mw28-_JgAAAJw"]
[Tue Jul 21 08:34:44.468207 2026] [security2:error] [pid 466512:tid 466677] [client 20.206.105.145:22088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/k4.php"] [unique_id "al9ZVCKGokixMSfKDOfjNwAAAjc"]
[Tue Jul 21 08:34:44.559485 2026] [core:error] [pid 466512:tid 466688] [client 137.184.11.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:34:44.559509 2026] [core:error] [pid 466512:tid 466688] [client 137.184.11.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:34:44.949228 2026] [security2:error] [pid 466512:tid 466695] [client 20.206.105.145:39281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/term.php"] [unique_id "al9ZVCKGokixMSfKDOfjQgAAAkk"]
[Tue Jul 21 08:34:45.014436 2026] [security2:error] [pid 465652:tid 465844] [client 20.206.105.145:21985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/k5.php"] [unique_id "al9ZVTzTqJoBC2Mw28-_MAAAAMM"]
[Tue Jul 21 08:34:45.017185 2026] [security2:error] [pid 466512:tid 466764] [client 20.206.105.145:25511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/u.php"] [unique_id "al9ZVSKGokixMSfKDOfjQwAAAo4"]
[Tue Jul 21 08:34:45.142267 2026] [security2:error] [pid 465652:tid 465888] [client 195.49.128.211:55332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZVTzTqJoBC2Mw28-_NQAAAO8"]
[Tue Jul 21 08:34:45.142382 2026] [security2:error] [pid 465652:tid 465888] [client 195.49.128.211:55332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZVTzTqJoBC2Mw28-_NQAAAO8"]
[Tue Jul 21 08:34:45.232412 2026] [security2:error] [pid 466512:tid 466725] [client 187.125.243.197:56009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZVSKGokixMSfKDOfjRQAAAmc"]
[Tue Jul 21 08:34:45.232570 2026] [security2:error] [pid 466512:tid 466725] [client 187.125.243.197:56009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZVSKGokixMSfKDOfjRQAAAmc"]
[Tue Jul 21 08:34:45.673480 2026] [security2:error] [pid 466512:tid 466688] [client 20.197.192.193:65159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/we.php"] [unique_id "al9ZVSKGokixMSfKDOfjSAAAAkI"]
[Tue Jul 21 08:34:45.749899 2026] [security2:error] [pid 466512:tid 466756] [client 103.151.46.103:51454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZVSKGokixMSfKDOfjSQAAAoY"]
[Tue Jul 21 08:34:45.750008 2026] [security2:error] [pid 466512:tid 466756] [client 103.151.46.103:51454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZVSKGokixMSfKDOfjSQAAAoY"]
[Tue Jul 21 08:34:45.917995 2026] [security2:error] [pid 465652:tid 465804] [client 20.206.105.145:21972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/w.php"] [unique_id "al9ZVTzTqJoBC2Mw28-_QQAAAJs"]
[Tue Jul 21 08:34:45.999088 2026] [security2:error] [pid 466512:tid 466547] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZVSKGokixMSfKDOfjUwACfyI"]
[Tue Jul 21 08:34:45.999214 2026] [security2:error] [pid 466512:tid 466749] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZVSKGokixMSfKDOfjUwACfyI"]
[Tue Jul 21 08:34:46.240719 2026] [security2:error] [pid 466512:tid 466695] [client 74.7.228.14:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "jurandirdasilvafigue1777857771000.0711679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9ZViKGokixMSfKDOfjYQACSX0"]
[Tue Jul 21 08:34:46.297129 2026] [security2:error] [pid 466512:tid 466599] [remote 45.79.123.44:60196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moneyclass.com.br"] [uri "/wp-login.php"] [unique_id "al9ZViKGokixMSfKDOfjZQACe1Y"]
[Tue Jul 21 08:34:46.380053 2026] [autoindex:error] [pid 465652:tid 465696] [remote 74.7.242.62:0] AH01276: Cannot serve directory /home2/jurand34/jurandirdasilvafigue1777857771000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:46.412984 2026] [security2:error] [pid 466512:tid 466764] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZViKGokixMSfKDOfjZgACjh4"]
[Tue Jul 21 08:34:46.576202 2026] [security2:error] [pid 465652:tid 465800] [client 5.38.115.39:53159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZVjzTqJoBC2Mw28-_SgAAAJc"]
[Tue Jul 21 08:34:46.576321 2026] [security2:error] [pid 465652:tid 465800] [client 5.38.115.39:53159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZVjzTqJoBC2Mw28-_SgAAAJc"]
[Tue Jul 21 08:34:46.621978 2026] [security2:error] [pid 466512:tid 466700] [client 213.152.186.163:39366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9ZViKGokixMSfKDOfjcQAAAk4"]
[Tue Jul 21 08:34:46.622090 2026] [security2:error] [pid 466512:tid 466700] [client 213.152.186.163:39366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9ZViKGokixMSfKDOfjcQAAAk4"]
[Tue Jul 21 08:34:46.742559 2026] [security2:error] [pid 466512:tid 466645] [client 20.206.105.145:39128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ha.php"] [unique_id "al9ZViKGokixMSfKDOfjcgAAAhc"]
[Tue Jul 21 08:34:46.797362 2026] [security2:error] [pid 466512:tid 466704] [client 20.206.105.145:21967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/fpwch.php"] [unique_id "al9ZViKGokixMSfKDOfjdAAAAlI"]
[Tue Jul 21 08:34:47.544934 2026] [security2:error] [pid 465652:tid 465802] [client 20.206.105.145:21963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/w2025.php"] [unique_id "al9ZVzzTqJoBC2Mw28-_WQAAAJk"]
[Tue Jul 21 08:34:47.811511 2026] [security2:error] [pid 465652:tid 465859] [client 14.245.224.124:62072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZVzzTqJoBC2Mw28-_XAAAANI"]
[Tue Jul 21 08:34:47.811732 2026] [security2:error] [pid 465652:tid 465859] [client 14.245.224.124:62072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZVzzTqJoBC2Mw28-_XAAAANI"]
[Tue Jul 21 08:34:47.883515 2026] [security2:error] [pid 465652:tid 465813] [client 49.144.66.253:33543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZVzzTqJoBC2Mw28-_XQAAAKQ"]
[Tue Jul 21 08:34:47.883685 2026] [security2:error] [pid 465652:tid 465813] [client 49.144.66.253:33543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZVzzTqJoBC2Mw28-_XQAAAKQ"]
[Tue Jul 21 08:34:47.943146 2026] [security2:error] [pid 465652:tid 465821] [client 152.59.34.51:65081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZVzzTqJoBC2Mw28-_YAAAAKw"]
[Tue Jul 21 08:34:47.943281 2026] [security2:error] [pid 465652:tid 465821] [client 152.59.34.51:65081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZVzzTqJoBC2Mw28-_YAAAAKw"]
[Tue Jul 21 08:34:47.982551 2026] [security2:error] [pid 465652:tid 465872] [client 74.249.245.134:52619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/adminfuns.php"] [unique_id "al9ZVzzTqJoBC2Mw28-_YgAAAN8"]
[Tue Jul 21 08:34:48.037208 2026] [security2:error] [pid 465652:tid 465899] [client 20.206.105.145:25127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/sss.php"] [unique_id "al9ZWDzTqJoBC2Mw28-_YwAAAPo"]
[Tue Jul 21 08:34:48.063384 2026] [security2:error] [pid 466512:tid 466698] [client 20.206.105.145:39255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/hur.php"] [unique_id "al9ZWCKGokixMSfKDOfjigAAAkw"]
[Tue Jul 21 08:34:48.155695 2026] [security2:error] [pid 465652:tid 465792] [client 54.238.43.39:58496] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://user@:80"] [hostname "widereviews.com.oficialwebsite.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9ZWDzTqJoBC2Mw28-_ZQAAAI8"]
[Tue Jul 21 08:34:48.253687 2026] [security2:error] [pid 465652:tid 465845] [client 20.151.10.161:65420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/about.php"] [unique_id "al9ZWDzTqJoBC2Mw28-_aQAAAMQ"]
[Tue Jul 21 08:34:48.432910 2026] [security2:error] [pid 466512:tid 466747] [client 20.197.192.193:43781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "libertysolutions.com.br"] [uri "/phpinfo.php1"] [unique_id "al9ZWCKGokixMSfKDOfjjAAAAn0"]
[Tue Jul 21 08:34:48.700345 2026] [security2:error] [pid 466512:tid 466722] [client 20.206.105.145:38942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/h02ugyh.php"] [unique_id "al9ZWCKGokixMSfKDOfjlAAAAmQ"]
[Tue Jul 21 08:34:48.795527 2026] [security2:error] [pid 466512:tid 466648] [client 20.206.105.145:38915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/seiso.php"] [unique_id "al9ZWCKGokixMSfKDOfjlgAAAho"]
[Tue Jul 21 08:34:48.874689 2026] [core:error] [pid 466512:tid 466769] [client 137.184.11.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.kleativ.com.br/
[Tue Jul 21 08:34:48.874709 2026] [core:error] [pid 466512:tid 466769] [client 137.184.11.173:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://webdisk.kleativ.com.br/
[Tue Jul 21 08:34:49.025416 2026] [security2:error] [pid 465652:tid 465890] [client 20.206.105.145:39113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/155.php"] [unique_id "al9ZWTzTqJoBC2Mw28-_fAAAAPE"]
[Tue Jul 21 08:34:49.037256 2026] [security2:error] [pid 466512:tid 466647] [client 213.152.186.163:47478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9ZWSKGokixMSfKDOfjnQAAAhk"]
[Tue Jul 21 08:34:49.037425 2026] [security2:error] [pid 466512:tid 466647] [client 213.152.186.163:47478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9ZWSKGokixMSfKDOfjnQAAAhk"]
[Tue Jul 21 08:34:49.118799 2026] [security2:error] [pid 465652:tid 465898] [client 54.238.43.39:58498] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://user@:80"] [hostname "widereviews.com.oficialwebsite.com.br"] [uri "/"] [unique_id "al9ZWTzTqJoBC2Mw28-_fgAAAPk"]
[Tue Jul 21 08:34:49.124935 2026] [security2:error] [pid 465652:tid 465699] [remote 45.90.123.233:53342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrsolar.org.br"] [uri "/wp-login.php"] [unique_id "al9ZWTzTqJoBC2Mw28-_fwAAmC4"]
[Tue Jul 21 08:34:49.418065 2026] [security2:error] [pid 466512:tid 466669] [client 20.206.105.145:25529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/sss.php"] [unique_id "al9ZWSKGokixMSfKDOfjogAAAi8"]
[Tue Jul 21 08:34:49.463065 2026] [security2:error] [pid 466512:tid 466717] [client 20.206.105.145:38929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ppp.php"] [unique_id "al9ZWSKGokixMSfKDOfjowAAAl8"]
[Tue Jul 21 08:34:49.771200 2026] [security2:error] [pid 465652:tid 465872] [client 20.206.105.145:38939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/201.php"] [unique_id "al9ZWTzTqJoBC2Mw28-_jAAAAN8"]
[Tue Jul 21 08:34:49.846971 2026] [security2:error] [pid 465652:tid 465869] [client 20.220.225.223:50242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/cro.php"] [unique_id "al9ZWTzTqJoBC2Mw28-_kQAAANw"]
[Tue Jul 21 08:34:49.999234 2026] [security2:error] [pid 466512:tid 466682] [client 20.206.105.145:39276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ops.php"] [unique_id "al9ZWSKGokixMSfKDOfjqgAAAjw"]
[Tue Jul 21 08:34:50.267537 2026] [security2:error] [pid 465652:tid 465804] [client 20.206.105.145:39127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ingfo.php"] [unique_id "al9ZWjzTqJoBC2Mw28-_lwAAAJs"]
[Tue Jul 21 08:34:50.417222 2026] [security2:error] [pid 465652:tid 465668] [remote 130.51.180.8:42054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cezadvogados.com"] [uri "/wp-login.php"] [unique_id "al9ZWjzTqJoBC2Mw28-_mgAAyA8"]
[Tue Jul 21 08:34:50.489996 2026] [security2:error] [pid 466512:tid 466680] [client 20.206.105.145:39248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/error_log.php"] [unique_id "al9ZWiKGokixMSfKDOfjrwAAAjo"]
[Tue Jul 21 08:34:50.512719 2026] [security2:error] [pid 466512:tid 466714] [client 20.206.105.145:25413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/c.php"] [unique_id "al9ZWiKGokixMSfKDOfjsAAAAlw"]
[Tue Jul 21 08:34:50.603369 2026] [security2:error] [pid 466512:tid 466765] [client 74.249.245.134:45674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/php8.php"] [unique_id "al9ZWiKGokixMSfKDOfjsgAAAo8"]
[Tue Jul 21 08:34:50.867052 2026] [security2:error] [pid 465652:tid 465867] [client 20.206.105.145:38924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xenon1337.php"] [unique_id "al9ZWjzTqJoBC2Mw28-_ogAAANo"]
[Tue Jul 21 08:34:50.888428 2026] [security2:error] [pid 465652:tid 465671] [remote 45.117.83.212:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9ZWjzTqJoBC2Mw28-_owAAzhI"]
[Tue Jul 21 08:34:50.888645 2026] [security2:error] [pid 465652:tid 465855] [client 45.117.83.212:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9ZWjzTqJoBC2Mw28-_owAAzhI"]
[Tue Jul 21 08:34:51.311237 2026] [security2:error] [pid 465652:tid 465853] [client 202.179.75.202:35720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZWzzTqJoBC2Mw28-_qAAAAMw"]
[Tue Jul 21 08:34:51.311470 2026] [security2:error] [pid 465652:tid 465853] [client 202.179.75.202:35720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZWzzTqJoBC2Mw28-_qAAAAMw"]
[Tue Jul 21 08:34:51.413612 2026] [security2:error] [pid 465652:tid 465707] [remote 5.252.52.249:42466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrsolar.org.br"] [uri "/wp-login.php"] [unique_id "al9ZWzzTqJoBC2Mw28-_rQAA5TY"]
[Tue Jul 21 08:34:51.419624 2026] [security2:error] [pid 465652:tid 465835] [client 195.49.128.211:64312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZWzzTqJoBC2Mw28-_rgAAALo"]
[Tue Jul 21 08:34:51.419751 2026] [security2:error] [pid 465652:tid 465835] [client 195.49.128.211:64312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZWzzTqJoBC2Mw28-_rgAAALo"]
[Tue Jul 21 08:34:51.450526 2026] [security2:error] [pid 465652:tid 465907] [client 20.151.10.161:65526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/about.php"] [unique_id "al9ZWzzTqJoBC2Mw28-_rwAAAQI"]
[Tue Jul 21 08:34:51.553854 2026] [security2:error] [pid 465652:tid 465897] [client 20.206.105.145:39237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/test11.php"] [unique_id "al9ZWzzTqJoBC2Mw28-_sAAAAPg"]
[Tue Jul 21 08:34:51.792079 2026] [security2:error] [pid 465652:tid 465874] [client 20.206.105.145:25521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/aa.php"] [unique_id "al9ZWzzTqJoBC2Mw28-_uQAAAOE"]
[Tue Jul 21 08:34:52.023364 2026] [security2:error] [pid 466512:tid 466702] [client 20.151.10.161:63705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/admin.php"] [unique_id "al9ZXCKGokixMSfKDOfjvAAAAlA"]
[Tue Jul 21 08:34:52.119226 2026] [security2:error] [pid 465652:tid 465691] [remote 45.79.123.44:56688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9ZXDzTqJoBC2Mw28-_vwAAxCY"]
[Tue Jul 21 08:34:52.119410 2026] [security2:error] [pid 465652:tid 465845] [client 45.79.123.44:56688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9ZXDzTqJoBC2Mw28-_vwAAxCY"]
[Tue Jul 21 08:34:52.460511 2026] [security2:error] [pid 466512:tid 466767] [client 20.151.10.161:63684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/admin.php"] [unique_id "al9ZXCKGokixMSfKDOfjwQAAApE"]
[Tue Jul 21 08:34:52.527376 2026] [security2:error] [pid 465652:tid 465862] [client 20.206.105.145:38935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/koala.php"] [unique_id "al9ZXDzTqJoBC2Mw28-_xQAAANU"]
[Tue Jul 21 08:34:52.527836 2026] [security2:error] [pid 466512:tid 466711] [client 20.206.105.145:21969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/scxy.php"] [unique_id "al9ZXCKGokixMSfKDOfjwgAAAlk"]
[Tue Jul 21 08:34:52.672437 2026] [security2:error] [pid 466512:tid 466653] [client 20.220.225.223:50395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/cron-tab.php"] [unique_id "al9ZXCKGokixMSfKDOfjwwAAAh8"]
[Tue Jul 21 08:34:52.688510 2026] [security2:error] [pid 466512:tid 466677] [client 122.176.100.127:60068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZXCKGokixMSfKDOfjxQAAAjc"]
[Tue Jul 21 08:34:52.688602 2026] [security2:error] [pid 466512:tid 466677] [client 122.176.100.127:60068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZXCKGokixMSfKDOfjxQAAAjc"]
[Tue Jul 21 08:34:52.813602 2026] [security2:error] [pid 466512:tid 466731] [client 20.206.105.145:25512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/100.php"] [unique_id "al9ZXCKGokixMSfKDOfjxwAAAm0"]
[Tue Jul 21 08:34:52.814410 2026] [security2:error] [pid 466512:tid 466648] [client 20.151.10.161:65458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/edit.php"] [unique_id "al9ZXCKGokixMSfKDOfjyAAAAho"]
[Tue Jul 21 08:34:52.858382 2026] [security2:error] [pid 466512:tid 466716] [client 20.206.105.145:39117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/mac.php"] [unique_id "al9ZXCKGokixMSfKDOfjyQAAAl4"]
[Tue Jul 21 08:34:53.042156 2026] [security2:error] [pid 466512:tid 466595] [remote 154.61.75.100:40492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ZXSKGokixMSfKDOfjzQACFFI"]
[Tue Jul 21 08:34:53.118751 2026] [security2:error] [pid 466512:tid 466761] [client 20.151.10.161:65498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9ZXSKGokixMSfKDOfj0AAAAos"]
[Tue Jul 21 08:34:53.323382 2026] [security2:error] [pid 466512:tid 466667] [client 74.249.245.134:46174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/info.php"] [unique_id "al9ZXSKGokixMSfKDOfj1QAAAi0"]
[Tue Jul 21 08:34:53.324594 2026] [security2:error] [pid 465652:tid 465844] [client 20.206.105.145:38955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/25d653587fdfd1.php"] [unique_id "al9ZXTzTqJoBC2Mw28-_0gAAAMM"]
[Tue Jul 21 08:34:53.463691 2026] [security2:error] [pid 466512:tid 466673] [client 20.151.10.161:63693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/f6.php"] [unique_id "al9ZXSKGokixMSfKDOfj2AAAAjM"]
[Tue Jul 21 08:34:53.662986 2026] [security2:error] [pid 466512:tid 466742] [client 20.206.105.145:38946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wefile.php"] [unique_id "al9ZXSKGokixMSfKDOfj3QAAAng"]
[Tue Jul 21 08:34:53.722864 2026] [proxy:error] [pid 466512:tid 466722] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:53.722936 2026] [proxy_http:error] [pid 466512:tid 466722] [client 20.206.105.145:38940] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:53.723517 2026] [proxy:error] [pid 466512:tid 466722] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:53.723561 2026] [proxy_http:error] [pid 466512:tid 466722] [client 20.206.105.145:38940] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:53.745126 2026] [proxy:error] [pid 466512:tid 466751] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:53.745197 2026] [proxy_http:error] [pid 466512:tid 466751] [client 20.206.105.145:39290] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:53.745857 2026] [proxy:error] [pid 466512:tid 466751] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:53.745885 2026] [proxy_http:error] [pid 466512:tid 466751] [client 20.206.105.145:39290] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:53.777782 2026] [security2:error] [pid 465652:tid 465856] [client 117.213.202.34:53772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZXTzTqJoBC2Mw28-_2QAAAM8"]
[Tue Jul 21 08:34:53.777921 2026] [security2:error] [pid 465652:tid 465856] [client 117.213.202.34:53772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZXTzTqJoBC2Mw28-_2QAAAM8"]
[Tue Jul 21 08:34:53.788854 2026] [security2:error] [pid 466512:tid 466648] [client 20.151.10.161:63638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/inputs.php"] [unique_id "al9ZXSKGokixMSfKDOfj5AAAAho"]
[Tue Jul 21 08:34:53.890000 2026] [security2:error] [pid 465652:tid 465897] [client 20.206.105.145:39121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9ZXTzTqJoBC2Mw28-_2wAAAPg"]
[Tue Jul 21 08:34:53.951810 2026] [security2:error] [pid 466512:tid 466723] [client 223.181.60.88:3783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZXSKGokixMSfKDOfj5QAAAmU"]
[Tue Jul 21 08:34:53.951920 2026] [security2:error] [pid 466512:tid 466723] [client 223.181.60.88:3783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZXSKGokixMSfKDOfj5QAAAmU"]
[Tue Jul 21 08:34:54.019439 2026] [autoindex:error] [pid 465652:tid 465899] [client 1.13.158.23:40218] AH01276: Cannot serve directory /home4/bcaccj52/accjbr.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:54.143034 2026] [security2:error] [pid 466512:tid 466698] [client 103.255.105.130:20236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZXiKGokixMSfKDOfj5gAAAkw"]
[Tue Jul 21 08:34:54.143210 2026] [security2:error] [pid 466512:tid 466698] [client 103.255.105.130:20236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZXiKGokixMSfKDOfj5gAAAkw"]
[Tue Jul 21 08:34:54.143798 2026] [security2:error] [pid 465652:tid 465796] [client 20.151.10.161:65510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/inputs.php"] [unique_id "al9ZXjzTqJoBC2Mw28-_4gAAAJM"]
[Tue Jul 21 08:34:54.230207 2026] [security2:error] [pid 465652:tid 465901] [client 20.206.105.145:38925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/2P.php"] [unique_id "al9ZXjzTqJoBC2Mw28-_5AAAAPw"]
[Tue Jul 21 08:34:54.547682 2026] [security2:error] [pid 465652:tid 465851] [client 20.151.10.161:65512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/av.php"] [unique_id "al9ZXjzTqJoBC2Mw28-_6gAAAMo"]
[Tue Jul 21 08:34:54.773364 2026] [security2:error] [pid 465652:tid 465822] [client 20.206.105.145:39140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/.well-known/about.php"] [unique_id "al9ZXjzTqJoBC2Mw28-_7gAAAK0"]
[Tue Jul 21 08:34:54.896547 2026] [security2:error] [pid 465652:tid 465666] [remote 104.28.249.138:41060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.249.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.somoszeroum.com.br"] [uri "/wp-login.php"] [unique_id "al9ZXDzTqJoBC2Mw28-_yQAArg0"], referer: https://www.somoszeroum.com.br/wp-admin/
[Tue Jul 21 08:34:54.899883 2026] [security2:error] [pid 465652:tid 465786] [client 20.151.10.161:65468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/classwithtostring.php"] [unique_id "al9ZXjzTqJoBC2Mw28-_9gAAAIk"]
[Tue Jul 21 08:34:55.180006 2026] [security2:error] [pid 465652:tid 465870] [client 20.151.10.161:63699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9ZXzzTqJoBC2Mw28-__gAAAN0"]
[Tue Jul 21 08:34:55.189146 2026] [security2:error] [pid 465652:tid 465828] [client 20.206.105.145:21960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/FWAZ.php"] [unique_id "al9ZXzzTqJoBC2Mw28-__wAAALM"]
[Tue Jul 21 08:34:55.483536 2026] [security2:error] [pid 466512:tid 466717] [client 20.151.10.161:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wp-blog.php"] [unique_id "al9ZXyKGokixMSfKDOfj7gAAAl8"]
[Tue Jul 21 08:34:55.599958 2026] [security2:error] [pid 465652:tid 465896] [client 20.206.105.145:38913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9ZXzzTqJoBC2Mw28_AEQAAAPc"]
[Tue Jul 21 08:34:55.710707 2026] [security2:error] [pid 466512:tid 466656] [client 187.125.243.197:56525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZXyKGokixMSfKDOfj8gAAAiI"]
[Tue Jul 21 08:34:55.710848 2026] [security2:error] [pid 466512:tid 466656] [client 187.125.243.197:56525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZXyKGokixMSfKDOfj8gAAAiI"]
[Tue Jul 21 08:34:55.795019 2026] [security2:error] [pid 465652:tid 465844] [client 65.21.113.253:48566] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZXzzTqJoBC2Mw28_ACwAAAMM"]
[Tue Jul 21 08:34:55.819433 2026] [security2:error] [pid 465652:tid 465747] [remote 152.53.111.131:41146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-login.php"] [unique_id "al9ZXzzTqJoBC2Mw28_ARwABAl4"]
[Tue Jul 21 08:34:55.826445 2026] [autoindex:error] [pid 466512:tid 466762] [client 20.151.10.161:65463] AH01276: Cannot serve directory /home3/chave482/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:55.833089 2026] [security2:error] [pid 466512:tid 466654] [client 20.206.105.145:25561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/footer.php"] [unique_id "al9ZXyKGokixMSfKDOfkEAAAAiA"]
[Tue Jul 21 08:34:55.856650 2026] [security2:error] [pid 465652:tid 465813] [client 195.49.128.211:55934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZXzzTqJoBC2Mw28_ATAAAAKQ"]
[Tue Jul 21 08:34:55.856730 2026] [security2:error] [pid 465652:tid 465813] [client 195.49.128.211:55934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZXzzTqJoBC2Mw28_ATAAAAKQ"]
[Tue Jul 21 08:34:56.101316 2026] [security2:error] [pid 466512:tid 466669] [client 20.151.10.161:65463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9ZYCKGokixMSfKDOfkEwAAAi8"]
[Tue Jul 21 08:34:56.181276 2026] [security2:error] [pid 465652:tid 465821] [client 20.220.225.223:50898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/koiy.php"] [unique_id "al9ZYDzTqJoBC2Mw28_AWQAAAKw"]
[Tue Jul 21 08:34:56.340596 2026] [security2:error] [pid 466512:tid 466747] [client 20.206.105.145:38933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/bob.php"] [unique_id "al9ZYCKGokixMSfKDOfkHQAAAn0"]
[Tue Jul 21 08:34:56.479020 2026] [security2:error] [pid 466512:tid 466695] [client 20.151.10.161:63680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/adminfuns.php"] [unique_id "al9ZYCKGokixMSfKDOfkJQAAAkk"]
[Tue Jul 21 08:34:56.517373 2026] [security2:error] [pid 465652:tid 465663] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZYDzTqJoBC2Mw28_AbgAA8go"]
[Tue Jul 21 08:34:56.517497 2026] [security2:error] [pid 465652:tid 465891] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZYDzTqJoBC2Mw28_AbgAA8go"]
[Tue Jul 21 08:34:56.573963 2026] [security2:error] [pid 465652:tid 465902] [client 103.151.46.103:51974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZYDzTqJoBC2Mw28_AbwAAAP0"]
[Tue Jul 21 08:34:56.574095 2026] [security2:error] [pid 465652:tid 465902] [client 103.151.46.103:51974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZYDzTqJoBC2Mw28_AbwAAAP0"]
[Tue Jul 21 08:34:57.095926 2026] [security2:error] [pid 465652:tid 465853] [client 20.151.10.161:65437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/goods.php"] [unique_id "al9ZYTzTqJoBC2Mw28_AegAAAMw"]
[Tue Jul 21 08:34:57.191944 2026] [security2:error] [pid 465652:tid 465820] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZYTzTqJoBC2Mw28_AeQAAqzs"]
[Tue Jul 21 08:34:57.305624 2026] [security2:error] [pid 465652:tid 465889] [client 5.38.115.39:53686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZYTzTqJoBC2Mw28_AgQAAAPA"]
[Tue Jul 21 08:34:57.305844 2026] [security2:error] [pid 465652:tid 465889] [client 5.38.115.39:53686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZYTzTqJoBC2Mw28_AgQAAAPA"]
[Tue Jul 21 08:34:57.545408 2026] [security2:error] [pid 466512:tid 466704] [client 20.151.10.161:65523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/ms-edit.php"] [unique_id "al9ZYSKGokixMSfKDOfkMAAAAlI"]
[Tue Jul 21 08:34:57.550789 2026] [security2:error] [pid 465652:tid 465684] [remote 132.148.72.88:39736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compressoresra.com.br"] [uri "/wp-login.php"] [unique_id "al9ZYTzTqJoBC2Mw28_AigAA6h8"]
[Tue Jul 21 08:34:57.887003 2026] [security2:error] [pid 466512:tid 466709] [client 20.151.10.161:63717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/222.php"] [unique_id "al9ZYSKGokixMSfKDOfkMgAAAlc"]
[Tue Jul 21 08:34:57.922910 2026] [security2:error] [pid 465652:tid 465795] [client 20.206.105.145:25474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/users.php"] [unique_id "al9ZYTzTqJoBC2Mw28_AjwAAAJI"]
[Tue Jul 21 08:34:58.331735 2026] [security2:error] [pid 465652:tid 465702] [remote 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZYjzTqJoBC2Mw28_AmwAA8jE"]
[Tue Jul 21 08:34:58.396869 2026] [security2:error] [pid 465652:tid 465862] [client 49.144.66.253:29821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZYjzTqJoBC2Mw28_AnwAAANU"]
[Tue Jul 21 08:34:58.397013 2026] [security2:error] [pid 465652:tid 465862] [client 49.144.66.253:29821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZYjzTqJoBC2Mw28_AnwAAANU"]
[Tue Jul 21 08:34:58.437926 2026] [proxy:error] [pid 466512:tid 466747] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:58.437994 2026] [proxy_http:error] [pid 466512:tid 466747] [client 20.206.105.145:39232] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:58.439370 2026] [proxy:error] [pid 466512:tid 466747] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:34:58.439438 2026] [proxy_http:error] [pid 466512:tid 466747] [client 20.206.105.145:39232] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:34:58.542588 2026] [security2:error] [pid 465652:tid 465740] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.shopmelhorcompraonline.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9ZYjzTqJoBC2Mw28_ApgABA1c"]
[Tue Jul 21 08:34:58.581548 2026] [security2:error] [pid 465652:tid 465799] [client 14.245.224.124:62534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZYjzTqJoBC2Mw28_AqAAAAJY"]
[Tue Jul 21 08:34:58.581672 2026] [security2:error] [pid 465652:tid 465799] [client 14.245.224.124:62534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZYjzTqJoBC2Mw28_AqAAAAJY"]
[Tue Jul 21 08:34:58.609422 2026] [security2:error] [pid 466512:tid 466716] [client 20.151.10.161:65486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9ZYiKGokixMSfKDOfkPwAAAl4"]
[Tue Jul 21 08:34:58.776592 2026] [security2:error] [pid 465652:tid 465893] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZYjzTqJoBC2Mw28_AmgAAAPQ"]
[Tue Jul 21 08:34:58.789841 2026] [security2:error] [pid 465652:tid 465670] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.shopmelhorcompraonline.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9ZYjzTqJoBC2Mw28_ArgAA3hE"]
[Tue Jul 21 08:34:58.896211 2026] [security2:error] [pid 465652:tid 465804] [client 152.59.34.51:15432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZYjzTqJoBC2Mw28_AvAAAAJs"]
[Tue Jul 21 08:34:58.896306 2026] [security2:error] [pid 465652:tid 465804] [client 152.59.34.51:15432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZYjzTqJoBC2Mw28_AvAAAAJs"]
[Tue Jul 21 08:34:59.003840 2026] [security2:error] [pid 465652:tid 465724] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.shopmelhorcompraonline.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9ZYzzTqJoBC2Mw28_AvQAA_Ec"]
[Tue Jul 21 08:34:59.242151 2026] [security2:error] [pid 465652:tid 465678] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.shopmelhorcompraonline.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9ZYzzTqJoBC2Mw28_AwgAA-hk"]
[Tue Jul 21 08:34:59.285731 2026] [security2:error] [pid 466512:tid 466754] [client 20.220.225.223:50883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/hp2.php"] [unique_id "al9ZYyKGokixMSfKDOfkWAAAAoQ"]
[Tue Jul 21 08:34:59.449338 2026] [autoindex:error] [pid 466512:tid 466697] [client 20.151.10.161:65416] AH01276: Cannot serve directory /home3/chave482/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:34:59.449923 2026] [security2:error] [pid 465652:tid 465723] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.shopmelhorcompraonline.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9ZYzzTqJoBC2Mw28_AxgAA5kY"]
[Tue Jul 21 08:34:59.661222 2026] [security2:error] [pid 465652:tid 465699] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.shopmelhorcompraonline.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9ZYzzTqJoBC2Mw28_AygAAry4"]
[Tue Jul 21 08:34:59.736030 2026] [security2:error] [pid 466512:tid 466722] [client 20.151.10.161:65416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9ZYyKGokixMSfKDOfkXgAAAmQ"]
[Tue Jul 21 08:34:59.848339 2026] [security2:error] [pid 465652:tid 465837] [client 20.206.105.145:25581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/177.php"] [unique_id "al9ZYzzTqJoBC2Mw28_AzAAAALw"]
[Tue Jul 21 08:34:59.853432 2026] [security2:error] [pid 466512:tid 466723] [client 61.1.167.83:60663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZYyKGokixMSfKDOfkYQAAAmU"]
[Tue Jul 21 08:34:59.853557 2026] [security2:error] [pid 466512:tid 466723] [client 61.1.167.83:60663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZYyKGokixMSfKDOfkYQAAAmU"]
[Tue Jul 21 08:34:59.881162 2026] [security2:error] [pid 465652:tid 465655] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.shopmelhorcompraonline.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9ZYzzTqJoBC2Mw28_AzgAAogI"]
[Tue Jul 21 08:34:59.987599 2026] [security2:error] [pid 466512:tid 466677] [client 5.31.193.106:29959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZYyKGokixMSfKDOfkYgAAAjc"]
[Tue Jul 21 08:34:59.987709 2026] [security2:error] [pid 466512:tid 466677] [client 5.31.193.106:29959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZYyKGokixMSfKDOfkYgAAAjc"]
[Tue Jul 21 08:35:00.087397 2026] [security2:error] [pid 465652:tid 465668] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.shopmelhorcompraonline.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9ZZDzTqJoBC2Mw28_A1AAA1Q8"]
[Tue Jul 21 08:35:00.100657 2026] [security2:error] [pid 466512:tid 466668] [client 74.249.245.134:50084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/edit.php"] [unique_id "al9ZZCKGokixMSfKDOfkZQAAAi4"]
[Tue Jul 21 08:35:00.242841 2026] [security2:error] [pid 466512:tid 466631] [remote 192.241.143.148:42104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9ZZCKGokixMSfKDOfkZgACKnY"]
[Tue Jul 21 08:35:00.299240 2026] [security2:error] [pid 465652:tid 465734] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.shopmelhorcompraonline.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9ZZDzTqJoBC2Mw28_A1QAAs1E"]
[Tue Jul 21 08:35:00.511080 2026] [proxy:error] [pid 466512:tid 466767] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:00.511169 2026] [proxy_http:error] [pid 466512:tid 466767] [client 20.206.105.145:38926] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:00.511614 2026] [proxy:error] [pid 466512:tid 466767] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:00.511645 2026] [proxy_http:error] [pid 466512:tid 466767] [client 20.206.105.145:38926] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:00.549075 2026] [security2:error] [pid 465652:tid 465745] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.shopmelhorcompraonline.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9ZZDzTqJoBC2Mw28_A2wAA5Vw"]
[Tue Jul 21 08:35:00.754529 2026] [security2:error] [pid 465652:tid 465722] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.shopmelhorcompraonline.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9ZZDzTqJoBC2Mw28_A4QAA9EU"]
[Tue Jul 21 08:35:00.903977 2026] [security2:error] [pid 466512:tid 466643] [client 20.206.105.145:25130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/config.php"] [unique_id "al9ZZCKGokixMSfKDOfkdAAAAhU"]
[Tue Jul 21 08:35:00.978583 2026] [security2:error] [pid 465652:tid 465690] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.shopmelhorcompraonline.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9ZZDzTqJoBC2Mw28_A5QAA-SU"]
[Tue Jul 21 08:35:01.074896 2026] [security2:error] [pid 465652:tid 465820] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZZDzTqJoBC2Mw28_A3wAAAKs"]
[Tue Jul 21 08:35:01.135555 2026] [security2:error] [pid 465652:tid 465856] [client 20.206.105.145:21989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/qterm.php"] [unique_id "al9ZZTzTqJoBC2Mw28_A6QAAAM8"]
[Tue Jul 21 08:35:01.226669 2026] [security2:error] [pid 465652:tid 465798] [client 20.220.225.223:50886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/hp3.php"] [unique_id "al9ZZTzTqJoBC2Mw28_A6wAAAJU"]
[Tue Jul 21 08:35:01.551506 2026] [security2:error] [pid 465652:tid 465660] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9ZZTzTqJoBC2Mw28_A7wAA7gc"]
[Tue Jul 21 08:35:01.724725 2026] [security2:error] [pid 465652:tid 465744] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9ZZTzTqJoBC2Mw28_A9gAAzVs"]
[Tue Jul 21 08:35:01.864376 2026] [security2:error] [pid 466512:tid 466661] [client 20.206.105.145:39280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/crgio.php"] [unique_id "al9ZZSKGokixMSfKDOfkfgAAAic"]
[Tue Jul 21 08:35:01.949572 2026] [autoindex:error] [pid 465652:tid 465870] [client 20.151.10.161:63664] AH01276: Cannot serve directory /home3/chave482/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:35:02.008668 2026] [security2:error] [pid 466512:tid 466682] [client 195.49.128.211:64926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZZiKGokixMSfKDOfkfwAAAjw"]
[Tue Jul 21 08:35:02.009069 2026] [security2:error] [pid 466512:tid 466682] [client 195.49.128.211:64926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZZiKGokixMSfKDOfkfwAAAjw"]
[Tue Jul 21 08:35:02.161849 2026] [security2:error] [pid 465652:tid 465891] [client 202.179.75.202:38098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZZjzTqJoBC2Mw28_BAAAAAPI"]
[Tue Jul 21 08:35:02.162025 2026] [security2:error] [pid 465652:tid 465891] [client 202.179.75.202:38098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZZjzTqJoBC2Mw28_BAAAAAPI"]
[Tue Jul 21 08:35:02.179218 2026] [security2:error] [pid 466512:tid 466517] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/wp.php"] [unique_id "al9ZZiKGokixMSfKDOfkggACjQQ"]
[Tue Jul 21 08:35:02.361304 2026] [security2:error] [pid 465652:tid 465766] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/new.php"] [unique_id "al9ZZjzTqJoBC2Mw28_BAQAArnE"]
[Tue Jul 21 08:35:02.363440 2026] [security2:error] [pid 465652:tid 465823] [client 20.206.105.145:25111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/gettest.php"] [unique_id "al9ZZjzTqJoBC2Mw28_BAgAAAK4"]
[Tue Jul 21 08:35:02.457699 2026] [security2:error] [pid 466512:tid 466656] [client 20.206.105.145:21956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/blurbs.php"] [unique_id "al9ZZiKGokixMSfKDOfkhQAAAiI"]
[Tue Jul 21 08:35:02.499413 2026] [security2:error] [pid 465652:tid 465865] [client 20.220.225.223:50303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/aa1.php"] [unique_id "al9ZZjzTqJoBC2Mw28_BBQAAANg"]
[Tue Jul 21 08:35:02.537589 2026] [security2:error] [pid 466512:tid 466561] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/class-t.api.php"] [unique_id "al9ZZiKGokixMSfKDOfkhgACYjA"]
[Tue Jul 21 08:35:02.682503 2026] [autoindex:error] [pid 465652:tid 465812] [client 20.151.10.161:63664] AH01276: Cannot serve directory /home3/chave482/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:35:02.729865 2026] [security2:error] [pid 465652:tid 465701] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/plugins.php"] [unique_id "al9ZZjzTqJoBC2Mw28_BDgAAqTA"]
[Tue Jul 21 08:35:02.802756 2026] [security2:error] [pid 466512:tid 466750] [client 74.7.230.50:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gopark1746020254824.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9ZZiKGokixMSfKDOfkiwACgCs"]
[Tue Jul 21 08:35:02.820151 2026] [security2:error] [pid 465652:tid 465793] [client 20.151.10.161:63664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/raw.php"] [unique_id "al9ZZjzTqJoBC2Mw28_BDwAAAJA"]
[Tue Jul 21 08:35:02.875099 2026] [security2:error] [pid 465652:tid 465848] [client 185.213.175.37:10304] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bcsenepol.com.br"] [uri "/2015/06/15/amazing-quote-post/feed/"] [unique_id "al9ZZjzTqJoBC2Mw28_BEQAAAMc"]
[Tue Jul 21 08:35:02.922031 2026] [security2:error] [pid 466512:tid 466601] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/jp.php"] [unique_id "al9ZZiKGokixMSfKDOfkjgACW1g"]
[Tue Jul 21 08:35:03.003210 2026] [security2:error] [pid 466512:tid 466752] [client 185.213.175.37:10340] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bcsenepol.com.br"] [uri "/2017/05/18/ola-mundo/feed/"] [unique_id "al9ZZyKGokixMSfKDOfkkQAAAoI"]
[Tue Jul 21 08:35:03.016697 2026] [security2:error] [pid 465652:tid 465820] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZZjzTqJoBC2Mw28_BBgAAAKs"]
[Tue Jul 21 08:35:03.107372 2026] [security2:error] [pid 465652:tid 465707] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/error.php"] [unique_id "al9ZZzzTqJoBC2Mw28_BFwAA8TY"]
[Tue Jul 21 08:35:03.141213 2026] [security2:error] [pid 465652:tid 465804] [client 122.176.100.127:60562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZZzzTqJoBC2Mw28_BGAAAAJs"]
[Tue Jul 21 08:35:03.145684 2026] [security2:error] [pid 465652:tid 465804] [client 122.176.100.127:60562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZZzzTqJoBC2Mw28_BGAAAAJs"]
[Tue Jul 21 08:35:03.277805 2026] [security2:error] [pid 466512:tid 466583] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/classwithtostring.php"] [unique_id "al9ZZyKGokixMSfKDOfklQACJkY"]
[Tue Jul 21 08:35:03.403158 2026] [security2:error] [pid 466512:tid 466742] [client 128.127.105.184:45844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZZyKGokixMSfKDOfkmwAAAng"]
[Tue Jul 21 08:35:03.403270 2026] [security2:error] [pid 466512:tid 466742] [client 128.127.105.184:45844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZZyKGokixMSfKDOfkmwAAAng"]
[Tue Jul 21 08:35:03.461919 2026] [security2:error] [pid 465652:tid 465741] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/bless.php"] [unique_id "al9ZZzzTqJoBC2Mw28_BHwAAzVg"]
[Tue Jul 21 08:35:03.592732 2026] [security2:error] [pid 466512:tid 466646] [client 89.238.167.134:54114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9ZZyKGokixMSfKDOfknAAAAhg"]
[Tue Jul 21 08:35:03.592863 2026] [security2:error] [pid 466512:tid 466646] [client 89.238.167.134:54114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9ZZyKGokixMSfKDOfknAAAAhg"]
[Tue Jul 21 08:35:03.628070 2026] [security2:error] [pid 466512:tid 466740] [client 34.74.242.206:1697] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "premiumgrupo.com.br"] [uri "/robots.txt"] [unique_id "al9ZZyKGokixMSfKDOfkoQAAAnY"]
[Tue Jul 21 08:35:03.628182 2026] [security2:error] [pid 466512:tid 466740] [client 34.74.242.206:1697] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "premiumgrupo.com.br"] [uri "/robots.txt"] [unique_id "al9ZZyKGokixMSfKDOfkoQAAAnY"]
[Tue Jul 21 08:35:03.631062 2026] [security2:error] [pid 466512:tid 466576] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/storage/index.php"] [unique_id "al9ZZyKGokixMSfKDOfkogACFD8"]
[Tue Jul 21 08:35:03.734995 2026] [security2:error] [pid 466512:tid 466686] [client 20.206.105.145:39232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/pucci.php"] [unique_id "al9ZZyKGokixMSfKDOfkpgAAAkA"]
[Tue Jul 21 08:35:03.821032 2026] [security2:error] [pid 465652:tid 465718] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/g.php"] [unique_id "al9ZZzzTqJoBC2Mw28_BKQAAs0E"]
[Tue Jul 21 08:35:03.855767 2026] [security2:error] [pid 466512:tid 466652] [client 74.249.245.134:50352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/166.php"] [unique_id "al9ZZyKGokixMSfKDOfkqwAAAh4"]
[Tue Jul 21 08:35:03.866675 2026] [security2:error] [pid 465652:tid 465873] [client 34.74.242.206:1698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "premiumgrupo.com.br"] [uri "/"] [unique_id "al9ZZzzTqJoBC2Mw28_BLAAAAOA"]
[Tue Jul 21 08:35:03.866746 2026] [security2:error] [pid 465652:tid 465873] [client 34.74.242.206:1698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "premiumgrupo.com.br"] [uri "/"] [unique_id "al9ZZzzTqJoBC2Mw28_BLAAAAOA"]
[Tue Jul 21 08:35:03.983856 2026] [security2:error] [pid 466512:tid 466522] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/nf.php"] [unique_id "al9ZZyKGokixMSfKDOfkrQACXwk"]
[Tue Jul 21 08:35:04.190545 2026] [security2:error] [pid 465652:tid 465677] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/xda.php"] [unique_id "al9ZaDzTqJoBC2Mw28_BLwAA3hg"]
[Tue Jul 21 08:35:04.357473 2026] [security2:error] [pid 466512:tid 466746] [client 117.213.202.34:54364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZaCKGokixMSfKDOfksQAAAnw"]
[Tue Jul 21 08:35:04.357779 2026] [security2:error] [pid 466512:tid 466746] [client 117.213.202.34:54364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZaCKGokixMSfKDOfksQAAAnw"]
[Tue Jul 21 08:35:04.361328 2026] [security2:error] [pid 465652:tid 465670] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/shell.php"] [unique_id "al9ZaDzTqJoBC2Mw28_BMwAAwBE"]
[Tue Jul 21 08:35:04.548681 2026] [security2:error] [pid 465652:tid 465770] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/3.php"] [unique_id "al9ZaDzTqJoBC2Mw28_BNwAA33U"]
[Tue Jul 21 08:35:04.691437 2026] [security2:error] [pid 465652:tid 465812] [client 20.151.10.161:65501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/abcd.php"] [unique_id "al9ZaDzTqJoBC2Mw28_BOwAAAKM"]
[Tue Jul 21 08:35:04.718719 2026] [security2:error] [pid 465652:tid 465724] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/mds.php"] [unique_id "al9ZaDzTqJoBC2Mw28_BPgAAqEc"]
[Tue Jul 21 08:35:04.872205 2026] [security2:error] [pid 466512:tid 466751] [client 103.255.105.130:37533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZaCKGokixMSfKDOfkvgAAAoE"]
[Tue Jul 21 08:35:04.872312 2026] [security2:error] [pid 466512:tid 466751] [client 103.255.105.130:37533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZaCKGokixMSfKDOfkvgAAAoE"]
[Tue Jul 21 08:35:04.895626 2026] [security2:error] [pid 465652:tid 465671] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/archive.php"] [unique_id "al9ZaDzTqJoBC2Mw28_BQQAAkBI"]
[Tue Jul 21 08:35:04.936973 2026] [security2:error] [pid 465652:tid 465883] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZaDzTqJoBC2Mw28_BNQAAAOo"]
[Tue Jul 21 08:35:04.948841 2026] [security2:error] [pid 465652:tid 465848] [client 20.220.225.223:50938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/acew67.php"] [unique_id "al9ZaDzTqJoBC2Mw28_BQgAAAMc"]
[Tue Jul 21 08:35:04.981664 2026] [security2:error] [pid 465652:tid 465901] [client 20.206.105.145:21986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/v543.php"] [unique_id "al9ZaDzTqJoBC2Mw28_BQwAAAPw"]
[Tue Jul 21 08:35:05.017862 2026] [security2:error] [pid 465652:tid 465889] [client 223.181.60.88:3026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZaTzTqJoBC2Mw28_BRAAAAPA"]
[Tue Jul 21 08:35:05.018025 2026] [security2:error] [pid 465652:tid 465889] [client 223.181.60.88:3026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZaTzTqJoBC2Mw28_BRAAAAPA"]
[Tue Jul 21 08:35:05.067744 2026] [security2:error] [pid 465652:tid 465655] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/amax.php"] [unique_id "al9ZaTzTqJoBC2Mw28_BVQAA4gI"]
[Tue Jul 21 08:35:05.266456 2026] [security2:error] [pid 465652:tid 465762] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/moon.php"] [unique_id "al9ZaTzTqJoBC2Mw28_BmwAA-W0"]
[Tue Jul 21 08:35:05.582167 2026] [security2:error] [pid 466512:tid 466715] [client 20.206.105.145:25112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/min.php"] [unique_id "al9ZaSKGokixMSfKDOflBQAAAl0"]
[Tue Jul 21 08:35:05.809782 2026] [security2:error] [pid 466512:tid 466682] [client 20.206.105.145:22094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/w3lls.php"] [unique_id "al9ZaSKGokixMSfKDOflDgAAAjw"]
[Tue Jul 21 08:35:05.818831 2026] [security2:error] [pid 465652:tid 465701] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/ws83.php"] [unique_id "al9ZaTzTqJoBC2Mw28_BpgAAszA"]
[Tue Jul 21 08:35:05.879448 2026] [security2:error] [pid 465652:tid 465772] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZaDzTqJoBC2Mw28_BPQAAv3c"]
[Tue Jul 21 08:35:05.879647 2026] [security2:error] [pid 465652:tid 465840] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZaDzTqJoBC2Mw28_BPQAAv3c"]
[Tue Jul 21 08:35:06.004219 2026] [security2:error] [pid 465652:tid 465707] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/CDX1.php"] [unique_id "al9ZajzTqJoBC2Mw28_BqgAArDY"]
[Tue Jul 21 08:35:06.181722 2026] [security2:error] [pid 465652:tid 465666] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/inputs.php"] [unique_id "al9ZajzTqJoBC2Mw28_BsQAA1w0"]
[Tue Jul 21 08:35:06.190761 2026] [security2:error] [pid 466512:tid 466646] [client 187.125.243.197:57032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZaiKGokixMSfKDOflFwAAAhg"]
[Tue Jul 21 08:35:06.192180 2026] [security2:error] [pid 466512:tid 466646] [client 187.125.243.197:57032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZaiKGokixMSfKDOflFwAAAhg"]
[Tue Jul 21 08:35:06.326834 2026] [proxy:error] [pid 466512:tid 466761] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:06.326935 2026] [proxy_http:error] [pid 466512:tid 466761] [client 20.206.105.145:39129] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:06.329073 2026] [proxy:error] [pid 466512:tid 466761] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:06.329159 2026] [proxy_http:error] [pid 466512:tid 466761] [client 20.206.105.145:39129] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:06.373215 2026] [security2:error] [pid 465652:tid 465741] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/ms-edit.php"] [unique_id "al9ZajzTqJoBC2Mw28_BtgAAkFg"]
[Tue Jul 21 08:35:06.426395 2026] [security2:error] [pid 466512:tid 466699] [client 195.49.128.211:56532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZaiKGokixMSfKDOflHQAAAk0"]
[Tue Jul 21 08:35:06.426500 2026] [security2:error] [pid 466512:tid 466699] [client 195.49.128.211:56532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZaiKGokixMSfKDOflHQAAAk0"]
[Tue Jul 21 08:35:06.493839 2026] [security2:error] [pid 466512:tid 466688] [client 20.151.10.161:65524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/a1.php"] [unique_id "al9ZaiKGokixMSfKDOflHgAAAkI"]
[Tue Jul 21 08:35:06.548206 2026] [security2:error] [pid 465652:tid 465687] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/simple.php"] [unique_id "al9ZajzTqJoBC2Mw28_BuQAAzCI"]
[Tue Jul 21 08:35:06.599472 2026] [security2:error] [pid 466512:tid 466715] [client 167.114.139.17:20750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.arielson.com.br"] [uri "/robots.txt"] [unique_id "al9ZaiKGokixMSfKDOflIAAAAl0"]
[Tue Jul 21 08:35:06.600322 2026] [security2:error] [pid 466512:tid 466715] [client 167.114.139.17:20750] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.arielson.com.br"] [uri "/robots.txt"] [unique_id "al9ZaiKGokixMSfKDOflIAAAAl0"]
[Tue Jul 21 08:35:06.699072 2026] [security2:error] [pid 466512:tid 466745] [client 20.206.105.145:21983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-ws68.php"] [unique_id "al9ZaiKGokixMSfKDOflJwAAAns"]
[Tue Jul 21 08:35:06.718769 2026] [security2:error] [pid 465652:tid 465755] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/404.php"] [unique_id "al9ZajzTqJoBC2Mw28_B_gAAymY"]
[Tue Jul 21 08:35:06.893412 2026] [security2:error] [pid 465652:tid 465732] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/file3.php"] [unique_id "al9ZajzTqJoBC2Mw28_CGAAAwE8"]
[Tue Jul 21 08:35:06.947182 2026] [security2:error] [pid 466512:tid 466756] [client 20.220.225.223:50278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/bscclapb.php"] [unique_id "al9ZaiKGokixMSfKDOfllAAAAoY"]
[Tue Jul 21 08:35:07.070567 2026] [security2:error] [pid 466512:tid 466597] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZayKGokixMSfKDOfloAACM1Q"]
[Tue Jul 21 08:35:07.070694 2026] [security2:error] [pid 466512:tid 466673] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZayKGokixMSfKDOfloAACM1Q"]
[Tue Jul 21 08:35:07.087637 2026] [security2:error] [pid 465652:tid 465684] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/wp-mail.php"] [unique_id "al9ZazzTqJoBC2Mw28_CHwAAqB8"]
[Tue Jul 21 08:35:07.260264 2026] [security2:error] [pid 465652:tid 465705] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/about.php"] [unique_id "al9ZazzTqJoBC2Mw28_CIQAA3zQ"]
[Tue Jul 21 08:35:07.302000 2026] [security2:error] [pid 465652:tid 465883] [client 20.206.105.145:25503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/edorxrr.php"] [unique_id "al9ZazzTqJoBC2Mw28_CIwAAAOo"]
[Tue Jul 21 08:35:07.327592 2026] [security2:error] [pid 465652:tid 465805] [client 103.151.46.103:52485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZazzTqJoBC2Mw28_CJgAAAJw"]
[Tue Jul 21 08:35:07.327744 2026] [security2:error] [pid 465652:tid 465805] [client 103.151.46.103:52485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZazzTqJoBC2Mw28_CJgAAAJw"]
[Tue Jul 21 08:35:07.437367 2026] [security2:error] [pid 465652:tid 465722] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/adminfuns.php"] [unique_id "al9ZazzTqJoBC2Mw28_CKwAApEU"]
[Tue Jul 21 08:35:07.437671 2026] [security2:error] [pid 465652:tid 465889] [client 213.152.186.163:32860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9ZazzTqJoBC2Mw28_CLAAAAPA"]
[Tue Jul 21 08:35:07.437738 2026] [security2:error] [pid 465652:tid 465889] [client 213.152.186.163:32860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9ZazzTqJoBC2Mw28_CLAAAAPA"]
[Tue Jul 21 08:35:07.552531 2026] [security2:error] [pid 466512:tid 466764] [client 20.206.105.145:22000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/xyn.php"] [unique_id "al9ZayKGokixMSfKDOflywAAAo4"]
[Tue Jul 21 08:35:07.608201 2026] [security2:error] [pid 465652:tid 465688] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/php8.php"] [unique_id "al9ZazzTqJoBC2Mw28_CLwAA2yM"]
[Tue Jul 21 08:35:07.763383 2026] [security2:error] [pid 466512:tid 466704] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZayKGokixMSfKDOfl1QACUlg"]
[Tue Jul 21 08:35:07.795876 2026] [security2:error] [pid 465652:tid 465778] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/info.php"] [unique_id "al9ZazzTqJoBC2Mw28_CMwAAsX0"]
[Tue Jul 21 08:35:07.877739 2026] [security2:error] [pid 465652:tid 465853] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZazzTqJoBC2Mw28_CKgAAAMw"]
[Tue Jul 21 08:35:07.904019 2026] [security2:error] [pid 465652:tid 465709] [remote 103.161.172.221:34888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roseoliveirarose.com.br"] [uri "/wp-login.php"] [unique_id "al9ZazzTqJoBC2Mw28_CNQAAmDg"]
[Tue Jul 21 08:35:07.967092 2026] [security2:error] [pid 465652:tid 465718] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/edit.php"] [unique_id "al9ZazzTqJoBC2Mw28_COAAA3UE"]
[Tue Jul 21 08:35:08.016357 2026] [security2:error] [pid 466512:tid 466766] [client 5.38.115.39:18813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZbCKGokixMSfKDOfl7wAAApA"]
[Tue Jul 21 08:35:08.016471 2026] [security2:error] [pid 466512:tid 466766] [client 5.38.115.39:18813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZbCKGokixMSfKDOfl7wAAApA"]
[Tue Jul 21 08:35:08.165198 2026] [security2:error] [pid 465652:tid 465663] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/166.php"] [unique_id "al9ZbDzTqJoBC2Mw28_COQAA5Qo"]
[Tue Jul 21 08:35:08.192598 2026] [security2:error] [pid 466512:tid 466694] [client 54.39.136.218:41768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.arielson.com.br"] [uri "/"] [unique_id "al9ZbCKGokixMSfKDOfl8AAAAkg"]
[Tue Jul 21 08:35:08.192692 2026] [security2:error] [pid 466512:tid 466694] [client 54.39.136.218:41768] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.arielson.com.br"] [uri "/"] [unique_id "al9ZbCKGokixMSfKDOfl8AAAAkg"]
[Tue Jul 21 08:35:08.359080 2026] [security2:error] [pid 465652:tid 465751] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/8.php"] [unique_id "al9ZbDzTqJoBC2Mw28_CPgAA-WI"]
[Tue Jul 21 08:35:08.479850 2026] [security2:error] [pid 465652:tid 465865] [client 20.151.10.161:65479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9ZbDzTqJoBC2Mw28_CQwAAANg"]
[Tue Jul 21 08:35:08.497311 2026] [security2:error] [pid 465652:tid 465841] [client 20.206.105.145:22081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/green3.php"] [unique_id "al9ZbDzTqJoBC2Mw28_CRAAAAMA"]
[Tue Jul 21 08:35:08.530435 2026] [security2:error] [pid 465652:tid 465729] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/ws38.php"] [unique_id "al9ZbDzTqJoBC2Mw28_CRgAAxUw"]
[Tue Jul 21 08:35:08.565852 2026] [proxy:error] [pid 466512:tid 466667] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:08.565925 2026] [proxy_http:error] [pid 466512:tid 466667] [client 20.206.105.145:38978] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:08.566407 2026] [proxy:error] [pid 466512:tid 466667] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:08.566436 2026] [proxy_http:error] [pid 466512:tid 466667] [client 20.206.105.145:38978] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:08.715519 2026] [security2:error] [pid 465652:tid 465746] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/a7.php"] [unique_id "al9ZbDzTqJoBC2Mw28_CRwAA6l0"]
[Tue Jul 21 08:35:08.717391 2026] [security2:error] [pid 466512:tid 466706] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "romuloalexssandro1767236069000.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9ZbCKGokixMSfKDOfmIQACVF0"]
[Tue Jul 21 08:35:08.888078 2026] [security2:error] [pid 465652:tid 465680] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/classsmtps.php"] [unique_id "al9ZbDzTqJoBC2Mw28_CSgAA6Bs"]
[Tue Jul 21 08:35:08.906459 2026] [security2:error] [pid 465652:tid 465793] [client 20.206.105.145:22082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/ccs.php"] [unique_id "al9ZbDzTqJoBC2Mw28_CSwAAAJA"]
[Tue Jul 21 08:35:09.064693 2026] [security2:error] [pid 465652:tid 465732] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/rip.php"] [unique_id "al9ZbTzTqJoBC2Mw28_CUAAA7k8"]
[Tue Jul 21 08:35:09.154277 2026] [security2:error] [pid 465652:tid 465804] [client 20.206.105.145:25497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/hur.php"] [unique_id "al9ZbTzTqJoBC2Mw28_CUgAAAJs"]
[Tue Jul 21 08:35:09.237226 2026] [security2:error] [pid 465652:tid 465744] [remote 74.249.245.134:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.wendelleite.com.br"] [uri "/1.php"] [unique_id "al9ZbTzTqJoBC2Mw28_CUwAA1Vs"]
[Tue Jul 21 08:35:09.237363 2026] [security2:error] [pid 465652:tid 465744] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/1.php"] [unique_id "al9ZbTzTqJoBC2Mw28_CUwAA1Vs"]
[Tue Jul 21 08:35:09.264761 2026] [security2:error] [pid 466512:tid 466714] [client 20.220.225.223:50940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/else1.php"] [unique_id "al9ZbSKGokixMSfKDOfmOwAAAlw"]
[Tue Jul 21 08:35:09.302112 2026] [security2:error] [pid 466512:tid 466674] [client 20.206.105.145:22089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/ccc.php"] [unique_id "al9ZbSKGokixMSfKDOfmPAAAAjQ"]
[Tue Jul 21 08:35:09.347372 2026] [security2:error] [pid 466512:tid 466695] [client 14.245.224.124:63002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZbSKGokixMSfKDOfmPwAAAkk"]
[Tue Jul 21 08:35:09.347636 2026] [security2:error] [pid 466512:tid 466695] [client 14.245.224.124:63002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZbSKGokixMSfKDOfmPwAAAkk"]
[Tue Jul 21 08:35:09.433972 2026] [security2:error] [pid 465652:tid 465803] [client 49.144.66.253:30229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZbTzTqJoBC2Mw28_CVwAAAJo"]
[Tue Jul 21 08:35:09.434156 2026] [security2:error] [pid 465652:tid 465803] [client 49.144.66.253:30229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZbTzTqJoBC2Mw28_CVwAAAJo"]
[Tue Jul 21 08:35:09.572686 2026] [security2:error] [pid 466512:tid 466708] [client 74.249.245.134:8743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/8.php"] [unique_id "al9ZbSKGokixMSfKDOfmSAAAAlY"]
[Tue Jul 21 08:35:09.596354 2026] [security2:error] [pid 466512:tid 466656] [client 152.59.34.51:49682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZbSKGokixMSfKDOfmSwAAAiI"]
[Tue Jul 21 08:35:09.601038 2026] [security2:error] [pid 466512:tid 466656] [client 152.59.34.51:49682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZbSKGokixMSfKDOfmSwAAAiI"]
[Tue Jul 21 08:35:09.648920 2026] [security2:error] [pid 465652:tid 465769] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/chosen.php"] [unique_id "al9ZbTzTqJoBC2Mw28_CWwAA0HQ"]
[Tue Jul 21 08:35:09.772804 2026] [security2:error] [pid 465652:tid 465859] [client 20.151.10.161:65432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9ZbTzTqJoBC2Mw28_CXgAAANI"]
[Tue Jul 21 08:35:09.777489 2026] [security2:error] [pid 465652:tid 465858] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZbTzTqJoBC2Mw28_CVAAAANE"]
[Tue Jul 21 08:35:09.801198 2026] [security2:error] [pid 466512:tid 466747] [client 20.206.105.145:21954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/get.php"] [unique_id "al9ZbSKGokixMSfKDOfmUwAAAn0"]
[Tue Jul 21 08:35:09.830015 2026] [security2:error] [pid 465652:tid 465692] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/css.php"] [unique_id "al9ZbTzTqJoBC2Mw28_CXwABASc"]
[Tue Jul 21 08:35:10.015852 2026] [security2:error] [pid 465652:tid 465712] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/php.php"] [unique_id "al9ZbjzTqJoBC2Mw28_CYQAAojs"]
[Tue Jul 21 08:35:10.030469 2026] [security2:error] [pid 465652:tid 465791] [client 20.206.105.145:21971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/images.php"] [unique_id "al9ZbjzTqJoBC2Mw28_CYgAAAI4"]
[Tue Jul 21 08:35:10.115799 2026] [security2:error] [pid 466512:tid 466674] [client 20.206.105.145:22090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/alls.php"] [unique_id "al9ZbiKGokixMSfKDOfmWgAAAjQ"]
[Tue Jul 21 08:35:10.187273 2026] [security2:error] [pid 465652:tid 465734] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/aa.php"] [unique_id "al9ZbjzTqJoBC2Mw28_CZAAA8VE"]
[Tue Jul 21 08:35:10.204796 2026] [security2:error] [pid 466512:tid 466764] [client 20.206.105.145:22083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/yyu.php"] [unique_id "al9ZbiKGokixMSfKDOfmXAAAAo4"]
[Tue Jul 21 08:35:10.359020 2026] [security2:error] [pid 465652:tid 465688] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/bolt.php"] [unique_id "al9ZbjzTqJoBC2Mw28_CZgAAxyM"]
[Tue Jul 21 08:35:10.494051 2026] [security2:error] [pid 465652:tid 465817] [client 20.151.10.161:65479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9ZbjzTqJoBC2Mw28_CaQAAAKg"]
[Tue Jul 21 08:35:10.905228 2026] [security2:error] [pid 465652:tid 465753] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/x.php"] [unique_id "al9ZbjzTqJoBC2Mw28_CbwAAqWQ"]
[Tue Jul 21 08:35:10.931911 2026] [security2:error] [pid 465652:tid 465889] [client 20.206.105.145:22006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/by.php"] [unique_id "al9ZbjzTqJoBC2Mw28_CcAAAAPA"]
[Tue Jul 21 08:35:10.946278 2026] [security2:error] [pid 466512:tid 466750] [client 20.206.105.145:25560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/zoro.php"] [unique_id "al9ZbiKGokixMSfKDOfmbQAAAoA"]
[Tue Jul 21 08:35:11.075335 2026] [security2:error] [pid 465652:tid 465778] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/jga.php"] [unique_id "al9ZbzzTqJoBC2Mw28_CcwAAyn0"]
[Tue Jul 21 08:35:11.277983 2026] [security2:error] [pid 465652:tid 465718] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/k.php"] [unique_id "al9ZbzzTqJoBC2Mw28_CdwAAt0E"]
[Tue Jul 21 08:35:11.449071 2026] [security2:error] [pid 465652:tid 465725] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/vx.php"] [unique_id "al9ZbzzTqJoBC2Mw28_CfAAAsUg"]
[Tue Jul 21 08:35:11.611445 2026] [security2:error] [pid 465652:tid 465795] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZbzzTqJoBC2Mw28_CcgAAAJI"]
[Tue Jul 21 08:35:11.634772 2026] [security2:error] [pid 466512:tid 466664] [client 20.151.10.161:63695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/simple.php"] [unique_id "al9ZbyKGokixMSfKDOfmcwAAAio"]
[Tue Jul 21 08:35:11.635629 2026] [security2:error] [pid 465652:tid 465670] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/ws77.php"] [unique_id "al9ZbzzTqJoBC2Mw28_CfgAAzBE"]
[Tue Jul 21 08:35:11.810158 2026] [security2:error] [pid 465652:tid 465779] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/2.php"] [unique_id "al9ZbzzTqJoBC2Mw28_CgwAAtX4"]
[Tue Jul 21 08:35:12.132018 2026] [security2:error] [pid 466512:tid 466726] [client 20.206.105.145:22011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/FAQ.php"] [unique_id "al9ZcCKGokixMSfKDOfmdQAAAmg"]
[Tue Jul 21 08:35:12.229560 2026] [security2:error] [pid 465652:tid 465662] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/asd.php"] [unique_id "al9ZcDzTqJoBC2Mw28_CiwAA-Qk"]
[Tue Jul 21 08:35:12.400931 2026] [security2:error] [pid 465652:tid 465653] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/default.php"] [unique_id "al9ZcDzTqJoBC2Mw28_CjgAArwA"]
[Tue Jul 21 08:35:12.401786 2026] [security2:error] [pid 465652:tid 465906] [client 20.206.105.145:25543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/coffexium.php"] [unique_id "al9ZcDzTqJoBC2Mw28_CjwAAAQE"]
[Tue Jul 21 08:35:12.571517 2026] [security2:error] [pid 465652:tid 465708] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/gettest.php"] [unique_id "al9ZcDzTqJoBC2Mw28_CkQAAojc"]
[Tue Jul 21 08:35:12.638188 2026] [security2:error] [pid 466512:tid 466714] [client 195.49.128.211:49160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZcCKGokixMSfKDOfmfQAAAlw"]
[Tue Jul 21 08:35:12.638364 2026] [security2:error] [pid 466512:tid 466714] [client 195.49.128.211:49160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZcCKGokixMSfKDOfmfQAAAlw"]
[Tue Jul 21 08:35:12.680865 2026] [security2:error] [pid 465652:tid 465822] [client 20.206.105.145:39110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-temp.php"] [unique_id "al9ZcDzTqJoBC2Mw28_CkwAAAK0"]
[Tue Jul 21 08:35:12.742649 2026] [security2:error] [pid 465652:tid 465755] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/tfm.php"] [unique_id "al9ZcDzTqJoBC2Mw28_ClAAA8WY"]
[Tue Jul 21 08:35:13.126023 2026] [security2:error] [pid 465652:tid 465875] [client 202.179.75.202:38444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZcTzTqJoBC2Mw28_CoQAAAOI"]
[Tue Jul 21 08:35:13.126142 2026] [security2:error] [pid 465652:tid 465875] [client 202.179.75.202:38444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZcTzTqJoBC2Mw28_CoQAAAOI"]
[Tue Jul 21 08:35:13.192033 2026] [security2:error] [pid 465652:tid 465819] [client 20.206.105.145:21979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/coffexium.php"] [unique_id "al9ZcTzTqJoBC2Mw28_CpAAAAKo"]
[Tue Jul 21 08:35:13.227864 2026] [security2:error] [pid 466512:tid 466750] [client 20.220.225.223:50274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/tkikikoko.php"] [unique_id "al9ZcSKGokixMSfKDOfmgwAAAoA"]
[Tue Jul 21 08:35:13.286562 2026] [security2:error] [pid 465652:tid 465855] [client 103.59.206.240:31411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZcTzTqJoBC2Mw28_CoAAAAM4"]
[Tue Jul 21 08:35:13.286788 2026] [security2:error] [pid 465652:tid 465855] [client 103.59.206.240:31411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZcTzTqJoBC2Mw28_CoAAAAM4"]
[Tue Jul 21 08:35:13.537658 2026] [security2:error] [pid 466512:tid 466751] [client 20.206.105.145:22009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/red.php"] [unique_id "al9ZcSKGokixMSfKDOfmhgAAAoE"]
[Tue Jul 21 08:35:13.636880 2026] [security2:error] [pid 466512:tid 466709] [client 122.176.100.127:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZcSKGokixMSfKDOfmiwAAAlc"]
[Tue Jul 21 08:35:13.637096 2026] [security2:error] [pid 466512:tid 466709] [client 122.176.100.127:61071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZcSKGokixMSfKDOfmiwAAAlc"]
[Tue Jul 21 08:35:13.646233 2026] [security2:error] [pid 465652:tid 465714] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/ws81.php"] [unique_id "al9ZcTzTqJoBC2Mw28_CqgAAuT0"]
[Tue Jul 21 08:35:13.648677 2026] [security2:error] [pid 465652:tid 465897] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZcTzTqJoBC2Mw28_CogAAAPg"]
[Tue Jul 21 08:35:13.736899 2026] [security2:error] [pid 466512:tid 466741] [client 20.206.105.145:21977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9ZcSKGokixMSfKDOfmkgAAAnc"]
[Tue Jul 21 08:35:13.821397 2026] [security2:error] [pid 465652:tid 465706] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/222.php"] [unique_id "al9ZcTzTqJoBC2Mw28_CrgAA-zU"]
[Tue Jul 21 08:35:13.934154 2026] [security2:error] [pid 466512:tid 466731] [client 20.220.225.223:20893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/ez.php"] [unique_id "al9ZcSKGokixMSfKDOfmlwAAAm0"]
[Tue Jul 21 08:35:13.979831 2026] [security2:error] [pid 466512:tid 466695] [client 20.206.105.145:25116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/app.php"] [unique_id "al9ZcSKGokixMSfKDOfmmAAAAkk"]
[Tue Jul 21 08:35:13.994769 2026] [security2:error] [pid 466512:tid 466715] [client 20.151.10.161:63716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/xxx.php"] [unique_id "al9ZcSKGokixMSfKDOfmmQAAAl0"]
[Tue Jul 21 08:35:14.019751 2026] [security2:error] [pid 465652:tid 465742] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/t.php"] [unique_id "al9ZcjzTqJoBC2Mw28_CswAA4Fk"]
[Tue Jul 21 08:35:14.218993 2026] [security2:error] [pid 465652:tid 465680] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/a.php"] [unique_id "al9ZcjzTqJoBC2Mw28_CtAAAyBs"]
[Tue Jul 21 08:35:14.392667 2026] [security2:error] [pid 465652:tid 465671] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/a1.php"] [unique_id "al9ZcjzTqJoBC2Mw28_CuQAAzBI"]
[Tue Jul 21 08:35:14.504790 2026] [security2:error] [pid 466512:tid 466678] [client 20.220.225.223:20896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/fz.php"] [unique_id "al9ZciKGokixMSfKDOfmswAAAjg"]
[Tue Jul 21 08:35:14.589451 2026] [security2:error] [pid 465652:tid 465719] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/w.php"] [unique_id "al9ZcjzTqJoBC2Mw28_CvAAAzUI"]
[Tue Jul 21 08:35:14.616240 2026] [security2:error] [pid 465652:tid 465891] [client 74.7.241.166:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "deniltoncostasilva1745938157961.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9ZcjzTqJoBC2Mw28_CvgAA8hk"]
[Tue Jul 21 08:35:15.041968 2026] [security2:error] [pid 465652:tid 465895] [client 20.151.10.161:63697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/hypo.php"] [unique_id "al9ZczzTqJoBC2Mw28_CwwAAAPY"]
[Tue Jul 21 08:35:15.093274 2026] [security2:error] [pid 466512:tid 466622] [remote 124.55.178.99:47934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "liranesuliano.acupunturaebemestar.com.br"] [uri "/wp-login.php"] [unique_id "al9ZcyKGokixMSfKDOfmxQACi20"]
[Tue Jul 21 08:35:15.268464 2026] [security2:error] [pid 465652:tid 465880] [client 117.213.202.34:54978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZczzTqJoBC2Mw28_CxwAAAOc"]
[Tue Jul 21 08:35:15.268730 2026] [security2:error] [pid 465652:tid 465880] [client 117.213.202.34:54978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZczzTqJoBC2Mw28_CxwAAAOc"]
[Tue Jul 21 08:35:15.396159 2026] [access_compat:error] [pid 465652:tid 465811] [client 162.241.63.68:11402] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:35:15.474956 2026] [security2:error] [pid 465652:tid 465850] [client 20.206.105.145:22097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/footer.php"] [unique_id "al9ZczzTqJoBC2Mw28_CzgAAAMk"]
[Tue Jul 21 08:35:15.499291 2026] [security2:error] [pid 466512:tid 466750] [client 14.97.58.74:54336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.58.97.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZcyKGokixMSfKDOfmyQAAAoA"]
[Tue Jul 21 08:35:15.499430 2026] [security2:error] [pid 466512:tid 466750] [client 14.97.58.74:54336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZcyKGokixMSfKDOfmyQAAAoA"]
[Tue Jul 21 08:35:15.599166 2026] [security2:error] [pid 465652:tid 465839] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZczzTqJoBC2Mw28_CxQAAAL4"]
[Tue Jul 21 08:35:15.742498 2026] [autoindex:error] [pid 465652:tid 465798] [client 20.151.10.161:65522] AH01276: Cannot serve directory /home3/chave482/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:35:15.742771 2026] [security2:error] [pid 466512:tid 466766] [client 223.181.60.88:9782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZcyKGokixMSfKDOfmzQAAApA"]
[Tue Jul 21 08:35:15.743605 2026] [security2:error] [pid 466512:tid 466766] [client 223.181.60.88:9782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZcyKGokixMSfKDOfmzQAAApA"]
[Tue Jul 21 08:35:16.018662 2026] [security2:error] [pid 465652:tid 465846] [client 20.151.10.161:65522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/chosen.php"] [unique_id "al9ZdDzTqJoBC2Mw28_C5wAAAMU"]
[Tue Jul 21 08:35:16.126381 2026] [proxy:error] [pid 466512:tid 466701] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:16.126465 2026] [proxy_http:error] [pid 466512:tid 466701] [client 20.206.105.145:39235] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:16.127101 2026] [proxy:error] [pid 466512:tid 466701] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:16.127142 2026] [proxy_http:error] [pid 466512:tid 466701] [client 20.206.105.145:39235] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:16.139703 2026] [security2:error] [pid 465652:tid 465737] [remote 20.153.140.50:48524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9ZdDzTqJoBC2Mw28_C6gAAw1Q"]
[Tue Jul 21 08:35:16.287293 2026] [security2:error] [pid 465652:tid 465679] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/wp-good.php"] [unique_id "al9ZdDzTqJoBC2Mw28_C7AABABo"]
[Tue Jul 21 08:35:16.330196 2026] [autoindex:error] [pid 466512:tid 466759] [client 20.151.10.161:63734] AH01276: Cannot serve directory /home3/chave482/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:35:16.366424 2026] [security2:error] [pid 466512:tid 466744] [client 20.220.225.223:20923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/la.php"] [unique_id "al9ZdCKGokixMSfKDOfm1QAAAno"]
[Tue Jul 21 08:35:16.461257 2026] [security2:error] [pid 465652:tid 465722] [remote 74.249.245.134:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "mail.wendelleite.com.br"] [uri "/.info.php"] [unique_id "al9ZdDzTqJoBC2Mw28_C8QAApEU"]
[Tue Jul 21 08:35:16.609045 2026] [security2:error] [pid 466512:tid 466678] [client 20.151.10.161:63734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/file5.php"] [unique_id "al9ZdCKGokixMSfKDOfm2gAAAjg"]
[Tue Jul 21 08:35:16.645969 2026] [security2:error] [pid 465652:tid 465840] [client 20.206.105.145:25099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/core.php"] [unique_id "al9ZdDzTqJoBC2Mw28_C9AAAAL8"]
[Tue Jul 21 08:35:16.693799 2026] [security2:error] [pid 466512:tid 466660] [client 187.125.243.197:57532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZdCKGokixMSfKDOfm2wAAAiY"]
[Tue Jul 21 08:35:16.693985 2026] [security2:error] [pid 466512:tid 466660] [client 187.125.243.197:57532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZdCKGokixMSfKDOfm2wAAAiY"]
[Tue Jul 21 08:35:16.699688 2026] [security2:error] [pid 465652:tid 465734] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/item.php"] [unique_id "al9ZdDzTqJoBC2Mw28_C9QAAs1E"]
[Tue Jul 21 08:35:16.844457 2026] [security2:error] [pid 466512:tid 466675] [client 103.151.46.103:52992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZdCKGokixMSfKDOfm3AAAAjU"]
[Tue Jul 21 08:35:16.844599 2026] [security2:error] [pid 466512:tid 466675] [client 103.151.46.103:52992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZdCKGokixMSfKDOfm3AAAAjU"]
[Tue Jul 21 08:35:16.902386 2026] [security2:error] [pid 465652:tid 465688] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/albin.php"] [unique_id "al9ZdDzTqJoBC2Mw28_C9wAAmiM"]
[Tue Jul 21 08:35:16.971395 2026] [security2:error] [pid 466512:tid 466688] [client 20.151.10.161:63619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/file.php"] [unique_id "al9ZdCKGokixMSfKDOfm3gAAAkI"]
[Tue Jul 21 08:35:16.994095 2026] [security2:error] [pid 465652:tid 465897] [client 195.49.128.211:57131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZdDzTqJoBC2Mw28_C_AAAAPg"]
[Tue Jul 21 08:35:16.994191 2026] [security2:error] [pid 465652:tid 465897] [client 195.49.128.211:57131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZdDzTqJoBC2Mw28_C_AAAAPg"]
[Tue Jul 21 08:35:17.036289 2026] [security2:error] [pid 466512:tid 466681] [client 20.220.225.223:20864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9ZdSKGokixMSfKDOfm3wAAAjs"]
[Tue Jul 21 08:35:17.045671 2026] [security2:error] [pid 466512:tid 466747] [client 109.248.148.246:44838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9ZdSKGokixMSfKDOfm4AAAAn0"]
[Tue Jul 21 08:35:17.045757 2026] [security2:error] [pid 466512:tid 466747] [client 109.248.148.246:44838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9ZdSKGokixMSfKDOfm4AAAAn0"]
[Tue Jul 21 08:35:17.061600 2026] [security2:error] [pid 466512:tid 466653] [client 185.213.175.37:30468] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "benattiodontologia.com.br"] [uri "/wp-json/"] [unique_id "al9ZdSKGokixMSfKDOfm5AAAAh8"]
[Tue Jul 21 08:35:17.066157 2026] [security2:error] [pid 466512:tid 466682] [client 185.213.175.37:30424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "benattiodontologia.com.br"] [uri "/wp-includes/js/jquery/jquery-migrate.min.js"] [unique_id "al9ZdSKGokixMSfKDOfm5gAAAjw"]
[Tue Jul 21 08:35:17.066294 2026] [security2:error] [pid 466512:tid 466682] [client 185.213.175.37:30424] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "benattiodontologia.com.br"] [uri "/wp-includes/js/jquery/jquery-migrate.min.js"] [unique_id "al9ZdSKGokixMSfKDOfm5gAAAjw"]
[Tue Jul 21 08:35:17.066885 2026] [security2:error] [pid 465652:tid 465838] [client 185.213.175.37:30414] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "benattiodontologia.com.br"] [uri "/wp-content/plugins/qi-addons-for-elementor/assets/css/grid.min.css"] [unique_id "al9ZdTzTqJoBC2Mw28_DAgAAAL0"]
[Tue Jul 21 08:35:17.069904 2026] [security2:error] [pid 466512:tid 466677] [client 185.213.175.37:30438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "benattiodontologia.com.br"] [uri "/wp-content/plugins/qi-addons-for-elementor/assets/plugins/swiper/8.4.5/swiper.min.css"] [unique_id "al9ZdSKGokixMSfKDOfm6QAAAjc"]
[Tue Jul 21 08:35:17.069969 2026] [security2:error] [pid 466512:tid 466677] [client 185.213.175.37:30438] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "benattiodontologia.com.br"] [uri "/wp-content/plugins/qi-addons-for-elementor/assets/plugins/swiper/8.4.5/swiper.min.css"] [unique_id "al9ZdSKGokixMSfKDOfm6QAAAjc"]
[Tue Jul 21 08:35:17.077124 2026] [security2:error] [pid 465652:tid 465816] [client 185.213.175.37:30562] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "benattiodontologia.com.br"] [uri "/wp-content/plugins/elementor/assets/css/widget-heading.min.css"] [unique_id "al9ZdTzTqJoBC2Mw28_DCAAAAKc"]
[Tue Jul 21 08:35:17.086469 2026] [security2:error] [pid 465652:tid 465845] [client 185.213.175.37:30538] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "benattiodontologia.com.br"] [uri "/wp-content/plugins/dentamedi-core/assets/css/dentamedi-core.min.css"] [unique_id "al9ZdTzTqJoBC2Mw28_DCwAAAMQ"]
[Tue Jul 21 08:35:17.110169 2026] [security2:error] [pid 465652:tid 465691] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/alfa.php"] [unique_id "al9ZdTzTqJoBC2Mw28_DDQAArSY"]
[Tue Jul 21 08:35:17.249481 2026] [security2:error] [pid 466512:tid 466730] [client 185.213.175.37:30700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "benattiodontologia.com.br"] [uri "/wp-content/plugins/dentamedi-core/inc/plugins/elementor/assets/css/elementor.min.css"] [unique_id "al9ZdSKGokixMSfKDOfm_wAAAmw"]
[Tue Jul 21 08:35:17.249661 2026] [security2:error] [pid 466512:tid 466730] [client 185.213.175.37:30700] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "benattiodontologia.com.br"] [uri "/wp-content/plugins/dentamedi-core/inc/plugins/elementor/assets/css/elementor.min.css"] [unique_id "al9ZdSKGokixMSfKDOfm_wAAAmw"]
[Tue Jul 21 08:35:17.277340 2026] [security2:error] [pid 466512:tid 466706] [client 20.151.10.161:65452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/aa2.php"] [unique_id "al9ZdSKGokixMSfKDOfnAQAAAlQ"]
[Tue Jul 21 08:35:17.282905 2026] [security2:error] [pid 465652:tid 465753] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9ZdTzTqJoBC2Mw28_DGwAAvmQ"]
[Tue Jul 21 08:35:17.319044 2026] [security2:error] [pid 465652:tid 465690] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZdTzTqJoBC2Mw28_DHQAA6yU"]
[Tue Jul 21 08:35:17.320097 2026] [security2:error] [pid 465652:tid 465884] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZdTzTqJoBC2Mw28_DHQAA6yU"]
[Tue Jul 21 08:35:17.336973 2026] [security2:error] [pid 465652:tid 465824] [client 185.213.175.37:30650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "benattiodontologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZdTzTqJoBC2Mw28_DEwAAAK8"]
[Tue Jul 21 08:35:17.455098 2026] [security2:error] [pid 465652:tid 465709] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/av.php"] [unique_id "al9ZdTzTqJoBC2Mw28_DIQAAuzg"]
[Tue Jul 21 08:35:17.518557 2026] [security2:error] [pid 466512:tid 466744] [client 20.206.105.145:38948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9ZdSKGokixMSfKDOfnBwAAAno"]
[Tue Jul 21 08:35:17.590666 2026] [security2:error] [pid 466512:tid 466625] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZdSKGokixMSfKDOfnCAACXnA"]
[Tue Jul 21 08:35:17.590878 2026] [security2:error] [pid 466512:tid 466716] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZdSKGokixMSfKDOfnCAACXnA"]
[Tue Jul 21 08:35:17.601665 2026] [security2:error] [pid 465652:tid 465827] [client 20.151.10.161:63671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/ccou.php"] [unique_id "al9ZdTzTqJoBC2Mw28_DJAAAALI"]
[Tue Jul 21 08:35:17.641888 2026] [security2:error] [pid 465652:tid 465687] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/gg.php"] [unique_id "al9ZdTzTqJoBC2Mw28_DJQAAnCI"]
[Tue Jul 21 08:35:17.716856 2026] [security2:error] [pid 466512:tid 466704] [client 20.220.225.223:34717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/inso.php"] [unique_id "al9ZdSKGokixMSfKDOfnCQAAAlI"]
[Tue Jul 21 08:35:17.812676 2026] [security2:error] [pid 465652:tid 465741] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/sql.php"] [unique_id "al9ZdTzTqJoBC2Mw28_DKAAAjFg"]
[Tue Jul 21 08:35:17.824404 2026] [security2:error] [pid 465652:tid 465906] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZdTzTqJoBC2Mw28_DHAAAAQE"]
[Tue Jul 21 08:35:17.917725 2026] [security2:error] [pid 466512:tid 466682] [client 20.206.105.145:22080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-content/index.php"] [unique_id "al9ZdSKGokixMSfKDOfnDQAAAjw"]
[Tue Jul 21 08:35:17.933861 2026] [security2:error] [pid 465652:tid 465818] [client 20.151.10.161:63701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/dr.php"] [unique_id "al9ZdTzTqJoBC2Mw28_DKgAAAKk"]
[Tue Jul 21 08:35:18.012565 2026] [security2:error] [pid 465652:tid 465738] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/up.php"] [unique_id "al9ZdjzTqJoBC2Mw28_DLAAA91U"]
[Tue Jul 21 08:35:18.214318 2026] [security2:error] [pid 465652:tid 465779] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/66.php"] [unique_id "al9ZdjzTqJoBC2Mw28_DLgAAm34"]
[Tue Jul 21 08:35:18.243310 2026] [security2:error] [pid 466512:tid 466654] [client 20.151.10.161:65514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/file31.php"] [unique_id "al9ZdiKGokixMSfKDOfnEgAAAiA"]
[Tue Jul 21 08:35:18.409252 2026] [security2:error] [pid 465652:tid 465669] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/666.php"] [unique_id "al9ZdjzTqJoBC2Mw28_DNAAAlBA"]
[Tue Jul 21 08:35:18.519654 2026] [security2:error] [pid 465652:tid 465793] [client 20.151.10.161:63660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/file6.php"] [unique_id "al9ZdjzTqJoBC2Mw28_DOAAAAJA"]
[Tue Jul 21 08:35:18.580285 2026] [security2:error] [pid 465652:tid 465708] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/byp.php"] [unique_id "al9ZdjzTqJoBC2Mw28_DOQAAmjc"]
[Tue Jul 21 08:35:18.602662 2026] [security2:error] [pid 465652:tid 465828] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZdjzTqJoBC2Mw28_DNwAAs3E"]
[Tue Jul 21 08:35:18.636398 2026] [security2:error] [pid 466512:tid 466740] [client 20.220.225.223:20867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/wpx.php"] [unique_id "al9ZdiKGokixMSfKDOfnGgAAAnY"]
[Tue Jul 21 08:35:18.706057 2026] [security2:error] [pid 466512:tid 466647] [client 5.38.115.39:54749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZdiKGokixMSfKDOfnHAAAAhk"]
[Tue Jul 21 08:35:18.706200 2026] [security2:error] [pid 466512:tid 466647] [client 5.38.115.39:54749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZdiKGokixMSfKDOfnHAAAAhk"]
[Tue Jul 21 08:35:18.763009 2026] [security2:error] [pid 465652:tid 465682] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/date.php"] [unique_id "al9ZdjzTqJoBC2Mw28_DQAAA9B0"]
[Tue Jul 21 08:35:18.868267 2026] [security2:error] [pid 466512:tid 466769] [client 20.151.10.161:63618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/file15.php"] [unique_id "al9ZdiKGokixMSfKDOfnHQAAApM"]
[Tue Jul 21 08:35:18.934581 2026] [security2:error] [pid 465652:tid 465658] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/pomo.php"] [unique_id "al9ZdjzTqJoBC2Mw28_DQwAApwU"]
[Tue Jul 21 08:35:18.984623 2026] [security2:error] [pid 465652:tid 465845] [client 20.206.105.145:39247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/puc.php"] [unique_id "al9ZdjzTqJoBC2Mw28_DRQAAAMQ"]
[Tue Jul 21 08:35:19.148998 2026] [security2:error] [pid 465652:tid 465710] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/test1.php"] [unique_id "al9ZdzzTqJoBC2Mw28_DSgAA1Tk"]
[Tue Jul 21 08:35:19.206203 2026] [security2:error] [pid 466512:tid 466754] [client 20.206.105.145:25431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/main.php"] [unique_id "al9ZdyKGokixMSfKDOfnIgAAAoQ"]
[Tue Jul 21 08:35:19.381230 2026] [security2:error] [pid 465652:tid 465685] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/fw.php"] [unique_id "al9ZdzzTqJoBC2Mw28_DTgAAiSA"]
[Tue Jul 21 08:35:19.438309 2026] [security2:error] [pid 465652:tid 465865] [client 20.151.10.161:65504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/jp.php"] [unique_id "al9ZdzzTqJoBC2Mw28_DTwAAANg"]
[Tue Jul 21 08:35:19.458629 2026] [security2:error] [pid 465652:tid 465848] [client 20.206.105.145:39156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/themes.php"] [unique_id "al9ZdzzTqJoBC2Mw28_DUAAAAMc"]
[Tue Jul 21 08:35:19.568910 2026] [security2:error] [pid 465652:tid 465706] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/fm.php"] [unique_id "al9ZdzzTqJoBC2Mw28_DVAAAlzU"]
[Tue Jul 21 08:35:19.586157 2026] [security2:error] [pid 466512:tid 466727] [client 74.249.245.134:44409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/ws38.php"] [unique_id "al9ZdyKGokixMSfKDOfnJwAAAmk"]
[Tue Jul 21 08:35:19.723730 2026] [security2:error] [pid 466512:tid 466751] [client 20.206.105.145:22210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/zoro.php"] [unique_id "al9ZdyKGokixMSfKDOfnKQAAAoE"]
[Tue Jul 21 08:35:19.728368 2026] [security2:error] [pid 465652:tid 465902] [client 89.238.167.134:54044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZdzzTqJoBC2Mw28_DVwAAAP0"]
[Tue Jul 21 08:35:19.728465 2026] [security2:error] [pid 465652:tid 465902] [client 89.238.167.134:54044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZdzzTqJoBC2Mw28_DVwAAAP0"]
[Tue Jul 21 08:35:19.763411 2026] [security2:error] [pid 466512:tid 466730] [client 20.151.10.161:65497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/f35.php"] [unique_id "al9ZdyKGokixMSfKDOfnLgAAAmw"]
[Tue Jul 21 08:35:19.772975 2026] [security2:error] [pid 465652:tid 465680] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/ini.php"] [unique_id "al9ZdzzTqJoBC2Mw28_DWQAAxRs"]
[Tue Jul 21 08:35:19.920689 2026] [security2:error] [pid 466512:tid 466749] [client 5.31.193.106:1833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZdyKGokixMSfKDOfnMAAAAn8"]
[Tue Jul 21 08:35:19.920786 2026] [security2:error] [pid 466512:tid 466749] [client 5.31.193.106:1833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZdyKGokixMSfKDOfnMAAAAn8"]
[Tue Jul 21 08:35:19.945349 2026] [security2:error] [pid 465652:tid 465732] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/themes.php"] [unique_id "al9ZdzzTqJoBC2Mw28_DXgAA_k8"]
[Tue Jul 21 08:35:20.050155 2026] [security2:error] [pid 465652:tid 465804] [client 20.151.10.161:63714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wp-load.php"] [unique_id "al9ZeDzTqJoBC2Mw28_DZAAAAJs"]
[Tue Jul 21 08:35:20.073345 2026] [security2:error] [pid 466512:tid 466765] [client 14.245.224.124:63468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZeCKGokixMSfKDOfnMgAAAo8"]
[Tue Jul 21 08:35:20.073747 2026] [security2:error] [pid 466512:tid 466765] [client 14.245.224.124:63468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZeCKGokixMSfKDOfnMgAAAo8"]
[Tue Jul 21 08:35:20.127536 2026] [security2:error] [pid 465652:tid 465719] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/dropdown.php"] [unique_id "al9ZeDzTqJoBC2Mw28_DZQAAykI"]
[Tue Jul 21 08:35:20.281245 2026] [security2:error] [pid 466512:tid 466649] [client 49.144.66.253:30664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZeCKGokixMSfKDOfnNQAAAhs"]
[Tue Jul 21 08:35:20.281436 2026] [security2:error] [pid 466512:tid 466649] [client 49.144.66.253:30664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZeCKGokixMSfKDOfnNQAAAhs"]
[Tue Jul 21 08:35:20.284341 2026] [security2:error] [pid 465652:tid 465817] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZdzzTqJoBC2Mw28_DWgAAAKg"]
[Tue Jul 21 08:35:20.324971 2026] [security2:error] [pid 465652:tid 465772] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/wp-links.php"] [unique_id "al9ZeDzTqJoBC2Mw28_DbgAA0Hc"]
[Tue Jul 21 08:35:20.335960 2026] [security2:error] [pid 465652:tid 465834] [client 81.171.74.60:59842] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/"] [unique_id "al9ZeDzTqJoBC2Mw28_DbwAAALk"]
[Tue Jul 21 08:35:20.336163 2026] [security2:error] [pid 466512:tid 466716] [client 81.171.74.60:59850] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/"] [unique_id "al9ZeCKGokixMSfKDOfnNgAAAl4"]
[Tue Jul 21 08:35:20.336202 2026] [security2:error] [pid 465652:tid 465887] [client 91.148.244.131:57350] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/"] [unique_id "al9ZeDzTqJoBC2Mw28_DcAAAAO4"]
[Tue Jul 21 08:35:20.336954 2026] [security2:error] [pid 465652:tid 465854] [client 81.171.74.60:59846] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/"] [unique_id "al9ZeDzTqJoBC2Mw28_DcQAAAM0"]
[Tue Jul 21 08:35:20.338137 2026] [security2:error] [pid 466512:tid 466646] [client 20.206.105.145:39273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/dx.php"] [unique_id "al9ZeCKGokixMSfKDOfnNwAAAhg"]
[Tue Jul 21 08:35:20.340208 2026] [security2:error] [pid 465652:tid 465787] [client 91.148.244.131:57366] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/"] [unique_id "al9ZeDzTqJoBC2Mw28_DcgAAAIo"]
[Tue Jul 21 08:35:20.341565 2026] [security2:error] [pid 465652:tid 465890] [client 91.148.244.131:57368] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/"] [unique_id "al9ZeDzTqJoBC2Mw28_DcwAAAPE"]
[Tue Jul 21 08:35:20.369085 2026] [autoindex:error] [pid 465652:tid 465861] [client 20.151.10.161:65430] AH01276: Cannot serve directory /home3/chave482/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:35:20.454972 2026] [security2:error] [pid 465652:tid 465891] [client 81.171.72.135:39938] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/"] [unique_id "al9ZeDzTqJoBC2Mw28_DdQAAAPI"]
[Tue Jul 21 08:35:20.455063 2026] [security2:error] [pid 465652:tid 465828] [client 81.171.72.135:39920] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/"] [unique_id "al9ZeDzTqJoBC2Mw28_DdgAAALM"]
[Tue Jul 21 08:35:20.455174 2026] [security2:error] [pid 465652:tid 465826] [client 81.171.72.135:39936] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/"] [unique_id "al9ZeDzTqJoBC2Mw28_DdwAAALE"]
[Tue Jul 21 08:35:20.553195 2026] [security2:error] [pid 465652:tid 465689] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/xmrlpc.php"] [unique_id "al9ZeDzTqJoBC2Mw28_DeAAAriQ"]
[Tue Jul 21 08:35:20.635170 2026] [security2:error] [pid 466512:tid 466752] [client 152.59.34.51:17370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZeCKGokixMSfKDOfnOAAAAoI"]
[Tue Jul 21 08:35:20.635275 2026] [security2:error] [pid 466512:tid 466752] [client 152.59.34.51:17370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZeCKGokixMSfKDOfnOAAAAoI"]
[Tue Jul 21 08:35:20.715425 2026] [autoindex:error] [pid 465652:tid 465858] [client 20.151.10.161:65430] AH01276: Cannot serve directory /home3/chave482/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:35:20.775706 2026] [security2:error] [pid 465652:tid 465667] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/htaccess.php"] [unique_id "al9ZeDzTqJoBC2Mw28_DggAAxw4"]
[Tue Jul 21 08:35:20.968599 2026] [security2:error] [pid 465652:tid 465759] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/readme.php"] [unique_id "al9ZeDzTqJoBC2Mw28_DhQAAq2o"]
[Tue Jul 21 08:35:21.038095 2026] [security2:error] [pid 465652:tid 465824] [client 20.151.10.161:65430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9ZeTzTqJoBC2Mw28_DhgAAAK8"]
[Tue Jul 21 08:35:21.129030 2026] [security2:error] [pid 466512:tid 466768] [client 91.148.244.131:57414] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/.env"] [unique_id "al9ZeSKGokixMSfKDOfnRQAAApI"]
[Tue Jul 21 08:35:21.132195 2026] [security2:error] [pid 466512:tid 466682] [client 91.148.244.131:57388] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9ZeSKGokixMSfKDOfnRgAAAjw"]
[Tue Jul 21 08:35:21.132637 2026] [security2:error] [pid 466512:tid 466756] [client 91.148.244.131:57410] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/user_secrets.yml"] [unique_id "al9ZeSKGokixMSfKDOfnRwAAAoY"]
[Tue Jul 21 08:35:21.155544 2026] [security2:error] [pid 465652:tid 465760] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/403.php"] [unique_id "al9ZeTzTqJoBC2Mw28_DiwAAy2s"]
[Tue Jul 21 08:35:21.254356 2026] [security2:error] [pid 465652:tid 465805] [client 20.206.105.145:25527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/init.php"] [unique_id "al9ZeTzTqJoBC2Mw28_DjAAAAJw"]
[Tue Jul 21 08:35:21.308420 2026] [security2:error] [pid 465652:tid 465875] [client 81.171.74.60:59862] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9ZeTzTqJoBC2Mw28_DjwAAAOI"]
[Tue Jul 21 08:35:21.309103 2026] [security2:error] [pid 465652:tid 465884] [client 81.171.74.60:59882] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/config.php"] [unique_id "al9ZeTzTqJoBC2Mw28_DkAAAAOs"]
[Tue Jul 21 08:35:21.310345 2026] [security2:error] [pid 466512:tid 466700] [client 81.171.74.60:59894] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/.env"] [unique_id "al9ZeSKGokixMSfKDOfnSQAAAk4"]
[Tue Jul 21 08:35:21.310975 2026] [security2:error] [pid 465652:tid 465836] [client 81.171.74.60:59866] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/database_backup.sql"] [unique_id "al9ZeTzTqJoBC2Mw28_DkQAAALs"]
[Tue Jul 21 08:35:21.355431 2026] [security2:error] [pid 465652:tid 465705] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/max.php"] [unique_id "al9ZeTzTqJoBC2Mw28_DkgAA3jQ"]
[Tue Jul 21 08:35:21.387410 2026] [security2:error] [pid 465652:tid 465839] [client 91.148.244.131:57404] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9ZeTzTqJoBC2Mw28_DkwAAAL4"]
[Tue Jul 21 08:35:21.387525 2026] [security2:error] [pid 466512:tid 466654] [client 20.151.10.161:63011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wp-links.php"] [unique_id "al9ZeSKGokixMSfKDOfnSgAAAiA"]
[Tue Jul 21 08:35:21.433050 2026] [security2:error] [pid 466512:tid 466674] [client 20.220.225.223:20894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/berlin.php"] [unique_id "al9ZeSKGokixMSfKDOfnTAAAAjQ"]
[Tue Jul 21 08:35:21.503700 2026] [security2:error] [pid 465652:tid 465901] [client 141.11.107.74:49790] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.lojadoclimatizador.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9ZeTzTqJoBC2Mw28_DlgAAAPw"]
[Tue Jul 21 08:35:21.525137 2026] [security2:error] [pid 465652:tid 465686] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/m.php"] [unique_id "al9ZeTzTqJoBC2Mw28_DlwAAwSE"]
[Tue Jul 21 08:35:21.527689 2026] [security2:error] [pid 466512:tid 466726] [client 141.11.107.74:49795] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.lojadoclimatizador.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9ZeSKGokixMSfKDOfnTwAAAmg"]
[Tue Jul 21 08:35:21.557790 2026] [security2:error] [pid 466512:tid 466721] [client 141.11.107.74:49802] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.lojadoclimatizador.com.br"] [uri "/"] [unique_id "al9ZeSKGokixMSfKDOfnUAAAAmM"]
[Tue Jul 21 08:35:21.580673 2026] [security2:error] [pid 466512:tid 466701] [client 20.206.105.145:22095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/admin.php"] [unique_id "al9ZeSKGokixMSfKDOfnUgAAAk8"]
[Tue Jul 21 08:35:21.616654 2026] [security2:error] [pid 465652:tid 465808] [client 141.11.107.74:49818] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "lojadoclimatizador.com.br"] [uri "/"] [unique_id "al9ZeTzTqJoBC2Mw28_DmwAAAJ8"]
[Tue Jul 21 08:35:21.689043 2026] [security2:error] [pid 466512:tid 466744] [client 20.220.225.223:50285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/wp-Blogs.php"] [unique_id "al9ZeSKGokixMSfKDOfnUwAAAno"]
[Tue Jul 21 08:35:21.698952 2026] [security2:error] [pid 466512:tid 466759] [client 20.151.10.161:63728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/solo1.php"] [unique_id "al9ZeSKGokixMSfKDOfnVAAAAok"]
[Tue Jul 21 08:35:21.708926 2026] [security2:error] [pid 465652:tid 465703] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/click.php"] [unique_id "al9ZeTzTqJoBC2Mw28_DnAAAvDI"]
[Tue Jul 21 08:35:22.098860 2026] [security2:error] [pid 466512:tid 466769] [client 91.148.244.131:57442] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/.git/HEAD"] [unique_id "al9ZeiKGokixMSfKDOfnWgAAApM"]
[Tue Jul 21 08:35:22.100493 2026] [security2:error] [pid 465652:tid 465897] [client 91.148.244.131:57440] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9ZejzTqJoBC2Mw28_DnwAAAPg"]
[Tue Jul 21 08:35:22.100637 2026] [security2:error] [pid 465652:tid 465817] [client 91.148.244.131:57458] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9ZejzTqJoBC2Mw28_DoQAAAKg"]
[Tue Jul 21 08:35:22.100701 2026] [security2:error] [pid 465652:tid 465876] [client 91.148.244.131:57470] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/database_backup.sql"] [unique_id "al9ZejzTqJoBC2Mw28_DoAAAAOM"]
[Tue Jul 21 08:35:22.239046 2026] [security2:error] [pid 466512:tid 466662] [client 20.151.10.161:65467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/sixxis.php"] [unique_id "al9ZeiKGokixMSfKDOfnXwAAAig"]
[Tue Jul 21 08:35:22.271781 2026] [security2:error] [pid 465652:tid 465880] [client 81.171.74.60:59930] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/api/.env"] [unique_id "al9ZejzTqJoBC2Mw28_DpAAAAOc"]
[Tue Jul 21 08:35:22.272153 2026] [security2:error] [pid 466512:tid 466713] [client 81.171.74.60:59924] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/docker-compose.yml"] [unique_id "al9ZeiKGokixMSfKDOfnYAAAAls"]
[Tue Jul 21 08:35:22.273516 2026] [security2:error] [pid 465652:tid 465834] [client 81.171.74.60:59920] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/phpinfo.php"] [unique_id "al9ZejzTqJoBC2Mw28_DpQAAALk"]
[Tue Jul 21 08:35:22.274230 2026] [security2:error] [pid 465652:tid 465854] [client 81.171.74.60:59944] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/user_secrets.yml"] [unique_id "al9ZejzTqJoBC2Mw28_DpgAAAM0"]
[Tue Jul 21 08:35:22.303479 2026] [security2:error] [pid 465652:tid 465811] [client 20.220.225.223:20903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/billur.php"] [unique_id "al9ZejzTqJoBC2Mw28_DqwAAAKI"]
[Tue Jul 21 08:35:22.303782 2026] [security2:error] [pid 465652:tid 465857] [client 91.148.244.131:57466] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/docker-compose.yml"] [unique_id "al9ZejzTqJoBC2Mw28_DrAAAANA"]
[Tue Jul 21 08:35:22.304692 2026] [security2:error] [pid 466512:tid 466745] [client 91.148.244.131:57454] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/api/.env"] [unique_id "al9ZeiKGokixMSfKDOfnYgAAAns"]
[Tue Jul 21 08:35:22.305121 2026] [security2:error] [pid 465652:tid 465785] [client 91.148.244.131:57428] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/phpinfo.php"] [unique_id "al9ZejzTqJoBC2Mw28_DrQAAAIg"]
[Tue Jul 21 08:35:22.477343 2026] [security2:error] [pid 465652:tid 465787] [client 81.171.74.60:59910] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/server.key"] [unique_id "al9ZejzTqJoBC2Mw28_DsAAAAIo"]
[Tue Jul 21 08:35:22.478951 2026] [security2:error] [pid 465652:tid 465887] [client 81.171.74.60:59900] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9ZejzTqJoBC2Mw28_DsQAAAO4"]
[Tue Jul 21 08:35:22.503779 2026] [security2:error] [pid 465652:tid 465875] [client 20.206.105.145:38914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/p.php"] [unique_id "al9ZejzTqJoBC2Mw28_DsgAAAOI"]
[Tue Jul 21 08:35:22.571972 2026] [security2:error] [pid 465652:tid 465818] [client 20.151.10.161:65495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/2P.update.php"] [unique_id "al9ZejzTqJoBC2Mw28_DswAAAKk"]
[Tue Jul 21 08:35:22.797582 2026] [security2:error] [pid 465652:tid 465795] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZejzTqJoBC2Mw28_DrwAAAJI"]
[Tue Jul 21 08:35:22.848521 2026] [security2:error] [pid 466512:tid 466649] [client 20.151.10.161:65423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/a.php"] [unique_id "al9ZeiKGokixMSfKDOfnaQAAAhs"]
[Tue Jul 21 08:35:22.871829 2026] [security2:error] [pid 465652:tid 465837] [client 20.220.225.223:50277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/wp-css.php"] [unique_id "al9ZejzTqJoBC2Mw28_DugAAALw"]
[Tue Jul 21 08:35:22.896840 2026] [proxy:error] [pid 465652:tid 465891] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:22.896911 2026] [proxy_http:error] [pid 465652:tid 465891] [client 20.206.105.145:38960] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:22.897403 2026] [proxy:error] [pid 465652:tid 465891] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:22.897436 2026] [proxy_http:error] [pid 465652:tid 465891] [client 20.206.105.145:38960] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:23.076520 2026] [security2:error] [pid 465652:tid 465832] [client 91.148.244.131:40372] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/backup.zip"] [unique_id "al9ZezzTqJoBC2Mw28_DwAAAALc"]
[Tue Jul 21 08:35:23.080546 2026] [security2:error] [pid 465652:tid 465881] [client 91.148.244.131:40344] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/actuator/heapdump"] [unique_id "al9ZezzTqJoBC2Mw28_DwQAAAOg"]
[Tue Jul 21 08:35:23.080679 2026] [security2:error] [pid 466512:tid 466646] [client 91.148.244.131:40360] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/.svn/wc.db"] [unique_id "al9ZeyKGokixMSfKDOfnbQAAAhg"]
[Tue Jul 21 08:35:23.080809 2026] [security2:error] [pid 465652:tid 465900] [client 91.148.244.131:40350] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/wp-config.php"] [unique_id "al9ZezzTqJoBC2Mw28_DwgAAAPs"]
[Tue Jul 21 08:35:23.086497 2026] [security2:error] [pid 465652:tid 465722] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/lv.php"] [unique_id "al9ZezzTqJoBC2Mw28_DwwAA5UU"]
[Tue Jul 21 08:35:23.153716 2026] [security2:error] [pid 466512:tid 466697] [client 20.151.10.161:63691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/k.php"] [unique_id "al9ZeyKGokixMSfKDOfnbgAAAks"]
[Tue Jul 21 08:35:23.184705 2026] [security2:error] [pid 466512:tid 466744] [client 195.49.128.211:49785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZeyKGokixMSfKDOfnbwAAAno"]
[Tue Jul 21 08:35:23.184859 2026] [security2:error] [pid 466512:tid 466744] [client 195.49.128.211:49785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZeyKGokixMSfKDOfnbwAAAno"]
[Tue Jul 21 08:35:23.255347 2026] [security2:error] [pid 465652:tid 465853] [client 81.171.74.60:50774] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/config/production.json"] [unique_id "al9ZezzTqJoBC2Mw28_DyAAAAMw"]
[Tue Jul 21 08:35:23.256096 2026] [security2:error] [pid 465652:tid 465816] [client 81.171.74.60:50790] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/secrets.json"] [unique_id "al9ZezzTqJoBC2Mw28_DyQAAAKc"]
[Tue Jul 21 08:35:23.257723 2026] [security2:error] [pid 466512:tid 466676] [client 81.171.74.60:50800] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/.env.production"] [unique_id "al9ZeyKGokixMSfKDOfncQAAAjY"]
[Tue Jul 21 08:35:23.258851 2026] [security2:error] [pid 466512:tid 466752] [client 81.171.74.60:50802] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9ZeyKGokixMSfKDOfncgAAAoI"]
[Tue Jul 21 08:35:23.260206 2026] [security2:error] [pid 465652:tid 465665] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/cong.php"] [unique_id "al9ZezzTqJoBC2Mw28_DygAAogw"]
[Tue Jul 21 08:35:23.281226 2026] [security2:error] [pid 466512:tid 466758] [client 91.148.244.131:40346] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9ZeyKGokixMSfKDOfncwAAAog"]
[Tue Jul 21 08:35:23.394711 2026] [security2:error] [pid 466512:tid 466699] [client 20.206.105.145:25109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/prekel.php"] [unique_id "al9ZeyKGokixMSfKDOfndgAAAk0"]
[Tue Jul 21 08:35:23.431580 2026] [security2:error] [pid 465652:tid 465688] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/brand.php"] [unique_id "al9ZezzTqJoBC2Mw28_DzAAAwCM"]
[Tue Jul 21 08:35:23.433456 2026] [security2:error] [pid 466512:tid 466689] [client 20.151.10.161:65508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/w.php"] [unique_id "al9ZeyKGokixMSfKDOfndwAAAkM"]
[Tue Jul 21 08:35:23.462215 2026] [security2:error] [pid 466512:tid 466742] [client 81.171.74.60:50814] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/.npmrc"] [unique_id "al9ZeyKGokixMSfKDOfneAAAAng"]
[Tue Jul 21 08:35:23.610083 2026] [security2:error] [pid 465652:tid 465720] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/atomlib.php"] [unique_id "al9ZezzTqJoBC2Mw28_DzwAA-kM"]
[Tue Jul 21 08:35:23.755820 2026] [security2:error] [pid 466512:tid 466642] [client 103.59.206.240:31182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZeyKGokixMSfKDOfnggAAAhQ"]
[Tue Jul 21 08:35:23.755963 2026] [security2:error] [pid 466512:tid 466642] [client 103.59.206.240:31182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZeyKGokixMSfKDOfnggAAAhQ"]
[Tue Jul 21 08:35:23.760472 2026] [security2:error] [pid 465652:tid 465852] [client 20.151.10.161:63655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/insc.php"] [unique_id "al9ZezzTqJoBC2Mw28_D0gAAAMs"]
[Tue Jul 21 08:35:23.815667 2026] [security2:error] [pid 465652:tid 465697] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/0x.php"] [unique_id "al9ZezzTqJoBC2Mw28_D0wAAlyw"]
[Tue Jul 21 08:35:23.858689 2026] [security2:error] [pid 466512:tid 466749] [client 20.206.105.145:39284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/bthil.php"] [unique_id "al9ZeyKGokixMSfKDOfngwAAAn8"]
[Tue Jul 21 08:35:23.869639 2026] [security2:error] [pid 466512:tid 466741] [client 20.220.225.223:34699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/mimpi.php"] [unique_id "al9ZeyKGokixMSfKDOfnhAAAAnc"]
[Tue Jul 21 08:35:24.010927 2026] [security2:error] [pid 465652:tid 465753] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/buy.php"] [unique_id "al9ZfDzTqJoBC2Mw28_D1QAA62Q"]
[Tue Jul 21 08:35:24.040730 2026] [security2:error] [pid 466512:tid 466755] [client 202.179.75.202:56556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZfCKGokixMSfKDOfnhwAAAoU"]
[Tue Jul 21 08:35:24.040850 2026] [security2:error] [pid 466512:tid 466755] [client 202.179.75.202:56556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZfCKGokixMSfKDOfnhwAAAoU"]
[Tue Jul 21 08:35:24.052952 2026] [security2:error] [pid 466512:tid 466716] [client 20.151.10.161:65447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9ZfCKGokixMSfKDOfniAAAAl4"]
[Tue Jul 21 08:35:24.053320 2026] [security2:error] [pid 465652:tid 465787] [client 91.148.244.131:40436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/config/production.json"] [unique_id "al9ZfDzTqJoBC2Mw28_D1wAAAIo"]
[Tue Jul 21 08:35:24.053322 2026] [security2:error] [pid 465652:tid 465805] [client 91.148.244.131:40450] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/server.key"] [unique_id "al9ZfDzTqJoBC2Mw28_D1gAAAJw"]
[Tue Jul 21 08:35:24.054387 2026] [security2:error] [pid 466512:tid 466726] [client 91.148.244.131:40424] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/.env.production"] [unique_id "al9ZfCKGokixMSfKDOfniQAAAmg"]
[Tue Jul 21 08:35:24.055113 2026] [security2:error] [pid 465652:tid 465887] [client 91.148.244.131:40406] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9ZfDzTqJoBC2Mw28_D2AAAAO4"]
[Tue Jul 21 08:35:24.186943 2026] [security2:error] [pid 465652:tid 465863] [client 122.176.100.127:61578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZfDzTqJoBC2Mw28_D3gAAANY"]
[Tue Jul 21 08:35:24.187110 2026] [security2:error] [pid 465652:tid 465863] [client 122.176.100.127:61578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZfDzTqJoBC2Mw28_D3gAAANY"]
[Tue Jul 21 08:35:24.197574 2026] [security2:error] [pid 465652:tid 465718] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/sx.php"] [unique_id "al9ZfDzTqJoBC2Mw28_D3wAAjEE"]
[Tue Jul 21 08:35:24.226482 2026] [security2:error] [pid 466512:tid 466746] [client 81.171.74.60:50852] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9ZfCKGokixMSfKDOfnjQAAAnw"]
[Tue Jul 21 08:35:24.226627 2026] [security2:error] [pid 466512:tid 466765] [client 81.171.74.60:50872] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-config.php"] [unique_id "al9ZfCKGokixMSfKDOfnjAAAAo8"]
[Tue Jul 21 08:35:24.228850 2026] [security2:error] [pid 466512:tid 466728] [client 81.171.74.60:50880] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/backup.zip"] [unique_id "al9ZfCKGokixMSfKDOfnjgAAAmo"]
[Tue Jul 21 08:35:24.229267 2026] [security2:error] [pid 465652:tid 465836] [client 81.171.74.60:50842] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/.bash_history"] [unique_id "al9ZfDzTqJoBC2Mw28_D4AAAALs"]
[Tue Jul 21 08:35:24.255124 2026] [security2:error] [pid 466512:tid 466701] [client 91.148.244.131:40414] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9ZfCKGokixMSfKDOfnkAAAAk8"]
[Tue Jul 21 08:35:24.258544 2026] [security2:error] [pid 466512:tid 466715] [client 91.148.244.131:40416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/dump.sql"] [unique_id "al9ZfCKGokixMSfKDOfnkgAAAl0"]
[Tue Jul 21 08:35:24.258660 2026] [security2:error] [pid 466512:tid 466721] [client 91.148.244.131:40394] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/backup.tar.gz"] [unique_id "al9ZfCKGokixMSfKDOfnkQAAAmM"]
[Tue Jul 21 08:35:24.377123 2026] [security2:error] [pid 465652:tid 465740] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/article.php"] [unique_id "al9ZfDzTqJoBC2Mw28_D5AAA21c"]
[Tue Jul 21 08:35:24.384176 2026] [security2:error] [pid 466512:tid 466663] [client 20.206.105.145:22241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/greap.php"] [unique_id "al9ZfCKGokixMSfKDOfnkwAAAik"]
[Tue Jul 21 08:35:24.427767 2026] [security2:error] [pid 466512:tid 466647] [client 81.171.74.60:50868] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/actuator/heapdump"] [unique_id "al9ZfCKGokixMSfKDOfnlAAAAhk"]
[Tue Jul 21 08:35:24.427886 2026] [security2:error] [pid 466512:tid 466750] [client 81.171.74.60:50896] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/.svn/wc.db"] [unique_id "al9ZfCKGokixMSfKDOfnlQAAAoA"]
[Tue Jul 21 08:35:24.429881 2026] [security2:error] [pid 466512:tid 466649] [client 81.171.74.60:50840] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/backup.tar.gz"] [unique_id "al9ZfCKGokixMSfKDOfnlgAAAhs"]
[Tue Jul 21 08:35:24.503439 2026] [security2:error] [pid 466512:tid 466685] [client 20.151.10.161:65492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/u.php"] [unique_id "al9ZfCKGokixMSfKDOfnmwAAAj8"]
[Tue Jul 21 08:35:24.551076 2026] [security2:error] [pid 465652:tid 465768] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/bootstrap.php"] [unique_id "al9ZfDzTqJoBC2Mw28_D5wAA8XM"]
[Tue Jul 21 08:35:24.647998 2026] [security2:error] [pid 466512:tid 466664] [client 20.206.105.145:39266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/7.php"] [unique_id "al9ZfCKGokixMSfKDOfnnAAAAio"]
[Tue Jul 21 08:35:24.724071 2026] [security2:error] [pid 465652:tid 465738] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/config-backup.php"] [unique_id "al9ZfDzTqJoBC2Mw28_D6gAA41U"]
[Tue Jul 21 08:35:24.849586 2026] [security2:error] [pid 466512:tid 466703] [client 81.171.74.60:50912] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9ZfCKGokixMSfKDOfnogAAAlE"]
[Tue Jul 21 08:35:24.906747 2026] [security2:error] [pid 465652:tid 465761] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/goods.php"] [unique_id "al9ZfDzTqJoBC2Mw28_D7wAAt2w"]
[Tue Jul 21 08:35:24.997877 2026] [security2:error] [pid 466512:tid 466695] [client 20.151.10.161:63086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/sss.php"] [unique_id "al9ZfCKGokixMSfKDOfnpQAAAkk"]
[Tue Jul 21 08:35:25.030262 2026] [security2:error] [pid 466512:tid 466759] [client 91.148.244.131:40454] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/.bash_history"] [unique_id "al9ZfSKGokixMSfKDOfnpgAAAok"]
[Tue Jul 21 08:35:25.030380 2026] [security2:error] [pid 466512:tid 466670] [client 91.148.244.131:40502] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/.npmrc"] [unique_id "al9ZfSKGokixMSfKDOfnpwAAAjA"]
[Tue Jul 21 08:35:25.032798 2026] [security2:error] [pid 466512:tid 466706] [client 91.148.244.131:40470] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/database.sql"] [unique_id "al9ZfSKGokixMSfKDOfnqAAAAlQ"]
[Tue Jul 21 08:35:25.091510 2026] [security2:error] [pid 465652:tid 465748] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/init.php"] [unique_id "al9ZfTzTqJoBC2Mw28_D8gAAuV8"]
[Tue Jul 21 08:35:25.186099 2026] [security2:error] [pid 466512:tid 466768] [client 20.206.105.145:39106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/8.php"] [unique_id "al9ZfSKGokixMSfKDOfnqwAAApI"]
[Tue Jul 21 08:35:25.236790 2026] [security2:error] [pid 466512:tid 466668] [client 91.148.244.131:40472] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9ZfSKGokixMSfKDOfnrwAAAi4"]
[Tue Jul 21 08:35:25.236914 2026] [security2:error] [pid 466512:tid 466740] [client 91.148.244.131:40474] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/config.xml"] [unique_id "al9ZfSKGokixMSfKDOfnsAAAAnY"]
[Tue Jul 21 08:35:25.237024 2026] [security2:error] [pid 466512:tid 466673] [client 91.148.244.131:40500] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/secrets.json"] [unique_id "al9ZfSKGokixMSfKDOfnrgAAAjM"]
[Tue Jul 21 08:35:25.551370 2026] [security2:error] [pid 466512:tid 466705] [client 81.171.74.60:50968] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9ZfSKGokixMSfKDOfntAAAAlM"]
[Tue Jul 21 08:35:25.552549 2026] [security2:error] [pid 466512:tid 466713] [client 81.171.74.60:50966] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/config.xml"] [unique_id "al9ZfSKGokixMSfKDOfntQAAAls"]
[Tue Jul 21 08:35:25.554094 2026] [security2:error] [pid 465652:tid 465811] [client 81.171.74.60:50938] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9ZfTzTqJoBC2Mw28_D-AAAAKI"]
[Tue Jul 21 08:35:25.554498 2026] [security2:error] [pid 465652:tid 465816] [client 81.171.74.60:50954] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9ZfTzTqJoBC2Mw28_D-QAAAKc"]
[Tue Jul 21 08:35:25.697379 2026] [security2:error] [pid 466512:tid 466758] [client 61.1.167.83:61240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZfSKGokixMSfKDOfnvAAAAog"]
[Tue Jul 21 08:35:25.697520 2026] [security2:error] [pid 466512:tid 466758] [client 61.1.167.83:61240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZfSKGokixMSfKDOfnvAAAAog"]
[Tue Jul 21 08:35:25.703446 2026] [security2:error] [pid 466512:tid 466620] [remote 68.178.160.25:37628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/wp-login.php"] [unique_id "al9ZfSKGokixMSfKDOfnvQACY2s"]
[Tue Jul 21 08:35:25.753513 2026] [security2:error] [pid 465652:tid 465857] [client 81.171.74.60:50956] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/backup.sql"] [unique_id "al9ZfTzTqJoBC2Mw28_D_QAAANA"]
[Tue Jul 21 08:35:25.753704 2026] [security2:error] [pid 465652:tid 465853] [client 81.171.74.60:50928] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/dump.sql"] [unique_id "al9ZfTzTqJoBC2Mw28_D_gAAAMw"]
[Tue Jul 21 08:35:25.792006 2026] [security2:error] [pid 465652:tid 465889] [client 20.151.10.161:65425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/sss.php"] [unique_id "al9ZfTzTqJoBC2Mw28_EAgAAAPA"]
[Tue Jul 21 08:35:25.824801 2026] [security2:error] [pid 466512:tid 466701] [client 117.213.202.34:55599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZfSKGokixMSfKDOfnxQAAAk8"]
[Tue Jul 21 08:35:25.824988 2026] [security2:error] [pid 466512:tid 466701] [client 117.213.202.34:55599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZfSKGokixMSfKDOfnxQAAAk8"]
[Tue Jul 21 08:35:26.015735 2026] [security2:error] [pid 465652:tid 465814] [client 65.21.113.253:44562] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZfTzTqJoBC2Mw28_EBAAAAKU"]
[Tue Jul 21 08:35:26.031298 2026] [security2:error] [pid 465652:tid 465902] [client 91.148.244.131:40508] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/config.php"] [unique_id "al9ZfjzTqJoBC2Mw28_EDAAAAP0"]
[Tue Jul 21 08:35:26.165233 2026] [security2:error] [pid 466512:tid 466766] [client 103.255.105.130:12324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.105.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZfiKGokixMSfKDOfnzgAAApA"]
[Tue Jul 21 08:35:26.165341 2026] [security2:error] [pid 466512:tid 466766] [client 103.255.105.130:12324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZfiKGokixMSfKDOfnzgAAApA"]
[Tue Jul 21 08:35:26.180377 2026] [security2:error] [pid 466512:tid 466721] [client 20.151.10.161:63668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/c.php"] [unique_id "al9ZfiKGokixMSfKDOfn0AAAAmM"]
[Tue Jul 21 08:35:26.183832 2026] [security2:error] [pid 465652:tid 465901] [client 20.206.105.145:25542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/0.php"] [unique_id "al9ZfjzTqJoBC2Mw28_EDwAAAPw"]
[Tue Jul 21 08:35:26.240229 2026] [security2:error] [pid 466512:tid 466662] [client 91.148.244.131:40520] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.jaypi.com.br"] [uri "/backup.sql"] [unique_id "al9ZfiKGokixMSfKDOfn6AAAAig"]
[Tue Jul 21 08:35:26.294325 2026] [security2:error] [pid 466512:tid 466745] [client 81.171.72.135:59668] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/config.xml"] [unique_id "al9ZfiKGokixMSfKDOfn6wAAAns"]
[Tue Jul 21 08:35:26.297066 2026] [security2:error] [pid 466512:tid 466705] [client 81.171.72.135:59648] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/dump.sql"] [unique_id "al9ZfiKGokixMSfKDOfn7AAAAlM"]
[Tue Jul 21 08:35:26.300154 2026] [security2:error] [pid 465652:tid 465903] [client 81.171.72.135:59670] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/config.php"] [unique_id "al9ZfjzTqJoBC2Mw28_EFQAAAP4"]
[Tue Jul 21 08:35:26.301630 2026] [security2:error] [pid 466512:tid 466713] [client 81.171.72.135:59664] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9ZfiKGokixMSfKDOfn7QAAAls"]
[Tue Jul 21 08:35:26.386240 2026] [security2:error] [pid 466512:tid 466697] [client 20.206.105.145:39107] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.goldentrips40.com"] [uri "/1.php"] [unique_id "al9ZfiKGokixMSfKDOfn7gAAAks"]
[Tue Jul 21 08:35:26.386359 2026] [security2:error] [pid 466512:tid 466697] [client 20.206.105.145:39107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/1.php"] [unique_id "al9ZfiKGokixMSfKDOfn7gAAAks"]
[Tue Jul 21 08:35:26.484001 2026] [security2:error] [pid 466512:tid 466699] [client 20.151.10.161:63706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/aa.php"] [unique_id "al9ZfiKGokixMSfKDOfn8AAAAk0"]
[Tue Jul 21 08:35:26.542281 2026] [security2:error] [pid 466512:tid 466752] [client 81.171.74.60:50988] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/database.sql"] [unique_id "al9ZfiKGokixMSfKDOfn9gAAAoI"]
[Tue Jul 21 08:35:26.542352 2026] [security2:error] [pid 465652:tid 465793] [client 81.171.74.60:50990] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/.git/HEAD"] [unique_id "al9ZfjzTqJoBC2Mw28_EGAAAAJA"]
[Tue Jul 21 08:35:26.587715 2026] [security2:error] [pid 466512:tid 466761] [client 223.181.60.88:3436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZfiKGokixMSfKDOfn9wAAAos"]
[Tue Jul 21 08:35:26.587979 2026] [security2:error] [pid 466512:tid 466761] [client 223.181.60.88:3436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZfiKGokixMSfKDOfn9wAAAos"]
[Tue Jul 21 08:35:26.744596 2026] [security2:error] [pid 465652:tid 465871] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZfjzTqJoBC2Mw28_EEAAAAN4"]
[Tue Jul 21 08:35:26.750158 2026] [security2:error] [pid 466512:tid 466670] [client 20.206.105.145:39104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/100.php"] [unique_id "al9ZfiKGokixMSfKDOfn-QAAAjA"]
[Tue Jul 21 08:35:26.758073 2026] [security2:error] [pid 466512:tid 466716] [client 20.151.10.161:65450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/100.php"] [unique_id "al9ZfiKGokixMSfKDOfn-gAAAl4"]
[Tue Jul 21 08:35:26.970962 2026] [security2:error] [pid 466512:tid 466730] [client 20.206.105.145:39114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/about.php"] [unique_id "al9ZfiKGokixMSfKDOfoAAAAAmw"]
[Tue Jul 21 08:35:27.054348 2026] [security2:error] [pid 466512:tid 466677] [client 20.151.10.161:63713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/footer.php"] [unique_id "al9ZfyKGokixMSfKDOfoAQAAAjc"]
[Tue Jul 21 08:35:27.088571 2026] [security2:error] [pid 466512:tid 466764] [client 45.146.55.186:48129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lumerah.com.br"] [uri "/wp-login.php"] [unique_id "al9ZfSKGokixMSfKDOfnqQAAAo4"]
[Tue Jul 21 08:35:27.165992 2026] [security2:error] [pid 465652:tid 465908] [client 187.125.243.197:58039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZfzzTqJoBC2Mw28_EIAAAAQM"]
[Tue Jul 21 08:35:27.166096 2026] [security2:error] [pid 465652:tid 465908] [client 187.125.243.197:58039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZfzzTqJoBC2Mw28_EIAAAAQM"]
[Tue Jul 21 08:35:27.271857 2026] [security2:error] [pid 466512:tid 466655] [client 81.171.72.135:59768] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/database.sql"] [unique_id "al9ZfyKGokixMSfKDOfoBAAAAiE"]
[Tue Jul 21 08:35:27.271860 2026] [security2:error] [pid 466512:tid 466662] [client 81.171.72.135:59698] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/database_backup.sql"] [unique_id "al9ZfyKGokixMSfKDOfoBgAAAig"]
[Tue Jul 21 08:35:27.271985 2026] [security2:error] [pid 466512:tid 466757] [client 81.171.72.135:59686] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/backup.sql"] [unique_id "al9ZfyKGokixMSfKDOfoBQAAAoc"]
[Tue Jul 21 08:35:27.272966 2026] [security2:error] [pid 465652:tid 465832] [client 81.171.72.135:59756] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/wp-config.php"] [unique_id "al9ZfzzTqJoBC2Mw28_EIwAAALc"]
[Tue Jul 21 08:35:27.443763 2026] [security2:error] [pid 465652:tid 465895] [client 20.151.10.161:65464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/users.php"] [unique_id "al9ZfzzTqJoBC2Mw28_EJwAAAPY"]
[Tue Jul 21 08:35:27.478636 2026] [security2:error] [pid 465652:tid 465830] [client 81.171.72.135:59700] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/backup.zip"] [unique_id "al9ZfzzTqJoBC2Mw28_EKQAAALU"]
[Tue Jul 21 08:35:27.478794 2026] [security2:error] [pid 465652:tid 465881] [client 81.171.72.135:59726] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/.svn/wc.db"] [unique_id "al9ZfzzTqJoBC2Mw28_EKAAAAOg"]
[Tue Jul 21 08:35:27.479087 2026] [security2:error] [pid 466512:tid 466726] [client 81.171.72.135:59728] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/actuator/heapdump"] [unique_id "al9ZfyKGokixMSfKDOfoDQAAAmg"]
[Tue Jul 21 08:35:27.499343 2026] [security2:error] [pid 466512:tid 466652] [client 103.151.46.103:53496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZfyKGokixMSfKDOfoDgAAAh4"]
[Tue Jul 21 08:35:27.499456 2026] [security2:error] [pid 466512:tid 466652] [client 103.151.46.103:53496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZfyKGokixMSfKDOfoDgAAAh4"]
[Tue Jul 21 08:35:27.613983 2026] [security2:error] [pid 465652:tid 465878] [client 195.49.128.211:57732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZfzzTqJoBC2Mw28_EKwAAAOU"]
[Tue Jul 21 08:35:27.614110 2026] [security2:error] [pid 465652:tid 465878] [client 195.49.128.211:57732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZfzzTqJoBC2Mw28_EKwAAAOU"]
[Tue Jul 21 08:35:27.690427 2026] [authz_core:error] [pid 465652:tid 465752] [remote 74.249.245.134:0] AH01630: client denied by server configuration: /home4/wende360/public_html/php.ini
[Tue Jul 21 08:35:27.860933 2026] [security2:error] [pid 465652:tid 465889] [client 20.151.10.161:63648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/177.php"] [unique_id "al9ZfzzTqJoBC2Mw28_EMQAAAPA"]
[Tue Jul 21 08:35:27.863818 2026] [security2:error] [pid 466512:tid 466615] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZfyKGokixMSfKDOfoEAACkmY"]
[Tue Jul 21 08:35:27.863944 2026] [security2:error] [pid 466512:tid 466768] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZfyKGokixMSfKDOfoEAACkmY"]
[Tue Jul 21 08:35:27.876712 2026] [security2:error] [pid 466512:tid 466727] [client 20.206.105.145:39124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/admin.php"] [unique_id "al9ZfyKGokixMSfKDOfoEQAAAmk"]
[Tue Jul 21 08:35:27.891136 2026] [security2:error] [pid 465652:tid 465696] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/settings.php"] [unique_id "al9ZfzzTqJoBC2Mw28_ENAAArys"]
[Tue Jul 21 08:35:27.902519 2026] [security2:error] [pid 466512:tid 466656] [client 20.206.105.145:22093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/177.php"] [unique_id "al9ZfyKGokixMSfKDOfoFAAAAiI"]
[Tue Jul 21 08:35:28.139311 2026] [security2:error] [pid 466512:tid 466548] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZgCKGokixMSfKDOfoGAACgiM"]
[Tue Jul 21 08:35:28.139458 2026] [security2:error] [pid 466512:tid 466752] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZgCKGokixMSfKDOfoGAACgiM"]
[Tue Jul 21 08:35:28.178336 2026] [security2:error] [pid 466512:tid 466756] [client 20.151.10.161:65506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/config.php"] [unique_id "al9ZgCKGokixMSfKDOfoGQAAAoY"]
[Tue Jul 21 08:35:28.271296 2026] [security2:error] [pid 466512:tid 466703] [client 20.206.105.145:38956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/edit.php"] [unique_id "al9ZgCKGokixMSfKDOfoGwAAAlE"]
[Tue Jul 21 08:35:28.346349 2026] [security2:error] [pid 466512:tid 466672] [client 128.127.105.184:51792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZgCKGokixMSfKDOfoHgAAAjI"]
[Tue Jul 21 08:35:28.346658 2026] [security2:error] [pid 466512:tid 466672] [client 128.127.105.184:51792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZgCKGokixMSfKDOfoHgAAAjI"]
[Tue Jul 21 08:35:28.612022 2026] [security2:error] [pid 465652:tid 465802] [client 20.151.10.161:63729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/gettest.php"] [unique_id "al9ZgDzTqJoBC2Mw28_EQAAAAJk"]
[Tue Jul 21 08:35:28.656897 2026] [security2:error] [pid 465652:tid 465812] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZgDzTqJoBC2Mw28_ENgAAAKM"]
[Tue Jul 21 08:35:28.780303 2026] [security2:error] [pid 465652:tid 465678] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/g.php"] [unique_id "al9ZgDzTqJoBC2Mw28_EQQAAyBk"]
[Tue Jul 21 08:35:28.960494 2026] [security2:error] [pid 466512:tid 466741] [client 20.151.10.161:65513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/min.php"] [unique_id "al9ZgCKGokixMSfKDOfoLQAAAnc"]
[Tue Jul 21 08:35:28.993769 2026] [security2:error] [pid 465652:tid 465684] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/403.php"] [unique_id "al9ZgDzTqJoBC2Mw28_ERgAAnB8"]
[Tue Jul 21 08:35:29.098223 2026] [security2:error] [pid 466512:tid 466709] [client 114.119.133.78:42937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mateusdespachante.com.br"] [uri "/&sa=U"] [unique_id "al9ZgSKGokixMSfKDOfoLgAAAlc"], referer: https://www.google.com.br/maps/search/Despachante%20Adir%2088.308-150
[Tue Jul 21 08:35:29.184641 2026] [security2:error] [pid 465652:tid 465724] [remote 74.249.245.134:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.wendelleite.com.br"] [uri "/api.php"] [unique_id "al9ZgTzTqJoBC2Mw28_ESgAAs0c"]
[Tue Jul 21 08:35:29.189045 2026] [security2:error] [pid 465652:tid 465813] [client 20.206.105.145:25100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/BDKR28.php"] [unique_id "al9ZgTzTqJoBC2Mw28_ESwAAAKQ"]
[Tue Jul 21 08:35:29.206574 2026] [security2:error] [pid 466512:tid 466675] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZgSKGokixMSfKDOfoMAACNTs"]
[Tue Jul 21 08:35:29.324149 2026] [security2:error] [pid 465652:tid 465809] [client 20.206.105.145:22214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/199.php"] [unique_id "al9ZgTzTqJoBC2Mw28_ETQAAAKA"]
[Tue Jul 21 08:35:29.540483 2026] [security2:error] [pid 466512:tid 466697] [client 5.38.115.39:55337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZgSKGokixMSfKDOfoXQAAAks"]
[Tue Jul 21 08:35:29.540606 2026] [security2:error] [pid 466512:tid 466697] [client 5.38.115.39:55337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZgSKGokixMSfKDOfoXQAAAks"]
[Tue Jul 21 08:35:29.625027 2026] [security2:error] [pid 466512:tid 466657] [client 20.151.10.161:65461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/edorxrr.php"] [unique_id "al9ZgSKGokixMSfKDOfoYQAAAiM"]
[Tue Jul 21 08:35:29.775872 2026] [security2:error] [pid 466512:tid 466701] [client 114.119.133.138:28383] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "paulaabrao.com.br"] [uri "/category/uncategorized"] [unique_id "al9ZgSKGokixMSfKDOfoeQAAAk8"], referer: https://paulaabrao.com.br/2019/10
[Tue Jul 21 08:35:29.899732 2026] [security2:error] [pid 465652:tid 465817] [client 20.206.105.145:39116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/admin.php"] [unique_id "al9ZgTzTqJoBC2Mw28_EWQAAAKg"]
[Tue Jul 21 08:35:30.046189 2026] [security2:error] [pid 466512:tid 466711] [client 20.206.105.145:25120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/f35.update.php"] [unique_id "al9ZgiKGokixMSfKDOfogAAAAlk"]
[Tue Jul 21 08:35:30.125004 2026] [security2:error] [pid 466512:tid 466714] [client 20.151.10.161:65491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/hur.php"] [unique_id "al9ZgiKGokixMSfKDOfogwAAAlw"]
[Tue Jul 21 08:35:30.152601 2026] [security2:error] [pid 466512:tid 466726] [client 20.220.225.223:34732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/dp.php"] [unique_id "al9ZgiKGokixMSfKDOfohAAAAmg"]
[Tue Jul 21 08:35:30.757749 2026] [security2:error] [pid 465652:tid 465845] [client 14.245.224.124:63933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZgjzTqJoBC2Mw28_EaAAAAMQ"]
[Tue Jul 21 08:35:30.757990 2026] [security2:error] [pid 465652:tid 465845] [client 14.245.224.124:63933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZgjzTqJoBC2Mw28_EaAAAAMQ"]
[Tue Jul 21 08:35:30.796309 2026] [security2:error] [pid 466512:tid 466719] [client 20.151.10.161:65475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/zoro.php"] [unique_id "al9ZgiKGokixMSfKDOfoiwAAAmE"]
[Tue Jul 21 08:35:31.276352 2026] [security2:error] [pid 465652:tid 465848] [client 49.144.66.253:31041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZgzzTqJoBC2Mw28_EhgAAAMc"]
[Tue Jul 21 08:35:31.276495 2026] [security2:error] [pid 465652:tid 465848] [client 49.144.66.253:31041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZgzzTqJoBC2Mw28_EhgAAAMc"]
[Tue Jul 21 08:35:31.318233 2026] [security2:error] [pid 466512:tid 466709] [client 152.59.34.51:50642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZgyKGokixMSfKDOfovwAAAlc"]
[Tue Jul 21 08:35:31.318419 2026] [security2:error] [pid 466512:tid 466709] [client 152.59.34.51:50642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZgyKGokixMSfKDOfovwAAAlc"]
[Tue Jul 21 08:35:31.554213 2026] [security2:error] [pid 465652:tid 465846] [client 20.206.105.145:39260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/f6.php"] [unique_id "al9ZgzzTqJoBC2Mw28_ExgAAAMU"]
[Tue Jul 21 08:35:31.611180 2026] [security2:error] [pid 465652:tid 465795] [client 20.206.105.145:21961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/file52.php"] [unique_id "al9ZgzzTqJoBC2Mw28_EywAAAJI"]
[Tue Jul 21 08:35:31.684673 2026] [security2:error] [pid 466512:tid 466765] [client 20.206.105.145:25589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/f900.php"] [unique_id "al9ZgyKGokixMSfKDOfpJQAAAo8"]
[Tue Jul 21 08:35:31.877645 2026] [security2:error] [pid 465652:tid 465858] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZgzzTqJoBC2Mw28_ExAAAANE"]
[Tue Jul 21 08:35:32.302272 2026] [security2:error] [pid 465652:tid 465856] [client 20.220.225.223:34691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/bootstrap.php"] [unique_id "al9ZhDzTqJoBC2Mw28_E0wAAAM8"]
[Tue Jul 21 08:35:32.482319 2026] [security2:error] [pid 466512:tid 466737] [client 144.76.32.189:63088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.32.76.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "startonesite.com.br"] [uri "/index.php/event/making-the-right-choice-in-career/"] [unique_id "al9ZgyKGokixMSfKDOfovQAAAnM"]
[Tue Jul 21 08:35:32.664601 2026] [security2:error] [pid 466512:tid 466685] [client 74.7.230.35:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.githec.com"] [uri "/robots.txt"] [unique_id "al9ZhCKGokixMSfKDOfpNAACP1c"]
[Tue Jul 21 08:35:32.669087 2026] [security2:error] [pid 466512:tid 466652] [client 20.151.10.161:65448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/coffexium.php"] [unique_id "al9ZhCKGokixMSfKDOfpNQAAAh4"]
[Tue Jul 21 08:35:32.738953 2026] [security2:error] [pid 466512:tid 466728] [client 20.206.105.145:39115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/inputs.php"] [unique_id "al9ZhCKGokixMSfKDOfpPwAAAmo"]
[Tue Jul 21 08:35:33.210823 2026] [security2:error] [pid 466512:tid 466649] [client 20.206.105.145:25114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/xmrl.php"] [unique_id "al9ZhSKGokixMSfKDOfpQQAAAhs"]
[Tue Jul 21 08:35:33.324504 2026] [security2:error] [pid 466512:tid 466537] [remote 209.42.18.223:39236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moratoadvogado.com"] [uri "/wp-login.php"] [unique_id "al9ZhSKGokixMSfKDOfpRAACdhg"]
[Tue Jul 21 08:35:33.486384 2026] [security2:error] [pid 465652:tid 465868] [client 20.220.225.223:20916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/wp-editor.php"] [unique_id "al9ZhTzTqJoBC2Mw28_E7QAAANs"]
[Tue Jul 21 08:35:33.516993 2026] [security2:error] [pid 466512:tid 466662] [client 81.171.72.135:48002] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9ZhSKGokixMSfKDOfpSAAAAig"]
[Tue Jul 21 08:35:33.518021 2026] [security2:error] [pid 466512:tid 466670] [client 81.171.72.135:48046] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9ZhSKGokixMSfKDOfpSQAAAjA"]
[Tue Jul 21 08:35:33.518896 2026] [security2:error] [pid 465652:tid 465826] [client 81.171.72.135:48016] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9ZhTzTqJoBC2Mw28_E7gAAALE"]
[Tue Jul 21 08:35:33.519575 2026] [security2:error] [pid 465652:tid 465827] [client 81.171.72.135:48030] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/backup.tar.gz"] [unique_id "al9ZhTzTqJoBC2Mw28_E7wAAALI"]
[Tue Jul 21 08:35:33.647347 2026] [security2:error] [pid 466512:tid 466762] [client 213.152.186.163:41400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9ZhSKGokixMSfKDOfpTgAAAow"]
[Tue Jul 21 08:35:33.647481 2026] [security2:error] [pid 466512:tid 466762] [client 213.152.186.163:41400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9ZhSKGokixMSfKDOfpTgAAAow"]
[Tue Jul 21 08:35:33.721093 2026] [security2:error] [pid 465652:tid 465880] [client 81.171.72.135:48020] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9ZhTzTqJoBC2Mw28_E9wAAAOc"]
[Tue Jul 21 08:35:33.721885 2026] [security2:error] [pid 465652:tid 465875] [client 81.171.72.135:48000] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9ZhTzTqJoBC2Mw28_E-AAAAOI"]
[Tue Jul 21 08:35:33.732689 2026] [security2:error] [pid 465652:tid 465883] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZhTzTqJoBC2Mw28_E6AAAAOo"]
[Tue Jul 21 08:35:33.784993 2026] [security2:error] [pid 466512:tid 466735] [client 20.206.105.145:38957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/av.php"] [unique_id "al9ZhSKGokixMSfKDOfpUAAAAnE"]
[Tue Jul 21 08:35:33.901853 2026] [security2:error] [pid 465652:tid 465819] [client 195.49.128.211:50409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZhTzTqJoBC2Mw28_E-gAAAKo"]
[Tue Jul 21 08:35:33.902012 2026] [security2:error] [pid 465652:tid 465819] [client 195.49.128.211:50409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZhTzTqJoBC2Mw28_E-gAAAKo"]
[Tue Jul 21 08:35:33.924030 2026] [security2:error] [pid 466512:tid 466674] [client 20.151.10.161:65482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/app.php"] [unique_id "al9ZhSKGokixMSfKDOfpUgAAAjQ"]
[Tue Jul 21 08:35:34.148539 2026] [security2:error] [pid 466512:tid 466679] [client 89.238.167.134:59172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZhiKGokixMSfKDOfpVgAAAjk"]
[Tue Jul 21 08:35:34.148643 2026] [security2:error] [pid 466512:tid 466679] [client 89.238.167.134:59172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZhiKGokixMSfKDOfpVgAAAjk"]
[Tue Jul 21 08:35:34.160913 2026] [security2:error] [pid 466512:tid 466548] [remote 199.189.225.40:63911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "links.principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9ZhiKGokixMSfKDOfpWwACIiM"]
[Tue Jul 21 08:35:34.317564 2026] [security2:error] [pid 466512:tid 466577] [remote 104.207.40.42:28197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.40.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9ZhiKGokixMSfKDOfpVwACbEA"]
[Tue Jul 21 08:35:34.441291 2026] [security2:error] [pid 466512:tid 466713] [client 128.127.105.184:51808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9ZhiKGokixMSfKDOfpYAAAAls"]
[Tue Jul 21 08:35:34.441400 2026] [security2:error] [pid 466512:tid 466713] [client 128.127.105.184:51808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9ZhiKGokixMSfKDOfpYAAAAls"]
[Tue Jul 21 08:35:34.615631 2026] [security2:error] [pid 466512:tid 466675] [client 20.206.105.145:38934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/classwithtostring.php"] [unique_id "al9ZhiKGokixMSfKDOfpYgAAAjU"]
[Tue Jul 21 08:35:34.669612 2026] [security2:error] [pid 466512:tid 466696] [client 81.171.72.135:48090] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/api/.env"] [unique_id "al9ZhiKGokixMSfKDOfpZQAAAko"]
[Tue Jul 21 08:35:34.670761 2026] [security2:error] [pid 466512:tid 466741] [client 81.171.72.135:48072] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/.git/HEAD"] [unique_id "al9ZhiKGokixMSfKDOfpZgAAAnc"]
[Tue Jul 21 08:35:34.670764 2026] [security2:error] [pid 465652:tid 465866] [client 81.171.72.135:48060] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/.env"] [unique_id "al9ZhjzTqJoBC2Mw28_FCAAAANk"]
[Tue Jul 21 08:35:34.672828 2026] [security2:error] [pid 465652:tid 465786] [client 81.171.72.135:48080] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/phpinfo.php"] [unique_id "al9ZhjzTqJoBC2Mw28_FCQAAAIk"]
[Tue Jul 21 08:35:34.706841 2026] [security2:error] [pid 466512:tid 466648] [client 20.206.105.145:25115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/memberfuns.php"] [unique_id "al9ZhiKGokixMSfKDOfpaAAAAho"]
[Tue Jul 21 08:35:34.724530 2026] [security2:error] [pid 465652:tid 465840] [client 122.176.100.127:62087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZhjzTqJoBC2Mw28_FCgAAAL8"]
[Tue Jul 21 08:35:34.724625 2026] [security2:error] [pid 465652:tid 465840] [client 122.176.100.127:62087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZhjzTqJoBC2Mw28_FCgAAAL8"]
[Tue Jul 21 08:35:34.873603 2026] [security2:error] [pid 466512:tid 466699] [client 81.171.72.135:48082] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/docker-compose.yml"] [unique_id "al9ZhiKGokixMSfKDOfpbQAAAk0"]
[Tue Jul 21 08:35:34.874433 2026] [security2:error] [pid 466512:tid 466728] [client 81.171.72.135:48116] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/user_secrets.yml"] [unique_id "al9ZhiKGokixMSfKDOfpbgAAAmo"]
[Tue Jul 21 08:35:34.874676 2026] [security2:error] [pid 465652:tid 465891] [client 81.171.72.135:48108] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/.env.production"] [unique_id "al9ZhjzTqJoBC2Mw28_FCwAAAPI"]
[Tue Jul 21 08:35:34.977859 2026] [security2:error] [pid 466512:tid 466678] [client 202.179.75.202:59356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZhiKGokixMSfKDOfpbwAAAjg"]
[Tue Jul 21 08:35:34.977972 2026] [security2:error] [pid 466512:tid 466678] [client 202.179.75.202:59356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZhiKGokixMSfKDOfpbwAAAjg"]
[Tue Jul 21 08:35:35.434460 2026] [security2:error] [pid 466512:tid 466744] [client 20.206.105.145:38961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9ZhyKGokixMSfKDOfpdQAAAno"]
[Tue Jul 21 08:35:35.652735 2026] [security2:error] [pid 465652:tid 465791] [client 81.171.72.135:48154] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/server.key"] [unique_id "al9ZhzzTqJoBC2Mw28_FGgAAAI4"]
[Tue Jul 21 08:35:35.652735 2026] [security2:error] [pid 466512:tid 466664] [client 81.171.72.135:48168] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/config/production.json"] [unique_id "al9ZhyKGokixMSfKDOfpegAAAio"]
[Tue Jul 21 08:35:35.652869 2026] [security2:error] [pid 466512:tid 466764] [client 81.171.72.135:48132] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9ZhyKGokixMSfKDOfpeQAAAo4"]
[Tue Jul 21 08:35:35.656519 2026] [security2:error] [pid 466512:tid 466688] [client 81.171.72.135:48144] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9ZhyKGokixMSfKDOfpewAAAkI"]
[Tue Jul 21 08:35:35.813922 2026] [security2:error] [pid 465652:tid 465801] [client 20.206.105.145:25095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/ms.php"] [unique_id "al9ZhzzTqJoBC2Mw28_FJAAAAJg"]
[Tue Jul 21 08:35:35.858109 2026] [security2:error] [pid 466512:tid 466682] [client 81.171.72.135:48182] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/secrets.json"] [unique_id "al9ZhyKGokixMSfKDOfpgwAAAjw"]
[Tue Jul 21 08:35:35.900433 2026] [security2:error] [pid 466512:tid 466655] [client 45.8.19.148:36623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeireirapiske.com.br"] [uri "/wp-login.php"] [unique_id "al9ZhyKGokixMSfKDOfphAAAAiE"]
[Tue Jul 21 08:35:36.082682 2026] [security2:error] [pid 465652:tid 465842] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZhzzTqJoBC2Mw28_FGAAAAME"]
[Tue Jul 21 08:35:36.131284 2026] [security2:error] [pid 466512:tid 466642] [client 20.151.10.161:63681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/core.php"] [unique_id "al9ZiCKGokixMSfKDOfphgAAAhQ"]
[Tue Jul 21 08:35:36.148115 2026] [autoindex:error] [pid 466512:tid 466714] [client 66.249.66.193:41858] AH01276: Cannot serve directory /home2/bavosc49/clinic.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:35:36.355953 2026] [security2:error] [pid 466512:tid 466701] [client 117.213.202.34:56466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZiCKGokixMSfKDOfpiAAAAk8"]
[Tue Jul 21 08:35:36.356211 2026] [security2:error] [pid 466512:tid 466701] [client 117.213.202.34:56466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZiCKGokixMSfKDOfpiAAAAk8"]
[Tue Jul 21 08:35:36.678083 2026] [security2:error] [pid 466512:tid 466651] [client 125.18.144.2:24925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.144.18.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZiCKGokixMSfKDOfpjgAAAh0"]
[Tue Jul 21 08:35:36.678291 2026] [security2:error] [pid 466512:tid 466651] [client 125.18.144.2:24925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZiCKGokixMSfKDOfpjgAAAh0"]
[Tue Jul 21 08:35:36.768238 2026] [security2:error] [pid 465652:tid 465785] [client 20.206.105.145:38950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-blog.php"] [unique_id "al9ZiDzTqJoBC2Mw28_FMgAAAIg"]
[Tue Jul 21 08:35:37.038238 2026] [security2:error] [pid 466512:tid 466659] [client 20.206.105.145:22100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/122.php"] [unique_id "al9ZiSKGokixMSfKDOfpkwAAAiU"]
[Tue Jul 21 08:35:37.058682 2026] [security2:error] [pid 466512:tid 466752] [client 74.249.245.134:46997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/classsmtps.php"] [unique_id "al9ZiSKGokixMSfKDOfplAAAAoI"]
[Tue Jul 21 08:35:37.445495 2026] [security2:error] [pid 466512:tid 466699] [client 223.181.60.88:6681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZiSKGokixMSfKDOfpvgAAAk0"]
[Tue Jul 21 08:35:37.445601 2026] [security2:error] [pid 466512:tid 466699] [client 223.181.60.88:6681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZiSKGokixMSfKDOfpvgAAAk0"]
[Tue Jul 21 08:35:37.509959 2026] [security2:error] [pid 465652:tid 465900] [client 20.220.225.223:20900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/cro.php"] [unique_id "al9ZiTzTqJoBC2Mw28_FPgAAAPs"]
[Tue Jul 21 08:35:37.576201 2026] [security2:error] [pid 466512:tid 466563] [remote 91.142.222.105:59238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9ZhyKGokixMSfKDOfpdwACcTI"]
[Tue Jul 21 08:35:37.697375 2026] [security2:error] [pid 466512:tid 466711] [client 187.125.243.197:58547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZiSKGokixMSfKDOfpxwAAAlk"]
[Tue Jul 21 08:35:37.697472 2026] [security2:error] [pid 466512:tid 466711] [client 187.125.243.197:58547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZiSKGokixMSfKDOfpxwAAAlk"]
[Tue Jul 21 08:35:37.945681 2026] [security2:error] [pid 465652:tid 465861] [client 20.206.105.145:25142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/zz.php"] [unique_id "al9ZiTzTqJoBC2Mw28_FRQAAANQ"]
[Tue Jul 21 08:35:38.022804 2026] [security2:error] [pid 465652:tid 465786] [client 103.151.46.103:53979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZijzTqJoBC2Mw28_FSAAAAIk"]
[Tue Jul 21 08:35:38.022916 2026] [security2:error] [pid 465652:tid 465786] [client 103.151.46.103:53979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZijzTqJoBC2Mw28_FSAAAAIk"]
[Tue Jul 21 08:35:38.260442 2026] [security2:error] [pid 465652:tid 465791] [client 20.151.10.161:63725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/main.php"] [unique_id "al9ZijzTqJoBC2Mw28_FTQAAAI4"]
[Tue Jul 21 08:35:38.315555 2026] [security2:error] [pid 465652:tid 465845] [client 195.49.128.211:58339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZijzTqJoBC2Mw28_FTwAAAMQ"]
[Tue Jul 21 08:35:38.315781 2026] [security2:error] [pid 465652:tid 465845] [client 195.49.128.211:58339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZijzTqJoBC2Mw28_FTwAAAMQ"]
[Tue Jul 21 08:35:38.392242 2026] [proxy:error] [pid 466512:tid 466703] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:38.392302 2026] [proxy_http:error] [pid 466512:tid 466703] [client 20.206.105.145:39278] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:38.392839 2026] [proxy:error] [pid 466512:tid 466703] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:38.392865 2026] [proxy_http:error] [pid 466512:tid 466703] [client 20.206.105.145:39278] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:38.418185 2026] [security2:error] [pid 466512:tid 466613] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZiiKGokixMSfKDOfp2AACO2Q"]
[Tue Jul 21 08:35:38.418304 2026] [security2:error] [pid 466512:tid 466681] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZiiKGokixMSfKDOfp2AACO2Q"]
[Tue Jul 21 08:35:38.443644 2026] [security2:error] [pid 466512:tid 466676] [client 89.238.167.134:37804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZiiKGokixMSfKDOfp2QAAAjY"]
[Tue Jul 21 08:35:38.443745 2026] [security2:error] [pid 466512:tid 466676] [client 89.238.167.134:37804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZiiKGokixMSfKDOfp2QAAAjY"]
[Tue Jul 21 08:35:38.674809 2026] [security2:error] [pid 466512:tid 466559] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZiiKGokixMSfKDOfp2wACSy4"]
[Tue Jul 21 08:35:38.674968 2026] [security2:error] [pid 466512:tid 466697] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZiiKGokixMSfKDOfp2wACSy4"]
[Tue Jul 21 08:35:39.144931 2026] [security2:error] [pid 466512:tid 466689] [client 20.206.105.145:39111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-content/admin.php"] [unique_id "al9ZiyKGokixMSfKDOfp4AAAAkM"]
[Tue Jul 21 08:35:39.181583 2026] [security2:error] [pid 466512:tid 466699] [client 20.206.105.145:25483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/for.php"] [unique_id "al9ZiyKGokixMSfKDOfp4wAAAk0"]
[Tue Jul 21 08:35:39.199904 2026] [security2:error] [pid 465652:tid 465774] [remote 130.185.118.215:47576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ZizzTqJoBC2Mw28_FiQAAx3k"]
[Tue Jul 21 08:35:39.207851 2026] [security2:error] [pid 466512:tid 466758] [client 20.206.105.145:22084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/green1.php"] [unique_id "al9ZiyKGokixMSfKDOfp5AAAAog"]
[Tue Jul 21 08:35:39.326449 2026] [security2:error] [pid 466512:tid 466608] [remote 167.71.218.184:53932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9ZiiKGokixMSfKDOfp1gACGV8"]
[Tue Jul 21 08:35:39.394619 2026] [security2:error] [pid 466512:tid 466759] [client 74.7.244.48:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sugar-delete.site"] [uri "/index.php"] [unique_id "al9ZiSKGokixMSfKDOfp0QAAAok"]
[Tue Jul 21 08:35:39.395402 2026] [security2:error] [pid 465652:tid 465876] [client 74.7.244.48:54372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sugar-delete.site"] [uri "/robots.txt"] [unique_id "al9ZiTzTqJoBC2Mw28_FRgAA40Y"]
[Tue Jul 21 08:35:39.580636 2026] [security2:error] [pid 465652:tid 465896] [client 45.132.227.209:25255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiferreira.com.br"] [uri "/wp-login.php"] [unique_id "al9ZizzTqJoBC2Mw28_FoQAAAPc"]
[Tue Jul 21 08:35:39.632090 2026] [security2:error] [pid 465652:tid 465841] [client 20.220.225.223:50905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/akismet.php"] [unique_id "al9ZizzTqJoBC2Mw28_FqQAAAMA"]
[Tue Jul 21 08:35:39.791199 2026] [security2:error] [pid 465652:tid 465891] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZizzTqJoBC2Mw28_FqgAA8j0"]
[Tue Jul 21 08:35:39.942573 2026] [security2:error] [pid 466512:tid 466737] [client 20.220.225.223:20871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/cron-tab.php"] [unique_id "al9ZiyKGokixMSfKDOfp7QAAAnM"]
[Tue Jul 21 08:35:40.091462 2026] [security2:error] [pid 465652:tid 465889] [client 20.206.105.145:39141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/adminfuns.php"] [unique_id "al9ZjDzTqJoBC2Mw28_FtAAAAPA"]
[Tue Jul 21 08:35:40.253402 2026] [security2:error] [pid 466512:tid 466693] [client 5.38.115.39:55788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZjCKGokixMSfKDOfp8gAAAkc"]
[Tue Jul 21 08:35:40.253614 2026] [security2:error] [pid 466512:tid 466693] [client 5.38.115.39:55788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZjCKGokixMSfKDOfp8gAAAkc"]
[Tue Jul 21 08:35:40.357799 2026] [core:alert] [pid 465652:tid 465826] [client 57.141.18.62:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:35:40.421596 2026] [security2:error] [pid 465652:tid 465845] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZizzTqJoBC2Mw28_FsQAAAMQ"]
[Tue Jul 21 08:35:40.509164 2026] [security2:error] [pid 465652:tid 465790] [client 20.206.105.145:22087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/biufile.php"] [unique_id "al9ZjDzTqJoBC2Mw28_FxAAAAI0"]
[Tue Jul 21 08:35:40.646343 2026] [security2:error] [pid 466512:tid 466706] [client 20.206.105.145:25591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/yup.php"] [unique_id "al9ZjCKGokixMSfKDOfp-AAAAlQ"]
[Tue Jul 21 08:35:41.311962 2026] [security2:error] [pid 465652:tid 465655] [remote 74.7.243.200:36858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.243.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sugar-delete.site"] [uri "/xmlrpc.php"] [unique_id "al9ZjDzTqJoBC2Mw28_F0QAA5gI"], referer: https://sugar-delete.site/
[Tue Jul 21 08:35:41.330550 2026] [security2:error] [pid 465652:tid 465803] [client 20.206.105.145:38951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/goods.php"] [unique_id "al9ZjTzTqJoBC2Mw28_F1QAAAJo"]
[Tue Jul 21 08:35:41.600963 2026] [security2:error] [pid 465652:tid 465820] [client 14.245.224.124:64404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZjTzTqJoBC2Mw28_F2wAAAKs"]
[Tue Jul 21 08:35:41.601133 2026] [security2:error] [pid 465652:tid 465820] [client 14.245.224.124:64404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZjTzTqJoBC2Mw28_F2wAAAKs"]
[Tue Jul 21 08:35:41.618553 2026] [security2:error] [pid 465652:tid 465902] [client 81.171.72.135:48192] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/.npmrc"] [unique_id "al9ZjTzTqJoBC2Mw28_F3AAAAP0"]
[Tue Jul 21 08:35:41.619794 2026] [security2:error] [pid 465652:tid 465898] [client 81.171.72.135:48208] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rockegrow.com.br"] [uri "/.bash_history"] [unique_id "al9ZjTzTqJoBC2Mw28_F3QAAAPk"]
[Tue Jul 21 08:35:41.863686 2026] [security2:error] [pid 466512:tid 466743] [client 20.151.10.161:65413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/init.php"] [unique_id "al9ZjSKGokixMSfKDOfqCQAAAnk"]
[Tue Jul 21 08:35:41.973725 2026] [security2:error] [pid 466512:tid 466744] [client 152.59.34.51:51118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZjSKGokixMSfKDOfqCgAAAno"]
[Tue Jul 21 08:35:41.973856 2026] [security2:error] [pid 466512:tid 466744] [client 152.59.34.51:51118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZjSKGokixMSfKDOfqCgAAAno"]
[Tue Jul 21 08:35:42.163841 2026] [security2:error] [pid 465652:tid 465841] [client 49.144.66.253:31233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZjjzTqJoBC2Mw28_F6AAAAMA"]
[Tue Jul 21 08:35:42.164233 2026] [security2:error] [pid 465652:tid 465841] [client 49.144.66.253:31233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZjjzTqJoBC2Mw28_F6AAAAMA"]
[Tue Jul 21 08:35:42.306476 2026] [security2:error] [pid 466512:tid 466655] [client 20.206.105.145:22225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wpconf.php"] [unique_id "al9ZjiKGokixMSfKDOfqDgAAAiE"]
[Tue Jul 21 08:35:42.464298 2026] [security2:error] [pid 465652:tid 465792] [client 5.31.193.106:58597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZjjzTqJoBC2Mw28_F7AAAAI8"]
[Tue Jul 21 08:35:42.464412 2026] [security2:error] [pid 465652:tid 465792] [client 5.31.193.106:58597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZjjzTqJoBC2Mw28_F7AAAAI8"]
[Tue Jul 21 08:35:42.674931 2026] [security2:error] [pid 466512:tid 466648] [client 20.206.105.145:39125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ms-edit.php"] [unique_id "al9ZjiKGokixMSfKDOfqEQAAAho"]
[Tue Jul 21 08:35:42.984411 2026] [security2:error] [pid 466512:tid 466703] [client 74.249.245.134:43531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/rip.php"] [unique_id "al9ZjiKGokixMSfKDOfqFwAAAlE"]
[Tue Jul 21 08:35:43.360986 2026] [security2:error] [pid 465652:tid 465853] [client 20.206.105.145:22121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/mosty.php"] [unique_id "al9ZjzzTqJoBC2Mw28_F-wAAAMw"]
[Tue Jul 21 08:35:43.657911 2026] [security2:error] [pid 466512:tid 466733] [client 87.199.196.160:55668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.196.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.murilomattos.com"] [uri "/wp-comments-post.php"] [unique_id "al9ZjyKGokixMSfKDOfqIAAAAm8"], referer: https://www.murilomattos.com/product/48h-event/
[Tue Jul 21 08:35:43.658051 2026] [security2:error] [pid 466512:tid 466733] [client 87.199.196.160:55668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.murilomattos.com"] [uri "/wp-comments-post.php"] [unique_id "al9ZjyKGokixMSfKDOfqIAAAAm8"], referer: https://www.murilomattos.com/product/48h-event/
[Tue Jul 21 08:35:43.694929 2026] [security2:error] [pid 466512:tid 466647] [client 20.206.105.145:25092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/wpxml.php"] [unique_id "al9ZjyKGokixMSfKDOfqIgAAAhk"]
[Tue Jul 21 08:35:43.717374 2026] [security2:error] [pid 466512:tid 466755] [client 20.206.105.145:38923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/222.php"] [unique_id "al9ZjyKGokixMSfKDOfqIwAAAoU"]
[Tue Jul 21 08:35:43.761527 2026] [security2:error] [pid 466512:tid 466728] [client 20.151.10.161:63626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/prekel.php"] [unique_id "al9ZjyKGokixMSfKDOfqJAAAAmo"]
[Tue Jul 21 08:35:43.772358 2026] [security2:error] [pid 465652:tid 465895] [client 20.206.105.145:22250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/dejavu.php"] [unique_id "al9ZjzzTqJoBC2Mw28_GCwAAAPY"]
[Tue Jul 21 08:35:43.779614 2026] [autoindex:error] [pid 466512:tid 466751] [client 82.156.116.86:42176] AH01276: Cannot serve directory /home4/serric15/voztricolor.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:35:44.285639 2026] [security2:error] [pid 465652:tid 465836] [client 20.226.114.112:5806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "diariomineral.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9ZkDzTqJoBC2Mw28_GGgAAALs"]
[Tue Jul 21 08:35:44.323419 2026] [security2:error] [pid 466512:tid 466655] [client 20.226.114.112:9309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.114.226.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/xmlrpc.php"] [unique_id "al9ZkCKGokixMSfKDOfqMQAAAiE"]
[Tue Jul 21 08:35:44.396653 2026] [security2:error] [pid 465652:tid 465906] [client 61.1.167.83:61769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZkDzTqJoBC2Mw28_GHQAAAQE"]
[Tue Jul 21 08:35:44.404066 2026] [security2:error] [pid 465652:tid 465906] [client 61.1.167.83:61769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZkDzTqJoBC2Mw28_GHQAAAQE"]
[Tue Jul 21 08:35:44.477068 2026] [security2:error] [pid 466512:tid 466672] [client 20.206.105.145:25104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/fffm.php"] [unique_id "al9ZkCKGokixMSfKDOfqMwAAAjI"]
[Tue Jul 21 08:35:44.567641 2026] [security2:error] [pid 465652:tid 465905] [client 195.49.128.211:51030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZkDzTqJoBC2Mw28_GIAAAAQA"]
[Tue Jul 21 08:35:44.567785 2026] [security2:error] [pid 465652:tid 465905] [client 195.49.128.211:51030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZkDzTqJoBC2Mw28_GIAAAAQA"]
[Tue Jul 21 08:35:44.615695 2026] [security2:error] [pid 466512:tid 466716] [client 20.220.225.223:50283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/ace2.php"] [unique_id "al9ZkCKGokixMSfKDOfqNQAAAl4"]
[Tue Jul 21 08:35:44.690275 2026] [security2:error] [pid 466512:tid 466683] [client 20.206.105.145:22101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/aaf.php"] [unique_id "al9ZkCKGokixMSfKDOfqNgAAAj0"]
[Tue Jul 21 08:35:44.746518 2026] [security2:error] [pid 465652:tid 465856] [client 20.226.114.112:9317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.114.226.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/xmlrpc.php"] [unique_id "al9ZkDzTqJoBC2Mw28_GKwAAAM8"]
[Tue Jul 21 08:35:44.746599 2026] [security2:error] [pid 465652:tid 465856] [client 20.226.114.112:9317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "diariomineral.com"] [uri "/xmlrpc.php"] [unique_id "al9ZkDzTqJoBC2Mw28_GKwAAAM8"]
[Tue Jul 21 08:35:44.803646 2026] [security2:error] [pid 465652:tid 465713] [remote 13.59.233.180:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "onkosclinica.com"] [uri "/"] [unique_id "al9ZkDzTqJoBC2Mw28_GLwAAlzw"]
[Tue Jul 21 08:35:44.813478 2026] [security2:error] [pid 466512:tid 466727] [client 20.206.105.145:25134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/gecko.php"] [unique_id "al9ZkCKGokixMSfKDOfqOAAAAmk"]
[Tue Jul 21 08:35:44.828230 2026] [security2:error] [pid 465652:tid 465878] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZkDzTqJoBC2Mw28_GGwAAAOU"]
[Tue Jul 21 08:35:44.829511 2026] [security2:error] [pid 466512:tid 466663] [client 185.198.240.6:20697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mbarcondicionados.com.br"] [uri "/wp-login.php"] [unique_id "al9ZkCKGokixMSfKDOfqOQAAAik"]
[Tue Jul 21 08:35:44.860428 2026] [security2:error] [pid 465652:tid 465896] [client 103.59.206.240:31059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZkDzTqJoBC2Mw28_GMAAAAPc"]
[Tue Jul 21 08:35:44.860546 2026] [security2:error] [pid 465652:tid 465896] [client 103.59.206.240:31059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZkDzTqJoBC2Mw28_GMAAAAPc"]
[Tue Jul 21 08:35:44.886485 2026] [security2:error] [pid 465652:tid 465791] [client 74.249.245.134:63686] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/1.php"] [unique_id "al9ZkDzTqJoBC2Mw28_GMQAAAI4"]
[Tue Jul 21 08:35:44.886570 2026] [security2:error] [pid 465652:tid 465791] [client 74.249.245.134:63686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/1.php"] [unique_id "al9ZkDzTqJoBC2Mw28_GMQAAAI4"]
[Tue Jul 21 08:35:45.046732 2026] [security2:error] [pid 465652:tid 465677] [remote 13.59.233.180:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "onkosclinica.com"] [uri "/robots.txt"] [unique_id "al9ZkTzTqJoBC2Mw28_GNQAA7hg"]
[Tue Jul 21 08:35:45.164419 2026] [security2:error] [pid 465652:tid 465871] [client 122.176.100.127:62591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZkTzTqJoBC2Mw28_GNwAAAN4"]
[Tue Jul 21 08:35:45.165895 2026] [security2:error] [pid 465652:tid 465871] [client 122.176.100.127:62591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZkTzTqJoBC2Mw28_GNwAAAN4"]
[Tue Jul 21 08:35:45.190155 2026] [security2:error] [pid 465652:tid 465735] [remote 13.59.233.180:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "onkosclinica.com"] [uri "/robots.txt"] [unique_id "al9ZkTzTqJoBC2Mw28_GOgAAslI"]
[Tue Jul 21 08:35:45.285931 2026] [security2:error] [pid 465652:tid 465778] [remote 13.59.233.180:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "onkosclinica.com"] [uri "/ads.txt"] [unique_id "al9ZkTzTqJoBC2Mw28_GPgAAx30"]
[Tue Jul 21 08:35:45.441782 2026] [security2:error] [pid 465652:tid 465738] [remote 13.59.233.180:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.onkosclinica.com"] [uri "/"] [unique_id "al9ZkTzTqJoBC2Mw28_GQQAA2FU"]
[Tue Jul 21 08:35:45.464952 2026] [security2:error] [pid 465652:tid 465812] [client 20.206.105.145:25523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/a1.php"] [unique_id "al9ZkTzTqJoBC2Mw28_GQgAAAKM"]
[Tue Jul 21 08:35:45.599169 2026] [security2:error] [pid 465652:tid 465839] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZkTzTqJoBC2Mw28_GRAAAAL4"]
[Tue Jul 21 08:35:45.742444 2026] [security2:error] [pid 466512:tid 466761] [client 20.220.225.223:34720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/koiy.php"] [unique_id "al9ZkSKGokixMSfKDOfqPwAAAos"]
[Tue Jul 21 08:35:45.890376 2026] [security2:error] [pid 466512:tid 466745] [client 202.179.75.202:42878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZkSKGokixMSfKDOfqQwAAAns"]
[Tue Jul 21 08:35:45.890471 2026] [security2:error] [pid 466512:tid 466745] [client 202.179.75.202:42878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZkSKGokixMSfKDOfqQwAAAns"]
[Tue Jul 21 08:35:46.001617 2026] [security2:error] [pid 466512:tid 466688] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9ZkiKGokixMSfKDOfqRQAAAkI"]
[Tue Jul 21 08:35:46.045756 2026] [security2:error] [pid 466512:tid 466689] [client 20.206.105.145:25549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/k2.php"] [unique_id "al9ZkiKGokixMSfKDOfqRgAAAkM"]
[Tue Jul 21 08:35:46.149039 2026] [security2:error] [pid 466512:tid 466604] [remote 104.207.51.18:24825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9ZkSKGokixMSfKDOfqRAACOls"]
[Tue Jul 21 08:35:46.396412 2026] [security2:error] [pid 465652:tid 465888] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9ZkjzTqJoBC2Mw28_GWAAAAO8"]
[Tue Jul 21 08:35:46.492071 2026] [security2:error] [pid 466512:tid 466676] [client 203.31.169.89:61555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.169.31.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kaducontractor.com"] [uri "/xmlrpc.php"] [unique_id "al9ZkiKGokixMSfKDOfqTAAAAjY"]
[Tue Jul 21 08:35:46.492228 2026] [security2:error] [pid 466512:tid 466676] [client 203.31.169.89:61555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kaducontractor.com"] [uri "/xmlrpc.php"] [unique_id "al9ZkiKGokixMSfKDOfqTAAAAjY"]
[Tue Jul 21 08:35:46.503940 2026] [security2:error] [pid 466512:tid 466677] [client 20.206.105.145:38938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/cgi-bin/index.php"] [unique_id "al9ZkiKGokixMSfKDOfqTQAAAjc"]
[Tue Jul 21 08:35:46.518442 2026] [security2:error] [pid 466512:tid 466743] [client 20.151.10.161:65503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/0.php"] [unique_id "al9ZkiKGokixMSfKDOfqTgAAAnk"]
[Tue Jul 21 08:35:46.670734 2026] [security2:error] [pid 466512:tid 466744] [client 20.206.105.145:21997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/term.php"] [unique_id "al9ZkiKGokixMSfKDOfqTwAAAno"]
[Tue Jul 21 08:35:46.740554 2026] [security2:error] [pid 466512:tid 466679] [client 20.206.105.145:25129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/82.php"] [unique_id "al9ZkiKGokixMSfKDOfqUgAAAjk"]
[Tue Jul 21 08:35:46.786042 2026] [security2:error] [pid 465652:tid 465814] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9ZkjzTqJoBC2Mw28_GXAAAAKU"]
[Tue Jul 21 08:35:46.826196 2026] [security2:error] [pid 466512:tid 466668] [client 20.206.105.145:25411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/config.json.php"] [unique_id "al9ZkiKGokixMSfKDOfqVwAAAi4"]
[Tue Jul 21 08:35:46.978862 2026] [security2:error] [pid 465652:tid 465791] [client 20.206.105.145:25491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "trueproducoes.com.br"] [uri "/fpwch.php"] [unique_id "al9ZkjzTqJoBC2Mw28_GYAAAAI4"]
[Tue Jul 21 08:35:47.030258 2026] [security2:error] [pid 465652:tid 465855] [client 117.213.202.34:57108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZkzzTqJoBC2Mw28_GYwAAAM4"]
[Tue Jul 21 08:35:47.030346 2026] [security2:error] [pid 465652:tid 465855] [client 117.213.202.34:57108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZkzzTqJoBC2Mw28_GYwAAAM4"]
[Tue Jul 21 08:35:47.197304 2026] [security2:error] [pid 466512:tid 466711] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9ZkyKGokixMSfKDOfqWwAAAlk"]
[Tue Jul 21 08:35:47.672198 2026] [security2:error] [pid 466512:tid 466648] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9ZkyKGokixMSfKDOfqXQAAAho"]
[Tue Jul 21 08:35:47.703949 2026] [security2:error] [pid 466512:tid 466701] [client 20.151.10.161:65428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/BDKR28.php"] [unique_id "al9ZkyKGokixMSfKDOfqXgAAAk8"]
[Tue Jul 21 08:35:47.846143 2026] [security2:error] [pid 466512:tid 466670] [client 20.206.105.145:22005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/ha.php"] [unique_id "al9ZkyKGokixMSfKDOfqaAAAAjA"]
[Tue Jul 21 08:35:47.992272 2026] [security2:error] [pid 465652:tid 465848] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZkzzTqJoBC2Mw28_GbgAAAMc"]
[Tue Jul 21 08:35:48.059237 2026] [security2:error] [pid 466512:tid 466696] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9ZlCKGokixMSfKDOfqbAAAAko"]
[Tue Jul 21 08:35:48.190318 2026] [security2:error] [pid 465652:tid 465845] [client 223.181.60.88:29115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZlDzTqJoBC2Mw28_GdwAAAMQ"]
[Tue Jul 21 08:35:48.190540 2026] [security2:error] [pid 465652:tid 465845] [client 223.181.60.88:29115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZlDzTqJoBC2Mw28_GdwAAAMQ"]
[Tue Jul 21 08:35:48.216830 2026] [security2:error] [pid 465652:tid 465786] [client 187.125.243.197:59055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZlDzTqJoBC2Mw28_GeQAAAIk"]
[Tue Jul 21 08:35:48.216971 2026] [security2:error] [pid 465652:tid 465786] [client 187.125.243.197:59055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZlDzTqJoBC2Mw28_GeQAAAIk"]
[Tue Jul 21 08:35:48.460527 2026] [security2:error] [pid 466512:tid 466743] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9ZlCKGokixMSfKDOfqdgAAAnk"]
[Tue Jul 21 08:35:48.467704 2026] [security2:error] [pid 466512:tid 466645] [client 20.206.105.145:21980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/hur.php"] [unique_id "al9ZlCKGokixMSfKDOfqdwAAAhc"]
[Tue Jul 21 08:35:48.872204 2026] [security2:error] [pid 466512:tid 466673] [client 20.151.10.161:63689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/f35.update.php"] [unique_id "al9ZlCKGokixMSfKDOfqfAAAAjM"]
[Tue Jul 21 08:35:48.877810 2026] [security2:error] [pid 466512:tid 466686] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9ZlCKGokixMSfKDOfqfQAAAkA"]
[Tue Jul 21 08:35:48.949283 2026] [security2:error] [pid 466512:tid 466765] [client 195.49.128.211:58955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZlCKGokixMSfKDOfqgQAAAo8"]
[Tue Jul 21 08:35:48.949485 2026] [security2:error] [pid 466512:tid 466765] [client 195.49.128.211:58955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZlCKGokixMSfKDOfqgQAAAo8"]
[Tue Jul 21 08:35:49.002957 2026] [security2:error] [pid 466512:tid 466555] [remote 65.111.2.188:43423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.2.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9ZkyKGokixMSfKDOfqZgACXio"]
[Tue Jul 21 08:35:49.169624 2026] [security2:error] [pid 465652:tid 465813] [client 20.206.105.145:22116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/h02ugyh.php"] [unique_id "al9ZlTzTqJoBC2Mw28_GjgAAAKQ"]
[Tue Jul 21 08:35:49.186711 2026] [core:error] [pid 465652:tid 465752] [remote 195.96.139.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpanel.tavarescont.com.br:8880
[Tue Jul 21 08:35:49.186732 2026] [core:error] [pid 465652:tid 465752] [remote 195.96.139.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpanel.tavarescont.com.br:8880
[Tue Jul 21 08:35:49.187336 2026] [security2:error] [pid 466512:tid 466529] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZlSKGokixMSfKDOfqgwACKxA"]
[Tue Jul 21 08:35:49.187497 2026] [security2:error] [pid 466512:tid 466665] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZlSKGokixMSfKDOfqgwACKxA"]
[Tue Jul 21 08:35:49.251877 2026] [security2:error] [pid 465652:tid 465721] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZlTzTqJoBC2Mw28_GkQAAlUQ"]
[Tue Jul 21 08:35:49.252038 2026] [security2:error] [pid 465652:tid 465798] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZlTzTqJoBC2Mw28_GkQAAlUQ"]
[Tue Jul 21 08:35:49.268283 2026] [security2:error] [pid 465652:tid 465891] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9ZlTzTqJoBC2Mw28_GkgAAAPI"]
[Tue Jul 21 08:35:49.334620 2026] [security2:error] [pid 465652:tid 465742] [remote 47.128.41.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "samilacalculos.com.br"] [uri "/robots.txt"] [unique_id "al9ZlTzTqJoBC2Mw28_GkwAAvVk"]
[Tue Jul 21 08:35:49.555915 2026] [security2:error] [pid 465652:tid 465843] [client 128.127.105.184:41238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9ZlTzTqJoBC2Mw28_GmQAAAMI"]
[Tue Jul 21 08:35:49.556001 2026] [security2:error] [pid 465652:tid 465843] [client 128.127.105.184:41238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9ZlTzTqJoBC2Mw28_GmQAAAMI"]
[Tue Jul 21 08:35:49.580150 2026] [proxy:error] [pid 466512:tid 466703] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:49.580214 2026] [proxy_http:error] [pid 466512:tid 466703] [client 20.206.105.145:39139] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:49.580831 2026] [proxy:error] [pid 466512:tid 466703] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:49.580858 2026] [proxy_http:error] [pid 466512:tid 466703] [client 20.206.105.145:39139] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:49.681452 2026] [security2:error] [pid 465652:tid 465791] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9ZlTzTqJoBC2Mw28_GmwAAAI4"]
[Tue Jul 21 08:35:49.692786 2026] [security2:error] [pid 465652:tid 465804] [client 20.206.105.145:38954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/BDKR28WP.php"] [unique_id "al9ZlTzTqJoBC2Mw28_GnAAAAJs"]
[Tue Jul 21 08:35:49.777018 2026] [proxy:error] [pid 466512:tid 466697] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:49.777105 2026] [proxy_http:error] [pid 466512:tid 466697] [client 20.206.105.145:38919] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:49.778156 2026] [proxy:error] [pid 466512:tid 466697] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:49.778194 2026] [proxy_http:error] [pid 466512:tid 466697] [client 20.206.105.145:38919] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:49.868944 2026] [proxy:error] [pid 466512:tid 466763] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:49.869004 2026] [proxy_http:error] [pid 466512:tid 466763] [client 20.206.105.145:38949] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:49.869498 2026] [proxy:error] [pid 466512:tid 466763] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:49.869523 2026] [proxy_http:error] [pid 466512:tid 466763] [client 20.206.105.145:38949] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:50.147436 2026] [security2:error] [pid 466512:tid 466695] [client 74.249.245.134:33072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/chosen.php"] [unique_id "al9ZliKGokixMSfKDOfqkQAAAkk"]
[Tue Jul 21 08:35:50.159070 2026] [security2:error] [pid 466512:tid 466685] [client 20.206.105.145:22139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/seiso.php"] [unique_id "al9ZliKGokixMSfKDOfqkgAAAj8"]
[Tue Jul 21 08:35:50.177092 2026] [security2:error] [pid 466512:tid 466688] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9ZliKGokixMSfKDOfqkwAAAkI"]
[Tue Jul 21 08:35:50.367722 2026] [security2:error] [pid 466512:tid 466676] [client 20.220.225.223:50290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.radiantus.online"] [uri "/ms.php"] [unique_id "al9ZliKGokixMSfKDOfqmwAAAjY"]
[Tue Jul 21 08:35:50.452908 2026] [security2:error] [pid 466512:tid 466730] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZliKGokixMSfKDOfqlwACbA0"]
[Tue Jul 21 08:35:50.453415 2026] [security2:error] [pid 465652:tid 465802] [client 20.220.225.223:34741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/hp2.php"] [unique_id "al9ZljzTqJoBC2Mw28_GqgAAAJk"]
[Tue Jul 21 08:35:50.587609 2026] [security2:error] [pid 465652:tid 465803] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9ZljzTqJoBC2Mw28_GsAAAAJo"]
[Tue Jul 21 08:35:50.756628 2026] [security2:error] [pid 466512:tid 466745] [client 103.151.46.103:54474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZliKGokixMSfKDOfqpwAAAns"]
[Tue Jul 21 08:35:50.758269 2026] [security2:error] [pid 466512:tid 466745] [client 103.151.46.103:54474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZliKGokixMSfKDOfqpwAAAns"]
[Tue Jul 21 08:35:50.955323 2026] [security2:error] [pid 466512:tid 466764] [client 173.252.95.29:45280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ZliKGokixMSfKDOfqqQAAAo4"]
[Tue Jul 21 08:35:50.990992 2026] [security2:error] [pid 466512:tid 466711] [client 20.151.10.161:65527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/f900.php"] [unique_id "al9ZliKGokixMSfKDOfqqwAAAlk"]
[Tue Jul 21 08:35:51.036016 2026] [security2:error] [pid 465652:tid 465883] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZljzTqJoBC2Mw28_GrwAAAOo"]
[Tue Jul 21 08:35:51.056231 2026] [security2:error] [pid 466512:tid 466735] [client 5.38.115.39:27535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZlyKGokixMSfKDOfqrwAAAnE"]
[Tue Jul 21 08:35:51.056338 2026] [security2:error] [pid 466512:tid 466735] [client 5.38.115.39:27535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZlyKGokixMSfKDOfqrwAAAnE"]
[Tue Jul 21 08:35:51.407586 2026] [core:error] [pid 466512:tid 466691] [client 66.249.66.5:44303] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:35:51.407610 2026] [core:error] [pid 466512:tid 466691] [client 66.249.66.5:44303] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:35:51.901440 2026] [security2:error] [pid 465652:tid 465881] [client 20.206.105.145:22227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/155.php"] [unique_id "al9ZlzzTqJoBC2Mw28_GxAAAAOg"]
[Tue Jul 21 08:35:51.959204 2026] [security2:error] [pid 466512:tid 466695] [client 20.151.10.161:63743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/xmrl.php"] [unique_id "al9ZlyKGokixMSfKDOfqvgAAAkk"]
[Tue Jul 21 08:35:52.062865 2026] [security2:error] [pid 465652:tid 465811] [client 20.206.105.145:38943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp.php"] [unique_id "al9ZmDzTqJoBC2Mw28_GyQAAAKI"]
[Tue Jul 21 08:35:52.363526 2026] [security2:error] [pid 465652:tid 465901] [client 14.245.224.124:64875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZmDzTqJoBC2Mw28_GzQAAAPw"]
[Tue Jul 21 08:35:52.363681 2026] [security2:error] [pid 465652:tid 465901] [client 14.245.224.124:64875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZmDzTqJoBC2Mw28_GzQAAAPw"]
[Tue Jul 21 08:35:52.512219 2026] [security2:error] [pid 466512:tid 466655] [client 20.151.10.161:65473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/memberfuns.php"] [unique_id "al9ZmCKGokixMSfKDOfq1gAAAiE"]
[Tue Jul 21 08:35:52.590179 2026] [security2:error] [pid 466512:tid 466676] [client 31.57.219.92:41032] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "novoar.net.br"] [uri "/"] [unique_id "al9ZmCKGokixMSfKDOfq3AAAAjY"]
[Tue Jul 21 08:35:52.770476 2026] [security2:error] [pid 465652:tid 465875] [client 152.59.34.51:51596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZmDzTqJoBC2Mw28_G4AAAAOI"]
[Tue Jul 21 08:35:52.770589 2026] [security2:error] [pid 465652:tid 465875] [client 152.59.34.51:51596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZmDzTqJoBC2Mw28_G4AAAAOI"]
[Tue Jul 21 08:35:52.829186 2026] [security2:error] [pid 466512:tid 466728] [client 20.151.10.161:65493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/ms.php"] [unique_id "al9ZmCKGokixMSfKDOfrAAAAAmo"]
[Tue Jul 21 08:35:52.933138 2026] [security2:error] [pid 466512:tid 466669] [client 49.144.66.253:31396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZmCKGokixMSfKDOfrBwAAAi8"]
[Tue Jul 21 08:35:52.933248 2026] [security2:error] [pid 466512:tid 466669] [client 49.144.66.253:31396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZmCKGokixMSfKDOfrBwAAAi8"]
[Tue Jul 21 08:35:53.014240 2026] [security2:error] [pid 466512:tid 466687] [client 109.248.148.246:55578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9ZmSKGokixMSfKDOfrCwAAAkE"]
[Tue Jul 21 08:35:53.014345 2026] [security2:error] [pid 466512:tid 466687] [client 109.248.148.246:55578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9ZmSKGokixMSfKDOfrCwAAAkE"]
[Tue Jul 21 08:35:53.108084 2026] [fcgid:warn] [pid 466512:tid 466665] (70014)End of file found: [client 45.79.207.252:53048] mod_fcgid: can't get data from http client
[Tue Jul 21 08:35:53.160811 2026] [security2:error] [pid 465652:tid 465851] [client 20.151.10.161:63045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/zz.php"] [unique_id "al9ZmTzTqJoBC2Mw28_G6gAAAMo"]
[Tue Jul 21 08:35:53.419765 2026] [security2:error] [pid 466512:tid 466670] [client 20.206.105.145:39263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/abcd.php"] [unique_id "al9ZmSKGokixMSfKDOfrFgAAAjA"]
[Tue Jul 21 08:35:53.537662 2026] [security2:error] [pid 466512:tid 466646] [client 20.151.10.161:63650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/for.php"] [unique_id "al9ZmSKGokixMSfKDOfrGQAAAhg"]
[Tue Jul 21 08:35:53.613891 2026] [security2:error] [pid 465652:tid 465850] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZmTzTqJoBC2Mw28_G5wAAAMk"]
[Tue Jul 21 08:35:53.828142 2026] [security2:error] [pid 466512:tid 466647] [client 20.151.10.161:65454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/yup.php"] [unique_id "al9ZmSKGokixMSfKDOfrJgAAAhk"]
[Tue Jul 21 08:35:53.935149 2026] [security2:error] [pid 466512:tid 466648] [client 74.249.245.134:42283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/css.php"] [unique_id "al9ZmSKGokixMSfKDOfrPgAAAho"]
[Tue Jul 21 08:35:54.014667 2026] [security2:error] [pid 466512:tid 466746] [client 20.206.105.145:38963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/a1.php"] [unique_id "al9ZmiKGokixMSfKDOfrQQAAAnw"]
[Tue Jul 21 08:35:54.108965 2026] [security2:error] [pid 466512:tid 466663] [client 20.220.225.223:20910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/hp3.php"] [unique_id "al9ZmiKGokixMSfKDOfrTQAAAik"]
[Tue Jul 21 08:35:54.165828 2026] [security2:error] [pid 465652:tid 465905] [client 20.151.10.161:63687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/wpxml.php"] [unique_id "al9ZmjzTqJoBC2Mw28_HEgAAAQA"]
[Tue Jul 21 08:35:54.455374 2026] [security2:error] [pid 465652:tid 465901] [client 20.151.10.161:65435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/fffm.php"] [unique_id "al9ZmjzTqJoBC2Mw28_HFwAAAPw"]
[Tue Jul 21 08:35:54.770477 2026] [security2:error] [pid 466512:tid 466665] [client 20.151.10.161:65490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/gecko.php"] [unique_id "al9ZmiKGokixMSfKDOfrbgAAAis"]
[Tue Jul 21 08:35:54.822863 2026] [security2:error] [pid 466512:tid 466701] [client 20.206.105.145:38965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9ZmiKGokixMSfKDOfrbwAAAk8"]
[Tue Jul 21 08:35:55.047524 2026] [security2:error] [pid 466512:tid 466646] [client 74.7.244.54:52554] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "milhasexpresso.com"] [uri "/index.php"] [unique_id "al9ZmiKGokixMSfKDOfrZgACGH4"]
[Tue Jul 21 08:35:55.050098 2026] [security2:error] [pid 466512:tid 466718] [client 20.151.10.161:63084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/a1.php"] [unique_id "al9ZmyKGokixMSfKDOfrcQAAAmA"]
[Tue Jul 21 08:35:55.199394 2026] [security2:error] [pid 465652:tid 465875] [client 195.49.128.211:51645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZmzzTqJoBC2Mw28_HJQAAAOI"]
[Tue Jul 21 08:35:55.199567 2026] [security2:error] [pid 465652:tid 465875] [client 195.49.128.211:51645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZmzzTqJoBC2Mw28_HJQAAAOI"]
[Tue Jul 21 08:35:55.340489 2026] [security2:error] [pid 466512:tid 466651] [client 20.151.10.161:65414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/k2.php"] [unique_id "al9ZmyKGokixMSfKDOfrdgAAAh0"]
[Tue Jul 21 08:35:55.363594 2026] [proxy:error] [pid 465652:tid 465851] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:55.363645 2026] [proxy_http:error] [pid 465652:tid 465851] [client 147.185.132.42:62732] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:55.364581 2026] [proxy:error] [pid 465652:tid 465851] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:55.364628 2026] [proxy_http:error] [pid 465652:tid 465851] [client 147.185.132.42:62732] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:55.621666 2026] [security2:error] [pid 466512:tid 466755] [client 20.151.10.161:63740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/82.php"] [unique_id "al9ZmyKGokixMSfKDOfreAAAAoU"]
[Tue Jul 21 08:35:55.723257 2026] [security2:error] [pid 465652:tid 465817] [client 122.176.100.127:63094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZmzzTqJoBC2Mw28_HLQAAAKg"]
[Tue Jul 21 08:35:55.723354 2026] [security2:error] [pid 465652:tid 465817] [client 122.176.100.127:63094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZmzzTqJoBC2Mw28_HLQAAAKg"]
[Tue Jul 21 08:35:55.763681 2026] [security2:error] [pid 466512:tid 466684] [client 20.220.225.223:20868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/aa1.php"] [unique_id "al9ZmyKGokixMSfKDOfrfgAAAj4"]
[Tue Jul 21 08:35:55.928713 2026] [security2:error] [pid 466512:tid 466645] [client 20.151.10.161:63627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/config.json.php"] [unique_id "al9ZmyKGokixMSfKDOfrgQAAAhc"]
[Tue Jul 21 08:35:56.052109 2026] [security2:error] [pid 465652:tid 465889] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZmzzTqJoBC2Mw28_HKwAAAPA"]
[Tue Jul 21 08:35:56.224299 2026] [security2:error] [pid 466512:tid 466675] [client 20.151.10.161:65421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.chaveiroportao.com.br"] [uri "/fpwch.php"] [unique_id "al9ZnCKGokixMSfKDOfrgwAAAjU"]
[Tue Jul 21 08:35:56.351638 2026] [proxy:error] [pid 465652:tid 465898] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:56.351746 2026] [proxy_http:error] [pid 465652:tid 465898] [client 20.206.105.145:38964] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:56.354005 2026] [proxy:error] [pid 465652:tid 465898] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:56.354174 2026] [proxy_http:error] [pid 465652:tid 465898] [client 20.206.105.145:38964] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:56.366582 2026] [security2:error] [pid 466512:tid 466751] [client 103.59.206.240:37202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZnCKGokixMSfKDOfrhgAAAoE"]
[Tue Jul 21 08:35:56.366729 2026] [security2:error] [pid 466512:tid 466751] [client 103.59.206.240:37202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZnCKGokixMSfKDOfrhgAAAoE"]
[Tue Jul 21 08:35:56.578657 2026] [security2:error] [pid 466512:tid 466687] [client 74.249.245.134:52276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/php.php"] [unique_id "al9ZnCKGokixMSfKDOfrhwAAAkE"]
[Tue Jul 21 08:35:56.593588 2026] [proxy:error] [pid 465652:tid 465785] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:56.593670 2026] [proxy_http:error] [pid 465652:tid 465785] [client 20.206.105.145:38971] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:56.594708 2026] [proxy:error] [pid 465652:tid 465785] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:56.594758 2026] [proxy_http:error] [pid 465652:tid 465785] [client 20.206.105.145:38971] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:56.800432 2026] [proxy:error] [pid 465652:tid 465881] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:56.800483 2026] [proxy_http:error] [pid 465652:tid 465881] [client 20.206.105.145:39154] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:56.800928 2026] [proxy:error] [pid 465652:tid 465881] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:56.800951 2026] [proxy_http:error] [pid 465652:tid 465881] [client 20.206.105.145:39154] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:56.814230 2026] [security2:error] [pid 465652:tid 465902] [client 202.179.75.202:49836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZnDzTqJoBC2Mw28_HSQAAAP0"]
[Tue Jul 21 08:35:56.814423 2026] [security2:error] [pid 465652:tid 465902] [client 202.179.75.202:49836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZnDzTqJoBC2Mw28_HSQAAAP0"]
[Tue Jul 21 08:35:56.927244 2026] [security2:error] [pid 466512:tid 466729] [client 20.206.105.145:39014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9ZnCKGokixMSfKDOfriQAAAms"]
[Tue Jul 21 08:35:57.258025 2026] [security2:error] [pid 466512:tid 466712] [client 20.206.105.145:39253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/gettest.php"] [unique_id "al9ZnSKGokixMSfKDOfrkAAAAlo"]
[Tue Jul 21 08:35:57.638256 2026] [security2:error] [pid 466512:tid 466714] [client 117.213.202.34:57718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZnSKGokixMSfKDOfrmwAAAlw"]
[Tue Jul 21 08:35:57.638411 2026] [security2:error] [pid 466512:tid 466714] [client 117.213.202.34:57718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZnSKGokixMSfKDOfrmwAAAlw"]
[Tue Jul 21 08:35:57.892991 2026] [security2:error] [pid 465652:tid 465862] [client 89.238.167.134:46652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9ZnTzTqJoBC2Mw28_HYAAAANU"]
[Tue Jul 21 08:35:57.893066 2026] [security2:error] [pid 465652:tid 465862] [client 89.238.167.134:46652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9ZnTzTqJoBC2Mw28_HYAAAANU"]
[Tue Jul 21 08:35:57.893765 2026] [proxy:error] [pid 465652:tid 465871] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:57.893826 2026] [proxy_http:error] [pid 465652:tid 465871] [client 20.206.105.145:38967] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:57.894468 2026] [proxy:error] [pid 465652:tid 465871] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:35:57.894490 2026] [proxy_http:error] [pid 465652:tid 465871] [client 20.206.105.145:38967] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:35:58.062924 2026] [security2:error] [pid 466512:tid 466667] [client 20.220.225.223:34747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/acew67.php"] [unique_id "al9ZniKGokixMSfKDOfroAAAAi0"]
[Tue Jul 21 08:35:58.392796 2026] [security2:error] [pid 465652:tid 465831] [client 20.206.105.145:39289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/simple.php"] [unique_id "al9ZnjzTqJoBC2Mw28_HaAAAALY"]
[Tue Jul 21 08:35:58.410292 2026] [security2:error] [pid 465652:tid 465760] [remote 72.167.132.114:46156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fisiopelvicafloripa.com.br"] [uri "/wp-login.php"] [unique_id "al9ZnjzTqJoBC2Mw28_HaQAA5ms"]
[Tue Jul 21 08:35:58.592999 2026] [security2:error] [pid 465652:tid 465810] [client 74.249.245.134:52286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/aa.php"] [unique_id "al9ZnjzTqJoBC2Mw28_HbgAAAKE"]
[Tue Jul 21 08:35:58.627196 2026] [security2:error] [pid 465652:tid 465864] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZnjzTqJoBC2Mw28_HYgAAANc"]
[Tue Jul 21 08:35:58.685124 2026] [security2:error] [pid 465652:tid 465849] [client 187.125.243.197:59556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZnjzTqJoBC2Mw28_HeQAAAMg"]
[Tue Jul 21 08:35:58.685500 2026] [security2:error] [pid 465652:tid 465849] [client 187.125.243.197:59556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZnjzTqJoBC2Mw28_HeQAAAMg"]
[Tue Jul 21 08:35:58.897948 2026] [security2:error] [pid 466512:tid 466664] [client 173.252.95.42:48358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ZniKGokixMSfKDOfrwwAAAio"]
[Tue Jul 21 08:35:59.023578 2026] [security2:error] [pid 465652:tid 465796] [client 223.181.60.88:14315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZnzzTqJoBC2Mw28_HkAAAAJM"]
[Tue Jul 21 08:35:59.023880 2026] [security2:error] [pid 465652:tid 465796] [client 223.181.60.88:14315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZnzzTqJoBC2Mw28_HkAAAAJM"]
[Tue Jul 21 08:35:59.106624 2026] [security2:error] [pid 466512:tid 466648] [client 20.220.225.223:20930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/bscclapb.php"] [unique_id "al9ZnyKGokixMSfKDOfr2wAAAho"]
[Tue Jul 21 08:35:59.451388 2026] [security2:error] [pid 466512:tid 466673] [client 20.206.105.145:39147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xxx.php"] [unique_id "al9ZnyKGokixMSfKDOfr3wAAAjM"]
[Tue Jul 21 08:35:59.454677 2026] [security2:error] [pid 466512:tid 466668] [client 195.49.128.211:59553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZnyKGokixMSfKDOfr4AAAAi4"]
[Tue Jul 21 08:35:59.454788 2026] [security2:error] [pid 466512:tid 466668] [client 195.49.128.211:59553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZnyKGokixMSfKDOfr4AAAAi4"]
[Tue Jul 21 08:35:59.810973 2026] [security2:error] [pid 465652:tid 465676] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZnzzTqJoBC2Mw28_HnQAAvRc"]
[Tue Jul 21 08:35:59.811136 2026] [security2:error] [pid 465652:tid 465838] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZnzzTqJoBC2Mw28_HnQAAvRc"]
[Tue Jul 21 08:35:59.852902 2026] [security2:error] [pid 466512:tid 466529] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZnyKGokixMSfKDOfr5QACPhA"]
[Tue Jul 21 08:35:59.853068 2026] [security2:error] [pid 466512:tid 466684] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZnyKGokixMSfKDOfr5QACPhA"]
[Tue Jul 21 08:35:59.870512 2026] [security2:error] [pid 466512:tid 466642] [client 20.206.105.145:39239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/hypo.php"] [unique_id "al9ZnyKGokixMSfKDOfr5gAAAhQ"]
[Tue Jul 21 08:36:00.235565 2026] [security2:error] [pid 466512:tid 466742] [client 20.226.60.151:64008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9ZoCKGokixMSfKDOfsCQAAAng"]
[Tue Jul 21 08:36:00.288759 2026] [security2:error] [pid 465652:tid 465850] [client 20.220.225.223:34710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/else1.php"] [unique_id "al9ZoDzTqJoBC2Mw28_HswAAAMk"]
[Tue Jul 21 08:36:00.295365 2026] [security2:error] [pid 465652:tid 465890] [client 74.249.245.134:42075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/bolt.php"] [unique_id "al9ZoDzTqJoBC2Mw28_HtAAAAPE"]
[Tue Jul 21 08:36:00.439898 2026] [security2:error] [pid 466512:tid 466674] [client 20.226.60.151:64096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9ZoCKGokixMSfKDOfsLAAAAjQ"]
[Tue Jul 21 08:36:00.506487 2026] [security2:error] [pid 466512:tid 466650] [client 20.226.60.151:64109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/xyn.php"] [unique_id "al9ZoCKGokixMSfKDOfsMwAAAhw"]
[Tue Jul 21 08:36:00.584520 2026] [proxy:error] [pid 466512:tid 466720] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:36:00.584583 2026] [proxy_http:error] [pid 466512:tid 466720] [client 20.206.105.145:39251] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:36:00.585043 2026] [proxy:error] [pid 466512:tid 466720] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:36:00.585068 2026] [proxy_http:error] [pid 466512:tid 466720] [client 20.206.105.145:39251] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:36:00.635490 2026] [security2:error] [pid 465652:tid 465830] [client 20.206.105.145:39131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/chosen.php"] [unique_id "al9ZoDzTqJoBC2Mw28_HygAAALU"]
[Tue Jul 21 08:36:00.708608 2026] [proxy:error] [pid 466512:tid 466673] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:36:00.708687 2026] [proxy_http:error] [pid 466512:tid 466673] [client 20.206.105.145:38982] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:36:00.709306 2026] [proxy:error] [pid 466512:tid 466673] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:36:00.709335 2026] [proxy_http:error] [pid 466512:tid 466673] [client 20.206.105.145:38982] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:36:00.742159 2026] [security2:error] [pid 465652:tid 465903] [client 20.206.105.145:39134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/als.php"] [unique_id "al9ZoDzTqJoBC2Mw28_HzwAAAP4"]
[Tue Jul 21 08:36:00.744049 2026] [security2:error] [pid 465652:tid 465818] [client 20.226.60.151:64020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/patie.php"] [unique_id "al9ZoDzTqJoBC2Mw28_H0AAAAKk"]
[Tue Jul 21 08:36:00.744204 2026] [security2:error] [pid 466512:tid 466630] [remote 199.189.225.40:44009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zooparquevet.com.br"] [uri "/wp-login.php"] [unique_id "al9ZoCKGokixMSfKDOfsSwACGHU"]
[Tue Jul 21 08:36:00.882364 2026] [security2:error] [pid 466512:tid 466653] [client 20.206.105.145:21974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/ppp.php"] [unique_id "al9ZoCKGokixMSfKDOfsUgAAAh8"]
[Tue Jul 21 08:36:00.906319 2026] [security2:error] [pid 466512:tid 466737] [client 20.206.105.145:39145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/pol.php"] [unique_id "al9ZoCKGokixMSfKDOfsUwAAAnM"]
[Tue Jul 21 08:36:00.960379 2026] [security2:error] [pid 465652:tid 465844] [client 20.206.105.145:38958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file5.php"] [unique_id "al9ZoDzTqJoBC2Mw28_H3gAAAMM"]
[Tue Jul 21 08:36:01.001992 2026] [security2:error] [pid 465652:tid 465804] [client 20.206.105.145:39137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9ZoTzTqJoBC2Mw28_H3wAAAJs"]
[Tue Jul 21 08:36:01.017533 2026] [security2:error] [pid 466512:tid 466734] [client 20.206.105.145:39151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file.php"] [unique_id "al9ZoSKGokixMSfKDOfsVwAAAnA"]
[Tue Jul 21 08:36:01.042540 2026] [security2:error] [pid 465652:tid 465840] [client 20.206.105.145:39143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/cfile.php"] [unique_id "al9ZoTzTqJoBC2Mw28_H4wAAAL8"]
[Tue Jul 21 08:36:01.073910 2026] [security2:error] [pid 465652:tid 465696] [remote 114.119.134.48:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.academiausina.com.br"] [uri "/about/"] [unique_id "al9ZoTzTqJoBC2Mw28_H5gAAkSs"], referer: https://www.academiausina.com.br/pricing/
[Tue Jul 21 08:36:01.086929 2026] [security2:error] [pid 465652:tid 465856] [client 20.206.105.145:39138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/class-wp.php"] [unique_id "al9ZoTzTqJoBC2Mw28_H5wAAAM8"]
[Tue Jul 21 08:36:01.114848 2026] [security2:error] [pid 465652:tid 465799] [client 20.206.105.145:39133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/admin.php"] [unique_id "al9ZoTzTqJoBC2Mw28_H6AAAAJY"]
[Tue Jul 21 08:36:01.139738 2026] [security2:error] [pid 466512:tid 466674] [client 20.206.105.145:39135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/aa2.php"] [unique_id "al9ZoSKGokixMSfKDOfsWwAAAjQ"]
[Tue Jul 21 08:36:01.157400 2026] [security2:error] [pid 466512:tid 466687] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZoSKGokixMSfKDOfsWAACQRU"]
[Tue Jul 21 08:36:01.207920 2026] [security2:error] [pid 466512:tid 466643] [client 20.206.105.145:39166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/ccou.php"] [unique_id "al9ZoSKGokixMSfKDOfsXQAAAhU"]
[Tue Jul 21 08:36:01.215728 2026] [security2:error] [pid 465652:tid 465843] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZoDzTqJoBC2Mw28_H1gAAAMI"]
[Tue Jul 21 08:36:01.279234 2026] [security2:error] [pid 465652:tid 465851] [client 20.206.105.145:38937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/dr.php"] [unique_id "al9ZoTzTqJoBC2Mw28_H6gAAAMo"]
[Tue Jul 21 08:36:01.367595 2026] [security2:error] [pid 466512:tid 466650] [client 20.220.225.223:20931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/tkikikoko.php"] [unique_id "al9ZoSKGokixMSfKDOfsXgAAAhw"]
[Tue Jul 21 08:36:01.459271 2026] [security2:error] [pid 466512:tid 466663] [client 20.206.105.145:38944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xamp.php"] [unique_id "al9ZoSKGokixMSfKDOfsYgAAAik"]
[Tue Jul 21 08:36:01.501060 2026] [security2:error] [pid 466512:tid 466685] [client 20.206.105.145:39155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/bless.php"] [unique_id "al9ZoSKGokixMSfKDOfsYwAAAj8"]
[Tue Jul 21 08:36:01.600349 2026] [security2:error] [pid 466512:tid 466695] [client 20.206.105.145:38953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file46.php"] [unique_id "al9ZoSKGokixMSfKDOfsZgAAAkk"]
[Tue Jul 21 08:36:01.616999 2026] [security2:error] [pid 465652:tid 465837] [client 103.151.46.103:54976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZoTzTqJoBC2Mw28_H9AAAALw"]
[Tue Jul 21 08:36:01.617503 2026] [security2:error] [pid 465652:tid 465837] [client 103.151.46.103:54976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZoTzTqJoBC2Mw28_H9AAAALw"]
[Tue Jul 21 08:36:01.727889 2026] [security2:error] [pid 466512:tid 466760] [client 5.38.115.39:18943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZoSKGokixMSfKDOfsaQAAAoo"]
[Tue Jul 21 08:36:01.728026 2026] [security2:error] [pid 466512:tid 466760] [client 5.38.115.39:18943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZoSKGokixMSfKDOfsaQAAAoo"]
[Tue Jul 21 08:36:01.941626 2026] [security2:error] [pid 466512:tid 466761] [client 74.249.245.134:45680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/x.php"] [unique_id "al9ZoSKGokixMSfKDOfscAAAAos"]
[Tue Jul 21 08:36:02.249080 2026] [security2:error] [pid 466512:tid 466744] [client 173.252.95.15:61708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ZoiKGokixMSfKDOfsfQAAAno"]
[Tue Jul 21 08:36:02.612207 2026] [security2:error] [pid 466512:tid 466662] [client 20.206.105.145:39011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/eee.php"] [unique_id "al9ZoiKGokixMSfKDOfsgQAAAig"]
[Tue Jul 21 08:36:02.660867 2026] [security2:error] [pid 465652:tid 465664] [remote 46.105.28.235:37186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ZojzTqJoBC2Mw28_IBgAArQs"]
[Tue Jul 21 08:36:02.708469 2026] [security2:error] [pid 466512:tid 466751] [client 20.220.225.223:20888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9ZoiKGokixMSfKDOfshgAAAoE"]
[Tue Jul 21 08:36:03.084545 2026] [security2:error] [pid 465652:tid 465820] [client 20.226.60.151:64089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/aa.php"] [unique_id "al9ZozzTqJoBC2Mw28_ICAAAAKs"]
[Tue Jul 21 08:36:03.122028 2026] [security2:error] [pid 466512:tid 466642] [client 14.245.224.124:65347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZoyKGokixMSfKDOfsiwAAAhQ"]
[Tue Jul 21 08:36:03.122145 2026] [security2:error] [pid 466512:tid 466642] [client 14.245.224.124:65347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZoyKGokixMSfKDOfsiwAAAhQ"]
[Tue Jul 21 08:36:03.393692 2026] [security2:error] [pid 465652:tid 465783] [client 5.31.193.106:29969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZozzTqJoBC2Mw28_IDgAAAIY"]
[Tue Jul 21 08:36:03.393857 2026] [security2:error] [pid 465652:tid 465783] [client 5.31.193.106:29969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZozzTqJoBC2Mw28_IDgAAAIY"]
[Tue Jul 21 08:36:03.449138 2026] [security2:error] [pid 466512:tid 466644] [client 152.59.34.51:52077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZoyKGokixMSfKDOfskwAAAhY"]
[Tue Jul 21 08:36:03.449296 2026] [security2:error] [pid 466512:tid 466644] [client 152.59.34.51:52077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZoyKGokixMSfKDOfskwAAAhY"]
[Tue Jul 21 08:36:03.699121 2026] [security2:error] [pid 465652:tid 465799] [client 74.249.245.134:55909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/jga.php"] [unique_id "al9ZozzTqJoBC2Mw28_IGQAAAJY"]
[Tue Jul 21 08:36:03.780192 2026] [security2:error] [pid 466512:tid 466712] [client 49.144.66.253:31549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZoyKGokixMSfKDOfslgAAAlo"]
[Tue Jul 21 08:36:03.780345 2026] [security2:error] [pid 466512:tid 466712] [client 49.144.66.253:31549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZoyKGokixMSfKDOfslgAAAlo"]
[Tue Jul 21 08:36:03.830617 2026] [security2:error] [pid 465652:tid 465800] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZozzTqJoBC2Mw28_IDQAAAJc"]
[Tue Jul 21 08:36:04.110760 2026] [security2:error] [pid 466512:tid 466533] [remote 45.79.123.44:60984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "precisosolucao.com.br"] [uri "/wp-login.php"] [unique_id "al9ZpCKGokixMSfKDOfsmAACYBQ"]
[Tue Jul 21 08:36:04.323410 2026] [security2:error] [pid 465652:tid 465845] [client 20.206.105.145:21973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/201.php"] [unique_id "al9ZpDzTqJoBC2Mw28_IJgAAAMQ"]
[Tue Jul 21 08:36:04.349640 2026] [security2:error] [pid 466512:tid 466759] [client 20.206.105.145:38991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file25.php"] [unique_id "al9ZpCKGokixMSfKDOfsnQAAAok"]
[Tue Jul 21 08:36:04.588293 2026] [security2:error] [pid 465652:tid 465903] [client 20.220.225.223:20885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/wp-css.php"] [unique_id "al9ZpDzTqJoBC2Mw28_IKAAAAP4"]
[Tue Jul 21 08:36:05.053089 2026] [security2:error] [pid 466512:tid 466648] [client 20.206.105.145:38977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file48.php"] [unique_id "al9ZpSKGokixMSfKDOftCQAAAho"]
[Tue Jul 21 08:36:05.074455 2026] [security2:error] [pid 465652:tid 465907] [client 61.1.167.83:62315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZpTzTqJoBC2Mw28_ILgAAAQI"]
[Tue Jul 21 08:36:05.076911 2026] [security2:error] [pid 465652:tid 465907] [client 61.1.167.83:62315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZpTzTqJoBC2Mw28_ILgAAAQI"]
[Tue Jul 21 08:36:05.365742 2026] [security2:error] [pid 466512:tid 466728] [client 20.220.225.223:42756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/wp-explorer.php"] [unique_id "al9ZpSKGokixMSfKDOftIAAAAmo"]
[Tue Jul 21 08:36:05.592238 2026] [security2:error] [pid 466512:tid 466734] [client 74.249.245.134:51836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/k.php"] [unique_id "al9ZpSKGokixMSfKDOftJgAAAnA"]
[Tue Jul 21 08:36:05.877649 2026] [security2:error] [pid 465652:tid 465832] [client 195.49.128.211:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZpTzTqJoBC2Mw28_IPQAAALc"]
[Tue Jul 21 08:36:05.877776 2026] [security2:error] [pid 465652:tid 465832] [client 195.49.128.211:52256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZpTzTqJoBC2Mw28_IPQAAALc"]
[Tue Jul 21 08:36:05.982168 2026] [security2:error] [pid 465652:tid 465848] [client 103.59.206.240:31041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZpTzTqJoBC2Mw28_IQAAAAMc"]
[Tue Jul 21 08:36:05.982299 2026] [security2:error] [pid 465652:tid 465848] [client 103.59.206.240:31041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZpTzTqJoBC2Mw28_IQAAAAMc"]
[Tue Jul 21 08:36:06.004140 2026] [security2:error] [pid 466512:tid 466670] [client 74.7.228.58:56160] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "piskefotografia.com.solucoesdeti.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9ZpSKGokixMSfKDOftNQACMHs"]
[Tue Jul 21 08:36:06.023756 2026] [security2:error] [pid 466512:tid 466679] [client 20.206.105.145:39254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file6.php"] [unique_id "al9ZpiKGokixMSfKDOftNgAAAjk"]
[Tue Jul 21 08:36:06.077676 2026] [security2:error] [pid 465652:tid 465873] [client 20.226.60.151:64106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/xwpg.php"] [unique_id "al9ZpjzTqJoBC2Mw28_IQQAAAOA"]
[Tue Jul 21 08:36:06.160653 2026] [security2:error] [pid 466512:tid 466667] [client 122.176.100.127:63608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZpiKGokixMSfKDOftOgAAAi0"]
[Tue Jul 21 08:36:06.160843 2026] [security2:error] [pid 466512:tid 466667] [client 122.176.100.127:63608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZpiKGokixMSfKDOftOgAAAi0"]
[Tue Jul 21 08:36:06.276247 2026] [security2:error] [pid 466512:tid 466674] [client 152.59.181.104:49553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZpiKGokixMSfKDOftOwAAAjQ"]
[Tue Jul 21 08:36:06.276466 2026] [security2:error] [pid 466512:tid 466674] [client 152.59.181.104:49553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZpiKGokixMSfKDOftOwAAAjQ"]
[Tue Jul 21 08:36:06.323666 2026] [security2:error] [pid 466512:tid 466721] [client 81.171.72.135:47258] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/"] [unique_id "al9ZpiKGokixMSfKDOftPAAAAmM"]
[Tue Jul 21 08:36:06.324409 2026] [security2:error] [pid 465652:tid 465856] [client 81.171.72.135:47256] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/"] [unique_id "al9ZpjzTqJoBC2Mw28_IRgAAAM8"]
[Tue Jul 21 08:36:06.325029 2026] [security2:error] [pid 465652:tid 465866] [client 81.171.72.135:47266] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/"] [unique_id "al9ZpjzTqJoBC2Mw28_IRwAAANk"]
[Tue Jul 21 08:36:06.393865 2026] [security2:error] [pid 465652:tid 465806] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZpTzTqJoBC2Mw28_IPgAAAJ0"]
[Tue Jul 21 08:36:06.630185 2026] [security2:error] [pid 465652:tid 465871] [client 20.206.105.145:39167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/a2.php"] [unique_id "al9ZpjzTqJoBC2Mw28_IUAAAAN4"]
[Tue Jul 21 08:36:07.301622 2026] [security2:error] [pid 466512:tid 466690] [client 81.171.72.135:47304] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9ZpyKGokixMSfKDOftRgAAAkQ"]
[Tue Jul 21 08:36:07.301622 2026] [security2:error] [pid 466512:tid 466707] [client 81.171.72.135:47276] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/.svn/wc.db"] [unique_id "al9ZpyKGokixMSfKDOftRwAAAlU"]
[Tue Jul 21 08:36:07.301938 2026] [security2:error] [pid 466512:tid 466660] [client 81.171.72.135:47318] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/database_backup.sql"] [unique_id "al9ZpyKGokixMSfKDOftSAAAAiY"]
[Tue Jul 21 08:36:07.350247 2026] [security2:error] [pid 465652:tid 465663] [remote 72.167.132.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexandrevitor1781543539748.0711679.meusitehostgator.com.br"] [uri "/wp-login.php"] [unique_id "al9ZpzzTqJoBC2Mw28_IZQAAmQo"]
[Tue Jul 21 08:36:07.622851 2026] [security2:error] [pid 466512:tid 466528] [remote 8.217.108.67:30458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/wp-login.php"] [unique_id "al9ZpyKGokixMSfKDOftTwACQA8"]
[Tue Jul 21 08:36:07.668072 2026] [security2:error] [pid 466512:tid 466737] [client 20.226.114.112:9280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oppbrazil.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9ZpyKGokixMSfKDOftUAAAAnM"]
[Tue Jul 21 08:36:07.695970 2026] [security2:error] [pid 466512:tid 466678] [client 20.226.114.112:9335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.114.226.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oppbrazil.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZpyKGokixMSfKDOftUQAAAjg"]
[Tue Jul 21 08:36:07.774248 2026] [security2:error] [pid 465652:tid 465862] [client 202.179.75.202:51690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZpzzTqJoBC2Mw28_IbAAAANU"]
[Tue Jul 21 08:36:07.774350 2026] [security2:error] [pid 465652:tid 465862] [client 202.179.75.202:51690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZpzzTqJoBC2Mw28_IbAAAANU"]
[Tue Jul 21 08:36:08.157192 2026] [security2:error] [pid 465652:tid 465799] [client 74.249.245.134:52240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/vx.php"] [unique_id "al9ZqDzTqJoBC2Mw28_IdQAAAJY"]
[Tue Jul 21 08:36:08.277334 2026] [security2:error] [pid 466512:tid 466740] [client 81.171.72.135:47380] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9ZqCKGokixMSfKDOftXAAAAnY"]
[Tue Jul 21 08:36:08.278795 2026] [security2:error] [pid 465652:tid 465804] [client 81.171.72.135:47330] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9ZqDzTqJoBC2Mw28_IdwAAAJs"]
[Tue Jul 21 08:36:08.279065 2026] [security2:error] [pid 466512:tid 466685] [client 81.171.72.135:47364] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/config.php"] [unique_id "al9ZqCKGokixMSfKDOftXQAAAj8"]
[Tue Jul 21 08:36:08.279945 2026] [security2:error] [pid 465652:tid 465899] [client 81.171.72.135:47328] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/backup.tar.gz"] [unique_id "al9ZqDzTqJoBC2Mw28_IeAAAAPo"]
[Tue Jul 21 08:36:08.341220 2026] [security2:error] [pid 465652:tid 465808] [client 20.206.105.145:38966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/file15.php"] [unique_id "al9ZqDzTqJoBC2Mw28_IewAAAJ8"]
[Tue Jul 21 08:36:08.347184 2026] [security2:error] [pid 466512:tid 466668] [client 117.213.202.34:58331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZqCKGokixMSfKDOftXwAAAi4"]
[Tue Jul 21 08:36:08.347458 2026] [security2:error] [pid 466512:tid 466668] [client 117.213.202.34:58331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZqCKGokixMSfKDOftXwAAAi4"]
[Tue Jul 21 08:36:08.403483 2026] [security2:error] [pid 465652:tid 465850] [client 20.226.60.151:64113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/ops.php"] [unique_id "al9ZqDzTqJoBC2Mw28_IfQAAAMk"]
[Tue Jul 21 08:36:08.480278 2026] [security2:error] [pid 465652:tid 465826] [client 81.171.72.135:47290] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/backup.zip"] [unique_id "al9ZqDzTqJoBC2Mw28_IgAAAALE"]
[Tue Jul 21 08:36:08.482534 2026] [security2:error] [pid 465652:tid 465801] [client 81.171.72.135:47350] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/dump.sql"] [unique_id "al9ZqDzTqJoBC2Mw28_IggAAAJg"]
[Tue Jul 21 08:36:08.482534 2026] [security2:error] [pid 465652:tid 465853] [client 81.171.72.135:47372] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9ZqDzTqJoBC2Mw28_IgQAAAMw"]
[Tue Jul 21 08:36:08.788750 2026] [security2:error] [pid 466512:tid 466625] [remote 162.19.246.208:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9ZqCKGokixMSfKDOftZwACNHA"]
[Tue Jul 21 08:36:08.813638 2026] [security2:error] [pid 466512:tid 466694] [client 20.206.105.145:21998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/ops.php"] [unique_id "al9ZqCKGokixMSfKDOftaAAAAkg"]
[Tue Jul 21 08:36:08.919953 2026] [security2:error] [pid 465652:tid 465851] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZqDzTqJoBC2Mw28_IfwAAAMo"]
[Tue Jul 21 08:36:09.117339 2026] [access_compat:error] [pid 466512:tid 466545] [remote 139.59.136.184:0] AH01797: client denied by server configuration: /home4/dralul00/deiacakes.com/server-status
[Tue Jul 21 08:36:09.251300 2026] [security2:error] [pid 466512:tid 466757] [client 81.171.72.135:47386] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/.env.production"] [unique_id "al9ZqSKGokixMSfKDOftcQAAAoc"]
[Tue Jul 21 08:36:09.254618 2026] [security2:error] [pid 466512:tid 466767] [client 81.171.72.135:47388] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/database.sql"] [unique_id "al9ZqSKGokixMSfKDOftcgAAApE"]
[Tue Jul 21 08:36:09.255228 2026] [security2:error] [pid 466512:tid 466707] [client 81.171.72.135:47438] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/backup.sql"] [unique_id "al9ZqSKGokixMSfKDOftcwAAAlU"]
[Tue Jul 21 08:36:09.255586 2026] [security2:error] [pid 465652:tid 465888] [client 81.171.72.135:47384] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9ZqTzTqJoBC2Mw28_IjgAAAO8"]
[Tue Jul 21 08:36:09.270228 2026] [security2:error] [pid 465652:tid 465882] [client 187.125.243.197:60066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZqTzTqJoBC2Mw28_IjwAAAOk"]
[Tue Jul 21 08:36:09.271471 2026] [security2:error] [pid 465652:tid 465882] [client 187.125.243.197:60066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZqTzTqJoBC2Mw28_IjwAAAOk"]
[Tue Jul 21 08:36:09.400373 2026] [security2:error] [pid 465652:tid 465898] [client 20.226.60.151:64033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/mac.php"] [unique_id "al9ZqTzTqJoBC2Mw28_IkgAAAPk"]
[Tue Jul 21 08:36:09.455311 2026] [security2:error] [pid 465652:tid 465813] [client 81.171.72.135:47400] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9ZqTzTqJoBC2Mw28_IlAAAAKQ"]
[Tue Jul 21 08:36:09.643449 2026] [security2:error] [pid 466512:tid 466769] [client 20.206.105.145:39149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/jp.php"] [unique_id "al9ZqSKGokixMSfKDOftegAAApM"]
[Tue Jul 21 08:36:09.866415 2026] [security2:error] [pid 466512:tid 466673] [client 20.226.114.112:12842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.114.226.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oppbrazil.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZqSKGokixMSfKDOftewAAAjM"]
[Tue Jul 21 08:36:09.866516 2026] [security2:error] [pid 466512:tid 466673] [client 20.226.114.112:12842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oppbrazil.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZqSKGokixMSfKDOftewAAAjM"]
[Tue Jul 21 08:36:09.876542 2026] [security2:error] [pid 466512:tid 466683] [client 89.238.167.134:53752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9ZqSKGokixMSfKDOftfAAAAj0"]
[Tue Jul 21 08:36:09.876696 2026] [security2:error] [pid 466512:tid 466683] [client 89.238.167.134:53752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9ZqSKGokixMSfKDOftfAAAAj0"]
[Tue Jul 21 08:36:09.880828 2026] [security2:error] [pid 465652:tid 465878] [client 20.220.225.223:34726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/akismet.php"] [unique_id "al9ZqTzTqJoBC2Mw28_ImwAAAOU"]
[Tue Jul 21 08:36:09.953853 2026] [security2:error] [pid 465652:tid 465796] [client 223.181.60.88:15667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZqTzTqJoBC2Mw28_IngAAAJM"]
[Tue Jul 21 08:36:09.953999 2026] [security2:error] [pid 465652:tid 465796] [client 223.181.60.88:15667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZqTzTqJoBC2Mw28_IngAAAJM"]
[Tue Jul 21 08:36:10.029674 2026] [security2:error] [pid 466512:tid 466685] [client 20.226.60.151:64064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/mg.php"] [unique_id "al9ZqiKGokixMSfKDOftfwAAAj8"]
[Tue Jul 21 08:36:10.036718 2026] [security2:error] [pid 466512:tid 466648] [client 195.49.128.211:60171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZqiKGokixMSfKDOftgAAAAho"]
[Tue Jul 21 08:36:10.036846 2026] [security2:error] [pid 466512:tid 466648] [client 195.49.128.211:60171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZqiKGokixMSfKDOftgAAAAho"]
[Tue Jul 21 08:36:10.233363 2026] [security2:error] [pid 465652:tid 465883] [client 81.171.72.135:47470] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/.git/HEAD"] [unique_id "al9ZqjzTqJoBC2Mw28_IoQAAAOo"]
[Tue Jul 21 08:36:10.233828 2026] [security2:error] [pid 466512:tid 466740] [client 81.171.72.135:47492] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/wp-config.php"] [unique_id "al9ZqiKGokixMSfKDOftgwAAAnY"]
[Tue Jul 21 08:36:10.234484 2026] [security2:error] [pid 465652:tid 465901] [client 81.171.72.135:47452] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/api/.env"] [unique_id "al9ZqjzTqJoBC2Mw28_IogAAAPw"]
[Tue Jul 21 08:36:10.234900 2026] [security2:error] [pid 466512:tid 466668] [client 81.171.72.135:47478] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/.env"] [unique_id "al9ZqiKGokixMSfKDOfthAAAAi4"]
[Tue Jul 21 08:36:10.271584 2026] [security2:error] [pid 465652:tid 465820] [client 74.249.245.134:43999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/ws77.php"] [unique_id "al9ZqjzTqJoBC2Mw28_IowAAAKs"]
[Tue Jul 21 08:36:10.336907 2026] [security2:error] [pid 466512:tid 466546] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZqiKGokixMSfKDOfthQACayE"]
[Tue Jul 21 08:36:10.338189 2026] [security2:error] [pid 466512:tid 466729] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZqiKGokixMSfKDOfthQACayE"]
[Tue Jul 21 08:36:10.434218 2026] [security2:error] [pid 466512:tid 466578] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZqiKGokixMSfKDOfthgACjUE"]
[Tue Jul 21 08:36:10.434411 2026] [security2:error] [pid 466512:tid 466763] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZqiKGokixMSfKDOfthgACjUE"]
[Tue Jul 21 08:36:10.436808 2026] [security2:error] [pid 466512:tid 466693] [client 81.171.72.135:47454] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/config.xml"] [unique_id "al9ZqiKGokixMSfKDOfthwAAAkc"]
[Tue Jul 21 08:36:10.518335 2026] [security2:error] [pid 466512:tid 466743] [client 20.220.225.223:20917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/ace2.php"] [unique_id "al9ZqiKGokixMSfKDOftiQAAAnk"]
[Tue Jul 21 08:36:10.575100 2026] [security2:error] [pid 466512:tid 466731] [client 20.226.60.151:64101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-post-data.php"] [unique_id "al9ZqiKGokixMSfKDOftigAAAm0"]
[Tue Jul 21 08:36:10.706347 2026] [security2:error] [pid 466512:tid 466738] [client 20.206.105.145:39005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/f35.php"] [unique_id "al9ZqiKGokixMSfKDOftjQAAAnQ"]
[Tue Jul 21 08:36:10.780350 2026] [security2:error] [pid 465652:tid 465852] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZqjzTqJoBC2Mw28_IpQAAAMs"]
[Tue Jul 21 08:36:10.938844 2026] [security2:error] [pid 466512:tid 466697] [client 103.151.46.103:55467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZqiKGokixMSfKDOftjgAAAks"]
[Tue Jul 21 08:36:10.938999 2026] [security2:error] [pid 466512:tid 466697] [client 103.151.46.103:55467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZqiKGokixMSfKDOftjgAAAks"]
[Tue Jul 21 08:36:10.943981 2026] [security2:error] [pid 465652:tid 465866] [client 20.226.60.151:64011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/pucci.php"] [unique_id "al9ZqjzTqJoBC2Mw28_IswAAANk"]
[Tue Jul 21 08:36:11.027624 2026] [security2:error] [pid 465652:tid 465799] [client 81.171.72.135:47546] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/phpinfo.php"] [unique_id "al9ZqzzTqJoBC2Mw28_ItgAAAJY"]
[Tue Jul 21 08:36:11.030071 2026] [security2:error] [pid 466512:tid 466680] [client 81.171.72.135:47506] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/actuator/heapdump"] [unique_id "al9ZqyKGokixMSfKDOftkQAAAjo"]
[Tue Jul 21 08:36:11.031989 2026] [security2:error] [pid 465652:tid 465909] [client 81.171.72.135:47534] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/user_secrets.yml"] [unique_id "al9ZqzzTqJoBC2Mw28_ItwAAAQQ"]
[Tue Jul 21 08:36:11.032464 2026] [security2:error] [pid 466512:tid 466646] [client 81.171.72.135:47522] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/docker-compose.yml"] [unique_id "al9ZqyKGokixMSfKDOftkgAAAhg"]
[Tue Jul 21 08:36:11.193582 2026] [security2:error] [pid 466512:tid 466669] [client 20.226.60.151:64086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/black.php"] [unique_id "al9ZqyKGokixMSfKDOftkwAAAi8"]
[Tue Jul 21 08:36:11.647427 2026] [security2:error] [pid 465652:tid 465855] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZqzzTqJoBC2Mw28_IwQAAzlk"]
[Tue Jul 21 08:36:11.801991 2026] [security2:error] [pid 466512:tid 466685] [client 20.206.105.145:38945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-load.php"] [unique_id "al9ZqyKGokixMSfKDOftnQAAAj8"]
[Tue Jul 21 08:36:11.854979 2026] [security2:error] [pid 466512:tid 466663] [client 20.206.105.145:22007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/ingfo.php"] [unique_id "al9ZqyKGokixMSfKDOftnwAAAik"]
[Tue Jul 21 08:36:11.999617 2026] [security2:error] [pid 465652:tid 465838] [client 81.171.72.135:47582] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/config/production.json"] [unique_id "al9ZqzzTqJoBC2Mw28_IyAAAAL0"]
[Tue Jul 21 08:36:11.999744 2026] [security2:error] [pid 466512:tid 466650] [client 81.171.72.135:47570] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9ZqyKGokixMSfKDOftpAAAAhw"]
[Tue Jul 21 08:36:11.999942 2026] [security2:error] [pid 466512:tid 466672] [client 81.171.72.135:47610] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/server.key"] [unique_id "al9ZqyKGokixMSfKDOftpQAAAjI"]
[Tue Jul 21 08:36:12.000255 2026] [security2:error] [pid 466512:tid 466768] [client 81.171.72.135:47572] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/.npmrc"] [unique_id "al9ZqyKGokixMSfKDOftpgAAApI"]
[Tue Jul 21 08:36:12.201997 2026] [security2:error] [pid 465652:tid 465831] [client 81.171.72.135:47594] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9ZrDzTqJoBC2Mw28_I0QAAALY"]
[Tue Jul 21 08:36:12.201997 2026] [security2:error] [pid 466512:tid 466654] [client 81.171.72.135:47616] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/secrets.json"] [unique_id "al9ZrCKGokixMSfKDOftqgAAAiA"]
[Tue Jul 21 08:36:12.202052 2026] [security2:error] [pid 466512:tid 466671] [client 81.171.72.135:47624] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "joaomarcosdesign.com.br"] [uri "/.bash_history"] [unique_id "al9ZrCKGokixMSfKDOftqQAAAjE"]
[Tue Jul 21 08:36:12.265899 2026] [security2:error] [pid 465652:tid 465893] [client 5.38.115.39:58745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZrDzTqJoBC2Mw28_I1AAAAPQ"]
[Tue Jul 21 08:36:12.266136 2026] [security2:error] [pid 465652:tid 465893] [client 5.38.115.39:58745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZrDzTqJoBC2Mw28_I1AAAAPQ"]
[Tue Jul 21 08:36:12.688150 2026] [security2:error] [pid 465652:tid 465784] [client 74.249.245.134:63712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/2.php"] [unique_id "al9ZrDzTqJoBC2Mw28_I3AAAAIc"]
[Tue Jul 21 08:36:12.719012 2026] [security2:error] [pid 466512:tid 466730] [client 20.226.60.151:64088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/zlece.php"] [unique_id "al9ZrCKGokixMSfKDOftswAAAmw"]
[Tue Jul 21 08:36:13.314279 2026] [security2:error] [pid 466512:tid 466734] [client 20.206.105.145:38996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xwpg.php"] [unique_id "al9ZrSKGokixMSfKDOfttgAAAnA"]
[Tue Jul 21 08:36:13.528962 2026] [security2:error] [pid 466512:tid 466681] [client 20.220.225.223:20906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.guiadeoferta.com.br"] [uri "/ms.php"] [unique_id "al9ZrSKGokixMSfKDOfttwAAAjs"]
[Tue Jul 21 08:36:13.605748 2026] [security2:error] [pid 465652:tid 465834] [client 213.152.186.163:49922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9ZrTzTqJoBC2Mw28_I8QAAALk"]
[Tue Jul 21 08:36:13.605848 2026] [security2:error] [pid 465652:tid 465834] [client 213.152.186.163:49922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9ZrTzTqJoBC2Mw28_I8QAAALk"]
[Tue Jul 21 08:36:13.674179 2026] [security2:error] [pid 465652:tid 465855] [client 20.226.60.151:64035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/vssrs.php"] [unique_id "al9ZrTzTqJoBC2Mw28_I8gAAAM4"]
[Tue Jul 21 08:36:13.783760 2026] [security2:error] [pid 466512:tid 466699] [client 14.245.224.124:49709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZrSKGokixMSfKDOftvwAAAk0"]
[Tue Jul 21 08:36:13.784216 2026] [security2:error] [pid 466512:tid 466699] [client 14.245.224.124:49709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZrSKGokixMSfKDOftvwAAAk0"]
[Tue Jul 21 08:36:13.806121 2026] [security2:error] [pid 465652:tid 465679] [remote 72.167.132.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9ZrTzTqJoBC2Mw28_I9gAAyho"]
[Tue Jul 21 08:36:13.806278 2026] [security2:error] [pid 465652:tid 465851] [client 72.167.132.114:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aud-7.com"] [uri "/xmlrpc.php"] [unique_id "al9ZrTzTqJoBC2Mw28_I9gAAyho"]
[Tue Jul 21 08:36:13.901633 2026] [security2:error] [pid 465652:tid 465902] [client 89.238.167.134:53758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9ZrTzTqJoBC2Mw28_I9wAAAP0"]
[Tue Jul 21 08:36:13.901755 2026] [security2:error] [pid 465652:tid 465902] [client 89.238.167.134:53758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9ZrTzTqJoBC2Mw28_I9wAAAP0"]
[Tue Jul 21 08:36:14.313309 2026] [security2:error] [pid 466512:tid 466755] [client 173.252.95.22:39336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ZriKGokixMSfKDOftyAAAAoU"]
[Tue Jul 21 08:36:14.518833 2026] [security2:error] [pid 465652:tid 465856] [client 152.59.34.51:52569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZrjzTqJoBC2Mw28_JAQAAAM8"]
[Tue Jul 21 08:36:14.518955 2026] [security2:error] [pid 465652:tid 465856] [client 152.59.34.51:52569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZrjzTqJoBC2Mw28_JAQAAAM8"]
[Tue Jul 21 08:36:14.521337 2026] [security2:error] [pid 465652:tid 465824] [client 20.226.60.151:64066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wicked.php"] [unique_id "al9ZrjzTqJoBC2Mw28_JAwAAAK8"]
[Tue Jul 21 08:36:14.547250 2026] [security2:error] [pid 466512:tid 466650] [client 173.252.95.1:65312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ZriKGokixMSfKDOftygAAAhw"]
[Tue Jul 21 08:36:14.692170 2026] [security2:error] [pid 465652:tid 465821] [client 49.144.66.253:31698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZrjzTqJoBC2Mw28_JBgAAAKw"]
[Tue Jul 21 08:36:14.692264 2026] [security2:error] [pid 465652:tid 465821] [client 49.144.66.253:31698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZrjzTqJoBC2Mw28_JBgAAAKw"]
[Tue Jul 21 08:36:14.738744 2026] [proxy:error] [pid 465652:tid 465858] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:36:14.738804 2026] [proxy_http:error] [pid 465652:tid 465858] [client 20.206.105.145:39257] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:36:14.739362 2026] [proxy:error] [pid 465652:tid 465858] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:36:14.739391 2026] [proxy_http:error] [pid 465652:tid 465858] [client 20.206.105.145:39257] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:36:15.166295 2026] [security2:error] [pid 466512:tid 466701] [client 20.206.105.145:21981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/error_log.php"] [unique_id "al9ZryKGokixMSfKDOft1gAAAk8"]
[Tue Jul 21 08:36:15.320689 2026] [security2:error] [pid 465652:tid 465820] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZrjzTqJoBC2Mw28_JDQAAAKs"]
[Tue Jul 21 08:36:15.603058 2026] [security2:error] [pid 466512:tid 466700] [client 74.249.245.134:42270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/asd.php"] [unique_id "al9ZryKGokixMSfKDOft2gAAAk4"]
[Tue Jul 21 08:36:15.668954 2026] [security2:error] [pid 466512:tid 466746] [client 20.226.60.151:64078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/24.php"] [unique_id "al9ZryKGokixMSfKDOft2wAAAnw"]
[Tue Jul 21 08:36:15.817626 2026] [access_compat:error] [pid 466512:tid 466762] [client 162.241.63.68:54212] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:36:16.117845 2026] [security2:error] [pid 466512:tid 466721] [client 152.59.181.104:50137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZsCKGokixMSfKDOft4QAAAmM"]
[Tue Jul 21 08:36:16.117991 2026] [security2:error] [pid 466512:tid 466721] [client 152.59.181.104:50137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZsCKGokixMSfKDOft4QAAAmM"]
[Tue Jul 21 08:36:16.343249 2026] [proxy:error] [pid 466512:tid 466745] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:36:16.343347 2026] [proxy_http:error] [pid 466512:tid 466745] [client 20.206.105.145:39165] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:36:16.344969 2026] [proxy:error] [pid 466512:tid 466745] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:36:16.345023 2026] [proxy_http:error] [pid 466512:tid 466745] [client 20.206.105.145:39165] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:36:16.436765 2026] [security2:error] [pid 466512:tid 466764] [client 195.49.128.211:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZsCKGokixMSfKDOft7AAAAo4"]
[Tue Jul 21 08:36:16.436955 2026] [security2:error] [pid 466512:tid 466764] [client 195.49.128.211:52872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZsCKGokixMSfKDOft7AAAAo4"]
[Tue Jul 21 08:36:16.542495 2026] [security2:error] [pid 466512:tid 466694] [client 103.59.206.240:31333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZsCKGokixMSfKDOft7QAAAkg"]
[Tue Jul 21 08:36:16.542607 2026] [security2:error] [pid 466512:tid 466694] [client 103.59.206.240:31333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZsCKGokixMSfKDOft7QAAAkg"]
[Tue Jul 21 08:36:16.638775 2026] [security2:error] [pid 466512:tid 466734] [client 122.176.100.127:64101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZsCKGokixMSfKDOft7gAAAnA"]
[Tue Jul 21 08:36:16.638925 2026] [security2:error] [pid 466512:tid 466734] [client 122.176.100.127:64101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZsCKGokixMSfKDOft7gAAAnA"]
[Tue Jul 21 08:36:16.792331 2026] [security2:error] [pid 466512:tid 466723] [client 34.62.211.118:59522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.211.62.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "simleite.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZsCKGokixMSfKDOft8QAAAmU"]
[Tue Jul 21 08:36:16.835301 2026] [security2:error] [pid 465652:tid 465871] [client 20.226.60.151:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/xacs.php"] [unique_id "al9ZsDzTqJoBC2Mw28_JLAAAAN4"]
[Tue Jul 21 08:36:17.431454 2026] [security2:error] [pid 466512:tid 466726] [client 91.92.47.101:1340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/wp-config.php"] [unique_id "al9ZsSKGokixMSfKDOft_QAAAmg"], referer: http://jaypi.com.br/
[Tue Jul 21 08:36:17.431548 2026] [security2:error] [pid 465652:tid 465881] [client 91.92.47.101:1372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/wp-config.php"] [unique_id "al9ZsTzTqJoBC2Mw28_JOQAAAOg"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:36:17.432134 2026] [security2:error] [pid 466512:tid 466656] [client 91.92.47.101:1352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jaypi.com.br"] [uri "/.env"] [unique_id "al9ZsSKGokixMSfKDOft_AAAAiI"], referer: http://jaypi.com.br/
[Tue Jul 21 08:36:17.432370 2026] [security2:error] [pid 466512:tid 466719] [client 91.92.47.101:1270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rockegrow.jaypi.com.br"] [uri "/.env"] [unique_id "al9ZsSKGokixMSfKDOft_gAAAmE"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:36:17.585088 2026] [security2:error] [pid 466512:tid 466757] [client 91.92.47.101:1414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/config.php"] [unique_id "al9ZsSKGokixMSfKDOfuBgAAAoc"], referer: http://jaypi.com.br/
[Tue Jul 21 08:36:17.586550 2026] [security2:error] [pid 466512:tid 466669] [client 91.92.47.101:1400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/info.php"] [unique_id "al9ZsSKGokixMSfKDOfuBwAAAi8"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:36:17.602156 2026] [security2:error] [pid 465652:tid 465787] [client 34.62.211.118:53105] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "simleite.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9ZsTzTqJoBC2Mw28_JQAAAAIo"]
[Tue Jul 21 08:36:17.648027 2026] [security2:error] [pid 465652:tid 465864] [client 20.226.60.151:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/zildan.php"] [unique_id "al9ZsTzTqJoBC2Mw28_JQQAAANc"]
[Tue Jul 21 08:36:17.956412 2026] [security2:error] [pid 465652:tid 465905] [client 74.249.245.134:53671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/default.php"] [unique_id "al9ZsTzTqJoBC2Mw28_JRQAAAQA"]
[Tue Jul 21 08:36:18.367058 2026] [security2:error] [pid 466512:tid 466649] [client 91.92.47.101:1260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/config.php"] [unique_id "al9ZsSKGokixMSfKDOft-gAAAhs"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:36:18.431873 2026] [security2:error] [pid 465652:tid 465856] [client 91.92.47.101:1306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/phpinfo.php"] [unique_id "al9ZsTzTqJoBC2Mw28_JNQAAAM8"], referer: http://jaypi.com.br/
[Tue Jul 21 08:36:18.433472 2026] [security2:error] [pid 465652:tid 465882] [client 91.92.47.101:1312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/info.php"] [unique_id "al9ZsTzTqJoBC2Mw28_JNgAAAOk"], referer: http://jaypi.com.br/
[Tue Jul 21 08:36:18.434066 2026] [security2:error] [pid 465652:tid 465824] [client 91.92.47.101:1278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/phpinfo.php"] [unique_id "al9ZsTzTqJoBC2Mw28_JNwAAAK8"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:36:18.463384 2026] [security2:error] [pid 466512:tid 466711] [client 34.62.211.118:60529] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "simleite.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9ZsiKGokixMSfKDOfuEgAAAlk"]
[Tue Jul 21 08:36:18.749476 2026] [security2:error] [pid 466512:tid 466712] [client 20.206.105.145:21984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/xenon1337.php"] [unique_id "al9ZsiKGokixMSfKDOfuFQAAAlo"]
[Tue Jul 21 08:36:18.988807 2026] [security2:error] [pid 465652:tid 465833] [client 117.213.202.34:58946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZsjzTqJoBC2Mw28_JZwAAALg"]
[Tue Jul 21 08:36:18.988995 2026] [security2:error] [pid 465652:tid 465833] [client 117.213.202.34:58946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZsjzTqJoBC2Mw28_JZwAAALg"]
[Tue Jul 21 08:36:19.058976 2026] [security2:error] [pid 465652:tid 465888] [client 20.226.60.151:64025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/csa.php"] [unique_id "al9ZszzTqJoBC2Mw28_JaAAAAO8"]
[Tue Jul 21 08:36:19.257850 2026] [security2:error] [pid 466512:tid 466713] [client 20.206.105.145:39240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/waf.php"] [unique_id "al9ZsyKGokixMSfKDOfuIAAAAls"]
[Tue Jul 21 08:36:19.363207 2026] [security2:error] [pid 466512:tid 466668] [client 34.62.211.118:53544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "simleite.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9ZsyKGokixMSfKDOfuIgAAAi4"]
[Tue Jul 21 08:36:19.464059 2026] [security2:error] [pid 465652:tid 465907] [client 74.7.175.156:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.blog.drapatriciavarella.com.br"] [uri "/index.php"] [unique_id "al9ZsjzTqJoBC2Mw28_JVAAAAQI"]
[Tue Jul 21 08:36:19.465264 2026] [security2:error] [pid 466512:tid 466662] [client 74.7.175.156:48700] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.blog.drapatriciavarella.com.br"] [uri "/robots.txt"] [unique_id "al9ZsiKGokixMSfKDOfuDgACKHc"]
[Tue Jul 21 08:36:19.588098 2026] [security2:error] [pid 466512:tid 466741] [client 187.125.243.197:60575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZsyKGokixMSfKDOfuLAAAAnc"]
[Tue Jul 21 08:36:19.588276 2026] [security2:error] [pid 466512:tid 466741] [client 187.125.243.197:60575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZsyKGokixMSfKDOfuLAAAAnc"]
[Tue Jul 21 08:36:19.792955 2026] [security2:error] [pid 466512:tid 466687] [client 20.226.60.151:59314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/w3llscc.php"] [unique_id "al9ZsyKGokixMSfKDOfuLQAAAkE"]
[Tue Jul 21 08:36:19.866303 2026] [security2:error] [pid 466512:tid 466514] [remote 46.101.194.217:60476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.194.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "monicamirandapereira1751478737000.bellarthconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "al9ZsSKGokixMSfKDOfuCwACXgE"]
[Tue Jul 21 08:36:19.870264 2026] [security2:error] [pid 465652:tid 465680] [remote 139.59.136.184:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "deiacakes.com"] [uri "/.env"] [unique_id "al9ZszzTqJoBC2Mw28_JdQAApRs"]
[Tue Jul 21 08:36:20.080895 2026] [security2:error] [pid 466512:tid 466707] [client 74.7.175.156:48714] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "blog.drapatriciavarella.com.br"] [uri "/robots.txt"] [unique_id "al9ZtCKGokixMSfKDOfuLwACVVc"], referer: https://www.blog.drapatriciavarella.com.br/robots.txt
[Tue Jul 21 08:36:20.113843 2026] [security2:error] [pid 466512:tid 466698] [client 20.226.60.151:64014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wpx.php"] [unique_id "al9ZtCKGokixMSfKDOfuMgAAAkw"]
[Tue Jul 21 08:36:20.191774 2026] [security2:error] [pid 466512:tid 466646] [client 34.62.211.118:59205] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "simleite.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9ZtCKGokixMSfKDOfuMwAAAhg"]
[Tue Jul 21 08:36:20.419157 2026] [security2:error] [pid 465652:tid 465840] [client 20.206.105.145:22120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/test11.php"] [unique_id "al9ZtDzTqJoBC2Mw28_JggAAAL8"]
[Tue Jul 21 08:36:20.481551 2026] [security2:error] [pid 465652:tid 465839] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZszzTqJoBC2Mw28_JegAAAL4"]
[Tue Jul 21 08:36:20.536015 2026] [security2:error] [pid 465652:tid 465784] [client 167.235.143.113:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9ZtDzTqJoBC2Mw28_JiAAAhyk"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:36:20.628032 2026] [security2:error] [pid 466512:tid 466749] [client 195.49.128.211:60775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZtCKGokixMSfKDOfuOwAAAn8"]
[Tue Jul 21 08:36:20.628155 2026] [security2:error] [pid 466512:tid 466749] [client 195.49.128.211:60775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZtCKGokixMSfKDOfuOwAAAn8"]
[Tue Jul 21 08:36:20.643586 2026] [security2:error] [pid 466512:tid 466703] [client 74.249.245.134:16097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/gettest.php"] [unique_id "al9ZtCKGokixMSfKDOfuPAAAAlE"]
[Tue Jul 21 08:36:20.731027 2026] [security2:error] [pid 465652:tid 465841] [client 223.181.60.88:29555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZtDzTqJoBC2Mw28_JjAAAAMA"]
[Tue Jul 21 08:36:20.731172 2026] [security2:error] [pid 465652:tid 465841] [client 223.181.60.88:29555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZtDzTqJoBC2Mw28_JjAAAAMA"]
[Tue Jul 21 08:36:20.894405 2026] [security2:error] [pid 466512:tid 466565] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZtCKGokixMSfKDOfuPwACWjQ"]
[Tue Jul 21 08:36:20.894602 2026] [security2:error] [pid 466512:tid 466712] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZtCKGokixMSfKDOfuPwACWjQ"]
[Tue Jul 21 08:36:21.024034 2026] [security2:error] [pid 465652:tid 465654] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZtTzTqJoBC2Mw28_JlgAAywE"]
[Tue Jul 21 08:36:21.024190 2026] [security2:error] [pid 465652:tid 465852] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZtTzTqJoBC2Mw28_JlgAAywE"]
[Tue Jul 21 08:36:21.072612 2026] [security2:error] [pid 466512:tid 466664] [client 167.235.143.113:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9ZtSKGokixMSfKDOfuQQACKl0"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:36:21.087006 2026] [security2:error] [pid 466512:tid 466678] [client 34.62.211.118:60445] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "simleite.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9ZtSKGokixMSfKDOfuQgAAAjg"]
[Tue Jul 21 08:36:21.111987 2026] [security2:error] [pid 465652:tid 465887] [client 20.226.60.151:64068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-css.php"] [unique_id "al9ZtTzTqJoBC2Mw28_JlwAAAO4"]
[Tue Jul 21 08:36:21.280554 2026] [security2:error] [pid 465652:tid 465871] [client 20.226.60.151:64119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/ho.php"] [unique_id "al9ZtTzTqJoBC2Mw28_JmQAAAN4"]
[Tue Jul 21 08:36:21.410729 2026] [security2:error] [pid 466512:tid 466682] [client 20.206.105.145:38983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/xstelth.php"] [unique_id "al9ZtSKGokixMSfKDOfuRwAAAjw"]
[Tue Jul 21 08:36:21.658752 2026] [security2:error] [pid 465652:tid 465845] [client 20.226.60.151:64012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/xy.php"] [unique_id "al9ZtTzTqJoBC2Mw28_JowAAAMQ"]
[Tue Jul 21 08:36:21.945168 2026] [security2:error] [pid 466512:tid 466662] [client 34.62.211.118:58661] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "simleite.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9ZtSKGokixMSfKDOfuTQAAAig"]
[Tue Jul 21 08:36:22.254688 2026] [security2:error] [pid 465652:tid 465880] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZtjzTqJoBC2Mw28_JrwAA52A"]
[Tue Jul 21 08:36:22.289749 2026] [security2:error] [pid 465652:tid 465787] [client 62.164.177.222:57380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZtjzTqJoBC2Mw28_JsAAAAIo"]
[Tue Jul 21 08:36:22.289935 2026] [security2:error] [pid 465652:tid 465787] [client 62.164.177.222:57380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZtjzTqJoBC2Mw28_JsAAAAIo"]
[Tue Jul 21 08:36:22.592931 2026] [security2:error] [pid 465652:tid 465794] [client 20.226.60.151:59094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/loader.php"] [unique_id "al9ZtjzTqJoBC2Mw28_JtQAAAJE"]
[Tue Jul 21 08:36:22.781309 2026] [security2:error] [pid 466512:tid 466690] [client 103.151.46.103:55964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZtiKGokixMSfKDOfuVQAAAkQ"]
[Tue Jul 21 08:36:22.781418 2026] [security2:error] [pid 466512:tid 466690] [client 103.151.46.103:55964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZtiKGokixMSfKDOfuVQAAAkQ"]
[Tue Jul 21 08:36:22.855117 2026] [security2:error] [pid 465652:tid 465857] [client 34.62.211.118:55277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "simleite.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9ZtjzTqJoBC2Mw28_JuwAAANA"]
[Tue Jul 21 08:36:22.897349 2026] [security2:error] [pid 465652:tid 465783] [client 20.206.105.145:22086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/koala.php"] [unique_id "al9ZtjzTqJoBC2Mw28_JvAAAAIY"]
[Tue Jul 21 08:36:22.924578 2026] [security2:error] [pid 466512:tid 466656] [client 5.38.115.39:41802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZtiKGokixMSfKDOfuVwAAAiI"]
[Tue Jul 21 08:36:22.924705 2026] [security2:error] [pid 466512:tid 466656] [client 5.38.115.39:41802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZtiKGokixMSfKDOfuVwAAAiI"]
[Tue Jul 21 08:36:23.041330 2026] [security2:error] [pid 466512:tid 466752] [client 20.226.60.151:64104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/spadex.php"] [unique_id "al9ZtyKGokixMSfKDOfuWQAAAoI"]
[Tue Jul 21 08:36:23.163961 2026] [security2:error] [pid 465652:tid 465882] [client 62.164.177.222:34250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZtzzTqJoBC2Mw28_JxAAAAOk"]
[Tue Jul 21 08:36:23.164042 2026] [security2:error] [pid 465652:tid 465882] [client 62.164.177.222:34250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZtzzTqJoBC2Mw28_JxAAAAOk"]
[Tue Jul 21 08:36:23.207477 2026] [security2:error] [pid 466512:tid 466703] [client 91.92.47.101:58410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/info.php"] [unique_id "al9ZtyKGokixMSfKDOfuYAAAAlE"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:36:23.210016 2026] [security2:error] [pid 465652:tid 465786] [client 91.92.47.101:58384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rockegrow.com.br"] [uri "/.env"] [unique_id "al9ZtzzTqJoBC2Mw28_JyAAAAIk"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:36:23.215614 2026] [security2:error] [pid 466512:tid 466694] [client 91.92.47.101:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/config.php"] [unique_id "al9ZtyKGokixMSfKDOfuYwAAAkg"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:36:23.216572 2026] [security2:error] [pid 465652:tid 465889] [client 91.92.47.101:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/phpinfo.php"] [unique_id "al9ZtzzTqJoBC2Mw28_JywAAAPA"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:36:23.217289 2026] [security2:error] [pid 466512:tid 466645] [client 91.92.47.101:58436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/wp-config.php"] [unique_id "al9ZtyKGokixMSfKDOfuZAAAAhc"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:36:23.339356 2026] [security2:error] [pid 466512:tid 466651] [client 74.249.245.134:53683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/tfm.php"] [unique_id "al9ZtyKGokixMSfKDOfuZwAAAh0"]
[Tue Jul 21 08:36:23.420577 2026] [security2:error] [pid 465652:tid 465830] [client 20.206.105.145:39019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-links.php"] [unique_id "al9ZtzzTqJoBC2Mw28_JzwAAALU"]
[Tue Jul 21 08:36:23.462445 2026] [security2:error] [pid 465652:tid 465852] [client 49.13.134.145:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9ZtzzTqJoBC2Mw28_J0AAAyyo"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:36:23.606964 2026] [security2:error] [pid 465652:tid 465849] [client 61.1.167.83:62833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZtzzTqJoBC2Mw28_J2gAAAMg"]
[Tue Jul 21 08:36:23.607069 2026] [security2:error] [pid 465652:tid 465849] [client 61.1.167.83:62833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZtzzTqJoBC2Mw28_J2gAAAMg"]
[Tue Jul 21 08:36:23.645226 2026] [security2:error] [pid 465652:tid 465841] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZtzzTqJoBC2Mw28_JxQAAAMA"]
[Tue Jul 21 08:36:23.746569 2026] [security2:error] [pid 465652:tid 465834] [client 34.62.211.118:58935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "simleite.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9ZtzzTqJoBC2Mw28_J3wAAALk"]
[Tue Jul 21 08:36:24.017413 2026] [security2:error] [pid 466512:tid 466755] [client 49.13.134.145:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9ZuCKGokixMSfKDOfubQAChXQ"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:36:24.057475 2026] [security2:error] [pid 466512:tid 466691] [client 20.226.60.151:64029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/2x.php"] [unique_id "al9ZuCKGokixMSfKDOfucQAAAkU"]
[Tue Jul 21 08:36:24.399646 2026] [security2:error] [pid 466512:tid 466674] [client 14.245.224.124:50181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZuCKGokixMSfKDOfuegAAAjQ"]
[Tue Jul 21 08:36:24.400326 2026] [security2:error] [pid 466512:tid 466674] [client 14.245.224.124:50181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZuCKGokixMSfKDOfuegAAAjQ"]
[Tue Jul 21 08:36:24.474687 2026] [security2:error] [pid 466512:tid 466730] [client 62.164.177.222:39104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/blog/xmlrpc.php"] [unique_id "al9ZuCKGokixMSfKDOfuewAAAmw"]
[Tue Jul 21 08:36:24.474804 2026] [security2:error] [pid 466512:tid 466730] [client 62.164.177.222:39104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/blog/xmlrpc.php"] [unique_id "al9ZuCKGokixMSfKDOfuewAAAmw"]
[Tue Jul 21 08:36:24.642087 2026] [security2:error] [pid 466512:tid 466705] [client 34.62.211.118:52821] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "simleite.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9ZuCKGokixMSfKDOfufAAAAlM"]
[Tue Jul 21 08:36:24.978299 2026] [security2:error] [pid 466512:tid 466727] [client 20.226.60.151:64092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/ctex1.php"] [unique_id "al9ZuCKGokixMSfKDOfufwAAAmk"]
[Tue Jul 21 08:36:25.007601 2026] [security2:error] [pid 466512:tid 466577] [remote 167.71.218.184:53100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ZuSKGokixMSfKDOfuggACJkA"]
[Tue Jul 21 08:36:25.163020 2026] [security2:error] [pid 466512:tid 466676] [client 20.206.105.145:38998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9ZuSKGokixMSfKDOfugwAAAjY"]
[Tue Jul 21 08:36:25.254500 2026] [security2:error] [pid 466512:tid 466696] [client 152.59.34.51:53840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZuSKGokixMSfKDOfuhgAAAko"]
[Tue Jul 21 08:36:25.254617 2026] [security2:error] [pid 466512:tid 466696] [client 152.59.34.51:53840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZuSKGokixMSfKDOfuhgAAAko"]
[Tue Jul 21 08:36:25.349749 2026] [security2:error] [pid 465652:tid 465857] [client 62.164.177.222:47108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "al9ZuTzTqJoBC2Mw28_J_QAAANA"]
[Tue Jul 21 08:36:25.349842 2026] [security2:error] [pid 465652:tid 465857] [client 62.164.177.222:47108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "al9ZuTzTqJoBC2Mw28_J_QAAANA"]
[Tue Jul 21 08:36:25.573492 2026] [security2:error] [pid 466512:tid 466658] [client 20.226.60.151:64037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/edorxrr.php"] [unique_id "al9ZuSKGokixMSfKDOfuiwAAAiQ"]
[Tue Jul 21 08:36:25.587168 2026] [security2:error] [pid 466512:tid 466731] [client 49.144.66.253:31847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZuSKGokixMSfKDOfujAAAAm0"]
[Tue Jul 21 08:36:25.587261 2026] [security2:error] [pid 466512:tid 466731] [client 49.144.66.253:31847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZuSKGokixMSfKDOfujAAAAm0"]
[Tue Jul 21 08:36:25.601498 2026] [security2:error] [pid 466512:tid 466689] [client 34.62.211.118:64976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "simleite.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9ZuSKGokixMSfKDOfujgAAAkM"]
[Tue Jul 21 08:36:25.639787 2026] [security2:error] [pid 466512:tid 466703] [client 173.252.95.36:37822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ZuSKGokixMSfKDOfujwAAAlE"]
[Tue Jul 21 08:36:25.651293 2026] [security2:error] [pid 466512:tid 466651] [client 74.249.245.134:53638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/ws81.php"] [unique_id "al9ZuSKGokixMSfKDOfukQAAAh0"]
[Tue Jul 21 08:36:25.830559 2026] [security2:error] [pid 466512:tid 466708] [client 114.119.155.10:35581] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "projetoflechas.org.br"] [uri "/wp-content/uploads/semanario2012313-1024x503.jpg"] [unique_id "al9ZuSKGokixMSfKDOfumAAAAlY"], referer: http://projetoflechas.org.br/wp-content/uploads/semanario2012313-1024x503.jpg?is-pending-load=1
[Tue Jul 21 08:36:25.843163 2026] [security2:error] [pid 466512:tid 466682] [client 20.226.60.151:64117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/miru1.php"] [unique_id "al9ZuSKGokixMSfKDOfumQAAAjw"]
[Tue Jul 21 08:36:25.925326 2026] [security2:error] [pid 465652:tid 465875] [client 185.213.175.37:63470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "betoperroy.com.br"] [uri "/"] [unique_id "al9ZuTzTqJoBC2Mw28_KCAAAAOI"]
[Tue Jul 21 08:36:25.925430 2026] [security2:error] [pid 465652:tid 465875] [client 185.213.175.37:63470] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "betoperroy.com.br"] [uri "/"] [unique_id "al9ZuTzTqJoBC2Mw28_KCAAAAOI"]
[Tue Jul 21 08:36:26.155729 2026] [security2:error] [pid 465652:tid 465909] [client 20.226.60.151:64105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/sump1.php"] [unique_id "al9ZujzTqJoBC2Mw28_KCwAAAQQ"]
[Tue Jul 21 08:36:26.223461 2026] [security2:error] [pid 465652:tid 465882] [client 62.164.177.222:52174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/site/xmlrpc.php"] [unique_id "al9ZujzTqJoBC2Mw28_KDAAAAOk"]
[Tue Jul 21 08:36:26.223561 2026] [security2:error] [pid 465652:tid 465882] [client 62.164.177.222:52174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/site/xmlrpc.php"] [unique_id "al9ZujzTqJoBC2Mw28_KDAAAAOk"]
[Tue Jul 21 08:36:26.523097 2026] [security2:error] [pid 465652:tid 465885] [client 34.62.211.118:57795] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "simleite.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9ZujzTqJoBC2Mw28_KFQAAAOw"]
[Tue Jul 21 08:36:26.531099 2026] [rewrite:warn] [pid 466512:tid 466529] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:36:26.636829 2026] [security2:error] [pid 465652:tid 465851] [client 20.226.60.151:64124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/file5.php"] [unique_id "al9ZujzTqJoBC2Mw28_KGAAAAMo"]
[Tue Jul 21 08:36:26.822177 2026] [security2:error] [pid 466512:tid 466763] [client 152.59.181.104:50567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZuiKGokixMSfKDOfuqgAAAo0"]
[Tue Jul 21 08:36:26.826937 2026] [security2:error] [pid 466512:tid 466763] [client 152.59.181.104:50567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZuiKGokixMSfKDOfuqgAAAo0"]
[Tue Jul 21 08:36:27.022287 2026] [security2:error] [pid 465652:tid 465833] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZujzTqJoBC2Mw28_KFgAAALg"]
[Tue Jul 21 08:36:27.027388 2026] [security2:error] [pid 465652:tid 465845] [client 91.192.10.181:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.marinapiassivasconce1782219596805.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "al9ZuzzTqJoBC2Mw28_KHQAAAMQ"]
[Tue Jul 21 08:36:27.027804 2026] [security2:error] [pid 466512:tid 466711] [client 91.192.10.181:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.marinapiassivasconce1782219596805.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "al9ZuyKGokixMSfKDOfusgAAAlk"]
[Tue Jul 21 08:36:27.036835 2026] [security2:error] [pid 466512:tid 466657] [client 91.192.10.181:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.marinapiassivasconce1782219596805.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9ZuyKGokixMSfKDOfuugAAAiM"]
[Tue Jul 21 08:36:27.097745 2026] [security2:error] [pid 466512:tid 466687] [client 62.164.177.222:57354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/web/xmlrpc.php"] [unique_id "al9ZuyKGokixMSfKDOfuvgAAAkE"]
[Tue Jul 21 08:36:27.097861 2026] [security2:error] [pid 466512:tid 466687] [client 62.164.177.222:57354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/web/xmlrpc.php"] [unique_id "al9ZuyKGokixMSfKDOfuvgAAAkE"]
[Tue Jul 21 08:36:27.112392 2026] [security2:error] [pid 466512:tid 466663] [client 20.206.105.145:39160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.goldentrips40.com"] [uri "/aaa.php"] [unique_id "al9ZuyKGokixMSfKDOfuvwAAAik"]
[Tue Jul 21 08:36:27.121280 2026] [security2:error] [pid 465652:tid 465782] [client 195.49.128.211:53486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZuzzTqJoBC2Mw28_KIgAAAIU"]
[Tue Jul 21 08:36:27.121400 2026] [security2:error] [pid 465652:tid 465782] [client 195.49.128.211:53486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZuzzTqJoBC2Mw28_KIgAAAIU"]
[Tue Jul 21 08:36:27.127677 2026] [security2:error] [pid 466512:tid 466707] [client 122.176.100.127:64612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZuyKGokixMSfKDOfuwQAAAlU"]
[Tue Jul 21 08:36:27.127854 2026] [security2:error] [pid 466512:tid 466707] [client 122.176.100.127:64612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZuyKGokixMSfKDOfuwQAAAlU"]
[Tue Jul 21 08:36:27.188317 2026] [security2:error] [pid 466512:tid 466658] [client 74.249.245.134:44029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/222.php"] [unique_id "al9ZuyKGokixMSfKDOfuwwAAAiQ"]
[Tue Jul 21 08:36:27.204993 2026] [security2:error] [pid 466512:tid 466731] [client 20.226.60.151:64048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/0xD.php"] [unique_id "al9ZuyKGokixMSfKDOfuxAAAAm0"]
[Tue Jul 21 08:36:27.417654 2026] [security2:error] [pid 466512:tid 466745] [client 34.62.211.118:54741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "simleite.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9ZuyKGokixMSfKDOfu0QAAAns"]
[Tue Jul 21 08:36:27.644199 2026] [security2:error] [pid 466512:tid 466697] [client 37.140.223.43:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "imobiliariasobrado.com.br"] [uri "/"] [unique_id "al9ZuyKGokixMSfKDOfu3AAAAks"], referer: http://imobiliariasobrado.com.br/
[Tue Jul 21 08:36:27.979141 2026] [security2:error] [pid 465652:tid 465908] [client 62.164.177.222:34598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/cms/xmlrpc.php"] [unique_id "al9ZuzzTqJoBC2Mw28_KPAAAAQM"]
[Tue Jul 21 08:36:27.979224 2026] [security2:error] [pid 465652:tid 465908] [client 62.164.177.222:34598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/cms/xmlrpc.php"] [unique_id "al9ZuzzTqJoBC2Mw28_KPAAAAQM"]
[Tue Jul 21 08:36:28.080939 2026] [security2:error] [pid 465652:tid 465805] [client 20.226.60.151:59104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/fnstall.php"] [unique_id "al9ZvDzTqJoBC2Mw28_KPQAAAJw"]
[Tue Jul 21 08:36:28.110674 2026] [security2:error] [pid 466512:tid 466657] [client 74.249.245.134:16100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/t.php"] [unique_id "al9ZvCKGokixMSfKDOfu8gAAAiM"]
[Tue Jul 21 08:36:28.421540 2026] [security2:error] [pid 466512:tid 466739] [client 37.140.223.43:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "imobiliariasobrado.com.br"] [uri "/wp-includes/css/buttons.css"] [unique_id "al9ZvCKGokixMSfKDOfu-wAAAnU"], referer: http://imobiliariasobrado.com.br/wp-includes/css/buttons.css
[Tue Jul 21 08:36:28.655719 2026] [security2:error] [pid 465652:tid 465878] [client 20.206.105.145:22085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/mac.php"] [unique_id "al9ZvDzTqJoBC2Mw28_KTQAAAOU"]
[Tue Jul 21 08:36:28.868586 2026] [security2:error] [pid 465652:tid 465790] [client 62.164.177.222:39616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/wp-site/xmlrpc.php"] [unique_id "al9ZvDzTqJoBC2Mw28_KUgAAAI0"]
[Tue Jul 21 08:36:28.868683 2026] [security2:error] [pid 465652:tid 465790] [client 62.164.177.222:39616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/wp-site/xmlrpc.php"] [unique_id "al9ZvDzTqJoBC2Mw28_KUgAAAI0"]
[Tue Jul 21 08:36:29.041413 2026] [security2:error] [pid 466512:tid 466747] [client 20.226.60.151:64000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/acp.php"] [unique_id "al9ZvSKGokixMSfKDOfvDAAAAn0"]
[Tue Jul 21 08:36:29.087178 2026] [security2:error] [pid 466512:tid 466659] [client 74.249.245.134:32569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/a.php"] [unique_id "al9ZvSKGokixMSfKDOfvDgAAAiU"]
[Tue Jul 21 08:36:29.112053 2026] [security2:error] [pid 465652:tid 465785] [client 37.140.223.43:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "imobiliariasobrado.com.br"] [uri "/media/system/js/core.js"] [unique_id "al9ZvTzTqJoBC2Mw28_KVwAAAIg"], referer: http://imobiliariasobrado.com.br/media/system/js/core.js
[Tue Jul 21 08:36:29.404769 2026] [security2:error] [pid 465652:tid 465851] [client 62.164.177.222:43022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9ZvTzTqJoBC2Mw28_KXwAAAMo"]
[Tue Jul 21 08:36:29.404878 2026] [security2:error] [pid 465652:tid 465851] [client 62.164.177.222:43022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9ZvTzTqJoBC2Mw28_KXwAAAMo"]
[Tue Jul 21 08:36:29.567281 2026] [security2:error] [pid 466512:tid 466732] [client 202.179.75.202:41082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZvSKGokixMSfKDOfvFgAAAm4"]
[Tue Jul 21 08:36:29.567398 2026] [security2:error] [pid 466512:tid 466732] [client 202.179.75.202:41082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZvSKGokixMSfKDOfvFgAAAm4"]
[Tue Jul 21 08:36:29.669213 2026] [security2:error] [pid 466512:tid 466751] [client 20.226.60.151:64090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/mosty.php"] [unique_id "al9ZvSKGokixMSfKDOfvFwAAAoE"]
[Tue Jul 21 08:36:29.788026 2026] [security2:error] [pid 465652:tid 465885] [client 117.213.202.34:59559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZvTzTqJoBC2Mw28_KZwAAAOw"]
[Tue Jul 21 08:36:29.788230 2026] [security2:error] [pid 465652:tid 465885] [client 117.213.202.34:59559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZvTzTqJoBC2Mw28_KZwAAAOw"]
[Tue Jul 21 08:36:29.812869 2026] [security2:error] [pid 465652:tid 465806] [client 159.223.41.76:63725] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bubaby.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9ZvTzTqJoBC2Mw28_KaAAAAJ0"]
[Tue Jul 21 08:36:29.878473 2026] [security2:error] [pid 465652:tid 465833] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZvTzTqJoBC2Mw28_KYQAAALg"]
[Tue Jul 21 08:36:30.097180 2026] [security2:error] [pid 466512:tid 466657] [client 187.125.243.197:61077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZviKGokixMSfKDOfvHwAAAiM"]
[Tue Jul 21 08:36:30.097307 2026] [security2:error] [pid 466512:tid 466657] [client 187.125.243.197:61077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZviKGokixMSfKDOfvHwAAAiM"]
[Tue Jul 21 08:36:30.268217 2026] [security2:error] [pid 465652:tid 465893] [client 173.252.95.59:32830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ZvjzTqJoBC2Mw28_KcQAAAPQ"]
[Tue Jul 21 08:36:30.279836 2026] [security2:error] [pid 466512:tid 466646] [client 62.164.177.222:48006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/new/xmlrpc.php"] [unique_id "al9ZviKGokixMSfKDOfvJwAAAhg"]
[Tue Jul 21 08:36:30.279919 2026] [security2:error] [pid 466512:tid 466646] [client 62.164.177.222:48006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/new/xmlrpc.php"] [unique_id "al9ZviKGokixMSfKDOfvJwAAAhg"]
[Tue Jul 21 08:36:30.645949 2026] [security2:error] [pid 466512:tid 466712] [client 20.226.60.151:64005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/6.php"] [unique_id "al9ZviKGokixMSfKDOfvbgAAAlo"]
[Tue Jul 21 08:36:30.851206 2026] [security2:error] [pid 466512:tid 466718] [client 20.206.105.145:22110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9ZviKGokixMSfKDOfvggAAAmA"]
[Tue Jul 21 08:36:31.119089 2026] [security2:error] [pid 466512:tid 466750] [client 20.226.60.151:64122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/32e17094cfindex.php"] [unique_id "al9ZvyKGokixMSfKDOfviAAAAoA"]
[Tue Jul 21 08:36:31.120958 2026] [security2:error] [pid 466512:tid 466733] [client 74.249.245.134:20361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/a1.php"] [unique_id "al9ZvyKGokixMSfKDOfviQAAAm8"]
[Tue Jul 21 08:36:31.183786 2026] [security2:error] [pid 466512:tid 466656] [client 159.223.41.76:52726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bubaby.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZvyKGokixMSfKDOfviwAAAiI"]
[Tue Jul 21 08:36:31.188600 2026] [security2:error] [pid 466512:tid 466675] [client 195.49.128.211:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZvyKGokixMSfKDOfvjAAAAjU"]
[Tue Jul 21 08:36:31.188744 2026] [security2:error] [pid 466512:tid 466675] [client 195.49.128.211:61389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZvyKGokixMSfKDOfvjAAAAjU"]
[Tue Jul 21 08:36:31.428316 2026] [security2:error] [pid 466512:tid 466618] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZvyKGokixMSfKDOfvkAACkmk"]
[Tue Jul 21 08:36:31.428486 2026] [security2:error] [pid 466512:tid 466768] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZvyKGokixMSfKDOfvkAACkmk"]
[Tue Jul 21 08:36:31.496531 2026] [security2:error] [pid 466512:tid 466691] [client 20.226.60.151:59286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/qqqa.php"] [unique_id "al9ZvyKGokixMSfKDOfvkgAAAkU"]
[Tue Jul 21 08:36:31.528333 2026] [security2:error] [pid 466512:tid 466758] [client 223.181.60.88:31953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZvyKGokixMSfKDOfvkwAAAog"]
[Tue Jul 21 08:36:31.528579 2026] [security2:error] [pid 466512:tid 466758] [client 223.181.60.88:31953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZvyKGokixMSfKDOfvkwAAAog"]
[Tue Jul 21 08:36:31.577324 2026] [security2:error] [pid 466512:tid 466726] [client 62.164.177.222:53470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/wp-login.php"] [unique_id "al9ZvyKGokixMSfKDOfvlAAAAmg"]
[Tue Jul 21 08:36:31.624986 2026] [security2:error] [pid 465652:tid 465730] [remote 139.59.136.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.136.59.139.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "deiacakes.com"] [uri "/info.php"] [unique_id "al9ZvzzTqJoBC2Mw28_KiQAAhk0"]
[Tue Jul 21 08:36:31.628804 2026] [security2:error] [pid 465652:tid 465675] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZvzzTqJoBC2Mw28_KkAAAuxY"]
[Tue Jul 21 08:36:31.628957 2026] [security2:error] [pid 465652:tid 465836] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZvzzTqJoBC2Mw28_KkAAAuxY"]
[Tue Jul 21 08:36:31.690610 2026] [security2:error] [pid 466512:tid 466643] [client 20.226.60.151:59278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/aunmc.php"] [unique_id "al9ZvyKGokixMSfKDOfvmAAAAhU"]
[Tue Jul 21 08:36:31.823012 2026] [security2:error] [pid 466512:tid 466740] [client 20.226.60.151:64050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/uoocf.php"] [unique_id "al9ZvyKGokixMSfKDOfvmgAAAnY"]
[Tue Jul 21 08:36:31.911632 2026] [security2:error] [pid 465652:tid 465873] [client 74.249.245.134:7654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/w.php"] [unique_id "al9ZvzzTqJoBC2Mw28_KkgAAAOA"]
[Tue Jul 21 08:36:32.344308 2026] [security2:error] [pid 466512:tid 466655] [client 20.226.60.151:59316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/iywwi.php"] [unique_id "al9ZwCKGokixMSfKDOfvowAAAiE"]
[Tue Jul 21 08:36:32.378384 2026] [security2:error] [pid 465652:tid 465715] [remote 65.60.38.74:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.38.60.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9ZwDzTqJoBC2Mw28_KlwAAtz4"]
[Tue Jul 21 08:36:32.689587 2026] [security2:error] [pid 466512:tid 466696] [client 20.226.60.151:64055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/gqgsa.php"] [unique_id "al9ZwCKGokixMSfKDOfvqgAAAko"]
[Tue Jul 21 08:36:32.749265 2026] [security2:error] [pid 465652:tid 465902] [client 20.226.60.151:64041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/elbzl.php"] [unique_id "al9ZwDzTqJoBC2Mw28_KogAAAP0"]
[Tue Jul 21 08:36:32.772946 2026] [security2:error] [pid 466512:tid 466745] [client 20.220.225.223:56210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9ZwCKGokixMSfKDOfvqwAAAns"]
[Tue Jul 21 08:36:32.832048 2026] [security2:error] [pid 465652:tid 465866] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZwDzTqJoBC2Mw28_KmgAAANk"]
[Tue Jul 21 08:36:32.839925 2026] [security2:error] [pid 466512:tid 466713] [client 20.206.105.145:21999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wefile.php"] [unique_id "al9ZwCKGokixMSfKDOfvrQAAAls"]
[Tue Jul 21 08:36:32.858951 2026] [security2:error] [pid 466512:tid 466679] [client 20.226.60.151:64093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/adjig.php"] [unique_id "al9ZwCKGokixMSfKDOfvrgAAAjk"]
[Tue Jul 21 08:36:32.899745 2026] [security2:error] [pid 466512:tid 466694] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZwCKGokixMSfKDOfvrAACSCo"]
[Tue Jul 21 08:36:32.982910 2026] [security2:error] [pid 465652:tid 465852] [client 20.226.60.151:64107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/byp.php"] [unique_id "al9ZwDzTqJoBC2Mw28_KpQAAAMs"]
[Tue Jul 21 08:36:33.134525 2026] [security2:error] [pid 466512:tid 466652] [client 20.226.60.151:64059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/ortasekerli1.php"] [unique_id "al9ZwSKGokixMSfKDOfvswAAAh4"]
[Tue Jul 21 08:36:33.674030 2026] [security2:error] [pid 465652:tid 465810] [client 20.226.60.151:64052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/classwithtostring.php"] [unique_id "al9ZwTzTqJoBC2Mw28_KuwAAAKE"]
[Tue Jul 21 08:36:33.796581 2026] [security2:error] [pid 466512:tid 466680] [client 109.248.148.246:59416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9ZwSKGokixMSfKDOfvugAAAjo"]
[Tue Jul 21 08:36:33.796690 2026] [security2:error] [pid 466512:tid 466680] [client 109.248.148.246:59416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9ZwSKGokixMSfKDOfvugAAAjo"]
[Tue Jul 21 08:36:33.802002 2026] [security2:error] [pid 466512:tid 466754] [client 5.38.115.39:58402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZwSKGokixMSfKDOfvuwAAAoQ"]
[Tue Jul 21 08:36:33.802144 2026] [security2:error] [pid 466512:tid 466754] [client 5.38.115.39:58402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZwSKGokixMSfKDOfvuwAAAoQ"]
[Tue Jul 21 08:36:34.035035 2026] [security2:error] [pid 466512:tid 466572] [remote 160.187.68.132:35554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colegioperseveranca.com"] [uri "/wp-login.php"] [unique_id "al9ZwSKGokixMSfKDOfvrwACdTs"]
[Tue Jul 21 08:36:34.055667 2026] [security2:error] [pid 465652:tid 465695] [remote 45.79.123.44:44628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "psicologafernandaguedes.com"] [uri "/wp-login.php"] [unique_id "al9ZwjzTqJoBC2Mw28_KvwAAnCo"]
[Tue Jul 21 08:36:34.179336 2026] [security2:error] [pid 465652:tid 465722] [remote 216.73.216.184:11115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9ZwjzTqJoBC2Mw28_KwwAAikU"]
[Tue Jul 21 08:36:34.306639 2026] [security2:error] [pid 466512:tid 466655] [client 20.226.60.151:64027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/root.php"] [unique_id "al9ZwiKGokixMSfKDOfvwgAAAiE"]
[Tue Jul 21 08:36:34.629242 2026] [security2:error] [pid 465652:tid 465811] [client 74.249.245.134:7658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/wp-good.php"] [unique_id "al9ZwjzTqJoBC2Mw28_KygAAAKI"]
[Tue Jul 21 08:36:34.798261 2026] [security2:error] [pid 466512:tid 466677] [client 213.152.186.163:54064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9ZwiKGokixMSfKDOfvxQAAAjc"]
[Tue Jul 21 08:36:34.798368 2026] [security2:error] [pid 466512:tid 466677] [client 213.152.186.163:54064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9ZwiKGokixMSfKDOfvxQAAAjc"]
[Tue Jul 21 08:36:34.873615 2026] [security2:error] [pid 466512:tid 466763] [client 20.220.225.223:2384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9ZwiKGokixMSfKDOfvyAAAAo0"]
[Tue Jul 21 08:36:34.918236 2026] [security2:error] [pid 465652:tid 465794] [client 5.31.193.106:58708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZwjzTqJoBC2Mw28_K0gAAAJE"]
[Tue Jul 21 08:36:34.918381 2026] [security2:error] [pid 465652:tid 465794] [client 5.31.193.106:58708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZwjzTqJoBC2Mw28_K0gAAAJE"]
[Tue Jul 21 08:36:34.980927 2026] [security2:error] [pid 466512:tid 466695] [client 159.223.41.76:65062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bubaby.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZwiKGokixMSfKDOfvyQAAAkk"]
[Tue Jul 21 08:36:34.981050 2026] [security2:error] [pid 466512:tid 466695] [client 159.223.41.76:65062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bubaby.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZwiKGokixMSfKDOfvyQAAAkk"]
[Tue Jul 21 08:36:35.010454 2026] [security2:error] [pid 465652:tid 465808] [client 20.226.60.151:64043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/sym403.php"] [unique_id "al9ZwzzTqJoBC2Mw28_K1AAAAJ8"]
[Tue Jul 21 08:36:35.028487 2026] [security2:error] [pid 465652:tid 465860] [client 14.245.224.124:50651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZwzzTqJoBC2Mw28_K1QAAANM"]
[Tue Jul 21 08:36:35.028619 2026] [security2:error] [pid 465652:tid 465860] [client 14.245.224.124:50651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZwzzTqJoBC2Mw28_K1QAAANM"]
[Tue Jul 21 08:36:35.766423 2026] [security2:error] [pid 466512:tid 466768] [client 20.226.60.151:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/v543.php"] [unique_id "al9ZwyKGokixMSfKDOfv1AAAApI"]
[Tue Jul 21 08:36:35.814529 2026] [security2:error] [pid 466512:tid 466708] [client 69.171.230.42:38682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ZwyKGokixMSfKDOfv1QAAAlY"]
[Tue Jul 21 08:36:35.875962 2026] [security2:error] [pid 465652:tid 465790] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZwzzTqJoBC2Mw28_K3AAAAI0"]
[Tue Jul 21 08:36:35.888645 2026] [security2:error] [pid 466512:tid 466644] [client 128.127.105.184:51532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZwyKGokixMSfKDOfv1wAAAhY"]
[Tue Jul 21 08:36:35.888728 2026] [security2:error] [pid 466512:tid 466644] [client 128.127.105.184:51532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZwyKGokixMSfKDOfv1wAAAhY"]
[Tue Jul 21 08:36:36.091885 2026] [security2:error] [pid 465652:tid 465825] [client 20.226.60.151:64018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/sixxis.php"] [unique_id "al9ZxDzTqJoBC2Mw28_K6wAAALA"]
[Tue Jul 21 08:36:36.331794 2026] [security2:error] [pid 465652:tid 465881] [client 20.226.60.151:64009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/ip.php"] [unique_id "al9ZxDzTqJoBC2Mw28_K7wAAAOg"]
[Tue Jul 21 08:36:36.499897 2026] [security2:error] [pid 465652:tid 465841] [client 20.226.60.151:64044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/kq1.php"] [unique_id "al9ZxDzTqJoBC2Mw28_K8gAAAMA"]
[Tue Jul 21 08:36:36.785667 2026] [security2:error] [pid 466512:tid 466705] [client 49.144.66.253:32008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZxCKGokixMSfKDOfv4AAAAlM"]
[Tue Jul 21 08:36:36.785824 2026] [security2:error] [pid 466512:tid 466705] [client 49.144.66.253:32008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZxCKGokixMSfKDOfv4AAAAlM"]
[Tue Jul 21 08:36:36.944667 2026] [security2:error] [pid 466512:tid 466741] [client 152.59.34.51:53540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZxCKGokixMSfKDOfv5AAAAnc"]
[Tue Jul 21 08:36:36.944834 2026] [security2:error] [pid 466512:tid 466741] [client 152.59.34.51:53540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZxCKGokixMSfKDOfv5AAAAnc"]
[Tue Jul 21 08:36:37.131112 2026] [security2:error] [pid 466512:tid 466715] [client 74.249.245.134:15788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/.info.php"] [unique_id "al9ZxSKGokixMSfKDOfv6QAAAl0"]
[Tue Jul 21 08:36:37.463853 2026] [security2:error] [pid 466512:tid 466677] [client 20.226.60.151:64006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/fw/faiyy.php"] [unique_id "al9ZxSKGokixMSfKDOfwDgAAAjc"]
[Tue Jul 21 08:36:37.548218 2026] [security2:error] [pid 466512:tid 466664] [client 152.59.181.104:51000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZxSKGokixMSfKDOfwJQAAAio"]
[Tue Jul 21 08:36:37.548306 2026] [security2:error] [pid 466512:tid 466664] [client 152.59.181.104:51000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZxSKGokixMSfKDOfwJQAAAio"]
[Tue Jul 21 08:36:37.582182 2026] [security2:error] [pid 466512:tid 466734] [client 20.206.105.145:22105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9ZxSKGokixMSfKDOfwKwAAAnA"]
[Tue Jul 21 08:36:37.642084 2026] [security2:error] [pid 465652:tid 465890] [client 122.176.100.127:65113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZxTzTqJoBC2Mw28_LCAAAAPE"]
[Tue Jul 21 08:36:37.642215 2026] [security2:error] [pid 465652:tid 465890] [client 122.176.100.127:65113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ZxTzTqJoBC2Mw28_LCAAAAPE"]
[Tue Jul 21 08:36:37.789361 2026] [security2:error] [pid 466512:tid 466764] [client 195.49.128.211:54104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZxSKGokixMSfKDOfwLwAAAo4"]
[Tue Jul 21 08:36:37.789470 2026] [security2:error] [pid 466512:tid 466764] [client 195.49.128.211:54104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ZxSKGokixMSfKDOfwLwAAAo4"]
[Tue Jul 21 08:36:37.959491 2026] [security2:error] [pid 465652:tid 465662] [remote 84.247.172.23:49684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "legadoengenhariaam.com.br"] [uri "/wp-login.php"] [unique_id "al9ZxTzTqJoBC2Mw28_LDAAA4Ak"]
[Tue Jul 21 08:36:37.978127 2026] [security2:error] [pid 465652:tid 465869] [client 103.59.206.240:31504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZxTzTqJoBC2Mw28_LDQAAANw"]
[Tue Jul 21 08:36:37.978240 2026] [security2:error] [pid 465652:tid 465869] [client 103.59.206.240:31504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZxTzTqJoBC2Mw28_LDQAAANw"]
[Tue Jul 21 08:36:38.011013 2026] [security2:error] [pid 466512:tid 466755] [client 20.226.60.151:64031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/h02ugyh.php"] [unique_id "al9ZxiKGokixMSfKDOfwMwAAAoU"]
[Tue Jul 21 08:36:38.155333 2026] [security2:error] [pid 465652:tid 465674] [remote 207.180.241.245:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "falarmelhor.com.br"] [uri "/wp-login.php"] [unique_id "al9ZxjzTqJoBC2Mw28_LEQAAuhU"]
[Tue Jul 21 08:36:38.552131 2026] [security2:error] [pid 466512:tid 466691] [client 20.226.60.151:64007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-temp.php"] [unique_id "al9ZxiKGokixMSfKDOfwOAAAAkU"]
[Tue Jul 21 08:36:38.744789 2026] [security2:error] [pid 465652:tid 465790] [client 213.152.186.163:45158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9ZxjzTqJoBC2Mw28_LHwAAAI0"]
[Tue Jul 21 08:36:38.744944 2026] [security2:error] [pid 465652:tid 465790] [client 213.152.186.163:45158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9ZxjzTqJoBC2Mw28_LHwAAAI0"]
[Tue Jul 21 08:36:38.834615 2026] [security2:error] [pid 465652:tid 465791] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZxjzTqJoBC2Mw28_LFgAAAI4"]
[Tue Jul 21 08:36:39.523292 2026] [security2:error] [pid 466512:tid 466717] [client 20.226.60.151:59291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-content/cong.php"] [unique_id "al9ZxyKGokixMSfKDOfwRAAAAl8"]
[Tue Jul 21 08:36:40.352149 2026] [qos:error] [pid 466512:tid 466712] [client 179.208.137.251:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9ZyCKGokixMSfKDOfxIQAAAlo, referer: https://woma.com.br/
[Tue Jul 21 08:36:40.352155 2026] [qos:error] [pid 466512:tid 466763] [client 179.208.137.251:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9ZyCKGokixMSfKDOfxJAAAAo0, referer: https://woma.com.br/
[Tue Jul 21 08:36:40.352239 2026] [qos:error] [pid 466512:tid 466667] [client 179.208.137.251:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9ZyCKGokixMSfKDOfxCQAAAi0, referer: https://woma.com.br/
[Tue Jul 21 08:36:40.353524 2026] [qos:error] [pid 466512:tid 466707] [client 179.208.137.251:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.6.100.222, id=al9ZyCKGokixMSfKDOfxKgAAAlU, referer: https://woma.com.br/
[Tue Jul 21 08:36:40.353556 2026] [qos:error] [pid 466512:tid 466704] [client 179.208.137.251:0] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=102, c=50.6.100.222, id=al9ZyCKGokixMSfKDOfxNAAAAlI, referer: https://woma.com.br/
[Tue Jul 21 08:36:40.365111 2026] [security2:error] [pid 466512:tid 466764] [client 74.7.230.62:43514] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "comercialdoprodutor.com.br"] [uri "/robots.txt"] [unique_id "al9ZyCKGokixMSfKDOfxJgACjjU"]
[Tue Jul 21 08:36:40.424710 2026] [security2:error] [pid 466512:tid 466744] [client 117.213.202.34:60159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZyCKGokixMSfKDOfxSwAAAno"]
[Tue Jul 21 08:36:40.424868 2026] [security2:error] [pid 466512:tid 466744] [client 117.213.202.34:60159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZyCKGokixMSfKDOfxSwAAAno"]
[Tue Jul 21 08:36:40.524858 2026] [security2:error] [pid 466512:tid 466769] [client 202.179.75.202:42152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZyCKGokixMSfKDOfxTQAAApM"]
[Tue Jul 21 08:36:40.524963 2026] [security2:error] [pid 466512:tid 466769] [client 202.179.75.202:42152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ZyCKGokixMSfKDOfxTQAAApM"]
[Tue Jul 21 08:36:40.559343 2026] [security2:error] [pid 465652:tid 465881] [client 187.125.243.197:61575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZyDzTqJoBC2Mw28_LXgAAAOg"]
[Tue Jul 21 08:36:40.560707 2026] [security2:error] [pid 465652:tid 465881] [client 187.125.243.197:61575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZyDzTqJoBC2Mw28_LXgAAAOg"]
[Tue Jul 21 08:36:41.267508 2026] [core:error] [pid 466512:tid 466570] [remote 52.167.144.209:14692] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:36:41.267531 2026] [core:error] [pid 466512:tid 466570] [remote 52.167.144.209:14692] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:36:41.345281 2026] [security2:error] [pid 465652:tid 465817] [client 20.206.105.145:22221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/2P.php"] [unique_id "al9ZyTzTqJoBC2Mw28_LbQAAAKg"]
[Tue Jul 21 08:36:41.397293 2026] [core:error] [pid 466512:tid 466568] [remote 52.167.144.209:14692] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:36:41.397318 2026] [core:error] [pid 466512:tid 466568] [remote 52.167.144.209:14692] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:36:41.746836 2026] [security2:error] [pid 466512:tid 466746] [client 109.248.148.246:43594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9ZySKGokixMSfKDOfxXgAAAnw"]
[Tue Jul 21 08:36:41.746944 2026] [security2:error] [pid 466512:tid 466746] [client 109.248.148.246:43594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9ZySKGokixMSfKDOfxXgAAAnw"]
[Tue Jul 21 08:36:41.765007 2026] [security2:error] [pid 466512:tid 466768] [client 103.151.46.103:56961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZySKGokixMSfKDOfxXwAAApI"]
[Tue Jul 21 08:36:41.765170 2026] [security2:error] [pid 466512:tid 466768] [client 103.151.46.103:56961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9ZySKGokixMSfKDOfxXwAAApI"]
[Tue Jul 21 08:36:41.782727 2026] [security2:error] [pid 466512:tid 466690] [client 195.49.128.211:62206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZySKGokixMSfKDOfxYAAAAkQ"]
[Tue Jul 21 08:36:41.782852 2026] [security2:error] [pid 466512:tid 466690] [client 195.49.128.211:62206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ZySKGokixMSfKDOfxYAAAAkQ"]
[Tue Jul 21 08:36:41.798712 2026] [security2:error] [pid 465652:tid 465858] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZyTzTqJoBC2Mw28_LbAAAANE"]
[Tue Jul 21 08:36:41.858028 2026] [security2:error] [pid 465652:tid 465664] [remote 20.153.140.50:36716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/wp-login.php"] [unique_id "al9ZyTzTqJoBC2Mw28_LdgAA5As"]
[Tue Jul 21 08:36:42.009851 2026] [security2:error] [pid 465652:tid 465833] [client 173.252.95.60:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ZyDzTqJoBC2Mw28_LZgAAALg"]
[Tue Jul 21 08:36:42.026676 2026] [security2:error] [pid 466512:tid 466613] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZyiKGokixMSfKDOfxZgACQ2Q"]
[Tue Jul 21 08:36:42.026853 2026] [security2:error] [pid 466512:tid 466689] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ZyiKGokixMSfKDOfxZgACQ2Q"]
[Tue Jul 21 08:36:42.262197 2026] [security2:error] [pid 466512:tid 466553] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZyiKGokixMSfKDOfxaAACKig"]
[Tue Jul 21 08:36:42.262313 2026] [security2:error] [pid 466512:tid 466664] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ZyiKGokixMSfKDOfxaAACKig"]
[Tue Jul 21 08:36:42.603212 2026] [security2:error] [pid 466512:tid 466721] [client 20.220.225.223:46967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/dp.php"] [unique_id "al9ZyiKGokixMSfKDOfxcQAAAmM"]
[Tue Jul 21 08:36:42.607975 2026] [security2:error] [pid 466512:tid 466656] [client 20.206.105.145:22014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/.well-known/about.php"] [unique_id "al9ZyiKGokixMSfKDOfxcgAAAiI"]
[Tue Jul 21 08:36:42.704756 2026] [security2:error] [pid 465652:tid 465786] [client 74.249.245.134:54621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/item.php"] [unique_id "al9ZyjzTqJoBC2Mw28_L2wAAAIk"]
[Tue Jul 21 08:36:43.055908 2026] [security2:error] [pid 466512:tid 466717] [client 20.226.60.151:64045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-includes/css/index.php"] [unique_id "al9ZyyKGokixMSfKDOfxnwAAAl8"]
[Tue Jul 21 08:36:43.142193 2026] [security2:error] [pid 466512:tid 466736] [client 20.226.60.151:64123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/jj.php"] [unique_id "al9ZyyKGokixMSfKDOfxowAAAnI"]
[Tue Jul 21 08:36:43.143801 2026] [security2:error] [pid 466512:tid 466679] [client 223.181.60.88:29368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZyyKGokixMSfKDOfxpAAAAjk"]
[Tue Jul 21 08:36:43.144006 2026] [security2:error] [pid 466512:tid 466679] [client 223.181.60.88:29368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ZyyKGokixMSfKDOfxpAAAAjk"]
[Tue Jul 21 08:36:43.350799 2026] [security2:error] [pid 466512:tid 466733] [client 20.226.60.151:64098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/class-walker-footer-dev.php"] [unique_id "al9ZyyKGokixMSfKDOfxqQAAAm8"]
[Tue Jul 21 08:36:43.619849 2026] [security2:error] [pid 466512:tid 466649] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ZyyKGokixMSfKDOfxqgACG1Q"]
[Tue Jul 21 08:36:43.774590 2026] [security2:error] [pid 465652:tid 465871] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZyzzTqJoBC2Mw28_MJQAAAN4"]
[Tue Jul 21 08:36:43.808331 2026] [security2:error] [pid 466512:tid 466702] [client 20.206.105.145:21994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9ZyyKGokixMSfKDOfxswAAAlA"]
[Tue Jul 21 08:36:43.811210 2026] [security2:error] [pid 466512:tid 466691] [client 185.198.240.186:33531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9ZyyKGokixMSfKDOfxsgAAAkU"]
[Tue Jul 21 08:36:43.829554 2026] [security2:error] [pid 466512:tid 466646] [client 20.226.60.151:64077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/txets.php"] [unique_id "al9ZyyKGokixMSfKDOfxtAAAAhg"]
[Tue Jul 21 08:36:43.914255 2026] [security2:error] [pid 466512:tid 466769] [client 20.226.60.151:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/dex.php"] [unique_id "al9ZyyKGokixMSfKDOfxtgAAApM"]
[Tue Jul 21 08:36:43.978840 2026] [security2:error] [pid 466512:tid 466678] [client 185.198.240.213:42247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9ZyyKGokixMSfKDOfxsQAAAjg"]
[Tue Jul 21 08:36:44.003958 2026] [security2:error] [pid 466512:tid 466718] [client 61.1.167.83:63395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZzCKGokixMSfKDOfxtwAAAmA"]
[Tue Jul 21 08:36:44.004095 2026] [security2:error] [pid 466512:tid 466718] [client 61.1.167.83:63395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZzCKGokixMSfKDOfxtwAAAmA"]
[Tue Jul 21 08:36:44.073415 2026] [security2:error] [pid 465652:tid 465805] [client 20.226.60.151:59082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/xpwer1.php"] [unique_id "al9ZzDzTqJoBC2Mw28_MNgAAAJw"]
[Tue Jul 21 08:36:44.260077 2026] [security2:error] [pid 466512:tid 466655] [client 20.226.60.151:64026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/flox.php"] [unique_id "al9ZzCKGokixMSfKDOfxvQAAAiE"]
[Tue Jul 21 08:36:44.376153 2026] [security2:error] [pid 466512:tid 466659] [client 20.220.225.223:46965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/old.php"] [unique_id "al9ZzCKGokixMSfKDOfxvwAAAiU"]
[Tue Jul 21 08:36:44.439698 2026] [security2:error] [pid 466512:tid 466693] [client 5.38.115.39:1166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZzCKGokixMSfKDOfxwAAAAkc"]
[Tue Jul 21 08:36:44.439869 2026] [security2:error] [pid 466512:tid 466693] [client 5.38.115.39:1166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ZzCKGokixMSfKDOfxwAAAAkc"]
[Tue Jul 21 08:36:44.539954 2026] [core:error] [pid 466512:tid 466539] [remote 40.77.167.74:54723] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:36:44.539975 2026] [core:error] [pid 466512:tid 466539] [remote 40.77.167.74:54723] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:36:44.569015 2026] [security2:error] [pid 466512:tid 466657] [client 20.206.105.145:22118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/bob.php"] [unique_id "al9ZzCKGokixMSfKDOfxwgAAAiM"]
[Tue Jul 21 08:36:44.660085 2026] [security2:error] [pid 466512:tid 466759] [client 20.226.60.151:59074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/popo.php"] [unique_id "al9ZzCKGokixMSfKDOfxwwAAAok"]
[Tue Jul 21 08:36:44.866467 2026] [security2:error] [pid 466512:tid 466667] [client 209.141.34.121:53893] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "escadasparana.com.br"] [uri "/"] [unique_id "al9ZzCKGokixMSfKDOfxygAAAi0"]
[Tue Jul 21 08:36:45.127704 2026] [security2:error] [pid 465652:tid 465843] [client 20.226.60.151:59324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/yas.php"] [unique_id "al9ZzTzTqJoBC2Mw28_MTwAAAMI"]
[Tue Jul 21 08:36:45.227391 2026] [security2:error] [pid 466512:tid 466717] [client 20.226.60.151:64114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/file61.php"] [unique_id "al9ZzSKGokixMSfKDOfxzQAAAl8"]
[Tue Jul 21 08:36:45.392201 2026] [security2:error] [pid 466512:tid 466765] [client 20.226.60.151:59284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/water.php"] [unique_id "al9ZzSKGokixMSfKDOfx0AAAAo8"]
[Tue Jul 21 08:36:45.394280 2026] [security2:error] [pid 465652:tid 465856] [client 209.141.34.121:53931] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "escadasparana.com.br"] [uri "/"] [unique_id "al9ZzTzTqJoBC2Mw28_MVwAAAM8"]
[Tue Jul 21 08:36:45.443763 2026] [security2:error] [pid 466512:tid 466716] [client 20.226.60.151:59272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/nano.php"] [unique_id "al9ZzSKGokixMSfKDOfx0gAAAl4"]
[Tue Jul 21 08:36:45.505285 2026] [security2:error] [pid 466512:tid 466736] [client 20.226.60.151:64083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/moon.php"] [unique_id "al9ZzSKGokixMSfKDOfx1QAAAnI"]
[Tue Jul 21 08:36:45.547562 2026] [security2:error] [pid 465652:tid 465887] [client 65.21.113.253:48568] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ZzTzTqJoBC2Mw28_MTQAAAO4"]
[Tue Jul 21 08:36:45.582561 2026] [security2:error] [pid 466512:tid 466711] [client 20.226.60.151:64097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-info.php"] [unique_id "al9ZzSKGokixMSfKDOfx1gAAAlk"]
[Tue Jul 21 08:36:45.668375 2026] [core:error] [pid 466512:tid 466637] [remote 52.167.144.173:14976] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:36:45.669215 2026] [core:error] [pid 466512:tid 466637] [remote 52.167.144.173:14976] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:36:45.739333 2026] [security2:error] [pid 465652:tid 465888] [client 14.245.224.124:51118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZzTzTqJoBC2Mw28_MXQAAAO8"]
[Tue Jul 21 08:36:45.739430 2026] [security2:error] [pid 465652:tid 465888] [client 14.245.224.124:51118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ZzTzTqJoBC2Mw28_MXQAAAO8"]
[Tue Jul 21 08:36:45.803488 2026] [security2:error] [pid 466512:tid 466762] [client 20.226.60.151:64095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/2000.php"] [unique_id "al9ZzSKGokixMSfKDOfx2wAAAow"]
[Tue Jul 21 08:36:46.038327 2026] [security2:error] [pid 466512:tid 466682] [client 20.206.105.145:22099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/crgio.php"] [unique_id "al9ZziKGokixMSfKDOfx3gAAAjw"]
[Tue Jul 21 08:36:46.128685 2026] [security2:error] [pid 466512:tid 466703] [client 109.248.148.246:43600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZziKGokixMSfKDOfx3wAAAlE"]
[Tue Jul 21 08:36:46.128786 2026] [security2:error] [pid 466512:tid 466703] [client 109.248.148.246:43600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ZziKGokixMSfKDOfx3wAAAlE"]
[Tue Jul 21 08:36:46.177759 2026] [security2:error] [pid 466512:tid 466749] [client 20.226.60.151:59295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/122.php"] [unique_id "al9ZziKGokixMSfKDOfx4AAAAn8"]
[Tue Jul 21 08:36:46.639439 2026] [security2:error] [pid 466512:tid 466538] [remote 103.161.172.221:51234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "equoterapiaprosseguir.com"] [uri "/wp-login.php"] [unique_id "al9ZziKGokixMSfKDOfx9AACQRk"]
[Tue Jul 21 08:36:46.840674 2026] [security2:error] [pid 466512:tid 466680] [client 20.206.105.145:22218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/pucci.php"] [unique_id "al9ZziKGokixMSfKDOfx-AAAAjo"]
[Tue Jul 21 08:36:46.919883 2026] [security2:error] [pid 466512:tid 466722] [client 152.59.34.51:54016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZziKGokixMSfKDOfx-QAAAmQ"]
[Tue Jul 21 08:36:46.920024 2026] [security2:error] [pid 466512:tid 466722] [client 152.59.34.51:54016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ZziKGokixMSfKDOfx-QAAAmQ"]
[Tue Jul 21 08:36:47.266647 2026] [security2:error] [pid 466512:tid 466645] [client 49.144.66.253:32148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZzyKGokixMSfKDOfyAwAAAhc"]
[Tue Jul 21 08:36:47.266775 2026] [security2:error] [pid 466512:tid 466645] [client 49.144.66.253:32148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ZzyKGokixMSfKDOfyAwAAAhc"]
[Tue Jul 21 08:36:47.428610 2026] [security2:error] [pid 466512:tid 466517] [remote 45.117.83.212:42044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/wp-login.php"] [unique_id "al9ZzyKGokixMSfKDOfyBAACFQQ"]
[Tue Jul 21 08:36:47.489081 2026] [security2:error] [pid 466512:tid 466753] [client 20.226.60.151:64065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/mds.php"] [unique_id "al9ZzyKGokixMSfKDOfyBgAAAoM"]
[Tue Jul 21 08:36:47.693012 2026] [security2:error] [pid 466512:tid 466740] [client 59.95.197.55:50200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZziKGokixMSfKDOfx8wAAAnY"]
[Tue Jul 21 08:36:47.693185 2026] [security2:error] [pid 466512:tid 466740] [client 59.95.197.55:50200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ZziKGokixMSfKDOfx8wAAAnY"]
[Tue Jul 21 08:36:47.777536 2026] [security2:error] [pid 466512:tid 466664] [client 89.238.167.134:34494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9ZzyKGokixMSfKDOfyCAAAAio"]
[Tue Jul 21 08:36:47.777628 2026] [security2:error] [pid 466512:tid 466664] [client 89.238.167.134:34494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9ZzyKGokixMSfKDOfyCAAAAio"]
[Tue Jul 21 08:36:48.086212 2026] [security2:error] [pid 466512:tid 466699] [client 122.176.100.127:49245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Z0CKGokixMSfKDOfyDQAAAk0"]
[Tue Jul 21 08:36:48.086393 2026] [security2:error] [pid 466512:tid 466699] [client 122.176.100.127:49245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Z0CKGokixMSfKDOfyDQAAAk0"]
[Tue Jul 21 08:36:48.178163 2026] [core:alert] [pid 465652:tid 465789] [client 57.141.18.26:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:36:48.202583 2026] [security2:error] [pid 466512:tid 466728] [client 20.226.60.151:64118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-blink.php"] [unique_id "al9Z0CKGokixMSfKDOfyEQAAAmo"]
[Tue Jul 21 08:36:48.244314 2026] [security2:error] [pid 465652:tid 465784] [client 152.59.181.104:51431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z0DzTqJoBC2Mw28_MiAAAAIc"]
[Tue Jul 21 08:36:48.244438 2026] [security2:error] [pid 465652:tid 465784] [client 152.59.181.104:51431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z0DzTqJoBC2Mw28_MiAAAAIc"]
[Tue Jul 21 08:36:48.343788 2026] [security2:error] [pid 466512:tid 466542] [remote 154.0.166.254:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samilacalculos.com.br"] [uri "/wp-login.php"] [unique_id "al9Z0CKGokixMSfKDOfyFQACUB0"]
[Tue Jul 21 08:36:48.446564 2026] [security2:error] [pid 466512:tid 466741] [client 195.49.128.211:54722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Z0CKGokixMSfKDOfyGQAAAnc"]
[Tue Jul 21 08:36:48.446663 2026] [security2:error] [pid 466512:tid 466741] [client 195.49.128.211:54722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Z0CKGokixMSfKDOfyGQAAAnc"]
[Tue Jul 21 08:36:48.485697 2026] [security2:error] [pid 466512:tid 466666] [client 20.10.88.227:3520] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gnxinox.com.br"] [uri "/index.php"] [unique_id "al9Z0CKGokixMSfKDOfyFgAAAiw"]
[Tue Jul 21 08:36:48.529363 2026] [security2:error] [pid 465652:tid 465882] [client 20.226.60.151:64057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/zc-208.php"] [unique_id "al9Z0DzTqJoBC2Mw28_MjQAAAOk"]
[Tue Jul 21 08:36:48.780361 2026] [security2:error] [pid 465652:tid 465668] [remote 38.242.157.30:33426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fit4me.online"] [uri "/wp-login.php"] [unique_id "al9Z0DzTqJoBC2Mw28_MlQAA-Q8"]
[Tue Jul 21 08:36:48.954550 2026] [security2:error] [pid 466512:tid 466697] [client 20.226.60.151:64081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/sid4.php"] [unique_id "al9Z0CKGokixMSfKDOfyHwAAAks"]
[Tue Jul 21 08:36:49.724972 2026] [security2:error] [pid 466512:tid 466751] [client 20.206.105.145:22103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-temp.php"] [unique_id "al9Z0SKGokixMSfKDOfyLQAAAoE"]
[Tue Jul 21 08:36:49.740085 2026] [security2:error] [pid 466512:tid 466599] [remote 124.55.178.99:38774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z0SKGokixMSfKDOfyLgACg1Y"]
[Tue Jul 21 08:36:49.740364 2026] [security2:error] [pid 466512:tid 466753] [client 124.55.178.99:38774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z0SKGokixMSfKDOfyLgACg1Y"]
[Tue Jul 21 08:36:49.780967 2026] [security2:error] [pid 466512:tid 466657] [client 109.248.148.246:44188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Z0SKGokixMSfKDOfyVgAAAiM"]
[Tue Jul 21 08:36:49.781077 2026] [security2:error] [pid 466512:tid 466657] [client 109.248.148.246:44188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Z0SKGokixMSfKDOfyVgAAAiM"]
[Tue Jul 21 08:36:49.830928 2026] [security2:error] [pid 466512:tid 466689] [client 20.226.60.151:59264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wmore1.php"] [unique_id "al9Z0SKGokixMSfKDOfyWAAAAkM"]
[Tue Jul 21 08:36:50.107897 2026] [security2:error] [pid 465652:tid 465864] [client 20.206.105.145:21964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9Z0jzTqJoBC2Mw28_MswAAANc"]
[Tue Jul 21 08:36:50.221336 2026] [security2:error] [pid 465652:tid 465880] [client 20.226.60.151:64061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/solo1.php"] [unique_id "al9Z0jzTqJoBC2Mw28_MtAAAAOc"]
[Tue Jul 21 08:36:50.303650 2026] [security2:error] [pid 465652:tid 465730] [remote 62.60.130.128:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.extrapro21.com"] [uri "/"] [unique_id "al9Z0jzTqJoBC2Mw28_MtgAA-E0"]
[Tue Jul 21 08:36:50.563493 2026] [security2:error] [pid 465652:tid 465772] [remote 62.60.130.128:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.extrapro21.com"] [uri "/wp-json/batch/v1"] [unique_id "al9Z0jzTqJoBC2Mw28_MvwAAlXc"]
[Tue Jul 21 08:36:51.135214 2026] [security2:error] [pid 466512:tid 466698] [client 187.125.243.197:62070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Z0yKGokixMSfKDOfycAAAAkw"]
[Tue Jul 21 08:36:51.135387 2026] [security2:error] [pid 466512:tid 466698] [client 187.125.243.197:62070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Z0yKGokixMSfKDOfycAAAAkw"]
[Tue Jul 21 08:36:51.139299 2026] [security2:error] [pid 466512:tid 466666] [client 20.226.60.151:59279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/cong.php"] [unique_id "al9Z0yKGokixMSfKDOfycQAAAiw"]
[Tue Jul 21 08:36:51.278770 2026] [security2:error] [pid 466512:tid 466762] [client 117.213.202.34:60779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z0yKGokixMSfKDOfycwAAAow"]
[Tue Jul 21 08:36:51.278941 2026] [security2:error] [pid 466512:tid 466762] [client 117.213.202.34:60779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z0yKGokixMSfKDOfycwAAAow"]
[Tue Jul 21 08:36:51.328181 2026] [security2:error] [pid 466512:tid 466682] [client 103.59.206.240:31486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z0yKGokixMSfKDOfydQAAAjw"]
[Tue Jul 21 08:36:51.328288 2026] [security2:error] [pid 466512:tid 466682] [client 103.59.206.240:31486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z0yKGokixMSfKDOfydQAAAjw"]
[Tue Jul 21 08:36:51.704765 2026] [security2:error] [pid 466512:tid 466680] [client 202.179.75.202:39158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Z0yKGokixMSfKDOfyegAAAjo"]
[Tue Jul 21 08:36:51.704890 2026] [security2:error] [pid 466512:tid 466680] [client 202.179.75.202:39158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Z0yKGokixMSfKDOfyegAAAjo"]
[Tue Jul 21 08:36:51.901403 2026] [security2:error] [pid 466512:tid 466526] [remote 49.12.216.176:59134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Z0yKGokixMSfKDOfyfAACTw0"]
[Tue Jul 21 08:36:51.945348 2026] [security2:error] [pid 465652:tid 465903] [client 20.206.105.145:22142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/puc.php"] [unique_id "al9Z0zzTqJoBC2Mw28_M2QAAAP4"]
[Tue Jul 21 08:36:52.227830 2026] [security2:error] [pid 465652:tid 465792] [client 45.8.19.181:27629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luanaarruda.com"] [uri "/wp-login.php"] [unique_id "al9Z1DzTqJoBC2Mw28_M4AAAAI8"]
[Tue Jul 21 08:36:52.234078 2026] [security2:error] [pid 465652:tid 465855] [client 20.226.60.151:64010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/public/css.php"] [unique_id "al9Z1DzTqJoBC2Mw28_M4QAAAM4"]
[Tue Jul 21 08:36:52.425629 2026] [security2:error] [pid 465652:tid 465899] [client 195.49.128.211:62921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Z1DzTqJoBC2Mw28_M5gAAAPo"]
[Tue Jul 21 08:36:52.425762 2026] [security2:error] [pid 465652:tid 465899] [client 195.49.128.211:62921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Z1DzTqJoBC2Mw28_M5gAAAPo"]
[Tue Jul 21 08:36:52.583308 2026] [security2:error] [pid 466512:tid 466618] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Z1CKGokixMSfKDOfygwACKmk"]
[Tue Jul 21 08:36:52.583471 2026] [security2:error] [pid 466512:tid 466664] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Z1CKGokixMSfKDOfygwACKmk"]
[Tue Jul 21 08:36:52.610833 2026] [security2:error] [pid 466512:tid 466700] [client 20.226.60.151:59287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/output.php"] [unique_id "al9Z1CKGokixMSfKDOfyhAAAAk4"]
[Tue Jul 21 08:36:52.806039 2026] [security2:error] [pid 466512:tid 466663] [client 20.226.60.151:64030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-file-120.php"] [unique_id "al9Z1CKGokixMSfKDOfyhQAAAik"]
[Tue Jul 21 08:36:52.880770 2026] [security2:error] [pid 466512:tid 466534] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9Z1CKGokixMSfKDOfyhwACZRU"]
[Tue Jul 21 08:36:52.880968 2026] [security2:error] [pid 466512:tid 466723] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9Z1CKGokixMSfKDOfyhwACZRU"]
[Tue Jul 21 08:36:53.030654 2026] [security2:error] [pid 466512:tid 466674] [client 173.252.95.59:35930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Z1SKGokixMSfKDOfyiwAAAjQ"]
[Tue Jul 21 08:36:53.249693 2026] [security2:error] [pid 466512:tid 466707] [client 223.181.60.88:16429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Z1SKGokixMSfKDOfykAAAAlU"]
[Tue Jul 21 08:36:53.250520 2026] [security2:error] [pid 466512:tid 466707] [client 223.181.60.88:16429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Z1SKGokixMSfKDOfykAAAAlU"]
[Tue Jul 21 08:36:53.275706 2026] [security2:error] [pid 466512:tid 466764] [client 103.151.46.103:57477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Z1SKGokixMSfKDOfykQAAAo4"]
[Tue Jul 21 08:36:53.275863 2026] [security2:error] [pid 466512:tid 466764] [client 103.151.46.103:57477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Z1SKGokixMSfKDOfykQAAAo4"]
[Tue Jul 21 08:36:53.340534 2026] [security2:error] [pid 466512:tid 466649] [client 20.226.60.151:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/special.php"] [unique_id "al9Z1SKGokixMSfKDOfylQAAAhs"]
[Tue Jul 21 08:36:53.496341 2026] [security2:error] [pid 466512:tid 466524] [remote 152.42.176.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.176.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Z1SKGokixMSfKDOfylAACfws"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:36:53.795893 2026] [security2:error] [pid 466512:tid 466676] [client 20.206.105.145:22013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/themes.php"] [unique_id "al9Z1SKGokixMSfKDOfynQAAAjY"]
[Tue Jul 21 08:36:53.805193 2026] [security2:error] [pid 466512:tid 466575] [remote 207.180.241.245:49202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Z1SKGokixMSfKDOfyngACcz4"]
[Tue Jul 21 08:36:53.805337 2026] [security2:error] [pid 466512:tid 466737] [client 207.180.241.245:49202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Z1SKGokixMSfKDOfyngACcz4"]
[Tue Jul 21 08:36:53.863806 2026] [security2:error] [pid 466512:tid 466558] [remote 152.42.176.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.176.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Z1SKGokixMSfKDOfyoAACSy0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:36:54.226128 2026] [security2:error] [pid 466512:tid 466569] [remote 152.42.176.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.176.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Z1iKGokixMSfKDOfypQAChTg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:36:54.266373 2026] [security2:error] [pid 465652:tid 465892] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Z1jzTqJoBC2Mw28_NBQAA81Y"]
[Tue Jul 21 08:36:54.276183 2026] [autoindex:error] [pid 466512:tid 466647] [client 13.219.67.125:29254] AH01276: Cannot serve directory /home1/pedid516/parceiroraizenpower.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:36:54.307153 2026] [security2:error] [pid 466512:tid 466667] [client 20.226.60.151:64084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/as.php"] [unique_id "al9Z1iKGokixMSfKDOfyqQAAAi0"]
[Tue Jul 21 08:36:54.461217 2026] [security2:error] [pid 466512:tid 466562] [remote 152.42.176.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.176.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Z1SKGokixMSfKDOfykgACYzE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:36:54.462066 2026] [security2:error] [pid 465652:tid 465716] [remote 152.42.176.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.176.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Z1TzTqJoBC2Mw28_M9QAAqD8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:36:54.471031 2026] [security2:error] [pid 466512:tid 466552] [remote 152.42.176.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.176.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Z1SKGokixMSfKDOfykwACWCc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:36:54.599243 2026] [security2:error] [pid 466512:tid 466574] [remote 152.42.176.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.176.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Z1iKGokixMSfKDOfyrQACgz0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:36:54.716778 2026] [core:error] [pid 466512:tid 466581] [remote 40.77.167.74:54743] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:36:54.716797 2026] [core:error] [pid 466512:tid 466581] [remote 40.77.167.74:54743] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:36:54.816188 2026] [security2:error] [pid 466512:tid 466515] [remote 152.42.176.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.176.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Z1iKGokixMSfKDOfysgAChAI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:36:54.823945 2026] [security2:error] [pid 466512:tid 466578] [remote 152.42.176.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.176.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Z1iKGokixMSfKDOfytAACI0E"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:36:54.832873 2026] [security2:error] [pid 466512:tid 466587] [remote 152.42.176.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.176.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9Z1iKGokixMSfKDOfytQACdko"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:36:55.015687 2026] [security2:error] [pid 465652:tid 465869] [client 20.206.105.145:22109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/dx.php"] [unique_id "al9Z1zzTqJoBC2Mw28_NEgAAANw"]
[Tue Jul 21 08:36:55.073264 2026] [security2:error] [pid 465652:tid 465836] [client 20.226.60.151:64091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/cgi-bin/index.php"] [unique_id "al9Z1zzTqJoBC2Mw28_NEwAAALs"]
[Tue Jul 21 08:36:55.160369 2026] [security2:error] [pid 466512:tid 466746] [client 5.38.115.39:63205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Z1yKGokixMSfKDOfyuQAAAnw"]
[Tue Jul 21 08:36:55.160515 2026] [security2:error] [pid 466512:tid 466746] [client 5.38.115.39:63205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Z1yKGokixMSfKDOfyuQAAAnw"]
[Tue Jul 21 08:36:55.843896 2026] [security2:error] [pid 465652:tid 465853] [client 20.206.105.145:21958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/p.php"] [unique_id "al9Z1zzTqJoBC2Mw28_NKQAAAMw"]
[Tue Jul 21 08:36:56.004835 2026] [security2:error] [pid 465652:tid 465839] [client 74.7.175.167:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "silviabocchesedelima1748188488739.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9Z2DzTqJoBC2Mw28_NKgAAvnU"]
[Tue Jul 21 08:36:56.064567 2026] [security2:error] [pid 465652:tid 465884] [client 74.249.245.134:51850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/albin.php"] [unique_id "al9Z2DzTqJoBC2Mw28_NKwAAAOs"]
[Tue Jul 21 08:36:56.109717 2026] [security2:error] [pid 466512:tid 466648] [client 20.226.60.151:59304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/w1px.php"] [unique_id "al9Z2CKGokixMSfKDOfywwAAAho"]
[Tue Jul 21 08:36:56.384315 2026] [security2:error] [pid 465652:tid 465804] [client 5.31.193.106:1830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Z2DzTqJoBC2Mw28_NNAAAAJs"]
[Tue Jul 21 08:36:56.392607 2026] [security2:error] [pid 465652:tid 465804] [client 5.31.193.106:1830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Z2DzTqJoBC2Mw28_NNAAAAJs"]
[Tue Jul 21 08:36:56.472253 2026] [security2:error] [pid 466512:tid 466749] [client 14.245.224.124:51602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Z2CKGokixMSfKDOfyyAAAAn8"]
[Tue Jul 21 08:36:56.472379 2026] [security2:error] [pid 466512:tid 466749] [client 14.245.224.124:51602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Z2CKGokixMSfKDOfyyAAAAn8"]
[Tue Jul 21 08:36:56.830337 2026] [security2:error] [pid 466512:tid 466654] [client 59.95.197.55:50706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z2CKGokixMSfKDOfyzQAAAiA"]
[Tue Jul 21 08:36:56.831081 2026] [security2:error] [pid 466512:tid 466654] [client 59.95.197.55:50706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z2CKGokixMSfKDOfyzQAAAiA"]
[Tue Jul 21 08:36:56.898670 2026] [security2:error] [pid 466512:tid 466684] [client 20.206.105.145:22237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/bthil.php"] [unique_id "al9Z2CKGokixMSfKDOfy0gAAAj4"]
[Tue Jul 21 08:36:57.005681 2026] [security2:error] [pid 465652:tid 465865] [client 128.127.105.184:33270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Z2TzTqJoBC2Mw28_NOwAAANg"]
[Tue Jul 21 08:36:57.005772 2026] [security2:error] [pid 465652:tid 465865] [client 128.127.105.184:33270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Z2TzTqJoBC2Mw28_NOwAAANg"]
[Tue Jul 21 08:36:57.091506 2026] [security2:error] [pid 466512:tid 466645] [client 20.226.60.151:64013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/yawa.php"] [unique_id "al9Z2SKGokixMSfKDOfy1gAAAhc"]
[Tue Jul 21 08:36:57.126845 2026] [security2:error] [pid 466512:tid 466721] [client 20.197.192.193:11193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Z2SKGokixMSfKDOfy2AAAAmM"]
[Tue Jul 21 08:36:57.203234 2026] [security2:error] [pid 466512:tid 466701] [client 20.197.192.193:11197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Z2SKGokixMSfKDOfy2QAAAk8"]
[Tue Jul 21 08:36:57.427973 2026] [security2:error] [pid 466512:tid 466736] [client 20.197.192.193:11142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/dp.php"] [unique_id "al9Z2SKGokixMSfKDOfy4wAAAnI"]
[Tue Jul 21 08:36:57.477596 2026] [security2:error] [pid 466512:tid 466669] [client 20.197.192.193:11141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/old.php"] [unique_id "al9Z2SKGokixMSfKDOfy5QAAAi8"]
[Tue Jul 21 08:36:57.576878 2026] [security2:error] [pid 466512:tid 466723] [client 20.206.105.145:22138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/7.php"] [unique_id "al9Z2SKGokixMSfKDOfy6AAAAmU"]
[Tue Jul 21 08:36:57.627933 2026] [security2:error] [pid 466512:tid 466752] [client 20.197.192.193:16833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/ms-new.php"] [unique_id "al9Z2SKGokixMSfKDOfy6QAAAoI"]
[Tue Jul 21 08:36:57.754616 2026] [security2:error] [pid 466512:tid 466674] [client 20.197.192.193:11152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/track.php"] [unique_id "al9Z2SKGokixMSfKDOfy6gAAAjQ"]
[Tue Jul 21 08:36:57.848536 2026] [security2:error] [pid 466512:tid 466660] [client 20.226.60.151:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/js.php"] [unique_id "al9Z2SKGokixMSfKDOfy7AAAAiY"]
[Tue Jul 21 08:36:57.899656 2026] [security2:error] [pid 466512:tid 466647] [client 152.59.34.51:57704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z2SKGokixMSfKDOfy7wAAAhk"]
[Tue Jul 21 08:36:57.899743 2026] [security2:error] [pid 466512:tid 466647] [client 152.59.34.51:57704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z2SKGokixMSfKDOfy7wAAAhk"]
[Tue Jul 21 08:36:57.962677 2026] [security2:error] [pid 466512:tid 466699] [client 20.197.192.193:16867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/2352356666.php"] [unique_id "al9Z2SKGokixMSfKDOfy8QAAAk0"]
[Tue Jul 21 08:36:58.105684 2026] [security2:error] [pid 466512:tid 466747] [client 20.197.192.193:16870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/pn.php"] [unique_id "al9Z2iKGokixMSfKDOfy9QAAAn0"]
[Tue Jul 21 08:36:58.112634 2026] [security2:error] [pid 465652:tid 465809] [client 49.144.66.253:32342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Z2jzTqJoBC2Mw28_NSQAAAKA"]
[Tue Jul 21 08:36:58.112737 2026] [security2:error] [pid 465652:tid 465809] [client 49.144.66.253:32342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Z2jzTqJoBC2Mw28_NSQAAAKA"]
[Tue Jul 21 08:36:58.173083 2026] [security2:error] [pid 466512:tid 466741] [client 20.226.60.151:64038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/core.php"] [unique_id "al9Z2iKGokixMSfKDOfy9gAAAnc"]
[Tue Jul 21 08:36:58.213715 2026] [security2:error] [pid 466512:tid 466668] [client 20.197.192.193:16841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/wp-wpbak.php"] [unique_id "al9Z2iKGokixMSfKDOfy-AAAAi4"]
[Tue Jul 21 08:36:58.282518 2026] [security2:error] [pid 466512:tid 466673] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z2iKGokixMSfKDOfy-QAAAjM"]
[Tue Jul 21 08:36:58.303131 2026] [security2:error] [pid 466512:tid 466712] [client 20.197.192.193:11147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/dr.php"] [unique_id "al9Z2iKGokixMSfKDOfy-wAAAlo"]
[Tue Jul 21 08:36:58.524385 2026] [security2:error] [pid 466512:tid 466745] [client 20.206.105.145:22224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/8.php"] [unique_id "al9Z2iKGokixMSfKDOfy_QAAAns"]
[Tue Jul 21 08:36:58.547823 2026] [security2:error] [pid 465652:tid 465794] [client 20.197.192.193:16851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/2x.php"] [unique_id "al9Z2jzTqJoBC2Mw28_NUQAAAJE"]
[Tue Jul 21 08:36:58.562044 2026] [security2:error] [pid 465652:tid 465818] [client 154.92.130.89:39785] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://:"] [hostname "startonesite.com.br"] [uri "/"] [unique_id "al9Z2jzTqJoBC2Mw28_NUgAAAKk"]
[Tue Jul 21 08:36:58.590605 2026] [security2:error] [pid 466512:tid 466649] [client 122.176.100.127:49750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Z2iKGokixMSfKDOfy_gAAAhs"]
[Tue Jul 21 08:36:58.590713 2026] [security2:error] [pid 466512:tid 466649] [client 122.176.100.127:49750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Z2iKGokixMSfKDOfy_gAAAhs"]
[Tue Jul 21 08:36:58.599543 2026] [security2:error] [pid 465652:tid 465908] [client 20.197.192.193:16879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/kq1.php"] [unique_id "al9Z2jzTqJoBC2Mw28_NVwAAAQM"]
[Tue Jul 21 08:36:58.734032 2026] [security2:error] [pid 466512:tid 466684] [client 20.197.192.193:16845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/zzz.php"] [unique_id "al9Z2iKGokixMSfKDOfy_wAAAj4"]
[Tue Jul 21 08:36:58.752585 2026] [security2:error] [pid 466512:tid 466738] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Z2iKGokixMSfKDOfzAAAAAnQ"]
[Tue Jul 21 08:36:58.768261 2026] [security2:error] [pid 466512:tid 466667] [client 20.206.105.145:22010] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/1.php"] [unique_id "al9Z2iKGokixMSfKDOfzAQAAAi0"]
[Tue Jul 21 08:36:58.768369 2026] [security2:error] [pid 466512:tid 466667] [client 20.206.105.145:22010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/1.php"] [unique_id "al9Z2iKGokixMSfKDOfzAQAAAi0"]
[Tue Jul 21 08:36:58.846191 2026] [security2:error] [pid 466512:tid 466734] [client 20.197.192.193:16835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/wicked.php"] [unique_id "al9Z2iKGokixMSfKDOfzAgAAAnA"]
[Tue Jul 21 08:36:58.944199 2026] [security2:error] [pid 465652:tid 465856] [client 20.197.192.193:11158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/edit.php"] [unique_id "al9Z2jzTqJoBC2Mw28_NXQAAAM8"]
[Tue Jul 21 08:36:59.026903 2026] [security2:error] [pid 466512:tid 466737] [client 103.59.206.240:31098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z2yKGokixMSfKDOfzBAAAAnM"]
[Tue Jul 21 08:36:59.027022 2026] [security2:error] [pid 466512:tid 466737] [client 103.59.206.240:31098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z2yKGokixMSfKDOfzBAAAAnM"]
[Tue Jul 21 08:36:59.112717 2026] [security2:error] [pid 465652:tid 465883] [client 20.197.192.193:11199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/kua.php"] [unique_id "al9Z2zzTqJoBC2Mw28_NYQAAAOo"]
[Tue Jul 21 08:36:59.137992 2026] [security2:error] [pid 466512:tid 466670] [client 152.59.181.104:5826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z2yKGokixMSfKDOfzBQAAAjA"]
[Tue Jul 21 08:36:59.138107 2026] [security2:error] [pid 466512:tid 466670] [client 152.59.181.104:5826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z2yKGokixMSfKDOfzBQAAAjA"]
[Tue Jul 21 08:36:59.160724 2026] [security2:error] [pid 466512:tid 466704] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Z2yKGokixMSfKDOfzBgAAAlI"]
[Tue Jul 21 08:36:59.173131 2026] [security2:error] [pid 466512:tid 466755] [client 195.49.128.211:55331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Z2yKGokixMSfKDOfzBwAAAoU"]
[Tue Jul 21 08:36:59.173264 2026] [security2:error] [pid 466512:tid 466755] [client 195.49.128.211:55331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Z2yKGokixMSfKDOfzBwAAAoU"]
[Tue Jul 21 08:36:59.244372 2026] [security2:error] [pid 466512:tid 466655] [client 20.197.192.193:11184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/ez.php"] [unique_id "al9Z2yKGokixMSfKDOfzCgAAAiE"]
[Tue Jul 21 08:36:59.277893 2026] [security2:error] [pid 465652:tid 465826] [client 20.226.60.151:59281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/19.php"] [unique_id "al9Z2zzTqJoBC2Mw28_NZAAAALE"]
[Tue Jul 21 08:36:59.381186 2026] [security2:error] [pid 466512:tid 466729] [client 20.197.192.193:16862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/fz.php"] [unique_id "al9Z2yKGokixMSfKDOfzEgAAAms"]
[Tue Jul 21 08:36:59.542738 2026] [security2:error] [pid 466512:tid 466662] [client 20.197.192.193:16838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/la.php"] [unique_id "al9Z2yKGokixMSfKDOfzGAAAAig"]
[Tue Jul 21 08:36:59.598798 2026] [security2:error] [pid 466512:tid 466674] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Z2yKGokixMSfKDOfzGwAAAjQ"]
[Tue Jul 21 08:36:59.668491 2026] [security2:error] [pid 465652:tid 465839] [client 20.197.192.193:16881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/nhvoanpl.php"] [unique_id "al9Z2zzTqJoBC2Mw28_NawAAAL4"]
[Tue Jul 21 08:36:59.858909 2026] [security2:error] [pid 466512:tid 466732] [client 20.197.192.193:11183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/inso.php"] [unique_id "al9Z2yKGokixMSfKDOfzHwAAAm4"]
[Tue Jul 21 08:37:00.005160 2026] [security2:error] [pid 465652:tid 465885] [client 20.197.192.193:16853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/wpx.php"] [unique_id "al9Z3DzTqJoBC2Mw28_NdQAAAOw"]
[Tue Jul 21 08:37:00.019282 2026] [security2:error] [pid 465652:tid 465805] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Z3DzTqJoBC2Mw28_NdgAAAJw"]
[Tue Jul 21 08:37:00.051825 2026] [security2:error] [pid 466512:tid 466699] [client 20.197.192.193:11161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/berlin.php"] [unique_id "al9Z3CKGokixMSfKDOfzIwAAAk0"]
[Tue Jul 21 08:37:00.140954 2026] [security2:error] [pid 466512:tid 466763] [client 20.197.192.193:11177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/billur.php"] [unique_id "al9Z3CKGokixMSfKDOfzJgAAAo0"]
[Tue Jul 21 08:37:00.293792 2026] [security2:error] [pid 466512:tid 466659] [client 20.197.192.193:11136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/mimpi.php"] [unique_id "al9Z3CKGokixMSfKDOfzKQAAAiU"]
[Tue Jul 21 08:37:00.475682 2026] [security2:error] [pid 465652:tid 465900] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Z3DzTqJoBC2Mw28_NewAAAPs"]
[Tue Jul 21 08:37:00.699827 2026] [security2:error] [pid 465652:tid 465782] [client 20.197.192.193:11179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/dp.php"] [unique_id "al9Z3DzTqJoBC2Mw28_NgQAAAIU"]
[Tue Jul 21 08:37:00.829920 2026] [security2:error] [pid 465652:tid 465905] [client 20.206.105.145:22003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/100.php"] [unique_id "al9Z3DzTqJoBC2Mw28_NhgAAAQA"]
[Tue Jul 21 08:37:00.882734 2026] [security2:error] [pid 466512:tid 466658] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Z3CKGokixMSfKDOfzNwAAAiQ"]
[Tue Jul 21 08:37:00.944021 2026] [security2:error] [pid 466512:tid 466690] [client 20.197.192.193:11165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/bootstrap.php"] [unique_id "al9Z3CKGokixMSfKDOfzOAAAAkQ"]
[Tue Jul 21 08:37:01.000969 2026] [security2:error] [pid 466512:tid 466704] [client 213.152.186.163:41906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Z3SKGokixMSfKDOfzOgAAAlI"]
[Tue Jul 21 08:37:01.001067 2026] [security2:error] [pid 466512:tid 466704] [client 213.152.186.163:41906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9Z3SKGokixMSfKDOfzOgAAAlI"]
[Tue Jul 21 08:37:01.017302 2026] [security2:error] [pid 466512:tid 466769] [client 20.197.192.193:11182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/wp-editor.php"] [unique_id "al9Z3SKGokixMSfKDOfzOwAAApM"]
[Tue Jul 21 08:37:01.123589 2026] [security2:error] [pid 466512:tid 466681] [client 89.238.167.134:56514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Z3SKGokixMSfKDOfzPwAAAjs"]
[Tue Jul 21 08:37:01.123678 2026] [security2:error] [pid 466512:tid 466681] [client 89.238.167.134:56514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Z3SKGokixMSfKDOfzPwAAAjs"]
[Tue Jul 21 08:37:01.213367 2026] [security2:error] [pid 466512:tid 466686] [client 20.197.192.193:53463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/cro.php"] [unique_id "al9Z3SKGokixMSfKDOfzQAAAAkA"]
[Tue Jul 21 08:37:01.287437 2026] [security2:error] [pid 465652:tid 465877] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Z3TzTqJoBC2Mw28_NjgAAAOQ"]
[Tue Jul 21 08:37:01.385761 2026] [security2:error] [pid 466512:tid 466679] [client 20.226.60.151:59091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/inc.php"] [unique_id "al9Z3SKGokixMSfKDOfzQgAAAjk"]
[Tue Jul 21 08:37:01.499116 2026] [security2:error] [pid 465652:tid 465846] [client 20.197.192.193:11137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/cron-tab.php"] [unique_id "al9Z3TzTqJoBC2Mw28_NkQAAAMU"]
[Tue Jul 21 08:37:01.632325 2026] [security2:error] [pid 465652:tid 465860] [client 20.197.192.193:11215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/koiy.php"] [unique_id "al9Z3TzTqJoBC2Mw28_NmgAAANM"]
[Tue Jul 21 08:37:01.632857 2026] [security2:error] [pid 466512:tid 466723] [client 128.127.105.184:42886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Z3SKGokixMSfKDOfzSwAAAmU"]
[Tue Jul 21 08:37:01.632990 2026] [security2:error] [pid 466512:tid 466723] [client 128.127.105.184:42886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9Z3SKGokixMSfKDOfzSwAAAmU"]
[Tue Jul 21 08:37:01.658522 2026] [security2:error] [pid 465652:tid 465818] [client 20.197.192.193:16854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/hp2.php"] [unique_id "al9Z3TzTqJoBC2Mw28_NnAAAAKk"]
[Tue Jul 21 08:37:01.686916 2026] [security2:error] [pid 466512:tid 466691] [client 20.197.192.193:16874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/hp3.php"] [unique_id "al9Z3SKGokixMSfKDOfzTQAAAkU"]
[Tue Jul 21 08:37:01.717296 2026] [security2:error] [pid 466512:tid 466728] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Z3SKGokixMSfKDOfzTgAAAmo"]
[Tue Jul 21 08:37:01.761151 2026] [security2:error] [pid 466512:tid 466744] [client 20.197.192.193:11187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/aa1.php"] [unique_id "al9Z3SKGokixMSfKDOfzTwAAAno"]
[Tue Jul 21 08:37:01.809101 2026] [security2:error] [pid 466512:tid 466703] [client 20.206.105.145:22015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/about.php"] [unique_id "al9Z3SKGokixMSfKDOfzUAAAAlE"]
[Tue Jul 21 08:37:01.844184 2026] [security2:error] [pid 465652:tid 465843] [client 187.125.243.197:62569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.243.125.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Z3TzTqJoBC2Mw28_NowAAAMI"]
[Tue Jul 21 08:37:01.844320 2026] [security2:error] [pid 465652:tid 465843] [client 187.125.243.197:62569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solarisimplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Z3TzTqJoBC2Mw28_NowAAAMI"]
[Tue Jul 21 08:37:01.880227 2026] [security2:error] [pid 465652:tid 465837] [client 20.197.192.193:16878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/acew67.php"] [unique_id "al9Z3TzTqJoBC2Mw28_NpAAAALw"]
[Tue Jul 21 08:37:02.025617 2026] [security2:error] [pid 466512:tid 466678] [client 20.197.192.193:16871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/bscclapb.php"] [unique_id "al9Z3iKGokixMSfKDOfzVAAAAjg"]
[Tue Jul 21 08:37:02.060930 2026] [security2:error] [pid 466512:tid 466711] [client 117.213.202.34:61388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z3iKGokixMSfKDOfzVQAAAlk"]
[Tue Jul 21 08:37:02.061129 2026] [security2:error] [pid 466512:tid 466711] [client 117.213.202.34:61388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z3iKGokixMSfKDOfzVQAAAlk"]
[Tue Jul 21 08:37:02.082366 2026] [security2:error] [pid 466512:tid 466747] [client 20.197.192.193:16875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/else1.php"] [unique_id "al9Z3iKGokixMSfKDOfzVwAAAn0"]
[Tue Jul 21 08:37:02.134483 2026] [security2:error] [pid 466512:tid 466666] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Z3iKGokixMSfKDOfzWgAAAiw"]
[Tue Jul 21 08:37:02.243236 2026] [security2:error] [pid 466512:tid 466659] [client 74.249.245.134:42679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/alfa.php"] [unique_id "al9Z3iKGokixMSfKDOfzWwAAAiU"]
[Tue Jul 21 08:37:02.248684 2026] [security2:error] [pid 466512:tid 466698] [client 20.197.192.193:11169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/tkikikoko.php"] [unique_id "al9Z3iKGokixMSfKDOfzXAAAAkw"]
[Tue Jul 21 08:37:02.388547 2026] [security2:error] [pid 465652:tid 465887] [client 202.179.75.202:53116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Z3jzTqJoBC2Mw28_NqgAAAO4"]
[Tue Jul 21 08:37:02.388685 2026] [security2:error] [pid 465652:tid 465887] [client 202.179.75.202:53116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Z3jzTqJoBC2Mw28_NqgAAAO4"]
[Tue Jul 21 08:37:02.465172 2026] [security2:error] [pid 465652:tid 465813] [client 20.197.192.193:16856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/wp-Blogs.php"] [unique_id "al9Z3jzTqJoBC2Mw28_NqwAAAKQ"]
[Tue Jul 21 08:37:02.481783 2026] [security2:error] [pid 465652:tid 465803] [client 20.206.105.145:22132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/admin.php"] [unique_id "al9Z3jzTqJoBC2Mw28_NrAAAAJo"]
[Tue Jul 21 08:37:02.621427 2026] [security2:error] [pid 466512:tid 466654] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Z3iKGokixMSfKDOfzXgAAAiA"]
[Tue Jul 21 08:37:02.721620 2026] [security2:error] [pid 466512:tid 466565] [remote 173.252.95.19:51980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Z3SKGokixMSfKDOfzRQACIzQ"]
[Tue Jul 21 08:37:02.753743 2026] [security2:error] [pid 466512:tid 466745] [client 20.197.192.193:11171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/wp-css.php"] [unique_id "al9Z3iKGokixMSfKDOfzYAAAAns"]
[Tue Jul 21 08:37:02.795077 2026] [security2:error] [pid 466512:tid 466767] [client 20.226.60.151:64074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-ppoxua4.php"] [unique_id "al9Z3iKGokixMSfKDOfzYQAAApE"]
[Tue Jul 21 08:37:02.798642 2026] [security2:error] [pid 465652:tid 465862] [client 20.206.105.145:21995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/edit.php"] [unique_id "al9Z3jzTqJoBC2Mw28_NtAAAANU"]
[Tue Jul 21 08:37:02.989218 2026] [security2:error] [pid 465652:tid 465826] [client 195.49.128.211:63522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Z3jzTqJoBC2Mw28_NtQAAALE"]
[Tue Jul 21 08:37:02.989348 2026] [security2:error] [pid 465652:tid 465826] [client 195.49.128.211:63522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Z3jzTqJoBC2Mw28_NtQAAALE"]
[Tue Jul 21 08:37:03.047339 2026] [security2:error] [pid 465652:tid 465884] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Z3zzTqJoBC2Mw28_NtwAAAOs"]
[Tue Jul 21 08:37:03.120089 2026] [security2:error] [pid 466512:tid 466540] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Z3yKGokixMSfKDOfzaAACFxs"]
[Tue Jul 21 08:37:03.120252 2026] [security2:error] [pid 466512:tid 466645] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Z3yKGokixMSfKDOfzaAACFxs"]
[Tue Jul 21 08:37:03.124969 2026] [security2:error] [pid 465652:tid 465855] [client 20.197.192.193:11194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/wp-explorer.php"] [unique_id "al9Z3zzTqJoBC2Mw28_NuQAAAM4"]
[Tue Jul 21 08:37:03.215308 2026] [security2:error] [pid 466512:tid 466717] [client 128.127.105.184:42898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Z3yKGokixMSfKDOfzagAAAl8"]
[Tue Jul 21 08:37:03.215393 2026] [security2:error] [pid 466512:tid 466717] [client 128.127.105.184:42898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9Z3yKGokixMSfKDOfzagAAAl8"]
[Tue Jul 21 08:37:03.224046 2026] [security2:error] [pid 466512:tid 466517] [remote 216.73.160.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-login.php"] [unique_id "al9Z3yKGokixMSfKDOfzawACRAQ"]
[Tue Jul 21 08:37:03.395915 2026] [security2:error] [pid 465652:tid 465900] [client 20.197.192.193:11168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/akismet.php"] [unique_id "al9Z3zzTqJoBC2Mw28_NwQAAAPs"]
[Tue Jul 21 08:37:03.470559 2026] [security2:error] [pid 465652:tid 465902] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Z3zzTqJoBC2Mw28_NwgAAAP0"]
[Tue Jul 21 08:37:03.484449 2026] [security2:error] [pid 465652:tid 465680] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9Z3zzTqJoBC2Mw28_NwwAAjRs"]
[Tue Jul 21 08:37:03.484600 2026] [security2:error] [pid 465652:tid 465790] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9Z3zzTqJoBC2Mw28_NwwAAjRs"]
[Tue Jul 21 08:37:03.560133 2026] [security2:error] [pid 466512:tid 466681] [client 20.197.192.193:16893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/ace2.php"] [unique_id "al9Z3yKGokixMSfKDOfzcAAAAjs"]
[Tue Jul 21 08:37:03.615065 2026] [security2:error] [pid 465652:tid 465816] [client 20.206.105.145:21993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Z3zzTqJoBC2Mw28_NygAAAKc"]
[Tue Jul 21 08:37:03.758316 2026] [security2:error] [pid 466512:tid 466729] [client 20.197.192.193:11146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.mannucarvalho.com"] [uri "/ms.php"] [unique_id "al9Z3yKGokixMSfKDOfzcQAAAms"]
[Tue Jul 21 08:37:03.922747 2026] [security2:error] [pid 466512:tid 466769] [client 223.181.60.88:31994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Z3yKGokixMSfKDOfzcwAAApM"]
[Tue Jul 21 08:37:03.922953 2026] [security2:error] [pid 466512:tid 466769] [client 223.181.60.88:31994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Z3yKGokixMSfKDOfzcwAAApM"]
[Tue Jul 21 08:37:03.965072 2026] [security2:error] [pid 466512:tid 466740] [client 173.252.95.19:51982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Z3yKGokixMSfKDOfzdAAAAnY"]
[Tue Jul 21 08:37:03.992340 2026] [security2:error] [pid 465652:tid 465892] [client 212.32.69.197:55755] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fisiopelvicafloripa.com.br"] [uri "/.env"] [unique_id "al9Z3zzTqJoBC2Mw28_N0wAAAPM"]
[Tue Jul 21 08:37:04.143020 2026] [security2:error] [pid 466512:tid 466694] [client 20.226.60.151:59133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-u3nxbvx.php"] [unique_id "al9Z4CKGokixMSfKDOfzeQAAAkg"]
[Tue Jul 21 08:37:04.668638 2026] [security2:error] [pid 466512:tid 466630] [remote 103.28.36.106:46270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "liranesuliano.com.br"] [uri "/wp-login.php"] [unique_id "al9Z4CKGokixMSfKDOfzhwACdXU"]
[Tue Jul 21 08:37:04.747489 2026] [security2:error] [pid 465652:tid 465881] [client 61.1.167.83:63932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z4DzTqJoBC2Mw28_N5gAAAOg"]
[Tue Jul 21 08:37:04.747604 2026] [security2:error] [pid 465652:tid 465881] [client 61.1.167.83:63932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z4DzTqJoBC2Mw28_N5gAAAOg"]
[Tue Jul 21 08:37:04.856751 2026] [security2:error] [pid 466512:tid 466763] [client 20.206.105.145:21962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/f6.php"] [unique_id "al9Z4CKGokixMSfKDOfziwAAAo0"]
[Tue Jul 21 08:37:04.953901 2026] [security2:error] [pid 466512:tid 466720] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Z4CKGokixMSfKDOfzjQACYmI"]
[Tue Jul 21 08:37:05.151863 2026] [security2:error] [pid 465652:tid 465801] [client 20.226.60.151:59327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/ss.php"] [unique_id "al9Z4TzTqJoBC2Mw28_N6gAAAJg"]
[Tue Jul 21 08:37:05.612619 2026] [security2:error] [pid 466512:tid 466688] [client 20.206.105.145:22104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/inputs.php"] [unique_id "al9Z4SKGokixMSfKDOfzlAAAAkI"]
[Tue Jul 21 08:37:05.624244 2026] [security2:error] [pid 465652:tid 465893] [client 103.151.46.103:57996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Z4TzTqJoBC2Mw28_N8wAAAPQ"]
[Tue Jul 21 08:37:05.624872 2026] [security2:error] [pid 465652:tid 465893] [client 103.151.46.103:57996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Z4TzTqJoBC2Mw28_N8wAAAPQ"]
[Tue Jul 21 08:37:05.731125 2026] [security2:error] [pid 466512:tid 466698] [client 5.38.115.39:60070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Z4SKGokixMSfKDOfzmAAAAkw"]
[Tue Jul 21 08:37:05.735663 2026] [security2:error] [pid 466512:tid 466698] [client 5.38.115.39:60070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Z4SKGokixMSfKDOfzmAAAAkw"]
[Tue Jul 21 08:37:05.807673 2026] [security2:error] [pid 466512:tid 466734] [client 20.226.60.151:59277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/min.php"] [unique_id "al9Z4SKGokixMSfKDOfznAAAAnA"]
[Tue Jul 21 08:37:06.284805 2026] [security2:error] [pid 466512:tid 466700] [client 20.226.60.151:64071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9Z4iKGokixMSfKDOfzpwAAAk4"]
[Tue Jul 21 08:37:06.380885 2026] [security2:error] [pid 465652:tid 465863] [client 20.206.105.145:21957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/av.php"] [unique_id "al9Z4jzTqJoBC2Mw28_OAwAAANY"]
[Tue Jul 21 08:37:06.649307 2026] [security2:error] [pid 466512:tid 466754] [client 20.226.60.151:64116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/autoload_classmap.php"] [unique_id "al9Z4iKGokixMSfKDOfzrwAAAoQ"]
[Tue Jul 21 08:37:06.763672 2026] [autoindex:error] [pid 465652:tid 465902] [client 159.65.187.103:43818] AH01276: Cannot serve directory /home2/lylowc82/conquisteemcasa.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:37:06.818156 2026] [security2:error] [pid 466512:tid 466535] [remote 216.24.219.119:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.219.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naldoinvest.com.br"] [uri "/wp-login.php"] [unique_id "al9Z4iKGokixMSfKDOfzrgAChxY"]
[Tue Jul 21 08:37:07.010913 2026] [security2:error] [pid 466512:tid 466572] [remote 124.55.178.99:39804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/wp-login.php"] [unique_id "al9Z4yKGokixMSfKDOfzswACLzs"]
[Tue Jul 21 08:37:07.027447 2026] [security2:error] [pid 466512:tid 466643] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z4yKGokixMSfKDOfztAAAAhU"]
[Tue Jul 21 08:37:07.053087 2026] [security2:error] [pid 466512:tid 466707] [client 128.127.105.184:42926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Z4yKGokixMSfKDOfztQAAAlU"]
[Tue Jul 21 08:37:07.053203 2026] [security2:error] [pid 466512:tid 466707] [client 128.127.105.184:42926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9Z4yKGokixMSfKDOfztQAAAlU"]
[Tue Jul 21 08:37:07.113307 2026] [security2:error] [pid 465652:tid 465897] [client 20.226.60.151:64110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-link-zorm.php"] [unique_id "al9Z4zzTqJoBC2Mw28_ODAAAAPg"]
[Tue Jul 21 08:37:07.239841 2026] [security2:error] [pid 465652:tid 465796] [client 20.206.105.145:21779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9Z4zzTqJoBC2Mw28_ODgAAAJM"]
[Tue Jul 21 08:37:07.250178 2026] [security2:error] [pid 466512:tid 466647] [client 14.245.224.124:52077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Z4yKGokixMSfKDOfztwAAAhk"]
[Tue Jul 21 08:37:07.250284 2026] [security2:error] [pid 466512:tid 466647] [client 14.245.224.124:52077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Z4yKGokixMSfKDOfztwAAAhk"]
[Tue Jul 21 08:37:07.439961 2026] [security2:error] [pid 466512:tid 466720] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9Z4yKGokixMSfKDOfzuwAAAmI"]
[Tue Jul 21 08:37:07.472702 2026] [autoindex:error] [pid 466512:tid 466678] [client 159.65.187.103:37906] AH01276: Cannot serve directory /home2/lylowc82/conquisteemcasa.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:37:07.632376 2026] [security2:error] [pid 466512:tid 466753] [client 20.226.60.151:59299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-link-szoppm.php"] [unique_id "al9Z4yKGokixMSfKDOfzwwAAAoM"]
[Tue Jul 21 08:37:07.754962 2026] [security2:error] [pid 466512:tid 466649] [client 74.249.245.134:52222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/autoload_classmap.php"] [unique_id "al9Z4yKGokixMSfKDOfzxAAAAhs"]
[Tue Jul 21 08:37:07.910312 2026] [security2:error] [pid 466512:tid 466642] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9Z4yKGokixMSfKDOfzygAAAhQ"]
[Tue Jul 21 08:37:07.942137 2026] [security2:error] [pid 466512:tid 466711] [client 59.95.197.55:51289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z4yKGokixMSfKDOfzzAAAAlk"]
[Tue Jul 21 08:37:07.942231 2026] [security2:error] [pid 466512:tid 466711] [client 59.95.197.55:51289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z4yKGokixMSfKDOfzzAAAAlk"]
[Tue Jul 21 08:37:08.128065 2026] [security2:error] [pid 465652:tid 465795] [client 20.226.60.151:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/albin.php"] [unique_id "al9Z5DzTqJoBC2Mw28_OGQAAAJI"]
[Tue Jul 21 08:37:08.187380 2026] [autoindex:error] [pid 466512:tid 466687] [client 198.235.24.27:63944] AH01276: Cannot serve directory /home1/imperd48/sabino-tracker.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:37:08.307668 2026] [security2:error] [pid 466512:tid 466695] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9Z5CKGokixMSfKDOfz1AAAAkk"]
[Tue Jul 21 08:37:08.570039 2026] [security2:error] [pid 465652:tid 465846] [client 152.59.34.51:54975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z5DzTqJoBC2Mw28_OIAAAAMU"]
[Tue Jul 21 08:37:08.570233 2026] [security2:error] [pid 465652:tid 465846] [client 152.59.34.51:54975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z5DzTqJoBC2Mw28_OIAAAAMU"]
[Tue Jul 21 08:37:08.648396 2026] [security2:error] [pid 466512:tid 466684] [client 20.206.105.145:21982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9Z5CKGokixMSfKDOfz2QAAAj4"]
[Tue Jul 21 08:37:08.702453 2026] [security2:error] [pid 466512:tid 466701] [client 69.171.230.116:57740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Z5CKGokixMSfKDOfz2gAAAk8"]
[Tue Jul 21 08:37:08.779688 2026] [security2:error] [pid 466512:tid 466653] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9Z5CKGokixMSfKDOfz2wAAAh8"]
[Tue Jul 21 08:37:08.968349 2026] [security2:error] [pid 466512:tid 466752] [client 49.144.66.253:32507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Z5CKGokixMSfKDOfz4AAAAoI"]
[Tue Jul 21 08:37:08.968568 2026] [security2:error] [pid 466512:tid 466752] [client 49.144.66.253:32507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Z5CKGokixMSfKDOfz4AAAAoI"]
[Tue Jul 21 08:37:09.004307 2026] [security2:error] [pid 465652:tid 465895] [client 20.226.60.151:59078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/cilus.php"] [unique_id "al9Z5TzTqJoBC2Mw28_OKgAAAPY"]
[Tue Jul 21 08:37:09.191473 2026] [security2:error] [pid 465652:tid 465801] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9Z5TzTqJoBC2Mw28_OLQAAAJg"]
[Tue Jul 21 08:37:09.193706 2026] [security2:error] [pid 465652:tid 465908] [client 122.176.100.127:50263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Z5TzTqJoBC2Mw28_OLAAAAQM"]
[Tue Jul 21 08:37:09.193865 2026] [security2:error] [pid 465652:tid 465908] [client 122.176.100.127:50263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Z5TzTqJoBC2Mw28_OLAAAAQM"]
[Tue Jul 21 08:37:09.235105 2026] [security2:error] [pid 466512:tid 466703] [client 45.79.207.110:58023] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.68"] [uri "/index.cgi"] [unique_id "al9Z5SKGokixMSfKDOfz4QAAAlE"]
[Tue Jul 21 08:37:09.241751 2026] [security2:error] [pid 466512:tid 466635] [remote 154.0.166.254:60744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9Z5SKGokixMSfKDOfz4gACSHo"]
[Tue Jul 21 08:37:09.241872 2026] [security2:error] [pid 466512:tid 466694] [client 154.0.166.254:60744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9Z5SKGokixMSfKDOfz4gACSHo"]
[Tue Jul 21 08:37:09.314287 2026] [security2:error] [pid 466512:tid 466739] [client 20.206.105.145:22136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-blog.php"] [unique_id "al9Z5SKGokixMSfKDOfz4wAAAnU"]
[Tue Jul 21 08:37:09.503607 2026] [security2:error] [pid 465652:tid 465838] [client 69.171.230.15:37846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Z5TzTqJoBC2Mw28_OLwAAAL0"]
[Tue Jul 21 08:37:09.619668 2026] [security2:error] [pid 465652:tid 465800] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9Z5TzTqJoBC2Mw28_ONQAAAJc"]
[Tue Jul 21 08:37:09.771302 2026] [security2:error] [pid 466512:tid 466702] [client 195.49.128.211:55937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Z5SKGokixMSfKDOfz7gAAAlA"]
[Tue Jul 21 08:37:09.771418 2026] [security2:error] [pid 466512:tid 466702] [client 195.49.128.211:55937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Z5SKGokixMSfKDOfz7gAAAlA"]
[Tue Jul 21 08:37:09.779825 2026] [security2:error] [pid 466512:tid 466699] [client 103.59.206.240:31312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z5SKGokixMSfKDOfz7wAAAk0"]
[Tue Jul 21 08:37:09.779949 2026] [security2:error] [pid 466512:tid 466699] [client 103.59.206.240:31312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z5SKGokixMSfKDOfz7wAAAk0"]
[Tue Jul 21 08:37:09.880414 2026] [security2:error] [pid 466512:tid 466555] [remote 41.76.214.143:37568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fisiopelvicafloripa.com.br"] [uri "/wp-login.php"] [unique_id "al9Z5SKGokixMSfKDOfz8AACVSo"]
[Tue Jul 21 08:37:09.895321 2026] [security2:error] [pid 466512:tid 466672] [client 20.226.60.151:64028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/gptsh.php"] [unique_id "al9Z5SKGokixMSfKDOfz8QAAAjI"]
[Tue Jul 21 08:37:10.089042 2026] [security2:error] [pid 466512:tid 466767] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9Z5iKGokixMSfKDOfz9AAAApE"]
[Tue Jul 21 08:37:10.401132 2026] [security2:error] [pid 466512:tid 466721] [client 20.226.60.151:64079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/rithin.php"] [unique_id "al9Z5iKGokixMSfKDOfz9gAAAmM"]
[Tue Jul 21 08:37:10.419781 2026] [security2:error] [pid 465652:tid 465845] [client 20.206.105.145:22137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9Z5jzTqJoBC2Mw28_OQQAAAMQ"]
[Tue Jul 21 08:37:10.433629 2026] [security2:error] [pid 465652:tid 465792] [client 184.154.76.20:32980] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "nrfilmes.com"] [uri "/index.php"] [unique_id "al9Z5TzTqJoBC2Mw28_OOwAAAI8"]
[Tue Jul 21 08:37:10.528008 2026] [security2:error] [pid 465652:tid 465861] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9Z5jzTqJoBC2Mw28_ORgAAANQ"]
[Tue Jul 21 08:37:10.646876 2026] [security2:error] [pid 465652:tid 465790] [client 20.226.60.151:59283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/fffm.php"] [unique_id "al9Z5jzTqJoBC2Mw28_OSQAAAI0"]
[Tue Jul 21 08:37:10.661645 2026] [security2:error] [pid 465652:tid 465749] [remote 160.187.68.132:57262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "murilomattos.com"] [uri "/wp-login.php"] [unique_id "al9Z5jzTqJoBC2Mw28_OSgAAlGA"]
[Tue Jul 21 08:37:10.746586 2026] [security2:error] [pid 465652:tid 465668] [remote 46.105.28.235:41178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/wp-login.php"] [unique_id "al9Z5jzTqJoBC2Mw28_OSwAAyg8"]
[Tue Jul 21 08:37:10.803872 2026] [core:error] [pid 466512:tid 466593] [remote 87.236.176.200:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpanel.tavarescont.com.br:2095
[Tue Jul 21 08:37:10.803911 2026] [core:error] [pid 466512:tid 466593] [remote 87.236.176.200:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpanel.tavarescont.com.br:2095
[Tue Jul 21 08:37:11.004198 2026] [security2:error] [pid 466512:tid 466695] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9Z5yKGokixMSfKDOfz-wAAAkk"]
[Tue Jul 21 08:37:11.214266 2026] [security2:error] [pid 465652:tid 465798] [client 20.226.60.151:53122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/dfre.php"] [unique_id "al9Z5zzTqJoBC2Mw28_OVgAAAJU"]
[Tue Jul 21 08:37:11.368427 2026] [security2:error] [pid 466512:tid 466654] [client 20.206.105.145:21990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/adminfuns.php"] [unique_id "al9Z5yKGokixMSfKDOf0BwAAAiA"]
[Tue Jul 21 08:37:11.388316 2026] [security2:error] [pid 466512:tid 466652] [client 69.171.230.27:39174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Z5yKGokixMSfKDOf0AwAAAh4"]
[Tue Jul 21 08:37:11.463940 2026] [security2:error] [pid 466512:tid 466656] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9Z5yKGokixMSfKDOf0CAAAAiI"]
[Tue Jul 21 08:37:11.729485 2026] [security2:error] [pid 466512:tid 466755] [client 69.171.230.40:46868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Z5yKGokixMSfKDOf0DQAAAoU"]
[Tue Jul 21 08:37:11.764555 2026] [security2:error] [pid 466512:tid 466668] [client 20.226.60.151:64103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/wp-happy.php"] [unique_id "al9Z5yKGokixMSfKDOf0DgAAAi4"]
[Tue Jul 21 08:37:11.928781 2026] [security2:error] [pid 466512:tid 466666] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9Z5yKGokixMSfKDOf0EAAAAiw"]
[Tue Jul 21 08:37:12.069855 2026] [security2:error] [pid 465652:tid 465795] [client 20.226.60.151:64002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/fpr4.php"] [unique_id "al9Z6DzTqJoBC2Mw28_OXAAAAJI"]
[Tue Jul 21 08:37:12.211201 2026] [security2:error] [pid 466512:tid 466735] [client 20.226.60.151:59296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/file88.php"] [unique_id "al9Z6CKGokixMSfKDOf0FAAAAnE"]
[Tue Jul 21 08:37:12.260489 2026] [security2:error] [pid 466512:tid 466659] [client 173.252.95.29:33772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Z6CKGokixMSfKDOf0FQAAAiU"]
[Tue Jul 21 08:37:12.271699 2026] [security2:error] [pid 466512:tid 466673] [client 173.252.95.62:33102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Z6CKGokixMSfKDOf0FgAAAjM"]
[Tue Jul 21 08:37:12.426297 2026] [security2:error] [pid 466512:tid 466745] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9Z6CKGokixMSfKDOf0GgAAAns"]
[Tue Jul 21 08:37:12.482976 2026] [security2:error] [pid 466512:tid 466709] [client 20.226.60.151:59285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/ccc.php"] [unique_id "al9Z6CKGokixMSfKDOf0GwAAAlc"]
[Tue Jul 21 08:37:12.585445 2026] [security2:error] [pid 466512:tid 466731] [client 117.213.202.34:61991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z6CKGokixMSfKDOf0HgAAAm0"]
[Tue Jul 21 08:37:12.585582 2026] [security2:error] [pid 466512:tid 466731] [client 117.213.202.34:61991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z6CKGokixMSfKDOf0HgAAAm0"]
[Tue Jul 21 08:37:12.678683 2026] [security2:error] [pid 465652:tid 465857] [client 20.206.105.145:22107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/goods.php"] [unique_id "al9Z6DzTqJoBC2Mw28_OZgAAANA"]
[Tue Jul 21 08:37:12.687819 2026] [security2:error] [pid 465652:tid 465886] [client 20.220.225.223:63324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/track.php"] [unique_id "al9Z6DzTqJoBC2Mw28_OaAAAAO0"]
[Tue Jul 21 08:37:13.294534 2026] [security2:error] [pid 465652:tid 465831] [client 202.179.75.202:45180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Z6TzTqJoBC2Mw28_ObgAAALY"]
[Tue Jul 21 08:37:13.294649 2026] [security2:error] [pid 465652:tid 465831] [client 202.179.75.202:45180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Z6TzTqJoBC2Mw28_ObgAAALY"]
[Tue Jul 21 08:37:13.331505 2026] [security2:error] [pid 466512:tid 466743] [client 20.206.105.145:22261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/ms-edit.php"] [unique_id "al9Z6SKGokixMSfKDOf0KgAAAnk"]
[Tue Jul 21 08:37:13.490649 2026] [security2:error] [pid 466512:tid 466655] [client 20.226.60.151:59273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/777.php"] [unique_id "al9Z6SKGokixMSfKDOf0LQAAAiE"]
[Tue Jul 21 08:37:13.613537 2026] [security2:error] [pid 466512:tid 466710] [client 195.49.128.211:64127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Z6SKGokixMSfKDOf0MgAAAlg"]
[Tue Jul 21 08:37:13.613713 2026] [security2:error] [pid 466512:tid 466710] [client 195.49.128.211:64127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Z6SKGokixMSfKDOf0MgAAAlg"]
[Tue Jul 21 08:37:13.667404 2026] [security2:error] [pid 466512:tid 466623] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Z6SKGokixMSfKDOf0MwACcm4"]
[Tue Jul 21 08:37:13.668583 2026] [security2:error] [pid 466512:tid 466736] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Z6SKGokixMSfKDOf0MwACcm4"]
[Tue Jul 21 08:37:13.740560 2026] [security2:error] [pid 465652:tid 465803] [client 20.206.105.145:22259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/222.php"] [unique_id "al9Z6TzTqJoBC2Mw28_OdwAAAJo"]
[Tue Jul 21 08:37:14.127343 2026] [security2:error] [pid 465652:tid 465694] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9Z6jzTqJoBC2Mw28_OewAApCk"]
[Tue Jul 21 08:37:14.127529 2026] [security2:error] [pid 465652:tid 465813] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9Z6jzTqJoBC2Mw28_OewAApCk"]
[Tue Jul 21 08:37:14.209334 2026] [security2:error] [pid 466512:tid 466643] [client 20.226.60.151:64072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/for.php"] [unique_id "al9Z6iKGokixMSfKDOf0OgAAAhU"]
[Tue Jul 21 08:37:14.296859 2026] [security2:error] [pid 466512:tid 466666] [client 20.206.105.145:21976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9Z6iKGokixMSfKDOf0QwAAAiw"]
[Tue Jul 21 08:37:14.452754 2026] [security2:error] [pid 466512:tid 466756] [client 20.206.105.145:22245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9Z6iKGokixMSfKDOf0SAAAAoY"]
[Tue Jul 21 08:37:14.766770 2026] [security2:error] [pid 466512:tid 466658] [client 20.206.105.145:22111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp.php"] [unique_id "al9Z6iKGokixMSfKDOf0VAAAAiQ"]
[Tue Jul 21 08:37:14.857087 2026] [security2:error] [pid 465652:tid 465853] [client 20.226.60.151:59134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/ssla.php"] [unique_id "al9Z6jzTqJoBC2Mw28_OhwAAAMw"]
[Tue Jul 21 08:37:14.878288 2026] [security2:error] [pid 466512:tid 466703] [client 223.181.60.88:7265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Z6iKGokixMSfKDOf0WQAAAlE"]
[Tue Jul 21 08:37:14.878400 2026] [security2:error] [pid 466512:tid 466703] [client 223.181.60.88:7265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Z6iKGokixMSfKDOf0WQAAAlE"]
[Tue Jul 21 08:37:14.889938 2026] [security2:error] [pid 466512:tid 466639] [remote 47.86.33.52:20826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9Z6iKGokixMSfKDOf0WgACk34"]
[Tue Jul 21 08:37:15.226479 2026] [security2:error] [pid 466512:tid 466716] [client 20.226.60.151:64087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lucassouza.art"] [uri "/zc-131.php"] [unique_id "al9Z6yKGokixMSfKDOf0YQAAAl4"]
[Tue Jul 21 08:37:15.420176 2026] [security2:error] [pid 465652:tid 465891] [client 74.249.245.134:52190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/av.php"] [unique_id "al9Z6zzTqJoBC2Mw28_OlAAAAPI"]
[Tue Jul 21 08:37:15.577586 2026] [security2:error] [pid 466512:tid 466653] [client 20.206.105.145:22124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/abcd.php"] [unique_id "al9Z6yKGokixMSfKDOf0ZAAAAh8"]
[Tue Jul 21 08:37:15.580236 2026] [security2:error] [pid 465652:tid 465850] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/config/config.ini.php.bak"] [unique_id "al9Z6zzTqJoBC2Mw28_OlwAAAMk"]
[Tue Jul 21 08:37:15.656863 2026] [security2:error] [pid 466512:tid 466654] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Z6yKGokixMSfKDOf0ZQACIHs"]
[Tue Jul 21 08:37:15.677633 2026] [security2:error] [pid 465652:tid 465856] [client 103.151.46.103:58506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.46.151.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Z6zzTqJoBC2Mw28_OmgAAAM8"]
[Tue Jul 21 08:37:15.677774 2026] [security2:error] [pid 465652:tid 465856] [client 103.151.46.103:58506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mannucarvalho.com"] [uri "/xmlrpc.php"] [unique_id "al9Z6zzTqJoBC2Mw28_OmgAAAM8"]
[Tue Jul 21 08:37:15.967423 2026] [security2:error] [pid 466512:tid 466660] [client 20.206.105.145:22229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/a1.php"] [unique_id "al9Z6yKGokixMSfKDOf0bQAAAiY"]
[Tue Jul 21 08:37:16.123030 2026] [security2:error] [pid 466512:tid 466738] [client 152.59.181.104:52353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z7CKGokixMSfKDOf0cgAAAnQ"]
[Tue Jul 21 08:37:16.123138 2026] [security2:error] [pid 466512:tid 466738] [client 152.59.181.104:52353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z7CKGokixMSfKDOf0cgAAAnQ"]
[Tue Jul 21 08:37:16.278463 2026] [access_compat:error] [pid 466512:tid 466674] [client 162.241.63.68:39550] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:37:16.475976 2026] [security2:error] [pid 466512:tid 466757] [client 5.38.115.39:60821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Z7CKGokixMSfKDOf0gAAAAoc"]
[Tue Jul 21 08:37:16.476093 2026] [security2:error] [pid 466512:tid 466757] [client 5.38.115.39:60821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Z7CKGokixMSfKDOf0gAAAAoc"]
[Tue Jul 21 08:37:16.555789 2026] [security2:error] [pid 465652:tid 465833] [client 213.152.186.163:38872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Z7DzTqJoBC2Mw28_OrAAAALg"]
[Tue Jul 21 08:37:16.555895 2026] [security2:error] [pid 465652:tid 465833] [client 213.152.186.163:38872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9Z7DzTqJoBC2Mw28_OrAAAALg"]
[Tue Jul 21 08:37:16.770243 2026] [security2:error] [pid 465652:tid 465909] [client 173.252.95.112:46670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Z7DzTqJoBC2Mw28_OswAAAQQ"]
[Tue Jul 21 08:37:16.871381 2026] [security2:error] [pid 466512:tid 466768] [client 20.206.105.145:21996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9Z7CKGokixMSfKDOf0hAAAApI"]
[Tue Jul 21 08:37:17.021163 2026] [security2:error] [pid 466512:tid 466576] [remote 72.167.132.114:58676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Z7SKGokixMSfKDOf0hgACGD8"]
[Tue Jul 21 08:37:17.181049 2026] [security2:error] [pid 466512:tid 466717] [client 20.206.105.145:22231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9Z7SKGokixMSfKDOf0iwAAAl8"]
[Tue Jul 21 08:37:17.271458 2026] [security2:error] [pid 465652:tid 465799] [client 20.206.105.145:22238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/gettest.php"] [unique_id "al9Z7TzTqJoBC2Mw28_OvAAAAJY"]
[Tue Jul 21 08:37:17.424946 2026] [security2:error] [pid 465652:tid 465854] [client 69.171.230.15:33228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Z7TzTqJoBC2Mw28_OxAAAAM0"]
[Tue Jul 21 08:37:17.518480 2026] [security2:error] [pid 466512:tid 466760] [client 20.206.105.145:22091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/simple.php"] [unique_id "al9Z7SKGokixMSfKDOf0jwAAAoo"]
[Tue Jul 21 08:37:17.583351 2026] [security2:error] [pid 466512:tid 466711] [client 5.31.193.106:58603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Z7SKGokixMSfKDOf0kAAAAlk"]
[Tue Jul 21 08:37:17.583556 2026] [security2:error] [pid 466512:tid 466711] [client 5.31.193.106:58603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9Z7SKGokixMSfKDOf0kAAAAlk"]
[Tue Jul 21 08:37:17.697972 2026] [security2:error] [pid 466512:tid 466719] [client 20.206.105.145:22257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/xxx.php"] [unique_id "al9Z7SKGokixMSfKDOf0kQAAAmE"]
[Tue Jul 21 08:37:17.808023 2026] [security2:error] [pid 466512:tid 466727] [client 20.206.105.145:22126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/hypo.php"] [unique_id "al9Z7SKGokixMSfKDOf0kgAAAmk"]
[Tue Jul 21 08:37:17.838210 2026] [security2:error] [pid 465652:tid 465789] [client 65.21.113.253:55632] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Z7TzTqJoBC2Mw28_OvgAAAIw"]
[Tue Jul 21 08:37:17.853871 2026] [security2:error] [pid 465652:tid 465864] [client 20.206.105.145:21978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/chosen.php"] [unique_id "al9Z7TzTqJoBC2Mw28_OzAAAANc"]
[Tue Jul 21 08:37:18.041140 2026] [security2:error] [pid 466512:tid 466765] [client 14.245.224.124:52552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Z7iKGokixMSfKDOf0lwAAAo8"]
[Tue Jul 21 08:37:18.041279 2026] [security2:error] [pid 466512:tid 466765] [client 14.245.224.124:52552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Z7iKGokixMSfKDOf0lwAAAo8"]
[Tue Jul 21 08:37:18.083837 2026] [security2:error] [pid 465652:tid 465872] [client 69.171.230.15:33240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Z7jzTqJoBC2Mw28_O0AAAAN8"]
[Tue Jul 21 08:37:18.391481 2026] [security2:error] [pid 466512:tid 466682] [client 59.95.197.55:51715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z7iKGokixMSfKDOf0mgAAAjw"]
[Tue Jul 21 08:37:18.391629 2026] [security2:error] [pid 466512:tid 466682] [client 59.95.197.55:51715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z7iKGokixMSfKDOf0mgAAAjw"]
[Tue Jul 21 08:37:18.462075 2026] [security2:error] [pid 465652:tid 465851] [client 128.127.105.184:38702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Z7jzTqJoBC2Mw28_O2AAAAMo"]
[Tue Jul 21 08:37:18.462216 2026] [security2:error] [pid 465652:tid 465851] [client 128.127.105.184:38702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9Z7jzTqJoBC2Mw28_O2AAAAMo"]
[Tue Jul 21 08:37:19.029478 2026] [security2:error] [pid 465652:tid 465855] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/config/config.ini.php.old"] [unique_id "al9Z7zzTqJoBC2Mw28_O5gAAAM4"]
[Tue Jul 21 08:37:19.405208 2026] [security2:error] [pid 465652:tid 465905] [client 152.59.34.51:55452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z7zzTqJoBC2Mw28_O7AAAAQA"]
[Tue Jul 21 08:37:19.405323 2026] [security2:error] [pid 465652:tid 465905] [client 152.59.34.51:55452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z7zzTqJoBC2Mw28_O7AAAAQA"]
[Tue Jul 21 08:37:19.434780 2026] [security2:error] [pid 466512:tid 466647] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/config/config.ini.php.save"] [unique_id "al9Z7yKGokixMSfKDOf0rwAAAhk"]
[Tue Jul 21 08:37:19.561679 2026] [security2:error] [pid 465652:tid 465783] [client 20.206.105.145:22098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/als.php"] [unique_id "al9Z7zzTqJoBC2Mw28_O7gAAAIY"]
[Tue Jul 21 08:37:19.778896 2026] [security2:error] [pid 466512:tid 466694] [client 122.176.100.127:50762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Z7yKGokixMSfKDOf0tgAAAkg"]
[Tue Jul 21 08:37:19.778992 2026] [security2:error] [pid 466512:tid 466694] [client 122.176.100.127:50762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Z7yKGokixMSfKDOf0tgAAAkg"]
[Tue Jul 21 08:37:19.788240 2026] [security2:error] [pid 466512:tid 466696] [client 49.144.66.253:32666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Z7yKGokixMSfKDOf0twAAAko"]
[Tue Jul 21 08:37:19.788363 2026] [security2:error] [pid 466512:tid 466696] [client 49.144.66.253:32666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Z7yKGokixMSfKDOf0twAAAko"]
[Tue Jul 21 08:37:19.823859 2026] [security2:error] [pid 465652:tid 465833] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/matomo/config/config.ini.php.bak"] [unique_id "al9Z7zzTqJoBC2Mw28_O8wAAALg"]
[Tue Jul 21 08:37:19.839005 2026] [security2:error] [pid 466512:tid 466670] [client 144.76.19.157:33676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.19.76.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Z7yKGokixMSfKDOf0ugAAAjA"]
[Tue Jul 21 08:37:20.101969 2026] [security2:error] [pid 465652:tid 465901] [client 65.21.113.253:55632] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9Z7zzTqJoBC2Mw28_O8AAAAPw"]
[Tue Jul 21 08:37:20.393169 2026] [security2:error] [pid 466512:tid 466749] [client 103.59.206.240:31158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z8CKGokixMSfKDOf0xQAAAn8"]
[Tue Jul 21 08:37:20.393336 2026] [security2:error] [pid 466512:tid 466749] [client 103.59.206.240:31158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z8CKGokixMSfKDOf0xQAAAn8"]
[Tue Jul 21 08:37:20.417214 2026] [security2:error] [pid 466512:tid 466734] [client 195.49.128.211:56546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Z8CKGokixMSfKDOf0xgAAAnA"]
[Tue Jul 21 08:37:20.417320 2026] [security2:error] [pid 466512:tid 466734] [client 195.49.128.211:56546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Z8CKGokixMSfKDOf0xgAAAnA"]
[Tue Jul 21 08:37:20.428236 2026] [security2:error] [pid 466512:tid 466758] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/piwik/config/config.ini.php.bak"] [unique_id "al9Z8CKGokixMSfKDOf0xwAAAog"]
[Tue Jul 21 08:37:20.756019 2026] [core:error] [pid 466512:tid 466558] [remote 195.96.139.33:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpcalendars.getveltrixhealth.com:8080
[Tue Jul 21 08:37:20.756048 2026] [core:error] [pid 466512:tid 466558] [remote 195.96.139.33:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpcalendars.getveltrixhealth.com:8080
[Tue Jul 21 08:37:20.849631 2026] [security2:error] [pid 466512:tid 466764] [client 144.76.19.157:33692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.19.76.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9Z8CKGokixMSfKDOf01AAAAo4"]
[Tue Jul 21 08:37:20.893864 2026] [security2:error] [pid 466512:tid 466720] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/analytics/config/config.ini.php.bak"] [unique_id "al9Z8CKGokixMSfKDOf01QAAAmI"]
[Tue Jul 21 08:37:21.204746 2026] [security2:error] [pid 466512:tid 466672] [client 20.206.105.145:22215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/pol.php"] [unique_id "al9Z8SKGokixMSfKDOf02gAAAjI"]
[Tue Jul 21 08:37:21.342989 2026] [security2:error] [pid 466512:tid 466723] [client 152.59.181.104:52719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z8SKGokixMSfKDOf02wAAAmU"]
[Tue Jul 21 08:37:21.343159 2026] [security2:error] [pid 466512:tid 466723] [client 152.59.181.104:52719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z8SKGokixMSfKDOf02wAAAmU"]
[Tue Jul 21 08:37:22.054211 2026] [security2:error] [pid 466512:tid 466710] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/piwik.old/config/config.ini.php"] [unique_id "al9Z8iKGokixMSfKDOf03wAAAlg"]
[Tue Jul 21 08:37:22.143833 2026] [security2:error] [pid 465652:tid 465903] [client 74.249.245.134:42004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/gg.php"] [unique_id "al9Z8jzTqJoBC2Mw28_PHgAAAP4"]
[Tue Jul 21 08:37:22.551697 2026] [security2:error] [pid 465652:tid 465879] [client 20.220.225.223:54312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/2352356666.php"] [unique_id "al9Z8jzTqJoBC2Mw28_PIwAAAOY"]
[Tue Jul 21 08:37:22.743373 2026] [security2:error] [pid 466512:tid 466711] [client 2.57.122.202:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.122.57.2.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.agrocibus.com"] [uri "/matomo.old/config/config.ini.php"] [unique_id "al9Z8iKGokixMSfKDOf06AAAAlk"]
[Tue Jul 21 08:37:23.309452 2026] [security2:error] [pid 466512:tid 466719] [client 114.119.136.134:54059] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gssbrasil.com.br"] [uri "/contatos"] [unique_id "al9Z8yKGokixMSfKDOf08QAAAmE"], referer: https://www.gssbrasil.com.br/contato?lightbox=dataItem-jgogry9e
[Tue Jul 21 08:37:23.877351 2026] [security2:error] [pid 466512:tid 466764] [client 109.248.148.246:39284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Z8yKGokixMSfKDOf0-AAAAo4"]
[Tue Jul 21 08:37:23.877460 2026] [security2:error] [pid 466512:tid 466764] [client 109.248.148.246:39284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9Z8yKGokixMSfKDOf0-AAAAo4"]
[Tue Jul 21 08:37:24.182037 2026] [security2:error] [pid 466512:tid 466683] [client 195.49.128.211:64728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Z9CKGokixMSfKDOf0-wAAAj0"]
[Tue Jul 21 08:37:24.182176 2026] [security2:error] [pid 466512:tid 466683] [client 195.49.128.211:64728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Z9CKGokixMSfKDOf0-wAAAj0"]
[Tue Jul 21 08:37:24.254647 2026] [security2:error] [pid 466512:tid 466581] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Z9CKGokixMSfKDOf0_AACS0Q"]
[Tue Jul 21 08:37:24.254852 2026] [security2:error] [pid 466512:tid 466697] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Z9CKGokixMSfKDOf0_AACS0Q"]
[Tue Jul 21 08:37:24.309511 2026] [security2:error] [pid 466512:tid 466720] [client 202.179.75.202:35954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Z9CKGokixMSfKDOf0_gAAAmI"]
[Tue Jul 21 08:37:24.309695 2026] [security2:error] [pid 466512:tid 466720] [client 202.179.75.202:35954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Z9CKGokixMSfKDOf0_gAAAmI"]
[Tue Jul 21 08:37:24.318558 2026] [security2:error] [pid 466512:tid 466695] [client 117.213.202.34:62595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z8yKGokixMSfKDOf08gAAAkk"]
[Tue Jul 21 08:37:24.318676 2026] [security2:error] [pid 466512:tid 466695] [client 117.213.202.34:62595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z8yKGokixMSfKDOf08gAAAkk"]
[Tue Jul 21 08:37:24.679100 2026] [security2:error] [pid 466512:tid 466587] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9Z9CKGokixMSfKDOf1BAACLEo"]
[Tue Jul 21 08:37:24.679219 2026] [security2:error] [pid 466512:tid 466666] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9Z9CKGokixMSfKDOf1BAACLEo"]
[Tue Jul 21 08:37:24.684278 2026] [security2:error] [pid 466512:tid 466675] [client 74.249.245.134:50814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/sql.php"] [unique_id "al9Z9CKGokixMSfKDOf1BQAAAjU"]
[Tue Jul 21 08:37:25.174923 2026] [security2:error] [pid 466512:tid 466673] [client 61.1.167.83:64475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z9SKGokixMSfKDOf1EQAAAjM"]
[Tue Jul 21 08:37:25.175043 2026] [security2:error] [pid 466512:tid 466673] [client 61.1.167.83:64475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z9SKGokixMSfKDOf1EQAAAjM"]
[Tue Jul 21 08:37:25.598691 2026] [security2:error] [pid 466512:tid 466714] [client 223.181.60.88:27321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Z9SKGokixMSfKDOf1FgAAAlw"]
[Tue Jul 21 08:37:25.599412 2026] [security2:error] [pid 466512:tid 466714] [client 223.181.60.88:27321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9Z9SKGokixMSfKDOf1FgAAAlw"]
[Tue Jul 21 08:37:25.629487 2026] [security2:error] [pid 466512:tid 466671] [client 20.197.192.193:15823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lumeneducacao.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Z9SKGokixMSfKDOf1GQAAAjE"]
[Tue Jul 21 08:37:25.660097 2026] [security2:error] [pid 466512:tid 466656] [client 20.197.192.193:22668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lumeneducacao.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Z9SKGokixMSfKDOf1GgAAAiI"]
[Tue Jul 21 08:37:25.685039 2026] [security2:error] [pid 465652:tid 465888] [client 20.197.192.193:22703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lumeneducacao.com.br"] [uri "/wp-file.php"] [unique_id "al9Z9TzTqJoBC2Mw28_PTgAAAO8"]
[Tue Jul 21 08:37:25.696584 2026] [security2:error] [pid 466512:tid 466665] [client 20.197.192.193:22714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lumeneducacao.com.br"] [uri "/karma_d2a8.php"] [unique_id "al9Z9SKGokixMSfKDOf1HAAAAis"]
[Tue Jul 21 08:37:25.709315 2026] [security2:error] [pid 465652:tid 465824] [client 20.197.192.193:15808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lumeneducacao.com.br"] [uri "/karma_fb76.php"] [unique_id "al9Z9TzTqJoBC2Mw28_PTwAAAK8"]
[Tue Jul 21 08:37:25.725501 2026] [security2:error] [pid 466512:tid 466651] [client 20.197.192.193:22698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lumeneducacao.com.br"] [uri "/k.php"] [unique_id "al9Z9SKGokixMSfKDOf1HQAAAh0"]
[Tue Jul 21 08:37:25.737455 2026] [security2:error] [pid 465652:tid 465868] [client 20.197.192.193:22667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lumeneducacao.com.br"] [uri "/2ops.php"] [unique_id "al9Z9TzTqJoBC2Mw28_PUAAAANs"]
[Tue Jul 21 08:37:25.748797 2026] [security2:error] [pid 466512:tid 466736] [client 20.197.192.193:15841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lumeneducacao.com.br"] [uri "/adobe.php"] [unique_id "al9Z9SKGokixMSfKDOf1HgAAAnI"]
[Tue Jul 21 08:37:25.760802 2026] [security2:error] [pid 465652:tid 465848] [client 20.197.192.193:15834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lumeneducacao.com.br"] [uri "/mac.php"] [unique_id "al9Z9TzTqJoBC2Mw28_PUQAAAMc"]
[Tue Jul 21 08:37:25.775248 2026] [security2:error] [pid 465652:tid 465866] [client 20.197.192.193:22686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lumeneducacao.com.br"] [uri "/HLA-dd.php"] [unique_id "al9Z9TzTqJoBC2Mw28_PUgAAANk"]
[Tue Jul 21 08:37:25.855729 2026] [security2:error] [pid 466512:tid 466738] [client 20.197.192.193:15856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lumeneducacao.com.br"] [uri "/c5007147cdindex.php"] [unique_id "al9Z9SKGokixMSfKDOf1HwAAAnQ"]
[Tue Jul 21 08:37:26.040805 2026] [security2:error] [pid 465652:tid 465845] [client 20.206.105.145:22133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/file5.php"] [unique_id "al9Z9jzTqJoBC2Mw28_PXQAAAMQ"]
[Tue Jul 21 08:37:26.075698 2026] [security2:error] [pid 465652:tid 465804] [client 20.220.225.223:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/pn.php"] [unique_id "al9Z9jzTqJoBC2Mw28_PXgAAAJs"]
[Tue Jul 21 08:37:26.244908 2026] [security2:error] [pid 466512:tid 466712] [client 74.249.245.134:49291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/up.php"] [unique_id "al9Z9iKGokixMSfKDOf1JQAAAlo"]
[Tue Jul 21 08:37:26.283872 2026] [security2:error] [pid 465652:tid 465834] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9Z9jzTqJoBC2Mw28_PYgAAuS4"]
[Tue Jul 21 08:37:26.826875 2026] [security2:error] [pid 465652:tid 465820] [client 89.238.167.134:51044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Z9jzTqJoBC2Mw28_PagAAAKs"]
[Tue Jul 21 08:37:26.826988 2026] [security2:error] [pid 465652:tid 465820] [client 89.238.167.134:51044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Z9jzTqJoBC2Mw28_PagAAAKs"]
[Tue Jul 21 08:37:26.984889 2026] [security2:error] [pid 466512:tid 466754] [client 173.252.95.35:33300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9Z9iKGokixMSfKDOf1LwAAAoQ"]
[Tue Jul 21 08:37:27.195863 2026] [security2:error] [pid 466512:tid 466649] [client 5.38.115.39:61483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Z9yKGokixMSfKDOf1MgAAAhs"]
[Tue Jul 21 08:37:27.196011 2026] [security2:error] [pid 466512:tid 466649] [client 5.38.115.39:61483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9Z9yKGokixMSfKDOf1MgAAAhs"]
[Tue Jul 21 08:37:27.920349 2026] [security2:error] [pid 466512:tid 466704] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9Z9yKGokixMSfKDOf1PQAAAlI"]
[Tue Jul 21 08:37:27.976533 2026] [security2:error] [pid 465652:tid 465836] [client 20.220.225.223:47747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wp-wpbak.php"] [unique_id "al9Z9zzTqJoBC2Mw28_PfgAAALs"]
[Tue Jul 21 08:37:28.207390 2026] [security2:error] [pid 466512:tid 466746] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9Z-CKGokixMSfKDOf1QQAAAnw"]
[Tue Jul 21 08:37:28.503624 2026] [security2:error] [pid 465652:tid 465857] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/xyn.php"] [unique_id "al9Z-DzTqJoBC2Mw28_PlQAAANA"]
[Tue Jul 21 08:37:28.786547 2026] [security2:error] [pid 466512:tid 466733] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/patie.php"] [unique_id "al9Z-CKGokixMSfKDOf1TAAAAm8"]
[Tue Jul 21 08:37:28.853790 2026] [security2:error] [pid 466512:tid 466711] [client 14.245.224.124:53032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Z-CKGokixMSfKDOf1TgAAAlk"]
[Tue Jul 21 08:37:28.853928 2026] [security2:error] [pid 466512:tid 466711] [client 14.245.224.124:53032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9Z-CKGokixMSfKDOf1TgAAAlk"]
[Tue Jul 21 08:37:28.894156 2026] [security2:error] [pid 465652:tid 465870] [client 74.249.245.134:52180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/66.php"] [unique_id "al9Z-DzTqJoBC2Mw28_PpwAAAN0"]
[Tue Jul 21 08:37:28.957197 2026] [security2:error] [pid 466512:tid 466687] [client 59.95.197.55:52140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z-CKGokixMSfKDOf1UAAAAkE"]
[Tue Jul 21 08:37:28.957304 2026] [security2:error] [pid 466512:tid 466687] [client 59.95.197.55:52140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z-CKGokixMSfKDOf1UAAAAkE"]
[Tue Jul 21 08:37:29.070259 2026] [security2:error] [pid 465652:tid 465812] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/aa.php"] [unique_id "al9Z-TzTqJoBC2Mw28_PrgAAAKM"]
[Tue Jul 21 08:37:29.393677 2026] [security2:error] [pid 465652:tid 465879] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/xwpg.php"] [unique_id "al9Z-TzTqJoBC2Mw28_PvAAAAOY"]
[Tue Jul 21 08:37:29.446501 2026] [security2:error] [pid 466512:tid 466717] [client 128.127.105.184:59918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Z-SKGokixMSfKDOf1VgAAAl8"]
[Tue Jul 21 08:37:29.446596 2026] [security2:error] [pid 466512:tid 466717] [client 128.127.105.184:59918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9Z-SKGokixMSfKDOf1VgAAAl8"]
[Tue Jul 21 08:37:29.697062 2026] [security2:error] [pid 466512:tid 466695] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/ops.php"] [unique_id "al9Z-SKGokixMSfKDOf1XAAAAkk"]
[Tue Jul 21 08:37:29.740542 2026] [security2:error] [pid 465652:tid 465854] [client 136.144.42.187:62621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9Z-TzTqJoBC2Mw28_PwgAAAM0"]
[Tue Jul 21 08:37:29.740691 2026] [security2:error] [pid 466512:tid 466652] [client 185.251.19.64:28943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9Z-SKGokixMSfKDOf1XwAAAh4"]
[Tue Jul 21 08:37:29.816331 2026] [security2:error] [pid 466512:tid 466724] [client 20.206.105.145:22129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9Z-SKGokixMSfKDOf1YAAAAmY"]
[Tue Jul 21 08:37:30.207901 2026] [security2:error] [pid 466512:tid 466642] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/mac.php"] [unique_id "al9Z-iKGokixMSfKDOf1ZgAAAhQ"]
[Tue Jul 21 08:37:30.210785 2026] [security2:error] [pid 466512:tid 466730] [client 122.176.100.127:51275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Z-iKGokixMSfKDOf1ZwAAAmw"]
[Tue Jul 21 08:37:30.211101 2026] [security2:error] [pid 466512:tid 466730] [client 122.176.100.127:51275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9Z-iKGokixMSfKDOf1ZwAAAmw"]
[Tue Jul 21 08:37:30.484559 2026] [security2:error] [pid 465652:tid 465817] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/mg.php"] [unique_id "al9Z-jzTqJoBC2Mw28_P0wAAAKg"]
[Tue Jul 21 08:37:30.573062 2026] [security2:error] [pid 466512:tid 466679] [client 185.251.19.79:27045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9Z-iKGokixMSfKDOf1bQAAAjk"]
[Tue Jul 21 08:37:30.583750 2026] [security2:error] [pid 466512:tid 466673] [client 74.249.245.134:20856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/666.php"] [unique_id "al9Z-iKGokixMSfKDOf1bgAAAjM"]
[Tue Jul 21 08:37:30.657167 2026] [security2:error] [pid 466512:tid 466669] [client 152.59.34.51:55941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z-iKGokixMSfKDOf1cAAAAi8"]
[Tue Jul 21 08:37:30.657292 2026] [security2:error] [pid 466512:tid 466669] [client 152.59.34.51:55941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z-iKGokixMSfKDOf1cAAAAi8"]
[Tue Jul 21 08:37:30.667450 2026] [security2:error] [pid 466512:tid 466704] [client 49.144.66.253:32839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Z-iKGokixMSfKDOf1cQAAAlI"]
[Tue Jul 21 08:37:30.667538 2026] [security2:error] [pid 466512:tid 466704] [client 49.144.66.253:32839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9Z-iKGokixMSfKDOf1cQAAAlI"]
[Tue Jul 21 08:37:30.767381 2026] [security2:error] [pid 466512:tid 466664] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-post-data.php"] [unique_id "al9Z-iKGokixMSfKDOf1cwAAAio"]
[Tue Jul 21 08:37:31.042656 2026] [security2:error] [pid 466512:tid 466648] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/pucci.php"] [unique_id "al9Z-yKGokixMSfKDOf1eAAAAho"]
[Tue Jul 21 08:37:31.046003 2026] [security2:error] [pid 466512:tid 466753] [client 195.49.128.211:57154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Z-yKGokixMSfKDOf1eQAAAoM"]
[Tue Jul 21 08:37:31.046135 2026] [security2:error] [pid 466512:tid 466753] [client 195.49.128.211:57154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9Z-yKGokixMSfKDOf1eQAAAoM"]
[Tue Jul 21 08:37:31.056164 2026] [security2:error] [pid 466512:tid 466747] [client 109.248.148.246:51126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.148.248.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Z-yKGokixMSfKDOf1egAAAn0"]
[Tue Jul 21 08:37:31.056263 2026] [security2:error] [pid 466512:tid 466747] [client 109.248.148.246:51126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9Z-yKGokixMSfKDOf1egAAAn0"]
[Tue Jul 21 08:37:31.060892 2026] [security2:error] [pid 465652:tid 465787] [client 152.59.181.104:53122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z-zzTqJoBC2Mw28_P4AAAAIo"]
[Tue Jul 21 08:37:31.065545 2026] [security2:error] [pid 465652:tid 465787] [client 152.59.181.104:53122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9Z-zzTqJoBC2Mw28_P4AAAAIo"]
[Tue Jul 21 08:37:31.310619 2026] [security2:error] [pid 466512:tid 466736] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/black.php"] [unique_id "al9Z-yKGokixMSfKDOf1fwAAAnI"]
[Tue Jul 21 08:37:31.581783 2026] [security2:error] [pid 466512:tid 466755] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/zlece.php"] [unique_id "al9Z-yKGokixMSfKDOf1gwAAAoU"]
[Tue Jul 21 08:37:31.848796 2026] [security2:error] [pid 465652:tid 465821] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/vssrs.php"] [unique_id "al9Z-zzTqJoBC2Mw28_P7AAAAKw"]
[Tue Jul 21 08:37:31.982246 2026] [security2:error] [pid 466512:tid 466651] [client 103.59.206.240:31422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z-yKGokixMSfKDOf1iQAAAh0"]
[Tue Jul 21 08:37:31.982381 2026] [security2:error] [pid 466512:tid 466651] [client 103.59.206.240:31422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z-yKGokixMSfKDOf1iQAAAh0"]
[Tue Jul 21 08:37:32.117046 2026] [security2:error] [pid 466512:tid 466697] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wicked.php"] [unique_id "al9Z_CKGokixMSfKDOf1jQAAAks"]
[Tue Jul 21 08:37:32.392954 2026] [security2:error] [pid 466512:tid 466750] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/24.php"] [unique_id "al9Z_CKGokixMSfKDOf1kgAAAoA"]
[Tue Jul 21 08:37:32.480416 2026] [security2:error] [pid 465652:tid 465792] [client 20.206.105.145:21762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/file.php"] [unique_id "al9Z_DzTqJoBC2Mw28_P8gAAAI8"]
[Tue Jul 21 08:37:32.675484 2026] [security2:error] [pid 466512:tid 466730] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/xacs.php"] [unique_id "al9Z_CKGokixMSfKDOf1mQAAAmw"]
[Tue Jul 21 08:37:32.775512 2026] [security2:error] [pid 466512:tid 466694] [client 74.249.245.134:55559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/byp.php"] [unique_id "al9Z_CKGokixMSfKDOf1nQAAAkg"]
[Tue Jul 21 08:37:32.958423 2026] [security2:error] [pid 466512:tid 466679] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/zildan.php"] [unique_id "al9Z_CKGokixMSfKDOf1oQAAAjk"]
[Tue Jul 21 08:37:33.243101 2026] [security2:error] [pid 466512:tid 466648] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/csa.php"] [unique_id "al9Z_SKGokixMSfKDOf1pwAAAho"]
[Tue Jul 21 08:37:33.495811 2026] [security2:error] [pid 466512:tid 466573] [remote 152.53.111.131:56100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9Z_SKGokixMSfKDOf1qwACWDw"]
[Tue Jul 21 08:37:33.526646 2026] [security2:error] [pid 465652:tid 465788] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/w3llscc.php"] [unique_id "al9Z_TzTqJoBC2Mw28_QBAAAAIs"]
[Tue Jul 21 08:37:33.822908 2026] [security2:error] [pid 465652:tid 465855] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wpx.php"] [unique_id "al9Z_TzTqJoBC2Mw28_QDwAAAM4"]
[Tue Jul 21 08:37:33.836734 2026] [security2:error] [pid 465652:tid 465703] [remote 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cristaofitsuplementos.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9Z_TzTqJoBC2Mw28_QEAABAjI"]
[Tue Jul 21 08:37:33.983790 2026] [security2:error] [pid 465652:tid 465699] [remote 85.204.70.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cristaofitsuplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9Z_TzTqJoBC2Mw28_QFgAAlS4"]
[Tue Jul 21 08:37:33.999361 2026] [security2:error] [pid 465652:tid 465784] [client 117.213.202.34:63200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z_TzTqJoBC2Mw28_QFwAAAIc"]
[Tue Jul 21 08:37:33.999551 2026] [security2:error] [pid 465652:tid 465784] [client 117.213.202.34:63200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9Z_TzTqJoBC2Mw28_QFwAAAIc"]
[Tue Jul 21 08:37:34.099007 2026] [security2:error] [pid 465652:tid 465806] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-css.php"] [unique_id "al9Z_jzTqJoBC2Mw28_QGwAAAJ0"]
[Tue Jul 21 08:37:34.367889 2026] [security2:error] [pid 466512:tid 466674] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/ho.php"] [unique_id "al9Z_iKGokixMSfKDOf1vQAAAjQ"]
[Tue Jul 21 08:37:34.647289 2026] [security2:error] [pid 466512:tid 466699] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/xy.php"] [unique_id "al9Z_iKGokixMSfKDOf1xgAAAk0"]
[Tue Jul 21 08:37:34.742012 2026] [security2:error] [pid 465652:tid 465846] [client 195.49.128.211:65335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Z_jzTqJoBC2Mw28_QKAAAAMU"]
[Tue Jul 21 08:37:34.742158 2026] [security2:error] [pid 465652:tid 465846] [client 195.49.128.211:65335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9Z_jzTqJoBC2Mw28_QKAAAAMU"]
[Tue Jul 21 08:37:34.750844 2026] [security2:error] [pid 465652:tid 465707] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Z_jzTqJoBC2Mw28_QKQAA4TY"]
[Tue Jul 21 08:37:34.751053 2026] [security2:error] [pid 465652:tid 465874] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9Z_jzTqJoBC2Mw28_QKQAA4TY"]
[Tue Jul 21 08:37:34.907469 2026] [security2:error] [pid 466512:tid 466762] [client 173.239.240.24:61041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cinspeluz.com.br"] [uri "/wp-login.php"] [unique_id "al9Z_iKGokixMSfKDOf1xwAAAow"], referer: https://t.co/
[Tue Jul 21 08:37:34.930808 2026] [security2:error] [pid 465652:tid 465827] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/loader.php"] [unique_id "al9Z_jzTqJoBC2Mw28_QLAAAALI"]
[Tue Jul 21 08:37:35.016965 2026] [security2:error] [pid 466512:tid 466640] [remote 100.42.189.89:39766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9Z_yKGokixMSfKDOf1yQACVX8"]
[Tue Jul 21 08:37:35.113186 2026] [security2:error] [pid 466512:tid 466656] [client 20.206.105.145:22008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/cfile.php"] [unique_id "al9Z_yKGokixMSfKDOf1zwAAAiI"]
[Tue Jul 21 08:37:35.210466 2026] [security2:error] [pid 466512:tid 466767] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/spadex.php"] [unique_id "al9Z_yKGokixMSfKDOf10AAAApE"]
[Tue Jul 21 08:37:35.214914 2026] [security2:error] [pid 465652:tid 465831] [client 202.179.75.202:42302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Z_zzTqJoBC2Mw28_QNQAAALY"]
[Tue Jul 21 08:37:35.215016 2026] [security2:error] [pid 465652:tid 465831] [client 202.179.75.202:42302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9Z_zzTqJoBC2Mw28_QNQAAALY"]
[Tue Jul 21 08:37:35.283943 2026] [security2:error] [pid 465652:tid 465679] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9Z_zzTqJoBC2Mw28_QNwAAiho"]
[Tue Jul 21 08:37:35.284171 2026] [security2:error] [pid 465652:tid 465787] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9Z_zzTqJoBC2Mw28_QNwAAiho"]
[Tue Jul 21 08:37:35.586416 2026] [security2:error] [pid 466512:tid 466752] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/2x.php"] [unique_id "al9Z_yKGokixMSfKDOf12AAAAoI"]
[Tue Jul 21 08:37:35.861017 2026] [security2:error] [pid 465652:tid 465891] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/ctex1.php"] [unique_id "al9Z_zzTqJoBC2Mw28_QRwAAAPI"]
[Tue Jul 21 08:37:36.009181 2026] [security2:error] [pid 465652:tid 465773] [remote 85.204.70.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cristaofitsuplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9aADzTqJoBC2Mw28_QSQAA-3g"]
[Tue Jul 21 08:37:36.009380 2026] [security2:error] [pid 465652:tid 465900] [client 85.204.70.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cristaofitsuplementos.com"] [uri "/xmlrpc.php"] [unique_id "al9aADzTqJoBC2Mw28_QSQAA-3g"]
[Tue Jul 21 08:37:36.142472 2026] [security2:error] [pid 466512:tid 466753] [client 20.206.105.145:22213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/class-wp.php"] [unique_id "al9aACKGokixMSfKDOf13wAAAoM"]
[Tue Jul 21 08:37:36.145011 2026] [security2:error] [pid 466512:tid 466758] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/edorxrr.php"] [unique_id "al9aACKGokixMSfKDOf14QAAAog"]
[Tue Jul 21 08:37:36.429786 2026] [security2:error] [pid 466512:tid 466548] [remote 162.243.80.244:47086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "hostag.com.br"] [uri "/.env"] [unique_id "al9aACKGokixMSfKDOf16QACOyM"]
[Tue Jul 21 08:37:36.460329 2026] [security2:error] [pid 466512:tid 466654] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/miru1.php"] [unique_id "al9aACKGokixMSfKDOf16gAAAiA"]
[Tue Jul 21 08:37:36.768895 2026] [security2:error] [pid 465652:tid 465873] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/sump1.php"] [unique_id "al9aADzTqJoBC2Mw28_QWwAAAOA"]
[Tue Jul 21 08:37:36.771911 2026] [security2:error] [pid 466512:tid 466604] [remote 81.173.115.7:44062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "darsenavogamarine.com"] [uri "/wp-login.php"] [unique_id "al9aACKGokixMSfKDOf17gACdFs"]
[Tue Jul 21 08:37:36.974351 2026] [security2:error] [pid 466512:tid 466761] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aACKGokixMSfKDOf17wACizU"]
[Tue Jul 21 08:37:37.072334 2026] [security2:error] [pid 465652:tid 465885] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/file5.php"] [unique_id "al9aATzTqJoBC2Mw28_QXwAAAOw"]
[Tue Jul 21 08:37:37.134875 2026] [security2:error] [pid 466512:tid 466698] [client 223.181.60.88:21753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aASKGokixMSfKDOf18QAAAkw"]
[Tue Jul 21 08:37:37.135016 2026] [security2:error] [pid 466512:tid 466698] [client 223.181.60.88:21753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aASKGokixMSfKDOf18QAAAkw"]
[Tue Jul 21 08:37:37.165835 2026] [security2:error] [pid 466512:tid 466720] [client 173.239.240.16:58897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinspeluz.com.br"] [uri "/wp-login.php"] [unique_id "al9aACKGokixMSfKDOf18AAAAmI"], referer: https://www.bing.com/
[Tue Jul 21 08:37:37.344657 2026] [security2:error] [pid 465652:tid 465890] [client 172.233.172.167:34644] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "humanizarmed.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9aATzTqJoBC2Mw28_QaQAAAPE"]
[Tue Jul 21 08:37:37.350034 2026] [security2:error] [pid 466512:tid 466724] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/0xD.php"] [unique_id "al9aASKGokixMSfKDOf18gAAAmY"]
[Tue Jul 21 08:37:37.356171 2026] [security2:error] [pid 465652:tid 465851] [client 34.26.127.63:53577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.127.26.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugardefender24.shop-officialstore.com"] [uri "/xmlrpc.php"] [unique_id "al9aADzTqJoBC2Mw28_QTwAAAMo"]
[Tue Jul 21 08:37:37.455197 2026] [security2:error] [pid 465652:tid 465887] [client 172.233.172.167:34644] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "humanizarmed.com.br"] [uri "/"] [unique_id "al9aATzTqJoBC2Mw28_QbgAAAO4"]
[Tue Jul 21 08:37:37.655584 2026] [security2:error] [pid 466512:tid 466672] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/fnstall.php"] [unique_id "al9aASKGokixMSfKDOf19AAAAjI"]
[Tue Jul 21 08:37:37.762342 2026] [security2:error] [pid 466512:tid 466612] [remote 119.195.102.159:57114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-login.php"] [unique_id "al9aASKGokixMSfKDOf19gACS2M"]
[Tue Jul 21 08:37:37.790840 2026] [security2:error] [pid 465652:tid 465817] [client 5.38.115.39:62032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aATzTqJoBC2Mw28_QdgAAAKg"]
[Tue Jul 21 08:37:37.790940 2026] [security2:error] [pid 465652:tid 465817] [client 5.38.115.39:62032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aATzTqJoBC2Mw28_QdgAAAKg"]
[Tue Jul 21 08:37:37.877374 2026] [security2:error] [pid 465652:tid 465818] [client 20.206.105.145:22253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/admin.php"] [unique_id "al9aATzTqJoBC2Mw28_QegAAAKk"]
[Tue Jul 21 08:37:37.892147 2026] [security2:error] [pid 466512:tid 466668] [client 34.26.127.63:60198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sugardefender24.shop-officialstore.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9aASKGokixMSfKDOf1-AAAAi4"]
[Tue Jul 21 08:37:37.938551 2026] [security2:error] [pid 465652:tid 465812] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/acp.php"] [unique_id "al9aATzTqJoBC2Mw28_QewAAAKM"]
[Tue Jul 21 08:37:38.221243 2026] [security2:error] [pid 466512:tid 466670] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/mosty.php"] [unique_id "al9aAiKGokixMSfKDOf1_wAAAjA"]
[Tue Jul 21 08:37:38.410098 2026] [security2:error] [pid 466512:tid 466673] [client 20.206.105.145:22230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/aa2.php"] [unique_id "al9aAiKGokixMSfKDOf2AQAAAjM"]
[Tue Jul 21 08:37:38.422591 2026] [security2:error] [pid 466512:tid 466645] [client 34.26.127.63:56289] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sugardefender24.shop-officialstore.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9aAiKGokixMSfKDOf2AwAAAhc"]
[Tue Jul 21 08:37:38.517508 2026] [security2:error] [pid 466512:tid 466686] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/6.php"] [unique_id "al9aAiKGokixMSfKDOf2BwAAAkA"]
[Tue Jul 21 08:37:38.571181 2026] [security2:error] [pid 465652:tid 465807] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9aAjzTqJoBC2Mw28_QhwAAAJ4"]
[Tue Jul 21 08:37:38.864895 2026] [security2:error] [pid 466512:tid 466716] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9aAiKGokixMSfKDOf2DgAAAl4"]
[Tue Jul 21 08:37:38.885700 2026] [security2:error] [pid 466512:tid 466732] [client 114.119.145.150:54421] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sogastro.com.br"] [uri "/&sa=U"] [unique_id "al9aAiKGokixMSfKDOf2DwAAAm4"], referer: https://sogastro.com.br/&sa=U
[Tue Jul 21 08:37:38.926974 2026] [security2:error] [pid 465652:tid 465804] [client 35.204.70.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.70.204.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aAjzTqJoBC2Mw28_QkgAAAJs"]
[Tue Jul 21 08:37:38.935885 2026] [security2:error] [pid 466512:tid 466759] [client 34.26.127.63:54061] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sugardefender24.shop-officialstore.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9aAiKGokixMSfKDOf2EgAAAok"]
[Tue Jul 21 08:37:38.959633 2026] [security2:error] [pid 466512:tid 466694] [client 5.31.193.106:58596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aAiKGokixMSfKDOf2FAAAAkg"]
[Tue Jul 21 08:37:38.968439 2026] [security2:error] [pid 466512:tid 466694] [client 5.31.193.106:58596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aAiKGokixMSfKDOf2FAAAAkg"]
[Tue Jul 21 08:37:39.133518 2026] [security2:error] [pid 466512:tid 466651] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/qqqa.php"] [unique_id "al9aAyKGokixMSfKDOf2GAAAAh0"]
[Tue Jul 21 08:37:39.314823 2026] [security2:error] [pid 465652:tid 465678] [remote 20.118.34.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-content/plugins/anttt/simple.php"] [unique_id "al9aATzTqJoBC2Mw28_QaAABBBk"], referer: www.google.com
[Tue Jul 21 08:37:39.401450 2026] [security2:error] [pid 466512:tid 466659] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/aunmc.php"] [unique_id "al9aAyKGokixMSfKDOf2IAAAAiU"]
[Tue Jul 21 08:37:39.444300 2026] [security2:error] [pid 466512:tid 466741] [client 34.26.127.63:61926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sugardefender24.shop-officialstore.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9aAyKGokixMSfKDOf2IQAAAnc"]
[Tue Jul 21 08:37:39.470811 2026] [security2:error] [pid 466512:tid 466700] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9aAyKGokixMSfKDOf2IgAAAk4"]
[Tue Jul 21 08:37:39.593870 2026] [security2:error] [pid 466512:tid 466649] [client 14.245.224.124:53508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aAyKGokixMSfKDOf2KAAAAhs"]
[Tue Jul 21 08:37:39.594020 2026] [security2:error] [pid 466512:tid 466649] [client 14.245.224.124:53508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aAyKGokixMSfKDOf2KAAAAhs"]
[Tue Jul 21 08:37:39.598416 2026] [security2:error] [pid 466512:tid 466551] [remote 216.73.216.184:19277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapd.xml"] [unique_id "al9aAyKGokixMSfKDOf2KQACMSY"]
[Tue Jul 21 08:37:39.652864 2026] [security2:error] [pid 465652:tid 465902] [client 59.95.197.55:52575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aAzzTqJoBC2Mw28_QmwAAAP0"]
[Tue Jul 21 08:37:39.654320 2026] [security2:error] [pid 465652:tid 465902] [client 59.95.197.55:52575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aAzzTqJoBC2Mw28_QmwAAAP0"]
[Tue Jul 21 08:37:39.676102 2026] [security2:error] [pid 465652:tid 465784] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/uoocf.php"] [unique_id "al9aAzzTqJoBC2Mw28_QnAAAAIc"]
[Tue Jul 21 08:37:39.836810 2026] [security2:error] [pid 465652:tid 465882] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9aAzzTqJoBC2Mw28_QoQAAAOk"]
[Tue Jul 21 08:37:39.953328 2026] [security2:error] [pid 466512:tid 466661] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/iywwi.php"] [unique_id "al9aAyKGokixMSfKDOf2LgAAAic"]
[Tue Jul 21 08:37:39.961059 2026] [security2:error] [pid 465652:tid 465782] [client 34.26.127.63:51987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sugardefender24.shop-officialstore.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9aAzzTqJoBC2Mw28_QpAAAAIU"]
[Tue Jul 21 08:37:40.009543 2026] [security2:error] [pid 466512:tid 466610] [remote 20.118.34.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-content/plugins/TOPXOH/wDR.php"] [unique_id "al9aBCKGokixMSfKDOf2LwACLGE"], referer: www.google.com
[Tue Jul 21 08:37:40.142876 2026] [security2:error] [pid 466512:tid 466712] [client 20.63.100.92:2603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9aAyKGokixMSfKDOf2GQAAAlo"]
[Tue Jul 21 08:37:40.195528 2026] [security2:error] [pid 466512:tid 466680] [client 20.206.105.145:22235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/ccou.php"] [unique_id "al9aBCKGokixMSfKDOf2MAAAAjo"]
[Tue Jul 21 08:37:40.236180 2026] [security2:error] [pid 466512:tid 466686] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/gqgsa.php"] [unique_id "al9aBCKGokixMSfKDOf2MQAAAkA"]
[Tue Jul 21 08:37:40.324052 2026] [security2:error] [pid 465652:tid 465887] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9aBDzTqJoBC2Mw28_QpwAAAO4"]
[Tue Jul 21 08:37:40.471660 2026] [security2:error] [pid 466512:tid 466669] [client 34.26.127.63:53653] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sugardefender24.shop-officialstore.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9aBCKGokixMSfKDOf2NgAAAi8"]
[Tue Jul 21 08:37:40.519769 2026] [security2:error] [pid 466512:tid 466664] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/elbzl.php"] [unique_id "al9aBCKGokixMSfKDOf2NwAAAio"]
[Tue Jul 21 08:37:40.525534 2026] [security2:error] [pid 466512:tid 466567] [remote 202.51.202.242:36332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9aAyKGokixMSfKDOf2IwACRzY"]
[Tue Jul 21 08:37:40.672737 2026] [security2:error] [pid 466512:tid 466732] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9aBCKGokixMSfKDOf2OwAAAm4"]
[Tue Jul 21 08:37:40.696266 2026] [security2:error] [pid 466512:tid 466673] [client 122.176.100.127:51770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aBCKGokixMSfKDOf2PAAAAjM"]
[Tue Jul 21 08:37:40.696363 2026] [security2:error] [pid 466512:tid 466673] [client 122.176.100.127:51770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aBCKGokixMSfKDOf2PAAAAjM"]
[Tue Jul 21 08:37:40.794692 2026] [security2:error] [pid 466512:tid 466759] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/adjig.php"] [unique_id "al9aBCKGokixMSfKDOf2PwAAAok"]
[Tue Jul 21 08:37:41.046744 2026] [security2:error] [pid 466512:tid 466694] [client 34.26.127.63:56658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sugardefender24.shop-officialstore.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9aBSKGokixMSfKDOf2SQAAAkg"]
[Tue Jul 21 08:37:41.069356 2026] [security2:error] [pid 466512:tid 466742] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9aBSKGokixMSfKDOf2SgAAAng"]
[Tue Jul 21 08:37:41.074482 2026] [security2:error] [pid 466512:tid 466729] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/byp.php"] [unique_id "al9aBSKGokixMSfKDOf2SwAAAms"]
[Tue Jul 21 08:37:41.109012 2026] [security2:error] [pid 466512:tid 466590] [remote 47.86.33.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9aBSKGokixMSfKDOf2TAACRU0"]
[Tue Jul 21 08:37:41.116971 2026] [security2:error] [pid 465652:tid 465837] [client 152.59.34.51:56419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aBTzTqJoBC2Mw28_QvAAAALw"]
[Tue Jul 21 08:37:41.117141 2026] [security2:error] [pid 465652:tid 465837] [client 152.59.34.51:56419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aBTzTqJoBC2Mw28_QvAAAALw"]
[Tue Jul 21 08:37:41.227602 2026] [security2:error] [pid 466512:tid 466560] [remote 20.118.34.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-content/plugins/wordpresss3cll/up.php"] [unique_id "al9aBSKGokixMSfKDOf2TQACOS8"], referer: www.google.com
[Tue Jul 21 08:37:41.349272 2026] [security2:error] [pid 466512:tid 466687] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9aBSKGokixMSfKDOf2UgAAAkE"]
[Tue Jul 21 08:37:41.531235 2026] [security2:error] [pid 466512:tid 466748] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9aBSKGokixMSfKDOf2VwAAAn4"]
[Tue Jul 21 08:37:41.582627 2026] [security2:error] [pid 466512:tid 466762] [client 34.26.127.63:60833] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sugardefender24.shop-officialstore.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9aBSKGokixMSfKDOf2WQAAAow"]
[Tue Jul 21 08:37:41.626152 2026] [security2:error] [pid 465652:tid 465891] [client 195.49.128.211:57755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aBTzTqJoBC2Mw28_QwwAAAPI"]
[Tue Jul 21 08:37:41.626267 2026] [security2:error] [pid 465652:tid 465891] [client 195.49.128.211:57755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aBTzTqJoBC2Mw28_QwwAAAPI"]
[Tue Jul 21 08:37:41.631840 2026] [security2:error] [pid 466512:tid 466670] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/classwithtostring.php"] [unique_id "al9aBSKGokixMSfKDOf2WgAAAjA"]
[Tue Jul 21 08:37:41.719064 2026] [security2:error] [pid 466512:tid 466738] [client 152.59.181.104:53559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aBSKGokixMSfKDOf2XAAAAnQ"]
[Tue Jul 21 08:37:41.719210 2026] [security2:error] [pid 466512:tid 466738] [client 152.59.181.104:53559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aBSKGokixMSfKDOf2XAAAAnQ"]
[Tue Jul 21 08:37:41.743410 2026] [security2:error] [pid 466512:tid 466685] [client 49.144.66.253:33007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aBSKGokixMSfKDOf2XQAAAj8"]
[Tue Jul 21 08:37:41.743527 2026] [security2:error] [pid 466512:tid 466685] [client 49.144.66.253:33007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aBSKGokixMSfKDOf2XQAAAj8"]
[Tue Jul 21 08:37:41.913856 2026] [security2:error] [pid 466512:tid 466650] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/root.php"] [unique_id "al9aBSKGokixMSfKDOf2YQAAAhw"]
[Tue Jul 21 08:37:41.958196 2026] [security2:error] [pid 466512:tid 466522] [remote 20.118.34.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.34.118.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-content/plugins/wp-file-upload/ROOBOTS.php"] [unique_id "al9aBSKGokixMSfKDOf2ZAACNwk"], referer: www.google.com
[Tue Jul 21 08:37:42.102361 2026] [security2:error] [pid 466512:tid 466755] [client 34.26.127.63:61652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sugardefender24.shop-officialstore.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9aBiKGokixMSfKDOf2ZgAAAoU"]
[Tue Jul 21 08:37:42.162500 2026] [security2:error] [pid 465652:tid 465877] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9aBjzTqJoBC2Mw28_QygAAAOQ"]
[Tue Jul 21 08:37:42.200317 2026] [security2:error] [pid 465652:tid 465870] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/sym403.php"] [unique_id "al9aBjzTqJoBC2Mw28_QywAAAN0"]
[Tue Jul 21 08:37:42.482532 2026] [security2:error] [pid 466512:tid 466759] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/v543.php"] [unique_id "al9aBiKGokixMSfKDOf2aQAAAok"]
[Tue Jul 21 08:37:42.533612 2026] [security2:error] [pid 466512:tid 466695] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9aBiKGokixMSfKDOf2bQAAAkk"]
[Tue Jul 21 08:37:42.599486 2026] [security2:error] [pid 466512:tid 466732] [client 34.26.127.63:56625] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sugardefender24.shop-officialstore.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9aBiKGokixMSfKDOf2cQAAAm4"]
[Tue Jul 21 08:37:42.613313 2026] [security2:error] [pid 465652:tid 465813] [client 20.206.105.145:22220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/dr.php"] [unique_id "al9aBjzTqJoBC2Mw28_Q0wAAAKQ"]
[Tue Jul 21 08:37:42.742253 2026] [security2:error] [pid 466512:tid 466758] [client 103.59.206.240:31034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aBiKGokixMSfKDOf2cgAAAog"]
[Tue Jul 21 08:37:42.742379 2026] [security2:error] [pid 466512:tid 466758] [client 103.59.206.240:31034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aBiKGokixMSfKDOf2cgAAAog"]
[Tue Jul 21 08:37:42.756987 2026] [security2:error] [pid 466512:tid 466742] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/sixxis.php"] [unique_id "al9aBiKGokixMSfKDOf2cwAAAng"]
[Tue Jul 21 08:37:42.818073 2026] [security2:error] [pid 466512:tid 466675] [client 173.252.95.63:42274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9aBSKGokixMSfKDOf2WwAAAjU"]
[Tue Jul 21 08:37:42.941303 2026] [security2:error] [pid 466512:tid 466648] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9aBiKGokixMSfKDOf2dQAAAho"]
[Tue Jul 21 08:37:43.025772 2026] [security2:error] [pid 466512:tid 466750] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/ip.php"] [unique_id "al9aByKGokixMSfKDOf2dwAAAoA"]
[Tue Jul 21 08:37:43.286344 2026] [security2:error] [pid 466512:tid 466651] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9aByKGokixMSfKDOf2fQAAAh0"]
[Tue Jul 21 08:37:43.301354 2026] [security2:error] [pid 466512:tid 466767] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/kq1.php"] [unique_id "al9aByKGokixMSfKDOf2fgAAApE"]
[Tue Jul 21 08:37:43.418227 2026] [security2:error] [pid 466512:tid 466528] [remote 97.74.87.194:51810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9aByKGokixMSfKDOf2gAACcA8"]
[Tue Jul 21 08:37:43.418381 2026] [security2:error] [pid 466512:tid 466734] [client 97.74.87.194:51810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9aByKGokixMSfKDOf2gAACcA8"]
[Tue Jul 21 08:37:43.489247 2026] [security2:error] [pid 466512:tid 466622] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sejabarbara.com.br"] [uri "/1a3382jcn3cblzdclu9laql2z.php"] [unique_id "al9aBiKGokixMSfKDOf2agACOG0"], referer: https://sejabarbara.com/1a3382jcn3cblzdclu9laql2z.php
[Tue Jul 21 08:37:43.582593 2026] [security2:error] [pid 466512:tid 466728] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9aByKGokixMSfKDOf2hgAAAmo"]
[Tue Jul 21 08:37:43.668388 2026] [security2:error] [pid 465652:tid 465802] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9aBzzTqJoBC2Mw28_Q5gAAAJk"]
[Tue Jul 21 08:37:43.856623 2026] [security2:error] [pid 465652:tid 465811] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/h02ugyh.php"] [unique_id "al9aBzzTqJoBC2Mw28_Q6AAAAKI"]
[Tue Jul 21 08:37:44.093447 2026] [security2:error] [pid 465652:tid 465694] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sejabarbara.com.br"] [uri "/backend/.env"] [unique_id "al9aCDzTqJoBC2Mw28_Q7AAArSk"], referer: https://sejabarbara.com/backend/.env
[Tue Jul 21 08:37:44.093465 2026] [security2:error] [pid 465652:tid 465714] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sejabarbara.com.br"] [uri "/.env"] [unique_id "al9aCDzTqJoBC2Mw28_Q7QAArT0"], referer: https://sejabarbara.com/.env
[Tue Jul 21 08:37:44.145134 2026] [security2:error] [pid 465652:tid 465824] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-temp.php"] [unique_id "al9aCDzTqJoBC2Mw28_Q8AAAAK8"]
[Tue Jul 21 08:37:44.209677 2026] [security2:error] [pid 465652:tid 465880] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9aCDzTqJoBC2Mw28_Q8wAAAOc"]
[Tue Jul 21 08:37:44.428138 2026] [security2:error] [pid 465652:tid 465787] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9aCDzTqJoBC2Mw28_Q9wAAAIo"]
[Tue Jul 21 08:37:44.548274 2026] [security2:error] [pid 465652:tid 465843] [client 117.213.202.34:63806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aCDzTqJoBC2Mw28_Q-gAAAMI"]
[Tue Jul 21 08:37:44.548414 2026] [security2:error] [pid 465652:tid 465843] [client 117.213.202.34:63806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aCDzTqJoBC2Mw28_Q-gAAAMI"]
[Tue Jul 21 08:37:44.560963 2026] [security2:error] [pid 465652:tid 465881] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9aCDzTqJoBC2Mw28_Q_QAAAOg"]
[Tue Jul 21 08:37:44.748866 2026] [security2:error] [pid 466512:tid 466762] [client 61.1.167.83:65038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aCCKGokixMSfKDOf2lgAAAow"]
[Tue Jul 21 08:37:44.762617 2026] [security2:error] [pid 466512:tid 466762] [client 61.1.167.83:65038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aCCKGokixMSfKDOf2lgAAAow"]
[Tue Jul 21 08:37:44.867647 2026] [security2:error] [pid 466512:tid 466744] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9aCCKGokixMSfKDOf2mAAAAno"]
[Tue Jul 21 08:37:44.914772 2026] [security2:error] [pid 466512:tid 466642] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9aCCKGokixMSfKDOf2mQAAAhQ"]
[Tue Jul 21 08:37:45.038273 2026] [security2:error] [pid 466512:tid 466524] [remote 216.73.216.184:41246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapd.xml"] [unique_id "al9aCSKGokixMSfKDOf2mwACPgs"]
[Tue Jul 21 08:37:45.278639 2026] [security2:error] [pid 465652:tid 465792] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9aCTzTqJoBC2Mw28_RCAAAAI8"]
[Tue Jul 21 08:37:45.288609 2026] [security2:error] [pid 466512:tid 466702] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/jj.php"] [unique_id "al9aCSKGokixMSfKDOf2oQAAAlA"]
[Tue Jul 21 08:37:45.325551 2026] [security2:error] [pid 466512:tid 466575] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aCSKGokixMSfKDOf2ogACgT4"]
[Tue Jul 21 08:37:45.325792 2026] [security2:error] [pid 466512:tid 466751] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aCSKGokixMSfKDOf2ogACgT4"]
[Tue Jul 21 08:37:45.341536 2026] [security2:error] [pid 466512:tid 466655] [client 195.49.128.211:49554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aCSKGokixMSfKDOf2pAAAAiE"]
[Tue Jul 21 08:37:45.341631 2026] [security2:error] [pid 466512:tid 466655] [client 195.49.128.211:49554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aCSKGokixMSfKDOf2pAAAAiE"]
[Tue Jul 21 08:37:45.571597 2026] [security2:error] [pid 466512:tid 466700] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9aCSKGokixMSfKDOf2pgAAAk4"]
[Tue Jul 21 08:37:45.839531 2026] [security2:error] [pid 465652:tid 465735] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aCTzTqJoBC2Mw28_RFQAAjVI"]
[Tue Jul 21 08:37:45.839676 2026] [security2:error] [pid 465652:tid 465790] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aCTzTqJoBC2Mw28_RFQAAjVI"]
[Tue Jul 21 08:37:45.849410 2026] [security2:error] [pid 466512:tid 466646] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/txets.php"] [unique_id "al9aCSKGokixMSfKDOf2sgAAAhg"]
[Tue Jul 21 08:37:45.932982 2026] [security2:error] [pid 466512:tid 466658] [client 20.63.100.92:7399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9aCSKGokixMSfKDOf2tAAAAiQ"]
[Tue Jul 21 08:37:46.126780 2026] [security2:error] [pid 465652:tid 465854] [client 202.179.75.202:47898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aCjzTqJoBC2Mw28_RGAAAAM0"]
[Tue Jul 21 08:37:46.127158 2026] [security2:error] [pid 465652:tid 465854] [client 202.179.75.202:47898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aCjzTqJoBC2Mw28_RGAAAAM0"]
[Tue Jul 21 08:37:46.135201 2026] [security2:error] [pid 466512:tid 466677] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/dex.php"] [unique_id "al9aCiKGokixMSfKDOf2uAAAAjc"]
[Tue Jul 21 08:37:46.480576 2026] [security2:error] [pid 466512:tid 466653] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/xpwer1.php"] [unique_id "al9aCiKGokixMSfKDOf2vgAAAh8"]
[Tue Jul 21 08:37:46.515626 2026] [security2:error] [pid 465652:tid 465886] [client 20.226.60.151:58503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9aCjzTqJoBC2Mw28_RHQAAAO0"]
[Tue Jul 21 08:37:46.766455 2026] [security2:error] [pid 466512:tid 466719] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/flox.php"] [unique_id "al9aCiKGokixMSfKDOf2xwAAAmE"]
[Tue Jul 21 08:37:46.772571 2026] [security2:error] [pid 466512:tid 466720] [client 20.206.105.145:21819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/xamp.php"] [unique_id "al9aCiKGokixMSfKDOf2yAAAAmI"]
[Tue Jul 21 08:37:47.049384 2026] [security2:error] [pid 466512:tid 466675] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/popo.php"] [unique_id "al9aCyKGokixMSfKDOf2zgAAAjU"]
[Tue Jul 21 08:37:47.150940 2026] [security2:error] [pid 466512:tid 466715] [client 223.181.60.88:25524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aCyKGokixMSfKDOf2zwAAAl0"]
[Tue Jul 21 08:37:47.152150 2026] [security2:error] [pid 466512:tid 466715] [client 223.181.60.88:25524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aCyKGokixMSfKDOf2zwAAAl0"]
[Tue Jul 21 08:37:47.325737 2026] [security2:error] [pid 466512:tid 466709] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/yas.php"] [unique_id "al9aCyKGokixMSfKDOf21gAAAlc"]
[Tue Jul 21 08:37:47.601353 2026] [security2:error] [pid 465652:tid 465905] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/file61.php"] [unique_id "al9aCzzTqJoBC2Mw28_RKQAAAQA"]
[Tue Jul 21 08:37:47.676645 2026] [security2:error] [pid 466512:tid 466768] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aCyKGokixMSfKDOf23AACkko"]
[Tue Jul 21 08:37:47.762171 2026] [security2:error] [pid 466512:tid 466520] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sejabarbara.com.br"] [uri "/source/.env"] [unique_id "al9aCyKGokixMSfKDOf23wACJAc"], referer: https://sejabarbara.com/source/.env
[Tue Jul 21 08:37:47.884486 2026] [security2:error] [pid 465652:tid 465811] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/water.php"] [unique_id "al9aCzzTqJoBC2Mw28_RMAAAAKI"]
[Tue Jul 21 08:37:48.161413 2026] [security2:error] [pid 465652:tid 465808] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/nano.php"] [unique_id "al9aDDzTqJoBC2Mw28_RNAAAAJ8"]
[Tue Jul 21 08:37:48.445165 2026] [security2:error] [pid 465652:tid 465899] [client 20.63.100.92:5453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/dp.php"] [unique_id "al9aDDzTqJoBC2Mw28_ROwAAAPo"]
[Tue Jul 21 08:37:48.479256 2026] [security2:error] [pid 466512:tid 466711] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/moon.php"] [unique_id "al9aDCKGokixMSfKDOf26gAAAlk"]
[Tue Jul 21 08:37:48.535392 2026] [security2:error] [pid 465652:tid 465801] [client 5.38.115.39:36429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aDDzTqJoBC2Mw28_RPAAAAJg"]
[Tue Jul 21 08:37:48.535524 2026] [security2:error] [pid 465652:tid 465801] [client 5.38.115.39:36429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aDDzTqJoBC2Mw28_RPAAAAJg"]
[Tue Jul 21 08:37:48.607971 2026] [security2:error] [pid 466512:tid 466726] [client 173.252.95.54:64818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9aDCKGokixMSfKDOf26QAAAmg"]
[Tue Jul 21 08:37:48.610147 2026] [security2:error] [pid 466512:tid 466568] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sejabarbara.com.br"] [uri "/framework/.env"] [unique_id "al9aDCKGokixMSfKDOf26wACRzc"], referer: https://sejabarbara.com/framework/.env
[Tue Jul 21 08:37:48.610189 2026] [security2:error] [pid 466512:tid 466513] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sejabarbara.com.br"] [uri "/ikiwiki/.env"] [unique_id "al9aDCKGokixMSfKDOf27AACRwA"], referer: https://sejabarbara.com/ikiwiki/.env
[Tue Jul 21 08:37:48.778436 2026] [security2:error] [pid 466512:tid 466699] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-info.php"] [unique_id "al9aDCKGokixMSfKDOf27gAAAk0"]
[Tue Jul 21 08:37:48.862463 2026] [security2:error] [pid 465652:tid 465835] [client 20.220.225.223:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/2x.php"] [unique_id "al9aDDzTqJoBC2Mw28_RRwAAALo"]
[Tue Jul 21 08:37:49.190771 2026] [security2:error] [pid 466512:tid 466732] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/2000.php"] [unique_id "al9aDSKGokixMSfKDOf29AAAAm4"]
[Tue Jul 21 08:37:49.224243 2026] [security2:error] [pid 466512:tid 466657] [client 20.206.105.145:22223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/bless.php"] [unique_id "al9aDSKGokixMSfKDOf29gAAAiM"]
[Tue Jul 21 08:37:49.472785 2026] [security2:error] [pid 465652:tid 465868] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/122.php"] [unique_id "al9aDTzTqJoBC2Mw28_RUAAAANs"]
[Tue Jul 21 08:37:49.754869 2026] [security2:error] [pid 466512:tid 466655] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/mds.php"] [unique_id "al9aDSKGokixMSfKDOf2_gAAAiE"]
[Tue Jul 21 08:37:50.055181 2026] [security2:error] [pid 466512:tid 466765] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-blink.php"] [unique_id "al9aDiKGokixMSfKDOf3BAAAAo8"]
[Tue Jul 21 08:37:50.126066 2026] [security2:error] [pid 466512:tid 466651] [client 195.206.105.227:32908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9aDiKGokixMSfKDOf3BwAAAh0"]
[Tue Jul 21 08:37:50.126194 2026] [security2:error] [pid 466512:tid 466651] [client 195.206.105.227:32908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9aDiKGokixMSfKDOf3BwAAAh0"]
[Tue Jul 21 08:37:50.199794 2026] [security2:error] [pid 465652:tid 465823] [client 59.95.197.55:53007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aDjzTqJoBC2Mw28_RVwAAAK4"]
[Tue Jul 21 08:37:50.199945 2026] [security2:error] [pid 465652:tid 465823] [client 59.95.197.55:53007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aDjzTqJoBC2Mw28_RVwAAAK4"]
[Tue Jul 21 08:37:50.325222 2026] [security2:error] [pid 466512:tid 466647] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/zc-208.php"] [unique_id "al9aDiKGokixMSfKDOf3CgAAAhk"]
[Tue Jul 21 08:37:50.335335 2026] [security2:error] [pid 465652:tid 465870] [client 14.245.224.124:54037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aDjzTqJoBC2Mw28_RWgAAAN0"]
[Tue Jul 21 08:37:50.335428 2026] [security2:error] [pid 465652:tid 465870] [client 14.245.224.124:54037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aDjzTqJoBC2Mw28_RWgAAAN0"]
[Tue Jul 21 08:37:50.335707 2026] [security2:error] [pid 465652:tid 465854] [client 103.76.88.37:37627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bavos.com.br"] [uri "/.env"] [unique_id "al9aDjzTqJoBC2Mw28_RWQAAAM0"]
[Tue Jul 21 08:37:50.600444 2026] [security2:error] [pid 466512:tid 466728] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/sid4.php"] [unique_id "al9aDiKGokixMSfKDOf3EQAAAmo"]
[Tue Jul 21 08:37:50.614903 2026] [security2:error] [pid 466512:tid 466663] [client 216.244.66.243:51854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ssvistorias.com.br"] [uri "/robots.txt"] [unique_id "al9aDiKGokixMSfKDOf3EgAAAik"]
[Tue Jul 21 08:37:50.614998 2026] [security2:error] [pid 466512:tid 466663] [client 216.244.66.243:51854] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ssvistorias.com.br"] [uri "/robots.txt"] [unique_id "al9aDiKGokixMSfKDOf3EgAAAik"]
[Tue Jul 21 08:37:50.945330 2026] [autoindex:error] [pid 466512:tid 466530] [remote 205.169.39.43:35392] AH01276: Cannot serve directory /home2/bavosc49/perfex.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:37:50.978154 2026] [security2:error] [pid 466512:tid 466624] [remote 45.150.79.142:46344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9aDiKGokixMSfKDOf3GwACN28"]
[Tue Jul 21 08:37:51.042728 2026] [security2:error] [pid 466512:tid 466711] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wmore1.php"] [unique_id "al9aDyKGokixMSfKDOf3HAAAAlk"]
[Tue Jul 21 08:37:51.180992 2026] [security2:error] [pid 466512:tid 466652] [client 122.176.100.127:52272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aDyKGokixMSfKDOf3IAAAAh4"]
[Tue Jul 21 08:37:51.181372 2026] [security2:error] [pid 466512:tid 466652] [client 122.176.100.127:52272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aDyKGokixMSfKDOf3IAAAAh4"]
[Tue Jul 21 08:37:51.204396 2026] [security2:error] [pid 466512:tid 466561] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sejabarbara.com.br"] [uri "/config.inc.php"] [unique_id "al9aDyKGokixMSfKDOf3IgACjTA"], referer: https://sejabarbara.com/config.inc.php
[Tue Jul 21 08:37:51.206269 2026] [security2:error] [pid 466512:tid 466632] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sejabarbara.com.br"] [uri "/system/.env"] [unique_id "al9aDyKGokixMSfKDOf3IwACjXc"], referer: https://sejabarbara.com/system/.env
[Tue Jul 21 08:37:51.321269 2026] [security2:error] [pid 465652:tid 465816] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/solo1.php"] [unique_id "al9aDzzTqJoBC2Mw28_RcgAAAKc"]
[Tue Jul 21 08:37:51.451598 2026] [security2:error] [pid 465652:tid 465827] [client 20.63.100.92:6286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/old.php"] [unique_id "al9aDzzTqJoBC2Mw28_RdgAAALI"]
[Tue Jul 21 08:37:51.472932 2026] [security2:error] [pid 466512:tid 466670] [client 20.206.105.145:21968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/file46.php"] [unique_id "al9aDyKGokixMSfKDOf3KwAAAjA"]
[Tue Jul 21 08:37:51.685350 2026] [core:error] [pid 465652:tid 465656] [remote 185.247.137.224:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpcalendars.getveltrixhealth.com:2086
[Tue Jul 21 08:37:51.685376 2026] [core:error] [pid 465652:tid 465656] [remote 185.247.137.224:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpcalendars.getveltrixhealth.com:2086
[Tue Jul 21 08:37:51.748065 2026] [security2:error] [pid 465652:tid 465852] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/cong.php"] [unique_id "al9aDzzTqJoBC2Mw28_RfQAAAMs"]
[Tue Jul 21 08:37:51.866952 2026] [security2:error] [pid 466512:tid 466696] [client 152.59.34.51:56897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aDyKGokixMSfKDOf3LAAAAko"]
[Tue Jul 21 08:37:51.867105 2026] [security2:error] [pid 466512:tid 466696] [client 152.59.34.51:56897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aDyKGokixMSfKDOf3LAAAAko"]
[Tue Jul 21 08:37:52.172426 2026] [security2:error] [pid 466512:tid 466679] [client 65.21.113.253:36146] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aECKGokixMSfKDOf3LgAAAjk"]
[Tue Jul 21 08:37:52.179735 2026] [security2:error] [pid 466512:tid 466761] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/public/css.php"] [unique_id "al9aECKGokixMSfKDOf3MQAAAos"]
[Tue Jul 21 08:37:52.290961 2026] [security2:error] [pid 466512:tid 466682] [client 81.171.72.93:49328] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/"] [unique_id "al9aECKGokixMSfKDOf3MgAAAjw"]
[Tue Jul 21 08:37:52.290982 2026] [security2:error] [pid 466512:tid 466692] [client 81.171.72.93:49318] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/"] [unique_id "al9aECKGokixMSfKDOf3MwAAAkY"]
[Tue Jul 21 08:37:52.291664 2026] [security2:error] [pid 466512:tid 466743] [client 81.171.72.93:49334] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/"] [unique_id "al9aECKGokixMSfKDOf3NAAAAnk"]
[Tue Jul 21 08:37:52.315530 2026] [security2:error] [pid 466512:tid 466751] [client 195.49.128.211:58363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aECKGokixMSfKDOf3NgAAAoE"]
[Tue Jul 21 08:37:52.315646 2026] [security2:error] [pid 466512:tid 466751] [client 195.49.128.211:58363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aECKGokixMSfKDOf3NgAAAoE"]
[Tue Jul 21 08:37:52.324703 2026] [security2:error] [pid 466512:tid 466718] [client 152.59.181.104:54004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aECKGokixMSfKDOf3NwAAAmA"]
[Tue Jul 21 08:37:52.324876 2026] [security2:error] [pid 466512:tid 466718] [client 152.59.181.104:54004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aECKGokixMSfKDOf3NwAAAmA"]
[Tue Jul 21 08:37:52.405953 2026] [security2:error] [pid 466512:tid 466730] [client 20.206.105.145:22248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/eee.php"] [unique_id "al9aECKGokixMSfKDOf3OQAAAmw"]
[Tue Jul 21 08:37:52.435034 2026] [security2:error] [pid 466512:tid 466702] [client 103.59.206.240:37201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aECKGokixMSfKDOf3OgAAAlA"]
[Tue Jul 21 08:37:52.435196 2026] [security2:error] [pid 466512:tid 466702] [client 103.59.206.240:37201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aECKGokixMSfKDOf3OgAAAlA"]
[Tue Jul 21 08:37:52.461636 2026] [security2:error] [pid 466512:tid 466645] [client 81.171.72.135:42222] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/"] [unique_id "al9aECKGokixMSfKDOf3PQAAAhc"]
[Tue Jul 21 08:37:52.462378 2026] [security2:error] [pid 466512:tid 466649] [client 81.171.72.135:42210] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/"] [unique_id "al9aECKGokixMSfKDOf3PwAAAhs"]
[Tue Jul 21 08:37:52.462379 2026] [security2:error] [pid 466512:tid 466687] [client 81.171.72.135:42198] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/"] [unique_id "al9aECKGokixMSfKDOf3PgAAAkE"]
[Tue Jul 21 08:37:52.463025 2026] [security2:error] [pid 466512:tid 466740] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/output.php"] [unique_id "al9aECKGokixMSfKDOf3QAAAAnY"]
[Tue Jul 21 08:37:52.564192 2026] [security2:error] [pid 466512:tid 466674] [client 49.146.52.188:33284] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "digitaclick.com"] [uri "/wp-comments-post.php"] [unique_id "al9aDiKGokixMSfKDOf3BQAAAjQ"]
[Tue Jul 21 08:37:52.586021 2026] [security2:error] [pid 466512:tid 466700] [client 49.144.66.253:33183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aECKGokixMSfKDOf3RQAAAk4"]
[Tue Jul 21 08:37:52.586126 2026] [security2:error] [pid 466512:tid 466700] [client 49.144.66.253:33183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aECKGokixMSfKDOf3RQAAAk4"]
[Tue Jul 21 08:37:52.751300 2026] [security2:error] [pid 466512:tid 466701] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-file-120.php"] [unique_id "al9aECKGokixMSfKDOf3TAAAAk8"]
[Tue Jul 21 08:37:52.894126 2026] [security2:error] [pid 466512:tid 466674] [client 49.146.52.188:33284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "digitaclick.com"] [uri "/wp-comments-post.php"] [unique_id "al9aDiKGokixMSfKDOf3BQAAAjQ"]
[Tue Jul 21 08:37:52.959771 2026] [security2:error] [pid 466512:tid 466540] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sejabarbara.com.br"] [uri "/app_dev.php/_profiler/open"] [unique_id "al9aECKGokixMSfKDOf3WgACURs"], referer: https://sejabarbara.com/app_dev.php/_profiler/open?file=app/config/parameters.yml
[Tue Jul 21 08:37:53.107878 2026] [security2:error] [pid 465652:tid 465889] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/special.php"] [unique_id "al9aETzTqJoBC2Mw28_RjgAAAPA"]
[Tue Jul 21 08:37:53.256308 2026] [security2:error] [pid 465652:tid 465835] [client 81.171.72.135:59926] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9aETzTqJoBC2Mw28_RkAAAALo"]
[Tue Jul 21 08:37:53.256841 2026] [security2:error] [pid 465652:tid 465837] [client 81.171.72.135:59922] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9aETzTqJoBC2Mw28_RkQAAALw"]
[Tue Jul 21 08:37:53.257872 2026] [security2:error] [pid 466512:tid 466742] [client 81.171.72.135:59910] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/user_secrets.yml"] [unique_id "al9aESKGokixMSfKDOf3YQAAAng"]
[Tue Jul 21 08:37:53.261076 2026] [security2:error] [pid 466512:tid 466667] [client 81.171.72.135:59924] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/.env.production"] [unique_id "al9aESKGokixMSfKDOf3YgAAAi0"]
[Tue Jul 21 08:37:53.325959 2026] [security2:error] [pid 466512:tid 466757] [client 65.21.113.253:36154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aECKGokixMSfKDOf3VAAAAoc"]
[Tue Jul 21 08:37:53.395151 2026] [security2:error] [pid 465652:tid 465900] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/as.php"] [unique_id "al9aETzTqJoBC2Mw28_RkgAAAPs"]
[Tue Jul 21 08:37:53.682936 2026] [security2:error] [pid 465652:tid 465663] [remote 45.79.123.44:33890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9aETzTqJoBC2Mw28_RmgAAyAo"]
[Tue Jul 21 08:37:53.724541 2026] [security2:error] [pid 465652:tid 465906] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9aETzTqJoBC2Mw28_RnAAAAQE"]
[Tue Jul 21 08:37:53.726915 2026] [security2:error] [pid 466512:tid 466611] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "sejabarbara.com.br"] [uri "/wp-content/mysql.sql"] [unique_id "al9aESKGokixMSfKDOf3bAACbGI"], referer: https://sejabarbara.com/wp-content/mysql.sql
[Tue Jul 21 08:37:54.000960 2026] [security2:error] [pid 465652:tid 465796] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/w1px.php"] [unique_id "al9aEjzTqJoBC2Mw28_RnwAAAJM"]
[Tue Jul 21 08:37:54.050988 2026] [security2:error] [pid 466512:tid 466537] [remote 72.167.132.114:43766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9aESKGokixMSfKDOf3WwACexg"]
[Tue Jul 21 08:37:54.063337 2026] [core:alert] [pid 465652:tid 465870] [client 57.141.18.67:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:37:54.093358 2026] [security2:error] [pid 466512:tid 466645] [client 20.206.105.145:22113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/file25.php"] [unique_id "al9aEiKGokixMSfKDOf3cgAAAhc"]
[Tue Jul 21 08:37:54.283131 2026] [security2:error] [pid 465652:tid 465829] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/yawa.php"] [unique_id "al9aEjzTqJoBC2Mw28_RrAAAALQ"]
[Tue Jul 21 08:37:54.306378 2026] [security2:error] [pid 466512:tid 466752] [client 198.44.157.34:42166] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9aECKGokixMSfKDOf3NQAAAoI"]
[Tue Jul 21 08:37:54.306494 2026] [security2:error] [pid 466512:tid 466752] [client 198.44.157.34:42166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9aECKGokixMSfKDOf3NQAAAoI"]
[Tue Jul 21 08:37:54.399383 2026] [security2:error] [pid 466512:tid 466647] [client 81.171.72.135:59974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/.bash_history"] [unique_id "al9aEiKGokixMSfKDOf3gAAAAhk"]
[Tue Jul 21 08:37:54.400429 2026] [security2:error] [pid 465652:tid 465800] [client 81.171.72.135:59944] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/secrets.json"] [unique_id "al9aEjzTqJoBC2Mw28_RrQAAAJc"]
[Tue Jul 21 08:37:54.400429 2026] [security2:error] [pid 466512:tid 466737] [client 81.171.72.135:59948] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/.env"] [unique_id "al9aEiKGokixMSfKDOf3gQAAAnM"]
[Tue Jul 21 08:37:54.401571 2026] [security2:error] [pid 465652:tid 465903] [client 81.171.72.135:59930] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/.npmrc"] [unique_id "al9aEjzTqJoBC2Mw28_RrgAAAP4"]
[Tue Jul 21 08:37:54.566855 2026] [security2:error] [pid 466512:tid 466704] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/js.php"] [unique_id "al9aEiKGokixMSfKDOf3iQAAAlI"]
[Tue Jul 21 08:37:54.604854 2026] [security2:error] [pid 466512:tid 466688] [client 81.171.72.135:59954] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9aEiKGokixMSfKDOf3lAAAAkI"]
[Tue Jul 21 08:37:54.744377 2026] [security2:error] [pid 466512:tid 466639] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sejabarbara.com.br"] [uri "/php-info.php"] [unique_id "al9aEiKGokixMSfKDOf3ngACPn4"], referer: https://sejabarbara.com/php-info.php
[Tue Jul 21 08:37:54.850965 2026] [security2:error] [pid 465652:tid 465802] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/core.php"] [unique_id "al9aEjzTqJoBC2Mw28_RuAAAAJk"]
[Tue Jul 21 08:37:54.871646 2026] [security2:error] [pid 466512:tid 466601] [remote 45.79.123.44:33904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "trilhasdafe.com.br"] [uri "/wp-login.php"] [unique_id "al9aEiKGokixMSfKDOf3pAACJ1g"]
[Tue Jul 21 08:37:55.054354 2026] [security2:error] [pid 465652:tid 465885] [client 20.226.60.151:58578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9aEzzTqJoBC2Mw28_RvAAAAOw"]
[Tue Jul 21 08:37:55.125866 2026] [security2:error] [pid 466512:tid 466705] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/19.php"] [unique_id "al9aEyKGokixMSfKDOf3uwAAAlM"]
[Tue Jul 21 08:37:55.239052 2026] [security2:error] [pid 465652:tid 465831] [client 20.220.225.223:2390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/kq1.php"] [unique_id "al9aEzzTqJoBC2Mw28_RvwAAALY"]
[Tue Jul 21 08:37:55.286679 2026] [security2:error] [pid 465652:tid 465866] [client 117.213.202.34:64410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aEzzTqJoBC2Mw28_RwQAAANk"]
[Tue Jul 21 08:37:55.286875 2026] [security2:error] [pid 465652:tid 465866] [client 117.213.202.34:64410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aEzzTqJoBC2Mw28_RwQAAANk"]
[Tue Jul 21 08:37:55.295010 2026] [security2:error] [pid 466512:tid 466575] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sejabarbara.com.br"] [uri "/info.php.bak"] [unique_id "al9aEyKGokixMSfKDOf3wAACFz4"], referer: https://sejabarbara.com/info.php.bak
[Tue Jul 21 08:37:55.402438 2026] [security2:error] [pid 466512:tid 466755] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/inc.php"] [unique_id "al9aEyKGokixMSfKDOf3xAAAAoU"]
[Tue Jul 21 08:37:55.437987 2026] [security2:error] [pid 465652:tid 465717] [remote 68.178.160.25:38088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "revistareflexopolitico.com.br"] [uri "/wp-login.php"] [unique_id "al9aEzzTqJoBC2Mw28_RwgAA2EA"]
[Tue Jul 21 08:37:55.549372 2026] [security2:error] [pid 466512:tid 466760] [client 81.171.72.135:59980] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9aEyKGokixMSfKDOf3yQAAAoo"]
[Tue Jul 21 08:37:55.553708 2026] [security2:error] [pid 466512:tid 466740] [client 81.171.72.135:60002] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9aEyKGokixMSfKDOf3ygAAAnY"]
[Tue Jul 21 08:37:55.553710 2026] [security2:error] [pid 465652:tid 465838] [client 81.171.72.135:59994] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9aEzzTqJoBC2Mw28_RxAAAAL0"]
[Tue Jul 21 08:37:55.553793 2026] [security2:error] [pid 465652:tid 465857] [client 81.171.72.135:59978] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/.git/HEAD"] [unique_id "al9aEzzTqJoBC2Mw28_RxQAAANA"]
[Tue Jul 21 08:37:55.609980 2026] [security2:error] [pid 465652:tid 465699] [remote 41.186.86.12:7620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dentepro.com.br"] [uri "/wp-login.php"] [unique_id "al9aEzzTqJoBC2Mw28_RxwAAyS4"]
[Tue Jul 21 08:37:55.687965 2026] [security2:error] [pid 466512:tid 466659] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9aEyKGokixMSfKDOf30wAAAiU"]
[Tue Jul 21 08:37:55.753653 2026] [security2:error] [pid 465652:tid 465864] [client 81.171.72.135:59998] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/server.key"] [unique_id "al9aEzzTqJoBC2Mw28_RygAAANc"]
[Tue Jul 21 08:37:55.758432 2026] [security2:error] [pid 466512:tid 466649] [client 81.171.72.135:59982] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/config/production.json"] [unique_id "al9aEyKGokixMSfKDOf31gAAAhs"]
[Tue Jul 21 08:37:55.848457 2026] [security2:error] [pid 466512:tid 466552] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aEyKGokixMSfKDOf32AACLCc"]
[Tue Jul 21 08:37:55.848718 2026] [security2:error] [pid 466512:tid 466666] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aEyKGokixMSfKDOf32AACLCc"]
[Tue Jul 21 08:37:55.888388 2026] [security2:error] [pid 466512:tid 466550] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sejabarbara.com.br"] [uri "/phpinfo.php.bak"] [unique_id "al9aEyKGokixMSfKDOf32wACWSU"], referer: https://sejabarbara.com/phpinfo.php.bak
[Tue Jul 21 08:37:55.932464 2026] [security2:error] [pid 466512:tid 466733] [client 195.206.105.227:32920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9aEyKGokixMSfKDOf33QAAAm8"]
[Tue Jul 21 08:37:55.932581 2026] [security2:error] [pid 466512:tid 466733] [client 195.206.105.227:32920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9aEyKGokixMSfKDOf33QAAAm8"]
[Tue Jul 21 08:37:55.944402 2026] [security2:error] [pid 465652:tid 465878] [client 195.49.128.211:50162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aEzzTqJoBC2Mw28_R0AAAAOU"]
[Tue Jul 21 08:37:55.944541 2026] [security2:error] [pid 465652:tid 465878] [client 195.49.128.211:50162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aEzzTqJoBC2Mw28_R0AAAAOU"]
[Tue Jul 21 08:37:55.965854 2026] [security2:error] [pid 466512:tid 466681] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9aEyKGokixMSfKDOf33gAAAjs"]
[Tue Jul 21 08:37:56.195888 2026] [security2:error] [pid 466512:tid 466662] [client 65.21.113.253:36154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aEyKGokixMSfKDOf31QAAAig"]
[Tue Jul 21 08:37:56.239847 2026] [security2:error] [pid 466512:tid 466769] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/ss.php"] [unique_id "al9aFCKGokixMSfKDOf34wAAApM"]
[Tue Jul 21 08:37:56.450045 2026] [security2:error] [pid 466512:tid 466520] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aFCKGokixMSfKDOf35gACOAc"]
[Tue Jul 21 08:37:56.450254 2026] [security2:error] [pid 466512:tid 466678] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aFCKGokixMSfKDOf35gACOAc"]
[Tue Jul 21 08:37:56.515659 2026] [security2:error] [pid 466512:tid 466661] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/min.php"] [unique_id "al9aFCKGokixMSfKDOf35wAAAic"]
[Tue Jul 21 08:37:56.542390 2026] [security2:error] [pid 466512:tid 466670] [client 20.220.225.223:40740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/zzz.php"] [unique_id "al9aFCKGokixMSfKDOf36AAAAjA"]
[Tue Jul 21 08:37:56.600470 2026] [security2:error] [pid 465652:tid 465891] [client 74.7.244.17:47878] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.samavidistribuicao.provendasatacado.com.br"] [uri "/index.php"] [unique_id "al9aFDzTqJoBC2Mw28_R2QAA8ig"]
[Tue Jul 21 08:37:56.699892 2026] [security2:error] [pid 466512:tid 466716] [client 81.171.72.135:60038] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/.svn/wc.db"] [unique_id "al9aFCKGokixMSfKDOf37QAAAl4"]
[Tue Jul 21 08:37:56.700256 2026] [security2:error] [pid 466512:tid 466732] [client 81.171.72.135:60036] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/wp-config.php"] [unique_id "al9aFCKGokixMSfKDOf37gAAAm4"]
[Tue Jul 21 08:37:56.703118 2026] [security2:error] [pid 466512:tid 466719] [client 81.171.72.135:60026] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/database_backup.sql"] [unique_id "al9aFCKGokixMSfKDOf37wAAAmE"]
[Tue Jul 21 08:37:56.703126 2026] [security2:error] [pid 465652:tid 465790] [client 81.171.72.135:60014] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/backup.zip"] [unique_id "al9aFDzTqJoBC2Mw28_R3AAAAI0"]
[Tue Jul 21 08:37:56.791746 2026] [security2:error] [pid 465652:tid 465820] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9aFDzTqJoBC2Mw28_R3gAAAKs"]
[Tue Jul 21 08:37:56.852705 2026] [security2:error] [pid 465652:tid 465854] [client 20.206.105.145:21965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/file48.php"] [unique_id "al9aFDzTqJoBC2Mw28_R3wAAAM0"]
[Tue Jul 21 08:37:56.881720 2026] [security2:error] [pid 466512:tid 466546] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sejabarbara.com.br"] [uri "/env/.env"] [unique_id "al9aFCKGokixMSfKDOf38gACXSE"], referer: https://sejabarbara.com/env/.env
[Tue Jul 21 08:37:56.903249 2026] [security2:error] [pid 466512:tid 466657] [client 81.171.72.135:60024] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/actuator/heapdump"] [unique_id "al9aFCKGokixMSfKDOf38wAAAiM"]
[Tue Jul 21 08:37:56.903746 2026] [security2:error] [pid 466512:tid 466720] [client 81.171.72.135:60030] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/config.xml"] [unique_id "al9aFCKGokixMSfKDOf39AAAAmI"]
[Tue Jul 21 08:37:57.013373 2026] [security2:error] [pid 466512:tid 466741] [client 74.249.245.134:47667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/pomo.php"] [unique_id "al9aFSKGokixMSfKDOf39QAAAnc"]
[Tue Jul 21 08:37:57.043917 2026] [security2:error] [pid 465652:tid 465906] [client 202.179.75.202:47634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aFTzTqJoBC2Mw28_R4QAAAQE"]
[Tue Jul 21 08:37:57.044030 2026] [security2:error] [pid 465652:tid 465906] [client 202.179.75.202:47634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aFTzTqJoBC2Mw28_R4QAAAQE"]
[Tue Jul 21 08:37:57.074283 2026] [security2:error] [pid 466512:tid 466695] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9aFSKGokixMSfKDOf39gAAAkk"]
[Tue Jul 21 08:37:57.335001 2026] [security2:error] [pid 466512:tid 466682] [client 81.171.72.135:60056] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/config.php"] [unique_id "al9aFSKGokixMSfKDOf3-gAAAjw"]
[Tue Jul 21 08:37:57.335243 2026] [security2:error] [pid 466512:tid 466692] [client 81.171.72.135:60050] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/dump.sql"] [unique_id "al9aFSKGokixMSfKDOf3-wAAAkY"]
[Tue Jul 21 08:37:57.337654 2026] [security2:error] [pid 466512:tid 466754] [client 81.171.72.135:60070] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/backup.sql"] [unique_id "al9aFSKGokixMSfKDOf3_AAAAoQ"]
[Tue Jul 21 08:37:57.349328 2026] [security2:error] [pid 466512:tid 466696] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9aFSKGokixMSfKDOf3_QAAAko"]
[Tue Jul 21 08:37:57.626933 2026] [security2:error] [pid 465652:tid 465876] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9aFTzTqJoBC2Mw28_R6gAAAOM"]
[Tue Jul 21 08:37:57.843133 2026] [security2:error] [pid 465652:tid 465791] [client 223.181.60.88:16915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aFTzTqJoBC2Mw28_R8QAAAI4"]
[Tue Jul 21 08:37:57.843361 2026] [security2:error] [pid 465652:tid 465791] [client 223.181.60.88:16915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aFTzTqJoBC2Mw28_R8QAAAI4"]
[Tue Jul 21 08:37:57.957144 2026] [security2:error] [pid 466512:tid 466646] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/albin.php"] [unique_id "al9aFSKGokixMSfKDOf4BAAAAhg"]
[Tue Jul 21 08:37:58.047958 2026] [security2:error] [pid 466512:tid 466708] [client 81.171.72.135:60116] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9aFiKGokixMSfKDOf4BwAAAlY"]
[Tue Jul 21 08:37:58.048727 2026] [security2:error] [pid 466512:tid 466738] [client 81.171.72.135:60100] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/docker-compose.yml"] [unique_id "al9aFiKGokixMSfKDOf4CAAAAnQ"]
[Tue Jul 21 08:37:58.049506 2026] [security2:error] [pid 465652:tid 465874] [client 81.171.72.135:60114] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/database.sql"] [unique_id "al9aFjzTqJoBC2Mw28_R9AAAAOE"]
[Tue Jul 21 08:37:58.050153 2026] [security2:error] [pid 466512:tid 466765] [client 81.171.72.135:60078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/api/.env"] [unique_id "al9aFiKGokixMSfKDOf4CQAAAo8"]
[Tue Jul 21 08:37:58.083893 2026] [security2:error] [pid 466512:tid 466687] [client 65.21.113.253:36154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aFSKGokixMSfKDOf3_gAAAkE"]
[Tue Jul 21 08:37:58.124486 2026] [security2:error] [pid 466512:tid 466643] [client 81.171.72.93:43760] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9aFiKGokixMSfKDOf4CgAAAhU"]
[Tue Jul 21 08:37:58.125204 2026] [security2:error] [pid 466512:tid 466668] [client 81.171.72.93:43764] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/wp-config.php"] [unique_id "al9aFiKGokixMSfKDOf4CwAAAi4"]
[Tue Jul 21 08:37:58.125654 2026] [security2:error] [pid 466512:tid 466647] [client 81.171.72.93:43748] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9aFiKGokixMSfKDOf4DAAAAhk"]
[Tue Jul 21 08:37:58.126482 2026] [security2:error] [pid 466512:tid 466728] [client 81.171.72.93:43772] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/.env.production"] [unique_id "al9aFiKGokixMSfKDOf4DQAAAmo"]
[Tue Jul 21 08:37:58.249985 2026] [security2:error] [pid 466512:tid 466701] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/cilus.php"] [unique_id "al9aFiKGokixMSfKDOf4EQAAAk8"]
[Tue Jul 21 08:37:58.250320 2026] [security2:error] [pid 466512:tid 466737] [client 81.171.72.135:60132] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/backup.tar.gz"] [unique_id "al9aFiKGokixMSfKDOf4EgAAAnM"]
[Tue Jul 21 08:37:58.250894 2026] [security2:error] [pid 466512:tid 466669] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aFiKGokixMSfKDOf4DgACLxc"]
[Tue Jul 21 08:37:58.251157 2026] [security2:error] [pid 465652:tid 465882] [client 81.171.72.135:60098] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9aFjzTqJoBC2Mw28_R9gAAAOk"]
[Tue Jul 21 08:37:58.253353 2026] [security2:error] [pid 466512:tid 466672] [client 81.171.72.135:60084] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/phpinfo.php"] [unique_id "al9aFiKGokixMSfKDOf4EwAAAjI"]
[Tue Jul 21 08:37:58.376262 2026] [security2:error] [pid 465652:tid 465859] [client 20.220.225.223:46968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wicked.php"] [unique_id "al9aFjzTqJoBC2Mw28_R_AAAANI"]
[Tue Jul 21 08:37:58.379967 2026] [security2:error] [pid 466512:tid 466698] [client 20.63.100.92:6301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/ms-new.php"] [unique_id "al9aFiKGokixMSfKDOf4FwAAAkw"]
[Tue Jul 21 08:37:58.540838 2026] [security2:error] [pid 466512:tid 466671] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/gptsh.php"] [unique_id "al9aFiKGokixMSfKDOf4JAAAAjE"]
[Tue Jul 21 08:37:58.805698 2026] [security2:error] [pid 466512:tid 466715] [client 45.227.253.15:59352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.253.227.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.com.br"] [uri "/index.php/jk"] [unique_id "al9aFiKGokixMSfKDOf4MAAAAl0"]
[Tue Jul 21 08:37:58.834959 2026] [security2:error] [pid 465652:tid 465843] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/rithin.php"] [unique_id "al9aFjzTqJoBC2Mw28_SBAAAAMI"]
[Tue Jul 21 08:37:58.845092 2026] [security2:error] [pid 466512:tid 466617] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sejabarbara.com.br"] [uri "/src/.env"] [unique_id "al9aFiKGokixMSfKDOf4MgACgGg"], referer: https://sejabarbara.com/src/.env
[Tue Jul 21 08:37:58.880067 2026] [security2:error] [pid 465652:tid 465855] [client 74.7.241.175:55692] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "coggurupi.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9aFjzTqJoBC2Mw28_SBwAAzkM"]
[Tue Jul 21 08:37:58.913603 2026] [security2:error] [pid 466512:tid 466573] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/.git/HEAD"] [unique_id "al9aFiKGokixMSfKDOf4NAACWzw"]
[Tue Jul 21 08:37:59.098370 2026] [security2:error] [pid 466512:tid 466761] [client 81.171.72.93:43782] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/.env"] [unique_id "al9aFyKGokixMSfKDOf4NgAAAos"]
[Tue Jul 21 08:37:59.104759 2026] [security2:error] [pid 466512:tid 466741] [client 81.171.72.93:43808] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/.git/HEAD"] [unique_id "al9aFyKGokixMSfKDOf4OAAAAnc"]
[Tue Jul 21 08:37:59.104759 2026] [security2:error] [pid 465652:tid 465794] [client 81.171.72.93:43784] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9aFzzTqJoBC2Mw28_SCgAAAJE"]
[Tue Jul 21 08:37:59.104891 2026] [security2:error] [pid 466512:tid 466657] [client 81.171.72.93:43824] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/api/.env"] [unique_id "al9aFyKGokixMSfKDOf4NwAAAiM"]
[Tue Jul 21 08:37:59.110089 2026] [security2:error] [pid 466512:tid 466697] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/fffm.php"] [unique_id "al9aFyKGokixMSfKDOf4OQAAAks"]
[Tue Jul 21 08:37:59.227461 2026] [security2:error] [pid 466512:tid 466744] [client 5.38.115.39:37371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aFyKGokixMSfKDOf4PQAAAno"]
[Tue Jul 21 08:37:59.227591 2026] [security2:error] [pid 466512:tid 466744] [client 5.38.115.39:37371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aFyKGokixMSfKDOf4PQAAAno"]
[Tue Jul 21 08:37:59.300148 2026] [security2:error] [pid 466512:tid 466679] [client 81.171.72.93:43832] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/phpinfo.php"] [unique_id "al9aFyKGokixMSfKDOf4PwAAAjk"]
[Tue Jul 21 08:37:59.306325 2026] [security2:error] [pid 466512:tid 466655] [client 81.171.72.93:43794] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/user_secrets.yml"] [unique_id "al9aFyKGokixMSfKDOf4QQAAAiE"]
[Tue Jul 21 08:37:59.306401 2026] [security2:error] [pid 466512:tid 466720] [client 81.171.72.93:43796] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/docker-compose.yml"] [unique_id "al9aFyKGokixMSfKDOf4QgAAAmI"]
[Tue Jul 21 08:37:59.416253 2026] [security2:error] [pid 466512:tid 466643] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/dfre.php"] [unique_id "al9aFyKGokixMSfKDOf4SgAAAhU"]
[Tue Jul 21 08:37:59.680082 2026] [security2:error] [pid 466512:tid 466681] [client 20.220.225.223:54282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/edit.php"] [unique_id "al9aFyKGokixMSfKDOf4UwAAAjs"]
[Tue Jul 21 08:37:59.720983 2026] [security2:error] [pid 466512:tid 466591] [remote 147.50.252.213:51852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9aFyKGokixMSfKDOf4VwACYE4"]
[Tue Jul 21 08:37:59.722702 2026] [security2:error] [pid 466512:tid 466726] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/wp-happy.php"] [unique_id "al9aFyKGokixMSfKDOf4WAAAAmg"]
[Tue Jul 21 08:37:59.784220 2026] [security2:error] [pid 466512:tid 466537] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/.env"] [unique_id "al9aFyKGokixMSfKDOf4WQACchg"]
[Tue Jul 21 08:37:59.784388 2026] [security2:error] [pid 466512:tid 466736] [client 34.155.146.79:48792] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "console.gradiente.com"] [uri "/.env"] [unique_id "al9aFyKGokixMSfKDOf4WQACchg"]
[Tue Jul 21 08:37:59.901329 2026] [security2:error] [pid 466512:tid 466542] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "console.gradiente.com"] [uri "/graphql"] [unique_id "al9aFyKGokixMSfKDOf4YQACcR0"]
[Tue Jul 21 08:37:59.989010 2026] [security2:error] [pid 466512:tid 466633] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "console.gradiente.com"] [uri "/.env.example"] [unique_id "al9aFyKGokixMSfKDOf4ZwACSHg"]
[Tue Jul 21 08:38:00.006930 2026] [security2:error] [pid 466512:tid 466642] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/fpr4.php"] [unique_id "al9aGCKGokixMSfKDOf4agAAAhQ"]
[Tue Jul 21 08:38:00.030996 2026] [security2:error] [pid 466512:tid 466602] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "console.gradiente.com"] [uri "/.env.production"] [unique_id "al9aGCKGokixMSfKDOf4awACNlk"]
[Tue Jul 21 08:38:00.074761 2026] [security2:error] [pid 466512:tid 466532] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/.env.bak"] [unique_id "al9aGCKGokixMSfKDOf4bgACXxM"]
[Tue Jul 21 08:38:00.075838 2026] [security2:error] [pid 466512:tid 466612] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/.env.old"] [unique_id "al9aGCKGokixMSfKDOf4bwACX2M"]
[Tue Jul 21 08:38:00.084030 2026] [security2:error] [pid 466512:tid 466516] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/.env.backup"] [unique_id "al9aGCKGokixMSfKDOf4cAACZgM"]
[Tue Jul 21 08:38:00.097240 2026] [security2:error] [pid 466512:tid 466554] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "console.gradiente.com"] [uri "/api/graphql"] [unique_id "al9aGCKGokixMSfKDOf4cQACiyk"]
[Tue Jul 21 08:38:00.101792 2026] [security2:error] [pid 466512:tid 466706] [client 81.171.72.93:43840] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/backup.tar.gz"] [unique_id "al9aGCKGokixMSfKDOf4cgAAAlQ"]
[Tue Jul 21 08:38:00.134569 2026] [security2:error] [pid 466512:tid 466605] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/backend/.env"] [unique_id "al9aGCKGokixMSfKDOf4dQACHVw"]
[Tue Jul 21 08:38:00.144449 2026] [security2:error] [pid 466512:tid 466635] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/api/.env"] [unique_id "al9aGCKGokixMSfKDOf4dgACKno"]
[Tue Jul 21 08:38:00.156666 2026] [security2:error] [pid 466512:tid 466580] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/config/.env"] [unique_id "al9aGCKGokixMSfKDOf4dwACekM"]
[Tue Jul 21 08:38:00.238651 2026] [security2:error] [pid 466512:tid 466525] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sejabarbara.com.br"] [uri "/config/app.php"] [unique_id "al9aGCKGokixMSfKDOf4fAACFww"], referer: https://sejabarbara.com/config/app.php
[Tue Jul 21 08:38:00.290615 2026] [security2:error] [pid 466512:tid 466593] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "console.gradiente.com"] [uri "/v1/graphql"] [unique_id "al9aGCKGokixMSfKDOf4gAACflA"]
[Tue Jul 21 08:38:00.299839 2026] [security2:error] [pid 466512:tid 466760] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/file88.php"] [unique_id "al9aGCKGokixMSfKDOf4ggAAAoo"]
[Tue Jul 21 08:38:00.555760 2026] [security2:error] [pid 466512:tid 466659] [client 81.171.72.93:43886] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/actuator/heapdump"] [unique_id "al9aGCKGokixMSfKDOf4oQAAAiU"]
[Tue Jul 21 08:38:00.560928 2026] [security2:error] [pid 466512:tid 466615] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "console.gradiente.com"] [uri "/.htpasswd"] [unique_id "al9aGCKGokixMSfKDOf4owACc2Y"]
[Tue Jul 21 08:38:00.581519 2026] [security2:error] [pid 466512:tid 466693] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/ccc.php"] [unique_id "al9aGCKGokixMSfKDOf4pgAAAkc"]
[Tue Jul 21 08:38:00.621391 2026] [fcgid:warn] [pid 466512:tid 466718] (70014)End of file found: [client 199.45.155.93:56636] mod_fcgid: can't get data from http client
[Tue Jul 21 08:38:00.772726 2026] [security2:error] [pid 466512:tid 466721] [client 59.95.197.55:53473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aGCKGokixMSfKDOf4tAAAAmM"]
[Tue Jul 21 08:38:00.773402 2026] [security2:error] [pid 466512:tid 466721] [client 59.95.197.55:53473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aGCKGokixMSfKDOf4tAAAAmM"]
[Tue Jul 21 08:38:00.803604 2026] [security2:error] [pid 466512:tid 466564] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/.ssh/id_rsa"] [unique_id "al9aGCKGokixMSfKDOf4twACODM"]
[Tue Jul 21 08:38:00.805681 2026] [security2:error] [pid 466512:tid 466552] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/.ssh/id_dsa"] [unique_id "al9aGCKGokixMSfKDOf4ugACOCc"]
[Tue Jul 21 08:38:00.862962 2026] [security2:error] [pid 466512:tid 466675] [client 74.249.245.134:46726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/test1.php"] [unique_id "al9aGCKGokixMSfKDOf4vwAAAjU"]
[Tue Jul 21 08:38:00.884274 2026] [security2:error] [pid 466512:tid 466758] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/777.php"] [unique_id "al9aGCKGokixMSfKDOf4xQAAAog"]
[Tue Jul 21 08:38:00.894896 2026] [security2:error] [pid 466512:tid 466578] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sejabarbara.com.br"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9aGCKGokixMSfKDOf4xgACNkE"], referer: https://sejabarbara.com/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
[Tue Jul 21 08:38:00.953042 2026] [security2:error] [pid 466512:tid 466570] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/id_rsa"] [unique_id "al9aGCKGokixMSfKDOf4yAACXzk"]
[Tue Jul 21 08:38:01.076125 2026] [security2:error] [pid 465652:tid 465862] [client 81.171.72.93:43912] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9aGTzTqJoBC2Mw28_SMgAAANU"]
[Tue Jul 21 08:38:01.078056 2026] [security2:error] [pid 466512:tid 466694] [client 81.171.72.93:43914] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/backup.zip"] [unique_id "al9aGSKGokixMSfKDOf40gAAAkg"]
[Tue Jul 21 08:38:01.093534 2026] [security2:error] [pid 466512:tid 466608] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/id_dsa"] [unique_id "al9aGSKGokixMSfKDOf41AACVF8"]
[Tue Jul 21 08:38:01.098143 2026] [security2:error] [pid 466512:tid 466674] [client 14.245.224.124:54908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aGSKGokixMSfKDOf41QAAAjQ"]
[Tue Jul 21 08:38:01.098333 2026] [security2:error] [pid 466512:tid 466674] [client 14.245.224.124:54908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aGSKGokixMSfKDOf41QAAAjQ"]
[Tue Jul 21 08:38:01.104297 2026] [security2:error] [pid 466512:tid 466597] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/server.key"] [unique_id "al9aGSKGokixMSfKDOf42AACVFQ"]
[Tue Jul 21 08:38:01.108123 2026] [security2:error] [pid 466512:tid 466617] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/privatekey.key"] [unique_id "al9aGSKGokixMSfKDOf41wACVGg"]
[Tue Jul 21 08:38:01.126052 2026] [security2:error] [pid 466512:tid 466573] [remote 154.61.75.100:37518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tryhealthonline.shop"] [uri "/wp-login.php"] [unique_id "al9aGSKGokixMSfKDOf42QACYjw"]
[Tue Jul 21 08:38:01.130904 2026] [security2:error] [pid 466512:tid 466637] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/key.pem"] [unique_id "al9aGSKGokixMSfKDOf42wACGnw"]
[Tue Jul 21 08:38:01.161479 2026] [security2:error] [pid 466512:tid 466664] [client 20.63.100.92:6905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/track.php"] [unique_id "al9aGSKGokixMSfKDOf43AAAAio"]
[Tue Jul 21 08:38:01.162719 2026] [security2:error] [pid 465652:tid 465839] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/for.php"] [unique_id "al9aGTzTqJoBC2Mw28_SMwAAAL4"]
[Tue Jul 21 08:38:01.180333 2026] [security2:error] [pid 465652:tid 465903] [client 185.213.175.37:46048] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bergsantana.com.br"] [uri "/wp-content/themes/flatsome/assets/js/chunk.slider.js"] [unique_id "al9aGTzTqJoBC2Mw28_SNQAAAP4"]
[Tue Jul 21 08:38:01.228253 2026] [security2:error] [pid 466512:tid 466685] [client 185.213.175.37:46038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bergsantana.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aGSKGokixMSfKDOf4zQAAAj8"]
[Tue Jul 21 08:38:01.330940 2026] [security2:error] [pid 466512:tid 466585] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9aGSKGokixMSfKDOf46gACQ0g"]
[Tue Jul 21 08:38:01.370963 2026] [security2:error] [pid 466512:tid 466764] [client 81.171.72.93:43854] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9aGSKGokixMSfKDOf47wAAAo4"]
[Tue Jul 21 08:38:01.449510 2026] [security2:error] [pid 466512:tid 466665] [client 20.206.105.145:21766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/file6.php"] [unique_id "al9aGSKGokixMSfKDOf49AAAAis"]
[Tue Jul 21 08:38:01.460378 2026] [security2:error] [pid 466512:tid 466647] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/ssla.php"] [unique_id "al9aGSKGokixMSfKDOf49QAAAhk"]
[Tue Jul 21 08:38:01.494068 2026] [security2:error] [pid 466512:tid 466565] [remote 45.148.10.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.10.148.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sejabarbara.com.br"] [uri "/phpinfo.php3"] [unique_id "al9aGSKGokixMSfKDOf49wACajQ"], referer: https://sejabarbara.com/phpinfo.php3
[Tue Jul 21 08:38:01.495241 2026] [security2:error] [pid 466512:tid 466624] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sejabarbara.com.br"] [uri "/core/.env"] [unique_id "al9aGSKGokixMSfKDOf49gACam8"], referer: https://sejabarbara.com/core/.env
[Tue Jul 21 08:38:01.495302 2026] [security2:error] [pid 466512:tid 466591] [remote 45.148.10.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sejabarbara.com.br"] [uri "/web/.env"] [unique_id "al9aGSKGokixMSfKDOf4-AACak4"], referer: https://sejabarbara.com/web/.env
[Tue Jul 21 08:38:01.498311 2026] [security2:error] [pid 466512:tid 466747] [client 65.21.113.253:36154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aGCKGokixMSfKDOf4xwAAAn0"]
[Tue Jul 21 08:38:01.536554 2026] [security2:error] [pid 466512:tid 466729] [client 81.171.72.93:43928] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9aGSKGokixMSfKDOf5AQAAAms"]
[Tue Jul 21 08:38:01.537698 2026] [security2:error] [pid 466512:tid 466646] [client 81.171.72.93:43942] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/.svn/wc.db"] [unique_id "al9aGSKGokixMSfKDOf5AgAAAhg"]
[Tue Jul 21 08:38:01.543248 2026] [security2:error] [pid 466512:tid 466542] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/.hermes/config.yaml"] [unique_id "al9aGSKGokixMSfKDOf5BQACPB0"]
[Tue Jul 21 08:38:01.543367 2026] [security2:error] [pid 466512:tid 466599] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/.codex/config.toml"] [unique_id "al9aGSKGokixMSfKDOf5BgACPFY"]
[Tue Jul 21 08:38:01.543400 2026] [security2:error] [pid 466512:tid 466682] [client 34.155.146.79:48792] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "console.gradiente.com"] [uri "/.hermes/config.yaml"] [unique_id "al9aGSKGokixMSfKDOf5BQACPB0"]
[Tue Jul 21 08:38:01.543511 2026] [security2:error] [pid 466512:tid 466682] [client 34.155.146.79:48792] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "console.gradiente.com"] [uri "/.codex/config.toml"] [unique_id "al9aGSKGokixMSfKDOf5BgACPFY"]
[Tue Jul 21 08:38:01.544712 2026] [security2:error] [pid 466512:tid 466548] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/.hermes/.env"] [unique_id "al9aGSKGokixMSfKDOf5BAACPCM"]
[Tue Jul 21 08:38:01.593581 2026] [security2:error] [pid 465652:tid 465795] [client 20.226.60.151:58582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xyn.php"] [unique_id "al9aGTzTqJoBC2Mw28_SPgAAAJI"]
[Tue Jul 21 08:38:01.657632 2026] [security2:error] [pid 466512:tid 466762] [client 122.176.100.127:52780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aGSKGokixMSfKDOf5EQAAAow"]
[Tue Jul 21 08:38:01.657800 2026] [security2:error] [pid 466512:tid 466762] [client 122.176.100.127:52780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aGSKGokixMSfKDOf5EQAAAow"]
[Tue Jul 21 08:38:01.759694 2026] [security2:error] [pid 466512:tid 466713] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bdois.com.br"] [uri "/zc-131.php"] [unique_id "al9aGSKGokixMSfKDOf5GwAAAls"]
[Tue Jul 21 08:38:01.770909 2026] [security2:error] [pid 466512:tid 466580] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "console.gradiente.com"] [uri "/wp-config.php.bak"] [unique_id "al9aGSKGokixMSfKDOf5HQACckM"]
[Tue Jul 21 08:38:01.773252 2026] [security2:error] [pid 466512:tid 466610] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "console.gradiente.com"] [uri "/.profile"] [unique_id "al9aGSKGokixMSfKDOf5HgACcmE"]
[Tue Jul 21 08:38:01.788688 2026] [security2:error] [pid 465652:tid 465872] [client 195.206.105.227:44446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9aGTzTqJoBC2Mw28_SPwAAAN8"]
[Tue Jul 21 08:38:01.788797 2026] [security2:error] [pid 465652:tid 465872] [client 195.206.105.227:44446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9aGTzTqJoBC2Mw28_SPwAAAN8"]
[Tue Jul 21 08:38:01.843691 2026] [security2:error] [pid 466512:tid 466551] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "console.gradiente.com"] [uri "/wp-config.php.old"] [unique_id "al9aGSKGokixMSfKDOf5IQACYyY"]
[Tue Jul 21 08:38:01.986216 2026] [security2:error] [pid 466512:tid 466560] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/config/.env.php"] [unique_id "al9aGSKGokixMSfKDOf5KgACbS8"]
[Tue Jul 21 08:38:01.986390 2026] [security2:error] [pid 466512:tid 466731] [client 34.155.146.79:48792] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "console.gradiente.com"] [uri "/config/.env.php"] [unique_id "al9aGSKGokixMSfKDOf5KgACbS8"]
[Tue Jul 21 08:38:01.987314 2026] [security2:error] [pid 466512:tid 466596] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/laravel/.env"] [unique_id "al9aGSKGokixMSfKDOf5KAACbVM"]
[Tue Jul 21 08:38:02.045067 2026] [security2:error] [pid 466512:tid 466759] [client 81.171.72.93:43962] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/database.sql"] [unique_id "al9aGiKGokixMSfKDOf5LQAAAok"]
[Tue Jul 21 08:38:02.046803 2026] [security2:error] [pid 466512:tid 466684] [client 81.171.72.93:43950] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/backup.sql"] [unique_id "al9aGiKGokixMSfKDOf5LgAAAj4"]
[Tue Jul 21 08:38:02.047243 2026] [security2:error] [pid 466512:tid 466683] [client 81.171.72.93:43974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/database_backup.sql"] [unique_id "al9aGiKGokixMSfKDOf5LwAAAj0"]
[Tue Jul 21 08:38:02.078964 2026] [security2:error] [pid 466512:tid 466639] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "console.gradiente.com"] [uri "/.env.php.bak"] [unique_id "al9aGiKGokixMSfKDOf5MAACNX4"]
[Tue Jul 21 08:38:02.218678 2026] [security2:error] [pid 466512:tid 466717] [client 198.44.157.34:48612] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aGiKGokixMSfKDOf5NAAAAl8"]
[Tue Jul 21 08:38:02.218767 2026] [security2:error] [pid 466512:tid 466717] [client 198.44.157.34:48612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aGiKGokixMSfKDOf5NAAAAl8"]
[Tue Jul 21 08:38:02.384245 2026] [security2:error] [pid 466512:tid 466607] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/core/.env"] [unique_id "al9aGiKGokixMSfKDOf5NwACVF4"]
[Tue Jul 21 08:38:02.392760 2026] [security2:error] [pid 466512:tid 466628] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "console.gradiente.com"] [uri "/bootstrap.yml"] [unique_id "al9aGiKGokixMSfKDOf5OAACGnM"]
[Tue Jul 21 08:38:02.428248 2026] [security2:error] [pid 466512:tid 466529] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "console.gradiente.com"] [uri "/configuration.php.bak"] [unique_id "al9aGiKGokixMSfKDOf5OgACPxA"]
[Tue Jul 21 08:38:02.429968 2026] [security2:error] [pid 466512:tid 466601] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/public/.env"] [unique_id "al9aGiKGokixMSfKDOf5PAACP1g"]
[Tue Jul 21 08:38:02.430250 2026] [security2:error] [pid 466512:tid 466634] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/.env.swp"] [unique_id "al9aGiKGokixMSfKDOf5PQACP3k"]
[Tue Jul 21 08:38:02.449040 2026] [security2:error] [pid 466512:tid 466528] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/application.yml"] [unique_id "al9aGiKGokixMSfKDOf5QAACOQ8"]
[Tue Jul 21 08:38:02.449253 2026] [security2:error] [pid 466512:tid 466679] [client 34.155.146.79:48792] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "console.gradiente.com"] [uri "/application.yml"] [unique_id "al9aGiKGokixMSfKDOf5QAACOQ8"]
[Tue Jul 21 08:38:02.450433 2026] [security2:error] [pid 466512:tid 466576] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/web/.env"] [unique_id "al9aGiKGokixMSfKDOf5QQACOT8"]
[Tue Jul 21 08:38:02.465839 2026] [security2:error] [pid 466512:tid 466622] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "console.gradiente.com"] [uri "/config.php.bak"] [unique_id "al9aGiKGokixMSfKDOf5QgACMW0"]
[Tue Jul 21 08:38:02.509189 2026] [security2:error] [pid 466512:tid 466697] [client 81.171.72.93:44008] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/dump.sql"] [unique_id "al9aGiKGokixMSfKDOf5RAAAAks"]
[Tue Jul 21 08:38:02.600934 2026] [security2:error] [pid 466512:tid 466615] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "console.gradiente.com"] [uri "/config/secrets.yml"] [unique_id "al9aGiKGokixMSfKDOf5SgACK2Y"]
[Tue Jul 21 08:38:02.612778 2026] [security2:error] [pid 465652:tid 465853] [client 152.59.34.51:57384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aGjzTqJoBC2Mw28_STgAAAMw"]
[Tue Jul 21 08:38:02.612943 2026] [security2:error] [pid 465652:tid 465853] [client 152.59.34.51:57384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aGjzTqJoBC2Mw28_STgAAAMw"]
[Tue Jul 21 08:38:02.671154 2026] [security2:error] [pid 466512:tid 466740] [client 81.171.72.93:44070] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9aGiKGokixMSfKDOf5VQAAAnY"]
[Tue Jul 21 08:38:02.671154 2026] [security2:error] [pid 466512:tid 466752] [client 81.171.72.93:44032] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9aGiKGokixMSfKDOf5VAAAAoI"]
[Tue Jul 21 08:38:02.673139 2026] [security2:error] [pid 466512:tid 466748] [client 81.171.72.93:44054] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/config.xml"] [unique_id "al9aGiKGokixMSfKDOf5VgAAAn4"]
[Tue Jul 21 08:38:02.687144 2026] [security2:error] [pid 466512:tid 466618] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "console.gradiente.com"] [uri "/appsettings.Production.json"] [unique_id "al9aGiKGokixMSfKDOf5WAACUGk"]
[Tue Jul 21 08:38:02.713013 2026] [security2:error] [pid 466512:tid 466691] [client 81.171.72.93:44048] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/server.key"] [unique_id "al9aGiKGokixMSfKDOf5WQAAAkU"]
[Tue Jul 21 08:38:02.814587 2026] [security2:error] [pid 466512:tid 466581] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/web.config"] [unique_id "al9aGiKGokixMSfKDOf5XAACN0Q"]
[Tue Jul 21 08:38:02.874216 2026] [security2:error] [pid 466512:tid 466655] [client 81.171.72.93:44036] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/.npmrc"] [unique_id "al9aGiKGokixMSfKDOf5ZwAAAiE"]
[Tue Jul 21 08:38:02.874356 2026] [security2:error] [pid 466512:tid 466689] [client 81.171.72.93:44038] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/config/production.json"] [unique_id "al9aGiKGokixMSfKDOf5aAAAAkM"]
[Tue Jul 21 08:38:02.932003 2026] [security2:error] [pid 466512:tid 466756] [client 74.249.245.134:20863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/fw.php"] [unique_id "al9aGiKGokixMSfKDOf5bAAAAoY"]
[Tue Jul 21 08:38:02.988488 2026] [security2:error] [pid 466512:tid 466764] [client 195.49.128.211:58974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aGiKGokixMSfKDOf5bwAAAo4"]
[Tue Jul 21 08:38:02.988586 2026] [security2:error] [pid 466512:tid 466764] [client 195.49.128.211:58974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aGiKGokixMSfKDOf5bwAAAo4"]
[Tue Jul 21 08:38:03.034902 2026] [security2:error] [pid 466512:tid 466546] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/.pypirc"] [unique_id "al9aGyKGokixMSfKDOf5cAAChCE"]
[Tue Jul 21 08:38:03.035071 2026] [security2:error] [pid 466512:tid 466754] [client 34.155.146.79:48792] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "console.gradiente.com"] [uri "/.pypirc"] [unique_id "al9aGyKGokixMSfKDOf5cAAChCE"]
[Tue Jul 21 08:38:03.069664 2026] [security2:error] [pid 466512:tid 466720] [client 103.59.206.240:31338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aGyKGokixMSfKDOf5eAAAAmI"]
[Tue Jul 21 08:38:03.069761 2026] [security2:error] [pid 466512:tid 466720] [client 103.59.206.240:31338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aGyKGokixMSfKDOf5eAAAAmI"]
[Tue Jul 21 08:38:03.149844 2026] [security2:error] [pid 466512:tid 466695] [client 152.59.181.104:54439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aGyKGokixMSfKDOf5fgAAAkk"]
[Tue Jul 21 08:38:03.149949 2026] [security2:error] [pid 466512:tid 466695] [client 152.59.181.104:54439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aGyKGokixMSfKDOf5fgAAAkk"]
[Tue Jul 21 08:38:03.152687 2026] [security2:error] [pid 466512:tid 466735] [client 20.220.225.223:54334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/kua.php"] [unique_id "al9aGyKGokixMSfKDOf5fwAAAnE"]
[Tue Jul 21 08:38:03.264063 2026] [security2:error] [pid 466512:tid 466617] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/app/.env"] [unique_id "al9aGyKGokixMSfKDOf5iQACLGg"]
[Tue Jul 21 08:38:03.304160 2026] [security2:error] [pid 466512:tid 466613] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "console.gradiente.com"] [uri "/frontend/.env"] [unique_id "al9aGyKGokixMSfKDOf5jgACd2Q"]
[Tue Jul 21 08:38:03.322425 2026] [security2:error] [pid 466512:tid 466540] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/src/.env"] [unique_id "al9aGyKGokixMSfKDOf5jwACIxs"]
[Tue Jul 21 08:38:03.342486 2026] [security2:error] [pid 466512:tid 466715] [client 49.144.66.253:33341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aGyKGokixMSfKDOf5kAAAAl0"]
[Tue Jul 21 08:38:03.342671 2026] [security2:error] [pid 466512:tid 466715] [client 49.144.66.253:33341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aGyKGokixMSfKDOf5kAAAAl0"]
[Tue Jul 21 08:38:03.344603 2026] [security2:error] [pid 466512:tid 466517] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/server/.env"] [unique_id "al9aGyKGokixMSfKDOf5kQACHQQ"]
[Tue Jul 21 08:38:03.422179 2026] [security2:error] [pid 466512:tid 466577] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "console.gradiente.com"] [uri "/dev/.env"] [unique_id "al9aGyKGokixMSfKDOf5lAACMUA"]
[Tue Jul 21 08:38:03.454941 2026] [proxy:error] [pid 466512:tid 466585] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:38:03.454994 2026] [proxy_http:error] [pid 466512:tid 466585] [remote 205.210.31.111:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:38:03.455731 2026] [proxy:error] [pid 466512:tid 466585] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:38:03.455764 2026] [proxy_http:error] [pid 466512:tid 466585] [remote 205.210.31.111:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:38:03.463891 2026] [security2:error] [pid 465652:tid 465820] [client 81.171.72.93:50016] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/secrets.json"] [unique_id "al9aGzzTqJoBC2Mw28_SWAAAAKs"]
[Tue Jul 21 08:38:03.466741 2026] [security2:error] [pid 465652:tid 465870] [client 81.171.72.93:50002] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/.bash_history"] [unique_id "al9aGzzTqJoBC2Mw28_SWQAAAN0"]
[Tue Jul 21 08:38:03.466873 2026] [security2:error] [pid 465652:tid 465854] [client 81.171.72.93:50012] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "casaejardimperfeito.com.br"] [uri "/config.php"] [unique_id "al9aGzzTqJoBC2Mw28_SWgAAAM0"]
[Tue Jul 21 08:38:03.474999 2026] [security2:error] [pid 466512:tid 466561] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/staging/.env"] [unique_id "al9aGyKGokixMSfKDOf5mwACSzA"]
[Tue Jul 21 08:38:03.475161 2026] [security2:error] [pid 466512:tid 466697] [client 34.155.146.79:48792] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "console.gradiente.com"] [uri "/staging/.env"] [unique_id "al9aGyKGokixMSfKDOf5mwACSzA"]
[Tue Jul 21 08:38:03.484004 2026] [security2:error] [pid 466512:tid 466565] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/production/.env"] [unique_id "al9aGyKGokixMSfKDOf5nAACjzQ"]
[Tue Jul 21 08:38:03.487774 2026] [security2:error] [pid 466512:tid 466624] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/docker/.env"] [unique_id "al9aGyKGokixMSfKDOf5nQACQW8"]
[Tue Jul 21 08:38:03.532439 2026] [security2:error] [pid 466512:tid 466591] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/.env.prod.bak"] [unique_id "al9aGyKGokixMSfKDOf5ngACWk4"]
[Tue Jul 21 08:38:03.546962 2026] [security2:error] [pid 466512:tid 466537] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "console.gradiente.com"] [uri "/@fs/proc/self/environ"] [unique_id "al9aGyKGokixMSfKDOf5nwACKxg"]
[Tue Jul 21 08:38:03.549038 2026] [security2:error] [pid 466512:tid 466609] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/@fs/.env"] [unique_id "al9aGyKGokixMSfKDOf5oAACK2A"]
[Tue Jul 21 08:38:03.558641 2026] [security2:error] [pid 466512:tid 466559] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/.env.production.bak"] [unique_id "al9aGyKGokixMSfKDOf5ogACFS4"]
[Tue Jul 21 08:38:03.586931 2026] [security2:error] [pid 466512:tid 466600] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "console.gradiente.com"] [uri "/@fs/root/.env"] [unique_id "al9aGyKGokixMSfKDOf5pQACglc"]
[Tue Jul 21 08:38:03.879109 2026] [security2:error] [pid 466512:tid 466612] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "console.gradiente.com"] [uri "/config/firebase-admin.json"] [unique_id "al9aGyKGokixMSfKDOf5tAACO2M"]
[Tue Jul 21 08:38:04.115331 2026] [security2:error] [pid 466512:tid 466593] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "console.gradiente.com"] [uri "/api/config"] [unique_id "al9aHCKGokixMSfKDOf5ygACSlA"]
[Tue Jul 21 08:38:04.175986 2026] [security2:error] [pid 466512:tid 466620] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/firebase-config.json"] [unique_id "al9aHCKGokixMSfKDOf50QACOGs"]
[Tue Jul 21 08:38:04.177463 2026] [security2:error] [pid 466512:tid 466639] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "console.gradiente.com"] [uri "/env.js"] [unique_id "al9aHCKGokixMSfKDOf50gACOH4"]
[Tue Jul 21 08:38:04.271999 2026] [security2:error] [pid 466512:tid 466572] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "console.gradiente.com"] [uri "/env.json"] [unique_id "al9aHCKGokixMSfKDOf50wACMDs"]
[Tue Jul 21 08:38:04.290854 2026] [security2:error] [pid 466512:tid 466607] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "console.gradiente.com"] [uri "/.well-known/jwks.json"] [unique_id "al9aHCKGokixMSfKDOf51AACSV4"]
[Tue Jul 21 08:38:04.349371 2026] [security2:error] [pid 466512:tid 466601] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/api/env"] [unique_id "al9aHCKGokixMSfKDOf52QACPlg"]
[Tue Jul 21 08:38:04.349618 2026] [security2:error] [pid 466512:tid 466684] [client 34.155.146.79:48792] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "console.gradiente.com"] [uri "/api/env"] [unique_id "al9aHCKGokixMSfKDOf52QACPlg"]
[Tue Jul 21 08:38:04.382122 2026] [security2:error] [pid 466512:tid 466629] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/runtime-config.js"] [unique_id "al9aHCKGokixMSfKDOf52wACNXQ"]
[Tue Jul 21 08:38:04.382352 2026] [security2:error] [pid 466512:tid 466675] [client 34.155.146.79:48792] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "console.gradiente.com"] [uri "/runtime-config.js"] [unique_id "al9aHCKGokixMSfKDOf52wACNXQ"]
[Tue Jul 21 08:38:04.411734 2026] [security2:error] [pid 465652:tid 465785] [client 61.1.167.83:49193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aHDzTqJoBC2Mw28_SawAAAIg"]
[Tue Jul 21 08:38:04.411936 2026] [security2:error] [pid 465652:tid 465785] [client 61.1.167.83:49193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aHDzTqJoBC2Mw28_SawAAAIg"]
[Tue Jul 21 08:38:04.418588 2026] [security2:error] [pid 466512:tid 466549] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "console.gradiente.com"] [uri "/manifest.webmanifest"] [unique_id "al9aHCKGokixMSfKDOf54AACLSQ"]
[Tue Jul 21 08:38:04.483263 2026] [security2:error] [pid 466512:tid 466523] [remote 209.97.182.179:34546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/wp-login.php"] [unique_id "al9aHCKGokixMSfKDOf54gACJwo"]
[Tue Jul 21 08:38:04.519180 2026] [security2:error] [pid 466512:tid 466720] [client 65.21.113.253:36154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aHCKGokixMSfKDOf5wQAAAmI"]
[Tue Jul 21 08:38:04.522235 2026] [security2:error] [pid 466512:tid 466557] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/openapi.json"] [unique_id "al9aHCKGokixMSfKDOf55AACbiw"]
[Tue Jul 21 08:38:04.522454 2026] [security2:error] [pid 466512:tid 466732] [client 34.155.146.79:48792] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "console.gradiente.com"] [uri "/openapi.json"] [unique_id "al9aHCKGokixMSfKDOf55AACbiw"]
[Tue Jul 21 08:38:04.576273 2026] [security2:error] [pid 466512:tid 466606] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "console.gradiente.com"] [uri "/api/account"] [unique_id "al9aHCKGokixMSfKDOf56gACNF0"]
[Tue Jul 21 08:38:04.596501 2026] [security2:error] [pid 466512:tid 466575] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "console.gradiente.com"] [uri "/app-config.json"] [unique_id "al9aHCKGokixMSfKDOf57AACVD4"]
[Tue Jul 21 08:38:04.751983 2026] [security2:error] [pid 465652:tid 465802] [client 20.226.60.151:58520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/patie.php"] [unique_id "al9aHDzTqJoBC2Mw28_ScAAAAJk"]
[Tue Jul 21 08:38:04.826872 2026] [security2:error] [pid 466512:tid 466550] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "console.gradiente.com"] [uri "/graphql"] [unique_id "al9aHCKGokixMSfKDOf5_QACKSU"]
[Tue Jul 21 08:38:04.827008 2026] [security2:error] [pid 466512:tid 466663] [client 34.155.146.79:48792] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "console.gradiente.com"] [uri "/graphql"] [unique_id "al9aHCKGokixMSfKDOf5_QACKSU"]
[Tue Jul 21 08:38:04.829780 2026] [security2:error] [pid 466512:tid 466587] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "console.gradiente.com"] [uri "/api/graphql"] [unique_id "al9aHCKGokixMSfKDOf5_gACa0o"]
[Tue Jul 21 08:38:05.052235 2026] [lsapi:error] [pid 465652:tid 465743] [remote 200.168.69.144:50688] [host asimd.ongsolution.com.br] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown, referer: https://asimd.ongsolution.com.br/pages/forms/financeiro/cadastro-banco.php
[Tue Jul 21 08:38:05.052253 2026] [lsapi:error] [pid 465652:tid 465743] [remote 200.168.69.144:50688] [host asimd.ongsolution.com.br] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache, referer: https://asimd.ongsolution.com.br/pages/forms/financeiro/cadastro-banco.php
[Tue Jul 21 08:38:05.052257 2026] [lsapi:error] [pid 465652:tid 465743] [remote 200.168.69.144:50688] [host asimd.ongsolution.com.br] Client error on sending request(POST /php/financeiro/atualizar-saldo-banco.php HTTP/2.0); uri(/php/financeiro/atualizar-saldo-banco.php) content-length(28): user_get_body(tmpstackbuf, 16384): read from client failed, referer: https://asimd.ongsolution.com.br/pages/forms/financeiro/cadastro-banco.php
[Tue Jul 21 08:38:05.069427 2026] [security2:error] [pid 466512:tid 466582] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "console.gradiente.com"] [uri "/phpinfo.php"] [unique_id "al9aHSKGokixMSfKDOf6BwACJUU"]
[Tue Jul 21 08:38:05.069444 2026] [security2:error] [pid 466512:tid 466578] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "console.gradiente.com"] [uri "/pi.php"] [unique_id "al9aHSKGokixMSfKDOf6CAACJUE"]
[Tue Jul 21 08:38:05.069472 2026] [security2:error] [pid 466512:tid 466570] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "console.gradiente.com"] [uri "/i.php"] [unique_id "al9aHSKGokixMSfKDOf6CQACJTk"]
[Tue Jul 21 08:38:05.093802 2026] [security2:error] [pid 466512:tid 466579] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "console.gradiente.com"] [uri "/test.php"] [unique_id "al9aHSKGokixMSfKDOf6DQACT0I"]
[Tue Jul 21 08:38:05.094152 2026] [security2:error] [pid 466512:tid 466598] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "console.gradiente.com"] [uri "/info.php"] [unique_id "al9aHSKGokixMSfKDOf6DgACT1U"]
[Tue Jul 21 08:38:05.268968 2026] [security2:error] [pid 465652:tid 465828] [client 20.226.60.151:58583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/aa.php"] [unique_id "al9aHTzTqJoBC2Mw28_SeAAAALM"]
[Tue Jul 21 08:38:05.286621 2026] [security2:error] [pid 466512:tid 466592] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "console.gradiente.com"] [uri "/app_dev.php/_profiler"] [unique_id "al9aHSKGokixMSfKDOf6GwACck8"]
[Tue Jul 21 08:38:05.287563 2026] [security2:error] [pid 466512:tid 466573] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.146.155.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "console.gradiente.com"] [uri "/app_dev.php"] [unique_id "al9aHSKGokixMSfKDOf6HAACcjw"]
[Tue Jul 21 08:38:05.302398 2026] [security2:error] [pid 466512:tid 466721] [client 20.206.105.145:22106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/a2.php"] [unique_id "al9aHSKGokixMSfKDOf6HwAAAmM"]
[Tue Jul 21 08:38:05.322183 2026] [security2:error] [pid 466512:tid 466613] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "console.gradiente.com"] [uri "/__debug__/"] [unique_id "al9aHSKGokixMSfKDOf6IAACH2Q"]
[Tue Jul 21 08:38:05.478585 2026] [access_compat:error] [pid 466512:tid 466631] [remote 34.155.146.79:48792] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 08:38:05.484760 2026] [security2:error] [pid 465652:tid 465831] [client 173.252.95.42:56370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9aHTzTqJoBC2Mw28_SeQAAALY"]
[Tue Jul 21 08:38:05.493898 2026] [security2:error] [pid 466512:tid 466561] [remote 34.155.146.79:48792] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "console.gradiente.com"] [uri "/server-info"] [unique_id "al9aHSKGokixMSfKDOf6KwACNTA"]
[Tue Jul 21 08:38:05.951679 2026] [security2:error] [pid 465652:tid 465859] [client 117.213.202.34:65022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aHTzTqJoBC2Mw28_SiQAAANI"]
[Tue Jul 21 08:38:05.951830 2026] [security2:error] [pid 465652:tid 465859] [client 117.213.202.34:65022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aHTzTqJoBC2Mw28_SiQAAANI"]
[Tue Jul 21 08:38:06.366145 2026] [security2:error] [pid 466512:tid 466567] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aHiKGokixMSfKDOf6VQACGjY"]
[Tue Jul 21 08:38:06.366423 2026] [security2:error] [pid 466512:tid 466648] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aHiKGokixMSfKDOf6VQACGjY"]
[Tue Jul 21 08:38:06.523127 2026] [security2:error] [pid 466512:tid 466686] [client 195.49.128.211:50763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aHiKGokixMSfKDOf6XgAAAkA"]
[Tue Jul 21 08:38:06.523244 2026] [security2:error] [pid 466512:tid 466686] [client 195.49.128.211:50763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aHiKGokixMSfKDOf6XgAAAkA"]
[Tue Jul 21 08:38:06.572925 2026] [security2:error] [pid 466512:tid 466700] [client 65.21.113.253:36154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aHiKGokixMSfKDOf6RwAAAk4"]
[Tue Jul 21 08:38:06.628729 2026] [security2:error] [pid 466512:tid 466680] [client 20.151.10.161:60747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9aHiKGokixMSfKDOf6ZAAAAjo"]
[Tue Jul 21 08:38:06.791468 2026] [security2:error] [pid 466512:tid 466532] [remote 103.28.36.122:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amandamorau.adv.br"] [uri "/wp-login.php"] [unique_id "al9aHiKGokixMSfKDOf6aQACXBM"]
[Tue Jul 21 08:38:06.908395 2026] [security2:error] [pid 466512:tid 466653] [client 74.249.245.134:50805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/fm.php"] [unique_id "al9aHiKGokixMSfKDOf6bgAAAh8"]
[Tue Jul 21 08:38:07.082960 2026] [security2:error] [pid 466512:tid 466601] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aHyKGokixMSfKDOf6cgACO1g"]
[Tue Jul 21 08:38:07.083109 2026] [security2:error] [pid 466512:tid 466681] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aHyKGokixMSfKDOf6cgACO1g"]
[Tue Jul 21 08:38:07.729332 2026] [security2:error] [pid 466512:tid 466693] [client 20.226.60.151:58571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xwpg.php"] [unique_id "al9aHyKGokixMSfKDOf6fgAAAkc"]
[Tue Jul 21 08:38:08.105443 2026] [security2:error] [pid 465652:tid 465876] [client 202.179.75.202:44338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aIDzTqJoBC2Mw28_SpAAAAOM"]
[Tue Jul 21 08:38:08.106250 2026] [security2:error] [pid 465652:tid 465876] [client 202.179.75.202:44338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aIDzTqJoBC2Mw28_SpAAAAOM"]
[Tue Jul 21 08:38:08.381640 2026] [proxy:error] [pid 466512:tid 466758] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:38:08.381741 2026] [proxy_http:error] [pid 466512:tid 466758] [client 45.55.137.34:34704] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:38:08.383395 2026] [proxy:error] [pid 466512:tid 466758] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:38:08.383454 2026] [proxy_http:error] [pid 466512:tid 466758] [client 45.55.137.34:34704] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:38:08.615283 2026] [proxy:error] [pid 466512:tid 466682] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:38:08.615352 2026] [proxy_http:error] [pid 466512:tid 466682] [client 45.55.137.34:34716] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.bavos.com.br/
[Tue Jul 21 08:38:08.615985 2026] [proxy:error] [pid 466512:tid 466682] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:38:08.616029 2026] [proxy_http:error] [pid 466512:tid 466682] [client 45.55.137.34:34716] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.bavos.com.br/
[Tue Jul 21 08:38:08.826788 2026] [security2:error] [pid 466512:tid 466700] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aICKGokixMSfKDOf6jQACTgo"]
[Tue Jul 21 08:38:08.900459 2026] [security2:error] [pid 466512:tid 466692] [client 223.181.60.88:18670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aICKGokixMSfKDOf6lgAAAkY"]
[Tue Jul 21 08:38:08.900559 2026] [security2:error] [pid 466512:tid 466692] [client 223.181.60.88:18670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aICKGokixMSfKDOf6lgAAAkY"]
[Tue Jul 21 08:38:08.934217 2026] [security2:error] [pid 466512:tid 466663] [client 65.21.113.253:36154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aICKGokixMSfKDOf6iQAAAik"]
[Tue Jul 21 08:38:09.036089 2026] [security2:error] [pid 466512:tid 466652] [client 20.220.225.223:46973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/ez.php"] [unique_id "al9aISKGokixMSfKDOf6lwAAAh4"]
[Tue Jul 21 08:38:09.094543 2026] [core:error] [pid 465652:tid 465892] [client 45.55.137.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:38:09.094560 2026] [core:error] [pid 465652:tid 465892] [client 45.55.137.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:38:09.107267 2026] [security2:error] [pid 465652:tid 465839] [client 20.206.105.145:22106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/file15.php"] [unique_id "al9aITzTqJoBC2Mw28_SugAAAL4"]
[Tue Jul 21 08:38:09.339192 2026] [security2:error] [pid 466512:tid 466737] [client 74.7.244.50:45150] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "patricialourenco.online"] [uri "/index.php"] [unique_id "al9aICKGokixMSfKDOf6kgACcyw"]
[Tue Jul 21 08:38:09.390207 2026] [autoindex:error] [pid 466512:tid 466757] [client 43.135.138.128:45016] AH01276: Cannot serve directory /home2/inlaud99/choppcontrol.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:38:09.843433 2026] [security2:error] [pid 466512:tid 466734] [client 5.38.115.39:1130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aISKGokixMSfKDOf6pgAAAnA"]
[Tue Jul 21 08:38:09.845930 2026] [security2:error] [pid 466512:tid 466734] [client 5.38.115.39:1130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aISKGokixMSfKDOf6pgAAAnA"]
[Tue Jul 21 08:38:09.859423 2026] [security2:error] [pid 465652:tid 465855] [client 20.206.105.145:33681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9aITzTqJoBC2Mw28_SyAAAAM4"]
[Tue Jul 21 08:38:09.936412 2026] [security2:error] [pid 466512:tid 466534] [remote 152.42.137.70:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.137.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tavarescont.com.br"] [uri "/wp-login.php"] [unique_id "al9aISKGokixMSfKDOf6pwACXhU"]
[Tue Jul 21 08:38:10.079910 2026] [security2:error] [pid 466512:tid 466741] [client 20.206.105.145:21797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/jp.php"] [unique_id "al9aIiKGokixMSfKDOf6qgAAAnc"]
[Tue Jul 21 08:38:10.195194 2026] [security2:error] [pid 465652:tid 465862] [client 5.31.193.106:58620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aIjzTqJoBC2Mw28_SzQAAANU"]
[Tue Jul 21 08:38:10.195285 2026] [security2:error] [pid 465652:tid 465862] [client 5.31.193.106:58620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aIjzTqJoBC2Mw28_SzQAAANU"]
[Tue Jul 21 08:38:10.554713 2026] [security2:error] [pid 466512:tid 466748] [client 20.206.105.145:33785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9aIiKGokixMSfKDOf6tQAAAn4"]
[Tue Jul 21 08:38:10.555245 2026] [security2:error] [pid 466512:tid 466677] [client 20.206.105.145:22117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/f35.php"] [unique_id "al9aIiKGokixMSfKDOf6tgAAAjc"]
[Tue Jul 21 08:38:10.682705 2026] [security2:error] [pid 465652:tid 465894] [client 20.63.100.92:2807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/2352356666.php"] [unique_id "al9aIjzTqJoBC2Mw28_S1wAAAPU"]
[Tue Jul 21 08:38:10.777722 2026] [security2:error] [pid 465652:tid 465890] [client 20.206.105.145:22228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-load.php"] [unique_id "al9aIjzTqJoBC2Mw28_S2AAAAPE"]
[Tue Jul 21 08:38:10.791568 2026] [security2:error] [pid 466512:tid 466730] [client 65.21.113.253:36154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aIiKGokixMSfKDOf6sgAAAmw"]
[Tue Jul 21 08:38:11.070561 2026] [security2:error] [pid 465652:tid 465876] [client 20.151.10.161:60746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9aIzzTqJoBC2Mw28_S5gAAAOM"]
[Tue Jul 21 08:38:11.104201 2026] [security2:error] [pid 465652:tid 465908] [client 20.206.105.145:22114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/xwpg.php"] [unique_id "al9aIzzTqJoBC2Mw28_S6QAAAQM"]
[Tue Jul 21 08:38:11.282915 2026] [security2:error] [pid 465652:tid 465901] [client 59.95.197.55:53910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aIzzTqJoBC2Mw28_S7AAAAPw"]
[Tue Jul 21 08:38:11.283364 2026] [security2:error] [pid 465652:tid 465901] [client 59.95.197.55:53910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aIzzTqJoBC2Mw28_S7AAAAPw"]
[Tue Jul 21 08:38:11.709792 2026] [security2:error] [pid 466512:tid 466756] [client 14.245.224.124:55414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aIyKGokixMSfKDOf6zAAAAoY"]
[Tue Jul 21 08:38:11.709932 2026] [security2:error] [pid 466512:tid 466756] [client 14.245.224.124:55414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aIyKGokixMSfKDOf6zAAAAoY"]
[Tue Jul 21 08:38:11.905292 2026] [core:error] [pid 466512:tid 466757] [client 45.55.137.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcontacts.bavos.com.br/
[Tue Jul 21 08:38:11.905309 2026] [core:error] [pid 466512:tid 466757] [client 45.55.137.34:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcontacts.bavos.com.br/
[Tue Jul 21 08:38:11.946458 2026] [security2:error] [pid 465652:tid 465887] [client 20.63.100.92:2207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/pn.php"] [unique_id "al9aIzzTqJoBC2Mw28_S_gAAAO4"]
[Tue Jul 21 08:38:12.195267 2026] [proxy:error] [pid 466512:tid 466703] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:38:12.195325 2026] [proxy_http:error] [pid 466512:tid 466703] [client 87.236.176.135:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:38:12.195857 2026] [proxy:error] [pid 466512:tid 466703] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:38:12.195880 2026] [proxy_http:error] [pid 466512:tid 466703] [client 87.236.176.135:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:38:12.335687 2026] [security2:error] [pid 465652:tid 465819] [client 122.176.100.127:53289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aJDzTqJoBC2Mw28_TBAAAAKo"]
[Tue Jul 21 08:38:12.335889 2026] [security2:error] [pid 465652:tid 465819] [client 122.176.100.127:53289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aJDzTqJoBC2Mw28_TBAAAAKo"]
[Tue Jul 21 08:38:12.361046 2026] [security2:error] [pid 465652:tid 465905] [client 20.151.10.161:60699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/media.php"] [unique_id "al9aJDzTqJoBC2Mw28_TBQAAAQA"]
[Tue Jul 21 08:38:12.538578 2026] [security2:error] [pid 466512:tid 466745] [client 20.206.105.145:33787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/media.php"] [unique_id "al9aJCKGokixMSfKDOf6_QAAAns"]
[Tue Jul 21 08:38:12.578987 2026] [security2:error] [pid 465652:tid 465864] [client 20.206.105.145:22211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/waf.php"] [unique_id "al9aJDzTqJoBC2Mw28_TCwAAANc"]
[Tue Jul 21 08:38:12.662756 2026] [security2:error] [pid 466512:tid 466585] [remote 202.51.202.242:37812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9aJCKGokixMSfKDOf7AAACPkg"]
[Tue Jul 21 08:38:13.223652 2026] [security2:error] [pid 466512:tid 466662] [client 20.151.10.161:60676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/images.php"] [unique_id "al9aJSKGokixMSfKDOf7EgAAAig"]
[Tue Jul 21 08:38:13.550929 2026] [security2:error] [pid 465652:tid 465899] [client 152.59.181.104:54877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aJTzTqJoBC2Mw28_TGwAAAPo"]
[Tue Jul 21 08:38:13.551020 2026] [security2:error] [pid 465652:tid 465899] [client 152.59.181.104:54877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aJTzTqJoBC2Mw28_TGwAAAPo"]
[Tue Jul 21 08:38:13.605253 2026] [security2:error] [pid 466512:tid 466653] [client 198.44.157.34:36310] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9aJSKGokixMSfKDOf7IAAAAh8"]
[Tue Jul 21 08:38:13.605345 2026] [security2:error] [pid 466512:tid 466653] [client 198.44.157.34:36310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9aJSKGokixMSfKDOf7IAAAAh8"]
[Tue Jul 21 08:38:13.619591 2026] [security2:error] [pid 466512:tid 466714] [client 74.249.245.134:20119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/ini.php"] [unique_id "al9aJSKGokixMSfKDOf7IQAAAlw"]
[Tue Jul 21 08:38:13.633843 2026] [security2:error] [pid 466512:tid 466702] [client 195.49.128.211:59585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aJSKGokixMSfKDOf7IwAAAlA"]
[Tue Jul 21 08:38:13.633933 2026] [security2:error] [pid 466512:tid 466702] [client 195.49.128.211:59585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aJSKGokixMSfKDOf7IwAAAlA"]
[Tue Jul 21 08:38:13.677211 2026] [security2:error] [pid 466512:tid 466677] [client 152.59.34.51:57858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aJSKGokixMSfKDOf7JgAAAjc"]
[Tue Jul 21 08:38:13.677320 2026] [security2:error] [pid 466512:tid 466677] [client 152.59.34.51:57858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aJSKGokixMSfKDOf7JgAAAjc"]
[Tue Jul 21 08:38:13.810326 2026] [security2:error] [pid 466512:tid 466718] [client 103.59.206.240:31376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aJSKGokixMSfKDOf7MwAAAmA"]
[Tue Jul 21 08:38:13.810457 2026] [security2:error] [pid 466512:tid 466718] [client 103.59.206.240:31376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aJSKGokixMSfKDOf7MwAAAmA"]
[Tue Jul 21 08:38:14.208202 2026] [security2:error] [pid 466512:tid 466690] [client 49.144.66.253:33485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aJiKGokixMSfKDOf7QgAAAkQ"]
[Tue Jul 21 08:38:14.208314 2026] [security2:error] [pid 466512:tid 466690] [client 49.144.66.253:33485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aJiKGokixMSfKDOf7QgAAAkQ"]
[Tue Jul 21 08:38:14.606270 2026] [security2:error] [pid 466512:tid 466662] [client 20.226.60.151:58572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/ops.php"] [unique_id "al9aJiKGokixMSfKDOf7TQAAAig"]
[Tue Jul 21 08:38:14.894692 2026] [security2:error] [pid 465652:tid 465866] [client 195.206.105.227:37192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aJjzTqJoBC2Mw28_TPAAAANk"]
[Tue Jul 21 08:38:14.894783 2026] [security2:error] [pid 465652:tid 465866] [client 195.206.105.227:37192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aJjzTqJoBC2Mw28_TPAAAANk"]
[Tue Jul 21 08:38:14.915538 2026] [security2:error] [pid 466512:tid 466753] [client 20.151.10.161:60770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/adminner.php"] [unique_id "al9aJiKGokixMSfKDOf7VQAAAoM"]
[Tue Jul 21 08:38:15.230887 2026] [security2:error] [pid 465652:tid 465828] [client 20.220.225.223:40730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/fz.php"] [unique_id "al9aJzzTqJoBC2Mw28_TQwAAALM"]
[Tue Jul 21 08:38:15.439516 2026] [security2:error] [pid 466512:tid 466677] [client 20.206.105.145:21991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/xstelth.php"] [unique_id "al9aJyKGokixMSfKDOf7XwAAAjc"]
[Tue Jul 21 08:38:15.575262 2026] [security2:error] [pid 466512:tid 466680] [client 20.151.10.161:60742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/admin.php"] [unique_id "al9aJyKGokixMSfKDOf7YgAAAjo"]
[Tue Jul 21 08:38:15.602952 2026] [security2:error] [pid 466512:tid 466709] [client 46.105.38.210:34223] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tragaseushow.com.br"] [uri "/robots.txt"] [unique_id "al9aJyKGokixMSfKDOf7YwAAAlc"]
[Tue Jul 21 08:38:15.603085 2026] [security2:error] [pid 466512:tid 466709] [client 46.105.38.210:34223] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tragaseushow.com.br"] [uri "/robots.txt"] [unique_id "al9aJyKGokixMSfKDOf7YwAAAlc"]
[Tue Jul 21 08:38:15.779226 2026] [security2:error] [pid 465652:tid 465874] [client 213.152.162.15:55230] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9aJzzTqJoBC2Mw28_TSwAAAOE"]
[Tue Jul 21 08:38:15.779321 2026] [security2:error] [pid 465652:tid 465874] [client 213.152.162.15:55230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9aJzzTqJoBC2Mw28_TSwAAAOE"]
[Tue Jul 21 08:38:16.083940 2026] [security2:error] [pid 465652:tid 465841] [client 20.206.105.145:33759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/images.php"] [unique_id "al9aKDzTqJoBC2Mw28_TWAAAAMA"]
[Tue Jul 21 08:38:16.219791 2026] [security2:error] [pid 465652:tid 465654] [remote 45.117.83.212:49058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9aKDzTqJoBC2Mw28_TWgAA6AE"]
[Tue Jul 21 08:38:16.368325 2026] [access_compat:error] [pid 466512:tid 466744] [client 162.241.63.68:10090] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:38:16.373327 2026] [fcgid:warn] [pid 466512:tid 466745] (70014)End of file found: [client 199.45.155.68:55272] mod_fcgid: can't get data from http client
[Tue Jul 21 08:38:16.546226 2026] [security2:error] [pid 466512:tid 466761] [client 117.213.202.34:49249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aKCKGokixMSfKDOf7eAAAAos"]
[Tue Jul 21 08:38:16.546328 2026] [security2:error] [pid 466512:tid 466761] [client 117.213.202.34:49249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aKCKGokixMSfKDOf7eAAAAos"]
[Tue Jul 21 08:38:16.921465 2026] [security2:error] [pid 466512:tid 466611] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aKCKGokixMSfKDOf7fgAChGI"]
[Tue Jul 21 08:38:16.921640 2026] [security2:error] [pid 466512:tid 466754] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aKCKGokixMSfKDOf7fgAChGI"]
[Tue Jul 21 08:38:16.940973 2026] [security2:error] [pid 466512:tid 466763] [client 20.220.225.223:54287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/la.php"] [unique_id "al9aKCKGokixMSfKDOf7fwAAAo0"]
[Tue Jul 21 08:38:17.026099 2026] [security2:error] [pid 466512:tid 466753] [client 20.151.10.161:60786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/k.php"] [unique_id "al9aKSKGokixMSfKDOf7gwAAAoM"]
[Tue Jul 21 08:38:17.119128 2026] [security2:error] [pid 465652:tid 465667] [remote 103.28.36.200:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9aKTzTqJoBC2Mw28_TbgAAiQ4"]
[Tue Jul 21 08:38:17.170396 2026] [security2:error] [pid 466512:tid 466711] [client 20.206.105.145:22092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-links.php"] [unique_id "al9aKSKGokixMSfKDOf7iAAAAlk"]
[Tue Jul 21 08:38:17.208328 2026] [security2:error] [pid 466512:tid 466655] [client 195.49.128.211:51371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aKSKGokixMSfKDOf7iQAAAiE"]
[Tue Jul 21 08:38:17.208443 2026] [security2:error] [pid 466512:tid 466655] [client 195.49.128.211:51371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aKSKGokixMSfKDOf7iQAAAiE"]
[Tue Jul 21 08:38:17.626630 2026] [security2:error] [pid 466512:tid 466564] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aKSKGokixMSfKDOf7lgACNzM"]
[Tue Jul 21 08:38:17.626738 2026] [security2:error] [pid 466512:tid 466677] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aKSKGokixMSfKDOf7lgACNzM"]
[Tue Jul 21 08:38:18.290974 2026] [security2:error] [pid 466512:tid 466533] [remote 199.189.225.40:43187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9aKiKGokixMSfKDOf7oAACTRQ"]
[Tue Jul 21 08:38:18.338709 2026] [security2:error] [pid 466512:tid 466729] [client 74.249.245.134:42699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/themes.php"] [unique_id "al9aKiKGokixMSfKDOf7ogAAAms"]
[Tue Jul 21 08:38:18.590657 2026] [security2:error] [pid 466512:tid 466543] [remote 45.79.123.44:37408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9aKiKGokixMSfKDOf7qgACKx4"]
[Tue Jul 21 08:38:18.867380 2026] [security2:error] [pid 465652:tid 465859] [client 20.206.105.145:33773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/adminner.php"] [unique_id "al9aKjzTqJoBC2Mw28_TiwAAANI"]
[Tue Jul 21 08:38:18.890018 2026] [security2:error] [pid 466512:tid 466679] [client 202.179.75.202:47518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aKiKGokixMSfKDOf7rwAAAjk"]
[Tue Jul 21 08:38:18.890465 2026] [security2:error] [pid 466512:tid 466679] [client 202.179.75.202:47518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aKiKGokixMSfKDOf7rwAAAjk"]
[Tue Jul 21 08:38:19.127833 2026] [security2:error] [pid 466512:tid 466637] [remote 173.252.95.15:63722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9aKyKGokixMSfKDOf7tQACSnw"]
[Tue Jul 21 08:38:19.423734 2026] [security2:error] [pid 466512:tid 466706] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aKyKGokixMSfKDOf7twACVFo"]
[Tue Jul 21 08:38:19.503807 2026] [security2:error] [pid 466512:tid 466713] [client 20.206.105.145:21772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9aKyKGokixMSfKDOf7uAAAAls"]
[Tue Jul 21 08:38:19.829972 2026] [security2:error] [pid 465652:tid 465906] [client 20.151.10.161:60773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/x.php"] [unique_id "al9aKzzTqJoBC2Mw28_ToQAAAQE"]
[Tue Jul 21 08:38:20.093183 2026] [security2:error] [pid 465652:tid 465790] [client 223.181.60.88:24131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aLDzTqJoBC2Mw28_TpwAAAI0"]
[Tue Jul 21 08:38:20.094846 2026] [security2:error] [pid 465652:tid 465790] [client 223.181.60.88:24131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aLDzTqJoBC2Mw28_TpwAAAI0"]
[Tue Jul 21 08:38:20.845628 2026] [security2:error] [pid 466512:tid 466655] [client 20.206.105.145:22258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.ibericaladrilhos.com.br"] [uri "/aaa.php"] [unique_id "al9aLCKGokixMSfKDOf73QAAAiE"]
[Tue Jul 21 08:38:20.927007 2026] [security2:error] [pid 465652:tid 465796] [client 5.38.115.39:64182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aLDzTqJoBC2Mw28_TvQAAAJM"]
[Tue Jul 21 08:38:20.927160 2026] [security2:error] [pid 465652:tid 465796] [client 5.38.115.39:64182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aLDzTqJoBC2Mw28_TvQAAAJM"]
[Tue Jul 21 08:38:21.057127 2026] [security2:error] [pid 465652:tid 465888] [client 20.206.105.145:33744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/admin.php"] [unique_id "al9aLTzTqJoBC2Mw28_TwgAAAO8"]
[Tue Jul 21 08:38:21.607270 2026] [security2:error] [pid 465652:tid 465674] [remote 217.182.128.41:35696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "escoladaseguranca.com.br"] [uri "/wp-login.php"] [unique_id "al9aLTzTqJoBC2Mw28_TzgAAqxU"]
[Tue Jul 21 08:38:21.719886 2026] [security2:error] [pid 465652:tid 465768] [remote 46.105.28.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.28.105.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.hauptmann.com.br"] [uri "/wp-login.php"] [unique_id "al9aLTzTqJoBC2Mw28_T0wAAinM"]
[Tue Jul 21 08:38:21.727688 2026] [security2:error] [pid 465652:tid 465793] [client 20.151.10.161:60694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wss.php"] [unique_id "al9aLTzTqJoBC2Mw28_T1AAAAJA"]
[Tue Jul 21 08:38:21.750144 2026] [security2:error] [pid 465652:tid 465809] [client 59.95.197.55:54363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aLTzTqJoBC2Mw28_T1QAAAKA"]
[Tue Jul 21 08:38:21.750236 2026] [security2:error] [pid 465652:tid 465809] [client 59.95.197.55:54363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aLTzTqJoBC2Mw28_T1QAAAKA"]
[Tue Jul 21 08:38:22.347847 2026] [security2:error] [pid 466512:tid 466744] [client 14.245.224.124:55894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aLiKGokixMSfKDOf76QAAAno"]
[Tue Jul 21 08:38:22.348168 2026] [security2:error] [pid 466512:tid 466744] [client 14.245.224.124:55894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aLiKGokixMSfKDOf76QAAAno"]
[Tue Jul 21 08:38:22.569992 2026] [security2:error] [pid 465652:tid 465845] [client 185.8.106.219:36002] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ocaminhodarecuperacao.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9aLjzTqJoBC2Mw28_T5AAAAMQ"]
[Tue Jul 21 08:38:22.828550 2026] [security2:error] [pid 465652:tid 465838] [client 20.151.10.161:60753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/ty.php"] [unique_id "al9aLjzTqJoBC2Mw28_T6AAAAL0"]
[Tue Jul 21 08:38:22.849657 2026] [security2:error] [pid 466512:tid 466690] [client 122.176.100.127:53799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aLiKGokixMSfKDOf78QAAAkQ"]
[Tue Jul 21 08:38:22.849763 2026] [security2:error] [pid 466512:tid 466690] [client 122.176.100.127:53799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aLiKGokixMSfKDOf78QAAAkQ"]
[Tue Jul 21 08:38:23.118771 2026] [security2:error] [pid 466512:tid 466643] [client 185.8.106.219:57768] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ocaminhodarecuperacao.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9aLyKGokixMSfKDOf7-gAAAhU"]
[Tue Jul 21 08:38:23.707964 2026] [security2:error] [pid 466512:tid 466706] [client 65.111.21.207:24729] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "clinicaleonazevedo.com.br"] [uri "/"] [unique_id "al9aLyKGokixMSfKDOf8BQAAAlQ"]
[Tue Jul 21 08:38:23.970464 2026] [security2:error] [pid 466512:tid 466689] [client 185.8.106.219:36020] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.ocaminhodarecuperacao.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9aLyKGokixMSfKDOf8DQAAAkM"]
[Tue Jul 21 08:38:23.978852 2026] [security2:error] [pid 466512:tid 466766] [client 65.111.21.207:24729] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "clinicaleonazevedo.com.br"] [uri "/"] [unique_id "al9aLyKGokixMSfKDOf8EAAAApA"]
[Tue Jul 21 08:38:24.010656 2026] [security2:error] [pid 466512:tid 466740] [client 20.151.10.161:60688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/155.php"] [unique_id "al9aMCKGokixMSfKDOf8EQAAAnY"]
[Tue Jul 21 08:38:24.123171 2026] [security2:error] [pid 465652:tid 465895] [client 152.59.181.104:55323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aMDzTqJoBC2Mw28_UAAAAAPY"]
[Tue Jul 21 08:38:24.123317 2026] [security2:error] [pid 465652:tid 465895] [client 152.59.181.104:55323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aMDzTqJoBC2Mw28_UAAAAAPY"]
[Tue Jul 21 08:38:24.160940 2026] [security2:error] [pid 466512:tid 466704] [client 195.49.128.211:60194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aMCKGokixMSfKDOf8EgAAAlI"]
[Tue Jul 21 08:38:24.161064 2026] [security2:error] [pid 466512:tid 466704] [client 195.49.128.211:60194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aMCKGokixMSfKDOf8EgAAAlI"]
[Tue Jul 21 08:38:24.192393 2026] [security2:error] [pid 466512:tid 466710] [client 20.206.105.145:33791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/k.php"] [unique_id "al9aMCKGokixMSfKDOf8EwAAAlg"]
[Tue Jul 21 08:38:24.251619 2026] [security2:error] [pid 466512:tid 466697] [client 65.111.21.207:24729] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9aMCKGokixMSfKDOf8FAAAAks"]
[Tue Jul 21 08:38:24.334455 2026] [security2:error] [pid 466512:tid 466692] [client 152.59.34.51:58340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aMCKGokixMSfKDOf8FwAAAkY"]
[Tue Jul 21 08:38:24.334678 2026] [security2:error] [pid 466512:tid 466692] [client 152.59.34.51:58340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aMCKGokixMSfKDOf8FwAAAkY"]
[Tue Jul 21 08:38:24.411764 2026] [security2:error] [pid 465652:tid 465787] [client 198.44.157.34:34710] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9aMDzTqJoBC2Mw28_UBwAAAIo"]
[Tue Jul 21 08:38:24.411868 2026] [security2:error] [pid 465652:tid 465787] [client 198.44.157.34:34710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9aMDzTqJoBC2Mw28_UBwAAAIo"]
[Tue Jul 21 08:38:24.544320 2026] [security2:error] [pid 466512:tid 466713] [client 103.59.206.240:37047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aMCKGokixMSfKDOf8GwAAAls"]
[Tue Jul 21 08:38:24.544416 2026] [security2:error] [pid 466512:tid 466713] [client 103.59.206.240:37047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aMCKGokixMSfKDOf8GwAAAls"]
[Tue Jul 21 08:38:24.791663 2026] [security2:error] [pid 466512:tid 466684] [client 65.111.21.207:25553] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "clinicaleonazevedo.com.br"] [uri "/"] [unique_id "al9aMCKGokixMSfKDOf8HwAAAj4"]
[Tue Jul 21 08:38:25.059162 2026] [security2:error] [pid 466512:tid 466688] [client 65.111.21.207:25553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "clinicaleonazevedo.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9aMSKGokixMSfKDOf8JAAAAkI"]
[Tue Jul 21 08:38:25.202427 2026] [security2:error] [pid 466512:tid 466669] [client 49.144.66.253:33636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aMSKGokixMSfKDOf8KAAAAi8"]
[Tue Jul 21 08:38:25.202531 2026] [security2:error] [pid 466512:tid 466669] [client 49.144.66.253:33636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aMSKGokixMSfKDOf8KAAAAi8"]
[Tue Jul 21 08:38:25.203447 2026] [security2:error] [pid 466512:tid 466716] [client 20.151.10.161:60702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/ops.php"] [unique_id "al9aMSKGokixMSfKDOf8KQAAAl4"]
[Tue Jul 21 08:38:25.240224 2026] [security2:error] [pid 466512:tid 466675] [client 185.8.106.219:36026] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ocaminhodarecuperacao.com"] [uri "/"] [unique_id "al9aMSKGokixMSfKDOf8LgAAAjU"]
[Tue Jul 21 08:38:25.602246 2026] [security2:error] [pid 466512:tid 466759] [client 65.111.21.207:52503] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "clinicaleonazevedo.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9aMSKGokixMSfKDOf8NAAAAok"]
[Tue Jul 21 08:38:26.045714 2026] [security2:error] [pid 466512:tid 466718] [client 20.151.10.161:60793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/ingfo.php"] [unique_id "al9aMiKGokixMSfKDOf8OgAAAmA"]
[Tue Jul 21 08:38:26.101380 2026] [security2:error] [pid 466512:tid 466730] [client 20.220.225.223:40747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/nhvoanpl.php"] [unique_id "al9aMiKGokixMSfKDOf8PAAAAmw"]
[Tue Jul 21 08:38:26.137979 2026] [security2:error] [pid 466512:tid 466643] [client 65.111.21.207:35605] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "clinicaleonazevedo.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9aMiKGokixMSfKDOf8PQAAAhU"]
[Tue Jul 21 08:38:26.355739 2026] [security2:error] [pid 466512:tid 466711] [client 61.1.167.83:49697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aMiKGokixMSfKDOf8PwAAAlk"]
[Tue Jul 21 08:38:26.356021 2026] [security2:error] [pid 466512:tid 466711] [client 61.1.167.83:49697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aMiKGokixMSfKDOf8PwAAAlk"]
[Tue Jul 21 08:38:26.617754 2026] [autoindex:error] [pid 465652:tid 465858] [client 98.91.173.173:0] AH01276: Cannot serve directory /home3/dani2752/patriciarodrigues.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:38:26.683173 2026] [security2:error] [pid 465652:tid 465837] [client 65.111.21.207:26433] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9aMjzTqJoBC2Mw28_UNwAAALw"]
[Tue Jul 21 08:38:26.945627 2026] [security2:error] [pid 466512:tid 466619] [remote 210.211.113.135:57316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.113.211.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9aMiKGokixMSfKDOf8SwACSWo"]
[Tue Jul 21 08:38:27.080491 2026] [security2:error] [pid 465652:tid 465823] [client 20.226.60.151:58574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/mac.php"] [unique_id "al9aMzzTqJoBC2Mw28_UPAAAAK4"]
[Tue Jul 21 08:38:27.099247 2026] [security2:error] [pid 466512:tid 466698] [client 20.151.10.161:60789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/error_log.php"] [unique_id "al9aMyKGokixMSfKDOf8UQAAAkw"]
[Tue Jul 21 08:38:27.102909 2026] [security2:error] [pid 465652:tid 465809] [client 20.63.100.92:2204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/wp-wpbak.php"] [unique_id "al9aMzzTqJoBC2Mw28_UPgAAAKA"]
[Tue Jul 21 08:38:27.228994 2026] [security2:error] [pid 466512:tid 466754] [client 65.111.21.207:29807] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "clinicaleonazevedo.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9aMyKGokixMSfKDOf8VAAAAoQ"]
[Tue Jul 21 08:38:27.236326 2026] [security2:error] [pid 465652:tid 465822] [client 117.213.202.34:49875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aMzzTqJoBC2Mw28_UQQAAAK0"]
[Tue Jul 21 08:38:27.236425 2026] [security2:error] [pid 465652:tid 465822] [client 117.213.202.34:49875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aMzzTqJoBC2Mw28_UQQAAAK0"]
[Tue Jul 21 08:38:27.461551 2026] [security2:error] [pid 466512:tid 466555] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aMyKGokixMSfKDOf8WgACGio"]
[Tue Jul 21 08:38:27.461735 2026] [security2:error] [pid 466512:tid 466648] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aMyKGokixMSfKDOf8WgACGio"]
[Tue Jul 21 08:38:27.763030 2026] [security2:error] [pid 466512:tid 466665] [client 65.111.21.207:54387] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "clinicaleonazevedo.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9aMyKGokixMSfKDOf8YQAAAis"]
[Tue Jul 21 08:38:27.826179 2026] [security2:error] [pid 466512:tid 466704] [client 195.49.128.211:51967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aMyKGokixMSfKDOf8YwAAAlI"]
[Tue Jul 21 08:38:27.826326 2026] [security2:error] [pid 466512:tid 466704] [client 195.49.128.211:51967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aMyKGokixMSfKDOf8YwAAAlI"]
[Tue Jul 21 08:38:28.018834 2026] [security2:error] [pid 466512:tid 466654] [client 20.206.105.145:33736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/x.php"] [unique_id "al9aNCKGokixMSfKDOf8ZwAAAiA"]
[Tue Jul 21 08:38:28.266869 2026] [security2:error] [pid 466512:tid 466583] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aNCKGokixMSfKDOf8bgACgEY"]
[Tue Jul 21 08:38:28.267100 2026] [security2:error] [pid 466512:tid 466750] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aNCKGokixMSfKDOf8bgACgEY"]
[Tue Jul 21 08:38:28.287143 2026] [security2:error] [pid 466512:tid 466678] [client 20.151.10.161:60791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/ok.php"] [unique_id "al9aNCKGokixMSfKDOf8cQAAAjg"]
[Tue Jul 21 08:38:28.302958 2026] [security2:error] [pid 466512:tid 466709] [client 65.111.21.207:35809] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9aNCKGokixMSfKDOf8cwAAAlc"]
[Tue Jul 21 08:38:28.843487 2026] [security2:error] [pid 466512:tid 466672] [client 65.111.21.207:11337] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "clinicaleonazevedo.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9aNCKGokixMSfKDOf8fgAAAjI"]
[Tue Jul 21 08:38:29.145503 2026] [security2:error] [pid 466512:tid 466701] [client 74.249.245.134:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/dropdown.php"] [unique_id "al9aNSKGokixMSfKDOf8ggAAAk8"]
[Tue Jul 21 08:38:29.386540 2026] [security2:error] [pid 465652:tid 465818] [client 65.111.21.207:62179] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "clinicaleonazevedo.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9aNTzTqJoBC2Mw28_UZwAAAKk"]
[Tue Jul 21 08:38:29.551797 2026] [security2:error] [pid 465652:tid 465895] [client 20.151.10.161:60777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/mac.php"] [unique_id "al9aNTzTqJoBC2Mw28_UaQAAAPY"]
[Tue Jul 21 08:38:29.704685 2026] [security2:error] [pid 465652:tid 465813] [client 202.179.75.202:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aNTzTqJoBC2Mw28_UbwAAAKQ"]
[Tue Jul 21 08:38:29.704839 2026] [security2:error] [pid 465652:tid 465813] [client 202.179.75.202:55550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aNTzTqJoBC2Mw28_UbwAAAKQ"]
[Tue Jul 21 08:38:29.708046 2026] [security2:error] [pid 465652:tid 465832] [client 34.0.61.43:45298] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "learningsociety.com.br"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "al9aNTzTqJoBC2Mw28_UbgAAALc"]
[Tue Jul 21 08:38:29.944110 2026] [security2:error] [pid 466512:tid 466680] [client 65.111.21.207:64489] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "clinicaleonazevedo.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9aNSKGokixMSfKDOf8mAAAAjo"]
[Tue Jul 21 08:38:30.070324 2026] [security2:error] [pid 466512:tid 466716] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aNiKGokixMSfKDOf8mwACXgo"]
[Tue Jul 21 08:38:30.247415 2026] [security2:error] [pid 465652:tid 465848] [client 20.206.105.145:33743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wss.php"] [unique_id "al9aNjzTqJoBC2Mw28_UdgAAAMc"]
[Tue Jul 21 08:38:30.487890 2026] [security2:error] [pid 465652:tid 465817] [client 65.111.21.207:24687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "clinicaleonazevedo.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9aNjzTqJoBC2Mw28_UegAAAKg"]
[Tue Jul 21 08:38:30.693758 2026] [security2:error] [pid 465652:tid 465783] [client 34.0.61.43:45312] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "learningsociety.com.br"] [uri "/index.php"] [unique_id "al9aNjzTqJoBC2Mw28_UdQAAAIY"]
[Tue Jul 21 08:38:30.771308 2026] [security2:error] [pid 465652:tid 465834] [client 142.93.64.197:60036] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "162.241.63.71"] [uri "/"] [unique_id "al9aNjzTqJoBC2Mw28_UhgAAALk"]
[Tue Jul 21 08:38:30.799359 2026] [security2:error] [pid 465652:tid 465870] [client 216.244.66.247:40692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/imvel-cidade/jardins"] [unique_id "al9aNjzTqJoBC2Mw28_UhwAAAN0"]
[Tue Jul 21 08:38:30.799476 2026] [security2:error] [pid 465652:tid 465870] [client 216.244.66.247:40692] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "powerflats.com.br"] [uri "/imvel-cidade/jardins"] [unique_id "al9aNjzTqJoBC2Mw28_UhwAAAN0"]
[Tue Jul 21 08:38:30.838009 2026] [security2:error] [pid 465652:tid 465799] [client 20.63.100.92:7739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/dr.php"] [unique_id "al9aNjzTqJoBC2Mw28_UjAAAAJY"]
[Tue Jul 21 08:38:30.905511 2026] [security2:error] [pid 465652:tid 465810] [client 142.93.64.197:46812] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "162.241.63.71"] [uri "/"] [unique_id "al9aNjzTqJoBC2Mw28_UlAAAAKE"]
[Tue Jul 21 08:38:30.989904 2026] [security2:error] [pid 466512:tid 466689] [client 223.181.60.88:8096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aNiKGokixMSfKDOf8qgAAAkM"]
[Tue Jul 21 08:38:30.990150 2026] [security2:error] [pid 466512:tid 466689] [client 223.181.60.88:8096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aNiKGokixMSfKDOf8qgAAAkM"]
[Tue Jul 21 08:38:31.049777 2026] [security2:error] [pid 465652:tid 465901] [client 20.151.10.161:60684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wefile.php"] [unique_id "al9aNzzTqJoBC2Mw28_UlQAAAPw"]
[Tue Jul 21 08:38:31.329788 2026] [autoindex:error] [pid 466512:tid 466727] [client 34.178.75.226:0] AH01276: Cannot serve directory /home2/gus15895/screenfreeclub.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:38:31.401673 2026] [security2:error] [pid 466512:tid 466697] [client 74.249.245.134:50708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/wp-links.php"] [unique_id "al9aNyKGokixMSfKDOf8swAAAks"]
[Tue Jul 21 08:38:31.406162 2026] [security2:error] [pid 466512:tid 466685] [client 5.38.115.39:32414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aNyKGokixMSfKDOf8tAAAAj8"]
[Tue Jul 21 08:38:31.406308 2026] [security2:error] [pid 466512:tid 466685] [client 5.38.115.39:32414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aNyKGokixMSfKDOf8tAAAAj8"]
[Tue Jul 21 08:38:31.408554 2026] [security2:error] [pid 465652:tid 465854] [client 34.0.61.43:45312] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "learningsociety.com.br"] [uri "/index.php"] [unique_id "al9aNjzTqJoBC2Mw28_UhQAAAM0"]
[Tue Jul 21 08:38:31.523303 2026] [autoindex:error] [pid 466512:tid 466663] [client 34.178.75.226:0] AH01276: Cannot serve directory /home2/gus15895/screenfreeclub.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:38:31.531863 2026] [security2:error] [pid 465652:tid 465819] [client 34.0.61.43:45324] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "learningsociety.com.br"] [uri "/index.php"] [unique_id "al9aNjzTqJoBC2Mw28_UjwAAAKo"]
[Tue Jul 21 08:38:31.545119 2026] [security2:error] [pid 466512:tid 466692] [client 34.0.61.43:45330] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "learningsociety.com.br"] [uri "/index.php"] [unique_id "al9aNiKGokixMSfKDOf8pwAAAkY"]
[Tue Jul 21 08:38:31.562531 2026] [security2:error] [pid 465652:tid 465850] [client 34.0.61.43:45338] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "learningsociety.com.br"] [uri "/index.php"] [unique_id "al9aNjzTqJoBC2Mw28_UkAAAAMk"]
[Tue Jul 21 08:38:31.569498 2026] [security2:error] [pid 465652:tid 465789] [client 34.0.61.43:35990] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "learningsociety.com.br"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "al9aNzzTqJoBC2Mw28_UnAAAAIw"]
[Tue Jul 21 08:38:31.586087 2026] [security2:error] [pid 465652:tid 465804] [client 34.0.61.43:45312] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "learningsociety.com.br"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "al9aNzzTqJoBC2Mw28_UnQAAAJs"]
[Tue Jul 21 08:38:31.587253 2026] [security2:error] [pid 465652:tid 465905] [client 34.0.61.43:45344] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "learningsociety.com.br"] [uri "/index.php"] [unique_id "al9aNjzTqJoBC2Mw28_UkgAAAQA"]
[Tue Jul 21 08:38:31.603297 2026] [security2:error] [pid 465652:tid 465812] [client 34.0.61.43:45324] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "learningsociety.com.br"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "al9aNzzTqJoBC2Mw28_UngAAAKM"]
[Tue Jul 21 08:38:31.617345 2026] [security2:error] [pid 466512:tid 466703] [client 34.0.61.43:45330] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "learningsociety.com.br"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "al9aNyKGokixMSfKDOf8uQAAAlE"]
[Tue Jul 21 08:38:31.617409 2026] [security2:error] [pid 466512:tid 466707] [client 34.0.61.43:45342] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "learningsociety.com.br"] [uri "/index.php"] [unique_id "al9aNiKGokixMSfKDOf8pgAAAlU"]
[Tue Jul 21 08:38:31.641788 2026] [security2:error] [pid 465652:tid 465863] [client 34.0.61.43:45338] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "learningsociety.com.br"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "al9aNzzTqJoBC2Mw28_UnwAAANY"]
[Tue Jul 21 08:38:31.645475 2026] [security2:error] [pid 465652:tid 465824] [client 20.151.10.161:60678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9aNzzTqJoBC2Mw28_UoAAAAK8"]
[Tue Jul 21 08:38:31.674900 2026] [security2:error] [pid 465652:tid 465816] [client 34.0.61.43:45312] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "learningsociety.com.br"] [uri "/wp-content/endurance-page-cache/_index.html"] [unique_id "al9aNzzTqJoBC2Mw28_UoQAAAKc"]
[Tue Jul 21 08:38:31.709288 2026] [security2:error] [pid 466512:tid 466646] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9aNyKGokixMSfKDOf8ugAAAhg"]
[Tue Jul 21 08:38:32.083360 2026] [security2:error] [pid 466512:tid 466702] [client 34.178.75.226:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.75.178.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aOCKGokixMSfKDOf8wgAAAlA"]
[Tue Jul 21 08:38:32.237707 2026] [security2:error] [pid 466512:tid 466657] [client 59.95.197.55:54800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aOCKGokixMSfKDOf8yAAAAiM"]
[Tue Jul 21 08:38:32.237805 2026] [security2:error] [pid 466512:tid 466657] [client 59.95.197.55:54800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aOCKGokixMSfKDOf8yAAAAiM"]
[Tue Jul 21 08:38:32.445839 2026] [autoindex:error] [pid 466512:tid 466749] [client 34.178.75.226:0] AH01276: Cannot serve directory /home2/gus15895/screenfreeclub.shop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:38:32.537723 2026] [security2:error] [pid 466512:tid 466746] [client 20.151.10.161:60768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9aOCKGokixMSfKDOf8zwAAAnw"]
[Tue Jul 21 08:38:32.656238 2026] [security2:error] [pid 466512:tid 466616] [remote 18.61.192.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-login.php"] [unique_id "al9aOCKGokixMSfKDOf80AACSGc"]
[Tue Jul 21 08:38:32.657427 2026] [security2:error] [pid 466512:tid 466682] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9aOCKGokixMSfKDOf80QAAAjw"]
[Tue Jul 21 08:38:33.010423 2026] [security2:error] [pid 466512:tid 466663] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9aOSKGokixMSfKDOf81wAAAik"]
[Tue Jul 21 08:38:33.142572 2026] [security2:error] [pid 466512:tid 466732] [client 14.245.224.124:56371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aOSKGokixMSfKDOf82gAAAm4"]
[Tue Jul 21 08:38:33.142666 2026] [security2:error] [pid 466512:tid 466732] [client 14.245.224.124:56371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aOSKGokixMSfKDOf82gAAAm4"]
[Tue Jul 21 08:38:33.291791 2026] [security2:error] [pid 465652:tid 465856] [client 20.206.105.145:33756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/ty.php"] [unique_id "al9aOTzTqJoBC2Mw28_UtAAAAM8"]
[Tue Jul 21 08:38:33.299137 2026] [security2:error] [pid 466512:tid 466661] [client 20.151.10.161:60701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/like.php"] [unique_id "al9aOSKGokixMSfKDOf82wAAAic"]
[Tue Jul 21 08:38:33.350982 2026] [security2:error] [pid 466512:tid 466709] [client 122.176.100.127:54488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aOSKGokixMSfKDOf83QAAAlc"]
[Tue Jul 21 08:38:33.351254 2026] [security2:error] [pid 466512:tid 466709] [client 122.176.100.127:54488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aOSKGokixMSfKDOf83QAAAlc"]
[Tue Jul 21 08:38:33.369661 2026] [security2:error] [pid 466512:tid 466665] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9aOSKGokixMSfKDOf83gAAAis"]
[Tue Jul 21 08:38:33.715146 2026] [security2:error] [pid 466512:tid 466692] [client 5.31.193.106:1820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aOSKGokixMSfKDOf85QAAAkY"]
[Tue Jul 21 08:38:33.718350 2026] [security2:error] [pid 466512:tid 466692] [client 5.31.193.106:1820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aOSKGokixMSfKDOf85QAAAkY"]
[Tue Jul 21 08:38:33.724549 2026] [security2:error] [pid 466512:tid 466705] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9aOSKGokixMSfKDOf85wAAAlM"]
[Tue Jul 21 08:38:33.985833 2026] [security2:error] [pid 465652:tid 465857] [client 20.151.10.161:60731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/.well-known/about.php"] [unique_id "al9aOTzTqJoBC2Mw28_UwgAAANA"]
[Tue Jul 21 08:38:34.128924 2026] [security2:error] [pid 466512:tid 466675] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9aOiKGokixMSfKDOf86wAAAjU"]
[Tue Jul 21 08:38:34.405222 2026] [security2:error] [pid 466512:tid 466695] [client 20.151.10.161:57549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9aOiKGokixMSfKDOf89AAAAkk"]
[Tue Jul 21 08:38:34.482181 2026] [security2:error] [pid 466512:tid 466706] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9aOiKGokixMSfKDOf89QAAAlQ"]
[Tue Jul 21 08:38:34.778616 2026] [security2:error] [pid 465652:tid 465782] [client 152.59.181.104:55777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aOjzTqJoBC2Mw28_U1AAAAIU"]
[Tue Jul 21 08:38:34.778742 2026] [security2:error] [pid 465652:tid 465782] [client 152.59.181.104:55777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aOjzTqJoBC2Mw28_U1AAAAIU"]
[Tue Jul 21 08:38:34.806034 2026] [security2:error] [pid 466512:tid 466733] [client 152.59.34.51:64402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aOiKGokixMSfKDOf8-wAAAm8"]
[Tue Jul 21 08:38:34.806179 2026] [security2:error] [pid 466512:tid 466733] [client 152.59.34.51:64402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aOiKGokixMSfKDOf8-wAAAm8"]
[Tue Jul 21 08:38:34.836666 2026] [security2:error] [pid 465652:tid 465804] [client 195.49.128.211:60798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aOjzTqJoBC2Mw28_U1gAAAJs"]
[Tue Jul 21 08:38:34.836837 2026] [security2:error] [pid 465652:tid 465804] [client 195.49.128.211:60798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aOjzTqJoBC2Mw28_U1gAAAJs"]
[Tue Jul 21 08:38:34.840244 2026] [security2:error] [pid 466512:tid 466649] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9aOiKGokixMSfKDOf8_wAAAhs"]
[Tue Jul 21 08:38:35.207576 2026] [security2:error] [pid 466512:tid 466650] [client 103.59.206.240:31186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aOyKGokixMSfKDOf9DwAAAhw"]
[Tue Jul 21 08:38:35.207688 2026] [security2:error] [pid 466512:tid 466650] [client 103.59.206.240:31186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aOyKGokixMSfKDOf9DwAAAhw"]
[Tue Jul 21 08:38:35.209488 2026] [security2:error] [pid 466512:tid 466552] [remote 162.19.246.208:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-login.php"] [unique_id "al9aOiKGokixMSfKDOf87AACaCc"]
[Tue Jul 21 08:38:35.209789 2026] [security2:error] [pid 466512:tid 466711] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9aOyKGokixMSfKDOf9EAAAAlk"]
[Tue Jul 21 08:38:35.251801 2026] [security2:error] [pid 466512:tid 466769] [client 20.151.10.161:57553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/pucci.php"] [unique_id "al9aOyKGokixMSfKDOf9EgAAApM"]
[Tue Jul 21 08:38:35.565640 2026] [security2:error] [pid 466512:tid 466685] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9aOyKGokixMSfKDOf9FwAAAj8"]
[Tue Jul 21 08:38:35.630100 2026] [security2:error] [pid 465652:tid 465885] [client 20.206.105.145:33764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/155.php"] [unique_id "al9aOzzTqJoBC2Mw28_U4AAAAOw"]
[Tue Jul 21 08:38:35.922804 2026] [security2:error] [pid 465652:tid 465787] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9aOzzTqJoBC2Mw28_U6QAAAIo"]
[Tue Jul 21 08:38:36.028327 2026] [security2:error] [pid 466512:tid 466764] [client 49.144.66.253:33780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aPCKGokixMSfKDOf9HwAAAo4"]
[Tue Jul 21 08:38:36.028479 2026] [security2:error] [pid 466512:tid 466764] [client 49.144.66.253:33780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aPCKGokixMSfKDOf9HwAAAo4"]
[Tue Jul 21 08:38:36.356108 2026] [security2:error] [pid 466512:tid 466714] [client 20.151.10.161:60778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wp-temp.php"] [unique_id "al9aPCKGokixMSfKDOf9JwAAAlw"]
[Tue Jul 21 08:38:36.746045 2026] [security2:error] [pid 466512:tid 466735] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9aPCKGokixMSfKDOf9MAAAAnE"]
[Tue Jul 21 08:38:37.099686 2026] [security2:error] [pid 466512:tid 466763] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9aPSKGokixMSfKDOf9NwAAAo0"]
[Tue Jul 21 08:38:37.171085 2026] [security2:error] [pid 466512:tid 466614] [remote 45.94.31.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9aPSKGokixMSfKDOf9OQACaWU"], referer: www.google.com
[Tue Jul 21 08:38:37.176498 2026] [security2:error] [pid 466512:tid 466515] [remote 45.94.31.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9aPSKGokixMSfKDOf9PQAChgI"]
[Tue Jul 21 08:38:37.236847 2026] [security2:error] [pid 465652:tid 465874] [client 20.226.60.151:58577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/mg.php"] [unique_id "al9aPTzTqJoBC2Mw28_U_gAAAOE"]
[Tue Jul 21 08:38:37.251344 2026] [security2:error] [pid 465652:tid 465815] [client 20.151.10.161:57563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/xmu.php"] [unique_id "al9aPTzTqJoBC2Mw28_U_wAAAKY"]
[Tue Jul 21 08:38:37.337964 2026] [security2:error] [pid 466512:tid 466577] [remote 45.94.31.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/wp-plain.php"] [unique_id "al9aPSKGokixMSfKDOf9PAACKUA"], referer: www.google.com
[Tue Jul 21 08:38:37.452652 2026] [security2:error] [pid 466512:tid 466764] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9aPSKGokixMSfKDOf9QQAAAo4"]
[Tue Jul 21 08:38:37.474333 2026] [security2:error] [pid 466512:tid 466638] [remote 45.94.31.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "al9aPSKGokixMSfKDOf9QgACS30"]
[Tue Jul 21 08:38:37.657282 2026] [security2:error] [pid 466512:tid 466576] [remote 45.94.31.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al9aPSKGokixMSfKDOf9SQACfj8"]
[Tue Jul 21 08:38:37.692157 2026] [security2:error] [pid 466512:tid 466608] [remote 45.94.31.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9aPSKGokixMSfKDOf9SgACWl8"], referer: www.google.com
[Tue Jul 21 08:38:37.803940 2026] [security2:error] [pid 465652:tid 465873] [client 20.151.10.161:60711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9aPTzTqJoBC2Mw28_VBwAAAOA"]
[Tue Jul 21 08:38:37.807398 2026] [security2:error] [pid 466512:tid 466662] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9aPSKGokixMSfKDOf9TAAAAig"]
[Tue Jul 21 08:38:37.869052 2026] [security2:error] [pid 465652:tid 465673] [remote 45.94.31.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/udukiubo.php"] [unique_id "al9aPTzTqJoBC2Mw28_VCQAAvRQ"], referer: www.google.com
[Tue Jul 21 08:38:38.059890 2026] [security2:error] [pid 465652:tid 465702] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aPjzTqJoBC2Mw28_VDQAAnTE"]
[Tue Jul 21 08:38:38.060033 2026] [security2:error] [pid 465652:tid 465806] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aPjzTqJoBC2Mw28_VDQAAnTE"]
[Tue Jul 21 08:38:38.085945 2026] [security2:error] [pid 466512:tid 466703] [client 117.213.202.34:50475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aPiKGokixMSfKDOf9UAAAAlE"]
[Tue Jul 21 08:38:38.086127 2026] [security2:error] [pid 466512:tid 466703] [client 117.213.202.34:50475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aPiKGokixMSfKDOf9UAAAAlE"]
[Tue Jul 21 08:38:38.163858 2026] [security2:error] [pid 466512:tid 466683] [client 34.178.75.226:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "screenfreeclub.shop.gustavosantosabreu1782388156433.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9aPiKGokixMSfKDOf9UgAAAj0"]
[Tue Jul 21 08:38:38.176804 2026] [security2:error] [pid 466512:tid 466553] [remote 45.94.31.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "al9aPiKGokixMSfKDOf9VAACUCg"]
[Tue Jul 21 08:38:38.361058 2026] [security2:error] [pid 466512:tid 466730] [client 20.151.10.161:57542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/puc.php"] [unique_id "al9aPiKGokixMSfKDOf9VgAAAmw"]
[Tue Jul 21 08:38:38.497305 2026] [security2:error] [pid 465652:tid 465786] [client 195.49.128.211:52572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aPjzTqJoBC2Mw28_VFQAAAIk"]
[Tue Jul 21 08:38:38.497416 2026] [security2:error] [pid 465652:tid 465786] [client 195.49.128.211:52572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aPjzTqJoBC2Mw28_VFQAAAIk"]
[Tue Jul 21 08:38:38.696236 2026] [security2:error] [pid 466512:tid 466599] [remote 45.94.31.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.31.94.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "academiausina.com.br"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "al9aPiKGokixMSfKDOf9XAACXlY"]
[Tue Jul 21 08:38:38.775543 2026] [security2:error] [pid 465652:tid 465837] [client 20.151.10.161:60706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/themes.php"] [unique_id "al9aPjzTqJoBC2Mw28_VHwAAALw"]
[Tue Jul 21 08:38:38.823346 2026] [security2:error] [pid 465652:tid 465810] [client 114.119.152.161:48441] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dantonio.com.br"] [uri "/"] [unique_id "al9aPjzTqJoBC2Mw28_VJAAAAKE"], referer: http://www.lokaliza.com.br/empresas/pecaseacessorios.htm
[Tue Jul 21 08:38:38.913801 2026] [security2:error] [pid 466512:tid 466558] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aPiKGokixMSfKDOf9XgACaS0"]
[Tue Jul 21 08:38:38.913945 2026] [security2:error] [pid 466512:tid 466727] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aPiKGokixMSfKDOf9XgACaS0"]
[Tue Jul 21 08:38:39.057906 2026] [security2:error] [pid 466512:tid 466690] [client 20.220.225.223:2395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/inso.php"] [unique_id "al9aPyKGokixMSfKDOf9YwAAAkQ"]
[Tue Jul 21 08:38:39.242358 2026] [security2:error] [pid 466512:tid 466647] [client 20.63.100.92:6888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/2x.php"] [unique_id "al9aPyKGokixMSfKDOf9bQAAAhk"]
[Tue Jul 21 08:38:39.307519 2026] [security2:error] [pid 466512:tid 466688] [client 20.151.10.161:60761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/8.php"] [unique_id "al9aPyKGokixMSfKDOf9bgAAAkI"]
[Tue Jul 21 08:38:39.562739 2026] [security2:error] [pid 466512:tid 466760] [client 51.68.111.215:32927] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "eduflow.com.br"] [uri "/robots.txt"] [unique_id "al9aPyKGokixMSfKDOf9dAAAAoo"]
[Tue Jul 21 08:38:39.562882 2026] [security2:error] [pid 466512:tid 466760] [client 51.68.111.215:32927] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "eduflow.com.br"] [uri "/robots.txt"] [unique_id "al9aPyKGokixMSfKDOf9dAAAAoo"]
[Tue Jul 21 08:38:39.658151 2026] [security2:error] [pid 466512:tid 466762] [client 20.151.10.161:60709] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "crm.lupipet.com.br"] [uri "/1.php"] [unique_id "al9aPyKGokixMSfKDOf9dwAAAow"]
[Tue Jul 21 08:38:39.658289 2026] [security2:error] [pid 466512:tid 466762] [client 20.151.10.161:60709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/1.php"] [unique_id "al9aPyKGokixMSfKDOf9dwAAAow"]
[Tue Jul 21 08:38:39.827629 2026] [autoindex:error] [pid 466512:tid 466702] [client 184.154.139.38:41296] AH01276: Cannot serve directory /home1/taina869/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.google.com/url?url=tainaracamara.adv.br&yahoo.com
[Tue Jul 21 08:38:39.873943 2026] [security2:error] [pid 465652:tid 465856] [client 74.249.245.134:20442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/xmrlpc.php"] [unique_id "al9aPzzTqJoBC2Mw28_VLgAAAM8"]
[Tue Jul 21 08:38:40.167580 2026] [security2:error] [pid 466512:tid 466665] [client 20.151.10.161:60757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/100.php"] [unique_id "al9aQCKGokixMSfKDOf9ggAAAis"]
[Tue Jul 21 08:38:40.184260 2026] [security2:error] [pid 466512:tid 466674] [client 20.206.105.145:33670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/ops.php"] [unique_id "al9aQCKGokixMSfKDOf9gwAAAjQ"]
[Tue Jul 21 08:38:40.689721 2026] [security2:error] [pid 466512:tid 466680] [client 20.151.10.161:60703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/about.php"] [unique_id "al9aQCKGokixMSfKDOf9iwAAAjo"]
[Tue Jul 21 08:38:40.752132 2026] [security2:error] [pid 466512:tid 466700] [client 202.179.75.202:48276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aQCKGokixMSfKDOf9jQAAAk4"]
[Tue Jul 21 08:38:40.752240 2026] [security2:error] [pid 466512:tid 466700] [client 202.179.75.202:48276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aQCKGokixMSfKDOf9jQAAAk4"]
[Tue Jul 21 08:38:40.778802 2026] [security2:error] [pid 466512:tid 466727] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aQCKGokixMSfKDOf9jAACaSo"]
[Tue Jul 21 08:38:40.904028 2026] [security2:error] [pid 465652:tid 465862] [client 184.154.139.38:41898] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "tainaracamara.adv.br"] [uri "/cgi-sys/404.html"] [unique_id "al9aQDzTqJoBC2Mw28_VRQAAANU"]
[Tue Jul 21 08:38:41.132561 2026] [security2:error] [pid 465652:tid 465798] [client 20.151.10.161:60677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/about.php"] [unique_id "al9aQTzTqJoBC2Mw28_VSQAAAJU"]
[Tue Jul 21 08:38:41.192581 2026] [security2:error] [pid 465652:tid 465891] [client 184.154.139.38:42044] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tainaracamara.adv.br"] [uri "/cgi-sys/css/custom_404.css"] [unique_id "al9aQTzTqJoBC2Mw28_VTgAAAPI"]
[Tue Jul 21 08:38:41.673284 2026] [security2:error] [pid 465652:tid 465813] [client 20.151.10.161:60738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/admin.php"] [unique_id "al9aQTzTqJoBC2Mw28_VWgAAAKQ"]
[Tue Jul 21 08:38:41.815862 2026] [security2:error] [pid 465652:tid 465861] [client 223.181.60.88:4572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aQTzTqJoBC2Mw28_VXQAAANQ"]
[Tue Jul 21 08:38:41.816052 2026] [security2:error] [pid 465652:tid 465861] [client 223.181.60.88:4572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aQTzTqJoBC2Mw28_VXQAAANQ"]
[Tue Jul 21 08:38:42.052548 2026] [security2:error] [pid 466512:tid 466754] [client 5.38.115.39:65238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aQiKGokixMSfKDOf9ngAAAoQ"]
[Tue Jul 21 08:38:42.052647 2026] [security2:error] [pid 466512:tid 466754] [client 5.38.115.39:65238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aQiKGokixMSfKDOf9ngAAAoQ"]
[Tue Jul 21 08:38:42.234550 2026] [security2:error] [pid 466512:tid 466751] [client 20.151.10.161:60692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/admin.php"] [unique_id "al9aQiKGokixMSfKDOf9ogAAAoE"]
[Tue Jul 21 08:38:42.255900 2026] [access_compat:error] [pid 466512:tid 466716] [client 40.77.167.45:0] AH01797: client denied by server configuration: /home4/fabi0417/powerflats.com.br/index.php4
[Tue Jul 21 08:38:42.286080 2026] [security2:error] [pid 466512:tid 466686] [client 184.154.139.38:42622] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tainaracamara.adv.br"] [uri "/cgi-sys/css/bootstrap.min.css"] [unique_id "al9aQiKGokixMSfKDOf9pQAAAkA"]
[Tue Jul 21 08:38:42.340108 2026] [security2:error] [pid 466512:tid 466627] [remote 45.117.83.212:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "annaguimaraes.com.br"] [uri "/wp-login.php"] [unique_id "al9aQiKGokixMSfKDOf9pwACj3I"]
[Tue Jul 21 08:38:42.491370 2026] [autoindex:error] [pid 466512:tid 466764] [client 49.51.195.195:51188] AH01276: Cannot serve directory /home1/asse7722/comecx.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:38:42.582132 2026] [autoindex:error] [pid 465652:tid 465828] [client 184.154.139.38:42808] AH01276: Cannot serve directory /home1/taina869/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:38:42.582585 2026] [security2:error] [pid 465652:tid 465828] [client 184.154.139.38:42808] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "403"] [hostname "tainaracamara.adv.br"] [uri "/cgi-sys/403.html"] [unique_id "al9aQjzTqJoBC2Mw28_VaQAAALM"]
[Tue Jul 21 08:38:42.676555 2026] [security2:error] [pid 466512:tid 466745] [client 198.44.157.34:50522] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9aQiKGokixMSfKDOf9qwAAAns"]
[Tue Jul 21 08:38:42.676660 2026] [security2:error] [pid 466512:tid 466745] [client 198.44.157.34:50522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9aQiKGokixMSfKDOf9qwAAAns"]
[Tue Jul 21 08:38:42.721903 2026] [security2:error] [pid 466512:tid 466649] [client 59.95.197.55:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aQiKGokixMSfKDOf9rwAAAhs"]
[Tue Jul 21 08:38:42.722662 2026] [security2:error] [pid 466512:tid 466649] [client 59.95.197.55:55240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aQiKGokixMSfKDOf9rwAAAhs"]
[Tue Jul 21 08:38:42.874386 2026] [security2:error] [pid 466512:tid 466719] [client 20.206.105.145:33770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/ingfo.php"] [unique_id "al9aQiKGokixMSfKDOf9swAAAmE"]
[Tue Jul 21 08:38:42.968241 2026] [security2:error] [pid 465652:tid 465784] [client 65.21.113.253:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aQjzTqJoBC2Mw28_VZgAAAIc"]
[Tue Jul 21 08:38:43.029242 2026] [security2:error] [pid 466512:tid 466763] [client 184.154.139.38:43052] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "tainaracamara.adv.br"] [uri "/cgi-sys/404.html"] [unique_id "al9aQyKGokixMSfKDOf9tQAAAo0"]
[Tue Jul 21 08:38:43.220971 2026] [security2:error] [pid 466512:tid 466676] [client 20.151.10.161:60765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/edit.php"] [unique_id "al9aQyKGokixMSfKDOf9uAAAAjY"]
[Tue Jul 21 08:38:43.352459 2026] [security2:error] [pid 466512:tid 466678] [client 61.1.167.83:50351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aQyKGokixMSfKDOf9ugAAAjg"]
[Tue Jul 21 08:38:43.352620 2026] [security2:error] [pid 466512:tid 466678] [client 61.1.167.83:50351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aQyKGokixMSfKDOf9ugAAAjg"]
[Tue Jul 21 08:38:43.804717 2026] [security2:error] [pid 466512:tid 466646] [client 20.220.225.223:46947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wpx.php"] [unique_id "al9aQyKGokixMSfKDOf9vAAAAhg"]
[Tue Jul 21 08:38:43.878663 2026] [security2:error] [pid 466512:tid 466765] [client 122.176.100.127:55082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aQyKGokixMSfKDOf9vgAAAo8"]
[Tue Jul 21 08:38:43.878948 2026] [security2:error] [pid 466512:tid 466765] [client 122.176.100.127:55082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aQyKGokixMSfKDOf9vgAAAo8"]
[Tue Jul 21 08:38:43.943335 2026] [security2:error] [pid 466512:tid 466727] [client 14.245.224.124:56852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aQyKGokixMSfKDOf9vwAAAmk"]
[Tue Jul 21 08:38:43.943421 2026] [security2:error] [pid 466512:tid 466727] [client 14.245.224.124:56852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aQyKGokixMSfKDOf9vwAAAmk"]
[Tue Jul 21 08:38:44.043195 2026] [security2:error] [pid 466512:tid 466717] [client 20.206.105.145:33751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/error_log.php"] [unique_id "al9aRCKGokixMSfKDOf9wAAAAl8"]
[Tue Jul 21 08:38:44.058254 2026] [security2:error] [pid 466512:tid 466663] [client 20.151.10.161:60696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9aRCKGokixMSfKDOf9wQAAAik"]
[Tue Jul 21 08:38:44.717992 2026] [security2:error] [pid 465652:tid 465804] [client 20.206.105.145:33780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/ok.php"] [unique_id "al9aRDzTqJoBC2Mw28_VkAAAAJs"]
[Tue Jul 21 08:38:44.831670 2026] [security2:error] [pid 465652:tid 465732] [remote 167.71.218.184:33474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9aRDzTqJoBC2Mw28_VlAAA7E8"]
[Tue Jul 21 08:38:45.119462 2026] [security2:error] [pid 466512:tid 466523] [remote 216.73.216.184:49002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapd.xml"] [unique_id "al9aRSKGokixMSfKDOf91wACUgo"]
[Tue Jul 21 08:38:45.306438 2026] [security2:error] [pid 465652:tid 465782] [client 65.21.113.253:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aRDzTqJoBC2Mw28_VkwAAAIU"]
[Tue Jul 21 08:38:45.393225 2026] [security2:error] [pid 466512:tid 466747] [client 152.59.181.104:56223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aRSKGokixMSfKDOf92gAAAn0"]
[Tue Jul 21 08:38:45.397941 2026] [security2:error] [pid 466512:tid 466747] [client 152.59.181.104:56223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aRSKGokixMSfKDOf92gAAAn0"]
[Tue Jul 21 08:38:45.490675 2026] [security2:error] [pid 466512:tid 466657] [client 195.49.128.211:61402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aRSKGokixMSfKDOf93wAAAiM"]
[Tue Jul 21 08:38:45.490777 2026] [security2:error] [pid 466512:tid 466657] [client 195.49.128.211:61402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aRSKGokixMSfKDOf93wAAAiM"]
[Tue Jul 21 08:38:45.497160 2026] [security2:error] [pid 465652:tid 465868] [client 20.206.105.145:33675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/mac.php"] [unique_id "al9aRTzTqJoBC2Mw28_VmwAAANs"]
[Tue Jul 21 08:38:45.633326 2026] [security2:error] [pid 466512:tid 466762] [client 20.63.100.92:2220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/kq1.php"] [unique_id "al9aRSKGokixMSfKDOf95AAAAow"]
[Tue Jul 21 08:38:45.652726 2026] [security2:error] [pid 465652:tid 465861] [client 69.171.230.23:35230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9aRTzTqJoBC2Mw28_VmgAAANQ"]
[Tue Jul 21 08:38:46.485086 2026] [security2:error] [pid 466512:tid 466704] [client 20.206.105.145:33755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wefile.php"] [unique_id "al9aRiKGokixMSfKDOf98AAAAlI"]
[Tue Jul 21 08:38:46.535021 2026] [security2:error] [pid 465652:tid 465859] [client 69.171.230.2:49790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9aRjzTqJoBC2Mw28_VrAAAANI"]
[Tue Jul 21 08:38:46.654926 2026] [security2:error] [pid 466512:tid 466761] [client 152.59.34.51:59299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aRiKGokixMSfKDOf99AAAAos"]
[Tue Jul 21 08:38:46.655044 2026] [security2:error] [pid 466512:tid 466761] [client 152.59.34.51:59299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aRiKGokixMSfKDOf99AAAAos"]
[Tue Jul 21 08:38:46.924078 2026] [security2:error] [pid 465652:tid 465821] [client 20.151.10.161:60736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/f6.php"] [unique_id "al9aRjzTqJoBC2Mw28_VsgAAAKw"]
[Tue Jul 21 08:38:47.002804 2026] [security2:error] [pid 466512:tid 466763] [client 20.220.225.223:2381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/berlin.php"] [unique_id "al9aRyKGokixMSfKDOf-AAAAAo0"]
[Tue Jul 21 08:38:47.112809 2026] [security2:error] [pid 466512:tid 466738] [client 74.249.245.134:32617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/htaccess.php"] [unique_id "al9aRyKGokixMSfKDOf-AQAAAnQ"]
[Tue Jul 21 08:38:47.147194 2026] [security2:error] [pid 465652:tid 465870] [client 65.21.113.253:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aRjzTqJoBC2Mw28_VrwAAAN0"]
[Tue Jul 21 08:38:47.307046 2026] [security2:error] [pid 466512:tid 466768] [client 49.144.66.253:29811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aRyKGokixMSfKDOf-BQAAApI"]
[Tue Jul 21 08:38:47.307397 2026] [security2:error] [pid 466512:tid 466768] [client 49.144.66.253:29811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aRyKGokixMSfKDOf-BQAAApI"]
[Tue Jul 21 08:38:47.525765 2026] [security2:error] [pid 465652:tid 465802] [client 20.206.105.145:33779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9aRzzTqJoBC2Mw28_VuQAAAJk"]
[Tue Jul 21 08:38:47.544932 2026] [security2:error] [pid 466512:tid 466562] [remote 216.73.217.12:25066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "companhiatop.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aRyKGokixMSfKDOf-AgACKzE"]
[Tue Jul 21 08:38:47.600053 2026] [security2:error] [pid 466512:tid 466722] [client 20.63.100.92:7696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/zzz.php"] [unique_id "al9aRyKGokixMSfKDOf-DwAAAmQ"]
[Tue Jul 21 08:38:47.915036 2026] [security2:error] [pid 466512:tid 466697] [client 64.42.179.43:33480] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9aRyKGokixMSfKDOf-FwAAAks"]
[Tue Jul 21 08:38:47.915139 2026] [security2:error] [pid 466512:tid 466697] [client 64.42.179.43:33480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9aRyKGokixMSfKDOf-FwAAAks"]
[Tue Jul 21 08:38:48.072383 2026] [security2:error] [pid 466512:tid 466745] [client 213.152.162.15:55000] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aSCKGokixMSfKDOf-HQAAAns"]
[Tue Jul 21 08:38:48.072494 2026] [security2:error] [pid 466512:tid 466745] [client 213.152.162.15:55000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aSCKGokixMSfKDOf-HQAAAns"]
[Tue Jul 21 08:38:48.587303 2026] [security2:error] [pid 465652:tid 465843] [client 117.213.202.34:51078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aSDzTqJoBC2Mw28_VxwAAAMI"]
[Tue Jul 21 08:38:48.587414 2026] [security2:error] [pid 465652:tid 465843] [client 117.213.202.34:51078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aSDzTqJoBC2Mw28_VxwAAAMI"]
[Tue Jul 21 08:38:48.635187 2026] [security2:error] [pid 466512:tid 466581] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aSCKGokixMSfKDOf-JQACI0Q"]
[Tue Jul 21 08:38:48.635330 2026] [security2:error] [pid 466512:tid 466657] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aSCKGokixMSfKDOf-JQACI0Q"]
[Tue Jul 21 08:38:48.688420 2026] [security2:error] [pid 466512:tid 466738] [client 64.42.179.43:34612] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9aSCKGokixMSfKDOf-JgAAAnQ"]
[Tue Jul 21 08:38:48.688528 2026] [security2:error] [pid 466512:tid 466738] [client 64.42.179.43:34612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9aSCKGokixMSfKDOf-JgAAAnQ"]
[Tue Jul 21 08:38:48.956011 2026] [security2:error] [pid 465652:tid 465885] [client 65.21.113.253:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aSDzTqJoBC2Mw28_VxAAAAOw"]
[Tue Jul 21 08:38:49.115249 2026] [proxy:error] [pid 466512:tid 466670] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:38:49.115327 2026] [proxy_http:error] [pid 466512:tid 466670] [client 143.198.153.179:55782] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:38:49.115826 2026] [proxy:error] [pid 466512:tid 466670] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:38:49.115852 2026] [proxy_http:error] [pid 466512:tid 466670] [client 143.198.153.179:55782] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:38:49.150110 2026] [security2:error] [pid 465652:tid 465832] [client 195.49.128.211:53174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aSTzTqJoBC2Mw28_V1AAAALc"]
[Tue Jul 21 08:38:49.150211 2026] [security2:error] [pid 465652:tid 465832] [client 195.49.128.211:53174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aSTzTqJoBC2Mw28_V1AAAALc"]
[Tue Jul 21 08:38:49.363553 2026] [security2:error] [pid 466512:tid 466756] [client 20.151.10.161:60762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/inputs.php"] [unique_id "al9aSSKGokixMSfKDOf-MgAAAoY"]
[Tue Jul 21 08:38:49.494192 2026] [proxy:error] [pid 465652:tid 465853] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:38:49.494280 2026] [proxy_http:error] [pid 465652:tid 465853] [client 143.198.153.179:55784] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.limetteodontologia.com.br/
[Tue Jul 21 08:38:49.495577 2026] [proxy:error] [pid 465652:tid 465853] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:38:49.495640 2026] [proxy_http:error] [pid 465652:tid 465853] [client 143.198.153.179:55784] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.limetteodontologia.com.br/
[Tue Jul 21 08:38:49.765496 2026] [security2:error] [pid 465652:tid 465692] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aSTzTqJoBC2Mw28_V3QABASc"]
[Tue Jul 21 08:38:49.765700 2026] [security2:error] [pid 465652:tid 465906] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aSTzTqJoBC2Mw28_V3QABASc"]
[Tue Jul 21 08:38:49.885076 2026] [security2:error] [pid 466512:tid 466650] [client 173.252.95.37:53884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9aRyKGokixMSfKDOf-FgAAAhw"]
[Tue Jul 21 08:38:49.897843 2026] [security2:error] [pid 465652:tid 465844] [client 20.220.225.223:2410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/billur.php"] [unique_id "al9aSTzTqJoBC2Mw28_V4QAAAMM"]
[Tue Jul 21 08:38:50.022161 2026] [security2:error] [pid 466512:tid 466568] [remote 57.141.18.106:42404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9aSSKGokixMSfKDOf-KwACajc"]
[Tue Jul 21 08:38:50.073509 2026] [security2:error] [pid 466512:tid 466724] [client 173.252.95.38:57340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9aSSKGokixMSfKDOf-QgAAAmY"]
[Tue Jul 21 08:38:50.240106 2026] [security2:error] [pid 465652:tid 465784] [client 20.197.192.193:44118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9aSjzTqJoBC2Mw28_V5gAAAIc"]
[Tue Jul 21 08:38:50.250156 2026] [core:error] [pid 466512:tid 466768] [client 143.198.153.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:38:50.250180 2026] [core:error] [pid 466512:tid 466768] [client 143.198.153.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:38:50.295973 2026] [security2:error] [pid 466512:tid 466769] [client 20.197.192.193:40780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9aSiKGokixMSfKDOf-SAAAApM"]
[Tue Jul 21 08:38:50.326014 2026] [security2:error] [pid 465652:tid 465808] [client 20.197.192.193:44157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/dp.php"] [unique_id "al9aSjzTqJoBC2Mw28_V5wAAAJ8"]
[Tue Jul 21 08:38:50.339484 2026] [security2:error] [pid 466512:tid 466665] [client 20.197.192.193:40821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/old.php"] [unique_id "al9aSiKGokixMSfKDOf-SQAAAis"]
[Tue Jul 21 08:38:50.354104 2026] [security2:error] [pid 466512:tid 466680] [client 20.197.192.193:44159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/ms-new.php"] [unique_id "al9aSiKGokixMSfKDOf-SgAAAjo"]
[Tue Jul 21 08:38:50.376732 2026] [security2:error] [pid 465652:tid 465874] [client 20.197.192.193:44155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/track.php"] [unique_id "al9aSjzTqJoBC2Mw28_V6gAAAOE"]
[Tue Jul 21 08:38:50.398449 2026] [security2:error] [pid 466512:tid 466722] [client 20.197.192.193:40831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/2352356666.php"] [unique_id "al9aSiKGokixMSfKDOf-SwAAAmQ"]
[Tue Jul 21 08:38:50.415833 2026] [security2:error] [pid 466512:tid 466760] [client 20.197.192.193:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/pn.php"] [unique_id "al9aSiKGokixMSfKDOf-TAAAAoo"]
[Tue Jul 21 08:38:50.438890 2026] [security2:error] [pid 466512:tid 466700] [client 20.197.192.193:40808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9aSiKGokixMSfKDOf-TgAAAk4"]
[Tue Jul 21 08:38:50.469083 2026] [security2:error] [pid 466512:tid 466666] [client 20.197.192.193:40778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/dr.php"] [unique_id "al9aSiKGokixMSfKDOf-UgAAAiw"]
[Tue Jul 21 08:38:50.477381 2026] [security2:error] [pid 466512:tid 466675] [client 20.206.105.145:33754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9aSiKGokixMSfKDOf-VAAAAjU"]
[Tue Jul 21 08:38:50.559122 2026] [security2:error] [pid 466512:tid 466765] [client 20.197.192.193:40830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/2x.php"] [unique_id "al9aSiKGokixMSfKDOf-VgAAAo8"]
[Tue Jul 21 08:38:50.636575 2026] [security2:error] [pid 466512:tid 466708] [client 20.197.192.193:44124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/kq1.php"] [unique_id "al9aSiKGokixMSfKDOf-XQAAAlY"]
[Tue Jul 21 08:38:50.683227 2026] [security2:error] [pid 465652:tid 465789] [client 20.197.192.193:53256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/zzz.php"] [unique_id "al9aSjzTqJoBC2Mw28_V8AAAAIw"]
[Tue Jul 21 08:38:50.721522 2026] [security2:error] [pid 465652:tid 465829] [client 20.197.192.193:44119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/wicked.php"] [unique_id "al9aSjzTqJoBC2Mw28_V8QAAALQ"]
[Tue Jul 21 08:38:50.751592 2026] [security2:error] [pid 466512:tid 466681] [client 20.197.192.193:44133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/edit.php"] [unique_id "al9aSiKGokixMSfKDOf-ZAAAAjs"]
[Tue Jul 21 08:38:50.791492 2026] [security2:error] [pid 466512:tid 466766] [client 20.197.192.193:44151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/kua.php"] [unique_id "al9aSiKGokixMSfKDOf-ZQAAApA"]
[Tue Jul 21 08:38:50.819429 2026] [security2:error] [pid 465652:tid 465904] [client 20.197.192.193:40813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/ez.php"] [unique_id "al9aSjzTqJoBC2Mw28_V9gAAAP8"]
[Tue Jul 21 08:38:50.835399 2026] [security2:error] [pid 465652:tid 465902] [client 65.21.113.253:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aSjzTqJoBC2Mw28_V6QAAAP0"]
[Tue Jul 21 08:38:50.843672 2026] [security2:error] [pid 465652:tid 465878] [client 195.206.105.227:47756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9aSjzTqJoBC2Mw28_V9wAAAOU"]
[Tue Jul 21 08:38:50.843776 2026] [security2:error] [pid 465652:tid 465878] [client 195.206.105.227:47756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9aSjzTqJoBC2Mw28_V9wAAAOU"]
[Tue Jul 21 08:38:50.863582 2026] [security2:error] [pid 466512:tid 466707] [client 20.197.192.193:44115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/fz.php"] [unique_id "al9aSiKGokixMSfKDOf-aAAAAlU"]
[Tue Jul 21 08:38:50.902079 2026] [security2:error] [pid 466512:tid 466686] [client 20.197.192.193:53289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/la.php"] [unique_id "al9aSiKGokixMSfKDOf-aQAAAkA"]
[Tue Jul 21 08:38:50.944483 2026] [security2:error] [pid 466512:tid 466751] [client 20.197.192.193:40781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9aSiKGokixMSfKDOf-agAAAoE"]
[Tue Jul 21 08:38:50.967367 2026] [security2:error] [pid 465652:tid 465857] [client 20.197.192.193:40829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/inso.php"] [unique_id "al9aSjzTqJoBC2Mw28_V-wAAANA"]
[Tue Jul 21 08:38:50.992115 2026] [security2:error] [pid 465652:tid 465801] [client 20.197.192.193:40791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/wpx.php"] [unique_id "al9aSjzTqJoBC2Mw28_V_AAAAJg"]
[Tue Jul 21 08:38:51.026110 2026] [security2:error] [pid 466512:tid 466680] [client 20.197.192.193:40793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/berlin.php"] [unique_id "al9aSyKGokixMSfKDOf-bAAAAjo"]
[Tue Jul 21 08:38:51.040949 2026] [security2:error] [pid 466512:tid 466760] [client 20.197.192.193:53262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/billur.php"] [unique_id "al9aSyKGokixMSfKDOf-bQAAAoo"]
[Tue Jul 21 08:38:51.074728 2026] [security2:error] [pid 466512:tid 466764] [client 20.197.192.193:40822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/mimpi.php"] [unique_id "al9aSyKGokixMSfKDOf-bgAAAo4"]
[Tue Jul 21 08:38:51.121030 2026] [security2:error] [pid 466512:tid 466756] [client 20.197.192.193:44114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/dp.php"] [unique_id "al9aSyKGokixMSfKDOf-bwAAAoY"]
[Tue Jul 21 08:38:51.186292 2026] [security2:error] [pid 465652:tid 465907] [client 20.197.192.193:40816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/bootstrap.php"] [unique_id "al9aSzzTqJoBC2Mw28_WAQAAAQI"]
[Tue Jul 21 08:38:51.206862 2026] [security2:error] [pid 465652:tid 465833] [client 20.197.192.193:44131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/wp-editor.php"] [unique_id "al9aSzzTqJoBC2Mw28_WAgAAALg"]
[Tue Jul 21 08:38:51.226822 2026] [security2:error] [pid 465652:tid 465869] [client 20.197.192.193:53275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/cro.php"] [unique_id "al9aSzzTqJoBC2Mw28_WAwAAANw"]
[Tue Jul 21 08:38:51.293712 2026] [security2:error] [pid 465652:tid 465820] [client 20.197.192.193:11502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/cron-tab.php"] [unique_id "al9aSzzTqJoBC2Mw28_WBwAAAKs"]
[Tue Jul 21 08:38:51.355325 2026] [security2:error] [pid 466512:tid 466765] [client 213.152.162.15:37516] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9aSyKGokixMSfKDOf-dAAAAo8"]
[Tue Jul 21 08:38:51.355498 2026] [security2:error] [pid 466512:tid 466765] [client 213.152.162.15:37516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9aSyKGokixMSfKDOf-dAAAAo8"]
[Tue Jul 21 08:38:51.358130 2026] [security2:error] [pid 465652:tid 465891] [client 20.197.192.193:40776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/koiy.php"] [unique_id "al9aSzzTqJoBC2Mw28_WCgAAAPI"]
[Tue Jul 21 08:38:51.403431 2026] [security2:error] [pid 466512:tid 466717] [client 20.197.192.193:44109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/hp2.php"] [unique_id "al9aSyKGokixMSfKDOf-dQAAAl8"]
[Tue Jul 21 08:38:51.449561 2026] [security2:error] [pid 466512:tid 466692] [client 20.197.192.193:44146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/hp3.php"] [unique_id "al9aSyKGokixMSfKDOf-dwAAAkY"]
[Tue Jul 21 08:38:51.466994 2026] [security2:error] [pid 465652:tid 465804] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aSzzTqJoBC2Mw28_WBgAAmwM"]
[Tue Jul 21 08:38:51.469803 2026] [security2:error] [pid 466512:tid 466723] [client 20.197.192.193:40775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/aa1.php"] [unique_id "al9aSyKGokixMSfKDOf-egAAAmU"]
[Tue Jul 21 08:38:51.478298 2026] [security2:error] [pid 466512:tid 466663] [client 20.226.60.151:58602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-post-data.php"] [unique_id "al9aSyKGokixMSfKDOf-ewAAAik"]
[Tue Jul 21 08:38:51.487589 2026] [security2:error] [pid 465652:tid 465866] [client 20.197.192.193:53269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/acew67.php"] [unique_id "al9aSzzTqJoBC2Mw28_WEAAAANk"]
[Tue Jul 21 08:38:51.506697 2026] [security2:error] [pid 466512:tid 466683] [client 20.197.192.193:44130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/bscclapb.php"] [unique_id "al9aSyKGokixMSfKDOf-fQAAAj0"]
[Tue Jul 21 08:38:51.512573 2026] [security2:error] [pid 466512:tid 466569] [remote 192.241.143.148:41614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "girassollimpeza.com.br"] [uri "/wp-login.php"] [unique_id "al9aSyKGokixMSfKDOf-fgACNTg"]
[Tue Jul 21 08:38:51.529266 2026] [security2:error] [pid 466512:tid 466735] [client 20.197.192.193:40769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/else1.php"] [unique_id "al9aSyKGokixMSfKDOf-fwAAAnE"]
[Tue Jul 21 08:38:51.558394 2026] [security2:error] [pid 466512:tid 466707] [client 20.197.192.193:44121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/tkikikoko.php"] [unique_id "al9aSyKGokixMSfKDOf-gQAAAlU"]
[Tue Jul 21 08:38:51.585460 2026] [security2:error] [pid 466512:tid 466754] [client 20.197.192.193:44140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9aSyKGokixMSfKDOf-ggAAAoQ"]
[Tue Jul 21 08:38:51.630914 2026] [security2:error] [pid 466512:tid 466701] [client 202.179.75.202:49962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aSyKGokixMSfKDOf-hQAAAk8"]
[Tue Jul 21 08:38:51.631037 2026] [security2:error] [pid 466512:tid 466701] [client 202.179.75.202:49962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aSyKGokixMSfKDOf-hQAAAk8"]
[Tue Jul 21 08:38:51.676541 2026] [security2:error] [pid 466512:tid 466685] [client 20.197.192.193:40797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/wp-css.php"] [unique_id "al9aSyKGokixMSfKDOf-hwAAAj8"]
[Tue Jul 21 08:38:51.714515 2026] [security2:error] [pid 466512:tid 466680] [client 20.197.192.193:44125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/wp-explorer.php"] [unique_id "al9aSyKGokixMSfKDOf-iQAAAjo"]
[Tue Jul 21 08:38:51.733174 2026] [security2:error] [pid 465652:tid 465856] [client 20.197.192.193:40773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/akismet.php"] [unique_id "al9aSzzTqJoBC2Mw28_WEwAAAM8"]
[Tue Jul 21 08:38:51.735412 2026] [security2:error] [pid 466512:tid 466690] [client 20.206.105.145:33678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/like.php"] [unique_id "al9aSyKGokixMSfKDOf-jAAAAkQ"]
[Tue Jul 21 08:38:51.760674 2026] [security2:error] [pid 466512:tid 466673] [client 20.197.192.193:40801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/ace2.php"] [unique_id "al9aSyKGokixMSfKDOf-jQAAAjM"]
[Tue Jul 21 08:38:51.774032 2026] [security2:error] [pid 466512:tid 466709] [client 20.220.225.223:63297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/mimpi.php"] [unique_id "al9aSyKGokixMSfKDOf-jgAAAlc"]
[Tue Jul 21 08:38:51.792452 2026] [security2:error] [pid 466512:tid 466755] [client 20.197.192.193:53250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.paginadoproduto-oficial.com.br"] [uri "/ms.php"] [unique_id "al9aSyKGokixMSfKDOf-jwAAAoU"]
[Tue Jul 21 08:38:51.829359 2026] [security2:error] [pid 466512:tid 466599] [remote 103.187.169.251:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "homemsedutoronline.com"] [uri "/wp-login.php"] [unique_id "al9aSyKGokixMSfKDOf-kQACMFY"]
[Tue Jul 21 08:38:52.323265 2026] [autoindex:error] [pid 466512:tid 466723] [client 74.7.242.45:0] AH01276: Cannot serve directory /home1/ofic8899/thekerassentials.shop-officialstore.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:38:52.412192 2026] [security2:error] [pid 466512:tid 466681] [client 172.203.225.221:45070] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.72"] [uri "/index.cgi"] [unique_id "al9aTCKGokixMSfKDOf-mQAAAjs"]
[Tue Jul 21 08:38:52.417945 2026] [security2:error] [pid 465652:tid 465859] [client 20.63.100.92:5449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/wicked.php"] [unique_id "al9aTDzTqJoBC2Mw28_WHQAAANI"]
[Tue Jul 21 08:38:52.432775 2026] [security2:error] [pid 466512:tid 466675] [client 74.7.228.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.thekerassentials.shop-officialstore.com"] [uri "/cgi-sys/404.html"] [unique_id "al9aTCKGokixMSfKDOf-nAAAAjU"]
[Tue Jul 21 08:38:52.433619 2026] [security2:error] [pid 466512:tid 466699] [client 74.7.228.31:57514] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.thekerassentials.shop-officialstore.com"] [uri "/robots.txt"] [unique_id "al9aTCKGokixMSfKDOf-mgACTTA"]
[Tue Jul 21 08:38:52.576378 2026] [security2:error] [pid 465652:tid 465796] [client 223.181.60.88:15133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aTDzTqJoBC2Mw28_WIwAAAJM"]
[Tue Jul 21 08:38:52.576562 2026] [security2:error] [pid 465652:tid 465796] [client 223.181.60.88:15133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aTDzTqJoBC2Mw28_WIwAAAJM"]
[Tue Jul 21 08:38:52.765326 2026] [security2:error] [pid 465652:tid 465800] [client 65.21.113.253:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aTDzTqJoBC2Mw28_WGwAAAJc"]
[Tue Jul 21 08:38:52.792527 2026] [security2:error] [pid 465652:tid 465783] [client 5.38.115.39:36978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aTDzTqJoBC2Mw28_WKQAAAIY"]
[Tue Jul 21 08:38:52.797043 2026] [security2:error] [pid 465652:tid 465783] [client 5.38.115.39:36978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aTDzTqJoBC2Mw28_WKQAAAIY"]
[Tue Jul 21 08:38:53.041778 2026] [security2:error] [pid 465652:tid 465878] [client 20.151.10.161:60754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/inputs.php"] [unique_id "al9aTTzTqJoBC2Mw28_WLgAAAOU"]
[Tue Jul 21 08:38:53.202392 2026] [security2:error] [pid 465652:tid 465870] [client 59.95.197.55:55672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aTTzTqJoBC2Mw28_WMQAAAN0"]
[Tue Jul 21 08:38:53.202548 2026] [security2:error] [pid 465652:tid 465870] [client 59.95.197.55:55672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aTTzTqJoBC2Mw28_WMQAAAN0"]
[Tue Jul 21 08:38:53.232729 2026] [security2:error] [pid 465652:tid 465748] [remote 41.186.86.12:61994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "overkotz.com"] [uri "/wp-login.php"] [unique_id "al9aTTzTqJoBC2Mw28_WMgAA-l8"]
[Tue Jul 21 08:38:53.277362 2026] [security2:error] [pid 465652:tid 465888] [client 195.206.105.227:47764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aTTzTqJoBC2Mw28_WNgAAAO8"]
[Tue Jul 21 08:38:53.277544 2026] [security2:error] [pid 465652:tid 465888] [client 195.206.105.227:47764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aTTzTqJoBC2Mw28_WNgAAAO8"]
[Tue Jul 21 08:38:53.352080 2026] [security2:error] [pid 466512:tid 466755] [client 20.206.105.145:33742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/.well-known/about.php"] [unique_id "al9aTSKGokixMSfKDOf-qAAAAoU"]
[Tue Jul 21 08:38:53.689839 2026] [security2:error] [pid 465652:tid 465826] [client 5.31.193.106:58720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aTTzTqJoBC2Mw28_WQwAAALE"]
[Tue Jul 21 08:38:53.689941 2026] [security2:error] [pid 465652:tid 465826] [client 5.31.193.106:58720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aTTzTqJoBC2Mw28_WQwAAALE"]
[Tue Jul 21 08:38:53.740101 2026] [security2:error] [pid 466512:tid 466728] [client 20.220.225.223:47763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/dp.php"] [unique_id "al9aTSKGokixMSfKDOf-sQAAAmo"]
[Tue Jul 21 08:38:53.879133 2026] [security2:error] [pid 465652:tid 465861] [client 38.60.198.111:52128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.198.60.38.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.brwmarcas.com.br"] [uri "/gestaolancamentos/wp-login.php"] [unique_id "al9aSzzTqJoBC2Mw28_WEgAAANQ"], referer: http://www.brwmarcas.com.br/gestaolancamentos/wp-admin/
[Tue Jul 21 08:38:54.068133 2026] [security2:error] [pid 465652:tid 465908] [client 74.249.245.134:41737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/readme.php"] [unique_id "al9aTjzTqJoBC2Mw28_WSQAAAQM"]
[Tue Jul 21 08:38:54.096330 2026] [security2:error] [pid 466512:tid 466559] [remote 45.146.55.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mecanicanogueira.com.br"] [uri "/wp-login.php"] [unique_id "al9aTSKGokixMSfKDOf-owACji4"]
[Tue Jul 21 08:38:54.161052 2026] [security2:error] [pid 465652:tid 465868] [client 91.92.47.101:10584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/db.php"] [unique_id "al9aTjzTqJoBC2Mw28_WSgAAANs"], referer: http://jaypi.com.br/
[Tue Jul 21 08:38:54.162654 2026] [security2:error] [pid 466512:tid 466736] [client 91.92.47.101:10550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/settings.php"] [unique_id "al9aTiKGokixMSfKDOf-vAAAAnI"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:38:54.163179 2026] [security2:error] [pid 466512:tid 466680] [client 91.92.47.101:10524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/db.php"] [unique_id "al9aTiKGokixMSfKDOf-vQAAAjo"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:38:54.163351 2026] [security2:error] [pid 465652:tid 465890] [client 91.92.47.101:10566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/settings.php"] [unique_id "al9aTjzTqJoBC2Mw28_WTAAAAPE"], referer: http://jaypi.com.br/
[Tue Jul 21 08:38:54.164173 2026] [security2:error] [pid 466512:tid 466660] [client 91.92.47.101:10558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "jaypi.com.br"] [uri "/.env.bak"] [unique_id "al9aTiKGokixMSfKDOf-uwAAAiY"], referer: http://jaypi.com.br/
[Tue Jul 21 08:38:54.397741 2026] [security2:error] [pid 466512:tid 466663] [client 122.176.100.127:55592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aTiKGokixMSfKDOf-wwAAAik"]
[Tue Jul 21 08:38:54.397919 2026] [security2:error] [pid 466512:tid 466663] [client 122.176.100.127:55592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aTiKGokixMSfKDOf-wwAAAik"]
[Tue Jul 21 08:38:54.551348 2026] [security2:error] [pid 466512:tid 466659] [client 20.151.10.161:60693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/av.php"] [unique_id "al9aTiKGokixMSfKDOf-xgAAAiU"]
[Tue Jul 21 08:38:54.580192 2026] [core:error] [pid 465652:tid 465859] [client 143.198.153.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.limetteodontologia.com.br/
[Tue Jul 21 08:38:54.580211 2026] [core:error] [pid 465652:tid 465859] [client 143.198.153.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.limetteodontologia.com.br/
[Tue Jul 21 08:38:54.582126 2026] [security2:error] [pid 466512:tid 466747] [client 91.92.47.101:10620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/database.php"] [unique_id "al9aTiKGokixMSfKDOf-zAAAAn0"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:38:54.582894 2026] [security2:error] [pid 466512:tid 466705] [client 91.92.47.101:10614] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "rockegrow.com.br"] [uri "/.env.bak"] [unique_id "al9aTiKGokixMSfKDOf-ywAAAlM"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:38:54.583142 2026] [security2:error] [pid 466512:tid 466687] [client 91.92.47.101:10534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "rockegrow.com.br"] [uri "/web.config"] [unique_id "al9aTiKGokixMSfKDOf-ygAAAkE"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:38:54.666772 2026] [security2:error] [pid 466512:tid 466643] [client 213.152.162.15:42772] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9aTiKGokixMSfKDOf-0gAAAhU"]
[Tue Jul 21 08:38:54.666923 2026] [security2:error] [pid 466512:tid 466643] [client 213.152.162.15:42772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9aTiKGokixMSfKDOf-0gAAAhU"]
[Tue Jul 21 08:38:54.675121 2026] [security2:error] [pid 465652:tid 465895] [client 14.245.224.124:57321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aTjzTqJoBC2Mw28_WYwAAAPY"]
[Tue Jul 21 08:38:54.675735 2026] [security2:error] [pid 465652:tid 465895] [client 14.245.224.124:57321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aTjzTqJoBC2Mw28_WYwAAAPY"]
[Tue Jul 21 08:38:54.722603 2026] [security2:error] [pid 465652:tid 465794] [client 91.92.47.101:10692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/db.php"] [unique_id "al9aTjzTqJoBC2Mw28_WZQAAAJE"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:38:54.723652 2026] [security2:error] [pid 465652:tid 465783] [client 91.92.47.101:10720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/settings.php"] [unique_id "al9aTjzTqJoBC2Mw28_WZgAAAIY"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:38:54.725705 2026] [security2:error] [pid 466512:tid 466666] [client 91.92.47.101:10676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "rockegrow.jaypi.com.br"] [uri "/web.config"] [unique_id "al9aTiKGokixMSfKDOf-1wAAAiw"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:38:54.726219 2026] [security2:error] [pid 465652:tid 465838] [client 91.92.47.101:10664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/database.php"] [unique_id "al9aTjzTqJoBC2Mw28_WaQAAAL0"], referer: http://jaypi.com.br/
[Tue Jul 21 08:38:54.726405 2026] [security2:error] [pid 466512:tid 466706] [client 91.92.47.101:10706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "rockegrow.jaypi.com.br"] [uri "/.env.bak"] [unique_id "al9aTiKGokixMSfKDOf-1gAAAlQ"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:38:54.726990 2026] [security2:error] [pid 465652:tid 465789] [client 91.92.47.101:10672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "jaypi.com.br"] [uri "/web.config"] [unique_id "al9aTjzTqJoBC2Mw28_WawAAAIw"], referer: http://jaypi.com.br/
[Tue Jul 21 08:38:54.772925 2026] [security2:error] [pid 465652:tid 465689] [remote 212.23.216.117:52124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.216.23.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ellosemijoias.com.br"] [uri "/wp-login.php"] [unique_id "al9aTTzTqJoBC2Mw28_WRAAAyCQ"]
[Tue Jul 21 08:38:54.778908 2026] [security2:error] [pid 465652:tid 465795] [client 65.21.113.253:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aTjzTqJoBC2Mw28_WTQAAAJI"]
[Tue Jul 21 08:38:55.527343 2026] [security2:error] [pid 466512:tid 466665] [client 38.60.198.111:52294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.198.60.38.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.brwmarcas.com.br"] [uri "/gestaolancamentos/wp-login.php"] [unique_id "al9aTyKGokixMSfKDOf-4AAAAis"], referer: www.google.com
[Tue Jul 21 08:38:55.594252 2026] [security2:error] [pid 466512:tid 466705] [client 20.151.10.161:60737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/classwithtostring.php"] [unique_id "al9aTyKGokixMSfKDOf-4QAAAlM"]
[Tue Jul 21 08:38:55.690685 2026] [security2:error] [pid 466512:tid 466745] [client 91.92.47.101:10754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/database.php"] [unique_id "al9aTyKGokixMSfKDOf-5AAAAns"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:38:55.781972 2026] [security2:error] [pid 466512:tid 466724] [client 20.220.225.223:54291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/bootstrap.php"] [unique_id "al9aTyKGokixMSfKDOf-6wAAAmY"]
[Tue Jul 21 08:38:56.088792 2026] [security2:error] [pid 465652:tid 465861] [client 20.206.105.145:33790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9aUDzTqJoBC2Mw28_WgwAAANQ"]
[Tue Jul 21 08:38:56.141978 2026] [security2:error] [pid 466512:tid 466683] [client 195.49.128.211:62016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aUCKGokixMSfKDOf-7wAAAj0"]
[Tue Jul 21 08:38:56.142093 2026] [security2:error] [pid 466512:tid 466683] [client 195.49.128.211:62016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aUCKGokixMSfKDOf-7wAAAj0"]
[Tue Jul 21 08:38:56.281387 2026] [security2:error] [pid 466512:tid 466692] [client 64.42.179.43:50354] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9aUCKGokixMSfKDOf-9AAAAkY"]
[Tue Jul 21 08:38:56.281588 2026] [security2:error] [pid 466512:tid 466692] [client 64.42.179.43:50354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9aUCKGokixMSfKDOf-9AAAAkY"]
[Tue Jul 21 08:38:56.371546 2026] [security2:error] [pid 466512:tid 466718] [client 152.59.181.104:56678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aUCKGokixMSfKDOf--AAAAmA"]
[Tue Jul 21 08:38:56.371763 2026] [security2:error] [pid 466512:tid 466718] [client 152.59.181.104:56678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aUCKGokixMSfKDOf--AAAAmA"]
[Tue Jul 21 08:38:56.620808 2026] [security2:error] [pid 465652:tid 465858] [client 20.151.10.161:4914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agrocibus.com.agrocibus.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9aUDzTqJoBC2Mw28_WiAAAANE"]
[Tue Jul 21 08:38:56.641298 2026] [security2:error] [pid 466512:tid 466739] [client 103.59.206.240:31276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aUCKGokixMSfKDOf--wAAAnU"]
[Tue Jul 21 08:38:56.641410 2026] [security2:error] [pid 466512:tid 466739] [client 103.59.206.240:31276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aUCKGokixMSfKDOf--wAAAnU"]
[Tue Jul 21 08:38:56.833750 2026] [security2:error] [pid 465652:tid 465879] [client 65.21.113.253:60484] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aUDzTqJoBC2Mw28_WhwAAAOY"]
[Tue Jul 21 08:38:56.847447 2026] [security2:error] [pid 465652:tid 465820] [client 152.59.34.51:59776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aUDzTqJoBC2Mw28_WkwAAAKs"]
[Tue Jul 21 08:38:56.847632 2026] [security2:error] [pid 465652:tid 465820] [client 152.59.34.51:59776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aUDzTqJoBC2Mw28_WkwAAAKs"]
[Tue Jul 21 08:38:56.897182 2026] [security2:error] [pid 465652:tid 465855] [client 20.151.10.161:4230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agrocibus.com.agrocibus.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9aUDzTqJoBC2Mw28_WlAAAAM4"]
[Tue Jul 21 08:38:57.172163 2026] [security2:error] [pid 466512:tid 466764] [client 20.151.10.161:4927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agrocibus.com.agrocibus.com.br"] [uri "/images.php"] [unique_id "al9aUSKGokixMSfKDOf_AAAAAo4"]
[Tue Jul 21 08:38:57.448179 2026] [security2:error] [pid 465652:tid 465903] [client 20.220.225.223:2416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wp-editor.php"] [unique_id "al9aUTzTqJoBC2Mw28_WnAAAAP4"]
[Tue Jul 21 08:38:57.456242 2026] [security2:error] [pid 466512:tid 466679] [client 20.151.10.161:4876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agrocibus.com.agrocibus.com.br"] [uri "/for.php"] [unique_id "al9aUSKGokixMSfKDOf_AgAAAjk"]
[Tue Jul 21 08:38:57.569420 2026] [security2:error] [pid 465652:tid 465857] [client 20.206.105.145:33676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/pucci.php"] [unique_id "al9aUTzTqJoBC2Mw28_WoAAAANA"]
[Tue Jul 21 08:38:57.648844 2026] [security2:error] [pid 466512:tid 466686] [client 49.144.66.253:30158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aUSKGokixMSfKDOf_BwAAAkA"]
[Tue Jul 21 08:38:57.648938 2026] [security2:error] [pid 466512:tid 466686] [client 49.144.66.253:30158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aUSKGokixMSfKDOf_BwAAAkA"]
[Tue Jul 21 08:38:57.686350 2026] [security2:error] [pid 465652:tid 465895] [client 106.222.204.167:7246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.204.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jurencosmetics.com"] [uri "/xmlrpc.php"] [unique_id "al9aUTzTqJoBC2Mw28_WnQAAAPY"]
[Tue Jul 21 08:38:57.686495 2026] [security2:error] [pid 465652:tid 465895] [client 106.222.204.167:7246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jurencosmetics.com"] [uri "/xmlrpc.php"] [unique_id "al9aUTzTqJoBC2Mw28_WnQAAAPY"]
[Tue Jul 21 08:38:57.732833 2026] [security2:error] [pid 465652:tid 465806] [client 20.151.10.161:4915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agrocibus.com.agrocibus.com.br"] [uri "/2larp.php"] [unique_id "al9aUTzTqJoBC2Mw28_WpAAAAJ0"]
[Tue Jul 21 08:38:57.811455 2026] [security2:error] [pid 466512:tid 466691] [client 5.199.232.222:2144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.232.199.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/xmlrpc.php"] [unique_id "al9aUCKGokixMSfKDOf-_QAAAkU"]
[Tue Jul 21 08:38:57.811589 2026] [security2:error] [pid 466512:tid 466691] [client 5.199.232.222:2144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kenyetuquinha.com"] [uri "/xmlrpc.php"] [unique_id "al9aUCKGokixMSfKDOf-_QAAAkU"]
[Tue Jul 21 08:38:57.859955 2026] [security2:error] [pid 466512:tid 466647] [client 20.151.10.161:60750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9aUSKGokixMSfKDOf_CgAAAhk"]
[Tue Jul 21 08:38:58.009192 2026] [security2:error] [pid 466512:tid 466706] [client 20.151.10.161:4900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agrocibus.com.agrocibus.com.br"] [uri "/adminner.php"] [unique_id "al9aUiKGokixMSfKDOf_DAAAAlQ"]
[Tue Jul 21 08:38:58.291909 2026] [security2:error] [pid 466512:tid 466701] [client 20.151.10.161:4920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agrocibus.com.agrocibus.com.br"] [uri "/82.php"] [unique_id "al9aUiKGokixMSfKDOf_EwAAAk8"]
[Tue Jul 21 08:38:58.381486 2026] [security2:error] [pid 466512:tid 466728] [client 185.244.152.38:64935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.152.244.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kenyetuquinha.com"] [uri "/xmlrpc.php"] [unique_id "al9aUiKGokixMSfKDOf_EQAAAmo"]
[Tue Jul 21 08:38:58.381706 2026] [security2:error] [pid 466512:tid 466728] [client 185.244.152.38:64935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kenyetuquinha.com"] [uri "/xmlrpc.php"] [unique_id "al9aUiKGokixMSfKDOf_EQAAAmo"]
[Tue Jul 21 08:38:58.568931 2026] [security2:error] [pid 465652:tid 465858] [client 20.151.10.161:4248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agrocibus.com.agrocibus.com.br"] [uri "/kir.php"] [unique_id "al9aUjzTqJoBC2Mw28_WswAAANE"]
[Tue Jul 21 08:38:58.951124 2026] [security2:error] [pid 465652:tid 465844] [client 198.204.224.34:49102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aumentodevendas.factorial.studio"] [uri "/wp-includes/adc37af5/edit.php"] [unique_id "al9aUjzTqJoBC2Mw28_WwAAAAMM"], referer: https://aumentodevendas.factorial.studio/wp-includes/adc37af5/edit.php
[Tue Jul 21 08:38:59.106542 2026] [security2:error] [pid 466512:tid 466683] [client 20.151.10.161:60707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wp-blog.php"] [unique_id "al9aUyKGokixMSfKDOf_IwAAAj0"]
[Tue Jul 21 08:38:59.120880 2026] [security2:error] [pid 465652:tid 465849] [client 20.206.105.145:33763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wp-temp.php"] [unique_id "al9aUzzTqJoBC2Mw28_WxwAAAMg"]
[Tue Jul 21 08:38:59.172234 2026] [security2:error] [pid 466512:tid 466636] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aUyKGokixMSfKDOf_JQACU3s"]
[Tue Jul 21 08:38:59.172413 2026] [security2:error] [pid 466512:tid 466705] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aUyKGokixMSfKDOf_JQACU3s"]
[Tue Jul 21 08:38:59.319368 2026] [security2:error] [pid 466512:tid 466724] [client 20.220.225.223:63334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/cro.php"] [unique_id "al9aUyKGokixMSfKDOf_JgAAAmY"]
[Tue Jul 21 08:38:59.330947 2026] [security2:error] [pid 465652:tid 465822] [client 117.213.202.34:51678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aUzzTqJoBC2Mw28_WzAAAAK0"]
[Tue Jul 21 08:38:59.331262 2026] [security2:error] [pid 465652:tid 465822] [client 117.213.202.34:51678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aUzzTqJoBC2Mw28_WzAAAAK0"]
[Tue Jul 21 08:38:59.767922 2026] [security2:error] [pid 465652:tid 465796] [client 195.49.128.211:53777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aUzzTqJoBC2Mw28_W1AAAAJM"]
[Tue Jul 21 08:38:59.768099 2026] [security2:error] [pid 465652:tid 465796] [client 195.49.128.211:53777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aUzzTqJoBC2Mw28_W1AAAAJM"]
[Tue Jul 21 08:38:59.895231 2026] [security2:error] [pid 466512:tid 466750] [client 69.171.230.2:61162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9aUyKGokixMSfKDOf_LgAAAoA"]
[Tue Jul 21 08:39:00.108584 2026] [security2:error] [pid 466512:tid 466565] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aVCKGokixMSfKDOf_NQACTTQ"]
[Tue Jul 21 08:39:00.108739 2026] [security2:error] [pid 466512:tid 466699] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aVCKGokixMSfKDOf_NQACTTQ"]
[Tue Jul 21 08:39:00.315684 2026] [security2:error] [pid 466512:tid 466739] [client 20.151.10.161:60763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9aVCKGokixMSfKDOf_OgAAAnU"]
[Tue Jul 21 08:39:00.633705 2026] [core:alert] [pid 466512:tid 466653] [client 57.141.18.68:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:39:00.947002 2026] [security2:error] [pid 466512:tid 466707] [client 20.151.10.161:60714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/adminfuns.php"] [unique_id "al9aVCKGokixMSfKDOf_RwAAAlU"]
[Tue Jul 21 08:39:00.992648 2026] [security2:error] [pid 465652:tid 465826] [client 61.1.167.83:51048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aVDzTqJoBC2Mw28_W8AAAALE"]
[Tue Jul 21 08:39:00.992775 2026] [security2:error] [pid 465652:tid 465826] [client 61.1.167.83:51048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aVDzTqJoBC2Mw28_W8AAAALE"]
[Tue Jul 21 08:39:01.120104 2026] [security2:error] [pid 465652:tid 465889] [client 20.226.60.151:58524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/pucci.php"] [unique_id "al9aVTzTqJoBC2Mw28_W9AAAAPA"]
[Tue Jul 21 08:39:01.826281 2026] [security2:error] [pid 465652:tid 465830] [client 20.206.105.145:33772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/xmu.php"] [unique_id "al9aVTzTqJoBC2Mw28_W_wAAALU"]
[Tue Jul 21 08:39:01.916137 2026] [security2:error] [pid 465652:tid 465822] [client 20.151.10.161:60794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/goods.php"] [unique_id "al9aVTzTqJoBC2Mw28_XAAAAAK0"]
[Tue Jul 21 08:39:02.149558 2026] [security2:error] [pid 466512:tid 466700] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aViKGokixMSfKDOf_TwACTiU"]
[Tue Jul 21 08:39:02.541224 2026] [security2:error] [pid 466512:tid 466665] [client 20.151.10.161:60681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/ms-edit.php"] [unique_id "al9aViKGokixMSfKDOf_UwAAAis"]
[Tue Jul 21 08:39:02.676728 2026] [security2:error] [pid 466512:tid 466654] [client 202.179.75.202:44868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aViKGokixMSfKDOf_VQAAAiA"]
[Tue Jul 21 08:39:02.676854 2026] [security2:error] [pid 466512:tid 466654] [client 202.179.75.202:44868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aViKGokixMSfKDOf_VQAAAiA"]
[Tue Jul 21 08:39:03.033851 2026] [security2:error] [pid 465652:tid 465800] [client 20.206.105.145:33730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9aVzzTqJoBC2Mw28_XIgAAAJc"]
[Tue Jul 21 08:39:03.179953 2026] [security2:error] [pid 465652:tid 465660] [remote 72.167.132.114:35294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedrocromo.com.br"] [uri "/wp-login.php"] [unique_id "al9aVzzTqJoBC2Mw28_XIwAA3wc"]
[Tue Jul 21 08:39:03.213726 2026] [security2:error] [pid 465652:tid 465861] [client 20.151.10.161:60787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/222.php"] [unique_id "al9aVzzTqJoBC2Mw28_XJwAAANQ"]
[Tue Jul 21 08:39:03.303527 2026] [security2:error] [pid 466512:tid 466745] [client 223.181.60.88:3295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aVyKGokixMSfKDOf_WQAAAns"]
[Tue Jul 21 08:39:03.303711 2026] [security2:error] [pid 466512:tid 466745] [client 223.181.60.88:3295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aVyKGokixMSfKDOf_WQAAAns"]
[Tue Jul 21 08:39:03.509721 2026] [security2:error] [pid 465652:tid 465817] [client 20.220.225.223:40760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/cron-tab.php"] [unique_id "al9aVzzTqJoBC2Mw28_XQQAAAKg"]
[Tue Jul 21 08:39:03.530023 2026] [security2:error] [pid 466512:tid 466756] [client 5.38.115.39:32002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aVyKGokixMSfKDOf_XQAAAoY"]
[Tue Jul 21 08:39:03.530148 2026] [security2:error] [pid 466512:tid 466756] [client 5.38.115.39:32002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aVyKGokixMSfKDOf_XQAAAoY"]
[Tue Jul 21 08:39:03.722204 2026] [security2:error] [pid 466512:tid 466643] [client 59.95.197.55:56128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aVyKGokixMSfKDOf_YAAAAhU"]
[Tue Jul 21 08:39:03.722353 2026] [security2:error] [pid 466512:tid 466643] [client 59.95.197.55:56128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aVyKGokixMSfKDOf_YAAAAhU"]
[Tue Jul 21 08:39:04.892193 2026] [security2:error] [pid 466512:tid 466758] [client 122.176.100.127:56102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aWCKGokixMSfKDOf_bwAAAog"]
[Tue Jul 21 08:39:04.892434 2026] [security2:error] [pid 466512:tid 466758] [client 122.176.100.127:56102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aWCKGokixMSfKDOf_bwAAAog"]
[Tue Jul 21 08:39:04.906792 2026] [security2:error] [pid 466512:tid 466753] [client 20.151.10.161:57591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9aWCKGokixMSfKDOf_cAAAAoM"]
[Tue Jul 21 08:39:05.047264 2026] [security2:error] [pid 466512:tid 466756] [client 20.206.105.145:33734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/puc.php"] [unique_id "al9aWSKGokixMSfKDOf_dAAAAoY"]
[Tue Jul 21 08:39:06.607137 2026] [security2:error] [pid 465652:tid 465864] [client 20.151.10.161:57537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9aWjzTqJoBC2Mw28_XgQAAANc"]
[Tue Jul 21 08:39:06.818294 2026] [security2:error] [pid 465652:tid 465904] [client 195.49.128.211:62626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aWjzTqJoBC2Mw28_XhAAAAP8"]
[Tue Jul 21 08:39:06.818457 2026] [security2:error] [pid 465652:tid 465904] [client 195.49.128.211:62626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aWjzTqJoBC2Mw28_XhAAAAP8"]
[Tue Jul 21 08:39:06.891668 2026] [security2:error] [pid 466512:tid 466720] [client 14.245.224.124:58172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aWiKGokixMSfKDOf_hgAAAmI"]
[Tue Jul 21 08:39:06.891785 2026] [security2:error] [pid 466512:tid 466720] [client 14.245.224.124:58172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aWiKGokixMSfKDOf_hgAAAmI"]
[Tue Jul 21 08:39:06.921978 2026] [proxy:error] [pid 466512:tid 466739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:06.922046 2026] [proxy_http:error] [pid 466512:tid 466739] [client 143.198.48.26:36424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:39:06.922802 2026] [proxy:error] [pid 466512:tid 466739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:06.922837 2026] [proxy_http:error] [pid 466512:tid 466739] [client 143.198.48.26:36424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:39:06.988294 2026] [security2:error] [pid 466512:tid 466747] [client 20.220.225.223:47754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/koiy.php"] [unique_id "al9aWiKGokixMSfKDOf_iQAAAn0"]
[Tue Jul 21 08:39:07.206370 2026] [security2:error] [pid 465652:tid 465901] [client 152.59.181.104:57120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aWzzTqJoBC2Mw28_XiwAAAPw"]
[Tue Jul 21 08:39:07.206486 2026] [security2:error] [pid 465652:tid 465901] [client 152.59.181.104:57120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aWzzTqJoBC2Mw28_XiwAAAPw"]
[Tue Jul 21 08:39:07.223226 2026] [security2:error] [pid 465652:tid 465836] [client 152.59.34.51:54826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aWzzTqJoBC2Mw28_XjAAAALs"]
[Tue Jul 21 08:39:07.223367 2026] [security2:error] [pid 465652:tid 465836] [client 152.59.34.51:54826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aWzzTqJoBC2Mw28_XjAAAALs"]
[Tue Jul 21 08:39:07.287150 2026] [proxy:error] [pid 466512:tid 466706] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:07.287247 2026] [proxy_http:error] [pid 466512:tid 466706] [client 143.198.48.26:36430] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.oscrias.com.br/
[Tue Jul 21 08:39:07.289205 2026] [proxy:error] [pid 466512:tid 466706] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:07.289262 2026] [proxy_http:error] [pid 466512:tid 466706] [client 143.198.48.26:36430] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.oscrias.com.br/
[Tue Jul 21 08:39:07.547258 2026] [security2:error] [pid 466512:tid 466573] [remote 199.189.225.40:62513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "selleto.com.br"] [uri "/wp-login.php"] [unique_id "al9aWyKGokixMSfKDOf_kAACUzw"]
[Tue Jul 21 08:39:07.848269 2026] [security2:error] [pid 466512:tid 466679] [client 20.151.10.161:60783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/raw.php"] [unique_id "al9aWyKGokixMSfKDOf_lgAAAjk"]
[Tue Jul 21 08:39:08.044420 2026] [proxy:error] [pid 466512:tid 466648] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:08.044456 2026] [proxy_http:error] [pid 466512:tid 466648] [client 143.198.48.26:38442] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:39:08.045213 2026] [proxy:error] [pid 466512:tid 466648] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:08.045242 2026] [proxy_http:error] [pid 466512:tid 466648] [client 143.198.48.26:38442] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:39:08.376094 2026] [security2:error] [pid 465652:tid 465875] [client 103.59.206.240:31473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aXDzTqJoBC2Mw28_XpwAAAOI"]
[Tue Jul 21 08:39:08.376338 2026] [security2:error] [pid 465652:tid 465875] [client 103.59.206.240:31473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aXDzTqJoBC2Mw28_XpwAAAOI"]
[Tue Jul 21 08:39:08.661454 2026] [security2:error] [pid 465652:tid 465892] [client 49.144.66.253:30612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aXDzTqJoBC2Mw28_XtQAAAPM"]
[Tue Jul 21 08:39:08.661567 2026] [security2:error] [pid 465652:tid 465892] [client 49.144.66.253:30612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aXDzTqJoBC2Mw28_XtQAAAPM"]
[Tue Jul 21 08:39:08.940057 2026] [security2:error] [pid 466512:tid 466753] [client 20.220.225.223:2429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/hp2.php"] [unique_id "al9aXCKGokixMSfKDOf_pgAAAoM"]
[Tue Jul 21 08:39:08.987448 2026] [security2:error] [pid 466512:tid 466654] [client 74.249.245.134:49011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/403.php"] [unique_id "al9aXCKGokixMSfKDOf_pwAAAiA"]
[Tue Jul 21 08:39:09.114555 2026] [security2:error] [pid 465652:tid 465802] [client 20.151.10.161:60734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/abcd.php"] [unique_id "al9aXTzTqJoBC2Mw28_XwQAAAJk"]
[Tue Jul 21 08:39:09.720421 2026] [security2:error] [pid 465652:tid 465758] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aXTzTqJoBC2Mw28_XxwAA52k"]
[Tue Jul 21 08:39:09.720575 2026] [security2:error] [pid 465652:tid 465880] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aXTzTqJoBC2Mw28_XxwAA52k"]
[Tue Jul 21 08:39:10.070046 2026] [security2:error] [pid 466512:tid 466686] [client 117.213.202.34:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aXiKGokixMSfKDOf_8gAAAkA"]
[Tue Jul 21 08:39:10.070219 2026] [security2:error] [pid 466512:tid 466686] [client 117.213.202.34:52284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aXiKGokixMSfKDOf_8gAAAkA"]
[Tue Jul 21 08:39:10.386201 2026] [security2:error] [pid 466512:tid 466701] [client 195.49.128.211:54377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aXiKGokixMSfKDOcAGwAAAk8"]
[Tue Jul 21 08:39:10.386305 2026] [security2:error] [pid 466512:tid 466701] [client 195.49.128.211:54377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aXiKGokixMSfKDOcAGwAAAk8"]
[Tue Jul 21 08:39:10.503505 2026] [security2:error] [pid 466512:tid 466720] [client 20.206.105.145:33679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/themes.php"] [unique_id "al9aXiKGokixMSfKDOcAJAAAAmI"]
[Tue Jul 21 08:39:10.763855 2026] [security2:error] [pid 465652:tid 465771] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aXjzTqJoBC2Mw28_X3AAA2XY"]
[Tue Jul 21 08:39:10.764051 2026] [security2:error] [pid 465652:tid 465866] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aXjzTqJoBC2Mw28_X3AAA2XY"]
[Tue Jul 21 08:39:10.845343 2026] [security2:error] [pid 465652:tid 465851] [client 20.151.10.161:60705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/a1.php"] [unique_id "al9aXjzTqJoBC2Mw28_X4gAAAMo"]
[Tue Jul 21 08:39:11.189102 2026] [security2:error] [pid 466512:tid 466766] [client 185.213.175.37:5590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "biolinkeer.com.br"] [uri "/assets/css/new_home/slick-theme.css"] [unique_id "al9aXyKGokixMSfKDOcAPAAAApA"]
[Tue Jul 21 08:39:11.189204 2026] [security2:error] [pid 466512:tid 466766] [client 185.213.175.37:5590] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "biolinkeer.com.br"] [uri "/assets/css/new_home/slick-theme.css"] [unique_id "al9aXyKGokixMSfKDOcAPAAAApA"]
[Tue Jul 21 08:39:11.412223 2026] [security2:error] [pid 466512:tid 466712] [client 20.226.60.151:58514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/black.php"] [unique_id "al9aXyKGokixMSfKDOcARwAAAlo"]
[Tue Jul 21 08:39:12.116885 2026] [security2:error] [pid 465652:tid 465865] [client 64.23.128.239:57522] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "inlaudo.com.br"] [uri "/"] [unique_id "al9aYDzTqJoBC2Mw28_X8gAAANg"]
[Tue Jul 21 08:39:12.168250 2026] [security2:error] [pid 465652:tid 465902] [client 74.7.175.177:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "roanalacerda.com.br"] [uri "/index.php"] [unique_id "al9aYDzTqJoBC2Mw28_X8wAAAP0"]
[Tue Jul 21 08:39:12.170106 2026] [security2:error] [pid 466512:tid 466675] [client 74.7.175.177:46636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "roanalacerda.com.br"] [uri "/robots.txt"] [unique_id "al9aYCKGokixMSfKDOcAWwACNWo"]
[Tue Jul 21 08:39:12.233991 2026] [security2:error] [pid 466512:tid 466696] [client 3.231.193.38:54632] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "madmoholding.com.br"] [uri "/"] [unique_id "al9aYCKGokixMSfKDOcAXwAAAko"]
[Tue Jul 21 08:39:12.306531 2026] [security2:error] [pid 465652:tid 465878] [client 20.63.100.92:2595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/kua.php"] [unique_id "al9aYDzTqJoBC2Mw28_X9wAAAOU"]
[Tue Jul 21 08:39:12.354934 2026] [proxy:error] [pid 466512:tid 466732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:12.355024 2026] [proxy_http:error] [pid 466512:tid 466732] [client 143.198.48.26:38566] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.oscrias.com.br/
[Tue Jul 21 08:39:12.356545 2026] [proxy:error] [pid 466512:tid 466732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:12.356591 2026] [proxy_http:error] [pid 466512:tid 466732] [client 143.198.48.26:38566] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.oscrias.com.br/
[Tue Jul 21 08:39:12.371113 2026] [security2:error] [pid 466512:tid 466685] [client 20.151.10.161:57581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9aYCKGokixMSfKDOcAYQAAAj8"]
[Tue Jul 21 08:39:12.796306 2026] [security2:error] [pid 466512:tid 466733] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aYCKGokixMSfKDOcAZAACbxs"]
[Tue Jul 21 08:39:12.998752 2026] [security2:error] [pid 466512:tid 466753] [client 20.151.10.161:60797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9aYCKGokixMSfKDOcAZwAAAoM"]
[Tue Jul 21 08:39:13.124912 2026] [autoindex:error] [pid 466512:tid 466768] [client 43.157.175.122:55566] AH01276: Cannot serve directory /home2/reser379/megaroteiros.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:39:13.521086 2026] [security2:error] [pid 466512:tid 466647] [client 202.179.75.202:38282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aYSKGokixMSfKDOcAbQAAAhk"]
[Tue Jul 21 08:39:13.521205 2026] [security2:error] [pid 466512:tid 466647] [client 202.179.75.202:38282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aYSKGokixMSfKDOcAbQAAAhk"]
[Tue Jul 21 08:39:13.924534 2026] [security2:error] [pid 465652:tid 465811] [client 20.151.10.161:60682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9aYTzTqJoBC2Mw28_YDwAAAKI"]
[Tue Jul 21 08:39:13.995236 2026] [security2:error] [pid 465652:tid 465723] [remote 72.167.132.114:53760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9aYTzTqJoBC2Mw28_YEgAAiUY"]
[Tue Jul 21 08:39:14.110084 2026] [security2:error] [pid 466512:tid 466657] [client 223.181.60.88:4885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aYiKGokixMSfKDOcAewAAAiM"]
[Tue Jul 21 08:39:14.110391 2026] [security2:error] [pid 466512:tid 466657] [client 223.181.60.88:4885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aYiKGokixMSfKDOcAewAAAiM"]
[Tue Jul 21 08:39:14.125800 2026] [security2:error] [pid 466512:tid 466701] [client 5.38.115.39:40968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aYiKGokixMSfKDOcAfAAAAk8"]
[Tue Jul 21 08:39:14.125908 2026] [security2:error] [pid 466512:tid 466701] [client 5.38.115.39:40968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aYiKGokixMSfKDOcAfAAAAk8"]
[Tue Jul 21 08:39:14.183536 2026] [security2:error] [pid 465652:tid 465782] [client 59.95.197.55:56584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aYjzTqJoBC2Mw28_YFQAAAIU"]
[Tue Jul 21 08:39:14.183664 2026] [security2:error] [pid 465652:tid 465782] [client 59.95.197.55:56584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aYjzTqJoBC2Mw28_YFQAAAIU"]
[Tue Jul 21 08:39:14.805234 2026] [security2:error] [pid 466512:tid 466718] [client 5.31.193.106:58568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aYiKGokixMSfKDOcAggAAAmA"]
[Tue Jul 21 08:39:14.819344 2026] [security2:error] [pid 466512:tid 466718] [client 5.31.193.106:58568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aYiKGokixMSfKDOcAggAAAmA"]
[Tue Jul 21 08:39:15.208927 2026] [security2:error] [pid 465652:tid 465799] [client 20.151.10.161:57545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/simple.php"] [unique_id "al9aYzzTqJoBC2Mw28_YJwAAAJY"]
[Tue Jul 21 08:39:15.359039 2026] [security2:error] [pid 466512:tid 466768] [client 122.176.100.127:56607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aYyKGokixMSfKDOcAjAAAApI"]
[Tue Jul 21 08:39:15.359418 2026] [security2:error] [pid 466512:tid 466768] [client 122.176.100.127:56607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aYyKGokixMSfKDOcAjAAAApI"]
[Tue Jul 21 08:39:15.782021 2026] [security2:error] [pid 465652:tid 465874] [client 20.151.10.161:60781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/xxx.php"] [unique_id "al9aYzzTqJoBC2Mw28_YMgAAAOE"]
[Tue Jul 21 08:39:15.963858 2026] [qos:error] [pid 465652:tid 465727] [remote 57.141.18.15:41038] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.15, id=al9aYzzTqJoBC2Mw28_YOQAAkko
[Tue Jul 21 08:39:16.320930 2026] [security2:error] [pid 465652:tid 465806] [client 14.245.224.124:58969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aZDzTqJoBC2Mw28_YQQAAAJ0"]
[Tue Jul 21 08:39:16.321093 2026] [security2:error] [pid 465652:tid 465806] [client 14.245.224.124:58969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aZDzTqJoBC2Mw28_YQQAAAJ0"]
[Tue Jul 21 08:39:16.436020 2026] [qos:error] [pid 465652:tid 465724] [remote 57.141.18.112:48364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.112, id=al9aZDzTqJoBC2Mw28_YQgAAr0c
[Tue Jul 21 08:39:16.668901 2026] [security2:error] [pid 465652:tid 465890] [client 20.151.10.161:60700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/hypo.php"] [unique_id "al9aZDzTqJoBC2Mw28_YRgAAAPE"]
[Tue Jul 21 08:39:16.670281 2026] [access_compat:error] [pid 466512:tid 466754] [client 162.241.63.68:32810] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:39:16.732567 2026] [security2:error] [pid 466512:tid 466720] [client 173.252.95.12:51228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9aZCKGokixMSfKDOcAlwAAAmI"]
[Tue Jul 21 08:39:16.995091 2026] [qos:error] [pid 466512:tid 466513] [remote 57.141.18.30:33154] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.30, id=al9aZCKGokixMSfKDOcAmwACcAA
[Tue Jul 21 08:39:17.032954 2026] [autoindex:error] [pid 466512:tid 466698] [client 147.185.132.58:64298] AH01276: Cannot serve directory /home1/joaor255/meupetpaixao.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:39:17.121932 2026] [qos:error] [pid 465652:tid 465737] [remote 57.141.18.85:45310] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.85, id=al9aZTzTqJoBC2Mw28_YSwAA3lQ
[Tue Jul 21 08:39:17.182510 2026] [qos:error] [pid 466512:tid 466545] [remote 57.141.18.32:32544] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.32, id=al9aZSKGokixMSfKDOcAnwACWiA
[Tue Jul 21 08:39:17.462123 2026] [security2:error] [pid 466512:tid 466765] [client 173.252.95.17:51188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9aZSKGokixMSfKDOcAowAAAo8"]
[Tue Jul 21 08:39:17.483887 2026] [security2:error] [pid 465652:tid 465845] [client 20.151.10.161:60741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/chosen.php"] [unique_id "al9aZTzTqJoBC2Mw28_YVAAAAMQ"]
[Tue Jul 21 08:39:17.503599 2026] [qos:error] [pid 465652:tid 465764] [remote 57.141.18.74:60410] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.74, id=al9aZTzTqJoBC2Mw28_YVQAA_G8
[Tue Jul 21 08:39:17.506708 2026] [security2:error] [pid 466512:tid 466700] [client 195.49.128.211:63415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aZSKGokixMSfKDOcApAAAAk4"]
[Tue Jul 21 08:39:17.506825 2026] [security2:error] [pid 466512:tid 466700] [client 195.49.128.211:63415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aZSKGokixMSfKDOcApAAAAk4"]
[Tue Jul 21 08:39:17.823566 2026] [qos:error] [pid 466512:tid 466620] [remote 57.141.18.40:54942] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.40, id=al9aZSKGokixMSfKDOcAqQACF2s
[Tue Jul 21 08:39:17.902631 2026] [security2:error] [pid 466512:tid 466739] [client 152.59.34.51:60743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aZSKGokixMSfKDOcAqgAAAnU"]
[Tue Jul 21 08:39:17.902807 2026] [security2:error] [pid 466512:tid 466739] [client 152.59.34.51:60743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aZSKGokixMSfKDOcAqgAAAnU"]
[Tue Jul 21 08:39:18.023358 2026] [security2:error] [pid 466512:tid 466718] [client 103.59.206.240:31156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aZiKGokixMSfKDOcAqwAAAmA"]
[Tue Jul 21 08:39:18.023502 2026] [security2:error] [pid 466512:tid 466718] [client 103.59.206.240:31156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aZiKGokixMSfKDOcAqwAAAmA"]
[Tue Jul 21 08:39:18.039610 2026] [security2:error] [pid 466512:tid 466663] [client 152.59.181.104:57640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aZiKGokixMSfKDOcArAAAAik"]
[Tue Jul 21 08:39:18.039798 2026] [security2:error] [pid 466512:tid 466663] [client 152.59.181.104:57640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aZiKGokixMSfKDOcArAAAAik"]
[Tue Jul 21 08:39:18.091783 2026] [security2:error] [pid 465652:tid 465803] [client 20.220.225.223:46944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/hp3.php"] [unique_id "al9aZjzTqJoBC2Mw28_YYQAAAJo"]
[Tue Jul 21 08:39:18.291851 2026] [qos:error] [pid 465652:tid 465686] [remote 57.141.18.100:49008] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.100, id=al9aZjzTqJoBC2Mw28_YZgAAkiE
[Tue Jul 21 08:39:18.307501 2026] [security2:error] [pid 465652:tid 465653] [remote 199.189.225.40:65405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9aZjzTqJoBC2Mw28_YZwAArQA"]
[Tue Jul 21 08:39:18.334698 2026] [security2:error] [pid 466512:tid 466657] [client 20.151.10.161:57536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/file5.php"] [unique_id "al9aZiKGokixMSfKDOcAtQAAAiM"]
[Tue Jul 21 08:39:18.441774 2026] [qos:error] [pid 466512:tid 466571] [remote 57.141.18.74:60426] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.74, id=al9aZiKGokixMSfKDOcAtwACajo
[Tue Jul 21 08:39:18.567755 2026] [qos:error] [pid 465652:tid 465758] [remote 57.141.18.46:45262] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.46, id=al9aZjzTqJoBC2Mw28_YaQAA7Gk
[Tue Jul 21 08:39:18.670572 2026] [security2:error] [pid 466512:tid 466617] [remote 132.148.72.88:45722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9aZiKGokixMSfKDOcAuQACVGg"]
[Tue Jul 21 08:39:18.943648 2026] [qos:error] [pid 466512:tid 466588] [remote 57.141.18.19:48490] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.19, id=al9aZiKGokixMSfKDOcAwQACF0s
[Tue Jul 21 08:39:19.435024 2026] [security2:error] [pid 466512:tid 466698] [client 143.244.57.121:48416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9aZyKGokixMSfKDOcAxwAAAkw"]
[Tue Jul 21 08:39:19.869047 2026] [security2:error] [pid 466512:tid 466753] [client 143.244.57.121:48420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "glauciadomingues.com"] [uri "/xmlrpc.php"] [unique_id "al9aZyKGokixMSfKDOcAzAAAAoM"]
[Tue Jul 21 08:39:19.919523 2026] [security2:error] [pid 466512:tid 466762] [client 20.151.10.161:60755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/file.php"] [unique_id "al9aZyKGokixMSfKDOcAzgAAAow"]
[Tue Jul 21 08:39:19.969219 2026] [security2:error] [pid 466512:tid 466764] [client 49.144.66.253:31027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aZyKGokixMSfKDOcA0gAAAo4"]
[Tue Jul 21 08:39:19.969324 2026] [security2:error] [pid 466512:tid 466764] [client 49.144.66.253:31027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aZyKGokixMSfKDOcA0gAAAo4"]
[Tue Jul 21 08:39:20.106111 2026] [qos:error] [pid 466512:tid 466537] [remote 57.141.18.99:43426] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.99, id=al9aaCKGokixMSfKDOcA1QACMRg
[Tue Jul 21 08:39:20.141499 2026] [security2:error] [pid 466512:tid 466661] [client 74.249.245.134:41961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/max.php"] [unique_id "al9aaCKGokixMSfKDOcA2AAAAic"]
[Tue Jul 21 08:39:20.215869 2026] [security2:error] [pid 466512:tid 466720] [client 127.0.0.1:41588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al9aaCKGokixMSfKDOcA2gAAAmI"]
[Tue Jul 21 08:39:20.215968 2026] [security2:error] [pid 466512:tid 466745] [client 74.7.228.61:58218] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.oticapersona.com.br"] [uri "/robots.txt"] [unique_id "al9aaCKGokixMSfKDOcA2QACezQ"]
[Tue Jul 21 08:39:20.266580 2026] [security2:error] [pid 465652:tid 465744] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aaDzTqJoBC2Mw28_YgwAAkVs"]
[Tue Jul 21 08:39:20.266847 2026] [security2:error] [pid 465652:tid 465794] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aaDzTqJoBC2Mw28_YgwAAkVs"]
[Tue Jul 21 08:39:20.692271 2026] [security2:error] [pid 465652:tid 465902] [client 143.244.57.121:34220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9aaDzTqJoBC2Mw28_YigAAAP0"]
[Tue Jul 21 08:39:20.790799 2026] [security2:error] [pid 466512:tid 466696] [client 117.213.202.34:52901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aaCKGokixMSfKDOcA6QAAAko"]
[Tue Jul 21 08:39:20.790986 2026] [security2:error] [pid 466512:tid 466696] [client 117.213.202.34:52901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aaCKGokixMSfKDOcA6QAAAko"]
[Tue Jul 21 08:39:20.992575 2026] [security2:error] [pid 465652:tid 465815] [client 195.49.128.211:54980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aaDzTqJoBC2Mw28_YkgAAAKY"]
[Tue Jul 21 08:39:20.992675 2026] [security2:error] [pid 465652:tid 465815] [client 195.49.128.211:54980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aaDzTqJoBC2Mw28_YkgAAAKY"]
[Tue Jul 21 08:39:21.030720 2026] [security2:error] [pid 465652:tid 465903] [client 49.13.130.29:38114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9aaTzTqJoBC2Mw28_YlAAAAP4"], referer: https://artetoner.com.br
[Tue Jul 21 08:39:21.057152 2026] [qos:error] [pid 465652:tid 465747] [remote 57.141.18.91:64020] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.91, id=al9aaTzTqJoBC2Mw28_YlQAAmV4
[Tue Jul 21 08:39:21.102591 2026] [security2:error] [pid 466512:tid 466661] [client 143.244.57.121:34232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9aaSKGokixMSfKDOcA7AAAAic"]
[Tue Jul 21 08:39:21.347361 2026] [security2:error] [pid 466512:tid 466589] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aaSKGokixMSfKDOcA8AACkEw"]
[Tue Jul 21 08:39:21.347569 2026] [security2:error] [pid 466512:tid 466766] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aaSKGokixMSfKDOcA8AACkEw"]
[Tue Jul 21 08:39:21.430349 2026] [security2:error] [pid 466512:tid 466715] [client 61.1.167.83:51639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aaSKGokixMSfKDOcA8QAAAl0"]
[Tue Jul 21 08:39:21.432903 2026] [security2:error] [pid 466512:tid 466715] [client 61.1.167.83:51639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aaSKGokixMSfKDOcA8QAAAl0"]
[Tue Jul 21 08:39:21.522349 2026] [security2:error] [pid 466512:tid 466768] [client 143.244.57.121:34242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9aaSKGokixMSfKDOcA8wAAApI"]
[Tue Jul 21 08:39:21.825426 2026] [security2:error] [pid 466512:tid 466656] [client 20.151.10.161:60795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/aa2.php"] [unique_id "al9aaSKGokixMSfKDOcA-QAAAiI"]
[Tue Jul 21 08:39:21.943802 2026] [security2:error] [pid 466512:tid 466647] [client 143.244.57.121:42539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9aaSKGokixMSfKDOcA_QAAAhk"]
[Tue Jul 21 08:39:22.141505 2026] [qos:error] [pid 466512:tid 466633] [remote 57.141.18.70:54898] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.70, id=al9aaiKGokixMSfKDOcBAQACF3g
[Tue Jul 21 08:39:22.365434 2026] [security2:error] [pid 466512:tid 466759] [client 143.244.57.121:8469] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9aaiKGokixMSfKDOcBBAAAAok"]
[Tue Jul 21 08:39:22.570248 2026] [security2:error] [pid 466512:tid 466768] [client 20.206.105.145:33673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/8.php"] [unique_id "al9aaiKGokixMSfKDOcBBwAAApI"]
[Tue Jul 21 08:39:22.725163 2026] [security2:error] [pid 466512:tid 466722] [client 20.220.225.223:46939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/aa1.php"] [unique_id "al9aaiKGokixMSfKDOcBCwAAAmQ"]
[Tue Jul 21 08:39:22.787049 2026] [security2:error] [pid 466512:tid 466655] [client 143.244.57.121:34260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9aaiKGokixMSfKDOcBDwAAAiE"]
[Tue Jul 21 08:39:22.827584 2026] [core:error] [pid 466512:tid 466657] [client 66.249.66.69:52428] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:39:22.827602 2026] [core:error] [pid 466512:tid 466657] [client 66.249.66.69:52428] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:39:23.206944 2026] [security2:error] [pid 465652:tid 465866] [client 143.244.57.121:34264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9aazzTqJoBC2Mw28_YsgAAANk"]
[Tue Jul 21 08:39:23.421832 2026] [security2:error] [pid 465652:tid 465859] [client 20.226.60.151:58527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/zlece.php"] [unique_id "al9aazzTqJoBC2Mw28_YtgAAANI"]
[Tue Jul 21 08:39:23.598240 2026] [security2:error] [pid 465652:tid 465864] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aazzTqJoBC2Mw28_YuAAA1xE"]
[Tue Jul 21 08:39:23.614844 2026] [security2:error] [pid 466512:tid 466648] [client 143.244.57.121:34276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9aayKGokixMSfKDOcBGgAAAho"]
[Tue Jul 21 08:39:23.700565 2026] [security2:error] [pid 465652:tid 465804] [client 20.63.100.92:5463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/ez.php"] [unique_id "al9aazzTqJoBC2Mw28_YwAAAAJs"]
[Tue Jul 21 08:39:23.850036 2026] [security2:error] [pid 466512:tid 466715] [client 20.151.10.161:60724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/ccou.php"] [unique_id "al9aayKGokixMSfKDOcBHAAAAl0"]
[Tue Jul 21 08:39:24.022477 2026] [security2:error] [pid 465652:tid 465878] [client 143.244.57.121:34292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9abDzTqJoBC2Mw28_YyQAAAOU"]
[Tue Jul 21 08:39:24.384104 2026] [security2:error] [pid 466512:tid 466753] [client 202.179.75.202:38334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9abCKGokixMSfKDOcBJgAAAoM"]
[Tue Jul 21 08:39:24.384227 2026] [security2:error] [pid 466512:tid 466753] [client 202.179.75.202:38334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9abCKGokixMSfKDOcBJgAAAoM"]
[Tue Jul 21 08:39:24.447775 2026] [security2:error] [pid 466512:tid 466674] [client 143.244.57.121:34294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9abCKGokixMSfKDOcBKAAAAjQ"]
[Tue Jul 21 08:39:24.677524 2026] [security2:error] [pid 466512:tid 466656] [client 59.95.197.55:57018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9abCKGokixMSfKDOcBLAAAAiI"]
[Tue Jul 21 08:39:24.677692 2026] [security2:error] [pid 466512:tid 466656] [client 59.95.197.55:57018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9abCKGokixMSfKDOcBLAAAAiI"]
[Tue Jul 21 08:39:24.778901 2026] [security2:error] [pid 466512:tid 466729] [client 5.38.115.39:51031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9abCKGokixMSfKDOcBMQAAAms"]
[Tue Jul 21 08:39:24.779023 2026] [security2:error] [pid 466512:tid 466729] [client 5.38.115.39:51031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9abCKGokixMSfKDOcBMQAAAms"]
[Tue Jul 21 08:39:24.825181 2026] [proxy:error] [pid 465652:tid 465857] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:24.825254 2026] [proxy_http:error] [pid 465652:tid 465857] [client 165.22.43.182:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:39:24.825874 2026] [proxy:error] [pid 465652:tid 465857] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:24.825901 2026] [proxy_http:error] [pid 465652:tid 465857] [client 165.22.43.182:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:39:24.839528 2026] [security2:error] [pid 466512:tid 466637] [remote 167.99.129.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.129.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9abCKGokixMSfKDOcBMgACe3w"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:39:24.842241 2026] [security2:error] [pid 466512:tid 466619] [remote 167.99.129.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.129.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9abCKGokixMSfKDOcBMwACQWo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:39:24.859457 2026] [security2:error] [pid 466512:tid 466531] [remote 167.99.129.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.129.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9abCKGokixMSfKDOcBNQACHxI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:39:24.869442 2026] [security2:error] [pid 466512:tid 466655] [client 143.244.57.121:34300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9abCKGokixMSfKDOcBNgAAAiE"]
[Tue Jul 21 08:39:24.883431 2026] [security2:error] [pid 466512:tid 466516] [remote 167.99.129.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.129.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9abCKGokixMSfKDOcBNwACZwM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:39:25.016892 2026] [security2:error] [pid 466512:tid 466678] [client 223.181.60.88:14827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9abSKGokixMSfKDOcBOAAAAjg"]
[Tue Jul 21 08:39:25.017093 2026] [security2:error] [pid 466512:tid 466678] [client 223.181.60.88:14827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9abSKGokixMSfKDOcBOAAAAjg"]
[Tue Jul 21 08:39:25.073832 2026] [proxy:error] [pid 465652:tid 465793] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:25.073902 2026] [proxy_http:error] [pid 465652:tid 465793] [client 165.22.43.182:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.leonardouralombardo1781757591426.0721679.meusitehostgator.com.br/
[Tue Jul 21 08:39:25.074455 2026] [proxy:error] [pid 465652:tid 465793] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:25.074487 2026] [proxy_http:error] [pid 465652:tid 465793] [client 165.22.43.182:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.leonardouralombardo1781757591426.0721679.meusitehostgator.com.br/
[Tue Jul 21 08:39:25.077648 2026] [security2:error] [pid 466512:tid 466635] [remote 167.99.129.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.129.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9abSKGokixMSfKDOcBOgACVHo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:39:25.099144 2026] [security2:error] [pid 466512:tid 466605] [remote 167.99.129.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.129.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9abSKGokixMSfKDOcBOwACfVw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:39:25.303097 2026] [security2:error] [pid 465652:tid 465897] [client 143.244.57.121:34302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9abTzTqJoBC2Mw28_Y2QAAAPg"]
[Tue Jul 21 08:39:25.424158 2026] [security2:error] [pid 466512:tid 466530] [remote 167.99.129.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.129.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9abSKGokixMSfKDOcBSAACNhE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:39:25.430327 2026] [security2:error] [pid 466512:tid 466687] [client 20.151.10.161:57585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/dr.php"] [unique_id "al9abSKGokixMSfKDOcBSQAAAkE"]
[Tue Jul 21 08:39:25.458505 2026] [security2:error] [pid 466512:tid 466602] [remote 167.99.129.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.129.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9abSKGokixMSfKDOcBSgACH1k"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:39:25.495331 2026] [security2:error] [pid 465652:tid 465665] [remote 103.161.172.221:56568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9abTzTqJoBC2Mw28_Y3AAAngw"]
[Tue Jul 21 08:39:25.641593 2026] [security2:error] [pid 466512:tid 466601] [remote 167.99.129.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.129.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9abSKGokixMSfKDOcBTAACOVg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:39:25.650607 2026] [security2:error] [pid 465652:tid 465712] [remote 167.99.129.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.129.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9abTzTqJoBC2Mw28_Y4AAA3zs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:39:25.660428 2026] [security2:error] [pid 466512:tid 466567] [remote 167.99.129.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.129.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9abSKGokixMSfKDOcBTQACPDY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:39:25.723477 2026] [security2:error] [pid 466512:tid 466649] [client 143.244.57.121:34316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9abSKGokixMSfKDOcBTwAAAhs"]
[Tue Jul 21 08:39:25.876100 2026] [security2:error] [pid 466512:tid 466672] [client 122.176.100.127:57127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9abSKGokixMSfKDOcBUgAAAjI"]
[Tue Jul 21 08:39:25.876203 2026] [security2:error] [pid 466512:tid 466672] [client 122.176.100.127:57127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9abSKGokixMSfKDOcBUgAAAjI"]
[Tue Jul 21 08:39:26.002589 2026] [security2:error] [pid 466512:tid 466559] [remote 167.99.129.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.129.99.167.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9abiKGokixMSfKDOcBVAACji4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:39:26.154513 2026] [security2:error] [pid 466512:tid 466692] [client 20.206.105.145:33690] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "choppon24h.com.br"] [uri "/1.php"] [unique_id "al9abiKGokixMSfKDOcBVQAAAkY"]
[Tue Jul 21 08:39:26.154604 2026] [security2:error] [pid 466512:tid 466692] [client 20.206.105.145:33690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/1.php"] [unique_id "al9abiKGokixMSfKDOcBVQAAAkY"]
[Tue Jul 21 08:39:26.156801 2026] [security2:error] [pid 465652:tid 465786] [client 34.168.58.236:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.58.168.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centrodevestibulares.com.br.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9abjzTqJoBC2Mw28_Y6AAAAIk"]
[Tue Jul 21 08:39:26.187969 2026] [security2:error] [pid 465652:tid 465894] [client 143.244.57.121:34322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "glauciadomingues.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9abjzTqJoBC2Mw28_Y7AAAAPU"]
[Tue Jul 21 08:39:26.424357 2026] [security2:error] [pid 466512:tid 466662] [client 20.151.10.161:60715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/file31.php"] [unique_id "al9abiKGokixMSfKDOcBWQAAAig"]
[Tue Jul 21 08:39:26.567261 2026] [security2:error] [pid 466512:tid 466717] [client 34.168.58.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9abiKGokixMSfKDOcBXQAAAl8"]
[Tue Jul 21 08:39:26.596161 2026] [security2:error] [pid 466512:tid 466538] [remote 120.72.98.5:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.98.72.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hauptmann.com.br"] [uri "/wp-login.php"] [unique_id "al9abiKGokixMSfKDOcBXgACYBk"]
[Tue Jul 21 08:39:26.653394 2026] [security2:error] [pid 466512:tid 466729] [client 20.220.225.223:2389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/acew67.php"] [unique_id "al9abiKGokixMSfKDOcBXwAAAms"]
[Tue Jul 21 08:39:27.076015 2026] [security2:error] [pid 466512:tid 466682] [client 34.168.58.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9abyKGokixMSfKDOcBaQAAAjw"]
[Tue Jul 21 08:39:27.112652 2026] [security2:error] [pid 465652:tid 465820] [client 14.245.224.124:59461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9abzzTqJoBC2Mw28_Y_wAAAKs"]
[Tue Jul 21 08:39:27.112746 2026] [security2:error] [pid 465652:tid 465820] [client 14.245.224.124:59461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9abzzTqJoBC2Mw28_Y_wAAAKs"]
[Tue Jul 21 08:39:27.231910 2026] [security2:error] [pid 465652:tid 465827] [client 20.206.105.145:33735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/100.php"] [unique_id "al9abzzTqJoBC2Mw28_ZAgAAALI"]
[Tue Jul 21 08:39:27.266598 2026] [security2:error] [pid 466512:tid 466762] [client 34.168.58.236:62233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.58.168.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "centrodevestibulares.com.br"] [uri "/xmlrpc.php"] [unique_id "al9abyKGokixMSfKDOcBagAAAow"]
[Tue Jul 21 08:39:27.462026 2026] [security2:error] [pid 466512:tid 466657] [client 69.171.230.5:57538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9abyKGokixMSfKDOcBbAAAAiM"]
[Tue Jul 21 08:39:27.497716 2026] [security2:error] [pid 465652:tid 465822] [client 34.168.58.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9abzzTqJoBC2Mw28_ZCgAAAK0"]
[Tue Jul 21 08:39:27.589025 2026] [security2:error] [pid 465652:tid 465880] [client 20.151.10.161:60729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/file6.php"] [unique_id "al9abzzTqJoBC2Mw28_ZCwAAAOc"]
[Tue Jul 21 08:39:27.782282 2026] [security2:error] [pid 466512:tid 466671] [client 34.168.58.236:59612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9abyKGokixMSfKDOcBcwAAAjE"]
[Tue Jul 21 08:39:27.878514 2026] [security2:error] [pid 465652:tid 465811] [client 20.206.105.145:33701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/about.php"] [unique_id "al9abzzTqJoBC2Mw28_ZDwAAAKI"]
[Tue Jul 21 08:39:27.897879 2026] [security2:error] [pid 465652:tid 465740] [remote 72.167.132.114:47068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/wp-login.php"] [unique_id "al9abzzTqJoBC2Mw28_ZEAAAulc"]
[Tue Jul 21 08:39:27.934743 2026] [security2:error] [pid 465652:tid 465872] [client 34.168.58.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9abzzTqJoBC2Mw28_ZEQAAAN8"]
[Tue Jul 21 08:39:28.110485 2026] [security2:error] [pid 465652:tid 465824] [client 173.252.95.8:56024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9abzzTqJoBC2Mw28_ZFAAAAK8"]
[Tue Jul 21 08:39:28.134918 2026] [security2:error] [pid 466512:tid 466651] [client 195.49.128.211:64137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9acCKGokixMSfKDOcBdQAAAh0"]
[Tue Jul 21 08:39:28.135035 2026] [security2:error] [pid 466512:tid 466651] [client 195.49.128.211:64137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9acCKGokixMSfKDOcBdQAAAh0"]
[Tue Jul 21 08:39:28.136081 2026] [security2:error] [pid 465652:tid 465856] [client 69.171.230.2:41056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9acDzTqJoBC2Mw28_ZGQAAAM8"]
[Tue Jul 21 08:39:28.142277 2026] [security2:error] [pid 466512:tid 466721] [client 20.220.225.223:2411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/bscclapb.php"] [unique_id "al9acCKGokixMSfKDOcBdgAAAmM"]
[Tue Jul 21 08:39:28.162302 2026] [security2:error] [pid 466512:tid 466661] [client 8.208.9.170:60876] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "constaraempreendimentos.com.br.ciclododinheiro.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9abyKGokixMSfKDOcBdAAAAic"]
[Tue Jul 21 08:39:28.233903 2026] [security2:error] [pid 465652:tid 465895] [client 69.171.230.41:36022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9acDzTqJoBC2Mw28_ZGAAAAPY"]
[Tue Jul 21 08:39:28.285087 2026] [security2:error] [pid 466512:tid 466729] [client 34.168.58.236:55056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9acCKGokixMSfKDOcBegAAAms"]
[Tue Jul 21 08:39:28.355160 2026] [security2:error] [pid 465652:tid 465894] [client 34.168.58.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9acDzTqJoBC2Mw28_ZHQAAAPU"]
[Tue Jul 21 08:39:28.475153 2026] [security2:error] [pid 465652:tid 465859] [client 20.151.10.161:57571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/file15.php"] [unique_id "al9acDzTqJoBC2Mw28_ZHwAAANI"]
[Tue Jul 21 08:39:28.642266 2026] [security2:error] [pid 465652:tid 465873] [client 34.168.58.236:65394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9acDzTqJoBC2Mw28_ZIgAAAOA"]
[Tue Jul 21 08:39:28.645368 2026] [security2:error] [pid 466512:tid 466675] [client 152.59.34.51:61406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9acCKGokixMSfKDOcBgAAAAjU"]
[Tue Jul 21 08:39:28.645483 2026] [security2:error] [pid 466512:tid 466675] [client 152.59.34.51:61406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9acCKGokixMSfKDOcBgAAAAjU"]
[Tue Jul 21 08:39:28.757404 2026] [security2:error] [pid 466512:tid 466678] [client 34.168.58.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9acCKGokixMSfKDOcBggAAAjg"]
[Tue Jul 21 08:39:28.762238 2026] [security2:error] [pid 465652:tid 465875] [client 8.208.9.170:60884] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "constaraempreendimentos.com.br.ciclododinheiro.com"] [uri "/"] [unique_id "al9acDzTqJoBC2Mw28_ZJAAAAOI"]
[Tue Jul 21 08:39:28.803161 2026] [security2:error] [pid 466512:tid 466590] [remote 18.61.192.253:34510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedrocromo.com.br"] [uri "/wp-login.php"] [unique_id "al9acCKGokixMSfKDOcBhAACbk0"]
[Tue Jul 21 08:39:28.874548 2026] [autoindex:error] [pid 466512:tid 466701] [client 198.235.24.17:62510] AH01276: Cannot serve directory /home2/rebe1126/rebecavivone.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:39:28.940285 2026] [security2:error] [pid 465652:tid 465889] [client 69.171.230.5:57546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9acDzTqJoBC2Mw28_ZKgAAAPA"]
[Tue Jul 21 08:39:28.976339 2026] [security2:error] [pid 466512:tid 466662] [client 152.59.181.104:14487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9acCKGokixMSfKDOcBjQAAAig"]
[Tue Jul 21 08:39:28.980912 2026] [security2:error] [pid 466512:tid 466662] [client 152.59.181.104:14487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9acCKGokixMSfKDOcBjQAAAig"]
[Tue Jul 21 08:39:28.992145 2026] [security2:error] [pid 466512:tid 466698] [client 69.171.230.6:49064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9acCKGokixMSfKDOcBhgAAAkw"]
[Tue Jul 21 08:39:29.062442 2026] [security2:error] [pid 466512:tid 466720] [client 65.21.113.253:34250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9acCKGokixMSfKDOcBfwAAAmI"]
[Tue Jul 21 08:39:29.075691 2026] [security2:error] [pid 466512:tid 466669] [client 34.168.58.236:59868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9acSKGokixMSfKDOcBjwAAAi8"]
[Tue Jul 21 08:39:29.172834 2026] [security2:error] [pid 465652:tid 465817] [client 34.168.58.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9acTzTqJoBC2Mw28_ZLgAAAKg"]
[Tue Jul 21 08:39:29.280436 2026] [security2:error] [pid 465652:tid 465721] [remote 119.195.102.159:34482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powertronicseguranca.com"] [uri "/wp-login.php"] [unique_id "al9acTzTqJoBC2Mw28_ZMQAAkUQ"]
[Tue Jul 21 08:39:29.353552 2026] [security2:error] [pid 466512:tid 466661] [client 69.171.230.5:57552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9acSKGokixMSfKDOcBmgAAAic"]
[Tue Jul 21 08:39:29.373049 2026] [security2:error] [pid 466512:tid 466651] [client 8.208.9.170:60888] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "constaraempreendimentos.com.br.ciclododinheiro.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9acSKGokixMSfKDOcBmwAAAh0"]
[Tue Jul 21 08:39:29.473857 2026] [security2:error] [pid 466512:tid 466705] [client 34.168.58.236:57479] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9acSKGokixMSfKDOcBngAAAlM"]
[Tue Jul 21 08:39:29.579946 2026] [security2:error] [pid 465652:tid 465823] [client 34.168.58.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9acTzTqJoBC2Mw28_ZOgAAAK4"]
[Tue Jul 21 08:39:29.657441 2026] [autoindex:error] [pid 466512:tid 466646] [client 52.230.100.152:0] AH01276: Cannot serve directory /home2/ric83751/sanovitta.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:39:29.677277 2026] [security2:error] [pid 465652:tid 465893] [client 103.59.206.240:31044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9acTzTqJoBC2Mw28_ZPgAAAPQ"]
[Tue Jul 21 08:39:29.677451 2026] [security2:error] [pid 465652:tid 465893] [client 103.59.206.240:31044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9acTzTqJoBC2Mw28_ZPgAAAPQ"]
[Tue Jul 21 08:39:29.898508 2026] [security2:error] [pid 465652:tid 465811] [client 20.206.105.145:33752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/about.php"] [unique_id "al9acTzTqJoBC2Mw28_ZRQAAAKI"]
[Tue Jul 21 08:39:29.915382 2026] [security2:error] [pid 466512:tid 466662] [client 34.168.58.236:51879] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9acSKGokixMSfKDOcBqwAAAig"]
[Tue Jul 21 08:39:29.944487 2026] [security2:error] [pid 465652:tid 465806] [client 20.206.105.145:33698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/admin.php"] [unique_id "al9acTzTqJoBC2Mw28_ZRgAAAJ0"]
[Tue Jul 21 08:39:29.959399 2026] [security2:error] [pid 465652:tid 465872] [client 20.206.105.145:33771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/admin.php"] [unique_id "al9acTzTqJoBC2Mw28_ZRwAAAN8"]
[Tue Jul 21 08:39:29.975624 2026] [security2:error] [pid 465652:tid 465883] [client 8.208.9.170:60892] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "constaraempreendimentos.com.br.ciclododinheiro.com"] [uri "/"] [unique_id "al9acTzTqJoBC2Mw28_ZSAAAAOo"]
[Tue Jul 21 08:39:30.016237 2026] [security2:error] [pid 465652:tid 465891] [client 20.206.105.145:33666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/edit.php"] [unique_id "al9acjzTqJoBC2Mw28_ZSQAAAPI"]
[Tue Jul 21 08:39:30.028522 2026] [security2:error] [pid 465652:tid 465784] [client 34.168.58.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9acjzTqJoBC2Mw28_ZSgAAAIc"]
[Tue Jul 21 08:39:30.041368 2026] [security2:error] [pid 465652:tid 465793] [client 185.213.175.37:60234] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bergsantana.com.br"] [uri "/wp-content/themes/flatsome/assets/js/%url%"] [unique_id "al9acjzTqJoBC2Mw28_ZTAAAAJA"]
[Tue Jul 21 08:39:30.059175 2026] [security2:error] [pid 466512:tid 466764] [client 20.151.10.161:60672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/jp.php"] [unique_id "al9aciKGokixMSfKDOcBrQAAAo4"]
[Tue Jul 21 08:39:30.313646 2026] [security2:error] [pid 465652:tid 465875] [client 20.206.105.145:33714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9acjzTqJoBC2Mw28_ZWAAAAOI"]
[Tue Jul 21 08:39:30.360720 2026] [security2:error] [pid 466512:tid 466747] [client 34.168.58.236:53752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9aciKGokixMSfKDOcBuAAAAn0"]
[Tue Jul 21 08:39:30.377442 2026] [security2:error] [pid 465652:tid 465856] [client 49.144.66.253:31438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9acjzTqJoBC2Mw28_ZWgAAAM8"]
[Tue Jul 21 08:39:30.377575 2026] [security2:error] [pid 465652:tid 465856] [client 49.144.66.253:31438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9acjzTqJoBC2Mw28_ZWgAAAM8"]
[Tue Jul 21 08:39:30.392838 2026] [security2:error] [pid 466512:tid 466766] [client 198.44.157.34:42142] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9aciKGokixMSfKDOcBtwAAApA"]
[Tue Jul 21 08:39:30.392953 2026] [security2:error] [pid 466512:tid 466766] [client 198.44.157.34:42142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9aciKGokixMSfKDOcBtwAAApA"]
[Tue Jul 21 08:39:30.482641 2026] [security2:error] [pid 466512:tid 466745] [client 34.168.58.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9aciKGokixMSfKDOcBuwAAAns"]
[Tue Jul 21 08:39:30.590030 2026] [security2:error] [pid 465652:tid 465799] [client 8.208.9.170:60901] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "constaraempreendimentos.com.br.ciclododinheiro.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9acjzTqJoBC2Mw28_ZXAAAAJY"]
[Tue Jul 21 08:39:30.764667 2026] [security2:error] [pid 466512:tid 466678] [client 34.168.58.236:51558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9aciKGokixMSfKDOcBvwAAAjg"]
[Tue Jul 21 08:39:30.824870 2026] [security2:error] [pid 466512:tid 466520] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aciKGokixMSfKDOcBwAACjAc"]
[Tue Jul 21 08:39:30.825071 2026] [security2:error] [pid 466512:tid 466762] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9aciKGokixMSfKDOcBwAACjAc"]
[Tue Jul 21 08:39:30.849950 2026] [security2:error] [pid 465652:tid 465866] [client 64.42.179.43:58752] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9acjzTqJoBC2Mw28_ZYgAAANk"]
[Tue Jul 21 08:39:30.850051 2026] [security2:error] [pid 465652:tid 465866] [client 64.42.179.43:58752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9acjzTqJoBC2Mw28_ZYgAAANk"]
[Tue Jul 21 08:39:30.886227 2026] [security2:error] [pid 466512:tid 466646] [client 34.168.58.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9aciKGokixMSfKDOcBwwAAAhg"]
[Tue Jul 21 08:39:30.943168 2026] [security2:error] [pid 465652:tid 465827] [client 20.151.10.161:60733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/f35.php"] [unique_id "al9acjzTqJoBC2Mw28_ZZwAAALI"]
[Tue Jul 21 08:39:30.974193 2026] [security2:error] [pid 465652:tid 465815] [client 74.249.245.134:41933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/m.php"] [unique_id "al9acjzTqJoBC2Mw28_ZaAAAAKY"]
[Tue Jul 21 08:39:31.034562 2026] [security2:error] [pid 466512:tid 466698] [client 20.206.105.145:33700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/f6.php"] [unique_id "al9acyKGokixMSfKDOcBxQAAAkw"]
[Tue Jul 21 08:39:31.158611 2026] [security2:error] [pid 465652:tid 465876] [client 34.168.58.236:53459] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9aczzTqJoBC2Mw28_ZbQAAAOM"]
[Tue Jul 21 08:39:31.204887 2026] [security2:error] [pid 465652:tid 465823] [client 8.208.9.170:60908] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "constaraempreendimentos.com.br.ciclododinheiro.com"] [uri "/"] [unique_id "al9aczzTqJoBC2Mw28_ZbgAAAK4"]
[Tue Jul 21 08:39:31.292215 2026] [security2:error] [pid 466512:tid 466719] [client 34.168.58.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9acyKGokixMSfKDOcByAAAAmE"]
[Tue Jul 21 08:39:31.320449 2026] [autoindex:error] [pid 466512:tid 466721] [client 52.230.100.152:0] AH01276: Cannot serve directory /home2/ric83751/sanovitta.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:39:31.455271 2026] [security2:error] [pid 466512:tid 466732] [client 65.21.113.253:34250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aciKGokixMSfKDOcBwQAAAm4"]
[Tue Jul 21 08:39:31.517487 2026] [security2:error] [pid 465652:tid 465883] [client 34.168.58.236:55056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9aczzTqJoBC2Mw28_ZeAAAAOo"]
[Tue Jul 21 08:39:31.550322 2026] [security2:error] [pid 465652:tid 465817] [client 117.213.202.34:53517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aczzTqJoBC2Mw28_ZeQAAAKg"]
[Tue Jul 21 08:39:31.550504 2026] [security2:error] [pid 465652:tid 465817] [client 117.213.202.34:53517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aczzTqJoBC2Mw28_ZeQAAAKg"]
[Tue Jul 21 08:39:31.589746 2026] [security2:error] [pid 465652:tid 465897] [client 195.49.128.211:55581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aczzTqJoBC2Mw28_ZegAAAPg"]
[Tue Jul 21 08:39:31.589982 2026] [security2:error] [pid 465652:tid 465897] [client 195.49.128.211:55581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aczzTqJoBC2Mw28_ZegAAAPg"]
[Tue Jul 21 08:39:31.660874 2026] [security2:error] [pid 466512:tid 466745] [client 20.151.10.161:60748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wp-load.php"] [unique_id "al9acyKGokixMSfKDOcB1AAAAns"]
[Tue Jul 21 08:39:31.734313 2026] [security2:error] [pid 466512:tid 466700] [client 20.206.105.145:33672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/inputs.php"] [unique_id "al9acyKGokixMSfKDOcB2gAAAk4"]
[Tue Jul 21 08:39:31.819282 2026] [security2:error] [pid 465652:tid 465834] [client 8.208.9.170:60915] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "constaraempreendimentos.com.br.ciclododinheiro.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9aczzTqJoBC2Mw28_ZgQAAALk"]
[Tue Jul 21 08:39:31.887982 2026] [security2:error] [pid 465652:tid 465858] [client 34.168.58.236:62233] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "centrodevestibulares.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9aczzTqJoBC2Mw28_ZggAAANE"]
[Tue Jul 21 08:39:32.034456 2026] [security2:error] [pid 465652:tid 465819] [client 8.229.228.188:55840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.228.229.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aczzTqJoBC2Mw28_ZaQAAAKo"]
[Tue Jul 21 08:39:32.228037 2026] [security2:error] [pid 466512:tid 466741] [client 85.113.70.242:56882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.70.113.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9adCKGokixMSfKDOcB7QAAAnc"]
[Tue Jul 21 08:39:32.419069 2026] [security2:error] [pid 466512:tid 466733] [client 8.208.9.170:60926] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "constaraempreendimentos.com.br.ciclododinheiro.com"] [uri "/"] [unique_id "al9adCKGokixMSfKDOcB-gAAAm8"]
[Tue Jul 21 08:39:32.432893 2026] [security2:error] [pid 466512:tid 466705] [client 20.206.105.145:33745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/inputs.php"] [unique_id "al9adCKGokixMSfKDOcB-wAAAlM"]
[Tue Jul 21 08:39:32.575574 2026] [security2:error] [pid 466512:tid 466657] [client 20.206.105.145:33696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/av.php"] [unique_id "al9adCKGokixMSfKDOcB_wAAAiM"]
[Tue Jul 21 08:39:32.620623 2026] [security2:error] [pid 466512:tid 466601] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9adCKGokixMSfKDOcCAAACYVg"]
[Tue Jul 21 08:39:32.620783 2026] [security2:error] [pid 466512:tid 466719] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9adCKGokixMSfKDOcCAAACYVg"]
[Tue Jul 21 08:39:32.626959 2026] [security2:error] [pid 466512:tid 466688] [client 20.151.10.161:60776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9adCKGokixMSfKDOcCAQAAAkI"]
[Tue Jul 21 08:39:32.644185 2026] [security2:error] [pid 466512:tid 466762] [client 20.206.105.145:33671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/classwithtostring.php"] [unique_id "al9adCKGokixMSfKDOcCAgAAAow"]
[Tue Jul 21 08:39:32.651111 2026] [security2:error] [pid 466512:tid 466700] [client 85.208.96.198:24976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ellosemijoias.com.br"] [uri "/robots.txt"] [unique_id "al9adCKGokixMSfKDOcCAwAAAk4"]
[Tue Jul 21 08:39:32.651252 2026] [security2:error] [pid 466512:tid 466700] [client 85.208.96.198:24976] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ellosemijoias.com.br"] [uri "/robots.txt"] [unique_id "al9adCKGokixMSfKDOcCAwAAAk4"]
[Tue Jul 21 08:39:32.705609 2026] [security2:error] [pid 465652:tid 465845] [client 20.206.105.145:33664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9adDzTqJoBC2Mw28_ZjAAAAMQ"]
[Tue Jul 21 08:39:32.773663 2026] [security2:error] [pid 465652:tid 465838] [client 8.229.228.188:49982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ericksheik.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9adDzTqJoBC2Mw28_ZjwAAAL0"]
[Tue Jul 21 08:39:33.170691 2026] [security2:error] [pid 466512:tid 466732] [client 85.208.96.206:38824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ellosemijoias.com.br"] [uri "/produtos/"] [unique_id "al9adSKGokixMSfKDOcCCwAAAm4"]
[Tue Jul 21 08:39:33.170820 2026] [security2:error] [pid 466512:tid 466732] [client 85.208.96.206:38824] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ellosemijoias.com.br"] [uri "/produtos/"] [unique_id "al9adSKGokixMSfKDOcCCwAAAm4"]
[Tue Jul 21 08:39:33.301966 2026] [security2:error] [pid 466512:tid 466718] [client 20.151.10.161:60679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wp-links.php"] [unique_id "al9adSKGokixMSfKDOcCDgAAAmA"]
[Tue Jul 21 08:39:33.495333 2026] [security2:error] [pid 465652:tid 465893] [client 85.113.70.242:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "efrelectronics.com.br"] [uri "/wp-content/plugins/wp-planet/readme.txt"] [unique_id "al9adTzTqJoBC2Mw28_ZlwAAAPQ"]
[Tue Jul 21 08:39:33.499764 2026] [security2:error] [pid 465652:tid 465815] [client 8.229.228.188:65074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ericksheik.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9adTzTqJoBC2Mw28_ZmAAAAKY"]
[Tue Jul 21 08:39:33.598137 2026] [security2:error] [pid 465652:tid 465876] [client 20.206.105.145:33669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wp-blog.php"] [unique_id "al9adTzTqJoBC2Mw28_ZmgAAAOM"]
[Tue Jul 21 08:39:33.840833 2026] [security2:error] [pid 466512:tid 466768] [client 65.21.113.253:34250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9adSKGokixMSfKDOcCEAAAApI"]
[Tue Jul 21 08:39:34.034485 2026] [security2:error] [pid 465652:tid 465849] [client 195.206.105.227:41982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9adjzTqJoBC2Mw28_ZogAAAMg"]
[Tue Jul 21 08:39:34.034638 2026] [security2:error] [pid 465652:tid 465849] [client 195.206.105.227:41982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9adjzTqJoBC2Mw28_ZogAAAMg"]
[Tue Jul 21 08:39:34.121833 2026] [security2:error] [pid 466512:tid 466762] [client 20.151.10.161:60774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/solo1.php"] [unique_id "al9adiKGokixMSfKDOcCFwAAAow"]
[Tue Jul 21 08:39:34.208396 2026] [security2:error] [pid 465652:tid 465793] [client 85.113.70.242:56898] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "efrelectronics.com.br"] [uri "/wp-content/plugins/advanced-text-widget/readme.txt"] [unique_id "al9adjzTqJoBC2Mw28_ZpgAAAJA"]
[Tue Jul 21 08:39:34.250850 2026] [security2:error] [pid 465652:tid 465903] [client 8.229.228.188:49633] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ericksheik.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9adjzTqJoBC2Mw28_ZpwAAAP4"]
[Tue Jul 21 08:39:34.394204 2026] [security2:error] [pid 465652:tid 465890] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9adjzTqJoBC2Mw28_ZqAAA8RY"]
[Tue Jul 21 08:39:34.464549 2026] [security2:error] [pid 465652:tid 465859] [client 20.220.225.223:54308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/else1.php"] [unique_id "al9adjzTqJoBC2Mw28_ZsQAAANI"]
[Tue Jul 21 08:39:34.497623 2026] [security2:error] [pid 466512:tid 466706] [client 85.113.70.242:56906] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "efrelectronics.com.br"] [uri "/"] [unique_id "al9adiKGokixMSfKDOcCHQAAAlQ"]
[Tue Jul 21 08:39:34.994569 2026] [security2:error] [pid 466512:tid 466647] [client 8.229.228.188:51663] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ericksheik.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9adiKGokixMSfKDOcCJgAAAhk"]
[Tue Jul 21 08:39:35.187120 2026] [security2:error] [pid 466512:tid 466663] [client 59.95.197.55:57451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9adyKGokixMSfKDOcCKQAAAik"]
[Tue Jul 21 08:39:35.187228 2026] [security2:error] [pid 466512:tid 466663] [client 59.95.197.55:57451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9adyKGokixMSfKDOcCKQAAAik"]
[Tue Jul 21 08:39:35.204503 2026] [security2:error] [pid 466512:tid 466682] [client 85.113.70.242:56900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.70.113.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-admin/options-general.php"] [unique_id "al9adyKGokixMSfKDOcCKgAAAjw"]
[Tue Jul 21 08:39:35.325494 2026] [security2:error] [pid 465652:tid 465878] [client 20.151.10.161:60784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/sixxis.php"] [unique_id "al9adzzTqJoBC2Mw28_ZwgAAAOU"]
[Tue Jul 21 08:39:35.444274 2026] [security2:error] [pid 466512:tid 466646] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9adyKGokixMSfKDOcCLwAAAhg"]
[Tue Jul 21 08:39:35.448331 2026] [security2:error] [pid 465652:tid 465852] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9adzzTqJoBC2Mw28_ZxwAAAMs"]
[Tue Jul 21 08:39:35.470567 2026] [security2:error] [pid 465652:tid 465820] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9adzzTqJoBC2Mw28_ZyAAAAKs"]
[Tue Jul 21 08:39:35.473311 2026] [security2:error] [pid 465652:tid 465805] [client 202.179.75.202:41788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9adzzTqJoBC2Mw28_ZyQAAAJw"]
[Tue Jul 21 08:39:35.473445 2026] [security2:error] [pid 465652:tid 465805] [client 202.179.75.202:41788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9adzzTqJoBC2Mw28_ZyQAAAJw"]
[Tue Jul 21 08:39:35.478950 2026] [security2:error] [pid 465652:tid 465827] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9adzzTqJoBC2Mw28_ZygAAALI"]
[Tue Jul 21 08:39:35.496440 2026] [security2:error] [pid 465652:tid 465850] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9adzzTqJoBC2Mw28_ZywAAAMk"]
[Tue Jul 21 08:39:35.505643 2026] [security2:error] [pid 466512:tid 466651] [client 5.38.115.39:28113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9adyKGokixMSfKDOcCMAAAAh0"]
[Tue Jul 21 08:39:35.505729 2026] [security2:error] [pid 466512:tid 466651] [client 5.38.115.39:28113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9adyKGokixMSfKDOcCMAAAAh0"]
[Tue Jul 21 08:39:35.506607 2026] [security2:error] [pid 466512:tid 466700] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9adyKGokixMSfKDOcCMQAAAk4"]
[Tue Jul 21 08:39:35.534426 2026] [security2:error] [pid 466512:tid 466754] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9adyKGokixMSfKDOcCMwAAAoQ"]
[Tue Jul 21 08:39:35.566697 2026] [security2:error] [pid 466512:tid 466714] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9adyKGokixMSfKDOcCNAAAAlw"]
[Tue Jul 21 08:39:35.743665 2026] [security2:error] [pid 465652:tid 465804] [client 8.229.228.188:51571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ericksheik.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9adzzTqJoBC2Mw28_Z0AAAAJs"]
[Tue Jul 21 08:39:35.776937 2026] [security2:error] [pid 466512:tid 466715] [client 216.73.160.182:31655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/wp-login.php"] [unique_id "al9adSKGokixMSfKDOcCFQAAAl0"]
[Tue Jul 21 08:39:35.844212 2026] [security2:error] [pid 466512:tid 466732] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9adyKGokixMSfKDOcCPQAAAm4"]
[Tue Jul 21 08:39:35.847028 2026] [security2:error] [pid 466512:tid 466718] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9adyKGokixMSfKDOcCPgAAAmA"]
[Tue Jul 21 08:39:35.856819 2026] [security2:error] [pid 466512:tid 466729] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9adyKGokixMSfKDOcCPwAAAms"]
[Tue Jul 21 08:39:35.891042 2026] [security2:error] [pid 466512:tid 466672] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9adyKGokixMSfKDOcCQgAAAjI"]
[Tue Jul 21 08:39:35.899181 2026] [security2:error] [pid 466512:tid 466733] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9adyKGokixMSfKDOcCQwAAAm8"]
[Tue Jul 21 08:39:35.922607 2026] [security2:error] [pid 466512:tid 466653] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9adyKGokixMSfKDOcCRAAAAh8"]
[Tue Jul 21 08:39:35.928915 2026] [security2:error] [pid 466512:tid 466663] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9adyKGokixMSfKDOcCRQAAAik"]
[Tue Jul 21 08:39:35.942003 2026] [security2:error] [pid 466512:tid 466682] [client 20.151.10.161:60704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/2P.update.php"] [unique_id "al9adyKGokixMSfKDOcCRgAAAjw"]
[Tue Jul 21 08:39:35.979225 2026] [security2:error] [pid 465652:tid 465806] [client 20.206.105.145:33692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9adzzTqJoBC2Mw28_Z1gAAAJ0"]
[Tue Jul 21 08:39:35.988353 2026] [security2:error] [pid 465652:tid 465872] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9adzzTqJoBC2Mw28_Z1wAAAN8"]
[Tue Jul 21 08:39:36.005088 2026] [security2:error] [pid 466512:tid 466662] [client 65.21.113.253:34250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9adyKGokixMSfKDOcCMgAAAig"]
[Tue Jul 21 08:39:36.020548 2026] [security2:error] [pid 465652:tid 465866] [client 5.31.193.106:1848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aeDzTqJoBC2Mw28_Z2AAAANk"]
[Tue Jul 21 08:39:36.020665 2026] [security2:error] [pid 465652:tid 465866] [client 5.31.193.106:1848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aeDzTqJoBC2Mw28_Z2AAAANk"]
[Tue Jul 21 08:39:36.058370 2026] [security2:error] [pid 466512:tid 466725] [client 173.252.95.30:63974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9aeCKGokixMSfKDOcCSAAAAmc"]
[Tue Jul 21 08:39:36.166102 2026] [security2:error] [pid 466512:tid 466688] [client 223.181.60.88:26873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aeCKGokixMSfKDOcCSwAAAkI"]
[Tue Jul 21 08:39:36.166251 2026] [security2:error] [pid 466512:tid 466688] [client 223.181.60.88:26873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aeCKGokixMSfKDOcCSwAAAkI"]
[Tue Jul 21 08:39:36.207191 2026] [security2:error] [pid 466512:tid 466754] [client 85.113.70.242:57388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "efrelectronics.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9aeCKGokixMSfKDOcCTgAAAoQ"]
[Tue Jul 21 08:39:36.225319 2026] [security2:error] [pid 466512:tid 466739] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9aeCKGokixMSfKDOcCUAAAAnU"]
[Tue Jul 21 08:39:36.232547 2026] [security2:error] [pid 466512:tid 466706] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9aeCKGokixMSfKDOcCUQAAAlQ"]
[Tue Jul 21 08:39:36.234526 2026] [security2:error] [pid 465652:tid 465903] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9aeDzTqJoBC2Mw28_Z3gAAAP4"]
[Tue Jul 21 08:39:36.273863 2026] [security2:error] [pid 465652:tid 465900] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9aeDzTqJoBC2Mw28_Z3wAAAPs"]
[Tue Jul 21 08:39:36.284167 2026] [security2:error] [pid 466512:tid 466679] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9aeCKGokixMSfKDOcCUgAAAjk"]
[Tue Jul 21 08:39:36.302220 2026] [security2:error] [pid 466512:tid 466674] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9aeCKGokixMSfKDOcCUwAAAjQ"]
[Tue Jul 21 08:39:36.317504 2026] [security2:error] [pid 466512:tid 466704] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9aeCKGokixMSfKDOcCVAAAAlI"]
[Tue Jul 21 08:39:36.334320 2026] [security2:error] [pid 466512:tid 466692] [client 20.151.10.161:60752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/a.php"] [unique_id "al9aeCKGokixMSfKDOcCVQAAAkY"]
[Tue Jul 21 08:39:36.375220 2026] [security2:error] [pid 466512:tid 466691] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9aeCKGokixMSfKDOcCVwAAAkU"]
[Tue Jul 21 08:39:36.448682 2026] [security2:error] [pid 466512:tid 466719] [client 8.229.228.188:53941] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ericksheik.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9aeCKGokixMSfKDOcCWAAAAmE"]
[Tue Jul 21 08:39:36.461397 2026] [security2:error] [pid 466512:tid 466664] [client 122.176.100.127:57634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aeCKGokixMSfKDOcCWQAAAio"]
[Tue Jul 21 08:39:36.461532 2026] [security2:error] [pid 466512:tid 466664] [client 122.176.100.127:57634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aeCKGokixMSfKDOcCWQAAAio"]
[Tue Jul 21 08:39:36.604498 2026] [security2:error] [pid 465652:tid 465783] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9aeDzTqJoBC2Mw28_Z6gAAAIY"]
[Tue Jul 21 08:39:36.609653 2026] [security2:error] [pid 465652:tid 465788] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9aeDzTqJoBC2Mw28_Z6wAAAIs"]
[Tue Jul 21 08:39:36.611717 2026] [security2:error] [pid 466512:tid 466753] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9aeCKGokixMSfKDOcCWgAAAoM"]
[Tue Jul 21 08:39:36.660020 2026] [security2:error] [pid 465652:tid 465817] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9aeDzTqJoBC2Mw28_Z7QAAAKg"]
[Tue Jul 21 08:39:36.660174 2026] [security2:error] [pid 465652:tid 465875] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9aeDzTqJoBC2Mw28_Z7AAAAOI"]
[Tue Jul 21 08:39:36.678164 2026] [security2:error] [pid 465652:tid 465819] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9aeDzTqJoBC2Mw28_Z7gAAAKo"]
[Tue Jul 21 08:39:36.721615 2026] [security2:error] [pid 466512:tid 466653] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9aeCKGokixMSfKDOcCWwAAAh8"]
[Tue Jul 21 08:39:36.779338 2026] [security2:error] [pid 466512:tid 466750] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9aeCKGokixMSfKDOcCXAAAAoA"]
[Tue Jul 21 08:39:36.911248 2026] [security2:error] [pid 466512:tid 466646] [client 20.151.10.161:51217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/k.php"] [unique_id "al9aeCKGokixMSfKDOcCYAAAAhg"]
[Tue Jul 21 08:39:36.987202 2026] [security2:error] [pid 466512:tid 466714] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9aeCKGokixMSfKDOcCYwAAAlw"]
[Tue Jul 21 08:39:36.989579 2026] [security2:error] [pid 465652:tid 465852] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9aeDzTqJoBC2Mw28_Z9gAAAMs"]
[Tue Jul 21 08:39:36.991666 2026] [security2:error] [pid 466512:tid 466675] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9aeCKGokixMSfKDOcCZAAAAjU"]
[Tue Jul 21 08:39:37.023671 2026] [security2:error] [pid 466512:tid 466739] [client 20.220.225.223:40763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/tkikikoko.php"] [unique_id "al9aeSKGokixMSfKDOcCZQAAAnU"]
[Tue Jul 21 08:39:37.039867 2026] [security2:error] [pid 466512:tid 466716] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9aeSKGokixMSfKDOcCZgAAAl4"]
[Tue Jul 21 08:39:37.043132 2026] [security2:error] [pid 466512:tid 466698] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9aeSKGokixMSfKDOcCZwAAAkw"]
[Tue Jul 21 08:39:37.057295 2026] [security2:error] [pid 466512:tid 466706] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9aeSKGokixMSfKDOcCaQAAAlQ"]
[Tue Jul 21 08:39:37.099402 2026] [security2:error] [pid 465652:tid 465820] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9aeTzTqJoBC2Mw28_Z-QAAAKs"]
[Tue Jul 21 08:39:37.150086 2026] [security2:error] [pid 465652:tid 465873] [client 8.229.228.188:54393] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ericksheik.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9aeTzTqJoBC2Mw28_Z-gAAAOA"]
[Tue Jul 21 08:39:37.151245 2026] [security2:error] [pid 466512:tid 466679] [client 198.44.157.34:42152] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9aeSKGokixMSfKDOcCbQAAAjk"]
[Tue Jul 21 08:39:37.151362 2026] [security2:error] [pid 466512:tid 466679] [client 198.44.157.34:42152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9aeSKGokixMSfKDOcCbQAAAjk"]
[Tue Jul 21 08:39:37.154017 2026] [security2:error] [pid 466512:tid 466761] [client 195.206.105.227:44076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9aeSKGokixMSfKDOcCbgAAAos"]
[Tue Jul 21 08:39:37.154118 2026] [security2:error] [pid 466512:tid 466761] [client 195.206.105.227:44076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9aeSKGokixMSfKDOcCbgAAAos"]
[Tue Jul 21 08:39:37.165908 2026] [security2:error] [pid 466512:tid 466674] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9aeSKGokixMSfKDOcCbwAAAjQ"]
[Tue Jul 21 08:39:37.206149 2026] [security2:error] [pid 465652:tid 465795] [client 85.113.70.242:57366] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "264"] [id "900296"] [msg "Gravity Forms Unsecured Upload Attempt"] [hostname "efrelectronics.com.br"] [uri "/"] [unique_id "al9aeTzTqJoBC2Mw28_Z_wAAAJI"]
[Tue Jul 21 08:39:37.366036 2026] [security2:error] [pid 466512:tid 466664] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aeSKGokixMSfKDOcCcQAAAio"]
[Tue Jul 21 08:39:37.371890 2026] [security2:error] [pid 466512:tid 466764] [client 20.63.100.92:7728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/fz.php"] [unique_id "al9aeSKGokixMSfKDOcCcgAAAo4"]
[Tue Jul 21 08:39:37.374909 2026] [security2:error] [pid 466512:tid 466705] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aeSKGokixMSfKDOcCcwAAAlM"]
[Tue Jul 21 08:39:37.379266 2026] [security2:error] [pid 466512:tid 466687] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aeSKGokixMSfKDOcCdAAAAkE"]
[Tue Jul 21 08:39:37.423598 2026] [security2:error] [pid 466512:tid 466733] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aeSKGokixMSfKDOcCdgAAAm8"]
[Tue Jul 21 08:39:37.423679 2026] [security2:error] [pid 465652:tid 465785] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aeTzTqJoBC2Mw28_aAgAAAIg"]
[Tue Jul 21 08:39:37.445401 2026] [security2:error] [pid 466512:tid 466647] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aeSKGokixMSfKDOcCeAAAAhk"]
[Tue Jul 21 08:39:37.508372 2026] [security2:error] [pid 466512:tid 466671] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aeSKGokixMSfKDOcCewAAAjE"]
[Tue Jul 21 08:39:37.552085 2026] [security2:error] [pid 465652:tid 465835] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aeTzTqJoBC2Mw28_aBQAAALo"]
[Tue Jul 21 08:39:37.740245 2026] [security2:error] [pid 465652:tid 465854] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9aeTzTqJoBC2Mw28_aBwAAAM0"]
[Tue Jul 21 08:39:37.770590 2026] [security2:error] [pid 466512:tid 466762] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9aeSKGokixMSfKDOcCfQAAAow"]
[Tue Jul 21 08:39:37.771990 2026] [security2:error] [pid 466512:tid 466745] [client 65.21.113.253:34250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aeSKGokixMSfKDOcCcAAAAns"]
[Tue Jul 21 08:39:37.773501 2026] [security2:error] [pid 466512:tid 466651] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9aeSKGokixMSfKDOcCfgAAAh0"]
[Tue Jul 21 08:39:37.799646 2026] [security2:error] [pid 465652:tid 465897] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9aeTzTqJoBC2Mw28_aCgAAAPg"]
[Tue Jul 21 08:39:37.800240 2026] [security2:error] [pid 466512:tid 466754] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9aeSKGokixMSfKDOcCfwAAAoQ"]
[Tue Jul 21 08:39:37.823345 2026] [security2:error] [pid 465652:tid 465891] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9aeTzTqJoBC2Mw28_aCwAAAPI"]
[Tue Jul 21 08:39:37.872064 2026] [security2:error] [pid 465652:tid 465908] [client 8.229.228.188:59241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ericksheik.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9aeTzTqJoBC2Mw28_aDAAAAQM"]
[Tue Jul 21 08:39:37.888315 2026] [security2:error] [pid 466512:tid 466663] [client 14.245.224.124:59945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aeSKGokixMSfKDOcCgAAAAik"]
[Tue Jul 21 08:39:37.888409 2026] [security2:error] [pid 466512:tid 466663] [client 14.245.224.124:59945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aeSKGokixMSfKDOcCgAAAAik"]
[Tue Jul 21 08:39:37.908276 2026] [security2:error] [pid 465652:tid 465883] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9aeTzTqJoBC2Mw28_aDQAAAOo"]
[Tue Jul 21 08:39:37.986018 2026] [security2:error] [pid 466512:tid 466716] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9aeSKGokixMSfKDOcCggAAAl4"]
[Tue Jul 21 08:39:38.117971 2026] [security2:error] [pid 465652:tid 465859] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9aejzTqJoBC2Mw28_aEQAAANI"]
[Tue Jul 21 08:39:38.191462 2026] [security2:error] [pid 466512:tid 466679] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9aeiKGokixMSfKDOcChgAAAjk"]
[Tue Jul 21 08:39:38.222435 2026] [security2:error] [pid 465652:tid 465886] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9aejzTqJoBC2Mw28_aFQAAAO0"]
[Tue Jul 21 08:39:38.223150 2026] [security2:error] [pid 466512:tid 466761] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9aeiKGokixMSfKDOcChwAAAos"]
[Tue Jul 21 08:39:38.228931 2026] [security2:error] [pid 466512:tid 466674] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9aeiKGokixMSfKDOcCiAAAAjQ"]
[Tue Jul 21 08:39:38.233112 2026] [security2:error] [pid 466512:tid 466656] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9aeiKGokixMSfKDOcCiQAAAiI"]
[Tue Jul 21 08:39:38.297989 2026] [security2:error] [pid 466512:tid 466715] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9aeiKGokixMSfKDOcCjAAAAl0"]
[Tue Jul 21 08:39:38.331721 2026] [security2:error] [pid 466512:tid 466617] [remote 167.71.218.184:50880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9aeiKGokixMSfKDOcCjQACTmg"]
[Tue Jul 21 08:39:38.336963 2026] [security2:error] [pid 465652:tid 465662] [remote 4.205.168.44:48498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-login.php"] [unique_id "al9aejzTqJoBC2Mw28_aFwAAwwk"]
[Tue Jul 21 08:39:38.386798 2026] [security2:error] [pid 466512:tid 466732] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9aeiKGokixMSfKDOcCjgAAAm4"]
[Tue Jul 21 08:39:38.497685 2026] [security2:error] [pid 465652:tid 465817] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9aejzTqJoBC2Mw28_aGwAAAKg"]
[Tue Jul 21 08:39:38.571692 2026] [security2:error] [pid 465652:tid 465809] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9aejzTqJoBC2Mw28_aHgAAAKA"]
[Tue Jul 21 08:39:38.603991 2026] [security2:error] [pid 466512:tid 466719] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9aeiKGokixMSfKDOcCjwAAAmE"]
[Tue Jul 21 08:39:38.605445 2026] [security2:error] [pid 465652:tid 465856] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9aejzTqJoBC2Mw28_aHwAAAM8"]
[Tue Jul 21 08:39:38.608223 2026] [security2:error] [pid 465652:tid 465828] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9aejzTqJoBC2Mw28_aIAAAALM"]
[Tue Jul 21 08:39:38.609459 2026] [security2:error] [pid 465652:tid 465797] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9aejzTqJoBC2Mw28_aIQAAAJQ"]
[Tue Jul 21 08:39:38.678149 2026] [security2:error] [pid 465652:tid 465821] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9aejzTqJoBC2Mw28_aIgAAAKw"]
[Tue Jul 21 08:39:38.678729 2026] [security2:error] [pid 465652:tid 465838] [client 20.151.10.161:60740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/w.php"] [unique_id "al9aejzTqJoBC2Mw28_aIwAAAL0"]
[Tue Jul 21 08:39:38.789834 2026] [security2:error] [pid 465652:tid 465902] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9aejzTqJoBC2Mw28_aJgAAAP0"]
[Tue Jul 21 08:39:38.793035 2026] [security2:error] [pid 465652:tid 465864] [client 195.49.128.211:64739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aejzTqJoBC2Mw28_aJwAAANc"]
[Tue Jul 21 08:39:38.793122 2026] [security2:error] [pid 465652:tid 465864] [client 195.49.128.211:64739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aejzTqJoBC2Mw28_aJwAAANc"]
[Tue Jul 21 08:39:38.836601 2026] [security2:error] [pid 465652:tid 465789] [client 173.252.95.58:41088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9aejzTqJoBC2Mw28_aKQAAAIw"]
[Tue Jul 21 08:39:38.947356 2026] [security2:error] [pid 465652:tid 465873] [client 173.252.95.27:36258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9aejzTqJoBC2Mw28_aKgAAAOA"]
[Tue Jul 21 08:39:38.959978 2026] [security2:error] [pid 465652:tid 465827] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9aejzTqJoBC2Mw28_aKwAAALI"]
[Tue Jul 21 08:39:39.013678 2026] [security2:error] [pid 465652:tid 465799] [client 20.206.105.145:33680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/adminfuns.php"] [unique_id "al9aezzTqJoBC2Mw28_aLwAAAJY"]
[Tue Jul 21 08:39:39.072043 2026] [security2:error] [pid 466512:tid 466653] [client 20.151.10.161:60683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/insc.php"] [unique_id "al9aeyKGokixMSfKDOcCkgAAAh8"]
[Tue Jul 21 08:39:39.080267 2026] [security2:error] [pid 466512:tid 466671] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9aeyKGokixMSfKDOcCkwAAAjE"]
[Tue Jul 21 08:39:39.091762 2026] [security2:error] [pid 465652:tid 465807] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9aezzTqJoBC2Mw28_aMQAAAJ4"]
[Tue Jul 21 08:39:39.196171 2026] [security2:error] [pid 466512:tid 466688] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9aeyKGokixMSfKDOcClAAAAkI"]
[Tue Jul 21 08:39:39.211566 2026] [security2:error] [pid 465652:tid 465885] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9aezzTqJoBC2Mw28_aMwAAAOw"]
[Tue Jul 21 08:39:39.234139 2026] [security2:error] [pid 465652:tid 465866] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9aezzTqJoBC2Mw28_aNAAAANk"]
[Tue Jul 21 08:39:39.239387 2026] [security2:error] [pid 465652:tid 465897] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9aezzTqJoBC2Mw28_aNQAAAPg"]
[Tue Jul 21 08:39:39.244895 2026] [security2:error] [pid 465652:tid 465891] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9aezzTqJoBC2Mw28_aNgAAAPI"]
[Tue Jul 21 08:39:39.273668 2026] [autoindex:error] [pid 466512:tid 466714] [client 205.210.31.143:64788] AH01276: Cannot serve directory /home4/ciclod61/bahtelecom.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:39:39.317341 2026] [security2:error] [pid 466512:tid 466664] [client 103.59.206.240:31073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aeyKGokixMSfKDOcCmwAAAio"]
[Tue Jul 21 08:39:39.317516 2026] [security2:error] [pid 466512:tid 466664] [client 103.59.206.240:31073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aeyKGokixMSfKDOcCmwAAAio"]
[Tue Jul 21 08:39:39.340252 2026] [security2:error] [pid 466512:tid 466698] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9aeyKGokixMSfKDOcCnQAAAkw"]
[Tue Jul 21 08:39:39.467878 2026] [security2:error] [pid 466512:tid 466713] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9aeyKGokixMSfKDOcCogAAAls"]
[Tue Jul 21 08:39:39.488650 2026] [security2:error] [pid 466512:tid 466732] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9aeyKGokixMSfKDOcCowAAAm4"]
[Tue Jul 21 08:39:39.520891 2026] [security2:error] [pid 466512:tid 466764] [client 152.59.34.51:62140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aeyKGokixMSfKDOcCpAAAAo4"]
[Tue Jul 21 08:39:39.525834 2026] [security2:error] [pid 466512:tid 466764] [client 152.59.34.51:62140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aeyKGokixMSfKDOcCpAAAAo4"]
[Tue Jul 21 08:39:39.589601 2026] [security2:error] [pid 465652:tid 465863] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9aezzTqJoBC2Mw28_aPwAAANY"]
[Tue Jul 21 08:39:39.604214 2026] [security2:error] [pid 466512:tid 466741] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9aeyKGokixMSfKDOcCqQAAAnc"]
[Tue Jul 21 08:39:39.609523 2026] [security2:error] [pid 465652:tid 465851] [client 152.59.181.104:42359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aezzTqJoBC2Mw28_aQAAAAMo"]
[Tue Jul 21 08:39:39.609629 2026] [security2:error] [pid 465652:tid 465851] [client 152.59.181.104:42359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9aezzTqJoBC2Mw28_aQAAAAMo"]
[Tue Jul 21 08:39:39.620940 2026] [security2:error] [pid 466512:tid 466706] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9aeyKGokixMSfKDOcCqgAAAlQ"]
[Tue Jul 21 08:39:39.626406 2026] [security2:error] [pid 465652:tid 465786] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9aezzTqJoBC2Mw28_aQQAAAIk"]
[Tue Jul 21 08:39:39.636980 2026] [security2:error] [pid 466512:tid 466705] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9aeyKGokixMSfKDOcCqwAAAlM"]
[Tue Jul 21 08:39:39.658047 2026] [security2:error] [pid 466512:tid 466721] [client 69.171.230.38:62790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9aeyKGokixMSfKDOcCrAAAAmM"]
[Tue Jul 21 08:39:39.718213 2026] [security2:error] [pid 465652:tid 465884] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9aezzTqJoBC2Mw28_aRAAAAOs"]
[Tue Jul 21 08:39:39.853472 2026] [security2:error] [pid 466512:tid 466716] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9aeyKGokixMSfKDOcCtAAAAl4"]
[Tue Jul 21 08:39:39.867766 2026] [security2:error] [pid 466512:tid 466664] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9aeyKGokixMSfKDOcCtQAAAio"]
[Tue Jul 21 08:39:39.933156 2026] [security2:error] [pid 466512:tid 466704] [client 20.151.10.161:60689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9aeyKGokixMSfKDOcCuAAAAlI"]
[Tue Jul 21 08:39:39.996594 2026] [security2:error] [pid 466512:tid 466766] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9aeyKGokixMSfKDOcCuQAAApA"]
[Tue Jul 21 08:39:39.997769 2026] [security2:error] [pid 465652:tid 465901] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9aezzTqJoBC2Mw28_aSQAAAPw"]
[Tue Jul 21 08:39:40.009267 2026] [security2:error] [pid 465652:tid 465856] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9afDzTqJoBC2Mw28_aSgAAAM8"]
[Tue Jul 21 08:39:40.009464 2026] [security2:error] [pid 466512:tid 466679] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9afCKGokixMSfKDOcCugAAAjk"]
[Tue Jul 21 08:39:40.021326 2026] [security2:error] [pid 466512:tid 466703] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9afCKGokixMSfKDOcCuwAAAlE"]
[Tue Jul 21 08:39:40.118985 2026] [security2:error] [pid 466512:tid 466732] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9afCKGokixMSfKDOcCvgAAAm4"]
[Tue Jul 21 08:39:40.151295 2026] [security2:error] [pid 466512:tid 466682] [client 61.1.167.83:52145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9afCKGokixMSfKDOcCwAAAAjw"]
[Tue Jul 21 08:39:40.151489 2026] [security2:error] [pid 466512:tid 466682] [client 61.1.167.83:52145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9afCKGokixMSfKDOcCwAAAAjw"]
[Tue Jul 21 08:39:40.230363 2026] [security2:error] [pid 465652:tid 465894] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9afDzTqJoBC2Mw28_aTwAAAPU"]
[Tue Jul 21 08:39:40.246097 2026] [security2:error] [pid 466512:tid 466670] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9afCKGokixMSfKDOcCxAAAAjA"]
[Tue Jul 21 08:39:40.378123 2026] [security2:error] [pid 466512:tid 466687] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9afCKGokixMSfKDOcCxwAAAkE"]
[Tue Jul 21 08:39:40.389613 2026] [security2:error] [pid 466512:tid 466672] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9afCKGokixMSfKDOcCyAAAAjI"]
[Tue Jul 21 08:39:40.409561 2026] [security2:error] [pid 466512:tid 466753] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9afCKGokixMSfKDOcCygAAAoM"]
[Tue Jul 21 08:39:40.412523 2026] [security2:error] [pid 466512:tid 466671] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9afCKGokixMSfKDOcCywAAAjE"]
[Tue Jul 21 08:39:40.415383 2026] [security2:error] [pid 466512:tid 466655] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9afCKGokixMSfKDOcCzAAAAiE"]
[Tue Jul 21 08:39:40.498009 2026] [security2:error] [pid 465652:tid 465789] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9afDzTqJoBC2Mw28_aVAAAAIw"]
[Tue Jul 21 08:39:40.608677 2026] [security2:error] [pid 466512:tid 466739] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9afCKGokixMSfKDOcC0AAAAnU"]
[Tue Jul 21 08:39:40.629735 2026] [security2:error] [pid 466512:tid 466714] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9afCKGokixMSfKDOcC0QAAAlw"]
[Tue Jul 21 08:39:40.773538 2026] [security2:error] [pid 466512:tid 466647] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9afCKGokixMSfKDOcC0gAAAhk"]
[Tue Jul 21 08:39:40.780408 2026] [security2:error] [pid 466512:tid 466674] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9afCKGokixMSfKDOcC0wAAAjQ"]
[Tue Jul 21 08:39:40.783046 2026] [security2:error] [pid 466512:tid 466769] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9afCKGokixMSfKDOcC1AAAApM"]
[Tue Jul 21 08:39:40.798007 2026] [security2:error] [pid 466512:tid 466703] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9afCKGokixMSfKDOcC1QAAAlE"]
[Tue Jul 21 08:39:40.806886 2026] [security2:error] [pid 466512:tid 466645] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9afCKGokixMSfKDOcC1gAAAhc"]
[Tue Jul 21 08:39:40.880873 2026] [security2:error] [pid 466512:tid 466700] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9afCKGokixMSfKDOcC3AAAAk4"]
[Tue Jul 21 08:39:40.961536 2026] [security2:error] [pid 466512:tid 466759] [client 20.206.105.145:33739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/goods.php"] [unique_id "al9afCKGokixMSfKDOcC3gAAAok"]
[Tue Jul 21 08:39:40.997008 2026] [security2:error] [pid 466512:tid 466741] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9afCKGokixMSfKDOcC4wAAAnc"]
[Tue Jul 21 08:39:41.013798 2026] [security2:error] [pid 465652:tid 465804] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9afTzTqJoBC2Mw28_aXgAAAJs"]
[Tue Jul 21 08:39:41.162138 2026] [security2:error] [pid 466512:tid 466705] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9afSKGokixMSfKDOcC5QAAAlM"]
[Tue Jul 21 08:39:41.162452 2026] [security2:error] [pid 466512:tid 466753] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9afSKGokixMSfKDOcC5gAAAoM"]
[Tue Jul 21 08:39:41.163652 2026] [security2:error] [pid 465652:tid 465885] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9afTzTqJoBC2Mw28_aYgAAAOw"]
[Tue Jul 21 08:39:41.198511 2026] [security2:error] [pid 466512:tid 466657] [client 85.113.70.242:57376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.70.113.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-admin/options-general.php"] [unique_id "al9afSKGokixMSfKDOcC5wAAAiM"]
[Tue Jul 21 08:39:41.216261 2026] [security2:error] [pid 466512:tid 466725] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9afSKGokixMSfKDOcC6AAAAmc"]
[Tue Jul 21 08:39:41.231537 2026] [security2:error] [pid 466512:tid 466688] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9afSKGokixMSfKDOcC6QAAAkI"]
[Tue Jul 21 08:39:41.268301 2026] [security2:error] [pid 466512:tid 466762] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9afSKGokixMSfKDOcC6gAAAow"]
[Tue Jul 21 08:39:41.305796 2026] [security2:error] [pid 466512:tid 466713] [client 49.144.66.253:31808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9afSKGokixMSfKDOcC7QAAAls"]
[Tue Jul 21 08:39:41.305932 2026] [proxy:error] [pid 466512:tid 466739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:41.306001 2026] [proxy_http:error] [pid 466512:tid 466739] [client 85.204.70.98:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:39:41.306047 2026] [security2:error] [pid 466512:tid 466713] [client 49.144.66.253:31808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9afSKGokixMSfKDOcC7QAAAls"]
[Tue Jul 21 08:39:41.308491 2026] [proxy:error] [pid 466512:tid 466739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:41.308567 2026] [proxy_http:error] [pid 466512:tid 466739] [client 85.204.70.98:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:39:41.382668 2026] [security2:error] [pid 466512:tid 466664] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9afSKGokixMSfKDOcC8gAAAio"]
[Tue Jul 21 08:39:41.401369 2026] [security2:error] [pid 466512:tid 466580] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9afSKGokixMSfKDOcC8wACgEM"]
[Tue Jul 21 08:39:41.401527 2026] [security2:error] [pid 466512:tid 466750] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9afSKGokixMSfKDOcC8wACgEM"]
[Tue Jul 21 08:39:41.403495 2026] [security2:error] [pid 466512:tid 466647] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9afSKGokixMSfKDOcC9AAAAhk"]
[Tue Jul 21 08:39:41.555314 2026] [security2:error] [pid 466512:tid 466754] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9afSKGokixMSfKDOcC9wAAAoQ"]
[Tue Jul 21 08:39:41.557876 2026] [security2:error] [pid 466512:tid 466698] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9afSKGokixMSfKDOcC-AAAAkw"]
[Tue Jul 21 08:39:41.557974 2026] [security2:error] [pid 466512:tid 466700] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9afSKGokixMSfKDOcC-QAAAk4"]
[Tue Jul 21 08:39:41.581161 2026] [proxy:error] [pid 466512:tid 466759] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:41.581217 2026] [proxy_http:error] [pid 466512:tid 466759] [client 85.204.70.98:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:39:41.581859 2026] [proxy:error] [pid 466512:tid 466759] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:41.581900 2026] [proxy_http:error] [pid 466512:tid 466759] [client 85.204.70.98:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:39:41.602805 2026] [security2:error] [pid 466512:tid 466642] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9afSKGokixMSfKDOcC-wAAAhQ"]
[Tue Jul 21 08:39:41.622334 2026] [security2:error] [pid 466512:tid 466651] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9afSKGokixMSfKDOcC_AAAAh0"]
[Tue Jul 21 08:39:41.650244 2026] [security2:error] [pid 466512:tid 466707] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9afSKGokixMSfKDOcC_QAAAlU"]
[Tue Jul 21 08:39:41.756283 2026] [security2:error] [pid 466512:tid 466653] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9afSKGokixMSfKDOcDAAAAAh8"]
[Tue Jul 21 08:39:41.801409 2026] [security2:error] [pid 466512:tid 466646] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9afSKGokixMSfKDOcDAwAAAhg"]
[Tue Jul 21 08:39:41.855035 2026] [security2:error] [pid 466512:tid 466663] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9afSKGokixMSfKDOcDBQAAAik"]
[Tue Jul 21 08:39:41.943724 2026] [security2:error] [pid 466512:tid 466706] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9afSKGokixMSfKDOcDBwAAAlQ"]
[Tue Jul 21 08:39:41.947895 2026] [security2:error] [pid 466512:tid 466687] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9afSKGokixMSfKDOcDCAAAAkE"]
[Tue Jul 21 08:39:41.949876 2026] [security2:error] [pid 466512:tid 466763] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9afSKGokixMSfKDOcDCQAAAo0"]
[Tue Jul 21 08:39:42.053636 2026] [security2:error] [pid 466512:tid 466716] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9afiKGokixMSfKDOcDCgAAAl4"]
[Tue Jul 21 08:39:42.054794 2026] [security2:error] [pid 465652:tid 465870] [client 213.152.162.15:45906] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9afTzTqJoBC2Mw28_aXwAAAN0"]
[Tue Jul 21 08:39:42.054921 2026] [security2:error] [pid 465652:tid 465870] [client 213.152.162.15:45906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9afTzTqJoBC2Mw28_aXwAAAN0"]
[Tue Jul 21 08:39:42.102176 2026] [security2:error] [pid 465652:tid 465851] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9afjzTqJoBC2Mw28_acAAAAMo"]
[Tue Jul 21 08:39:42.132589 2026] [security2:error] [pid 466512:tid 466750] [client 85.204.70.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9afiKGokixMSfKDOcDDQAAAoA"]
[Tue Jul 21 08:39:42.159180 2026] [security2:error] [pid 466512:tid 466721] [client 195.49.128.211:56187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9afiKGokixMSfKDOcDEAAAAmM"]
[Tue Jul 21 08:39:42.159292 2026] [security2:error] [pid 466512:tid 466721] [client 195.49.128.211:56187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9afiKGokixMSfKDOcDEAAAAmM"]
[Tue Jul 21 08:39:42.169478 2026] [security2:error] [pid 466512:tid 466645] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9afiKGokixMSfKDOcDEQAAAhc"]
[Tue Jul 21 08:39:42.234450 2026] [security2:error] [pid 465652:tid 465844] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9afjzTqJoBC2Mw28_adwAAAMM"]
[Tue Jul 21 08:39:42.241233 2026] [security2:error] [pid 465652:tid 465858] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9afjzTqJoBC2Mw28_aeQAAANE"]
[Tue Jul 21 08:39:42.336727 2026] [security2:error] [pid 466512:tid 466761] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9afiKGokixMSfKDOcDEwAAAos"]
[Tue Jul 21 08:39:42.339148 2026] [security2:error] [pid 466512:tid 466754] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9afiKGokixMSfKDOcDFAAAAoQ"]
[Tue Jul 21 08:39:42.341015 2026] [security2:error] [pid 466512:tid 466718] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9afiKGokixMSfKDOcDFQAAAmA"]
[Tue Jul 21 08:39:42.348005 2026] [security2:error] [pid 465652:tid 465892] [client 117.213.202.34:54133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9afjzTqJoBC2Mw28_aegAAAPM"]
[Tue Jul 21 08:39:42.348213 2026] [security2:error] [pid 465652:tid 465892] [client 117.213.202.34:54133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9afjzTqJoBC2Mw28_aegAAAPM"]
[Tue Jul 21 08:39:42.348212 2026] [security2:error] [pid 466512:tid 466698] [client 20.206.105.145:33746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/ms-edit.php"] [unique_id "al9afiKGokixMSfKDOcDFgAAAkw"]
[Tue Jul 21 08:39:42.425500 2026] [proxy:error] [pid 466512:tid 466764] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:42.425565 2026] [proxy_http:error] [pid 466512:tid 466764] [client 85.204.70.98:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:39:42.426183 2026] [proxy:error] [pid 466512:tid 466764] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:39:42.426209 2026] [proxy_http:error] [pid 466512:tid 466764] [client 85.204.70.98:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:39:42.455985 2026] [security2:error] [pid 465652:tid 465843] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9afjzTqJoBC2Mw28_afQAAAMI"]
[Tue Jul 21 08:39:42.489736 2026] [security2:error] [pid 465652:tid 465901] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9afjzTqJoBC2Mw28_afwAAAPw"]
[Tue Jul 21 08:39:42.568988 2026] [security2:error] [pid 465652:tid 465856] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9afjzTqJoBC2Mw28_agAAAAM8"]
[Tue Jul 21 08:39:42.649209 2026] [security2:error] [pid 465652:tid 465878] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9afjzTqJoBC2Mw28_agwAAAOU"]
[Tue Jul 21 08:39:42.655494 2026] [security2:error] [pid 466512:tid 466671] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9afiKGokixMSfKDOcDGgAAAjE"]
[Tue Jul 21 08:39:42.716176 2026] [security2:error] [pid 465652:tid 465838] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9afjzTqJoBC2Mw28_ahAAAAL0"]
[Tue Jul 21 08:39:42.718233 2026] [security2:error] [pid 466512:tid 466743] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9afiKGokixMSfKDOcDHAAAAnk"]
[Tue Jul 21 08:39:42.718353 2026] [security2:error] [pid 466512:tid 466657] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9afiKGokixMSfKDOcDHQAAAiM"]
[Tue Jul 21 08:39:42.720242 2026] [security2:error] [pid 466512:tid 466653] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9afiKGokixMSfKDOcDHgAAAh8"]
[Tue Jul 21 08:39:42.836803 2026] [security2:error] [pid 465652:tid 465864] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9afjzTqJoBC2Mw28_ahwAAANc"]
[Tue Jul 21 08:39:42.848279 2026] [security2:error] [pid 466512:tid 466643] [client 20.151.10.161:60767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/u.php"] [unique_id "al9afiKGokixMSfKDOcDIQAAAhU"]
[Tue Jul 21 08:39:42.898458 2026] [security2:error] [pid 466512:tid 466739] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9afiKGokixMSfKDOcDIgAAAnU"]
[Tue Jul 21 08:39:42.948581 2026] [security2:error] [pid 466512:tid 466687] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9afiKGokixMSfKDOcDIwAAAkE"]
[Tue Jul 21 08:39:42.993883 2026] [security2:error] [pid 466512:tid 466672] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9afiKGokixMSfKDOcDJQAAAjI"]
[Tue Jul 21 08:39:43.053707 2026] [security2:error] [pid 466512:tid 466750] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9afyKGokixMSfKDOcDKAAAAoA"]
[Tue Jul 21 08:39:43.087903 2026] [security2:error] [pid 466512:tid 466721] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9afyKGokixMSfKDOcDKQAAAmM"]
[Tue Jul 21 08:39:43.098713 2026] [security2:error] [pid 466512:tid 466645] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9afyKGokixMSfKDOcDKgAAAhc"]
[Tue Jul 21 08:39:43.098776 2026] [security2:error] [pid 466512:tid 466674] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9afyKGokixMSfKDOcDKwAAAjQ"]
[Tue Jul 21 08:39:43.103195 2026] [security2:error] [pid 466512:tid 466715] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9afyKGokixMSfKDOcDLAAAAl0"]
[Tue Jul 21 08:39:43.216978 2026] [security2:error] [pid 466512:tid 466700] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9afyKGokixMSfKDOcDMQAAAk4"]
[Tue Jul 21 08:39:43.269362 2026] [security2:error] [pid 465652:tid 465893] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9afzzTqJoBC2Mw28_ajAAAAPQ"]
[Tue Jul 21 08:39:43.276908 2026] [security2:error] [pid 466512:tid 466610] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9afyKGokixMSfKDOcDNAAChWE"]
[Tue Jul 21 08:39:43.277124 2026] [security2:error] [pid 466512:tid 466755] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9afyKGokixMSfKDOcDNAAChWE"]
[Tue Jul 21 08:39:43.291410 2026] [security2:error] [pid 466512:tid 466741] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9afyKGokixMSfKDOcDNwAAAnc"]
[Tue Jul 21 08:39:43.333657 2026] [security2:error] [pid 466512:tid 466719] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9afyKGokixMSfKDOcDOAAAAmE"]
[Tue Jul 21 08:39:43.456732 2026] [security2:error] [pid 465652:tid 465837] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9afzzTqJoBC2Mw28_ajwAAALw"]
[Tue Jul 21 08:39:43.474842 2026] [security2:error] [pid 466512:tid 466671] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9afyKGokixMSfKDOcDOQAAAjE"]
[Tue Jul 21 08:39:43.524649 2026] [security2:error] [pid 466512:tid 466657] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9afyKGokixMSfKDOcDOwAAAiM"]
[Tue Jul 21 08:39:43.538864 2026] [security2:error] [pid 466512:tid 466727] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9afyKGokixMSfKDOcDPQAAAmk"]
[Tue Jul 21 08:39:43.542290 2026] [security2:error] [pid 466512:tid 466663] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9afyKGokixMSfKDOcDQAAAAik"]
[Tue Jul 21 08:39:43.544954 2026] [security2:error] [pid 466512:tid 466713] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9afyKGokixMSfKDOcDQQAAAls"]
[Tue Jul 21 08:39:43.591433 2026] [security2:error] [pid 466512:tid 466749] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9afyKGokixMSfKDOcDQgAAAn8"]
[Tue Jul 21 08:39:43.677989 2026] [security2:error] [pid 465652:tid 465885] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9afzzTqJoBC2Mw28_alQAAAOw"]
[Tue Jul 21 08:39:43.686510 2026] [security2:error] [pid 466512:tid 466670] [client 20.206.105.145:33732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/222.php"] [unique_id "al9afyKGokixMSfKDOcDQwAAAjA"]
[Tue Jul 21 08:39:43.712620 2026] [security2:error] [pid 466512:tid 466716] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9afyKGokixMSfKDOcDRAAAAl4"]
[Tue Jul 21 08:39:43.816675 2026] [security2:error] [pid 465652:tid 465891] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9afzzTqJoBC2Mw28_amAAAAPI"]
[Tue Jul 21 08:39:43.848710 2026] [security2:error] [pid 466512:tid 466703] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9afyKGokixMSfKDOcDRgAAAlE"]
[Tue Jul 21 08:39:43.871315 2026] [security2:error] [pid 466512:tid 466721] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9afyKGokixMSfKDOcDRwAAAmM"]
[Tue Jul 21 08:39:43.901036 2026] [security2:error] [pid 466512:tid 466674] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9afyKGokixMSfKDOcDSAAAAjQ"]
[Tue Jul 21 08:39:43.924103 2026] [security2:error] [pid 466512:tid 466715] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9afyKGokixMSfKDOcDSQAAAl0"]
[Tue Jul 21 08:39:43.927496 2026] [security2:error] [pid 466512:tid 466768] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9afyKGokixMSfKDOcDSgAAApI"]
[Tue Jul 21 08:39:44.020502 2026] [security2:error] [pid 466512:tid 466692] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9agCKGokixMSfKDOcDSwAAAkY"]
[Tue Jul 21 08:39:44.063407 2026] [security2:error] [pid 465652:tid 465903] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9agDzTqJoBC2Mw28_anAAAAP4"]
[Tue Jul 21 08:39:44.089643 2026] [security2:error] [pid 466512:tid 466732] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9agCKGokixMSfKDOcDTAAAAm4"]
[Tue Jul 21 08:39:44.092295 2026] [security2:error] [pid 466512:tid 466688] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9agCKGokixMSfKDOcDTQAAAkI"]
[Tue Jul 21 08:39:44.247329 2026] [security2:error] [pid 465652:tid 465796] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9agDzTqJoBC2Mw28_aoQAAAJM"]
[Tue Jul 21 08:39:44.251446 2026] [security2:error] [pid 466512:tid 466667] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9agCKGokixMSfKDOcDUgAAAi0"]
[Tue Jul 21 08:39:44.278525 2026] [security2:error] [pid 466512:tid 466729] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9agCKGokixMSfKDOcDUwAAAms"]
[Tue Jul 21 08:39:44.308679 2026] [security2:error] [pid 466512:tid 466659] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9agCKGokixMSfKDOcDVAAAAiU"]
[Tue Jul 21 08:39:44.310433 2026] [security2:error] [pid 466512:tid 466738] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9agCKGokixMSfKDOcDVQAAAnQ"]
[Tue Jul 21 08:39:44.363274 2026] [security2:error] [pid 466512:tid 466662] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9agCKGokixMSfKDOcDVgAAAig"]
[Tue Jul 21 08:39:44.393870 2026] [security2:error] [pid 466512:tid 466743] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9agCKGokixMSfKDOcDWAAAAnk"]
[Tue Jul 21 08:39:44.396018 2026] [security2:error] [pid 466512:tid 466717] [client 114.119.134.231:23043] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "valordisruptivo.com.br"] [uri "/favicon.ico"] [unique_id "al9agCKGokixMSfKDOcDWQAAAl8"], referer: https://valordisruptivo.com.br/favicon.ico
[Tue Jul 21 08:39:44.447211 2026] [security2:error] [pid 465652:tid 465858] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9agDzTqJoBC2Mw28_aqQAAANE"]
[Tue Jul 21 08:39:44.505402 2026] [security2:error] [pid 465652:tid 465875] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9agDzTqJoBC2Mw28_asAAAAOI"]
[Tue Jul 21 08:39:44.624417 2026] [security2:error] [pid 466512:tid 466687] [client 20.206.105.145:33729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9agCKGokixMSfKDOcDXgAAAkE"]
[Tue Jul 21 08:39:44.635926 2026] [security2:error] [pid 466512:tid 466672] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9agCKGokixMSfKDOcDXwAAAjI"]
[Tue Jul 21 08:39:44.671920 2026] [security2:error] [pid 466512:tid 466716] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9agCKGokixMSfKDOcDYAAAAl4"]
[Tue Jul 21 08:39:44.676576 2026] [security2:error] [pid 466512:tid 466714] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9agCKGokixMSfKDOcDYQAAAlw"]
[Tue Jul 21 08:39:44.680585 2026] [security2:error] [pid 465652:tid 465890] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9agDzTqJoBC2Mw28_aswAAAPE"]
[Tue Jul 21 08:39:44.698562 2026] [security2:error] [pid 466512:tid 466664] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9agCKGokixMSfKDOcDYgAAAio"]
[Tue Jul 21 08:39:44.702381 2026] [security2:error] [pid 466512:tid 466763] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9agCKGokixMSfKDOcDYwAAAo0"]
[Tue Jul 21 08:39:44.769545 2026] [security2:error] [pid 466512:tid 466647] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9agCKGokixMSfKDOcDZAAAAhk"]
[Tue Jul 21 08:39:44.835536 2026] [security2:error] [pid 465652:tid 465825] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9agDzTqJoBC2Mw28_atgAAALA"]
[Tue Jul 21 08:39:44.886908 2026] [security2:error] [pid 466512:tid 466715] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9agCKGokixMSfKDOcDaAAAAl0"]
[Tue Jul 21 08:39:44.908965 2026] [security2:error] [pid 466512:tid 466680] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9agCKGokixMSfKDOcDaQAAAjo"]
[Tue Jul 21 08:39:45.041322 2026] [security2:error] [pid 465652:tid 465901] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9agDzTqJoBC2Mw28_auQAA_C4"]
[Tue Jul 21 08:39:45.049644 2026] [security2:error] [pid 466512:tid 466732] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9agSKGokixMSfKDOcDbQAAAm4"]
[Tue Jul 21 08:39:45.065094 2026] [security2:error] [pid 466512:tid 466688] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9agSKGokixMSfKDOcDbgAAAkI"]
[Tue Jul 21 08:39:45.085660 2026] [security2:error] [pid 466512:tid 466759] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9agSKGokixMSfKDOcDbwAAAok"]
[Tue Jul 21 08:39:45.086965 2026] [security2:error] [pid 466512:tid 466642] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9agSKGokixMSfKDOcDcAAAAhQ"]
[Tue Jul 21 08:39:45.095753 2026] [security2:error] [pid 465652:tid 465838] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9agTzTqJoBC2Mw28_avAAAAL0"]
[Tue Jul 21 08:39:45.095752 2026] [security2:error] [pid 465652:tid 465821] [client 20.151.10.161:60720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/sss.php"] [unique_id "al9agTzTqJoBC2Mw28_auwAAAKw"]
[Tue Jul 21 08:39:45.157439 2026] [security2:error] [pid 465652:tid 465848] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9agTzTqJoBC2Mw28_avQAAAMc"]
[Tue Jul 21 08:39:45.181246 2026] [security2:error] [pid 466512:tid 466741] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9agSKGokixMSfKDOcDcwAAAnc"]
[Tue Jul 21 08:39:45.240949 2026] [security2:error] [pid 466512:tid 466753] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9agSKGokixMSfKDOcDdgAAAoM"]
[Tue Jul 21 08:39:45.270827 2026] [security2:error] [pid 466512:tid 466738] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9agSKGokixMSfKDOcDdwAAAnQ"]
[Tue Jul 21 08:39:45.311929 2026] [security2:error] [pid 466512:tid 466657] [client 20.206.105.145:33786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9agSKGokixMSfKDOcDeQAAAiM"]
[Tue Jul 21 08:39:45.428921 2026] [security2:error] [pid 466512:tid 466762] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9agSKGokixMSfKDOcDegAAAow"]
[Tue Jul 21 08:39:45.447730 2026] [security2:error] [pid 465652:tid 465822] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9agTzTqJoBC2Mw28_axQAAAK0"]
[Tue Jul 21 08:39:45.452575 2026] [security2:error] [pid 466512:tid 466605] [remote 159.65.81.207:35976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "novoar.net.br"] [uri "/wp-login.php"] [unique_id "al9agSKGokixMSfKDOcDewACHVw"]
[Tue Jul 21 08:39:45.454330 2026] [security2:error] [pid 466512:tid 466653] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9agSKGokixMSfKDOcDfAAAAh8"]
[Tue Jul 21 08:39:45.463644 2026] [security2:error] [pid 466512:tid 466720] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9agSKGokixMSfKDOcDfQAAAmI"]
[Tue Jul 21 08:39:45.465333 2026] [security2:error] [pid 465652:tid 465852] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9agTzTqJoBC2Mw28_axgAAAMs"]
[Tue Jul 21 08:39:45.481743 2026] [security2:error] [pid 466512:tid 466706] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9agSKGokixMSfKDOcDfgAAAlQ"]
[Tue Jul 21 08:39:45.539971 2026] [security2:error] [pid 465652:tid 465810] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9agTzTqJoBC2Mw28_ayAAAAKE"]
[Tue Jul 21 08:39:45.624451 2026] [autoindex:error] [pid 465652:tid 465816] [client 198.235.24.35:62076] AH01276: Cannot serve directory /home3/eltonf08/efrelectronics.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:39:45.636610 2026] [security2:error] [pid 466512:tid 466763] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9agSKGokixMSfKDOcDgAAAAo0"]
[Tue Jul 21 08:39:45.654703 2026] [security2:error] [pid 466512:tid 466674] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9agSKGokixMSfKDOcDggAAAjQ"]
[Tue Jul 21 08:39:45.728102 2026] [security2:error] [pid 465652:tid 465802] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9agTzTqJoBC2Mw28_azAAAAJk"]
[Tue Jul 21 08:39:45.815699 2026] [security2:error] [pid 466512:tid 466755] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9agSKGokixMSfKDOcDiwAAAoU"]
[Tue Jul 21 08:39:45.832291 2026] [security2:error] [pid 466512:tid 466719] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9agSKGokixMSfKDOcDjQAAAmE"]
[Tue Jul 21 08:39:45.852166 2026] [security2:error] [pid 466512:tid 466705] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9agSKGokixMSfKDOcDjgAAAlM"]
[Tue Jul 21 08:39:45.853576 2026] [security2:error] [pid 466512:tid 466753] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9agSKGokixMSfKDOcDjwAAAoM"]
[Tue Jul 21 08:39:45.867916 2026] [security2:error] [pid 466512:tid 466662] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9agSKGokixMSfKDOcDkAAAAig"]
[Tue Jul 21 08:39:45.939255 2026] [security2:error] [pid 466512:tid 466681] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9agSKGokixMSfKDOcDkwAAAjs"]
[Tue Jul 21 08:39:45.953842 2026] [security2:error] [pid 466512:tid 466658] [client 20.206.105.145:33711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/raw.php"] [unique_id "al9agSKGokixMSfKDOcDlgAAAiQ"]
[Tue Jul 21 08:39:46.002089 2026] [security2:error] [pid 466512:tid 466678] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9agiKGokixMSfKDOcDlwAAAjg"]
[Tue Jul 21 08:39:46.013394 2026] [security2:error] [pid 465652:tid 465866] [client 20.151.10.161:60796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/sss.php"] [unique_id "al9agjzTqJoBC2Mw28_a0gAAANk"]
[Tue Jul 21 08:39:46.018214 2026] [security2:error] [pid 466512:tid 466762] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9agiKGokixMSfKDOcDmAAAAow"]
[Tue Jul 21 08:39:46.026470 2026] [security2:error] [pid 465652:tid 465889] [client 59.95.197.55:57885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9agjzTqJoBC2Mw28_a0wAAAPA"]
[Tue Jul 21 08:39:46.026560 2026] [security2:error] [pid 465652:tid 465889] [client 59.95.197.55:57885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9agjzTqJoBC2Mw28_a0wAAAPA"]
[Tue Jul 21 08:39:46.036696 2026] [security2:error] [pid 466512:tid 466651] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9agiKGokixMSfKDOcDmQAAAh0"]
[Tue Jul 21 08:39:46.203227 2026] [security2:error] [pid 465652:tid 465903] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9agjzTqJoBC2Mw28_a2AAAAP4"]
[Tue Jul 21 08:39:46.210290 2026] [security2:error] [pid 465652:tid 465839] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9agjzTqJoBC2Mw28_a2QAAAL4"]
[Tue Jul 21 08:39:46.233396 2026] [security2:error] [pid 465652:tid 465865] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9agjzTqJoBC2Mw28_a2gAAANg"]
[Tue Jul 21 08:39:46.237174 2026] [security2:error] [pid 466512:tid 466740] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9agiKGokixMSfKDOcDmgAAAnY"]
[Tue Jul 21 08:39:46.249051 2026] [security2:error] [pid 465652:tid 465895] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9agjzTqJoBC2Mw28_a2wAAAPY"]
[Tue Jul 21 08:39:46.277607 2026] [security2:error] [pid 465652:tid 465900] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9agjzTqJoBC2Mw28_a3AAAAPs"]
[Tue Jul 21 08:39:46.296663 2026] [security2:error] [pid 466512:tid 466672] [client 5.38.115.39:36448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9agiKGokixMSfKDOcDnQAAAjI"]
[Tue Jul 21 08:39:46.296822 2026] [security2:error] [pid 466512:tid 466672] [client 5.38.115.39:36448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9agiKGokixMSfKDOcDnQAAAjI"]
[Tue Jul 21 08:39:46.337731 2026] [security2:error] [pid 466512:tid 466664] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9agiKGokixMSfKDOcDnwAAAio"]
[Tue Jul 21 08:39:46.398662 2026] [security2:error] [pid 466512:tid 466768] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9agiKGokixMSfKDOcDogAAApI"]
[Tue Jul 21 08:39:46.417984 2026] [security2:error] [pid 466512:tid 466692] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9agiKGokixMSfKDOcDowAAAkY"]
[Tue Jul 21 08:39:46.550957 2026] [security2:error] [pid 466512:tid 466766] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9agiKGokixMSfKDOcDpQAAApA"]
[Tue Jul 21 08:39:46.584361 2026] [security2:error] [pid 465652:tid 465788] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9agjzTqJoBC2Mw28_a5QAAAIs"]
[Tue Jul 21 08:39:46.586952 2026] [security2:error] [pid 465652:tid 465843] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9agjzTqJoBC2Mw28_a5gAAAMI"]
[Tue Jul 21 08:39:46.593833 2026] [security2:error] [pid 465652:tid 465891] [client 202.179.75.202:33612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9agjzTqJoBC2Mw28_a5wAAAPI"]
[Tue Jul 21 08:39:46.594436 2026] [security2:error] [pid 465652:tid 465891] [client 202.179.75.202:33612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9agjzTqJoBC2Mw28_a5wAAAPI"]
[Tue Jul 21 08:39:46.603581 2026] [security2:error] [pid 466512:tid 466671] [client 223.181.60.88:13726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9agiKGokixMSfKDOcDpgAAAjE"]
[Tue Jul 21 08:39:46.604710 2026] [security2:error] [pid 466512:tid 466671] [client 223.181.60.88:13726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9agiKGokixMSfKDOcDpgAAAjE"]
[Tue Jul 21 08:39:46.611764 2026] [security2:error] [pid 465652:tid 465783] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9agjzTqJoBC2Mw28_a6AAAAIY"]
[Tue Jul 21 08:39:46.618698 2026] [security2:error] [pid 466512:tid 466722] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9agiKGokixMSfKDOcDpwAAAmQ"]
[Tue Jul 21 08:39:46.627131 2026] [security2:error] [pid 465652:tid 465890] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9agjzTqJoBC2Mw28_a6QAAAPE"]
[Tue Jul 21 08:39:46.720899 2026] [security2:error] [pid 465652:tid 465838] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9agjzTqJoBC2Mw28_a7gAAAL0"]
[Tue Jul 21 08:39:46.783496 2026] [security2:error] [pid 465652:tid 465820] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9agjzTqJoBC2Mw28_a8QAAAKs"]
[Tue Jul 21 08:39:46.800094 2026] [security2:error] [pid 465652:tid 465841] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9agjzTqJoBC2Mw28_a8wAAAMA"]
[Tue Jul 21 08:39:46.824121 2026] [security2:error] [pid 465652:tid 465831] [client 85.204.70.98:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.alexandrericardoabde1782224350389.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9agjzTqJoBC2Mw28_a9AAAALY"]
[Tue Jul 21 08:39:46.910185 2026] [security2:error] [pid 465652:tid 465870] [client 122.176.100.127:58137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9agjzTqJoBC2Mw28_a-wAAAN0"]
[Tue Jul 21 08:39:46.911421 2026] [security2:error] [pid 465652:tid 465870] [client 122.176.100.127:58137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9agjzTqJoBC2Mw28_a-wAAAN0"]
[Tue Jul 21 08:39:46.959431 2026] [security2:error] [pid 465652:tid 465782] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9agjzTqJoBC2Mw28_a_QAAAIU"]
[Tue Jul 21 08:39:46.963192 2026] [security2:error] [pid 465652:tid 465799] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9agjzTqJoBC2Mw28_a_gAAAJY"]
[Tue Jul 21 08:39:46.989859 2026] [security2:error] [pid 465652:tid 465909] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9agjzTqJoBC2Mw28_bAAAAAQQ"]
[Tue Jul 21 08:39:46.996265 2026] [security2:error] [pid 465652:tid 465785] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9agjzTqJoBC2Mw28_bAQAAAIg"]
[Tue Jul 21 08:39:47.006898 2026] [security2:error] [pid 465652:tid 465850] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9agzzTqJoBC2Mw28_bAgAAAMk"]
[Tue Jul 21 08:39:47.008255 2026] [security2:error] [pid 465652:tid 465885] [client 20.206.105.145:33728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/abcd.php"] [unique_id "al9agzzTqJoBC2Mw28_bAwAAAOw"]
[Tue Jul 21 08:39:47.098016 2026] [security2:error] [pid 465652:tid 465854] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9agzzTqJoBC2Mw28_bBAAAAM0"]
[Tue Jul 21 08:39:47.173827 2026] [security2:error] [pid 465652:tid 465903] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9agzzTqJoBC2Mw28_bBgAAAP4"]
[Tue Jul 21 08:39:47.181434 2026] [security2:error] [pid 465652:tid 465880] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9agzzTqJoBC2Mw28_bBwAAAOc"]
[Tue Jul 21 08:39:47.360950 2026] [security2:error] [pid 465652:tid 465886] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9agzzTqJoBC2Mw28_bDQAAAO0"]
[Tue Jul 21 08:39:47.364679 2026] [security2:error] [pid 465652:tid 465851] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9agzzTqJoBC2Mw28_bDgAAAMo"]
[Tue Jul 21 08:39:47.392036 2026] [security2:error] [pid 465652:tid 465786] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9agzzTqJoBC2Mw28_bDwAAAIk"]
[Tue Jul 21 08:39:47.482527 2026] [security2:error] [pid 465652:tid 465890] [client 20.206.105.145:33614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/a1.php"] [unique_id "al9agzzTqJoBC2Mw28_bFQAAAPE"]
[Tue Jul 21 08:39:47.524452 2026] [security2:error] [pid 465652:tid 465862] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9agzzTqJoBC2Mw28_bFwAAANU"]
[Tue Jul 21 08:39:47.565548 2026] [security2:error] [pid 465652:tid 465828] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9agzzTqJoBC2Mw28_bGQAAALM"]
[Tue Jul 21 08:39:47.566827 2026] [security2:error] [pid 465652:tid 465848] [client 185.192.71.14:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9agzzTqJoBC2Mw28_bGgAAAMc"]
[Tue Jul 21 08:39:47.639974 2026] [security2:error] [pid 465652:tid 465807] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9agzzTqJoBC2Mw28_bHAAAAJ4"]
[Tue Jul 21 08:39:47.678380 2026] [security2:error] [pid 465652:tid 465842] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9agzzTqJoBC2Mw28_bHQAAAME"]
[Tue Jul 21 08:39:47.776430 2026] [security2:error] [pid 465652:tid 465789] [client 185.192.71.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9agzzTqJoBC2Mw28_bIAAAAIw"]
[Tue Jul 21 08:39:47.784245 2026] [security2:error] [pid 465652:tid 465819] [client 185.192.71.15:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9agzzTqJoBC2Mw28_bIgAAAKo"]
[Tue Jul 21 08:39:47.785645 2026] [security2:error] [pid 465652:tid 465805] [client 185.192.71.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9agzzTqJoBC2Mw28_bIwAAAJw"]
[Tue Jul 21 08:39:47.876794 2026] [security2:error] [pid 465652:tid 465810] [client 20.151.10.161:57558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/c.php"] [unique_id "al9agzzTqJoBC2Mw28_bJgAAAKE"]
[Tue Jul 21 08:39:47.968183 2026] [security2:error] [pid 465652:tid 465876] [client 185.192.71.249:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9agzzTqJoBC2Mw28_bKgAAAOM"]
[Tue Jul 21 08:39:47.984559 2026] [security2:error] [pid 465652:tid 465826] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9agzzTqJoBC2Mw28_bKwAAALE"]
[Tue Jul 21 08:39:47.995202 2026] [security2:error] [pid 465652:tid 465909] [client 20.206.105.145:33722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9agzzTqJoBC2Mw28_bLAAAAQQ"]
[Tue Jul 21 08:39:48.023713 2026] [security2:error] [pid 465652:tid 465824] [client 185.192.71.1:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9ahDzTqJoBC2Mw28_bLgAAAK8"]
[Tue Jul 21 08:39:48.060087 2026] [security2:error] [pid 465652:tid 465801] [client 185.192.71.12:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.sandrojosemoraisparr1782840988253.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9ahDzTqJoBC2Mw28_bLwAAAJg"]
[Tue Jul 21 08:39:48.550261 2026] [security2:error] [pid 465652:tid 465856] [client 168.167.81.163:60046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9ahDzTqJoBC2Mw28_bQwAAAM8"]
[Tue Jul 21 08:39:48.550375 2026] [security2:error] [pid 465652:tid 465856] [client 168.167.81.163:60046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9ahDzTqJoBC2Mw28_bQwAAAM8"]
[Tue Jul 21 08:39:48.633196 2026] [security2:error] [pid 465652:tid 465872] [client 14.245.224.124:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ahDzTqJoBC2Mw28_bRQAAAN8"]
[Tue Jul 21 08:39:48.633314 2026] [security2:error] [pid 465652:tid 465872] [client 14.245.224.124:60424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ahDzTqJoBC2Mw28_bRQAAAN8"]
[Tue Jul 21 08:39:48.769465 2026] [security2:error] [pid 465652:tid 465878] [client 20.206.105.145:33693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9ahDzTqJoBC2Mw28_bSQAAAOU"]
[Tue Jul 21 08:39:48.973593 2026] [security2:error] [pid 465652:tid 465747] [remote 84.247.172.23:51334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mecdutos.com.br"] [uri "/wp-login.php"] [unique_id "al9ahDzTqJoBC2Mw28_bTgAAwl4"]
[Tue Jul 21 08:39:49.423170 2026] [security2:error] [pid 465652:tid 465842] [client 195.49.128.211:65344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ahTzTqJoBC2Mw28_bXwAAAME"]
[Tue Jul 21 08:39:49.423293 2026] [security2:error] [pid 465652:tid 465842] [client 195.49.128.211:65344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9ahTzTqJoBC2Mw28_bXwAAAME"]
[Tue Jul 21 08:39:49.488258 2026] [security2:error] [pid 465652:tid 465895] [client 85.113.70.242:33380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.70.113.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-content/plugins/wp-planet/rss.class/scripts/magpie_debug.php"] [unique_id "al9ahTzTqJoBC2Mw28_bZgAAAPY"]
[Tue Jul 21 08:39:49.713442 2026] [security2:error] [pid 465652:tid 465786] [client 20.151.10.161:60675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/aa.php"] [unique_id "al9ahTzTqJoBC2Mw28_bcQAAAIk"]
[Tue Jul 21 08:39:49.801968 2026] [security2:error] [pid 465652:tid 465856] [client 20.206.105.145:33781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9ahTzTqJoBC2Mw28_bcgAAAM8"]
[Tue Jul 21 08:39:49.934527 2026] [security2:error] [pid 465652:tid 465782] [client 103.59.206.240:31107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ahTzTqJoBC2Mw28_bdgAAAIU"]
[Tue Jul 21 08:39:49.934621 2026] [security2:error] [pid 465652:tid 465782] [client 103.59.206.240:31107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ahTzTqJoBC2Mw28_bdgAAAIU"]
[Tue Jul 21 08:39:50.152158 2026] [security2:error] [pid 465652:tid 465837] [client 152.59.34.51:62623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ahjzTqJoBC2Mw28_bfQAAALw"]
[Tue Jul 21 08:39:50.152288 2026] [security2:error] [pid 465652:tid 465837] [client 152.59.34.51:62623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ahjzTqJoBC2Mw28_bfQAAALw"]
[Tue Jul 21 08:39:50.228568 2026] [security2:error] [pid 465652:tid 465902] [client 85.113.70.242:33384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.70.113.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-content/plugins/advanced-text-widget/advancedtext.php"] [unique_id "al9ahjzTqJoBC2Mw28_bgQAAAP0"]
[Tue Jul 21 08:39:50.465348 2026] [security2:error] [pid 465652:tid 465875] [client 152.59.181.104:59394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ahjzTqJoBC2Mw28_biAAAAOI"]
[Tue Jul 21 08:39:50.465497 2026] [security2:error] [pid 465652:tid 465875] [client 152.59.181.104:59394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9ahjzTqJoBC2Mw28_biAAAAOI"]
[Tue Jul 21 08:39:50.507976 2026] [security2:error] [pid 465652:tid 465802] [client 85.113.70.242:33394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.70.113.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-admin/index.php"] [unique_id "al9ahjzTqJoBC2Mw28_biQAAAJk"]
[Tue Jul 21 08:39:50.592519 2026] [security2:error] [pid 465652:tid 465885] [client 20.206.105.145:33766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/simple.php"] [unique_id "al9ahjzTqJoBC2Mw28_bjwAAAOw"]
[Tue Jul 21 08:39:50.767543 2026] [security2:error] [pid 465652:tid 465796] [client 20.151.10.161:60780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/100.php"] [unique_id "al9ahjzTqJoBC2Mw28_blgAAAJM"]
[Tue Jul 21 08:39:51.253643 2026] [security2:error] [pid 465652:tid 465878] [client 20.206.105.145:33613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/xxx.php"] [unique_id "al9ahzzTqJoBC2Mw28_bpwAAAOU"]
[Tue Jul 21 08:39:51.492378 2026] [security2:error] [pid 465652:tid 465862] [client 85.113.70.242:33414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "efrelectronics.com.br"] [uri "/"] [unique_id "al9ahzzTqJoBC2Mw28_brQAAANU"]
[Tue Jul 21 08:39:51.701617 2026] [security2:error] [pid 465652:tid 465865] [client 20.151.10.161:60792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/footer.php"] [unique_id "al9ahzzTqJoBC2Mw28_btgAAANg"]
[Tue Jul 21 08:39:51.864901 2026] [security2:error] [pid 465652:tid 465822] [client 20.206.105.145:33636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/hypo.php"] [unique_id "al9ahzzTqJoBC2Mw28_btwAAAK0"]
[Tue Jul 21 08:39:51.958906 2026] [security2:error] [pid 465652:tid 465718] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ahzzTqJoBC2Mw28_buwAA4UE"]
[Tue Jul 21 08:39:51.959059 2026] [security2:error] [pid 465652:tid 465874] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ahzzTqJoBC2Mw28_buwAA4UE"]
[Tue Jul 21 08:39:52.039897 2026] [security2:error] [pid 465652:tid 465836] [client 20.226.60.151:58586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wicked.php"] [unique_id "al9aiDzTqJoBC2Mw28_bvQAAALs"]
[Tue Jul 21 08:39:52.204595 2026] [security2:error] [pid 465652:tid 465870] [client 85.113.70.242:33410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.70.113.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-content/plugins/showbizpro/temp/update_extract/n7C6z.php"] [unique_id "al9aiDzTqJoBC2Mw28_bxQAAAN0"]
[Tue Jul 21 08:39:52.213343 2026] [security2:error] [pid 465652:tid 465802] [client 49.144.66.253:32155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aiDzTqJoBC2Mw28_bxgAAAJk"]
[Tue Jul 21 08:39:52.213468 2026] [security2:error] [pid 465652:tid 465802] [client 49.144.66.253:32155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aiDzTqJoBC2Mw28_bxgAAAJk"]
[Tue Jul 21 08:39:52.298343 2026] [security2:error] [pid 465652:tid 465833] [client 20.206.105.145:33695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/chosen.php"] [unique_id "al9aiDzTqJoBC2Mw28_byAAAALg"]
[Tue Jul 21 08:39:52.383428 2026] [security2:error] [pid 465652:tid 465854] [client 20.151.10.161:57566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/users.php"] [unique_id "al9aiDzTqJoBC2Mw28_bzAAAAM0"]
[Tue Jul 21 08:39:52.484359 2026] [security2:error] [pid 465652:tid 465884] [client 198.44.157.34:52860] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9aiDzTqJoBC2Mw28_bzQAAAOs"]
[Tue Jul 21 08:39:52.484467 2026] [security2:error] [pid 465652:tid 465884] [client 198.44.157.34:52860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9aiDzTqJoBC2Mw28_bzQAAAOs"]
[Tue Jul 21 08:39:52.796488 2026] [security2:error] [pid 465652:tid 465889] [client 195.49.128.211:56790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aiDzTqJoBC2Mw28_b4gAAAPA"]
[Tue Jul 21 08:39:52.796584 2026] [security2:error] [pid 465652:tid 465889] [client 195.49.128.211:56790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aiDzTqJoBC2Mw28_b4gAAAPA"]
[Tue Jul 21 08:39:52.936916 2026] [security2:error] [pid 465652:tid 465903] [client 20.206.105.145:33750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/file5.php"] [unique_id "al9aiDzTqJoBC2Mw28_b5AAAAP4"]
[Tue Jul 21 08:39:53.118506 2026] [security2:error] [pid 465652:tid 465890] [client 117.213.202.34:54743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aiTzTqJoBC2Mw28_b6wAAAPE"]
[Tue Jul 21 08:39:53.118657 2026] [security2:error] [pid 465652:tid 465890] [client 117.213.202.34:54743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aiTzTqJoBC2Mw28_b6wAAAPE"]
[Tue Jul 21 08:39:53.217718 2026] [security2:error] [pid 465652:tid 465810] [client 85.113.70.242:33418] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "264"] [id "900296"] [msg "Gravity Forms Unsecured Upload Attempt"] [hostname "efrelectronics.com.br"] [uri "/"] [unique_id "al9aiTzTqJoBC2Mw28_b8QAAAKE"]
[Tue Jul 21 08:39:53.244475 2026] [security2:error] [pid 465652:tid 465842] [client 20.151.10.161:57552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/177.php"] [unique_id "al9aiTzTqJoBC2Mw28_b8gAAAME"]
[Tue Jul 21 08:39:53.437311 2026] [security2:error] [pid 465652:tid 465817] [client 20.206.105.145:33687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/file.php"] [unique_id "al9aiTzTqJoBC2Mw28_b-AAAAKg"]
[Tue Jul 21 08:39:53.733780 2026] [security2:error] [pid 465652:tid 465783] [client 20.151.10.161:60769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/config.php"] [unique_id "al9aiTzTqJoBC2Mw28_cBQAAAIY"]
[Tue Jul 21 08:39:53.798668 2026] [security2:error] [pid 465652:tid 465705] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aiTzTqJoBC2Mw28_cBgAA8jQ"]
[Tue Jul 21 08:39:53.798780 2026] [security2:error] [pid 465652:tid 465891] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aiTzTqJoBC2Mw28_cBgAA8jQ"]
[Tue Jul 21 08:39:54.486773 2026] [security2:error] [pid 465652:tid 465832] [client 20.151.10.161:60743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/gettest.php"] [unique_id "al9aijzTqJoBC2Mw28_cGAAAALc"]
[Tue Jul 21 08:39:54.724438 2026] [security2:error] [pid 465652:tid 465825] [client 20.206.105.145:33665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/aa2.php"] [unique_id "al9aijzTqJoBC2Mw28_cJQAAALA"]
[Tue Jul 21 08:39:54.977996 2026] [security2:error] [pid 465652:tid 465902] [client 74.249.245.134:41836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/lv.php"] [unique_id "al9aijzTqJoBC2Mw28_cKQAAAP0"]
[Tue Jul 21 08:39:55.498202 2026] [security2:error] [pid 465652:tid 465877] [client 20.151.10.161:60686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/min.php"] [unique_id "al9aizzTqJoBC2Mw28_cPwAAAOQ"]
[Tue Jul 21 08:39:55.651864 2026] [security2:error] [pid 465652:tid 465806] [client 20.63.100.92:8348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/nhvoanpl.php"] [unique_id "al9aizzTqJoBC2Mw28_cQwAAAJ0"]
[Tue Jul 21 08:39:55.954193 2026] [security2:error] [pid 465652:tid 465810] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aizzTqJoBC2Mw28_cSgAAoSg"]
[Tue Jul 21 08:39:56.398004 2026] [security2:error] [pid 465652:tid 465858] [client 20.151.10.161:57596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/edorxrr.php"] [unique_id "al9ajDzTqJoBC2Mw28_cYQAAANE"]
[Tue Jul 21 08:39:56.429402 2026] [security2:error] [pid 465652:tid 465891] [client 20.206.105.145:33765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/ccou.php"] [unique_id "al9ajDzTqJoBC2Mw28_cZQAAAPI"]
[Tue Jul 21 08:39:56.503098 2026] [security2:error] [pid 465652:tid 465827] [client 203.25.124.42:20823] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/"] [unique_id "al9ajDzTqJoBC2Mw28_cZwAAALI"]
[Tue Jul 21 08:39:56.503518 2026] [security2:error] [pid 465652:tid 465909] [client 59.95.197.55:58332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ajDzTqJoBC2Mw28_caAAAAQQ"]
[Tue Jul 21 08:39:56.503598 2026] [security2:error] [pid 465652:tid 465909] [client 59.95.197.55:58332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ajDzTqJoBC2Mw28_caAAAAQQ"]
[Tue Jul 21 08:39:56.931379 2026] [security2:error] [pid 465652:tid 465831] [client 5.38.115.39:6743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ajDzTqJoBC2Mw28_cdQAAALY"]
[Tue Jul 21 08:39:56.934118 2026] [security2:error] [pid 465652:tid 465871] [client 20.151.10.161:60728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/hur.php"] [unique_id "al9ajDzTqJoBC2Mw28_cdgAAAN4"]
[Tue Jul 21 08:39:56.935204 2026] [security2:error] [pid 465652:tid 465831] [client 5.38.115.39:6743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ajDzTqJoBC2Mw28_cdQAAALY"]
[Tue Jul 21 08:39:57.264045 2026] [security2:error] [pid 465652:tid 465786] [client 203.25.124.65:51581] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/core.php"] [unique_id "al9ajTzTqJoBC2Mw28_cewAAAIk"]
[Tue Jul 21 08:39:57.393572 2026] [security2:error] [pid 465652:tid 465826] [client 122.176.100.127:58646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ajTzTqJoBC2Mw28_chwAAALE"]
[Tue Jul 21 08:39:57.394275 2026] [security2:error] [pid 465652:tid 465826] [client 122.176.100.127:58646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ajTzTqJoBC2Mw28_chwAAALE"]
[Tue Jul 21 08:39:57.447840 2026] [security2:error] [pid 465652:tid 465843] [client 202.179.75.202:46646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ajTzTqJoBC2Mw28_ciQAAAMI"]
[Tue Jul 21 08:39:57.447962 2026] [security2:error] [pid 465652:tid 465843] [client 202.179.75.202:46646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9ajTzTqJoBC2Mw28_ciQAAAMI"]
[Tue Jul 21 08:39:57.512075 2026] [security2:error] [pid 465652:tid 465793] [client 223.181.60.88:12742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ajTzTqJoBC2Mw28_ciwAAAJA"]
[Tue Jul 21 08:39:57.512546 2026] [security2:error] [pid 465652:tid 465793] [client 223.181.60.88:12742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9ajTzTqJoBC2Mw28_ciwAAAJA"]
[Tue Jul 21 08:39:57.600521 2026] [security2:error] [pid 465652:tid 465815] [client 20.151.10.161:60732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/zoro.php"] [unique_id "al9ajTzTqJoBC2Mw28_ckAAAAKY"]
[Tue Jul 21 08:39:57.625502 2026] [security2:error] [pid 465652:tid 465795] [client 173.252.95.23:54002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ajTzTqJoBC2Mw28_ckQAAAJI"]
[Tue Jul 21 08:39:57.632232 2026] [security2:error] [pid 465652:tid 465874] [client 5.31.193.106:30000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ajTzTqJoBC2Mw28_ckgAAAOE"]
[Tue Jul 21 08:39:57.632371 2026] [security2:error] [pid 465652:tid 465874] [client 5.31.193.106:30000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ajTzTqJoBC2Mw28_ckgAAAOE"]
[Tue Jul 21 08:39:57.856757 2026] [security2:error] [pid 465652:tid 465885] [client 20.206.105.145:33685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/dr.php"] [unique_id "al9ajTzTqJoBC2Mw28_clwAAAOw"]
[Tue Jul 21 08:39:58.023798 2026] [security2:error] [pid 465652:tid 465787] [client 20.151.10.161:57587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/coffexium.php"] [unique_id "al9ajjzTqJoBC2Mw28_cnQAAAIo"]
[Tue Jul 21 08:39:58.302048 2026] [security2:error] [pid 465652:tid 465864] [client 69.171.230.6:52926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ajjzTqJoBC2Mw28_cogAAANc"]
[Tue Jul 21 08:39:58.458730 2026] [security2:error] [pid 465652:tid 465783] [client 212.32.76.7:42235] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "al9ajjzTqJoBC2Mw28_cqwAAAIY"]
[Tue Jul 21 08:39:58.556611 2026] [security2:error] [pid 465652:tid 465900] [client 172.233.163.221:55464] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "drapaulamelo.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9ajjzTqJoBC2Mw28_crgAAAPs"]
[Tue Jul 21 08:39:58.666866 2026] [security2:error] [pid 465652:tid 465858] [client 172.233.163.221:55464] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "drapaulamelo.com.br"] [uri "/"] [unique_id "al9ajjzTqJoBC2Mw28_csgAAANE"]
[Tue Jul 21 08:39:58.694635 2026] [security2:error] [pid 465652:tid 465833] [client 168.167.81.163:60765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9ajjzTqJoBC2Mw28_cswAAALg"]
[Tue Jul 21 08:39:58.694729 2026] [security2:error] [pid 465652:tid 465833] [client 168.167.81.163:60765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9ajjzTqJoBC2Mw28_cswAAALg"]
[Tue Jul 21 08:39:59.016571 2026] [security2:error] [pid 465652:tid 465815] [client 69.171.230.116:54958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ajzzTqJoBC2Mw28_cvAAAAKY"]
[Tue Jul 21 08:39:59.179940 2026] [security2:error] [pid 465652:tid 465788] [client 20.151.10.161:57575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/app.php"] [unique_id "al9ajzzTqJoBC2Mw28_cwAAAAIs"]
[Tue Jul 21 08:39:59.315132 2026] [security2:error] [pid 465652:tid 465787] [client 20.206.105.145:33768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/file31.php"] [unique_id "al9ajzzTqJoBC2Mw28_cwgAAAIo"]
[Tue Jul 21 08:39:59.492160 2026] [security2:error] [pid 465652:tid 465836] [client 14.245.224.124:60906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ajzzTqJoBC2Mw28_cywAAALs"]
[Tue Jul 21 08:39:59.492325 2026] [security2:error] [pid 465652:tid 465836] [client 14.245.224.124:60906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9ajzzTqJoBC2Mw28_cywAAALs"]
[Tue Jul 21 08:39:59.572112 2026] [security2:error] [pid 465652:tid 465792] [client 5.39.1.245:51344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "lumeneducacao.com.br"] [uri "/robots.txt"] [unique_id "al9ajzzTqJoBC2Mw28_c0AAAAI8"]
[Tue Jul 21 08:39:59.572269 2026] [security2:error] [pid 465652:tid 465792] [client 5.39.1.245:51344] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lumeneducacao.com.br"] [uri "/robots.txt"] [unique_id "al9ajzzTqJoBC2Mw28_c0AAAAI8"]
[Tue Jul 21 08:39:59.699559 2026] [security2:error] [pid 465652:tid 465829] [client 61.1.167.83:52680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ajzzTqJoBC2Mw28_c1gAAALQ"]
[Tue Jul 21 08:39:59.699704 2026] [security2:error] [pid 465652:tid 465829] [client 61.1.167.83:52680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ajzzTqJoBC2Mw28_c1gAAALQ"]
[Tue Jul 21 08:39:59.896098 2026] [security2:error] [pid 465652:tid 465873] [client 20.151.10.161:60713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/core.php"] [unique_id "al9ajzzTqJoBC2Mw28_c3QAAAOA"]
[Tue Jul 21 08:39:59.971818 2026] [security2:error] [pid 465652:tid 465817] [client 203.25.124.42:52547] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/admin.php"] [unique_id "al9ajzzTqJoBC2Mw28_c5AAAAKg"]
[Tue Jul 21 08:39:59.978648 2026] [security2:error] [pid 465652:tid 465795] [client 20.206.105.145:33725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/file6.php"] [unique_id "al9ajzzTqJoBC2Mw28_c5wAAAJI"]
[Tue Jul 21 08:40:00.060765 2026] [security2:error] [pid 465652:tid 465870] [client 195.49.128.211:49567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9akDzTqJoBC2Mw28_c7QAAAN0"]
[Tue Jul 21 08:40:00.060912 2026] [security2:error] [pid 465652:tid 465870] [client 195.49.128.211:49567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9akDzTqJoBC2Mw28_c7QAAAN0"]
[Tue Jul 21 08:40:00.351378 2026] [security2:error] [pid 465652:tid 465732] [remote 216.73.216.184:14570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemape.xml"] [unique_id "al9akDzTqJoBC2Mw28_c9gAAuU8"]
[Tue Jul 21 08:40:00.466952 2026] [security2:error] [pid 465652:tid 465883] [client 69.171.230.10:56482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9akDzTqJoBC2Mw28_c9AAAAOo"]
[Tue Jul 21 08:40:00.571657 2026] [security2:error] [pid 465652:tid 465810] [client 20.151.10.161:57547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/main.php"] [unique_id "al9akDzTqJoBC2Mw28_dAgAAAKE"]
[Tue Jul 21 08:40:00.591573 2026] [security2:error] [pid 465652:tid 465878] [client 103.59.206.240:31248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9akDzTqJoBC2Mw28_dAwAAAOU"]
[Tue Jul 21 08:40:00.591688 2026] [security2:error] [pid 465652:tid 465878] [client 103.59.206.240:31248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9akDzTqJoBC2Mw28_dAwAAAOU"]
[Tue Jul 21 08:40:00.678446 2026] [security2:error] [pid 465652:tid 465783] [client 20.206.105.145:33712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/file15.php"] [unique_id "al9akDzTqJoBC2Mw28_dEAAAAIY"]
[Tue Jul 21 08:40:00.719430 2026] [security2:error] [pid 465652:tid 465852] [client 74.249.245.134:48959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/cong.php"] [unique_id "al9akDzTqJoBC2Mw28_dEgAAAMs"]
[Tue Jul 21 08:40:00.971558 2026] [security2:error] [pid 465652:tid 465815] [client 152.59.34.51:42345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9akDzTqJoBC2Mw28_dEwAAAKY"]
[Tue Jul 21 08:40:00.971681 2026] [security2:error] [pid 465652:tid 465815] [client 152.59.34.51:42345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9akDzTqJoBC2Mw28_dEwAAAKY"]
[Tue Jul 21 08:40:01.045949 2026] [security2:error] [pid 465652:tid 465854] [client 152.59.181.104:1041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9akTzTqJoBC2Mw28_dGwAAAM0"]
[Tue Jul 21 08:40:01.046036 2026] [security2:error] [pid 465652:tid 465854] [client 152.59.181.104:1041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9akTzTqJoBC2Mw28_dGwAAAM0"]
[Tue Jul 21 08:40:01.091882 2026] [security2:error] [pid 465652:tid 465874] [client 20.151.10.161:50117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/init.php"] [unique_id "al9akTzTqJoBC2Mw28_dHQAAAOE"]
[Tue Jul 21 08:40:01.370332 2026] [security2:error] [pid 465652:tid 465866] [client 20.206.105.145:33778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/jp.php"] [unique_id "al9akTzTqJoBC2Mw28_dJAAAANk"]
[Tue Jul 21 08:40:01.547168 2026] [security2:error] [pid 465652:tid 465832] [client 54.39.203.119:42774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "lumeneducacao.com.br"] [uri "/"] [unique_id "al9akTzTqJoBC2Mw28_dNAAAALc"]
[Tue Jul 21 08:40:01.547310 2026] [security2:error] [pid 465652:tid 465832] [client 54.39.203.119:42774] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lumeneducacao.com.br"] [uri "/"] [unique_id "al9akTzTqJoBC2Mw28_dNAAAALc"]
[Tue Jul 21 08:40:01.604588 2026] [security2:error] [pid 465652:tid 465837] [client 20.151.10.161:57539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/prekel.php"] [unique_id "al9akTzTqJoBC2Mw28_dOAAAALw"]
[Tue Jul 21 08:40:01.636417 2026] [security2:error] [pid 465652:tid 465857] [client 69.171.230.38:59144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9akTzTqJoBC2Mw28_dOgAAANA"]
[Tue Jul 21 08:40:01.860989 2026] [security2:error] [pid 465652:tid 465817] [client 203.25.124.70:36735] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/goods.php"] [unique_id "al9akTzTqJoBC2Mw28_dPgAAAKg"]
[Tue Jul 21 08:40:02.269634 2026] [security2:error] [pid 465652:tid 465822] [client 20.151.10.161:60687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/0.php"] [unique_id "al9akjzTqJoBC2Mw28_dTQAAAK0"]
[Tue Jul 21 08:40:02.464974 2026] [security2:error] [pid 465652:tid 465889] [client 2.57.168.11:43055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.168.57.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9akjzTqJoBC2Mw28_dUQAAAPA"]
[Tue Jul 21 08:40:02.522229 2026] [security2:error] [pid 465652:tid 465738] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9akjzTqJoBC2Mw28_dUwAAh1U"]
[Tue Jul 21 08:40:02.523033 2026] [security2:error] [pid 465652:tid 465784] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9akjzTqJoBC2Mw28_dUwAAh1U"]
[Tue Jul 21 08:40:02.670024 2026] [security2:error] [pid 465652:tid 465862] [client 198.44.157.34:34584] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9akjzTqJoBC2Mw28_dYgAAANU"]
[Tue Jul 21 08:40:02.670273 2026] [security2:error] [pid 465652:tid 465862] [client 198.44.157.34:34584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9akjzTqJoBC2Mw28_dYgAAANU"]
[Tue Jul 21 08:40:02.757536 2026] [security2:error] [pid 465652:tid 465810] [client 203.25.124.49:44719] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/edit-tags.php"] [unique_id "al9akjzTqJoBC2Mw28_dYwAAAKE"]
[Tue Jul 21 08:40:02.762727 2026] [security2:error] [pid 465652:tid 465673] [remote 54.39.89.229:28172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "limetteodontologia.com.br"] [uri "/o-que-sao-alinhadores-transparentes-e-como-funcionam/"] [unique_id "al9akjzTqJoBC2Mw28_dZAAAzxQ"]
[Tue Jul 21 08:40:02.762882 2026] [security2:error] [pid 465652:tid 465856] [client 54.39.89.229:28172] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "limetteodontologia.com.br"] [uri "/o-que-sao-alinhadores-transparentes-e-como-funcionam/"] [unique_id "al9akjzTqJoBC2Mw28_dZAAAzxQ"]
[Tue Jul 21 08:40:03.054011 2026] [security2:error] [pid 465652:tid 465838] [client 195.206.105.227:40420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9akzzTqJoBC2Mw28_dagAAAL0"]
[Tue Jul 21 08:40:03.054100 2026] [security2:error] [pid 465652:tid 465838] [client 195.206.105.227:40420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9akzzTqJoBC2Mw28_dagAAAL0"]
[Tue Jul 21 08:40:03.258175 2026] [security2:error] [pid 465652:tid 465886] [client 49.144.66.253:32523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9akzzTqJoBC2Mw28_dcgAAAO0"]
[Tue Jul 21 08:40:03.258358 2026] [security2:error] [pid 465652:tid 465886] [client 49.144.66.253:32523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9akzzTqJoBC2Mw28_dcgAAAO0"]
[Tue Jul 21 08:40:03.283280 2026] [security2:error] [pid 465652:tid 465867] [client 20.206.105.145:33682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/f35.php"] [unique_id "al9akzzTqJoBC2Mw28_dcwAAANo"]
[Tue Jul 21 08:40:03.409215 2026] [security2:error] [pid 465652:tid 465841] [client 20.151.10.161:60759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/BDKR28.php"] [unique_id "al9akzzTqJoBC2Mw28_dfQAAAMA"]
[Tue Jul 21 08:40:03.428243 2026] [security2:error] [pid 465652:tid 465902] [client 195.49.128.211:57396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9akzzTqJoBC2Mw28_dfgAAAP0"]
[Tue Jul 21 08:40:03.428359 2026] [security2:error] [pid 465652:tid 465902] [client 195.49.128.211:57396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9akzzTqJoBC2Mw28_dfgAAAP0"]
[Tue Jul 21 08:40:03.669014 2026] [security2:error] [pid 465652:tid 465850] [client 203.25.124.57:56507] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/filemanager.php"] [unique_id "al9akzzTqJoBC2Mw28_djwAAAMk"]
[Tue Jul 21 08:40:03.833827 2026] [security2:error] [pid 465652:tid 465903] [client 117.213.202.34:55359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9akzzTqJoBC2Mw28_dkgAAAP4"]
[Tue Jul 21 08:40:03.834031 2026] [security2:error] [pid 465652:tid 465903] [client 117.213.202.34:55359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9akzzTqJoBC2Mw28_dkgAAAP4"]
[Tue Jul 21 08:40:03.945154 2026] [security2:error] [pid 465652:tid 465827] [client 20.220.225.223:12316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9akzzTqJoBC2Mw28_dlAAAALI"]
[Tue Jul 21 08:40:04.128510 2026] [security2:error] [pid 465652:tid 465859] [client 20.206.105.145:33720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wp-load.php"] [unique_id "al9alDzTqJoBC2Mw28_dnAAAANI"]
[Tue Jul 21 08:40:04.362551 2026] [security2:error] [pid 465652:tid 465855] [client 20.151.10.161:57541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/f35.update.php"] [unique_id "al9alDzTqJoBC2Mw28_dpQAAAM4"]
[Tue Jul 21 08:40:04.589016 2026] [security2:error] [pid 465652:tid 465787] [client 20.206.105.145:33784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9alDzTqJoBC2Mw28_drgAAAIo"]
[Tue Jul 21 08:40:04.693898 2026] [security2:error] [pid 465652:tid 465853] [client 20.220.225.223:2375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wp-css.php"] [unique_id "al9alDzTqJoBC2Mw28_dtQAAAMw"]
[Tue Jul 21 08:40:04.810498 2026] [security2:error] [pid 465652:tid 465668] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9alDzTqJoBC2Mw28_duwAA_Q8"]
[Tue Jul 21 08:40:04.810708 2026] [security2:error] [pid 465652:tid 465902] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9alDzTqJoBC2Mw28_duwAA_Q8"]
[Tue Jul 21 08:40:04.970510 2026] [security2:error] [pid 465652:tid 465837] [client 203.25.124.36:37137] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/"] [unique_id "al9alDzTqJoBC2Mw28_dvAAAALw"]
[Tue Jul 21 08:40:05.192088 2026] [security2:error] [pid 465652:tid 465891] [client 20.151.10.161:51210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/f900.php"] [unique_id "al9alTzTqJoBC2Mw28_dwwAAAPI"]
[Tue Jul 21 08:40:05.757229 2026] [security2:error] [pid 465652:tid 465864] [client 20.197.192.193:65187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9alTzTqJoBC2Mw28_d2QAAANc"]
[Tue Jul 21 08:40:06.083627 2026] [security2:error] [pid 465652:tid 465819] [client 20.151.10.161:57560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/xmrl.php"] [unique_id "al9aljzTqJoBC2Mw28_d4AAAAKo"]
[Tue Jul 21 08:40:06.164265 2026] [security2:error] [pid 465652:tid 465796] [client 203.25.124.37:36299] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-config-sample.php"] [unique_id "al9aljzTqJoBC2Mw28_d4gAAAJM"]
[Tue Jul 21 08:40:06.177545 2026] [security2:error] [pid 465652:tid 465885] [client 20.206.105.145:33610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wp-links.php"] [unique_id "al9aljzTqJoBC2Mw28_d4wAAAOw"]
[Tue Jul 21 08:40:06.205667 2026] [security2:error] [pid 465652:tid 465853] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aljzTqJoBC2Mw28_d4QAAzAs"]
[Tue Jul 21 08:40:06.489516 2026] [security2:error] [pid 465652:tid 465859] [client 198.44.157.34:55518] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9aljzTqJoBC2Mw28_d8QAAANI"]
[Tue Jul 21 08:40:06.489620 2026] [security2:error] [pid 465652:tid 465859] [client 198.44.157.34:55518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9aljzTqJoBC2Mw28_d8QAAANI"]
[Tue Jul 21 08:40:06.834521 2026] [security2:error] [pid 465652:tid 465836] [client 59.95.197.55:58773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aljzTqJoBC2Mw28_eCgAAALs"]
[Tue Jul 21 08:40:06.834662 2026] [security2:error] [pid 465652:tid 465836] [client 59.95.197.55:58773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aljzTqJoBC2Mw28_eCgAAALs"]
[Tue Jul 21 08:40:06.859499 2026] [core:alert] [pid 465652:tid 465789] [client 57.141.18.48:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:40:06.987618 2026] [security2:error] [pid 465652:tid 465793] [client 20.220.225.223:12307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9aljzTqJoBC2Mw28_eHAAAAJA"]
[Tue Jul 21 08:40:07.484957 2026] [security2:error] [pid 465652:tid 465872] [client 168.167.81.163:62408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9alzzTqJoBC2Mw28_ePgAAAN8"]
[Tue Jul 21 08:40:07.485064 2026] [security2:error] [pid 465652:tid 465872] [client 168.167.81.163:62408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9alzzTqJoBC2Mw28_ePgAAAN8"]
[Tue Jul 21 08:40:07.559075 2026] [security2:error] [pid 465652:tid 465831] [client 212.32.76.4:34879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403.php"] [unique_id "al9alzzTqJoBC2Mw28_eQQAAALY"]
[Tue Jul 21 08:40:07.641439 2026] [security2:error] [pid 465652:tid 465865] [client 5.38.115.39:53327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9alzzTqJoBC2Mw28_eQwAAANg"]
[Tue Jul 21 08:40:07.641575 2026] [security2:error] [pid 465652:tid 465865] [client 5.38.115.39:53327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9alzzTqJoBC2Mw28_eQwAAANg"]
[Tue Jul 21 08:40:07.808444 2026] [security2:error] [pid 465652:tid 465845] [client 20.151.10.161:60697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/memberfuns.php"] [unique_id "al9alzzTqJoBC2Mw28_eRwAAAMQ"]
[Tue Jul 21 08:40:07.899864 2026] [security2:error] [pid 465652:tid 465796] [client 173.252.95.23:56690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9alzzTqJoBC2Mw28_eTgAAAJM"]
[Tue Jul 21 08:40:07.911522 2026] [security2:error] [pid 465652:tid 465867] [client 122.176.100.127:59152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9alzzTqJoBC2Mw28_eTwAAANo"]
[Tue Jul 21 08:40:07.911648 2026] [security2:error] [pid 465652:tid 465867] [client 122.176.100.127:59152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9alzzTqJoBC2Mw28_eTwAAANo"]
[Tue Jul 21 08:40:08.013629 2026] [security2:error] [pid 465652:tid 465905] [client 20.197.192.193:65158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9amDzTqJoBC2Mw28_eUgAAAQA"]
[Tue Jul 21 08:40:08.159358 2026] [security2:error] [pid 465652:tid 465827] [client 198.44.157.34:34594] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9amDzTqJoBC2Mw28_eUwAAALI"]
[Tue Jul 21 08:40:08.159451 2026] [security2:error] [pid 465652:tid 465827] [client 198.44.157.34:34594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9amDzTqJoBC2Mw28_eUwAAALI"]
[Tue Jul 21 08:40:08.251195 2026] [security2:error] [pid 465652:tid 465852] [client 202.179.75.202:46502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9amDzTqJoBC2Mw28_eVQAAAMs"]
[Tue Jul 21 08:40:08.251314 2026] [security2:error] [pid 465652:tid 465852] [client 202.179.75.202:46502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9amDzTqJoBC2Mw28_eVQAAAMs"]
[Tue Jul 21 08:40:08.426211 2026] [security2:error] [pid 465652:tid 465875] [client 20.206.105.145:33782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/solo1.php"] [unique_id "al9amDzTqJoBC2Mw28_eXwAAAOI"]
[Tue Jul 21 08:40:08.647230 2026] [security2:error] [pid 465652:tid 465820] [client 223.181.60.88:18736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9amDzTqJoBC2Mw28_eYQAAAKs"]
[Tue Jul 21 08:40:08.647384 2026] [security2:error] [pid 465652:tid 465820] [client 223.181.60.88:18736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9amDzTqJoBC2Mw28_eYQAAAKs"]
[Tue Jul 21 08:40:08.662456 2026] [security2:error] [pid 465652:tid 465818] [client 212.32.76.6:24703] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "al9amDzTqJoBC2Mw28_eZgAAAKk"]
[Tue Jul 21 08:40:09.041705 2026] [security2:error] [pid 465652:tid 465810] [client 20.151.10.161:60722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/ms.php"] [unique_id "al9amTzTqJoBC2Mw28_edgAAAKE"]
[Tue Jul 21 08:40:09.519060 2026] [autoindex:error] [pid 465652:tid 465801] [client 43.165.65.117:42900] AH01276: Cannot serve directory /home2/silv4569/silviolevada.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:09.631716 2026] [security2:error] [pid 465652:tid 465886] [client 20.220.225.223:46970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9amTzTqJoBC2Mw28_eiQAAAO0"]
[Tue Jul 21 08:40:09.692222 2026] [security2:error] [pid 465652:tid 465900] [client 20.63.100.92:8972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/inso.php"] [unique_id "al9amTzTqJoBC2Mw28_eiwAAAPs"]
[Tue Jul 21 08:40:09.871929 2026] [security2:error] [pid 465652:tid 465822] [client 74.249.245.134:51496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/brand.php"] [unique_id "al9amTzTqJoBC2Mw28_ejwAAAK0"]
[Tue Jul 21 08:40:09.933700 2026] [security2:error] [pid 465652:tid 465883] [client 20.220.225.223:12311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/dp.php"] [unique_id "al9amTzTqJoBC2Mw28_elgAAAOo"]
[Tue Jul 21 08:40:10.280953 2026] [security2:error] [pid 465652:tid 465903] [client 14.245.224.124:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9amjzTqJoBC2Mw28_engAAAP4"]
[Tue Jul 21 08:40:10.281118 2026] [security2:error] [pid 465652:tid 465903] [client 14.245.224.124:61395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9amjzTqJoBC2Mw28_engAAAP4"]
[Tue Jul 21 08:40:10.336006 2026] [core:error] [pid 465652:tid 465664] [remote 57.141.18.73:45366] AH10244: invalid URI path (/%post_type%/dicas-para-voce-planejar-a-compra-de-seu-imovel/)
[Tue Jul 21 08:40:10.363240 2026] [security2:error] [pid 465652:tid 465835] [client 203.25.124.52:55919] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/"] [unique_id "al9amjzTqJoBC2Mw28_eogAAALo"]
[Tue Jul 21 08:40:10.453558 2026] [security2:error] [pid 465652:tid 465894] [client 20.151.10.161:51215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/zz.php"] [unique_id "al9amjzTqJoBC2Mw28_eqAAAAPU"]
[Tue Jul 21 08:40:10.526525 2026] [security2:error] [pid 465652:tid 465838] [client 20.206.105.145:33767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/sixxis.php"] [unique_id "al9amjzTqJoBC2Mw28_erAAAAL0"]
[Tue Jul 21 08:40:10.747954 2026] [security2:error] [pid 465652:tid 465885] [client 195.49.128.211:50204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9amjzTqJoBC2Mw28_etAAAAOw"]
[Tue Jul 21 08:40:10.748112 2026] [security2:error] [pid 465652:tid 465885] [client 195.49.128.211:50204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9amjzTqJoBC2Mw28_etAAAAOw"]
[Tue Jul 21 08:40:10.817489 2026] [security2:error] [pid 465652:tid 465705] [remote 72.167.132.114:36152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lojadedoces.com"] [uri "/wp-login.php"] [unique_id "al9amjzTqJoBC2Mw28_etQAAyjQ"]
[Tue Jul 21 08:40:11.245285 2026] [security2:error] [pid 465652:tid 465866] [client 20.206.105.145:33624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/2P.update.php"] [unique_id "al9amzzTqJoBC2Mw28_evgAAANk"]
[Tue Jul 21 08:40:11.496046 2026] [security2:error] [pid 465652:tid 465833] [client 213.152.162.15:38586] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9amzzTqJoBC2Mw28_ewwAAALg"]
[Tue Jul 21 08:40:11.496166 2026] [security2:error] [pid 465652:tid 465833] [client 213.152.162.15:38586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9amzzTqJoBC2Mw28_ewwAAALg"]
[Tue Jul 21 08:40:11.676867 2026] [security2:error] [pid 465652:tid 465870] [client 20.151.10.161:60698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/for.php"] [unique_id "al9amzzTqJoBC2Mw28_e0AAAAN0"]
[Tue Jul 21 08:40:11.736867 2026] [security2:error] [pid 465652:tid 465894] [client 20.226.60.151:58505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/24.php"] [unique_id "al9amzzTqJoBC2Mw28_e1QAAAPU"]
[Tue Jul 21 08:40:11.761039 2026] [security2:error] [pid 465652:tid 465784] [client 212.32.76.4:31381] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/item.php"] [unique_id "al9amzzTqJoBC2Mw28_e1gAAAIc"]
[Tue Jul 21 08:40:11.793544 2026] [security2:error] [pid 465652:tid 465722] [remote 5.252.52.249:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9amzzTqJoBC2Mw28_e2QABAUU"]
[Tue Jul 21 08:40:11.872960 2026] [security2:error] [pid 465652:tid 465899] [client 152.59.181.104:60320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9amzzTqJoBC2Mw28_e3QAAAPo"]
[Tue Jul 21 08:40:11.877638 2026] [security2:error] [pid 465652:tid 465899] [client 152.59.181.104:60320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9amzzTqJoBC2Mw28_e3QAAAPo"]
[Tue Jul 21 08:40:11.935502 2026] [security2:error] [pid 465652:tid 465782] [client 20.206.105.145:33731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/a.php"] [unique_id "al9amzzTqJoBC2Mw28_e3wAAAIU"]
[Tue Jul 21 08:40:12.246846 2026] [security2:error] [pid 465652:tid 465827] [client 152.59.34.51:63598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9anDzTqJoBC2Mw28_fGAAAALI"]
[Tue Jul 21 08:40:12.246970 2026] [security2:error] [pid 465652:tid 465827] [client 152.59.34.51:63598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9anDzTqJoBC2Mw28_fGAAAALI"]
[Tue Jul 21 08:40:12.687805 2026] [security2:error] [pid 465652:tid 465749] [remote 54.64.35.240:43996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.35.64.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9anDzTqJoBC2Mw28_fKwAAwmA"]
[Tue Jul 21 08:40:12.788364 2026] [security2:error] [pid 465652:tid 465791] [client 127.0.0.1:36674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al9anDzTqJoBC2Mw28_fLgAAAI4"]
[Tue Jul 21 08:40:12.788435 2026] [security2:error] [pid 465652:tid 465810] [client 74.7.230.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "autodiscover.soutendenciaenergia.com.br"] [uri "/robots.txt"] [unique_id "al9anDzTqJoBC2Mw28_fLQAAAKE"]
[Tue Jul 21 08:40:12.852316 2026] [security2:error] [pid 465652:tid 465867] [client 20.151.10.161:57577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/yup.php"] [unique_id "al9anDzTqJoBC2Mw28_fMgAAANo"]
[Tue Jul 21 08:40:12.862744 2026] [core:alert] [pid 465652:tid 465836] [client 66.249.66.11:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:40:12.971558 2026] [security2:error] [pid 465652:tid 465782] [client 114.119.151.146:63707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sphawks.com.br"] [uri "/wp-content/uploads/2019/10/69308672_10220098605925617_3796315386706657280_n-150x150.jpg"] [unique_id "al9anDzTqJoBC2Mw28_fNgAAAIU"], referer: http://sphawks.com.br/wp-content/uploads/2019/10/69308672_10220098605925617_3796315386706657280_n-150x150.jpg
[Tue Jul 21 08:40:13.051699 2026] [security2:error] [pid 465652:tid 465653] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9anTzTqJoBC2Mw28_fOAAAhwA"]
[Tue Jul 21 08:40:13.051882 2026] [security2:error] [pid 465652:tid 465784] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9anTzTqJoBC2Mw28_fOAAAhwA"]
[Tue Jul 21 08:40:13.066973 2026] [security2:error] [pid 465652:tid 465885] [client 203.25.124.53:40509] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/adminfuns.php"] [unique_id "al9anTzTqJoBC2Mw28_fOwAAAOw"]
[Tue Jul 21 08:40:13.459088 2026] [security2:error] [pid 465652:tid 465865] [client 20.206.105.145:33604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/k.php"] [unique_id "al9anTzTqJoBC2Mw28_fSAAAANg"]
[Tue Jul 21 08:40:13.675502 2026] [security2:error] [pid 465652:tid 465904] [client 20.151.10.161:60680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/wpxml.php"] [unique_id "al9anTzTqJoBC2Mw28_fUwAAAP8"]
[Tue Jul 21 08:40:13.967301 2026] [security2:error] [pid 465652:tid 465828] [client 203.25.124.39:56525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wpx/"] [unique_id "al9anTzTqJoBC2Mw28_fVgAAALM"]
[Tue Jul 21 08:40:14.086883 2026] [security2:error] [pid 465652:tid 465858] [client 114.119.145.126:59887] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.pousadaalpesdeminas.com.br"] [uri "/index.html"] [unique_id "al9anjzTqJoBC2Mw28_fWAAAANE"], referer: https://www.pousadaalpesdeminas.com.br/index.html
[Tue Jul 21 08:40:14.088549 2026] [security2:error] [pid 465652:tid 465902] [client 195.49.128.211:58003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9anjzTqJoBC2Mw28_fWQAAAP0"]
[Tue Jul 21 08:40:14.088634 2026] [security2:error] [pid 465652:tid 465902] [client 195.49.128.211:58003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9anjzTqJoBC2Mw28_fWQAAAP0"]
[Tue Jul 21 08:40:14.113889 2026] [security2:error] [pid 465652:tid 465867] [client 49.144.66.253:32947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9anjzTqJoBC2Mw28_fXQAAANo"]
[Tue Jul 21 08:40:14.113966 2026] [security2:error] [pid 465652:tid 465867] [client 49.144.66.253:32947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9anjzTqJoBC2Mw28_fXQAAANo"]
[Tue Jul 21 08:40:14.203803 2026] [security2:error] [pid 465652:tid 465853] [client 20.151.10.161:51212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/fffm.php"] [unique_id "al9anjzTqJoBC2Mw28_fYQAAAMw"]
[Tue Jul 21 08:40:14.217990 2026] [security2:error] [pid 465652:tid 465859] [client 20.220.225.223:40764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9anjzTqJoBC2Mw28_fYgAAANI"]
[Tue Jul 21 08:40:14.429254 2026] [security2:error] [pid 465652:tid 465790] [client 20.206.105.145:33601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/w.php"] [unique_id "al9anjzTqJoBC2Mw28_faQAAAI0"]
[Tue Jul 21 08:40:14.535770 2026] [security2:error] [pid 465652:tid 465838] [client 117.213.202.34:56155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9anjzTqJoBC2Mw28_fbgAAAL0"]
[Tue Jul 21 08:40:14.535898 2026] [security2:error] [pid 465652:tid 465838] [client 117.213.202.34:56155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9anjzTqJoBC2Mw28_fbgAAAL0"]
[Tue Jul 21 08:40:14.951369 2026] [security2:error] [pid 465652:tid 465815] [client 20.151.10.161:51224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/gecko.php"] [unique_id "al9anjzTqJoBC2Mw28_feQAAAKY"]
[Tue Jul 21 08:40:14.971163 2026] [security2:error] [pid 465652:tid 465710] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9anjzTqJoBC2Mw28_fewAA-Dk"]
[Tue Jul 21 08:40:14.971316 2026] [security2:error] [pid 465652:tid 465897] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9anjzTqJoBC2Mw28_fewAA-Dk"]
[Tue Jul 21 08:40:15.107662 2026] [security2:error] [pid 465652:tid 465835] [client 20.220.225.223:12321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/old.php"] [unique_id "al9anzzTqJoBC2Mw28_ffQAAALo"]
[Tue Jul 21 08:40:15.369265 2026] [security2:error] [pid 465652:tid 465720] [remote 52.167.144.159:6425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bracksimoveis.com.br"] [uri "/video.php/app225/double-double-no-basquete/"] [unique_id "al9anzzTqJoBC2Mw28_figAAhUM"]
[Tue Jul 21 08:40:15.547073 2026] [security2:error] [pid 465652:tid 465859] [client 20.206.105.145:33738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/insc.php"] [unique_id "al9anzzTqJoBC2Mw28_fjQAAANI"]
[Tue Jul 21 08:40:15.815004 2026] [security2:error] [pid 465652:tid 465838] [client 20.151.10.161:51204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/a1.php"] [unique_id "al9anzzTqJoBC2Mw28_flwAAAL0"]
[Tue Jul 21 08:40:15.911747 2026] [security2:error] [pid 465652:tid 465799] [client 20.220.225.223:54313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wp-explorer.php"] [unique_id "al9anzzTqJoBC2Mw28_fmQAAAJY"]
[Tue Jul 21 08:40:15.917276 2026] [security2:error] [pid 465652:tid 465883] [client 20.220.225.223:54307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/dp.php"] [unique_id "al9anzzTqJoBC2Mw28_fmgAAAOo"]
[Tue Jul 21 08:40:15.968982 2026] [security2:error] [pid 465652:tid 465879] [client 212.32.76.2:54067] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/files.php"] [unique_id "al9anzzTqJoBC2Mw28_fnAAAAOY"]
[Tue Jul 21 08:40:16.624277 2026] [security2:error] [pid 465652:tid 465809] [client 168.167.81.163:65125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9aoDzTqJoBC2Mw28_ftgAAAKA"]
[Tue Jul 21 08:40:16.624417 2026] [security2:error] [pid 465652:tid 465809] [client 168.167.81.163:65125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9aoDzTqJoBC2Mw28_ftgAAAKA"]
[Tue Jul 21 08:40:16.632170 2026] [security2:error] [pid 465652:tid 465772] [remote 20.75.217.75:4908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9aoDzTqJoBC2Mw28_ftwAA3Xc"]
[Tue Jul 21 08:40:16.726802 2026] [security2:error] [pid 465652:tid 465902] [client 20.220.225.223:54283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/old.php"] [unique_id "al9aoDzTqJoBC2Mw28_fuQAAAP0"]
[Tue Jul 21 08:40:16.775666 2026] [security2:error] [pid 465652:tid 465852] [client 20.206.105.145:46026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9aoDzTqJoBC2Mw28_fvQAAAMs"]
[Tue Jul 21 08:40:16.825323 2026] [security2:error] [pid 465652:tid 465853] [client 20.206.105.145:45326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9aoDzTqJoBC2Mw28_fwQAAAMw"]
[Tue Jul 21 08:40:16.852337 2026] [security2:error] [pid 465652:tid 465813] [client 20.206.105.145:45319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/media.php"] [unique_id "al9aoDzTqJoBC2Mw28_fwgAAAKQ"]
[Tue Jul 21 08:40:16.924667 2026] [security2:error] [pid 465652:tid 465830] [client 20.206.105.145:45375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/images.php"] [unique_id "al9aoDzTqJoBC2Mw28_fxAAAALU"]
[Tue Jul 21 08:40:16.980937 2026] [security2:error] [pid 465652:tid 465888] [client 20.206.105.145:45334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/adminner.php"] [unique_id "al9aoDzTqJoBC2Mw28_fxQAAAO8"]
[Tue Jul 21 08:40:16.993035 2026] [security2:error] [pid 465652:tid 465885] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aoDzTqJoBC2Mw28_fwwAA7BE"]
[Tue Jul 21 08:40:17.066378 2026] [access_compat:error] [pid 465652:tid 465879] [client 162.241.63.68:19992] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:40:17.074553 2026] [security2:error] [pid 465652:tid 465829] [client 20.206.105.145:45352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/admin.php"] [unique_id "al9aoTzTqJoBC2Mw28_fyQAAALQ"]
[Tue Jul 21 08:40:17.097877 2026] [security2:error] [pid 465652:tid 465899] [client 20.206.105.145:45318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/k.php"] [unique_id "al9aoTzTqJoBC2Mw28_fygAAAPo"]
[Tue Jul 21 08:40:17.120022 2026] [security2:error] [pid 465652:tid 465903] [client 20.206.105.145:45330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/x.php"] [unique_id "al9aoTzTqJoBC2Mw28_fzQAAAP4"]
[Tue Jul 21 08:40:17.126537 2026] [security2:error] [pid 465652:tid 465814] [client 20.151.10.161:60745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/k2.php"] [unique_id "al9aoTzTqJoBC2Mw28_fzwAAAKU"]
[Tue Jul 21 08:40:17.133396 2026] [security2:error] [pid 465652:tid 465789] [client 59.95.197.55:59219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aoTzTqJoBC2Mw28_fzgAAAIw"]
[Tue Jul 21 08:40:17.133519 2026] [security2:error] [pid 465652:tid 465789] [client 59.95.197.55:59219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aoTzTqJoBC2Mw28_fzgAAAIw"]
[Tue Jul 21 08:40:17.149163 2026] [security2:error] [pid 465652:tid 465815] [client 20.206.105.145:45341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wss.php"] [unique_id "al9aoTzTqJoBC2Mw28_f0QAAAKY"]
[Tue Jul 21 08:40:17.157375 2026] [security2:error] [pid 465652:tid 465835] [client 203.25.124.64:23761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/news-portal/zdata.php"] [unique_id "al9aoTzTqJoBC2Mw28_f0gAAALo"]
[Tue Jul 21 08:40:17.246872 2026] [security2:error] [pid 465652:tid 465836] [client 20.206.105.145:46047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/ty.php"] [unique_id "al9aoTzTqJoBC2Mw28_f2gAAALs"]
[Tue Jul 21 08:40:17.252491 2026] [security2:error] [pid 465652:tid 465791] [client 20.63.100.92:6081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/wpx.php"] [unique_id "al9aoTzTqJoBC2Mw28_f2wAAAI4"]
[Tue Jul 21 08:40:17.347441 2026] [security2:error] [pid 465652:tid 465902] [client 20.206.105.145:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/155.php"] [unique_id "al9aoTzTqJoBC2Mw28_f4QAAAP0"]
[Tue Jul 21 08:40:17.389601 2026] [security2:error] [pid 465652:tid 465820] [client 20.220.225.223:46943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/akismet.php"] [unique_id "al9aoTzTqJoBC2Mw28_f4wAAAKs"]
[Tue Jul 21 08:40:17.592843 2026] [security2:error] [pid 465652:tid 465864] [client 20.206.105.145:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/ops.php"] [unique_id "al9aoTzTqJoBC2Mw28_f5gAAANc"]
[Tue Jul 21 08:40:17.704511 2026] [security2:error] [pid 465652:tid 465790] [client 20.206.105.145:46024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/ingfo.php"] [unique_id "al9aoTzTqJoBC2Mw28_f5wAAAI0"]
[Tue Jul 21 08:40:17.772553 2026] [security2:error] [pid 465652:tid 465887] [client 20.206.105.145:45317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/error_log.php"] [unique_id "al9aoTzTqJoBC2Mw28_f6AAAAO4"]
[Tue Jul 21 08:40:17.834307 2026] [security2:error] [pid 465652:tid 465859] [client 61.1.167.83:53179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aoTzTqJoBC2Mw28_f7QAAANI"]
[Tue Jul 21 08:40:17.834443 2026] [security2:error] [pid 465652:tid 465859] [client 61.1.167.83:53179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aoTzTqJoBC2Mw28_f7QAAANI"]
[Tue Jul 21 08:40:17.865891 2026] [security2:error] [pid 465652:tid 465787] [client 20.206.105.145:45337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/ok.php"] [unique_id "al9aoTzTqJoBC2Mw28_f9AAAAIo"]
[Tue Jul 21 08:40:17.867367 2026] [security2:error] [pid 465652:tid 465878] [client 167.114.139.167:57958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.farmacianaturofarma.com.br"] [uri "/robots.txt"] [unique_id "al9aoTzTqJoBC2Mw28_f9QAAAOU"]
[Tue Jul 21 08:40:17.867452 2026] [security2:error] [pid 465652:tid 465878] [client 167.114.139.167:57958] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.farmacianaturofarma.com.br"] [uri "/robots.txt"] [unique_id "al9aoTzTqJoBC2Mw28_f9QAAAOU"]
[Tue Jul 21 08:40:17.927655 2026] [security2:error] [pid 465652:tid 465855] [client 20.220.225.223:40756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/ms-new.php"] [unique_id "al9aoTzTqJoBC2Mw28_f9wAAAM4"]
[Tue Jul 21 08:40:17.927880 2026] [security2:error] [pid 465652:tid 465899] [client 20.220.225.223:12300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/ms-new.php"] [unique_id "al9aoTzTqJoBC2Mw28_f-AAAAPo"]
[Tue Jul 21 08:40:17.980708 2026] [security2:error] [pid 465652:tid 465657] [remote 65.111.30.180:60837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.30.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9aoTzTqJoBC2Mw28_f7AABAwQ"]
[Tue Jul 21 08:40:18.010421 2026] [security2:error] [pid 465652:tid 465785] [client 20.206.105.145:33648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9aojzTqJoBC2Mw28_f-gAAAIg"]
[Tue Jul 21 08:40:18.031661 2026] [security2:error] [pid 465652:tid 465814] [client 20.206.105.145:45358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/mac.php"] [unique_id "al9aojzTqJoBC2Mw28_f-wAAAKU"]
[Tue Jul 21 08:40:18.069245 2026] [security2:error] [pid 465652:tid 465841] [client 203.25.124.50:29077] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/css/"] [unique_id "al9aojzTqJoBC2Mw28_f_AAAAMA"]
[Tue Jul 21 08:40:18.173641 2026] [security2:error] [pid 465652:tid 465872] [client 20.206.105.145:45324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wefile.php"] [unique_id "al9aojzTqJoBC2Mw28_f_QAAAN8"]
[Tue Jul 21 08:40:18.287160 2026] [security2:error] [pid 465652:tid 465874] [client 20.206.105.145:45975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9aojzTqJoBC2Mw28_gAgAAAOE"]
[Tue Jul 21 08:40:18.347248 2026] [security2:error] [pid 465652:tid 465844] [client 122.176.100.127:59666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aojzTqJoBC2Mw28_gBwAAAMM"]
[Tue Jul 21 08:40:18.347485 2026] [security2:error] [pid 465652:tid 465844] [client 122.176.100.127:59666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9aojzTqJoBC2Mw28_gBwAAAMM"]
[Tue Jul 21 08:40:18.353199 2026] [autoindex:error] [pid 465652:tid 465870] [client 20.206.105.145:45331] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:18.368209 2026] [security2:error] [pid 465652:tid 465852] [client 20.151.10.161:57557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/82.php"] [unique_id "al9aojzTqJoBC2Mw28_gCQAAAMs"]
[Tue Jul 21 08:40:18.382968 2026] [security2:error] [pid 465652:tid 465834] [client 5.38.115.39:53872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aojzTqJoBC2Mw28_gDQAAALk"]
[Tue Jul 21 08:40:18.383123 2026] [security2:error] [pid 465652:tid 465834] [client 5.38.115.39:53872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9aojzTqJoBC2Mw28_gDQAAALk"]
[Tue Jul 21 08:40:18.420393 2026] [autoindex:error] [pid 465652:tid 465786] [client 20.206.105.145:45331] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:18.425551 2026] [security2:error] [pid 465652:tid 465801] [client 20.206.105.145:45331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9aojzTqJoBC2Mw28_gEAAAAJg"]
[Tue Jul 21 08:40:18.474360 2026] [security2:error] [pid 465652:tid 465850] [client 65.21.113.253:51992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aojzTqJoBC2Mw28_gAAAAAMk"]
[Tue Jul 21 08:40:18.702300 2026] [security2:error] [pid 465652:tid 465838] [client 20.206.105.145:45367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/like.php"] [unique_id "al9aojzTqJoBC2Mw28_gFQAAAL0"]
[Tue Jul 21 08:40:18.845602 2026] [security2:error] [pid 465652:tid 465836] [client 5.31.193.106:58579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aojzTqJoBC2Mw28_gGQAAALs"]
[Tue Jul 21 08:40:18.845726 2026] [security2:error] [pid 465652:tid 465836] [client 5.31.193.106:58579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aojzTqJoBC2Mw28_gGQAAALs"]
[Tue Jul 21 08:40:18.892655 2026] [security2:error] [pid 465652:tid 465819] [client 20.206.105.145:46034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/.well-known/about.php"] [unique_id "al9aojzTqJoBC2Mw28_gHQAAAKo"]
[Tue Jul 21 08:40:19.003714 2026] [security2:error] [pid 465652:tid 465841] [client 20.220.225.223:40757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/track.php"] [unique_id "al9aozzTqJoBC2Mw28_gIwAAAMA"]
[Tue Jul 21 08:40:19.144421 2026] [security2:error] [pid 465652:tid 465891] [client 20.206.105.145:45360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9aozzTqJoBC2Mw28_gJwAAAPI"]
[Tue Jul 21 08:40:19.249902 2026] [security2:error] [pid 465652:tid 465875] [client 202.179.75.202:49834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aozzTqJoBC2Mw28_gKQAAAOI"]
[Tue Jul 21 08:40:19.250627 2026] [security2:error] [pid 465652:tid 465875] [client 202.179.75.202:49834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9aozzTqJoBC2Mw28_gKQAAAOI"]
[Tue Jul 21 08:40:19.261620 2026] [security2:error] [pid 465652:tid 465783] [client 198.244.168.120:52172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.farmacianaturofarma.com.br"] [uri "/"] [unique_id "al9aozzTqJoBC2Mw28_gKgAAAIY"]
[Tue Jul 21 08:40:19.261845 2026] [security2:error] [pid 465652:tid 465783] [client 198.244.168.120:52172] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.farmacianaturofarma.com.br"] [uri "/"] [unique_id "al9aozzTqJoBC2Mw28_gKgAAAIY"]
[Tue Jul 21 08:40:19.297668 2026] [security2:error] [pid 465652:tid 465864] [client 223.181.60.88:27808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aozzTqJoBC2Mw28_gLAAAANc"]
[Tue Jul 21 08:40:19.297929 2026] [security2:error] [pid 465652:tid 465864] [client 223.181.60.88:27808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9aozzTqJoBC2Mw28_gLAAAANc"]
[Tue Jul 21 08:40:19.373949 2026] [security2:error] [pid 465652:tid 465871] [client 203.25.124.41:58987] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/classwithtostring.php"] [unique_id "al9aozzTqJoBC2Mw28_gMAAAAN4"]
[Tue Jul 21 08:40:19.377904 2026] [autoindex:error] [pid 465652:tid 465851] [client 20.206.105.145:45332] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:19.448003 2026] [autoindex:error] [pid 465652:tid 465844] [client 20.206.105.145:45332] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:19.453342 2026] [security2:error] [pid 465652:tid 465801] [client 20.206.105.145:45332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/pucci.php"] [unique_id "al9aozzTqJoBC2Mw28_gOgAAAJg"]
[Tue Jul 21 08:40:19.566277 2026] [security2:error] [pid 465652:tid 465826] [client 20.151.10.161:51235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/config.json.php"] [unique_id "al9aozzTqJoBC2Mw28_gQQAAALE"]
[Tue Jul 21 08:40:19.574946 2026] [security2:error] [pid 465652:tid 465887] [client 198.44.157.34:60594] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aozzTqJoBC2Mw28_gQgAAAO4"]
[Tue Jul 21 08:40:19.575055 2026] [security2:error] [pid 465652:tid 465887] [client 198.44.157.34:60594] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aozzTqJoBC2Mw28_gQgAAAO4"]
[Tue Jul 21 08:40:19.575076 2026] [security2:error] [pid 465652:tid 465887] [client 198.44.157.34:60594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9aozzTqJoBC2Mw28_gQgAAAO4"]
[Tue Jul 21 08:40:19.622855 2026] [security2:error] [pid 465652:tid 465822] [client 103.76.88.36:56658] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aronconsultoria.com"] [uri "/.env"] [unique_id "al9aozzTqJoBC2Mw28_gRQAAAK0"]
[Tue Jul 21 08:40:19.631540 2026] [autoindex:error] [pid 465652:tid 465846] [client 20.206.105.145:46023] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:19.641228 2026] [security2:error] [pid 465652:tid 465785] [client 65.21.113.253:51996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aozzTqJoBC2Mw28_gKAAAAIg"]
[Tue Jul 21 08:40:19.665141 2026] [autoindex:error] [pid 465652:tid 465879] [client 20.206.105.145:46023] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:19.673300 2026] [security2:error] [pid 465652:tid 465784] [client 20.206.105.145:46023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wp-temp.php"] [unique_id "al9aozzTqJoBC2Mw28_gSgAAAIc"]
[Tue Jul 21 08:40:19.684471 2026] [security2:error] [pid 465652:tid 465855] [client 74.7.228.10:59898] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aizenpower.shop-officialstore.com"] [uri "/index.php"] [unique_id "al9aozzTqJoBC2Mw28_gJAAAzkA"]
[Tue Jul 21 08:40:19.728507 2026] [security2:error] [pid 465652:tid 465800] [client 103.76.88.36:57311] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aron.adv.br"] [uri "/.env"] [unique_id "al9aozzTqJoBC2Mw28_gSwAAAJc"]
[Tue Jul 21 08:40:19.758895 2026] [autoindex:error] [pid 465652:tid 465829] [client 20.206.105.145:45363] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:19.768399 2026] [security2:error] [pid 465652:tid 465899] [client 20.206.105.145:45363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/xmu.php"] [unique_id "al9aozzTqJoBC2Mw28_gTgAAAPo"]
[Tue Jul 21 08:40:19.798605 2026] [security2:error] [pid 465652:tid 465893] [client 103.76.88.36:58889] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aron.adv.br.tainaracamara.adv.br"] [uri "/.env"] [unique_id "al9aozzTqJoBC2Mw28_gTwAAAPQ"]
[Tue Jul 21 08:40:19.850650 2026] [security2:error] [pid 465652:tid 465853] [client 103.76.88.36:59215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aronconsultoria.com.tainaracamara.adv.br"] [uri "/.env"] [unique_id "al9aozzTqJoBC2Mw28_gUAAAAMw"]
[Tue Jul 21 08:40:19.884514 2026] [security2:error] [pid 465652:tid 465858] [client 20.206.105.145:46025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9aozzTqJoBC2Mw28_gUQAAANE"]
[Tue Jul 21 08:40:19.927628 2026] [security2:error] [pid 465652:tid 465894] [client 20.206.105.145:33630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/u.php"] [unique_id "al9aozzTqJoBC2Mw28_gVAAAAPU"]
[Tue Jul 21 08:40:19.985578 2026] [security2:error] [pid 465652:tid 465869] [client 20.206.105.145:46018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/puc.php"] [unique_id "al9aozzTqJoBC2Mw28_gVgAAANw"]
[Tue Jul 21 08:40:20.086364 2026] [security2:error] [pid 465652:tid 465782] [client 20.206.105.145:45321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/themes.php"] [unique_id "al9apDzTqJoBC2Mw28_gXgAAAIU"]
[Tue Jul 21 08:40:20.168564 2026] [security2:error] [pid 465652:tid 465906] [client 20.226.60.151:58515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xacs.php"] [unique_id "al9apDzTqJoBC2Mw28_gYgAAAQE"]
[Tue Jul 21 08:40:20.292031 2026] [autoindex:error] [pid 465652:tid 465820] [client 20.206.105.145:45350] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:20.302235 2026] [security2:error] [pid 465652:tid 465833] [client 20.206.105.145:45350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/8.php"] [unique_id "al9apDzTqJoBC2Mw28_gZwAAALg"]
[Tue Jul 21 08:40:20.322398 2026] [security2:error] [pid 465652:tid 465674] [remote 65.111.6.250:23985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.6.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9apDzTqJoBC2Mw28_gaAAA2hU"]
[Tue Jul 21 08:40:20.659736 2026] [security2:error] [pid 465652:tid 465894] [client 20.206.105.145:45343] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ericksheik.com.br"] [uri "/1.php"] [unique_id "al9apDzTqJoBC2Mw28_gfAAAAPU"]
[Tue Jul 21 08:40:20.659867 2026] [security2:error] [pid 465652:tid 465894] [client 20.206.105.145:45343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/1.php"] [unique_id "al9apDzTqJoBC2Mw28_gfAAAAPU"]
[Tue Jul 21 08:40:20.762577 2026] [security2:error] [pid 465652:tid 465851] [client 203.25.124.37:54027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/"] [unique_id "al9apDzTqJoBC2Mw28_ghQAAAMo"]
[Tue Jul 21 08:40:20.826870 2026] [security2:error] [pid 465652:tid 465862] [client 20.220.225.223:63318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/2352356666.php"] [unique_id "al9apDzTqJoBC2Mw28_ghgAAANU"]
[Tue Jul 21 08:40:20.927594 2026] [security2:error] [pid 465652:tid 465906] [client 20.206.105.145:45314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/100.php"] [unique_id "al9apDzTqJoBC2Mw28_giAAAAQE"]
[Tue Jul 21 08:40:20.929454 2026] [security2:error] [pid 465652:tid 465844] [client 20.206.105.145:33715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/sss.php"] [unique_id "al9apDzTqJoBC2Mw28_giQAAAMM"]
[Tue Jul 21 08:40:20.983172 2026] [security2:error] [pid 465652:tid 465874] [client 20.206.105.145:46055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/about.php"] [unique_id "al9apDzTqJoBC2Mw28_giwAAAOE"]
[Tue Jul 21 08:40:21.105171 2026] [security2:error] [pid 465652:tid 465879] [client 20.206.105.145:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/about.php"] [unique_id "al9apTzTqJoBC2Mw28_glgAAAOY"]
[Tue Jul 21 08:40:21.105586 2026] [security2:error] [pid 465652:tid 465830] [client 20.151.10.161:57579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "crm.lupipet.com.br"] [uri "/fpwch.php"] [unique_id "al9apTzTqJoBC2Mw28_glwAAALU"]
[Tue Jul 21 08:40:21.130612 2026] [security2:error] [pid 465652:tid 465799] [client 14.245.224.124:61878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9apTzTqJoBC2Mw28_gmAAAAJY"]
[Tue Jul 21 08:40:21.130721 2026] [security2:error] [pid 465652:tid 465799] [client 14.245.224.124:61878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9apTzTqJoBC2Mw28_gmAAAAJY"]
[Tue Jul 21 08:40:21.244418 2026] [security2:error] [pid 465652:tid 465843] [client 20.206.105.145:45342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/admin.php"] [unique_id "al9apTzTqJoBC2Mw28_gmwAAAMI"]
[Tue Jul 21 08:40:21.433274 2026] [security2:error] [pid 465652:tid 465775] [remote 103.28.36.122:42234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wp-login.php"] [unique_id "al9apTzTqJoBC2Mw28_gnQAAuXo"]
[Tue Jul 21 08:40:21.437138 2026] [security2:error] [pid 465652:tid 465786] [client 195.49.128.211:50800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9apTzTqJoBC2Mw28_gnwAAAIk"]
[Tue Jul 21 08:40:21.437267 2026] [security2:error] [pid 465652:tid 465786] [client 195.49.128.211:50800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9apTzTqJoBC2Mw28_gnwAAAIk"]
[Tue Jul 21 08:40:21.458769 2026] [security2:error] [pid 465652:tid 465894] [client 20.206.105.145:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/admin.php"] [unique_id "al9apTzTqJoBC2Mw28_goAAAAPU"]
[Tue Jul 21 08:40:21.468443 2026] [security2:error] [pid 465652:tid 465793] [client 20.220.225.223:40746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/pn.php"] [unique_id "al9apTzTqJoBC2Mw28_goQAAAJA"]
[Tue Jul 21 08:40:21.550928 2026] [security2:error] [pid 465652:tid 465875] [client 20.206.105.145:45333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/edit.php"] [unique_id "al9apTzTqJoBC2Mw28_grAAAAOI"]
[Tue Jul 21 08:40:21.598614 2026] [security2:error] [pid 465652:tid 465782] [client 20.220.225.223:47760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/ace2.php"] [unique_id "al9apTzTqJoBC2Mw28_grgAAAIU"]
[Tue Jul 21 08:40:21.609848 2026] [security2:error] [pid 465652:tid 465840] [client 20.197.192.193:43790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/wander.php"] [unique_id "al9apTzTqJoBC2Mw28_grwAAAL8"]
[Tue Jul 21 08:40:21.748607 2026] [security2:error] [pid 465652:tid 465890] [client 20.206.105.145:45344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9apTzTqJoBC2Mw28_gtwAAAPE"]
[Tue Jul 21 08:40:21.780378 2026] [security2:error] [pid 465652:tid 465806] [client 203.25.124.32:27851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9apTzTqJoBC2Mw28_guQAAAJ0"]
[Tue Jul 21 08:40:21.806846 2026] [security2:error] [pid 465652:tid 465838] [client 74.249.245.134:11714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/atomlib.php"] [unique_id "al9apTzTqJoBC2Mw28_guwAAAL0"]
[Tue Jul 21 08:40:21.917072 2026] [security2:error] [pid 465652:tid 465799] [client 20.206.105.145:45338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/f6.php"] [unique_id "al9apTzTqJoBC2Mw28_gvgAAAJY"]
[Tue Jul 21 08:40:21.946875 2026] [security2:error] [pid 465652:tid 465878] [client 185.198.240.89:56477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-login.php"] [unique_id "al9apTzTqJoBC2Mw28_gvwAAAOU"]
[Tue Jul 21 08:40:21.958847 2026] [security2:error] [pid 465652:tid 465855] [client 20.206.105.145:45327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/inputs.php"] [unique_id "al9apTzTqJoBC2Mw28_gwAAAAM4"]
[Tue Jul 21 08:40:21.988976 2026] [security2:error] [pid 465652:tid 465865] [client 20.206.105.145:45339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/inputs.php"] [unique_id "al9apTzTqJoBC2Mw28_gwgAAANg"]
[Tue Jul 21 08:40:22.062613 2026] [security2:error] [pid 465652:tid 465826] [client 20.206.105.145:45993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/av.php"] [unique_id "al9apjzTqJoBC2Mw28_gyAAAALE"]
[Tue Jul 21 08:40:22.089614 2026] [security2:error] [pid 465652:tid 465815] [client 20.206.105.145:46044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/classwithtostring.php"] [unique_id "al9apjzTqJoBC2Mw28_gygAAAKY"]
[Tue Jul 21 08:40:22.100232 2026] [security2:error] [pid 465652:tid 465902] [client 173.252.95.43:64956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9apDzTqJoBC2Mw28_gigAAAP0"]
[Tue Jul 21 08:40:22.192437 2026] [security2:error] [pid 465652:tid 465909] [client 20.206.105.145:46043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9apjzTqJoBC2Mw28_g0gAAAQQ"]
[Tue Jul 21 08:40:22.253826 2026] [security2:error] [pid 465652:tid 465783] [client 103.59.206.240:31391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9apjzTqJoBC2Mw28_g1QAAAIY"]
[Tue Jul 21 08:40:22.253938 2026] [security2:error] [pid 465652:tid 465783] [client 103.59.206.240:31391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9apjzTqJoBC2Mw28_g1QAAAIY"]
[Tue Jul 21 08:40:22.363279 2026] [security2:error] [pid 465652:tid 465782] [client 20.206.105.145:45353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wp-blog.php"] [unique_id "al9apjzTqJoBC2Mw28_g2gAAAIU"]
[Tue Jul 21 08:40:22.460611 2026] [security2:error] [pid 465652:tid 465881] [client 203.25.124.39:41989] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/fm.php"] [unique_id "al9apjzTqJoBC2Mw28_g3gAAAOg"]
[Tue Jul 21 08:40:22.575777 2026] [security2:error] [pid 465652:tid 465798] [client 152.59.181.104:60781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9apjzTqJoBC2Mw28_g3wAAAJU"]
[Tue Jul 21 08:40:22.575981 2026] [security2:error] [pid 465652:tid 465798] [client 152.59.181.104:60781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9apjzTqJoBC2Mw28_g3wAAAJU"]
[Tue Jul 21 08:40:22.619027 2026] [autoindex:error] [pid 465652:tid 465833] [client 20.206.105.145:45313] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:22.723353 2026] [security2:error] [pid 465652:tid 465882] [client 20.206.105.145:33699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/sss.php"] [unique_id "al9apjzTqJoBC2Mw28_g6QAAAOk"]
[Tue Jul 21 08:40:22.807983 2026] [security2:error] [pid 465652:tid 465869] [client 65.21.113.253:51996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9apjzTqJoBC2Mw28_g2QAAANw"]
[Tue Jul 21 08:40:22.862857 2026] [security2:error] [pid 465652:tid 465784] [client 20.206.105.145:45313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9apjzTqJoBC2Mw28_g7AAAAIc"]
[Tue Jul 21 08:40:22.966795 2026] [security2:error] [pid 465652:tid 465819] [client 152.59.34.51:28869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.34.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9apjzTqJoBC2Mw28_g7QAAAKo"]
[Tue Jul 21 08:40:22.966938 2026] [security2:error] [pid 465652:tid 465819] [client 152.59.34.51:28869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9apjzTqJoBC2Mw28_g7QAAAKo"]
[Tue Jul 21 08:40:22.998686 2026] [security2:error] [pid 465652:tid 465865] [client 20.220.225.223:46949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wp-wpbak.php"] [unique_id "al9apjzTqJoBC2Mw28_g7wAAANg"]
[Tue Jul 21 08:40:23.251881 2026] [security2:error] [pid 465652:tid 465902] [client 20.206.105.145:45328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/adminfuns.php"] [unique_id "al9apzzTqJoBC2Mw28_g-QAAAP0"]
[Tue Jul 21 08:40:23.380600 2026] [security2:error] [pid 465652:tid 465899] [client 195.206.105.227:57548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9apzzTqJoBC2Mw28_g-wAAAPo"]
[Tue Jul 21 08:40:23.380747 2026] [security2:error] [pid 465652:tid 465899] [client 195.206.105.227:57548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9apzzTqJoBC2Mw28_g-wAAAPo"]
[Tue Jul 21 08:40:23.458336 2026] [security2:error] [pid 465652:tid 465891] [client 20.220.225.223:42908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/ms.php"] [unique_id "al9apzzTqJoBC2Mw28_g_AAAAPI"]
[Tue Jul 21 08:40:23.519026 2026] [security2:error] [pid 465652:tid 465828] [client 20.220.225.223:54323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/dr.php"] [unique_id "al9apzzTqJoBC2Mw28_g_gAAALM"]
[Tue Jul 21 08:40:23.564032 2026] [security2:error] [pid 465652:tid 465900] [client 20.206.105.145:46040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/goods.php"] [unique_id "al9apzzTqJoBC2Mw28_g_wAAAPs"]
[Tue Jul 21 08:40:23.590136 2026] [security2:error] [pid 465652:tid 465835] [client 20.206.105.145:46017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/ms-edit.php"] [unique_id "al9apzzTqJoBC2Mw28_hAQAAALo"]
[Tue Jul 21 08:40:23.592180 2026] [security2:error] [pid 465652:tid 465773] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9apzzTqJoBC2Mw28_hAAAA73g"]
[Tue Jul 21 08:40:23.592319 2026] [security2:error] [pid 465652:tid 465888] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9apzzTqJoBC2Mw28_hAAAA73g"]
[Tue Jul 21 08:40:23.635632 2026] [security2:error] [pid 465652:tid 465783] [client 20.206.105.145:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/222.php"] [unique_id "al9apzzTqJoBC2Mw28_hAgAAAIY"]
[Tue Jul 21 08:40:24.024961 2026] [security2:error] [pid 465652:tid 465686] [remote 124.253.201.137:36920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.201.253.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9aqDzTqJoBC2Mw28_hDgAA7SE"]
[Tue Jul 21 08:40:24.189516 2026] [security2:error] [pid 465652:tid 465822] [client 20.220.225.223:47761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/2x.php"] [unique_id "al9aqDzTqJoBC2Mw28_hEAAAAK0"]
[Tue Jul 21 08:40:24.215167 2026] [security2:error] [pid 465652:tid 465859] [client 20.206.105.145:33726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/c.php"] [unique_id "al9aqDzTqJoBC2Mw28_hGAAAANI"]
[Tue Jul 21 08:40:24.377199 2026] [security2:error] [pid 465652:tid 465908] [client 20.206.105.145:45349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9aqDzTqJoBC2Mw28_hIAAAAQM"]
[Tue Jul 21 08:40:24.511070 2026] [security2:error] [pid 465652:tid 465829] [client 20.226.60.151:58511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/zildan.php"] [unique_id "al9aqDzTqJoBC2Mw28_hJgAAALQ"]
[Tue Jul 21 08:40:24.517539 2026] [security2:error] [pid 465652:tid 465853] [client 20.197.192.193:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/jga.php"] [unique_id "al9aqDzTqJoBC2Mw28_hKAAAAMw"]
[Tue Jul 21 08:40:24.562967 2026] [security2:error] [pid 465652:tid 465848] [client 203.25.124.31:30597] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/"] [unique_id "al9aqDzTqJoBC2Mw28_hKQAAAMc"]
[Tue Jul 21 08:40:24.680580 2026] [security2:error] [pid 465652:tid 465878] [client 195.49.128.211:58623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aqDzTqJoBC2Mw28_hKwAAAOU"]
[Tue Jul 21 08:40:24.680734 2026] [security2:error] [pid 465652:tid 465878] [client 195.49.128.211:58623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aqDzTqJoBC2Mw28_hKwAAAOU"]
[Tue Jul 21 08:40:24.756331 2026] [security2:error] [pid 465652:tid 465828] [client 198.44.157.34:60614] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9aqDzTqJoBC2Mw28_hMAAAALM"]
[Tue Jul 21 08:40:24.756453 2026] [security2:error] [pid 465652:tid 465828] [client 198.44.157.34:60614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9aqDzTqJoBC2Mw28_hMAAAALM"]
[Tue Jul 21 08:40:24.840213 2026] [autoindex:error] [pid 465652:tid 465862] [client 20.206.105.145:46067] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:24.856109 2026] [security2:error] [pid 465652:tid 465851] [client 20.206.105.145:46067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9aqDzTqJoBC2Mw28_hNQAAAMo"]
[Tue Jul 21 08:40:24.866111 2026] [security2:error] [pid 465652:tid 465834] [client 49.144.66.253:33321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aqDzTqJoBC2Mw28_hNgAAALk"]
[Tue Jul 21 08:40:24.866200 2026] [security2:error] [pid 465652:tid 465834] [client 49.144.66.253:33321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9aqDzTqJoBC2Mw28_hNgAAALk"]
[Tue Jul 21 08:40:24.882923 2026] [security2:error] [pid 465652:tid 465885] [client 65.21.113.253:51996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9aqDzTqJoBC2Mw28_hIgAAAOw"]
[Tue Jul 21 08:40:24.940199 2026] [security2:error] [pid 465652:tid 465833] [client 20.220.225.223:12598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/track.php"] [unique_id "al9aqDzTqJoBC2Mw28_hOgAAALg"]
[Tue Jul 21 08:40:25.042918 2026] [autoindex:error] [pid 465652:tid 465867] [client 20.206.105.145:45357] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:25.064109 2026] [autoindex:error] [pid 465652:tid 465785] [client 20.206.105.145:45357] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:25.069082 2026] [security2:error] [pid 465652:tid 465854] [client 20.206.105.145:45357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/raw.php"] [unique_id "al9aqTzTqJoBC2Mw28_hPwAAAM0"]
[Tue Jul 21 08:40:25.184355 2026] [security2:error] [pid 465652:tid 465823] [client 20.206.105.145:45361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/abcd.php"] [unique_id "al9aqTzTqJoBC2Mw28_hQgAAAK4"]
[Tue Jul 21 08:40:25.234824 2026] [security2:error] [pid 465652:tid 465826] [client 117.213.202.34:56877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aqTzTqJoBC2Mw28_hQwAAALE"]
[Tue Jul 21 08:40:25.234989 2026] [security2:error] [pid 465652:tid 465826] [client 117.213.202.34:56877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aqTzTqJoBC2Mw28_hQwAAALE"]
[Tue Jul 21 08:40:25.299409 2026] [security2:error] [pid 465652:tid 465877] [client 20.206.105.145:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/a1.php"] [unique_id "al9aqTzTqJoBC2Mw28_hRwAAAOQ"]
[Tue Jul 21 08:40:25.372992 2026] [security2:error] [pid 465652:tid 465789] [client 20.206.105.145:45312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9aqTzTqJoBC2Mw28_hTAAAAIw"]
[Tue Jul 21 08:40:25.449750 2026] [security2:error] [pid 465652:tid 465863] [client 20.206.105.145:45354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9aqTzTqJoBC2Mw28_hUQAAANY"]
[Tue Jul 21 08:40:25.510503 2026] [security2:error] [pid 465652:tid 465828] [client 20.206.105.145:46041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9aqTzTqJoBC2Mw28_hUwAAALM"]
[Tue Jul 21 08:40:25.574793 2026] [security2:error] [pid 465652:tid 465835] [client 203.25.124.39:29197] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/js/widgets/"] [unique_id "al9aqTzTqJoBC2Mw28_hVgAAALo"]
[Tue Jul 21 08:40:25.640430 2026] [security2:error] [pid 465652:tid 465795] [client 20.206.105.145:45374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/simple.php"] [unique_id "al9aqTzTqJoBC2Mw28_hWQAAAJI"]
[Tue Jul 21 08:40:25.740836 2026] [security2:error] [pid 465652:tid 465768] [remote 154.61.75.100:49676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/wp-login.php"] [unique_id "al9aqTzTqJoBC2Mw28_hWgAAp3M"]
[Tue Jul 21 08:40:25.764326 2026] [security2:error] [pid 465652:tid 465782] [client 20.206.105.145:33623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/aa.php"] [unique_id "al9aqTzTqJoBC2Mw28_hWwAAAIU"]
[Tue Jul 21 08:40:25.790913 2026] [security2:error] [pid 465652:tid 465885] [client 20.206.105.145:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/xxx.php"] [unique_id "al9aqTzTqJoBC2Mw28_hXgAAAOw"]
[Tue Jul 21 08:40:25.918391 2026] [security2:error] [pid 465652:tid 465882] [client 20.206.105.145:46036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/hypo.php"] [unique_id "al9aqTzTqJoBC2Mw28_hZwAAAOk"]
[Tue Jul 21 08:40:25.937995 2026] [security2:error] [pid 465652:tid 465770] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aqTzTqJoBC2Mw28_haAAAtnU"]
[Tue Jul 21 08:40:25.938109 2026] [security2:error] [pid 465652:tid 465831] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9aqTzTqJoBC2Mw28_haAAAtnU"]
[Tue Jul 21 08:40:26.032363 2026] [autoindex:error] [pid 465652:tid 465830] [client 20.206.105.145:45340] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:26.066690 2026] [security2:error] [pid 465652:tid 465861] [client 20.206.105.145:45340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/chosen.php"] [unique_id "al9aqjzTqJoBC2Mw28_hbAAAANQ"]
[Tue Jul 21 08:40:26.074032 2026] [security2:error] [pid 465652:tid 465873] [client 20.197.192.193:65201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/x.php"] [unique_id "al9aqjzTqJoBC2Mw28_hbQAAAOA"]
[Tue Jul 21 08:40:26.110282 2026] [autoindex:error] [pid 465652:tid 465838] [client 20.206.105.145:46016] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:26.113135 2026] [security2:error] [pid 465652:tid 465908] [client 85.204.70.102:15640] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rustikusboxingschool.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9aqjzTqJoBC2Mw28_hbwAAAQM"]
[Tue Jul 21 08:40:26.121526 2026] [security2:error] [pid 465652:tid 465876] [client 20.206.105.145:46016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/file5.php"] [unique_id "al9aqjzTqJoBC2Mw28_hcQAAAOM"]
[Tue Jul 21 08:40:26.165568 2026] [security2:error] [pid 465652:tid 465789] [client 20.226.60.151:58608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/csa.php"] [unique_id "al9aqjzTqJoBC2Mw28_hdAAAAIw"]
[Tue Jul 21 08:40:26.197214 2026] [security2:error] [pid 465652:tid 465853] [client 20.206.105.145:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/file.php"] [unique_id "al9aqjzTqJoBC2Mw28_hdQAAAMw"]
[Tue Jul 21 08:40:26.664217 2026] [security2:error] [pid 465652:tid 465897] [client 212.32.76.6:55845] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/222.php"] [unique_id "al9aqjzTqJoBC2Mw28_hggAAAPg"]
[Tue Jul 21 08:40:26.755066 2026] [security2:error] [pid 465652:tid 465782] [client 20.206.105.145:46037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/aa2.php"] [unique_id "al9aqjzTqJoBC2Mw28_hgwAAAIU"]
[Tue Jul 21 08:40:26.895038 2026] [security2:error] [pid 465652:tid 465820] [client 85.204.70.102:58324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rustikusboxingschool.com"] [uri "/xmlrpc.php"] [unique_id "al9aqjzTqJoBC2Mw28_hhwAAAKs"]
[Tue Jul 21 08:40:27.311131 2026] [security2:error] [pid 465652:tid 465876] [client 20.206.105.145:45922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/ccou.php"] [unique_id "al9aqzzTqJoBC2Mw28_hkAAAAOM"]
[Tue Jul 21 08:40:27.326836 2026] [security2:error] [pid 465652:tid 465789] [client 20.206.105.145:33774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/100.php"] [unique_id "al9aqzzTqJoBC2Mw28_hkQAAAIw"]
[Tue Jul 21 08:40:27.494788 2026] [security2:error] [pid 465652:tid 465783] [client 20.220.225.223:46938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/kq1.php"] [unique_id "al9aqzzTqJoBC2Mw28_hnAAAAIY"]
[Tue Jul 21 08:40:27.508981 2026] [security2:error] [pid 465652:tid 465893] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9aqzzTqJoBC2Mw28_hmgAA9EI"]
[Tue Jul 21 08:40:27.609345 2026] [security2:error] [pid 465652:tid 465823] [client 59.95.197.55:59659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aqzzTqJoBC2Mw28_hoAAAAK4"]
[Tue Jul 21 08:40:27.609459 2026] [security2:error] [pid 465652:tid 465823] [client 59.95.197.55:59659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aqzzTqJoBC2Mw28_hoAAAAK4"]
[Tue Jul 21 08:40:27.804606 2026] [security2:error] [pid 465652:tid 465863] [client 168.167.81.163:62139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9aqzzTqJoBC2Mw28_hqAAAANY"]
[Tue Jul 21 08:40:27.804783 2026] [security2:error] [pid 465652:tid 465863] [client 168.167.81.163:62139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9aqzzTqJoBC2Mw28_hqAAAANY"]
[Tue Jul 21 08:40:27.851896 2026] [security2:error] [pid 465652:tid 465761] [remote 104.207.52.93:16773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9aqzzTqJoBC2Mw28_hpAAAl2w"]
[Tue Jul 21 08:40:27.863825 2026] [security2:error] [pid 465652:tid 465883] [client 203.25.124.33:59209] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/aaa.php"] [unique_id "al9aqzzTqJoBC2Mw28_hqgAAAOo"]
[Tue Jul 21 08:40:27.981608 2026] [security2:error] [pid 465652:tid 465854] [client 20.206.105.145:33605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/footer.php"] [unique_id "al9aqzzTqJoBC2Mw28_hrgAAAM0"]
[Tue Jul 21 08:40:27.994980 2026] [security2:error] [pid 465652:tid 465886] [client 20.206.105.145:45995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/dr.php"] [unique_id "al9aqzzTqJoBC2Mw28_hsgAAAO0"]
[Tue Jul 21 08:40:28.058947 2026] [proxy:error] [pid 465652:tid 465865] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:28.059011 2026] [proxy_http:error] [pid 465652:tid 465865] [client 143.244.57.92:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:28.059592 2026] [proxy:error] [pid 465652:tid 465865] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:28.059622 2026] [proxy_http:error] [pid 465652:tid 465865] [client 143.244.57.92:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:28.349742 2026] [proxy:error] [pid 465652:tid 465878] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:28.349867 2026] [proxy_http:error] [pid 465652:tid 465878] [client 143.244.57.92:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:28.352242 2026] [proxy:error] [pid 465652:tid 465878] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:28.352323 2026] [proxy_http:error] [pid 465652:tid 465878] [client 143.244.57.92:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:28.637559 2026] [security2:error] [pid 465652:tid 465834] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9arDzTqJoBC2Mw28_h0gAAALk"]
[Tue Jul 21 08:40:28.673122 2026] [security2:error] [pid 465652:tid 465899] [client 20.206.105.145:45973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/file31.php"] [unique_id "al9arDzTqJoBC2Mw28_h1AAAAPo"]
[Tue Jul 21 08:40:28.723761 2026] [security2:error] [pid 465652:tid 465869] [client 20.197.192.193:65195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9arDzTqJoBC2Mw28_h1gAAANw"]
[Tue Jul 21 08:40:28.827870 2026] [security2:error] [pid 465652:tid 465787] [client 122.176.100.127:60165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9arDzTqJoBC2Mw28_h2AAAAIo"]
[Tue Jul 21 08:40:28.827991 2026] [security2:error] [pid 465652:tid 465787] [client 122.176.100.127:60165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9arDzTqJoBC2Mw28_h2AAAAIo"]
[Tue Jul 21 08:40:28.928995 2026] [security2:error] [pid 465652:tid 465867] [client 143.244.57.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9arDzTqJoBC2Mw28_h2QAAANo"]
[Tue Jul 21 08:40:28.964268 2026] [security2:error] [pid 465652:tid 465833] [client 212.32.76.2:64033] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "al9arDzTqJoBC2Mw28_h2wAAALg"]
[Tue Jul 21 08:40:29.067528 2026] [security2:error] [pid 465652:tid 465893] [client 5.38.115.39:27920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9arTzTqJoBC2Mw28_h5AAAAPQ"]
[Tue Jul 21 08:40:29.067643 2026] [security2:error] [pid 465652:tid 465893] [client 5.38.115.39:27920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9arTzTqJoBC2Mw28_h5AAAAPQ"]
[Tue Jul 21 08:40:29.197855 2026] [security2:error] [pid 465652:tid 465905] [client 85.204.70.102:58328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rustikusboxingschool.com"] [uri "/xmlrpc.php"] [unique_id "al9arTzTqJoBC2Mw28_h5gAAAQA"]
[Tue Jul 21 08:40:29.197976 2026] [security2:error] [pid 465652:tid 465905] [client 85.204.70.102:58328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rustikusboxingschool.com"] [uri "/xmlrpc.php"] [unique_id "al9arTzTqJoBC2Mw28_h5gAAAQA"]
[Tue Jul 21 08:40:29.214351 2026] [proxy:error] [pid 465652:tid 465795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:29.214405 2026] [proxy_http:error] [pid 465652:tid 465795] [client 143.244.57.92:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:29.215025 2026] [proxy:error] [pid 465652:tid 465795] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:29.215058 2026] [proxy_http:error] [pid 465652:tid 465795] [client 143.244.57.92:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:29.432295 2026] [security2:error] [pid 465652:tid 465838] [client 20.206.105.145:45325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/file6.php"] [unique_id "al9arTzTqJoBC2Mw28_h6AAAAL0"]
[Tue Jul 21 08:40:29.503432 2026] [security2:error] [pid 465652:tid 465879] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9arTzTqJoBC2Mw28_h7AAAAOY"]
[Tue Jul 21 08:40:29.531404 2026] [security2:error] [pid 465652:tid 465816] [client 74.249.245.134:42706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/0x.php"] [unique_id "al9arTzTqJoBC2Mw28_h7QAAAKc"]
[Tue Jul 21 08:40:29.629233 2026] [security2:error] [pid 465652:tid 465846] [client 20.220.225.223:54330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/zzz.php"] [unique_id "al9arTzTqJoBC2Mw28_h9QAAAMU"]
[Tue Jul 21 08:40:29.636651 2026] [security2:error] [pid 465652:tid 465899] [client 20.206.105.145:33668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/users.php"] [unique_id "al9arTzTqJoBC2Mw28_h9gAAAPo"]
[Tue Jul 21 08:40:29.667756 2026] [security2:error] [pid 465652:tid 465800] [client 203.25.124.43:33003] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/inputs.php"] [unique_id "al9arTzTqJoBC2Mw28_h9wAAAJc"]
[Tue Jul 21 08:40:29.789068 2026] [security2:error] [pid 465652:tid 465831] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9arTzTqJoBC2Mw28_iAAAAALY"]
[Tue Jul 21 08:40:29.911099 2026] [security2:error] [pid 465652:tid 465850] [client 20.206.105.145:45351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/file15.php"] [unique_id "al9arTzTqJoBC2Mw28_iAgAAAMk"]
[Tue Jul 21 08:40:30.077325 2026] [security2:error] [pid 465652:tid 465876] [client 20.206.105.145:45365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/jp.php"] [unique_id "al9arjzTqJoBC2Mw28_iCAAAAOM"]
[Tue Jul 21 08:40:30.130428 2026] [security2:error] [pid 465652:tid 465814] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9arjzTqJoBC2Mw28_iCwAAAKU"]
[Tue Jul 21 08:40:30.213922 2026] [security2:error] [pid 465652:tid 465896] [client 20.206.105.145:45347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/f35.php"] [unique_id "al9arjzTqJoBC2Mw28_iDgAAAPc"]
[Tue Jul 21 08:40:30.215731 2026] [security2:error] [pid 465652:tid 465885] [client 202.179.75.202:55058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9arjzTqJoBC2Mw28_iDwAAAOw"]
[Tue Jul 21 08:40:30.215807 2026] [security2:error] [pid 465652:tid 465885] [client 202.179.75.202:55058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9arjzTqJoBC2Mw28_iDwAAAOw"]
[Tue Jul 21 08:40:30.259875 2026] [security2:error] [pid 465652:tid 465851] [client 223.181.60.88:9094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9arjzTqJoBC2Mw28_iEAAAAMo"]
[Tue Jul 21 08:40:30.260088 2026] [security2:error] [pid 465652:tid 465851] [client 223.181.60.88:9094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9arjzTqJoBC2Mw28_iEAAAAMo"]
[Tue Jul 21 08:40:30.345200 2026] [security2:error] [pid 465652:tid 465804] [client 20.206.105.145:46027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wp-load.php"] [unique_id "al9arjzTqJoBC2Mw28_iEQAAAJs"]
[Tue Jul 21 08:40:30.417724 2026] [security2:error] [pid 465652:tid 465864] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9arjzTqJoBC2Mw28_iFQAAANc"]
[Tue Jul 21 08:40:30.490682 2026] [security2:error] [pid 465652:tid 465845] [client 20.220.225.223:54328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wicked.php"] [unique_id "al9arjzTqJoBC2Mw28_iFwAAAMQ"]
[Tue Jul 21 08:40:30.541180 2026] [autoindex:error] [pid 465652:tid 465803] [client 20.206.105.145:46076] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:30.546233 2026] [security2:error] [pid 465652:tid 465852] [client 185.213.175.37:20720] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "benti.com.br"] [uri "/wp-content/uploads/2024/08/cropped-Logo-Benti-Quadrado_20240822_073007_0000-2-192x192.png"] [unique_id "al9arjzTqJoBC2Mw28_iHgAAAMs"]
[Tue Jul 21 08:40:30.599524 2026] [autoindex:error] [pid 465652:tid 465908] [client 20.206.105.145:46076] AH01276: Cannot serve directory /home1/ericks84/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:30.623515 2026] [security2:error] [pid 465652:tid 465806] [client 20.206.105.145:46076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wp-admin/css/colors/midnight/about.php"] [unique_id "al9arjzTqJoBC2Mw28_iJgAAAJ0"]
[Tue Jul 21 08:40:30.703803 2026] [security2:error] [pid 465652:tid 465863] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9arjzTqJoBC2Mw28_iKQAAANY"]
[Tue Jul 21 08:40:30.714148 2026] [security2:error] [pid 465652:tid 465801] [client 185.213.175.37:20758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "benti.com.br"] [uri "/xmlrpc.php"] [unique_id "al9arjzTqJoBC2Mw28_iKgAAAJg"]
[Tue Jul 21 08:40:30.714324 2026] [security2:error] [pid 465652:tid 465801] [client 185.213.175.37:20758] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "benti.com.br"] [uri "/xmlrpc.php"] [unique_id "al9arjzTqJoBC2Mw28_iKgAAAJg"]
[Tue Jul 21 08:40:30.720004 2026] [security2:error] [pid 465652:tid 465824] [client 185.213.175.37:20760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "benti.com.br"] [uri "/wp-content/uploads/2021/05/BENTI-RETANGULAR-BRANCO.png"] [unique_id "al9arjzTqJoBC2Mw28_iKwAAAK8"]
[Tue Jul 21 08:40:30.720092 2026] [security2:error] [pid 465652:tid 465824] [client 185.213.175.37:20760] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "benti.com.br"] [uri "/wp-content/uploads/2021/05/BENTI-RETANGULAR-BRANCO.png"] [unique_id "al9arjzTqJoBC2Mw28_iKwAAAK8"]
[Tue Jul 21 08:40:30.735504 2026] [security2:error] [pid 465652:tid 465846] [client 185.213.175.37:20798] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "benti.com.br"] [uri "/wp-includes/css/dist/preferences/style.min.css"] [unique_id "al9arjzTqJoBC2Mw28_iLgAAAMU"]
[Tue Jul 21 08:40:30.751453 2026] [security2:error] [pid 465652:tid 465883] [client 185.213.175.37:20846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "benti.com.br"] [uri "/wp-content/uploads/2024/08/cropped-Logo-Benti-Quadrado_20240822_073007_0000-2-32x32.png"] [unique_id "al9arjzTqJoBC2Mw28_iMAAAAOo"]
[Tue Jul 21 08:40:30.751527 2026] [security2:error] [pid 465652:tid 465883] [client 185.213.175.37:20846] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "benti.com.br"] [uri "/wp-content/uploads/2024/08/cropped-Logo-Benti-Quadrado_20240822_073007_0000-2-32x32.png"] [unique_id "al9arjzTqJoBC2Mw28_iMAAAAOo"]
[Tue Jul 21 08:40:30.776854 2026] [security2:error] [pid 465652:tid 465899] [client 185.213.175.37:20832] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "benti.com.br"] [uri "/wp-json/wp/v2/posts/1"] [unique_id "al9arjzTqJoBC2Mw28_iNgAAAPo"]
[Tue Jul 21 08:40:30.990205 2026] [security2:error] [pid 465652:tid 465804] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9arjzTqJoBC2Mw28_iOwAAAJs"]
[Tue Jul 21 08:40:31.030063 2026] [security2:error] [pid 465652:tid 465809] [client 20.220.225.223:12591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/2352356666.php"] [unique_id "al9arzzTqJoBC2Mw28_iPAAAAKA"]
[Tue Jul 21 08:40:31.280419 2026] [security2:error] [pid 465652:tid 465867] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9arzzTqJoBC2Mw28_iSwAAANo"]
[Tue Jul 21 08:40:31.332757 2026] [security2:error] [pid 465652:tid 465800] [client 85.208.96.195:25234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivaconcierge.com.br"] [uri "/imoveis/asg-0101/"] [unique_id "al9arzzTqJoBC2Mw28_iUgAAAJc"]
[Tue Jul 21 08:40:31.332965 2026] [security2:error] [pid 465652:tid 465800] [client 85.208.96.195:25234] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vivaconcierge.com.br"] [uri "/imoveis/asg-0101/"] [unique_id "al9arzzTqJoBC2Mw28_iUgAAAJc"]
[Tue Jul 21 08:40:31.416289 2026] [security2:error] [pid 465652:tid 465886] [client 20.206.105.145:45323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wp-links.php"] [unique_id "al9arzzTqJoBC2Mw28_iVAAAAO0"]
[Tue Jul 21 08:40:31.421116 2026] [security2:error] [pid 465652:tid 465843] [client 20.197.192.193:65174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/ee.php"] [unique_id "al9arzzTqJoBC2Mw28_iVQAAAMI"]
[Tue Jul 21 08:40:31.462808 2026] [security2:error] [pid 465652:tid 465863] [client 203.25.124.32:46107] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/about.php"] [unique_id "al9arzzTqJoBC2Mw28_iVgAAANY"]
[Tue Jul 21 08:40:31.564292 2026] [security2:error] [pid 465652:tid 465784] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9arzzTqJoBC2Mw28_iXAAAAIc"]
[Tue Jul 21 08:40:31.634249 2026] [security2:error] [pid 465652:tid 465824] [client 74.7.175.147:35752] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.advogadogustavocheregati.com.br"] [uri "/robots.txt"] [unique_id "al9arzzTqJoBC2Mw28_iXgAAAK8"]
[Tue Jul 21 08:40:31.852833 2026] [security2:error] [pid 465652:tid 465900] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9arzzTqJoBC2Mw28_iZgAAAPs"]
[Tue Jul 21 08:40:31.854658 2026] [security2:error] [pid 465652:tid 465853] [client 173.252.95.40:44488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9arzzTqJoBC2Mw28_iZQAAAMw"]
[Tue Jul 21 08:40:31.952785 2026] [security2:error] [pid 465652:tid 465883] [client 14.245.224.124:62353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9arzzTqJoBC2Mw28_iaAAAAOo"]
[Tue Jul 21 08:40:31.953294 2026] [security2:error] [pid 465652:tid 465883] [client 14.245.224.124:62353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9arzzTqJoBC2Mw28_iaAAAAOo"]
[Tue Jul 21 08:40:32.108397 2026] [security2:error] [pid 465652:tid 465899] [client 195.49.128.211:51414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9asDzTqJoBC2Mw28_icQAAAPo"]
[Tue Jul 21 08:40:32.108528 2026] [security2:error] [pid 465652:tid 465899] [client 195.49.128.211:51414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9asDzTqJoBC2Mw28_icQAAAPo"]
[Tue Jul 21 08:40:32.137762 2026] [security2:error] [pid 465652:tid 465893] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9asDzTqJoBC2Mw28_icwAAAPQ"]
[Tue Jul 21 08:40:32.251931 2026] [security2:error] [pid 465652:tid 465820] [client 74.249.245.134:51493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/buy.php"] [unique_id "al9asDzTqJoBC2Mw28_iegAAAKs"]
[Tue Jul 21 08:40:32.257614 2026] [security2:error] [pid 465652:tid 465830] [client 65.21.113.253:55342] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9arzzTqJoBC2Mw28_iYwAAALU"]
[Tue Jul 21 08:40:32.370429 2026] [security2:error] [pid 465652:tid 465897] [client 203.25.124.41:55157] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/speculative8.php"] [unique_id "al9asDzTqJoBC2Mw28_ifQAAAPg"]
[Tue Jul 21 08:40:32.422547 2026] [security2:error] [pid 465652:tid 465814] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9asDzTqJoBC2Mw28_ifwAAAKU"]
[Tue Jul 21 08:40:32.534546 2026] [security2:error] [pid 465652:tid 465786] [client 173.252.95.5:47864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9asDzTqJoBC2Mw28_ifgAAAIk"]
[Tue Jul 21 08:40:32.534972 2026] [security2:error] [pid 465652:tid 465869] [client 103.59.206.240:37091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9asDzTqJoBC2Mw28_iggAAANw"]
[Tue Jul 21 08:40:32.535156 2026] [security2:error] [pid 465652:tid 465869] [client 103.59.206.240:37091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9asDzTqJoBC2Mw28_iggAAANw"]
[Tue Jul 21 08:40:32.690041 2026] [security2:error] [pid 465652:tid 465784] [client 20.206.105.145:46030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/solo1.php"] [unique_id "al9asDzTqJoBC2Mw28_ihwAAAIc"]
[Tue Jul 21 08:40:32.708097 2026] [security2:error] [pid 465652:tid 465882] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9asDzTqJoBC2Mw28_iiAAAAOk"]
[Tue Jul 21 08:40:32.728939 2026] [security2:error] [pid 465652:tid 465859] [client 20.226.60.151:58593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/w3llscc.php"] [unique_id "al9asDzTqJoBC2Mw28_iiQAAANI"]
[Tue Jul 21 08:40:32.995177 2026] [security2:error] [pid 465652:tid 465851] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9asDzTqJoBC2Mw28_ilAAAAMo"]
[Tue Jul 21 08:40:33.261331 2026] [security2:error] [pid 465652:tid 465852] [client 212.32.76.13:64085] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/radio.php"] [unique_id "al9asTzTqJoBC2Mw28_inAAAAMs"]
[Tue Jul 21 08:40:33.284437 2026] [security2:error] [pid 465652:tid 465890] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9asTzTqJoBC2Mw28_inQAAAPE"]
[Tue Jul 21 08:40:33.344389 2026] [security2:error] [pid 465652:tid 465908] [client 152.59.181.104:61248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9asTzTqJoBC2Mw28_iogAAAQM"]
[Tue Jul 21 08:40:33.344603 2026] [security2:error] [pid 465652:tid 465908] [client 152.59.181.104:61248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9asTzTqJoBC2Mw28_iogAAAQM"]
[Tue Jul 21 08:40:33.420518 2026] [security2:error] [pid 465652:tid 465811] [client 20.197.192.193:65213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/blue.php"] [unique_id "al9asTzTqJoBC2Mw28_ipAAAAKI"]
[Tue Jul 21 08:40:33.501645 2026] [security2:error] [pid 465652:tid 465821] [client 20.206.105.145:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/sixxis.php"] [unique_id "al9asTzTqJoBC2Mw28_iqAAAAKw"]
[Tue Jul 21 08:40:33.567693 2026] [security2:error] [pid 465652:tid 465872] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9asTzTqJoBC2Mw28_iqgAAAN8"]
[Tue Jul 21 08:40:33.856063 2026] [security2:error] [pid 465652:tid 465864] [client 143.244.57.92:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danieldevasconcelosg1782925925327.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9asTzTqJoBC2Mw28_itAAAANc"]
[Tue Jul 21 08:40:33.885774 2026] [security2:error] [pid 465652:tid 465817] [client 20.206.105.145:33716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/177.php"] [unique_id "al9asTzTqJoBC2Mw28_itQAAAKg"]
[Tue Jul 21 08:40:33.893269 2026] [security2:error] [pid 465652:tid 465858] [client 20.226.60.151:58576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wpx.php"] [unique_id "al9asTzTqJoBC2Mw28_itgAAANE"]
[Tue Jul 21 08:40:34.061423 2026] [security2:error] [pid 465652:tid 465902] [client 74.249.245.134:42747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/sx.php"] [unique_id "al9asjzTqJoBC2Mw28_iugAAAP0"]
[Tue Jul 21 08:40:34.123101 2026] [security2:error] [pid 465652:tid 465709] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9asjzTqJoBC2Mw28_iuwAA0jg"]
[Tue Jul 21 08:40:34.123230 2026] [security2:error] [pid 465652:tid 465859] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9asjzTqJoBC2Mw28_iuwAA0jg"]
[Tue Jul 21 08:40:34.139387 2026] [security2:error] [pid 465652:tid 465685] [remote 34.182.152.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.152.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.amandamorau.adv.br"] [uri "/xmlrpc.php"] [unique_id "al9asjzTqJoBC2Mw28_ivQAA4yA"]
[Tue Jul 21 08:40:34.149685 2026] [security2:error] [pid 465652:tid 465906] [client 20.220.225.223:2398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/edit.php"] [unique_id "al9asjzTqJoBC2Mw28_iwAAAAQE"]
[Tue Jul 21 08:40:34.261135 2026] [security2:error] [pid 465652:tid 465801] [client 203.25.124.215:63873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/js/"] [unique_id "al9asjzTqJoBC2Mw28_iwwAAAJg"]
[Tue Jul 21 08:40:34.330390 2026] [security2:error] [pid 465652:tid 465710] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.amandamorau.adv.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9asjzTqJoBC2Mw28_iyAAAszk"]
[Tue Jul 21 08:40:34.355661 2026] [security2:error] [pid 465652:tid 465899] [client 20.206.105.145:46071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/2P.update.php"] [unique_id "al9asjzTqJoBC2Mw28_izAAAAPo"]
[Tue Jul 21 08:40:34.530228 2026] [security2:error] [pid 465652:tid 465761] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.amandamorau.adv.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9asjzTqJoBC2Mw28_i1QAAsGw"]
[Tue Jul 21 08:40:34.651208 2026] [security2:error] [pid 465652:tid 465831] [client 20.63.100.92:6206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/billur.php"] [unique_id "al9asjzTqJoBC2Mw28_i2AAAALY"]
[Tue Jul 21 08:40:34.681442 2026] [security2:error] [pid 465652:tid 465720] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.amandamorau.adv.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9asjzTqJoBC2Mw28_i2wABA0M"]
[Tue Jul 21 08:40:34.720832 2026] [security2:error] [pid 465652:tid 465900] [client 65.21.113.253:55342] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9asjzTqJoBC2Mw28_iwgAAAPs"]
[Tue Jul 21 08:40:34.754716 2026] [security2:error] [pid 465652:tid 465775] [remote 64.225.121.94:56798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "murilomattos.com"] [uri "/wp-login.php"] [unique_id "al9asjzTqJoBC2Mw28_i3QAA_no"]
[Tue Jul 21 08:40:34.789026 2026] [security2:error] [pid 465652:tid 465810] [client 20.206.105.145:46075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/a.php"] [unique_id "al9asjzTqJoBC2Mw28_i4AAAAKE"]
[Tue Jul 21 08:40:34.885130 2026] [security2:error] [pid 465652:tid 465669] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.amandamorau.adv.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9asjzTqJoBC2Mw28_i5gAAzRA"]
[Tue Jul 21 08:40:35.033889 2026] [security2:error] [pid 465652:tid 465901] [client 20.206.105.145:46029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/k.php"] [unique_id "al9aszzTqJoBC2Mw28_i6QAAAPw"]
[Tue Jul 21 08:40:35.045693 2026] [security2:error] [pid 465652:tid 465787] [client 20.220.225.223:2401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/kua.php"] [unique_id "al9aszzTqJoBC2Mw28_i6gAAAIo"]
[Tue Jul 21 08:40:35.108436 2026] [security2:error] [pid 465652:tid 465689] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.amandamorau.adv.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9aszzTqJoBC2Mw28_i6wAA5iQ"]
[Tue Jul 21 08:40:35.164242 2026] [security2:error] [pid 465652:tid 465850] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9aszzTqJoBC2Mw28_i7QAAAMk"]
[Tue Jul 21 08:40:35.293124 2026] [security2:error] [pid 465652:tid 465820] [client 195.49.128.211:59232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aszzTqJoBC2Mw28_i8gAAAKs"]
[Tue Jul 21 08:40:35.293279 2026] [security2:error] [pid 465652:tid 465820] [client 195.49.128.211:59232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9aszzTqJoBC2Mw28_i8gAAAKs"]
[Tue Jul 21 08:40:35.305880 2026] [security2:error] [pid 465652:tid 465723] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.amandamorau.adv.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9aszzTqJoBC2Mw28_i8wAAkUY"]
[Tue Jul 21 08:40:35.355919 2026] [security2:error] [pid 465652:tid 465876] [client 20.206.105.145:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/w.php"] [unique_id "al9aszzTqJoBC2Mw28_i9QAAAOM"]
[Tue Jul 21 08:40:35.441137 2026] [security2:error] [pid 465652:tid 465760] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.amandamorau.adv.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9aszzTqJoBC2Mw28_i-gAAmGs"]
[Tue Jul 21 08:40:35.451372 2026] [security2:error] [pid 465652:tid 465851] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aszzTqJoBC2Mw28_i-wAAAMo"]
[Tue Jul 21 08:40:35.466530 2026] [security2:error] [pid 465652:tid 465865] [client 203.25.124.74:53879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/updates.php"] [unique_id "al9aszzTqJoBC2Mw28_i_AAAANg"]
[Tue Jul 21 08:40:35.490463 2026] [security2:error] [pid 465652:tid 465804] [client 20.206.105.145:46069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/insc.php"] [unique_id "al9aszzTqJoBC2Mw28_i_gAAAJs"]
[Tue Jul 21 08:40:35.588202 2026] [security2:error] [pid 465652:tid 465780] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.amandamorau.adv.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9aszzTqJoBC2Mw28_i_wAAy38"]
[Tue Jul 21 08:40:35.600113 2026] [security2:error] [pid 465652:tid 465883] [client 74.249.245.134:42740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/article.php"] [unique_id "al9aszzTqJoBC2Mw28_jAAAAAOo"]
[Tue Jul 21 08:40:35.835417 2026] [security2:error] [pid 465652:tid 465808] [client 20.206.105.145:45370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9aszzTqJoBC2Mw28_jBwAAAJ8"]
[Tue Jul 21 08:40:35.845865 2026] [security2:error] [pid 465652:tid 465715] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.amandamorau.adv.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9aszzTqJoBC2Mw28_jCAAA9T4"]
[Tue Jul 21 08:40:35.907450 2026] [security2:error] [pid 465652:tid 465742] [remote 119.195.102.159:60540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9aszzTqJoBC2Mw28_jDAABAlk"]
[Tue Jul 21 08:40:35.921749 2026] [security2:error] [pid 465652:tid 465869] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9aszzTqJoBC2Mw28_jEAAAANw"]
[Tue Jul 21 08:40:35.968519 2026] [security2:error] [pid 465652:tid 465824] [client 117.213.202.34:57490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aszzTqJoBC2Mw28_jEgAAAK8"]
[Tue Jul 21 08:40:35.968858 2026] [security2:error] [pid 465652:tid 465824] [client 117.213.202.34:57490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9aszzTqJoBC2Mw28_jEgAAAK8"]
[Tue Jul 21 08:40:35.983281 2026] [security2:error] [pid 465652:tid 465678] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.amandamorau.adv.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9aszzTqJoBC2Mw28_jEwAA_Bk"]
[Tue Jul 21 08:40:36.049426 2026] [security2:error] [pid 465652:tid 465858] [client 20.220.225.223:43281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/ez.php"] [unique_id "al9atDzTqJoBC2Mw28_jFQAAANE"]
[Tue Jul 21 08:40:36.097054 2026] [security2:error] [pid 465652:tid 465895] [client 20.206.105.145:46035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/u.php"] [unique_id "al9atDzTqJoBC2Mw28_jFgAAAPY"]
[Tue Jul 21 08:40:36.115916 2026] [security2:error] [pid 465652:tid 465759] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.amandamorau.adv.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9atDzTqJoBC2Mw28_jGAAAkWo"]
[Tue Jul 21 08:40:36.206398 2026] [security2:error] [pid 465652:tid 465789] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9atDzTqJoBC2Mw28_jGQAAAIw"]
[Tue Jul 21 08:40:36.264949 2026] [security2:error] [pid 465652:tid 465741] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.amandamorau.adv.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9atDzTqJoBC2Mw28_jHQAAzFg"]
[Tue Jul 21 08:40:36.300615 2026] [security2:error] [pid 465652:tid 465739] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9atDzTqJoBC2Mw28_jIQAAs1Y"]
[Tue Jul 21 08:40:36.300780 2026] [security2:error] [pid 465652:tid 465828] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9atDzTqJoBC2Mw28_jIQAAs1Y"]
[Tue Jul 21 08:40:36.308664 2026] [security2:error] [pid 465652:tid 465803] [client 142.44.225.244:64760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "fontedodireito.com"] [uri "/robots.txt"] [unique_id "al9atDzTqJoBC2Mw28_jIgAAAJo"]
[Tue Jul 21 08:40:36.308834 2026] [security2:error] [pid 465652:tid 465803] [client 142.44.225.244:64760] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fontedodireito.com"] [uri "/robots.txt"] [unique_id "al9atDzTqJoBC2Mw28_jIgAAAJo"]
[Tue Jul 21 08:40:36.371789 2026] [security2:error] [pid 465652:tid 465852] [client 212.32.76.10:35915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/colors/blue/"] [unique_id "al9atDzTqJoBC2Mw28_jIwAAAMs"]
[Tue Jul 21 08:40:36.441212 2026] [security2:error] [pid 465652:tid 465844] [client 49.144.66.253:33768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9atDzTqJoBC2Mw28_jJgAAAMM"]
[Tue Jul 21 08:40:36.441321 2026] [security2:error] [pid 465652:tid 465844] [client 49.144.66.253:33768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9atDzTqJoBC2Mw28_jJgAAAMM"]
[Tue Jul 21 08:40:36.491702 2026] [security2:error] [pid 465652:tid 465788] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9atDzTqJoBC2Mw28_jKgAAAIs"]
[Tue Jul 21 08:40:36.775009 2026] [security2:error] [pid 465652:tid 465894] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9atDzTqJoBC2Mw28_jMQAAAPU"]
[Tue Jul 21 08:40:36.826424 2026] [security2:error] [pid 465652:tid 465814] [client 20.206.105.145:46056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/sss.php"] [unique_id "al9atDzTqJoBC2Mw28_jMwAAAKU"]
[Tue Jul 21 08:40:37.027067 2026] [security2:error] [pid 465652:tid 465861] [client 20.206.105.145:33776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/config.php"] [unique_id "al9atTzTqJoBC2Mw28_jOgAAANQ"]
[Tue Jul 21 08:40:37.036757 2026] [security2:error] [pid 465652:tid 465888] [client 20.206.105.145:46066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/sss.php"] [unique_id "al9atTzTqJoBC2Mw28_jOwAAAO8"]
[Tue Jul 21 08:40:37.059360 2026] [security2:error] [pid 465652:tid 465892] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9atTzTqJoBC2Mw28_jPAAAAPM"]
[Tue Jul 21 08:40:37.086739 2026] [security2:error] [pid 465652:tid 465737] [remote 173.239.240.72:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9atTzTqJoBC2Mw28_jPQAAh1Q"]
[Tue Jul 21 08:40:37.139674 2026] [security2:error] [pid 465652:tid 465789] [client 20.206.105.145:46060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/c.php"] [unique_id "al9atTzTqJoBC2Mw28_jPgAAAIw"]
[Tue Jul 21 08:40:37.227346 2026] [security2:error] [pid 465652:tid 465865] [client 20.206.105.145:45368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/aa.php"] [unique_id "al9atTzTqJoBC2Mw28_jPwAAANg"]
[Tue Jul 21 08:40:37.313132 2026] [security2:error] [pid 465652:tid 465855] [client 20.206.105.145:45907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/100.php"] [unique_id "al9atTzTqJoBC2Mw28_jRAAAAM4"]
[Tue Jul 21 08:40:37.344851 2026] [security2:error] [pid 465652:tid 465893] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9atTzTqJoBC2Mw28_jSQAAAPQ"]
[Tue Jul 21 08:40:37.390038 2026] [security2:error] [pid 465652:tid 465818] [client 20.206.105.145:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/footer.php"] [unique_id "al9atTzTqJoBC2Mw28_jSgAAAKk"]
[Tue Jul 21 08:40:37.560205 2026] [security2:error] [pid 465652:tid 465833] [client 198.44.157.34:55638] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9atTzTqJoBC2Mw28_jSwAAALg"]
[Tue Jul 21 08:40:37.560329 2026] [security2:error] [pid 465652:tid 465833] [client 198.44.157.34:55638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9atTzTqJoBC2Mw28_jSwAAALg"]
[Tue Jul 21 08:40:37.629448 2026] [security2:error] [pid 465652:tid 465891] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9atTzTqJoBC2Mw28_jUAAAAPI"]
[Tue Jul 21 08:40:37.755377 2026] [security2:error] [pid 465652:tid 465811] [client 51.75.236.143:52076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "fontedodireito.com"] [uri "/"] [unique_id "al9atTzTqJoBC2Mw28_jVgAAAKI"]
[Tue Jul 21 08:40:37.755510 2026] [security2:error] [pid 465652:tid 465811] [client 51.75.236.143:52076] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fontedodireito.com"] [uri "/"] [unique_id "al9atTzTqJoBC2Mw28_jVgAAAKI"]
[Tue Jul 21 08:40:37.786287 2026] [security2:error] [pid 465652:tid 465887] [client 20.220.225.223:12595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/pn.php"] [unique_id "al9atTzTqJoBC2Mw28_jVwAAAO4"]
[Tue Jul 21 08:40:37.847645 2026] [security2:error] [pid 465652:tid 465867] [client 20.206.105.145:46064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/users.php"] [unique_id "al9atTzTqJoBC2Mw28_jWAAAANo"]
[Tue Jul 21 08:40:37.879750 2026] [security2:error] [pid 465652:tid 465872] [client 20.226.60.151:58536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-css.php"] [unique_id "al9atTzTqJoBC2Mw28_jXAAAAN8"]
[Tue Jul 21 08:40:37.913696 2026] [security2:error] [pid 465652:tid 465805] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9atTzTqJoBC2Mw28_jXgAAAJw"]
[Tue Jul 21 08:40:37.992616 2026] [security2:error] [pid 465652:tid 465863] [client 20.206.105.145:45329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/177.php"] [unique_id "al9atTzTqJoBC2Mw28_jYQAAANY"]
[Tue Jul 21 08:40:38.075331 2026] [security2:error] [pid 465652:tid 465858] [client 20.206.105.145:45908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/config.php"] [unique_id "al9atjzTqJoBC2Mw28_jZwAAANE"]
[Tue Jul 21 08:40:38.075638 2026] [security2:error] [pid 465652:tid 465901] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9atjzTqJoBC2Mw28_jZAAA_CU"]
[Tue Jul 21 08:40:38.109085 2026] [security2:error] [pid 465652:tid 465844] [client 59.95.197.55:60104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9atjzTqJoBC2Mw28_jaAAAAMM"]
[Tue Jul 21 08:40:38.109759 2026] [security2:error] [pid 465652:tid 465844] [client 59.95.197.55:60104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9atjzTqJoBC2Mw28_jaAAAAMM"]
[Tue Jul 21 08:40:38.161352 2026] [security2:error] [pid 465652:tid 465864] [client 203.25.124.73:49389] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/theme-compat/"] [unique_id "al9atjzTqJoBC2Mw28_jaQAAANc"]
[Tue Jul 21 08:40:38.204038 2026] [security2:error] [pid 465652:tid 465888] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9atjzTqJoBC2Mw28_jagAAAO8"]
[Tue Jul 21 08:40:38.205462 2026] [security2:error] [pid 465652:tid 465807] [client 20.206.105.145:46015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/gettest.php"] [unique_id "al9atjzTqJoBC2Mw28_jawAAAJ4"]
[Tue Jul 21 08:40:38.205885 2026] [security2:error] [pid 465652:tid 465873] [client 20.220.225.223:56201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/fz.php"] [unique_id "al9atjzTqJoBC2Mw28_jbAAAAOA"]
[Tue Jul 21 08:40:38.371426 2026] [security2:error] [pid 465652:tid 465786] [client 65.21.113.253:55342] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9atTzTqJoBC2Mw28_jXQAAAIk"]
[Tue Jul 21 08:40:38.491842 2026] [security2:error] [pid 465652:tid 465851] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9atjzTqJoBC2Mw28_jcQAAAMo"]
[Tue Jul 21 08:40:38.555208 2026] [security2:error] [pid 465652:tid 465874] [client 74.249.245.134:20548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/bootstrap.php"] [unique_id "al9atjzTqJoBC2Mw28_jdgAAAOE"]
[Tue Jul 21 08:40:38.618464 2026] [security2:error] [pid 465652:tid 465814] [client 5.31.193.106:58583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9atjzTqJoBC2Mw28_jeQAAAKU"]
[Tue Jul 21 08:40:38.622709 2026] [security2:error] [pid 465652:tid 465814] [client 5.31.193.106:58583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9atjzTqJoBC2Mw28_jeQAAAKU"]
[Tue Jul 21 08:40:38.706780 2026] [security2:error] [pid 465652:tid 465880] [client 20.63.100.92:2715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/mimpi.php"] [unique_id "al9atjzTqJoBC2Mw28_jfQAAAOc"]
[Tue Jul 21 08:40:38.721015 2026] [security2:error] [pid 465652:tid 465883] [client 195.206.105.227:51588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9atjzTqJoBC2Mw28_jfgAAAOo"]
[Tue Jul 21 08:40:38.721114 2026] [security2:error] [pid 465652:tid 465883] [client 195.206.105.227:51588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9atjzTqJoBC2Mw28_jfgAAAOo"]
[Tue Jul 21 08:40:38.794441 2026] [security2:error] [pid 465652:tid 465846] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9atjzTqJoBC2Mw28_jfwAAAMU"]
[Tue Jul 21 08:40:38.972371 2026] [security2:error] [pid 465652:tid 465900] [client 20.206.105.145:45372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/min.php"] [unique_id "al9atjzTqJoBC2Mw28_jgwAAAPs"]
[Tue Jul 21 08:40:39.079083 2026] [security2:error] [pid 465652:tid 465811] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9atzzTqJoBC2Mw28_jhgAAAKI"]
[Tue Jul 21 08:40:39.310228 2026] [security2:error] [pid 465652:tid 465866] [client 122.176.100.127:60683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9atzzTqJoBC2Mw28_jiwAAANk"]
[Tue Jul 21 08:40:39.310455 2026] [security2:error] [pid 465652:tid 465866] [client 122.176.100.127:60683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9atzzTqJoBC2Mw28_jiwAAANk"]
[Tue Jul 21 08:40:39.361247 2026] [security2:error] [pid 465652:tid 465810] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9atzzTqJoBC2Mw28_jjAAAAKE"]
[Tue Jul 21 08:40:39.469913 2026] [security2:error] [pid 465652:tid 465901] [client 20.197.192.193:65185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/wp-signup.php"] [unique_id "al9atzzTqJoBC2Mw28_jkgAAAPw"]
[Tue Jul 21 08:40:39.589217 2026] [security2:error] [pid 465652:tid 465895] [client 168.167.81.163:61824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9atzzTqJoBC2Mw28_jmAAAAPY"]
[Tue Jul 21 08:40:39.589338 2026] [security2:error] [pid 465652:tid 465895] [client 168.167.81.163:61824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9atzzTqJoBC2Mw28_jmAAAAPY"]
[Tue Jul 21 08:40:39.644894 2026] [security2:error] [pid 465652:tid 465859] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9atzzTqJoBC2Mw28_joQAAANI"]
[Tue Jul 21 08:40:39.645477 2026] [security2:error] [pid 465652:tid 465890] [client 216.73.160.178:40445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9atzzTqJoBC2Mw28_jnwAAAPE"]
[Tue Jul 21 08:40:39.798040 2026] [security2:error] [pid 465652:tid 465909] [client 216.73.160.174:34625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9atzzTqJoBC2Mw28_jngAAAQQ"]
[Tue Jul 21 08:40:39.805433 2026] [security2:error] [pid 465652:tid 465821] [client 5.38.115.39:31998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9atzzTqJoBC2Mw28_jpAAAAKw"]
[Tue Jul 21 08:40:39.806489 2026] [security2:error] [pid 465652:tid 465821] [client 5.38.115.39:31998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9atzzTqJoBC2Mw28_jpAAAAKw"]
[Tue Jul 21 08:40:39.905726 2026] [security2:error] [pid 465652:tid 465814] [client 74.249.245.134:51485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/config-backup.php"] [unique_id "al9atzzTqJoBC2Mw28_jpgAAAKU"]
[Tue Jul 21 08:40:39.931428 2026] [security2:error] [pid 465652:tid 465813] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9atzzTqJoBC2Mw28_jqAAAAKQ"]
[Tue Jul 21 08:40:39.932902 2026] [security2:error] [pid 465652:tid 465809] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9atzzTqJoBC2Mw28_jqQAAAKA"]
[Tue Jul 21 08:40:39.974395 2026] [security2:error] [pid 465652:tid 465896] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9atzzTqJoBC2Mw28_jrgAAAPc"]
[Tue Jul 21 08:40:39.989733 2026] [security2:error] [pid 465652:tid 465856] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9atzzTqJoBC2Mw28_jrwAAAM8"]
[Tue Jul 21 08:40:40.015600 2026] [security2:error] [pid 465652:tid 465836] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9auDzTqJoBC2Mw28_jsAAAALs"]
[Tue Jul 21 08:40:40.033153 2026] [security2:error] [pid 465652:tid 465816] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9auDzTqJoBC2Mw28_jsgAAAKc"]
[Tue Jul 21 08:40:40.041935 2026] [security2:error] [pid 465652:tid 465831] [client 61.1.167.83:53799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9auDzTqJoBC2Mw28_jtAAAALY"]
[Tue Jul 21 08:40:40.042042 2026] [security2:error] [pid 465652:tid 465831] [client 61.1.167.83:53799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9auDzTqJoBC2Mw28_jtAAAALY"]
[Tue Jul 21 08:40:40.055377 2026] [security2:error] [pid 465652:tid 465811] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9auDzTqJoBC2Mw28_jtgAAAKI"]
[Tue Jul 21 08:40:40.215909 2026] [security2:error] [pid 465652:tid 465854] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.joycedelimabulhoespi1782854397400.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9auDzTqJoBC2Mw28_juwAAAM0"]
[Tue Jul 21 08:40:40.326834 2026] [security2:error] [pid 465652:tid 465882] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9auDzTqJoBC2Mw28_jvgAAAOk"]
[Tue Jul 21 08:40:40.343266 2026] [security2:error] [pid 465652:tid 465901] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9auDzTqJoBC2Mw28_jwAAAAPw"]
[Tue Jul 21 08:40:40.383924 2026] [security2:error] [pid 465652:tid 465885] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9auDzTqJoBC2Mw28_jwQAAAOw"]
[Tue Jul 21 08:40:40.415648 2026] [security2:error] [pid 465652:tid 465829] [client 20.220.225.223:40750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/la.php"] [unique_id "al9auDzTqJoBC2Mw28_jwgAAALQ"]
[Tue Jul 21 08:40:40.472542 2026] [security2:error] [pid 465652:tid 465873] [client 20.220.225.223:12589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9auDzTqJoBC2Mw28_jwwAAAOA"]
[Tue Jul 21 08:40:40.488746 2026] [security2:error] [pid 465652:tid 465895] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9auDzTqJoBC2Mw28_jxAAAAPY"]
[Tue Jul 21 08:40:40.491108 2026] [security2:error] [pid 465652:tid 465791] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9auDzTqJoBC2Mw28_jxQAAAI4"]
[Tue Jul 21 08:40:40.494651 2026] [security2:error] [pid 465652:tid 465857] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9auDzTqJoBC2Mw28_jxgAAANA"]
[Tue Jul 21 08:40:40.507601 2026] [security2:error] [pid 465652:tid 465817] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9auDzTqJoBC2Mw28_jxwAAAKg"]
[Tue Jul 21 08:40:40.653750 2026] [security2:error] [pid 465652:tid 465797] [client 216.73.160.19:21501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9atzzTqJoBC2Mw28_joAAAAJQ"]
[Tue Jul 21 08:40:40.661343 2026] [security2:error] [pid 465652:tid 465789] [client 203.25.124.68:58923] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/"] [unique_id "al9auDzTqJoBC2Mw28_jywAAAIw"]
[Tue Jul 21 08:40:40.682652 2026] [security2:error] [pid 465652:tid 465893] [client 20.206.105.145:33645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/gettest.php"] [unique_id "al9auDzTqJoBC2Mw28_jzgAAAPQ"]
[Tue Jul 21 08:40:40.705881 2026] [security2:error] [pid 465652:tid 465828] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9auDzTqJoBC2Mw28_j0AAAALM"]
[Tue Jul 21 08:40:40.725972 2026] [security2:error] [pid 465652:tid 465838] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9auDzTqJoBC2Mw28_j0QAAAL0"]
[Tue Jul 21 08:40:40.768783 2026] [security2:error] [pid 465652:tid 465864] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9auDzTqJoBC2Mw28_j0gAAANc"]
[Tue Jul 21 08:40:40.894663 2026] [security2:error] [pid 465652:tid 465880] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9auDzTqJoBC2Mw28_j0wAAAOc"]
[Tue Jul 21 08:40:40.896393 2026] [security2:error] [pid 465652:tid 465813] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9auDzTqJoBC2Mw28_j1AAAAKQ"]
[Tue Jul 21 08:40:40.897268 2026] [security2:error] [pid 465652:tid 465822] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9auDzTqJoBC2Mw28_j1QAAAK0"]
[Tue Jul 21 08:40:40.901264 2026] [security2:error] [pid 465652:tid 465809] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9auDzTqJoBC2Mw28_j1gAAAKA"]
[Tue Jul 21 08:40:40.937036 2026] [security2:error] [pid 465652:tid 465892] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ms-themes.php"] [unique_id "al9auDzTqJoBC2Mw28_j2AAAAPM"]
[Tue Jul 21 08:40:40.969569 2026] [security2:error] [pid 465652:tid 465904] [client 20.63.100.92:2515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/dp.php"] [unique_id "al9auDzTqJoBC2Mw28_j2wAAAP8"]
[Tue Jul 21 08:40:41.087882 2026] [security2:error] [pid 465652:tid 465835] [client 223.181.60.88:24862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9auTzTqJoBC2Mw28_j3QAAALo"]
[Tue Jul 21 08:40:41.088174 2026] [security2:error] [pid 465652:tid 465835] [client 223.181.60.88:24862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9auTzTqJoBC2Mw28_j3QAAALo"]
[Tue Jul 21 08:40:41.103675 2026] [security2:error] [pid 465652:tid 465839] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9auTzTqJoBC2Mw28_j3gAAAL4"]
[Tue Jul 21 08:40:41.113170 2026] [security2:error] [pid 465652:tid 465798] [client 20.206.105.145:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/edorxrr.php"] [unique_id "al9auTzTqJoBC2Mw28_j4AAAAJU"]
[Tue Jul 21 08:40:41.152457 2026] [security2:error] [pid 465652:tid 465799] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9auTzTqJoBC2Mw28_j4QAAAJY"]
[Tue Jul 21 08:40:41.152756 2026] [security2:error] [pid 465652:tid 465804] [client 202.179.75.202:51500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9auTzTqJoBC2Mw28_j4gAAAJs"]
[Tue Jul 21 08:40:41.152850 2026] [security2:error] [pid 465652:tid 465804] [client 202.179.75.202:51500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9auTzTqJoBC2Mw28_j4gAAAJs"]
[Tue Jul 21 08:40:41.233346 2026] [security2:error] [pid 465652:tid 465840] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9auTzTqJoBC2Mw28_j6QAAAL8"]
[Tue Jul 21 08:40:41.293604 2026] [security2:error] [pid 465652:tid 465860] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9auTzTqJoBC2Mw28_j7gAAANM"]
[Tue Jul 21 08:40:41.299971 2026] [security2:error] [pid 465652:tid 465854] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9auTzTqJoBC2Mw28_j7wAAAM0"]
[Tue Jul 21 08:40:41.304373 2026] [security2:error] [pid 465652:tid 465802] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9auTzTqJoBC2Mw28_j8AAAAJk"]
[Tue Jul 21 08:40:41.322794 2026] [security2:error] [pid 465652:tid 465863] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9auTzTqJoBC2Mw28_j8QAAANY"]
[Tue Jul 21 08:40:41.370944 2026] [security2:error] [pid 465652:tid 465808] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/chosen.php"] [unique_id "al9auTzTqJoBC2Mw28_j8gAAAJ8"]
[Tue Jul 21 08:40:41.488700 2026] [security2:error] [pid 465652:tid 465793] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9auTzTqJoBC2Mw28_j8wAAAJA"]
[Tue Jul 21 08:40:41.530112 2026] [security2:error] [pid 465652:tid 465885] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9auTzTqJoBC2Mw28_j9QAAAOw"]
[Tue Jul 21 08:40:41.592399 2026] [security2:error] [pid 465652:tid 465857] [client 20.197.192.193:65183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/csa.php"] [unique_id "al9auTzTqJoBC2Mw28_j9wAAANA"]
[Tue Jul 21 08:40:41.620476 2026] [security2:error] [pid 465652:tid 465820] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9auTzTqJoBC2Mw28_j-AAAAKs"]
[Tue Jul 21 08:40:41.639087 2026] [security2:error] [pid 465652:tid 465825] [client 216.73.160.27:44235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9atzzTqJoBC2Mw28_jnQAAALA"]
[Tue Jul 21 08:40:41.673345 2026] [security2:error] [pid 465652:tid 465824] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9auTzTqJoBC2Mw28_j-gAAAK8"]
[Tue Jul 21 08:40:41.683496 2026] [security2:error] [pid 465652:tid 465794] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9auTzTqJoBC2Mw28_j-wAAAJE"]
[Tue Jul 21 08:40:41.702450 2026] [security2:error] [pid 465652:tid 465853] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9auTzTqJoBC2Mw28_j_AAAAMw"]
[Tue Jul 21 08:40:41.707702 2026] [security2:error] [pid 465652:tid 465908] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9auTzTqJoBC2Mw28_j_QAAAQM"]
[Tue Jul 21 08:40:41.753685 2026] [security2:error] [pid 465652:tid 465905] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/file.php"] [unique_id "al9auTzTqJoBC2Mw28_kBQAAAQA"]
[Tue Jul 21 08:40:41.759650 2026] [security2:error] [pid 465652:tid 465823] [client 212.32.76.6:31013] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/languages/plugins/"] [unique_id "al9auTzTqJoBC2Mw28_kBgAAAK4"]
[Tue Jul 21 08:40:41.797287 2026] [security2:error] [pid 465652:tid 465782] [client 20.206.105.145:45957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/hur.php"] [unique_id "al9auTzTqJoBC2Mw28_kCQAAAIU"]
[Tue Jul 21 08:40:41.825487 2026] [security2:error] [pid 465652:tid 465710] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9auTzTqJoBC2Mw28_kCwAAyTk"]
[Tue Jul 21 08:40:41.914031 2026] [proxy:error] [pid 465652:tid 465890] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:41.914099 2026] [proxy_http:error] [pid 465652:tid 465890] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:41.914529 2026] [proxy:error] [pid 465652:tid 465890] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:41.914554 2026] [proxy_http:error] [pid 465652:tid 465890] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:41.968821 2026] [security2:error] [pid 465652:tid 465728] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9auTzTqJoBC2Mw28_kDgAAz0s"]
[Tue Jul 21 08:40:42.117245 2026] [security2:error] [pid 465652:tid 465831] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aujzTqJoBC2Mw28_kEAAAALY"]
[Tue Jul 21 08:40:42.128720 2026] [security2:error] [pid 465652:tid 465900] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aujzTqJoBC2Mw28_kEQAAAPs"]
[Tue Jul 21 08:40:42.156118 2026] [security2:error] [pid 465652:tid 465839] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aujzTqJoBC2Mw28_kEwAAAL4"]
[Tue Jul 21 08:40:42.205695 2026] [security2:error] [pid 465652:tid 465799] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aujzTqJoBC2Mw28_kFAAAAJY"]
[Tue Jul 21 08:40:42.226686 2026] [security2:error] [pid 465652:tid 465804] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aujzTqJoBC2Mw28_kFQAAAJs"]
[Tue Jul 21 08:40:42.227886 2026] [security2:error] [pid 465652:tid 465806] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aujzTqJoBC2Mw28_kFgAAAJ0"]
[Tue Jul 21 08:40:42.246417 2026] [security2:error] [pid 465652:tid 465783] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/flower.php"] [unique_id "al9aujzTqJoBC2Mw28_kGAAAAIY"]
[Tue Jul 21 08:40:42.262026 2026] [security2:error] [pid 465652:tid 465790] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9aujzTqJoBC2Mw28_kHQAAAI0"]
[Tue Jul 21 08:40:42.300214 2026] [proxy:error] [pid 465652:tid 465810] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:42.300277 2026] [proxy_http:error] [pid 465652:tid 465810] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:42.300721 2026] [proxy:error] [pid 465652:tid 465810] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:42.300744 2026] [proxy_http:error] [pid 465652:tid 465810] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:42.401271 2026] [security2:error] [pid 465652:tid 465778] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/media.php"] [unique_id "al9aujzTqJoBC2Mw28_kIgAAv30"]
[Tue Jul 21 08:40:42.459977 2026] [security2:error] [pid 465652:tid 465901] [client 74.249.245.134:20565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/goods.php"] [unique_id "al9aujzTqJoBC2Mw28_kIwAAAPw"]
[Tue Jul 21 08:40:42.510035 2026] [security2:error] [pid 465652:tid 465793] [client 20.206.105.145:46079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/zoro.php"] [unique_id "al9aujzTqJoBC2Mw28_kJAAAAJA"]
[Tue Jul 21 08:40:42.535168 2026] [security2:error] [pid 465652:tid 465866] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9aujzTqJoBC2Mw28_kKAAAANk"]
[Tue Jul 21 08:40:42.535168 2026] [security2:error] [pid 465652:tid 465807] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9aujzTqJoBC2Mw28_kKQAAAJ4"]
[Tue Jul 21 08:40:42.552839 2026] [security2:error] [pid 465652:tid 465720] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/images.php"] [unique_id "al9aujzTqJoBC2Mw28_kKgAA0EM"]
[Tue Jul 21 08:40:42.555341 2026] [security2:error] [pid 465652:tid 465817] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9aujzTqJoBC2Mw28_kKwAAAKg"]
[Tue Jul 21 08:40:42.607198 2026] [security2:error] [pid 465652:tid 465825] [client 20.197.192.193:65203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/min.php"] [unique_id "al9aujzTqJoBC2Mw28_kLAAAALA"]
[Tue Jul 21 08:40:42.660651 2026] [security2:error] [pid 465652:tid 465794] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9aujzTqJoBC2Mw28_kLQAAAJE"]
[Tue Jul 21 08:40:42.662893 2026] [security2:error] [pid 465652:tid 465826] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9aujzTqJoBC2Mw28_kLgAAALE"]
[Tue Jul 21 08:40:42.663189 2026] [security2:error] [pid 465652:tid 465853] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9aujzTqJoBC2Mw28_kLwAAAMw"]
[Tue Jul 21 08:40:42.665846 2026] [security2:error] [pid 465652:tid 465906] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/gifclass.php"] [unique_id "al9aujzTqJoBC2Mw28_kMAAAAQE"]
[Tue Jul 21 08:40:42.677107 2026] [security2:error] [pid 465652:tid 465797] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9aujzTqJoBC2Mw28_kMQAAAJQ"]
[Tue Jul 21 08:40:42.688456 2026] [security2:error] [pid 465652:tid 465854] [client 14.245.224.124:62829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aujzTqJoBC2Mw28_kMgAAAM0"]
[Tue Jul 21 08:40:42.688862 2026] [security2:error] [pid 465652:tid 465854] [client 14.245.224.124:62829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9aujzTqJoBC2Mw28_kMgAAAM0"]
[Tue Jul 21 08:40:42.695942 2026] [security2:error] [pid 465652:tid 465713] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/gecko.php"] [unique_id "al9aujzTqJoBC2Mw28_kMwAA3Dw"]
[Tue Jul 21 08:40:42.740639 2026] [proxy:error] [pid 465652:tid 465893] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:42.740692 2026] [proxy_http:error] [pid 465652:tid 465893] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:42.741347 2026] [proxy:error] [pid 465652:tid 465893] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:42.742379 2026] [proxy_http:error] [pid 465652:tid 465893] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:42.790496 2026] [security2:error] [pid 465652:tid 465863] [client 195.49.128.211:52011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aujzTqJoBC2Mw28_kOAAAANY"]
[Tue Jul 21 08:40:42.790614 2026] [security2:error] [pid 465652:tid 465863] [client 195.49.128.211:52011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9aujzTqJoBC2Mw28_kOAAAANY"]
[Tue Jul 21 08:40:42.844617 2026] [security2:error] [pid 465652:tid 465745] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/82.php"] [unique_id "al9aujzTqJoBC2Mw28_kPAAA51w"]
[Tue Jul 21 08:40:42.885012 2026] [security2:error] [pid 465652:tid 465865] [client 20.226.60.151:58619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/ho.php"] [unique_id "al9aujzTqJoBC2Mw28_kPgAAANg"]
[Tue Jul 21 08:40:42.947558 2026] [security2:error] [pid 465652:tid 465792] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9aujzTqJoBC2Mw28_kPwAAAI8"]
[Tue Jul 21 08:40:42.951219 2026] [security2:error] [pid 465652:tid 465784] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9aujzTqJoBC2Mw28_kQAAAAIc"]
[Tue Jul 21 08:40:42.964652 2026] [security2:error] [pid 465652:tid 465877] [client 203.25.124.52:59403] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/ioxi-o.php"] [unique_id "al9aujzTqJoBC2Mw28_kQQAAAOQ"]
[Tue Jul 21 08:40:42.999161 2026] [security2:error] [pid 465652:tid 465689] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/admin.php"] [unique_id "al9aujzTqJoBC2Mw28_kQwAA6iQ"]
[Tue Jul 21 08:40:43.010277 2026] [security2:error] [pid 465652:tid 465846] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9auzzTqJoBC2Mw28_kRAAAAMU"]
[Tue Jul 21 08:40:43.054068 2026] [security2:error] [pid 465652:tid 465895] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9auzzTqJoBC2Mw28_kRQAAAPY"]
[Tue Jul 21 08:40:43.058465 2026] [security2:error] [pid 465652:tid 465803] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9auzzTqJoBC2Mw28_kRgAAAJo"]
[Tue Jul 21 08:40:43.065345 2026] [security2:error] [pid 465652:tid 465818] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9auzzTqJoBC2Mw28_kRwAAAKk"]
[Tue Jul 21 08:40:43.067135 2026] [security2:error] [pid 465652:tid 465902] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bless.php"] [unique_id "al9auzzTqJoBC2Mw28_kSAAAAP0"]
[Tue Jul 21 08:40:43.149705 2026] [security2:error] [pid 465652:tid 465734] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/adminner.php"] [unique_id "al9auzzTqJoBC2Mw28_kSgAAtVE"]
[Tue Jul 21 08:40:43.170930 2026] [security2:error] [pid 465652:tid 465836] [client 20.220.225.223:12605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/dr.php"] [unique_id "al9auzzTqJoBC2Mw28_kSwAAALs"]
[Tue Jul 21 08:40:43.219494 2026] [security2:error] [pid 465652:tid 465884] [client 103.59.206.240:31115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9auzzTqJoBC2Mw28_kTAAAAOs"]
[Tue Jul 21 08:40:43.219581 2026] [security2:error] [pid 465652:tid 465884] [client 103.59.206.240:31115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9auzzTqJoBC2Mw28_kTAAAAOs"]
[Tue Jul 21 08:40:43.266113 2026] [security2:error] [pid 465652:tid 465783] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9auzzTqJoBC2Mw28_kTwAAAIY"]
[Tue Jul 21 08:40:43.269218 2026] [security2:error] [pid 465652:tid 465790] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9auzzTqJoBC2Mw28_kUQAAAI0"]
[Tue Jul 21 08:40:43.313346 2026] [security2:error] [pid 465652:tid 465702] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/admin.php"] [unique_id "al9auzzTqJoBC2Mw28_kVAAA8DE"]
[Tue Jul 21 08:40:43.323656 2026] [security2:error] [pid 465652:tid 465867] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9auzzTqJoBC2Mw28_kVQAAANo"]
[Tue Jul 21 08:40:43.331665 2026] [security2:error] [pid 465652:tid 465897] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9auzzTqJoBC2Mw28_kVwAAAPg"]
[Tue Jul 21 08:40:43.336179 2026] [security2:error] [pid 465652:tid 465805] [client 20.63.100.92:2333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/bootstrap.php"] [unique_id "al9auzzTqJoBC2Mw28_kWAAAAJw"]
[Tue Jul 21 08:40:43.384251 2026] [security2:error] [pid 465652:tid 465780] [remote 216.73.216.184:33325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemape.xml"] [unique_id "al9auzzTqJoBC2Mw28_kXAAA_n8"]
[Tue Jul 21 08:40:43.392767 2026] [security2:error] [pid 465652:tid 465843] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9auzzTqJoBC2Mw28_kXQAAAMI"]
[Tue Jul 21 08:40:43.434365 2026] [security2:error] [pid 465652:tid 465882] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9auzzTqJoBC2Mw28_kXgAAAOk"]
[Tue Jul 21 08:40:43.444174 2026] [security2:error] [pid 465652:tid 465901] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9auzzTqJoBC2Mw28_kXwAAAPw"]
[Tue Jul 21 08:40:43.450624 2026] [security2:error] [pid 465652:tid 465886] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/class-t.api.php"] [unique_id "al9auzzTqJoBC2Mw28_kYAAAAO0"]
[Tue Jul 21 08:40:43.451885 2026] [security2:error] [pid 465652:tid 465793] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9auzzTqJoBC2Mw28_kYQAAAJA"]
[Tue Jul 21 08:40:43.463978 2026] [security2:error] [pid 465652:tid 465655] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/k.php"] [unique_id "al9auzzTqJoBC2Mw28_kYgAA7AI"]
[Tue Jul 21 08:40:43.507176 2026] [fcgid:warn] [pid 465652:tid 465796] (70014)End of file found: [client 184.154.76.20:45966] mod_fcgid: can't get data from http client
[Tue Jul 21 08:40:43.609613 2026] [security2:error] [pid 465652:tid 465747] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/blurbs.php"] [unique_id "al9auzzTqJoBC2Mw28_kZgAAsF4"]
[Tue Jul 21 08:40:43.645462 2026] [security2:error] [pid 465652:tid 465853] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9auzzTqJoBC2Mw28_kaAAAAMw"]
[Tue Jul 21 08:40:43.704258 2026] [security2:error] [pid 465652:tid 465797] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9auzzTqJoBC2Mw28_kaQAAAJQ"]
[Tue Jul 21 08:40:43.752761 2026] [security2:error] [pid 465652:tid 465715] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/bajah.php"] [unique_id "al9auzzTqJoBC2Mw28_kagAA3D4"]
[Tue Jul 21 08:40:43.771435 2026] [security2:error] [pid 465652:tid 465832] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9auzzTqJoBC2Mw28_kawAAALc"]
[Tue Jul 21 08:40:43.796607 2026] [security2:error] [pid 465652:tid 465791] [client 20.206.105.145:46045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/coffexium.php"] [unique_id "al9auzzTqJoBC2Mw28_kbgAAAI4"]
[Tue Jul 21 08:40:43.811757 2026] [security2:error] [pid 465652:tid 465878] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9auzzTqJoBC2Mw28_kbwAAAOU"]
[Tue Jul 21 08:40:43.822221 2026] [security2:error] [pid 465652:tid 465909] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9auzzTqJoBC2Mw28_kcgAAAQQ"]
[Tue Jul 21 08:40:43.841883 2026] [security2:error] [pid 465652:tid 465848] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9auzzTqJoBC2Mw28_kdgAAAMc"]
[Tue Jul 21 08:40:43.848658 2026] [security2:error] [pid 465652:tid 465864] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9auzzTqJoBC2Mw28_keAAAANc"]
[Tue Jul 21 08:40:43.875161 2026] [security2:error] [pid 465652:tid 465759] [remote 162.243.80.244:36076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "conectivatec.com.br"] [uri "/.env"] [unique_id "al9auzzTqJoBC2Mw28_keQAAumo"]
[Tue Jul 21 08:40:43.881465 2026] [security2:error] [pid 465652:tid 465880] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9auzzTqJoBC2Mw28_kewAAAOc"]
[Tue Jul 21 08:40:43.903677 2026] [security2:error] [pid 465652:tid 465741] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/a.php"] [unique_id "al9auzzTqJoBC2Mw28_kfQAApFg"]
[Tue Jul 21 08:40:44.015677 2026] [security2:error] [pid 465652:tid 465852] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/blurbs.php"] [unique_id "al9avDzTqJoBC2Mw28_kfwAAAMs"]
[Tue Jul 21 08:40:44.046378 2026] [security2:error] [pid 465652:tid 465670] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/edit.php"] [unique_id "al9avDzTqJoBC2Mw28_kggAA_RE"]
[Tue Jul 21 08:40:44.066616 2026] [security2:error] [pid 465652:tid 465856] [client 203.25.124.52:34651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/IXR/"] [unique_id "al9avDzTqJoBC2Mw28_kgwAAAM8"]
[Tue Jul 21 08:40:44.094795 2026] [security2:error] [pid 465652:tid 465830] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9avDzTqJoBC2Mw28_khAAAALU"]
[Tue Jul 21 08:40:44.142260 2026] [security2:error] [pid 465652:tid 465871] [client 152.59.181.104:61710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9avDzTqJoBC2Mw28_khgAAAN4"]
[Tue Jul 21 08:40:44.147024 2026] [security2:error] [pid 465652:tid 465871] [client 152.59.181.104:61710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9avDzTqJoBC2Mw28_khgAAAN4"]
[Tue Jul 21 08:40:44.149640 2026] [security2:error] [pid 465652:tid 465789] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9avDzTqJoBC2Mw28_khwAAAIw"]
[Tue Jul 21 08:40:44.177448 2026] [security2:error] [pid 465652:tid 465896] [client 20.206.105.145:33703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/min.php"] [unique_id "al9avDzTqJoBC2Mw28_kiAAAAPc"]
[Tue Jul 21 08:40:44.197684 2026] [security2:error] [pid 465652:tid 465701] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/hosty.php"] [unique_id "al9avDzTqJoBC2Mw28_kiQAA-zA"]
[Tue Jul 21 08:40:44.238973 2026] [security2:error] [pid 465652:tid 465783] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9avDzTqJoBC2Mw28_kjwAAAIY"]
[Tue Jul 21 08:40:44.247424 2026] [security2:error] [pid 465652:tid 465795] [client 20.206.105.145:46062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/app.php"] [unique_id "al9avDzTqJoBC2Mw28_kkAAAAJI"]
[Tue Jul 21 08:40:44.280939 2026] [security2:error] [pid 465652:tid 465804] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9avDzTqJoBC2Mw28_kkgAAAJs"]
[Tue Jul 21 08:40:44.291055 2026] [security2:error] [pid 465652:tid 465897] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9avDzTqJoBC2Mw28_kkwAAAPg"]
[Tue Jul 21 08:40:44.327225 2026] [security2:error] [pid 465652:tid 465907] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9avDzTqJoBC2Mw28_klQAAAQI"]
[Tue Jul 21 08:40:44.334084 2026] [security2:error] [pid 465652:tid 465894] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9avDzTqJoBC2Mw28_kmgAAAPU"]
[Tue Jul 21 08:40:44.338059 2026] [security2:error] [pid 465652:tid 465840] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9avDzTqJoBC2Mw28_kmwAAAL8"]
[Tue Jul 21 08:40:44.347581 2026] [security2:error] [pid 465652:tid 465753] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/k.php"] [unique_id "al9avDzTqJoBC2Mw28_kngAA0mQ"]
[Tue Jul 21 08:40:44.402152 2026] [security2:error] [pid 465652:tid 465793] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/akcc.php"] [unique_id "al9avDzTqJoBC2Mw28_knwAAAJA"]
[Tue Jul 21 08:40:44.493642 2026] [security2:error] [pid 465652:tid 465888] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9avDzTqJoBC2Mw28_koQAAAO8"]
[Tue Jul 21 08:40:44.513626 2026] [security2:error] [pid 465652:tid 465777] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/aaa.php"] [unique_id "al9avDzTqJoBC2Mw28_kpQAAqHw"]
[Tue Jul 21 08:40:44.537701 2026] [security2:error] [pid 465652:tid 465822] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9avDzTqJoBC2Mw28_kpgAAAK0"]
[Tue Jul 21 08:40:44.659444 2026] [security2:error] [pid 465652:tid 465724] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/file5.php"] [unique_id "al9avDzTqJoBC2Mw28_krQAAs0c"]
[Tue Jul 21 08:40:44.667282 2026] [security2:error] [pid 465652:tid 465657] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9avDzTqJoBC2Mw28_krgAA7AQ"]
[Tue Jul 21 08:40:44.667398 2026] [security2:error] [pid 465652:tid 465885] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9avDzTqJoBC2Mw28_krgAA7AQ"]
[Tue Jul 21 08:40:44.742891 2026] [security2:error] [pid 465652:tid 465879] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9avDzTqJoBC2Mw28_krwAAAOY"]
[Tue Jul 21 08:40:44.745807 2026] [security2:error] [pid 465652:tid 465782] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9avDzTqJoBC2Mw28_ksAAAAIU"]
[Tue Jul 21 08:40:44.755699 2026] [security2:error] [pid 465652:tid 465835] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9avDzTqJoBC2Mw28_ksgAAALo"]
[Tue Jul 21 08:40:44.758825 2026] [security2:error] [pid 465652:tid 465880] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9avDzTqJoBC2Mw28_kswAAAOc"]
[Tue Jul 21 08:40:44.759290 2026] [security2:error] [pid 465652:tid 465800] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9avDzTqJoBC2Mw28_ktAAAAJc"]
[Tue Jul 21 08:40:44.768512 2026] [security2:error] [pid 465652:tid 465850] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9avDzTqJoBC2Mw28_ktQAAAMk"]
[Tue Jul 21 08:40:44.810865 2026] [security2:error] [pid 465652:tid 465737] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/222.php"] [unique_id "al9avDzTqJoBC2Mw28_ktgAAoFQ"]
[Tue Jul 21 08:40:44.897699 2026] [security2:error] [pid 465652:tid 465786] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9avDzTqJoBC2Mw28_kuQAAAIk"]
[Tue Jul 21 08:40:44.935530 2026] [security2:error] [pid 465652:tid 465902] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/abcd.php"] [unique_id "al9avDzTqJoBC2Mw28_kvAAAAP0"]
[Tue Jul 21 08:40:44.958434 2026] [security2:error] [pid 465652:tid 465660] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/test.php"] [unique_id "al9avDzTqJoBC2Mw28_kvwAAigc"]
[Tue Jul 21 08:40:44.972064 2026] [security2:error] [pid 465652:tid 465788] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9avDzTqJoBC2Mw28_kwQAAAIs"]
[Tue Jul 21 08:40:44.976448 2026] [security2:error] [pid 465652:tid 465783] [client 20.206.105.145:46053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/core.php"] [unique_id "al9avDzTqJoBC2Mw28_kwgAAAIY"]
[Tue Jul 21 08:40:45.112356 2026] [security2:error] [pid 465652:tid 465684] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/aaa.php"] [unique_id "al9avTzTqJoBC2Mw28_kxAAA7h8"]
[Tue Jul 21 08:40:45.127894 2026] [security2:error] [pid 465652:tid 465867] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9avTzTqJoBC2Mw28_kxQAAANo"]
[Tue Jul 21 08:40:45.181654 2026] [autoindex:error] [pid 465652:tid 465907] [client 198.235.24.177:58946] AH01276: Cannot serve directory /home1/ogcsol05/sideli.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:45.263325 2026] [security2:error] [pid 465652:tid 465661] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/11.php"] [unique_id "al9avTzTqJoBC2Mw28_kygAA3wg"]
[Tue Jul 21 08:40:45.307603 2026] [security2:error] [pid 465652:tid 465802] [client 20.206.105.145:45336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/main.php"] [unique_id "al9avTzTqJoBC2Mw28_kywAAAJk"]
[Tue Jul 21 08:40:45.312901 2026] [security2:error] [pid 465652:tid 465843] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9avTzTqJoBC2Mw28_kzAAAAMI"]
[Tue Jul 21 08:40:45.314006 2026] [security2:error] [pid 465652:tid 465882] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9avTzTqJoBC2Mw28_kzQAAAOk"]
[Tue Jul 21 08:40:45.344019 2026] [security2:error] [pid 465652:tid 465901] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9avTzTqJoBC2Mw28_kzgAAAPw"]
[Tue Jul 21 08:40:45.347728 2026] [security2:error] [pid 465652:tid 465810] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9avTzTqJoBC2Mw28_kzwAAAKE"]
[Tue Jul 21 08:40:45.348059 2026] [security2:error] [pid 465652:tid 465886] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9avTzTqJoBC2Mw28_k0AAAAO0"]
[Tue Jul 21 08:40:45.349429 2026] [security2:error] [pid 465652:tid 465793] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9avTzTqJoBC2Mw28_k0QAAAJA"]
[Tue Jul 21 08:40:45.415529 2026] [security2:error] [pid 465652:tid 465690] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/mac.php"] [unique_id "al9avTzTqJoBC2Mw28_k1QAA7yU"]
[Tue Jul 21 08:40:45.451603 2026] [security2:error] [pid 465652:tid 465826] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/shelp.php"] [unique_id "al9avTzTqJoBC2Mw28_k3gAAALE"]
[Tue Jul 21 08:40:45.468503 2026] [security2:error] [pid 465652:tid 465822] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9avTzTqJoBC2Mw28_k4QAAAK0"]
[Tue Jul 21 08:40:45.472831 2026] [security2:error] [pid 465652:tid 465823] [client 20.206.105.145:46020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/init.php"] [unique_id "al9avTzTqJoBC2Mw28_k4gAAAK4"]
[Tue Jul 21 08:40:45.488447 2026] [security2:error] [pid 465652:tid 465878] [client 20.220.225.223:12320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/2x.php"] [unique_id "al9avTzTqJoBC2Mw28_k5AAAAOU"]
[Tue Jul 21 08:40:45.567288 2026] [security2:error] [pid 465652:tid 465838] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9avTzTqJoBC2Mw28_k5QAAAL0"]
[Tue Jul 21 08:40:45.572293 2026] [security2:error] [pid 465652:tid 465730] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/chosen.php"] [unique_id "al9avTzTqJoBC2Mw28_k5wAA5k0"]
[Tue Jul 21 08:40:45.744675 2026] [security2:error] [pid 465652:tid 465771] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/cream1.php"] [unique_id "al9avTzTqJoBC2Mw28_k6AABBHY"]
[Tue Jul 21 08:40:45.860057 2026] [security2:error] [pid 465652:tid 465883] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9avTzTqJoBC2Mw28_k6QAAAOo"]
[Tue Jul 21 08:40:45.861866 2026] [security2:error] [pid 465652:tid 465784] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9avTzTqJoBC2Mw28_k6gAAAIc"]
[Tue Jul 21 08:40:45.883058 2026] [security2:error] [pid 465652:tid 465852] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9avTzTqJoBC2Mw28_k7AAAAMs"]
[Tue Jul 21 08:40:45.885347 2026] [security2:error] [pid 465652:tid 465895] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9avTzTqJoBC2Mw28_k7QAAAPY"]
[Tue Jul 21 08:40:45.894239 2026] [security2:error] [pid 465652:tid 465803] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9avTzTqJoBC2Mw28_k7wAAAJo"]
[Tue Jul 21 08:40:45.894277 2026] [proxy:error] [pid 465652:tid 465707] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:45.894314 2026] [proxy_http:error] [pid 465652:tid 465707] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:45.894968 2026] [security2:error] [pid 465652:tid 465902] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9avTzTqJoBC2Mw28_k8AAAAP0"]
[Tue Jul 21 08:40:45.895805 2026] [proxy:error] [pid 465652:tid 465707] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:45.895877 2026] [proxy_http:error] [pid 465652:tid 465707] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:45.909062 2026] [security2:error] [pid 465652:tid 465891] [client 20.206.105.145:45345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/prekel.php"] [unique_id "al9avTzTqJoBC2Mw28_k8QAAAPI"]
[Tue Jul 21 08:40:45.966065 2026] [security2:error] [pid 465652:tid 465798] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9avTzTqJoBC2Mw28_k9gAAAJU"]
[Tue Jul 21 08:40:45.969090 2026] [security2:error] [pid 465652:tid 465874] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9avTzTqJoBC2Mw28_k9wAAAOE"]
[Tue Jul 21 08:40:45.972103 2026] [security2:error] [pid 465652:tid 465820] [client 195.49.128.211:59854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9avTzTqJoBC2Mw28_k-QAAAKs"]
[Tue Jul 21 08:40:45.972244 2026] [security2:error] [pid 465652:tid 465820] [client 195.49.128.211:59854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9avTzTqJoBC2Mw28_k-QAAAKs"]
[Tue Jul 21 08:40:46.061521 2026] [proxy:error] [pid 465652:tid 465773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:46.061589 2026] [proxy_http:error] [pid 465652:tid 465773] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:46.062121 2026] [proxy:error] [pid 465652:tid 465773] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:46.062146 2026] [proxy_http:error] [pid 465652:tid 465773] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:46.088340 2026] [security2:error] [pid 465652:tid 465805] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cord.php"] [unique_id "al9avjzTqJoBC2Mw28_lAQAAAJw"]
[Tue Jul 21 08:40:46.170903 2026] [security2:error] [pid 465652:tid 465802] [client 212.32.76.11:29793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/404.php"] [unique_id "al9avjzTqJoBC2Mw28_lAgAAAJk"]
[Tue Jul 21 08:40:46.225370 2026] [security2:error] [pid 465652:tid 465711] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/dr.php"] [unique_id "al9avjzTqJoBC2Mw28_lBwAA1Do"]
[Tue Jul 21 08:40:46.263701 2026] [security2:error] [pid 465652:tid 465815] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9avjzTqJoBC2Mw28_lCQAAAKY"]
[Tue Jul 21 08:40:46.283501 2026] [security2:error] [pid 465652:tid 465829] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9avjzTqJoBC2Mw28_lCgAAALQ"]
[Tue Jul 21 08:40:46.284393 2026] [security2:error] [pid 465652:tid 465840] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9avjzTqJoBC2Mw28_lCwAAAL8"]
[Tue Jul 21 08:40:46.286418 2026] [security2:error] [pid 465652:tid 465888] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9avjzTqJoBC2Mw28_lDAAAAO8"]
[Tue Jul 21 08:40:46.309872 2026] [security2:error] [pid 465652:tid 465866] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9avjzTqJoBC2Mw28_lDQAAANk"]
[Tue Jul 21 08:40:46.314401 2026] [security2:error] [pid 465652:tid 465824] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9avjzTqJoBC2Mw28_lDgAAAK8"]
[Tue Jul 21 08:40:46.354400 2026] [security2:error] [pid 465652:tid 465857] [client 20.206.105.145:46021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/0.php"] [unique_id "al9avjzTqJoBC2Mw28_lEAAAANA"]
[Tue Jul 21 08:40:46.354456 2026] [security2:error] [pid 465652:tid 465816] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9avjzTqJoBC2Mw28_lDwAAAKc"]
[Tue Jul 21 08:40:46.372559 2026] [security2:error] [pid 465652:tid 465853] [client 20.206.105.145:33684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/edorxrr.php"] [unique_id "al9avjzTqJoBC2Mw28_lEQAAAMw"]
[Tue Jul 21 08:40:46.374754 2026] [security2:error] [pid 465652:tid 465679] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/x.php"] [unique_id "al9avjzTqJoBC2Mw28_lEgAArRo"]
[Tue Jul 21 08:40:46.420341 2026] [security2:error] [pid 465652:tid 465906] [client 74.7.241.146:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lunalabdesign.com.br"] [uri "/index.php"] [unique_id "al9avTzTqJoBC2Mw28_k4AAAAQE"]
[Tue Jul 21 08:40:46.421163 2026] [security2:error] [pid 465652:tid 465892] [client 74.7.241.146:43238] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lunalabdesign.com.br"] [uri "/robots.txt"] [unique_id "al9avTzTqJoBC2Mw28_k3QAA820"]
[Tue Jul 21 08:40:46.450585 2026] [security2:error] [pid 465652:tid 465828] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9avjzTqJoBC2Mw28_lFQAAALM"]
[Tue Jul 21 08:40:46.475998 2026] [security2:error] [pid 465652:tid 465879] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/dex.php"] [unique_id "al9avjzTqJoBC2Mw28_lGQAAAOY"]
[Tue Jul 21 08:40:46.528605 2026] [security2:error] [pid 465652:tid 465740] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/155.php"] [unique_id "al9avjzTqJoBC2Mw28_lHQAAj1c"]
[Tue Jul 21 08:40:46.585356 2026] [security2:error] [pid 465652:tid 465865] [client 20.206.105.145:46048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/BDKR28.php"] [unique_id "al9avjzTqJoBC2Mw28_lHwAAANg"]
[Tue Jul 21 08:40:46.640524 2026] [security2:error] [pid 465652:tid 465830] [client 117.213.202.34:58113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9avjzTqJoBC2Mw28_lIQAAALU"]
[Tue Jul 21 08:40:46.640621 2026] [security2:error] [pid 465652:tid 465830] [client 117.213.202.34:58113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9avjzTqJoBC2Mw28_lIQAAALU"]
[Tue Jul 21 08:40:46.662981 2026] [security2:error] [pid 465652:tid 465856] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9avjzTqJoBC2Mw28_lIgAAAM8"]
[Tue Jul 21 08:40:46.667314 2026] [security2:error] [pid 465652:tid 465798] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9avjzTqJoBC2Mw28_lIwAAAJU"]
[Tue Jul 21 08:40:46.676333 2026] [security2:error] [pid 465652:tid 465874] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9avjzTqJoBC2Mw28_lJAAAAOE"]
[Tue Jul 21 08:40:46.679219 2026] [security2:error] [pid 465652:tid 465820] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9avjzTqJoBC2Mw28_lJQAAAKs"]
[Tue Jul 21 08:40:46.684531 2026] [security2:error] [pid 465652:tid 465733] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/ops.php"] [unique_id "al9avjzTqJoBC2Mw28_lJgAAylA"]
[Tue Jul 21 08:40:46.696577 2026] [security2:error] [pid 465652:tid 465799] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9avjzTqJoBC2Mw28_lJwAAAJY"]
[Tue Jul 21 08:40:46.701832 2026] [security2:error] [pid 465652:tid 465788] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9avjzTqJoBC2Mw28_lKAAAAIs"]
[Tue Jul 21 08:40:46.759564 2026] [security2:error] [pid 465652:tid 465729] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9avjzTqJoBC2Mw28_lKQAAqEw"]
[Tue Jul 21 08:40:46.759691 2026] [security2:error] [pid 465652:tid 465817] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9avjzTqJoBC2Mw28_lKQAAqEw"]
[Tue Jul 21 08:40:46.783325 2026] [security2:error] [pid 465652:tid 465871] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9avjzTqJoBC2Mw28_lKgAAAN4"]
[Tue Jul 21 08:40:46.834442 2026] [security2:error] [pid 465652:tid 465790] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9avjzTqJoBC2Mw28_lLAAAAI0"]
[Tue Jul 21 08:40:46.840670 2026] [security2:error] [pid 465652:tid 465672] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/file31.php"] [unique_id "al9avjzTqJoBC2Mw28_lLgAA4hM"]
[Tue Jul 21 08:40:46.864023 2026] [security2:error] [pid 465652:tid 465909] [client 49.144.66.253:30116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9avjzTqJoBC2Mw28_lLwAAAQQ"]
[Tue Jul 21 08:40:46.864127 2026] [security2:error] [pid 465652:tid 465909] [client 49.144.66.253:30116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9avjzTqJoBC2Mw28_lLwAAAQQ"]
[Tue Jul 21 08:40:46.960676 2026] [security2:error] [pid 465652:tid 465758] [remote 72.167.132.114:40728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9avjzTqJoBC2Mw28_lNQAA9mk"]
[Tue Jul 21 08:40:46.993296 2026] [security2:error] [pid 465652:tid 465725] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/file6.php"] [unique_id "al9avjzTqJoBC2Mw28_lOQAAmUg"]
[Tue Jul 21 08:40:47.005515 2026] [security2:error] [pid 465652:tid 465810] [client 20.206.105.145:46078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/f35.update.php"] [unique_id "al9avzzTqJoBC2Mw28_lOwAAAKE"]
[Tue Jul 21 08:40:47.054469 2026] [security2:error] [pid 465652:tid 465829] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9avzzTqJoBC2Mw28_lPgAAALQ"]
[Tue Jul 21 08:40:47.055467 2026] [security2:error] [pid 465652:tid 465840] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9avzzTqJoBC2Mw28_lPwAAAL8"]
[Tue Jul 21 08:40:47.069949 2026] [security2:error] [pid 465652:tid 465824] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9avzzTqJoBC2Mw28_lQQAAAK8"]
[Tue Jul 21 08:40:47.071454 2026] [security2:error] [pid 465652:tid 465796] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9avzzTqJoBC2Mw28_lQgAAAJM"]
[Tue Jul 21 08:40:47.074402 2026] [security2:error] [pid 465652:tid 465857] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9avzzTqJoBC2Mw28_lQwAAANA"]
[Tue Jul 21 08:40:47.088728 2026] [security2:error] [pid 465652:tid 465853] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9avzzTqJoBC2Mw28_lRQAAAMw"]
[Tue Jul 21 08:40:47.143588 2026] [security2:error] [pid 465652:tid 465908] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9avzzTqJoBC2Mw28_lSAAAAQM"]
[Tue Jul 21 08:40:47.154671 2026] [proxy:error] [pid 465652:tid 465700] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:47.154735 2026] [proxy_http:error] [pid 465652:tid 465700] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:47.155323 2026] [proxy:error] [pid 465652:tid 465700] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:47.155356 2026] [proxy_http:error] [pid 465652:tid 465700] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:47.184974 2026] [security2:error] [pid 465652:tid 465794] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9avzzTqJoBC2Mw28_lSwAAAJE"]
[Tue Jul 21 08:40:47.243453 2026] [security2:error] [pid 465652:tid 465878] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9avzzTqJoBC2Mw28_lTgAAAOU"]
[Tue Jul 21 08:40:47.252996 2026] [security2:error] [pid 465652:tid 465893] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9avzzTqJoBC2Mw28_lTwAAAPQ"]
[Tue Jul 21 08:40:47.304550 2026] [security2:error] [pid 465652:tid 465681] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/adminfuns.php"] [unique_id "al9avzzTqJoBC2Mw28_lUAAAuhw"]
[Tue Jul 21 08:40:47.356586 2026] [security2:error] [pid 465652:tid 465863] [client 74.249.245.134:20950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/init.php"] [unique_id "al9avzzTqJoBC2Mw28_lUgAAANY"]
[Tue Jul 21 08:40:47.373507 2026] [security2:error] [pid 465652:tid 465825] [client 113.22.144.139:59271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9avzzTqJoBC2Mw28_lTAAAALA"]
[Tue Jul 21 08:40:47.373660 2026] [security2:error] [pid 465652:tid 465825] [client 113.22.144.139:59271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9avzzTqJoBC2Mw28_lTAAAALA"]
[Tue Jul 21 08:40:47.446694 2026] [security2:error] [pid 465652:tid 465809] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9avzzTqJoBC2Mw28_lUwAAAKA"]
[Tue Jul 21 08:40:47.446886 2026] [security2:error] [pid 465652:tid 465905] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9avzzTqJoBC2Mw28_lVAAAAQA"]
[Tue Jul 21 08:40:47.448256 2026] [security2:error] [pid 465652:tid 465792] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9avzzTqJoBC2Mw28_lVQAAAI8"]
[Tue Jul 21 08:40:47.449682 2026] [security2:error] [pid 465652:tid 465784] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9avzzTqJoBC2Mw28_lVgAAAIc"]
[Tue Jul 21 08:40:47.457907 2026] [security2:error] [pid 465652:tid 465865] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9avzzTqJoBC2Mw28_lWAAAANg"]
[Tue Jul 21 08:40:47.458799 2026] [security2:error] [pid 465652:tid 465750] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/goods.php"] [unique_id "al9avzzTqJoBC2Mw28_lWQAA6mE"]
[Tue Jul 21 08:40:47.484478 2026] [security2:error] [pid 465652:tid 465859] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9avzzTqJoBC2Mw28_lWwAAANI"]
[Tue Jul 21 08:40:47.536725 2026] [security2:error] [pid 465652:tid 465801] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9avzzTqJoBC2Mw28_lXgAAAJg"]
[Tue Jul 21 08:40:47.582562 2026] [security2:error] [pid 465652:tid 465851] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9avzzTqJoBC2Mw28_lZAAAAMo"]
[Tue Jul 21 08:40:47.611338 2026] [security2:error] [pid 465652:tid 465704] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/100.php"] [unique_id "al9avzzTqJoBC2Mw28_lZQAAljM"]
[Tue Jul 21 08:40:47.612491 2026] [security2:error] [pid 465652:tid 465788] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/zwso.php"] [unique_id "al9avzzTqJoBC2Mw28_lZgAAAIs"]
[Tue Jul 21 08:40:47.649501 2026] [security2:error] [pid 465652:tid 465790] [client 20.220.225.223:12294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/kq1.php"] [unique_id "al9avzzTqJoBC2Mw28_lZwAAAI0"]
[Tue Jul 21 08:40:47.681956 2026] [security2:error] [pid 465652:tid 465783] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9avzzTqJoBC2Mw28_laAAAAIY"]
[Tue Jul 21 08:40:47.755566 2026] [security2:error] [pid 465652:tid 465768] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/about.php"] [unique_id "al9avzzTqJoBC2Mw28_laQAAonM"]
[Tue Jul 21 08:40:47.761472 2026] [security2:error] [pid 465652:tid 465909] [client 203.25.124.215:24425] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/mah.php"] [unique_id "al9avzzTqJoBC2Mw28_lagAAAQQ"]
[Tue Jul 21 08:40:47.840194 2026] [security2:error] [pid 465652:tid 465832] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9avzzTqJoBC2Mw28_lbgAAALc"]
[Tue Jul 21 08:40:47.845556 2026] [security2:error] [pid 465652:tid 465903] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9avzzTqJoBC2Mw28_lbwAAAP4"]
[Tue Jul 21 08:40:47.845841 2026] [security2:error] [pid 465652:tid 465895] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9avzzTqJoBC2Mw28_lcAAAAPY"]
[Tue Jul 21 08:40:47.849578 2026] [security2:error] [pid 465652:tid 465901] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9avzzTqJoBC2Mw28_lcQAAAPw"]
[Tue Jul 21 08:40:47.860857 2026] [security2:error] [pid 465652:tid 465831] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9avzzTqJoBC2Mw28_lcgAAALY"]
[Tue Jul 21 08:40:47.863606 2026] [security2:error] [pid 465652:tid 465833] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9avzzTqJoBC2Mw28_ldAAAALg"]
[Tue Jul 21 08:40:47.897782 2026] [security2:error] [pid 465652:tid 465691] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/about.php"] [unique_id "al9avzzTqJoBC2Mw28_ldQAAvCY"]
[Tue Jul 21 08:40:47.967247 2026] [security2:error] [pid 465652:tid 465886] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9avzzTqJoBC2Mw28_ldgAAAO0"]
[Tue Jul 21 08:40:47.972744 2026] [security2:error] [pid 465652:tid 465815] [client 20.206.105.145:46001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/f900.php"] [unique_id "al9avzzTqJoBC2Mw28_ldwAAAKY"]
[Tue Jul 21 08:40:48.009315 2026] [security2:error] [pid 465652:tid 465870] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9awDzTqJoBC2Mw28_leAAAAN0"]
[Tue Jul 21 08:40:48.062447 2026] [security2:error] [pid 465652:tid 465822] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9awDzTqJoBC2Mw28_lfgAAAK0"]
[Tue Jul 21 08:40:48.064330 2026] [security2:error] [pid 465652:tid 465710] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/admin.php"] [unique_id "al9awDzTqJoBC2Mw28_lfwABATk"]
[Tue Jul 21 08:40:48.107831 2026] [security2:error] [pid 465652:tid 465860] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9awDzTqJoBC2Mw28_lgQAAANM"]
[Tue Jul 21 08:40:48.157004 2026] [security2:error] [pid 465652:tid 465899] [client 20.206.105.145:45366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/xmrl.php"] [unique_id "al9awDzTqJoBC2Mw28_lhwAAAPo"]
[Tue Jul 21 08:40:48.229219 2026] [security2:error] [pid 465652:tid 465728] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/admin.php"] [unique_id "al9awDzTqJoBC2Mw28_liwAAhUs"]
[Tue Jul 21 08:40:48.229323 2026] [security2:error] [pid 465652:tid 465785] [client 204.12.208.18:51181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-includes/addb8871/index.php"] [unique_id "al9awDzTqJoBC2Mw28_ligAAAIg"], referer: https://rkcentroautomotivoo.com.br/wp-includes/addb8871/index.php
[Tue Jul 21 08:40:48.295423 2026] [security2:error] [pid 465652:tid 465800] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9awDzTqJoBC2Mw28_ljAAAAJc"]
[Tue Jul 21 08:40:48.297369 2026] [security2:error] [pid 465652:tid 465825] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9awDzTqJoBC2Mw28_ljQAAALA"]
[Tue Jul 21 08:40:48.298399 2026] [security2:error] [pid 465652:tid 465841] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9awDzTqJoBC2Mw28_ljgAAAMA"]
[Tue Jul 21 08:40:48.298569 2026] [security2:error] [pid 465652:tid 465850] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9awDzTqJoBC2Mw28_ljwAAAMk"]
[Tue Jul 21 08:40:48.299614 2026] [security2:error] [pid 465652:tid 465814] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9awDzTqJoBC2Mw28_lkAAAAKU"]
[Tue Jul 21 08:40:48.299637 2026] [security2:error] [pid 465652:tid 465813] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9awDzTqJoBC2Mw28_lkQAAAKQ"]
[Tue Jul 21 08:40:48.301805 2026] [security2:error] [pid 465652:tid 465809] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9awDzTqJoBC2Mw28_lkgAAAKA"]
[Tue Jul 21 08:40:48.370593 2026] [security2:error] [pid 465652:tid 465865] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9awDzTqJoBC2Mw28_llAAAANg"]
[Tue Jul 21 08:40:48.372888 2026] [security2:error] [pid 465652:tid 465664] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/themes.php"] [unique_id "al9awDzTqJoBC2Mw28_llQAA0gs"]
[Tue Jul 21 08:40:48.373549 2026] [security2:error] [pid 465652:tid 465883] [client 20.206.105.145:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/memberfuns.php"] [unique_id "al9awDzTqJoBC2Mw28_llgAAAOo"]
[Tue Jul 21 08:40:48.419874 2026] [security2:error] [pid 465652:tid 465904] [client 20.226.60.151:58506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xy.php"] [unique_id "al9awDzTqJoBC2Mw28_llwAAAP8"]
[Tue Jul 21 08:40:48.450294 2026] [security2:error] [pid 465652:tid 465856] [client 20.206.105.145:45967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/ms.php"] [unique_id "al9awDzTqJoBC2Mw28_lmAAAAM8"]
[Tue Jul 21 08:40:48.493111 2026] [security2:error] [pid 465652:tid 465839] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/bolt.php"] [unique_id "al9awDzTqJoBC2Mw28_lnAAAAL4"]
[Tue Jul 21 08:40:48.493149 2026] [security2:error] [pid 465652:tid 465900] [client 20.220.225.223:63298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/nhvoanpl.php"] [unique_id "al9awDzTqJoBC2Mw28_lmwAAAPs"]
[Tue Jul 21 08:40:48.517025 2026] [security2:error] [pid 465652:tid 465817] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9awDzTqJoBC2Mw28_lnQAAAKg"]
[Tue Jul 21 08:40:48.519868 2026] [proxy:error] [pid 465652:tid 465778] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:48.519938 2026] [proxy_http:error] [pid 465652:tid 465778] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:48.520518 2026] [proxy:error] [pid 465652:tid 465778] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:48.520545 2026] [proxy_http:error] [pid 465652:tid 465778] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:48.525147 2026] [security2:error] [pid 465652:tid 465902] [client 168.167.81.163:64567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9awDzTqJoBC2Mw28_loAAAAP0"]
[Tue Jul 21 08:40:48.525269 2026] [security2:error] [pid 465652:tid 465902] [client 168.167.81.163:64567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9awDzTqJoBC2Mw28_loAAAAP0"]
[Tue Jul 21 08:40:48.561631 2026] [security2:error] [pid 465652:tid 465804] [client 203.25.124.50:30519] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/"] [unique_id "al9awDzTqJoBC2Mw28_lpQAAAJs"]
[Tue Jul 21 08:40:48.580931 2026] [security2:error] [pid 465652:tid 465894] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9awDzTqJoBC2Mw28_lpwAAAPU"]
[Tue Jul 21 08:40:48.662499 2026] [security2:error] [pid 465652:tid 465903] [client 20.206.105.145:45893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/zz.php"] [unique_id "al9awDzTqJoBC2Mw28_lqgAAAP4"]
[Tue Jul 21 08:40:48.675239 2026] [proxy:error] [pid 465652:tid 465712] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:48.675312 2026] [proxy_http:error] [pid 465652:tid 465712] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:48.676115 2026] [proxy:error] [pid 465652:tid 465712] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:48.676154 2026] [proxy_http:error] [pid 465652:tid 465712] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:48.687449 2026] [security2:error] [pid 465652:tid 465805] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9awDzTqJoBC2Mw28_lrAAAAJw"]
[Tue Jul 21 08:40:48.688197 2026] [security2:error] [pid 465652:tid 465816] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9awDzTqJoBC2Mw28_lrQAAAKc"]
[Tue Jul 21 08:40:48.689299 2026] [security2:error] [pid 465652:tid 465810] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9awDzTqJoBC2Mw28_lrgAAAKE"]
[Tue Jul 21 08:40:48.689470 2026] [security2:error] [pid 465652:tid 465808] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9awDzTqJoBC2Mw28_lqQAAnzw"]
[Tue Jul 21 08:40:48.689648 2026] [security2:error] [pid 465652:tid 465831] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9awDzTqJoBC2Mw28_lrwAAALY"]
[Tue Jul 21 08:40:48.689867 2026] [security2:error] [pid 465652:tid 465833] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9awDzTqJoBC2Mw28_lsAAAALg"]
[Tue Jul 21 08:40:48.692080 2026] [security2:error] [pid 465652:tid 465786] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9awDzTqJoBC2Mw28_lsQAAAIk"]
[Tue Jul 21 08:40:48.714066 2026] [security2:error] [pid 465652:tid 465889] [client 59.95.197.55:60556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9awDzTqJoBC2Mw28_lsgAAAPA"]
[Tue Jul 21 08:40:48.714171 2026] [security2:error] [pid 465652:tid 465889] [client 59.95.197.55:60556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9awDzTqJoBC2Mw28_lsgAAAPA"]
[Tue Jul 21 08:40:48.759533 2026] [security2:error] [pid 465652:tid 465897] [client 204.12.208.18:51188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-includes/addb8871/index.php"] [unique_id "al9awDzTqJoBC2Mw28_lswAAAPg"], referer: https://rkcentroautomotivoo.com.br/wp-includes/addb8871/index.php
[Tue Jul 21 08:40:48.827545 2026] [security2:error] [pid 465652:tid 465853] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9awDzTqJoBC2Mw28_ltgAAAMw"]
[Tue Jul 21 08:40:48.832609 2026] [security2:error] [pid 465652:tid 465774] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/.well-known/about.php"] [unique_id "al9awDzTqJoBC2Mw28_luAAA2Xk"]
[Tue Jul 21 08:40:48.866249 2026] [security2:error] [pid 465652:tid 465840] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9awDzTqJoBC2Mw28_luwAAAL8"]
[Tue Jul 21 08:40:48.978455 2026] [security2:error] [pid 465652:tid 465689] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9awDzTqJoBC2Mw28_lvAAAkSQ"]
[Tue Jul 21 08:40:49.080568 2026] [security2:error] [pid 465652:tid 465782] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9awTzTqJoBC2Mw28_lwQAAAIU"]
[Tue Jul 21 08:40:49.086239 2026] [security2:error] [pid 465652:tid 465785] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9awTzTqJoBC2Mw28_lwgAAAIg"]
[Tue Jul 21 08:40:49.086661 2026] [security2:error] [pid 465652:tid 465845] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9awTzTqJoBC2Mw28_lwwAAAMQ"]
[Tue Jul 21 08:40:49.086875 2026] [security2:error] [pid 465652:tid 465800] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9awTzTqJoBC2Mw28_lxAAAAJc"]
[Tue Jul 21 08:40:49.088170 2026] [security2:error] [pid 465652:tid 465841] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9awTzTqJoBC2Mw28_lxgAAAMA"]
[Tue Jul 21 08:40:49.089439 2026] [security2:error] [pid 465652:tid 465850] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9awTzTqJoBC2Mw28_lxwAAAMk"]
[Tue Jul 21 08:40:49.105246 2026] [security2:error] [pid 465652:tid 465809] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/cjfuns.php"] [unique_id "al9awTzTqJoBC2Mw28_lygAAAKA"]
[Tue Jul 21 08:40:49.131861 2026] [security2:error] [pid 465652:tid 465693] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wefile.php"] [unique_id "al9awTzTqJoBC2Mw28_lywAAkCg"]
[Tue Jul 21 08:40:49.153026 2026] [security2:error] [pid 465652:tid 465859] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9awTzTqJoBC2Mw28_lzAAAANI"]
[Tue Jul 21 08:40:49.188031 2026] [security2:error] [pid 465652:tid 465819] [client 20.206.105.145:46068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/for.php"] [unique_id "al9awTzTqJoBC2Mw28_lzgAAAKo"]
[Tue Jul 21 08:40:49.226063 2026] [security2:error] [pid 465652:tid 465803] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9awTzTqJoBC2Mw28_lzwAAAJo"]
[Tue Jul 21 08:40:49.283168 2026] [security2:error] [pid 465652:tid 465779] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9awTzTqJoBC2Mw28_l0AAAyn4"]
[Tue Jul 21 08:40:49.301677 2026] [security2:error] [pid 465652:tid 465883] [client 204.12.208.18:51195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.208.12.204.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-includes/addb8871/index.php"] [unique_id "al9awTzTqJoBC2Mw28_l0QAAAOo"], referer: https://rkcentroautomotivoo.com.br/wp-includes/addb8871/index.php
[Tue Jul 21 08:40:49.429887 2026] [proxy:error] [pid 465652:tid 465669] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:49.429944 2026] [proxy_http:error] [pid 465652:tid 465669] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:49.430508 2026] [proxy:error] [pid 465652:tid 465669] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:49.430532 2026] [proxy_http:error] [pid 465652:tid 465669] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:49.438486 2026] [security2:error] [pid 465652:tid 465817] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9awTzTqJoBC2Mw28_l1AAAAKg"]
[Tue Jul 21 08:40:49.459861 2026] [security2:error] [pid 465652:tid 465875] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9awTzTqJoBC2Mw28_l1gAAAOI"]
[Tue Jul 21 08:40:49.462950 2026] [security2:error] [pid 465652:tid 465783] [client 203.25.124.31:26425] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp.php"] [unique_id "al9awTzTqJoBC2Mw28_l1wAAAIY"]
[Tue Jul 21 08:40:49.471462 2026] [security2:error] [pid 465652:tid 465887] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9awTzTqJoBC2Mw28_l2QAAAO4"]
[Tue Jul 21 08:40:49.471463 2026] [security2:error] [pid 465652:tid 465871] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9awTzTqJoBC2Mw28_l2AAAAN4"]
[Tue Jul 21 08:40:49.473671 2026] [security2:error] [pid 465652:tid 465811] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9awTzTqJoBC2Mw28_l2gAAAKI"]
[Tue Jul 21 08:40:49.473919 2026] [security2:error] [pid 465652:tid 465818] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9awTzTqJoBC2Mw28_l2wAAAKk"]
[Tue Jul 21 08:40:49.474824 2026] [security2:error] [pid 465652:tid 465804] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9awTzTqJoBC2Mw28_l3AAAAJs"]
[Tue Jul 21 08:40:49.488605 2026] [security2:error] [pid 465652:tid 465894] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9awTzTqJoBC2Mw28_l3QAAAPU"]
[Tue Jul 21 08:40:49.501118 2026] [security2:error] [pid 465652:tid 465854] [client 20.220.225.223:12569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/zzz.php"] [unique_id "al9awTzTqJoBC2Mw28_l3wAAAM0"]
[Tue Jul 21 08:40:49.501136 2026] [security2:error] [pid 465652:tid 465909] [client 20.197.192.193:43801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/echkm.php"] [unique_id "al9awTzTqJoBC2Mw28_l3gAAAQQ"]
[Tue Jul 21 08:40:49.583382 2026] [proxy:error] [pid 465652:tid 465780] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:49.583434 2026] [proxy_http:error] [pid 465652:tid 465780] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:49.584019 2026] [proxy:error] [pid 465652:tid 465780] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:49.584056 2026] [proxy_http:error] [pid 465652:tid 465780] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:49.625614 2026] [security2:error] [pid 465652:tid 465889] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9awTzTqJoBC2Mw28_l6AAAAPA"]
[Tue Jul 21 08:40:49.723228 2026] [security2:error] [pid 465652:tid 465824] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9awTzTqJoBC2Mw28_l7gAAAK8"]
[Tue Jul 21 08:40:49.746227 2026] [security2:error] [pid 465652:tid 465742] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9awTzTqJoBC2Mw28_l7wAAjlk"]
[Tue Jul 21 08:40:49.746519 2026] [security2:error] [pid 465652:tid 465904] [client 74.7.228.9:42578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arielson.com.br"] [uri "/index.php"] [unique_id "al9awTzTqJoBC2Mw28_l0gAA_zE"]
[Tue Jul 21 08:40:49.804599 2026] [security2:error] [pid 465652:tid 465878] [client 20.226.60.151:58617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/loader.php"] [unique_id "al9awTzTqJoBC2Mw28_l8AAAAOU"]
[Tue Jul 21 08:40:49.838391 2026] [security2:error] [pid 465652:tid 465844] [client 122.176.100.127:61186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9awTzTqJoBC2Mw28_l8QAAAMM"]
[Tue Jul 21 08:40:49.838541 2026] [security2:error] [pid 465652:tid 465844] [client 122.176.100.127:61186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9awTzTqJoBC2Mw28_l8QAAAMM"]
[Tue Jul 21 08:40:49.862367 2026] [security2:error] [pid 465652:tid 465794] [client 20.206.105.145:45987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/yup.php"] [unique_id "al9awTzTqJoBC2Mw28_l8gAAAJE"]
[Tue Jul 21 08:40:49.890120 2026] [security2:error] [pid 465652:tid 465692] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/8.php"] [unique_id "al9awTzTqJoBC2Mw28_l8wAAzic"]
[Tue Jul 21 08:40:49.896430 2026] [security2:error] [pid 465652:tid 465828] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9awTzTqJoBC2Mw28_l9AAAALM"]
[Tue Jul 21 08:40:49.896430 2026] [security2:error] [pid 465652:tid 465862] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9awTzTqJoBC2Mw28_l9QAAANU"]
[Tue Jul 21 08:40:49.897390 2026] [security2:error] [pid 465652:tid 465848] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9awTzTqJoBC2Mw28_l9gAAAMc"]
[Tue Jul 21 08:40:49.901317 2026] [security2:error] [pid 465652:tid 465784] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9awTzTqJoBC2Mw28_l-AAAAIc"]
[Tue Jul 21 08:40:49.901590 2026] [security2:error] [pid 465652:tid 465821] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9awTzTqJoBC2Mw28_l9wAAAKw"]
[Tue Jul 21 08:40:49.904510 2026] [security2:error] [pid 465652:tid 465782] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9awTzTqJoBC2Mw28_l-QAAAIU"]
[Tue Jul 21 08:40:49.999709 2026] [security2:error] [pid 465652:tid 465863] [client 20.206.105.145:33694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/hur.php"] [unique_id "al9awTzTqJoBC2Mw28_l-gAAANY"]
[Tue Jul 21 08:40:50.007559 2026] [security2:error] [pid 465652:tid 465785] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9awjzTqJoBC2Mw28_l_AAAAIg"]
[Tue Jul 21 08:40:50.011776 2026] [security2:error] [pid 465652:tid 465845] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9awjzTqJoBC2Mw28_l_QAAAMQ"]
[Tue Jul 21 08:40:50.034062 2026] [security2:error] [pid 465652:tid 465841] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9awjzTqJoBC2Mw28_l_gAAAMA"]
[Tue Jul 21 08:40:50.034843 2026] [security2:error] [pid 465652:tid 465673] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9awjzTqJoBC2Mw28_l_wAAyRQ"]
[Tue Jul 21 08:40:50.215384 2026] [security2:error] [pid 465652:tid 465680] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/f6.php"] [unique_id "al9awjzTqJoBC2Mw28_mCAAAuhs"]
[Tue Jul 21 08:40:50.287165 2026] [security2:error] [pid 465652:tid 465790] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9awjzTqJoBC2Mw28_mCwAAAI0"]
[Tue Jul 21 08:40:50.290068 2026] [security2:error] [pid 465652:tid 465896] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9awjzTqJoBC2Mw28_mDAAAAPc"]
[Tue Jul 21 08:40:50.291206 2026] [security2:error] [pid 465652:tid 465795] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9awjzTqJoBC2Mw28_mDQAAAJI"]
[Tue Jul 21 08:40:50.291456 2026] [security2:error] [pid 465652:tid 465875] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9awjzTqJoBC2Mw28_mDgAAAOI"]
[Tue Jul 21 08:40:50.292476 2026] [security2:error] [pid 465652:tid 465783] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9awjzTqJoBC2Mw28_mDwAAAIY"]
[Tue Jul 21 08:40:50.292548 2026] [security2:error] [pid 465652:tid 465871] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9awjzTqJoBC2Mw28_mEAAAAN4"]
[Tue Jul 21 08:40:50.293082 2026] [security2:error] [pid 465652:tid 465871] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9awjzTqJoBC2Mw28_mEQAAAN4"]
[Tue Jul 21 08:40:50.375850 2026] [security2:error] [pid 465652:tid 465753] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/inputs.php"] [unique_id "al9awjzTqJoBC2Mw28_mFAAAqWQ"]
[Tue Jul 21 08:40:50.464830 2026] [security2:error] [pid 465652:tid 465909] [client 203.25.124.212:31835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/hello-plus/classes/ehp-sarang.php"] [unique_id "al9awjzTqJoBC2Mw28_mFQAAAQQ"]
[Tue Jul 21 08:40:50.472490 2026] [security2:error] [pid 465652:tid 465788] [client 184.154.76.20:55402] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "nrfilmes.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "al9awjzTqJoBC2Mw28_mFgAAAIs"]
[Tue Jul 21 08:40:50.472606 2026] [security2:error] [pid 465652:tid 465788] [client 184.154.76.20:55402] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "nrfilmes.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "al9awjzTqJoBC2Mw28_mFgAAAIs"]
[Tue Jul 21 08:40:50.478192 2026] [security2:error] [pid 465652:tid 465903] [client 20.220.225.223:52614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/inso.php"] [unique_id "al9awjzTqJoBC2Mw28_mFwAAAP4"]
[Tue Jul 21 08:40:50.499122 2026] [security2:error] [pid 465652:tid 465808] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/index.php"] [unique_id "al9awjzTqJoBC2Mw28_mGAAAAJ8"]
[Tue Jul 21 08:40:50.516663 2026] [security2:error] [pid 465652:tid 465831] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9awjzTqJoBC2Mw28_mGgAAALY"]
[Tue Jul 21 08:40:50.518111 2026] [security2:error] [pid 465652:tid 465695] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/inputs.php"] [unique_id "al9awjzTqJoBC2Mw28_mGwAA9io"]
[Tue Jul 21 08:40:50.531022 2026] [security2:error] [pid 465652:tid 465864] [client 5.38.115.39:19782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9awjzTqJoBC2Mw28_mHQAAANc"]
[Tue Jul 21 08:40:50.531166 2026] [security2:error] [pid 465652:tid 465864] [client 5.38.115.39:19782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9awjzTqJoBC2Mw28_mHQAAANc"]
[Tue Jul 21 08:40:50.577064 2026] [security2:error] [pid 465652:tid 465802] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9awjzTqJoBC2Mw28_mHgAAAJk"]
[Tue Jul 21 08:40:50.662540 2026] [security2:error] [pid 465652:tid 465658] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/classwithtostring.php"] [unique_id "al9awjzTqJoBC2Mw28_mIwAA0QU"]
[Tue Jul 21 08:40:50.679970 2026] [security2:error] [pid 465652:tid 465846] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9awjzTqJoBC2Mw28_mJQAAAMU"]
[Tue Jul 21 08:40:50.681735 2026] [security2:error] [pid 465652:tid 465857] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9awjzTqJoBC2Mw28_mJgAAANA"]
[Tue Jul 21 08:40:50.682959 2026] [security2:error] [pid 465652:tid 465853] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9awjzTqJoBC2Mw28_mKAAAAMw"]
[Tue Jul 21 08:40:50.685410 2026] [security2:error] [pid 465652:tid 465890] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9awjzTqJoBC2Mw28_mKQAAAPE"]
[Tue Jul 21 08:40:50.687701 2026] [security2:error] [pid 465652:tid 465866] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9awjzTqJoBC2Mw28_mKgAAANk"]
[Tue Jul 21 08:40:50.690820 2026] [security2:error] [pid 465652:tid 465876] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9awjzTqJoBC2Mw28_mKwAAAOM"]
[Tue Jul 21 08:40:50.749108 2026] [security2:error] [pid 465652:tid 465904] [client 20.226.60.151:58611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/spadex.php"] [unique_id "al9awjzTqJoBC2Mw28_mLgAAAP8"]
[Tue Jul 21 08:40:50.808591 2026] [security2:error] [pid 465652:tid 465697] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9awjzTqJoBC2Mw28_mMAAA_Cw"]
[Tue Jul 21 08:40:50.862149 2026] [security2:error] [pid 465652:tid 465884] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9awjzTqJoBC2Mw28_mMQAAAOs"]
[Tue Jul 21 08:40:50.930206 2026] [security2:error] [pid 465652:tid 465782] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9awjzTqJoBC2Mw28_mMgAAAIU"]
[Tue Jul 21 08:40:50.957842 2026] [security2:error] [pid 465652:tid 465869] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/ioxi-o.php"] [unique_id "al9awjzTqJoBC2Mw28_mMwAAANw"]
[Tue Jul 21 08:40:50.960417 2026] [security2:error] [pid 465652:tid 465657] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wp-blog.php"] [unique_id "al9awjzTqJoBC2Mw28_mNAAA2gQ"]
[Tue Jul 21 08:40:51.048612 2026] [security2:error] [pid 465652:tid 465796] [client 184.154.76.20:55412] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "nrfilmes.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al9awzzTqJoBC2Mw28_mNgAAAJM"]
[Tue Jul 21 08:40:51.048770 2026] [security2:error] [pid 465652:tid 465796] [client 184.154.76.20:55412] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "nrfilmes.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al9awzzTqJoBC2Mw28_mNgAAAJM"]
[Tue Jul 21 08:40:51.108645 2026] [proxy:error] [pid 465652:tid 465737] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:51.108727 2026] [proxy_http:error] [pid 465652:tid 465737] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:51.109748 2026] [proxy:error] [pid 465652:tid 465737] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:51.109790 2026] [proxy_http:error] [pid 465652:tid 465737] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:51.113484 2026] [security2:error] [pid 465652:tid 465841] [client 20.220.225.223:56202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wpx.php"] [unique_id "al9awzzTqJoBC2Mw28_mOAAAAMA"]
[Tue Jul 21 08:40:51.134085 2026] [security2:error] [pid 465652:tid 465893] [client 20.206.105.145:45373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/wpxml.php"] [unique_id "al9awzzTqJoBC2Mw28_mOQAAAPQ"]
[Tue Jul 21 08:40:51.147026 2026] [security2:error] [pid 465652:tid 465814] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9awzzTqJoBC2Mw28_mOgAAAKU"]
[Tue Jul 21 08:40:51.179166 2026] [security2:error] [pid 465652:tid 465859] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9awzzTqJoBC2Mw28_mPQAAANI"]
[Tue Jul 21 08:40:51.180418 2026] [security2:error] [pid 465652:tid 465881] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9awzzTqJoBC2Mw28_mPwAAAOg"]
[Tue Jul 21 08:40:51.180517 2026] [security2:error] [pid 465652:tid 465852] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9awzzTqJoBC2Mw28_mPgAAAMs"]
[Tue Jul 21 08:40:51.180834 2026] [security2:error] [pid 465652:tid 465803] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9awzzTqJoBC2Mw28_mQAAAAJo"]
[Tue Jul 21 08:40:51.183616 2026] [security2:error] [pid 465652:tid 465880] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9awzzTqJoBC2Mw28_mQgAAAOc"]
[Tue Jul 21 08:40:51.248474 2026] [security2:error] [pid 465652:tid 465883] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9awzzTqJoBC2Mw28_mRgAAAOo"]
[Tue Jul 21 08:40:51.277740 2026] [security2:error] [pid 465652:tid 465727] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9awzzTqJoBC2Mw28_mSQAAvko"]
[Tue Jul 21 08:40:51.342374 2026] [security2:error] [pid 465652:tid 465875] [client 20.206.105.145:33724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/zoro.php"] [unique_id "al9awzzTqJoBC2Mw28_mSgAAAOI"]
[Tue Jul 21 08:40:51.367690 2026] [security2:error] [pid 465652:tid 465809] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/insc.php"] [unique_id "al9awzzTqJoBC2Mw28_mSwAAAKA"]
[Tue Jul 21 08:40:51.424896 2026] [security2:error] [pid 465652:tid 465806] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9awzzTqJoBC2Mw28_mTgAAAJ0"]
[Tue Jul 21 08:40:51.432288 2026] [security2:error] [pid 465652:tid 465788] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9awzzTqJoBC2Mw28_mTwAAAIs"]
[Tue Jul 21 08:40:51.434398 2026] [security2:error] [pid 465652:tid 465663] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/ms-edit.php"] [unique_id "al9awzzTqJoBC2Mw28_mUAAAtwo"]
[Tue Jul 21 08:40:51.537968 2026] [security2:error] [pid 465652:tid 465831] [client 20.206.105.145:45890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/fffm.php"] [unique_id "al9awzzTqJoBC2Mw28_mUgAAALY"]
[Tue Jul 21 08:40:51.564294 2026] [security2:error] [pid 465652:tid 465889] [client 203.25.124.61:30089] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwentyone/content-index.php"] [unique_id "al9awzzTqJoBC2Mw28_mUwAAAPA"]
[Tue Jul 21 08:40:51.577683 2026] [security2:error] [pid 465652:tid 465661] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9awzzTqJoBC2Mw28_mVAAA-Ag"]
[Tue Jul 21 08:40:51.617567 2026] [security2:error] [pid 465652:tid 465795] [client 184.154.76.20:55418] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "nrfilmes.com"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "al9awzzTqJoBC2Mw28_mVQAAAJI"]
[Tue Jul 21 08:40:51.617705 2026] [security2:error] [pid 465652:tid 465795] [client 184.154.76.20:55418] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "nrfilmes.com"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "al9awzzTqJoBC2Mw28_mVQAAAJI"]
[Tue Jul 21 08:40:51.629261 2026] [security2:error] [pid 465652:tid 465686] [remote 20.153.140.50:48440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nocaminhodafe.com.br"] [uri "/wp-login.php"] [unique_id "al9awzzTqJoBC2Mw28_mVgAAxCE"]
[Tue Jul 21 08:40:51.643002 2026] [security2:error] [pid 465652:tid 465853] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9awzzTqJoBC2Mw28_mVwAAAMw"]
[Tue Jul 21 08:40:51.644608 2026] [security2:error] [pid 465652:tid 465890] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9awzzTqJoBC2Mw28_mWAAAAPE"]
[Tue Jul 21 08:40:51.644646 2026] [security2:error] [pid 465652:tid 465866] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9awzzTqJoBC2Mw28_mWQAAANk"]
[Tue Jul 21 08:40:51.652727 2026] [security2:error] [pid 465652:tid 465838] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9awzzTqJoBC2Mw28_mWgAAAL0"]
[Tue Jul 21 08:40:51.679351 2026] [security2:error] [pid 465652:tid 465837] [client 20.220.225.223:63335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/berlin.php"] [unique_id "al9awzzTqJoBC2Mw28_mWwAAALw"]
[Tue Jul 21 08:40:51.716149 2026] [security2:error] [pid 465652:tid 465807] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9awzzTqJoBC2Mw28_mXgAAAJ4"]
[Tue Jul 21 08:40:51.716285 2026] [security2:error] [pid 465652:tid 465690] [remote 103.187.169.251:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9awzzTqJoBC2Mw28_mXQAAqyU"]
[Tue Jul 21 08:40:51.735007 2026] [proxy:error] [pid 465652:tid 465696] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:51.735080 2026] [proxy_http:error] [pid 465652:tid 465696] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:51.735516 2026] [proxy:error] [pid 465652:tid 465696] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:51.735551 2026] [proxy_http:error] [pid 465652:tid 465696] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:51.743835 2026] [security2:error] [pid 465652:tid 465876] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9awzzTqJoBC2Mw28_mYgAAAOM"]
[Tue Jul 21 08:40:51.774357 2026] [security2:error] [pid 465652:tid 465901] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9awzzTqJoBC2Mw28_mZgAAAPw"]
[Tue Jul 21 08:40:51.846519 2026] [security2:error] [pid 465652:tid 465863] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/classwithtostring.php"] [unique_id "al9awzzTqJoBC2Mw28_mbQAAANY"]
[Tue Jul 21 08:40:51.862537 2026] [security2:error] [pid 465652:tid 465785] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9awzzTqJoBC2Mw28_mbgAAAIg"]
[Tue Jul 21 08:40:51.891387 2026] [security2:error] [pid 465652:tid 465707] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9awzzTqJoBC2Mw28_mbwAAkzY"]
[Tue Jul 21 08:40:51.913762 2026] [security2:error] [pid 465652:tid 465798] [client 223.181.60.88:2311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9awzzTqJoBC2Mw28_mcAAAAJU"]
[Tue Jul 21 08:40:51.913969 2026] [security2:error] [pid 465652:tid 465798] [client 223.181.60.88:2311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9awzzTqJoBC2Mw28_mcAAAAJU"]
[Tue Jul 21 08:40:51.926738 2026] [security2:error] [pid 465652:tid 465850] [client 20.197.192.193:65193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/mac.php"] [unique_id "al9awzzTqJoBC2Mw28_mcQAAAMk"]
[Tue Jul 21 08:40:52.022389 2026] [security2:error] [pid 465652:tid 465859] [client 20.220.225.223:12317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/wicked.php"] [unique_id "al9axDzTqJoBC2Mw28_mcwAAANI"]
[Tue Jul 21 08:40:52.025159 2026] [security2:error] [pid 465652:tid 465881] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9axDzTqJoBC2Mw28_mdAAAAOg"]
[Tue Jul 21 08:40:52.035732 2026] [proxy:error] [pid 465652:tid 465667] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:52.035798 2026] [proxy_http:error] [pid 465652:tid 465667] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:52.036451 2026] [proxy:error] [pid 465652:tid 465667] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:52.036481 2026] [proxy_http:error] [pid 465652:tid 465667] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:52.151073 2026] [security2:error] [pid 465652:tid 465822] [client 202.179.75.202:33882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9axDzTqJoBC2Mw28_megAAAK0"]
[Tue Jul 21 08:40:52.151186 2026] [security2:error] [pid 465652:tid 465822] [client 202.179.75.202:33882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9axDzTqJoBC2Mw28_megAAAK0"]
[Tue Jul 21 08:40:52.175098 2026] [security2:error] [pid 465652:tid 465825] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9axDzTqJoBC2Mw28_mewAAALA"]
[Tue Jul 21 08:40:52.176237 2026] [security2:error] [pid 465652:tid 465851] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9axDzTqJoBC2Mw28_mfAAAAMo"]
[Tue Jul 21 08:40:52.178921 2026] [security2:error] [pid 465652:tid 465874] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9axDzTqJoBC2Mw28_mfQAAAOE"]
[Tue Jul 21 08:40:52.179725 2026] [security2:error] [pid 465652:tid 465883] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9axDzTqJoBC2Mw28_mfwAAAOo"]
[Tue Jul 21 08:40:52.179783 2026] [security2:error] [pid 465652:tid 465839] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9axDzTqJoBC2Mw28_mgAAAAL4"]
[Tue Jul 21 08:40:52.180946 2026] [proxy:error] [pid 465652:tid 465731] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:52.181019 2026] [proxy_http:error] [pid 465652:tid 465731] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:52.181953 2026] [proxy:error] [pid 465652:tid 465731] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:52.181999 2026] [proxy_http:error] [pid 465652:tid 465731] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:52.203627 2026] [security2:error] [pid 465652:tid 465792] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9axDzTqJoBC2Mw28_mggAAAI8"]
[Tue Jul 21 08:40:52.271674 2026] [security2:error] [pid 465652:tid 465887] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/txets.php"] [unique_id "al9axDzTqJoBC2Mw28_mhgAAAO4"]
[Tue Jul 21 08:40:52.287426 2026] [security2:error] [pid 465652:tid 465818] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9axDzTqJoBC2Mw28_miQAAAKk"]
[Tue Jul 21 08:40:52.309625 2026] [security2:error] [pid 465652:tid 465809] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.brunamariacontelzagu1782829060204.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9axDzTqJoBC2Mw28_mjAAAAKA"]
[Tue Jul 21 08:40:52.325553 2026] [security2:error] [pid 465652:tid 465687] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/abcd.php"] [unique_id "al9axDzTqJoBC2Mw28_mjgAA5iI"]
[Tue Jul 21 08:40:52.380501 2026] [security2:error] [pid 465652:tid 465895] [client 20.206.105.145:45335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/gecko.php"] [unique_id "al9axDzTqJoBC2Mw28_mjwAAAPY"]
[Tue Jul 21 08:40:52.469072 2026] [security2:error] [pid 465652:tid 465762] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/file15.php"] [unique_id "al9axDzTqJoBC2Mw28_mkgAA0W0"]
[Tue Jul 21 08:40:52.472457 2026] [security2:error] [pid 465652:tid 465795] [client 212.32.76.5:24031] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/admin.php"] [unique_id "al9axDzTqJoBC2Mw28_mkwAAAJI"]
[Tue Jul 21 08:40:52.475946 2026] [security2:error] [pid 465652:tid 465892] [client 184.154.76.20:55422] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nrfilmes.com"] [uri "/wp-content/plugins/elementor-pro/changelog.txt"] [unique_id "al9axDzTqJoBC2Mw28_mgQAAAPM"]
[Tue Jul 21 08:40:52.645170 2026] [security2:error] [pid 465652:tid 465755] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/jp.php"] [unique_id "al9axDzTqJoBC2Mw28_mlwAAv2Y"]
[Tue Jul 21 08:40:52.675386 2026] [security2:error] [pid 465652:tid 465829] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9axDzTqJoBC2Mw28_mmAAAALQ"]
[Tue Jul 21 08:40:52.676533 2026] [security2:error] [pid 465652:tid 465824] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9axDzTqJoBC2Mw28_mmQAAAK8"]
[Tue Jul 21 08:40:52.686084 2026] [security2:error] [pid 465652:tid 465797] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9axDzTqJoBC2Mw28_mmgAAAJQ"]
[Tue Jul 21 08:40:52.689205 2026] [security2:error] [pid 465652:tid 465826] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9axDzTqJoBC2Mw28_mmwAAALE"]
[Tue Jul 21 08:40:52.695583 2026] [security2:error] [pid 465652:tid 465789] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9axDzTqJoBC2Mw28_mnAAAAIw"]
[Tue Jul 21 08:40:52.701850 2026] [security2:error] [pid 465652:tid 465860] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9axDzTqJoBC2Mw28_mnQAAANM"]
[Tue Jul 21 08:40:52.739215 2026] [security2:error] [pid 465652:tid 465909] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-content/themes/txets.php"] [unique_id "al9axDzTqJoBC2Mw28_mnwAAAQQ"]
[Tue Jul 21 08:40:52.744082 2026] [security2:error] [pid 465652:tid 465884] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9axDzTqJoBC2Mw28_moQAAAOs"]
[Tue Jul 21 08:40:52.794153 2026] [security2:error] [pid 465652:tid 465752] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/f35.php"] [unique_id "al9axDzTqJoBC2Mw28_mpgAAh2M"]
[Tue Jul 21 08:40:52.937363 2026] [security2:error] [pid 465652:tid 465672] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wp-load.php"] [unique_id "al9axDzTqJoBC2Mw28_mrAAAyxM"]
[Tue Jul 21 08:40:52.945204 2026] [security2:error] [pid 465652:tid 465880] [client 20.226.60.151:58597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/2x.php"] [unique_id "al9axDzTqJoBC2Mw28_mrQAAAOc"]
[Tue Jul 21 08:40:53.055969 2026] [security2:error] [pid 465652:tid 465825] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9axTzTqJoBC2Mw28_msAAAALA"]
[Tue Jul 21 08:40:53.057172 2026] [security2:error] [pid 465652:tid 465851] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9axTzTqJoBC2Mw28_msQAAAMo"]
[Tue Jul 21 08:40:53.066005 2026] [security2:error] [pid 465652:tid 465877] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpanel.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9axTzTqJoBC2Mw28_msgAAAOQ"]
[Tue Jul 21 08:40:53.068562 2026] [security2:error] [pid 465652:tid 465874] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9axTzTqJoBC2Mw28_mswAAAOE"]
[Tue Jul 21 08:40:53.079976 2026] [security2:error] [pid 465652:tid 465725] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/xyn.php"] [unique_id "al9axTzTqJoBC2Mw28_mtAAA6kg"]
[Tue Jul 21 08:40:53.101027 2026] [security2:error] [pid 465652:tid 465839] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9axTzTqJoBC2Mw28_mtQAAAL4"]
[Tue Jul 21 08:40:53.104859 2026] [security2:error] [pid 465652:tid 465799] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9axTzTqJoBC2Mw28_mtgAAAJY"]
[Tue Jul 21 08:40:53.190631 2026] [security2:error] [pid 465652:tid 465906] [client 184.154.76.20:55426] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nrfilmes.com"] [uri "/wp-content/plugins/woo-variation-swatches/README.txt"] [unique_id "al9axTzTqJoBC2Mw28_mtwAAAQE"]
[Tue Jul 21 08:40:53.203615 2026] [security2:error] [pid 465652:tid 465900] [client 20.206.105.145:45976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/a1.php"] [unique_id "al9axTzTqJoBC2Mw28_muQAAAPs"]
[Tue Jul 21 08:40:53.205874 2026] [security2:error] [pid 465652:tid 465811] [client 185.192.71.10:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webdisk.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9axTzTqJoBC2Mw28_mugAAAKI"]
[Tue Jul 21 08:40:53.224206 2026] [proxy:error] [pid 465652:tid 465743] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:53.224265 2026] [proxy_http:error] [pid 465652:tid 465743] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:53.224805 2026] [proxy:error] [pid 465652:tid 465743] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:53.224840 2026] [proxy_http:error] [pid 465652:tid 465743] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:53.253633 2026] [security2:error] [pid 465652:tid 465788] [client 20.220.225.223:46972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/billur.php"] [unique_id "al9axTzTqJoBC2Mw28_mvgAAAIs"]
[Tue Jul 21 08:40:53.338319 2026] [security2:error] [pid 465652:tid 465831] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-admin/txets.php"] [unique_id "al9axTzTqJoBC2Mw28_mwgAAALY"]
[Tue Jul 21 08:40:53.380352 2026] [proxy:error] [pid 465652:tid 465750] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:53.380422 2026] [proxy_http:error] [pid 465652:tid 465750] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:53.381038 2026] [proxy:error] [pid 465652:tid 465750] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:40:53.381081 2026] [proxy_http:error] [pid 465652:tid 465750] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:40:53.385033 2026] [security2:error] [pid 465652:tid 465881] [client 195.49.128.211:52618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9axTzTqJoBC2Mw28_myAAAAOg"]
[Tue Jul 21 08:40:53.385155 2026] [security2:error] [pid 465652:tid 465881] [client 195.49.128.211:52618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9axTzTqJoBC2Mw28_myAAAAOg"]
[Tue Jul 21 08:40:53.440326 2026] [security2:error] [pid 465652:tid 465892] [client 91.230.225.191:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "autodiscover.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9axTzTqJoBC2Mw28_mzAAAAPM"]
[Tue Jul 21 08:40:53.444434 2026] [security2:error] [pid 465652:tid 465834] [client 91.230.225.4:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "webmail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9axTzTqJoBC2Mw28_mzQAAALk"]
[Tue Jul 21 08:40:53.460678 2026] [security2:error] [pid 465652:tid 465857] [client 91.230.225.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcontacts.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9axTzTqJoBC2Mw28_mzgAAANA"]
[Tue Jul 21 08:40:53.467256 2026] [security2:error] [pid 465652:tid 465845] [client 20.197.192.193:65199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/samll.php"] [unique_id "al9axTzTqJoBC2Mw28_mzwAAAMQ"]
[Tue Jul 21 08:40:53.495512 2026] [security2:error] [pid 465652:tid 465866] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9axTzTqJoBC2Mw28_m0AAAANk"]
[Tue Jul 21 08:40:53.504703 2026] [security2:error] [pid 465652:tid 465807] [client 91.230.225.182:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9axTzTqJoBC2Mw28_m0QAAAJ4"]
[Tue Jul 21 08:40:53.506442 2026] [security2:error] [pid 465652:tid 465837] [client 141.11.107.74:52046] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "reserveseulugar.com.br"] [uri "/"] [unique_id "al9axTzTqJoBC2Mw28_m0gAAALw"]
[Tue Jul 21 08:40:53.524882 2026] [security2:error] [pid 465652:tid 465787] [client 14.245.224.124:63302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9axTzTqJoBC2Mw28_m0wAAAIo"]
[Tue Jul 21 08:40:53.525342 2026] [security2:error] [pid 465652:tid 465787] [client 14.245.224.124:63302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9axTzTqJoBC2Mw28_m0wAAAIo"]
[Tue Jul 21 08:40:53.555885 2026] [security2:error] [pid 465652:tid 465840] [client 20.206.105.145:33561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/coffexium.php"] [unique_id "al9axTzTqJoBC2Mw28_m1AAAAL8"]
[Tue Jul 21 08:40:53.569006 2026] [security2:error] [pid 465652:tid 465676] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/ccc.php"] [unique_id "al9axTzTqJoBC2Mw28_m1QAArxc"]
[Tue Jul 21 08:40:53.713582 2026] [security2:error] [pid 465652:tid 465694] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/w.php"] [unique_id "al9axTzTqJoBC2Mw28_m1wAArik"]
[Tue Jul 21 08:40:53.734250 2026] [security2:error] [pid 465652:tid 465844] [client 20.226.60.151:58603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/ctex1.php"] [unique_id "al9axTzTqJoBC2Mw28_m2AAAAMM"]
[Tue Jul 21 08:40:53.768913 2026] [security2:error] [pid 465652:tid 465784] [client 203.25.124.64:39851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/404.php"] [unique_id "al9axTzTqJoBC2Mw28_m3AAAAIc"]
[Tue Jul 21 08:40:53.822863 2026] [security2:error] [pid 465652:tid 465835] [client 103.59.206.240:31023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9axTzTqJoBC2Mw28_m3QAAALo"]
[Tue Jul 21 08:40:53.822991 2026] [security2:error] [pid 465652:tid 465835] [client 103.59.206.240:31023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9axTzTqJoBC2Mw28_m3QAAALo"]
[Tue Jul 21 08:40:53.862785 2026] [security2:error] [pid 465652:tid 465668] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9axTzTqJoBC2Mw28_m3wAA6Q8"]
[Tue Jul 21 08:40:53.910167 2026] [security2:error] [pid 465652:tid 465893] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9axTzTqJoBC2Mw28_m5QAAAPQ"]
[Tue Jul 21 08:40:53.911288 2026] [security2:error] [pid 465652:tid 465859] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-includes/txets.php"] [unique_id "al9axTzTqJoBC2Mw28_m5gAAANI"]
[Tue Jul 21 08:40:53.946586 2026] [security2:error] [pid 465652:tid 465884] [client 184.154.76.20:55436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "nrfilmes.com"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "al9axTzTqJoBC2Mw28_m5wAAAOs"]
[Tue Jul 21 08:40:53.946745 2026] [security2:error] [pid 465652:tid 465884] [client 184.154.76.20:55436] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "nrfilmes.com"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "al9axTzTqJoBC2Mw28_m5wAAAOs"]
[Tue Jul 21 08:40:54.006485 2026] [security2:error] [pid 465652:tid 465674] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/FWAZ.php"] [unique_id "al9axjzTqJoBC2Mw28_m6QAAqhU"]
[Tue Jul 21 08:40:54.032855 2026] [core:error] [pid 465652:tid 465736] [remote 40.77.167.24:64571] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:40:54.032878 2026] [core:error] [pid 465652:tid 465736] [remote 40.77.167.24:64571] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:40:54.046002 2026] [security2:error] [pid 465652:tid 465841] [client 173.252.95.61:53662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9axjzTqJoBC2Mw28_m6wAAAMA"]
[Tue Jul 21 08:40:54.148846 2026] [security2:error] [pid 465652:tid 465705] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/miru1.php"] [unique_id "al9axjzTqJoBC2Mw28_m8wAAljQ"]
[Tue Jul 21 08:40:54.164890 2026] [security2:error] [pid 465652:tid 465900] [client 20.206.105.145:45355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/k2.php"] [unique_id "al9axjzTqJoBC2Mw28_m9AAAAPs"]
[Tue Jul 21 08:40:54.291187 2026] [security2:error] [pid 465652:tid 465703] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/aa.php"] [unique_id "al9axjzTqJoBC2Mw28_m-QAA9TI"]
[Tue Jul 21 08:40:54.297399 2026] [security2:error] [pid 465652:tid 465814] [client 91.230.225.9:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9axjzTqJoBC2Mw28_m-wAAAKU"]
[Tue Jul 21 08:40:54.397349 2026] [security2:error] [pid 465652:tid 465843] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/goods.php"] [unique_id "al9axjzTqJoBC2Mw28_nBAAAAMI"]
[Tue Jul 21 08:40:54.435701 2026] [security2:error] [pid 465652:tid 465712] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/122.php"] [unique_id "al9axjzTqJoBC2Mw28_nCwAA3Ts"]
[Tue Jul 21 08:40:54.458610 2026] [security2:error] [pid 465652:tid 465883] [client 173.252.95.11:63342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9axjzTqJoBC2Mw28_m-gAAAOo"]
[Tue Jul 21 08:40:54.517912 2026] [security2:error] [pid 465652:tid 465804] [client 184.154.76.20:55442] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "nrfilmes.com"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "al9axjzTqJoBC2Mw28_nDgAAAJs"]
[Tue Jul 21 08:40:54.518079 2026] [security2:error] [pid 465652:tid 465804] [client 184.154.76.20:55442] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "nrfilmes.com"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "al9axjzTqJoBC2Mw28_nDgAAAJs"]
[Tue Jul 21 08:40:54.530903 2026] [authz_core:error] [pid 465652:tid 465808] [client 74.249.245.134:0] AH01630: client denied by server configuration: /home3/bilili18/cartoriodecurupira.com.br/php.ini
[Tue Jul 21 08:40:54.578906 2026] [security2:error] [pid 465652:tid 465774] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/get.php"] [unique_id "al9axjzTqJoBC2Mw28_nEwAAjHk"]
[Tue Jul 21 08:40:54.678959 2026] [security2:error] [pid 465652:tid 465823] [client 74.249.245.134:42338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/settings.php"] [unique_id "al9axjzTqJoBC2Mw28_nFwAAAK4"]
[Tue Jul 21 08:40:54.722026 2026] [security2:error] [pid 465652:tid 465745] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/as.php"] [unique_id "al9axjzTqJoBC2Mw28_nGQAAzFw"]
[Tue Jul 21 08:40:54.861535 2026] [security2:error] [pid 465652:tid 465899] [client 203.25.124.73:28185] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/file.php"] [unique_id "al9axjzTqJoBC2Mw28_nHgAAAPo"]
[Tue Jul 21 08:40:54.868346 2026] [security2:error] [pid 465652:tid 465709] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/ccou.php"] [unique_id "al9axjzTqJoBC2Mw28_nIAAA3Dg"]
[Tue Jul 21 08:40:54.906960 2026] [security2:error] [pid 465652:tid 465905] [client 152.59.181.104:62180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9axjzTqJoBC2Mw28_nIwAAAQA"]
[Tue Jul 21 08:40:54.907089 2026] [security2:error] [pid 465652:tid 465905] [client 152.59.181.104:62180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9axjzTqJoBC2Mw28_nIwAAAQA"]
[Tue Jul 21 08:40:54.909261 2026] [security2:error] [pid 465652:tid 465859] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/wp-editor.php"] [unique_id "al9axjzTqJoBC2Mw28_nJAAAANI"]
[Tue Jul 21 08:40:55.012651 2026] [security2:error] [pid 465652:tid 465666] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/w3lls.php"] [unique_id "al9axzzTqJoBC2Mw28_nKQAAkQ0"]
[Tue Jul 21 08:40:55.046357 2026] [security2:error] [pid 465652:tid 465838] [client 20.197.192.193:65178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/abcd.php"] [unique_id "al9axzzTqJoBC2Mw28_nLQAAAL0"]
[Tue Jul 21 08:40:55.110719 2026] [security2:error] [pid 465652:tid 465878] [client 184.154.76.20:55456] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nrfilmes.com"] [uri "/readme.html"] [unique_id "al9axzzTqJoBC2Mw28_nLwAAAOU"]
[Tue Jul 21 08:40:55.117703 2026] [security2:error] [pid 465652:tid 465896] [client 20.206.105.145:33748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/app.php"] [unique_id "al9axzzTqJoBC2Mw28_nMAAAAPc"]
[Tue Jul 21 08:40:55.156800 2026] [security2:error] [pid 465652:tid 465669] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/test1.php"] [unique_id "al9axzzTqJoBC2Mw28_nMQAAtxA"]
[Tue Jul 21 08:40:55.184481 2026] [security2:error] [pid 465652:tid 465780] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9axzzTqJoBC2Mw28_nMwAAy38"]
[Tue Jul 21 08:40:55.184678 2026] [security2:error] [pid 465652:tid 465852] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9axzzTqJoBC2Mw28_nMwAAy38"]
[Tue Jul 21 08:40:55.221186 2026] [security2:error] [pid 465652:tid 465907] [client 20.226.60.151:34838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/edorxrr.php"] [unique_id "al9axzzTqJoBC2Mw28_nNAAAAQI"]
[Tue Jul 21 08:40:55.299982 2026] [security2:error] [pid 465652:tid 465760] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/database.php"] [unique_id "al9axzzTqJoBC2Mw28_nNgAA1ms"]
[Tue Jul 21 08:40:55.305657 2026] [security2:error] [pid 465652:tid 465818] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/lufix.php"] [unique_id "al9axzzTqJoBC2Mw28_nNwAAAKk"]
[Tue Jul 21 08:40:55.443937 2026] [security2:error] [pid 465652:tid 465698] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/file.php"] [unique_id "al9axzzTqJoBC2Mw28_nPwAAni0"]
[Tue Jul 21 08:40:55.450649 2026] [core:error] [pid 465652:tid 465742] [remote 40.77.167.74:58578] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:40:55.450678 2026] [core:error] [pid 465652:tid 465742] [remote 40.77.167.74:58578] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:40:55.475036 2026] [security2:error] [pid 465652:tid 465874] [client 74.7.230.6:39966] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "dash.bavos.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9axzzTqJoBC2Mw28_nQQAA4TE"]
[Tue Jul 21 08:40:55.509063 2026] [security2:error] [pid 465652:tid 465887] [client 173.252.95.21:59196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9axjzTqJoBC2Mw28_nAQAAAO4"]
[Tue Jul 21 08:40:55.565673 2026] [security2:error] [pid 465652:tid 465829] [client 20.206.105.145:45998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/82.php"] [unique_id "al9axzzTqJoBC2Mw28_nRgAAALQ"]
[Tue Jul 21 08:40:55.626335 2026] [security2:error] [pid 465652:tid 465751] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/file.php"] [unique_id "al9axzzTqJoBC2Mw28_nSAAArmI"]
[Tue Jul 21 08:40:55.691433 2026] [security2:error] [pid 465652:tid 465902] [client 91.230.225.3:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mail.edmaramazonas1782840966935.0711679.meusitehostgator.com.br"] [uri "/style.php"] [unique_id "al9axzzTqJoBC2Mw28_nSgAAAP0"]
[Tue Jul 21 08:40:55.776721 2026] [security2:error] [pid 465652:tid 465741] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/777.php"] [unique_id "al9axzzTqJoBC2Mw28_nSwAAp1g"]
[Tue Jul 21 08:40:55.920581 2026] [security2:error] [pid 465652:tid 465670] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/ssixta.php"] [unique_id "al9axzzTqJoBC2Mw28_nUgAAzxE"]
[Tue Jul 21 08:40:55.938326 2026] [security2:error] [pid 465652:tid 465880] [client 20.206.105.145:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/config.json.php"] [unique_id "al9axzzTqJoBC2Mw28_nUwAAAOc"]
[Tue Jul 21 08:40:55.963684 2026] [security2:error] [pid 465652:tid 465904] [client 203.25.124.35:31281] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/chosen.php"] [unique_id "al9axzzTqJoBC2Mw28_nVQAAAP8"]
[Tue Jul 21 08:40:55.987579 2026] [autoindex:error] [pid 465652:tid 465678] [remote 74.7.242.3:56712] AH01276: Cannot serve directory /home2/bavosc49/dash.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:40:56.064110 2026] [security2:error] [pid 465652:tid 465665] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/1c.php"] [unique_id "al9ayDzTqJoBC2Mw28_nWwAAlgw"]
[Tue Jul 21 08:40:56.064980 2026] [security2:error] [pid 465652:tid 465793] [client 20.206.105.145:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ericksheik.com.br"] [uri "/fpwch.php"] [unique_id "al9ayDzTqJoBC2Mw28_nXAAAAJA"]
[Tue Jul 21 08:40:56.084084 2026] [security2:error] [pid 465652:tid 465792] [client 20.226.60.151:58599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/miru1.php"] [unique_id "al9ayDzTqJoBC2Mw28_nXQAAAI8"]
[Tue Jul 21 08:40:56.129624 2026] [security2:error] [pid 465652:tid 465803] [client 198.44.157.34:48376] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ayDzTqJoBC2Mw28_nXwAAAJo"]
[Tue Jul 21 08:40:56.129748 2026] [security2:error] [pid 465652:tid 465803] [client 198.44.157.34:48376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ayDzTqJoBC2Mw28_nXwAAAJo"]
[Tue Jul 21 08:40:56.207274 2026] [security2:error] [pid 465652:tid 465658] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/test2.php"] [unique_id "al9ayDzTqJoBC2Mw28_nYQAAqAU"]
[Tue Jul 21 08:40:56.350194 2026] [security2:error] [pid 465652:tid 465777] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/buy.php"] [unique_id "al9ayDzTqJoBC2Mw28_nYwAA9Hw"]
[Tue Jul 21 08:40:56.459434 2026] [security2:error] [pid 465652:tid 465841] [client 195.49.128.211:60456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ayDzTqJoBC2Mw28_nagAAAMA"]
[Tue Jul 21 08:40:56.459611 2026] [security2:error] [pid 465652:tid 465841] [client 195.49.128.211:60456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ayDzTqJoBC2Mw28_nagAAAMA"]
[Tue Jul 21 08:40:56.492537 2026] [security2:error] [pid 465652:tid 465895] [client 20.220.225.223:12545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/edit.php"] [unique_id "al9ayDzTqJoBC2Mw28_nbwAAAPY"]
[Tue Jul 21 08:40:56.492711 2026] [security2:error] [pid 465652:tid 465657] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/ssend.php"] [unique_id "al9ayDzTqJoBC2Mw28_ncAAA3QQ"]
[Tue Jul 21 08:40:56.637151 2026] [security2:error] [pid 465652:tid 465660] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/item.php"] [unique_id "al9ayDzTqJoBC2Mw28_nfwAAoAc"]
[Tue Jul 21 08:40:56.794930 2026] [security2:error] [pid 465652:tid 465727] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/ss.php"] [unique_id "al9ayDzTqJoBC2Mw28_nggAA6Uo"]
[Tue Jul 21 08:40:56.870356 2026] [security2:error] [pid 465652:tid 465859] [client 203.25.124.64:37583] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/"] [unique_id "al9ayDzTqJoBC2Mw28_nhAAAANI"]
[Tue Jul 21 08:40:56.940896 2026] [security2:error] [pid 465652:tid 465682] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/hypo.php"] [unique_id "al9ayDzTqJoBC2Mw28_niAAA2B0"]
[Tue Jul 21 08:40:57.049233 2026] [security2:error] [pid 465652:tid 465815] [client 61.1.167.83:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ayTzTqJoBC2Mw28_nigAAAKY"]
[Tue Jul 21 08:40:57.049353 2026] [security2:error] [pid 465652:tid 465815] [client 61.1.167.83:54266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ayTzTqJoBC2Mw28_nigAAAKY"]
[Tue Jul 21 08:40:57.061337 2026] [security2:error] [pid 465652:tid 465838] [client 20.206.105.145:33688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/core.php"] [unique_id "al9ayTzTqJoBC2Mw28_njwAAAL0"]
[Tue Jul 21 08:40:57.093338 2026] [security2:error] [pid 465652:tid 465661] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/users.php"] [unique_id "al9ayTzTqJoBC2Mw28_nkAAA1Qg"]
[Tue Jul 21 08:40:57.226202 2026] [security2:error] [pid 465652:tid 465686] [remote 47.86.33.52:28808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiasaudeplena.com.br.ciclododinheiro.com"] [uri "/wp-login.php"] [unique_id "al9ayTzTqJoBC2Mw28_nkgAArCE"]
[Tue Jul 21 08:40:57.245134 2026] [security2:error] [pid 465652:tid 465690] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/177.php"] [unique_id "al9ayTzTqJoBC2Mw28_nkwAAmCU"]
[Tue Jul 21 08:40:57.392169 2026] [security2:error] [pid 465652:tid 465757] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ayTzTqJoBC2Mw28_nlQAAz2g"]
[Tue Jul 21 08:40:57.392312 2026] [security2:error] [pid 465652:tid 465856] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ayTzTqJoBC2Mw28_nlQAAz2g"]
[Tue Jul 21 08:40:57.396148 2026] [security2:error] [pid 465652:tid 465684] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/config.php"] [unique_id "al9ayTzTqJoBC2Mw28_nlwAAxx8"]
[Tue Jul 21 08:40:57.397374 2026] [security2:error] [pid 465652:tid 465790] [client 117.213.202.34:58728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ayTzTqJoBC2Mw28_nlgAAAI0"]
[Tue Jul 21 08:40:57.397462 2026] [security2:error] [pid 465652:tid 465790] [client 117.213.202.34:58728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ayTzTqJoBC2Mw28_nlgAAAI0"]
[Tue Jul 21 08:40:57.544206 2026] [security2:error] [pid 465652:tid 465667] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/gettest.php"] [unique_id "al9ayTzTqJoBC2Mw28_noAAA9g4"]
[Tue Jul 21 08:40:57.608692 2026] [security2:error] [pid 465652:tid 465699] [remote 20.75.217.69:1969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ayTzTqJoBC2Mw28_nogAA9C4"]
[Tue Jul 21 08:40:57.696343 2026] [security2:error] [pid 465652:tid 465731] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/min.php"] [unique_id "al9ayTzTqJoBC2Mw28_nqgAAsE4"]
[Tue Jul 21 08:40:57.744250 2026] [security2:error] [pid 465652:tid 465806] [client 49.144.66.253:30597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ayTzTqJoBC2Mw28_nrQAAAJ0"]
[Tue Jul 21 08:40:57.744354 2026] [security2:error] [pid 465652:tid 465806] [client 49.144.66.253:30597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ayTzTqJoBC2Mw28_nrQAAAJ0"]
[Tue Jul 21 08:40:57.839561 2026] [security2:error] [pid 465652:tid 465765] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/dvjul.php"] [unique_id "al9ayTzTqJoBC2Mw28_nsAAApXA"]
[Tue Jul 21 08:40:57.840436 2026] [security2:error] [pid 465652:tid 465857] [client 20.220.225.223:12342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/kua.php"] [unique_id "al9ayTzTqJoBC2Mw28_nsQAAANA"]
[Tue Jul 21 08:40:57.894432 2026] [security2:error] [pid 465652:tid 465799] [client 113.22.144.139:60341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ayTzTqJoBC2Mw28_nswAAAJY"]
[Tue Jul 21 08:40:57.894534 2026] [security2:error] [pid 465652:tid 465799] [client 113.22.144.139:60341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ayTzTqJoBC2Mw28_nswAAAJY"]
[Tue Jul 21 08:40:57.962607 2026] [security2:error] [pid 465652:tid 465805] [client 203.25.124.58:30793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/1.php"] [unique_id "al9ayTzTqJoBC2Mw28_nuAAAAJw"]
[Tue Jul 21 08:40:57.983083 2026] [security2:error] [pid 465652:tid 465679] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/biufile.php"] [unique_id "al9ayTzTqJoBC2Mw28_nuQAA2Bo"]
[Tue Jul 21 08:40:58.019503 2026] [security2:error] [pid 465652:tid 465884] [client 20.220.225.223:58106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/mimpi.php"] [unique_id "al9ayjzTqJoBC2Mw28_nvAAAAOs"]
[Tue Jul 21 08:40:58.113954 2026] [security2:error] [pid 465652:tid 465838] [client 20.63.100.92:1871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/wp-editor.php"] [unique_id "al9ayjzTqJoBC2Mw28_nwAAAAL0"]
[Tue Jul 21 08:40:58.146206 2026] [security2:error] [pid 465652:tid 465740] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/av.php"] [unique_id "al9ayjzTqJoBC2Mw28_nwgAA5Fc"]
[Tue Jul 21 08:40:58.184570 2026] [security2:error] [pid 465652:tid 465880] [client 20.226.60.151:58591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/sump1.php"] [unique_id "al9ayjzTqJoBC2Mw28_nwwAAAOc"]
[Tue Jul 21 08:40:58.301335 2026] [security2:error] [pid 465652:tid 465653] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/coffexium.php"] [unique_id "al9ayjzTqJoBC2Mw28_nxAAA1QA"]
[Tue Jul 21 08:40:58.339155 2026] [security2:error] [pid 465652:tid 465764] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/.env"] [unique_id "al9ayjzTqJoBC2Mw28_nxQAAkG8"]
[Tue Jul 21 08:40:58.339184 2026] [security2:error] [pid 465652:tid 465746] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/.env"] [unique_id "al9ayjzTqJoBC2Mw28_nxgAAkF0"]
[Tue Jul 21 08:40:58.339947 2026] [security2:error] [pid 465652:tid 465729] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/.env.bak"] [unique_id "al9ayjzTqJoBC2Mw28_nygAAkEw"]
[Tue Jul 21 08:40:58.339954 2026] [security2:error] [pid 465652:tid 465733] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/.env.backup"] [unique_id "al9ayjzTqJoBC2Mw28_nyAAAkFA"]
[Tue Jul 21 08:40:58.407757 2026] [security2:error] [pid 465652:tid 465675] [remote 216.73.216.184:34476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemap.xml"] [unique_id "al9ayjzTqJoBC2Mw28_n3AAAhhY"]
[Tue Jul 21 08:40:58.444392 2026] [security2:error] [pid 465652:tid 465750] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/core.php"] [unique_id "al9ayjzTqJoBC2Mw28_n4AAA0WE"]
[Tue Jul 21 08:40:58.476461 2026] [security2:error] [pid 465652:tid 465668] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.gradiente.com"] [uri "/wp-config.php;/style.css"] [unique_id "al9ayjzTqJoBC2Mw28_n5gAAtw8"]
[Tue Jul 21 08:40:58.476556 2026] [security2:error] [pid 465652:tid 465694] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.gradiente.com"] [uri "/wp-config.php.bak"] [unique_id "al9ayjzTqJoBC2Mw28_n5wAAtyk"]
[Tue Jul 21 08:40:58.479998 2026] [security2:error] [pid 465652:tid 465776] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/wp-config.php"] [unique_id "al9ayjzTqJoBC2Mw28_n6QAAt3s"]
[Tue Jul 21 08:40:58.534409 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.534587 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.534634 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.534673 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.534806 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.534896 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.534933 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.534999 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535033 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535077 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535112 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535147 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535181 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535216 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535251 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535287 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535322 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535357 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535392 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535427 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535460 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535494 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535530 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535563 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535598 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535633 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535668 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535749 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535783 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535826 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535876 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535911 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535959 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.535998 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536025 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536088 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536404 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536425 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536463 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536497 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536530 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536564 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536613 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536649 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536683 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536717 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536750 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536786 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536827 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536862 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536897 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536932 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.536967 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537002 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537039 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537082 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537117 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537164 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537201 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537235 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537272 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537310 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537345 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537385 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537419 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537452 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537486 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537520 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537553 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537586 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537620 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537654 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537687 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537721 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537754 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537789 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537827 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537861 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537897 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537932 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.537965 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.538008 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.538052 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.538098 2026] [lsapi:warn] [pid 465652:tid 465766] [remote 40.77.167.25:12968] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:40:58.587141 2026] [security2:error] [pid 465652:tid 465709] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/als.php"] [unique_id "al9ayjzTqJoBC2Mw28_oDgAA5jg"]
[Tue Jul 21 08:40:58.658514 2026] [core:error] [pid 465652:tid 465666] [remote 40.77.167.74:58578] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:40:58.658541 2026] [core:error] [pid 465652:tid 465666] [remote 40.77.167.74:58578] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:40:58.734559 2026] [security2:error] [pid 465652:tid 465734] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/simple.php"] [unique_id "al9ayjzTqJoBC2Mw28_oGQAA71E"]
[Tue Jul 21 08:40:58.837877 2026] [security2:error] [pid 465652:tid 465808] [client 20.197.192.193:43795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/xyn.php"] [unique_id "al9ayjzTqJoBC2Mw28_oHgAAAJ8"]
[Tue Jul 21 08:40:58.879899 2026] [security2:error] [pid 465652:tid 465657] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/init.php"] [unique_id "al9ayjzTqJoBC2Mw28_oOgAA7AQ"]
[Tue Jul 21 08:40:58.973946 2026] [security2:error] [pid 465652:tid 465890] [client 20.220.225.223:11984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/ez.php"] [unique_id "al9ayjzTqJoBC2Mw28_oQAAAAPE"]
[Tue Jul 21 08:40:59.037285 2026] [security2:error] [pid 465652:tid 465727] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/fpwch.php"] [unique_id "al9ayzzTqJoBC2Mw28_oQgAA_Eo"]
[Tue Jul 21 08:40:59.054327 2026] [security2:error] [pid 465652:tid 465794] [client 168.167.81.163:62458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9ayzzTqJoBC2Mw28_oRQAAAJE"]
[Tue Jul 21 08:40:59.054420 2026] [security2:error] [pid 465652:tid 465794] [client 168.167.81.163:62458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9ayzzTqJoBC2Mw28_oRQAAAJE"]
[Tue Jul 21 08:40:59.171720 2026] [security2:error] [pid 465652:tid 465833] [client 59.95.197.55:60999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ayzzTqJoBC2Mw28_oTAAAALg"]
[Tue Jul 21 08:40:59.172411 2026] [security2:error] [pid 465652:tid 465833] [client 59.95.197.55:60999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ayzzTqJoBC2Mw28_oTAAAALg"]
[Tue Jul 21 08:40:59.193965 2026] [security2:error] [pid 465652:tid 465726] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/domvf.php"] [unique_id "al9ayzzTqJoBC2Mw28_oTQAA10k"]
[Tue Jul 21 08:40:59.216093 2026] [security2:error] [pid 465652:tid 465796] [client 193.148.56.61:63874] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "oticapersona.com.br"] [uri "/"] [unique_id "al9ayzzTqJoBC2Mw28_oTgAAAJM"]
[Tue Jul 21 08:40:59.344734 2026] [security2:error] [pid 465652:tid 465749] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wp.php"] [unique_id "al9ayzzTqJoBC2Mw28_oXwAAvmA"]
[Tue Jul 21 08:40:59.490181 2026] [security2:error] [pid 465652:tid 465767] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/class.php"] [unique_id "al9ayzzTqJoBC2Mw28_oawAAxXI"]
[Tue Jul 21 08:40:59.494301 2026] [security2:error] [pid 465652:tid 465884] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ayzzTqJoBC2Mw28_oYAAA6ys"]
[Tue Jul 21 08:40:59.509160 2026] [security2:error] [pid 465652:tid 465707] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/.ssh/id_rsa"] [unique_id "al9ayzzTqJoBC2Mw28_obAAAhjY"]
[Tue Jul 21 08:40:59.536976 2026] [security2:error] [pid 465652:tid 465687] [remote 156.59.198.136:28236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "transitoaberto.com.br"] [uri "/wp-content/uploads/2020/12/Capina1.jpg"] [unique_id "al9ayzzTqJoBC2Mw28_obgAA3iI"], referer: https://transitoaberto.com.br/jacarei-divulga-calendario-de-servicos-de-zeladoria-em-dezembro/
[Tue Jul 21 08:40:59.611424 2026] [security2:error] [pid 465652:tid 465906] [client 193.148.56.61:63978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "oticapersona.com.br"] [uri "/"] [unique_id "al9ayzzTqJoBC2Mw28_odwAAAQE"]
[Tue Jul 21 08:40:59.636791 2026] [security2:error] [pid 465652:tid 465755] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/echkm.php"] [unique_id "al9ayzzTqJoBC2Mw28_oewAA5mY"]
[Tue Jul 21 08:40:59.721890 2026] [security2:error] [pid 465652:tid 465740] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/config/app.php"] [unique_id "al9ayzzTqJoBC2Mw28_ofQAA1lc"]
[Tue Jul 21 08:40:59.722120 2026] [security2:error] [pid 465652:tid 465653] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/config/mail.php"] [unique_id "al9ayzzTqJoBC2Mw28_ofwAA1gA"]
[Tue Jul 21 08:40:59.722137 2026] [security2:error] [pid 465652:tid 465739] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/config/database.php"] [unique_id "al9ayzzTqJoBC2Mw28_ofgAA1lY"]
[Tue Jul 21 08:40:59.788779 2026] [security2:error] [pid 465652:tid 465729] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/lib.php"] [unique_id "al9ayzzTqJoBC2Mw28_ohwAAvEw"]
[Tue Jul 21 08:40:59.860920 2026] [security2:error] [pid 465652:tid 465888] [client 203.25.124.66:21591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/fukasawa/inc/classes/403.php"] [unique_id "al9ayzzTqJoBC2Mw28_ojAAAAO8"]
[Tue Jul 21 08:40:59.888845 2026] [security2:error] [pid 465652:tid 465825] [client 20.63.100.92:1484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/cro.php"] [unique_id "al9ayzzTqJoBC2Mw28_ojQAAALA"]
[Tue Jul 21 08:40:59.946755 2026] [security2:error] [pid 465652:tid 465717] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/backup.sql"] [unique_id "al9ayzzTqJoBC2Mw28_okQAAlEA"]
[Tue Jul 21 08:40:59.955910 2026] [security2:error] [pid 465652:tid 465750] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/login.php"] [unique_id "al9ayzzTqJoBC2Mw28_okgAAtGE"]
[Tue Jul 21 08:40:59.959775 2026] [security2:error] [pid 465652:tid 465700] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/dump.sql"] [unique_id "al9ayzzTqJoBC2Mw28_okwAAlC8"]
[Tue Jul 21 08:41:00.017687 2026] [security2:error] [pid 465652:tid 465672] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/database.sql"] [unique_id "al9azDzTqJoBC2Mw28_olwAA8xM"]
[Tue Jul 21 08:41:00.099026 2026] [security2:error] [pid 465652:tid 465824] [client 198.44.157.34:50926] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9azDzTqJoBC2Mw28_oogAAAK8"]
[Tue Jul 21 08:41:00.099109 2026] [security2:error] [pid 465652:tid 465824] [client 198.44.157.34:50926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9azDzTqJoBC2Mw28_oogAAAK8"]
[Tue Jul 21 08:41:00.104596 2026] [security2:error] [pid 465652:tid 465691] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/a2.php"] [unique_id "al9azDzTqJoBC2Mw28_oowAAwyY"]
[Tue Jul 21 08:41:00.166592 2026] [security2:error] [pid 465652:tid 465828] [client 20.206.105.145:33674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/main.php"] [unique_id "al9azDzTqJoBC2Mw28_opQAAALM"]
[Tue Jul 21 08:41:00.242261 2026] [security2:error] [pid 465652:tid 465722] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/.env"] [unique_id "al9azDzTqJoBC2Mw28_orQAAnEU"]
[Tue Jul 21 08:41:00.260347 2026] [security2:error] [pid 465652:tid 465728] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/d61.php"] [unique_id "al9azDzTqJoBC2Mw28_orwAAiUs"]
[Tue Jul 21 08:41:00.280017 2026] [security2:error] [pid 465652:tid 465850] [client 20.220.225.223:2394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/dp.php"] [unique_id "al9azDzTqJoBC2Mw28_osAAAAMk"]
[Tue Jul 21 08:41:00.414370 2026] [rewrite:warn] [pid 465652:tid 465778] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:41:00.424889 2026] [security2:error] [pid 465652:tid 465761] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/info.php"] [unique_id "al9azDzTqJoBC2Mw28_otAAAu2w"]
[Tue Jul 21 08:41:00.434217 2026] [security2:error] [pid 465652:tid 465881] [client 122.176.100.127:61707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9azDzTqJoBC2Mw28_otQAAAOg"]
[Tue Jul 21 08:41:00.434327 2026] [security2:error] [pid 465652:tid 465881] [client 122.176.100.127:61707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9azDzTqJoBC2Mw28_otQAAAOg"]
[Tue Jul 21 08:41:00.448169 2026] [security2:error] [pid 465652:tid 465866] [client 20.220.225.223:12331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/fz.php"] [unique_id "al9azDzTqJoBC2Mw28_otgAAANk"]
[Tue Jul 21 08:41:00.578627 2026] [security2:error] [pid 465652:tid 465758] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/11.php"] [unique_id "al9azDzTqJoBC2Mw28_ouQAA2mk"]
[Tue Jul 21 08:41:00.629505 2026] [security2:error] [pid 465652:tid 465705] [remote 192.241.143.148:38810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carrosselbuique.com.br"] [uri "/wp-login.php"] [unique_id "al9azDzTqJoBC2Mw28_ovQABADQ"]
[Tue Jul 21 08:41:00.674261 2026] [security2:error] [pid 465652:tid 465856] [client 203.25.124.54:35151] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/alera/gecko.php"] [unique_id "al9azDzTqJoBC2Mw28_ovwAAAM8"]
[Tue Jul 21 08:41:00.731223 2026] [security2:error] [pid 465652:tid 465745] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/v2.php"] [unique_id "al9azDzTqJoBC2Mw28_oxQAAjVw"]
[Tue Jul 21 08:41:00.877929 2026] [security2:error] [pid 465652:tid 465659] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/panel.php"] [unique_id "al9azDzTqJoBC2Mw28_oxwAAxAY"]
[Tue Jul 21 08:41:00.896522 2026] [security2:error] [pid 465652:tid 465863] [client 8.229.228.188:55095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.228.229.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "erp.inlaudo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9azDzTqJoBC2Mw28_oyQAAANY"]
[Tue Jul 21 08:41:01.030150 2026] [security2:error] [pid 465652:tid 465738] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/dex.php"] [unique_id "al9azTzTqJoBC2Mw28_oywAA4FU"]
[Tue Jul 21 08:41:01.051092 2026] [security2:error] [pid 465652:tid 465895] [client 213.152.162.15:38236] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9azDzTqJoBC2Mw28_oyAAAAPY"]
[Tue Jul 21 08:41:01.051206 2026] [security2:error] [pid 465652:tid 465895] [client 213.152.162.15:38236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9azDzTqJoBC2Mw28_oyAAAAPY"]
[Tue Jul 21 08:41:01.161589 2026] [security2:error] [pid 465652:tid 465769] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.gradiente.com"] [uri "/wp-config.php"] [unique_id "al9azTzTqJoBC2Mw28_o0QAA43Q"]
[Tue Jul 21 08:41:01.182411 2026] [security2:error] [pid 465652:tid 465770] [remote 20.104.96.117:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.academiausina.com.br"] [uri "/1.php"] [unique_id "al9azTzTqJoBC2Mw28_o1gAApXU"]
[Tue Jul 21 08:41:01.182511 2026] [security2:error] [pid 465652:tid 465770] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/1.php"] [unique_id "al9azTzTqJoBC2Mw28_o1gAApXU"]
[Tue Jul 21 08:41:01.185122 2026] [security2:error] [pid 465652:tid 465900] [client 5.38.115.39:56066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9azTzTqJoBC2Mw28_o2AAAAPs"]
[Tue Jul 21 08:41:01.185233 2026] [security2:error] [pid 465652:tid 465900] [client 5.38.115.39:56066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9azTzTqJoBC2Mw28_o2AAAAPs"]
[Tue Jul 21 08:41:01.203320 2026] [security2:error] [pid 465652:tid 465721] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/.env.backup"] [unique_id "al9azTzTqJoBC2Mw28_o2wAAnUQ"]
[Tue Jul 21 08:41:01.273145 2026] [security2:error] [pid 465652:tid 465882] [client 8.229.228.188:60759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "erp.inlaudo.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9azTzTqJoBC2Mw28_o3wAAAOk"]
[Tue Jul 21 08:41:01.305666 2026] [security2:error] [pid 465652:tid 465785] [client 5.31.193.106:1796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9azTzTqJoBC2Mw28_o4QAAAIg"]
[Tue Jul 21 08:41:01.312107 2026] [security2:error] [pid 465652:tid 465785] [client 5.31.193.106:1796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9azTzTqJoBC2Mw28_o4QAAAIg"]
[Tue Jul 21 08:41:01.330884 2026] [security2:error] [pid 465652:tid 465693] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/ms.php"] [unique_id "al9azTzTqJoBC2Mw28_o4gAAkyg"]
[Tue Jul 21 08:41:01.396398 2026] [security2:error] [pid 465652:tid 465838] [client 20.206.105.145:33647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/init.php"] [unique_id "al9azTzTqJoBC2Mw28_o5gAAAL0"]
[Tue Jul 21 08:41:01.477686 2026] [proxy:error] [pid 465652:tid 465716] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:01.477759 2026] [proxy_http:error] [pid 465652:tid 465716] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:01.478520 2026] [proxy:error] [pid 465652:tid 465716] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:01.478554 2026] [proxy_http:error] [pid 465652:tid 465716] [remote 20.104.96.117:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:01.482307 2026] [rewrite:warn] [pid 465652:tid 465669] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:41:01.638885 2026] [security2:error] [pid 465652:tid 465760] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/memberfuns.php"] [unique_id "al9azTzTqJoBC2Mw28_o7gAA2Ws"]
[Tue Jul 21 08:41:01.646178 2026] [security2:error] [pid 465652:tid 465813] [client 8.229.228.188:55286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "erp.inlaudo.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9azTzTqJoBC2Mw28_o8AAAAKQ"]
[Tue Jul 21 08:41:01.662789 2026] [security2:error] [pid 465652:tid 465880] [client 203.25.124.54:28813] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/so-pinyin-slugs/inc/main_json.php"] [unique_id "al9azTzTqJoBC2Mw28_o8gAAAOc"]
[Tue Jul 21 08:41:01.739148 2026] [security2:error] [pid 465652:tid 465655] [remote 102.134.101.35:34866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9azTzTqJoBC2Mw28_o8wAA8QI"]
[Tue Jul 21 08:41:01.799391 2026] [security2:error] [pid 465652:tid 465702] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/0.php"] [unique_id "al9azTzTqJoBC2Mw28_o-QAA4jE"]
[Tue Jul 21 08:41:01.945630 2026] [security2:error] [pid 465652:tid 465751] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/BDKR28.php"] [unique_id "al9azTzTqJoBC2Mw28_o-wAA8GI"]
[Tue Jul 21 08:41:02.000149 2026] [security2:error] [pid 465652:tid 465902] [client 8.229.228.188:58291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "erp.inlaudo.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9azTzTqJoBC2Mw28_o_QAAAP0"]
[Tue Jul 21 08:41:02.028870 2026] [security2:error] [pid 465652:tid 465818] [client 20.220.225.223:12319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/la.php"] [unique_id "al9azjzTqJoBC2Mw28_o_gAAAKk"]
[Tue Jul 21 08:41:02.102573 2026] [security2:error] [pid 465652:tid 465671] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/green1.php"] [unique_id "al9azjzTqJoBC2Mw28_pAAAAthI"]
[Tue Jul 21 08:41:02.267710 2026] [security2:error] [pid 465652:tid 465863] [client 74.249.245.134:63717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/g.php"] [unique_id "al9azjzTqJoBC2Mw28_pCAAAANY"]
[Tue Jul 21 08:41:02.274519 2026] [security2:error] [pid 465652:tid 465673] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/nc4.php"] [unique_id "al9azjzTqJoBC2Mw28_pCwAA_hQ"]
[Tue Jul 21 08:41:02.391906 2026] [security2:error] [pid 465652:tid 465850] [client 47.128.126.253:50870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.moadvogadas.com.br"] [uri "/robots.txt"] [unique_id "al9azjzTqJoBC2Mw28_pDwAAAMk"]
[Tue Jul 21 08:41:02.398649 2026] [security2:error] [pid 465652:tid 465782] [client 8.229.228.188:61093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "erp.inlaudo.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9azjzTqJoBC2Mw28_pEAAAAIU"]
[Tue Jul 21 08:41:02.419173 2026] [security2:error] [pid 465652:tid 465753] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/a1.php"] [unique_id "al9azjzTqJoBC2Mw28_pEQAA82Q"]
[Tue Jul 21 08:41:02.571537 2026] [security2:error] [pid 465652:tid 465678] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/eee.php"] [unique_id "al9azjzTqJoBC2Mw28_pEwAA4xk"]
[Tue Jul 21 08:41:02.612182 2026] [security2:error] [pid 465652:tid 465832] [client 74.7.175.161:32770] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "zeisslondrina.com.br.oticapersona.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9azjzTqJoBC2Mw28_pFAAAtxg"]
[Tue Jul 21 08:41:02.728371 2026] [security2:error] [pid 465652:tid 465665] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/wp-aothait.php"] [unique_id "al9azjzTqJoBC2Mw28_pFgAApQw"]
[Tue Jul 21 08:41:02.757411 2026] [security2:error] [pid 465652:tid 465791] [client 8.229.228.188:63614] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "erp.inlaudo.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9azjzTqJoBC2Mw28_pGgAAAI4"]
[Tue Jul 21 08:41:02.870711 2026] [security2:error] [pid 465652:tid 465784] [client 212.32.76.11:25531] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/assets/"] [unique_id "al9azjzTqJoBC2Mw28_pIQAAAIc"]
[Tue Jul 21 08:41:02.871088 2026] [security2:error] [pid 465652:tid 465657] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/config.json.php"] [unique_id "al9azjzTqJoBC2Mw28_pIgABAwQ"]
[Tue Jul 21 08:41:03.014757 2026] [security2:error] [pid 465652:tid 465766] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9azzzTqJoBC2Mw28_pJAAAiXE"]
[Tue Jul 21 08:41:03.142743 2026] [security2:error] [pid 465652:tid 465851] [client 8.229.228.188:53894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "erp.inlaudo.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9azzzTqJoBC2Mw28_pJgAAAMo"]
[Tue Jul 21 08:41:03.157219 2026] [security2:error] [pid 465652:tid 465748] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/k2.php"] [unique_id "al9azzzTqJoBC2Mw28_pKAAApl8"]
[Tue Jul 21 08:41:03.200735 2026] [security2:error] [pid 465652:tid 465823] [client 202.179.75.202:37110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9azzzTqJoBC2Mw28_pKQAAAK4"]
[Tue Jul 21 08:41:03.200866 2026] [security2:error] [pid 465652:tid 465823] [client 202.179.75.202:37110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9azzzTqJoBC2Mw28_pKQAAAK4"]
[Tue Jul 21 08:41:03.293390 2026] [security2:error] [pid 465652:tid 465836] [client 20.220.225.223:12305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9azzzTqJoBC2Mw28_pLgAAALs"]
[Tue Jul 21 08:41:03.293848 2026] [security2:error] [pid 465652:tid 465835] [client 20.226.60.151:34860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/file5.php"] [unique_id "al9azzzTqJoBC2Mw28_pLwAAALo"]
[Tue Jul 21 08:41:03.305755 2026] [security2:error] [pid 465652:tid 465682] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9azzzTqJoBC2Mw28_pMgAA8R0"]
[Tue Jul 21 08:41:03.306178 2026] [security2:error] [pid 465652:tid 465660] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pMQAAkgc"]
[Tue Jul 21 08:41:03.306725 2026] [security2:error] [pid 465652:tid 465684] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pOwAAkh8"]
[Tue Jul 21 08:41:03.307339 2026] [security2:error] [pid 465652:tid 465715] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pOAAAkj4"]
[Tue Jul 21 08:41:03.307350 2026] [security2:error] [pid 465652:tid 465718] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pMwAAkkE"]
[Tue Jul 21 08:41:03.307407 2026] [security2:error] [pid 465652:tid 465724] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pNAAAkkc"]
[Tue Jul 21 08:41:03.307447 2026] [security2:error] [pid 465652:tid 465663] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pNQAAkgo"]
[Tue Jul 21 08:41:03.307445 2026] [security2:error] [pid 465652:tid 465682] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pNwAAkh0"]
[Tue Jul 21 08:41:03.445288 2026] [security2:error] [pid 465652:tid 465653] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pUgAAwgA"]
[Tue Jul 21 08:41:03.445448 2026] [security2:error] [pid 465652:tid 465739] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pVgAAwlY"]
[Tue Jul 21 08:41:03.445463 2026] [security2:error] [pid 465652:tid 465746] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pVwAAwl0"]
[Tue Jul 21 08:41:03.445484 2026] [security2:error] [pid 465652:tid 465740] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pVAAAwlc"]
[Tue Jul 21 08:41:03.445512 2026] [security2:error] [pid 465652:tid 465679] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pUwAAwho"]
[Tue Jul 21 08:41:03.445542 2026] [security2:error] [pid 465652:tid 465773] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pVQAAwng"]
[Tue Jul 21 08:41:03.446230 2026] [security2:error] [pid 465652:tid 465771] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pWQAAwnY"]
[Tue Jul 21 08:41:03.446447 2026] [security2:error] [pid 465652:tid 465733] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9azzzTqJoBC2Mw28_pWAAAwlA"]
[Tue Jul 21 08:41:03.455522 2026] [security2:error] [pid 465652:tid 465764] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9azzzTqJoBC2Mw28_pXwAA7m8"]
[Tue Jul 21 08:41:03.512071 2026] [security2:error] [pid 465652:tid 465788] [client 8.229.228.188:56759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "erp.inlaudo.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9azzzTqJoBC2Mw28_pYQAAAIs"]
[Tue Jul 21 08:41:03.568740 2026] [security2:error] [pid 465652:tid 465818] [client 173.252.95.7:64036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9azzzTqJoBC2Mw28_pYgAAAKk"]
[Tue Jul 21 08:41:03.577677 2026] [security2:error] [pid 465652:tid 465888] [client 20.206.105.145:33619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/prekel.php"] [unique_id "al9azzzTqJoBC2Mw28_pYwAAAO8"]
[Tue Jul 21 08:41:03.607738 2026] [security2:error] [pid 465652:tid 465765] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9azzzTqJoBC2Mw28_pZAAAx3A"]
[Tue Jul 21 08:41:03.765553 2026] [security2:error] [pid 465652:tid 465752] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/for.php"] [unique_id "al9azzzTqJoBC2Mw28_pagAAmWM"]
[Tue Jul 21 08:41:03.860500 2026] [security2:error] [pid 465652:tid 465909] [client 223.181.60.88:21137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9azzzTqJoBC2Mw28_pbwAAAQQ"]
[Tue Jul 21 08:41:03.861253 2026] [security2:error] [pid 465652:tid 465909] [client 223.181.60.88:21137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9azzzTqJoBC2Mw28_pbwAAAQQ"]
[Tue Jul 21 08:41:03.890256 2026] [security2:error] [pid 465652:tid 465900] [client 8.229.228.188:51609] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "erp.inlaudo.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9azzzTqJoBC2Mw28_pcAAAAPs"]
[Tue Jul 21 08:41:03.908674 2026] [security2:error] [pid 465652:tid 465700] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.academiausina.com.br"] [uri "/raw.php"] [unique_id "al9azzzTqJoBC2Mw28_pcQAAji8"]
[Tue Jul 21 08:41:03.958730 2026] [security2:error] [pid 465652:tid 465824] [client 20.220.225.223:47759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/bootstrap.php"] [unique_id "al9azzzTqJoBC2Mw28_pcgAAAK8"]
[Tue Jul 21 08:41:03.991575 2026] [security2:error] [pid 465652:tid 465787] [client 195.49.128.211:53212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9azzzTqJoBC2Mw28_pdAAAAIo"]
[Tue Jul 21 08:41:03.991694 2026] [security2:error] [pid 465652:tid 465787] [client 195.49.128.211:53212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9azzzTqJoBC2Mw28_pdAAAAIo"]
[Tue Jul 21 08:41:04.261714 2026] [security2:error] [pid 465652:tid 465786] [client 8.229.228.188:64349] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "erp.inlaudo.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9a0DzTqJoBC2Mw28_pfQAAAIk"]
[Tue Jul 21 08:41:04.269381 2026] [security2:error] [pid 465652:tid 465815] [client 203.25.124.61:52753] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/hello.php"] [unique_id "al9a0DzTqJoBC2Mw28_pgAAAAKY"]
[Tue Jul 21 08:41:04.304281 2026] [security2:error] [pid 465652:tid 465856] [client 69.171.230.41:34320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9a0DzTqJoBC2Mw28_pgwAAAM8"]
[Tue Jul 21 08:41:04.313674 2026] [core:error] [pid 465652:tid 465691] [remote 40.77.167.30:23011] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:41:04.313699 2026] [core:error] [pid 465652:tid 465691] [remote 40.77.167.30:23011] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:41:04.468904 2026] [security2:error] [pid 465652:tid 465896] [client 103.59.206.240:31250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a0DzTqJoBC2Mw28_piQAAAPc"]
[Tue Jul 21 08:41:04.469004 2026] [security2:error] [pid 465652:tid 465896] [client 103.59.206.240:31250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a0DzTqJoBC2Mw28_piQAAAPc"]
[Tue Jul 21 08:41:04.673011 2026] [security2:error] [pid 465652:tid 465881] [client 14.245.224.124:63776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9a0DzTqJoBC2Mw28_pjAAAAOg"]
[Tue Jul 21 08:41:04.673150 2026] [security2:error] [pid 465652:tid 465881] [client 14.245.224.124:63776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9a0DzTqJoBC2Mw28_pjAAAAOg"]
[Tue Jul 21 08:41:05.235624 2026] [security2:error] [pid 465652:tid 465745] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_poAAA5Fw"]
[Tue Jul 21 08:41:05.235632 2026] [security2:error] [pid 465652:tid 465757] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_pngAA5Gg"]
[Tue Jul 21 08:41:05.235706 2026] [security2:error] [pid 465652:tid 465736] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_pnAAA5FM"]
[Tue Jul 21 08:41:05.235730 2026] [security2:error] [pid 465652:tid 465719] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_pnQAA5EI"]
[Tue Jul 21 08:41:05.235783 2026] [security2:error] [pid 465652:tid 465720] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_pnwAA5EM"]
[Tue Jul 21 08:41:05.264768 2026] [security2:error] [pid 465652:tid 465814] [client 203.25.124.70:37805] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/maint/"] [unique_id "al9a0TzTqJoBC2Mw28_ppwAAAKU"]
[Tue Jul 21 08:41:05.373135 2026] [security2:error] [pid 465652:tid 465709] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_puAAA5Dg"]
[Tue Jul 21 08:41:05.373174 2026] [security2:error] [pid 465652:tid 465689] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_puwAA5CQ"]
[Tue Jul 21 08:41:05.373198 2026] [security2:error] [pid 465652:tid 465693] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_pvQAA5Cg"]
[Tue Jul 21 08:41:05.373228 2026] [security2:error] [pid 465652:tid 465712] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_pvAAA5Ds"]
[Tue Jul 21 08:41:05.373270 2026] [security2:error] [pid 465652:tid 465721] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_puQAA5EQ"]
[Tue Jul 21 08:41:05.373291 2026] [security2:error] [pid 465652:tid 465681] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_pugAA5Bw"]
[Tue Jul 21 08:41:05.374298 2026] [security2:error] [pid 465652:tid 465676] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_pvgAA5Bc"]
[Tue Jul 21 08:41:05.374330 2026] [security2:error] [pid 465652:tid 465716] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_pwAAA5D8"]
[Tue Jul 21 08:41:05.374400 2026] [security2:error] [pid 465652:tid 465669] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_pwQAA5BA"]
[Tue Jul 21 08:41:05.374496 2026] [security2:error] [pid 465652:tid 465685] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0TzTqJoBC2Mw28_pvwAA5CA"]
[Tue Jul 21 08:41:05.722422 2026] [security2:error] [pid 465652:tid 465887] [client 152.59.181.104:62654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9a0TzTqJoBC2Mw28_pygAAAO4"]
[Tue Jul 21 08:41:05.722536 2026] [security2:error] [pid 465652:tid 465887] [client 152.59.181.104:62654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9a0TzTqJoBC2Mw28_pygAAAO4"]
[Tue Jul 21 08:41:05.770934 2026] [security2:error] [pid 465652:tid 465655] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9a0TzTqJoBC2Mw28_pywAAuQI"]
[Tue Jul 21 08:41:05.771117 2026] [security2:error] [pid 465652:tid 465834] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9a0TzTqJoBC2Mw28_pywAAuQI"]
[Tue Jul 21 08:41:06.002189 2026] [security2:error] [pid 465652:tid 465891] [client 74.249.245.134:46101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/403.php"] [unique_id "al9a0jzTqJoBC2Mw28_p2gAAAPI"]
[Tue Jul 21 08:41:06.291435 2026] [security2:error] [pid 465652:tid 465906] [client 20.220.225.223:63327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wp-editor.php"] [unique_id "al9a0jzTqJoBC2Mw28_p3wAAAQE"]
[Tue Jul 21 08:41:06.518054 2026] [security2:error] [pid 465652:tid 465870] [client 20.206.105.145:33662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/0.php"] [unique_id "al9a0jzTqJoBC2Mw28_p5gAAAN0"]
[Tue Jul 21 08:41:06.662739 2026] [security2:error] [pid 465652:tid 465797] [client 212.32.76.5:49439] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wordpress/wp-admin/maint/"] [unique_id "al9a0jzTqJoBC2Mw28_p6gAAAJQ"]
[Tue Jul 21 08:41:07.148240 2026] [security2:error] [pid 465652:tid 465789] [client 195.49.128.211:61057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9a0zzTqJoBC2Mw28_p-AAAAIw"]
[Tue Jul 21 08:41:07.148342 2026] [security2:error] [pid 465652:tid 465789] [client 195.49.128.211:61057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9a0zzTqJoBC2Mw28_p-AAAAIw"]
[Tue Jul 21 08:41:07.228875 2026] [security2:error] [pid 465652:tid 465688] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0zzTqJoBC2Mw28_p_gAApiM"]
[Tue Jul 21 08:41:07.228876 2026] [security2:error] [pid 465652:tid 465766] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0zzTqJoBC2Mw28_p-wAApnE"]
[Tue Jul 21 08:41:07.229062 2026] [security2:error] [pid 465652:tid 465658] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0zzTqJoBC2Mw28_p_QAApgU"]
[Tue Jul 21 08:41:07.428732 2026] [security2:error] [pid 465652:tid 465711] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0zzTqJoBC2Mw28_qEAAAuTo"]
[Tue Jul 21 08:41:07.430553 2026] [security2:error] [pid 465652:tid 465684] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0zzTqJoBC2Mw28_qEwAAuR8"]
[Tue Jul 21 08:41:07.430608 2026] [security2:error] [pid 465652:tid 465660] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0zzTqJoBC2Mw28_qEgAAuQc"]
[Tue Jul 21 08:41:07.430860 2026] [security2:error] [pid 465652:tid 465715] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0zzTqJoBC2Mw28_qFAAAuT4"]
[Tue Jul 21 08:41:07.431121 2026] [security2:error] [pid 465652:tid 465718] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0zzTqJoBC2Mw28_qFgAAuUE"]
[Tue Jul 21 08:41:07.431729 2026] [security2:error] [pid 465652:tid 465684] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0zzTqJoBC2Mw28_qFwAAuR8"]
[Tue Jul 21 08:41:07.431786 2026] [security2:error] [pid 465652:tid 465695] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0zzTqJoBC2Mw28_qGQAAuSo"]
[Tue Jul 21 08:41:07.431931 2026] [security2:error] [pid 465652:tid 465663] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0zzTqJoBC2Mw28_qGAAAuQo"]
[Tue Jul 21 08:41:07.431973 2026] [security2:error] [pid 465652:tid 465724] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0zzTqJoBC2Mw28_qFQAAuUc"]
[Tue Jul 21 08:41:07.431976 2026] [security2:error] [pid 465652:tid 465715] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0zzTqJoBC2Mw28_qGgAAuT4"]
[Tue Jul 21 08:41:07.529142 2026] [security2:error] [pid 465652:tid 465661] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a0zzTqJoBC2Mw28_qIAAAugg"]
[Tue Jul 21 08:41:07.660643 2026] [security2:error] [pid 465652:tid 465801] [client 203.25.124.43:42623] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "al9a0zzTqJoBC2Mw28_qJQAAAJg"]
[Tue Jul 21 08:41:07.991320 2026] [security2:error] [pid 465652:tid 465823] [client 117.213.202.34:59325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a0zzTqJoBC2Mw28_qKwAAAK4"]
[Tue Jul 21 08:41:07.991473 2026] [security2:error] [pid 465652:tid 465823] [client 117.213.202.34:59325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a0zzTqJoBC2Mw28_qKwAAAK4"]
[Tue Jul 21 08:41:08.066781 2026] [security2:error] [pid 465652:tid 465686] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9a1DzTqJoBC2Mw28_qLAAA4iE"]
[Tue Jul 21 08:41:08.066950 2026] [security2:error] [pid 465652:tid 465875] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9a1DzTqJoBC2Mw28_qLAAA4iE"]
[Tue Jul 21 08:41:08.306871 2026] [security2:error] [pid 465652:tid 465870] [client 74.249.245.134:46138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cartoriodecurupira.com.br.bililica.com"] [uri "/api.php"] [unique_id "al9a1DzTqJoBC2Mw28_qNQAAAN0"]
[Tue Jul 21 08:41:08.312265 2026] [security2:error] [pid 465652:tid 465893] [client 195.206.105.227:36770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9a1DzTqJoBC2Mw28_qNgAAAPQ"]
[Tue Jul 21 08:41:08.312350 2026] [security2:error] [pid 465652:tid 465893] [client 195.206.105.227:36770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9a1DzTqJoBC2Mw28_qNgAAAPQ"]
[Tue Jul 21 08:41:08.504718 2026] [security2:error] [pid 465652:tid 465897] [client 213.152.162.15:38250] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9a1DzTqJoBC2Mw28_qPwAAAPg"]
[Tue Jul 21 08:41:08.504806 2026] [security2:error] [pid 465652:tid 465897] [client 213.152.162.15:38250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9a1DzTqJoBC2Mw28_qPwAAAPg"]
[Tue Jul 21 08:41:08.777902 2026] [security2:error] [pid 465652:tid 465814] [client 49.144.66.253:30998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9a1DzTqJoBC2Mw28_qRAAAAKU"]
[Tue Jul 21 08:41:08.778012 2026] [security2:error] [pid 465652:tid 465814] [client 49.144.66.253:30998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9a1DzTqJoBC2Mw28_qRAAAAKU"]
[Tue Jul 21 08:41:08.864051 2026] [security2:error] [pid 465652:tid 465863] [client 203.25.124.39:32343] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "al9a1DzTqJoBC2Mw28_qRQAAANY"]
[Tue Jul 21 08:41:09.107012 2026] [security2:error] [pid 465652:tid 465764] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qSwAAym8"]
[Tue Jul 21 08:41:09.107362 2026] [security2:error] [pid 465652:tid 465763] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qTAAAym4"]
[Tue Jul 21 08:41:09.198738 2026] [security2:error] [pid 465652:tid 465749] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qXgAAymA"]
[Tue Jul 21 08:41:09.207992 2026] [security2:error] [pid 465652:tid 465782] [client 113.22.144.139:60935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a1TzTqJoBC2Mw28_qYQAAAIU"]
[Tue Jul 21 08:41:09.208106 2026] [security2:error] [pid 465652:tid 465782] [client 113.22.144.139:60935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a1TzTqJoBC2Mw28_qYQAAAIU"]
[Tue Jul 21 08:41:09.288174 2026] [security2:error] [pid 465652:tid 465717] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qYgAAxUA"]
[Tue Jul 21 08:41:09.289228 2026] [security2:error] [pid 465652:tid 465725] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qYwAAxUg"]
[Tue Jul 21 08:41:09.292849 2026] [security2:error] [pid 465652:tid 465777] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qZAAAuXw"]
[Tue Jul 21 08:41:09.292949 2026] [security2:error] [pid 465652:tid 465675] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qZgAAuRY"]
[Tue Jul 21 08:41:09.293062 2026] [security2:error] [pid 465652:tid 465762] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qaAAAuW0"]
[Tue Jul 21 08:41:09.294022 2026] [security2:error] [pid 465652:tid 465700] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qZQAAuS8"]
[Tue Jul 21 08:41:09.294083 2026] [security2:error] [pid 465652:tid 465729] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qZwAAuUw"]
[Tue Jul 21 08:41:09.294088 2026] [security2:error] [pid 465652:tid 465762] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qawAAuW0"]
[Tue Jul 21 08:41:09.294132 2026] [security2:error] [pid 465652:tid 465691] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qagAAuSY"]
[Tue Jul 21 08:41:09.294185 2026] [security2:error] [pid 465652:tid 465656] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qbAAAuQM"]
[Tue Jul 21 08:41:09.294398 2026] [security2:error] [pid 465652:tid 465776] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qaQAAuXs"]
[Tue Jul 21 08:41:09.311144 2026] [security2:error] [pid 465652:tid 465737] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1TzTqJoBC2Mw28_qcAAAuVQ"]
[Tue Jul 21 08:41:09.716708 2026] [security2:error] [pid 465652:tid 465826] [client 59.95.197.55:61446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a1TzTqJoBC2Mw28_qegAAALE"]
[Tue Jul 21 08:41:09.719363 2026] [security2:error] [pid 465652:tid 465826] [client 59.95.197.55:61446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a1TzTqJoBC2Mw28_qegAAALE"]
[Tue Jul 21 08:41:09.840284 2026] [security2:error] [pid 465652:tid 465802] [client 20.220.225.223:12585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/inso.php"] [unique_id "al9a1TzTqJoBC2Mw28_qgwAAAJk"]
[Tue Jul 21 08:41:10.037057 2026] [security2:error] [pid 465652:tid 465817] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9a1TzTqJoBC2Mw28_qhQAAqEI"]
[Tue Jul 21 08:41:10.042601 2026] [security2:error] [pid 465652:tid 465800] [client 20.206.105.145:33762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/BDKR28.php"] [unique_id "al9a1jzTqJoBC2Mw28_qiQAAAJc"]
[Tue Jul 21 08:41:10.064577 2026] [security2:error] [pid 465652:tid 465853] [client 203.25.124.213:50075] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/edit.php"] [unique_id "al9a1jzTqJoBC2Mw28_qigAAAMw"]
[Tue Jul 21 08:41:10.260830 2026] [security2:error] [pid 465652:tid 465852] [client 213.152.162.15:34444] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9a1jzTqJoBC2Mw28_qjQAAAMs"]
[Tue Jul 21 08:41:10.260939 2026] [security2:error] [pid 465652:tid 465852] [client 213.152.162.15:34444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9a1jzTqJoBC2Mw28_qjQAAAMs"]
[Tue Jul 21 08:41:10.760115 2026] [security2:error] [pid 465652:tid 465794] [client 65.21.113.253:50098] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9a1jzTqJoBC2Mw28_qkQAAAJE"]
[Tue Jul 21 08:41:10.975020 2026] [security2:error] [pid 465652:tid 465837] [client 122.176.100.127:62208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9a1jzTqJoBC2Mw28_qoQAAALw"]
[Tue Jul 21 08:41:10.975158 2026] [security2:error] [pid 465652:tid 465837] [client 122.176.100.127:62208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9a1jzTqJoBC2Mw28_qoQAAALw"]
[Tue Jul 21 08:41:10.994735 2026] [proxy:error] [pid 465652:tid 465782] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:10.994798 2026] [proxy_http:error] [pid 465652:tid 465782] [client 205.210.31.213:57396] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:10.995792 2026] [proxy:error] [pid 465652:tid 465782] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:10.995838 2026] [proxy_http:error] [pid 465652:tid 465782] [client 205.210.31.213:57396] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:11.064755 2026] [security2:error] [pid 465652:tid 465792] [client 212.32.76.9:58825] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/archives/"] [unique_id "al9a1zzTqJoBC2Mw28_qpQAAAI8"]
[Tue Jul 21 08:41:11.157112 2026] [security2:error] [pid 465652:tid 465664] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1zzTqJoBC2Mw28_qsQAAiQs"]
[Tue Jul 21 08:41:11.179212 2026] [security2:error] [pid 465652:tid 465666] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1zzTqJoBC2Mw28_qtAAAiQ0"]
[Tue Jul 21 08:41:11.186311 2026] [security2:error] [pid 465652:tid 465798] [client 20.226.60.151:58521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/0xD.php"] [unique_id "al9a1zzTqJoBC2Mw28_qtQAAAJU"]
[Tue Jul 21 08:41:11.213315 2026] [security2:error] [pid 465652:tid 465732] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1zzTqJoBC2Mw28_qtwAAiU8"]
[Tue Jul 21 08:41:11.272407 2026] [security2:error] [pid 465652:tid 465705] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1zzTqJoBC2Mw28_quwAA6jQ"]
[Tue Jul 21 08:41:11.273598 2026] [security2:error] [pid 465652:tid 465780] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1zzTqJoBC2Mw28_qvAAA3n8"]
[Tue Jul 21 08:41:11.279051 2026] [security2:error] [pid 465652:tid 465698] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1zzTqJoBC2Mw28_qwAAA_S0"]
[Tue Jul 21 08:41:11.279103 2026] [security2:error] [pid 465652:tid 465751] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1zzTqJoBC2Mw28_qvwAA_WI"]
[Tue Jul 21 08:41:11.279138 2026] [security2:error] [pid 465652:tid 465655] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1zzTqJoBC2Mw28_qvgAA_QI"]
[Tue Jul 21 08:41:11.292389 2026] [security2:error] [pid 465652:tid 465775] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1zzTqJoBC2Mw28_qwgABAno"]
[Tue Jul 21 08:41:11.292555 2026] [security2:error] [pid 465652:tid 465702] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1zzTqJoBC2Mw28_qxAABAjE"]
[Tue Jul 21 08:41:11.292619 2026] [security2:error] [pid 465652:tid 465779] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1zzTqJoBC2Mw28_qxwABAn4"]
[Tue Jul 21 08:41:11.292687 2026] [security2:error] [pid 465652:tid 465742] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1zzTqJoBC2Mw28_qwwABAlk"]
[Tue Jul 21 08:41:11.293089 2026] [security2:error] [pid 465652:tid 465778] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/"] [unique_id "al9a1zzTqJoBC2Mw28_qxgABAn0"]
[Tue Jul 21 08:41:11.560082 2026] [security2:error] [pid 465652:tid 465845] [client 20.206.105.145:33663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/f35.update.php"] [unique_id "al9a1zzTqJoBC2Mw28_q0wAAAMQ"]
[Tue Jul 21 08:41:11.578708 2026] [security2:error] [pid 465652:tid 465893] [client 20.220.225.223:54304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/cro.php"] [unique_id "al9a1zzTqJoBC2Mw28_q1AAAAPQ"]
[Tue Jul 21 08:41:11.858151 2026] [security2:error] [pid 465652:tid 465811] [client 5.38.115.39:45297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9a1zzTqJoBC2Mw28_q3QAAAKI"]
[Tue Jul 21 08:41:11.858297 2026] [security2:error] [pid 465652:tid 465811] [client 5.38.115.39:45297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9a1zzTqJoBC2Mw28_q3QAAAKI"]
[Tue Jul 21 08:41:11.975236 2026] [security2:error] [pid 465652:tid 465812] [client 203.25.124.55:44457] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/includes/"] [unique_id "al9a1zzTqJoBC2Mw28_q3wAAAKM"]
[Tue Jul 21 08:41:12.352382 2026] [security2:error] [pid 465652:tid 465820] [client 20.63.100.92:1514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/cron-tab.php"] [unique_id "al9a2DzTqJoBC2Mw28_q6AAAAKs"]
[Tue Jul 21 08:41:12.616483 2026] [security2:error] [pid 465652:tid 465657] [remote 72.167.132.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aud-7.com"] [uri "/wp-login.php"] [unique_id "al9a2DzTqJoBC2Mw28_q8QAA6wQ"]
[Tue Jul 21 08:41:12.775027 2026] [security2:error] [pid 465652:tid 465823] [client 203.25.124.213:54349] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/x.php"] [unique_id "al9a2DzTqJoBC2Mw28_q-wAAAK4"]
[Tue Jul 21 08:41:13.025697 2026] [security2:error] [pid 465652:tid 465896] [client 65.21.113.253:50098] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9a2DzTqJoBC2Mw28_q8AAAAPc"]
[Tue Jul 21 08:41:13.082692 2026] [security2:error] [pid 465652:tid 465905] [client 20.197.192.193:43789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/byp8.php"] [unique_id "al9a2TzTqJoBC2Mw28_rAgAAAQA"]
[Tue Jul 21 08:41:13.623590 2026] [security2:error] [pid 465652:tid 465784] [client 223.181.60.88:25982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9a2TzTqJoBC2Mw28_rEAAAAIc"]
[Tue Jul 21 08:41:13.623795 2026] [security2:error] [pid 465652:tid 465784] [client 223.181.60.88:25982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9a2TzTqJoBC2Mw28_rEAAAAIc"]
[Tue Jul 21 08:41:14.034289 2026] [security2:error] [pid 465652:tid 465861] [client 20.206.105.145:33710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/f900.php"] [unique_id "al9a2jzTqJoBC2Mw28_rGgAAANQ"]
[Tue Jul 21 08:41:14.054119 2026] [security2:error] [pid 465652:tid 465904] [client 20.226.60.151:58581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/fnstall.php"] [unique_id "al9a2jzTqJoBC2Mw28_rHAAAAP8"]
[Tue Jul 21 08:41:14.133750 2026] [security2:error] [pid 465652:tid 465791] [client 202.179.75.202:56244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9a2jzTqJoBC2Mw28_rHgAAAI4"]
[Tue Jul 21 08:41:14.133878 2026] [security2:error] [pid 465652:tid 465791] [client 202.179.75.202:56244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9a2jzTqJoBC2Mw28_rHgAAAI4"]
[Tue Jul 21 08:41:14.263486 2026] [security2:error] [pid 465652:tid 465839] [client 203.25.124.52:31067] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "al9a2jzTqJoBC2Mw28_rJAAAAL4"]
[Tue Jul 21 08:41:14.267879 2026] [security2:error] [pid 465652:tid 465814] [client 69.171.230.16:58068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9a2jzTqJoBC2Mw28_rJQAAAKU"]
[Tue Jul 21 08:41:14.485303 2026] [core:alert] [pid 465652:tid 465883] [client 57.141.18.54:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:41:14.567713 2026] [security2:error] [pid 465652:tid 465822] [client 173.252.95.19:59800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9a2jzTqJoBC2Mw28_rNwAAAK0"]
[Tue Jul 21 08:41:14.608191 2026] [security2:error] [pid 465652:tid 465764] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/dump.sql"] [unique_id "al9a2jzTqJoBC2Mw28_rQAAAmm8"]
[Tue Jul 21 08:41:14.623170 2026] [security2:error] [pid 465652:tid 465820] [client 195.49.128.211:53819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9a2jzTqJoBC2Mw28_rVwAAAKs"]
[Tue Jul 21 08:41:14.623266 2026] [security2:error] [pid 465652:tid 465820] [client 195.49.128.211:53819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9a2jzTqJoBC2Mw28_rVwAAAKs"]
[Tue Jul 21 08:41:14.747001 2026] [security2:error] [pid 465652:tid 465720] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a2jzTqJoBC2Mw28_rdQAAmkM"]
[Tue Jul 21 08:41:14.747125 2026] [security2:error] [pid 465652:tid 465745] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9a2jzTqJoBC2Mw28_reQAAmlw"]
[Tue Jul 21 08:41:14.747136 2026] [core:error] [pid 465652:tid 465662] [remote 103.215.75.19:39626] AH10244: invalid URI path (/dana-na/../dana/html5acc/guacamole/../../../../../../../etc/passwd?/dana/html5acc/guacamole/)
[Tue Jul 21 08:41:14.747972 2026] [security2:error] [pid 465652:tid 465700] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/db.sql"] [unique_id "al9a2jzTqJoBC2Mw28_rZAAAmi8"]
[Tue Jul 21 08:41:14.748182 2026] [security2:error] [pid 465652:tid 465729] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/mysql.sql"] [unique_id "al9a2jzTqJoBC2Mw28_rZQAAmkw"]
[Tue Jul 21 08:41:14.748888 2026] [security2:error] [pid 465652:tid 465750] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/database.sql"] [unique_id "al9a2jzTqJoBC2Mw28_rWwAAmmE"]
[Tue Jul 21 08:41:14.749275 2026] [security2:error] [pid 465652:tid 465656] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/export.sql"] [unique_id "al9a2jzTqJoBC2Mw28_raAAAmgM"]
[Tue Jul 21 08:41:14.749617 2026] [security2:error] [pid 465652:tid 465668] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/backup.sql"] [unique_id "al9a2jzTqJoBC2Mw28_rYwAAmg8"]
[Tue Jul 21 08:41:14.753148 2026] [security2:error] [pid 465652:tid 465719] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/wp-login.php"] [unique_id "al9a2jzTqJoBC2Mw28_rdAAAmkI"]
[Tue Jul 21 08:41:14.753722 2026] [security2:error] [pid 465652:tid 465675] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/wp-login.php"] [unique_id "al9a2jzTqJoBC2Mw28_rYgAAmhY"]
[Tue Jul 21 08:41:14.759199 2026] [security2:error] [pid 465652:tid 465818] [client 61.1.167.83:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a2jzTqJoBC2Mw28_rmgAAAKk"]
[Tue Jul 21 08:41:14.759292 2026] [security2:error] [pid 465652:tid 465818] [client 61.1.167.83:54772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a2jzTqJoBC2Mw28_rmgAAAKk"]
[Tue Jul 21 08:41:14.774877 2026] [security2:error] [pid 465652:tid 465839] [client 64.42.179.43:58134] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9a2jzTqJoBC2Mw28_rpwAAAL4"]
[Tue Jul 21 08:41:14.774981 2026] [security2:error] [pid 465652:tid 465839] [client 64.42.179.43:58134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9a2jzTqJoBC2Mw28_rpwAAAL4"]
[Tue Jul 21 08:41:14.886621 2026] [security2:error] [pid 465652:tid 465689] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php"] [unique_id "al9a2jzTqJoBC2Mw28_rrQAAmiQ"]
[Tue Jul 21 08:41:15.025605 2026] [http2:info] [pid 465652:tid 465803] [client 103.215.75.19:39626] AH10178: h2_stream(465652-1653-383,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:41:15.030739 2026] [security2:error] [pid 465652:tid 465851] [client 103.59.206.240:31029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a2zzTqJoBC2Mw28_ruQAAAMo"]
[Tue Jul 21 08:41:15.030845 2026] [security2:error] [pid 465652:tid 465851] [client 103.59.206.240:31029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a2zzTqJoBC2Mw28_ruQAAAMo"]
[Tue Jul 21 08:41:15.103445 2026] [security2:error] [pid 465652:tid 465889] [client 65.21.113.253:50098] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9a2jzTqJoBC2Mw28_rOAAAAPA"]
[Tue Jul 21 08:41:15.252273 2026] [security2:error] [pid 465652:tid 465836] [client 14.245.224.124:64272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9a2zzTqJoBC2Mw28_ruwAAALs"]
[Tue Jul 21 08:41:15.252480 2026] [security2:error] [pid 465652:tid 465836] [client 14.245.224.124:64272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9a2zzTqJoBC2Mw28_ruwAAALs"]
[Tue Jul 21 08:41:15.432239 2026] [security2:error] [pid 465652:tid 465873] [client 20.206.105.145:33689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/xmrl.php"] [unique_id "al9a2zzTqJoBC2Mw28_rwAAAAOA"]
[Tue Jul 21 08:41:16.164237 2026] [security2:error] [pid 465652:tid 465908] [client 203.25.124.48:26441] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/colors/light/"] [unique_id "al9a3DzTqJoBC2Mw28_r2AAAAQM"]
[Tue Jul 21 08:41:16.270126 2026] [security2:error] [pid 465652:tid 465655] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9a3DzTqJoBC2Mw28_r3AAA6AI"]
[Tue Jul 21 08:41:16.270266 2026] [security2:error] [pid 465652:tid 465881] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9a3DzTqJoBC2Mw28_r3AAA6AI"]
[Tue Jul 21 08:41:16.356512 2026] [security2:error] [pid 465652:tid 465804] [client 20.220.225.223:2369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/cron-tab.php"] [unique_id "al9a3DzTqJoBC2Mw28_r3gAAAJs"]
[Tue Jul 21 08:41:16.363107 2026] [security2:error] [pid 465652:tid 465894] [client 168.167.81.163:59696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9a3DzTqJoBC2Mw28_r3wAAAPU"]
[Tue Jul 21 08:41:16.363229 2026] [security2:error] [pid 465652:tid 465894] [client 168.167.81.163:59696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9a3DzTqJoBC2Mw28_r3wAAAPU"]
[Tue Jul 21 08:41:16.556179 2026] [security2:error] [pid 465652:tid 465905] [client 20.226.60.151:58584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/acp.php"] [unique_id "al9a3DzTqJoBC2Mw28_r6gAAAQA"]
[Tue Jul 21 08:41:16.576410 2026] [security2:error] [pid 465652:tid 465824] [client 152.59.181.104:63135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9a3DzTqJoBC2Mw28_r7AAAAK8"]
[Tue Jul 21 08:41:16.576525 2026] [security2:error] [pid 465652:tid 465824] [client 152.59.181.104:63135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9a3DzTqJoBC2Mw28_r7AAAAK8"]
[Tue Jul 21 08:41:16.584658 2026] [core:error] [pid 465652:tid 465760] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/.env)
[Tue Jul 21 08:41:16.584658 2026] [core:error] [pid 465652:tid 465673] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/usr/share/nginx/html/.env)
[Tue Jul 21 08:41:16.584678 2026] [core:error] [pid 465652:tid 465734] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/srv/http/html/.env)
[Tue Jul 21 08:41:16.584683 2026] [core:error] [pid 465652:tid 465670] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/www/wwwroot/.env)
[Tue Jul 21 08:41:16.584760 2026] [core:error] [pid 465652:tid 465671] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/data/www/.env)
[Tue Jul 21 08:41:16.585183 2026] [core:error] [pid 465652:tid 465738] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/www/html/.env)
[Tue Jul 21 08:41:16.585333 2026] [core:error] [pid 465652:tid 465753] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/app/.env)
[Tue Jul 21 08:41:16.585421 2026] [core:error] [pid 465652:tid 465774] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/.env)
[Tue Jul 21 08:41:16.723349 2026] [core:error] [pid 465652:tid 465678] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/usr/local/apache2/htdocs/.env)
[Tue Jul 21 08:41:16.723349 2026] [core:error] [pid 465652:tid 465768] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/public/.env)
[Tue Jul 21 08:41:16.723349 2026] [core:error] [pid 465652:tid 465706] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/srv/www/html/.env)
[Tue Jul 21 08:41:16.723349 2026] [core:error] [pid 465652:tid 465747] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/srv/www/.env)
[Tue Jul 21 08:41:16.723359 2026] [core:error] [pid 465652:tid 465713] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/laravel/.env)
[Tue Jul 21 08:41:16.723667 2026] [core:error] [pid 465652:tid 465665] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/app/public/../.env)
[Tue Jul 21 08:41:16.723762 2026] [core:error] [pid 465652:tid 465766] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/opt/app/.env)
[Tue Jul 21 08:41:16.723873 2026] [core:error] [pid 465652:tid 465688] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/usr/local/www/apache24/data/.env)
[Tue Jul 21 08:41:16.724414 2026] [security2:error] [pid 465652:tid 465701] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a3DzTqJoBC2Mw28_sKAAA7zA"]
[Tue Jul 21 08:41:16.725713 2026] [security2:error] [pid 465652:tid 465701] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "al9a3DzTqJoBC2Mw28_sLgAA7zA"]
[Tue Jul 21 08:41:16.735364 2026] [security2:error] [pid 465652:tid 465857] [client 198.44.157.34:34808] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9a3DzTqJoBC2Mw28_sUAAAANA"]
[Tue Jul 21 08:41:16.735463 2026] [security2:error] [pid 465652:tid 465857] [client 198.44.157.34:34808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9a3DzTqJoBC2Mw28_sUAAAANA"]
[Tue Jul 21 08:41:16.863197 2026] [security2:error] [pid 465652:tid 465755] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a3DzTqJoBC2Mw28_sawAA72Y"]
[Tue Jul 21 08:41:16.980161 2026] [security2:error] [pid 465652:tid 465851] [client 20.220.225.223:12554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/wpx.php"] [unique_id "al9a3DzTqJoBC2Mw28_scQAAAMo"]
[Tue Jul 21 08:41:17.003273 2026] [http2:info] [pid 465652:tid 465888] [client 103.215.75.19:39626] AH10178: h2_stream(465652-1653-471,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:41:17.040060 2026] [security2:error] [pid 465652:tid 465855] [client 198.44.157.34:34812] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9a3TzTqJoBC2Mw28_scwAAAM4"]
[Tue Jul 21 08:41:17.040143 2026] [security2:error] [pid 465652:tid 465855] [client 198.44.157.34:34812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9a3TzTqJoBC2Mw28_scwAAAM4"]
[Tue Jul 21 08:41:17.049624 2026] [security2:error] [pid 465652:tid 465869] [client 20.206.105.145:33652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/memberfuns.php"] [unique_id "al9a3TzTqJoBC2Mw28_sdQAAANw"]
[Tue Jul 21 08:41:17.122713 2026] [security2:error] [pid 465652:tid 465802] [client 65.21.113.253:50098] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9a3DzTqJoBC2Mw28_r7QAAAJk"]
[Tue Jul 21 08:41:17.168009 2026] [access_compat:error] [pid 465652:tid 465889] [client 162.241.63.68:33408] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:41:17.231658 2026] [security2:error] [pid 465652:tid 465805] [client 173.252.95.1:57114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9a3TzTqJoBC2Mw28_sewAAAJw"]
[Tue Jul 21 08:41:17.314449 2026] [security2:error] [pid 465652:tid 465850] [client 195.206.105.227:54998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9a3TzTqJoBC2Mw28_sfAAAAMk"]
[Tue Jul 21 08:41:17.314546 2026] [security2:error] [pid 465652:tid 465850] [client 195.206.105.227:54998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9a3TzTqJoBC2Mw28_sfAAAAMk"]
[Tue Jul 21 08:41:17.725930 2026] [security2:error] [pid 465652:tid 465793] [client 69.171.230.28:33820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9a3TzTqJoBC2Mw28_siQAAAJA"]
[Tue Jul 21 08:41:17.759440 2026] [security2:error] [pid 465652:tid 465827] [client 195.49.128.211:61803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9a3TzTqJoBC2Mw28_sigAAALI"]
[Tue Jul 21 08:41:17.759586 2026] [security2:error] [pid 465652:tid 465827] [client 195.49.128.211:61803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9a3TzTqJoBC2Mw28_sigAAALI"]
[Tue Jul 21 08:41:17.957967 2026] [security2:error] [pid 465652:tid 465796] [client 203.25.124.213:26013] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin.php"] [unique_id "al9a3TzTqJoBC2Mw28_sjQAAAJM"]
[Tue Jul 21 08:41:18.072494 2026] [security2:error] [pid 465652:tid 465823] [client 20.206.105.145:33677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/ms.php"] [unique_id "al9a3jzTqJoBC2Mw28_skgAAAK4"]
[Tue Jul 21 08:41:18.144357 2026] [security2:error] [pid 465652:tid 465837] [client 20.197.192.193:43810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/user.php"] [unique_id "al9a3jzTqJoBC2Mw28_slgAAALw"]
[Tue Jul 21 08:41:18.327606 2026] [security2:error] [pid 465652:tid 465874] [client 173.252.95.10:64894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9a3jzTqJoBC2Mw28_smAAAAOE"]
[Tue Jul 21 08:41:18.450293 2026] [core:error] [pid 465652:tid 465750] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/public_html/.env)
[Tue Jul 21 08:41:18.459939 2026] [security2:error] [pid 465652:tid 465656] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/wp-config.php"] [unique_id "al9a3jzTqJoBC2Mw28_snQAA3AM"]
[Tue Jul 21 08:41:18.464082 2026] [security2:error] [pid 465652:tid 465668] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/config/database.php"] [unique_id "al9a3jzTqJoBC2Mw28_sngAA3A8"]
[Tue Jul 21 08:41:18.470329 2026] [security2:error] [pid 465652:tid 465675] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/application/database.php"] [unique_id "al9a3jzTqJoBC2Mw28_snwAA3BY"]
[Tue Jul 21 08:41:18.471822 2026] [core:error] [pid 465652:tid 465719] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/laravel/.env)
[Tue Jul 21 08:41:18.483118 2026] [core:error] [pid 465652:tid 465679] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/api/.env)
[Tue Jul 21 08:41:18.490607 2026] [core:error] [pid 465652:tid 465710] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/app/.env)
[Tue Jul 21 08:41:18.493643 2026] [core:error] [pid 465652:tid 465737] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/vhosts/.env)
[Tue Jul 21 08:41:18.562323 2026] [security2:error] [pid 465652:tid 465769] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9a3jzTqJoBC2Mw28_stQAAmnQ"]
[Tue Jul 21 08:41:18.562447 2026] [security2:error] [pid 465652:tid 465803] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9a3jzTqJoBC2Mw28_stQAAmnQ"]
[Tue Jul 21 08:41:18.600218 2026] [core:error] [pid 465652:tid 465776] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/backend/.env)
[Tue Jul 21 08:41:18.600257 2026] [core:error] [pid 465652:tid 465691] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/home/ubuntu/.env)
[Tue Jul 21 08:41:18.600269 2026] [core:error] [pid 465652:tid 465752] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/root/.env)
[Tue Jul 21 08:41:18.600442 2026] [core:error] [pid 465652:tid 465749] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/app/config/parameters.yml)
[Tue Jul 21 08:41:18.600488 2026] [core:error] [pid 465652:tid 465777] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/app/.env)
[Tue Jul 21 08:41:18.600658 2026] [core:error] [pid 465652:tid 465754] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/app/config/parameters.yml)
[Tue Jul 21 08:41:18.600883 2026] [core:error] [pid 465652:tid 465689] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/api/.env)
[Tue Jul 21 08:41:18.601288 2026] [core:error] [pid 465652:tid 465712] [remote 103.215.75.19:39626] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/.env.local)
[Tue Jul 21 08:41:18.601792 2026] [security2:error] [pid 465652:tid 465669] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/vendor/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9a3jzTqJoBC2Mw28_s1AAAwBA"]
[Tue Jul 21 08:41:18.601924 2026] [security2:error] [pid 465652:tid 465716] [remote 103.215.75.19:39626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a3jzTqJoBC2Mw28_s1QAAwD8"]
[Tue Jul 21 08:41:18.603516 2026] [access_compat:error] [pid 465652:tid 465743] [remote 103.215.75.19:39626] AH01797: client denied by server configuration: proxy:http://127.0.0.1/cgi-sys/autodiscover.cgi
[Tue Jul 21 08:41:18.631108 2026] [security2:error] [pid 465652:tid 465906] [client 117.213.202.34:59936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a3jzTqJoBC2Mw28_tFAAAAQE"]
[Tue Jul 21 08:41:18.631235 2026] [security2:error] [pid 465652:tid 465906] [client 117.213.202.34:59936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a3jzTqJoBC2Mw28_tFAAAAQE"]
[Tue Jul 21 08:41:18.869530 2026] [security2:error] [pid 465652:tid 465797] [client 212.32.76.7:28655] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wa/"] [unique_id "al9a3jzTqJoBC2Mw28_tHAAAAJQ"]
[Tue Jul 21 08:41:18.911299 2026] [http2:info] [pid 465652:tid 465841] [client 103.215.75.19:39626] AH10178: h2_stream(465652-1653-559,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:41:19.030150 2026] [core:error] [pid 465652:tid 465783] (104)Connection reset by peer: [client 127.0.0.1:20430] AH00574: ap_content_length_filter: apr_bucket_read() failed
[Tue Jul 21 08:41:19.030234 2026] [proxy_http:error] [pid 465652:tid 465837] (70008)Partial results are valid but processing is incomplete: [client 127.0.0.1:20414] AH01110: error reading response
[Tue Jul 21 08:41:19.086917 2026] [security2:error] [pid 465652:tid 465813] [client 173.252.95.58:33830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9a3zzTqJoBC2Mw28_tHQAAAKQ"]
[Tue Jul 21 08:41:19.573180 2026] [security2:error] [pid 465652:tid 465884] [client 20.206.105.145:33667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/zz.php"] [unique_id "al9a3zzTqJoBC2Mw28_tMwAAAOs"]
[Tue Jul 21 08:41:19.604358 2026] [security2:error] [pid 465652:tid 465888] [client 113.22.144.139:61400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a3zzTqJoBC2Mw28_tNQAAAO8"]
[Tue Jul 21 08:41:19.604485 2026] [security2:error] [pid 465652:tid 465888] [client 113.22.144.139:61400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a3zzTqJoBC2Mw28_tNQAAAO8"]
[Tue Jul 21 08:41:19.683874 2026] [security2:error] [pid 465652:tid 465862] [client 49.144.66.253:31423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9a3zzTqJoBC2Mw28_tOgAAANU"]
[Tue Jul 21 08:41:19.684026 2026] [security2:error] [pid 465652:tid 465862] [client 49.144.66.253:31423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9a3zzTqJoBC2Mw28_tOgAAANU"]
[Tue Jul 21 08:41:20.207284 2026] [security2:error] [pid 465652:tid 465839] [client 59.95.197.55:61894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a4DzTqJoBC2Mw28_tQAAAAL4"]
[Tue Jul 21 08:41:20.207713 2026] [security2:error] [pid 465652:tid 465839] [client 59.95.197.55:61894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a4DzTqJoBC2Mw28_tQAAAAL4"]
[Tue Jul 21 08:41:20.563233 2026] [http2:info] [pid 511108:tid 511108] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 08:41:20.582979 2026] [security2:error] [pid 511108:tid 511238] [client 20.220.225.223:40753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/koiy.php"] [unique_id "al9a4ITd5soprXwxAH3lrAAAAAA"]
[Tue Jul 21 08:41:20.584506 2026] [security2:error] [pid 511108:tid 511242] [client 20.197.192.193:65214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/ops.php"] [unique_id "al9a4ITd5soprXwxAH3lrQAAAAQ"]
[Tue Jul 21 08:41:20.720440 2026] [security2:error] [pid 511108:tid 511252] [client 74.7.230.28:42560] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.clinicaviva.bravacomunicacao.com"] [uri "/cgi-sys/404.html"] [unique_id "al9a4ITd5soprXwxAH3lswAADgM"]
[Tue Jul 21 08:41:20.724922 2026] [security2:error] [pid 511108:tid 511121] [remote 103.215.75.19:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a4ITd5soprXwxAH3lvgAAGQw"]
[Tue Jul 21 08:41:20.724935 2026] [security2:error] [pid 511108:tid 511120] [remote 103.215.75.19:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/var/www/html/wp-config.php"] [unique_id "al9a4ITd5soprXwxAH3lvQAAGQs"]
[Tue Jul 21 08:41:20.724974 2026] [security2:error] [pid 511108:tid 511122] [remote 103.215.75.19:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9a4ITd5soprXwxAH3lvwAAGQ0"]
[Tue Jul 21 08:41:20.725058 2026] [autoindex:error] [pid 511108:tid 511113] [remote 74.7.243.225:53132] AH01276: Cannot serve directory /home1/bravac03/clinicaviva.bravacomunicacao.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:41:20.734436 2026] [security2:error] [pid 511108:tid 511243] [client 173.252.95.58:33846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9a4ITd5soprXwxAH3lwwAAAAU"]
[Tue Jul 21 08:41:20.838560 2026] [security2:error] [pid 511108:tid 511260] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9a4ITd5soprXwxAH3lxgAAFhA"]
[Tue Jul 21 08:41:21.272664 2026] [security2:error] [pid 511108:tid 511359] [client 20.206.105.145:33646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/for.php"] [unique_id "al9a4YTd5soprXwxAH3l1wAAAHk"]
[Tue Jul 21 08:41:21.511114 2026] [security2:error] [pid 511108:tid 511340] [client 122.176.100.127:62724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9a4YTd5soprXwxAH3l3wAAAGY"]
[Tue Jul 21 08:41:21.511379 2026] [security2:error] [pid 511108:tid 511340] [client 122.176.100.127:62724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9a4YTd5soprXwxAH3l3wAAAGY"]
[Tue Jul 21 08:41:21.886993 2026] [security2:error] [pid 511108:tid 511266] [client 20.220.225.223:12584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/berlin.php"] [unique_id "al9a4YTd5soprXwxAH3l5wAAABw"]
[Tue Jul 21 08:41:22.231837 2026] [security2:error] [pid 511108:tid 511146] [remote 103.215.75.19:56724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/.env"] [unique_id "al9a4oTd5soprXwxAH3l8gAALiU"]
[Tue Jul 21 08:41:22.232964 2026] [security2:error] [pid 511108:tid 511147] [remote 103.215.75.19:56724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/media../.env"] [unique_id "al9a4oTd5soprXwxAH3l8wAALiY"]
[Tue Jul 21 08:41:22.236369 2026] [security2:error] [pid 511108:tid 511148] [remote 103.215.75.19:56724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/uploads../.env"] [unique_id "al9a4oTd5soprXwxAH3l9AAAKic"]
[Tue Jul 21 08:41:22.287398 2026] [security2:error] [pid 511108:tid 511149] [remote 103.215.75.19:56724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/files../.env"] [unique_id "al9a4oTd5soprXwxAH3l9QAAMSg"]
[Tue Jul 21 08:41:22.302751 2026] [security2:error] [pid 511108:tid 511288] [client 20.206.105.145:33718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/yup.php"] [unique_id "al9a4oTd5soprXwxAH3l9gAAADI"]
[Tue Jul 21 08:41:22.340906 2026] [security2:error] [pid 511108:tid 511152] [remote 103.215.75.19:56724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/img../.env"] [unique_id "al9a4oTd5soprXwxAH3l-AAAOCs"]
[Tue Jul 21 08:41:22.341769 2026] [security2:error] [pid 511108:tid 511151] [remote 103.215.75.19:56724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/public../.env"] [unique_id "al9a4oTd5soprXwxAH3l-QAAOCo"]
[Tue Jul 21 08:41:22.411594 2026] [security2:error] [pid 511108:tid 511156] [remote 103.215.75.19:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9a4oTd5soprXwxAH3mAQAANS8"]
[Tue Jul 21 08:41:22.435020 2026] [security2:error] [pid 511108:tid 511252] [client 5.31.193.106:29991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9a4oTd5soprXwxAH3mAgAAAA4"]
[Tue Jul 21 08:41:22.435174 2026] [security2:error] [pid 511108:tid 511252] [client 5.31.193.106:29991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9a4oTd5soprXwxAH3mAgAAAA4"]
[Tue Jul 21 08:41:22.495974 2026] [security2:error] [pid 511108:tid 511328] [client 20.226.60.151:58516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/mosty.php"] [unique_id "al9a4oTd5soprXwxAH3mBgAAAFo"]
[Tue Jul 21 08:41:22.611069 2026] [security2:error] [pid 511108:tid 511264] [client 5.38.115.39:57168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9a4oTd5soprXwxAH3mDAAAABo"]
[Tue Jul 21 08:41:22.611182 2026] [security2:error] [pid 511108:tid 511264] [client 5.38.115.39:57168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9a4oTd5soprXwxAH3mDAAAABo"]
[Tue Jul 21 08:41:22.621530 2026] [security2:error] [pid 511108:tid 511161] [remote 103.215.75.19:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/static../../var/www/html/wp-config.php"] [unique_id "al9a4oTd5soprXwxAH3mDwAAazQ"]
[Tue Jul 21 08:41:22.621548 2026] [security2:error] [pid 511108:tid 511162] [remote 103.215.75.19:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/assets../../var/www/html/wp-config.php"] [unique_id "al9a4oTd5soprXwxAH3mEAAAazU"]
[Tue Jul 21 08:41:22.622489 2026] [security2:error] [pid 511108:tid 511348] [client 4.204.201.85:17009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9a4oTd5soprXwxAH3mDgAAAG4"]
[Tue Jul 21 08:41:22.622901 2026] [security2:error] [pid 511108:tid 511163] [remote 103.215.75.19:56724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.gradiente.com"] [uri "/.env"] [unique_id "al9a4oTd5soprXwxAH3mEQAAazY"]
[Tue Jul 21 08:41:22.764537 2026] [security2:error] [pid 511108:tid 511311] [client 212.32.76.7:54265] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-file.php"] [unique_id "al9a4oTd5soprXwxAH3mFwAAAEk"]
[Tue Jul 21 08:41:22.835568 2026] [security2:error] [pid 511108:tid 511253] [client 20.220.225.223:48902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/hp2.php"] [unique_id "al9a4oTd5soprXwxAH3mHgAAAA8"]
[Tue Jul 21 08:41:22.971853 2026] [security2:error] [pid 511108:tid 511261] [client 172.234.215.24:53472] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "reserveseulugar.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9a4oTd5soprXwxAH3mIwAAABc"]
[Tue Jul 21 08:41:23.068527 2026] [http2:info] [pid 511108:tid 511324] [client 103.215.75.19:57026] AH10178: h2_stream(511108-71-5,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:41:23.115860 2026] [security2:error] [pid 511108:tid 511272] [client 172.234.215.24:53472] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "reserveseulugar.com.br"] [uri "/"] [unique_id "al9a44Td5soprXwxAH3mKAAAACI"]
[Tue Jul 21 08:41:23.206561 2026] [security2:error] [pid 511108:tid 511290] [client 4.204.201.85:16934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9a44Td5soprXwxAH3mLQAAADQ"]
[Tue Jul 21 08:41:23.792569 2026] [security2:error] [pid 511108:tid 511339] [client 20.220.225.223:54320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/hp3.php"] [unique_id "al9a44Td5soprXwxAH3mOwAAAGU"]
[Tue Jul 21 08:41:23.966440 2026] [core:error] [pid 511108:tid 511180] [remote 103.215.75.19:57026] AH10244: invalid URI path (/icons/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/etc/passwd)
[Tue Jul 21 08:41:23.966538 2026] [core:error] [pid 511108:tid 511179] [remote 103.215.75.19:57026] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/etc/passwd)
[Tue Jul 21 08:41:23.966643 2026] [core:error] [pid 511108:tid 511181] [remote 103.215.75.19:57026] AH10244: invalid URI path (/static../../../../../etc/passwd)
[Tue Jul 21 08:41:23.972295 2026] [security2:error] [pid 511108:tid 511344] [client 4.204.201.85:16995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/media.php"] [unique_id "al9a44Td5soprXwxAH3mRgAAAGo"]
[Tue Jul 21 08:41:24.019253 2026] [core:error] [pid 511108:tid 511183] [remote 103.215.75.19:57026] AH10244: invalid URI path (/assets../../../../../etc/passwd)
[Tue Jul 21 08:41:24.120753 2026] [security2:error] [pid 511108:tid 511186] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9a5ITd5soprXwxAH3mUAAADE0"]
[Tue Jul 21 08:41:24.360978 2026] [security2:error] [pid 511108:tid 511320] [client 203.25.124.42:47615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/info.php"] [unique_id "al9a5ITd5soprXwxAH3mXAAAAFI"]
[Tue Jul 21 08:41:24.399862 2026] [security2:error] [pid 511108:tid 511193] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a5ITd5soprXwxAH3mZAAAQVQ"]
[Tue Jul 21 08:41:24.566187 2026] [http2:info] [pid 511108:tid 511272] [client 103.215.75.19:57026] AH10178: h2_stream(511108-71-23,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:41:24.568292 2026] [security2:error] [pid 511108:tid 511256] [client 20.206.105.145:33536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/wpxml.php"] [unique_id "al9a5ITd5soprXwxAH3mZQAAABI"]
[Tue Jul 21 08:41:24.585384 2026] [security2:error] [pid 511108:tid 511283] [client 4.204.201.85:16984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/images.php"] [unique_id "al9a5ITd5soprXwxAH3maQAAAC0"]
[Tue Jul 21 08:41:24.686510 2026] [security2:error] [pid 511108:tid 511347] [client 223.181.60.88:31155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9a5ITd5soprXwxAH3mcAAAAG0"]
[Tue Jul 21 08:41:24.686684 2026] [security2:error] [pid 511108:tid 511347] [client 223.181.60.88:31155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9a5ITd5soprXwxAH3mcAAAAG0"]
[Tue Jul 21 08:41:25.008696 2026] [security2:error] [pid 511108:tid 511287] [client 202.179.75.202:52432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9a5YTd5soprXwxAH3mdwAAADE"]
[Tue Jul 21 08:41:25.008863 2026] [security2:error] [pid 511108:tid 511287] [client 202.179.75.202:52432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9a5YTd5soprXwxAH3mdwAAADE"]
[Tue Jul 21 08:41:25.242462 2026] [security2:error] [pid 511108:tid 511350] [client 20.220.225.223:47748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/aa1.php"] [unique_id "al9a5YTd5soprXwxAH3mgAAAAHA"]
[Tue Jul 21 08:41:25.269962 2026] [security2:error] [pid 511108:tid 511338] [client 212.32.76.12:44895] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/ID3/"] [unique_id "al9a5YTd5soprXwxAH3mggAAAGQ"]
[Tue Jul 21 08:41:25.293278 2026] [security2:error] [pid 511108:tid 511318] [client 195.49.128.211:54420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9a5YTd5soprXwxAH3mgwAAAFA"]
[Tue Jul 21 08:41:25.293419 2026] [security2:error] [pid 511108:tid 511318] [client 195.49.128.211:54420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9a5YTd5soprXwxAH3mgwAAAFA"]
[Tue Jul 21 08:41:25.455427 2026] [security2:error] [pid 511108:tid 511355] [client 20.226.60.151:58507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/6.php"] [unique_id "al9a5YTd5soprXwxAH3miQAAAHU"]
[Tue Jul 21 08:41:25.528588 2026] [security2:error] [pid 511108:tid 511251] [client 4.204.201.85:16944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/gecko.php"] [unique_id "al9a5YTd5soprXwxAH3miwAAAA0"]
[Tue Jul 21 08:41:25.779003 2026] [security2:error] [pid 511108:tid 511211] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9a5YTd5soprXwxAH3mlAAAZmY"]
[Tue Jul 21 08:41:25.985860 2026] [security2:error] [pid 511108:tid 511365] [client 14.245.224.124:64755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.224.245.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9a5YTd5soprXwxAH3mmgAAAH8"]
[Tue Jul 21 08:41:25.985985 2026] [security2:error] [pid 511108:tid 511365] [client 14.245.224.124:64755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ocaminhodarecuperacao.com"] [uri "/xmlrpc.php"] [unique_id "al9a5YTd5soprXwxAH3mmgAAAH8"]
[Tue Jul 21 08:41:26.197831 2026] [cgid:error] [pid 511108:tid 511326] (32)Broken pipe: [client 127.0.0.1:32278] AH02651: Error writing request body to script /usr/local/cpanel/cgi-sys/autodiscover.cgi
[Tue Jul 21 08:41:26.197875 2026] [core:error] [pid 511108:tid 511326] (104)Connection reset by peer: [client 127.0.0.1:32278] AH00574: ap_content_length_filter: apr_bucket_read() failed
[Tue Jul 21 08:41:26.198027 2026] [proxy_http:error] [pid 511108:tid 511296] (20014)Internal error (specific information not available): [client 127.0.0.1:32266] AH01102: error reading status line from remote server 127.0.0.1:80
[Tue Jul 21 08:41:26.198038 2026] [proxy:error] [pid 511108:tid 511296] [client 127.0.0.1:32266] AH00898: Error reading from remote server returned by /cgi-sys/autodiscover.cgi
[Tue Jul 21 08:41:26.209918 2026] [security2:error] [pid 511108:tid 511292] [client 78.46.190.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9a5oTd5soprXwxAH3mpQAANnA"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:41:26.216730 2026] [security2:error] [pid 511108:tid 511304] [client 20.63.100.92:3457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/koiy.php"] [unique_id "al9a5oTd5soprXwxAH3mrAAAAEI"]
[Tue Jul 21 08:41:26.447554 2026] [security2:error] [pid 511108:tid 511344] [client 20.197.192.193:65215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/term.php"] [unique_id "al9a5oTd5soprXwxAH3mtAAAAGo"]
[Tue Jul 21 08:41:26.467636 2026] [security2:error] [pid 511108:tid 511341] [client 203.25.124.67:55611] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/index/function.php"] [unique_id "al9a5oTd5soprXwxAH3mtQAAAGc"]
[Tue Jul 21 08:41:26.484452 2026] [security2:error] [pid 511108:tid 511343] [client 4.204.201.85:16900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/82.php"] [unique_id "al9a5oTd5soprXwxAH3mtgAAAGk"]
[Tue Jul 21 08:41:26.648210 2026] [security2:error] [pid 511108:tid 511283] [client 103.59.206.240:31463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a5oTd5soprXwxAH3mugAAAC0"]
[Tue Jul 21 08:41:26.648326 2026] [security2:error] [pid 511108:tid 511283] [client 103.59.206.240:31463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a5oTd5soprXwxAH3mugAAAC0"]
[Tue Jul 21 08:41:26.759586 2026] [security2:error] [pid 511108:tid 511300] [client 195.206.105.227:48364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9a5oTd5soprXwxAH3mxAAAAD4"]
[Tue Jul 21 08:41:26.759677 2026] [security2:error] [pid 511108:tid 511300] [client 195.206.105.227:48364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9a5oTd5soprXwxAH3mxAAAAD4"]
[Tue Jul 21 08:41:26.764187 2026] [security2:error] [pid 511108:tid 511278] [client 78.46.190.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9a5oTd5soprXwxAH3mxQAAKHk"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:41:26.787439 2026] [security2:error] [pid 511108:tid 511232] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9a5oTd5soprXwxAH3mxwAAGns"]
[Tue Jul 21 08:41:26.787587 2026] [security2:error] [pid 511108:tid 511264] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9a5oTd5soprXwxAH3mxwAAGns"]
[Tue Jul 21 08:41:27.256727 2026] [security2:error] [pid 511108:tid 511110] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9a54Td5soprXwxAH3mzwAATAE"]
[Tue Jul 21 08:41:27.265951 2026] [security2:error] [pid 511108:tid 511316] [client 20.197.192.193:43779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/ah25.php"] [unique_id "al9a54Td5soprXwxAH3m0QAAAE4"]
[Tue Jul 21 08:41:27.385054 2026] [security2:error] [pid 511108:tid 511294] [client 91.230.225.185:52273] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/ms-themes.php"] [unique_id "al9a54Td5soprXwxAH3m2AAAADg"]
[Tue Jul 21 08:41:27.405945 2026] [security2:error] [pid 511108:tid 511249] [client 168.167.81.163:60956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9a54Td5soprXwxAH3m2QAAAAs"]
[Tue Jul 21 08:41:27.406065 2026] [security2:error] [pid 511108:tid 511249] [client 168.167.81.163:60956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9a54Td5soprXwxAH3m2QAAAAs"]
[Tue Jul 21 08:41:27.464420 2026] [security2:error] [pid 511108:tid 511297] [client 4.204.201.85:16924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/admin.php"] [unique_id "al9a54Td5soprXwxAH3m2gAAADs"]
[Tue Jul 21 08:41:27.565157 2026] [security2:error] [pid 511108:tid 511274] [client 152.59.181.104:37512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9a54Td5soprXwxAH3m2wAAACQ"]
[Tue Jul 21 08:41:27.565254 2026] [security2:error] [pid 511108:tid 511274] [client 152.59.181.104:37512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9a54Td5soprXwxAH3m2wAAACQ"]
[Tue Jul 21 08:41:27.597392 2026] [security2:error] [pid 511108:tid 511248] [client 20.206.105.145:33634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/fffm.php"] [unique_id "al9a54Td5soprXwxAH3m3AAAAAo"]
[Tue Jul 21 08:41:27.774733 2026] [core:error] [pid 511108:tid 511281] (104)Connection reset by peer: [client 127.0.0.1:32340] AH00574: ap_content_length_filter: apr_bucket_read() failed
[Tue Jul 21 08:41:27.774934 2026] [proxy_http:error] [pid 511108:tid 511333] (70008)Partial results are valid but processing is incomplete: [client 127.0.0.1:32334] AH01110: error reading response
[Tue Jul 21 08:41:27.775089 2026] [proxy_http:error] [pid 511108:tid 511121] (70008)Partial results are valid but processing is incomplete: [remote 103.215.75.19:57026] AH01110: error reading response
[Tue Jul 21 08:41:27.777168 2026] [security2:error] [pid 511108:tid 511304] [client 173.252.95.10:45632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9a54Td5soprXwxAH3m7gAAAEI"]
[Tue Jul 21 08:41:27.792323 2026] [security2:error] [pid 511108:tid 511313] [client 173.252.95.19:37814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9a54Td5soprXwxAH3m7wAAAEs"]
[Tue Jul 21 08:41:27.999570 2026] [security2:error] [pid 511108:tid 511355] [client 4.204.201.85:1491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/adminner.php"] [unique_id "al9a54Td5soprXwxAH3m9AAAAHU"]
[Tue Jul 21 08:41:28.067630 2026] [security2:error] [pid 511108:tid 511356] [client 51.68.236.87:11891] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oppbrazil.com.br"] [uri "/robots.txt"] [unique_id "al9a6ITd5soprXwxAH3m9QAAAHY"]
[Tue Jul 21 08:41:28.067774 2026] [security2:error] [pid 511108:tid 511356] [client 51.68.236.87:11891] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "oppbrazil.com.br"] [uri "/robots.txt"] [unique_id "al9a6ITd5soprXwxAH3m9QAAAHY"]
[Tue Jul 21 08:41:28.132061 2026] [security2:error] [pid 511108:tid 511364] [client 185.92.25.111:60241] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/chosen.php"] [unique_id "al9a6ITd5soprXwxAH3m9wAAAH4"]
[Tue Jul 21 08:41:28.272024 2026] [security2:error] [pid 511108:tid 511359] [client 20.220.225.223:46951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/acew67.php"] [unique_id "al9a6ITd5soprXwxAH3m_wAAAHk"]
[Tue Jul 21 08:41:28.415828 2026] [security2:error] [pid 511108:tid 511251] [client 195.49.128.211:62566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9a6ITd5soprXwxAH3nAwAAAA0"]
[Tue Jul 21 08:41:28.415955 2026] [security2:error] [pid 511108:tid 511251] [client 195.49.128.211:62566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9a6ITd5soprXwxAH3nAwAAAA0"]
[Tue Jul 21 08:41:28.605319 2026] [security2:error] [pid 511108:tid 511258] [client 91.230.225.1:60867] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/file.php"] [unique_id "al9a6ITd5soprXwxAH3nDQAAABQ"]
[Tue Jul 21 08:41:28.635020 2026] [security2:error] [pid 511108:tid 511135] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9a6ITd5soprXwxAH3nDgAACBo"]
[Tue Jul 21 08:41:28.640328 2026] [security2:error] [pid 511108:tid 511243] [client 20.220.225.223:2419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/bscclapb.php"] [unique_id "al9a6ITd5soprXwxAH3nDwAAAAU"]
[Tue Jul 21 08:41:28.670427 2026] [security2:error] [pid 511108:tid 511320] [client 4.204.201.85:17000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/admin.php"] [unique_id "al9a6ITd5soprXwxAH3nEAAAAFI"]
[Tue Jul 21 08:41:28.813841 2026] [security2:error] [pid 511108:tid 511291] [client 20.226.60.151:58594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/32e17094cfindex.php"] [unique_id "al9a6ITd5soprXwxAH3nFwAAADU"]
[Tue Jul 21 08:41:28.846908 2026] [security2:error] [pid 511108:tid 511274] [client 20.220.225.223:12323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/billur.php"] [unique_id "al9a6ITd5soprXwxAH3nGAAAACQ"]
[Tue Jul 21 08:41:28.959505 2026] [security2:error] [pid 511108:tid 511287] [client 203.25.124.71:43665] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/upgrade/"] [unique_id "al9a6ITd5soprXwxAH3nGwAAADE"]
[Tue Jul 21 08:41:28.971168 2026] [security2:error] [pid 511108:tid 511279] [client 20.206.105.145:33622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/gecko.php"] [unique_id "al9a6ITd5soprXwxAH3nHQAAACk"]
[Tue Jul 21 08:41:28.988493 2026] [security2:error] [pid 511108:tid 511141] [remote 67.20.76.238:14130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.76.20.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deals-ecomm.shop"] [uri "/wp-login.php"] [unique_id "al9a6ITd5soprXwxAH3nIAAAYiA"]
[Tue Jul 21 08:41:29.013387 2026] [security2:error] [pid 511108:tid 511252] [client 185.192.71.6:23111] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/flower.php"] [unique_id "al9a6YTd5soprXwxAH3nJAAAAA4"]
[Tue Jul 21 08:41:29.148145 2026] [security2:error] [pid 511108:tid 511144] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a6YTd5soprXwxAH3nJQAAaiM"]
[Tue Jul 21 08:41:29.335058 2026] [security2:error] [pid 511108:tid 511149] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9a6YTd5soprXwxAH3nKwAAPyg"]
[Tue Jul 21 08:41:29.335184 2026] [security2:error] [pid 511108:tid 511301] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9a6YTd5soprXwxAH3nKwAAPyg"]
[Tue Jul 21 08:41:29.417613 2026] [security2:error] [pid 511108:tid 511240] [client 78.46.190.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9a6YTd5soprXwxAH3nLwAAAio"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:41:29.424649 2026] [security2:error] [pid 511108:tid 511243] [client 117.213.202.34:60546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a6YTd5soprXwxAH3nMAAAAAU"]
[Tue Jul 21 08:41:29.424787 2026] [security2:error] [pid 511108:tid 511243] [client 117.213.202.34:60546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a6YTd5soprXwxAH3nMAAAAAU"]
[Tue Jul 21 08:41:29.435333 2026] [security2:error] [pid 511108:tid 511296] [client 4.204.201.85:16906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/k.php"] [unique_id "al9a6YTd5soprXwxAH3nMQAAADo"]
[Tue Jul 21 08:41:29.618325 2026] [security2:error] [pid 511108:tid 511242] [client 185.192.71.251:43697] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/gifclass.php"] [unique_id "al9a6YTd5soprXwxAH3nOgAAAAQ"]
[Tue Jul 21 08:41:29.920787 2026] [security2:error] [pid 511108:tid 511288] [client 20.226.60.151:58522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/qqqa.php"] [unique_id "al9a6YTd5soprXwxAH3nQwAAADI"]
[Tue Jul 21 08:41:29.966056 2026] [security2:error] [pid 511108:tid 511265] [client 78.46.190.63:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9a6YTd5soprXwxAH3nRQAAGzQ"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:41:30.014680 2026] [security2:error] [pid 511108:tid 511162] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9a6oTd5soprXwxAH3nRgAAODU"]
[Tue Jul 21 08:41:30.080385 2026] [security2:error] [pid 511108:tid 511307] [client 4.204.201.85:1473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/blurbs.php"] [unique_id "al9a6oTd5soprXwxAH3nTQAAAEU"]
[Tue Jul 21 08:41:30.083036 2026] [security2:error] [pid 511108:tid 511303] [client 185.192.71.18:58137] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/bless.php"] [unique_id "al9a6oTd5soprXwxAH3nTwAAAEE"]
[Tue Jul 21 08:41:30.089607 2026] [autoindex:error] [pid 511108:tid 511297] [client 172.252.104.206:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:41:30.277089 2026] [security2:error] [pid 511108:tid 511330] [client 203.25.124.53:36271] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/edit-tags.php"] [unique_id "al9a6oTd5soprXwxAH3nWAAAAFw"]
[Tue Jul 21 08:41:30.335430 2026] [security2:error] [pid 511108:tid 511257] [client 113.22.144.139:61907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a6oTd5soprXwxAH3nWQAAABM"]
[Tue Jul 21 08:41:30.335547 2026] [security2:error] [pid 511108:tid 511257] [client 113.22.144.139:61907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a6oTd5soprXwxAH3nWQAAABM"]
[Tue Jul 21 08:41:30.407272 2026] [security2:error] [pid 511108:tid 511167] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a6oTd5soprXwxAH3nYAAAfjo"]
[Tue Jul 21 08:41:30.516450 2026] [security2:error] [pid 511108:tid 511312] [client 185.192.71.5:38365] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/class-t.api.php"] [unique_id "al9a6oTd5soprXwxAH3naQAAAEo"]
[Tue Jul 21 08:41:30.529531 2026] [security2:error] [pid 511108:tid 511310] [client 20.63.100.92:7747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/hp2.php"] [unique_id "al9a6oTd5soprXwxAH3nagAAAEg"]
[Tue Jul 21 08:41:30.570264 2026] [security2:error] [pid 511108:tid 511270] [client 49.144.66.253:31877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9a6oTd5soprXwxAH3nbQAAACA"]
[Tue Jul 21 08:41:30.570351 2026] [security2:error] [pid 511108:tid 511270] [client 49.144.66.253:31877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9a6oTd5soprXwxAH3nbQAAACA"]
[Tue Jul 21 08:41:30.651666 2026] [security2:error] [pid 511108:tid 511340] [client 20.220.225.223:63311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/else1.php"] [unique_id "al9a6oTd5soprXwxAH3nbgAAAGY"]
[Tue Jul 21 08:41:30.705521 2026] [security2:error] [pid 511108:tid 511295] [client 59.95.197.55:62339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a6oTd5soprXwxAH3ncAAAADk"]
[Tue Jul 21 08:41:30.706298 2026] [security2:error] [pid 511108:tid 511295] [client 59.95.197.55:62339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a6oTd5soprXwxAH3ncAAAADk"]
[Tue Jul 21 08:41:30.750518 2026] [security2:error] [pid 511108:tid 511324] [client 4.204.201.85:16956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/bajah.php"] [unique_id "al9a6oTd5soprXwxAH3ncgAAAFY"]
[Tue Jul 21 08:41:30.946382 2026] [security2:error] [pid 511108:tid 511238] [client 185.192.71.6:30061] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/blurbs.php"] [unique_id "al9a6oTd5soprXwxAH3neAAAAAA"]
[Tue Jul 21 08:41:31.192083 2026] [security2:error] [pid 511108:tid 511282] [client 91.92.47.101:46410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/phpinfo/info.php"] [unique_id "al9a64Td5soprXwxAH3nggAAACw"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:41:31.210756 2026] [security2:error] [pid 511108:tid 511247] [client 91.92.47.101:46356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/server_info.php"] [unique_id "al9a64Td5soprXwxAH3nhQAAAAk"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:41:31.210825 2026] [security2:error] [pid 511108:tid 511287] [client 91.92.47.101:46292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/test.php"] [unique_id "al9a64Td5soprXwxAH3nhAAAADE"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:41:31.210843 2026] [security2:error] [pid 511108:tid 511279] [client 91.92.47.101:46252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/php_info.php"] [unique_id "al9a64Td5soprXwxAH3nhgAAACk"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:41:31.211661 2026] [security2:error] [pid 511108:tid 511338] [client 91.92.47.101:46324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/portal/phpinfo.php"] [unique_id "al9a64Td5soprXwxAH3nhwAAAGQ"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:41:31.211750 2026] [security2:error] [pid 511108:tid 511333] [client 91.92.47.101:46334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/phpinfo/info.php"] [unique_id "al9a64Td5soprXwxAH3niAAAAF8"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:41:31.212068 2026] [security2:error] [pid 511108:tid 511337] [client 91.92.47.101:46350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/configuration.php"] [unique_id "al9a64Td5soprXwxAH3niQAAAGM"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:41:31.213263 2026] [security2:error] [pid 511108:tid 511362] [client 91.92.47.101:46388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/pinfo.php"] [unique_id "al9a64Td5soprXwxAH3njwAAAHw"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:41:31.213680 2026] [security2:error] [pid 511108:tid 511269] [client 91.92.47.101:46308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/functions.php"] [unique_id "al9a64Td5soprXwxAH3nkQAAAB8"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:41:31.217880 2026] [security2:error] [pid 511108:tid 511327] [client 91.92.47.101:46380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.com.br"] [uri "/index.php"] [unique_id "al9a64Td5soprXwxAH3nmgAAAFk"], referer: http://rockegrow.com.br/
[Tue Jul 21 08:41:31.232808 2026] [security2:error] [pid 511108:tid 511265] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9a64Td5soprXwxAH3ngQAAG0I"]
[Tue Jul 21 08:41:31.354837 2026] [security2:error] [pid 511108:tid 511248] [client 91.230.225.189:61699] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/akcc.php"] [unique_id "al9a64Td5soprXwxAH3nnQAAAAo"]
[Tue Jul 21 08:41:31.462026 2026] [security2:error] [pid 511108:tid 511364] [client 203.25.124.74:23601] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/log.php"] [unique_id "al9a64Td5soprXwxAH3nowAAAH4"]
[Tue Jul 21 08:41:31.562235 2026] [security2:error] [pid 511108:tid 511186] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a64Td5soprXwxAH3nqQAAFk0"]
[Tue Jul 21 08:41:31.611768 2026] [security2:error] [pid 511108:tid 511295] [client 4.204.201.85:17004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/a.php"] [unique_id "al9a64Td5soprXwxAH3nrQAAADk"]
[Tue Jul 21 08:41:31.669734 2026] [security2:error] [pid 511108:tid 511261] [client 20.63.100.92:2322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/hp3.php"] [unique_id "al9a64Td5soprXwxAH3nrwAAABc"]
[Tue Jul 21 08:41:31.674920 2026] [security2:error] [pid 511108:tid 511329] [client 20.220.225.223:54280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/tkikikoko.php"] [unique_id "al9a64Td5soprXwxAH3nsQAAAFs"]
[Tue Jul 21 08:41:31.717102 2026] [security2:error] [pid 511108:tid 511187] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9a64Td5soprXwxAH3nswAAFE4"]
[Tue Jul 21 08:41:31.952634 2026] [security2:error] [pid 511108:tid 511272] [client 91.230.225.190:28965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/abcd.php"] [unique_id "al9a64Td5soprXwxAH3ntgAAACI"]
[Tue Jul 21 08:41:31.959704 2026] [security2:error] [pid 511108:tid 511301] [client 122.176.100.127:63227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9a64Td5soprXwxAH3ntwAAAD8"]
[Tue Jul 21 08:41:31.959842 2026] [security2:error] [pid 511108:tid 511301] [client 122.176.100.127:63227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9a64Td5soprXwxAH3ntwAAAD8"]
[Tue Jul 21 08:41:32.076210 2026] [security2:error] [pid 511108:tid 511280] [client 20.226.60.151:58622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/aunmc.php"] [unique_id "al9a7ITd5soprXwxAH3nxQAAACo"]
[Tue Jul 21 08:41:32.168947 2026] [security2:error] [pid 511108:tid 511247] [client 4.204.201.85:16921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/edit.php"] [unique_id "al9a7ITd5soprXwxAH3nyQAAAAk"]
[Tue Jul 21 08:41:32.184193 2026] [security2:error] [pid 511108:tid 511365] [client 69.171.230.3:61826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9a7ITd5soprXwxAH3nvQAAAH8"]
[Tue Jul 21 08:41:32.407036 2026] [security2:error] [pid 511108:tid 511351] [client 185.192.71.19:43205] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/shelp.php"] [unique_id "al9a7ITd5soprXwxAH3nzgAAAHE"]
[Tue Jul 21 08:41:32.540259 2026] [security2:error] [pid 511108:tid 511344] [client 195.206.105.227:45154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9a7ITd5soprXwxAH3n0wAAAGo"]
[Tue Jul 21 08:41:32.540331 2026] [security2:error] [pid 511108:tid 511344] [client 195.206.105.227:45154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9a7ITd5soprXwxAH3n0wAAAGo"]
[Tue Jul 21 08:41:32.653463 2026] [proxy:error] [pid 511108:tid 511177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:32.653503 2026] [proxy_http:error] [pid 511108:tid 511177] [remote 74.7.230.27:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:32.654297 2026] [proxy:error] [pid 511108:tid 511177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:32.654331 2026] [proxy_http:error] [pid 511108:tid 511177] [remote 74.7.230.27:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:32.654488 2026] [security2:error] [pid 511108:tid 511350] [client 74.7.230.27:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "503"] [hostname "cpcontacts.sejabarbara.com.br"] [uri "/___proxy_subdomain_cpcontacts/robots.txt"] [unique_id "al9a7ITd5soprXwxAH3n2gAAcEQ"]
[Tue Jul 21 08:41:32.698725 2026] [security2:error] [pid 511108:tid 511197] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a7ITd5soprXwxAH3n3AAAJFg"]
[Tue Jul 21 08:41:32.707804 2026] [security2:error] [pid 511108:tid 511357] [client 20.206.105.145:33643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/a1.php"] [unique_id "al9a7ITd5soprXwxAH3n3QAAAHc"]
[Tue Jul 21 08:41:32.763272 2026] [security2:error] [pid 511108:tid 511311] [client 212.32.76.14:28437] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/bless.php"] [unique_id "al9a7ITd5soprXwxAH3n4AAAAEk"]
[Tue Jul 21 08:41:32.787805 2026] [security2:error] [pid 511108:tid 511348] [client 4.204.201.85:16910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/hosty.php"] [unique_id "al9a7ITd5soprXwxAH3n5AAAAG4"]
[Tue Jul 21 08:41:32.833077 2026] [security2:error] [pid 511108:tid 511202] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9a7ITd5soprXwxAH3n5gAAHF0"]
[Tue Jul 21 08:41:32.861179 2026] [security2:error] [pid 511108:tid 511310] [client 91.230.225.190:23581] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/cord.php"] [unique_id "al9a7ITd5soprXwxAH3n5wAAAEg"]
[Tue Jul 21 08:41:33.031162 2026] [security2:error] [pid 511108:tid 511329] [client 20.220.225.223:40736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wp-Blogs.php"] [unique_id "al9a7YTd5soprXwxAH3n6wAAAFs"]
[Tue Jul 21 08:41:33.074463 2026] [security2:error] [pid 511108:tid 511324] [client 20.226.60.151:58497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/uoocf.php"] [unique_id "al9a7YTd5soprXwxAH3n7wAAAFY"]
[Tue Jul 21 08:41:33.292649 2026] [security2:error] [pid 511108:tid 511297] [client 20.197.192.193:65179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/8.php"] [unique_id "al9a7YTd5soprXwxAH3n-AAAADs"]
[Tue Jul 21 08:41:33.296444 2026] [security2:error] [pid 511108:tid 511291] [client 91.230.225.190:27051] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/dex.php"] [unique_id "al9a7YTd5soprXwxAH3n-QAAADU"]
[Tue Jul 21 08:41:33.362410 2026] [security2:error] [pid 511108:tid 511364] [client 5.38.115.39:63233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9a7YTd5soprXwxAH3n-wAAAH4"]
[Tue Jul 21 08:41:33.362499 2026] [security2:error] [pid 511108:tid 511364] [client 5.38.115.39:63233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9a7YTd5soprXwxAH3n-wAAAH4"]
[Tue Jul 21 08:41:33.638969 2026] [security2:error] [pid 511108:tid 511362] [client 20.63.100.92:4470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/aa1.php"] [unique_id "al9a7YTd5soprXwxAH3oBQAAAHw"]
[Tue Jul 21 08:41:33.725700 2026] [security2:error] [pid 511108:tid 511251] [client 4.204.201.85:1504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/k.php"] [unique_id "al9a7YTd5soprXwxAH3oCgAAAA0"]
[Tue Jul 21 08:41:33.750365 2026] [security2:error] [pid 511108:tid 511351] [client 185.192.71.13:28447] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9a7YTd5soprXwxAH3oCwAAAHE"]
[Tue Jul 21 08:41:33.767143 2026] [security2:error] [pid 511108:tid 511213] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a7YTd5soprXwxAH3oDQAAU2g"]
[Tue Jul 21 08:41:33.819500 2026] [security2:error] [pid 511108:tid 511309] [client 20.226.60.151:34832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/iywwi.php"] [unique_id "al9a7YTd5soprXwxAH3oDgAAAEc"]
[Tue Jul 21 08:41:33.821008 2026] [security2:error] [pid 511108:tid 511333] [client 185.213.175.37:53322] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bkp.liranesuliano.com.br"] [uri "/"] [unique_id "al9a7YTd5soprXwxAH3oDwAAAF8"]
[Tue Jul 21 08:41:33.874784 2026] [security2:error] [pid 511108:tid 511318] [client 168.167.81.163:63208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9a7YTd5soprXwxAH3oEAAAAFA"]
[Tue Jul 21 08:41:33.874803 2026] [security2:error] [pid 511108:tid 511286] [client 195.206.105.227:45156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9a7YTd5soprXwxAH3oEQAAADA"]
[Tue Jul 21 08:41:33.874878 2026] [security2:error] [pid 511108:tid 511286] [client 195.206.105.227:45156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9a7YTd5soprXwxAH3oEQAAADA"]
[Tue Jul 21 08:41:33.874905 2026] [security2:error] [pid 511108:tid 511318] [client 168.167.81.163:63208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9a7YTd5soprXwxAH3oEAAAAFA"]
[Tue Jul 21 08:41:33.885506 2026] [security2:error] [pid 511108:tid 511217] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9a7YTd5soprXwxAH3oEwAAemw"]
[Tue Jul 21 08:41:34.032653 2026] [proxy:error] [pid 511108:tid 511221] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:34.032692 2026] [proxy_http:error] [pid 511108:tid 511221] [remote 74.7.244.1:49272] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:34.033508 2026] [proxy:error] [pid 511108:tid 511221] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:34.033536 2026] [proxy_http:error] [pid 511108:tid 511221] [remote 74.7.244.1:49272] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:34.212121 2026] [security2:error] [pid 511108:tid 511334] [client 91.230.225.8:65519] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/zwso.php"] [unique_id "al9a7oTd5soprXwxAH3oIAAAAGA"]
[Tue Jul 21 08:41:34.265174 2026] [security2:error] [pid 511108:tid 511315] [client 4.204.201.85:1493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/aaa.php"] [unique_id "al9a7oTd5soprXwxAH3oIQAAAE0"]
[Tue Jul 21 08:41:34.429295 2026] [security2:error] [pid 511108:tid 511223] [remote 167.71.218.184:52482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9a7oTd5soprXwxAH3oJwAAWnI"]
[Tue Jul 21 08:41:34.458491 2026] [security2:error] [pid 511108:tid 511268] [client 203.25.124.67:30183] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Text/"] [unique_id "al9a7oTd5soprXwxAH3oKAAAAB4"]
[Tue Jul 21 08:41:34.504572 2026] [security2:error] [pid 511108:tid 511222] [remote 202.51.202.242:51952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "prissedermatologia.com.br"] [uri "/wp-login.php"] [unique_id "al9a7oTd5soprXwxAH3oKgAAHXE"]
[Tue Jul 21 08:41:34.540329 2026] [security2:error] [pid 511108:tid 511261] [client 20.220.225.223:2378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wp-css.php"] [unique_id "al9a7oTd5soprXwxAH3oKwAAABc"]
[Tue Jul 21 08:41:34.631456 2026] [security2:error] [pid 511108:tid 511230] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a7oTd5soprXwxAH3oMQAAUnk"]
[Tue Jul 21 08:41:34.657667 2026] [security2:error] [pid 511108:tid 511276] [client 91.92.47.101:46530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/php_info.php"] [unique_id "al9a7oTd5soprXwxAH3oOAAAACY"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:41:34.658517 2026] [security2:error] [pid 511108:tid 511244] [client 91.92.47.101:46442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/pinfo.php"] [unique_id "al9a7oTd5soprXwxAH3oOQAAAAY"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:41:34.658636 2026] [security2:error] [pid 511108:tid 511239] [client 91.92.47.101:46494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/index.php"] [unique_id "al9a7oTd5soprXwxAH3oOgAAAAE"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:41:34.659428 2026] [security2:error] [pid 511108:tid 511314] [client 91.92.47.101:46424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/configuration.php"] [unique_id "al9a7oTd5soprXwxAH3oPAAAAEw"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:41:34.659563 2026] [security2:error] [pid 511108:tid 511289] [client 91.92.47.101:46540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/test.php"] [unique_id "al9a7oTd5soprXwxAH3oPQAAADM"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:41:34.659878 2026] [security2:error] [pid 511108:tid 511307] [client 91.92.47.101:46508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/server_info.php"] [unique_id "al9a7oTd5soprXwxAH3oPgAAAEU"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:41:34.659940 2026] [security2:error] [pid 511108:tid 511342] [client 91.92.47.101:46480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/functions.php"] [unique_id "al9a7oTd5soprXwxAH3oPwAAAGg"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:41:34.660460 2026] [security2:error] [pid 511108:tid 511347] [client 91.92.47.101:46554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rockegrow.jaypi.com.br"] [uri "/portal/phpinfo.php"] [unique_id "al9a7oTd5soprXwxAH3oQQAAAG0"], referer: http://rockegrow.jaypi.com.br/
[Tue Jul 21 08:41:34.688100 2026] [security2:error] [pid 511108:tid 511282] [client 91.230.225.6:46457] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/wp-content/plugins/hellopress/wp_mna.php"] [unique_id "al9a7oTd5soprXwxAH3oTgAAACw"]
[Tue Jul 21 08:41:34.726101 2026] [security2:error] [pid 511108:tid 511214] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9a7oTd5soprXwxAH3oTwAAQmk"]
[Tue Jul 21 08:41:34.735339 2026] [security2:error] [pid 511108:tid 511284] [client 20.226.60.151:58604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/gqgsa.php"] [unique_id "al9a7oTd5soprXwxAH3oUgAAAC4"]
[Tue Jul 21 08:41:34.868854 2026] [security2:error] [pid 511108:tid 511318] [client 4.204.201.85:16979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/file5.php"] [unique_id "al9a7oTd5soprXwxAH3oWwAAAFA"]
[Tue Jul 21 08:41:35.121370 2026] [security2:error] [pid 511108:tid 511260] [client 185.192.71.250:60797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/bolt.php"] [unique_id "al9a74Td5soprXwxAH3oYQAAABY"]
[Tue Jul 21 08:41:35.149530 2026] [autoindex:error] [pid 511108:tid 511261] [client 205.210.31.240:64080] AH01276: Cannot serve directory /home1/warlle02/ewfconstrucao.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:41:35.401742 2026] [security2:error] [pid 511108:tid 511319] [client 20.226.60.151:58499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/elbzl.php"] [unique_id "al9a74Td5soprXwxAH3ocQAAAFE"]
[Tue Jul 21 08:41:35.414460 2026] [security2:error] [pid 511108:tid 511259] [client 20.220.225.223:12298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/mimpi.php"] [unique_id "al9a74Td5soprXwxAH3ocgAAABU"]
[Tue Jul 21 08:41:35.417733 2026] [security2:error] [pid 511108:tid 511362] [client 223.181.60.88:10500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9a74Td5soprXwxAH3ocwAAAHw"]
[Tue Jul 21 08:41:35.418538 2026] [security2:error] [pid 511108:tid 511362] [client 223.181.60.88:10500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9a74Td5soprXwxAH3ocwAAAHw"]
[Tue Jul 21 08:41:35.466685 2026] [security2:error] [pid 511108:tid 511304] [client 212.32.76.13:40201] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/languages/themes/"] [unique_id "al9a74Td5soprXwxAH3odgAAAEI"]
[Tue Jul 21 08:41:35.525106 2026] [security2:error] [pid 511108:tid 511302] [client 91.230.225.188:31929] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/cjfuns.php"] [unique_id "al9a74Td5soprXwxAH3oeQAAAEA"]
[Tue Jul 21 08:41:35.593269 2026] [security2:error] [pid 511108:tid 511309] [client 4.204.201.85:17003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/222.php"] [unique_id "al9a74Td5soprXwxAH3oewAAAEc"]
[Tue Jul 21 08:41:35.831891 2026] [security2:error] [pid 511108:tid 511282] [client 202.179.75.202:36602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9a74Td5soprXwxAH3oiAAAACw"]
[Tue Jul 21 08:41:35.832924 2026] [security2:error] [pid 511108:tid 511282] [client 202.179.75.202:36602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9a74Td5soprXwxAH3oiAAAACw"]
[Tue Jul 21 08:41:35.885533 2026] [security2:error] [pid 511108:tid 511311] [client 20.226.60.151:58615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/adjig.php"] [unique_id "al9a74Td5soprXwxAH3okAAAAEk"]
[Tue Jul 21 08:41:35.897905 2026] [security2:error] [pid 511108:tid 511308] [client 195.49.128.211:55020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9a74Td5soprXwxAH3ongAAAEY"]
[Tue Jul 21 08:41:35.898032 2026] [security2:error] [pid 511108:tid 511308] [client 195.49.128.211:55020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9a74Td5soprXwxAH3ongAAAEY"]
[Tue Jul 21 08:41:35.943517 2026] [security2:error] [pid 511108:tid 511335] [client 185.192.71.250:55835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/wp-admin/css/index.php"] [unique_id "al9a74Td5soprXwxAH3orAAAAGE"]
[Tue Jul 21 08:41:35.975725 2026] [security2:error] [pid 511108:tid 511161] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a74Td5soprXwxAH3orgAAbDQ"]
[Tue Jul 21 08:41:36.144983 2026] [security2:error] [pid 511108:tid 511166] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9a8ITd5soprXwxAH3otQAAHDk"]
[Tue Jul 21 08:41:36.318081 2026] [security2:error] [pid 511108:tid 511259] [client 20.220.225.223:48918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/wp-explorer.php"] [unique_id "al9a8ITd5soprXwxAH3oxgAAABU"]
[Tue Jul 21 08:41:36.335893 2026] [security2:error] [pid 511108:tid 511285] [client 103.59.206.240:31039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a8ITd5soprXwxAH3oxwAAAC8"]
[Tue Jul 21 08:41:36.336048 2026] [security2:error] [pid 511108:tid 511285] [client 103.59.206.240:31039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a8ITd5soprXwxAH3oxwAAAC8"]
[Tue Jul 21 08:41:36.353747 2026] [security2:error] [pid 511108:tid 511341] [client 185.192.71.6:60203] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/wp-content/plugins/index.php"] [unique_id "al9a8ITd5soprXwxAH3ozAAAAGc"]
[Tue Jul 21 08:41:36.367644 2026] [security2:error] [pid 511108:tid 511321] [client 4.204.201.85:1472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/test.php"] [unique_id "al9a8ITd5soprXwxAH3ozwAAAFM"]
[Tue Jul 21 08:41:36.657441 2026] [security2:error] [pid 511108:tid 511186] [remote 167.71.218.184:59512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9a8ITd5soprXwxAH3o1AAAdU0"]
[Tue Jul 21 08:41:36.700945 2026] [security2:error] [pid 511108:tid 511352] [client 20.63.100.92:1134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/acew67.php"] [unique_id "al9a8ITd5soprXwxAH3o3AAAAHI"]
[Tue Jul 21 08:41:36.812452 2026] [security2:error] [pid 511108:tid 511242] [client 185.192.71.247:65125] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/wp-content/index.php"] [unique_id "al9a8ITd5soprXwxAH3o4AAAAAQ"]
[Tue Jul 21 08:41:36.968952 2026] [security2:error] [pid 511108:tid 511240] [client 20.226.60.151:34817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/byp.php"] [unique_id "al9a8ITd5soprXwxAH3o6QAAAAI"]
[Tue Jul 21 08:41:37.049570 2026] [security2:error] [pid 511108:tid 511261] [client 4.204.201.85:1482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/aaa.php"] [unique_id "al9a8YTd5soprXwxAH3o6wAAABc"]
[Tue Jul 21 08:41:37.158280 2026] [security2:error] [pid 511108:tid 511327] [client 203.25.124.74:65317] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/file-upload-types/assets/css/403.php"] [unique_id "al9a8YTd5soprXwxAH3o9AAAAFk"]
[Tue Jul 21 08:41:37.216554 2026] [security2:error] [pid 511108:tid 511362] [client 91.230.225.183:63861] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/ioxi-o.php"] [unique_id "al9a8YTd5soprXwxAH3pAQAAAHw"]
[Tue Jul 21 08:41:37.333951 2026] [security2:error] [pid 511108:tid 511222] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9a8YTd5soprXwxAH3pEAAAJ3E"]
[Tue Jul 21 08:41:37.334124 2026] [security2:error] [pid 511108:tid 511277] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9a8YTd5soprXwxAH3pEAAAJ3E"]
[Tue Jul 21 08:41:37.335286 2026] [security2:error] [pid 511108:tid 511302] [client 20.220.225.223:63312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/akismet.php"] [unique_id "al9a8YTd5soprXwxAH3pEgAAAEA"]
[Tue Jul 21 08:41:37.454556 2026] [security2:error] [pid 511108:tid 511109] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a8YTd5soprXwxAH3pIgAAAAA"]
[Tue Jul 21 08:41:37.471182 2026] [security2:error] [pid 511108:tid 511281] [client 20.63.100.92:9085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/bscclapb.php"] [unique_id "al9a8YTd5soprXwxAH3pIwAAACs"]
[Tue Jul 21 08:41:37.500056 2026] [security2:error] [pid 511108:tid 511271] [client 61.1.167.83:55285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a8YTd5soprXwxAH3pJgAAACE"]
[Tue Jul 21 08:41:37.510339 2026] [security2:error] [pid 511108:tid 511271] [client 61.1.167.83:55285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a8YTd5soprXwxAH3pJgAAACE"]
[Tue Jul 21 08:41:37.594772 2026] [security2:error] [pid 511108:tid 511249] [client 4.204.201.85:1476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/11.php"] [unique_id "al9a8YTd5soprXwxAH3pKgAAAAs"]
[Tue Jul 21 08:41:37.630084 2026] [security2:error] [pid 511108:tid 511114] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9a8YTd5soprXwxAH3pLAAAdwU"]
[Tue Jul 21 08:41:37.692078 2026] [security2:error] [pid 511108:tid 511116] [remote 188.164.197.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fidellium.com"] [uri "/wp-login.php"] [unique_id "al9a8YTd5soprXwxAH3pLgAAcAc"]
[Tue Jul 21 08:41:38.131693 2026] [security2:error] [pid 511108:tid 511294] [client 198.44.157.34:44540] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9a8oTd5soprXwxAH3pQwAAADg"]
[Tue Jul 21 08:41:38.131806 2026] [security2:error] [pid 511108:tid 511294] [client 198.44.157.34:44540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9a8oTd5soprXwxAH3pQwAAADg"]
[Tue Jul 21 08:41:38.226202 2026] [security2:error] [pid 511108:tid 511329] [client 4.204.201.85:1524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/mac.php"] [unique_id "al9a8oTd5soprXwxAH3pRQAAAFs"]
[Tue Jul 21 08:41:38.250363 2026] [security2:error] [pid 511108:tid 511337] [client 91.92.47.101:25562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/portal/phpinfo.php"] [unique_id "al9a8oTd5soprXwxAH3pRwAAAGM"], referer: http://jaypi.com.br/
[Tue Jul 21 08:41:38.250701 2026] [security2:error] [pid 511108:tid 511285] [client 91.92.47.101:25600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/php_info.php"] [unique_id "al9a8oTd5soprXwxAH3pSAAAAC8"], referer: http://jaypi.com.br/
[Tue Jul 21 08:41:38.250994 2026] [security2:error] [pid 511108:tid 511341] [client 91.92.47.101:25582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/phpinfo/info.php"] [unique_id "al9a8oTd5soprXwxAH3pSQAAAGc"], referer: http://jaypi.com.br/
[Tue Jul 21 08:41:38.251527 2026] [security2:error] [pid 511108:tid 511321] [client 91.92.47.101:25556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/index.php"] [unique_id "al9a8oTd5soprXwxAH3pSwAAAFM"], referer: http://jaypi.com.br/
[Tue Jul 21 08:41:38.251757 2026] [security2:error] [pid 511108:tid 511270] [client 91.92.47.101:25640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/functions.php"] [unique_id "al9a8oTd5soprXwxAH3pTAAAACA"], referer: http://jaypi.com.br/
[Tue Jul 21 08:41:38.275010 2026] [security2:error] [pid 511108:tid 511339] [client 91.92.47.101:25614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/server_info.php"] [unique_id "al9a8oTd5soprXwxAH3pUgAAAGU"], referer: http://jaypi.com.br/
[Tue Jul 21 08:41:38.275191 2026] [security2:error] [pid 511108:tid 511257] [client 91.92.47.101:25546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/test.php"] [unique_id "al9a8oTd5soprXwxAH3pUwAAABM"], referer: http://jaypi.com.br/
[Tue Jul 21 08:41:38.276074 2026] [security2:error] [pid 511108:tid 511351] [client 91.92.47.101:25686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/configuration.php"] [unique_id "al9a8oTd5soprXwxAH3pVQAAAHE"], referer: http://jaypi.com.br/
[Tue Jul 21 08:41:38.277074 2026] [security2:error] [pid 511108:tid 511302] [client 91.92.47.101:25646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jaypi.com.br"] [uri "/pinfo.php"] [unique_id "al9a8oTd5soprXwxAH3pWAAAAEA"], referer: http://jaypi.com.br/
[Tue Jul 21 08:41:38.300536 2026] [security2:error] [pid 511108:tid 511112] [remote 103.161.172.221:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "granicap.com.br"] [uri "/wp-login.php"] [unique_id "al9a8oTd5soprXwxAH3pYQAAVAM"]
[Tue Jul 21 08:41:38.641695 2026] [security2:error] [pid 511108:tid 511262] [client 20.226.60.151:58569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/ortasekerli1.php"] [unique_id "al9a8oTd5soprXwxAH3pbAAAABg"]
[Tue Jul 21 08:41:38.728621 2026] [security2:error] [pid 511108:tid 511253] [client 4.204.201.85:1513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/chosen.php"] [unique_id "al9a8oTd5soprXwxAH3pbQAAAA8"]
[Tue Jul 21 08:41:38.866531 2026] [security2:error] [pid 511108:tid 511279] [client 203.25.124.51:62873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/autoload_classmap.php"] [unique_id "al9a8oTd5soprXwxAH3pdAAAACk"]
[Tue Jul 21 08:41:38.891890 2026] [security2:error] [pid 511108:tid 511323] [client 91.230.225.187:56879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/insc.php"] [unique_id "al9a8oTd5soprXwxAH3pdgAAAFU"]
[Tue Jul 21 08:41:38.975652 2026] [security2:error] [pid 511108:tid 511247] [client 195.49.128.211:63196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9a8oTd5soprXwxAH3peQAAAAk"]
[Tue Jul 21 08:41:38.975748 2026] [security2:error] [pid 511108:tid 511247] [client 195.49.128.211:63196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9a8oTd5soprXwxAH3peQAAAAk"]
[Tue Jul 21 08:41:39.008370 2026] [security2:error] [pid 511108:tid 511144] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a84Td5soprXwxAH3pfwAAWSM"]
[Tue Jul 21 08:41:39.102124 2026] [security2:error] [pid 511108:tid 511321] [client 20.220.225.223:12568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/dp.php"] [unique_id "al9a84Td5soprXwxAH3phAAAAFM"]
[Tue Jul 21 08:41:39.128277 2026] [security2:error] [pid 511108:tid 511264] [client 152.59.181.104:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9a84Td5soprXwxAH3phgAAABo"]
[Tue Jul 21 08:41:39.128745 2026] [security2:error] [pid 511108:tid 511264] [client 152.59.181.104:64075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9a84Td5soprXwxAH3phgAAABo"]
[Tue Jul 21 08:41:39.180355 2026] [security2:error] [pid 511108:tid 511148] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9a84Td5soprXwxAH3phwAAVCc"]
[Tue Jul 21 08:41:39.300673 2026] [security2:error] [pid 511108:tid 511338] [client 91.230.225.194:38245] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/classwithtostring.php"] [unique_id "al9a84Td5soprXwxAH3piQAAAGQ"]
[Tue Jul 21 08:41:39.306460 2026] [security2:error] [pid 511108:tid 511265] [client 4.204.201.85:1460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/cream1.php"] [unique_id "al9a84Td5soprXwxAH3pigAAABs"]
[Tue Jul 21 08:41:39.389857 2026] [security2:error] [pid 511108:tid 511271] [client 20.63.100.92:7839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/else1.php"] [unique_id "al9a84Td5soprXwxAH3pjAAAACE"]
[Tue Jul 21 08:41:39.486147 2026] [security2:error] [pid 511108:tid 511243] [client 20.197.192.193:43777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/red.php"] [unique_id "al9a84Td5soprXwxAH3plwAAAAU"]
[Tue Jul 21 08:41:39.498459 2026] [security2:error] [pid 511108:tid 511332] [client 20.220.225.223:40743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/ace2.php"] [unique_id "al9a84Td5soprXwxAH3pmAAAAF4"]
[Tue Jul 21 08:41:39.677068 2026] [security2:error] [pid 511108:tid 511248] [client 20.226.60.151:58530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/classwithtostring.php"] [unique_id "al9a84Td5soprXwxAH3pnwAAAAo"]
[Tue Jul 21 08:41:39.771658 2026] [security2:error] [pid 511108:tid 511328] [client 185.192.71.8:47541] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/txets.php"] [unique_id "al9a84Td5soprXwxAH3poQAAAFo"]
[Tue Jul 21 08:41:39.784072 2026] [security2:error] [pid 511108:tid 511159] [remote 173.252.82.21:40522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9a84Td5soprXwxAH3pnQAAYTI"]
[Tue Jul 21 08:41:39.865281 2026] [security2:error] [pid 511108:tid 511299] [client 203.25.124.70:30547] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/bolt.php"] [unique_id "al9a84Td5soprXwxAH3powAAAD0"]
[Tue Jul 21 08:41:39.891893 2026] [security2:error] [pid 511108:tid 511323] [client 173.252.95.7:52522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9a84Td5soprXwxAH3ppAAAAFU"]
[Tue Jul 21 08:41:39.900136 2026] [security2:error] [pid 511108:tid 511275] [client 4.204.201.85:16923] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-content/uploads/"] [unique_id "al9a84Td5soprXwxAH3ppgAAACU"]
[Tue Jul 21 08:41:40.069869 2026] [security2:error] [pid 511108:tid 511162] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9a9ITd5soprXwxAH3pqgAAIzU"]
[Tue Jul 21 08:41:40.069995 2026] [security2:error] [pid 511108:tid 511273] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9a9ITd5soprXwxAH3pqgAAIzU"]
[Tue Jul 21 08:41:40.232141 2026] [security2:error] [pid 511108:tid 511350] [client 117.213.202.34:61154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a9ITd5soprXwxAH3psAAAAHA"]
[Tue Jul 21 08:41:40.232313 2026] [security2:error] [pid 511108:tid 511350] [client 117.213.202.34:61154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a9ITd5soprXwxAH3psAAAAHA"]
[Tue Jul 21 08:41:40.281834 2026] [security2:error] [pid 511108:tid 511296] [client 185.192.71.1:54253] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/wp-content/themes/txets.php"] [unique_id "al9a9ITd5soprXwxAH3psQAAADo"]
[Tue Jul 21 08:41:40.355228 2026] [security2:error] [pid 511108:tid 511285] [client 4.204.201.85:17001] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-includes/Text/"] [unique_id "al9a9ITd5soprXwxAH3ptQAAAC8"]
[Tue Jul 21 08:41:40.454707 2026] [security2:error] [pid 511108:tid 511363] [client 20.226.60.151:58585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/root.php"] [unique_id "al9a9ITd5soprXwxAH3pugAAAH0"]
[Tue Jul 21 08:41:40.540384 2026] [security2:error] [pid 511108:tid 511283] [client 113.22.144.139:62348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a9ITd5soprXwxAH3pvQAAAC0"]
[Tue Jul 21 08:41:40.541421 2026] [security2:error] [pid 511108:tid 511283] [client 113.22.144.139:62348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a9ITd5soprXwxAH3pvQAAAC0"]
[Tue Jul 21 08:41:40.643874 2026] [security2:error] [pid 511108:tid 511286] [client 173.252.95.35:50652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9a9ITd5soprXwxAH3pwQAAADA"]
[Tue Jul 21 08:41:40.706605 2026] [security2:error] [pid 511108:tid 511357] [client 91.230.225.192:22761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/wp-admin/txets.php"] [unique_id "al9a9ITd5soprXwxAH3pxQAAAHc"]
[Tue Jul 21 08:41:40.708807 2026] [security2:error] [pid 511108:tid 511288] [client 20.220.225.223:58059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lp.mannucarvalho.com"] [uri "/ms.php"] [unique_id "al9a9ITd5soprXwxAH3pxgAAADI"]
[Tue Jul 21 08:41:40.733324 2026] [security2:error] [pid 511108:tid 511155] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php"] [unique_id "al9a9ITd5soprXwxAH3pyAAAey4"]
[Tue Jul 21 08:41:40.866684 2026] [security2:error] [pid 511108:tid 511348] [client 203.25.124.55:54383] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/maint/chosen.php"] [unique_id "al9a9ITd5soprXwxAH3pywAAAG4"]
[Tue Jul 21 08:41:40.903315 2026] [security2:error] [pid 511108:tid 511235] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9a9ITd5soprXwxAH3pzQAAHX4"]
[Tue Jul 21 08:41:40.950109 2026] [security2:error] [pid 511108:tid 511172] [remote 54.39.210.202:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "climadek.com.br"] [uri "/robots.txt"] [unique_id "al9a9ITd5soprXwxAH3p0AAAFj8"]
[Tue Jul 21 08:41:40.950268 2026] [security2:error] [pid 511108:tid 511260] [client 54.39.210.202:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "climadek.com.br"] [uri "/robots.txt"] [unique_id "al9a9ITd5soprXwxAH3p0AAAFj8"]
[Tue Jul 21 08:41:40.976072 2026] [security2:error] [pid 511108:tid 511275] [client 4.204.201.85:16948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/dr.php"] [unique_id "al9a9ITd5soprXwxAH3p0wAAACU"]
[Tue Jul 21 08:41:41.131394 2026] [security2:error] [pid 511108:tid 511178] [remote 49.12.216.176:46118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9a9YTd5soprXwxAH3p3gAAYEU"]
[Tue Jul 21 08:41:41.144837 2026] [security2:error] [pid 511108:tid 511351] [client 91.230.225.192:49223] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/wp-includes/txets.php"] [unique_id "al9a9YTd5soprXwxAH3p4QAAAHE"]
[Tue Jul 21 08:41:41.171005 2026] [security2:error] [pid 511108:tid 511333] [client 59.95.197.55:62791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a9YTd5soprXwxAH3p4gAAAF8"]
[Tue Jul 21 08:41:41.171206 2026] [security2:error] [pid 511108:tid 511333] [client 59.95.197.55:62791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a9YTd5soprXwxAH3p4gAAAF8"]
[Tue Jul 21 08:41:41.326999 2026] [security2:error] [pid 511108:tid 511270] [client 4.204.201.85:16996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/x.php"] [unique_id "al9a9YTd5soprXwxAH3p6gAAACA"]
[Tue Jul 21 08:41:41.558712 2026] [security2:error] [pid 511108:tid 511238] [client 185.192.71.20:55227] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/goods.php"] [unique_id "al9a9YTd5soprXwxAH3p9AAAAAA"]
[Tue Jul 21 08:41:41.854464 2026] [security2:error] [pid 511108:tid 511259] [client 20.220.225.223:12552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/bootstrap.php"] [unique_id "al9a9YTd5soprXwxAH3qAQAAABU"]
[Tue Jul 21 08:41:41.893659 2026] [security2:error] [pid 511108:tid 511277] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9a9YTd5soprXwxAH3p_wAAJ1Y"]
[Tue Jul 21 08:41:41.925378 2026] [security2:error] [pid 511108:tid 511266] [client 4.204.201.85:17006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/155.php"] [unique_id "al9a9YTd5soprXwxAH3qAwAAABw"]
[Tue Jul 21 08:41:41.986509 2026] [security2:error] [pid 511108:tid 511330] [client 20.226.60.151:34859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/sym403.php"] [unique_id "al9a9YTd5soprXwxAH3qBwAAAFw"]
[Tue Jul 21 08:41:42.040313 2026] [security2:error] [pid 511108:tid 511249] [client 49.144.66.253:32311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9a9oTd5soprXwxAH3qCwAAAAs"]
[Tue Jul 21 08:41:42.040441 2026] [security2:error] [pid 511108:tid 511249] [client 49.144.66.253:32311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9a9oTd5soprXwxAH3qCwAAAAs"]
[Tue Jul 21 08:41:42.439490 2026] [security2:error] [pid 511108:tid 511251] [client 122.176.100.127:63737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9a9oTd5soprXwxAH3qFgAAAA0"]
[Tue Jul 21 08:41:42.439599 2026] [security2:error] [pid 511108:tid 511251] [client 122.176.100.127:63737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9a9oTd5soprXwxAH3qFgAAAA0"]
[Tue Jul 21 08:41:42.481852 2026] [security2:error] [pid 511108:tid 511302] [client 4.204.201.85:16982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/ops.php"] [unique_id "al9a9oTd5soprXwxAH3qGAAAAEA"]
[Tue Jul 21 08:41:42.543774 2026] [security2:error] [pid 511108:tid 511199] [remote 103.215.75.19:57026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gradiente.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9a9oTd5soprXwxAH3qHAAAZFo"]
[Tue Jul 21 08:41:42.704068 2026] [autoindex:error] [pid 511108:tid 511212] [remote 66.249.70.196:0] AH01276: Cannot serve directory /home1/bastar15/lacorsini.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:41:42.978295 2026] [security2:error] [pid 511108:tid 511243] [client 4.204.201.85:16933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/file31.php"] [unique_id "al9a9oTd5soprXwxAH3qKAAAAAU"]
[Tue Jul 21 08:41:42.986096 2026] [core:error] [pid 511108:tid 511210] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:41:42.986116 2026] [core:error] [pid 511108:tid 511210] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:41:43.091268 2026] [security2:error] [pid 511108:tid 511347] [client 185.192.71.11:35503] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/wp-editor.php"] [unique_id "al9a94Td5soprXwxAH3qLgAAAG0"]
[Tue Jul 21 08:41:43.498690 2026] [security2:error] [pid 511108:tid 511251] [client 34.168.58.236:62193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.58.168.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cezaretto.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a94Td5soprXwxAH3qOAAAAA0"]
[Tue Jul 21 08:41:43.523757 2026] [security2:error] [pid 511108:tid 511301] [client 91.230.225.5:20571] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/lufix.php"] [unique_id "al9a94Td5soprXwxAH3qOgAAAD8"]
[Tue Jul 21 08:41:43.609464 2026] [security2:error] [pid 511108:tid 511285] [client 20.206.105.145:33747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/k2.php"] [unique_id "al9a94Td5soprXwxAH3qQwAAAC8"]
[Tue Jul 21 08:41:43.696620 2026] [core:error] [pid 511108:tid 511234] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:41:43.696644 2026] [core:error] [pid 511108:tid 511234] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:41:43.750397 2026] [security2:error] [pid 511108:tid 511313] [client 4.204.201.85:16938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/file6.php"] [unique_id "al9a94Td5soprXwxAH3qRwAAAEs"]
[Tue Jul 21 08:41:43.790872 2026] [security2:error] [pid 511108:tid 511267] [client 5.31.193.106:1854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9a94Td5soprXwxAH3qSQAAAB0"]
[Tue Jul 21 08:41:43.790998 2026] [security2:error] [pid 511108:tid 511267] [client 5.31.193.106:1854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9a94Td5soprXwxAH3qSQAAAB0"]
[Tue Jul 21 08:41:43.838036 2026] [security2:error] [pid 511108:tid 511364] [client 203.25.124.215:51085] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a9YTd5soprXwxAH3p9wAAAH4"]
[Tue Jul 21 08:41:43.935594 2026] [security2:error] [pid 511108:tid 511292] [client 185.192.71.1:44023] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "treeoflifehealth.online"] [uri "/style.php"] [unique_id "al9a94Td5soprXwxAH3qTQAAADY"]
[Tue Jul 21 08:41:43.944638 2026] [security2:error] [pid 511108:tid 511240] [client 168.167.81.163:63935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9a94Td5soprXwxAH3qTwAAAAI"]
[Tue Jul 21 08:41:43.945477 2026] [security2:error] [pid 511108:tid 511240] [client 168.167.81.163:63935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9a94Td5soprXwxAH3qTwAAAAI"]
[Tue Jul 21 08:41:43.986645 2026] [security2:error] [pid 511108:tid 511111] [remote 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.extrapro21.com"] [uri "/xmlrpc.php"] [unique_id "al9a94Td5soprXwxAH3qUQAABQI"]
[Tue Jul 21 08:41:44.077078 2026] [security2:error] [pid 511108:tid 511362] [client 5.38.115.39:58280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9a-ITd5soprXwxAH3qVgAAAHw"]
[Tue Jul 21 08:41:44.077196 2026] [security2:error] [pid 511108:tid 511362] [client 5.38.115.39:58280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9a-ITd5soprXwxAH3qVgAAAHw"]
[Tue Jul 21 08:41:44.206452 2026] [security2:error] [pid 511108:tid 511219] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.extrapro21.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9a-ITd5soprXwxAH3qWwAAJW4"]
[Tue Jul 21 08:41:44.213711 2026] [security2:error] [pid 511108:tid 511244] [client 34.168.58.236:51967] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9a-ITd5soprXwxAH3qXAAAAAY"]
[Tue Jul 21 08:41:44.253070 2026] [security2:error] [pid 511108:tid 511311] [client 4.204.201.85:17010] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-includes/assets/"] [unique_id "al9a-ITd5soprXwxAH3qYwAAAEk"]
[Tue Jul 21 08:41:44.400749 2026] [security2:error] [pid 511108:tid 511115] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.extrapro21.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9a-ITd5soprXwxAH3qZwAACgY"]
[Tue Jul 21 08:41:44.606656 2026] [security2:error] [pid 511108:tid 511131] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.extrapro21.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9a-ITd5soprXwxAH3qbAAAPRY"]
[Tue Jul 21 08:41:44.771183 2026] [security2:error] [pid 511108:tid 511355] [client 4.204.201.85:16977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/adminfuns.php"] [unique_id "al9a-ITd5soprXwxAH3qcgAAAHU"]
[Tue Jul 21 08:41:44.774850 2026] [security2:error] [pid 511108:tid 511283] [client 203.25.124.2:38283] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/worksec.php"] [unique_id "al9a-ITd5soprXwxAH3qcwAAAC0"]
[Tue Jul 21 08:41:44.894460 2026] [security2:error] [pid 511108:tid 511112] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.extrapro21.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9a-ITd5soprXwxAH3qeAAAMwM"]
[Tue Jul 21 08:41:44.931456 2026] [security2:error] [pid 511108:tid 511270] [client 34.168.58.236:58359] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9a-ITd5soprXwxAH3qegAAACA"]
[Tue Jul 21 08:41:45.064085 2026] [security2:error] [pid 511108:tid 511271] [client 20.220.225.223:12604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/wp-editor.php"] [unique_id "al9a-YTd5soprXwxAH3qewAAACE"]
[Tue Jul 21 08:41:45.204127 2026] [security2:error] [pid 511108:tid 511181] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.extrapro21.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9a-YTd5soprXwxAH3qgQAAEEg"]
[Tue Jul 21 08:41:45.319885 2026] [security2:error] [pid 511108:tid 511266] [client 4.204.201.85:16898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/goods.php"] [unique_id "al9a-YTd5soprXwxAH3qhQAAABw"]
[Tue Jul 21 08:41:45.472767 2026] [security2:error] [pid 511108:tid 511137] [remote 156.59.198.135:53004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "insp1.com.br"] [uri "/wp-content/uploads/2021/11/313320_27b30dc0cba44e5bba8dd3c5ad3f3401_mv2-400x284.jpg"] [unique_id "al9a-YTd5soprXwxAH3qigAAJRw"], referer: https://insp1.com.br/empinando-as-pipas-do-conhecimento/
[Tue Jul 21 08:41:45.557392 2026] [security2:error] [pid 511108:tid 511138] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.extrapro21.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9a-YTd5soprXwxAH3qiwAASR0"]
[Tue Jul 21 08:41:45.569559 2026] [core:error] [pid 511108:tid 511144] [remote 198.235.24.128:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://webdisk.getveltrixhealth.com/
[Tue Jul 21 08:41:45.569594 2026] [core:error] [pid 511108:tid 511144] [remote 198.235.24.128:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://webdisk.getveltrixhealth.com/
[Tue Jul 21 08:41:45.662389 2026] [security2:error] [pid 511108:tid 511362] [client 34.168.58.236:52517] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9a-YTd5soprXwxAH3qlAAAAHw"]
[Tue Jul 21 08:41:45.764365 2026] [security2:error] [pid 511108:tid 511140] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.extrapro21.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9a-YTd5soprXwxAH3qlwAADx8"]
[Tue Jul 21 08:41:45.792652 2026] [security2:error] [pid 511108:tid 511147] [remote 185.177.238.46:47946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cownnex.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9a-YTd5soprXwxAH3qmAAAeyY"]
[Tue Jul 21 08:41:45.870470 2026] [security2:error] [pid 511108:tid 511328] [client 203.25.124.71:39547] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content.php"] [unique_id "al9a-YTd5soprXwxAH3qnAAAAFo"]
[Tue Jul 21 08:41:45.992878 2026] [security2:error] [pid 511108:tid 511128] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.extrapro21.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9a-YTd5soprXwxAH3qnwAAPRM"]
[Tue Jul 21 08:41:46.048104 2026] [security2:error] [pid 511108:tid 511264] [client 4.204.201.85:1479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/100.php"] [unique_id "al9a-oTd5soprXwxAH3qoQAAABo"]
[Tue Jul 21 08:41:46.184289 2026] [security2:error] [pid 511108:tid 511363] [client 185.177.238.46:52392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cownnex.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9a-oTd5soprXwxAH3qpgAAAH0"]
[Tue Jul 21 08:41:46.189740 2026] [security2:error] [pid 511108:tid 511244] [client 223.181.60.88:19825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9a-oTd5soprXwxAH3qpwAAAAY"]
[Tue Jul 21 08:41:46.191470 2026] [security2:error] [pid 511108:tid 511244] [client 223.181.60.88:19825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9a-oTd5soprXwxAH3qpwAAAAY"]
[Tue Jul 21 08:41:46.230012 2026] [security2:error] [pid 511108:tid 511317] [client 20.226.60.151:58509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/v543.php"] [unique_id "al9a-oTd5soprXwxAH3qqQAAAE8"]
[Tue Jul 21 08:41:46.299540 2026] [security2:error] [pid 511108:tid 511159] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.extrapro21.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9a-oTd5soprXwxAH3qrgAARzI"]
[Tue Jul 21 08:41:46.391210 2026] [security2:error] [pid 511108:tid 511282] [client 20.63.100.92:2749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/tkikikoko.php"] [unique_id "al9a-oTd5soprXwxAH3qsgAAACw"]
[Tue Jul 21 08:41:46.430174 2026] [security2:error] [pid 511108:tid 511318] [client 34.168.58.236:50097] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9a-oTd5soprXwxAH3qswAAAFA"]
[Tue Jul 21 08:41:46.507569 2026] [security2:error] [pid 511108:tid 511341] [client 20.220.225.223:12023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/cro.php"] [unique_id "al9a-oTd5soprXwxAH3qtAAAAGc"]
[Tue Jul 21 08:41:46.507602 2026] [security2:error] [pid 511108:tid 511229] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.extrapro21.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9a-oTd5soprXwxAH3qtQAAI3g"]
[Tue Jul 21 08:41:46.566979 2026] [security2:error] [pid 511108:tid 511359] [client 195.49.128.211:55618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9a-oTd5soprXwxAH3qtgAAAHk"]
[Tue Jul 21 08:41:46.567098 2026] [security2:error] [pid 511108:tid 511359] [client 195.49.128.211:55618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9a-oTd5soprXwxAH3qtgAAAHk"]
[Tue Jul 21 08:41:46.636913 2026] [security2:error] [pid 511108:tid 511267] [client 216.73.160.18:47319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9a-YTd5soprXwxAH3qjwAAAB0"]
[Tue Jul 21 08:41:46.669454 2026] [security2:error] [pid 511108:tid 511158] [remote 45.79.123.44:34048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9a-oTd5soprXwxAH3quAAAYjE"]
[Tue Jul 21 08:41:46.752908 2026] [security2:error] [pid 511108:tid 511163] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.extrapro21.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9a-oTd5soprXwxAH3qvgAAdzY"]
[Tue Jul 21 08:41:46.835625 2026] [security2:error] [pid 511108:tid 511240] [client 202.179.75.202:46804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9a-oTd5soprXwxAH3qwAAAAAI"]
[Tue Jul 21 08:41:46.835739 2026] [security2:error] [pid 511108:tid 511240] [client 202.179.75.202:46804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9a-oTd5soprXwxAH3qwAAAAAI"]
[Tue Jul 21 08:41:46.902541 2026] [security2:error] [pid 511108:tid 511157] [remote 91.142.222.105:33870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medoraldracena.com.br"] [uri "/wp-login.php"] [unique_id "al9a-oTd5soprXwxAH3qxAAADjA"]
[Tue Jul 21 08:41:46.949279 2026] [security2:error] [pid 511108:tid 511356] [client 103.59.206.240:31117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a-oTd5soprXwxAH3qxQAAAHY"]
[Tue Jul 21 08:41:46.949401 2026] [security2:error] [pid 511108:tid 511356] [client 103.59.206.240:31117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a-oTd5soprXwxAH3qxQAAAHY"]
[Tue Jul 21 08:41:46.961899 2026] [security2:error] [pid 511108:tid 511303] [client 203.25.124.70:46969] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/chosen.php"] [unique_id "al9a-oTd5soprXwxAH3qxgAAAEE"]
[Tue Jul 21 08:41:47.000982 2026] [security2:error] [pid 511108:tid 511136] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.extrapro21.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9a-oTd5soprXwxAH3qxwAAWxs"]
[Tue Jul 21 08:41:47.063620 2026] [security2:error] [pid 511108:tid 511156] [remote 65.111.21.65:26425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.21.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9a-4Td5soprXwxAH3qyAAAJS8"]
[Tue Jul 21 08:41:47.147725 2026] [security2:error] [pid 511108:tid 511291] [client 34.168.58.236:51279] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9a-4Td5soprXwxAH3qygAAADU"]
[Tue Jul 21 08:41:47.402110 2026] [security2:error] [pid 511108:tid 511166] [remote 185.177.238.46:47964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cownnex.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9a-4Td5soprXwxAH3q1wAAWjk"]
[Tue Jul 21 08:41:47.448272 2026] [security2:error] [pid 511108:tid 511307] [client 4.204.201.85:16897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/about.php"] [unique_id "al9a-4Td5soprXwxAH3q2AAAAEU"]
[Tue Jul 21 08:41:47.803006 2026] [security2:error] [pid 511108:tid 511359] [client 20.206.105.145:33625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/82.php"] [unique_id "al9a-4Td5soprXwxAH3q4AAAAHk"]
[Tue Jul 21 08:41:47.868341 2026] [security2:error] [pid 511108:tid 511164] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9a-4Td5soprXwxAH3q4gAARDc"]
[Tue Jul 21 08:41:47.868516 2026] [security2:error] [pid 511108:tid 511306] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9a-4Td5soprXwxAH3q4gAARDc"]
[Tue Jul 21 08:41:47.992979 2026] [security2:error] [pid 511108:tid 511265] [client 34.168.58.236:63539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9a-4Td5soprXwxAH3q5wAAABs"]
[Tue Jul 21 08:41:47.993080 2026] [security2:error] [pid 511108:tid 511179] [remote 185.177.238.46:47972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cownnex.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9a-4Td5soprXwxAH3q5gAAGEY"]
[Tue Jul 21 08:41:48.056824 2026] [security2:error] [pid 511108:tid 511314] [client 203.25.124.2:27377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/tinymce/themes/about.php"] [unique_id "al9a_ITd5soprXwxAH3q6wAAAEw"]
[Tue Jul 21 08:41:48.125766 2026] [autoindex:error] [pid 511108:tid 511300] [client 119.28.89.249:41962] AH01276: Cannot serve directory /home2/tiago878/public_html/hostserv/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:41:48.248985 2026] [security2:error] [pid 511108:tid 511291] [client 20.220.225.223:12579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/cron-tab.php"] [unique_id "al9a_ITd5soprXwxAH3q8gAAADU"]
[Tue Jul 21 08:41:48.382886 2026] [security2:error] [pid 511108:tid 511316] [client 185.177.238.46:52404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cownnex.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9a_ITd5soprXwxAH3q-QAAAE4"]
[Tue Jul 21 08:41:48.416161 2026] [autoindex:error] [pid 511108:tid 511196] [remote 74.7.242.36:56406] AH01276: Cannot serve directory /home1/princ430/cms.principiamatematica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:41:48.473762 2026] [security2:error] [pid 511108:tid 511344] [client 4.204.201.85:16955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/about.php"] [unique_id "al9a_ITd5soprXwxAH3q_QAAAGo"]
[Tue Jul 21 08:41:48.504173 2026] [security2:error] [pid 511108:tid 511340] [client 74.7.228.55:48284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.cms.principiamatematica.com"] [uri "/cgi-sys/404.html"] [unique_id "al9a_ITd5soprXwxAH3rAAAAZlY"]
[Tue Jul 21 08:41:48.705840 2026] [security2:error] [pid 511108:tid 511278] [client 34.168.58.236:54753] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9a_ITd5soprXwxAH3rAQAAACg"]
[Tue Jul 21 08:41:48.964125 2026] [security2:error] [pid 511108:tid 511309] [client 203.25.124.65:33905] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/ssss/src.php"] [unique_id "al9a_ITd5soprXwxAH3rDQAAAEc"]
[Tue Jul 21 08:41:48.969559 2026] [security2:error] [pid 511108:tid 511207] [remote 185.177.238.46:47974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.cownnex.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9a_ITd5soprXwxAH3rDgAAVGI"]
[Tue Jul 21 08:41:49.124358 2026] [security2:error] [pid 511108:tid 511202] [remote 45.3.45.107:27385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9a_ITd5soprXwxAH3rDAAAT10"]
[Tue Jul 21 08:41:49.220064 2026] [security2:error] [pid 511108:tid 511267] [client 20.63.100.92:2352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/wp-Blogs.php"] [unique_id "al9a_YTd5soprXwxAH3rFQAAAB0"]
[Tue Jul 21 08:41:49.298392 2026] [security2:error] [pid 511108:tid 511336] [client 20.197.192.193:43778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/fffm.php"] [unique_id "al9a_YTd5soprXwxAH3rFgAAAGI"]
[Tue Jul 21 08:41:49.307330 2026] [security2:error] [pid 511108:tid 511302] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9a_ITd5soprXwxAH3rCAAAAEA"]
[Tue Jul 21 08:41:49.426316 2026] [security2:error] [pid 511108:tid 511245] [client 34.168.58.236:50117] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9a_YTd5soprXwxAH3rHgAAAAc"]
[Tue Jul 21 08:41:49.497430 2026] [proxy:error] [pid 511108:tid 511360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:49.497468 2026] [proxy_http:error] [pid 511108:tid 511360] [client 205.210.31.25:57842] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:49.497956 2026] [proxy:error] [pid 511108:tid 511360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:49.497978 2026] [proxy_http:error] [pid 511108:tid 511360] [client 205.210.31.25:57842] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:49.511808 2026] [proxy:error] [pid 511108:tid 511310] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:49.511871 2026] [proxy_http:error] [pid 511108:tid 511310] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:49.512624 2026] [proxy:error] [pid 511108:tid 511310] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:49.512655 2026] [proxy_http:error] [pid 511108:tid 511310] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:49.554001 2026] [security2:error] [pid 511108:tid 511221] [remote 185.177.238.46:47976] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "cownnex.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9a_YTd5soprXwxAH3rJQAAG3A"]
[Tue Jul 21 08:41:49.613232 2026] [security2:error] [pid 511108:tid 511275] [client 4.204.201.85:16943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/admin.php"] [unique_id "al9a_YTd5soprXwxAH3rJwAAACU"]
[Tue Jul 21 08:41:49.615913 2026] [security2:error] [pid 511108:tid 511346] [client 195.49.128.211:63804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9a_YTd5soprXwxAH3rKAAAAGw"]
[Tue Jul 21 08:41:49.616000 2026] [security2:error] [pid 511108:tid 511346] [client 195.49.128.211:63804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9a_YTd5soprXwxAH3rKAAAAGw"]
[Tue Jul 21 08:41:49.923831 2026] [security2:error] [pid 511108:tid 511284] [client 152.59.181.104:64565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9a_YTd5soprXwxAH3rNQAAAC4"]
[Tue Jul 21 08:41:49.929131 2026] [security2:error] [pid 511108:tid 511284] [client 152.59.181.104:64565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9a_YTd5soprXwxAH3rNQAAAC4"]
[Tue Jul 21 08:41:49.944362 2026] [proxy:error] [pid 511108:tid 511283] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:49.944423 2026] [proxy_http:error] [pid 511108:tid 511283] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:49.944981 2026] [proxy:error] [pid 511108:tid 511283] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:49.945009 2026] [proxy_http:error] [pid 511108:tid 511283] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:49.945277 2026] [security2:error] [pid 511108:tid 511247] [client 185.177.238.46:52412] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "cownnex.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9a_YTd5soprXwxAH3rOAAAAAk"]
[Tue Jul 21 08:41:49.978552 2026] [security2:error] [pid 511108:tid 511331] [client 20.220.225.223:12564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/koiy.php"] [unique_id "al9a_YTd5soprXwxAH3rOQAAAF0"]
[Tue Jul 21 08:41:50.117230 2026] [security2:error] [pid 511108:tid 511248] [client 34.168.58.236:54545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9a_oTd5soprXwxAH3rOgAAAAo"]
[Tue Jul 21 08:41:50.331835 2026] [security2:error] [pid 511108:tid 511259] [client 4.204.201.85:1510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/admin.php"] [unique_id "al9a_oTd5soprXwxAH3rPgAAABU"]
[Tue Jul 21 08:41:50.354443 2026] [proxy:error] [pid 511108:tid 511298] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:50.354510 2026] [proxy_http:error] [pid 511108:tid 511298] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:50.355128 2026] [proxy:error] [pid 511108:tid 511298] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:41:50.355155 2026] [proxy_http:error] [pid 511108:tid 511298] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:41:50.363810 2026] [security2:error] [pid 511108:tid 511336] [client 212.32.76.3:30185] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/css/dist/components/"] [unique_id "al9a_oTd5soprXwxAH3rQgAAAGI"]
[Tue Jul 21 08:41:50.530013 2026] [security2:error] [pid 511108:tid 511226] [remote 185.177.238.46:47978] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.cownnex.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9a_oTd5soprXwxAH3rSQAAHXU"]
[Tue Jul 21 08:41:50.742952 2026] [security2:error] [pid 511108:tid 511228] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9a_oTd5soprXwxAH3rUgAAI3c"]
[Tue Jul 21 08:41:50.743136 2026] [security2:error] [pid 511108:tid 511273] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9a_oTd5soprXwxAH3rUgAAI3c"]
[Tue Jul 21 08:41:50.820122 2026] [security2:error] [pid 511108:tid 511262] [client 34.168.58.236:54230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9a_oTd5soprXwxAH3rVwAAABg"]
[Tue Jul 21 08:41:51.025868 2026] [security2:error] [pid 511108:tid 511284] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a_4Td5soprXwxAH3rYQAAAC4"]
[Tue Jul 21 08:41:51.049055 2026] [security2:error] [pid 511108:tid 511339] [client 117.213.202.34:61760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a_oTd5soprXwxAH3rWgAAAGU"]
[Tue Jul 21 08:41:51.049223 2026] [security2:error] [pid 511108:tid 511339] [client 117.213.202.34:61760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a_oTd5soprXwxAH3rWgAAAGU"]
[Tue Jul 21 08:41:51.424930 2026] [security2:error] [pid 511108:tid 511270] [client 4.204.201.85:1497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/themes.php"] [unique_id "al9a_4Td5soprXwxAH3rZwAAACA"]
[Tue Jul 21 08:41:51.468526 2026] [security2:error] [pid 511108:tid 511257] [client 203.25.124.43:64079] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/files/"] [unique_id "al9a_4Td5soprXwxAH3rawAAABM"]
[Tue Jul 21 08:41:51.526605 2026] [security2:error] [pid 511108:tid 511317] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9a_4Td5soprXwxAH3rbgAAAE8"]
[Tue Jul 21 08:41:51.564147 2026] [security2:error] [pid 511108:tid 511289] [client 34.168.58.236:50826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cezaretto.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9a_4Td5soprXwxAH3rcQAAADM"]
[Tue Jul 21 08:41:51.641341 2026] [security2:error] [pid 511108:tid 511305] [client 113.22.144.139:62878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a_4Td5soprXwxAH3rcgAAAEM"]
[Tue Jul 21 08:41:51.642050 2026] [security2:error] [pid 511108:tid 511305] [client 113.22.144.139:62878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a_4Td5soprXwxAH3rcgAAAEM"]
[Tue Jul 21 08:41:51.703400 2026] [security2:error] [pid 511108:tid 511295] [client 59.95.197.55:63241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a_4Td5soprXwxAH3rdgAAADk"]
[Tue Jul 21 08:41:51.703527 2026] [security2:error] [pid 511108:tid 511295] [client 59.95.197.55:63241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9a_4Td5soprXwxAH3rdgAAADk"]
[Tue Jul 21 08:41:51.719661 2026] [security2:error] [pid 511108:tid 511280] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9a_4Td5soprXwxAH3rZgAAACo"]
[Tue Jul 21 08:41:52.061244 2026] [security2:error] [pid 511108:tid 511297] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9bAITd5soprXwxAH3rfgAAADs"]
[Tue Jul 21 08:41:52.253616 2026] [security2:error] [pid 511108:tid 511329] [client 4.204.201.85:16915] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-includes/blocks/details/"] [unique_id "al9bAITd5soprXwxAH3rgAAAAFs"]
[Tue Jul 21 08:41:52.368283 2026] [security2:error] [pid 511108:tid 511294] [client 203.25.124.72:33717] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/themes.php"] [unique_id "al9bAITd5soprXwxAH3rhAAAADg"]
[Tue Jul 21 08:41:52.461496 2026] [security2:error] [pid 511108:tid 511328] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9bAITd5soprXwxAH3rhgAAAFo"]
[Tue Jul 21 08:41:52.644855 2026] [security2:error] [pid 511108:tid 511350] [client 49.144.66.253:32728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bAITd5soprXwxAH3rkwAAAHA"]
[Tue Jul 21 08:41:52.644959 2026] [security2:error] [pid 511108:tid 511350] [client 49.144.66.253:32728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bAITd5soprXwxAH3rkwAAAHA"]
[Tue Jul 21 08:41:52.660283 2026] [security2:error] [pid 511108:tid 511283] [client 20.63.100.92:2672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/wp-css.php"] [unique_id "al9bAITd5soprXwxAH3rlAAAAC0"]
[Tue Jul 21 08:41:52.664752 2026] [security2:error] [pid 511108:tid 511246] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bAITd5soprXwxAH3rjQAACGM"]
[Tue Jul 21 08:41:52.681166 2026] [security2:error] [pid 511108:tid 511343] [client 20.220.225.223:12596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/hp2.php"] [unique_id "al9bAITd5soprXwxAH3rlQAAAGk"]
[Tue Jul 21 08:41:52.899667 2026] [security2:error] [pid 511108:tid 511312] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9bAITd5soprXwxAH3rmAAAAEo"]
[Tue Jul 21 08:41:52.917216 2026] [security2:error] [pid 511108:tid 511316] [client 122.176.100.127:64242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bAITd5soprXwxAH3rmQAAAE4"]
[Tue Jul 21 08:41:52.917389 2026] [security2:error] [pid 511108:tid 511316] [client 122.176.100.127:64242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bAITd5soprXwxAH3rmQAAAE4"]
[Tue Jul 21 08:41:53.062925 2026] [security2:error] [pid 511108:tid 511303] [client 61.1.167.83:55838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bAYTd5soprXwxAH3rnwAAAEE"]
[Tue Jul 21 08:41:53.065917 2026] [security2:error] [pid 511108:tid 511303] [client 61.1.167.83:55838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bAYTd5soprXwxAH3rnwAAAEE"]
[Tue Jul 21 08:41:53.121642 2026] [security2:error] [pid 511108:tid 511281] [client 4.204.201.85:16991] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-includes/blocks/audi/"] [unique_id "al9bAYTd5soprXwxAH3rpAAAACs"]
[Tue Jul 21 08:41:53.341227 2026] [security2:error] [pid 511108:tid 511364] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9bAYTd5soprXwxAH3rpgAAAH4"]
[Tue Jul 21 08:41:53.574967 2026] [security2:error] [pid 511108:tid 511359] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bAYTd5soprXwxAH3rogAAAHk"]
[Tue Jul 21 08:41:53.676681 2026] [security2:error] [pid 511108:tid 511300] [client 203.25.124.32:41375] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/ahax.php"] [unique_id "al9bAYTd5soprXwxAH3rrgAAAD4"]
[Tue Jul 21 08:41:53.709211 2026] [security2:error] [pid 511108:tid 511267] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9bAYTd5soprXwxAH3rsQAAAB0"]
[Tue Jul 21 08:41:53.864704 2026] [security2:error] [pid 511108:tid 511275] [client 4.204.201.85:1474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/.well-known/about.php"] [unique_id "al9bAYTd5soprXwxAH3rtAAAACU"]
[Tue Jul 21 08:41:53.965361 2026] [security2:error] [pid 511108:tid 511260] [client 20.206.105.145:33758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/config.json.php"] [unique_id "al9bAYTd5soprXwxAH3rtgAAABY"]
[Tue Jul 21 08:41:54.122365 2026] [security2:error] [pid 511108:tid 511339] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9bAoTd5soprXwxAH3rwgAAAGU"]
[Tue Jul 21 08:41:54.135183 2026] [security2:error] [pid 511108:tid 511264] [client 172.104.172.64:52172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "trab.giovanoniadv.com.br"] [uri "/"] [unique_id "al9bAoTd5soprXwxAH3rwwAAABo"]
[Tue Jul 21 08:41:54.527521 2026] [security2:error] [pid 511108:tid 511244] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9bAoTd5soprXwxAH3rzwAAAAY"]
[Tue Jul 21 08:41:54.667266 2026] [security2:error] [pid 511108:tid 511336] [client 203.25.124.69:65377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/images/"] [unique_id "al9bAoTd5soprXwxAH3r1QAAAGI"]
[Tue Jul 21 08:41:54.678403 2026] [security2:error] [pid 511108:tid 511361] [client 4.204.201.85:16916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9bAoTd5soprXwxAH3r1gAAAHs"]
[Tue Jul 21 08:41:54.856482 2026] [security2:error] [pid 511108:tid 511299] [client 5.38.115.39:28752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bAoTd5soprXwxAH3r3wAAAD0"]
[Tue Jul 21 08:41:54.856618 2026] [security2:error] [pid 511108:tid 511299] [client 5.38.115.39:28752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bAoTd5soprXwxAH3r3wAAAD0"]
[Tue Jul 21 08:41:54.978916 2026] [security2:error] [pid 511108:tid 511157] [remote 57.141.18.114:55392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/rk-centro-automotivo/"] [unique_id "al9bAoTd5soprXwxAH3r4QAABzA"]
[Tue Jul 21 08:41:54.999212 2026] [security2:error] [pid 511108:tid 511238] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9bAoTd5soprXwxAH3r4wAAAAA"]
[Tue Jul 21 08:41:55.082869 2026] [security2:error] [pid 511108:tid 511349] [client 20.220.225.223:12560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/hp3.php"] [unique_id "al9bA4Td5soprXwxAH3r5QAAAG8"]
[Tue Jul 21 08:41:55.372404 2026] [security2:error] [pid 511108:tid 511162] [remote 142.93.2.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.2.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bA4Td5soprXwxAH3r8QAAGjU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:41:55.454035 2026] [security2:error] [pid 511108:tid 511319] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9bA4Td5soprXwxAH3r9gAAAFE"]
[Tue Jul 21 08:41:55.512002 2026] [security2:error] [pid 511108:tid 511155] [remote 142.93.2.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.2.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bA4Td5soprXwxAH3r7wAAWy4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:41:55.527507 2026] [security2:error] [pid 511108:tid 511167] [remote 142.93.2.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.2.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bA4Td5soprXwxAH3r8AAAQDo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:41:55.560006 2026] [security2:error] [pid 511108:tid 511283] [client 212.32.76.7:60731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/preformatted/"] [unique_id "al9bA4Td5soprXwxAH3r-gAAAC0"]
[Tue Jul 21 08:41:55.670228 2026] [security2:error] [pid 511108:tid 511171] [remote 142.93.2.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.2.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bA4Td5soprXwxAH3sAAAAID4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:41:55.687479 2026] [security2:error] [pid 511108:tid 511179] [remote 142.93.2.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.2.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bA4Td5soprXwxAH3sAQAAXkY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:41:55.689373 2026] [security2:error] [pid 511108:tid 511287] [client 4.204.201.85:1512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/wefile.php"] [unique_id "al9bA4Td5soprXwxAH3sAgAAADE"]
[Tue Jul 21 08:41:55.787911 2026] [security2:error] [pid 511108:tid 511182] [remote 142.93.2.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.2.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bA4Td5soprXwxAH3sBwAAQkk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:41:55.920440 2026] [security2:error] [pid 511108:tid 511323] [client 20.226.60.151:58537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/sixxis.php"] [unique_id "al9bA4Td5soprXwxAH3sCQAAAFU"]
[Tue Jul 21 08:41:55.958471 2026] [security2:error] [pid 511108:tid 511363] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9bA4Td5soprXwxAH3sCwAAAH0"]
[Tue Jul 21 08:41:55.962547 2026] [security2:error] [pid 511108:tid 511187] [remote 142.93.2.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.2.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bA4Td5soprXwxAH3sDAAAIU4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:41:56.069918 2026] [security2:error] [pid 511108:tid 511190] [remote 142.93.2.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.2.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bBITd5soprXwxAH3sDQAAflE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:41:56.073324 2026] [security2:error] [pid 511108:tid 511196] [remote 142.93.2.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.2.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bBITd5soprXwxAH3sDgAAclc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:41:56.086948 2026] [security2:error] [pid 511108:tid 511340] [client 20.63.100.92:5663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/wp-explorer.php"] [unique_id "al9bBITd5soprXwxAH3sDwAAAGY"]
[Tue Jul 21 08:41:56.137491 2026] [security2:error] [pid 511108:tid 511193] [remote 142.93.2.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.2.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bBITd5soprXwxAH3sEAAAKlQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:41:56.214011 2026] [security2:error] [pid 511108:tid 511173] [remote 142.93.2.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.2.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bBITd5soprXwxAH3sFgAAfEA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:41:56.339706 2026] [security2:error] [pid 511108:tid 511297] [client 4.204.201.85:16987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9bBITd5soprXwxAH3sGgAAADs"]
[Tue Jul 21 08:41:56.351402 2026] [security2:error] [pid 511108:tid 511149] [remote 142.93.2.214:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.2.93.142.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bA4Td5soprXwxAH3r7gAAWig"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:41:56.370722 2026] [security2:error] [pid 511108:tid 511292] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bA4Td5soprXwxAH3sCgAAADY"]
[Tue Jul 21 08:41:56.372977 2026] [security2:error] [pid 511108:tid 511330] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9bBITd5soprXwxAH3sIAAAAFw"]
[Tue Jul 21 08:41:56.454379 2026] [security2:error] [pid 511108:tid 511276] [client 20.226.60.151:58502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/ip.php"] [unique_id "al9bBITd5soprXwxAH3sIQAAACY"]
[Tue Jul 21 08:41:56.524488 2026] [security2:error] [pid 511108:tid 511326] [client 20.226.60.151:34873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/kq1.php"] [unique_id "al9bBITd5soprXwxAH3sIgAAAFg"]
[Tue Jul 21 08:41:56.581252 2026] [security2:error] [pid 511108:tid 511278] [client 20.226.60.151:58545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/fw/faiyy.php"] [unique_id "al9bBITd5soprXwxAH3sIwAAACg"]
[Tue Jul 21 08:41:56.676118 2026] [security2:error] [pid 511108:tid 511360] [client 198.44.157.34:37000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bBITd5soprXwxAH3sJQAAAHo"]
[Tue Jul 21 08:41:56.676252 2026] [security2:error] [pid 511108:tid 511360] [client 198.44.157.34:37000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bBITd5soprXwxAH3sJQAAAHo"]
[Tue Jul 21 08:41:56.838250 2026] [security2:error] [pid 511108:tid 511239] [client 4.204.201.85:14048] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al9bBITd5soprXwxAH3sLQAAAAE"]
[Tue Jul 21 08:41:56.931215 2026] [security2:error] [pid 511108:tid 511312] [client 20.220.225.223:12318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/aa1.php"] [unique_id "al9bBITd5soprXwxAH3sMAAAAEo"]
[Tue Jul 21 08:41:56.952775 2026] [security2:error] [pid 511108:tid 511356] [client 223.181.60.88:28762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9bBITd5soprXwxAH3sMQAAAHY"]
[Tue Jul 21 08:41:56.953057 2026] [security2:error] [pid 511108:tid 511356] [client 223.181.60.88:28762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9bBITd5soprXwxAH3sMQAAAHY"]
[Tue Jul 21 08:41:56.961691 2026] [security2:error] [pid 511108:tid 511287] [client 20.226.60.151:58620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/h02ugyh.php"] [unique_id "al9bBITd5soprXwxAH3sMgAAADE"]
[Tue Jul 21 08:41:57.159943 2026] [security2:error] [pid 511108:tid 511309] [client 203.25.124.41:51557] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "al9bBYTd5soprXwxAH3sNQAAAEc"]
[Tue Jul 21 08:41:57.254972 2026] [security2:error] [pid 511108:tid 511336] [client 20.220.225.223:12577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/acew67.php"] [unique_id "al9bBYTd5soprXwxAH3sOQAAAGI"]
[Tue Jul 21 08:41:57.268505 2026] [security2:error] [pid 511108:tid 511333] [client 195.49.128.211:56221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bBYTd5soprXwxAH3sOgAAAF8"]
[Tue Jul 21 08:41:57.268591 2026] [security2:error] [pid 511108:tid 511333] [client 195.49.128.211:56221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bBYTd5soprXwxAH3sOgAAAF8"]
[Tue Jul 21 08:41:57.271379 2026] [security2:error] [pid 511108:tid 511257] [client 20.197.192.193:65157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/ftde.php"] [unique_id "al9bBYTd5soprXwxAH3sOwAAABM"]
[Tue Jul 21 08:41:57.306574 2026] [security2:error] [pid 511108:tid 511271] [client 198.44.157.34:36988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9bBYTd5soprXwxAH3sPwAAACE"]
[Tue Jul 21 08:41:57.306656 2026] [security2:error] [pid 511108:tid 511271] [client 198.44.157.34:36988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9bBYTd5soprXwxAH3sPwAAACE"]
[Tue Jul 21 08:41:57.443862 2026] [security2:error] [pid 511108:tid 511288] [client 20.63.100.92:6438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/akismet.php"] [unique_id "al9bBYTd5soprXwxAH3sRAAAADI"]
[Tue Jul 21 08:41:57.583144 2026] [security2:error] [pid 511108:tid 511291] [client 4.204.201.85:14073] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-admin/js/"] [unique_id "al9bBYTd5soprXwxAH3sSAAAADU"]
[Tue Jul 21 08:41:57.587328 2026] [security2:error] [pid 511108:tid 511243] [client 103.59.206.240:31239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bBYTd5soprXwxAH3sSQAAAAU"]
[Tue Jul 21 08:41:57.587454 2026] [security2:error] [pid 511108:tid 511243] [client 103.59.206.240:31239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bBYTd5soprXwxAH3sSQAAAAU"]
[Tue Jul 21 08:41:57.686672 2026] [security2:error] [pid 511108:tid 511359] [client 173.252.95.11:39846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bBYTd5soprXwxAH3sTQAAAHk"]
[Tue Jul 21 08:41:57.748595 2026] [security2:error] [pid 511108:tid 511352] [client 202.179.75.202:45672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bBYTd5soprXwxAH3sTgAAAHI"]
[Tue Jul 21 08:41:57.748713 2026] [security2:error] [pid 511108:tid 511352] [client 202.179.75.202:45672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bBYTd5soprXwxAH3sTgAAAHI"]
[Tue Jul 21 08:41:57.978875 2026] [security2:error] [pid 511108:tid 511350] [client 20.220.225.223:12556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/bscclapb.php"] [unique_id "al9bBYTd5soprXwxAH3sVgAAAHA"]
[Tue Jul 21 08:41:58.041550 2026] [security2:error] [pid 511108:tid 511175] [remote 195.26.244.42:51944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9bBYTd5soprXwxAH3sMwAAU0I"]
[Tue Jul 21 08:41:58.066492 2026] [security2:error] [pid 511108:tid 511319] [client 203.25.124.32:30333] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/customize/"] [unique_id "al9bBoTd5soprXwxAH3sWQAAAFE"]
[Tue Jul 21 08:41:58.129417 2026] [security2:error] [pid 511108:tid 511358] [client 4.204.201.85:17011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9bBoTd5soprXwxAH3sWgAAAHg"]
[Tue Jul 21 08:41:58.181518 2026] [security2:error] [pid 511108:tid 511299] [client 114.119.159.17:29779] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "onkosclinica.com.br"] [uri "/home/computador-pode-auxiliar-no-diagnostico-do-cancer-de-pulmao"] [unique_id "al9bBoTd5soprXwxAH3sXAAAAD0"], referer: http://onkosclinica.com.br/home/postagem/page/3
[Tue Jul 21 08:41:58.267405 2026] [security2:error] [pid 511108:tid 511239] [client 20.197.192.193:65198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/yup.php"] [unique_id "al9bBoTd5soprXwxAH3sYAAAAAE"]
[Tue Jul 21 08:41:58.295474 2026] [security2:error] [pid 511108:tid 511332] [client 20.220.225.223:12299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/else1.php"] [unique_id "al9bBoTd5soprXwxAH3sYwAAAF4"]
[Tue Jul 21 08:41:58.380141 2026] [security2:error] [pid 511108:tid 511226] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bBoTd5soprXwxAH3sagAAJHU"]
[Tue Jul 21 08:41:58.380299 2026] [security2:error] [pid 511108:tid 511274] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bBoTd5soprXwxAH3sagAAJHU"]
[Tue Jul 21 08:41:58.907808 2026] [security2:error] [pid 511108:tid 511281] [client 69.171.230.42:54030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bBoTd5soprXwxAH3sdwAAACs"]
[Tue Jul 21 08:41:58.913346 2026] [security2:error] [pid 511108:tid 511349] [client 20.226.60.151:34869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-temp.php"] [unique_id "al9bBoTd5soprXwxAH3sgQAAAG8"]
[Tue Jul 21 08:41:58.934113 2026] [security2:error] [pid 511108:tid 511324] [client 20.220.225.223:12011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/tkikikoko.php"] [unique_id "al9bBoTd5soprXwxAH3shAAAAFY"]
[Tue Jul 21 08:41:58.959771 2026] [security2:error] [pid 511108:tid 511342] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bBoTd5soprXwxAH3sbwAAAGg"]
[Tue Jul 21 08:41:59.163655 2026] [security2:error] [pid 511108:tid 511355] [client 203.25.124.33:22037] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/classwithtostring.php"] [unique_id "al9bB4Td5soprXwxAH3sjgAAAHU"]
[Tue Jul 21 08:41:59.199235 2026] [security2:error] [pid 511108:tid 511313] [client 47.128.98.141:61984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "inonebrasil.com.br"] [uri "/robots.txt"] [unique_id "al9bB4Td5soprXwxAH3sjwAAAEs"]
[Tue Jul 21 08:41:59.247768 2026] [security2:error] [pid 511108:tid 511304] [client 74.7.241.131:46180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "divvinotrip.com.br"] [uri "/index.php"] [unique_id "al9bBoTd5soprXwxAH3sbgAAQnc"]
[Tue Jul 21 08:41:59.294661 2026] [security2:error] [pid 511108:tid 511263] [client 4.204.201.85:1530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/8.php"] [unique_id "al9bB4Td5soprXwxAH3skgAAABk"]
[Tue Jul 21 08:41:59.547054 2026] [security2:error] [pid 511108:tid 511298] [client 20.220.225.223:12576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9bB4Td5soprXwxAH3snQAAADw"]
[Tue Jul 21 08:42:00.057677 2026] [security2:error] [pid 511108:tid 511295] [client 74.7.241.131:46196] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.divvinotrip.com.br"] [uri "/index.php"] [unique_id "al9bB4Td5soprXwxAH3sqwAAORY"], referer: https://divvinotrip.com.br/robots.txt
[Tue Jul 21 08:42:00.166066 2026] [security2:error] [pid 511108:tid 511349] [client 20.197.192.193:65176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/jj.php"] [unique_id "al9bCITd5soprXwxAH3srQAAAG8"]
[Tue Jul 21 08:42:00.171771 2026] [security2:error] [pid 511108:tid 511324] [client 203.25.124.74:54071] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/gallery/"] [unique_id "al9bCITd5soprXwxAH3srgAAAFY"]
[Tue Jul 21 08:42:00.211872 2026] [security2:error] [pid 511108:tid 511342] [client 4.204.201.85:16980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-content/admin.php"] [unique_id "al9bCITd5soprXwxAH3srwAAAGg"]
[Tue Jul 21 08:42:00.250688 2026] [security2:error] [pid 511108:tid 511356] [client 195.49.128.211:64408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bCITd5soprXwxAH3ssAAAAHY"]
[Tue Jul 21 08:42:00.250802 2026] [security2:error] [pid 511108:tid 511356] [client 195.49.128.211:64408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bCITd5soprXwxAH3ssAAAAHY"]
[Tue Jul 21 08:42:00.320261 2026] [security2:error] [pid 511108:tid 511330] [client 20.226.60.151:58518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-content/cong.php"] [unique_id "al9bCITd5soprXwxAH3ssQAAAFw"]
[Tue Jul 21 08:42:00.517459 2026] [security2:error] [pid 511108:tid 511266] [client 74.7.230.5:53088] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.divvinotrip.com.br"] [uri "/index.php"] [unique_id "al9bCITd5soprXwxAH3suAAAHAA"]
[Tue Jul 21 08:42:00.795677 2026] [security2:error] [pid 511108:tid 511280] [client 152.59.181.104:65043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bCITd5soprXwxAH3swgAAACo"]
[Tue Jul 21 08:42:00.795780 2026] [security2:error] [pid 511108:tid 511280] [client 152.59.181.104:65043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bCITd5soprXwxAH3swgAAACo"]
[Tue Jul 21 08:42:00.963474 2026] [security2:error] [pid 511108:tid 511254] [client 4.204.201.85:17018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/f6.php"] [unique_id "al9bCITd5soprXwxAH3sygAAABA"]
[Tue Jul 21 08:42:01.025880 2026] [proxy:error] [pid 511108:tid 511333] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:01.025947 2026] [proxy_http:error] [pid 511108:tid 511333] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:01.026698 2026] [proxy:error] [pid 511108:tid 511333] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:01.026733 2026] [proxy_http:error] [pid 511108:tid 511333] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:01.315682 2026] [security2:error] [pid 511108:tid 511146] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bCYTd5soprXwxAH3s0gAARyU"]
[Tue Jul 21 08:42:01.315862 2026] [security2:error] [pid 511108:tid 511309] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bCYTd5soprXwxAH3s0gAARyU"]
[Tue Jul 21 08:42:01.417746 2026] [security2:error] [pid 511108:tid 511304] [client 117.213.202.34:62368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bCYTd5soprXwxAH3s1wAAAEI"]
[Tue Jul 21 08:42:01.417891 2026] [security2:error] [pid 511108:tid 511304] [client 117.213.202.34:62368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bCYTd5soprXwxAH3s1wAAAEI"]
[Tue Jul 21 08:42:01.419911 2026] [security2:error] [pid 511108:tid 511264] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bCITd5soprXwxAH3syQAAABo"]
[Tue Jul 21 08:42:01.436755 2026] [proxy:error] [pid 511108:tid 511336] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:01.436825 2026] [proxy_http:error] [pid 511108:tid 511336] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:01.437522 2026] [proxy:error] [pid 511108:tid 511336] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:01.437554 2026] [proxy_http:error] [pid 511108:tid 511336] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:01.536496 2026] [security2:error] [pid 511108:tid 511356] [client 64.42.179.43:51074] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9bCYTd5soprXwxAH3s3AAAAHY"]
[Tue Jul 21 08:42:01.536580 2026] [security2:error] [pid 511108:tid 511356] [client 64.42.179.43:51074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9bCYTd5soprXwxAH3s3AAAAHY"]
[Tue Jul 21 08:42:01.767143 2026] [security2:error] [pid 511108:tid 511256] [client 203.25.124.33:52591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/js/widgets/images/"] [unique_id "al9bCYTd5soprXwxAH3s5AAAABI"]
[Tue Jul 21 08:42:01.951757 2026] [security2:error] [pid 511108:tid 511360] [client 4.204.201.85:1506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/inputs.php"] [unique_id "al9bCYTd5soprXwxAH3s6gAAAHo"]
[Tue Jul 21 08:42:01.993091 2026] [proxy:error] [pid 511108:tid 511263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:01.993181 2026] [proxy_http:error] [pid 511108:tid 511263] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:01.994165 2026] [proxy:error] [pid 511108:tid 511263] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:01.994212 2026] [proxy_http:error] [pid 511108:tid 511263] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:02.258708 2026] [security2:error] [pid 511108:tid 511292] [client 59.95.197.55:63693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bCoTd5soprXwxAH3s9wAAADY"]
[Tue Jul 21 08:42:02.258851 2026] [security2:error] [pid 511108:tid 511292] [client 59.95.197.55:63693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bCoTd5soprXwxAH3s9wAAADY"]
[Tue Jul 21 08:42:02.476190 2026] [security2:error] [pid 511108:tid 511348] [client 113.22.144.139:63389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bCoTd5soprXwxAH3s_QAAAG4"]
[Tue Jul 21 08:42:02.476331 2026] [security2:error] [pid 511108:tid 511348] [client 113.22.144.139:63389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bCoTd5soprXwxAH3s_QAAAG4"]
[Tue Jul 21 08:42:02.501219 2026] [security2:error] [pid 511108:tid 511276] [client 172.104.172.64:57016] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "trabalhista.giovanoniadv.com.br"] [uri "/"] [unique_id "al9bCoTd5soprXwxAH3s_gAAACY"]
[Tue Jul 21 08:42:02.514627 2026] [security2:error] [pid 511108:tid 511315] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bCoTd5soprXwxAH3tAAAAAE0"]
[Tue Jul 21 08:42:02.603152 2026] [security2:error] [pid 511108:tid 511334] [client 20.220.225.223:12292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/wp-css.php"] [unique_id "al9bCoTd5soprXwxAH3tBAAAAGA"]
[Tue Jul 21 08:42:02.712896 2026] [security2:error] [pid 511108:tid 511323] [client 4.204.201.85:16917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/inputs.php"] [unique_id "al9bCoTd5soprXwxAH3tCAAAAFU"]
[Tue Jul 21 08:42:02.944861 2026] [security2:error] [pid 511108:tid 511264] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9bCoTd5soprXwxAH3tDAAAABo"]
[Tue Jul 21 08:42:03.161482 2026] [security2:error] [pid 511108:tid 511291] [client 203.25.124.2:60193] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/imgareaselect/"] [unique_id "al9bC4Td5soprXwxAH3tFAAAADU"]
[Tue Jul 21 08:42:03.228657 2026] [security2:error] [pid 511108:tid 511312] [client 168.167.81.163:59280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bC4Td5soprXwxAH3tGAAAAEo"]
[Tue Jul 21 08:42:03.229583 2026] [security2:error] [pid 511108:tid 511312] [client 168.167.81.163:59280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bC4Td5soprXwxAH3tGAAAAEo"]
[Tue Jul 21 08:42:03.294731 2026] [security2:error] [pid 511108:tid 511262] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bC4Td5soprXwxAH3tFwAAGDg"]
[Tue Jul 21 08:42:03.295161 2026] [security2:error] [pid 511108:tid 511327] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bC4Td5soprXwxAH3tEgAAAFk"]
[Tue Jul 21 08:42:03.375015 2026] [security2:error] [pid 511108:tid 511296] [client 122.176.100.127:64748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bC4Td5soprXwxAH3tHQAAADo"]
[Tue Jul 21 08:42:03.375169 2026] [security2:error] [pid 511108:tid 511296] [client 122.176.100.127:64748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bC4Td5soprXwxAH3tHQAAADo"]
[Tue Jul 21 08:42:03.526294 2026] [security2:error] [pid 511108:tid 511360] [client 20.220.225.223:11997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/wp-explorer.php"] [unique_id "al9bC4Td5soprXwxAH3tIgAAAHo"]
[Tue Jul 21 08:42:03.627371 2026] [security2:error] [pid 511108:tid 511243] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9bC4Td5soprXwxAH3tJgAAAAU"]
[Tue Jul 21 08:42:03.682862 2026] [security2:error] [pid 511108:tid 511242] [client 20.206.105.145:33637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppon24h.com.br"] [uri "/fpwch.php"] [unique_id "al9bC4Td5soprXwxAH3tKAAAAAQ"]
[Tue Jul 21 08:42:03.902904 2026] [security2:error] [pid 511108:tid 511328] [client 5.31.193.106:29954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bC4Td5soprXwxAH3tLAAAAFo"]
[Tue Jul 21 08:42:03.909251 2026] [security2:error] [pid 511108:tid 511328] [client 5.31.193.106:29954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bC4Td5soprXwxAH3tLAAAAFo"]
[Tue Jul 21 08:42:03.961734 2026] [security2:error] [pid 511108:tid 511244] [client 203.25.124.66:55847] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "al9bC4Td5soprXwxAH3tLQAAAAY"]
[Tue Jul 21 08:42:03.984373 2026] [security2:error] [pid 511108:tid 511345] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bC4Td5soprXwxAH3tIQAAAGs"]
[Tue Jul 21 08:42:04.045323 2026] [security2:error] [pid 511108:tid 511257] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9bDITd5soprXwxAH3tOAAAABM"]
[Tue Jul 21 08:42:04.071656 2026] [security2:error] [pid 511108:tid 511347] [client 49.144.66.253:33144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bDITd5soprXwxAH3tOQAAAG0"]
[Tue Jul 21 08:42:04.071801 2026] [security2:error] [pid 511108:tid 511347] [client 49.144.66.253:33144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bDITd5soprXwxAH3tOQAAAG0"]
[Tue Jul 21 08:42:04.283569 2026] [security2:error] [pid 511108:tid 511307] [client 4.204.201.85:1454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/classwithtostring.php"] [unique_id "al9bDITd5soprXwxAH3tQQAAAEU"]
[Tue Jul 21 08:42:04.443781 2026] [security2:error] [pid 511108:tid 511286] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9bDITd5soprXwxAH3tRgAAADA"]
[Tue Jul 21 08:42:04.595517 2026] [security2:error] [pid 511108:tid 511341] [client 20.197.192.193:43785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/dragonshell.php"] [unique_id "al9bDITd5soprXwxAH3tTQAAAGc"]
[Tue Jul 21 08:42:04.837301 2026] [security2:error] [pid 511108:tid 511329] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9bDITd5soprXwxAH3tWQAAAFs"]
[Tue Jul 21 08:42:04.943326 2026] [security2:error] [pid 511108:tid 511298] [client 20.226.114.112:14454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9bDITd5soprXwxAH3tYwAAADw"]
[Tue Jul 21 08:42:04.964716 2026] [security2:error] [pid 511108:tid 511316] [client 212.32.76.10:48039] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/shell/"] [unique_id "al9bDITd5soprXwxAH3tZQAAAE4"]
[Tue Jul 21 08:42:04.990526 2026] [security2:error] [pid 511108:tid 511333] [client 20.220.225.223:11993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/akismet.php"] [unique_id "al9bDITd5soprXwxAH3tZwAAAF8"]
[Tue Jul 21 08:42:05.016846 2026] [security2:error] [pid 511108:tid 511251] [client 20.226.114.112:15865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.114.226.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "asserradaliberdade.ong.br"] [uri "/xmlrpc.php"] [unique_id "al9bDYTd5soprXwxAH3taAAAAA0"]
[Tue Jul 21 08:42:05.032855 2026] [security2:error] [pid 511108:tid 511337] [client 20.226.114.112:15865] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3taQAAAGM"]
[Tue Jul 21 08:42:05.049245 2026] [security2:error] [pid 511108:tid 511343] [client 20.226.114.112:15859] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3tawAAAGk"]
[Tue Jul 21 08:42:05.061763 2026] [security2:error] [pid 511108:tid 511249] [client 20.226.114.112:8570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3tbAAAAAs"]
[Tue Jul 21 08:42:05.082974 2026] [security2:error] [pid 511108:tid 511365] [client 4.204.201.85:16968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9bDYTd5soprXwxAH3tbgAAAH8"]
[Tue Jul 21 08:42:05.086837 2026] [security2:error] [pid 511108:tid 511314] [client 20.226.114.112:15372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3tcAAAAEw"]
[Tue Jul 21 08:42:05.114416 2026] [security2:error] [pid 511108:tid 511351] [client 20.226.114.112:15371] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3tcwAAAHE"]
[Tue Jul 21 08:42:05.130964 2026] [authz_core:error] [pid 511108:tid 511362] [client 136.67.86.240:0] AH01630: client denied by server configuration: /home4/serric15/contafic.com.br/wp-includes/ID3/license.txt
[Tue Jul 21 08:42:05.145083 2026] [security2:error] [pid 511108:tid 511311] [client 20.226.114.112:15378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3tdwAAAEk"]
[Tue Jul 21 08:42:05.161885 2026] [security2:error] [pid 511108:tid 511264] [client 20.226.114.112:8538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3teAAAABo"]
[Tue Jul 21 08:42:05.179581 2026] [security2:error] [pid 511108:tid 511349] [client 20.226.114.112:14428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3teQAAAG8"]
[Tue Jul 21 08:42:05.199268 2026] [security2:error] [pid 511108:tid 511356] [client 20.226.114.112:14427] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3tewAAAHY"]
[Tue Jul 21 08:42:05.226842 2026] [security2:error] [pid 511108:tid 511284] [client 20.226.114.112:14542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3tfQAAAC4"]
[Tue Jul 21 08:42:05.296855 2026] [security2:error] [pid 511108:tid 511308] [client 20.226.114.112:1977] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3tgwAAAEY"]
[Tue Jul 21 08:42:05.320331 2026] [security2:error] [pid 511108:tid 511270] [client 20.226.114.112:14450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3thQAAACA"]
[Tue Jul 21 08:42:05.330769 2026] [security2:error] [pid 511108:tid 511267] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3thgAAAB0"]
[Tue Jul 21 08:42:05.336444 2026] [security2:error] [pid 511108:tid 511278] [client 20.226.114.112:15816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3thwAAACg"]
[Tue Jul 21 08:42:05.388449 2026] [security2:error] [pid 511108:tid 511289] [client 20.226.114.112:15816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "asserradaliberdade.ong.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3tiQAAADM"]
[Tue Jul 21 08:42:05.390864 2026] [security2:error] [pid 511108:tid 511275] [client 20.63.100.92:2306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/ace2.php"] [unique_id "al9bDYTd5soprXwxAH3tigAAACU"]
[Tue Jul 21 08:42:05.559735 2026] [security2:error] [pid 511108:tid 511242] [client 5.38.115.39:6057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bDYTd5soprXwxAH3tjwAAAAQ"]
[Tue Jul 21 08:42:05.559946 2026] [security2:error] [pid 511108:tid 511242] [client 5.38.115.39:6057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bDYTd5soprXwxAH3tjwAAAAQ"]
[Tue Jul 21 08:42:05.677157 2026] [security2:error] [pid 511108:tid 511283] [client 136.67.86.240:56778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.86.67.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "contafic.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bDYTd5soprXwxAH3tkwAAAC0"]
[Tue Jul 21 08:42:05.727745 2026] [security2:error] [pid 511108:tid 511353] [client 4.204.201.85:16964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-blog.php"] [unique_id "al9bDYTd5soprXwxAH3tlAAAAHM"]
[Tue Jul 21 08:42:05.744808 2026] [security2:error] [pid 511108:tid 511363] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bDYTd5soprXwxAH3tgAAAAH0"]
[Tue Jul 21 08:42:05.891141 2026] [security2:error] [pid 511108:tid 511361] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9bDYTd5soprXwxAH3tnAAAAHs"]
[Tue Jul 21 08:42:06.061789 2026] [security2:error] [pid 511108:tid 511314] [client 203.25.124.36:36989] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/mini.php"] [unique_id "al9bDoTd5soprXwxAH3toAAAAEw"]
[Tue Jul 21 08:42:06.205232 2026] [security2:error] [pid 511108:tid 511295] [client 195.206.105.227:56194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9bDoTd5soprXwxAH3tpgAAADk"]
[Tue Jul 21 08:42:06.205319 2026] [security2:error] [pid 511108:tid 511295] [client 195.206.105.227:56194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9bDoTd5soprXwxAH3tpgAAADk"]
[Tue Jul 21 08:42:06.224772 2026] [security2:error] [pid 511108:tid 511245] [client 4.204.201.85:1489] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-includes/js/jquery/"] [unique_id "al9bDoTd5soprXwxAH3tqAAAAAc"]
[Tue Jul 21 08:42:06.230570 2026] [security2:error] [pid 511108:tid 511357] [client 20.226.60.151:34864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9bDoTd5soprXwxAH3tqQAAAHc"]
[Tue Jul 21 08:42:06.303935 2026] [security2:error] [pid 511108:tid 511180] [remote 192.241.143.148:44790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9bDoTd5soprXwxAH3trAAAO0c"]
[Tue Jul 21 08:42:06.342296 2026] [security2:error] [pid 511108:tid 511324] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9bDoTd5soprXwxAH3trwAAAFY"]
[Tue Jul 21 08:42:06.483687 2026] [security2:error] [pid 511108:tid 511238] [client 136.67.86.240:65208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "contafic.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9bDoTd5soprXwxAH3tsAAAAAA"]
[Tue Jul 21 08:42:06.809898 2026] [security2:error] [pid 511108:tid 511350] [client 20.197.192.193:43813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/wp-mt.php"] [unique_id "al9bDoTd5soprXwxAH3tvAAAAHA"]
[Tue Jul 21 08:42:06.895557 2026] [security2:error] [pid 511108:tid 511329] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9bDoTd5soprXwxAH3tvgAAAFs"]
[Tue Jul 21 08:42:07.020873 2026] [security2:error] [pid 511108:tid 511328] [client 4.204.201.85:1475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/wp-content/admin.php"] [unique_id "al9bD4Td5soprXwxAH3tvwAAAFo"]
[Tue Jul 21 08:42:07.065773 2026] [security2:error] [pid 511108:tid 511285] [client 203.25.124.50:53793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/admin/function.php"] [unique_id "al9bD4Td5soprXwxAH3twQAAAC8"]
[Tue Jul 21 08:42:07.155469 2026] [security2:error] [pid 511108:tid 511363] [client 20.220.225.223:12005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/ace2.php"] [unique_id "al9bD4Td5soprXwxAH3txQAAAH0"]
[Tue Jul 21 08:42:07.240525 2026] [security2:error] [pid 511108:tid 511263] [client 136.67.86.240:54884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "contafic.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9bD4Td5soprXwxAH3txwAAABk"]
[Tue Jul 21 08:42:07.330858 2026] [security2:error] [pid 511108:tid 511305] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9bD4Td5soprXwxAH3tzAAAAEM"]
[Tue Jul 21 08:42:07.635977 2026] [security2:error] [pid 511108:tid 511307] [client 4.204.201.85:16927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/ms-edit.php"] [unique_id "al9bD4Td5soprXwxAH3t0wAAAEU"]
[Tue Jul 21 08:42:07.803250 2026] [security2:error] [pid 511108:tid 511311] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9bD4Td5soprXwxAH3t2gAAAEk"]
[Tue Jul 21 08:42:07.803986 2026] [security2:error] [pid 511108:tid 511296] [client 41.89.234.2:51690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bD4Td5soprXwxAH3t0gAAADo"]
[Tue Jul 21 08:42:07.804134 2026] [security2:error] [pid 511108:tid 511296] [client 41.89.234.2:51690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bD4Td5soprXwxAH3t0gAAADo"]
[Tue Jul 21 08:42:07.846111 2026] [security2:error] [pid 511108:tid 511283] [client 223.181.60.88:29578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9bD4Td5soprXwxAH3t3AAAAC0"]
[Tue Jul 21 08:42:07.846256 2026] [security2:error] [pid 511108:tid 511283] [client 223.181.60.88:29578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9bD4Td5soprXwxAH3t3AAAAC0"]
[Tue Jul 21 08:42:07.849717 2026] [security2:error] [pid 511108:tid 511344] [client 195.49.128.211:56824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bD4Td5soprXwxAH3t3QAAAGo"]
[Tue Jul 21 08:42:07.849845 2026] [security2:error] [pid 511108:tid 511344] [client 195.49.128.211:56824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bD4Td5soprXwxAH3t3QAAAGo"]
[Tue Jul 21 08:42:07.900016 2026] [security2:error] [pid 511108:tid 511356] [client 20.220.225.223:12575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.gssbrasil.com.br"] [uri "/ms.php"] [unique_id "al9bD4Td5soprXwxAH3t4AAAAHY"]
[Tue Jul 21 08:42:07.962607 2026] [security2:error] [pid 511108:tid 511300] [client 136.67.86.240:50887] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "contafic.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9bD4Td5soprXwxAH3t5AAAAD4"]
[Tue Jul 21 08:42:07.970673 2026] [security2:error] [pid 511108:tid 511261] [client 203.25.124.43:54009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/config.php"] [unique_id "al9bD4Td5soprXwxAH3t5QAAABc"]
[Tue Jul 21 08:42:08.012053 2026] [security2:error] [pid 511108:tid 511282] [client 4.204.201.85:16918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.novoar.net.br"] [uri "/cgi-bin/index.php"] [unique_id "al9bEITd5soprXwxAH3t5gAAACw"]
[Tue Jul 21 08:42:08.234659 2026] [security2:error] [pid 511108:tid 511265] [client 103.59.206.240:31109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bEITd5soprXwxAH3t7AAAABs"]
[Tue Jul 21 08:42:08.234804 2026] [security2:error] [pid 511108:tid 511265] [client 103.59.206.240:31109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bEITd5soprXwxAH3t7AAAABs"]
[Tue Jul 21 08:42:08.254938 2026] [security2:error] [pid 511108:tid 511354] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9bEITd5soprXwxAH3t7QAAAHQ"]
[Tue Jul 21 08:42:08.344124 2026] [security2:error] [pid 511108:tid 511294] [client 20.63.100.92:2726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/ms.php"] [unique_id "al9bEITd5soprXwxAH3t8gAAADg"]
[Tue Jul 21 08:42:08.546316 2026] [security2:error] [pid 511108:tid 511342] [client 31.57.219.92:51708] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "nutrawidenews.com"] [uri "/"] [unique_id "al9bEITd5soprXwxAH3t9gAAAGg"]
[Tue Jul 21 08:42:08.585310 2026] [security2:error] [pid 511108:tid 511304] [client 202.179.75.202:42872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bEITd5soprXwxAH3t9wAAAEI"]
[Tue Jul 21 08:42:08.586978 2026] [security2:error] [pid 511108:tid 511304] [client 202.179.75.202:42872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bEITd5soprXwxAH3t9wAAAEI"]
[Tue Jul 21 08:42:08.596611 2026] [security2:error] [pid 511108:tid 511328] [client 20.226.60.151:58600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/jj.php"] [unique_id "al9bEITd5soprXwxAH3t-AAAAFo"]
[Tue Jul 21 08:42:08.684222 2026] [security2:error] [pid 511108:tid 511290] [client 136.67.86.240:55803] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "contafic.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9bEITd5soprXwxAH3t_QAAADQ"]
[Tue Jul 21 08:42:08.880167 2026] [security2:error] [pid 511108:tid 511118] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bEITd5soprXwxAH3uAQAALwk"]
[Tue Jul 21 08:42:08.880418 2026] [security2:error] [pid 511108:tid 511285] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bEITd5soprXwxAH3uAQAALwk"]
[Tue Jul 21 08:42:08.938532 2026] [security2:error] [pid 511108:tid 511266] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bEITd5soprXwxAH3t9QAAABw"]
[Tue Jul 21 08:42:08.968221 2026] [security2:error] [pid 511108:tid 511337] [client 212.32.76.13:58675] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/m.php"] [unique_id "al9bEITd5soprXwxAH3uBQAAAGM"]
[Tue Jul 21 08:42:09.378760 2026] [security2:error] [pid 511108:tid 511306] [client 136.67.86.240:54266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "contafic.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9bEYTd5soprXwxAH3uFAAAAEQ"]
[Tue Jul 21 08:42:09.390208 2026] [security2:error] [pid 511108:tid 511340] [client 61.1.167.83:56346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bEYTd5soprXwxAH3uFQAAAGY"]
[Tue Jul 21 08:42:09.390325 2026] [security2:error] [pid 511108:tid 511340] [client 61.1.167.83:56346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bEYTd5soprXwxAH3uFQAAAGY"]
[Tue Jul 21 08:42:09.942323 2026] [security2:error] [pid 511108:tid 511346] [client 20.197.192.193:65206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/ww.php"] [unique_id "al9bEYTd5soprXwxAH3uKwAAAGw"]
[Tue Jul 21 08:42:10.098528 2026] [security2:error] [pid 511108:tid 511246] [client 136.67.86.240:57109] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "contafic.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9bEoTd5soprXwxAH3uLwAAAAg"]
[Tue Jul 21 08:42:10.652178 2026] [security2:error] [pid 511108:tid 511334] [client 20.226.60.151:58557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9bEoTd5soprXwxAH3uPAAAAGA"]
[Tue Jul 21 08:42:10.692020 2026] [security2:error] [pid 511108:tid 511288] [client 198.44.157.34:50738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bEoTd5soprXwxAH3uPQAAADI"]
[Tue Jul 21 08:42:10.692137 2026] [security2:error] [pid 511108:tid 511288] [client 198.44.157.34:50738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bEoTd5soprXwxAH3uPQAAADI"]
[Tue Jul 21 08:42:10.803244 2026] [security2:error] [pid 511108:tid 511292] [client 136.67.86.240:64770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "contafic.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9bEoTd5soprXwxAH3uPgAAADY"]
[Tue Jul 21 08:42:10.822430 2026] [security2:error] [pid 511108:tid 511333] [client 195.49.128.211:65012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bEoTd5soprXwxAH3uPwAAAF8"]
[Tue Jul 21 08:42:10.822554 2026] [security2:error] [pid 511108:tid 511333] [client 195.49.128.211:65012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bEoTd5soprXwxAH3uPwAAAF8"]
[Tue Jul 21 08:42:10.964303 2026] [security2:error] [pid 511108:tid 511264] [client 203.25.124.61:44665] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/languages/"] [unique_id "al9bEoTd5soprXwxAH3uRwAAABo"]
[Tue Jul 21 08:42:11.523763 2026] [security2:error] [pid 511108:tid 511343] [client 152.59.181.104:65523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bE4Td5soprXwxAH3uXQAAAGk"]
[Tue Jul 21 08:42:11.528467 2026] [security2:error] [pid 511108:tid 511343] [client 152.59.181.104:65523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bE4Td5soprXwxAH3uXQAAAGk"]
[Tue Jul 21 08:42:11.563484 2026] [security2:error] [pid 511108:tid 511239] [client 136.67.86.240:63974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "contafic.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9bE4Td5soprXwxAH3uXwAAAAE"]
[Tue Jul 21 08:42:11.865190 2026] [security2:error] [pid 511108:tid 511363] [client 203.25.124.33:26809] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/about.php"] [unique_id "al9bE4Td5soprXwxAH3uZgAAAH0"]
[Tue Jul 21 08:42:12.020145 2026] [security2:error] [pid 511108:tid 511246] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bE4Td5soprXwxAH3uXgAAAAg"]
[Tue Jul 21 08:42:12.026418 2026] [security2:error] [pid 511108:tid 511163] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bFITd5soprXwxAH3uagAAazY"]
[Tue Jul 21 08:42:12.026541 2026] [security2:error] [pid 511108:tid 511345] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bFITd5soprXwxAH3uagAAazY"]
[Tue Jul 21 08:42:12.157611 2026] [security2:error] [pid 511108:tid 511360] [client 20.226.60.151:58503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/txets.php"] [unique_id "al9bFITd5soprXwxAH3ubgAAAHo"]
[Tue Jul 21 08:42:12.164376 2026] [security2:error] [pid 511108:tid 511339] [client 117.213.202.34:62974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bFITd5soprXwxAH3ubwAAAGU"]
[Tue Jul 21 08:42:12.164607 2026] [security2:error] [pid 511108:tid 511339] [client 117.213.202.34:62974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bFITd5soprXwxAH3ubwAAAGU"]
[Tue Jul 21 08:42:12.298326 2026] [security2:error] [pid 511108:tid 511257] [client 136.67.86.240:53767] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "contafic.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9bFITd5soprXwxAH3ucQAAABM"]
[Tue Jul 21 08:42:12.321552 2026] [security2:error] [pid 511108:tid 511292] [client 54.39.0.212:22776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dominiunsbrasil.com"] [uri "/robots.txt"] [unique_id "al9bFITd5soprXwxAH3ucgAAADY"]
[Tue Jul 21 08:42:12.321664 2026] [security2:error] [pid 511108:tid 511292] [client 54.39.0.212:22776] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dominiunsbrasil.com"] [uri "/robots.txt"] [unique_id "al9bFITd5soprXwxAH3ucgAAADY"]
[Tue Jul 21 08:42:12.615979 2026] [security2:error] [pid 511108:tid 511324] [client 213.152.162.15:46840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9bFITd5soprXwxAH3ufQAAAFY"]
[Tue Jul 21 08:42:12.616077 2026] [security2:error] [pid 511108:tid 511324] [client 213.152.162.15:46840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9bFITd5soprXwxAH3ufQAAAFY"]
[Tue Jul 21 08:42:12.694917 2026] [security2:error] [pid 511108:tid 511254] [client 113.22.144.139:63851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bFITd5soprXwxAH3ufgAAABA"]
[Tue Jul 21 08:42:12.695661 2026] [security2:error] [pid 511108:tid 511254] [client 113.22.144.139:63851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bFITd5soprXwxAH3ufgAAABA"]
[Tue Jul 21 08:42:12.710120 2026] [security2:error] [pid 511108:tid 511337] [client 59.95.197.55:64152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bFITd5soprXwxAH3ugAAAAGM"]
[Tue Jul 21 08:42:12.711107 2026] [security2:error] [pid 511108:tid 511337] [client 59.95.197.55:64152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bFITd5soprXwxAH3ugAAAAGM"]
[Tue Jul 21 08:42:12.986358 2026] [security2:error] [pid 511108:tid 511297] [client 136.67.86.240:63453] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "contafic.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9bFITd5soprXwxAH3uiAAAADs"]
[Tue Jul 21 08:42:13.069700 2026] [security2:error] [pid 511108:tid 511309] [client 203.25.124.55:21945] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/packed.php"] [unique_id "al9bFYTd5soprXwxAH3ujgAAAEc"]
[Tue Jul 21 08:42:13.153999 2026] [core:error] [pid 511108:tid 511170] [remote 40.77.167.24:64548] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:42:13.154018 2026] [core:error] [pid 511108:tid 511170] [remote 40.77.167.24:64548] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:42:13.678019 2026] [security2:error] [pid 511108:tid 511351] [client 136.67.86.240:50048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "contafic.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9bFYTd5soprXwxAH3uogAAAHE"]
[Tue Jul 21 08:42:13.733500 2026] [security2:error] [pid 511108:tid 511323] [client 54.39.0.121:52000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dominiunsbrasil.com"] [uri "/"] [unique_id "al9bFYTd5soprXwxAH3upAAAAFU"]
[Tue Jul 21 08:42:13.733613 2026] [security2:error] [pid 511108:tid 511323] [client 54.39.0.121:52000] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dominiunsbrasil.com"] [uri "/"] [unique_id "al9bFYTd5soprXwxAH3upAAAAFU"]
[Tue Jul 21 08:42:13.865905 2026] [security2:error] [pid 511108:tid 511274] [client 122.176.100.127:65262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bFYTd5soprXwxAH3upgAAACQ"]
[Tue Jul 21 08:42:13.866197 2026] [security2:error] [pid 511108:tid 511274] [client 122.176.100.127:65262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bFYTd5soprXwxAH3upgAAACQ"]
[Tue Jul 21 08:42:13.967898 2026] [security2:error] [pid 511108:tid 511364] [client 212.32.76.12:44443] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwentyfive/"] [unique_id "al9bFYTd5soprXwxAH3uqAAAAH4"]
[Tue Jul 21 08:42:14.182008 2026] [security2:error] [pid 511108:tid 511295] [client 20.197.192.193:65209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/cron.php"] [unique_id "al9bFoTd5soprXwxAH3utgAAADk"]
[Tue Jul 21 08:42:14.508183 2026] [security2:error] [pid 511108:tid 511254] [client 49.144.66.253:33537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bFoTd5soprXwxAH3uwAAAABA"]
[Tue Jul 21 08:42:14.508272 2026] [security2:error] [pid 511108:tid 511254] [client 49.144.66.253:33537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bFoTd5soprXwxAH3uwAAAABA"]
[Tue Jul 21 08:42:14.529003 2026] [security2:error] [pid 511108:tid 511318] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bFoTd5soprXwxAH3urwAAAFA"]
[Tue Jul 21 08:42:14.576850 2026] [security2:error] [pid 511108:tid 511153] [remote 150.95.80.135:39754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.80.95.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9bFoTd5soprXwxAH3uwgAATCw"]
[Tue Jul 21 08:42:14.810317 2026] [security2:error] [pid 511108:tid 511349] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bFoTd5soprXwxAH3uywAAbzc"]
[Tue Jul 21 08:42:15.625922 2026] [security2:error] [pid 511108:tid 511360] [client 41.89.234.2:52228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bF4Td5soprXwxAH3u5gAAAHo"]
[Tue Jul 21 08:42:15.626120 2026] [security2:error] [pid 511108:tid 511360] [client 41.89.234.2:52228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bF4Td5soprXwxAH3u5gAAAHo"]
[Tue Jul 21 08:42:16.060128 2026] [security2:error] [pid 511108:tid 511270] [client 203.25.124.31:39143] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403x.php"] [unique_id "al9bGITd5soprXwxAH3u7gAAACA"]
[Tue Jul 21 08:42:16.185437 2026] [security2:error] [pid 511108:tid 511322] [client 20.226.60.151:34820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/dex.php"] [unique_id "al9bGITd5soprXwxAH3u9QAAAFQ"]
[Tue Jul 21 08:42:16.202310 2026] [security2:error] [pid 511108:tid 511283] [client 5.38.115.39:59959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bGITd5soprXwxAH3u9gAAAC0"]
[Tue Jul 21 08:42:16.202428 2026] [security2:error] [pid 511108:tid 511283] [client 5.38.115.39:59959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bGITd5soprXwxAH3u9gAAAC0"]
[Tue Jul 21 08:42:16.335848 2026] [security2:error] [pid 511108:tid 511238] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bF4Td5soprXwxAH3u7AAAAAA"]
[Tue Jul 21 08:42:16.755036 2026] [security2:error] [pid 511108:tid 511320] [client 20.197.192.193:65208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/xxx.php"] [unique_id "al9bGITd5soprXwxAH3vAwAAAFI"]
[Tue Jul 21 08:42:16.855100 2026] [security2:error] [pid 511108:tid 511339] [client 168.167.81.163:64121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bGITd5soprXwxAH3vBQAAAGU"]
[Tue Jul 21 08:42:16.855217 2026] [security2:error] [pid 511108:tid 511339] [client 168.167.81.163:64121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bGITd5soprXwxAH3vBQAAAGU"]
[Tue Jul 21 08:42:17.166985 2026] [security2:error] [pid 511108:tid 511293] [client 203.25.124.68:57741] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/user/upgrade/"] [unique_id "al9bGYTd5soprXwxAH3vFgAAADc"]
[Tue Jul 21 08:42:17.381970 2026] [access_compat:error] [pid 511108:tid 511357] [client 162.241.63.68:31472] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:42:17.740297 2026] [security2:error] [pid 511108:tid 511228] [remote 47.128.53.140:61356] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "havoy.com.br"] [uri "/contato/"] [unique_id "al9bGYTd5soprXwxAH3vIwAAO3c"]
[Tue Jul 21 08:42:17.963305 2026] [security2:error] [pid 511108:tid 511363] [client 203.25.124.57:45953] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Text/Diff/"] [unique_id "al9bGYTd5soprXwxAH3vSwAAAH0"]
[Tue Jul 21 08:42:18.438913 2026] [security2:error] [pid 511108:tid 511301] [client 195.49.128.211:57423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bGoTd5soprXwxAH3vXQAAAD8"]
[Tue Jul 21 08:42:18.439026 2026] [security2:error] [pid 511108:tid 511301] [client 195.49.128.211:57423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bGoTd5soprXwxAH3vXQAAAD8"]
[Tue Jul 21 08:42:18.462767 2026] [security2:error] [pid 511108:tid 511362] [client 20.226.60.151:58533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xpwer1.php"] [unique_id "al9bGoTd5soprXwxAH3vXgAAAHw"]
[Tue Jul 21 08:42:18.763884 2026] [security2:error] [pid 511108:tid 511304] [client 203.25.124.51:35715] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/"] [unique_id "al9bGoTd5soprXwxAH3vdwAAAEI"]
[Tue Jul 21 08:42:18.846843 2026] [security2:error] [pid 511108:tid 511245] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bGoTd5soprXwxAH3vWAAAAAc"]
[Tue Jul 21 08:42:18.854580 2026] [security2:error] [pid 511108:tid 511321] [client 103.59.206.240:31419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bGoTd5soprXwxAH3vhgAAAFM"]
[Tue Jul 21 08:42:18.854723 2026] [security2:error] [pid 511108:tid 511321] [client 103.59.206.240:31419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bGoTd5soprXwxAH3vhgAAAFM"]
[Tue Jul 21 08:42:19.304735 2026] [security2:error] [pid 511108:tid 511293] [client 64.42.179.43:45642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9bG4Td5soprXwxAH3vlgAAADc"]
[Tue Jul 21 08:42:19.304898 2026] [security2:error] [pid 511108:tid 511293] [client 64.42.179.43:45642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9bG4Td5soprXwxAH3vlgAAADc"]
[Tue Jul 21 08:42:19.375114 2026] [security2:error] [pid 511108:tid 511271] [client 223.181.60.88:27340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9bG4Td5soprXwxAH3vlwAAACE"]
[Tue Jul 21 08:42:19.375291 2026] [security2:error] [pid 511108:tid 511271] [client 223.181.60.88:27340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9bG4Td5soprXwxAH3vlwAAACE"]
[Tue Jul 21 08:42:19.377585 2026] [security2:error] [pid 511108:tid 511200] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bG4Td5soprXwxAH3vmAAAeVs"]
[Tue Jul 21 08:42:19.377742 2026] [security2:error] [pid 511108:tid 511359] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bG4Td5soprXwxAH3vmAAAeVs"]
[Tue Jul 21 08:42:19.564671 2026] [security2:error] [pid 511108:tid 511309] [client 202.179.75.202:55272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bG4Td5soprXwxAH3vnQAAAEc"]
[Tue Jul 21 08:42:19.564860 2026] [security2:error] [pid 511108:tid 511309] [client 202.179.75.202:55272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bG4Td5soprXwxAH3vnQAAAEc"]
[Tue Jul 21 08:42:19.763126 2026] [security2:error] [pid 511108:tid 511281] [client 203.25.124.49:22155] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/we.php"] [unique_id "al9bG4Td5soprXwxAH3vogAAACs"]
[Tue Jul 21 08:42:20.150394 2026] [security2:error] [pid 511108:tid 511272] [client 173.252.95.0:58538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bHITd5soprXwxAH3wFQAAACI"]
[Tue Jul 21 08:42:20.500350 2026] [core:alert] [pid 511108:tid 511296] [client 57.141.18.2:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:42:20.789505 2026] [security2:error] [pid 511108:tid 511273] [client 65.21.113.253:36650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bHITd5soprXwxAH3wLAAAACM"]
[Tue Jul 21 08:42:21.065855 2026] [security2:error] [pid 511108:tid 511340] [client 185.198.240.4:46357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "dener.design"] [uri "/wp-login.php"] [unique_id "al9bGYTd5soprXwxAH3vDgAAAGY"]
[Tue Jul 21 08:42:21.396921 2026] [security2:error] [pid 511108:tid 511294] [client 195.49.128.211:49228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bHYTd5soprXwxAH3wQgAAADg"]
[Tue Jul 21 08:42:21.397050 2026] [security2:error] [pid 511108:tid 511294] [client 195.49.128.211:49228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bHYTd5soprXwxAH3wQgAAADg"]
[Tue Jul 21 08:42:21.465329 2026] [security2:error] [pid 511108:tid 511345] [client 203.25.124.57:34387] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/neve/assets/apps/dashboard/build/"] [unique_id "al9bHYTd5soprXwxAH3wRgAAAGs"]
[Tue Jul 21 08:42:21.545854 2026] [security2:error] [pid 511108:tid 511282] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bHYTd5soprXwxAH3wOAAAACw"]
[Tue Jul 21 08:42:21.678271 2026] [core:error] [pid 511108:tid 511186] [remote 87.236.176.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpanel.drasumaiajacob.com:8080
[Tue Jul 21 08:42:21.678289 2026] [core:error] [pid 511108:tid 511186] [remote 87.236.176.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://cpanel.drasumaiajacob.com:8080
[Tue Jul 21 08:42:21.928233 2026] [security2:error] [pid 511108:tid 511337] [client 195.206.105.227:34484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9bHYTd5soprXwxAH3wUgAAAGM"]
[Tue Jul 21 08:42:21.928333 2026] [security2:error] [pid 511108:tid 511337] [client 195.206.105.227:34484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9bHYTd5soprXwxAH3wUgAAAGM"]
[Tue Jul 21 08:42:22.329053 2026] [security2:error] [pid 511108:tid 511263] [client 152.59.181.104:49618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bHoTd5soprXwxAH3wXgAAABk"]
[Tue Jul 21 08:42:22.329205 2026] [security2:error] [pid 511108:tid 511263] [client 152.59.181.104:49618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bHoTd5soprXwxAH3wXgAAABk"]
[Tue Jul 21 08:42:22.458415 2026] [security2:error] [pid 511108:tid 511196] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bHoTd5soprXwxAH3wYwAAOVc"]
[Tue Jul 21 08:42:22.458590 2026] [security2:error] [pid 511108:tid 511295] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bHoTd5soprXwxAH3wYwAAOVc"]
[Tue Jul 21 08:42:22.671829 2026] [security2:error] [pid 511108:tid 511272] [client 212.32.76.13:65099] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/css/dist/"] [unique_id "al9bHoTd5soprXwxAH3waAAAACI"]
[Tue Jul 21 08:42:22.696989 2026] [security2:error] [pid 511108:tid 511364] [client 117.213.202.34:63588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bHoTd5soprXwxAH3waQAAAH4"]
[Tue Jul 21 08:42:22.697169 2026] [security2:error] [pid 511108:tid 511364] [client 117.213.202.34:63588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bHoTd5soprXwxAH3waQAAAH4"]
[Tue Jul 21 08:42:23.056673 2026] [security2:error] [pid 511108:tid 511257] [client 20.226.60.151:58565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/flox.php"] [unique_id "al9bH4Td5soprXwxAH3weAAAABM"]
[Tue Jul 21 08:42:23.074239 2026] [security2:error] [pid 511108:tid 511212] [remote 209.97.182.179:38628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9bH4Td5soprXwxAH3weQAAa2c"]
[Tue Jul 21 08:42:23.120683 2026] [security2:error] [pid 511108:tid 511311] [client 195.206.105.227:34488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bH4Td5soprXwxAH3wfQAAAEk"]
[Tue Jul 21 08:42:23.120794 2026] [security2:error] [pid 511108:tid 511311] [client 195.206.105.227:34488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bH4Td5soprXwxAH3wfQAAAEk"]
[Tue Jul 21 08:42:23.189905 2026] [security2:error] [pid 511108:tid 511241] [client 59.95.197.55:64619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bH4Td5soprXwxAH3wfwAAAAM"]
[Tue Jul 21 08:42:23.190030 2026] [security2:error] [pid 511108:tid 511241] [client 59.95.197.55:64619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bH4Td5soprXwxAH3wfwAAAAM"]
[Tue Jul 21 08:42:23.200223 2026] [security2:error] [pid 511108:tid 511249] [client 54.39.0.188:24056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "frsadvocacia.net"] [uri "/robots.txt"] [unique_id "al9bH4Td5soprXwxAH3wgAAAAAs"]
[Tue Jul 21 08:42:23.200311 2026] [security2:error] [pid 511108:tid 511249] [client 54.39.0.188:24056] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "frsadvocacia.net"] [uri "/robots.txt"] [unique_id "al9bH4Td5soprXwxAH3wgAAAAAs"]
[Tue Jul 21 08:42:23.294605 2026] [autoindex:error] [pid 511108:tid 511238] [client 13.219.67.125:62730] AH01276: Cannot serve directory /home2/bavosc49/perfex.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:42:23.764502 2026] [security2:error] [pid 511108:tid 511319] [client 203.25.124.72:50773] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/media-text/"] [unique_id "al9bH4Td5soprXwxAH3wlgAAAFE"]
[Tue Jul 21 08:42:23.864497 2026] [security2:error] [pid 511108:tid 511314] [client 20.197.192.193:65167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/hunter.php"] [unique_id "al9bH4Td5soprXwxAH3wmAAAAEw"]
[Tue Jul 21 08:42:24.374540 2026] [security2:error] [pid 511108:tid 511333] [client 122.176.100.127:49385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bIITd5soprXwxAH3w1AAAAF8"]
[Tue Jul 21 08:42:24.374648 2026] [security2:error] [pid 511108:tid 511333] [client 122.176.100.127:49385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bIITd5soprXwxAH3w1AAAAF8"]
[Tue Jul 21 08:42:24.401772 2026] [security2:error] [pid 511108:tid 511256] [client 173.252.95.35:54778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bIITd5soprXwxAH3w1QAAABI"]
[Tue Jul 21 08:42:24.504682 2026] [security2:error] [pid 511108:tid 511338] [client 113.22.144.139:64401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bIITd5soprXwxAH3w2gAAAGQ"]
[Tue Jul 21 08:42:24.504824 2026] [security2:error] [pid 511108:tid 511338] [client 113.22.144.139:64401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bIITd5soprXwxAH3w2gAAAGQ"]
[Tue Jul 21 08:42:24.611280 2026] [security2:error] [pid 511108:tid 511248] [client 142.44.233.72:17126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "frsadvocacia.net"] [uri "/"] [unique_id "al9bIITd5soprXwxAH3w4QAAAAo"]
[Tue Jul 21 08:42:24.611403 2026] [security2:error] [pid 511108:tid 511248] [client 142.44.233.72:17126] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "frsadvocacia.net"] [uri "/"] [unique_id "al9bIITd5soprXwxAH3w4QAAAAo"]
[Tue Jul 21 08:42:24.812858 2026] [security2:error] [pid 511108:tid 511334] [client 168.167.81.163:63262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bIITd5soprXwxAH3w6AAAAGA"]
[Tue Jul 21 08:42:24.813056 2026] [security2:error] [pid 511108:tid 511334] [client 168.167.81.163:63262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bIITd5soprXwxAH3w6AAAAGA"]
[Tue Jul 21 08:42:24.964402 2026] [security2:error] [pid 511108:tid 511343] [client 203.25.124.40:34353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "al9bIITd5soprXwxAH3w7AAAAGk"]
[Tue Jul 21 08:42:25.236892 2026] [security2:error] [pid 511108:tid 511300] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bIYTd5soprXwxAH3w9gAAPjY"]
[Tue Jul 21 08:42:25.266764 2026] [security2:error] [pid 511108:tid 511242] [client 20.197.192.193:43832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/we.php"] [unique_id "al9bIYTd5soprXwxAH3w9wAAAAQ"]
[Tue Jul 21 08:42:25.514727 2026] [security2:error] [pid 511108:tid 511245] [client 49.144.66.253:29861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bIYTd5soprXwxAH3w_gAAAAc"]
[Tue Jul 21 08:42:25.514877 2026] [security2:error] [pid 511108:tid 511245] [client 49.144.66.253:29861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bIYTd5soprXwxAH3w_gAAAAc"]
[Tue Jul 21 08:42:25.560386 2026] [security2:error] [pid 511108:tid 511295] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bIYTd5soprXwxAH3w9AAAADk"]
[Tue Jul 21 08:42:25.787147 2026] [security2:error] [pid 511108:tid 511296] [client 20.226.60.151:58618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/popo.php"] [unique_id "al9bIYTd5soprXwxAH3xBwAAADo"]
[Tue Jul 21 08:42:25.880758 2026] [security2:error] [pid 511108:tid 511309] [client 41.89.234.2:52674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bIYTd5soprXwxAH3xCgAAAEc"]
[Tue Jul 21 08:42:25.880909 2026] [security2:error] [pid 511108:tid 511309] [client 41.89.234.2:52674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bIYTd5soprXwxAH3xCgAAAEc"]
[Tue Jul 21 08:42:26.262160 2026] [security2:error] [pid 511108:tid 511351] [client 5.31.193.106:1835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bIoTd5soprXwxAH3xFwAAAHE"]
[Tue Jul 21 08:42:26.262274 2026] [security2:error] [pid 511108:tid 511351] [client 5.31.193.106:1835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bIoTd5soprXwxAH3xFwAAAHE"]
[Tue Jul 21 08:42:26.766431 2026] [security2:error] [pid 511108:tid 511244] [client 203.25.124.37:58909] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/rest-api/fields/"] [unique_id "al9bIoTd5soprXwxAH3xIgAAAAY"]
[Tue Jul 21 08:42:26.847920 2026] [security2:error] [pid 511108:tid 511348] [client 5.38.115.39:60683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bIoTd5soprXwxAH3xIwAAAG4"]
[Tue Jul 21 08:42:26.848077 2026] [security2:error] [pid 511108:tid 511348] [client 5.38.115.39:60683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bIoTd5soprXwxAH3xIwAAAG4"]
[Tue Jul 21 08:42:27.256592 2026] [security2:error] [pid 511108:tid 511311] [client 195.206.105.227:34498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9bI4Td5soprXwxAH3xNAAAAEk"]
[Tue Jul 21 08:42:27.256714 2026] [security2:error] [pid 511108:tid 511311] [client 195.206.105.227:34498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9bI4Td5soprXwxAH3xNAAAAEk"]
[Tue Jul 21 08:42:27.863791 2026] [security2:error] [pid 511108:tid 511329] [client 64.42.179.43:35088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9bI4Td5soprXwxAH3xQQAAAFs"]
[Tue Jul 21 08:42:27.863926 2026] [security2:error] [pid 511108:tid 511329] [client 64.42.179.43:35088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9bI4Td5soprXwxAH3xQQAAAFs"]
[Tue Jul 21 08:42:28.055883 2026] [security2:error] [pid 511108:tid 511293] [client 61.1.167.83:56894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bJITd5soprXwxAH3xSwAAADc"]
[Tue Jul 21 08:42:28.065254 2026] [security2:error] [pid 511108:tid 511293] [client 61.1.167.83:56894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bJITd5soprXwxAH3xSwAAADc"]
[Tue Jul 21 08:42:28.072440 2026] [security2:error] [pid 511108:tid 511315] [client 203.25.124.211:36705] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentynineteen/sass/site/"] [unique_id "al9bJITd5soprXwxAH3xTQAAAE0"]
[Tue Jul 21 08:42:28.818649 2026] [security2:error] [pid 511108:tid 511151] [remote 68.178.160.25:60288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "manosorvetes.com.br"] [uri "/wp-login.php"] [unique_id "al9bJITd5soprXwxAH3xZwAAbio"]
[Tue Jul 21 08:42:28.908751 2026] [security2:error] [pid 511108:tid 511260] [client 173.252.95.54:42534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bJITd5soprXwxAH3xaQAAABY"]
[Tue Jul 21 08:42:29.045681 2026] [security2:error] [pid 511108:tid 511311] [client 195.49.128.211:58022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bJYTd5soprXwxAH3xdgAAAEk"]
[Tue Jul 21 08:42:29.045775 2026] [security2:error] [pid 511108:tid 511311] [client 195.49.128.211:58022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bJYTd5soprXwxAH3xdgAAAEk"]
[Tue Jul 21 08:42:29.353021 2026] [security2:error] [pid 511108:tid 511286] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bJITd5soprXwxAH3xaAAAADA"]
[Tue Jul 21 08:42:29.463490 2026] [security2:error] [pid 511108:tid 511357] [client 103.59.206.240:31167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bJYTd5soprXwxAH3xigAAAHc"]
[Tue Jul 21 08:42:29.464469 2026] [security2:error] [pid 511108:tid 511357] [client 103.59.206.240:31167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bJYTd5soprXwxAH3xigAAAHc"]
[Tue Jul 21 08:42:29.662439 2026] [security2:error] [pid 511108:tid 511285] [client 203.25.124.64:37259] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/fukasawa/inc/classes/403x.php"] [unique_id "al9bJYTd5soprXwxAH3xmAAAAC8"]
[Tue Jul 21 08:42:29.745023 2026] [security2:error] [pid 511108:tid 511282] [client 69.171.230.114:41540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bJYTd5soprXwxAH3xmwAAACw"]
[Tue Jul 21 08:42:29.757064 2026] [security2:error] [pid 511108:tid 511365] [client 20.197.192.193:43803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.reidocouro.com.br"] [uri "/phpinfo.php1"] [unique_id "al9bJYTd5soprXwxAH3xnQAAAH8"]
[Tue Jul 21 08:42:29.896349 2026] [security2:error] [pid 511108:tid 511222] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bJYTd5soprXwxAH3xqAAAPXE"]
[Tue Jul 21 08:42:29.896496 2026] [security2:error] [pid 511108:tid 511299] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bJYTd5soprXwxAH3xqAAAPXE"]
[Tue Jul 21 08:42:30.418020 2026] [security2:error] [pid 511108:tid 511298] [client 202.179.75.202:50904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bJoTd5soprXwxAH3x1gAAADw"]
[Tue Jul 21 08:42:30.418195 2026] [security2:error] [pid 511108:tid 511298] [client 202.179.75.202:50904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bJoTd5soprXwxAH3x1gAAADw"]
[Tue Jul 21 08:42:30.446877 2026] [security2:error] [pid 511108:tid 511337] [client 223.181.60.88:5100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9bJoTd5soprXwxAH3x1wAAAGM"]
[Tue Jul 21 08:42:30.447111 2026] [security2:error] [pid 511108:tid 511337] [client 223.181.60.88:5100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9bJoTd5soprXwxAH3x1wAAAGM"]
[Tue Jul 21 08:42:30.765848 2026] [autoindex:error] [pid 511108:tid 511356] [client 103.59.161.72:0] AH01276: Cannot serve directory /home2/jurand34/digitaclick.com/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:42:30.978911 2026] [security2:error] [pid 511108:tid 511265] [client 212.32.76.14:62693] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/filester/assets/css/404.php"] [unique_id "al9bJoTd5soprXwxAH3x6gAAABs"]
[Tue Jul 21 08:42:31.663698 2026] [security2:error] [pid 511108:tid 511300] [client 212.32.76.5:41111] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/wp-conflg.php"] [unique_id "al9bJ4Td5soprXwxAH3yEwAAAD4"]
[Tue Jul 21 08:42:31.942806 2026] [autoindex:error] [pid 511108:tid 511302] [client 103.59.161.72:0] AH01276: Cannot serve directory /home2/jurand34/digitaclick.com/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:42:31.984298 2026] [security2:error] [pid 511108:tid 511332] [client 195.49.128.211:49835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bJ4Td5soprXwxAH3yJAAAAF4"]
[Tue Jul 21 08:42:31.984404 2026] [security2:error] [pid 511108:tid 511332] [client 195.49.128.211:49835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bJ4Td5soprXwxAH3yJAAAAF4"]
[Tue Jul 21 08:42:32.181553 2026] [security2:error] [pid 511108:tid 511250] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bJ4Td5soprXwxAH3yFgAAAAw"]
[Tue Jul 21 08:42:32.579265 2026] [security2:error] [pid 511108:tid 511340] [client 20.226.60.151:58582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/yas.php"] [unique_id "al9bKITd5soprXwxAH3yNwAAAGY"]
[Tue Jul 21 08:42:32.963556 2026] [security2:error] [pid 511108:tid 511283] [client 203.25.124.212:52301] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al9bKITd5soprXwxAH3yQgAAAC0"]
[Tue Jul 21 08:42:33.155110 2026] [security2:error] [pid 511108:tid 511220] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bKYTd5soprXwxAH3ySQAAY28"]
[Tue Jul 21 08:42:33.155392 2026] [security2:error] [pid 511108:tid 511337] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bKYTd5soprXwxAH3ySQAAY28"]
[Tue Jul 21 08:42:33.228565 2026] [security2:error] [pid 511108:tid 511249] [client 152.59.181.104:50179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bKYTd5soprXwxAH3yTAAAAAs"]
[Tue Jul 21 08:42:33.228736 2026] [security2:error] [pid 511108:tid 511249] [client 152.59.181.104:50179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bKYTd5soprXwxAH3yTAAAAAs"]
[Tue Jul 21 08:42:33.437905 2026] [security2:error] [pid 511108:tid 511269] [client 117.213.202.34:64194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bKYTd5soprXwxAH3yUAAAAB8"]
[Tue Jul 21 08:42:33.438090 2026] [security2:error] [pid 511108:tid 511269] [client 117.213.202.34:64194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bKYTd5soprXwxAH3yUAAAAB8"]
[Tue Jul 21 08:42:33.683166 2026] [security2:error] [pid 511108:tid 511281] [client 59.95.197.55:65076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bKYTd5soprXwxAH3yWgAAACs"]
[Tue Jul 21 08:42:33.683701 2026] [security2:error] [pid 511108:tid 511281] [client 59.95.197.55:65076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bKYTd5soprXwxAH3yWgAAACs"]
[Tue Jul 21 08:42:34.067190 2026] [security2:error] [pid 511108:tid 511350] [client 203.25.124.32:40303] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/maint/includes/"] [unique_id "al9bKoTd5soprXwxAH3yaAAAAHA"]
[Tue Jul 21 08:42:34.629465 2026] [security2:error] [pid 511108:tid 511359] [client 20.226.60.151:58508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/file61.php"] [unique_id "al9bKoTd5soprXwxAH3ydgAAAHk"]
[Tue Jul 21 08:42:34.641175 2026] [security2:error] [pid 511108:tid 511301] [client 113.22.144.139:64865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bKoTd5soprXwxAH3yeAAAAD8"]
[Tue Jul 21 08:42:34.641308 2026] [security2:error] [pid 511108:tid 511301] [client 113.22.144.139:64865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bKoTd5soprXwxAH3yeAAAAD8"]
[Tue Jul 21 08:42:34.804048 2026] [security2:error] [pid 511108:tid 511264] [client 122.176.100.127:49907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bKoTd5soprXwxAH3ygQAAABo"]
[Tue Jul 21 08:42:34.804355 2026] [security2:error] [pid 511108:tid 511264] [client 122.176.100.127:49907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bKoTd5soprXwxAH3ygQAAABo"]
[Tue Jul 21 08:42:34.820166 2026] [security2:error] [pid 511108:tid 511354] [client 103.59.161.72:56518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.161.59.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "digitaclick.com"] [uri "/wp-login.php"] [unique_id "al9bKYTd5soprXwxAH3yWQAAAHQ"]
[Tue Jul 21 08:42:35.274443 2026] [security2:error] [pid 511108:tid 511267] [client 212.32.76.12:64515] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/comment-date/"] [unique_id "al9bK4Td5soprXwxAH3ylAAAAB0"]
[Tue Jul 21 08:42:35.301598 2026] [security2:error] [pid 511108:tid 511299] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bK4Td5soprXwxAH3yjgAAPUU"]
[Tue Jul 21 08:42:35.319164 2026] [security2:error] [pid 511108:tid 511290] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bKoTd5soprXwxAH3yggAAADQ"]
[Tue Jul 21 08:42:35.352314 2026] [security2:error] [pid 511108:tid 511240] [client 41.89.234.2:53147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bK4Td5soprXwxAH3ylgAAAAI"]
[Tue Jul 21 08:42:35.352444 2026] [security2:error] [pid 511108:tid 511240] [client 41.89.234.2:53147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bK4Td5soprXwxAH3ylgAAAAI"]
[Tue Jul 21 08:42:35.484673 2026] [security2:error] [pid 511108:tid 511308] [client 168.167.81.163:59961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bK4Td5soprXwxAH3ymgAAAEY"]
[Tue Jul 21 08:42:35.484871 2026] [security2:error] [pid 511108:tid 511308] [client 168.167.81.163:59961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bK4Td5soprXwxAH3ymgAAAEY"]
[Tue Jul 21 08:42:35.877776 2026] [security2:error] [pid 511108:tid 511316] [client 20.226.60.151:34827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/water.php"] [unique_id "al9bK4Td5soprXwxAH3ypwAAAE4"]
[Tue Jul 21 08:42:35.961607 2026] [security2:error] [pid 511108:tid 511241] [client 203.25.124.211:64149] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "al9bK4Td5soprXwxAH3yrgAAAAM"]
[Tue Jul 21 08:42:36.481155 2026] [security2:error] [pid 511108:tid 511302] [client 49.144.66.253:30362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bLITd5soprXwxAH3yvQAAAEA"]
[Tue Jul 21 08:42:36.481311 2026] [security2:error] [pid 511108:tid 511302] [client 49.144.66.253:30362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bLITd5soprXwxAH3yvQAAAEA"]
[Tue Jul 21 08:42:36.597669 2026] [security2:error] [pid 511108:tid 511342] [client 47.128.118.139:62024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "siteecommerceshop.com"] [uri "/robots.txt"] [unique_id "al9bLITd5soprXwxAH3ywAAAAGg"]
[Tue Jul 21 08:42:36.684108 2026] [security2:error] [pid 511108:tid 511157] [remote 97.74.87.194:56624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9bLITd5soprXwxAH3yxgAAUjA"]
[Tue Jul 21 08:42:36.727051 2026] [security2:error] [pid 511108:tid 511239] [client 20.226.60.151:58548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/nano.php"] [unique_id "al9bLITd5soprXwxAH3yywAAAAE"]
[Tue Jul 21 08:42:36.971583 2026] [security2:error] [pid 511108:tid 511268] [client 203.25.124.74:26853] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/widgets/chosen.php"] [unique_id "al9bLITd5soprXwxAH3zFwAAAB4"]
[Tue Jul 21 08:42:37.437187 2026] [security2:error] [pid 511108:tid 511327] [client 5.38.115.39:32897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bLYTd5soprXwxAH3zSwAAAFk"]
[Tue Jul 21 08:42:37.437297 2026] [security2:error] [pid 511108:tid 511327] [client 5.38.115.39:32897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bLYTd5soprXwxAH3zSwAAAFk"]
[Tue Jul 21 08:42:37.970542 2026] [security2:error] [pid 511108:tid 511277] [client 212.32.76.5:21875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/theme-check/main.php"] [unique_id "al9bLYTd5soprXwxAH3zZQAAACc"]
[Tue Jul 21 08:42:38.096475 2026] [security2:error] [pid 511108:tid 511364] [client 20.226.60.151:58540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/moon.php"] [unique_id "al9bLoTd5soprXwxAH3zbQAAAH4"]
[Tue Jul 21 08:42:38.160163 2026] [security2:error] [pid 511108:tid 511175] [remote 89.216.62.195:44386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.62.216.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "digitaclick.com"] [uri "/wp-login.php"] [unique_id "al9bLITd5soprXwxAH3yuAAAUUI"]
[Tue Jul 21 08:42:38.362301 2026] [security2:error] [pid 511108:tid 511293] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bLYTd5soprXwxAH3zXgAAADc"]
[Tue Jul 21 08:42:39.016435 2026] [security2:error] [pid 511108:tid 511143] [remote 87.106.217.70:59064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.217.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9bLoTd5soprXwxAH3zZgAATSI"]
[Tue Jul 21 08:42:39.063482 2026] [security2:error] [pid 511108:tid 511271] [client 203.25.124.73:21249] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/css.php"] [unique_id "al9bL4Td5soprXwxAH3zjQAAACE"]
[Tue Jul 21 08:42:39.738427 2026] [security2:error] [pid 511108:tid 511243] [client 195.49.128.211:58627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bL4Td5soprXwxAH3zpQAAAAU"]
[Tue Jul 21 08:42:39.738636 2026] [security2:error] [pid 511108:tid 511243] [client 195.49.128.211:58627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bL4Td5soprXwxAH3zpQAAAAU"]
[Tue Jul 21 08:42:40.065550 2026] [security2:error] [pid 511108:tid 511362] [client 103.59.206.240:31447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bMITd5soprXwxAH3zrwAAAHw"]
[Tue Jul 21 08:42:40.066143 2026] [security2:error] [pid 511108:tid 511362] [client 103.59.206.240:31447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bMITd5soprXwxAH3zrwAAAHw"]
[Tue Jul 21 08:42:40.098462 2026] [core:error] [pid 511108:tid 511114] [remote 74.7.244.32:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:42:40.098485 2026] [core:error] [pid 511108:tid 511114] [remote 74.7.244.32:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:42:40.098652 2026] [security2:error] [pid 511108:tid 511250] [client 74.7.244.32:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcontacts.vidrosprovetro.com.br"] [uri "/___proxy_subdomain_cpcontacts/index.php"] [unique_id "al9bMITd5soprXwxAH3zsAAADAU"]
[Tue Jul 21 08:42:40.358851 2026] [security2:error] [pid 511108:tid 511344] [client 212.32.76.4:42245] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/admin.php"] [unique_id "al9bMITd5soprXwxAH3zugAAAGo"]
[Tue Jul 21 08:42:40.415559 2026] [security2:error] [pid 511108:tid 511235] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bMITd5soprXwxAH3zwAAAZn4"]
[Tue Jul 21 08:42:40.415711 2026] [security2:error] [pid 511108:tid 511340] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bMITd5soprXwxAH3zwAAAZn4"]
[Tue Jul 21 08:42:40.586002 2026] [security2:error] [pid 511108:tid 511151] [remote 173.252.87.15:51106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9bMITd5soprXwxAH3zwwAAVyo"]
[Tue Jul 21 08:42:41.249799 2026] [security2:error] [pid 511108:tid 511365] [client 202.179.75.202:36946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bMYTd5soprXwxAH3z0gAAAH8"]
[Tue Jul 21 08:42:41.249938 2026] [security2:error] [pid 511108:tid 511365] [client 202.179.75.202:36946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bMYTd5soprXwxAH3z0gAAAH8"]
[Tue Jul 21 08:42:41.261822 2026] [security2:error] [pid 511108:tid 511326] [client 223.181.60.88:27175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9bMYTd5soprXwxAH3z0wAAAFg"]
[Tue Jul 21 08:42:41.261920 2026] [security2:error] [pid 511108:tid 511326] [client 223.181.60.88:27175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9bMYTd5soprXwxAH3z0wAAAFg"]
[Tue Jul 21 08:42:41.332278 2026] [security2:error] [pid 511108:tid 511332] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bMITd5soprXwxAH3zzAAAAF4"]
[Tue Jul 21 08:42:41.771852 2026] [security2:error] [pid 511108:tid 511271] [client 203.25.124.42:24779] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/2025/"] [unique_id "al9bMYTd5soprXwxAH3z7QAAACE"]
[Tue Jul 21 08:42:41.849518 2026] [security2:error] [pid 511108:tid 511313] [client 213.152.162.15:45894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9bMYTd5soprXwxAH3z8QAAAEs"]
[Tue Jul 21 08:42:41.849613 2026] [security2:error] [pid 511108:tid 511313] [client 213.152.162.15:45894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9bMYTd5soprXwxAH3z8QAAAEs"]
[Tue Jul 21 08:42:42.013548 2026] [security2:error] [pid 511108:tid 511252] [client 185.251.19.64:47647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9bMoTd5soprXwxAH3z-wAAAA4"]
[Tue Jul 21 08:42:42.015749 2026] [security2:error] [pid 511108:tid 511354] [client 45.132.227.200:33853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9bMoTd5soprXwxAH3z-gAAAHQ"]
[Tue Jul 21 08:42:42.565518 2026] [security2:error] [pid 511108:tid 511264] [client 195.49.128.211:50440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bMoTd5soprXwxAH30DgAAABo"]
[Tue Jul 21 08:42:42.565629 2026] [security2:error] [pid 511108:tid 511264] [client 195.49.128.211:50440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bMoTd5soprXwxAH30DgAAABo"]
[Tue Jul 21 08:42:42.600786 2026] [security2:error] [pid 511108:tid 511347] [client 20.226.60.151:58517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-info.php"] [unique_id "al9bMoTd5soprXwxAH30DwAAAG0"]
[Tue Jul 21 08:42:42.725441 2026] [security2:error] [pid 511108:tid 511246] [client 15.235.27.78:24658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "balaodevoo.com.br"] [uri "/robots.txt"] [unique_id "al9bMoTd5soprXwxAH30EwAAAAg"]
[Tue Jul 21 08:42:42.725563 2026] [security2:error] [pid 511108:tid 511246] [client 15.235.27.78:24658] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "balaodevoo.com.br"] [uri "/robots.txt"] [unique_id "al9bMoTd5soprXwxAH30EwAAAAg"]
[Tue Jul 21 08:42:42.839788 2026] [security2:error] [pid 511108:tid 511241] [client 173.252.95.36:60678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bMoTd5soprXwxAH30FgAAAAM"]
[Tue Jul 21 08:42:42.864254 2026] [security2:error] [pid 511108:tid 511290] [client 203.25.124.41:45987] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/comment-content/"] [unique_id "al9bMoTd5soprXwxAH30GAAAADQ"]
[Tue Jul 21 08:42:43.848854 2026] [security2:error] [pid 511108:tid 511305] [client 152.59.181.104:50660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bM4Td5soprXwxAH30ZwAAAEM"]
[Tue Jul 21 08:42:43.848957 2026] [security2:error] [pid 511108:tid 511305] [client 152.59.181.104:50660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bM4Td5soprXwxAH30ZwAAAEM"]
[Tue Jul 21 08:42:43.911006 2026] [security2:error] [pid 511108:tid 511302] [client 173.252.95.42:35928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bM4Td5soprXwxAH30bAAAAEA"]
[Tue Jul 21 08:42:43.918627 2026] [security2:error] [pid 511108:tid 511360] [client 203.25.124.187:58069] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/"] [unique_id "al9bM4Td5soprXwxAH30bQAAAHo"]
[Tue Jul 21 08:42:43.939211 2026] [security2:error] [pid 511108:tid 511118] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bM4Td5soprXwxAH30bwAACAk"]
[Tue Jul 21 08:42:43.939431 2026] [security2:error] [pid 511108:tid 511246] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bM4Td5soprXwxAH30bwAACAk"]
[Tue Jul 21 08:42:44.093840 2026] [security2:error] [pid 511108:tid 511270] [client 117.213.202.34:64799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bNITd5soprXwxAH30cgAAACA"]
[Tue Jul 21 08:42:44.093990 2026] [security2:error] [pid 511108:tid 511270] [client 117.213.202.34:64799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bNITd5soprXwxAH30cgAAACA"]
[Tue Jul 21 08:42:44.131833 2026] [security2:error] [pid 511108:tid 511289] [client 54.39.89.134:49586] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "balaodevoo.com.br"] [uri "/"] [unique_id "al9bNITd5soprXwxAH30dwAAADM"]
[Tue Jul 21 08:42:44.131947 2026] [security2:error] [pid 511108:tid 511289] [client 54.39.89.134:49586] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "balaodevoo.com.br"] [uri "/"] [unique_id "al9bNITd5soprXwxAH30dwAAADM"]
[Tue Jul 21 08:42:44.164836 2026] [security2:error] [pid 511108:tid 511266] [client 203.25.124.32:57019] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/images/"] [unique_id "al9bNITd5soprXwxAH30eAAAABw"]
[Tue Jul 21 08:42:44.181195 2026] [security2:error] [pid 511108:tid 511342] [client 59.95.197.55:49156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bNITd5soprXwxAH30gwAAAGg"]
[Tue Jul 21 08:42:44.181772 2026] [security2:error] [pid 511108:tid 511342] [client 59.95.197.55:49156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bNITd5soprXwxAH30gwAAAGg"]
[Tue Jul 21 08:42:44.688940 2026] [security2:error] [pid 511108:tid 511301] [client 212.32.76.54:33751] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/core.php"] [unique_id "al9bNITd5soprXwxAH30rQAAAD8"]
[Tue Jul 21 08:42:44.767003 2026] [security2:error] [pid 511108:tid 511241] [client 61.1.167.83:57364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bNITd5soprXwxAH30sAAAAAM"]
[Tue Jul 21 08:42:44.767163 2026] [security2:error] [pid 511108:tid 511241] [client 61.1.167.83:57364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bNITd5soprXwxAH30sAAAAAM"]
[Tue Jul 21 08:42:44.935469 2026] [autoindex:error] [pid 511108:tid 511255] [client 186.202.163.107:0] AH01276: Cannot serve directory /home2/senatr95/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:42:45.258231 2026] [security2:error] [pid 511108:tid 511362] [client 122.176.100.127:50409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bNYTd5soprXwxAH30vQAAAHw"]
[Tue Jul 21 08:42:45.258342 2026] [security2:error] [pid 511108:tid 511362] [client 122.176.100.127:50409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bNYTd5soprXwxAH30vQAAAHw"]
[Tue Jul 21 08:42:45.568719 2026] [security2:error] [pid 511108:tid 511340] [client 212.32.76.4:48359] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/options.php"] [unique_id "al9bNYTd5soprXwxAH30wwAAAGY"]
[Tue Jul 21 08:42:45.649688 2026] [security2:error] [pid 511108:tid 511224] [remote 45.150.79.142:37426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9bNYTd5soprXwxAH30xQAAJ3M"]
[Tue Jul 21 08:42:45.758430 2026] [security2:error] [pid 511108:tid 511291] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9bNYTd5soprXwxAH30ygAAADU"]
[Tue Jul 21 08:42:45.786748 2026] [security2:error] [pid 511108:tid 511343] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bNYTd5soprXwxAH30vgAAAGk"]
[Tue Jul 21 08:42:45.935568 2026] [security2:error] [pid 511108:tid 511349] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bNYTd5soprXwxAH30zgAAb2Y"]
[Tue Jul 21 08:42:45.967426 2026] [security2:error] [pid 511108:tid 511281] [client 203.25.124.193:46389] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "al9bNYTd5soprXwxAH300QAAACs"]
[Tue Jul 21 08:42:46.012433 2026] [security2:error] [pid 511108:tid 511301] [client 114.119.132.58:42909] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "zooparquevet.com.br"] [uri "/portfolio-posts/sala-de-recepcao-de-clientes-5/"] [unique_id "al9bNoTd5soprXwxAH301QAAAD8"], referer: http://zooparquevet.com.br/portfolio-posts/sala-de-recepcao-de-clientes-4
[Tue Jul 21 08:42:46.039559 2026] [security2:error] [pid 511108:tid 511290] [client 34.38.193.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.193.38.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bNoTd5soprXwxAH301wAAADQ"]
[Tue Jul 21 08:42:46.073522 2026] [security2:error] [pid 511108:tid 511239] [client 41.89.234.2:53567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bNoTd5soprXwxAH302AAAAAE"]
[Tue Jul 21 08:42:46.073674 2026] [security2:error] [pid 511108:tid 511239] [client 41.89.234.2:53567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bNoTd5soprXwxAH302AAAAAE"]
[Tue Jul 21 08:42:46.129535 2026] [security2:error] [pid 511108:tid 511242] [client 113.22.144.139:65419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bNoTd5soprXwxAH302QAAAAQ"]
[Tue Jul 21 08:42:46.130213 2026] [security2:error] [pid 511108:tid 511242] [client 113.22.144.139:65419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bNoTd5soprXwxAH302QAAAAQ"]
[Tue Jul 21 08:42:46.338830 2026] [security2:error] [pid 511108:tid 511345] [client 173.252.95.33:55490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bNoTd5soprXwxAH305AAAAGs"]
[Tue Jul 21 08:42:46.468045 2026] [security2:error] [pid 511108:tid 511354] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9bNoTd5soprXwxAH305wAAAHQ"]
[Tue Jul 21 08:42:46.745721 2026] [security2:error] [pid 511108:tid 511365] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9bNoTd5soprXwxAH308QAAAH8"]
[Tue Jul 21 08:42:47.029356 2026] [security2:error] [pid 511108:tid 511282] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9bN4Td5soprXwxAH30-wAAACw"]
[Tue Jul 21 08:42:47.230016 2026] [security2:error] [pid 511108:tid 511287] [client 168.167.81.163:60622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bN4Td5soprXwxAH31AgAAADE"]
[Tue Jul 21 08:42:47.230162 2026] [security2:error] [pid 511108:tid 511287] [client 168.167.81.163:60622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bN4Td5soprXwxAH31AgAAADE"]
[Tue Jul 21 08:42:47.306749 2026] [security2:error] [pid 511108:tid 511346] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9bN4Td5soprXwxAH31BwAAAGw"]
[Tue Jul 21 08:42:47.374646 2026] [security2:error] [pid 511108:tid 511241] [client 203.25.124.254:29319] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/admin.php"] [unique_id "al9bN4Td5soprXwxAH31CAAAAAM"]
[Tue Jul 21 08:42:47.386819 2026] [autoindex:error] [pid 511108:tid 511305] [client 43.131.253.14:37620] AH01276: Cannot serve directory /home2/lylowc82/conquisteemcasa.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:42:47.564719 2026] [security2:error] [pid 511108:tid 511248] [client 203.25.124.213:38935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/chosen.php"] [unique_id "al9bN4Td5soprXwxAH31HwAAAAo"]
[Tue Jul 21 08:42:47.583952 2026] [security2:error] [pid 511108:tid 511329] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9bN4Td5soprXwxAH31IgAAAFs"]
[Tue Jul 21 08:42:47.659327 2026] [security2:error] [pid 511108:tid 511269] [client 141.11.107.74:52409] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcalendars.domuscondominios.com.br"] [uri "/___proxy_subdomain_cpcalendars/"] [unique_id "al9bN4Td5soprXwxAH31JAAAAB8"]
[Tue Jul 21 08:42:47.684507 2026] [security2:error] [pid 511108:tid 511342] [client 141.11.107.74:52415] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ftp.domuscondominios.com.br"] [uri "/"] [unique_id "al9bN4Td5soprXwxAH31JgAAAGg"]
[Tue Jul 21 08:42:47.685618 2026] [security2:error] [pid 511108:tid 511253] [client 141.11.107.74:52417] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpcontacts.domuscondominios.com.br"] [uri "/___proxy_subdomain_cpcontacts/"] [unique_id "al9bN4Td5soprXwxAH31JwAAAA8"]
[Tue Jul 21 08:42:47.689389 2026] [security2:error] [pid 511108:tid 511320] [client 141.11.107.74:52432] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "cpanel.domuscondominios.com.br"] [uri "/___proxy_subdomain_cpanel/"] [unique_id "al9bN4Td5soprXwxAH31KAAAAFI"]
[Tue Jul 21 08:42:47.710989 2026] [security2:error] [pid 511108:tid 511271] [client 141.11.107.74:52436] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "domuscondominios.com.br"] [uri "/"] [unique_id "al9bN4Td5soprXwxAH31KQAAACE"]
[Tue Jul 21 08:42:47.711082 2026] [security2:error] [pid 511108:tid 511356] [client 141.11.107.74:52438] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.domuscondominios.com.br"] [uri "/___proxy_subdomain_webdisk/"] [unique_id "al9bN4Td5soprXwxAH31KgAAAHY"]
[Tue Jul 21 08:42:47.712867 2026] [security2:error] [pid 511108:tid 511351] [client 141.11.107.74:52457] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.domuscondominios.com.br"] [uri "/"] [unique_id "al9bN4Td5soprXwxAH31KwAAAHE"]
[Tue Jul 21 08:42:47.753643 2026] [security2:error] [pid 511108:tid 511244] [client 5.31.193.106:58722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bN4Td5soprXwxAH31LAAAAAY"]
[Tue Jul 21 08:42:47.753751 2026] [security2:error] [pid 511108:tid 511244] [client 5.31.193.106:58722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bN4Td5soprXwxAH31LAAAAAY"]
[Tue Jul 21 08:42:47.755855 2026] [security2:error] [pid 511108:tid 511260] [client 141.11.107.74:52476] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.domuscondominios.com.br"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al9bN4Td5soprXwxAH31LQAAABY"]
[Tue Jul 21 08:42:47.852355 2026] [security2:error] [pid 511108:tid 511263] [client 141.11.107.74:52560] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "autodiscover.domuscondominios.com.br"] [uri "/"] [unique_id "al9bN4Td5soprXwxAH31MwAAABk"]
[Tue Jul 21 08:42:47.859745 2026] [security2:error] [pid 511108:tid 511319] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9bN4Td5soprXwxAH31NAAAAFE"]
[Tue Jul 21 08:42:48.120334 2026] [security2:error] [pid 511108:tid 511242] [client 5.38.115.39:61972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bOITd5soprXwxAH31OAAAAAQ"]
[Tue Jul 21 08:42:48.120451 2026] [security2:error] [pid 511108:tid 511242] [client 5.38.115.39:61972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bOITd5soprXwxAH31OAAAAAQ"]
[Tue Jul 21 08:42:48.137532 2026] [security2:error] [pid 511108:tid 511282] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9bOITd5soprXwxAH31PAAAACw"]
[Tue Jul 21 08:42:48.180808 2026] [security2:error] [pid 511108:tid 511340] [client 49.144.66.253:30803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bOITd5soprXwxAH31QQAAAGY"]
[Tue Jul 21 08:42:48.180906 2026] [security2:error] [pid 511108:tid 511340] [client 49.144.66.253:30803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bOITd5soprXwxAH31QQAAAGY"]
[Tue Jul 21 08:42:48.299410 2026] [autoindex:error] [pid 511108:tid 511304] [client 24.199.118.1:0] AH01276: Cannot serve directory /home1/hiuryd21/hiurydossantosperoni1782932116000.0721679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:42:48.405135 2026] [security2:error] [pid 511108:tid 511239] [client 20.226.60.151:58623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/2000.php"] [unique_id "al9bOITd5soprXwxAH31UAAAAAE"]
[Tue Jul 21 08:42:48.426113 2026] [security2:error] [pid 511108:tid 511356] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9bOITd5soprXwxAH31jAAAAHY"]
[Tue Jul 21 08:42:48.477920 2026] [security2:error] [pid 511108:tid 511261] [client 203.25.124.187:37087] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/goods.php"] [unique_id "al9bOITd5soprXwxAH31rgAAABc"]
[Tue Jul 21 08:42:48.701896 2026] [security2:error] [pid 511108:tid 511310] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9bOITd5soprXwxAH31uAAAAEg"]
[Tue Jul 21 08:42:48.982914 2026] [security2:error] [pid 511108:tid 511297] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9bOITd5soprXwxAH31vwAAADs"]
[Tue Jul 21 08:42:49.260808 2026] [security2:error] [pid 511108:tid 511241] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9bOYTd5soprXwxAH31xwAAAAM"]
[Tue Jul 21 08:42:49.537222 2026] [security2:error] [pid 511108:tid 511315] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9bOYTd5soprXwxAH32XwAAAE0"]
[Tue Jul 21 08:42:49.564423 2026] [security2:error] [pid 511108:tid 511301] [client 212.32.76.13:33639] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/images/as.php"] [unique_id "al9bOYTd5soprXwxAH32YAAAAD8"]
[Tue Jul 21 08:42:49.608776 2026] [security2:error] [pid 511108:tid 511242] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bOYTd5soprXwxAH31wgAAAAQ"]
[Tue Jul 21 08:42:49.774552 2026] [security2:error] [pid 511108:tid 511268] [client 203.25.124.9:41469] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/edit-tags.php"] [unique_id "al9bOYTd5soprXwxAH32ZgAAAB4"]
[Tue Jul 21 08:42:49.813508 2026] [security2:error] [pid 511108:tid 511329] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9bOYTd5soprXwxAH32ZwAAAFs"]
[Tue Jul 21 08:42:50.090783 2026] [security2:error] [pid 511108:tid 511339] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9bOoTd5soprXwxAH32cAAAAGU"]
[Tue Jul 21 08:42:50.304596 2026] [security2:error] [pid 511108:tid 511318] [client 195.49.128.211:59239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bOoTd5soprXwxAH32eAAAAFA"]
[Tue Jul 21 08:42:50.304737 2026] [security2:error] [pid 511108:tid 511318] [client 195.49.128.211:59239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bOoTd5soprXwxAH32eAAAAFA"]
[Tue Jul 21 08:42:50.367048 2026] [security2:error] [pid 511108:tid 511273] [client 34.38.193.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "willianricardodaliuz1751037106901.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9bOoTd5soprXwxAH32ewAAACM"]
[Tue Jul 21 08:42:50.441194 2026] [security2:error] [pid 511108:tid 511288] [client 20.226.60.151:58609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/122.php"] [unique_id "al9bOoTd5soprXwxAH32gAAAADI"]
[Tue Jul 21 08:42:50.738120 2026] [security2:error] [pid 511108:tid 511355] [client 103.59.206.240:31201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bOoTd5soprXwxAH32gQAAAHU"]
[Tue Jul 21 08:42:50.738269 2026] [security2:error] [pid 511108:tid 511355] [client 103.59.206.240:31201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bOoTd5soprXwxAH32gQAAAHU"]
[Tue Jul 21 08:42:50.941583 2026] [security2:error] [pid 511108:tid 511182] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bOoTd5soprXwxAH32iQAAXEk"]
[Tue Jul 21 08:42:50.941771 2026] [security2:error] [pid 511108:tid 511330] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bOoTd5soprXwxAH32iQAAXEk"]
[Tue Jul 21 08:42:50.970715 2026] [security2:error] [pid 511108:tid 511240] [client 203.25.124.210:30781] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/filemanager.php"] [unique_id "al9bOoTd5soprXwxAH32jwAAAAI"]
[Tue Jul 21 08:42:51.117447 2026] [security2:error] [pid 511108:tid 511193] [remote 65.111.28.104:40979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9bOoTd5soprXwxAH32jQAAVVQ"]
[Tue Jul 21 08:42:51.267194 2026] [security2:error] [pid 511108:tid 511261] [client 203.25.124.35:59589] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-security.php"] [unique_id "al9bO4Td5soprXwxAH32lQAAABc"]
[Tue Jul 21 08:42:52.172213 2026] [security2:error] [pid 511108:tid 511242] [client 202.179.75.202:33554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bPITd5soprXwxAH32rQAAAAQ"]
[Tue Jul 21 08:42:52.172339 2026] [security2:error] [pid 511108:tid 511242] [client 202.179.75.202:33554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bPITd5soprXwxAH32rQAAAAQ"]
[Tue Jul 21 08:42:52.260709 2026] [security2:error] [pid 511108:tid 511340] [client 212.32.76.10:65353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/system.php"] [unique_id "al9bPITd5soprXwxAH32sAAAAGY"]
[Tue Jul 21 08:42:52.712387 2026] [security2:error] [pid 511108:tid 511257] [client 223.181.60.88:3441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.60.181.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9bPITd5soprXwxAH32vQAAABM"]
[Tue Jul 21 08:42:52.712637 2026] [security2:error] [pid 511108:tid 511257] [client 223.181.60.88:3441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "hypehutdeals.com"] [uri "/xmlrpc.php"] [unique_id "al9bPITd5soprXwxAH32vQAAABM"]
[Tue Jul 21 08:42:52.918947 2026] [security2:error] [pid 511108:tid 511321] [client 198.44.157.34:42422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9bPITd5soprXwxAH32wgAAAFM"]
[Tue Jul 21 08:42:52.919107 2026] [security2:error] [pid 511108:tid 511321] [client 198.44.157.34:42422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9bPITd5soprXwxAH32wgAAAFM"]
[Tue Jul 21 08:42:53.008305 2026] [security2:error] [pid 511108:tid 511140] [remote 185.8.106.219:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fidellium.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9bPYTd5soprXwxAH329AAAPh8"]
[Tue Jul 21 08:42:53.145486 2026] [security2:error] [pid 511108:tid 511361] [client 195.49.128.211:51043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bPYTd5soprXwxAH32_wAAAHs"]
[Tue Jul 21 08:42:53.145604 2026] [security2:error] [pid 511108:tid 511361] [client 195.49.128.211:51043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bPYTd5soprXwxAH32_wAAAHs"]
[Tue Jul 21 08:42:53.314067 2026] [security2:error] [pid 511108:tid 511336] [client 20.226.60.151:58523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/mds.php"] [unique_id "al9bPYTd5soprXwxAH33BgAAAGI"]
[Tue Jul 21 08:42:53.563183 2026] [security2:error] [pid 511108:tid 511269] [client 203.25.124.36:20241] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/header.php"] [unique_id "al9bPYTd5soprXwxAH33EgAAAB8"]
[Tue Jul 21 08:42:53.606907 2026] [security2:error] [pid 511108:tid 511266] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bPYTd5soprXwxAH32-wAAABw"]
[Tue Jul 21 08:42:53.662114 2026] [security2:error] [pid 511108:tid 511115] [remote 185.8.106.219:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fidellium.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9bPYTd5soprXwxAH33FwAAIAY"], referer: http://fidellium.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Tue Jul 21 08:42:53.850441 2026] [security2:error] [pid 511108:tid 511329] [client 20.206.105.145:55688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9bPYTd5soprXwxAH33HAAAAFs"]
[Tue Jul 21 08:42:53.868383 2026] [security2:error] [pid 511108:tid 511365] [client 203.25.124.185:32105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/"] [unique_id "al9bPYTd5soprXwxAH33HQAAAH8"]
[Tue Jul 21 08:42:54.152513 2026] [security2:error] [pid 511108:tid 511303] [client 74.7.175.192:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "radarsulista.com.br"] [uri "/index.php"] [unique_id "al9bO4Td5soprXwxAH32kQAAQQo"]
[Tue Jul 21 08:42:54.178934 2026] [security2:error] [pid 511108:tid 511110] [remote 185.8.106.219:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.fidellium.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9bPoTd5soprXwxAH33KwAACwE"]
[Tue Jul 21 08:42:54.372973 2026] [security2:error] [pid 511108:tid 511127] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bPoTd5soprXwxAH33NQAAbBI"]
[Tue Jul 21 08:42:54.373181 2026] [security2:error] [pid 511108:tid 511346] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bPoTd5soprXwxAH33NQAAbBI"]
[Tue Jul 21 08:42:54.582756 2026] [security2:error] [pid 511108:tid 511323] [client 152.59.181.104:51139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bPoTd5soprXwxAH33OwAAAFU"]
[Tue Jul 21 08:42:54.582905 2026] [security2:error] [pid 511108:tid 511323] [client 152.59.181.104:51139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bPoTd5soprXwxAH33OwAAAFU"]
[Tue Jul 21 08:42:54.621081 2026] [security2:error] [pid 511108:tid 511253] [client 20.206.105.145:55695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9bPoTd5soprXwxAH33PgAAAA8"]
[Tue Jul 21 08:42:54.645567 2026] [security2:error] [pid 511108:tid 511241] [client 117.213.202.34:65408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bPoTd5soprXwxAH33PwAAAAM"]
[Tue Jul 21 08:42:54.645710 2026] [security2:error] [pid 511108:tid 511241] [client 117.213.202.34:65408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bPoTd5soprXwxAH33PwAAAAM"]
[Tue Jul 21 08:42:54.672491 2026] [security2:error] [pid 511108:tid 511333] [client 203.25.124.47:22135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/fonts/"] [unique_id "al9bPoTd5soprXwxAH33QQAAAF8"]
[Tue Jul 21 08:42:54.751882 2026] [security2:error] [pid 511108:tid 511349] [client 59.95.197.55:49630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bPoTd5soprXwxAH33RQAAAG8"]
[Tue Jul 21 08:42:54.752008 2026] [security2:error] [pid 511108:tid 511349] [client 59.95.197.55:49630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bPoTd5soprXwxAH33RQAAAG8"]
[Tue Jul 21 08:42:54.752722 2026] [security2:error] [pid 511108:tid 511209] [remote 185.8.106.219:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fidellium.com"] [uri "/"] [unique_id "al9bPoTd5soprXwxAH33RgAAFmQ"]
[Tue Jul 21 08:42:54.772504 2026] [security2:error] [pid 511108:tid 511281] [client 203.25.124.252:36481] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-config-sample.php"] [unique_id "al9bPoTd5soprXwxAH33RwAAACs"]
[Tue Jul 21 08:42:54.816632 2026] [proxy:error] [pid 511108:tid 511355] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:54.816698 2026] [proxy_http:error] [pid 511108:tid 511355] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:54.817479 2026] [proxy:error] [pid 511108:tid 511355] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:54.817512 2026] [proxy_http:error] [pid 511108:tid 511355] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.163751 2026] [proxy:error] [pid 511108:tid 511360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.163830 2026] [proxy_http:error] [pid 511108:tid 511360] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.164394 2026] [proxy:error] [pid 511108:tid 511360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.164417 2026] [proxy_http:error] [pid 511108:tid 511360] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.334073 2026] [security2:error] [pid 511108:tid 511334] [client 74.7.230.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.psicologafernandaguedes.com"] [uri "/cgi-sys/404.html"] [unique_id "al9bP4Td5soprXwxAH33WgAAAGA"]
[Tue Jul 21 08:42:55.334804 2026] [security2:error] [pid 511108:tid 511338] [client 74.7.230.9:58062] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.psicologafernandaguedes.com"] [uri "/robots.txt"] [unique_id "al9bP4Td5soprXwxAH33WAAAZCY"]
[Tue Jul 21 08:42:55.500648 2026] [proxy:error] [pid 511108:tid 511363] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.500727 2026] [proxy_http:error] [pid 511108:tid 511363] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.501564 2026] [proxy:error] [pid 511108:tid 511363] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.501599 2026] [proxy_http:error] [pid 511108:tid 511363] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.540952 2026] [proxy:error] [pid 511108:tid 511301] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.541031 2026] [proxy_http:error] [pid 511108:tid 511301] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.541217 2026] [proxy:error] [pid 511108:tid 511319] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.541316 2026] [proxy_http:error] [pid 511108:tid 511319] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.541756 2026] [proxy:error] [pid 511108:tid 511301] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.541800 2026] [proxy_http:error] [pid 511108:tid 511301] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.543422 2026] [proxy:error] [pid 511108:tid 511319] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.543476 2026] [proxy_http:error] [pid 511108:tid 511319] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.543703 2026] [proxy:error] [pid 511108:tid 511267] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.543745 2026] [proxy_http:error] [pid 511108:tid 511267] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.543848 2026] [proxy:error] [pid 511108:tid 511339] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.543903 2026] [proxy_http:error] [pid 511108:tid 511339] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.544003 2026] [proxy:error] [pid 511108:tid 511346] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.544061 2026] [proxy_http:error] [pid 511108:tid 511346] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.544210 2026] [proxy:error] [pid 511108:tid 511267] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.544232 2026] [proxy_http:error] [pid 511108:tid 511267] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.544626 2026] [proxy:error] [pid 511108:tid 511339] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.544657 2026] [proxy_http:error] [pid 511108:tid 511339] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.544735 2026] [proxy:error] [pid 511108:tid 511346] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.544767 2026] [proxy_http:error] [pid 511108:tid 511346] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.545026 2026] [security2:error] [pid 511108:tid 511296] [client 91.192.10.181:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.marinapiassivasconce1782219596805.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "al9bP4Td5soprXwxAH33aAAAADo"]
[Tue Jul 21 08:42:55.545210 2026] [security2:error] [pid 511108:tid 511273] [client 91.192.10.181:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.marinapiassivasconce1782219596805.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9bP4Td5soprXwxAH33aQAAACM"]
[Tue Jul 21 08:42:55.554150 2026] [security2:error] [pid 511108:tid 511287] [client 91.192.10.181:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.marinapiassivasconce1782219596805.0721679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "al9bP4Td5soprXwxAH33agAAADE"]
[Tue Jul 21 08:42:55.558894 2026] [proxy:error] [pid 511108:tid 511361] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.558965 2026] [proxy_http:error] [pid 511108:tid 511361] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.559769 2026] [proxy:error] [pid 511108:tid 511361] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:42:55.559807 2026] [proxy_http:error] [pid 511108:tid 511361] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:42:55.592827 2026] [security2:error] [pid 511108:tid 511318] [client 20.206.105.145:55807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/media.php"] [unique_id "al9bP4Td5soprXwxAH33bQAAAFA"]
[Tue Jul 21 08:42:55.740479 2026] [security2:error] [pid 511108:tid 511314] [client 122.176.100.127:50931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bP4Td5soprXwxAH33dAAAAEw"]
[Tue Jul 21 08:42:55.740607 2026] [security2:error] [pid 511108:tid 511314] [client 122.176.100.127:50931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bP4Td5soprXwxAH33dAAAAEw"]
[Tue Jul 21 08:42:55.785600 2026] [security2:error] [pid 511108:tid 511281] [client 212.32.76.65:49451] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403.php"] [unique_id "al9bP4Td5soprXwxAH33eAAAACs"]
[Tue Jul 21 08:42:55.796749 2026] [security2:error] [pid 511108:tid 511297] [client 74.7.230.27:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "psicologafernandaguedes.com"] [uri "/cgi-sys/404.html"] [unique_id "al9bP4Td5soprXwxAH33ewAAADs"]
[Tue Jul 21 08:42:55.798186 2026] [security2:error] [pid 511108:tid 511344] [client 74.7.230.27:50454] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "psicologafernandaguedes.com"] [uri "/robots.txt"] [unique_id "al9bP4Td5soprXwxAH33dgAAanY"]
[Tue Jul 21 08:42:56.019355 2026] [security2:error] [pid 511108:tid 511255] [client 20.226.60.151:58589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-blink.php"] [unique_id "al9bQITd5soprXwxAH33gQAAABE"]
[Tue Jul 21 08:42:56.339773 2026] [security2:error] [pid 511108:tid 511343] [client 113.22.144.139:49491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bQITd5soprXwxAH33iAAAAGk"]
[Tue Jul 21 08:42:56.339922 2026] [security2:error] [pid 511108:tid 511343] [client 113.22.144.139:49491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bQITd5soprXwxAH33iAAAAGk"]
[Tue Jul 21 08:42:56.461665 2026] [security2:error] [pid 511108:tid 511268] [client 20.206.105.145:55716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/images.php"] [unique_id "al9bQITd5soprXwxAH33iwAAAB4"]
[Tue Jul 21 08:42:56.562700 2026] [autoindex:error] [pid 511108:tid 511363] [client 185.213.175.37:0] AH01276: Cannot serve directory /home1/asse7722/blog.findcomp.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:42:56.596910 2026] [security2:error] [pid 511108:tid 511291] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bQITd5soprXwxAH33jAAANSg"]
[Tue Jul 21 08:42:56.820301 2026] [security2:error] [pid 511108:tid 511362] [client 168.167.81.163:59156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bQITd5soprXwxAH33ngAAAHw"]
[Tue Jul 21 08:42:56.820465 2026] [security2:error] [pid 511108:tid 511362] [client 168.167.81.163:59156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bQITd5soprXwxAH33ngAAAHw"]
[Tue Jul 21 08:42:56.873408 2026] [security2:error] [pid 511108:tid 511253] [client 203.25.124.210:31483] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/images/admin.php"] [unique_id "al9bQITd5soprXwxAH33oAAAAA8"]
[Tue Jul 21 08:42:57.071502 2026] [security2:error] [pid 511108:tid 511302] [client 31.58.51.184:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "brunocesarribeiro1782216213881.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9bQYTd5soprXwxAH33pAAAAEA"]
[Tue Jul 21 08:42:57.218749 2026] [security2:error] [pid 511108:tid 511238] [client 41.89.234.2:25312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bQYTd5soprXwxAH33qgAAAAA"]
[Tue Jul 21 08:42:57.218892 2026] [security2:error] [pid 511108:tid 511238] [client 41.89.234.2:25312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bQYTd5soprXwxAH33qgAAAAA"]
[Tue Jul 21 08:42:57.386600 2026] [autoindex:error] [pid 511108:tid 511244] [client 169.58.40.230:49912] AH01276: Cannot serve directory /home3/sabri472/evolvaa.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:42:57.562262 2026] [security2:error] [pid 511108:tid 511271] [client 20.206.105.145:55763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/adminner.php"] [unique_id "al9bQYTd5soprXwxAH33sgAAACE"]
[Tue Jul 21 08:42:57.969539 2026] [security2:error] [pid 511108:tid 511303] [client 203.25.124.199:45823] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/"] [unique_id "al9bQYTd5soprXwxAH33xwAAAEE"]
[Tue Jul 21 08:42:58.012436 2026] [autoindex:error] [pid 511108:tid 511282] [client 169.58.40.230:44734] AH01276: Cannot serve directory /home3/sabri472/evolvaa.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:42:58.051045 2026] [security2:error] [pid 511108:tid 511309] [client 213.152.162.15:59578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9bQoTd5soprXwxAH33yQAAAEc"]
[Tue Jul 21 08:42:58.051156 2026] [security2:error] [pid 511108:tid 511309] [client 213.152.162.15:59578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9bQoTd5soprXwxAH33yQAAAEc"]
[Tue Jul 21 08:42:58.162328 2026] [security2:error] [pid 511108:tid 511334] [client 203.25.124.54:57633] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "al9bQoTd5soprXwxAH33zQAAAGA"]
[Tue Jul 21 08:42:58.301927 2026] [security2:error] [pid 511108:tid 511289] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bQYTd5soprXwxAH33vAAAADM"]
[Tue Jul 21 08:42:58.345950 2026] [security2:error] [pid 511108:tid 511310] [client 49.144.66.253:31218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bQoTd5soprXwxAH330wAAAEg"]
[Tue Jul 21 08:42:58.346117 2026] [security2:error] [pid 511108:tid 511310] [client 49.144.66.253:31218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bQoTd5soprXwxAH330wAAAEg"]
[Tue Jul 21 08:42:58.727939 2026] [security2:error] [pid 511108:tid 511234] [remote 45.3.41.176:55227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9bQoTd5soprXwxAH331wAAXn0"]
[Tue Jul 21 08:42:58.775192 2026] [security2:error] [pid 511108:tid 511291] [client 5.38.115.39:62648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bQoTd5soprXwxAH333wAAADU"]
[Tue Jul 21 08:42:58.775314 2026] [security2:error] [pid 511108:tid 511291] [client 5.38.115.39:62648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bQoTd5soprXwxAH333wAAADU"]
[Tue Jul 21 08:42:58.973671 2026] [security2:error] [pid 511108:tid 511311] [client 203.25.124.193:46709] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/item.php"] [unique_id "al9bQoTd5soprXwxAH335wAAAEk"]
[Tue Jul 21 08:42:59.017895 2026] [security2:error] [pid 511108:tid 511169] [remote 130.51.180.8:35166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9bQ4Td5soprXwxAH336QAAKzw"]
[Tue Jul 21 08:42:59.066502 2026] [security2:error] [pid 511108:tid 511348] [client 212.32.76.4:28039] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/a.php"] [unique_id "al9bQ4Td5soprXwxAH336wAAAG4"]
[Tue Jul 21 08:42:59.680032 2026] [security2:error] [pid 511108:tid 511294] [client 203.25.124.181:25637] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/adminfuns.php"] [unique_id "al9bQ4Td5soprXwxAH33_QAAADg"]
[Tue Jul 21 08:42:59.962945 2026] [security2:error] [pid 511108:tid 511323] [client 203.25.124.212:46437] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "al9bQ4Td5soprXwxAH34BgAAAFU"]
[Tue Jul 21 08:43:00.021951 2026] [security2:error] [pid 511108:tid 511326] [client 20.206.105.145:55787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/admin.php"] [unique_id "al9bRITd5soprXwxAH34CgAAAFg"]
[Tue Jul 21 08:43:00.389120 2026] [security2:error] [pid 511108:tid 511361] [client 203.25.124.251:43389] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wpx/"] [unique_id "al9bRITd5soprXwxAH34HwAAAHs"]
[Tue Jul 21 08:43:00.651939 2026] [security2:error] [pid 511108:tid 511165] [remote 104.207.33.106:19429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9bRITd5soprXwxAH34PQAALzg"]
[Tue Jul 21 08:43:00.904874 2026] [security2:error] [pid 511108:tid 511163] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bRITd5soprXwxAH34QwAAMzY"]
[Tue Jul 21 08:43:00.905111 2026] [security2:error] [pid 511108:tid 511289] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bRITd5soprXwxAH34QwAAMzY"]
[Tue Jul 21 08:43:00.961711 2026] [security2:error] [pid 511108:tid 511305] [client 195.49.128.211:59843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bRITd5soprXwxAH34SQAAAEM"]
[Tue Jul 21 08:43:00.961853 2026] [security2:error] [pid 511108:tid 511305] [client 195.49.128.211:59843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bRITd5soprXwxAH34SQAAAEM"]
[Tue Jul 21 08:43:01.068960 2026] [security2:error] [pid 511108:tid 511360] [client 203.25.124.50:23673] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Requests/src/Exception/Transport/"] [unique_id "al9bRYTd5soprXwxAH34XAAAAHo"]
[Tue Jul 21 08:43:01.379895 2026] [security2:error] [pid 511108:tid 511253] [client 103.59.206.240:31414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bRYTd5soprXwxAH34aQAAAA8"]
[Tue Jul 21 08:43:01.380462 2026] [security2:error] [pid 511108:tid 511253] [client 103.59.206.240:31414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bRYTd5soprXwxAH34aQAAAA8"]
[Tue Jul 21 08:43:01.478121 2026] [security2:error] [pid 511108:tid 511215] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bRYTd5soprXwxAH34bAAAaWo"]
[Tue Jul 21 08:43:01.478356 2026] [security2:error] [pid 511108:tid 511343] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bRYTd5soprXwxAH34bAAAaWo"]
[Tue Jul 21 08:43:01.675682 2026] [security2:error] [pid 511108:tid 511287] [client 203.25.124.200:57571] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/files.php"] [unique_id "al9bRYTd5soprXwxAH34dQAAADE"]
[Tue Jul 21 08:43:01.729939 2026] [security2:error] [pid 511108:tid 511216] [remote 54.39.210.29:54310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.arielson.com.br"] [uri "/robots.txt"] [unique_id "al9bRYTd5soprXwxAH34eAAALGs"]
[Tue Jul 21 08:43:01.730134 2026] [security2:error] [pid 511108:tid 511282] [client 54.39.210.29:54310] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.arielson.com.br"] [uri "/robots.txt"] [unique_id "al9bRYTd5soprXwxAH34eAAALGs"]
[Tue Jul 21 08:43:02.369459 2026] [security2:error] [pid 511108:tid 511252] [client 203.25.124.211:25669] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/network/"] [unique_id "al9bRoTd5soprXwxAH34qAAAAA4"]
[Tue Jul 21 08:43:02.567048 2026] [security2:error] [pid 511108:tid 511120] [remote 45.3.42.162:13595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9bRoTd5soprXwxAH34sAAAVAs"]
[Tue Jul 21 08:43:02.575667 2026] [security2:error] [pid 511108:tid 511309] [client 20.151.10.161:56344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9bRoTd5soprXwxAH34sgAAAEc"]
[Tue Jul 21 08:43:02.838422 2026] [security2:error] [pid 511108:tid 511326] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bRoTd5soprXwxAH34qQAAAFg"]
[Tue Jul 21 08:43:02.861995 2026] [security2:error] [pid 511108:tid 511249] [client 20.206.105.145:55686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/k.php"] [unique_id "al9bRoTd5soprXwxAH34uwAAAAs"]
[Tue Jul 21 08:43:03.106543 2026] [security2:error] [pid 511108:tid 511287] [client 202.179.75.202:60736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bR4Td5soprXwxAH34wAAAADE"]
[Tue Jul 21 08:43:03.106644 2026] [security2:error] [pid 511108:tid 511287] [client 202.179.75.202:60736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bR4Td5soprXwxAH34wAAAADE"]
[Tue Jul 21 08:43:03.154800 2026] [security2:error] [pid 511108:tid 511351] [client 20.151.10.161:56445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9bR4Td5soprXwxAH34xQAAAHE"]
[Tue Jul 21 08:43:03.272427 2026] [security2:error] [pid 511108:tid 511111] [remote 54.39.136.205:43420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.arielson.com.br"] [uri "/"] [unique_id "al9bR4Td5soprXwxAH34yQAAGAI"]
[Tue Jul 21 08:43:03.272685 2026] [security2:error] [pid 511108:tid 511262] [client 54.39.136.205:43420] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.arielson.com.br"] [uri "/"] [unique_id "al9bR4Td5soprXwxAH34yQAAGAI"]
[Tue Jul 21 08:43:03.436411 2026] [security2:error] [pid 511108:tid 511323] [client 20.151.10.161:56443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/x.php"] [unique_id "al9bR4Td5soprXwxAH340wAAAFU"]
[Tue Jul 21 08:43:03.559703 2026] [security2:error] [pid 511108:tid 511309] [client 203.25.124.55:31047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/profile.php"] [unique_id "al9bR4Td5soprXwxAH34-wAAAEc"]
[Tue Jul 21 08:43:03.662768 2026] [security2:error] [pid 511108:tid 511347] [client 31.58.51.184:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "brunocesarribeiro1782216213881.0721679.meusitehostgator.com.br"] [uri "/backend/.env"] [unique_id "al9bR4Td5soprXwxAH35AQAAAG0"]
[Tue Jul 21 08:43:03.674725 2026] [security2:error] [pid 511108:tid 511350] [client 31.58.51.184:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "brunocesarribeiro1782216213881.0721679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9bR4Td5soprXwxAH35CAAAAHA"]
[Tue Jul 21 08:43:03.677220 2026] [security2:error] [pid 511108:tid 511326] [client 203.25.124.184:50561] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/news-portal/zdata.php"] [unique_id "al9bR4Td5soprXwxAH35CgAAAFg"]
[Tue Jul 21 08:43:03.753409 2026] [security2:error] [pid 511108:tid 511255] [client 61.1.167.83:57907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bR4Td5soprXwxAH35EgAAABE"]
[Tue Jul 21 08:43:03.753528 2026] [security2:error] [pid 511108:tid 511255] [client 61.1.167.83:57907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bR4Td5soprXwxAH35EgAAABE"]
[Tue Jul 21 08:43:03.773637 2026] [security2:error] [pid 511108:tid 511304] [client 20.151.10.161:30659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/j260624_13.php"] [unique_id "al9bR4Td5soprXwxAH35FAAAAEI"]
[Tue Jul 21 08:43:03.777028 2026] [security2:error] [pid 511108:tid 511327] [client 198.44.157.34:47874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9bR4Td5soprXwxAH35FQAAAFk"]
[Tue Jul 21 08:43:03.777115 2026] [security2:error] [pid 511108:tid 511327] [client 198.44.157.34:47874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9bR4Td5soprXwxAH35FQAAAFk"]
[Tue Jul 21 08:43:03.856440 2026] [security2:error] [pid 511108:tid 511330] [client 195.49.128.211:51646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bR4Td5soprXwxAH35GgAAAFw"]
[Tue Jul 21 08:43:03.857178 2026] [security2:error] [pid 511108:tid 511330] [client 195.49.128.211:51646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bR4Td5soprXwxAH35GgAAAFw"]
[Tue Jul 21 08:43:04.187876 2026] [security2:error] [pid 511108:tid 511260] [client 20.151.10.161:56347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/d62.php"] [unique_id "al9bSITd5soprXwxAH35LwAAABY"]
[Tue Jul 21 08:43:04.195685 2026] [security2:error] [pid 511108:tid 511351] [client 20.10.88.227:3521] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rioclaroimovel.com.br"] [uri "/index.php"] [unique_id "al9bR4Td5soprXwxAH35JwAAAHE"]
[Tue Jul 21 08:43:04.560461 2026] [security2:error] [pid 511108:tid 511263] [client 212.32.76.7:52719] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/tinymce/utils/"] [unique_id "al9bSITd5soprXwxAH35agAAABk"]
[Tue Jul 21 08:43:04.672920 2026] [security2:error] [pid 511108:tid 511246] [client 20.151.10.161:56329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/ups.php"] [unique_id "al9bSITd5soprXwxAH35cQAAAAg"]
[Tue Jul 21 08:43:04.698145 2026] [security2:error] [pid 511108:tid 511268] [client 20.206.105.145:55767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/x.php"] [unique_id "al9bSITd5soprXwxAH35cwAAAB4"]
[Tue Jul 21 08:43:04.819336 2026] [security2:error] [pid 511108:tid 511144] [remote 97.74.87.194:35866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9bSITd5soprXwxAH35eQAAFyM"]
[Tue Jul 21 08:43:04.953942 2026] [security2:error] [pid 511108:tid 511313] [client 213.152.162.15:38294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9bSITd5soprXwxAH35ggAAAEs"]
[Tue Jul 21 08:43:04.954030 2026] [security2:error] [pid 511108:tid 511313] [client 213.152.162.15:38294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9bSITd5soprXwxAH35ggAAAEs"]
[Tue Jul 21 08:43:05.103827 2026] [security2:error] [pid 511108:tid 511311] [client 20.151.10.161:56323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/k.php"] [unique_id "al9bSYTd5soprXwxAH35lgAAAEk"]
[Tue Jul 21 08:43:05.121729 2026] [security2:error] [pid 511108:tid 511155] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bSYTd5soprXwxAH35lwAAMi4"]
[Tue Jul 21 08:43:05.121894 2026] [security2:error] [pid 511108:tid 511288] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bSYTd5soprXwxAH35lwAAMi4"]
[Tue Jul 21 08:43:05.149419 2026] [security2:error] [pid 511108:tid 511289] [client 20.226.60.151:58560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/zc-208.php"] [unique_id "al9bSYTd5soprXwxAH35mwAAADM"]
[Tue Jul 21 08:43:05.286024 2026] [security2:error] [pid 511108:tid 511267] [client 59.95.197.55:50356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bSYTd5soprXwxAH35uwAAAB0"]
[Tue Jul 21 08:43:05.286613 2026] [security2:error] [pid 511108:tid 511267] [client 59.95.197.55:50356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bSYTd5soprXwxAH35uwAAAB0"]
[Tue Jul 21 08:43:05.317203 2026] [security2:error] [pid 511108:tid 511197] [remote 103.187.169.251:42490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agencia.aede.com.br"] [uri "/wp-login.php"] [unique_id "al9bSYTd5soprXwxAH35vwAAIVg"]
[Tue Jul 21 08:43:05.365452 2026] [security2:error] [pid 511108:tid 511301] [client 117.213.202.34:49642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bSYTd5soprXwxAH35xAAAAD8"]
[Tue Jul 21 08:43:05.365664 2026] [security2:error] [pid 511108:tid 511301] [client 117.213.202.34:49642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bSYTd5soprXwxAH35xAAAAD8"]
[Tue Jul 21 08:43:05.402724 2026] [security2:error] [pid 511108:tid 511274] [client 152.59.181.104:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bSYTd5soprXwxAH35xwAAACQ"]
[Tue Jul 21 08:43:05.402917 2026] [security2:error] [pid 511108:tid 511274] [client 152.59.181.104:51620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bSYTd5soprXwxAH35xwAAACQ"]
[Tue Jul 21 08:43:05.567005 2026] [security2:error] [pid 511108:tid 511326] [client 212.32.76.6:60725] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/block-patterns/"] [unique_id "al9bSYTd5soprXwxAH35zQAAAFg"]
[Tue Jul 21 08:43:05.673924 2026] [security2:error] [pid 511108:tid 511304] [client 203.25.124.187:31487] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/css/"] [unique_id "al9bSYTd5soprXwxAH350gAAAEI"]
[Tue Jul 21 08:43:05.836930 2026] [security2:error] [pid 511108:tid 511316] [client 20.151.10.161:56428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/k2.php"] [unique_id "al9bSYTd5soprXwxAH352QAAAE4"]
[Tue Jul 21 08:43:06.233892 2026] [security2:error] [pid 511108:tid 511303] [client 122.176.100.127:51433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bSoTd5soprXwxAH355gAAAEE"]
[Tue Jul 21 08:43:06.234079 2026] [security2:error] [pid 511108:tid 511303] [client 122.176.100.127:51433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bSoTd5soprXwxAH355gAAAEE"]
[Tue Jul 21 08:43:06.297768 2026] [security2:error] [pid 511108:tid 511263] [client 20.206.105.145:55699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wss.php"] [unique_id "al9bSoTd5soprXwxAH356gAAABk"]
[Tue Jul 21 08:43:06.324601 2026] [security2:error] [pid 511108:tid 511274] [client 20.151.10.161:56405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/k3.php"] [unique_id "al9bSoTd5soprXwxAH357AAAACQ"]
[Tue Jul 21 08:43:06.410960 2026] [security2:error] [pid 511108:tid 511324] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bSYTd5soprXwxAH352wAAAFY"]
[Tue Jul 21 08:43:06.475306 2026] [security2:error] [pid 511108:tid 511314] [client 203.25.124.208:41221] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/classwithtostring.php"] [unique_id "al9bSoTd5soprXwxAH357wAAAEw"]
[Tue Jul 21 08:43:06.653414 2026] [security2:error] [pid 511108:tid 511250] [client 20.151.10.161:56331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/k4.php"] [unique_id "al9bSoTd5soprXwxAH359wAAAAw"]
[Tue Jul 21 08:43:06.670466 2026] [security2:error] [pid 511108:tid 511249] [client 203.25.124.52:38627] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwentythree/patterns/template-singl-portfolio.php"] [unique_id "al9bSoTd5soprXwxAH35-AAAAAs"]
[Tue Jul 21 08:43:06.948488 2026] [security2:error] [pid 511108:tid 511282] [client 20.151.10.161:56406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/k5.php"] [unique_id "al9bSoTd5soprXwxAH36BgAAACw"]
[Tue Jul 21 08:43:07.111171 2026] [security2:error] [pid 511108:tid 511312] [client 104.238.222.26:51288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.paulaabrao.com.br"] [uri "/wp-login.php"] [unique_id "al9bSoTd5soprXwxAH353wAAAEo"]
[Tue Jul 21 08:43:07.121463 2026] [security2:error] [pid 511108:tid 511318] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bS4Td5soprXwxAH36BwAAUFI"]
[Tue Jul 21 08:43:07.256931 2026] [security2:error] [pid 511108:tid 511290] [client 5.31.193.106:58574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bS4Td5soprXwxAH36EgAAADQ"]
[Tue Jul 21 08:43:07.257106 2026] [security2:error] [pid 511108:tid 511290] [client 5.31.193.106:58574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bS4Td5soprXwxAH36EgAAADQ"]
[Tue Jul 21 08:43:07.316365 2026] [autoindex:error] [pid 511108:tid 511305] [client 5.78.122.81:55498] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/ceramicasantoaugusto.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.ceramicasantoaugusto.com.br/
[Tue Jul 21 08:43:07.420006 2026] [security2:error] [pid 511108:tid 511329] [client 20.151.10.161:56332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/w.php"] [unique_id "al9bS4Td5soprXwxAH36HgAAAFs"]
[Tue Jul 21 08:43:07.461152 2026] [security2:error] [pid 511108:tid 511320] [client 104.238.222.26:63696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.paulaabrao.com.br"] [uri "/wp-login.php"] [unique_id "al9bS4Td5soprXwxAH36HwAAAFI"], referer: https://www.google.com/search?q=wordpress
[Tue Jul 21 08:43:07.471967 2026] [security2:error] [pid 511108:tid 511309] [client 203.25.124.182:38307] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/"] [unique_id "al9bS4Td5soprXwxAH36IAAAAEc"]
[Tue Jul 21 08:43:07.565147 2026] [security2:error] [pid 511108:tid 511299] [client 203.25.124.73:53803] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/certificates/"] [unique_id "al9bS4Td5soprXwxAH36JQAAAD0"]
[Tue Jul 21 08:43:07.739222 2026] [security2:error] [pid 511108:tid 511165] [remote 147.50.252.213:33236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/wp-login.php"] [unique_id "al9bS4Td5soprXwxAH36LgAAHjg"]
[Tue Jul 21 08:43:07.856682 2026] [security2:error] [pid 511108:tid 511326] [client 20.151.10.161:56418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/fpwch.php"] [unique_id "al9bS4Td5soprXwxAH36MgAAAFg"]
[Tue Jul 21 08:43:07.887735 2026] [security2:error] [pid 511108:tid 511285] [client 113.22.144.139:50057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bS4Td5soprXwxAH36NQAAAC8"]
[Tue Jul 21 08:43:07.887831 2026] [security2:error] [pid 511108:tid 511285] [client 113.22.144.139:50057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bS4Td5soprXwxAH36NQAAAC8"]
[Tue Jul 21 08:43:08.233859 2026] [security2:error] [pid 511108:tid 511322] [client 20.151.10.161:56341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/w2025.php"] [unique_id "al9bTITd5soprXwxAH36PgAAAFQ"]
[Tue Jul 21 08:43:08.610297 2026] [security2:error] [pid 511108:tid 511209] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9bTITd5soprXwxAH36TwAARmQ"]
[Tue Jul 21 08:43:08.679285 2026] [security2:error] [pid 511108:tid 511279] [client 20.151.10.161:56343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/scxy.php"] [unique_id "al9bTITd5soprXwxAH36UQAAACk"]
[Tue Jul 21 08:43:08.699777 2026] [security2:error] [pid 511108:tid 511346] [client 168.167.81.163:64760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bTITd5soprXwxAH36UwAAAGw"]
[Tue Jul 21 08:43:08.699888 2026] [security2:error] [pid 511108:tid 511346] [client 168.167.81.163:64760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bTITd5soprXwxAH36UwAAAGw"]
[Tue Jul 21 08:43:08.758937 2026] [security2:error] [pid 511108:tid 511301] [client 20.206.105.145:55689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/ty.php"] [unique_id "al9bTITd5soprXwxAH36VQAAAD8"]
[Tue Jul 21 08:43:08.770793 2026] [security2:error] [pid 511108:tid 511329] [client 203.25.124.202:51017] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/admin.php"] [unique_id "al9bTITd5soprXwxAH36VwAAAFs"]
[Tue Jul 21 08:43:08.866495 2026] [security2:error] [pid 511108:tid 511350] [client 203.25.124.55:28475] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/includes/user/"] [unique_id "al9bTITd5soprXwxAH36XwAAAHA"]
[Tue Jul 21 08:43:09.045888 2026] [security2:error] [pid 511108:tid 511216] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9bTYTd5soprXwxAH36aAAAC2s"]
[Tue Jul 21 08:43:09.185099 2026] [security2:error] [pid 511108:tid 511355] [client 20.151.10.161:56333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/FWAZ.php"] [unique_id "al9bTYTd5soprXwxAH36bQAAAHU"]
[Tue Jul 21 08:43:09.216797 2026] [security2:error] [pid 511108:tid 511242] [client 49.144.66.253:31653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bTYTd5soprXwxAH36bwAAAAQ"]
[Tue Jul 21 08:43:09.216893 2026] [security2:error] [pid 511108:tid 511242] [client 49.144.66.253:31653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bTYTd5soprXwxAH36bwAAAAQ"]
[Tue Jul 21 08:43:09.216890 2026] [security2:error] [pid 511108:tid 511218] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/xyn.php"] [unique_id "al9bTYTd5soprXwxAH36bgAAG20"]
[Tue Jul 21 08:43:09.381667 2026] [security2:error] [pid 511108:tid 511187] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/patie.php"] [unique_id "al9bTYTd5soprXwxAH36eQAAPk4"]
[Tue Jul 21 08:43:09.422151 2026] [security2:error] [pid 511108:tid 511274] [client 41.89.234.2:25761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bTYTd5soprXwxAH36fgAAACQ"]
[Tue Jul 21 08:43:09.422279 2026] [security2:error] [pid 511108:tid 511274] [client 41.89.234.2:25761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bTYTd5soprXwxAH36fgAAACQ"]
[Tue Jul 21 08:43:09.466855 2026] [security2:error] [pid 511108:tid 511253] [client 20.151.10.161:56330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/qterm.php"] [unique_id "al9bTYTd5soprXwxAH36hAAAAA8"]
[Tue Jul 21 08:43:09.468903 2026] [security2:error] [pid 511108:tid 511337] [client 5.38.115.39:33012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bTYTd5soprXwxAH36gwAAAGM"]
[Tue Jul 21 08:43:09.469016 2026] [security2:error] [pid 511108:tid 511337] [client 5.38.115.39:33012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bTYTd5soprXwxAH36gwAAAGM"]
[Tue Jul 21 08:43:09.533174 2026] [security2:error] [pid 511108:tid 511197] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/aa.php"] [unique_id "al9bTYTd5soprXwxAH36hQAAGVg"]
[Tue Jul 21 08:43:09.661524 2026] [security2:error] [pid 511108:tid 511324] [client 20.226.60.151:34816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/sid4.php"] [unique_id "al9bTYTd5soprXwxAH36hwAAAFY"]
[Tue Jul 21 08:43:09.695319 2026] [security2:error] [pid 511108:tid 511122] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/xwpg.php"] [unique_id "al9bTYTd5soprXwxAH36iQAAPA0"]
[Tue Jul 21 08:43:09.764666 2026] [security2:error] [pid 511108:tid 511365] [client 20.151.10.161:56321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/blurbs.php"] [unique_id "al9bTYTd5soprXwxAH36jgAAAH8"]
[Tue Jul 21 08:43:09.868314 2026] [security2:error] [pid 511108:tid 511184] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/ops.php"] [unique_id "al9bTYTd5soprXwxAH36kwAABUs"]
[Tue Jul 21 08:43:09.872534 2026] [security2:error] [pid 511108:tid 511320] [client 203.25.124.5:48451] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/fm.php"] [unique_id "al9bTYTd5soprXwxAH36lQAAAFI"]
[Tue Jul 21 08:43:10.018543 2026] [security2:error] [pid 511108:tid 511230] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/mac.php"] [unique_id "al9bToTd5soprXwxAH36mwAAE3k"]
[Tue Jul 21 08:43:10.121951 2026] [security2:error] [pid 511108:tid 511289] [client 20.151.10.161:56338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/v543.php"] [unique_id "al9bToTd5soprXwxAH36ngAAADM"]
[Tue Jul 21 08:43:10.170089 2026] [security2:error] [pid 511108:tid 511188] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/mg.php"] [unique_id "al9bToTd5soprXwxAH36nwAASk8"]
[Tue Jul 21 08:43:10.321439 2026] [security2:error] [pid 511108:tid 511141] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-post-data.php"] [unique_id "al9bToTd5soprXwxAH36ogAAMiA"]
[Tue Jul 21 08:43:10.458967 2026] [security2:error] [pid 511108:tid 511327] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bTYTd5soprXwxAH36mQAAAFk"]
[Tue Jul 21 08:43:10.471258 2026] [security2:error] [pid 511108:tid 511201] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/pucci.php"] [unique_id "al9bToTd5soprXwxAH36xQAAVlw"]
[Tue Jul 21 08:43:10.474960 2026] [security2:error] [pid 511108:tid 511283] [client 20.151.10.161:56445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/w3lls.php"] [unique_id "al9bToTd5soprXwxAH36xgAAAC0"]
[Tue Jul 21 08:43:10.567409 2026] [security2:error] [pid 511108:tid 511261] [client 203.25.124.72:23491] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/66.php"] [unique_id "al9bToTd5soprXwxAH36zAAAABc"]
[Tue Jul 21 08:43:10.573260 2026] [security2:error] [pid 511108:tid 511347] [client 203.25.124.254:38657] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/"] [unique_id "al9bToTd5soprXwxAH36zQAAAG0"]
[Tue Jul 21 08:43:10.636545 2026] [security2:error] [pid 511108:tid 511163] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/black.php"] [unique_id "al9bToTd5soprXwxAH360AAAZDY"]
[Tue Jul 21 08:43:10.820634 2026] [security2:error] [pid 511108:tid 511173] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/zlece.php"] [unique_id "al9bToTd5soprXwxAH367AAAd0A"]
[Tue Jul 21 08:43:10.994735 2026] [security2:error] [pid 511108:tid 511193] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/vssrs.php"] [unique_id "al9bToTd5soprXwxAH369AAAGFQ"]
[Tue Jul 21 08:43:11.145011 2026] [security2:error] [pid 511108:tid 511143] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bT4Td5soprXwxAH36_AAAXiI"]
[Tue Jul 21 08:43:11.145159 2026] [security2:error] [pid 511108:tid 511332] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bT4Td5soprXwxAH36_AAAXiI"]
[Tue Jul 21 08:43:11.148010 2026] [security2:error] [pid 511108:tid 511126] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wicked.php"] [unique_id "al9bT4Td5soprXwxAH36_QAAXxE"]
[Tue Jul 21 08:43:11.284174 2026] [security2:error] [pid 511108:tid 511244] [client 20.151.10.161:56417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-ws68.php"] [unique_id "al9bT4Td5soprXwxAH36_gAAAAY"]
[Tue Jul 21 08:43:11.338515 2026] [security2:error] [pid 511108:tid 511215] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/24.php"] [unique_id "al9bT4Td5soprXwxAH36_wAAPGo"]
[Tue Jul 21 08:43:11.475498 2026] [security2:error] [pid 511108:tid 511299] [client 212.32.76.57:60475] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/js/widgets/"] [unique_id "al9bT4Td5soprXwxAH37BQAAAD0"]
[Tue Jul 21 08:43:11.488304 2026] [security2:error] [pid 511108:tid 511185] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/xacs.php"] [unique_id "al9bT4Td5soprXwxAH37BgAAUkw"]
[Tue Jul 21 08:43:11.600080 2026] [security2:error] [pid 511108:tid 511329] [client 195.49.128.211:60449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bT4Td5soprXwxAH37CgAAAFs"]
[Tue Jul 21 08:43:11.600195 2026] [security2:error] [pid 511108:tid 511329] [client 195.49.128.211:60449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bT4Td5soprXwxAH37CgAAAFs"]
[Tue Jul 21 08:43:11.652410 2026] [security2:error] [pid 511108:tid 511212] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/zildan.php"] [unique_id "al9bT4Td5soprXwxAH37DAAAVGc"]
[Tue Jul 21 08:43:11.820293 2026] [security2:error] [pid 511108:tid 511167] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/csa.php"] [unique_id "al9bT4Td5soprXwxAH37DwAACzo"]
[Tue Jul 21 08:43:11.870017 2026] [security2:error] [pid 511108:tid 511246] [client 203.25.124.42:41555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/languages/autoload_classmap.php"] [unique_id "al9bT4Td5soprXwxAH37EwAAAAg"]
[Tue Jul 21 08:43:11.913419 2026] [fcgid:warn] [pid 511108:tid 511312] (70014)End of file found: [client 168.144.100.227:61785] mod_fcgid: can't get data from http client
[Tue Jul 21 08:43:11.948568 2026] [security2:error] [pid 511108:tid 511269] [client 103.59.206.240:31176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bT4Td5soprXwxAH37GQAAAB8"]
[Tue Jul 21 08:43:11.948692 2026] [security2:error] [pid 511108:tid 511269] [client 103.59.206.240:31176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bT4Td5soprXwxAH37GQAAAB8"]
[Tue Jul 21 08:43:11.981096 2026] [autoindex:error] [pid 511108:tid 511303] [client 20.226.60.151:58605] AH01276: Cannot serve directory /home3/proj7307/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:11.990044 2026] [security2:error] [pid 511108:tid 511194] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/w3llscc.php"] [unique_id "al9bT4Td5soprXwxAH37IAAAelU"]
[Tue Jul 21 08:43:12.061641 2026] [security2:error] [pid 511108:tid 511159] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bUITd5soprXwxAH37IQAADzI"]
[Tue Jul 21 08:43:12.061777 2026] [security2:error] [pid 511108:tid 511253] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bUITd5soprXwxAH37IQAADzI"]
[Tue Jul 21 08:43:12.187185 2026] [security2:error] [pid 511108:tid 511334] [client 20.151.10.161:56424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/xyn.php"] [unique_id "al9bUITd5soprXwxAH37KAAAAGA"]
[Tue Jul 21 08:43:12.231230 2026] [security2:error] [pid 511108:tid 511152] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wpx.php"] [unique_id "al9bUITd5soprXwxAH37KgAAPCs"]
[Tue Jul 21 08:43:12.279306 2026] [security2:error] [pid 511108:tid 511349] [client 20.226.60.151:58605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wmore1.php"] [unique_id "al9bUITd5soprXwxAH37LQAAAG8"]
[Tue Jul 21 08:43:12.487998 2026] [security2:error] [pid 511108:tid 511174] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-css.php"] [unique_id "al9bUITd5soprXwxAH37QAAAA0E"]
[Tue Jul 21 08:43:12.571449 2026] [security2:error] [pid 511108:tid 511362] [client 203.25.124.210:24081] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/222.php"] [unique_id "al9bUITd5soprXwxAH37RAAAAHw"]
[Tue Jul 21 08:43:12.596881 2026] [security2:error] [pid 511108:tid 511249] [client 20.206.105.145:55758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/155.php"] [unique_id "al9bUITd5soprXwxAH37SAAAAAs"]
[Tue Jul 21 08:43:12.653769 2026] [security2:error] [pid 511108:tid 511294] [client 180.153.236.145:16079] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.comecx.online"] [uri "/"] [unique_id "al9bUITd5soprXwxAH37TAAAADg"], referer: http://www.comecx.online/
[Tue Jul 21 08:43:12.653929 2026] [security2:error] [pid 511108:tid 511294] [client 180.153.236.145:16079] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.comecx.online"] [uri "/"] [unique_id "al9bUITd5soprXwxAH37TAAAADg"], referer: http://www.comecx.online/
[Tue Jul 21 08:43:12.666006 2026] [security2:error] [pid 511108:tid 511172] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/ho.php"] [unique_id "al9bUITd5soprXwxAH37TQAAMz8"]
[Tue Jul 21 08:43:12.832622 2026] [security2:error] [pid 511108:tid 511160] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/xy.php"] [unique_id "al9bUITd5soprXwxAH37UAAAFjM"]
[Tue Jul 21 08:43:12.996937 2026] [security2:error] [pid 511108:tid 511229] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/loader.php"] [unique_id "al9bUITd5soprXwxAH37VAAAQ3g"]
[Tue Jul 21 08:43:13.028514 2026] [security2:error] [pid 511108:tid 511345] [client 74.7.228.24:55796] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.clinicaleonazevedo.com.br"] [uri "/index.php"] [unique_id "al9bUITd5soprXwxAH37IgAAa3E"]
[Tue Jul 21 08:43:13.155589 2026] [security2:error] [pid 511108:tid 511111] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/spadex.php"] [unique_id "al9bUYTd5soprXwxAH37YAAATgI"]
[Tue Jul 21 08:43:13.165799 2026] [security2:error] [pid 511108:tid 511314] [client 203.25.124.2:38729] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/2024/"] [unique_id "al9bUYTd5soprXwxAH37YQAAAEw"]
[Tue Jul 21 08:43:13.323565 2026] [security2:error] [pid 511108:tid 511199] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/2x.php"] [unique_id "al9bUYTd5soprXwxAH37aAAAUlo"]
[Tue Jul 21 08:43:13.381688 2026] [security2:error] [pid 511108:tid 511365] [client 20.151.10.161:56422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/green3.php"] [unique_id "al9bUYTd5soprXwxAH37aQAAAH8"]
[Tue Jul 21 08:43:13.457756 2026] [security2:error] [pid 511108:tid 511306] [client 74.7.228.24:55802] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "clinicaleonazevedo.com.br"] [uri "/index.php"] [unique_id "al9bUYTd5soprXwxAH37agAARAA"], referer: https://www.clinicaleonazevedo.com.br/robots.txt
[Tue Jul 21 08:43:13.484818 2026] [security2:error] [pid 511108:tid 511338] [client 20.226.60.151:58542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/solo1.php"] [unique_id "al9bUYTd5soprXwxAH37bAAAAGQ"]
[Tue Jul 21 08:43:13.487134 2026] [security2:error] [pid 511108:tid 511147] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/ctex1.php"] [unique_id "al9bUYTd5soprXwxAH37bgAAcCY"]
[Tue Jul 21 08:43:13.578579 2026] [security2:error] [pid 511108:tid 511257] [client 203.25.124.193:21905] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/aaa.php"] [unique_id "al9bUYTd5soprXwxAH37dAAAABM"]
[Tue Jul 21 08:43:13.601401 2026] [security2:error] [pid 511108:tid 511285] [client 173.252.95.28:55004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bUYTd5soprXwxAH37dQAAAC8"]
[Tue Jul 21 08:43:13.662155 2026] [security2:error] [pid 511108:tid 511144] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/edorxrr.php"] [unique_id "al9bUYTd5soprXwxAH37egAALCM"]
[Tue Jul 21 08:43:13.813423 2026] [security2:error] [pid 511108:tid 511220] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/miru1.php"] [unique_id "al9bUYTd5soprXwxAH37fAAAK28"]
[Tue Jul 21 08:43:13.919732 2026] [security2:error] [pid 511108:tid 511269] [client 20.151.10.161:56334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/ccs.php"] [unique_id "al9bUYTd5soprXwxAH37fwAAAB8"]
[Tue Jul 21 08:43:13.980274 2026] [security2:error] [pid 511108:tid 511136] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/sump1.php"] [unique_id "al9bUYTd5soprXwxAH37gAAAWxs"]
[Tue Jul 21 08:43:14.218261 2026] [autoindex:error] [pid 511108:tid 511298] [client 20.226.60.151:58595] AH01276: Cannot serve directory /home3/proj7307/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:14.240771 2026] [security2:error] [pid 511108:tid 511316] [client 20.226.60.151:58595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/cong.php"] [unique_id "al9bUoTd5soprXwxAH37kAAAAE4"]
[Tue Jul 21 08:43:14.262736 2026] [security2:error] [pid 511108:tid 511293] [client 203.25.124.35:36039] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/chosen.php"] [unique_id "al9bUoTd5soprXwxAH37kQAAADc"]
[Tue Jul 21 08:43:14.289085 2026] [security2:error] [pid 511108:tid 511175] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/file5.php"] [unique_id "al9bUoTd5soprXwxAH37kgAAb0I"]
[Tue Jul 21 08:43:14.396560 2026] [security2:error] [pid 511108:tid 511330] [client 202.179.75.202:53668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bUoTd5soprXwxAH37kwAAAFw"]
[Tue Jul 21 08:43:14.396680 2026] [security2:error] [pid 511108:tid 511330] [client 202.179.75.202:53668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bUoTd5soprXwxAH37kwAAAFw"]
[Tue Jul 21 08:43:14.442436 2026] [security2:error] [pid 511108:tid 511340] [client 20.151.10.161:56402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/ccc.php"] [unique_id "al9bUoTd5soprXwxAH37lwAAAGY"]
[Tue Jul 21 08:43:14.456176 2026] [security2:error] [pid 511108:tid 511180] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/0xD.php"] [unique_id "al9bUoTd5soprXwxAH37mAAAWEc"]
[Tue Jul 21 08:43:14.479335 2026] [security2:error] [pid 511108:tid 511336] [client 195.49.128.211:52250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bUoTd5soprXwxAH37mgAAAGI"]
[Tue Jul 21 08:43:14.479459 2026] [security2:error] [pid 511108:tid 511336] [client 195.49.128.211:52250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bUoTd5soprXwxAH37mgAAAGI"]
[Tue Jul 21 08:43:14.608635 2026] [security2:error] [pid 511108:tid 511328] [client 20.206.105.145:55704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/ops.php"] [unique_id "al9bUoTd5soprXwxAH37oQAAAFo"]
[Tue Jul 21 08:43:14.674697 2026] [security2:error] [pid 511108:tid 511209] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/fnstall.php"] [unique_id "al9bUoTd5soprXwxAH37owAAe2Q"]
[Tue Jul 21 08:43:14.827668 2026] [security2:error] [pid 511108:tid 511143] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/acp.php"] [unique_id "al9bUoTd5soprXwxAH37qgAAFyI"]
[Tue Jul 21 08:43:14.992562 2026] [security2:error] [pid 511108:tid 511206] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/mosty.php"] [unique_id "al9bUoTd5soprXwxAH37rwAAMmE"]
[Tue Jul 21 08:43:15.151113 2026] [security2:error] [pid 511108:tid 511233] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/6.php"] [unique_id "al9bU4Td5soprXwxAH37tQAAGHw"]
[Tue Jul 21 08:43:15.158794 2026] [security2:error] [pid 511108:tid 511285] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bUoTd5soprXwxAH37ogAAAC8"]
[Tue Jul 21 08:43:15.207753 2026] [security2:error] [pid 511108:tid 511260] [client 20.151.10.161:56382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/get.php"] [unique_id "al9bU4Td5soprXwxAH37uAAAABY"]
[Tue Jul 21 08:43:15.317405 2026] [security2:error] [pid 511108:tid 511131] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/32e17094cfindex.php"] [unique_id "al9bU4Td5soprXwxAH37vgAANRY"]
[Tue Jul 21 08:43:15.323931 2026] [autoindex:error] [pid 511108:tid 511340] [client 20.226.60.151:34840] AH01276: Cannot serve directory /home3/proj7307/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:15.345427 2026] [security2:error] [pid 511108:tid 511279] [client 20.226.60.151:34840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/public/css.php"] [unique_id "al9bU4Td5soprXwxAH37vwAAACk"]
[Tue Jul 21 08:43:15.468522 2026] [security2:error] [pid 511108:tid 511120] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/qqqa.php"] [unique_id "al9bU4Td5soprXwxAH37wQAAWgs"]
[Tue Jul 21 08:43:15.621514 2026] [security2:error] [pid 511108:tid 511161] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/aunmc.php"] [unique_id "al9bU4Td5soprXwxAH37xAAAfDQ"]
[Tue Jul 21 08:43:15.711895 2026] [security2:error] [pid 511108:tid 511210] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bU4Td5soprXwxAH37ywAAf2U"]
[Tue Jul 21 08:43:15.712053 2026] [security2:error] [pid 511108:tid 511365] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bU4Td5soprXwxAH37ywAAf2U"]
[Tue Jul 21 08:43:15.773120 2026] [security2:error] [pid 511108:tid 511194] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/uoocf.php"] [unique_id "al9bU4Td5soprXwxAH371wAAQ1U"]
[Tue Jul 21 08:43:15.793121 2026] [security2:error] [pid 511108:tid 511244] [client 59.95.197.55:51000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bU4Td5soprXwxAH372QAAAAY"]
[Tue Jul 21 08:43:15.793887 2026] [security2:error] [pid 511108:tid 511244] [client 59.95.197.55:51000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bU4Td5soprXwxAH372QAAAAY"]
[Tue Jul 21 08:43:15.871266 2026] [security2:error] [pid 511108:tid 511345] [client 203.25.124.252:59047] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/admin.php"] [unique_id "al9bU4Td5soprXwxAH372gAAAGs"]
[Tue Jul 21 08:43:15.890449 2026] [security2:error] [pid 511108:tid 511242] [client 20.151.10.161:56384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/images.php"] [unique_id "al9bU4Td5soprXwxAH373AAAAAQ"]
[Tue Jul 21 08:43:15.925481 2026] [security2:error] [pid 511108:tid 511169] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/iywwi.php"] [unique_id "al9bU4Td5soprXwxAH373wAAGDw"]
[Tue Jul 21 08:43:15.948995 2026] [security2:error] [pid 511108:tid 511245] [client 20.206.105.145:55714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/ingfo.php"] [unique_id "al9bU4Td5soprXwxAH374AAAAAc"]
[Tue Jul 21 08:43:16.092156 2026] [security2:error] [pid 511108:tid 511179] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/gqgsa.php"] [unique_id "al9bVITd5soprXwxAH375AAAL0Y"]
[Tue Jul 21 08:43:16.243843 2026] [security2:error] [pid 511108:tid 511279] [client 20.206.105.145:55717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/error_log.php"] [unique_id "al9bVITd5soprXwxAH376wAAACk"]
[Tue Jul 21 08:43:16.247374 2026] [security2:error] [pid 511108:tid 511113] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/elbzl.php"] [unique_id "al9bVITd5soprXwxAH377gAAWAQ"]
[Tue Jul 21 08:43:16.312656 2026] [security2:error] [pid 511108:tid 511338] [client 152.59.181.104:52107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bVITd5soprXwxAH377wAAAGQ"]
[Tue Jul 21 08:43:16.312884 2026] [security2:error] [pid 511108:tid 511338] [client 152.59.181.104:52107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bVITd5soprXwxAH377wAAAGQ"]
[Tue Jul 21 08:43:16.399944 2026] [security2:error] [pid 511108:tid 511129] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/adjig.php"] [unique_id "al9bVITd5soprXwxAH379wAASBQ"]
[Tue Jul 21 08:43:16.572896 2026] [security2:error] [pid 511108:tid 511184] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/byp.php"] [unique_id "al9bVITd5soprXwxAH37_gAAW0s"]
[Tue Jul 21 08:43:16.580538 2026] [security2:error] [pid 511108:tid 511269] [client 212.32.76.10:31675] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/footer.php"] [unique_id "al9bVITd5soprXwxAH37_wAAAB8"]
[Tue Jul 21 08:43:16.685100 2026] [security2:error] [pid 511108:tid 511273] [client 122.176.100.127:51945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bVITd5soprXwxAH38BQAAACM"]
[Tue Jul 21 08:43:16.685319 2026] [security2:error] [pid 511108:tid 511273] [client 122.176.100.127:51945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bVITd5soprXwxAH38BQAAACM"]
[Tue Jul 21 08:43:16.695823 2026] [http2:info] [pid 514479:tid 514479] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 08:43:16.712640 2026] [security2:error] [pid 511108:tid 511244] [client 20.151.10.161:56444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/alls.php"] [unique_id "al9bVITd5soprXwxAH38CQAAAAY"]
[Tue Jul 21 08:43:16.749487 2026] [security2:error] [pid 511108:tid 511174] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/ortasekerli1.php"] [unique_id "al9bVITd5soprXwxAH38DAAABEE"]
[Tue Jul 21 08:43:16.934597 2026] [security2:error] [pid 511108:tid 511213] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/classwithtostring.php"] [unique_id "al9bVITd5soprXwxAH38DwAAb2g"]
[Tue Jul 21 08:43:16.940235 2026] [security2:error] [pid 511108:tid 511341] [client 20.206.105.145:55766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/ok.php"] [unique_id "al9bVITd5soprXwxAH38EAAAAGc"]
[Tue Jul 21 08:43:17.079990 2026] [security2:error] [pid 511108:tid 511270] [client 117.213.202.34:50273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bVITd5soprXwxAH374wAAACA"]
[Tue Jul 21 08:43:17.080156 2026] [security2:error] [pid 511108:tid 511270] [client 117.213.202.34:50273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bVITd5soprXwxAH374wAAACA"]
[Tue Jul 21 08:43:17.085924 2026] [security2:error] [pid 511108:tid 511225] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/root.php"] [unique_id "al9bVYTd5soprXwxAH38EwAAN3Q"]
[Tue Jul 21 08:43:17.105026 2026] [security2:error] [pid 514479:tid 514623] [client 20.151.10.161:30658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/yyu.php"] [unique_id "al9bVfzqsQqnLoCgUjhfBgAAARM"]
[Tue Jul 21 08:43:17.247731 2026] [security2:error] [pid 511108:tid 511121] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/sym403.php"] [unique_id "al9bVYTd5soprXwxAH38GgAAfAw"]
[Tue Jul 21 08:43:17.401264 2026] [security2:error] [pid 511108:tid 511116] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/v543.php"] [unique_id "al9bVYTd5soprXwxAH38IgAAMwc"]
[Tue Jul 21 08:43:17.458409 2026] [security2:error] [pid 511108:tid 511273] [client 20.151.10.161:56409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/by.php"] [unique_id "al9bVYTd5soprXwxAH38IwAAACM"]
[Tue Jul 21 08:43:17.462057 2026] [access_compat:error] [pid 511108:tid 511281] [client 162.241.63.68:50052] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:43:17.478188 2026] [security2:error] [pid 511108:tid 511282] [client 203.25.124.199:29875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/inputs.php"] [unique_id "al9bVYTd5soprXwxAH38JQAAACw"]
[Tue Jul 21 08:43:17.575340 2026] [security2:error] [pid 511108:tid 511191] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/sixxis.php"] [unique_id "al9bVYTd5soprXwxAH38JwAAa1I"]
[Tue Jul 21 08:43:17.720327 2026] [security2:error] [pid 511108:tid 511359] [client 20.226.60.151:58550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/output.php"] [unique_id "al9bVYTd5soprXwxAH38KwAAAHk"]
[Tue Jul 21 08:43:17.738535 2026] [security2:error] [pid 511108:tid 511201] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/ip.php"] [unique_id "al9bVYTd5soprXwxAH38LgAAGVw"]
[Tue Jul 21 08:43:17.761895 2026] [security2:error] [pid 514479:tid 514633] [client 20.151.10.161:56447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/FAQ.php"] [unique_id "al9bVfzqsQqnLoCgUjhfCwAAAR0"]
[Tue Jul 21 08:43:17.825356 2026] [security2:error] [pid 511108:tid 511337] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bVYTd5soprXwxAH38LwAAYwA"]
[Tue Jul 21 08:43:17.868546 2026] [security2:error] [pid 511108:tid 511260] [client 203.25.124.61:27783] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/wp-file-manager-pro/"] [unique_id "al9bVYTd5soprXwxAH38MQAAABY"]
[Tue Jul 21 08:43:17.909267 2026] [security2:error] [pid 511108:tid 511163] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/kq1.php"] [unique_id "al9bVYTd5soprXwxAH38NQAAezY"]
[Tue Jul 21 08:43:18.061254 2026] [security2:error] [pid 514479:tid 514638] [client 20.151.10.161:56328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/coffexium.php"] [unique_id "al9bVvzqsQqnLoCgUjhfDQAAASI"]
[Tue Jul 21 08:43:18.183803 2026] [security2:error] [pid 511108:tid 511269] [client 113.22.144.139:50516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bVoTd5soprXwxAH38OwAAAB8"]
[Tue Jul 21 08:43:18.183995 2026] [security2:error] [pid 511108:tid 511269] [client 113.22.144.139:50516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bVoTd5soprXwxAH38OwAAAB8"]
[Tue Jul 21 08:43:18.193603 2026] [security2:error] [pid 511108:tid 511200] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/fw/faiyy.php"] [unique_id "al9bVoTd5soprXwxAH38PAAAJVs"]
[Tue Jul 21 08:43:18.347004 2026] [security2:error] [pid 514479:tid 514645] [client 20.206.105.145:55745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/mac.php"] [unique_id "al9bVvzqsQqnLoCgUjhfEAAAASk"]
[Tue Jul 21 08:43:18.473075 2026] [security2:error] [pid 511108:tid 511127] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/h02ugyh.php"] [unique_id "al9bVoTd5soprXwxAH38RQAAdhI"]
[Tue Jul 21 08:43:18.564898 2026] [security2:error] [pid 511108:tid 511321] [client 203.25.124.65:44577] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/system_log.php"] [unique_id "al9bVoTd5soprXwxAH38SQAAAFM"]
[Tue Jul 21 08:43:18.602729 2026] [security2:error] [pid 511108:tid 511305] [client 20.151.10.161:56431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/red.php"] [unique_id "al9bVoTd5soprXwxAH38SgAAAEM"]
[Tue Jul 21 08:43:18.625655 2026] [security2:error] [pid 511108:tid 511128] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-temp.php"] [unique_id "al9bVoTd5soprXwxAH38SwAAaBM"]
[Tue Jul 21 08:43:18.669840 2026] [security2:error] [pid 514479:tid 514649] [client 203.25.124.5:37401] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/about.php"] [unique_id "al9bVvzqsQqnLoCgUjhfEwAAAS0"]
[Tue Jul 21 08:43:18.780480 2026] [security2:error] [pid 511108:tid 511148] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-content/cong.php"] [unique_id "al9bVoTd5soprXwxAH38UQAAZyc"]
[Tue Jul 21 08:43:18.991901 2026] [security2:error] [pid 511108:tid 511345] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bVoTd5soprXwxAH38RwAAAGs"]
[Tue Jul 21 08:43:19.153645 2026] [security2:error] [pid 511108:tid 511126] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-includes/css/index.php"] [unique_id "al9bV4Td5soprXwxAH38WgAAfBE"]
[Tue Jul 21 08:43:19.316287 2026] [security2:error] [pid 511108:tid 511206] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/jj.php"] [unique_id "al9bV4Td5soprXwxAH38XQAAcGE"]
[Tue Jul 21 08:43:19.426530 2026] [autoindex:error] [pid 511108:tid 511292] [client 20.151.10.161:0] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:19.488372 2026] [security2:error] [pid 511108:tid 511185] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al9bV4Td5soprXwxAH38aAAABkw"]
[Tue Jul 21 08:43:19.580276 2026] [security2:error] [pid 514479:tid 514617] [client 41.89.234.2:54836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bV_zqsQqnLoCgUjhfHgAAAQ0"]
[Tue Jul 21 08:43:19.580448 2026] [security2:error] [pid 514479:tid 514617] [client 41.89.234.2:54836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bV_zqsQqnLoCgUjhfHgAAAQ0"]
[Tue Jul 21 08:43:19.639173 2026] [security2:error] [pid 511108:tid 511131] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/txets.php"] [unique_id "al9bV4Td5soprXwxAH38bwAAeBY"]
[Tue Jul 21 08:43:19.701054 2026] [core:error] [pid 514479:tid 514492] [remote 198.235.24.41:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://webmail.compranawebprodutos.com/
[Tue Jul 21 08:43:19.701082 2026] [core:error] [pid 514479:tid 514492] [remote 198.235.24.41:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://webmail.compranawebprodutos.com/
[Tue Jul 21 08:43:19.746401 2026] [security2:error] [pid 514479:tid 514676] [client 20.151.10.161:56389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9bV_zqsQqnLoCgUjhfIQAAAUg"]
[Tue Jul 21 08:43:19.765149 2026] [security2:error] [pid 514479:tid 514678] [client 203.25.124.43:21843] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/separator/"] [unique_id "al9bV_zqsQqnLoCgUjhfIgAAAUo"]
[Tue Jul 21 08:43:19.790375 2026] [security2:error] [pid 511108:tid 511161] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/dex.php"] [unique_id "al9bV4Td5soprXwxAH38cgAAeTQ"]
[Tue Jul 21 08:43:19.887369 2026] [security2:error] [pid 511108:tid 511195] [remote 47.86.33.52:15866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/wp-login.php"] [unique_id "al9bV4Td5soprXwxAH38eAAAXFY"]
[Tue Jul 21 08:43:19.950654 2026] [security2:error] [pid 511108:tid 511150] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/xpwer1.php"] [unique_id "al9bV4Td5soprXwxAH38eQAAYyk"]
[Tue Jul 21 08:43:19.966942 2026] [security2:error] [pid 511108:tid 511341] [client 203.25.124.200:59953] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/speculative8.php"] [unique_id "al9bV4Td5soprXwxAH38egAAAGc"]
[Tue Jul 21 08:43:20.034477 2026] [security2:error] [pid 511108:tid 511365] [client 168.167.81.163:61728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bWITd5soprXwxAH38fAAAAH8"]
[Tue Jul 21 08:43:20.034582 2026] [security2:error] [pid 511108:tid 511365] [client 168.167.81.163:61728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bWITd5soprXwxAH38fAAAAH8"]
[Tue Jul 21 08:43:20.119530 2026] [security2:error] [pid 511108:tid 511219] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/flox.php"] [unique_id "al9bWITd5soprXwxAH38fQAAb24"]
[Tue Jul 21 08:43:20.155887 2026] [security2:error] [pid 511108:tid 511297] [client 5.38.115.39:63799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bWITd5soprXwxAH38fgAAADs"]
[Tue Jul 21 08:43:20.156020 2026] [security2:error] [pid 511108:tid 511297] [client 5.38.115.39:63799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bWITd5soprXwxAH38fgAAADs"]
[Tue Jul 21 08:43:20.266221 2026] [security2:error] [pid 514479:tid 514683] [client 49.144.66.253:32144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bWPzqsQqnLoCgUjhfLAAAAU8"]
[Tue Jul 21 08:43:20.266408 2026] [security2:error] [pid 514479:tid 514683] [client 49.144.66.253:32144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bWPzqsQqnLoCgUjhfLAAAAU8"]
[Tue Jul 21 08:43:20.271325 2026] [security2:error] [pid 511108:tid 511179] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/popo.php"] [unique_id "al9bWITd5soprXwxAH38gQAATEY"]
[Tue Jul 21 08:43:20.389371 2026] [autoindex:error] [pid 511108:tid 511238] [client 20.151.10.161:0] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:20.401941 2026] [security2:error] [pid 514479:tid 514695] [client 20.197.192.193:2834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9bWPzqsQqnLoCgUjhfLQAAAVs"]
[Tue Jul 21 08:43:20.438525 2026] [security2:error] [pid 511108:tid 511231] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/yas.php"] [unique_id "al9bWITd5soprXwxAH38iQAAVno"]
[Tue Jul 21 08:43:20.537611 2026] [security2:error] [pid 514479:tid 514701] [client 20.151.10.161:56349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/footer.php"] [unique_id "al9bWPzqsQqnLoCgUjhfLwAAAWE"]
[Tue Jul 21 08:43:20.609155 2026] [security2:error] [pid 511108:tid 511184] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/file61.php"] [unique_id "al9bWITd5soprXwxAH38kAAAPUs"]
[Tue Jul 21 08:43:20.791318 2026] [security2:error] [pid 511108:tid 511208] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/water.php"] [unique_id "al9bWITd5soprXwxAH38kgAAU2M"]
[Tue Jul 21 08:43:20.799058 2026] [security2:error] [pid 514479:tid 514712] [client 20.206.105.145:55778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wefile.php"] [unique_id "al9bWPzqsQqnLoCgUjhfNAAAAWw"]
[Tue Jul 21 08:43:20.859181 2026] [security2:error] [pid 511108:tid 511262] [client 20.197.192.193:2784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9bWITd5soprXwxAH38lAAAABg"]
[Tue Jul 21 08:43:20.966774 2026] [security2:error] [pid 511108:tid 511125] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/nano.php"] [unique_id "al9bWITd5soprXwxAH38mwAAOxA"]
[Tue Jul 21 08:43:20.979186 2026] [security2:error] [pid 511108:tid 511260] [client 198.44.157.34:40664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9bWITd5soprXwxAH38nAAAABY"]
[Tue Jul 21 08:43:20.979255 2026] [security2:error] [pid 511108:tid 511260] [client 198.44.157.34:40664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9bWITd5soprXwxAH38nAAAABY"]
[Tue Jul 21 08:43:21.070502 2026] [autoindex:error] [pid 511108:tid 511240] [client 20.151.10.161:0] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:21.171596 2026] [security2:error] [pid 514479:tid 514718] [client 203.25.124.12:30499] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/radio.php"] [unique_id "al9bWfzqsQqnLoCgUjhfNwAAAXI"]
[Tue Jul 21 08:43:21.175589 2026] [security2:error] [pid 511108:tid 511213] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/moon.php"] [unique_id "al9bWYTd5soprXwxAH38pQAAJmg"]
[Tue Jul 21 08:43:21.181731 2026] [security2:error] [pid 511108:tid 511360] [client 20.197.192.193:2767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/dp.php"] [unique_id "al9bWYTd5soprXwxAH38pgAAAHo"]
[Tue Jul 21 08:43:21.188087 2026] [security2:error] [pid 514479:tid 514719] [client 64.42.179.43:41668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9bWfzqsQqnLoCgUjhfOAAAAXM"]
[Tue Jul 21 08:43:21.188164 2026] [security2:error] [pid 514479:tid 514719] [client 64.42.179.43:41668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9bWfzqsQqnLoCgUjhfOAAAAXM"]
[Tue Jul 21 08:43:21.198868 2026] [security2:error] [pid 511108:tid 511238] [client 172.233.177.18:40736] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "abbaprotect.com"] [uri "/wp-json/batch/v1"] [unique_id "al9bWYTd5soprXwxAH38pwAAAAA"]
[Tue Jul 21 08:43:21.209374 2026] [security2:error] [pid 511108:tid 511275] [client 20.151.10.161:56446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-content/index.php"] [unique_id "al9bWYTd5soprXwxAH38qAAAACU"]
[Tue Jul 21 08:43:21.284161 2026] [security2:error] [pid 511108:tid 511245] [client 203.25.124.74:49943] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/mah/function.php"] [unique_id "al9bWYTd5soprXwxAH38qQAAAAc"]
[Tue Jul 21 08:43:21.312001 2026] [security2:error] [pid 511108:tid 511292] [client 172.233.177.18:40736] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "abbaprotect.com"] [uri "/"] [unique_id "al9bWYTd5soprXwxAH38rQAAADY"]
[Tue Jul 21 08:43:21.317545 2026] [security2:error] [pid 511108:tid 511269] [client 20.226.60.151:34821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-file-120.php"] [unique_id "al9bWYTd5soprXwxAH38rgAAAB8"]
[Tue Jul 21 08:43:21.371114 2026] [security2:error] [pid 511108:tid 511121] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-info.php"] [unique_id "al9bWYTd5soprXwxAH38rwAAWww"]
[Tue Jul 21 08:43:21.388614 2026] [security2:error] [pid 511108:tid 511294] [client 20.197.192.193:2791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/old.php"] [unique_id "al9bWYTd5soprXwxAH38sgAAADg"]
[Tue Jul 21 08:43:21.554626 2026] [security2:error] [pid 511108:tid 511117] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/2000.php"] [unique_id "al9bWYTd5soprXwxAH38uQAAdAg"]
[Tue Jul 21 08:43:21.641666 2026] [security2:error] [pid 514479:tid 514501] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bWfzqsQqnLoCgUjhfPgABdBE"]
[Tue Jul 21 08:43:21.641794 2026] [security2:error] [pid 514479:tid 514720] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bWfzqsQqnLoCgUjhfPgABdBE"]
[Tue Jul 21 08:43:21.679208 2026] [security2:error] [pid 511108:tid 511359] [client 20.151.10.161:56391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/zoro.php"] [unique_id "al9bWYTd5soprXwxAH38uwAAAHk"]
[Tue Jul 21 08:43:21.743528 2026] [security2:error] [pid 511108:tid 511199] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/122.php"] [unique_id "al9bWYTd5soprXwxAH38vwAAQ1o"]
[Tue Jul 21 08:43:21.835928 2026] [security2:error] [pid 514479:tid 514730] [client 20.197.192.193:2838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/ms-new.php"] [unique_id "al9bWfzqsQqnLoCgUjhfQAAAAX4"]
[Tue Jul 21 08:43:21.895040 2026] [security2:error] [pid 511108:tid 511145] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/mds.php"] [unique_id "al9bWYTd5soprXwxAH38wQAAdyQ"]
[Tue Jul 21 08:43:21.911449 2026] [security2:error] [pid 511108:tid 511242] [client 61.1.167.83:58414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bWYTd5soprXwxAH38wwAAAAQ"]
[Tue Jul 21 08:43:21.913256 2026] [security2:error] [pid 511108:tid 511242] [client 61.1.167.83:58414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bWYTd5soprXwxAH38wwAAAAQ"]
[Tue Jul 21 08:43:21.961798 2026] [security2:error] [pid 511108:tid 511316] [client 20.151.10.161:56335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/admin.php"] [unique_id "al9bWYTd5soprXwxAH38xwAAAE4"]
[Tue Jul 21 08:43:22.046751 2026] [security2:error] [pid 511108:tid 511122] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-blink.php"] [unique_id "al9bWoTd5soprXwxAH38yAAAIQ0"]
[Tue Jul 21 08:43:22.211908 2026] [security2:error] [pid 511108:tid 511147] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/zc-208.php"] [unique_id "al9bWoTd5soprXwxAH380gAAWyY"]
[Tue Jul 21 08:43:22.237385 2026] [security2:error] [pid 511108:tid 511363] [client 20.197.192.193:2848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/track.php"] [unique_id "al9bWoTd5soprXwxAH381AAAAH0"]
[Tue Jul 21 08:43:22.266298 2026] [security2:error] [pid 511108:tid 511244] [client 20.151.10.161:56367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/greap.php"] [unique_id "al9bWoTd5soprXwxAH381QAAAAY"]
[Tue Jul 21 08:43:22.276652 2026] [security2:error] [pid 511108:tid 511299] [client 212.32.76.62:39129] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/js/"] [unique_id "al9bWoTd5soprXwxAH381wAAAD0"]
[Tue Jul 21 08:43:22.337036 2026] [security2:error] [pid 514479:tid 514734] [client 195.49.128.211:61056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bWvzqsQqnLoCgUjhfRgAAAYI"]
[Tue Jul 21 08:43:22.337270 2026] [security2:error] [pid 514479:tid 514734] [client 195.49.128.211:61056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bWvzqsQqnLoCgUjhfRgAAAYI"]
[Tue Jul 21 08:43:22.365096 2026] [security2:error] [pid 511108:tid 511110] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/sid4.php"] [unique_id "al9bWoTd5soprXwxAH382QAAPAE"]
[Tue Jul 21 08:43:22.519319 2026] [security2:error] [pid 511108:tid 511254] [client 20.197.192.193:2855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/2352356666.php"] [unique_id "al9bWoTd5soprXwxAH383wAAABA"]
[Tue Jul 21 08:43:22.570952 2026] [security2:error] [pid 511108:tid 511343] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bWoTd5soprXwxAH38zAAAAGk"]
[Tue Jul 21 08:43:22.574603 2026] [security2:error] [pid 514479:tid 514733] [client 103.59.206.240:31298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bWvzqsQqnLoCgUjhfSAAAAYE"]
[Tue Jul 21 08:43:22.574751 2026] [security2:error] [pid 514479:tid 514733] [client 103.59.206.240:31298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bWvzqsQqnLoCgUjhfSAAAAYE"]
[Tue Jul 21 08:43:22.588646 2026] [security2:error] [pid 511108:tid 511128] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bWoTd5soprXwxAH384gAAQhM"]
[Tue Jul 21 08:43:22.588811 2026] [security2:error] [pid 511108:tid 511304] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bWoTd5soprXwxAH384gAAQhM"]
[Tue Jul 21 08:43:22.659926 2026] [security2:error] [pid 514479:tid 514615] [client 20.151.10.161:56350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/177.php"] [unique_id "al9bWvzqsQqnLoCgUjhfSQAAAQs"]
[Tue Jul 21 08:43:22.665314 2026] [security2:error] [pid 514479:tid 514631] [client 203.25.124.55:24939] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/languages/admin.php"] [unique_id "al9bWvzqsQqnLoCgUjhfSgAAARs"]
[Tue Jul 21 08:43:22.679409 2026] [security2:error] [pid 511108:tid 511198] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wmore1.php"] [unique_id "al9bWoTd5soprXwxAH385QAAWFk"]
[Tue Jul 21 08:43:22.795414 2026] [security2:error] [pid 511108:tid 511260] [client 20.197.192.193:2850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/pn.php"] [unique_id "al9bWoTd5soprXwxAH386gAAABY"]
[Tue Jul 21 08:43:22.886609 2026] [security2:error] [pid 511108:tid 511209] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/solo1.php"] [unique_id "al9bWoTd5soprXwxAH387AAAUmQ"]
[Tue Jul 21 08:43:23.111894 2026] [security2:error] [pid 511108:tid 511294] [client 20.151.10.161:56412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/199.php"] [unique_id "al9bW4Td5soprXwxAH389AAAADg"]
[Tue Jul 21 08:43:23.201607 2026] [security2:error] [pid 511108:tid 511189] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/cong.php"] [unique_id "al9bW4Td5soprXwxAH38-QAAClA"]
[Tue Jul 21 08:43:23.412634 2026] [security2:error] [pid 511108:tid 511347] [client 20.151.10.161:56393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/file52.php"] [unique_id "al9bW4Td5soprXwxAH38_gAAAG0"]
[Tue Jul 21 08:43:23.486164 2026] [security2:error] [pid 511108:tid 511149] [remote 45.117.83.212:59736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9bW4Td5soprXwxAH39AgAATig"]
[Tue Jul 21 08:43:23.486327 2026] [security2:error] [pid 511108:tid 511316] [client 45.117.83.212:59736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9bW4Td5soprXwxAH39AgAATig"]
[Tue Jul 21 08:43:23.568439 2026] [security2:error] [pid 514479:tid 514646] [client 212.32.76.66:60523] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/updates.php"] [unique_id "al9bW_zqsQqnLoCgUjhfUQAAASo"]
[Tue Jul 21 08:43:23.614356 2026] [security2:error] [pid 511108:tid 511131] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/public/css.php"] [unique_id "al9bW4Td5soprXwxAH39BAAAQhY"]
[Tue Jul 21 08:43:23.819926 2026] [security2:error] [pid 511108:tid 511112] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/output.php"] [unique_id "al9bW4Td5soprXwxAH39CwAAFgM"]
[Tue Jul 21 08:43:23.823736 2026] [security2:error] [pid 514479:tid 514654] [client 20.206.105.145:55793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9bW_zqsQqnLoCgUjhfVQAAATI"]
[Tue Jul 21 08:43:23.864839 2026] [security2:error] [pid 511108:tid 511277] [client 20.151.10.161:56390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/122.php"] [unique_id "al9bW4Td5soprXwxAH39DAAAACc"]
[Tue Jul 21 08:43:24.003400 2026] [security2:error] [pid 511108:tid 511240] [client 20.197.192.193:2819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wp-wpbak.php"] [unique_id "al9bXITd5soprXwxAH39EQAAAAI"]
[Tue Jul 21 08:43:24.036315 2026] [security2:error] [pid 511108:tid 511194] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-file-120.php"] [unique_id "al9bXITd5soprXwxAH39EgAAN1U"]
[Tue Jul 21 08:43:24.066670 2026] [security2:error] [pid 511108:tid 511344] [client 20.197.192.193:2852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/dr.php"] [unique_id "al9bXITd5soprXwxAH39EwAAAGo"]
[Tue Jul 21 08:43:24.068559 2026] [security2:error] [pid 511108:tid 511305] [client 212.32.76.12:60231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/spacer/"] [unique_id "al9bXITd5soprXwxAH39FAAAAEM"]
[Tue Jul 21 08:43:24.139954 2026] [security2:error] [pid 514479:tid 514662] [client 20.197.192.193:2753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/2x.php"] [unique_id "al9bXPzqsQqnLoCgUjhfVwAAATo"]
[Tue Jul 21 08:43:24.167104 2026] [security2:error] [pid 511108:tid 511267] [client 20.197.192.193:2839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/kq1.php"] [unique_id "al9bXITd5soprXwxAH39FwAAAB0"]
[Tue Jul 21 08:43:24.190746 2026] [security2:error] [pid 511108:tid 511219] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/special.php"] [unique_id "al9bXITd5soprXwxAH39GAAAcG4"]
[Tue Jul 21 08:43:24.226945 2026] [security2:error] [pid 514479:tid 514666] [client 20.197.192.193:2782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/zzz.php"] [unique_id "al9bXPzqsQqnLoCgUjhfWgAAAT4"]
[Tue Jul 21 08:43:24.241237 2026] [security2:error] [pid 514479:tid 514670] [client 20.197.192.193:2865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wicked.php"] [unique_id "al9bXPzqsQqnLoCgUjhfXAAAAUI"]
[Tue Jul 21 08:43:24.265191 2026] [security2:error] [pid 514479:tid 514667] [client 20.197.192.193:2873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/edit.php"] [unique_id "al9bXPzqsQqnLoCgUjhfXQAAAT8"]
[Tue Jul 21 08:43:24.295005 2026] [security2:error] [pid 514479:tid 514680] [client 20.197.192.193:2829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/kua.php"] [unique_id "al9bXPzqsQqnLoCgUjhfXgAAAUw"]
[Tue Jul 21 08:43:24.352011 2026] [security2:error] [pid 511108:tid 511179] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/as.php"] [unique_id "al9bXITd5soprXwxAH39HAAACUY"]
[Tue Jul 21 08:43:24.364897 2026] [security2:error] [pid 514479:tid 514682] [client 20.197.192.193:2754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/ez.php"] [unique_id "al9bXPzqsQqnLoCgUjhfXwAAAU4"]
[Tue Jul 21 08:43:24.423766 2026] [security2:error] [pid 511108:tid 511272] [client 20.197.192.193:2830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/fz.php"] [unique_id "al9bXITd5soprXwxAH39IQAAACI"]
[Tue Jul 21 08:43:24.495227 2026] [security2:error] [pid 511108:tid 511347] [client 20.151.10.161:30685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/green1.php"] [unique_id "al9bXITd5soprXwxAH39JQAAAG0"]
[Tue Jul 21 08:43:24.504913 2026] [security2:error] [pid 511108:tid 511231] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/cgi-bin/index.php"] [unique_id "al9bXITd5soprXwxAH39JgAAZHo"]
[Tue Jul 21 08:43:24.576088 2026] [security2:error] [pid 511108:tid 511252] [client 212.32.76.56:62235] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/colors/blue/"] [unique_id "al9bXITd5soprXwxAH39KAAAAA4"]
[Tue Jul 21 08:43:24.606398 2026] [security2:error] [pid 514479:tid 514694] [client 20.197.192.193:2822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/la.php"] [unique_id "al9bXPzqsQqnLoCgUjhfZAAAAVo"]
[Tue Jul 21 08:43:24.656991 2026] [security2:error] [pid 511108:tid 511190] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/w1px.php"] [unique_id "al9bXITd5soprXwxAH39LgAAf1E"]
[Tue Jul 21 08:43:24.728173 2026] [security2:error] [pid 514479:tid 514700] [client 20.197.192.193:2849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/nhvoanpl.php"] [unique_id "al9bXPzqsQqnLoCgUjhfZgAAAWA"]
[Tue Jul 21 08:43:24.754501 2026] [security2:error] [pid 511108:tid 511314] [client 20.197.192.193:54016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/inso.php"] [unique_id "al9bXITd5soprXwxAH39MQAAAEw"]
[Tue Jul 21 08:43:24.809434 2026] [security2:error] [pid 511108:tid 511125] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/yawa.php"] [unique_id "al9bXITd5soprXwxAH39NAAAIxA"]
[Tue Jul 21 08:43:24.829512 2026] [security2:error] [pid 511108:tid 511297] [client 20.151.10.161:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/biufile.php"] [unique_id "al9bXITd5soprXwxAH39NgAAADs"]
[Tue Jul 21 08:43:24.829686 2026] [security2:error] [pid 511108:tid 511361] [client 20.226.60.151:34872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/special.php"] [unique_id "al9bXITd5soprXwxAH39NwAAAHs"]
[Tue Jul 21 08:43:24.834792 2026] [security2:error] [pid 514479:tid 514513] [remote 209.97.182.179:51848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9bXPzqsQqnLoCgUjhfaAABWx0"]
[Tue Jul 21 08:43:24.835245 2026] [security2:error] [pid 511108:tid 511291] [client 20.197.192.193:2862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wpx.php"] [unique_id "al9bXITd5soprXwxAH39OAAAADU"]
[Tue Jul 21 08:43:24.891622 2026] [security2:error] [pid 514479:tid 514706] [client 20.197.192.193:2879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/berlin.php"] [unique_id "al9bXPzqsQqnLoCgUjhfaQAAAWY"]
[Tue Jul 21 08:43:24.961371 2026] [security2:error] [pid 511108:tid 511166] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/js.php"] [unique_id "al9bXITd5soprXwxAH39OgAAajk"]
[Tue Jul 21 08:43:24.991295 2026] [security2:error] [pid 511108:tid 511267] [client 20.197.192.193:2760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/billur.php"] [unique_id "al9bXITd5soprXwxAH39PAAAAB0"]
[Tue Jul 21 08:43:25.054999 2026] [security2:error] [pid 511108:tid 511292] [client 20.197.192.193:2780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/mimpi.php"] [unique_id "al9bXYTd5soprXwxAH39QAAAADY"]
[Tue Jul 21 08:43:25.087780 2026] [security2:error] [pid 511108:tid 511286] [client 195.49.128.211:52848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bXYTd5soprXwxAH39QQAAADA"]
[Tue Jul 21 08:43:25.087873 2026] [security2:error] [pid 511108:tid 511286] [client 195.49.128.211:52848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bXYTd5soprXwxAH39QQAAADA"]
[Tue Jul 21 08:43:25.155519 2026] [security2:error] [pid 511108:tid 511296] [client 20.197.192.193:2844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/dp.php"] [unique_id "al9bXYTd5soprXwxAH39QwAAADo"]
[Tue Jul 21 08:43:25.171560 2026] [security2:error] [pid 511108:tid 511294] [client 203.25.124.53:55565] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/certificates/chosen.php"] [unique_id "al9bXYTd5soprXwxAH39RAAAADg"]
[Tue Jul 21 08:43:25.188361 2026] [security2:error] [pid 511108:tid 511121] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/core.php"] [unique_id "al9bXYTd5soprXwxAH39RQAAZww"]
[Tue Jul 21 08:43:25.188931 2026] [security2:error] [pid 514479:tid 514714] [client 20.197.192.193:2859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/bootstrap.php"] [unique_id "al9bXfzqsQqnLoCgUjhfbAAAAW4"]
[Tue Jul 21 08:43:25.213894 2026] [security2:error] [pid 514479:tid 514713] [client 20.151.10.161:56345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wpconf.php"] [unique_id "al9bXfzqsQqnLoCgUjhfbQAAAW0"]
[Tue Jul 21 08:43:25.276500 2026] [security2:error] [pid 511108:tid 511247] [client 20.197.192.193:2870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wp-editor.php"] [unique_id "al9bXYTd5soprXwxAH39RgAAAAk"]
[Tue Jul 21 08:43:25.373756 2026] [security2:error] [pid 511108:tid 511217] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/19.php"] [unique_id "al9bXYTd5soprXwxAH39SgAAU2w"]
[Tue Jul 21 08:43:25.384356 2026] [security2:error] [pid 511108:tid 511260] [client 216.73.161.176:34709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9bXYTd5soprXwxAH39TgAAABY"]
[Tue Jul 21 08:43:25.385931 2026] [security2:error] [pid 511108:tid 511242] [client 216.73.161.167:56103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9bXYTd5soprXwxAH39SwAAAAQ"]
[Tue Jul 21 08:43:25.387960 2026] [security2:error] [pid 511108:tid 511307] [client 173.239.211.135:55085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.211.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9bXYTd5soprXwxAH39TAAAAEU"]
[Tue Jul 21 08:43:25.415974 2026] [security2:error] [pid 514479:tid 514721] [client 20.197.192.193:2816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/cro.php"] [unique_id "al9bXfzqsQqnLoCgUjhfcAAAAXU"]
[Tue Jul 21 08:43:25.441445 2026] [security2:error] [pid 514479:tid 514712] [client 202.179.75.202:51998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bXfzqsQqnLoCgUjhfcQAAAWw"]
[Tue Jul 21 08:43:25.441607 2026] [security2:error] [pid 514479:tid 514712] [client 202.179.75.202:51998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bXfzqsQqnLoCgUjhfcQAAAWw"]
[Tue Jul 21 08:43:25.466420 2026] [security2:error] [pid 511108:tid 511257] [client 20.197.192.193:2878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/cron-tab.php"] [unique_id "al9bXYTd5soprXwxAH39VgAAABM"]
[Tue Jul 21 08:43:25.474317 2026] [security2:error] [pid 511108:tid 511264] [client 212.32.76.66:61759] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/theme-compat/"] [unique_id "al9bXYTd5soprXwxAH39VwAAABo"]
[Tue Jul 21 08:43:25.529927 2026] [security2:error] [pid 514479:tid 514728] [client 20.206.105.145:55687] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al9bXfzqsQqnLoCgUjhfcgAAAXw"]
[Tue Jul 21 08:43:25.539212 2026] [security2:error] [pid 511108:tid 511349] [client 20.197.192.193:2869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/koiy.php"] [unique_id "al9bXYTd5soprXwxAH39WgAAAG8"]
[Tue Jul 21 08:43:25.545577 2026] [security2:error] [pid 511108:tid 511203] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/inc.php"] [unique_id "al9bXYTd5soprXwxAH39WwAAGF4"]
[Tue Jul 21 08:43:25.616694 2026] [security2:error] [pid 514479:tid 514737] [client 20.197.192.193:2773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/hp2.php"] [unique_id "al9bXfzqsQqnLoCgUjhfdQAAAYU"]
[Tue Jul 21 08:43:25.709499 2026] [security2:error] [pid 511108:tid 511133] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-ppoxua4.php"] [unique_id "al9bXYTd5soprXwxAH39XQAAexg"]
[Tue Jul 21 08:43:25.729549 2026] [security2:error] [pid 511108:tid 511240] [client 20.151.10.161:56430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/mosty.php"] [unique_id "al9bXYTd5soprXwxAH39XgAAAAI"]
[Tue Jul 21 08:43:25.772173 2026] [security2:error] [pid 511108:tid 511352] [client 20.197.192.193:2836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/hp3.php"] [unique_id "al9bXYTd5soprXwxAH39XwAAAHI"]
[Tue Jul 21 08:43:25.860754 2026] [security2:error] [pid 511108:tid 511201] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-u3nxbvx.php"] [unique_id "al9bXYTd5soprXwxAH39YwAAAFw"]
[Tue Jul 21 08:43:25.904988 2026] [security2:error] [pid 514479:tid 514679] [client 20.197.192.193:2833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/aa1.php"] [unique_id "al9bXfzqsQqnLoCgUjhfeQAAAUs"]
[Tue Jul 21 08:43:25.928394 2026] [security2:error] [pid 514479:tid 514623] [client 20.197.192.193:2788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/acew67.php"] [unique_id "al9bXfzqsQqnLoCgUjhfewAAARM"]
[Tue Jul 21 08:43:26.044311 2026] [security2:error] [pid 511108:tid 511111] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/ss.php"] [unique_id "al9bXoTd5soprXwxAH39agAAMAI"]
[Tue Jul 21 08:43:26.095170 2026] [security2:error] [pid 511108:tid 511311] [client 20.197.192.193:2789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/bscclapb.php"] [unique_id "al9bXoTd5soprXwxAH39awAAAEk"]
[Tue Jul 21 08:43:26.199302 2026] [security2:error] [pid 511108:tid 511109] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/min.php"] [unique_id "al9bXoTd5soprXwxAH39bAAAdQA"]
[Tue Jul 21 08:43:26.287325 2026] [security2:error] [pid 511108:tid 511297] [client 59.95.197.55:51513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bXoTd5soprXwxAH39bQAAADs"]
[Tue Jul 21 08:43:26.287487 2026] [security2:error] [pid 511108:tid 511297] [client 59.95.197.55:51513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bXoTd5soprXwxAH39bQAAADs"]
[Tue Jul 21 08:43:26.333765 2026] [security2:error] [pid 514479:tid 514520] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bXvzqsQqnLoCgUjhfgwABEiQ"]
[Tue Jul 21 08:43:26.334037 2026] [security2:error] [pid 514479:tid 514622] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bXvzqsQqnLoCgUjhfgwABEiQ"]
[Tue Jul 21 08:43:26.354067 2026] [security2:error] [pid 511108:tid 511163] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9bXoTd5soprXwxAH39cQAAIjY"]
[Tue Jul 21 08:43:26.379529 2026] [security2:error] [pid 511108:tid 511354] [client 20.197.192.193:2371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/else1.php"] [unique_id "al9bXoTd5soprXwxAH39cgAAAHQ"]
[Tue Jul 21 08:43:26.381106 2026] [security2:error] [pid 514479:tid 514633] [client 203.25.124.184:33373] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/"] [unique_id "al9bXvzqsQqnLoCgUjhfhQAAAR0"]
[Tue Jul 21 08:43:26.412845 2026] [security2:error] [pid 511108:tid 511351] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bXYTd5soprXwxAH39ZgAAAHE"]
[Tue Jul 21 08:43:26.472389 2026] [security2:error] [pid 511108:tid 511346] [client 203.25.124.64:46889] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/shortcode/"] [unique_id "al9bXoTd5soprXwxAH39dgAAAGw"]
[Tue Jul 21 08:43:26.518482 2026] [security2:error] [pid 511108:tid 511182] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/autoload_classmap.php"] [unique_id "al9bXoTd5soprXwxAH39eQAAZEk"]
[Tue Jul 21 08:43:26.661723 2026] [security2:error] [pid 511108:tid 511269] [client 117.213.202.34:50877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bXoTd5soprXwxAH39fgAAAB8"]
[Tue Jul 21 08:43:26.661867 2026] [security2:error] [pid 511108:tid 511269] [client 117.213.202.34:50877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bXoTd5soprXwxAH39fgAAAB8"]
[Tue Jul 21 08:43:26.716006 2026] [security2:error] [pid 514479:tid 514656] [client 20.197.192.193:2863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/tkikikoko.php"] [unique_id "al9bXvzqsQqnLoCgUjhfhgAAATQ"]
[Tue Jul 21 08:43:26.774758 2026] [security2:error] [pid 511108:tid 511227] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-link-zorm.php"] [unique_id "al9bXoTd5soprXwxAH39gAAAGHY"]
[Tue Jul 21 08:43:26.790825 2026] [security2:error] [pid 514479:tid 514661] [client 20.151.10.161:56374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/dejavu.php"] [unique_id "al9bXvzqsQqnLoCgUjhfhwAAATk"]
[Tue Jul 21 08:43:26.960457 2026] [security2:error] [pid 514479:tid 514634] [client 152.59.181.104:52587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bXvzqsQqnLoCgUjhfiQAAAR4"]
[Tue Jul 21 08:43:26.960569 2026] [security2:error] [pid 514479:tid 514634] [client 152.59.181.104:52587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bXvzqsQqnLoCgUjhfiQAAAR4"]
[Tue Jul 21 08:43:26.961721 2026] [security2:error] [pid 511108:tid 511220] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-link-szoppm.php"] [unique_id "al9bXoTd5soprXwxAH39iQAAe28"]
[Tue Jul 21 08:43:27.010261 2026] [security2:error] [pid 514479:tid 514671] [client 198.44.157.34:40674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9bX_zqsQqnLoCgUjhfjQAAAUM"]
[Tue Jul 21 08:43:27.010401 2026] [security2:error] [pid 514479:tid 514671] [client 198.44.157.34:40674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9bX_zqsQqnLoCgUjhfjQAAAUM"]
[Tue Jul 21 08:43:27.114287 2026] [security2:error] [pid 511108:tid 511175] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/albin.php"] [unique_id "al9bX4Td5soprXwxAH39jwAAQ0I"]
[Tue Jul 21 08:43:27.178894 2026] [security2:error] [pid 514479:tid 514647] [client 122.176.100.127:52447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bX_zqsQqnLoCgUjhflgAAASs"]
[Tue Jul 21 08:43:27.179087 2026] [security2:error] [pid 514479:tid 514647] [client 122.176.100.127:52447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bX_zqsQqnLoCgUjhflgAAASs"]
[Tue Jul 21 08:43:27.276327 2026] [security2:error] [pid 511108:tid 511154] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/cilus.php"] [unique_id "al9bX4Td5soprXwxAH39kgAAJi0"]
[Tue Jul 21 08:43:27.415149 2026] [security2:error] [pid 514479:tid 514696] [client 20.206.105.145:55796] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-admin/js/"] [unique_id "al9bX_zqsQqnLoCgUjhfmAAAAVw"]
[Tue Jul 21 08:43:27.439625 2026] [security2:error] [pid 511108:tid 511115] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/gptsh.php"] [unique_id "al9bX4Td5soprXwxAH39lgAAOAY"]
[Tue Jul 21 08:43:27.468183 2026] [security2:error] [pid 514479:tid 514703] [client 212.32.76.66:40173] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/languages/plugins/"] [unique_id "al9bX_zqsQqnLoCgUjhfmgAAAWM"]
[Tue Jul 21 08:43:27.496655 2026] [core:alert] [pid 514479:tid 514684] [client 173.252.82.25:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:43:27.621942 2026] [security2:error] [pid 511108:tid 511155] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/rithin.php"] [unique_id "al9bX4Td5soprXwxAH39nQAADC4"]
[Tue Jul 21 08:43:27.677019 2026] [security2:error] [pid 511108:tid 511360] [client 20.197.192.193:2790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wp-Blogs.php"] [unique_id "al9bX4Td5soprXwxAH39oAAAAHo"]
[Tue Jul 21 08:43:27.772698 2026] [security2:error] [pid 511108:tid 511211] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/fffm.php"] [unique_id "al9bX4Td5soprXwxAH39owAAC2Y"]
[Tue Jul 21 08:43:27.836254 2026] [security2:error] [pid 511108:tid 511323] [client 20.226.60.151:58513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/as.php"] [unique_id "al9bX4Td5soprXwxAH39pQAAAFU"]
[Tue Jul 21 08:43:27.992686 2026] [security2:error] [pid 511108:tid 511234] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/dfre.php"] [unique_id "al9bX4Td5soprXwxAH39qgAAGn0"]
[Tue Jul 21 08:43:28.121281 2026] [security2:error] [pid 511108:tid 511329] [client 20.14.74.238:45116] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.70"] [uri "/index.cgi"] [unique_id "al9bYITd5soprXwxAH39rQAAAFs"]
[Tue Jul 21 08:43:28.144037 2026] [security2:error] [pid 511108:tid 511215] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/wp-happy.php"] [unique_id "al9bYITd5soprXwxAH39rgAAH2o"]
[Tue Jul 21 08:43:28.204443 2026] [security2:error] [pid 511108:tid 511306] [client 41.89.234.2:55274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bYITd5soprXwxAH39sQAAAEQ"]
[Tue Jul 21 08:43:28.204639 2026] [security2:error] [pid 511108:tid 511306] [client 41.89.234.2:55274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bYITd5soprXwxAH39sQAAAEQ"]
[Tue Jul 21 08:43:28.285142 2026] [security2:error] [pid 511108:tid 511359] [client 20.206.105.145:55720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9bYITd5soprXwxAH39swAAAHk"]
[Tue Jul 21 08:43:28.295615 2026] [security2:error] [pid 511108:tid 511216] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/fpr4.php"] [unique_id "al9bYITd5soprXwxAH39tAAAKWs"]
[Tue Jul 21 08:43:28.348860 2026] [proxy:error] [pid 511108:tid 511185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:43:28.348964 2026] [proxy_http:error] [pid 511108:tid 511185] [remote 205.210.31.16:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.nerdshoppe.com.br/
[Tue Jul 21 08:43:28.351253 2026] [proxy:error] [pid 511108:tid 511185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:43:28.351323 2026] [proxy_http:error] [pid 511108:tid 511185] [remote 205.210.31.16:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.nerdshoppe.com.br/
[Tue Jul 21 08:43:28.367941 2026] [security2:error] [pid 511108:tid 511252] [client 212.32.76.11:31635] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/edit-wolf.php"] [unique_id "al9bYITd5soprXwxAH39twAAAA4"]
[Tue Jul 21 08:43:28.436797 2026] [security2:error] [pid 511108:tid 511347] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bYITd5soprXwxAH39uQAAbR8"]
[Tue Jul 21 08:43:28.447218 2026] [security2:error] [pid 511108:tid 511212] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/file88.php"] [unique_id "al9bYITd5soprXwxAH39vAAAGWc"]
[Tue Jul 21 08:43:28.461705 2026] [security2:error] [pid 511108:tid 511352] [client 20.151.10.161:56370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/aaf.php"] [unique_id "al9bYITd5soprXwxAH39vgAAAHI"]
[Tue Jul 21 08:43:28.577254 2026] [security2:error] [pid 511108:tid 511350] [client 203.25.124.188:53907] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/ioxi-o.php"] [unique_id "al9bYITd5soprXwxAH39wAAAAHA"]
[Tue Jul 21 08:43:28.598447 2026] [security2:error] [pid 511108:tid 511161] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/ccc.php"] [unique_id "al9bYITd5soprXwxAH39wgAABzQ"]
[Tue Jul 21 08:43:28.600889 2026] [security2:error] [pid 514479:tid 514631] [client 91.92.47.81:35218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "englobehair.com.br"] [uri "/.env"] [unique_id "al9bYPzqsQqnLoCgUjhfsAAAARs"], referer: http://englobehair.com.br/
[Tue Jul 21 08:43:28.602888 2026] [security2:error] [pid 514479:tid 514733] [client 91.92.47.81:35228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/info.php"] [unique_id "al9bYPzqsQqnLoCgUjhfsQAAAYE"], referer: http://englobehair.com.br/
[Tue Jul 21 08:43:28.603944 2026] [security2:error] [pid 514479:tid 514632] [client 91.92.47.81:35196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/wp-config.php"] [unique_id "al9bYPzqsQqnLoCgUjhfswAAARw"], referer: http://englobehair.com.br/
[Tue Jul 21 08:43:28.667401 2026] [core:alert] [pid 511108:tid 511341] [client 57.141.18.109:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:43:28.750358 2026] [security2:error] [pid 511108:tid 511194] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/777.php"] [unique_id "al9bYITd5soprXwxAH39ygAAWlU"]
[Tue Jul 21 08:43:28.815983 2026] [security2:error] [pid 514479:tid 514642] [client 91.92.47.81:35218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/phpinfo.php"] [unique_id "al9bYPzqsQqnLoCgUjhfuQAAASY"], referer: http://englobehair.com.br/
[Tue Jul 21 08:43:28.855859 2026] [security2:error] [pid 511108:tid 511338] [client 168.167.81.163:65051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bYITd5soprXwxAH39ywAAAGQ"]
[Tue Jul 21 08:43:28.855962 2026] [security2:error] [pid 511108:tid 511338] [client 168.167.81.163:65051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bYITd5soprXwxAH39ywAAAGQ"]
[Tue Jul 21 08:43:28.903167 2026] [security2:error] [pid 511108:tid 511219] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/for.php"] [unique_id "al9bYITd5soprXwxAH39zAAAF24"]
[Tue Jul 21 08:43:29.115536 2026] [security2:error] [pid 511108:tid 511210] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/ssla.php"] [unique_id "al9bYYTd5soprXwxAH390wAAY2U"]
[Tue Jul 21 08:43:29.116833 2026] [security2:error] [pid 514479:tid 514650] [client 141.11.107.74:64402] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "clinicaleonazevedo.com.br"] [uri "/"] [unique_id "al9bYfzqsQqnLoCgUjhfugAAAS4"]
[Tue Jul 21 08:43:29.152893 2026] [security2:error] [pid 511108:tid 511179] [remote 94.23.188.209:46584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "beautyline.com.br"] [uri "/robots.txt"] [unique_id "al9bYYTd5soprXwxAH391QAAcUY"]
[Tue Jul 21 08:43:29.153065 2026] [security2:error] [pid 511108:tid 511351] [client 94.23.188.209:46584] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "beautyline.com.br"] [uri "/robots.txt"] [unique_id "al9bYYTd5soprXwxAH391QAAcUY"]
[Tue Jul 21 08:43:29.222297 2026] [security2:error] [pid 511108:tid 511329] [client 20.197.192.193:2876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wp-css.php"] [unique_id "al9bYYTd5soprXwxAH392QAAAFs"]
[Tue Jul 21 08:43:29.281908 2026] [security2:error] [pid 511108:tid 511231] [remote 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.assumaocontrole.com"] [uri "/zc-131.php"] [unique_id "al9bYYTd5soprXwxAH392gAAf3o"]
[Tue Jul 21 08:43:29.317435 2026] [security2:error] [pid 514479:tid 514627] [client 113.22.144.139:51020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bYfzqsQqnLoCgUjhfvAAAARc"]
[Tue Jul 21 08:43:29.317674 2026] [security2:error] [pid 514479:tid 514627] [client 113.22.144.139:51020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bYfzqsQqnLoCgUjhfvAAAARc"]
[Tue Jul 21 08:43:29.466062 2026] [security2:error] [pid 511108:tid 511240] [client 212.32.76.13:49307] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/2021/10/"] [unique_id "al9bYYTd5soprXwxAH395AAAAAI"]
[Tue Jul 21 08:43:29.603837 2026] [security2:error] [pid 514479:tid 514616] [client 91.92.47.81:35208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/config.php"] [unique_id "al9bYPzqsQqnLoCgUjhfsgAAAQw"], referer: http://englobehair.com.br/
[Tue Jul 21 08:43:29.691346 2026] [security2:error] [pid 514479:tid 514643] [client 20.206.105.145:55692] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wordpress/wp-admin/maint/"] [unique_id "al9bYfzqsQqnLoCgUjhfxQAAASc"]
[Tue Jul 21 08:43:29.699825 2026] [security2:error] [pid 514479:tid 514667] [client 20.197.192.193:2812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/wp-explorer.php"] [unique_id "al9bYfzqsQqnLoCgUjhfxgAAAT8"]
[Tue Jul 21 08:43:29.802706 2026] [security2:error] [pid 511108:tid 511225] [remote 191.101.50.240:53994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.50.101.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9bYYTd5soprXwxAH398gAAGXQ"]
[Tue Jul 21 08:43:29.843989 2026] [security2:error] [pid 514479:tid 514696] [client 198.44.157.34:41684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9bYfzqsQqnLoCgUjhfygAAAVw"]
[Tue Jul 21 08:43:29.844125 2026] [security2:error] [pid 514479:tid 514696] [client 198.44.157.34:41684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9bYfzqsQqnLoCgUjhfygAAAVw"]
[Tue Jul 21 08:43:29.987151 2026] [security2:error] [pid 511108:tid 511276] [client 212.32.76.56:29621] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/IXR/"] [unique_id "al9bYYTd5soprXwxAH398wAAACY"]
[Tue Jul 21 08:43:30.005509 2026] [security2:error] [pid 514479:tid 514537] [remote 85.122.114.146:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.114.122.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.volyo.com.br"] [uri "/wp-login.php"] [unique_id "al9bYfzqsQqnLoCgUjhfzQABTzU"]
[Tue Jul 21 08:43:30.123738 2026] [security2:error] [pid 511108:tid 511292] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bYYTd5soprXwxAH396wAAADY"]
[Tue Jul 21 08:43:30.312099 2026] [security2:error] [pid 511108:tid 511329] [client 20.226.60.151:58596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/cgi-bin/index.php"] [unique_id "al9bYoTd5soprXwxAH3-AAAAAFs"]
[Tue Jul 21 08:43:30.334060 2026] [security2:error] [pid 511108:tid 511343] [client 20.197.192.193:2781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/akismet.php"] [unique_id "al9bYoTd5soprXwxAH3-AQAAAGk"]
[Tue Jul 21 08:43:30.366604 2026] [security2:error] [pid 511108:tid 511333] [client 203.25.124.53:55275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/widgets/admin.php"] [unique_id "al9bYoTd5soprXwxAH3-AgAAAF8"]
[Tue Jul 21 08:43:30.642326 2026] [security2:error] [pid 514479:tid 514708] [client 20.197.192.193:2835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/ace2.php"] [unique_id "al9bYvzqsQqnLoCgUjhf0wAAAWg"]
[Tue Jul 21 08:43:30.694006 2026] [security2:error] [pid 511108:tid 511172] [remote 142.44.225.12:41904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "beautyline.com.br"] [uri "/"] [unique_id "al9bYoTd5soprXwxAH3-DAAAUj8"]
[Tue Jul 21 08:43:30.694210 2026] [security2:error] [pid 511108:tid 511320] [client 142.44.225.12:41904] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "beautyline.com.br"] [uri "/"] [unique_id "al9bYoTd5soprXwxAH3-DAAAUj8"]
[Tue Jul 21 08:43:30.720655 2026] [security2:error] [pid 514479:tid 514691] [client 5.31.193.106:1846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bYvzqsQqnLoCgUjhf1AAAAVc"]
[Tue Jul 21 08:43:30.720830 2026] [security2:error] [pid 514479:tid 514691] [client 5.31.193.106:1846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bYvzqsQqnLoCgUjhf1AAAAVc"]
[Tue Jul 21 08:43:30.759079 2026] [security2:error] [pid 514479:tid 514730] [client 20.197.192.193:2778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bestdealsvalmir.com"] [uri "/ms.php"] [unique_id "al9bYvzqsQqnLoCgUjhf1gAAAX4"]
[Tue Jul 21 08:43:30.856550 2026] [security2:error] [pid 511108:tid 511351] [client 5.38.115.39:64369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bYoTd5soprXwxAH3-EQAAAHE"]
[Tue Jul 21 08:43:30.856692 2026] [security2:error] [pid 511108:tid 511351] [client 5.38.115.39:64369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bYoTd5soprXwxAH3-EQAAAHE"]
[Tue Jul 21 08:43:31.349747 2026] [security2:error] [pid 511108:tid 511254] [client 49.144.66.253:32562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bY4Td5soprXwxAH3-IgAAABA"]
[Tue Jul 21 08:43:31.349913 2026] [security2:error] [pid 511108:tid 511254] [client 49.144.66.253:32562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bY4Td5soprXwxAH3-IgAAABA"]
[Tue Jul 21 08:43:31.460969 2026] [security2:error] [pid 514479:tid 514626] [client 203.25.124.37:29765] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/tinymce/themes/"] [unique_id "al9bY_zqsQqnLoCgUjhf3AAAARY"]
[Tue Jul 21 08:43:31.672085 2026] [security2:error] [pid 511108:tid 511286] [client 212.32.76.59:43027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/404.php"] [unique_id "al9bY4Td5soprXwxAH3-KwAAADA"]
[Tue Jul 21 08:43:31.931084 2026] [security2:error] [pid 514479:tid 514717] [client 20.151.10.161:30660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/term.php"] [unique_id "al9bY_zqsQqnLoCgUjhf8AAAAXE"]
[Tue Jul 21 08:43:31.953430 2026] [security2:error] [pid 514479:tid 514739] [client 185.198.240.89:44567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "voweltravel.com.br"] [uri "/wp-login.php"] [unique_id "al9bY_zqsQqnLoCgUjhf8QAAAYc"]
[Tue Jul 21 08:43:32.156283 2026] [security2:error] [pid 511108:tid 511114] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bZITd5soprXwxAH3-OAAAdQU"]
[Tue Jul 21 08:43:32.156376 2026] [security2:error] [pid 511108:tid 511355] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bZITd5soprXwxAH3-OAAAdQU"]
[Tue Jul 21 08:43:32.445097 2026] [security2:error] [pid 514479:tid 514681] [client 20.226.60.151:34825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/w1px.php"] [unique_id "al9bZPzqsQqnLoCgUjhgWwAAAU0"]
[Tue Jul 21 08:43:32.566252 2026] [security2:error] [pid 514479:tid 514704] [client 203.25.124.202:25415] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/mah.php"] [unique_id "al9bZPzqsQqnLoCgUjhgYAAAAWQ"]
[Tue Jul 21 08:43:32.664737 2026] [security2:error] [pid 514479:tid 514709] [client 212.32.76.7:54423] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/social-link/"] [unique_id "al9bZPzqsQqnLoCgUjhgZgAAAWk"]
[Tue Jul 21 08:43:32.933655 2026] [security2:error] [pid 514479:tid 514648] [client 213.152.162.15:52090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9bZPzqsQqnLoCgUjhgagAAASw"]
[Tue Jul 21 08:43:32.933755 2026] [security2:error] [pid 514479:tid 514648] [client 213.152.162.15:52090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9bZPzqsQqnLoCgUjhgagAAASw"]
[Tue Jul 21 08:43:33.004937 2026] [security2:error] [pid 514479:tid 514700] [client 195.49.128.211:61660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bZfzqsQqnLoCgUjhgbQAAAWA"]
[Tue Jul 21 08:43:33.005099 2026] [security2:error] [pid 514479:tid 514700] [client 195.49.128.211:61660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bZfzqsQqnLoCgUjhgbQAAAWA"]
[Tue Jul 21 08:43:33.093628 2026] [security2:error] [pid 514479:tid 514552] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bZfzqsQqnLoCgUjhgbgABLUM"]
[Tue Jul 21 08:43:33.093774 2026] [security2:error] [pid 514479:tid 514649] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bZfzqsQqnLoCgUjhgbgABLUM"]
[Tue Jul 21 08:43:33.156399 2026] [security2:error] [pid 514479:tid 514682] [client 103.59.206.240:31086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bZfzqsQqnLoCgUjhgcgAAAU4"]
[Tue Jul 21 08:43:33.156504 2026] [security2:error] [pid 514479:tid 514682] [client 103.59.206.240:31086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bZfzqsQqnLoCgUjhgcgAAAU4"]
[Tue Jul 21 08:43:33.323782 2026] [security2:error] [pid 514479:tid 514691] [client 20.206.105.145:55705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/like.php"] [unique_id "al9bZfzqsQqnLoCgUjhgdAAAAVc"]
[Tue Jul 21 08:43:33.664107 2026] [security2:error] [pid 511108:tid 511300] [client 203.25.124.58:62949] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-good.php"] [unique_id "al9bZYTd5soprXwxAH3-VwAAAD4"]
[Tue Jul 21 08:43:33.673996 2026] [security2:error] [pid 511108:tid 511260] [client 212.32.76.55:25245] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/"] [unique_id "al9bZYTd5soprXwxAH3-WAAAABY"]
[Tue Jul 21 08:43:33.958348 2026] [security2:error] [pid 511108:tid 511346] [client 198.44.157.34:59514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9bZYTd5soprXwxAH3-WwAAAGw"]
[Tue Jul 21 08:43:33.958449 2026] [security2:error] [pid 511108:tid 511346] [client 198.44.157.34:59514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9bZYTd5soprXwxAH3-WwAAAGw"]
[Tue Jul 21 08:43:33.995775 2026] [security2:error] [pid 511108:tid 511305] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bZYTd5soprXwxAH3-UwAAAEM"]
[Tue Jul 21 08:43:34.034803 2026] [security2:error] [pid 511108:tid 511349] [client 20.151.10.161:30696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/ha.php"] [unique_id "al9bZoTd5soprXwxAH3-XwAAAG8"]
[Tue Jul 21 08:43:34.133209 2026] [security2:error] [pid 511108:tid 511259] [client 20.206.105.145:55785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/.well-known/about.php"] [unique_id "al9bZoTd5soprXwxAH3-ZAAAABU"]
[Tue Jul 21 08:43:34.652704 2026] [security2:error] [pid 514479:tid 514637] [client 20.197.192.193:27136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9bZvzqsQqnLoCgUjhghQAAASE"]
[Tue Jul 21 08:43:34.850788 2026] [security2:error] [pid 514479:tid 514625] [client 64.42.179.43:50616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bZvzqsQqnLoCgUjhgigAAARU"]
[Tue Jul 21 08:43:34.850932 2026] [security2:error] [pid 514479:tid 514625] [client 64.42.179.43:50616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bZvzqsQqnLoCgUjhgigAAARU"]
[Tue Jul 21 08:43:34.869365 2026] [security2:error] [pid 514479:tid 514656] [client 203.25.124.73:50083] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/elementor/css/"] [unique_id "al9bZvzqsQqnLoCgUjhgiwAAATQ"]
[Tue Jul 21 08:43:34.874074 2026] [security2:error] [pid 514479:tid 514627] [client 203.25.124.198:39239] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp.php"] [unique_id "al9bZvzqsQqnLoCgUjhgjAAAARc"]
[Tue Jul 21 08:43:35.174685 2026] [security2:error] [pid 514479:tid 514643] [client 20.151.10.161:56346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/hur.php"] [unique_id "al9bZ_zqsQqnLoCgUjhgkQAAASc"]
[Tue Jul 21 08:43:35.353340 2026] [security2:error] [pid 511108:tid 511184] [remote 103.187.169.251:44014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "health-24.shop"] [uri "/wp-login.php"] [unique_id "al9bZ4Td5soprXwxAH3-hAAACUs"]
[Tue Jul 21 08:43:35.422878 2026] [security2:error] [pid 511108:tid 511312] [client 20.206.105.145:55754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9bZ4Td5soprXwxAH3-hgAAAEo"]
[Tue Jul 21 08:43:35.559916 2026] [security2:error] [pid 511108:tid 511273] [client 20.226.60.151:58568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/yawa.php"] [unique_id "al9bZ4Td5soprXwxAH3-iQAAACM"]
[Tue Jul 21 08:43:35.678395 2026] [security2:error] [pid 514479:tid 514617] [client 195.49.128.211:53449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bZ_zqsQqnLoCgUjhgmQAAAQ0"]
[Tue Jul 21 08:43:35.678524 2026] [security2:error] [pid 514479:tid 514617] [client 195.49.128.211:53449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bZ_zqsQqnLoCgUjhgmQAAAQ0"]
[Tue Jul 21 08:43:35.777077 2026] [security2:error] [pid 514479:tid 514693] [client 203.25.124.199:49503] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/hello-plus/classes/ehp-sarang.php"] [unique_id "al9bZ_zqsQqnLoCgUjhgnAAAAVk"]
[Tue Jul 21 08:43:35.839332 2026] [security2:error] [pid 511108:tid 511332] [client 20.151.10.161:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/h02ugyh.php"] [unique_id "al9bZ4Td5soprXwxAH3-kAAAAF4"]
[Tue Jul 21 08:43:35.862257 2026] [security2:error] [pid 511108:tid 511356] [client 203.25.124.32:58609] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/config.php"] [unique_id "al9bZ4Td5soprXwxAH3-kQAAAHY"]
[Tue Jul 21 08:43:36.241126 2026] [security2:error] [pid 511108:tid 511336] [client 202.179.75.202:45852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9baITd5soprXwxAH3-nQAAAGI"]
[Tue Jul 21 08:43:36.241264 2026] [security2:error] [pid 511108:tid 511336] [client 202.179.75.202:45852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9baITd5soprXwxAH3-nQAAAGI"]
[Tue Jul 21 08:43:36.318899 2026] [security2:error] [pid 511108:tid 511222] [remote 203.134.193.134:12664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.193.134.203.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9baITd5soprXwxAH3-ogAAa3E"]
[Tue Jul 21 08:43:36.387607 2026] [security2:error] [pid 514479:tid 514730] [client 195.206.105.227:49624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9baPzqsQqnLoCgUjhgpAAAAX4"]
[Tue Jul 21 08:43:36.387742 2026] [security2:error] [pid 514479:tid 514730] [client 195.206.105.227:49624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9baPzqsQqnLoCgUjhgpAAAAX4"]
[Tue Jul 21 08:43:36.604917 2026] [security2:error] [pid 514479:tid 514731] [client 20.206.105.145:55777] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-admin/css/"] [unique_id "al9baPzqsQqnLoCgUjhgpwAAAX8"]
[Tue Jul 21 08:43:36.640212 2026] [security2:error] [pid 514479:tid 514738] [client 20.151.10.161:56326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/seiso.php"] [unique_id "al9baPzqsQqnLoCgUjhgqAAAAYY"]
[Tue Jul 21 08:43:36.859094 2026] [security2:error] [pid 511108:tid 511310] [client 203.25.124.65:42059] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "al9baITd5soprXwxAH3-sgAAAEg"]
[Tue Jul 21 08:43:36.861913 2026] [security2:error] [pid 511108:tid 511325] [client 59.95.197.55:51984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9baITd5soprXwxAH3-swAAAFc"]
[Tue Jul 21 08:43:36.862630 2026] [security2:error] [pid 511108:tid 511325] [client 59.95.197.55:51984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9baITd5soprXwxAH3-swAAAFc"]
[Tue Jul 21 08:43:36.875775 2026] [security2:error] [pid 511108:tid 511247] [client 203.25.124.180:49681] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwentyone/content-index.php"] [unique_id "al9baITd5soprXwxAH3-tAAAAAk"]
[Tue Jul 21 08:43:37.099242 2026] [security2:error] [pid 511108:tid 511279] [client 20.151.10.161:30711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/155.php"] [unique_id "al9baYTd5soprXwxAH3-twAAACk"]
[Tue Jul 21 08:43:37.155935 2026] [security2:error] [pid 514479:tid 514733] [client 20.226.60.151:58563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/js.php"] [unique_id "al9bafzqsQqnLoCgUjhgrAAAAYE"]
[Tue Jul 21 08:43:37.301947 2026] [security2:error] [pid 514479:tid 514579] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bafzqsQqnLoCgUjhgrwABGF4"]
[Tue Jul 21 08:43:37.302181 2026] [security2:error] [pid 514479:tid 514628] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bafzqsQqnLoCgUjhgrwABGF4"]
[Tue Jul 21 08:43:37.393556 2026] [security2:error] [pid 514479:tid 514662] [client 20.151.10.161:30674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/ppp.php"] [unique_id "al9bafzqsQqnLoCgUjhgsgAAATo"]
[Tue Jul 21 08:43:37.432289 2026] [security2:error] [pid 514479:tid 514728] [client 117.213.202.34:51480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bafzqsQqnLoCgUjhgswAAAXw"]
[Tue Jul 21 08:43:37.432486 2026] [security2:error] [pid 514479:tid 514728] [client 117.213.202.34:51480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bafzqsQqnLoCgUjhgswAAAXw"]
[Tue Jul 21 08:43:37.676452 2026] [security2:error] [pid 514479:tid 514672] [client 203.25.124.209:32841] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/admin.php"] [unique_id "al9bafzqsQqnLoCgUjhgtgAAAUQ"]
[Tue Jul 21 08:43:37.679896 2026] [security2:error] [pid 514479:tid 514626] [client 122.176.100.127:52960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bafzqsQqnLoCgUjhgtwAAARY"]
[Tue Jul 21 08:43:37.680056 2026] [security2:error] [pid 514479:tid 514626] [client 122.176.100.127:52960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bafzqsQqnLoCgUjhgtwAAARY"]
[Tue Jul 21 08:43:37.739298 2026] [security2:error] [pid 511108:tid 511268] [client 152.59.181.104:53078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9baYTd5soprXwxAH3-yQAAAB4"]
[Tue Jul 21 08:43:37.739475 2026] [security2:error] [pid 511108:tid 511268] [client 152.59.181.104:53078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9baYTd5soprXwxAH3-yQAAAB4"]
[Tue Jul 21 08:43:37.810398 2026] [security2:error] [pid 514479:tid 514681] [client 20.151.10.161:56436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/201.php"] [unique_id "al9bafzqsQqnLoCgUjhguwAAAU0"]
[Tue Jul 21 08:43:38.157268 2026] [security2:error] [pid 511108:tid 511277] [client 20.151.10.161:30625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/ops.php"] [unique_id "al9baoTd5soprXwxAH3-0wAAACc"]
[Tue Jul 21 08:43:38.180195 2026] [security2:error] [pid 514479:tid 514704] [client 45.227.253.15:58526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.253.227.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "precisosolucao.com.br"] [uri "/index.php/jk"] [unique_id "al9bavzqsQqnLoCgUjhgvQAAAWQ"]
[Tue Jul 21 08:43:38.196931 2026] [security2:error] [pid 511108:tid 511307] [client 20.206.105.145:55759] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al9baoTd5soprXwxAH3-1wAAAEU"]
[Tue Jul 21 08:43:38.485130 2026] [security2:error] [pid 511108:tid 511286] [client 20.151.10.161:56359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/ingfo.php"] [unique_id "al9baoTd5soprXwxAH3-4AAAADA"]
[Tue Jul 21 08:43:38.649729 2026] [security2:error] [pid 511108:tid 511306] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9baoTd5soprXwxAH3-0gAAAEQ"]
[Tue Jul 21 08:43:38.698229 2026] [security2:error] [pid 511108:tid 511320] [client 20.226.60.151:58501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/core.php"] [unique_id "al9baoTd5soprXwxAH3-4gAAAFI"]
[Tue Jul 21 08:43:38.719362 2026] [security2:error] [pid 514479:tid 514620] [client 173.252.95.4:52820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bavzqsQqnLoCgUjhgxAAAARA"]
[Tue Jul 21 08:43:38.769099 2026] [security2:error] [pid 511108:tid 511300] [client 203.25.124.11:20563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/404.php"] [unique_id "al9baoTd5soprXwxAH3-5gAAAD4"]
[Tue Jul 21 08:43:38.817962 2026] [security2:error] [pid 514479:tid 514718] [client 20.151.10.161:30681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/error_log.php"] [unique_id "al9bavzqsQqnLoCgUjhgxwAAAXI"]
[Tue Jul 21 08:43:38.834007 2026] [proxy:error] [pid 514479:tid 514685] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:43:38.834053 2026] [proxy_http:error] [pid 514479:tid 514685] [client 157.52.92.27:35254] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:43:38.834684 2026] [proxy:error] [pid 514479:tid 514685] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:43:38.834713 2026] [proxy_http:error] [pid 514479:tid 514685] [client 157.52.92.27:35254] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:43:39.063149 2026] [security2:error] [pid 511108:tid 511258] [client 20.206.105.145:55776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/pucci.php"] [unique_id "al9ba4Td5soprXwxAH3-7wAAABQ"]
[Tue Jul 21 08:43:39.063216 2026] [security2:error] [pid 511108:tid 511246] [client 41.89.234.2:55708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ba4Td5soprXwxAH3-8AAAAAg"]
[Tue Jul 21 08:43:39.063329 2026] [security2:error] [pid 511108:tid 511246] [client 41.89.234.2:55708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ba4Td5soprXwxAH3-8AAAAAg"]
[Tue Jul 21 08:43:39.065528 2026] [security2:error] [pid 511108:tid 511243] [client 203.25.124.37:64957] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/theme-compat/chosen.php"] [unique_id "al9ba4Td5soprXwxAH3-8QAAAAU"]
[Tue Jul 21 08:43:39.140992 2026] [security2:error] [pid 511108:tid 511241] [client 20.151.10.161:56351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/xenon1337.php"] [unique_id "al9ba4Td5soprXwxAH3-9QAAAAM"]
[Tue Jul 21 08:43:39.170760 2026] [security2:error] [pid 511108:tid 511295] [client 69.171.230.114:39604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ba4Td5soprXwxAH3-9gAAADk"]
[Tue Jul 21 08:43:39.239503 2026] [security2:error] [pid 511108:tid 511263] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ba4Td5soprXwxAH3-9wAAGX8"]
[Tue Jul 21 08:43:39.429400 2026] [security2:error] [pid 514479:tid 514645] [client 20.151.10.161:56362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/test11.php"] [unique_id "al9ba_zqsQqnLoCgUjhgzQAAASk"]
[Tue Jul 21 08:43:39.497154 2026] [security2:error] [pid 514479:tid 514711] [client 168.167.81.163:60086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9ba_zqsQqnLoCgUjhg0AAAAWs"]
[Tue Jul 21 08:43:39.497323 2026] [security2:error] [pid 514479:tid 514711] [client 168.167.81.163:60086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9ba_zqsQqnLoCgUjhg0AAAAWs"]
[Tue Jul 21 08:43:39.644592 2026] [security2:error] [pid 514479:tid 514695] [client 173.252.95.59:33394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ba_zqsQqnLoCgUjhg0wAAAVs"]
[Tue Jul 21 08:43:39.753976 2026] [security2:error] [pid 514479:tid 514632] [client 20.151.10.161:30641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/koala.php"] [unique_id "al9ba_zqsQqnLoCgUjhg1AAAARw"]
[Tue Jul 21 08:43:39.800131 2026] [security2:error] [pid 511108:tid 511332] [client 20.206.105.145:55760] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-includes/blocks/details/"] [unique_id "al9ba4Td5soprXwxAH3_CQAAAF4"]
[Tue Jul 21 08:43:39.820704 2026] [security2:error] [pid 514479:tid 514639] [client 198.44.157.34:49598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9ba_zqsQqnLoCgUjhg1gAAASM"]
[Tue Jul 21 08:43:39.820800 2026] [security2:error] [pid 514479:tid 514639] [client 198.44.157.34:49598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9ba_zqsQqnLoCgUjhg1gAAASM"]
[Tue Jul 21 08:43:39.866622 2026] [security2:error] [pid 511108:tid 511310] [client 20.206.105.145:55798] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-includes/blocks/audio/"] [unique_id "al9ba4Td5soprXwxAH3_CwAAAEg"]
[Tue Jul 21 08:43:39.876164 2026] [security2:error] [pid 511108:tid 511320] [client 212.32.76.65:20407] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/file.php"] [unique_id "al9ba4Td5soprXwxAH3_DAAAAFI"]
[Tue Jul 21 08:43:39.911125 2026] [security2:error] [pid 514479:tid 514633] [client 20.206.105.145:51958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-temp.php"] [unique_id "al9ba_zqsQqnLoCgUjhg2AAAAR0"]
[Tue Jul 21 08:43:39.989559 2026] [security2:error] [pid 514479:tid 514716] [client 20.206.105.145:55715] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-includes/blocks/buttons/"] [unique_id "al9ba_zqsQqnLoCgUjhg2gAAAXA"]
[Tue Jul 21 08:43:40.054187 2026] [security2:error] [pid 514479:tid 514584] [remote 103.187.169.251:43726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oficialwebsite.com.br"] [uri "/wp-login.php"] [unique_id "al9bbPzqsQqnLoCgUjhg2wABOmM"]
[Tue Jul 21 08:43:40.058779 2026] [security2:error] [pid 511108:tid 511341] [client 203.25.124.57:60135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/root.php"] [unique_id "al9bbITd5soprXwxAH3_EwAAAGc"]
[Tue Jul 21 08:43:40.201800 2026] [security2:error] [pid 511108:tid 511346] [client 74.7.244.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.conquisteemcasa.com.br"] [uri "/index.php"] [unique_id "al9baoTd5soprXwxAH3-6AAAbGo"]
[Tue Jul 21 08:43:40.224634 2026] [security2:error] [pid 514479:tid 514650] [client 20.206.105.145:55684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/xmu.php"] [unique_id "al9bbPzqsQqnLoCgUjhg3gAAAS4"]
[Tue Jul 21 08:43:40.254192 2026] [security2:error] [pid 511108:tid 511308] [client 20.151.10.161:56399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/mac.php"] [unique_id "al9bbITd5soprXwxAH3_GwAAAEY"]
[Tue Jul 21 08:43:40.324561 2026] [security2:error] [pid 511108:tid 511303] [client 69.171.230.40:56980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bbITd5soprXwxAH3_IAAAAEE"]
[Tue Jul 21 08:43:40.430323 2026] [security2:error] [pid 514479:tid 514681] [client 20.206.105.145:55802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9bbPzqsQqnLoCgUjhg4QAAAU0"]
[Tue Jul 21 08:43:40.532536 2026] [security2:error] [pid 511108:tid 511260] [client 173.252.95.3:33846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ba4Td5soprXwxAH3_AAAAABY"]
[Tue Jul 21 08:43:40.581955 2026] [security2:error] [pid 511108:tid 511244] [client 61.1.167.83:58982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bbITd5soprXwxAH3_KgAAAAY"]
[Tue Jul 21 08:43:40.582071 2026] [security2:error] [pid 511108:tid 511244] [client 61.1.167.83:58982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bbITd5soprXwxAH3_KgAAAAY"]
[Tue Jul 21 08:43:40.597085 2026] [security2:error] [pid 514479:tid 514653] [client 20.151.10.161:30630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/25d653587fdfd1.php"] [unique_id "al9bbPzqsQqnLoCgUjhg4wAAATE"]
[Tue Jul 21 08:43:40.824345 2026] [autoindex:error] [pid 514479:tid 514704] [client 198.235.24.200:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:40.860850 2026] [security2:error] [pid 511108:tid 511332] [client 203.25.124.39:27101] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/widgets/"] [unique_id "al9bbITd5soprXwxAH3_LwAAAF4"]
[Tue Jul 21 08:43:40.868633 2026] [security2:error] [pid 511108:tid 511240] [client 173.252.95.20:61086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ba4Td5soprXwxAH3_CgAAAAI"]
[Tue Jul 21 08:43:40.870378 2026] [security2:error] [pid 514479:tid 514671] [client 212.32.76.65:28293] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/chosen.php"] [unique_id "al9bbPzqsQqnLoCgUjhg6gAAAUM"]
[Tue Jul 21 08:43:40.898708 2026] [security2:error] [pid 511108:tid 511242] [client 113.22.144.139:51578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bbITd5soprXwxAH3_MAAAAAQ"]
[Tue Jul 21 08:43:40.898840 2026] [security2:error] [pid 511108:tid 511242] [client 113.22.144.139:51578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bbITd5soprXwxAH3_MAAAAAQ"]
[Tue Jul 21 08:43:41.044383 2026] [security2:error] [pid 511108:tid 511306] [client 20.206.105.145:55784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/puc.php"] [unique_id "al9bbYTd5soprXwxAH3_NgAAAEQ"]
[Tue Jul 21 08:43:41.100172 2026] [security2:error] [pid 511108:tid 511261] [client 20.151.10.161:56420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wefile.php"] [unique_id "al9bbYTd5soprXwxAH3_OAAAABc"]
[Tue Jul 21 08:43:41.423534 2026] [security2:error] [pid 511108:tid 511258] [client 173.252.95.30:46640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bbYTd5soprXwxAH3_QQAAABQ"]
[Tue Jul 21 08:43:41.515507 2026] [security2:error] [pid 514479:tid 514678] [client 5.38.115.39:64920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bbfzqsQqnLoCgUjhg9AAAAUo"]
[Tue Jul 21 08:43:41.515632 2026] [security2:error] [pid 514479:tid 514678] [client 5.38.115.39:64920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bbfzqsQqnLoCgUjhg9AAAAUo"]
[Tue Jul 21 08:43:41.699898 2026] [security2:error] [pid 511108:tid 511312] [client 20.206.105.145:55756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/themes.php"] [unique_id "al9bbYTd5soprXwxAH3_SgAAAEo"]
[Tue Jul 21 08:43:41.712166 2026] [security2:error] [pid 511108:tid 511313] [client 173.252.95.2:36328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bbYTd5soprXwxAH3_RAAAAEs"]
[Tue Jul 21 08:43:41.742135 2026] [security2:error] [pid 511108:tid 511324] [client 20.226.60.151:58512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/19.php"] [unique_id "al9bbYTd5soprXwxAH3_TAAAAFY"]
[Tue Jul 21 08:43:42.074395 2026] [security2:error] [pid 514479:tid 514711] [client 212.32.76.4:20005] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/class.php"] [unique_id "al9bbvzqsQqnLoCgUjhg_wAAAWs"]
[Tue Jul 21 08:43:42.221524 2026] [security2:error] [pid 514479:tid 514730] [client 49.144.66.253:32981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bbvzqsQqnLoCgUjhhAwAAAX4"]
[Tue Jul 21 08:43:42.221653 2026] [security2:error] [pid 514479:tid 514730] [client 49.144.66.253:32981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bbvzqsQqnLoCgUjhhAwAAAX4"]
[Tue Jul 21 08:43:42.232711 2026] [security2:error] [pid 514479:tid 514709] [client 69.171.230.39:64980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bbfzqsQqnLoCgUjhg7wAAAWk"]
[Tue Jul 21 08:43:42.264423 2026] [security2:error] [pid 511108:tid 511240] [client 173.252.95.112:62612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bboTd5soprXwxAH3_VAAAAAI"]
[Tue Jul 21 08:43:42.365128 2026] [security2:error] [pid 511108:tid 511359] [client 20.206.105.145:55701] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-includes/Requests/"] [unique_id "al9bboTd5soprXwxAH3_VwAAAHk"]
[Tue Jul 21 08:43:42.405484 2026] [autoindex:error] [pid 514479:tid 514646] [client 20.151.10.161:0] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:42.431494 2026] [security2:error] [pid 514479:tid 514597] [remote 130.185.118.215:43374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9bbvzqsQqnLoCgUjhhCAABIXA"]
[Tue Jul 21 08:43:42.632991 2026] [security2:error] [pid 514479:tid 514615] [client 20.206.105.145:51904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/8.php"] [unique_id "al9bbvzqsQqnLoCgUjhhCwAAAQs"]
[Tue Jul 21 08:43:42.706584 2026] [security2:error] [pid 514479:tid 514594] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bbvzqsQqnLoCgUjhhDAABQm0"]
[Tue Jul 21 08:43:42.706694 2026] [security2:error] [pid 514479:tid 514670] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bbvzqsQqnLoCgUjhhDAABQm0"]
[Tue Jul 21 08:43:42.776117 2026] [security2:error] [pid 511108:tid 511303] [client 203.25.124.202:38861] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/"] [unique_id "al9bboTd5soprXwxAH3_jQAAAEE"]
[Tue Jul 21 08:43:42.778085 2026] [security2:error] [pid 511108:tid 511326] [client 62.60.130.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.alanferreira1753727067926.0721679.meusitehostgator.com.br"] [uri "/"] [unique_id "al9bboTd5soprXwxAH3_jgAAAFg"]
[Tue Jul 21 08:43:42.815124 2026] [security2:error] [pid 511108:tid 511209] [remote 20.153.140.50:54542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9bboTd5soprXwxAH3_jwAAQ2Q"]
[Tue Jul 21 08:43:42.868870 2026] [autoindex:error] [pid 514479:tid 514668] [client 20.151.10.161:56414] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:42.928989 2026] [security2:error] [pid 511108:tid 511300] [client 173.252.95.38:49918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bboTd5soprXwxAH3_kwAAAD4"]
[Tue Jul 21 08:43:43.023152 2026] [security2:error] [pid 511108:tid 511358] [client 62.60.130.235:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.alanferreira1753727067926.0721679.meusitehostgator.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9bb4Td5soprXwxAH3_rgAAAHg"]
[Tue Jul 21 08:43:43.027913 2026] [security2:error] [pid 511108:tid 511248] [client 69.171.230.39:64992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bb4Td5soprXwxAH3_rwAAAAo"]
[Tue Jul 21 08:43:43.179547 2026] [security2:error] [pid 511108:tid 511324] [client 20.151.10.161:56401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9bb4Td5soprXwxAH3_uQAAAFY"]
[Tue Jul 21 08:43:43.479218 2026] [security2:error] [pid 511108:tid 511333] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bboTd5soprXwxAH3_rQAAAF8"]
[Tue Jul 21 08:43:43.599470 2026] [security2:error] [pid 511108:tid 511219] [remote 207.180.241.245:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp-login.php"] [unique_id "al9bb4Td5soprXwxAH3_xQAAEG4"]
[Tue Jul 21 08:43:43.619653 2026] [security2:error] [pid 514479:tid 514718] [client 20.206.105.145:55696] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/1.php"] [unique_id "al9bb_zqsQqnLoCgUjhhGQAAAXI"]
[Tue Jul 21 08:43:43.619736 2026] [security2:error] [pid 514479:tid 514718] [client 20.206.105.145:55696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/1.php"] [unique_id "al9bb_zqsQqnLoCgUjhhGQAAAXI"]
[Tue Jul 21 08:43:43.620661 2026] [security2:error] [pid 511108:tid 511359] [client 20.151.10.161:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/2P.php"] [unique_id "al9bb4Td5soprXwxAH3_xgAAAHk"]
[Tue Jul 21 08:43:43.625374 2026] [security2:error] [pid 511108:tid 511117] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bb4Td5soprXwxAH3_xwAARAg"]
[Tue Jul 21 08:43:43.625482 2026] [security2:error] [pid 511108:tid 511306] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bb4Td5soprXwxAH3_xwAARAg"]
[Tue Jul 21 08:43:43.673682 2026] [security2:error] [pid 511108:tid 511285] [client 195.49.128.211:62265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bb4Td5soprXwxAH3_zAAAAC8"]
[Tue Jul 21 08:43:43.673774 2026] [security2:error] [pid 511108:tid 511285] [client 195.49.128.211:62265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bb4Td5soprXwxAH3_zAAAAC8"]
[Tue Jul 21 08:43:43.769643 2026] [security2:error] [pid 511108:tid 511336] [client 212.32.76.60:28165] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/1.php"] [unique_id "al9bb4Td5soprXwxAH3_zgAAAGI"]
[Tue Jul 21 08:43:43.789557 2026] [security2:error] [pid 514479:tid 514701] [client 103.59.206.240:31408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bb_zqsQqnLoCgUjhhHQAAAWE"]
[Tue Jul 21 08:43:43.789691 2026] [security2:error] [pid 514479:tid 514701] [client 103.59.206.240:31408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bb_zqsQqnLoCgUjhhHQAAAWE"]
[Tue Jul 21 08:43:44.080163 2026] [security2:error] [pid 514479:tid 514711] [client 195.206.105.227:52710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9bcPzqsQqnLoCgUjhhIgAAAWs"]
[Tue Jul 21 08:43:44.080251 2026] [security2:error] [pid 514479:tid 514711] [client 195.206.105.227:52710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9bcPzqsQqnLoCgUjhhIgAAAWs"]
[Tue Jul 21 08:43:44.082620 2026] [security2:error] [pid 511108:tid 511317] [client 20.206.105.145:55792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/100.php"] [unique_id "al9bcITd5soprXwxAH3_1QAAAE8"]
[Tue Jul 21 08:43:44.122874 2026] [security2:error] [pid 514479:tid 514645] [client 20.151.10.161:30657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/.well-known/about.php"] [unique_id "al9bcPzqsQqnLoCgUjhhIwAAASk"]
[Tue Jul 21 08:43:44.475916 2026] [security2:error] [pid 514479:tid 514739] [client 20.151.10.161:56403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9bcPzqsQqnLoCgUjhhKAAAAYc"]
[Tue Jul 21 08:43:44.487522 2026] [security2:error] [pid 511108:tid 511311] [client 20.206.105.145:55706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/about.php"] [unique_id "al9bcITd5soprXwxAH3_4QAAAEk"]
[Tue Jul 21 08:43:44.566388 2026] [security2:error] [pid 511108:tid 511325] [client 203.25.124.50:26189] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "al9bcITd5soprXwxAH3_4gAAAFc"]
[Tue Jul 21 08:43:44.774964 2026] [security2:error] [pid 511108:tid 511301] [client 20.151.10.161:56361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/bob.php"] [unique_id "al9bcITd5soprXwxAH3_5gAAAD8"]
[Tue Jul 21 08:43:44.846886 2026] [security2:error] [pid 514479:tid 514652] [client 20.206.105.145:55700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/about.php"] [unique_id "al9bcPzqsQqnLoCgUjhhLgAAATA"]
[Tue Jul 21 08:43:44.916288 2026] [security2:error] [pid 514479:tid 514677] [client 20.226.60.151:58577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/inc.php"] [unique_id "al9bcPzqsQqnLoCgUjhhMAAAAUk"]
[Tue Jul 21 08:43:45.144864 2026] [security2:error] [pid 511108:tid 511240] [client 198.44.157.34:49600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9bcYTd5soprXwxAH3_9AAAAAI"]
[Tue Jul 21 08:43:45.144990 2026] [security2:error] [pid 511108:tid 511240] [client 198.44.157.34:49600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9bcYTd5soprXwxAH3_9AAAAAI"]
[Tue Jul 21 08:43:45.333067 2026] [autoindex:error] [pid 514479:tid 514668] [client 20.151.10.161:56414] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:45.365602 2026] [security2:error] [pid 514479:tid 514686] [client 212.32.76.5:21895] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/news-portal/admins-dir.php"] [unique_id "al9bcfzqsQqnLoCgUjhhNwAAAVI"]
[Tue Jul 21 08:43:45.663684 2026] [autoindex:error] [pid 514479:tid 514696] [client 20.151.10.161:56414] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:45.673651 2026] [security2:error] [pid 511108:tid 511246] [client 203.25.124.189:57971] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/fukasawa/inc/classes/403.php"] [unique_id "al9bcYTd5soprXwxAH3__gAAAAg"]
[Tue Jul 21 08:43:45.816682 2026] [security2:error] [pid 514479:tid 514620] [client 20.151.10.161:56433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/crgio.php"] [unique_id "al9bcfzqsQqnLoCgUjhhQQAAARA"]
[Tue Jul 21 08:43:45.822060 2026] [security2:error] [pid 514479:tid 514699] [client 20.206.105.145:55730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/admin.php"] [unique_id "al9bcfzqsQqnLoCgUjhhQgAAAV8"]
[Tue Jul 21 08:43:46.099479 2026] [security2:error] [pid 514479:tid 514720] [client 20.151.10.161:56320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/pucci.php"] [unique_id "al9bcvzqsQqnLoCgUjhhRwAAAXQ"]
[Tue Jul 21 08:43:46.250756 2026] [security2:error] [pid 514479:tid 514737] [client 195.49.128.211:54055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bcvzqsQqnLoCgUjhhSAAAAYU"]
[Tue Jul 21 08:43:46.250908 2026] [security2:error] [pid 514479:tid 514737] [client 195.49.128.211:54055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bcvzqsQqnLoCgUjhhSAAAAYU"]
[Tue Jul 21 08:43:46.548280 2026] [security2:error] [pid 511108:tid 511265] [client 20.206.105.145:55800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/admin.php"] [unique_id "al9bcoTd5soprXwxAH0ADAAAABs"]
[Tue Jul 21 08:43:46.576155 2026] [security2:error] [pid 514479:tid 514730] [client 203.25.124.57:59475] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/js/chosen.php"] [unique_id "al9bcvzqsQqnLoCgUjhhTgAAAX4"]
[Tue Jul 21 08:43:46.670528 2026] [autoindex:error] [pid 514479:tid 514717] [client 20.151.10.161:0] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:46.871423 2026] [security2:error] [pid 514479:tid 514615] [client 212.32.76.63:32381] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/alera/gecko.php"] [unique_id "al9bcvzqsQqnLoCgUjhhWgAAAQs"]
[Tue Jul 21 08:43:47.040687 2026] [autoindex:error] [pid 514479:tid 514687] [client 20.151.10.161:0] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:47.052112 2026] [security2:error] [pid 514479:tid 514693] [client 202.179.75.202:32830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bc_zqsQqnLoCgUjhhXwAAAVk"]
[Tue Jul 21 08:43:47.052851 2026] [security2:error] [pid 514479:tid 514693] [client 202.179.75.202:32830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bc_zqsQqnLoCgUjhhXwAAAVk"]
[Tue Jul 21 08:43:47.137737 2026] [security2:error] [pid 511108:tid 511319] [client 20.206.105.145:55722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/edit.php"] [unique_id "al9bc4Td5soprXwxAH0AFgAAAFE"]
[Tue Jul 21 08:43:47.179427 2026] [security2:error] [pid 514479:tid 514668] [client 20.151.10.161:56419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-temp.php"] [unique_id "al9bc_zqsQqnLoCgUjhhYQAAAUA"]
[Tue Jul 21 08:43:47.264040 2026] [security2:error] [pid 514479:tid 514688] [client 203.25.124.48:29353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/classwithtostring.php"] [unique_id "al9bc_zqsQqnLoCgUjhhYgAAAVQ"]
[Tue Jul 21 08:43:47.346567 2026] [security2:error] [pid 511108:tid 511248] [client 59.95.197.55:52449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bc4Td5soprXwxAH0AGAAAAAo"]
[Tue Jul 21 08:43:47.347162 2026] [security2:error] [pid 511108:tid 511248] [client 59.95.197.55:52449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bc4Td5soprXwxAH0AGAAAAAo"]
[Tue Jul 21 08:43:47.583830 2026] [security2:error] [pid 511108:tid 511347] [client 203.25.124.187:60789] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/so-pinyin-slugs/inc/main_json.php"] [unique_id "al9bc4Td5soprXwxAH0AGwAAAG0"]
[Tue Jul 21 08:43:47.621725 2026] [security2:error] [pid 511108:tid 511287] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bc4Td5soprXwxAH0AFQAAADE"]
[Tue Jul 21 08:43:47.666703 2026] [autoindex:error] [pid 514479:tid 514700] [client 20.151.10.161:0] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:47.673880 2026] [security2:error] [pid 514479:tid 514520] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bc_zqsQqnLoCgUjhhbQABESQ"]
[Tue Jul 21 08:43:47.674045 2026] [security2:error] [pid 514479:tid 514621] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bc_zqsQqnLoCgUjhhbQABESQ"]
[Tue Jul 21 08:43:47.972566 2026] [security2:error] [pid 514479:tid 514729] [client 20.206.105.145:55803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-content/admin.php"] [unique_id "al9bc_zqsQqnLoCgUjhhdAAAAX0"]
[Tue Jul 21 08:43:47.986015 2026] [security2:error] [pid 514479:tid 514655] [client 20.151.10.161:56372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9bc_zqsQqnLoCgUjhhdgAAATM"]
[Tue Jul 21 08:43:48.186566 2026] [security2:error] [pid 511108:tid 511244] [client 117.213.202.34:52091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bdITd5soprXwxAH0AJAAAAAY"]
[Tue Jul 21 08:43:48.186727 2026] [security2:error] [pid 511108:tid 511244] [client 117.213.202.34:52091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bdITd5soprXwxAH0AJAAAAAY"]
[Tue Jul 21 08:43:48.248478 2026] [security2:error] [pid 511108:tid 511314] [client 122.176.100.127:53469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bdITd5soprXwxAH0AJgAAAEw"]
[Tue Jul 21 08:43:48.248713 2026] [security2:error] [pid 511108:tid 511314] [client 122.176.100.127:53469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bdITd5soprXwxAH0AJgAAAEw"]
[Tue Jul 21 08:43:48.322754 2026] [security2:error] [pid 514479:tid 514637] [client 20.151.10.161:56364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/puc.php"] [unique_id "al9bdPzqsQqnLoCgUjhhfAAAASE"]
[Tue Jul 21 08:43:48.516007 2026] [security2:error] [pid 514479:tid 514620] [client 152.59.181.104:53560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bdPzqsQqnLoCgUjhhgAAAARA"]
[Tue Jul 21 08:43:48.516114 2026] [security2:error] [pid 514479:tid 514620] [client 152.59.181.104:53560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bdPzqsQqnLoCgUjhhgAAAARA"]
[Tue Jul 21 08:43:48.838089 2026] [security2:error] [pid 511108:tid 511242] [client 20.151.10.161:56377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/themes.php"] [unique_id "al9bdITd5soprXwxAH0AKwAAAAQ"]
[Tue Jul 21 08:43:48.842934 2026] [security2:error] [pid 514479:tid 514704] [client 20.226.60.151:58562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9bdPzqsQqnLoCgUjhhiwAAAWQ"]
[Tue Jul 21 08:43:49.040800 2026] [security2:error] [pid 511108:tid 511263] [client 20.206.105.145:51909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/f6.php"] [unique_id "al9bdYTd5soprXwxAH0AMQAAABk"]
[Tue Jul 21 08:43:49.065343 2026] [security2:error] [pid 511108:tid 511243] [client 203.25.124.66:50101] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwentytwo/templates/"] [unique_id "al9bdYTd5soprXwxAH0AMgAAAAU"]
[Tue Jul 21 08:43:49.071655 2026] [security2:error] [pid 511108:tid 511277] [client 203.25.124.182:59711] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/assets/"] [unique_id "al9bdYTd5soprXwxAH0AMwAAACc"]
[Tue Jul 21 08:43:49.384573 2026] [security2:error] [pid 511108:tid 511322] [client 20.151.10.161:30684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/dx.php"] [unique_id "al9bdYTd5soprXwxAH0AOQAAAFQ"]
[Tue Jul 21 08:43:49.476017 2026] [security2:error] [pid 514479:tid 514515] [remote 103.187.169.251:38862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rgagestaodecondominios.adm.br"] [uri "/wp-login.php"] [unique_id "al9bdfzqsQqnLoCgUjhhkQABTx8"]
[Tue Jul 21 08:43:49.789981 2026] [security2:error] [pid 511108:tid 511283] [client 20.151.10.161:30664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/p.php"] [unique_id "al9bdYTd5soprXwxAH0ARQAAAC0"]
[Tue Jul 21 08:43:49.872659 2026] [security2:error] [pid 511108:tid 511261] [client 203.25.124.5:28179] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/hello.php"] [unique_id "al9bdYTd5soprXwxAH0ARgAAABc"]
[Tue Jul 21 08:43:49.983672 2026] [security2:error] [pid 511108:tid 511246] [client 198.44.157.34:35840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9bdYTd5soprXwxAH0ATAAAAAg"]
[Tue Jul 21 08:43:49.983773 2026] [security2:error] [pid 511108:tid 511246] [client 198.44.157.34:35840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9bdYTd5soprXwxAH0ATAAAAAg"]
[Tue Jul 21 08:43:50.015712 2026] [security2:error] [pid 511108:tid 511124] [remote 217.182.128.41:45818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9bdoTd5soprXwxAH0ATQAALw8"]
[Tue Jul 21 08:43:50.015864 2026] [security2:error] [pid 511108:tid 511285] [client 217.182.128.41:45818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9bdoTd5soprXwxAH0ATQAALw8"]
[Tue Jul 21 08:43:50.067915 2026] [security2:error] [pid 511108:tid 511268] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bdYTd5soprXwxAH0ASAAAHgQ"]
[Tue Jul 21 08:43:50.108696 2026] [security2:error] [pid 511108:tid 511275] [client 168.167.81.163:61713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bdoTd5soprXwxAH0ATwAAACU"]
[Tue Jul 21 08:43:50.108808 2026] [security2:error] [pid 511108:tid 511275] [client 168.167.81.163:61713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bdoTd5soprXwxAH0ATwAAACU"]
[Tue Jul 21 08:43:50.343908 2026] [autoindex:error] [pid 514479:tid 514709] [client 20.151.10.161:0] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:50.458318 2026] [security2:error] [pid 511108:tid 511326] [client 20.226.60.151:58520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9bdoTd5soprXwxAH0AVgAAAFg"]
[Tue Jul 21 08:43:50.486790 2026] [security2:error] [pid 511108:tid 511277] [client 20.151.10.161:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/bthil.php"] [unique_id "al9bdoTd5soprXwxAH0AWQAAACc"]
[Tue Jul 21 08:43:50.787107 2026] [security2:error] [pid 511108:tid 511362] [client 20.151.10.161:56366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/7.php"] [unique_id "al9bdoTd5soprXwxAH0AXQAAAHw"]
[Tue Jul 21 08:43:50.985634 2026] [rewrite:warn] [pid 511108:tid 511120] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:43:50.988304 2026] [security2:error] [pid 514479:tid 514688] [client 20.206.105.145:55719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/inputs.php"] [unique_id "al9bdvzqsQqnLoCgUjhhsgAAAVQ"]
[Tue Jul 21 08:43:51.181297 2026] [security2:error] [pid 511108:tid 511355] [client 203.25.124.251:65071] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/maint/"] [unique_id "al9bd4Td5soprXwxAH0AZwAAAHU"]
[Tue Jul 21 08:43:51.231225 2026] [security2:error] [pid 514479:tid 514684] [client 20.151.10.161:56396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/8.php"] [unique_id "al9bd_zqsQqnLoCgUjhhtQAAAVA"]
[Tue Jul 21 08:43:51.233893 2026] [security2:error] [pid 514479:tid 514694] [client 20.197.192.193:23543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9bd_zqsQqnLoCgUjhhtgAAAVo"]
[Tue Jul 21 08:43:51.341047 2026] [security2:error] [pid 511108:tid 511249] [client 80.96.109.64:50398] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "limaradiologiadigital.com.br"] [uri "/"] [unique_id "al9bd4Td5soprXwxAH0AbAAAAAs"]
[Tue Jul 21 08:43:51.365327 2026] [security2:error] [pid 511108:tid 511314] [client 20.197.192.193:23521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9bd4Td5soprXwxAH0AbgAAAEw"]
[Tue Jul 21 08:43:51.380668 2026] [security2:error] [pid 511108:tid 511264] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bdoTd5soprXwxAH0AYgAAABo"]
[Tue Jul 21 08:43:51.469728 2026] [security2:error] [pid 514479:tid 514667] [client 20.197.192.193:24462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/dp.php"] [unique_id "al9bd_zqsQqnLoCgUjhhuQAAAT8"]
[Tue Jul 21 08:43:51.559421 2026] [security2:error] [pid 514479:tid 514700] [client 203.25.124.36:43873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Requests/src/Utility/"] [unique_id "al9bd_zqsQqnLoCgUjhhuwAAAWA"]
[Tue Jul 21 08:43:51.560281 2026] [security2:error] [pid 511108:tid 511349] [client 20.197.192.193:23548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/old.php"] [unique_id "al9bd4Td5soprXwxAH0AcwAAAG8"]
[Tue Jul 21 08:43:51.561622 2026] [security2:error] [pid 511108:tid 511317] [client 20.151.10.161:30690] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "detetiveespecialista.com"] [uri "/1.php"] [unique_id "al9bd4Td5soprXwxAH0AdAAAAE8"]
[Tue Jul 21 08:43:51.561728 2026] [security2:error] [pid 511108:tid 511317] [client 20.151.10.161:30690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/1.php"] [unique_id "al9bd4Td5soprXwxAH0AdAAAAE8"]
[Tue Jul 21 08:43:51.672636 2026] [security2:error] [pid 514479:tid 514657] [client 20.197.192.193:24459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/ms-new.php"] [unique_id "al9bd_zqsQqnLoCgUjhhvAAAATU"]
[Tue Jul 21 08:43:51.718069 2026] [security2:error] [pid 514479:tid 514668] [client 113.22.144.139:52093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bd_zqsQqnLoCgUjhhvQAAAUA"]
[Tue Jul 21 08:43:51.718176 2026] [security2:error] [pid 514479:tid 514668] [client 113.22.144.139:52093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bd_zqsQqnLoCgUjhhvQAAAUA"]
[Tue Jul 21 08:43:51.736131 2026] [security2:error] [pid 511108:tid 511328] [client 20.197.192.193:23542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/track.php"] [unique_id "al9bd4Td5soprXwxAH0AdQAAAFo"]
[Tue Jul 21 08:43:51.756284 2026] [security2:error] [pid 514479:tid 514649] [client 20.206.105.145:51926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/inputs.php"] [unique_id "al9bd_zqsQqnLoCgUjhhvgAAAS0"]
[Tue Jul 21 08:43:51.762759 2026] [security2:error] [pid 511108:tid 511300] [client 20.197.192.193:23493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/2352356666.php"] [unique_id "al9bd4Td5soprXwxAH0AdgAAAD4"]
[Tue Jul 21 08:43:51.796893 2026] [security2:error] [pid 511108:tid 511298] [client 20.197.192.193:23500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/pn.php"] [unique_id "al9bd4Td5soprXwxAH0AeQAAADw"]
[Tue Jul 21 08:43:51.819831 2026] [security2:error] [pid 511108:tid 511350] [client 20.197.192.193:24469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/wp-wpbak.php"] [unique_id "al9bd4Td5soprXwxAH0AegAAAHA"]
[Tue Jul 21 08:43:51.843498 2026] [security2:error] [pid 514479:tid 514641] [client 20.197.192.193:23541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/dr.php"] [unique_id "al9bd_zqsQqnLoCgUjhhwQAAASU"]
[Tue Jul 21 08:43:51.851497 2026] [security2:error] [pid 514479:tid 514701] [client 20.226.60.151:58528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/ss.php"] [unique_id "al9bd_zqsQqnLoCgUjhhwgAAAWE"]
[Tue Jul 21 08:43:51.860051 2026] [security2:error] [pid 514479:tid 514698] [client 5.31.193.106:1802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bd_zqsQqnLoCgUjhhwwAAAV4"]
[Tue Jul 21 08:43:51.860153 2026] [security2:error] [pid 514479:tid 514698] [client 5.31.193.106:1802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bd_zqsQqnLoCgUjhhwwAAAV4"]
[Tue Jul 21 08:43:51.864770 2026] [security2:error] [pid 514479:tid 514726] [client 20.197.192.193:23529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/2x.php"] [unique_id "al9bd_zqsQqnLoCgUjhhxAAAAXo"]
[Tue Jul 21 08:43:51.889299 2026] [security2:error] [pid 514479:tid 514675] [client 20.151.10.161:30619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/100.php"] [unique_id "al9bd_zqsQqnLoCgUjhhxgAAAUc"]
[Tue Jul 21 08:43:51.910404 2026] [security2:error] [pid 511108:tid 511243] [client 20.197.192.193:23509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/kq1.php"] [unique_id "al9bd4Td5soprXwxAH0AfQAAAAU"]
[Tue Jul 21 08:43:51.980312 2026] [security2:error] [pid 511108:tid 511272] [client 20.197.192.193:24452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/zzz.php"] [unique_id "al9bd4Td5soprXwxAH0AfgAAACI"]
[Tue Jul 21 08:43:52.044718 2026] [security2:error] [pid 511108:tid 511245] [client 20.197.192.193:24473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/wicked.php"] [unique_id "al9beITd5soprXwxAH0AfwAAAAc"]
[Tue Jul 21 08:43:52.073805 2026] [security2:error] [pid 514479:tid 514671] [client 20.197.192.193:23504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/edit.php"] [unique_id "al9bePzqsQqnLoCgUjhhyAAAAUM"]
[Tue Jul 21 08:43:52.118014 2026] [security2:error] [pid 514479:tid 514655] [client 20.197.192.193:24466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/kua.php"] [unique_id "al9bePzqsQqnLoCgUjhhyQAAATM"]
[Tue Jul 21 08:43:52.143187 2026] [security2:error] [pid 514479:tid 514633] [client 20.197.192.193:23491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/ez.php"] [unique_id "al9bePzqsQqnLoCgUjhhzAAAAR0"]
[Tue Jul 21 08:43:52.163119 2026] [security2:error] [pid 514479:tid 514709] [client 20.197.192.193:23549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/fz.php"] [unique_id "al9bePzqsQqnLoCgUjhhzQAAAWk"]
[Tue Jul 21 08:43:52.183211 2026] [security2:error] [pid 514479:tid 514646] [client 20.197.192.193:24448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/la.php"] [unique_id "al9bePzqsQqnLoCgUjhhzgAAASo"]
[Tue Jul 21 08:43:52.200166 2026] [security2:error] [pid 514479:tid 514690] [client 5.38.115.39:38303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bePzqsQqnLoCgUjhhzwAAAVY"]
[Tue Jul 21 08:43:52.200252 2026] [security2:error] [pid 514479:tid 514690] [client 5.38.115.39:38303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bePzqsQqnLoCgUjhhzwAAAVY"]
[Tue Jul 21 08:43:52.251100 2026] [security2:error] [pid 511108:tid 511301] [client 20.197.192.193:24024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/nhvoanpl.php"] [unique_id "al9beITd5soprXwxAH0AiAAAAD8"]
[Tue Jul 21 08:43:52.269513 2026] [security2:error] [pid 511108:tid 511274] [client 20.151.10.161:56325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/about.php"] [unique_id "al9beITd5soprXwxAH0AiQAAACQ"]
[Tue Jul 21 08:43:52.314460 2026] [security2:error] [pid 511108:tid 511260] [client 80.96.109.64:50404] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "limaradiologiadigital.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9beITd5soprXwxAH0AjAAAABY"]
[Tue Jul 21 08:43:52.396556 2026] [security2:error] [pid 514479:tid 514687] [client 20.197.192.193:23503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/inso.php"] [unique_id "al9bePzqsQqnLoCgUjhh1wAAAVM"]
[Tue Jul 21 08:43:52.452531 2026] [security2:error] [pid 511108:tid 511353] [client 20.206.105.145:51840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/av.php"] [unique_id "al9beITd5soprXwxAH0AkQAAAHM"]
[Tue Jul 21 08:43:52.459922 2026] [security2:error] [pid 511108:tid 511283] [client 203.25.124.32:62405] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "al9beITd5soprXwxAH0AkgAAAC0"]
[Tue Jul 21 08:43:52.469896 2026] [security2:error] [pid 511108:tid 511261] [client 203.25.124.190:38987] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wordpress/wp-admin/maint/"] [unique_id "al9beITd5soprXwxAH0AkwAAABc"]
[Tue Jul 21 08:43:52.502247 2026] [security2:error] [pid 514479:tid 514643] [client 20.197.192.193:24450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/wpx.php"] [unique_id "al9bePzqsQqnLoCgUjhh2AAAASc"]
[Tue Jul 21 08:43:52.548915 2026] [security2:error] [pid 511108:tid 511264] [client 20.197.192.193:24475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/berlin.php"] [unique_id "al9beITd5soprXwxAH0AlgAAABo"]
[Tue Jul 21 08:43:52.574668 2026] [security2:error] [pid 511108:tid 511246] [client 20.151.10.161:56342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/admin.php"] [unique_id "al9beITd5soprXwxAH0AlwAAAAg"]
[Tue Jul 21 08:43:52.582289 2026] [security2:error] [pid 514479:tid 514688] [client 20.197.192.193:23524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/billur.php"] [unique_id "al9bePzqsQqnLoCgUjhh2wAAAVQ"]
[Tue Jul 21 08:43:52.625253 2026] [security2:error] [pid 514479:tid 514644] [client 20.197.192.193:24464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/mimpi.php"] [unique_id "al9bePzqsQqnLoCgUjhh3QAAASg"]
[Tue Jul 21 08:43:52.666709 2026] [security2:error] [pid 514479:tid 514636] [client 20.197.192.193:24461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/dp.php"] [unique_id "al9bePzqsQqnLoCgUjhh3gAAASA"]
[Tue Jul 21 08:43:52.703935 2026] [security2:error] [pid 514479:tid 514696] [client 20.197.192.193:23514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/bootstrap.php"] [unique_id "al9bePzqsQqnLoCgUjhh3wAAAVw"]
[Tue Jul 21 08:43:52.771497 2026] [security2:error] [pid 511108:tid 511241] [client 20.206.105.145:51947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9beITd5soprXwxAH0AmwAAAAM"]
[Tue Jul 21 08:43:52.791273 2026] [security2:error] [pid 514479:tid 514694] [client 20.197.192.193:23533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/wp-editor.php"] [unique_id "al9bePzqsQqnLoCgUjhh4AAAAVo"]
[Tue Jul 21 08:43:52.845706 2026] [security2:error] [pid 514479:tid 514663] [client 20.197.192.193:24486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/cro.php"] [unique_id "al9bePzqsQqnLoCgUjhh4QAAATs"]
[Tue Jul 21 08:43:52.875418 2026] [security2:error] [pid 511108:tid 511333] [client 20.151.10.161:30689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/edit.php"] [unique_id "al9beITd5soprXwxAH0AngAAAF8"]
[Tue Jul 21 08:43:52.878523 2026] [security2:error] [pid 514479:tid 514697] [client 20.197.192.193:23535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/cron-tab.php"] [unique_id "al9bePzqsQqnLoCgUjhh4gAAAV0"]
[Tue Jul 21 08:43:52.895763 2026] [security2:error] [pid 514479:tid 514700] [client 20.197.192.193:23519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/koiy.php"] [unique_id "al9bePzqsQqnLoCgUjhh4wAAAWA"]
[Tue Jul 21 08:43:52.914292 2026] [security2:error] [pid 514479:tid 514678] [client 20.197.192.193:24467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/hp2.php"] [unique_id "al9bePzqsQqnLoCgUjhh5AAAAUo"]
[Tue Jul 21 08:43:52.952596 2026] [security2:error] [pid 514479:tid 514641] [client 20.197.192.193:23510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/hp3.php"] [unique_id "al9bePzqsQqnLoCgUjhh5wAAASU"]
[Tue Jul 21 08:43:52.976746 2026] [security2:error] [pid 514479:tid 514698] [client 20.197.192.193:24453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/aa1.php"] [unique_id "al9bePzqsQqnLoCgUjhh6AAAAV4"]
[Tue Jul 21 08:43:53.023562 2026] [security2:error] [pid 514479:tid 514720] [client 20.197.192.193:24503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/acew67.php"] [unique_id "al9befzqsQqnLoCgUjhh6QAAAXQ"]
[Tue Jul 21 08:43:53.113153 2026] [security2:error] [pid 514479:tid 514671] [client 20.197.192.193:24485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/bscclapb.php"] [unique_id "al9befzqsQqnLoCgUjhh6gAAAUM"]
[Tue Jul 21 08:43:53.157643 2026] [security2:error] [pid 514479:tid 514633] [client 20.197.192.193:24495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/else1.php"] [unique_id "al9befzqsQqnLoCgUjhh7QAAAR0"]
[Tue Jul 21 08:43:53.177149 2026] [security2:error] [pid 511108:tid 511349] [client 49.144.66.253:33378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9beYTd5soprXwxAH0AoQAAAG8"]
[Tue Jul 21 08:43:53.177286 2026] [security2:error] [pid 511108:tid 511349] [client 49.144.66.253:33378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9beYTd5soprXwxAH0AoQAAAG8"]
[Tue Jul 21 08:43:53.193253 2026] [security2:error] [pid 511108:tid 511328] [client 20.151.10.161:30688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-content/admin.php"] [unique_id "al9beYTd5soprXwxAH0AogAAAFo"]
[Tue Jul 21 08:43:53.206461 2026] [security2:error] [pid 514479:tid 514539] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9befzqsQqnLoCgUjhh8AABXzc"]
[Tue Jul 21 08:43:53.206607 2026] [security2:error] [pid 514479:tid 514699] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9befzqsQqnLoCgUjhh8AABXzc"]
[Tue Jul 21 08:43:53.209641 2026] [security2:error] [pid 514479:tid 514690] [client 20.197.192.193:23547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/tkikikoko.php"] [unique_id "al9befzqsQqnLoCgUjhh8QAAAVY"]
[Tue Jul 21 08:43:53.272469 2026] [security2:error] [pid 514479:tid 514740] [client 80.96.109.64:54782] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "limaradiologiadigital.com.br"] [uri "/"] [unique_id "al9befzqsQqnLoCgUjhh8wAAAYg"]
[Tue Jul 21 08:43:53.277809 2026] [security2:error] [pid 511108:tid 511303] [client 20.197.192.193:23546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/wp-Blogs.php"] [unique_id "al9beYTd5soprXwxAH0AowAAAEE"]
[Tue Jul 21 08:43:53.305273 2026] [security2:error] [pid 511108:tid 511311] [client 18.191.148.181:53108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "avermetais.com.br"] [uri "/robots.txt"] [unique_id "al9beYTd5soprXwxAH0ApAAAAEk"]
[Tue Jul 21 08:43:53.314697 2026] [security2:error] [pid 511108:tid 511326] [client 18.191.148.181:53116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "avermetais.com.br"] [uri "/robots.txt"] [unique_id "al9beYTd5soprXwxAH0ApQAAAFg"]
[Tue Jul 21 08:43:53.326965 2026] [security2:error] [pid 514479:tid 514722] [client 20.206.105.145:55783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9befzqsQqnLoCgUjhh9gAAAXY"]
[Tue Jul 21 08:43:53.365768 2026] [security2:error] [pid 514479:tid 514661] [client 203.25.124.43:60023] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/lock360.php"] [unique_id "al9befzqsQqnLoCgUjhh-gAAATk"]
[Tue Jul 21 08:43:53.440919 2026] [security2:error] [pid 514479:tid 514693] [client 20.206.105.145:55776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/classwithtostring.php"] [unique_id "al9befzqsQqnLoCgUjhh_AAAAVk"]
[Tue Jul 21 08:43:53.462536 2026] [security2:error] [pid 514479:tid 514625] [client 18.191.148.181:33778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "avermetais.com.br"] [uri "/"] [unique_id "al9befzqsQqnLoCgUjhh_QAAARU"]
[Tue Jul 21 08:43:53.483426 2026] [security2:error] [pid 514479:tid 514660] [client 20.197.192.193:23495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/wp-css.php"] [unique_id "al9befzqsQqnLoCgUjhh_gAAATg"]
[Tue Jul 21 08:43:53.531478 2026] [security2:error] [pid 514479:tid 514713] [client 20.151.10.161:30631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/f6.php"] [unique_id "al9befzqsQqnLoCgUjhh_wAAAW0"]
[Tue Jul 21 08:43:53.542683 2026] [security2:error] [pid 514479:tid 514723] [client 20.197.192.193:24480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/wp-explorer.php"] [unique_id "al9befzqsQqnLoCgUjhiAQAAAXc"]
[Tue Jul 21 08:43:53.584822 2026] [security2:error] [pid 514479:tid 514666] [client 18.191.148.181:53120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "avermetais.com.br"] [uri "/ads.txt"] [unique_id "al9befzqsQqnLoCgUjhiAgAAAT4"]
[Tue Jul 21 08:43:53.672270 2026] [security2:error] [pid 514479:tid 514657] [client 203.25.124.180:43675] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "al9befzqsQqnLoCgUjhiBQAAATU"]
[Tue Jul 21 08:43:53.676429 2026] [security2:error] [pid 514479:tid 514668] [client 20.197.192.193:23520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/akismet.php"] [unique_id "al9befzqsQqnLoCgUjhiBgAAAUA"]
[Tue Jul 21 08:43:53.817859 2026] [security2:error] [pid 514479:tid 514675] [client 20.197.192.193:23508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/ace2.php"] [unique_id "al9befzqsQqnLoCgUjhiCQAAAUc"]
[Tue Jul 21 08:43:53.874035 2026] [security2:error] [pid 514479:tid 514691] [client 20.151.10.161:56410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/inputs.php"] [unique_id "al9befzqsQqnLoCgUjhiCwAAAVc"]
[Tue Jul 21 08:43:53.916358 2026] [security2:error] [pid 514479:tid 514714] [client 20.197.192.193:24465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.ciclododinheiro.com"] [uri "/ms.php"] [unique_id "al9befzqsQqnLoCgUjhiDAAAAW4"]
[Tue Jul 21 08:43:54.081838 2026] [security2:error] [pid 514479:tid 514728] [client 20.226.60.151:34754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/min.php"] [unique_id "al9bevzqsQqnLoCgUjhiDwAAAXw"]
[Tue Jul 21 08:43:54.112056 2026] [security2:error] [pid 511108:tid 511342] [client 18.191.148.181:33780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.avermetais.com.br"] [uri "/"] [unique_id "al9beoTd5soprXwxAH0AtQAAAGg"]
[Tue Jul 21 08:43:54.165258 2026] [security2:error] [pid 511108:tid 511193] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9beoTd5soprXwxAH0AtgAAJFQ"]
[Tue Jul 21 08:43:54.165389 2026] [security2:error] [pid 511108:tid 511274] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9beoTd5soprXwxAH0AtgAAJFQ"]
[Tue Jul 21 08:43:54.238927 2026] [security2:error] [pid 514479:tid 514633] [client 80.96.109.64:54784] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "limaradiologiadigital.com.br"] [uri "/"] [unique_id "al9bevzqsQqnLoCgUjhiEQAAAR0"]
[Tue Jul 21 08:43:54.251859 2026] [security2:error] [pid 514479:tid 514662] [client 20.151.10.161:56411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/av.php"] [unique_id "al9bevzqsQqnLoCgUjhiEgAAATo"]
[Tue Jul 21 08:43:54.272084 2026] [security2:error] [pid 511108:tid 511346] [client 20.206.105.145:55680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/media.php"] [unique_id "al9beoTd5soprXwxAH0AugAAAGw"]
[Tue Jul 21 08:43:54.309930 2026] [security2:error] [pid 514479:tid 514699] [client 20.206.105.145:55731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9bevzqsQqnLoCgUjhiEwAAAV8"]
[Tue Jul 21 08:43:54.368500 2026] [security2:error] [pid 514479:tid 514729] [client 195.49.128.211:62935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bevzqsQqnLoCgUjhiFAAAAX0"]
[Tue Jul 21 08:43:54.368681 2026] [security2:error] [pid 514479:tid 514729] [client 195.49.128.211:62935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bevzqsQqnLoCgUjhiFAAAAX0"]
[Tue Jul 21 08:43:54.411374 2026] [security2:error] [pid 514479:tid 514731] [client 103.59.206.240:31231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bevzqsQqnLoCgUjhiFQAAAX8"]
[Tue Jul 21 08:43:54.411543 2026] [security2:error] [pid 514479:tid 514731] [client 103.59.206.240:31231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bevzqsQqnLoCgUjhiFQAAAX8"]
[Tue Jul 21 08:43:54.464242 2026] [security2:error] [pid 511108:tid 511320] [client 203.25.124.54:23045] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/fonts/wp-conflg.php"] [unique_id "al9beoTd5soprXwxAH0AvwAAAFI"]
[Tue Jul 21 08:43:54.555356 2026] [security2:error] [pid 511108:tid 511349] [client 20.151.10.161:56398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/classwithtostring.php"] [unique_id "al9beoTd5soprXwxAH0AxAAAAG8"]
[Tue Jul 21 08:43:54.624829 2026] [security2:error] [pid 514479:tid 514722] [client 20.226.60.151:58519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9bevzqsQqnLoCgUjhiFwAAAXY"]
[Tue Jul 21 08:43:54.670036 2026] [security2:error] [pid 511108:tid 511350] [client 212.32.76.66:38199] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "al9beoTd5soprXwxAH0AyAAAAHA"]
[Tue Jul 21 08:43:54.671891 2026] [security2:error] [pid 511108:tid 511326] [client 64.42.179.43:46710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9beoTd5soprXwxAH0AyQAAAFg"]
[Tue Jul 21 08:43:54.671982 2026] [security2:error] [pid 511108:tid 511326] [client 64.42.179.43:46710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9beoTd5soprXwxAH0AyQAAAFg"]
[Tue Jul 21 08:43:54.732568 2026] [security2:error] [pid 514479:tid 514693] [client 20.206.105.145:51949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/images.php"] [unique_id "al9bevzqsQqnLoCgUjhiGQAAAVk"]
[Tue Jul 21 08:43:54.856543 2026] [security2:error] [pid 511108:tid 511272] [client 20.206.105.145:55801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-blog.php"] [unique_id "al9beoTd5soprXwxAH0AzwAAACI"]
[Tue Jul 21 08:43:54.862787 2026] [security2:error] [pid 511108:tid 511305] [client 20.151.10.161:30712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9beoTd5soprXwxAH0A0AAAAEM"]
[Tue Jul 21 08:43:55.033684 2026] [security2:error] [pid 511108:tid 511317] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9beoTd5soprXwxAH0AxQAAAE8"]
[Tue Jul 21 08:43:55.174108 2026] [security2:error] [pid 511108:tid 511314] [client 20.151.10.161:30595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-blog.php"] [unique_id "al9be4Td5soprXwxAH0A1QAAAEw"]
[Tue Jul 21 08:43:55.209014 2026] [security2:error] [pid 511108:tid 511319] [client 80.96.109.64:54792] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "limaradiologiadigital.com.br"] [uri "/"] [unique_id "al9be4Td5soprXwxAH0A1gAAAFE"]
[Tue Jul 21 08:43:55.469346 2026] [security2:error] [pid 511108:tid 511365] [client 212.32.76.5:50323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwentythree/patterns/"] [unique_id "al9be4Td5soprXwxAH0A3QAAAH8"]
[Tue Jul 21 08:43:55.520537 2026] [security2:error] [pid 514479:tid 514666] [client 20.206.105.145:55693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/adminner.php"] [unique_id "al9be_zqsQqnLoCgUjhiIgAAAT4"]
[Tue Jul 21 08:43:55.572507 2026] [security2:error] [pid 514479:tid 514668] [client 203.25.124.210:20665] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/edit.php"] [unique_id "al9be_zqsQqnLoCgUjhiJAAAAUA"]
[Tue Jul 21 08:43:55.668525 2026] [security2:error] [pid 514479:tid 514701] [client 20.206.105.145:55707] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-includes/js/jquery/"] [unique_id "al9be_zqsQqnLoCgUjhiJgAAAWE"]
[Tue Jul 21 08:43:55.968508 2026] [security2:error] [pid 514479:tid 514702] [client 80.96.109.64:54796] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "limaradiologiadigital.com.br"] [uri "/"] [unique_id "al9be_zqsQqnLoCgUjhiLwAAAWI"]
[Tue Jul 21 08:43:56.205828 2026] [security2:error] [pid 514479:tid 514740] [client 20.206.105.145:55690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/admin.php"] [unique_id "al9bfPzqsQqnLoCgUjhiNAAAAYg"]
[Tue Jul 21 08:43:56.363333 2026] [security2:error] [pid 514479:tid 514738] [client 203.25.124.58:55035] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/js/widgets/admin.php"] [unique_id "al9bfPzqsQqnLoCgUjhiOAAAAYY"]
[Tue Jul 21 08:43:56.420497 2026] [security2:error] [pid 511108:tid 511363] [client 20.206.105.145:51951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-content/admin.php"] [unique_id "al9bfITd5soprXwxAH0A8QAAAH0"]
[Tue Jul 21 08:43:56.453301 2026] [autoindex:error] [pid 514479:tid 514716] [client 44.220.233.148:57810] AH01276: Cannot serve directory /home1/rondo837/public_html/sites/planamoveis.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:56.698203 2026] [autoindex:error] [pid 514479:tid 514625] [client 20.151.10.161:0] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:43:56.807057 2026] [security2:error] [pid 514479:tid 514687] [client 195.49.128.211:54649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bfPzqsQqnLoCgUjhiPwAAAVM"]
[Tue Jul 21 08:43:56.807187 2026] [security2:error] [pid 514479:tid 514687] [client 195.49.128.211:54649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bfPzqsQqnLoCgUjhiPwAAAVM"]
[Tue Jul 21 08:43:56.977648 2026] [security2:error] [pid 514479:tid 514696] [client 20.151.10.161:56386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-content/admin.php"] [unique_id "al9bfPzqsQqnLoCgUjhiQgAAAVw"]
[Tue Jul 21 08:43:57.137489 2026] [qos:error] [pid 514479:tid 514559] [remote 57.141.18.116:37268] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.116, id=al9bffzqsQqnLoCgUjhiRQABKEo
[Tue Jul 21 08:43:57.164449 2026] [security2:error] [pid 514479:tid 514685] [client 20.206.105.145:51931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/k.php"] [unique_id "al9bffzqsQqnLoCgUjhiRgAAAVE"]
[Tue Jul 21 08:43:57.271624 2026] [security2:error] [pid 514479:tid 514678] [client 20.151.10.161:56357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/adminfuns.php"] [unique_id "al9bffzqsQqnLoCgUjhiRwAAAUo"]
[Tue Jul 21 08:43:57.346921 2026] [qos:error] [pid 511108:tid 511184] [remote 57.141.18.86:25376] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.86, id=al9bfYTd5soprXwxAH0BAAAAf0s
[Tue Jul 21 08:43:57.367828 2026] [security2:error] [pid 511108:tid 511302] [client 212.32.76.4:58469] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/dist/vendor/about.php"] [unique_id "al9bfYTd5soprXwxAH0BAQAAAEA"]
[Tue Jul 21 08:43:57.369136 2026] [security2:error] [pid 511108:tid 511268] [client 69.171.230.42:54898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bfYTd5soprXwxAH0BAgAAAB4"]
[Tue Jul 21 08:43:57.507838 2026] [security2:error] [pid 511108:tid 511326] [client 61.1.167.83:59483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bfYTd5soprXwxAH0BAwAAAFg"]
[Tue Jul 21 08:43:57.507960 2026] [security2:error] [pid 511108:tid 511326] [client 61.1.167.83:59483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bfYTd5soprXwxAH0BAwAAAFg"]
[Tue Jul 21 08:43:57.568276 2026] [security2:error] [pid 511108:tid 511264] [client 203.25.124.3:51365] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/archives/"] [unique_id "al9bfYTd5soprXwxAH0BBQAAABo"]
[Tue Jul 21 08:43:57.627268 2026] [security2:error] [pid 514479:tid 514697] [client 20.206.105.145:51964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/adminfuns.php"] [unique_id "al9bffzqsQqnLoCgUjhiSgAAAV0"]
[Tue Jul 21 08:43:57.860717 2026] [security2:error] [pid 514479:tid 514721] [client 20.206.105.145:55713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/goods.php"] [unique_id "al9bffzqsQqnLoCgUjhiTgAAAXU"]
[Tue Jul 21 08:43:57.895430 2026] [qos:error] [pid 511108:tid 511196] [remote 57.141.18.8:53238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.8, id=al9bfYTd5soprXwxAH0BDQAAMFc
[Tue Jul 21 08:43:57.904285 2026] [security2:error] [pid 511108:tid 511322] [client 20.151.10.161:56432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/goods.php"] [unique_id "al9bfYTd5soprXwxAH0BDgAAAFQ"]
[Tue Jul 21 08:43:57.931973 2026] [security2:error] [pid 511108:tid 511254] [client 202.179.75.202:34168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bfYTd5soprXwxAH0BDwAAABA"]
[Tue Jul 21 08:43:57.932118 2026] [security2:error] [pid 511108:tid 511254] [client 202.179.75.202:34168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bfYTd5soprXwxAH0BDwAAABA"]
[Tue Jul 21 08:43:57.940713 2026] [security2:error] [pid 511108:tid 511252] [client 59.95.197.55:52911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bfYTd5soprXwxAH0BEAAAAA4"]
[Tue Jul 21 08:43:57.940802 2026] [security2:error] [pid 511108:tid 511252] [client 59.95.197.55:52911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bfYTd5soprXwxAH0BEAAAAA4"]
[Tue Jul 21 08:43:58.028610 2026] [qos:error] [pid 514479:tid 514568] [remote 57.141.18.53:36930] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.53, id=al9bfvzqsQqnLoCgUjhiTwABTFM
[Tue Jul 21 08:43:58.191266 2026] [security2:error] [pid 511108:tid 511207] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bfoTd5soprXwxAH0BFQAAUGI"]
[Tue Jul 21 08:43:58.191400 2026] [security2:error] [pid 511108:tid 511318] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bfoTd5soprXwxAH0BFQAAUGI"]
[Tue Jul 21 08:43:58.242195 2026] [security2:error] [pid 514479:tid 514681] [client 20.206.105.145:51942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/ms-edit.php"] [unique_id "al9bfvzqsQqnLoCgUjhiVgAAAU0"]
[Tue Jul 21 08:43:58.262207 2026] [security2:error] [pid 511108:tid 511334] [client 212.32.76.8:54327] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/footnotes/"] [unique_id "al9bfoTd5soprXwxAH0BFwAAAGA"]
[Tue Jul 21 08:43:58.275058 2026] [qos:error] [pid 511108:tid 511124] [remote 57.141.18.17:44046] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.17, id=al9bfoTd5soprXwxAH0BGAAAFg8
[Tue Jul 21 08:43:58.359492 2026] [security2:error] [pid 514479:tid 514722] [client 20.206.105.145:51937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/x.php"] [unique_id "al9bfvzqsQqnLoCgUjhiWAAAAXY"]
[Tue Jul 21 08:43:58.557933 2026] [security2:error] [pid 511108:tid 511307] [client 41.89.234.2:56150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bfoTd5soprXwxAH0BIAAAAEU"]
[Tue Jul 21 08:43:58.558064 2026] [security2:error] [pid 511108:tid 511307] [client 41.89.234.2:56150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bfoTd5soprXwxAH0BIAAAAEU"]
[Tue Jul 21 08:43:58.597512 2026] [qos:error] [pid 511108:tid 511151] [remote 57.141.18.47:62234] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.47, id=al9bfoTd5soprXwxAH0BIQAABCo
[Tue Jul 21 08:43:58.623139 2026] [security2:error] [pid 511108:tid 511265] [client 20.206.105.145:55786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/222.php"] [unique_id "al9bfoTd5soprXwxAH0BKQAAABs"]
[Tue Jul 21 08:43:58.674942 2026] [security2:error] [pid 514479:tid 514667] [client 203.25.124.5:28769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/includes/"] [unique_id "al9bfvzqsQqnLoCgUjhi1QAAAT8"]
[Tue Jul 21 08:43:58.722312 2026] [security2:error] [pid 511108:tid 511305] [client 20.151.10.161:30662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/ms-edit.php"] [unique_id "al9bfoTd5soprXwxAH0BLQAAAEM"]
[Tue Jul 21 08:43:58.734109 2026] [security2:error] [pid 514479:tid 514702] [client 122.176.100.127:54015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bfvzqsQqnLoCgUjhi1wAAAWI"]
[Tue Jul 21 08:43:58.734255 2026] [security2:error] [pid 514479:tid 514702] [client 122.176.100.127:54015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bfvzqsQqnLoCgUjhi1wAAAWI"]
[Tue Jul 21 08:43:58.773423 2026] [security2:error] [pid 511108:tid 511327] [client 117.213.202.34:52699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bfoTd5soprXwxAH0BLwAAAFk"]
[Tue Jul 21 08:43:58.773561 2026] [security2:error] [pid 511108:tid 511327] [client 117.213.202.34:52699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bfoTd5soprXwxAH0BLwAAAFk"]
[Tue Jul 21 08:43:58.819413 2026] [security2:error] [pid 511108:tid 511314] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bfoTd5soprXwxAH0BGQAAAEw"]
[Tue Jul 21 08:43:58.898701 2026] [qos:error] [pid 514479:tid 514599] [remote 57.141.18.0:51050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.0, id=al9bfvzqsQqnLoCgUjhi-wABQHI
[Tue Jul 21 08:43:58.933079 2026] [qos:error] [pid 514479:tid 514491] [remote 57.141.18.81:52142] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.81, id=al9bfvzqsQqnLoCgUjhi_QABYQc
[Tue Jul 21 08:43:59.114196 2026] [security2:error] [pid 514479:tid 514731] [client 20.206.105.145:55702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/wss.php"] [unique_id "al9bf_zqsQqnLoCgUjhi_wAAAX8"]
[Tue Jul 21 08:43:59.235102 2026] [security2:error] [pid 514479:tid 514625] [client 20.151.10.161:56387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/222.php"] [unique_id "al9bf_zqsQqnLoCgUjhjKgAAARU"]
[Tue Jul 21 08:43:59.242379 2026] [security2:error] [pid 514479:tid 514688] [client 20.206.105.145:55781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/cgi-bin/index.php"] [unique_id "al9bf_zqsQqnLoCgUjhjKwAAAVQ"]
[Tue Jul 21 08:43:59.251423 2026] [security2:error] [pid 511108:tid 511319] [client 152.59.181.104:54041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bf4Td5soprXwxAH0BPgAAAFE"]
[Tue Jul 21 08:43:59.251531 2026] [security2:error] [pid 511108:tid 511319] [client 152.59.181.104:54041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bf4Td5soprXwxAH0BPgAAAFE"]
[Tue Jul 21 08:43:59.273875 2026] [qos:error] [pid 511108:tid 511242] [client 162.241.63.68:50256] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9bf4Td5soprXwxAH0BPwAAAAQ
[Tue Jul 21 08:43:59.468485 2026] [security2:error] [pid 514479:tid 514636] [client 203.25.124.67:61703] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/pullquote/"] [unique_id "al9bf_zqsQqnLoCgUjhjLQAAASA"]
[Tue Jul 21 08:43:59.490907 2026] [security2:error] [pid 511108:tid 511349] [client 173.252.95.38:47296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bf4Td5soprXwxAH0BQwAAAG8"]
[Tue Jul 21 08:43:59.574914 2026] [security2:error] [pid 514479:tid 514622] [client 203.25.124.197:24739] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/x.php"] [unique_id "al9bf_zqsQqnLoCgUjhjLwAAARI"]
[Tue Jul 21 08:43:59.835454 2026] [security2:error] [pid 514479:tid 514685] [client 20.151.10.161:56442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/cgi-bin/index.php"] [unique_id "al9bf_zqsQqnLoCgUjhjOwAAAVE"]
[Tue Jul 21 08:44:00.278583 2026] [qos:error] [pid 514479:tid 514496] [remote 57.141.18.1:21804] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.1, id=al9bgPzqsQqnLoCgUjhjWwABRww
[Tue Jul 21 08:44:00.289356 2026] [qos:error] [pid 514479:tid 514599] [remote 57.141.18.15:55978] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.15, id=al9bgPzqsQqnLoCgUjhjXQABFnI
[Tue Jul 21 08:44:00.289941 2026] [qos:error] [pid 514479:tid 514646] [client 162.241.63.68:50270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9bgPzqsQqnLoCgUjhjXgAAASo
[Tue Jul 21 08:44:00.290285 2026] [qos:error] [pid 514479:tid 514664] [client 162.241.63.68:50262] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9bgPzqsQqnLoCgUjhjXwAAATw
[Tue Jul 21 08:44:00.367631 2026] [security2:error] [pid 511108:tid 511312] [client 203.25.124.50:47849] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/simple.php"] [unique_id "al9bgITd5soprXwxAH0BUAAAAEo"]
[Tue Jul 21 08:44:00.390507 2026] [security2:error] [pid 511108:tid 511276] [client 20.206.105.145:51929] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-includes/css/dist/"] [unique_id "al9bgITd5soprXwxAH0BUQAAACY"]
[Tue Jul 21 08:44:00.475731 2026] [security2:error] [pid 514479:tid 514647] [client 212.32.76.58:50031] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/admin.php"] [unique_id "al9bgPzqsQqnLoCgUjhjdAAAASs"]
[Tue Jul 21 08:44:00.476582 2026] [security2:error] [pid 514479:tid 514632] [client 20.206.105.145:55804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/ty.php"] [unique_id "al9bgPzqsQqnLoCgUjhjdQAAARw"]
[Tue Jul 21 08:44:00.650881 2026] [security2:error] [pid 514479:tid 514723] [client 168.167.81.163:59119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bgPzqsQqnLoCgUjhjiQAAAXc"]
[Tue Jul 21 08:44:00.650989 2026] [security2:error] [pid 514479:tid 514723] [client 168.167.81.163:59119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bgPzqsQqnLoCgUjhjiQAAAXc"]
[Tue Jul 21 08:44:00.691634 2026] [security2:error] [pid 511108:tid 511245] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bgITd5soprXwxAH0BVwAABzc"]
[Tue Jul 21 08:44:00.864781 2026] [qos:error] [pid 514479:tid 514566] [remote 57.141.18.111:58784] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.111, id=al9bgPzqsQqnLoCgUjhjsAABYVE
[Tue Jul 21 08:44:00.924225 2026] [security2:error] [pid 514479:tid 514647] [client 20.206.105.145:55790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/155.php"] [unique_id "al9bgPzqsQqnLoCgUjhjtAAAASs"]
[Tue Jul 21 08:44:01.238238 2026] [qos:error] [pid 514479:tid 514589] [remote 57.141.18.51:60796] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.51, id=al9bgfzqsQqnLoCgUjhjxAABU2g
[Tue Jul 21 08:44:01.268603 2026] [security2:error] [pid 514479:tid 514671] [client 203.25.124.41:55653] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/includes/admin.php"] [unique_id "al9bgfzqsQqnLoCgUjhjyAAAAUM"]
[Tue Jul 21 08:44:01.290678 2026] [qos:error] [pid 511108:tid 511282] [client 162.241.63.68:50274] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9bgYTd5soprXwxAH0BZAAAACw
[Tue Jul 21 08:44:01.342266 2026] [security2:error] [pid 514479:tid 514664] [client 20.226.60.151:58614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/autoload_classmap.php"] [unique_id "al9bgfzqsQqnLoCgUjhj0gAAATw"]
[Tue Jul 21 08:44:01.440396 2026] [security2:error] [pid 511108:tid 511272] [client 20.206.105.145:55739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/BDKR28WP.php"] [unique_id "al9bgYTd5soprXwxAH0BaAAAACI"]
[Tue Jul 21 08:44:01.473367 2026] [security2:error] [pid 514479:tid 514651] [client 203.25.124.251:47399] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/colors/light/"] [unique_id "al9bgfzqsQqnLoCgUjhj4wAAAS8"]
[Tue Jul 21 08:44:01.482317 2026] [autoindex:error] [pid 514479:tid 514701] [client 20.151.10.161:0] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:01.521158 2026] [security2:error] [pid 514479:tid 514728] [client 173.252.95.9:57432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bgfzqsQqnLoCgUjhj6gAAAXw"]
[Tue Jul 21 08:44:01.521574 2026] [security2:error] [pid 514479:tid 514682] [client 20.206.105.145:55789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/ops.php"] [unique_id "al9bgfzqsQqnLoCgUjhj6wAAAU4"]
[Tue Jul 21 08:44:01.643801 2026] [security2:error] [pid 514479:tid 514730] [client 20.151.10.161:56415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/BDKR28WP.php"] [unique_id "al9bgfzqsQqnLoCgUjhkAgAAAX4"]
[Tue Jul 21 08:44:01.655219 2026] [security2:error] [pid 514479:tid 514680] [client 64.42.179.43:53040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9bgfzqsQqnLoCgUjhkBQAAAUw"]
[Tue Jul 21 08:44:01.655303 2026] [security2:error] [pid 514479:tid 514680] [client 64.42.179.43:53040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9bgfzqsQqnLoCgUjhkBQAAAUw"]
[Tue Jul 21 08:44:02.071968 2026] [security2:error] [pid 514479:tid 514715] [client 20.206.105.145:55800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/ingfo.php"] [unique_id "al9bgvzqsQqnLoCgUjhkFwAAAW8"]
[Tue Jul 21 08:44:02.169783 2026] [security2:error] [pid 514479:tid 514662] [client 20.226.60.151:58616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-link-zorm.php"] [unique_id "al9bgvzqsQqnLoCgUjhkGQAAATo"]
[Tue Jul 21 08:44:02.239966 2026] [security2:error] [pid 511108:tid 511301] [client 20.226.60.151:58527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9bgoTd5soprXwxAH0BegAAAD8"]
[Tue Jul 21 08:44:02.265373 2026] [security2:error] [pid 511108:tid 511271] [client 20.206.105.145:55721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/error_log.php"] [unique_id "al9bgoTd5soprXwxAH0BewAAACE"]
[Tue Jul 21 08:44:02.268495 2026] [security2:error] [pid 514479:tid 514689] [client 203.25.124.37:56487] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/css/dist/reusable-blocks/"] [unique_id "al9bgvzqsQqnLoCgUjhkGwAAAVU"]
[Tue Jul 21 08:44:02.302953 2026] [security2:error] [pid 514479:tid 514720] [client 172.212.190.89:6461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "luanaarruda.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9bgvzqsQqnLoCgUjhkHQAAAXQ"]
[Tue Jul 21 08:44:02.346314 2026] [security2:error] [pid 514479:tid 514696] [client 20.226.60.151:34793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/albin.php"] [unique_id "al9bgvzqsQqnLoCgUjhkHwAAAVw"]
[Tue Jul 21 08:44:02.360014 2026] [security2:error] [pid 514479:tid 514694] [client 195.206.105.227:43690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9bgvzqsQqnLoCgUjhkIAAAAVo"]
[Tue Jul 21 08:44:02.360171 2026] [security2:error] [pid 514479:tid 514694] [client 195.206.105.227:43690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9bgvzqsQqnLoCgUjhkIAAAAVo"]
[Tue Jul 21 08:44:02.437689 2026] [security2:error] [pid 514479:tid 514626] [client 113.22.144.139:52581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bgvzqsQqnLoCgUjhkIQAAARY"]
[Tue Jul 21 08:44:02.438242 2026] [security2:error] [pid 514479:tid 514626] [client 113.22.144.139:52581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bgvzqsQqnLoCgUjhkIQAAARY"]
[Tue Jul 21 08:44:02.500844 2026] [security2:error] [pid 514479:tid 514685] [client 20.226.60.151:34836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/cilus.php"] [unique_id "al9bgvzqsQqnLoCgUjhkJAAAAVE"]
[Tue Jul 21 08:44:02.543911 2026] [qos:error] [pid 514479:tid 514561] [remote 57.141.18.32:53568] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.32, id=al9bgvzqsQqnLoCgUjhkKAABd0w
[Tue Jul 21 08:44:02.578992 2026] [security2:error] [pid 514479:tid 514657] [client 203.25.124.199:59829] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin.php"] [unique_id "al9bgvzqsQqnLoCgUjhkLAAAATU"]
[Tue Jul 21 08:44:02.586115 2026] [security2:error] [pid 514479:tid 514630] [client 20.206.105.145:51923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/ok.php"] [unique_id "al9bgvzqsQqnLoCgUjhkLQAAARo"]
[Tue Jul 21 08:44:02.649575 2026] [security2:error] [pid 511108:tid 511242] [client 136.67.17.243:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.17.67.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bgoTd5soprXwxAH0BggAAAAQ"]
[Tue Jul 21 08:44:02.734118 2026] [security2:error] [pid 511108:tid 511291] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bgoTd5soprXwxAH0BeQAAADU"]
[Tue Jul 21 08:44:02.751775 2026] [autoindex:error] [pid 514479:tid 514653] [client 20.151.10.161:0] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:02.760873 2026] [security2:error] [pid 511108:tid 511344] [client 20.206.105.145:51907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/mac.php"] [unique_id "al9bgoTd5soprXwxAH0BhgAAAGo"]
[Tue Jul 21 08:44:02.813384 2026] [qos:error] [pid 514479:tid 514517] [remote 57.141.18.77:48976] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.77, id=al9bgvzqsQqnLoCgUjhkNwABSiE
[Tue Jul 21 08:44:02.842853 2026] [security2:error] [pid 511108:tid 511310] [client 5.38.115.39:10823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bgoTd5soprXwxAH0BiQAAAEg"]
[Tue Jul 21 08:44:02.842968 2026] [security2:error] [pid 511108:tid 511310] [client 5.38.115.39:10823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bgoTd5soprXwxAH0BiQAAAEg"]
[Tue Jul 21 08:44:02.970059 2026] [security2:error] [pid 514479:tid 514704] [client 203.25.124.47:47659] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-signin.php"] [unique_id "al9bgvzqsQqnLoCgUjhkQAAAAWQ"]
[Tue Jul 21 08:44:02.989662 2026] [security2:error] [pid 514479:tid 514624] [client 20.206.105.145:51958] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-includes/l10n/"] [unique_id "al9bgvzqsQqnLoCgUjhkQgAAARQ"]
[Tue Jul 21 08:44:03.006754 2026] [security2:error] [pid 514479:tid 514702] [client 20.206.105.145:51896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/wefile.php"] [unique_id "al9bg_zqsQqnLoCgUjhkQwAAAWI"]
[Tue Jul 21 08:44:03.060677 2026] [security2:error] [pid 514479:tid 514650] [client 20.206.105.145:55685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9bg_zqsQqnLoCgUjhkRAAAAS4"]
[Tue Jul 21 08:44:03.077168 2026] [security2:error] [pid 514479:tid 514671] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9bg_zqsQqnLoCgUjhkRQAAAUM"]
[Tue Jul 21 08:44:03.164085 2026] [security2:error] [pid 511108:tid 511285] [client 20.206.105.145:51944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9bg4Td5soprXwxAH0BjwAAAC8"]
[Tue Jul 21 08:44:03.179596 2026] [autoindex:error] [pid 514479:tid 514725] [client 20.151.10.161:0] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:03.236253 2026] [security2:error] [pid 514479:tid 514659] [client 20.206.105.145:55805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/like.php"] [unique_id "al9bg_zqsQqnLoCgUjhkTAAAATc"]
[Tue Jul 21 08:44:03.261633 2026] [qos:error] [pid 514479:tid 514593] [remote 57.141.18.90:57594] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.90, id=al9bg_zqsQqnLoCgUjhkTQABXmw
[Tue Jul 21 08:44:03.289219 2026] [qos:error] [pid 511108:tid 511263] [client 162.241.63.68:50298] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=162.241.63.68, id=al9bg4Td5soprXwxAH0BlAAAABk
[Tue Jul 21 08:44:03.328384 2026] [security2:error] [pid 514479:tid 514737] [client 20.206.105.145:55718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/.well-known/about.php"] [unique_id "al9bg_zqsQqnLoCgUjhkTgAAAYU"]
[Tue Jul 21 08:44:03.339345 2026] [security2:error] [pid 514479:tid 514699] [client 20.151.10.161:56378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp.php"] [unique_id "al9bg_zqsQqnLoCgUjhkTwAAAV8"]
[Tue Jul 21 08:44:03.354868 2026] [security2:error] [pid 511108:tid 511254] [client 20.206.105.145:51924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9bg4Td5soprXwxAH0BlQAAABA"]
[Tue Jul 21 08:44:03.388071 2026] [security2:error] [pid 511108:tid 511363] [client 20.206.105.145:55697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/pucci.php"] [unique_id "al9bg4Td5soprXwxAH0BmQAAAH0"]
[Tue Jul 21 08:44:03.428580 2026] [security2:error] [pid 511108:tid 511317] [client 20.206.105.145:51963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/wp-temp.php"] [unique_id "al9bg4Td5soprXwxAH0BnAAAAE8"]
[Tue Jul 21 08:44:03.467860 2026] [security2:error] [pid 514479:tid 514646] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9bg_zqsQqnLoCgUjhkUgAAASo"]
[Tue Jul 21 08:44:03.529801 2026] [security2:error] [pid 511108:tid 511314] [client 20.206.105.145:55749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/xmu.php"] [unique_id "al9bg4Td5soprXwxAH0BngAAAEw"]
[Tue Jul 21 08:44:03.575704 2026] [security2:error] [pid 511108:tid 511261] [client 203.25.124.5:23755] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wa/"] [unique_id "al9bg4Td5soprXwxAH0BnwAAABc"]
[Tue Jul 21 08:44:03.585359 2026] [security2:error] [pid 511108:tid 511362] [client 20.206.105.145:55765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9bg4Td5soprXwxAH0BoAAAAHw"]
[Tue Jul 21 08:44:03.665283 2026] [security2:error] [pid 514479:tid 514625] [client 20.206.105.145:51955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/puc.php"] [unique_id "al9bg_zqsQqnLoCgUjhkVAAAARU"]
[Tue Jul 21 08:44:03.716749 2026] [security2:error] [pid 514479:tid 514487] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bg_zqsQqnLoCgUjhkVwABTAM"]
[Tue Jul 21 08:44:03.716884 2026] [security2:error] [pid 514479:tid 514680] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bg_zqsQqnLoCgUjhkVwABTAM"]
[Tue Jul 21 08:44:03.737754 2026] [security2:error] [pid 514479:tid 514648] [client 20.206.105.145:55761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/themes.php"] [unique_id "al9bg_zqsQqnLoCgUjhkWAAAASw"]
[Tue Jul 21 08:44:03.768130 2026] [security2:error] [pid 514479:tid 514728] [client 20.206.105.145:55691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/8.php"] [unique_id "al9bg_zqsQqnLoCgUjhkXQAAAXw"]
[Tue Jul 21 08:44:03.811093 2026] [security2:error] [pid 514479:tid 514662] [client 20.226.60.151:58621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/gptsh.php"] [unique_id "al9bg_zqsQqnLoCgUjhkXwAAATo"]
[Tue Jul 21 08:44:03.847129 2026] [security2:error] [pid 511108:tid 511312] [client 20.206.105.145:51878] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-content/uploads/"] [unique_id "al9bg4Td5soprXwxAH0BowAAAEo"]
[Tue Jul 21 08:44:03.859608 2026] [security2:error] [pid 511108:tid 511246] [client 203.25.124.51:62541] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/config.php"] [unique_id "al9bg4Td5soprXwxAH0BpQAAAAg"]
[Tue Jul 21 08:44:03.871679 2026] [security2:error] [pid 511108:tid 511249] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9bg4Td5soprXwxAH0BpwAAAAs"]
[Tue Jul 21 08:44:03.939171 2026] [security2:error] [pid 511108:tid 511319] [client 20.206.105.145:55698] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "alvesmacedo.com"] [uri "/1.php"] [unique_id "al9bg4Td5soprXwxAH0BqgAAAFE"]
[Tue Jul 21 08:44:03.939271 2026] [security2:error] [pid 511108:tid 511319] [client 20.206.105.145:55698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/1.php"] [unique_id "al9bg4Td5soprXwxAH0BqgAAAFE"]
[Tue Jul 21 08:44:04.052656 2026] [security2:error] [pid 511108:tid 511269] [client 74.7.241.182:47694] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "jbms.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9bhITd5soprXwxAH0BqwAAH2A"]
[Tue Jul 21 08:44:04.123831 2026] [security2:error] [pid 511108:tid 511346] [client 20.151.10.161:30687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/abcd.php"] [unique_id "al9bhITd5soprXwxAH0BrAAAAGw"]
[Tue Jul 21 08:44:04.136005 2026] [security2:error] [pid 511108:tid 511271] [client 49.144.66.253:33787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bhITd5soprXwxAH0BrQAAACE"]
[Tue Jul 21 08:44:04.136120 2026] [security2:error] [pid 511108:tid 511271] [client 49.144.66.253:33787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bhITd5soprXwxAH0BrQAAACE"]
[Tue Jul 21 08:44:04.287982 2026] [security2:error] [pid 514479:tid 514704] [client 20.206.105.145:51906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/100.php"] [unique_id "al9bhPzqsQqnLoCgUjhkZAAAAWQ"]
[Tue Jul 21 08:44:04.320795 2026] [qos:error] [pid 511108:tid 511208] [remote 57.141.18.67:42802] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.67, id=al9bhITd5soprXwxAH0BsAAABmM
[Tue Jul 21 08:44:04.360917 2026] [security2:error] [pid 511108:tid 511357] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9bhITd5soprXwxAH0BsgAAAHc"]
[Tue Jul 21 08:44:04.508618 2026] [security2:error] [pid 514479:tid 514705] [client 20.206.105.145:55753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/about.php"] [unique_id "al9bhPzqsQqnLoCgUjhkZwAAAWU"]
[Tue Jul 21 08:44:04.597870 2026] [security2:error] [pid 514479:tid 514685] [client 20.151.10.161:56337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/a1.php"] [unique_id "al9bhPzqsQqnLoCgUjhkaAAAAVE"]
[Tue Jul 21 08:44:04.678165 2026] [security2:error] [pid 514479:tid 514671] [client 203.25.124.210:57337] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-file.php"] [unique_id "al9bhPzqsQqnLoCgUjhkaQAAAUM"]
[Tue Jul 21 08:44:04.743240 2026] [security2:error] [pid 514479:tid 514530] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bhPzqsQqnLoCgUjhkagABWi4"]
[Tue Jul 21 08:44:04.743431 2026] [security2:error] [pid 514479:tid 514694] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bhPzqsQqnLoCgUjhkagABWi4"]
[Tue Jul 21 08:44:04.763375 2026] [security2:error] [pid 514479:tid 514647] [client 212.32.76.7:40935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/freeform/"] [unique_id "al9bhPzqsQqnLoCgUjhkawAAASs"]
[Tue Jul 21 08:44:04.837945 2026] [security2:error] [pid 514479:tid 514721] [client 20.206.105.145:55771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/about.php"] [unique_id "al9bhPzqsQqnLoCgUjhkbAAAAXU"]
[Tue Jul 21 08:44:04.907949 2026] [security2:error] [pid 511108:tid 511363] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9bhITd5soprXwxAH0BvwAAAH0"]
[Tue Jul 21 08:44:05.031126 2026] [security2:error] [pid 514479:tid 514630] [client 20.206.105.145:55726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/admin.php"] [unique_id "al9bhfzqsQqnLoCgUjhkbgAAARo"]
[Tue Jul 21 08:44:05.083110 2026] [security2:error] [pid 514479:tid 514650] [client 195.49.128.211:63715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bhfzqsQqnLoCgUjhkbwAAAS4"]
[Tue Jul 21 08:44:05.083262 2026] [security2:error] [pid 514479:tid 514650] [client 195.49.128.211:63715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bhfzqsQqnLoCgUjhkbwAAAS4"]
[Tue Jul 21 08:44:05.104398 2026] [security2:error] [pid 511108:tid 511349] [client 103.59.206.240:31235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bhYTd5soprXwxAH0BwQAAAG8"]
[Tue Jul 21 08:44:05.104577 2026] [security2:error] [pid 511108:tid 511349] [client 103.59.206.240:31235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bhYTd5soprXwxAH0BwQAAAG8"]
[Tue Jul 21 08:44:05.329313 2026] [security2:error] [pid 511108:tid 511318] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9bhYTd5soprXwxAH0BxgAAAFA"]
[Tue Jul 21 08:44:05.352527 2026] [security2:error] [pid 511108:tid 511260] [client 20.206.105.145:51964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/admin.php"] [unique_id "al9bhYTd5soprXwxAH0BxwAAABY"]
[Tue Jul 21 08:44:05.362511 2026] [security2:error] [pid 511108:tid 511292] [client 20.151.10.161:30708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9bhYTd5soprXwxAH0ByAAAADY"]
[Tue Jul 21 08:44:05.473555 2026] [security2:error] [pid 514479:tid 514620] [client 198.44.157.34:53466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9bhfzqsQqnLoCgUjhkdAAAARA"]
[Tue Jul 21 08:44:05.473644 2026] [security2:error] [pid 514479:tid 514620] [client 198.44.157.34:53466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9bhfzqsQqnLoCgUjhkdAAAARA"]
[Tue Jul 21 08:44:05.561329 2026] [security2:error] [pid 511108:tid 511326] [client 20.197.192.193:3998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9bhYTd5soprXwxAH0BzwAAAFg"]
[Tue Jul 21 08:44:05.645260 2026] [security2:error] [pid 511108:tid 511346] [client 20.206.105.145:51930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/raw.php"] [unique_id "al9bhYTd5soprXwxAH0B0AAAAGw"]
[Tue Jul 21 08:44:05.727957 2026] [security2:error] [pid 511108:tid 511250] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9bhYTd5soprXwxAH0B0QAAAAw"]
[Tue Jul 21 08:44:05.769518 2026] [security2:error] [pid 514479:tid 514701] [client 20.206.105.145:51903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/edit.php"] [unique_id "al9bhfzqsQqnLoCgUjhkewAAAWE"]
[Tue Jul 21 08:44:05.868651 2026] [security2:error] [pid 511108:tid 511184] [remote 173.252.82.23:35912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9bhYTd5soprXwxAH0B1wAAG0s"]
[Tue Jul 21 08:44:05.877163 2026] [security2:error] [pid 514479:tid 514716] [client 203.25.124.181:32027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/info.php"] [unique_id "al9bhfzqsQqnLoCgUjhkfwAAAXA"]
[Tue Jul 21 08:44:05.931075 2026] [security2:error] [pid 511108:tid 511253] [client 20.206.105.145:51941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/abcd.php"] [unique_id "al9bhYTd5soprXwxAH0B2wAAAA8"]
[Tue Jul 21 08:44:05.960051 2026] [security2:error] [pid 511108:tid 511343] [client 20.206.105.145:55683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/a1.php"] [unique_id "al9bhYTd5soprXwxAH0B3QAAAGk"]
[Tue Jul 21 08:44:05.997770 2026] [security2:error] [pid 511108:tid 511254] [client 20.206.105.145:11162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9bhYTd5soprXwxAH0B4QAAABA"]
[Tue Jul 21 08:44:06.083598 2026] [security2:error] [pid 511108:tid 511349] [client 20.206.105.145:55740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9bhoTd5soprXwxAH0B4wAAAG8"]
[Tue Jul 21 08:44:06.120590 2026] [security2:error] [pid 514479:tid 514666] [client 20.206.105.145:55797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-content/BypassBest.php"] [unique_id "al9bhvzqsQqnLoCgUjhkhQAAAT4"]
[Tue Jul 21 08:44:06.165919 2026] [security2:error] [pid 514479:tid 514702] [client 203.25.124.64:34527] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/maintenance/"] [unique_id "al9bhvzqsQqnLoCgUjhkhgAAAWI"]
[Tue Jul 21 08:44:06.186085 2026] [security2:error] [pid 514479:tid 514626] [client 20.206.105.145:55735] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/wp-content/"] [unique_id "al9bhvzqsQqnLoCgUjhkhwAAARY"]
[Tue Jul 21 08:44:06.188085 2026] [security2:error] [pid 514479:tid 514685] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9bhvzqsQqnLoCgUjhkiAAAAVE"]
[Tue Jul 21 08:44:06.367570 2026] [security2:error] [pid 514479:tid 514721] [client 20.206.105.145:51919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/wp-content/admin.php"] [unique_id "al9bhvzqsQqnLoCgUjhkiwAAAXU"]
[Tue Jul 21 08:44:06.480798 2026] [security2:error] [pid 511108:tid 511266] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bhYTd5soprXwxAH0B3gAAABw"]
[Tue Jul 21 08:44:06.562827 2026] [security2:error] [pid 514479:tid 514659] [client 20.206.105.145:55782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/simple.php"] [unique_id "al9bhvzqsQqnLoCgUjhkjgAAATc"]
[Tue Jul 21 08:44:06.591451 2026] [security2:error] [pid 514479:tid 514730] [client 20.206.105.145:51917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/f6.php"] [unique_id "al9bhvzqsQqnLoCgUjhkjwAAAX4"]
[Tue Jul 21 08:44:06.631256 2026] [security2:error] [pid 514479:tid 514638] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9bhvzqsQqnLoCgUjhkkAAAASI"]
[Tue Jul 21 08:44:06.836989 2026] [security2:error] [pid 514479:tid 514674] [client 20.206.105.145:55742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/inputs.php"] [unique_id "al9bhvzqsQqnLoCgUjhkkwAAAUY"]
[Tue Jul 21 08:44:06.923478 2026] [security2:error] [pid 511108:tid 511240] [client 20.206.105.145:51850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/inputs.php"] [unique_id "al9bhoTd5soprXwxAH0B7wAAAAI"]
[Tue Jul 21 08:44:06.962447 2026] [security2:error] [pid 511108:tid 511350] [client 203.25.124.49:41781] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/module.php"] [unique_id "al9bhoTd5soprXwxAH0B8QAAAHA"]
[Tue Jul 21 08:44:07.068773 2026] [security2:error] [pid 514479:tid 514682] [client 20.206.105.145:51874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/av.php"] [unique_id "al9bh_zqsQqnLoCgUjhkmgAAAU4"]
[Tue Jul 21 08:44:07.071469 2026] [security2:error] [pid 514479:tid 514648] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9bh_zqsQqnLoCgUjhkmwAAASw"]
[Tue Jul 21 08:44:07.141030 2026] [security2:error] [pid 511108:tid 511238] [client 20.226.60.151:34835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/rithin.php"] [unique_id "al9bh4Td5soprXwxAH0B9gAAAAA"]
[Tue Jul 21 08:44:07.145265 2026] [security2:error] [pid 514479:tid 514676] [client 20.206.105.145:55752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/xxx.php"] [unique_id "al9bh_zqsQqnLoCgUjhknAAAAUg"]
[Tue Jul 21 08:44:07.230184 2026] [security2:error] [pid 514479:tid 514632] [client 20.206.105.145:55744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/classwithtostring.php"] [unique_id "al9bh_zqsQqnLoCgUjhknQAAARw"]
[Tue Jul 21 08:44:07.362026 2026] [security2:error] [pid 514479:tid 514615] [client 64.42.179.43:53046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9bh_zqsQqnLoCgUjhkngAAAQs"]
[Tue Jul 21 08:44:07.362203 2026] [security2:error] [pid 514479:tid 514615] [client 64.42.179.43:53046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9bh_zqsQqnLoCgUjhkngAAAQs"]
[Tue Jul 21 08:44:07.390922 2026] [security2:error] [pid 511108:tid 511358] [client 195.49.128.211:55244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bh4Td5soprXwxAH0B-gAAAHg"]
[Tue Jul 21 08:44:07.391050 2026] [security2:error] [pid 511108:tid 511358] [client 195.49.128.211:55244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bh4Td5soprXwxAH0B-gAAAHg"]
[Tue Jul 21 08:44:07.407883 2026] [security2:error] [pid 514479:tid 514660] [client 20.197.192.193:27086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/old.php"] [unique_id "al9bh_zqsQqnLoCgUjhkoQAAATg"]
[Tue Jul 21 08:44:07.458156 2026] [security2:error] [pid 514479:tid 514702] [client 20.206.105.145:51918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9bh_zqsQqnLoCgUjhkowAAAWI"]
[Tue Jul 21 08:44:07.473669 2026] [security2:error] [pid 514479:tid 514705] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9bh_zqsQqnLoCgUjhkpQAAAWU"]
[Tue Jul 21 08:44:07.505559 2026] [security2:error] [pid 514479:tid 514685] [client 20.206.105.145:51960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/wp-blog.php"] [unique_id "al9bh_zqsQqnLoCgUjhkpgAAAVE"]
[Tue Jul 21 08:44:07.543170 2026] [security2:error] [pid 511108:tid 511302] [client 198.44.157.34:53470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9bh4Td5soprXwxAH0B_QAAAEA"]
[Tue Jul 21 08:44:07.543330 2026] [security2:error] [pid 511108:tid 511302] [client 198.44.157.34:53470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9bh4Td5soprXwxAH0B_QAAAEA"]
[Tue Jul 21 08:44:07.591155 2026] [security2:error] [pid 514479:tid 514708] [client 20.206.105.145:55681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/wp-content/admin.php"] [unique_id "al9bh_zqsQqnLoCgUjhkqgAAAWg"]
[Tue Jul 21 08:44:07.692726 2026] [security2:error] [pid 514479:tid 514694] [client 20.206.105.145:51885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/adminfuns.php"] [unique_id "al9bh_zqsQqnLoCgUjhkqwAAAVo"]
[Tue Jul 21 08:44:07.850098 2026] [security2:error] [pid 511108:tid 511268] [client 20.206.105.145:51948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alvesmacedo.com"] [uri "/goods.php"] [unique_id "al9bh4Td5soprXwxAH0CAgAAAB4"]
[Tue Jul 21 08:44:07.865590 2026] [security2:error] [pid 514479:tid 514650] [client 203.25.124.212:37199] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Requests/chosen.php"] [unique_id "al9bh_zqsQqnLoCgUjhkrgAAAS4"]
[Tue Jul 21 08:44:07.889557 2026] [security2:error] [pid 514479:tid 514730] [client 136.67.17.243:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9bh_zqsQqnLoCgUjhksgAAAX4"]
[Tue Jul 21 08:44:07.996104 2026] [security2:error] [pid 514479:tid 514699] [client 20.206.105.145:55711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.bomtempo.eng.br"] [uri "/hypo.php"] [unique_id "al9bh_zqsQqnLoCgUjhktQAAAV8"]
[Tue Jul 21 08:44:08.170162 2026] [security2:error] [pid 514479:tid 514682] [client 212.32.76.54:49095] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/ID3/"] [unique_id "al9biPzqsQqnLoCgUjhkugAAAU4"]
[Tue Jul 21 08:44:08.323122 2026] [security2:error] [pid 514479:tid 514715] [client 20.197.192.193:41513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9biPzqsQqnLoCgUjhkvAAAAW8"]
[Tue Jul 21 08:44:08.478791 2026] [security2:error] [pid 514479:tid 514630] [client 59.95.197.55:53383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9biPzqsQqnLoCgUjhkwAAAARo"]
[Tue Jul 21 08:44:08.478957 2026] [security2:error] [pid 514479:tid 514630] [client 59.95.197.55:53383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9biPzqsQqnLoCgUjhkwAAAARo"]
[Tue Jul 21 08:44:08.519841 2026] [security2:error] [pid 514479:tid 514704] [client 173.252.95.23:46310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9biPzqsQqnLoCgUjhkwgAAAWQ"]
[Tue Jul 21 08:44:08.630435 2026] [security2:error] [pid 511108:tid 511263] [client 69.171.230.6:64082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9biITd5soprXwxAH0CEgAAABk"]
[Tue Jul 21 08:44:08.768225 2026] [security2:error] [pid 511108:tid 511318] [client 203.25.124.69:43525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/admin.php"] [unique_id "al9biITd5soprXwxAH0CFwAAAFA"]
[Tue Jul 21 08:44:08.796495 2026] [security2:error] [pid 511108:tid 511213] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9biITd5soprXwxAH0CGQAAc2g"]
[Tue Jul 21 08:44:08.796765 2026] [security2:error] [pid 511108:tid 511353] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9biITd5soprXwxAH0CGQAAc2g"]
[Tue Jul 21 08:44:08.803683 2026] [security2:error] [pid 511108:tid 511264] [client 114.198.138.124:62906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9biITd5soprXwxAH0CGAAAABo"]
[Tue Jul 21 08:44:08.803803 2026] [security2:error] [pid 511108:tid 511264] [client 114.198.138.124:62906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9biITd5soprXwxAH0CGAAAABo"]
[Tue Jul 21 08:44:08.827438 2026] [security2:error] [pid 514479:tid 514689] [client 202.179.75.202:33452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9biPzqsQqnLoCgUjhkxwAAAVU"]
[Tue Jul 21 08:44:08.827529 2026] [security2:error] [pid 514479:tid 514689] [client 202.179.75.202:33452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9biPzqsQqnLoCgUjhkxwAAAVU"]
[Tue Jul 21 08:44:08.974851 2026] [security2:error] [pid 511108:tid 511319] [client 20.151.10.161:30697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9biITd5soprXwxAH0CHAAAAFE"]
[Tue Jul 21 08:44:09.158988 2026] [security2:error] [pid 514479:tid 514726] [client 69.171.230.15:49798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bifzqsQqnLoCgUjhkygAAAXo"]
[Tue Jul 21 08:44:09.264981 2026] [security2:error] [pid 514479:tid 514708] [client 122.176.100.127:54718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bifzqsQqnLoCgUjhkzgAAAWg"]
[Tue Jul 21 08:44:09.265151 2026] [security2:error] [pid 514479:tid 514708] [client 122.176.100.127:54718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bifzqsQqnLoCgUjhkzgAAAWg"]
[Tue Jul 21 08:44:09.280714 2026] [security2:error] [pid 511108:tid 511271] [client 69.171.230.23:57020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9biYTd5soprXwxAH0CIgAAACE"]
[Tue Jul 21 08:44:09.406874 2026] [security2:error] [pid 514479:tid 514727] [client 20.151.10.161:30703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/gettest.php"] [unique_id "al9bifzqsQqnLoCgUjhkzwAAAXs"]
[Tue Jul 21 08:44:09.507536 2026] [security2:error] [pid 514479:tid 514654] [client 117.213.202.34:53295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bifzqsQqnLoCgUjhk0AAAATI"]
[Tue Jul 21 08:44:09.507689 2026] [security2:error] [pid 514479:tid 514654] [client 117.213.202.34:53295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bifzqsQqnLoCgUjhk0AAAATI"]
[Tue Jul 21 08:44:09.563572 2026] [security2:error] [pid 511108:tid 511328] [client 212.32.76.12:32687] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/block-patterns/chosen.php"] [unique_id "al9biYTd5soprXwxAH0CJgAAAFo"]
[Tue Jul 21 08:44:09.828671 2026] [security2:error] [pid 514479:tid 514731] [client 69.171.230.40:62756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bifzqsQqnLoCgUjhk1QAAAX8"]
[Tue Jul 21 08:44:09.986964 2026] [security2:error] [pid 514479:tid 514615] [client 212.32.76.63:54225] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/index/function.php"] [unique_id "al9bifzqsQqnLoCgUjhk2AAAAQs"]
[Tue Jul 21 08:44:09.998112 2026] [security2:error] [pid 511108:tid 511311] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9biYTd5soprXwxAH0CJAAAAEk"]
[Tue Jul 21 08:44:10.087501 2026] [security2:error] [pid 514479:tid 514722] [client 152.59.181.104:50957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bivzqsQqnLoCgUjhk3gAAAXY"]
[Tue Jul 21 08:44:10.087619 2026] [security2:error] [pid 514479:tid 514722] [client 152.59.181.104:50957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bivzqsQqnLoCgUjhk3gAAAXY"]
[Tue Jul 21 08:44:10.092473 2026] [security2:error] [pid 511108:tid 511298] [client 41.89.234.2:57030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bioTd5soprXwxAH0CMgAAADw"]
[Tue Jul 21 08:44:10.092608 2026] [security2:error] [pid 511108:tid 511298] [client 41.89.234.2:57030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bioTd5soprXwxAH0CMgAAADw"]
[Tue Jul 21 08:44:10.121011 2026] [security2:error] [pid 514479:tid 514626] [client 20.226.60.151:58586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/fffm.php"] [unique_id "al9bivzqsQqnLoCgUjhk3wAAARY"]
[Tue Jul 21 08:44:10.177336 2026] [security2:error] [pid 514479:tid 514636] [client 69.171.230.43:36988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bivzqsQqnLoCgUjhk2QAAASA"]
[Tue Jul 21 08:44:10.465065 2026] [security2:error] [pid 514479:tid 514741] [client 212.32.76.10:32537] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/ws.php"] [unique_id "al9bivzqsQqnLoCgUjhk5gAAAYk"]
[Tue Jul 21 08:44:10.522602 2026] [security2:error] [pid 511108:tid 511297] [client 20.151.10.161:30627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/simple.php"] [unique_id "al9bioTd5soprXwxAH0CPgAAADs"]
[Tue Jul 21 08:44:10.568878 2026] [security2:error] [pid 514479:tid 514620] [client 74.7.230.41:59276] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "arkos.ia.br"] [uri "/cgi-sys/404.html"] [unique_id "al9bivzqsQqnLoCgUjhk5wABEFs"]
[Tue Jul 21 08:44:10.793765 2026] [security2:error] [pid 514479:tid 514699] [client 20.197.192.193:27148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/ms-new.php"] [unique_id "al9bivzqsQqnLoCgUjhk6gAAAV8"]
[Tue Jul 21 08:44:10.873797 2026] [security2:error] [pid 514479:tid 514681] [client 203.25.124.254:28179] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/upgrade/"] [unique_id "al9bivzqsQqnLoCgUjhk6wAAAU0"]
[Tue Jul 21 08:44:10.965143 2026] [security2:error] [pid 514479:tid 514653] [client 20.151.10.161:56327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/xxx.php"] [unique_id "al9bivzqsQqnLoCgUjhk7wAAATE"]
[Tue Jul 21 08:44:11.078969 2026] [proxy:error] [pid 514479:tid 514674] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:11.079010 2026] [proxy_http:error] [pid 514479:tid 514674] [client 198.235.24.89:59118] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:11.079867 2026] [proxy:error] [pid 514479:tid 514674] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:11.079897 2026] [proxy_http:error] [pid 514479:tid 514674] [client 198.235.24.89:59118] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:11.121424 2026] [security2:error] [pid 514479:tid 514671] [client 168.167.81.163:61687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bi_zqsQqnLoCgUjhk8QAAAUM"]
[Tue Jul 21 08:44:11.121547 2026] [security2:error] [pid 514479:tid 514671] [client 168.167.81.163:61687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bi_zqsQqnLoCgUjhk8QAAAUM"]
[Tue Jul 21 08:44:11.239064 2026] [security2:error] [pid 511108:tid 511358] [client 69.171.230.39:62342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bi4Td5soprXwxAH0CTwAAAHg"]
[Tue Jul 21 08:44:11.276055 2026] [security2:error] [pid 511108:tid 511329] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bi4Td5soprXwxAH0CTQAAWxE"]
[Tue Jul 21 08:44:11.466902 2026] [security2:error] [pid 511108:tid 511363] [client 203.25.124.42:45959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/tinymce/plugins/wp-load.php"] [unique_id "al9bi4Td5soprXwxAH0CUAAAAH0"]
[Tue Jul 21 08:44:11.516213 2026] [security2:error] [pid 511108:tid 511169] [remote 91.142.222.105:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tavarescont.com.br"] [uri "/wp-login.php"] [unique_id "al9bi4Td5soprXwxAH0CUQAAIjw"]
[Tue Jul 21 08:44:11.606418 2026] [security2:error] [pid 511108:tid 511281] [client 20.151.10.161:56416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/hypo.php"] [unique_id "al9bi4Td5soprXwxAH0CVAAAACs"]
[Tue Jul 21 08:44:11.712171 2026] [security2:error] [pid 511108:tid 511299] [client 69.171.230.43:37002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bi4Td5soprXwxAH0CWQAAAD0"]
[Tue Jul 21 08:44:11.714202 2026] [security2:error] [pid 511108:tid 511232] [remote 41.185.8.147:39872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.8.185.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bestsellerdigital.com.br"] [uri "/wp-login.php"] [unique_id "al9bi4Td5soprXwxAH0CUgAAdns"]
[Tue Jul 21 08:44:12.075510 2026] [security2:error] [pid 511108:tid 511287] [client 203.25.124.9:63905] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/edit-tags.php"] [unique_id "al9bjITd5soprXwxAH0CXwAAADE"]
[Tue Jul 21 08:44:12.325712 2026] [security2:error] [pid 511108:tid 511343] [client 5.31.193.106:58623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bjITd5soprXwxAH0CZQAAAGk"]
[Tue Jul 21 08:44:12.325985 2026] [security2:error] [pid 511108:tid 511343] [client 5.31.193.106:58623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bjITd5soprXwxAH0CZQAAAGk"]
[Tue Jul 21 08:44:12.406850 2026] [autoindex:error] [pid 511108:tid 511242] [client 20.151.10.161:56385] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:12.464928 2026] [security2:error] [pid 511108:tid 511354] [client 203.25.124.68:21319] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "al9bjITd5soprXwxAH0CbAAAAHQ"]
[Tue Jul 21 08:44:12.810391 2026] [security2:error] [pid 514479:tid 514689] [client 20.151.10.161:30675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/chosen.php"] [unique_id "al9bjPzqsQqnLoCgUjhlAQAAAVU"]
[Tue Jul 21 08:44:12.841317 2026] [security2:error] [pid 514479:tid 514615] [client 113.22.144.139:53062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bjPzqsQqnLoCgUjhlAgAAAQs"]
[Tue Jul 21 08:44:12.841409 2026] [security2:error] [pid 514479:tid 514615] [client 113.22.144.139:53062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bjPzqsQqnLoCgUjhlAgAAAQs"]
[Tue Jul 21 08:44:13.220112 2026] [security2:error] [pid 511108:tid 511358] [client 20.197.192.193:27189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/track.php"] [unique_id "al9bjYTd5soprXwxAH0CeQAAAHg"]
[Tue Jul 21 08:44:13.271986 2026] [security2:error] [pid 511108:tid 511243] [client 203.25.124.189:43155] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/log.php"] [unique_id "al9bjYTd5soprXwxAH0CewAAAAU"]
[Tue Jul 21 08:44:13.419715 2026] [security2:error] [pid 511108:tid 511281] [client 20.197.192.193:27073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/2352356666.php"] [unique_id "al9bjYTd5soprXwxAH0CgAAAACs"]
[Tue Jul 21 08:44:13.465523 2026] [security2:error] [pid 514479:tid 514657] [client 203.25.124.74:44073] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/simple.php"] [unique_id "al9bjfzqsQqnLoCgUjhlBQAAATU"]
[Tue Jul 21 08:44:13.472079 2026] [security2:error] [pid 514479:tid 514655] [client 5.38.115.39:58662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bjfzqsQqnLoCgUjhlBgAAATM"]
[Tue Jul 21 08:44:13.472210 2026] [security2:error] [pid 514479:tid 514655] [client 5.38.115.39:58662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bjfzqsQqnLoCgUjhlBgAAATM"]
[Tue Jul 21 08:44:13.502023 2026] [security2:error] [pid 514479:tid 514668] [client 20.197.192.193:27144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/pn.php"] [unique_id "al9bjfzqsQqnLoCgUjhlBwAAAUA"]
[Tue Jul 21 08:44:13.571892 2026] [security2:error] [pid 514479:tid 514661] [client 20.226.60.151:34852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/dfre.php"] [unique_id "al9bjfzqsQqnLoCgUjhlCwAAATk"]
[Tue Jul 21 08:44:13.614207 2026] [security2:error] [pid 511108:tid 511323] [client 20.197.192.193:27184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-wpbak.php"] [unique_id "al9bjYTd5soprXwxAH0CggAAAFU"]
[Tue Jul 21 08:44:13.676255 2026] [security2:error] [pid 511108:tid 511348] [client 20.197.192.193:27149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/dr.php"] [unique_id "al9bjYTd5soprXwxAH0CgwAAAG4"]
[Tue Jul 21 08:44:13.715397 2026] [autoindex:error] [pid 514479:tid 514726] [client 20.151.10.161:0] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:13.781191 2026] [security2:error] [pid 511108:tid 511363] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bjYTd5soprXwxAH0CfwAAAH0"]
[Tue Jul 21 08:44:13.867582 2026] [security2:error] [pid 514479:tid 514653] [client 20.151.10.161:56339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/als.php"] [unique_id "al9bjfzqsQqnLoCgUjhlDwAAATE"]
[Tue Jul 21 08:44:14.164752 2026] [security2:error] [pid 511108:tid 511353] [client 203.25.124.58:23367] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/link/"] [unique_id "al9bjoTd5soprXwxAH0CkAAAAHM"]
[Tue Jul 21 08:44:14.231161 2026] [security2:error] [pid 511108:tid 511161] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bjoTd5soprXwxAH0CkQAAGjQ"]
[Tue Jul 21 08:44:14.231349 2026] [security2:error] [pid 511108:tid 511264] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bjoTd5soprXwxAH0CkQAAGjQ"]
[Tue Jul 21 08:44:14.231398 2026] [security2:error] [pid 514479:tid 514648] [client 20.197.192.193:27081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/2x.php"] [unique_id "al9bjvzqsQqnLoCgUjhlEgAAASw"]
[Tue Jul 21 08:44:14.411724 2026] [security2:error] [pid 511108:tid 511244] [client 20.151.10.161:56440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/pol.php"] [unique_id "al9bjoTd5soprXwxAH0ClgAAAAY"]
[Tue Jul 21 08:44:14.462344 2026] [security2:error] [pid 514479:tid 514651] [client 20.197.192.193:4094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/dp.php"] [unique_id "al9bjvzqsQqnLoCgUjhlGQAAAS8"]
[Tue Jul 21 08:44:14.469835 2026] [security2:error] [pid 514479:tid 514623] [client 212.32.76.55:42871] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/bless.php"] [unique_id "al9bjvzqsQqnLoCgUjhlGgAAARM"]
[Tue Jul 21 08:44:14.639238 2026] [security2:error] [pid 514479:tid 514716] [client 69.171.230.114:39654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bjvzqsQqnLoCgUjhlHQAAAXA"]
[Tue Jul 21 08:44:14.780255 2026] [security2:error] [pid 514479:tid 514625] [client 69.171.230.38:39768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bjvzqsQqnLoCgUjhlIQAAARU"]
[Tue Jul 21 08:44:14.842501 2026] [security2:error] [pid 514479:tid 514721] [client 20.151.10.161:30663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/file5.php"] [unique_id "al9bjvzqsQqnLoCgUjhlIgAAAXU"]
[Tue Jul 21 08:44:15.168791 2026] [security2:error] [pid 514479:tid 514615] [client 212.32.76.8:25363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/config.php"] [unique_id "al9bj_zqsQqnLoCgUjhlIwAAAQs"]
[Tue Jul 21 08:44:15.192803 2026] [security2:error] [pid 514479:tid 514685] [client 49.144.66.253:30168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bj_zqsQqnLoCgUjhlJAAAAVE"]
[Tue Jul 21 08:44:15.192912 2026] [security2:error] [pid 514479:tid 514685] [client 49.144.66.253:30168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bj_zqsQqnLoCgUjhlJAAAAVE"]
[Tue Jul 21 08:44:15.201610 2026] [security2:error] [pid 514479:tid 514698] [client 20.151.10.161:56376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9bj_zqsQqnLoCgUjhlJQAAAV4"]
[Tue Jul 21 08:44:15.287716 2026] [security2:error] [pid 511108:tid 511233] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bj4Td5soprXwxAH0CoQAATnw"]
[Tue Jul 21 08:44:15.287957 2026] [security2:error] [pid 511108:tid 511316] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bj4Td5soprXwxAH0CoQAATnw"]
[Tue Jul 21 08:44:15.608987 2026] [security2:error] [pid 511108:tid 511250] [client 114.198.138.124:63638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9bj4Td5soprXwxAH0CpwAAAAw"]
[Tue Jul 21 08:44:15.609118 2026] [security2:error] [pid 511108:tid 511250] [client 114.198.138.124:63638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9bj4Td5soprXwxAH0CpwAAAAw"]
[Tue Jul 21 08:44:15.647777 2026] [security2:error] [pid 514479:tid 514726] [client 20.151.10.161:30603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/file.php"] [unique_id "al9bj_zqsQqnLoCgUjhlKwAAAXo"]
[Tue Jul 21 08:44:15.692440 2026] [security2:error] [pid 514479:tid 514694] [client 195.49.128.211:64380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bj_zqsQqnLoCgUjhlLgAAAVo"]
[Tue Jul 21 08:44:15.692533 2026] [security2:error] [pid 514479:tid 514694] [client 195.49.128.211:64380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bj_zqsQqnLoCgUjhlLgAAAVo"]
[Tue Jul 21 08:44:15.749810 2026] [security2:error] [pid 511108:tid 511294] [client 103.59.206.240:31087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bj4Td5soprXwxAH0CqAAAADg"]
[Tue Jul 21 08:44:15.749962 2026] [security2:error] [pid 511108:tid 511294] [client 103.59.206.240:31087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bj4Td5soprXwxAH0CqAAAADg"]
[Tue Jul 21 08:44:15.760957 2026] [security2:error] [pid 514479:tid 514592] [remote 51.222.168.150:20466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "blog.importeicomponentes.com.br"] [uri "/glossario/isolador-optico-guia-completo/"] [unique_id "al9bj_zqsQqnLoCgUjhlMAABOWs"]
[Tue Jul 21 08:44:15.761100 2026] [security2:error] [pid 514479:tid 514661] [client 51.222.168.150:20466] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "blog.importeicomponentes.com.br"] [uri "/glossario/isolador-optico-guia-completo/"] [unique_id "al9bj_zqsQqnLoCgUjhlMAABOWs"]
[Tue Jul 21 08:44:15.784610 2026] [security2:error] [pid 514479:tid 514664] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9bj_zqsQqnLoCgUjhlMQAAATw"]
[Tue Jul 21 08:44:16.095036 2026] [security2:error] [pid 511108:tid 511321] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bkITd5soprXwxAH0CsQAAAFM"]
[Tue Jul 21 08:44:16.126067 2026] [security2:error] [pid 511108:tid 511287] [client 20.226.60.151:34780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-happy.php"] [unique_id "al9bkITd5soprXwxAH0CsgAAADE"]
[Tue Jul 21 08:44:16.168627 2026] [security2:error] [pid 514479:tid 514629] [client 212.32.76.13:33161] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "al9bkPzqsQqnLoCgUjhlNQAAARk"]
[Tue Jul 21 08:44:16.177424 2026] [security2:error] [pid 511108:tid 511318] [client 212.32.76.54:55499] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Text/"] [unique_id "al9bkITd5soprXwxAH0CswAAAFA"]
[Tue Jul 21 08:44:16.185724 2026] [security2:error] [pid 514479:tid 514627] [client 20.151.10.161:30661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/cfile.php"] [unique_id "al9bkPzqsQqnLoCgUjhlNgAAARc"]
[Tue Jul 21 08:44:16.328719 2026] [security2:error] [pid 514479:tid 514712] [client 61.1.167.83:59984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bkPzqsQqnLoCgUjhlNwAAAWw"]
[Tue Jul 21 08:44:16.328894 2026] [security2:error] [pid 514479:tid 514712] [client 61.1.167.83:59984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bkPzqsQqnLoCgUjhlNwAAAWw"]
[Tue Jul 21 08:44:16.543302 2026] [security2:error] [pid 514479:tid 514702] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9bkPzqsQqnLoCgUjhlPQAAAWI"]
[Tue Jul 21 08:44:16.765900 2026] [security2:error] [pid 514479:tid 514626] [client 45.227.253.15:54882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.253.227.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/index.php/jk"] [unique_id "al9bkPzqsQqnLoCgUjhlRAAAARY"]
[Tue Jul 21 08:44:16.832050 2026] [security2:error] [pid 511108:tid 511285] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9bkITd5soprXwxAH0CvgAAAC8"]
[Tue Jul 21 08:44:17.036656 2026] [security2:error] [pid 511108:tid 511357] [client 20.151.10.161:56408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/class-wp.php"] [unique_id "al9bkYTd5soprXwxAH0CxgAAAHc"]
[Tue Jul 21 08:44:17.067851 2026] [security2:error] [pid 514479:tid 514650] [client 212.32.76.9:46721] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/codemirror/"] [unique_id "al9bkfzqsQqnLoCgUjhlRwAAAS4"]
[Tue Jul 21 08:44:17.118193 2026] [security2:error] [pid 511108:tid 511243] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9bkYTd5soprXwxAH0CyAAAAAU"]
[Tue Jul 21 08:44:17.277489 2026] [security2:error] [pid 511108:tid 511246] [client 203.25.124.200:38195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/languages/themes/"] [unique_id "al9bkYTd5soprXwxAH0CyQAAAAg"]
[Tue Jul 21 08:44:17.322362 2026] [security2:error] [pid 511108:tid 511293] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bkITd5soprXwxAH0CvwAAADc"]
[Tue Jul 21 08:44:17.404317 2026] [security2:error] [pid 511108:tid 511329] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9bkYTd5soprXwxAH0CzAAAAFs"]
[Tue Jul 21 08:44:17.407851 2026] [security2:error] [pid 511108:tid 511242] [client 192.3.56.200:53437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.56.3.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9bkYTd5soprXwxAH0CxwAAAAQ"], referer: https://valloratoodo.com/hello-world/
[Tue Jul 21 08:44:17.516419 2026] [access_compat:error] [pid 511108:tid 511298] [client 162.241.63.68:43900] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:44:17.546940 2026] [security2:error] [pid 511108:tid 511286] [client 173.252.95.26:55254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bkYTd5soprXwxAH0CywAAADA"]
[Tue Jul 21 08:44:17.601233 2026] [security2:error] [pid 511108:tid 511256] [client 20.151.10.161:30702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/admin.php"] [unique_id "al9bkYTd5soprXwxAH0C1gAAABI"]
[Tue Jul 21 08:44:17.689276 2026] [security2:error] [pid 511108:tid 511349] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9bkYTd5soprXwxAH0C1wAAAG8"]
[Tue Jul 21 08:44:17.854030 2026] [security2:error] [pid 511108:tid 511226] [remote 45.79.123.44:51934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9bkYTd5soprXwxAH0C2AAAIXU"]
[Tue Jul 21 08:44:17.969213 2026] [security2:error] [pid 511108:tid 511350] [client 20.151.10.161:30682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/aa2.php"] [unique_id "al9bkYTd5soprXwxAH0C3gAAAHA"]
[Tue Jul 21 08:44:17.969300 2026] [security2:error] [pid 514479:tid 514701] [client 203.25.124.47:53653] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/ab.php"] [unique_id "al9bkfzqsQqnLoCgUjhlTAAAAWE"]
[Tue Jul 21 08:44:17.975086 2026] [security2:error] [pid 514479:tid 514687] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9bkfzqsQqnLoCgUjhlTQAAAVM"]
[Tue Jul 21 08:44:18.003951 2026] [security2:error] [pid 511108:tid 511327] [client 195.49.128.211:55841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bkoTd5soprXwxAH0C3wAAAFk"]
[Tue Jul 21 08:44:18.004059 2026] [security2:error] [pid 511108:tid 511327] [client 195.49.128.211:55841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bkoTd5soprXwxAH0C3wAAAFk"]
[Tue Jul 21 08:44:18.179406 2026] [proxy:error] [pid 514479:tid 514719] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:18.179444 2026] [proxy_http:error] [pid 514479:tid 514719] [client 144.126.210.162:51328] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:18.179954 2026] [proxy:error] [pid 514479:tid 514719] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:18.179978 2026] [proxy_http:error] [pid 514479:tid 514719] [client 144.126.210.162:51328] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:18.261921 2026] [security2:error] [pid 511108:tid 511258] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9bkoTd5soprXwxAH0C5QAAABQ"]
[Tue Jul 21 08:44:18.345633 2026] [security2:error] [pid 514479:tid 514735] [client 192.3.56.200:34690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.56.3.192.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9bkvzqsQqnLoCgUjhlUgAAAYM"], referer: https://valloratoodo.com/hello-world/
[Tue Jul 21 08:44:18.436724 2026] [security2:error] [pid 514479:tid 514623] [client 20.151.10.161:30464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/ccou.php"] [unique_id "al9bkvzqsQqnLoCgUjhlUwAAARM"]
[Tue Jul 21 08:44:18.539214 2026] [proxy:error] [pid 514479:tid 514716] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:18.539287 2026] [proxy_http:error] [pid 514479:tid 514716] [client 144.126.210.162:51334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.locadoracmd.com.br/
[Tue Jul 21 08:44:18.539720 2026] [proxy:error] [pid 514479:tid 514716] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:18.539745 2026] [proxy_http:error] [pid 514479:tid 514716] [client 144.126.210.162:51334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.locadoracmd.com.br/
[Tue Jul 21 08:44:18.546470 2026] [security2:error] [pid 514479:tid 514693] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9bkvzqsQqnLoCgUjhlVgAAAVk"]
[Tue Jul 21 08:44:18.617485 2026] [proxy:error] [pid 514479:tid 514688] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:18.617548 2026] [proxy_http:error] [pid 514479:tid 514688] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:18.618052 2026] [proxy:error] [pid 514479:tid 514688] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:18.618086 2026] [proxy_http:error] [pid 514479:tid 514688] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:18.672572 2026] [security2:error] [pid 514479:tid 514660] [client 203.25.124.7:25761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/file-upload-types/assets/css/403.php"] [unique_id "al9bkvzqsQqnLoCgUjhlWgAAATg"]
[Tue Jul 21 08:44:18.768490 2026] [security2:error] [pid 514479:tid 514721] [client 203.25.124.51:36281] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/comments-pagination-numbers/"] [unique_id "al9bkvzqsQqnLoCgUjhlWwAAAXU"]
[Tue Jul 21 08:44:18.830764 2026] [security2:error] [pid 511108:tid 511264] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9bkoTd5soprXwxAH0C7QAAABo"]
[Tue Jul 21 08:44:18.907094 2026] [security2:error] [pid 514479:tid 514676] [client 20.151.10.161:56404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/dr.php"] [unique_id "al9bkvzqsQqnLoCgUjhlXQAAAUg"]
[Tue Jul 21 08:44:18.920395 2026] [security2:error] [pid 511108:tid 511270] [client 59.95.197.55:53860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bkoTd5soprXwxAH0C7gAAACA"]
[Tue Jul 21 08:44:18.921102 2026] [security2:error] [pid 511108:tid 511270] [client 59.95.197.55:53860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bkoTd5soprXwxAH0C7gAAACA"]
[Tue Jul 21 08:44:18.950231 2026] [security2:error] [pid 511108:tid 511227] [remote 72.167.132.114:44932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-login.php"] [unique_id "al9bkoTd5soprXwxAH0C8QAAH3Y"]
[Tue Jul 21 08:44:19.022532 2026] [proxy:error] [pid 511108:tid 511361] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:19.022597 2026] [proxy_http:error] [pid 511108:tid 511361] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:19.023282 2026] [proxy:error] [pid 511108:tid 511361] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:19.023320 2026] [proxy_http:error] [pid 511108:tid 511361] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:19.116507 2026] [security2:error] [pid 511108:tid 511242] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9bk4Td5soprXwxAH0C9AAAAAQ"]
[Tue Jul 21 08:44:19.252404 2026] [security2:error] [pid 514479:tid 514650] [client 20.226.60.151:34828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/fpr4.php"] [unique_id "al9bk_zqsQqnLoCgUjhlZgAAAS4"]
[Tue Jul 21 08:44:19.342303 2026] [core:error] [pid 511108:tid 511298] [client 144.126.210.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:44:19.342337 2026] [core:error] [pid 511108:tid 511298] [client 144.126.210.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:44:19.352777 2026] [security2:error] [pid 511108:tid 511253] [client 20.151.10.161:56363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/xamp.php"] [unique_id "al9bk4Td5soprXwxAH0C-QAAAA8"]
[Tue Jul 21 08:44:19.372051 2026] [security2:error] [pid 514479:tid 514507] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bk_zqsQqnLoCgUjhlaQABXhc"]
[Tue Jul 21 08:44:19.372236 2026] [security2:error] [pid 514479:tid 514698] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bk_zqsQqnLoCgUjhlaQABXhc"]
[Tue Jul 21 08:44:19.400867 2026] [security2:error] [pid 511108:tid 511278] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9bk4Td5soprXwxAH0C-gAAACg"]
[Tue Jul 21 08:44:19.433001 2026] [proxy:error] [pid 511108:tid 511311] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:19.433086 2026] [proxy_http:error] [pid 511108:tid 511311] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:19.434365 2026] [proxy:error] [pid 511108:tid 511311] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:19.434422 2026] [proxy_http:error] [pid 511108:tid 511311] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:19.539347 2026] [security2:error] [pid 514479:tid 514699] [client 20.197.192.193:4055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/old.php"] [unique_id "al9bk_zqsQqnLoCgUjhlbAAAAV8"]
[Tue Jul 21 08:44:19.548522 2026] [rewrite:warn] [pid 511108:tid 511116] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:44:19.667676 2026] [security2:error] [pid 514479:tid 514618] [client 203.25.124.57:21801] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/post-featured-image/"] [unique_id "al9bk_zqsQqnLoCgUjhlcAAAAQ4"]
[Tue Jul 21 08:44:19.678461 2026] [security2:error] [pid 514479:tid 514667] [client 20.226.60.151:58570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/file88.php"] [unique_id "al9bk_zqsQqnLoCgUjhlcQAAAT8"]
[Tue Jul 21 08:44:19.687828 2026] [security2:error] [pid 514479:tid 514722] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9bk_zqsQqnLoCgUjhlcwAAAXY"]
[Tue Jul 21 08:44:19.725783 2026] [security2:error] [pid 511108:tid 511268] [client 122.176.100.127:55253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bk4Td5soprXwxAH0DBgAAAB4"]
[Tue Jul 21 08:44:19.725925 2026] [security2:error] [pid 511108:tid 511268] [client 122.176.100.127:55253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bk4Td5soprXwxAH0DBgAAAB4"]
[Tue Jul 21 08:44:19.776734 2026] [security2:error] [pid 511108:tid 511348] [client 202.179.75.202:54948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bk4Td5soprXwxAH0DCAAAAG4"]
[Tue Jul 21 08:44:19.776866 2026] [security2:error] [pid 511108:tid 511348] [client 202.179.75.202:54948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bk4Td5soprXwxAH0DCAAAAG4"]
[Tue Jul 21 08:44:19.831465 2026] [security2:error] [pid 514479:tid 514632] [client 20.151.10.161:30666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/bless.php"] [unique_id "al9bk_zqsQqnLoCgUjhldgAAARw"]
[Tue Jul 21 08:44:19.935559 2026] [security2:error] [pid 514479:tid 514675] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bk_zqsQqnLoCgUjhleAAAAUc"]
[Tue Jul 21 08:44:19.975573 2026] [security2:error] [pid 514479:tid 514631] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9bk_zqsQqnLoCgUjhlegAAARs"]
[Tue Jul 21 08:44:19.987376 2026] [security2:error] [pid 514479:tid 514735] [client 20.226.60.151:58531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/ccc.php"] [unique_id "al9bk_zqsQqnLoCgUjhlewAAAYM"]
[Tue Jul 21 08:44:20.015285 2026] [security2:error] [pid 511108:tid 511265] [client 117.213.202.34:53910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9blITd5soprXwxAH0DDQAAABs"]
[Tue Jul 21 08:44:20.015396 2026] [security2:error] [pid 511108:tid 511265] [client 117.213.202.34:53910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9blITd5soprXwxAH0DDQAAABs"]
[Tue Jul 21 08:44:20.072080 2026] [security2:error] [pid 511108:tid 511238] [client 203.25.124.182:23111] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/autoload_classmap.php"] [unique_id "al9blITd5soprXwxAH0DDwAAAAA"]
[Tue Jul 21 08:44:20.259846 2026] [security2:error] [pid 514479:tid 514688] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9blPzqsQqnLoCgUjhlggAAAVQ"]
[Tue Jul 21 08:44:20.300106 2026] [security2:error] [pid 514479:tid 514625] [client 20.151.10.161:30618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/file46.php"] [unique_id "al9blPzqsQqnLoCgUjhlgwAAARU"]
[Tue Jul 21 08:44:20.430219 2026] [security2:error] [pid 514479:tid 514679] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9blPzqsQqnLoCgUjhliQAAAUs"]
[Tue Jul 21 08:44:20.463683 2026] [security2:error] [pid 514479:tid 514697] [client 203.25.124.50:31913] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/wc-logs/"] [unique_id "al9blPzqsQqnLoCgUjhljAAAAV0"]
[Tue Jul 21 08:44:20.547331 2026] [security2:error] [pid 514479:tid 514647] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9blPzqsQqnLoCgUjhlkAAAASs"]
[Tue Jul 21 08:44:20.681553 2026] [security2:error] [pid 511108:tid 511293] [client 20.226.60.151:58510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/777.php"] [unique_id "al9blITd5soprXwxAH0DGQAAADc"]
[Tue Jul 21 08:44:20.699460 2026] [security2:error] [pid 514479:tid 514699] [client 20.151.10.161:30704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/eee.php"] [unique_id "al9blPzqsQqnLoCgUjhlkwAAAV8"]
[Tue Jul 21 08:44:20.831217 2026] [security2:error] [pid 511108:tid 511281] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "orneestudiocriativo1782822434171.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9blITd5soprXwxAH0DHQAAACs"]
[Tue Jul 21 08:44:20.879481 2026] [security2:error] [pid 514479:tid 514712] [client 152.59.181.104:55012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9blPzqsQqnLoCgUjhllwAAAWw"]
[Tue Jul 21 08:44:20.879650 2026] [security2:error] [pid 514479:tid 514712] [client 152.59.181.104:55012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9blPzqsQqnLoCgUjhllwAAAWw"]
[Tue Jul 21 08:44:20.881781 2026] [security2:error] [pid 514479:tid 514661] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9blPzqsQqnLoCgUjhlmAAAATk"]
[Tue Jul 21 08:44:20.931382 2026] [security2:error] [pid 511108:tid 511365] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9blITd5soprXwxAH0DFAAAAH8"]
[Tue Jul 21 08:44:21.081516 2026] [security2:error] [pid 514479:tid 514737] [client 203.25.124.251:61729] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/bolt.php"] [unique_id "al9blfzqsQqnLoCgUjhlnAAAAYU"]
[Tue Jul 21 08:44:21.083845 2026] [security2:error] [pid 514479:tid 514611] [remote 147.135.76.247:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.76.135.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "annaguimaraes.com.br"] [uri "/wp-login.php"] [unique_id "al9bk_zqsQqnLoCgUjhldwABYX4"], referer: http://annaguimaraes.com.br/wp-login.php
[Tue Jul 21 08:44:21.127191 2026] [security2:error] [pid 511108:tid 511314] [client 20.151.10.161:56371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/file25.php"] [unique_id "al9blYTd5soprXwxAH0DJQAAAEw"]
[Tue Jul 21 08:44:21.293996 2026] [security2:error] [pid 514479:tid 514651] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9blfzqsQqnLoCgUjhlngAAAS8"]
[Tue Jul 21 08:44:21.493911 2026] [security2:error] [pid 514479:tid 514492] [remote 147.135.76.247:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.76.135.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "annaguimaraes.com.br"] [uri "/administrator/index.php"] [unique_id "al9blfzqsQqnLoCgUjhloQABMgg"], referer: http://annaguimaraes.com.br/administrator/index.php
[Tue Jul 21 08:44:21.531715 2026] [security2:error] [pid 514479:tid 514624] [client 20.151.10.161:56426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/file48.php"] [unique_id "al9blfzqsQqnLoCgUjhlpQAAARQ"]
[Tue Jul 21 08:44:21.779711 2026] [security2:error] [pid 511108:tid 511355] [client 20.226.60.151:58524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/for.php"] [unique_id "al9blYTd5soprXwxAH0DQgAAAHU"]
[Tue Jul 21 08:44:21.790319 2026] [security2:error] [pid 514479:tid 514703] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9blfzqsQqnLoCgUjhlrAAAAWM"]
[Tue Jul 21 08:44:21.898782 2026] [security2:error] [pid 511108:tid 511220] [remote 147.135.76.247:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.76.135.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "annaguimaraes.com.br"] [uri "/api/index.php/v1/config/application"] [unique_id "al9blYTd5soprXwxAH0DRQAAYG8"], referer: http://annaguimaraes.com.br/api/index.php/v1/config/application?public=true
[Tue Jul 21 08:44:21.921025 2026] [security2:error] [pid 514479:tid 514655] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9blfzqsQqnLoCgUjhlrQABMxo"]
[Tue Jul 21 08:44:21.966354 2026] [security2:error] [pid 514479:tid 514708] [client 20.151.10.161:30528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/file6.php"] [unique_id "al9blfzqsQqnLoCgUjhlsgAAAWg"]
[Tue Jul 21 08:44:22.163507 2026] [security2:error] [pid 514479:tid 514661] [client 20.197.192.193:27076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/kq1.php"] [unique_id "al9blvzqsQqnLoCgUjhltwAAATk"]
[Tue Jul 21 08:44:22.207185 2026] [security2:error] [pid 511108:tid 511291] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9bloTd5soprXwxAH0DSQAAADU"]
[Tue Jul 21 08:44:22.558944 2026] [security2:error] [pid 511108:tid 511252] [client 203.25.124.66:53567] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/upload.php"] [unique_id "al9bloTd5soprXwxAH0DUAAAAA4"]
[Tue Jul 21 08:44:22.576576 2026] [security2:error] [pid 511108:tid 511249] [client 203.25.124.190:64029] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/maint/chosen.php"] [unique_id "al9bloTd5soprXwxAH0DUgAAAAs"]
[Tue Jul 21 08:44:22.631148 2026] [security2:error] [pid 511108:tid 511243] [client 20.151.10.161:56340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/a2.php"] [unique_id "al9bloTd5soprXwxAH0DUwAAAAU"]
[Tue Jul 21 08:44:22.875141 2026] [security2:error] [pid 514479:tid 514664] [client 168.167.81.163:60523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9blvzqsQqnLoCgUjhlwAAAATw"]
[Tue Jul 21 08:44:22.875246 2026] [security2:error] [pid 514479:tid 514664] [client 168.167.81.163:60523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9blvzqsQqnLoCgUjhlwAAAATw"]
[Tue Jul 21 08:44:22.885196 2026] [security2:error] [pid 511108:tid 511282] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9bloTd5soprXwxAH0DWgAAACw"]
[Tue Jul 21 08:44:22.942601 2026] [proxy:error] [pid 514479:tid 514702] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:22.942673 2026] [proxy_http:error] [pid 514479:tid 514702] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:22.943645 2026] [proxy:error] [pid 514479:tid 514702] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:22.943691 2026] [proxy_http:error] [pid 514479:tid 514702] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:23.110316 2026] [security2:error] [pid 511108:tid 511253] [client 20.151.10.161:30670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/file15.php"] [unique_id "al9bl4Td5soprXwxAH0DWwAAAA8"]
[Tue Jul 21 08:44:23.339003 2026] [proxy:error] [pid 514479:tid 514647] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:23.339103 2026] [proxy_http:error] [pid 514479:tid 514647] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:23.341381 2026] [proxy:error] [pid 514479:tid 514647] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:23.341468 2026] [proxy_http:error] [pid 514479:tid 514647] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:23.484468 2026] [security2:error] [pid 514479:tid 514633] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9bl_zqsQqnLoCgUjhlzwAAAR0"]
[Tue Jul 21 08:44:23.487035 2026] [security2:error] [pid 514479:tid 514726] [client 20.151.10.161:30599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/jp.php"] [unique_id "al9bl_zqsQqnLoCgUjhl0AAAAXo"]
[Tue Jul 21 08:44:23.504000 2026] [security2:error] [pid 514479:tid 514699] [client 20.226.60.151:34839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/ssla.php"] [unique_id "al9bl_zqsQqnLoCgUjhl0QAAAV8"]
[Tue Jul 21 08:44:23.615430 2026] [security2:error] [pid 511108:tid 511194] [remote 130.51.180.8:37276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9bl4Td5soprXwxAH0DYAAAPFU"]
[Tue Jul 21 08:44:23.681306 2026] [core:error] [pid 514479:tid 514687] [client 144.126.210.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcontacts.locadoracmd.com.br/
[Tue Jul 21 08:44:23.681326 2026] [core:error] [pid 514479:tid 514687] [client 144.126.210.162:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcontacts.locadoracmd.com.br/
[Tue Jul 21 08:44:23.776304 2026] [proxy:error] [pid 514479:tid 514671] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:23.776366 2026] [proxy_http:error] [pid 514479:tid 514671] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:23.777000 2026] [proxy:error] [pid 514479:tid 514671] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:23.777032 2026] [proxy_http:error] [pid 514479:tid 514671] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:23.778654 2026] [security2:error] [pid 514479:tid 514715] [client 20.151.10.161:30613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/f35.php"] [unique_id "al9bl_zqsQqnLoCgUjhl3wAAAW8"]
[Tue Jul 21 08:44:23.842192 2026] [security2:error] [pid 514479:tid 514737] [client 203.25.124.191:53247] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/xmlrpc.php"] [unique_id "al9bl_zqsQqnLoCgUjhl2QAAAYU"]
[Tue Jul 21 08:44:23.865369 2026] [security2:error] [pid 514479:tid 514728] [client 203.25.124.57:24949] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/maint/network/"] [unique_id "al9bl_zqsQqnLoCgUjhl4QAAAXw"]
[Tue Jul 21 08:44:23.909953 2026] [security2:error] [pid 511108:tid 511324] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9bl4Td5soprXwxAH0DaAAAAFY"]
[Tue Jul 21 08:44:24.066908 2026] [security2:error] [pid 514479:tid 514703] [client 113.22.144.139:53593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bmPzqsQqnLoCgUjhl5QAAAWM"]
[Tue Jul 21 08:44:24.067060 2026] [security2:error] [pid 514479:tid 514703] [client 113.22.144.139:53593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bmPzqsQqnLoCgUjhl5QAAAWM"]
[Tue Jul 21 08:44:24.091627 2026] [security2:error] [pid 514479:tid 514617] [client 20.151.10.161:30614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-load.php"] [unique_id "al9bmPzqsQqnLoCgUjhl5gAAAQ0"]
[Tue Jul 21 08:44:24.184337 2026] [security2:error] [pid 514479:tid 514681] [client 5.38.115.39:50803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bmPzqsQqnLoCgUjhl5wAAAU0"]
[Tue Jul 21 08:44:24.184510 2026] [security2:error] [pid 514479:tid 514681] [client 5.38.115.39:50803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bmPzqsQqnLoCgUjhl5wAAAU0"]
[Tue Jul 21 08:44:24.304155 2026] [security2:error] [pid 511108:tid 511348] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bmITd5soprXwxAH0DbQAAAG4"]
[Tue Jul 21 08:44:24.392115 2026] [security2:error] [pid 514479:tid 514700] [client 41.89.234.2:57475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bmPzqsQqnLoCgUjhl7QAAAWA"]
[Tue Jul 21 08:44:24.392137 2026] [security2:error] [pid 514479:tid 514665] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9bmPzqsQqnLoCgUjhl7AAAAT0"]
[Tue Jul 21 08:44:24.392211 2026] [security2:error] [pid 514479:tid 514700] [client 41.89.234.2:57475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bmPzqsQqnLoCgUjhl7QAAAWA"]
[Tue Jul 21 08:44:24.416248 2026] [security2:error] [pid 514479:tid 514616] [client 20.151.10.161:30622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/xwpg.php"] [unique_id "al9bmPzqsQqnLoCgUjhl8AAAAQw"]
[Tue Jul 21 08:44:24.466978 2026] [security2:error] [pid 511108:tid 511184] [remote 130.51.180.8:39446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "horiclinicaguarulhos.com.br"] [uri "/wp-login.php"] [unique_id "al9bmITd5soprXwxAH0DcAAAc0s"]
[Tue Jul 21 08:44:24.603161 2026] [security2:error] [pid 514479:tid 514625] [client 65.21.113.253:42168] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bmPzqsQqnLoCgUjhl8QAAARU"]
[Tue Jul 21 08:44:24.780680 2026] [security2:error] [pid 514479:tid 514567] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bmPzqsQqnLoCgUjhl9gABXFI"]
[Tue Jul 21 08:44:24.780850 2026] [security2:error] [pid 514479:tid 514696] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bmPzqsQqnLoCgUjhl9gABXFI"]
[Tue Jul 21 08:44:24.781203 2026] [security2:error] [pid 514479:tid 514541] [remote 20.153.140.50:33062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limaradiologiadigital.com.br"] [uri "/wp-login.php"] [unique_id "al9bmPzqsQqnLoCgUjhl9QABFDk"]
[Tue Jul 21 08:44:24.819054 2026] [security2:error] [pid 514479:tid 514636] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9bmPzqsQqnLoCgUjhl-QAAASA"]
[Tue Jul 21 08:44:24.821830 2026] [security2:error] [pid 514479:tid 514662] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9bmPzqsQqnLoCgUjhl-gAAATo"]
[Tue Jul 21 08:44:24.965224 2026] [security2:error] [pid 514479:tid 514701] [client 203.25.124.51:30039] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/group/"] [unique_id "al9bmPzqsQqnLoCgUjhl_wAAAWE"]
[Tue Jul 21 08:44:25.262193 2026] [security2:error] [pid 511108:tid 511270] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9bmYTd5soprXwxAH0DgAAAACA"]
[Tue Jul 21 08:44:25.268697 2026] [security2:error] [pid 511108:tid 511293] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9bmYTd5soprXwxAH0DgQAAADc"]
[Tue Jul 21 08:44:25.275100 2026] [security2:error] [pid 514479:tid 514716] [client 212.32.76.65:52653] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/worksec.php"] [unique_id "al9bmfzqsQqnLoCgUjhmAQAAAXA"]
[Tue Jul 21 08:44:25.281353 2026] [security2:error] [pid 511108:tid 511333] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bmITd5soprXwxAH0DdwAAAF8"]
[Tue Jul 21 08:44:25.419117 2026] [autoindex:error] [pid 511108:tid 511282] [client 20.151.10.161:0] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:25.561990 2026] [security2:error] [pid 511108:tid 511269] [client 172.234.215.11:52712] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "governess.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9bmYTd5soprXwxAH0DlAAAAB8"]
[Tue Jul 21 08:44:25.706159 2026] [security2:error] [pid 511108:tid 511321] [client 172.234.215.11:52712] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "governess.com.br"] [uri "/"] [unique_id "al9bmYTd5soprXwxAH0DlQAAAFM"]
[Tue Jul 21 08:44:25.708513 2026] [security2:error] [pid 511108:tid 511349] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9bmYTd5soprXwxAH0DlgAAAG8"]
[Tue Jul 21 08:44:25.734649 2026] [security2:error] [pid 511108:tid 511341] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9bmYTd5soprXwxAH0DmAAAAGc"]
[Tue Jul 21 08:44:25.784400 2026] [security2:error] [pid 511108:tid 511123] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bmYTd5soprXwxAH0DmQAALg4"]
[Tue Jul 21 08:44:25.784566 2026] [security2:error] [pid 511108:tid 511284] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bmYTd5soprXwxAH0DmQAALg4"]
[Tue Jul 21 08:44:25.830173 2026] [security2:error] [pid 514479:tid 514676] [client 173.252.95.5:58348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bmfzqsQqnLoCgUjhmBAAAAUg"]
[Tue Jul 21 08:44:25.864946 2026] [security2:error] [pid 511108:tid 511327] [client 203.25.124.42:43865] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/"] [unique_id "al9bmYTd5soprXwxAH0DmwAAAFk"]
[Tue Jul 21 08:44:25.952524 2026] [autoindex:error] [pid 511108:tid 511268] [client 20.151.10.161:56419] AH01276: Cannot serve directory /home3/werdes65/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:25.959926 2026] [security2:error] [pid 514479:tid 514619] [client 49.144.66.253:30619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bmfzqsQqnLoCgUjhmDQAAAQ8"]
[Tue Jul 21 08:44:25.960030 2026] [security2:error] [pid 514479:tid 514619] [client 49.144.66.253:30619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bmfzqsQqnLoCgUjhmDQAAAQ8"]
[Tue Jul 21 08:44:26.100789 2026] [security2:error] [pid 511108:tid 511294] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9bmoTd5soprXwxAH0DoQAAADg"]
[Tue Jul 21 08:44:26.107933 2026] [security2:error] [pid 511108:tid 511286] [client 20.151.10.161:30716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/waf.php"] [unique_id "al9bmoTd5soprXwxAH0DogAAADA"]
[Tue Jul 21 08:44:26.285833 2026] [security2:error] [pid 511108:tid 511292] [client 195.49.128.211:64984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bmoTd5soprXwxAH0DpgAAADY"]
[Tue Jul 21 08:44:26.286047 2026] [security2:error] [pid 511108:tid 511292] [client 195.49.128.211:64984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bmoTd5soprXwxAH0DpgAAADY"]
[Tue Jul 21 08:44:26.440603 2026] [security2:error] [pid 514479:tid 514697] [client 103.59.206.240:31269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bmvzqsQqnLoCgUjhmEAAAAV0"]
[Tue Jul 21 08:44:26.440729 2026] [security2:error] [pid 514479:tid 514697] [client 103.59.206.240:31269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bmvzqsQqnLoCgUjhmEAAAAV0"]
[Tue Jul 21 08:44:26.521831 2026] [security2:error] [pid 514479:tid 514722] [client 20.226.60.151:34789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/zc-131.php"] [unique_id "al9bmvzqsQqnLoCgUjhmEgAAAXY"]
[Tue Jul 21 08:44:26.544314 2026] [security2:error] [pid 514479:tid 514662] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9bmvzqsQqnLoCgUjhmEwAAATo"]
[Tue Jul 21 08:44:26.665802 2026] [security2:error] [pid 511108:tid 511351] [client 20.151.10.161:56367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/xstelth.php"] [unique_id "al9bmoTd5soprXwxAH0DsgAAAHE"]
[Tue Jul 21 08:44:26.666952 2026] [security2:error] [pid 514479:tid 514667] [client 203.25.124.53:58497] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/666.php"] [unique_id "al9bmvzqsQqnLoCgUjhmFwAAAT8"]
[Tue Jul 21 08:44:26.970150 2026] [security2:error] [pid 514479:tid 514727] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9bmvzqsQqnLoCgUjhmHQAAAXs"]
[Tue Jul 21 08:44:27.015944 2026] [security2:error] [pid 514479:tid 514651] [client 20.151.10.161:30628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-links.php"] [unique_id "al9bm_zqsQqnLoCgUjhmHwAAAS8"]
[Tue Jul 21 08:44:27.212776 2026] [security2:error] [pid 514479:tid 514631] [client 114.198.138.124:64253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9bm_zqsQqnLoCgUjhmIQAAARs"]
[Tue Jul 21 08:44:27.212883 2026] [security2:error] [pid 514479:tid 514631] [client 114.198.138.124:64253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9bm_zqsQqnLoCgUjhmIQAAARs"]
[Tue Jul 21 08:44:27.226036 2026] [security2:error] [pid 514479:tid 514577] [remote 90.148.142.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.142.148.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bm_zqsQqnLoCgUjhmIgABNFw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:27.230591 2026] [security2:error] [pid 511108:tid 511127] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bm4Td5soprXwxAH0DvAAAYxI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:27.233690 2026] [security2:error] [pid 514479:tid 514593] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bm_zqsQqnLoCgUjhmIwABiWw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:27.261497 2026] [security2:error] [pid 514479:tid 514487] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bm_zqsQqnLoCgUjhmJAABZQM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:27.403886 2026] [security2:error] [pid 514479:tid 514712] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9bm_zqsQqnLoCgUjhmJgAAAWw"]
[Tue Jul 21 08:44:27.470882 2026] [security2:error] [pid 514479:tid 514493] [remote 90.148.142.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.142.148.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bm_zqsQqnLoCgUjhmKAABXgk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:27.477091 2026] [security2:error] [pid 511108:tid 511213] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bm4Td5soprXwxAH0DvwAAdmg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:27.482529 2026] [security2:error] [pid 514479:tid 514554] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bm_zqsQqnLoCgUjhmKQABDEU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:27.617684 2026] [security2:error] [pid 514479:tid 514619] [client 20.151.10.161:30594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9bm_zqsQqnLoCgUjhmLQAAAQ8"]
[Tue Jul 21 08:44:27.711200 2026] [security2:error] [pid 514479:tid 514530] [remote 90.148.142.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.142.148.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bm_zqsQqnLoCgUjhmMAABXy4"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:27.718561 2026] [security2:error] [pid 511108:tid 511147] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bm4Td5soprXwxAH0DygAAOCY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:27.725684 2026] [security2:error] [pid 514479:tid 514607] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bm_zqsQqnLoCgUjhmMQABM3o"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:27.784713 2026] [security2:error] [pid 514479:tid 514604] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bm_zqsQqnLoCgUjhmMwABR3c"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:27.853317 2026] [security2:error] [pid 514479:tid 514623] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9bm_zqsQqnLoCgUjhmNgAAARM"]
[Tue Jul 21 08:44:27.871696 2026] [security2:error] [pid 511108:tid 511358] [client 203.25.124.31:43085] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "al9bm4Td5soprXwxAH0DzQAAAHg"]
[Tue Jul 21 08:44:27.949741 2026] [security2:error] [pid 511108:tid 511322] [client 20.151.10.161:56426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/aaa.php"] [unique_id "al9bm4Td5soprXwxAH0DzwAAAFQ"]
[Tue Jul 21 08:44:27.955554 2026] [security2:error] [pid 514479:tid 514562] [remote 90.148.142.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.142.148.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bm_zqsQqnLoCgUjhmNwABU00"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:27.966949 2026] [security2:error] [pid 511108:tid 511109] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bm4Td5soprXwxAH0D0gAAbAA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:27.968717 2026] [security2:error] [pid 514479:tid 514543] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bm_zqsQqnLoCgUjhmOAABJjs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:27.985905 2026] [security2:error] [pid 511108:tid 511304] [client 203.25.124.208:49173] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content.php"] [unique_id "al9bm4Td5soprXwxAH0D0wAAAEI"]
[Tue Jul 21 08:44:28.042658 2026] [security2:error] [pid 514479:tid 514571] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bnPzqsQqnLoCgUjhmOgABDlY"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:28.057778 2026] [security2:error] [pid 511108:tid 511238] [client 78.46.215.1:47018] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9bnITd5soprXwxAH0D_AAAAAA"], referer: https://artetoner.com.br
[Tue Jul 21 08:44:28.176635 2026] [security2:error] [pid 511108:tid 511285] [client 74.7.175.130:50336] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "promotrend.com.br"] [uri "/index.php"] [unique_id "al9bmYTd5soprXwxAH0DfQAAL0Y"]
[Tue Jul 21 08:44:28.203022 2026] [security2:error] [pid 514479:tid 514563] [remote 90.148.142.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.142.148.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bnPzqsQqnLoCgUjhmPQABQ04"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:28.216197 2026] [security2:error] [pid 511108:tid 511220] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bnITd5soprXwxAH0D_gAABW8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:28.220388 2026] [security2:error] [pid 514479:tid 514509] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bnPzqsQqnLoCgUjhmPgABbxk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:28.276501 2026] [security2:error] [pid 511108:tid 511289] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9bnITd5soprXwxAH0D_wAAADM"]
[Tue Jul 21 08:44:28.321140 2026] [security2:error] [pid 514479:tid 514573] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bnPzqsQqnLoCgUjhmPwABhVg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:28.440827 2026] [security2:error] [pid 514479:tid 514597] [remote 90.148.142.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.142.148.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bnPzqsQqnLoCgUjhmQAABGnA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:28.462127 2026] [security2:error] [pid 514479:tid 514601] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bnPzqsQqnLoCgUjhmQQABfHQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:28.602077 2026] [security2:error] [pid 514479:tid 514572] [remote 188.53.162.157:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.162.53.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9bnPzqsQqnLoCgUjhmQwABcFc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:44:28.610422 2026] [security2:error] [pid 511108:tid 511338] [client 195.49.128.211:56439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bnITd5soprXwxAH0ECwAAAGQ"]
[Tue Jul 21 08:44:28.610513 2026] [security2:error] [pid 511108:tid 511338] [client 195.49.128.211:56439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bnITd5soprXwxAH0ECwAAAGQ"]
[Tue Jul 21 08:44:28.810840 2026] [security2:error] [pid 514479:tid 514682] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9bnPzqsQqnLoCgUjhmRAAAAU4"]
[Tue Jul 21 08:44:28.848455 2026] [security2:error] [pid 511108:tid 511328] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bnITd5soprXwxAH0EAAAAAFo"]
[Tue Jul 21 08:44:28.862238 2026] [security2:error] [pid 514479:tid 514684] [client 212.32.76.5:46417] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/l10n/wp-conflg.php"] [unique_id "al9bnPzqsQqnLoCgUjhmRQAAAVA"]
[Tue Jul 21 08:44:28.944575 2026] [security2:error] [pid 514479:tid 514596] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php"] [unique_id "al9bnPzqsQqnLoCgUjhmRgABfW8"]
[Tue Jul 21 08:44:28.945378 2026] [security2:error] [pid 514479:tid 514575] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/install.php"] [unique_id "al9bnPzqsQqnLoCgUjhmRwABfVo"]
[Tue Jul 21 08:44:28.946114 2026] [security2:error] [pid 514479:tid 514511] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/settings.php"] [unique_id "al9bnPzqsQqnLoCgUjhmTAABfRs"]
[Tue Jul 21 08:44:28.946220 2026] [security2:error] [pid 514479:tid 514564] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/mail.php"] [unique_id "al9bnPzqsQqnLoCgUjhmSQABfU8"]
[Tue Jul 21 08:44:29.176602 2026] [security2:error] [pid 514479:tid 514664] [client 180.191.14.211:48771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.14.191.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "juliagoncalvesestetica.com"] [uri "/xmlrpc.php"] [unique_id "al9bnfzqsQqnLoCgUjhmUgAAATw"]
[Tue Jul 21 08:44:29.176738 2026] [security2:error] [pid 514479:tid 514664] [client 180.191.14.211:48771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "juliagoncalvesestetica.com"] [uri "/xmlrpc.php"] [unique_id "al9bnfzqsQqnLoCgUjhmUgAAATw"]
[Tue Jul 21 08:44:29.237517 2026] [security2:error] [pid 514479:tid 514616] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9bnfzqsQqnLoCgUjhmUwAAAQw"]
[Tue Jul 21 08:44:29.353077 2026] [security2:error] [pid 511108:tid 511288] [client 20.197.192.193:53631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/ms-new.php"] [unique_id "al9bnYTd5soprXwxAH0EHwAAADI"]
[Tue Jul 21 08:44:29.394947 2026] [security2:error] [pid 514479:tid 514617] [client 59.95.197.55:54322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bnfzqsQqnLoCgUjhmVAAAAQ0"]
[Tue Jul 21 08:44:29.395091 2026] [security2:error] [pid 514479:tid 514617] [client 59.95.197.55:54322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bnfzqsQqnLoCgUjhmVAAAAQ0"]
[Tue Jul 21 08:44:29.633337 2026] [security2:error] [pid 514479:tid 514699] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9bnfzqsQqnLoCgUjhmVgAAAV8"]
[Tue Jul 21 08:44:29.970411 2026] [security2:error] [pid 511108:tid 511344] [client 203.25.124.199:36383] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/chosen.php"] [unique_id "al9bnYTd5soprXwxAH0EKgAAAGo"]
[Tue Jul 21 08:44:30.066613 2026] [security2:error] [pid 514479:tid 514678] [client 203.25.124.42:45969] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/user.php"] [unique_id "al9bnvzqsQqnLoCgUjhmYAAAAUo"]
[Tue Jul 21 08:44:30.198385 2026] [security2:error] [pid 511108:tid 511364] [client 122.176.100.127:55769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bnoTd5soprXwxAH0ELwAAAH4"]
[Tue Jul 21 08:44:30.198499 2026] [security2:error] [pid 511108:tid 511364] [client 122.176.100.127:55769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bnoTd5soprXwxAH0ELwAAAH4"]
[Tue Jul 21 08:44:30.238601 2026] [security2:error] [pid 514479:tid 514628] [client 173.252.95.11:41354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bnvzqsQqnLoCgUjhmZQAAARg"]
[Tue Jul 21 08:44:30.300214 2026] [security2:error] [pid 514479:tid 514501] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bnvzqsQqnLoCgUjhmZgABXBE"]
[Tue Jul 21 08:44:30.300490 2026] [security2:error] [pid 514479:tid 514696] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bnvzqsQqnLoCgUjhmZgABXBE"]
[Tue Jul 21 08:44:30.587318 2026] [autoindex:error] [pid 514479:tid 514665] [client 205.210.31.73:57558] AH01276: Cannot serve directory /home2/werley42/impactoensino.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:30.680756 2026] [security2:error] [pid 514479:tid 514630] [client 202.179.75.202:41264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bnvzqsQqnLoCgUjhmbwAAARo"]
[Tue Jul 21 08:44:30.681543 2026] [security2:error] [pid 514479:tid 514630] [client 202.179.75.202:41264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bnvzqsQqnLoCgUjhmbwAAARo"]
[Tue Jul 21 08:44:30.732375 2026] [security2:error] [pid 514479:tid 514642] [client 117.213.202.34:54512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bnvzqsQqnLoCgUjhmcAAAASY"]
[Tue Jul 21 08:44:30.732511 2026] [security2:error] [pid 514479:tid 514642] [client 117.213.202.34:54512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bnvzqsQqnLoCgUjhmcAAAASY"]
[Tue Jul 21 08:44:30.776050 2026] [security2:error] [pid 514479:tid 514631] [client 173.252.95.20:46172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bnvzqsQqnLoCgUjhmcQAAARs"]
[Tue Jul 21 08:44:30.891513 2026] [security2:error] [pid 514479:tid 514660] [client 173.252.95.60:43024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bnvzqsQqnLoCgUjhmcgAAATg"]
[Tue Jul 21 08:44:31.077854 2026] [security2:error] [pid 511108:tid 511196] [remote 167.71.240.77:56702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.240.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9bn4Td5soprXwxAH0EOgAAQlc"]
[Tue Jul 21 08:44:31.159860 2026] [security2:error] [pid 514479:tid 514647] [client 212.32.76.7:57925] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/nextpage/"] [unique_id "al9bn_zqsQqnLoCgUjhmdQAAASs"]
[Tue Jul 21 08:44:31.179335 2026] [security2:error] [pid 514479:tid 514680] [client 203.25.124.11:28021] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/tinymce/themes/about.php"] [unique_id "al9bn_zqsQqnLoCgUjhmdgAAAUw"]
[Tue Jul 21 08:44:31.290133 2026] [security2:error] [pid 511108:tid 511216] [remote 67.20.76.238:51284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.76.20.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peak-bioboost.shop-officialstore.com"] [uri "/wp-login.php"] [unique_id "al9bn4Td5soprXwxAH0EPwAAO2s"]
[Tue Jul 21 08:44:31.322504 2026] [security2:error] [pid 511108:tid 511270] [client 173.252.95.30:58090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bn4Td5soprXwxAH0EQAAAACA"]
[Tue Jul 21 08:44:31.582482 2026] [security2:error] [pid 511108:tid 511314] [client 20.197.195.24:63209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9bn4Td5soprXwxAH0ERAAAAEw"]
[Tue Jul 21 08:44:31.677110 2026] [security2:error] [pid 511108:tid 511246] [client 152.59.181.104:55493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bn4Td5soprXwxAH0ESQAAAAg"]
[Tue Jul 21 08:44:31.677224 2026] [security2:error] [pid 511108:tid 511246] [client 152.59.181.104:55493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bn4Td5soprXwxAH0ESQAAAAg"]
[Tue Jul 21 08:44:31.684262 2026] [security2:error] [pid 514479:tid 514590] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.backup"] [unique_id "al9bn_zqsQqnLoCgUjhmfgABRmk"]
[Tue Jul 21 08:44:31.684907 2026] [security2:error] [pid 514479:tid 514583] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.bak"] [unique_id "al9bn_zqsQqnLoCgUjhmgAABRmI"]
[Tue Jul 21 08:44:31.685622 2026] [security2:error] [pid 514479:tid 514591] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env"] [unique_id "al9bn_zqsQqnLoCgUjhmhAABRmo"]
[Tue Jul 21 08:44:31.854654 2026] [security2:error] [pid 514479:tid 514486] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-config.php.bak"] [unique_id "al9bn_zqsQqnLoCgUjhmjQABEwI"]
[Tue Jul 21 08:44:31.854776 2026] [security2:error] [pid 514479:tid 514486] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-config.php;/style.css"] [unique_id "al9bn_zqsQqnLoCgUjhmjgABEwI"]
[Tue Jul 21 08:44:31.855335 2026] [security2:error] [pid 514479:tid 514497] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-config.php"] [unique_id "al9bn_zqsQqnLoCgUjhmkAABEw0"]
[Tue Jul 21 08:44:31.855980 2026] [security2:error] [pid 514479:tid 514589] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env"] [unique_id "al9bn_zqsQqnLoCgUjhmiwABE2g"]
[Tue Jul 21 08:44:31.976381 2026] [security2:error] [pid 511108:tid 511343] [client 20.197.195.24:63148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9bn4Td5soprXwxAH0EWgAAAGk"]
[Tue Jul 21 08:44:32.030446 2026] [security2:error] [pid 511108:tid 511348] [client 20.197.192.193:27090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/zzz.php"] [unique_id "al9boITd5soprXwxAH0EWwAAAG4"]
[Tue Jul 21 08:44:32.277611 2026] [security2:error] [pid 514479:tid 514637] [client 203.25.124.39:35299] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/code/"] [unique_id "al9boPzqsQqnLoCgUjhmlQAAASE"]
[Tue Jul 21 08:44:32.284362 2026] [security2:error] [pid 514479:tid 514703] [client 20.197.195.24:63106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/media.php"] [unique_id "al9boPzqsQqnLoCgUjhmlgAAAWM"]
[Tue Jul 21 08:44:32.589650 2026] [security2:error] [pid 511108:tid 511322] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9boITd5soprXwxAH0EbAAAVDI"]
[Tue Jul 21 08:44:32.598498 2026] [security2:error] [pid 514479:tid 514684] [client 20.197.195.24:63178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/images.php"] [unique_id "al9boPzqsQqnLoCgUjhmmAAAAVA"]
[Tue Jul 21 08:44:32.670764 2026] [security2:error] [pid 514479:tid 514730] [client 203.25.124.181:57793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/ssss/src.php"] [unique_id "al9boPzqsQqnLoCgUjhmmwAAAX4"]
[Tue Jul 21 08:44:32.694014 2026] [security2:error] [pid 511108:tid 511352] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9boITd5soprXwxAH0EXQAAAHI"]
[Tue Jul 21 08:44:32.698185 2026] [security2:error] [pid 514479:tid 514656] [client 20.197.195.24:63229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/gecko.php"] [unique_id "al9boPzqsQqnLoCgUjhmnQAAATQ"]
[Tue Jul 21 08:44:32.824800 2026] [security2:error] [pid 514479:tid 514659] [client 20.197.195.24:63202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/82.php"] [unique_id "al9boPzqsQqnLoCgUjhmpQAAATc"]
[Tue Jul 21 08:44:32.976444 2026] [security2:error] [pid 514479:tid 514688] [client 173.252.95.28:36972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9boPzqsQqnLoCgUjhmqAAAAVQ"]
[Tue Jul 21 08:44:33.239753 2026] [security2:error] [pid 514479:tid 514654] [client 20.197.195.24:63137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/admin.php"] [unique_id "al9bofzqsQqnLoCgUjhmrgAAATI"]
[Tue Jul 21 08:44:33.297843 2026] [authz_core:error] [pid 514479:tid 514496] [remote 103.215.74.26:49678] AH01630: client denied by server configuration: /home2/acupu265/auriculo.liranesuliano.com/.htpasswd
[Tue Jul 21 08:44:33.303500 2026] [security2:error] [pid 514479:tid 514516] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.ssh/id_rsa"] [unique_id "al9bofzqsQqnLoCgUjhmtAABXyA"]
[Tue Jul 21 08:44:33.380988 2026] [security2:error] [pid 514479:tid 514492] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config/app.php"] [unique_id "al9bofzqsQqnLoCgUjhmtwABXwg"]
[Tue Jul 21 08:44:33.385966 2026] [security2:error] [pid 514479:tid 514582] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config/mail.php"] [unique_id "al9bofzqsQqnLoCgUjhmuQABX2E"]
[Tue Jul 21 08:44:33.391158 2026] [security2:error] [pid 514479:tid 514510] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/dump.sql"] [unique_id "al9bofzqsQqnLoCgUjhmvAABXxo"]
[Tue Jul 21 08:44:33.393374 2026] [security2:error] [pid 514479:tid 514491] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config/database.php"] [unique_id "al9bofzqsQqnLoCgUjhmvQABXwc"]
[Tue Jul 21 08:44:33.408905 2026] [security2:error] [pid 514479:tid 514610] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/backup.sql"] [unique_id "al9bofzqsQqnLoCgUjhmvgABX30"]
[Tue Jul 21 08:44:33.424318 2026] [security2:error] [pid 514479:tid 514733] [client 41.89.234.2:57914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bofzqsQqnLoCgUjhmvwAAAYE"]
[Tue Jul 21 08:44:33.424473 2026] [security2:error] [pid 514479:tid 514733] [client 41.89.234.2:57914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bofzqsQqnLoCgUjhmvwAAAYE"]
[Tue Jul 21 08:44:33.453744 2026] [security2:error] [pid 514479:tid 514489] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/database.sql"] [unique_id "al9bofzqsQqnLoCgUjhmwAABXwU"]
[Tue Jul 21 08:44:33.461277 2026] [security2:error] [pid 514479:tid 514674] [client 203.25.124.211:53967] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwentytwo/assets/fonts/"] [unique_id "al9bofzqsQqnLoCgUjhmwQAAAUY"]
[Tue Jul 21 08:44:33.493042 2026] [security2:error] [pid 514479:tid 514570] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env"] [unique_id "al9bofzqsQqnLoCgUjhmxAABF1U"]
[Tue Jul 21 08:44:33.694949 2026] [security2:error] [pid 511108:tid 511323] [client 20.197.195.24:63116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/adminner.php"] [unique_id "al9boYTd5soprXwxAH0EjAAAAFU"]
[Tue Jul 21 08:44:33.791927 2026] [autoindex:error] [pid 514479:tid 514671] [client 35.204.70.15:0] AH01276: Cannot serve directory /home1/tavar035/raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:33.972956 2026] [security2:error] [pid 511108:tid 511356] [client 203.25.124.189:38027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/css/dist/components/"] [unique_id "al9boYTd5soprXwxAH0ElwAAAHY"]
[Tue Jul 21 08:44:33.983676 2026] [autoindex:error] [pid 514479:tid 514620] [client 35.204.70.15:0] AH01276: Cannot serve directory /home1/tavar035/raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:34.023217 2026] [security2:error] [pid 514479:tid 514662] [client 5.31.193.106:30014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bovzqsQqnLoCgUjhm0AAAATo"]
[Tue Jul 21 08:44:34.026327 2026] [security2:error] [pid 514479:tid 514662] [client 5.31.193.106:30014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9bovzqsQqnLoCgUjhm0AAAATo"]
[Tue Jul 21 08:44:34.057370 2026] [security2:error] [pid 514479:tid 514631] [client 20.197.195.24:63141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/admin.php"] [unique_id "al9bovzqsQqnLoCgUjhm0wAAARs"]
[Tue Jul 21 08:44:34.059299 2026] [core:alert] [pid 514479:tid 514665] [client 57.141.18.8:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:44:34.206263 2026] [security2:error] [pid 514479:tid 514625] [client 64.42.179.43:41244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9bovzqsQqnLoCgUjhm1gAAARU"]
[Tue Jul 21 08:44:34.206357 2026] [security2:error] [pid 514479:tid 514625] [client 64.42.179.43:41244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9bovzqsQqnLoCgUjhm1gAAARU"]
[Tue Jul 21 08:44:34.284368 2026] [security2:error] [pid 514479:tid 514739] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9bovzqsQqnLoCgUjhm2QAAAYc"]
[Tue Jul 21 08:44:34.309552 2026] [security2:error] [pid 514479:tid 514617] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9bovzqsQqnLoCgUjhm3gAAAQ0"]
[Tue Jul 21 08:44:34.314332 2026] [autoindex:error] [pid 514479:tid 514521] [remote 35.204.70.15:0] AH01276: Cannot serve directory /home1/tavar035/raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:34.545548 2026] [security2:error] [pid 511108:tid 511277] [client 20.197.195.24:63200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/k.php"] [unique_id "al9booTd5soprXwxAH0EswAAACc"]
[Tue Jul 21 08:44:34.636669 2026] [security2:error] [pid 514479:tid 514740] [client 35.204.70.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.70.204.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bovzqsQqnLoCgUjhm4QAAAYg"]
[Tue Jul 21 08:44:34.644585 2026] [security2:error] [pid 514479:tid 514523] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9bovzqsQqnLoCgUjhm4gABTyc"]
[Tue Jul 21 08:44:34.686786 2026] [security2:error] [pid 514479:tid 514552] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-config.php"] [unique_id "al9bovzqsQqnLoCgUjhm4wABHEM"]
[Tue Jul 21 08:44:34.687629 2026] [security2:error] [pid 514479:tid 514569] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9bovzqsQqnLoCgUjhm5AABP1Q"]
[Tue Jul 21 08:44:34.745762 2026] [authz_core:error] [pid 514479:tid 514517] [remote 103.215.74.26:49678] AH01630: client denied by server configuration: /home2/acupu265/auriculo.liranesuliano.com/.htpasswd
[Tue Jul 21 08:44:34.761686 2026] [security2:error] [pid 514479:tid 514687] [client 203.25.124.42:49945] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/t.php"] [unique_id "al9bovzqsQqnLoCgUjhm5wAAAVM"]
[Tue Jul 21 08:44:34.781370 2026] [security2:error] [pid 514479:tid 514577] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.backup"] [unique_id "al9bovzqsQqnLoCgUjhm6QABgVw"]
[Tue Jul 21 08:44:34.788397 2026] [security2:error] [pid 511108:tid 511287] [client 35.204.70.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.70.204.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9booTd5soprXwxAH0EugAAADE"]
[Tue Jul 21 08:44:34.795978 2026] [security2:error] [pid 514479:tid 514689] [client 5.38.115.39:51564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bovzqsQqnLoCgUjhm6gAAAVU"]
[Tue Jul 21 08:44:34.796136 2026] [security2:error] [pid 514479:tid 514689] [client 5.38.115.39:51564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bovzqsQqnLoCgUjhm6gAAAVU"]
[Tue Jul 21 08:44:34.799488 2026] [security2:error] [pid 511108:tid 511135] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-plain.php"] [unique_id "al9booTd5soprXwxAH0EuwAATRo"], referer: www.google.com
[Tue Jul 21 08:44:34.825209 2026] [security2:error] [pid 514479:tid 514487] [remote 35.204.70.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.70.204.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bovzqsQqnLoCgUjhm7AABNgM"]
[Tue Jul 21 08:44:34.898576 2026] [security2:error] [pid 511108:tid 511353] [client 20.197.195.24:63173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/blurbs.php"] [unique_id "al9booTd5soprXwxAH0EvwAAAHM"]
[Tue Jul 21 08:44:35.042043 2026] [security2:error] [pid 514479:tid 514495] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9bo_zqsQqnLoCgUjhm8QABeAs"], referer: www.google.com
[Tue Jul 21 08:44:35.076252 2026] [security2:error] [pid 514479:tid 514706] [client 203.25.124.5:62309] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/files/"] [unique_id "al9bo_zqsQqnLoCgUjhm8gAAAWY"]
[Tue Jul 21 08:44:35.146452 2026] [autoindex:error] [pid 511108:tid 511322] [client 35.204.70.15:0] AH01276: Cannot serve directory /home1/tavar035/raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:35.183477 2026] [security2:error] [pid 514479:tid 514604] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9bo_zqsQqnLoCgUjhm9wABb3c"]
[Tue Jul 21 08:44:35.238471 2026] [security2:error] [pid 514479:tid 514562] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9bo_zqsQqnLoCgUjhm-gABaU0"], referer: www.google.com
[Tue Jul 21 08:44:35.295070 2026] [security2:error] [pid 514479:tid 514543] [remote 35.204.70.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.70.204.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bo_zqsQqnLoCgUjhm-wABQzs"]
[Tue Jul 21 08:44:35.342240 2026] [security2:error] [pid 514479:tid 514571] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bo_zqsQqnLoCgUjhm_QABc1Y"]
[Tue Jul 21 08:44:35.342526 2026] [security2:error] [pid 514479:tid 514719] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bo_zqsQqnLoCgUjhm_QABc1Y"]
[Tue Jul 21 08:44:35.369966 2026] [security2:error] [pid 514479:tid 514563] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/talxveim.php"] [unique_id "al9bo_zqsQqnLoCgUjhm_gABcE4"], referer: www.google.com
[Tue Jul 21 08:44:35.480171 2026] [security2:error] [pid 511108:tid 511363] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9bo4Td5soprXwxAH0EzgAAAH0"]
[Tue Jul 21 08:44:35.484409 2026] [security2:error] [pid 514479:tid 514617] [client 20.197.195.24:63117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/bajah.php"] [unique_id "al9bo_zqsQqnLoCgUjhnCAAAAQ0"]
[Tue Jul 21 08:44:35.514328 2026] [security2:error] [pid 514479:tid 514684] [client 74.7.228.4:46992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "samuelcassanelianton1780366023000.focsmart.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9bo_zqsQqnLoCgUjhnCQABUEg"]
[Tue Jul 21 08:44:35.580700 2026] [autoindex:error] [pid 514479:tid 514573] [remote 74.7.227.20:60704] AH01276: Cannot serve directory /home2/samu8017/samuelcassanelianton1780366023000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:35.698292 2026] [autoindex:error] [pid 514479:tid 514601] [remote 35.204.70.15:0] AH01276: Cannot serve directory /home1/tavar035/raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:35.823257 2026] [security2:error] [pid 511108:tid 511278] [client 162.241.63.68:0] ModSecurity: Warning. Matched phrase "Iria" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/wp-cron.php"] [unique_id "al9bo4Td5soprXwxAH0E2wAAACg"]
[Tue Jul 21 08:44:35.833967 2026] [security2:error] [pid 511108:tid 511338] [client 91.192.10.181:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.joseantoniopereira1782236338228.0711679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/backend/.env"] [unique_id "al9bo4Td5soprXwxAH0E3QAAAGQ"]
[Tue Jul 21 08:44:35.836908 2026] [security2:error] [pid 514479:tid 514740] [client 91.192.10.181:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.joseantoniopereira1782236338228.0711679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al9bo_zqsQqnLoCgUjhnFQAAAYg"]
[Tue Jul 21 08:44:35.839904 2026] [security2:error] [pid 514479:tid 514689] [client 91.192.10.181:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.joseantoniopereira1782236338228.0711679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpanel/api/.env"] [unique_id "al9bo_zqsQqnLoCgUjhnGgAAAVU"]
[Tue Jul 21 08:44:35.853964 2026] [security2:error] [pid 514479:tid 514674] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9bo_zqsQqnLoCgUjhnGwAAAUY"]
[Tue Jul 21 08:44:35.866236 2026] [security2:error] [pid 511108:tid 511323] [client 203.25.124.71:37889] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/html-api/chosen.php"] [unique_id "al9bo4Td5soprXwxAH0E6QAAAFU"]
[Tue Jul 21 08:44:35.909364 2026] [security2:error] [pid 511108:tid 511305] [client 113.22.144.139:54176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bo4Td5soprXwxAH0E6wAAAEM"]
[Tue Jul 21 08:44:35.909489 2026] [security2:error] [pid 511108:tid 511305] [client 113.22.144.139:54176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bo4Td5soprXwxAH0E6wAAAEM"]
[Tue Jul 21 08:44:35.987710 2026] [security2:error] [pid 514479:tid 514575] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "al9bo_zqsQqnLoCgUjhnIAABH1o"]
[Tue Jul 21 08:44:36.129318 2026] [authz_core:error] [pid 514479:tid 514511] [remote 103.215.74.26:49678] AH01630: client denied by server configuration: /home2/acupu265/auriculo.liranesuliano.com/.htpasswd
[Tue Jul 21 08:44:36.142409 2026] [security2:error] [pid 514479:tid 514564] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9bpPzqsQqnLoCgUjhnJQABZk8"]
[Tue Jul 21 08:44:36.238370 2026] [security2:error] [pid 514479:tid 514574] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al9bpPzqsQqnLoCgUjhnLQABW1k"]
[Tue Jul 21 08:44:36.296515 2026] [security2:error] [pid 514479:tid 514692] [client 20.197.195.24:63182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/a.php"] [unique_id "al9bpPzqsQqnLoCgUjhnLwAAAVg"]
[Tue Jul 21 08:44:36.312589 2026] [security2:error] [pid 511108:tid 511109] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bpITd5soprXwxAH0FBAAAOQA"]
[Tue Jul 21 08:44:36.312950 2026] [security2:error] [pid 511108:tid 511295] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bpITd5soprXwxAH0FBAAAOQA"]
[Tue Jul 21 08:44:36.345492 2026] [security2:error] [pid 514479:tid 514639] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9bpPzqsQqnLoCgUjhnMQAAASM"]
[Tue Jul 21 08:44:36.381285 2026] [security2:error] [pid 514479:tid 514719] [client 212.32.76.58:25373] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/themes.php"] [unique_id "al9bpPzqsQqnLoCgUjhnMwAAAXM"]
[Tue Jul 21 08:44:36.411898 2026] [security2:error] [pid 514479:tid 514533] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9bpPzqsQqnLoCgUjhnOQABITE"]
[Tue Jul 21 08:44:36.456370 2026] [security2:error] [pid 511108:tid 511321] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bo4Td5soprXwxAH0E7gAAAFM"]
[Tue Jul 21 08:44:36.459730 2026] [security2:error] [pid 514479:tid 514547] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "al9bpPzqsQqnLoCgUjhnPQABOj8"]
[Tue Jul 21 08:44:36.467851 2026] [security2:error] [pid 514479:tid 514726] [client 61.1.167.83:60548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bpPzqsQqnLoCgUjhnPgAAAXo"]
[Tue Jul 21 08:44:36.468003 2026] [security2:error] [pid 514479:tid 514726] [client 61.1.167.83:60548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bpPzqsQqnLoCgUjhnPgAAAXo"]
[Tue Jul 21 08:44:36.678472 2026] [security2:error] [pid 514479:tid 514609] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "al9bpPzqsQqnLoCgUjhnRQABEHw"]
[Tue Jul 21 08:44:36.701161 2026] [security2:error] [pid 514479:tid 514617] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9bpPzqsQqnLoCgUjhnRgAAAQ0"]
[Tue Jul 21 08:44:36.725406 2026] [security2:error] [pid 511108:tid 511348] [client 114.198.138.124:64864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9bpITd5soprXwxAH0FEgAAAG4"]
[Tue Jul 21 08:44:36.725517 2026] [security2:error] [pid 511108:tid 511348] [client 114.198.138.124:64864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9bpITd5soprXwxAH0FEgAAAG4"]
[Tue Jul 21 08:44:36.834548 2026] [security2:error] [pid 511108:tid 511268] [client 49.144.66.253:31031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bpITd5soprXwxAH0FFwAAAB4"]
[Tue Jul 21 08:44:36.834672 2026] [security2:error] [pid 511108:tid 511268] [client 49.144.66.253:31031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bpITd5soprXwxAH0FFwAAAB4"]
[Tue Jul 21 08:44:36.982742 2026] [security2:error] [pid 511108:tid 511255] [client 195.49.128.211:49209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bpITd5soprXwxAH0FHAAAABE"]
[Tue Jul 21 08:44:36.982865 2026] [security2:error] [pid 511108:tid 511255] [client 195.49.128.211:49209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bpITd5soprXwxAH0FHAAAABE"]
[Tue Jul 21 08:44:37.047111 2026] [security2:error] [pid 514479:tid 514546] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9bpfzqsQqnLoCgUjhnSwABST4"]
[Tue Jul 21 08:44:37.047926 2026] [security2:error] [pid 511108:tid 511325] [client 35.204.70.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.70.204.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bpYTd5soprXwxAH0FHwAAAFc"]
[Tue Jul 21 08:44:37.048043 2026] [security2:error] [pid 511108:tid 511325] [client 35.204.70.15:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "raquelmiriandasilva1748099894000.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bpYTd5soprXwxAH0FHwAAAFc"]
[Tue Jul 21 08:44:37.050994 2026] [security2:error] [pid 511108:tid 511306] [client 103.59.206.240:31269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bpYTd5soprXwxAH0FIAAAAEQ"]
[Tue Jul 21 08:44:37.051130 2026] [security2:error] [pid 511108:tid 511306] [client 103.59.206.240:31269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bpYTd5soprXwxAH0FIAAAAEQ"]
[Tue Jul 21 08:44:37.055569 2026] [security2:error] [pid 514479:tid 514689] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9bpfzqsQqnLoCgUjhnTQAAAVU"]
[Tue Jul 21 08:44:37.365270 2026] [security2:error] [pid 514479:tid 514584] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9bpfzqsQqnLoCgUjhnVgABH2M"]
[Tue Jul 21 08:44:37.385025 2026] [security2:error] [pid 514479:tid 514499] [remote 35.204.70.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.70.204.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bpfzqsQqnLoCgUjhnVwABIA8"]
[Tue Jul 21 08:44:37.385146 2026] [security2:error] [pid 514479:tid 514636] [client 35.204.70.15:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "raquelmiriandasilva1748099894000.tavarescont.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bpfzqsQqnLoCgUjhnVwABIA8"]
[Tue Jul 21 08:44:37.393027 2026] [security2:error] [pid 514479:tid 514683] [client 20.197.195.24:63124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/edit.php"] [unique_id "al9bpfzqsQqnLoCgUjhnWAAAAU8"]
[Tue Jul 21 08:44:37.409340 2026] [security2:error] [pid 514479:tid 514667] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9bpfzqsQqnLoCgUjhnWQAAAT8"]
[Tue Jul 21 08:44:37.418442 2026] [security2:error] [pid 514479:tid 514687] [client 198.44.157.34:49932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9bpfzqsQqnLoCgUjhnWgAAAVM"]
[Tue Jul 21 08:44:37.418536 2026] [security2:error] [pid 514479:tid 514687] [client 198.44.157.34:49932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9bpfzqsQqnLoCgUjhnWgAAAVM"]
[Tue Jul 21 08:44:37.576591 2026] [security2:error] [pid 514479:tid 514629] [client 212.32.76.55:40151] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/ahax.php"] [unique_id "al9bpfzqsQqnLoCgUjhnXQAAARk"]
[Tue Jul 21 08:44:37.612356 2026] [authz_core:error] [pid 514479:tid 514528] [remote 103.215.74.26:49678] AH01630: client denied by server configuration: /home2/acupu265/auriculo.liranesuliano.com/.htpasswd
[Tue Jul 21 08:44:37.761753 2026] [security2:error] [pid 514479:tid 514692] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9bpfzqsQqnLoCgUjhnYgAAAVg"]
[Tue Jul 21 08:44:37.822631 2026] [security2:error] [pid 514479:tid 514583] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9bpfzqsQqnLoCgUjhnZAABhGI"]
[Tue Jul 21 08:44:38.038321 2026] [security2:error] [pid 514479:tid 514590] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9bpvzqsQqnLoCgUjhnbAABemk"]
[Tue Jul 21 08:44:38.068608 2026] [security2:error] [pid 511108:tid 511300] [client 20.197.195.24:63191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/hosty.php"] [unique_id "al9bpoTd5soprXwxAH0FMAAAAD4"]
[Tue Jul 21 08:44:38.160131 2026] [security2:error] [pid 511108:tid 511328] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9bpoTd5soprXwxAH0FMQAAAFo"]
[Tue Jul 21 08:44:38.242834 2026] [security2:error] [pid 514479:tid 514540] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9bpvzqsQqnLoCgUjhnbQABaTg"]
[Tue Jul 21 08:44:38.496858 2026] [security2:error] [pid 514479:tid 514585] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9bpvzqsQqnLoCgUjhnbgABbGQ"]
[Tue Jul 21 08:44:38.521308 2026] [security2:error] [pid 511108:tid 511329] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9bpoTd5soprXwxAH0FNQAAAFs"]
[Tue Jul 21 08:44:38.574106 2026] [security2:error] [pid 511108:tid 511299] [client 212.32.76.7:23005] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/css/dist/edit-post/"] [unique_id "al9bpoTd5soprXwxAH0FOQAAAD0"]
[Tue Jul 21 08:44:38.605588 2026] [security2:error] [pid 511108:tid 511221] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/z9x8c7v6b5-debug-trigger-login.gradiente.com"] [unique_id "al9bpoTd5soprXwxAH0FPwAAK3A"]
[Tue Jul 21 08:44:38.738205 2026] [proxy:error] [pid 514479:tid 514721] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:38.738297 2026] [proxy_http:error] [pid 514479:tid 514721] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:38.739493 2026] [proxy:error] [pid 514479:tid 514721] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:38.739555 2026] [proxy_http:error] [pid 514479:tid 514721] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:38.777459 2026] [security2:error] [pid 511108:tid 511290] [client 212.32.76.60:58655] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/images/"] [unique_id "al9bpoTd5soprXwxAH0FSgAAADQ"]
[Tue Jul 21 08:44:38.808353 2026] [security2:error] [pid 514479:tid 514592] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9bpvzqsQqnLoCgUjhncQABPms"]
[Tue Jul 21 08:44:38.876297 2026] [security2:error] [pid 511108:tid 511365] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9bpoTd5soprXwxAH0FSwAAAH8"]
[Tue Jul 21 08:44:38.991371 2026] [authz_core:error] [pid 514479:tid 514532] [remote 103.215.74.26:49678] AH01630: client denied by server configuration: /home2/acupu265/auriculo.liranesuliano.com/.htpasswd, referer: https://www.google.com/
[Tue Jul 21 08:44:38.999962 2026] [security2:error] [pid 514479:tid 514494] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9bpvzqsQqnLoCgUjhncwABDQo"]
[Tue Jul 21 08:44:39.025640 2026] [security2:error] [pid 514479:tid 514621] [client 20.197.195.24:63120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/k.php"] [unique_id "al9bp_zqsQqnLoCgUjhndAAAARE"]
[Tue Jul 21 08:44:39.168513 2026] [proxy:error] [pid 511108:tid 511354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:39.168578 2026] [proxy_http:error] [pid 511108:tid 511354] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:39.169198 2026] [proxy:error] [pid 511108:tid 511354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:39.169223 2026] [proxy_http:error] [pid 511108:tid 511354] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:39.230550 2026] [security2:error] [pid 514479:tid 514500] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9bp_zqsQqnLoCgUjhndQABKxA"]
[Tue Jul 21 08:44:39.243453 2026] [security2:error] [pid 511108:tid 511206] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "login.gradiente.com"] [uri "/graphql"] [unique_id "al9bp4Td5soprXwxAH0FVQAAK2E"]
[Tue Jul 21 08:44:39.244189 2026] [security2:error] [pid 514479:tid 514688] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9bp_zqsQqnLoCgUjhndgAAAVQ"]
[Tue Jul 21 08:44:39.246674 2026] [security2:error] [pid 514479:tid 514700] [client 195.49.128.211:57040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bp_zqsQqnLoCgUjhndwAAAWA"]
[Tue Jul 21 08:44:39.246755 2026] [security2:error] [pid 514479:tid 514700] [client 195.49.128.211:57040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bp_zqsQqnLoCgUjhndwAAAWA"]
[Tue Jul 21 08:44:39.551729 2026] [proxy:error] [pid 514479:tid 514654] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:39.551799 2026] [proxy_http:error] [pid 514479:tid 514654] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:39.552476 2026] [proxy:error] [pid 514479:tid 514654] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:44:39.552504 2026] [proxy_http:error] [pid 514479:tid 514654] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:44:39.579564 2026] [security2:error] [pid 511108:tid 511194] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "login.gradiente.com"] [uri "/api/graphql"] [unique_id "al9bp4Td5soprXwxAH0FXgAAK1U"]
[Tue Jul 21 08:44:39.591760 2026] [security2:error] [pid 511108:tid 511249] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9bp4Td5soprXwxAH0FYAAAAAs"]
[Tue Jul 21 08:44:39.593985 2026] [security2:error] [pid 514479:tid 514600] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9bp_zqsQqnLoCgUjhnfgABL3M"]
[Tue Jul 21 08:44:39.777712 2026] [security2:error] [pid 511108:tid 511341] [client 20.197.195.24:63175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/aaa.php"] [unique_id "al9bp4Td5soprXwxAH0FaQAAAGc"]
[Tue Jul 21 08:44:39.793356 2026] [security2:error] [pid 514479:tid 514553] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9bp_zqsQqnLoCgUjhnggABbkQ"]
[Tue Jul 21 08:44:39.810020 2026] [security2:error] [pid 511108:tid 511171] [remote 116.179.37.176:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9bp4Td5soprXwxAH0FagAAET4"], referer: https://androapkmod.com/tag/zombieland-afk-survival-tudo-liberado/
[Tue Jul 21 08:44:39.863250 2026] [security2:error] [pid 514479:tid 514680] [client 59.95.197.55:54794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bp_zqsQqnLoCgUjhngwAAAUw"]
[Tue Jul 21 08:44:39.863955 2026] [security2:error] [pid 514479:tid 514680] [client 59.95.197.55:54794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bp_zqsQqnLoCgUjhngwAAAUw"]
[Tue Jul 21 08:44:39.864916 2026] [security2:error] [pid 511108:tid 511351] [client 203.25.124.2:43133] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/plugin/"] [unique_id "al9bp4Td5soprXwxAH0FbAAAAHE"]
[Tue Jul 21 08:44:39.919035 2026] [security2:error] [pid 511108:tid 511230] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "login.gradiente.com"] [uri "/v1/graphql"] [unique_id "al9bp4Td5soprXwxAH0FbgAAfXk"]
[Tue Jul 21 08:44:39.953476 2026] [security2:error] [pid 511108:tid 511289] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9bp4Td5soprXwxAH0FcQAAADM"]
[Tue Jul 21 08:44:39.972799 2026] [security2:error] [pid 511108:tid 511273] [client 203.25.124.189:53203] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/preformatted/"] [unique_id "al9bp4Td5soprXwxAH0FdAAAACM"]
[Tue Jul 21 08:44:39.988530 2026] [security2:error] [pid 511108:tid 511180] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.env"] [unique_id "al9bp4Td5soprXwxAH0FdgAAbEc"]
[Tue Jul 21 08:44:40.004311 2026] [security2:error] [pid 511108:tid 511352] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bqITd5soprXwxAH0FeAAAAHI"]
[Tue Jul 21 08:44:40.169511 2026] [security2:error] [pid 514479:tid 514520] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9bqPzqsQqnLoCgUjhniAABhSQ"]
[Tue Jul 21 08:44:40.203467 2026] [security2:error] [pid 514479:tid 514628] [client 20.197.192.193:4000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/track.php"] [unique_id "al9bqPzqsQqnLoCgUjhniQAAARg"]
[Tue Jul 21 08:44:40.309536 2026] [security2:error] [pid 514479:tid 514692] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9bqPzqsQqnLoCgUjhniwAAAVg"]
[Tue Jul 21 08:44:40.334622 2026] [security2:error] [pid 511108:tid 511247] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bp4Td5soprXwxAH0FawAAAAk"]
[Tue Jul 21 08:44:40.439166 2026] [authz_core:error] [pid 514479:tid 514486] [remote 103.215.74.26:49678] AH01630: client denied by server configuration: /home2/acupu265/auriculo.liranesuliano.com/.htpasswd, referer: https://www.bing.com/
[Tue Jul 21 08:44:40.446079 2026] [security2:error] [pid 514479:tid 514503] [remote 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.tavarescont.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9bqPzqsQqnLoCgUjhnjgABfBM"]
[Tue Jul 21 08:44:40.458973 2026] [security2:error] [pid 511108:tid 511344] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9bqITd5soprXwxAH0FhwAAAGo"]
[Tue Jul 21 08:44:40.659603 2026] [security2:error] [pid 511108:tid 511246] [client 35.204.70.15:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "raquelmiriandasilva1748099664000.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9bqITd5soprXwxAH0FjgAAAAg"]
[Tue Jul 21 08:44:40.708503 2026] [security2:error] [pid 511108:tid 511347] [client 122.176.100.127:56268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bqITd5soprXwxAH0FjwAAAG0"]
[Tue Jul 21 08:44:40.708646 2026] [security2:error] [pid 511108:tid 511347] [client 122.176.100.127:56268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bqITd5soprXwxAH0FjwAAAG0"]
[Tue Jul 21 08:44:40.726534 2026] [security2:error] [pid 511108:tid 511225] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.env.backup"] [unique_id "al9bqITd5soprXwxAH0FlAAAS3Q"]
[Tue Jul 21 08:44:40.726600 2026] [security2:error] [pid 511108:tid 511190] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "login.gradiente.com"] [uri "/.env.local"] [unique_id "al9bqITd5soprXwxAH0FlgAAS1E"]
[Tue Jul 21 08:44:40.782236 2026] [security2:error] [pid 511108:tid 511117] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/backend/.env"] [unique_id "al9bqITd5soprXwxAH0FmQAAfgg"]
[Tue Jul 21 08:44:40.782377 2026] [security2:error] [pid 511108:tid 511364] [client 34.101.153.152:59196] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/backend/.env"] [unique_id "al9bqITd5soprXwxAH0FmQAAfgg"]
[Tue Jul 21 08:44:40.782883 2026] [security2:error] [pid 511108:tid 511226] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/config/.env"] [unique_id "al9bqITd5soprXwxAH0FmAAAfnU"]
[Tue Jul 21 08:44:40.783055 2026] [security2:error] [pid 511108:tid 511213] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/api/.env"] [unique_id "al9bqITd5soprXwxAH0FmgAAfmg"]
[Tue Jul 21 08:44:40.783355 2026] [security2:error] [pid 511108:tid 511146] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.env.bak"] [unique_id "al9bqITd5soprXwxAH0FlwAAfiU"]
[Tue Jul 21 08:44:40.784348 2026] [security2:error] [pid 511108:tid 511110] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.env.old"] [unique_id "al9bqITd5soprXwxAH0FnAAAfgE"]
[Tue Jul 21 08:44:40.854842 2026] [security2:error] [pid 511108:tid 511315] [client 212.32.76.12:52291] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/tinymce/langs/"] [unique_id "al9bqITd5soprXwxAH0FnwAAAE0"]
[Tue Jul 21 08:44:40.980243 2026] [security2:error] [pid 514479:tid 514722] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9bqPzqsQqnLoCgUjhnlwAAAXY"]
[Tue Jul 21 08:44:41.072012 2026] [security2:error] [pid 514479:tid 514740] [client 20.197.195.24:63172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/file5.php"] [unique_id "al9bqfzqsQqnLoCgUjhnnAAAAYg"]
[Tue Jul 21 08:44:41.157657 2026] [security2:error] [pid 511108:tid 511198] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "login.gradiente.com"] [uri "/.npmrc"] [unique_id "al9bqYTd5soprXwxAH0FrQAAeFk"]
[Tue Jul 21 08:44:41.170955 2026] [security2:error] [pid 511108:tid 511189] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/firebase-adminsdk.json"] [unique_id "al9bqYTd5soprXwxAH0FrgAAQlA"]
[Tue Jul 21 08:44:41.171132 2026] [security2:error] [pid 511108:tid 511304] [client 34.101.153.152:59196] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/firebase-adminsdk.json"] [unique_id "al9bqYTd5soprXwxAH0FrgAAQlA"]
[Tue Jul 21 08:44:41.174600 2026] [security2:error] [pid 514479:tid 514651] [client 203.25.124.203:40175] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "al9bqfzqsQqnLoCgUjhnngAAAS8"]
[Tue Jul 21 08:44:41.191965 2026] [security2:error] [pid 511108:tid 511197] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/serviceAccountKey.json"] [unique_id "al9bqYTd5soprXwxAH0FrwAABVg"]
[Tue Jul 21 08:44:41.192101 2026] [security2:error] [pid 511108:tid 511243] [client 34.101.153.152:59196] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/serviceAccountKey.json"] [unique_id "al9bqYTd5soprXwxAH0FrwAABVg"]
[Tue Jul 21 08:44:41.267693 2026] [security2:error] [pid 511108:tid 511169] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bqYTd5soprXwxAH0FsgAAMDw"]
[Tue Jul 21 08:44:41.267908 2026] [security2:error] [pid 511108:tid 511286] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bqYTd5soprXwxAH0FsgAAMDw"]
[Tue Jul 21 08:44:41.402202 2026] [security2:error] [pid 514479:tid 514712] [client 117.213.202.34:55120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bqfzqsQqnLoCgUjhnoAAAAWw"]
[Tue Jul 21 08:44:41.402340 2026] [security2:error] [pid 514479:tid 514712] [client 117.213.202.34:55120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bqfzqsQqnLoCgUjhnoAAAAWw"]
[Tue Jul 21 08:44:41.464150 2026] [security2:error] [pid 514479:tid 514655] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9bqfzqsQqnLoCgUjhnoQAAATM"]
[Tue Jul 21 08:44:41.500883 2026] [security2:error] [pid 511108:tid 511177] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/.htpasswd"] [unique_id "al9bqYTd5soprXwxAH0FvAAAIkQ"]
[Tue Jul 21 08:44:41.535267 2026] [security2:error] [pid 511108:tid 511159] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/.vscode/launch.json"] [unique_id "al9bqYTd5soprXwxAH0FvgAAADI"]
[Tue Jul 21 08:44:41.564443 2026] [security2:error] [pid 511108:tid 511115] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.ssh/id_rsa"] [unique_id "al9bqYTd5soprXwxAH0FvwAAIwY"]
[Tue Jul 21 08:44:41.671195 2026] [security2:error] [pid 511108:tid 511310] [client 202.179.75.202:33114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bqYTd5soprXwxAH0FwgAAAEg"]
[Tue Jul 21 08:44:41.671351 2026] [security2:error] [pid 511108:tid 511310] [client 202.179.75.202:33114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bqYTd5soprXwxAH0FwgAAAEg"]
[Tue Jul 21 08:44:41.846357 2026] [security2:error] [pid 511108:tid 511176] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.ssh/id_dsa"] [unique_id "al9bqYTd5soprXwxAH0FxwAAREM"]
[Tue Jul 21 08:44:41.891281 2026] [authz_core:error] [pid 514479:tid 514522] [remote 103.215.74.26:49678] AH01630: client denied by server configuration: /home2/acupu265/auriculo.liranesuliano.com/.htpasswd, referer: https://duckduckgo.com/
[Tue Jul 21 08:44:42.050264 2026] [security2:error] [pid 514479:tid 514732] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9bqvzqsQqnLoCgUjhnqQAAAYA"]
[Tue Jul 21 08:44:42.176753 2026] [security2:error] [pid 511108:tid 511206] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/id_rsa"] [unique_id "al9bqoTd5soprXwxAH0F1gAAPWE"]
[Tue Jul 21 08:44:42.201810 2026] [security2:error] [pid 511108:tid 511162] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/id_dsa"] [unique_id "al9bqoTd5soprXwxAH0F1wAAKjU"]
[Tue Jul 21 08:44:42.316548 2026] [security2:error] [pid 511108:tid 511220] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/key.pem"] [unique_id "al9bqoTd5soprXwxAH0F4AAAS28"]
[Tue Jul 21 08:44:42.373343 2026] [security2:error] [pid 511108:tid 511277] [client 203.25.124.10:25119] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/customize/"] [unique_id "al9bqoTd5soprXwxAH0F5AAAACc"]
[Tue Jul 21 08:44:42.485762 2026] [security2:error] [pid 511108:tid 511234] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/privatekey.key"] [unique_id "al9bqoTd5soprXwxAH0F5QAAfn0"]
[Tue Jul 21 08:44:42.543899 2026] [security2:error] [pid 511108:tid 511315] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9bqoTd5soprXwxAH0F6QAAAE0"]
[Tue Jul 21 08:44:42.550343 2026] [security2:error] [pid 514479:tid 514645] [client 152.59.181.104:55987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bqvzqsQqnLoCgUjhnrgAAASk"]
[Tue Jul 21 08:44:42.550429 2026] [security2:error] [pid 514479:tid 514645] [client 152.59.181.104:55987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bqvzqsQqnLoCgUjhnrgAAASk"]
[Tue Jul 21 08:44:42.584102 2026] [security2:error] [pid 511108:tid 511111] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/host.key"] [unique_id "al9bqoTd5soprXwxAH0F7gAARgI"]
[Tue Jul 21 08:44:42.584284 2026] [security2:error] [pid 511108:tid 511308] [client 34.101.153.152:59196] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/host.key"] [unique_id "al9bqoTd5soprXwxAH0F7gAARgI"]
[Tue Jul 21 08:44:42.711023 2026] [security2:error] [pid 511108:tid 511230] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9bqoTd5soprXwxAH0F-gAAVHk"]
[Tue Jul 21 08:44:42.722680 2026] [security2:error] [pid 514479:tid 514647] [client 20.197.195.24:63193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/222.php"] [unique_id "al9bqvzqsQqnLoCgUjhnsQAAASs"]
[Tue Jul 21 08:44:42.763867 2026] [security2:error] [pid 514479:tid 514673] [client 203.25.124.66:38545] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/query-pagination-previous/"] [unique_id "al9bqvzqsQqnLoCgUjhntAAAAUU"]
[Tue Jul 21 08:44:43.036173 2026] [security2:error] [pid 511108:tid 511140] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/.hermes/config.yaml"] [unique_id "al9bq4Td5soprXwxAH0GHgAAPR8"]
[Tue Jul 21 08:44:43.038081 2026] [security2:error] [pid 511108:tid 511112] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.hermes/.env"] [unique_id "al9bq4Td5soprXwxAH0GHwAAPQM"]
[Tue Jul 21 08:44:43.123514 2026] [security2:error] [pid 514479:tid 514727] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9bq_zqsQqnLoCgUjhoQwAAAXs"]
[Tue Jul 21 08:44:43.196280 2026] [security2:error] [pid 514479:tid 514689] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bq_zqsQqnLoCgUjhoRAABVSc"]
[Tue Jul 21 08:44:43.222091 2026] [authz_core:error] [pid 514479:tid 514577] [remote 103.215.74.26:49678] AH01630: client denied by server configuration: /home2/acupu265/auriculo.liranesuliano.com/.htpasswd
[Tue Jul 21 08:44:43.238080 2026] [security2:error] [pid 511108:tid 511216] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "al9bq4Td5soprXwxAH0GKwAAbms"]
[Tue Jul 21 08:44:43.447617 2026] [security2:error] [pid 511108:tid 511110] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "login.gradiente.com"] [uri "/.bash_profile"] [unique_id "al9bq4Td5soprXwxAH0GQQAAEAE"]
[Tue Jul 21 08:44:43.510716 2026] [security2:error] [pid 511108:tid 511129] [remote 103.161.172.221:41482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9bq4Td5soprXwxAH0GQwAAMRQ"]
[Tue Jul 21 08:44:43.538978 2026] [security2:error] [pid 511108:tid 511318] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9bq4Td5soprXwxAH0GRAAAAFA"]
[Tue Jul 21 08:44:43.622510 2026] [security2:error] [pid 511108:tid 511174] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "login.gradiente.com"] [uri "/wp-config.php.bak"] [unique_id "al9bq4Td5soprXwxAH0GRgAAPkE"]
[Tue Jul 21 08:44:43.635483 2026] [security2:error] [pid 511108:tid 511116] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "login.gradiente.com"] [uri "/wp-config.php.old"] [unique_id "al9bq4Td5soprXwxAH0GRwAAYwc"]
[Tue Jul 21 08:44:43.641940 2026] [security2:error] [pid 511108:tid 511227] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/storage/logs/laravel.log"] [unique_id "al9bq4Td5soprXwxAH0GSAAAcnY"]
[Tue Jul 21 08:44:43.664728 2026] [security2:error] [pid 511108:tid 511127] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/laravel/.env"] [unique_id "al9bq4Td5soprXwxAH0GTAAACRI"]
[Tue Jul 21 08:44:43.671950 2026] [security2:error] [pid 514479:tid 514627] [client 203.25.124.3:23843] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/classwithtostring.php"] [unique_id "al9bq_zqsQqnLoCgUjhoawAAARc"]
[Tue Jul 21 08:44:43.705637 2026] [security2:error] [pid 511108:tid 511317] [client 41.89.234.2:58365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bq4Td5soprXwxAH0GTgAAAE8"]
[Tue Jul 21 08:44:43.705747 2026] [security2:error] [pid 511108:tid 511317] [client 41.89.234.2:58365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bq4Td5soprXwxAH0GTgAAAE8"]
[Tue Jul 21 08:44:43.714328 2026] [security2:error] [pid 511108:tid 511313] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bq4Td5soprXwxAH0GJAAAAEs"]
[Tue Jul 21 08:44:43.821030 2026] [security2:error] [pid 511108:tid 511197] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/.env.php.bak"] [unique_id "al9bq4Td5soprXwxAH0GVgAANlg"]
[Tue Jul 21 08:44:43.821197 2026] [security2:error] [pid 511108:tid 511292] [client 34.101.153.152:59196] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/.env.php.bak"] [unique_id "al9bq4Td5soprXwxAH0GVgAANlg"]
[Tue Jul 21 08:44:43.927496 2026] [security2:error] [pid 514479:tid 514652] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9bq_zqsQqnLoCgUjhocgAAATA"]
[Tue Jul 21 08:44:43.938613 2026] [security2:error] [pid 514479:tid 514692] [client 198.44.157.34:57048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9bq_zqsQqnLoCgUjhocwAAAVg"]
[Tue Jul 21 08:44:43.938712 2026] [security2:error] [pid 514479:tid 514692] [client 198.44.157.34:57048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9bq_zqsQqnLoCgUjhocwAAAVg"]
[Tue Jul 21 08:44:44.006664 2026] [security2:error] [pid 511108:tid 511201] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/config.php.bak"] [unique_id "al9brITd5soprXwxAH0GXAAANlw"]
[Tue Jul 21 08:44:44.007054 2026] [security2:error] [pid 511108:tid 511200] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/core/.env"] [unique_id "al9brITd5soprXwxAH0GWgAANls"]
[Tue Jul 21 08:44:44.036146 2026] [security2:error] [pid 511108:tid 511167] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.env.swp"] [unique_id "al9brITd5soprXwxAH0GXgAANjo"]
[Tue Jul 21 08:44:44.065969 2026] [security2:error] [pid 511108:tid 511114] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/public/.env"] [unique_id "al9brITd5soprXwxAH0GYQAANgU"]
[Tue Jul 21 08:44:44.067429 2026] [security2:error] [pid 511108:tid 511177] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/web/.env"] [unique_id "al9brITd5soprXwxAH0GYAAANkQ"]
[Tue Jul 21 08:44:44.158930 2026] [security2:error] [pid 511108:tid 511204] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/configuration.php.bak"] [unique_id "al9bq4Td5soprXwxAH0GWQAANl8"]
[Tue Jul 21 08:44:44.247421 2026] [security2:error] [pid 514479:tid 514686] [client 20.197.195.24:63152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/test.php"] [unique_id "al9brPzqsQqnLoCgUjhofAAAAVI"]
[Tue Jul 21 08:44:44.339058 2026] [security2:error] [pid 514479:tid 514715] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9brPzqsQqnLoCgUjhofgAAAW8"]
[Tue Jul 21 08:44:44.420855 2026] [security2:error] [pid 511108:tid 511236] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "login.gradiente.com"] [uri "/config/secrets.yml"] [unique_id "al9brITd5soprXwxAH0GdAAANn8"]
[Tue Jul 21 08:44:44.463176 2026] [security2:error] [pid 514479:tid 514682] [client 203.25.124.50:24321] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Requests/src/Auth/"] [unique_id "al9brPzqsQqnLoCgUjhogQAAAU4"]
[Tue Jul 21 08:44:44.613882 2026] [authz_core:error] [pid 514479:tid 514498] [remote 103.215.74.26:49678] AH01630: client denied by server configuration: /home2/acupu265/auriculo.liranesuliano.com/.htpasswd
[Tue Jul 21 08:44:44.770732 2026] [security2:error] [pid 514479:tid 514666] [client 20.197.195.24:63126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/aaa.php"] [unique_id "al9brPzqsQqnLoCgUjhohwAAAT4"]
[Tue Jul 21 08:44:44.773645 2026] [security2:error] [pid 511108:tid 511138] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/config/.env.php"] [unique_id "al9bq4Td5soprXwxAH0GUwAANh0"]
[Tue Jul 21 08:44:44.781456 2026] [security2:error] [pid 511108:tid 511298] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9brITd5soprXwxAH0GhAAAADw"]
[Tue Jul 21 08:44:45.124872 2026] [security2:error] [pid 511108:tid 511234] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/local.settings.json"] [unique_id "al9brYTd5soprXwxAH0GjAAAEX0"]
[Tue Jul 21 08:44:45.126872 2026] [security2:error] [pid 511108:tid 511208] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/web.config"] [unique_id "al9brYTd5soprXwxAH0GjQAAEWM"]
[Tue Jul 21 08:44:45.189909 2026] [security2:error] [pid 514479:tid 514732] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9brfzqsQqnLoCgUjhojQAAAYA"]
[Tue Jul 21 08:44:45.269180 2026] [security2:error] [pid 514479:tid 514672] [client 173.252.95.39:48646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9brPzqsQqnLoCgUjhofQAAAUQ"]
[Tue Jul 21 08:44:45.373597 2026] [security2:error] [pid 514479:tid 514699] [client 203.25.124.70:27967] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/wp.php"] [unique_id "al9brfzqsQqnLoCgUjhokwAAAV8"]
[Tue Jul 21 08:44:45.473670 2026] [security2:error] [pid 514479:tid 514654] [client 203.25.124.199:35429] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/gallery/"] [unique_id "al9brfzqsQqnLoCgUjholQAAATI"]
[Tue Jul 21 08:44:45.499199 2026] [security2:error] [pid 511108:tid 511322] [client 5.38.115.39:51920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9brYTd5soprXwxAH0GoAAAAFQ"]
[Tue Jul 21 08:44:45.499315 2026] [security2:error] [pid 511108:tid 511322] [client 5.38.115.39:51920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9brYTd5soprXwxAH0GoAAAAFQ"]
[Tue Jul 21 08:44:45.553248 2026] [security2:error] [pid 511108:tid 511140] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/sendgrid.env"] [unique_id "al9brYTd5soprXwxAH0GqQAATh8"]
[Tue Jul 21 08:44:45.553392 2026] [security2:error] [pid 511108:tid 511316] [client 34.101.153.152:59196] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/sendgrid.env"] [unique_id "al9brYTd5soprXwxAH0GqQAATh8"]
[Tue Jul 21 08:44:45.618963 2026] [security2:error] [pid 514479:tid 514678] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9brfzqsQqnLoCgUjholwAAAUo"]
[Tue Jul 21 08:44:45.809964 2026] [security2:error] [pid 514479:tid 514679] [client 20.197.192.193:4093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/2352356666.php"] [unique_id "al9brfzqsQqnLoCgUjhomQAAAUs"]
[Tue Jul 21 08:44:45.854024 2026] [security2:error] [pid 511108:tid 511117] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/frontend/.env"] [unique_id "al9brYTd5soprXwxAH0GtwAAXwg"]
[Tue Jul 21 08:44:45.861744 2026] [security2:error] [pid 514479:tid 514601] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9brfzqsQqnLoCgUjhonAABbHQ"]
[Tue Jul 21 08:44:45.861880 2026] [security2:error] [pid 514479:tid 514712] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9brfzqsQqnLoCgUjhonAABbHQ"]
[Tue Jul 21 08:44:45.892380 2026] [security2:error] [pid 514479:tid 514695] [client 20.197.195.24:63149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/11.php"] [unique_id "al9brfzqsQqnLoCgUjhonQAAAVs"]
[Tue Jul 21 08:44:45.905272 2026] [security2:error] [pid 511108:tid 511141] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/app/.env"] [unique_id "al9brYTd5soprXwxAH0GuQAAZCA"]
[Tue Jul 21 08:44:45.905336 2026] [security2:error] [pid 511108:tid 511192] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/src/.env"] [unique_id "al9brYTd5soprXwxAH0GuwAAZFM"]
[Tue Jul 21 08:44:45.905336 2026] [security2:error] [pid 511108:tid 511121] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/server/.env"] [unique_id "al9brYTd5soprXwxAH0GugAAZAw"]
[Tue Jul 21 08:44:45.925260 2026] [security2:error] [pid 511108:tid 511226] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/dev/.env"] [unique_id "al9brYTd5soprXwxAH0GvQAAenU"]
[Tue Jul 21 08:44:45.943138 2026] [security2:error] [pid 511108:tid 511219] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/production/.env"] [unique_id "al9brYTd5soprXwxAH0GvwAAQG4"]
[Tue Jul 21 08:44:45.964939 2026] [security2:error] [pid 511108:tid 511146] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/docker/.env"] [unique_id "al9brYTd5soprXwxAH0GwAAALiU"]
[Tue Jul 21 08:44:46.086594 2026] [security2:error] [pid 514479:tid 514687] [client 20.197.192.193:27074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wicked.php"] [unique_id "al9brvzqsQqnLoCgUjhonwAAAVM"]
[Tue Jul 21 08:44:46.163865 2026] [security2:error] [pid 514479:tid 514677] [client 64.42.179.43:38138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9brvzqsQqnLoCgUjhoowAAAUk"]
[Tue Jul 21 08:44:46.163953 2026] [security2:error] [pid 514479:tid 514677] [client 64.42.179.43:38138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9brvzqsQqnLoCgUjhoowAAAUk"]
[Tue Jul 21 08:44:46.236378 2026] [security2:error] [pid 511108:tid 511222] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/.env.prod.bak"] [unique_id "al9broTd5soprXwxAH0GxQAAPXE"]
[Tue Jul 21 08:44:46.236611 2026] [security2:error] [pid 511108:tid 511299] [client 34.101.153.152:59196] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/.env.prod.bak"] [unique_id "al9broTd5soprXwxAH0GxQAAPXE"]
[Tue Jul 21 08:44:46.237475 2026] [security2:error] [pid 511108:tid 511203] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/staging/.env"] [unique_id "al9broTd5soprXwxAH0GxAAAPV4"]
[Tue Jul 21 08:44:46.237900 2026] [security2:error] [pid 511108:tid 511207] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/.env.production.bak"] [unique_id "al9broTd5soprXwxAH0GwwAAPWI"]
[Tue Jul 21 08:44:46.264018 2026] [security2:error] [pid 511108:tid 511227] [remote 34.101.153.152:59196] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "login.gradiente.com"] [uri "/@fs/proc/self/environ"] [unique_id "al9broTd5soprXwxAH0GyAAAW3Y"]
[Tue Jul 21 08:44:46.265784 2026] [security2:error] [pid 511108:tid 511147] [remote 34.101.153.152:59196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/@fs/.env"] [unique_id "al9broTd5soprXwxAH0GyQAAWyY"]
[Tue Jul 21 08:44:46.266879 2026] [security2:error] [pid 514479:tid 514682] [client 203.25.124.206:64895] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/js/widgets/images/"] [unique_id "al9brvzqsQqnLoCgUjhopAAAAU4"]
[Tue Jul 21 08:44:46.471787 2026] [security2:error] [pid 514479:tid 514726] [client 212.32.76.10:25215] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/news-portal/sitebar.php"] [unique_id "al9brvzqsQqnLoCgUjhoqgAAAXo"]
[Tue Jul 21 08:44:46.483938 2026] [security2:error] [pid 514479:tid 514631] [client 168.167.81.163:62568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9brvzqsQqnLoCgUjhoqwAAARs"]
[Tue Jul 21 08:44:46.484703 2026] [security2:error] [pid 514479:tid 514631] [client 168.167.81.163:62568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9brvzqsQqnLoCgUjhoqwAAARs"]
[Tue Jul 21 08:44:46.683532 2026] [security2:error] [pid 511108:tid 511290] [client 20.197.195.24:49996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/mac.php"] [unique_id "al9broTd5soprXwxAH0G0QAAADQ"]
[Tue Jul 21 08:44:46.803479 2026] [security2:error] [pid 511108:tid 511361] [client 113.22.144.139:54592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9broTd5soprXwxAH0G0gAAAHs"]
[Tue Jul 21 08:44:46.803608 2026] [security2:error] [pid 511108:tid 511361] [client 113.22.144.139:54592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9broTd5soprXwxAH0G0gAAAHs"]
[Tue Jul 21 08:44:46.848655 2026] [security2:error] [pid 511108:tid 511198] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9broTd5soprXwxAH0G1AAAbVk"]
[Tue Jul 21 08:44:46.848771 2026] [security2:error] [pid 511108:tid 511347] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9broTd5soprXwxAH0G1AAAbVk"]
[Tue Jul 21 08:44:47.181264 2026] [security2:error] [pid 514479:tid 514600] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/db.sql"] [unique_id "al9br_zqsQqnLoCgUjho3wABK3M"]
[Tue Jul 21 08:44:47.181264 2026] [security2:error] [pid 514479:tid 514503] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/dump.sql"] [unique_id "al9br_zqsQqnLoCgUjho4wABKxM"]
[Tue Jul 21 08:44:47.181308 2026] [security2:error] [pid 514479:tid 514502] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/mysql.sql"] [unique_id "al9br_zqsQqnLoCgUjho5QABKxI"]
[Tue Jul 21 08:44:47.295218 2026] [security2:error] [pid 511108:tid 511298] [client 114.198.138.124:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9br4Td5soprXwxAH0G4AAAADw"]
[Tue Jul 21 08:44:47.295391 2026] [security2:error] [pid 511108:tid 511298] [client 114.198.138.124:65480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9br4Td5soprXwxAH0G4AAAADw"]
[Tue Jul 21 08:44:47.325944 2026] [security2:error] [pid 511108:tid 511177] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/firebase-config.json"] [unique_id "al9br4Td5soprXwxAH0G6AAAJ0Q"]
[Tue Jul 21 08:44:47.326559 2026] [security2:error] [pid 514479:tid 514494] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/database.sql"] [unique_id "al9br_zqsQqnLoCgUjho7QABKwo"]
[Tue Jul 21 08:44:47.328158 2026] [security2:error] [pid 514479:tid 514526] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-login.php"] [unique_id "al9br_zqsQqnLoCgUjho6gABKyo"]
[Tue Jul 21 08:44:47.328964 2026] [security2:error] [pid 514479:tid 514526] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9br_zqsQqnLoCgUjho8QABKyo"]
[Tue Jul 21 08:44:47.329351 2026] [security2:error] [pid 511108:tid 511201] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "login.gradiente.com"] [uri "/api/v1/settings"] [unique_id "al9br4Td5soprXwxAH0G6gAAJ1w"]
[Tue Jul 21 08:44:47.330257 2026] [security2:error] [pid 514479:tid 514597] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/backup.sql"] [unique_id "al9br_zqsQqnLoCgUjho8gABK3A"]
[Tue Jul 21 08:44:47.334333 2026] [security2:error] [pid 514479:tid 514496] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/info.php"] [unique_id "al9br_zqsQqnLoCgUjhpBgABKww"]
[Tue Jul 21 08:44:47.334908 2026] [security2:error] [pid 514479:tid 514496] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/phpinfo.php"] [unique_id "al9br_zqsQqnLoCgUjhpCAABKww"]
[Tue Jul 21 08:44:47.335346 2026] [security2:error] [pid 514479:tid 514496] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/opcache-status.php"] [unique_id "al9br_zqsQqnLoCgUjhpDAABKww"]
[Tue Jul 21 08:44:47.368466 2026] [security2:error] [pid 514479:tid 514536] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.bak"] [unique_id "al9br_zqsQqnLoCgUjhpNwABKzQ"]
[Tue Jul 21 08:44:47.369610 2026] [security2:error] [pid 514479:tid 514508] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.local.backup"] [unique_id "al9br_zqsQqnLoCgUjhpNAABKxg"]
[Tue Jul 21 08:44:47.373485 2026] [security2:error] [pid 514479:tid 514609] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.backup"] [unique_id "al9br_zqsQqnLoCgUjhpLwABK3w"]
[Tue Jul 21 08:44:47.386344 2026] [security2:error] [pid 514479:tid 514551] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.local.old"] [unique_id "al9br_zqsQqnLoCgUjhpPQABK0I"]
[Tue Jul 21 08:44:47.387699 2026] [security2:error] [pid 514479:tid 514611] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env~"] [unique_id "al9br_zqsQqnLoCgUjhpPgABK34"]
[Tue Jul 21 08:44:47.390283 2026] [security2:error] [pid 514479:tid 514637] [client 20.197.195.24:63184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/chosen.php"] [unique_id "al9br_zqsQqnLoCgUjhpQwAAASE"]
[Tue Jul 21 08:44:47.392394 2026] [security2:error] [pid 514479:tid 514500] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.local~"] [unique_id "al9br_zqsQqnLoCgUjhpPAABKxA"]
[Tue Jul 21 08:44:47.392823 2026] [security2:error] [pid 514479:tid 514564] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.local.bak"] [unique_id "al9br_zqsQqnLoCgUjhpOwABK08"]
[Tue Jul 21 08:44:47.489952 2026] [core:error] [pid 511108:tid 511158] [remote 103.215.74.26:34040] AH10244: invalid URI path (/dana-na/../dana/html5acc/guacamole/../../../../../../../etc/passwd?/dana/html5acc/guacamole/)
[Tue Jul 21 08:44:47.490962 2026] [security2:error] [pid 511108:tid 511149] [remote 103.215.74.26:34040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9br4Td5soprXwxAH0G9AAAMCg"]
[Tue Jul 21 08:44:47.498529 2026] [security2:error] [pid 514479:tid 514484] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.old"] [unique_id "al9br_zqsQqnLoCgUjhpRwABKwA"]
[Tue Jul 21 08:44:47.499009 2026] [security2:error] [pid 511108:tid 511193] [remote 103.215.74.26:34040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.local.orig"] [unique_id "al9br4Td5soprXwxAH0G9QAAMFQ"]
[Tue Jul 21 08:44:47.501557 2026] [security2:error] [pid 514479:tid 514502] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9br_zqsQqnLoCgUjhpTAABKxI"]
[Tue Jul 21 08:44:47.501741 2026] [security2:error] [pid 514479:tid 514560] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-login.php"] [unique_id "al9br_zqsQqnLoCgUjhpTgABK0s"]
[Tue Jul 21 08:44:47.502706 2026] [security2:error] [pid 514479:tid 514499] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9br_zqsQqnLoCgUjhpUQABKw8"]
[Tue Jul 21 08:44:47.504738 2026] [security2:error] [pid 514479:tid 514531] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/export.sql"] [unique_id "al9br_zqsQqnLoCgUjhpSQABKy8"]
[Tue Jul 21 08:44:47.504827 2026] [security2:error] [pid 514479:tid 514484] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.swp"] [unique_id "al9br_zqsQqnLoCgUjhpSAABKwA"]
[Tue Jul 21 08:44:47.506320 2026] [security2:error] [pid 514479:tid 514541] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.local.swp"] [unique_id "al9br_zqsQqnLoCgUjhpSgABKzk"]
[Tue Jul 21 08:44:47.506320 2026] [security2:error] [pid 514479:tid 514560] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.copy"] [unique_id "al9br_zqsQqnLoCgUjhpUAABK0s"]
[Tue Jul 21 08:44:47.580273 2026] [security2:error] [pid 514479:tid 514672] [client 212.32.76.54:59453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/imgareaselect/"] [unique_id "al9br_zqsQqnLoCgUjhpUwAAAUQ"]
[Tue Jul 21 08:44:47.596381 2026] [security2:error] [pid 514479:tid 514617] [client 20.197.195.24:63171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/cream1.php"] [unique_id "al9br_zqsQqnLoCgUjhpVQAAAQ0"]
[Tue Jul 21 08:44:47.607094 2026] [security2:error] [pid 511108:tid 511365] [client 103.59.206.240:31335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9br4Td5soprXwxAH0G9wAAAH8"]
[Tue Jul 21 08:44:47.607187 2026] [security2:error] [pid 511108:tid 511365] [client 103.59.206.240:31335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9br4Td5soprXwxAH0G9wAAAH8"]
[Tue Jul 21 08:44:47.651712 2026] [security2:error] [pid 511108:tid 511358] [client 195.49.128.211:49837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9br4Td5soprXwxAH0G-QAAAHg"]
[Tue Jul 21 08:44:47.651986 2026] [security2:error] [pid 511108:tid 511358] [client 195.49.128.211:49837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9br4Td5soprXwxAH0G-QAAAHg"]
[Tue Jul 21 08:44:47.672840 2026] [security2:error] [pid 511108:tid 511310] [client 203.25.124.74:48591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/database.php"] [unique_id "al9br4Td5soprXwxAH0G_QAAAEg"]
[Tue Jul 21 08:44:47.770356 2026] [security2:error] [pid 511108:tid 511157] [remote 103.215.74.26:34040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9br4Td5soprXwxAH0HAQAAMDA"]
[Tue Jul 21 08:44:47.771174 2026] [security2:error] [pid 511108:tid 511153] [remote 103.215.74.26:34040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php"] [unique_id "al9br4Td5soprXwxAH0HAgAAMCw"]
[Tue Jul 21 08:44:47.909601 2026] [security2:error] [pid 511108:tid 511346] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9br4Td5soprXwxAH0G7QAAAGw"]
[Tue Jul 21 08:44:47.912750 2026] [http2:info] [pid 511108:tid 511286] [client 103.215.74.26:34040] AH10178: h2_stream(511108-1147-17,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:44:47.915710 2026] [security2:error] [pid 511108:tid 511176] [remote 103.215.74.26:34040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.env.orig"] [unique_id "al9br4Td5soprXwxAH0HCQAAMEM"]
[Tue Jul 21 08:44:48.047337 2026] [security2:error] [pid 511108:tid 511111] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/api/v2/settings"] [unique_id "al9bsITd5soprXwxAH0HFgAATAI"]
[Tue Jul 21 08:44:48.047483 2026] [security2:error] [pid 511108:tid 511314] [client 34.101.153.152:44738] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/api/v2/settings"] [unique_id "al9bsITd5soprXwxAH0HFgAATAI"]
[Tue Jul 21 08:44:48.074149 2026] [autoindex:error] [pid 514479:tid 514628] [client 20.197.195.24:63114] AH01276: Cannot serve directory /home4/drjoao27/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:48.094516 2026] [autoindex:error] [pid 514479:tid 514676] [client 20.197.195.24:63114] AH01276: Cannot serve directory /home4/drjoao27/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:48.099692 2026] [security2:error] [pid 514479:tid 514683] [client 20.197.195.24:63114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/dr.php"] [unique_id "al9bsPzqsQqnLoCgUjhpWwAAAU8"]
[Tue Jul 21 08:44:48.165064 2026] [security2:error] [pid 511108:tid 511144] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/api/openapi.json"] [unique_id "al9bsITd5soprXwxAH0HGwAARyM"]
[Tue Jul 21 08:44:48.165219 2026] [security2:error] [pid 511108:tid 511309] [client 34.101.153.152:44738] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/api/openapi.json"] [unique_id "al9bsITd5soprXwxAH0HGwAARyM"]
[Tue Jul 21 08:44:48.327174 2026] [security2:error] [pid 511108:tid 511329] [client 49.144.66.253:31474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bsITd5soprXwxAH0HHwAAAFs"]
[Tue Jul 21 08:44:48.327373 2026] [security2:error] [pid 511108:tid 511329] [client 49.144.66.253:31474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bsITd5soprXwxAH0HHwAAAFs"]
[Tue Jul 21 08:44:48.394893 2026] [lsapi:error] [pid 514479:tid 514488] [remote 103.215.74.26:49678] [host auriculo.liranesuliano.com] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown
[Tue Jul 21 08:44:48.394923 2026] [lsapi:error] [pid 514479:tid 514488] [remote 103.215.74.26:49678] [host auriculo.liranesuliano.com] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache
[Tue Jul 21 08:44:48.394931 2026] [lsapi:error] [pid 514479:tid 514488] [remote 103.215.74.26:49678] [host auriculo.liranesuliano.com] Client error on sending request(POST /health HTTP/2.0); uri(/index.php) content-length(78): user_get_body(tmpstackbuf, 16384): read from client failed
[Tue Jul 21 08:44:48.561447 2026] [security2:error] [pid 511108:tid 511124] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/api/v1/env"] [unique_id "al9bsITd5soprXwxAH0HLgAAbg8"]
[Tue Jul 21 08:44:48.569682 2026] [security2:error] [pid 514479:tid 514712] [client 198.44.157.34:60056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9bsPzqsQqnLoCgUjhpYwAAAWw"]
[Tue Jul 21 08:44:48.569749 2026] [security2:error] [pid 514479:tid 514712] [client 198.44.157.34:60056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9bsPzqsQqnLoCgUjhpYwAAAWw"]
[Tue Jul 21 08:44:48.674906 2026] [security2:error] [pid 511108:tid 511251] [client 212.32.76.66:55121] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "al9bsITd5soprXwxAH0HMQAAAA0"]
[Tue Jul 21 08:44:48.798409 2026] [security2:error] [pid 511108:tid 511225] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/graphql/console"] [unique_id "al9bsITd5soprXwxAH0HNwAAN3Q"]
[Tue Jul 21 08:44:48.835235 2026] [security2:error] [pid 511108:tid 511132] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/graphql"] [unique_id "al9bsITd5soprXwxAH0HOQAATRc"]
[Tue Jul 21 08:44:48.961452 2026] [security2:error] [pid 511108:tid 511248] [client 203.25.124.213:50023] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/login.php"] [unique_id "al9bsITd5soprXwxAH0HQAAAAAo"]
[Tue Jul 21 08:44:49.009809 2026] [security2:error] [pid 514479:tid 514697] [client 198.44.157.34:60046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9bsfzqsQqnLoCgUjhpaQAAAV0"]
[Tue Jul 21 08:44:49.009900 2026] [security2:error] [pid 514479:tid 514697] [client 198.44.157.34:60046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9bsfzqsQqnLoCgUjhpaQAAAV0"]
[Tue Jul 21 08:44:49.155174 2026] [security2:error] [pid 511108:tid 511110] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/test.php"] [unique_id "al9bsYTd5soprXwxAH0HSQAAIgE"]
[Tue Jul 21 08:44:49.157340 2026] [security2:error] [pid 511108:tid 511235] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/info.php"] [unique_id "al9bsYTd5soprXwxAH0HSgAAIX4"]
[Tue Jul 21 08:44:49.174675 2026] [security2:error] [pid 511108:tid 511129] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/pi.php"] [unique_id "al9bsYTd5soprXwxAH0HSwAAfRQ"]
[Tue Jul 21 08:44:49.175086 2026] [security2:error] [pid 511108:tid 511222] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/phpinfo.php"] [unique_id "al9bsYTd5soprXwxAH0HTAAAfXE"]
[Tue Jul 21 08:44:49.216320 2026] [security2:error] [pid 511108:tid 511207] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/i.php"] [unique_id "al9bsYTd5soprXwxAH0HTgAAU2I"]
[Tue Jul 21 08:44:49.391020 2026] [security2:error] [pid 514479:tid 514707] [client 20.197.195.24:63186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/x.php"] [unique_id "al9bsfzqsQqnLoCgUjhpbwAAAWc"]
[Tue Jul 21 08:44:49.460791 2026] [lsapi:error] [pid 514479:tid 514580] [remote 103.215.74.26:49678] [host auriculo.liranesuliano.com] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown
[Tue Jul 21 08:44:49.460829 2026] [lsapi:error] [pid 514479:tid 514580] [remote 103.215.74.26:49678] [host auriculo.liranesuliano.com] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache
[Tue Jul 21 08:44:49.460836 2026] [lsapi:error] [pid 514479:tid 514580] [remote 103.215.74.26:49678] [host auriculo.liranesuliano.com] Client error on sending request(POST /actuator/env HTTP/2.0); uri(/index.php) content-length(78): user_get_body(tmpstackbuf, 16384): read from client failed
[Tue Jul 21 08:44:49.596889 2026] [security2:error] [pid 511108:tid 511127] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/__debug__/"] [unique_id "al9bsYTd5soprXwxAH0HWAAASBI"]
[Tue Jul 21 08:44:49.699502 2026] [security2:error] [pid 511108:tid 511189] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/app_dev.php/_profiler"] [unique_id "al9bsYTd5soprXwxAH0HYAAAWlA"]
[Tue Jul 21 08:44:49.699611 2026] [security2:error] [pid 511108:tid 511169] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "login.gradiente.com"] [uri "/telescope/requests"] [unique_id "al9bsYTd5soprXwxAH0HYQAAWjw"]
[Tue Jul 21 08:44:49.699911 2026] [security2:error] [pid 511108:tid 511173] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.153.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "login.gradiente.com"] [uri "/app_dev.php"] [unique_id "al9bsYTd5soprXwxAH0HYgAAWkA"]
[Tue Jul 21 08:44:49.709443 2026] [security2:error] [pid 511108:tid 511224] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "login.gradiente.com"] [uri "/_debugbar/open"] [unique_id "al9bsYTd5soprXwxAH0HYwAAWnM"]
[Tue Jul 21 08:44:49.709569 2026] [security2:error] [pid 511108:tid 511328] [client 34.101.153.152:44738] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "login.gradiente.com"] [uri "/_debugbar/open"] [unique_id "al9bsYTd5soprXwxAH0HYwAAWnM"]
[Tue Jul 21 08:44:49.727185 2026] [access_compat:error] [pid 511108:tid 511198] [remote 34.101.153.152:44738] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 08:44:49.832581 2026] [security2:error] [pid 511108:tid 511365] [client 195.49.128.211:57645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bsYTd5soprXwxAH0HaQAAAH8"]
[Tue Jul 21 08:44:49.832760 2026] [security2:error] [pid 511108:tid 511365] [client 195.49.128.211:57645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bsYTd5soprXwxAH0HaQAAAH8"]
[Tue Jul 21 08:44:49.832976 2026] [http2:info] [pid 511108:tid 511313] [client 103.215.74.26:34040] AH10178: h2_stream(511108-1147-89,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:44:49.846241 2026] [security2:error] [pid 514479:tid 514739] [client 20.197.195.24:63121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/155.php"] [unique_id "al9bsfzqsQqnLoCgUjhpdAAAAYc"]
[Tue Jul 21 08:44:49.967399 2026] [security2:error] [pid 511108:tid 511200] [remote 34.101.153.152:44738] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "login.gradiente.com"] [uri "/server-info"] [unique_id "al9bsYTd5soprXwxAH0HbAAAKFs"]
[Tue Jul 21 08:44:49.971936 2026] [security2:error] [pid 511108:tid 511305] [client 203.25.124.197:25683] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/shell/"] [unique_id "al9bsYTd5soprXwxAH0HbgAAAEM"]
[Tue Jul 21 08:44:50.068461 2026] [security2:error] [pid 511108:tid 511280] [client 203.25.124.65:49983] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/user/config.php"] [unique_id "al9bsoTd5soprXwxAH0HdgAAACo"]
[Tue Jul 21 08:44:50.185701 2026] [security2:error] [pid 514479:tid 514732] [client 20.197.195.24:63167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ops.php"] [unique_id "al9bsvzqsQqnLoCgUjhpdwAAAYA"]
[Tue Jul 21 08:44:50.320710 2026] [lsapi:error] [pid 514479:tid 514572] [remote 103.215.74.26:49678] [host auriculo.liranesuliano.com] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown
[Tue Jul 21 08:44:50.320741 2026] [lsapi:error] [pid 514479:tid 514572] [remote 103.215.74.26:49678] [host auriculo.liranesuliano.com] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache
[Tue Jul 21 08:44:50.320751 2026] [lsapi:error] [pid 514479:tid 514572] [remote 103.215.74.26:49678] [host auriculo.liranesuliano.com] Client error on sending request(POST / HTTP/2.0); uri(/) content-length(78): user_get_body(tmpstackbuf, 16384): read from client failed
[Tue Jul 21 08:44:50.322041 2026] [security2:error] [pid 514479:tid 514645] [client 185.213.175.37:18824] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "blog.importeicomponentes.com.br"] [uri "/feed/"] [unique_id "al9bsvzqsQqnLoCgUjhpegAAASk"]
[Tue Jul 21 08:44:50.340402 2026] [security2:error] [pid 511108:tid 511288] [client 59.95.197.55:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bsoTd5soprXwxAH0HfQAAADI"]
[Tue Jul 21 08:44:50.340669 2026] [security2:error] [pid 511108:tid 511288] [client 59.95.197.55:55264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bsoTd5soprXwxAH0HfQAAADI"]
[Tue Jul 21 08:44:50.395869 2026] [lsapi:error] [pid 514479:tid 514502] [remote 103.215.74.26:49678] [host auriculo.liranesuliano.com] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown
[Tue Jul 21 08:44:50.395890 2026] [lsapi:error] [pid 514479:tid 514502] [remote 103.215.74.26:49678] [host auriculo.liranesuliano.com] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache
[Tue Jul 21 08:44:50.395896 2026] [lsapi:error] [pid 514479:tid 514502] [remote 103.215.74.26:49678] [host auriculo.liranesuliano.com] Client error on sending request(POST /_ignition/execute-solution HTTP/2.0); uri(/index.php) content-length(179): user_get_body(tmpstackbuf, 16384): read from client failed
[Tue Jul 21 08:44:50.452151 2026] [security2:error] [pid 511108:tid 511312] [client 20.197.195.24:49987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/file31.php"] [unique_id "al9bsoTd5soprXwxAH0HhwAAAEo"]
[Tue Jul 21 08:44:50.516904 2026] [security2:error] [pid 511108:tid 511244] [client 173.252.95.16:57082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bsoTd5soprXwxAH0HfgAAAAY"]
[Tue Jul 21 08:44:50.612661 2026] [security2:error] [pid 514479:tid 514500] [remote 159.223.116.62:57940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.116.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9bsvzqsQqnLoCgUjhphAABYRA"]
[Tue Jul 21 08:44:50.612862 2026] [security2:error] [pid 514479:tid 514701] [client 159.223.116.62:57940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9bsvzqsQqnLoCgUjhphAABYRA"]
[Tue Jul 21 08:44:50.849285 2026] [security2:error] [pid 511108:tid 511315] [client 20.197.195.24:63130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/file6.php"] [unique_id "al9bsoTd5soprXwxAH0HkAAAAE0"]
[Tue Jul 21 08:44:50.974216 2026] [security2:error] [pid 514479:tid 514712] [client 203.25.124.207:25941] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/mini.php"] [unique_id "al9bsvzqsQqnLoCgUjhpiQAAAWw"]
[Tue Jul 21 08:44:50.997345 2026] [autoindex:error] [pid 514479:tid 514653] [client 20.197.195.24:63189] AH01276: Cannot serve directory /home4/drjoao27/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:51.006882 2026] [security2:error] [pid 514479:tid 514695] [client 20.197.195.24:63189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/adminfuns.php"] [unique_id "al9bs_zqsQqnLoCgUjhpiwAAAVs"]
[Tue Jul 21 08:44:51.060734 2026] [security2:error] [pid 514479:tid 514642] [client 203.25.124.35:34187] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/languages/themes/admin.php"] [unique_id "al9bs_zqsQqnLoCgUjhpjQAAASY"]
[Tue Jul 21 08:44:51.102311 2026] [security2:error] [pid 514479:tid 514697] [client 20.197.195.24:63142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/goods.php"] [unique_id "al9bs_zqsQqnLoCgUjhplAAAAV0"]
[Tue Jul 21 08:44:51.147635 2026] [security2:error] [pid 514479:tid 514705] [client 122.176.100.127:56791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bs_zqsQqnLoCgUjhplwAAAWU"]
[Tue Jul 21 08:44:51.147867 2026] [security2:error] [pid 514479:tid 514705] [client 122.176.100.127:56791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bs_zqsQqnLoCgUjhplwAAAWU"]
[Tue Jul 21 08:44:51.252488 2026] [security2:error] [pid 514479:tid 514660] [client 20.197.195.24:63105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/100.php"] [unique_id "al9bs_zqsQqnLoCgUjhpnQAAATg"]
[Tue Jul 21 08:44:51.339765 2026] [security2:error] [pid 514479:tid 514665] [client 20.197.192.193:4081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/pn.php"] [unique_id "al9bs_zqsQqnLoCgUjhpnwAAAT0"]
[Tue Jul 21 08:44:51.346040 2026] [security2:error] [pid 514479:tid 514637] [client 20.197.195.24:50033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/about.php"] [unique_id "al9bs_zqsQqnLoCgUjhpoAAAASE"]
[Tue Jul 21 08:44:51.373544 2026] [security2:error] [pid 514479:tid 514673] [client 20.197.195.24:63213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/about.php"] [unique_id "al9bs_zqsQqnLoCgUjhpoQAAAUU"]
[Tue Jul 21 08:44:51.392910 2026] [security2:error] [pid 511108:tid 511304] [client 20.197.195.24:49985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/admin.php"] [unique_id "al9bs4Td5soprXwxAH0HmAAAAEI"]
[Tue Jul 21 08:44:51.426886 2026] [security2:error] [pid 514479:tid 514635] [client 20.197.195.24:63228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/admin.php"] [unique_id "al9bs_zqsQqnLoCgUjhpogAAAR8"]
[Tue Jul 21 08:44:51.539012 2026] [security2:error] [pid 514479:tid 514645] [client 20.197.195.24:50034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/themes.php"] [unique_id "al9bs_zqsQqnLoCgUjhpowAAASk"]
[Tue Jul 21 08:44:51.615455 2026] [autoindex:error] [pid 511108:tid 511363] [client 20.197.195.24:63127] AH01276: Cannot serve directory /home4/drjoao27/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:51.740282 2026] [security2:error] [pid 514479:tid 514499] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bs_zqsQqnLoCgUjhpqQABFg8"]
[Tue Jul 21 08:44:51.740469 2026] [security2:error] [pid 514479:tid 514626] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bs_zqsQqnLoCgUjhpqQABFg8"]
[Tue Jul 21 08:44:51.759044 2026] [http2:info] [pid 514479:tid 514733] [client 103.215.74.26:49678] AH10178: h2_stream(514479-207-775,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:44:51.927359 2026] [security2:error] [pid 511108:tid 511243] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bs4Td5soprXwxAH0HmQAAAAU"]
[Tue Jul 21 08:44:52.120015 2026] [security2:error] [pid 511108:tid 511249] [client 117.213.202.34:55803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9btITd5soprXwxAH0HpAAAAAs"]
[Tue Jul 21 08:44:52.120145 2026] [security2:error] [pid 511108:tid 511249] [client 117.213.202.34:55803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9btITd5soprXwxAH0HpAAAAAs"]
[Tue Jul 21 08:44:52.135405 2026] [security2:error] [pid 514479:tid 514551] [remote 195.2.79.165:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.79.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9bs_zqsQqnLoCgUjhplgABQkI"], referer: https://alphafix.com.br/
[Tue Jul 21 08:44:52.178537 2026] [security2:error] [pid 514479:tid 514652] [client 203.25.124.11:43187] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/admin/function.php"] [unique_id "al9btPzqsQqnLoCgUjhpswAAATA"]
[Tue Jul 21 08:44:52.260900 2026] [security2:error] [pid 514479:tid 514727] [client 203.25.124.65:57507] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/PHPMailer/"] [unique_id "al9btPzqsQqnLoCgUjhptAAAAXs"]
[Tue Jul 21 08:44:52.428801 2026] [security2:error] [pid 514479:tid 514678] [client 202.179.75.202:50096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9btPzqsQqnLoCgUjhpvAAAAUo"]
[Tue Jul 21 08:44:52.428903 2026] [security2:error] [pid 514479:tid 514678] [client 202.179.75.202:50096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9btPzqsQqnLoCgUjhpvAAAAUo"]
[Tue Jul 21 08:44:52.456862 2026] [security2:error] [pid 511108:tid 511255] [client 41.89.234.2:58809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9btITd5soprXwxAH0HqwAAABE"]
[Tue Jul 21 08:44:52.457052 2026] [security2:error] [pid 511108:tid 511255] [client 41.89.234.2:58809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9btITd5soprXwxAH0HqwAAABE"]
[Tue Jul 21 08:44:52.541406 2026] [security2:error] [pid 514479:tid 514532] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-config.php.swp"] [unique_id "al9btPzqsQqnLoCgUjhpvwABMzA"]
[Tue Jul 21 08:44:52.541944 2026] [security2:error] [pid 514479:tid 514532] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php.bak"] [unique_id "al9btPzqsQqnLoCgUjhpwQABMzA"]
[Tue Jul 21 08:44:52.594551 2026] [security2:error] [pid 514479:tid 514636] [client 45.66.35.37:36652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.35.66.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grupogradiente.com.br"] [uri "/xmlrpc.php"] [unique_id "al9btPzqsQqnLoCgUjhpuwAAASA"]
[Tue Jul 21 08:44:52.594684 2026] [security2:error] [pid 514479:tid 514636] [client 45.66.35.37:36652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grupogradiente.com.br"] [uri "/xmlrpc.php"] [unique_id "al9btPzqsQqnLoCgUjhpuwAAASA"]
[Tue Jul 21 08:44:52.698311 2026] [core:error] [pid 514479:tid 514505] [remote 103.215.74.26:49678] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/home/admin/web/public_html/.env)
[Tue Jul 21 08:44:52.698349 2026] [core:error] [pid 514479:tid 514560] [remote 103.215.74.26:49678] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/.env.local)
[Tue Jul 21 08:44:52.698458 2026] [core:error] [pid 514479:tid 514541] [remote 103.215.74.26:49678] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/home/admin/public_html/.env)
[Tue Jul 21 08:44:52.698458 2026] [core:error] [pid 514479:tid 514606] [remote 103.215.74.26:49678] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/.env.production)
[Tue Jul 21 08:44:52.776202 2026] [core:error] [pid 514479:tid 514524] [remote 103.215.74.26:49678] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/etc/passwd)
[Tue Jul 21 08:44:52.776202 2026] [core:error] [pid 514479:tid 514597] [remote 103.215.74.26:49678] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/var/www/.env)
[Tue Jul 21 08:44:52.776202 2026] [core:error] [pid 514479:tid 514541] [remote 103.215.74.26:49678] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/srv/www/.env)
[Tue Jul 21 08:44:52.776278 2026] [core:error] [pid 514479:tid 514487] [remote 103.215.74.26:49678] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/var/www/html/.env)
[Tue Jul 21 08:44:52.776285 2026] [core:error] [pid 514479:tid 514606] [remote 103.215.74.26:49678] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/opt/app/.env)
[Tue Jul 21 08:44:52.776294 2026] [core:error] [pid 514479:tid 514505] [remote 103.215.74.26:49678] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/etc/passwd)
[Tue Jul 21 08:44:52.776346 2026] [security2:error] [pid 514479:tid 514595] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/var/www/html/wp-config.php"] [unique_id "al9btPzqsQqnLoCgUjhp0QABOG4"]
[Tue Jul 21 08:44:52.776684 2026] [core:error] [pid 514479:tid 514595] [remote 103.215.74.26:49678] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/.env)
[Tue Jul 21 08:44:52.778089 2026] [core:error] [pid 514479:tid 514560] [remote 103.215.74.26:49678] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/.env)
[Tue Jul 21 08:44:52.853569 2026] [security2:error] [pid 514479:tid 514739] [client 173.252.95.60:59052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9btPzqsQqnLoCgUjhp2QAAAYc"]
[Tue Jul 21 08:44:52.859043 2026] [security2:error] [pid 514479:tid 514524] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php.old"] [unique_id "al9btPzqsQqnLoCgUjhp2gABOCg"]
[Tue Jul 21 08:44:52.859523 2026] [security2:error] [pid 514479:tid 514524] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/xmlrpc.php"] [unique_id "al9btPzqsQqnLoCgUjhp2wABOCg"]
[Tue Jul 21 08:44:52.860343 2026] [core:error] [pid 514479:tid 514524] [remote 103.215.74.26:49678] AH10244: invalid URI path (/icons/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/var/www/html/.env)
[Tue Jul 21 08:44:52.863843 2026] [core:error] [pid 514479:tid 514487] [remote 103.215.74.26:49678] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/etc/passwd)
[Tue Jul 21 08:44:52.865780 2026] [security2:error] [pid 514479:tid 514606] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/database.yml.bak"] [unique_id "al9btPzqsQqnLoCgUjhp3gABOHk"]
[Tue Jul 21 08:44:52.871045 2026] [core:error] [pid 514479:tid 514595] [remote 103.215.74.26:49678] AH10244: invalid URI path (/icons/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/etc/passwd)
[Tue Jul 21 08:44:52.878245 2026] [security2:error] [pid 514479:tid 514543] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php.bak"] [unique_id "al9btPzqsQqnLoCgUjhp5QABODs"]
[Tue Jul 21 08:44:52.878771 2026] [security2:error] [pid 514479:tid 514543] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php~"] [unique_id "al9btPzqsQqnLoCgUjhp5wABODs"]
[Tue Jul 21 08:44:52.879067 2026] [security2:error] [pid 514479:tid 514490] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php.old"] [unique_id "al9btPzqsQqnLoCgUjhp6AABOAY"]
[Tue Jul 21 08:44:52.879652 2026] [security2:error] [pid 514479:tid 514490] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php.orig"] [unique_id "al9btPzqsQqnLoCgUjhp6gABOAY"]
[Tue Jul 21 08:44:52.879789 2026] [security2:error] [pid 514479:tid 514610] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php.swp"] [unique_id "al9btPzqsQqnLoCgUjhp7AABOH0"]
[Tue Jul 21 08:44:52.880042 2026] [security2:error] [pid 514479:tid 514490] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php.tmp"] [unique_id "al9btPzqsQqnLoCgUjhp7QABOAY"]
[Tue Jul 21 08:44:52.880301 2026] [security2:error] [pid 514479:tid 514489] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php.save"] [unique_id "al9btPzqsQqnLoCgUjhp6wABOAU"]
[Tue Jul 21 08:44:52.880487 2026] [security2:error] [pid 514479:tid 514508] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/appsettings.json.bak"] [unique_id "al9btPzqsQqnLoCgUjhp5AABOBg"]
[Tue Jul 21 08:44:52.892875 2026] [security2:error] [pid 514479:tid 514492] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php.backup"] [unique_id "al9btPzqsQqnLoCgUjhp8AABOAg"]
[Tue Jul 21 08:44:52.896888 2026] [security2:error] [pid 514479:tid 514599] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9btPzqsQqnLoCgUjhp8gABOHI"]
[Tue Jul 21 08:44:52.897335 2026] [security2:error] [pid 514479:tid 514599] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/xmlrpc.php"] [unique_id "al9btPzqsQqnLoCgUjhp8wABOHI"]
[Tue Jul 21 08:44:52.898454 2026] [security2:error] [pid 514479:tid 514529] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php.bkp"] [unique_id "al9btPzqsQqnLoCgUjhp9gABOC0"]
[Tue Jul 21 08:44:52.898609 2026] [security2:error] [pid 514479:tid 514513] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php-backup"] [unique_id "al9btPzqsQqnLoCgUjhp9QABOB0"]
[Tue Jul 21 08:44:52.899073 2026] [security2:error] [pid 514479:tid 514529] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php.copy"] [unique_id "al9btPzqsQqnLoCgUjhp9wABOC0"]
[Tue Jul 21 08:44:52.900218 2026] [security2:error] [pid 514479:tid 514599] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/settings.py.bak"] [unique_id "al9btPzqsQqnLoCgUjhp9AABOHI"]
[Tue Jul 21 08:44:53.010484 2026] [security2:error] [pid 514479:tid 514556] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9btfzqsQqnLoCgUjhp-QABOEc"]
[Tue Jul 21 08:44:53.128640 2026] [security2:error] [pid 511108:tid 511346] [client 20.197.195.24:63127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/.well-known/about.php"] [unique_id "al9btYTd5soprXwxAH0HugAAAGw"]
[Tue Jul 21 08:44:53.143443 2026] [security2:error] [pid 514479:tid 514519] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.php.1"] [unique_id "al9btfzqsQqnLoCgUjhp_wABOCM"]
[Tue Jul 21 08:44:53.277565 2026] [security2:error] [pid 511108:tid 511267] [client 152.59.181.104:56468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9btYTd5soprXwxAH0HvgAAAB0"]
[Tue Jul 21 08:44:53.278490 2026] [security2:error] [pid 511108:tid 511267] [client 152.59.181.104:56468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9btYTd5soprXwxAH0HvgAAAB0"]
[Tue Jul 21 08:44:53.462837 2026] [http2:info] [pid 514479:tid 514660] [client 103.215.74.26:49678] AH10178: h2_stream(514479-207-1007,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:44:53.463362 2026] [security2:error] [pid 514479:tid 514616] [client 203.25.124.212:64971] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/wp-file-manager/file_folder_manager.php"] [unique_id "al9btfzqsQqnLoCgUjhqEQAAAQw"]
[Tue Jul 21 08:44:53.464893 2026] [security2:error] [pid 514479:tid 514604] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/.htaccess.bak"] [unique_id "al9btfzqsQqnLoCgUjhqDgABOHc"]
[Tue Jul 21 08:44:53.466126 2026] [security2:error] [pid 514479:tid 514612] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/configuration.php.bak"] [unique_id "al9btfzqsQqnLoCgUjhqHAABOH8"]
[Tue Jul 21 08:44:53.466223 2026] [security2:error] [pid 514479:tid 514573] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/configuration.php~"] [unique_id "al9btfzqsQqnLoCgUjhqHgABOFg"]
[Tue Jul 21 08:44:53.466280 2026] [security2:error] [pid 514479:tid 514602] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-content/uploads/wp-config.php"] [unique_id "al9btfzqsQqnLoCgUjhqHQABOHU"]
[Tue Jul 21 08:44:53.467473 2026] [security2:error] [pid 514479:tid 514493] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-admin/upgrade.php"] [unique_id "al9btfzqsQqnLoCgUjhqLAABOAk"]
[Tue Jul 21 08:44:53.467898 2026] [security2:error] [pid 514479:tid 514559] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/wordfence-waf.php"] [unique_id "al9btfzqsQqnLoCgUjhqMAABOEo"]
[Tue Jul 21 08:44:53.467965 2026] [security2:error] [pid 514479:tid 514607] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-admin/setup-config.php"] [unique_id "al9btfzqsQqnLoCgUjhqLgABOHo"]
[Tue Jul 21 08:44:53.468131 2026] [security2:error] [pid 514479:tid 514527] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-content/uploads/backup.sql"] [unique_id "al9btfzqsQqnLoCgUjhqIgABOCs"]
[Tue Jul 21 08:44:53.468217 2026] [security2:error] [pid 514479:tid 514499] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-admin/install.php"] [unique_id "al9btfzqsQqnLoCgUjhqMQABOA8"]
[Tue Jul 21 08:44:53.468417 2026] [security2:error] [pid 514479:tid 514607] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/installer.php"] [unique_id "al9btfzqsQqnLoCgUjhqMwABOHo"]
[Tue Jul 21 08:44:53.468543 2026] [security2:error] [pid 514479:tid 514550] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/configuration.php.orig"] [unique_id "al9btfzqsQqnLoCgUjhqNAABOEE"]
[Tue Jul 21 08:44:53.468629 2026] [security2:error] [pid 514479:tid 514499] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/installer-backup.php"] [unique_id "al9btfzqsQqnLoCgUjhqNgABOA8"]
[Tue Jul 21 08:44:53.468669 2026] [security2:error] [pid 514479:tid 514602] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-content/uploads/database.sql"] [unique_id "al9btfzqsQqnLoCgUjhqJgABOHU"]
[Tue Jul 21 08:44:53.468933 2026] [security2:error] [pid 514479:tid 514550] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/configuration.php.save"] [unique_id "al9btfzqsQqnLoCgUjhqNwABOEE"]
[Tue Jul 21 08:44:53.469384 2026] [security2:error] [pid 514479:tid 514493] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/configuration.php.old"] [unique_id "al9btfzqsQqnLoCgUjhqLwABOAk"]
[Tue Jul 21 08:44:53.469918 2026] [security2:error] [pid 514479:tid 514507] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-content/uploads/db.sql"] [unique_id "al9btfzqsQqnLoCgUjhqJwABOBc"]
[Tue Jul 21 08:44:53.470395 2026] [security2:error] [pid 514479:tid 514598] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-content/uploads/dump.sql"] [unique_id "al9btfzqsQqnLoCgUjhqKAABOHE"]
[Tue Jul 21 08:44:53.470399 2026] [security2:error] [pid 514479:tid 514507] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/configuration.php.swp"] [unique_id "al9btfzqsQqnLoCgUjhqQwABOBc"]
[Tue Jul 21 08:44:53.471149 2026] [security2:error] [pid 514479:tid 514554] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/configuration.php.backup"] [unique_id "al9btfzqsQqnLoCgUjhqSwABOEU"]
[Tue Jul 21 08:44:53.471182 2026] [security2:error] [pid 514479:tid 514591] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/configuration.php.tmp"] [unique_id "al9btfzqsQqnLoCgUjhqSgABOGo"]
[Tue Jul 21 08:44:53.474032 2026] [security2:error] [pid 514479:tid 514561] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/installer-data.sql"] [unique_id "al9btfzqsQqnLoCgUjhqSQABOEw"]
[Tue Jul 21 08:44:53.474040 2026] [security2:error] [pid 514479:tid 514559] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-content/mysql.sql"] [unique_id "al9btfzqsQqnLoCgUjhqMgABOEo"]
[Tue Jul 21 08:44:53.878477 2026] [security2:error] [pid 514479:tid 514652] [client 20.197.195.24:63132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9btfzqsQqnLoCgUjhqVAAAATA"]
[Tue Jul 21 08:44:53.964321 2026] [security2:error] [pid 514479:tid 514656] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9btfzqsQqnLoCgUjhqUgABNAU"]
[Tue Jul 21 08:44:54.208698 2026] [security2:error] [pid 514479:tid 514670] [client 45.66.35.37:36662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.35.66.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grupogradiente.com.br"] [uri "/xmlrpc.php"] [unique_id "al9btvzqsQqnLoCgUjhqYAAAAUI"]
[Tue Jul 21 08:44:54.208810 2026] [security2:error] [pid 514479:tid 514670] [client 45.66.35.37:36662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grupogradiente.com.br"] [uri "/xmlrpc.php"] [unique_id "al9btvzqsQqnLoCgUjhqYAAAAUI"]
[Tue Jul 21 08:44:54.344640 2026] [security2:error] [pid 514479:tid 514705] [client 20.197.195.24:63188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wefile.php"] [unique_id "al9btvzqsQqnLoCgUjhqaAAAAWU"]
[Tue Jul 21 08:44:54.566170 2026] [security2:error] [pid 511108:tid 511274] [client 203.25.124.61:25813] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "al9btoTd5soprXwxAH0HzwAAACQ"]
[Tue Jul 21 08:44:54.600413 2026] [security2:error] [pid 511108:tid 511283] [client 20.197.195.24:50002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9btoTd5soprXwxAH0H0QAAAC0"]
[Tue Jul 21 08:44:54.661989 2026] [security2:error] [pid 514479:tid 514696] [client 168.167.81.163:63033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9btvzqsQqnLoCgUjhqcgAAAVw"]
[Tue Jul 21 08:44:54.662154 2026] [security2:error] [pid 514479:tid 514696] [client 168.167.81.163:63033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9btvzqsQqnLoCgUjhqcgAAAVw"]
[Tue Jul 21 08:44:54.714474 2026] [http2:info] [pid 514479:tid 514660] [client 103.215.74.26:49678] AH10178: h2_stream(514479-207-1093,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:44:54.824134 2026] [security2:error] [pid 511108:tid 511364] [client 5.31.193.106:1804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9btoTd5soprXwxAH0H1gAAAH4"]
[Tue Jul 21 08:44:54.824233 2026] [security2:error] [pid 511108:tid 511364] [client 5.31.193.106:1804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9btoTd5soprXwxAH0H1gAAAH4"]
[Tue Jul 21 08:44:54.845142 2026] [security2:error] [pid 514479:tid 514721] [client 61.1.167.83:61077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9btvzqsQqnLoCgUjhqdQAAAXU"]
[Tue Jul 21 08:44:54.845243 2026] [security2:error] [pid 514479:tid 514721] [client 61.1.167.83:61077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9btvzqsQqnLoCgUjhqdQAAAXU"]
[Tue Jul 21 08:44:55.002339 2026] [security2:error] [pid 514479:tid 514558] [remote 195.2.67.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.67.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onkosclinica.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9btvzqsQqnLoCgUjhqdAABgEk"], referer: https://onkosclinica.com/
[Tue Jul 21 08:44:55.171888 2026] [security2:error] [pid 514479:tid 514709] [client 203.25.124.192:22881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/config.php"] [unique_id "al9bt_zqsQqnLoCgUjhqdwAAAWk"]
[Tue Jul 21 08:44:55.414146 2026] [security2:error] [pid 514479:tid 514493] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/adminer.php"] [unique_id "al9btvzqsQqnLoCgUjhqhAABOAk"]
[Tue Jul 21 08:44:55.415532 2026] [authz_core:error] [pid 514479:tid 514493] [remote 103.215.74.26:49678] AH01630: client denied by server configuration: /home2/acupu265/auriculo.liranesuliano.com/error_log
[Tue Jul 21 08:44:55.425084 2026] [autoindex:error] [pid 511108:tid 511332] [client 20.197.195.24:50035] AH01276: Cannot serve directory /home4/drjoao27/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:55.498500 2026] [security2:error] [pid 514479:tid 514569] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/settings.php-backup"] [unique_id "al9btvzqsQqnLoCgUjhqjAABOFQ"]
[Tue Jul 21 08:44:55.499460 2026] [security2:error] [pid 514479:tid 514569] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/settings.php.copy"] [unique_id "al9btvzqsQqnLoCgUjhqjQABOFQ"]
[Tue Jul 21 08:44:55.500258 2026] [security2:error] [pid 514479:tid 514569] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/settings.php.bkp"] [unique_id "al9btvzqsQqnLoCgUjhqjgABOFQ"]
[Tue Jul 21 08:44:55.500857 2026] [security2:error] [pid 514479:tid 514592] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/dup-installer/main.installer.php"] [unique_id "al9btvzqsQqnLoCgUjhqkAABOGs"]
[Tue Jul 21 08:44:55.501260 2026] [security2:error] [pid 514479:tid 514523] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/settings.php.1"] [unique_id "al9btvzqsQqnLoCgUjhqkQABOCc"]
[Tue Jul 21 08:44:55.501265 2026] [security2:error] [pid 514479:tid 514592] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/database.php.bak"] [unique_id "al9btvzqsQqnLoCgUjhqkgABOGs"]
[Tue Jul 21 08:44:55.501994 2026] [security2:error] [pid 514479:tid 514523] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/database.php.old"] [unique_id "al9btvzqsQqnLoCgUjhqlAABOCc"]
[Tue Jul 21 08:44:55.502575 2026] [security2:error] [pid 514479:tid 514523] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-content/w3tc-config/master.php"] [unique_id "al9btvzqsQqnLoCgUjhqlQABOCc"]
[Tue Jul 21 08:44:55.503028 2026] [security2:error] [pid 514479:tid 514531] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/database.php.orig"] [unique_id "al9btvzqsQqnLoCgUjhqlgABOC8"]
[Tue Jul 21 08:44:55.503042 2026] [security2:error] [pid 514479:tid 514523] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/database.php~"] [unique_id "al9btvzqsQqnLoCgUjhqlwABOCc"]
[Tue Jul 21 08:44:55.503608 2026] [security2:error] [pid 514479:tid 514554] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9btvzqsQqnLoCgUjhqnAABOEU"]
[Tue Jul 21 08:44:55.503627 2026] [security2:error] [pid 514479:tid 514555] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-content/plugins/w3-total-cache/pub/opt/detect-post-info.php"] [unique_id "al9btvzqsQqnLoCgUjhqmwABOEY"]
[Tue Jul 21 08:44:55.592727 2026] [security2:error] [pid 514479:tid 514584] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/wp-links-opml.php"] [unique_id "al9bt_zqsQqnLoCgUjhqqQABOGM"]
[Tue Jul 21 08:44:55.613744 2026] [security2:error] [pid 514479:tid 514596] [remote 65.111.7.225:47451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.7.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9btvzqsQqnLoCgUjhqawABSW8"]
[Tue Jul 21 08:44:55.632078 2026] [autoindex:error] [pid 511108:tid 511356] [client 20.197.195.24:50035] AH01276: Cannot serve directory /home4/drjoao27/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:55.659318 2026] [security2:error] [pid 511108:tid 511333] [client 20.197.195.24:50035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9bt4Td5soprXwxAH0H5AAAAF8"]
[Tue Jul 21 08:44:55.740527 2026] [security2:error] [pid 511108:tid 511338] [client 20.197.195.24:63215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/8.php"] [unique_id "al9bt4Td5soprXwxAH0H5QAAAGQ"]
[Tue Jul 21 08:44:55.788972 2026] [security2:error] [pid 514479:tid 514653] [client 20.197.195.24:63177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-content/admin.php"] [unique_id "al9bt_zqsQqnLoCgUjhqrAAAATE"]
[Tue Jul 21 08:44:55.792179 2026] [security2:error] [pid 514479:tid 514651] [client 45.66.35.37:36668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.35.66.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grupogradiente.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bt_zqsQqnLoCgUjhqrQAAAS8"]
[Tue Jul 21 08:44:55.792303 2026] [security2:error] [pid 514479:tid 514651] [client 45.66.35.37:36668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grupogradiente.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bt_zqsQqnLoCgUjhqrQAAAS8"]
[Tue Jul 21 08:44:55.896970 2026] [security2:error] [pid 514479:tid 514741] [client 20.197.195.24:63136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/f6.php"] [unique_id "al9bt_zqsQqnLoCgUjhqsQAAAYk"]
[Tue Jul 21 08:44:56.040225 2026] [security2:error] [pid 514479:tid 514701] [client 20.197.195.24:63183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/inputs.php"] [unique_id "al9buPzqsQqnLoCgUjhqswAAAWE"]
[Tue Jul 21 08:44:56.081066 2026] [security2:error] [pid 511108:tid 511310] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bt4Td5soprXwxAH0H4wAAAEg"]
[Tue Jul 21 08:44:56.090661 2026] [security2:error] [pid 511108:tid 511247] [client 20.197.195.24:63203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/inputs.php"] [unique_id "al9buITd5soprXwxAH0H7gAAAAk"]
[Tue Jul 21 08:44:56.135300 2026] [security2:error] [pid 514479:tid 514711] [client 20.197.195.24:63180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/classwithtostring.php"] [unique_id "al9buPzqsQqnLoCgUjhqugAAAWs"]
[Tue Jul 21 08:44:56.217614 2026] [security2:error] [pid 514479:tid 514625] [client 5.38.115.39:52482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9buPzqsQqnLoCgUjhqvAAAARU"]
[Tue Jul 21 08:44:56.217744 2026] [security2:error] [pid 514479:tid 514625] [client 5.38.115.39:52482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9buPzqsQqnLoCgUjhqvAAAARU"]
[Tue Jul 21 08:44:56.225707 2026] [security2:error] [pid 514479:tid 514621] [client 20.197.195.24:63164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9buPzqsQqnLoCgUjhqvQAAARE"]
[Tue Jul 21 08:44:56.259076 2026] [security2:error] [pid 514479:tid 514637] [client 203.25.124.73:49167] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/about.php"] [unique_id "al9buPzqsQqnLoCgUjhqvwAAASE"]
[Tue Jul 21 08:44:56.345278 2026] [security2:error] [pid 511108:tid 511330] [client 20.197.195.24:63128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-blog.php"] [unique_id "al9buITd5soprXwxAH0H9wAAAFw"]
[Tue Jul 21 08:44:56.369963 2026] [security2:error] [pid 514479:tid 514672] [client 195.206.105.227:56740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9buPzqsQqnLoCgUjhqwgAAAUQ"]
[Tue Jul 21 08:44:56.370140 2026] [security2:error] [pid 514479:tid 514672] [client 195.206.105.227:56740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9buPzqsQqnLoCgUjhqwgAAAUQ"]
[Tue Jul 21 08:44:56.391648 2026] [security2:error] [pid 511108:tid 511129] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9buITd5soprXwxAH0H_QAAKBQ"]
[Tue Jul 21 08:44:56.391916 2026] [security2:error] [pid 511108:tid 511278] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9buITd5soprXwxAH0H_QAAKBQ"]
[Tue Jul 21 08:44:56.416284 2026] [security2:error] [pid 514479:tid 514555] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/database.php.save"] [unique_id "al9bt_zqsQqnLoCgUjhqwwABOEY"]
[Tue Jul 21 08:44:56.416917 2026] [security2:error] [pid 514479:tid 514555] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/database.php.swp"] [unique_id "al9bt_zqsQqnLoCgUjhqxAABOEY"]
[Tue Jul 21 08:44:56.416960 2026] [security2:error] [pid 514479:tid 514511] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/database.php.tmp"] [unique_id "al9bt_zqsQqnLoCgUjhqxQABOBs"]
[Tue Jul 21 08:44:56.417169 2026] [security2:error] [pid 514479:tid 514555] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/database.php-backup"] [unique_id "al9bt_zqsQqnLoCgUjhqxwABOEY"]
[Tue Jul 21 08:44:56.417403 2026] [security2:error] [pid 514479:tid 514511] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/database.php.copy"] [unique_id "al9bt_zqsQqnLoCgUjhqyAABOBs"]
[Tue Jul 21 08:44:56.417465 2026] [security2:error] [pid 514479:tid 514555] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/database.php.bkp"] [unique_id "al9bt_zqsQqnLoCgUjhqyQABOEY"]
[Tue Jul 21 08:44:56.417467 2026] [security2:error] [pid 514479:tid 514510] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/database.php.backup"] [unique_id "al9bt_zqsQqnLoCgUjhqxgABOBo"]
[Tue Jul 21 08:44:56.417805 2026] [security2:error] [pid 514479:tid 514511] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/database.php.1"] [unique_id "al9buPzqsQqnLoCgUjhqygABOBs"]
[Tue Jul 21 08:44:56.417930 2026] [security2:error] [pid 514479:tid 514489] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9buPzqsQqnLoCgUjhqzgABOAU"]
[Tue Jul 21 08:44:56.418076 2026] [security2:error] [pid 514479:tid 514555] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.inc.php~"] [unique_id "al9buPzqsQqnLoCgUjhqywABOEY"]
[Tue Jul 21 08:44:56.418144 2026] [security2:error] [pid 514479:tid 514510] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.inc.php.bak"] [unique_id "al9buPzqsQqnLoCgUjhqzAABOBo"]
[Tue Jul 21 08:44:56.418155 2026] [security2:error] [pid 514479:tid 514513] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.inc.php.orig"] [unique_id "al9buPzqsQqnLoCgUjhqzwABOB0"]
[Tue Jul 21 08:44:56.418189 2026] [security2:error] [pid 514479:tid 514508] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.inc.php.old"] [unique_id "al9buPzqsQqnLoCgUjhqzQABOBg"]
[Tue Jul 21 08:44:56.473843 2026] [security2:error] [pid 511108:tid 511360] [client 212.32.76.66:56627] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/m.php"] [unique_id "al9buITd5soprXwxAH0H_wAAAHo"]
[Tue Jul 21 08:44:56.506790 2026] [security2:error] [pid 514479:tid 514599] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.inc.php.swp"] [unique_id "al9buPzqsQqnLoCgUjhq0QABH3I"]
[Tue Jul 21 08:44:56.506804 2026] [security2:error] [pid 514479:tid 514580] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.inc.php.save"] [unique_id "al9buPzqsQqnLoCgUjhq0AABH18"]
[Tue Jul 21 08:44:56.507259 2026] [security2:error] [pid 514479:tid 514529] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.inc.php.tmp"] [unique_id "al9buPzqsQqnLoCgUjhq0gABHy0"]
[Tue Jul 21 08:44:56.508153 2026] [security2:error] [pid 514479:tid 514601] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.inc.php.bkp"] [unique_id "al9buPzqsQqnLoCgUjhq1gABH3Q"]
[Tue Jul 21 08:44:56.508192 2026] [security2:error] [pid 514479:tid 514560] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.inc.php.1"] [unique_id "al9buPzqsQqnLoCgUjhq1wABH0s"]
[Tue Jul 21 08:44:56.508249 2026] [security2:error] [pid 514479:tid 514562] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.inc.php.copy"] [unique_id "al9buPzqsQqnLoCgUjhq1QABH00"]
[Tue Jul 21 08:44:56.508600 2026] [security2:error] [pid 514479:tid 514534] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.inc.php-backup"] [unique_id "al9buPzqsQqnLoCgUjhq1AABHzI"]
[Tue Jul 21 08:44:56.508605 2026] [security2:error] [pid 514479:tid 514495] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config.inc.php.backup"] [unique_id "al9buPzqsQqnLoCgUjhq0wABHws"]
[Tue Jul 21 08:44:56.608912 2026] [security2:error] [pid 514479:tid 514714] [client 113.22.144.139:55103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9buPzqsQqnLoCgUjhq2wAAAW4"]
[Tue Jul 21 08:44:56.609092 2026] [security2:error] [pid 514479:tid 514714] [client 113.22.144.139:55103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9buPzqsQqnLoCgUjhq2wAAAW4"]
[Tue Jul 21 08:44:56.648127 2026] [http2:info] [pid 514479:tid 514624] [client 103.215.74.26:49678] AH10178: h2_stream(514479-207-1175,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:44:56.649552 2026] [security2:error] [pid 514479:tid 514607] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9buPzqsQqnLoCgUjhq3QABFHo"]
[Tue Jul 21 08:44:56.965857 2026] [security2:error] [pid 511108:tid 511241] [client 212.32.76.13:24809] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/sitemaps/admin.php"] [unique_id "al9buITd5soprXwxAH0IEgAAAAM"]
[Tue Jul 21 08:44:56.994579 2026] [autoindex:error] [pid 511108:tid 511361] [client 20.197.195.24:63179] AH01276: Cannot serve directory /home4/drjoao27/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:57.027950 2026] [security2:error] [pid 511108:tid 511293] [client 20.197.195.24:63179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-content/admin.php"] [unique_id "al9buYTd5soprXwxAH0IFwAAADc"]
[Tue Jul 21 08:44:57.302658 2026] [security2:error] [pid 514479:tid 514556] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/local.php~"] [unique_id "al9bufzqsQqnLoCgUjhq6gABa0c"]
[Tue Jul 21 08:44:57.302678 2026] [security2:error] [pid 514479:tid 514498] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/local.php.bak"] [unique_id "al9bufzqsQqnLoCgUjhq6QABaw4"]
[Tue Jul 21 08:44:57.303131 2026] [security2:error] [pid 514479:tid 514525] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/local.php.old"] [unique_id "al9bufzqsQqnLoCgUjhq6wABayk"]
[Tue Jul 21 08:44:57.303168 2026] [security2:error] [pid 514479:tid 514498] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/local.php.orig"] [unique_id "al9bufzqsQqnLoCgUjhq7AABaw4"]
[Tue Jul 21 08:44:57.303227 2026] [security2:error] [pid 514479:tid 514547] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/local.php.save"] [unique_id "al9bufzqsQqnLoCgUjhq7QABaz8"]
[Tue Jul 21 08:44:57.304227 2026] [security2:error] [pid 514479:tid 514564] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/local.php.backup"] [unique_id "al9bufzqsQqnLoCgUjhq7gABa08"]
[Tue Jul 21 08:44:57.304730 2026] [security2:error] [pid 514479:tid 514564] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/local.php.bkp"] [unique_id "al9bufzqsQqnLoCgUjhq8gABa08"]
[Tue Jul 21 08:44:57.304898 2026] [security2:error] [pid 514479:tid 514590] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/local.php.tmp"] [unique_id "al9bufzqsQqnLoCgUjhq8QABa2k"]
[Tue Jul 21 08:44:57.304964 2026] [security2:error] [pid 514479:tid 514503] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/local.php.copy"] [unique_id "al9bufzqsQqnLoCgUjhq8wABaxM"]
[Tue Jul 21 08:44:57.305015 2026] [security2:error] [pid 514479:tid 514608] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/local.php.swp"] [unique_id "al9bufzqsQqnLoCgUjhq8AABa3s"]
[Tue Jul 21 08:44:57.305068 2026] [security2:error] [pid 514479:tid 514484] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/local.php-backup"] [unique_id "al9bufzqsQqnLoCgUjhq7wABawA"]
[Tue Jul 21 08:44:57.305127 2026] [security2:error] [pid 514479:tid 514564] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/local.php.1"] [unique_id "al9bufzqsQqnLoCgUjhq9AABa08"]
[Tue Jul 21 08:44:57.305319 2026] [security2:error] [pid 514479:tid 514527] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9bufzqsQqnLoCgUjhq9QABays"]
[Tue Jul 21 08:44:57.369658 2026] [security2:error] [pid 514479:tid 514542] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/settings.py~"] [unique_id "al9bufzqsQqnLoCgUjhq9wABUzo"]
[Tue Jul 21 08:44:57.372316 2026] [security2:error] [pid 511108:tid 511291] [client 203.25.124.182:28737] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/languages/"] [unique_id "al9buYTd5soprXwxAH0IIgAAADU"]
[Tue Jul 21 08:44:57.378320 2026] [security2:error] [pid 514479:tid 514519] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/settings.py.old"] [unique_id "al9bufzqsQqnLoCgUjhq-QABUyM"]
[Tue Jul 21 08:44:57.378737 2026] [security2:error] [pid 514479:tid 514530] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/settings.py.swp"] [unique_id "al9bufzqsQqnLoCgUjhq_AABUy4"]
[Tue Jul 21 08:44:57.380202 2026] [security2:error] [pid 514479:tid 514542] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/settings.py.bak"] [unique_id "al9bufzqsQqnLoCgUjhq-AABUzo"]
[Tue Jul 21 08:44:57.380576 2026] [security2:error] [pid 514479:tid 514586] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/settings.py.backup"] [unique_id "al9bufzqsQqnLoCgUjhq_QABU2U"]
[Tue Jul 21 08:44:57.381025 2026] [security2:error] [pid 514479:tid 514563] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/settings.py.orig"] [unique_id "al9bufzqsQqnLoCgUjhq_gABU04"]
[Tue Jul 21 08:44:57.420593 2026] [security2:error] [pid 514479:tid 514567] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bufzqsQqnLoCgUjhrAAABOlI"]
[Tue Jul 21 08:44:57.420858 2026] [security2:error] [pid 514479:tid 514662] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bufzqsQqnLoCgUjhrAAABOlI"]
[Tue Jul 21 08:44:57.821112 2026] [security2:error] [pid 514479:tid 514570] [remote 45.3.45.84:63985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9bufzqsQqnLoCgUjhrBwABPVU"]
[Tue Jul 21 08:44:57.846439 2026] [security2:error] [pid 511108:tid 511254] [client 114.198.138.124:49715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9buYTd5soprXwxAH0ILgAAABA"]
[Tue Jul 21 08:44:57.846562 2026] [security2:error] [pid 511108:tid 511254] [client 114.198.138.124:49715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9buYTd5soprXwxAH0ILgAAABA"]
[Tue Jul 21 08:44:57.886680 2026] [security2:error] [pid 511108:tid 511296] [client 20.197.195.24:50019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ms-edit.php"] [unique_id "al9buYTd5soprXwxAH0IMQAAADo"]
[Tue Jul 21 08:44:57.950370 2026] [security2:error] [pid 511108:tid 511122] [remote 37.59.204.140:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "energyzapp.com"] [uri "/robots.txt"] [unique_id "al9buYTd5soprXwxAH0INQAAXw0"]
[Tue Jul 21 08:44:57.950597 2026] [security2:error] [pid 511108:tid 511333] [client 37.59.204.140:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "energyzapp.com"] [uri "/robots.txt"] [unique_id "al9buYTd5soprXwxAH0INQAAXw0"]
[Tue Jul 21 08:44:58.077846 2026] [security2:error] [pid 514479:tid 514550] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9buvzqsQqnLoCgUjhrDwABbkE"]
[Tue Jul 21 08:44:58.131240 2026] [security2:error] [pid 514479:tid 514602] [remote 184.168.124.4:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.124.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9buvzqsQqnLoCgUjhrEgABYHU"], referer: http://assumaocontrole.com/
[Tue Jul 21 08:44:58.167378 2026] [security2:error] [pid 511108:tid 511342] [client 203.25.124.48:42591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/js/widgets/maint/"] [unique_id "al9buoTd5soprXwxAH0IOQAAAGg"]
[Tue Jul 21 08:44:58.256633 2026] [security2:error] [pid 514479:tid 514626] [client 103.59.206.240:31044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9buvzqsQqnLoCgUjhrFgAAARY"]
[Tue Jul 21 08:44:58.256777 2026] [security2:error] [pid 514479:tid 514626] [client 103.59.206.240:31044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9buvzqsQqnLoCgUjhrFgAAARY"]
[Tue Jul 21 08:44:58.261193 2026] [security2:error] [pid 514479:tid 514723] [client 195.49.128.211:50458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9buvzqsQqnLoCgUjhrFwAAAXc"]
[Tue Jul 21 08:44:58.261413 2026] [security2:error] [pid 514479:tid 514723] [client 195.49.128.211:50458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9buvzqsQqnLoCgUjhrFwAAAXc"]
[Tue Jul 21 08:44:58.474380 2026] [security2:error] [pid 511108:tid 511278] [client 203.25.124.206:54679] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/about.php"] [unique_id "al9buoTd5soprXwxAH0IQgAAACg"]
[Tue Jul 21 08:44:58.589064 2026] [security2:error] [pid 514479:tid 514552] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9buvzqsQqnLoCgUjhrHwABiUM"]
[Tue Jul 21 08:44:58.830674 2026] [security2:error] [pid 514479:tid 514682] [client 20.197.195.24:63144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/cgi-bin/index.php"] [unique_id "al9buvzqsQqnLoCgUjhrIgAAAU4"]
[Tue Jul 21 08:44:58.899142 2026] [security2:error] [pid 514479:tid 514494] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9buvzqsQqnLoCgUjhrIwABIAo"]
[Tue Jul 21 08:44:58.948029 2026] [security2:error] [pid 514479:tid 514686] [client 20.197.192.193:27198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/edit.php"] [unique_id "al9buvzqsQqnLoCgUjhrJQAAAVI"]
[Tue Jul 21 08:44:59.003305 2026] [security2:error] [pid 514479:tid 514538] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9bu_zqsQqnLoCgUjhrKAABZTY"]
[Tue Jul 21 08:44:59.127873 2026] [security2:error] [pid 511108:tid 511347] [client 49.144.66.253:31915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bu4Td5soprXwxAH0IUgAAAG0"]
[Tue Jul 21 08:44:59.127999 2026] [security2:error] [pid 511108:tid 511347] [client 49.144.66.253:31915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bu4Td5soprXwxAH0IUgAAAG0"]
[Tue Jul 21 08:44:59.170697 2026] [security2:error] [pid 514479:tid 514659] [client 212.32.76.6:35203] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/languages/classwithtostring.php"] [unique_id "al9bu_zqsQqnLoCgUjhrKgAAATc"]
[Tue Jul 21 08:44:59.253777 2026] [autoindex:error] [pid 514479:tid 514654] [client 20.197.195.24:50010] AH01276: Cannot serve directory /home4/drjoao27/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:44:59.287896 2026] [security2:error] [pid 514479:tid 514517] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9bu_zqsQqnLoCgUjhrLgABVSE"]
[Tue Jul 21 08:44:59.289143 2026] [security2:error] [pid 514479:tid 514620] [client 20.197.195.24:50010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/BDKR28WP.php"] [unique_id "al9bu_zqsQqnLoCgUjhrLwAAARA"]
[Tue Jul 21 08:44:59.573637 2026] [security2:error] [pid 514479:tid 514616] [client 203.25.124.5:44483] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/packed.php"] [unique_id "al9bu_zqsQqnLoCgUjhrPAAAAQw"]
[Tue Jul 21 08:44:59.641212 2026] [security2:error] [pid 514479:tid 514520] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9bu_zqsQqnLoCgUjhrPQABKyQ"]
[Tue Jul 21 08:44:59.739265 2026] [security2:error] [pid 511108:tid 511186] [remote 15.235.98.58:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "energyzapp.com"] [uri "/"] [unique_id "al9bu4Td5soprXwxAH0IXwAATU0"]
[Tue Jul 21 08:44:59.739462 2026] [security2:error] [pid 511108:tid 511315] [client 15.235.98.58:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "energyzapp.com"] [uri "/"] [unique_id "al9bu4Td5soprXwxAH0IXwAATU0"]
[Tue Jul 21 08:44:59.856597 2026] [security2:error] [pid 514479:tid 514593] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9bu_zqsQqnLoCgUjhrQQABeGw"]
[Tue Jul 21 08:44:59.977058 2026] [security2:error] [pid 514479:tid 514486] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9bu_zqsQqnLoCgUjhrQwABdwI"]
[Tue Jul 21 08:45:00.001261 2026] [autoindex:error] [pid 514479:tid 514691] [client 20.197.195.24:63230] AH01276: Cannot serve directory /home4/drjoao27/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:45:00.076454 2026] [security2:error] [pid 514479:tid 514611] [remote 54.37.118.65:40452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "teletransportadora.com"] [uri "/robots.txt"] [unique_id "al9bvPzqsQqnLoCgUjhrRwABTH4"]
[Tue Jul 21 08:45:00.076635 2026] [security2:error] [pid 514479:tid 514680] [client 54.37.118.65:40452] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "teletransportadora.com"] [uri "/robots.txt"] [unique_id "al9bvPzqsQqnLoCgUjhrRwABTH4"]
[Tue Jul 21 08:45:00.136207 2026] [security2:error] [pid 514479:tid 514572] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9bvPzqsQqnLoCgUjhrSwABglc"]
[Tue Jul 21 08:45:00.178489 2026] [security2:error] [pid 511108:tid 511327] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bu4Td5soprXwxAH0IWwAAAFk"]
[Tue Jul 21 08:45:00.179079 2026] [autoindex:error] [pid 514479:tid 514667] [client 20.197.195.24:63230] AH01276: Cannot serve directory /home4/drjoao27/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:45:00.308767 2026] [security2:error] [pid 514479:tid 514561] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9bvPzqsQqnLoCgUjhrTgABiUw"]
[Tue Jul 21 08:45:00.372338 2026] [security2:error] [pid 514479:tid 514670] [client 212.32.76.13:30335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al9bvPzqsQqnLoCgUjhrUAAAAUI"]
[Tue Jul 21 08:45:00.437016 2026] [security2:error] [pid 514479:tid 514697] [client 20.197.195.24:63230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/abcd.php"] [unique_id "al9bvPzqsQqnLoCgUjhrUQAAAV0"]
[Tue Jul 21 08:45:00.448488 2026] [security2:error] [pid 511108:tid 511298] [client 195.49.128.211:58249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bvITd5soprXwxAH0IbAAAADw"]
[Tue Jul 21 08:45:00.448579 2026] [security2:error] [pid 511108:tid 511298] [client 195.49.128.211:58249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bvITd5soprXwxAH0IbAAAADw"]
[Tue Jul 21 08:45:00.481782 2026] [security2:error] [pid 514479:tid 514610] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9bvPzqsQqnLoCgUjhrUgABdH0"]
[Tue Jul 21 08:45:00.587881 2026] [security2:error] [pid 511108:tid 511275] [client 212.32.76.66:42137] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwentyfive/"] [unique_id "al9bvITd5soprXwxAH0IcgAAACU"]
[Tue Jul 21 08:45:00.659618 2026] [security2:error] [pid 514479:tid 514569] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9bvPzqsQqnLoCgUjhrUwABIFQ"]
[Tue Jul 21 08:45:00.804114 2026] [security2:error] [pid 514479:tid 514496] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9bvPzqsQqnLoCgUjhrVgABLgw"]
[Tue Jul 21 08:45:00.818953 2026] [security2:error] [pid 511108:tid 511221] [remote 104.207.59.205:12213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.59.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9bvITd5soprXwxAH0IcwAAIHA"]
[Tue Jul 21 08:45:00.836877 2026] [security2:error] [pid 514479:tid 514715] [client 59.95.197.55:55731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bvPzqsQqnLoCgUjhrWQAAAW8"]
[Tue Jul 21 08:45:00.836972 2026] [security2:error] [pid 514479:tid 514715] [client 59.95.197.55:55731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bvPzqsQqnLoCgUjhrWQAAAW8"]
[Tue Jul 21 08:45:00.994161 2026] [security2:error] [pid 514479:tid 514493] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9bvPzqsQqnLoCgUjhrWwABegk"]
[Tue Jul 21 08:45:01.063349 2026] [security2:error] [pid 514479:tid 514694] [client 212.32.76.13:41883] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/colors/modern/test2.php"] [unique_id "al9bvfzqsQqnLoCgUjhrXwAAAVo"]
[Tue Jul 21 08:45:01.153400 2026] [security2:error] [pid 514479:tid 514545] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9bvfzqsQqnLoCgUjhrYwABVT0"]
[Tue Jul 21 08:45:01.172455 2026] [core:error] [pid 514479:tid 514719] [client 66.249.66.67:50398] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:45:01.172479 2026] [core:error] [pid 514479:tid 514719] [client 66.249.66.67:50398] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:45:01.293390 2026] [security2:error] [pid 511108:tid 511330] [client 20.197.195.24:63211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/file15.php"] [unique_id "al9bvYTd5soprXwxAH0IfgAAAFw"]
[Tue Jul 21 08:45:01.334041 2026] [security2:error] [pid 514479:tid 514554] [remote 207.180.241.245:56480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/wp-login.php"] [unique_id "al9bvfzqsQqnLoCgUjhrZgABU0U"]
[Tue Jul 21 08:45:01.335251 2026] [security2:error] [pid 514479:tid 514539] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9bvfzqsQqnLoCgUjhrZwABXDc"]
[Tue Jul 21 08:45:01.379605 2026] [security2:error] [pid 514479:tid 514673] [client 203.25.124.246:41905] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403x.php"] [unique_id "al9bvfzqsQqnLoCgUjhraAAAAUU"]
[Tue Jul 21 08:45:01.497886 2026] [security2:error] [pid 514479:tid 514485] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9bvfzqsQqnLoCgUjhrawABDQE"]
[Tue Jul 21 08:45:01.600163 2026] [security2:error] [pid 514479:tid 514709] [client 20.197.195.24:63151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/jp.php"] [unique_id "al9bvfzqsQqnLoCgUjhrbQAAAWk"]
[Tue Jul 21 08:45:01.605910 2026] [security2:error] [pid 514479:tid 514740] [client 122.176.100.127:57289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bvfzqsQqnLoCgUjhrbgAAAYg"]
[Tue Jul 21 08:45:01.605992 2026] [security2:error] [pid 514479:tid 514740] [client 122.176.100.127:57289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9bvfzqsQqnLoCgUjhrbgAAAYg"]
[Tue Jul 21 08:45:01.662360 2026] [security2:error] [pid 511108:tid 511179] [remote 167.114.139.141:59734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "teletransportadora.com"] [uri "/"] [unique_id "al9bvYTd5soprXwxAH0IhAAALkY"]
[Tue Jul 21 08:45:01.662531 2026] [security2:error] [pid 511108:tid 511284] [client 167.114.139.141:59734] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "teletransportadora.com"] [uri "/"] [unique_id "al9bvYTd5soprXwxAH0IhAAALkY"]
[Tue Jul 21 08:45:01.723864 2026] [security2:error] [pid 514479:tid 514609] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9bvfzqsQqnLoCgUjhrbwABJHw"]
[Tue Jul 21 08:45:01.815022 2026] [security2:error] [pid 511108:tid 511265] [client 20.197.195.24:63134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/f35.php"] [unique_id "al9bvYTd5soprXwxAH0IiAAAABs"]
[Tue Jul 21 08:45:01.874792 2026] [security2:error] [pid 514479:tid 514553] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9bvfzqsQqnLoCgUjhrjgABK0Q"]
[Tue Jul 21 08:45:01.929169 2026] [security2:error] [pid 514479:tid 514557] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bvfzqsQqnLoCgUjhrjwABR0g"]
[Tue Jul 21 08:45:01.929386 2026] [security2:error] [pid 514479:tid 514675] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9bvfzqsQqnLoCgUjhrjwABR0g"]
[Tue Jul 21 08:45:02.034090 2026] [security2:error] [pid 511108:tid 511361] [client 20.197.195.24:63219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-load.php"] [unique_id "al9bvoTd5soprXwxAH0IjQAAAHs"]
[Tue Jul 21 08:45:02.060025 2026] [security2:error] [pid 514479:tid 514525] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php"] [unique_id "al9bvvzqsQqnLoCgUjhrkQABeCk"]
[Tue Jul 21 08:45:02.205918 2026] [security2:error] [pid 514479:tid 514590] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9bvvzqsQqnLoCgUjhrkwABVGk"]
[Tue Jul 21 08:45:02.375714 2026] [security2:error] [pid 514479:tid 514657] [client 203.25.124.254:30261] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/user/upgrade/"] [unique_id "al9bvvzqsQqnLoCgUjhrlwAAATU"]
[Tue Jul 21 08:45:02.565742 2026] [security2:error] [pid 514479:tid 514618] [client 203.25.124.74:42529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwentyfive/parts/"] [unique_id "al9bvvzqsQqnLoCgUjhroQAAAQ4"]
[Tue Jul 21 08:45:02.569106 2026] [security2:error] [pid 514479:tid 514530] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9bvvzqsQqnLoCgUjhrogABiS4"]
[Tue Jul 21 08:45:02.797053 2026] [security2:error] [pid 514479:tid 514652] [client 117.213.202.34:56615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bvvzqsQqnLoCgUjhrswAAATA"]
[Tue Jul 21 08:45:02.797195 2026] [security2:error] [pid 514479:tid 514652] [client 117.213.202.34:56615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bvvzqsQqnLoCgUjhrswAAATA"]
[Tue Jul 21 08:45:02.903620 2026] [security2:error] [pid 514479:tid 514645] [client 41.89.234.2:32431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bvvzqsQqnLoCgUjhrvwAAASk"]
[Tue Jul 21 08:45:02.903753 2026] [security2:error] [pid 514479:tid 514645] [client 41.89.234.2:32431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bvvzqsQqnLoCgUjhrvwAAASk"]
[Tue Jul 21 08:45:02.936768 2026] [security2:error] [pid 514479:tid 514637] [client 20.197.195.24:50038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xyn.php"] [unique_id "al9bvvzqsQqnLoCgUjhrwQAAASE"]
[Tue Jul 21 08:45:02.938537 2026] [security2:error] [pid 514479:tid 514536] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9bvvzqsQqnLoCgUjhrwgABgTQ"]
[Tue Jul 21 08:45:02.984103 2026] [security2:error] [pid 511108:tid 511162] [remote 151.123.176.92:23577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.176.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9bvoTd5soprXwxAH0InAAAIzU"]
[Tue Jul 21 08:45:03.000701 2026] [security2:error] [pid 511108:tid 511339] [client 20.197.192.193:4008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/wp-wpbak.php"] [unique_id "al9bvoTd5soprXwxAH0IoAAAAGU"]
[Tue Jul 21 08:45:03.276400 2026] [security2:error] [pid 511108:tid 511337] [client 203.25.124.204:21999] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Text/Diff/"] [unique_id "al9bv4Td5soprXwxAH0IpQAAAGM"]
[Tue Jul 21 08:45:03.292098 2026] [security2:error] [pid 514479:tid 514620] [client 202.179.75.202:34814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bv_zqsQqnLoCgUjhr0QAAARA"]
[Tue Jul 21 08:45:03.292253 2026] [security2:error] [pid 514479:tid 514620] [client 202.179.75.202:34814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9bv_zqsQqnLoCgUjhr0QAAARA"]
[Tue Jul 21 08:45:03.429901 2026] [core:error] [pid 511108:tid 511325] [client 66.249.66.67:34791] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:45:03.429927 2026] [core:error] [pid 511108:tid 511325] [client 66.249.66.67:34791] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:45:03.671409 2026] [security2:error] [pid 511108:tid 511358] [client 173.252.95.19:36650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bv4Td5soprXwxAH0IrAAAAHg"]
[Tue Jul 21 08:45:04.078719 2026] [security2:error] [pid 511108:tid 511328] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bv4Td5soprXwxAH0IqgAAAFo"]
[Tue Jul 21 08:45:04.097310 2026] [security2:error] [pid 511108:tid 511249] [client 152.59.181.104:56947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bwITd5soprXwxAH0ItAAAAAs"]
[Tue Jul 21 08:45:04.097481 2026] [security2:error] [pid 511108:tid 511249] [client 152.59.181.104:56947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9bwITd5soprXwxAH0ItAAAAAs"]
[Tue Jul 21 08:45:04.123110 2026] [security2:error] [pid 514479:tid 514715] [client 54.39.136.2:17862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "diskvidros.com.br"] [uri "/robots.txt"] [unique_id "al9bwPzqsQqnLoCgUjhr9AAAAW8"]
[Tue Jul 21 08:45:04.123232 2026] [security2:error] [pid 514479:tid 514715] [client 54.39.136.2:17862] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "diskvidros.com.br"] [uri "/robots.txt"] [unique_id "al9bwPzqsQqnLoCgUjhr9AAAAW8"]
[Tue Jul 21 08:45:04.131276 2026] [security2:error] [pid 511108:tid 511124] [remote 57.141.18.106:30584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9bwITd5soprXwxAH0ItQAAFA8"]
[Tue Jul 21 08:45:04.170911 2026] [security2:error] [pid 514479:tid 514627] [client 203.25.124.252:27751] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/"] [unique_id "al9bwPzqsQqnLoCgUjhr9QAAARc"]
[Tue Jul 21 08:45:04.345314 2026] [security2:error] [pid 514479:tid 514650] [client 173.252.95.114:59338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bwPzqsQqnLoCgUjhr-AAAAS4"]
[Tue Jul 21 08:45:04.364666 2026] [security2:error] [pid 511108:tid 511244] [client 203.25.124.70:41521] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/query-title/"] [unique_id "al9bwITd5soprXwxAH0IugAAAAY"]
[Tue Jul 21 08:45:04.424573 2026] [security2:error] [pid 514479:tid 514701] [client 69.171.230.28:35590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9bwPzqsQqnLoCgUjhr_AAAAWE"]
[Tue Jul 21 08:45:04.570099 2026] [security2:error] [pid 514479:tid 514728] [client 20.10.88.201:1602] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rioclaroimovel.com.br"] [uri "/index.php"] [unique_id "al9bwPzqsQqnLoCgUjhr-gAAAXw"]
[Tue Jul 21 08:45:04.609688 2026] [security2:error] [pid 514479:tid 514646] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9bwPzqsQqnLoCgUjhr_gABKnw"]
[Tue Jul 21 08:45:05.169321 2026] [security2:error] [pid 514479:tid 514740] [client 212.32.76.6:43771] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/config.php"] [unique_id "al9bwfzqsQqnLoCgUjhsCQAAAYg"]
[Tue Jul 21 08:45:05.259554 2026] [security2:error] [pid 511108:tid 511289] [client 168.167.81.163:59774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bwYTd5soprXwxAH0IzwAAADM"]
[Tue Jul 21 08:45:05.265750 2026] [security2:error] [pid 511108:tid 511289] [client 168.167.81.163:59774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9bwYTd5soprXwxAH0IzwAAADM"]
[Tue Jul 21 08:45:05.274022 2026] [security2:error] [pid 511108:tid 511272] [client 203.25.124.197:50431] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/we.php"] [unique_id "al9bwYTd5soprXwxAH0I0AAAACI"]
[Tue Jul 21 08:45:05.303432 2026] [autoindex:error] [pid 511108:tid 511253] [client 20.197.195.24:63198] AH01276: Cannot serve directory /home4/drjoao27/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:45:05.304177 2026] [security2:error] [pid 514479:tid 514560] [remote 57.141.18.42:51334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapm.xml"] [unique_id "al9bwfzqsQqnLoCgUjhsDAABEks"]
[Tue Jul 21 08:45:05.536458 2026] [security2:error] [pid 511108:tid 511308] [client 142.44.220.0:63418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "diskvidros.com.br"] [uri "/"] [unique_id "al9bwYTd5soprXwxAH0I1gAAAEY"]
[Tue Jul 21 08:45:05.536556 2026] [security2:error] [pid 511108:tid 511308] [client 142.44.220.0:63418] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "diskvidros.com.br"] [uri "/"] [unique_id "al9bwYTd5soprXwxAH0I1gAAAEY"]
[Tue Jul 21 08:45:06.066556 2026] [security2:error] [pid 514479:tid 514683] [client 203.25.124.70:46453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/images/"] [unique_id "al9bwvzqsQqnLoCgUjhsEAAAAU8"]
[Tue Jul 21 08:45:06.248670 2026] [autoindex:error] [pid 511108:tid 511352] [client 20.197.195.24:63198] AH01276: Cannot serve directory /home4/drjoao27/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:45:06.255321 2026] [security2:error] [pid 511108:tid 511300] [client 20.197.195.24:63198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ccc.php"] [unique_id "al9bwoTd5soprXwxAH0I5AAAAD4"]
[Tue Jul 21 08:45:06.273679 2026] [security2:error] [pid 514479:tid 514656] [client 212.32.76.58:34229] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/neve/assets/apps/dashboard/build/"] [unique_id "al9bwvzqsQqnLoCgUjhsFgAAATQ"]
[Tue Jul 21 08:45:06.945325 2026] [security2:error] [pid 514479:tid 514523] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bwvzqsQqnLoCgUjhsHgABICc"]
[Tue Jul 21 08:45:06.945500 2026] [security2:error] [pid 514479:tid 514636] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bwvzqsQqnLoCgUjhsHgABICc"]
[Tue Jul 21 08:45:07.001620 2026] [security2:error] [pid 511108:tid 511311] [client 5.38.115.39:53041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bw4Td5soprXwxAH0I8gAAAEk"]
[Tue Jul 21 08:45:07.001761 2026] [security2:error] [pid 511108:tid 511311] [client 5.38.115.39:53041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bw4Td5soprXwxAH0I8gAAAEk"]
[Tue Jul 21 08:45:07.307357 2026] [security2:error] [pid 514479:tid 514698] [client 20.197.195.24:49924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/w.php"] [unique_id "al9bw_zqsQqnLoCgUjhsIQAAAV4"]
[Tue Jul 21 08:45:07.438336 2026] [security2:error] [pid 514479:tid 514737] [client 113.22.144.139:55614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bw_zqsQqnLoCgUjhsIgAAAYU"]
[Tue Jul 21 08:45:07.438467 2026] [security2:error] [pid 514479:tid 514737] [client 113.22.144.139:55614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bw_zqsQqnLoCgUjhsIgAAAYU"]
[Tue Jul 21 08:45:07.479243 2026] [security2:error] [pid 514479:tid 514631] [client 203.25.124.200:40191] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/css/dist/"] [unique_id "al9bw_zqsQqnLoCgUjhsIwAAARs"]
[Tue Jul 21 08:45:07.561856 2026] [security2:error] [pid 511108:tid 511251] [client 212.32.76.4:35029] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/index-string.php"] [unique_id "al9bw4Td5soprXwxAH0JAgAAAA0"]
[Tue Jul 21 08:45:07.707346 2026] [security2:error] [pid 511108:tid 511319] [client 34.90.87.188:59230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9bw4Td5soprXwxAH0JBQAAAFE"]
[Tue Jul 21 08:45:07.997429 2026] [security2:error] [pid 514479:tid 514580] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bw_zqsQqnLoCgUjhsJgABUF8"]
[Tue Jul 21 08:45:07.997608 2026] [security2:error] [pid 514479:tid 514684] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bw_zqsQqnLoCgUjhsJgABUF8"]
[Tue Jul 21 08:45:08.135966 2026] [security2:error] [pid 511108:tid 511357] [client 34.90.87.188:49569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.87.90.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "praticarjuntos.empacta.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bxITd5soprXwxAH0JDwAAAHc"]
[Tue Jul 21 08:45:08.178155 2026] [security2:error] [pid 514479:tid 514623] [client 203.25.124.183:61559] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/media-text/"] [unique_id "al9bxPzqsQqnLoCgUjhsKgAAARM"]
[Tue Jul 21 08:45:08.178771 2026] [security2:error] [pid 511108:tid 511264] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9bw4Td5soprXwxAH0JBgAAABo"]
[Tue Jul 21 08:45:08.394861 2026] [security2:error] [pid 514479:tid 514704] [client 20.197.195.24:63146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9bxPzqsQqnLoCgUjhsLQAAAWQ"]
[Tue Jul 21 08:45:08.465963 2026] [security2:error] [pid 514479:tid 514672] [client 114.198.138.124:50333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9bxPzqsQqnLoCgUjhsLgAAAUQ"]
[Tue Jul 21 08:45:08.466129 2026] [security2:error] [pid 514479:tid 514672] [client 114.198.138.124:50333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9bxPzqsQqnLoCgUjhsLgAAAUQ"]
[Tue Jul 21 08:45:08.770476 2026] [security2:error] [pid 511108:tid 511337] [client 203.25.124.211:55861] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/includes/images/index.php"] [unique_id "al9bxITd5soprXwxAH0JGwAAAGM"]
[Tue Jul 21 08:45:08.850146 2026] [security2:error] [pid 514479:tid 514735] [client 195.49.128.211:51075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bxPzqsQqnLoCgUjhsNgAAAYM"]
[Tue Jul 21 08:45:08.850283 2026] [security2:error] [pid 514479:tid 514735] [client 195.49.128.211:51075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bxPzqsQqnLoCgUjhsNgAAAYM"]
[Tue Jul 21 08:45:08.879516 2026] [security2:error] [pid 514479:tid 514677] [client 212.32.76.65:22875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "al9bxPzqsQqnLoCgUjhsNwAAAUk"]
[Tue Jul 21 08:45:08.917597 2026] [security2:error] [pid 514479:tid 514740] [client 103.59.206.240:31026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bxPzqsQqnLoCgUjhsOAAAAYg"]
[Tue Jul 21 08:45:08.918256 2026] [security2:error] [pid 514479:tid 514740] [client 103.59.206.240:31026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bxPzqsQqnLoCgUjhsOAAAAYg"]
[Tue Jul 21 08:45:08.982777 2026] [proxy:error] [pid 511108:tid 511296] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:08.982871 2026] [proxy_http:error] [pid 511108:tid 511296] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:08.983892 2026] [proxy:error] [pid 511108:tid 511296] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:08.983933 2026] [proxy_http:error] [pid 511108:tid 511296] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:09.312462 2026] [security2:error] [pid 514479:tid 514632] [client 34.90.87.188:60613] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9bxfzqsQqnLoCgUjhsOgAAARw"]
[Tue Jul 21 08:45:09.420009 2026] [proxy:error] [pid 514479:tid 514694] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:09.420071 2026] [proxy_http:error] [pid 514479:tid 514694] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:09.420633 2026] [proxy:error] [pid 514479:tid 514694] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:09.420661 2026] [proxy_http:error] [pid 514479:tid 514694] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:09.649402 2026] [security2:error] [pid 514479:tid 514654] [client 20.197.195.24:63201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/FWAZ.php"] [unique_id "al9bxfzqsQqnLoCgUjhsQgAAATI"]
[Tue Jul 21 08:45:09.765771 2026] [security2:error] [pid 514479:tid 514722] [client 212.32.76.8:36225] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/includes/update-core-time.php"] [unique_id "al9bxfzqsQqnLoCgUjhsRAAAAXY"]
[Tue Jul 21 08:45:09.766651 2026] [security2:error] [pid 514479:tid 514738] [client 20.197.192.193:4059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/dr.php"] [unique_id "al9bxfzqsQqnLoCgUjhsRQAAAYY"]
[Tue Jul 21 08:45:09.779944 2026] [security2:error] [pid 514479:tid 514663] [client 203.25.124.185:53959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/rest-api/fields/"] [unique_id "al9bxfzqsQqnLoCgUjhsRgAAATs"]
[Tue Jul 21 08:45:09.788090 2026] [security2:error] [pid 514479:tid 514679] [client 34.90.87.188:55316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9bxfzqsQqnLoCgUjhsRwAAAUs"]
[Tue Jul 21 08:45:09.840904 2026] [security2:error] [pid 514479:tid 514639] [client 49.144.66.253:32360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bxfzqsQqnLoCgUjhsSAAAASM"]
[Tue Jul 21 08:45:09.841100 2026] [security2:error] [pid 514479:tid 514639] [client 49.144.66.253:32360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9bxfzqsQqnLoCgUjhsSAAAASM"]
[Tue Jul 21 08:45:09.880118 2026] [proxy:error] [pid 514479:tid 514701] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:09.880183 2026] [proxy_http:error] [pid 514479:tid 514701] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:09.880777 2026] [proxy:error] [pid 514479:tid 514701] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:09.880800 2026] [proxy_http:error] [pid 514479:tid 514701] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:10.179071 2026] [security2:error] [pid 514479:tid 514566] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9bxvzqsQqnLoCgUjhsVwABKVE"]
[Tue Jul 21 08:45:10.179853 2026] [security2:error] [pid 514479:tid 514547] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9bxvzqsQqnLoCgUjhsUgABKT8"]
[Tue Jul 21 08:45:10.180069 2026] [security2:error] [pid 514479:tid 514510] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9bxvzqsQqnLoCgUjhsTQABKRo"]
[Tue Jul 21 08:45:10.238718 2026] [security2:error] [pid 511108:tid 511358] [client 34.90.87.188:58521] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9bxoTd5soprXwxAH0JNAAAAHg"]
[Tue Jul 21 08:45:10.271075 2026] [autoindex:error] [pid 514479:tid 514689] [client 154.211.19.105:50223] AH01276: Cannot serve directory /home3/sabri472/evolvaa.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:45:10.318529 2026] [security2:error] [pid 514479:tid 514564] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9bxvzqsQqnLoCgUjhsWQABKU8"]
[Tue Jul 21 08:45:10.318538 2026] [security2:error] [pid 514479:tid 514521] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9bxvzqsQqnLoCgUjhsWgABKSU"]
[Tue Jul 21 08:45:10.319342 2026] [security2:error] [pid 514479:tid 514484] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9bxvzqsQqnLoCgUjhsXAABKQA"]
[Tue Jul 21 08:45:10.321178 2026] [security2:error] [pid 514479:tid 514719] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bxvzqsQqnLoCgUjhsXQAAAXM"]
[Tue Jul 21 08:45:10.492714 2026] [security2:error] [pid 514479:tid 514643] [client 20.197.195.24:63225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/miru1.php"] [unique_id "al9bxvzqsQqnLoCgUjhsYQAAASc"]
[Tue Jul 21 08:45:10.509431 2026] [security2:error] [pid 514479:tid 514498] [remote 173.252.82.2:57406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9bxvzqsQqnLoCgUjhsXwABGQ4"]
[Tue Jul 21 08:45:10.732123 2026] [security2:error] [pid 514479:tid 514620] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9bxvzqsQqnLoCgUjhsZQAAARA"]
[Tue Jul 21 08:45:10.777015 2026] [security2:error] [pid 514479:tid 514714] [client 212.32.76.64:56473] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentynineteen/sass/site/"] [unique_id "al9bxvzqsQqnLoCgUjhsZgAAAW4"]
[Tue Jul 21 08:45:10.782022 2026] [security2:error] [pid 514479:tid 514608] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9bxvzqsQqnLoCgUjhsZwABRHs"]
[Tue Jul 21 08:45:10.789210 2026] [security2:error] [pid 514479:tid 514710] [client 20.197.195.24:63159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/aa.php"] [unique_id "al9bxvzqsQqnLoCgUjhsaAAAAWo"]
[Tue Jul 21 08:45:10.792390 2026] [security2:error] [pid 514479:tid 514568] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9bxvzqsQqnLoCgUjhsagABR1M"]
[Tue Jul 21 08:45:10.792401 2026] [security2:error] [pid 514479:tid 514527] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9bxvzqsQqnLoCgUjhsawABRys"]
[Tue Jul 21 08:45:10.947811 2026] [security2:error] [pid 514479:tid 514624] [client 20.197.195.24:63143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/122.php"] [unique_id "al9bxvzqsQqnLoCgUjhsdAAAARQ"]
[Tue Jul 21 08:45:10.985266 2026] [security2:error] [pid 514479:tid 514571] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/api"] [unique_id "al9bxvzqsQqnLoCgUjhseQABT1Y"]
[Tue Jul 21 08:45:11.006657 2026] [security2:error] [pid 511108:tid 511348] [client 195.49.128.211:58868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bx4Td5soprXwxAH0JQQAAAG4"]
[Tue Jul 21 08:45:11.006845 2026] [security2:error] [pid 511108:tid 511348] [client 195.49.128.211:58868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9bx4Td5soprXwxAH0JQQAAAG4"]
[Tue Jul 21 08:45:11.112251 2026] [security2:error] [pid 514479:tid 514734] [client 34.90.87.188:53370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9bx_zqsQqnLoCgUjhsfgAAAYI"]
[Tue Jul 21 08:45:11.129699 2026] [security2:error] [pid 514479:tid 514740] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9bx_zqsQqnLoCgUjhsfwAAAYg"]
[Tue Jul 21 08:45:11.163867 2026] [security2:error] [pid 514479:tid 514732] [client 203.25.124.37:40431] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/woocommerce-call.php"] [unique_id "al9bx_zqsQqnLoCgUjhsgAAAAYA"]
[Tue Jul 21 08:45:11.246658 2026] [security2:error] [pid 514479:tid 514636] [client 20.197.195.24:49947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/get.php"] [unique_id "al9bx_zqsQqnLoCgUjhshQAAASA"]
[Tue Jul 21 08:45:11.334977 2026] [security2:error] [pid 514479:tid 514704] [client 59.95.197.55:56223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bx_zqsQqnLoCgUjhshgAAAWQ"]
[Tue Jul 21 08:45:11.335736 2026] [security2:error] [pid 514479:tid 514704] [client 59.95.197.55:56223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bx_zqsQqnLoCgUjhshgAAAWQ"]
[Tue Jul 21 08:45:11.414479 2026] [security2:error] [pid 514479:tid 514701] [client 20.197.195.24:50042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/as.php"] [unique_id "al9bx_zqsQqnLoCgUjhsiAAAAWE"]
[Tue Jul 21 08:45:11.418879 2026] [security2:error] [pid 514479:tid 514595] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/api"] [unique_id "al9bx_zqsQqnLoCgUjhsigABXm4"]
[Tue Jul 21 08:45:11.516415 2026] [security2:error] [pid 514479:tid 514642] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9bx_zqsQqnLoCgUjhsjAAAASY"]
[Tue Jul 21 08:45:11.525021 2026] [security2:error] [pid 514479:tid 514681] [client 34.90.87.188:51301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9bx_zqsQqnLoCgUjhsjQAAAU0"]
[Tue Jul 21 08:45:11.580086 2026] [security2:error] [pid 514479:tid 514736] [client 20.197.195.24:49990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ccou.php"] [unique_id "al9bx_zqsQqnLoCgUjhsjwAAAYQ"]
[Tue Jul 21 08:45:11.600940 2026] [security2:error] [pid 514479:tid 514541] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/api"] [unique_id "al9bx_zqsQqnLoCgUjhskAABZjk"]
[Tue Jul 21 08:45:11.651384 2026] [security2:error] [pid 514479:tid 514602] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api"] [unique_id "al9bx_zqsQqnLoCgUjhslgABZnU"]
[Tue Jul 21 08:45:11.660948 2026] [security2:error] [pid 514479:tid 514606] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api"] [unique_id "al9bx_zqsQqnLoCgUjhslwABZnk"]
[Tue Jul 21 08:45:11.675182 2026] [security2:error] [pid 514479:tid 514552] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api"] [unique_id "al9bx_zqsQqnLoCgUjhsmAABZkM"]
[Tue Jul 21 08:45:11.675510 2026] [security2:error] [pid 514479:tid 514598] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api"] [unique_id "al9bx_zqsQqnLoCgUjhsmQABZnE"]
[Tue Jul 21 08:45:11.752521 2026] [security2:error] [pid 514479:tid 514494] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api"] [unique_id "al9bx_zqsQqnLoCgUjhsmgABKQo"]
[Tue Jul 21 08:45:11.873290 2026] [security2:error] [pid 514479:tid 514635] [client 203.25.124.206:62477] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/fukasawa/inc/classes/403x.php"] [unique_id "al9bx_zqsQqnLoCgUjhsnQAAAR8"]
[Tue Jul 21 08:45:11.924955 2026] [security2:error] [pid 514479:tid 514705] [client 20.197.195.24:63109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/w3lls.php"] [unique_id "al9bx_zqsQqnLoCgUjhsngAAAWU"]
[Tue Jul 21 08:45:11.944926 2026] [security2:error] [pid 514479:tid 514716] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9bx_zqsQqnLoCgUjhsoAAAAXA"]
[Tue Jul 21 08:45:11.963770 2026] [security2:error] [pid 511108:tid 511289] [client 212.32.76.12:37453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/user/upgrade/index.php"] [unique_id "al9bx4Td5soprXwxAH0JUwAAADM"]
[Tue Jul 21 08:45:12.035385 2026] [security2:error] [pid 514479:tid 514538] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api"] [unique_id "al9byPzqsQqnLoCgUjhsogABEDY"]
[Tue Jul 21 08:45:12.082395 2026] [security2:error] [pid 514479:tid 514737] [client 122.176.100.127:57799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9byPzqsQqnLoCgUjhspQAAAYU"]
[Tue Jul 21 08:45:12.082501 2026] [security2:error] [pid 514479:tid 514737] [client 122.176.100.127:57799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9byPzqsQqnLoCgUjhspQAAAYU"]
[Tue Jul 21 08:45:12.195708 2026] [security2:error] [pid 514479:tid 514526] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v1"] [unique_id "al9byPzqsQqnLoCgUjhspwABRio"]
[Tue Jul 21 08:45:12.216768 2026] [security2:error] [pid 511108:tid 511293] [client 34.90.87.188:60898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9byITd5soprXwxAH0JWAAAADc"]
[Tue Jul 21 08:45:12.229726 2026] [security2:error] [pid 511108:tid 511351] [client 20.197.195.24:63119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/test1.php"] [unique_id "al9byITd5soprXwxAH0JWwAAAHE"]
[Tue Jul 21 08:45:12.283216 2026] [security2:error] [pid 514479:tid 514587] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v1"] [unique_id "al9byPzqsQqnLoCgUjhsrQABMWY"]
[Tue Jul 21 08:45:12.285065 2026] [security2:error] [pid 511108:tid 511298] [client 20.197.195.24:50012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/database.php"] [unique_id "al9byITd5soprXwxAH0JXgAAADw"]
[Tue Jul 21 08:45:12.316865 2026] [security2:error] [pid 511108:tid 511307] [client 20.197.195.24:63125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/file.php"] [unique_id "al9byITd5soprXwxAH0JXwAAAEU"]
[Tue Jul 21 08:45:12.323541 2026] [security2:error] [pid 514479:tid 514591] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v1"] [unique_id "al9byPzqsQqnLoCgUjhsrwABMWo"]
[Tue Jul 21 08:45:12.367227 2026] [security2:error] [pid 511108:tid 511304] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9byITd5soprXwxAH0JYgAAAEI"]
[Tue Jul 21 08:45:12.406721 2026] [security2:error] [pid 511108:tid 511275] [client 20.197.195.24:63123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/file.php"] [unique_id "al9byITd5soprXwxAH0JYwAAACU"]
[Tue Jul 21 08:45:12.457170 2026] [security2:error] [pid 514479:tid 514680] [client 74.7.241.157:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mairaelias1745851015542.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9byPzqsQqnLoCgUjhstAABTGw"]
[Tue Jul 21 08:45:12.475663 2026] [security2:error] [pid 514479:tid 514732] [client 20.197.195.24:63197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/777.php"] [unique_id "al9byPzqsQqnLoCgUjhstQAAAYA"]
[Tue Jul 21 08:45:12.659177 2026] [security2:error] [pid 511108:tid 511333] [client 34.90.87.188:53515] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9byITd5soprXwxAH0JbAAAAF8"]
[Tue Jul 21 08:45:12.675530 2026] [security2:error] [pid 514479:tid 514692] [client 20.197.195.24:63205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ssixta.php"] [unique_id "al9byPzqsQqnLoCgUjhstwAAAVg"]
[Tue Jul 21 08:45:12.676166 2026] [security2:error] [pid 514479:tid 514725] [client 203.25.124.190:20795] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/filester/assets/css/404.php"] [unique_id "al9byPzqsQqnLoCgUjhsuAAAAXk"]
[Tue Jul 21 08:45:12.742215 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.742306 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.742424 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.742463 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.742498 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.742614 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.742688 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.742727 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.742778 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.742821 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.742869 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.742906 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.742942 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.742978 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743023 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743060 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743096 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743134 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743170 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743205 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743241 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743276 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743311 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743347 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743382 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743419 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743455 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743491 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743581 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743617 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743654 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743689 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743724 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743761 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743797 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743842 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743874 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743912 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.743963 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744006 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744059 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744103 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744149 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744213 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744256 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744292 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744329 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744365 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744415 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744453 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744489 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744525 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744561 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744598 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744634 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744670 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744708 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744745 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744783 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744824 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744863 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744898 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744934 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.744985 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745027 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745064 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745109 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745149 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745186 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745225 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745265 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745302 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745346 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745382 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745418 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745455 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745491 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745526 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745562 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745598 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745635 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745671 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745708 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745743 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745779 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745827 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745855 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745893 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745929 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.745965 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.746015 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.746051 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.746096 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.746136 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.746184 2026] [lsapi:warn] [pid 514479:tid 514655] [client 189.6.178.120:59152] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:45:12.761315 2026] [security2:error] [pid 514479:tid 514611] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v1"] [unique_id "al9byPzqsQqnLoCgUjhsugABIX4"]
[Tue Jul 21 08:45:12.799379 2026] [security2:error] [pid 511108:tid 511278] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9byITd5soprXwxAH0JcAAAACg"]
[Tue Jul 21 08:45:12.822869 2026] [security2:error] [pid 511108:tid 511324] [client 65.21.113.253:42266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9byITd5soprXwxAH0JYQAAAFY"]
[Tue Jul 21 08:45:12.835213 2026] [security2:error] [pid 514479:tid 514717] [client 173.252.95.17:53964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9byPzqsQqnLoCgUjhsvAAAAXE"]
[Tue Jul 21 08:45:12.853384 2026] [security2:error] [pid 514479:tid 514600] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v1"] [unique_id "al9byPzqsQqnLoCgUjhsvQABDnM"]
[Tue Jul 21 08:45:12.886508 2026] [security2:error] [pid 514479:tid 514605] [remote 192.241.143.148:58936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9byPzqsQqnLoCgUjhsvgABY3g"]
[Tue Jul 21 08:45:12.905807 2026] [security2:error] [pid 514479:tid 514520] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v1"] [unique_id "al9byPzqsQqnLoCgUjhsvwABYSQ"]
[Tue Jul 21 08:45:12.910191 2026] [security2:error] [pid 511108:tid 511344] [client 20.197.195.24:49931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/1c.php"] [unique_id "al9byITd5soprXwxAH0JcgAAAGo"]
[Tue Jul 21 08:45:12.923825 2026] [security2:error] [pid 514479:tid 514576] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v1"] [unique_id "al9byPzqsQqnLoCgUjhswAABa1s"]
[Tue Jul 21 08:45:12.970445 2026] [security2:error] [pid 511108:tid 511269] [client 212.32.76.10:23257] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/maint/css/index.php"] [unique_id "al9byITd5soprXwxAH0JcwAAAB8"]
[Tue Jul 21 08:45:12.991994 2026] [security2:error] [pid 514479:tid 514532] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v1"] [unique_id "al9byPzqsQqnLoCgUjhswgABfTA"]
[Tue Jul 21 08:45:12.996783 2026] [security2:error] [pid 514479:tid 514561] [remote 184.168.124.4:47074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.124.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "links.principiamatematica.com"] [uri "/wp-login.php"] [unique_id "al9byPzqsQqnLoCgUjhswwABgkw"]
[Tue Jul 21 08:45:13.092746 2026] [security2:error] [pid 514479:tid 514515] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v1"] [unique_id "al9byfzqsQqnLoCgUjhsxgABhB8"]
[Tue Jul 21 08:45:13.094032 2026] [security2:error] [pid 514479:tid 514559] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v2"] [unique_id "al9byfzqsQqnLoCgUjhsyQABhEo"]
[Tue Jul 21 08:45:13.094661 2026] [security2:error] [pid 514479:tid 514531] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v2"] [unique_id "al9byfzqsQqnLoCgUjhszwABhC8"]
[Tue Jul 21 08:45:13.096417 2026] [security2:error] [pid 511108:tid 511320] [client 20.197.195.24:49988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/test2.php"] [unique_id "al9byYTd5soprXwxAH0JdwAAAFI"]
[Tue Jul 21 08:45:13.156178 2026] [security2:error] [pid 514479:tid 514592] [remote 160.187.68.132:34716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9byfzqsQqnLoCgUjhs0gABe2s"]
[Tue Jul 21 08:45:13.215132 2026] [security2:error] [pid 514479:tid 514687] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9byfzqsQqnLoCgUjhs1AAAAVM"]
[Tue Jul 21 08:45:13.289717 2026] [security2:error] [pid 514479:tid 514545] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9byfzqsQqnLoCgUjhs1wABMD0"]
[Tue Jul 21 08:45:13.289904 2026] [security2:error] [pid 514479:tid 514652] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9byfzqsQqnLoCgUjhs1wABMD0"]
[Tue Jul 21 08:45:13.300222 2026] [security2:error] [pid 511108:tid 511285] [client 34.90.87.188:56387] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9byYTd5soprXwxAH0JewAAAC8"]
[Tue Jul 21 08:45:13.347214 2026] [security2:error] [pid 511108:tid 511259] [client 20.197.195.24:50003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/buy.php"] [unique_id "al9byYTd5soprXwxAH0JfAAAABU"]
[Tue Jul 21 08:45:13.506193 2026] [security2:error] [pid 514479:tid 514589] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v2"] [unique_id "al9byfzqsQqnLoCgUjhs2QABDWg"]
[Tue Jul 21 08:45:13.630234 2026] [security2:error] [pid 514479:tid 514691] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9byfzqsQqnLoCgUjhs3wAAAVc"]
[Tue Jul 21 08:45:13.769667 2026] [security2:error] [pid 514479:tid 514649] [client 203.25.124.4:45339] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/wp-conflg.php"] [unique_id "al9byfzqsQqnLoCgUjhs4gAAAS0"]
[Tue Jul 21 08:45:13.771739 2026] [security2:error] [pid 514479:tid 514485] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v2"] [unique_id "al9byfzqsQqnLoCgUjhs4wABgwE"]
[Tue Jul 21 08:45:13.772612 2026] [security2:error] [pid 514479:tid 514609] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v2"] [unique_id "al9byfzqsQqnLoCgUjhs5AABg3w"]
[Tue Jul 21 08:45:13.773260 2026] [security2:error] [pid 514479:tid 514500] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v2"] [unique_id "al9byfzqsQqnLoCgUjhs5QABgxA"]
[Tue Jul 21 08:45:13.776420 2026] [security2:error] [pid 514479:tid 514690] [client 20.197.195.24:50030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ssend.php"] [unique_id "al9byfzqsQqnLoCgUjhs5gAAAVY"]
[Tue Jul 21 08:45:13.837803 2026] [security2:error] [pid 514479:tid 514529] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v2"] [unique_id "al9byfzqsQqnLoCgUjhs6gABFi0"]
[Tue Jul 21 08:45:13.837968 2026] [security2:error] [pid 514479:tid 514601] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v2"] [unique_id "al9byfzqsQqnLoCgUjhs6QABFnQ"]
[Tue Jul 21 08:45:13.840893 2026] [security2:error] [pid 514479:tid 514489] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/v2"] [unique_id "al9byfzqsQqnLoCgUjhs6wABPwU"]
[Tue Jul 21 08:45:13.850350 2026] [security2:error] [pid 514479:tid 514560] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/config"] [unique_id "al9byfzqsQqnLoCgUjhs7gABHEs"]
[Tue Jul 21 08:45:13.916243 2026] [security2:error] [pid 514479:tid 514722] [client 61.1.167.83:61619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9byfzqsQqnLoCgUjhs8AAAAXY"]
[Tue Jul 21 08:45:13.927622 2026] [security2:error] [pid 514479:tid 514722] [client 61.1.167.83:61619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9byfzqsQqnLoCgUjhs8AAAAXY"]
[Tue Jul 21 08:45:13.947762 2026] [security2:error] [pid 514479:tid 514694] [client 34.90.87.188:61692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9byfzqsQqnLoCgUjhs8QAAAVo"]
[Tue Jul 21 08:45:13.965243 2026] [security2:error] [pid 514479:tid 514670] [client 203.25.124.48:44963] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/pattern/index.php"] [unique_id "al9byfzqsQqnLoCgUjhs8gAAAUI"]
[Tue Jul 21 08:45:14.032464 2026] [security2:error] [pid 514479:tid 514741] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9byvzqsQqnLoCgUjhs8wAAAYk"]
[Tue Jul 21 08:45:14.069648 2026] [security2:error] [pid 511108:tid 511276] [client 20.197.192.193:27165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/kua.php"] [unique_id "al9byoTd5soprXwxAH0JhAAAACY"]
[Tue Jul 21 08:45:14.094820 2026] [security2:error] [pid 514479:tid 514678] [client 20.197.195.24:49968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/item.php"] [unique_id "al9byvzqsQqnLoCgUjhs9QAAAUo"]
[Tue Jul 21 08:45:14.168713 2026] [security2:error] [pid 514479:tid 514674] [client 202.179.75.202:55640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9byvzqsQqnLoCgUjhs-QAAAUY"]
[Tue Jul 21 08:45:14.168807 2026] [security2:error] [pid 514479:tid 514674] [client 202.179.75.202:55640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9byvzqsQqnLoCgUjhs-QAAAUY"]
[Tue Jul 21 08:45:14.223831 2026] [security2:error] [pid 514479:tid 514725] [client 20.197.195.24:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ss.php"] [unique_id "al9byvzqsQqnLoCgUjhs_AAAAXk"]
[Tue Jul 21 08:45:14.337013 2026] [security2:error] [pid 511108:tid 511361] [client 20.197.195.24:49998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/hypo.php"] [unique_id "al9byoTd5soprXwxAH0JkAAAAHs"]
[Tue Jul 21 08:45:14.427775 2026] [security2:error] [pid 514479:tid 514607] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/config"] [unique_id "al9byvzqsQqnLoCgUjhtAgABI3o"]
[Tue Jul 21 08:45:14.471196 2026] [security2:error] [pid 514479:tid 514511] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/config"] [unique_id "al9byvzqsQqnLoCgUjhtBAABPBs"]
[Tue Jul 21 08:45:14.478074 2026] [security2:error] [pid 511108:tid 511314] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9byoTd5soprXwxAH0JkwAAAEw"]
[Tue Jul 21 08:45:14.504825 2026] [security2:error] [pid 511108:tid 511288] [client 117.213.202.34:57195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.202.213.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9byYTd5soprXwxAH0JfgAAADI"]
[Tue Jul 21 08:45:14.505039 2026] [security2:error] [pid 511108:tid 511288] [client 117.213.202.34:57195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sscoenper.com.br"] [uri "/xmlrpc.php"] [unique_id "al9byYTd5soprXwxAH0JfgAAADI"]
[Tue Jul 21 08:45:14.540595 2026] [security2:error] [pid 514479:tid 514597] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config"] [unique_id "al9byvzqsQqnLoCgUjhtCAABPHA"]
[Tue Jul 21 08:45:14.548373 2026] [security2:error] [pid 514479:tid 514488] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config"] [unique_id "al9byvzqsQqnLoCgUjhtCQABPAQ"]
[Tue Jul 21 08:45:14.576804 2026] [security2:error] [pid 514479:tid 514618] [client 203.25.124.197:39877] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al9byvzqsQqnLoCgUjhtCgAAAQ4"]
[Tue Jul 21 08:45:14.599985 2026] [security2:error] [pid 511108:tid 511260] [client 34.90.87.188:53483] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9byoTd5soprXwxAH0JlAAAABY"]
[Tue Jul 21 08:45:14.625749 2026] [security2:error] [pid 514479:tid 514604] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config"] [unique_id "al9byvzqsQqnLoCgUjhtDAABa3c"]
[Tue Jul 21 08:45:14.626282 2026] [security2:error] [pid 514479:tid 514596] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config"] [unique_id "al9byvzqsQqnLoCgUjhtDQABa28"]
[Tue Jul 21 08:45:14.626598 2026] [security2:error] [pid 514479:tid 514580] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config"] [unique_id "al9byvzqsQqnLoCgUjhtDgABa18"]
[Tue Jul 21 08:45:14.734886 2026] [security2:error] [pid 514479:tid 514704] [client 41.89.234.2:59705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9byvzqsQqnLoCgUjhtEAAAAWQ"]
[Tue Jul 21 08:45:14.735094 2026] [security2:error] [pid 514479:tid 514704] [client 41.89.234.2:59705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9byvzqsQqnLoCgUjhtEAAAAWQ"]
[Tue Jul 21 08:45:14.922185 2026] [security2:error] [pid 514479:tid 514492] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/config"] [unique_id "al9byvzqsQqnLoCgUjhtEwABhAg"]
[Tue Jul 21 08:45:14.928788 2026] [security2:error] [pid 514479:tid 514615] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9byvzqsQqnLoCgUjhtFAAAAQs"]
[Tue Jul 21 08:45:14.948861 2026] [security2:error] [pid 511108:tid 511346] [client 168.167.81.163:63458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9byoTd5soprXwxAH0JnwAAAGw"]
[Tue Jul 21 08:45:14.948979 2026] [security2:error] [pid 511108:tid 511346] [client 168.167.81.163:63458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9byoTd5soprXwxAH0JnwAAAGw"]
[Tue Jul 21 08:45:15.039777 2026] [security2:error] [pid 514479:tid 514660] [client 20.197.195.24:63223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/users.php"] [unique_id "al9by_zqsQqnLoCgUjhtFwAAATg"]
[Tue Jul 21 08:45:15.119663 2026] [security2:error] [pid 514479:tid 514584] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/api/config"] [unique_id "al9by_zqsQqnLoCgUjhtGQABQWM"]
[Tue Jul 21 08:45:15.121287 2026] [security2:error] [pid 514479:tid 514629] [client 34.90.87.188:55864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9by_zqsQqnLoCgUjhtGwAAARk"]
[Tue Jul 21 08:45:15.207915 2026] [security2:error] [pid 514479:tid 514673] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9by_zqsQqnLoCgUjhtHAABRX8"]
[Tue Jul 21 08:45:15.237967 2026] [security2:error] [pid 514479:tid 514547] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/api/config"] [unique_id "al9by_zqsQqnLoCgUjhtIQABQT8"]
[Tue Jul 21 08:45:15.265082 2026] [security2:error] [pid 511108:tid 511255] [client 203.25.124.47:50173] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/upgrade-temp-backup/chosen.php"] [unique_id "al9by4Td5soprXwxAH0JqAAAABE"]
[Tue Jul 21 08:45:15.305048 2026] [security2:error] [pid 514479:tid 514525] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/api/config"] [unique_id "al9by_zqsQqnLoCgUjhtJQABQSk"]
[Tue Jul 21 08:45:15.404115 2026] [security2:error] [pid 511108:tid 511342] [client 20.197.195.24:50017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/177.php"] [unique_id "al9by4Td5soprXwxAH0JqwAAAGg"]
[Tue Jul 21 08:45:15.520874 2026] [security2:error] [pid 511108:tid 511300] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9by4Td5soprXwxAH0JrwAAAD4"]
[Tue Jul 21 08:45:15.586265 2026] [security2:error] [pid 514479:tid 514557] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/config"] [unique_id "al9by_zqsQqnLoCgUjhtKwABg0g"]
[Tue Jul 21 08:45:15.592903 2026] [security2:error] [pid 514479:tid 514599] [remote 159.65.81.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9by_zqsQqnLoCgUjhtLAABDXI"]
[Tue Jul 21 08:45:15.713729 2026] [security2:error] [pid 514479:tid 514564] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/config"] [unique_id "al9by_zqsQqnLoCgUjhtLQABeE8"]
[Tue Jul 21 08:45:15.820766 2026] [security2:error] [pid 514479:tid 514521] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/config"] [unique_id "al9by_zqsQqnLoCgUjhtLwABgCU"]
[Tue Jul 21 08:45:15.855980 2026] [security2:error] [pid 514479:tid 514683] [client 20.197.195.24:63170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/config.php"] [unique_id "al9by_zqsQqnLoCgUjhtMQAAAU8"]
[Tue Jul 21 08:45:15.883158 2026] [security2:error] [pid 514479:tid 514484] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/config"] [unique_id "al9by_zqsQqnLoCgUjhtMwABPwA"]
[Tue Jul 21 08:45:15.926105 2026] [security2:error] [pid 514479:tid 514528] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/config"] [unique_id "al9by_zqsQqnLoCgUjhtNAABdyw"]
[Tue Jul 21 08:45:15.950640 2026] [security2:error] [pid 514479:tid 514503] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/api/config"] [unique_id "al9by_zqsQqnLoCgUjhtNgABHBM"]
[Tue Jul 21 08:45:15.994619 2026] [security2:error] [pid 511108:tid 511352] [client 5.31.193.106:30012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9by4Td5soprXwxAH0JvQAAAHI"]
[Tue Jul 21 08:45:15.998347 2026] [security2:error] [pid 511108:tid 511352] [client 5.31.193.106:30012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9by4Td5soprXwxAH0JvQAAAHI"]
[Tue Jul 21 08:45:16.053147 2026] [security2:error] [pid 514479:tid 514568] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/login"] [unique_id "al9bzPzqsQqnLoCgUjhtOgABGlM"]
[Tue Jul 21 08:45:16.063846 2026] [security2:error] [pid 514479:tid 514678] [client 212.32.76.10:57875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/elementor/includes/template-library/classes/view.php"] [unique_id "al9bzPzqsQqnLoCgUjhtPQAAAUo"]
[Tue Jul 21 08:45:16.069924 2026] [security2:error] [pid 511108:tid 511263] [client 34.90.87.188:60242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9bzITd5soprXwxAH0JvwAAABk"]
[Tue Jul 21 08:45:16.089056 2026] [security2:error] [pid 514479:tid 514542] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/login"] [unique_id "al9bzPzqsQqnLoCgUjhtQQABGjo"]
[Tue Jul 21 08:45:16.376978 2026] [security2:error] [pid 514479:tid 514639] [client 20.197.195.24:63153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/gettest.php"] [unique_id "al9bzPzqsQqnLoCgUjhtRQAAASM"]
[Tue Jul 21 08:45:16.446118 2026] [security2:error] [pid 514479:tid 514586] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/login"] [unique_id "al9bzPzqsQqnLoCgUjhtRgABcWU"]
[Tue Jul 21 08:45:16.475558 2026] [security2:error] [pid 514479:tid 514618] [client 203.25.124.184:22019] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/maint/includes/"] [unique_id "al9bzPzqsQqnLoCgUjhtRwAAAQ4"]
[Tue Jul 21 08:45:16.676555 2026] [security2:error] [pid 514479:tid 514728] [client 20.197.192.193:53617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/2x.php"] [unique_id "al9bzPzqsQqnLoCgUjhtTQAAAXw"]
[Tue Jul 21 08:45:16.679334 2026] [security2:error] [pid 514479:tid 514585] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/login"] [unique_id "al9bzPzqsQqnLoCgUjhtTgABTWQ"]
[Tue Jul 21 08:45:16.814680 2026] [security2:error] [pid 514479:tid 514551] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/login"] [unique_id "al9bzPzqsQqnLoCgUjhtTwABKUI"]
[Tue Jul 21 08:45:16.827767 2026] [security2:error] [pid 514479:tid 514595] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/login"] [unique_id "al9bzPzqsQqnLoCgUjhtUgABhG4"]
[Tue Jul 21 08:45:16.860707 2026] [security2:error] [pid 514479:tid 514573] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/login"] [unique_id "al9bzPzqsQqnLoCgUjhtVAABU1g"]
[Tue Jul 21 08:45:16.903694 2026] [security2:error] [pid 514479:tid 514550] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/login"] [unique_id "al9bzPzqsQqnLoCgUjhtVwABQEE"]
[Tue Jul 21 08:45:16.904351 2026] [security2:error] [pid 514479:tid 514602] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/login"] [unique_id "al9bzPzqsQqnLoCgUjhtWAABQHU"]
[Tue Jul 21 08:45:16.937107 2026] [security2:error] [pid 511108:tid 511289] [client 20.197.192.193:27192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/ez.php"] [unique_id "al9bzITd5soprXwxAH0J1wAAADM"]
[Tue Jul 21 08:45:16.941476 2026] [security2:error] [pid 514479:tid 514552] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/contact"] [unique_id "al9bzPzqsQqnLoCgUjhtWgABUEM"]
[Tue Jul 21 08:45:16.971138 2026] [security2:error] [pid 511108:tid 511314] [client 34.90.87.188:55110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9bzITd5soprXwxAH0J2AAAAEw"]
[Tue Jul 21 08:45:17.166637 2026] [security2:error] [pid 514479:tid 514718] [client 203.25.124.58:53177] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/network/theme-install-function.php"] [unique_id "al9bzfzqsQqnLoCgUjhtXwAAAXI"]
[Tue Jul 21 08:45:17.174275 2026] [security2:error] [pid 514479:tid 514661] [client 20.197.195.24:63217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/min.php"] [unique_id "al9bzfzqsQqnLoCgUjhtYAAAATk"]
[Tue Jul 21 08:45:17.317752 2026] [security2:error] [pid 511108:tid 511321] [client 20.197.192.193:27150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/fz.php"] [unique_id "al9bzYTd5soprXwxAH0J4AAAAFM"]
[Tue Jul 21 08:45:17.323382 2026] [security2:error] [pid 511108:tid 511253] [client 74.7.244.9:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dracrislaineoliveira.com.br"] [uri "/index.php"] [unique_id "al9bzITd5soprXwxAH0J1gAAAA8"]
[Tue Jul 21 08:45:17.324186 2026] [security2:error] [pid 514479:tid 514689] [client 74.7.244.9:36094] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "dracrislaineoliveira.com.br"] [uri "/robots.txt"] [unique_id "al9bzPzqsQqnLoCgUjhtVgABVTk"]
[Tue Jul 21 08:45:17.340360 2026] [security2:error] [pid 511108:tid 511288] [client 69.48.229.91:44854] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "startonesite.com.br"] [uri "/"] [unique_id "al9bzYTd5soprXwxAH0J4QAAADI"]
[Tue Jul 21 08:45:17.455404 2026] [security2:error] [pid 514479:tid 514691] [client 34.90.87.188:54876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9bzfzqsQqnLoCgUjhtZgAAAVc"]
[Tue Jul 21 08:45:17.508703 2026] [security2:error] [pid 514479:tid 514538] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/contact"] [unique_id "al9bzfzqsQqnLoCgUjhtaAABbjY"]
[Tue Jul 21 08:45:17.520806 2026] [security2:error] [pid 511108:tid 511227] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bzYTd5soprXwxAH0J5QAAMXY"]
[Tue Jul 21 08:45:17.521017 2026] [security2:error] [pid 511108:tid 511287] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9bzYTd5soprXwxAH0J5QAAMXY"]
[Tue Jul 21 08:45:17.522781 2026] [security2:error] [pid 514479:tid 514628] [client 20.197.195.24:49930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/dvjul.php"] [unique_id "al9bzfzqsQqnLoCgUjhtaQAAARg"]
[Tue Jul 21 08:45:17.609396 2026] [security2:error] [pid 514479:tid 514502] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/contact"] [unique_id "al9bzfzqsQqnLoCgUjhtawABbhI"]
[Tue Jul 21 08:45:17.690633 2026] [security2:error] [pid 511108:tid 511355] [client 5.38.115.39:53610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bzYTd5soprXwxAH0J7AAAAHU"]
[Tue Jul 21 08:45:17.690807 2026] [security2:error] [pid 511108:tid 511355] [client 5.38.115.39:53610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9bzYTd5soprXwxAH0J7AAAAHU"]
[Tue Jul 21 08:45:17.703851 2026] [security2:error] [pid 514479:tid 514540] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/contact"] [unique_id "al9bzfzqsQqnLoCgUjhtbwABYDg"]
[Tue Jul 21 08:45:17.739235 2026] [security2:error] [pid 514479:tid 514570] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/contact"] [unique_id "al9bzfzqsQqnLoCgUjhtcAABYFU"]
[Tue Jul 21 08:45:17.783296 2026] [security2:error] [pid 514479:tid 514591] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/contact"] [unique_id "al9bzfzqsQqnLoCgUjhtcQABYGo"]
[Tue Jul 21 08:45:17.797650 2026] [security2:error] [pid 511108:tid 511323] [client 20.197.195.24:63135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/biufile.php"] [unique_id "al9bzYTd5soprXwxAH0J7gAAAFU"]
[Tue Jul 21 08:45:17.820435 2026] [security2:error] [pid 514479:tid 514507] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/contact"] [unique_id "al9bzfzqsQqnLoCgUjhtdAABDRc"]
[Tue Jul 21 08:45:17.831529 2026] [security2:error] [pid 514479:tid 514517] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/contact"] [unique_id "al9bzfzqsQqnLoCgUjhtdQABeCE"]
[Tue Jul 21 08:45:17.867112 2026] [access_compat:error] [pid 514479:tid 514656] [client 162.241.63.68:15792] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:45:18.061958 2026] [security2:error] [pid 511108:tid 511243] [client 203.25.124.53:43005] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/shadow-bot.php"] [unique_id "al9bzoTd5soprXwxAH0J9AAAAAU"]
[Tue Jul 21 08:45:18.072138 2026] [security2:error] [pid 514479:tid 514632] [client 203.25.124.6:65373] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/comment-date/"] [unique_id "al9bzvzqsQqnLoCgUjhteAAAARw"]
[Tue Jul 21 08:45:18.089665 2026] [security2:error] [pid 514479:tid 514603] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/contact"] [unique_id "al9bzvzqsQqnLoCgUjhtegABdnY"]
[Tue Jul 21 08:45:18.188254 2026] [security2:error] [pid 514479:tid 514694] [client 20.197.195.24:63220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/av.php"] [unique_id "al9bzvzqsQqnLoCgUjhtfAAAAVo"]
[Tue Jul 21 08:45:18.279095 2026] [security2:error] [pid 511108:tid 511258] [client 34.90.87.188:56682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "praticarjuntos.empacta.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9bzoTd5soprXwxAH0J9gAAABQ"]
[Tue Jul 21 08:45:18.376463 2026] [security2:error] [pid 511108:tid 511296] [client 113.22.144.139:56128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bzoTd5soprXwxAH0J_AAAADo"]
[Tue Jul 21 08:45:18.377237 2026] [security2:error] [pid 511108:tid 511296] [client 113.22.144.139:56128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bzoTd5soprXwxAH0J_AAAADo"]
[Tue Jul 21 08:45:18.384350 2026] [security2:error] [pid 514479:tid 514720] [client 20.197.192.193:27167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/la.php"] [unique_id "al9bzvzqsQqnLoCgUjhtfQAAAXQ"]
[Tue Jul 21 08:45:18.437724 2026] [security2:error] [pid 514479:tid 514486] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/a2a"] [unique_id "al9bzvzqsQqnLoCgUjhtfwABbwI"]
[Tue Jul 21 08:45:18.444429 2026] [security2:error] [pid 514479:tid 514697] [client 20.197.195.24:63155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/coffexium.php"] [unique_id "al9bzvzqsQqnLoCgUjhtgAAAAV0"]
[Tue Jul 21 08:45:18.538038 2026] [security2:error] [pid 514479:tid 514593] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bzvzqsQqnLoCgUjhtggABSmw"]
[Tue Jul 21 08:45:18.538194 2026] [security2:error] [pid 514479:tid 514678] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9bzvzqsQqnLoCgUjhtggABSmw"]
[Tue Jul 21 08:45:18.603198 2026] [security2:error] [pid 511108:tid 511269] [client 114.119.129.4:56651] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.domuscondominios.com.br"] [uri "/sobre"] [unique_id "al9bzoTd5soprXwxAH0KAgAAAB8"], referer: https://www.domuscondominios.com.br/sobre
[Tue Jul 21 08:45:18.700580 2026] [security2:error] [pid 511108:tid 511336] [client 20.197.195.24:63207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/core.php"] [unique_id "al9bzoTd5soprXwxAH0KBwAAAGI"]
[Tue Jul 21 08:45:18.711960 2026] [security2:error] [pid 514479:tid 514576] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/a2a"] [unique_id "al9bzvzqsQqnLoCgUjhtiAABMls"]
[Tue Jul 21 08:45:18.768837 2026] [security2:error] [pid 514479:tid 514561] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/a2a"] [unique_id "al9bzvzqsQqnLoCgUjhtigABMkw"]
[Tue Jul 21 08:45:18.857205 2026] [security2:error] [pid 514479:tid 514731] [client 20.197.195.24:63133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/als.php"] [unique_id "al9bzvzqsQqnLoCgUjhtjwAAAX8"]
[Tue Jul 21 08:45:18.862278 2026] [security2:error] [pid 511108:tid 511301] [client 203.25.124.57:27457] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/shadow-bot.php"] [unique_id "al9bzoTd5soprXwxAH0KCAAAAD8"]
[Tue Jul 21 08:45:18.878514 2026] [security2:error] [pid 514479:tid 514692] [client 203.25.124.11:34329] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "al9bzvzqsQqnLoCgUjhtkQAAAVg"]
[Tue Jul 21 08:45:18.949273 2026] [security2:error] [pid 511108:tid 511280] [client 69.48.229.91:44860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "startonesite.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9bzoTd5soprXwxAH0KDAAAACo"]
[Tue Jul 21 08:45:18.982510 2026] [security2:error] [pid 514479:tid 514622] [client 114.198.138.124:50925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9bzvzqsQqnLoCgUjhtkwAAARI"]
[Tue Jul 21 08:45:18.982665 2026] [security2:error] [pid 514479:tid 514622] [client 114.198.138.124:50925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9bzvzqsQqnLoCgUjhtkwAAARI"]
[Tue Jul 21 08:45:19.065434 2026] [security2:error] [pid 511108:tid 511292] [client 20.197.195.24:63218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/simple.php"] [unique_id "al9bz4Td5soprXwxAH0KDQAAADY"]
[Tue Jul 21 08:45:19.074714 2026] [security2:error] [pid 514479:tid 514537] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/a2a"] [unique_id "al9bz_zqsQqnLoCgUjhtlAABgjU"]
[Tue Jul 21 08:45:19.248000 2026] [security2:error] [pid 514479:tid 514544] [remote 5.252.52.249:53220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tryhealth.shop"] [uri "/wp-login.php"] [unique_id "al9bz_zqsQqnLoCgUjhtlwABazw"]
[Tue Jul 21 08:45:19.250993 2026] [security2:error] [pid 514479:tid 514645] [client 20.197.195.24:63221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/init.php"] [unique_id "al9bz_zqsQqnLoCgUjhtmAAAASk"]
[Tue Jul 21 08:45:19.276978 2026] [security2:error] [pid 514479:tid 514496] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/a2a"] [unique_id "al9bz_zqsQqnLoCgUjhtmQABCww"]
[Tue Jul 21 08:45:19.407019 2026] [security2:error] [pid 511108:tid 511361] [client 20.197.195.24:63195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/fpwch.php"] [unique_id "al9bz4Td5soprXwxAH0KEQAAAHs"]
[Tue Jul 21 08:45:19.449954 2026] [security2:error] [pid 514479:tid 514569] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/a2a"] [unique_id "al9bz_zqsQqnLoCgUjhtnAABQFQ"]
[Tue Jul 21 08:45:19.490830 2026] [security2:error] [pid 514479:tid 514610] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/a2a"] [unique_id "al9bz_zqsQqnLoCgUjhtnQABIn0"]
[Tue Jul 21 08:45:19.495966 2026] [security2:error] [pid 514479:tid 514704] [client 195.49.128.211:51689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bz_zqsQqnLoCgUjhtngAAAWQ"]
[Tue Jul 21 08:45:19.496106 2026] [security2:error] [pid 514479:tid 514704] [client 195.49.128.211:51689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9bz_zqsQqnLoCgUjhtngAAAWQ"]
[Tue Jul 21 08:45:19.504474 2026] [security2:error] [pid 514479:tid 514637] [client 103.59.206.240:31427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bz_zqsQqnLoCgUjhtnwAAASE"]
[Tue Jul 21 08:45:19.504609 2026] [security2:error] [pid 514479:tid 514637] [client 103.59.206.240:31427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bz_zqsQqnLoCgUjhtnwAAASE"]
[Tue Jul 21 08:45:19.547915 2026] [security2:error] [pid 514479:tid 514501] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/a2a"] [unique_id "al9bz_zqsQqnLoCgUjhtoAABPRE"]
[Tue Jul 21 08:45:19.615990 2026] [security2:error] [pid 514479:tid 514554] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/a2a"] [unique_id "al9bz_zqsQqnLoCgUjhtogABX0U"]
[Tue Jul 21 08:45:19.735827 2026] [security2:error] [pid 514479:tid 514588] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/mcp"] [unique_id "al9bz_zqsQqnLoCgUjhtpQABK2c"]
[Tue Jul 21 08:45:19.736016 2026] [security2:error] [pid 511108:tid 511297] [client 20.197.195.24:63190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/domvf.php"] [unique_id "al9bz4Td5soprXwxAH0KHAAAADs"]
[Tue Jul 21 08:45:19.849718 2026] [security2:error] [pid 511108:tid 511320] [client 20.197.195.24:63165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp.php"] [unique_id "al9bz4Td5soprXwxAH0KHQAAAFI"]
[Tue Jul 21 08:45:19.872654 2026] [security2:error] [pid 514479:tid 514689] [client 203.25.124.198:38575] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/widgets/chosen.php"] [unique_id "al9bz_zqsQqnLoCgUjhtqwAAAVU"]
[Tue Jul 21 08:45:19.893802 2026] [security2:error] [pid 514479:tid 514529] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/mcp"] [unique_id "al9bz_zqsQqnLoCgUjhtrQABKy0"]
[Tue Jul 21 08:45:19.904155 2026] [security2:error] [pid 514479:tid 514545] [remote 74.7.227.50:58940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dracrislaineoliveira.com.br"] [uri "/xmlrpc.php"] [unique_id "al9bz_zqsQqnLoCgUjhtoQABUD0"], referer: https://dracrislaineoliveira.com.br/
[Tue Jul 21 08:45:19.909400 2026] [security2:error] [pid 514479:tid 514739] [client 20.197.195.24:63122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/class.php"] [unique_id "al9bz_zqsQqnLoCgUjhtrgAAAYc"]
[Tue Jul 21 08:45:20.083626 2026] [security2:error] [pid 514479:tid 514700] [client 20.197.195.24:63139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/echkm.php"] [unique_id "al9b0PzqsQqnLoCgUjhtuAAAAWA"]
[Tue Jul 21 08:45:20.263354 2026] [security2:error] [pid 511108:tid 511299] [client 203.25.124.55:27295] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/load.php"] [unique_id "al9b0ITd5soprXwxAH0KJgAAAD0"]
[Tue Jul 21 08:45:20.279832 2026] [security2:error] [pid 514479:tid 514555] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/mcp"] [unique_id "al9b0PzqsQqnLoCgUjhtugABMUY"]
[Tue Jul 21 08:45:20.577133 2026] [security2:error] [pid 514479:tid 514715] [client 203.25.124.11:43685] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/theme-check/main.php"] [unique_id "al9b0PzqsQqnLoCgUjhtxwAAAW8"]
[Tue Jul 21 08:45:20.656444 2026] [security2:error] [pid 514479:tid 514534] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/mcp"] [unique_id "al9b0PzqsQqnLoCgUjhtyQABhjI"]
[Tue Jul 21 08:45:20.675527 2026] [security2:error] [pid 511108:tid 511298] [client 20.197.195.24:49994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/lib.php"] [unique_id "al9b0ITd5soprXwxAH0KLAAAADw"]
[Tue Jul 21 08:45:20.778122 2026] [security2:error] [pid 514479:tid 514511] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/mcp"] [unique_id "al9b0PzqsQqnLoCgUjhtzgABPhs"]
[Tue Jul 21 08:45:20.791990 2026] [security2:error] [pid 514479:tid 514703] [client 20.197.192.193:27177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/nhvoanpl.php"] [unique_id "al9b0PzqsQqnLoCgUjht0AAAAWM"]
[Tue Jul 21 08:45:20.818535 2026] [security2:error] [pid 514479:tid 514597] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/mcp"] [unique_id "al9b0PzqsQqnLoCgUjht0QABPHA"]
[Tue Jul 21 08:45:20.920398 2026] [security2:error] [pid 514479:tid 514734] [client 20.197.195.24:63115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/login.php"] [unique_id "al9b0PzqsQqnLoCgUjht0gAAAYI"]
[Tue Jul 21 08:45:20.921942 2026] [security2:error] [pid 514479:tid 514488] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/mcp"] [unique_id "al9b0PzqsQqnLoCgUjht0wABfAQ"]
[Tue Jul 21 08:45:20.961913 2026] [security2:error] [pid 514479:tid 514641] [client 198.44.157.34:45460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9b0PzqsQqnLoCgUjht1AAAASU"]
[Tue Jul 21 08:45:20.962026 2026] [security2:error] [pid 514479:tid 514641] [client 198.44.157.34:45460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9b0PzqsQqnLoCgUjht1AAAASU"]
[Tue Jul 21 08:45:20.968376 2026] [security2:error] [pid 514479:tid 514523] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/mcp"] [unique_id "al9b0PzqsQqnLoCgUjht1QABeyc"]
[Tue Jul 21 08:45:21.001450 2026] [security2:error] [pid 514479:tid 514654] [client 49.144.66.253:32805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9b0fzqsQqnLoCgUjht2QAAATI"]
[Tue Jul 21 08:45:21.001546 2026] [security2:error] [pid 514479:tid 514654] [client 49.144.66.253:32805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9b0fzqsQqnLoCgUjht2QAAATI"]
[Tue Jul 21 08:45:21.085271 2026] [security2:error] [pid 514479:tid 514504] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/mcp"] [unique_id "al9b0fzqsQqnLoCgUjht2gABNxQ"]
[Tue Jul 21 08:45:21.136626 2026] [security2:error] [pid 514479:tid 514698] [client 20.197.195.24:63145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/a2.php"] [unique_id "al9b0fzqsQqnLoCgUjht3QAAAV4"]
[Tue Jul 21 08:45:21.197423 2026] [security2:error] [pid 514479:tid 514661] [client 69.171.230.116:55558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9b0PzqsQqnLoCgUjhttgAAATk"]
[Tue Jul 21 08:45:21.235246 2026] [security2:error] [pid 514479:tid 514596] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9b0fzqsQqnLoCgUjht3wABOG8"]
[Tue Jul 21 08:45:21.322482 2026] [security2:error] [pid 514479:tid 514643] [client 20.197.195.24:8396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/d61.php"] [unique_id "al9b0fzqsQqnLoCgUjht4QAAASc"]
[Tue Jul 21 08:45:21.366160 2026] [security2:error] [pid 514479:tid 514713] [client 212.32.76.2:45983] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/wp-activate.php"] [unique_id "al9b0fzqsQqnLoCgUjht4gAAAW0"]
[Tue Jul 21 08:45:21.380635 2026] [security2:error] [pid 514479:tid 514689] [client 203.25.124.10:54537] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/css.php"] [unique_id "al9b0fzqsQqnLoCgUjht5AAAAVU"]
[Tue Jul 21 08:45:21.583053 2026] [security2:error] [pid 514479:tid 514696] [client 195.49.128.211:59463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9b0fzqsQqnLoCgUjht6QAAAVw"]
[Tue Jul 21 08:45:21.583226 2026] [security2:error] [pid 514479:tid 514696] [client 195.49.128.211:59463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9b0fzqsQqnLoCgUjht6QAAAVw"]
[Tue Jul 21 08:45:21.654327 2026] [security2:error] [pid 514479:tid 514657] [client 20.197.195.24:50031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/info.php"] [unique_id "al9b0fzqsQqnLoCgUjht6wAAATU"]
[Tue Jul 21 08:45:21.744696 2026] [security2:error] [pid 514479:tid 514714] [client 64.42.179.43:52718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9b0fzqsQqnLoCgUjht7AAAAW4"]
[Tue Jul 21 08:45:21.744799 2026] [security2:error] [pid 514479:tid 514714] [client 64.42.179.43:52718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9b0fzqsQqnLoCgUjht7AAAAW4"]
[Tue Jul 21 08:45:21.826140 2026] [security2:error] [pid 511108:tid 511324] [client 59.95.197.55:56691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b0YTd5soprXwxAH0KPgAAAFY"]
[Tue Jul 21 08:45:21.826325 2026] [security2:error] [pid 511108:tid 511324] [client 59.95.197.55:56691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b0YTd5soprXwxAH0KPgAAAFY"]
[Tue Jul 21 08:45:21.963065 2026] [security2:error] [pid 514479:tid 514508] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9b0fzqsQqnLoCgUjht8AABcBg"]
[Tue Jul 21 08:45:22.075608 2026] [security2:error] [pid 514479:tid 514575] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9b0vzqsQqnLoCgUjht9QABS1o"]
[Tue Jul 21 08:45:22.277569 2026] [security2:error] [pid 514479:tid 514566] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9b0vzqsQqnLoCgUjht-AABflE"]
[Tue Jul 21 08:45:22.344474 2026] [security2:error] [pid 511108:tid 511353] [client 20.197.195.24:49997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/11.php"] [unique_id "al9b0oTd5soprXwxAH0KRwAAAHM"]
[Tue Jul 21 08:45:22.462828 2026] [security2:error] [pid 514479:tid 514513] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9b0vzqsQqnLoCgUjht-gABdx0"]
[Tue Jul 21 08:45:22.463585 2026] [security2:error] [pid 514479:tid 514556] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9b0vzqsQqnLoCgUjht-wABdkc"]
[Tue Jul 21 08:45:22.464875 2026] [security2:error] [pid 514479:tid 514553] [remote 74.7.227.50:58940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dracrislaineoliveira.com.br"] [uri "/wp-login.php"] [unique_id "al9b0vzqsQqnLoCgUjht_AABiUQ"], referer: https://dracrislaineoliveira.com.br/
[Tue Jul 21 08:45:22.466009 2026] [security2:error] [pid 514479:tid 514629] [client 203.25.124.69:38705] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/module.php"] [unique_id "al9b0vzqsQqnLoCgUjht_QAAARk"]
[Tue Jul 21 08:45:22.481189 2026] [security2:error] [pid 514479:tid 514499] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9b0vzqsQqnLoCgUjht_gABWg8"]
[Tue Jul 21 08:45:22.564306 2026] [security2:error] [pid 514479:tid 514590] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9b0vzqsQqnLoCgUjht_wABQmk"]
[Tue Jul 21 08:45:22.591729 2026] [security2:error] [pid 514479:tid 514685] [client 122.176.100.127:58280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9b0vzqsQqnLoCgUjhuAQAAAVE"]
[Tue Jul 21 08:45:22.591913 2026] [security2:error] [pid 514479:tid 514685] [client 122.176.100.127:58280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9b0vzqsQqnLoCgUjhuAQAAAVE"]
[Tue Jul 21 08:45:22.637330 2026] [autoindex:error] [pid 511108:tid 511125] [remote 20.226.32.81:0] AH01276: Cannot serve directory /home2/techkn33/marcomarafon.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:45:22.759334 2026] [security2:error] [pid 514479:tid 514557] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9b0vzqsQqnLoCgUjhuBAABXUg"]
[Tue Jul 21 08:45:22.981789 2026] [security2:error] [pid 514479:tid 514680] [client 203.25.124.246:37363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/admin.php"] [unique_id "al9b0vzqsQqnLoCgUjhuBgAAAUw"]
[Tue Jul 21 08:45:22.998523 2026] [security2:error] [pid 511108:tid 511363] [client 20.197.195.24:50043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/v2.php"] [unique_id "al9b0oTd5soprXwxAH0KUQAAAH0"]
[Tue Jul 21 08:45:23.669191 2026] [autoindex:error] [pid 511108:tid 511277] [client 205.210.31.56:62514] AH01276: Cannot serve directory /home2/jefe0292/robopsf3.agendaclique.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:45:23.756424 2026] [security2:error] [pid 514479:tid 514527] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9b0_zqsQqnLoCgUjhuFQABVis"]
[Tue Jul 21 08:45:23.762859 2026] [security2:error] [pid 514479:tid 514703] [client 212.32.76.9:56351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "al9b0_zqsQqnLoCgUjhuFgAAAWM"]
[Tue Jul 21 08:45:23.878306 2026] [security2:error] [pid 514479:tid 514518] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9b0_zqsQqnLoCgUjhuGQABIyI"]
[Tue Jul 21 08:45:23.878456 2026] [security2:error] [pid 514479:tid 514639] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9b0_zqsQqnLoCgUjhuGQABIyI"]
[Tue Jul 21 08:45:23.894626 2026] [security2:error] [pid 514479:tid 514678] [client 41.89.234.2:60153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b0_zqsQqnLoCgUjhuGwAAAUo"]
[Tue Jul 21 08:45:23.894961 2026] [security2:error] [pid 514479:tid 514678] [client 41.89.234.2:60153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b0_zqsQqnLoCgUjhuGwAAAUo"]
[Tue Jul 21 08:45:23.897819 2026] [security2:error] [pid 514479:tid 514681] [client 20.197.195.24:49932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/panel.php"] [unique_id "al9b0_zqsQqnLoCgUjhuHAAAAU0"]
[Tue Jul 21 08:45:23.971018 2026] [security2:error] [pid 511108:tid 511311] [client 203.25.124.209:58475] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/2025/"] [unique_id "al9b04Td5soprXwxAH0KYQAAAEk"]
[Tue Jul 21 08:45:24.531383 2026] [security2:error] [pid 511108:tid 511287] [client 64.42.179.43:52710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9b1ITd5soprXwxAH0KagAAADE"]
[Tue Jul 21 08:45:24.531481 2026] [security2:error] [pid 511108:tid 511287] [client 64.42.179.43:52710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9b1ITd5soprXwxAH0KagAAADE"]
[Tue Jul 21 08:45:24.539263 2026] [security2:error] [pid 514479:tid 514558] [remote 103.215.74.26:49678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "auriculo.liranesuliano.com"] [uri "/"] [unique_id "al9b1PzqsQqnLoCgUjhuIgABPUk"]
[Tue Jul 21 08:45:24.670126 2026] [security2:error] [pid 511108:tid 511304] [client 212.32.76.59:31617] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/comment-content/"] [unique_id "al9b1ITd5soprXwxAH0KbgAAAEI"]
[Tue Jul 21 08:45:24.768060 2026] [security2:error] [pid 511108:tid 511202] [remote 20.153.140.50:42230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "governess.com.br"] [uri "/wp-login.php"] [unique_id "al9b1ITd5soprXwxAH0KbwAAD10"]
[Tue Jul 21 08:45:24.961135 2026] [security2:error] [pid 511108:tid 511300] [client 20.197.195.24:63112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/dex.php"] [unique_id "al9b1ITd5soprXwxAH0KgAAAAD4"]
[Tue Jul 21 08:45:24.965636 2026] [security2:error] [pid 514479:tid 514643] [client 203.25.124.42:37147] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/system.php"] [unique_id "al9b1PzqsQqnLoCgUjhuJQAAASc"]
[Tue Jul 21 08:45:24.983042 2026] [security2:error] [pid 514479:tid 514652] [client 65.21.113.253:44888] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9b1PzqsQqnLoCgUjhuIwAAATA"]
[Tue Jul 21 08:45:25.142736 2026] [security2:error] [pid 514479:tid 514699] [client 202.179.75.202:48998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9b1fzqsQqnLoCgUjhuKQAAAV8"]
[Tue Jul 21 08:45:25.142861 2026] [security2:error] [pid 514479:tid 514699] [client 202.179.75.202:48998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9b1fzqsQqnLoCgUjhuKQAAAV8"]
[Tue Jul 21 08:45:25.481295 2026] [security2:error] [pid 511108:tid 511269] [client 212.32.76.62:55317] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/images/"] [unique_id "al9b1YTd5soprXwxAH0KhwAAAB8"]
[Tue Jul 21 08:45:25.530424 2026] [security2:error] [pid 511108:tid 511275] [client 152.59.181.104:57884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9b1YTd5soprXwxAH0KiAAAACU"]
[Tue Jul 21 08:45:25.530603 2026] [security2:error] [pid 511108:tid 511275] [client 152.59.181.104:57884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9b1YTd5soprXwxAH0KiAAAACU"]
[Tue Jul 21 08:45:25.634217 2026] [security2:error] [pid 514479:tid 514710] [client 20.197.195.24:49986] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "drjoaoguedes.com"] [uri "/1.php"] [unique_id "al9b1fzqsQqnLoCgUjhuLQAAAWo"]
[Tue Jul 21 08:45:25.634326 2026] [security2:error] [pid 514479:tid 514710] [client 20.197.195.24:49986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/1.php"] [unique_id "al9b1fzqsQqnLoCgUjhuLQAAAWo"]
[Tue Jul 21 08:45:25.815173 2026] [security2:error] [pid 514479:tid 514621] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9b1fzqsQqnLoCgUjhuLwABEVI"]
[Tue Jul 21 08:45:25.863388 2026] [security2:error] [pid 511108:tid 511348] [client 203.25.124.213:35985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/wp-links-opml.php"] [unique_id "al9b1YTd5soprXwxAH0KjQAAAG4"]
[Tue Jul 21 08:45:26.090290 2026] [security2:error] [pid 514479:tid 514658] [client 157.85.206.185:9404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.206.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.brwmarcas.com.br"] [uri "/gestaolancamentos/wp-login.php"] [unique_id "al9b1vzqsQqnLoCgUjhuMgAAATY"]
[Tue Jul 21 08:45:26.177773 2026] [security2:error] [pid 511108:tid 511214] [remote 184.168.124.4:44490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.124.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-login.php"] [unique_id "al9b1oTd5soprXwxAH0KkgAAeGk"]
[Tue Jul 21 08:45:26.272679 2026] [security2:error] [pid 511108:tid 511272] [client 203.25.124.189:23391] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/options.php"] [unique_id "al9b1oTd5soprXwxAH0KmgAAACI"]
[Tue Jul 21 08:45:26.410097 2026] [security2:error] [pid 511108:tid 511314] [client 20.197.195.24:63196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/ms.php"] [unique_id "al9b1oTd5soprXwxAH0KngAAAEw"]
[Tue Jul 21 08:45:26.438784 2026] [security2:error] [pid 511108:tid 511260] [client 20.197.192.193:27096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/inso.php"] [unique_id "al9b1oTd5soprXwxAH0KoAAAABY"]
[Tue Jul 21 08:45:26.644725 2026] [autoindex:error] [pid 511108:tid 511277] [client 20.197.195.24:63113] AH01276: Cannot serve directory /home4/drjoao27/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:45:26.697540 2026] [security2:error] [pid 511108:tid 511305] [client 20.197.195.24:63113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/memberfuns.php"] [unique_id "al9b1oTd5soprXwxAH0KpgAAAEM"]
[Tue Jul 21 08:45:26.971057 2026] [security2:error] [pid 514479:tid 514741] [client 212.32.76.13:45671] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "al9b1vzqsQqnLoCgUjhuOAAAAYk"]
[Tue Jul 21 08:45:27.173340 2026] [security2:error] [pid 514479:tid 514686] [client 203.25.124.202:31921] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/chosen.php"] [unique_id "al9b1_zqsQqnLoCgUjhuOwAAAVI"]
[Tue Jul 21 08:45:27.308115 2026] [security2:error] [pid 514479:tid 514738] [client 20.197.195.24:49946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/0.php"] [unique_id "al9b1_zqsQqnLoCgUjhuPQAAAYY"]
[Tue Jul 21 08:45:27.404799 2026] [security2:error] [pid 514479:tid 514737] [client 168.167.81.163:61491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9b1_zqsQqnLoCgUjhuQgAAAYU"]
[Tue Jul 21 08:45:27.404921 2026] [security2:error] [pid 514479:tid 514737] [client 168.167.81.163:61491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9b1_zqsQqnLoCgUjhuQgAAAYU"]
[Tue Jul 21 08:45:27.975856 2026] [security2:error] [pid 514479:tid 514645] [client 203.25.124.191:34793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/images/as.php"] [unique_id "al9b1_zqsQqnLoCgUjhuTQAAASk"]
[Tue Jul 21 08:45:28.075507 2026] [security2:error] [pid 511108:tid 511189] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9b2ITd5soprXwxAH0KuQAABVA"]
[Tue Jul 21 08:45:28.075678 2026] [security2:error] [pid 511108:tid 511243] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9b2ITd5soprXwxAH0KuQAABVA"]
[Tue Jul 21 08:45:28.087495 2026] [security2:error] [pid 514479:tid 514641] [client 20.197.195.24:63166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/BDKR28.php"] [unique_id "al9b2PzqsQqnLoCgUjhuTgAAASU"]
[Tue Jul 21 08:45:28.358972 2026] [security2:error] [pid 511108:tid 511300] [client 212.32.76.12:24869] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugin-install.php"] [unique_id "al9b2ITd5soprXwxAH0KvgAAAD4"]
[Tue Jul 21 08:45:28.375044 2026] [security2:error] [pid 511108:tid 511271] [client 5.38.115.39:36712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9b2ITd5soprXwxAH0KvwAAACE"]
[Tue Jul 21 08:45:28.375592 2026] [security2:error] [pid 511108:tid 511271] [client 5.38.115.39:36712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9b2ITd5soprXwxAH0KvwAAACE"]
[Tue Jul 21 08:45:28.378869 2026] [security2:error] [pid 514479:tid 514706] [client 203.25.124.42:39755] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/"] [unique_id "al9b2PzqsQqnLoCgUjhuUwAAAWY"]
[Tue Jul 21 08:45:28.832261 2026] [security2:error] [pid 511108:tid 511238] [client 157.85.206.185:7732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.206.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.brwmarcas.com.br"] [uri "/gestaolancamentos/wp-login.php"] [unique_id "al9b2ITd5soprXwxAH0KxgAAAAA"]
[Tue Jul 21 08:45:28.870030 2026] [security2:error] [pid 511108:tid 511241] [client 203.25.124.3:32283] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-security.php"] [unique_id "al9b2ITd5soprXwxAH0KxwAAAAM"]
[Tue Jul 21 08:45:29.046738 2026] [security2:error] [pid 511108:tid 511317] [client 20.197.192.193:27162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wpx.php"] [unique_id "al9b2YTd5soprXwxAH0KywAAAE8"]
[Tue Jul 21 08:45:29.102525 2026] [security2:error] [pid 511108:tid 511114] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9b2YTd5soprXwxAH0KzAAAHwU"]
[Tue Jul 21 08:45:29.102664 2026] [security2:error] [pid 511108:tid 511269] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9b2YTd5soprXwxAH0KzAAAHwU"]
[Tue Jul 21 08:45:29.122406 2026] [security2:error] [pid 511108:tid 511348] [client 20.197.195.24:63118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/green1.php"] [unique_id "al9b2YTd5soprXwxAH0KzQAAAG4"]
[Tue Jul 21 08:45:29.142184 2026] [security2:error] [pid 514479:tid 514689] [client 203.25.124.212:61649] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/core.php"] [unique_id "al9b2fzqsQqnLoCgUjhuYAAAAVU"]
[Tue Jul 21 08:45:29.251106 2026] [security2:error] [pid 514479:tid 514643] [client 113.22.144.139:56650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b2fzqsQqnLoCgUjhuYQAAASc"]
[Tue Jul 21 08:45:29.251219 2026] [security2:error] [pid 514479:tid 514643] [client 113.22.144.139:56650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b2fzqsQqnLoCgUjhuYQAAASc"]
[Tue Jul 21 08:45:29.364588 2026] [security2:error] [pid 511108:tid 511292] [client 203.25.124.47:56789] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/includes/class-walker-nav-menu-edit-interpreter.php"] [unique_id "al9b2YTd5soprXwxAH0K1QAAADY"]
[Tue Jul 21 08:45:29.689346 2026] [security2:error] [pid 514479:tid 514623] [client 20.197.192.193:27172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/berlin.php"] [unique_id "al9b2fzqsQqnLoCgUjhuZQAAARM"]
[Tue Jul 21 08:45:29.776794 2026] [security2:error] [pid 511108:tid 511310] [client 20.197.195.24:50045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/nc4.php"] [unique_id "al9b2YTd5soprXwxAH0K2QAAAEg"]
[Tue Jul 21 08:45:29.872549 2026] [security2:error] [pid 511108:tid 511306] [client 203.25.124.207:41947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/system.php"] [unique_id "al9b2YTd5soprXwxAH0K3gAAAEQ"]
[Tue Jul 21 08:45:29.940629 2026] [security2:error] [pid 511108:tid 511330] [client 203.25.124.66:48351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/3PJcpMFsD8B.php"] [unique_id "al9b2YTd5soprXwxAH0K4QAAAFw"]
[Tue Jul 21 08:45:30.033214 2026] [security2:error] [pid 511108:tid 511354] [client 114.198.138.124:51496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9b2oTd5soprXwxAH0K4wAAAHQ"]
[Tue Jul 21 08:45:30.033342 2026] [security2:error] [pid 511108:tid 511354] [client 114.198.138.124:51496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9b2oTd5soprXwxAH0K4wAAAHQ"]
[Tue Jul 21 08:45:30.037088 2026] [security2:error] [pid 514479:tid 514714] [client 65.21.113.253:44888] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9b2fzqsQqnLoCgUjhuZAAAAW4"]
[Tue Jul 21 08:45:30.070920 2026] [security2:error] [pid 514479:tid 514710] [client 103.59.206.240:31486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b2vzqsQqnLoCgUjhuawAAAWo"]
[Tue Jul 21 08:45:30.071083 2026] [security2:error] [pid 514479:tid 514710] [client 103.59.206.240:31486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b2vzqsQqnLoCgUjhuawAAAWo"]
[Tue Jul 21 08:45:30.174906 2026] [security2:error] [pid 514479:tid 514617] [client 195.49.128.211:52300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9b2vzqsQqnLoCgUjhubAAAAQ0"]
[Tue Jul 21 08:45:30.175083 2026] [security2:error] [pid 514479:tid 514617] [client 195.49.128.211:52300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9b2vzqsQqnLoCgUjhubAAAAQ0"]
[Tue Jul 21 08:45:30.452786 2026] [security2:error] [pid 511108:tid 511149] [remote 41.186.86.12:12181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9b2oTd5soprXwxAH0K6wAAOSg"]
[Tue Jul 21 08:45:30.505142 2026] [security2:error] [pid 514479:tid 514725] [client 20.197.195.24:50046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/a1.php"] [unique_id "al9b2vzqsQqnLoCgUjhudQAAAXk"]
[Tue Jul 21 08:45:30.563459 2026] [security2:error] [pid 511108:tid 511276] [client 203.25.124.69:27881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/customize/class-wp-widget-area-customize-control-interpreter.php"] [unique_id "al9b2oTd5soprXwxAH0K7QAAACY"]
[Tue Jul 21 08:45:30.742501 2026] [security2:error] [pid 514479:tid 514692] [client 20.197.195.24:49938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/eee.php"] [unique_id "al9b2vzqsQqnLoCgUjhueAAAAVg"]
[Tue Jul 21 08:45:30.781412 2026] [security2:error] [pid 511108:tid 511254] [client 203.25.124.206:34873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/header.php"] [unique_id "al9b2oTd5soprXwxAH0K8wAAABA"]
[Tue Jul 21 08:45:31.038832 2026] [security2:error] [pid 514479:tid 514654] [client 20.197.195.24:49978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-aothait.php"] [unique_id "al9b2_zqsQqnLoCgUjhuhQAAATI"]
[Tue Jul 21 08:45:31.047172 2026] [security2:error] [pid 514479:tid 514659] [client 203.25.124.68:21873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/admin.php"] [unique_id "al9b2_zqsQqnLoCgUjhuhwAAATc"]
[Tue Jul 21 08:45:31.083493 2026] [security2:error] [pid 511108:tid 511193] [remote 104.207.39.187:58279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.39.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9b2oTd5soprXwxAH0K9gAARVQ"]
[Tue Jul 21 08:45:31.206694 2026] [security2:error] [pid 511108:tid 511252] [client 195.206.105.227:41628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9b24Td5soprXwxAH0K_gAAAA4"]
[Tue Jul 21 08:45:31.206780 2026] [security2:error] [pid 511108:tid 511252] [client 195.206.105.227:41628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9b24Td5soprXwxAH0K_gAAAA4"]
[Tue Jul 21 08:45:31.539694 2026] [security2:error] [pid 514479:tid 514675] [client 20.197.195.24:8399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/config.json.php"] [unique_id "al9b2_zqsQqnLoCgUjhulAAAAUc"]
[Tue Jul 21 08:45:31.682738 2026] [security2:error] [pid 514479:tid 514657] [client 203.25.124.183:38935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/fonts/"] [unique_id "al9b2_zqsQqnLoCgUjhulQAAATU"]
[Tue Jul 21 08:45:31.796871 2026] [security2:error] [pid 511108:tid 511278] [client 49.144.66.253:33195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9b24Td5soprXwxAH0LDQAAACg"]
[Tue Jul 21 08:45:31.797023 2026] [security2:error] [pid 511108:tid 511278] [client 49.144.66.253:33195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9b24Td5soprXwxAH0LDQAAACg"]
[Tue Jul 21 08:45:31.862801 2026] [security2:error] [pid 511108:tid 511245] [client 212.32.76.8:26101] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/ai-client/adapters/admin.php"] [unique_id "al9b24Td5soprXwxAH0LDwAAAAc"]
[Tue Jul 21 08:45:31.937534 2026] [security2:error] [pid 514479:tid 514714] [client 20.197.195.24:49940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9b2_zqsQqnLoCgUjhumwAAAW4"]
[Tue Jul 21 08:45:32.035325 2026] [security2:error] [pid 511108:tid 511301] [client 203.25.124.61:40357] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/goods.php"] [unique_id "al9b3ITd5soprXwxAH0LEwAAAD8"]
[Tue Jul 21 08:45:32.203550 2026] [security2:error] [pid 514479:tid 514658] [client 195.49.128.211:60082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9b3PzqsQqnLoCgUjhupgAAATY"]
[Tue Jul 21 08:45:32.203647 2026] [security2:error] [pid 514479:tid 514658] [client 195.49.128.211:60082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9b3PzqsQqnLoCgUjhupgAAATY"]
[Tue Jul 21 08:45:32.361467 2026] [security2:error] [pid 514479:tid 514735] [client 59.95.197.55:57160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b3PzqsQqnLoCgUjhurAAAAYM"]
[Tue Jul 21 08:45:32.361609 2026] [security2:error] [pid 514479:tid 514735] [client 59.95.197.55:57160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b3PzqsQqnLoCgUjhurAAAAYM"]
[Tue Jul 21 08:45:32.549775 2026] [security2:error] [pid 511108:tid 511357] [client 20.197.195.24:49966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/k2.php"] [unique_id "al9b3ITd5soprXwxAH0LHgAAAHc"]
[Tue Jul 21 08:45:32.774032 2026] [security2:error] [pid 514479:tid 514698] [client 203.25.124.203:38751] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "al9b3PzqsQqnLoCgUjhurwAAAV4"]
[Tue Jul 21 08:45:33.018315 2026] [security2:error] [pid 514479:tid 514627] [client 122.176.100.127:58766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9b3fzqsQqnLoCgUjhuswAAARc"]
[Tue Jul 21 08:45:33.018550 2026] [security2:error] [pid 514479:tid 514627] [client 122.176.100.127:58766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9b3fzqsQqnLoCgUjhuswAAARc"]
[Tue Jul 21 08:45:33.048982 2026] [security2:error] [pid 514479:tid 514673] [client 20.197.195.24:49984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/uiuvs58l.php"] [unique_id "al9b3fzqsQqnLoCgUjhutQAAAUU"]
[Tue Jul 21 08:45:33.094520 2026] [security2:error] [pid 514479:tid 514713] [client 61.1.167.83:62080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b3fzqsQqnLoCgUjhutwAAAW0"]
[Tue Jul 21 08:45:33.094649 2026] [security2:error] [pid 514479:tid 514713] [client 61.1.167.83:62080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b3fzqsQqnLoCgUjhutwAAAW0"]
[Tue Jul 21 08:45:33.143048 2026] [security2:error] [pid 514479:tid 514631] [client 203.25.124.54:24999] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/edit-tags.php"] [unique_id "al9b3fzqsQqnLoCgUjhuuwAAARs"]
[Tue Jul 21 08:45:33.163388 2026] [security2:error] [pid 514479:tid 514684] [client 203.25.124.74:56395] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/widget-group/index.php"] [unique_id "al9b3fzqsQqnLoCgUjhuvQAAAVA"]
[Tue Jul 21 08:45:33.358063 2026] [security2:error] [pid 514479:tid 514546] [remote 104.207.44.115:11557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.44.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9b3fzqsQqnLoCgUjhuvwABIT4"]
[Tue Jul 21 08:45:33.496056 2026] [security2:error] [pid 511108:tid 511287] [client 20.197.195.24:49933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/40p9ixjd.php"] [unique_id "al9b3YTd5soprXwxAH0LLQAAADE"]
[Tue Jul 21 08:45:33.570321 2026] [security2:error] [pid 514479:tid 514688] [client 203.25.124.254:41257] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/a.php"] [unique_id "al9b3fzqsQqnLoCgUjhuwwAAAVQ"]
[Tue Jul 21 08:45:33.891467 2026] [security2:error] [pid 511108:tid 511294] [client 20.197.195.24:63131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9b3YTd5soprXwxAH0LNwAAADg"]
[Tue Jul 21 08:45:33.962579 2026] [security2:error] [pid 514479:tid 514704] [client 20.197.195.24:8409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/for.php"] [unique_id "al9b3fzqsQqnLoCgUjhu1wAAAWQ"]
[Tue Jul 21 08:45:34.012479 2026] [security2:error] [pid 511108:tid 511319] [client 20.197.195.24:63140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/raw.php"] [unique_id "al9b3oTd5soprXwxAH0LOQAAAFE"]
[Tue Jul 21 08:45:34.061733 2026] [security2:error] [pid 514479:tid 514588] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9b3vzqsQqnLoCgUjhu3gABQ2c"]
[Tue Jul 21 08:45:34.061956 2026] [security2:error] [pid 514479:tid 514671] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9b3vzqsQqnLoCgUjhu3gABQ2c"]
[Tue Jul 21 08:45:34.164137 2026] [security2:error] [pid 514479:tid 514715] [client 203.25.124.55:55721] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/preformatted/index.php"] [unique_id "al9b3vzqsQqnLoCgUjhu4AAAAW8"]
[Tue Jul 21 08:45:34.358039 2026] [security2:error] [pid 514479:tid 514701] [client 195.206.105.227:41630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9b3vzqsQqnLoCgUjhu6AAAAWE"]
[Tue Jul 21 08:45:34.358129 2026] [security2:error] [pid 514479:tid 514701] [client 195.206.105.227:41630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9b3vzqsQqnLoCgUjhu6AAAAWE"]
[Tue Jul 21 08:45:34.369438 2026] [security2:error] [pid 511108:tid 511275] [client 203.25.124.180:50187] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/about.php"] [unique_id "al9b3oTd5soprXwxAH0LQwAAACU"]
[Tue Jul 21 08:45:35.156184 2026] [security2:error] [pid 514479:tid 514659] [client 198.44.157.34:37262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9b3_zqsQqnLoCgUjhu9AAAATc"]
[Tue Jul 21 08:45:35.156279 2026] [security2:error] [pid 514479:tid 514659] [client 198.44.157.34:37262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9b3_zqsQqnLoCgUjhu9AAAATc"]
[Tue Jul 21 08:45:35.320756 2026] [security2:error] [pid 514479:tid 514683] [client 65.21.113.253:44888] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9b3vzqsQqnLoCgUjhu7gAAAU8"]
[Tue Jul 21 08:45:35.376522 2026] [security2:error] [pid 514479:tid 514647] [client 203.25.124.7:20099] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Requests/src/Exception/Transport/"] [unique_id "al9b3_zqsQqnLoCgUjhu-QAAASs"]
[Tue Jul 21 08:45:35.634534 2026] [security2:error] [pid 514479:tid 514692] [client 212.32.76.4:22799] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/filemanager.php"] [unique_id "al9b3_zqsQqnLoCgUjhvSAAAAVg"]
[Tue Jul 21 08:45:35.974437 2026] [proxy:error] [pid 514479:tid 514691] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:35.974522 2026] [proxy_http:error] [pid 514479:tid 514691] [client 167.71.182.69:51872] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:35.975621 2026] [proxy:error] [pid 514479:tid 514691] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:35.975664 2026] [proxy_http:error] [pid 514479:tid 514691] [client 167.71.182.69:51872] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:36.055220 2026] [security2:error] [pid 514479:tid 514625] [client 202.179.75.202:50364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9b4PzqsQqnLoCgUjhvcAAAARU"]
[Tue Jul 21 08:45:36.055359 2026] [security2:error] [pid 514479:tid 514625] [client 202.179.75.202:50364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9b4PzqsQqnLoCgUjhvcAAAARU"]
[Tue Jul 21 08:45:36.078746 2026] [security2:error] [pid 511108:tid 511310] [client 168.167.81.163:59102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9b4ITd5soprXwxAH0LXQAAAEg"]
[Tue Jul 21 08:45:36.085317 2026] [security2:error] [pid 511108:tid 511310] [client 168.167.81.163:59102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9b4ITd5soprXwxAH0LXQAAAEg"]
[Tue Jul 21 08:45:36.219187 2026] [proxy:error] [pid 514479:tid 514682] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:36.219266 2026] [proxy_http:error] [pid 514479:tid 514682] [client 167.71.182.69:51878] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.cdatecnologia.com.br/
[Tue Jul 21 08:45:36.219750 2026] [proxy:error] [pid 514479:tid 514682] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:36.219779 2026] [proxy_http:error] [pid 514479:tid 514682] [client 167.71.182.69:51878] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.cdatecnologia.com.br/
[Tue Jul 21 08:45:36.272735 2026] [security2:error] [pid 514479:tid 514671] [client 203.25.124.191:35253] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/network/"] [unique_id "al9b4PzqsQqnLoCgUjhvdQAAAUM"]
[Tue Jul 21 08:45:36.347407 2026] [security2:error] [pid 514479:tid 514711] [client 152.59.181.104:58549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9b4PzqsQqnLoCgUjhveAAAAWs"]
[Tue Jul 21 08:45:36.347529 2026] [security2:error] [pid 514479:tid 514711] [client 152.59.181.104:58549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9b4PzqsQqnLoCgUjhveAAAAWs"]
[Tue Jul 21 08:45:36.375552 2026] [security2:error] [pid 514479:tid 514617] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9b4PzqsQqnLoCgUjhvdgABDTw"]
[Tue Jul 21 08:45:36.438332 2026] [security2:error] [pid 514479:tid 514725] [client 203.25.124.51:61967] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/"] [unique_id "al9b4PzqsQqnLoCgUjhveQAAAXk"]
[Tue Jul 21 08:45:36.687512 2026] [proxy:error] [pid 511108:tid 511326] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:36.687549 2026] [proxy_http:error] [pid 511108:tid 511326] [client 167.71.182.69:56356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:36.688135 2026] [proxy:error] [pid 511108:tid 511326] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:36.688162 2026] [proxy_http:error] [pid 511108:tid 511326] [client 167.71.182.69:56356] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:37.136024 2026] [security2:error] [pid 511108:tid 511327] [client 5.31.193.106:29971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9b4YTd5soprXwxAH0LcgAAAFk"]
[Tue Jul 21 08:45:37.136194 2026] [security2:error] [pid 511108:tid 511327] [client 5.31.193.106:29971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9b4YTd5soprXwxAH0LcgAAAFk"]
[Tue Jul 21 08:45:37.347548 2026] [security2:error] [pid 511108:tid 511312] [client 91.92.47.81:10134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/settings.php"] [unique_id "al9b4YTd5soprXwxAH0LdQAAAEo"], referer: http://englobehair.com.br/
[Tue Jul 21 08:45:37.348193 2026] [security2:error] [pid 514479:tid 514641] [client 203.25.124.211:35041] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-config-sample.php"] [unique_id "al9b4fzqsQqnLoCgUjhvhwAAASU"]
[Tue Jul 21 08:45:37.349084 2026] [security2:error] [pid 514479:tid 514734] [client 91.92.47.81:10142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "englobehair.com.br"] [uri "/.env.bak"] [unique_id "al9b4fzqsQqnLoCgUjhvhgAAAYI"], referer: http://englobehair.com.br/
[Tue Jul 21 08:45:37.701878 2026] [security2:error] [pid 514479:tid 514686] [client 91.92.47.81:10170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/db.php"] [unique_id "al9b4fzqsQqnLoCgUjhvjwAAAVI"], referer: http://englobehair.com.br/
[Tue Jul 21 08:45:37.702413 2026] [security2:error] [pid 514479:tid 514627] [client 91.92.47.81:10168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/database.php"] [unique_id "al9b4fzqsQqnLoCgUjhvkgAAARc"], referer: http://englobehair.com.br/
[Tue Jul 21 08:45:37.703126 2026] [security2:error] [pid 514479:tid 514635] [client 91.92.47.81:10186] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "englobehair.com.br"] [uri "/web.config"] [unique_id "al9b4fzqsQqnLoCgUjhvkQAAAR8"], referer: http://englobehair.com.br/
[Tue Jul 21 08:45:37.832033 2026] [security2:error] [pid 511108:tid 511364] [client 198.44.157.34:53356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9b4YTd5soprXwxAH0LggAAAH4"]
[Tue Jul 21 08:45:37.832155 2026] [security2:error] [pid 511108:tid 511364] [client 198.44.157.34:53356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9b4YTd5soprXwxAH0LggAAAH4"]
[Tue Jul 21 08:45:37.982019 2026] [security2:error] [pid 514479:tid 514637] [client 203.25.124.184:53583] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/profile.php"] [unique_id "al9b4fzqsQqnLoCgUjhvoAAAASE"]
[Tue Jul 21 08:45:38.560595 2026] [security2:error] [pid 514479:tid 514697] [client 212.32.76.11:63663] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/list/list/wp-config.php"] [unique_id "al9b4vzqsQqnLoCgUjhvrQAAAV0"]
[Tue Jul 21 08:45:38.642052 2026] [security2:error] [pid 511108:tid 511156] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9b4oTd5soprXwxAH0LkAAAZC8"]
[Tue Jul 21 08:45:38.642226 2026] [security2:error] [pid 511108:tid 511338] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9b4oTd5soprXwxAH0LkAAAZC8"]
[Tue Jul 21 08:45:38.795903 2026] [security2:error] [pid 514479:tid 514565] [remote 41.186.86.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cromobelo.com.br"] [uri "/wp-login.php"] [unique_id "al9b4vzqsQqnLoCgUjhvsgABdFA"]
[Tue Jul 21 08:45:38.877585 2026] [security2:error] [pid 511108:tid 511286] [client 203.25.124.6:29861] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/tinymce/utils/"] [unique_id "al9b4oTd5soprXwxAH0LlAAAADA"]
[Tue Jul 21 08:45:38.965054 2026] [security2:error] [pid 514479:tid 514722] [client 5.38.115.39:10507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9b4vzqsQqnLoCgUjhvswAAAXY"]
[Tue Jul 21 08:45:38.965193 2026] [security2:error] [pid 514479:tid 514722] [client 5.38.115.39:10507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9b4vzqsQqnLoCgUjhvswAAAXY"]
[Tue Jul 21 08:45:39.246013 2026] [security2:error] [pid 514479:tid 514532] [remote 130.51.180.8:58136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pomotionjustforyou.com"] [uri "/wp-login.php"] [unique_id "al9b4_zqsQqnLoCgUjhvtgABgzA"]
[Tue Jul 21 08:45:39.344381 2026] [security2:error] [pid 511108:tid 511289] [client 203.25.124.58:39869] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403.php"] [unique_id "al9b44Td5soprXwxAH0LnwAAADM"]
[Tue Jul 21 08:45:39.581694 2026] [security2:error] [pid 511108:tid 511336] [client 203.25.124.11:52031] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/block-patterns/"] [unique_id "al9b44Td5soprXwxAH0LoQAAAGI"]
[Tue Jul 21 08:45:39.631337 2026] [security2:error] [pid 511108:tid 511206] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9b44Td5soprXwxAH0LpQAAbWE"]
[Tue Jul 21 08:45:39.631527 2026] [security2:error] [pid 511108:tid 511347] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9b44Td5soprXwxAH0LpQAAbWE"]
[Tue Jul 21 08:45:39.681087 2026] [proxy:error] [pid 511108:tid 511266] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:39.681174 2026] [proxy_http:error] [pid 511108:tid 511266] [client 167.71.182.69:42242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.cdatecnologia.com.br/
[Tue Jul 21 08:45:39.682011 2026] [proxy:error] [pid 511108:tid 511266] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:39.682041 2026] [proxy_http:error] [pid 511108:tid 511266] [client 167.71.182.69:42242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.cdatecnologia.com.br/
[Tue Jul 21 08:45:39.866365 2026] [security2:error] [pid 514479:tid 514631] [client 203.25.124.48:29961] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/post-author-biography/post-author-biography/class-wp-http.php"] [unique_id "al9b4_zqsQqnLoCgUjhvwQAAARs"]
[Tue Jul 21 08:45:40.056359 2026] [core:error] [pid 511108:tid 511295] [client 66.249.66.67:65481] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:45:40.056394 2026] [core:error] [pid 511108:tid 511295] [client 66.249.66.67:65481] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:45:40.152801 2026] [security2:error] [pid 511108:tid 511316] [client 198.44.157.34:34496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9b5ITd5soprXwxAH0LrwAAAE4"]
[Tue Jul 21 08:45:40.152917 2026] [security2:error] [pid 511108:tid 511316] [client 198.44.157.34:34496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9b5ITd5soprXwxAH0LrwAAAE4"]
[Tue Jul 21 08:45:40.165799 2026] [security2:error] [pid 514479:tid 514664] [client 113.22.144.139:57161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b5PzqsQqnLoCgUjhvwwAAATw"]
[Tue Jul 21 08:45:40.165921 2026] [security2:error] [pid 514479:tid 514664] [client 113.22.144.139:57161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b5PzqsQqnLoCgUjhvwwAAATw"]
[Tue Jul 21 08:45:40.207274 2026] [security2:error] [pid 514479:tid 514655] [client 114.198.138.124:52063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9b5PzqsQqnLoCgUjhvxgAAATM"]
[Tue Jul 21 08:45:40.209585 2026] [security2:error] [pid 514479:tid 514655] [client 114.198.138.124:52063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9b5PzqsQqnLoCgUjhvxgAAATM"]
[Tue Jul 21 08:45:40.257109 2026] [security2:error] [pid 514479:tid 514684] [client 65.21.113.253:44888] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9b4_zqsQqnLoCgUjhvwAAAAVA"]
[Tue Jul 21 08:45:40.324982 2026] [security2:error] [pid 514479:tid 514555] [remote 119.195.102.159:56970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nocaminhodafe.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b5PzqsQqnLoCgUjhvyQABbUY"]
[Tue Jul 21 08:45:40.325219 2026] [security2:error] [pid 514479:tid 514713] [client 119.195.102.159:56970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nocaminhodafe.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b5PzqsQqnLoCgUjhvyQABbUY"]
[Tue Jul 21 08:45:40.667733 2026] [security2:error] [pid 514479:tid 514692] [client 103.59.206.240:31130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b5PzqsQqnLoCgUjhv0QAAAVg"]
[Tue Jul 21 08:45:40.667867 2026] [security2:error] [pid 514479:tid 514692] [client 103.59.206.240:31130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b5PzqsQqnLoCgUjhv0QAAAVg"]
[Tue Jul 21 08:45:40.676481 2026] [security2:error] [pid 514479:tid 514695] [client 203.25.124.201:52701] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwentythree/patterns/template-singl-portfolio.php"] [unique_id "al9b5PzqsQqnLoCgUjhv0gAAAVs"]
[Tue Jul 21 08:45:40.824963 2026] [security2:error] [pid 514479:tid 514736] [client 195.49.128.211:52914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9b5PzqsQqnLoCgUjhv2AAAAYQ"]
[Tue Jul 21 08:45:40.825128 2026] [security2:error] [pid 514479:tid 514736] [client 195.49.128.211:52914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9b5PzqsQqnLoCgUjhv2AAAAYQ"]
[Tue Jul 21 08:45:40.873766 2026] [core:alert] [pid 511108:tid 511256] [client 57.141.18.7:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:45:40.964331 2026] [security2:error] [pid 514479:tid 514722] [client 203.25.124.66:38667] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/post-time-to-read/post-time-to-read/post-template.php"] [unique_id "al9b5PzqsQqnLoCgUjhv3QAAAXY"]
[Tue Jul 21 08:45:41.136204 2026] [security2:error] [pid 514479:tid 514730] [client 203.25.124.61:45527] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/images/admin.php"] [unique_id "al9b5fzqsQqnLoCgUjhv4gAAAX4"]
[Tue Jul 21 08:45:41.573254 2026] [security2:error] [pid 514479:tid 514713] [client 212.32.76.64:38343] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/certificates/"] [unique_id "al9b5fzqsQqnLoCgUjhv9AAAAW0"]
[Tue Jul 21 08:45:42.652784 2026] [security2:error] [pid 511108:tid 511302] [client 198.44.157.34:42524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9b5oTd5soprXwxAH0L9QAAAEA"]
[Tue Jul 21 08:45:42.652910 2026] [security2:error] [pid 511108:tid 511302] [client 198.44.157.34:42524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9b5oTd5soprXwxAH0L9QAAAEA"]
[Tue Jul 21 08:45:42.666657 2026] [security2:error] [pid 514479:tid 514650] [client 49.144.66.253:33593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9b5vzqsQqnLoCgUjhwBwAAAS4"]
[Tue Jul 21 08:45:42.666777 2026] [security2:error] [pid 514479:tid 514650] [client 49.144.66.253:33593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9b5vzqsQqnLoCgUjhwBwAAAS4"]
[Tue Jul 21 08:45:42.681156 2026] [security2:error] [pid 514479:tid 514716] [client 212.32.76.56:32023] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/includes/user/"] [unique_id "al9b5vzqsQqnLoCgUjhwCAAAAXA"]
[Tue Jul 21 08:45:42.757160 2026] [security2:error] [pid 514479:tid 514737] [client 195.49.128.211:60678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9b5vzqsQqnLoCgUjhwCQAAAYU"]
[Tue Jul 21 08:45:42.757339 2026] [security2:error] [pid 514479:tid 514737] [client 195.49.128.211:60678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9b5vzqsQqnLoCgUjhwCQAAAYU"]
[Tue Jul 21 08:45:42.825552 2026] [security2:error] [pid 514479:tid 514620] [client 59.95.197.55:57618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b5vzqsQqnLoCgUjhwCwAAARA"]
[Tue Jul 21 08:45:42.825684 2026] [security2:error] [pid 514479:tid 514620] [client 59.95.197.55:57618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b5vzqsQqnLoCgUjhwCwAAARA"]
[Tue Jul 21 08:45:43.262750 2026] [security2:error] [pid 511108:tid 511293] [client 203.25.124.43:65395] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/post-template/post-template/api-gateway.php"] [unique_id "al9b54Td5soprXwxAH0MAAAAADc"]
[Tue Jul 21 08:45:43.495737 2026] [security2:error] [pid 514479:tid 514685] [client 122.176.100.127:59248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9b5_zqsQqnLoCgUjhwGAAAAVE"]
[Tue Jul 21 08:45:43.495855 2026] [security2:error] [pid 514479:tid 514685] [client 122.176.100.127:59248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9b5_zqsQqnLoCgUjhwGAAAAVE"]
[Tue Jul 21 08:45:43.675135 2026] [security2:error] [pid 514479:tid 514664] [client 212.32.76.63:24737] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/66.php"] [unique_id "al9b5_zqsQqnLoCgUjhwGwAAATw"]
[Tue Jul 21 08:45:43.886017 2026] [security2:error] [pid 514479:tid 514714] [client 41.89.234.2:60599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b5_zqsQqnLoCgUjhwHQAAAW4"]
[Tue Jul 21 08:45:43.886117 2026] [security2:error] [pid 514479:tid 514714] [client 41.89.234.2:60599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b5_zqsQqnLoCgUjhwHQAAAW4"]
[Tue Jul 21 08:45:43.950564 2026] [security2:error] [pid 514479:tid 514706] [client 20.197.192.193:4063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/zzz.php"] [unique_id "al9b5_zqsQqnLoCgUjhwIAAAAWY"]
[Tue Jul 21 08:45:44.346209 2026] [security2:error] [pid 514479:tid 514553] [remote 184.168.124.4:55666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.124.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9b6PzqsQqnLoCgUjhwKAABOEQ"]
[Tue Jul 21 08:45:44.541369 2026] [security2:error] [pid 514479:tid 514738] [client 203.25.124.40:62397] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/"] [unique_id "al9b6PzqsQqnLoCgUjhwLQAAAYY"]
[Tue Jul 21 08:45:44.580712 2026] [security2:error] [pid 511108:tid 511265] [client 64.42.179.43:49486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9b6ITd5soprXwxAH0MTgAAABs"]
[Tue Jul 21 08:45:44.580791 2026] [security2:error] [pid 511108:tid 511265] [client 64.42.179.43:49486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9b6ITd5soprXwxAH0MTgAAABs"]
[Tue Jul 21 08:45:44.762136 2026] [security2:error] [pid 511108:tid 511260] [client 203.25.124.42:38839] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/customize/network/index.php"] [unique_id "al9b6ITd5soprXwxAH0MWAAAABY"]
[Tue Jul 21 08:45:44.907107 2026] [security2:error] [pid 511108:tid 511149] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9b6ITd5soprXwxAH0MZgAAICg"]
[Tue Jul 21 08:45:44.907264 2026] [security2:error] [pid 511108:tid 511270] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9b6ITd5soprXwxAH0MZgAAICg"]
[Tue Jul 21 08:45:45.371921 2026] [security2:error] [pid 514479:tid 514659] [client 203.25.124.182:38929] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/languages/autoload_classmap.php"] [unique_id "al9b6fzqsQqnLoCgUjhwRQAAATc"]
[Tue Jul 21 08:45:45.441435 2026] [security2:error] [pid 511108:tid 511323] [client 203.25.124.212:31303] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/item.php"] [unique_id "al9b6YTd5soprXwxAH0MhgAAAFU"]
[Tue Jul 21 08:45:45.561545 2026] [security2:error] [pid 514479:tid 514718] [client 203.25.124.67:39557] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/widgets/theme-compat/index.php"] [unique_id "al9b6fzqsQqnLoCgUjhwRwAAAXI"]
[Tue Jul 21 08:45:45.579037 2026] [security2:error] [pid 514479:tid 514510] [remote 57.141.18.39:62460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/wp-sitemap-users-1.xml"] [unique_id "al9b6PzqsQqnLoCgUjhwLAABGRo"]
[Tue Jul 21 08:45:46.009196 2026] [security2:error] [pid 514479:tid 514653] [client 20.197.195.24:2768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9b6vzqsQqnLoCgUjhwUQAAATE"]
[Tue Jul 21 08:45:46.246087 2026] [security2:error] [pid 514479:tid 514671] [client 203.25.124.213:26885] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/adminfuns.php"] [unique_id "al9b6vzqsQqnLoCgUjhwVwAAAUM"]
[Tue Jul 21 08:45:46.378864 2026] [security2:error] [pid 514479:tid 514617] [client 203.25.124.198:32505] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/2024/"] [unique_id "al9b6vzqsQqnLoCgUjhwYAAAAQ0"]
[Tue Jul 21 08:45:46.480743 2026] [security2:error] [pid 514479:tid 514647] [client 65.21.113.253:59768] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9b6vzqsQqnLoCgUjhwUAAAASs"]
[Tue Jul 21 08:45:46.766452 2026] [security2:error] [pid 514479:tid 514618] [client 203.25.124.51:44499] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/upgrade/patterns/index.php"] [unique_id "al9b6vzqsQqnLoCgUjhweAAAAQ4"]
[Tue Jul 21 08:45:46.909916 2026] [security2:error] [pid 514479:tid 514628] [client 168.167.81.163:62644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9b6vzqsQqnLoCgUjhwegAAARg"]
[Tue Jul 21 08:45:46.910038 2026] [security2:error] [pid 514479:tid 514628] [client 168.167.81.163:62644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9b6vzqsQqnLoCgUjhwegAAARg"]
[Tue Jul 21 08:45:46.980737 2026] [proxy:error] [pid 514479:tid 514727] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:46.980825 2026] [proxy_http:error] [pid 514479:tid 514727] [client 147.182.253.52:57436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:46.981409 2026] [proxy:error] [pid 514479:tid 514727] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:46.981436 2026] [proxy_http:error] [pid 514479:tid 514727] [client 147.182.253.52:57436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:47.021620 2026] [security2:error] [pid 514479:tid 514714] [client 20.197.195.24:17824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9b6_zqsQqnLoCgUjhwfgAAAW4"]
[Tue Jul 21 08:45:47.045306 2026] [security2:error] [pid 514479:tid 514644] [client 202.179.75.202:55150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9b6_zqsQqnLoCgUjhwfwAAASg"]
[Tue Jul 21 08:45:47.045443 2026] [security2:error] [pid 514479:tid 514644] [client 202.179.75.202:55150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9b6_zqsQqnLoCgUjhwfwAAASg"]
[Tue Jul 21 08:45:47.174445 2026] [security2:error] [pid 511108:tid 511263] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9b64Td5soprXwxAH0MzQAAGVM"]
[Tue Jul 21 08:45:47.205205 2026] [security2:error] [pid 511108:tid 511363] [client 20.197.192.193:4015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/wicked.php"] [unique_id "al9b64Td5soprXwxAH0M0QAAAH0"]
[Tue Jul 21 08:45:47.260622 2026] [security2:error] [pid 511108:tid 511353] [client 152.59.181.104:59127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9b64Td5soprXwxAH0M0wAAAHM"]
[Tue Jul 21 08:45:47.260762 2026] [security2:error] [pid 511108:tid 511353] [client 152.59.181.104:59127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9b64Td5soprXwxAH0M0wAAAHM"]
[Tue Jul 21 08:45:47.341097 2026] [proxy:error] [pid 511108:tid 511326] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:47.341192 2026] [proxy_http:error] [pid 511108:tid 511326] [client 147.182.253.52:57448] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.vanessaglowhair.com/
[Tue Jul 21 08:45:47.342769 2026] [proxy:error] [pid 511108:tid 511326] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:47.342852 2026] [proxy_http:error] [pid 511108:tid 511326] [client 147.182.253.52:57448] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.vanessaglowhair.com/
[Tue Jul 21 08:45:47.374804 2026] [security2:error] [pid 514479:tid 514731] [client 212.32.76.57:49821] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/chosen.php"] [unique_id "al9b6_zqsQqnLoCgUjhwkAAAAX8"]
[Tue Jul 21 08:45:47.398378 2026] [autoindex:error] [pid 514479:tid 514674] [client 147.185.132.225:57786] AH01276: Cannot serve directory /home3/factor11/yunofp/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:45:47.642157 2026] [security2:error] [pid 511108:tid 511334] [client 203.25.124.2:30935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wpx/"] [unique_id "al9b64Td5soprXwxAH0M4QAAAGA"]
[Tue Jul 21 08:45:47.754412 2026] [security2:error] [pid 511108:tid 511351] [client 20.197.195.24:2804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/media.php"] [unique_id "al9b64Td5soprXwxAH0M6gAAAHE"]
[Tue Jul 21 08:45:47.768427 2026] [security2:error] [pid 511108:tid 511262] [client 212.32.76.7:29399] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/images/widgets/index.php"] [unique_id "al9b64Td5soprXwxAH0M6wAAABg"]
[Tue Jul 21 08:45:48.069111 2026] [proxy:error] [pid 514479:tid 514650] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:48.069150 2026] [proxy_http:error] [pid 514479:tid 514650] [client 147.182.253.52:60692] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:48.069601 2026] [proxy:error] [pid 514479:tid 514650] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:48.069622 2026] [proxy_http:error] [pid 514479:tid 514650] [client 147.182.253.52:60692] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:48.175917 2026] [security2:error] [pid 514479:tid 514623] [client 198.44.157.34:42532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9b7PzqsQqnLoCgUjhwmgAAARM"]
[Tue Jul 21 08:45:48.176022 2026] [security2:error] [pid 514479:tid 514623] [client 198.44.157.34:42532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9b7PzqsQqnLoCgUjhwmgAAARM"]
[Tue Jul 21 08:45:48.225225 2026] [security2:error] [pid 514479:tid 514684] [client 20.197.192.193:6342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9b7PzqsQqnLoCgUjhwnAAAAVA"]
[Tue Jul 21 08:45:48.376444 2026] [security2:error] [pid 514479:tid 514687] [client 212.32.76.63:59221] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/footer.php"] [unique_id "al9b7PzqsQqnLoCgUjhwpQAAAVM"]
[Tue Jul 21 08:45:48.707157 2026] [security2:error] [pid 514479:tid 514636] [client 20.197.195.24:49003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/images.php"] [unique_id "al9b7PzqsQqnLoCgUjhwqgAAASA"]
[Tue Jul 21 08:45:48.797001 2026] [security2:error] [pid 514479:tid 514719] [client 213.152.162.15:39720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9b7PzqsQqnLoCgUjhwqwAAAXM"]
[Tue Jul 21 08:45:48.797142 2026] [security2:error] [pid 514479:tid 514719] [client 213.152.162.15:39720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9b7PzqsQqnLoCgUjhwqwAAAXM"]
[Tue Jul 21 08:45:48.804548 2026] [security2:error] [pid 514479:tid 514635] [client 20.197.192.193:6875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9b7PzqsQqnLoCgUjhwrAAAAR8"]
[Tue Jul 21 08:45:48.868647 2026] [security2:error] [pid 514479:tid 514655] [client 203.25.124.49:37761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/customize/includes/index.php"] [unique_id "al9b7PzqsQqnLoCgUjhwrgAAATM"]
[Tue Jul 21 08:45:48.950226 2026] [security2:error] [pid 514479:tid 514680] [client 212.32.76.2:49309] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/files.php"] [unique_id "al9b7PzqsQqnLoCgUjhwrwAAAUw"]
[Tue Jul 21 08:45:49.203538 2026] [security2:error] [pid 511108:tid 511116] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9b7YTd5soprXwxAH0NAgAAIgc"]
[Tue Jul 21 08:45:49.203676 2026] [security2:error] [pid 511108:tid 511272] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9b7YTd5soprXwxAH0NAgAAIgc"]
[Tue Jul 21 08:45:49.275552 2026] [security2:error] [pid 514479:tid 514676] [client 203.25.124.204:25059] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/wp-file-manager-pro/"] [unique_id "al9b7fzqsQqnLoCgUjhwswAAAUg"]
[Tue Jul 21 08:45:49.304913 2026] [security2:error] [pid 514479:tid 514710] [client 20.168.122.6:48720] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.68"] [uri "/index.cgi"] [unique_id "al9b7fzqsQqnLoCgUjhwtAAAAWo"]
[Tue Jul 21 08:45:49.393920 2026] [security2:error] [pid 511108:tid 511286] [client 173.252.95.58:39566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9b7YTd5soprXwxAH0NBQAAADA"]
[Tue Jul 21 08:45:49.476011 2026] [security2:error] [pid 514479:tid 514707] [client 20.197.192.193:6870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/dp.php"] [unique_id "al9b7fzqsQqnLoCgUjhwtQAAAWc"]
[Tue Jul 21 08:45:49.761047 2026] [security2:error] [pid 514479:tid 514644] [client 5.38.115.39:55307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9b7fzqsQqnLoCgUjhwuQAAASg"]
[Tue Jul 21 08:45:49.761163 2026] [security2:error] [pid 514479:tid 514644] [client 5.38.115.39:55307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9b7fzqsQqnLoCgUjhwuQAAASg"]
[Tue Jul 21 08:45:49.856313 2026] [security2:error] [pid 514479:tid 514716] [client 20.197.195.24:17734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/gecko.php"] [unique_id "al9b7fzqsQqnLoCgUjhwuwAAAXA"]
[Tue Jul 21 08:45:49.965209 2026] [security2:error] [pid 514479:tid 514740] [client 203.25.124.42:39141] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/colors/upgrade/index.php"] [unique_id "al9b7fzqsQqnLoCgUjhwvgAAAYg"]
[Tue Jul 21 08:45:49.990520 2026] [security2:error] [pid 514479:tid 514648] [client 20.197.192.193:6893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/old.php"] [unique_id "al9b7fzqsQqnLoCgUjhwvwAAASw"]
[Tue Jul 21 08:45:50.178041 2026] [security2:error] [pid 514479:tid 514670] [client 212.32.76.55:31037] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/system_log.php"] [unique_id "al9b7vzqsQqnLoCgUjhwwgAAAUI"]
[Tue Jul 21 08:45:50.190419 2026] [security2:error] [pid 514479:tid 514573] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9b7vzqsQqnLoCgUjhwxAABJlg"]
[Tue Jul 21 08:45:50.190615 2026] [security2:error] [pid 514479:tid 514642] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9b7vzqsQqnLoCgUjhwxAABJlg"]
[Tue Jul 21 08:45:50.237571 2026] [security2:error] [pid 511108:tid 511197] [remote 188.164.197.230:40542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alcovaperiodico.com"] [uri "/wp-login.php"] [unique_id "al9b7oTd5soprXwxAH0NEgAASVg"]
[Tue Jul 21 08:45:50.269189 2026] [security2:error] [pid 511108:tid 511291] [client 20.197.192.193:6899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/ms-new.php"] [unique_id "al9b7oTd5soprXwxAH0NFAAAADU"]
[Tue Jul 21 08:45:50.670136 2026] [security2:error] [pid 514479:tid 514512] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9b7fzqsQqnLoCgUjhwtwABQxw"]
[Tue Jul 21 08:45:50.670359 2026] [security2:error] [pid 514479:tid 514671] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9b7fzqsQqnLoCgUjhwtwABQxw"]
[Tue Jul 21 08:45:50.691087 2026] [security2:error] [pid 511108:tid 511323] [client 20.197.192.193:6891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/track.php"] [unique_id "al9b7oTd5soprXwxAH0NHAAAAFU"]
[Tue Jul 21 08:45:50.732972 2026] [security2:error] [pid 511108:tid 511276] [client 114.198.138.124:52635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9b7oTd5soprXwxAH0NHQAAACY"]
[Tue Jul 21 08:45:50.733150 2026] [security2:error] [pid 511108:tid 511276] [client 114.198.138.124:52635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9b7oTd5soprXwxAH0NHQAAACY"]
[Tue Jul 21 08:45:50.758960 2026] [security2:error] [pid 514479:tid 514639] [client 20.197.195.24:17817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/82.php"] [unique_id "al9b7vzqsQqnLoCgUjhwzAAAASM"]
[Tue Jul 21 08:45:50.767415 2026] [security2:error] [pid 514479:tid 514694] [client 212.32.76.2:38063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/news-portal/user-install.php"] [unique_id "al9b7vzqsQqnLoCgUjhwzQAAAVo"]
[Tue Jul 21 08:45:50.840389 2026] [security2:error] [pid 514479:tid 514734] [client 203.25.124.55:53439] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/news-portal/zdata.php"] [unique_id "al9b7vzqsQqnLoCgUjhwzwAAAYI"]
[Tue Jul 21 08:45:50.861065 2026] [security2:error] [pid 514479:tid 514620] [client 20.197.192.193:6359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/2352356666.php"] [unique_id "al9b7vzqsQqnLoCgUjhw0QAAARA"]
[Tue Jul 21 08:45:50.877498 2026] [security2:error] [pid 511108:tid 511350] [client 203.25.124.252:26919] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/separator/"] [unique_id "al9b7oTd5soprXwxAH0NIgAAAHA"]
[Tue Jul 21 08:45:50.920251 2026] [proxy:error] [pid 511108:tid 511273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:50.920333 2026] [proxy_http:error] [pid 511108:tid 511273] [client 147.185.132.69:60328] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:50.920956 2026] [proxy:error] [pid 511108:tid 511273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:50.920993 2026] [proxy_http:error] [pid 511108:tid 511273] [client 147.185.132.69:60328] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:51.097960 2026] [security2:error] [pid 511108:tid 511252] [client 20.197.195.24:17792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/admin.php"] [unique_id "al9b74Td5soprXwxAH0NJQAAAA4"]
[Tue Jul 21 08:45:51.151179 2026] [security2:error] [pid 514479:tid 514684] [client 65.21.113.253:59768] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9b7vzqsQqnLoCgUjhwygAAAVA"]
[Tue Jul 21 08:45:51.156562 2026] [security2:error] [pid 514479:tid 514687] [client 20.197.192.193:6357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/pn.php"] [unique_id "al9b7_zqsQqnLoCgUjhw0wAAAVM"]
[Tue Jul 21 08:45:51.181021 2026] [security2:error] [pid 514479:tid 514640] [client 113.22.144.139:57674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b7_zqsQqnLoCgUjhw1gAAASQ"]
[Tue Jul 21 08:45:51.181211 2026] [security2:error] [pid 514479:tid 514640] [client 113.22.144.139:57674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b7_zqsQqnLoCgUjhw1gAAASQ"]
[Tue Jul 21 08:45:51.184435 2026] [security2:error] [pid 514479:tid 514618] [client 20.197.192.193:53622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/edit.php"] [unique_id "al9b7_zqsQqnLoCgUjhw1wAAAQ4"]
[Tue Jul 21 08:45:51.240050 2026] [security2:error] [pid 511108:tid 511342] [client 173.252.95.18:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9b74Td5soprXwxAH0NJAAAAGg"]
[Tue Jul 21 08:45:51.266775 2026] [security2:error] [pid 514479:tid 514715] [client 20.197.192.193:6367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9b7_zqsQqnLoCgUjhw2AAAAW8"]
[Tue Jul 21 08:45:51.311909 2026] [security2:error] [pid 514479:tid 514724] [client 103.59.206.240:31028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b7_zqsQqnLoCgUjhw2gAAAXg"]
[Tue Jul 21 08:45:51.312029 2026] [security2:error] [pid 514479:tid 514724] [client 103.59.206.240:31028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b7_zqsQqnLoCgUjhw2gAAAXg"]
[Tue Jul 21 08:45:51.321611 2026] [security2:error] [pid 514479:tid 514673] [client 20.197.192.193:6336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/dr.php"] [unique_id "al9b7_zqsQqnLoCgUjhw2wAAAUU"]
[Tue Jul 21 08:45:51.426741 2026] [security2:error] [pid 511108:tid 511307] [client 195.49.128.211:53523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9b74Td5soprXwxAH0NKwAAAEU"]
[Tue Jul 21 08:45:51.427048 2026] [security2:error] [pid 511108:tid 511307] [client 195.49.128.211:53523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9b74Td5soprXwxAH0NKwAAAEU"]
[Tue Jul 21 08:45:51.467056 2026] [security2:error] [pid 514479:tid 514727] [client 20.197.192.193:6368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/2x.php"] [unique_id "al9b7_zqsQqnLoCgUjhw3gAAAXs"]
[Tue Jul 21 08:45:51.514573 2026] [security2:error] [pid 514479:tid 514629] [client 20.197.192.193:6399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/kq1.php"] [unique_id "al9b7_zqsQqnLoCgUjhw4AAAARk"]
[Tue Jul 21 08:45:51.569490 2026] [security2:error] [pid 514479:tid 514739] [client 20.197.192.193:6889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/zzz.php"] [unique_id "al9b7_zqsQqnLoCgUjhw5AAAAYc"]
[Tue Jul 21 08:45:51.627149 2026] [security2:error] [pid 511108:tid 511360] [client 20.197.195.24:17761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/adminner.php"] [unique_id "al9b74Td5soprXwxAH0NMQAAAHo"]
[Tue Jul 21 08:45:51.754716 2026] [security2:error] [pid 511108:tid 511317] [client 173.252.95.41:60100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9b74Td5soprXwxAH0NMwAAAE8"]
[Tue Jul 21 08:45:51.765924 2026] [security2:error] [pid 514479:tid 514624] [client 203.25.124.73:55205] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/missing/missing/theme-single.php"] [unique_id "al9b7_zqsQqnLoCgUjhw6QAAARQ"]
[Tue Jul 21 08:45:51.766121 2026] [security2:error] [pid 514479:tid 514733] [client 20.197.192.193:6857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/wicked.php"] [unique_id "al9b7_zqsQqnLoCgUjhw6AAAAYE"]
[Tue Jul 21 08:45:51.871327 2026] [security2:error] [pid 514479:tid 514665] [client 203.25.124.181:22431] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/mah/function.php"] [unique_id "al9b7_zqsQqnLoCgUjhw6gAAAT0"]
[Tue Jul 21 08:45:51.880168 2026] [security2:error] [pid 514479:tid 514644] [client 20.197.195.24:17805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/admin.php"] [unique_id "al9b7_zqsQqnLoCgUjhw6wAAASg"]
[Tue Jul 21 08:45:51.900940 2026] [security2:error] [pid 514479:tid 514736] [client 20.197.192.193:6882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/edit.php"] [unique_id "al9b7_zqsQqnLoCgUjhw7AAAAYQ"]
[Tue Jul 21 08:45:52.037948 2026] [security2:error] [pid 514479:tid 514741] [client 203.25.124.37:36263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/css/"] [unique_id "al9b8PzqsQqnLoCgUjhw8AAAAYk"]
[Tue Jul 21 08:45:52.143385 2026] [security2:error] [pid 511108:tid 511269] [client 20.197.192.193:7004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/kua.php"] [unique_id "al9b8ITd5soprXwxAH0NNwAAAB8"]
[Tue Jul 21 08:45:52.371898 2026] [security2:error] [pid 511108:tid 511318] [client 20.197.195.24:17855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/k.php"] [unique_id "al9b8ITd5soprXwxAH0NPAAAAFA"]
[Tue Jul 21 08:45:52.373080 2026] [security2:error] [pid 511108:tid 511345] [client 20.197.192.193:6871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/ez.php"] [unique_id "al9b8ITd5soprXwxAH0NPQAAAGs"]
[Tue Jul 21 08:45:52.384475 2026] [proxy:error] [pid 511108:tid 511251] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:52.384507 2026] [proxy_http:error] [pid 511108:tid 511251] [client 147.182.253.52:60796] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.vanessaglowhair.com/
[Tue Jul 21 08:45:52.385061 2026] [proxy:error] [pid 511108:tid 511251] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:52.385082 2026] [proxy_http:error] [pid 511108:tid 511251] [client 147.182.253.52:60796] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.vanessaglowhair.com/
[Tue Jul 21 08:45:52.606441 2026] [security2:error] [pid 514479:tid 514675] [client 20.197.195.24:17800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/blurbs.php"] [unique_id "al9b8PzqsQqnLoCgUjhw9wAAAUc"]
[Tue Jul 21 08:45:52.608587 2026] [security2:error] [pid 511108:tid 511244] [client 20.197.192.193:6385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/fz.php"] [unique_id "al9b8ITd5soprXwxAH0NQQAAAAY"]
[Tue Jul 21 08:45:52.682174 2026] [security2:error] [pid 511108:tid 511270] [client 20.197.192.193:6859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/la.php"] [unique_id "al9b8ITd5soprXwxAH0NQgAAACA"]
[Tue Jul 21 08:45:52.836230 2026] [security2:error] [pid 511108:tid 511257] [client 20.197.195.24:49004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/bajah.php"] [unique_id "al9b8ITd5soprXwxAH0NRQAAABM"]
[Tue Jul 21 08:45:52.885937 2026] [security2:error] [pid 511108:tid 511321] [client 20.197.192.193:6879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9b8ITd5soprXwxAH0NSAAAAFM"]
[Tue Jul 21 08:45:52.976018 2026] [security2:error] [pid 514479:tid 514620] [client 203.25.124.204:34591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/languages/admin.php"] [unique_id "al9b8PzqsQqnLoCgUjhw-wAAARA"]
[Tue Jul 21 08:45:52.999767 2026] [security2:error] [pid 514479:tid 514688] [client 20.197.192.193:6908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/inso.php"] [unique_id "al9b8PzqsQqnLoCgUjhw_AAAAVQ"]
[Tue Jul 21 08:45:53.056408 2026] [security2:error] [pid 514479:tid 514689] [client 61.1.167.83:62629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b8fzqsQqnLoCgUjhw_QAAAVU"]
[Tue Jul 21 08:45:53.059424 2026] [security2:error] [pid 514479:tid 514689] [client 61.1.167.83:62629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b8fzqsQqnLoCgUjhw_QAAAVU"]
[Tue Jul 21 08:45:53.065457 2026] [security2:error] [pid 514479:tid 514690] [client 203.25.124.212:20371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/admin-header-string.php"] [unique_id "al9b8fzqsQqnLoCgUjhw_gAAAVY"]
[Tue Jul 21 08:45:53.222544 2026] [security2:error] [pid 514479:tid 514728] [client 20.197.195.24:17772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/a.php"] [unique_id "al9b8fzqsQqnLoCgUjhw_wAAAXw"]
[Tue Jul 21 08:45:53.312988 2026] [security2:error] [pid 511108:tid 511320] [client 59.95.197.55:58085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b8YTd5soprXwxAH0NTQAAAFI"]
[Tue Jul 21 08:45:53.313714 2026] [security2:error] [pid 511108:tid 511320] [client 59.95.197.55:58085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b8YTd5soprXwxAH0NTQAAAFI"]
[Tue Jul 21 08:45:53.328450 2026] [security2:error] [pid 514479:tid 514618] [client 20.197.192.193:27099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/mimpi.php"] [unique_id "al9b8fzqsQqnLoCgUjhxAgAAAQ4"]
[Tue Jul 21 08:45:53.328788 2026] [security2:error] [pid 514479:tid 514672] [client 203.25.124.47:39691] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9b8fzqsQqnLoCgUjhxAwAAAUQ"]
[Tue Jul 21 08:45:53.350153 2026] [security2:error] [pid 514479:tid 514726] [client 195.49.128.211:61279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9b8fzqsQqnLoCgUjhxBAAAAXo"]
[Tue Jul 21 08:45:53.350251 2026] [security2:error] [pid 514479:tid 514726] [client 195.49.128.211:61279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9b8fzqsQqnLoCgUjhxBAAAAXo"]
[Tue Jul 21 08:45:53.453757 2026] [security2:error] [pid 511108:tid 511299] [client 20.197.195.24:49002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/edit.php"] [unique_id "al9b8YTd5soprXwxAH0NUQAAAD0"]
[Tue Jul 21 08:45:53.536581 2026] [security2:error] [pid 511108:tid 511323] [client 20.197.192.193:6379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/wpx.php"] [unique_id "al9b8YTd5soprXwxAH0NVQAAAFU"]
[Tue Jul 21 08:45:53.665299 2026] [security2:error] [pid 511108:tid 511364] [client 49.144.66.253:29923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9b8YTd5soprXwxAH0NVwAAAH4"]
[Tue Jul 21 08:45:53.665403 2026] [security2:error] [pid 511108:tid 511364] [client 49.144.66.253:29923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9b8YTd5soprXwxAH0NVwAAAH4"]
[Tue Jul 21 08:45:53.702036 2026] [security2:error] [pid 514479:tid 514627] [client 185.8.106.219:26908] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9b8fzqsQqnLoCgUjhxBwAAARc"]
[Tue Jul 21 08:45:53.813282 2026] [security2:error] [pid 514479:tid 514718] [client 20.197.192.193:41472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/kua.php"] [unique_id "al9b8fzqsQqnLoCgUjhxCQAAAXI"]
[Tue Jul 21 08:45:53.860916 2026] [security2:error] [pid 511108:tid 511296] [client 20.197.195.24:2796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/hosty.php"] [unique_id "al9b8YTd5soprXwxAH0NXQAAADo"]
[Tue Jul 21 08:45:53.988549 2026] [security2:error] [pid 514479:tid 514715] [client 122.176.100.127:59731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9b8fzqsQqnLoCgUjhxCgAAAW8"]
[Tue Jul 21 08:45:53.988726 2026] [security2:error] [pid 514479:tid 514715] [client 122.176.100.127:59731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9b8fzqsQqnLoCgUjhxCgAAAW8"]
[Tue Jul 21 08:45:54.047701 2026] [security2:error] [pid 514479:tid 514713] [client 20.197.192.193:6340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/berlin.php"] [unique_id "al9b8vzqsQqnLoCgUjhxDQAAAW0"]
[Tue Jul 21 08:45:54.123018 2026] [security2:error] [pid 511108:tid 511201] [remote 20.153.140.50:49404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "santotchay.com"] [uri "/wp-login.php"] [unique_id "al9b8oTd5soprXwxAH0NYAAAEVw"]
[Tue Jul 21 08:45:54.261937 2026] [security2:error] [pid 511108:tid 511344] [client 212.32.76.11:41169] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/fonts-long.php"] [unique_id "al9b8oTd5soprXwxAH0NYQAAAGo"]
[Tue Jul 21 08:45:54.273485 2026] [security2:error] [pid 514479:tid 514714] [client 203.25.124.246:58015] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/spacer/"] [unique_id "al9b8vzqsQqnLoCgUjhxDgAAAW4"]
[Tue Jul 21 08:45:54.370112 2026] [security2:error] [pid 514479:tid 514645] [client 20.197.195.24:48950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/k.php"] [unique_id "al9b8vzqsQqnLoCgUjhxDwAAASk"]
[Tue Jul 21 08:45:54.496740 2026] [security2:error] [pid 514479:tid 514710] [client 185.8.106.219:53416] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9b8vzqsQqnLoCgUjhxEgAAAWo"]
[Tue Jul 21 08:45:54.537846 2026] [security2:error] [pid 514479:tid 514619] [client 203.25.124.53:25365] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/"] [unique_id "al9b8vzqsQqnLoCgUjhxEwAAAQ8"]
[Tue Jul 21 08:45:54.553700 2026] [security2:error] [pid 511108:tid 511360] [client 20.197.192.193:6390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/billur.php"] [unique_id "al9b8oTd5soprXwxAH0NagAAAHo"]
[Tue Jul 21 08:45:54.729402 2026] [security2:error] [pid 514479:tid 514707] [client 20.197.192.193:6349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/mimpi.php"] [unique_id "al9b8vzqsQqnLoCgUjhxFQAAAWc"]
[Tue Jul 21 08:45:54.772614 2026] [security2:error] [pid 511108:tid 511358] [client 213.152.162.15:48614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9b8oTd5soprXwxAH0NbgAAAHg"]
[Tue Jul 21 08:45:54.772742 2026] [security2:error] [pid 511108:tid 511358] [client 213.152.162.15:48614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9b8oTd5soprXwxAH0NbgAAAHg"]
[Tue Jul 21 08:45:54.806173 2026] [security2:error] [pid 514479:tid 514494] [remote 74.235.96.117:32962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9b8vzqsQqnLoCgUjhxFwABFQo"]
[Tue Jul 21 08:45:54.828078 2026] [core:error] [pid 514479:tid 514649] [client 66.249.66.67:44668] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:45:54.828107 2026] [core:error] [pid 514479:tid 514649] [client 66.249.66.67:44668] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:45:54.880398 2026] [security2:error] [pid 511108:tid 511322] [client 20.197.192.193:6897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/dp.php"] [unique_id "al9b8oTd5soprXwxAH0NcgAAAFQ"]
[Tue Jul 21 08:45:55.024238 2026] [security2:error] [pid 511108:tid 511345] [client 20.197.192.193:6884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/bootstrap.php"] [unique_id "al9b84Td5soprXwxAH0NdAAAAGs"]
[Tue Jul 21 08:45:55.260141 2026] [security2:error] [pid 514479:tid 514679] [client 20.197.195.24:17787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/aaa.php"] [unique_id "al9b8_zqsQqnLoCgUjhxHwAAAUs"]
[Tue Jul 21 08:45:55.263166 2026] [security2:error] [pid 514479:tid 514716] [client 203.25.124.213:42675] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/wp-config/index.php"] [unique_id "al9b8_zqsQqnLoCgUjhxIAAAAXA"]
[Tue Jul 21 08:45:55.275349 2026] [security2:error] [pid 514479:tid 514686] [client 203.25.124.254:25677] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/certificates/chosen.php"] [unique_id "al9b8_zqsQqnLoCgUjhxIQAAAVI"]
[Tue Jul 21 08:45:55.355734 2026] [security2:error] [pid 514479:tid 514691] [client 20.197.192.193:6383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/wp-editor.php"] [unique_id "al9b8_zqsQqnLoCgUjhxJAAAAVc"]
[Tue Jul 21 08:45:55.368978 2026] [security2:error] [pid 514479:tid 514736] [client 65.21.113.253:59768] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9b8vzqsQqnLoCgUjhxGwAAAYQ"]
[Tue Jul 21 08:45:55.593250 2026] [security2:error] [pid 514479:tid 514678] [client 20.197.192.193:6976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/cro.php"] [unique_id "al9b8_zqsQqnLoCgUjhxKgAAAUo"]
[Tue Jul 21 08:45:55.665417 2026] [security2:error] [pid 514479:tid 514505] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9b8_zqsQqnLoCgUjhxLQABfxU"]
[Tue Jul 21 08:45:55.665544 2026] [security2:error] [pid 514479:tid 514731] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9b8_zqsQqnLoCgUjhxLQABfxU"]
[Tue Jul 21 08:45:55.975858 2026] [security2:error] [pid 514479:tid 514712] [client 203.25.124.5:29577] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/shortcode/"] [unique_id "al9b8_zqsQqnLoCgUjhxMwAAAWw"]
[Tue Jul 21 08:45:55.979541 2026] [security2:error] [pid 514479:tid 514726] [client 20.197.192.193:6338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/cron-tab.php"] [unique_id "al9b8_zqsQqnLoCgUjhxNAAAAXo"]
[Tue Jul 21 08:45:56.225923 2026] [security2:error] [pid 514479:tid 514616] [client 20.197.195.24:17728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/file5.php"] [unique_id "al9b9PzqsQqnLoCgUjhxOQAAAQw"]
[Tue Jul 21 08:45:56.270879 2026] [security2:error] [pid 514479:tid 514635] [client 203.25.124.72:40487] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/cyber-security-blocks/parts/parts/user-edit.php"] [unique_id "al9b9PzqsQqnLoCgUjhxOgAAAR8"]
[Tue Jul 21 08:45:56.286715 2026] [security2:error] [pid 514479:tid 514667] [client 20.197.192.193:6380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/koiy.php"] [unique_id "al9b9PzqsQqnLoCgUjhxOwAAAT8"]
[Tue Jul 21 08:45:56.441873 2026] [security2:error] [pid 514479:tid 514698] [client 203.25.124.35:38443] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9b9PzqsQqnLoCgUjhxPwAAAV4"]
[Tue Jul 21 08:45:56.583437 2026] [security2:error] [pid 514479:tid 514614] [client 41.89.234.2:61490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b9PzqsQqnLoCgUjhxRAAAAQo"]
[Tue Jul 21 08:45:56.583567 2026] [security2:error] [pid 514479:tid 514614] [client 41.89.234.2:61490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b9PzqsQqnLoCgUjhxRAAAAQo"]
[Tue Jul 21 08:45:56.722441 2026] [security2:error] [pid 514479:tid 514740] [client 20.197.192.193:6394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/hp2.php"] [unique_id "al9b9PzqsQqnLoCgUjhxSAAAAYg"]
[Tue Jul 21 08:45:56.819940 2026] [security2:error] [pid 514479:tid 514622] [client 185.8.106.219:26920] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/"] [unique_id "al9b9PzqsQqnLoCgUjhxSgAAARI"]
[Tue Jul 21 08:45:57.263548 2026] [security2:error] [pid 514479:tid 514675] [client 203.25.124.52:62597] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/shadow-bot.php"] [unique_id "al9b9fzqsQqnLoCgUjhxUwAAAUc"]
[Tue Jul 21 08:45:57.387318 2026] [security2:error] [pid 514479:tid 514671] [client 64.42.179.43:51072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9b9fzqsQqnLoCgUjhxVAAAAUM"]
[Tue Jul 21 08:45:57.387411 2026] [security2:error] [pid 514479:tid 514671] [client 64.42.179.43:51072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9b9fzqsQqnLoCgUjhxVAAAAUM"]
[Tue Jul 21 08:45:57.408618 2026] [security2:error] [pid 514479:tid 514739] [client 168.167.81.163:59456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9b9fzqsQqnLoCgUjhxVQAAAYc"]
[Tue Jul 21 08:45:57.408722 2026] [security2:error] [pid 514479:tid 514739] [client 168.167.81.163:59456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9b9fzqsQqnLoCgUjhxVQAAAYc"]
[Tue Jul 21 08:45:57.416720 2026] [proxy:error] [pid 514479:tid 514486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:57.416747 2026] [proxy_http:error] [pid 514479:tid 514486] [remote 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:57.417373 2026] [proxy:error] [pid 514479:tid 514486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:57.417396 2026] [proxy_http:error] [pid 514479:tid 514486] [remote 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:57.511342 2026] [security2:error] [pid 511108:tid 511336] [client 20.197.192.193:6994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/hp3.php"] [unique_id "al9b9YTd5soprXwxAH0NiwAAAGI"]
[Tue Jul 21 08:45:57.639880 2026] [security2:error] [pid 514479:tid 514734] [client 203.25.124.64:52309] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/fm.php"] [unique_id "al9b9fzqsQqnLoCgUjhxWQAAAYI"]
[Tue Jul 21 08:45:57.805104 2026] [fcgid:warn] [pid 514479:tid 514662] (70014)End of file found: [client 172.105.128.13:41118] mod_fcgid: can't get data from http client
[Tue Jul 21 08:45:57.816603 2026] [security2:error] [pid 511108:tid 511333] [client 74.7.241.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "douglasmoraesleite1745769445760.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9b9YTd5soprXwxAH0NkQAAXyQ"]
[Tue Jul 21 08:45:57.901993 2026] [security2:error] [pid 514479:tid 514731] [client 20.197.195.24:17778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/222.php"] [unique_id "al9b9fzqsQqnLoCgUjhxXwAAAX8"]
[Tue Jul 21 08:45:57.917053 2026] [security2:error] [pid 514479:tid 514639] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9b9fzqsQqnLoCgUjhxXQABI2Y"]
[Tue Jul 21 08:45:58.028637 2026] [security2:error] [pid 511108:tid 511323] [client 202.179.75.202:59682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9b9oTd5soprXwxAH0NmAAAAFU"]
[Tue Jul 21 08:45:58.028748 2026] [security2:error] [pid 511108:tid 511323] [client 202.179.75.202:59682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9b9oTd5soprXwxAH0NmAAAAFU"]
[Tue Jul 21 08:45:58.065996 2026] [proxy:error] [pid 514479:tid 514572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:58.066079 2026] [proxy_http:error] [pid 514479:tid 514572] [remote 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:58.066745 2026] [proxy:error] [pid 514479:tid 514572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:45:58.066772 2026] [proxy_http:error] [pid 514479:tid 514572] [remote 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:45:58.167628 2026] [security2:error] [pid 514479:tid 514674] [client 212.32.76.10:25713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/html/html/dark-mode.php"] [unique_id "al9b9vzqsQqnLoCgUjhxYwAAAUY"]
[Tue Jul 21 08:45:58.351842 2026] [security2:error] [pid 514479:tid 514517] [remote 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.nyersuplementos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b9vzqsQqnLoCgUjhxZgABDiE"]
[Tue Jul 21 08:45:58.554861 2026] [security2:error] [pid 511108:tid 511360] [client 20.197.192.193:6852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/aa1.php"] [unique_id "al9b9oTd5soprXwxAH0NpwAAAHo"]
[Tue Jul 21 08:45:58.627784 2026] [security2:error] [pid 514479:tid 514603] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nyersuplementos.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9b9vzqsQqnLoCgUjhxZwABG3Y"]
[Tue Jul 21 08:45:58.754745 2026] [security2:error] [pid 511108:tid 511269] [client 212.32.76.6:45617] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/"] [unique_id "al9b9oTd5soprXwxAH0NqQAAAB8"]
[Tue Jul 21 08:45:58.764177 2026] [fcgid:warn] [pid 511108:tid 511358] (70014)End of file found: [client 172.105.128.13:41132] mod_fcgid: can't get data from http client
[Tue Jul 21 08:45:58.800582 2026] [security2:error] [pid 514479:tid 514659] [client 20.197.192.193:27137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/dp.php"] [unique_id "al9b9vzqsQqnLoCgUjhxawAAATc"]
[Tue Jul 21 08:45:58.844614 2026] [security2:error] [pid 511108:tid 511334] [client 5.31.193.106:58580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9b9oTd5soprXwxAH0NrgAAAGA"]
[Tue Jul 21 08:45:58.844711 2026] [security2:error] [pid 511108:tid 511334] [client 5.31.193.106:58580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9b9oTd5soprXwxAH0NrgAAAGA"]
[Tue Jul 21 08:45:58.869337 2026] [security2:error] [pid 511108:tid 511346] [client 203.25.124.184:27741] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/edit-wolf.php"] [unique_id "al9b9oTd5soprXwxAH0NrwAAAGw"]
[Tue Jul 21 08:45:58.884358 2026] [security2:error] [pid 514479:tid 514570] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nyersuplementos.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9b9vzqsQqnLoCgUjhxbwABb1U"]
[Tue Jul 21 08:45:59.065931 2026] [security2:error] [pid 514479:tid 514660] [client 203.25.124.61:21871] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/includes/menu-beta.php"] [unique_id "al9b9_zqsQqnLoCgUjhxeAAAATg"]
[Tue Jul 21 08:45:59.153849 2026] [security2:error] [pid 514479:tid 514710] [client 20.197.195.24:48929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/test.php"] [unique_id "al9b9_zqsQqnLoCgUjhxegAAAWo"]
[Tue Jul 21 08:45:59.172902 2026] [security2:error] [pid 514479:tid 514576] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nyersuplementos.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9b9_zqsQqnLoCgUjhxewABSFs"]
[Tue Jul 21 08:45:59.417631 2026] [security2:error] [pid 514479:tid 514520] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nyersuplementos.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9b9_zqsQqnLoCgUjhxgwABcCQ"]
[Tue Jul 21 08:45:59.435229 2026] [security2:error] [pid 514479:tid 514699] [client 212.32.76.13:49763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/js/widgets/"] [unique_id "al9b9_zqsQqnLoCgUjhxhAAAAV8"]
[Tue Jul 21 08:45:59.461424 2026] [security2:error] [pid 514479:tid 514698] [client 65.21.113.253:59768] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9b9_zqsQqnLoCgUjhxdwAAAV4"]
[Tue Jul 21 08:45:59.622359 2026] [security2:error] [pid 514479:tid 514531] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nyersuplementos.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9b9_zqsQqnLoCgUjhxhgABay8"]
[Tue Jul 21 08:45:59.710000 2026] [security2:error] [pid 514479:tid 514593] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9b9_zqsQqnLoCgUjhxhwABUmw"]
[Tue Jul 21 08:45:59.710203 2026] [security2:error] [pid 514479:tid 514686] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9b9_zqsQqnLoCgUjhxhwABUmw"]
[Tue Jul 21 08:45:59.722083 2026] [security2:error] [pid 514479:tid 514515] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9b9_zqsQqnLoCgUjhxiAABJh8"]
[Tue Jul 21 08:45:59.722314 2026] [security2:error] [pid 514479:tid 514642] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9b9_zqsQqnLoCgUjhxiAABJh8"]
[Tue Jul 21 08:45:59.867228 2026] [security2:error] [pid 514479:tid 514559] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nyersuplementos.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9b9_zqsQqnLoCgUjhxiwABO0o"]
[Tue Jul 21 08:45:59.870721 2026] [security2:error] [pid 514479:tid 514700] [client 212.32.76.63:30401] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/2021/10/"] [unique_id "al9b9_zqsQqnLoCgUjhxjAAAAWA"]
[Tue Jul 21 08:46:00.089746 2026] [security2:error] [pid 514479:tid 514537] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nyersuplementos.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9b-PzqsQqnLoCgUjhxjwABKDU"]
[Tue Jul 21 08:46:00.258396 2026] [security2:error] [pid 511108:tid 511347] [client 203.25.124.211:26655] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/block-bindings/lib/index.php"] [unique_id "al9b-ITd5soprXwxAH0NxAAAAG0"]
[Tue Jul 21 08:46:00.305808 2026] [security2:error] [pid 514479:tid 514544] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nyersuplementos.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9b-PzqsQqnLoCgUjhxkwABVDw"]
[Tue Jul 21 08:46:00.379957 2026] [security2:error] [pid 514479:tid 514738] [client 203.25.124.42:36097] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/222.php"] [unique_id "al9b-PzqsQqnLoCgUjhxlQAAAYY"]
[Tue Jul 21 08:46:00.496161 2026] [security2:error] [pid 514479:tid 514651] [client 5.38.115.39:41971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9b-PzqsQqnLoCgUjhxmQAAAS8"]
[Tue Jul 21 08:46:00.496297 2026] [security2:error] [pid 514479:tid 514651] [client 5.38.115.39:41971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9b-PzqsQqnLoCgUjhxmQAAAS8"]
[Tue Jul 21 08:46:00.511454 2026] [security2:error] [pid 514479:tid 514588] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nyersuplementos.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9b-PzqsQqnLoCgUjhxmgABY2c"]
[Tue Jul 21 08:46:00.679202 2026] [security2:error] [pid 514479:tid 514687] [client 212.32.76.61:31935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/widgets/admin.php"] [unique_id "al9b-PzqsQqnLoCgUjhxmwAAAVM"]
[Tue Jul 21 08:46:00.715213 2026] [security2:error] [pid 514479:tid 514610] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9b-PzqsQqnLoCgUjhxnAABfX0"]
[Tue Jul 21 08:46:00.715412 2026] [security2:error] [pid 514479:tid 514729] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9b-PzqsQqnLoCgUjhxnAABfX0"]
[Tue Jul 21 08:46:00.763442 2026] [core:alert] [pid 514479:tid 514637] [client 66.249.66.74:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:46:00.790486 2026] [security2:error] [pid 514479:tid 514554] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nyersuplementos.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9b-PzqsQqnLoCgUjhxoAABbEU"]
[Tue Jul 21 08:46:00.851135 2026] [security2:error] [pid 511108:tid 511111] [remote 207.180.241.245:48576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goldentrips40.com"] [uri "/wp-login.php"] [unique_id "al9b-ITd5soprXwxAH0NzAAAEwI"]
[Tue Jul 21 08:46:00.959761 2026] [security2:error] [pid 514479:tid 514636] [client 20.197.192.193:7029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/acew67.php"] [unique_id "al9b-PzqsQqnLoCgUjhxowAAASA"]
[Tue Jul 21 08:46:01.051573 2026] [security2:error] [pid 514479:tid 514561] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nyersuplementos.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9b-fzqsQqnLoCgUjhxpAABeEw"]
[Tue Jul 21 08:46:01.093455 2026] [security2:error] [pid 514479:tid 514629] [client 20.197.195.24:17781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/aaa.php"] [unique_id "al9b-fzqsQqnLoCgUjhxpQAAARk"]
[Tue Jul 21 08:46:01.244148 2026] [security2:error] [pid 514479:tid 514638] [client 114.198.138.124:53209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9b-fzqsQqnLoCgUjhxpgAAASI"]
[Tue Jul 21 08:46:01.244255 2026] [security2:error] [pid 514479:tid 514638] [client 114.198.138.124:53209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9b-fzqsQqnLoCgUjhxpgAAASI"]
[Tue Jul 21 08:46:01.288326 2026] [security2:error] [pid 514479:tid 514578] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nyersuplementos.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9b-fzqsQqnLoCgUjhxqQABOF0"]
[Tue Jul 21 08:46:01.358653 2026] [security2:error] [pid 514479:tid 514647] [client 203.25.124.52:30573] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/network/theme-install-table.php"] [unique_id "al9b-fzqsQqnLoCgUjhxqwAAASs"]
[Tue Jul 21 08:46:01.384149 2026] [security2:error] [pid 514479:tid 514569] [remote 65.111.14.169:19335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.14.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9b-fzqsQqnLoCgUjhxrAABM1Q"]
[Tue Jul 21 08:46:01.662228 2026] [security2:error] [pid 514479:tid 514686] [client 20.197.192.193:53573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/ez.php"] [unique_id "al9b-fzqsQqnLoCgUjhxuAAAAVI"]
[Tue Jul 21 08:46:01.740374 2026] [security2:error] [pid 514479:tid 514697] [client 203.25.124.51:41319] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/aaa.php"] [unique_id "al9b-fzqsQqnLoCgUjhxvQAAAV0"]
[Tue Jul 21 08:46:01.774428 2026] [security2:error] [pid 514479:tid 514665] [client 203.25.124.191:63845] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/tinymce/themes/"] [unique_id "al9b-fzqsQqnLoCgUjhxvwAAAT0"]
[Tue Jul 21 08:46:01.892931 2026] [security2:error] [pid 514479:tid 514669] [client 113.22.144.139:58177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b-fzqsQqnLoCgUjhxwQAAAUE"]
[Tue Jul 21 08:46:01.893074 2026] [security2:error] [pid 514479:tid 514669] [client 113.22.144.139:58177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b-fzqsQqnLoCgUjhxwQAAAUE"]
[Tue Jul 21 08:46:01.927728 2026] [security2:error] [pid 514479:tid 514643] [client 20.197.192.193:53599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/fz.php"] [unique_id "al9b-fzqsQqnLoCgUjhxxQAAASc"]
[Tue Jul 21 08:46:02.007634 2026] [security2:error] [pid 514479:tid 514733] [client 103.59.206.240:31436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b-vzqsQqnLoCgUjhxyQAAAYE"]
[Tue Jul 21 08:46:02.007773 2026] [security2:error] [pid 514479:tid 514733] [client 103.59.206.240:31436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b-vzqsQqnLoCgUjhxyQAAAYE"]
[Tue Jul 21 08:46:02.019185 2026] [security2:error] [pid 514479:tid 514624] [client 20.197.192.193:41482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/la.php"] [unique_id "al9b-vzqsQqnLoCgUjhxygAAARQ"]
[Tue Jul 21 08:46:02.035801 2026] [security2:error] [pid 514479:tid 514716] [client 195.49.128.211:54135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9b-vzqsQqnLoCgUjhxywAAAXA"]
[Tue Jul 21 08:46:02.035945 2026] [security2:error] [pid 514479:tid 514716] [client 195.49.128.211:54135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9b-vzqsQqnLoCgUjhxywAAAXA"]
[Tue Jul 21 08:46:02.110258 2026] [security2:error] [pid 514479:tid 514728] [client 20.197.192.193:4041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/nhvoanpl.php"] [unique_id "al9b-vzqsQqnLoCgUjhxzAAAAXw"]
[Tue Jul 21 08:46:02.256514 2026] [security2:error] [pid 514479:tid 514732] [client 20.197.192.193:4078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/inso.php"] [unique_id "al9b-vzqsQqnLoCgUjhxzgAAAYA"]
[Tue Jul 21 08:46:02.317203 2026] [security2:error] [pid 511108:tid 511290] [client 20.197.195.24:17756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/11.php"] [unique_id "al9b-oTd5soprXwxAH0N4AAAADQ"]
[Tue Jul 21 08:46:02.357664 2026] [security2:error] [pid 514479:tid 514685] [client 20.197.192.193:53594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/wpx.php"] [unique_id "al9b-vzqsQqnLoCgUjhx1AAAAVE"]
[Tue Jul 21 08:46:02.409715 2026] [security2:error] [pid 514479:tid 514725] [client 20.197.192.193:4061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/berlin.php"] [unique_id "al9b-vzqsQqnLoCgUjhx1QAAAXk"]
[Tue Jul 21 08:46:02.473614 2026] [security2:error] [pid 511108:tid 511298] [client 20.197.192.193:4072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/billur.php"] [unique_id "al9b-oTd5soprXwxAH0N4gAAADw"]
[Tue Jul 21 08:46:02.542317 2026] [security2:error] [pid 514479:tid 514634] [client 20.197.192.193:41476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/mimpi.php"] [unique_id "al9b-vzqsQqnLoCgUjhx2gAAAR4"]
[Tue Jul 21 08:46:02.634480 2026] [security2:error] [pid 514479:tid 514625] [client 20.197.192.193:4085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/dp.php"] [unique_id "al9b-vzqsQqnLoCgUjhx3gAAARU"]
[Tue Jul 21 08:46:02.766946 2026] [security2:error] [pid 514479:tid 514706] [client 20.197.192.193:4040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/bootstrap.php"] [unique_id "al9b-vzqsQqnLoCgUjhx4AAAAWY"]
[Tue Jul 21 08:46:02.838919 2026] [security2:error] [pid 511108:tid 511300] [client 20.197.192.193:6352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/bscclapb.php"] [unique_id "al9b-oTd5soprXwxAH0N6AAAAD4"]
[Tue Jul 21 08:46:02.870249 2026] [security2:error] [pid 514479:tid 514740] [client 203.25.124.74:61811] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/chosen.php"] [unique_id "al9b-vzqsQqnLoCgUjhx4gAAAYg"]
[Tue Jul 21 08:46:02.934335 2026] [security2:error] [pid 511108:tid 511265] [client 212.32.76.9:41761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/admin.php"] [unique_id "al9b-oTd5soprXwxAH0N6wAAABs"]
[Tue Jul 21 08:46:03.074530 2026] [security2:error] [pid 511108:tid 511314] [client 203.25.124.254:60593] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/social-link/"] [unique_id "al9b-4Td5soprXwxAH0N7gAAAEw"]
[Tue Jul 21 08:46:03.367025 2026] [security2:error] [pid 511108:tid 511283] [client 20.197.195.24:48946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/mac.php"] [unique_id "al9b-4Td5soprXwxAH0N8QAAAC0"]
[Tue Jul 21 08:46:03.817218 2026] [security2:error] [pid 514479:tid 514694] [client 59.95.197.55:58553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b-_zqsQqnLoCgUjhx8QAAAVo"]
[Tue Jul 21 08:46:03.817845 2026] [security2:error] [pid 514479:tid 514694] [client 59.95.197.55:58553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b-_zqsQqnLoCgUjhx8QAAAVo"]
[Tue Jul 21 08:46:03.837602 2026] [security2:error] [pid 514479:tid 514731] [client 212.32.76.11:33281] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/inputs.php"] [unique_id "al9b-_zqsQqnLoCgUjhx8gAAAX8"]
[Tue Jul 21 08:46:03.864249 2026] [security2:error] [pid 514479:tid 514716] [client 203.25.124.52:61245] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/SimplePie/src/Content/autoload_classmap.php"] [unique_id "al9b-_zqsQqnLoCgUjhx9AAAAXA"]
[Tue Jul 21 08:46:03.936372 2026] [security2:error] [pid 514479:tid 514688] [client 195.49.128.211:62063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9b-_zqsQqnLoCgUjhx9QAAAVQ"]
[Tue Jul 21 08:46:03.936496 2026] [security2:error] [pid 514479:tid 514688] [client 195.49.128.211:62063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9b-_zqsQqnLoCgUjhx9QAAAVQ"]
[Tue Jul 21 08:46:03.998436 2026] [security2:error] [pid 511108:tid 511244] [client 20.197.192.193:53606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/wp-editor.php"] [unique_id "al9b-4Td5soprXwxAH0N-wAAAAY"]
[Tue Jul 21 08:46:04.078021 2026] [security2:error] [pid 511108:tid 511341] [client 212.32.76.63:27105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-good.php"] [unique_id "al9b_ITd5soprXwxAH0N_QAAAGc"]
[Tue Jul 21 08:46:04.528454 2026] [security2:error] [pid 514479:tid 514656] [client 65.21.113.253:59768] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9b_PzqsQqnLoCgUjhx9gAAATQ"]
[Tue Jul 21 08:46:04.533898 2026] [security2:error] [pid 514479:tid 514663] [client 122.176.100.127:60220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9b_PzqsQqnLoCgUjhx_QAAATs"]
[Tue Jul 21 08:46:04.534145 2026] [security2:error] [pid 514479:tid 514663] [client 122.176.100.127:60220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9b_PzqsQqnLoCgUjhx_QAAATs"]
[Tue Jul 21 08:46:04.838292 2026] [security2:error] [pid 511108:tid 511284] [client 203.25.124.41:20857] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/about.php"] [unique_id "al9b_ITd5soprXwxAH0OBwAAAC4"]
[Tue Jul 21 08:46:04.962051 2026] [security2:error] [pid 514479:tid 514647] [client 212.32.76.5:44195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/IXR/shadow-bot.php"] [unique_id "al9b_PzqsQqnLoCgUjhyBAAAASs"]
[Tue Jul 21 08:46:05.093828 2026] [security2:error] [pid 514479:tid 514724] [client 49.144.66.253:30425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9b_fzqsQqnLoCgUjhyCgAAAXg"]
[Tue Jul 21 08:46:05.093995 2026] [security2:error] [pid 514479:tid 514724] [client 49.144.66.253:30425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9b_fzqsQqnLoCgUjhyCgAAAXg"]
[Tue Jul 21 08:46:05.375823 2026] [security2:error] [pid 514479:tid 514660] [client 203.25.124.200:39829] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/elementor/css/"] [unique_id "al9b_fzqsQqnLoCgUjhyFwAAATg"]
[Tue Jul 21 08:46:05.481208 2026] [security2:error] [pid 514479:tid 514699] [client 20.197.195.24:17837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/chosen.php"] [unique_id "al9b_fzqsQqnLoCgUjhyGQAAAV8"]
[Tue Jul 21 08:46:05.559827 2026] [security2:error] [pid 514479:tid 514620] [client 173.252.95.11:41942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9b_fzqsQqnLoCgUjhyGgAAARA"]
[Tue Jul 21 08:46:05.664104 2026] [security2:error] [pid 511108:tid 511319] [client 203.25.124.41:47215] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/chosen.php"] [unique_id "al9b_YTd5soprXwxAH0OEgAAAFE"]
[Tue Jul 21 08:46:05.840049 2026] [security2:error] [pid 514479:tid 514641] [client 212.32.76.12:42877] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/speculative8.php"] [unique_id "al9b_fzqsQqnLoCgUjhyIQAAASU"]
[Tue Jul 21 08:46:05.967332 2026] [security2:error] [pid 514479:tid 514741] [client 41.89.234.2:61934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b_fzqsQqnLoCgUjhyJAAAAYk"]
[Tue Jul 21 08:46:05.967456 2026] [security2:error] [pid 514479:tid 514741] [client 41.89.234.2:61934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9b_fzqsQqnLoCgUjhyJAAAAYk"]
[Tue Jul 21 08:46:06.176614 2026] [security2:error] [pid 514479:tid 514728] [client 203.25.124.185:63857] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/config.php"] [unique_id "al9b_vzqsQqnLoCgUjhyKAAAAXw"]
[Tue Jul 21 08:46:06.566909 2026] [security2:error] [pid 514479:tid 514718] [client 203.25.124.36:58829] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/prenota/gecko.php"] [unique_id "al9b_vzqsQqnLoCgUjhyMQAAAXI"]
[Tue Jul 21 08:46:06.574002 2026] [security2:error] [pid 514479:tid 514616] [client 20.197.195.24:2790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/cream1.php"] [unique_id "al9b_vzqsQqnLoCgUjhyMgAAAQw"]
[Tue Jul 21 08:46:06.729375 2026] [security2:error] [pid 511108:tid 511165] [remote 192.241.143.148:48980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9b_oTd5soprXwxAH0OIAAAWjg"]
[Tue Jul 21 08:46:06.812085 2026] [security2:error] [pid 511108:tid 511236] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9b_oTd5soprXwxAH0OIgAANH8"]
[Tue Jul 21 08:46:06.812282 2026] [security2:error] [pid 511108:tid 511290] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9b_oTd5soprXwxAH0OIgAANH8"]
[Tue Jul 21 08:46:06.943392 2026] [security2:error] [pid 511108:tid 511300] [client 203.25.124.37:54931] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/radio.php"] [unique_id "al9b_oTd5soprXwxAH0OJQAAAD4"]
[Tue Jul 21 08:46:07.269893 2026] [security2:error] [pid 511108:tid 511282] [client 203.25.124.188:61481] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "al9b_4Td5soprXwxAH0OKgAAACw"]
[Tue Jul 21 08:46:07.271319 2026] [security2:error] [pid 511108:tid 511274] [client 20.197.192.193:53615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/cro.php"] [unique_id "al9b_4Td5soprXwxAH0OKwAAACQ"]
[Tue Jul 21 08:46:07.663633 2026] [security2:error] [pid 514479:tid 514700] [client 203.25.124.51:49769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/css/as.php"] [unique_id "al9b__zqsQqnLoCgUjhyPAAAAWA"]
[Tue Jul 21 08:46:08.074433 2026] [security2:error] [pid 511108:tid 511244] [client 203.25.124.209:39645] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/theme-compat/chosen.php"] [unique_id "al9cAITd5soprXwxAH0OPQAAAAY"]
[Tue Jul 21 08:46:08.108121 2026] [security2:error] [pid 514479:tid 514710] [client 168.167.81.163:63943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cAPzqsQqnLoCgUjhyRQAAAWo"]
[Tue Jul 21 08:46:08.108231 2026] [security2:error] [pid 514479:tid 514710] [client 168.167.81.163:63943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cAPzqsQqnLoCgUjhyRQAAAWo"]
[Tue Jul 21 08:46:08.124382 2026] [security2:error] [pid 514479:tid 514665] [client 198.44.157.34:39476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9cAPzqsQqnLoCgUjhyRgAAAT0"]
[Tue Jul 21 08:46:08.124475 2026] [security2:error] [pid 514479:tid 514665] [client 198.44.157.34:39476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9cAPzqsQqnLoCgUjhyRgAAAT0"]
[Tue Jul 21 08:46:08.249509 2026] [security2:error] [pid 514479:tid 514739] [client 203.25.124.64:23305] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/js/"] [unique_id "al9cAPzqsQqnLoCgUjhySgAAAYc"]
[Tue Jul 21 08:46:08.327613 2026] [security2:error] [pid 514479:tid 514727] [client 62.164.177.222:49294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enernordeste.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cAPzqsQqnLoCgUjhyTQAAAXs"]
[Tue Jul 21 08:46:08.327738 2026] [security2:error] [pid 514479:tid 514727] [client 62.164.177.222:49294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "enernordeste.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cAPzqsQqnLoCgUjhyTQAAAXs"]
[Tue Jul 21 08:46:08.622114 2026] [security2:error] [pid 514479:tid 514678] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cAPzqsQqnLoCgUjhyTwABSgY"]
[Tue Jul 21 08:46:08.738899 2026] [security2:error] [pid 514479:tid 514624] [client 64.42.179.43:33428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9cAPzqsQqnLoCgUjhyUQAAARQ"]
[Tue Jul 21 08:46:08.739032 2026] [security2:error] [pid 514479:tid 514624] [client 64.42.179.43:33428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9cAPzqsQqnLoCgUjhyUQAAARQ"]
[Tue Jul 21 08:46:08.801631 2026] [security2:error] [pid 514479:tid 514705] [client 20.197.192.193:6395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/else1.php"] [unique_id "al9cAPzqsQqnLoCgUjhyVAAAAWU"]
[Tue Jul 21 08:46:08.827943 2026] [security2:error] [pid 514479:tid 514717] [client 202.179.75.202:51632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cAPzqsQqnLoCgUjhyVQAAAXE"]
[Tue Jul 21 08:46:08.828073 2026] [security2:error] [pid 514479:tid 514717] [client 202.179.75.202:51632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cAPzqsQqnLoCgUjhyVQAAAXE"]
[Tue Jul 21 08:46:08.998444 2026] [security2:error] [pid 511108:tid 511337] [client 20.197.195.24:17827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/dr.php"] [unique_id "al9cAITd5soprXwxAH0OTgAAAGM"]
[Tue Jul 21 08:46:09.034704 2026] [security2:error] [pid 514479:tid 514652] [client 62.164.177.222:53478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enernordeste.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cAfzqsQqnLoCgUjhyWAAAATA"]
[Tue Jul 21 08:46:09.034840 2026] [security2:error] [pid 514479:tid 514652] [client 62.164.177.222:53478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "enernordeste.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cAfzqsQqnLoCgUjhyWAAAATA"]
[Tue Jul 21 08:46:09.076372 2026] [security2:error] [pid 514479:tid 514622] [client 212.32.76.63:26517] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/root.php"] [unique_id "al9cAfzqsQqnLoCgUjhyWQAAARI"]
[Tue Jul 21 08:46:09.740738 2026] [security2:error] [pid 514479:tid 514659] [client 203.25.124.66:65449] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/updates.php"] [unique_id "al9cAfzqsQqnLoCgUjhyZgAAATc"]
[Tue Jul 21 08:46:09.915617 2026] [security2:error] [pid 514479:tid 514645] [client 62.164.177.222:58032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enernordeste.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9cAfzqsQqnLoCgUjhyagAAASk"]
[Tue Jul 21 08:46:09.915716 2026] [security2:error] [pid 514479:tid 514645] [client 62.164.177.222:58032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "enernordeste.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9cAfzqsQqnLoCgUjhyagAAASk"]
[Tue Jul 21 08:46:10.059826 2026] [security2:error] [pid 514479:tid 514733] [client 20.197.195.24:17815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/x.php"] [unique_id "al9cAvzqsQqnLoCgUjhybAAAAYE"]
[Tue Jul 21 08:46:10.071964 2026] [security2:error] [pid 514479:tid 514724] [client 212.32.76.57:50713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/widgets/"] [unique_id "al9cAvzqsQqnLoCgUjhybgAAAXg"]
[Tue Jul 21 08:46:10.161670 2026] [security2:error] [pid 514479:tid 514484] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cAvzqsQqnLoCgUjhycgABOQA"]
[Tue Jul 21 08:46:10.161887 2026] [security2:error] [pid 514479:tid 514661] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cAvzqsQqnLoCgUjhycgABOQA"]
[Tue Jul 21 08:46:10.286162 2026] [security2:error] [pid 514479:tid 514571] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cAvzqsQqnLoCgUjhydQABGFY"]
[Tue Jul 21 08:46:10.286297 2026] [security2:error] [pid 514479:tid 514628] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cAvzqsQqnLoCgUjhydQABGFY"]
[Tue Jul 21 08:46:10.333078 2026] [security2:error] [pid 514479:tid 514630] [client 20.197.192.193:6896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/tkikikoko.php"] [unique_id "al9cAvzqsQqnLoCgUjhydgAAARo"]
[Tue Jul 21 08:46:10.621705 2026] [security2:error] [pid 514479:tid 514623] [client 62.164.177.222:34660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enernordeste.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9cAvzqsQqnLoCgUjhyegAAARM"]
[Tue Jul 21 08:46:10.621800 2026] [security2:error] [pid 514479:tid 514623] [client 62.164.177.222:34660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "enernordeste.com.br"] [uri "/wp/xmlrpc.php"] [unique_id "al9cAvzqsQqnLoCgUjhyegAAARM"]
[Tue Jul 21 08:46:10.827102 2026] [security2:error] [pid 514479:tid 514641] [client 20.197.192.193:27176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/bootstrap.php"] [unique_id "al9cAvzqsQqnLoCgUjhyfAAAASU"]
[Tue Jul 21 08:46:10.837439 2026] [security2:error] [pid 514479:tid 514671] [client 203.25.124.61:43845] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/colors/blue/"] [unique_id "al9cAvzqsQqnLoCgUjhyfQAAAUM"]
[Tue Jul 21 08:46:11.039398 2026] [security2:error] [pid 514479:tid 514681] [client 212.32.76.12:42791] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/home-link/wp-login.php"] [unique_id "al9cAPzqsQqnLoCgUjhyVgAAAU0"]
[Tue Jul 21 08:46:11.040212 2026] [security2:error] [pid 514479:tid 514717] [client 20.197.195.24:48981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/155.php"] [unique_id "al9cA_zqsQqnLoCgUjhygwAAAXE"]
[Tue Jul 21 08:46:11.040439 2026] [security2:error] [pid 514479:tid 514660] [client 5.38.115.39:56566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cA_zqsQqnLoCgUjhyhAAAATg"]
[Tue Jul 21 08:46:11.040522 2026] [security2:error] [pid 514479:tid 514660] [client 5.38.115.39:56566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cA_zqsQqnLoCgUjhyhAAAATg"]
[Tue Jul 21 08:46:11.079367 2026] [security2:error] [pid 514479:tid 514653] [client 203.25.124.197:44427] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/class.php"] [unique_id "al9cA_zqsQqnLoCgUjhyhgAAATE"]
[Tue Jul 21 08:46:11.223176 2026] [security2:error] [pid 514479:tid 514692] [client 61.1.167.83:63157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cA_zqsQqnLoCgUjhyiAAAAVg"]
[Tue Jul 21 08:46:11.223300 2026] [security2:error] [pid 514479:tid 514692] [client 61.1.167.83:63157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cA_zqsQqnLoCgUjhyiAAAAVg"]
[Tue Jul 21 08:46:11.239716 2026] [security2:error] [pid 514479:tid 514608] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cA_zqsQqnLoCgUjhyiQABens"]
[Tue Jul 21 08:46:11.239992 2026] [security2:error] [pid 514479:tid 514726] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cA_zqsQqnLoCgUjhyiQABens"]
[Tue Jul 21 08:46:11.311917 2026] [security2:error] [pid 511108:tid 511273] [client 65.21.113.253:50048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cAoTd5soprXwxAH0OZgAAACM"]
[Tue Jul 21 08:46:11.333426 2026] [security2:error] [pid 514479:tid 514690] [client 62.164.177.222:38646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enernordeste.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "al9cA_zqsQqnLoCgUjhyjAAAAVY"]
[Tue Jul 21 08:46:11.333523 2026] [security2:error] [pid 514479:tid 514690] [client 62.164.177.222:38646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "enernordeste.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "al9cA_zqsQqnLoCgUjhyjAAAAVY"]
[Tue Jul 21 08:46:11.754009 2026] [security2:error] [pid 511108:tid 511285] [client 114.198.138.124:53775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cA4Td5soprXwxAH0OdQAAAC8"]
[Tue Jul 21 08:46:11.754117 2026] [security2:error] [pid 511108:tid 511285] [client 114.198.138.124:53775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cA4Td5soprXwxAH0OdQAAAC8"]
[Tue Jul 21 08:46:11.943860 2026] [security2:error] [pid 514479:tid 514627] [client 203.25.124.43:48311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/theme-compat/"] [unique_id "al9cA_zqsQqnLoCgUjhykwAAARc"]
[Tue Jul 21 08:46:11.969448 2026] [security2:error] [pid 511108:tid 511239] [client 203.25.124.3:44235] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "al9cA4Td5soprXwxAH0OeAAAAAE"]
[Tue Jul 21 08:46:12.040217 2026] [security2:error] [pid 514479:tid 514667] [client 62.164.177.222:42794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enernordeste.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9cBPzqsQqnLoCgUjhylwAAAT8"]
[Tue Jul 21 08:46:12.040303 2026] [security2:error] [pid 514479:tid 514667] [client 62.164.177.222:42794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "enernordeste.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9cBPzqsQqnLoCgUjhylwAAAT8"]
[Tue Jul 21 08:46:12.060930 2026] [security2:error] [pid 514479:tid 514715] [client 212.32.76.8:53471] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/fix/admin.php"] [unique_id "al9cBPzqsQqnLoCgUjhymAAAAW8"]
[Tue Jul 21 08:46:12.566310 2026] [security2:error] [pid 514479:tid 514721] [client 20.197.192.193:6894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9cBPzqsQqnLoCgUjhynAAAAXU"]
[Tue Jul 21 08:46:12.670696 2026] [security2:error] [pid 514479:tid 514629] [client 195.49.128.211:54742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9cBPzqsQqnLoCgUjhyoAAAARk"]
[Tue Jul 21 08:46:12.670832 2026] [security2:error] [pid 514479:tid 514629] [client 195.49.128.211:54742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9cBPzqsQqnLoCgUjhyoAAAARk"]
[Tue Jul 21 08:46:12.728480 2026] [security2:error] [pid 514479:tid 514672] [client 113.22.144.139:58679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cBPzqsQqnLoCgUjhyoQAAAUQ"]
[Tue Jul 21 08:46:12.729179 2026] [security2:error] [pid 514479:tid 514672] [client 113.22.144.139:58679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cBPzqsQqnLoCgUjhyoQAAAUQ"]
[Tue Jul 21 08:46:12.762400 2026] [security2:error] [pid 514479:tid 514661] [client 203.25.124.212:34317] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/fix/ioxi-o.php"] [unique_id "al9cBPzqsQqnLoCgUjhypAAAATk"]
[Tue Jul 21 08:46:12.857964 2026] [security2:error] [pid 514479:tid 514700] [client 74.7.241.156:43100] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.fabrikadosuplemento.com"] [uri "/cgi-sys/404.html"] [unique_id "al9cBPzqsQqnLoCgUjhypgABYCw"]
[Tue Jul 21 08:46:12.894161 2026] [security2:error] [pid 514479:tid 514642] [client 62.164.177.222:48138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enernordeste.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9cBPzqsQqnLoCgUjhypwAAASY"]
[Tue Jul 21 08:46:12.894269 2026] [security2:error] [pid 514479:tid 514642] [client 62.164.177.222:48138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "enernordeste.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9cBPzqsQqnLoCgUjhypwAAASY"]
[Tue Jul 21 08:46:12.934776 2026] [security2:error] [pid 514479:tid 514640] [client 20.197.192.193:53630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/cron-tab.php"] [unique_id "al9cBPzqsQqnLoCgUjhyqAAAASQ"]
[Tue Jul 21 08:46:13.050344 2026] [security2:error] [pid 514479:tid 514714] [client 203.25.124.211:24987] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/"] [unique_id "al9cBfzqsQqnLoCgUjhyrgAAAW4"]
[Tue Jul 21 08:46:13.076054 2026] [security2:error] [pid 514479:tid 514675] [client 203.25.124.7:31639] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/news-portal/admins-dir.php"] [unique_id "al9cBfzqsQqnLoCgUjhyrwAAAUc"]
[Tue Jul 21 08:46:13.173720 2026] [security2:error] [pid 514479:tid 514671] [client 20.197.192.193:6867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/wp-css.php"] [unique_id "al9cBfzqsQqnLoCgUjhysQAAAUM"]
[Tue Jul 21 08:46:13.269286 2026] [security2:error] [pid 514479:tid 514686] [client 20.197.192.193:6992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/wp-explorer.php"] [unique_id "al9cBfzqsQqnLoCgUjhyswAAAVI"]
[Tue Jul 21 08:46:13.389225 2026] [security2:error] [pid 514479:tid 514660] [client 20.197.192.193:6384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/akismet.php"] [unique_id "al9cBfzqsQqnLoCgUjhytAAAATg"]
[Tue Jul 21 08:46:13.545022 2026] [security2:error] [pid 511108:tid 511360] [client 20.197.195.24:48939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/ops.php"] [unique_id "al9cBYTd5soprXwxAH0OjgAAAHo"]
[Tue Jul 21 08:46:13.548418 2026] [security2:error] [pid 514479:tid 514741] [client 20.197.192.193:6344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/ace2.php"] [unique_id "al9cBfzqsQqnLoCgUjhytQAAAYk"]
[Tue Jul 21 08:46:13.602968 2026] [security2:error] [pid 511108:tid 511357] [client 62.164.177.222:52486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enernordeste.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9cBYTd5soprXwxAH0OkQAAAHc"]
[Tue Jul 21 08:46:13.603064 2026] [security2:error] [pid 511108:tid 511357] [client 62.164.177.222:52486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "enernordeste.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9cBYTd5soprXwxAH0OkQAAAHc"]
[Tue Jul 21 08:46:13.612662 2026] [security2:error] [pid 514479:tid 514703] [client 173.252.95.9:59352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cBfzqsQqnLoCgUjhytwAAAWM"]
[Tue Jul 21 08:46:13.664665 2026] [security2:error] [pid 511108:tid 511291] [client 203.25.124.212:65303] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/ioxi-o.php"] [unique_id "al9cBYTd5soprXwxAH0OkgAAADU"]
[Tue Jul 21 08:46:13.821725 2026] [security2:error] [pid 514479:tid 514690] [client 172.86.119.116:46960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "linkmaster.net.br"] [uri "/"] [unique_id "al9cBfzqsQqnLoCgUjhyugAAAVY"]
[Tue Jul 21 08:46:14.257388 2026] [security2:error] [pid 511108:tid 511311] [client 69.171.230.28:57056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cBoTd5soprXwxAH0OmQAAAEk"]
[Tue Jul 21 08:46:14.311016 2026] [security2:error] [pid 514479:tid 514657] [client 62.164.177.222:56778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enernordeste.com.br"] [uri "/wp-site/xmlrpc.php"] [unique_id "al9cBvzqsQqnLoCgUjhywQAAATU"]
[Tue Jul 21 08:46:14.311111 2026] [security2:error] [pid 514479:tid 514657] [client 62.164.177.222:56778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "enernordeste.com.br"] [uri "/wp-site/xmlrpc.php"] [unique_id "al9cBvzqsQqnLoCgUjhywQAAATU"]
[Tue Jul 21 08:46:14.328360 2026] [security2:error] [pid 514479:tid 514684] [client 59.95.197.55:59034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cBvzqsQqnLoCgUjhywgAAAVA"]
[Tue Jul 21 08:46:14.328494 2026] [security2:error] [pid 514479:tid 514684] [client 59.95.197.55:59034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cBvzqsQqnLoCgUjhywgAAAVA"]
[Tue Jul 21 08:46:14.340342 2026] [security2:error] [pid 514479:tid 514627] [client 203.25.124.33:40745] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/languages/plugins/"] [unique_id "al9cBvzqsQqnLoCgUjhywwAAARc"]
[Tue Jul 21 08:46:14.375577 2026] [security2:error] [pid 514479:tid 514719] [client 203.25.124.6:34717] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/js/chosen.php"] [unique_id "al9cBvzqsQqnLoCgUjhyxAAAAXM"]
[Tue Jul 21 08:46:14.530325 2026] [security2:error] [pid 514479:tid 514707] [client 195.49.128.211:62787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cBvzqsQqnLoCgUjhyxQAAAWc"]
[Tue Jul 21 08:46:14.530450 2026] [security2:error] [pid 514479:tid 514707] [client 195.49.128.211:62787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cBvzqsQqnLoCgUjhyxQAAAWc"]
[Tue Jul 21 08:46:14.824528 2026] [security2:error] [pid 514479:tid 514645] [client 176.31.139.24:30428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "oficialwebsite.com.br"] [uri "/robots.txt"] [unique_id "al9cBvzqsQqnLoCgUjhyyQAAASk"]
[Tue Jul 21 08:46:14.824634 2026] [security2:error] [pid 514479:tid 514645] [client 176.31.139.24:30428] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "oficialwebsite.com.br"] [uri "/robots.txt"] [unique_id "al9cBvzqsQqnLoCgUjhyyQAAASk"]
[Tue Jul 21 08:46:14.973752 2026] [security2:error] [pid 514479:tid 514634] [client 69.171.230.3:52446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cBvzqsQqnLoCgUjhyzAAAAR4"]
[Tue Jul 21 08:46:15.010779 2026] [security2:error] [pid 511108:tid 511365] [client 122.176.100.127:60704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cB4Td5soprXwxAH0OqAAAAH8"]
[Tue Jul 21 08:46:15.011138 2026] [security2:error] [pid 511108:tid 511365] [client 122.176.100.127:60704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cB4Td5soprXwxAH0OqAAAAH8"]
[Tue Jul 21 08:46:15.018584 2026] [security2:error] [pid 511108:tid 511300] [client 62.164.177.222:60992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enernordeste.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9cB4Td5soprXwxAH0OqQAAAD4"]
[Tue Jul 21 08:46:15.018667 2026] [security2:error] [pid 511108:tid 511300] [client 62.164.177.222:60992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "enernordeste.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9cB4Td5soprXwxAH0OqQAAAD4"]
[Tue Jul 21 08:46:15.165750 2026] [security2:error] [pid 514479:tid 514651] [client 212.32.76.60:21259] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/classwithtostring.php"] [unique_id "al9cB_zqsQqnLoCgUjhy0gAAAS8"]
[Tue Jul 21 08:46:15.176331 2026] [security2:error] [pid 511108:tid 511349] [client 172.86.119.116:46966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.linkmaster.net.br"] [uri "/"] [unique_id "al9cB4Td5soprXwxAH0OqwAAAG8"]
[Tue Jul 21 08:46:15.355875 2026] [security2:error] [pid 511108:tid 511282] [client 203.25.124.73:36227] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/ioxi-o.php"] [unique_id "al9cB4Td5soprXwxAH0OrQAAACw"]
[Tue Jul 21 08:46:15.406660 2026] [security2:error] [pid 514479:tid 514621] [client 20.151.10.161:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9cB_zqsQqnLoCgUjhy0wAAARE"]
[Tue Jul 21 08:46:15.406746 2026] [security2:error] [pid 514479:tid 514704] [client 49.144.66.253:30814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cB_zqsQqnLoCgUjhy1AAAAWQ"]
[Tue Jul 21 08:46:15.406844 2026] [security2:error] [pid 514479:tid 514704] [client 49.144.66.253:30814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cB_zqsQqnLoCgUjhy1AAAAWQ"]
[Tue Jul 21 08:46:15.524994 2026] [security2:error] [pid 514479:tid 514699] [client 20.197.192.193:6873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "parquepradoimoveis.com.br"] [uri "/ms.php"] [unique_id "al9cB_zqsQqnLoCgUjhy2AAAAV8"]
[Tue Jul 21 08:46:15.545159 2026] [security2:error] [pid 514479:tid 514665] [client 62.164.177.222:35822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enernordeste.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9cB_zqsQqnLoCgUjhy2QAAAT0"]
[Tue Jul 21 08:46:15.545261 2026] [security2:error] [pid 514479:tid 514665] [client 62.164.177.222:35822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "enernordeste.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9cB_zqsQqnLoCgUjhy2QAAAT0"]
[Tue Jul 21 08:46:15.655269 2026] [security2:error] [pid 511108:tid 511278] [client 203.25.124.43:62979] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wpx/index.php"] [unique_id "al9cB4Td5soprXwxAH0OsgAAACg"]
[Tue Jul 21 08:46:16.147206 2026] [security2:error] [pid 514479:tid 514733] [client 203.25.124.70:33521] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/IXR/"] [unique_id "al9cCPzqsQqnLoCgUjhy4QAAAYE"]
[Tue Jul 21 08:46:16.242281 2026] [security2:error] [pid 511108:tid 511245] [client 15.235.27.42:55904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "oficialwebsite.com.br"] [uri "/"] [unique_id "al9cCITd5soprXwxAH0OvAAAAAc"]
[Tue Jul 21 08:46:16.242407 2026] [security2:error] [pid 511108:tid 511245] [client 15.235.27.42:55904] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "oficialwebsite.com.br"] [uri "/"] [unique_id "al9cCITd5soprXwxAH0OvAAAAAc"]
[Tue Jul 21 08:46:16.273293 2026] [security2:error] [pid 511108:tid 511269] [client 203.25.124.183:47677] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwentytwo/templates/"] [unique_id "al9cCITd5soprXwxAH0OvgAAAB8"]
[Tue Jul 21 08:46:16.300658 2026] [security2:error] [pid 511108:tid 511260] [client 20.197.192.193:4045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/koiy.php"] [unique_id "al9cCITd5soprXwxAH0OwgAAABY"]
[Tue Jul 21 08:46:16.362754 2026] [security2:error] [pid 511108:tid 511272] [client 203.25.124.50:32917] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-matcha1.php"] [unique_id "al9cCITd5soprXwxAH0OxAAAACI"]
[Tue Jul 21 08:46:16.501536 2026] [security2:error] [pid 511108:tid 511281] [client 41.89.234.2:62381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cCITd5soprXwxAH0OxQAAACs"]
[Tue Jul 21 08:46:16.501707 2026] [security2:error] [pid 511108:tid 511281] [client 41.89.234.2:62381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cCITd5soprXwxAH0OxQAAACs"]
[Tue Jul 21 08:46:16.637214 2026] [security2:error] [pid 511108:tid 511297] [client 65.21.113.253:50048] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cCITd5soprXwxAH0OuwAAADs"]
[Tue Jul 21 08:46:16.784069 2026] [security2:error] [pid 511108:tid 511363] [client 62.164.177.222:38674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "enernordeste.com.br"] [uri "/wp-login.php"] [unique_id "al9cCITd5soprXwxAH0OzQAAAH0"]
[Tue Jul 21 08:46:16.973330 2026] [security2:error] [pid 514479:tid 514530] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cCPzqsQqnLoCgUjhy6AABWC4"]
[Tue Jul 21 08:46:16.973457 2026] [security2:error] [pid 514479:tid 514692] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cCPzqsQqnLoCgUjhy6AABWC4"]
[Tue Jul 21 08:46:17.165183 2026] [security2:error] [pid 511108:tid 511299] [client 203.25.124.40:36133] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwenty/assets/js/index.php"] [unique_id "al9cCYTd5soprXwxAH0O1AAAAD0"]
[Tue Jul 21 08:46:17.242295 2026] [security2:error] [pid 514479:tid 514601] [remote 8.217.108.67:48944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinicius-schneider.com"] [uri "/wp-login.php"] [unique_id "al9cCfzqsQqnLoCgUjhy7QABMXQ"]
[Tue Jul 21 08:46:17.280202 2026] [security2:error] [pid 511108:tid 511286] [client 20.197.195.24:48974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/file31.php"] [unique_id "al9cCYTd5soprXwxAH0O2gAAADA"]
[Tue Jul 21 08:46:17.881591 2026] [security2:error] [pid 511108:tid 511365] [client 198.44.157.34:48344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9cCYTd5soprXwxAH0O5QAAAH8"]
[Tue Jul 21 08:46:17.881714 2026] [security2:error] [pid 511108:tid 511365] [client 198.44.157.34:48344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9cCYTd5soprXwxAH0O5QAAAH8"]
[Tue Jul 21 08:46:17.882526 2026] [security2:error] [pid 514479:tid 514723] [client 203.25.124.3:39329] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Requests/src/Utility/"] [unique_id "al9cCfzqsQqnLoCgUjhy9gAAAXc"]
[Tue Jul 21 08:46:18.000827 2026] [access_compat:error] [pid 511108:tid 511259] [client 162.241.63.68:25842] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:46:18.077175 2026] [security2:error] [pid 511108:tid 511343] [client 20.151.10.161:62444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9cCoTd5soprXwxAH0O6wAAAGk"]
[Tue Jul 21 08:46:18.170127 2026] [security2:error] [pid 514479:tid 514634] [client 203.25.124.36:49405] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/dlex/dlex.php"] [unique_id "al9cCvzqsQqnLoCgUjhy-AAAAR4"]
[Tue Jul 21 08:46:18.630861 2026] [security2:error] [pid 511108:tid 511308] [client 203.25.124.70:44673] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/404.php"] [unique_id "al9cCoTd5soprXwxAH0O-QAAAEY"]
[Tue Jul 21 08:46:18.651488 2026] [security2:error] [pid 511108:tid 511290] [client 20.151.10.161:62429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/x.php"] [unique_id "al9cCoTd5soprXwxAH0O-wAAADQ"]
[Tue Jul 21 08:46:18.678692 2026] [security2:error] [pid 514479:tid 514667] [client 168.167.81.163:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cCvzqsQqnLoCgUjhy-wAAAT8"]
[Tue Jul 21 08:46:18.678789 2026] [security2:error] [pid 514479:tid 514667] [client 168.167.81.163:61395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cCvzqsQqnLoCgUjhy-wAAAT8"]
[Tue Jul 21 08:46:18.971666 2026] [security2:error] [pid 514479:tid 514617] [client 182.70.243.214:62334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.243.70.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingfans.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cCvzqsQqnLoCgUjhy_wAAAQ0"]
[Tue Jul 21 08:46:18.971829 2026] [security2:error] [pid 514479:tid 514617] [client 182.70.243.214:62334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kingfans.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cCvzqsQqnLoCgUjhy_wAAAQ0"]
[Tue Jul 21 08:46:18.984310 2026] [security2:error] [pid 514479:tid 514711] [client 20.197.192.193:27182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-editor.php"] [unique_id "al9cCvzqsQqnLoCgUjhzAAAAAWs"]
[Tue Jul 21 08:46:19.164320 2026] [security2:error] [pid 514479:tid 514664] [client 203.25.124.48:40027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/view-source/ioxi-o.php"] [unique_id "al9cC_zqsQqnLoCgUjhzAgAAATw"]
[Tue Jul 21 08:46:19.274583 2026] [security2:error] [pid 511108:tid 511314] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cC4Td5soprXwxAH0PBAAATEM"]
[Tue Jul 21 08:46:19.591012 2026] [security2:error] [pid 514479:tid 514631] [client 20.197.195.24:59844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/file6.php"] [unique_id "al9cC_zqsQqnLoCgUjhzCgAAARs"]
[Tue Jul 21 08:46:19.615925 2026] [security2:error] [pid 514479:tid 514725] [client 20.151.10.161:62443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/j260624_13.php"] [unique_id "al9cC_zqsQqnLoCgUjhzCwAAAXk"]
[Tue Jul 21 08:46:19.730119 2026] [security2:error] [pid 511108:tid 511342] [client 202.179.75.202:47856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cC4Td5soprXwxAH0PEAAAAGg"]
[Tue Jul 21 08:46:19.730250 2026] [security2:error] [pid 511108:tid 511342] [client 202.179.75.202:47856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cC4Td5soprXwxAH0PEAAAAGg"]
[Tue Jul 21 08:46:20.064754 2026] [security2:error] [pid 514479:tid 514632] [client 203.25.124.211:38849] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/network/cache/index.php"] [unique_id "al9cDPzqsQqnLoCgUjhzDgAAARw"]
[Tue Jul 21 08:46:20.177127 2026] [security2:error] [pid 514479:tid 514615] [client 203.25.124.246:35419] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "al9cDPzqsQqnLoCgUjhzEAAAAQs"]
[Tue Jul 21 08:46:20.196800 2026] [security2:error] [pid 511108:tid 511286] [client 198.44.157.34:43842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9cDITd5soprXwxAH0PHAAAADA"]
[Tue Jul 21 08:46:20.196913 2026] [security2:error] [pid 511108:tid 511286] [client 198.44.157.34:43842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9cDITd5soprXwxAH0PHAAAADA"]
[Tue Jul 21 08:46:20.316489 2026] [security2:error] [pid 511108:tid 511353] [client 20.151.10.161:62415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/d62.php"] [unique_id "al9cDITd5soprXwxAH0PHQAAAHM"]
[Tue Jul 21 08:46:20.332003 2026] [security2:error] [pid 511108:tid 511188] [remote 31.59.129.193:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "focsmart.com.br"] [uri "/application.yml"] [unique_id "al9cDITd5soprXwxAH0PHgAASU8"]
[Tue Jul 21 08:46:20.339528 2026] [security2:error] [pid 514479:tid 514694] [client 203.25.124.72:25555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/mah.php"] [unique_id "al9cDPzqsQqnLoCgUjhzEwAAAVo"]
[Tue Jul 21 08:46:20.493686 2026] [security2:error] [pid 514479:tid 514714] [client 5.31.193.106:1853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cDPzqsQqnLoCgUjhzFgAAAW4"]
[Tue Jul 21 08:46:20.493802 2026] [security2:error] [pid 514479:tid 514714] [client 5.31.193.106:1853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cDPzqsQqnLoCgUjhzFgAAAW4"]
[Tue Jul 21 08:46:20.591338 2026] [security2:error] [pid 514479:tid 514538] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cDPzqsQqnLoCgUjhzFwABfzY"]
[Tue Jul 21 08:46:20.591466 2026] [security2:error] [pid 514479:tid 514731] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cDPzqsQqnLoCgUjhzFwABfzY"]
[Tue Jul 21 08:46:20.683195 2026] [security2:error] [pid 514479:tid 514618] [client 64.42.179.43:32906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9cDPzqsQqnLoCgUjhzGAAAAQ4"]
[Tue Jul 21 08:46:20.683316 2026] [security2:error] [pid 514479:tid 514618] [client 64.42.179.43:32906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9cDPzqsQqnLoCgUjhzGAAAAQ4"]
[Tue Jul 21 08:46:20.765363 2026] [security2:error] [pid 514479:tid 514689] [client 203.25.124.36:26003] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/table/table/updater-tool.php"] [unique_id "al9cDPzqsQqnLoCgUjhzGQAAAVU"]
[Tue Jul 21 08:46:20.794011 2026] [security2:error] [pid 514479:tid 514653] [client 20.197.192.193:27178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/cro.php"] [unique_id "al9cDPzqsQqnLoCgUjhzGgAAATE"]
[Tue Jul 21 08:46:20.809470 2026] [security2:error] [pid 514479:tid 514598] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cDPzqsQqnLoCgUjhzGwABVnE"]
[Tue Jul 21 08:46:20.809568 2026] [security2:error] [pid 514479:tid 514690] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cDPzqsQqnLoCgUjhzGwABVnE"]
[Tue Jul 21 08:46:21.007689 2026] [security2:error] [pid 511108:tid 511364] [client 20.151.10.161:62434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/ups.php"] [unique_id "al9cDYTd5soprXwxAH0PMQAAAH4"]
[Tue Jul 21 08:46:21.070435 2026] [security2:error] [pid 514479:tid 514646] [client 203.25.124.246:34947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/lock360.php"] [unique_id "al9cDfzqsQqnLoCgUjhzIQAAASo"]
[Tue Jul 21 08:46:21.439867 2026] [security2:error] [pid 514479:tid 514672] [client 203.25.124.39:21541] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/"] [unique_id "al9cDfzqsQqnLoCgUjhzTgAAAUQ"]
[Tue Jul 21 08:46:21.535590 2026] [security2:error] [pid 511108:tid 511265] [client 20.151.10.161:62410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/k.php"] [unique_id "al9cDYTd5soprXwxAH0POAAAABs"]
[Tue Jul 21 08:46:21.737052 2026] [security2:error] [pid 514479:tid 514607] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cDfzqsQqnLoCgUjhzZgABGHo"]
[Tue Jul 21 08:46:21.737198 2026] [security2:error] [pid 514479:tid 514628] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cDfzqsQqnLoCgUjhzZgABGHo"]
[Tue Jul 21 08:46:21.865863 2026] [security2:error] [pid 511108:tid 511312] [client 5.38.115.39:23664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cDYTd5soprXwxAH0PPwAAAEo"]
[Tue Jul 21 08:46:21.865995 2026] [security2:error] [pid 511108:tid 511312] [client 5.38.115.39:23664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cDYTd5soprXwxAH0PPwAAAEo"]
[Tue Jul 21 08:46:21.963291 2026] [security2:error] [pid 511108:tid 511258] [client 203.25.124.53:56137] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/maintenance.php"] [unique_id "al9cDYTd5soprXwxAH0PRQAAABQ"]
[Tue Jul 21 08:46:21.974645 2026] [autoindex:error] [pid 511108:tid 511135] [remote 143.137.38.229:26915] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/
[Tue Jul 21 08:46:22.105656 2026] [security2:error] [pid 511108:tid 511283] [client 20.151.10.161:62452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/k2.php"] [unique_id "al9cDoTd5soprXwxAH0PSwAAAC0"]
[Tue Jul 21 08:46:22.113984 2026] [autoindex:error] [pid 511108:tid 511234] [remote 143.137.38.229:26915] AH01276: Cannot serve directory /home3/eslang81/sistema/dashboard/painel/img/perfil/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://dashboard.esidiomass.com.br/painel/?pag=chamada_consulta
[Tue Jul 21 08:46:22.158929 2026] [security2:error] [pid 514479:tid 514575] [remote 178.18.124.148:17428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.124.18.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/wp-login.php"] [unique_id "al9cDvzqsQqnLoCgUjhzbQABdlo"]
[Tue Jul 21 08:46:22.179888 2026] [security2:error] [pid 514479:tid 514671] [client 212.32.76.56:61883] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/fonts/wp-conflg.php"] [unique_id "al9cDvzqsQqnLoCgUjhzbgAAAUM"]
[Tue Jul 21 08:46:22.533350 2026] [security2:error] [pid 511108:tid 511338] [client 212.32.76.14:64857] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp.php"] [unique_id "al9cDoTd5soprXwxAH0PUQAAAGQ"]
[Tue Jul 21 08:46:22.576621 2026] [security2:error] [pid 511108:tid 511255] [client 114.198.138.124:54348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cDoTd5soprXwxAH0PUgAAABE"]
[Tue Jul 21 08:46:22.576735 2026] [security2:error] [pid 511108:tid 511255] [client 114.198.138.124:54348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cDoTd5soprXwxAH0PUgAAABE"]
[Tue Jul 21 08:46:22.687799 2026] [security2:error] [pid 514479:tid 514714] [client 20.151.10.161:62346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/k3.php"] [unique_id "al9cDvzqsQqnLoCgUjhzeQAAAW4"]
[Tue Jul 21 08:46:22.860370 2026] [security2:error] [pid 514479:tid 514729] [client 212.32.76.5:52871] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/admin.php"] [unique_id "al9cDvzqsQqnLoCgUjhzfwAAAX0"]
[Tue Jul 21 08:46:23.104948 2026] [security2:error] [pid 514479:tid 514703] [client 65.21.113.253:51226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cDvzqsQqnLoCgUjhzeAAAAWM"]
[Tue Jul 21 08:46:23.166178 2026] [security2:error] [pid 514479:tid 514735] [client 20.197.192.193:4006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/hp2.php"] [unique_id "al9cD_zqsQqnLoCgUjhzggAAAYM"]
[Tue Jul 21 08:46:23.169185 2026] [security2:error] [pid 514479:tid 514716] [client 69.171.230.23:60256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cD_zqsQqnLoCgUjhzhAAAAXA"]
[Tue Jul 21 08:46:23.364088 2026] [security2:error] [pid 514479:tid 514676] [client 196.251.121.187:62290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "vivaconcierge.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9cD_zqsQqnLoCgUjhzhgAAAUg"]
[Tue Jul 21 08:46:23.365282 2026] [security2:error] [pid 511108:tid 511286] [client 195.49.128.211:55355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9cD4Td5soprXwxAH0PXgAAADA"]
[Tue Jul 21 08:46:23.365385 2026] [security2:error] [pid 511108:tid 511286] [client 195.49.128.211:55355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9cD4Td5soprXwxAH0PXgAAADA"]
[Tue Jul 21 08:46:23.403492 2026] [security2:error] [pid 511108:tid 511304] [client 20.151.10.161:62403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/k4.php"] [unique_id "al9cD4Td5soprXwxAH0PYAAAAEI"]
[Tue Jul 21 08:46:23.489650 2026] [security2:error] [pid 511108:tid 511262] [client 203.25.124.254:37477] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwentythree/patterns/"] [unique_id "al9cD4Td5soprXwxAH0PYwAAABg"]
[Tue Jul 21 08:46:23.533719 2026] [security2:error] [pid 514479:tid 514731] [client 113.22.144.139:59203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cD_zqsQqnLoCgUjhziAAAAX8"]
[Tue Jul 21 08:46:23.533809 2026] [security2:error] [pid 514479:tid 514731] [client 113.22.144.139:59203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cD_zqsQqnLoCgUjhziAAAAX8"]
[Tue Jul 21 08:46:23.577286 2026] [security2:error] [pid 514479:tid 514560] [remote 31.59.129.193:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "focsmart.com.br"] [uri "/.env"] [unique_id "al9cD_zqsQqnLoCgUjhziQABTEs"]
[Tue Jul 21 08:46:23.663996 2026] [security2:error] [pid 511108:tid 511365] [client 203.25.124.54:30539] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/home.php"] [unique_id "al9cD4Td5soprXwxAH0PZwAAAH8"]
[Tue Jul 21 08:46:23.802381 2026] [security2:error] [pid 514479:tid 514684] [client 103.59.206.240:31334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cD_zqsQqnLoCgUjhziwAAAVA"]
[Tue Jul 21 08:46:23.802496 2026] [security2:error] [pid 514479:tid 514684] [client 103.59.206.240:31334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cD_zqsQqnLoCgUjhziwAAAVA"]
[Tue Jul 21 08:46:23.945261 2026] [security2:error] [pid 514479:tid 514642] [client 203.25.124.53:20761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/hello-plus/classes/ehp-sarang.php"] [unique_id "al9cD_zqsQqnLoCgUjhzjQAAASY"]
[Tue Jul 21 08:46:24.205233 2026] [security2:error] [pid 514479:tid 514698] [client 20.151.10.161:62364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/k5.php"] [unique_id "al9cEPzqsQqnLoCgUjhzkAAAAV4"]
[Tue Jul 21 08:46:24.242733 2026] [security2:error] [pid 511108:tid 511117] [remote 159.65.81.207:55498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "combolog.com.br"] [uri "/wp-login.php"] [unique_id "al9cEITd5soprXwxAH0PbQAAcQg"]
[Tue Jul 21 08:46:24.579151 2026] [security2:error] [pid 511108:tid 511282] [client 20.151.10.161:62424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/w.php"] [unique_id "al9cEITd5soprXwxAH0PcQAAACw"]
[Tue Jul 21 08:46:24.675234 2026] [security2:error] [pid 514479:tid 514624] [client 203.25.124.6:20269] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/js/widgets/admin.php"] [unique_id "al9cEPzqsQqnLoCgUjhzmwAAARQ"]
[Tue Jul 21 08:46:24.799795 2026] [security2:error] [pid 514479:tid 514699] [client 59.95.197.55:59508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cEPzqsQqnLoCgUjhznAAAAV8"]
[Tue Jul 21 08:46:24.800468 2026] [security2:error] [pid 514479:tid 514699] [client 59.95.197.55:59508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cEPzqsQqnLoCgUjhznAAAAV8"]
[Tue Jul 21 08:46:24.825208 2026] [security2:error] [pid 514479:tid 514688] [client 31.56.58.129:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bdois.com.br"] [uri "/.env"] [unique_id "al9cEPzqsQqnLoCgUjhznQAAAVQ"]
[Tue Jul 21 08:46:24.961796 2026] [security2:error] [pid 514479:tid 514662] [client 20.151.10.161:62342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/fpwch.php"] [unique_id "al9cEPzqsQqnLoCgUjhzoAAAATo"]
[Tue Jul 21 08:46:24.997530 2026] [security2:error] [pid 514479:tid 514580] [remote 142.44.233.69:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "digitalbelfort.com"] [uri "/robots.txt"] [unique_id "al9cEPzqsQqnLoCgUjhzoQABZV8"]
[Tue Jul 21 08:46:24.997643 2026] [security2:error] [pid 514479:tid 514705] [client 142.44.233.69:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "digitalbelfort.com"] [uri "/robots.txt"] [unique_id "al9cEPzqsQqnLoCgUjhzoQABZV8"]
[Tue Jul 21 08:46:25.043705 2026] [security2:error] [pid 511108:tid 511289] [client 203.25.124.51:65437] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwentyone/content-index.php"] [unique_id "al9cEYTd5soprXwxAH0PeAAAADM"]
[Tue Jul 21 08:46:25.132328 2026] [security2:error] [pid 511108:tid 511274] [client 195.49.128.211:63386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cEYTd5soprXwxAH0PfQAAACQ"]
[Tue Jul 21 08:46:25.132443 2026] [security2:error] [pid 511108:tid 511274] [client 195.49.128.211:63386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cEYTd5soprXwxAH0PfQAAACQ"]
[Tue Jul 21 08:46:25.221088 2026] [security2:error] [pid 511108:tid 511182] [remote 31.59.129.193:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "focsmart.com.br"] [uri "/.env.bak"] [unique_id "al9cEYTd5soprXwxAH0PhAAADkk"]
[Tue Jul 21 08:46:25.368891 2026] [security2:error] [pid 511108:tid 511303] [client 203.25.124.182:58599] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/dist/vendor/about.php"] [unique_id "al9cEYTd5soprXwxAH0PiQAAAEE"]
[Tue Jul 21 08:46:25.383170 2026] [security2:error] [pid 514479:tid 514674] [client 20.151.10.161:62455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/w2025.php"] [unique_id "al9cEfzqsQqnLoCgUjhzpgAAAUY"]
[Tue Jul 21 08:46:25.461149 2026] [security2:error] [pid 514479:tid 514709] [client 212.32.76.14:58615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/oceanwp/content-index.php"] [unique_id "al9cEfzqsQqnLoCgUjhzpwAAAWk"]
[Tue Jul 21 08:46:25.497045 2026] [security2:error] [pid 514479:tid 514678] [client 122.176.100.127:61183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cEfzqsQqnLoCgUjhzqAAAAUo"]
[Tue Jul 21 08:46:25.497168 2026] [security2:error] [pid 514479:tid 514678] [client 122.176.100.127:61183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cEfzqsQqnLoCgUjhzqAAAAUo"]
[Tue Jul 21 08:46:25.887354 2026] [security2:error] [pid 514479:tid 514616] [client 20.197.195.24:48916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/adminfuns.php"] [unique_id "al9cEfzqsQqnLoCgUjhzqQAAAQw"]
[Tue Jul 21 08:46:25.898646 2026] [security2:error] [pid 514479:tid 514729] [client 20.151.10.161:62449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/scxy.php"] [unique_id "al9cEfzqsQqnLoCgUjhzqgAAAX0"]
[Tue Jul 21 08:46:26.041327 2026] [security2:error] [pid 514479:tid 514730] [client 203.25.124.36:26041] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/admin.php"] [unique_id "al9cEvzqsQqnLoCgUjhzrQAAAX4"]
[Tue Jul 21 08:46:26.072536 2026] [security2:error] [pid 514479:tid 514719] [client 203.25.124.190:48613] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/footnotes/"] [unique_id "al9cEvzqsQqnLoCgUjhzrgAAAXM"]
[Tue Jul 21 08:46:26.136464 2026] [security2:error] [pid 514479:tid 514499] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env"] [unique_id "al9cEvzqsQqnLoCgUjhzrwABgw8"]
[Tue Jul 21 08:46:26.137474 2026] [security2:error] [pid 514479:tid 514553] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env.bak"] [unique_id "al9cEvzqsQqnLoCgUjhzswABg0Q"]
[Tue Jul 21 08:46:26.142110 2026] [security2:error] [pid 514479:tid 514490] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env.backup"] [unique_id "al9cEvzqsQqnLoCgUjhztwABgwY"]
[Tue Jul 21 08:46:26.153005 2026] [security2:error] [pid 514479:tid 514484] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env"] [unique_id "al9cEvzqsQqnLoCgUjhzvwABgwA"]
[Tue Jul 21 08:46:26.428617 2026] [security2:error] [pid 514479:tid 514703] [client 49.144.66.253:31233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cEvzqsQqnLoCgUjhzyAAAAWM"]
[Tue Jul 21 08:46:26.428802 2026] [security2:error] [pid 514479:tid 514703] [client 49.144.66.253:31233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cEvzqsQqnLoCgUjhzyAAAAWM"]
[Tue Jul 21 08:46:26.566334 2026] [security2:error] [pid 511108:tid 511267] [client 203.25.124.42:22923] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/Divi/content-index.php"] [unique_id "al9cEoTd5soprXwxAH0PowAAAB0"]
[Tue Jul 21 08:46:26.774213 2026] [security2:error] [pid 511108:tid 511365] [client 203.25.124.183:28143] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/pullquote/"] [unique_id "al9cEoTd5soprXwxAH0PqQAAAH8"]
[Tue Jul 21 08:46:26.797259 2026] [security2:error] [pid 514479:tid 514618] [client 31.56.58.129:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.bdois.com.br"] [uri "/.env"] [unique_id "al9cEvzqsQqnLoCgUjhzzgAAAQ4"]
[Tue Jul 21 08:46:27.032348 2026] [security2:error] [pid 514479:tid 514723] [client 41.89.234.2:38384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cE_zqsQqnLoCgUjhz1gAAAXc"]
[Tue Jul 21 08:46:27.032467 2026] [security2:error] [pid 514479:tid 514723] [client 41.89.234.2:38384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cE_zqsQqnLoCgUjhz1gAAAXc"]
[Tue Jul 21 08:46:27.167696 2026] [security2:error] [pid 511108:tid 511174] [remote 31.59.129.193:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "focsmart.com.br"] [uri "/.env.test"] [unique_id "al9cE4Td5soprXwxAH0PrwAAFUE"]
[Tue Jul 21 08:46:27.167928 2026] [security2:error] [pid 511108:tid 511259] [client 31.59.129.193:0] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "focsmart.com.br"] [uri "/.env.test"] [unique_id "al9cE4Td5soprXwxAH0PrwAAFUE"]
[Tue Jul 21 08:46:27.189779 2026] [security2:error] [pid 514479:tid 514563] [remote 31.59.129.193:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "focsmart.com.br"] [uri "/api/.env"] [unique_id "al9cE_zqsQqnLoCgUjhz2wABQ04"]
[Tue Jul 21 08:46:27.384984 2026] [security2:error] [pid 511108:tid 511173] [remote 31.59.129.193:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "focsmart.com.br"] [uri "/.env.old"] [unique_id "al9cE4Td5soprXwxAH0PtQAACUA"]
[Tue Jul 21 08:46:27.390054 2026] [security2:error] [pid 511108:tid 511222] [remote 103.161.172.221:33560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9cE4Td5soprXwxAH0PsgAAEXE"]
[Tue Jul 21 08:46:27.502707 2026] [security2:error] [pid 514479:tid 514498] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cE_zqsQqnLoCgUjhz3wABTQ4"]
[Tue Jul 21 08:46:27.502885 2026] [security2:error] [pid 514479:tid 514681] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cE_zqsQqnLoCgUjhz3wABTQ4"]
[Tue Jul 21 08:46:27.953071 2026] [security2:error] [pid 514479:tid 514550] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9cE_zqsQqnLoCgUjhz7gABWEE"]
[Tue Jul 21 08:46:28.031923 2026] [security2:error] [pid 514479:tid 514573] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/config/app.php"] [unique_id "al9cFPzqsQqnLoCgUjhz8wABWFg"]
[Tue Jul 21 08:46:28.038762 2026] [security2:error] [pid 514479:tid 514674] [client 203.25.124.69:61619] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/404.php"] [unique_id "al9cFPzqsQqnLoCgUjhz9AAAAUY"]
[Tue Jul 21 08:46:28.056374 2026] [security2:error] [pid 514479:tid 514601] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/config/database.php"] [unique_id "al9cFPzqsQqnLoCgUjhz9gABWHQ"]
[Tue Jul 21 08:46:28.057580 2026] [security2:error] [pid 514479:tid 514512] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/config/mail.php"] [unique_id "al9cFPzqsQqnLoCgUjhz9wABWBw"]
[Tue Jul 21 08:46:28.069169 2026] [security2:error] [pid 511108:tid 511289] [client 203.25.124.197:47963] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/simple.php"] [unique_id "al9cFITd5soprXwxAH0PwAAAADM"]
[Tue Jul 21 08:46:28.070138 2026] [security2:error] [pid 514479:tid 514514] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/backup.sql"] [unique_id "al9cFPzqsQqnLoCgUjhz-gABWB4"]
[Tue Jul 21 08:46:28.079562 2026] [security2:error] [pid 514479:tid 514503] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/dump.sql"] [unique_id "al9cFPzqsQqnLoCgUjhz-wABWBM"]
[Tue Jul 21 08:46:28.080347 2026] [security2:error] [pid 514479:tid 514536] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/database.sql"] [unique_id "al9cFPzqsQqnLoCgUjhz_AABWDQ"]
[Tue Jul 21 08:46:28.088497 2026] [security2:error] [pid 511108:tid 511341] [client 20.197.192.193:4039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/hp3.php"] [unique_id "al9cFITd5soprXwxAH0PwQAAAGc"]
[Tue Jul 21 08:46:28.089109 2026] [security2:error] [pid 514479:tid 514502] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env"] [unique_id "al9cFPzqsQqnLoCgUjhz_QABWBI"]
[Tue Jul 21 08:46:28.461836 2026] [security2:error] [pid 511108:tid 511285] [client 172.86.119.116:56454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "linkmaster.net.br"] [uri "/"] [unique_id "al9cFITd5soprXwxAH0PxQAAAC8"]
[Tue Jul 21 08:46:28.462051 2026] [security2:error] [pid 514479:tid 514730] [client 172.86.119.116:56456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "www.linkmaster.net.br"] [uri "/"] [unique_id "al9cFPzqsQqnLoCgUjh0CgAAAX4"]
[Tue Jul 21 08:46:28.493825 2026] [security2:error] [pid 514479:tid 514702] [client 20.197.192.193:27087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/cron-tab.php"] [unique_id "al9cFPzqsQqnLoCgUjh0DAAAAWI"]
[Tue Jul 21 08:46:28.566892 2026] [security2:error] [pid 514479:tid 514735] [client 203.25.124.72:44829] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/exnova/content-index.php"] [unique_id "al9cFPzqsQqnLoCgUjh0DwAAAYM"]
[Tue Jul 21 08:46:28.659397 2026] [security2:error] [pid 514479:tid 514657] [client 65.21.113.253:51228] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cFPzqsQqnLoCgUjh0DQAAATU"]
[Tue Jul 21 08:46:28.748399 2026] [security2:error] [pid 511108:tid 511204] [remote 31.59.129.193:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "focsmart.com.br"] [uri "/.env.backup"] [unique_id "al9cFITd5soprXwxAH0PywAAHl8"]
[Tue Jul 21 08:46:29.262930 2026] [security2:error] [pid 514479:tid 514576] [remote 188.164.197.230:36862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limaradiologiadigital.com.br"] [uri "/wp-login.php"] [unique_id "al9cFfzqsQqnLoCgUjh0GAABf1s"]
[Tue Jul 21 08:46:29.265129 2026] [security2:error] [pid 514479:tid 514734] [client 61.1.167.83:63659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cFfzqsQqnLoCgUjh0GQAAAYI"]
[Tue Jul 21 08:46:29.265214 2026] [security2:error] [pid 514479:tid 514734] [client 61.1.167.83:63659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cFfzqsQqnLoCgUjh0GQAAAYI"]
[Tue Jul 21 08:46:29.271236 2026] [security2:error] [pid 511108:tid 511270] [client 212.32.76.60:65441] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/includes/admin.php"] [unique_id "al9cFYTd5soprXwxAH0P1AAAACA"]
[Tue Jul 21 08:46:29.392397 2026] [security2:error] [pid 514479:tid 514724] [client 20.151.10.161:62373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/FWAZ.php"] [unique_id "al9cFfzqsQqnLoCgUjh0GwAAAXg"]
[Tue Jul 21 08:46:29.394223 2026] [security2:error] [pid 514479:tid 514691] [client 198.44.157.34:52058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cFfzqsQqnLoCgUjh0HAAAAVc"]
[Tue Jul 21 08:46:29.394300 2026] [security2:error] [pid 514479:tid 514691] [client 198.44.157.34:52058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cFfzqsQqnLoCgUjh0HAAAAVc"]
[Tue Jul 21 08:46:29.558511 2026] [security2:error] [pid 514479:tid 514727] [client 203.25.124.61:48491] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/specia/content-index.php"] [unique_id "al9cFfzqsQqnLoCgUjh0HgAAAXs"]
[Tue Jul 21 08:46:29.753014 2026] [security2:error] [pid 514479:tid 514670] [client 20.197.192.193:27155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/koiy.php"] [unique_id "al9cFfzqsQqnLoCgUjh0JQAAAUI"]
[Tue Jul 21 08:46:29.770820 2026] [security2:error] [pid 514479:tid 514515] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env.backup"] [unique_id "al9cFfzqsQqnLoCgUjh0JwABYR8"]
[Tue Jul 21 08:46:29.797581 2026] [security2:error] [pid 514479:tid 514618] [client 65.21.113.253:51242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cFfzqsQqnLoCgUjh0GgAAAQ4"]
[Tue Jul 21 08:46:29.890834 2026] [security2:error] [pid 511108:tid 511358] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cFYTd5soprXwxAH0P3gAAeEw"]
[Tue Jul 21 08:46:29.936458 2026] [security2:error] [pid 511108:tid 511279] [client 203.25.124.42:45823] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/file.php"] [unique_id "al9cFYTd5soprXwxAH0P4AAAACk"]
[Tue Jul 21 08:46:30.289010 2026] [security2:error] [pid 514479:tid 514665] [client 168.167.81.163:62311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cFvzqsQqnLoCgUjh0LQAAAT0"]
[Tue Jul 21 08:46:30.289133 2026] [security2:error] [pid 514479:tid 514665] [client 168.167.81.163:62311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cFvzqsQqnLoCgUjh0LQAAAT0"]
[Tue Jul 21 08:46:30.568743 2026] [security2:error] [pid 511108:tid 511330] [client 212.32.76.58:20241] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/css/dist/reusable-blocks/"] [unique_id "al9cFoTd5soprXwxAH0P7AAAAFw"]
[Tue Jul 21 08:46:30.616773 2026] [proxy:error] [pid 511108:tid 511351] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:46:30.616853 2026] [proxy_http:error] [pid 511108:tid 511351] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:46:30.617460 2026] [proxy:error] [pid 511108:tid 511351] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:46:30.617496 2026] [proxy_http:error] [pid 511108:tid 511351] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:46:30.657492 2026] [security2:error] [pid 511108:tid 511272] [client 202.179.75.202:57644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cFoTd5soprXwxAH0P7wAAACI"]
[Tue Jul 21 08:46:30.657638 2026] [security2:error] [pid 511108:tid 511272] [client 202.179.75.202:57644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cFoTd5soprXwxAH0P7wAAACI"]
[Tue Jul 21 08:46:30.887768 2026] [security2:error] [pid 514479:tid 514692] [client 20.151.10.161:62432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/qterm.php"] [unique_id "al9cFvzqsQqnLoCgUjh0MQAAAVg"]
[Tue Jul 21 08:46:30.939775 2026] [security2:error] [pid 514479:tid 514678] [client 203.25.124.211:45345] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/chosen.php"] [unique_id "al9cFvzqsQqnLoCgUjh0MgAAAUo"]
[Tue Jul 21 08:46:30.972518 2026] [security2:error] [pid 511108:tid 511257] [client 74.7.228.41:53212] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "humanizarmed.com.br"] [uri "/index.php"] [unique_id "al9cFYTd5soprXwxAH0P3QAAEzA"]
[Tue Jul 21 08:46:30.973047 2026] [security2:error] [pid 511108:tid 511352] [client 203.25.124.33:40539] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "al9cFoTd5soprXwxAH0P-AAAAHI"]
[Tue Jul 21 08:46:31.014269 2026] [security2:error] [pid 511108:tid 511163] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cF4Td5soprXwxAH0P-QAAbzY"]
[Tue Jul 21 08:46:31.014408 2026] [security2:error] [pid 511108:tid 511349] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cF4Td5soprXwxAH0P-QAAbzY"]
[Tue Jul 21 08:46:31.046757 2026] [proxy:error] [pid 511108:tid 511271] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:46:31.046853 2026] [proxy_http:error] [pid 511108:tid 511271] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:46:31.047924 2026] [proxy:error] [pid 511108:tid 511271] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:46:31.047993 2026] [proxy_http:error] [pid 511108:tid 511271] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:46:31.117582 2026] [security2:error] [pid 514479:tid 514506] [remote 38.242.157.30:41392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/wp-login.php"] [unique_id "al9cF_zqsQqnLoCgUjh0NAABaRY"]
[Tue Jul 21 08:46:31.375357 2026] [security2:error] [pid 514479:tid 514589] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cF_zqsQqnLoCgUjh0OgABcWg"]
[Tue Jul 21 08:46:31.375479 2026] [security2:error] [pid 514479:tid 514717] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cF_zqsQqnLoCgUjh0OgABcWg"]
[Tue Jul 21 08:46:31.441953 2026] [proxy:error] [pid 511108:tid 511265] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:46:31.442033 2026] [proxy_http:error] [pid 511108:tid 511265] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:46:31.442537 2026] [proxy:error] [pid 511108:tid 511265] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:46:31.442564 2026] [proxy_http:error] [pid 511108:tid 511265] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:46:31.532052 2026] [security2:error] [pid 514479:tid 514688] [client 47.128.53.177:12638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "havoy.com.br"] [uri "/robots.txt"] [unique_id "al9cF_zqsQqnLoCgUjh0QAAAAVQ"]
[Tue Jul 21 08:46:31.669240 2026] [security2:error] [pid 514479:tid 514655] [client 203.25.124.251:48591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-signin.php"] [unique_id "al9cF_zqsQqnLoCgUjh0RAAAATM"]
[Tue Jul 21 08:46:31.726575 2026] [security2:error] [pid 514479:tid 514578] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0RgABW10"]
[Tue Jul 21 08:46:31.726613 2026] [security2:error] [pid 514479:tid 514561] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0RQABW0w"]
[Tue Jul 21 08:46:31.726630 2026] [security2:error] [pid 514479:tid 514569] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0RwABW1Q"]
[Tue Jul 21 08:46:31.726653 2026] [security2:error] [pid 514479:tid 514537] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0SAABWzU"]
[Tue Jul 21 08:46:31.726706 2026] [security2:error] [pid 514479:tid 514526] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0SQABWyo"]
[Tue Jul 21 08:46:31.727359 2026] [security2:error] [pid 514479:tid 514600] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0TAABW3M"]
[Tue Jul 21 08:46:31.728121 2026] [security2:error] [pid 514479:tid 514546] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0SgABWz4"]
[Tue Jul 21 08:46:31.740623 2026] [security2:error] [pid 514479:tid 514486] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0VAABWwI"]
[Tue Jul 21 08:46:31.740682 2026] [security2:error] [pid 514479:tid 514605] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0VQABW3g"]
[Tue Jul 21 08:46:31.740867 2026] [security2:error] [pid 514479:tid 514579] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0VgABW14"]
[Tue Jul 21 08:46:31.742481 2026] [security2:error] [pid 514479:tid 514501] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0VwABWxE"]
[Tue Jul 21 08:46:31.743749 2026] [security2:error] [pid 514479:tid 514539] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0WAABWzc"]
[Tue Jul 21 08:46:31.744205 2026] [security2:error] [pid 514479:tid 514545] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0WQABWz0"]
[Tue Jul 21 08:46:31.745356 2026] [security2:error] [pid 514479:tid 514565] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0WwABW1A"]
[Tue Jul 21 08:46:31.746038 2026] [security2:error] [pid 514479:tid 514532] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cF_zqsQqnLoCgUjh0WgABWzA"]
[Tue Jul 21 08:46:31.825954 2026] [security2:error] [pid 514479:tid 514683] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cF_zqsQqnLoCgUjh0XQAAAU8"]
[Tue Jul 21 08:46:31.829785 2026] [security2:error] [pid 514479:tid 514706] [client 203.25.124.40:57385] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/"] [unique_id "al9cF_zqsQqnLoCgUjh0XgAAAWY"]
[Tue Jul 21 08:46:32.006227 2026] [security2:error] [pid 511108:tid 511125] [remote 31.59.129.193:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "focsmart.com.br"] [uri "/public/.env"] [unique_id "al9cGITd5soprXwxAH0QFAAAEhA"]
[Tue Jul 21 08:46:32.006228 2026] [security2:error] [pid 511108:tid 511215] [remote 31.59.129.193:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "focsmart.com.br"] [uri "/backend/.env"] [unique_id "al9cGITd5soprXwxAH0QEwAAEmo"]
[Tue Jul 21 08:46:32.006248 2026] [security2:error] [pid 511108:tid 511143] [remote 31.59.129.193:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "focsmart.com.br"] [uri "/app/.env"] [unique_id "al9cGITd5soprXwxAH0QEgAAEiI"]
[Tue Jul 21 08:46:32.126514 2026] [security2:error] [pid 511108:tid 511176] [remote 216.73.160.42:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-login.php"] [unique_id "al9cFoTd5soprXwxAH0P5AAAF0M"]
[Tue Jul 21 08:46:32.180542 2026] [security2:error] [pid 514479:tid 514736] [client 20.151.10.161:62421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/blurbs.php"] [unique_id "al9cGPzqsQqnLoCgUjh0ZAAAAYQ"]
[Tue Jul 21 08:46:32.182398 2026] [security2:error] [pid 514479:tid 514687] [client 47.128.122.27:18718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "overkotz.com"] [uri "/robots.txt"] [unique_id "al9cGPzqsQqnLoCgUjh0ZQAAAVM"]
[Tue Jul 21 08:46:32.254615 2026] [security2:error] [pid 514479:tid 514529] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cGPzqsQqnLoCgUjh0ZwABVy0"]
[Tue Jul 21 08:46:32.254751 2026] [security2:error] [pid 514479:tid 514691] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cGPzqsQqnLoCgUjh0ZwABVy0"]
[Tue Jul 21 08:46:32.322007 2026] [security2:error] [pid 514479:tid 514640] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9cGPzqsQqnLoCgUjh0agAAASQ"]
[Tue Jul 21 08:46:32.376107 2026] [security2:error] [pid 511108:tid 511329] [client 49.13.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9cGITd5soprXwxAH0QGwAAWx0"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:46:32.378367 2026] [security2:error] [pid 514479:tid 514625] [client 213.152.162.15:42140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9cGPzqsQqnLoCgUjh0awAAARU"]
[Tue Jul 21 08:46:32.378454 2026] [security2:error] [pid 514479:tid 514625] [client 213.152.162.15:42140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9cGPzqsQqnLoCgUjh0awAAARU"]
[Tue Jul 21 08:46:32.475499 2026] [security2:error] [pid 514479:tid 514701] [client 203.25.124.210:36011] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/config.php"] [unique_id "al9cGPzqsQqnLoCgUjh0bwAAAWE"]
[Tue Jul 21 08:46:32.592533 2026] [security2:error] [pid 514479:tid 514731] [client 5.38.115.39:57687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cGPzqsQqnLoCgUjh0cAAAAX8"]
[Tue Jul 21 08:46:32.592690 2026] [security2:error] [pid 514479:tid 514731] [client 5.38.115.39:57687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cGPzqsQqnLoCgUjh0cAAAAX8"]
[Tue Jul 21 08:46:32.745717 2026] [security2:error] [pid 511108:tid 511311] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9cGITd5soprXwxAH0QIAAAAEk"]
[Tue Jul 21 08:46:32.839340 2026] [security2:error] [pid 514479:tid 514704] [client 203.25.124.37:56633] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/1.php"] [unique_id "al9cGPzqsQqnLoCgUjh0dQAAAWQ"]
[Tue Jul 21 08:46:32.877372 2026] [security2:error] [pid 514479:tid 514673] [client 198.44.157.34:33466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9cGPzqsQqnLoCgUjh0dgAAAUU"]
[Tue Jul 21 08:46:32.877474 2026] [security2:error] [pid 514479:tid 514673] [client 198.44.157.34:33466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9cGPzqsQqnLoCgUjh0dgAAAUU"]
[Tue Jul 21 08:46:32.932780 2026] [security2:error] [pid 511108:tid 511327] [client 49.13.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9cGITd5soprXwxAH0QJgAAWXA"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:46:33.159284 2026] [security2:error] [pid 514479:tid 514689] [client 20.151.10.161:62436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/v543.php"] [unique_id "al9cGfzqsQqnLoCgUjh0fAAAAVU"]
[Tue Jul 21 08:46:33.163040 2026] [security2:error] [pid 514479:tid 514692] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9cGfzqsQqnLoCgUjh0fQAAAVg"]
[Tue Jul 21 08:46:33.166703 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.166799 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.166917 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.166958 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167004 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167117 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167189 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167228 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167280 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167317 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167353 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167390 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167425 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167461 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167496 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167531 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167568 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167604 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167640 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167676 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167712 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167760 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167789 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167832 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167866 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167902 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167942 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.167991 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168086 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168122 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168158 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168200 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168234 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168270 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168308 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168342 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168378 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168417 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168468 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168504 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168555 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168597 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168638 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168708 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168731 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168766 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168801 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168844 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168892 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168929 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.168964 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169007 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169042 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169078 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169113 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169148 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169183 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169219 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169256 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169290 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169326 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169363 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169396 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169447 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169482 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169516 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169559 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169595 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169630 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169667 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169706 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169744 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169783 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169825 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169860 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169894 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169929 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.169964 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170004 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170039 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170075 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170111 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170145 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170178 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170213 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170249 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170284 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170320 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170353 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170388 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170427 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170463 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170506 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170543 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.170587 2026] [lsapi:warn] [pid 514479:tid 514620] [client 189.6.178.120:62528] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:46:33.469751 2026] [security2:error] [pid 514479:tid 514732] [client 114.198.138.124:54910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cGfzqsQqnLoCgUjh0gwAAAYA"]
[Tue Jul 21 08:46:33.469925 2026] [security2:error] [pid 514479:tid 514732] [client 114.198.138.124:54910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cGfzqsQqnLoCgUjh0gwAAAYA"]
[Tue Jul 21 08:46:33.478377 2026] [security2:error] [pid 511108:tid 511325] [client 212.32.76.66:44587] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/freeform/"] [unique_id "al9cGYTd5soprXwxAH0QNQAAAFc"]
[Tue Jul 21 08:46:33.519419 2026] [security2:error] [pid 514479:tid 514676] [client 74.7.175.177:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lucastrindade1745866075349.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9cGfzqsQqnLoCgUjh0hAABSAU"]
[Tue Jul 21 08:46:33.536889 2026] [security2:error] [pid 514479:tid 514497] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0hgABfg0"]
[Tue Jul 21 08:46:33.536959 2026] [security2:error] [pid 514479:tid 514522] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0hQABfiY"]
[Tue Jul 21 08:46:33.537738 2026] [security2:error] [pid 514479:tid 514492] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0iAABfgg"]
[Tue Jul 21 08:46:33.539123 2026] [security2:error] [pid 514479:tid 514562] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0iwABfk0"]
[Tue Jul 21 08:46:33.539237 2026] [security2:error] [pid 514479:tid 514607] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0igABfno"]
[Tue Jul 21 08:46:33.551228 2026] [security2:error] [pid 514479:tid 514575] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0kgABflo"]
[Tue Jul 21 08:46:33.551903 2026] [security2:error] [pid 514479:tid 514583] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0kwABfmI"]
[Tue Jul 21 08:46:33.552466 2026] [security2:error] [pid 514479:tid 514524] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0lQABfig"]
[Tue Jul 21 08:46:33.552522 2026] [security2:error] [pid 514479:tid 514582] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0lAABfmE"]
[Tue Jul 21 08:46:33.553889 2026] [security2:error] [pid 514479:tid 514735] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9cGfzqsQqnLoCgUjh0lwAAAYM"]
[Tue Jul 21 08:46:33.554187 2026] [security2:error] [pid 514479:tid 514597] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0mAABfnA"]
[Tue Jul 21 08:46:33.554332 2026] [core:error] [pid 514479:tid 514574] [remote 34.182.152.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:46:33.554347 2026] [core:error] [pid 514479:tid 514574] [remote 34.182.152.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:46:33.593662 2026] [security2:error] [pid 514479:tid 514584] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0mQABfmM"]
[Tue Jul 21 08:46:33.601135 2026] [security2:error] [pid 514479:tid 514523] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0mgABfic"]
[Tue Jul 21 08:46:33.616018 2026] [security2:error] [pid 514479:tid 514560] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0mwABfks"]
[Tue Jul 21 08:46:33.625414 2026] [security2:error] [pid 514479:tid 514491] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0nAABfgc"]
[Tue Jul 21 08:46:33.630985 2026] [security2:error] [pid 514479:tid 514596] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cGfzqsQqnLoCgUjh0nQABfm8"]
[Tue Jul 21 08:46:33.792787 2026] [security2:error] [pid 511108:tid 511316] [client 20.151.10.161:62361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/w3lls.php"] [unique_id "al9cGYTd5soprXwxAH0QPQAAAE4"]
[Tue Jul 21 08:46:33.985854 2026] [security2:error] [pid 514479:tid 514698] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9cGfzqsQqnLoCgUjh0ogAAAV4"]
[Tue Jul 21 08:46:34.015597 2026] [security2:error] [pid 514479:tid 514720] [client 195.49.128.211:55973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9cGvzqsQqnLoCgUjh0owAAAXQ"]
[Tue Jul 21 08:46:34.015740 2026] [security2:error] [pid 514479:tid 514720] [client 195.49.128.211:55973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9cGvzqsQqnLoCgUjh0owAAAXQ"]
[Tue Jul 21 08:46:34.018558 2026] [security2:error] [pid 511108:tid 511118] [remote 34.182.152.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.152.182.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.bomnegociopromotora.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cGYTd5soprXwxAH0QQQAAcgk"]
[Tue Jul 21 08:46:34.183114 2026] [security2:error] [pid 514479:tid 514513] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.bomnegociopromotora.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9cGvzqsQqnLoCgUjh0pQABHx0"]
[Tue Jul 21 08:46:34.232590 2026] [security2:error] [pid 514479:tid 514680] [client 103.59.206.240:31123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cGvzqsQqnLoCgUjh0qAAAAUw"]
[Tue Jul 21 08:46:34.232703 2026] [security2:error] [pid 514479:tid 514680] [client 103.59.206.240:31123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cGvzqsQqnLoCgUjh0qAAAAUw"]
[Tue Jul 21 08:46:34.270798 2026] [security2:error] [pid 514479:tid 514640] [client 203.25.124.202:23381] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/maintenance/"] [unique_id "al9cGvzqsQqnLoCgUjh0qgAAASQ"]
[Tue Jul 21 08:46:34.315244 2026] [security2:error] [pid 511108:tid 511113] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.bomnegociopromotora.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9cGoTd5soprXwxAH0QRAAAAQQ"]
[Tue Jul 21 08:46:34.408064 2026] [security2:error] [pid 514479:tid 514625] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9cGvzqsQqnLoCgUjh0rQAAARU"]
[Tue Jul 21 08:46:34.432505 2026] [security2:error] [pid 514479:tid 514641] [client 203.25.124.55:64483] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/fukasawa/inc/classes/403.php"] [unique_id "al9cGvzqsQqnLoCgUjh0sAAAASU"]
[Tue Jul 21 08:46:34.583043 2026] [security2:error] [pid 514479:tid 514686] [client 173.252.95.29:39834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cGvzqsQqnLoCgUjh0uAAAAVI"]
[Tue Jul 21 08:46:34.632702 2026] [security2:error] [pid 514479:tid 514525] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.bomnegociopromotora.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9cGvzqsQqnLoCgUjh0ugABEik"]
[Tue Jul 21 08:46:34.657798 2026] [security2:error] [pid 514479:tid 514652] [client 203.25.124.64:44357] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/css/eroor.php"] [unique_id "al9cGvzqsQqnLoCgUjh0uwAAATA"]
[Tue Jul 21 08:46:34.748078 2026] [security2:error] [pid 514479:tid 514694] [client 20.151.10.161:62453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-ws68.php"] [unique_id "al9cGvzqsQqnLoCgUjh0vQAAAVo"]
[Tue Jul 21 08:46:34.813398 2026] [security2:error] [pid 514479:tid 514728] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9cGvzqsQqnLoCgUjh0vgAAAXw"]
[Tue Jul 21 08:46:34.874979 2026] [security2:error] [pid 511108:tid 511112] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.bomnegociopromotora.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9cGoTd5soprXwxAH0QTQAADgM"]
[Tue Jul 21 08:46:34.931468 2026] [security2:error] [pid 514479:tid 514659] [client 113.22.144.139:59956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cGvzqsQqnLoCgUjh0vwAAATc"]
[Tue Jul 21 08:46:34.932114 2026] [security2:error] [pid 514479:tid 514659] [client 113.22.144.139:59956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cGvzqsQqnLoCgUjh0vwAAATc"]
[Tue Jul 21 08:46:34.953247 2026] [security2:error] [pid 514479:tid 514553] [remote 130.51.180.8:48796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northcomm.com.br"] [uri "/wp-login.php"] [unique_id "al9cGvzqsQqnLoCgUjh0wQABZEQ"]
[Tue Jul 21 08:46:35.048075 2026] [security2:error] [pid 514479:tid 514490] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.bomnegociopromotora.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9cG_zqsQqnLoCgUjh0xAABcgY"]
[Tue Jul 21 08:46:35.131346 2026] [security2:error] [pid 514479:tid 514679] [client 65.21.113.253:51242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cGvzqsQqnLoCgUjh0vAAAAUs"]
[Tue Jul 21 08:46:35.219232 2026] [security2:error] [pid 511108:tid 511292] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9cG4Td5soprXwxAH0QUgAAADY"]
[Tue Jul 21 08:46:35.270994 2026] [security2:error] [pid 511108:tid 511230] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.bomnegociopromotora.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9cG4Td5soprXwxAH0QVAAACHk"]
[Tue Jul 21 08:46:35.294256 2026] [security2:error] [pid 514479:tid 514508] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cG_zqsQqnLoCgUjh0xwABGhg"]
[Tue Jul 21 08:46:35.298042 2026] [security2:error] [pid 514479:tid 514599] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cG_zqsQqnLoCgUjh0yQABGnI"]
[Tue Jul 21 08:46:35.300586 2026] [security2:error] [pid 514479:tid 514566] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cG_zqsQqnLoCgUjh0ywABGlE"]
[Tue Jul 21 08:46:35.305254 2026] [security2:error] [pid 514479:tid 514650] [client 59.95.197.55:59977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cG_zqsQqnLoCgUjh0zAAAAS4"]
[Tue Jul 21 08:46:35.305360 2026] [security2:error] [pid 514479:tid 514650] [client 59.95.197.55:59977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cG_zqsQqnLoCgUjh0zAAAAS4"]
[Tue Jul 21 08:46:35.318247 2026] [security2:error] [pid 514479:tid 514590] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cG_zqsQqnLoCgUjh00gABGmk"]
[Tue Jul 21 08:46:35.319007 2026] [security2:error] [pid 514479:tid 514518] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cG_zqsQqnLoCgUjh00wABGiI"]
[Tue Jul 21 08:46:35.325375 2026] [security2:error] [pid 514479:tid 514648] [client 49.13.134.145:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9cG_zqsQqnLoCgUjh0zgABLCU"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:46:35.364764 2026] [security2:error] [pid 514479:tid 514542] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cG_zqsQqnLoCgUjh01gABGjo"]
[Tue Jul 21 08:46:35.366713 2026] [security2:error] [pid 514479:tid 514608] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cG_zqsQqnLoCgUjh01wABGns"]
[Tue Jul 21 08:46:35.370179 2026] [security2:error] [pid 514479:tid 514519] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cG_zqsQqnLoCgUjh02AABGiM"]
[Tue Jul 21 08:46:35.371112 2026] [security2:error] [pid 514479:tid 514516] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cG_zqsQqnLoCgUjh02QABGiA"]
[Tue Jul 21 08:46:35.382341 2026] [security2:error] [pid 514479:tid 514528] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cG_zqsQqnLoCgUjh02gABGiw"]
[Tue Jul 21 08:46:35.386735 2026] [security2:error] [pid 514479:tid 514551] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cG_zqsQqnLoCgUjh02wABGkI"]
[Tue Jul 21 08:46:35.389434 2026] [security2:error] [pid 514479:tid 514586] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cG_zqsQqnLoCgUjh03AABGmU"]
[Tue Jul 21 08:46:35.395904 2026] [security2:error] [pid 514479:tid 514594] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cG_zqsQqnLoCgUjh03QABGm0"]
[Tue Jul 21 08:46:35.400116 2026] [security2:error] [pid 514479:tid 514563] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cG_zqsQqnLoCgUjh03wABGk4"]
[Tue Jul 21 08:46:35.461576 2026] [security2:error] [pid 511108:tid 511261] [client 20.197.192.193:27131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/hp2.php"] [unique_id "al9cG4Td5soprXwxAH0QXwAAABc"]
[Tue Jul 21 08:46:35.492584 2026] [security2:error] [pid 514479:tid 514498] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.bomnegociopromotora.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9cG_zqsQqnLoCgUjh04AABdQ4"]
[Tue Jul 21 08:46:35.545527 2026] [security2:error] [pid 511108:tid 511364] [client 203.25.124.71:46335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/alera/gecko.php"] [unique_id "al9cG4Td5soprXwxAH0QYwAAAH4"]
[Tue Jul 21 08:46:35.624527 2026] [security2:error] [pid 511108:tid 511279] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9cG4Td5soprXwxAH0QaQAAACk"]
[Tue Jul 21 08:46:35.661408 2026] [security2:error] [pid 511108:tid 511192] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.bomnegociopromotora.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9cG4Td5soprXwxAH0QagAASVM"]
[Tue Jul 21 08:46:35.753679 2026] [security2:error] [pid 514479:tid 514667] [client 195.49.128.211:63991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cG_zqsQqnLoCgUjh04wAAAT8"]
[Tue Jul 21 08:46:35.753804 2026] [security2:error] [pid 514479:tid 514667] [client 195.49.128.211:63991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cG_zqsQqnLoCgUjh04wAAAT8"]
[Tue Jul 21 08:46:35.843354 2026] [security2:error] [pid 514479:tid 514595] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.bomnegociopromotora.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9cG_zqsQqnLoCgUjh05QABT24"]
[Tue Jul 21 08:46:35.875481 2026] [security2:error] [pid 514479:tid 514706] [client 49.13.134.145:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9cG_zqsQqnLoCgUjh05gABZkk"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:46:36.018998 2026] [security2:error] [pid 511108:tid 511156] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.bomnegociopromotora.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9cHITd5soprXwxAH0QcQAAXi8"]
[Tue Jul 21 08:46:36.028103 2026] [security2:error] [pid 511108:tid 511320] [client 122.176.100.127:61676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cHITd5soprXwxAH0QcgAAAFI"]
[Tue Jul 21 08:46:36.028896 2026] [security2:error] [pid 511108:tid 511320] [client 122.176.100.127:61676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cHITd5soprXwxAH0QcgAAAFI"]
[Tue Jul 21 08:46:36.067102 2026] [security2:error] [pid 514479:tid 514724] [client 203.25.124.74:24069] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/languages/themes/home.php"] [unique_id "al9cHPzqsQqnLoCgUjh06gAAAXg"]
[Tue Jul 21 08:46:36.096427 2026] [security2:error] [pid 511108:tid 511276] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9cHITd5soprXwxAH0QdQAAACY"]
[Tue Jul 21 08:46:36.205183 2026] [security2:error] [pid 514479:tid 514500] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.bomnegociopromotora.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9cHPzqsQqnLoCgUjh07AABdBA"]
[Tue Jul 21 08:46:36.271511 2026] [security2:error] [pid 514479:tid 514691] [client 212.32.76.66:37711] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/module.php"] [unique_id "al9cHPzqsQqnLoCgUjh07QAAAVc"]
[Tue Jul 21 08:46:36.337055 2026] [security2:error] [pid 511108:tid 511219] [remote 34.182.152.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.bomnegociopromotora.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9cHITd5soprXwxAH0QdwAAEG4"]
[Tue Jul 21 08:46:36.461540 2026] [security2:error] [pid 511108:tid 511272] [client 20.151.10.161:62389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/xyn.php"] [unique_id "al9cHITd5soprXwxAH0QegAAACI"]
[Tue Jul 21 08:46:36.497123 2026] [security2:error] [pid 511108:tid 511257] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9cHITd5soprXwxAH0QewAAABM"]
[Tue Jul 21 08:46:36.741659 2026] [security2:error] [pid 514479:tid 514701] [client 203.25.124.55:39827] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/so-pinyin-slugs/inc/main_json.php"] [unique_id "al9cHPzqsQqnLoCgUjh09AAAAWE"]
[Tue Jul 21 08:46:36.828484 2026] [security2:error] [pid 511108:tid 511289] [client 20.10.88.201:61441] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shop-officialstore.com"] [uri "/index.php"] [unique_id "al9cHITd5soprXwxAH0QgAAAADM"]
[Tue Jul 21 08:46:36.994679 2026] [security2:error] [pid 514479:tid 514705] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9cHPzqsQqnLoCgUjh0-gAAAWU"]
[Tue Jul 21 08:46:37.001512 2026] [security2:error] [pid 514479:tid 514585] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh0-wABemQ"]
[Tue Jul 21 08:46:37.005635 2026] [security2:error] [pid 514479:tid 514567] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh0_AABElI"]
[Tue Jul 21 08:46:37.054310 2026] [security2:error] [pid 514479:tid 514512] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh1AwABiRw"]
[Tue Jul 21 08:46:37.056230 2026] [security2:error] [pid 514479:tid 514552] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh1BAABiUM"]
[Tue Jul 21 08:46:37.058632 2026] [security2:error] [pid 514479:tid 514514] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh1BQABiR4"]
[Tue Jul 21 08:46:37.059626 2026] [security2:error] [pid 514479:tid 514503] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh1BgABiRM"]
[Tue Jul 21 08:46:37.060422 2026] [security2:error] [pid 514479:tid 514536] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh1BwABiTQ"]
[Tue Jul 21 08:46:37.064673 2026] [security2:error] [pid 514479:tid 514502] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh1CAABiRI"]
[Tue Jul 21 08:46:37.067603 2026] [security2:error] [pid 514479:tid 514602] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh1CQABiXU"]
[Tue Jul 21 08:46:37.074736 2026] [security2:error] [pid 514479:tid 514541] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh1CgABiTk"]
[Tue Jul 21 08:46:37.076131 2026] [security2:error] [pid 514479:tid 514606] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh1DAABiXk"]
[Tue Jul 21 08:46:37.076459 2026] [security2:error] [pid 514479:tid 514543] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh1CwABiTs"]
[Tue Jul 21 08:46:37.077608 2026] [security2:error] [pid 514479:tid 514581] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh1DQABiWA"]
[Tue Jul 21 08:46:37.084206 2026] [security2:error] [pid 514479:tid 514505] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh1DwABiRU"]
[Tue Jul 21 08:46:37.144012 2026] [security2:error] [pid 514479:tid 514576] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHfzqsQqnLoCgUjh1EAABU1s"]
[Tue Jul 21 08:46:37.370628 2026] [security2:error] [pid 514479:tid 514678] [client 203.25.124.50:33705] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/languages/plugins/options.php"] [unique_id "al9cHfzqsQqnLoCgUjh1FgAAAUo"]
[Tue Jul 21 08:46:37.452203 2026] [security2:error] [pid 511108:tid 511360] [client 49.144.66.253:31639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cHYTd5soprXwxAH0QjwAAAHo"]
[Tue Jul 21 08:46:37.452332 2026] [security2:error] [pid 511108:tid 511360] [client 49.144.66.253:31639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cHYTd5soprXwxAH0QjwAAAHo"]
[Tue Jul 21 08:46:37.553901 2026] [security2:error] [pid 514479:tid 514645] [client 41.89.234.2:63269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cHfzqsQqnLoCgUjh1GAAAASk"]
[Tue Jul 21 08:46:37.554040 2026] [security2:error] [pid 514479:tid 514645] [client 41.89.234.2:63269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cHfzqsQqnLoCgUjh1GAAAASk"]
[Tue Jul 21 08:46:37.576143 2026] [security2:error] [pid 514479:tid 514704] [client 103.76.88.37:44054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "bcsenepol.com.br"] [uri "/.env"] [unique_id "al9cHfzqsQqnLoCgUjh1GQAAAWQ"]
[Tue Jul 21 08:46:37.770669 2026] [security2:error] [pid 514479:tid 514719] [client 203.25.124.11:47091] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Requests/chosen.php"] [unique_id "al9cHfzqsQqnLoCgUjh1HQAAAXM"]
[Tue Jul 21 08:46:37.798769 2026] [security2:error] [pid 511108:tid 511147] [remote 45.79.123.44:49844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9cHYTd5soprXwxAH0QlAAAdiY"]
[Tue Jul 21 08:46:37.931305 2026] [security2:error] [pid 514479:tid 514648] [client 20.151.10.161:62367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/green3.php"] [unique_id "al9cHfzqsQqnLoCgUjh1HgAAASw"]
[Tue Jul 21 08:46:38.037250 2026] [security2:error] [pid 511108:tid 511189] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cHoTd5soprXwxAH0QmgAANFA"]
[Tue Jul 21 08:46:38.037398 2026] [security2:error] [pid 511108:tid 511290] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cHoTd5soprXwxAH0QmgAANFA"]
[Tue Jul 21 08:46:38.577330 2026] [security2:error] [pid 514479:tid 514684] [client 203.25.124.35:64121] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/tinymce/themes/panel.php"] [unique_id "al9cHvzqsQqnLoCgUjh1KAAAAVA"]
[Tue Jul 21 08:46:38.850690 2026] [security2:error] [pid 514479:tid 514588] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHvzqsQqnLoCgUjh1MgABI2c"]
[Tue Jul 21 08:46:38.851097 2026] [security2:error] [pid 514479:tid 514589] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHvzqsQqnLoCgUjh1NAABI2g"]
[Tue Jul 21 08:46:38.851131 2026] [security2:error] [pid 514479:tid 514506] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHvzqsQqnLoCgUjh1MwABIxY"]
[Tue Jul 21 08:46:38.851944 2026] [security2:error] [pid 514479:tid 514554] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHvzqsQqnLoCgUjh1NgABI0U"]
[Tue Jul 21 08:46:38.858387 2026] [security2:error] [pid 514479:tid 514561] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHvzqsQqnLoCgUjh1OAABI0w"]
[Tue Jul 21 08:46:38.858392 2026] [security2:error] [pid 514479:tid 514578] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHvzqsQqnLoCgUjh1NwABI10"]
[Tue Jul 21 08:46:38.864627 2026] [security2:error] [pid 514479:tid 514537] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHvzqsQqnLoCgUjh1OgABIzU"]
[Tue Jul 21 08:46:38.864662 2026] [security2:error] [pid 514479:tid 514569] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHvzqsQqnLoCgUjh1OQABI1Q"]
[Tue Jul 21 08:46:38.865729 2026] [security2:error] [pid 514479:tid 514600] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHvzqsQqnLoCgUjh1PAABI3M"]
[Tue Jul 21 08:46:38.865980 2026] [security2:error] [pid 514479:tid 514526] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHvzqsQqnLoCgUjh1OwABIyo"]
[Tue Jul 21 08:46:38.874912 2026] [security2:error] [pid 514479:tid 514546] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHvzqsQqnLoCgUjh1PQABIz4"]
[Tue Jul 21 08:46:38.876718 2026] [security2:error] [pid 514479:tid 514605] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHvzqsQqnLoCgUjh1PwABI3g"]
[Tue Jul 21 08:46:38.877751 2026] [security2:error] [pid 514479:tid 514579] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/"] [unique_id "al9cHvzqsQqnLoCgUjh1QAABI14"]
[Tue Jul 21 08:46:38.946222 2026] [security2:error] [pid 511108:tid 511332] [client 20.197.195.24:17819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/goods.php"] [unique_id "al9cHoTd5soprXwxAH0QpwAAAF4"]
[Tue Jul 21 08:46:39.139570 2026] [security2:error] [pid 514479:tid 514637] [client 212.32.76.6:44395] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/assets/"] [unique_id "al9cH_zqsQqnLoCgUjh1SAAAASE"]
[Tue Jul 21 08:46:39.253351 2026] [security2:error] [pid 514479:tid 514641] [client 20.151.10.161:62438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/ccs.php"] [unique_id "al9cH_zqsQqnLoCgUjh1SQAAASU"]
[Tue Jul 21 08:46:39.566385 2026] [security2:error] [pid 514479:tid 514686] [client 20.197.192.193:27085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/hp3.php"] [unique_id "al9cH_zqsQqnLoCgUjh1TwAAAVI"]
[Tue Jul 21 08:46:39.772742 2026] [security2:error] [pid 514479:tid 514710] [client 212.32.76.11:43423] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Requests/Response/Response/multisite-setup.php"] [unique_id "al9cH_zqsQqnLoCgUjh1UgAAAWo"]
[Tue Jul 21 08:46:39.773121 2026] [security2:error] [pid 514479:tid 514632] [client 20.197.192.193:53628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/aa1.php"] [unique_id "al9cH_zqsQqnLoCgUjh1UQAAARw"]
[Tue Jul 21 08:46:39.935872 2026] [security2:error] [pid 511108:tid 511259] [client 203.25.124.65:55239] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/hello.php"] [unique_id "al9cH4Td5soprXwxAH0QsgAAABU"]
[Tue Jul 21 08:46:39.943958 2026] [security2:error] [pid 511108:tid 511256] [client 168.167.81.163:63201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cH4Td5soprXwxAH0QswAAABI"]
[Tue Jul 21 08:46:39.944067 2026] [security2:error] [pid 511108:tid 511256] [client 168.167.81.163:63201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cH4Td5soprXwxAH0QswAAABI"]
[Tue Jul 21 08:46:40.486218 2026] [security2:error] [pid 514479:tid 514741] [client 65.21.113.253:51242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cIPzqsQqnLoCgUjh1VQAAAYk"]
[Tue Jul 21 08:46:40.540919 2026] [security2:error] [pid 511108:tid 511323] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cIITd5soprXwxAH0QvwAAVRE"]
[Tue Jul 21 08:46:41.050176 2026] [security2:error] [pid 511108:tid 511224] [remote 31.59.129.193:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "focsmart.com.br"] [uri "/api/config"] [unique_id "al9cIYTd5soprXwxAH0QyAAAS3M"]
[Tue Jul 21 08:46:41.060020 2026] [security2:error] [pid 511108:tid 511260] [client 203.25.124.42:49325] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/data.php"] [unique_id "al9cIYTd5soprXwxAH0QyQAAABY"]
[Tue Jul 21 08:46:41.082262 2026] [security2:error] [pid 511108:tid 511153] [remote 31.59.129.193:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "focsmart.com.br"] [uri "/config.json"] [unique_id "al9cIYTd5soprXwxAH0QywAATiw"]
[Tue Jul 21 08:46:41.082407 2026] [security2:error] [pid 511108:tid 511316] [client 31.59.129.193:0] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "focsmart.com.br"] [uri "/config.json"] [unique_id "al9cIYTd5soprXwxAH0QywAATiw"]
[Tue Jul 21 08:46:41.225958 2026] [security2:error] [pid 511108:tid 511284] [client 5.31.193.106:1823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cIYTd5soprXwxAH0Q0AAAAC4"]
[Tue Jul 21 08:46:41.226097 2026] [security2:error] [pid 511108:tid 511284] [client 5.31.193.106:1823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cIYTd5soprXwxAH0Q0AAAAC4"]
[Tue Jul 21 08:46:41.282737 2026] [security2:error] [pid 511108:tid 511336] [client 203.25.124.197:47203] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/admin.php"] [unique_id "al9cIYTd5soprXwxAH0Q0QAAAGI"]
[Tue Jul 21 08:46:41.321748 2026] [security2:error] [pid 514479:tid 514534] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env.bak"] [unique_id "al9cIfzqsQqnLoCgUjh1eAABRDI"]
[Tue Jul 21 08:46:41.321851 2026] [security2:error] [pid 514479:tid 514489] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env.production.bak"] [unique_id "al9cIfzqsQqnLoCgUjh1dwABRAU"]
[Tue Jul 21 08:46:41.321862 2026] [security2:error] [pid 514479:tid 514522] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env.swp"] [unique_id "al9cIfzqsQqnLoCgUjh1ewABRCY"]
[Tue Jul 21 08:46:41.322937 2026] [security2:error] [pid 514479:tid 514562] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env.local.bak"] [unique_id "al9cIfzqsQqnLoCgUjh1fgABRE0"]
[Tue Jul 21 08:46:41.323533 2026] [security2:error] [pid 514479:tid 514555] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/wp-login.php"] [unique_id "al9cIfzqsQqnLoCgUjh1cQABREY"]
[Tue Jul 21 08:46:41.335660 2026] [security2:error] [pid 514479:tid 514607] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env.backup"] [unique_id "al9cIfzqsQqnLoCgUjh1gAABRHo"]
[Tue Jul 21 08:46:41.336021 2026] [security2:error] [pid 514479:tid 514575] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env~"] [unique_id "al9cIfzqsQqnLoCgUjh1ggABRFo"]
[Tue Jul 21 08:46:41.336690 2026] [security2:error] [pid 514479:tid 514509] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env.old"] [unique_id "al9cIfzqsQqnLoCgUjh1gQABRBk"]
[Tue Jul 21 08:46:41.339708 2026] [security2:error] [pid 514479:tid 514574] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/config.php.bak"] [unique_id "al9cIfzqsQqnLoCgUjh1iwABRFk"]
[Tue Jul 21 08:46:41.340042 2026] [security2:error] [pid 514479:tid 514584] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/config.php.old"] [unique_id "al9cIfzqsQqnLoCgUjh1jAABRGM"]
[Tue Jul 21 08:46:41.341629 2026] [security2:error] [pid 514479:tid 514504] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env.orig"] [unique_id "al9cIfzqsQqnLoCgUjh1jQABRBQ"]
[Tue Jul 21 08:46:41.343222 2026] [security2:error] [pid 514479:tid 514488] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/wp-login.php"] [unique_id "al9cIfzqsQqnLoCgUjh1lgABRAQ"]
[Tue Jul 21 08:46:41.345982 2026] [security2:error] [pid 514479:tid 514525] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cIfzqsQqnLoCgUjh1nwABRCk"]
[Tue Jul 21 08:46:41.351923 2026] [security2:error] [pid 514479:tid 514612] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php"] [unique_id "al9cIfzqsQqnLoCgUjh1owABRH8"]
[Tue Jul 21 08:46:41.363645 2026] [security2:error] [pid 514479:tid 514553] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9cIfzqsQqnLoCgUjh1pAABREQ"]
[Tue Jul 21 08:46:41.457728 2026] [security2:error] [pid 514479:tid 514490] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cIfzqsQqnLoCgUjh1pgABRAY"]
[Tue Jul 21 08:46:41.475527 2026] [autoindex:error] [pid 511108:tid 511265] [client 23.180.120.146:50854] AH01276: Cannot serve directory /home1/bastar15/mirth.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:46:41.504943 2026] [security2:error] [pid 514479:tid 514499] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cIfzqsQqnLoCgUjh1qAABNg8"]
[Tue Jul 21 08:46:41.505080 2026] [security2:error] [pid 514479:tid 514658] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cIfzqsQqnLoCgUjh1qAABNg8"]
[Tue Jul 21 08:46:41.610948 2026] [security2:error] [pid 514479:tid 514700] [client 20.151.10.161:62355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/ccc.php"] [unique_id "al9cIfzqsQqnLoCgUjh1qQAAAWA"]
[Tue Jul 21 08:46:41.645882 2026] [security2:error] [pid 514479:tid 514702] [client 203.25.124.43:60285] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/maint/"] [unique_id "al9cIfzqsQqnLoCgUjh1qgAAAWI"]
[Tue Jul 21 08:46:41.741368 2026] [security2:error] [pid 511108:tid 511348] [client 202.179.75.202:36352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cIYTd5soprXwxAH0Q4wAAAG4"]
[Tue Jul 21 08:46:41.741478 2026] [security2:error] [pid 511108:tid 511348] [client 202.179.75.202:36352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cIYTd5soprXwxAH0Q4wAAAG4"]
[Tue Jul 21 08:46:41.972665 2026] [security2:error] [pid 514479:tid 514590] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cIfzqsQqnLoCgUjh1swABXWk"]
[Tue Jul 21 08:46:41.972795 2026] [security2:error] [pid 514479:tid 514697] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cIfzqsQqnLoCgUjh1swABXWk"]
[Tue Jul 21 08:46:42.269188 2026] [security2:error] [pid 514479:tid 514659] [client 20.151.10.161:62458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/get.php"] [unique_id "al9cIvzqsQqnLoCgUjh1tQAAATc"]
[Tue Jul 21 08:46:42.272066 2026] [security2:error] [pid 511108:tid 511286] [client 212.32.76.13:25781] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/crop/crop/sitemap-generator.php"] [unique_id "al9cIoTd5soprXwxAH0Q6QAAADA"]
[Tue Jul 21 08:46:42.275783 2026] [security2:error] [pid 514479:tid 514738] [client 203.25.124.10:62345] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/block-patterns/chosen.php"] [unique_id "al9cIvzqsQqnLoCgUjh1tgAAAYY"]
[Tue Jul 21 08:46:42.741152 2026] [security2:error] [pid 514479:tid 514650] [client 203.25.124.33:55195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wordpress/wp-admin/maint/"] [unique_id "al9cIvzqsQqnLoCgUjh1vwAAAS4"]
[Tue Jul 21 08:46:42.815779 2026] [security2:error] [pid 511108:tid 511119] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cIoTd5soprXwxAH0Q_AAAFQo"]
[Tue Jul 21 08:46:42.815922 2026] [security2:error] [pid 511108:tid 511259] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cIoTd5soprXwxAH0Q_AAAFQo"]
[Tue Jul 21 08:46:42.922392 2026] [security2:error] [pid 511108:tid 511215] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/database.yml.bak"] [unique_id "al9cIoTd5soprXwxAH0Q_wAARWo"]
[Tue Jul 21 08:46:42.922458 2026] [security2:error] [pid 511108:tid 511143] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/settings.py.bak"] [unique_id "al9cIoTd5soprXwxAH0RAAAARSI"]
[Tue Jul 21 08:46:42.922523 2026] [security2:error] [pid 511108:tid 511125] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/appsettings.json.bak"] [unique_id "al9cIoTd5soprXwxAH0Q_gAARRA"]
[Tue Jul 21 08:46:42.985548 2026] [security2:error] [pid 514479:tid 514690] [client 203.25.124.4:63731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/ws.php"] [unique_id "al9cIvzqsQqnLoCgUjh1xQAAAVY"]
[Tue Jul 21 08:46:43.014070 2026] [security2:error] [pid 514479:tid 514737] [client 185.198.240.15:62137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mbarcondicionados.com.br"] [uri "/wp-login.php"] [unique_id "al9cI_zqsQqnLoCgUjh1xgAAAYU"]
[Tue Jul 21 08:46:43.035873 2026] [security2:error] [pid 511108:tid 511176] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.htaccess.bak"] [unique_id "al9cI4Td5soprXwxAH0RAgAAeUM"]
[Tue Jul 21 08:46:43.056120 2026] [security2:error] [pid 511108:tid 511148] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cI4Td5soprXwxAH0REwAAeSc"]
[Tue Jul 21 08:46:43.071894 2026] [security2:error] [pid 511108:tid 511155] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/vendor/phpunit/phpunit/Util/PHP/eval-stdin.php"] [unique_id "al9cI4Td5soprXwxAH0RFQAAeS4"]
[Tue Jul 21 08:46:43.169219 2026] [security2:error] [pid 511108:tid 511135] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cI4Td5soprXwxAH0RHAAAeRo"]
[Tue Jul 21 08:46:43.177404 2026] [security2:error] [pid 511108:tid 511326] [client 5.38.115.39:58236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cI4Td5soprXwxAH0RHQAAAFg"]
[Tue Jul 21 08:46:43.177578 2026] [security2:error] [pid 511108:tid 511326] [client 5.38.115.39:58236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cI4Td5soprXwxAH0RHQAAAFg"]
[Tue Jul 21 08:46:43.222368 2026] [security2:error] [pid 511108:tid 511151] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/dump.sql"] [unique_id "al9cI4Td5soprXwxAH0RIgAAeSo"]
[Tue Jul 21 08:46:43.360249 2026] [security2:error] [pid 514479:tid 514688] [client 203.25.124.36:55889] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Requests/Transport/Transport/spam-filter.php"] [unique_id "al9cI_zqsQqnLoCgUjh14gAAAVQ"]
[Tue Jul 21 08:46:43.529138 2026] [security2:error] [pid 514479:tid 514649] [client 20.151.10.161:62352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/images.php"] [unique_id "al9cI_zqsQqnLoCgUjh17wAAAS0"]
[Tue Jul 21 08:46:43.675252 2026] [security2:error] [pid 514479:tid 514681] [client 212.32.76.66:23193] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/tinymce/plugins/wp-load.php"] [unique_id "al9cI_zqsQqnLoCgUjh18gAAAU0"]
[Tue Jul 21 08:46:43.998158 2026] [security2:error] [pid 514479:tid 514674] [client 173.252.95.8:37334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cI_zqsQqnLoCgUjh1_QAAAUY"]
[Tue Jul 21 08:46:44.093432 2026] [security2:error] [pid 514479:tid 514651] [client 20.151.10.161:62400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/alls.php"] [unique_id "al9cJPzqsQqnLoCgUjh2DgAAAS8"]
[Tue Jul 21 08:46:44.099075 2026] [security2:error] [pid 514479:tid 514625] [client 114.198.138.124:55482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cJPzqsQqnLoCgUjh2DwAAARU"]
[Tue Jul 21 08:46:44.099217 2026] [security2:error] [pid 514479:tid 514625] [client 114.198.138.124:55482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cJPzqsQqnLoCgUjh2DwAAARU"]
[Tue Jul 21 08:46:44.241157 2026] [security2:error] [pid 514479:tid 514656] [client 203.25.124.41:23283] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/admin.php"] [unique_id "al9cJPzqsQqnLoCgUjh2EwAAATQ"]
[Tue Jul 21 08:46:44.360983 2026] [security2:error] [pid 514479:tid 514643] [client 203.25.124.68:49157] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/db-status.php"] [unique_id "al9cJPzqsQqnLoCgUjh2FwAAASc"]
[Tue Jul 21 08:46:44.566693 2026] [security2:error] [pid 511108:tid 511270] [client 20.197.192.193:27082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/aa1.php"] [unique_id "al9cJITd5soprXwxAH0RNgAAACA"]
[Tue Jul 21 08:46:44.616290 2026] [security2:error] [pid 514479:tid 514540] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/database.sql"] [unique_id "al9cJPzqsQqnLoCgUjh2HwABGTg"]
[Tue Jul 21 08:46:44.616308 2026] [security2:error] [pid 514479:tid 514593] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/backup.sql"] [unique_id "al9cJPzqsQqnLoCgUjh2IAABGWw"]
[Tue Jul 21 08:46:44.616308 2026] [security2:error] [pid 514479:tid 514559] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/db.sql"] [unique_id "al9cJPzqsQqnLoCgUjh2IQABGUo"]
[Tue Jul 21 08:46:44.642834 2026] [security2:error] [pid 511108:tid 511351] [client 195.49.128.211:56586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9cJITd5soprXwxAH0ROAAAAHE"]
[Tue Jul 21 08:46:44.643024 2026] [security2:error] [pid 511108:tid 511351] [client 195.49.128.211:56586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9cJITd5soprXwxAH0ROAAAAHE"]
[Tue Jul 21 08:46:44.670903 2026] [security2:error] [pid 511108:tid 511141] [remote 100.42.189.89:47738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kaducontractor.com"] [uri "/wp-login.php"] [unique_id "al9cJITd5soprXwxAH0ROQAAayA"]
[Tue Jul 21 08:46:44.710908 2026] [security2:error] [pid 514479:tid 514588] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/mysql.sql"] [unique_id "al9cJPzqsQqnLoCgUjh2IgABUGc"]
[Tue Jul 21 08:46:44.713115 2026] [security2:error] [pid 514479:tid 514589] [remote 69.5.20.170:43224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.20.5.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ellosemijoias.com.br"] [uri "/wp-login.php"] [unique_id "al9cJPzqsQqnLoCgUjh2IwABbWg"]
[Tue Jul 21 08:46:44.722501 2026] [security2:error] [pid 514479:tid 514506] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cJPzqsQqnLoCgUjh2JAABgxY"]
[Tue Jul 21 08:46:44.737124 2026] [security2:error] [pid 514479:tid 514694] [client 20.151.10.161:62339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/yyu.php"] [unique_id "al9cJPzqsQqnLoCgUjh2JQAAAVo"]
[Tue Jul 21 08:46:44.737129 2026] [security2:error] [pid 514479:tid 514554] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/vendor/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9cJPzqsQqnLoCgUjh2JgABH0U"]
[Tue Jul 21 08:46:44.778679 2026] [security2:error] [pid 514479:tid 514561] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/export.sql"] [unique_id "al9cJPzqsQqnLoCgUjh2KQABdkw"]
[Tue Jul 21 08:46:44.869281 2026] [security2:error] [pid 514479:tid 514664] [client 212.32.76.57:44861] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "al9cJPzqsQqnLoCgUjh2KwAAATw"]
[Tue Jul 21 08:46:44.948852 2026] [core:error] [pid 514479:tid 514685] (104)Connection reset by peer: [client 127.0.0.1:34850] AH00574: ap_content_length_filter: apr_bucket_read() failed
[Tue Jul 21 08:46:44.948952 2026] [proxy_http:error] [pid 514479:tid 514569] (70008)Partial results are valid but processing is incomplete: [remote 103.215.75.19:0] AH01110: error reading response
[Tue Jul 21 08:46:44.965195 2026] [security2:error] [pid 511108:tid 511242] [client 173.252.95.25:62798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cI4Td5soprXwxAH0RLQAAAAQ"]
[Tue Jul 21 08:46:45.125477 2026] [security2:error] [pid 514479:tid 514665] [client 20.197.192.193:53620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/acew67.php"] [unique_id "al9cJfzqsQqnLoCgUjh2UgAAAT0"]
[Tue Jul 21 08:46:45.256656 2026] [security2:error] [pid 511108:tid 511336] [client 113.22.144.139:60641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cJYTd5soprXwxAH0RQgAAAGI"]
[Tue Jul 21 08:46:45.256802 2026] [security2:error] [pid 511108:tid 511336] [client 113.22.144.139:60641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cJYTd5soprXwxAH0RQgAAAGI"]
[Tue Jul 21 08:46:45.265718 2026] [security2:error] [pid 514479:tid 514668] [client 212.32.76.4:39971] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/SimplePie/XML/XML/sitemap-generator.php"] [unique_id "al9cJfzqsQqnLoCgUjh2WgAAAUA"]
[Tue Jul 21 08:46:45.370391 2026] [security2:error] [pid 514479:tid 514650] [client 20.151.10.161:62354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/by.php"] [unique_id "al9cJfzqsQqnLoCgUjh2XAAAAS4"]
[Tue Jul 21 08:46:45.445992 2026] [security2:error] [pid 511108:tid 511346] [client 212.32.76.14:48387] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/admin.php"] [unique_id "al9cJYTd5soprXwxAH0RRgAAAGw"]
[Tue Jul 21 08:46:45.542550 2026] [security2:error] [pid 511108:tid 511241] [client 23.180.120.146:50868] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "www.mirth.com.br.bastarecomecar.com.br"] [uri "/"] [unique_id "al9cJYTd5soprXwxAH0RSAAAAAM"]
[Tue Jul 21 08:46:45.785159 2026] [security2:error] [pid 514479:tid 514659] [client 59.95.197.55:60441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cJfzqsQqnLoCgUjh2YwAAATc"]
[Tue Jul 21 08:46:45.785300 2026] [security2:error] [pid 514479:tid 514659] [client 59.95.197.55:60441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cJfzqsQqnLoCgUjh2YwAAATc"]
[Tue Jul 21 08:46:45.858614 2026] [security2:error] [pid 514479:tid 514717] [client 65.21.113.253:51242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cJfzqsQqnLoCgUjh2XgAAAXE"]
[Tue Jul 21 08:46:45.873786 2026] [security2:error] [pid 514479:tid 514655] [client 203.25.124.202:24769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/simple.php"] [unique_id "al9cJfzqsQqnLoCgUjh2ZQAAATM"]
[Tue Jul 21 08:46:46.290292 2026] [security2:error] [pid 511108:tid 511130] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env"] [unique_id "al9cJoTd5soprXwxAH0RVgAAERU"]
[Tue Jul 21 08:46:46.293036 2026] [security2:error] [pid 511108:tid 511111] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/assets../.env"] [unique_id "al9cJoTd5soprXwxAH0RWAAADAI"]
[Tue Jul 21 08:46:46.293036 2026] [security2:error] [pid 511108:tid 511216] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/static../.env"] [unique_id "al9cJoTd5soprXwxAH0RVwAADGs"]
[Tue Jul 21 08:46:46.335269 2026] [security2:error] [pid 511108:tid 511320] [client 195.49.128.211:64588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cJoTd5soprXwxAH0RXQAAAFI"]
[Tue Jul 21 08:46:46.335414 2026] [security2:error] [pid 511108:tid 511320] [client 195.49.128.211:64588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cJoTd5soprXwxAH0RXQAAAFI"]
[Tue Jul 21 08:46:46.339989 2026] [security2:error] [pid 514479:tid 514720] [client 23.180.120.146:50872] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "www.mirth.com.br.bastarecomecar.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9cJvzqsQqnLoCgUjh2bQAAAXQ"]
[Tue Jul 21 08:46:46.358010 2026] [security2:error] [pid 514479:tid 514722] [client 203.25.124.48:64691] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/test.php"] [unique_id "al9cJvzqsQqnLoCgUjh2cwAAAXY"]
[Tue Jul 21 08:46:46.402487 2026] [security2:error] [pid 514479:tid 514644] [client 20.197.192.193:27100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/acew67.php"] [unique_id "al9cJvzqsQqnLoCgUjh2egAAASg"]
[Tue Jul 21 08:46:46.491772 2026] [security2:error] [pid 511108:tid 511227] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cJoTd5soprXwxAH0RZgAAb3Y"]
[Tue Jul 21 08:46:46.507572 2026] [security2:error] [pid 511108:tid 511189] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9cJoTd5soprXwxAH0RZwAAb1A"]
[Tue Jul 21 08:46:46.518225 2026] [security2:error] [pid 514479:tid 514731] [client 20.151.10.161:62460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/FAQ.php"] [unique_id "al9cJvzqsQqnLoCgUjh2fwAAAX8"]
[Tue Jul 21 08:46:46.525810 2026] [security2:error] [pid 514479:tid 514624] [client 122.176.100.127:62159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cJvzqsQqnLoCgUjh2gAAAARQ"]
[Tue Jul 21 08:46:46.526044 2026] [security2:error] [pid 514479:tid 514624] [client 122.176.100.127:62159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cJvzqsQqnLoCgUjh2gAAAARQ"]
[Tue Jul 21 08:46:46.565324 2026] [security2:error] [pid 511108:tid 511178] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cJoTd5soprXwxAH0RagAAQEU"]
[Tue Jul 21 08:46:46.641533 2026] [security2:error] [pid 514479:tid 514710] [client 203.25.124.40:51043] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/edit.php"] [unique_id "al9cJvzqsQqnLoCgUjh2hQAAAWo"]
[Tue Jul 21 08:46:46.701254 2026] [security2:error] [pid 511108:tid 511239] [client 51.161.37.80:21466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.10db.com.br"] [uri "/robots.txt"] [unique_id "al9cJoTd5soprXwxAH0RbAAAAAE"]
[Tue Jul 21 08:46:46.701368 2026] [security2:error] [pid 511108:tid 511239] [client 51.161.37.80:21466] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.10db.com.br"] [uri "/robots.txt"] [unique_id "al9cJoTd5soprXwxAH0RbAAAAAE"]
[Tue Jul 21 08:46:46.770408 2026] [security2:error] [pid 511108:tid 511169] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cJoTd5soprXwxAH0RbwAAPDw"]
[Tue Jul 21 08:46:46.773658 2026] [security2:error] [pid 511108:tid 511295] [client 203.25.124.198:31525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/link/"] [unique_id "al9cJoTd5soprXwxAH0RcgAAADk"]
[Tue Jul 21 08:46:46.805236 2026] [core:error] [pid 514479:tid 514651] (104)Connection reset by peer: [client 127.0.0.1:35048] AH00574: ap_content_length_filter: apr_bucket_read() failed
[Tue Jul 21 08:46:46.805411 2026] [proxy_http:error] [pid 511108:tid 511174] (70008)Partial results are valid but processing is incomplete: [remote 103.215.75.19:0] AH01110: error reading response
[Tue Jul 21 08:46:46.816076 2026] [security2:error] [pid 514479:tid 514574] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cJvzqsQqnLoCgUjh2hgABTlk"]
[Tue Jul 21 08:46:46.816257 2026] [security2:error] [pid 514479:tid 514682] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cJvzqsQqnLoCgUjh2hgABTlk"]
[Tue Jul 21 08:46:47.118994 2026] [security2:error] [pid 514479:tid 514653] [client 74.7.241.143:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "joaobatistaborgesjun1746391689565.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9cJ_zqsQqnLoCgUjh2pAABMRs"]
[Tue Jul 21 08:46:47.452045 2026] [security2:error] [pid 511108:tid 511259] [client 61.1.167.83:64160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cJ4Td5soprXwxAH0RkAAAABU"]
[Tue Jul 21 08:46:47.457268 2026] [security2:error] [pid 511108:tid 511259] [client 61.1.167.83:64160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cJ4Td5soprXwxAH0RkAAAABU"]
[Tue Jul 21 08:46:47.609772 2026] [core:alert] [pid 514479:tid 514725] [client 57.141.18.82:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:46:47.670701 2026] [security2:error] [pid 511108:tid 511334] [client 203.25.124.215:46231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/jquery/ui/ui/forum-engine.php"] [unique_id "al9cJ4Td5soprXwxAH0RlQAAAGA"]
[Tue Jul 21 08:46:47.771285 2026] [security2:error] [pid 511108:tid 511342] [client 203.25.124.198:57325] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/config.php"] [unique_id "al9cJ4Td5soprXwxAH0RlgAAAGg"]
[Tue Jul 21 08:46:47.944555 2026] [security2:error] [pid 514479:tid 514596] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env"] [unique_id "al9cJ_zqsQqnLoCgUjh2wwABbW8"]
[Tue Jul 21 08:46:47.946921 2026] [security2:error] [pid 514479:tid 514491] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/uploads../.env"] [unique_id "al9cJ_zqsQqnLoCgUjh2xAABhgc"]
[Tue Jul 21 08:46:47.948597 2026] [security2:error] [pid 514479:tid 514513] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/public../.env"] [unique_id "al9cJ_zqsQqnLoCgUjh2yAABhh0"]
[Tue Jul 21 08:46:47.948801 2026] [security2:error] [pid 514479:tid 514591] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/media../.env"] [unique_id "al9cJ_zqsQqnLoCgUjh2xQABhmo"]
[Tue Jul 21 08:46:47.948801 2026] [security2:error] [pid 514479:tid 514549] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/files../.env"] [unique_id "al9cJ_zqsQqnLoCgUjh2xgABhkA"]
[Tue Jul 21 08:46:47.948800 2026] [security2:error] [pid 514479:tid 514557] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/img../.env"] [unique_id "al9cJ_zqsQqnLoCgUjh2xwABhkg"]
[Tue Jul 21 08:46:47.960696 2026] [security2:error] [pid 514479:tid 514580] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env"] [unique_id "al9cJ_zqsQqnLoCgUjh2ygABgV8"]
[Tue Jul 21 08:46:47.974190 2026] [security2:error] [pid 514479:tid 514736] [client 103.59.206.240:31290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cJ_zqsQqnLoCgUjh2zgAAAYQ"]
[Tue Jul 21 08:46:47.974263 2026] [security2:error] [pid 514479:tid 514736] [client 103.59.206.240:31290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cJ_zqsQqnLoCgUjh2zgAAAYQ"]
[Tue Jul 21 08:46:48.035159 2026] [security2:error] [pid 514479:tid 514732] [client 203.25.124.32:31797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/archives/"] [unique_id "al9cKPzqsQqnLoCgUjh20wAAAYA"]
[Tue Jul 21 08:46:48.091149 2026] [security2:error] [pid 514479:tid 514590] [remote 103.215.75.19:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.infoalert.com.br"] [uri "/.env.backup"] [unique_id "al9cKPzqsQqnLoCgUjh21AABQGk"]
[Tue Jul 21 08:46:48.106640 2026] [security2:error] [pid 514479:tid 514669] [client 41.89.234.2:63718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cKPzqsQqnLoCgUjh21QAAAUE"]
[Tue Jul 21 08:46:48.106734 2026] [security2:error] [pid 514479:tid 514669] [client 41.89.234.2:63718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cKPzqsQqnLoCgUjh21QAAAUE"]
[Tue Jul 21 08:46:48.120944 2026] [security2:error] [pid 511108:tid 511267] [client 142.44.225.98:30378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.10db.com.br"] [uri "/"] [unique_id "al9cKITd5soprXwxAH0RowAAAB0"]
[Tue Jul 21 08:46:48.121070 2026] [security2:error] [pid 511108:tid 511267] [client 142.44.225.98:30378] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.10db.com.br"] [uri "/"] [unique_id "al9cKITd5soprXwxAH0RowAAAB0"]
[Tue Jul 21 08:46:48.235569 2026] [security2:error] [pid 514479:tid 514707] [client 20.151.10.161:62461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/coffexium.php"] [unique_id "al9cKPzqsQqnLoCgUjh22AAAAWc"]
[Tue Jul 21 08:46:48.308373 2026] [security2:error] [pid 511108:tid 511187] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9cKITd5soprXwxAH0RqwAAME4"]
[Tue Jul 21 08:46:48.574259 2026] [security2:error] [pid 514479:tid 514724] [client 212.32.76.66:43631] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "al9cKPzqsQqnLoCgUjh2-QAAAXg"]
[Tue Jul 21 08:46:48.598762 2026] [security2:error] [pid 514479:tid 514500] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cKPzqsQqnLoCgUjh2_wABEBA"]
[Tue Jul 21 08:46:48.598903 2026] [security2:error] [pid 514479:tid 514620] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cKPzqsQqnLoCgUjh2_wABEBA"]
[Tue Jul 21 08:46:48.614126 2026] [security2:error] [pid 514479:tid 514604] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cKPzqsQqnLoCgUjh3AgABT3c"]
[Tue Jul 21 08:46:48.675422 2026] [access_compat:error] [pid 511108:tid 511119] [remote 103.215.75.19:0] AH01797: client denied by server configuration: proxy:http://127.0.0.1/cgi-sys/autodiscover.cgi
[Tue Jul 21 08:46:48.763958 2026] [security2:error] [pid 511108:tid 511361] [client 203.25.124.74:45871] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/tinymce/plugins/ms-files.php"] [unique_id "al9cKITd5soprXwxAH0RuwAAAHs"]
[Tue Jul 21 08:46:48.856926 2026] [security2:error] [pid 514479:tid 514667] [client 49.144.66.253:32062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cKPzqsQqnLoCgUjh3FAAAAT8"]
[Tue Jul 21 08:46:48.857046 2026] [security2:error] [pid 514479:tid 514667] [client 49.144.66.253:32062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cKPzqsQqnLoCgUjh3FAAAAT8"]
[Tue Jul 21 08:46:49.143502 2026] [security2:error] [pid 514479:tid 514660] [client 203.25.124.33:35135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/includes/"] [unique_id "al9cKfzqsQqnLoCgUjh3HQAAATg"]
[Tue Jul 21 08:46:49.534949 2026] [security2:error] [pid 511108:tid 511239] [client 74.7.244.36:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.componentemais.com.br.consertauto.com"] [uri "/index.php"] [unique_id "al9cKITd5soprXwxAH0RwAAAAAE"]
[Tue Jul 21 08:46:49.541923 2026] [security2:error] [pid 514479:tid 514624] [client 74.7.244.36:40660] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.componentemais.com.br.consertauto.com"] [uri "/robots.txt"] [unique_id "al9cKPzqsQqnLoCgUjh3FQABFBU"]
[Tue Jul 21 08:46:49.647534 2026] [security2:error] [pid 514479:tid 514710] [client 65.21.113.253:51242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cKfzqsQqnLoCgUjh3GwAAAWo"]
[Tue Jul 21 08:46:49.673203 2026] [security2:error] [pid 514479:tid 514726] [client 203.25.124.197:23713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/codemirror/"] [unique_id "al9cKfzqsQqnLoCgUjh3KwAAAXo"]
[Tue Jul 21 08:46:49.766898 2026] [security2:error] [pid 514479:tid 514711] [client 203.25.124.71:52757] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/includes/includes/logo/se.php"] [unique_id "al9cKfzqsQqnLoCgUjh3LQAAAWs"]
[Tue Jul 21 08:46:49.868537 2026] [core:error] [pid 511108:tid 511172] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:46:49.868559 2026] [core:error] [pid 511108:tid 511172] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:46:49.878871 2026] [security2:error] [pid 514479:tid 514669] [client 196.251.121.187:54708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "ryancastroweb.com"] [uri "/"] [unique_id "al9cKfzqsQqnLoCgUjh3LwAAAUE"]
[Tue Jul 21 08:46:50.120493 2026] [core:error] [pid 511108:tid 511232] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:46:50.120522 2026] [core:error] [pid 511108:tid 511232] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:46:50.174357 2026] [security2:error] [pid 514479:tid 514588] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9cKvzqsQqnLoCgUjh3MQABFWc"]
[Tue Jul 21 08:46:50.443685 2026] [security2:error] [pid 514479:tid 514662] [client 203.25.124.41:23957] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/x.php"] [unique_id "al9cKvzqsQqnLoCgUjh3NQAAATo"]
[Tue Jul 21 08:46:50.447052 2026] [security2:error] [pid 511108:tid 511145] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cKoTd5soprXwxAH0R3gAALCQ"]
[Tue Jul 21 08:46:50.464670 2026] [security2:error] [pid 514479:tid 514698] [client 20.151.10.161:62371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/red.php"] [unique_id "al9cKvzqsQqnLoCgUjh3NgAAAV4"]
[Tue Jul 21 08:46:50.518013 2026] [security2:error] [pid 514479:tid 514653] [client 20.10.88.227:1730] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tryhealth.shop"] [uri "/robots.txt"] [unique_id "al9cKvzqsQqnLoCgUjh3OAAAATE"]
[Tue Jul 21 08:46:50.663370 2026] [security2:error] [pid 514479:tid 514667] [client 203.25.124.41:34135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/widgets/shadow-bot.php"] [unique_id "al9cKvzqsQqnLoCgUjh3QAAAAT8"]
[Tue Jul 21 08:46:50.677003 2026] [security2:error] [pid 511108:tid 511255] [client 203.25.124.188:20325] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/ab.php"] [unique_id "al9cKoTd5soprXwxAH0R6QAAABE"]
[Tue Jul 21 08:46:50.922221 2026] [security2:error] [pid 514479:tid 514578] [remote 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cKvzqsQqnLoCgUjh3QwABY10"]
[Tue Jul 21 08:46:51.148645 2026] [security2:error] [pid 514479:tid 514537] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.promocao-relampago.club"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9cK_zqsQqnLoCgUjh3RgABhjU"]
[Tue Jul 21 08:46:51.199205 2026] [security2:error] [pid 514479:tid 514617] [client 20.197.192.193:27078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/bscclapb.php"] [unique_id "al9cK_zqsQqnLoCgUjh3RwAAAQ0"]
[Tue Jul 21 08:46:51.346879 2026] [security2:error] [pid 511108:tid 511140] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.promocao-relampago.club"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9cK4Td5soprXwxAH0R8gAAbx8"]
[Tue Jul 21 08:46:51.444048 2026] [security2:error] [pid 514479:tid 514661] [client 203.25.124.43:60379] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/admin.php"] [unique_id "al9cK_zqsQqnLoCgUjh3SwAAATk"]
[Tue Jul 21 08:46:51.473795 2026] [security2:error] [pid 511108:tid 511299] [client 203.25.124.200:32653] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/comments-pagination-numbers/"] [unique_id "al9cK4Td5soprXwxAH0R8wAAAD0"]
[Tue Jul 21 08:46:51.505407 2026] [security2:error] [pid 514479:tid 514652] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cK_zqsQqnLoCgUjh3SgABMFQ"]
[Tue Jul 21 08:46:51.567137 2026] [security2:error] [pid 514479:tid 514546] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.promocao-relampago.club"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9cK_zqsQqnLoCgUjh3TQABDD4"]
[Tue Jul 21 08:46:51.662685 2026] [security2:error] [pid 514479:tid 514668] [client 203.25.124.47:64255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/login.php"] [unique_id "al9cK_zqsQqnLoCgUjh3TwAAAUA"]
[Tue Jul 21 08:46:51.680022 2026] [security2:error] [pid 511108:tid 511247] [client 20.197.195.24:48896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/100.php"] [unique_id "al9cK4Td5soprXwxAH0R-gAAAAk"]
[Tue Jul 21 08:46:51.759432 2026] [security2:error] [pid 514479:tid 514587] [remote 41.186.86.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalbsolutions.com"] [uri "/wp-login.php"] [unique_id "al9cK_zqsQqnLoCgUjh3UQABFGY"]
[Tue Jul 21 08:46:51.965068 2026] [security2:error] [pid 514479:tid 514496] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.promocao-relampago.club"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9cK_zqsQqnLoCgUjh3UwABagw"]
[Tue Jul 21 08:46:51.966893 2026] [security2:error] [pid 511108:tid 511112] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cK4Td5soprXwxAH0R_QAAcwM"]
[Tue Jul 21 08:46:51.966989 2026] [security2:error] [pid 511108:tid 511353] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cK4Td5soprXwxAH0R_QAAcwM"]
[Tue Jul 21 08:46:51.993464 2026] [security2:error] [pid 514479:tid 514486] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9cK_zqsQqnLoCgUjh3VAABegI"]
[Tue Jul 21 08:46:52.159748 2026] [security2:error] [pid 511108:tid 511132] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.promocao-relampago.club"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9cLITd5soprXwxAH0SAgAASxc"]
[Tue Jul 21 08:46:52.210622 2026] [security2:error] [pid 511108:tid 511209] [remote 87.106.217.70:34512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.217.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/xmlrpc.php"] [unique_id "al9cLITd5soprXwxAH0R_wAAMWQ"]
[Tue Jul 21 08:46:52.210887 2026] [security2:error] [pid 511108:tid 511287] [client 87.106.217.70:34512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "supremaservices.net"] [uri "/xmlrpc.php"] [unique_id "al9cLITd5soprXwxAH0R_wAAMWQ"]
[Tue Jul 21 08:46:52.297785 2026] [core:error] [pid 514479:tid 514712] (104)Connection reset by peer: [client 127.0.0.1:60892] AH00574: ap_content_length_filter: apr_bucket_read() failed
[Tue Jul 21 08:46:52.297943 2026] [proxy_http:error] [pid 511108:tid 511141] (70008)Partial results are valid but processing is incomplete: [remote 103.215.75.19:0] AH01110: error reading response
[Tue Jul 21 08:46:52.383075 2026] [security2:error] [pid 514479:tid 514539] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.promocao-relampago.club"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9cLPzqsQqnLoCgUjh3XAABdjc"]
[Tue Jul 21 08:46:52.441105 2026] [security2:error] [pid 514479:tid 514720] [client 203.25.124.72:27769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/colors/light/"] [unique_id "al9cLPzqsQqnLoCgUjh3XQAAAXQ"]
[Tue Jul 21 08:46:52.513552 2026] [security2:error] [pid 514479:tid 514531] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cLPzqsQqnLoCgUjh3YAABWi8"]
[Tue Jul 21 08:46:52.513728 2026] [security2:error] [pid 514479:tid 514694] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cLPzqsQqnLoCgUjh3YAABWi8"]
[Tue Jul 21 08:46:52.678338 2026] [security2:error] [pid 514479:tid 514677] [client 203.25.124.11:35187] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/post-featured-image/"] [unique_id "al9cLPzqsQqnLoCgUjh3YwAAAUk"]
[Tue Jul 21 08:46:52.693478 2026] [security2:error] [pid 514479:tid 514701] [client 20.151.10.161:62439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9cLPzqsQqnLoCgUjh3ZAAAAWE"]
[Tue Jul 21 08:46:52.741084 2026] [security2:error] [pid 514479:tid 514577] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.promocao-relampago.club"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9cLPzqsQqnLoCgUjh3ZgABXlw"]
[Tue Jul 21 08:46:52.970766 2026] [security2:error] [pid 511108:tid 511230] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.promocao-relampago.club"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9cLITd5soprXwxAH0SFAAAO3k"]
[Tue Jul 21 08:46:53.205993 2026] [security2:error] [pid 514479:tid 514517] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.promocao-relampago.club"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9cLfzqsQqnLoCgUjh3agABRCE"]
[Tue Jul 21 08:46:53.399299 2026] [security2:error] [pid 511108:tid 511170] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cLYTd5soprXwxAH0SHgAAGD0"]
[Tue Jul 21 08:46:53.399434 2026] [security2:error] [pid 511108:tid 511262] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cLYTd5soprXwxAH0SHgAAGD0"]
[Tue Jul 21 08:46:53.467881 2026] [security2:error] [pid 511108:tid 511310] [client 212.32.76.14:27651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/well-known/index.php"] [unique_id "al9cLYTd5soprXwxAH0SHwAAAEg"]
[Tue Jul 21 08:46:53.468269 2026] [security2:error] [pid 514479:tid 514493] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.promocao-relampago.club"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9cLfzqsQqnLoCgUjh3bQABSgk"]
[Tue Jul 21 08:46:53.475382 2026] [security2:error] [pid 514479:tid 514632] [client 203.25.124.193:21021] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/wc-logs/"] [unique_id "al9cLfzqsQqnLoCgUjh3bgAAARw"]
[Tue Jul 21 08:46:53.535254 2026] [security2:error] [pid 511108:tid 511292] [client 202.179.75.202:42758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cLYTd5soprXwxAH0SIAAAADY"]
[Tue Jul 21 08:46:53.535368 2026] [security2:error] [pid 511108:tid 511292] [client 202.179.75.202:42758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cLYTd5soprXwxAH0SIAAAADY"]
[Tue Jul 21 08:46:53.793981 2026] [security2:error] [pid 511108:tid 511216] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.promocao-relampago.club"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9cLYTd5soprXwxAH0SIwAACGs"]
[Tue Jul 21 08:46:53.847442 2026] [security2:error] [pid 514479:tid 514660] [client 212.32.76.9:28169] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin.php"] [unique_id "al9cLfzqsQqnLoCgUjh3cgAAATg"]
[Tue Jul 21 08:46:53.893892 2026] [security2:error] [pid 514479:tid 514644] [client 5.38.115.39:1670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cLfzqsQqnLoCgUjh3dAAAASg"]
[Tue Jul 21 08:46:53.894017 2026] [security2:error] [pid 514479:tid 514644] [client 5.38.115.39:1670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cLfzqsQqnLoCgUjh3dAAAASg"]
[Tue Jul 21 08:46:53.912556 2026] [security2:error] [pid 514479:tid 514550] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9cLfzqsQqnLoCgUjh3dQABVEE"]
[Tue Jul 21 08:46:54.027050 2026] [security2:error] [pid 514479:tid 514534] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.promocao-relampago.club"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9cLvzqsQqnLoCgUjh3egABRjI"]
[Tue Jul 21 08:46:54.267921 2026] [core:error] [pid 514479:tid 514659] (104)Connection reset by peer: [client 127.0.0.1:60906] AH00574: ap_content_length_filter: apr_bucket_read() failed
[Tue Jul 21 08:46:54.268086 2026] [proxy_http:error] [pid 511108:tid 511147] (70008)Partial results are valid but processing is incomplete: [remote 103.215.75.19:0] AH01110: error reading response
[Tue Jul 21 08:46:54.702199 2026] [security2:error] [pid 514479:tid 514685] [client 91.92.47.81:21482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/php_info.php"] [unique_id "al9cLvzqsQqnLoCgUjh3hwAAAVE"], referer: http://englobehair.com.br/
[Tue Jul 21 08:46:54.748253 2026] [security2:error] [pid 514479:tid 514635] [client 114.198.138.124:56050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cLvzqsQqnLoCgUjh3iwAAAR8"]
[Tue Jul 21 08:46:54.748359 2026] [security2:error] [pid 514479:tid 514635] [client 114.198.138.124:56050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cLvzqsQqnLoCgUjh3iwAAAR8"]
[Tue Jul 21 08:46:54.843233 2026] [security2:error] [pid 514479:tid 514683] [client 203.25.124.40:48511] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wa/"] [unique_id "al9cLvzqsQqnLoCgUjh3jgAAAU8"]
[Tue Jul 21 08:46:54.893851 2026] [security2:error] [pid 514479:tid 514697] [client 91.92.47.81:21514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/test.php"] [unique_id "al9cLvzqsQqnLoCgUjh3jwAAAV0"], referer: http://englobehair.com.br/
[Tue Jul 21 08:46:54.895668 2026] [security2:error] [pid 514479:tid 514705] [client 91.92.47.81:21504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/server_info.php"] [unique_id "al9cLvzqsQqnLoCgUjh3kAAAAWU"], referer: http://englobehair.com.br/
[Tue Jul 21 08:46:54.896121 2026] [security2:error] [pid 511108:tid 511359] [client 91.92.47.81:21584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/index.php"] [unique_id "al9cLoTd5soprXwxAH0SOQAAAHk"], referer: http://englobehair.com.br/
[Tue Jul 21 08:46:54.896521 2026] [security2:error] [pid 514479:tid 514667] [client 91.92.47.81:21576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/configuration.php"] [unique_id "al9cLvzqsQqnLoCgUjh3kQAAAT8"], referer: http://englobehair.com.br/
[Tue Jul 21 08:46:54.897878 2026] [security2:error] [pid 514479:tid 514649] [client 91.92.47.81:21556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/functions.php"] [unique_id "al9cLvzqsQqnLoCgUjh3kgAAAS0"], referer: http://englobehair.com.br/
[Tue Jul 21 08:46:54.898079 2026] [security2:error] [pid 511108:tid 511295] [client 91.92.47.81:21524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/pinfo.php"] [unique_id "al9cLoTd5soprXwxAH0SOwAAADk"], referer: http://englobehair.com.br/
[Tue Jul 21 08:46:54.898349 2026] [security2:error] [pid 514479:tid 514672] [client 91.92.47.81:21554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/portal/phpinfo.php"] [unique_id "al9cLvzqsQqnLoCgUjh3kwAAAUQ"], referer: http://englobehair.com.br/
[Tue Jul 21 08:46:54.899290 2026] [security2:error] [pid 511108:tid 511288] [client 91.92.47.81:21542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.47.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "englobehair.com.br"] [uri "/phpinfo/info.php"] [unique_id "al9cLoTd5soprXwxAH0SPAAAADI"], referer: http://englobehair.com.br/
[Tue Jul 21 08:46:54.899601 2026] [security2:error] [pid 514479:tid 514664] [client 65.21.113.253:51242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cLvzqsQqnLoCgUjh3hAAAATw"]
[Tue Jul 21 08:46:54.972330 2026] [security2:error] [pid 511108:tid 511321] [client 203.25.124.6:49187] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/upload.php"] [unique_id "al9cLoTd5soprXwxAH0SQAAAAFM"]
[Tue Jul 21 08:46:55.060671 2026] [security2:error] [pid 514479:tid 514645] [client 20.151.10.161:62454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/footer.php"] [unique_id "al9cL_zqsQqnLoCgUjh3oQAAASk"]
[Tue Jul 21 08:46:55.219000 2026] [security2:error] [pid 514479:tid 514665] [client 195.49.128.211:56981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9cL_zqsQqnLoCgUjh3pAAAAT0"]
[Tue Jul 21 08:46:55.219100 2026] [security2:error] [pid 514479:tid 514665] [client 195.49.128.211:56981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "siteecommerceshop.com"] [uri "/xmlrpc.php"] [unique_id "al9cL_zqsQqnLoCgUjh3pAAAAT0"]
[Tue Jul 21 08:46:55.219980 2026] [security2:error] [pid 514479:tid 514584] [remote 57.141.18.29:41086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9cL_zqsQqnLoCgUjh3owABNGM"]
[Tue Jul 21 08:46:55.460928 2026] [security2:error] [pid 511108:tid 511260] [client 203.25.124.32:25763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/backup.php"] [unique_id "al9cL4Td5soprXwxAH0SSwAAABY"]
[Tue Jul 21 08:46:55.500028 2026] [security2:error] [pid 514479:tid 514646] [client 168.167.81.163:59409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cL_zqsQqnLoCgUjh3pgAAASo"]
[Tue Jul 21 08:46:55.500157 2026] [security2:error] [pid 514479:tid 514646] [client 168.167.81.163:59409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cL_zqsQqnLoCgUjh3pgAAASo"]
[Tue Jul 21 08:46:55.798831 2026] [security2:error] [pid 511108:tid 511149] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9cL4Td5soprXwxAH0SVwAAFSg"]
[Tue Jul 21 08:46:55.874636 2026] [security2:error] [pid 511108:tid 511355] [client 203.25.124.188:29773] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/maint/network/"] [unique_id "al9cL4Td5soprXwxAH0SWgAAAHU"]
[Tue Jul 21 08:46:56.001749 2026] [security2:error] [pid 511108:tid 511159] [remote 31.59.129.193:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "focsmart.com.br"] [uri "/runtime-config.js"] [unique_id "al9cMITd5soprXwxAH0SYQAANjI"]
[Tue Jul 21 08:46:56.051507 2026] [security2:error] [pid 514479:tid 514688] [client 113.22.144.139:61156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cMPzqsQqnLoCgUjh3tgAAAVQ"]
[Tue Jul 21 08:46:56.051614 2026] [security2:error] [pid 514479:tid 514688] [client 113.22.144.139:61156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cMPzqsQqnLoCgUjh3tgAAAVQ"]
[Tue Jul 21 08:46:56.138914 2026] [security2:error] [pid 514479:tid 514659] [client 203.25.124.48:62419] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-file.php"] [unique_id "al9cMPzqsQqnLoCgUjh3twAAATc"]
[Tue Jul 21 08:46:56.172711 2026] [security2:error] [pid 514479:tid 514509] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cMPzqsQqnLoCgUjh3vQABHRk"]
[Tue Jul 21 08:46:56.261717 2026] [security2:error] [pid 514479:tid 514731] [client 212.32.76.12:60841] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/user/freedoms-old.php"] [unique_id "al9cMPzqsQqnLoCgUjh3wgAAAX8"]
[Tue Jul 21 08:46:56.304620 2026] [security2:error] [pid 511108:tid 511316] [client 59.95.197.55:60909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cMITd5soprXwxAH0SagAAAE4"]
[Tue Jul 21 08:46:56.304723 2026] [security2:error] [pid 511108:tid 511316] [client 59.95.197.55:60909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cMITd5soprXwxAH0SagAAAE4"]
[Tue Jul 21 08:46:56.541993 2026] [security2:error] [pid 514479:tid 514737] [client 216.144.249.201:43526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mannucarvalho.com"] [uri "/.env"] [unique_id "al9cMPzqsQqnLoCgUjh3yQAAAYU"]
[Tue Jul 21 08:46:56.653728 2026] [security2:error] [pid 514479:tid 514629] [client 103.59.206.240:31029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cMPzqsQqnLoCgUjh3zwAAARk"]
[Tue Jul 21 08:46:56.653842 2026] [security2:error] [pid 514479:tid 514629] [client 103.59.206.240:31029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cMPzqsQqnLoCgUjh3zwAAARk"]
[Tue Jul 21 08:46:56.677990 2026] [security2:error] [pid 511108:tid 511115] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cMITd5soprXwxAH0ScQAAKAY"]
[Tue Jul 21 08:46:56.678103 2026] [security2:error] [pid 511108:tid 511278] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cMITd5soprXwxAH0ScQAAKAY"]
[Tue Jul 21 08:46:56.777165 2026] [security2:error] [pid 514479:tid 514719] [client 203.25.124.185:47499] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/group/"] [unique_id "al9cMPzqsQqnLoCgUjh31AAAAXM"]
[Tue Jul 21 08:46:56.921847 2026] [security2:error] [pid 514479:tid 514701] [client 195.49.128.211:65188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cMPzqsQqnLoCgUjh31gAAAWE"]
[Tue Jul 21 08:46:56.921949 2026] [security2:error] [pid 514479:tid 514701] [client 195.49.128.211:65188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cMPzqsQqnLoCgUjh31gAAAWE"]
[Tue Jul 21 08:46:56.999178 2026] [security2:error] [pid 511108:tid 511286] [client 122.176.100.127:62648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cMITd5soprXwxAH0SeAAAADA"]
[Tue Jul 21 08:46:56.999296 2026] [security2:error] [pid 511108:tid 511286] [client 122.176.100.127:62648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cMITd5soprXwxAH0SeAAAADA"]
[Tue Jul 21 08:46:57.180605 2026] [security2:error] [pid 511108:tid 511326] [client 20.197.192.193:27158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/else1.php"] [unique_id "al9cMYTd5soprXwxAH0SewAAAFg"]
[Tue Jul 21 08:46:57.256417 2026] [security2:error] [pid 511108:tid 511224] [remote 51.75.236.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "digitalbelfort.com"] [uri "/"] [unique_id "al9cMYTd5soprXwxAH0SfQAAPXM"]
[Tue Jul 21 08:46:57.256632 2026] [security2:error] [pid 511108:tid 511299] [client 51.75.236.153:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "digitalbelfort.com"] [uri "/"] [unique_id "al9cMYTd5soprXwxAH0SfQAAPXM"]
[Tue Jul 21 08:46:57.445771 2026] [security2:error] [pid 514479:tid 514729] [client 203.25.124.215:29661] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/info.php"] [unique_id "al9cMfzqsQqnLoCgUjh34QAAAX0"]
[Tue Jul 21 08:46:57.558632 2026] [security2:error] [pid 511108:tid 511297] [client 216.144.249.201:43556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mannucarvalho.com"] [uri "/.env.backup"] [unique_id "al9cMYTd5soprXwxAH0ShgAAADs"]
[Tue Jul 21 08:46:57.562070 2026] [security2:error] [pid 511108:tid 511261] [client 212.32.76.14:58761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/post-author-name-path.php"] [unique_id "al9cMYTd5soprXwxAH0ShwAAABc"]
[Tue Jul 21 08:46:57.614656 2026] [security2:error] [pid 511108:tid 511336] [client 216.144.249.201:43542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mannucarvalho.com"] [uri "/.env.bak"] [unique_id "al9cMYTd5soprXwxAH0SiQAAAGI"]
[Tue Jul 21 08:46:57.673881 2026] [security2:error] [pid 514479:tid 514612] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9cMfzqsQqnLoCgUjh34wABMH8"]
[Tue Jul 21 08:46:57.776320 2026] [security2:error] [pid 514479:tid 514661] [client 212.32.76.62:53859] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/"] [unique_id "al9cMfzqsQqnLoCgUjh35AAAATk"]
[Tue Jul 21 08:46:57.977452 2026] [security2:error] [pid 514479:tid 514610] [remote 31.59.129.193:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "focsmart.com.br"] [uri "/api/env"] [unique_id "al9cMfzqsQqnLoCgUjh37AABiH0"]
[Tue Jul 21 08:46:58.019890 2026] [security2:error] [pid 511108:tid 511199] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cMoTd5soprXwxAH0SjgAAQFo"]
[Tue Jul 21 08:46:58.025400 2026] [security2:error] [pid 511108:tid 511248] [client 216.144.249.201:43650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mannucarvalho.com"] [uri "/laravel/.env"] [unique_id "al9cMoTd5soprXwxAH0SjwAAAAo"]
[Tue Jul 21 08:46:58.029041 2026] [security2:error] [pid 514479:tid 514647] [client 216.144.249.201:43766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mannucarvalho.com"] [uri "/service-account.json"] [unique_id "al9cMvzqsQqnLoCgUjh37QAAASs"]
[Tue Jul 21 08:46:58.029118 2026] [security2:error] [pid 514479:tid 514647] [client 216.144.249.201:43766] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mannucarvalho.com"] [uri "/service-account.json"] [unique_id "al9cMvzqsQqnLoCgUjh37QAAASs"]
[Tue Jul 21 08:46:58.029782 2026] [security2:error] [pid 514479:tid 514636] [client 216.144.249.201:43640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mannucarvalho.com"] [uri "/api/.env"] [unique_id "al9cMvzqsQqnLoCgUjh37wAAASA"]
[Tue Jul 21 08:46:58.032005 2026] [security2:error] [pid 511108:tid 511331] [client 216.144.249.201:43624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mannucarvalho.com"] [uri "/backend/.env"] [unique_id "al9cMoTd5soprXwxAH0SlAAAAF0"]
[Tue Jul 21 08:46:58.032586 2026] [security2:error] [pid 514479:tid 514722] [client 216.144.249.201:43910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.249.144.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mannucarvalho.com"] [uri "/wp-config.php"] [unique_id "al9cMvzqsQqnLoCgUjh38AAAAXY"]
[Tue Jul 21 08:46:58.032755 2026] [security2:error] [pid 511108:tid 511294] [client 216.144.249.201:43584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mannucarvalho.com"] [uri "/.env.old"] [unique_id "al9cMoTd5soprXwxAH0SlQAAADg"]
[Tue Jul 21 08:46:58.069834 2026] [security2:error] [pid 511108:tid 511164] [remote 206.189.42.80:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.42.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9cMoTd5soprXwxAH0SmgAACDc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:46:58.075136 2026] [security2:error] [pid 514479:tid 514497] [remote 206.189.42.80:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.42.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9cMvzqsQqnLoCgUjh4BAABfQ0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:46:58.154174 2026] [security2:error] [pid 511108:tid 511268] [client 216.144.249.201:43864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mannucarvalho.com"] [uri "/swagger.json"] [unique_id "al9cMoTd5soprXwxAH0SnwAAAB4"]
[Tue Jul 21 08:46:58.154241 2026] [security2:error] [pid 511108:tid 511268] [client 216.144.249.201:43864] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mannucarvalho.com"] [uri "/swagger.json"] [unique_id "al9cMoTd5soprXwxAH0SnwAAAB4"]
[Tue Jul 21 08:46:58.161192 2026] [security2:error] [pid 511108:tid 511323] [client 216.144.249.201:44160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mannucarvalho.com"] [uri "/wp/.env"] [unique_id "al9cMoTd5soprXwxAH0SpQAAAFU"]
[Tue Jul 21 08:46:58.161781 2026] [security2:error] [pid 514479:tid 514724] [client 216.144.249.201:43914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mannucarvalho.com"] [uri "/wp-config.php.bak"] [unique_id "al9cMvzqsQqnLoCgUjh4EgAAAXg"]
[Tue Jul 21 08:46:58.161787 2026] [security2:error] [pid 514479:tid 514739] [client 216.144.249.201:43616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mannucarvalho.com"] [uri "/app/.env"] [unique_id "al9cMvzqsQqnLoCgUjh4DQAAAYc"]
[Tue Jul 21 08:46:58.162224 2026] [security2:error] [pid 514479:tid 514620] [client 216.144.249.201:43678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mannucarvalho.com"] [uri "/config.json"] [unique_id "al9cMvzqsQqnLoCgUjh4EwAAARA"]
[Tue Jul 21 08:46:58.162333 2026] [security2:error] [pid 514479:tid 514620] [client 216.144.249.201:43678] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mannucarvalho.com"] [uri "/config.json"] [unique_id "al9cMvzqsQqnLoCgUjh4EwAAARA"]
[Tue Jul 21 08:46:58.165191 2026] [security2:error] [pid 514479:tid 514720] [client 216.144.249.201:43648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mannucarvalho.com"] [uri "/public/.env"] [unique_id "al9cMvzqsQqnLoCgUjh4GAAAAXQ"]
[Tue Jul 21 08:46:58.165564 2026] [security2:error] [pid 514479:tid 514684] [client 216.144.249.201:43926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "mannucarvalho.com"] [uri "/web.config"] [unique_id "al9cMvzqsQqnLoCgUjh4GQAAAVA"]
[Tue Jul 21 08:46:58.390627 2026] [security2:error] [pid 511108:tid 511163] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cMoTd5soprXwxAH0SxwAAWTY"]
[Tue Jul 21 08:46:58.390794 2026] [security2:error] [pid 511108:tid 511327] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cMoTd5soprXwxAH0SxwAAWTY"]
[Tue Jul 21 08:46:58.444880 2026] [security2:error] [pid 514479:tid 514492] [remote 206.189.42.80:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.42.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9cMvzqsQqnLoCgUjh4RwABEQg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:46:58.605445 2026] [security2:error] [pid 514479:tid 514623] [client 41.89.234.2:64158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cMvzqsQqnLoCgUjh4SwAAARM"]
[Tue Jul 21 08:46:58.605584 2026] [security2:error] [pid 514479:tid 514623] [client 41.89.234.2:64158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cMvzqsQqnLoCgUjh4SwAAARM"]
[Tue Jul 21 08:46:58.662215 2026] [security2:error] [pid 514479:tid 514676] [client 203.25.124.71:51467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/class-wp-error-character.php"] [unique_id "al9cMvzqsQqnLoCgUjh4ZQAAAUg"]
[Tue Jul 21 08:46:58.677062 2026] [security2:error] [pid 511108:tid 511256] [client 203.25.124.192:30083] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/666.php"] [unique_id "al9cMoTd5soprXwxAH0S3QAAABI"]
[Tue Jul 21 08:46:58.750524 2026] [security2:error] [pid 514479:tid 514658] [client 203.25.124.39:37885] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/ID3/"] [unique_id "al9cMvzqsQqnLoCgUjh4lAAAATY"]
[Tue Jul 21 08:46:58.804491 2026] [security2:error] [pid 514479:tid 514582] [remote 206.189.42.80:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.42.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9cMvzqsQqnLoCgUjh4lQABGWE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:46:58.994012 2026] [security2:error] [pid 511108:tid 511290] [client 20.151.10.161:62360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-content/index.php"] [unique_id "al9cMoTd5soprXwxAH0THgAAADQ"]
[Tue Jul 21 08:46:59.019185 2026] [security2:error] [pid 514479:tid 514532] [remote 206.189.42.80:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.42.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9cM_zqsQqnLoCgUjh4nwABUTA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:46:59.060436 2026] [security2:error] [pid 514479:tid 514661] [client 65.21.113.253:51242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cMvzqsQqnLoCgUjh4SAAAATk"]
[Tue Jul 21 08:46:59.067782 2026] [security2:error] [pid 514479:tid 514592] [remote 206.189.42.80:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.42.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9cMvzqsQqnLoCgUjh4AQABXms"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:46:59.070851 2026] [security2:error] [pid 514479:tid 514495] [remote 206.189.42.80:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.42.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9cMvzqsQqnLoCgUjh4AgABVQs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:46:59.186453 2026] [security2:error] [pid 514479:tid 514499] [remote 206.189.42.80:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.42.189.206.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9cM_zqsQqnLoCgUjh4ogABRQ8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:46:59.193665 2026] [security2:error] [pid 511108:tid 511119] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cM4Td5soprXwxAH0TIwAABAo"]
[Tue Jul 21 08:46:59.193836 2026] [security2:error] [pid 511108:tid 511242] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cM4Td5soprXwxAH0TIwAABAo"]
[Tue Jul 21 08:46:59.280377 2026] [security2:error] [pid 511108:tid 511191] [remote 207.180.241.245:39278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.241.180.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gmtruckms.com"] [uri "/wp-login.php"] [unique_id "al9cM4Td5soprXwxAH0TJAAAU1I"]
[Tue Jul 21 08:46:59.457131 2026] [security2:error] [pid 514479:tid 514643] [client 49.144.66.253:32472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cM_zqsQqnLoCgUjh4pQAAASc"]
[Tue Jul 21 08:46:59.457278 2026] [security2:error] [pid 514479:tid 514643] [client 49.144.66.253:32472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cM_zqsQqnLoCgUjh4pQAAASc"]
[Tue Jul 21 08:46:59.532109 2026] [security2:error] [pid 514479:tid 514647] [client 20.197.192.193:7283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9cM_zqsQqnLoCgUjh4qAAAASs"]
[Tue Jul 21 08:46:59.562854 2026] [security2:error] [pid 511108:tid 511245] [client 203.25.124.68:31201] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-cron-element.php"] [unique_id "al9cM4Td5soprXwxAH0TMQAAAAc"]
[Tue Jul 21 08:46:59.673685 2026] [security2:error] [pid 511108:tid 511280] [client 212.32.76.54:25179] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "al9cM4Td5soprXwxAH0TNwAAACo"]
[Tue Jul 21 08:46:59.716736 2026] [security2:error] [pid 514479:tid 514583] [remote 41.186.86.12:39092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "limetteodontologia.com.br.draanacarlalima.com.br"] [uri "/wp-login.php"] [unique_id "al9cM_zqsQqnLoCgUjh4qwABYmI"]
[Tue Jul 21 08:46:59.837724 2026] [security2:error] [pid 514479:tid 514685] [client 203.25.124.72:61421] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/index/function.php"] [unique_id "al9cM_zqsQqnLoCgUjh4rAAAAVE"]
[Tue Jul 21 08:46:59.867902 2026] [security2:error] [pid 511108:tid 511200] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cM4Td5soprXwxAH0TOAAAVls"]
[Tue Jul 21 08:46:59.891708 2026] [security2:error] [pid 514479:tid 514661] [client 20.197.192.193:8180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9cM_zqsQqnLoCgUjh4rQAAATk"]
[Tue Jul 21 08:47:00.147858 2026] [security2:error] [pid 511108:tid 511282] [client 20.197.192.193:8155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/dp.php"] [unique_id "al9cNITd5soprXwxAH0TPQAAACw"]
[Tue Jul 21 08:47:00.325981 2026] [security2:error] [pid 514479:tid 514549] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9cNPzqsQqnLoCgUjh4sgABZUA"]
[Tue Jul 21 08:47:00.426288 2026] [security2:error] [pid 514479:tid 514734] [client 20.197.192.193:7242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/old.php"] [unique_id "al9cNPzqsQqnLoCgUjh4swAAAYI"]
[Tue Jul 21 08:47:00.577144 2026] [security2:error] [pid 511108:tid 511298] [client 20.197.192.193:8130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/ms-new.php"] [unique_id "al9cNITd5soprXwxAH0TRQAAADw"]
[Tue Jul 21 08:47:00.665920 2026] [security2:error] [pid 511108:tid 511312] [client 203.25.124.212:33959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/sitemaps/chosen.php"] [unique_id "al9cNITd5soprXwxAH0TRwAAAEo"]
[Tue Jul 21 08:47:00.850829 2026] [security2:error] [pid 514479:tid 514714] [client 20.197.192.193:8137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/track.php"] [unique_id "al9cNPzqsQqnLoCgUjh4tgAAAW4"]
[Tue Jul 21 08:47:01.011148 2026] [security2:error] [pid 514479:tid 514673] [client 20.197.192.193:7240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/2352356666.php"] [unique_id "al9cNfzqsQqnLoCgUjh4uAAAAUU"]
[Tue Jul 21 08:47:01.038299 2026] [security2:error] [pid 514479:tid 514718] [client 212.32.76.2:26369] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/upgrade/"] [unique_id "al9cNfzqsQqnLoCgUjh4uQAAAXI"]
[Tue Jul 21 08:47:01.075448 2026] [security2:error] [pid 511108:tid 511301] [client 138.185.145.78:40540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vivaconcierge.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cNYTd5soprXwxAH0TTgAAAD8"]
[Tue Jul 21 08:47:01.075545 2026] [security2:error] [pid 511108:tid 511301] [client 138.185.145.78:40540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vivaconcierge.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cNYTd5soprXwxAH0TTgAAAD8"]
[Tue Jul 21 08:47:01.083214 2026] [security2:error] [pid 514479:tid 514580] [remote 45.150.79.142:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cinsofe.com"] [uri "/wp-login.php"] [unique_id "al9cNfzqsQqnLoCgUjh4ugABTV8"]
[Tue Jul 21 08:47:01.136634 2026] [security2:error] [pid 514479:tid 514691] [client 195.206.105.227:39872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh4vAAAAVc"]
[Tue Jul 21 08:47:01.136705 2026] [security2:error] [pid 514479:tid 514691] [client 195.206.105.227:39872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh4vAAAAVc"]
[Tue Jul 21 08:47:01.149594 2026] [security2:error] [pid 514479:tid 514679] [client 168.167.81.163:59503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh4vQAAAUs"]
[Tue Jul 21 08:47:01.156745 2026] [security2:error] [pid 514479:tid 514679] [client 168.167.81.163:59503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh4vQAAAUs"]
[Tue Jul 21 08:47:01.172823 2026] [security2:error] [pid 511108:tid 511348] [client 20.197.192.193:27089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/tkikikoko.php"] [unique_id "al9cNYTd5soprXwxAH0TUgAAAG4"]
[Tue Jul 21 08:47:01.173345 2026] [security2:error] [pid 514479:tid 514682] [client 5.39.1.252:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "soutendenciaenergia.com.br"] [uri "/robots.txt"] [unique_id "al9cNfzqsQqnLoCgUjh4vgAAAU4"]
[Tue Jul 21 08:47:01.173432 2026] [security2:error] [pid 514479:tid 514682] [client 5.39.1.252:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "soutendenciaenergia.com.br"] [uri "/robots.txt"] [unique_id "al9cNfzqsQqnLoCgUjh4vgAAAU4"]
[Tue Jul 21 08:47:01.269997 2026] [security2:error] [pid 514479:tid 514646] [client 138.185.145.78:40716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vivaconcierge.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh4vwAAASo"]
[Tue Jul 21 08:47:01.270104 2026] [security2:error] [pid 514479:tid 514646] [client 138.185.145.78:40716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vivaconcierge.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh4vwAAASo"]
[Tue Jul 21 08:47:01.295033 2026] [security2:error] [pid 514479:tid 514636] [client 20.197.192.193:7272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/pn.php"] [unique_id "al9cNfzqsQqnLoCgUjh4wgAAASA"]
[Tue Jul 21 08:47:01.379763 2026] [security2:error] [pid 511108:tid 511238] [client 203.25.124.181:52515] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/l10n/wp-conflg.php"] [unique_id "al9cNYTd5soprXwxAH0TVwAAAAA"]
[Tue Jul 21 08:47:01.517434 2026] [security2:error] [pid 514479:tid 514677] [client 138.185.145.78:40794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vivaconcierge.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh4xgAAAUk"]
[Tue Jul 21 08:47:01.517534 2026] [security2:error] [pid 514479:tid 514677] [client 138.185.145.78:40794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vivaconcierge.com.br"] [uri "/blog/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh4xgAAAUk"]
[Tue Jul 21 08:47:01.568779 2026] [security2:error] [pid 514479:tid 514724] [client 203.25.124.68:32645] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/antiperfo.php"] [unique_id "al9cNfzqsQqnLoCgUjh4xwAAAXg"]
[Tue Jul 21 08:47:01.615114 2026] [security2:error] [pid 514479:tid 514656] [client 138.185.145.78:40978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vivaconcierge.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh4yQAAATQ"]
[Tue Jul 21 08:47:01.615197 2026] [security2:error] [pid 514479:tid 514656] [client 138.185.145.78:40978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vivaconcierge.com.br"] [uri "/wordpress/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh4yQAAATQ"]
[Tue Jul 21 08:47:01.662246 2026] [security2:error] [pid 511108:tid 511357] [client 20.197.192.193:7266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9cNYTd5soprXwxAH0TXAAAAHc"]
[Tue Jul 21 08:47:01.716173 2026] [security2:error] [pid 514479:tid 514736] [client 138.185.145.78:41032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vivaconcierge.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh40AAAAYQ"]
[Tue Jul 21 08:47:01.716307 2026] [security2:error] [pid 514479:tid 514736] [client 138.185.145.78:41032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vivaconcierge.com.br"] [uri "/site/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh40AAAAYQ"]
[Tue Jul 21 08:47:01.769804 2026] [security2:error] [pid 511108:tid 511223] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cNYTd5soprXwxAH0TXgAAdXI"]
[Tue Jul 21 08:47:01.816086 2026] [security2:error] [pid 514479:tid 514642] [client 138.185.145.78:41096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vivaconcierge.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh40wAAASY"]
[Tue Jul 21 08:47:01.816190 2026] [security2:error] [pid 514479:tid 514642] [client 138.185.145.78:41096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vivaconcierge.com.br"] [uri "/web/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh40wAAASY"]
[Tue Jul 21 08:47:01.914475 2026] [security2:error] [pid 514479:tid 514702] [client 138.185.145.78:41154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vivaconcierge.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh41AAAAWI"]
[Tue Jul 21 08:47:01.914570 2026] [security2:error] [pid 514479:tid 514702] [client 138.185.145.78:41154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vivaconcierge.com.br"] [uri "/cms/xmlrpc.php"] [unique_id "al9cNfzqsQqnLoCgUjh41AAAAWI"]
[Tue Jul 21 08:47:02.022136 2026] [security2:error] [pid 514479:tid 514738] [client 138.185.145.78:41216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vivaconcierge.com.br"] [uri "/wp-site/xmlrpc.php"] [unique_id "al9cNvzqsQqnLoCgUjh41QAAAYY"]
[Tue Jul 21 08:47:02.022248 2026] [security2:error] [pid 514479:tid 514738] [client 138.185.145.78:41216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vivaconcierge.com.br"] [uri "/wp-site/xmlrpc.php"] [unique_id "al9cNvzqsQqnLoCgUjh41QAAAYY"]
[Tue Jul 21 08:47:02.027044 2026] [security2:error] [pid 511108:tid 511350] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cNYTd5soprXwxAH0TYQAAcF0"]
[Tue Jul 21 08:47:02.122841 2026] [security2:error] [pid 511108:tid 511314] [client 138.185.145.78:41270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vivaconcierge.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9cNoTd5soprXwxAH0TYwAAAEw"]
[Tue Jul 21 08:47:02.122990 2026] [security2:error] [pid 511108:tid 511314] [client 138.185.145.78:41270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vivaconcierge.com.br"] [uri "/wpsite/xmlrpc.php"] [unique_id "al9cNoTd5soprXwxAH0TYwAAAEw"]
[Tue Jul 21 08:47:02.205498 2026] [security2:error] [pid 514479:tid 514518] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9cNvzqsQqnLoCgUjh43gABMyI"]
[Tue Jul 21 08:47:02.222751 2026] [security2:error] [pid 514479:tid 514654] [client 138.185.145.78:41322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vivaconcierge.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9cNvzqsQqnLoCgUjh43wAAATI"]
[Tue Jul 21 08:47:02.222862 2026] [security2:error] [pid 514479:tid 514654] [client 138.185.145.78:41322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vivaconcierge.com.br"] [uri "/old/xmlrpc.php"] [unique_id "al9cNvzqsQqnLoCgUjh43wAAATI"]
[Tue Jul 21 08:47:02.252324 2026] [security2:error] [pid 514479:tid 514616] [client 203.25.124.65:58233] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/edit-tags.php"] [unique_id "al9cNvzqsQqnLoCgUjh44AAAAQw"]
[Tue Jul 21 08:47:02.466487 2026] [security2:error] [pid 514479:tid 514709] [client 138.185.145.78:41390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vivaconcierge.com.br"] [uri "/wp-login.php"] [unique_id "al9cNvzqsQqnLoCgUjh46QAAAWk"]
[Tue Jul 21 08:47:02.489383 2026] [security2:error] [pid 514479:tid 514519] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cNvzqsQqnLoCgUjh47AABbSM"]
[Tue Jul 21 08:47:02.489552 2026] [security2:error] [pid 514479:tid 514713] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cNvzqsQqnLoCgUjh47AABbSM"]
[Tue Jul 21 08:47:02.555367 2026] [security2:error] [pid 514479:tid 514659] [client 61.1.167.83:64548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cNvzqsQqnLoCgUjh47QAAATc"]
[Tue Jul 21 08:47:02.555571 2026] [security2:error] [pid 514479:tid 514659] [client 61.1.167.83:64548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cNvzqsQqnLoCgUjh47QAAATc"]
[Tue Jul 21 08:47:02.566247 2026] [security2:error] [pid 514479:tid 514740] [client 203.25.124.35:51625] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/blog-stream/inc/upgrade-to-pro/section-pro.php"] [unique_id "al9cNvzqsQqnLoCgUjh47gAAAYg"]
[Tue Jul 21 08:47:02.566425 2026] [security2:error] [pid 514479:tid 514619] [client 65.21.113.253:51242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cNvzqsQqnLoCgUjh42QAAAQ8"]
[Tue Jul 21 08:47:02.626056 2026] [security2:error] [pid 511108:tid 511255] [client 51.161.37.36:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "soutendenciaenergia.com.br"] [uri "/"] [unique_id "al9cNoTd5soprXwxAH0TcQAAABE"]
[Tue Jul 21 08:47:02.626177 2026] [security2:error] [pid 511108:tid 511255] [client 51.161.37.36:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "soutendenciaenergia.com.br"] [uri "/"] [unique_id "al9cNoTd5soprXwxAH0TcQAAABE"]
[Tue Jul 21 08:47:02.692740 2026] [security2:error] [pid 514479:tid 514706] [client 20.197.192.193:27146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-Blogs.php"] [unique_id "al9cNvzqsQqnLoCgUjh49AAAAWY"]
[Tue Jul 21 08:47:03.069583 2026] [security2:error] [pid 514479:tid 514736] [client 212.32.76.62:33269] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/user.php"] [unique_id "al9cN_zqsQqnLoCgUjh49QAAAYQ"]
[Tue Jul 21 08:47:03.150290 2026] [security2:error] [pid 511108:tid 511175] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cN4Td5soprXwxAH0TewAAXUI"]
[Tue Jul 21 08:47:03.150455 2026] [security2:error] [pid 511108:tid 511331] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cN4Td5soprXwxAH0TewAAXUI"]
[Tue Jul 21 08:47:03.468871 2026] [security2:error] [pid 514479:tid 514717] [client 5.31.193.106:1837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cN_zqsQqnLoCgUjh4-AAAAXE"]
[Tue Jul 21 08:47:03.469013 2026] [security2:error] [pid 514479:tid 514717] [client 5.31.193.106:1837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cN_zqsQqnLoCgUjh4-AAAAXE"]
[Tue Jul 21 08:47:03.660699 2026] [security2:error] [pid 511108:tid 511117] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cN4Td5soprXwxAH0TgAAAFgg"]
[Tue Jul 21 08:47:03.662002 2026] [security2:error] [pid 514479:tid 514642] [client 212.32.76.8:34955] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/fusion-styles/user/index.php"] [unique_id "al9cN_zqsQqnLoCgUjh4-QAAASY"]
[Tue Jul 21 08:47:03.843255 2026] [security2:error] [pid 514479:tid 514738] [client 212.32.76.11:24673] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/log.php"] [unique_id "al9cN_zqsQqnLoCgUjh4_AAAAYY"]
[Tue Jul 21 08:47:03.878082 2026] [security2:error] [pid 514479:tid 514630] [client 212.32.76.64:58877] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/nextpage/"] [unique_id "al9cN_zqsQqnLoCgUjh4_QAAARo"]
[Tue Jul 21 08:47:03.937135 2026] [security2:error] [pid 514479:tid 514564] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cN_zqsQqnLoCgUjh4_gABHU8"]
[Tue Jul 21 08:47:03.937303 2026] [security2:error] [pid 514479:tid 514633] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cN_zqsQqnLoCgUjh4_gABHU8"]
[Tue Jul 21 08:47:04.072609 2026] [security2:error] [pid 514479:tid 514551] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9cOPzqsQqnLoCgUjh5AwABgUI"]
[Tue Jul 21 08:47:04.333433 2026] [security2:error] [pid 511108:tid 511283] [client 202.179.75.202:38030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cOITd5soprXwxAH0TiQAAAC0"]
[Tue Jul 21 08:47:04.333551 2026] [security2:error] [pid 511108:tid 511283] [client 202.179.75.202:38030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cOITd5soprXwxAH0TiQAAAC0"]
[Tue Jul 21 08:47:04.369537 2026] [security2:error] [pid 514479:tid 514650] [client 203.25.124.48:21263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwentyfive/parts/upgrade/index.php"] [unique_id "al9cOPzqsQqnLoCgUjh5CgAAAS4"]
[Tue Jul 21 08:47:04.520834 2026] [security2:error] [pid 514479:tid 514652] [client 5.38.115.39:59355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cOPzqsQqnLoCgUjh5DwAAATA"]
[Tue Jul 21 08:47:04.520993 2026] [security2:error] [pid 514479:tid 514652] [client 5.38.115.39:59355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cOPzqsQqnLoCgUjh5DwAAATA"]
[Tue Jul 21 08:47:04.672718 2026] [security2:error] [pid 511108:tid 511342] [client 203.25.124.180:48421] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/code/"] [unique_id "al9cOITd5soprXwxAH0TjwAAAGg"]
[Tue Jul 21 08:47:04.759765 2026] [security2:error] [pid 511108:tid 511264] [client 198.44.157.34:52994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cOITd5soprXwxAH0TkgAAABo"]
[Tue Jul 21 08:47:04.759951 2026] [security2:error] [pid 511108:tid 511264] [client 198.44.157.34:52994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cOITd5soprXwxAH0TkgAAABo"]
[Tue Jul 21 08:47:04.952084 2026] [proxy:error] [pid 514479:tid 514631] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:47:04.952152 2026] [proxy_http:error] [pid 514479:tid 514631] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:47:04.952857 2026] [proxy:error] [pid 514479:tid 514631] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:47:04.952902 2026] [proxy_http:error] [pid 514479:tid 514631] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:47:05.170377 2026] [security2:error] [pid 514479:tid 514714] [client 20.197.192.193:53616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/else1.php"] [unique_id "al9cOfzqsQqnLoCgUjh5FwAAAW4"]
[Tue Jul 21 08:47:05.345542 2026] [proxy:error] [pid 514479:tid 514691] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:47:05.345623 2026] [proxy_http:error] [pid 514479:tid 514691] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:47:05.346383 2026] [proxy:error] [pid 514479:tid 514691] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:47:05.346418 2026] [proxy_http:error] [pid 514479:tid 514691] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:47:05.375972 2026] [security2:error] [pid 514479:tid 514484] [remote 167.71.132.111:38088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.132.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9cOfzqsQqnLoCgUjh5GwABggA"]
[Tue Jul 21 08:47:05.464854 2026] [security2:error] [pid 514479:tid 514653] [client 203.25.124.64:37217] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/network/theme-install-variable.php"] [unique_id "al9cOfzqsQqnLoCgUjh5IAAAATE"]
[Tue Jul 21 08:47:05.530874 2026] [security2:error] [pid 511108:tid 511225] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cOYTd5soprXwxAH0TnAAAbnQ"]
[Tue Jul 21 08:47:05.638378 2026] [security2:error] [pid 514479:tid 514713] [client 203.25.124.66:43079] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/bless.php"] [unique_id "al9cOfzqsQqnLoCgUjh5JQAAAW0"]
[Tue Jul 21 08:47:05.675074 2026] [security2:error] [pid 514479:tid 514665] [client 203.25.124.9:58975] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwentytwo/assets/fonts/"] [unique_id "al9cOfzqsQqnLoCgUjh5JgAAAT0"]
[Tue Jul 21 08:47:05.757994 2026] [security2:error] [pid 514479:tid 514498] [remote 117.0.21.154:57816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fremetexlondrina.com.br"] [uri "/wp-login.php"] [unique_id "al9cOfzqsQqnLoCgUjh5JwABHQ4"]
[Tue Jul 21 08:47:05.774866 2026] [proxy:error] [pid 514479:tid 514627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:47:05.774932 2026] [proxy_http:error] [pid 514479:tid 514627] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:47:05.775402 2026] [proxy:error] [pid 514479:tid 514627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:47:05.775426 2026] [proxy_http:error] [pid 514479:tid 514627] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:47:05.875304 2026] [security2:error] [pid 514479:tid 514650] [client 20.197.192.193:8182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/dr.php"] [unique_id "al9cOfzqsQqnLoCgUjh5LQAAAS4"]
[Tue Jul 21 08:47:05.922986 2026] [security2:error] [pid 514479:tid 514542] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9cOfzqsQqnLoCgUjh5LgABNDo"]
[Tue Jul 21 08:47:06.021085 2026] [security2:error] [pid 514479:tid 514669] [client 65.21.113.253:51242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cOfzqsQqnLoCgUjh5JAAAAUE"]
[Tue Jul 21 08:47:06.117210 2026] [security2:error] [pid 514479:tid 514684] [client 114.198.138.124:56618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cOvzqsQqnLoCgUjh5SQAAAVA"]
[Tue Jul 21 08:47:06.117325 2026] [security2:error] [pid 514479:tid 514684] [client 114.198.138.124:56618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cOvzqsQqnLoCgUjh5SQAAAVA"]
[Tue Jul 21 08:47:06.161805 2026] [security2:error] [pid 511108:tid 511357] [client 20.197.192.193:8164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/2x.php"] [unique_id "al9cOoTd5soprXwxAH0TpAAAAHc"]
[Tue Jul 21 08:47:06.192831 2026] [security2:error] [pid 511108:tid 511299] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cOoTd5soprXwxAH0TpQAAAD0"]
[Tue Jul 21 08:47:06.464553 2026] [security2:error] [pid 511108:tid 511268] [client 203.25.124.61:31597] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentynineteen/sass/site/index.php"] [unique_id "al9cOoTd5soprXwxAH0TrAAAAB4"]
[Tue Jul 21 08:47:06.475770 2026] [security2:error] [pid 511108:tid 511305] [client 203.25.124.183:56703] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/t.php"] [unique_id "al9cOoTd5soprXwxAH0TrQAAAEM"]
[Tue Jul 21 08:47:06.480418 2026] [security2:error] [pid 514479:tid 514523] [remote 51.89.129.123:61702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "fullconcursosmilitares.com"] [uri "/robots.txt"] [unique_id "al9cOvzqsQqnLoCgUjh5TwABHic"]
[Tue Jul 21 08:47:06.480584 2026] [security2:error] [pid 514479:tid 514634] [client 51.89.129.123:61702] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fullconcursosmilitares.com"] [uri "/robots.txt"] [unique_id "al9cOvzqsQqnLoCgUjh5TwABHic"]
[Tue Jul 21 08:47:06.600592 2026] [security2:error] [pid 514479:tid 514661] [client 20.197.192.193:7257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/kq1.php"] [unique_id "al9cOvzqsQqnLoCgUjh5VQAAATk"]
[Tue Jul 21 08:47:06.656382 2026] [security2:error] [pid 514479:tid 514617] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9cOvzqsQqnLoCgUjh5VwAAAQ0"]
[Tue Jul 21 08:47:06.768675 2026] [security2:error] [pid 511108:tid 511327] [client 59.95.197.55:61384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cOoTd5soprXwxAH0TtQAAAFk"]
[Tue Jul 21 08:47:06.769404 2026] [security2:error] [pid 511108:tid 511327] [client 59.95.197.55:61384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cOoTd5soprXwxAH0TtQAAAFk"]
[Tue Jul 21 08:47:07.083380 2026] [security2:error] [pid 514479:tid 514701] [client 113.22.144.139:61690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cO_zqsQqnLoCgUjh5eQAAAWE"]
[Tue Jul 21 08:47:07.083532 2026] [security2:error] [pid 514479:tid 514701] [client 113.22.144.139:61690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cO_zqsQqnLoCgUjh5eQAAAWE"]
[Tue Jul 21 08:47:07.095010 2026] [security2:error] [pid 511108:tid 511323] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9cO4Td5soprXwxAH0TuwAAAFU"]
[Tue Jul 21 08:47:07.100395 2026] [security2:error] [pid 514479:tid 514611] [remote 45.150.79.142:40418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rqracademy.com"] [uri "/wp-login.php"] [unique_id "al9cO_zqsQqnLoCgUjh5egABS34"]
[Tue Jul 21 08:47:07.164748 2026] [security2:error] [pid 511108:tid 511282] [client 203.25.124.36:60387] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwentyone/assets/sass/05-blocks/preformatted/index.php"] [unique_id "al9cO4Td5soprXwxAH0TvwAAACw"]
[Tue Jul 21 08:47:07.230250 2026] [security2:error] [pid 514479:tid 514653] [client 203.25.124.67:51833] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Text/"] [unique_id "al9cO_zqsQqnLoCgUjh5fwAAATE"]
[Tue Jul 21 08:47:07.319264 2026] [security2:error] [pid 514479:tid 514507] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cO_zqsQqnLoCgUjh5gAABgxc"]
[Tue Jul 21 08:47:07.319417 2026] [security2:error] [pid 514479:tid 514735] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cO_zqsQqnLoCgUjh5gAABgxc"]
[Tue Jul 21 08:47:07.353531 2026] [security2:error] [pid 511108:tid 511304] [client 20.197.192.193:8145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/zzz.php"] [unique_id "al9cO4Td5soprXwxAH0TxgAAAEI"]
[Tue Jul 21 08:47:07.410898 2026] [security2:error] [pid 511108:tid 511123] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cO4Td5soprXwxAH0TyAAAfQ4"]
[Tue Jul 21 08:47:07.468625 2026] [security2:error] [pid 511108:tid 511256] [client 195.49.128.211:49398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cO4Td5soprXwxAH0TygAAABI"]
[Tue Jul 21 08:47:07.468741 2026] [security2:error] [pid 511108:tid 511256] [client 195.49.128.211:49398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cO4Td5soprXwxAH0TygAAABI"]
[Tue Jul 21 08:47:07.475254 2026] [security2:error] [pid 511108:tid 511243] [client 212.32.76.64:28947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/html-api/chosen.php"] [unique_id "al9cO4Td5soprXwxAH0TywAAAAU"]
[Tue Jul 21 08:47:07.487106 2026] [security2:error] [pid 514479:tid 514718] [client 122.176.100.127:63131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cO_zqsQqnLoCgUjh5ggAAAXI"]
[Tue Jul 21 08:47:07.487235 2026] [security2:error] [pid 514479:tid 514718] [client 122.176.100.127:63131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cO_zqsQqnLoCgUjh5ggAAAXI"]
[Tue Jul 21 08:47:07.506539 2026] [security2:error] [pid 511108:tid 511173] [remote 173.252.95.58:38958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9cO4Td5soprXwxAH0TzAAABkA"]
[Tue Jul 21 08:47:07.518080 2026] [security2:error] [pid 514479:tid 514686] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9cO_zqsQqnLoCgUjh5gwAAAVI"]
[Tue Jul 21 08:47:07.618757 2026] [security2:error] [pid 514479:tid 514674] [client 20.151.10.161:62430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/zoro.php"] [unique_id "al9cO_zqsQqnLoCgUjh5hAAAAUY"]
[Tue Jul 21 08:47:07.799808 2026] [security2:error] [pid 514479:tid 514489] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9cO_zqsQqnLoCgUjh5iQABZgU"]
[Tue Jul 21 08:47:07.948702 2026] [security2:error] [pid 511108:tid 511316] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9cO4Td5soprXwxAH0T2AAAAE4"]
[Tue Jul 21 08:47:08.172843 2026] [security2:error] [pid 514479:tid 514723] [client 212.32.76.63:63743] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/css/dist/edit-post/"] [unique_id "al9cPPzqsQqnLoCgUjh5jgAAAXc"]
[Tue Jul 21 08:47:08.183860 2026] [security2:error] [pid 511108:tid 511364] [client 20.197.192.193:27190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-css.php"] [unique_id "al9cPITd5soprXwxAH0T3AAAAH4"]
[Tue Jul 21 08:47:08.252662 2026] [security2:error] [pid 514479:tid 514699] [client 203.25.124.72:56707] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/languages/themes/"] [unique_id "al9cPPzqsQqnLoCgUjh5kQAAAV8"]
[Tue Jul 21 08:47:08.329125 2026] [security2:error] [pid 511108:tid 511360] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9cPITd5soprXwxAH0T3QAAAHo"]
[Tue Jul 21 08:47:08.397634 2026] [security2:error] [pid 514479:tid 514625] [client 20.197.192.193:7259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/wicked.php"] [unique_id "al9cPPzqsQqnLoCgUjh5lQAAARU"]
[Tue Jul 21 08:47:08.626418 2026] [security2:error] [pid 511108:tid 511137] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cPITd5soprXwxAH0T4gAACRw"]
[Tue Jul 21 08:47:08.626533 2026] [security2:error] [pid 511108:tid 511247] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cPITd5soprXwxAH0T4gAACRw"]
[Tue Jul 21 08:47:08.662193 2026] [security2:error] [pid 511108:tid 511278] [client 203.25.124.50:24461] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/elex/elex.php"] [unique_id "al9cPITd5soprXwxAH0T5AAAACg"]
[Tue Jul 21 08:47:08.786753 2026] [security2:error] [pid 514479:tid 514631] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9cPPzqsQqnLoCgUjh5mwAAARs"]
[Tue Jul 21 08:47:08.974865 2026] [security2:error] [pid 514479:tid 514695] [client 203.25.124.198:41879] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/plugin/"] [unique_id "al9cPPzqsQqnLoCgUjh5nQAAAVs"]
[Tue Jul 21 08:47:09.011764 2026] [security2:error] [pid 511108:tid 511296] [client 20.197.192.193:8138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/edit.php"] [unique_id "al9cPYTd5soprXwxAH0T7wAAADo"]
[Tue Jul 21 08:47:09.159749 2026] [security2:error] [pid 511108:tid 511357] [client 41.89.234.2:41329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cPYTd5soprXwxAH0T8wAAAHc"]
[Tue Jul 21 08:47:09.159897 2026] [security2:error] [pid 511108:tid 511357] [client 41.89.234.2:41329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cPYTd5soprXwxAH0T8wAAAHc"]
[Tue Jul 21 08:47:09.183772 2026] [security2:error] [pid 511108:tid 511120] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php"] [unique_id "al9cPYTd5soprXwxAH0T9AAAVgs"]
[Tue Jul 21 08:47:09.220721 2026] [security2:error] [pid 514479:tid 514622] [client 20.197.192.193:27084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-explorer.php"] [unique_id "al9cPfzqsQqnLoCgUjh5ogAAARI"]
[Tue Jul 21 08:47:09.239339 2026] [security2:error] [pid 511108:tid 511246] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9cPYTd5soprXwxAH0T9wAAAAg"]
[Tue Jul 21 08:47:09.366020 2026] [security2:error] [pid 514479:tid 514635] [client 203.25.124.47:48129] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/oceanwp/sass/base/1.php"] [unique_id "al9cPfzqsQqnLoCgUjh5pQAAAR8"]
[Tue Jul 21 08:47:09.432868 2026] [security2:error] [pid 514479:tid 514632] [client 20.197.192.193:7295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/kua.php"] [unique_id "al9cPfzqsQqnLoCgUjh5pwAAARw"]
[Tue Jul 21 08:47:09.519204 2026] [security2:error] [pid 514479:tid 514673] [client 20.197.192.193:27183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/akismet.php"] [unique_id "al9cPfzqsQqnLoCgUjh5qAAAAUU"]
[Tue Jul 21 08:47:09.637970 2026] [security2:error] [pid 514479:tid 514614] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9cPfzqsQqnLoCgUjh5qwAAAQo"]
[Tue Jul 21 08:47:09.646754 2026] [security2:error] [pid 514479:tid 514504] [remote 103.215.75.19:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.75.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.infoalert.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9cPfzqsQqnLoCgUjh5rAABgBQ"]
[Tue Jul 21 08:47:09.716737 2026] [security2:error] [pid 514479:tid 514730] [client 20.197.192.193:27166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/ace2.php"] [unique_id "al9cPfzqsQqnLoCgUjh5rgAAAX4"]
[Tue Jul 21 08:47:09.817374 2026] [security2:error] [pid 514479:tid 514553] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cPfzqsQqnLoCgUjh5sQABO0Q"]
[Tue Jul 21 08:47:09.817495 2026] [security2:error] [pid 514479:tid 514663] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cPfzqsQqnLoCgUjh5sQABO0Q"]
[Tue Jul 21 08:47:09.974547 2026] [security2:error] [pid 514479:tid 514681] [client 203.25.124.183:34939] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/tinymce/langs/"] [unique_id "al9cPfzqsQqnLoCgUjh5sgAAAU0"]
[Tue Jul 21 08:47:09.983210 2026] [security2:error] [pid 514479:tid 514691] [client 65.21.113.253:51242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cPfzqsQqnLoCgUjh5qQAAAVc"]
[Tue Jul 21 08:47:10.054611 2026] [security2:error] [pid 511108:tid 511342] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9cPoTd5soprXwxAH0UAgAAAGg"]
[Tue Jul 21 08:47:10.243255 2026] [security2:error] [pid 511108:tid 511329] [client 20.197.192.193:7284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/ez.php"] [unique_id "al9cPoTd5soprXwxAH0UBAAAAFs"]
[Tue Jul 21 08:47:10.321356 2026] [security2:error] [pid 514479:tid 514619] [client 20.197.192.193:27139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/ms.php"] [unique_id "al9cPvzqsQqnLoCgUjh5ugAAAQ8"]
[Tue Jul 21 08:47:10.459702 2026] [security2:error] [pid 514479:tid 514657] [client 198.44.157.34:35442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9cPvzqsQqnLoCgUjh5vAAAATU"]
[Tue Jul 21 08:47:10.459806 2026] [security2:error] [pid 514479:tid 514657] [client 198.44.157.34:35442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9cPvzqsQqnLoCgUjh5vAAAATU"]
[Tue Jul 21 08:47:10.460547 2026] [security2:error] [pid 514479:tid 514694] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9cPvzqsQqnLoCgUjh5vQAAAVo"]
[Tue Jul 21 08:47:10.541612 2026] [security2:error] [pid 511108:tid 511289] [client 203.25.124.33:37431] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/file-upload-types/assets/css/403.php"] [unique_id "al9cPoTd5soprXwxAH0UDQAAADM"]
[Tue Jul 21 08:47:10.669104 2026] [security2:error] [pid 514479:tid 514706] [client 203.25.124.57:40739] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwentyone/emerance.php"] [unique_id "al9cPvzqsQqnLoCgUjh5wAAAAWY"]
[Tue Jul 21 08:47:10.774603 2026] [security2:error] [pid 514479:tid 514688] [client 203.25.124.4:22371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/query-pagination-previous/"] [unique_id "al9cPvzqsQqnLoCgUjh5wQAAAVQ"]
[Tue Jul 21 08:47:10.846183 2026] [security2:error] [pid 514479:tid 514650] [client 49.144.66.253:32900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cPvzqsQqnLoCgUjh5wwAAAS4"]
[Tue Jul 21 08:47:10.846290 2026] [security2:error] [pid 514479:tid 514650] [client 49.144.66.253:32900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cPvzqsQqnLoCgUjh5wwAAAS4"]
[Tue Jul 21 08:47:10.962235 2026] [security2:error] [pid 514479:tid 514678] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9cPvzqsQqnLoCgUjh5xgAAAUo"]
[Tue Jul 21 08:47:11.241712 2026] [security2:error] [pid 511108:tid 511238] [client 203.25.124.70:25549] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/autoload_classmap.php"] [unique_id "al9cP4Td5soprXwxAH0UFgAAAAA"]
[Tue Jul 21 08:47:11.446490 2026] [security2:error] [pid 511108:tid 511266] [client 20.197.192.193:8139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/fz.php"] [unique_id "al9cP4Td5soprXwxAH0UGwAAABw"]
[Tue Jul 21 08:47:11.479315 2026] [security2:error] [pid 511108:tid 511268] [client 212.32.76.57:57675] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Requests/src/Auth/"] [unique_id "al9cP4Td5soprXwxAH0UHAAAAB4"]
[Tue Jul 21 08:47:11.571154 2026] [security2:error] [pid 514479:tid 514739] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9cP_zqsQqnLoCgUjh5zAAAAYc"]
[Tue Jul 21 08:47:11.759538 2026] [security2:error] [pid 511108:tid 511269] [client 203.25.124.61:61623] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentynineteen/content-index.php"] [unique_id "al9cP4Td5soprXwxAH0UIgAAAB8"]
[Tue Jul 21 08:47:11.905360 2026] [security2:error] [pid 511108:tid 511350] [client 20.151.10.161:62359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/admin.php"] [unique_id "al9cP4Td5soprXwxAH0UJwAAAHA"]
[Tue Jul 21 08:47:11.934195 2026] [security2:error] [pid 511108:tid 511292] [client 168.167.81.163:63572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cP4Td5soprXwxAH0UKAAAADY"]
[Tue Jul 21 08:47:11.934324 2026] [security2:error] [pid 511108:tid 511292] [client 168.167.81.163:63572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cP4Td5soprXwxAH0UKAAAADY"]
[Tue Jul 21 08:47:12.026968 2026] [security2:error] [pid 514479:tid 514532] [remote 81.173.115.7:53840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/wp-login.php"] [unique_id "al9cQPzqsQqnLoCgUjh50gABGzA"]
[Tue Jul 21 08:47:12.049994 2026] [proxy:error] [pid 511108:tid 511200] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:47:12.050029 2026] [proxy_http:error] [pid 511108:tid 511200] [remote 74.7.230.14:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:47:12.050453 2026] [proxy:error] [pid 511108:tid 511200] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:47:12.050474 2026] [proxy_http:error] [pid 511108:tid 511200] [remote 74.7.230.14:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:47:12.238450 2026] [security2:error] [pid 514479:tid 514638] [client 203.25.124.40:23799] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/bolt.php"] [unique_id "al9cQPzqsQqnLoCgUjh52AAAASI"]
[Tue Jul 21 08:47:12.574606 2026] [security2:error] [pid 514479:tid 514732] [client 203.25.124.207:42845] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/wp.php"] [unique_id "al9cQPzqsQqnLoCgUjh53QAAAYA"]
[Tue Jul 21 08:47:12.625465 2026] [security2:error] [pid 511108:tid 511287] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cQITd5soprXwxAH0UNQAAMWc"]
[Tue Jul 21 08:47:12.833949 2026] [security2:error] [pid 514479:tid 514676] [client 20.197.192.193:7235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/la.php"] [unique_id "al9cQPzqsQqnLoCgUjh54QAAAUg"]
[Tue Jul 21 08:47:12.858204 2026] [security2:error] [pid 511108:tid 511365] [client 203.25.124.73:46393] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/responsive-lightbox/assets/nivo/themes/wp-load.php"] [unique_id "al9cQITd5soprXwxAH0UOwAAAH8"]
[Tue Jul 21 08:47:12.938775 2026] [security2:error] [pid 514479:tid 514499] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cQPzqsQqnLoCgUjh54wABgQ8"]
[Tue Jul 21 08:47:12.938913 2026] [security2:error] [pid 514479:tid 514733] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cQPzqsQqnLoCgUjh54wABgQ8"]
[Tue Jul 21 08:47:12.947784 2026] [security2:error] [pid 514479:tid 514734] [client 91.148.245.81:58672] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/"] [unique_id "al9cQPzqsQqnLoCgUjh55AAAAYI"]
[Tue Jul 21 08:47:12.950117 2026] [security2:error] [pid 514479:tid 514735] [client 91.148.245.81:58656] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/"] [unique_id "al9cQPzqsQqnLoCgUjh55QAAAYM"]
[Tue Jul 21 08:47:12.951650 2026] [security2:error] [pid 511108:tid 511270] [client 91.148.245.81:58678] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/"] [unique_id "al9cQITd5soprXwxAH0UPgAAACA"]
[Tue Jul 21 08:47:13.054598 2026] [core:error] [pid 514479:tid 514583] [remote 74.7.228.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:47:13.054635 2026] [core:error] [pid 514479:tid 514583] [remote 74.7.228.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:47:13.054873 2026] [security2:error] [pid 514479:tid 514718] [client 74.7.228.37:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.dralulmabhering.com.br"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "al9cQfzqsQqnLoCgUjh55wABcmI"]
[Tue Jul 21 08:47:13.260923 2026] [security2:error] [pid 514479:tid 514663] [client 65.21.113.253:51242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cQPzqsQqnLoCgUjh54AAAATs"]
[Tue Jul 21 08:47:13.484845 2026] [security2:error] [pid 511108:tid 511359] [client 203.25.124.12:40741] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/news-portal/sitebar.php"] [unique_id "al9cQYTd5soprXwxAH0URgAAAHk"]
[Tue Jul 21 08:47:13.611464 2026] [security2:error] [pid 514479:tid 514669] [client 20.197.192.193:53580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/tkikikoko.php"] [unique_id "al9cQfzqsQqnLoCgUjh5_gAAAUE"]
[Tue Jul 21 08:47:13.646676 2026] [security2:error] [pid 514479:tid 514609] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cQfzqsQqnLoCgUjh5_wABGHw"]
[Tue Jul 21 08:47:13.646793 2026] [security2:error] [pid 514479:tid 514628] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cQfzqsQqnLoCgUjh5_wABGHw"]
[Tue Jul 21 08:47:13.669373 2026] [security2:error] [pid 514479:tid 514723] [client 20.197.192.193:7263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9cQfzqsQqnLoCgUjh6AAAAAXc"]
[Tue Jul 21 08:47:13.769485 2026] [security2:error] [pid 514479:tid 514639] [client 203.25.124.212:42481] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/responsive-lightbox/assets/jstree/themes/system.php"] [unique_id "al9cQfzqsQqnLoCgUjh6AgAAASM"]
[Tue Jul 21 08:47:13.841271 2026] [security2:error] [pid 514479:tid 514668] [client 203.25.124.31:29589] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/maint/chosen.php"] [unique_id "al9cQfzqsQqnLoCgUjh6AwAAAUA"]
[Tue Jul 21 08:47:13.841943 2026] [security2:error] [pid 511108:tid 511298] [client 185.251.19.69:55687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "havoy.com.br"] [uri "/wp-login.php"] [unique_id "al9cQYTd5soprXwxAH0UTQAAADw"]
[Tue Jul 21 08:47:13.916630 2026] [security2:error] [pid 514479:tid 514684] [client 91.148.245.81:42620] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9cQfzqsQqnLoCgUjh6BAAAAVA"]
[Tue Jul 21 08:47:13.918548 2026] [security2:error] [pid 514479:tid 514715] [client 91.148.245.81:42618] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9cQfzqsQqnLoCgUjh6BQAAAW8"]
[Tue Jul 21 08:47:13.920014 2026] [security2:error] [pid 514479:tid 514699] [client 91.148.245.81:42630] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9cQfzqsQqnLoCgUjh6BgAAAV8"]
[Tue Jul 21 08:47:13.920647 2026] [security2:error] [pid 514479:tid 514690] [client 91.148.245.81:42644] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/wp-config.php"] [unique_id "al9cQfzqsQqnLoCgUjh6BwAAAVY"]
[Tue Jul 21 08:47:14.236520 2026] [security2:error] [pid 511108:tid 511355] [client 20.197.192.193:7256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/inso.php"] [unique_id "al9cQoTd5soprXwxAH0UVAAAAHU"]
[Tue Jul 21 08:47:14.475906 2026] [security2:error] [pid 511108:tid 511158] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cQoTd5soprXwxAH0UWAAAQzE"]
[Tue Jul 21 08:47:14.476094 2026] [security2:error] [pid 511108:tid 511305] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cQoTd5soprXwxAH0UWAAAQzE"]
[Tue Jul 21 08:47:14.656892 2026] [security2:error] [pid 514479:tid 514616] [client 20.197.192.193:7287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/wpx.php"] [unique_id "al9cQvzqsQqnLoCgUjh6IQAAAQw"]
[Tue Jul 21 08:47:14.664592 2026] [security2:error] [pid 511108:tid 511325] [client 203.25.124.211:41817] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/contact-form-7/includes/js/jquery-ui/themes/data.php"] [unique_id "al9cQoTd5soprXwxAH0UXAAAAFc"]
[Tue Jul 21 08:47:14.672536 2026] [security2:error] [pid 511108:tid 511361] [client 203.25.124.200:36271] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/database.php"] [unique_id "al9cQoTd5soprXwxAH0UXQAAAHs"]
[Tue Jul 21 08:47:14.907481 2026] [security2:error] [pid 511108:tid 511262] [client 91.148.245.81:42712] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/.env"] [unique_id "al9cQoTd5soprXwxAH0UYAAAABg"]
[Tue Jul 21 08:47:14.907481 2026] [security2:error] [pid 514479:tid 514679] [client 91.148.245.81:42660] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/api/.env"] [unique_id "al9cQvzqsQqnLoCgUjh6LAAAAUs"]
[Tue Jul 21 08:47:14.907744 2026] [security2:error] [pid 511108:tid 511269] [client 91.148.245.81:42700] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/phpinfo.php"] [unique_id "al9cQoTd5soprXwxAH0UYQAAAB8"]
[Tue Jul 21 08:47:14.909247 2026] [security2:error] [pid 514479:tid 514614] [client 91.148.245.81:42688] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/.git/HEAD"] [unique_id "al9cQvzqsQqnLoCgUjh6LgAAAQo"]
[Tue Jul 21 08:47:15.054228 2026] [security2:error] [pid 514479:tid 514598] [remote 57.141.18.84:44432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9cQ_zqsQqnLoCgUjh6MgABU3E"]
[Tue Jul 21 08:47:15.110689 2026] [security2:error] [pid 511108:tid 511241] [client 91.148.245.81:42674] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/docker-compose.yml"] [unique_id "al9cQ4Td5soprXwxAH0UaAAAAAM"]
[Tue Jul 21 08:47:15.111175 2026] [security2:error] [pid 514479:tid 514635] [client 91.148.245.81:42698] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/user_secrets.yml"] [unique_id "al9cQ_zqsQqnLoCgUjh6NAAAAR8"]
[Tue Jul 21 08:47:15.112869 2026] [security2:error] [pid 514479:tid 514733] [client 203.25.124.31:47173] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cQvzqsQqnLoCgUjh6MAAAAYE"]
[Tue Jul 21 08:47:15.142098 2026] [security2:error] [pid 511108:tid 511346] [client 20.197.192.193:8140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/berlin.php"] [unique_id "al9cQ4Td5soprXwxAH0UbQAAAGw"]
[Tue Jul 21 08:47:15.186094 2026] [security2:error] [pid 514479:tid 514631] [client 61.1.167.83:64822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.167.1.61.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cQ_zqsQqnLoCgUjh6NwAAARs"]
[Tue Jul 21 08:47:15.186227 2026] [security2:error] [pid 514479:tid 514631] [client 61.1.167.83:64822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "clinicaleonazevedo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cQ_zqsQqnLoCgUjh6NwAAARs"]
[Tue Jul 21 08:47:15.216407 2026] [security2:error] [pid 514479:tid 514726] [client 5.38.115.39:59926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cQ_zqsQqnLoCgUjh6OAAAAXo"]
[Tue Jul 21 08:47:15.216523 2026] [security2:error] [pid 514479:tid 514726] [client 5.38.115.39:59926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cQ_zqsQqnLoCgUjh6OAAAAXo"]
[Tue Jul 21 08:47:15.254225 2026] [security2:error] [pid 514479:tid 514709] [client 202.179.75.202:51870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cQ_zqsQqnLoCgUjh6OgAAAWk"]
[Tue Jul 21 08:47:15.254399 2026] [security2:error] [pid 514479:tid 514709] [client 202.179.75.202:51870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cQ_zqsQqnLoCgUjh6OgAAAWk"]
[Tue Jul 21 08:47:15.340466 2026] [security2:error] [pid 514479:tid 514670] [client 20.197.192.193:7243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/billur.php"] [unique_id "al9cQ_zqsQqnLoCgUjh6PQAAAUI"]
[Tue Jul 21 08:47:15.413354 2026] [security2:error] [pid 514479:tid 514725] [client 20.197.192.193:8151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/mimpi.php"] [unique_id "al9cQ_zqsQqnLoCgUjh6PwAAAXk"]
[Tue Jul 21 08:47:15.590761 2026] [security2:error] [pid 514479:tid 514699] [client 20.197.192.193:7225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/dp.php"] [unique_id "al9cQ_zqsQqnLoCgUjh6QgAAAV8"]
[Tue Jul 21 08:47:15.635014 2026] [security2:error] [pid 514479:tid 514647] [client 20.197.192.193:7280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/bootstrap.php"] [unique_id "al9cQ_zqsQqnLoCgUjh6QwAAASs"]
[Tue Jul 21 08:47:15.665429 2026] [security2:error] [pid 514479:tid 514642] [client 203.25.124.35:54701] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/windazo/inc/plugins/wp-blog-header.php"] [unique_id "al9cQ_zqsQqnLoCgUjh6RAAAASY"]
[Tue Jul 21 08:47:15.676196 2026] [security2:error] [pid 514479:tid 514710] [client 212.32.76.66:57557] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/login.php"] [unique_id "al9cQ_zqsQqnLoCgUjh6RgAAAWo"]
[Tue Jul 21 08:47:15.802371 2026] [security2:error] [pid 511108:tid 511288] [client 20.197.192.193:7234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/wp-editor.php"] [unique_id "al9cQ4Td5soprXwxAH0UeAAAADI"]
[Tue Jul 21 08:47:15.920441 2026] [security2:error] [pid 514479:tid 514661] [client 91.148.245.81:42722] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9cQ_zqsQqnLoCgUjh6SAAAATk"]
[Tue Jul 21 08:47:15.920444 2026] [security2:error] [pid 514479:tid 514654] [client 91.148.245.81:42720] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/.env.production"] [unique_id "al9cQ_zqsQqnLoCgUjh6SQAAATI"]
[Tue Jul 21 08:47:15.920828 2026] [security2:error] [pid 514479:tid 514700] [client 91.148.245.81:42740] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/server.key"] [unique_id "al9cQ_zqsQqnLoCgUjh6SgAAAWA"]
[Tue Jul 21 08:47:15.921375 2026] [security2:error] [pid 514479:tid 514685] [client 91.148.245.81:42748] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/config/production.json"] [unique_id "al9cQ_zqsQqnLoCgUjh6SwAAAVE"]
[Tue Jul 21 08:47:15.947105 2026] [security2:error] [pid 514479:tid 514678] [client 20.197.192.193:54226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/wp-Blogs.php"] [unique_id "al9cQ_zqsQqnLoCgUjh6TAAAAUo"]
[Tue Jul 21 08:47:16.005107 2026] [security2:error] [pid 514479:tid 514703] [client 20.197.192.193:7219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/cro.php"] [unique_id "al9cRPzqsQqnLoCgUjh6TQAAAWM"]
[Tue Jul 21 08:47:16.090571 2026] [security2:error] [pid 514479:tid 514738] [client 20.197.192.193:7293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/cron-tab.php"] [unique_id "al9cRPzqsQqnLoCgUjh6TwAAAYY"]
[Tue Jul 21 08:47:16.129881 2026] [security2:error] [pid 514479:tid 514711] [client 91.148.245.81:42746] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/secrets.json"] [unique_id "al9cRPzqsQqnLoCgUjh6VAAAAWs"]
[Tue Jul 21 08:47:16.130218 2026] [security2:error] [pid 514479:tid 514664] [client 91.148.245.81:42736] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9cRPzqsQqnLoCgUjh6VQAAATw"]
[Tue Jul 21 08:47:16.131126 2026] [security2:error] [pid 514479:tid 514695] [client 91.148.245.81:42742] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/.npmrc"] [unique_id "al9cRPzqsQqnLoCgUjh6VgAAAVs"]
[Tue Jul 21 08:47:16.146496 2026] [security2:error] [pid 514479:tid 514630] [client 212.32.76.9:60069] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/worksec.php"] [unique_id "al9cRPzqsQqnLoCgUjh6VwAAARo"]
[Tue Jul 21 08:47:16.165638 2026] [autoindex:error] [pid 514479:tid 514732] [client 172.252.43.55:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:47:16.208323 2026] [security2:error] [pid 514479:tid 514737] [client 20.10.88.201:2944] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gnxinox.com.br"] [uri "/index.php"] [unique_id "al9cRPzqsQqnLoCgUjh6UQAAAYU"]
[Tue Jul 21 08:47:16.264097 2026] [security2:error] [pid 511108:tid 511251] [client 20.197.192.193:8176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/koiy.php"] [unique_id "al9cRITd5soprXwxAH0UgAAAAA0"]
[Tue Jul 21 08:47:16.384303 2026] [core:error] [pid 511108:tid 511256] [client 66.249.66.67:62865] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:47:16.384335 2026] [core:error] [pid 511108:tid 511256] [client 66.249.66.67:62865] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:47:16.394547 2026] [security2:error] [pid 514479:tid 514679] [client 64.42.179.43:54240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9cRPzqsQqnLoCgUjh6WwAAAUs"]
[Tue Jul 21 08:47:16.394664 2026] [security2:error] [pid 514479:tid 514679] [client 64.42.179.43:54240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9cRPzqsQqnLoCgUjh6WwAAAUs"]
[Tue Jul 21 08:47:16.528851 2026] [security2:error] [pid 514479:tid 514705] [client 65.21.113.253:51242] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cRPzqsQqnLoCgUjh6TgAAAWU"]
[Tue Jul 21 08:47:16.650294 2026] [security2:error] [pid 514479:tid 514728] [client 20.197.192.193:7254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/hp2.php"] [unique_id "al9cRPzqsQqnLoCgUjh6XwAAAXw"]
[Tue Jul 21 08:47:16.665797 2026] [security2:error] [pid 514479:tid 514659] [client 203.25.124.71:39627] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/js_composer/include/classes/vendors/plugins/api.php"] [unique_id "al9cRPzqsQqnLoCgUjh6YAAAATc"]
[Tue Jul 21 08:47:17.064686 2026] [security2:error] [pid 514479:tid 514676] [client 103.59.206.240:31391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cRfzqsQqnLoCgUjh6ZQAAAUg"]
[Tue Jul 21 08:47:17.064844 2026] [security2:error] [pid 514479:tid 514676] [client 103.59.206.240:31391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cRfzqsQqnLoCgUjh6ZQAAAUg"]
[Tue Jul 21 08:47:17.085469 2026] [security2:error] [pid 514479:tid 514651] [client 203.25.124.208:50281] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/user/config.php"] [unique_id "al9cRfzqsQqnLoCgUjh6ZwAAAS8"]
[Tue Jul 21 08:47:17.106934 2026] [security2:error] [pid 514479:tid 514650] [client 20.197.192.193:8136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/hp3.php"] [unique_id "al9cRfzqsQqnLoCgUjh6aQAAAS4"]
[Tue Jul 21 08:47:17.113673 2026] [security2:error] [pid 511108:tid 511315] [client 91.148.245.81:42776] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/.bash_history"] [unique_id "al9cRYTd5soprXwxAH0UigAAAE0"]
[Tue Jul 21 08:47:17.114926 2026] [security2:error] [pid 511108:tid 511338] [client 91.148.245.81:42820] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/config.xml"] [unique_id "al9cRYTd5soprXwxAH0UjAAAAGQ"]
[Tue Jul 21 08:47:17.115045 2026] [security2:error] [pid 511108:tid 511286] [client 91.148.245.81:42830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/config.php"] [unique_id "al9cRYTd5soprXwxAH0UiwAAADA"]
[Tue Jul 21 08:47:17.115473 2026] [security2:error] [pid 511108:tid 511360] [client 91.148.245.81:42810] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/backup.tar.gz"] [unique_id "al9cRYTd5soprXwxAH0UjQAAAHo"]
[Tue Jul 21 08:47:17.243844 2026] [security2:error] [pid 514479:tid 514674] [client 203.25.124.72:53753] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content.php"] [unique_id "al9cRfzqsQqnLoCgUjh6bAAAAUY"]
[Tue Jul 21 08:47:17.244254 2026] [security2:error] [pid 514479:tid 514677] [client 59.95.197.55:61864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cRfzqsQqnLoCgUjh6bQAAAUk"]
[Tue Jul 21 08:47:17.244998 2026] [security2:error] [pid 514479:tid 514677] [client 59.95.197.55:61864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cRfzqsQqnLoCgUjh6bQAAAUk"]
[Tue Jul 21 08:47:17.317194 2026] [security2:error] [pid 511108:tid 511291] [client 91.148.245.81:42802] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/backup.zip"] [unique_id "al9cRYTd5soprXwxAH0UkwAAADU"]
[Tue Jul 21 08:47:17.367119 2026] [security2:error] [pid 514479:tid 514668] [client 203.25.124.66:22483] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/stockholm/woocommerce/single-product/add-to-cart/internal.php"] [unique_id "al9cRfzqsQqnLoCgUjh6bwAAAUA"]
[Tue Jul 21 08:47:17.623063 2026] [security2:error] [pid 511108:tid 511283] [client 20.197.192.193:8353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9cRYTd5soprXwxAH0UlwAAAC0"]
[Tue Jul 21 08:47:17.743408 2026] [security2:error] [pid 514479:tid 514636] [client 91.148.245.81:42876] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/actuator/heapdump"] [unique_id "al9cRfzqsQqnLoCgUjh6egAAASA"]
[Tue Jul 21 08:47:17.744585 2026] [security2:error] [pid 511108:tid 511295] [client 91.148.245.81:42870] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/dump.sql"] [unique_id "al9cRYTd5soprXwxAH0UnAAAADk"]
[Tue Jul 21 08:47:17.744753 2026] [security2:error] [pid 514479:tid 514647] [client 91.148.245.81:42850] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/database.sql"] [unique_id "al9cRfzqsQqnLoCgUjh6fAAAASs"]
[Tue Jul 21 08:47:17.747920 2026] [security2:error] [pid 511108:tid 511255] [client 20.197.192.193:8187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/aa1.php"] [unique_id "al9cRYTd5soprXwxAH0UnQAAABE"]
[Tue Jul 21 08:47:17.966259 2026] [security2:error] [pid 514479:tid 514717] [client 122.176.100.127:63614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cRfzqsQqnLoCgUjh6iAAAAXE"]
[Tue Jul 21 08:47:17.966508 2026] [security2:error] [pid 514479:tid 514717] [client 122.176.100.127:63614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cRfzqsQqnLoCgUjh6iAAAAXE"]
[Tue Jul 21 08:47:18.007558 2026] [security2:error] [pid 511108:tid 511147] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cRoTd5soprXwxAH0UpgAAYyY"]
[Tue Jul 21 08:47:18.007691 2026] [security2:error] [pid 511108:tid 511337] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cRoTd5soprXwxAH0UpgAAYyY"]
[Tue Jul 21 08:47:18.010081 2026] [security2:error] [pid 514479:tid 514639] [client 113.22.144.139:62212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cRvzqsQqnLoCgUjh6jwAAASM"]
[Tue Jul 21 08:47:18.010904 2026] [security2:error] [pid 514479:tid 514639] [client 113.22.144.139:62212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cRvzqsQqnLoCgUjh6jwAAASM"]
[Tue Jul 21 08:47:18.069263 2026] [security2:error] [pid 511108:tid 511352] [client 195.49.128.211:50004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cRoTd5soprXwxAH0UqAAAAHI"]
[Tue Jul 21 08:47:18.069374 2026] [security2:error] [pid 511108:tid 511352] [client 195.49.128.211:50004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cRoTd5soprXwxAH0UqAAAAHI"]
[Tue Jul 21 08:47:18.176425 2026] [security2:error] [pid 514479:tid 514730] [client 20.197.192.193:8185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/acew67.php"] [unique_id "al9cRvzqsQqnLoCgUjh6lgAAAX4"]
[Tue Jul 21 08:47:18.234064 2026] [security2:error] [pid 514479:tid 514737] [client 203.25.124.58:20375] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/chosen.php"] [unique_id "al9cRvzqsQqnLoCgUjh6lwAAAYU"]
[Tue Jul 21 08:47:18.291145 2026] [security2:error] [pid 514479:tid 514701] [client 91.148.245.81:42886] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/.svn/wc.db"] [unique_id "al9cRvzqsQqnLoCgUjh6mwAAAWE"]
[Tue Jul 21 08:47:18.454819 2026] [access_compat:error] [pid 514479:tid 514687] [client 162.241.63.68:27622] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:47:18.667516 2026] [security2:error] [pid 514479:tid 514688] [client 212.32.76.11:63313] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/post-template/index.php"] [unique_id "al9cRvzqsQqnLoCgUjh6pAAAAVQ"]
[Tue Jul 21 08:47:18.712108 2026] [security2:error] [pid 514479:tid 514633] [client 91.148.245.81:42946] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9cRvzqsQqnLoCgUjh6qAAAAR0"]
[Tue Jul 21 08:47:18.712265 2026] [security2:error] [pid 514479:tid 514718] [client 91.148.245.81:42932] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/database_backup.sql"] [unique_id "al9cRvzqsQqnLoCgUjh6qQAAAXI"]
[Tue Jul 21 08:47:18.713136 2026] [security2:error] [pid 514479:tid 514619] [client 91.148.245.81:42916] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/backup.sql"] [unique_id "al9cRvzqsQqnLoCgUjh6qgAAAQ8"]
[Tue Jul 21 08:47:18.714323 2026] [security2:error] [pid 511108:tid 511342] [client 91.148.245.81:42950] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9cRoTd5soprXwxAH0UsAAAAGg"]
[Tue Jul 21 08:47:18.767392 2026] [security2:error] [pid 514479:tid 514621] [client 20.197.192.193:7286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/bscclapb.php"] [unique_id "al9cRvzqsQqnLoCgUjh6qwAAARE"]
[Tue Jul 21 08:47:19.010836 2026] [security2:error] [pid 514479:tid 514642] [client 20.197.192.193:8380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9cR_zqsQqnLoCgUjh6sQAAASY"]
[Tue Jul 21 08:47:19.039789 2026] [security2:error] [pid 514479:tid 514641] [client 20.197.192.193:7244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/else1.php"] [unique_id "al9cR_zqsQqnLoCgUjh6sgAAASU"]
[Tue Jul 21 08:47:19.229406 2026] [security2:error] [pid 514479:tid 514526] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cR_zqsQqnLoCgUjh6tQABFSo"]
[Tue Jul 21 08:47:19.229566 2026] [security2:error] [pid 514479:tid 514625] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cR_zqsQqnLoCgUjh6tQABFSo"]
[Tue Jul 21 08:47:19.432516 2026] [security2:error] [pid 514479:tid 514638] [client 20.197.192.193:7277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/tkikikoko.php"] [unique_id "al9cR_zqsQqnLoCgUjh6ugAAASI"]
[Tue Jul 21 08:47:19.502682 2026] [security2:error] [pid 514479:tid 514623] [client 91.148.245.81:42964] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lp.oticapersona.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9cR_zqsQqnLoCgUjh6uwAAARM"]
[Tue Jul 21 08:47:19.646464 2026] [security2:error] [pid 514479:tid 514689] [client 212.32.76.13:42521] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/tinymce/themes/about.php"] [unique_id "al9cR_zqsQqnLoCgUjh6wAAAAVU"]
[Tue Jul 21 08:47:19.784525 2026] [security2:error] [pid 514479:tid 514721] [client 41.89.234.2:65074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cR_zqsQqnLoCgUjh6xAAAAXU"]
[Tue Jul 21 08:47:19.784634 2026] [security2:error] [pid 514479:tid 514721] [client 41.89.234.2:65074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cR_zqsQqnLoCgUjh6xAAAAXU"]
[Tue Jul 21 08:47:19.871574 2026] [security2:error] [pid 511108:tid 511306] [client 203.25.124.188:62909] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/languages/themes/admin.php"] [unique_id "al9cR4Td5soprXwxAH0UvgAAAEQ"]
[Tue Jul 21 08:47:19.963662 2026] [security2:error] [pid 511108:tid 511308] [client 203.25.124.55:52279] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "al9cR4Td5soprXwxAH0UvwAAAEY"]
[Tue Jul 21 08:47:20.337936 2026] [security2:error] [pid 514479:tid 514670] [client 20.197.192.193:7250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9cSPzqsQqnLoCgUjh60gAAAUI"]
[Tue Jul 21 08:47:20.344198 2026] [security2:error] [pid 511108:tid 511210] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cSITd5soprXwxAH0UyAAAN2U"]
[Tue Jul 21 08:47:20.344384 2026] [security2:error] [pid 511108:tid 511293] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cSITd5soprXwxAH0UyAAAN2U"]
[Tue Jul 21 08:47:20.500061 2026] [security2:error] [pid 514479:tid 514682] [client 185.198.240.231:44789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9cSPzqsQqnLoCgUjh61gAAAU4"]
[Tue Jul 21 08:47:20.658140 2026] [security2:error] [pid 514479:tid 514704] [client 185.198.240.211:52421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9cSPzqsQqnLoCgUjh61QAAAWQ"]
[Tue Jul 21 08:47:20.671594 2026] [security2:error] [pid 514479:tid 514674] [client 20.197.192.193:8134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/wp-css.php"] [unique_id "al9cSPzqsQqnLoCgUjh62AAAAUY"]
[Tue Jul 21 08:47:20.676108 2026] [security2:error] [pid 511108:tid 511343] [client 203.25.124.3:50563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/PHPMailer/"] [unique_id "al9cSITd5soprXwxAH0UzwAAAGk"]
[Tue Jul 21 08:47:20.925670 2026] [security2:error] [pid 514479:tid 514646] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9cSPzqsQqnLoCgUjh63QAAASo"]
[Tue Jul 21 08:47:20.935871 2026] [security2:error] [pid 514479:tid 514715] [client 203.25.124.64:40205] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/ssss/src.php"] [unique_id "al9cSPzqsQqnLoCgUjh63gAAAW8"]
[Tue Jul 21 08:47:20.964939 2026] [security2:error] [pid 511108:tid 511253] [client 20.197.192.193:7265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/wp-explorer.php"] [unique_id "al9cSITd5soprXwxAH0U2gAAAA8"]
[Tue Jul 21 08:47:20.967118 2026] [security2:error] [pid 514479:tid 514641] [client 203.25.124.48:61455] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/css/dist/block-directory/index.php"] [unique_id "al9cSPzqsQqnLoCgUjh63wAAASU"]
[Tue Jul 21 08:47:21.145933 2026] [security2:error] [pid 514479:tid 514680] [client 20.197.192.193:8132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/akismet.php"] [unique_id "al9cSfzqsQqnLoCgUjh64gAAAUw"]
[Tue Jul 21 08:47:21.213188 2026] [security2:error] [pid 511108:tid 511287] [client 143.244.57.121:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cSYTd5soprXwxAH0U4AAAADE"]
[Tue Jul 21 08:47:21.330975 2026] [security2:error] [pid 511108:tid 511281] [client 49.144.66.253:33283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cSYTd5soprXwxAH0U4gAAACs"]
[Tue Jul 21 08:47:21.331071 2026] [security2:error] [pid 511108:tid 511281] [client 49.144.66.253:33283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cSYTd5soprXwxAH0U4gAAACs"]
[Tue Jul 21 08:47:21.352016 2026] [security2:error] [pid 514479:tid 514702] [client 20.197.192.193:8147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/ace2.php"] [unique_id "al9cSfzqsQqnLoCgUjh66gAAAWI"]
[Tue Jul 21 08:47:21.666872 2026] [security2:error] [pid 514479:tid 514722] [client 20.197.192.193:8173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.setpointgeradores.com.br"] [uri "/ms.php"] [unique_id "al9cSfzqsQqnLoCgUjh67wAAAXY"]
[Tue Jul 21 08:47:21.673867 2026] [security2:error] [pid 511108:tid 511365] [client 203.25.124.7:61505] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/wp-file-manager/file_folder_manager.php"] [unique_id "al9cSYTd5soprXwxAH0U6AAAAH8"]
[Tue Jul 21 08:47:21.688110 2026] [security2:error] [pid 514479:tid 514737] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9cSfzqsQqnLoCgUjh68AAAAYU"]
[Tue Jul 21 08:47:21.769639 2026] [security2:error] [pid 514479:tid 514652] [client 20.197.192.193:4068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/wp-css.php"] [unique_id "al9cSfzqsQqnLoCgUjh68QAAATA"]
[Tue Jul 21 08:47:21.867031 2026] [security2:error] [pid 514479:tid 514721] [client 203.25.124.213:39467] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "al9cSfzqsQqnLoCgUjh68wAAAXU"]
[Tue Jul 21 08:47:21.917220 2026] [security2:error] [pid 514479:tid 514517] [remote 72.167.132.114:32798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9cSfzqsQqnLoCgUjh69AABgCE"]
[Tue Jul 21 08:47:21.972879 2026] [security2:error] [pid 514479:tid 514695] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9cSfzqsQqnLoCgUjh69QAAAVs"]
[Tue Jul 21 08:47:22.039445 2026] [security2:error] [pid 511108:tid 511342] [client 203.25.124.33:64295] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/css/dist/components/"] [unique_id "al9cSoTd5soprXwxAH0U7wAAAGg"]
[Tue Jul 21 08:47:22.260294 2026] [security2:error] [pid 514479:tid 514657] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9cSvzqsQqnLoCgUjh7AQAAATU"]
[Tue Jul 21 08:47:22.545681 2026] [security2:error] [pid 514479:tid 514619] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9cSvzqsQqnLoCgUjh7CQAAAQ8"]
[Tue Jul 21 08:47:22.578526 2026] [security2:error] [pid 514479:tid 514621] [client 203.25.124.198:35065] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "al9cSvzqsQqnLoCgUjh7CgAAARE"]
[Tue Jul 21 08:47:22.635351 2026] [security2:error] [pid 514479:tid 514574] [remote 148.113.130.216:59902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "fullconcursosmilitares.com"] [uri "/"] [unique_id "al9cSvzqsQqnLoCgUjh7FwABLlk"]
[Tue Jul 21 08:47:22.635471 2026] [security2:error] [pid 514479:tid 514650] [client 148.113.130.216:59902] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "fullconcursosmilitares.com"] [uri "/"] [unique_id "al9cSvzqsQqnLoCgUjh7FwABLlk"]
[Tue Jul 21 08:47:22.833443 2026] [security2:error] [pid 514479:tid 514691] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9cSvzqsQqnLoCgUjh7IwAAAVc"]
[Tue Jul 21 08:47:22.862512 2026] [security2:error] [pid 514479:tid 514715] [client 203.25.124.64:29679] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "al9cSvzqsQqnLoCgUjh7JAAAAW8"]
[Tue Jul 21 08:47:23.121487 2026] [security2:error] [pid 514479:tid 514726] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9cS_zqsQqnLoCgUjh7KgAAAXo"]
[Tue Jul 21 08:47:23.290886 2026] [security2:error] [pid 514479:tid 514655] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cS_zqsQqnLoCgUjh7LAABMwg"]
[Tue Jul 21 08:47:23.293400 2026] [security2:error] [pid 514479:tid 514682] [client 5.31.193.106:29960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cS_zqsQqnLoCgUjh7LwAAAU4"]
[Tue Jul 21 08:47:23.305176 2026] [security2:error] [pid 514479:tid 514682] [client 5.31.193.106:29960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cS_zqsQqnLoCgUjh7LwAAAU4"]
[Tue Jul 21 08:47:23.339240 2026] [security2:error] [pid 514479:tid 514645] [client 212.32.76.13:32347] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/files/"] [unique_id "al9cS_zqsQqnLoCgUjh7MAAAASk"]
[Tue Jul 21 08:47:23.370784 2026] [security2:error] [pid 511108:tid 511267] [client 203.25.124.210:36085] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/about.php"] [unique_id "al9cS4Td5soprXwxAH0VAgAAAB0"]
[Tue Jul 21 08:47:23.387717 2026] [security2:error] [pid 514479:tid 514580] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cS_zqsQqnLoCgUjh7MgABJF8"]
[Tue Jul 21 08:47:23.387851 2026] [security2:error] [pid 514479:tid 514640] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cS_zqsQqnLoCgUjh7MgABJF8"]
[Tue Jul 21 08:47:23.409927 2026] [security2:error] [pid 514479:tid 514719] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9cS_zqsQqnLoCgUjh7NAAAAXM"]
[Tue Jul 21 08:47:23.490939 2026] [security2:error] [pid 511108:tid 511148] [remote 15.235.98.108:26994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "localizavistorias.com"] [uri "/robots.txt"] [unique_id "al9cS4Td5soprXwxAH0VBQAAJic"]
[Tue Jul 21 08:47:23.491134 2026] [security2:error] [pid 511108:tid 511276] [client 15.235.98.108:26994] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "localizavistorias.com"] [uri "/robots.txt"] [unique_id "al9cS4Td5soprXwxAH0VBQAAJic"]
[Tue Jul 21 08:47:23.672563 2026] [security2:error] [pid 514479:tid 514727] [client 168.167.81.163:65175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cS_zqsQqnLoCgUjh7PQAAAXs"]
[Tue Jul 21 08:47:23.672691 2026] [security2:error] [pid 514479:tid 514727] [client 168.167.81.163:65175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cS_zqsQqnLoCgUjh7PQAAAXs"]
[Tue Jul 21 08:47:23.696515 2026] [security2:error] [pid 514479:tid 514663] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9cS_zqsQqnLoCgUjh7PgAAATs"]
[Tue Jul 21 08:47:23.982153 2026] [security2:error] [pid 514479:tid 514694] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9cS_zqsQqnLoCgUjh7RAAAAVo"]
[Tue Jul 21 08:47:24.200724 2026] [security2:error] [pid 514479:tid 514510] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cTPzqsQqnLoCgUjh7SgABLRo"]
[Tue Jul 21 08:47:24.200904 2026] [security2:error] [pid 514479:tid 514649] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cTPzqsQqnLoCgUjh7SgABLRo"]
[Tue Jul 21 08:47:24.224028 2026] [security2:error] [pid 514479:tid 514650] [client 20.197.192.193:9427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/wander.php"] [unique_id "al9cTPzqsQqnLoCgUjh7SwAAAS4"]
[Tue Jul 21 08:47:24.259546 2026] [security2:error] [pid 514479:tid 514508] [remote 45.79.123.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9cTPzqsQqnLoCgUjh7TQABXRg"]
[Tue Jul 21 08:47:24.267161 2026] [security2:error] [pid 514479:tid 514674] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9cTPzqsQqnLoCgUjh7TgAAAUY"]
[Tue Jul 21 08:47:24.272566 2026] [security2:error] [pid 514479:tid 514698] [client 203.25.124.202:32589] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/sitemaps/admin.php"] [unique_id "al9cTPzqsQqnLoCgUjh7TwAAAV4"]
[Tue Jul 21 08:47:24.331074 2026] [security2:error] [pid 511108:tid 511360] [client 152.59.181.104:62112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cTITd5soprXwxAH0VEQAAAHo"]
[Tue Jul 21 08:47:24.331789 2026] [security2:error] [pid 511108:tid 511360] [client 152.59.181.104:62112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cTITd5soprXwxAH0VEQAAAHo"]
[Tue Jul 21 08:47:24.553522 2026] [security2:error] [pid 514479:tid 514680] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9cTPzqsQqnLoCgUjh7UwAAAUw"]
[Tue Jul 21 08:47:24.753323 2026] [security2:error] [pid 514479:tid 514617] [client 203.25.124.50:36405] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/themes.php"] [unique_id "al9cTPzqsQqnLoCgUjh7WAAAAQ0"]
[Tue Jul 21 08:47:24.833653 2026] [security2:error] [pid 514479:tid 514566] [remote 199.189.225.40:48493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9cTPzqsQqnLoCgUjh7WQABP1E"]
[Tue Jul 21 08:47:24.840859 2026] [security2:error] [pid 514479:tid 514623] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9cTPzqsQqnLoCgUjh7WgAAARM"]
[Tue Jul 21 08:47:25.019675 2026] [security2:error] [pid 514479:tid 514511] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cTfzqsQqnLoCgUjh7XgABLBs"]
[Tue Jul 21 08:47:25.019905 2026] [security2:error] [pid 514479:tid 514648] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cTfzqsQqnLoCgUjh7XgABLBs"]
[Tue Jul 21 08:47:25.026472 2026] [security2:error] [pid 514479:tid 514668] [client 65.21.113.253:59818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cTPzqsQqnLoCgUjh7VAAAAUA"]
[Tue Jul 21 08:47:25.062378 2026] [security2:error] [pid 514479:tid 514564] [remote 142.44.228.81:48112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "localizavistorias.com"] [uri "/"] [unique_id "al9cTfzqsQqnLoCgUjh7XwABbE8"]
[Tue Jul 21 08:47:25.062546 2026] [security2:error] [pid 514479:tid 514712] [client 142.44.228.81:48112] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "localizavistorias.com"] [uri "/"] [unique_id "al9cTfzqsQqnLoCgUjh7XwABbE8"]
[Tue Jul 21 08:47:25.074228 2026] [security2:error] [pid 511108:tid 511263] [client 203.25.124.181:55583] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/js/widgets/maint/"] [unique_id "al9cTYTd5soprXwxAH0VGwAAABk"]
[Tue Jul 21 08:47:25.153938 2026] [security2:error] [pid 514479:tid 514630] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9cTfzqsQqnLoCgUjh7YgAAARo"]
[Tue Jul 21 08:47:25.439687 2026] [security2:error] [pid 514479:tid 514679] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9cTfzqsQqnLoCgUjh7aAAAAUs"]
[Tue Jul 21 08:47:25.544581 2026] [security2:error] [pid 514479:tid 514728] [client 195.206.105.227:49834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9cTfzqsQqnLoCgUjh7awAAAXw"]
[Tue Jul 21 08:47:25.544706 2026] [security2:error] [pid 514479:tid 514728] [client 195.206.105.227:49834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9cTfzqsQqnLoCgUjh7awAAAXw"]
[Tue Jul 21 08:47:25.725162 2026] [security2:error] [pid 511108:tid 511278] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9cTYTd5soprXwxAH0VJQAAACg"]
[Tue Jul 21 08:47:25.870047 2026] [security2:error] [pid 514479:tid 514653] [client 45.8.19.182:57609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lotfiimplantes.com.br"] [uri "/wp-login.php"] [unique_id "al9cTfzqsQqnLoCgUjh7cQAAATE"]
[Tue Jul 21 08:47:25.908378 2026] [security2:error] [pid 514479:tid 514741] [client 20.197.195.24:2763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/about.php"] [unique_id "al9cTfzqsQqnLoCgUjh7cgAAAYk"]
[Tue Jul 21 08:47:25.945770 2026] [security2:error] [pid 514479:tid 514621] [client 203.25.124.51:48963] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/ahax.php"] [unique_id "al9cTfzqsQqnLoCgUjh7cwAAARE"]
[Tue Jul 21 08:47:25.962394 2026] [security2:error] [pid 514479:tid 514725] [client 203.25.124.42:35059] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9cTfzqsQqnLoCgUjh7dAAAAXk"]
[Tue Jul 21 08:47:25.986466 2026] [security2:error] [pid 511108:tid 511346] [client 5.38.115.39:60635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cTYTd5soprXwxAH0VKwAAAGw"]
[Tue Jul 21 08:47:25.992829 2026] [security2:error] [pid 511108:tid 511346] [client 5.38.115.39:60635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cTYTd5soprXwxAH0VKwAAAGw"]
[Tue Jul 21 08:47:26.018179 2026] [security2:error] [pid 511108:tid 511324] [client 143.244.57.121:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.leonardopaiva1782846359465.0721679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9cToTd5soprXwxAH0VLAAAAFY"]
[Tue Jul 21 08:47:26.282752 2026] [security2:error] [pid 514479:tid 514642] [client 203.25.124.199:45235] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/languages/classwithtostring.php"] [unique_id "al9cTvzqsQqnLoCgUjh7eQAAASY"]
[Tue Jul 21 08:47:26.297009 2026] [security2:error] [pid 514479:tid 514633] [client 202.179.75.202:51134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cTvzqsQqnLoCgUjh7egAAAR0"]
[Tue Jul 21 08:47:26.297142 2026] [security2:error] [pid 514479:tid 514633] [client 202.179.75.202:51134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cTvzqsQqnLoCgUjh7egAAAR0"]
[Tue Jul 21 08:47:26.421519 2026] [security2:error] [pid 511108:tid 511358] [client 114.198.138.124:57757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cToTd5soprXwxAH0VNgAAAHg"]
[Tue Jul 21 08:47:26.421642 2026] [security2:error] [pid 511108:tid 511358] [client 114.198.138.124:57757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cToTd5soprXwxAH0VNgAAAHg"]
[Tue Jul 21 08:47:26.592950 2026] [security2:error] [pid 511108:tid 511251] [client 20.197.192.193:8347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/jga.php"] [unique_id "al9cToTd5soprXwxAH0VOgAAAA0"]
[Tue Jul 21 08:47:26.604338 2026] [security2:error] [pid 511108:tid 511218] [remote 8.217.108.67:6246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fgengenharia.eng.br"] [uri "/wp-login.php"] [unique_id "al9cToTd5soprXwxAH0VOwAAL20"]
[Tue Jul 21 08:47:27.141010 2026] [security2:error] [pid 514479:tid 514623] [client 203.25.124.49:29083] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/images/"] [unique_id "al9cT_zqsQqnLoCgUjh7gwAAARM"]
[Tue Jul 21 08:47:27.475838 2026] [security2:error] [pid 511108:tid 511248] [client 64.42.179.43:50600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9cT4Td5soprXwxAH0VSQAAAAo"]
[Tue Jul 21 08:47:27.475940 2026] [security2:error] [pid 511108:tid 511248] [client 64.42.179.43:50600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9cT4Td5soprXwxAH0VSQAAAAo"]
[Tue Jul 21 08:47:27.477096 2026] [security2:error] [pid 514479:tid 514702] [client 20.197.192.193:54218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/wp-explorer.php"] [unique_id "al9cT_zqsQqnLoCgUjh7hwAAAWI"]
[Tue Jul 21 08:47:27.577219 2026] [security2:error] [pid 511108:tid 511254] [client 203.25.124.208:41541] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al9cT4Td5soprXwxAH0VSgAAABA"]
[Tue Jul 21 08:47:27.739768 2026] [security2:error] [pid 511108:tid 511298] [client 59.95.197.55:62337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cT4Td5soprXwxAH0VTgAAADw"]
[Tue Jul 21 08:47:27.739909 2026] [security2:error] [pid 511108:tid 511298] [client 59.95.197.55:62337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cT4Td5soprXwxAH0VTgAAADw"]
[Tue Jul 21 08:47:28.163264 2026] [security2:error] [pid 511108:tid 511255] [client 82.102.18.190:32994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "farmacianaturofarma.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9cUITd5soprXwxAH0VVQAAABE"]
[Tue Jul 21 08:47:28.210721 2026] [security2:error] [pid 511108:tid 511305] [client 103.59.206.240:31368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cUITd5soprXwxAH0VVgAAAEM"]
[Tue Jul 21 08:47:28.210854 2026] [security2:error] [pid 511108:tid 511305] [client 103.59.206.240:31368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cUITd5soprXwxAH0VVgAAAEM"]
[Tue Jul 21 08:47:28.481688 2026] [security2:error] [pid 511108:tid 511318] [client 122.176.100.127:64099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cUITd5soprXwxAH0VWQAAAFA"]
[Tue Jul 21 08:47:28.482004 2026] [security2:error] [pid 511108:tid 511318] [client 122.176.100.127:64099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cUITd5soprXwxAH0VWQAAAFA"]
[Tue Jul 21 08:47:28.527934 2026] [security2:error] [pid 514479:tid 514735] [client 203.25.124.212:37997] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/preformatted/"] [unique_id "al9cUPzqsQqnLoCgUjh7kgAAAYM"]
[Tue Jul 21 08:47:28.534229 2026] [security2:error] [pid 514479:tid 514567] [remote 212.80.9.235:55010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cUPzqsQqnLoCgUjh7kwABdlI"]
[Tue Jul 21 08:47:28.534356 2026] [security2:error] [pid 514479:tid 514722] [client 212.80.9.235:55010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cUPzqsQqnLoCgUjh7kwABdlI"]
[Tue Jul 21 08:47:28.646975 2026] [security2:error] [pid 514479:tid 514502] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cUPzqsQqnLoCgUjh7lQABfBI"]
[Tue Jul 21 08:47:28.647132 2026] [security2:error] [pid 514479:tid 514728] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cUPzqsQqnLoCgUjh7lQABfBI"]
[Tue Jul 21 08:47:28.647897 2026] [security2:error] [pid 511108:tid 511263] [client 195.49.128.211:50605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cUITd5soprXwxAH0VXwAAABk"]
[Tue Jul 21 08:47:28.647997 2026] [security2:error] [pid 511108:tid 511263] [client 195.49.128.211:50605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cUITd5soprXwxAH0VXwAAABk"]
[Tue Jul 21 08:47:28.677378 2026] [security2:error] [pid 514479:tid 514640] [client 203.25.124.201:46809] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/colors/modern/test2.php"] [unique_id "al9cUPzqsQqnLoCgUjh7lwAAASQ"]
[Tue Jul 21 08:47:28.815229 2026] [security2:error] [pid 514479:tid 514707] [client 113.22.144.139:62729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cUPzqsQqnLoCgUjh7mgAAAWc"]
[Tue Jul 21 08:47:28.815967 2026] [security2:error] [pid 514479:tid 514707] [client 113.22.144.139:62729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cUPzqsQqnLoCgUjh7mgAAAWc"]
[Tue Jul 21 08:47:28.867488 2026] [security2:error] [pid 514479:tid 514727] [client 203.25.124.213:29637] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "al9cUPzqsQqnLoCgUjh7nQAAAXs"]
[Tue Jul 21 08:47:29.190669 2026] [security2:error] [pid 514479:tid 514663] [client 65.21.113.253:59818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cUPzqsQqnLoCgUjh7mQAAATs"]
[Tue Jul 21 08:47:29.281499 2026] [security2:error] [pid 514479:tid 514697] [client 20.197.192.193:8325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/x.php"] [unique_id "al9cUfzqsQqnLoCgUjh7oQAAAV0"]
[Tue Jul 21 08:47:29.640923 2026] [security2:error] [pid 514479:tid 514739] [client 203.25.124.73:29625] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/colors/coffee/"] [unique_id "al9cUfzqsQqnLoCgUjh7qgAAAYc"]
[Tue Jul 21 08:47:29.684531 2026] [security2:error] [pid 514479:tid 514622] [client 20.197.192.193:41484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/akismet.php"] [unique_id "al9cUfzqsQqnLoCgUjh7rwAAARI"]
[Tue Jul 21 08:47:29.713478 2026] [security2:error] [pid 514479:tid 514632] [client 185.8.106.219:39924] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tempex.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9cUfzqsQqnLoCgUjh7sAAAARw"]
[Tue Jul 21 08:47:29.764300 2026] [security2:error] [pid 514479:tid 514692] [client 203.25.124.65:58113] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/wp-conflg.php"] [unique_id "al9cUfzqsQqnLoCgUjh7swAAAVg"]
[Tue Jul 21 08:47:29.905603 2026] [security2:error] [pid 514479:tid 514514] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cUfzqsQqnLoCgUjh7ugABQh4"]
[Tue Jul 21 08:47:29.905723 2026] [security2:error] [pid 514479:tid 514670] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cUfzqsQqnLoCgUjh7ugABQh4"]
[Tue Jul 21 08:47:29.946052 2026] [security2:error] [pid 511108:tid 511241] [client 82.102.18.190:33006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cUITd5soprXwxAH0VZQAAAAM"]
[Tue Jul 21 08:47:30.320918 2026] [security2:error] [pid 514479:tid 514635] [client 41.89.234.2:41654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cUvzqsQqnLoCgUjh7wgAAAR8"]
[Tue Jul 21 08:47:30.321106 2026] [security2:error] [pid 514479:tid 514635] [client 41.89.234.2:41654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cUvzqsQqnLoCgUjh7wgAAAR8"]
[Tue Jul 21 08:47:30.384483 2026] [security2:error] [pid 514479:tid 514643] [client 203.25.124.206:44113] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwentyfive/parts/"] [unique_id "al9cUvzqsQqnLoCgUjh7wwAAASc"]
[Tue Jul 21 08:47:30.682453 2026] [security2:error] [pid 514479:tid 514619] [client 20.197.192.193:53584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/ace2.php"] [unique_id "al9cUvzqsQqnLoCgUjh7xgAAAQ8"]
[Tue Jul 21 08:47:30.684052 2026] [security2:error] [pid 511108:tid 511256] [client 20.197.192.193:8331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9cUoTd5soprXwxAH0VeAAAABI"]
[Tue Jul 21 08:47:30.864708 2026] [security2:error] [pid 514479:tid 514560] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cUvzqsQqnLoCgUjh7ygABUEs"]
[Tue Jul 21 08:47:30.864855 2026] [security2:error] [pid 514479:tid 514684] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cUvzqsQqnLoCgUjh7ygABUEs"]
[Tue Jul 21 08:47:31.062514 2026] [security2:error] [pid 514479:tid 514631] [client 203.25.124.40:26893] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/function/function.php"] [unique_id "al9cU_zqsQqnLoCgUjh7zwAAARs"]
[Tue Jul 21 08:47:31.233018 2026] [security2:error] [pid 514479:tid 514654] [client 212.32.76.14:56747] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/customize/"] [unique_id "al9cU_zqsQqnLoCgUjh70AAAATI"]
[Tue Jul 21 08:47:31.560189 2026] [security2:error] [pid 514479:tid 514680] [client 20.151.10.161:62382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/greap.php"] [unique_id "al9cU_zqsQqnLoCgUjh71QAAAUw"]
[Tue Jul 21 08:47:31.577380 2026] [security2:error] [pid 514479:tid 514667] [client 212.32.76.64:25749] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/query-title/"] [unique_id "al9cU_zqsQqnLoCgUjh71gAAAT8"]
[Tue Jul 21 08:47:31.672286 2026] [security2:error] [pid 514479:tid 514632] [client 20.197.192.193:8320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/ee.php"] [unique_id "al9cU_zqsQqnLoCgUjh72AAAARw"]
[Tue Jul 21 08:47:31.968006 2026] [security2:error] [pid 511108:tid 511350] [client 185.8.106.219:26768] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tempex.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9cU4Td5soprXwxAH0VkQAAAHA"]
[Tue Jul 21 08:47:32.010168 2026] [security2:error] [pid 514479:tid 514655] [client 20.151.10.161:28546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9cVPzqsQqnLoCgUjh73gAAATM"]
[Tue Jul 21 08:47:32.161262 2026] [security2:error] [pid 514479:tid 514682] [client 203.25.124.50:54827] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "al9cVPzqsQqnLoCgUjh74wAAAU4"]
[Tue Jul 21 08:47:32.396206 2026] [security2:error] [pid 514479:tid 514652] [client 20.151.10.161:28545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9cVPzqsQqnLoCgUjh76AAAATA"]
[Tue Jul 21 08:47:32.436338 2026] [security2:error] [pid 511108:tid 511247] [client 203.25.124.212:47777] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/classwithtostring.php"] [unique_id "al9cVITd5soprXwxAH0VlwAAAAk"]
[Tue Jul 21 08:47:32.673243 2026] [security2:error] [pid 514479:tid 514732] [client 49.144.66.253:33700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cVPzqsQqnLoCgUjh78AAAAYA"]
[Tue Jul 21 08:47:32.673410 2026] [security2:error] [pid 514479:tid 514732] [client 49.144.66.253:33700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cVPzqsQqnLoCgUjh78AAAAYA"]
[Tue Jul 21 08:47:32.724850 2026] [security2:error] [pid 511108:tid 511323] [client 82.102.18.190:44593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "farmacianaturofarma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cVITd5soprXwxAH0VoAAAAFU"]
[Tue Jul 21 08:47:32.724985 2026] [security2:error] [pid 511108:tid 511323] [client 82.102.18.190:44593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "farmacianaturofarma.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cVITd5soprXwxAH0VoAAAAFU"]
[Tue Jul 21 08:47:32.748188 2026] [security2:error] [pid 511108:tid 511253] [client 20.151.10.161:28498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/x.php"] [unique_id "al9cVITd5soprXwxAH0VoQAAAA8"]
[Tue Jul 21 08:47:32.777265 2026] [security2:error] [pid 514479:tid 514709] [client 203.25.124.6:30757] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/config.php"] [unique_id "al9cVPzqsQqnLoCgUjh78wAAAWk"]
[Tue Jul 21 08:47:32.881871 2026] [security2:error] [pid 514479:tid 514615] [client 65.21.113.253:59818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cVPzqsQqnLoCgUjh75wAAAQs"]
[Tue Jul 21 08:47:32.938021 2026] [security2:error] [pid 511108:tid 511330] [client 173.252.95.29:58632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cVITd5soprXwxAH0VpAAAAFw"]
[Tue Jul 21 08:47:33.158217 2026] [security2:error] [pid 514479:tid 514677] [client 203.25.124.68:46955] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/network/upgrade/index.php"] [unique_id "al9cVfzqsQqnLoCgUjh7-AAAAUk"]
[Tue Jul 21 08:47:33.202929 2026] [security2:error] [pid 514479:tid 514698] [client 20.151.10.161:28513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/j260624_13.php"] [unique_id "al9cVfzqsQqnLoCgUjh7_gAAAV4"]
[Tue Jul 21 08:47:33.288995 2026] [security2:error] [pid 511108:tid 511310] [client 185.8.106.219:47260] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.tempex.com.br"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9cVYTd5soprXwxAH0VsAAAAEg"]
[Tue Jul 21 08:47:33.644723 2026] [security2:error] [pid 511108:tid 511265] [client 203.25.124.50:40853] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/gallery/"] [unique_id "al9cVYTd5soprXwxAH0VwgAAABs"]
[Tue Jul 21 08:47:33.855825 2026] [security2:error] [pid 511108:tid 511161] [remote 199.189.225.40:42737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thiagomartins.com"] [uri "/wp-login.php"] [unique_id "al9cVYTd5soprXwxAH0VxgAAVDQ"]
[Tue Jul 21 08:47:33.859808 2026] [security2:error] [pid 514479:tid 514672] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cVfzqsQqnLoCgUjh8GwABRHo"]
[Tue Jul 21 08:47:33.919497 2026] [security2:error] [pid 511108:tid 511163] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cVYTd5soprXwxAH0VxwAACzY"]
[Tue Jul 21 08:47:33.919660 2026] [security2:error] [pid 511108:tid 511249] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cVYTd5soprXwxAH0VxwAACzY"]
[Tue Jul 21 08:47:33.981159 2026] [security2:error] [pid 514479:tid 514681] [client 203.25.124.4:61643] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/images/"] [unique_id "al9cVfzqsQqnLoCgUjh8HgAAAU0"]
[Tue Jul 21 08:47:34.079845 2026] [security2:error] [pid 514479:tid 514717] [client 20.151.10.161:28568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/d62.php"] [unique_id "al9cVvzqsQqnLoCgUjh8IQAAAXE"]
[Tue Jul 21 08:47:34.464867 2026] [security2:error] [pid 511108:tid 511274] [client 203.25.124.66:28983] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "al9cVoTd5soprXwxAH0VzwAAACQ"]
[Tue Jul 21 08:47:34.569194 2026] [security2:error] [pid 514479:tid 514727] [client 185.8.106.219:47264] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tempex.com.br"] [uri "/"] [unique_id "al9cVvzqsQqnLoCgUjh8MAAAAXs"]
[Tue Jul 21 08:47:34.683853 2026] [security2:error] [pid 514479:tid 514671] [client 20.151.10.161:28574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ups.php"] [unique_id "al9cVvzqsQqnLoCgUjh8NgAAAUM"]
[Tue Jul 21 08:47:34.723837 2026] [security2:error] [pid 511108:tid 511215] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cVoTd5soprXwxAH0V1wAAXmo"]
[Tue Jul 21 08:47:34.724050 2026] [security2:error] [pid 511108:tid 511332] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cVoTd5soprXwxAH0V1wAAXmo"]
[Tue Jul 21 08:47:34.753460 2026] [security2:error] [pid 514479:tid 514701] [client 20.197.195.24:49000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/admin.php"] [unique_id "al9cVvzqsQqnLoCgUjh8OAAAAWE"]
[Tue Jul 21 08:47:34.862926 2026] [rewrite:error] [pid 511108:tid 511275] [client 57.141.18.47:0] AH10411: Rewritten query string contains control characters or spaces
[Tue Jul 21 08:47:35.109219 2026] [security2:error] [pid 514479:tid 514670] [client 152.59.181.104:62614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cV_zqsQqnLoCgUjh8OwAAAUI"]
[Tue Jul 21 08:47:35.109344 2026] [security2:error] [pid 514479:tid 514670] [client 152.59.181.104:62614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cV_zqsQqnLoCgUjh8OwAAAUI"]
[Tue Jul 21 08:47:35.178646 2026] [security2:error] [pid 514479:tid 514718] [client 212.32.76.64:54205] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/index-string.php"] [unique_id "al9cV_zqsQqnLoCgUjh8PQAAAXI"]
[Tue Jul 21 08:47:35.455310 2026] [security2:error] [pid 511108:tid 511331] [client 20.151.10.161:28239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/k.php"] [unique_id "al9cV4Td5soprXwxAH0V5gAAAF0"]
[Tue Jul 21 08:47:35.473594 2026] [security2:error] [pid 514479:tid 514654] [client 203.25.124.39:49161] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9cV_zqsQqnLoCgUjh8PwAAATI"]
[Tue Jul 21 08:47:35.599269 2026] [security2:error] [pid 514479:tid 514582] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cV_zqsQqnLoCgUjh8QwABIWE"]
[Tue Jul 21 08:47:35.599490 2026] [security2:error] [pid 514479:tid 514637] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cV_zqsQqnLoCgUjh8QwABIWE"]
[Tue Jul 21 08:47:36.318525 2026] [security2:error] [pid 511108:tid 511221] [remote 20.153.140.50:58772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9cWITd5soprXwxAH0V9QAAIHA"]
[Tue Jul 21 08:47:36.345308 2026] [security2:error] [pid 514479:tid 514715] [client 203.25.124.67:28421] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/js/widgets/images/"] [unique_id "al9cWPzqsQqnLoCgUjh8SQAAAW8"]
[Tue Jul 21 08:47:36.460735 2026] [security2:error] [pid 514479:tid 514685] [client 65.21.113.253:59818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cWPzqsQqnLoCgUjh8RQAAAVE"]
[Tue Jul 21 08:47:36.474890 2026] [security2:error] [pid 514479:tid 514655] [client 212.32.76.61:60865] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/includes/images/index.php"] [unique_id "al9cWPzqsQqnLoCgUjh8SgAAATM"]
[Tue Jul 21 08:47:36.767321 2026] [security2:error] [pid 514479:tid 514656] [client 5.38.115.39:61347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cWPzqsQqnLoCgUjh8TgAAATQ"]
[Tue Jul 21 08:47:36.767460 2026] [security2:error] [pid 514479:tid 514656] [client 5.38.115.39:61347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cWPzqsQqnLoCgUjh8TgAAATQ"]
[Tue Jul 21 08:47:36.924065 2026] [security2:error] [pid 511108:tid 511262] [client 114.198.138.124:58328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cWITd5soprXwxAH0WAAAAABg"]
[Tue Jul 21 08:47:36.924180 2026] [security2:error] [pid 511108:tid 511262] [client 114.198.138.124:58328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cWITd5soprXwxAH0WAAAAABg"]
[Tue Jul 21 08:47:36.969423 2026] [security2:error] [pid 514479:tid 514629] [client 203.25.124.53:37359] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9cWPzqsQqnLoCgUjh8VAAAARk"]
[Tue Jul 21 08:47:37.255789 2026] [security2:error] [pid 514479:tid 514705] [client 203.25.124.50:38843] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/imgareaselect/"] [unique_id "al9cWfzqsQqnLoCgUjh8XAAAAWU"]
[Tue Jul 21 08:47:37.261557 2026] [security2:error] [pid 514479:tid 514524] [remote 114.119.134.178:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hauptmann.com.br"] [uri "/listings-with-elementor/page/3/"] [unique_id "al9cWfzqsQqnLoCgUjh8XQABcCg"], referer: https://hauptmann.com.br/listings-with-elementor/page/5/
[Tue Jul 21 08:47:37.303485 2026] [security2:error] [pid 514479:tid 514735] [client 202.179.75.202:37098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cWfzqsQqnLoCgUjh8XgAAAYM"]
[Tue Jul 21 08:47:37.303606 2026] [security2:error] [pid 514479:tid 514735] [client 202.179.75.202:37098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cWfzqsQqnLoCgUjh8XgAAAYM"]
[Tue Jul 21 08:47:37.340411 2026] [security2:error] [pid 514479:tid 514615] [client 48.217.233.215:60854] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.69"] [uri "/index.cgi"] [unique_id "al9cWfzqsQqnLoCgUjh8XwAAAQs"]
[Tue Jul 21 08:47:38.069998 2026] [security2:error] [pid 514479:tid 514734] [client 203.25.124.5:25093] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/includes/update-core-time.php"] [unique_id "al9cWvzqsQqnLoCgUjh8cwAAAYI"]
[Tue Jul 21 08:47:38.320312 2026] [security2:error] [pid 514479:tid 514670] [client 59.95.197.55:62813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cWvzqsQqnLoCgUjh8dwAAAUI"]
[Tue Jul 21 08:47:38.320444 2026] [security2:error] [pid 514479:tid 514670] [client 59.95.197.55:62813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cWvzqsQqnLoCgUjh8dwAAAUI"]
[Tue Jul 21 08:47:38.362183 2026] [security2:error] [pid 514479:tid 514628] [client 212.32.76.8:31875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/network/chosen.php"] [unique_id "al9cWvzqsQqnLoCgUjh8eAAAARg"]
[Tue Jul 21 08:47:38.579660 2026] [security2:error] [pid 511108:tid 511239] [client 168.167.81.163:63025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cWoTd5soprXwxAH0WFQAAAAE"]
[Tue Jul 21 08:47:38.579759 2026] [security2:error] [pid 511108:tid 511239] [client 168.167.81.163:63025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cWoTd5soprXwxAH0WFQAAAAE"]
[Tue Jul 21 08:47:38.627371 2026] [security2:error] [pid 511108:tid 511132] [remote 72.167.132.114:35716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fgengenharia.eng.br"] [uri "/wp-login.php"] [unique_id "al9cWoTd5soprXwxAH0WFgAAMBc"]
[Tue Jul 21 08:47:38.670941 2026] [security2:error] [pid 511108:tid 511281] [client 20.151.10.161:28528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/k2.php"] [unique_id "al9cWoTd5soprXwxAH0WHAAAACs"]
[Tue Jul 21 08:47:38.812030 2026] [security2:error] [pid 514479:tid 514706] [client 103.59.206.240:31020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cWvzqsQqnLoCgUjh8fAAAAWY"]
[Tue Jul 21 08:47:38.812195 2026] [security2:error] [pid 514479:tid 514706] [client 103.59.206.240:31020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cWvzqsQqnLoCgUjh8fAAAAWY"]
[Tue Jul 21 08:47:38.883000 2026] [security2:error] [pid 514479:tid 514684] [client 20.197.192.193:54249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.prismaseg.com"] [uri "/ms.php"] [unique_id "al9cWvzqsQqnLoCgUjh8fgAAAVA"]
[Tue Jul 21 08:47:38.891247 2026] [security2:error] [pid 514479:tid 514672] [client 122.176.100.127:64587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cWvzqsQqnLoCgUjh8gAAAAUQ"]
[Tue Jul 21 08:47:38.891362 2026] [security2:error] [pid 514479:tid 514672] [client 122.176.100.127:64587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cWvzqsQqnLoCgUjh8gAAAAUQ"]
[Tue Jul 21 08:47:39.251907 2026] [security2:error] [pid 514479:tid 514663] [client 195.49.128.211:51206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cW_zqsQqnLoCgUjh8mQAAATs"]
[Tue Jul 21 08:47:39.252037 2026] [security2:error] [pid 514479:tid 514663] [client 195.49.128.211:51206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cW_zqsQqnLoCgUjh8mQAAATs"]
[Tue Jul 21 08:47:39.345629 2026] [security2:error] [pid 514479:tid 514500] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cW_zqsQqnLoCgUjh8mgABChA"]
[Tue Jul 21 08:47:39.345787 2026] [security2:error] [pid 514479:tid 514614] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cW_zqsQqnLoCgUjh8mgABChA"]
[Tue Jul 21 08:47:39.541198 2026] [security2:error] [pid 511108:tid 511313] [client 203.25.124.61:29815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/wp-conflg.php"] [unique_id "al9cW4Td5soprXwxAH0WJwAAAEs"]
[Tue Jul 21 08:47:39.564693 2026] [security2:error] [pid 514479:tid 514737] [client 203.25.124.70:56483] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "al9cW_zqsQqnLoCgUjh8nwAAAYU"]
[Tue Jul 21 08:47:39.630930 2026] [security2:error] [pid 514479:tid 514691] [client 113.22.144.139:63246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cW_zqsQqnLoCgUjh8ogAAAVc"]
[Tue Jul 21 08:47:39.631045 2026] [security2:error] [pid 514479:tid 514691] [client 113.22.144.139:63246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cW_zqsQqnLoCgUjh8ogAAAVc"]
[Tue Jul 21 08:47:39.677184 2026] [security2:error] [pid 514479:tid 514640] [client 203.25.124.209:49345] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/woocommerce-call.php"] [unique_id "al9cW_zqsQqnLoCgUjh8pAAAASQ"]
[Tue Jul 21 08:47:40.237989 2026] [security2:error] [pid 514479:tid 514735] [client 203.25.124.215:47013] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/shell/"] [unique_id "al9cXPzqsQqnLoCgUjh8sgAAAYM"]
[Tue Jul 21 08:47:40.391349 2026] [security2:error] [pid 511108:tid 511183] [remote 202.51.202.242:36696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9cXITd5soprXwxAH0WNQAACEo"]
[Tue Jul 21 08:47:40.425914 2026] [security2:error] [pid 514479:tid 514707] [client 65.21.113.253:59818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cW_zqsQqnLoCgUjh8qgAAAWc"]
[Tue Jul 21 08:47:40.454009 2026] [security2:error] [pid 511108:tid 511121] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cXITd5soprXwxAH0WNwAAZgw"]
[Tue Jul 21 08:47:40.454139 2026] [security2:error] [pid 511108:tid 511340] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cXITd5soprXwxAH0WNwAAZgw"]
[Tue Jul 21 08:47:40.874157 2026] [security2:error] [pid 514479:tid 514677] [client 203.25.124.74:44999] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/news-portal/fm.php"] [unique_id "al9cXPzqsQqnLoCgUjh8uwAAAUk"]
[Tue Jul 21 08:47:40.883608 2026] [security2:error] [pid 511108:tid 511276] [client 41.89.234.2:49709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cXITd5soprXwxAH0WPgAAACY"]
[Tue Jul 21 08:47:40.883702 2026] [security2:error] [pid 511108:tid 511276] [client 41.89.234.2:49709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cXITd5soprXwxAH0WPgAAACY"]
[Tue Jul 21 08:47:41.135594 2026] [security2:error] [pid 514479:tid 514713] [client 20.197.195.24:2791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/admin.php"] [unique_id "al9cXfzqsQqnLoCgUjh8vgAAAW0"]
[Tue Jul 21 08:47:41.172286 2026] [security2:error] [pid 514479:tid 514657] [client 212.32.76.66:60727] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/user/upgrade/index.php"] [unique_id "al9cXfzqsQqnLoCgUjh8vwAAATU"]
[Tue Jul 21 08:47:41.408517 2026] [security2:error] [pid 514479:tid 514636] [client 20.151.10.161:28243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/k3.php"] [unique_id "al9cXfzqsQqnLoCgUjh8wwAAASA"]
[Tue Jul 21 08:47:41.460230 2026] [security2:error] [pid 514479:tid 514516] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cXfzqsQqnLoCgUjh8xAABHSA"]
[Tue Jul 21 08:47:41.460447 2026] [security2:error] [pid 514479:tid 514633] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cXfzqsQqnLoCgUjh8xAABHSA"]
[Tue Jul 21 08:47:41.845761 2026] [security2:error] [pid 511108:tid 511239] [client 212.32.76.9:23807] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/mini.php"] [unique_id "al9cXYTd5soprXwxAH0WTgAAAAE"]
[Tue Jul 21 08:47:41.903321 2026] [security2:error] [pid 514479:tid 514536] [remote 39.97.110.217:46628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.110.97.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9cXfzqsQqnLoCgUjh8ygABPDQ"]
[Tue Jul 21 08:47:41.903481 2026] [security2:error] [pid 514479:tid 514664] [client 39.97.110.217:46628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9cXfzqsQqnLoCgUjh8ygABPDQ"]
[Tue Jul 21 08:47:42.163945 2026] [security2:error] [pid 514479:tid 514632] [client 20.151.10.161:28534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/k4.php"] [unique_id "al9cXvzqsQqnLoCgUjh8zAAAARw"]
[Tue Jul 21 08:47:42.445667 2026] [core:error] [pid 514479:tid 514722] [client 198.235.24.74:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:47:42.445698 2026] [core:error] [pid 514479:tid 514722] [client 198.235.24.74:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:47:42.473969 2026] [security2:error] [pid 511108:tid 511348] [client 203.25.124.36:45463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/customize/index.php"] [unique_id "al9cXoTd5soprXwxAH0WVgAAAG4"]
[Tue Jul 21 08:47:42.487249 2026] [security2:error] [pid 511108:tid 511260] [client 47.128.114.249:15712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "distribuidorasja.com.br"] [uri "/robots.txt"] [unique_id "al9cXoTd5soprXwxAH0WVwAAABY"]
[Tue Jul 21 08:47:42.734083 2026] [security2:error] [pid 514479:tid 514651] [client 20.151.10.161:28494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/k5.php"] [unique_id "al9cXvzqsQqnLoCgUjh82gAAAS8"]
[Tue Jul 21 08:47:42.773501 2026] [security2:error] [pid 514479:tid 514644] [client 203.25.124.210:65049] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/maint/css/index.php"] [unique_id "al9cXvzqsQqnLoCgUjh82wAAASg"]
[Tue Jul 21 08:47:42.785015 2026] [security2:error] [pid 511108:tid 511173] [remote 84.247.172.23:49072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9cXoTd5soprXwxAH0WXAAABEA"]
[Tue Jul 21 08:47:42.944246 2026] [security2:error] [pid 514479:tid 514673] [client 203.25.124.36:64331] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/admin/function.php"] [unique_id "al9cXvzqsQqnLoCgUjh84AAAAUU"]
[Tue Jul 21 08:47:43.091156 2026] [security2:error] [pid 514479:tid 514741] [client 173.252.95.20:49330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cX_zqsQqnLoCgUjh85QAAAYk"]
[Tue Jul 21 08:47:43.210113 2026] [security2:error] [pid 514479:tid 514669] [client 49.144.66.253:30047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cX_zqsQqnLoCgUjh86QAAAUE"]
[Tue Jul 21 08:47:43.210235 2026] [security2:error] [pid 514479:tid 514669] [client 49.144.66.253:30047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cX_zqsQqnLoCgUjh86QAAAUE"]
[Tue Jul 21 08:47:43.287743 2026] [security2:error] [pid 514479:tid 514641] [client 20.151.10.161:28236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/w.php"] [unique_id "al9cX_zqsQqnLoCgUjh87gAAASU"]
[Tue Jul 21 08:47:43.631003 2026] [security2:error] [pid 511108:tid 511289] [client 173.252.95.16:32846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cX4Td5soprXwxAH0WZQAAADM"]
[Tue Jul 21 08:47:43.645794 2026] [security2:error] [pid 511108:tid 511303] [client 20.151.10.161:28519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/fpwch.php"] [unique_id "al9cX4Td5soprXwxAH0WZwAAAEE"]
[Tue Jul 21 08:47:43.661345 2026] [security2:error] [pid 511108:tid 511287] [client 212.32.76.13:25849] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css/colors/admin.php"] [unique_id "al9cX4Td5soprXwxAH0WaAAAADE"]
[Tue Jul 21 08:47:43.724072 2026] [security2:error] [pid 514479:tid 514678] [client 69.171.230.2:57700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cX_zqsQqnLoCgUjh8_gAAAUo"]
[Tue Jul 21 08:47:43.770141 2026] [security2:error] [pid 511108:tid 511177] [remote 54.39.203.183:22176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "runnezy.com.br"] [uri "/robots.txt"] [unique_id "al9cX4Td5soprXwxAH0WagAAPUQ"]
[Tue Jul 21 08:47:43.770375 2026] [security2:error] [pid 511108:tid 511299] [client 54.39.203.183:22176] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "runnezy.com.br"] [uri "/robots.txt"] [unique_id "al9cX4Td5soprXwxAH0WagAAPUQ"]
[Tue Jul 21 08:47:43.771154 2026] [security2:error] [pid 514479:tid 514721] [client 173.252.95.1:36282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cX_zqsQqnLoCgUjh8_wAAAXU"]
[Tue Jul 21 08:47:43.775906 2026] [security2:error] [pid 511108:tid 511339] [client 203.25.124.183:27131] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/pattern/index.php"] [unique_id "al9cX4Td5soprXwxAH0WawAAAGU"]
[Tue Jul 21 08:47:44.032100 2026] [security2:error] [pid 514479:tid 514670] [client 20.151.10.161:28524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/w2025.php"] [unique_id "al9cYPzqsQqnLoCgUjh9CAAAAUI"]
[Tue Jul 21 08:47:44.117301 2026] [security2:error] [pid 514479:tid 514622] [client 65.21.113.253:59818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cX_zqsQqnLoCgUjh8-AAAARI"]
[Tue Jul 21 08:47:44.152957 2026] [security2:error] [pid 514479:tid 514679] [client 203.25.124.70:50061] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/config.php"] [unique_id "al9cYPzqsQqnLoCgUjh9DAAAAUs"]
[Tue Jul 21 08:47:44.425840 2026] [security2:error] [pid 514479:tid 514726] [client 69.171.230.2:57712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cYPzqsQqnLoCgUjh9EgAAAXo"]
[Tue Jul 21 08:47:44.427084 2026] [security2:error] [pid 514479:tid 514539] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cYPzqsQqnLoCgUjh9EwABTjc"]
[Tue Jul 21 08:47:44.427294 2026] [security2:error] [pid 514479:tid 514682] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cYPzqsQqnLoCgUjh9EwABTjc"]
[Tue Jul 21 08:47:44.546448 2026] [security2:error] [pid 514479:tid 514663] [client 5.31.193.106:30004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cYPzqsQqnLoCgUjh9FgAAATs"]
[Tue Jul 21 08:47:44.546577 2026] [security2:error] [pid 514479:tid 514663] [client 5.31.193.106:30004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cYPzqsQqnLoCgUjh9FgAAATs"]
[Tue Jul 21 08:47:44.627282 2026] [security2:error] [pid 514479:tid 514635] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cYPzqsQqnLoCgUjh9FAABHww"]
[Tue Jul 21 08:47:44.644646 2026] [security2:error] [pid 514479:tid 514660] [client 20.151.10.161:28578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/scxy.php"] [unique_id "al9cYPzqsQqnLoCgUjh9GgAAATg"]
[Tue Jul 21 08:47:44.649741 2026] [security2:error] [pid 514479:tid 514732] [client 213.152.162.15:50248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cYPzqsQqnLoCgUjh9GwAAAYA"]
[Tue Jul 21 08:47:44.649845 2026] [security2:error] [pid 514479:tid 514732] [client 213.152.162.15:50248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cYPzqsQqnLoCgUjh9GwAAAYA"]
[Tue Jul 21 08:47:44.954488 2026] [security2:error] [pid 514479:tid 514619] [client 212.32.76.7:42401] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/images/wp-conflg.php"] [unique_id "al9cYPzqsQqnLoCgUjh9HQAAAQ8"]
[Tue Jul 21 08:47:45.076018 2026] [security2:error] [pid 514479:tid 514710] [client 203.25.124.7:24963] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/upgrade-temp-backup/chosen.php"] [unique_id "al9cYfzqsQqnLoCgUjh9JQAAAWo"]
[Tue Jul 21 08:47:45.090729 2026] [security2:error] [pid 514479:tid 514605] [remote 130.185.118.215:42356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9cYfzqsQqnLoCgUjh9JgABEXg"]
[Tue Jul 21 08:47:45.243160 2026] [security2:error] [pid 514479:tid 514738] [client 20.151.10.161:28482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/FWAZ.php"] [unique_id "al9cYfzqsQqnLoCgUjh9JwAAAYY"]
[Tue Jul 21 08:47:45.286509 2026] [security2:error] [pid 514479:tid 514572] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cYfzqsQqnLoCgUjh9KAABJVc"]
[Tue Jul 21 08:47:45.286748 2026] [security2:error] [pid 514479:tid 514641] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cYfzqsQqnLoCgUjh9KAABJVc"]
[Tue Jul 21 08:47:45.323361 2026] [security2:error] [pid 514479:tid 514505] [remote 148.113.128.81:54944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "runnezy.com.br"] [uri "/"] [unique_id "al9cYfzqsQqnLoCgUjh9KgABHRU"]
[Tue Jul 21 08:47:45.323537 2026] [security2:error] [pid 514479:tid 514633] [client 148.113.128.81:54944] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "runnezy.com.br"] [uri "/"] [unique_id "al9cYfzqsQqnLoCgUjh9KgABHRU"]
[Tue Jul 21 08:47:45.420690 2026] [security2:error] [pid 514479:tid 514628] [client 168.167.81.163:61387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cYfzqsQqnLoCgUjh9KwAAARg"]
[Tue Jul 21 08:47:45.420800 2026] [security2:error] [pid 514479:tid 514628] [client 168.167.81.163:61387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cYfzqsQqnLoCgUjh9KwAAARg"]
[Tue Jul 21 08:47:45.534488 2026] [security2:error] [pid 514479:tid 514702] [client 20.226.60.151:57620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9cYfzqsQqnLoCgUjh9LAAAAWI"]
[Tue Jul 21 08:47:45.550124 2026] [security2:error] [pid 511108:tid 511272] [client 203.25.124.73:29083] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/m.php"] [unique_id "al9cYYTd5soprXwxAH0WgQAAACI"]
[Tue Jul 21 08:47:45.848256 2026] [security2:error] [pid 514479:tid 514634] [client 152.59.181.104:63112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cYfzqsQqnLoCgUjh9MwAAAR4"]
[Tue Jul 21 08:47:45.848354 2026] [security2:error] [pid 514479:tid 514634] [client 152.59.181.104:63112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cYfzqsQqnLoCgUjh9MwAAAR4"]
[Tue Jul 21 08:47:46.000534 2026] [autoindex:error] [pid 511108:tid 511283] [client 67.205.140.53:56556] AH01276: Cannot serve directory /home1/ogcsol05/sideli.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:47:46.117103 2026] [security2:error] [pid 514479:tid 514559] [remote 81.173.115.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iducali.com.br"] [uri "/wp-login.php"] [unique_id "al9cYvzqsQqnLoCgUjh9NwABc0o"]
[Tue Jul 21 08:47:46.179188 2026] [security2:error] [pid 514479:tid 514522] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cYvzqsQqnLoCgUjh9OwABNCY"]
[Tue Jul 21 08:47:46.179336 2026] [security2:error] [pid 514479:tid 514656] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cYvzqsQqnLoCgUjh9OwABNCY"]
[Tue Jul 21 08:47:46.263443 2026] [security2:error] [pid 511108:tid 511271] [client 203.25.124.73:56257] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Text/chosen.php"] [unique_id "al9cYoTd5soprXwxAH0WkgAAACE"]
[Tue Jul 21 08:47:46.488263 2026] [security2:error] [pid 511108:tid 511273] [client 20.151.10.161:62345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/177.php"] [unique_id "al9cYoTd5soprXwxAH0WlAAAACM"]
[Tue Jul 21 08:47:46.503663 2026] [security2:error] [pid 511108:tid 511365] [client 69.171.230.27:60714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cYoTd5soprXwxAH0WlQAAAH8"]
[Tue Jul 21 08:47:46.533062 2026] [security2:error] [pid 514479:tid 514683] [client 20.226.60.151:57556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9cYvzqsQqnLoCgUjh9PAAAAU8"]
[Tue Jul 21 08:47:46.577712 2026] [security2:error] [pid 511108:tid 511351] [client 203.25.124.200:45595] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/elementor/includes/template-library/classes/view.php"] [unique_id "al9cYoTd5soprXwxAH0WlwAAAHE"]
[Tue Jul 21 08:47:46.657460 2026] [security2:error] [pid 514479:tid 514647] [client 20.151.10.161:28250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/qterm.php"] [unique_id "al9cYvzqsQqnLoCgUjh9QQAAASs"]
[Tue Jul 21 08:47:46.743206 2026] [security2:error] [pid 514479:tid 514708] [client 203.25.124.2:50301] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/languages/"] [unique_id "al9cYvzqsQqnLoCgUjh9RgAAAWg"]
[Tue Jul 21 08:47:47.178417 2026] [security2:error] [pid 514479:tid 514693] [client 20.151.10.161:28242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/blurbs.php"] [unique_id "al9cY_zqsQqnLoCgUjh9VAAAAVk"]
[Tue Jul 21 08:47:47.475682 2026] [security2:error] [pid 511108:tid 511260] [client 5.38.115.39:28791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cY4Td5soprXwxAH0WpwAAABY"]
[Tue Jul 21 08:47:47.475800 2026] [security2:error] [pid 511108:tid 511260] [client 5.38.115.39:28791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cY4Td5soprXwxAH0WpwAAABY"]
[Tue Jul 21 08:47:47.487045 2026] [security2:error] [pid 514479:tid 514723] [client 203.25.124.35:54325] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/chosen.php"] [unique_id "al9cY_zqsQqnLoCgUjh9cwAAAXc"]
[Tue Jul 21 08:47:47.539707 2026] [security2:error] [pid 511108:tid 511300] [client 114.198.138.124:58900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cY4Td5soprXwxAH0WqAAAAD4"]
[Tue Jul 21 08:47:47.539902 2026] [security2:error] [pid 511108:tid 511300] [client 114.198.138.124:58900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cY4Td5soprXwxAH0WqAAAAD4"]
[Tue Jul 21 08:47:47.640005 2026] [security2:error] [pid 511108:tid 511287] [client 20.151.10.161:28563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/v543.php"] [unique_id "al9cY4Td5soprXwxAH0WqgAAADE"]
[Tue Jul 21 08:47:47.800872 2026] [security2:error] [pid 514479:tid 514657] [client 65.21.113.253:59818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cY_zqsQqnLoCgUjh9VgAAATU"]
[Tue Jul 21 08:47:48.003941 2026] [security2:error] [pid 514479:tid 514629] [client 20.197.195.24:17783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/themes.php"] [unique_id "al9cZPzqsQqnLoCgUjh9fAAAARk"]
[Tue Jul 21 08:47:48.043265 2026] [security2:error] [pid 514479:tid 514691] [client 203.25.124.53:39213] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/about.php"] [unique_id "al9cZPzqsQqnLoCgUjh9fQAAAVc"]
[Tue Jul 21 08:47:48.297190 2026] [security2:error] [pid 514479:tid 514634] [client 202.179.75.202:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cZPzqsQqnLoCgUjh9ggAAAR4"]
[Tue Jul 21 08:47:48.297310 2026] [security2:error] [pid 514479:tid 514634] [client 202.179.75.202:59768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cZPzqsQqnLoCgUjh9ggAAAR4"]
[Tue Jul 21 08:47:48.338701 2026] [security2:error] [pid 514479:tid 514717] [client 20.151.10.161:28525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/w3lls.php"] [unique_id "al9cZPzqsQqnLoCgUjh9gwAAAXE"]
[Tue Jul 21 08:47:48.360678 2026] [security2:error] [pid 514479:tid 514686] [client 20.226.60.151:57536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/xyn.php"] [unique_id "al9cZPzqsQqnLoCgUjh9hAAAAVI"]
[Tue Jul 21 08:47:48.843167 2026] [security2:error] [pid 511108:tid 511316] [client 59.95.197.55:63279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cZITd5soprXwxAH0WuAAAAE4"]
[Tue Jul 21 08:47:48.843355 2026] [security2:error] [pid 511108:tid 511316] [client 59.95.197.55:63279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cZITd5soprXwxAH0WuAAAAE4"]
[Tue Jul 21 08:47:49.066722 2026] [security2:error] [pid 514479:tid 514732] [client 203.25.124.246:29221] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/network/theme-install-function.php"] [unique_id "al9cZfzqsQqnLoCgUjh9jQAAAYA"]
[Tue Jul 21 08:47:49.124455 2026] [security2:error] [pid 514479:tid 514618] [client 20.151.10.161:28523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-ws68.php"] [unique_id "al9cZfzqsQqnLoCgUjh9jgAAAQ4"]
[Tue Jul 21 08:47:49.185988 2026] [security2:error] [pid 514479:tid 514491] [remote 149.102.245.142:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "climadek.com.br"] [uri "/"] [unique_id "al9cZfzqsQqnLoCgUjh9jwABeQc"]
[Tue Jul 21 08:47:49.391190 2026] [security2:error] [pid 514479:tid 514673] [client 122.176.100.127:65074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cZfzqsQqnLoCgUjh9lwAAAUU"]
[Tue Jul 21 08:47:49.393097 2026] [security2:error] [pid 514479:tid 514673] [client 122.176.100.127:65074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cZfzqsQqnLoCgUjh9lwAAAUU"]
[Tue Jul 21 08:47:49.401895 2026] [security2:error] [pid 514479:tid 514663] [client 103.59.206.240:31364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cZfzqsQqnLoCgUjh9mAAAATs"]
[Tue Jul 21 08:47:49.402039 2026] [security2:error] [pid 514479:tid 514663] [client 103.59.206.240:31364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cZfzqsQqnLoCgUjh9mAAAATs"]
[Tue Jul 21 08:47:49.435590 2026] [security2:error] [pid 511108:tid 511251] [client 203.25.124.36:63125] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/packed.php"] [unique_id "al9cZYTd5soprXwxAH0WxAAAAA0"]
[Tue Jul 21 08:47:49.756507 2026] [security2:error] [pid 514479:tid 514678] [client 203.25.124.68:30595] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/system.php"] [unique_id "al9cZfzqsQqnLoCgUjh9mwAAAUo"]
[Tue Jul 21 08:47:49.768669 2026] [security2:error] [pid 511108:tid 511247] [client 20.151.10.161:28071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/xyn.php"] [unique_id "al9cZYTd5soprXwxAH0WzgAAAAk"]
[Tue Jul 21 08:47:49.852934 2026] [security2:error] [pid 514479:tid 514693] [client 195.49.128.211:51805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cZfzqsQqnLoCgUjh9nAAAAVk"]
[Tue Jul 21 08:47:49.853090 2026] [security2:error] [pid 514479:tid 514693] [client 195.49.128.211:51805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cZfzqsQqnLoCgUjh9nAAAAVk"]
[Tue Jul 21 08:47:49.934035 2026] [security2:error] [pid 511108:tid 511139] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cZYTd5soprXwxAH0WzwAAZB4"]
[Tue Jul 21 08:47:49.934178 2026] [security2:error] [pid 511108:tid 511338] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cZYTd5soprXwxAH0WzwAAZB4"]
[Tue Jul 21 08:47:50.061939 2026] [security2:error] [pid 511108:tid 511352] [client 20.197.195.24:48928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/.well-known/about.php"] [unique_id "al9cZoTd5soprXwxAH0W1AAAAHI"]
[Tue Jul 21 08:47:50.174857 2026] [security2:error] [pid 511108:tid 511172] [remote 149.102.245.142:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "climadek.com.br"] [uri "/"] [unique_id "al9cZoTd5soprXwxAH0W1wAAKD8"]
[Tue Jul 21 08:47:50.275930 2026] [security2:error] [pid 514479:tid 514624] [client 203.25.124.190:52173] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/shadow-bot.php"] [unique_id "al9cZvzqsQqnLoCgUjh9owAAARQ"]
[Tue Jul 21 08:47:50.354848 2026] [security2:error] [pid 511108:tid 511296] [client 195.206.105.227:50070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9cZoTd5soprXwxAH0W3gAAADo"]
[Tue Jul 21 08:47:50.355006 2026] [security2:error] [pid 511108:tid 511296] [client 195.206.105.227:50070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9cZoTd5soprXwxAH0W3gAAADo"]
[Tue Jul 21 08:47:50.442640 2026] [security2:error] [pid 511108:tid 511326] [client 113.22.144.139:63768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cZoTd5soprXwxAH0W4AAAAFg"]
[Tue Jul 21 08:47:50.442760 2026] [security2:error] [pid 511108:tid 511326] [client 113.22.144.139:63768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cZoTd5soprXwxAH0W4AAAAFg"]
[Tue Jul 21 08:47:50.627482 2026] [security2:error] [pid 514479:tid 514679] [client 20.226.60.151:57625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/patie.php"] [unique_id "al9cZvzqsQqnLoCgUjh9pgAAAUs"]
[Tue Jul 21 08:47:50.745194 2026] [security2:error] [pid 511108:tid 511329] [client 203.25.124.2:60529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwentyfive/"] [unique_id "al9cZoTd5soprXwxAH0W5QAAAFs"]
[Tue Jul 21 08:47:50.869192 2026] [security2:error] [pid 514479:tid 514665] [client 203.25.124.70:63819] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/PHPMailer/wp-conflg.php"] [unique_id "al9cZvzqsQqnLoCgUjh9qQAAAT0"]
[Tue Jul 21 08:47:51.001551 2026] [security2:error] [pid 514479:tid 514484] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cZ_zqsQqnLoCgUjh9qgABEAA"]
[Tue Jul 21 08:47:51.001709 2026] [security2:error] [pid 514479:tid 514620] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cZ_zqsQqnLoCgUjh9qgABEAA"]
[Tue Jul 21 08:47:51.120036 2026] [security2:error] [pid 511108:tid 511261] [client 20.151.10.161:28522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/green3.php"] [unique_id "al9cZ4Td5soprXwxAH0W7gAAABc"]
[Tue Jul 21 08:47:51.373035 2026] [security2:error] [pid 514479:tid 514686] [client 212.32.76.58:58831] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/shadow-bot.php"] [unique_id "al9cZ_zqsQqnLoCgUjh9sAAAAVI"]
[Tue Jul 21 08:47:51.445971 2026] [security2:error] [pid 514479:tid 514726] [client 20.197.195.24:17752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9cZ_zqsQqnLoCgUjh9sgAAAXo"]
[Tue Jul 21 08:47:51.484060 2026] [security2:error] [pid 511108:tid 511242] [client 41.89.234.2:50169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cZ4Td5soprXwxAH0W9wAAAAQ"]
[Tue Jul 21 08:47:51.484200 2026] [security2:error] [pid 511108:tid 511242] [client 41.89.234.2:50169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cZ4Td5soprXwxAH0W9wAAAAQ"]
[Tue Jul 21 08:47:51.744329 2026] [security2:error] [pid 514479:tid 514708] [client 203.25.124.61:61989] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/enhanced-text-widget/analyst/src/403x.php"] [unique_id "al9cZ_zqsQqnLoCgUjh9tgAAAWg"]
[Tue Jul 21 08:47:51.836324 2026] [security2:error] [pid 511108:tid 511322] [client 20.151.10.161:4877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.benti.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9cZ4Td5soprXwxAH0W-gAAAFQ"]
[Tue Jul 21 08:47:51.868290 2026] [security2:error] [pid 511108:tid 511257] [client 203.25.124.2:20933] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/news-portal/wp-admins.php"] [unique_id "al9cZ4Td5soprXwxAH0W_QAAABM"]
[Tue Jul 21 08:47:52.051352 2026] [security2:error] [pid 514479:tid 514558] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9caPzqsQqnLoCgUjh9vwABZ0k"]
[Tue Jul 21 08:47:52.051475 2026] [security2:error] [pid 514479:tid 514707] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9caPzqsQqnLoCgUjh9vwABZ0k"]
[Tue Jul 21 08:47:52.068899 2026] [security2:error] [pid 514479:tid 514688] [client 65.21.113.253:59818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cZ_zqsQqnLoCgUjh9tAAAAVQ"]
[Tue Jul 21 08:47:52.114132 2026] [security2:error] [pid 514479:tid 514713] [client 20.151.10.161:4894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.benti.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9caPzqsQqnLoCgUjh9wAAAAW0"]
[Tue Jul 21 08:47:52.157588 2026] [security2:error] [pid 514479:tid 514710] [client 20.151.10.161:28566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ccs.php"] [unique_id "al9caPzqsQqnLoCgUjh9wgAAAWo"]
[Tue Jul 21 08:47:52.199630 2026] [security2:error] [pid 514479:tid 514689] [client 20.197.195.24:2778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/wefile.php"] [unique_id "al9caPzqsQqnLoCgUjh9wwAAAVU"]
[Tue Jul 21 08:47:52.206584 2026] [security2:error] [pid 514479:tid 514619] [client 20.226.60.151:57639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/aa.php"] [unique_id "al9caPzqsQqnLoCgUjh9xAAAAQ8"]
[Tue Jul 21 08:47:52.390160 2026] [security2:error] [pid 511108:tid 511258] [client 20.151.10.161:4914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.benti.com.br"] [uri "/images.php"] [unique_id "al9caITd5soprXwxAH0XBwAAABQ"]
[Tue Jul 21 08:47:52.457152 2026] [security2:error] [pid 514479:tid 514633] [client 20.104.96.117:59649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9caPzqsQqnLoCgUjh9ygAAAR0"]
[Tue Jul 21 08:47:52.566113 2026] [security2:error] [pid 511108:tid 511248] [client 203.25.124.207:48183] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/load.php"] [unique_id "al9caITd5soprXwxAH0XCgAAAAo"]
[Tue Jul 21 08:47:52.683334 2026] [security2:error] [pid 514479:tid 514639] [client 20.151.10.161:4889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.benti.com.br"] [uri "/for.php"] [unique_id "al9caPzqsQqnLoCgUjh9zAAAASM"]
[Tue Jul 21 08:47:52.696223 2026] [security2:error] [pid 511108:tid 511251] [client 198.44.157.34:33676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9caITd5soprXwxAH0XDAAAAA0"]
[Tue Jul 21 08:47:52.696319 2026] [security2:error] [pid 511108:tid 511251] [client 198.44.157.34:33676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9caITd5soprXwxAH0XDAAAAA0"]
[Tue Jul 21 08:47:52.800331 2026] [security2:error] [pid 511108:tid 511268] [client 20.151.10.161:28591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ccc.php"] [unique_id "al9caITd5soprXwxAH0XDgAAAB4"]
[Tue Jul 21 08:47:52.959401 2026] [security2:error] [pid 514479:tid 514648] [client 20.151.10.161:4881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.benti.com.br"] [uri "/2larp.php"] [unique_id "al9caPzqsQqnLoCgUjh90QAAASw"]
[Tue Jul 21 08:47:52.968963 2026] [security2:error] [pid 514479:tid 514670] [client 212.32.76.7:33487] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/images/chosen.php"] [unique_id "al9caPzqsQqnLoCgUjh90gAAAUI"]
[Tue Jul 21 08:47:53.169727 2026] [security2:error] [pid 511108:tid 511131] [remote 185.177.238.46:35976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcsenepol.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9caYTd5soprXwxAH0XFwAAVRY"]
[Tue Jul 21 08:47:53.197414 2026] [security2:error] [pid 514479:tid 514655] [client 20.197.195.24:2774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9cafzqsQqnLoCgUjh91QAAATM"]
[Tue Jul 21 08:47:53.242229 2026] [security2:error] [pid 514479:tid 514640] [client 20.151.10.161:4875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.benti.com.br"] [uri "/adminner.php"] [unique_id "al9cafzqsQqnLoCgUjh91gAAASQ"]
[Tue Jul 21 08:47:53.390928 2026] [security2:error] [pid 514479:tid 514712] [client 20.151.10.161:28535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/get.php"] [unique_id "al9cafzqsQqnLoCgUjh92QAAAWw"]
[Tue Jul 21 08:47:53.395088 2026] [security2:error] [pid 511108:tid 511181] [remote 185.177.238.46:35978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carvalhogrossiimoveis.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9caYTd5soprXwxAH0XGgAAa0g"]
[Tue Jul 21 08:47:53.396926 2026] [security2:error] [pid 514479:tid 514581] [remote 185.177.238.46:35980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ellosemijoias.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9cafzqsQqnLoCgUjh92gABdGA"]
[Tue Jul 21 08:47:53.404968 2026] [security2:error] [pid 514479:tid 514590] [remote 185.177.238.46:35982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "startonesite.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9cafzqsQqnLoCgUjh92wABNWk"]
[Tue Jul 21 08:47:53.523514 2026] [security2:error] [pid 511108:tid 511273] [client 20.151.10.161:4902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.benti.com.br"] [uri "/82.php"] [unique_id "al9caYTd5soprXwxAH0XHgAAACM"]
[Tue Jul 21 08:47:53.560626 2026] [security2:error] [pid 511108:tid 511296] [client 185.177.238.46:46242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcsenepol.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9caYTd5soprXwxAH0XHwAAADo"]
[Tue Jul 21 08:47:53.798997 2026] [security2:error] [pid 511108:tid 511329] [client 20.151.10.161:4864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.benti.com.br"] [uri "/kir.php"] [unique_id "al9caYTd5soprXwxAH0XIgAAAFs"]
[Tue Jul 21 08:47:53.803297 2026] [security2:error] [pid 514479:tid 514717] [client 185.177.238.46:46244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carvalhogrossiimoveis.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9cafzqsQqnLoCgUjh93gAAAXE"]
[Tue Jul 21 08:47:53.804134 2026] [security2:error] [pid 514479:tid 514686] [client 185.177.238.46:46246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ellosemijoias.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9cafzqsQqnLoCgUjh93wAAAVI"]
[Tue Jul 21 08:47:53.805449 2026] [security2:error] [pid 514479:tid 514675] [client 185.177.238.46:46248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "startonesite.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9cafzqsQqnLoCgUjh94AAAAUc"]
[Tue Jul 21 08:47:53.810101 2026] [security2:error] [pid 514479:tid 514595] [remote 57.141.18.31:44188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9cafzqsQqnLoCgUjh94QABfm4"]
[Tue Jul 21 08:47:53.854034 2026] [security2:error] [pid 514479:tid 514643] [client 20.151.10.161:28240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/images.php"] [unique_id "al9cafzqsQqnLoCgUjh95AAAASc"]
[Tue Jul 21 08:47:53.861480 2026] [security2:error] [pid 514479:tid 514726] [client 20.197.195.24:2795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/wp-admin/css/colour.php"] [unique_id "al9cafzqsQqnLoCgUjh95wAAAXo"]
[Tue Jul 21 08:47:53.981935 2026] [core:alert] [pid 514479:tid 514708] [client 57.141.18.118:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:47:54.040902 2026] [security2:error] [pid 511108:tid 511357] [client 49.144.66.253:30504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9caoTd5soprXwxAH0XJwAAAHc"]
[Tue Jul 21 08:47:54.041014 2026] [security2:error] [pid 511108:tid 511357] [client 49.144.66.253:30504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9caoTd5soprXwxAH0XJwAAAHc"]
[Tue Jul 21 08:47:54.071543 2026] [security2:error] [pid 514479:tid 514646] [client 203.25.124.192:50941] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/wp-activate.php"] [unique_id "al9cavzqsQqnLoCgUjh97AAAASo"]
[Tue Jul 21 08:47:54.105305 2026] [security2:error] [pid 511108:tid 511261] [client 20.226.60.151:57657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/xwpg.php"] [unique_id "al9caoTd5soprXwxAH0XKwAAABc"]
[Tue Jul 21 08:47:54.151643 2026] [security2:error] [pid 514479:tid 514667] [client 212.32.76.10:56691] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/user/upgrade/"] [unique_id "al9cavzqsQqnLoCgUjh97gAAAT8"]
[Tue Jul 21 08:47:54.171757 2026] [security2:error] [pid 511108:tid 511260] [client 203.25.124.52:46627] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/css.php"] [unique_id "al9caoTd5soprXwxAH0XLQAAABY"]
[Tue Jul 21 08:47:54.309182 2026] [security2:error] [pid 511108:tid 511292] [client 168.167.81.163:62483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9caoTd5soprXwxAH0XPQAAADY"]
[Tue Jul 21 08:47:54.309392 2026] [security2:error] [pid 511108:tid 511292] [client 168.167.81.163:62483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9caoTd5soprXwxAH0XPQAAADY"]
[Tue Jul 21 08:47:54.373476 2026] [security2:error] [pid 514479:tid 514527] [remote 185.177.238.46:35984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bcsenepol.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9cavzqsQqnLoCgUjh97wABgCs"]
[Tue Jul 21 08:47:54.422341 2026] [security2:error] [pid 514479:tid 514718] [client 20.197.195.24:48973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/8.php"] [unique_id "al9cavzqsQqnLoCgUjh98QAAAXI"]
[Tue Jul 21 08:47:54.447414 2026] [security2:error] [pid 514479:tid 514710] [client 20.151.10.161:28540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/alls.php"] [unique_id "al9cavzqsQqnLoCgUjh98gAAAWo"]
[Tue Jul 21 08:47:54.734745 2026] [security2:error] [pid 511108:tid 511136] [remote 185.177.238.46:35986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.startonesite.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9caoTd5soprXwxAH0XSgAARxs"]
[Tue Jul 21 08:47:54.784268 2026] [security2:error] [pid 514479:tid 514616] [client 20.151.10.161:28559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/yyu.php"] [unique_id "al9cavzqsQqnLoCgUjh99wAAAQw"]
[Tue Jul 21 08:47:54.823278 2026] [security2:error] [pid 514479:tid 514516] [remote 185.177.238.46:35988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carvalhogrossiimoveis.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9cavzqsQqnLoCgUjh9-AABDyA"]
[Tue Jul 21 08:47:54.913662 2026] [security2:error] [pid 511108:tid 511210] [remote 185.177.238.46:35990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ellosemijoias.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9caoTd5soprXwxAH0XTQAAfmU"]
[Tue Jul 21 08:47:54.939538 2026] [security2:error] [pid 511108:tid 511193] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9caoTd5soprXwxAH0XUAAALVQ"]
[Tue Jul 21 08:47:54.939672 2026] [security2:error] [pid 511108:tid 511283] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9caoTd5soprXwxAH0XUAAALVQ"]
[Tue Jul 21 08:47:54.959115 2026] [security2:error] [pid 511108:tid 511149] [remote 185.177.238.46:35992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcsenepol.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9caoTd5soprXwxAH0XUQAAGig"]
[Tue Jul 21 08:47:54.967788 2026] [security2:error] [pid 511108:tid 511291] [client 20.197.195.24:59529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/wp-content/admin.php"] [unique_id "al9caoTd5soprXwxAH0XUgAAADU"]
[Tue Jul 21 08:47:54.976523 2026] [security2:error] [pid 514479:tid 514738] [client 212.32.76.66:58461] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/module.php"] [unique_id "al9cavzqsQqnLoCgUjh9-gAAAYY"]
[Tue Jul 21 08:47:55.001083 2026] [security2:error] [pid 511108:tid 511246] [client 20.220.225.223:43173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9ca4Td5soprXwxAH0XVQAAAAg"]
[Tue Jul 21 08:47:55.097485 2026] [security2:error] [pid 511108:tid 511312] [client 20.197.192.193:9412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/wp-signup.php"] [unique_id "al9ca4Td5soprXwxAH0XVgAAAEo"]
[Tue Jul 21 08:47:55.108114 2026] [security2:error] [pid 514479:tid 514653] [client 20.197.195.24:17750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/f6.php"] [unique_id "al9ca_zqsQqnLoCgUjh9_QAAATE"]
[Tue Jul 21 08:47:55.174826 2026] [security2:error] [pid 514479:tid 514734] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ca_zqsQqnLoCgUjh9_AABgi4"]
[Tue Jul 21 08:47:55.184868 2026] [security2:error] [pid 511108:tid 511360] [client 20.197.195.24:2772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/inputs.php"] [unique_id "al9ca4Td5soprXwxAH0XWQAAAHo"]
[Tue Jul 21 08:47:55.222359 2026] [security2:error] [pid 514479:tid 514668] [client 20.197.195.24:17748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/inputs.php"] [unique_id "al9ca_zqsQqnLoCgUjh9_wAAAUA"]
[Tue Jul 21 08:47:55.247835 2026] [security2:error] [pid 514479:tid 514632] [client 20.151.10.161:28262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/by.php"] [unique_id "al9ca_zqsQqnLoCgUjh-AAAAARw"]
[Tue Jul 21 08:47:55.255657 2026] [security2:error] [pid 514479:tid 514702] [client 20.197.195.24:48925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/classwithtostring.php"] [unique_id "al9ca_zqsQqnLoCgUjh-AQAAAWI"]
[Tue Jul 21 08:47:55.264503 2026] [security2:error] [pid 511108:tid 511298] [client 203.25.124.69:47487] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "al9ca4Td5soprXwxAH0XWwAAADw"]
[Tue Jul 21 08:47:55.350034 2026] [security2:error] [pid 514479:tid 514627] [client 185.177.238.46:46260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bcsenepol.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9ca_zqsQqnLoCgUjh-AgAAARc"]
[Tue Jul 21 08:47:55.362265 2026] [security2:error] [pid 511108:tid 511196] [remote 185.177.238.46:35994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "startonesite.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9ca4Td5soprXwxAH0XXQAAOVc"]
[Tue Jul 21 08:47:55.391771 2026] [security2:error] [pid 514479:tid 514740] [client 20.197.192.193:9429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/csa.php"] [unique_id "al9ca_zqsQqnLoCgUjh-AwAAAYg"]
[Tue Jul 21 08:47:55.414899 2026] [security2:error] [pid 511108:tid 511233] [remote 185.177.238.46:35996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carvalhogrossiimoveis.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9ca4Td5soprXwxAH0XXgAAT3w"]
[Tue Jul 21 08:47:55.500978 2026] [security2:error] [pid 511108:tid 511116] [remote 185.177.238.46:35998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ellosemijoias.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9ca4Td5soprXwxAH0XYgAAUQc"]
[Tue Jul 21 08:47:55.648661 2026] [security2:error] [pid 514479:tid 514736] [client 20.151.10.161:28585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/FAQ.php"] [unique_id "al9ca_zqsQqnLoCgUjh-BgAAAYQ"]
[Tue Jul 21 08:47:55.650803 2026] [security2:error] [pid 514479:tid 514685] [client 20.197.195.24:17848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/wp-content/themes/index.php"] [unique_id "al9ca_zqsQqnLoCgUjh-BwAAAVE"]
[Tue Jul 21 08:47:55.706490 2026] [security2:error] [pid 514479:tid 514641] [client 65.21.113.253:59818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ca_zqsQqnLoCgUjh9_gAAASU"]
[Tue Jul 21 08:47:55.777886 2026] [security2:error] [pid 511108:tid 511167] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9ca4Td5soprXwxAH0XaAAAKDo"]
[Tue Jul 21 08:47:55.778068 2026] [security2:error] [pid 511108:tid 511278] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9ca4Td5soprXwxAH0XaAAAKDo"]
[Tue Jul 21 08:47:55.787827 2026] [security2:error] [pid 514479:tid 514679] [client 185.177.238.46:46264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "startonesite.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9ca_zqsQqnLoCgUjh-CAAAAUs"]
[Tue Jul 21 08:47:55.805341 2026] [security2:error] [pid 511108:tid 511297] [client 185.177.238.46:46266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "carvalhogrossiimoveis.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9ca4Td5soprXwxAH0XaQAAADs"]
[Tue Jul 21 08:47:55.892732 2026] [security2:error] [pid 511108:tid 511281] [client 185.177.238.46:46268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ellosemijoias.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9ca4Td5soprXwxAH0XawAAACs"]
[Tue Jul 21 08:47:55.924031 2026] [security2:error] [pid 511108:tid 511238] [client 20.197.195.24:59898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/wp-blog.php"] [unique_id "al9ca4Td5soprXwxAH0XbAAAAAA"]
[Tue Jul 21 08:47:55.936914 2026] [security2:error] [pid 514479:tid 514536] [remote 185.177.238.46:36000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bcsenepol.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9ca_zqsQqnLoCgUjh-CgABGTQ"]
[Tue Jul 21 08:47:56.005264 2026] [security2:error] [pid 511108:tid 511275] [client 182.189.99.211:47685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ca4Td5soprXwxAH0XagAAACU"]
[Tue Jul 21 08:47:56.005406 2026] [security2:error] [pid 511108:tid 511275] [client 182.189.99.211:47685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ca4Td5soprXwxAH0XagAAACU"]
[Tue Jul 21 08:47:56.159302 2026] [security2:error] [pid 514479:tid 514735] [client 20.226.60.151:57652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ops.php"] [unique_id "al9cbPzqsQqnLoCgUjh-DgAAAYM"]
[Tue Jul 21 08:47:56.173755 2026] [proxy:error] [pid 511108:tid 511197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:47:56.173788 2026] [proxy_http:error] [pid 511108:tid 511197] [remote 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:47:56.174344 2026] [proxy:error] [pid 511108:tid 511197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:47:56.174369 2026] [proxy_http:error] [pid 511108:tid 511197] [remote 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:47:56.233234 2026] [security2:error] [pid 514479:tid 514652] [client 203.25.124.32:36889] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Text/Diff/"] [unique_id "al9cbPzqsQqnLoCgUjh-DwAAATA"]
[Tue Jul 21 08:47:56.245801 2026] [security2:error] [pid 514479:tid 514640] [client 114.119.155.13:44781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cmpartners.com.br"] [uri "/cmpartners.com.br/wp-content/uploads/2021/08/Bitmap.png"] [unique_id "al9cbPzqsQqnLoCgUjh-EAAAASQ"], referer: https://cmpartners.com.br/
[Tue Jul 21 08:47:56.363069 2026] [security2:error] [pid 514479:tid 514725] [client 203.25.124.31:40957] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/advanced-product-fields-for-woocommerce/db.php"] [unique_id "al9cbPzqsQqnLoCgUjh-FAAAAXk"]
[Tue Jul 21 08:47:56.371974 2026] [proxy:error] [pid 511108:tid 511199] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:47:56.372069 2026] [proxy_http:error] [pid 511108:tid 511199] [remote 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:47:56.373360 2026] [proxy:error] [pid 511108:tid 511199] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:47:56.373417 2026] [proxy_http:error] [pid 511108:tid 511199] [remote 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:47:56.375036 2026] [security2:error] [pid 514479:tid 514606] [remote 185.177.238.46:36002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.startonesite.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9cbPzqsQqnLoCgUjh-FQABUHk"]
[Tue Jul 21 08:47:56.390628 2026] [security2:error] [pid 514479:tid 514586] [remote 185.177.238.46:36004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.carvalhogrossiimoveis.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9cbPzqsQqnLoCgUjh-FgABH2U"]
[Tue Jul 21 08:47:56.480138 2026] [security2:error] [pid 514479:tid 514538] [remote 185.177.238.46:36006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.238.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.ellosemijoias.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9cbPzqsQqnLoCgUjh-FwABFTY"]
[Tue Jul 21 08:47:56.523775 2026] [security2:error] [pid 514479:tid 514598] [remote 185.177.238.46:36008] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bcsenepol.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9cbPzqsQqnLoCgUjh-GQABZnE"]
[Tue Jul 21 08:47:56.610628 2026] [security2:error] [pid 514479:tid 514732] [client 20.197.195.24:2792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/wp-content/admin.php"] [unique_id "al9cbPzqsQqnLoCgUjh-GwAAAYA"]
[Tue Jul 21 08:47:56.667627 2026] [security2:error] [pid 511108:tid 511329] [client 152.59.181.104:63603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cbITd5soprXwxAH0XfAAAAFs"]
[Tue Jul 21 08:47:56.667837 2026] [security2:error] [pid 511108:tid 511329] [client 152.59.181.104:63603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cbITd5soprXwxAH0XfAAAAFs"]
[Tue Jul 21 08:47:56.771865 2026] [security2:error] [pid 514479:tid 514492] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cbPzqsQqnLoCgUjh-HwABZwg"]
[Tue Jul 21 08:47:56.771971 2026] [security2:error] [pid 514479:tid 514707] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cbPzqsQqnLoCgUjh-HwABZwg"]
[Tue Jul 21 08:47:56.786204 2026] [security2:error] [pid 514479:tid 514638] [client 20.151.10.161:28544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/coffexium.php"] [unique_id "al9cbPzqsQqnLoCgUjh-IAAAASI"]
[Tue Jul 21 08:47:56.911898 2026] [security2:error] [pid 511108:tid 511257] [client 185.177.238.46:46276] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "bcsenepol.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9cbITd5soprXwxAH0XfwAAABM"]
[Tue Jul 21 08:47:56.960352 2026] [security2:error] [pid 514479:tid 514515] [remote 185.177.238.46:36012] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "startonesite.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9cbPzqsQqnLoCgUjh-IQABfR8"]
[Tue Jul 21 08:47:56.975317 2026] [security2:error] [pid 514479:tid 514594] [remote 185.177.238.46:36014] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "carvalhogrossiimoveis.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9cbPzqsQqnLoCgUjh-IgABEW0"]
[Tue Jul 21 08:47:57.067966 2026] [security2:error] [pid 511108:tid 511185] [remote 185.177.238.46:36016] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "ellosemijoias.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9cbYTd5soprXwxAH0XggAAGEw"]
[Tue Jul 21 08:47:57.087681 2026] [security2:error] [pid 514479:tid 514521] [remote 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cbfzqsQqnLoCgUjh-JQABYSU"]
[Tue Jul 21 08:47:57.173242 2026] [security2:error] [pid 514479:tid 514654] [client 203.25.124.11:34875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "al9cbfzqsQqnLoCgUjh-JwAAATI"]
[Tue Jul 21 08:47:57.350032 2026] [security2:error] [pid 511108:tid 511362] [client 185.177.238.46:46284] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "startonesite.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9cbYTd5soprXwxAH0XiQAAAHw"]
[Tue Jul 21 08:47:57.358228 2026] [security2:error] [pid 511108:tid 511179] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.shopmelhorcompraonline.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9cbYTd5soprXwxAH0XigAAGkY"]
[Tue Jul 21 08:47:57.366565 2026] [security2:error] [pid 514479:tid 514632] [client 185.177.238.46:46286] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "carvalhogrossiimoveis.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9cbfzqsQqnLoCgUjh-KQAAARw"]
[Tue Jul 21 08:47:57.458414 2026] [security2:error] [pid 514479:tid 514627] [client 20.197.195.24:17786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/ms-edit.php"] [unique_id "al9cbfzqsQqnLoCgUjh-KwAAARc"]
[Tue Jul 21 08:47:57.459342 2026] [security2:error] [pid 514479:tid 514664] [client 185.177.238.46:46288] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "ellosemijoias.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9cbfzqsQqnLoCgUjh-LAAAATw"]
[Tue Jul 21 08:47:57.471594 2026] [security2:error] [pid 511108:tid 511246] [client 20.151.10.161:28249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/red.php"] [unique_id "al9cbYTd5soprXwxAH0XjAAAAAg"]
[Tue Jul 21 08:47:57.496501 2026] [security2:error] [pid 514479:tid 514523] [remote 185.177.238.46:36020] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.bcsenepol.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9cbfzqsQqnLoCgUjh-LQABRCc"]
[Tue Jul 21 08:47:57.635759 2026] [security2:error] [pid 514479:tid 514681] [client 212.32.76.5:21521] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/sodium_compat/namespaced/Core/ChaCha20/"] [unique_id "al9cbfzqsQqnLoCgUjh-MwAAAU0"]
[Tue Jul 21 08:47:57.646175 2026] [security2:error] [pid 514479:tid 514561] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.shopmelhorcompraonline.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9cbfzqsQqnLoCgUjh-NAABJUw"]
[Tue Jul 21 08:47:57.670651 2026] [security2:error] [pid 514479:tid 514705] [client 203.25.124.32:55055] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/wp.php"] [unique_id "al9cbfzqsQqnLoCgUjh-NQAAAWU"]
[Tue Jul 21 08:47:57.860085 2026] [security2:error] [pid 511108:tid 511138] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.shopmelhorcompraonline.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9cbYTd5soprXwxAH0XkgAADR0"]
[Tue Jul 21 08:47:57.935081 2026] [security2:error] [pid 514479:tid 514717] [client 20.226.60.151:57633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/mac.php"] [unique_id "al9cbfzqsQqnLoCgUjh-OAAAAXE"]
[Tue Jul 21 08:47:57.938018 2026] [security2:error] [pid 514479:tid 514546] [remote 185.177.238.46:36022] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.startonesite.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9cbfzqsQqnLoCgUjh-OQABfD4"]
[Tue Jul 21 08:47:57.950560 2026] [security2:error] [pid 514479:tid 514576] [remote 185.177.238.46:36024] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.carvalhogrossiimoveis.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9cbfzqsQqnLoCgUjh-OgABCls"]
[Tue Jul 21 08:47:58.045448 2026] [security2:error] [pid 514479:tid 514541] [remote 185.177.238.46:36026] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "www.ellosemijoias.com.br"] [uri "/wp-content/plugins/super-forms/readme.txt"] [unique_id "al9cbvzqsQqnLoCgUjh-PAABWDk"]
[Tue Jul 21 08:47:58.064407 2026] [security2:error] [pid 514479:tid 514731] [client 114.198.138.124:59467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cbvzqsQqnLoCgUjh-PQAAAX8"]
[Tue Jul 21 08:47:58.064477 2026] [security2:error] [pid 514479:tid 514731] [client 114.198.138.124:59467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cbvzqsQqnLoCgUjh-PQAAAX8"]
[Tue Jul 21 08:47:58.141405 2026] [security2:error] [pid 511108:tid 511293] [client 5.38.115.39:62466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cboTd5soprXwxAH0XmQAAADc"]
[Tue Jul 21 08:47:58.141589 2026] [security2:error] [pid 511108:tid 511293] [client 5.38.115.39:62466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cboTd5soprXwxAH0XmQAAADc"]
[Tue Jul 21 08:47:58.143256 2026] [security2:error] [pid 514479:tid 514494] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.shopmelhorcompraonline.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9cbvzqsQqnLoCgUjh-PgABTwo"]
[Tue Jul 21 08:47:58.476584 2026] [security2:error] [pid 511108:tid 511325] [client 203.25.124.11:27513] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/system.php"] [unique_id "al9cboTd5soprXwxAH0XnQAAAFc"]
[Tue Jul 21 08:47:58.526720 2026] [security2:error] [pid 511108:tid 511212] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.shopmelhorcompraonline.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9cboTd5soprXwxAH0XngAAAWc"]
[Tue Jul 21 08:47:58.537604 2026] [security2:error] [pid 514479:tid 514667] [client 203.25.124.211:24673] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/we.php"] [unique_id "al9cbvzqsQqnLoCgUjh-RQAAAT8"]
[Tue Jul 21 08:47:58.573348 2026] [security2:error] [pid 511108:tid 511133] [remote 198.244.168.106:33768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "valorizeadistribuidora.com.br"] [uri "/robots.txt"] [unique_id "al9cboTd5soprXwxAH0XnwAAXhg"]
[Tue Jul 21 08:47:58.573465 2026] [security2:error] [pid 511108:tid 511332] [client 198.244.168.106:33768] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "valorizeadistribuidora.com.br"] [uri "/robots.txt"] [unique_id "al9cboTd5soprXwxAH0XnwAAXhg"]
[Tue Jul 21 08:47:58.742697 2026] [security2:error] [pid 514479:tid 514673] [client 195.206.105.227:56380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9cbvzqsQqnLoCgUjh-SwAAAUU"]
[Tue Jul 21 08:47:58.742793 2026] [security2:error] [pid 514479:tid 514673] [client 195.206.105.227:56380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9cbvzqsQqnLoCgUjh-SwAAAUU"]
[Tue Jul 21 08:47:58.861050 2026] [security2:error] [pid 514479:tid 514631] [client 20.226.60.151:57586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/mg.php"] [unique_id "al9cbvzqsQqnLoCgUjh-TwAAARs"]
[Tue Jul 21 08:47:58.885334 2026] [security2:error] [pid 514479:tid 514540] [remote 51.161.65.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "garagemdoluidi.com.br"] [uri "/category/furniture/"] [unique_id "al9cbvzqsQqnLoCgUjh-UAABOzg"]
[Tue Jul 21 08:47:58.885538 2026] [security2:error] [pid 514479:tid 514663] [client 51.161.65.251:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "garagemdoluidi.com.br"] [uri "/category/furniture/"] [unique_id "al9cbvzqsQqnLoCgUjh-UAABOzg"]
[Tue Jul 21 08:47:58.918752 2026] [security2:error] [pid 514479:tid 514560] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.shopmelhorcompraonline.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9cbvzqsQqnLoCgUjh-UgABDEs"]
[Tue Jul 21 08:47:58.933133 2026] [security2:error] [pid 514479:tid 514637] [client 20.151.10.161:28575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9cbvzqsQqnLoCgUjh-VAAAASE"]
[Tue Jul 21 08:47:58.958842 2026] [security2:error] [pid 514479:tid 514577] [remote 57.141.18.10:43910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9cbvzqsQqnLoCgUjh-VQABgVw"]
[Tue Jul 21 08:47:58.961384 2026] [security2:error] [pid 514479:tid 514660] [client 212.32.76.9:40615] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9cbvzqsQqnLoCgUjh-VgAAATg"]
[Tue Jul 21 08:47:59.089286 2026] [security2:error] [pid 514479:tid 514713] [client 65.21.113.253:59818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cbvzqsQqnLoCgUjh-SAAAAW0"]
[Tue Jul 21 08:47:59.114423 2026] [security2:error] [pid 514479:tid 514710] [client 202.179.75.202:53956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cb_zqsQqnLoCgUjh-WAAAAWo"]
[Tue Jul 21 08:47:59.114530 2026] [security2:error] [pid 514479:tid 514710] [client 202.179.75.202:53956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cb_zqsQqnLoCgUjh-WAAAAWo"]
[Tue Jul 21 08:47:59.166173 2026] [security2:error] [pid 511108:tid 511211] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.shopmelhorcompraonline.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9cb4Td5soprXwxAH0XqAAACWY"]
[Tue Jul 21 08:47:59.313082 2026] [security2:error] [pid 514479:tid 514639] [client 20.197.195.24:2777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/cgi-bin/index.php"] [unique_id "al9cb_zqsQqnLoCgUjh-XAAAASM"]
[Tue Jul 21 08:47:59.321619 2026] [security2:error] [pid 514479:tid 514718] [client 59.95.197.55:63749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cb_zqsQqnLoCgUjh-XQAAAXI"]
[Tue Jul 21 08:47:59.322356 2026] [security2:error] [pid 514479:tid 514718] [client 59.95.197.55:63749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cb_zqsQqnLoCgUjh-XQAAAXI"]
[Tue Jul 21 08:47:59.438823 2026] [security2:error] [pid 514479:tid 514677] [client 203.25.124.37:62323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/neve/assets/apps/dashboard/build/"] [unique_id "al9cb_zqsQqnLoCgUjh-XgAAAUk"]
[Tue Jul 21 08:47:59.554420 2026] [security2:error] [pid 514479:tid 514531] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.shopmelhorcompraonline.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9cb_zqsQqnLoCgUjh-YAABFC8"]
[Tue Jul 21 08:47:59.670053 2026] [security2:error] [pid 514479:tid 514670] [client 203.25.124.192:54343] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/wp-links-opml.php"] [unique_id "al9cb_zqsQqnLoCgUjh-YwAAAUI"]
[Tue Jul 21 08:47:59.765791 2026] [security2:error] [pid 511108:tid 511158] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.shopmelhorcompraonline.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9cb4Td5soprXwxAH0XswAADzE"]
[Tue Jul 21 08:47:59.882575 2026] [security2:error] [pid 514479:tid 514668] [client 122.176.100.127:49179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cb_zqsQqnLoCgUjh-ZgAAAUA"]
[Tue Jul 21 08:47:59.882759 2026] [security2:error] [pid 514479:tid 514668] [client 122.176.100.127:49179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cb_zqsQqnLoCgUjh-ZgAAAUA"]
[Tue Jul 21 08:48:00.025784 2026] [security2:error] [pid 514479:tid 514545] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.shopmelhorcompraonline.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9ccPzqsQqnLoCgUjh-aQABhD0"]
[Tue Jul 21 08:48:00.063258 2026] [security2:error] [pid 514479:tid 514628] [client 203.25.124.43:50021] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9ccPzqsQqnLoCgUjh-agAAARg"]
[Tue Jul 21 08:48:00.074914 2026] [security2:error] [pid 514479:tid 514722] [client 20.151.10.161:28270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/footer.php"] [unique_id "al9ccPzqsQqnLoCgUjh-awAAAXY"]
[Tue Jul 21 08:48:00.282334 2026] [security2:error] [pid 511108:tid 511234] [remote 54.39.136.167:60008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "valorizeadistribuidora.com.br"] [uri "/"] [unique_id "al9ccITd5soprXwxAH0XvgAAKX0"]
[Tue Jul 21 08:48:00.282540 2026] [security2:error] [pid 511108:tid 511279] [client 54.39.136.167:60008] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "valorizeadistribuidora.com.br"] [uri "/"] [unique_id "al9ccITd5soprXwxAH0XvgAAKX0"]
[Tue Jul 21 08:48:00.297538 2026] [security2:error] [pid 511108:tid 511166] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.shopmelhorcompraonline.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9ccITd5soprXwxAH0XvwAABDk"]
[Tue Jul 21 08:48:00.406746 2026] [security2:error] [pid 514479:tid 514728] [client 20.197.195.24:17821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/BDKR28WP.php"] [unique_id "al9ccPzqsQqnLoCgUjh-bwAAAXw"]
[Tue Jul 21 08:48:00.418277 2026] [security2:error] [pid 514479:tid 514614] [client 20.226.60.151:57540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-post-data.php"] [unique_id "al9ccPzqsQqnLoCgUjh-cQAAAQo"]
[Tue Jul 21 08:48:00.470971 2026] [security2:error] [pid 514479:tid 514723] [client 195.49.128.211:52410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ccPzqsQqnLoCgUjh-cgAAAXc"]
[Tue Jul 21 08:48:00.471146 2026] [security2:error] [pid 514479:tid 514723] [client 195.49.128.211:52410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ccPzqsQqnLoCgUjh-cgAAAXc"]
[Tue Jul 21 08:48:00.627676 2026] [security2:error] [pid 514479:tid 514611] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.shopmelhorcompraonline.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9ccPzqsQqnLoCgUjh-cwABKH4"]
[Tue Jul 21 08:48:00.650733 2026] [security2:error] [pid 514479:tid 514643] [client 203.25.124.47:37227] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/css/dist/"] [unique_id "al9ccPzqsQqnLoCgUjh-dAAAASc"]
[Tue Jul 21 08:48:00.777067 2026] [security2:error] [pid 514479:tid 514647] [client 203.25.124.11:36415] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/ms-files.php"] [unique_id "al9ccPzqsQqnLoCgUjh-dgAAASs"]
[Tue Jul 21 08:48:00.829330 2026] [security2:error] [pid 511108:tid 511266] [client 20.151.10.161:28580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-content/index.php"] [unique_id "al9ccITd5soprXwxAH0XxwAAABw"]
[Tue Jul 21 08:48:00.866037 2026] [security2:error] [pid 514479:tid 514587] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ccPzqsQqnLoCgUjh-egABWGY"]
[Tue Jul 21 08:48:00.866163 2026] [security2:error] [pid 514479:tid 514692] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ccPzqsQqnLoCgUjh-egABWGY"]
[Tue Jul 21 08:48:01.163855 2026] [security2:error] [pid 511108:tid 511282] [client 203.25.124.70:50337] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/Simple.php"] [unique_id "al9ccYTd5soprXwxAH0XzAAAACw"]
[Tue Jul 21 08:48:01.209616 2026] [security2:error] [pid 514479:tid 514605] [remote 51.79.215.219:56046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.215.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-login.php"] [unique_id "al9ccfzqsQqnLoCgUjh-fgABT3g"]
[Tue Jul 21 08:48:01.225690 2026] [security2:error] [pid 511108:tid 511268] [client 20.151.10.161:28231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/zoro.php"] [unique_id "al9ccYTd5soprXwxAH0XzwAAAB4"]
[Tue Jul 21 08:48:01.588663 2026] [security2:error] [pid 514479:tid 514699] [client 113.22.144.139:64321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ccfzqsQqnLoCgUjh-gQAAAV8"]
[Tue Jul 21 08:48:01.589408 2026] [security2:error] [pid 514479:tid 514699] [client 113.22.144.139:64321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ccfzqsQqnLoCgUjh-gQAAAV8"]
[Tue Jul 21 08:48:01.639441 2026] [security2:error] [pid 514479:tid 514631] [client 203.25.124.58:22485] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/media-text/"] [unique_id "al9ccfzqsQqnLoCgUjh-ggAAARs"]
[Tue Jul 21 08:48:01.685390 2026] [security2:error] [pid 511108:tid 511284] [client 20.151.10.161:62406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/199.php"] [unique_id "al9ccYTd5soprXwxAH0X2AAAAC4"]
[Tue Jul 21 08:48:01.922792 2026] [security2:error] [pid 514479:tid 514696] [client 20.151.10.161:28500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/admin.php"] [unique_id "al9ccfzqsQqnLoCgUjh-iQAAAVw"]
[Tue Jul 21 08:48:01.957129 2026] [security2:error] [pid 514479:tid 514710] [client 20.197.195.24:48943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/abcd.php"] [unique_id "al9ccfzqsQqnLoCgUjh-igAAAWo"]
[Tue Jul 21 08:48:01.963129 2026] [security2:error] [pid 511108:tid 511141] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ccYTd5soprXwxAH0X3wAAZCA"]
[Tue Jul 21 08:48:01.963315 2026] [security2:error] [pid 511108:tid 511338] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ccYTd5soprXwxAH0X3wAAZCA"]
[Tue Jul 21 08:48:02.145288 2026] [security2:error] [pid 514479:tid 514676] [client 41.89.234.2:50621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ccvzqsQqnLoCgUjh-jwAAAUg"]
[Tue Jul 21 08:48:02.145426 2026] [security2:error] [pid 514479:tid 514676] [client 41.89.234.2:50621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ccvzqsQqnLoCgUjh-jwAAAUg"]
[Tue Jul 21 08:48:02.219716 2026] [security2:error] [pid 511108:tid 511334] [client 20.151.10.161:28553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/greap.php"] [unique_id "al9ccoTd5soprXwxAH0X5AAAAGA"]
[Tue Jul 21 08:48:02.459853 2026] [security2:error] [pid 514479:tid 514672] [client 173.252.95.1:36624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ccvzqsQqnLoCgUjh-lgAAAUQ"]
[Tue Jul 21 08:48:02.572660 2026] [security2:error] [pid 511108:tid 511343] [client 203.25.124.2:44449] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/index.php"] [unique_id "al9ccoTd5soprXwxAH0X7gAAAGk"]
[Tue Jul 21 08:48:02.581429 2026] [security2:error] [pid 514479:tid 514522] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ccvzqsQqnLoCgUjh-mQABIyY"]
[Tue Jul 21 08:48:02.581597 2026] [security2:error] [pid 514479:tid 514639] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ccvzqsQqnLoCgUjh-mQABIyY"]
[Tue Jul 21 08:48:02.677626 2026] [security2:error] [pid 511108:tid 511308] [client 20.151.10.161:28549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/177.php"] [unique_id "al9ccoTd5soprXwxAH0X8QAAAEY"]
[Tue Jul 21 08:48:02.699548 2026] [security2:error] [pid 514479:tid 514712] [client 20.226.60.151:57619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/pucci.php"] [unique_id "al9ccvzqsQqnLoCgUjh-mgAAAWw"]
[Tue Jul 21 08:48:02.738683 2026] [security2:error] [pid 511108:tid 511253] [client 203.25.124.215:40809] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "al9ccoTd5soprXwxAH0X8wAAAA8"]
[Tue Jul 21 08:48:03.115303 2026] [security2:error] [pid 514479:tid 514741] [client 20.151.10.161:28548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/199.php"] [unique_id "al9cc_zqsQqnLoCgUjh-pAAAAYk"]
[Tue Jul 21 08:48:03.171475 2026] [security2:error] [pid 511108:tid 511341] [client 103.59.206.240:31262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cc4Td5soprXwxAH0X_QAAAGc"]
[Tue Jul 21 08:48:03.171627 2026] [security2:error] [pid 511108:tid 511341] [client 103.59.206.240:31262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cc4Td5soprXwxAH0X_QAAAGc"]
[Tue Jul 21 08:48:03.265152 2026] [security2:error] [pid 514479:tid 514735] [client 212.32.76.13:41993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/storage/framework/views/shell.php"] [unique_id "al9cc_zqsQqnLoCgUjh-pQAAAYM"]
[Tue Jul 21 08:48:03.361531 2026] [security2:error] [pid 511108:tid 511279] [client 173.252.95.29:61530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cc4Td5soprXwxAH0YBQAAACk"]
[Tue Jul 21 08:48:03.435192 2026] [security2:error] [pid 514479:tid 514731] [client 65.21.113.253:59818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ccvzqsQqnLoCgUjh-oAAAAX8"]
[Tue Jul 21 08:48:03.439790 2026] [security2:error] [pid 514479:tid 514618] [client 20.151.10.161:28049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file52.php"] [unique_id "al9cc_zqsQqnLoCgUjh-qAAAAQ4"]
[Tue Jul 21 08:48:03.726698 2026] [security2:error] [pid 511108:tid 511251] [client 20.151.10.161:28247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/122.php"] [unique_id "al9cc4Td5soprXwxAH0YDgAAAA0"]
[Tue Jul 21 08:48:03.842918 2026] [security2:error] [pid 511108:tid 511256] [client 203.25.124.43:38213] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/rest-api/fields/"] [unique_id "al9cc4Td5soprXwxAH0YEQAAABI"]
[Tue Jul 21 08:48:03.960757 2026] [security2:error] [pid 511108:tid 511350] [client 212.32.76.2:64621] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/tinyfilemanager/tinyfilemanager.php"] [unique_id "al9cc4Td5soprXwxAH0YFwAAAHA"]
[Tue Jul 21 08:48:04.048406 2026] [security2:error] [pid 514479:tid 514671] [client 20.151.10.161:28508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/green1.php"] [unique_id "al9cdPzqsQqnLoCgUjh-rwAAAUM"]
[Tue Jul 21 08:48:04.201174 2026] [security2:error] [pid 511108:tid 511353] [client 20.197.195.24:2787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/file15.php"] [unique_id "al9cdITd5soprXwxAH0YHQAAAHM"]
[Tue Jul 21 08:48:04.430901 2026] [security2:error] [pid 514479:tid 514637] [client 20.151.10.161:28599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/biufile.php"] [unique_id "al9cdPzqsQqnLoCgUjh-swAAASE"]
[Tue Jul 21 08:48:04.474830 2026] [security2:error] [pid 511108:tid 511316] [client 173.252.95.62:39330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cdITd5soprXwxAH0YJQAAAE4"]
[Tue Jul 21 08:48:04.495186 2026] [security2:error] [pid 514479:tid 514690] [client 20.226.60.151:57641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/black.php"] [unique_id "al9cdPzqsQqnLoCgUjh-tQAAAVY"]
[Tue Jul 21 08:48:04.653191 2026] [security2:error] [pid 511108:tid 511273] [client 114.119.139.78:26191] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "compressoresra.com.br"] [uri "/"] [unique_id "al9cdITd5soprXwxAH0YJwAAACM"], referer: https://compressoresra.com.br/separadores-de-condensado/
[Tue Jul 21 08:48:04.667463 2026] [security2:error] [pid 514479:tid 514710] [client 203.25.124.191:37899] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugin-install.php"] [unique_id "al9cdPzqsQqnLoCgUjh-twAAAWo"]
[Tue Jul 21 08:48:04.789395 2026] [security2:error] [pid 511108:tid 511253] [client 20.151.10.161:28495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wpconf.php"] [unique_id "al9cdITd5soprXwxAH0YKwAAAA8"]
[Tue Jul 21 08:48:04.892785 2026] [security2:error] [pid 514479:tid 514678] [client 49.144.66.253:30908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cdPzqsQqnLoCgUjh-vQAAAUo"]
[Tue Jul 21 08:48:04.892921 2026] [security2:error] [pid 514479:tid 514678] [client 49.144.66.253:30908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cdPzqsQqnLoCgUjh-vQAAAUo"]
[Tue Jul 21 08:48:05.368887 2026] [security2:error] [pid 511108:tid 511285] [client 20.151.10.161:28537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/mosty.php"] [unique_id "al9cdYTd5soprXwxAH0YNQAAAC8"]
[Tue Jul 21 08:48:05.375519 2026] [security2:error] [pid 511108:tid 511267] [client 20.197.195.24:48935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/jp.php"] [unique_id "al9cdYTd5soprXwxAH0YNgAAAB0"]
[Tue Jul 21 08:48:05.415160 2026] [security2:error] [pid 511108:tid 511115] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cdYTd5soprXwxAH0YNwAAdQY"]
[Tue Jul 21 08:48:05.415314 2026] [security2:error] [pid 511108:tid 511355] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cdYTd5soprXwxAH0YNwAAdQY"]
[Tue Jul 21 08:48:05.547113 2026] [security2:error] [pid 511108:tid 511301] [client 182.189.99.211:48247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cdYTd5soprXwxAH0YPAAAAD8"]
[Tue Jul 21 08:48:05.547224 2026] [security2:error] [pid 511108:tid 511301] [client 182.189.99.211:48247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cdYTd5soprXwxAH0YPAAAAD8"]
[Tue Jul 21 08:48:05.567590 2026] [security2:error] [pid 511108:tid 511281] [client 203.25.124.49:40023] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/shell.php"] [unique_id "al9cdYTd5soprXwxAH0YPQAAACs"]
[Tue Jul 21 08:48:05.685924 2026] [security2:error] [pid 511108:tid 511349] [client 173.252.95.31:38626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cdYTd5soprXwxAH0YPwAAAG8"]
[Tue Jul 21 08:48:05.759721 2026] [security2:error] [pid 511108:tid 511329] [client 5.31.193.106:29963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cdYTd5soprXwxAH0YQQAAAFs"]
[Tue Jul 21 08:48:05.759863 2026] [security2:error] [pid 511108:tid 511329] [client 5.31.193.106:29963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cdYTd5soprXwxAH0YQQAAAFs"]
[Tue Jul 21 08:48:05.795695 2026] [security2:error] [pid 514479:tid 514656] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cdfzqsQqnLoCgUjh-9AABNCw"]
[Tue Jul 21 08:48:05.796279 2026] [security2:error] [pid 514479:tid 514717] [client 20.151.10.161:28573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/dejavu.php"] [unique_id "al9cdfzqsQqnLoCgUjh-9QAAAXE"]
[Tue Jul 21 08:48:05.873752 2026] [security2:error] [pid 514479:tid 514726] [client 203.25.124.193:60831] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/includes/class-walker-nav-menu-edit-interpreter.php"] [unique_id "al9cdfzqsQqnLoCgUjh-9gAAAXo"]
[Tue Jul 21 08:48:06.145505 2026] [security2:error] [pid 514479:tid 514731] [client 212.32.76.13:64723] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentynineteen/sass/site/"] [unique_id "al9cdvzqsQqnLoCgUjh_AAAAAX8"]
[Tue Jul 21 08:48:06.269820 2026] [security2:error] [pid 511108:tid 511305] [client 20.226.60.151:57629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/zlece.php"] [unique_id "al9cdoTd5soprXwxAH0YSwAAAEM"]
[Tue Jul 21 08:48:06.271520 2026] [security2:error] [pid 511108:tid 511240] [client 20.151.10.161:28496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/aaf.php"] [unique_id "al9cdoTd5soprXwxAH0YTAAAAAI"]
[Tue Jul 21 08:48:06.313587 2026] [security2:error] [pid 514479:tid 514484] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cdvzqsQqnLoCgUjh_AQABhwA"]
[Tue Jul 21 08:48:06.313801 2026] [security2:error] [pid 514479:tid 514739] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cdvzqsQqnLoCgUjh_AQABhwA"]
[Tue Jul 21 08:48:06.364988 2026] [security2:error] [pid 511108:tid 511350] [client 203.25.124.32:65329] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/aatdgetgdg/main.php"] [unique_id "al9cdoTd5soprXwxAH0YTQAAAHA"]
[Tue Jul 21 08:48:06.464517 2026] [security2:error] [pid 511108:tid 511323] [client 168.167.81.163:59772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cdoTd5soprXwxAH0YUQAAAFU"]
[Tue Jul 21 08:48:06.464634 2026] [security2:error] [pid 511108:tid 511323] [client 168.167.81.163:59772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cdoTd5soprXwxAH0YUQAAAFU"]
[Tue Jul 21 08:48:06.550704 2026] [security2:error] [pid 511108:tid 511259] [client 20.226.60.151:57546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/vssrs.php"] [unique_id "al9cdoTd5soprXwxAH0YVQAAABU"]
[Tue Jul 21 08:48:06.573194 2026] [security2:error] [pid 514479:tid 514635] [client 65.21.113.253:59818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cdvzqsQqnLoCgUjh-_gAAAR8"]
[Tue Jul 21 08:48:06.651435 2026] [security2:error] [pid 514479:tid 514699] [client 20.151.10.161:28040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/term.php"] [unique_id "al9cdvzqsQqnLoCgUjh_CAAAAV8"]
[Tue Jul 21 08:48:06.975326 2026] [security2:error] [pid 511108:tid 511356] [client 203.25.124.251:35289] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/customize/class-wp-widget-area-customize-control-interpreter.php"] [unique_id "al9cdoTd5soprXwxAH0YWQAAAHY"]
[Tue Jul 21 08:48:06.981139 2026] [security2:error] [pid 514479:tid 514690] [client 20.151.10.161:28227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ha.php"] [unique_id "al9cdvzqsQqnLoCgUjh_CgAAAVY"]
[Tue Jul 21 08:48:07.127133 2026] [security2:error] [pid 514479:tid 514519] [remote 160.187.68.132:35566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arthromdcanada.online"] [uri "/wp-login.php"] [unique_id "al9cd_zqsQqnLoCgUjh_DgABOSM"]
[Tue Jul 21 08:48:07.249078 2026] [security2:error] [pid 514479:tid 514654] [client 203.25.124.74:53849] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/fukasawa/inc/classes/403x.php"] [unique_id "al9cd_zqsQqnLoCgUjh_EAAAATI"]
[Tue Jul 21 08:48:07.318258 2026] [security2:error] [pid 514479:tid 514590] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cd_zqsQqnLoCgUjh_EgABDWk"]
[Tue Jul 21 08:48:07.318470 2026] [rewrite:warn] [pid 514479:tid 514581] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:48:07.318564 2026] [security2:error] [pid 514479:tid 514617] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cd_zqsQqnLoCgUjh_EgABDWk"]
[Tue Jul 21 08:48:07.459231 2026] [security2:error] [pid 514479:tid 514732] [client 152.59.181.104:64088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cd_zqsQqnLoCgUjh_EwAAAYA"]
[Tue Jul 21 08:48:07.459350 2026] [security2:error] [pid 514479:tid 514732] [client 152.59.181.104:64088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cd_zqsQqnLoCgUjh_EwAAAYA"]
[Tue Jul 21 08:48:07.468426 2026] [security2:error] [pid 514479:tid 514703] [client 203.25.124.37:51483] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/asasx.php"] [unique_id "al9cd_zqsQqnLoCgUjh_FQAAAWM"]
[Tue Jul 21 08:48:07.515329 2026] [security2:error] [pid 511108:tid 511314] [client 20.197.195.24:48901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/f35.php"] [unique_id "al9cd4Td5soprXwxAH0YZQAAAEw"]
[Tue Jul 21 08:48:07.537991 2026] [security2:error] [pid 511108:tid 511250] [client 20.151.10.161:28589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/hur.php"] [unique_id "al9cd4Td5soprXwxAH0YZgAAAAw"]
[Tue Jul 21 08:48:07.648758 2026] [security2:error] [pid 511108:tid 511289] [client 20.226.60.151:57610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wicked.php"] [unique_id "al9cd4Td5soprXwxAH0YagAAADM"]
[Tue Jul 21 08:48:07.903333 2026] [security2:error] [pid 514479:tid 514672] [client 20.151.10.161:28577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/h02ugyh.php"] [unique_id "al9cd_zqsQqnLoCgUjh_HwAAAUQ"]
[Tue Jul 21 08:48:08.189553 2026] [security2:error] [pid 514479:tid 514620] [client 20.226.60.151:57649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/24.php"] [unique_id "al9cePzqsQqnLoCgUjh_JQAAARA"]
[Tue Jul 21 08:48:08.239559 2026] [security2:error] [pid 511108:tid 511241] [client 203.25.124.2:31127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/filester/assets/css/404.php"] [unique_id "al9ceITd5soprXwxAH0YcQAAAAM"]
[Tue Jul 21 08:48:08.273134 2026] [security2:error] [pid 511108:tid 511285] [client 212.32.76.62:33583] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/ai-client/adapters/admin.php"] [unique_id "al9ceITd5soprXwxAH0YcwAAAC8"]
[Tue Jul 21 08:48:08.531252 2026] [security2:error] [pid 514479:tid 514644] [client 20.151.10.161:28577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/seiso.php"] [unique_id "al9cePzqsQqnLoCgUjh_JwAAASg"]
[Tue Jul 21 08:48:08.564329 2026] [security2:error] [pid 511108:tid 511246] [client 203.25.124.48:53377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/template-wploader.php"] [unique_id "al9ceITd5soprXwxAH0YeAAAAAg"]
[Tue Jul 21 08:48:08.608957 2026] [security2:error] [pid 511108:tid 511309] [client 114.198.138.124:60036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9ceITd5soprXwxAH0YfAAAAEc"]
[Tue Jul 21 08:48:08.609051 2026] [security2:error] [pid 511108:tid 511309] [client 114.198.138.124:60036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9ceITd5soprXwxAH0YfAAAAEc"]
[Tue Jul 21 08:48:08.909587 2026] [security2:error] [pid 511108:tid 511330] [client 5.38.115.39:1621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ceITd5soprXwxAH0YgQAAAFw"]
[Tue Jul 21 08:48:08.909731 2026] [security2:error] [pid 511108:tid 511330] [client 5.38.115.39:1621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ceITd5soprXwxAH0YgQAAAFw"]
[Tue Jul 21 08:48:09.023139 2026] [security2:error] [pid 514479:tid 514739] [client 20.226.60.151:57614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/xacs.php"] [unique_id "al9cefzqsQqnLoCgUjh_LgAAAYc"]
[Tue Jul 21 08:48:09.086429 2026] [security2:error] [pid 514479:tid 514709] [client 20.151.10.161:28271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/155.php"] [unique_id "al9cefzqsQqnLoCgUjh_MQAAAWk"]
[Tue Jul 21 08:48:09.258556 2026] [security2:error] [pid 511108:tid 511298] [client 20.197.195.24:48958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/wp-load.php"] [unique_id "al9ceYTd5soprXwxAH0YiAAAADw"]
[Tue Jul 21 08:48:09.468529 2026] [security2:error] [pid 514479:tid 514687] [client 212.32.76.54:32411] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/widget-group/index.php"] [unique_id "al9cefzqsQqnLoCgUjh_NwAAAVM"]
[Tue Jul 21 08:48:09.471824 2026] [security2:error] [pid 514479:tid 514713] [client 20.226.60.151:57543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/zildan.php"] [unique_id "al9cefzqsQqnLoCgUjh_OAAAAW0"]
[Tue Jul 21 08:48:09.513050 2026] [security2:error] [pid 511108:tid 511293] [client 20.151.10.161:28607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ppp.php"] [unique_id "al9ceYTd5soprXwxAH0YiwAAADc"]
[Tue Jul 21 08:48:09.540934 2026] [security2:error] [pid 511108:tid 511350] [client 203.25.124.69:29147] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/wp-conflg.php"] [unique_id "al9ceYTd5soprXwxAH0YjAAAAHA"]
[Tue Jul 21 08:48:09.558524 2026] [security2:error] [pid 514479:tid 514684] [client 203.25.124.49:22371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/test.php"] [unique_id "al9cefzqsQqnLoCgUjh_OQAAAVA"]
[Tue Jul 21 08:48:09.652038 2026] [security2:error] [pid 514479:tid 514697] [client 20.197.192.193:8360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/min.php"] [unique_id "al9cefzqsQqnLoCgUjh_PQAAAV0"]
[Tue Jul 21 08:48:09.851414 2026] [security2:error] [pid 514479:tid 514631] [client 59.95.197.55:64230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cefzqsQqnLoCgUjh_QAAAARs"]
[Tue Jul 21 08:48:09.851531 2026] [security2:error] [pid 514479:tid 514631] [client 59.95.197.55:64230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cefzqsQqnLoCgUjh_QAAAARs"]
[Tue Jul 21 08:48:09.945773 2026] [security2:error] [pid 514479:tid 514696] [client 202.179.75.202:51042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cefzqsQqnLoCgUjh_QQAAAVw"]
[Tue Jul 21 08:48:09.945914 2026] [security2:error] [pid 514479:tid 514696] [client 202.179.75.202:51042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9cefzqsQqnLoCgUjh_QQAAAVw"]
[Tue Jul 21 08:48:09.954252 2026] [security2:error] [pid 514479:tid 514677] [client 20.197.195.24:48923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/xyn.php"] [unique_id "al9cefzqsQqnLoCgUjh_QgAAAUk"]
[Tue Jul 21 08:48:10.285794 2026] [security2:error] [pid 514479:tid 514659] [client 20.151.10.161:28230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/201.php"] [unique_id "al9cevzqsQqnLoCgUjh_RgAAATc"]
[Tue Jul 21 08:48:10.295743 2026] [security2:error] [pid 514479:tid 514693] [client 65.21.113.253:59818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cefzqsQqnLoCgUjh_PwAAAVk"]
[Tue Jul 21 08:48:10.352380 2026] [security2:error] [pid 514479:tid 514703] [client 122.176.100.127:49672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cevzqsQqnLoCgUjh_SAAAAWM"]
[Tue Jul 21 08:48:10.352637 2026] [security2:error] [pid 514479:tid 514703] [client 122.176.100.127:49672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cevzqsQqnLoCgUjh_SAAAAWM"]
[Tue Jul 21 08:48:10.480000 2026] [security2:error] [pid 514479:tid 514711] [client 203.25.124.192:34599] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/preformatted/index.php"] [unique_id "al9cevzqsQqnLoCgUjh_SgAAAWs"]
[Tue Jul 21 08:48:10.556826 2026] [security2:error] [pid 514479:tid 514679] [client 20.226.60.151:57539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/csa.php"] [unique_id "al9cevzqsQqnLoCgUjh_SwAAAUs"]
[Tue Jul 21 08:48:10.746528 2026] [security2:error] [pid 511108:tid 511253] [client 212.32.76.12:63841] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al9ceoTd5soprXwxAH0YoQAAAA8"]
[Tue Jul 21 08:48:10.763612 2026] [security2:error] [pid 511108:tid 511347] [client 212.32.76.5:42381] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "al9ceoTd5soprXwxAH0YogAAAG0"]
[Tue Jul 21 08:48:10.778634 2026] [security2:error] [pid 514479:tid 514740] [client 103.59.206.240:31095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cevzqsQqnLoCgUjh_TwAAAYg"]
[Tue Jul 21 08:48:10.778723 2026] [security2:error] [pid 514479:tid 514740] [client 103.59.206.240:31095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cevzqsQqnLoCgUjh_TwAAAYg"]
[Tue Jul 21 08:48:10.803347 2026] [security2:error] [pid 511108:tid 511302] [client 20.151.10.161:62348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/file52.php"] [unique_id "al9ceoTd5soprXwxAH0YowAAAEA"]
[Tue Jul 21 08:48:10.809059 2026] [security2:error] [pid 514479:tid 514622] [client 20.226.60.151:57551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/w3llscc.php"] [unique_id "al9cevzqsQqnLoCgUjh_UAAAARI"]
[Tue Jul 21 08:48:10.853019 2026] [security2:error] [pid 511108:tid 511299] [client 20.197.195.24:2776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/ccc.php"] [unique_id "al9ceoTd5soprXwxAH0YpQAAAD0"]
[Tue Jul 21 08:48:10.893753 2026] [security2:error] [pid 514479:tid 514538] [remote 120.72.98.5:60428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.98.72.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.bomnegociopromotora.com.br"] [uri "/wp-login.php"] [unique_id "al9cevzqsQqnLoCgUjh_UQABRDY"]
[Tue Jul 21 08:48:11.093143 2026] [security2:error] [pid 514479:tid 514712] [client 195.49.128.211:53015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ce_zqsQqnLoCgUjh_UwAAAWw"]
[Tue Jul 21 08:48:11.093261 2026] [security2:error] [pid 514479:tid 514712] [client 195.49.128.211:53015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ce_zqsQqnLoCgUjh_UwAAAWw"]
[Tue Jul 21 08:48:11.221113 2026] [security2:error] [pid 514479:tid 514706] [client 20.151.10.161:28533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ops.php"] [unique_id "al9ce_zqsQqnLoCgUjh_WAAAAWY"]
[Tue Jul 21 08:48:11.274926 2026] [security2:error] [pid 514479:tid 514716] [client 203.25.124.193:46193] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/list/list/wp-config.php"] [unique_id "al9ce_zqsQqnLoCgUjh_WgAAAXA"]
[Tue Jul 21 08:48:11.372867 2026] [security2:error] [pid 514479:tid 514724] [client 20.197.195.24:17749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/w.php"] [unique_id "al9ce_zqsQqnLoCgUjh_WwAAAXg"]
[Tue Jul 21 08:48:11.387087 2026] [security2:error] [pid 511108:tid 511274] [client 49.205.120.177:15212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.120.205.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kellyassuncaoadv.com"] [uri "/xmlrpc.php"] [unique_id "al9ce4Td5soprXwxAH0YsAAAACQ"]
[Tue Jul 21 08:48:11.387271 2026] [security2:error] [pid 511108:tid 511274] [client 49.205.120.177:15212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kellyassuncaoadv.com"] [uri "/xmlrpc.php"] [unique_id "al9ce4Td5soprXwxAH0YsAAAACQ"]
[Tue Jul 21 08:48:11.565568 2026] [security2:error] [pid 514479:tid 514731] [client 212.32.76.2:37409] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/moon.php"] [unique_id "al9ce_zqsQqnLoCgUjh_XAAAAX8"]
[Tue Jul 21 08:48:11.828470 2026] [security2:error] [pid 514479:tid 514725] [client 20.197.195.24:17759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9ce_zqsQqnLoCgUjh_YAAAAXk"]
[Tue Jul 21 08:48:11.831606 2026] [security2:error] [pid 514479:tid 514594] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ce_zqsQqnLoCgUjh_YQABgW0"]
[Tue Jul 21 08:48:11.831722 2026] [security2:error] [pid 514479:tid 514733] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ce_zqsQqnLoCgUjh_YQABgW0"]
[Tue Jul 21 08:48:11.867022 2026] [security2:error] [pid 511108:tid 511280] [client 113.22.144.139:64808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ce4Td5soprXwxAH0YtwAAACo"]
[Tue Jul 21 08:48:11.867963 2026] [security2:error] [pid 511108:tid 511280] [client 113.22.144.139:64808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ce4Td5soprXwxAH0YtwAAACo"]
[Tue Jul 21 08:48:11.875616 2026] [security2:error] [pid 511108:tid 511300] [client 20.226.60.151:57553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wpx.php"] [unique_id "al9ce4Td5soprXwxAH0YuAAAAD4"]
[Tue Jul 21 08:48:11.981211 2026] [security2:error] [pid 511108:tid 511330] [client 20.151.10.161:28287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ingfo.php"] [unique_id "al9ce4Td5soprXwxAH0YugAAAFw"]
[Tue Jul 21 08:48:12.240460 2026] [security2:error] [pid 514479:tid 514617] [client 203.25.124.212:65375] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/maint/includes/"] [unique_id "al9cfPzqsQqnLoCgUjh_YgAAAQ0"]
[Tue Jul 21 08:48:12.278069 2026] [security2:error] [pid 514479:tid 514697] [client 212.32.76.54:22435] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/post-author-biography/post-author-biography/class-wp-http.php"] [unique_id "al9cfPzqsQqnLoCgUjh_YwAAAV0"]
[Tue Jul 21 08:48:12.309437 2026] [security2:error] [pid 514479:tid 514734] [client 20.197.195.24:48909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/FWAZ.php"] [unique_id "al9cfPzqsQqnLoCgUjh_ZgAAAYI"]
[Tue Jul 21 08:48:12.448096 2026] [security2:error] [pid 514479:tid 514737] [client 20.197.192.193:8376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/echkm.php"] [unique_id "al9cfPzqsQqnLoCgUjh_bQAAAYU"]
[Tue Jul 21 08:48:12.512101 2026] [security2:error] [pid 511108:tid 511293] [client 20.151.10.161:28550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/error_log.php"] [unique_id "al9cfITd5soprXwxAH0YwwAAADc"]
[Tue Jul 21 08:48:12.559898 2026] [security2:error] [pid 511108:tid 511239] [client 203.25.124.33:59427] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/upload/"] [unique_id "al9cfITd5soprXwxAH0YxQAAAAE"]
[Tue Jul 21 08:48:12.759322 2026] [security2:error] [pid 514479:tid 514679] [client 20.197.195.24:48985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/miru1.php"] [unique_id "al9cfPzqsQqnLoCgUjh_cwAAAUs"]
[Tue Jul 21 08:48:12.768132 2026] [security2:error] [pid 511108:tid 511329] [client 41.89.234.2:51251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cfITd5soprXwxAH0YxgAAAFs"]
[Tue Jul 21 08:48:12.768267 2026] [security2:error] [pid 511108:tid 511329] [client 41.89.234.2:51251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cfITd5soprXwxAH0YxgAAAFs"]
[Tue Jul 21 08:48:12.787767 2026] [security2:error] [pid 514479:tid 514576] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cfPzqsQqnLoCgUjh_dAABIls"]
[Tue Jul 21 08:48:12.787928 2026] [security2:error] [pid 514479:tid 514638] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cfPzqsQqnLoCgUjh_dAABIls"]
[Tue Jul 21 08:48:13.031996 2026] [security2:error] [pid 514479:tid 514623] [client 20.151.10.161:28596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/xenon1337.php"] [unique_id "al9cffzqsQqnLoCgUjh_ewAAARM"]
[Tue Jul 21 08:48:13.065116 2026] [security2:error] [pid 514479:tid 514712] [client 20.197.195.24:17820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/aa.php"] [unique_id "al9cffzqsQqnLoCgUjh_fAAAAWw"]
[Tue Jul 21 08:48:13.104196 2026] [security2:error] [pid 514479:tid 514494] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cffzqsQqnLoCgUjh_fQABawo"]
[Tue Jul 21 08:48:13.104361 2026] [security2:error] [pid 514479:tid 514711] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cffzqsQqnLoCgUjh_fQABawo"]
[Tue Jul 21 08:48:13.375068 2026] [security2:error] [pid 514479:tid 514721] [client 20.197.195.24:17826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/122.php"] [unique_id "al9cffzqsQqnLoCgUjh_hAAAAXU"]
[Tue Jul 21 08:48:13.438846 2026] [security2:error] [pid 514479:tid 514704] [client 203.25.124.212:45729] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/comment-date/"] [unique_id "al9cffzqsQqnLoCgUjh_hwAAAWQ"]
[Tue Jul 21 08:48:13.464497 2026] [security2:error] [pid 514479:tid 514671] [client 212.32.76.2:20359] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/css/index.php"] [unique_id "al9cffzqsQqnLoCgUjh_iAAAAUM"]
[Tue Jul 21 08:48:13.548610 2026] [security2:error] [pid 511108:tid 511296] [client 20.151.10.161:28261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/test11.php"] [unique_id "al9cfYTd5soprXwxAH0Y0QAAADo"]
[Tue Jul 21 08:48:13.575253 2026] [security2:error] [pid 514479:tid 514698] [client 20.197.195.24:59819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/get.php"] [unique_id "al9cffzqsQqnLoCgUjh_iQAAAV4"]
[Tue Jul 21 08:48:13.670009 2026] [security2:error] [pid 514479:tid 514739] [client 203.25.124.4:47215] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/post-time-to-read/post-time-to-read/post-template.php"] [unique_id "al9cffzqsQqnLoCgUjh_iwAAAYc"]
[Tue Jul 21 08:48:13.729415 2026] [security2:error] [pid 514479:tid 514690] [client 20.197.195.24:48914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/as.php"] [unique_id "al9cffzqsQqnLoCgUjh_jAAAAVY"]
[Tue Jul 21 08:48:13.914428 2026] [security2:error] [pid 511108:tid 511286] [client 20.197.195.24:17767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/ccou.php"] [unique_id "al9cfYTd5soprXwxAH0Y1wAAADA"]
[Tue Jul 21 08:48:14.014268 2026] [security2:error] [pid 514479:tid 514621] [client 20.151.10.161:28265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/koala.php"] [unique_id "al9cfvzqsQqnLoCgUjh_lQAAARE"]
[Tue Jul 21 08:48:14.023440 2026] [security2:error] [pid 511108:tid 511334] [client 20.197.195.24:49005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/w3lls.php"] [unique_id "al9cfoTd5soprXwxAH0Y2AAAAGA"]
[Tue Jul 21 08:48:14.173355 2026] [security2:error] [pid 514479:tid 514713] [client 65.21.113.253:59818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cffzqsQqnLoCgUjh_jQAAAW0"]
[Tue Jul 21 08:48:14.221841 2026] [security2:error] [pid 514479:tid 514715] [client 20.197.195.24:48948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/test1.php"] [unique_id "al9cfvzqsQqnLoCgUjh_mgAAAW8"]
[Tue Jul 21 08:48:14.253293 2026] [security2:error] [pid 514479:tid 514659] [client 74.7.228.14:56050] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "www.olimposolar.com.br"] [uri "/robots.txt"] [unique_id "al9cfvzqsQqnLoCgUjh_mwABNzc"]
[Tue Jul 21 08:48:14.360223 2026] [security2:error] [pid 511108:tid 511275] [client 20.226.60.151:57627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-css.php"] [unique_id "al9cfoTd5soprXwxAH0Y4QAAACU"]
[Tue Jul 21 08:48:14.372727 2026] [security2:error] [pid 514479:tid 514679] [client 203.25.124.35:55311] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/network/cache/"] [unique_id "al9cfvzqsQqnLoCgUjh_nQAAAUs"]
[Tue Jul 21 08:48:14.422074 2026] [security2:error] [pid 514479:tid 514675] [client 20.197.195.24:2707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/database.php"] [unique_id "al9cfvzqsQqnLoCgUjh_oQAAAUc"]
[Tue Jul 21 08:48:14.427028 2026] [security2:error] [pid 514479:tid 514638] [client 74.7.228.14:56050] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.olimposolar.com.br"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al9cfvzqsQqnLoCgUjh_ngABIgI"], referer: https://www.olimposolar.com.br/robots.txt
[Tue Jul 21 08:48:14.481048 2026] [security2:error] [pid 511108:tid 511295] [client 20.151.10.161:28536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/mac.php"] [unique_id "al9cfoTd5soprXwxAH0Y5AAAADk"]
[Tue Jul 21 08:48:14.640884 2026] [security2:error] [pid 514479:tid 514711] [client 203.25.124.39:55779] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/tinymce/skins/lightgray/"] [unique_id "al9cfvzqsQqnLoCgUjh_pwAAAWs"]
[Tue Jul 21 08:48:14.774860 2026] [security2:error] [pid 511108:tid 511262] [client 203.25.124.209:35883] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/post-template/post-template/api-gateway.php"] [unique_id "al9cfoTd5soprXwxAH0Y5gAAABg"]
[Tue Jul 21 08:48:14.923390 2026] [security2:error] [pid 511108:tid 511357] [client 20.197.195.24:17740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/file.php"] [unique_id "al9cfoTd5soprXwxAH0Y6wAAAHc"]
[Tue Jul 21 08:48:14.924282 2026] [security2:error] [pid 514479:tid 514712] [client 173.252.95.14:40520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cfvzqsQqnLoCgUjh_qQAAAWw"]
[Tue Jul 21 08:48:14.952886 2026] [security2:error] [pid 514479:tid 514723] [client 20.151.10.161:28505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9cfvzqsQqnLoCgUjh_rgAAAXc"]
[Tue Jul 21 08:48:15.268781 2026] [security2:error] [pid 514479:tid 514738] [client 20.151.10.161:62363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/122.php"] [unique_id "al9cf_zqsQqnLoCgUjh_sQAAAYY"]
[Tue Jul 21 08:48:15.365492 2026] [security2:error] [pid 514479:tid 514698] [client 20.151.10.161:28551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wefile.php"] [unique_id "al9cf_zqsQqnLoCgUjh_swAAAV4"]
[Tue Jul 21 08:48:15.426190 2026] [security2:error] [pid 514479:tid 514637] [client 20.197.195.24:17793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/file.php"] [unique_id "al9cf_zqsQqnLoCgUjh_tQAAASE"]
[Tue Jul 21 08:48:15.443661 2026] [security2:error] [pid 511108:tid 511288] [client 168.167.81.163:59527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cf4Td5soprXwxAH0Y8wAAADI"]
[Tue Jul 21 08:48:15.443767 2026] [security2:error] [pid 511108:tid 511288] [client 168.167.81.163:59527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cf4Td5soprXwxAH0Y8wAAADI"]
[Tue Jul 21 08:48:15.573088 2026] [security2:error] [pid 511108:tid 511312] [client 203.25.124.36:60739] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/abcd.php"] [unique_id "al9cf4Td5soprXwxAH0Y-AAAAEo"]
[Tue Jul 21 08:48:15.644361 2026] [security2:error] [pid 514479:tid 514669] [client 20.197.195.24:17746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/777.php"] [unique_id "al9cf_zqsQqnLoCgUjh_uAAAAUE"]
[Tue Jul 21 08:48:15.721518 2026] [security2:error] [pid 514479:tid 514732] [client 142.44.233.157:62592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "daianapontes.com.br"] [uri "/robots.txt"] [unique_id "al9cf_zqsQqnLoCgUjh_ugAAAYA"]
[Tue Jul 21 08:48:15.721619 2026] [security2:error] [pid 514479:tid 514732] [client 142.44.233.157:62592] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "daianapontes.com.br"] [uri "/robots.txt"] [unique_id "al9cf_zqsQqnLoCgUjh_ugAAAYA"]
[Tue Jul 21 08:48:15.735340 2026] [security2:error] [pid 511108:tid 511311] [client 203.25.124.71:39523] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/widgets/chosen.php"] [unique_id "al9cf4Td5soprXwxAH0Y-gAAAEk"]
[Tue Jul 21 08:48:15.784971 2026] [security2:error] [pid 511108:tid 511300] [client 49.144.66.253:31364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cf4Td5soprXwxAH0Y-wAAAD4"]
[Tue Jul 21 08:48:15.785089 2026] [security2:error] [pid 511108:tid 511300] [client 49.144.66.253:31364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cf4Td5soprXwxAH0Y-wAAAD4"]
[Tue Jul 21 08:48:15.804437 2026] [security2:error] [pid 514479:tid 514714] [client 20.197.195.24:17813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/ssixta.php"] [unique_id "al9cf_zqsQqnLoCgUjh_vAAAAW4"]
[Tue Jul 21 08:48:15.860049 2026] [security2:error] [pid 514479:tid 514522] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cf_zqsQqnLoCgUjh_vwABgiY"]
[Tue Jul 21 08:48:15.860231 2026] [security2:error] [pid 514479:tid 514734] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cf_zqsQqnLoCgUjh_vwABgiY"]
[Tue Jul 21 08:48:15.954991 2026] [security2:error] [pid 514479:tid 514736] [client 20.151.10.161:28515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9cf_zqsQqnLoCgUjh_wgAAAYQ"]
[Tue Jul 21 08:48:15.974126 2026] [security2:error] [pid 511108:tid 511298] [client 203.25.124.190:53025] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/customize/network/index.php"] [unique_id "al9cf4Td5soprXwxAH0Y_gAAADw"]
[Tue Jul 21 08:48:16.035451 2026] [security2:error] [pid 514479:tid 514668] [client 20.197.195.24:2758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/1c.php"] [unique_id "al9cgPzqsQqnLoCgUjh_xAAAAUA"]
[Tue Jul 21 08:48:16.135002 2026] [security2:error] [pid 514479:tid 514679] [client 20.197.195.24:17745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/test2.php"] [unique_id "al9cgPzqsQqnLoCgUjh_xQAAAUs"]
[Tue Jul 21 08:48:16.251459 2026] [access_compat:error] [pid 511108:tid 511319] [client 220.202.112.134:0] AH01797: client denied by server configuration: /home4/fabi0417/powerflats.com.br/index.php4
[Tue Jul 21 08:48:16.283450 2026] [security2:error] [pid 514479:tid 514656] [client 20.151.10.161:28554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/2P.php"] [unique_id "al9cgPzqsQqnLoCgUjh_ygAAATQ"]
[Tue Jul 21 08:48:16.337565 2026] [security2:error] [pid 511108:tid 511325] [client 20.197.195.24:17802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/buy.php"] [unique_id "al9cgITd5soprXwxAH0ZCwAAAFc"]
[Tue Jul 21 08:48:16.396031 2026] [security2:error] [pid 514479:tid 514700] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cgPzqsQqnLoCgUjh_yQABYEE"]
[Tue Jul 21 08:48:16.444334 2026] [security2:error] [pid 514479:tid 514620] [client 20.197.195.24:48978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/ssend.php"] [unique_id "al9cgPzqsQqnLoCgUjh_zAAAARA"]
[Tue Jul 21 08:48:16.663797 2026] [security2:error] [pid 514479:tid 514676] [client 203.25.124.32:37553] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwentyfour/patterns/template-singl-portfolio.php"] [unique_id "al9cgPzqsQqnLoCgUjh_zwAAAUg"]
[Tue Jul 21 08:48:16.740421 2026] [security2:error] [pid 511108:tid 511336] [client 20.197.192.193:8366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/mac.php"] [unique_id "al9cgITd5soprXwxAH0ZFgAAAGI"]
[Tue Jul 21 08:48:16.749349 2026] [security2:error] [pid 511108:tid 511338] [client 20.151.10.161:62374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/green1.php"] [unique_id "al9cgITd5soprXwxAH0ZFwAAAGQ"]
[Tue Jul 21 08:48:16.754310 2026] [security2:error] [pid 514479:tid 514630] [client 20.151.10.161:28583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/.well-known/about.php"] [unique_id "al9cgPzqsQqnLoCgUjh_1QAAARo"]
[Tue Jul 21 08:48:16.780373 2026] [security2:error] [pid 514479:tid 514622] [client 212.32.76.59:49353] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/widgets/theme-compat/index.php"] [unique_id "al9cgPzqsQqnLoCgUjh_1wAAARI"]
[Tue Jul 21 08:48:16.800248 2026] [security2:error] [pid 511108:tid 511159] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cgITd5soprXwxAH0ZGgAAFjI"]
[Tue Jul 21 08:48:16.800393 2026] [security2:error] [pid 511108:tid 511260] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cgITd5soprXwxAH0ZGgAAFjI"]
[Tue Jul 21 08:48:16.823152 2026] [security2:error] [pid 511108:tid 511262] [client 20.197.195.24:2706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/item.php"] [unique_id "al9cgITd5soprXwxAH0ZGwAAABg"]
[Tue Jul 21 08:48:16.933949 2026] [security2:error] [pid 514479:tid 514627] [client 20.226.60.151:57626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ho.php"] [unique_id "al9cgPzqsQqnLoCgUjh_2AAAARc"]
[Tue Jul 21 08:48:17.043781 2026] [security2:error] [pid 514479:tid 514723] [client 203.25.124.51:65243] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/theme-check/main.php"] [unique_id "al9cgfzqsQqnLoCgUjh_2wAAAXc"]
[Tue Jul 21 08:48:17.095424 2026] [security2:error] [pid 514479:tid 514671] [client 20.197.195.24:48905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/ss.php"] [unique_id "al9cgfzqsQqnLoCgUjh_3gAAAUM"]
[Tue Jul 21 08:48:17.161754 2026] [security2:error] [pid 514479:tid 514672] [client 182.189.99.211:48309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cgfzqsQqnLoCgUjh_4AAAAUQ"]
[Tue Jul 21 08:48:17.161929 2026] [security2:error] [pid 514479:tid 514672] [client 182.189.99.211:48309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cgfzqsQqnLoCgUjh_4AAAAUQ"]
[Tue Jul 21 08:48:17.280823 2026] [security2:error] [pid 514479:tid 514637] [client 20.197.195.24:48955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/hypo.php"] [unique_id "al9cgfzqsQqnLoCgUjh_4QAAASE"]
[Tue Jul 21 08:48:17.299210 2026] [security2:error] [pid 511108:tid 511281] [client 20.151.10.161:28241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9cgYTd5soprXwxAH0ZJAAAACs"]
[Tue Jul 21 08:48:17.320334 2026] [security2:error] [pid 511108:tid 511279] [client 198.44.157.34:52444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cgYTd5soprXwxAH0ZJQAAACk"]
[Tue Jul 21 08:48:17.320507 2026] [security2:error] [pid 511108:tid 511279] [client 198.44.157.34:52444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cgYTd5soprXwxAH0ZJQAAACk"]
[Tue Jul 21 08:48:17.610884 2026] [security2:error] [pid 514479:tid 514641] [client 20.151.10.161:28606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/bob.php"] [unique_id "al9cgfzqsQqnLoCgUjh_6wAAASU"]
[Tue Jul 21 08:48:17.665834 2026] [security2:error] [pid 514479:tid 514679] [client 20.197.195.24:2695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/users.php"] [unique_id "al9cgfzqsQqnLoCgUjh_7QAAAUs"]
[Tue Jul 21 08:48:17.769187 2026] [security2:error] [pid 514479:tid 514685] [client 203.25.124.35:60491] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/class-wp-smtp-bar.php"] [unique_id "al9cgfzqsQqnLoCgUjh_7gAAAVE"]
[Tue Jul 21 08:48:17.778391 2026] [security2:error] [pid 514479:tid 514649] [client 203.25.124.204:58259] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/upgrade/patterns/index.php"] [unique_id "al9cgfzqsQqnLoCgUjh_7wAAAS0"]
[Tue Jul 21 08:48:17.863299 2026] [security2:error] [pid 514479:tid 514597] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cgfzqsQqnLoCgUjh_8gABN3A"]
[Tue Jul 21 08:48:17.863454 2026] [security2:error] [pid 514479:tid 514659] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cgfzqsQqnLoCgUjh_8gABN3A"]
[Tue Jul 21 08:48:17.961083 2026] [security2:error] [pid 514479:tid 514616] [client 20.197.195.24:48949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/177.php"] [unique_id "al9cgfzqsQqnLoCgUjh_8wAAAQw"]
[Tue Jul 21 08:48:18.159021 2026] [security2:error] [pid 514479:tid 514650] [client 20.197.195.24:48969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/config.php"] [unique_id "al9cgvzqsQqnLoCgUjh_9wAAAS4"]
[Tue Jul 21 08:48:18.226470 2026] [security2:error] [pid 514479:tid 514652] [client 20.151.10.161:62365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/biufile.php"] [unique_id "al9cgvzqsQqnLoCgUjh_-QAAATA"]
[Tue Jul 21 08:48:18.339695 2026] [security2:error] [pid 511108:tid 511296] [client 203.25.124.211:29685] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/css.php"] [unique_id "al9cgoTd5soprXwxAH0ZOwAAADo"]
[Tue Jul 21 08:48:18.429490 2026] [security2:error] [pid 511108:tid 511337] [client 20.151.10.161:28063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/crgio.php"] [unique_id "al9cgoTd5soprXwxAH0ZPQAAAGM"]
[Tue Jul 21 08:48:18.590498 2026] [security2:error] [pid 511108:tid 511273] [client 20.197.195.24:2769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/gettest.php"] [unique_id "al9cgoTd5soprXwxAH0ZPwAAACM"]
[Tue Jul 21 08:48:18.846999 2026] [security2:error] [pid 514479:tid 514672] [client 20.151.10.161:28079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/pucci.php"] [unique_id "al9cgvzqsQqnLoCgUjiABAAAAUQ"]
[Tue Jul 21 08:48:18.904918 2026] [access_compat:error] [pid 511108:tid 511318] [client 162.241.63.68:23480] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:48:18.917901 2026] [security2:error] [pid 514479:tid 514656] [client 152.59.181.104:64572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cgvzqsQqnLoCgUjiABQAAATQ"]
[Tue Jul 21 08:48:18.918306 2026] [security2:error] [pid 514479:tid 514656] [client 152.59.181.104:64572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cgvzqsQqnLoCgUjiABQAAATQ"]
[Tue Jul 21 08:48:18.970677 2026] [security2:error] [pid 511108:tid 511262] [client 203.25.124.73:28085] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/assets/images/selam.php"] [unique_id "al9cgoTd5soprXwxAH0ZRwAAABg"]
[Tue Jul 21 08:48:19.068902 2026] [security2:error] [pid 514479:tid 514669] [client 20.226.60.151:57630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/xy.php"] [unique_id "al9cg_zqsQqnLoCgUjiABgAAAUE"]
[Tue Jul 21 08:48:19.242357 2026] [security2:error] [pid 511108:tid 511289] [client 114.198.138.124:60606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cg4Td5soprXwxAH0ZUQAAADM"]
[Tue Jul 21 08:48:19.242473 2026] [security2:error] [pid 511108:tid 511289] [client 114.198.138.124:60606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cg4Td5soprXwxAH0ZUQAAADM"]
[Tue Jul 21 08:48:19.245533 2026] [security2:error] [pid 514479:tid 514696] [client 198.44.157.34:55358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9cg_zqsQqnLoCgUjiACQAAAVw"]
[Tue Jul 21 08:48:19.245613 2026] [security2:error] [pid 514479:tid 514696] [client 198.44.157.34:55358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9cg_zqsQqnLoCgUjiACQAAAVw"]
[Tue Jul 21 08:48:19.371508 2026] [security2:error] [pid 511108:tid 511328] [client 203.25.124.198:41007] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/images/widgets/index.php"] [unique_id "al9cg4Td5soprXwxAH0ZVAAAAFo"]
[Tue Jul 21 08:48:19.478076 2026] [security2:error] [pid 511108:tid 511288] [client 20.197.195.24:48959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/min.php"] [unique_id "al9cg4Td5soprXwxAH0ZWQAAADI"]
[Tue Jul 21 08:48:19.626930 2026] [security2:error] [pid 511108:tid 511267] [client 5.38.115.39:28824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cg4Td5soprXwxAH0ZXQAAAB0"]
[Tue Jul 21 08:48:19.627052 2026] [security2:error] [pid 511108:tid 511267] [client 5.38.115.39:28824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cg4Td5soprXwxAH0ZXQAAAB0"]
[Tue Jul 21 08:48:19.657170 2026] [security2:error] [pid 511108:tid 511311] [client 20.151.10.161:28579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-temp.php"] [unique_id "al9cg4Td5soprXwxAH0ZYQAAAEk"]
[Tue Jul 21 08:48:20.126869 2026] [security2:error] [pid 514479:tid 514653] [client 20.151.10.161:8424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wpconf.php"] [unique_id "al9chPzqsQqnLoCgUjiAEAAAATE"]
[Tue Jul 21 08:48:20.163178 2026] [security2:error] [pid 514479:tid 514700] [client 20.197.195.24:49010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/dvjul.php"] [unique_id "al9chPzqsQqnLoCgUjiAEgAAAWA"]
[Tue Jul 21 08:48:20.164688 2026] [security2:error] [pid 514479:tid 514544] [remote 202.51.202.242:43522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guilhermeverissimo.com.br"] [uri "/wp-login.php"] [unique_id "al9chPzqsQqnLoCgUjiAEQABDzw"]
[Tue Jul 21 08:48:20.182061 2026] [security2:error] [pid 514479:tid 514659] [client 64.42.179.43:36470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9chPzqsQqnLoCgUjiAEwAAATc"]
[Tue Jul 21 08:48:20.182126 2026] [security2:error] [pid 514479:tid 514659] [client 64.42.179.43:36470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9chPzqsQqnLoCgUjiAEwAAATc"]
[Tue Jul 21 08:48:20.218286 2026] [security2:error] [pid 511108:tid 511259] [client 173.252.95.2:52756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9chITd5soprXwxAH0ZbAAAABU"]
[Tue Jul 21 08:48:20.239704 2026] [security2:error] [pid 511108:tid 511284] [client 203.25.124.67:30991] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/admin.php"] [unique_id "al9chITd5soprXwxAH0ZbQAAAC4"]
[Tue Jul 21 08:48:20.275153 2026] [security2:error] [pid 511108:tid 511333] [client 203.25.124.210:57391] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/customize/includes/index.php"] [unique_id "al9chITd5soprXwxAH0ZcAAAAF8"]
[Tue Jul 21 08:48:20.297461 2026] [security2:error] [pid 511108:tid 511266] [client 59.95.197.55:64712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9chITd5soprXwxAH0ZcQAAABw"]
[Tue Jul 21 08:48:20.297671 2026] [security2:error] [pid 511108:tid 511266] [client 59.95.197.55:64712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9chITd5soprXwxAH0ZcQAAABw"]
[Tue Jul 21 08:48:20.377711 2026] [security2:error] [pid 511108:tid 511326] [client 20.151.10.161:28579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9chITd5soprXwxAH0ZcwAAAFg"]
[Tue Jul 21 08:48:20.462897 2026] [security2:error] [pid 511108:tid 511254] [client 203.25.124.36:59523] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/manager.php"] [unique_id "al9chITd5soprXwxAH0ZdAAAABA"]
[Tue Jul 21 08:48:20.520611 2026] [security2:error] [pid 511108:tid 511294] [client 20.226.60.151:57579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/loader.php"] [unique_id "al9chITd5soprXwxAH0ZdgAAADg"]
[Tue Jul 21 08:48:20.622092 2026] [security2:error] [pid 511108:tid 511334] [client 20.197.195.24:2797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/biufile.php"] [unique_id "al9chITd5soprXwxAH0ZeAAAAGA"]
[Tue Jul 21 08:48:20.723913 2026] [security2:error] [pid 514479:tid 514666] [client 20.151.10.161:28481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/puc.php"] [unique_id "al9chPzqsQqnLoCgUjiAGAAAAT4"]
[Tue Jul 21 08:48:20.812043 2026] [security2:error] [pid 511108:tid 511270] [client 202.179.75.202:51206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.75.179.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9chITd5soprXwxAH0ZfgAAACA"]
[Tue Jul 21 08:48:20.812136 2026] [security2:error] [pid 511108:tid 511270] [client 202.179.75.202:51206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sugar-delete.online"] [uri "/xmlrpc.php"] [unique_id "al9chITd5soprXwxAH0ZfgAAACA"]
[Tue Jul 21 08:48:21.009015 2026] [security2:error] [pid 511108:tid 511262] [client 20.197.192.193:9558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/samll.php"] [unique_id "al9chYTd5soprXwxAH0ZgQAAABg"]
[Tue Jul 21 08:48:21.028429 2026] [security2:error] [pid 511108:tid 511285] [client 20.151.10.161:28509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/themes.php"] [unique_id "al9chYTd5soprXwxAH0ZggAAAC8"]
[Tue Jul 21 08:48:21.051198 2026] [security2:error] [pid 511108:tid 511355] [client 203.25.124.42:24169] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/2025/"] [unique_id "al9chYTd5soprXwxAH0ZgwAAAHU"]
[Tue Jul 21 08:48:21.469057 2026] [security2:error] [pid 514479:tid 514671] [client 203.25.124.12:22341] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/colors/upgrade/index.php"] [unique_id "al9chfzqsQqnLoCgUjiAIwAAAUM"]
[Tue Jul 21 08:48:21.476822 2026] [security2:error] [pid 514479:tid 514731] [client 103.59.206.240:31315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9chfzqsQqnLoCgUjiAJAAAAX8"]
[Tue Jul 21 08:48:21.479167 2026] [security2:error] [pid 514479:tid 514731] [client 103.59.206.240:31315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9chfzqsQqnLoCgUjiAJAAAAX8"]
[Tue Jul 21 08:48:21.575171 2026] [security2:error] [pid 514479:tid 514669] [client 20.151.10.161:28047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/dx.php"] [unique_id "al9chfzqsQqnLoCgUjiAJQAAAUE"]
[Tue Jul 21 08:48:21.686079 2026] [security2:error] [pid 514479:tid 514739] [client 20.197.195.24:48920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/av.php"] [unique_id "al9chfzqsQqnLoCgUjiAJwAAAYc"]
[Tue Jul 21 08:48:21.698263 2026] [security2:error] [pid 514479:tid 514618] [client 74.7.241.144:51558] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "adms2.com.br"] [uri "/index.php"] [unique_id "al9chfzqsQqnLoCgUjiAJgABDho"]
[Tue Jul 21 08:48:21.778808 2026] [security2:error] [pid 511108:tid 511291] [client 195.49.128.211:53621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9chYTd5soprXwxAH0ZkwAAADU"]
[Tue Jul 21 08:48:21.778962 2026] [security2:error] [pid 511108:tid 511291] [client 195.49.128.211:53621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9chYTd5soprXwxAH0ZkwAAADU"]
[Tue Jul 21 08:48:21.965115 2026] [security2:error] [pid 514479:tid 514685] [client 203.25.124.69:26421] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/upload.php"] [unique_id "al9chfzqsQqnLoCgUjiALAAAAVE"]
[Tue Jul 21 08:48:22.041373 2026] [security2:error] [pid 511108:tid 511277] [client 20.151.10.161:28503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/p.php"] [unique_id "al9choTd5soprXwxAH0ZlwAAACc"]
[Tue Jul 21 08:48:22.103175 2026] [security2:error] [pid 514479:tid 514707] [client 20.151.10.161:62402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/mosty.php"] [unique_id "al9chvzqsQqnLoCgUjiALgAAAWc"]
[Tue Jul 21 08:48:22.181557 2026] [security2:error] [pid 511108:tid 511345] [client 122.176.100.127:50157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9choTd5soprXwxAH0ZmgAAAGs"]
[Tue Jul 21 08:48:22.181699 2026] [security2:error] [pid 511108:tid 511345] [client 122.176.100.127:50157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9choTd5soprXwxAH0ZmgAAAGs"]
[Tue Jul 21 08:48:22.346039 2026] [security2:error] [pid 514479:tid 514497] [remote 103.28.36.106:53900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9chvzqsQqnLoCgUjiAMQABGw0"]
[Tue Jul 21 08:48:22.438704 2026] [security2:error] [pid 514479:tid 514652] [client 203.25.124.66:28065] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/comment-content/"] [unique_id "al9chvzqsQqnLoCgUjiANgAAATA"]
[Tue Jul 21 08:48:22.561708 2026] [security2:error] [pid 511108:tid 511333] [client 20.151.10.161:28052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/bthil.php"] [unique_id "al9choTd5soprXwxAH0ZpwAAAF8"]
[Tue Jul 21 08:48:22.584347 2026] [security2:error] [pid 511108:tid 511126] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9choTd5soprXwxAH0ZqAAAKhE"]
[Tue Jul 21 08:48:22.584496 2026] [security2:error] [pid 511108:tid 511280] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9choTd5soprXwxAH0ZqAAAKhE"]
[Tue Jul 21 08:48:22.654244 2026] [security2:error] [pid 511108:tid 511325] [client 20.226.60.151:57648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/spadex.php"] [unique_id "al9choTd5soprXwxAH0ZqQAAAFc"]
[Tue Jul 21 08:48:22.686969 2026] [security2:error] [pid 511108:tid 511266] [client 20.197.195.24:2706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/coffexium.php"] [unique_id "al9choTd5soprXwxAH0ZqwAAABw"]
[Tue Jul 21 08:48:22.711113 2026] [security2:error] [pid 511108:tid 511265] [client 113.22.144.139:65341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9choTd5soprXwxAH0ZrAAAABs"]
[Tue Jul 21 08:48:22.711320 2026] [security2:error] [pid 511108:tid 511265] [client 113.22.144.139:65341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9choTd5soprXwxAH0ZrAAAABs"]
[Tue Jul 21 08:48:22.767707 2026] [security2:error] [pid 511108:tid 511337] [client 212.32.76.55:61187] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/news-portal/user-install.php"] [unique_id "al9choTd5soprXwxAH0ZrQAAAGM"]
[Tue Jul 21 08:48:22.909592 2026] [security2:error] [pid 511108:tid 511250] [client 20.151.10.161:62357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/dejavu.php"] [unique_id "al9choTd5soprXwxAH0ZswAAAAw"]
[Tue Jul 21 08:48:22.968526 2026] [security2:error] [pid 514479:tid 514736] [client 20.151.10.161:28497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/7.php"] [unique_id "al9chvzqsQqnLoCgUjiASgAAAYQ"]
[Tue Jul 21 08:48:23.220514 2026] [security2:error] [pid 511108:tid 511261] [client 41.89.234.2:51862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ch4Td5soprXwxAH0ZugAAABc"]
[Tue Jul 21 08:48:23.220703 2026] [security2:error] [pid 511108:tid 511261] [client 41.89.234.2:51862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ch4Td5soprXwxAH0ZugAAABc"]
[Tue Jul 21 08:48:23.447064 2026] [security2:error] [pid 511108:tid 511340] [client 203.25.124.33:31195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/images/"] [unique_id "al9ch4Td5soprXwxAH0ZwwAAAGY"]
[Tue Jul 21 08:48:23.484530 2026] [security2:error] [pid 514479:tid 514681] [client 20.226.60.151:57591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/2x.php"] [unique_id "al9ch_zqsQqnLoCgUjiAVgAAAU0"]
[Tue Jul 21 08:48:23.585081 2026] [security2:error] [pid 511108:tid 511258] [client 20.151.10.161:28235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/8.php"] [unique_id "al9ch4Td5soprXwxAH0ZyAAAABQ"]
[Tue Jul 21 08:48:23.636488 2026] [security2:error] [pid 511108:tid 511328] [client 148.113.130.217:47448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "daianapontes.com.br"] [uri "/"] [unique_id "al9ch4Td5soprXwxAH0ZyQAAAFo"]
[Tue Jul 21 08:48:23.636593 2026] [security2:error] [pid 511108:tid 511328] [client 148.113.130.217:47448] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "daianapontes.com.br"] [uri "/"] [unique_id "al9ch4Td5soprXwxAH0ZyQAAAFo"]
[Tue Jul 21 08:48:23.657436 2026] [security2:error] [pid 511108:tid 511230] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ch4Td5soprXwxAH0ZygAATnk"]
[Tue Jul 21 08:48:23.657535 2026] [security2:error] [pid 511108:tid 511316] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ch4Td5soprXwxAH0ZygAATnk"]
[Tue Jul 21 08:48:23.676137 2026] [security2:error] [pid 514479:tid 514513] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ch_zqsQqnLoCgUjiAWgABTh0"]
[Tue Jul 21 08:48:23.676315 2026] [security2:error] [pid 514479:tid 514682] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ch_zqsQqnLoCgUjiAWgABTh0"]
[Tue Jul 21 08:48:23.681080 2026] [security2:error] [pid 511108:tid 511209] [remote 124.55.178.99:43302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mastertork.com.br"] [uri "/wp-login.php"] [unique_id "al9choTd5soprXwxAH0ZqgAAZWQ"]
[Tue Jul 21 08:48:23.877168 2026] [security2:error] [pid 514479:tid 514661] [client 203.25.124.9:28107] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/missing/missing/theme-single.php"] [unique_id "al9ch_zqsQqnLoCgUjiAXAAAATk"]
[Tue Jul 21 08:48:23.957229 2026] [core:error] [pid 514479:tid 514582] [remote 40.77.167.24:52174] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:48:23.957247 2026] [core:error] [pid 514479:tid 514582] [remote 40.77.167.24:52174] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:48:23.959622 2026] [security2:error] [pid 511108:tid 511251] [client 20.151.10.161:28067] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ibericaladrilhos.com.br"] [uri "/1.php"] [unique_id "al9ch4Td5soprXwxAH0ZzgAAAA0"]
[Tue Jul 21 08:48:23.959737 2026] [security2:error] [pid 511108:tid 511251] [client 20.151.10.161:28067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/1.php"] [unique_id "al9ch4Td5soprXwxAH0ZzgAAAA0"]
[Tue Jul 21 08:48:24.103242 2026] [core:error] [pid 514479:tid 514528] [remote 40.77.167.24:52174] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:48:24.103260 2026] [core:error] [pid 514479:tid 514528] [remote 40.77.167.24:52174] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:48:24.182197 2026] [security2:error] [pid 514479:tid 514723] [client 20.197.195.24:49006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/core.php"] [unique_id "al9ciPzqsQqnLoCgUjiAZgAAAXc"]
[Tue Jul 21 08:48:24.259922 2026] [security2:error] [pid 514479:tid 514680] [client 203.25.124.58:56127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "al9ciPzqsQqnLoCgUjiAaAAAAUw"]
[Tue Jul 21 08:48:24.338956 2026] [security2:error] [pid 514479:tid 514737] [client 212.32.76.10:60201] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/options.php"] [unique_id "al9ciPzqsQqnLoCgUjiAagAAAYU"]
[Tue Jul 21 08:48:24.417926 2026] [security2:error] [pid 514479:tid 514518] [remote 74.235.96.117:36898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-login.php"] [unique_id "al9ciPzqsQqnLoCgUjiAawABhyI"]
[Tue Jul 21 08:48:24.825746 2026] [security2:error] [pid 511108:tid 511268] [client 20.197.195.24:59845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/als.php"] [unique_id "al9ciITd5soprXwxAH0Z3QAAAB4"]
[Tue Jul 21 08:48:24.872043 2026] [security2:error] [pid 514479:tid 514707] [client 20.226.60.151:57606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ctex1.php"] [unique_id "al9ciPzqsQqnLoCgUjiAcgAAAWc"]
[Tue Jul 21 08:48:24.964597 2026] [security2:error] [pid 514479:tid 514659] [client 20.151.10.161:28516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/100.php"] [unique_id "al9ciPzqsQqnLoCgUjiAcwAAATc"]
[Tue Jul 21 08:48:25.069408 2026] [security2:error] [pid 514479:tid 514702] [client 203.25.124.181:49851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/admin-header-string.php"] [unique_id "al9cifzqsQqnLoCgUjiAdgAAAWI"]
[Tue Jul 21 08:48:25.087115 2026] [core:error] [pid 511108:tid 511359] [client 66.249.66.69:44611] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:48:25.087131 2026] [core:error] [pid 511108:tid 511359] [client 66.249.66.69:44611] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:48:25.203925 2026] [security2:error] [pid 514479:tid 514728] [client 20.151.10.161:62442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/aaf.php"] [unique_id "al9cifzqsQqnLoCgUjiAdwAAAXw"]
[Tue Jul 21 08:48:25.275205 2026] [security2:error] [pid 514479:tid 514681] [client 20.104.96.117:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/xyn.php"] [unique_id "al9cifzqsQqnLoCgUjiAeAAAAU0"]
[Tue Jul 21 08:48:25.366692 2026] [security2:error] [pid 514479:tid 514638] [client 203.25.124.49:33503] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/buy.php"] [unique_id "al9cifzqsQqnLoCgUjiAegAAASI"]
[Tue Jul 21 08:48:25.801550 2026] [security2:error] [pid 511108:tid 511319] [client 20.151.10.161:28521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/about.php"] [unique_id "al9ciYTd5soprXwxAH0Z7gAAAFE"]
[Tue Jul 21 08:48:25.843265 2026] [security2:error] [pid 511108:tid 511286] [client 20.197.195.24:48956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/simple.php"] [unique_id "al9ciYTd5soprXwxAH0Z7wAAADA"]
[Tue Jul 21 08:48:25.946338 2026] [security2:error] [pid 511108:tid 511313] [client 203.25.124.31:47051] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/chosen.php"] [unique_id "al9ciYTd5soprXwxAH0Z8gAAAEs"]
[Tue Jul 21 08:48:26.015841 2026] [security2:error] [pid 511108:tid 511355] [client 185.8.106.219:27118] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "powertronicseguranca.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9cioTd5soprXwxAH0Z9AAAAHU"]
[Tue Jul 21 08:48:26.139070 2026] [security2:error] [pid 514479:tid 514623] [client 168.167.81.163:62252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9civzqsQqnLoCgUjiAhQAAARM"]
[Tue Jul 21 08:48:26.139163 2026] [security2:error] [pid 514479:tid 514623] [client 168.167.81.163:62252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9civzqsQqnLoCgUjiAhQAAARM"]
[Tue Jul 21 08:48:26.230617 2026] [core:error] [pid 514479:tid 514581] [remote 40.77.167.72:5501] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:48:26.230640 2026] [core:error] [pid 514479:tid 514581] [remote 40.77.167.72:5501] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:48:26.365746 2026] [security2:error] [pid 514479:tid 514490] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9civzqsQqnLoCgUjiAigABTAY"]
[Tue Jul 21 08:48:26.365905 2026] [security2:error] [pid 514479:tid 514680] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9civzqsQqnLoCgUjiAigABTAY"]
[Tue Jul 21 08:48:26.404541 2026] [security2:error] [pid 511108:tid 511322] [client 20.151.10.161:28501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/admin.php"] [unique_id "al9cioTd5soprXwxAH0Z9wAAAFQ"]
[Tue Jul 21 08:48:26.464831 2026] [security2:error] [pid 514479:tid 514696] [client 203.25.124.66:57677] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/zgbrarc/cong.php"] [unique_id "al9civzqsQqnLoCgUjiAiwAAAVw"]
[Tue Jul 21 08:48:26.533137 2026] [security2:error] [pid 514479:tid 514639] [client 182.189.99.211:48457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9civzqsQqnLoCgUjiAjQAAASM"]
[Tue Jul 21 08:48:26.533233 2026] [security2:error] [pid 514479:tid 514639] [client 182.189.99.211:48457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9civzqsQqnLoCgUjiAjQAAASM"]
[Tue Jul 21 08:48:26.580977 2026] [security2:error] [pid 514479:tid 514713] [client 185.8.106.219:25994] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "powertronicseguranca.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9civzqsQqnLoCgUjiAkAAAAW0"]
[Tue Jul 21 08:48:26.627579 2026] [security2:error] [pid 511108:tid 511238] [client 49.144.66.253:31768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cioTd5soprXwxAH0Z_QAAAAA"]
[Tue Jul 21 08:48:26.627718 2026] [security2:error] [pid 511108:tid 511238] [client 49.144.66.253:31768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cioTd5soprXwxAH0Z_QAAAAA"]
[Tue Jul 21 08:48:26.648059 2026] [security2:error] [pid 514479:tid 514629] [client 20.151.10.161:62338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/term.php"] [unique_id "al9civzqsQqnLoCgUjiAkwAAARk"]
[Tue Jul 21 08:48:26.669753 2026] [security2:error] [pid 514479:tid 514707] [client 20.197.195.24:17768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/init.php"] [unique_id "al9civzqsQqnLoCgUjiAlAAAAWc"]
[Tue Jul 21 08:48:26.778237 2026] [security2:error] [pid 511108:tid 511274] [client 203.25.124.190:32605] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/fonts-long.php"] [unique_id "al9cioTd5soprXwxAH0aAQAAACQ"]
[Tue Jul 21 08:48:26.864666 2026] [security2:error] [pid 514479:tid 514703] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9civzqsQqnLoCgUjiAlwABY0U"]
[Tue Jul 21 08:48:26.977881 2026] [security2:error] [pid 511108:tid 511362] [client 5.31.193.106:30403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cioTd5soprXwxAH0aAgAAAHw"]
[Tue Jul 21 08:48:26.978025 2026] [security2:error] [pid 511108:tid 511362] [client 5.31.193.106:30403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cioTd5soprXwxAH0aAgAAAHw"]
[Tue Jul 21 08:48:26.983786 2026] [security2:error] [pid 514479:tid 514652] [client 20.151.10.161:28284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/edit.php"] [unique_id "al9civzqsQqnLoCgUjiAmQAAATA"]
[Tue Jul 21 08:48:27.140662 2026] [security2:error] [pid 511108:tid 511277] [client 212.32.76.11:64971] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/images/as.php"] [unique_id "al9ci4Td5soprXwxAH0aCQAAACc"]
[Tue Jul 21 08:48:27.323272 2026] [security2:error] [pid 511108:tid 511191] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9ci4Td5soprXwxAH0aDQAAHVI"]
[Tue Jul 21 08:48:27.323538 2026] [security2:error] [pid 511108:tid 511267] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9ci4Td5soprXwxAH0aDQAAHVI"]
[Tue Jul 21 08:48:27.435537 2026] [security2:error] [pid 511108:tid 511333] [client 20.197.195.24:48987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/fpwch.php"] [unique_id "al9ci4Td5soprXwxAH0aEgAAAF8"]
[Tue Jul 21 08:48:27.438555 2026] [security2:error] [pid 514479:tid 514655] [client 20.151.10.161:28576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9ci_zqsQqnLoCgUjiAnwAAATM"]
[Tue Jul 21 08:48:27.503725 2026] [security2:error] [pid 514479:tid 514676] [client 20.151.10.161:8421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/ha.php"] [unique_id "al9ci_zqsQqnLoCgUjiAogAAAUg"]
[Tue Jul 21 08:48:27.553309 2026] [security2:error] [pid 511108:tid 511244] [client 185.8.106.219:27120] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.powertronicseguranca.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9ci4Td5soprXwxAH0aGQAAAAY"]
[Tue Jul 21 08:48:27.681373 2026] [security2:error] [pid 514479:tid 514667] [client 20.197.195.24:49022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/domvf.php"] [unique_id "al9ci_zqsQqnLoCgUjiAqAAAAT8"]
[Tue Jul 21 08:48:27.944309 2026] [security2:error] [pid 511108:tid 511338] [client 20.226.60.151:57654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/edorxrr.php"] [unique_id "al9ci4Td5soprXwxAH0aIQAAAGQ"]
[Tue Jul 21 08:48:28.000657 2026] [security2:error] [pid 514479:tid 514618] [client 20.151.10.161:28532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/f6.php"] [unique_id "al9ci_zqsQqnLoCgUjiArAAAAQ4"]
[Tue Jul 21 08:48:28.178829 2026] [core:error] [pid 514479:tid 514569] [remote 40.77.167.72:5501] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:48:28.178852 2026] [core:error] [pid 514479:tid 514569] [remote 40.77.167.72:5501] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:48:28.191918 2026] [security2:error] [pid 514479:tid 514639] [client 20.197.195.24:59808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/wp.php"] [unique_id "al9cjPzqsQqnLoCgUjiAsAAAASM"]
[Tue Jul 21 08:48:28.304444 2026] [core:error] [pid 514479:tid 514538] [remote 40.77.167.72:5501] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:48:28.304478 2026] [core:error] [pid 514479:tid 514538] [remote 40.77.167.72:5501] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:48:28.356941 2026] [security2:error] [pid 511108:tid 511220] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cjITd5soprXwxAH0aKQAAGG8"]
[Tue Jul 21 08:48:28.357093 2026] [security2:error] [pid 511108:tid 511262] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cjITd5soprXwxAH0aKQAAGG8"]
[Tue Jul 21 08:48:28.439262 2026] [security2:error] [pid 514479:tid 514680] [client 185.8.106.219:27122] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "powertronicseguranca.com"] [uri "/"] [unique_id "al9cjPzqsQqnLoCgUjiAswAAAUw"]
[Tue Jul 21 08:48:28.529123 2026] [security2:error] [pid 511108:tid 511340] [client 20.151.10.161:62404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/hur.php"] [unique_id "al9cjITd5soprXwxAH0aLAAAAGY"]
[Tue Jul 21 08:48:28.571971 2026] [security2:error] [pid 514479:tid 514719] [client 212.32.76.58:22587] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/wp-config/index.php"] [unique_id "al9cjPzqsQqnLoCgUjiAtQAAAXM"]
[Tue Jul 21 08:48:28.642234 2026] [security2:error] [pid 514479:tid 514674] [client 203.25.124.49:40683] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-security.php"] [unique_id "al9cjPzqsQqnLoCgUjiAtgAAAUY"]
[Tue Jul 21 08:48:28.858176 2026] [security2:error] [pid 514479:tid 514660] [client 203.25.124.2:35279] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9cjPzqsQqnLoCgUjiAuwAAATg"]
[Tue Jul 21 08:48:28.901370 2026] [security2:error] [pid 514479:tid 514703] [client 20.197.195.24:2706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/class.php"] [unique_id "al9cjPzqsQqnLoCgUjiAvAAAAWM"]
[Tue Jul 21 08:48:28.945609 2026] [security2:error] [pid 514479:tid 514652] [client 20.151.10.161:28493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/inputs.php"] [unique_id "al9cjPzqsQqnLoCgUjiAvgAAATA"]
[Tue Jul 21 08:48:29.205252 2026] [security2:error] [pid 511108:tid 511248] [client 152.59.181.104:65062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cjYTd5soprXwxAH0aOgAAAAo"]
[Tue Jul 21 08:48:29.205378 2026] [security2:error] [pid 511108:tid 511248] [client 152.59.181.104:65062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cjYTd5soprXwxAH0aOgAAAAo"]
[Tue Jul 21 08:48:29.233831 2026] [security2:error] [pid 514479:tid 514722] [client 20.151.10.161:62451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/h02ugyh.php"] [unique_id "al9cjfzqsQqnLoCgUjiAwQAAAXY"]
[Tue Jul 21 08:48:29.460713 2026] [security2:error] [pid 511108:tid 511267] [client 20.197.195.24:48899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/echkm.php"] [unique_id "al9cjYTd5soprXwxAH0aQQAAAB0"]
[Tue Jul 21 08:48:29.472717 2026] [security2:error] [pid 511108:tid 511284] [client 203.25.124.209:50339] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/cyber-security-blocks/parts/parts/user-edit.php"] [unique_id "al9cjYTd5soprXwxAH0aQgAAAC4"]
[Tue Jul 21 08:48:29.595682 2026] [security2:error] [pid 514479:tid 514733] [client 20.104.96.117:59138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/patie.php"] [unique_id "al9cjfzqsQqnLoCgUjiAyQAAAYE"]
[Tue Jul 21 08:48:29.695746 2026] [security2:error] [pid 514479:tid 514712] [client 114.198.138.124:61173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cjfzqsQqnLoCgUjiAzwAAAWw"]
[Tue Jul 21 08:48:29.700879 2026] [security2:error] [pid 514479:tid 514712] [client 114.198.138.124:61173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cjfzqsQqnLoCgUjiAzwAAAWw"]
[Tue Jul 21 08:48:29.801491 2026] [security2:error] [pid 514479:tid 514694] [client 20.151.10.161:62422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/seiso.php"] [unique_id "al9cjfzqsQqnLoCgUjiA0QAAAVo"]
[Tue Jul 21 08:48:29.881710 2026] [security2:error] [pid 514479:tid 514696] [client 203.25.124.69:20871] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/customize/wp-conflg.php"] [unique_id "al9cjfzqsQqnLoCgUjiA0wAAAVw"]
[Tue Jul 21 08:48:30.151867 2026] [security2:error] [pid 514479:tid 514680] [client 20.197.195.24:2708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/lib.php"] [unique_id "al9cjvzqsQqnLoCgUjiA2wAAAUw"]
[Tue Jul 21 08:48:30.221371 2026] [security2:error] [pid 514479:tid 514674] [client 20.151.10.161:28569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/av.php"] [unique_id "al9cjvzqsQqnLoCgUjiA3QAAAUY"]
[Tue Jul 21 08:48:30.371598 2026] [security2:error] [pid 514479:tid 514695] [client 212.32.76.58:46959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/shadow-bot.php"] [unique_id "al9cjvzqsQqnLoCgUjiA4AAAAVs"]
[Tue Jul 21 08:48:30.437905 2026] [security2:error] [pid 514479:tid 514681] [client 20.151.10.161:8323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/155.php"] [unique_id "al9cjvzqsQqnLoCgUjiA4gAAAU0"]
[Tue Jul 21 08:48:30.447309 2026] [security2:error] [pid 514479:tid 514672] [client 5.38.115.39:64150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cjvzqsQqnLoCgUjiA4wAAAUQ"]
[Tue Jul 21 08:48:30.447463 2026] [security2:error] [pid 514479:tid 514672] [client 5.38.115.39:64150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cjvzqsQqnLoCgUjiA4wAAAUQ"]
[Tue Jul 21 08:48:30.635744 2026] [security2:error] [pid 514479:tid 514722] [client 203.25.124.64:37977] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/system.php"] [unique_id "al9cjvzqsQqnLoCgUjiA5AAAAXY"]
[Tue Jul 21 08:48:30.650660 2026] [security2:error] [pid 514479:tid 514660] [client 31.57.219.92:62532] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "ocaminhodarecuperacao.com"] [uri "/"] [unique_id "al9cjvzqsQqnLoCgUjiA5QAAATg"]
[Tue Jul 21 08:48:30.812499 2026] [security2:error] [pid 514479:tid 514707] [client 59.95.197.55:65186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cjvzqsQqnLoCgUjiA6wAAAWc"]
[Tue Jul 21 08:48:30.812648 2026] [security2:error] [pid 514479:tid 514707] [client 59.95.197.55:65186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cjvzqsQqnLoCgUjiA6wAAAWc"]
[Tue Jul 21 08:48:30.832176 2026] [security2:error] [pid 514479:tid 514689] [client 20.226.60.151:59747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/miru1.php"] [unique_id "al9cjvzqsQqnLoCgUjiA7AAAAVU"]
[Tue Jul 21 08:48:30.891404 2026] [security2:error] [pid 514479:tid 514662] [client 20.151.10.161:62384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/ppp.php"] [unique_id "al9cjvzqsQqnLoCgUjiA7gAAATo"]
[Tue Jul 21 08:48:31.110039 2026] [security2:error] [pid 514479:tid 514618] [client 20.197.195.24:17733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/login.php"] [unique_id "al9cj_zqsQqnLoCgUjiA8AAAAQ4"]
[Tue Jul 21 08:48:31.318388 2026] [security2:error] [pid 514479:tid 514628] [client 122.176.100.127:50632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cj_zqsQqnLoCgUjiA9AAAARg"]
[Tue Jul 21 08:48:31.318567 2026] [security2:error] [pid 514479:tid 514628] [client 122.176.100.127:50632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cj_zqsQqnLoCgUjiA9AAAARg"]
[Tue Jul 21 08:48:31.364372 2026] [security2:error] [pid 514479:tid 514634] [client 212.32.76.10:46537] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/themes.php"] [unique_id "al9cj_zqsQqnLoCgUjiA-QAAAR4"]
[Tue Jul 21 08:48:31.370888 2026] [security2:error] [pid 511108:tid 511322] [client 20.151.10.161:62462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/201.php"] [unique_id "al9cj4Td5soprXwxAH0aYwAAAFQ"]
[Tue Jul 21 08:48:31.373551 2026] [security2:error] [pid 511108:tid 511339] [client 203.25.124.200:27159] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/html/html/dark-mode.php"] [unique_id "al9cj4Td5soprXwxAH0aZAAAAGU"]
[Tue Jul 21 08:48:31.488977 2026] [security2:error] [pid 511108:tid 511343] [client 20.151.10.161:28584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9cj4Td5soprXwxAH0aZgAAAGk"]
[Tue Jul 21 08:48:31.631553 2026] [security2:error] [pid 514479:tid 514679] [client 20.197.195.24:48927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/a2.php"] [unique_id "al9cj_zqsQqnLoCgUjiA-wAAAUs"]
[Tue Jul 21 08:48:31.866194 2026] [security2:error] [pid 514479:tid 514681] [client 20.151.10.161:8400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/ops.php"] [unique_id "al9cj_zqsQqnLoCgUjiBAQAAAU0"]
[Tue Jul 21 08:48:31.874760 2026] [security2:error] [pid 514479:tid 514611] [remote 151.123.177.57:14731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9cjvzqsQqnLoCgUjiA6AABIn4"]
[Tue Jul 21 08:48:32.088916 2026] [security2:error] [pid 514479:tid 514727] [client 103.59.206.240:31063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ckPzqsQqnLoCgUjiBBAAAAXs"]
[Tue Jul 21 08:48:32.089044 2026] [security2:error] [pid 514479:tid 514727] [client 103.59.206.240:31063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ckPzqsQqnLoCgUjiBBAAAAXs"]
[Tue Jul 21 08:48:32.270739 2026] [security2:error] [pid 511108:tid 511263] [client 203.25.124.9:45609] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/includes/menu-beta.php"] [unique_id "al9ckITd5soprXwxAH0acQAAABk"]
[Tue Jul 21 08:48:32.318347 2026] [security2:error] [pid 511108:tid 511257] [client 195.49.128.211:54215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ckITd5soprXwxAH0acwAAABM"]
[Tue Jul 21 08:48:32.318562 2026] [security2:error] [pid 511108:tid 511257] [client 195.49.128.211:54215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9ckITd5soprXwxAH0acwAAABM"]
[Tue Jul 21 08:48:32.429970 2026] [security2:error] [pid 514479:tid 514619] [client 20.151.10.161:28229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9ckPzqsQqnLoCgUjiBCgAAAQ8"]
[Tue Jul 21 08:48:32.476097 2026] [security2:error] [pid 511108:tid 511112] [remote 41.186.86.12:3217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/wp-login.php"] [unique_id "al9ckITd5soprXwxAH0aeQAAPgM"]
[Tue Jul 21 08:48:32.498135 2026] [security2:error] [pid 514479:tid 514733] [client 20.151.10.161:62420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/ingfo.php"] [unique_id "al9ckPzqsQqnLoCgUjiBCwAAAYE"]
[Tue Jul 21 08:48:32.537394 2026] [security2:error] [pid 511108:tid 511329] [client 203.25.124.2:64293] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/header.php"] [unique_id "al9ckITd5soprXwxAH0aegAAAFs"]
[Tue Jul 21 08:48:32.814574 2026] [security2:error] [pid 511108:tid 511255] [client 20.197.195.24:59838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/d61.php"] [unique_id "al9ckITd5soprXwxAH0afAAAABE"]
[Tue Jul 21 08:48:32.906367 2026] [security2:error] [pid 514479:tid 514634] [client 20.104.96.117:59191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/aa.php"] [unique_id "al9ckPzqsQqnLoCgUjiBFgAAAR4"]
[Tue Jul 21 08:48:33.036733 2026] [security2:error] [pid 514479:tid 514653] [client 20.226.60.151:57621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/sump1.php"] [unique_id "al9ckfzqsQqnLoCgUjiBFwAAATE"]
[Tue Jul 21 08:48:33.271166 2026] [security2:error] [pid 514479:tid 514700] [client 203.25.124.191:46445] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/block-bindings/lib/index.php"] [unique_id "al9ckfzqsQqnLoCgUjiBGQAAAWA"]
[Tue Jul 21 08:48:33.307614 2026] [security2:error] [pid 511108:tid 511359] [client 173.252.95.19:62600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ckYTd5soprXwxAH0aigAAAHk"]
[Tue Jul 21 08:48:33.344273 2026] [security2:error] [pid 511108:tid 511340] [client 20.151.10.161:62412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/error_log.php"] [unique_id "al9ckYTd5soprXwxAH0aiwAAAGY"]
[Tue Jul 21 08:48:33.472414 2026] [security2:error] [pid 511108:tid 511146] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ckYTd5soprXwxAH0akAAASyU"]
[Tue Jul 21 08:48:33.472537 2026] [security2:error] [pid 511108:tid 511313] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ckYTd5soprXwxAH0akAAASyU"]
[Tue Jul 21 08:48:33.515973 2026] [security2:error] [pid 514479:tid 514684] [client 173.252.95.59:57878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ckfzqsQqnLoCgUjiBIgAAAVA"]
[Tue Jul 21 08:48:33.537753 2026] [security2:error] [pid 514479:tid 514631] [client 20.151.10.161:28594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-blog.php"] [unique_id "al9ckfzqsQqnLoCgUjiBJAAAARs"]
[Tue Jul 21 08:48:33.596882 2026] [security2:error] [pid 511108:tid 511361] [client 113.22.144.139:49476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ckYTd5soprXwxAH0alAAAAHs"]
[Tue Jul 21 08:48:33.597023 2026] [security2:error] [pid 511108:tid 511361] [client 113.22.144.139:49476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ckYTd5soprXwxAH0alAAAAHs"]
[Tue Jul 21 08:48:33.712060 2026] [security2:error] [pid 514479:tid 514661] [client 74.7.175.165:58068] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "expovilhena.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9ckfzqsQqnLoCgUjiBJgABOUY"]
[Tue Jul 21 08:48:33.743026 2026] [security2:error] [pid 514479:tid 514629] [client 41.89.234.2:52388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ckfzqsQqnLoCgUjiBJwAAARk"]
[Tue Jul 21 08:48:33.743149 2026] [security2:error] [pid 514479:tid 514629] [client 41.89.234.2:52388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ckfzqsQqnLoCgUjiBJwAAARk"]
[Tue Jul 21 08:48:33.766026 2026] [security2:error] [pid 514479:tid 514676] [client 203.25.124.49:34743] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/fmadmin.php"] [unique_id "al9ckfzqsQqnLoCgUjiBKAAAAUg"]
[Tue Jul 21 08:48:33.780034 2026] [proxy:error] [pid 514479:tid 514689] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:48:33.780114 2026] [proxy_http:error] [pid 514479:tid 514689] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:48:33.780714 2026] [proxy:error] [pid 514479:tid 514689] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:48:33.780739 2026] [proxy_http:error] [pid 514479:tid 514689] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:48:33.941493 2026] [security2:error] [pid 514479:tid 514731] [client 203.25.124.43:51501] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/fonts/"] [unique_id "al9ckfzqsQqnLoCgUjiBLgAAAX8"]
[Tue Jul 21 08:48:33.981661 2026] [security2:error] [pid 514479:tid 514489] [remote 45.3.46.64:29719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9ckfzqsQqnLoCgUjiBMAABKwU"]
[Tue Jul 21 08:48:34.231820 2026] [security2:error] [pid 514479:tid 514666] [client 20.197.195.24:17762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/info.php"] [unique_id "al9ckvzqsQqnLoCgUjiBMwAAAT4"]
[Tue Jul 21 08:48:34.262523 2026] [security2:error] [pid 511108:tid 511267] [client 20.197.192.193:8327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/abcd.php"] [unique_id "al9ckoTd5soprXwxAH0anQAAAB0"]
[Tue Jul 21 08:48:34.266157 2026] [security2:error] [pid 514479:tid 514600] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ckvzqsQqnLoCgUjiBNAABZXM"]
[Tue Jul 21 08:48:34.266647 2026] [security2:error] [pid 514479:tid 514705] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9ckvzqsQqnLoCgUjiBNAABZXM"]
[Tue Jul 21 08:48:34.277386 2026] [security2:error] [pid 511108:tid 511342] [client 203.25.124.12:58471] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/network/theme-install-table.php"] [unique_id "al9ckoTd5soprXwxAH0angAAAGg"]
[Tue Jul 21 08:48:34.286063 2026] [proxy:error] [pid 511108:tid 511300] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:48:34.286171 2026] [proxy_http:error] [pid 511108:tid 511300] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:48:34.288447 2026] [proxy:error] [pid 511108:tid 511300] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:48:34.288531 2026] [proxy_http:error] [pid 511108:tid 511300] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:48:34.387640 2026] [security2:error] [pid 514479:tid 514696] [client 20.104.96.117:59144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/xwpg.php"] [unique_id "al9ckvzqsQqnLoCgUjiBNgAAAVw"]
[Tue Jul 21 08:48:34.608671 2026] [security2:error] [pid 511108:tid 511129] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ckoTd5soprXwxAH0apgAAfxQ"]
[Tue Jul 21 08:48:34.608838 2026] [security2:error] [pid 511108:tid 511365] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ckoTd5soprXwxAH0apgAAfxQ"]
[Tue Jul 21 08:48:34.632018 2026] [security2:error] [pid 511108:tid 511356] [client 20.197.195.24:2762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/11.php"] [unique_id "al9ckoTd5soprXwxAH0apwAAAHY"]
[Tue Jul 21 08:48:34.649014 2026] [security2:error] [pid 511108:tid 511335] [client 20.151.10.161:62341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/xenon1337.php"] [unique_id "al9ckoTd5soprXwxAH0aqAAAAGE"]
[Tue Jul 21 08:48:34.671606 2026] [security2:error] [pid 511108:tid 511265] [client 221.159.119.6:53140] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "wget http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "162.241.63.70"] [uri "/cgi-bin/luci/;stok=/locale"] [unique_id "al9ckoTd5soprXwxAH0aqQAAABs"]
[Tue Jul 21 08:48:34.679243 2026] [security2:error] [pid 511108:tid 511251] [client 20.197.192.193:8358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/xyn.php"] [unique_id "al9ckoTd5soprXwxAH0aqgAAAA0"]
[Tue Jul 21 08:48:34.687940 2026] [security2:error] [pid 514479:tid 514674] [client 20.226.60.151:57624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/file5.php"] [unique_id "al9ckvzqsQqnLoCgUjiBPgAAAUY"]
[Tue Jul 21 08:48:34.747300 2026] [security2:error] [pid 514479:tid 514681] [client 20.151.10.161:28058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9ckvzqsQqnLoCgUjiBPwAAAU0"]
[Tue Jul 21 08:48:34.885862 2026] [proxy:error] [pid 511108:tid 511302] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:48:34.885941 2026] [proxy_http:error] [pid 511108:tid 511302] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:48:34.886706 2026] [proxy:error] [pid 511108:tid 511302] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:48:34.886743 2026] [proxy_http:error] [pid 511108:tid 511302] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:48:34.939245 2026] [security2:error] [pid 511108:tid 511336] [client 20.197.195.24:2783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/v2.php"] [unique_id "al9ckoTd5soprXwxAH0asAAAAGI"]
[Tue Jul 21 08:48:35.002677 2026] [security2:error] [pid 511108:tid 511250] [client 221.159.119.6:53236] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (?:/count\\\\.cgi|^/magento/index\\\\.php/admin/dashboard/|^/images/stories/|^/content/pdf/media/print)" against "REQUEST_URI" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "421"] [id "340014"] [rev "17"] [msg "Atomicorp.com WAF Rules: CMD injection"] [data "wget http"] [severity "CRITICAL"] [tag "Command Injection"] [hostname "162.241.63.70"] [uri "/cgi-bin/luci/;stok=/locale"] [unique_id "al9ck4Td5soprXwxAH0atwAAAAw"]
[Tue Jul 21 08:48:35.064467 2026] [security2:error] [pid 514479:tid 514650] [client 212.32.76.9:28081] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/class.api.php"] [unique_id "al9ck_zqsQqnLoCgUjiBRgAAAS4"]
[Tue Jul 21 08:48:35.139450 2026] [security2:error] [pid 511108:tid 511339] [client 20.104.96.117:59167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ops.php"] [unique_id "al9ck4Td5soprXwxAH0avAAAAGU"]
[Tue Jul 21 08:48:35.281383 2026] [security2:error] [pid 511108:tid 511316] [client 203.25.124.198:58459] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/chosen.php"] [unique_id "al9ck4Td5soprXwxAH0avQAAAE4"]
[Tue Jul 21 08:48:35.282602 2026] [security2:error] [pid 511108:tid 511313] [client 20.151.10.161:28234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/adminfuns.php"] [unique_id "al9ck4Td5soprXwxAH0avgAAAEs"]
[Tue Jul 21 08:48:35.304061 2026] [security2:error] [pid 511108:tid 511203] [remote 20.153.140.50:41512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compressoresra.com.br"] [uri "/wp-login.php"] [unique_id "al9ck4Td5soprXwxAH0avwAAaV4"]
[Tue Jul 21 08:48:35.314259 2026] [security2:error] [pid 514479:tid 514661] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ck_zqsQqnLoCgUjiBSgAAATk"]
[Tue Jul 21 08:48:35.480120 2026] [security2:error] [pid 511108:tid 511312] [client 20.197.195.24:49001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/panel.php"] [unique_id "al9ck4Td5soprXwxAH0axQAAAEo"]
[Tue Jul 21 08:48:35.742530 2026] [security2:error] [pid 514479:tid 514731] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9ck_zqsQqnLoCgUjiBTgAAAX8"]
[Tue Jul 21 08:48:35.782446 2026] [security2:error] [pid 511108:tid 511323] [client 20.197.195.24:17753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/dex.php"] [unique_id "al9ck4Td5soprXwxAH0ayQAAAFU"]
[Tue Jul 21 08:48:36.068172 2026] [security2:error] [pid 514479:tid 514617] [client 20.151.10.161:28530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/goods.php"] [unique_id "al9clPzqsQqnLoCgUjiBVwAAAQ0"]
[Tue Jul 21 08:48:36.087473 2026] [security2:error] [pid 511108:tid 511280] [client 20.197.195.24:17780] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "efgaplicativos.online"] [uri "/1.php"] [unique_id "al9clITd5soprXwxAH0azwAAACo"]
[Tue Jul 21 08:48:36.087558 2026] [security2:error] [pid 511108:tid 511280] [client 20.197.195.24:17780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/1.php"] [unique_id "al9clITd5soprXwxAH0azwAAACo"]
[Tue Jul 21 08:48:36.139159 2026] [security2:error] [pid 514479:tid 514696] [client 203.25.124.36:25833] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/colors/ocean/"] [unique_id "al9clPzqsQqnLoCgUjiBWQAAAVw"]
[Tue Jul 21 08:48:36.248916 2026] [security2:error] [pid 511108:tid 511137] [remote 65.111.1.69:59007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.1.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9clITd5soprXwxAH0azgAAHRw"]
[Tue Jul 21 08:48:36.269209 2026] [security2:error] [pid 514479:tid 514639] [client 203.25.124.189:47651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/SimplePie/src/Content/autoload_classmap.php"] [unique_id "al9clPzqsQqnLoCgUjiBWwAAASM"]
[Tue Jul 21 08:48:36.316371 2026] [security2:error] [pid 511108:tid 511356] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9clITd5soprXwxAH0a0gAAAHY"]
[Tue Jul 21 08:48:36.358679 2026] [security2:error] [pid 514479:tid 514739] [client 203.25.124.47:28017] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "al9clPzqsQqnLoCgUjiBXQAAAYc"]
[Tue Jul 21 08:48:36.368357 2026] [security2:error] [pid 511108:tid 511265] [client 20.151.10.161:62397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/test11.php"] [unique_id "al9clITd5soprXwxAH0a0wAAABs"]
[Tue Jul 21 08:48:36.607607 2026] [security2:error] [pid 514479:tid 514663] [client 168.167.81.163:64493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9clPzqsQqnLoCgUjiBYQAAATs"]
[Tue Jul 21 08:48:36.607704 2026] [security2:error] [pid 514479:tid 514663] [client 168.167.81.163:64493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9clPzqsQqnLoCgUjiBYQAAATs"]
[Tue Jul 21 08:48:36.708717 2026] [security2:error] [pid 511108:tid 511315] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9clITd5soprXwxAH0a3QAAAE0"]
[Tue Jul 21 08:48:36.734607 2026] [security2:error] [pid 514479:tid 514691] [client 20.226.60.151:57601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/0xD.php"] [unique_id "al9clPzqsQqnLoCgUjiBYgAAAVc"]
[Tue Jul 21 08:48:36.762830 2026] [security2:error] [pid 514479:tid 514678] [client 20.104.96.117:59188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/mac.php"] [unique_id "al9clPzqsQqnLoCgUjiBYwAAAUo"]
[Tue Jul 21 08:48:36.826171 2026] [security2:error] [pid 511108:tid 511271] [client 20.151.10.161:62347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/koala.php"] [unique_id "al9clITd5soprXwxAH0a3gAAACE"]
[Tue Jul 21 08:48:36.841340 2026] [security2:error] [pid 511108:tid 511164] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9clITd5soprXwxAH0a3wAAMDc"]
[Tue Jul 21 08:48:36.841472 2026] [security2:error] [pid 511108:tid 511286] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9clITd5soprXwxAH0a3wAAMDc"]
[Tue Jul 21 08:48:37.045842 2026] [security2:error] [pid 511108:tid 511270] [client 203.25.124.73:21421] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/a.php"] [unique_id "al9clYTd5soprXwxAH0a4wAAACA"]
[Tue Jul 21 08:48:37.087979 2026] [security2:error] [pid 511108:tid 511334] [client 182.189.99.211:48352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9clYTd5soprXwxAH0a5wAAAGA"]
[Tue Jul 21 08:48:37.088508 2026] [security2:error] [pid 511108:tid 511334] [client 182.189.99.211:48352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9clYTd5soprXwxAH0a5wAAAGA"]
[Tue Jul 21 08:48:37.112603 2026] [security2:error] [pid 514479:tid 514650] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9clfzqsQqnLoCgUjiBaQAAAS4"]
[Tue Jul 21 08:48:37.170443 2026] [security2:error] [pid 511108:tid 511248] [client 203.25.124.37:27459] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/includes/index.php"] [unique_id "al9clYTd5soprXwxAH0a6QAAAAo"]
[Tue Jul 21 08:48:37.259772 2026] [security2:error] [pid 514479:tid 514706] [client 20.197.195.24:2756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/ms.php"] [unique_id "al9clfzqsQqnLoCgUjiBagAAAWY"]
[Tue Jul 21 08:48:37.260727 2026] [security2:error] [pid 514479:tid 514631] [client 20.151.10.161:62388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/mac.php"] [unique_id "al9clfzqsQqnLoCgUjiBawAAARs"]
[Tue Jul 21 08:48:37.274760 2026] [security2:error] [pid 514479:tid 514727] [client 203.25.124.254:23409] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/IXR/shadow-bot.php"] [unique_id "al9clfzqsQqnLoCgUjiBbAAAAXs"]
[Tue Jul 21 08:48:37.408620 2026] [security2:error] [pid 514479:tid 514676] [client 20.197.195.24:2744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/memberfuns.php"] [unique_id "al9clfzqsQqnLoCgUjiBcAAAAUg"]
[Tue Jul 21 08:48:37.602401 2026] [security2:error] [pid 514479:tid 514630] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9clfzqsQqnLoCgUjiBegAAARo"]
[Tue Jul 21 08:48:37.608518 2026] [security2:error] [pid 514479:tid 514660] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9clfzqsQqnLoCgUjiBcgABODE"]
[Tue Jul 21 08:48:37.786291 2026] [security2:error] [pid 514479:tid 514664] [client 20.197.195.24:48991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/0.php"] [unique_id "al9clfzqsQqnLoCgUjiBfQAAATw"]
[Tue Jul 21 08:48:37.824956 2026] [security2:error] [pid 514479:tid 514592] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9clfzqsQqnLoCgUjiBfgABhGs"]
[Tue Jul 21 08:48:37.825092 2026] [security2:error] [pid 514479:tid 514736] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9clfzqsQqnLoCgUjiBfgABhGs"]
[Tue Jul 21 08:48:37.883992 2026] [security2:error] [pid 514479:tid 514722] [client 45.146.55.189:39985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lumerah.com.br"] [uri "/wp-login.php"] [unique_id "al9ck_zqsQqnLoCgUjiBUAAAAXY"]
[Tue Jul 21 08:48:37.987902 2026] [security2:error] [pid 511108:tid 511215] [remote 5.252.52.249:53608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9clYTd5soprXwxAH0a8gAALmo"]
[Tue Jul 21 08:48:37.988412 2026] [security2:error] [pid 511108:tid 511290] [client 49.144.66.253:32226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9clYTd5soprXwxAH0a8wAAADQ"]
[Tue Jul 21 08:48:37.988520 2026] [security2:error] [pid 511108:tid 511290] [client 49.144.66.253:32226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9clYTd5soprXwxAH0a8wAAADQ"]
[Tue Jul 21 08:48:37.997529 2026] [security2:error] [pid 514479:tid 514654] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9clfzqsQqnLoCgUjiBfwAAATI"]
[Tue Jul 21 08:48:37.998973 2026] [security2:error] [pid 514479:tid 514625] [client 20.151.10.161:28587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ms-edit.php"] [unique_id "al9clfzqsQqnLoCgUjiBgAAAARU"]
[Tue Jul 21 08:48:38.004319 2026] [security2:error] [pid 514479:tid 514639] [client 20.197.192.193:9415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/byp8.php"] [unique_id "al9clvzqsQqnLoCgUjiBgQAAASM"]
[Tue Jul 21 08:48:38.039988 2026] [security2:error] [pid 514479:tid 514677] [client 20.197.195.24:2734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/BDKR28.php"] [unique_id "al9clvzqsQqnLoCgUjiBhAAAAUk"]
[Tue Jul 21 08:48:38.114309 2026] [security2:error] [pid 511108:tid 511333] [client 20.104.96.117:59689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/mg.php"] [unique_id "al9cloTd5soprXwxAH0a9gAAAF8"]
[Tue Jul 21 08:48:38.202865 2026] [security2:error] [pid 514479:tid 514620] [client 20.197.195.24:17825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/green1.php"] [unique_id "al9clvzqsQqnLoCgUjiBiwAAARA"]
[Tue Jul 21 08:48:38.247135 2026] [security2:error] [pid 514479:tid 514638] [client 20.226.60.151:57542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/fnstall.php"] [unique_id "al9clvzqsQqnLoCgUjiBjAAAASI"]
[Tue Jul 21 08:48:38.345082 2026] [security2:error] [pid 514479:tid 514670] [client 203.25.124.55:47851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/about.php"] [unique_id "al9clvzqsQqnLoCgUjiBjQAAAUI"]
[Tue Jul 21 08:48:38.376417 2026] [security2:error] [pid 514479:tid 514724] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9clvzqsQqnLoCgUjiBkAAAAXg"]
[Tue Jul 21 08:48:38.389111 2026] [security2:error] [pid 514479:tid 514633] [client 20.151.10.161:62340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9clvzqsQqnLoCgUjiBkQAAAR0"]
[Tue Jul 21 08:48:38.457253 2026] [security2:error] [pid 514479:tid 514676] [client 20.104.96.117:44118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9clvzqsQqnLoCgUjiBkwAAAUg"]
[Tue Jul 21 08:48:38.511252 2026] [security2:error] [pid 514479:tid 514667] [client 20.197.195.24:48968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/nc4.php"] [unique_id "al9clvzqsQqnLoCgUjiBlgAAAT8"]
[Tue Jul 21 08:48:38.563546 2026] [security2:error] [pid 514479:tid 514671] [client 212.32.76.9:30429] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9clvzqsQqnLoCgUjiBmAAAAUM"]
[Tue Jul 21 08:48:38.632408 2026] [security2:error] [pid 514479:tid 514582] [remote 192.249.127.213:33008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.127.249.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roha.life"] [uri "/wp-login.php"] [unique_id "al9clvzqsQqnLoCgUjiBmgABPmE"]
[Tue Jul 21 08:48:38.746253 2026] [proxy:error] [pid 514479:tid 514733] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:48:38.746289 2026] [proxy_http:error] [pid 514479:tid 514733] [client 140.248.75.63:3648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:48:38.746736 2026] [proxy:error] [pid 514479:tid 514733] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:48:38.746758 2026] [proxy_http:error] [pid 514479:tid 514733] [client 140.248.75.63:3648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:48:38.769195 2026] [security2:error] [pid 514479:tid 514718] [client 203.25.124.246:38111] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/chosen.php"] [unique_id "al9clvzqsQqnLoCgUjiBnwAAAXI"]
[Tue Jul 21 08:48:38.801227 2026] [security2:error] [pid 514479:tid 514625] [client 20.197.195.24:48971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/a1.php"] [unique_id "al9clvzqsQqnLoCgUjiBoAAAARU"]
[Tue Jul 21 08:48:38.820698 2026] [security2:error] [pid 511108:tid 511275] [client 20.104.96.117:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9cloTd5soprXwxAH0bBgAAACU"]
[Tue Jul 21 08:48:38.847012 2026] [security2:error] [pid 511108:tid 511244] [client 195.2.79.165:64605] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.2.79.165" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "gmtruckms.com"] [uri "/wp-comments-post.php"] [unique_id "al9cloTd5soprXwxAH0bCAAAAAY"], referer: https://gmtruckms.com/2023/11/30/hello-world/#comment-5598
[Tue Jul 21 08:48:38.847137 2026] [security2:error] [pid 511108:tid 511244] [client 195.2.79.165:64605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "gmtruckms.com"] [uri "/wp-comments-post.php"] [unique_id "al9cloTd5soprXwxAH0bCAAAAAY"], referer: https://gmtruckms.com/2023/11/30/hello-world/#comment-5598
[Tue Jul 21 08:48:38.857463 2026] [security2:error] [pid 511108:tid 511303] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9cloTd5soprXwxAH0bCQAAAEE"]
[Tue Jul 21 08:48:38.885487 2026] [security2:error] [pid 514479:tid 514528] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9clvzqsQqnLoCgUjiBoQABZyw"]
[Tue Jul 21 08:48:38.885652 2026] [security2:error] [pid 514479:tid 514707] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9clvzqsQqnLoCgUjiBoQABZyw"]
[Tue Jul 21 08:48:39.001311 2026] [security2:error] [pid 514479:tid 514681] [client 20.197.195.24:49018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/eee.php"] [unique_id "al9cl_zqsQqnLoCgUjiBowAAAU0"]
[Tue Jul 21 08:48:39.085731 2026] [security2:error] [pid 514479:tid 514616] [client 20.197.195.24:2779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/wp-aothait.php"] [unique_id "al9cl_zqsQqnLoCgUjiBpAAAAQw"]
[Tue Jul 21 08:48:39.237583 2026] [security2:error] [pid 514479:tid 514714] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9cl_zqsQqnLoCgUjiBpwAAAW4"]
[Tue Jul 21 08:48:39.242993 2026] [security2:error] [pid 511108:tid 511253] [client 20.197.195.24:17797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/config.json.php"] [unique_id "al9cl4Td5soprXwxAH0bDwAAAA8"]
[Tue Jul 21 08:48:39.277745 2026] [security2:error] [pid 514479:tid 514719] [client 72.13.62.5:42500] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "4inteligencia.com"] [uri "/index.php"] [unique_id "al9clvzqsQqnLoCgUjiBhwAAAXM"]
[Tue Jul 21 08:48:39.283905 2026] [security2:error] [pid 511108:tid 511361] [client 20.104.96.117:59137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-post-data.php"] [unique_id "al9cl4Td5soprXwxAH0bEwAAAHs"]
[Tue Jul 21 08:48:39.289095 2026] [security2:error] [pid 511108:tid 511334] [client 20.104.96.117:44115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/media.php"] [unique_id "al9cl4Td5soprXwxAH0bFAAAAGA"]
[Tue Jul 21 08:48:39.604279 2026] [security2:error] [pid 514479:tid 514628] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9cl_zqsQqnLoCgUjiBrQAAARg"]
[Tue Jul 21 08:48:39.632528 2026] [security2:error] [pid 514479:tid 514671] [client 20.104.96.117:44231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/images.php"] [unique_id "al9cl_zqsQqnLoCgUjiBsAAAAUM"]
[Tue Jul 21 08:48:39.651086 2026] [ssl:error] [pid 514479:tid 514636] [client 72.13.62.5:34139] AH02032: Hostname br1102.hostgator.com.br (default host as no SNI was provided) and hostname 4inteligencia.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue Jul 21 08:48:39.651169 2026] [security2:error] [pid 514479:tid 514636] [client 72.13.62.5:34139] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "421"] [hostname "4inteligencia.com"] [uri "/robots.txt"] [unique_id "al9cl_zqsQqnLoCgUjiBsQAAASA"]
[Tue Jul 21 08:48:39.705212 2026] [security2:error] [pid 514479:tid 514737] [client 20.197.195.24:2702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9cl_zqsQqnLoCgUjiBuAAAAYU"]
[Tue Jul 21 08:48:39.763895 2026] [security2:error] [pid 514479:tid 514622] [client 20.104.96.117:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/pucci.php"] [unique_id "al9cl_zqsQqnLoCgUjiBugAAARI"]
[Tue Jul 21 08:48:39.858976 2026] [proxy:error] [pid 511108:tid 511327] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:48:39.859012 2026] [proxy_http:error] [pid 511108:tid 511327] [client 140.248.75.63:3662] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:48:39.859697 2026] [proxy:error] [pid 511108:tid 511327] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:48:39.859724 2026] [proxy_http:error] [pid 511108:tid 511327] [client 140.248.75.63:3662] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:48:39.865895 2026] [security2:error] [pid 514479:tid 514639] [client 212.32.76.6:62323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/assets/index.php"] [unique_id "al9cl_zqsQqnLoCgUjiBvgAAASM"]
[Tue Jul 21 08:48:39.865967 2026] [security2:error] [pid 514479:tid 514625] [client 20.226.60.151:57647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/acp.php"] [unique_id "al9cl_zqsQqnLoCgUjiBvQAAARU"]
[Tue Jul 21 08:48:39.873605 2026] [security2:error] [pid 514479:tid 514643] [client 203.25.124.4:51235] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/prenota/gecko.php"] [unique_id "al9cl_zqsQqnLoCgUjiBvwAAASc"]
[Tue Jul 21 08:48:39.888908 2026] [security2:error] [pid 514479:tid 514634] [client 20.151.10.161:62456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wefile.php"] [unique_id "al9cl_zqsQqnLoCgUjiBwAAAAR4"]
[Tue Jul 21 08:48:39.948936 2026] [security2:error] [pid 514479:tid 514700] [client 152.59.181.104:49161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cl_zqsQqnLoCgUjiBwQAAAWA"]
[Tue Jul 21 08:48:39.949080 2026] [security2:error] [pid 514479:tid 514700] [client 152.59.181.104:49161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cl_zqsQqnLoCgUjiBwQAAAWA"]
[Tue Jul 21 08:48:39.982700 2026] [security2:error] [pid 514479:tid 514707] [client 20.104.96.117:44128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/gecko.php"] [unique_id "al9cl_zqsQqnLoCgUjiBwgAAAWc"]
[Tue Jul 21 08:48:40.024087 2026] [security2:error] [pid 514479:tid 514691] [client 20.197.195.24:48915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/k2.php"] [unique_id "al9cmPzqsQqnLoCgUjiBxQAAAVc"]
[Tue Jul 21 08:48:40.025400 2026] [security2:error] [pid 514479:tid 514688] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9cmPzqsQqnLoCgUjiBxgAAAVQ"]
[Tue Jul 21 08:48:40.227520 2026] [security2:error] [pid 514479:tid 514519] [remote 167.71.218.184:50076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9cmPzqsQqnLoCgUjiBywABPyM"]
[Tue Jul 21 08:48:40.275005 2026] [security2:error] [pid 514479:tid 514677] [client 114.198.138.124:61737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cmPzqsQqnLoCgUjiBzQAAAUk"]
[Tue Jul 21 08:48:40.275175 2026] [security2:error] [pid 514479:tid 514677] [client 114.198.138.124:61737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cmPzqsQqnLoCgUjiBzQAAAUk"]
[Tue Jul 21 08:48:40.351710 2026] [security2:error] [pid 514479:tid 514719] [client 20.104.96.117:44256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/82.php"] [unique_id "al9cmPzqsQqnLoCgUjiBzwAAAXM"]
[Tue Jul 21 08:48:40.425857 2026] [security2:error] [pid 514479:tid 514633] [client 20.197.195.24:2810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/uiuvs58l.php"] [unique_id "al9cmPzqsQqnLoCgUjiB0AAAAR0"]
[Tue Jul 21 08:48:40.426535 2026] [security2:error] [pid 514479:tid 514727] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9cmPzqsQqnLoCgUjiB0QAAAXs"]
[Tue Jul 21 08:48:40.731135 2026] [security2:error] [pid 511108:tid 511267] [client 20.220.225.223:46711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/dp.php"] [unique_id "al9cmITd5soprXwxAH0bJgAAAB0"]
[Tue Jul 21 08:48:40.769204 2026] [security2:error] [pid 511108:tid 511287] [client 20.197.195.24:64412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/40p9ixjd.php"] [unique_id "al9cmITd5soprXwxAH0bKAAAADE"]
[Tue Jul 21 08:48:40.837139 2026] [security2:error] [pid 511108:tid 511356] [client 20.104.96.117:59199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/black.php"] [unique_id "al9cmITd5soprXwxAH0bKgAAAHY"]
[Tue Jul 21 08:48:40.853279 2026] [security2:error] [pid 514479:tid 514733] [client 20.104.96.117:44284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/admin.php"] [unique_id "al9cmPzqsQqnLoCgUjiB2wAAAYE"]
[Tue Jul 21 08:48:40.873343 2026] [security2:error] [pid 514479:tid 514696] [client 203.25.124.9:24431] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/css/as.php"] [unique_id "al9cmPzqsQqnLoCgUjiB3gAAAVw"]
[Tue Jul 21 08:48:40.875657 2026] [security2:error] [pid 514479:tid 514622] [client 72.13.62.5:42500] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "4inteligencia.com"] [uri "/index.php"] [unique_id "al9cmPzqsQqnLoCgUjiB2AAAARI"]
[Tue Jul 21 08:48:40.964003 2026] [security2:error] [pid 511108:tid 511332] [client 203.25.124.212:49331] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "al9cmITd5soprXwxAH0bLAAAAF4"]
[Tue Jul 21 08:48:41.003213 2026] [security2:error] [pid 514479:tid 514675] [client 20.151.10.161:62392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9cmfzqsQqnLoCgUjiB5QAAAUc"]
[Tue Jul 21 08:48:41.057260 2026] [security2:error] [pid 511108:tid 511364] [client 20.197.192.193:9424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/user.php"] [unique_id "al9cmYTd5soprXwxAH0bLwAAAH4"]
[Tue Jul 21 08:48:41.096502 2026] [security2:error] [pid 514479:tid 514691] [client 20.226.60.151:57578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/mosty.php"] [unique_id "al9cmfzqsQqnLoCgUjiB5gAAAVc"]
[Tue Jul 21 08:48:41.102318 2026] [security2:error] [pid 511108:tid 511333] [client 5.38.115.39:64705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cmYTd5soprXwxAH0bMAAAAF8"]
[Tue Jul 21 08:48:41.102426 2026] [security2:error] [pid 511108:tid 511333] [client 5.38.115.39:64705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cmYTd5soprXwxAH0bMAAAAF8"]
[Tue Jul 21 08:48:41.248862 2026] [ssl:error] [pid 514479:tid 514674] [client 72.13.62.5:39967] AH02032: Hostname br1102.hostgator.com.br (default host as no SNI was provided) and hostname 4inteligencia.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Tue Jul 21 08:48:41.248941 2026] [security2:error] [pid 514479:tid 514631] [client 20.197.195.24:17730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/uiuvs58l.update.php"] [unique_id "al9cmfzqsQqnLoCgUjiB7AAAARs"]
[Tue Jul 21 08:48:41.248970 2026] [security2:error] [pid 514479:tid 514674] [client 72.13.62.5:39967] ModSecurity: Warning. Matched phrase "ips-agent" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "421"] [hostname "4inteligencia.com"] [uri "/"] [unique_id "al9cmfzqsQqnLoCgUjiB7QAAAUY"]
[Tue Jul 21 08:48:41.334765 2026] [security2:error] [pid 511108:tid 511276] [client 212.32.76.4:63497] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Requests/src/Exception/Transport/"] [unique_id "al9cmYTd5soprXwxAH0bPAAAACY"]
[Tue Jul 21 08:48:41.350270 2026] [security2:error] [pid 514479:tid 514738] [client 59.95.197.55:49278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cmfzqsQqnLoCgUjiB7gAAAYY"]
[Tue Jul 21 08:48:41.350419 2026] [security2:error] [pid 514479:tid 514738] [client 59.95.197.55:49278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cmfzqsQqnLoCgUjiB7gAAAYY"]
[Tue Jul 21 08:48:41.380554 2026] [security2:error] [pid 511108:tid 511318] [client 213.152.162.15:53922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9cmYTd5soprXwxAH0bQAAAAFA"]
[Tue Jul 21 08:48:41.380670 2026] [security2:error] [pid 511108:tid 511318] [client 213.152.162.15:53922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9cmYTd5soprXwxAH0bQAAAAFA"]
[Tue Jul 21 08:48:41.518235 2026] [security2:error] [pid 511108:tid 511250] [client 20.104.96.117:44263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/adminner.php"] [unique_id "al9cmYTd5soprXwxAH0bQgAAAAw"]
[Tue Jul 21 08:48:41.558492 2026] [security2:error] [pid 514479:tid 514723] [client 20.197.195.24:48982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/for.php"] [unique_id "al9cmfzqsQqnLoCgUjiB9AAAAXc"]
[Tue Jul 21 08:48:41.635024 2026] [security2:error] [pid 511108:tid 511343] [client 20.151.10.161:28278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/222.php"] [unique_id "al9cmYTd5soprXwxAH0bRwAAAGk"]
[Tue Jul 21 08:48:41.689702 2026] [security2:error] [pid 514479:tid 514556] [remote 81.173.115.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9cmfzqsQqnLoCgUjiB9gABGEc"], referer: http://assumaocontrole.com/
[Tue Jul 21 08:48:41.779852 2026] [security2:error] [pid 514479:tid 514681] [client 122.176.100.127:51116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cmfzqsQqnLoCgUjiB-gAAAU0"]
[Tue Jul 21 08:48:41.779951 2026] [security2:error] [pid 514479:tid 514681] [client 122.176.100.127:51116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cmfzqsQqnLoCgUjiB-gAAAU0"]
[Tue Jul 21 08:48:41.936786 2026] [security2:error] [pid 511108:tid 511263] [client 20.104.96.117:44257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/admin.php"] [unique_id "al9cmYTd5soprXwxAH0bUQAAABk"]
[Tue Jul 21 08:48:41.940491 2026] [security2:error] [pid 514479:tid 514694] [client 212.32.76.58:55019] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/home-link/wp-login.php"] [unique_id "al9cmfzqsQqnLoCgUjiB-QAAAVo"]
[Tue Jul 21 08:48:42.007243 2026] [security2:error] [pid 511108:tid 511323] [client 20.197.195.24:48996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "efgaplicativos.online"] [uri "/raw.php"] [unique_id "al9cmoTd5soprXwxAH0bUwAAAFU"]
[Tue Jul 21 08:48:42.226581 2026] [security2:error] [pid 511108:tid 511309] [client 20.151.10.161:62431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/2P.php"] [unique_id "al9cmoTd5soprXwxAH0bVwAAAEc"]
[Tue Jul 21 08:48:42.263354 2026] [security2:error] [pid 511108:tid 511342] [client 203.25.124.55:57929] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/load.php"] [unique_id "al9cmoTd5soprXwxAH0bWQAAAGg"]
[Tue Jul 21 08:48:42.280072 2026] [security2:error] [pid 514479:tid 514666] [client 202.28.194.139:33919] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "202.28.194.139" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "gmtruckms.com"] [uri "/wp-comments-post.php"] [unique_id "al9cmvzqsQqnLoCgUjiCAQAAAT4"], referer: https://gmtruckms.com/2023/11/30/hello-world/#comment-5598
[Tue Jul 21 08:48:42.280448 2026] [security2:error] [pid 514479:tid 514666] [client 202.28.194.139:33919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "gmtruckms.com"] [uri "/wp-comments-post.php"] [unique_id "al9cmvzqsQqnLoCgUjiCAQAAAT4"], referer: https://gmtruckms.com/2023/11/30/hello-world/#comment-5598
[Tue Jul 21 08:48:42.337045 2026] [security2:error] [pid 514479:tid 514651] [client 203.25.124.35:28883] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/network/"] [unique_id "al9cmvzqsQqnLoCgUjiCAgAAAS8"]
[Tue Jul 21 08:48:42.339450 2026] [security2:error] [pid 511108:tid 511279] [client 173.252.95.2:62760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cmoTd5soprXwxAH0bXwAAACk"]
[Tue Jul 21 08:48:42.355980 2026] [security2:error] [pid 514479:tid 514595] [remote 57.141.18.95:20388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9cmvzqsQqnLoCgUjiCBAABDG4"]
[Tue Jul 21 08:48:42.370937 2026] [security2:error] [pid 514479:tid 514674] [client 20.104.96.117:44240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/k.php"] [unique_id "al9cmvzqsQqnLoCgUjiCBgAAAUY"]
[Tue Jul 21 08:48:42.456463 2026] [security2:error] [pid 511108:tid 511306] [client 20.104.96.117:59651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/zlece.php"] [unique_id "al9cmoTd5soprXwxAH0bZAAAAEQ"]
[Tue Jul 21 08:48:42.591204 2026] [security2:error] [pid 514479:tid 514709] [client 20.226.60.151:59739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/6.php"] [unique_id "al9cmvzqsQqnLoCgUjiCDAAAAWk"]
[Tue Jul 21 08:48:42.736908 2026] [security2:error] [pid 514479:tid 514635] [client 20.104.96.117:44113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/blurbs.php"] [unique_id "al9cmvzqsQqnLoCgUjiCDQAAAR8"]
[Tue Jul 21 08:48:42.928404 2026] [security2:error] [pid 514479:tid 514718] [client 213.152.162.15:37034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9cmvzqsQqnLoCgUjiCEgAAAXI"]
[Tue Jul 21 08:48:42.928498 2026] [security2:error] [pid 514479:tid 514718] [client 213.152.162.15:37034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9cmvzqsQqnLoCgUjiCEgAAAXI"]
[Tue Jul 21 08:48:42.968103 2026] [security2:error] [pid 511108:tid 511246] [client 195.49.128.211:54816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cmoTd5soprXwxAH0bbgAAAAg"]
[Tue Jul 21 08:48:42.968204 2026] [security2:error] [pid 511108:tid 511246] [client 195.49.128.211:54816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cmoTd5soprXwxAH0bbgAAAAg"]
[Tue Jul 21 08:48:43.072392 2026] [security2:error] [pid 514479:tid 514673] [client 212.32.76.63:50519] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/fix/admin.php"] [unique_id "al9cm_zqsQqnLoCgUjiCFQAAAUU"]
[Tue Jul 21 08:48:43.239462 2026] [security2:error] [pid 511108:tid 511250] [client 20.104.96.117:44239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/bajah.php"] [unique_id "al9cm4Td5soprXwxAH0bcQAAAAw"]
[Tue Jul 21 08:48:43.244031 2026] [security2:error] [pid 514479:tid 514671] [client 20.151.10.161:62349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/.well-known/about.php"] [unique_id "al9cm_zqsQqnLoCgUjiCGAAAAUM"]
[Tue Jul 21 08:48:43.245296 2026] [security2:error] [pid 511108:tid 511253] [client 203.25.124.48:25809] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/profile.php"] [unique_id "al9cm4Td5soprXwxAH0bcgAAAA8"]
[Tue Jul 21 08:48:43.256952 2026] [security2:error] [pid 514479:tid 514663] [client 20.220.225.223:22588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/old.php"] [unique_id "al9cm_zqsQqnLoCgUjiCGgAAATs"]
[Tue Jul 21 08:48:43.266107 2026] [security2:error] [pid 514479:tid 514715] [client 20.226.60.151:57588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9cm_zqsQqnLoCgUjiCGwAAAW8"]
[Tue Jul 21 08:48:43.302667 2026] [proxy:error] [pid 514479:tid 514691] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:48:43.302771 2026] [proxy_http:error] [pid 514479:tid 514691] [client 143.198.104.129:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:48:43.304659 2026] [proxy:error] [pid 514479:tid 514691] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:48:43.304722 2026] [proxy_http:error] [pid 514479:tid 514691] [client 143.198.104.129:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:48:43.447931 2026] [security2:error] [pid 514479:tid 514706] [client 20.197.192.193:9417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/ops.php"] [unique_id "al9cm_zqsQqnLoCgUjiCIAAAAWY"]
[Tue Jul 21 08:48:43.470180 2026] [security2:error] [pid 514479:tid 514651] [client 20.151.10.161:28590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9cm_zqsQqnLoCgUjiCIQAAAS8"]
[Tue Jul 21 08:48:43.646845 2026] [proxy:error] [pid 514479:tid 514661] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:48:43.646910 2026] [proxy_http:error] [pid 514479:tid 514661] [client 143.198.104.129:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.tiagorochaamorim1781889826254.0711679.meusitehostgator.com.br/
[Tue Jul 21 08:48:43.647367 2026] [proxy:error] [pid 514479:tid 514661] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:48:43.647388 2026] [proxy_http:error] [pid 514479:tid 514661] [client 143.198.104.129:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.tiagorochaamorim1781889826254.0711679.meusitehostgator.com.br/
[Tue Jul 21 08:48:43.747282 2026] [security2:error] [pid 514479:tid 514739] [client 103.59.206.240:31390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cm_zqsQqnLoCgUjiCJwAAAYc"]
[Tue Jul 21 08:48:43.747868 2026] [security2:error] [pid 514479:tid 514739] [client 103.59.206.240:31390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cm_zqsQqnLoCgUjiCJwAAAYc"]
[Tue Jul 21 08:48:43.750854 2026] [security2:error] [pid 514479:tid 514623] [client 20.104.96.117:61163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/vssrs.php"] [unique_id "al9cm_zqsQqnLoCgUjiCKAAAARM"]
[Tue Jul 21 08:48:43.989231 2026] [security2:error] [pid 514479:tid 514633] [client 114.119.135.57:44993] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.insp1.com.br"] [uri "/single-post/2019/08/12/psicomotricidade-no%C3%A7%C3%A3o-de-espa%C3%A7o-e-capacidade-de-socializa%C3%A7%C3%A3o-s%C3%A3o-pr%C3%A1ticas-di%C3%A1rias-no-mat"] [unique_id "al9cm_zqsQqnLoCgUjiCLwAAAR0"], referer: https://www.insp1.com.br/single-post/2019/08/12/psicomotricidade-no%C3%A7%C3%A3o-de-espa%C3%A7o-e-capacidade-de-socializa%C3%A7%C3%A3o-s%C3%A3o-pr%C3%A1ticas-di%C3%A1rias-no-mat
[Tue Jul 21 08:48:44.003998 2026] [security2:error] [pid 511108:tid 511282] [client 20.226.60.151:59714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/qqqa.php"] [unique_id "al9cnITd5soprXwxAH0bhAAAACw"]
[Tue Jul 21 08:48:44.027500 2026] [security2:error] [pid 511108:tid 511309] [client 20.104.96.117:44121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/a.php"] [unique_id "al9cnITd5soprXwxAH0bhQAAAEc"]
[Tue Jul 21 08:48:44.075281 2026] [security2:error] [pid 514479:tid 514715] [client 212.32.76.65:29565] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/fix/ioxi-o.php"] [unique_id "al9cnPzqsQqnLoCgUjiCMgAAAW8"]
[Tue Jul 21 08:48:44.272298 2026] [security2:error] [pid 514479:tid 514719] [client 41.89.234.2:44521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cnPzqsQqnLoCgUjiCOAAAAXM"]
[Tue Jul 21 08:48:44.272544 2026] [security2:error] [pid 514479:tid 514719] [client 41.89.234.2:44521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cnPzqsQqnLoCgUjiCOAAAAXM"]
[Tue Jul 21 08:48:44.338421 2026] [security2:error] [pid 514479:tid 514494] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cnPzqsQqnLoCgUjiCOQABJwo"]
[Tue Jul 21 08:48:44.338716 2026] [security2:error] [pid 514479:tid 514643] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cnPzqsQqnLoCgUjiCOQABJwo"]
[Tue Jul 21 08:48:44.368010 2026] [security2:error] [pid 514479:tid 514666] [client 212.32.76.7:23455] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/index.php"] [unique_id "al9cnPzqsQqnLoCgUjiCOwAAAT4"]
[Tue Jul 21 08:48:44.403391 2026] [security2:error] [pid 514479:tid 514626] [client 113.22.144.139:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cnPzqsQqnLoCgUjiCPwAAARY"]
[Tue Jul 21 08:48:44.403856 2026] [security2:error] [pid 514479:tid 514626] [client 113.22.144.139:50008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cnPzqsQqnLoCgUjiCPwAAARY"]
[Tue Jul 21 08:48:44.532174 2026] [security2:error] [pid 514479:tid 514727] [client 20.104.96.117:59671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wicked.php"] [unique_id "al9cnPzqsQqnLoCgUjiCQQAAAXs"]
[Tue Jul 21 08:48:44.578874 2026] [security2:error] [pid 514479:tid 514662] [client 185.213.175.37:53680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bomexito.com.br"] [uri "/"] [unique_id "al9cnPzqsQqnLoCgUjiCQwAAATo"]
[Tue Jul 21 08:48:44.578965 2026] [security2:error] [pid 514479:tid 514662] [client 185.213.175.37:53680] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bomexito.com.br"] [uri "/"] [unique_id "al9cnPzqsQqnLoCgUjiCQwAAATo"]
[Tue Jul 21 08:48:44.584648 2026] [security2:error] [pid 514479:tid 514649] [client 20.104.96.117:44283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/edit.php"] [unique_id "al9cnPzqsQqnLoCgUjiCTgAAAS0"]
[Tue Jul 21 08:48:44.849480 2026] [security2:error] [pid 511108:tid 511333] [client 20.151.10.161:62343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9cnITd5soprXwxAH0blwAAAF8"]
[Tue Jul 21 08:48:44.925464 2026] [security2:error] [pid 514479:tid 514697] [client 20.104.96.117:59679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/24.php"] [unique_id "al9cnPzqsQqnLoCgUjiCjgAAAV0"]
[Tue Jul 21 08:48:44.929483 2026] [security2:error] [pid 514479:tid 514732] [client 20.104.96.117:44255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/hosty.php"] [unique_id "al9cnPzqsQqnLoCgUjiCkAAAAYA"]
[Tue Jul 21 08:48:44.959608 2026] [security2:error] [pid 511108:tid 511114] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cnITd5soprXwxAH0bmwAAQwU"]
[Tue Jul 21 08:48:44.959736 2026] [security2:error] [pid 511108:tid 511305] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cnITd5soprXwxAH0bmwAAQwU"]
[Tue Jul 21 08:48:45.286741 2026] [security2:error] [pid 514479:tid 514716] [client 20.104.96.117:44242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/k.php"] [unique_id "al9cnfzqsQqnLoCgUjiCnwAAAXA"]
[Tue Jul 21 08:48:45.290744 2026] [security2:error] [pid 514479:tid 514626] [client 20.226.60.151:57611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/aunmc.php"] [unique_id "al9cnfzqsQqnLoCgUjiCoAAAARY"]
[Tue Jul 21 08:48:45.376350 2026] [autoindex:error] [pid 514479:tid 514665] [client 186.202.163.107:33309] AH01276: Cannot serve directory /home2/prove728/public_html/sinalogistica.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:48:45.525917 2026] [security2:error] [pid 514479:tid 514603] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cnfzqsQqnLoCgUjiCrQABgXY"]
[Tue Jul 21 08:48:45.526110 2026] [security2:error] [pid 514479:tid 514733] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cnfzqsQqnLoCgUjiCrQABgXY"]
[Tue Jul 21 08:48:45.578434 2026] [security2:error] [pid 511108:tid 511319] [client 20.104.96.117:59157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/xacs.php"] [unique_id "al9cnYTd5soprXwxAH0bogAAAFE"]
[Tue Jul 21 08:48:45.611337 2026] [security2:error] [pid 514479:tid 514737] [client 20.151.10.161:28557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9cnfzqsQqnLoCgUjiCsgAAAYU"]
[Tue Jul 21 08:48:45.655004 2026] [security2:error] [pid 514479:tid 514660] [client 20.104.96.117:44110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/aaa.php"] [unique_id "al9cnfzqsQqnLoCgUjiCswAAATg"]
[Tue Jul 21 08:48:45.974615 2026] [security2:error] [pid 514479:tid 514678] [client 20.104.96.117:44233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/file5.php"] [unique_id "al9cnfzqsQqnLoCgUjiCtwAAAUo"]
[Tue Jul 21 08:48:46.048061 2026] [security2:error] [pid 514479:tid 514740] [client 203.25.124.53:63595] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/tinymce/utils/"] [unique_id "al9cnvzqsQqnLoCgUjiCuQAAAYg"]
[Tue Jul 21 08:48:46.060468 2026] [security2:error] [pid 514479:tid 514626] [client 212.32.76.12:27749] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/k.php"] [unique_id "al9cnvzqsQqnLoCgUjiCuwAAARY"]
[Tue Jul 21 08:48:46.258406 2026] [security2:error] [pid 514479:tid 514714] [client 20.226.60.151:57646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/uoocf.php"] [unique_id "al9cnvzqsQqnLoCgUjiCvgAAAW4"]
[Tue Jul 21 08:48:46.259865 2026] [security2:error] [pid 514479:tid 514665] [client 20.104.96.117:44139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/222.php"] [unique_id "al9cnvzqsQqnLoCgUjiCvwAAAT0"]
[Tue Jul 21 08:48:46.544513 2026] [security2:error] [pid 514479:tid 514737] [client 20.104.96.117:44120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/test.php"] [unique_id "al9cnvzqsQqnLoCgUjiCxgAAAYU"]
[Tue Jul 21 08:48:46.725584 2026] [security2:error] [pid 511108:tid 511266] [client 20.151.10.161:62362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/bob.php"] [unique_id "al9cnoTd5soprXwxAH0brwAAABw"]
[Tue Jul 21 08:48:46.837393 2026] [security2:error] [pid 511108:tid 511270] [client 20.226.60.151:57582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/iywwi.php"] [unique_id "al9cnoTd5soprXwxAH0bsgAAACA"]
[Tue Jul 21 08:48:46.875121 2026] [security2:error] [pid 511108:tid 511355] [client 20.104.96.117:44213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/aaa.php"] [unique_id "al9cnoTd5soprXwxAH0bswAAAHU"]
[Tue Jul 21 08:48:46.959755 2026] [security2:error] [pid 514479:tid 514715] [client 212.32.76.7:33247] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-conflg.php"] [unique_id "al9cnvzqsQqnLoCgUjiCyQAAAW8"]
[Tue Jul 21 08:48:46.972142 2026] [security2:error] [pid 514479:tid 514675] [client 212.32.76.56:57813] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/ioxi-o.php"] [unique_id "al9cnvzqsQqnLoCgUjiCygAAAUc"]
[Tue Jul 21 08:48:47.028237 2026] [security2:error] [pid 514479:tid 514620] [client 20.226.60.151:57550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/gqgsa.php"] [unique_id "al9cn_zqsQqnLoCgUjiCzQAAARA"]
[Tue Jul 21 08:48:47.124498 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.124594 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.124712 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.124766 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.124832 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.124971 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125065 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125122 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125198 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125251 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125303 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125356 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125407 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125459 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125510 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125563 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125614 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125666 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125719 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125771 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125832 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125884 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125945 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.125997 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126049 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126101 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126153 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126205 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126313 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126367 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126418 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126470 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126521 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126573 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126625 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126677 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126730 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126784 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126865 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.126917 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127000 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127060 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127111 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127159 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127216 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127268 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127319 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127371 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127439 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127493 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127548 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127601 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127653 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127707 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127759 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127819 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127875 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127933 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.127983 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128035 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128091 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128142 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128194 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128262 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128317 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128370 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128431 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128486 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128537 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128592 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128649 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128703 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128761 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128820 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128875 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128936 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.128982 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129033 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129085 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129136 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129191 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129242 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129294 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129345 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129397 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129448 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129501 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129555 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129607 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129658 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129715 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129768 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129841 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129895 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.129964 2026] [lsapi:warn] [pid 511108:tid 511135] [remote 189.6.178.120:49569] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:47.132668 2026] [security2:error] [pid 514479:tid 514681] [client 20.104.96.117:59685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/zildan.php"] [unique_id "al9cn_zqsQqnLoCgUjiC0gAAAU0"]
[Tue Jul 21 08:48:47.233060 2026] [security2:error] [pid 514479:tid 514724] [client 20.104.96.117:44268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/11.php"] [unique_id "al9cn_zqsQqnLoCgUjiC1gAAAXg"]
[Tue Jul 21 08:48:47.239093 2026] [security2:error] [pid 514479:tid 514665] [client 203.25.124.36:44475] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/block-patterns/"] [unique_id "al9cn_zqsQqnLoCgUjiC1wAAAT0"]
[Tue Jul 21 08:48:47.288506 2026] [security2:error] [pid 511108:tid 511191] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cn4Td5soprXwxAH0cAQAAVVI"]
[Tue Jul 21 08:48:47.289086 2026] [security2:error] [pid 511108:tid 511323] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cn4Td5soprXwxAH0cAQAAVVI"]
[Tue Jul 21 08:48:47.490254 2026] [security2:error] [pid 514479:tid 514671] [client 65.21.113.253:48674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cn_zqsQqnLoCgUjiC2AAAAUM"]
[Tue Jul 21 08:48:47.557762 2026] [security2:error] [pid 511108:tid 511312] [client 182.189.99.211:47737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cn4Td5soprXwxAH0cEwAAAEo"]
[Tue Jul 21 08:48:47.557932 2026] [security2:error] [pid 511108:tid 511312] [client 182.189.99.211:47737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cn4Td5soprXwxAH0cEwAAAEo"]
[Tue Jul 21 08:48:47.586089 2026] [security2:error] [pid 511108:tid 511256] [client 20.104.96.117:44259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/mac.php"] [unique_id "al9cn4Td5soprXwxAH0cGgAAABI"]
[Tue Jul 21 08:48:47.631060 2026] [security2:error] [pid 511108:tid 511283] [client 20.151.10.161:28263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp.php"] [unique_id "al9cn4Td5soprXwxAH0cHwAAAC0"]
[Tue Jul 21 08:48:47.868875 2026] [security2:error] [pid 511108:tid 511340] [client 20.104.96.117:44280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/chosen.php"] [unique_id "al9cn4Td5soprXwxAH0cJAAAAGY"]
[Tue Jul 21 08:48:48.020038 2026] [security2:error] [pid 511108:tid 511321] [client 20.104.96.117:59148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/csa.php"] [unique_id "al9coITd5soprXwxAH0cKgAAAFM"]
[Tue Jul 21 08:48:48.038508 2026] [security2:error] [pid 514479:tid 514731] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cn_zqsQqnLoCgUjiC4AABfzk"]
[Tue Jul 21 08:48:48.064974 2026] [security2:error] [pid 511108:tid 511266] [client 203.25.124.37:64001] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/block-bindings/"] [unique_id "al9coITd5soprXwxAH0cLAAAABw"]
[Tue Jul 21 08:48:48.237009 2026] [security2:error] [pid 514479:tid 514625] [client 20.104.96.117:44127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/cream1.php"] [unique_id "al9coPzqsQqnLoCgUjiC5AAAARU"]
[Tue Jul 21 08:48:48.245740 2026] [security2:error] [pid 511108:tid 511285] [client 5.31.193.106:58611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9coITd5soprXwxAH0cMQAAAC8"]
[Tue Jul 21 08:48:48.245852 2026] [security2:error] [pid 511108:tid 511285] [client 5.31.193.106:58611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9coITd5soprXwxAH0cMQAAAC8"]
[Tue Jul 21 08:48:48.277901 2026] [security2:error] [pid 514479:tid 514741] [client 203.25.124.10:20217] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wpx/index.php"] [unique_id "al9coPzqsQqnLoCgUjiC5QAAAYk"]
[Tue Jul 21 08:48:48.294256 2026] [security2:error] [pid 511108:tid 511257] [client 20.226.60.151:57565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/elbzl.php"] [unique_id "al9coITd5soprXwxAH0cMwAAABM"]
[Tue Jul 21 08:48:48.330959 2026] [security2:error] [pid 511108:tid 511253] [client 49.144.66.253:32634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9coITd5soprXwxAH0cNAAAAA8"]
[Tue Jul 21 08:48:48.331205 2026] [security2:error] [pid 511108:tid 511253] [client 49.144.66.253:32634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9coITd5soprXwxAH0cNAAAAA8"]
[Tue Jul 21 08:48:48.344418 2026] [security2:error] [pid 511108:tid 511218] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9coITd5soprXwxAH0cNQAACm0"]
[Tue Jul 21 08:48:48.344657 2026] [security2:error] [pid 511108:tid 511248] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9coITd5soprXwxAH0cNQAACm0"]
[Tue Jul 21 08:48:48.379276 2026] [security2:error] [pid 514479:tid 514675] [client 198.44.157.34:43162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9coPzqsQqnLoCgUjiC5gAAAUc"]
[Tue Jul 21 08:48:48.379407 2026] [security2:error] [pid 514479:tid 514675] [client 198.44.157.34:43162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9coPzqsQqnLoCgUjiC5gAAAUc"]
[Tue Jul 21 08:48:48.566250 2026] [autoindex:error] [pid 511108:tid 511309] [client 20.104.96.117:0] AH01276: Cannot serve directory /home3/gadelh32/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:48:48.639092 2026] [security2:error] [pid 511108:tid 511279] [client 20.104.96.117:59677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/w3llscc.php"] [unique_id "al9coITd5soprXwxAH0cPQAAACk"]
[Tue Jul 21 08:48:48.645356 2026] [security2:error] [pid 511108:tid 511301] [client 65.21.113.253:48676] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9coITd5soprXwxAH0cMAAAAD8"]
[Tue Jul 21 08:48:48.743355 2026] [security2:error] [pid 514479:tid 514706] [client 212.32.76.14:33101] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwentythree/patterns/template-singl-portfolio.php"] [unique_id "al9coPzqsQqnLoCgUjiC7AAAAWY"]
[Tue Jul 21 08:48:48.884728 2026] [autoindex:error] [pid 514479:tid 514716] [client 20.104.96.117:0] AH01276: Cannot serve directory /home3/gadelh32/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:48:48.894216 2026] [security2:error] [pid 511108:tid 511364] [client 20.151.10.161:8414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/crgio.php"] [unique_id "al9coITd5soprXwxAH0cQwAAAH4"]
[Tue Jul 21 08:48:49.036800 2026] [security2:error] [pid 514479:tid 514724] [client 20.104.96.117:44112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/dr.php"] [unique_id "al9cofzqsQqnLoCgUjiC8gAAAXg"]
[Tue Jul 21 08:48:49.111630 2026] [security2:error] [pid 511108:tid 511202] [remote 159.65.81.207:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cristaofitsuplementos.com"] [uri "/wp-login.php"] [unique_id "al9coYTd5soprXwxAH0cSAAAEl0"]
[Tue Jul 21 08:48:49.172109 2026] [security2:error] [pid 514479:tid 514723] [client 212.32.76.10:22835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-confiq.php"] [unique_id "al9cofzqsQqnLoCgUjiC9AAAAXc"]
[Tue Jul 21 08:48:49.207381 2026] [security2:error] [pid 511108:tid 511342] [client 168.167.81.163:61735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9coYTd5soprXwxAH0cSwAAAGg"]
[Tue Jul 21 08:48:49.207483 2026] [security2:error] [pid 511108:tid 511342] [client 168.167.81.163:61735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9coYTd5soprXwxAH0cSwAAAGg"]
[Tue Jul 21 08:48:49.207822 2026] [security2:error] [pid 514479:tid 514649] [client 20.151.10.161:28252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/abcd.php"] [unique_id "al9cofzqsQqnLoCgUjiC9QAAAS0"]
[Tue Jul 21 08:48:49.296921 2026] [security2:error] [pid 514479:tid 514696] [client 20.104.96.117:59683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wpx.php"] [unique_id "al9cofzqsQqnLoCgUjiC-AAAAVw"]
[Tue Jul 21 08:48:49.328721 2026] [security2:error] [pid 514479:tid 514737] [client 20.104.96.117:44262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/x.php"] [unique_id "al9cofzqsQqnLoCgUjiC-wAAAYU"]
[Tue Jul 21 08:48:49.409948 2026] [security2:error] [pid 514479:tid 514487] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cofzqsQqnLoCgUjiC_wABYgM"]
[Tue Jul 21 08:48:49.410126 2026] [security2:error] [pid 514479:tid 514702] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cofzqsQqnLoCgUjiC_wABYgM"]
[Tue Jul 21 08:48:49.572573 2026] [security2:error] [pid 514479:tid 514620] [client 20.226.60.151:57580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/adjig.php"] [unique_id "al9cofzqsQqnLoCgUjiDAwAAARA"]
[Tue Jul 21 08:48:49.627883 2026] [security2:error] [pid 514479:tid 514718] [client 20.104.96.117:44246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/155.php"] [unique_id "al9cofzqsQqnLoCgUjiDBgAAAXI"]
[Tue Jul 21 08:48:49.881365 2026] [security2:error] [pid 514479:tid 514707] [client 20.104.96.117:59698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-css.php"] [unique_id "al9cofzqsQqnLoCgUjiDDAAAAWc"]
[Tue Jul 21 08:48:49.925121 2026] [security2:error] [pid 511108:tid 511295] [client 20.104.96.117:44228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/ops.php"] [unique_id "al9coYTd5soprXwxAH0cUwAAADk"]
[Tue Jul 21 08:48:50.044506 2026] [security2:error] [pid 514479:tid 514677] [client 212.32.76.12:20739] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/certificates/"] [unique_id "al9covzqsQqnLoCgUjiDDwAAAUk"]
[Tue Jul 21 08:48:50.166536 2026] [security2:error] [pid 511108:tid 511355] [client 212.32.76.2:32495] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/fm.php/sts.php"] [unique_id "al9cooTd5soprXwxAH0cWAAAAHU"]
[Tue Jul 21 08:48:50.203803 2026] [security2:error] [pid 511108:tid 511313] [client 20.104.96.117:44137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/file31.php"] [unique_id "al9cooTd5soprXwxAH0cWQAAAEs"]
[Tue Jul 21 08:48:50.486731 2026] [security2:error] [pid 511108:tid 511254] [client 20.104.96.117:44104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/file6.php"] [unique_id "al9cooTd5soprXwxAH0cYgAAABA"]
[Tue Jul 21 08:48:50.572046 2026] [security2:error] [pid 514479:tid 514664] [client 203.25.124.203:62955] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-matcha1.php"] [unique_id "al9covzqsQqnLoCgUjiDFAAAATw"]
[Tue Jul 21 08:48:50.577382 2026] [security2:error] [pid 511108:tid 511238] [client 20.104.96.117:59171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ho.php"] [unique_id "al9cooTd5soprXwxAH0cZAAAAAA"]
[Tue Jul 21 08:48:50.617865 2026] [security2:error] [pid 514479:tid 514737] [client 20.226.60.151:59723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/byp.php"] [unique_id "al9covzqsQqnLoCgUjiDGQAAAYU"]
[Tue Jul 21 08:48:50.631704 2026] [security2:error] [pid 511108:tid 511276] [client 152.59.181.104:49648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cooTd5soprXwxAH0cZgAAACY"]
[Tue Jul 21 08:48:50.631807 2026] [security2:error] [pid 511108:tid 511276] [client 152.59.181.104:49648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cooTd5soprXwxAH0cZgAAACY"]
[Tue Jul 21 08:48:50.631839 2026] [security2:error] [pid 514479:tid 514660] [client 20.197.192.193:9543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/term.php"] [unique_id "al9covzqsQqnLoCgUjiDGgAAATg"]
[Tue Jul 21 08:48:50.819696 2026] [autoindex:error] [pid 514479:tid 514626] [client 20.104.96.117:0] AH01276: Cannot serve directory /home3/gadelh32/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:48:50.893742 2026] [security2:error] [pid 511108:tid 511350] [client 114.198.138.124:62324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cooTd5soprXwxAH0cagAAAHA"]
[Tue Jul 21 08:48:50.893894 2026] [security2:error] [pid 511108:tid 511350] [client 114.198.138.124:62324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cooTd5soprXwxAH0cagAAAHA"]
[Tue Jul 21 08:48:50.972084 2026] [security2:error] [pid 514479:tid 514677] [client 20.151.10.161:28595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/a1.php"] [unique_id "al9covzqsQqnLoCgUjiDIwAAAUk"]
[Tue Jul 21 08:48:51.094229 2026] [security2:error] [pid 514479:tid 514665] [client 20.104.96.117:44162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/adminfuns.php"] [unique_id "al9co_zqsQqnLoCgUjiDJQAAAT0"]
[Tue Jul 21 08:48:51.261286 2026] [security2:error] [pid 511108:tid 511333] [client 212.32.76.8:27351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/upload/index.php"] [unique_id "al9co4Td5soprXwxAH0ccgAAAF8"]
[Tue Jul 21 08:48:51.340485 2026] [security2:error] [pid 514479:tid 514697] [client 20.104.96.117:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/xy.php"] [unique_id "al9co_zqsQqnLoCgUjiDPAAAAV0"]
[Tue Jul 21 08:48:51.386875 2026] [security2:error] [pid 514479:tid 514707] [client 20.104.96.117:44167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/goods.php"] [unique_id "al9co_zqsQqnLoCgUjiDQQAAAWc"]
[Tue Jul 21 08:48:51.437544 2026] [security2:error] [pid 514479:tid 514673] [client 203.25.124.31:58715] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/includes/user/"] [unique_id "al9co_zqsQqnLoCgUjiDRgAAAUU"]
[Tue Jul 21 08:48:51.540412 2026] [security2:error] [pid 514479:tid 514718] [client 69.171.230.28:61978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9co_zqsQqnLoCgUjiDSwAAAXI"]
[Tue Jul 21 08:48:51.669039 2026] [security2:error] [pid 511108:tid 511266] [client 203.25.124.192:64911] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwenty/assets/js/index.php"] [unique_id "al9co4Td5soprXwxAH0cjQAAABw"]
[Tue Jul 21 08:48:51.745297 2026] [security2:error] [pid 514479:tid 514626] [client 20.104.96.117:44244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/100.php"] [unique_id "al9co_zqsQqnLoCgUjiDWQAAARY"]
[Tue Jul 21 08:48:51.746051 2026] [security2:error] [pid 514479:tid 514716] [client 20.226.60.151:57562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9co_zqsQqnLoCgUjiDWgAAAXA"]
[Tue Jul 21 08:48:51.829356 2026] [security2:error] [pid 514479:tid 514636] [client 59.95.197.55:49809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9co_zqsQqnLoCgUjiDWwAAASA"]
[Tue Jul 21 08:48:51.829455 2026] [security2:error] [pid 514479:tid 514636] [client 59.95.197.55:49809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9co_zqsQqnLoCgUjiDWwAAASA"]
[Tue Jul 21 08:48:51.832716 2026] [security2:error] [pid 514479:tid 514681] [client 64.42.179.43:50160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9co_zqsQqnLoCgUjiDXAAAAU0"]
[Tue Jul 21 08:48:51.832792 2026] [security2:error] [pid 514479:tid 514681] [client 64.42.179.43:50160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9co_zqsQqnLoCgUjiDXAAAAU0"]
[Tue Jul 21 08:48:51.856029 2026] [security2:error] [pid 514479:tid 514700] [client 5.38.115.39:46150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9co_zqsQqnLoCgUjiDXQAAAWA"]
[Tue Jul 21 08:48:51.856141 2026] [security2:error] [pid 514479:tid 514700] [client 5.38.115.39:46150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9co_zqsQqnLoCgUjiDXQAAAWA"]
[Tue Jul 21 08:48:52.045307 2026] [security2:error] [pid 514479:tid 514649] [client 20.104.96.117:44254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/about.php"] [unique_id "al9cpPzqsQqnLoCgUjiDYgAAAS0"]
[Tue Jul 21 08:48:52.150012 2026] [security2:error] [pid 511108:tid 511301] [client 203.25.124.47:28255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/66.php"] [unique_id "al9cpITd5soprXwxAH0cpwAAAD8"]
[Tue Jul 21 08:48:52.298508 2026] [security2:error] [pid 514479:tid 514625] [client 122.176.100.127:51599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cpPzqsQqnLoCgUjiDawAAARU"]
[Tue Jul 21 08:48:52.298888 2026] [security2:error] [pid 514479:tid 514625] [client 122.176.100.127:51599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cpPzqsQqnLoCgUjiDawAAARU"]
[Tue Jul 21 08:48:52.313097 2026] [security2:error] [pid 511108:tid 511357] [client 20.104.96.117:59668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/loader.php"] [unique_id "al9cpITd5soprXwxAH0cqgAAAHc"]
[Tue Jul 21 08:48:52.316622 2026] [security2:error] [pid 511108:tid 511268] [client 20.151.10.161:62378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/pucci.php"] [unique_id "al9cpITd5soprXwxAH0cqwAAAB4"]
[Tue Jul 21 08:48:52.320739 2026] [security2:error] [pid 511108:tid 511253] [client 173.252.95.25:33704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cpITd5soprXwxAH0cqAAAAA8"]
[Tue Jul 21 08:48:52.333484 2026] [security2:error] [pid 511108:tid 511361] [client 20.104.96.117:44125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/about.php"] [unique_id "al9cpITd5soprXwxAH0crgAAAHs"]
[Tue Jul 21 08:48:52.360690 2026] [security2:error] [pid 511108:tid 511306] [client 203.25.124.72:53057] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/images/index.php"] [unique_id "al9cpITd5soprXwxAH0csQAAAEQ"]
[Tue Jul 21 08:48:52.471778 2026] [security2:error] [pid 511108:tid 511289] [client 65.21.113.253:48676] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9co4Td5soprXwxAH0clQAAADM"]
[Tue Jul 21 08:48:52.578228 2026] [security2:error] [pid 511108:tid 511243] [client 203.25.124.10:65469] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/dlex/dlex.php"] [unique_id "al9cpITd5soprXwxAH0ctgAAAAU"]
[Tue Jul 21 08:48:52.583403 2026] [security2:error] [pid 514479:tid 514716] [client 195.206.105.227:34298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9cpPzqsQqnLoCgUjiDcgAAAXA"]
[Tue Jul 21 08:48:52.583511 2026] [security2:error] [pid 514479:tid 514716] [client 195.206.105.227:34298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9cpPzqsQqnLoCgUjiDcgAAAXA"]
[Tue Jul 21 08:48:52.638654 2026] [security2:error] [pid 511108:tid 511359] [client 20.104.96.117:44234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/admin.php"] [unique_id "al9cpITd5soprXwxAH0cuQAAAHk"]
[Tue Jul 21 08:48:52.645452 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.645550 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.645668 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.645711 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.645746 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.645870 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.645957 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.645995 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646048 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646085 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646121 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646157 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646193 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646229 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646265 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646300 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646336 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646373 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646410 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646446 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646482 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646517 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646554 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646590 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646626 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646663 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646699 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646737 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646830 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646869 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646905 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646947 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.646984 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647020 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647057 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647092 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647131 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647182 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647220 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647271 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647314 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647343 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647403 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647497 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647541 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647582 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647618 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647654 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647691 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647742 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647780 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647823 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647860 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647896 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647936 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.647972 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648009 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648046 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648084 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648121 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648157 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648196 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648234 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648271 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648321 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648368 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648425 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648486 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648546 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648605 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648665 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648731 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648797 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648873 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648917 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.648967 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649005 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649042 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649078 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649115 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649150 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649187 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649223 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649259 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649296 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649332 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649369 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649407 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649446 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649483 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649519 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649564 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649597 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649644 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649688 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.649735 2026] [lsapi:warn] [pid 511108:tid 511110] [remote 189.6.178.120:49656] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:52.776736 2026] [security2:error] [pid 514479:tid 514630] [client 20.197.192.193:9432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/ah25.php"] [unique_id "al9cpPzqsQqnLoCgUjiDdgAAARo"]
[Tue Jul 21 08:48:52.817567 2026] [security2:error] [pid 514479:tid 514546] [remote 159.65.81.207:43642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com.br"] [uri "/wp-login.php"] [unique_id "al9cpPzqsQqnLoCgUjiDeAABFj4"]
[Tue Jul 21 08:48:52.913834 2026] [security2:error] [pid 514479:tid 514694] [client 20.104.96.117:59690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/spadex.php"] [unique_id "al9cpPzqsQqnLoCgUjiDfAAAAVo"]
[Tue Jul 21 08:48:53.098341 2026] [security2:error] [pid 514479:tid 514664] [client 20.104.96.117:44253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/admin.php"] [unique_id "al9cpfzqsQqnLoCgUjiDgwAAATw"]
[Tue Jul 21 08:48:53.147100 2026] [security2:error] [pid 514479:tid 514715] [client 212.32.76.14:34009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/languages/autoload_classmap.php"] [unique_id "al9cpfzqsQqnLoCgUjiDhAAAAW8"]
[Tue Jul 21 08:48:53.407324 2026] [security2:error] [pid 514479:tid 514741] [client 20.151.10.161:28518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9cpfzqsQqnLoCgUjiDhwAAAYk"]
[Tue Jul 21 08:48:53.431612 2026] [security2:error] [pid 511108:tid 511340] [client 103.59.206.240:31192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cpYTd5soprXwxAH0dGQAAAGY"]
[Tue Jul 21 08:48:53.431720 2026] [security2:error] [pid 511108:tid 511340] [client 103.59.206.240:31192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cpYTd5soprXwxAH0dGQAAAGY"]
[Tue Jul 21 08:48:53.491882 2026] [security2:error] [pid 514479:tid 514633] [client 203.25.124.4:50141] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/view-source/ioxi-o.php"] [unique_id "al9cpfzqsQqnLoCgUjiDigAAAR0"]
[Tue Jul 21 08:48:53.517283 2026] [security2:error] [pid 514479:tid 514681] [client 20.104.96.117:44279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/themes.php"] [unique_id "al9cpfzqsQqnLoCgUjiDiwAAAU0"]
[Tue Jul 21 08:48:53.566591 2026] [security2:error] [pid 514479:tid 514697] [client 203.25.124.70:51963] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "al9cpfzqsQqnLoCgUjiDjgAAAV0"]
[Tue Jul 21 08:48:53.676042 2026] [security2:error] [pid 514479:tid 514637] [client 195.49.128.211:55424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cpfzqsQqnLoCgUjiDkQAAASE"]
[Tue Jul 21 08:48:53.676198 2026] [security2:error] [pid 514479:tid 514637] [client 195.49.128.211:55424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cpfzqsQqnLoCgUjiDkQAAASE"]
[Tue Jul 21 08:48:53.783265 2026] [security2:error] [pid 514479:tid 514677] [client 20.104.96.117:59143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/2x.php"] [unique_id "al9cpfzqsQqnLoCgUjiDkgAAAUk"]
[Tue Jul 21 08:48:53.885388 2026] [autoindex:error] [pid 514479:tid 514718] [client 20.104.96.117:0] AH01276: Cannot serve directory /home3/gadelh32/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:48:54.131205 2026] [security2:error] [pid 514479:tid 514580] [remote 119.195.102.159:43462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9cpvzqsQqnLoCgUjiDmwABbl8"]
[Tue Jul 21 08:48:54.176889 2026] [security2:error] [pid 511108:tid 511330] [client 203.25.124.184:44393] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/network/cache/index.php"] [unique_id "al9cpoTd5soprXwxAH0dJgAAAFw"]
[Tue Jul 21 08:48:54.270847 2026] [security2:error] [pid 511108:tid 511310] [client 212.32.76.5:61571] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "al9cpoTd5soprXwxAH0dKgAAAEg"]
[Tue Jul 21 08:48:54.369159 2026] [security2:error] [pid 514479:tid 514695] [client 20.226.60.151:57545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/classwithtostring.php"] [unique_id "al9cpvzqsQqnLoCgUjiDpAAAAVs"]
[Tue Jul 21 08:48:54.490397 2026] [security2:error] [pid 511108:tid 511341] [client 20.104.96.117:59162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ctex1.php"] [unique_id "al9cpoTd5soprXwxAH0dMAAAAGc"]
[Tue Jul 21 08:48:54.500526 2026] [security2:error] [pid 514479:tid 514700] [client 20.151.10.161:62337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-temp.php"] [unique_id "al9cpvzqsQqnLoCgUjiDpQAAAWA"]
[Tue Jul 21 08:48:54.901394 2026] [security2:error] [pid 514479:tid 514690] [client 41.89.234.2:53307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cpvzqsQqnLoCgUjiDqwAAAVY"]
[Tue Jul 21 08:48:54.901557 2026] [security2:error] [pid 514479:tid 514690] [client 41.89.234.2:53307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cpvzqsQqnLoCgUjiDqwAAAVY"]
[Tue Jul 21 08:48:55.013535 2026] [security2:error] [pid 511108:tid 511295] [client 20.104.96.117:59658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/edorxrr.php"] [unique_id "al9cp4Td5soprXwxAH0dOQAAADk"]
[Tue Jul 21 08:48:55.049292 2026] [security2:error] [pid 511108:tid 511259] [client 203.25.124.66:47317] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/2024/"] [unique_id "al9cp4Td5soprXwxAH0dOwAAABU"]
[Tue Jul 21 08:48:55.223789 2026] [security2:error] [pid 514479:tid 514633] [client 113.22.144.139:50531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cp_zqsQqnLoCgUjiDrgAAAR0"]
[Tue Jul 21 08:48:55.225007 2026] [security2:error] [pid 514479:tid 514633] [client 113.22.144.139:50531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cp_zqsQqnLoCgUjiDrgAAAR0"]
[Tue Jul 21 08:48:55.344803 2026] [security2:error] [pid 511108:tid 511156] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cp4Td5soprXwxAH0dQAAAEy8"]
[Tue Jul 21 08:48:55.345102 2026] [security2:error] [pid 511108:tid 511156] [remote 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cp4Td5soprXwxAH0dQAAAEy8"]
[Tue Jul 21 08:48:55.363512 2026] [security2:error] [pid 514479:tid 514634] [client 203.25.124.58:20429] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "al9cp_zqsQqnLoCgUjiDsQAAAR4"]
[Tue Jul 21 08:48:55.378056 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.378149 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.378283 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.378349 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.378406 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.378536 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.378631 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.378687 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.378763 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.378829 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.378884 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.378945 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.378999 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379051 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379103 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379157 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379210 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379263 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379316 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379367 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379417 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379469 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379521 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379574 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379629 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379685 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379740 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379797 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379909 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379957 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.379991 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380026 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380060 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380095 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380129 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380164 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380205 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380236 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380288 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380323 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380372 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380413 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380456 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380512 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380549 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380584 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380618 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380652 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380699 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380735 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380769 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380804 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380856 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380891 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380935 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.380970 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381005 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381041 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381076 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381111 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381148 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381182 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381218 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381266 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381302 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381336 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381380 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381416 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381452 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381490 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381529 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381565 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381605 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381640 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381675 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381711 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381744 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381778 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381812 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381858 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381894 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381937 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.381970 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.382005 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.382039 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.382073 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.382108 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.382144 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.382179 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.382213 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.382253 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.382290 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.382333 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.382370 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.382414 2026] [lsapi:warn] [pid 511108:tid 511128] [remote 189.6.178.120:49688] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:55.420552 2026] [security2:error] [pid 511108:tid 511125] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cp4Td5soprXwxAH0dQgAAMBA"]
[Tue Jul 21 08:48:55.420700 2026] [security2:error] [pid 511108:tid 511286] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cp4Td5soprXwxAH0dQgAAMBA"]
[Tue Jul 21 08:48:55.635075 2026] [autoindex:error] [pid 514479:tid 514733] [client 185.213.175.37:20404] AH01276: Cannot serve directory /home2/bavosc49/booking.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:48:55.684387 2026] [autoindex:error] [pid 514479:tid 514700] [client 172.252.228.23:0] AH01276: Cannot serve directory /home2/inlaud99/distribuidorasja.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:48:55.685263 2026] [security2:error] [pid 511108:tid 511311] [client 203.25.124.9:47197] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/table/table/updater-tool.php"] [unique_id "al9cp4Td5soprXwxAH0dlQAAAEk"]
[Tue Jul 21 08:48:56.020762 2026] [security2:error] [pid 511108:tid 511305] [client 20.151.10.161:28598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9cqITd5soprXwxAH0doQAAAEM"]
[Tue Jul 21 08:48:56.101700 2026] [security2:error] [pid 511108:tid 511243] [client 20.104.96.117:59179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/miru1.php"] [unique_id "al9cqITd5soprXwxAH0dpQAAAAU"]
[Tue Jul 21 08:48:56.129783 2026] [security2:error] [pid 511108:tid 511239] [client 20.226.60.151:57599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/root.php"] [unique_id "al9cqITd5soprXwxAH0dpgAAAAE"]
[Tue Jul 21 08:48:56.206150 2026] [security2:error] [pid 514479:tid 514714] [client 20.197.192.193:9409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/8.php"] [unique_id "al9cqPzqsQqnLoCgUjiDwgAAAW4"]
[Tue Jul 21 08:48:56.251743 2026] [security2:error] [pid 511108:tid 511308] [client 203.25.124.48:28341] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/chosen.php"] [unique_id "al9cqITd5soprXwxAH0dqgAAAEY"]
[Tue Jul 21 08:48:56.282487 2026] [security2:error] [pid 511108:tid 511321] [client 20.226.60.151:57651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/sym403.php"] [unique_id "al9cqITd5soprXwxAH0dqwAAAFM"]
[Tue Jul 21 08:48:56.335146 2026] [security2:error] [pid 511108:tid 511242] [client 20.104.96.117:44273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/.well-known/about.php"] [unique_id "al9cqITd5soprXwxAH0drgAAAAQ"]
[Tue Jul 21 08:48:56.379581 2026] [security2:error] [pid 514479:tid 514714] [client 20.226.60.151:57642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/v543.php"] [unique_id "al9cqPzqsQqnLoCgUjiDyAAAAW4"]
[Tue Jul 21 08:48:56.553493 2026] [security2:error] [pid 514479:tid 514563] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cqPzqsQqnLoCgUjiDywABHk4"]
[Tue Jul 21 08:48:56.553686 2026] [security2:error] [pid 514479:tid 514634] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cqPzqsQqnLoCgUjiDywABHk4"]
[Tue Jul 21 08:48:56.573912 2026] [security2:error] [pid 511108:tid 511256] [client 203.25.124.43:33711] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "al9cqITd5soprXwxAH0dtAAAABI"]
[Tue Jul 21 08:48:56.613711 2026] [security2:error] [pid 511108:tid 511295] [client 20.104.96.117:44229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9cqITd5soprXwxAH0dtwAAADk"]
[Tue Jul 21 08:48:56.667092 2026] [security2:error] [pid 514479:tid 514715] [client 20.226.60.151:57645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/sixxis.php"] [unique_id "al9cqPzqsQqnLoCgUjiDzQAAAW8"]
[Tue Jul 21 08:48:56.684805 2026] [security2:error] [pid 511108:tid 511356] [client 65.21.113.253:48676] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cqITd5soprXwxAH0dqQAAAHY"]
[Tue Jul 21 08:48:56.703154 2026] [security2:error] [pid 511108:tid 511326] [client 20.104.96.117:59189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/sump1.php"] [unique_id "al9cqITd5soprXwxAH0duQAAAFg"]
[Tue Jul 21 08:48:56.799305 2026] [security2:error] [pid 514479:tid 514621] [client 20.151.10.161:28593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/gettest.php"] [unique_id "al9cqPzqsQqnLoCgUjiDzgAAARE"]
[Tue Jul 21 08:48:56.873361 2026] [security2:error] [pid 514479:tid 514625] [client 203.25.124.180:32757] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/maintenance.php"] [unique_id "al9cqPzqsQqnLoCgUjiD0QAAARU"]
[Tue Jul 21 08:48:56.965603 2026] [security2:error] [pid 511108:tid 511245] [client 20.104.96.117:44252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/wefile.php"] [unique_id "al9cqITd5soprXwxAH0dvQAAAAc"]
[Tue Jul 21 08:48:56.999840 2026] [security2:error] [pid 514479:tid 514634] [client 20.226.60.151:57584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ip.php"] [unique_id "al9cqPzqsQqnLoCgUjiD1AAAAR4"]
[Tue Jul 21 08:48:57.250066 2026] [security2:error] [pid 514479:tid 514715] [client 203.25.124.57:45067] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/footer.php"] [unique_id "al9cqfzqsQqnLoCgUjiD1gAAAW8"]
[Tue Jul 21 08:48:57.268391 2026] [security2:error] [pid 514479:tid 514633] [client 20.151.10.161:62435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9cqfzqsQqnLoCgUjiD2AAAAR0"]
[Tue Jul 21 08:48:57.280810 2026] [security2:error] [pid 514479:tid 514556] [remote 45.137.215.217:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "45.137.215.217" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "extrapro21.com"] [uri "/wp-comments-post.php"] [unique_id "al9cqfzqsQqnLoCgUjiD2QABQEc"], referer: https://extrapro21.com/2025/11/26/hello-world/
[Tue Jul 21 08:48:57.280906 2026] [security2:error] [pid 514479:tid 514738] [client 20.104.96.117:44114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9cqfzqsQqnLoCgUjiD2gAAAYY"]
[Tue Jul 21 08:48:57.281081 2026] [security2:error] [pid 514479:tid 514668] [client 45.137.215.217:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "extrapro21.com"] [uri "/wp-comments-post.php"] [unique_id "al9cqfzqsQqnLoCgUjiD2QABQEc"], referer: https://extrapro21.com/2025/11/26/hello-world/
[Tue Jul 21 08:48:57.285140 2026] [security2:error] [pid 514479:tid 514495] [remote 192.241.143.148:42320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/wp-login.php"] [unique_id "al9cqfzqsQqnLoCgUjiD2wABaQs"]
[Tue Jul 21 08:48:57.401477 2026] [security2:error] [pid 511108:tid 511280] [client 198.44.157.34:43164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9cqYTd5soprXwxAH0dxwAAACo"]
[Tue Jul 21 08:48:57.401577 2026] [security2:error] [pid 511108:tid 511280] [client 198.44.157.34:43164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9cqYTd5soprXwxAH0dxwAAACo"]
[Tue Jul 21 08:48:57.441412 2026] [security2:error] [pid 514479:tid 514697] [client 20.104.96.117:61131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/file5.php"] [unique_id "al9cqfzqsQqnLoCgUjiD3AAAAV0"]
[Tue Jul 21 08:48:57.467351 2026] [security2:error] [pid 514479:tid 514741] [client 203.25.124.33:35711] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/languages/index.php"] [unique_id "al9cqfzqsQqnLoCgUjiD4QAAAYk"]
[Tue Jul 21 08:48:57.557579 2026] [security2:error] [pid 514479:tid 514702] [client 20.226.60.151:57561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/kq1.php"] [unique_id "al9cqfzqsQqnLoCgUjiD5gAAAWI"]
[Tue Jul 21 08:48:57.558210 2026] [security2:error] [pid 511108:tid 511310] [client 195.206.105.227:55334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9cqYTd5soprXwxAH0dygAAAEg"]
[Tue Jul 21 08:48:57.558348 2026] [security2:error] [pid 511108:tid 511310] [client 195.206.105.227:55334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9cqYTd5soprXwxAH0dygAAAEg"]
[Tue Jul 21 08:48:57.602275 2026] [autoindex:error] [pid 514479:tid 514636] [client 20.104.96.117:0] AH01276: Cannot serve directory /home3/gadelh32/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:48:57.621241 2026] [security2:error] [pid 511108:tid 511240] [client 20.220.225.223:22208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/ms-new.php"] [unique_id "al9cqYTd5soprXwxAH0dzQAAAAI"]
[Tue Jul 21 08:48:57.676975 2026] [security2:error] [pid 514479:tid 514674] [client 203.25.124.208:30413] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/admin.php"] [unique_id "al9cqfzqsQqnLoCgUjiD7QAAAUY"]
[Tue Jul 21 08:48:57.756524 2026] [core:error] [pid 514479:tid 514738] [client 66.249.66.67:41189] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:48:57.756550 2026] [core:error] [pid 514479:tid 514738] [client 66.249.66.67:41189] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:48:57.765716 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.765832 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.765965 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766017 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766053 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766169 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766249 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766292 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766345 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766382 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766419 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766456 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766491 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766528 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766564 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766600 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766637 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766674 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766712 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766750 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766787 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766832 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766871 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766907 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766951 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.766989 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767026 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767062 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767148 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767192 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767230 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767265 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767302 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767338 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767375 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767411 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767447 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767483 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767519 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767570 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767639 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767689 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767726 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767763 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767798 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767858 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767900 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.767942 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768005 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768102 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768108 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768147 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768185 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768221 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768258 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768308 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768345 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768382 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768419 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768457 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768494 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768530 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768568 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768605 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768643 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768679 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768715 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768754 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768790 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768834 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768883 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768921 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.768965 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769010 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769048 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769085 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769124 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769165 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769203 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769246 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769283 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769319 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769356 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769392 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769428 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769465 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769501 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769542 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769599 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769634 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769678 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769714 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769759 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769797 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769851 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769888 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769939 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.769981 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.770028 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.770077 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.770120 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.770170 2026] [lsapi:warn] [pid 514479:tid 514571] [remote 189.6.178.120:49746] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:48:57.794302 2026] [security2:error] [pid 514479:tid 514590] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cqfzqsQqnLoCgUjiD8gABcmk"]
[Tue Jul 21 08:48:57.794448 2026] [security2:error] [pid 514479:tid 514718] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cqfzqsQqnLoCgUjiD8gABcmk"]
[Tue Jul 21 08:48:57.858061 2026] [security2:error] [pid 511108:tid 511337] [client 173.252.95.29:50652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cqYTd5soprXwxAH0dzgAAAGM"]
[Tue Jul 21 08:48:57.886859 2026] [security2:error] [pid 514479:tid 514724] [client 20.151.10.161:28253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/simple.php"] [unique_id "al9cqfzqsQqnLoCgUjiEPQAAAXg"]
[Tue Jul 21 08:48:57.935916 2026] [autoindex:error] [pid 514479:tid 514630] [client 20.104.96.117:44116] AH01276: Cannot serve directory /home3/gadelh32/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:48:58.073676 2026] [security2:error] [pid 514479:tid 514690] [client 20.104.96.117:44116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9cqvzqsQqnLoCgUjiETQAAAVY"]
[Tue Jul 21 08:48:58.081636 2026] [security2:error] [pid 514479:tid 514637] [client 182.189.99.211:48325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cqvzqsQqnLoCgUjiETgAAASE"]
[Tue Jul 21 08:48:58.081765 2026] [security2:error] [pid 514479:tid 514637] [client 182.189.99.211:48325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cqvzqsQqnLoCgUjiETgAAASE"]
[Tue Jul 21 08:48:58.122498 2026] [autoindex:error] [pid 514479:tid 514687] [client 35.229.94.153:0] AH01276: Cannot serve directory /home2/fer06244/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:48:58.176035 2026] [security2:error] [pid 514479:tid 514604] [remote 167.71.218.184:40520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedrocromo.com.br"] [uri "/wp-login.php"] [unique_id "al9cqvzqsQqnLoCgUjiEWAABb3c"]
[Tue Jul 21 08:48:58.396844 2026] [security2:error] [pid 514479:tid 514681] [client 20.226.60.151:59749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9cqvzqsQqnLoCgUjiEXQAAAU0"]
[Tue Jul 21 08:48:58.402901 2026] [security2:error] [pid 514479:tid 514697] [client 20.104.96.117:44243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/8.php"] [unique_id "al9cqvzqsQqnLoCgUjiEXgAAAV0"]
[Tue Jul 21 08:48:58.417953 2026] [security2:error] [pid 511108:tid 511353] [client 51.68.107.150:21645] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hvrtecnologia.com.br"] [uri "/robots.txt"] [unique_id "al9cqoTd5soprXwxAH0d1gAAAHM"]
[Tue Jul 21 08:48:58.418062 2026] [security2:error] [pid 511108:tid 511353] [client 51.68.107.150:21645] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "hvrtecnologia.com.br"] [uri "/robots.txt"] [unique_id "al9cqoTd5soprXwxAH0d1gAAAHM"]
[Tue Jul 21 08:48:58.418900 2026] [security2:error] [pid 514479:tid 514741] [client 20.104.96.117:59705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/0xD.php"] [unique_id "al9cqvzqsQqnLoCgUjiEYAAAAYk"]
[Tue Jul 21 08:48:58.568559 2026] [security2:error] [pid 514479:tid 514714] [client 212.32.76.13:36881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/media-new.php"] [unique_id "al9cqvzqsQqnLoCgUjiEYwAAAW4"]
[Tue Jul 21 08:48:58.611285 2026] [security2:error] [pid 514479:tid 514707] [client 20.104.96.117:4045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9cqvzqsQqnLoCgUjiEZAAAAWc"]
[Tue Jul 21 08:48:58.681713 2026] [security2:error] [pid 514479:tid 514620] [client 212.32.76.57:43575] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/home.php"] [unique_id "al9cqvzqsQqnLoCgUjiEZwAAARA"]
[Tue Jul 21 08:48:58.699799 2026] [security2:error] [pid 511108:tid 511244] [client 20.104.96.117:44131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9cqoTd5soprXwxAH0d3wAAAAY"]
[Tue Jul 21 08:48:58.744145 2026] [security2:error] [pid 514479:tid 514733] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cqvzqsQqnLoCgUjiEZQABgWM"]
[Tue Jul 21 08:48:58.833012 2026] [security2:error] [pid 514479:tid 514643] [client 20.197.192.193:9456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/red.php"] [unique_id "al9cqvzqsQqnLoCgUjiEaAAAASc"]
[Tue Jul 21 08:48:58.868025 2026] [security2:error] [pid 514479:tid 514633] [client 20.151.10.161:28035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/xxx.php"] [unique_id "al9cqvzqsQqnLoCgUjiEaQAAAR0"]
[Tue Jul 21 08:48:58.872073 2026] [security2:error] [pid 514479:tid 514687] [client 20.226.60.151:57628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/h02ugyh.php"] [unique_id "al9cqvzqsQqnLoCgUjiEagAAAVM"]
[Tue Jul 21 08:48:58.891525 2026] [security2:error] [pid 514479:tid 514640] [client 34.178.75.226:50786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9cqvzqsQqnLoCgUjiEawAAASQ"]
[Tue Jul 21 08:48:58.903298 2026] [security2:error] [pid 514479:tid 514533] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cqvzqsQqnLoCgUjiEbAABGjE"]
[Tue Jul 21 08:48:58.903438 2026] [security2:error] [pid 514479:tid 514630] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cqvzqsQqnLoCgUjiEbAABGjE"]
[Tue Jul 21 08:48:58.945553 2026] [security2:error] [pid 514479:tid 514715] [client 212.32.76.12:21753] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/wp-file-manager-pro/"] [unique_id "al9cqvzqsQqnLoCgUjiEbQAAAW8"]
[Tue Jul 21 08:48:59.019535 2026] [security2:error] [pid 514479:tid 514657] [client 20.104.96.117:44249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/f6.php"] [unique_id "al9cq_zqsQqnLoCgUjiEbwAAATU"]
[Tue Jul 21 08:48:59.251676 2026] [security2:error] [pid 514479:tid 514634] [client 20.226.60.151:59760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-temp.php"] [unique_id "al9cq_zqsQqnLoCgUjiEdQAAAR4"]
[Tue Jul 21 08:48:59.323965 2026] [security2:error] [pid 514479:tid 514724] [client 20.104.96.117:44117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/inputs.php"] [unique_id "al9cq_zqsQqnLoCgUjiEdgAAAXg"]
[Tue Jul 21 08:48:59.326708 2026] [security2:error] [pid 514479:tid 514626] [client 49.144.66.253:33041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cq_zqsQqnLoCgUjiEdwAAARY"]
[Tue Jul 21 08:48:59.326914 2026] [security2:error] [pid 514479:tid 514626] [client 49.144.66.253:33041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cq_zqsQqnLoCgUjiEdwAAARY"]
[Tue Jul 21 08:48:59.367076 2026] [security2:error] [pid 514479:tid 514707] [client 34.178.75.226:53437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.75.178.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cq_zqsQqnLoCgUjiEeAAAAWc"]
[Tue Jul 21 08:48:59.413233 2026] [security2:error] [pid 514479:tid 514620] [client 20.104.96.117:59656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/fnstall.php"] [unique_id "al9cq_zqsQqnLoCgUjiEeQAAARA"]
[Tue Jul 21 08:48:59.634899 2026] [security2:error] [pid 514479:tid 514670] [client 35.229.94.153:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.94.229.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cqvzqsQqnLoCgUjiEZgAAAUI"]
[Tue Jul 21 08:48:59.639679 2026] [security2:error] [pid 514479:tid 514662] [client 20.104.96.117:44164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/inputs.php"] [unique_id "al9cq_zqsQqnLoCgUjiEfgAAATo"]
[Tue Jul 21 08:48:59.664117 2026] [security2:error] [pid 511108:tid 511272] [client 203.25.124.52:51863] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/tiny.php"] [unique_id "al9cq4Td5soprXwxAH0d6wAAACI"]
[Tue Jul 21 08:48:59.753498 2026] [security2:error] [pid 514479:tid 514657] [client 20.226.60.151:57650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9cq_zqsQqnLoCgUjiEgwAAATU"]
[Tue Jul 21 08:48:59.759987 2026] [security2:error] [pid 514479:tid 514708] [client 20.151.10.161:28526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/hypo.php"] [unique_id "al9cq_zqsQqnLoCgUjiEhAAAAWg"]
[Tue Jul 21 08:48:59.881454 2026] [security2:error] [pid 514479:tid 514612] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cq_zqsQqnLoCgUjiEhwABJ38"]
[Tue Jul 21 08:48:59.881664 2026] [security2:error] [pid 514479:tid 514643] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9cq_zqsQqnLoCgUjiEhwABJ38"]
[Tue Jul 21 08:48:59.920183 2026] [security2:error] [pid 514479:tid 514678] [client 35.229.94.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9cq_zqsQqnLoCgUjiEiQAAAUo"]
[Tue Jul 21 08:49:00.005102 2026] [security2:error] [pid 514479:tid 514637] [client 20.104.96.117:44285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/classwithtostring.php"] [unique_id "al9crPzqsQqnLoCgUjiEigAAASE"]
[Tue Jul 21 08:49:00.139775 2026] [security2:error] [pid 511108:tid 511364] [client 65.21.113.253:48676] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cq4Td5soprXwxAH0d7gAAAH4"]
[Tue Jul 21 08:49:00.201143 2026] [security2:error] [pid 511108:tid 511280] [client 35.229.94.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9crITd5soprXwxAH0d9AAAACo"]
[Tue Jul 21 08:49:00.236376 2026] [security2:error] [pid 511108:tid 511273] [client 203.25.124.42:59453] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/system_log.php"] [unique_id "al9crITd5soprXwxAH0d-AAAACM"]
[Tue Jul 21 08:49:00.374695 2026] [security2:error] [pid 514479:tid 514695] [client 20.104.96.117:59700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/acp.php"] [unique_id "al9crPzqsQqnLoCgUjiEkQAAAVs"]
[Tue Jul 21 08:49:00.381735 2026] [security2:error] [pid 511108:tid 511329] [client 20.104.96.117:44155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9crITd5soprXwxAH0d-gAAAFs"]
[Tue Jul 21 08:49:00.468200 2026] [security2:error] [pid 511108:tid 511305] [client 35.229.94.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9crITd5soprXwxAH0d-wAAAEM"]
[Tue Jul 21 08:49:00.492798 2026] [security2:error] [pid 514479:tid 514662] [client 20.226.60.151:57563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9crPzqsQqnLoCgUjiEkwAAATo"]
[Tue Jul 21 08:49:00.499541 2026] [security2:error] [pid 511108:tid 511265] [client 20.104.96.117:46760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9crITd5soprXwxAH0d_AAAABs"]
[Tue Jul 21 08:49:00.685120 2026] [security2:error] [pid 511108:tid 511306] [client 20.104.96.117:44223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/wp-blog.php"] [unique_id "al9crITd5soprXwxAH0d_wAAAEQ"]
[Tue Jul 21 08:49:00.729705 2026] [security2:error] [pid 511108:tid 511289] [client 35.229.94.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9crITd5soprXwxAH0eBgAAADM"]
[Tue Jul 21 08:49:00.793992 2026] [security2:error] [pid 511108:tid 511351] [client 203.25.124.50:41041] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/license.php"] [unique_id "al9crITd5soprXwxAH0eCAAAAHE"]
[Tue Jul 21 08:49:00.867024 2026] [core:alert] [pid 511108:tid 511349] [client 57.141.18.85:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:49:00.957089 2026] [security2:error] [pid 514479:tid 514693] [client 34.178.75.226:56736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9crPzqsQqnLoCgUjiEmwAAAVk"]
[Tue Jul 21 08:49:00.959861 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.959939 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960052 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960094 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960128 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960234 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960307 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960345 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960396 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960434 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960471 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960509 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960544 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960580 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960616 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960651 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960687 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960723 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960759 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960794 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960844 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960882 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960918 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.960965 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961000 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961036 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961072 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961109 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961193 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961229 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961264 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961300 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961336 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961370 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961407 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961443 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961480 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961532 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961567 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961619 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961661 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961690 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961749 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961841 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961850 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961883 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961918 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961961 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.961998 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962048 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962085 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962121 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962157 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962193 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962228 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962263 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962300 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962336 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962373 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962409 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962444 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962482 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962518 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962553 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962603 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962639 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962675 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962719 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962756 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962791 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962837 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962876 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962912 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962962 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.962997 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963032 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963068 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963104 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963139 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963175 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963210 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963245 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963281 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963316 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963351 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963387 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963422 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963459 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963498 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963533 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963568 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963610 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963645 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963691 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963727 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.963773 2026] [lsapi:warn] [pid 514479:tid 514591] [remote 189.6.178.120:49832] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:00.984533 2026] [security2:error] [pid 514479:tid 514681] [client 168.167.81.163:64722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9crPzqsQqnLoCgUjiEnAAAAU0"]
[Tue Jul 21 08:49:00.984616 2026] [security2:error] [pid 514479:tid 514681] [client 168.167.81.163:64722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9crPzqsQqnLoCgUjiEnAAAAU0"]
[Tue Jul 21 08:49:01.003097 2026] [autoindex:error] [pid 511108:tid 511244] [client 20.104.96.117:0] AH01276: Cannot serve directory /home3/gadelh32/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:49:01.091962 2026] [security2:error] [pid 511108:tid 511241] [client 35.229.94.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9crYTd5soprXwxAH0eGAAAAAM"]
[Tue Jul 21 08:49:01.111480 2026] [security2:error] [pid 514479:tid 514674] [client 20.226.60.151:57554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/jj.php"] [unique_id "al9crfzqsQqnLoCgUjiE5QAAAUY"]
[Tue Jul 21 08:49:01.280029 2026] [security2:error] [pid 514479:tid 514662] [client 20.104.96.117:44230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9crfzqsQqnLoCgUjiE8QAAATo"]
[Tue Jul 21 08:49:01.386654 2026] [security2:error] [pid 514479:tid 514708] [client 20.104.96.117:59664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/mosty.php"] [unique_id "al9crfzqsQqnLoCgUjiE-wAAAWg"]
[Tue Jul 21 08:49:01.387620 2026] [security2:error] [pid 514479:tid 514682] [client 34.178.75.226:63035] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9crfzqsQqnLoCgUjiE_AAAAU4"]
[Tue Jul 21 08:49:01.397342 2026] [security2:error] [pid 514479:tid 514621] [client 35.229.94.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9crfzqsQqnLoCgUjiE_QAAARE"]
[Tue Jul 21 08:49:01.412917 2026] [security2:error] [pid 511108:tid 511250] [client 114.198.138.124:63115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9crYTd5soprXwxAH0eHwAAAAw"]
[Tue Jul 21 08:49:01.413121 2026] [security2:error] [pid 511108:tid 511250] [client 114.198.138.124:63115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9crYTd5soprXwxAH0eHwAAAAw"]
[Tue Jul 21 08:49:01.433548 2026] [security2:error] [pid 514479:tid 514630] [client 152.59.181.104:50213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9crfzqsQqnLoCgUjiE_wAAARo"]
[Tue Jul 21 08:49:01.433707 2026] [security2:error] [pid 514479:tid 514630] [client 152.59.181.104:50213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9crfzqsQqnLoCgUjiE_wAAARo"]
[Tue Jul 21 08:49:01.474853 2026] [security2:error] [pid 514479:tid 514681] [client 203.25.124.251:37247] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/oceanwp/content-index.php"] [unique_id "al9crfzqsQqnLoCgUjiFAAAAAU0"]
[Tue Jul 21 08:49:01.569934 2026] [security2:error] [pid 511108:tid 511355] [client 20.104.96.117:44124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/ms-edit.php"] [unique_id "al9crYTd5soprXwxAH0eIAAAAHU"]
[Tue Jul 21 08:49:01.694800 2026] [security2:error] [pid 511108:tid 511268] [client 35.229.94.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9crYTd5soprXwxAH0eJAAAAB4"]
[Tue Jul 21 08:49:01.855097 2026] [security2:error] [pid 514479:tid 514735] [client 203.25.124.64:37625] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/separator/"] [unique_id "al9crfzqsQqnLoCgUjiFAgAAAYM"]
[Tue Jul 21 08:49:01.862257 2026] [security2:error] [pid 514479:tid 514635] [client 212.32.76.9:55891] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/av.php"] [unique_id "al9crfzqsQqnLoCgUjiFAwAAAR8"]
[Tue Jul 21 08:49:01.862738 2026] [security2:error] [pid 514479:tid 514664] [client 20.104.96.117:44275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9crfzqsQqnLoCgUjiFBAAAATw"]
[Tue Jul 21 08:49:01.868709 2026] [qos:error] [pid 511108:tid 511168] [remote 57.141.18.118:21540] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.118, id=al9crYTd5soprXwxAH0eMgAAezs
[Tue Jul 21 08:49:01.888218 2026] [security2:error] [pid 511108:tid 511240] [client 34.178.75.226:50610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9crYTd5soprXwxAH0eNAAAAAI"]
[Tue Jul 21 08:49:01.894479 2026] [security2:error] [pid 514479:tid 514633] [client 20.104.96.117:46772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/xyn.php"] [unique_id "al9crfzqsQqnLoCgUjiFBQAAAR0"]
[Tue Jul 21 08:49:01.979944 2026] [security2:error] [pid 511108:tid 511329] [client 35.229.94.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9crYTd5soprXwxAH0eOAAAAFs"]
[Tue Jul 21 08:49:02.113449 2026] [qos:error] [pid 514479:tid 514495] [remote 57.141.18.52:50032] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.52, id=al9crvzqsQqnLoCgUjiFBgABOgs
[Tue Jul 21 08:49:02.238629 2026] [security2:error] [pid 514479:tid 514678] [client 35.229.94.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9crvzqsQqnLoCgUjiFCwAAAUo"]
[Tue Jul 21 08:49:02.246077 2026] [autoindex:error] [pid 514479:tid 514643] [client 20.104.96.117:0] AH01276: Cannot serve directory /home3/gadelh32/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:49:02.354288 2026] [security2:error] [pid 514479:tid 514668] [client 34.178.75.226:56007] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9crvzqsQqnLoCgUjiFDgAAAUA"]
[Tue Jul 21 08:49:02.374205 2026] [security2:error] [pid 511108:tid 511365] [client 59.95.197.55:50513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9croTd5soprXwxAH0ePgAAAH8"]
[Tue Jul 21 08:49:02.374396 2026] [security2:error] [pid 511108:tid 511365] [client 59.95.197.55:50513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9croTd5soprXwxAH0ePgAAAH8"]
[Tue Jul 21 08:49:02.374434 2026] [security2:error] [pid 511108:tid 511326] [client 203.25.124.204:58073] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/Divi/content-index.php"] [unique_id "al9croTd5soprXwxAH0ePwAAAFg"]
[Tue Jul 21 08:49:02.523873 2026] [security2:error] [pid 514479:tid 514620] [client 20.104.96.117:44111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9crvzqsQqnLoCgUjiFEwAAARA"]
[Tue Jul 21 08:49:02.523876 2026] [security2:error] [pid 514479:tid 514674] [client 35.229.94.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9crvzqsQqnLoCgUjiFEgAAAUY"]
[Tue Jul 21 08:49:02.535980 2026] [security2:error] [pid 514479:tid 514636] [client 20.226.60.151:57609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9crvzqsQqnLoCgUjiFFgAAASA"]
[Tue Jul 21 08:49:02.550549 2026] [security2:error] [pid 514479:tid 514690] [client 20.151.10.161:28183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/chosen.php"] [unique_id "al9crvzqsQqnLoCgUjiFFwAAAVY"]
[Tue Jul 21 08:49:02.721204 2026] [security2:error] [pid 514479:tid 514702] [client 5.38.115.39:37406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9crvzqsQqnLoCgUjiFHAAAAWI"]
[Tue Jul 21 08:49:02.721334 2026] [security2:error] [pid 514479:tid 514702] [client 5.38.115.39:37406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9crvzqsQqnLoCgUjiFHAAAAWI"]
[Tue Jul 21 08:49:02.747373 2026] [security2:error] [pid 514479:tid 514741] [client 122.176.100.127:52080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9crvzqsQqnLoCgUjiFHgAAAYk"]
[Tue Jul 21 08:49:02.747490 2026] [security2:error] [pid 514479:tid 514741] [client 122.176.100.127:52080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9crvzqsQqnLoCgUjiFHgAAAYk"]
[Tue Jul 21 08:49:02.780365 2026] [security2:error] [pid 514479:tid 514621] [client 34.178.75.226:51662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9crvzqsQqnLoCgUjiFIAAAARE"]
[Tue Jul 21 08:49:02.853400 2026] [security2:error] [pid 511108:tid 511285] [client 35.229.94.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9croTd5soprXwxAH0eSAAAAC8"]
[Tue Jul 21 08:49:02.906167 2026] [autoindex:error] [pid 514479:tid 514718] [client 20.104.96.117:0] AH01276: Cannot serve directory /home3/gadelh32/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:49:02.917506 2026] [security2:error] [pid 511108:tid 511306] [client 216.73.160.193:38875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/wp-login.php"] [unique_id "al9croTd5soprXwxAH0eSwAAAEQ"]
[Tue Jul 21 08:49:02.933489 2026] [security2:error] [pid 514479:tid 514696] [client 46.253.131.21:64825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9crvzqsQqnLoCgUjiFFAAAAVw"], referer: https://insp1.com.br/wp-login.php
[Tue Jul 21 08:49:02.973436 2026] [security2:error] [pid 511108:tid 511242] [client 212.32.76.7:28509] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-login-css.php"] [unique_id "al9croTd5soprXwxAH0eTAAAAAQ"]
[Tue Jul 21 08:49:03.012031 2026] [security2:error] [pid 511108:tid 511340] [client 20.104.96.117:59650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/6.php"] [unique_id "al9cr4Td5soprXwxAH0eTQAAAGY"]
[Tue Jul 21 08:49:03.113976 2026] [security2:error] [pid 514479:tid 514711] [client 35.229.94.153:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9cr_zqsQqnLoCgUjiFJgAAAWs"]
[Tue Jul 21 08:49:03.130005 2026] [qos:error] [pid 514479:tid 514553] [remote 57.141.18.4:57710] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.4, id=al9cr_zqsQqnLoCgUjiFJwABIUQ
[Tue Jul 21 08:49:03.136244 2026] [security2:error] [pid 514479:tid 514620] [client 203.25.124.72:29989] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/mah/function.php"] [unique_id "al9cr_zqsQqnLoCgUjiFKAAAARA"]
[Tue Jul 21 08:49:03.201054 2026] [autoindex:error] [pid 514479:tid 514735] [client 20.104.96.117:0] AH01276: Cannot serve directory /home3/gadelh32/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:49:03.204030 2026] [security2:error] [pid 514479:tid 514664] [client 34.178.75.226:52928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9cr_zqsQqnLoCgUjiFLgAAATw"]
[Tue Jul 21 08:49:03.351045 2026] [security2:error] [pid 514479:tid 514621] [client 20.151.10.161:28045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/als.php"] [unique_id "al9cr_zqsQqnLoCgUjiFNAAAARE"]
[Tue Jul 21 08:49:03.357289 2026] [security2:error] [pid 511108:tid 511293] [client 20.104.96.117:44869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/abcd.php"] [unique_id "al9cr4Td5soprXwxAH0eWwAAADc"]
[Tue Jul 21 08:49:03.498331 2026] [qos:error] [pid 511108:tid 511213] [remote 57.141.18.95:30270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.95, id=al9cr4Td5soprXwxAH0eXQAAHmg
[Tue Jul 21 08:49:03.533620 2026] [security2:error] [pid 511108:tid 511254] [client 65.21.113.253:48676] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cr4Td5soprXwxAH0eTwAAABA"]
[Tue Jul 21 08:49:03.572327 2026] [security2:error] [pid 514479:tid 514635] [client 203.25.124.254:59095] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/exnova/content-index.php"] [unique_id "al9cr_zqsQqnLoCgUjiFNgAAAR8"]
[Tue Jul 21 08:49:03.620657 2026] [security2:error] [pid 514479:tid 514681] [client 20.226.60.151:57653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/txets.php"] [unique_id "al9cr_zqsQqnLoCgUjiFNwAAAU0"]
[Tue Jul 21 08:49:03.645559 2026] [security2:error] [pid 511108:tid 511361] [client 20.104.96.117:44195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/file15.php"] [unique_id "al9cr4Td5soprXwxAH0eXgAAAHs"]
[Tue Jul 21 08:49:03.667355 2026] [qos:error] [pid 514479:tid 514556] [remote 57.141.18.79:45324] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.79, id=al9cr_zqsQqnLoCgUjiFOQABXEc
[Tue Jul 21 08:49:03.692009 2026] [qos:error] [pid 514479:tid 514508] [remote 57.141.18.14:33850] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.14, id=al9cr_zqsQqnLoCgUjiFOwABWRg
[Tue Jul 21 08:49:03.761004 2026] [qos:error] [pid 511108:tid 511159] [remote 74.7.227.54:49270] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=74.7.227.54, id=al9cr4Td5soprXwxAH0eYQAAKjI, referer: https://arielson.com.br/coursos/?duration=medium%2CextraLong&filter_course-category=115,397,453&filter_course-tag=130%2C454%2C455%2C249%2C134&filtering=1&level=all_levels&orderby=course_title_za
[Tue Jul 21 08:49:03.868759 2026] [security2:error] [pid 511108:tid 511339] [client 20.104.96.117:3986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/patie.php"] [unique_id "al9cr4Td5soprXwxAH0eZgAAAGU"]
[Tue Jul 21 08:49:03.910181 2026] [qos:error] [pid 511108:tid 511229] [remote 57.141.18.57:33230] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.57, id=al9cr4Td5soprXwxAH0eZwAAJng
[Tue Jul 21 08:49:03.992233 2026] [security2:error] [pid 511108:tid 511308] [client 34.178.75.226:55614] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9cr4Td5soprXwxAH0eaQAAAEY"]
[Tue Jul 21 08:49:03.993564 2026] [security2:error] [pid 511108:tid 511342] [client 20.151.10.161:28527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/pol.php"] [unique_id "al9cr4Td5soprXwxAH0eagAAAGg"]
[Tue Jul 21 08:49:04.014613 2026] [security2:error] [pid 511108:tid 511289] [client 20.104.96.117:44278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/jp.php"] [unique_id "al9csITd5soprXwxAH0ebAAAADM"]
[Tue Jul 21 08:49:04.019024 2026] [proxy:error] [pid 514479:tid 514738] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:04.019118 2026] [proxy_http:error] [pid 514479:tid 514738] [client 198.235.24.24:64028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:04.019964 2026] [proxy:error] [pid 514479:tid 514738] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:04.020020 2026] [proxy_http:error] [pid 514479:tid 514738] [client 198.235.24.24:64028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:04.091792 2026] [security2:error] [pid 514479:tid 514485] [remote 173.252.82.37:45534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9cr_zqsQqnLoCgUjiFQgABTgE"]
[Tue Jul 21 08:49:04.134076 2026] [security2:error] [pid 514479:tid 514675] [client 103.59.206.240:31205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9csPzqsQqnLoCgUjiFRgAAAUc"]
[Tue Jul 21 08:49:04.134230 2026] [security2:error] [pid 514479:tid 514675] [client 103.59.206.240:31205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9csPzqsQqnLoCgUjiFRgAAAUc"]
[Tue Jul 21 08:49:04.182959 2026] [security2:error] [pid 511108:tid 511239] [client 203.25.124.48:30905] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/classwithtostring.php"] [unique_id "al9csITd5soprXwxAH0ebwAAAAE"]
[Tue Jul 21 08:49:04.263858 2026] [security2:error] [pid 514479:tid 514638] [client 20.104.96.117:59158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/32e17094cfindex.php"] [unique_id "al9csPzqsQqnLoCgUjiFSgAAASI"]
[Tue Jul 21 08:49:04.320514 2026] [security2:error] [pid 511108:tid 511285] [client 20.104.96.117:44282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/f35.php"] [unique_id "al9csITd5soprXwxAH0ecQAAAC8"]
[Tue Jul 21 08:49:04.381506 2026] [security2:error] [pid 511108:tid 511315] [client 195.49.128.211:56025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9csITd5soprXwxAH0ecgAAAE0"]
[Tue Jul 21 08:49:04.381631 2026] [security2:error] [pid 511108:tid 511315] [client 195.49.128.211:56025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9csITd5soprXwxAH0ecgAAAE0"]
[Tue Jul 21 08:49:04.570082 2026] [security2:error] [pid 514479:tid 514664] [client 203.25.124.254:48379] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/specia/content-index.php"] [unique_id "al9csPzqsQqnLoCgUjiFeAAAATw"]
[Tue Jul 21 08:49:04.601524 2026] [security2:error] [pid 514479:tid 514627] [client 20.104.96.117:44100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/wp-load.php"] [unique_id "al9csPzqsQqnLoCgUjiFegAAARc"]
[Tue Jul 21 08:49:04.621174 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.621314 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.621446 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.621511 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.621570 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.621699 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.621788 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.621859 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.621943 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.621999 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622051 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622105 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622159 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622211 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622265 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622318 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622371 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622424 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622478 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622530 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622582 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622635 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622687 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622739 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622793 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622856 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622910 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.622970 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623074 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623129 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623183 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623236 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623290 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623343 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623395 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623448 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623500 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623556 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623631 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623685 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623761 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623832 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623876 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623932 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.623994 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624048 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624101 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624154 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624222 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624278 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624330 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624383 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624436 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624489 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624542 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624597 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624649 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624704 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624758 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624817 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624904 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.624962 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625014 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625081 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625136 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625188 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625250 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625307 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625358 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625414 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625471 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625528 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625590 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625644 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625698 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625752 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625805 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625865 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625919 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.625981 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626035 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626087 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626141 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626194 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626247 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626301 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626354 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626410 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626463 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626517 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626575 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626630 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626692 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626747 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.626809 2026] [lsapi:warn] [pid 514479:tid 514633] [client 124.221.140.98:38298] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n, referer: https://www.atacadomaster.com/
[Tue Jul 21 08:49:04.640532 2026] [security2:error] [pid 514479:tid 514668] [client 203.25.124.54:29651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/languages/admin.php"] [unique_id "al9csPzqsQqnLoCgUjiFfgAAAUA"]
[Tue Jul 21 08:49:04.643541 2026] [security2:error] [pid 511108:tid 511257] [client 20.151.10.161:28246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file5.php"] [unique_id "al9csITd5soprXwxAH0eeAAAABM"]
[Tue Jul 21 08:49:04.762432 2026] [security2:error] [pid 514479:tid 514643] [client 20.104.96.117:46747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/aa.php"] [unique_id "al9csPzqsQqnLoCgUjiFggAAASc"]
[Tue Jul 21 08:49:04.871099 2026] [security2:error] [pid 514479:tid 514737] [client 34.178.75.226:52928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9csPzqsQqnLoCgUjiFhgAAAYU"]
[Tue Jul 21 08:49:04.893997 2026] [security2:error] [pid 511108:tid 511253] [client 20.104.96.117:44274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/xyn.php"] [unique_id "al9csITd5soprXwxAH0efwAAAA8"]
[Tue Jul 21 08:49:04.902225 2026] [security2:error] [pid 514479:tid 514624] [client 20.226.60.151:59759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/dex.php"] [unique_id "al9csPzqsQqnLoCgUjiFiAAAARQ"]
[Tue Jul 21 08:49:05.168809 2026] [security2:error] [pid 514479:tid 514626] [client 203.25.124.68:21139] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Text/Diff/Engine/template-singl-portfolio.php"] [unique_id "al9csfzqsQqnLoCgUjiFiwAAARY"]
[Tue Jul 21 08:49:05.211575 2026] [security2:error] [pid 514479:tid 514620] [client 20.151.10.161:28167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9csfzqsQqnLoCgUjiFjAAAARA"]
[Tue Jul 21 08:49:05.237067 2026] [autoindex:error] [pid 514479:tid 514711] [client 20.104.96.117:0] AH01276: Cannot serve directory /home3/gadelh32/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:49:05.323782 2026] [security2:error] [pid 511108:tid 511295] [client 118.195.159.13:57256] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "wilkermoronicriminalista.com"] [uri "/wp-comments-post.php"] [unique_id "al9csITd5soprXwxAH0egAAAADk"]
[Tue Jul 21 08:49:05.421635 2026] [security2:error] [pid 511108:tid 511323] [client 41.89.234.2:53759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9csYTd5soprXwxAH0ejAAAAFU"]
[Tue Jul 21 08:49:05.421759 2026] [security2:error] [pid 511108:tid 511323] [client 41.89.234.2:53759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9csYTd5soprXwxAH0ejAAAAFU"]
[Tue Jul 21 08:49:05.500343 2026] [security2:error] [pid 514479:tid 514665] [client 34.178.75.226:63509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9csfzqsQqnLoCgUjiFlwAAAT0"]
[Tue Jul 21 08:49:05.564483 2026] [autoindex:error] [pid 511108:tid 511305] [client 20.104.96.117:44126] AH01276: Cannot serve directory /home3/gadelh32/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:49:05.638430 2026] [security2:error] [pid 514479:tid 514624] [client 203.25.124.211:63621] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/spacer/"] [unique_id "al9csfzqsQqnLoCgUjiFnAAAARQ"]
[Tue Jul 21 08:49:05.639977 2026] [security2:error] [pid 514479:tid 514630] [client 20.104.96.117:59146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/qqqa.php"] [unique_id "al9csfzqsQqnLoCgUjiFnQAAARo"]
[Tue Jul 21 08:49:05.713369 2026] [security2:error] [pid 511108:tid 511289] [client 20.104.96.117:44126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/ccc.php"] [unique_id "al9csYTd5soprXwxAH0emAAAADM"]
[Tue Jul 21 08:49:05.713371 2026] [security2:error] [pid 511108:tid 511295] [client 118.195.159.13:57256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "wilkermoronicriminalista.com"] [uri "/wp-comments-post.php"] [unique_id "al9csITd5soprXwxAH0egAAAADk"]
[Tue Jul 21 08:49:05.813882 2026] [security2:error] [pid 514479:tid 514674] [client 20.104.96.117:4070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/xwpg.php"] [unique_id "al9csfzqsQqnLoCgUjiFoAAAAUY"]
[Tue Jul 21 08:49:05.971047 2026] [security2:error] [pid 511108:tid 511306] [client 20.226.60.151:59715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/xpwer1.php"] [unique_id "al9csYTd5soprXwxAH0eogAAAEQ"]
[Tue Jul 21 08:49:05.976204 2026] [security2:error] [pid 514479:tid 514699] [client 212.32.76.55:63849] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "al9csfzqsQqnLoCgUjiFogAAAV8"]
[Tue Jul 21 08:49:05.994534 2026] [security2:error] [pid 514479:tid 514690] [client 20.104.96.117:44144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/w.php"] [unique_id "al9csfzqsQqnLoCgUjiFowAAAVY"]
[Tue Jul 21 08:49:06.006294 2026] [security2:error] [pid 514479:tid 514633] [client 34.178.75.226:64896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9csvzqsQqnLoCgUjiFpAAAAR0"]
[Tue Jul 21 08:49:06.024366 2026] [security2:error] [pid 514479:tid 514485] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9csvzqsQqnLoCgUjiFpQABhQE"]
[Tue Jul 21 08:49:06.024503 2026] [security2:error] [pid 514479:tid 514737] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9csvzqsQqnLoCgUjiFpQABhQE"]
[Tue Jul 21 08:49:06.060356 2026] [security2:error] [pid 514479:tid 514664] [client 113.22.144.139:51060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9csvzqsQqnLoCgUjiFpgAAATw"]
[Tue Jul 21 08:49:06.061063 2026] [security2:error] [pid 514479:tid 514664] [client 113.22.144.139:51060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9csvzqsQqnLoCgUjiFpgAAATw"]
[Tue Jul 21 08:49:06.163399 2026] [security2:error] [pid 514479:tid 514621] [client 203.25.124.57:24305] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "al9csvzqsQqnLoCgUjiFqAAAARE"]
[Tue Jul 21 08:49:06.201470 2026] [security2:error] [pid 511108:tid 511158] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9csoTd5soprXwxAH0epQAAXTE"]
[Tue Jul 21 08:49:06.201681 2026] [security2:error] [pid 511108:tid 511331] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9csoTd5soprXwxAH0epQAAXTE"]
[Tue Jul 21 08:49:06.298316 2026] [security2:error] [pid 514479:tid 514682] [client 20.104.96.117:44142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9csvzqsQqnLoCgUjiFqwAAAU4"]
[Tue Jul 21 08:49:06.415589 2026] [security2:error] [pid 514479:tid 514630] [client 34.178.75.226:56714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9csvzqsQqnLoCgUjiFrwAAARo"]
[Tue Jul 21 08:49:06.635493 2026] [security2:error] [pid 511108:tid 511341] [client 20.104.96.117:44158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/FWAZ.php"] [unique_id "al9csoTd5soprXwxAH0esAAAAGc"]
[Tue Jul 21 08:49:06.651574 2026] [security2:error] [pid 514479:tid 514697] [client 173.252.95.28:32974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9csfzqsQqnLoCgUjiFlgAAAV0"]
[Tue Jul 21 08:49:06.708329 2026] [security2:error] [pid 514479:tid 514725] [client 20.151.10.161:28597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file.php"] [unique_id "al9csvzqsQqnLoCgUjiFtgAAAXk"]
[Tue Jul 21 08:49:06.719950 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720047 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720156 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720203 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720242 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720351 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720425 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720463 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720513 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720548 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720583 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720618 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720651 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720686 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720721 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720755 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720790 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720837 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720872 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720907 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720957 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.720992 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721026 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721060 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721095 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721130 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721165 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721199 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721310 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721330 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721361 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721397 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721432 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721466 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721501 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721537 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721572 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721608 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721643 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721678 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721716 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721767 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721803 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721850 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721885 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721947 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.721988 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722017 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722076 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722167 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722225 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722266 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722302 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722338 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722374 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722423 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722461 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722499 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722534 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722572 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722608 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722642 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722679 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722715 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722753 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722788 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722834 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722871 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722907 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722950 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.722999 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723037 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723073 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723118 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723156 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723192 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723229 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723268 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723306 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723348 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723384 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723422 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723457 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723493 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723529 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723566 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723602 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723637 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723673 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723709 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723744 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723781 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723831 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723862 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723900 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723940 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.723976 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.724015 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.724050 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.724094 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.724130 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.724174 2026] [lsapi:warn] [pid 511108:tid 511143] [remote 189.6.178.120:49925] [host atacadomaster.com] Backend log: PHP Warning:  Statically_Rewriter::rewrite_url(): Argument #1 ($asset) must be passed by reference, value given in /home3/atacad84/public_html/wp-content/plugins/statically/inc/statically_rewriter.class.php on line 343\n
[Tue Jul 21 08:49:06.741501 2026] [security2:error] [pid 514479:tid 514674] [client 203.25.124.35:21003] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/certificates/chosen.php"] [unique_id "al9csvzqsQqnLoCgUjiFtwAAAUY"]
[Tue Jul 21 08:49:06.875456 2026] [security2:error] [pid 514479:tid 514621] [client 34.178.75.226:55381] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9csvzqsQqnLoCgUjiFvgAAARE"]
[Tue Jul 21 08:49:06.924176 2026] [security2:error] [pid 514479:tid 514738] [client 20.104.96.117:44163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/miru1.php"] [unique_id "al9csvzqsQqnLoCgUjiFwQAAAYY"]
[Tue Jul 21 08:49:06.928691 2026] [security2:error] [pid 511108:tid 511294] [client 20.104.96.117:59136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/aunmc.php"] [unique_id "al9csoTd5soprXwxAH0fAQAAADg"]
[Tue Jul 21 08:49:07.169162 2026] [security2:error] [pid 511108:tid 511295] [client 212.32.76.59:53447] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/css/eroor.php"] [unique_id "al9cs4Td5soprXwxAH0fFQAAADk"]
[Tue Jul 21 08:49:07.241898 2026] [security2:error] [pid 514479:tid 514725] [client 20.104.96.117:44221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/aa.php"] [unique_id "al9cs_zqsQqnLoCgUjiFyAAAAXk"]
[Tue Jul 21 08:49:07.242676 2026] [qos:error] [pid 514479:tid 514610] [remote 57.141.18.98:44834] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.98, id=al9cs_zqsQqnLoCgUjiFyQABg30
[Tue Jul 21 08:49:07.362256 2026] [security2:error] [pid 514479:tid 514637] [client 203.25.124.51:42125] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/lock360.php"] [unique_id "al9cs_zqsQqnLoCgUjiFywAAASE"]
[Tue Jul 21 08:49:07.368882 2026] [qos:error] [pid 511108:tid 511179] [remote 57.141.18.57:33240] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.57, id=al9cs4Td5soprXwxAH0fHAAAPkY
[Tue Jul 21 08:49:07.404195 2026] [security2:error] [pid 514479:tid 514633] [client 20.104.96.117:3993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/ops.php"] [unique_id "al9cs_zqsQqnLoCgUjiFzAAAAR0"]
[Tue Jul 21 08:49:07.421911 2026] [security2:error] [pid 514479:tid 514715] [client 34.178.75.226:64626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9cs_zqsQqnLoCgUjiFzwAAAW8"]
[Tue Jul 21 08:49:07.443769 2026] [security2:error] [pid 514479:tid 514695] [client 20.151.10.161:28246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/cfile.php"] [unique_id "al9cs_zqsQqnLoCgUjiF0QAAAVs"]
[Tue Jul 21 08:49:07.490587 2026] [security2:error] [pid 514479:tid 514583] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cs_zqsQqnLoCgUjiF0gABPWI"]
[Tue Jul 21 08:49:07.490778 2026] [security2:error] [pid 514479:tid 514665] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cs_zqsQqnLoCgUjiF0gABPWI"]
[Tue Jul 21 08:49:07.514293 2026] [security2:error] [pid 511108:tid 511306] [client 20.226.60.151:59755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/flox.php"] [unique_id "al9cs4Td5soprXwxAH0fIQAAAEQ"]
[Tue Jul 21 08:49:07.585625 2026] [security2:error] [pid 511108:tid 511340] [client 20.104.96.117:44237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/122.php"] [unique_id "al9cs4Td5soprXwxAH0fJQAAAGY"]
[Tue Jul 21 08:49:07.587444 2026] [security2:error] [pid 514479:tid 514682] [client 103.98.85.204:61162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.85.98.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kslifepro.com"] [uri "/xmlrpc.php"] [unique_id "al9cs_zqsQqnLoCgUjiF1AAAAU4"]
[Tue Jul 21 08:49:07.587636 2026] [security2:error] [pid 514479:tid 514682] [client 103.98.85.204:61162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kslifepro.com"] [uri "/xmlrpc.php"] [unique_id "al9cs_zqsQqnLoCgUjiF1AAAAU4"]
[Tue Jul 21 08:49:07.658453 2026] [security2:error] [pid 511108:tid 511353] [client 83.97.116.56:51713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9csoTd5soprXwxAH0epgAAAHM"], referer: https://insp1.com.br/wp-login.php
[Tue Jul 21 08:49:07.742423 2026] [security2:error] [pid 511108:tid 511241] [client 203.25.124.51:46735] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/shortcode/"] [unique_id "al9cs4Td5soprXwxAH0fJwAAAAM"]
[Tue Jul 21 08:49:07.897671 2026] [security2:error] [pid 514479:tid 514708] [client 20.104.96.117:44150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/get.php"] [unique_id "al9cs_zqsQqnLoCgUjiF2gAAAWg"]
[Tue Jul 21 08:49:08.010077 2026] [security2:error] [pid 514479:tid 514695] [client 20.104.96.117:61134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/uoocf.php"] [unique_id "al9ctPzqsQqnLoCgUjiF3wAAAVs"]
[Tue Jul 21 08:49:08.055038 2026] [security2:error] [pid 514479:tid 514741] [client 34.178.75.226:58113] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "seguryredes.com.br.hostag.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9ctPzqsQqnLoCgUjiF5AAAAYk"]
[Tue Jul 21 08:49:08.188936 2026] [security2:error] [pid 514479:tid 514734] [client 20.104.96.117:44129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/as.php"] [unique_id "al9ctPzqsQqnLoCgUjiF5gAAAYI"]
[Tue Jul 21 08:49:08.220336 2026] [security2:error] [pid 514479:tid 514517] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9ctPzqsQqnLoCgUjiF5wABISE"]
[Tue Jul 21 08:49:08.220512 2026] [security2:error] [pid 514479:tid 514637] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9ctPzqsQqnLoCgUjiF5wABISE"]
[Tue Jul 21 08:49:08.234694 2026] [security2:error] [pid 514479:tid 514620] [client 195.206.105.227:44250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9ctPzqsQqnLoCgUjiF6AAAARA"]
[Tue Jul 21 08:49:08.234788 2026] [security2:error] [pid 514479:tid 514620] [client 195.206.105.227:44250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9ctPzqsQqnLoCgUjiF6AAAARA"]
[Tue Jul 21 08:49:08.264537 2026] [security2:error] [pid 514479:tid 514711] [client 203.25.124.37:53821] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/alfa.php"] [unique_id "al9ctPzqsQqnLoCgUjiF6QAAAWs"]
[Tue Jul 21 08:49:08.292562 2026] [security2:error] [pid 511108:tid 511284] [client 20.197.192.193:9448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/fffm.php"] [unique_id "al9ctITd5soprXwxAH0fLQAAAC4"]
[Tue Jul 21 08:49:08.316100 2026] [security2:error] [pid 514479:tid 514678] [client 74.7.228.23:43230] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "fit4me.online"] [uri "/robots.txt"] [unique_id "al9ctPzqsQqnLoCgUjiF6gABSm4"]
[Tue Jul 21 08:49:08.327508 2026] [security2:error] [pid 511108:tid 511301] [client 20.151.10.161:62409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/puc.php"] [unique_id "al9ctITd5soprXwxAH0fLwAAAD8"]
[Tue Jul 21 08:49:08.490105 2026] [security2:error] [pid 514479:tid 514664] [client 74.7.228.23:43230] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fit4me.online"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al9ctPzqsQqnLoCgUjiF6wABPGo"], referer: https://fit4me.online/robots.txt
[Tue Jul 21 08:49:08.537035 2026] [security2:error] [pid 514479:tid 514695] [client 20.151.10.161:28169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/class-wp.php"] [unique_id "al9ctPzqsQqnLoCgUjiF7QAAAVs"]
[Tue Jul 21 08:49:08.570808 2026] [security2:error] [pid 511108:tid 511335] [client 203.25.124.193:42135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/languages/themes/home.php"] [unique_id "al9ctITd5soprXwxAH0fNgAAAGE"]
[Tue Jul 21 08:49:08.580561 2026] [security2:error] [pid 514479:tid 514621] [client 20.104.96.117:44182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/ccou.php"] [unique_id "al9ctPzqsQqnLoCgUjiF7gAAARE"]
[Tue Jul 21 08:49:08.581982 2026] [security2:error] [pid 514479:tid 514738] [client 20.226.60.151:57572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/popo.php"] [unique_id "al9ctPzqsQqnLoCgUjiF7wAAAYY"]
[Tue Jul 21 08:49:08.615754 2026] [security2:error] [pid 511108:tid 511319] [client 65.21.113.253:48676] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ctITd5soprXwxAH0fKwAAAFE"]
[Tue Jul 21 08:49:08.652404 2026] [security2:error] [pid 511108:tid 511345] [client 182.189.99.211:47896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ctITd5soprXwxAH0fOAAAAGs"]
[Tue Jul 21 08:49:08.652514 2026] [security2:error] [pid 511108:tid 511345] [client 182.189.99.211:47896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ctITd5soprXwxAH0fOAAAAGs"]
[Tue Jul 21 08:49:08.652999 2026] [security2:error] [pid 511108:tid 511305] [client 203.25.124.43:26389] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/edit-wolf.php"] [unique_id "al9ctITd5soprXwxAH0fOQAAAEM"]
[Tue Jul 21 08:49:08.672240 2026] [security2:error] [pid 514479:tid 514665] [client 20.104.96.117:46735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/mac.php"] [unique_id "al9ctPzqsQqnLoCgUjiF8AAAAT0"]
[Tue Jul 21 08:49:08.820232 2026] [security2:error] [pid 514479:tid 514640] [client 20.104.96.117:61178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/iywwi.php"] [unique_id "al9ctPzqsQqnLoCgUjiF8QAAASQ"]
[Tue Jul 21 08:49:08.876423 2026] [security2:error] [pid 511108:tid 511308] [client 20.104.96.117:44161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/w3lls.php"] [unique_id "al9ctITd5soprXwxAH0fOwAAAEY"]
[Tue Jul 21 08:49:09.190959 2026] [security2:error] [pid 511108:tid 511256] [client 20.104.96.117:44151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/test1.php"] [unique_id "al9ctYTd5soprXwxAH0fQQAAABI"]
[Tue Jul 21 08:49:09.268954 2026] [security2:error] [pid 514479:tid 514646] [client 203.25.124.64:44617] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "al9ctfzqsQqnLoCgUjiF-AAAASo"]
[Tue Jul 21 08:49:09.425316 2026] [security2:error] [pid 511108:tid 511252] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ctYTd5soprXwxAH0fRAAADi4"]
[Tue Jul 21 08:49:09.447450 2026] [security2:error] [pid 514479:tid 514664] [client 20.151.10.161:28081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/admin.php"] [unique_id "al9ctfzqsQqnLoCgUjiF-wAAATw"]
[Tue Jul 21 08:49:09.471623 2026] [security2:error] [pid 514479:tid 514602] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9ctfzqsQqnLoCgUjiF_QABcnU"]
[Tue Jul 21 08:49:09.471773 2026] [security2:error] [pid 514479:tid 514718] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9ctfzqsQqnLoCgUjiF_QABcnU"]
[Tue Jul 21 08:49:09.495100 2026] [security2:error] [pid 511108:tid 511242] [client 20.104.96.117:44251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/database.php"] [unique_id "al9ctYTd5soprXwxAH0fRwAAAAQ"]
[Tue Jul 21 08:49:09.567066 2026] [security2:error] [pid 511108:tid 511288] [client 20.104.96.117:59159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/gqgsa.php"] [unique_id "al9ctYTd5soprXwxAH0fTQAAADI"]
[Tue Jul 21 08:49:09.567297 2026] [security2:error] [pid 511108:tid 511283] [client 20.197.192.193:8375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/ftde.php"] [unique_id "al9ctYTd5soprXwxAH0fTgAAAC0"]
[Tue Jul 21 08:49:09.769045 2026] [qos:error] [pid 514479:tid 514515] [remote 57.141.18.1:26850] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.1, id=al9ctfzqsQqnLoCgUjiGAwABJB8
[Tue Jul 21 08:49:09.798380 2026] [security2:error] [pid 511108:tid 511329] [client 20.104.96.117:44191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/file.php"] [unique_id "al9ctYTd5soprXwxAH0fUgAAAFs"]
[Tue Jul 21 08:49:09.806251 2026] [security2:error] [pid 511108:tid 511361] [client 5.31.193.106:1819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ctYTd5soprXwxAH0fUwAAAHs"]
[Tue Jul 21 08:49:09.806414 2026] [security2:error] [pid 511108:tid 511361] [client 5.31.193.106:1819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9ctYTd5soprXwxAH0fUwAAAHs"]
[Tue Jul 21 08:49:09.932610 2026] [security2:error] [pid 514479:tid 514697] [client 20.151.10.161:28520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/aa2.php"] [unique_id "al9ctfzqsQqnLoCgUjiGBQAAAV0"]
[Tue Jul 21 08:49:09.970279 2026] [security2:error] [pid 511108:tid 511341] [client 20.197.192.193:9433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/yup.php"] [unique_id "al9ctYTd5soprXwxAH0fVgAAAGc"]
[Tue Jul 21 08:49:10.041058 2026] [security2:error] [pid 511108:tid 511259] [client 168.167.81.163:59977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9ctoTd5soprXwxAH0fVwAAABU"]
[Tue Jul 21 08:49:10.041166 2026] [security2:error] [pid 511108:tid 511259] [client 168.167.81.163:59977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9ctoTd5soprXwxAH0fVwAAABU"]
[Tue Jul 21 08:49:10.074520 2026] [security2:error] [pid 514479:tid 514626] [client 203.25.124.185:30669] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/languages/plugins/options.php"] [unique_id "al9ctvzqsQqnLoCgUjiGBgAAARY"]
[Tue Jul 21 08:49:10.097071 2026] [security2:error] [pid 511108:tid 511284] [client 20.104.96.117:44192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/file.php"] [unique_id "al9ctoTd5soprXwxAH0fWwAAAC4"]
[Tue Jul 21 08:49:10.142772 2026] [security2:error] [pid 511108:tid 511309] [client 203.25.124.212:65017] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/2021/10/"] [unique_id "al9ctoTd5soprXwxAH0fXQAAAEc"]
[Tue Jul 21 08:49:10.266579 2026] [security2:error] [pid 514479:tid 514711] [client 203.25.124.37:52605] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/templates/atomic/templates.php"] [unique_id "al9ctvzqsQqnLoCgUjiGDAAAAWs"]
[Tue Jul 21 08:49:10.319058 2026] [security2:error] [pid 514479:tid 514638] [client 49.144.66.253:33459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ctvzqsQqnLoCgUjiGDQAAASI"]
[Tue Jul 21 08:49:10.319242 2026] [security2:error] [pid 514479:tid 514638] [client 49.144.66.253:33459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9ctvzqsQqnLoCgUjiGDQAAASI"]
[Tue Jul 21 08:49:10.399252 2026] [security2:error] [pid 511108:tid 511323] [client 20.104.96.117:44132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/777.php"] [unique_id "al9ctoTd5soprXwxAH0fYAAAAFU"]
[Tue Jul 21 08:49:10.406033 2026] [security2:error] [pid 514479:tid 514720] [client 20.226.60.151:53522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/yas.php"] [unique_id "al9ctvzqsQqnLoCgUjiGDwAAAXQ"]
[Tue Jul 21 08:49:10.431393 2026] [security2:error] [pid 514479:tid 514525] [remote 103.133.28.98:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.28.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ctvzqsQqnLoCgUjiGEAABRik"]
[Tue Jul 21 08:49:10.431559 2026] [security2:error] [pid 514479:tid 514674] [client 103.133.28.98:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9ctvzqsQqnLoCgUjiGEAABRik"]
[Tue Jul 21 08:49:10.698954 2026] [security2:error] [pid 511108:tid 511351] [client 20.104.96.117:44174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/ssixta.php"] [unique_id "al9ctoTd5soprXwxAH0fZgAAAHE"]
[Tue Jul 21 08:49:10.836738 2026] [security2:error] [pid 511108:tid 511256] [client 20.151.10.161:28180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/ccou.php"] [unique_id "al9ctoTd5soprXwxAH0fawAAABI"]
[Tue Jul 21 08:49:10.938253 2026] [security2:error] [pid 514479:tid 514643] [client 34.74.154.250:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.154.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ctfzqsQqnLoCgUjiGBAAAASc"]
[Tue Jul 21 08:49:10.962216 2026] [security2:error] [pid 514479:tid 514669] [client 20.197.192.193:9574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/jj.php"] [unique_id "al9ctvzqsQqnLoCgUjiGFQAAAUE"]
[Tue Jul 21 08:49:11.014092 2026] [security2:error] [pid 514479:tid 514626] [client 20.104.96.117:44136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/1c.php"] [unique_id "al9ct_zqsQqnLoCgUjiGFgAAARY"]
[Tue Jul 21 08:49:11.147368 2026] [security2:error] [pid 514479:tid 514699] [client 203.25.124.35:37017] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/widgets/admin.php"] [unique_id "al9ct_zqsQqnLoCgUjiGGQAAAV8"]
[Tue Jul 21 08:49:11.201507 2026] [security2:error] [pid 511108:tid 511288] [client 34.74.154.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9ct4Td5soprXwxAH0fcgAAADI"]
[Tue Jul 21 08:49:11.222781 2026] [security2:error] [pid 511108:tid 511283] [client 20.151.10.161:8408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/themes.php"] [unique_id "al9ct4Td5soprXwxAH0fcwAAAC0"]
[Tue Jul 21 08:49:11.269784 2026] [security2:error] [pid 514479:tid 514735] [client 203.25.124.36:34481] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-links.php"] [unique_id "al9ct_zqsQqnLoCgUjiGHgAAAYM"]
[Tue Jul 21 08:49:11.301125 2026] [security2:error] [pid 511108:tid 511331] [client 173.252.95.12:51880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ct4Td5soprXwxAH0fdAAAAF0"]
[Tue Jul 21 08:49:11.311735 2026] [security2:error] [pid 514479:tid 514633] [client 20.104.96.117:44186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/test2.php"] [unique_id "al9ct_zqsQqnLoCgUjiGHwAAAR0"]
[Tue Jul 21 08:49:11.312903 2026] [security2:error] [pid 514479:tid 514720] [client 20.104.96.117:59674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/elbzl.php"] [unique_id "al9ct_zqsQqnLoCgUjiGIAAAAXQ"]
[Tue Jul 21 08:49:11.480856 2026] [security2:error] [pid 514479:tid 514741] [client 203.25.124.10:22465] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/tinymce/themes/panel.php"] [unique_id "al9ct_zqsQqnLoCgUjiGJgAAAYk"]
[Tue Jul 21 08:49:11.581116 2026] [security2:error] [pid 514479:tid 514697] [client 34.74.154.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9ct_zqsQqnLoCgUjiGKAAAAV0"]
[Tue Jul 21 08:49:11.625313 2026] [security2:error] [pid 514479:tid 514627] [client 20.220.225.223:22545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/track.php"] [unique_id "al9ct_zqsQqnLoCgUjiGKgAAARc"]
[Tue Jul 21 08:49:11.641892 2026] [security2:error] [pid 514479:tid 514717] [client 20.151.10.161:28228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/dr.php"] [unique_id "al9ct_zqsQqnLoCgUjiGKwAAAXE"]
[Tue Jul 21 08:49:11.647330 2026] [security2:error] [pid 511108:tid 511279] [client 20.104.96.117:46762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/mg.php"] [unique_id "al9ct4Td5soprXwxAH0feQAAACk"]
[Tue Jul 21 08:49:11.661104 2026] [security2:error] [pid 514479:tid 514711] [client 20.104.96.117:44123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/buy.php"] [unique_id "al9ct_zqsQqnLoCgUjiGLgAAAWs"]
[Tue Jul 21 08:49:11.749254 2026] [security2:error] [pid 514479:tid 514614] [client 20.226.60.151:57659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/file61.php"] [unique_id "al9ct_zqsQqnLoCgUjiGLwAAAQo"]
[Tue Jul 21 08:49:11.882643 2026] [security2:error] [pid 514479:tid 514681] [client 34.74.154.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9ct_zqsQqnLoCgUjiGMwAAAU0"]
[Tue Jul 21 08:49:11.961000 2026] [security2:error] [pid 514479:tid 514697] [client 20.104.96.117:59666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/adjig.php"] [unique_id "al9ct_zqsQqnLoCgUjiGNQAAAV0"]
[Tue Jul 21 08:49:12.000374 2026] [security2:error] [pid 514479:tid 514699] [client 20.104.96.117:44173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/ssend.php"] [unique_id "al9cuPzqsQqnLoCgUjiGOQAAAV8"]
[Tue Jul 21 08:49:12.005160 2026] [security2:error] [pid 514479:tid 514641] [client 114.198.138.124:63766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cuPzqsQqnLoCgUjiGOgAAASU"]
[Tue Jul 21 08:49:12.005249 2026] [security2:error] [pid 514479:tid 514641] [client 114.198.138.124:63766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cuPzqsQqnLoCgUjiGOgAAASU"]
[Tue Jul 21 08:49:12.168474 2026] [security2:error] [pid 514479:tid 514685] [client 203.25.124.2:34357] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al9cuPzqsQqnLoCgUjiGPAAAAVE"]
[Tue Jul 21 08:49:12.178232 2026] [security2:error] [pid 511108:tid 511328] [client 203.25.124.209:42273] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Requests/Response/Response/multisite-setup.php"] [unique_id "al9cuITd5soprXwxAH0fggAAAFo"]
[Tue Jul 21 08:49:12.239983 2026] [security2:error] [pid 511108:tid 511287] [client 34.74.154.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9cuITd5soprXwxAH0fhAAAADE"]
[Tue Jul 21 08:49:12.301423 2026] [security2:error] [pid 514479:tid 514614] [client 20.104.96.117:44866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/item.php"] [unique_id "al9cuPzqsQqnLoCgUjiGQQAAAQo"]
[Tue Jul 21 08:49:12.365100 2026] [security2:error] [pid 514479:tid 514674] [client 152.59.181.104:50705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cuPzqsQqnLoCgUjiGQwAAAUY"]
[Tue Jul 21 08:49:12.369721 2026] [security2:error] [pid 514479:tid 514674] [client 152.59.181.104:50705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9cuPzqsQqnLoCgUjiGQwAAAUY"]
[Tue Jul 21 08:49:12.504402 2026] [security2:error] [pid 511108:tid 511308] [client 34.74.154.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9cuITd5soprXwxAH0fiQAAAEY"]
[Tue Jul 21 08:49:12.600974 2026] [security2:error] [pid 511108:tid 511289] [client 20.104.96.117:44238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/ss.php"] [unique_id "al9cuITd5soprXwxAH0fjAAAADM"]
[Tue Jul 21 08:49:12.769984 2026] [security2:error] [pid 514479:tid 514668] [client 34.74.154.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9cuPzqsQqnLoCgUjiGRgAAAUA"]
[Tue Jul 21 08:49:12.826375 2026] [security2:error] [pid 511108:tid 511352] [client 59.95.197.55:51135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cuITd5soprXwxAH0fkwAAAHI"]
[Tue Jul 21 08:49:12.826542 2026] [security2:error] [pid 511108:tid 511352] [client 59.95.197.55:51135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cuITd5soprXwxAH0fkwAAAHI"]
[Tue Jul 21 08:49:12.829998 2026] [security2:error] [pid 514479:tid 514690] [client 20.151.10.161:28248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/xamp.php"] [unique_id "al9cuPzqsQqnLoCgUjiGRwAAAVY"]
[Tue Jul 21 08:49:12.958241 2026] [security2:error] [pid 511108:tid 511286] [client 20.104.96.117:44276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/hypo.php"] [unique_id "al9cuITd5soprXwxAH0flgAAADA"]
[Tue Jul 21 08:49:13.090836 2026] [security2:error] [pid 514479:tid 514598] [remote 162.243.80.244:45438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.liranesuliano.acupunturaebemestar.com.br"] [uri "/.env"] [unique_id "al9cufzqsQqnLoCgUjiGTQABa3E"]
[Tue Jul 21 08:49:13.160971 2026] [security2:error] [pid 511108:tid 511349] [client 212.32.76.11:27073] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "al9cuYTd5soprXwxAH0fmQAAAG8"]
[Tue Jul 21 08:49:13.162350 2026] [security2:error] [pid 511108:tid 511279] [client 20.151.10.161:62417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/dx.php"] [unique_id "al9cuYTd5soprXwxAH0fmgAAACk"]
[Tue Jul 21 08:49:13.167384 2026] [security2:error] [pid 511108:tid 511341] [client 34.74.154.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9cuYTd5soprXwxAH0fmwAAAGc"]
[Tue Jul 21 08:49:13.212876 2026] [security2:error] [pid 511108:tid 511248] [client 20.151.10.161:28164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/bless.php"] [unique_id "al9cuYTd5soprXwxAH0fnQAAAAo"]
[Tue Jul 21 08:49:13.221060 2026] [security2:error] [pid 514479:tid 514715] [client 122.176.100.127:52557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cufzqsQqnLoCgUjiGTgAAAW8"]
[Tue Jul 21 08:49:13.221160 2026] [security2:error] [pid 514479:tid 514715] [client 122.176.100.127:52557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cufzqsQqnLoCgUjiGTgAAAW8"]
[Tue Jul 21 08:49:13.305852 2026] [security2:error] [pid 511108:tid 511335] [client 31.134.5.226:22991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9ctoTd5soprXwxAH0fbQAAAGE"], referer: https://insp1.com.br/wp-login.php
[Tue Jul 21 08:49:13.324695 2026] [security2:error] [pid 511108:tid 511355] [client 20.104.96.117:44130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/users.php"] [unique_id "al9cuYTd5soprXwxAH0fowAAAHU"]
[Tue Jul 21 08:49:13.376168 2026] [security2:error] [pid 514479:tid 514657] [client 5.38.115.39:50157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cufzqsQqnLoCgUjiGTwAAATU"]
[Tue Jul 21 08:49:13.376360 2026] [security2:error] [pid 514479:tid 514657] [client 5.38.115.39:50157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cufzqsQqnLoCgUjiGTwAAATU"]
[Tue Jul 21 08:49:13.439307 2026] [security2:error] [pid 511108:tid 511364] [client 34.74.154.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9cuYTd5soprXwxAH0fpgAAAH4"]
[Tue Jul 21 08:49:13.542686 2026] [security2:error] [pid 511108:tid 511249] [client 203.25.124.43:41241] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/tinymce/themes/"] [unique_id "al9cuYTd5soprXwxAH0fqAAAAAs"]
[Tue Jul 21 08:49:13.626475 2026] [security2:error] [pid 511108:tid 511287] [client 20.104.96.117:4063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-post-data.php"] [unique_id "al9cuYTd5soprXwxAH0fqQAAADE"]
[Tue Jul 21 08:49:13.636825 2026] [security2:error] [pid 514479:tid 514664] [client 20.104.96.117:44175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/177.php"] [unique_id "al9cufzqsQqnLoCgUjiGUQAAATw"]
[Tue Jul 21 08:49:13.668632 2026] [security2:error] [pid 514479:tid 514717] [client 20.151.10.161:28087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file46.php"] [unique_id "al9cufzqsQqnLoCgUjiGUgAAAXE"]
[Tue Jul 21 08:49:13.730040 2026] [security2:error] [pid 511108:tid 511290] [client 34.74.154.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9cuYTd5soprXwxAH0fqgAAADQ"]
[Tue Jul 21 08:49:13.773015 2026] [security2:error] [pid 511108:tid 511319] [client 212.32.76.57:50337] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/data.php"] [unique_id "al9cuYTd5soprXwxAH0frwAAAFE"]
[Tue Jul 21 08:49:13.833032 2026] [security2:error] [pid 514479:tid 514725] [client 20.226.60.151:59614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/water.php"] [unique_id "al9cufzqsQqnLoCgUjiGVAAAAXk"]
[Tue Jul 21 08:49:13.889726 2026] [security2:error] [pid 511108:tid 511328] [client 65.21.113.253:48676] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cuYTd5soprXwxAH0fpwAAAFo"]
[Tue Jul 21 08:49:13.964313 2026] [security2:error] [pid 514479:tid 514643] [client 20.104.96.117:44180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/config.php"] [unique_id "al9cufzqsQqnLoCgUjiGVgAAASc"]
[Tue Jul 21 08:49:14.007788 2026] [security2:error] [pid 514479:tid 514699] [client 20.104.96.117:61161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/byp.php"] [unique_id "al9cuvzqsQqnLoCgUjiGWAAAAV8"]
[Tue Jul 21 08:49:14.015841 2026] [security2:error] [pid 514479:tid 514696] [client 34.74.154.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9cuvzqsQqnLoCgUjiGWQAAAVw"]
[Tue Jul 21 08:49:14.046095 2026] [security2:error] [pid 514479:tid 514685] [client 20.151.10.161:28487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/eee.php"] [unique_id "al9cuvzqsQqnLoCgUjiGXAAAAVE"]
[Tue Jul 21 08:49:14.163965 2026] [security2:error] [pid 511108:tid 511360] [client 203.25.124.74:30815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/new.php"] [unique_id "al9cuoTd5soprXwxAH0ftgAAAHo"]
[Tue Jul 21 08:49:14.240429 2026] [security2:error] [pid 511108:tid 511282] [client 20.104.96.117:44286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/gettest.php"] [unique_id "al9cuoTd5soprXwxAH0ftwAAACw"]
[Tue Jul 21 08:49:14.286635 2026] [security2:error] [pid 511108:tid 511356] [client 20.151.10.161:62366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/p.php"] [unique_id "al9cuoTd5soprXwxAH0fugAAAHY"]
[Tue Jul 21 08:49:14.295158 2026] [security2:error] [pid 511108:tid 511272] [client 34.74.154.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9cuoTd5soprXwxAH0fuwAAACI"]
[Tue Jul 21 08:49:14.468956 2026] [security2:error] [pid 514479:tid 514587] [remote 37.59.204.142:22914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "jurencosmetics.com"] [uri "/robots.txt"] [unique_id "al9cuvzqsQqnLoCgUjiGYAABfGY"]
[Tue Jul 21 08:49:14.469101 2026] [security2:error] [pid 514479:tid 514728] [client 37.59.204.142:22914] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jurencosmetics.com"] [uri "/robots.txt"] [unique_id "al9cuvzqsQqnLoCgUjiGYAABfGY"]
[Tue Jul 21 08:49:14.475611 2026] [security2:error] [pid 514479:tid 514707] [client 20.151.10.161:28487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file25.php"] [unique_id "al9cuvzqsQqnLoCgUjiGYQAAAWc"]
[Tue Jul 21 08:49:14.531391 2026] [security2:error] [pid 514479:tid 514664] [client 20.104.96.117:44271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/min.php"] [unique_id "al9cuvzqsQqnLoCgUjiGYgAAATw"]
[Tue Jul 21 08:49:14.571747 2026] [security2:error] [pid 511108:tid 511322] [client 34.74.154.250:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9cuoTd5soprXwxAH0fwgAAAFQ"]
[Tue Jul 21 08:49:14.640615 2026] [security2:error] [pid 514479:tid 514621] [client 212.32.76.5:51993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/social-link/"] [unique_id "al9cuvzqsQqnLoCgUjiGZAAAARE"]
[Tue Jul 21 08:49:14.758804 2026] [security2:error] [pid 514479:tid 514706] [client 103.59.206.240:31230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cuvzqsQqnLoCgUjiGZQAAAWY"]
[Tue Jul 21 08:49:14.759384 2026] [security2:error] [pid 514479:tid 514706] [client 103.59.206.240:31230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cuvzqsQqnLoCgUjiGZQAAAWY"]
[Tue Jul 21 08:49:14.822185 2026] [security2:error] [pid 514479:tid 514643] [client 20.104.96.117:44168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/dvjul.php"] [unique_id "al9cuvzqsQqnLoCgUjiGaQAAASc"]
[Tue Jul 21 08:49:14.851004 2026] [security2:error] [pid 514479:tid 514638] [client 20.197.192.193:38253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9cuvzqsQqnLoCgUjiGawAAASI"]
[Tue Jul 21 08:49:14.862982 2026] [security2:error] [pid 514479:tid 514626] [client 20.151.10.161:28511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file48.php"] [unique_id "al9cuvzqsQqnLoCgUjiGbAAAARY"]
[Tue Jul 21 08:49:14.872077 2026] [security2:error] [pid 514479:tid 514526] [remote 47.128.23.2:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "expertemrecheios.com"] [uri "/robots.txt"] [unique_id "al9cuvzqsQqnLoCgUjiGbQABZCo"]
[Tue Jul 21 08:49:15.019470 2026] [security2:error] [pid 514479:tid 514717] [client 195.49.128.211:56633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cu_zqsQqnLoCgUjiGcAAAAXE"]
[Tue Jul 21 08:49:15.019595 2026] [security2:error] [pid 514479:tid 514717] [client 195.49.128.211:56633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cu_zqsQqnLoCgUjiGcAAAAXE"]
[Tue Jul 21 08:49:15.133355 2026] [security2:error] [pid 514479:tid 514660] [client 20.104.96.117:44108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/biufile.php"] [unique_id "al9cu_zqsQqnLoCgUjiGcwAAATg"]
[Tue Jul 21 08:49:15.282580 2026] [security2:error] [pid 514479:tid 514728] [client 212.32.76.54:57357] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/crop/crop/sitemap-generator.php"] [unique_id "al9cu_zqsQqnLoCgUjiGdAAAAXw"]
[Tue Jul 21 08:49:15.424445 2026] [security2:error] [pid 514479:tid 514725] [client 20.104.96.117:44203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/av.php"] [unique_id "al9cu_zqsQqnLoCgUjiGdgAAAXk"]
[Tue Jul 21 08:49:15.527932 2026] [security2:error] [pid 511108:tid 511311] [client 20.151.10.161:28225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file6.php"] [unique_id "al9cu4Td5soprXwxAH0f0AAAAEk"]
[Tue Jul 21 08:49:15.562367 2026] [security2:error] [pid 514479:tid 514643] [client 212.32.76.3:36707] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "al9cu_zqsQqnLoCgUjiGeQAAASc"]
[Tue Jul 21 08:49:15.711318 2026] [security2:error] [pid 511108:tid 511323] [client 20.104.96.117:44883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/coffexium.php"] [unique_id "al9cu4Td5soprXwxAH0f0wAAAFU"]
[Tue Jul 21 08:49:15.718928 2026] [security2:error] [pid 514479:tid 514638] [client 20.104.96.117:3972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/pucci.php"] [unique_id "al9cu_zqsQqnLoCgUjiGegAAASI"]
[Tue Jul 21 08:49:15.864156 2026] [security2:error] [pid 514479:tid 514708] [client 41.89.234.2:54216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cu_zqsQqnLoCgUjiGfAAAAWg"]
[Tue Jul 21 08:49:15.864275 2026] [security2:error] [pid 514479:tid 514708] [client 41.89.234.2:54216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cu_zqsQqnLoCgUjiGfAAAAWg"]
[Tue Jul 21 08:49:15.927653 2026] [security2:error] [pid 514479:tid 514703] [client 203.25.124.40:47305] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-good.php"] [unique_id "al9cu_zqsQqnLoCgUjiGfQAAAWM"]
[Tue Jul 21 08:49:15.965514 2026] [security2:error] [pid 511108:tid 511360] [client 20.104.96.117:59675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ortasekerli1.php"] [unique_id "al9cu4Td5soprXwxAH0f2gAAAHo"]
[Tue Jul 21 08:49:16.004196 2026] [security2:error] [pid 514479:tid 514645] [client 20.104.96.117:44215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/core.php"] [unique_id "al9cvPzqsQqnLoCgUjiGgAAAASk"]
[Tue Jul 21 08:49:16.016005 2026] [security2:error] [pid 511108:tid 511121] [remote 15.235.98.57:54958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "jurencosmetics.com"] [uri "/product/senscience-true-hue-shampoo-1000ml-33oz/"] [unique_id "al9cvITd5soprXwxAH0f3AAAFgw"]
[Tue Jul 21 08:49:16.016165 2026] [security2:error] [pid 511108:tid 511260] [client 15.235.98.57:54958] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jurencosmetics.com"] [uri "/product/senscience-true-hue-shampoo-1000ml-33oz/"] [unique_id "al9cvITd5soprXwxAH0f3AAAFgw"]
[Tue Jul 21 08:49:16.087527 2026] [security2:error] [pid 511108:tid 511300] [client 20.151.10.161:62425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/bthil.php"] [unique_id "al9cvITd5soprXwxAH0f3QAAAD4"]
[Tue Jul 21 08:49:16.109902 2026] [security2:error] [pid 511108:tid 511357] [client 20.197.192.193:22349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9cvITd5soprXwxAH0f3gAAAHc"]
[Tue Jul 21 08:49:16.119027 2026] [security2:error] [pid 511108:tid 511292] [client 20.151.10.161:27904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/a2.php"] [unique_id "al9cvITd5soprXwxAH0f3wAAADY"]
[Tue Jul 21 08:49:16.183442 2026] [security2:error] [pid 514479:tid 514678] [client 20.226.60.151:59737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/nano.php"] [unique_id "al9cvPzqsQqnLoCgUjiGhAAAAUo"]
[Tue Jul 21 08:49:16.304823 2026] [security2:error] [pid 514479:tid 514675] [client 20.104.96.117:44105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/als.php"] [unique_id "al9cvPzqsQqnLoCgUjiGhQAAAUc"]
[Tue Jul 21 08:49:16.388614 2026] [security2:error] [pid 514479:tid 514621] [client 212.32.76.62:38893] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Requests/Transport/Transport/spam-filter.php"] [unique_id "al9cvPzqsQqnLoCgUjiGhgAAARE"]
[Tue Jul 21 08:49:16.426674 2026] [security2:error] [pid 514479:tid 514519] [remote 159.223.116.62:39768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.116.223.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9cvPzqsQqnLoCgUjiGiAABCyM"]
[Tue Jul 21 08:49:16.466494 2026] [security2:error] [pid 511108:tid 511308] [client 203.25.124.70:24275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-links-opml.php"] [unique_id "al9cvITd5soprXwxAH0f5wAAAEY"]
[Tue Jul 21 08:49:16.557803 2026] [security2:error] [pid 511108:tid 511145] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cvITd5soprXwxAH0f6gAAQiQ"]
[Tue Jul 21 08:49:16.557971 2026] [security2:error] [pid 511108:tid 511304] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cvITd5soprXwxAH0f6gAAQiQ"]
[Tue Jul 21 08:49:16.688093 2026] [security2:error] [pid 511108:tid 511264] [client 20.104.96.117:44232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/simple.php"] [unique_id "al9cvITd5soprXwxAH0f7AAAABo"]
[Tue Jul 21 08:49:16.690262 2026] [security2:error] [pid 514479:tid 514549] [remote 45.76.153.27:37732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.153.76.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9cvPzqsQqnLoCgUjiGjAABTEA"]
[Tue Jul 21 08:49:16.713027 2026] [security2:error] [pid 511108:tid 511362] [client 20.151.10.161:28510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/file15.php"] [unique_id "al9cvITd5soprXwxAH0f7QAAAHw"]
[Tue Jul 21 08:49:16.739139 2026] [security2:error] [pid 511108:tid 511142] [remote 20.153.140.50:58446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "archrender.com.br"] [uri "/wp-login.php"] [unique_id "al9cvITd5soprXwxAH0f7gAAfyE"]
[Tue Jul 21 08:49:16.760828 2026] [security2:error] [pid 511108:tid 511343] [client 31.134.14.165:28943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9cvITd5soprXwxAH0f4QAAAGk"], referer: https://insp1.com.br/wp-login.php
[Tue Jul 21 08:49:16.875576 2026] [security2:error] [pid 514479:tid 514735] [client 20.151.10.161:62446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/7.php"] [unique_id "al9cvPzqsQqnLoCgUjiGjQAAAYM"]
[Tue Jul 21 08:49:16.891176 2026] [security2:error] [pid 511108:tid 511168] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cvITd5soprXwxAH0f8wAAOzs"]
[Tue Jul 21 08:49:16.891310 2026] [security2:error] [pid 511108:tid 511297] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cvITd5soprXwxAH0f8wAAOzs"]
[Tue Jul 21 08:49:16.939539 2026] [security2:error] [pid 514479:tid 514674] [client 113.22.144.139:51593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cvPzqsQqnLoCgUjiGjgAAAUY"]
[Tue Jul 21 08:49:16.940436 2026] [security2:error] [pid 514479:tid 514674] [client 113.22.144.139:51593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cvPzqsQqnLoCgUjiGjgAAAUY"]
[Tue Jul 21 08:49:17.043769 2026] [security2:error] [pid 511108:tid 511240] [client 203.25.124.47:42277] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/elementor/css/"] [unique_id "al9cvYTd5soprXwxAH0f-AAAAAI"]
[Tue Jul 21 08:49:17.054278 2026] [security2:error] [pid 514479:tid 514738] [client 20.104.96.117:44214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/init.php"] [unique_id "al9cvfzqsQqnLoCgUjiGjwAAAYY"]
[Tue Jul 21 08:49:17.247273 2026] [security2:error] [pid 514479:tid 514707] [client 20.151.10.161:28582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/jp.php"] [unique_id "al9cvfzqsQqnLoCgUjiGkwAAAWc"]
[Tue Jul 21 08:49:17.253320 2026] [security2:error] [pid 511108:tid 511345] [client 20.104.96.117:61284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/black.php"] [unique_id "al9cvYTd5soprXwxAH0f-gAAAGs"]
[Tue Jul 21 08:49:17.421413 2026] [security2:error] [pid 514479:tid 514706] [client 20.104.96.117:44109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/fpwch.php"] [unique_id "al9cvfzqsQqnLoCgUjiGlQAAAWY"]
[Tue Jul 21 08:49:17.676290 2026] [security2:error] [pid 514479:tid 514734] [client 212.32.76.54:62435] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/db-status.php"] [unique_id "al9cvfzqsQqnLoCgUjiGngAAAYI"]
[Tue Jul 21 08:49:17.721414 2026] [security2:error] [pid 514479:tid 514619] [client 20.226.60.151:59745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/moon.php"] [unique_id "al9cvfzqsQqnLoCgUjiGoAAAAQ8"]
[Tue Jul 21 08:49:17.905347 2026] [security2:error] [pid 511108:tid 511357] [client 20.151.10.161:28205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/f35.php"] [unique_id "al9cvYTd5soprXwxAH0gBAAAAHc"]
[Tue Jul 21 08:49:17.915460 2026] [security2:error] [pid 511108:tid 511307] [client 20.151.10.161:62398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/8.php"] [unique_id "al9cvYTd5soprXwxAH0gBQAAAEU"]
[Tue Jul 21 08:49:17.932192 2026] [security2:error] [pid 514479:tid 514643] [client 62.113.113.162:49262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.113.113.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.agrocibus.com.br"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9cvfzqsQqnLoCgUjiGoQAAASc"], referer: https://www.agrocibus.com.br/
[Tue Jul 21 08:49:18.118663 2026] [security2:error] [pid 514479:tid 514715] [client 20.197.192.193:38240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/dp.php"] [unique_id "al9cvvzqsQqnLoCgUjiGpAAAAW8"]
[Tue Jul 21 08:49:18.142998 2026] [security2:error] [pid 514479:tid 514627] [client 203.25.124.55:27195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/config.php"] [unique_id "al9cvvzqsQqnLoCgUjiGpQAAARc"]
[Tue Jul 21 08:49:18.227172 2026] [security2:error] [pid 511108:tid 511178] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cvoTd5soprXwxAH0gDAAANkU"]
[Tue Jul 21 08:49:18.227318 2026] [security2:error] [pid 511108:tid 511292] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cvoTd5soprXwxAH0gDAAANkU"]
[Tue Jul 21 08:49:18.333114 2026] [security2:error] [pid 514479:tid 514728] [client 20.104.96.117:44272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/domvf.php"] [unique_id "al9cvvzqsQqnLoCgUjiGpwAAAXw"]
[Tue Jul 21 08:49:18.563946 2026] [security2:error] [pid 514479:tid 514646] [client 203.25.124.47:35731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/revslider/includes/external/page/index.php"] [unique_id "al9cvvzqsQqnLoCgUjiGqgAAASo"]
[Tue Jul 21 08:49:18.597788 2026] [security2:error] [pid 511108:tid 511353] [client 65.21.113.253:48676] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cvoTd5soprXwxAH0gCgAAAHM"]
[Tue Jul 21 08:49:18.684754 2026] [security2:error] [pid 514479:tid 514607] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cvvzqsQqnLoCgUjiGqwABZ3o"]
[Tue Jul 21 08:49:18.684896 2026] [security2:error] [pid 514479:tid 514707] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cvvzqsQqnLoCgUjiGqwABZ3o"]
[Tue Jul 21 08:49:18.690110 2026] [security2:error] [pid 511108:tid 511264] [client 20.151.10.161:8447] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.eduhenmac.com.br"] [uri "/1.php"] [unique_id "al9cvoTd5soprXwxAH0gFAAAABo"]
[Tue Jul 21 08:49:18.690222 2026] [security2:error] [pid 511108:tid 511264] [client 20.151.10.161:8447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/1.php"] [unique_id "al9cvoTd5soprXwxAH0gFAAAABo"]
[Tue Jul 21 08:49:18.942684 2026] [security2:error] [pid 511108:tid 511263] [client 20.151.10.161:28181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-load.php"] [unique_id "al9cvoTd5soprXwxAH0gFwAAABk"]
[Tue Jul 21 08:49:19.023119 2026] [security2:error] [pid 511108:tid 511284] [client 20.104.96.117:44154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/wp.php"] [unique_id "al9cv4Td5soprXwxAH0gGgAAAC4"]
[Tue Jul 21 08:49:19.068241 2026] [security2:error] [pid 511108:tid 511266] [client 203.25.124.200:31791] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/SimplePie/XML/XML/sitemap-generator.php"] [unique_id "al9cv4Td5soprXwxAH0gHAAAABw"]
[Tue Jul 21 08:49:19.129896 2026] [security2:error] [pid 514479:tid 514636] [client 168.167.81.163:61818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cv_zqsQqnLoCgUjiGtQAAASA"]
[Tue Jul 21 08:49:19.130019 2026] [security2:error] [pid 514479:tid 514636] [client 168.167.81.163:61818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cv_zqsQqnLoCgUjiGtQAAASA"]
[Tue Jul 21 08:49:19.146686 2026] [security2:error] [pid 514479:tid 514706] [client 182.189.99.211:48364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cv_zqsQqnLoCgUjiGtgAAAWY"]
[Tue Jul 21 08:49:19.146760 2026] [security2:error] [pid 511108:tid 511279] [client 203.25.124.71:44837] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/rest-api/endpoints/"] [unique_id "al9cv4Td5soprXwxAH0gHQAAACk"]
[Tue Jul 21 08:49:19.146804 2026] [security2:error] [pid 514479:tid 514706] [client 182.189.99.211:48364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cv_zqsQqnLoCgUjiGtgAAAWY"]
[Tue Jul 21 08:49:19.285744 2026] [security2:error] [pid 514479:tid 514554] [remote 178.18.124.148:52688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.124.18.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/wp-login.php"] [unique_id "al9cv_zqsQqnLoCgUjiGuAABMEU"]
[Tue Jul 21 08:49:19.323095 2026] [security2:error] [pid 511108:tid 511240] [client 20.226.60.151:57537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-info.php"] [unique_id "al9cv4Td5soprXwxAH0gIAAAAAI"]
[Tue Jul 21 08:49:19.326810 2026] [access_compat:error] [pid 514479:tid 514633] [client 162.241.63.68:22374] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:49:19.477340 2026] [security2:error] [pid 514479:tid 514627] [client 20.104.96.117:44147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/class.php"] [unique_id "al9cv_zqsQqnLoCgUjiGvQAAARc"]
[Tue Jul 21 08:49:19.574836 2026] [security2:error] [pid 511108:tid 511294] [client 20.151.10.161:62440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/100.php"] [unique_id "al9cv4Td5soprXwxAH0gKAAAADg"]
[Tue Jul 21 08:49:19.643074 2026] [security2:error] [pid 514479:tid 514675] [client 20.197.192.193:38217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/old.php"] [unique_id "al9cv_zqsQqnLoCgUjiGxAAAAUc"]
[Tue Jul 21 08:49:19.675106 2026] [security2:error] [pid 514479:tid 514725] [client 20.104.96.117:4089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/zlece.php"] [unique_id "al9cv_zqsQqnLoCgUjiGxQAAAXk"]
[Tue Jul 21 08:49:19.954623 2026] [security2:error] [pid 514479:tid 514718] [client 20.104.96.117:44103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/echkm.php"] [unique_id "al9cv_zqsQqnLoCgUjiGxwAAAXI"]
[Tue Jul 21 08:49:19.963006 2026] [security2:error] [pid 514479:tid 514680] [client 203.25.124.49:63125] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/222.php"] [unique_id "al9cv_zqsQqnLoCgUjiGyAAAAUw"]
[Tue Jul 21 08:49:20.025686 2026] [security2:error] [pid 511108:tid 511282] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cv4Td5soprXwxAH0gKgAALCk"]
[Tue Jul 21 08:49:20.042328 2026] [security2:error] [pid 511108:tid 511219] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cwITd5soprXwxAH0gLAAAHm4"]
[Tue Jul 21 08:49:20.042437 2026] [security2:error] [pid 511108:tid 511268] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cwITd5soprXwxAH0gLAAAHm4"]
[Tue Jul 21 08:49:20.083711 2026] [security2:error] [pid 511108:tid 511360] [client 173.252.95.38:44002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cwITd5soprXwxAH0gMAAAAHo"]
[Tue Jul 21 08:49:20.128120 2026] [security2:error] [pid 511108:tid 511307] [client 20.151.10.161:28166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/xwpg.php"] [unique_id "al9cwITd5soprXwxAH0gMwAAAEU"]
[Tue Jul 21 08:49:20.141939 2026] [security2:error] [pid 514479:tid 514695] [client 20.197.192.193:38233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/ms-new.php"] [unique_id "al9cwPzqsQqnLoCgUjiGygAAAVs"]
[Tue Jul 21 08:49:20.353847 2026] [security2:error] [pid 514479:tid 514674] [client 20.104.96.117:59669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/classwithtostring.php"] [unique_id "al9cwPzqsQqnLoCgUjiGywAAAUY"]
[Tue Jul 21 08:49:20.380571 2026] [security2:error] [pid 511108:tid 511244] [client 64.42.179.43:33456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9cwITd5soprXwxAH0gNwAAAAY"]
[Tue Jul 21 08:49:20.380678 2026] [security2:error] [pid 511108:tid 511244] [client 64.42.179.43:33456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9cwITd5soprXwxAH0gNwAAAAY"]
[Tue Jul 21 08:49:20.450123 2026] [security2:error] [pid 511108:tid 511322] [client 203.25.124.64:21937] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/theme-compat/chosen.php"] [unique_id "al9cwITd5soprXwxAH0gOQAAAFQ"]
[Tue Jul 21 08:49:20.471996 2026] [security2:error] [pid 514479:tid 514641] [client 212.32.76.64:22899] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/test.php"] [unique_id "al9cwPzqsQqnLoCgUjiGzAAAASU"]
[Tue Jul 21 08:49:20.661148 2026] [security2:error] [pid 514479:tid 514724] [client 203.25.124.66:60609] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/about/function.php"] [unique_id "al9cwPzqsQqnLoCgUjiG1QAAAXg"]
[Tue Jul 21 08:49:20.794754 2026] [security2:error] [pid 514479:tid 514522] [remote 212.80.9.235:45506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.9.80.212.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "franciscaco.com.br"] [uri "/wp-login.php"] [unique_id "al9cv_zqsQqnLoCgUjiGwwABUSY"]
[Tue Jul 21 08:49:20.838844 2026] [security2:error] [pid 514479:tid 514668] [client 20.104.96.117:44217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/lib.php"] [unique_id "al9cwPzqsQqnLoCgUjiG2AAAAUA"]
[Tue Jul 21 08:49:20.897508 2026] [security2:error] [pid 511108:tid 511284] [client 20.151.10.161:62419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/about.php"] [unique_id "al9cwITd5soprXwxAH0gRAAAAC4"]
[Tue Jul 21 08:49:20.913895 2026] [security2:error] [pid 514479:tid 514696] [client 20.226.60.151:57637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/2000.php"] [unique_id "al9cwPzqsQqnLoCgUjiG3QAAAVw"]
[Tue Jul 21 08:49:21.129769 2026] [security2:error] [pid 514479:tid 514645] [client 45.121.0.214:51587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.0.121.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/xmlrpc.php"] [unique_id "al9cwPzqsQqnLoCgUjiG4AAAASk"]
[Tue Jul 21 08:49:21.129940 2026] [security2:error] [pid 514479:tid 514645] [client 45.121.0.214:51587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "atom-growth.com"] [uri "/xmlrpc.php"] [unique_id "al9cwPzqsQqnLoCgUjiG4AAAASk"]
[Tue Jul 21 08:49:21.277642 2026] [security2:error] [pid 514479:tid 514672] [client 49.144.66.253:29781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cwfzqsQqnLoCgUjiG4gAAAUQ"]
[Tue Jul 21 08:49:21.277879 2026] [security2:error] [pid 514479:tid 514672] [client 49.144.66.253:29781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9cwfzqsQqnLoCgUjiG4gAAAUQ"]
[Tue Jul 21 08:49:21.354010 2026] [security2:error] [pid 511108:tid 511323] [client 20.104.96.117:44171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/login.php"] [unique_id "al9cwYTd5soprXwxAH0gTgAAAFU"]
[Tue Jul 21 08:49:21.524237 2026] [security2:error] [pid 514479:tid 514669] [client 20.151.10.161:62386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/admin.php"] [unique_id "al9cwfzqsQqnLoCgUjiG5AAAAUE"]
[Tue Jul 21 08:49:21.588778 2026] [security2:error] [pid 511108:tid 511294] [client 20.151.10.161:28269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/waf.php"] [unique_id "al9cwYTd5soprXwxAH0gUgAAADg"]
[Tue Jul 21 08:49:21.610030 2026] [security2:error] [pid 514479:tid 514711] [client 20.104.96.117:4037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/vssrs.php"] [unique_id "al9cwfzqsQqnLoCgUjiG5QAAAWs"]
[Tue Jul 21 08:49:21.675240 2026] [security2:error] [pid 511108:tid 511305] [client 203.25.124.6:39161] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/jquery/ui/ui/forum-engine.php"] [unique_id "al9cwYTd5soprXwxAH0gVwAAAEM"]
[Tue Jul 21 08:49:21.837084 2026] [security2:error] [pid 511108:tid 511254] [client 193.202.16.196:42665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9cwITd5soprXwxAH0gOAAAABA"], referer: https://insp1.com.br/wp-login.php
[Tue Jul 21 08:49:21.871764 2026] [security2:error] [pid 511108:tid 511272] [client 203.25.124.42:34365] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/maint/about.php"] [unique_id "al9cwYTd5soprXwxAH0gXQAAACI"]
[Tue Jul 21 08:49:21.972100 2026] [security2:error] [pid 511108:tid 511300] [client 20.104.96.117:44135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/a2.php"] [unique_id "al9cwYTd5soprXwxAH0gYAAAAD4"]
[Tue Jul 21 08:49:22.306227 2026] [security2:error] [pid 511108:tid 511365] [client 20.151.10.161:28255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/xstelth.php"] [unique_id "al9cwoTd5soprXwxAH0gbAAAAH8"]
[Tue Jul 21 08:49:22.636136 2026] [security2:error] [pid 514479:tid 514705] [client 203.25.124.47:49517] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/root.php"] [unique_id "al9cwvzqsQqnLoCgUjiG5wAAAWU"]
[Tue Jul 21 08:49:22.711259 2026] [security2:error] [pid 514479:tid 514728] [client 20.151.10.161:8402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/edit.php"] [unique_id "al9cwvzqsQqnLoCgUjiG6AAAAXw"]
[Tue Jul 21 08:49:22.759409 2026] [security2:error] [pid 511108:tid 511153] [remote 167.71.240.77:59806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.240.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/wp-login.php"] [unique_id "al9cwoTd5soprXwxAH0gdAAAdSw"]
[Tue Jul 21 08:49:22.867724 2026] [security2:error] [pid 511108:tid 511339] [client 203.25.124.198:57073] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/tinymce/plugins/ms-files.php"] [unique_id "al9cwoTd5soprXwxAH0gdQAAAGU"]
[Tue Jul 21 08:49:22.999121 2026] [security2:error] [pid 514479:tid 514707] [client 20.151.10.161:28558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-links.php"] [unique_id "al9cwvzqsQqnLoCgUjiG7QAAAWc"]
[Tue Jul 21 08:49:23.090204 2026] [security2:error] [pid 514479:tid 514664] [client 65.21.113.253:42636] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9cw_zqsQqnLoCgUjiG7wAAATw"]
[Tue Jul 21 08:49:23.186084 2026] [security2:error] [pid 511108:tid 511249] [client 20.226.60.151:57608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/122.php"] [unique_id "al9cw4Td5soprXwxAH0geAAAAAs"]
[Tue Jul 21 08:49:23.281649 2026] [security2:error] [pid 511108:tid 511294] [client 20.151.10.161:62385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9cw4Td5soprXwxAH0gfQAAADg"]
[Tue Jul 21 08:49:23.358537 2026] [security2:error] [pid 514479:tid 514683] [client 59.95.197.55:51623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cw_zqsQqnLoCgUjiG8gAAAU8"]
[Tue Jul 21 08:49:23.358728 2026] [security2:error] [pid 514479:tid 514683] [client 59.95.197.55:51623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cw_zqsQqnLoCgUjiG8gAAAU8"]
[Tue Jul 21 08:49:23.535005 2026] [security2:error] [pid 511108:tid 511316] [client 20.104.96.117:44140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/d61.php"] [unique_id "al9cw4Td5soprXwxAH0ggQAAAE4"]
[Tue Jul 21 08:49:23.605608 2026] [security2:error] [pid 511108:tid 511359] [client 20.151.10.161:28558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9cw4Td5soprXwxAH0gggAAAHk"]
[Tue Jul 21 08:49:23.635927 2026] [security2:error] [pid 514479:tid 514626] [client 203.25.124.73:59607] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/widgets/"] [unique_id "al9cw_zqsQqnLoCgUjiG9QAAARY"]
[Tue Jul 21 08:49:23.702259 2026] [security2:error] [pid 514479:tid 514718] [client 122.176.100.127:53041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cw_zqsQqnLoCgUjiG9gAAAXI"]
[Tue Jul 21 08:49:23.702387 2026] [security2:error] [pid 514479:tid 514718] [client 122.176.100.127:53041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9cw_zqsQqnLoCgUjiG9gAAAXI"]
[Tue Jul 21 08:49:23.846347 2026] [security2:error] [pid 511108:tid 511357] [client 20.104.96.117:4051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wicked.php"] [unique_id "al9cw4Td5soprXwxAH0ghwAAAHc"]
[Tue Jul 21 08:49:23.946063 2026] [security2:error] [pid 514479:tid 514630] [client 20.104.96.117:44264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/info.php"] [unique_id "al9cw_zqsQqnLoCgUjiG_AAAARo"]
[Tue Jul 21 08:49:23.959439 2026] [security2:error] [pid 511108:tid 511288] [client 212.32.76.13:28183] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/upload/upload.php"] [unique_id "al9cw4Td5soprXwxAH0giQAAADI"]
[Tue Jul 21 08:49:23.967950 2026] [security2:error] [pid 514479:tid 514681] [client 65.21.113.253:35818] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cw_zqsQqnLoCgUjiG-gAAAU0"]
[Tue Jul 21 08:49:24.039447 2026] [security2:error] [pid 511108:tid 511360] [client 5.38.115.39:15211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cxITd5soprXwxAH0gigAAAHo"]
[Tue Jul 21 08:49:24.039589 2026] [security2:error] [pid 511108:tid 511360] [client 5.38.115.39:15211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cxITd5soprXwxAH0gigAAAHo"]
[Tue Jul 21 08:49:24.075586 2026] [security2:error] [pid 511108:tid 511342] [client 212.32.76.65:62829] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/includes/includes/logo/se.php"] [unique_id "al9cxITd5soprXwxAH0giwAAAGg"]
[Tue Jul 21 08:49:24.153492 2026] [security2:error] [pid 514479:tid 514633] [client 20.151.10.161:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/f6.php"] [unique_id "al9cxPzqsQqnLoCgUjiG_gAAAR0"]
[Tue Jul 21 08:49:24.296630 2026] [security2:error] [pid 514479:tid 514710] [client 20.151.10.161:28041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ibericaladrilhos.com.br"] [uri "/aaa.php"] [unique_id "al9cxPzqsQqnLoCgUjiHBAAAAWo"]
[Tue Jul 21 08:49:24.335005 2026] [security2:error] [pid 511108:tid 511329] [client 20.104.96.117:44281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/11.php"] [unique_id "al9cxITd5soprXwxAH0gmgAAAFs"]
[Tue Jul 21 08:49:24.440731 2026] [security2:error] [pid 514479:tid 514635] [client 65.21.113.253:42650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9cxPzqsQqnLoCgUjiHBgAAAR8"]
[Tue Jul 21 08:49:24.460908 2026] [security2:error] [pid 514479:tid 514615] [client 20.104.96.117:59655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/root.php"] [unique_id "al9cxPzqsQqnLoCgUjiHBwAAAQs"]
[Tue Jul 21 08:49:24.654402 2026] [security2:error] [pid 514479:tid 514704] [client 20.151.10.161:8431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/inputs.php"] [unique_id "al9cxPzqsQqnLoCgUjiHCQAAAWQ"]
[Tue Jul 21 08:49:24.728543 2026] [security2:error] [pid 511108:tid 511294] [client 20.104.96.117:44877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/v2.php"] [unique_id "al9cxITd5soprXwxAH0gpAAAADg"]
[Tue Jul 21 08:49:24.884376 2026] [security2:error] [pid 511108:tid 511276] [client 114.198.138.124:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cxITd5soprXwxAH0gqAAAACY"]
[Tue Jul 21 08:49:24.884486 2026] [security2:error] [pid 511108:tid 511276] [client 114.198.138.124:64335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9cxITd5soprXwxAH0gqAAAACY"]
[Tue Jul 21 08:49:25.039887 2026] [security2:error] [pid 511108:tid 511359] [client 203.25.124.31:53237] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/class.php"] [unique_id "al9cxYTd5soprXwxAH0gqgAAAHk"]
[Tue Jul 21 08:49:25.062913 2026] [security2:error] [pid 514479:tid 514689] [client 203.25.124.70:34111] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wpc.php"] [unique_id "al9cxfzqsQqnLoCgUjiHDgAAAVU"]
[Tue Jul 21 08:49:25.115939 2026] [security2:error] [pid 514479:tid 514638] [client 195.206.105.227:38906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9cxfzqsQqnLoCgUjiHDwAAASI"]
[Tue Jul 21 08:49:25.116024 2026] [security2:error] [pid 514479:tid 514638] [client 195.206.105.227:38906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9cxfzqsQqnLoCgUjiHDwAAASI"]
[Tue Jul 21 08:49:25.127595 2026] [security2:error] [pid 511108:tid 511262] [client 213.152.162.15:60072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cxYTd5soprXwxAH0grgAAABg"]
[Tue Jul 21 08:49:25.127684 2026] [security2:error] [pid 511108:tid 511262] [client 213.152.162.15:60072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9cxYTd5soprXwxAH0grgAAABg"]
[Tue Jul 21 08:49:25.132957 2026] [security2:error] [pid 514479:tid 514696] [client 20.151.10.161:8388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/av.php"] [unique_id "al9cxfzqsQqnLoCgUjiHEAAAAVw"]
[Tue Jul 21 08:49:25.181585 2026] [security2:error] [pid 511108:tid 511324] [client 69.171.230.42:57966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9cxYTd5soprXwxAH0grwAAAFY"]
[Tue Jul 21 08:49:25.271977 2026] [security2:error] [pid 511108:tid 511337] [client 20.104.96.117:44265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/panel.php"] [unique_id "al9cxYTd5soprXwxAH0gsAAAAGM"]
[Tue Jul 21 08:49:25.425191 2026] [security2:error] [pid 514479:tid 514707] [client 103.59.206.240:31500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cxfzqsQqnLoCgUjiHFQAAAWc"]
[Tue Jul 21 08:49:25.425321 2026] [security2:error] [pid 514479:tid 514707] [client 103.59.206.240:31500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cxfzqsQqnLoCgUjiHFQAAAWc"]
[Tue Jul 21 08:49:25.476363 2026] [security2:error] [pid 514479:tid 514617] [client 212.32.76.54:21255] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/widgets/shadow-bot.php"] [unique_id "al9cxfzqsQqnLoCgUjiHGQAAAQ0"]
[Tue Jul 21 08:49:25.567285 2026] [security2:error] [pid 511108:tid 511319] [client 65.21.113.253:35822] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cxYTd5soprXwxAH0grQAAAFE"]
[Tue Jul 21 08:49:25.628606 2026] [security2:error] [pid 511108:tid 511254] [client 195.49.128.211:57240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cxYTd5soprXwxAH0guQAAABA"]
[Tue Jul 21 08:49:25.628722 2026] [security2:error] [pid 511108:tid 511254] [client 195.49.128.211:57240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9cxYTd5soprXwxAH0guQAAABA"]
[Tue Jul 21 08:49:25.652714 2026] [security2:error] [pid 514479:tid 514636] [client 20.104.96.117:44936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/dex.php"] [unique_id "al9cxfzqsQqnLoCgUjiHGwAAASA"]
[Tue Jul 21 08:49:25.720252 2026] [security2:error] [pid 511108:tid 511362] [client 20.104.96.117:46756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/24.php"] [unique_id "al9cxYTd5soprXwxAH0gvAAAAHw"]
[Tue Jul 21 08:49:25.860112 2026] [security2:error] [pid 514479:tid 514669] [client 20.151.10.161:62428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/classwithtostring.php"] [unique_id "al9cxfzqsQqnLoCgUjiHHAAAAUE"]
[Tue Jul 21 08:49:26.033836 2026] [security2:error] [pid 514479:tid 514654] [client 203.25.124.43:48617] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "al9cxvzqsQqnLoCgUjiHHgAAATI"]
[Tue Jul 21 08:49:26.068765 2026] [security2:error] [pid 511108:tid 511304] [client 212.32.76.11:38813] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "al9cxoTd5soprXwxAH0gxQAAAEI"]
[Tue Jul 21 08:49:26.310404 2026] [security2:error] [pid 514479:tid 514715] [client 20.226.60.151:59604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/mds.php"] [unique_id "al9cxvzqsQqnLoCgUjiHIAAAAW8"]
[Tue Jul 21 08:49:26.347314 2026] [security2:error] [pid 511108:tid 511339] [client 20.104.96.117:44222] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "gadelhadealmeida.com.br"] [uri "/1.php"] [unique_id "al9cxoTd5soprXwxAH0gxwAAAGU"]
[Tue Jul 21 08:49:26.347462 2026] [security2:error] [pid 511108:tid 511339] [client 20.104.96.117:44222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/1.php"] [unique_id "al9cxoTd5soprXwxAH0gxwAAAGU"]
[Tue Jul 21 08:49:26.352481 2026] [security2:error] [pid 514479:tid 514498] [remote 154.61.75.100:33664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9cxvzqsQqnLoCgUjiHIQABWQ4"]
[Tue Jul 21 08:49:26.475225 2026] [security2:error] [pid 511108:tid 511320] [client 203.25.124.185:22813] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/login.php"] [unique_id "al9cxoTd5soprXwxAH0gzgAAAFI"]
[Tue Jul 21 08:49:26.483158 2026] [security2:error] [pid 514479:tid 514681] [client 41.89.234.2:54673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cxvzqsQqnLoCgUjiHJQAAAU0"]
[Tue Jul 21 08:49:26.483240 2026] [security2:error] [pid 514479:tid 514681] [client 41.89.234.2:54673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cxvzqsQqnLoCgUjiHJQAAAU0"]
[Tue Jul 21 08:49:27.059903 2026] [security2:error] [pid 514479:tid 514617] [client 20.197.192.193:21888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/track.php"] [unique_id "al9cx_zqsQqnLoCgUjiHLQAAAQ0"]
[Tue Jul 21 08:49:27.141139 2026] [security2:error] [pid 511108:tid 511357] [client 20.104.96.117:44149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/ms.php"] [unique_id "al9cx4Td5soprXwxAH0g2QAAAHc"]
[Tue Jul 21 08:49:27.240072 2026] [security2:error] [pid 511108:tid 511331] [client 203.25.124.53:62981] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/news-portal/admins-dir.php"] [unique_id "al9cx4Td5soprXwxAH0g2gAAAF0"]
[Tue Jul 21 08:49:27.385188 2026] [security2:error] [pid 511108:tid 511183] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cx4Td5soprXwxAH0g3QAAFko"]
[Tue Jul 21 08:49:27.385327 2026] [security2:error] [pid 511108:tid 511260] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9cx4Td5soprXwxAH0g3QAAFko"]
[Tue Jul 21 08:49:27.386418 2026] [security2:error] [pid 511108:tid 511252] [client 203.25.124.252:39563] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/well-known/index.php"] [unique_id "al9cx4Td5soprXwxAH0g3gAAAA4"]
[Tue Jul 21 08:49:27.516839 2026] [security2:error] [pid 514479:tid 514633] [client 20.104.96.117:46766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/xacs.php"] [unique_id "al9cx_zqsQqnLoCgUjiHNAAAAR0"]
[Tue Jul 21 08:49:27.576698 2026] [security2:error] [pid 514479:tid 514729] [client 20.151.10.161:62447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9cx_zqsQqnLoCgUjiHNQAAAX0"]
[Tue Jul 21 08:49:27.712507 2026] [autoindex:error] [pid 511108:tid 511326] [client 20.104.96.117:44287] AH01276: Cannot serve directory /home3/gadelh32/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:49:27.769671 2026] [security2:error] [pid 514479:tid 514645] [client 113.22.144.139:52109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cx_zqsQqnLoCgUjiHNgAAASk"]
[Tue Jul 21 08:49:27.769767 2026] [security2:error] [pid 514479:tid 514645] [client 113.22.144.139:52109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cx_zqsQqnLoCgUjiHNgAAASk"]
[Tue Jul 21 08:49:27.800088 2026] [security2:error] [pid 514479:tid 514572] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cx_zqsQqnLoCgUjiHNwABEVc"]
[Tue Jul 21 08:49:27.800307 2026] [security2:error] [pid 514479:tid 514621] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cx_zqsQqnLoCgUjiHNwABEVc"]
[Tue Jul 21 08:49:27.965231 2026] [security2:error] [pid 514479:tid 514706] [client 212.32.76.4:35371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/as.php"] [unique_id "al9cx_zqsQqnLoCgUjiHOQAAAWY"]
[Tue Jul 21 08:49:27.985888 2026] [security2:error] [pid 511108:tid 511304] [client 20.104.96.117:44287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/memberfuns.php"] [unique_id "al9cx4Td5soprXwxAH0g7wAAAEI"]
[Tue Jul 21 08:49:28.228223 2026] [security2:error] [pid 514479:tid 514689] [client 20.197.192.193:38234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/2352356666.php"] [unique_id "al9cyPzqsQqnLoCgUjiHPwAAAVU"]
[Tue Jul 21 08:49:28.341513 2026] [security2:error] [pid 511108:tid 511263] [client 203.25.124.32:36747] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/js/chosen.php"] [unique_id "al9cyITd5soprXwxAH0g9AAAABk"]
[Tue Jul 21 08:49:28.369315 2026] [security2:error] [pid 514479:tid 514653] [client 212.32.76.62:35499] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/backup.php"] [unique_id "al9cyPzqsQqnLoCgUjiHQQAAATE"]
[Tue Jul 21 08:49:28.513469 2026] [security2:error] [pid 514479:tid 514707] [client 20.104.96.117:3988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/zildan.php"] [unique_id "al9cyPzqsQqnLoCgUjiHRgAAAWc"]
[Tue Jul 21 08:49:28.644647 2026] [security2:error] [pid 514479:tid 514617] [client 20.104.96.117:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/0.php"] [unique_id "al9cyPzqsQqnLoCgUjiHRwAAAQ0"]
[Tue Jul 21 08:49:28.741874 2026] [security2:error] [pid 514479:tid 514734] [client 20.226.60.151:57581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-blink.php"] [unique_id "al9cyPzqsQqnLoCgUjiHSAAAAYI"]
[Tue Jul 21 08:49:29.006499 2026] [security2:error] [pid 514479:tid 514703] [client 20.104.96.117:44134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/BDKR28.php"] [unique_id "al9cyfzqsQqnLoCgUjiHSwAAAWM"]
[Tue Jul 21 08:49:29.049142 2026] [security2:error] [pid 511108:tid 511255] [client 203.25.124.72:50577] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/classwithtostring.php"] [unique_id "al9cyYTd5soprXwxAH0g_QAAABE"]
[Tue Jul 21 08:49:29.065513 2026] [security2:error] [pid 514479:tid 514515] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cyfzqsQqnLoCgUjiHTwABfx8"]
[Tue Jul 21 08:49:29.065734 2026] [security2:error] [pid 514479:tid 514731] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cyfzqsQqnLoCgUjiHTwABfx8"]
[Tue Jul 21 08:49:29.135668 2026] [security2:error] [pid 514479:tid 514621] [client 65.21.113.253:42650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9cyfzqsQqnLoCgUjiHUQAAARE"]
[Tue Jul 21 08:49:29.142007 2026] [security2:error] [pid 514479:tid 514525] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cyfzqsQqnLoCgUjiHUgABdik"]
[Tue Jul 21 08:49:29.142138 2026] [security2:error] [pid 514479:tid 514722] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9cyfzqsQqnLoCgUjiHUgABdik"]
[Tue Jul 21 08:49:29.366457 2026] [security2:error] [pid 511108:tid 511241] [client 20.104.96.117:44250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/green1.php"] [unique_id "al9cyYTd5soprXwxAH0hAwAAAAM"]
[Tue Jul 21 08:49:29.574462 2026] [security2:error] [pid 511108:tid 511333] [client 20.151.10.161:8385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-blog.php"] [unique_id "al9cyYTd5soprXwxAH0hCgAAAF8"]
[Tue Jul 21 08:49:29.592781 2026] [security2:error] [pid 514479:tid 514672] [client 182.189.99.211:47780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cyfzqsQqnLoCgUjiHWAAAAUQ"]
[Tue Jul 21 08:49:29.592865 2026] [security2:error] [pid 514479:tid 514672] [client 182.189.99.211:47780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9cyfzqsQqnLoCgUjiHWAAAAUQ"]
[Tue Jul 21 08:49:29.612202 2026] [security2:error] [pid 514479:tid 514726] [client 20.104.96.117:46745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/csa.php"] [unique_id "al9cyfzqsQqnLoCgUjiHWgAAAXo"]
[Tue Jul 21 08:49:29.863749 2026] [security2:error] [pid 511108:tid 511365] [client 203.25.124.53:20777] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwentyfive/patterns/template-singl-portfolio.php"] [unique_id "al9cyYTd5soprXwxAH0hDQAAAH8"]
[Tue Jul 21 08:49:29.867654 2026] [security2:error] [pid 514479:tid 514652] [client 20.104.96.117:44183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/nc4.php"] [unique_id "al9cyfzqsQqnLoCgUjiHXwAAATA"]
[Tue Jul 21 08:49:29.893087 2026] [security2:error] [pid 514479:tid 514639] [client 168.167.81.163:62379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cyfzqsQqnLoCgUjiHYAAAASM"]
[Tue Jul 21 08:49:29.893182 2026] [security2:error] [pid 514479:tid 514639] [client 168.167.81.163:62379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9cyfzqsQqnLoCgUjiHYAAAASM"]
[Tue Jul 21 08:49:30.049507 2026] [security2:error] [pid 511108:tid 511329] [client 20.226.60.151:57617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/zc-208.php"] [unique_id "al9cyoTd5soprXwxAH0hFAAAAFs"]
[Tue Jul 21 08:49:30.127356 2026] [security2:error] [pid 511108:tid 511297] [client 45.121.0.214:51517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.0.121.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atom-growth.com"] [uri "/xmlrpc.php"] [unique_id "al9cyoTd5soprXwxAH0hGAAAADs"]
[Tue Jul 21 08:49:30.127469 2026] [security2:error] [pid 511108:tid 511297] [client 45.121.0.214:51517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "atom-growth.com"] [uri "/xmlrpc.php"] [unique_id "al9cyoTd5soprXwxAH0hGAAAADs"]
[Tue Jul 21 08:49:30.210540 2026] [security2:error] [pid 514479:tid 514693] [client 65.21.113.253:56528] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9cyfzqsQqnLoCgUjiHXQAAAVk"]
[Tue Jul 21 08:49:30.251590 2026] [security2:error] [pid 511108:tid 511302] [client 212.32.76.8:62821] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwentytwo/templates/"] [unique_id "al9cyoTd5soprXwxAH0hHAAAAEA"]
[Tue Jul 21 08:49:30.273127 2026] [security2:error] [pid 514479:tid 514633] [client 203.25.124.254:28133] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/user/freedoms-old.php"] [unique_id "al9cyvzqsQqnLoCgUjiHZgAAAR0"]
[Tue Jul 21 08:49:30.341249 2026] [security2:error] [pid 514479:tid 514645] [client 20.104.96.117:59709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/sym403.php"] [unique_id "al9cyvzqsQqnLoCgUjiHaAAAASk"]
[Tue Jul 21 08:49:30.488678 2026] [security2:error] [pid 514479:tid 514715] [client 20.104.96.117:44159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/a1.php"] [unique_id "al9cyvzqsQqnLoCgUjiHaQAAAW8"]
[Tue Jul 21 08:49:30.618688 2026] [security2:error] [pid 511108:tid 511166] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cyoTd5soprXwxAH0hJgAAYTk"]
[Tue Jul 21 08:49:30.618846 2026] [security2:error] [pid 511108:tid 511335] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9cyoTd5soprXwxAH0hJgAAYTk"]
[Tue Jul 21 08:49:30.727967 2026] [security2:error] [pid 514479:tid 514619] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9cyvzqsQqnLoCgUjiHbwABD2k"]
[Tue Jul 21 08:49:30.748307 2026] [security2:error] [pid 511108:tid 511282] [client 195.206.105.227:52718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9cyoTd5soprXwxAH0hKgAAACw"]
[Tue Jul 21 08:49:30.748390 2026] [security2:error] [pid 511108:tid 511282] [client 195.206.105.227:52718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9cyoTd5soprXwxAH0hKgAAACw"]
[Tue Jul 21 08:49:30.880831 2026] [security2:error] [pid 511108:tid 511345] [client 20.104.96.117:44911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/eee.php"] [unique_id "al9cyoTd5soprXwxAH0hLAAAAGs"]
[Tue Jul 21 08:49:30.981978 2026] [security2:error] [pid 511108:tid 511309] [client 20.197.192.193:22371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/pn.php"] [unique_id "al9cyoTd5soprXwxAH0hLQAAAEc"]
[Tue Jul 21 08:49:31.059794 2026] [security2:error] [pid 511108:tid 511344] [client 5.31.193.106:30404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cy4Td5soprXwxAH0hLgAAAGo"]
[Tue Jul 21 08:49:31.059912 2026] [security2:error] [pid 511108:tid 511344] [client 5.31.193.106:30404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9cy4Td5soprXwxAH0hLgAAAGo"]
[Tue Jul 21 08:49:31.145413 2026] [security2:error] [pid 514479:tid 514675] [client 20.104.96.117:46750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/w3llscc.php"] [unique_id "al9cy_zqsQqnLoCgUjiHdQAAAUc"]
[Tue Jul 21 08:49:31.163872 2026] [security2:error] [pid 514479:tid 514728] [client 203.25.124.74:55763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wso.php"] [unique_id "al9cy_zqsQqnLoCgUjiHdwAAAXw"]
[Tue Jul 21 08:49:31.190072 2026] [security2:error] [pid 511108:tid 511331] [client 212.32.76.55:39111] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/post-author-name-path.php"] [unique_id "al9cy4Td5soprXwxAH0hNAAAAF0"]
[Tue Jul 21 08:49:31.254445 2026] [security2:error] [pid 514479:tid 514638] [client 20.104.96.117:44153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/wp-aothait.php"] [unique_id "al9cy_zqsQqnLoCgUjiHeAAAASI"]
[Tue Jul 21 08:49:31.553149 2026] [security2:error] [pid 514479:tid 514639] [client 20.104.96.117:44277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/config.json.php"] [unique_id "al9cy_zqsQqnLoCgUjiHfAAAASM"]
[Tue Jul 21 08:49:31.626898 2026] [security2:error] [pid 514479:tid 514614] [client 20.226.60.151:57663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/sid4.php"] [unique_id "al9cy_zqsQqnLoCgUjiHfQAAAQo"]
[Tue Jul 21 08:49:31.641041 2026] [security2:error] [pid 514479:tid 514678] [client 203.25.124.68:37591] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Requests/src/Utility/"] [unique_id "al9cy_zqsQqnLoCgUjiHfgAAAUo"]
[Tue Jul 21 08:49:31.888954 2026] [security2:error] [pid 514479:tid 514521] [remote 103.82.22.235:48316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bellascleaningsolutionsllc.com"] [uri "/wp-login.php"] [unique_id "al9cy_zqsQqnLoCgUjiHgQABeiU"]
[Tue Jul 21 08:49:31.961961 2026] [security2:error] [pid 511108:tid 511274] [client 20.104.96.117:44216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9cy4Td5soprXwxAH0hRwAAACQ"]
[Tue Jul 21 08:49:32.013507 2026] [security2:error] [pid 514479:tid 514630] [client 20.220.225.223:43194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/pn.php"] [unique_id "al9czPzqsQqnLoCgUjiHhAAAARo"]
[Tue Jul 21 08:49:32.162364 2026] [security2:error] [pid 511108:tid 511280] [client 212.32.76.4:22177] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-info.php"] [unique_id "al9czITd5soprXwxAH0hTAAAACo"]
[Tue Jul 21 08:49:32.191038 2026] [security2:error] [pid 514479:tid 514617] [client 49.144.66.253:30273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9czPzqsQqnLoCgUjiHhwAAAQ0"]
[Tue Jul 21 08:49:32.191139 2026] [security2:error] [pid 514479:tid 514617] [client 49.144.66.253:30273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9czPzqsQqnLoCgUjiHhwAAAQ0"]
[Tue Jul 21 08:49:32.368414 2026] [security2:error] [pid 514479:tid 514645] [client 20.104.96.117:44896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/k2.php"] [unique_id "al9czPzqsQqnLoCgUjiHigAAASk"]
[Tue Jul 21 08:49:32.462104 2026] [security2:error] [pid 514479:tid 514737] [client 20.151.10.161:8389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9czPzqsQqnLoCgUjiHkAAAAYU"]
[Tue Jul 21 08:49:32.744146 2026] [security2:error] [pid 511108:tid 511344] [client 20.104.96.117:44181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9czITd5soprXwxAH0hWwAAAGo"]
[Tue Jul 21 08:49:32.769985 2026] [security2:error] [pid 514479:tid 514651] [client 20.104.96.117:4084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wpx.php"] [unique_id "al9czPzqsQqnLoCgUjiHmAAAAS8"]
[Tue Jul 21 08:49:32.989104 2026] [security2:error] [pid 514479:tid 514711] [client 198.44.157.34:37814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9czPzqsQqnLoCgUjiHmwAAAWs"]
[Tue Jul 21 08:49:32.989209 2026] [security2:error] [pid 514479:tid 514711] [client 198.44.157.34:37814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9czPzqsQqnLoCgUjiHmwAAAWs"]
[Tue Jul 21 08:49:33.029649 2026] [security2:error] [pid 511108:tid 511245] [client 203.25.124.55:50367] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/sodium_compat/src/Core/"] [unique_id "al9czYTd5soprXwxAH0hbwAAAAc"]
[Tue Jul 21 08:49:33.132673 2026] [security2:error] [pid 511108:tid 511359] [client 114.198.138.124:64900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9czYTd5soprXwxAH0hcgAAAHk"]
[Tue Jul 21 08:49:33.132763 2026] [security2:error] [pid 511108:tid 511359] [client 114.198.138.124:64900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9czYTd5soprXwxAH0hcgAAAHk"]
[Tue Jul 21 08:49:33.148781 2026] [security2:error] [pid 514479:tid 514707] [client 20.104.96.117:44157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9czfzqsQqnLoCgUjiHnQAAAWc"]
[Tue Jul 21 08:49:33.245149 2026] [security2:error] [pid 514479:tid 514618] [client 198.44.157.34:45118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9czfzqsQqnLoCgUjiHoQAAAQ4"]
[Tue Jul 21 08:49:33.245225 2026] [security2:error] [pid 514479:tid 514618] [client 198.44.157.34:45118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9czfzqsQqnLoCgUjiHoQAAAQ4"]
[Tue Jul 21 08:49:33.473805 2026] [security2:error] [pid 511108:tid 511279] [client 203.25.124.7:55131] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/class-wp-error-character.php"] [unique_id "al9czYTd5soprXwxAH0hkAAAACk"]
[Tue Jul 21 08:49:33.763479 2026] [security2:error] [pid 514479:tid 514699] [client 203.25.124.47:61825] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/s.php"] [unique_id "al9czfzqsQqnLoCgUjiHtwAAAV8"]
[Tue Jul 21 08:49:33.832063 2026] [security2:error] [pid 514479:tid 514675] [client 198.44.157.34:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9czfzqsQqnLoCgUjiHugAAAUc"]
[Tue Jul 21 08:49:33.832194 2026] [security2:error] [pid 514479:tid 514675] [client 198.44.157.34:37826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9czfzqsQqnLoCgUjiHugAAAUc"]
[Tue Jul 21 08:49:33.854410 2026] [security2:error] [pid 511108:tid 511260] [client 59.95.197.55:52089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9czYTd5soprXwxAH0hnQAAABY"]
[Tue Jul 21 08:49:33.855197 2026] [security2:error] [pid 511108:tid 511260] [client 59.95.197.55:52089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9czYTd5soprXwxAH0hnQAAABY"]
[Tue Jul 21 08:49:34.053409 2026] [security2:error] [pid 514479:tid 514667] [client 65.21.113.253:42650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9czvzqsQqnLoCgUjiHvQAAAT8"]
[Tue Jul 21 08:49:34.085844 2026] [security2:error] [pid 514479:tid 514615] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "produto-express.com"] [uri "/index.php"] [unique_id "al9czvzqsQqnLoCgUjiHvAABCyo"]
[Tue Jul 21 08:49:34.092802 2026] [security2:error] [pid 514479:tid 514718] [client 20.104.96.117:44145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9czvzqsQqnLoCgUjiHvgAAAXI"]
[Tue Jul 21 08:49:34.125862 2026] [security2:error] [pid 511108:tid 511292] [client 20.104.96.117:4046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-css.php"] [unique_id "al9czoTd5soprXwxAH0hoQAAADY"]
[Tue Jul 21 08:49:34.183330 2026] [security2:error] [pid 511108:tid 511285] [client 20.226.60.151:57607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wmore1.php"] [unique_id "al9czoTd5soprXwxAH0howAAAC8"]
[Tue Jul 21 08:49:34.192129 2026] [security2:error] [pid 511108:tid 511249] [client 122.176.100.127:53528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9czoTd5soprXwxAH0hpAAAAAs"]
[Tue Jul 21 08:49:34.192266 2026] [security2:error] [pid 511108:tid 511249] [client 122.176.100.127:53528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9czoTd5soprXwxAH0hpAAAAAs"]
[Tue Jul 21 08:49:34.270157 2026] [security2:error] [pid 514479:tid 514619] [client 88.99.80.227:13178] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9czvzqsQqnLoCgUjiHyAAAAQ8"], referer: https://artetoner.com.br
[Tue Jul 21 08:49:34.475485 2026] [security2:error] [pid 514479:tid 514678] [client 203.25.124.254:46477] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-cron-element.php"] [unique_id "al9czvzqsQqnLoCgUjiHzQAAAUo"]
[Tue Jul 21 08:49:34.485197 2026] [security2:error] [pid 514479:tid 514739] [client 20.104.96.117:61137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/v543.php"] [unique_id "al9czvzqsQqnLoCgUjiHzgAAAYc"]
[Tue Jul 21 08:49:34.569008 2026] [security2:error] [pid 514479:tid 514725] [client 203.25.124.73:20667] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/69.php"] [unique_id "al9czvzqsQqnLoCgUjiHzwAAAXk"]
[Tue Jul 21 08:49:34.626251 2026] [security2:error] [pid 514479:tid 514693] [client 20.104.96.117:44886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/for.php"] [unique_id "al9czvzqsQqnLoCgUjiH1AAAAVk"]
[Tue Jul 21 08:49:34.668615 2026] [security2:error] [pid 514479:tid 514646] [client 20.104.96.117:3976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/ho.php"] [unique_id "al9czvzqsQqnLoCgUjiH1gAAASo"]
[Tue Jul 21 08:49:34.690647 2026] [security2:error] [pid 514479:tid 514711] [client 5.38.115.39:51130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9czvzqsQqnLoCgUjiH1wAAAWs"]
[Tue Jul 21 08:49:34.690728 2026] [security2:error] [pid 514479:tid 514711] [client 5.38.115.39:51130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9czvzqsQqnLoCgUjiH1wAAAWs"]
[Tue Jul 21 08:49:34.793702 2026] [security2:error] [pid 514479:tid 514741] [client 20.226.60.151:57587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/solo1.php"] [unique_id "al9czvzqsQqnLoCgUjiH2gAAAYk"]
[Tue Jul 21 08:49:35.125966 2026] [security2:error] [pid 514479:tid 514641] [client 65.21.113.253:56530] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9czvzqsQqnLoCgUjiH2AAAASU"]
[Tue Jul 21 08:49:35.153436 2026] [security2:error] [pid 514479:tid 514653] [client 20.151.10.161:62381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/adminfuns.php"] [unique_id "al9cz_zqsQqnLoCgUjiH4AAAATE"]
[Tue Jul 21 08:49:35.354145 2026] [security2:error] [pid 514479:tid 514726] [client 20.104.96.117:44874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gadelhadealmeida.com.br"] [uri "/raw.php"] [unique_id "al9cz_zqsQqnLoCgUjiH5AAAAXo"]
[Tue Jul 21 08:49:35.487657 2026] [security2:error] [pid 511108:tid 511302] [client 20.220.225.223:35118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9cz4Td5soprXwxAH0hvAAAAEA"]
[Tue Jul 21 08:49:35.750699 2026] [security2:error] [pid 514479:tid 514678] [client 20.104.96.117:4053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/xy.php"] [unique_id "al9cz_zqsQqnLoCgUjiH6gAAAUo"]
[Tue Jul 21 08:49:35.750984 2026] [security2:error] [pid 511108:tid 511321] [client 20.226.60.151:57631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/cong.php"] [unique_id "al9cz4Td5soprXwxAH0hvwAAAFM"]
[Tue Jul 21 08:49:35.833032 2026] [security2:error] [pid 511108:tid 511264] [client 212.32.76.13:22929] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/lock360.php"] [unique_id "al9cz4Td5soprXwxAH0hwAAAABo"]
[Tue Jul 21 08:49:35.856960 2026] [security2:error] [pid 514479:tid 514635] [client 212.32.76.7:22265] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-crom.php"] [unique_id "al9cz_zqsQqnLoCgUjiH6wAAAR8"]
[Tue Jul 21 08:49:36.054626 2026] [security2:error] [pid 511108:tid 511295] [client 103.59.206.240:31227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c0ITd5soprXwxAH0hyAAAADk"]
[Tue Jul 21 08:49:36.054777 2026] [security2:error] [pid 511108:tid 511295] [client 103.59.206.240:31227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c0ITd5soprXwxAH0hyAAAADk"]
[Tue Jul 21 08:49:36.070351 2026] [security2:error] [pid 514479:tid 514722] [client 20.104.96.117:59680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/sixxis.php"] [unique_id "al9c0PzqsQqnLoCgUjiH7wAAAXY"]
[Tue Jul 21 08:49:36.178158 2026] [security2:error] [pid 514479:tid 514732] [client 195.49.128.211:57847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9c0PzqsQqnLoCgUjiH8AAAAYA"]
[Tue Jul 21 08:49:36.178288 2026] [security2:error] [pid 514479:tid 514732] [client 195.49.128.211:57847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9c0PzqsQqnLoCgUjiH8AAAAYA"]
[Tue Jul 21 08:49:36.457198 2026] [security2:error] [pid 514479:tid 514733] [client 20.104.96.117:46740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/loader.php"] [unique_id "al9c0PzqsQqnLoCgUjiH-gAAAYE"]
[Tue Jul 21 08:49:36.888477 2026] [security2:error] [pid 514479:tid 514707] [client 20.151.10.161:62423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/goods.php"] [unique_id "al9c0PzqsQqnLoCgUjiIFQAAAWc"]
[Tue Jul 21 08:49:36.894502 2026] [security2:error] [pid 514479:tid 514688] [client 20.226.60.151:57585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/public/css.php"] [unique_id "al9c0PzqsQqnLoCgUjiIGAAAAVQ"]
[Tue Jul 21 08:49:36.985222 2026] [security2:error] [pid 511108:tid 511285] [client 41.89.234.2:55137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c0ITd5soprXwxAH0h2gAAAC8"]
[Tue Jul 21 08:49:36.985330 2026] [security2:error] [pid 511108:tid 511285] [client 41.89.234.2:55137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c0ITd5soprXwxAH0h2gAAAC8"]
[Tue Jul 21 08:49:37.060877 2026] [security2:error] [pid 511108:tid 511365] [client 212.32.76.9:50403] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9c0YTd5soprXwxAH0h3AAAAH8"]
[Tue Jul 21 08:49:37.105099 2026] [security2:error] [pid 511108:tid 511337] [client 20.104.96.117:61130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ip.php"] [unique_id "al9c0YTd5soprXwxAH0h3wAAAGM"]
[Tue Jul 21 08:49:37.133345 2026] [security2:error] [pid 511108:tid 511334] [client 203.25.124.73:32191] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/fonts/wp-conflg.php"] [unique_id "al9c0YTd5soprXwxAH0h4AAAAGA"]
[Tue Jul 21 08:49:37.222462 2026] [security2:error] [pid 514479:tid 514573] [remote 45.117.83.212:33054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "frsadvocacia.net"] [uri "/xmlrpc.php"] [unique_id "al9c0fzqsQqnLoCgUjiIKAABeFg"]
[Tue Jul 21 08:49:37.222599 2026] [security2:error] [pid 514479:tid 514724] [client 45.117.83.212:33054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "frsadvocacia.net"] [uri "/xmlrpc.php"] [unique_id "al9c0fzqsQqnLoCgUjiIKAABeFg"]
[Tue Jul 21 08:49:37.425043 2026] [autoindex:error] [pid 514479:tid 514699] [client 43.130.102.223:53030] AH01276: Cannot serve directory /home2/ric83751/sanovitta.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:49:37.573400 2026] [security2:error] [pid 514479:tid 514707] [client 20.104.96.117:46761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/spadex.php"] [unique_id "al9c0fzqsQqnLoCgUjiINQAAAWc"]
[Tue Jul 21 08:49:37.840456 2026] [security2:error] [pid 514479:tid 514738] [client 103.178.142.91:62467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.142.178.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joeidiomas.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c0fzqsQqnLoCgUjiIOQAAAYY"]
[Tue Jul 21 08:49:37.840574 2026] [security2:error] [pid 514479:tid 514738] [client 103.178.142.91:62467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joeidiomas.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c0fzqsQqnLoCgUjiIOQAAAYY"]
[Tue Jul 21 08:49:37.929273 2026] [security2:error] [pid 514479:tid 514645] [client 20.197.192.193:8355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/wp-mt.php"] [unique_id "al9c0fzqsQqnLoCgUjiIQgAAASk"]
[Tue Jul 21 08:49:38.022663 2026] [security2:error] [pid 511108:tid 511139] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9c0oTd5soprXwxAH0h8AAAex4"]
[Tue Jul 21 08:49:38.022803 2026] [security2:error] [pid 511108:tid 511361] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9c0oTd5soprXwxAH0h8AAAex4"]
[Tue Jul 21 08:49:38.152289 2026] [security2:error] [pid 514479:tid 514705] [client 198.44.157.34:45134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9c0vzqsQqnLoCgUjiIUAAAAWU"]
[Tue Jul 21 08:49:38.152399 2026] [security2:error] [pid 514479:tid 514705] [client 198.44.157.34:45134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9c0vzqsQqnLoCgUjiIUAAAAWU"]
[Tue Jul 21 08:49:38.168694 2026] [security2:error] [pid 511108:tid 511328] [client 203.25.124.12:41253] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/sitemaps/chosen.php"] [unique_id "al9c0oTd5soprXwxAH0h8wAAAFo"]
[Tue Jul 21 08:49:38.189750 2026] [security2:error] [pid 514479:tid 514641] [client 20.104.96.117:3969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/2x.php"] [unique_id "al9c0vzqsQqnLoCgUjiIUgAAASU"]
[Tue Jul 21 08:49:38.476956 2026] [security2:error] [pid 511108:tid 511285] [client 20.197.192.193:38231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9c0oTd5soprXwxAH0h-AAAAC8"]
[Tue Jul 21 08:49:38.489981 2026] [security2:error] [pid 514479:tid 514635] [client 65.21.113.253:42650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9c0vzqsQqnLoCgUjiIWQAAAR8"]
[Tue Jul 21 08:49:38.524202 2026] [security2:error] [pid 511108:tid 511241] [client 20.151.10.161:62375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/ms-edit.php"] [unique_id "al9c0oTd5soprXwxAH0h-QAAAAM"]
[Tue Jul 21 08:49:38.560457 2026] [security2:error] [pid 511108:tid 511337] [client 203.25.124.65:39515] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/click.php"] [unique_id "al9c0oTd5soprXwxAH0h-gAAAGM"]
[Tue Jul 21 08:49:38.599619 2026] [security2:error] [pid 511108:tid 511297] [client 113.22.144.139:52624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c0oTd5soprXwxAH0h_AAAADs"]
[Tue Jul 21 08:49:38.599771 2026] [security2:error] [pid 511108:tid 511297] [client 113.22.144.139:52624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c0oTd5soprXwxAH0h_AAAADs"]
[Tue Jul 21 08:49:38.705247 2026] [security2:error] [pid 514479:tid 514705] [client 20.104.96.117:59173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/kq1.php"] [unique_id "al9c0vzqsQqnLoCgUjiIYwAAAWU"]
[Tue Jul 21 08:49:38.765513 2026] [security2:error] [pid 514479:tid 514510] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c0vzqsQqnLoCgUjiIZAABgRo"]
[Tue Jul 21 08:49:38.765734 2026] [security2:error] [pid 514479:tid 514733] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c0vzqsQqnLoCgUjiIZAABgRo"]
[Tue Jul 21 08:49:38.832551 2026] [security2:error] [pid 514479:tid 514622] [client 20.197.192.193:22370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/dr.php"] [unique_id "al9c0vzqsQqnLoCgUjiIagAAARI"]
[Tue Jul 21 08:49:38.956855 2026] [security2:error] [pid 511108:tid 511314] [client 20.226.60.151:59717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/output.php"] [unique_id "al9c0oTd5soprXwxAH0iAAAAAEw"]
[Tue Jul 21 08:49:38.972009 2026] [proxy:error] [pid 514479:tid 514726] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:38.972082 2026] [proxy_http:error] [pid 514479:tid 514726] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:38.972769 2026] [proxy:error] [pid 514479:tid 514726] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:38.972823 2026] [proxy_http:error] [pid 514479:tid 514726] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:39.106110 2026] [security2:error] [pid 514479:tid 514683] [client 20.104.96.117:46734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/ctex1.php"] [unique_id "al9c0_zqsQqnLoCgUjiIcQAAAU8"]
[Tue Jul 21 08:49:39.181105 2026] [security2:error] [pid 514479:tid 514679] [client 203.25.124.188:52973] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/antiperfo.php"] [unique_id "al9c0_zqsQqnLoCgUjiIdgAAAUs"]
[Tue Jul 21 08:49:39.261332 2026] [security2:error] [pid 511108:tid 511345] [client 203.25.124.64:56763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/byp.php"] [unique_id "al9c04Td5soprXwxAH0iCQAAAGs"]
[Tue Jul 21 08:49:39.304929 2026] [security2:error] [pid 514479:tid 514675] [client 20.220.225.223:46361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/dr.php"] [unique_id "al9c0_zqsQqnLoCgUjiIeAAAAUc"]
[Tue Jul 21 08:49:39.446561 2026] [security2:error] [pid 514479:tid 514549] [remote 8.217.108.67:27086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9c0_zqsQqnLoCgUjiIeQABZ0A"]
[Tue Jul 21 08:49:39.513667 2026] [security2:error] [pid 511108:tid 511320] [client 198.44.157.34:54972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9c04Td5soprXwxAH0iDwAAAFI"]
[Tue Jul 21 08:49:39.513760 2026] [security2:error] [pid 511108:tid 511320] [client 198.44.157.34:54972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9c04Td5soprXwxAH0iDwAAAFI"]
[Tue Jul 21 08:49:39.527852 2026] [proxy:error] [pid 514479:tid 514674] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:39.527931 2026] [proxy_http:error] [pid 514479:tid 514674] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:39.528512 2026] [proxy:error] [pid 514479:tid 514674] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:39.528542 2026] [proxy_http:error] [pid 514479:tid 514674] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:39.587111 2026] [security2:error] [pid 511108:tid 511224] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9c04Td5soprXwxAH0iEAAAaHM"]
[Tue Jul 21 08:49:39.587299 2026] [security2:error] [pid 511108:tid 511342] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9c04Td5soprXwxAH0iEAAAaHM"]
[Tue Jul 21 08:49:39.617304 2026] [security2:error] [pid 514479:tid 514734] [client 65.21.113.253:56532] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9c0_zqsQqnLoCgUjiIdQAAAYI"]
[Tue Jul 21 08:49:39.746428 2026] [security2:error] [pid 511108:tid 511359] [client 198.44.157.34:54968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9c04Td5soprXwxAH0iFAAAAHk"]
[Tue Jul 21 08:49:39.746535 2026] [security2:error] [pid 511108:tid 511359] [client 198.44.157.34:54968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9c04Td5soprXwxAH0iFAAAAHk"]
[Tue Jul 21 08:49:39.836720 2026] [security2:error] [pid 511108:tid 511358] [client 212.32.76.9:49687] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwentythree/patterns/"] [unique_id "al9c04Td5soprXwxAH0iFQAAAHg"]
[Tue Jul 21 08:49:39.999593 2026] [security2:error] [pid 511108:tid 511343] [client 203.25.124.74:45369] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/ateprivacy-policy-guide.php"] [unique_id "al9c04Td5soprXwxAH0iFgAAAGk"]
[Tue Jul 21 08:49:40.024584 2026] [proxy:error] [pid 514479:tid 514729] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:40.024656 2026] [proxy_http:error] [pid 514479:tid 514729] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:40.025112 2026] [proxy:error] [pid 514479:tid 514729] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:40.025139 2026] [proxy_http:error] [pid 514479:tid 514729] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:40.126273 2026] [security2:error] [pid 511108:tid 511221] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c1ITd5soprXwxAH0iGgAAMXA"]
[Tue Jul 21 08:49:40.126463 2026] [security2:error] [pid 511108:tid 511287] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c1ITd5soprXwxAH0iGgAAMXA"]
[Tue Jul 21 08:49:40.129959 2026] [security2:error] [pid 514479:tid 514633] [client 20.104.96.117:61167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/fw/faiyy.php"] [unique_id "al9c1PzqsQqnLoCgUjiIgwAAAR0"]
[Tue Jul 21 08:49:40.208463 2026] [security2:error] [pid 511108:tid 511329] [client 182.189.99.211:48299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c1ITd5soprXwxAH0iHgAAAFs"]
[Tue Jul 21 08:49:40.208577 2026] [security2:error] [pid 511108:tid 511329] [client 182.189.99.211:48299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c1ITd5soprXwxAH0iHgAAAFs"]
[Tue Jul 21 08:49:40.284940 2026] [security2:error] [pid 514479:tid 514695] [client 203.25.124.189:20663] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/blog-stream/inc/upgrade-to-pro/section-pro.php"] [unique_id "al9c1PzqsQqnLoCgUjiIiAAAAVs"]
[Tue Jul 21 08:49:40.474613 2026] [security2:error] [pid 511108:tid 511244] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c1ITd5soprXwxAH0iHwAAAAY"]
[Tue Jul 21 08:49:40.535707 2026] [security2:error] [pid 514479:tid 514708] [client 20.104.96.117:4067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/edorxrr.php"] [unique_id "al9c1PzqsQqnLoCgUjiIlgAAAWg"]
[Tue Jul 21 08:49:40.719672 2026] [security2:error] [pid 514479:tid 514731] [client 20.151.10.161:62418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/222.php"] [unique_id "al9c1PzqsQqnLoCgUjiIoQAAAX8"]
[Tue Jul 21 08:49:40.997133 2026] [security2:error] [pid 511108:tid 511305] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9c1ITd5soprXwxAH0iLAAAAEM"]
[Tue Jul 21 08:49:41.148218 2026] [security2:error] [pid 514479:tid 514614] [client 20.226.60.151:59719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-file-120.php"] [unique_id "al9c1fzqsQqnLoCgUjiIpgAAAQo"]
[Tue Jul 21 08:49:41.157712 2026] [security2:error] [pid 514479:tid 514610] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9c1fzqsQqnLoCgUjiIpwABMX0"]
[Tue Jul 21 08:49:41.157853 2026] [security2:error] [pid 514479:tid 514653] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9c1fzqsQqnLoCgUjiIpwABMX0"]
[Tue Jul 21 08:49:41.390633 2026] [security2:error] [pid 511108:tid 511267] [client 20.104.96.117:46759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/miru1.php"] [unique_id "al9c1YTd5soprXwxAH0iNQAAAB0"]
[Tue Jul 21 08:49:41.394257 2026] [security2:error] [pid 511108:tid 511264] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9c1YTd5soprXwxAH0iNgAAABo"]
[Tue Jul 21 08:49:41.431666 2026] [security2:error] [pid 511108:tid 511323] [client 203.25.124.48:57901] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/js/widgets/admin.php"] [unique_id "al9c1YTd5soprXwxAH0iNwAAAFU"]
[Tue Jul 21 08:49:41.568435 2026] [security2:error] [pid 514479:tid 514638] [client 203.25.124.212:25819] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "al9c1fzqsQqnLoCgUjiIrwAAASI"]
[Tue Jul 21 08:49:41.578016 2026] [security2:error] [pid 511108:tid 511354] [client 203.25.124.246:29943] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/fusion-styles/user/index.php"] [unique_id "al9c1YTd5soprXwxAH0iPAAAAHQ"]
[Tue Jul 21 08:49:41.602999 2026] [security2:error] [pid 511108:tid 511276] [client 20.151.10.161:62350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9c1YTd5soprXwxAH0iPgAAACY"]
[Tue Jul 21 08:49:41.723729 2026] [security2:error] [pid 514479:tid 514651] [client 20.104.96.117:59176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/h02ugyh.php"] [unique_id "al9c1fzqsQqnLoCgUjiItQAAAS8"]
[Tue Jul 21 08:49:41.767886 2026] [security2:error] [pid 514479:tid 514708] [client 20.197.192.193:22368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/2x.php"] [unique_id "al9c1fzqsQqnLoCgUjiItwAAAWg"]
[Tue Jul 21 08:49:41.881926 2026] [security2:error] [pid 511108:tid 511309] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9c1YTd5soprXwxAH0iPwAAR1o"]
[Tue Jul 21 08:49:41.918181 2026] [security2:error] [pid 511108:tid 511339] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9c1YTd5soprXwxAH0iRAAAAGU"]
[Tue Jul 21 08:49:42.040434 2026] [security2:error] [pid 514479:tid 514674] [client 20.104.96.117:4034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/sump1.php"] [unique_id "al9c1vzqsQqnLoCgUjiIvwAAAUY"]
[Tue Jul 21 08:49:42.074303 2026] [security2:error] [pid 514479:tid 514710] [client 168.167.81.163:62988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9c1vzqsQqnLoCgUjiIwAAAAWo"]
[Tue Jul 21 08:49:42.074413 2026] [security2:error] [pid 514479:tid 514710] [client 168.167.81.163:62988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9c1vzqsQqnLoCgUjiIwAAAAWo"]
[Tue Jul 21 08:49:42.389505 2026] [security2:error] [pid 514479:tid 514732] [client 20.151.10.161:62356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9c1vzqsQqnLoCgUjiIwwAAAYA"]
[Tue Jul 21 08:49:42.406766 2026] [security2:error] [pid 514479:tid 514715] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9c1vzqsQqnLoCgUjiIxAAAAW8"]
[Tue Jul 21 08:49:42.494893 2026] [security2:error] [pid 514479:tid 514631] [client 20.104.96.117:4092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/file5.php"] [unique_id "al9c1vzqsQqnLoCgUjiIxwAAARs"]
[Tue Jul 21 08:49:42.672386 2026] [security2:error] [pid 514479:tid 514703] [client 203.25.124.191:65307] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwentyfive/parts/upgrade/index.php"] [unique_id "al9c1vzqsQqnLoCgUjiIzAAAAWM"]
[Tue Jul 21 08:49:42.807454 2026] [security2:error] [pid 511108:tid 511293] [client 20.104.96.117:59147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-temp.php"] [unique_id "al9c1oTd5soprXwxAH0iVgAAADc"]
[Tue Jul 21 08:49:42.808992 2026] [security2:error] [pid 511108:tid 511357] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9c1oTd5soprXwxAH0iVwAAAHc"]
[Tue Jul 21 08:49:42.848930 2026] [security2:error] [pid 511108:tid 511334] [client 203.25.124.73:22211] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/dist/vendor/about.php"] [unique_id "al9c1oTd5soprXwxAH0iXAAAAGA"]
[Tue Jul 21 08:49:43.040158 2026] [security2:error] [pid 514479:tid 514685] [client 203.25.124.54:61779] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/bltm/wp-login.php"] [unique_id "al9c1vzqsQqnLoCgUjiI0gAAAVE"]
[Tue Jul 21 08:49:43.224673 2026] [security2:error] [pid 514479:tid 514639] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9c1_zqsQqnLoCgUjiI1QAAASM"]
[Tue Jul 21 08:49:43.229067 2026] [security2:error] [pid 511108:tid 511354] [client 20.151.10.161:8401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp.php"] [unique_id "al9c14Td5soprXwxAH0iZgAAAHQ"]
[Tue Jul 21 08:49:43.338513 2026] [security2:error] [pid 514479:tid 514618] [client 20.226.60.151:57634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/special.php"] [unique_id "al9c1_zqsQqnLoCgUjiI2QAAAQ4"]
[Tue Jul 21 08:49:43.379905 2026] [security2:error] [pid 514479:tid 514641] [client 65.21.113.253:42650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9c1_zqsQqnLoCgUjiI2wAAASU"]
[Tue Jul 21 08:49:43.407733 2026] [security2:error] [pid 514479:tid 514623] [client 49.144.66.253:30710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9c1_zqsQqnLoCgUjiI3AAAARM"]
[Tue Jul 21 08:49:43.407841 2026] [security2:error] [pid 514479:tid 514623] [client 49.144.66.253:30710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9c1_zqsQqnLoCgUjiI3AAAARM"]
[Tue Jul 21 08:49:43.422068 2026] [security2:error] [pid 514479:tid 514707] [client 20.104.96.117:46774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/0xD.php"] [unique_id "al9c1_zqsQqnLoCgUjiI3QAAAWc"]
[Tue Jul 21 08:49:43.624882 2026] [security2:error] [pid 514479:tid 514696] [client 20.104.96.117:61177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-content/cong.php"] [unique_id "al9c1_zqsQqnLoCgUjiI3wAAAVw"]
[Tue Jul 21 08:49:43.648702 2026] [security2:error] [pid 511108:tid 511301] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9c14Td5soprXwxAH0iaQAAAD8"]
[Tue Jul 21 08:49:43.681165 2026] [security2:error] [pid 511108:tid 511276] [client 114.198.138.124:65465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9c14Td5soprXwxAH0iawAAACY"]
[Tue Jul 21 08:49:43.681253 2026] [security2:error] [pid 511108:tid 511276] [client 114.198.138.124:65465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9c14Td5soprXwxAH0iawAAACY"]
[Tue Jul 21 08:49:43.688929 2026] [security2:error] [pid 511108:tid 511283] [client 20.151.10.161:62463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/abcd.php"] [unique_id "al9c14Td5soprXwxAH0ibAAAAC0"]
[Tue Jul 21 08:49:43.870933 2026] [security2:error] [pid 511108:tid 511256] [client 203.25.124.201:29897] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/network/theme-install-variable.php"] [unique_id "al9c14Td5soprXwxAH0icgAAABI"]
[Tue Jul 21 08:49:44.023519 2026] [security2:error] [pid 511108:tid 511331] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9c2ITd5soprXwxAH0idwAAAF0"]
[Tue Jul 21 08:49:44.045069 2026] [security2:error] [pid 514479:tid 514715] [client 203.25.124.2:57333] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/footnotes/"] [unique_id "al9c2PzqsQqnLoCgUjiI5QAAAW8"]
[Tue Jul 21 08:49:44.127670 2026] [security2:error] [pid 511108:tid 511299] [client 20.151.10.161:62372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/a1.php"] [unique_id "al9c2ITd5soprXwxAH0ieQAAAD0"]
[Tue Jul 21 08:49:44.321277 2026] [security2:error] [pid 514479:tid 514705] [client 59.95.197.55:52558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c2PzqsQqnLoCgUjiI6gAAAWU"]
[Tue Jul 21 08:49:44.321477 2026] [security2:error] [pid 514479:tid 514705] [client 59.95.197.55:52558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c2PzqsQqnLoCgUjiI6gAAAWU"]
[Tue Jul 21 08:49:44.345791 2026] [security2:error] [pid 511108:tid 511273] [client 20.226.60.151:59775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/as.php"] [unique_id "al9c2ITd5soprXwxAH0ifgAAACM"]
[Tue Jul 21 08:49:44.388702 2026] [security2:error] [pid 514479:tid 514733] [client 198.44.157.34:54994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9c2PzqsQqnLoCgUjiI7AAAAYE"]
[Tue Jul 21 08:49:44.388802 2026] [security2:error] [pid 514479:tid 514733] [client 198.44.157.34:54994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9c2PzqsQqnLoCgUjiI7AAAAYE"]
[Tue Jul 21 08:49:44.406800 2026] [security2:error] [pid 514479:tid 514726] [client 20.104.96.117:4086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/fnstall.php"] [unique_id "al9c2PzqsQqnLoCgUjiI9AAAAXo"]
[Tue Jul 21 08:49:44.458691 2026] [security2:error] [pid 511108:tid 511365] [client 212.32.76.13:24269] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/includes/nav.php"] [unique_id "al9c2ITd5soprXwxAH0igwAAAH8"]
[Tue Jul 21 08:49:44.483135 2026] [security2:error] [pid 511108:tid 511263] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9c2ITd5soprXwxAH0ihAAAABk"]
[Tue Jul 21 08:49:44.511574 2026] [security2:error] [pid 511108:tid 511249] [client 65.21.113.253:50630] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9c2ITd5soprXwxAH0ieAAAAAs"]
[Tue Jul 21 08:49:44.583608 2026] [security2:error] [pid 514479:tid 514679] [client 20.151.10.161:8398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9c2PzqsQqnLoCgUjiI9wAAAUs"]
[Tue Jul 21 08:49:44.655097 2026] [security2:error] [pid 514479:tid 514631] [client 122.176.100.127:54057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9c2PzqsQqnLoCgUjiI-wAAARs"]
[Tue Jul 21 08:49:44.655226 2026] [security2:error] [pid 514479:tid 514631] [client 122.176.100.127:54057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9c2PzqsQqnLoCgUjiI-wAAARs"]
[Tue Jul 21 08:49:44.742404 2026] [security2:error] [pid 511108:tid 511297] [client 195.206.105.227:60266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9c2ITd5soprXwxAH0ihgAAADs"]
[Tue Jul 21 08:49:44.742501 2026] [security2:error] [pid 511108:tid 511297] [client 195.206.105.227:60266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9c2ITd5soprXwxAH0ihgAAADs"]
[Tue Jul 21 08:49:44.883264 2026] [security2:error] [pid 511108:tid 511362] [client 203.25.124.206:23977] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentynineteen/sass/site/index.php"] [unique_id "al9c2ITd5soprXwxAH0iiQAAAHw"]
[Tue Jul 21 08:49:44.884042 2026] [security2:error] [pid 511108:tid 511305] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9c2ITd5soprXwxAH0iigAAAEM"]
[Tue Jul 21 08:49:45.070352 2026] [security2:error] [pid 511108:tid 511264] [client 20.226.60.151:57549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9c2YTd5soprXwxAH0ikAAAABo"]
[Tue Jul 21 08:49:45.256514 2026] [security2:error] [pid 514479:tid 514628] [client 2.57.168.33:63105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.168.57.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9c2fzqsQqnLoCgUjiJCgAAARg"]
[Tue Jul 21 08:49:45.370871 2026] [security2:error] [pid 514479:tid 514731] [client 5.38.115.39:51740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9c2fzqsQqnLoCgUjiJEwAAAX8"]
[Tue Jul 21 08:49:45.371007 2026] [security2:error] [pid 514479:tid 514731] [client 5.38.115.39:51740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9c2fzqsQqnLoCgUjiJEwAAAX8"]
[Tue Jul 21 08:49:45.375872 2026] [security2:error] [pid 514479:tid 514692] [client 20.220.225.223:46387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/2x.php"] [unique_id "al9c2fzqsQqnLoCgUjiJFAAAAVg"]
[Tue Jul 21 08:49:45.414254 2026] [security2:error] [pid 514479:tid 514717] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9c2fzqsQqnLoCgUjiJFwAAAXE"]
[Tue Jul 21 08:49:45.542791 2026] [security2:error] [pid 514479:tid 514711] [client 20.104.96.117:46744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/acp.php"] [unique_id "al9c2fzqsQqnLoCgUjiJGwAAAWs"]
[Tue Jul 21 08:49:45.806763 2026] [security2:error] [pid 514479:tid 514704] [client 20.197.192.193:8378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/ww.php"] [unique_id "al9c2fzqsQqnLoCgUjiJIgAAAWQ"]
[Tue Jul 21 08:49:45.836304 2026] [security2:error] [pid 514479:tid 514639] [client 20.151.10.161:8328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9c2fzqsQqnLoCgUjiJJQAAASM"]
[Tue Jul 21 08:49:45.840162 2026] [security2:error] [pid 514479:tid 514712] [client 212.32.76.3:52851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/pullquote/"] [unique_id "al9c2fzqsQqnLoCgUjiJJgAAAWw"]
[Tue Jul 21 08:49:45.862745 2026] [security2:error] [pid 511108:tid 511339] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vaniellenbragamoura1782152770547.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9c2YTd5soprXwxAH0iogAAAGU"]
[Tue Jul 21 08:49:45.870268 2026] [security2:error] [pid 511108:tid 511331] [client 203.25.124.68:33761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/shell3.php"] [unique_id "al9c2YTd5soprXwxAH0iowAAAF0"]
[Tue Jul 21 08:49:45.975982 2026] [security2:error] [pid 514479:tid 514679] [client 203.25.124.200:56389] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwentyone/assets/sass/05-blocks/preformatted/index.php"] [unique_id "al9c2fzqsQqnLoCgUjiJKQAAAUs"]
[Tue Jul 21 08:49:46.276223 2026] [security2:error] [pid 514479:tid 514683] [client 180.93.252.125:48406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "sscoenper.com.br"] [uri "/"] [unique_id "al9c2vzqsQqnLoCgUjiJMgAAAU8"]
[Tue Jul 21 08:49:46.285362 2026] [security2:error] [pid 514479:tid 514647] [client 20.104.96.117:61064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9c2vzqsQqnLoCgUjiJMwAAASs"]
[Tue Jul 21 08:49:46.646764 2026] [security2:error] [pid 511108:tid 511313] [client 203.25.124.36:31235] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/simple.php"] [unique_id "al9c2oTd5soprXwxAH0iuQAAAEs"]
[Tue Jul 21 08:49:46.712764 2026] [security2:error] [pid 511108:tid 511353] [client 103.59.206.240:31319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c2oTd5soprXwxAH0iuwAAAHM"]
[Tue Jul 21 08:49:46.712903 2026] [security2:error] [pid 511108:tid 511353] [client 103.59.206.240:31319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c2oTd5soprXwxAH0iuwAAAHM"]
[Tue Jul 21 08:49:46.751265 2026] [security2:error] [pid 514479:tid 514734] [client 195.49.128.211:58457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9c2vzqsQqnLoCgUjiJOwAAAYI"]
[Tue Jul 21 08:49:46.751406 2026] [security2:error] [pid 514479:tid 514734] [client 195.49.128.211:58457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9c2vzqsQqnLoCgUjiJOwAAAYI"]
[Tue Jul 21 08:49:46.820650 2026] [security2:error] [pid 511108:tid 511280] [client 20.151.10.161:62353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/gettest.php"] [unique_id "al9c2oTd5soprXwxAH0ivAAAACo"]
[Tue Jul 21 08:49:46.889436 2026] [security2:error] [pid 514479:tid 514703] [client 69.171.230.15:41194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9c2vzqsQqnLoCgUjiJPAAAAWM"]
[Tue Jul 21 08:49:47.065465 2026] [security2:error] [pid 514479:tid 514661] [client 20.220.225.223:37626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/kq1.php"] [unique_id "al9c2_zqsQqnLoCgUjiJPgAAATk"]
[Tue Jul 21 08:49:47.074385 2026] [security2:error] [pid 514479:tid 514614] [client 203.25.124.3:53439] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/elex/elex.php"] [unique_id "al9c2_zqsQqnLoCgUjiJPwAAAQo"]
[Tue Jul 21 08:49:47.172440 2026] [security2:error] [pid 514479:tid 514689] [client 212.32.76.12:65247] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/hplfuns.php"] [unique_id "al9c2_zqsQqnLoCgUjiJRQAAAVU"]
[Tue Jul 21 08:49:47.363596 2026] [security2:error] [pid 511108:tid 511325] [client 20.226.60.151:59765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/w1px.php"] [unique_id "al9c24Td5soprXwxAH0ixAAAAFc"]
[Tue Jul 21 08:49:47.409109 2026] [security2:error] [pid 511108:tid 511361] [client 20.151.10.161:62459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/simple.php"] [unique_id "al9c24Td5soprXwxAH0ixgAAAHs"]
[Tue Jul 21 08:49:47.481882 2026] [security2:error] [pid 514479:tid 514639] [client 173.252.95.38:34028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9c2_zqsQqnLoCgUjiJSgAAASM"]
[Tue Jul 21 08:49:47.588169 2026] [security2:error] [pid 514479:tid 514657] [client 20.104.96.117:61121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/jj.php"] [unique_id "al9c2_zqsQqnLoCgUjiJSwAAATU"]
[Tue Jul 21 08:49:47.600976 2026] [security2:error] [pid 511108:tid 511314] [client 41.89.234.2:55596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c24Td5soprXwxAH0iyQAAAEw"]
[Tue Jul 21 08:49:47.601143 2026] [security2:error] [pid 511108:tid 511314] [client 41.89.234.2:55596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c24Td5soprXwxAH0iyQAAAEw"]
[Tue Jul 21 08:49:47.716405 2026] [security2:error] [pid 514479:tid 514736] [client 20.104.96.117:4047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/mosty.php"] [unique_id "al9c2_zqsQqnLoCgUjiJUQAAAYQ"]
[Tue Jul 21 08:49:47.895870 2026] [security2:error] [pid 514479:tid 514693] [client 65.21.113.253:42650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9c2_zqsQqnLoCgUjiJUgAAAVk"]
[Tue Jul 21 08:49:47.940098 2026] [security2:error] [pid 514479:tid 514731] [client 20.151.10.161:8411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/xxx.php"] [unique_id "al9c2_zqsQqnLoCgUjiJVAAAAX8"]
[Tue Jul 21 08:49:48.063111 2026] [security2:error] [pid 514479:tid 514729] [client 173.252.95.25:49184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9c3PzqsQqnLoCgUjiJVgAAAX0"]
[Tue Jul 21 08:49:48.141567 2026] [security2:error] [pid 514479:tid 514723] [client 212.32.76.2:39623] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/includes/admin.php"] [unique_id "al9c3PzqsQqnLoCgUjiJVwAAAXc"]
[Tue Jul 21 08:49:48.169940 2026] [security2:error] [pid 511108:tid 511329] [client 212.32.76.60:48021] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/oceanwp/sass/base/1.php"] [unique_id "al9c3ITd5soprXwxAH0i1wAAAFs"]
[Tue Jul 21 08:49:48.313724 2026] [security2:error] [pid 511108:tid 511249] [client 195.206.105.227:49316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9c3ITd5soprXwxAH0i2gAAAAs"]
[Tue Jul 21 08:49:48.313975 2026] [security2:error] [pid 511108:tid 511249] [client 195.206.105.227:49316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9c3ITd5soprXwxAH0i2gAAAAs"]
[Tue Jul 21 08:49:48.429427 2026] [security2:error] [pid 511108:tid 511263] [client 20.151.10.161:62377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/hypo.php"] [unique_id "al9c3ITd5soprXwxAH0i2wAAABk"]
[Tue Jul 21 08:49:48.466617 2026] [proxy:error] [pid 511108:tid 511242] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:48.466687 2026] [proxy_http:error] [pid 511108:tid 511242] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:48.467337 2026] [proxy:error] [pid 511108:tid 511242] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:48.467372 2026] [proxy_http:error] [pid 511108:tid 511242] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:48.566955 2026] [security2:error] [pid 511108:tid 511334] [client 203.25.124.58:45063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/admin/index.php"] [unique_id "al9c3ITd5soprXwxAH0i3wAAAGA"]
[Tue Jul 21 08:49:48.682883 2026] [security2:error] [pid 511108:tid 511362] [client 20.197.192.193:22367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/kq1.php"] [unique_id "al9c3ITd5soprXwxAH0i4gAAAHw"]
[Tue Jul 21 08:49:48.688347 2026] [security2:error] [pid 514479:tid 514695] [client 20.220.225.223:35135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/zzz.php"] [unique_id "al9c3PzqsQqnLoCgUjiJXAAAAVs"]
[Tue Jul 21 08:49:48.690611 2026] [security2:error] [pid 514479:tid 514663] [client 20.226.60.151:53516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/yawa.php"] [unique_id "al9c3PzqsQqnLoCgUjiJXQAAATs"]
[Tue Jul 21 08:49:48.699185 2026] [security2:error] [pid 511108:tid 511201] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9c3ITd5soprXwxAH0i4wAAf1w"]
[Tue Jul 21 08:49:48.699306 2026] [security2:error] [pid 511108:tid 511365] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9c3ITd5soprXwxAH0i4wAAf1w"]
[Tue Jul 21 08:49:48.837084 2026] [security2:error] [pid 514479:tid 514631] [client 20.104.96.117:59192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/class-walker-footer-dev.php"] [unique_id "al9c3PzqsQqnLoCgUjiJYQAAARs"]
[Tue Jul 21 08:49:48.848467 2026] [proxy:error] [pid 514479:tid 514688] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:48.848533 2026] [proxy_http:error] [pid 514479:tid 514688] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:48.849375 2026] [proxy:error] [pid 514479:tid 514688] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:48.849417 2026] [proxy_http:error] [pid 514479:tid 514688] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:48.960728 2026] [security2:error] [pid 511108:tid 511255] [client 65.21.113.253:50644] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9c3ITd5soprXwxAH0i4AAAABE"]
[Tue Jul 21 08:49:48.962797 2026] [security2:error] [pid 514479:tid 514675] [client 69.171.230.10:55774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9c3PzqsQqnLoCgUjiJYwAAAUc"]
[Tue Jul 21 08:49:49.117105 2026] [security2:error] [pid 514479:tid 514621] [client 104.197.105.8:36806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "rlvenergiainteligente.com.br"] [uri "/"] [unique_id "al9c3fzqsQqnLoCgUjiJawAAARE"]
[Tue Jul 21 08:49:49.160723 2026] [security2:error] [pid 514479:tid 514647] [client 20.151.10.161:8442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/chosen.php"] [unique_id "al9c3fzqsQqnLoCgUjiJbQAAASs"]
[Tue Jul 21 08:49:49.279394 2026] [proxy:error] [pid 514479:tid 514715] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:49.280024 2026] [proxy_http:error] [pid 514479:tid 514715] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:49.282379 2026] [proxy:error] [pid 514479:tid 514715] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:49.282459 2026] [proxy_http:error] [pid 514479:tid 514715] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:49.307038 2026] [security2:error] [pid 514479:tid 514727] [client 173.252.95.42:60238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9c3fzqsQqnLoCgUjiJcAAAAXs"]
[Tue Jul 21 08:49:49.378429 2026] [security2:error] [pid 514479:tid 514705] [client 203.25.124.10:54399] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwentyone/emerance.php"] [unique_id "al9c3fzqsQqnLoCgUjiJcgAAAWU"]
[Tue Jul 21 08:49:49.394243 2026] [security2:error] [pid 514479:tid 514641] [client 20.197.192.193:38221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/zzz.php"] [unique_id "al9c3fzqsQqnLoCgUjiJcwAAASU"]
[Tue Jul 21 08:49:49.408243 2026] [security2:error] [pid 514479:tid 514619] [client 113.22.144.139:53143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c3fzqsQqnLoCgUjiJdAAAAQ8"]
[Tue Jul 21 08:49:49.408322 2026] [security2:error] [pid 514479:tid 514619] [client 113.22.144.139:53143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c3fzqsQqnLoCgUjiJdAAAAQ8"]
[Tue Jul 21 08:49:49.529413 2026] [security2:error] [pid 511108:tid 511270] [client 203.25.124.53:36287] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/css/dist/reusable-blocks/"] [unique_id "al9c3YTd5soprXwxAH0i8gAAACA"]
[Tue Jul 21 08:49:49.562752 2026] [security2:error] [pid 514479:tid 514723] [client 203.25.124.50:56191] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/admin-wolf.php"] [unique_id "al9c3fzqsQqnLoCgUjiJdgAAAXc"]
[Tue Jul 21 08:49:49.632487 2026] [security2:error] [pid 514479:tid 514691] [client 173.252.95.14:61306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9c3fzqsQqnLoCgUjiJeAAAAVc"]
[Tue Jul 21 08:49:49.679263 2026] [security2:error] [pid 514479:tid 514686] [client 20.197.192.193:9573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/cron.php"] [unique_id "al9c3fzqsQqnLoCgUjiJeQAAAVI"]
[Tue Jul 21 08:49:49.689767 2026] [security2:error] [pid 514479:tid 514516] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c3fzqsQqnLoCgUjiJegABEiA"]
[Tue Jul 21 08:49:49.689905 2026] [security2:error] [pid 514479:tid 514622] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c3fzqsQqnLoCgUjiJegABEiA"]
[Tue Jul 21 08:49:49.750646 2026] [security2:error] [pid 511108:tid 511312] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c3YTd5soprXwxAH0i-AAAAEo"]
[Tue Jul 21 08:49:50.025872 2026] [security2:error] [pid 514479:tid 514734] [client 20.151.10.161:8399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/als.php"] [unique_id "al9c3vzqsQqnLoCgUjiJgAAAAYI"]
[Tue Jul 21 08:49:50.045283 2026] [security2:error] [pid 514479:tid 514577] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9c3vzqsQqnLoCgUjiJgQABgFw"]
[Tue Jul 21 08:49:50.045511 2026] [security2:error] [pid 514479:tid 514732] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9c3vzqsQqnLoCgUjiJgQABgFw"]
[Tue Jul 21 08:49:50.105392 2026] [security2:error] [pid 514479:tid 514621] [client 20.104.96.117:59150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/txets.php"] [unique_id "al9c3vzqsQqnLoCgUjiJhQAAARE"]
[Tue Jul 21 08:49:50.231761 2026] [security2:error] [pid 511108:tid 511256] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9c3oTd5soprXwxAH0i_QAAABI"]
[Tue Jul 21 08:49:50.289565 2026] [security2:error] [pid 511108:tid 511290] [client 173.252.95.3:39816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9c3oTd5soprXwxAH0jAAAAADQ"]
[Tue Jul 21 08:49:50.408335 2026] [security2:error] [pid 514479:tid 514574] [remote 17.246.15.184:33854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.15.246.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9c3vzqsQqnLoCgUjiJiQABRVk"]
[Tue Jul 21 08:49:50.476362 2026] [security2:error] [pid 511108:tid 511329] [client 212.32.76.63:25159] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentynineteen/content-index.php"] [unique_id "al9c3oTd5soprXwxAH0jBQAAAFs"]
[Tue Jul 21 08:49:50.571802 2026] [security2:error] [pid 511108:tid 511349] [client 203.25.124.67:64651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "al9c3oTd5soprXwxAH0jCgAAAG8"]
[Tue Jul 21 08:49:50.606709 2026] [security2:error] [pid 511108:tid 511299] [client 20.151.10.161:62358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/pol.php"] [unique_id "al9c3oTd5soprXwxAH0jCwAAAD0"]
[Tue Jul 21 08:49:50.657928 2026] [security2:error] [pid 511108:tid 511285] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9c3oTd5soprXwxAH0jDAAAAC8"]
[Tue Jul 21 08:49:50.692278 2026] [security2:error] [pid 514479:tid 514674] [client 182.189.99.211:48309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c3vzqsQqnLoCgUjiJjgAAAUY"]
[Tue Jul 21 08:49:50.692411 2026] [security2:error] [pid 514479:tid 514674] [client 182.189.99.211:48309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c3vzqsQqnLoCgUjiJjgAAAUY"]
[Tue Jul 21 08:49:50.737904 2026] [security2:error] [pid 514479:tid 514717] [client 212.32.76.5:65099] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-signin.php"] [unique_id "al9c3vzqsQqnLoCgUjiJjwAAAXE"]
[Tue Jul 21 08:49:50.825566 2026] [security2:error] [pid 514479:tid 514635] [client 20.226.60.151:57644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/js.php"] [unique_id "al9c3vzqsQqnLoCgUjiJkwAAAR8"]
[Tue Jul 21 08:49:51.034384 2026] [security2:error] [pid 514479:tid 514518] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c3_zqsQqnLoCgUjiJlgABfSI"]
[Tue Jul 21 08:49:51.034537 2026] [security2:error] [pid 514479:tid 514729] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c3_zqsQqnLoCgUjiJlgABfSI"]
[Tue Jul 21 08:49:51.103610 2026] [security2:error] [pid 514479:tid 514676] [client 168.167.81.163:62905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9c3_zqsQqnLoCgUjiJlwAAAUg"]
[Tue Jul 21 08:49:51.103718 2026] [security2:error] [pid 514479:tid 514676] [client 168.167.81.163:62905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9c3_zqsQqnLoCgUjiJlwAAAUg"]
[Tue Jul 21 08:49:51.109838 2026] [security2:error] [pid 511108:tid 511247] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9c34Td5soprXwxAH0jFQAAAAk"]
[Tue Jul 21 08:49:51.282055 2026] [security2:error] [pid 514479:tid 514679] [client 212.32.76.54:49777] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/responsive-lightbox/assets/nivo/themes/wp-load.php"] [unique_id "al9c3_zqsQqnLoCgUjiJnQAAAUs"]
[Tue Jul 21 08:49:51.285129 2026] [security2:error] [pid 514479:tid 514738] [client 20.104.96.117:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/dex.php"] [unique_id "al9c3_zqsQqnLoCgUjiJngAAAYY"]
[Tue Jul 21 08:49:51.373614 2026] [security2:error] [pid 514479:tid 514708] [client 20.151.10.161:62391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/file5.php"] [unique_id "al9c3_zqsQqnLoCgUjiJnwAAAWg"]
[Tue Jul 21 08:49:51.445508 2026] [security2:error] [pid 514479:tid 514685] [client 173.252.95.34:49990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9c3_zqsQqnLoCgUjiJnAAAAVE"]
[Tue Jul 21 08:49:51.494730 2026] [security2:error] [pid 511108:tid 511260] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9c34Td5soprXwxAH0jIQAAABY"]
[Tue Jul 21 08:49:51.666198 2026] [security2:error] [pid 514479:tid 514736] [client 203.25.124.55:31099] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/2021/file.php"] [unique_id "al9c3_zqsQqnLoCgUjiJpAAAAYQ"]
[Tue Jul 21 08:49:51.673496 2026] [security2:error] [pid 514479:tid 514689] [client 5.31.193.106:30406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9c3_zqsQqnLoCgUjiJpQAAAVU"]
[Tue Jul 21 08:49:51.673612 2026] [security2:error] [pid 514479:tid 514689] [client 5.31.193.106:30406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9c3_zqsQqnLoCgUjiJpQAAAVU"]
[Tue Jul 21 08:49:51.706308 2026] [security2:error] [pid 511108:tid 511122] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9c34Td5soprXwxAH0jJgAASg0"]
[Tue Jul 21 08:49:51.706435 2026] [security2:error] [pid 511108:tid 511312] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9c34Td5soprXwxAH0jJgAASg0"]
[Tue Jul 21 08:49:51.769636 2026] [security2:error] [pid 514479:tid 514722] [client 20.151.10.161:62399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9c3_zqsQqnLoCgUjiJpwAAAXY"]
[Tue Jul 21 08:49:51.944291 2026] [security2:error] [pid 511108:tid 511261] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9c34Td5soprXwxAH0jLQAAABc"]
[Tue Jul 21 08:49:52.008072 2026] [security2:error] [pid 514479:tid 514647] [client 64.42.179.43:51002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9c4PzqsQqnLoCgUjiJqgAAASs"]
[Tue Jul 21 08:49:52.008193 2026] [security2:error] [pid 514479:tid 514647] [client 64.42.179.43:51002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9c4PzqsQqnLoCgUjiJqgAAASs"]
[Tue Jul 21 08:49:52.091152 2026] [security2:error] [pid 514479:tid 514718] [client 20.197.192.193:8374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/xxx.php"] [unique_id "al9c4PzqsQqnLoCgUjiJqwAAAXI"]
[Tue Jul 21 08:49:52.282732 2026] [security2:error] [pid 511108:tid 511274] [client 203.25.124.184:20119] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/responsive-lightbox/assets/jstree/themes/system.php"] [unique_id "al9c4ITd5soprXwxAH0jMQAAACQ"]
[Tue Jul 21 08:49:52.284649 2026] [security2:error] [pid 511108:tid 511249] [client 20.226.60.151:57655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/core.php"] [unique_id "al9c4ITd5soprXwxAH0jMgAAAAs"]
[Tue Jul 21 08:49:52.328682 2026] [security2:error] [pid 511108:tid 511263] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9c4ITd5soprXwxAH0jNAAAABk"]
[Tue Jul 21 08:49:52.468195 2026] [security2:error] [pid 511108:tid 511317] [client 20.104.96.117:4003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/6.php"] [unique_id "al9c4ITd5soprXwxAH0jOgAAAE8"]
[Tue Jul 21 08:49:52.577541 2026] [security2:error] [pid 514479:tid 514733] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9c4PzqsQqnLoCgUjiJtAABgSc"]
[Tue Jul 21 08:49:52.640142 2026] [security2:error] [pid 514479:tid 514615] [client 203.25.124.33:51725] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/config.php"] [unique_id "al9c4PzqsQqnLoCgUjiJtwAAAQs"]
[Tue Jul 21 08:49:52.685317 2026] [security2:error] [pid 514479:tid 514729] [client 20.104.96.117:61158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/xpwer1.php"] [unique_id "al9c4PzqsQqnLoCgUjiJuQAAAX0"]
[Tue Jul 21 08:49:52.792260 2026] [security2:error] [pid 514479:tid 514618] [client 20.197.192.193:22336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/wicked.php"] [unique_id "al9c4PzqsQqnLoCgUjiJuwAAAQ4"]
[Tue Jul 21 08:49:52.846310 2026] [security2:error] [pid 514479:tid 514708] [client 65.21.113.253:42650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9c4PzqsQqnLoCgUjiJvgAAAWg"]
[Tue Jul 21 08:49:52.848517 2026] [security2:error] [pid 514479:tid 514685] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9c4PzqsQqnLoCgUjiJvwAAAVE"]
[Tue Jul 21 08:49:52.848662 2026] [security2:error] [pid 514479:tid 514724] [client 20.151.10.161:8325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/file.php"] [unique_id "al9c4PzqsQqnLoCgUjiJwAAAAXg"]
[Tue Jul 21 08:49:52.960458 2026] [security2:error] [pid 514479:tid 514688] [client 203.25.124.212:22009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "al9c4PzqsQqnLoCgUjiJwwAAAVQ"]
[Tue Jul 21 08:49:53.373213 2026] [security2:error] [pid 514479:tid 514705] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9c4fzqsQqnLoCgUjiJyAAAAWU"]
[Tue Jul 21 08:49:53.374987 2026] [security2:error] [pid 514479:tid 514715] [client 20.220.225.223:46691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/wicked.php"] [unique_id "al9c4fzqsQqnLoCgUjiJyQAAAW8"]
[Tue Jul 21 08:49:53.375702 2026] [security2:error] [pid 514479:tid 514659] [client 203.25.124.198:59669] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/contact-form-7/includes/js/jquery-ui/themes/data.php"] [unique_id "al9c4fzqsQqnLoCgUjiJygAAATc"]
[Tue Jul 21 08:49:53.599293 2026] [core:error] [pid 514479:tid 514673] [client 66.249.66.38:61744] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:49:53.599321 2026] [core:error] [pid 514479:tid 514673] [client 66.249.66.38:61744] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:49:53.768156 2026] [security2:error] [pid 514479:tid 514652] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9c4fzqsQqnLoCgUjiJ0AAAATA"]
[Tue Jul 21 08:49:53.877686 2026] [security2:error] [pid 514479:tid 514722] [client 65.21.113.253:54760] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9c4fzqsQqnLoCgUjiJzQAAAXY"]
[Tue Jul 21 08:49:53.907079 2026] [security2:error] [pid 514479:tid 514741] [client 20.104.96.117:61156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/flox.php"] [unique_id "al9c4fzqsQqnLoCgUjiJ0QAAAYk"]
[Tue Jul 21 08:49:53.963183 2026] [security2:error] [pid 511108:tid 511253] [client 203.25.124.36:41405] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "al9c4YTd5soprXwxAH0jSgAAAA8"]
[Tue Jul 21 08:49:53.991625 2026] [security2:error] [pid 514479:tid 514723] [client 20.151.10.161:62351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/cfile.php"] [unique_id "al9c4fzqsQqnLoCgUjiJ1AAAAXc"]
[Tue Jul 21 08:49:54.043705 2026] [security2:error] [pid 514479:tid 514646] [client 49.144.66.253:31116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9c4vzqsQqnLoCgUjiJ1QAAASo"]
[Tue Jul 21 08:49:54.043805 2026] [security2:error] [pid 514479:tid 514646] [client 49.144.66.253:31116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9c4vzqsQqnLoCgUjiJ1QAAASo"]
[Tue Jul 21 08:49:54.223018 2026] [security2:error] [pid 514479:tid 514711] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9c4vzqsQqnLoCgUjiJ2QAAAWs"]
[Tue Jul 21 08:49:54.274118 2026] [security2:error] [pid 511108:tid 511354] [client 203.25.124.189:58821] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/windazo/inc/plugins/wp-blog-header.php"] [unique_id "al9c4oTd5soprXwxAH0jTgAAAHQ"]
[Tue Jul 21 08:49:54.278378 2026] [security2:error] [pid 514479:tid 514730] [client 114.198.138.124:49652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9c4vzqsQqnLoCgUjiJ2wAAAX4"]
[Tue Jul 21 08:49:54.278541 2026] [security2:error] [pid 514479:tid 514730] [client 114.198.138.124:49652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9c4vzqsQqnLoCgUjiJ2wAAAX4"]
[Tue Jul 21 08:49:54.424329 2026] [security2:error] [pid 514479:tid 514694] [client 20.104.96.117:3992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/32e17094cfindex.php"] [unique_id "al9c4vzqsQqnLoCgUjiJ3QAAAVo"]
[Tue Jul 21 08:49:54.457271 2026] [security2:error] [pid 514479:tid 514575] [remote 116.179.37.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9c4vzqsQqnLoCgUjiJ3AABgVo"], referer: https://androapkmod.com/grand-criminal-online/
[Tue Jul 21 08:49:54.534489 2026] [security2:error] [pid 514479:tid 514663] [client 20.104.96.117:59707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/popo.php"] [unique_id "al9c4vzqsQqnLoCgUjiJ4AAAATs"]
[Tue Jul 21 08:49:54.590489 2026] [proxy:error] [pid 514479:tid 514737] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:54.590572 2026] [proxy_http:error] [pid 514479:tid 514737] [client 198.235.24.134:62202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:54.591201 2026] [proxy:error] [pid 514479:tid 514737] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:49:54.591236 2026] [proxy_http:error] [pid 514479:tid 514737] [client 198.235.24.134:62202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:49:54.639131 2026] [security2:error] [pid 514479:tid 514675] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9c4vzqsQqnLoCgUjiJ5AAAAUc"]
[Tue Jul 21 08:49:54.855117 2026] [security2:error] [pid 514479:tid 514729] [client 59.95.197.55:53032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c4vzqsQqnLoCgUjiJ5gAAAX0"]
[Tue Jul 21 08:49:54.855930 2026] [security2:error] [pid 514479:tid 514729] [client 59.95.197.55:53032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c4vzqsQqnLoCgUjiJ5gAAAX0"]
[Tue Jul 21 08:49:54.954589 2026] [security2:error] [pid 511108:tid 511290] [client 20.197.192.193:38239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/edit.php"] [unique_id "al9c4oTd5soprXwxAH0jVAAAADQ"]
[Tue Jul 21 08:49:55.024549 2026] [security2:error] [pid 514479:tid 514621] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.viniciusdealmeidacos1782118134490.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9c4_zqsQqnLoCgUjiJ5wAAARE"]
[Tue Jul 21 08:49:55.144096 2026] [security2:error] [pid 511108:tid 511251] [client 20.226.60.151:57566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/19.php"] [unique_id "al9c44Td5soprXwxAH0jWgAAAA0"]
[Tue Jul 21 08:49:55.149420 2026] [security2:error] [pid 511108:tid 511312] [client 122.176.100.127:54707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9c44Td5soprXwxAH0jWwAAAEo"]
[Tue Jul 21 08:49:55.149560 2026] [security2:error] [pid 511108:tid 511312] [client 122.176.100.127:54707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9c44Td5soprXwxAH0jWwAAAEo"]
[Tue Jul 21 08:49:55.254103 2026] [security2:error] [pid 514479:tid 514732] [client 20.151.10.161:62336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/class-wp.php"] [unique_id "al9c4_zqsQqnLoCgUjiJ6QAAAYA"]
[Tue Jul 21 08:49:55.336304 2026] [security2:error] [pid 514479:tid 514715] [client 212.32.76.13:35929] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/freeform/"] [unique_id "al9c4_zqsQqnLoCgUjiJ6wAAAW8"]
[Tue Jul 21 08:49:55.371572 2026] [security2:error] [pid 514479:tid 514620] [client 203.25.124.209:23343] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/js_composer/include/classes/vendors/plugins/api.php"] [unique_id "al9c4_zqsQqnLoCgUjiJ7QAAARA"]
[Tue Jul 21 08:49:55.932150 2026] [security2:error] [pid 511108:tid 511247] [client 20.151.10.161:8390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/admin.php"] [unique_id "al9c44Td5soprXwxAH0jbQAAAAk"]
[Tue Jul 21 08:49:56.042180 2026] [security2:error] [pid 511108:tid 511279] [client 203.25.124.37:39275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/maintenance/"] [unique_id "al9c5ITd5soprXwxAH0jbgAAACk"]
[Tue Jul 21 08:49:56.055956 2026] [security2:error] [pid 514479:tid 514627] [client 5.38.115.39:52188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9c5PzqsQqnLoCgUjiJ_AAAARc"]
[Tue Jul 21 08:49:56.060122 2026] [security2:error] [pid 514479:tid 514627] [client 5.38.115.39:52188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9c5PzqsQqnLoCgUjiJ_AAAARc"]
[Tue Jul 21 08:49:56.323567 2026] [security2:error] [pid 514479:tid 514724] [client 20.104.96.117:4081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/qqqa.php"] [unique_id "al9c5PzqsQqnLoCgUjiJ_wAAAXg"]
[Tue Jul 21 08:49:56.450883 2026] [security2:error] [pid 514479:tid 514502] [remote 38.54.76.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.76.54.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9c5PzqsQqnLoCgUjiKAQABHRI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:49:56.463461 2026] [security2:error] [pid 511108:tid 511224] [remote 38.54.76.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.76.54.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9c5ITd5soprXwxAH0jeQAAD3M"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:49:56.470540 2026] [security2:error] [pid 514479:tid 514661] [client 203.25.124.192:25805] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/stockholm/woocommerce/single-product/add-to-cart/internal.php"] [unique_id "al9c5PzqsQqnLoCgUjiKAgAAATk"]
[Tue Jul 21 08:49:56.502141 2026] [security2:error] [pid 514479:tid 514536] [remote 38.54.76.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.76.54.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9c5PzqsQqnLoCgUjiKAwABSDQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:49:56.573513 2026] [security2:error] [pid 511108:tid 511320] [client 203.25.124.74:34877] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/xml.php"] [unique_id "al9c5ITd5soprXwxAH0jegAAAFI"]
[Tue Jul 21 08:49:56.735997 2026] [security2:error] [pid 514479:tid 514731] [client 20.197.192.193:38237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/kua.php"] [unique_id "al9c5PzqsQqnLoCgUjiKBwAAAX8"]
[Tue Jul 21 08:49:56.743303 2026] [security2:error] [pid 511108:tid 511178] [remote 38.54.76.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.76.54.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9c5ITd5soprXwxAH0jggAAOkU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:49:56.750706 2026] [security2:error] [pid 511108:tid 511361] [client 20.151.10.161:62441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/aa2.php"] [unique_id "al9c5ITd5soprXwxAH0jgwAAAHs"]
[Tue Jul 21 08:49:56.761065 2026] [security2:error] [pid 514479:tid 514727] [client 20.226.60.151:57618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/inc.php"] [unique_id "al9c5PzqsQqnLoCgUjiKCAAAAXs"]
[Tue Jul 21 08:49:56.792196 2026] [security2:error] [pid 514479:tid 514501] [remote 38.54.76.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.76.54.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9c5PzqsQqnLoCgUjiKCQABgBE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:49:56.797901 2026] [security2:error] [pid 511108:tid 511231] [remote 38.54.76.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.76.54.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9c5ITd5soprXwxAH0jhAAAV3o"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:49:57.037047 2026] [security2:error] [pid 511108:tid 511290] [client 20.104.96.117:61122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/yas.php"] [unique_id "al9c5YTd5soprXwxAH0jhwAAADQ"]
[Tue Jul 21 08:49:57.119314 2026] [security2:error] [pid 514479:tid 514525] [remote 38.54.76.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.76.54.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9c5fzqsQqnLoCgUjiKDwABGyk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:49:57.139125 2026] [security2:error] [pid 514479:tid 514648] [client 20.197.192.193:38224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/ez.php"] [unique_id "al9c5fzqsQqnLoCgUjiKEAAAASw"]
[Tue Jul 21 08:49:57.171456 2026] [security2:error] [pid 511108:tid 511180] [remote 38.54.76.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.76.54.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9c5YTd5soprXwxAH0jiQAAZUc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:49:57.199827 2026] [security2:error] [pid 514479:tid 514576] [remote 38.54.76.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.76.54.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9c5fzqsQqnLoCgUjiKFAABI1s"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:49:57.337853 2026] [security2:error] [pid 514479:tid 514686] [client 65.21.113.253:42650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9c5fzqsQqnLoCgUjiKGQAAAVI"]
[Tue Jul 21 08:49:57.385524 2026] [security2:error] [pid 511108:tid 511243] [client 20.151.10.161:8432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/ccou.php"] [unique_id "al9c5YTd5soprXwxAH0jjgAAAAU"]
[Tue Jul 21 08:49:57.391459 2026] [security2:error] [pid 511108:tid 511255] [client 103.59.206.240:31307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c5YTd5soprXwxAH0jjwAAABE"]
[Tue Jul 21 08:49:57.391558 2026] [security2:error] [pid 511108:tid 511255] [client 103.59.206.240:31307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c5YTd5soprXwxAH0jjwAAABE"]
[Tue Jul 21 08:49:57.454236 2026] [security2:error] [pid 514479:tid 514515] [remote 38.54.76.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.76.54.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9c5fzqsQqnLoCgUjiKGwABax8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:49:57.464742 2026] [security2:error] [pid 511108:tid 511125] [remote 38.54.76.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.76.54.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9c5YTd5soprXwxAH0jkgAAPRA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:49:57.471181 2026] [security2:error] [pid 511108:tid 511263] [client 212.32.76.56:30877] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/post-template/index.php"] [unique_id "al9c5YTd5soprXwxAH0jkwAAABk"]
[Tue Jul 21 08:49:57.500338 2026] [security2:error] [pid 511108:tid 511284] [client 173.252.95.29:34878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9c5YTd5soprXwxAH0jlAAAAC4"]
[Tue Jul 21 08:49:57.517715 2026] [security2:error] [pid 514479:tid 514718] [client 195.49.128.211:59078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9c5fzqsQqnLoCgUjiKGgAAAXI"]
[Tue Jul 21 08:49:57.517834 2026] [security2:error] [pid 514479:tid 514718] [client 195.49.128.211:59078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9c5fzqsQqnLoCgUjiKGgAAAXI"]
[Tue Jul 21 08:49:57.536838 2026] [security2:error] [pid 511108:tid 511218] [remote 38.54.76.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.76.54.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9c5YTd5soprXwxAH0jlQAAO20"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:49:57.540690 2026] [security2:error] [pid 511108:tid 511334] [client 212.32.76.14:25893] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/module.php"] [unique_id "al9c5YTd5soprXwxAH0jlgAAAGA"]
[Tue Jul 21 08:49:57.557759 2026] [security2:error] [pid 514479:tid 514496] [remote 38.54.76.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.76.54.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9c5fzqsQqnLoCgUjiKHQABCww"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:49:57.600465 2026] [security2:error] [pid 514479:tid 514740] [client 20.220.225.223:35086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/edit.php"] [unique_id "al9c5fzqsQqnLoCgUjiKHgAAAYg"]
[Tue Jul 21 08:49:57.651890 2026] [security2:error] [pid 511108:tid 511352] [client 20.197.192.193:38226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/fz.php"] [unique_id "al9c5YTd5soprXwxAH0jmAAAAHI"]
[Tue Jul 21 08:49:57.725226 2026] [security2:error] [pid 514479:tid 514728] [client 20.226.60.151:57660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9c5fzqsQqnLoCgUjiKHwAAAXw"]
[Tue Jul 21 08:49:57.784798 2026] [security2:error] [pid 514479:tid 514527] [remote 38.54.76.172:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.76.54.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9c5fzqsQqnLoCgUjiKIAABgSs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:49:57.992533 2026] [security2:error] [pid 514479:tid 514668] [client 20.151.10.161:8339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/dr.php"] [unique_id "al9c5fzqsQqnLoCgUjiKJAAAAUA"]
[Tue Jul 21 08:49:58.193351 2026] [security2:error] [pid 514479:tid 514703] [client 41.89.234.2:47293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c5vzqsQqnLoCgUjiKJQAAAWM"]
[Tue Jul 21 08:49:58.193646 2026] [security2:error] [pid 514479:tid 514703] [client 41.89.234.2:47293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c5vzqsQqnLoCgUjiKJQAAAWM"]
[Tue Jul 21 08:49:58.363291 2026] [security2:error] [pid 511108:tid 511298] [client 203.25.124.70:55169] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-conflg/function.php"] [unique_id "al9c5oTd5soprXwxAH0jpwAAADw"]
[Tue Jul 21 08:49:58.370727 2026] [security2:error] [pid 511108:tid 511323] [client 64.42.179.43:53448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9c5oTd5soprXwxAH0jqQAAAFU"]
[Tue Jul 21 08:49:58.370846 2026] [security2:error] [pid 511108:tid 511323] [client 64.42.179.43:53448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9c5oTd5soprXwxAH0jqQAAAFU"]
[Tue Jul 21 08:49:58.438945 2026] [security2:error] [pid 511108:tid 511357] [client 65.21.113.253:54762] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9c5oTd5soprXwxAH0joAAAAHc"]
[Tue Jul 21 08:49:58.480663 2026] [security2:error] [pid 514479:tid 514721] [client 20.226.60.151:59735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9c5vzqsQqnLoCgUjiKKQAAAXU"]
[Tue Jul 21 08:49:58.577498 2026] [security2:error] [pid 514479:tid 514705] [client 203.25.124.206:65525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/images/index.php"] [unique_id "al9c5vzqsQqnLoCgUjiKKwAAAWU"]
[Tue Jul 21 08:49:58.691601 2026] [security2:error] [pid 511108:tid 511260] [client 51.68.236.72:11113] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acheservicos.com.br"] [uri "/robots.txt"] [unique_id "al9c5oTd5soprXwxAH0jrQAAABY"]
[Tue Jul 21 08:49:58.691698 2026] [security2:error] [pid 511108:tid 511260] [client 51.68.236.72:11113] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "acheservicos.com.br"] [uri "/robots.txt"] [unique_id "al9c5oTd5soprXwxAH0jrQAAABY"]
[Tue Jul 21 08:49:58.920099 2026] [security2:error] [pid 514479:tid 514648] [client 20.197.192.193:22359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/la.php"] [unique_id "al9c5vzqsQqnLoCgUjiKMAAAASw"]
[Tue Jul 21 08:49:58.930424 2026] [security2:error] [pid 514479:tid 514722] [client 203.25.124.37:48943] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Requests/chosen.php"] [unique_id "al9c5vzqsQqnLoCgUjiKMQAAAXY"]
[Tue Jul 21 08:49:59.056160 2026] [security2:error] [pid 511108:tid 511226] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9c54Td5soprXwxAH0juQAAV3U"]
[Tue Jul 21 08:49:59.056380 2026] [security2:error] [pid 511108:tid 511325] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9c54Td5soprXwxAH0juQAAV3U"]
[Tue Jul 21 08:49:59.166422 2026] [security2:error] [pid 514479:tid 514696] [client 20.104.96.117:46777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/aunmc.php"] [unique_id "al9c5_zqsQqnLoCgUjiKNwAAAVw"]
[Tue Jul 21 08:49:59.304031 2026] [security2:error] [pid 514479:tid 514730] [client 20.151.10.161:8412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/xamp.php"] [unique_id "al9c5_zqsQqnLoCgUjiKPQAAAX4"]
[Tue Jul 21 08:49:59.314531 2026] [security2:error] [pid 514479:tid 514740] [client 20.197.192.193:50567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9c5_zqsQqnLoCgUjiKPwAAAYg"]
[Tue Jul 21 08:49:59.473439 2026] [security2:error] [pid 514479:tid 514695] [client 212.32.76.6:50949] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/network_xo.php"] [unique_id "al9c5_zqsQqnLoCgUjiKQgAAAVs"]
[Tue Jul 21 08:49:59.995864 2026] [security2:error] [pid 511108:tid 511365] [client 20.197.192.193:38245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9c54Td5soprXwxAH0jygAAAH8"]
[Tue Jul 21 08:50:00.041757 2026] [security2:error] [pid 514479:tid 514732] [client 212.32.76.12:42769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/admin.php"] [unique_id "al9c6PzqsQqnLoCgUjiKUwAAAYA"]
[Tue Jul 21 08:50:00.141488 2026] [security2:error] [pid 511108:tid 511266] [client 20.226.60.151:57557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ss.php"] [unique_id "al9c6ITd5soprXwxAH0jzgAAABw"]
[Tue Jul 21 08:50:00.169234 2026] [security2:error] [pid 511108:tid 511292] [client 203.25.124.36:60437] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/sitemaps/"] [unique_id "al9c6ITd5soprXwxAH0jzwAAADY"]
[Tue Jul 21 08:50:00.171080 2026] [security2:error] [pid 511108:tid 511247] [client 203.25.124.182:57377] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/css/dist/block-directory/index.php"] [unique_id "al9c6ITd5soprXwxAH0j0AAAAAk"]
[Tue Jul 21 08:50:00.341403 2026] [security2:error] [pid 514479:tid 514675] [client 113.22.144.139:53673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c6PzqsQqnLoCgUjiKVgAAAUc"]
[Tue Jul 21 08:50:00.341582 2026] [security2:error] [pid 514479:tid 514675] [client 113.22.144.139:53673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c6PzqsQqnLoCgUjiKVgAAAUc"]
[Tue Jul 21 08:50:00.381714 2026] [security2:error] [pid 514479:tid 514688] [client 74.7.241.139:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.protagonjoinville.produtoswendellcarvalho.com"] [uri "/index.php"] [unique_id "al9c5_zqsQqnLoCgUjiKRwAAAVQ"]
[Tue Jul 21 08:50:00.385417 2026] [security2:error] [pid 514479:tid 514498] [remote 74.7.241.139:38610] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.protagonjoinville.produtoswendellcarvalho.com"] [uri "/robots.txt"] [unique_id "al9c5_zqsQqnLoCgUjiKRQABGQ4"]
[Tue Jul 21 08:50:00.497237 2026] [security2:error] [pid 511108:tid 511198] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9c6ITd5soprXwxAH0j1wAAc1k"]
[Tue Jul 21 08:50:00.497404 2026] [security2:error] [pid 511108:tid 511353] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9c6ITd5soprXwxAH0j1wAAc1k"]
[Tue Jul 21 08:50:00.555183 2026] [security2:error] [pid 511108:tid 511128] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c6ITd5soprXwxAH0j2AAAKhM"]
[Tue Jul 21 08:50:00.555388 2026] [security2:error] [pid 511108:tid 511280] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c6ITd5soprXwxAH0j2AAAKhM"]
[Tue Jul 21 08:50:00.764456 2026] [security2:error] [pid 514479:tid 514695] [client 20.104.96.117:61072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/file61.php"] [unique_id "al9c6PzqsQqnLoCgUjiKXgAAAVs"]
[Tue Jul 21 08:50:00.772370 2026] [security2:error] [pid 511108:tid 511253] [client 20.197.192.193:38227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/inso.php"] [unique_id "al9c6ITd5soprXwxAH0j2gAAAA8"]
[Tue Jul 21 08:50:00.985157 2026] [security2:error] [pid 511108:tid 511276] [client 74.7.244.56:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "protagonjoinville.produtoswendellcarvalho.com"] [uri "/index.php"] [unique_id "al9c6ITd5soprXwxAH0j4QAAACY"]
[Tue Jul 21 08:50:00.986487 2026] [security2:error] [pid 511108:tid 511335] [client 74.7.244.56:50790] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "protagonjoinville.produtoswendellcarvalho.com"] [uri "/robots.txt"] [unique_id "al9c6ITd5soprXwxAH0j4AAAYUg"]
[Tue Jul 21 08:50:01.044698 2026] [security2:error] [pid 511108:tid 511325] [client 74.7.241.139:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "protagonjoinville.produtoswendellcarvalho.com"] [uri "/index.php"] [unique_id "al9c6ITd5soprXwxAH0j5gAAAFc"], referer: https://www.protagonjoinville.produtoswendellcarvalho.com/robots.txt
[Tue Jul 21 08:50:01.045409 2026] [security2:error] [pid 511108:tid 511290] [client 74.7.241.139:38624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "protagonjoinville.produtoswendellcarvalho.com"] [uri "/robots.txt"] [unique_id "al9c6ITd5soprXwxAH0j5AAANEA"], referer: https://www.protagonjoinville.produtoswendellcarvalho.com/robots.txt
[Tue Jul 21 08:50:01.144685 2026] [security2:error] [pid 514479:tid 514727] [client 203.25.124.66:49229] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/block-patterns/chosen.php"] [unique_id "al9c6fzqsQqnLoCgUjiKZQAAAXs"]
[Tue Jul 21 08:50:01.176870 2026] [security2:error] [pid 511108:tid 511282] [client 212.32.76.63:33855] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/assets/about.php"] [unique_id "al9c6YTd5soprXwxAH0j6wAAACw"]
[Tue Jul 21 08:50:01.212192 2026] [security2:error] [pid 514479:tid 514614] [client 182.189.99.211:48352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c6fzqsQqnLoCgUjiKaAAAAQo"]
[Tue Jul 21 08:50:01.212308 2026] [security2:error] [pid 514479:tid 514614] [client 182.189.99.211:48352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c6fzqsQqnLoCgUjiKaAAAAQo"]
[Tue Jul 21 08:50:01.463597 2026] [security2:error] [pid 514479:tid 514717] [client 212.32.76.10:23527] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/pomo/index.php"] [unique_id "al9c6fzqsQqnLoCgUjiKawAAAXE"]
[Tue Jul 21 08:50:01.520956 2026] [security2:error] [pid 514479:tid 514696] [client 5.31.193.106:58574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9c6fzqsQqnLoCgUjiKbAAAAVw"]
[Tue Jul 21 08:50:01.521146 2026] [security2:error] [pid 514479:tid 514696] [client 5.31.193.106:58574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9c6fzqsQqnLoCgUjiKbAAAAVw"]
[Tue Jul 21 08:50:01.617233 2026] [security2:error] [pid 514479:tid 514673] [client 20.220.225.223:34877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/kua.php"] [unique_id "al9c6fzqsQqnLoCgUjiKbwAAAUU"]
[Tue Jul 21 08:50:01.711132 2026] [security2:error] [pid 511108:tid 511258] [client 20.197.192.193:56777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9c6YTd5soprXwxAH0j_gAAABQ"]
[Tue Jul 21 08:50:01.735851 2026] [security2:error] [pid 514479:tid 514737] [client 168.167.81.163:61483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9c6fzqsQqnLoCgUjiKcQAAAYU"]
[Tue Jul 21 08:50:01.736035 2026] [security2:error] [pid 514479:tid 514737] [client 168.167.81.163:61483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9c6fzqsQqnLoCgUjiKcQAAAYU"]
[Tue Jul 21 08:50:01.775168 2026] [security2:error] [pid 514479:tid 514590] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c6fzqsQqnLoCgUjiKcgABVGk"]
[Tue Jul 21 08:50:01.775330 2026] [security2:error] [pid 514479:tid 514688] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c6fzqsQqnLoCgUjiKcgABVGk"]
[Tue Jul 21 08:50:01.974090 2026] [security2:error] [pid 511108:tid 511251] [client 203.25.124.202:47343] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "al9c6YTd5soprXwxAH0kBAAAAA0"]
[Tue Jul 21 08:50:02.112568 2026] [security2:error] [pid 514479:tid 514597] [remote 20.84.23.222:6431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.23.84.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compressoresra.com.br"] [uri "/wp-login.php"] [unique_id "al9c6vzqsQqnLoCgUjiKdwABUnA"]
[Tue Jul 21 08:50:02.146663 2026] [security2:error] [pid 514479:tid 514653] [client 203.25.124.55:51723] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/ws.php"] [unique_id "al9c6vzqsQqnLoCgUjiKfAAAATE"]
[Tue Jul 21 08:50:02.206934 2026] [security2:error] [pid 514479:tid 514703] [client 65.21.113.253:42650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9c6vzqsQqnLoCgUjiKfwAAAWM"]
[Tue Jul 21 08:50:02.207391 2026] [security2:error] [pid 511108:tid 511142] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9c6oTd5soprXwxAH0kDAAAUyE"]
[Tue Jul 21 08:50:02.207538 2026] [security2:error] [pid 511108:tid 511321] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9c6oTd5soprXwxAH0kDAAAUyE"]
[Tue Jul 21 08:50:02.342281 2026] [security2:error] [pid 511108:tid 511287] [client 20.226.60.151:59725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/min.php"] [unique_id "al9c6oTd5soprXwxAH0kDQAAADE"]
[Tue Jul 21 08:50:02.462577 2026] [security2:error] [pid 511108:tid 511283] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9c6oTd5soprXwxAH0kDwAALUQ"]
[Tue Jul 21 08:50:02.662188 2026] [security2:error] [pid 514479:tid 514652] [client 212.32.76.14:27169] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/plugins/revslider/includes/external/page/"] [unique_id "al9c6vzqsQqnLoCgUjiKiAAAATA"]
[Tue Jul 21 08:50:02.838984 2026] [security2:error] [pid 511108:tid 511316] [client 20.104.96.117:46730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/uoocf.php"] [unique_id "al9c6oTd5soprXwxAH0kHQAAAE4"]
[Tue Jul 21 08:50:02.951030 2026] [security2:error] [pid 514479:tid 514668] [client 20.197.192.193:8339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/hunter.php"] [unique_id "al9c6vzqsQqnLoCgUjiKiwAAAUA"]
[Tue Jul 21 08:50:03.070206 2026] [security2:error] [pid 511108:tid 511278] [client 203.25.124.209:20435] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9c64Td5soprXwxAH0kJQAAACg"]
[Tue Jul 21 08:50:03.108895 2026] [security2:error] [pid 514479:tid 514725] [client 20.197.192.193:38212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/wpx.php"] [unique_id "al9c6_zqsQqnLoCgUjiKkQAAAXk"]
[Tue Jul 21 08:50:03.135455 2026] [security2:error] [pid 514479:tid 514717] [client 114.119.158.125:52463] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "brwmarcas.com.br"] [uri "/atomlib.php"] [unique_id "al9c6_zqsQqnLoCgUjiKkgAAAXE"], referer: https://brwmarcas.com.br/atomlib.php?s/C449736
[Tue Jul 21 08:50:03.217902 2026] [security2:error] [pid 514479:tid 514711] [client 185.8.106.219:55860] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "wilkermoronicriminalista.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9c6_zqsQqnLoCgUjiKlAAAAWs"]
[Tue Jul 21 08:50:03.222592 2026] [security2:error] [pid 514479:tid 514730] [client 20.220.225.223:37631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/ez.php"] [unique_id "al9c6_zqsQqnLoCgUjiKlQAAAX4"]
[Tue Jul 21 08:50:03.361270 2026] [security2:error] [pid 511108:tid 511328] [client 20.197.192.193:22351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/berlin.php"] [unique_id "al9c64Td5soprXwxAH0kKgAAAFo"]
[Tue Jul 21 08:50:03.364768 2026] [security2:error] [pid 514479:tid 514620] [client 65.21.113.253:53784] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9c6vzqsQqnLoCgUjiKigAAARA"]
[Tue Jul 21 08:50:03.378212 2026] [security2:error] [pid 514479:tid 514491] [remote 41.186.86.12:59433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9c6_zqsQqnLoCgUjiKmQABGgc"]
[Tue Jul 21 08:50:03.562770 2026] [security2:error] [pid 514479:tid 514614] [client 20.226.60.151:59721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9c6_zqsQqnLoCgUjiKnAAAAQo"]
[Tue Jul 21 08:50:03.646458 2026] [security2:error] [pid 514479:tid 514656] [client 203.25.124.41:62123] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/tinymce/plugins/wp-load.php"] [unique_id "al9c6_zqsQqnLoCgUjiKnQAAATQ"]
[Tue Jul 21 08:50:03.769798 2026] [security2:error] [pid 511108:tid 511314] [client 203.25.124.53:35821] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "al9c64Td5soprXwxAH0kMgAAAEw"]
[Tue Jul 21 08:50:03.879658 2026] [security2:error] [pid 514479:tid 514625] [client 20.197.192.193:38269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/billur.php"] [unique_id "al9c6_zqsQqnLoCgUjiKnwAAARU"]
[Tue Jul 21 08:50:03.933134 2026] [security2:error] [pid 511108:tid 511283] [client 185.8.106.219:39848] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "wilkermoronicriminalista.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9c64Td5soprXwxAH0kNgAAAC0"]
[Tue Jul 21 08:50:03.978097 2026] [security2:error] [pid 511108:tid 511267] [client 212.32.76.66:61653] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "al9c64Td5soprXwxAH0kOAAAAB0"]
[Tue Jul 21 08:50:04.356252 2026] [security2:error] [pid 511108:tid 511339] [client 20.197.192.193:38264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/mimpi.php"] [unique_id "al9c7ITd5soprXwxAH0kQAAAAGU"]
[Tue Jul 21 08:50:04.449967 2026] [security2:error] [pid 514479:tid 514649] [client 20.104.96.117:46781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/iywwi.php"] [unique_id "al9c7PzqsQqnLoCgUjiKpwAAAS0"]
[Tue Jul 21 08:50:04.464416 2026] [security2:error] [pid 511108:tid 511275] [client 203.25.124.31:56349] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/nrhogjyecktixbal0fnt5Cakc.php"] [unique_id "al9c7ITd5soprXwxAH0kQgAAACU"]
[Tue Jul 21 08:50:04.704653 2026] [security2:error] [pid 511108:tid 511299] [client 20.226.60.151:57604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9c7ITd5soprXwxAH0kRgAAAD0"]
[Tue Jul 21 08:50:04.755549 2026] [security2:error] [pid 514479:tid 514621] [client 20.220.225.223:35082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/fz.php"] [unique_id "al9c7PzqsQqnLoCgUjiKrgAAARE"]
[Tue Jul 21 08:50:04.864986 2026] [security2:error] [pid 511108:tid 511300] [client 20.151.10.161:62394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/bless.php"] [unique_id "al9c7ITd5soprXwxAH0kSQAAAD4"]
[Tue Jul 21 08:50:04.900179 2026] [security2:error] [pid 514479:tid 514646] [client 49.144.66.253:31524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9c7PzqsQqnLoCgUjiKsAAAASo"]
[Tue Jul 21 08:50:04.900319 2026] [security2:error] [pid 514479:tid 514646] [client 49.144.66.253:31524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9c7PzqsQqnLoCgUjiKsAAAASo"]
[Tue Jul 21 08:50:05.035752 2026] [security2:error] [pid 511108:tid 511304] [client 203.25.124.64:38883] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/jcrop/Jcrop.php"] [unique_id "al9c7YTd5soprXwxAH0kTwAAAEI"]
[Tue Jul 21 08:50:05.080380 2026] [security2:error] [pid 514479:tid 514615] [client 185.8.106.219:55870] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.wilkermoronicriminalista.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9c7fzqsQqnLoCgUjiKsgAAAQs"]
[Tue Jul 21 08:50:05.172364 2026] [security2:error] [pid 511108:tid 511327] [client 20.104.96.117:3997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/gqgsa.php"] [unique_id "al9c7YTd5soprXwxAH0kUQAAAFk"]
[Tue Jul 21 08:50:05.177388 2026] [security2:error] [pid 514479:tid 514741] [client 212.32.76.59:30539] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/wp-conflg.php"] [unique_id "al9c7fzqsQqnLoCgUjiKswAAAYk"]
[Tue Jul 21 08:50:05.305554 2026] [security2:error] [pid 511108:tid 511251] [client 20.197.192.193:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/wander.php"] [unique_id "al9c7YTd5soprXwxAH0kUwAAAA0"]
[Tue Jul 21 08:50:05.325386 2026] [security2:error] [pid 514479:tid 514722] [client 59.95.197.55:53508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c7fzqsQqnLoCgUjiKtwAAAXY"]
[Tue Jul 21 08:50:05.329084 2026] [security2:error] [pid 514479:tid 514722] [client 59.95.197.55:53508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c7fzqsQqnLoCgUjiKtwAAAXY"]
[Tue Jul 21 08:50:05.566808 2026] [security2:error] [pid 514479:tid 514657] [client 203.25.124.70:41917] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-trackback.php"] [unique_id "al9c7fzqsQqnLoCgUjiKugAAATU"]
[Tue Jul 21 08:50:05.604923 2026] [security2:error] [pid 514479:tid 514668] [client 114.198.138.124:50244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9c7fzqsQqnLoCgUjiKvAAAAUA"]
[Tue Jul 21 08:50:05.605028 2026] [security2:error] [pid 514479:tid 514668] [client 114.198.138.124:50244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9c7fzqsQqnLoCgUjiKvAAAAUA"]
[Tue Jul 21 08:50:05.607104 2026] [security2:error] [pid 511108:tid 511256] [client 122.176.100.127:55215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9c7YTd5soprXwxAH0kWgAAABI"]
[Tue Jul 21 08:50:05.607193 2026] [security2:error] [pid 511108:tid 511256] [client 122.176.100.127:55215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9c7YTd5soprXwxAH0kWgAAABI"]
[Tue Jul 21 08:50:05.675304 2026] [security2:error] [pid 514479:tid 514614] [client 20.151.10.161:8403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/file46.php"] [unique_id "al9c7fzqsQqnLoCgUjiKvgAAAQo"]
[Tue Jul 21 08:50:05.837125 2026] [security2:error] [pid 514479:tid 514675] [client 20.226.60.151:57570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9c7fzqsQqnLoCgUjiKwQAAAUc"]
[Tue Jul 21 08:50:06.046202 2026] [security2:error] [pid 514479:tid 514629] [client 212.32.76.6:43101] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/simple.php"] [unique_id "al9c7vzqsQqnLoCgUjiKxAAAARk"]
[Tue Jul 21 08:50:06.236231 2026] [security2:error] [pid 514479:tid 514731] [client 185.8.106.219:55880] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "wilkermoronicriminalista.com"] [uri "/"] [unique_id "al9c7vzqsQqnLoCgUjiKxgAAAX8"]
[Tue Jul 21 08:50:06.475739 2026] [security2:error] [pid 511108:tid 511261] [client 203.25.124.209:43313] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/function/function.php"] [unique_id "al9c7oTd5soprXwxAH0kagAAABc"]
[Tue Jul 21 08:50:06.483111 2026] [security2:error] [pid 511108:tid 511318] [client 195.206.105.227:35492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9c7oTd5soprXwxAH0kawAAAFA"]
[Tue Jul 21 08:50:06.483193 2026] [security2:error] [pid 511108:tid 511318] [client 195.206.105.227:35492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9c7oTd5soprXwxAH0kawAAAFA"]
[Tue Jul 21 08:50:06.669909 2026] [security2:error] [pid 511108:tid 511263] [client 203.25.124.73:36977] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/ty.php"] [unique_id "al9c7oTd5soprXwxAH0kdAAAABk"]
[Tue Jul 21 08:50:06.804805 2026] [security2:error] [pid 514479:tid 514728] [client 5.38.115.39:52717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9c7vzqsQqnLoCgUjiKywAAAXw"]
[Tue Jul 21 08:50:06.804948 2026] [security2:error] [pid 514479:tid 514728] [client 5.38.115.39:52717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9c7vzqsQqnLoCgUjiKywAAAXw"]
[Tue Jul 21 08:50:07.006567 2026] [security2:error] [pid 511108:tid 511309] [client 45.227.253.15:38354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.253.227.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "juridic.bavos.com.br"] [uri "/index.php/jk"] [unique_id "al9c7oTd5soprXwxAH0keQAAAEc"]
[Tue Jul 21 08:50:07.035133 2026] [security2:error] [pid 514479:tid 514715] [client 203.25.124.35:60729] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/link/"] [unique_id "al9c7_zqsQqnLoCgUjiK0AAAAW8"]
[Tue Jul 21 08:50:07.048367 2026] [security2:error] [pid 511108:tid 511353] [client 81.171.74.60:45418] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/"] [unique_id "al9c74Td5soprXwxAH0kfQAAAHM"]
[Tue Jul 21 08:50:07.048704 2026] [security2:error] [pid 514479:tid 514616] [client 81.171.74.60:45420] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/"] [unique_id "al9c7_zqsQqnLoCgUjiK0QAAAQw"]
[Tue Jul 21 08:50:07.052803 2026] [security2:error] [pid 511108:tid 511334] [client 81.171.74.60:45442] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/"] [unique_id "al9c74Td5soprXwxAH0kfgAAAGA"]
[Tue Jul 21 08:50:07.114560 2026] [security2:error] [pid 511108:tid 511298] [client 20.104.96.117:4044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/elbzl.php"] [unique_id "al9c74Td5soprXwxAH0kgAAAADw"]
[Tue Jul 21 08:50:07.560004 2026] [security2:error] [pid 511108:tid 511335] [client 20.197.192.193:9426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/we.php"] [unique_id "al9c74Td5soprXwxAH0kiwAAAGE"]
[Tue Jul 21 08:50:07.569837 2026] [security2:error] [pid 514479:tid 514684] [client 20.151.10.161:62427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/eee.php"] [unique_id "al9c7_zqsQqnLoCgUjiK2QAAAVA"]
[Tue Jul 21 08:50:07.602405 2026] [security2:error] [pid 511108:tid 511238] [client 20.197.192.193:38238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/dp.php"] [unique_id "al9c74Td5soprXwxAH0kjwAAAAA"]
[Tue Jul 21 08:50:07.657579 2026] [security2:error] [pid 514479:tid 514663] [client 200.110.59.238:65378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.59.110.200.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kvengenharia.com"] [uri "/xmlrpc.php"] [unique_id "al9c7_zqsQqnLoCgUjiK2AAAATs"]
[Tue Jul 21 08:50:07.657687 2026] [security2:error] [pid 514479:tid 514663] [client 200.110.59.238:65378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kvengenharia.com"] [uri "/xmlrpc.php"] [unique_id "al9c7_zqsQqnLoCgUjiK2AAAATs"]
[Tue Jul 21 08:50:07.708245 2026] [core:alert] [pid 511108:tid 511296] [client 57.141.18.84:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:50:07.736871 2026] [security2:error] [pid 511108:tid 511324] [client 203.25.124.213:56937] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/config.php"] [unique_id "al9c74Td5soprXwxAH0klAAAAFY"]
[Tue Jul 21 08:50:07.762357 2026] [security2:error] [pid 514479:tid 514614] [client 212.32.76.12:61479] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/default.php"] [unique_id "al9c7_zqsQqnLoCgUjiK3QAAAQo"]
[Tue Jul 21 08:50:07.835568 2026] [security2:error] [pid 511108:tid 511263] [client 65.21.113.253:38152] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9c74Td5soprXwxAH0klQAAABk"]
[Tue Jul 21 08:50:07.887198 2026] [security2:error] [pid 511108:tid 511275] [client 20.226.60.151:57613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9c74Td5soprXwxAH0kmAAAACU"]
[Tue Jul 21 08:50:07.918917 2026] [security2:error] [pid 511108:tid 511314] [client 195.49.128.211:59693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9c74Td5soprXwxAH0kmQAAAEw"]
[Tue Jul 21 08:50:07.919051 2026] [security2:error] [pid 511108:tid 511314] [client 195.49.128.211:59693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9c74Td5soprXwxAH0kmQAAAEw"]
[Tue Jul 21 08:50:08.030138 2026] [security2:error] [pid 514479:tid 514695] [client 81.171.74.60:45452] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/backup.zip"] [unique_id "al9c8PzqsQqnLoCgUjiK4AAAAVs"]
[Tue Jul 21 08:50:08.030477 2026] [security2:error] [pid 511108:tid 511301] [client 81.171.74.60:45450] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/backup.tar.gz"] [unique_id "al9c8ITd5soprXwxAH0kmgAAAD8"]
[Tue Jul 21 08:50:08.031720 2026] [security2:error] [pid 511108:tid 511312] [client 81.171.74.60:45474] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9c8ITd5soprXwxAH0knAAAAEo"]
[Tue Jul 21 08:50:08.031773 2026] [security2:error] [pid 511108:tid 511284] [client 81.171.74.60:45480] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/database.sql"] [unique_id "al9c8ITd5soprXwxAH0kmwAAAC4"]
[Tue Jul 21 08:50:08.066495 2026] [security2:error] [pid 514479:tid 514633] [client 203.25.124.200:57239] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/index.php"] [unique_id "al9c8PzqsQqnLoCgUjiK4QAAAR0"]
[Tue Jul 21 08:50:08.147997 2026] [security2:error] [pid 514479:tid 514738] [client 20.226.60.151:57573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/albin.php"] [unique_id "al9c8PzqsQqnLoCgUjiK5AAAAYY"]
[Tue Jul 21 08:50:08.223992 2026] [security2:error] [pid 514479:tid 514731] [client 20.197.192.193:50577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/jga.php"] [unique_id "al9c8PzqsQqnLoCgUjiK5QAAAX8"]
[Tue Jul 21 08:50:08.617122 2026] [security2:error] [pid 514479:tid 514671] [client 41.89.234.2:56520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c8PzqsQqnLoCgUjiK6wAAAUM"]
[Tue Jul 21 08:50:08.617238 2026] [security2:error] [pid 514479:tid 514671] [client 41.89.234.2:56520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c8PzqsQqnLoCgUjiK6wAAAUM"]
[Tue Jul 21 08:50:08.900738 2026] [security2:error] [pid 514479:tid 514679] [client 20.197.192.193:38215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/bootstrap.php"] [unique_id "al9c8PzqsQqnLoCgUjiK7wAAAUs"]
[Tue Jul 21 08:50:08.944846 2026] [security2:error] [pid 514479:tid 514696] [client 65.21.113.253:53786] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9c8PzqsQqnLoCgUjiK6QAAAVw"]
[Tue Jul 21 08:50:08.962595 2026] [security2:error] [pid 511108:tid 511285] [client 203.25.124.55:61973] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/SimplePie/font-editor.php"] [unique_id "al9c8ITd5soprXwxAH0krQAAAC8"]
[Tue Jul 21 08:50:08.969938 2026] [security2:error] [pid 511108:tid 511303] [client 203.25.124.187:63173] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/network/upgrade/index.php"] [unique_id "al9c8ITd5soprXwxAH0krgAAAEE"]
[Tue Jul 21 08:50:09.011034 2026] [security2:error] [pid 511108:tid 511320] [client 81.171.74.60:45504] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/config.php"] [unique_id "al9c8YTd5soprXwxAH0ksAAAAFI"]
[Tue Jul 21 08:50:09.014062 2026] [security2:error] [pid 514479:tid 514717] [client 81.171.74.60:45542] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/actuator/heapdump"] [unique_id "al9c8fzqsQqnLoCgUjiK9AAAAXE"]
[Tue Jul 21 08:50:09.015875 2026] [security2:error] [pid 514479:tid 514682] [client 81.171.74.60:45522] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/dump.sql"] [unique_id "al9c8fzqsQqnLoCgUjiK9QAAAU4"]
[Tue Jul 21 08:50:09.020472 2026] [security2:error] [pid 514479:tid 514692] [client 81.171.74.60:45488] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/config.xml"] [unique_id "al9c8fzqsQqnLoCgUjiK9gAAAVg"]
[Tue Jul 21 08:50:09.035099 2026] [security2:error] [pid 511108:tid 511328] [client 203.25.124.67:58293] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/colors/midnight/"] [unique_id "al9c8YTd5soprXwxAH0ksQAAAFo"]
[Tue Jul 21 08:50:09.214608 2026] [security2:error] [pid 514479:tid 514621] [client 81.171.74.60:45492] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/backup.sql"] [unique_id "al9c8fzqsQqnLoCgUjiK_gAAARE"]
[Tue Jul 21 08:50:09.217113 2026] [security2:error] [pid 511108:tid 511256] [client 81.171.74.60:45510] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/.svn/wc.db"] [unique_id "al9c8YTd5soprXwxAH0ktAAAABI"]
[Tue Jul 21 08:50:09.218928 2026] [security2:error] [pid 514479:tid 514715] [client 81.171.74.60:45534] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/docker-compose.yml"] [unique_id "al9c8fzqsQqnLoCgUjiLAgAAAW8"]
[Tue Jul 21 08:50:09.597578 2026] [security2:error] [pid 514479:tid 514629] [client 20.197.192.193:50584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/x.php"] [unique_id "al9c8fzqsQqnLoCgUjiLCQAAARk"]
[Tue Jul 21 08:50:09.661932 2026] [security2:error] [pid 514479:tid 514552] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9c8fzqsQqnLoCgUjiLCwABK0M"]
[Tue Jul 21 08:50:09.662074 2026] [security2:error] [pid 514479:tid 514647] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9c8fzqsQqnLoCgUjiLCwABK0M"]
[Tue Jul 21 08:50:09.756428 2026] [security2:error] [pid 511108:tid 511316] [client 20.104.96.117:59149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/water.php"] [unique_id "al9c8YTd5soprXwxAH0kwwAAAE4"]
[Tue Jul 21 08:50:09.970326 2026] [security2:error] [pid 514479:tid 514731] [client 212.32.76.7:56643] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "al9c8fzqsQqnLoCgUjiLDgAAAX8"]
[Tue Jul 21 08:50:09.973945 2026] [security2:error] [pid 511108:tid 511314] [client 203.25.124.207:30571] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "al9c8YTd5soprXwxAH0kxwAAAEw"]
[Tue Jul 21 08:50:10.181655 2026] [security2:error] [pid 514479:tid 514639] [client 20.226.60.151:57658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/cilus.php"] [unique_id "al9c8vzqsQqnLoCgUjiLEQAAASM"]
[Tue Jul 21 08:50:10.241827 2026] [security2:error] [pid 514479:tid 514661] [client 203.25.124.61:33347] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/codemirror/"] [unique_id "al9c8vzqsQqnLoCgUjiLEgAAATk"]
[Tue Jul 21 08:50:10.968730 2026] [security2:error] [pid 514479:tid 514634] [client 203.25.124.42:25499] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al9c8vzqsQqnLoCgUjiLHgAAAR4"]
[Tue Jul 21 08:50:10.978751 2026] [security2:error] [pid 514479:tid 514722] [client 203.25.124.207:33637] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9c8vzqsQqnLoCgUjiLHwAAAXY"]
[Tue Jul 21 08:50:11.009252 2026] [security2:error] [pid 514479:tid 514523] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9c8_zqsQqnLoCgUjiLIAABWCc"]
[Tue Jul 21 08:50:11.009378 2026] [security2:error] [pid 514479:tid 514692] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9c8_zqsQqnLoCgUjiLIAABWCc"]
[Tue Jul 21 08:50:11.129781 2026] [security2:error] [pid 511108:tid 511284] [client 113.22.144.139:54211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c84Td5soprXwxAH0k1wAAAC4"]
[Tue Jul 21 08:50:11.129933 2026] [security2:error] [pid 511108:tid 511284] [client 113.22.144.139:54211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c84Td5soprXwxAH0k1wAAAC4"]
[Tue Jul 21 08:50:11.245033 2026] [security2:error] [pid 511108:tid 511361] [client 203.25.124.41:40275] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/ab.php"] [unique_id "al9c84Td5soprXwxAH0k2gAAAHs"]
[Tue Jul 21 08:50:11.289093 2026] [security2:error] [pid 514479:tid 514558] [remote 192.241.143.148:34928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9c8_zqsQqnLoCgUjiLJAABWUk"]
[Tue Jul 21 08:50:11.383958 2026] [security2:error] [pid 514479:tid 514604] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c8_zqsQqnLoCgUjiLJQABDnc"]
[Tue Jul 21 08:50:11.384174 2026] [security2:error] [pid 514479:tid 514618] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c8_zqsQqnLoCgUjiLJQABDnc"]
[Tue Jul 21 08:50:11.665238 2026] [security2:error] [pid 514479:tid 514684] [client 182.189.99.211:48132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c8_zqsQqnLoCgUjiLKwAAAVA"]
[Tue Jul 21 08:50:11.665366 2026] [security2:error] [pid 514479:tid 514684] [client 182.189.99.211:48132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c8_zqsQqnLoCgUjiLKwAAAVA"]
[Tue Jul 21 08:50:11.976000 2026] [security2:error] [pid 514479:tid 514661] [client 203.25.124.210:44969] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9c8_zqsQqnLoCgUjiLNwAAATk"]
[Tue Jul 21 08:50:12.036835 2026] [security2:error] [pid 511108:tid 511254] [client 103.59.206.240:31122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c9ITd5soprXwxAH0k6QAAABA"]
[Tue Jul 21 08:50:12.037435 2026] [security2:error] [pid 511108:tid 511254] [client 103.59.206.240:31122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c9ITd5soprXwxAH0k6QAAABA"]
[Tue Jul 21 08:50:12.140796 2026] [security2:error] [pid 511108:tid 511344] [client 203.25.124.72:58857] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/comments-pagination-numbers/"] [unique_id "al9c9ITd5soprXwxAH0k6wAAAGo"]
[Tue Jul 21 08:50:12.311741 2026] [security2:error] [pid 514479:tid 514692] [client 20.151.10.161:8426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/file25.php"] [unique_id "al9c9PzqsQqnLoCgUjiLPgAAAVg"]
[Tue Jul 21 08:50:12.476890 2026] [security2:error] [pid 511108:tid 511261] [client 203.25.124.52:64301] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-atom.php"] [unique_id "al9c9ITd5soprXwxAH0k8AAAABc"]
[Tue Jul 21 08:50:12.554071 2026] [security2:error] [pid 511108:tid 511263] [client 64.42.179.43:49098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9c9ITd5soprXwxAH0k9AAAABk"]
[Tue Jul 21 08:50:12.554161 2026] [security2:error] [pid 511108:tid 511263] [client 64.42.179.43:49098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9c9ITd5soprXwxAH0k9AAAABk"]
[Tue Jul 21 08:50:12.642348 2026] [security2:error] [pid 514479:tid 514528] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c9PzqsQqnLoCgUjiLRgABECw"]
[Tue Jul 21 08:50:12.642491 2026] [security2:error] [pid 514479:tid 514620] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c9PzqsQqnLoCgUjiLRgABECw"]
[Tue Jul 21 08:50:12.662249 2026] [security2:error] [pid 511108:tid 511297] [client 20.226.60.151:57559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/gptsh.php"] [unique_id "al9c9ITd5soprXwxAH0k9gAAADs"]
[Tue Jul 21 08:50:12.708558 2026] [security2:error] [pid 511108:tid 511170] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9c9ITd5soprXwxAH0k-gAAeD0"]
[Tue Jul 21 08:50:12.708692 2026] [security2:error] [pid 511108:tid 511358] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9c9ITd5soprXwxAH0k-gAAeD0"]
[Tue Jul 21 08:50:13.025229 2026] [security2:error] [pid 514479:tid 514615] [client 216.73.160.37:38823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9c9fzqsQqnLoCgUjiLUAAAAQs"]
[Tue Jul 21 08:50:13.026852 2026] [security2:error] [pid 511108:tid 511305] [client 216.73.160.185:51411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9c9YTd5soprXwxAH0lDQAAAEM"]
[Tue Jul 21 08:50:13.028551 2026] [security2:error] [pid 514479:tid 514679] [client 216.73.160.184:37499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9c9fzqsQqnLoCgUjiLUQAAAUs"]
[Tue Jul 21 08:50:13.036027 2026] [security2:error] [pid 511108:tid 511258] [client 203.25.124.42:43921] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/post-featured-image/"] [unique_id "al9c9YTd5soprXwxAH0lDwAAABQ"]
[Tue Jul 21 08:50:13.043096 2026] [security2:error] [pid 514479:tid 514629] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9c9PzqsQqnLoCgUjiLTgABGVo"]
[Tue Jul 21 08:50:13.123601 2026] [security2:error] [pid 511108:tid 511282] [client 168.167.81.163:61563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9c9YTd5soprXwxAH0lEgAAACw"]
[Tue Jul 21 08:50:13.129554 2026] [security2:error] [pid 511108:tid 511282] [client 168.167.81.163:61563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9c9YTd5soprXwxAH0lEgAAACw"]
[Tue Jul 21 08:50:13.209776 2026] [security2:error] [pid 511108:tid 511267] [client 216.73.160.30:64117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9c9YTd5soprXwxAH0lDgAAAB0"]
[Tue Jul 21 08:50:13.481723 2026] [security2:error] [pid 514479:tid 514648] [client 212.32.76.55:47085] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/network/chosen.php"] [unique_id "al9c9fzqsQqnLoCgUjiLVwAAASw"]
[Tue Jul 21 08:50:14.048672 2026] [security2:error] [pid 511108:tid 511328] [client 212.32.76.7:54581] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/wc-logs/"] [unique_id "al9c9oTd5soprXwxAH0lPQAAAFo"]
[Tue Jul 21 08:50:14.154722 2026] [security2:error] [pid 514479:tid 514619] [client 54.39.210.108:28080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "appauto.com.br"] [uri "/robots.txt"] [unique_id "al9c9vzqsQqnLoCgUjiLXwAAAQ8"]
[Tue Jul 21 08:50:14.154870 2026] [security2:error] [pid 514479:tid 514619] [client 54.39.210.108:28080] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "appauto.com.br"] [uri "/robots.txt"] [unique_id "al9c9vzqsQqnLoCgUjiLXwAAAQ8"]
[Tue Jul 21 08:50:14.182430 2026] [security2:error] [pid 511108:tid 511269] [client 20.226.60.151:57544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/rithin.php"] [unique_id "al9c9oTd5soprXwxAH0lPwAAAB8"]
[Tue Jul 21 08:50:14.605430 2026] [security2:error] [pid 514479:tid 514569] [remote 5.252.52.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "climadek.com.br"] [uri "/wp-login.php"] [unique_id "al9c9vzqsQqnLoCgUjiLaAABWVQ"]
[Tue Jul 21 08:50:14.665301 2026] [security2:error] [pid 514479:tid 514715] [client 203.25.124.32:36211] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/tinymce/themes/inlite/"] [unique_id "al9c9vzqsQqnLoCgUjiLagAAAW8"]
[Tue Jul 21 08:50:14.827915 2026] [security2:error] [pid 511108:tid 511306] [client 20.197.192.193:56811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9c9oTd5soprXwxAH0lSQAAAEQ"]
[Tue Jul 21 08:50:14.851686 2026] [security2:error] [pid 514479:tid 514649] [client 81.171.74.60:60010] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/user_secrets.yml"] [unique_id "al9c9vzqsQqnLoCgUjiLbgAAAS0"]
[Tue Jul 21 08:50:14.852945 2026] [security2:error] [pid 514479:tid 514618] [client 81.171.74.60:60022] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/config/production.json"] [unique_id "al9c9vzqsQqnLoCgUjiLbwAAAQ4"]
[Tue Jul 21 08:50:14.853464 2026] [security2:error] [pid 511108:tid 511315] [client 81.171.74.60:60000] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9c9oTd5soprXwxAH0lSgAAAE0"]
[Tue Jul 21 08:50:14.856676 2026] [security2:error] [pid 514479:tid 514727] [client 81.171.74.60:60054] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/.env.production"] [unique_id "al9c9vzqsQqnLoCgUjiLcAAAAXs"]
[Tue Jul 21 08:50:15.053729 2026] [security2:error] [pid 514479:tid 514653] [client 81.171.74.60:60032] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9c9_zqsQqnLoCgUjiLdAAAATE"]
[Tue Jul 21 08:50:15.053730 2026] [security2:error] [pid 514479:tid 514614] [client 81.171.74.60:60034] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/server.key"] [unique_id "al9c9_zqsQqnLoCgUjiLcwAAAQo"]
[Tue Jul 21 08:50:15.054241 2026] [security2:error] [pid 514479:tid 514721] [client 81.171.74.60:60040] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9c9_zqsQqnLoCgUjiLdQAAAXU"]
[Tue Jul 21 08:50:15.149822 2026] [security2:error] [pid 511108:tid 511324] [client 203.25.124.43:41137] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/upload.php"] [unique_id "al9c94Td5soprXwxAH0lTwAAAFY"]
[Tue Jul 21 08:50:15.170552 2026] [security2:error] [pid 511108:tid 511297] [client 203.25.124.202:63189] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "al9c94Td5soprXwxAH0lUAAAADs"]
[Tue Jul 21 08:50:15.696419 2026] [security2:error] [pid 514479:tid 514647] [client 49.144.66.253:31963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9c9_zqsQqnLoCgUjiLfwAAASs"]
[Tue Jul 21 08:50:15.696527 2026] [security2:error] [pid 514479:tid 514647] [client 49.144.66.253:31963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9c9_zqsQqnLoCgUjiLfwAAASs"]
[Tue Jul 21 08:50:15.749354 2026] [security2:error] [pid 511108:tid 511281] [client 148.113.128.44:38290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "appauto.com.br"] [uri "/"] [unique_id "al9c94Td5soprXwxAH0lXgAAACs"]
[Tue Jul 21 08:50:15.749452 2026] [security2:error] [pid 511108:tid 511281] [client 148.113.128.44:38290] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "appauto.com.br"] [uri "/"] [unique_id "al9c94Td5soprXwxAH0lXgAAACs"]
[Tue Jul 21 08:50:15.830636 2026] [security2:error] [pid 514479:tid 514696] [client 81.171.74.60:60070] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9c9_zqsQqnLoCgUjiLggAAAVw"]
[Tue Jul 21 08:50:15.831505 2026] [security2:error] [pid 511108:tid 511243] [client 81.171.74.60:60088] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9c94Td5soprXwxAH0lXwAAAAU"]
[Tue Jul 21 08:50:15.831961 2026] [security2:error] [pid 511108:tid 511286] [client 81.171.74.60:60098] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/.git/HEAD"] [unique_id "al9c94Td5soprXwxAH0lYAAAADA"]
[Tue Jul 21 08:50:15.831961 2026] [security2:error] [pid 514479:tid 514699] [client 81.171.74.60:60076] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9c9_zqsQqnLoCgUjiLgwAAAV8"]
[Tue Jul 21 08:50:15.865754 2026] [security2:error] [pid 514479:tid 514659] [client 59.95.197.55:53997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c9_zqsQqnLoCgUjiLhAAAATc"]
[Tue Jul 21 08:50:15.866353 2026] [security2:error] [pid 514479:tid 514659] [client 59.95.197.55:53997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c9_zqsQqnLoCgUjiLhAAAATc"]
[Tue Jul 21 08:50:16.034339 2026] [security2:error] [pid 511108:tid 511250] [client 81.171.74.60:60118] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/database_backup.sql"] [unique_id "al9c-ITd5soprXwxAH0lYwAAAAw"]
[Tue Jul 21 08:50:16.035036 2026] [security2:error] [pid 514479:tid 514637] [client 81.171.74.60:60102] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/wp-config.php"] [unique_id "al9c-PzqsQqnLoCgUjiLhgAAASE"]
[Tue Jul 21 08:50:16.060664 2026] [security2:error] [pid 514479:tid 514711] [client 203.25.124.52:59201] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/uploads/about.php"] [unique_id "al9c-PzqsQqnLoCgUjiLhwAAAWs"]
[Tue Jul 21 08:50:16.074243 2026] [security2:error] [pid 514479:tid 514640] [client 203.25.124.202:39491] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/news-portal/fm.php"] [unique_id "al9c-PzqsQqnLoCgUjiLiAAAASQ"]
[Tue Jul 21 08:50:16.108190 2026] [security2:error] [pid 514479:tid 514619] [client 122.176.100.127:55705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9c-PzqsQqnLoCgUjiLigAAAQ8"]
[Tue Jul 21 08:50:16.108303 2026] [security2:error] [pid 514479:tid 514619] [client 122.176.100.127:55705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9c-PzqsQqnLoCgUjiLigAAAQ8"]
[Tue Jul 21 08:50:16.332422 2026] [security2:error] [pid 514479:tid 514649] [client 20.226.60.151:59584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/fffm.php"] [unique_id "al9c-PzqsQqnLoCgUjiLkwAAAS0"]
[Tue Jul 21 08:50:16.338478 2026] [security2:error] [pid 514479:tid 514727] [client 203.25.124.33:35993] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/maint/network/"] [unique_id "al9c-PzqsQqnLoCgUjiLlAAAAXs"]
[Tue Jul 21 08:50:16.414756 2026] [security2:error] [pid 514479:tid 514656] [client 65.21.113.253:41688] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9c-PzqsQqnLoCgUjiLlQAAATQ"]
[Tue Jul 21 08:50:16.438443 2026] [security2:error] [pid 514479:tid 514676] [client 173.252.95.0:34454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9c-PzqsQqnLoCgUjiLlgAAAUg"]
[Tue Jul 21 08:50:16.661410 2026] [security2:error] [pid 511108:tid 511311] [client 20.197.195.24:62757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9c-ITd5soprXwxAH0lbQAAAEk"]
[Tue Jul 21 08:50:16.774123 2026] [security2:error] [pid 514479:tid 514629] [client 114.198.138.124:50849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9c-PzqsQqnLoCgUjiLmAAAARk"]
[Tue Jul 21 08:50:16.774210 2026] [security2:error] [pid 514479:tid 514629] [client 114.198.138.124:50849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9c-PzqsQqnLoCgUjiLmAAAARk"]
[Tue Jul 21 08:50:16.804954 2026] [security2:error] [pid 511108:tid 511328] [client 81.171.74.60:60136] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/.env"] [unique_id "al9c-ITd5soprXwxAH0lbwAAAFo"]
[Tue Jul 21 08:50:16.806967 2026] [security2:error] [pid 511108:tid 511269] [client 81.171.74.60:60128] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/api/.env"] [unique_id "al9c-ITd5soprXwxAH0lcAAAAB8"]
[Tue Jul 21 08:50:16.807387 2026] [security2:error] [pid 514479:tid 514614] [client 81.171.74.60:60150] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/secrets.json"] [unique_id "al9c-PzqsQqnLoCgUjiLmwAAAQo"]
[Tue Jul 21 08:50:16.807838 2026] [security2:error] [pid 511108:tid 511305] [client 81.171.74.60:60180] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9c-ITd5soprXwxAH0lcQAAAEM"]
[Tue Jul 21 08:50:16.813916 2026] [security2:error] [pid 511108:tid 511354] [client 20.197.192.193:50563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/ee.php"] [unique_id "al9c-ITd5soprXwxAH0lcgAAAHQ"]
[Tue Jul 21 08:50:16.909053 2026] [security2:error] [pid 514479:tid 514688] [client 20.104.96.117:61128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/nano.php"] [unique_id "al9c-PzqsQqnLoCgUjiLnAAAAVQ"]
[Tue Jul 21 08:50:17.008846 2026] [security2:error] [pid 511108:tid 511242] [client 81.171.74.60:60156] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/.bash_history"] [unique_id "al9c-YTd5soprXwxAH0ldgAAAAQ"]
[Tue Jul 21 08:50:17.010047 2026] [security2:error] [pid 511108:tid 511258] [client 81.171.74.60:60194] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/.npmrc"] [unique_id "al9c-YTd5soprXwxAH0ldwAAABQ"]
[Tue Jul 21 08:50:17.010163 2026] [security2:error] [pid 514479:tid 514721] [client 81.171.74.60:60164] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "reserveseulugar.com.br"] [uri "/phpinfo.php"] [unique_id "al9c-fzqsQqnLoCgUjiLogAAAXU"]
[Tue Jul 21 08:50:17.164081 2026] [security2:error] [pid 511108:tid 511361] [client 203.25.124.67:32933] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/covr-wpcom/assets/fonts/manrope_normal.php"] [unique_id "al9c-YTd5soprXwxAH0lewAAAHs"]
[Tue Jul 21 08:50:17.175079 2026] [security2:error] [pid 511108:tid 511348] [client 212.32.76.63:22291] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/customize/index.php"] [unique_id "al9c-YTd5soprXwxAH0lfAAAAG4"]
[Tue Jul 21 08:50:17.490941 2026] [security2:error] [pid 514479:tid 514712] [client 5.38.115.39:53294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9c-fzqsQqnLoCgUjiLqQAAAWw"]
[Tue Jul 21 08:50:17.491043 2026] [security2:error] [pid 514479:tid 514712] [client 5.38.115.39:53294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9c-fzqsQqnLoCgUjiLqQAAAWw"]
[Tue Jul 21 08:50:17.538887 2026] [security2:error] [pid 511108:tid 511346] [client 203.25.124.64:55025] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/group/"] [unique_id "al9c-YTd5soprXwxAH0lhQAAAGw"]
[Tue Jul 21 08:50:17.554179 2026] [security2:error] [pid 514479:tid 514671] [client 65.21.113.253:47560] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9c-fzqsQqnLoCgUjiLpAAAAUM"]
[Tue Jul 21 08:50:17.965474 2026] [security2:error] [pid 514479:tid 514663] [client 20.197.192.193:38254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/wp-editor.php"] [unique_id "al9c-fzqsQqnLoCgUjiLrgAAATs"]
[Tue Jul 21 08:50:18.266193 2026] [security2:error] [pid 514479:tid 514656] [client 203.25.124.51:48219] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/js/privacy-tools.min.php"] [unique_id "al9c-vzqsQqnLoCgUjiLswAAATQ"]
[Tue Jul 21 08:50:18.444662 2026] [security2:error] [pid 511108:tid 511313] [client 203.25.124.61:52903] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/"] [unique_id "al9c-oTd5soprXwxAH0llAAAAEs"]
[Tue Jul 21 08:50:18.530940 2026] [security2:error] [pid 514479:tid 514739] [client 195.49.128.211:60305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9c-vzqsQqnLoCgUjiLtgAAAYc"]
[Tue Jul 21 08:50:18.531035 2026] [security2:error] [pid 514479:tid 514739] [client 195.49.128.211:60305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9c-vzqsQqnLoCgUjiLtgAAAYc"]
[Tue Jul 21 08:50:18.545940 2026] [security2:error] [pid 511108:tid 511250] [client 173.252.95.35:50220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9c-oTd5soprXwxAH0llwAAAAw"]
[Tue Jul 21 08:50:18.558436 2026] [security2:error] [pid 514479:tid 514668] [client 20.197.192.193:50561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/blue.php"] [unique_id "al9c-vzqsQqnLoCgUjiLtwAAAUA"]
[Tue Jul 21 08:50:18.605227 2026] [security2:error] [pid 511108:tid 511348] [client 20.104.96.117:61143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/moon.php"] [unique_id "al9c-oTd5soprXwxAH0lmQAAAG4"]
[Tue Jul 21 08:50:18.724345 2026] [security2:error] [pid 511108:tid 511320] [client 20.226.60.151:59599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/dfre.php"] [unique_id "al9c-oTd5soprXwxAH0lmwAAAFI"]
[Tue Jul 21 08:50:18.724477 2026] [security2:error] [pid 514479:tid 514728] [client 20.220.225.223:46367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/la.php"] [unique_id "al9c-vzqsQqnLoCgUjiLuQAAAXw"]
[Tue Jul 21 08:50:18.779423 2026] [security2:error] [pid 514479:tid 514733] [client 103.59.206.240:31360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c-vzqsQqnLoCgUjiLuwAAAYE"]
[Tue Jul 21 08:50:18.779524 2026] [security2:error] [pid 514479:tid 514733] [client 103.59.206.240:31360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c-vzqsQqnLoCgUjiLuwAAAYE"]
[Tue Jul 21 08:50:18.896710 2026] [security2:error] [pid 511108:tid 511306] [client 20.197.192.193:8367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "biolinkeer.hostag.com.br"] [uri "/phpinfo.php1"] [unique_id "al9c-oTd5soprXwxAH0loAAAAEQ"]
[Tue Jul 21 08:50:18.996611 2026] [security2:error] [pid 511108:tid 511315] [client 173.252.95.59:63696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9c-oTd5soprXwxAH0lpQAAAE0"]
[Tue Jul 21 08:50:19.076392 2026] [security2:error] [pid 511108:tid 511324] [client 20.104.96.117:3978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/adjig.php"] [unique_id "al9c-4Td5soprXwxAH0lpwAAAFY"]
[Tue Jul 21 08:50:19.243884 2026] [security2:error] [pid 514479:tid 514736] [client 41.89.234.2:56987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c-_zqsQqnLoCgUjiLxgAAAYQ"]
[Tue Jul 21 08:50:19.244041 2026] [security2:error] [pid 514479:tid 514736] [client 41.89.234.2:56987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c-_zqsQqnLoCgUjiLxgAAAYQ"]
[Tue Jul 21 08:50:19.325510 2026] [security2:error] [pid 514479:tid 514550] [remote 173.252.82.52:43112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9c-_zqsQqnLoCgUjiLxQABG0E"]
[Tue Jul 21 08:50:19.463688 2026] [security2:error] [pid 514479:tid 514693] [client 203.25.124.36:51481] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/options.php"] [unique_id "al9c-_zqsQqnLoCgUjiLxwAAAVk"]
[Tue Jul 21 08:50:19.546719 2026] [security2:error] [pid 514479:tid 514661] [client 20.197.192.193:22344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/cro.php"] [unique_id "al9c-_zqsQqnLoCgUjiLygAAATk"]
[Tue Jul 21 08:50:19.570155 2026] [security2:error] [pid 514479:tid 514737] [client 212.32.76.57:58713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css/colors/admin.php"] [unique_id "al9c-_zqsQqnLoCgUjiLywAAAYU"]
[Tue Jul 21 08:50:19.641454 2026] [security2:error] [pid 514479:tid 514625] [client 212.32.76.13:41081] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/666.php"] [unique_id "al9c-_zqsQqnLoCgUjiLzgAAARU"]
[Tue Jul 21 08:50:19.681803 2026] [security2:error] [pid 514479:tid 514679] [client 20.197.195.24:3247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9c-_zqsQqnLoCgUjiLzwAAAUs"]
[Tue Jul 21 08:50:19.829597 2026] [access_compat:error] [pid 511108:tid 511312] [client 162.241.63.68:14138] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:50:20.283188 2026] [security2:error] [pid 511108:tid 511113] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9c_ITd5soprXwxAH0lvAAAQgQ"]
[Tue Jul 21 08:50:20.283480 2026] [security2:error] [pid 511108:tid 511304] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9c_ITd5soprXwxAH0lvAAAQgQ"]
[Tue Jul 21 08:50:20.436383 2026] [security2:error] [pid 511108:tid 511290] [client 20.197.195.24:3206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/media.php"] [unique_id "al9c_ITd5soprXwxAH0lxgAAADQ"]
[Tue Jul 21 08:50:20.487173 2026] [security2:error] [pid 511108:tid 511110] [remote 20.75.217.69:1505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "governess.com.br"] [uri "/wp-login.php"] [unique_id "al9c_ITd5soprXwxAH0lyAAAMQE"]
[Tue Jul 21 08:50:20.488516 2026] [security2:error] [pid 511108:tid 511361] [client 195.206.105.227:39256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9c_ITd5soprXwxAH0lygAAAHs"]
[Tue Jul 21 08:50:20.488575 2026] [security2:error] [pid 511108:tid 511361] [client 195.206.105.227:39256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9c_ITd5soprXwxAH0lygAAAHs"]
[Tue Jul 21 08:50:20.779486 2026] [security2:error] [pid 511108:tid 511307] [client 20.151.10.161:62387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/file48.php"] [unique_id "al9c_ITd5soprXwxAH0l0AAAAEU"]
[Tue Jul 21 08:50:20.842556 2026] [security2:error] [pid 514479:tid 514622] [client 20.197.195.24:62736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/images.php"] [unique_id "al9c_PzqsQqnLoCgUjiL2wAAARI"]
[Tue Jul 21 08:50:21.076142 2026] [security2:error] [pid 514479:tid 514665] [client 20.226.60.151:59616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/wp-happy.php"] [unique_id "al9c_fzqsQqnLoCgUjiL3gAAAT0"]
[Tue Jul 21 08:50:21.116545 2026] [security2:error] [pid 514479:tid 514647] [client 20.104.96.117:59196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-info.php"] [unique_id "al9c_fzqsQqnLoCgUjiL3wAAASs"]
[Tue Jul 21 08:50:21.149930 2026] [security2:error] [pid 511108:tid 511297] [client 20.220.225.223:46364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9c_YTd5soprXwxAH0l0wAAADs"]
[Tue Jul 21 08:50:21.244866 2026] [security2:error] [pid 511108:tid 511347] [client 203.25.124.48:60915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/sodium_compat/namespaced/Core/"] [unique_id "al9c_YTd5soprXwxAH0l1gAAAG0"]
[Tue Jul 21 08:50:21.273306 2026] [security2:error] [pid 511108:tid 511360] [client 198.44.157.34:41062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9c_YTd5soprXwxAH0l2AAAAHo"]
[Tue Jul 21 08:50:21.273495 2026] [security2:error] [pid 511108:tid 511360] [client 198.44.157.34:41062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9c_YTd5soprXwxAH0l2AAAAHo"]
[Tue Jul 21 08:50:21.378775 2026] [security2:error] [pid 511108:tid 511340] [client 20.197.192.193:50593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/wp-signup.php"] [unique_id "al9c_YTd5soprXwxAH0l2gAAAGY"]
[Tue Jul 21 08:50:21.441106 2026] [security2:error] [pid 514479:tid 514681] [client 20.197.195.24:3304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/gecko.php"] [unique_id "al9c_fzqsQqnLoCgUjiL5QAAAU0"]
[Tue Jul 21 08:50:21.452207 2026] [security2:error] [pid 514479:tid 514560] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9c_fzqsQqnLoCgUjiL5gABN0s"]
[Tue Jul 21 08:50:21.452303 2026] [security2:error] [pid 514479:tid 514659] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9c_fzqsQqnLoCgUjiL5gABN0s"]
[Tue Jul 21 08:50:21.468734 2026] [security2:error] [pid 511108:tid 511281] [client 212.32.76.14:31317] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/user/wp-conflg.php"] [unique_id "al9c_YTd5soprXwxAH0l3QAAACs"]
[Tue Jul 21 08:50:21.471908 2026] [security2:error] [pid 514479:tid 514640] [client 203.25.124.208:31147] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/images/wp-conflg.php"] [unique_id "al9c_fzqsQqnLoCgUjiL6AAAASQ"]
[Tue Jul 21 08:50:21.548628 2026] [proxy:error] [pid 514479:tid 514700] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:50:21.548683 2026] [proxy_http:error] [pid 514479:tid 514700] [client 85.204.70.100:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:50:21.549217 2026] [proxy:error] [pid 514479:tid 514700] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:50:21.549239 2026] [proxy_http:error] [pid 514479:tid 514700] [client 85.204.70.100:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:50:21.829237 2026] [proxy:error] [pid 514479:tid 514615] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:50:21.829307 2026] [proxy_http:error] [pid 514479:tid 514615] [client 85.204.70.100:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:50:21.829837 2026] [proxy:error] [pid 514479:tid 514615] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:50:21.829859 2026] [proxy_http:error] [pid 514479:tid 514615] [client 85.204.70.100:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:50:21.853699 2026] [security2:error] [pid 514479:tid 514676] [client 20.197.195.24:63405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/82.php"] [unique_id "al9c_fzqsQqnLoCgUjiL8QAAAUg"]
[Tue Jul 21 08:50:21.952379 2026] [security2:error] [pid 514479:tid 514658] [client 113.22.144.139:54748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c_fzqsQqnLoCgUjiL9AAAATY"]
[Tue Jul 21 08:50:21.953363 2026] [security2:error] [pid 514479:tid 514658] [client 113.22.144.139:54748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c_fzqsQqnLoCgUjiL9AAAATY"]
[Tue Jul 21 08:50:22.103719 2026] [security2:error] [pid 511108:tid 511261] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9c_oTd5soprXwxAH0l5AAAABc"]
[Tue Jul 21 08:50:22.304084 2026] [security2:error] [pid 514479:tid 514661] [client 182.189.99.211:48141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c_vzqsQqnLoCgUjiL-gAAATk"]
[Tue Jul 21 08:50:22.304377 2026] [security2:error] [pid 514479:tid 514661] [client 182.189.99.211:48141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c_vzqsQqnLoCgUjiL-gAAATk"]
[Tue Jul 21 08:50:22.344262 2026] [security2:error] [pid 514479:tid 514648] [client 203.25.124.32:26617] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/l10n/wp-conflg.php"] [unique_id "al9c_vzqsQqnLoCgUjiL_QAAASw"]
[Tue Jul 21 08:50:22.349018 2026] [security2:error] [pid 514479:tid 514556] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c_vzqsQqnLoCgUjiL_AABgUc"]
[Tue Jul 21 08:50:22.349288 2026] [security2:error] [pid 514479:tid 514733] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c_vzqsQqnLoCgUjiL_AABgUc"]
[Tue Jul 21 08:50:22.385067 2026] [security2:error] [pid 514479:tid 514721] [client 85.204.70.100:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c_vzqsQqnLoCgUjiL_gAAAXU"]
[Tue Jul 21 08:50:22.441530 2026] [security2:error] [pid 514479:tid 514617] [client 20.226.60.151:57558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/fpr4.php"] [unique_id "al9c_vzqsQqnLoCgUjiL_wAAAQ0"]
[Tue Jul 21 08:50:22.472570 2026] [security2:error] [pid 514479:tid 514727] [client 203.25.124.252:49627] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Text/chosen.php"] [unique_id "al9c_vzqsQqnLoCgUjiMAAAAAXs"]
[Tue Jul 21 08:50:22.519695 2026] [security2:error] [pid 514479:tid 514688] [client 20.197.195.24:3244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/admin.php"] [unique_id "al9c_vzqsQqnLoCgUjiMAwAAAVQ"]
[Tue Jul 21 08:50:22.561569 2026] [security2:error] [pid 511108:tid 511277] [client 212.32.76.6:49873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/.well-known/"] [unique_id "al9c_oTd5soprXwxAH0l7wAAACc"]
[Tue Jul 21 08:50:22.659935 2026] [proxy:error] [pid 514479:tid 514736] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:50:22.660001 2026] [proxy_http:error] [pid 514479:tid 514736] [client 85.204.70.100:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:50:22.660437 2026] [proxy:error] [pid 514479:tid 514736] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:50:22.660461 2026] [proxy_http:error] [pid 514479:tid 514736] [client 85.204.70.100:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:50:22.746207 2026] [security2:error] [pid 514479:tid 514654] [client 20.197.195.24:62752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/adminner.php"] [unique_id "al9c_vzqsQqnLoCgUjiMCQAAATI"]
[Tue Jul 21 08:50:22.778517 2026] [security2:error] [pid 511108:tid 511354] [client 20.104.96.117:46770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/byp.php"] [unique_id "al9c_oTd5soprXwxAH0l9QAAAHQ"]
[Tue Jul 21 08:50:22.884552 2026] [security2:error] [pid 511108:tid 511254] [client 65.21.113.253:59288] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9c_oTd5soprXwxAH0l9wAAABA"]
[Tue Jul 21 08:50:22.925977 2026] [security2:error] [pid 514479:tid 514559] [remote 8.217.108.67:37188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vmmarketing.com.br"] [uri "/wp-login.php"] [unique_id "al9c_vzqsQqnLoCgUjiMDAABGUo"]
[Tue Jul 21 08:50:22.939594 2026] [security2:error] [pid 514479:tid 514717] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9c_vzqsQqnLoCgUjiMDQAAAXE"]
[Tue Jul 21 08:50:22.993465 2026] [security2:error] [pid 511108:tid 511244] [client 20.197.195.24:62730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/admin.php"] [unique_id "al9c_oTd5soprXwxAH0l-QAAAAY"]
[Tue Jul 21 08:50:23.043315 2026] [security2:error] [pid 511108:tid 511296] [client 212.32.76.8:54307] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/user.php"] [unique_id "al9c_4Td5soprXwxAH0l_AAAADo"]
[Tue Jul 21 08:50:23.049015 2026] [security2:error] [pid 511108:tid 511271] [client 64.42.179.43:48592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9c_4Td5soprXwxAH0l_QAAACE"]
[Tue Jul 21 08:50:23.049098 2026] [security2:error] [pid 511108:tid 511271] [client 64.42.179.43:48592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9c_4Td5soprXwxAH0l_QAAACE"]
[Tue Jul 21 08:50:23.186607 2026] [security2:error] [pid 511108:tid 511267] [client 20.151.10.161:8336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/file6.php"] [unique_id "al9c_4Td5soprXwxAH0l_gAAAB0"]
[Tue Jul 21 08:50:23.216218 2026] [security2:error] [pid 514479:tid 514692] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9c__zqsQqnLoCgUjiMEAAAAVg"]
[Tue Jul 21 08:50:23.281836 2026] [security2:error] [pid 514479:tid 514570] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9c__zqsQqnLoCgUjiMEgABU1U"]
[Tue Jul 21 08:50:23.282205 2026] [security2:error] [pid 514479:tid 514687] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9c__zqsQqnLoCgUjiMEgABU1U"]
[Tue Jul 21 08:50:23.381271 2026] [security2:error] [pid 511108:tid 511339] [client 203.25.124.197:28847] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/chosen.php"] [unique_id "al9c_4Td5soprXwxAH0mBAAAAGU"]
[Tue Jul 21 08:50:23.492297 2026] [security2:error] [pid 514479:tid 514658] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9c__zqsQqnLoCgUjiMFAAAATY"]
[Tue Jul 21 08:50:23.525027 2026] [security2:error] [pid 514479:tid 514566] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c__zqsQqnLoCgUjiMFwABgFE"]
[Tue Jul 21 08:50:23.525262 2026] [security2:error] [pid 514479:tid 514732] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9c__zqsQqnLoCgUjiMFwABgFE"]
[Tue Jul 21 08:50:23.531862 2026] [security2:error] [pid 511108:tid 511340] [client 20.104.96.117:61146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/2000.php"] [unique_id "al9c_4Td5soprXwxAH0mCQAAAGY"]
[Tue Jul 21 08:50:23.539523 2026] [security2:error] [pid 511108:tid 511251] [client 20.197.195.24:3262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/k.php"] [unique_id "al9c_4Td5soprXwxAH0mCgAAAA0"]
[Tue Jul 21 08:50:23.641038 2026] [security2:error] [pid 511108:tid 511301] [client 5.31.193.106:1675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9c_4Td5soprXwxAH0mDgAAAD8"]
[Tue Jul 21 08:50:23.649377 2026] [security2:error] [pid 511108:tid 511301] [client 5.31.193.106:1675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9c_4Td5soprXwxAH0mDgAAAD8"]
[Tue Jul 21 08:50:23.663711 2026] [security2:error] [pid 514479:tid 514740] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9c__zqsQqnLoCgUjiMGgABiEI"]
[Tue Jul 21 08:50:23.667722 2026] [security2:error] [pid 511108:tid 511323] [client 212.32.76.12:45143] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-configs.php"] [unique_id "al9c_4Td5soprXwxAH0mDwAAAFU"]
[Tue Jul 21 08:50:23.786368 2026] [security2:error] [pid 511108:tid 511238] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9c_4Td5soprXwxAH0mEQAAAAA"]
[Tue Jul 21 08:50:23.873496 2026] [security2:error] [pid 514479:tid 514671] [client 20.197.195.24:62738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/blurbs.php"] [unique_id "al9c__zqsQqnLoCgUjiMGwAAAUM"]
[Tue Jul 21 08:50:23.948162 2026] [security2:error] [pid 511108:tid 511312] [client 20.104.96.117:59139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/122.php"] [unique_id "al9c_4Td5soprXwxAH0mFgAAAEo"]
[Tue Jul 21 08:50:23.968517 2026] [security2:error] [pid 511108:tid 511307] [client 65.21.113.253:54524] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9c_4Td5soprXwxAH0mDAAAAEU"]
[Tue Jul 21 08:50:24.062461 2026] [security2:error] [pid 514479:tid 514643] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9dAPzqsQqnLoCgUjiMHAAAASc"]
[Tue Jul 21 08:50:24.336854 2026] [security2:error] [pid 511108:tid 511356] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9dAITd5soprXwxAH0mHQAAAHY"]
[Tue Jul 21 08:50:24.486749 2026] [security2:error] [pid 511108:tid 511313] [client 20.226.60.151:57541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/file88.php"] [unique_id "al9dAITd5soprXwxAH0mIQAAAEs"]
[Tue Jul 21 08:50:24.611274 2026] [security2:error] [pid 514479:tid 514721] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9dAPzqsQqnLoCgUjiMIAAAAXU"]
[Tue Jul 21 08:50:24.871842 2026] [security2:error] [pid 511108:tid 511354] [client 203.25.124.47:47545] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/class.php"] [unique_id "al9dAITd5soprXwxAH0mJgAAAHQ"]
[Tue Jul 21 08:50:24.875149 2026] [security2:error] [pid 514479:tid 514727] [client 203.25.124.183:23127] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/system.php"] [unique_id "al9dAPzqsQqnLoCgUjiMIgAAAXs"]
[Tue Jul 21 08:50:24.886767 2026] [security2:error] [pid 514479:tid 514730] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9dAPzqsQqnLoCgUjiMIwAAAX4"]
[Tue Jul 21 08:50:24.971677 2026] [security2:error] [pid 514479:tid 514646] [client 20.104.96.117:46780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/ortasekerli1.php"] [unique_id "al9dAPzqsQqnLoCgUjiMJgAAASo"]
[Tue Jul 21 08:50:24.985867 2026] [security2:error] [pid 511108:tid 511327] [client 20.197.195.24:62729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/bajah.php"] [unique_id "al9dAITd5soprXwxAH0mKgAAAFk"]
[Tue Jul 21 08:50:25.163861 2026] [security2:error] [pid 514479:tid 514696] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9dAfzqsQqnLoCgUjiMKAAAAVw"]
[Tue Jul 21 08:50:25.365538 2026] [security2:error] [pid 514479:tid 514736] [client 20.197.195.24:62774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/a.php"] [unique_id "al9dAfzqsQqnLoCgUjiMKgAAAYQ"]
[Tue Jul 21 08:50:25.417885 2026] [security2:error] [pid 514479:tid 514686] [client 20.197.195.24:3286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/edit.php"] [unique_id "al9dAfzqsQqnLoCgUjiMLAAAAVI"]
[Tue Jul 21 08:50:25.439664 2026] [security2:error] [pid 514479:tid 514631] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9dAfzqsQqnLoCgUjiMLQAAARs"]
[Tue Jul 21 08:50:25.474055 2026] [security2:error] [pid 511108:tid 511351] [client 20.197.195.24:8844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/hosty.php"] [unique_id "al9dAYTd5soprXwxAH0mNgAAAHE"]
[Tue Jul 21 08:50:25.530933 2026] [security2:error] [pid 514479:tid 514717] [client 203.25.124.65:45683] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/nextpage/"] [unique_id "al9dAfzqsQqnLoCgUjiMMAAAAXE"]
[Tue Jul 21 08:50:25.579863 2026] [security2:error] [pid 514479:tid 514663] [client 20.197.195.24:63382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/k.php"] [unique_id "al9dAfzqsQqnLoCgUjiMMQAAATs"]
[Tue Jul 21 08:50:25.714810 2026] [security2:error] [pid 511108:tid 511315] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9dAYTd5soprXwxAH0mOQAAAE0"]
[Tue Jul 21 08:50:25.766822 2026] [security2:error] [pid 511108:tid 511346] [client 20.151.10.161:8299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/a2.php"] [unique_id "al9dAYTd5soprXwxAH0mOgAAAGw"]
[Tue Jul 21 08:50:25.992490 2026] [security2:error] [pid 514479:tid 514621] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9dAfzqsQqnLoCgUjiMOgAAARE"]
[Tue Jul 21 08:50:26.043803 2026] [security2:error] [pid 514479:tid 514624] [client 20.197.195.24:8858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/aaa.php"] [unique_id "al9dAvzqsQqnLoCgUjiMOwAAARQ"]
[Tue Jul 21 08:50:26.159721 2026] [security2:error] [pid 514479:tid 514655] [client 20.197.192.193:21925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/cron-tab.php"] [unique_id "al9dAvzqsQqnLoCgUjiMPQAAATM"]
[Tue Jul 21 08:50:26.262647 2026] [security2:error] [pid 511108:tid 511276] [client 203.25.124.42:34973] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Text/Diff/Engine/"] [unique_id "al9dAoTd5soprXwxAH0mRgAAACY"]
[Tue Jul 21 08:50:26.269611 2026] [security2:error] [pid 511108:tid 511260] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9dAoTd5soprXwxAH0mRwAAABY"]
[Tue Jul 21 08:50:26.275777 2026] [security2:error] [pid 511108:tid 511238] [client 203.25.124.202:47635] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/PHPMailer/wp-conflg.php"] [unique_id "al9dAoTd5soprXwxAH0mSAAAAAA"]
[Tue Jul 21 08:50:26.350675 2026] [security2:error] [pid 514479:tid 514732] [client 114.198.138.124:51429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dAvzqsQqnLoCgUjiMQAAAAYA"]
[Tue Jul 21 08:50:26.350941 2026] [security2:error] [pid 514479:tid 514732] [client 114.198.138.124:51429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dAvzqsQqnLoCgUjiMQAAAAYA"]
[Tue Jul 21 08:50:26.359242 2026] [security2:error] [pid 511108:tid 511268] [client 59.95.197.55:54463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dAoTd5soprXwxAH0mSQAAAB4"]
[Tue Jul 21 08:50:26.359435 2026] [security2:error] [pid 511108:tid 511268] [client 59.95.197.55:54463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dAoTd5soprXwxAH0mSQAAAB4"]
[Tue Jul 21 08:50:26.414205 2026] [security2:error] [pid 511108:tid 511282] [client 168.167.81.163:59203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dAoTd5soprXwxAH0mSgAAACw"]
[Tue Jul 21 08:50:26.414313 2026] [security2:error] [pid 511108:tid 511282] [client 168.167.81.163:59203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dAoTd5soprXwxAH0mSgAAACw"]
[Tue Jul 21 08:50:26.517030 2026] [security2:error] [pid 511108:tid 511278] [client 20.197.195.24:63369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/file5.php"] [unique_id "al9dAoTd5soprXwxAH0mTAAAACg"]
[Tue Jul 21 08:50:26.544141 2026] [security2:error] [pid 511108:tid 511321] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9dAoTd5soprXwxAH0mTgAAAFM"]
[Tue Jul 21 08:50:26.634618 2026] [security2:error] [pid 514479:tid 514624] [client 122.176.100.127:56191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dAvzqsQqnLoCgUjiMSwAAARQ"]
[Tue Jul 21 08:50:26.634874 2026] [security2:error] [pid 514479:tid 514624] [client 122.176.100.127:56191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dAvzqsQqnLoCgUjiMSwAAARQ"]
[Tue Jul 21 08:50:26.645498 2026] [security2:error] [pid 514479:tid 514690] [client 49.144.66.253:32382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dAvzqsQqnLoCgUjiMTAAAAVY"]
[Tue Jul 21 08:50:26.645599 2026] [security2:error] [pid 514479:tid 514690] [client 49.144.66.253:32382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dAvzqsQqnLoCgUjiMTAAAAVY"]
[Tue Jul 21 08:50:26.747301 2026] [security2:error] [pid 514479:tid 514688] [client 203.25.124.64:44195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/code/"] [unique_id "al9dAvzqsQqnLoCgUjiMTQAAAVQ"]
[Tue Jul 21 08:50:26.820268 2026] [security2:error] [pid 514479:tid 514718] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9dAvzqsQqnLoCgUjiMUAAAAXI"]
[Tue Jul 21 08:50:26.844736 2026] [security2:error] [pid 511108:tid 511245] [client 65.21.113.253:59288] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dAoTd5soprXwxAH0mUwAAAAc"]
[Tue Jul 21 08:50:26.851140 2026] [security2:error] [pid 514479:tid 514660] [client 20.226.60.151:57596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ccc.php"] [unique_id "al9dAvzqsQqnLoCgUjiMUQAAATg"]
[Tue Jul 21 08:50:26.885655 2026] [security2:error] [pid 514479:tid 514699] [client 20.104.96.117:4054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/classwithtostring.php"] [unique_id "al9dAvzqsQqnLoCgUjiMUwAAAV8"]
[Tue Jul 21 08:50:26.918091 2026] [security2:error] [pid 514479:tid 514736] [client 20.197.195.24:62734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/222.php"] [unique_id "al9dAvzqsQqnLoCgUjiMVAAAAYQ"]
[Tue Jul 21 08:50:26.970638 2026] [security2:error] [pid 514479:tid 514725] [client 20.151.10.161:8340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/file15.php"] [unique_id "al9dAvzqsQqnLoCgUjiMVgAAAXk"]
[Tue Jul 21 08:50:27.096246 2026] [security2:error] [pid 511108:tid 511313] [client 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sabrinasantacosta1782728737994.0711679.meusitehostgator.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9dA4Td5soprXwxAH0mWAAAAEs"]
[Tue Jul 21 08:50:27.359503 2026] [security2:error] [pid 511108:tid 511285] [client 203.25.124.54:27755] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/content.php"] [unique_id "al9dA4Td5soprXwxAH0mXQAAAC8"]
[Tue Jul 21 08:50:27.521257 2026] [security2:error] [pid 514479:tid 514695] [client 20.197.195.24:3236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/test.php"] [unique_id "al9dA_zqsQqnLoCgUjiMXwAAAVs"]
[Tue Jul 21 08:50:27.548543 2026] [security2:error] [pid 511108:tid 511254] [client 20.151.10.161:8438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/jp.php"] [unique_id "al9dA4Td5soprXwxAH0mYgAAABA"]
[Tue Jul 21 08:50:27.775140 2026] [security2:error] [pid 514479:tid 514661] [client 20.197.195.24:62745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/aaa.php"] [unique_id "al9dA_zqsQqnLoCgUjiMZAAAATk"]
[Tue Jul 21 08:50:27.863770 2026] [security2:error] [pid 514479:tid 514711] [client 203.25.124.9:39099] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/news-portal/wp-admins.php"] [unique_id "al9dA_zqsQqnLoCgUjiMZgAAAWs"]
[Tue Jul 21 08:50:27.898227 2026] [security2:error] [pid 514479:tid 514529] [remote 47.128.53.128:50078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "havoy.com.br"] [uri "/contato/"] [unique_id "al9dA_zqsQqnLoCgUjiMZwABLC0"]
[Tue Jul 21 08:50:27.917104 2026] [security2:error] [pid 514479:tid 514625] [client 65.21.113.253:54536] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dA_zqsQqnLoCgUjiMXgAAARU"]
[Tue Jul 21 08:50:27.945402 2026] [security2:error] [pid 514479:tid 514733] [client 203.25.124.71:58687] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwentytwo/assets/fonts/"] [unique_id "al9dA_zqsQqnLoCgUjiMaAAAAYE"]
[Tue Jul 21 08:50:28.036311 2026] [security2:error] [pid 514479:tid 514618] [client 20.197.195.24:3213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/11.php"] [unique_id "al9dBPzqsQqnLoCgUjiMawAAAQ4"]
[Tue Jul 21 08:50:28.113890 2026] [security2:error] [pid 511108:tid 511351] [client 20.151.10.161:8419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/f35.php"] [unique_id "al9dBITd5soprXwxAH0mawAAAHE"]
[Tue Jul 21 08:50:28.219648 2026] [security2:error] [pid 514479:tid 514653] [client 5.38.115.39:53838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dBPzqsQqnLoCgUjiMbAAAATE"]
[Tue Jul 21 08:50:28.219758 2026] [security2:error] [pid 514479:tid 514653] [client 5.38.115.39:53838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dBPzqsQqnLoCgUjiMbAAAATE"]
[Tue Jul 21 08:50:28.271242 2026] [security2:error] [pid 514479:tid 514722] [client 20.197.195.24:63376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/mac.php"] [unique_id "al9dBPzqsQqnLoCgUjiMbQAAAXY"]
[Tue Jul 21 08:50:28.352519 2026] [security2:error] [pid 514479:tid 514614] [client 20.197.192.193:22360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/koiy.php"] [unique_id "al9dBPzqsQqnLoCgUjiMbgAAAQo"]
[Tue Jul 21 08:50:28.555620 2026] [security2:error] [pid 514479:tid 514692] [client 20.197.195.24:8863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/chosen.php"] [unique_id "al9dBPzqsQqnLoCgUjiMdQAAAVg"]
[Tue Jul 21 08:50:28.748314 2026] [security2:error] [pid 514479:tid 514627] [client 20.151.10.161:62411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-load.php"] [unique_id "al9dBPzqsQqnLoCgUjiMfAAAARc"]
[Tue Jul 21 08:50:28.786388 2026] [security2:error] [pid 514479:tid 514489] [remote 45.79.123.44:44490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "manual.fernandohipolito.com.br"] [uri "/wp-login.php"] [unique_id "al9dBPzqsQqnLoCgUjiMfQABOAU"]
[Tue Jul 21 08:50:28.831635 2026] [security2:error] [pid 514479:tid 514619] [client 20.226.60.151:57574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/777.php"] [unique_id "al9dBPzqsQqnLoCgUjiMfwAAAQ8"]
[Tue Jul 21 08:50:28.937059 2026] [security2:error] [pid 511108:tid 511283] [client 203.25.124.32:42273] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/t.php"] [unique_id "al9dBITd5soprXwxAH0megAAAC0"]
[Tue Jul 21 08:50:28.968758 2026] [security2:error] [pid 514479:tid 514693] [client 203.25.124.43:61351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/css/dist/block-library/"] [unique_id "al9dBPzqsQqnLoCgUjiMggAAAVk"]
[Tue Jul 21 08:50:29.042299 2026] [security2:error] [pid 511108:tid 511361] [client 195.49.128.211:60903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dBYTd5soprXwxAH0mfQAAAHs"]
[Tue Jul 21 08:50:29.042428 2026] [security2:error] [pid 511108:tid 511361] [client 195.49.128.211:60903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dBYTd5soprXwxAH0mfQAAAHs"]
[Tue Jul 21 08:50:29.135823 2026] [security2:error] [pid 514479:tid 514731] [client 20.151.10.161:8326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/xwpg.php"] [unique_id "al9dBfzqsQqnLoCgUjiMgwAAAX8"]
[Tue Jul 21 08:50:29.173228 2026] [security2:error] [pid 514479:tid 514673] [client 20.104.96.117:3994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/root.php"] [unique_id "al9dBfzqsQqnLoCgUjiMhAAAAUU"]
[Tue Jul 21 08:50:29.180947 2026] [security2:error] [pid 514479:tid 514655] [client 20.104.96.117:59711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/mds.php"] [unique_id "al9dBfzqsQqnLoCgUjiMhQAAATM"]
[Tue Jul 21 08:50:29.370505 2026] [security2:error] [pid 511108:tid 511278] [client 203.25.124.189:26445] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/images/chosen.php"] [unique_id "al9dBYTd5soprXwxAH0mgwAAACg"]
[Tue Jul 21 08:50:29.386864 2026] [security2:error] [pid 514479:tid 514711] [client 213.152.162.15:52146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dBfzqsQqnLoCgUjiMiAAAAWs"]
[Tue Jul 21 08:50:29.386948 2026] [security2:error] [pid 514479:tid 514711] [client 213.152.162.15:52146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dBfzqsQqnLoCgUjiMiAAAAWs"]
[Tue Jul 21 08:50:29.525486 2026] [security2:error] [pid 514479:tid 514671] [client 182.77.72.76:5225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.72.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kianesantana.online"] [uri "/xmlrpc.php"] [unique_id "al9dBfzqsQqnLoCgUjiMiQAAAUM"]
[Tue Jul 21 08:50:29.525618 2026] [security2:error] [pid 514479:tid 514671] [client 182.77.72.76:5225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kianesantana.online"] [uri "/xmlrpc.php"] [unique_id "al9dBfzqsQqnLoCgUjiMiQAAAUM"]
[Tue Jul 21 08:50:29.531949 2026] [security2:error] [pid 514479:tid 514733] [client 20.197.195.24:63378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/cream1.php"] [unique_id "al9dBfzqsQqnLoCgUjiMigAAAYE"]
[Tue Jul 21 08:50:29.668530 2026] [security2:error] [pid 511108:tid 511307] [client 173.252.95.27:39330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dBYTd5soprXwxAH0miAAAAEU"]
[Tue Jul 21 08:50:29.769097 2026] [security2:error] [pid 511108:tid 511243] [client 41.89.234.2:57453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dBYTd5soprXwxAH0miQAAAAU"]
[Tue Jul 21 08:50:29.769205 2026] [security2:error] [pid 511108:tid 511243] [client 41.89.234.2:57453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dBYTd5soprXwxAH0miQAAAAU"]
[Tue Jul 21 08:50:29.914980 2026] [security2:error] [pid 511108:tid 511356] [client 20.151.10.161:8417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/waf.php"] [unique_id "al9dBYTd5soprXwxAH0mjgAAAHY"]
[Tue Jul 21 08:50:30.235224 2026] [security2:error] [pid 514479:tid 514622] [client 20.197.192.193:21891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/hp2.php"] [unique_id "al9dBvzqsQqnLoCgUjiMkgAAARI"]
[Tue Jul 21 08:50:30.270685 2026] [security2:error] [pid 514479:tid 514670] [client 203.25.124.39:38141] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/post-terms/"] [unique_id "al9dBvzqsQqnLoCgUjiMlAAAAUI"]
[Tue Jul 21 08:50:30.297791 2026] [security2:error] [pid 514479:tid 514636] [client 20.197.195.24:8860] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.tempex.com.br"] [uri "/wp-content/uploads/"] [unique_id "al9dBvzqsQqnLoCgUjiMlQAAASA"]
[Tue Jul 21 08:50:30.357428 2026] [security2:error] [pid 514479:tid 514686] [client 203.25.124.39:63165] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/html-api/chosen.php"] [unique_id "al9dBvzqsQqnLoCgUjiMlgAAAVI"]
[Tue Jul 21 08:50:30.396751 2026] [security2:error] [pid 514479:tid 514631] [client 20.151.10.161:8436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/xstelth.php"] [unique_id "al9dBvzqsQqnLoCgUjiMmgAAARs"]
[Tue Jul 21 08:50:30.439513 2026] [security2:error] [pid 514479:tid 514736] [client 173.252.95.33:56962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dBvzqsQqnLoCgUjiMkwAAAYQ"]
[Tue Jul 21 08:50:30.934967 2026] [security2:error] [pid 514479:tid 514568] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dBvzqsQqnLoCgUjiMpgABO1M"]
[Tue Jul 21 08:50:30.935097 2026] [security2:error] [pid 514479:tid 514663] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dBvzqsQqnLoCgUjiMpgABO1M"]
[Tue Jul 21 08:50:31.038030 2026] [security2:error] [pid 511108:tid 511241] [client 173.252.95.42:63370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dB4Td5soprXwxAH0mnAAAAAM"]
[Tue Jul 21 08:50:31.073450 2026] [security2:error] [pid 511108:tid 511258] [client 203.25.124.252:50621] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/css.php"] [unique_id "al9dB4Td5soprXwxAH0mngAAABQ"]
[Tue Jul 21 08:50:31.235227 2026] [security2:error] [pid 511108:tid 511318] [client 20.151.10.161:8443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-links.php"] [unique_id "al9dB4Td5soprXwxAH0mogAAAFA"]
[Tue Jul 21 08:50:31.639497 2026] [security2:error] [pid 514479:tid 514618] [client 203.25.124.71:39985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/css/dist/edit-post/"] [unique_id "al9dB_zqsQqnLoCgUjiMrQAAAQ4"]
[Tue Jul 21 08:50:31.658771 2026] [security2:error] [pid 511108:tid 511360] [client 20.197.192.193:38220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/hp3.php"] [unique_id "al9dB4Td5soprXwxAH0mpgAAAHo"]
[Tue Jul 21 08:50:31.684442 2026] [security2:error] [pid 511108:tid 511340] [client 65.21.113.253:59288] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dB4Td5soprXwxAH0mqAAAAGY"]
[Tue Jul 21 08:50:31.701783 2026] [security2:error] [pid 511108:tid 511347] [client 20.197.195.24:3309] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.tempex.com.br"] [uri "/wp-includes/Text/"] [unique_id "al9dB4Td5soprXwxAH0mqQAAAG0"]
[Tue Jul 21 08:50:31.799150 2026] [security2:error] [pid 511108:tid 511240] [client 173.252.95.17:45494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dB4Td5soprXwxAH0mqwAAAAI"]
[Tue Jul 21 08:50:31.873562 2026] [security2:error] [pid 514479:tid 514493] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dB_zqsQqnLoCgUjiMsQABcgk"]
[Tue Jul 21 08:50:31.873696 2026] [security2:error] [pid 514479:tid 514718] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dB_zqsQqnLoCgUjiMsQABcgk"]
[Tue Jul 21 08:50:31.926908 2026] [security2:error] [pid 511108:tid 511306] [client 20.220.225.223:46382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/inso.php"] [unique_id "al9dB4Td5soprXwxAH0mrgAAAEQ"]
[Tue Jul 21 08:50:31.962722 2026] [security2:error] [pid 511108:tid 511316] [client 198.44.157.34:39762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9dB4Td5soprXwxAH0mrwAAAE4"]
[Tue Jul 21 08:50:31.962805 2026] [security2:error] [pid 511108:tid 511316] [client 198.44.157.34:39762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9dB4Td5soprXwxAH0mrwAAAE4"]
[Tue Jul 21 08:50:32.035386 2026] [security2:error] [pid 514479:tid 514707] [client 20.151.10.161:62415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9dCPzqsQqnLoCgUjiMtgAAAWc"]
[Tue Jul 21 08:50:32.161146 2026] [security2:error] [pid 511108:tid 511335] [client 212.32.76.8:38269] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/b.php"] [unique_id "al9dCITd5soprXwxAH0msAAAAGE"]
[Tue Jul 21 08:50:32.164524 2026] [security2:error] [pid 514479:tid 514650] [client 20.104.96.117:59660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-blink.php"] [unique_id "al9dCPzqsQqnLoCgUjiMuAAAAS4"]
[Tue Jul 21 08:50:32.286277 2026] [security2:error] [pid 511108:tid 511361] [client 20.197.192.193:38222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/aa1.php"] [unique_id "al9dCITd5soprXwxAH0mtAAAAHs"]
[Tue Jul 21 08:50:32.372103 2026] [security2:error] [pid 514479:tid 514660] [client 212.32.76.60:38233] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "al9dCPzqsQqnLoCgUjiMvgAAATg"]
[Tue Jul 21 08:50:32.756767 2026] [security2:error] [pid 514479:tid 514715] [client 65.21.113.253:53180] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dCPzqsQqnLoCgUjiMvQAAAW8"]
[Tue Jul 21 08:50:32.831982 2026] [security2:error] [pid 514479:tid 514659] [client 203.25.124.47:63815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/plugin/"] [unique_id "al9dCPzqsQqnLoCgUjiMxwAAATc"]
[Tue Jul 21 08:50:32.877399 2026] [security2:error] [pid 514479:tid 514687] [client 136.144.42.179:34199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.42.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiferreira.com.br"] [uri "/wp-login.php"] [unique_id "al9dCPzqsQqnLoCgUjiMyAAAAVM"]
[Tue Jul 21 08:50:32.954920 2026] [security2:error] [pid 511108:tid 511260] [client 20.226.60.151:59766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/for.php"] [unique_id "al9dCITd5soprXwxAH0mvAAAABY"]
[Tue Jul 21 08:50:32.971529 2026] [security2:error] [pid 511108:tid 511194] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dCITd5soprXwxAH0mvQAAc1U"]
[Tue Jul 21 08:50:32.971672 2026] [security2:error] [pid 511108:tid 511353] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dCITd5soprXwxAH0mvQAAc1U"]
[Tue Jul 21 08:50:33.052528 2026] [security2:error] [pid 514479:tid 514692] [client 113.22.144.139:55275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dCfzqsQqnLoCgUjiMywAAAVg"]
[Tue Jul 21 08:50:33.052629 2026] [security2:error] [pid 514479:tid 514692] [client 113.22.144.139:55275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dCfzqsQqnLoCgUjiMywAAAVg"]
[Tue Jul 21 08:50:33.333043 2026] [security2:error] [pid 511108:tid 511292] [client 20.151.10.161:62370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.eduhenmac.com.br"] [uri "/aaa.php"] [unique_id "al9dCYTd5soprXwxAH0mxgAAADY"]
[Tue Jul 21 08:50:33.471117 2026] [security2:error] [pid 514479:tid 514671] [client 203.25.124.246:34351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/advanced-product-fields-for-woocommerce/db.php"] [unique_id "al9dCfzqsQqnLoCgUjiM0AAAAUM"]
[Tue Jul 21 08:50:33.546201 2026] [security2:error] [pid 514479:tid 514490] [remote 156.67.31.167:41526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9dCfzqsQqnLoCgUjiM0QABWwY"]
[Tue Jul 21 08:50:33.815848 2026] [security2:error] [pid 514479:tid 514531] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dCfzqsQqnLoCgUjiM1QABVi8"]
[Tue Jul 21 08:50:33.815985 2026] [security2:error] [pid 514479:tid 514690] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dCfzqsQqnLoCgUjiM1QABVi8"]
[Tue Jul 21 08:50:33.825100 2026] [security2:error] [pid 514479:tid 514730] [client 182.189.99.211:47959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dCfzqsQqnLoCgUjiM1gAAAX4"]
[Tue Jul 21 08:50:33.825183 2026] [security2:error] [pid 514479:tid 514730] [client 182.189.99.211:47959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dCfzqsQqnLoCgUjiM1gAAAX4"]
[Tue Jul 21 08:50:34.048172 2026] [core:error] [pid 514479:tid 514722] [client 66.249.66.68:36703] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:50:34.048196 2026] [core:error] [pid 514479:tid 514722] [client 66.249.66.68:36703] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:50:34.060032 2026] [security2:error] [pid 514479:tid 514720] [client 20.197.192.193:50575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/csa.php"] [unique_id "al9dCvzqsQqnLoCgUjiM2AAAAXQ"]
[Tue Jul 21 08:50:34.193354 2026] [security2:error] [pid 511108:tid 511304] [client 195.206.105.227:39426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9dCoTd5soprXwxAH0m0AAAAEI"]
[Tue Jul 21 08:50:34.193448 2026] [security2:error] [pid 511108:tid 511304] [client 195.206.105.227:39426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9dCoTd5soprXwxAH0m0AAAAEI"]
[Tue Jul 21 08:50:34.263029 2026] [security2:error] [pid 514479:tid 514725] [client 20.197.192.193:22345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/acew67.php"] [unique_id "al9dCvzqsQqnLoCgUjiM3QAAAXk"]
[Tue Jul 21 08:50:34.336183 2026] [security2:error] [pid 511108:tid 511191] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dCoTd5soprXwxAH0m1gAAQ1I"]
[Tue Jul 21 08:50:34.336442 2026] [security2:error] [pid 511108:tid 511305] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dCoTd5soprXwxAH0m1gAAQ1I"]
[Tue Jul 21 08:50:34.377016 2026] [security2:error] [pid 514479:tid 514713] [client 20.104.96.117:61142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/zc-208.php"] [unique_id "al9dCvzqsQqnLoCgUjiM6AAAAW0"]
[Tue Jul 21 08:50:34.379777 2026] [security2:error] [pid 514479:tid 514707] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dCvzqsQqnLoCgUjiM3gABZ1I"]
[Tue Jul 21 08:50:34.420302 2026] [security2:error] [pid 514479:tid 514660] [client 20.197.195.24:3303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/dr.php"] [unique_id "al9dCvzqsQqnLoCgUjiM6gAAATg"]
[Tue Jul 21 08:50:34.478366 2026] [security2:error] [pid 514479:tid 514663] [client 168.167.81.163:65120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dCvzqsQqnLoCgUjiM6wAAATs"]
[Tue Jul 21 08:50:34.478502 2026] [security2:error] [pid 514479:tid 514663] [client 168.167.81.163:65120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dCvzqsQqnLoCgUjiM6wAAATs"]
[Tue Jul 21 08:50:34.559829 2026] [security2:error] [pid 514479:tid 514680] [client 203.25.124.70:55585] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/blocks/audio/"] [unique_id "al9dCvzqsQqnLoCgUjiM8AAAAUw"]
[Tue Jul 21 08:50:34.576536 2026] [security2:error] [pid 514479:tid 514735] [client 203.25.124.193:20299] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/wp.php"] [unique_id "al9dCvzqsQqnLoCgUjiM8gAAAYM"]
[Tue Jul 21 08:50:34.847615 2026] [security2:error] [pid 514479:tid 514542] [remote 120.72.98.5:13534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.98.72.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fisiopelvicafloripa.com.br"] [uri "/wp-login.php"] [unique_id "al9dCvzqsQqnLoCgUjiNCwABTTo"]
[Tue Jul 21 08:50:35.228967 2026] [security2:error] [pid 514479:tid 514700] [client 20.197.192.193:56802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/min.php"] [unique_id "al9dC_zqsQqnLoCgUjiNlgAAAWA"]
[Tue Jul 21 08:50:35.231843 2026] [security2:error] [pid 514479:tid 514713] [client 20.197.192.193:22366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/bscclapb.php"] [unique_id "al9dC_zqsQqnLoCgUjiNlwAAAW0"]
[Tue Jul 21 08:50:35.561742 2026] [security2:error] [pid 514479:tid 514672] [client 203.25.124.50:26621] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/class-db.php"] [unique_id "al9dC_zqsQqnLoCgUjiNtAAAAUQ"]
[Tue Jul 21 08:50:35.673195 2026] [security2:error] [pid 514479:tid 514618] [client 203.25.124.189:30739] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/tinyfilemanager.php"] [unique_id "al9dC_zqsQqnLoCgUjiNtwAAAQ4"]
[Tue Jul 21 08:50:35.744968 2026] [security2:error] [pid 514479:tid 514647] [client 20.197.192.193:50617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/echkm.php"] [unique_id "al9dC_zqsQqnLoCgUjiNuwAAASs"]
[Tue Jul 21 08:50:36.020089 2026] [access_compat:error] [pid 514479:tid 514686] [client 43.130.60.195:0] AH01797: client denied by server configuration: /home4/fabi0417/powerflats.com.br/index.php4
[Tue Jul 21 08:50:36.042301 2026] [security2:error] [pid 511108:tid 511278] [client 65.21.113.253:59288] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dDITd5soprXwxAH0m-QAAACg"]
[Tue Jul 21 08:50:36.149516 2026] [security2:error] [pid 511108:tid 511264] [client 198.44.157.34:48162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9dDITd5soprXwxAH0m-gAAABo"]
[Tue Jul 21 08:50:36.149613 2026] [security2:error] [pid 511108:tid 511264] [client 198.44.157.34:48162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9dDITd5soprXwxAH0m-gAAABo"]
[Tue Jul 21 08:50:36.169161 2026] [security2:error] [pid 514479:tid 514616] [client 198.44.157.34:39768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9dDPzqsQqnLoCgUjiNwwAAAQw"]
[Tue Jul 21 08:50:36.169231 2026] [security2:error] [pid 514479:tid 514616] [client 198.44.157.34:39768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9dDPzqsQqnLoCgUjiNwwAAAQw"]
[Tue Jul 21 08:50:36.240023 2026] [security2:error] [pid 514479:tid 514710] [client 203.25.124.213:44811] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/tinymce/langs/"] [unique_id "al9dDPzqsQqnLoCgUjiNxwAAAWo"]
[Tue Jul 21 08:50:36.359866 2026] [security2:error] [pid 514479:tid 514645] [client 212.32.76.4:60857] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/readme.php"] [unique_id "al9dDPzqsQqnLoCgUjiNywAAASk"]
[Tue Jul 21 08:50:36.445358 2026] [security2:error] [pid 514479:tid 514665] [client 114.198.138.124:51987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dDPzqsQqnLoCgUjiNzQAAAT0"]
[Tue Jul 21 08:50:36.445469 2026] [security2:error] [pid 514479:tid 514665] [client 114.198.138.124:51987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dDPzqsQqnLoCgUjiNzQAAAT0"]
[Tue Jul 21 08:50:36.514919 2026] [security2:error] [pid 514479:tid 514680] [client 20.197.192.193:50603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/mac.php"] [unique_id "al9dDPzqsQqnLoCgUjiNzwAAAUw"]
[Tue Jul 21 08:50:36.564706 2026] [security2:error] [pid 514479:tid 514715] [client 47.128.17.36:16158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "agencia.aede.com.br"] [uri "/robots.txt"] [unique_id "al9dDPzqsQqnLoCgUjiN0QAAAW8"]
[Tue Jul 21 08:50:36.832975 2026] [security2:error] [pid 514479:tid 514669] [client 20.197.195.24:8842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/x.php"] [unique_id "al9dDPzqsQqnLoCgUjiN1AAAAUE"]
[Tue Jul 21 08:50:36.914937 2026] [security2:error] [pid 511108:tid 511230] [remote 45.79.123.44:37102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cezaretto.com.br"] [uri "/wp-login.php"] [unique_id "al9dDITd5soprXwxAH0nBAAAR3k"]
[Tue Jul 21 08:50:36.937679 2026] [security2:error] [pid 511108:tid 511298] [client 203.25.124.2:57733] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/query-pagination-previous/"] [unique_id "al9dDITd5soprXwxAH0nBgAAADw"]
[Tue Jul 21 08:50:36.960490 2026] [security2:error] [pid 511108:tid 511245] [client 59.95.197.55:54944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dDITd5soprXwxAH0nCAAAAAc"]
[Tue Jul 21 08:50:36.962396 2026] [security2:error] [pid 511108:tid 511245] [client 59.95.197.55:54944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dDITd5soprXwxAH0nCAAAAAc"]
[Tue Jul 21 08:50:36.974862 2026] [security2:error] [pid 511108:tid 511269] [client 203.25.124.200:49289] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9dDITd5soprXwxAH0nCQAAAB8"]
[Tue Jul 21 08:50:37.063027 2026] [security2:error] [pid 514479:tid 514732] [client 198.44.157.34:48176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9dDfzqsQqnLoCgUjiN2AAAAYA"]
[Tue Jul 21 08:50:37.063167 2026] [security2:error] [pid 514479:tid 514732] [client 198.44.157.34:48176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9dDfzqsQqnLoCgUjiN2AAAAYA"]
[Tue Jul 21 08:50:37.066867 2026] [security2:error] [pid 511108:tid 511304] [client 20.104.96.117:61155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/sid4.php"] [unique_id "al9dDYTd5soprXwxAH0nCgAAAEI"]
[Tue Jul 21 08:50:37.092097 2026] [security2:error] [pid 511108:tid 511256] [client 65.21.113.253:53188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dDITd5soprXwxAH0nAQAAABI"]
[Tue Jul 21 08:50:37.115496 2026] [security2:error] [pid 511108:tid 511292] [client 122.176.100.127:56685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dDYTd5soprXwxAH0nCwAAADY"]
[Tue Jul 21 08:50:37.116140 2026] [security2:error] [pid 511108:tid 511292] [client 122.176.100.127:56685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dDYTd5soprXwxAH0nCwAAADY"]
[Tue Jul 21 08:50:37.351093 2026] [security2:error] [pid 514479:tid 514617] [client 20.197.192.193:50595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/samll.php"] [unique_id "al9dDfzqsQqnLoCgUjiN3QAAAQ0"]
[Tue Jul 21 08:50:37.740777 2026] [security2:error] [pid 514479:tid 514696] [client 20.226.60.151:57640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/ssla.php"] [unique_id "al9dDfzqsQqnLoCgUjiN4wAAAVw"]
[Tue Jul 21 08:50:37.782289 2026] [access_compat:error] [pid 514479:tid 514647] [client 43.130.60.195:0] AH01797: client denied by server configuration: /home4/fabi0417/powerflats.com.br/index.php4, referer: http://powerflats.com.br
[Tue Jul 21 08:50:37.979009 2026] [security2:error] [pid 511108:tid 511296] [client 49.144.66.253:32821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dDYTd5soprXwxAH0nHAAAADo"]
[Tue Jul 21 08:50:37.979117 2026] [security2:error] [pid 511108:tid 511296] [client 49.144.66.253:32821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dDYTd5soprXwxAH0nHAAAADo"]
[Tue Jul 21 08:50:38.141504 2026] [security2:error] [pid 511108:tid 511340] [client 203.25.124.72:41093] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Requests/src/Auth/"] [unique_id "al9dDoTd5soprXwxAH0nHgAAAGY"]
[Tue Jul 21 08:50:38.278612 2026] [security2:error] [pid 511108:tid 511281] [client 203.25.124.193:54159] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/Simple.php"] [unique_id "al9dDoTd5soprXwxAH0nJQAAACs"]
[Tue Jul 21 08:50:38.293887 2026] [autoindex:error] [pid 511108:tid 511306] [client 35.231.134.63:51798] AH01276: Cannot serve directory /home4/dralul00/moniquemenezes.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:50:38.458348 2026] [security2:error] [pid 511108:tid 511337] [client 212.32.76.2:43117] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/files/index.php"] [unique_id "al9dDoTd5soprXwxAH0nKgAAAGM"]
[Tue Jul 21 08:50:38.526914 2026] [autoindex:error] [pid 514479:tid 514713] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/andr8586/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:50:38.612276 2026] [autoindex:error] [pid 511108:tid 511342] [client 35.231.134.63:51798] AH01276: Cannot serve directory /home4/dralul00/moniquemenezes.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:50:38.613804 2026] [security2:error] [pid 511108:tid 511358] [client 20.197.192.193:22342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/else1.php"] [unique_id "al9dDoTd5soprXwxAH0nLgAAAHg"]
[Tue Jul 21 08:50:38.782806 2026] [security2:error] [pid 514479:tid 514674] [client 20.197.195.24:3274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/155.php"] [unique_id "al9dDvzqsQqnLoCgUjiN8QAAAUY"]
[Tue Jul 21 08:50:38.793387 2026] [security2:error] [pid 511108:tid 511353] [client 35.231.134.63:51798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9dDoTd5soprXwxAH0nMgAAAHM"]
[Tue Jul 21 08:50:38.798658 2026] [autoindex:error] [pid 511108:tid 511307] [client 205.210.31.133:65438] AH01276: Cannot serve directory /home3/factor11/atracta.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:50:38.880130 2026] [security2:error] [pid 514479:tid 514665] [client 74.7.228.20:51644] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "protetordegraxa.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9dDvzqsQqnLoCgUjiN9wABPXU"]
[Tue Jul 21 08:50:38.932746 2026] [security2:error] [pid 511108:tid 511352] [client 5.38.115.39:36930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dDoTd5soprXwxAH0nNAAAAHI"]
[Tue Jul 21 08:50:38.932945 2026] [security2:error] [pid 511108:tid 511352] [client 5.38.115.39:36930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dDoTd5soprXwxAH0nNAAAAHI"]
[Tue Jul 21 08:50:39.079569 2026] [security2:error] [pid 511108:tid 511325] [client 74.7.244.34:45014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.prostadine.shop-officialstore.com"] [uri "/index.php"] [unique_id "al9dDoTd5soprXwxAH0nKQAAVxk"]
[Tue Jul 21 08:50:39.100495 2026] [security2:error] [pid 514479:tid 514659] [client 20.197.192.193:52710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/abcd.php"] [unique_id "al9dD_zqsQqnLoCgUjiN-wAAATc"]
[Tue Jul 21 08:50:39.154937 2026] [security2:error] [pid 514479:tid 514692] [client 35.231.134.63:64625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.134.231.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/xmlrpc.php"] [unique_id "al9dD_zqsQqnLoCgUjiN_QAAAVg"]
[Tue Jul 21 08:50:39.169255 2026] [security2:error] [pid 511108:tid 511265] [client 196.171.16.187:63517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.16.171.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suora.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dD4Td5soprXwxAH0nNgAAABs"]
[Tue Jul 21 08:50:39.169432 2026] [security2:error] [pid 511108:tid 511265] [client 196.171.16.187:63517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "suora.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dD4Td5soprXwxAH0nNgAAABs"]
[Tue Jul 21 08:50:39.379867 2026] [security2:error] [pid 514479:tid 514618] [client 20.226.60.151:57569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mucareis.com.br"] [uri "/zc-131.php"] [unique_id "al9dD_zqsQqnLoCgUjiOAQAAAQ4"]
[Tue Jul 21 08:50:39.388652 2026] [security2:error] [pid 514479:tid 514620] [client 20.220.225.223:19972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9dD_zqsQqnLoCgUjiOAgAAARA"]
[Tue Jul 21 08:50:39.489289 2026] [autoindex:error] [pid 514479:tid 514727] [client 35.231.134.63:62405] AH01276: Cannot serve directory /home4/dralul00/moniquemenezes.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:50:39.491385 2026] [security2:error] [pid 514479:tid 514560] [remote 41.186.86.12:40700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9dD_zqsQqnLoCgUjiOBAABS0s"]
[Tue Jul 21 08:50:39.542124 2026] [security2:error] [pid 514479:tid 514688] [client 203.25.124.65:41943] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/wp.php"] [unique_id "al9dD_zqsQqnLoCgUjiOBQAAAVQ"]
[Tue Jul 21 08:50:39.572802 2026] [security2:error] [pid 514479:tid 514696] [client 212.32.76.66:43699] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/index.php"] [unique_id "al9dD_zqsQqnLoCgUjiOBwAAAVw"]
[Tue Jul 21 08:50:39.584083 2026] [security2:error] [pid 511108:tid 511292] [client 20.104.96.117:59687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wmore1.php"] [unique_id "al9dD4Td5soprXwxAH0nQAAAADY"]
[Tue Jul 21 08:50:39.640650 2026] [security2:error] [pid 511108:tid 511222] [remote 74.7.244.34:45026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "prostadine.shop-officialstore.com"] [uri "/index.php"] [unique_id "al9dD4Td5soprXwxAH0nQQAAPHE"], referer: https://www.prostadine.shop-officialstore.com/robots.txt
[Tue Jul 21 08:50:39.641066 2026] [security2:error] [pid 511108:tid 511310] [client 195.49.128.211:61565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dD4Td5soprXwxAH0nQgAAAEg"]
[Tue Jul 21 08:50:39.641164 2026] [security2:error] [pid 511108:tid 511310] [client 195.49.128.211:61565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dD4Td5soprXwxAH0nQgAAAEg"]
[Tue Jul 21 08:50:39.677313 2026] [security2:error] [pid 514479:tid 514722] [client 203.25.124.213:40681] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "al9dD_zqsQqnLoCgUjiOCgAAAXY"]
[Tue Jul 21 08:50:39.932038 2026] [security2:error] [pid 514479:tid 514740] [client 35.231.134.63:62405] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9dD_zqsQqnLoCgUjiODAAAAYg"]
[Tue Jul 21 08:50:39.971472 2026] [security2:error] [pid 514479:tid 514619] [client 103.59.206.240:31396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dD_zqsQqnLoCgUjiODQAAAQ8"]
[Tue Jul 21 08:50:39.971559 2026] [security2:error] [pid 514479:tid 514619] [client 103.59.206.240:31396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dD_zqsQqnLoCgUjiODQAAAQ8"]
[Tue Jul 21 08:50:40.075883 2026] [security2:error] [pid 511108:tid 511338] [client 198.44.157.34:42462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dEITd5soprXwxAH0nSwAAAGQ"]
[Tue Jul 21 08:50:40.075997 2026] [security2:error] [pid 511108:tid 511338] [client 198.44.157.34:42462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dEITd5soprXwxAH0nSwAAAGQ"]
[Tue Jul 21 08:50:40.166715 2026] [security2:error] [pid 514479:tid 514674] [client 20.104.96.117:4079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/sym403.php"] [unique_id "al9dEPzqsQqnLoCgUjiOEAAAAUY"]
[Tue Jul 21 08:50:40.168056 2026] [security2:error] [pid 511108:tid 511255] [client 20.197.192.193:38232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/tkikikoko.php"] [unique_id "al9dEITd5soprXwxAH0nTgAAABE"]
[Tue Jul 21 08:50:40.187264 2026] [security2:error] [pid 511108:tid 511324] [client 35.231.134.63:57800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9dEITd5soprXwxAH0nTwAAAFY"]
[Tue Jul 21 08:50:40.294369 2026] [security2:error] [pid 514479:tid 514720] [client 41.89.234.2:49119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dEPzqsQqnLoCgUjiOEwAAAXQ"]
[Tue Jul 21 08:50:40.294582 2026] [security2:error] [pid 514479:tid 514720] [client 41.89.234.2:49119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dEPzqsQqnLoCgUjiOEwAAAXQ"]
[Tue Jul 21 08:50:40.384404 2026] [security2:error] [pid 514479:tid 514559] [remote 167.71.218.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/wp-login.php"] [unique_id "al9dEPzqsQqnLoCgUjiOFAABF0o"]
[Tue Jul 21 08:50:40.422419 2026] [security2:error] [pid 511108:tid 511289] [client 65.21.113.253:59288] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dEITd5soprXwxAH0nVAAAADM"]
[Tue Jul 21 08:50:40.545074 2026] [security2:error] [pid 514479:tid 514709] [client 35.231.134.63:57748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9dEPzqsQqnLoCgUjiOGwAAAWk"]
[Tue Jul 21 08:50:40.766675 2026] [security2:error] [pid 514479:tid 514733] [client 20.197.195.24:62767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/ops.php"] [unique_id "al9dEPzqsQqnLoCgUjiOHQAAAYE"]
[Tue Jul 21 08:50:40.844594 2026] [security2:error] [pid 514479:tid 514634] [client 203.25.124.57:50199] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/news-portal/sitebar.php"] [unique_id "al9dEPzqsQqnLoCgUjiOHwAAAR4"]
[Tue Jul 21 08:50:40.864804 2026] [security2:error] [pid 511108:tid 511276] [client 203.25.124.53:49437] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/js/"] [unique_id "al9dEITd5soprXwxAH0nWgAAACY"]
[Tue Jul 21 08:50:40.872906 2026] [security2:error] [pid 514479:tid 514679] [client 203.25.124.207:30749] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/storage/framework/views/shell.php"] [unique_id "al9dEPzqsQqnLoCgUjiOIQAAAUs"]
[Tue Jul 21 08:50:40.876265 2026] [security2:error] [pid 514479:tid 514646] [client 35.231.134.63:62229] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9dEPzqsQqnLoCgUjiOIgAAASo"]
[Tue Jul 21 08:50:40.900166 2026] [security2:error] [pid 514479:tid 514730] [client 20.197.192.193:38263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9dEPzqsQqnLoCgUjiOJAAAAX4"]
[Tue Jul 21 08:50:41.182775 2026] [security2:error] [pid 514479:tid 514726] [client 20.197.192.193:22356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/wp-css.php"] [unique_id "al9dEfzqsQqnLoCgUjiOLAAAAXo"]
[Tue Jul 21 08:50:41.198308 2026] [security2:error] [pid 514479:tid 514678] [client 35.231.134.63:49491] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9dEfzqsQqnLoCgUjiOLQAAAUo"]
[Tue Jul 21 08:50:41.423748 2026] [security2:error] [pid 514479:tid 514713] [client 20.197.195.24:3257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/file31.php"] [unique_id "al9dEfzqsQqnLoCgUjiOLgAAAW0"]
[Tue Jul 21 08:50:41.456189 2026] [security2:error] [pid 514479:tid 514702] [client 114.119.155.83:42867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "beautyline.com.br"] [uri "/favicon.ico"] [unique_id "al9dEfzqsQqnLoCgUjiOLwAAAWI"], referer: https://beautyline.com.br/favicon.ico
[Tue Jul 21 08:50:41.484689 2026] [security2:error] [pid 511108:tid 511325] [client 20.197.192.193:22343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/wp-explorer.php"] [unique_id "al9dEYTd5soprXwxAH0nYwAAAFc"]
[Tue Jul 21 08:50:41.535921 2026] [security2:error] [pid 514479:tid 514526] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dEfzqsQqnLoCgUjiOMwABOio"]
[Tue Jul 21 08:50:41.536089 2026] [security2:error] [pid 514479:tid 514662] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dEfzqsQqnLoCgUjiOMwABOio"]
[Tue Jul 21 08:50:41.536235 2026] [security2:error] [pid 514479:tid 514727] [client 65.21.113.253:49782] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dEfzqsQqnLoCgUjiOKwAAAXs"]
[Tue Jul 21 08:50:41.552876 2026] [security2:error] [pid 511108:tid 511247] [client 35.231.134.63:62060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9dEYTd5soprXwxAH0nagAAAAk"]
[Tue Jul 21 08:50:41.776276 2026] [security2:error] [pid 514479:tid 514670] [client 20.197.192.193:22347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/akismet.php"] [unique_id "al9dEfzqsQqnLoCgUjiOTQAAAUI"]
[Tue Jul 21 08:50:41.856611 2026] [security2:error] [pid 514479:tid 514628] [client 35.231.134.63:56960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9dEfzqsQqnLoCgUjiOTgAAARg"]
[Tue Jul 21 08:50:41.943515 2026] [security2:error] [pid 514479:tid 514717] [client 20.197.195.24:63420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/file6.php"] [unique_id "al9dEfzqsQqnLoCgUjiOUQAAAXE"]
[Tue Jul 21 08:50:42.048797 2026] [security2:error] [pid 514479:tid 514662] [client 203.25.124.40:26661] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/database.php"] [unique_id "al9dEvzqsQqnLoCgUjiOVgAAATo"]
[Tue Jul 21 08:50:42.111113 2026] [security2:error] [pid 514479:tid 514690] [client 35.231.134.63:51698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9dEvzqsQqnLoCgUjiOVwAAAVY"]
[Tue Jul 21 08:50:42.163356 2026] [security2:error] [pid 511108:tid 511359] [client 203.25.124.73:38759] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-includes/Requests/library/"] [unique_id "al9dEoTd5soprXwxAH0nfwAAAHk"]
[Tue Jul 21 08:50:42.174845 2026] [security2:error] [pid 514479:tid 514720] [client 203.25.124.209:21451] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/tinyfilemanager/tinyfilemanager.php"] [unique_id "al9dEvzqsQqnLoCgUjiOWwAAAXQ"]
[Tue Jul 21 08:50:42.247232 2026] [security2:error] [pid 514479:tid 514568] [remote 45.76.153.27:57576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.153.76.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "formaesplendida.com"] [uri "/wp-login.php"] [unique_id "al9dEvzqsQqnLoCgUjiOXQABfVM"]
[Tue Jul 21 08:50:42.337025 2026] [security2:error] [pid 511108:tid 511338] [client 20.197.192.193:38255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/ace2.php"] [unique_id "al9dEoTd5soprXwxAH0ngAAAAGQ"]
[Tue Jul 21 08:50:42.343775 2026] [security2:error] [pid 511108:tid 511364] [client 20.197.195.24:3283] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.tempex.com.br"] [uri "/wp-includes/assets/"] [unique_id "al9dEoTd5soprXwxAH0ngQAAAH4"]
[Tue Jul 21 08:50:42.372717 2026] [security2:error] [pid 514479:tid 514537] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dEvzqsQqnLoCgUjiOYAABezU"]
[Tue Jul 21 08:50:42.372916 2026] [security2:error] [pid 514479:tid 514727] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dEvzqsQqnLoCgUjiOYAABezU"]
[Tue Jul 21 08:50:42.466877 2026] [security2:error] [pid 511108:tid 511255] [client 35.231.134.63:60639] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9dEoTd5soprXwxAH0nggAAABE"]
[Tue Jul 21 08:50:42.617001 2026] [security2:error] [pid 514479:tid 514732] [client 20.197.195.24:63365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/adminfuns.php"] [unique_id "al9dEvzqsQqnLoCgUjiOZgAAAYA"]
[Tue Jul 21 08:50:42.750351 2026] [security2:error] [pid 511108:tid 511272] [client 35.231.134.63:64229] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9dEoTd5soprXwxAH0njAAAACI"]
[Tue Jul 21 08:50:42.880001 2026] [security2:error] [pid 514479:tid 514735] [client 173.252.95.1:48438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dEvzqsQqnLoCgUjiOaQAAAYM"]
[Tue Jul 21 08:50:42.903507 2026] [security2:error] [pid 514479:tid 514738] [client 201.20.89.75:53776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.89.20.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dEvzqsQqnLoCgUjiOaAAAAYY"]
[Tue Jul 21 08:50:42.903655 2026] [security2:error] [pid 514479:tid 514738] [client 201.20.89.75:53776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dEvzqsQqnLoCgUjiOaAAAAYY"]
[Tue Jul 21 08:50:43.053971 2026] [security2:error] [pid 514479:tid 514640] [client 35.231.134.63:61230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9dE_zqsQqnLoCgUjiObAAAASQ"]
[Tue Jul 21 08:50:43.231918 2026] [security2:error] [pid 511108:tid 511331] [client 20.197.195.24:3218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/goods.php"] [unique_id "al9dE4Td5soprXwxAH0nkgAAAF0"]
[Tue Jul 21 08:50:43.279430 2026] [security2:error] [pid 511108:tid 511312] [client 203.25.124.10:60125] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/shell.php"] [unique_id "al9dE4Td5soprXwxAH0nlAAAAEo"]
[Tue Jul 21 08:50:43.284655 2026] [security2:error] [pid 511108:tid 511358] [client 20.197.192.193:22364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.expovilhena.com.br"] [uri "/ms.php"] [unique_id "al9dE4Td5soprXwxAH0nlQAAAHg"]
[Tue Jul 21 08:50:43.332751 2026] [security2:error] [pid 511108:tid 511344] [client 35.231.134.63:60238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9dE4Td5soprXwxAH0nlwAAAGo"]
[Tue Jul 21 08:50:43.437377 2026] [security2:error] [pid 511108:tid 511279] [client 203.25.124.211:30885] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/login.php"] [unique_id "al9dE4Td5soprXwxAH0nmwAAACk"]
[Tue Jul 21 08:50:43.466669 2026] [security2:error] [pid 514479:tid 514648] [client 203.25.124.72:65193] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/twentytwentyfour/"] [unique_id "al9dE_zqsQqnLoCgUjiOdAAAASw"]
[Tue Jul 21 08:50:43.592426 2026] [security2:error] [pid 514479:tid 514693] [client 20.197.195.24:63370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/100.php"] [unique_id "al9dE_zqsQqnLoCgUjiOeAAAAVk"]
[Tue Jul 21 08:50:43.615212 2026] [security2:error] [pid 514479:tid 514524] [remote 41.186.86.12:44800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9dE_zqsQqnLoCgUjiOegABXig"]
[Tue Jul 21 08:50:43.615393 2026] [security2:error] [pid 514479:tid 514698] [client 41.186.86.12:44800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9dE_zqsQqnLoCgUjiOegABXig"]
[Tue Jul 21 08:50:43.640988 2026] [security2:error] [pid 511108:tid 511285] [client 35.231.134.63:59982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9dE4Td5soprXwxAH0noQAAAC8"]
[Tue Jul 21 08:50:43.731715 2026] [security2:error] [pid 514479:tid 514636] [client 74.7.175.166:55108] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.app.arkos.ia.br"] [uri "/cgi-sys/404.html"] [unique_id "al9dE_zqsQqnLoCgUjiOewABIHc"]
[Tue Jul 21 08:50:43.836709 2026] [security2:error] [pid 514479:tid 514528] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dE_zqsQqnLoCgUjiOfgABVCw"]
[Tue Jul 21 08:50:43.836927 2026] [security2:error] [pid 514479:tid 514688] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dE_zqsQqnLoCgUjiOfgABVCw"]
[Tue Jul 21 08:50:44.062352 2026] [security2:error] [pid 511108:tid 511302] [client 35.231.134.63:50556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9dFITd5soprXwxAH0npwAAAEA"]
[Tue Jul 21 08:50:44.071207 2026] [core:error] [pid 514479:tid 514527] [remote 82.102.18.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:50:44.071233 2026] [core:error] [pid 514479:tid 514527] [remote 82.102.18.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:50:44.106293 2026] [security2:error] [pid 514479:tid 514657] [client 213.152.162.15:41094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9dFPzqsQqnLoCgUjiOhAAAATU"]
[Tue Jul 21 08:50:44.106386 2026] [security2:error] [pid 514479:tid 514657] [client 213.152.162.15:41094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9dFPzqsQqnLoCgUjiOhAAAATU"]
[Tue Jul 21 08:50:44.163021 2026] [security2:error] [pid 511108:tid 511247] [client 113.22.144.139:55810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dFITd5soprXwxAH0nrAAAAAk"]
[Tue Jul 21 08:50:44.163782 2026] [security2:error] [pid 511108:tid 511247] [client 113.22.144.139:55810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dFITd5soprXwxAH0nrAAAAAk"]
[Tue Jul 21 08:50:44.184055 2026] [security2:error] [pid 514479:tid 514700] [client 20.220.225.223:19973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9dFPzqsQqnLoCgUjiOhwAAAWA"]
[Tue Jul 21 08:50:44.252272 2026] [security2:error] [pid 514479:tid 514515] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9dFPzqsQqnLoCgUjiOiwABRh8"]
[Tue Jul 21 08:50:44.317743 2026] [security2:error] [pid 514479:tid 514616] [client 182.189.99.211:47697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dFPzqsQqnLoCgUjiOjAAAAQw"]
[Tue Jul 21 08:50:44.318405 2026] [security2:error] [pid 514479:tid 514616] [client 182.189.99.211:47697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dFPzqsQqnLoCgUjiOjAAAAQw"]
[Tue Jul 21 08:50:44.347610 2026] [security2:error] [pid 514479:tid 514502] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dFPzqsQqnLoCgUjiOjQABXxI"]
[Tue Jul 21 08:50:44.350051 2026] [security2:error] [pid 514479:tid 514699] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dFPzqsQqnLoCgUjiOjQABXxI"]
[Tue Jul 21 08:50:44.354875 2026] [security2:error] [pid 511108:tid 511342] [client 168.167.81.163:64126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dFITd5soprXwxAH0nsAAAAGg"]
[Tue Jul 21 08:50:44.355054 2026] [security2:error] [pid 511108:tid 511342] [client 168.167.81.163:64126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dFITd5soprXwxAH0nsAAAAGg"]
[Tue Jul 21 08:50:44.445361 2026] [security2:error] [pid 514479:tid 514735] [client 35.231.134.63:49301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "moniquemenezes.com.dralulmabhering.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9dFPzqsQqnLoCgUjiOjgAAAYM"]
[Tue Jul 21 08:50:44.464036 2026] [security2:error] [pid 514479:tid 514738] [client 20.220.225.223:22563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/wpx.php"] [unique_id "al9dFPzqsQqnLoCgUjiOjwAAAYY"]
[Tue Jul 21 08:50:44.662836 2026] [security2:error] [pid 514479:tid 514709] [client 212.32.76.10:63149] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-content/themes/radio.php"] [unique_id "al9dFPzqsQqnLoCgUjiOkwAAAWk"]
[Tue Jul 21 08:50:44.681657 2026] [security2:error] [pid 511108:tid 511191] [remote 82.102.18.188:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dFITd5soprXwxAH0ntwAAdVI"]
[Tue Jul 21 08:50:44.701238 2026] [security2:error] [pid 514479:tid 514656] [client 20.197.195.24:14680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/about.php"] [unique_id "al9dFPzqsQqnLoCgUjiOlAAAATQ"]
[Tue Jul 21 08:50:44.742329 2026] [security2:error] [pid 514479:tid 514695] [client 203.25.124.53:45049] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/user/config.php"] [unique_id "al9dFPzqsQqnLoCgUjiOlwAAAVs"]
[Tue Jul 21 08:50:44.828870 2026] [security2:error] [pid 514479:tid 514643] [client 5.31.193.106:30459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dFPzqsQqnLoCgUjiOmAAAASc"]
[Tue Jul 21 08:50:44.829012 2026] [security2:error] [pid 514479:tid 514643] [client 5.31.193.106:30459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dFPzqsQqnLoCgUjiOmAAAASc"]
[Tue Jul 21 08:50:44.839914 2026] [core:error] [pid 514479:tid 514601] [remote 82.102.18.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:50:44.839931 2026] [core:error] [pid 514479:tid 514601] [remote 82.102.18.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:50:44.849577 2026] [security2:error] [pid 514479:tid 514620] [client 20.104.96.117:59153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/solo1.php"] [unique_id "al9dFPzqsQqnLoCgUjiOmgAAARA"]
[Tue Jul 21 08:50:44.965634 2026] [security2:error] [pid 514479:tid 514523] [remote 192.241.143.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9dFPzqsQqnLoCgUjiOngABHic"]
[Tue Jul 21 08:50:44.996773 2026] [security2:error] [pid 511108:tid 511135] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9dFITd5soprXwxAH0nuwAAPho"]
[Tue Jul 21 08:50:45.097830 2026] [security2:error] [pid 514479:tid 514711] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dFPzqsQqnLoCgUjiOnQABa2I"]
[Tue Jul 21 08:50:45.140335 2026] [security2:error] [pid 511108:tid 511357] [client 65.21.113.253:59288] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dFYTd5soprXwxAH0nvgAAAHc"]
[Tue Jul 21 08:50:45.152626 2026] [security2:error] [pid 514479:tid 514543] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9dFfzqsQqnLoCgUjiOpQABcTs"]
[Tue Jul 21 08:50:45.245228 2026] [security2:error] [pid 514479:tid 514490] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dFfzqsQqnLoCgUjiOpwABTwY"]
[Tue Jul 21 08:50:45.245353 2026] [security2:error] [pid 514479:tid 514683] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dFfzqsQqnLoCgUjiOpwABTwY"]
[Tue Jul 21 08:50:45.312622 2026] [security2:error] [pid 511108:tid 511131] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9dFYTd5soprXwxAH0nwgAATBY"]
[Tue Jul 21 08:50:45.469717 2026] [security2:error] [pid 514479:tid 514511] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9dFfzqsQqnLoCgUjiOqwABMhs"]
[Tue Jul 21 08:50:45.538237 2026] [security2:error] [pid 511108:tid 511339] [client 203.25.124.211:65411] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/languages/themes/admin.php"] [unique_id "al9dFYTd5soprXwxAH0nxAAAAGU"]
[Tue Jul 21 08:50:45.627043 2026] [security2:error] [pid 511108:tid 511197] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9dFYTd5soprXwxAH0nxgAARFg"]
[Tue Jul 21 08:50:45.667618 2026] [security2:error] [pid 514479:tid 514741] [client 203.25.124.209:30649] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/aatdgetgdg/main.php"] [unique_id "al9dFfzqsQqnLoCgUjiOrQAAAYk"]
[Tue Jul 21 08:50:45.733958 2026] [security2:error] [pid 514479:tid 514710] [client 20.197.195.24:8147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/about.php"] [unique_id "al9dFfzqsQqnLoCgUjiOsAAAAWo"]
[Tue Jul 21 08:50:45.779081 2026] [security2:error] [pid 514479:tid 514633] [client 203.25.124.58:55225] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/shell.php"] [unique_id "al9dFfzqsQqnLoCgUjiOsQAAAR0"]
[Tue Jul 21 08:50:45.782373 2026] [security2:error] [pid 514479:tid 514534] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9dFfzqsQqnLoCgUjiOsgABODI"]
[Tue Jul 21 08:50:45.940148 2026] [security2:error] [pid 511108:tid 511183] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9dFYTd5soprXwxAH0nzAAAY0o"]
[Tue Jul 21 08:50:46.096841 2026] [security2:error] [pid 514479:tid 514513] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9dFvzqsQqnLoCgUjiOtgABDx0"]
[Tue Jul 21 08:50:46.211194 2026] [security2:error] [pid 514479:tid 514674] [client 64.42.179.43:41058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9dFvzqsQqnLoCgUjiOuAAAAUY"]
[Tue Jul 21 08:50:46.211282 2026] [security2:error] [pid 514479:tid 514674] [client 64.42.179.43:41058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9dFvzqsQqnLoCgUjiOuAAAAUY"]
[Tue Jul 21 08:50:46.217554 2026] [security2:error] [pid 514479:tid 514621] [client 65.21.113.253:49790] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dFfzqsQqnLoCgUjiOswAAARE"]
[Tue Jul 21 08:50:46.253101 2026] [security2:error] [pid 511108:tid 511231] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9dFoTd5soprXwxAH0nzwAAT3o"]
[Tue Jul 21 08:50:46.409054 2026] [security2:error] [pid 514479:tid 514569] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9dFvzqsQqnLoCgUjiOvAABg1Q"]
[Tue Jul 21 08:50:46.409700 2026] [security2:error] [pid 511108:tid 511301] [client 173.252.95.61:64190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dFoTd5soprXwxAH0n0QAAAD8"]
[Tue Jul 21 08:50:46.565562 2026] [security2:error] [pid 511108:tid 511162] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9dFoTd5soprXwxAH0n0wAARTU"]
[Tue Jul 21 08:50:46.721164 2026] [security2:error] [pid 514479:tid 514542] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9dFvzqsQqnLoCgUjiOxAABEDo"]
[Tue Jul 21 08:50:46.739169 2026] [security2:error] [pid 514479:tid 514646] [client 203.25.124.52:57853] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/PHPMailer/"] [unique_id "al9dFvzqsQqnLoCgUjiOxQAAASo"]
[Tue Jul 21 08:50:46.879760 2026] [security2:error] [pid 514479:tid 514721] [client 20.197.195.24:3260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/admin.php"] [unique_id "al9dFvzqsQqnLoCgUjiOyAAAAXU"]
[Tue Jul 21 08:50:46.880039 2026] [security2:error] [pid 511108:tid 511133] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9dFoTd5soprXwxAH0n3AAAHRg"]
[Tue Jul 21 08:50:46.932918 2026] [security2:error] [pid 514479:tid 514562] [remote 173.252.87.41:59996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9dFvzqsQqnLoCgUjiOyQABPk0"]
[Tue Jul 21 08:50:46.982028 2026] [security2:error] [pid 514479:tid 514681] [client 114.198.138.124:52560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dFvzqsQqnLoCgUjiOygAAAU0"]
[Tue Jul 21 08:50:46.982138 2026] [security2:error] [pid 514479:tid 514681] [client 114.198.138.124:52560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dFvzqsQqnLoCgUjiOygAAAU0"]
[Tue Jul 21 08:50:47.039515 2026] [security2:error] [pid 514479:tid 514599] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9dF_zqsQqnLoCgUjiOzAABD3I"]
[Tue Jul 21 08:50:47.058882 2026] [security2:error] [pid 511108:tid 511339] [client 212.32.76.12:53935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jaypi.com.br"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "al9dF4Td5soprXwxAH0n7AAAAGU"]
[Tue Jul 21 08:50:47.195978 2026] [security2:error] [pid 511108:tid 511192] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9dF4Td5soprXwxAH0n7gAAVVM"]
[Tue Jul 21 08:50:47.353971 2026] [security2:error] [pid 514479:tid 514498] [remote 82.102.18.188:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ginecologistadrcelsofukuda.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9dF_zqsQqnLoCgUjiO2AABQw4"]
[Tue Jul 21 08:50:47.375348 2026] [security2:error] [pid 514479:tid 514672] [client 203.25.124.246:30101] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/asasx.php"] [unique_id "al9dF_zqsQqnLoCgUjiO2QAAAUQ"]
[Tue Jul 21 08:50:47.376210 2026] [security2:error] [pid 514479:tid 514705] [client 59.95.197.55:55425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dF_zqsQqnLoCgUjiO2gAAAWU"]
[Tue Jul 21 08:50:47.376329 2026] [security2:error] [pid 514479:tid 514705] [client 59.95.197.55:55425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dF_zqsQqnLoCgUjiO2gAAAWU"]
[Tue Jul 21 08:50:47.442038 2026] [autoindex:error] [pid 511108:tid 511353] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/andr8586/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:50:47.572548 2026] [security2:error] [pid 511108:tid 511299] [client 122.176.100.127:57165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dF4Td5soprXwxAH0n-wAAAD0"]
[Tue Jul 21 08:50:47.572687 2026] [security2:error] [pid 511108:tid 511299] [client 122.176.100.127:57165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dF4Td5soprXwxAH0n-wAAAD0"]
[Tue Jul 21 08:50:47.744340 2026] [security2:error] [pid 511108:tid 511294] [client 20.104.96.117:59197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/cong.php"] [unique_id "al9dF4Td5soprXwxAH0oAQAAADg"]
[Tue Jul 21 08:50:47.911546 2026] [security2:error] [pid 514479:tid 514635] [client 20.197.195.24:63384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/admin.php"] [unique_id "al9dF_zqsQqnLoCgUjiO4wAAAR8"]
[Tue Jul 21 08:50:47.972429 2026] [security2:error] [pid 514479:tid 514683] [client 20.104.96.117:4071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/v543.php"] [unique_id "al9dF_zqsQqnLoCgUjiO6gAAAU8"]
[Tue Jul 21 08:50:48.277479 2026] [security2:error] [pid 511108:tid 511324] [client 203.25.124.7:53775] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/template-wploader.php"] [unique_id "al9dGITd5soprXwxAH0oCwAAAFY"]
[Tue Jul 21 08:50:48.327612 2026] [security2:error] [pid 511108:tid 511327] [client 212.32.76.8:26697] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/wp-file-manager/file_folder_manager.php"] [unique_id "al9dGITd5soprXwxAH0oEQAAAFk"]
[Tue Jul 21 08:50:48.462875 2026] [security2:error] [pid 511108:tid 511296] [client 20.197.195.24:63391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/themes.php"] [unique_id "al9dGITd5soprXwxAH0oEwAAADo"]
[Tue Jul 21 08:50:48.556962 2026] [security2:error] [pid 511108:tid 511340] [client 49.144.66.253:33178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dGITd5soprXwxAH0oFwAAAGY"]
[Tue Jul 21 08:50:48.557046 2026] [security2:error] [pid 511108:tid 511340] [client 49.144.66.253:33178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dGITd5soprXwxAH0oFwAAAGY"]
[Tue Jul 21 08:50:48.568181 2026] [autoindex:error] [pid 514479:tid 514681] [client 20.104.96.117:0] AH01276: Cannot serve directory /home2/andr8586/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:50:48.863625 2026] [security2:error] [pid 514479:tid 514659] [client 20.104.96.117:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/public/css.php"] [unique_id "al9dGPzqsQqnLoCgUjiO9AAAATc"]
[Tue Jul 21 08:50:48.983574 2026] [security2:error] [pid 514479:tid 514738] [client 20.197.195.24:62749] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.tempex.com.br"] [uri "/wp-includes/blocks/details/"] [unique_id "al9dGPzqsQqnLoCgUjiO9gAAAYY"]
[Tue Jul 21 08:50:49.157051 2026] [security2:error] [pid 514479:tid 514619] [client 114.119.135.35:51097] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.alperembalagens.com.br"] [uri "/produtos/depart/69/maletas"] [unique_id "al9dGfzqsQqnLoCgUjiO-AAAAQ8"], referer: https://www.alperembalagens.com.br/produtos/depart/14/copos
[Tue Jul 21 08:50:49.375497 2026] [security2:error] [pid 514479:tid 514687] [client 212.32.76.61:50507] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/test.php"] [unique_id "al9dGfzqsQqnLoCgUjiO_AAAAVM"]
[Tue Jul 21 08:50:49.646846 2026] [security2:error] [pid 511108:tid 511337] [client 5.38.115.39:41895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dGYTd5soprXwxAH0oJwAAAGM"]
[Tue Jul 21 08:50:49.647015 2026] [security2:error] [pid 511108:tid 511337] [client 5.38.115.39:41895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dGYTd5soprXwxAH0oJwAAAGM"]
[Tue Jul 21 08:50:49.822481 2026] [security2:error] [pid 511108:tid 511352] [client 20.220.225.223:22979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/berlin.php"] [unique_id "al9dGYTd5soprXwxAH0oKAAAAHI"]
[Tue Jul 21 08:50:49.837758 2026] [security2:error] [pid 511108:tid 511254] [client 65.21.113.253:59288] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dGYTd5soprXwxAH0oKgAAABA"]
[Tue Jul 21 08:50:49.848132 2026] [security2:error] [pid 514479:tid 514635] [client 203.25.124.212:32651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/classwithtostring.php"] [unique_id "al9dGfzqsQqnLoCgUjiPAQAAAR8"]
[Tue Jul 21 08:50:50.104085 2026] [security2:error] [pid 511108:tid 511239] [client 20.104.96.117:61175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/output.php"] [unique_id "al9dGoTd5soprXwxAH0oNwAAAAE"]
[Tue Jul 21 08:50:50.197538 2026] [security2:error] [pid 511108:tid 511299] [client 195.49.128.211:62323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dGoTd5soprXwxAH0oOAAAAD0"]
[Tue Jul 21 08:50:50.197687 2026] [security2:error] [pid 511108:tid 511299] [client 195.49.128.211:62323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dGoTd5soprXwxAH0oOAAAAD0"]
[Tue Jul 21 08:50:50.256282 2026] [security2:error] [pid 511108:tid 511318] [client 20.197.195.24:3220] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.tempex.com.br"] [uri "/wp-includes/blocks/audi/"] [unique_id "al9dGoTd5soprXwxAH0oOwAAAFA"]
[Tue Jul 21 08:50:50.367648 2026] [security2:error] [pid 511108:tid 511346] [client 20.104.96.117:4028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/sixxis.php"] [unique_id "al9dGoTd5soprXwxAH0oPgAAAGw"]
[Tue Jul 21 08:50:50.667713 2026] [security2:error] [pid 514479:tid 514628] [client 65.21.113.253:41294] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dGvzqsQqnLoCgUjiPCAAAARg"]
[Tue Jul 21 08:50:50.669818 2026] [security2:error] [pid 514479:tid 514692] [client 203.25.124.188:43427] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/network/index.php"] [unique_id "al9dGvzqsQqnLoCgUjiPCwAAAVg"]
[Tue Jul 21 08:50:50.838835 2026] [security2:error] [pid 514479:tid 514697] [client 41.89.234.2:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dGvzqsQqnLoCgUjiPDAAAAV0"]
[Tue Jul 21 08:50:50.838983 2026] [security2:error] [pid 514479:tid 514697] [client 41.89.234.2:58390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dGvzqsQqnLoCgUjiPDAAAAV0"]
[Tue Jul 21 08:50:50.940302 2026] [security2:error] [pid 511108:tid 511125] [remote 100.42.189.89:47708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/xmlrpc.php"] [unique_id "al9dGoTd5soprXwxAH0obwAAQxA"]
[Tue Jul 21 08:50:50.940444 2026] [security2:error] [pid 511108:tid 511305] [client 100.42.189.89:47708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "buyonlinetodayatadiscount.net"] [uri "/xmlrpc.php"] [unique_id "al9dGoTd5soprXwxAH0obwAAQxA"]
[Tue Jul 21 08:50:51.130465 2026] [security2:error] [pid 511108:tid 511307] [client 20.197.195.24:3229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/.well-known/about.php"] [unique_id "al9dG4Td5soprXwxAH0oeQAAAEU"]
[Tue Jul 21 08:50:51.146022 2026] [security2:error] [pid 514479:tid 514704] [client 203.25.124.212:33459] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/about.php"] [unique_id "al9dG_zqsQqnLoCgUjiPDwAAAWQ"]
[Tue Jul 21 08:50:51.415628 2026] [security2:error] [pid 514479:tid 514700] [client 20.104.96.117:59663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-file-120.php"] [unique_id "al9dG_zqsQqnLoCgUjiPEwAAAWA"]
[Tue Jul 21 08:50:51.645079 2026] [security2:error] [pid 514479:tid 514662] [client 198.44.157.34:55382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9dG_zqsQqnLoCgUjiPGQAAATo"]
[Tue Jul 21 08:50:51.645224 2026] [security2:error] [pid 514479:tid 514662] [client 198.44.157.34:55382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9dG_zqsQqnLoCgUjiPGQAAATo"]
[Tue Jul 21 08:50:51.786096 2026] [security2:error] [pid 514479:tid 514653] [client 65.21.113.253:41300] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dG_zqsQqnLoCgUjiPEgAAATE"]
[Tue Jul 21 08:50:51.975825 2026] [security2:error] [pid 511108:tid 511241] [client 212.32.76.66:52159] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/moon.php"] [unique_id "al9dG4Td5soprXwxAH0ogwAAAAM"]
[Tue Jul 21 08:50:52.023549 2026] [security2:error] [pid 514479:tid 514694] [client 20.197.192.193:56798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/xyn.php"] [unique_id "al9dHPzqsQqnLoCgUjiPHgAAAVo"]
[Tue Jul 21 08:50:52.031083 2026] [security2:error] [pid 514479:tid 514606] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dHPzqsQqnLoCgUjiPHwABVXk"]
[Tue Jul 21 08:50:52.031226 2026] [security2:error] [pid 514479:tid 514689] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dHPzqsQqnLoCgUjiPHwABVXk"]
[Tue Jul 21 08:50:52.103245 2026] [security2:error] [pid 514479:tid 514727] [client 74.7.228.53:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "digital-universo.com"] [uri "/index.php"] [unique_id "al9dG_zqsQqnLoCgUjiPEAABex4"]
[Tue Jul 21 08:50:52.247769 2026] [security2:error] [pid 511108:tid 511346] [client 203.25.124.67:45427] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/sitemaps/admin.php"] [unique_id "al9dHITd5soprXwxAH0oiwAAAGw"]
[Tue Jul 21 08:50:52.292493 2026] [security2:error] [pid 514479:tid 514614] [client 20.197.192.193:52732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/byp8.php"] [unique_id "al9dHPzqsQqnLoCgUjiPIgAAAQo"]
[Tue Jul 21 08:50:52.295538 2026] [security2:error] [pid 511108:tid 511256] [client 114.119.128.162:62931] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pacodasrosas.com.br"] [uri "/lojas/page/4"] [unique_id "al9dHITd5soprXwxAH0ojAAAABI"], referer: https://pacodasrosas.com.br/lojas/page/4
[Tue Jul 21 08:50:52.721087 2026] [security2:error] [pid 514479:tid 514637] [client 20.220.225.223:35120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/billur.php"] [unique_id "al9dHPzqsQqnLoCgUjiPKwAAASE"]
[Tue Jul 21 08:50:52.865952 2026] [security2:error] [pid 514479:tid 514584] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dHPzqsQqnLoCgUjiPLQABWGM"]
[Tue Jul 21 08:50:52.866102 2026] [security2:error] [pid 514479:tid 514692] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dHPzqsQqnLoCgUjiPLQABWGM"]
[Tue Jul 21 08:50:53.173208 2026] [security2:error] [pid 514479:tid 514621] [client 203.25.124.190:54303] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/upload/"] [unique_id "al9dHfzqsQqnLoCgUjiPLwAAARE"]
[Tue Jul 21 08:50:53.253755 2026] [security2:error] [pid 514479:tid 514740] [client 20.197.195.24:63419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9dHfzqsQqnLoCgUjiPMAAAAYg"]
[Tue Jul 21 08:50:53.779339 2026] [security2:error] [pid 511108:tid 511261] [client 103.59.206.240:31314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dHYTd5soprXwxAH0orgAAABc"]
[Tue Jul 21 08:50:53.779474 2026] [security2:error] [pid 511108:tid 511261] [client 103.59.206.240:31314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dHYTd5soprXwxAH0orgAAABc"]
[Tue Jul 21 08:50:53.852581 2026] [security2:error] [pid 511108:tid 511334] [client 20.220.225.223:19315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/dp.php"] [unique_id "al9dHYTd5soprXwxAH0orwAAAGA"]
[Tue Jul 21 08:50:53.881855 2026] [security2:error] [pid 511108:tid 511341] [client 20.197.195.24:3305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/wefile.php"] [unique_id "al9dHYTd5soprXwxAH0osQAAAGc"]
[Tue Jul 21 08:50:53.923926 2026] [security2:error] [pid 514479:tid 514691] [client 20.220.225.223:46355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/mimpi.php"] [unique_id "al9dHfzqsQqnLoCgUjiPOAAAAVc"]
[Tue Jul 21 08:50:54.041283 2026] [security2:error] [pid 511108:tid 511281] [client 20.197.192.193:50612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/user.php"] [unique_id "al9dHoTd5soprXwxAH0otgAAACs"]
[Tue Jul 21 08:50:54.141564 2026] [security2:error] [pid 511108:tid 511243] [client 20.104.96.117:59185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/special.php"] [unique_id "al9dHoTd5soprXwxAH0ouQAAAAU"]
[Tue Jul 21 08:50:54.237428 2026] [security2:error] [pid 514479:tid 514634] [client 203.25.124.35:20027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/js/widgets/maint/"] [unique_id "al9dHvzqsQqnLoCgUjiPPgAAAR4"]
[Tue Jul 21 08:50:54.420950 2026] [security2:error] [pid 511108:tid 511335] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "digital-universo.com"] [uri "/index.php"] [unique_id "al9dHoTd5soprXwxAH0ouwAAYW8"]
[Tue Jul 21 08:50:54.478368 2026] [security2:error] [pid 514479:tid 514722] [client 203.25.124.184:59001] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/css/index.php"] [unique_id "al9dHvzqsQqnLoCgUjiPQAAAAXY"]
[Tue Jul 21 08:50:54.668569 2026] [security2:error] [pid 514479:tid 514710] [client 20.104.96.117:61705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/ip.php"] [unique_id "al9dHvzqsQqnLoCgUjiPRgAAAWo"]
[Tue Jul 21 08:50:54.771532 2026] [security2:error] [pid 511108:tid 511253] [client 20.197.192.193:52686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/ops.php"] [unique_id "al9dHoTd5soprXwxAH0owwAAAA8"]
[Tue Jul 21 08:50:54.784350 2026] [security2:error] [pid 514479:tid 514668] [client 113.22.144.139:56344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dHvzqsQqnLoCgUjiPRwAAAUA"]
[Tue Jul 21 08:50:54.784486 2026] [security2:error] [pid 514479:tid 514668] [client 113.22.144.139:56344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dHvzqsQqnLoCgUjiPRwAAAUA"]
[Tue Jul 21 08:50:54.833080 2026] [security2:error] [pid 514479:tid 514549] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dHvzqsQqnLoCgUjiPSwABbUA"]
[Tue Jul 21 08:50:54.833257 2026] [security2:error] [pid 514479:tid 514713] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dHvzqsQqnLoCgUjiPSwABbUA"]
[Tue Jul 21 08:50:54.885620 2026] [security2:error] [pid 514479:tid 514645] [client 182.189.99.211:47817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dHvzqsQqnLoCgUjiPTQAAASk"]
[Tue Jul 21 08:50:54.886164 2026] [security2:error] [pid 514479:tid 514645] [client 182.189.99.211:47817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dHvzqsQqnLoCgUjiPTQAAASk"]
[Tue Jul 21 08:50:54.913297 2026] [security2:error] [pid 514479:tid 514529] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dHvzqsQqnLoCgUjiPTgABfy0"]
[Tue Jul 21 08:50:54.913443 2026] [security2:error] [pid 514479:tid 514731] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dHvzqsQqnLoCgUjiPTgABfy0"]
[Tue Jul 21 08:50:55.013805 2026] [security2:error] [pid 514479:tid 514617] [client 168.167.81.163:64539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dH_zqsQqnLoCgUjiPTwAAAQ0"]
[Tue Jul 21 08:50:55.013942 2026] [security2:error] [pid 514479:tid 514617] [client 168.167.81.163:64539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dH_zqsQqnLoCgUjiPTwAAAQ0"]
[Tue Jul 21 08:50:55.360718 2026] [security2:error] [pid 511108:tid 511360] [client 20.197.192.193:50583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/term.php"] [unique_id "al9dH4Td5soprXwxAH0o2AAAAHo"]
[Tue Jul 21 08:50:55.448400 2026] [security2:error] [pid 514479:tid 514740] [client 203.25.124.58:29457] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/languages/classwithtostring.php"] [unique_id "al9dH_zqsQqnLoCgUjiPVAAAAYg"]
[Tue Jul 21 08:50:55.580697 2026] [security2:error] [pid 514479:tid 514639] [client 20.197.195.24:62755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9dH_zqsQqnLoCgUjiPVgAAASM"]
[Tue Jul 21 08:50:55.600706 2026] [security2:error] [pid 511108:tid 511258] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dH4Td5soprXwxAH0o3gAAFDM"]
[Tue Jul 21 08:50:55.679670 2026] [security2:error] [pid 514479:tid 514636] [client 203.25.124.190:55831] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/network/cache/"] [unique_id "al9dH_zqsQqnLoCgUjiPWAAAASA"]
[Tue Jul 21 08:50:56.033032 2026] [security2:error] [pid 514479:tid 514685] [client 65.21.113.253:36944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dIPzqsQqnLoCgUjiPWwAAAVE"]
[Tue Jul 21 08:50:56.277755 2026] [security2:error] [pid 514479:tid 514495] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dIPzqsQqnLoCgUjiPXgABJAs"]
[Tue Jul 21 08:50:56.277992 2026] [security2:error] [pid 514479:tid 514640] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dIPzqsQqnLoCgUjiPXgABJAs"]
[Tue Jul 21 08:50:56.288587 2026] [security2:error] [pid 511108:tid 511252] [client 20.220.225.223:37621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/dp.php"] [unique_id "al9dIITd5soprXwxAH0pAQAAAA4"]
[Tue Jul 21 08:50:56.423110 2026] [security2:error] [pid 514479:tid 514657] [client 20.104.96.117:46720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/kq1.php"] [unique_id "al9dIPzqsQqnLoCgUjiPXwAAATU"]
[Tue Jul 21 08:50:56.444414 2026] [security2:error] [pid 511108:tid 511209] [remote 188.164.197.230:52730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9dIITd5soprXwxAH0pBwAAHGQ"]
[Tue Jul 21 08:50:56.548225 2026] [security2:error] [pid 514479:tid 514696] [client 203.25.124.213:55493] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al9dIPzqsQqnLoCgUjiPYAAAAVw"]
[Tue Jul 21 08:50:56.686106 2026] [security2:error] [pid 514479:tid 514595] [remote 45.76.153.27:58530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.153.76.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9dIPzqsQqnLoCgUjiPZAABU24"]
[Tue Jul 21 08:50:56.775762 2026] [security2:error] [pid 514479:tid 514634] [client 203.25.124.210:48197] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/abcd.php"] [unique_id "al9dIPzqsQqnLoCgUjiPZgAAAR4"]
[Tue Jul 21 08:50:57.117736 2026] [security2:error] [pid 514479:tid 514689] [client 65.21.113.253:41302] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dIPzqsQqnLoCgUjiPZQAAAVU"]
[Tue Jul 21 08:50:57.303550 2026] [security2:error] [pid 514479:tid 514713] [client 20.104.96.117:61152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/as.php"] [unique_id "al9dIfzqsQqnLoCgUjiPawAAAW0"]
[Tue Jul 21 08:50:57.437211 2026] [security2:error] [pid 514479:tid 514633] [client 20.104.96.117:4042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/fw/faiyy.php"] [unique_id "al9dIfzqsQqnLoCgUjiPbAAAAR0"]
[Tue Jul 21 08:50:57.480916 2026] [security2:error] [pid 514479:tid 514710] [client 114.198.138.124:53144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dIfzqsQqnLoCgUjiPbQAAAWo"]
[Tue Jul 21 08:50:57.481006 2026] [security2:error] [pid 514479:tid 514710] [client 114.198.138.124:53144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dIfzqsQqnLoCgUjiPbQAAAWo"]
[Tue Jul 21 08:50:57.564440 2026] [security2:error] [pid 514479:tid 514637] [client 173.252.95.13:51408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dIfzqsQqnLoCgUjiPcgAAASE"]
[Tue Jul 21 08:50:57.774994 2026] [security2:error] [pid 514479:tid 514621] [client 203.25.124.181:51721] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwentyfour/patterns/template-singl-portfolio.php"] [unique_id "al9dIfzqsQqnLoCgUjiPdQAAARE"]
[Tue Jul 21 08:50:57.882296 2026] [security2:error] [pid 514479:tid 514540] [remote 130.51.180.8:52512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/wp-login.php"] [unique_id "al9dIfzqsQqnLoCgUjiPdgABPzg"]
[Tue Jul 21 08:50:57.903117 2026] [security2:error] [pid 514479:tid 514650] [client 59.95.197.55:55909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dIfzqsQqnLoCgUjiPdwAAAS4"]
[Tue Jul 21 08:50:57.903219 2026] [security2:error] [pid 514479:tid 514650] [client 59.95.197.55:55909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dIfzqsQqnLoCgUjiPdwAAAS4"]
[Tue Jul 21 08:50:57.960360 2026] [security2:error] [pid 511108:tid 511256] [client 20.197.195.24:62722] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.tempex.com.br"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al9dIYTd5soprXwxAH0pGQAAABI"]
[Tue Jul 21 08:50:58.046566 2026] [security2:error] [pid 514479:tid 514659] [client 203.25.124.42:41791] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/colors/modern/test2.php"] [unique_id "al9dIvzqsQqnLoCgUjiPeAAAATc"]
[Tue Jul 21 08:50:58.060692 2026] [security2:error] [pid 514479:tid 514665] [client 122.176.100.127:57646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dIvzqsQqnLoCgUjiPeQAAAT0"]
[Tue Jul 21 08:50:58.060866 2026] [security2:error] [pid 514479:tid 514665] [client 122.176.100.127:57646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dIvzqsQqnLoCgUjiPeQAAAT0"]
[Tue Jul 21 08:50:58.666974 2026] [security2:error] [pid 514479:tid 514625] [client 20.104.96.117:4005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/h02ugyh.php"] [unique_id "al9dIvzqsQqnLoCgUjiPggAAARU"]
[Tue Jul 21 08:50:59.006136 2026] [security2:error] [pid 511108:tid 511361] [client 185.213.175.37:52746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "botecocarnenalata.com.br"] [uri "/login.php"] [unique_id "al9dI4Td5soprXwxAH0pKAAAAHs"]
[Tue Jul 21 08:50:59.006218 2026] [security2:error] [pid 511108:tid 511361] [client 185.213.175.37:52746] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "botecocarnenalata.com.br"] [uri "/login.php"] [unique_id "al9dI4Td5soprXwxAH0pKAAAAHs"]
[Tue Jul 21 08:50:59.077315 2026] [security2:error] [pid 514479:tid 514664] [client 203.25.124.184:59865] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/class-wp-smtp-bar.php"] [unique_id "al9dI_zqsQqnLoCgUjiPjwAAATw"]
[Tue Jul 21 08:50:59.328771 2026] [security2:error] [pid 511108:tid 511305] [client 185.213.175.37:52774] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "botecocarnenalata.com.br"] [uri "/uploads/produtos/prod_69226773d5664.jpg"] [unique_id "al9dI4Td5soprXwxAH0pLgAAAEM"]
[Tue Jul 21 08:50:59.433509 2026] [security2:error] [pid 511108:tid 511244] [client 20.197.192.193:50582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/ah25.php"] [unique_id "al9dI4Td5soprXwxAH0pLwAAAAY"]
[Tue Jul 21 08:50:59.445235 2026] [security2:error] [pid 511108:tid 511291] [client 185.213.175.37:52776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botecocarnenalata.com.br"] [uri "/clientes_aberto.php"] [unique_id "al9dI4Td5soprXwxAH0pMAAAADU"]
[Tue Jul 21 08:50:59.468256 2026] [security2:error] [pid 514479:tid 514723] [client 20.104.96.117:61151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9dI_zqsQqnLoCgUjiPlQAAAXc"]
[Tue Jul 21 08:50:59.527115 2026] [security2:error] [pid 514479:tid 514661] [client 49.144.66.253:33574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dI_zqsQqnLoCgUjiPlwAAATk"]
[Tue Jul 21 08:50:59.527208 2026] [security2:error] [pid 514479:tid 514661] [client 49.144.66.253:33574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dI_zqsQqnLoCgUjiPlwAAATk"]
[Tue Jul 21 08:50:59.549774 2026] [security2:error] [pid 514479:tid 514725] [client 203.25.124.68:32005] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwentyfive/parts/"] [unique_id "al9dI_zqsQqnLoCgUjiPmAAAAXk"]
[Tue Jul 21 08:50:59.869471 2026] [security2:error] [pid 514479:tid 514588] [remote 47.128.39.207:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "naturofarma.com.br"] [uri "/robots.txt"] [unique_id "al9dI_zqsQqnLoCgUjiPnQABPmc"]
[Tue Jul 21 08:51:00.349689 2026] [security2:error] [pid 514479:tid 514685] [client 20.197.192.193:50597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/8.php"] [unique_id "al9dJPzqsQqnLoCgUjiPogAAAVE"]
[Tue Jul 21 08:51:00.365721 2026] [security2:error] [pid 511108:tid 511352] [client 5.38.115.39:55476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dJITd5soprXwxAH0pOwAAAHI"]
[Tue Jul 21 08:51:00.365916 2026] [security2:error] [pid 511108:tid 511352] [client 5.38.115.39:55476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dJITd5soprXwxAH0pOwAAAHI"]
[Tue Jul 21 08:51:00.490273 2026] [security2:error] [pid 511108:tid 511185] [remote 202.51.202.242:49518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hypehutdeals.com"] [uri "/wp-login.php"] [unique_id "al9dJITd5soprXwxAH0pPQAAf0w"]
[Tue Jul 21 08:51:00.809514 2026] [security2:error] [pid 514479:tid 514732] [client 195.49.128.211:62991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dJPzqsQqnLoCgUjiPpQAAAYA"]
[Tue Jul 21 08:51:00.809618 2026] [security2:error] [pid 514479:tid 514732] [client 195.49.128.211:62991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dJPzqsQqnLoCgUjiPpQAAAYA"]
[Tue Jul 21 08:51:00.864590 2026] [security2:error] [pid 511108:tid 511299] [client 20.104.96.117:4033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-temp.php"] [unique_id "al9dJITd5soprXwxAH0pQgAAAD0"]
[Tue Jul 21 08:51:00.878021 2026] [security2:error] [pid 514479:tid 514646] [client 20.104.96.117:59147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/w1px.php"] [unique_id "al9dJPzqsQqnLoCgUjiPpgAAASo"]
[Tue Jul 21 08:51:01.038998 2026] [security2:error] [pid 514479:tid 514711] [client 203.25.124.58:39033] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/query-title/"] [unique_id "al9dJfzqsQqnLoCgUjiPqwAAAWs"]
[Tue Jul 21 08:51:01.175344 2026] [security2:error] [pid 511108:tid 511336] [client 203.25.124.197:52213] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/assets/images/selam.php"] [unique_id "al9dJYTd5soprXwxAH0pRgAAAGI"]
[Tue Jul 21 08:51:01.367257 2026] [security2:error] [pid 511108:tid 511364] [client 41.89.234.2:58855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dJYTd5soprXwxAH0pSQAAAH4"]
[Tue Jul 21 08:51:01.367423 2026] [security2:error] [pid 511108:tid 511364] [client 41.89.234.2:58855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dJYTd5soprXwxAH0pSQAAAH4"]
[Tue Jul 21 08:51:01.414669 2026] [security2:error] [pid 514479:tid 514739] [client 20.220.225.223:46682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/bootstrap.php"] [unique_id "al9dJfzqsQqnLoCgUjiPrQAAAYc"]
[Tue Jul 21 08:51:01.434228 2026] [security2:error] [pid 514479:tid 514709] [client 103.59.206.240:31067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dJfzqsQqnLoCgUjiPrwAAAWk"]
[Tue Jul 21 08:51:01.434337 2026] [security2:error] [pid 514479:tid 514709] [client 103.59.206.240:31067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dJfzqsQqnLoCgUjiPrwAAAWk"]
[Tue Jul 21 08:51:01.459105 2026] [security2:error] [pid 514479:tid 514702] [client 20.197.195.24:63413] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.tempex.com.br"] [uri "/wp-admin/js/"] [unique_id "al9dJfzqsQqnLoCgUjiPsAAAAWI"]
[Tue Jul 21 08:51:01.542236 2026] [security2:error] [pid 514479:tid 514651] [client 20.197.192.193:56775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/red.php"] [unique_id "al9dJfzqsQqnLoCgUjiPsQAAAS8"]
[Tue Jul 21 08:51:01.847642 2026] [security2:error] [pid 511108:tid 511290] [client 20.197.195.24:3234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9dJYTd5soprXwxAH0pTwAAADQ"]
[Tue Jul 21 08:51:01.876625 2026] [security2:error] [pid 514479:tid 514668] [client 173.252.95.0:42434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dJfzqsQqnLoCgUjiPtwAAAUA"]
[Tue Jul 21 08:51:02.442371 2026] [security2:error] [pid 511108:tid 511305] [client 203.25.124.64:54371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/config.php"] [unique_id "al9dJoTd5soprXwxAH0pWwAAAEM"]
[Tue Jul 21 08:51:02.577199 2026] [security2:error] [pid 511108:tid 511165] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dJoTd5soprXwxAH0pXwAAbTg"]
[Tue Jul 21 08:51:02.577369 2026] [security2:error] [pid 511108:tid 511347] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dJoTd5soprXwxAH0pXwAAbTg"]
[Tue Jul 21 08:51:02.588306 2026] [security2:error] [pid 514479:tid 514561] [remote 45.3.41.95:35531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9dJvzqsQqnLoCgUjiPwQABTUw"]
[Tue Jul 21 08:51:02.599537 2026] [security2:error] [pid 514479:tid 514726] [client 20.104.96.117:46768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-content/cong.php"] [unique_id "al9dJvzqsQqnLoCgUjiPwwAAAXo"]
[Tue Jul 21 08:51:02.614100 2026] [security2:error] [pid 511108:tid 511307] [client 20.197.195.24:3235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/8.php"] [unique_id "al9dJoTd5soprXwxAH0pYAAAAEU"]
[Tue Jul 21 08:51:03.040596 2026] [security2:error] [pid 511108:tid 511253] [client 20.220.225.223:19287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/old.php"] [unique_id "al9dJ4Td5soprXwxAH0pawAAAA8"]
[Tue Jul 21 08:51:03.072778 2026] [security2:error] [pid 511108:tid 511331] [client 203.25.124.181:38793] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/manager.php"] [unique_id "al9dJ4Td5soprXwxAH0pbAAAAF0"]
[Tue Jul 21 08:51:03.180935 2026] [security2:error] [pid 511108:tid 511294] [client 20.104.96.117:59691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/yawa.php"] [unique_id "al9dJ4Td5soprXwxAH0pbgAAADg"]
[Tue Jul 21 08:51:03.243349 2026] [security2:error] [pid 511108:tid 511297] [client 20.197.195.24:14716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9dJ4Td5soprXwxAH0pcAAAADs"]
[Tue Jul 21 08:51:03.300062 2026] [security2:error] [pid 511108:tid 511181] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dJ4Td5soprXwxAH0pcQAAEEg"]
[Tue Jul 21 08:51:03.300288 2026] [security2:error] [pid 511108:tid 511254] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dJ4Td5soprXwxAH0pcQAAEEg"]
[Tue Jul 21 08:51:03.442539 2026] [security2:error] [pid 511108:tid 511352] [client 203.25.124.68:54547] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/images/"] [unique_id "al9dJ4Td5soprXwxAH0pdQAAAHI"]
[Tue Jul 21 08:51:03.880789 2026] [security2:error] [pid 511108:tid 511139] [remote 185.213.175.37:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "botzappro.com.br"] [uri "/comments/feed/"] [unique_id "al9dJ4Td5soprXwxAH0pfgAAIh4"]
[Tue Jul 21 08:51:03.986034 2026] [security2:error] [pid 514479:tid 514712] [client 20.197.195.24:63397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/f6.php"] [unique_id "al9dJ_zqsQqnLoCgUjiPzAAAAWw"]
[Tue Jul 21 08:51:04.129763 2026] [security2:error] [pid 511108:tid 511334] [client 64.42.179.43:55648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.179.42.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9dKITd5soprXwxAH0phAAAAGA"]
[Tue Jul 21 08:51:04.129865 2026] [security2:error] [pid 511108:tid 511334] [client 64.42.179.43:55648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9dKITd5soprXwxAH0phAAAAGA"]
[Tue Jul 21 08:51:04.174498 2026] [security2:error] [pid 511108:tid 511261] [client 203.25.124.207:57953] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/upload.php"] [unique_id "al9dKITd5soprXwxAH0phQAAABc"]
[Tue Jul 21 08:51:04.468188 2026] [security2:error] [pid 511108:tid 511360] [client 182.189.99.211:47742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dKITd5soprXwxAH0piwAAAHo"]
[Tue Jul 21 08:51:04.468290 2026] [security2:error] [pid 511108:tid 511360] [client 182.189.99.211:47742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dKITd5soprXwxAH0piwAAAHo"]
[Tue Jul 21 08:51:04.480219 2026] [security2:error] [pid 511108:tid 511314] [client 20.104.96.117:3977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-includes/css/index.php"] [unique_id "al9dKITd5soprXwxAH0pjAAAAEw"]
[Tue Jul 21 08:51:04.749950 2026] [security2:error] [pid 511108:tid 511340] [client 47.128.34.198:31550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "alperembalagens.com.br"] [uri "/robots.txt"] [unique_id "al9dKITd5soprXwxAH0pkQAAAGY"]
[Tue Jul 21 08:51:04.751751 2026] [security2:error] [pid 514479:tid 514646] [client 74.7.244.13:46270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "espacokids51.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9dKPzqsQqnLoCgUjiPzwABKn8"]
[Tue Jul 21 08:51:04.821674 2026] [security2:error] [pid 511108:tid 511268] [client 74.7.228.46:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.agrocibus.com"] [uri "/cgi-sys/404.html"] [unique_id "al9dKITd5soprXwxAH0pkgAAAB4"]
[Tue Jul 21 08:51:04.893669 2026] [autoindex:error] [pid 514479:tid 514735] [client 74.7.241.20:0] AH01276: Cannot serve directory /home3/agroci73/agrocibus.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:51:04.953296 2026] [security2:error] [pid 511108:tid 511323] [client 20.220.225.223:19302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/ms-new.php"] [unique_id "al9dKITd5soprXwxAH0plgAAAFU"]
[Tue Jul 21 08:51:05.179802 2026] [security2:error] [pid 514479:tid 514693] [client 212.32.76.60:24089] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "al9dKfzqsQqnLoCgUjiP2gAAAVk"]
[Tue Jul 21 08:51:05.336851 2026] [security2:error] [pid 514479:tid 514524] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dKfzqsQqnLoCgUjiP2wABRyg"]
[Tue Jul 21 08:51:05.337991 2026] [security2:error] [pid 514479:tid 514675] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dKfzqsQqnLoCgUjiP2wABRyg"]
[Tue Jul 21 08:51:05.449025 2026] [security2:error] [pid 514479:tid 514741] [client 203.25.124.71:60421] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/index-string.php"] [unique_id "al9dKfzqsQqnLoCgUjiP3AAAAYk"]
[Tue Jul 21 08:51:05.591036 2026] [security2:error] [pid 514479:tid 514662] [client 113.22.144.139:56867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dKfzqsQqnLoCgUjiP4AAAATo"]
[Tue Jul 21 08:51:05.591147 2026] [security2:error] [pid 514479:tid 514662] [client 113.22.144.139:56867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dKfzqsQqnLoCgUjiP4AAAATo"]
[Tue Jul 21 08:51:05.605035 2026] [security2:error] [pid 514479:tid 514707] [client 198.44.157.34:55628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9dKfzqsQqnLoCgUjiP4QAAAWc"]
[Tue Jul 21 08:51:05.605127 2026] [security2:error] [pid 514479:tid 514707] [client 198.44.157.34:55628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9dKfzqsQqnLoCgUjiP4QAAAWc"]
[Tue Jul 21 08:51:05.768036 2026] [security2:error] [pid 514479:tid 514604] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dKfzqsQqnLoCgUjiP5AABYnc"]
[Tue Jul 21 08:51:05.768179 2026] [security2:error] [pid 514479:tid 514702] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dKfzqsQqnLoCgUjiP5AABYnc"]
[Tue Jul 21 08:51:06.211054 2026] [security2:error] [pid 511108:tid 511253] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dKoTd5soprXwxAH0ppQAAD3Y"]
[Tue Jul 21 08:51:06.238606 2026] [proxy:error] [pid 514479:tid 514700] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:51:06.238687 2026] [proxy_http:error] [pid 514479:tid 514700] [client 64.23.200.236:34242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:51:06.239344 2026] [proxy:error] [pid 514479:tid 514700] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:51:06.239374 2026] [proxy_http:error] [pid 514479:tid 514700] [client 64.23.200.236:34242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:51:06.245412 2026] [security2:error] [pid 514479:tid 514624] [client 20.197.195.24:8834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.tempex.com.br"] [uri "/inputs.php"] [unique_id "al9dKvzqsQqnLoCgUjiP7AAAARQ"]
[Tue Jul 21 08:51:06.471745 2026] [security2:error] [pid 511108:tid 511254] [client 212.32.76.60:61941] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/buy.php"] [unique_id "al9dKoTd5soprXwxAH0pqAAAABA"]
[Tue Jul 21 08:51:06.601798 2026] [proxy:error] [pid 514479:tid 514667] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:51:06.601893 2026] [proxy_http:error] [pid 514479:tid 514667] [client 64.23.200.236:34246] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.ssvistorias.com.br/
[Tue Jul 21 08:51:06.602455 2026] [proxy:error] [pid 514479:tid 514667] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:51:06.602488 2026] [proxy_http:error] [pid 514479:tid 514667] [client 64.23.200.236:34246] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.ssvistorias.com.br/
[Tue Jul 21 08:51:06.736616 2026] [security2:error] [pid 514479:tid 514659] [client 203.25.124.57:50689] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/includes/images/index.php"] [unique_id "al9dKvzqsQqnLoCgUjiP8wAAATc"]
[Tue Jul 21 08:51:06.742985 2026] [security2:error] [pid 511108:tid 511245] [client 168.167.81.163:60343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dKoTd5soprXwxAH0prgAAAAc"]
[Tue Jul 21 08:51:06.743080 2026] [security2:error] [pid 511108:tid 511245] [client 168.167.81.163:60343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dKoTd5soprXwxAH0prgAAAAc"]
[Tue Jul 21 08:51:06.798353 2026] [security2:error] [pid 511108:tid 511236] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9dKoTd5soprXwxAH0psQAAUH8"], referer: www.google.com
[Tue Jul 21 08:51:06.799252 2026] [security2:error] [pid 514479:tid 514536] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-plain.php"] [unique_id "al9dKvzqsQqnLoCgUjiP9AABGDQ"], referer: www.google.com
[Tue Jul 21 08:51:06.810084 2026] [security2:error] [pid 511108:tid 511191] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9dKoTd5soprXwxAH0psgAAaVI"]
[Tue Jul 21 08:51:07.002161 2026] [security2:error] [pid 511108:tid 511206] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/cduzbnha.php"] [unique_id "al9dK4Td5soprXwxAH0ptQAAC2E"], referer: www.google.com
[Tue Jul 21 08:51:07.002512 2026] [security2:error] [pid 511108:tid 511135] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9dK4Td5soprXwxAH0ptgAACxo"], referer: www.google.com
[Tue Jul 21 08:51:07.060383 2026] [security2:error] [pid 514479:tid 514636] [client 65.21.113.253:37516] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dK_zqsQqnLoCgUjiP9gAAASA"]
[Tue Jul 21 08:51:07.219167 2026] [security2:error] [pid 511108:tid 511333] [client 5.31.193.106:1667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dK4Td5soprXwxAH0pugAAAF8"]
[Tue Jul 21 08:51:07.219315 2026] [security2:error] [pid 511108:tid 511333] [client 5.31.193.106:1667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dK4Td5soprXwxAH0pugAAAF8"]
[Tue Jul 21 08:51:07.275562 2026] [security2:error] [pid 514479:tid 514535] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dK_zqsQqnLoCgUjiP_QABgzM"]
[Tue Jul 21 08:51:07.275787 2026] [security2:error] [pid 514479:tid 514735] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dK_zqsQqnLoCgUjiP_QABgzM"]
[Tue Jul 21 08:51:07.331167 2026] [proxy:error] [pid 514479:tid 514682] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:51:07.331253 2026] [proxy_http:error] [pid 514479:tid 514682] [client 64.23.200.236:52946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:51:07.333011 2026] [proxy:error] [pid 514479:tid 514682] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:51:07.333078 2026] [proxy_http:error] [pid 514479:tid 514682] [client 64.23.200.236:52946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:51:07.434947 2026] [security2:error] [pid 514479:tid 514696] [client 203.25.124.58:54079] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/includes/update-core-time.php"] [unique_id "al9dK_zqsQqnLoCgUjiP_wAAAVw"]
[Tue Jul 21 08:51:07.510501 2026] [security2:error] [pid 514479:tid 514643] [client 20.104.96.117:4023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/jj.php"] [unique_id "al9dK_zqsQqnLoCgUjiQAAAAASc"]
[Tue Jul 21 08:51:07.578773 2026] [security2:error] [pid 514479:tid 514634] [client 203.25.124.192:45161] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/zgbrarc/cong.php"] [unique_id "al9dK_zqsQqnLoCgUjiQBAAAAR4"]
[Tue Jul 21 08:51:08.144845 2026] [security2:error] [pid 514479:tid 514687] [client 65.21.113.253:39624] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dK_zqsQqnLoCgUjiQCQAAAVM"]
[Tue Jul 21 08:51:08.339071 2026] [security2:error] [pid 514479:tid 514741] [client 59.95.197.55:56391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dLPzqsQqnLoCgUjiQFAAAAYk"]
[Tue Jul 21 08:51:08.339208 2026] [security2:error] [pid 514479:tid 514741] [client 59.95.197.55:56391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dLPzqsQqnLoCgUjiQFAAAAYk"]
[Tue Jul 21 08:51:08.350158 2026] [security2:error] [pid 511108:tid 511354] [client 212.32.76.14:32723] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/woocommerce-call.php"] [unique_id "al9dLITd5soprXwxAH0pzgAAAHQ"]
[Tue Jul 21 08:51:08.358243 2026] [security2:error] [pid 514479:tid 514710] [client 20.104.96.117:59682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/js.php"] [unique_id "al9dLPzqsQqnLoCgUjiQFQAAAWo"]
[Tue Jul 21 08:51:08.490159 2026] [security2:error] [pid 514479:tid 514582] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "al9dLPzqsQqnLoCgUjiQFwABfWE"]
[Tue Jul 21 08:51:08.571483 2026] [security2:error] [pid 514479:tid 514651] [client 122.176.100.127:58128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dLPzqsQqnLoCgUjiQGAAAAS8"]
[Tue Jul 21 08:51:08.571693 2026] [security2:error] [pid 514479:tid 514651] [client 122.176.100.127:58128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dLPzqsQqnLoCgUjiQGAAAAS8"]
[Tue Jul 21 08:51:08.683576 2026] [security2:error] [pid 514479:tid 514650] [client 203.25.124.187:62989] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/autoload_classmap.php"] [unique_id "al9dLPzqsQqnLoCgUjiQHAAAAS4"]
[Tue Jul 21 08:51:08.894259 2026] [security2:error] [pid 511108:tid 511352] [client 20.104.96.117:46752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/class-walker-footer-dev.php"] [unique_id "al9dLITd5soprXwxAH0qBAAAAHI"]
[Tue Jul 21 08:51:09.096688 2026] [security2:error] [pid 511108:tid 511244] [client 114.198.138.124:53718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dLYTd5soprXwxAH0qFwAAAAY"]
[Tue Jul 21 08:51:09.097032 2026] [security2:error] [pid 511108:tid 511244] [client 114.198.138.124:53718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dLYTd5soprXwxAH0qFwAAAAY"]
[Tue Jul 21 08:51:09.741762 2026] [security2:error] [pid 514479:tid 514733] [client 203.25.124.52:57089] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/user/upgrade/index.php"] [unique_id "al9dLfzqsQqnLoCgUjiQMAAAAYE"]
[Tue Jul 21 08:51:09.762469 2026] [security2:error] [pid 514479:tid 514543] [remote 45.3.34.80:37623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.34.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9dLfzqsQqnLoCgUjiQKgABcjs"]
[Tue Jul 21 08:51:09.771424 2026] [security2:error] [pid 511108:tid 511306] [client 203.25.124.252:49497] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/customize/wp-conflg.php"] [unique_id "al9dLYTd5soprXwxAH0qJwAAAEQ"]
[Tue Jul 21 08:51:09.956038 2026] [security2:error] [pid 514479:tid 514530] [remote 119.195.102.159:40728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "franciscaco.com.br"] [uri "/wp-login.php"] [unique_id "al9dLfzqsQqnLoCgUjiQMQABgy4"]
[Tue Jul 21 08:51:10.425559 2026] [security2:error] [pid 511108:tid 511354] [client 49.144.66.253:29914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dLoTd5soprXwxAH0qNQAAAHQ"]
[Tue Jul 21 08:51:10.425717 2026] [security2:error] [pid 511108:tid 511354] [client 49.144.66.253:29914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dLoTd5soprXwxAH0qNQAAAHQ"]
[Tue Jul 21 08:51:10.541054 2026] [proxy:error] [pid 514479:tid 514576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:51:10.541108 2026] [proxy_http:error] [pid 514479:tid 514576] [remote 74.7.175.168:58152] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:51:10.541879 2026] [proxy:error] [pid 514479:tid 514576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:51:10.541920 2026] [proxy_http:error] [pid 514479:tid 514576] [remote 74.7.175.168:58152] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:51:10.614963 2026] [security2:error] [pid 514479:tid 514665] [client 20.104.96.117:4036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/txets.php"] [unique_id "al9dLvzqsQqnLoCgUjiQQAAAAT0"]
[Tue Jul 21 08:51:11.045365 2026] [security2:error] [pid 514479:tid 514629] [client 203.25.124.39:24631] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/maint/css/index.php"] [unique_id "al9dL_zqsQqnLoCgUjiQSQAAARk"]
[Tue Jul 21 08:51:11.070862 2026] [security2:error] [pid 514479:tid 514627] [client 5.38.115.39:56016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dL_zqsQqnLoCgUjiQSgAAARc"]
[Tue Jul 21 08:51:11.071052 2026] [security2:error] [pid 514479:tid 514627] [client 5.38.115.39:56016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dL_zqsQqnLoCgUjiQSgAAARc"]
[Tue Jul 21 08:51:11.180414 2026] [security2:error] [pid 514479:tid 514654] [client 203.25.124.200:50629] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/themes.php"] [unique_id "al9dL_zqsQqnLoCgUjiQUAAAATI"]
[Tue Jul 21 08:51:11.394854 2026] [security2:error] [pid 514479:tid 514620] [client 152.59.181.104:54318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dL_zqsQqnLoCgUjiQWgAAARA"]
[Tue Jul 21 08:51:11.395031 2026] [security2:error] [pid 514479:tid 514620] [client 152.59.181.104:54318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dL_zqsQqnLoCgUjiQWgAAARA"]
[Tue Jul 21 08:51:11.401269 2026] [security2:error] [pid 511108:tid 511309] [client 195.49.128.211:63597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dL4Td5soprXwxAH0qPwAAAEc"]
[Tue Jul 21 08:51:11.401377 2026] [security2:error] [pid 511108:tid 511309] [client 195.49.128.211:63597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dL4Td5soprXwxAH0qPwAAAEc"]
[Tue Jul 21 08:51:11.510050 2026] [security2:error] [pid 511108:tid 511253] [client 173.252.95.9:56590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dL4Td5soprXwxAH0qQQAAAA8"]
[Tue Jul 21 08:51:11.782369 2026] [proxy:error] [pid 514479:tid 514653] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:51:11.782428 2026] [proxy_http:error] [pid 514479:tid 514653] [client 64.23.200.236:53038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.ssvistorias.com.br/
[Tue Jul 21 08:51:11.782874 2026] [proxy:error] [pid 514479:tid 514653] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:51:11.782908 2026] [proxy_http:error] [pid 514479:tid 514653] [client 64.23.200.236:53038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.ssvistorias.com.br/
[Tue Jul 21 08:51:11.944076 2026] [security2:error] [pid 514479:tid 514681] [client 20.104.96.117:3985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/dex.php"] [unique_id "al9dL_zqsQqnLoCgUjiQYAAAAU0"]
[Tue Jul 21 08:51:12.008702 2026] [security2:error] [pid 514479:tid 514707] [client 41.89.234.2:59331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dMPzqsQqnLoCgUjiQYgAAAWc"]
[Tue Jul 21 08:51:12.008855 2026] [security2:error] [pid 514479:tid 514707] [client 41.89.234.2:59331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dMPzqsQqnLoCgUjiQYgAAAWc"]
[Tue Jul 21 08:51:12.037182 2026] [security2:error] [pid 511108:tid 511350] [client 203.25.124.35:43319] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/pattern/index.php"] [unique_id "al9dMITd5soprXwxAH0qSgAAAHA"]
[Tue Jul 21 08:51:12.089153 2026] [security2:error] [pid 514479:tid 514665] [client 20.220.225.223:46343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/wp-editor.php"] [unique_id "al9dMPzqsQqnLoCgUjiQYwAAAT0"]
[Tue Jul 21 08:51:12.110014 2026] [autoindex:error] [pid 511108:tid 511223] [remote 74.7.243.194:36044] AH01276: Cannot serve directory /home2/cla35313/protetordegraxa.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://sergechel.info
[Tue Jul 21 08:51:12.202485 2026] [security2:error] [pid 514479:tid 514641] [client 103.59.206.240:31332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dMPzqsQqnLoCgUjiQZAAAASU"]
[Tue Jul 21 08:51:12.202593 2026] [security2:error] [pid 514479:tid 514641] [client 103.59.206.240:31332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dMPzqsQqnLoCgUjiQZAAAASU"]
[Tue Jul 21 08:51:12.407323 2026] [security2:error] [pid 514479:tid 514666] [client 173.252.95.4:39136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dMPzqsQqnLoCgUjiQagAAAT4"]
[Tue Jul 21 08:51:12.429433 2026] [security2:error] [pid 514479:tid 514545] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al9dMPzqsQqnLoCgUjiQawABOj0"]
[Tue Jul 21 08:51:12.657007 2026] [security2:error] [pid 514479:tid 514718] [client 65.21.113.253:51922] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dMPzqsQqnLoCgUjiQdQAAAXI"]
[Tue Jul 21 08:51:12.672143 2026] [security2:error] [pid 514479:tid 514648] [client 20.104.96.117:3995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/xpwer1.php"] [unique_id "al9dMPzqsQqnLoCgUjiQeAAAASw"]
[Tue Jul 21 08:51:13.116080 2026] [security2:error] [pid 514479:tid 514587] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dMfzqsQqnLoCgUjiQfwABNGY"]
[Tue Jul 21 08:51:13.116220 2026] [security2:error] [pid 514479:tid 514656] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dMfzqsQqnLoCgUjiQfwABNGY"]
[Tue Jul 21 08:51:13.143507 2026] [security2:error] [pid 514479:tid 514713] [client 212.32.76.11:22625] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/upgrade-temp-backup/chosen.php"] [unique_id "al9dMfzqsQqnLoCgUjiQgAAAAW0"]
[Tue Jul 21 08:51:13.457582 2026] [security2:error] [pid 514479:tid 514624] [client 15.204.80.170:53392] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "zooparquevet.com.br"] [uri "/"] [unique_id "al9dMfzqsQqnLoCgUjiQhwAAARQ"]
[Tue Jul 21 08:51:13.673999 2026] [security2:error] [pid 514479:tid 514665] [client 20.104.96.117:46746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/flox.php"] [unique_id "al9dMfzqsQqnLoCgUjiQiwAAAT0"]
[Tue Jul 21 08:51:13.715189 2026] [security2:error] [pid 514479:tid 514650] [client 20.104.96.117:59181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/core.php"] [unique_id "al9dMfzqsQqnLoCgUjiQjAAAAS4"]
[Tue Jul 21 08:51:13.733998 2026] [security2:error] [pid 514479:tid 514573] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dMfzqsQqnLoCgUjiQjQABZ1g"]
[Tue Jul 21 08:51:13.734140 2026] [security2:error] [pid 514479:tid 514707] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dMfzqsQqnLoCgUjiQjQABZ1g"]
[Tue Jul 21 08:51:13.734860 2026] [security2:error] [pid 514479:tid 514664] [client 65.21.113.253:42372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dMfzqsQqnLoCgUjiQgQAAATw"]
[Tue Jul 21 08:51:13.980043 2026] [core:alert] [pid 514479:tid 514712] [client 57.141.18.24:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:51:14.340306 2026] [security2:error] [pid 514479:tid 514627] [client 212.32.76.12:35857] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/elementor/includes/template-library/classes/view.php"] [unique_id "al9dMvzqsQqnLoCgUjiQlgAAARc"]
[Tue Jul 21 08:51:14.574173 2026] [security2:error] [pid 511108:tid 511365] [client 212.32.76.58:42507] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/fmadmin.php"] [unique_id "al9dMoTd5soprXwxAH0qeAAAAH8"]
[Tue Jul 21 08:51:14.613437 2026] [access_compat:error] [pid 514479:tid 514727] [client 13.219.67.125:0] AH01797: client denied by server configuration: /home4/fabi0417/powerflats.com.br/index.php4
[Tue Jul 21 08:51:14.729445 2026] [security2:error] [pid 514479:tid 514720] [client 20.104.96.117:4055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/popo.php"] [unique_id "al9dMvzqsQqnLoCgUjiQogAAAXQ"]
[Tue Jul 21 08:51:15.396527 2026] [security2:error] [pid 514479:tid 514584] [remote 47.86.33.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alphafix.com.br"] [uri "/wp-login.php"] [unique_id "al9dM_zqsQqnLoCgUjiQrgABU2M"]
[Tue Jul 21 08:51:15.531655 2026] [access_compat:error] [pid 514479:tid 514681] [client 98.91.173.173:0] AH01797: client denied by server configuration: /home4/fabi0417/powerflats.com.br/index.php4
[Tue Jul 21 08:51:15.574266 2026] [security2:error] [pid 511108:tid 511247] [client 203.25.124.11:58835] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/class.api.php"] [unique_id "al9dM4Td5soprXwxAH0qigAAAAk"]
[Tue Jul 21 08:51:15.634059 2026] [security2:error] [pid 511108:tid 511334] [client 203.25.124.73:37145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/network/theme-install-function.php"] [unique_id "al9dM4Td5soprXwxAH0qiwAAAGA"]
[Tue Jul 21 08:51:15.920410 2026] [security2:error] [pid 511108:tid 511183] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dM4Td5soprXwxAH0qkQAAfko"]
[Tue Jul 21 08:51:15.920540 2026] [security2:error] [pid 511108:tid 511364] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dM4Td5soprXwxAH0qkQAAfko"]
[Tue Jul 21 08:51:15.964757 2026] [security2:error] [pid 511108:tid 511356] [client 182.189.99.211:48381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dM4Td5soprXwxAH0qkwAAAHY"]
[Tue Jul 21 08:51:15.964913 2026] [security2:error] [pid 511108:tid 511356] [client 182.189.99.211:48381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dM4Td5soprXwxAH0qkwAAAHY"]
[Tue Jul 21 08:51:16.114377 2026] [security2:error] [pid 514479:tid 514660] [client 168.167.81.163:60110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dNPzqsQqnLoCgUjiQwAAAATg"]
[Tue Jul 21 08:51:16.114537 2026] [security2:error] [pid 514479:tid 514660] [client 168.167.81.163:60110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dNPzqsQqnLoCgUjiQwAAAATg"]
[Tue Jul 21 08:51:16.215743 2026] [security2:error] [pid 511108:tid 511111] [remote 72.167.132.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9dNITd5soprXwxAH0qlwAAJQI"]
[Tue Jul 21 08:51:16.416273 2026] [security2:error] [pid 514479:tid 514657] [client 20.104.96.117:46754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/yas.php"] [unique_id "al9dNPzqsQqnLoCgUjiQwwAAATU"]
[Tue Jul 21 08:51:16.481246 2026] [security2:error] [pid 511108:tid 511361] [client 212.32.76.62:59493] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "al9dNITd5soprXwxAH0qmwAAAHs"]
[Tue Jul 21 08:51:16.494859 2026] [security2:error] [pid 514479:tid 514631] [client 20.104.96.117:59180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/19.php"] [unique_id "al9dNPzqsQqnLoCgUjiQxQAAARs"]
[Tue Jul 21 08:51:16.507533 2026] [security2:error] [pid 514479:tid 514628] [client 113.22.144.139:57398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dNPzqsQqnLoCgUjiQxgAAARg"]
[Tue Jul 21 08:51:16.508034 2026] [security2:error] [pid 514479:tid 514628] [client 113.22.144.139:57398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dNPzqsQqnLoCgUjiQxgAAARg"]
[Tue Jul 21 08:51:16.635950 2026] [security2:error] [pid 511108:tid 511226] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dNITd5soprXwxAH0qowAAV3U"]
[Tue Jul 21 08:51:16.636127 2026] [security2:error] [pid 511108:tid 511325] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dNITd5soprXwxAH0qowAAV3U"]
[Tue Jul 21 08:51:16.672232 2026] [security2:error] [pid 511108:tid 511312] [client 20.220.225.223:22575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/cro.php"] [unique_id "al9dNITd5soprXwxAH0qpAAAAEo"]
[Tue Jul 21 08:51:16.739540 2026] [security2:error] [pid 514479:tid 514675] [client 203.25.124.32:59833] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/shadow-bot.php"] [unique_id "al9dNPzqsQqnLoCgUjiQyQAAAUc"]
[Tue Jul 21 08:51:16.752572 2026] [security2:error] [pid 514479:tid 514734] [client 195.206.105.227:38036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dNPzqsQqnLoCgUjiQygAAAYI"]
[Tue Jul 21 08:51:16.752681 2026] [security2:error] [pid 514479:tid 514734] [client 195.206.105.227:38036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dNPzqsQqnLoCgUjiQygAAAYI"]
[Tue Jul 21 08:51:16.853312 2026] [security2:error] [pid 514479:tid 514625] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dNPzqsQqnLoCgUjiQywABFTY"]
[Tue Jul 21 08:51:17.174487 2026] [security2:error] [pid 514479:tid 514735] [client 203.25.124.3:42043] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/includes/index.php"] [unique_id "al9dNfzqsQqnLoCgUjiQ0gAAAYM"]
[Tue Jul 21 08:51:17.240014 2026] [security2:error] [pid 514479:tid 514668] [client 65.21.113.253:51922] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dNfzqsQqnLoCgUjiQ1AAAAUA"]
[Tue Jul 21 08:51:17.792302 2026] [security2:error] [pid 514479:tid 514729] [client 20.104.96.117:4013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/file61.php"] [unique_id "al9dNfzqsQqnLoCgUjiQ2QAAAX0"]
[Tue Jul 21 08:51:18.075895 2026] [security2:error] [pid 511108:tid 511199] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dNoTd5soprXwxAH0qwAAAcFo"]
[Tue Jul 21 08:51:18.076061 2026] [security2:error] [pid 511108:tid 511350] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dNoTd5soprXwxAH0qwAAAcFo"]
[Tue Jul 21 08:51:18.173393 2026] [security2:error] [pid 514479:tid 514637] [client 203.25.124.254:64659] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9dNvzqsQqnLoCgUjiQ4AAAASE"]
[Tue Jul 21 08:51:18.335909 2026] [security2:error] [pid 514479:tid 514730] [client 65.21.113.253:42378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dNfzqsQqnLoCgUjiQ2gAAAX4"]
[Tue Jul 21 08:51:18.478663 2026] [security2:error] [pid 514479:tid 514671] [client 20.220.225.223:19289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/track.php"] [unique_id "al9dNvzqsQqnLoCgUjiQ4wAAAUM"]
[Tue Jul 21 08:51:18.526122 2026] [security2:error] [pid 514479:tid 514660] [client 20.220.225.223:35126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/cron-tab.php"] [unique_id "al9dNvzqsQqnLoCgUjiQ5AAAATg"]
[Tue Jul 21 08:51:18.607192 2026] [security2:error] [pid 514479:tid 514674] [client 114.198.138.124:50741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dNvzqsQqnLoCgUjiQ5QAAAUY"]
[Tue Jul 21 08:51:18.607336 2026] [security2:error] [pid 514479:tid 514674] [client 114.198.138.124:50741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dNvzqsQqnLoCgUjiQ5QAAAUY"]
[Tue Jul 21 08:51:18.607929 2026] [security2:error] [pid 514479:tid 514619] [client 20.104.96.117:59667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/inc.php"] [unique_id "al9dNvzqsQqnLoCgUjiQ5gAAAQ8"]
[Tue Jul 21 08:51:18.813822 2026] [security2:error] [pid 511108:tid 511258] [client 59.95.197.55:56873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dNoTd5soprXwxAH0qzQAAABQ"]
[Tue Jul 21 08:51:18.813977 2026] [security2:error] [pid 511108:tid 511258] [client 59.95.197.55:56873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dNoTd5soprXwxAH0qzQAAABQ"]
[Tue Jul 21 08:51:18.938042 2026] [security2:error] [pid 514479:tid 514489] [remote 14.225.211.68:52144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.211.225.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9dNvzqsQqnLoCgUjiQ7QABRAU"]
[Tue Jul 21 08:51:19.039506 2026] [security2:error] [pid 511108:tid 511281] [client 203.25.124.55:43831] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/shadow-bot.php"] [unique_id "al9dN4Td5soprXwxAH0q0gAAACs"]
[Tue Jul 21 08:51:19.141857 2026] [security2:error] [pid 514479:tid 514737] [client 122.176.100.127:58612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dN_zqsQqnLoCgUjiQ8QAAAYU"]
[Tue Jul 21 08:51:19.141995 2026] [security2:error] [pid 514479:tid 514737] [client 122.176.100.127:58612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dN_zqsQqnLoCgUjiQ8QAAAYU"]
[Tue Jul 21 08:51:19.157329 2026] [security2:error] [pid 514479:tid 514691] [client 216.73.160.19:47997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9dN_zqsQqnLoCgUjiQ8gAAAVc"]
[Tue Jul 21 08:51:19.363265 2026] [security2:error] [pid 511108:tid 511181] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "al9dN4Td5soprXwxAH0q3AAADUg"]
[Tue Jul 21 08:51:19.402040 2026] [security2:error] [pid 511108:tid 511122] [remote 103.82.22.235:45406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/wp-login.php"] [unique_id "al9dN4Td5soprXwxAH0q3QAAWg0"]
[Tue Jul 21 08:51:19.474564 2026] [security2:error] [pid 514479:tid 514733] [client 212.32.76.61:24401] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/assets/index.php"] [unique_id "al9dN_zqsQqnLoCgUjiQ9gAAAYE"]
[Tue Jul 21 08:51:19.586544 2026] [security2:error] [pid 511108:tid 511325] [client 20.104.96.117:4080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/water.php"] [unique_id "al9dN4Td5soprXwxAH0q3wAAAFc"]
[Tue Jul 21 08:51:20.171661 2026] [security2:error] [pid 514479:tid 514710] [client 203.25.124.200:37113] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "al9dOPzqsQqnLoCgUjiQ_gAAAWo"]
[Tue Jul 21 08:51:20.298533 2026] [access_compat:error] [pid 511108:tid 511310] [client 162.241.63.68:12398] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:51:20.615172 2026] [security2:error] [pid 511108:tid 511358] [client 20.220.225.223:19267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/2352356666.php"] [unique_id "al9dOITd5soprXwxAH0q9gAAAHg"]
[Tue Jul 21 08:51:20.761690 2026] [security2:error] [pid 511108:tid 511327] [client 198.44.157.34:57006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9dOITd5soprXwxAH0q_AAAAFk"]
[Tue Jul 21 08:51:20.761788 2026] [security2:error] [pid 511108:tid 511327] [client 198.44.157.34:57006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9dOITd5soprXwxAH0q_AAAAFk"]
[Tue Jul 21 08:51:20.925744 2026] [security2:error] [pid 511108:tid 511306] [client 20.104.96.117:59678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-ppoxua4.php"] [unique_id "al9dOITd5soprXwxAH0rAgAAAEQ"]
[Tue Jul 21 08:51:21.191305 2026] [security2:error] [pid 514479:tid 514636] [client 20.104.96.117:46776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/nano.php"] [unique_id "al9dOfzqsQqnLoCgUjiRCgAAASA"]
[Tue Jul 21 08:51:21.272468 2026] [security2:error] [pid 514479:tid 514721] [client 212.32.76.63:27457] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/load.php"] [unique_id "al9dOfzqsQqnLoCgUjiRCwAAAXU"]
[Tue Jul 21 08:51:21.380028 2026] [security2:error] [pid 511108:tid 511273] [client 152.59.181.104:54836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dOYTd5soprXwxAH0rCwAAACM"]
[Tue Jul 21 08:51:21.384747 2026] [security2:error] [pid 511108:tid 511273] [client 152.59.181.104:54836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dOYTd5soprXwxAH0rCwAAACM"]
[Tue Jul 21 08:51:21.385277 2026] [security2:error] [pid 511108:tid 511238] [client 49.144.66.253:30399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dOYTd5soprXwxAH0rDAAAAAA"]
[Tue Jul 21 08:51:21.385384 2026] [security2:error] [pid 511108:tid 511238] [client 49.144.66.253:30399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dOYTd5soprXwxAH0rDAAAAAA"]
[Tue Jul 21 08:51:21.540554 2026] [security2:error] [pid 514479:tid 514610] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/.aws/config"] [unique_id "al9dOfzqsQqnLoCgUjiRFQABbH0"]
[Tue Jul 21 08:51:21.730752 2026] [security2:error] [pid 511108:tid 511316] [client 5.38.115.39:56582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dOYTd5soprXwxAH0rDwAAAE4"]
[Tue Jul 21 08:51:21.730908 2026] [security2:error] [pid 511108:tid 511316] [client 5.38.115.39:56582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dOYTd5soprXwxAH0rDwAAAE4"]
[Tue Jul 21 08:51:21.743127 2026] [security2:error] [pid 511108:tid 511344] [client 212.32.76.2:23751] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/load.php"] [unique_id "al9dOYTd5soprXwxAH0rEAAAAGo"]
[Tue Jul 21 08:51:21.933486 2026] [security2:error] [pid 514479:tid 514682] [client 74.7.230.40:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "lacorsini.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9dOfzqsQqnLoCgUjiRIgABTng"]
[Tue Jul 21 08:51:21.960472 2026] [security2:error] [pid 514479:tid 514622] [client 20.220.225.223:19322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/pn.php"] [unique_id "al9dOfzqsQqnLoCgUjiRJAAAARI"]
[Tue Jul 21 08:51:21.982791 2026] [autoindex:error] [pid 511108:tid 511167] [remote 74.7.241.57:0] AH01276: Cannot serve directory /home1/bastar15/lacorsini.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:51:22.050328 2026] [security2:error] [pid 514479:tid 514635] [client 195.49.128.211:64211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dOvzqsQqnLoCgUjiRJQAAAR8"]
[Tue Jul 21 08:51:22.050429 2026] [security2:error] [pid 514479:tid 514635] [client 195.49.128.211:64211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dOvzqsQqnLoCgUjiRJQAAAR8"]
[Tue Jul 21 08:51:22.259966 2026] [security2:error] [pid 514479:tid 514515] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "api.gradiente.com"] [uri "/.git-credentials"] [unique_id "al9dOvzqsQqnLoCgUjiRKAABbB8"]
[Tue Jul 21 08:51:22.375097 2026] [security2:error] [pid 514479:tid 514655] [client 203.25.124.197:36635] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/index.php"] [unique_id "al9dOvzqsQqnLoCgUjiRLAAAATM"]
[Tue Jul 21 08:51:22.538368 2026] [security2:error] [pid 514479:tid 514678] [client 20.104.96.117:59142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-u3nxbvx.php"] [unique_id "al9dOvzqsQqnLoCgUjiRMAAAAUo"]
[Tue Jul 21 08:51:22.644404 2026] [security2:error] [pid 514479:tid 514688] [client 20.220.225.223:19653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wp-wpbak.php"] [unique_id "al9dOvzqsQqnLoCgUjiRNQAAAVQ"]
[Tue Jul 21 08:51:22.649156 2026] [security2:error] [pid 514479:tid 514732] [client 41.89.234.2:61306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dOvzqsQqnLoCgUjiRNgAAAYA"]
[Tue Jul 21 08:51:22.649289 2026] [security2:error] [pid 514479:tid 514732] [client 41.89.234.2:61306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dOvzqsQqnLoCgUjiRNgAAAYA"]
[Tue Jul 21 08:51:22.818036 2026] [security2:error] [pid 514479:tid 514731] [client 20.10.88.227:49218] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "arthromdcanada.online"] [uri "/robots.txt"] [unique_id "al9dOvzqsQqnLoCgUjiROwAAAX8"]
[Tue Jul 21 08:51:22.849452 2026] [security2:error] [pid 511108:tid 511277] [client 103.59.206.240:31146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dOoTd5soprXwxAH0rJAAAACc"]
[Tue Jul 21 08:51:22.849639 2026] [security2:error] [pid 511108:tid 511277] [client 103.59.206.240:31146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dOoTd5soprXwxAH0rJAAAACc"]
[Tue Jul 21 08:51:23.057080 2026] [security2:error] [pid 514479:tid 514583] [remote 68.178.160.25:52712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9dO_zqsQqnLoCgUjiRRAABaGI"]
[Tue Jul 21 08:51:23.064763 2026] [security2:error] [pid 514479:tid 514738] [client 65.21.113.253:47460] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dO_zqsQqnLoCgUjiRRwAAAYY"]
[Tue Jul 21 08:51:23.161744 2026] [security2:error] [pid 511108:tid 511359] [client 203.25.124.204:62605] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/k.php"] [unique_id "al9dO4Td5soprXwxAH0rKAAAAHk"]
[Tue Jul 21 08:51:23.167436 2026] [security2:error] [pid 514479:tid 514684] [client 20.104.96.117:61743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/moon.php"] [unique_id "al9dO_zqsQqnLoCgUjiRTQAAAVA"]
[Tue Jul 21 08:51:23.328835 2026] [security2:error] [pid 511108:tid 511338] [client 203.25.124.69:23823] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/wp-activate.php"] [unique_id "al9dO4Td5soprXwxAH0rLAAAAGQ"]
[Tue Jul 21 08:51:23.358226 2026] [security2:error] [pid 514479:tid 514507] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/.env"] [unique_id "al9dO_zqsQqnLoCgUjiRXgABZxc"]
[Tue Jul 21 08:51:23.383983 2026] [security2:error] [pid 514479:tid 514545] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "api.gradiente.com"] [uri "/.env.production"] [unique_id "al9dO_zqsQqnLoCgUjiRZwABbz0"]
[Tue Jul 21 08:51:23.385399 2026] [security2:error] [pid 514479:tid 514498] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "api.gradiente.com"] [uri "/graphql"] [unique_id "al9dO_zqsQqnLoCgUjiRaQABIA4"]
[Tue Jul 21 08:51:23.428131 2026] [security2:error] [pid 514479:tid 514590] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/.env.old"] [unique_id "al9dO_zqsQqnLoCgUjiRgwABNGk"]
[Tue Jul 21 08:51:23.448618 2026] [security2:error] [pid 514479:tid 514578] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/.env.backup"] [unique_id "al9dO_zqsQqnLoCgUjiRjwABZV0"]
[Tue Jul 21 08:51:23.451345 2026] [security2:error] [pid 514479:tid 514552] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/.env.bak"] [unique_id "al9dO_zqsQqnLoCgUjiRkwABiEM"]
[Tue Jul 21 08:51:23.471335 2026] [security2:error] [pid 514479:tid 514532] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/api/.env"] [unique_id "al9dO_zqsQqnLoCgUjiRnQABGzA"]
[Tue Jul 21 08:51:23.589928 2026] [security2:error] [pid 514479:tid 514588] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/config/.env"] [unique_id "al9dO_zqsQqnLoCgUjiRpQABW2c"]
[Tue Jul 21 08:51:23.596192 2026] [security2:error] [pid 514479:tid 514504] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/backend/.env"] [unique_id "al9dO_zqsQqnLoCgUjiRpgABQRQ"]
[Tue Jul 21 08:51:23.677854 2026] [security2:error] [pid 511108:tid 511127] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dO4Td5soprXwxAH0rNQAAExI"]
[Tue Jul 21 08:51:23.678034 2026] [security2:error] [pid 511108:tid 511257] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dO4Td5soprXwxAH0rNQAAExI"]
[Tue Jul 21 08:51:23.717757 2026] [security2:error] [pid 514479:tid 514679] [client 20.197.192.193:50616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/ftde.php"] [unique_id "al9dO_zqsQqnLoCgUjiRqAAAAUs"]
[Tue Jul 21 08:51:23.730982 2026] [security2:error] [pid 514479:tid 514563] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "api.gradiente.com"] [uri "/api/graphql"] [unique_id "al9dO_zqsQqnLoCgUjiRrAABJ04"]
[Tue Jul 21 08:51:23.952352 2026] [security2:error] [pid 514479:tid 514485] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "api.gradiente.com"] [uri "/.docker/config.json"] [unique_id "al9dO_zqsQqnLoCgUjiRuQABUgE"]
[Tue Jul 21 08:51:24.077276 2026] [security2:error] [pid 514479:tid 514585] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "api.gradiente.com"] [uri "/v1/graphql"] [unique_id "al9dPPzqsQqnLoCgUjiRwgABf2Q"]
[Tue Jul 21 08:51:24.078315 2026] [security2:error] [pid 514479:tid 514512] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/.boto"] [unique_id "al9dPPzqsQqnLoCgUjiRxAABfxw"]
[Tue Jul 21 08:51:24.129042 2026] [security2:error] [pid 514479:tid 514725] [client 65.21.113.253:59802] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dO_zqsQqnLoCgUjiRrgAAAXk"]
[Tue Jul 21 08:51:24.162333 2026] [security2:error] [pid 511108:tid 511204] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dPITd5soprXwxAH0rPgAAVV8"]
[Tue Jul 21 08:51:24.162456 2026] [security2:error] [pid 511108:tid 511323] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dPITd5soprXwxAH0rPgAAVV8"]
[Tue Jul 21 08:51:24.208074 2026] [security2:error] [pid 514479:tid 514687] [client 196.251.121.45:50676] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "162.241.63.71"] [uri "/login"] [unique_id "al9dPPzqsQqnLoCgUjiR8AAAAVM"]
[Tue Jul 21 08:51:24.244004 2026] [authz_core:error] [pid 514479:tid 514596] [remote 34.35.143.238:58352] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Tue Jul 21 08:51:24.328540 2026] [security2:error] [pid 514479:tid 514602] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/.svn/entries"] [unique_id "al9dPPzqsQqnLoCgUjiR9AABfXU"]
[Tue Jul 21 08:51:24.369758 2026] [security2:error] [pid 514479:tid 514739] [client 20.104.96.117:59703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ss.php"] [unique_id "al9dPPzqsQqnLoCgUjiR_wAAAYc"]
[Tue Jul 21 08:51:24.472748 2026] [security2:error] [pid 514479:tid 514508] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/docker-compose.yaml"] [unique_id "al9dPPzqsQqnLoCgUjiSDQABKRg"]
[Tue Jul 21 08:51:24.472935 2026] [security2:error] [pid 514479:tid 514645] [client 34.35.143.238:58352] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "api.gradiente.com"] [uri "/docker-compose.yaml"] [unique_id "al9dPPzqsQqnLoCgUjiSDQABKRg"]
[Tue Jul 21 08:51:24.512688 2026] [security2:error] [pid 514479:tid 514519] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/.ssh/id_rsa"] [unique_id "al9dPPzqsQqnLoCgUjiSEQABLiM"]
[Tue Jul 21 08:51:24.553598 2026] [security2:error] [pid 514479:tid 514529] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/.ssh/id_ecdsa"] [unique_id "al9dPPzqsQqnLoCgUjiSEwABPC0"]
[Tue Jul 21 08:51:24.555491 2026] [security2:error] [pid 514479:tid 514553] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/.ssh/id_dsa"] [unique_id "al9dPPzqsQqnLoCgUjiSEgABPEQ"]
[Tue Jul 21 08:51:24.555835 2026] [security2:error] [pid 514479:tid 514578] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "api.gradiente.com"] [uri "/.ssh/id_ed25519"] [unique_id "al9dPPzqsQqnLoCgUjiSFAABPF0"]
[Tue Jul 21 08:51:24.671546 2026] [security2:error] [pid 514479:tid 514721] [client 20.220.225.223:19970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/dr.php"] [unique_id "al9dPPzqsQqnLoCgUjiSGAAAAXU"]
[Tue Jul 21 08:51:24.765085 2026] [security2:error] [pid 514479:tid 514516] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/id_rsa"] [unique_id "al9dPPzqsQqnLoCgUjiSGgABFiA"]
[Tue Jul 21 08:51:24.867472 2026] [security2:error] [pid 514479:tid 514554] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "api.gradiente.com"] [uri "/id_dsa"] [unique_id "al9dPPzqsQqnLoCgUjiSIAABZUU"]
[Tue Jul 21 08:51:24.884350 2026] [security2:error] [pid 514479:tid 514533] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "api.gradiente.com"] [uri "/id_ecdsa"] [unique_id "al9dPPzqsQqnLoCgUjiSIgABiDE"]
[Tue Jul 21 08:51:24.913144 2026] [security2:error] [pid 514479:tid 514500] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/key.pem"] [unique_id "al9dPPzqsQqnLoCgUjiSIwABdhA"]
[Tue Jul 21 08:51:24.951754 2026] [security2:error] [pid 514479:tid 514489] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/privatekey.key"] [unique_id "al9dPPzqsQqnLoCgUjiSJgABRgU"]
[Tue Jul 21 08:51:24.969858 2026] [security2:error] [pid 514479:tid 514666] [client 20.197.192.193:56771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/yup.php"] [unique_id "al9dPPzqsQqnLoCgUjiSKAAAAT4"]
[Tue Jul 21 08:51:24.986381 2026] [security2:error] [pid 514479:tid 514682] [client 20.220.225.223:22583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/koiy.php"] [unique_id "al9dPPzqsQqnLoCgUjiSKQAAAU4"]
[Tue Jul 21 08:51:25.042854 2026] [security2:error] [pid 514479:tid 514622] [client 212.32.76.7:34515] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/module.php"] [unique_id "al9dPfzqsQqnLoCgUjiSLAAAARI"]
[Tue Jul 21 08:51:25.074953 2026] [security2:error] [pid 514479:tid 514660] [client 203.25.124.206:43569] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-conflg.php"] [unique_id "al9dPfzqsQqnLoCgUjiSLgAAATg"]
[Tue Jul 21 08:51:25.128649 2026] [security2:error] [pid 514479:tid 514539] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "api.gradiente.com"] [uri "/private-key"] [unique_id "al9dPfzqsQqnLoCgUjiSMAABRzc"]
[Tue Jul 21 08:51:25.459592 2026] [security2:error] [pid 514479:tid 514546] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/ssl/localhost.key"] [unique_id "al9dPfzqsQqnLoCgUjiSOgABJD4"]
[Tue Jul 21 08:51:25.459839 2026] [security2:error] [pid 514479:tid 514640] [client 34.35.143.238:58352] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "api.gradiente.com"] [uri "/ssl/localhost.key"] [unique_id "al9dPfzqsQqnLoCgUjiSOgABJD4"]
[Tue Jul 21 08:51:25.460596 2026] [security2:error] [pid 514479:tid 514557] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/.openclaw/.env"] [unique_id "al9dPfzqsQqnLoCgUjiSOQABJEg"]
[Tue Jul 21 08:51:25.509532 2026] [security2:error] [pid 514479:tid 514610] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/.continue/config.json"] [unique_id "al9dPfzqsQqnLoCgUjiSPAABgX0"]
[Tue Jul 21 08:51:25.509668 2026] [security2:error] [pid 514479:tid 514733] [client 34.35.143.238:58352] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "api.gradiente.com"] [uri "/.continue/config.json"] [unique_id "al9dPfzqsQqnLoCgUjiSPAABgX0"]
[Tue Jul 21 08:51:25.529695 2026] [security2:error] [pid 514479:tid 514608] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "api.gradiente.com"] [uri "/.codex/config.toml"] [unique_id "al9dPfzqsQqnLoCgUjiSPgABN3s"]
[Tue Jul 21 08:51:25.728555 2026] [security2:error] [pid 514479:tid 514515] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/.hermes/.env"] [unique_id "al9dPfzqsQqnLoCgUjiSQgABgB8"]
[Tue Jul 21 08:51:25.728738 2026] [security2:error] [pid 514479:tid 514732] [client 34.35.143.238:58352] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "api.gradiente.com"] [uri "/.hermes/.env"] [unique_id "al9dPfzqsQqnLoCgUjiSQgABgB8"]
[Tue Jul 21 08:51:25.817251 2026] [security2:error] [pid 514479:tid 514638] [client 31.57.219.92:8208] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "odontoclinicms.com.br"] [uri "/"] [unique_id "al9dPfzqsQqnLoCgUjiSRwAAASI"]
[Tue Jul 21 08:51:25.833460 2026] [security2:error] [pid 514479:tid 514731] [client 20.220.225.223:35073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/hp2.php"] [unique_id "al9dPfzqsQqnLoCgUjiSSAAAAX8"]
[Tue Jul 21 08:51:26.097840 2026] [security2:error] [pid 511108:tid 511352] [client 20.104.96.117:61126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/min.php"] [unique_id "al9dPoTd5soprXwxAH0rZQAAAHI"]
[Tue Jul 21 08:51:26.231215 2026] [security2:error] [pid 514479:tid 514541] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "api.gradiente.com"] [uri "/wp-config.php.old"] [unique_id "al9dPvzqsQqnLoCgUjiSXAABhzk"]
[Tue Jul 21 08:51:26.282702 2026] [security2:error] [pid 514479:tid 514523] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "api.gradiente.com"] [uri "/wp-config.php.bak"] [unique_id "al9dPvzqsQqnLoCgUjiSZAABhCc"]
[Tue Jul 21 08:51:26.465696 2026] [core:error] [pid 514479:tid 514498] [remote 95.108.213.167:57836] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:51:26.465725 2026] [core:error] [pid 514479:tid 514498] [remote 95.108.213.167:57836] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:51:26.468184 2026] [security2:error] [pid 514479:tid 514609] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dPvzqsQqnLoCgUjiSfAABHXw"]
[Tue Jul 21 08:51:26.468328 2026] [security2:error] [pid 514479:tid 514633] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dPvzqsQqnLoCgUjiSfAABHXw"]
[Tue Jul 21 08:51:26.499254 2026] [security2:error] [pid 514479:tid 514628] [client 182.189.99.211:48170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dPvzqsQqnLoCgUjiSfwAAARg"]
[Tue Jul 21 08:51:26.499349 2026] [security2:error] [pid 514479:tid 514628] [client 182.189.99.211:48170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dPvzqsQqnLoCgUjiSfwAAARg"]
[Tue Jul 21 08:51:26.574693 2026] [security2:error] [pid 514479:tid 514721] [client 203.25.124.188:59991] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/block-bindings/"] [unique_id "al9dPvzqsQqnLoCgUjiShAAAAXU"]
[Tue Jul 21 08:51:26.580930 2026] [security2:error] [pid 514479:tid 514521] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/laravel/.env"] [unique_id "al9dPvzqsQqnLoCgUjiShQABKiU"]
[Tue Jul 21 08:51:26.583345 2026] [security2:error] [pid 514479:tid 514564] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.gradiente.com"] [uri "/config/.env.php"] [unique_id "al9dPvzqsQqnLoCgUjiShwABKk8"]
[Tue Jul 21 08:51:26.600706 2026] [security2:error] [pid 511108:tid 511286] [client 20.220.225.223:19311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/2x.php"] [unique_id "al9dPoTd5soprXwxAH0raQAAADA"]
[Tue Jul 21 08:51:26.613108 2026] [security2:error] [pid 514479:tid 514596] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.gradiente.com"] [uri "/.env.php.bak"] [unique_id "al9dPvzqsQqnLoCgUjiSiQABZW8"]
[Tue Jul 21 08:51:26.614080 2026] [security2:error] [pid 514479:tid 514561] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/core/.env"] [unique_id "al9dPvzqsQqnLoCgUjiSiAABZUw"]
[Tue Jul 21 08:51:26.633926 2026] [security2:error] [pid 514479:tid 514587] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.gradiente.com"] [uri "/config.php.bak"] [unique_id "al9dPvzqsQqnLoCgUjiSigABiGY"]
[Tue Jul 21 08:51:26.659688 2026] [security2:error] [pid 514479:tid 514562] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.gradiente.com"] [uri "/configuration.php.bak"] [unique_id "al9dPvzqsQqnLoCgUjiSjgABVk0"]
[Tue Jul 21 08:51:26.672520 2026] [security2:error] [pid 514479:tid 514712] [client 168.167.81.163:60469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dPvzqsQqnLoCgUjiSjwAAAWw"]
[Tue Jul 21 08:51:26.678744 2026] [security2:error] [pid 514479:tid 514712] [client 168.167.81.163:60469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dPvzqsQqnLoCgUjiSjwAAAWw"]
[Tue Jul 21 08:51:26.800757 2026] [security2:error] [pid 514479:tid 514579] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/.env.swp"] [unique_id "al9dPvzqsQqnLoCgUjiSkwABF14"]
[Tue Jul 21 08:51:26.857426 2026] [security2:error] [pid 511108:tid 511362] [client 20.104.96.117:4093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-info.php"] [unique_id "al9dPoTd5soprXwxAH0rbQAAAHw"]
[Tue Jul 21 08:51:26.858494 2026] [security2:error] [pid 514479:tid 514560] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/web/.env"] [unique_id "al9dPvzqsQqnLoCgUjiSlQABOEs"]
[Tue Jul 21 08:51:26.928394 2026] [security2:error] [pid 514479:tid 514597] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/public/.env"] [unique_id "al9dPvzqsQqnLoCgUjiSlwABLHA"]
[Tue Jul 21 08:51:26.993892 2026] [security2:error] [pid 514479:tid 514573] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/config/application.properties"] [unique_id "al9dPvzqsQqnLoCgUjiSnQABJ1g"]
[Tue Jul 21 08:51:26.994007 2026] [security2:error] [pid 514479:tid 514590] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "api.gradiente.com"] [uri "/bootstrap.properties"] [unique_id "al9dPvzqsQqnLoCgUjiSmwABJ2k"]
[Tue Jul 21 08:51:27.252122 2026] [security2:error] [pid 514479:tid 514540] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dP_zqsQqnLoCgUjiSuQABVDg"]
[Tue Jul 21 08:51:27.252246 2026] [security2:error] [pid 514479:tid 514688] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dP_zqsQqnLoCgUjiSuQABVDg"]
[Tue Jul 21 08:51:27.288023 2026] [security2:error] [pid 514479:tid 514619] [client 5.31.193.106:58590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dP_zqsQqnLoCgUjiSugAAAQ8"]
[Tue Jul 21 08:51:27.288114 2026] [security2:error] [pid 514479:tid 514619] [client 5.31.193.106:58590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dP_zqsQqnLoCgUjiSugAAAQ8"]
[Tue Jul 21 08:51:27.367125 2026] [security2:error] [pid 514479:tid 514533] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "al9dP_zqsQqnLoCgUjiSvAABXzE"]
[Tue Jul 21 08:51:27.375648 2026] [security2:error] [pid 514479:tid 514704] [client 212.32.76.54:58391] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-confiq.php"] [unique_id "al9dP_zqsQqnLoCgUjiSvQAAAWQ"]
[Tue Jul 21 08:51:27.410325 2026] [security2:error] [pid 514479:tid 514686] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dP_zqsQqnLoCgUjiSuwABUkU"]
[Tue Jul 21 08:51:27.502850 2026] [security2:error] [pid 511108:tid 511292] [client 20.197.192.193:56826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/jj.php"] [unique_id "al9dP4Td5soprXwxAH0reAAAADY"]
[Tue Jul 21 08:51:27.643113 2026] [security2:error] [pid 514479:tid 514711] [client 203.25.124.211:23667] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/wp-links-opml.php"] [unique_id "al9dP_zqsQqnLoCgUjiSxgAAAWs"]
[Tue Jul 21 08:51:27.658130 2026] [security2:error] [pid 514479:tid 514622] [client 113.22.144.139:57949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dP_zqsQqnLoCgUjiSxwAAARI"]
[Tue Jul 21 08:51:27.659099 2026] [security2:error] [pid 514479:tid 514622] [client 113.22.144.139:57949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dP_zqsQqnLoCgUjiSxwAAARI"]
[Tue Jul 21 08:51:27.682769 2026] [security2:error] [pid 514479:tid 514651] [client 65.21.113.253:47476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9dP_zqsQqnLoCgUjiSyAAAAS8"]
[Tue Jul 21 08:51:27.728778 2026] [security2:error] [pid 514479:tid 514532] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/actuator/env"] [unique_id "al9dP_zqsQqnLoCgUjiSyQABHTA"]
[Tue Jul 21 08:51:27.793168 2026] [security2:error] [pid 514479:tid 514522] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/appsettings.json"] [unique_id "al9dP_zqsQqnLoCgUjiSzgABGCY"]
[Tue Jul 21 08:51:27.809795 2026] [security2:error] [pid 514479:tid 514594] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "api.gradiente.com"] [uri "/local.settings.json"] [unique_id "al9dP_zqsQqnLoCgUjiS0QABLm0"]
[Tue Jul 21 08:51:27.810482 2026] [security2:error] [pid 514479:tid 514504] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/appsettings.Production.json"] [unique_id "al9dP_zqsQqnLoCgUjiS0wABLhQ"]
[Tue Jul 21 08:51:27.810615 2026] [security2:error] [pid 514479:tid 514650] [client 34.35.143.238:58352] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "api.gradiente.com"] [uri "/appsettings.Production.json"] [unique_id "al9dP_zqsQqnLoCgUjiS0wABLhQ"]
[Tue Jul 21 08:51:27.811520 2026] [security2:error] [pid 514479:tid 514588] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/web.config"] [unique_id "al9dP_zqsQqnLoCgUjiS0gABLmc"]
[Tue Jul 21 08:51:27.957728 2026] [security2:error] [pid 511108:tid 511246] [client 91.148.244.131:43076] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/"] [unique_id "al9dP4Td5soprXwxAH0rgwAAAAg"]
[Tue Jul 21 08:51:27.961779 2026] [security2:error] [pid 514479:tid 514665] [client 91.148.244.131:43066] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/"] [unique_id "al9dP_zqsQqnLoCgUjiS2AAAAT0"]
[Tue Jul 21 08:51:27.967343 2026] [security2:error] [pid 514479:tid 514676] [client 91.148.244.131:43078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/"] [unique_id "al9dP_zqsQqnLoCgUjiS2QAAAUg"]
[Tue Jul 21 08:51:28.148375 2026] [security2:error] [pid 514479:tid 514608] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/config/secrets.yml"] [unique_id "al9dQPzqsQqnLoCgUjiS5gABbXs"]
[Tue Jul 21 08:51:28.170648 2026] [security2:error] [pid 514479:tid 514604] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "api.gradiente.com"] [uri "/.streamlit/secrets.toml"] [unique_id "al9dQPzqsQqnLoCgUjiS5wABQXc"]
[Tue Jul 21 08:51:28.191891 2026] [security2:error] [pid 514479:tid 514485] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/.env.development"] [unique_id "al9dQPzqsQqnLoCgUjiS7AABOAE"]
[Tue Jul 21 08:51:28.192124 2026] [security2:error] [pid 514479:tid 514660] [client 34.35.143.238:58352] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "api.gradiente.com"] [uri "/.env.development"] [unique_id "al9dQPzqsQqnLoCgUjiS7AABOAE"]
[Tue Jul 21 08:51:28.481519 2026] [security2:error] [pid 514479:tid 514671] [client 203.25.124.246:38215] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/fm.php/sts.php"] [unique_id "al9dQPzqsQqnLoCgUjiS8gAAAUM"]
[Tue Jul 21 08:51:28.511588 2026] [security2:error] [pid 514479:tid 514658] [client 65.21.113.253:59812] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dQPzqsQqnLoCgUjiS7wAAATY"]
[Tue Jul 21 08:51:28.522776 2026] [security2:error] [pid 514479:tid 514612] [remote 72.167.132.114:58776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "volyoaudiobooks.com"] [uri "/wp-login.php"] [unique_id "al9dQPzqsQqnLoCgUjiS-QABF38"]
[Tue Jul 21 08:51:28.553288 2026] [security2:error] [pid 514479:tid 514528] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/src/.env"] [unique_id "al9dQPzqsQqnLoCgUjiS_gABSyw"]
[Tue Jul 21 08:51:28.553439 2026] [security2:error] [pid 514479:tid 514679] [client 34.35.143.238:58352] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "api.gradiente.com"] [uri "/src/.env"] [unique_id "al9dQPzqsQqnLoCgUjiS_gABSyw"]
[Tue Jul 21 08:51:28.553792 2026] [security2:error] [pid 514479:tid 514494] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/app/.env"] [unique_id "al9dQPzqsQqnLoCgUjiS_QABSwo"]
[Tue Jul 21 08:51:28.597945 2026] [security2:error] [pid 514479:tid 514555] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/frontend/.env"] [unique_id "al9dQPzqsQqnLoCgUjiS_wABX0Y"]
[Tue Jul 21 08:51:28.817806 2026] [security2:error] [pid 514479:tid 514518] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dQPzqsQqnLoCgUjiTAwABGiI"]
[Tue Jul 21 08:51:28.817964 2026] [security2:error] [pid 514479:tid 514630] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dQPzqsQqnLoCgUjiTAwABGiI"]
[Tue Jul 21 08:51:28.869081 2026] [security2:error] [pid 511108:tid 511317] [client 20.104.96.117:61132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9dQITd5soprXwxAH0rjwAAAE8"]
[Tue Jul 21 08:51:28.878100 2026] [security2:error] [pid 514479:tid 514502] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/production/.env"] [unique_id "al9dQPzqsQqnLoCgUjiTBgABUxI"]
[Tue Jul 21 08:51:28.901958 2026] [security2:error] [pid 514479:tid 514556] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/server/.env"] [unique_id "al9dQPzqsQqnLoCgUjiTCgABY0c"]
[Tue Jul 21 08:51:28.902067 2026] [security2:error] [pid 514479:tid 514543] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/docker/.env"] [unique_id "al9dQPzqsQqnLoCgUjiTCQABYzs"]
[Tue Jul 21 08:51:28.902068 2026] [security2:error] [pid 514479:tid 514530] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/staging/.env"] [unique_id "al9dQPzqsQqnLoCgUjiTBwABYy4"]
[Tue Jul 21 08:51:28.902067 2026] [security2:error] [pid 514479:tid 514550] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/dev/.env"] [unique_id "al9dQPzqsQqnLoCgUjiTCAABY0E"]
[Tue Jul 21 08:51:28.931611 2026] [security2:error] [pid 514479:tid 514692] [client 91.148.244.131:43100] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/dump.sql"] [unique_id "al9dQPzqsQqnLoCgUjiTDAAAAVg"]
[Tue Jul 21 08:51:28.931612 2026] [security2:error] [pid 511108:tid 511262] [client 91.148.244.131:43082] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/database.sql"] [unique_id "al9dQITd5soprXwxAH0rkgAAABg"]
[Tue Jul 21 08:51:28.931611 2026] [security2:error] [pid 511108:tid 511298] [client 91.148.244.131:43084] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/actuator/heapdump"] [unique_id "al9dQITd5soprXwxAH0rkQAAADw"]
[Tue Jul 21 08:51:28.933908 2026] [security2:error] [pid 511108:tid 511269] [client 91.148.244.131:43092] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/config.xml"] [unique_id "al9dQITd5soprXwxAH0rkwAAAB8"]
[Tue Jul 21 08:51:28.935245 2026] [security2:error] [pid 514479:tid 514491] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/.env.production.bak"] [unique_id "al9dQPzqsQqnLoCgUjiTDgABfQc"]
[Tue Jul 21 08:51:28.935248 2026] [security2:error] [pid 514479:tid 514523] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/.env.prod.bak"] [unique_id "al9dQPzqsQqnLoCgUjiTDQABfSc"]
[Tue Jul 21 08:51:28.962392 2026] [security2:error] [pid 514479:tid 514693] [client 65.21.113.253:47482] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dQPzqsQqnLoCgUjiTDwAAAVk"]
[Tue Jul 21 08:51:29.085665 2026] [security2:error] [pid 514479:tid 514565] [remote 34.35.143.238:58352] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/@fs/.env"] [unique_id "al9dQfzqsQqnLoCgUjiTEgABClA"]
[Tue Jul 21 08:51:29.209204 2026] [security2:error] [pid 514479:tid 514708] [client 114.198.138.124:51347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dQfzqsQqnLoCgUjiTGQAAAWg"]
[Tue Jul 21 08:51:29.209304 2026] [security2:error] [pid 514479:tid 514708] [client 114.198.138.124:51347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dQfzqsQqnLoCgUjiTGQAAAWg"]
[Tue Jul 21 08:51:29.257919 2026] [security2:error] [pid 514479:tid 514513] [remote 34.35.143.238:58352] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "api.gradiente.com"] [uri "/@fs/proc/self/environ"] [unique_id "al9dQfzqsQqnLoCgUjiTGgABhh0"]
[Tue Jul 21 08:51:29.358050 2026] [security2:error] [pid 514479:tid 514664] [client 20.104.96.117:61733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/2000.php"] [unique_id "al9dQfzqsQqnLoCgUjiTHQAAATw"]
[Tue Jul 21 08:51:29.476546 2026] [security2:error] [pid 511108:tid 511297] [client 59.95.197.55:57348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dQYTd5soprXwxAH0rnwAAADs"]
[Tue Jul 21 08:51:29.476646 2026] [security2:error] [pid 511108:tid 511297] [client 59.95.197.55:57348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dQYTd5soprXwxAH0rnwAAADs"]
[Tue Jul 21 08:51:29.560020 2026] [security2:error] [pid 514479:tid 514709] [client 122.176.100.127:59095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dQfzqsQqnLoCgUjiTKgAAAWk"]
[Tue Jul 21 08:51:29.560161 2026] [security2:error] [pid 514479:tid 514709] [client 122.176.100.127:59095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dQfzqsQqnLoCgUjiTKgAAAWk"]
[Tue Jul 21 08:51:29.578277 2026] [security2:error] [pid 514479:tid 514631] [client 203.25.124.7:64711] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/upload/index.php"] [unique_id "al9dQfzqsQqnLoCgUjiTLgAAARs"]
[Tue Jul 21 08:51:29.782806 2026] [security2:error] [pid 514479:tid 514685] [client 173.252.95.10:55056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dQfzqsQqnLoCgUjiTQAAAAVE"]
[Tue Jul 21 08:51:29.907753 2026] [security2:error] [pid 511108:tid 511264] [client 91.148.244.131:43122] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/.svn/wc.db"] [unique_id "al9dQYTd5soprXwxAH0rpgAAABo"]
[Tue Jul 21 08:51:29.908641 2026] [security2:error] [pid 514479:tid 514615] [client 91.148.244.131:43104] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9dQfzqsQqnLoCgUjiTQQAAAQs"]
[Tue Jul 21 08:51:29.908642 2026] [security2:error] [pid 511108:tid 511302] [client 91.148.244.131:43120] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9dQYTd5soprXwxAH0rpwAAAEA"]
[Tue Jul 21 08:51:29.909440 2026] [security2:error] [pid 511108:tid 511285] [client 91.148.244.131:43124] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/backup.tar.gz"] [unique_id "al9dQYTd5soprXwxAH0rqAAAAC8"]
[Tue Jul 21 08:51:29.929493 2026] [security2:error] [pid 514479:tid 514704] [client 203.25.124.66:24039] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/system.php"] [unique_id "al9dQfzqsQqnLoCgUjiTQgAAAWQ"]
[Tue Jul 21 08:51:29.942343 2026] [security2:error] [pid 514479:tid 514686] [client 20.197.192.193:50590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/dragonshell.php"] [unique_id "al9dQfzqsQqnLoCgUjiTQwAAAVI"]
[Tue Jul 21 08:51:30.046617 2026] [security2:error] [pid 511108:tid 511280] [client 65.21.113.253:57096] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dQYTd5soprXwxAH0roQAAACo"]
[Tue Jul 21 08:51:30.074573 2026] [security2:error] [pid 514479:tid 514732] [client 173.252.95.30:33278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dQvzqsQqnLoCgUjiTRwAAAYA"]
[Tue Jul 21 08:51:30.109890 2026] [security2:error] [pid 514479:tid 514671] [client 91.148.244.131:43132] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9dQvzqsQqnLoCgUjiTSAAAAUM"]
[Tue Jul 21 08:51:30.327268 2026] [security2:error] [pid 511108:tid 511259] [client 20.197.192.193:56797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/wp-mt.php"] [unique_id "al9dQoTd5soprXwxAH0rrgAAABU"]
[Tue Jul 21 08:51:30.497777 2026] [security2:error] [pid 514479:tid 514520] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "api.gradiente.com"] [uri "/config.js"] [unique_id "al9dQvzqsQqnLoCgUjiTVgABPyQ"]
[Tue Jul 21 08:51:30.497854 2026] [security2:error] [pid 514479:tid 514571] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "api.gradiente.com"] [uri "/firebase-config.json"] [unique_id "al9dQvzqsQqnLoCgUjiTWQABP1Y"]
[Tue Jul 21 08:51:30.531853 2026] [security2:error] [pid 514479:tid 514684] [client 91.148.244.131:43178] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9dQvzqsQqnLoCgUjiTWgAAAVA"]
[Tue Jul 21 08:51:30.532114 2026] [security2:error] [pid 514479:tid 514689] [client 91.148.244.131:43158] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9dQvzqsQqnLoCgUjiTWwAAAVU"]
[Tue Jul 21 08:51:30.534354 2026] [security2:error] [pid 514479:tid 514675] [client 91.148.244.131:43176] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/.git/HEAD"] [unique_id "al9dQvzqsQqnLoCgUjiTXAAAAUc"]
[Tue Jul 21 08:51:30.534353 2026] [security2:error] [pid 511108:tid 511266] [client 91.148.244.131:43174] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9dQoTd5soprXwxAH0rsQAAABw"]
[Tue Jul 21 08:51:30.576372 2026] [security2:error] [pid 514479:tid 514681] [client 203.25.124.191:42505] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/images/index.php"] [unique_id "al9dQvzqsQqnLoCgUjiTXwAAAU0"]
[Tue Jul 21 08:51:30.613321 2026] [security2:error] [pid 514479:tid 514560] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "api.gradiente.com"] [uri "/api/v1/settings"] [unique_id "al9dQvzqsQqnLoCgUjiTYAABfks"]
[Tue Jul 21 08:51:30.613321 2026] [security2:error] [pid 514479:tid 514592] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/api/settings"] [unique_id "al9dQvzqsQqnLoCgUjiTYQABfms"]
[Tue Jul 21 08:51:30.613503 2026] [security2:error] [pid 514479:tid 514730] [client 34.35.143.238:57840] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "api.gradiente.com"] [uri "/api/settings"] [unique_id "al9dQvzqsQqnLoCgUjiTYQABfms"]
[Tue Jul 21 08:51:30.694919 2026] [security2:error] [pid 514479:tid 514707] [client 20.104.96.117:61087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9dQvzqsQqnLoCgUjiTYwAAAWc"]
[Tue Jul 21 08:51:30.757764 2026] [security2:error] [pid 514479:tid 514664] [client 20.220.225.223:19664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/kq1.php"] [unique_id "al9dQvzqsQqnLoCgUjiTZAAAATw"]
[Tue Jul 21 08:51:30.854223 2026] [security2:error] [pid 514479:tid 514573] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/api/v1/config"] [unique_id "al9dQvzqsQqnLoCgUjiTawABJVg"]
[Tue Jul 21 08:51:30.854371 2026] [security2:error] [pid 514479:tid 514641] [client 34.35.143.238:57840] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "api.gradiente.com"] [uri "/api/v1/config"] [unique_id "al9dQvzqsQqnLoCgUjiTawABJVg"]
[Tue Jul 21 08:51:30.881042 2026] [security2:error] [pid 514479:tid 514618] [client 20.197.192.193:50573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/ww.php"] [unique_id "al9dQvzqsQqnLoCgUjiTbgAAAQ4"]
[Tue Jul 21 08:51:31.244544 2026] [security2:error] [pid 514479:tid 514660] [client 212.32.76.10:35745] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/wp-links-opml.php"] [unique_id "al9dQ_zqsQqnLoCgUjiTewAAATg"]
[Tue Jul 21 08:51:31.513305 2026] [security2:error] [pid 511108:tid 511330] [client 91.148.244.131:43204] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/.env"] [unique_id "al9dQ4Td5soprXwxAH0rvAAAAFw"]
[Tue Jul 21 08:51:31.514864 2026] [security2:error] [pid 514479:tid 514720] [client 91.148.244.131:43228] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/api/.env"] [unique_id "al9dQ_zqsQqnLoCgUjiTiQAAAXQ"]
[Tue Jul 21 08:51:31.518626 2026] [security2:error] [pid 514479:tid 514658] [client 91.148.244.131:43220] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/phpinfo.php"] [unique_id "al9dQ_zqsQqnLoCgUjiTigAAATY"]
[Tue Jul 21 08:51:31.519185 2026] [security2:error] [pid 514479:tid 514648] [client 91.148.244.131:43244] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/docker-compose.yml"] [unique_id "al9dQ_zqsQqnLoCgUjiTiwAAASw"]
[Tue Jul 21 08:51:31.551912 2026] [security2:error] [pid 514479:tid 514540] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "api.gradiente.com"] [uri "/api/v1/env"] [unique_id "al9dQ_zqsQqnLoCgUjiTjQABNDg"]
[Tue Jul 21 08:51:31.601392 2026] [security2:error] [pid 511108:tid 511273] [client 47.128.41.216:43892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "agencianativa.com.br"] [uri "/robots.txt"] [unique_id "al9dQ4Td5soprXwxAH0rvQAAACM"]
[Tue Jul 21 08:51:31.669522 2026] [security2:error] [pid 514479:tid 514686] [client 198.44.157.34:44874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9dQ_zqsQqnLoCgUjiTlgAAAVI"]
[Tue Jul 21 08:51:31.669609 2026] [security2:error] [pid 514479:tid 514686] [client 198.44.157.34:44874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9dQ_zqsQqnLoCgUjiTlgAAAVI"]
[Tue Jul 21 08:51:31.674300 2026] [security2:error] [pid 514479:tid 514731] [client 203.25.124.191:24765] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/admin-header.php"] [unique_id "al9dQ_zqsQqnLoCgUjiTmAAAAX8"]
[Tue Jul 21 08:51:31.717599 2026] [security2:error] [pid 514479:tid 514679] [client 91.148.244.131:43214] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/user_secrets.yml"] [unique_id "al9dQ_zqsQqnLoCgUjiTmgAAAUs"]
[Tue Jul 21 08:51:31.719253 2026] [security2:error] [pid 514479:tid 514642] [client 91.148.244.131:43246] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/.env.production"] [unique_id "al9dQ_zqsQqnLoCgUjiTmwAAASY"]
[Tue Jul 21 08:51:31.722001 2026] [security2:error] [pid 514479:tid 514685] [client 91.148.244.131:43216] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9dQ_zqsQqnLoCgUjiTnAAAAVE"]
[Tue Jul 21 08:51:31.726596 2026] [security2:error] [pid 514479:tid 514539] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/graphql"] [unique_id "al9dQ_zqsQqnLoCgUjiTngABEDc"]
[Tue Jul 21 08:51:31.952789 2026] [security2:error] [pid 511108:tid 511168] [remote 103.28.36.200:60050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9dQ4Td5soprXwxAH0rxAAAFjs"]
[Tue Jul 21 08:51:32.009208 2026] [security2:error] [pid 514479:tid 514517] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.gradiente.com"] [uri "/phpinfo.php"] [unique_id "al9dRPzqsQqnLoCgUjiTpQABVSE"]
[Tue Jul 21 08:51:32.009542 2026] [security2:error] [pid 514479:tid 514504] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.gradiente.com"] [uri "/info.php"] [unique_id "al9dRPzqsQqnLoCgUjiTpgABVRQ"]
[Tue Jul 21 08:51:32.034567 2026] [security2:error] [pid 514479:tid 514557] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "api.gradiente.com"] [uri "/api/graphql"] [unique_id "al9dRPzqsQqnLoCgUjiTqQABR0g"]
[Tue Jul 21 08:51:32.042871 2026] [security2:error] [pid 514479:tid 514510] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.gradiente.com"] [uri "/test.php"] [unique_id "al9dRPzqsQqnLoCgUjiTrAABRxo"]
[Tue Jul 21 08:51:32.061875 2026] [security2:error] [pid 514479:tid 514608] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.gradiente.com"] [uri "/pi.php"] [unique_id "al9dRPzqsQqnLoCgUjiTrgABfns"]
[Tue Jul 21 08:51:32.082835 2026] [security2:error] [pid 514479:tid 514607] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.gradiente.com"] [uri "/i.php"] [unique_id "al9dRPzqsQqnLoCgUjiTsAABc3o"]
[Tue Jul 21 08:51:32.112530 2026] [security2:error] [pid 514479:tid 514734] [client 152.59.181.104:55296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dRPzqsQqnLoCgUjiTsQAAAYI"]
[Tue Jul 21 08:51:32.112626 2026] [security2:error] [pid 514479:tid 514734] [client 152.59.181.104:55296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dRPzqsQqnLoCgUjiTsQAAAYI"]
[Tue Jul 21 08:51:32.256876 2026] [security2:error] [pid 514479:tid 514695] [client 49.144.66.253:30814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dRPzqsQqnLoCgUjiTtQAAAVs"]
[Tue Jul 21 08:51:32.257012 2026] [security2:error] [pid 514479:tid 514695] [client 49.144.66.253:30814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dRPzqsQqnLoCgUjiTtQAAAVs"]
[Tue Jul 21 08:51:32.312352 2026] [security2:error] [pid 514479:tid 514707] [client 91.148.244.131:43252] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/server.key"] [unique_id "al9dRPzqsQqnLoCgUjiTtwAAAWc"]
[Tue Jul 21 08:51:32.368443 2026] [security2:error] [pid 514479:tid 514604] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/_profiler/open"] [unique_id "al9dRPzqsQqnLoCgUjiTuAABIHc"]
[Tue Jul 21 08:51:32.369061 2026] [security2:error] [pid 514479:tid 514484] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "api.gradiente.com"] [uri "/_profiler/latest"] [unique_id "al9dRPzqsQqnLoCgUjiTuQABIAA"]
[Tue Jul 21 08:51:32.395636 2026] [security2:error] [pid 514479:tid 514582] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.gradiente.com"] [uri "/app_dev.php"] [unique_id "al9dRPzqsQqnLoCgUjiTvgABLmE"]
[Tue Jul 21 08:51:32.406446 2026] [security2:error] [pid 514479:tid 514531] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.143.35.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "api.gradiente.com"] [uri "/app_dev.php/_profiler"] [unique_id "al9dRPzqsQqnLoCgUjiTwQABPS8"]
[Tue Jul 21 08:51:32.447684 2026] [security2:error] [pid 514479:tid 514566] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.gradiente.com"] [uri "/telescope/requests"] [unique_id "al9dRPzqsQqnLoCgUjiTwwABFlE"]
[Tue Jul 21 08:51:32.447810 2026] [security2:error] [pid 514479:tid 514626] [client 34.35.143.238:57840] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "api.gradiente.com"] [uri "/telescope/requests"] [unique_id "al9dRPzqsQqnLoCgUjiTwwABFlE"]
[Tue Jul 21 08:51:32.562053 2026] [security2:error] [pid 514479:tid 514617] [client 5.38.115.39:23665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dRPzqsQqnLoCgUjiTxwAAAQ0"]
[Tue Jul 21 08:51:32.562165 2026] [security2:error] [pid 514479:tid 514617] [client 5.38.115.39:23665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dRPzqsQqnLoCgUjiTxwAAAQ0"]
[Tue Jul 21 08:51:32.650547 2026] [security2:error] [pid 514479:tid 514726] [client 195.49.128.211:64813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dRPzqsQqnLoCgUjiTyQAAAXo"]
[Tue Jul 21 08:51:32.650724 2026] [security2:error] [pid 514479:tid 514726] [client 195.49.128.211:64813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dRPzqsQqnLoCgUjiTyQAAAXo"]
[Tue Jul 21 08:51:32.677905 2026] [security2:error] [pid 514479:tid 514655] [client 212.32.76.64:60779] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/autoload_classmap/function.php"] [unique_id "al9dRPzqsQqnLoCgUjiTygAAATM"]
[Tue Jul 21 08:51:32.697594 2026] [security2:error] [pid 514479:tid 514740] [client 91.148.244.131:43258] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/config/production.json"] [unique_id "al9dRPzqsQqnLoCgUjiTywAAAYg"]
[Tue Jul 21 08:51:32.699705 2026] [security2:error] [pid 514479:tid 514635] [client 91.148.244.131:43290] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/secrets.json"] [unique_id "al9dRPzqsQqnLoCgUjiTzAAAAR8"]
[Tue Jul 21 08:51:32.699706 2026] [security2:error] [pid 514479:tid 514663] [client 91.148.244.131:43274] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9dRPzqsQqnLoCgUjiTzgAAATs"]
[Tue Jul 21 08:51:32.699845 2026] [security2:error] [pid 514479:tid 514741] [client 91.148.244.131:43268] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/.npmrc"] [unique_id "al9dRPzqsQqnLoCgUjiTzQAAAYk"]
[Tue Jul 21 08:51:32.813371 2026] [security2:error] [pid 514479:tid 514528] [remote 34.35.143.238:57840] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "api.gradiente.com"] [uri "/server-info"] [unique_id "al9dRPzqsQqnLoCgUjiT0gABFSw"]
[Tue Jul 21 08:51:32.942314 2026] [security2:error] [pid 514479:tid 514679] [client 203.25.124.37:54675] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/ms-files.php"] [unique_id "al9dRPzqsQqnLoCgUjiT3gAAAUs"]
[Tue Jul 21 08:51:33.029728 2026] [access_compat:error] [pid 514479:tid 514550] [remote 34.35.143.238:57840] AH01797: client denied by server configuration: /var/www/html/server-status
[Tue Jul 21 08:51:33.068936 2026] [security2:error] [pid 511108:tid 511276] [client 20.104.96.117:46769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/122.php"] [unique_id "al9dRYTd5soprXwxAH0r1QAAACY"]
[Tue Jul 21 08:51:33.296778 2026] [security2:error] [pid 514479:tid 514691] [client 41.89.234.2:60278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dRfzqsQqnLoCgUjiT7AAAAVc"]
[Tue Jul 21 08:51:33.296959 2026] [security2:error] [pid 514479:tid 514691] [client 41.89.234.2:60278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dRfzqsQqnLoCgUjiT7AAAAVc"]
[Tue Jul 21 08:51:33.470329 2026] [security2:error] [pid 511108:tid 511295] [client 212.32.76.63:40829] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "al9dRYTd5soprXwxAH0r3wAAADk"]
[Tue Jul 21 08:51:33.499466 2026] [security2:error] [pid 514479:tid 514693] [client 91.148.244.131:35554] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/database_backup.sql"] [unique_id "al9dRfzqsQqnLoCgUjiT8QAAAVk"]
[Tue Jul 21 08:51:33.501721 2026] [security2:error] [pid 511108:tid 511284] [client 91.148.244.131:35536] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/backup.zip"] [unique_id "al9dRYTd5soprXwxAH0r4QAAAC4"]
[Tue Jul 21 08:51:33.502000 2026] [security2:error] [pid 511108:tid 511332] [client 91.148.244.131:35552] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/wp-config.php"] [unique_id "al9dRYTd5soprXwxAH0r4gAAAF4"]
[Tue Jul 21 08:51:33.502412 2026] [security2:error] [pid 511108:tid 511351] [client 91.148.244.131:35502] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/.bash_history"] [unique_id "al9dRYTd5soprXwxAH0r4wAAAHE"]
[Tue Jul 21 08:51:33.519305 2026] [security2:error] [pid 514479:tid 514616] [client 20.197.192.193:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/cron.php"] [unique_id "al9dRfzqsQqnLoCgUjiT8gAAAQw"]
[Tue Jul 21 08:51:33.602180 2026] [security2:error] [pid 511108:tid 511296] [client 20.104.96.117:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-link-zorm.php"] [unique_id "al9dRYTd5soprXwxAH0r5QAAADo"]
[Tue Jul 21 08:51:33.612014 2026] [security2:error] [pid 514479:tid 514683] [client 103.59.206.240:31092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dRfzqsQqnLoCgUjiT9wAAAU8"]
[Tue Jul 21 08:51:33.612128 2026] [security2:error] [pid 514479:tid 514683] [client 103.59.206.240:31092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dRfzqsQqnLoCgUjiT9wAAAU8"]
[Tue Jul 21 08:51:33.701719 2026] [security2:error] [pid 514479:tid 514711] [client 91.148.244.131:35540] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/backup.sql"] [unique_id "al9dRfzqsQqnLoCgUjiT-AAAAWs"]
[Tue Jul 21 08:51:33.703502 2026] [security2:error] [pid 511108:tid 511261] [client 91.148.244.131:35514] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "politicabrasil.com.br"] [uri "/config.php"] [unique_id "al9dRYTd5soprXwxAH0r5wAAABc"]
[Tue Jul 21 08:51:34.257161 2026] [security2:error] [pid 511108:tid 511225] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dRoTd5soprXwxAH0r7wAAHnQ"]
[Tue Jul 21 08:51:34.257338 2026] [security2:error] [pid 511108:tid 511268] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dRoTd5soprXwxAH0r7wAAHnQ"]
[Tue Jul 21 08:51:34.343235 2026] [security2:error] [pid 514479:tid 514666] [client 203.25.124.48:31079] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugin-install.php"] [unique_id "al9dRvzqsQqnLoCgUjiUAgAAAT4"]
[Tue Jul 21 08:51:34.446498 2026] [security2:error] [pid 514479:tid 514737] [client 20.220.225.223:19682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/zzz.php"] [unique_id "al9dRvzqsQqnLoCgUjiUBgAAAYU"]
[Tue Jul 21 08:51:34.482173 2026] [security2:error] [pid 514479:tid 514655] [client 203.25.124.185:37989] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "al9dRvzqsQqnLoCgUjiUBwAAATM"]
[Tue Jul 21 08:51:34.639411 2026] [security2:error] [pid 514479:tid 514492] [remote 45.90.123.233:51320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9dRvzqsQqnLoCgUjiUDwABOgg"]
[Tue Jul 21 08:51:34.678461 2026] [security2:error] [pid 514479:tid 514580] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dRvzqsQqnLoCgUjiUEAABbF8"]
[Tue Jul 21 08:51:34.678592 2026] [security2:error] [pid 514479:tid 514712] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dRvzqsQqnLoCgUjiUEAABbF8"]
[Tue Jul 21 08:51:34.905724 2026] [security2:error] [pid 514479:tid 514726] [client 198.44.157.34:33998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dRvzqsQqnLoCgUjiUFAAAAXo"]
[Tue Jul 21 08:51:34.905808 2026] [security2:error] [pid 514479:tid 514726] [client 198.44.157.34:33998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dRvzqsQqnLoCgUjiUFAAAAXo"]
[Tue Jul 21 08:51:34.966317 2026] [proxy:error] [pid 511108:tid 511137] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:51:34.966357 2026] [proxy_http:error] [pid 511108:tid 511137] [remote 74.7.228.46:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:51:34.966967 2026] [proxy:error] [pid 511108:tid 511137] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:51:34.966996 2026] [proxy_http:error] [pid 511108:tid 511137] [remote 74.7.228.46:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:51:35.030016 2026] [security2:error] [pid 511108:tid 511304] [client 20.104.96.117:61710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/mds.php"] [unique_id "al9dR4Td5soprXwxAH0r_gAAAEI"]
[Tue Jul 21 08:51:35.086194 2026] [security2:error] [pid 514479:tid 514687] [client 20.104.96.117:59652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-link-szoppm.php"] [unique_id "al9dR_zqsQqnLoCgUjiUHAAAAVM"]
[Tue Jul 21 08:51:35.431434 2026] [security2:error] [pid 514479:tid 514535] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "al9dR_zqsQqnLoCgUjiUJgABVTM"]
[Tue Jul 21 08:51:35.473639 2026] [security2:error] [pid 514479:tid 514651] [client 212.32.76.55:65227] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/languages/index.php"] [unique_id "al9dR_zqsQqnLoCgUjiUJwAAAS8"]
[Tue Jul 21 08:51:35.586673 2026] [security2:error] [pid 514479:tid 514699] [client 123.22.65.205:57275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.65.22.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kotovicz.com"] [uri "/xmlrpc.php"] [unique_id "al9dR_zqsQqnLoCgUjiUJAAAAV8"]
[Tue Jul 21 08:51:35.586900 2026] [security2:error] [pid 514479:tid 514699] [client 123.22.65.205:57275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kotovicz.com"] [uri "/xmlrpc.php"] [unique_id "al9dR_zqsQqnLoCgUjiUJAAAAV8"]
[Tue Jul 21 08:51:35.644997 2026] [security2:error] [pid 511108:tid 511336] [client 203.25.124.66:58331] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/includes/class-walker-nav-menu-edit-interpreter.php"] [unique_id "al9dR4Td5soprXwxAH0sBwAAAGI"]
[Tue Jul 21 08:51:35.727628 2026] [security2:error] [pid 514479:tid 514647] [client 20.197.192.193:56197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/xxx.php"] [unique_id "al9dR_zqsQqnLoCgUjiUKwAAASs"]
[Tue Jul 21 08:51:36.049433 2026] [security2:error] [pid 511108:tid 511365] [client 182.189.99.211:47725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dSITd5soprXwxAH0sDQAAAH8"]
[Tue Jul 21 08:51:36.049614 2026] [security2:error] [pid 511108:tid 511365] [client 182.189.99.211:47725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dSITd5soprXwxAH0sDQAAAH8"]
[Tue Jul 21 08:51:36.330434 2026] [security2:error] [pid 514479:tid 514728] [client 198.44.157.34:34008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9dSPzqsQqnLoCgUjiUYgAAAXw"]
[Tue Jul 21 08:51:36.330557 2026] [security2:error] [pid 514479:tid 514728] [client 198.44.157.34:34008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9dSPzqsQqnLoCgUjiUYgAAAXw"]
[Tue Jul 21 08:51:36.373927 2026] [security2:error] [pid 511108:tid 511258] [client 203.25.124.207:24837] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/media-new.php"] [unique_id "al9dSITd5soprXwxAH0sFQAAABQ"]
[Tue Jul 21 08:51:37.013053 2026] [security2:error] [pid 511108:tid 511325] [client 173.252.95.42:63064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dSYTd5soprXwxAH0sIgAAAFc"]
[Tue Jul 21 08:51:37.019499 2026] [security2:error] [pid 514479:tid 514504] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dSfzqsQqnLoCgUjiUcgABORQ"]
[Tue Jul 21 08:51:37.019638 2026] [security2:error] [pid 514479:tid 514661] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dSfzqsQqnLoCgUjiUcgABORQ"]
[Tue Jul 21 08:51:37.076600 2026] [security2:error] [pid 514479:tid 514724] [client 203.25.124.200:57409] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/tiny.php"] [unique_id "al9dSfzqsQqnLoCgUjiUcwAAAXg"]
[Tue Jul 21 08:51:37.246875 2026] [security2:error] [pid 514479:tid 514557] [remote 147.90.209.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "al9dSfzqsQqnLoCgUjiUeAABU0g"]
[Tue Jul 21 08:51:37.249921 2026] [security2:error] [pid 514479:tid 514659] [client 203.25.124.32:24501] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/customize/class-wp-widget-area-customize-control-interpreter.php"] [unique_id "al9dSfzqsQqnLoCgUjiUeQAAATc"]
[Tue Jul 21 08:51:37.505546 2026] [security2:error] [pid 514479:tid 514675] [client 20.104.96.117:59141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/albin.php"] [unique_id "al9dSfzqsQqnLoCgUjiUfwAAAUc"]
[Tue Jul 21 08:51:37.655094 2026] [security2:error] [pid 514479:tid 514620] [client 23.180.120.146:36492] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "quietumplus.shop-officialstore.com"] [uri "/"] [unique_id "al9dSfzqsQqnLoCgUjiUgAAAARA"]
[Tue Jul 21 08:51:37.861475 2026] [security2:error] [pid 511108:tid 511287] [client 65.21.113.253:39814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dSYTd5soprXwxAH0sMQAAADE"]
[Tue Jul 21 08:51:37.913285 2026] [security2:error] [pid 514479:tid 514649] [client 1.54.149.212:60280] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "br1102.hostgator.com.br"] [uri "/"] [unique_id "al9dSfzqsQqnLoCgUjiUgwAAAS0"]
[Tue Jul 21 08:51:37.936784 2026] [security2:error] [pid 514479:tid 514631] [client 203.25.124.51:21905] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/ai-client/adapters/admin.php"] [unique_id "al9dSfzqsQqnLoCgUjiUhQAAARs"]
[Tue Jul 21 08:51:37.939842 2026] [security2:error] [pid 514479:tid 514719] [client 128.140.106.114:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9dSfzqsQqnLoCgUjiUhAABcxo"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:51:37.964718 2026] [security2:error] [pid 514479:tid 514707] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dSfzqsQqnLoCgUjiUggABZz4"]
[Tue Jul 21 08:51:37.976332 2026] [security2:error] [pid 511108:tid 511278] [client 212.32.76.58:24063] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/license.php"] [unique_id "al9dSYTd5soprXwxAH0sMgAAACg"]
[Tue Jul 21 08:51:38.176004 2026] [security2:error] [pid 514479:tid 514568] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dSvzqsQqnLoCgUjiUiwABHlM"]
[Tue Jul 21 08:51:38.176166 2026] [security2:error] [pid 514479:tid 514634] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dSvzqsQqnLoCgUjiUiwABHlM"]
[Tue Jul 21 08:51:38.282969 2026] [security2:error] [pid 511108:tid 511200] [remote 173.252.95.62:51562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9dSoTd5soprXwxAH0sOwAAAFs"]
[Tue Jul 21 08:51:38.454953 2026] [security2:error] [pid 514479:tid 514652] [client 23.180.120.146:36504] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "quietumplus.shop-officialstore.com"] [uri "/wp-json/batch/v1"] [unique_id "al9dSvzqsQqnLoCgUjiUjQAAATA"]
[Tue Jul 21 08:51:38.490565 2026] [security2:error] [pid 514479:tid 514709] [client 128.140.106.114:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9dSvzqsQqnLoCgUjiUjgABaXs"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:51:38.653454 2026] [security2:error] [pid 514479:tid 514735] [client 168.167.81.163:60536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dSvzqsQqnLoCgUjiUkQAAAYM"]
[Tue Jul 21 08:51:38.653559 2026] [security2:error] [pid 514479:tid 514735] [client 168.167.81.163:60536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dSvzqsQqnLoCgUjiUkQAAAYM"]
[Tue Jul 21 08:51:38.931180 2026] [security2:error] [pid 514479:tid 514736] [client 65.21.113.253:57102] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dSvzqsQqnLoCgUjiUkAAAAYQ"]
[Tue Jul 21 08:51:39.124554 2026] [security2:error] [pid 514479:tid 514740] [client 20.104.96.117:61076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/cilus.php"] [unique_id "al9dS_zqsQqnLoCgUjiUlQAAAYg"]
[Tue Jul 21 08:51:39.174461 2026] [security2:error] [pid 514479:tid 514657] [client 203.25.124.252:40725] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/av.php"] [unique_id "al9dS_zqsQqnLoCgUjiUlwAAATU"]
[Tue Jul 21 08:51:39.241117 2026] [security2:error] [pid 511108:tid 511315] [client 203.25.124.37:40851] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/widget-group/index.php"] [unique_id "al9dS4Td5soprXwxAH0sSgAAAE0"]
[Tue Jul 21 08:51:39.375578 2026] [security2:error] [pid 514479:tid 514713] [client 185.213.175.37:29116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "booking.bavos.com.br"] [uri "/cgi-sys/images/logo-hostgator.svg"] [unique_id "al9dS_zqsQqnLoCgUjiUoQAAAW0"]
[Tue Jul 21 08:51:39.375650 2026] [security2:error] [pid 514479:tid 514713] [client 185.213.175.37:29116] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "booking.bavos.com.br"] [uri "/cgi-sys/images/logo-hostgator.svg"] [unique_id "al9dS_zqsQqnLoCgUjiUoQAAAW0"]
[Tue Jul 21 08:51:39.450494 2026] [security2:error] [pid 511108:tid 511319] [client 113.22.144.139:58483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dS4Td5soprXwxAH0sTgAAAFE"]
[Tue Jul 21 08:51:39.450604 2026] [security2:error] [pid 511108:tid 511319] [client 113.22.144.139:58483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dS4Td5soprXwxAH0sTgAAAFE"]
[Tue Jul 21 08:51:39.616908 2026] [security2:error] [pid 514479:tid 514604] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dS_zqsQqnLoCgUjiUrQABS3c"]
[Tue Jul 21 08:51:39.617051 2026] [security2:error] [pid 514479:tid 514679] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dS_zqsQqnLoCgUjiUrQABS3c"]
[Tue Jul 21 08:51:39.731988 2026] [security2:error] [pid 511108:tid 511247] [client 114.198.138.124:51937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dS4Td5soprXwxAH0sVAAAAAk"]
[Tue Jul 21 08:51:39.732096 2026] [security2:error] [pid 511108:tid 511247] [client 114.198.138.124:51937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dS4Td5soprXwxAH0sVAAAAAk"]
[Tue Jul 21 08:51:39.821157 2026] [security2:error] [pid 514479:tid 514686] [client 59.95.197.55:57811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dS_zqsQqnLoCgUjiUrgAAAVI"]
[Tue Jul 21 08:51:39.821269 2026] [security2:error] [pid 514479:tid 514686] [client 59.95.197.55:57811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dS_zqsQqnLoCgUjiUrgAAAVI"]
[Tue Jul 21 08:51:40.062547 2026] [security2:error] [pid 514479:tid 514630] [client 122.176.100.127:59576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dTPzqsQqnLoCgUjiUsQAAARo"]
[Tue Jul 21 08:51:40.062687 2026] [security2:error] [pid 514479:tid 514630] [client 122.176.100.127:59576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dTPzqsQqnLoCgUjiUsQAAARo"]
[Tue Jul 21 08:51:40.183333 2026] [security2:error] [pid 511108:tid 511314] [client 203.25.124.206:23521] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-login-css.php"] [unique_id "al9dTITd5soprXwxAH0sWwAAAEw"]
[Tue Jul 21 08:51:40.547432 2026] [security2:error] [pid 514479:tid 514725] [client 212.32.76.5:45837] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/preformatted/index.php"] [unique_id "al9dTPzqsQqnLoCgUjiUtAAAAXk"]
[Tue Jul 21 08:51:40.668637 2026] [security2:error] [pid 514479:tid 514696] [client 20.220.225.223:37589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/hp3.php"] [unique_id "al9dTPzqsQqnLoCgUjiUtwAAAVw"]
[Tue Jul 21 08:51:40.945564 2026] [security2:error] [pid 514479:tid 514645] [client 88.99.80.227:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9dTPzqsQqnLoCgUjiUvAABKQE"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:51:41.157666 2026] [security2:error] [pid 511108:tid 511330] [client 20.220.225.223:43162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/aa1.php"] [unique_id "al9dTYTd5soprXwxAH0saQAAAFw"]
[Tue Jul 21 08:51:41.306739 2026] [security2:error] [pid 511108:tid 511331] [client 173.252.95.23:65436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dTYTd5soprXwxAH0scQAAAF0"]
[Tue Jul 21 08:51:41.504713 2026] [security2:error] [pid 514479:tid 514736] [client 88.99.80.227:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9dTfzqsQqnLoCgUjiUxgABhGE"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:51:41.585051 2026] [security2:error] [pid 511108:tid 511300] [client 203.25.124.184:37041] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/classwithtostring.php"] [unique_id "al9dTYTd5soprXwxAH0sdAAAAD4"]
[Tue Jul 21 08:51:41.644297 2026] [security2:error] [pid 511108:tid 511318] [client 203.25.124.213:32065] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/list/list/wp-config.php"] [unique_id "al9dTYTd5soprXwxAH0sdQAAAFA"]
[Tue Jul 21 08:51:41.737362 2026] [security2:error] [pid 511108:tid 511138] [remote 68.178.160.25:42432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9dTYTd5soprXwxAH0seQAAah0"]
[Tue Jul 21 08:51:41.992680 2026] [security2:error] [pid 514479:tid 514705] [client 20.104.96.117:61702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-blink.php"] [unique_id "al9dTfzqsQqnLoCgUjiU0gAAAWU"]
[Tue Jul 21 08:51:42.114081 2026] [security2:error] [pid 514479:tid 514656] [client 20.220.225.223:48224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9dTvzqsQqnLoCgUjiU1AAAATQ"]
[Tue Jul 21 08:51:42.196151 2026] [security2:error] [pid 514479:tid 514690] [client 20.104.96.117:61166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/gptsh.php"] [unique_id "al9dTvzqsQqnLoCgUjiU1QAAAVY"]
[Tue Jul 21 08:51:42.477342 2026] [security2:error] [pid 511108:tid 511258] [client 65.21.113.253:39814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dToTd5soprXwxAH0shQAAABQ"]
[Tue Jul 21 08:51:42.858306 2026] [security2:error] [pid 514479:tid 514704] [client 152.59.181.104:1059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dTvzqsQqnLoCgUjiU5wAAAWQ"]
[Tue Jul 21 08:51:42.858405 2026] [security2:error] [pid 514479:tid 514704] [client 152.59.181.104:1059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dTvzqsQqnLoCgUjiU5wAAAWQ"]
[Tue Jul 21 08:51:43.150239 2026] [security2:error] [pid 514479:tid 514627] [client 203.25.124.58:33779] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/post-author-biography/post-author-biography/class-wp-http.php"] [unique_id "al9dT_zqsQqnLoCgUjiU7wAAARc"]
[Tue Jul 21 08:51:43.240280 2026] [security2:error] [pid 514479:tid 514667] [client 5.38.115.39:57669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dT_zqsQqnLoCgUjiU8QAAAT8"]
[Tue Jul 21 08:51:43.240416 2026] [security2:error] [pid 514479:tid 514667] [client 5.38.115.39:57669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dT_zqsQqnLoCgUjiU8QAAAT8"]
[Tue Jul 21 08:51:43.290212 2026] [security2:error] [pid 514479:tid 514662] [client 195.49.128.211:65425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dT_zqsQqnLoCgUjiU8wAAATo"]
[Tue Jul 21 08:51:43.290359 2026] [security2:error] [pid 514479:tid 514662] [client 195.49.128.211:65425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dT_zqsQqnLoCgUjiU8wAAATo"]
[Tue Jul 21 08:51:43.302106 2026] [security2:error] [pid 511108:tid 511360] [client 49.144.66.253:31242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dT4Td5soprXwxAH0sjwAAAHo"]
[Tue Jul 21 08:51:43.302240 2026] [security2:error] [pid 511108:tid 511360] [client 49.144.66.253:31242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dT4Td5soprXwxAH0sjwAAAHo"]
[Tue Jul 21 08:51:43.584454 2026] [security2:error] [pid 514479:tid 514689] [client 65.21.113.253:46452] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dT_zqsQqnLoCgUjiU8AAAAVU"]
[Tue Jul 21 08:51:43.665928 2026] [rewrite:warn] [pid 511108:tid 511120] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:43.735685 2026] [autoindex:error] [pid 514479:tid 514682] [client 192.175.111.246:41945] AH01276: Cannot serve directory /home4/dralul00/idufinance.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:51:44.076858 2026] [security2:error] [pid 514479:tid 514619] [client 203.25.124.251:37113] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Text/Diff/Engine/template-singl-portfolio.php"] [unique_id "al9dUPzqsQqnLoCgUjiU_AAAAQ8"]
[Tue Jul 21 08:51:44.108745 2026] [security2:error] [pid 514479:tid 514724] [client 20.220.225.223:48215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9dUPzqsQqnLoCgUjiU_QAAAXg"]
[Tue Jul 21 08:51:44.110251 2026] [security2:error] [pid 514479:tid 514661] [client 20.220.225.223:19293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wicked.php"] [unique_id "al9dUPzqsQqnLoCgUjiU_gAAATk"]
[Tue Jul 21 08:51:44.126665 2026] [security2:error] [pid 511108:tid 511333] [client 41.89.234.2:2496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dUITd5soprXwxAH0smAAAAF8"]
[Tue Jul 21 08:51:44.126755 2026] [security2:error] [pid 511108:tid 511333] [client 41.89.234.2:2496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dUITd5soprXwxAH0smAAAAF8"]
[Tue Jul 21 08:51:44.242433 2026] [security2:error] [pid 511108:tid 511261] [client 103.59.206.240:31140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dUITd5soprXwxAH0smQAAABc"]
[Tue Jul 21 08:51:44.243116 2026] [security2:error] [pid 511108:tid 511261] [client 103.59.206.240:31140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dUITd5soprXwxAH0smQAAABc"]
[Tue Jul 21 08:51:44.344192 2026] [security2:error] [pid 514479:tid 514651] [client 203.25.124.71:44145] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/post-time-to-read/post-time-to-read/post-template.php"] [unique_id "al9dUPzqsQqnLoCgUjiVCQAAAS8"]
[Tue Jul 21 08:51:44.673513 2026] [security2:error] [pid 514479:tid 514698] [client 20.220.225.223:48249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/dp.php"] [unique_id "al9dUPzqsQqnLoCgUjiVFQAAAV4"]
[Tue Jul 21 08:51:44.897251 2026] [security2:error] [pid 514479:tid 514542] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dUPzqsQqnLoCgUjiVGAABKzo"]
[Tue Jul 21 08:51:44.897377 2026] [security2:error] [pid 514479:tid 514647] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dUPzqsQqnLoCgUjiVGAABKzo"]
[Tue Jul 21 08:51:45.072787 2026] [security2:error] [pid 514479:tid 514712] [client 203.25.124.210:37975] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "al9dUfzqsQqnLoCgUjiVIAAAAWw"]
[Tue Jul 21 08:51:45.197255 2026] [security2:error] [pid 514479:tid 514599] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dUfzqsQqnLoCgUjiVIgABI3I"]
[Tue Jul 21 08:51:45.197385 2026] [security2:error] [pid 514479:tid 514639] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dUfzqsQqnLoCgUjiVIgABI3I"]
[Tue Jul 21 08:51:45.230203 2026] [security2:error] [pid 514479:tid 514705] [client 20.220.225.223:38724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/old.php"] [unique_id "al9dUfzqsQqnLoCgUjiVIwAAAWU"]
[Tue Jul 21 08:51:45.269689 2026] [security2:error] [pid 514479:tid 514656] [client 20.220.225.223:34875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/acew67.php"] [unique_id "al9dUfzqsQqnLoCgUjiVJAAAATQ"]
[Tue Jul 21 08:51:45.342612 2026] [security2:error] [pid 514479:tid 514657] [client 114.119.140.179:42295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "foreverconfidence.com"] [uri "/wp-content/uploads/elementor/thumbs/cavitation2-1920w-1-qnch5c698kv1eqtxjv5aoophe466f2y4mkq1zo66wg.webp"] [unique_id "al9dUfzqsQqnLoCgUjiVJgAAATU"], referer: https://foreverconfidence.com/gallery/
[Tue Jul 21 08:51:45.546326 2026] [security2:error] [pid 514479:tid 514624] [client 203.25.124.70:28725] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/post-template/post-template/api-gateway.php"] [unique_id "al9dUfzqsQqnLoCgUjiVLgAAARQ"]
[Tue Jul 21 08:51:46.132779 2026] [security2:error] [pid 514479:tid 514700] [client 20.197.192.193:56784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/hunter.php"] [unique_id "al9dUvzqsQqnLoCgUjiVPAAAAWA"]
[Tue Jul 21 08:51:46.171516 2026] [security2:error] [pid 514479:tid 514691] [client 203.25.124.5:55559] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/lock360.php"] [unique_id "al9dUvzqsQqnLoCgUjiVPQAAAVc"]
[Tue Jul 21 08:51:46.245222 2026] [security2:error] [pid 514479:tid 514674] [client 20.104.96.117:61712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/zc-208.php"] [unique_id "al9dUvzqsQqnLoCgUjiVQwAAAUY"]
[Tue Jul 21 08:51:46.483486 2026] [security2:error] [pid 514479:tid 514728] [client 182.189.99.211:47706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dUvzqsQqnLoCgUjiVTgAAAXw"]
[Tue Jul 21 08:51:46.483681 2026] [security2:error] [pid 514479:tid 514728] [client 182.189.99.211:47706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dUvzqsQqnLoCgUjiVTgAAAXw"]
[Tue Jul 21 08:51:46.831436 2026] [security2:error] [pid 514479:tid 514656] [client 212.32.76.9:57443] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/customize/network/index.php"] [unique_id "al9dUvzqsQqnLoCgUjiVWAAAATQ"]
[Tue Jul 21 08:51:46.977807 2026] [security2:error] [pid 514479:tid 514673] [client 203.25.124.192:35955] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/alfa.php"] [unique_id "al9dUvzqsQqnLoCgUjiVWQAAAUU"]
[Tue Jul 21 08:51:47.156847 2026] [rewrite:warn] [pid 514479:tid 514560] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.554223 2026] [security2:error] [pid 514479:tid 514509] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dU_zqsQqnLoCgUjiVcAABiBk"]
[Tue Jul 21 08:51:47.554354 2026] [security2:error] [pid 514479:tid 514740] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dU_zqsQqnLoCgUjiVcAABiBk"]
[Tue Jul 21 08:51:47.569564 2026] [rewrite:warn] [pid 514479:tid 514506] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.569887 2026] [rewrite:warn] [pid 514479:tid 514573] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.586704 2026] [rewrite:warn] [pid 514479:tid 514552] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.621801 2026] [rewrite:warn] [pid 514479:tid 514584] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.647076 2026] [security2:error] [pid 514479:tid 514578] [remote 162.243.80.244:7572] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.loja.tropicaliaeyewear.com.br"] [uri "/.env"] [unique_id "al9dU_zqsQqnLoCgUjiVfAABG10"]
[Tue Jul 21 08:51:47.649842 2026] [rewrite:warn] [pid 514479:tid 514595] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.654246 2026] [security2:error] [pid 514479:tid 514641] [client 65.21.113.253:44762] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dU_zqsQqnLoCgUjiVgAAAASU"]
[Tue Jul 21 08:51:47.665948 2026] [rewrite:warn] [pid 514479:tid 514551] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.704516 2026] [rewrite:warn] [pid 514479:tid 514533] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.720154 2026] [rewrite:warn] [pid 514479:tid 514499] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.724983 2026] [rewrite:warn] [pid 514479:tid 514554] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.724984 2026] [rewrite:warn] [pid 514479:tid 514500] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.725177 2026] [rewrite:warn] [pid 514479:tid 514489] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.725229 2026] [rewrite:warn] [pid 514479:tid 514609] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.725485 2026] [rewrite:warn] [pid 514479:tid 514603] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.725968 2026] [rewrite:warn] [pid 514479:tid 514532] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:47.931008 2026] [security2:error] [pid 514479:tid 514679] [client 168.167.81.163:60321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dU_zqsQqnLoCgUjiVjAAAAUs"]
[Tue Jul 21 08:51:47.931166 2026] [security2:error] [pid 514479:tid 514679] [client 168.167.81.163:60321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dU_zqsQqnLoCgUjiVjAAAAUs"]
[Tue Jul 21 08:51:48.036906 2026] [security2:error] [pid 514479:tid 514614] [client 212.32.76.12:49487] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/widgets/theme-compat/index.php"] [unique_id "al9dVPzqsQqnLoCgUjiVlQAAAQo"]
[Tue Jul 21 08:51:48.078396 2026] [security2:error] [pid 514479:tid 514637] [client 203.25.124.183:30531] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/maint/index.php"] [unique_id "al9dVPzqsQqnLoCgUjiVlgAAASE"]
[Tue Jul 21 08:51:48.363150 2026] [security2:error] [pid 514479:tid 514568] [remote 72.167.132.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "annaguimaraes.com.br"] [uri "/wp-login.php"] [unique_id "al9dVPzqsQqnLoCgUjiVoAABh1M"]
[Tue Jul 21 08:51:48.537146 2026] [security2:error] [pid 514479:tid 514653] [client 5.31.193.106:1820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dVPzqsQqnLoCgUjiVpQAAATE"]
[Tue Jul 21 08:51:48.537247 2026] [security2:error] [pid 514479:tid 514653] [client 5.31.193.106:1820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dVPzqsQqnLoCgUjiVpQAAATE"]
[Tue Jul 21 08:51:48.610166 2026] [security2:error] [pid 514479:tid 514683] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dVPzqsQqnLoCgUjiVpAABT30"]
[Tue Jul 21 08:51:48.720713 2026] [security2:error] [pid 514479:tid 514659] [client 65.21.113.253:46456] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dVPzqsQqnLoCgUjiVngAAATc"]
[Tue Jul 21 08:51:48.965586 2026] [security2:error] [pid 514479:tid 514634] [client 212.32.76.55:42223] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/templates/atomic/templates.php"] [unique_id "al9dVPzqsQqnLoCgUjiVtwAAAR4"]
[Tue Jul 21 08:51:49.037094 2026] [security2:error] [pid 514479:tid 514699] [client 212.32.76.12:31207] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/upgrade/patterns/index.php"] [unique_id "al9dVfzqsQqnLoCgUjiVvAAAAV8"]
[Tue Jul 21 08:51:49.041334 2026] [security2:error] [pid 514479:tid 514582] [remote 68.178.160.25:52622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9dVfzqsQqnLoCgUjiVvQABD2E"]
[Tue Jul 21 08:51:49.088168 2026] [security2:error] [pid 514479:tid 514536] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dVfzqsQqnLoCgUjiVvwABbDQ"]
[Tue Jul 21 08:51:49.088351 2026] [security2:error] [pid 514479:tid 514712] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dVfzqsQqnLoCgUjiVvwABbDQ"]
[Tue Jul 21 08:51:49.098941 2026] [security2:error] [pid 514479:tid 514518] [remote 68.178.160.25:45864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medoraldracena.com.br"] [uri "/wp-login.php"] [unique_id "al9dVfzqsQqnLoCgUjiVwAABVyI"]
[Tue Jul 21 08:51:49.164094 2026] [security2:error] [pid 514479:tid 514701] [client 113.22.144.139:59007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dVfzqsQqnLoCgUjiVwQAAAWE"]
[Tue Jul 21 08:51:49.164745 2026] [security2:error] [pid 514479:tid 514701] [client 113.22.144.139:59007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dVfzqsQqnLoCgUjiVwQAAAWE"]
[Tue Jul 21 08:51:49.338269 2026] [security2:error] [pid 514479:tid 514668] [client 20.220.225.223:19657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/edit.php"] [unique_id "al9dVfzqsQqnLoCgUjiVyQAAAUA"]
[Tue Jul 21 08:51:49.588297 2026] [security2:error] [pid 514479:tid 514726] [client 20.220.225.223:37602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/bscclapb.php"] [unique_id "al9dVfzqsQqnLoCgUjiV1AAAAXo"]
[Tue Jul 21 08:51:50.075158 2026] [security2:error] [pid 514479:tid 514678] [client 203.25.124.199:39267] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-links.php"] [unique_id "al9dVvzqsQqnLoCgUjiV4gAAAUo"]
[Tue Jul 21 08:51:50.146466 2026] [security2:error] [pid 514479:tid 514728] [client 203.25.124.212:60837] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/images/widgets/index.php"] [unique_id "al9dVvzqsQqnLoCgUjiV5QAAAXw"]
[Tue Jul 21 08:51:50.298635 2026] [security2:error] [pid 514479:tid 514697] [client 59.95.197.55:58287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dVvzqsQqnLoCgUjiV7wAAAV0"]
[Tue Jul 21 08:51:50.298758 2026] [security2:error] [pid 514479:tid 514697] [client 59.95.197.55:58287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dVvzqsQqnLoCgUjiV7wAAAV0"]
[Tue Jul 21 08:51:50.301253 2026] [security2:error] [pid 514479:tid 514655] [client 114.198.138.124:52524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dVvzqsQqnLoCgUjiV8AAAATM"]
[Tue Jul 21 08:51:50.301346 2026] [security2:error] [pid 514479:tid 514655] [client 114.198.138.124:52524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dVvzqsQqnLoCgUjiV8AAAATM"]
[Tue Jul 21 08:51:50.449857 2026] [security2:error] [pid 514479:tid 514615] [client 20.220.225.223:60265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/ms-new.php"] [unique_id "al9dVvzqsQqnLoCgUjiV8QAAAQs"]
[Tue Jul 21 08:51:50.519519 2026] [security2:error] [pid 514479:tid 514669] [client 122.176.100.127:60052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dVvzqsQqnLoCgUjiV8wAAAUE"]
[Tue Jul 21 08:51:50.520187 2026] [security2:error] [pid 514479:tid 514669] [client 122.176.100.127:60052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dVvzqsQqnLoCgUjiV8wAAAUE"]
[Tue Jul 21 08:51:50.634279 2026] [security2:error] [pid 514479:tid 514558] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dVvzqsQqnLoCgUjiV-QABQEk"]
[Tue Jul 21 08:51:50.634460 2026] [security2:error] [pid 514479:tid 514668] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dVvzqsQqnLoCgUjiV-QABQEk"]
[Tue Jul 21 08:51:51.076253 2026] [security2:error] [pid 514479:tid 514704] [client 212.32.76.60:36371] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al9dV_zqsQqnLoCgUjiWDAAAAWQ"]
[Tue Jul 21 08:51:51.173298 2026] [security2:error] [pid 514479:tid 514636] [client 20.197.192.193:50587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/we.php"] [unique_id "al9dV_zqsQqnLoCgUjiWEgAAASA"]
[Tue Jul 21 08:51:51.434005 2026] [security2:error] [pid 514479:tid 514698] [client 212.32.76.9:44497] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/customize/includes/index.php"] [unique_id "al9dV_zqsQqnLoCgUjiWJAAAAV4"]
[Tue Jul 21 08:51:52.018142 2026] [security2:error] [pid 514479:tid 514695] [client 20.220.225.223:46340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/else1.php"] [unique_id "al9dWPzqsQqnLoCgUjiWQgAAAVs"]
[Tue Jul 21 08:51:52.036225 2026] [security2:error] [pid 514479:tid 514645] [client 20.220.225.223:19658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/kua.php"] [unique_id "al9dWPzqsQqnLoCgUjiWQwAAASk"]
[Tue Jul 21 08:51:52.068500 2026] [security2:error] [pid 514479:tid 514625] [client 203.25.124.198:62943] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/about.php"] [unique_id "al9dWPzqsQqnLoCgUjiWRgAAARU"]
[Tue Jul 21 08:51:52.253563 2026] [security2:error] [pid 514479:tid 514688] [client 65.21.113.253:44762] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dWPzqsQqnLoCgUjiWTQAAAVQ"]
[Tue Jul 21 08:51:52.256069 2026] [rewrite:warn] [pid 514479:tid 514516] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:52.282664 2026] [security2:error] [pid 514479:tid 514584] [remote 119.195.102.159:43496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "umapsicologiaqueprovoca.com"] [uri "/wp-login.php"] [unique_id "al9dWPzqsQqnLoCgUjiWTwABJWM"]
[Tue Jul 21 08:51:52.578706 2026] [security2:error] [pid 514479:tid 514735] [client 102.129.223.92:10417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.223.129.102.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "localizavistorias.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9dWPzqsQqnLoCgUjiWWQAAAYM"], referer: https://localizavistorias.com/contato/
[Tue Jul 21 08:51:52.615419 2026] [security2:error] [pid 514479:tid 514722] [client 20.197.192.193:56807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "g7laboratoriooptico.com.br"] [uri "/phpinfo.php1"] [unique_id "al9dWPzqsQqnLoCgUjiWWgAAAXY"]
[Tue Jul 21 08:51:52.651002 2026] [security2:error] [pid 514479:tid 514687] [client 212.32.76.2:41131] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/colors/upgrade/index.php"] [unique_id "al9dWPzqsQqnLoCgUjiWWwAAAVM"]
[Tue Jul 21 08:51:53.185824 2026] [security2:error] [pid 514479:tid 514704] [client 203.25.124.206:49201] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/new.php"] [unique_id "al9dWfzqsQqnLoCgUjiWeAAAAWQ"]
[Tue Jul 21 08:51:53.205673 2026] [security2:error] [pid 514479:tid 514690] [client 34.23.49.104:55062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.49.23.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hctreinamentos.net"] [uri "/xmlrpc.php"] [unique_id "al9dWfzqsQqnLoCgUjiWeQAAAVY"]
[Tue Jul 21 08:51:53.375519 2026] [security2:error] [pid 514479:tid 514698] [client 65.21.113.253:33408] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dWPzqsQqnLoCgUjiWagAAAV4"]
[Tue Jul 21 08:51:53.546594 2026] [security2:error] [pid 514479:tid 514626] [client 152.59.181.104:56237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dWfzqsQqnLoCgUjiWiAAAARY"]
[Tue Jul 21 08:51:53.546724 2026] [security2:error] [pid 514479:tid 514626] [client 152.59.181.104:56237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dWfzqsQqnLoCgUjiWiAAAARY"]
[Tue Jul 21 08:51:53.762375 2026] [security2:error] [pid 514479:tid 514696] [client 34.23.49.104:59151] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hctreinamentos.net"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9dWfzqsQqnLoCgUjiWkQAAAVw"]
[Tue Jul 21 08:51:53.892310 2026] [security2:error] [pid 514479:tid 514628] [client 195.49.128.211:49646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dWfzqsQqnLoCgUjiWlgAAARg"]
[Tue Jul 21 08:51:53.892455 2026] [security2:error] [pid 514479:tid 514628] [client 195.49.128.211:49646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dWfzqsQqnLoCgUjiWlgAAARg"]
[Tue Jul 21 08:51:53.953114 2026] [security2:error] [pid 514479:tid 514673] [client 5.38.115.39:19127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dWfzqsQqnLoCgUjiWmgAAAUU"]
[Tue Jul 21 08:51:53.953227 2026] [security2:error] [pid 514479:tid 514673] [client 5.38.115.39:19127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dWfzqsQqnLoCgUjiWmgAAAUU"]
[Tue Jul 21 08:51:54.040404 2026] [security2:error] [pid 514479:tid 514664] [client 203.25.124.43:49473] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/news-portal/user-install.php"] [unique_id "al9dWvzqsQqnLoCgUjiWnQAAATw"]
[Tue Jul 21 08:51:54.165377 2026] [security2:error] [pid 514479:tid 514725] [client 45.8.19.163:45901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "madeireirapiske.com.br"] [uri "/wp-login.php"] [unique_id "al9dWfzqsQqnLoCgUjiWnAAAAXk"]
[Tue Jul 21 08:51:54.179432 2026] [security2:error] [pid 514479:tid 514679] [client 49.144.66.253:31655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dWvzqsQqnLoCgUjiWnwAAAUs"]
[Tue Jul 21 08:51:54.179551 2026] [security2:error] [pid 514479:tid 514679] [client 49.144.66.253:31655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dWvzqsQqnLoCgUjiWnwAAAUs"]
[Tue Jul 21 08:51:54.348983 2026] [security2:error] [pid 514479:tid 514669] [client 34.23.49.104:63483] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hctreinamentos.net"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9dWvzqsQqnLoCgUjiWowAAAUE"]
[Tue Jul 21 08:51:54.375740 2026] [security2:error] [pid 514479:tid 514633] [client 212.32.76.62:50907] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "al9dWvzqsQqnLoCgUjiWpAAAAR0"]
[Tue Jul 21 08:51:54.583736 2026] [security2:error] [pid 514479:tid 514735] [client 20.104.96.117:46773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/sid4.php"] [unique_id "al9dWvzqsQqnLoCgUjiWqgAAAYM"]
[Tue Jul 21 08:51:54.873603 2026] [security2:error] [pid 514479:tid 514680] [client 41.89.234.2:61222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dWvzqsQqnLoCgUjiWsAAAAUw"]
[Tue Jul 21 08:51:54.873711 2026] [security2:error] [pid 514479:tid 514680] [client 41.89.234.2:61222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dWvzqsQqnLoCgUjiWsAAAAUw"]
[Tue Jul 21 08:51:54.878105 2026] [security2:error] [pid 514479:tid 514616] [client 34.23.49.104:58735] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hctreinamentos.net"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9dWvzqsQqnLoCgUjiWsQAAAQw"]
[Tue Jul 21 08:51:55.031088 2026] [security2:error] [pid 514479:tid 514635] [client 103.59.206.240:31475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dW_zqsQqnLoCgUjiWtgAAAR8"]
[Tue Jul 21 08:51:55.031212 2026] [security2:error] [pid 514479:tid 514635] [client 103.59.206.240:31475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dW_zqsQqnLoCgUjiWtgAAAR8"]
[Tue Jul 21 08:51:55.083810 2026] [security2:error] [pid 514479:tid 514682] [client 203.25.124.180:61935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-links-opml.php"] [unique_id "al9dW_zqsQqnLoCgUjiWtwAAAU4"]
[Tue Jul 21 08:51:55.145498 2026] [security2:error] [pid 514479:tid 514710] [client 203.25.124.74:22305] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/missing/missing/theme-single.php"] [unique_id "al9dW_zqsQqnLoCgUjiWuQAAAWo"]
[Tue Jul 21 08:51:55.397686 2026] [security2:error] [pid 514479:tid 514640] [client 34.23.49.104:63039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hctreinamentos.net"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9dW_zqsQqnLoCgUjiWxAAAASQ"]
[Tue Jul 21 08:51:55.405666 2026] [security2:error] [pid 514479:tid 514630] [client 198.44.157.34:57146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9dW_zqsQqnLoCgUjiWxgAAARo"]
[Tue Jul 21 08:51:55.405772 2026] [security2:error] [pid 514479:tid 514630] [client 198.44.157.34:57146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9dW_zqsQqnLoCgUjiWxgAAARo"]
[Tue Jul 21 08:51:55.432313 2026] [security2:error] [pid 514479:tid 514524] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dW_zqsQqnLoCgUjiWxwABDig"]
[Tue Jul 21 08:51:55.432501 2026] [security2:error] [pid 514479:tid 514618] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dW_zqsQqnLoCgUjiWxwABDig"]
[Tue Jul 21 08:51:55.637643 2026] [security2:error] [pid 514479:tid 514583] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dW_zqsQqnLoCgUjiWzQABEmI"]
[Tue Jul 21 08:51:55.637764 2026] [security2:error] [pid 514479:tid 514622] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dW_zqsQqnLoCgUjiWzQABEmI"]
[Tue Jul 21 08:51:55.729959 2026] [security2:error] [pid 514479:tid 514679] [client 20.220.225.223:19294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/ez.php"] [unique_id "al9dW_zqsQqnLoCgUjiWzgAAAUs"]
[Tue Jul 21 08:51:55.909147 2026] [security2:error] [pid 514479:tid 514625] [client 34.23.49.104:56363] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hctreinamentos.net"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9dW_zqsQqnLoCgUjiW1AAAARU"]
[Tue Jul 21 08:51:56.212810 2026] [http2:info] [pid 533360:tid 533360] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 08:51:56.233019 2026] [security2:error] [pid 533360:tid 533496] [client 212.32.76.64:29509] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/revslider/includes/external/page/index.php"] [unique_id "al9dXHUPuLYrePtEkUcD9AAAAIg"]
[Tue Jul 21 08:51:56.233081 2026] [security2:error] [pid 533360:tid 533493] [client 203.25.124.35:37957] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/admin-header-string.php"] [unique_id "al9dXHUPuLYrePtEkUcD8wAAAIU"]
[Tue Jul 21 08:51:56.363146 2026] [security2:error] [pid 514479:tid 514586] [remote 154.61.75.100:44044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9dXPzqsQqnLoCgUjiW2gABiWU"]
[Tue Jul 21 08:51:56.472849 2026] [security2:error] [pid 533360:tid 533494] [client 34.23.49.104:52477] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hctreinamentos.net"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9dXHUPuLYrePtEkUcD-QAAAIY"]
[Tue Jul 21 08:51:56.738276 2026] [security2:error] [pid 533360:tid 533520] [client 20.220.225.223:38744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/track.php"] [unique_id "al9dXHUPuLYrePtEkUcEAwAAAKA"]
[Tue Jul 21 08:51:56.970214 2026] [security2:error] [pid 533360:tid 533500] [client 182.189.99.211:48121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dXHUPuLYrePtEkUcEDgAAAIw"]
[Tue Jul 21 08:51:56.970341 2026] [security2:error] [pid 533360:tid 533500] [client 182.189.99.211:48121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dXHUPuLYrePtEkUcEDgAAAIw"]
[Tue Jul 21 08:51:56.995587 2026] [security2:error] [pid 533360:tid 533521] [client 34.23.49.104:51850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hctreinamentos.net"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9dXHUPuLYrePtEkUcEDwAAAKE"]
[Tue Jul 21 08:51:57.079583 2026] [security2:error] [pid 533360:tid 533545] [client 203.25.124.5:60195] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/222.php"] [unique_id "al9dXXUPuLYrePtEkUcEEQAAALk"]
[Tue Jul 21 08:51:57.098108 2026] [security2:error] [pid 533360:tid 533546] [client 65.21.113.253:38478] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dXXUPuLYrePtEkUcEEgAAALo"]
[Tue Jul 21 08:51:57.228485 2026] [security2:error] [pid 533360:tid 533559] [client 20.104.96.117:46755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wmore1.php"] [unique_id "al9dXXUPuLYrePtEkUcEGAAAAMc"]
[Tue Jul 21 08:51:57.620164 2026] [security2:error] [pid 533360:tid 533564] [client 34.23.49.104:53000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hctreinamentos.net"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9dXXUPuLYrePtEkUcEHgAAAMw"]
[Tue Jul 21 08:51:57.789043 2026] [security2:error] [pid 533360:tid 533598] [client 20.104.96.117:59184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/rithin.php"] [unique_id "al9dXXUPuLYrePtEkUcEKQAAAO4"]
[Tue Jul 21 08:51:57.851804 2026] [security2:error] [pid 533360:tid 533562] [client 114.119.129.107:24469] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.elitegeo.com.br"] [uri "/amp/imagem/clientes/imagem13.png"] [unique_id "al9dXXUPuLYrePtEkUcELgAAAMo"], referer: https://www.elitegeo.com.br/amp/
[Tue Jul 21 08:51:57.853544 2026] [rewrite:warn] [pid 533360:tid 533383] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:51:57.894521 2026] [security2:error] [pid 533360:tid 533553] [client 35.204.70.15:56046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "reabfit.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9dXXUPuLYrePtEkUcENQAAAME"]
[Tue Jul 21 08:51:58.030962 2026] [security2:error] [pid 533360:tid 533387] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dXnUPuLYrePtEkUcEOwAAiBc"]
[Tue Jul 21 08:51:58.031223 2026] [security2:error] [pid 533360:tid 533496] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dXnUPuLYrePtEkUcEOwAAiBc"]
[Tue Jul 21 08:51:58.119201 2026] [security2:error] [pid 533360:tid 533606] [client 34.23.49.104:61690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hctreinamentos.net"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9dXnUPuLYrePtEkUcEPQAAAPY"]
[Tue Jul 21 08:51:58.191690 2026] [security2:error] [pid 533360:tid 533582] [client 65.21.113.253:33414] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dXXUPuLYrePtEkUcEKAAAAN4"]
[Tue Jul 21 08:51:58.603098 2026] [security2:error] [pid 533360:tid 533540] [client 34.23.49.104:62645] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "hctreinamentos.net"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9dXnUPuLYrePtEkUcESwAAALQ"]
[Tue Jul 21 08:51:58.695850 2026] [security2:error] [pid 533360:tid 533597] [client 168.167.81.163:63332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dXnUPuLYrePtEkUcETwAAAO0"]
[Tue Jul 21 08:51:58.695993 2026] [security2:error] [pid 533360:tid 533597] [client 168.167.81.163:63332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dXnUPuLYrePtEkUcETwAAAO0"]
[Tue Jul 21 08:51:58.713219 2026] [security2:error] [pid 533360:tid 533574] [client 20.220.225.223:38721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/2352356666.php"] [unique_id "al9dXnUPuLYrePtEkUcEUAAAANY"]
[Tue Jul 21 08:51:58.849265 2026] [security2:error] [pid 533360:tid 533583] [client 212.32.76.6:30565] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/fonts-long.php"] [unique_id "al9dXnUPuLYrePtEkUcEVAAAAN8"]
[Tue Jul 21 08:51:58.871088 2026] [security2:error] [pid 533360:tid 533589] [client 20.104.96.117:4072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/solo1.php"] [unique_id "al9dXnUPuLYrePtEkUcEVwAAAOU"]
[Tue Jul 21 08:51:59.302567 2026] [security2:error] [pid 533360:tid 533593] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dX3UPuLYrePtEkUcEXwAA6SY"]
[Tue Jul 21 08:51:59.322625 2026] [security2:error] [pid 533360:tid 533575] [client 20.10.88.227:11650] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gnxinox.com.br"] [uri "/index.php"] [unique_id "al9dX3UPuLYrePtEkUcEZAAAANc"]
[Tue Jul 21 08:51:59.814644 2026] [security2:error] [pid 533360:tid 533608] [client 35.204.70.15:65331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.70.204.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reabfit.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dX3UPuLYrePtEkUcEgQAAAPg"]
[Tue Jul 21 08:51:59.843620 2026] [security2:error] [pid 533360:tid 533541] [client 203.25.124.67:62959] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/wp-config/index.php"] [unique_id "al9dX3UPuLYrePtEkUcEgwAAALU"]
[Tue Jul 21 08:51:59.942331 2026] [security2:error] [pid 533360:tid 533416] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dX3UPuLYrePtEkUcEhQAAvzQ"]
[Tue Jul 21 08:51:59.942507 2026] [security2:error] [pid 533360:tid 533551] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dX3UPuLYrePtEkUcEhQAAvzQ"]
[Tue Jul 21 08:52:00.060350 2026] [security2:error] [pid 533360:tid 533581] [client 113.22.144.139:59598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dYHUPuLYrePtEkUcEiQAAAN0"]
[Tue Jul 21 08:52:00.061937 2026] [security2:error] [pid 533360:tid 533581] [client 113.22.144.139:59598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dYHUPuLYrePtEkUcEiQAAAN0"]
[Tue Jul 21 08:52:00.170478 2026] [security2:error] [pid 533360:tid 533542] [client 212.32.76.56:47019] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/about/function.php"] [unique_id "al9dYHUPuLYrePtEkUcEiwAAALY"]
[Tue Jul 21 08:52:00.262835 2026] [security2:error] [pid 533360:tid 533420] [remote 194.164.192.228:45862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abrsolar.org.br"] [uri "/wp-login.php"] [unique_id "al9dYHUPuLYrePtEkUcEkAAArjg"]
[Tue Jul 21 08:52:00.570434 2026] [security2:error] [pid 533360:tid 533593] [client 20.104.96.117:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/fffm.php"] [unique_id "al9dYHUPuLYrePtEkUcElQAAAOk"]
[Tue Jul 21 08:52:00.615057 2026] [security2:error] [pid 533360:tid 533620] [client 20.197.192.193:27155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9dYHUPuLYrePtEkUcEmQAAAQQ"]
[Tue Jul 21 08:52:00.773039 2026] [security2:error] [pid 533360:tid 533578] [client 59.95.197.55:58763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dYHUPuLYrePtEkUcEqgAAANo"]
[Tue Jul 21 08:52:00.773798 2026] [security2:error] [pid 533360:tid 533578] [client 59.95.197.55:58763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dYHUPuLYrePtEkUcEqgAAANo"]
[Tue Jul 21 08:52:00.860171 2026] [security2:error] [pid 533360:tid 533580] [client 114.198.138.124:53124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dYHUPuLYrePtEkUcEswAAANw"]
[Tue Jul 21 08:52:00.860287 2026] [security2:error] [pid 533360:tid 533580] [client 114.198.138.124:53124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dYHUPuLYrePtEkUcEswAAANw"]
[Tue Jul 21 08:52:00.963494 2026] [security2:error] [pid 533360:tid 533530] [client 20.104.96.117:4035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/cong.php"] [unique_id "al9dYHUPuLYrePtEkUcEtgAAAKo"]
[Tue Jul 21 08:52:01.002776 2026] [security2:error] [pid 533360:tid 533568] [client 122.176.100.127:60533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dYXUPuLYrePtEkUcEuAAAANA"]
[Tue Jul 21 08:52:01.002957 2026] [security2:error] [pid 533360:tid 533568] [client 122.176.100.127:60533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dYXUPuLYrePtEkUcEuAAAANA"]
[Tue Jul 21 08:52:01.079469 2026] [security2:error] [pid 533360:tid 533432] [remote 64.227.151.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.151.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9dYXUPuLYrePtEkUcEuwAA8UQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:52:01.079602 2026] [security2:error] [pid 533360:tid 533431] [remote 64.227.151.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.151.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9dYXUPuLYrePtEkUcEugAArUM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:52:01.082024 2026] [security2:error] [pid 533360:tid 533518] [client 65.21.113.253:38478] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dYXUPuLYrePtEkUcEvAAAAJ4"]
[Tue Jul 21 08:52:01.138845 2026] [proxy:error] [pid 533360:tid 533498] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:52:01.138909 2026] [proxy_http:error] [pid 533360:tid 533498] [client 198.235.24.180:62224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:52:01.139599 2026] [proxy:error] [pid 533360:tid 533498] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:52:01.139635 2026] [proxy_http:error] [pid 533360:tid 533498] [client 198.235.24.180:62224] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:52:01.155211 2026] [security2:error] [pid 533360:tid 533430] [remote 64.227.151.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.151.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9dYXUPuLYrePtEkUcEuQAAjUI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:52:01.156554 2026] [security2:error] [pid 533360:tid 533435] [remote 64.227.151.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.151.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9dYXUPuLYrePtEkUcEwwAAqEc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:52:01.295393 2026] [security2:error] [pid 533360:tid 533583] [client 20.220.225.223:35101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/tkikikoko.php"] [unique_id "al9dYXUPuLYrePtEkUcEyQAAAN8"]
[Tue Jul 21 08:52:01.397381 2026] [security2:error] [pid 533360:tid 533438] [remote 64.227.151.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.151.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9dYXUPuLYrePtEkUcEzQAA8ko"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:52:01.487050 2026] [security2:error] [pid 533360:tid 533440] [remote 64.227.151.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.151.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9dYXUPuLYrePtEkUcEzwAA7Ew"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:52:01.550750 2026] [security2:error] [pid 533360:tid 533442] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dYXUPuLYrePtEkUcE0gAAxk4"]
[Tue Jul 21 08:52:01.550961 2026] [security2:error] [pid 533360:tid 533558] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dYXUPuLYrePtEkUcE0gAAxk4"]
[Tue Jul 21 08:52:01.794794 2026] [security2:error] [pid 533360:tid 533502] [client 20.220.225.223:38729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/pn.php"] [unique_id "al9dYXUPuLYrePtEkUcE2gAAAI4"]
[Tue Jul 21 08:52:01.923470 2026] [security2:error] [pid 533360:tid 533447] [remote 64.227.151.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.151.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9dYXUPuLYrePtEkUcE6AAAl1M"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:52:02.136568 2026] [security2:error] [pid 533360:tid 533453] [remote 64.227.151.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.151.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9dYnUPuLYrePtEkUcE8wAA3lk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:52:02.163300 2026] [security2:error] [pid 533360:tid 533454] [remote 45.3.50.206:30955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.50.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9dYnUPuLYrePtEkUcE9QAAo1o"]
[Tue Jul 21 08:52:02.221190 2026] [security2:error] [pid 533360:tid 533456] [remote 160.187.68.132:40564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9dYnUPuLYrePtEkUcE-QAA_Fw"]
[Tue Jul 21 08:52:02.241453 2026] [security2:error] [pid 533360:tid 533600] [client 65.21.113.253:40020] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dYXUPuLYrePtEkUcE1wAAAPA"]
[Tue Jul 21 08:52:02.248204 2026] [security2:error] [pid 533360:tid 533457] [remote 64.227.151.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.151.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9dYnUPuLYrePtEkUcE-wAAqV0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:52:02.277092 2026] [security2:error] [pid 533360:tid 533581] [client 203.25.124.190:27947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/maint/about.php"] [unique_id "al9dYnUPuLYrePtEkUcE_QAAAN0"]
[Tue Jul 21 08:52:02.312500 2026] [security2:error] [pid 533360:tid 533459] [remote 64.227.151.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.151.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9dYnUPuLYrePtEkUcE_gAAmF8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:52:02.440037 2026] [security2:error] [pid 533360:tid 533597] [client 203.25.124.32:22685] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/cyber-security-blocks/parts/parts/user-edit.php"] [unique_id "al9dYnUPuLYrePtEkUcFDgAAAO0"]
[Tue Jul 21 08:52:02.466293 2026] [security2:error] [pid 533360:tid 533534] [client 20.104.96.117:61135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/dfre.php"] [unique_id "al9dYnUPuLYrePtEkUcFEgAAAK4"]
[Tue Jul 21 08:52:02.496011 2026] [security2:error] [pid 533360:tid 533479] [remote 64.227.151.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.151.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9dYnUPuLYrePtEkUcFGQAA4nM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:52:02.569386 2026] [security2:error] [pid 533360:tid 533481] [remote 64.227.151.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.151.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9dYnUPuLYrePtEkUcFHQAAmnU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:52:02.616995 2026] [security2:error] [pid 533360:tid 533485] [remote 64.227.151.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.151.227.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9dYnUPuLYrePtEkUcFIwAAxnk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:52:02.733618 2026] [security2:error] [pid 533360:tid 533580] [client 74.7.175.175:42866] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.carlosmangajr.com"] [uri "/index.php"] [unique_id "al9dYXUPuLYrePtEkUcE6gAA3FU"]
[Tue Jul 21 08:52:03.542160 2026] [security2:error] [pid 533360:tid 533589] [client 203.25.124.51:39015] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/shadow-bot.php"] [unique_id "al9dY3UPuLYrePtEkUcFUAAAAOU"]
[Tue Jul 21 08:52:03.871564 2026] [security2:error] [pid 533360:tid 533580] [client 203.25.124.192:23985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/upload/upload.php"] [unique_id "al9dY3UPuLYrePtEkUcFYAAAANw"]
[Tue Jul 21 08:52:03.927928 2026] [security2:error] [pid 533360:tid 533585] [client 20.197.192.193:27172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9dY3UPuLYrePtEkUcFaAAAAOE"]
[Tue Jul 21 08:52:04.316175 2026] [security2:error] [pid 533360:tid 533522] [client 152.59.181.104:61551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dZHUPuLYrePtEkUcFdQAAAKI"]
[Tue Jul 21 08:52:04.316318 2026] [security2:error] [pid 533360:tid 533522] [client 152.59.181.104:61551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dZHUPuLYrePtEkUcFdQAAAKI"]
[Tue Jul 21 08:52:04.504781 2026] [security2:error] [pid 533360:tid 533615] [client 195.49.128.211:50258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dZHUPuLYrePtEkUcFjQAAAP8"]
[Tue Jul 21 08:52:04.504935 2026] [security2:error] [pid 533360:tid 533615] [client 195.49.128.211:50258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dZHUPuLYrePtEkUcFjQAAAP8"]
[Tue Jul 21 08:52:04.842846 2026] [security2:error] [pid 533360:tid 533535] [client 5.38.115.39:32859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dZHUPuLYrePtEkUcFsgAAAK8"]
[Tue Jul 21 08:52:04.842986 2026] [security2:error] [pid 533360:tid 533535] [client 5.38.115.39:32859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dZHUPuLYrePtEkUcFsgAAAK8"]
[Tue Jul 21 08:52:05.043727 2026] [security2:error] [pid 533360:tid 533498] [client 203.25.124.215:35989] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/html/html/dark-mode.php"] [unique_id "al9dZXUPuLYrePtEkUcFvAAAAIo"]
[Tue Jul 21 08:52:05.058464 2026] [security2:error] [pid 533360:tid 533599] [client 49.144.66.253:32077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dZXUPuLYrePtEkUcFvQAAAO8"]
[Tue Jul 21 08:52:05.058569 2026] [security2:error] [pid 533360:tid 533599] [client 49.144.66.253:32077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dZXUPuLYrePtEkUcFvQAAAO8"]
[Tue Jul 21 08:52:05.095473 2026] [security2:error] [pid 533360:tid 533529] [client 20.104.96.117:61109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/wp-happy.php"] [unique_id "al9dZXUPuLYrePtEkUcFvgAAAKk"]
[Tue Jul 21 08:52:05.127559 2026] [security2:error] [pid 533360:tid 533550] [client 35.204.70.15:51933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.70.204.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reabfit.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dZXUPuLYrePtEkUcFvwAAAL4"]
[Tue Jul 21 08:52:05.127699 2026] [security2:error] [pid 533360:tid 533550] [client 35.204.70.15:51933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "reabfit.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dZXUPuLYrePtEkUcFvwAAAL4"]
[Tue Jul 21 08:52:05.362493 2026] [security2:error] [pid 533360:tid 533510] [client 20.197.192.193:27146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/dp.php"] [unique_id "al9dZXUPuLYrePtEkUcFxwAAAJY"]
[Tue Jul 21 08:52:05.464637 2026] [security2:error] [pid 533360:tid 533494] [client 41.89.234.2:61698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dZXUPuLYrePtEkUcFywAAAIY"]
[Tue Jul 21 08:52:05.464846 2026] [security2:error] [pid 533360:tid 533494] [client 41.89.234.2:61698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dZXUPuLYrePtEkUcFywAAAIY"]
[Tue Jul 21 08:52:05.934346 2026] [security2:error] [pid 533360:tid 533618] [client 20.220.225.223:46699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9dZXUPuLYrePtEkUcF2AAAAQI"]
[Tue Jul 21 08:52:06.069240 2026] [security2:error] [pid 533360:tid 533504] [client 203.25.124.251:50939] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wpc.php"] [unique_id "al9dZnUPuLYrePtEkUcF3AAAAJA"]
[Tue Jul 21 08:52:06.139066 2026] [security2:error] [pid 533360:tid 533513] [client 203.25.124.73:53975] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/includes/menu-beta.php"] [unique_id "al9dZnUPuLYrePtEkUcF3QAAAJk"]
[Tue Jul 21 08:52:06.162586 2026] [security2:error] [pid 533360:tid 533463] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dZnUPuLYrePtEkUcF3gAAn2M"]
[Tue Jul 21 08:52:06.162810 2026] [security2:error] [pid 533360:tid 533519] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dZnUPuLYrePtEkUcF3gAAn2M"]
[Tue Jul 21 08:52:06.190108 2026] [security2:error] [pid 533360:tid 533535] [client 198.44.157.34:34326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9dZnUPuLYrePtEkUcF4AAAAK8"]
[Tue Jul 21 08:52:06.190211 2026] [security2:error] [pid 533360:tid 533535] [client 198.44.157.34:34326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9dZnUPuLYrePtEkUcF4AAAAK8"]
[Tue Jul 21 08:52:07.052183 2026] [security2:error] [pid 533360:tid 533481] [remote 51.68.236.68:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "shopmelhorcompraonline.com"] [uri "/robots.txt"] [unique_id "al9dZ3UPuLYrePtEkUcF-AAA7XU"]
[Tue Jul 21 08:52:07.052421 2026] [security2:error] [pid 533360:tid 533597] [client 51.68.236.68:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "shopmelhorcompraonline.com"] [uri "/robots.txt"] [unique_id "al9dZ3UPuLYrePtEkUcF-AAA7XU"]
[Tue Jul 21 08:52:07.062068 2026] [security2:error] [pid 533360:tid 533598] [client 65.21.113.253:58260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dZ3UPuLYrePtEkUcF-QAAAO4"]
[Tue Jul 21 08:52:07.081638 2026] [security2:error] [pid 533360:tid 533575] [client 20.104.96.117:60963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/fpr4.php"] [unique_id "al9dZ3UPuLYrePtEkUcF_QAAANc"]
[Tue Jul 21 08:52:07.333265 2026] [security2:error] [pid 533360:tid 533390] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9dZ3UPuLYrePtEkUcGIwABAho"]
[Tue Jul 21 08:52:07.380013 2026] [security2:error] [pid 533360:tid 533391] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9dZ3UPuLYrePtEkUcGJAAA4hs"]
[Tue Jul 21 08:52:07.406474 2026] [security2:error] [pid 533360:tid 533385] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/media.php"] [unique_id "al9dZ3UPuLYrePtEkUcGJQAA8xU"]
[Tue Jul 21 08:52:07.424969 2026] [security2:error] [pid 533360:tid 533394] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/images.php"] [unique_id "al9dZ3UPuLYrePtEkUcGKgAAlx4"]
[Tue Jul 21 08:52:07.439855 2026] [security2:error] [pid 533360:tid 533568] [client 203.25.124.53:20097] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/block-bindings/lib/index.php"] [unique_id "al9dZ3UPuLYrePtEkUcGKwAAANA"]
[Tue Jul 21 08:52:07.462841 2026] [security2:error] [pid 533360:tid 533364] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/gecko.php"] [unique_id "al9dZ3UPuLYrePtEkUcGLAAAkAA"]
[Tue Jul 21 08:52:07.524857 2026] [security2:error] [pid 533360:tid 533404] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/82.php"] [unique_id "al9dZ3UPuLYrePtEkUcGMwAArCg"]
[Tue Jul 21 08:52:07.551397 2026] [security2:error] [pid 533360:tid 533408] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/admin.php"] [unique_id "al9dZ3UPuLYrePtEkUcGOAAAtSw"]
[Tue Jul 21 08:52:07.565765 2026] [autoindex:error] [pid 533360:tid 533517] [client 34.168.88.184:51239] AH01276: Cannot serve directory /home3/eltonf08/efrelectronics.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:52:07.565921 2026] [autoindex:error] [pid 533360:tid 533521] [client 34.168.88.184:51595] AH01276: Cannot serve directory /home3/eltonf08/efrelectronics.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:52:07.659482 2026] [security2:error] [pid 533360:tid 533514] [client 182.189.99.211:48359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dZ3UPuLYrePtEkUcGRAAAAJo"]
[Tue Jul 21 08:52:07.660278 2026] [security2:error] [pid 533360:tid 533514] [client 182.189.99.211:48359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dZ3UPuLYrePtEkUcGRAAAAJo"]
[Tue Jul 21 08:52:07.783982 2026] [security2:error] [pid 533360:tid 533415] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dZ3UPuLYrePtEkUcGSQAAvzM"]
[Tue Jul 21 08:52:07.784129 2026] [security2:error] [pid 533360:tid 533551] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dZ3UPuLYrePtEkUcGSQAAvzM"]
[Tue Jul 21 08:52:07.784295 2026] [security2:error] [pid 533360:tid 533506] [client 20.220.225.223:37613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/wp-css.php"] [unique_id "al9dZ3UPuLYrePtEkUcGSgAAAJI"]
[Tue Jul 21 08:52:08.129477 2026] [security2:error] [pid 533360:tid 533569] [client 65.21.113.253:40028] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dZ3UPuLYrePtEkUcGSAAAANE"]
[Tue Jul 21 08:52:08.175697 2026] [security2:error] [pid 533360:tid 533572] [client 203.25.124.192:50733] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "al9daHUPuLYrePtEkUcGXAAAANQ"]
[Tue Jul 21 08:52:08.284933 2026] [security2:error] [pid 533360:tid 533552] [client 34.168.88.184:51595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.88.168.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com"] [uri "/xmlrpc.php"] [unique_id "al9daHUPuLYrePtEkUcGYAAAAMA"]
[Tue Jul 21 08:52:08.390755 2026] [security2:error] [pid 533360:tid 533603] [client 20.220.225.223:60258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9daHUPuLYrePtEkUcGYwAAAPM"]
[Tue Jul 21 08:52:08.411529 2026] [security2:error] [pid 533360:tid 533414] [remote 45.146.55.191:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.55.146.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mecanicanogueira.com.br"] [uri "/wp-login.php"] [unique_id "al9daHUPuLYrePtEkUcGXwAAjjI"]
[Tue Jul 21 08:52:08.530458 2026] [security2:error] [pid 533360:tid 533410] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9daHUPuLYrePtEkUcGaQAAkS4"]
[Tue Jul 21 08:52:08.530664 2026] [security2:error] [pid 533360:tid 533505] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9daHUPuLYrePtEkUcGaQAAkS4"]
[Tue Jul 21 08:52:08.543610 2026] [security2:error] [pid 533360:tid 533519] [client 34.168.88.184:51239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.88.168.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.efrelectronics.com.br"] [uri "/xmlrpc.php"] [unique_id "al9daHUPuLYrePtEkUcGawAAAJ8"]
[Tue Jul 21 08:52:08.676609 2026] [security2:error] [pid 533360:tid 533545] [client 20.197.192.193:27179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/old.php"] [unique_id "al9daHUPuLYrePtEkUcGcwAAALk"]
[Tue Jul 21 08:52:08.722118 2026] [security2:error] [pid 533360:tid 533543] [client 34.168.88.184:65281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9daHUPuLYrePtEkUcGdgAAALc"]
[Tue Jul 21 08:52:08.768582 2026] [security2:error] [pid 533360:tid 533605] [client 173.252.95.58:53488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9daHUPuLYrePtEkUcGbAAAAPU"]
[Tue Jul 21 08:52:08.850955 2026] [security2:error] [pid 533360:tid 533560] [client 195.206.105.227:36866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9daHUPuLYrePtEkUcGfgAAAMg"]
[Tue Jul 21 08:52:08.851062 2026] [security2:error] [pid 533360:tid 533560] [client 195.206.105.227:36866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9daHUPuLYrePtEkUcGfgAAAMg"]
[Tue Jul 21 08:52:08.878714 2026] [security2:error] [pid 533360:tid 533551] [client 203.25.124.9:53733] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/as.php"] [unique_id "al9daHUPuLYrePtEkUcGfwAAAL8"]
[Tue Jul 21 08:52:08.940642 2026] [security2:error] [pid 533360:tid 533565] [client 203.25.124.32:63185] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/network/theme-install-table.php"] [unique_id "al9daHUPuLYrePtEkUcGgAAAAM0"]
[Tue Jul 21 08:52:08.960039 2026] [security2:error] [pid 533360:tid 533438] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/adminner.php"] [unique_id "al9daHUPuLYrePtEkUcGggAA_0o"]
[Tue Jul 21 08:52:08.978999 2026] [security2:error] [pid 533360:tid 533421] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/admin.php"] [unique_id "al9daHUPuLYrePtEkUcGgwAA9jk"]
[Tue Jul 21 08:52:08.987529 2026] [security2:error] [pid 533360:tid 533600] [client 34.168.88.184:53334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com.efrelectronics.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9daHUPuLYrePtEkUcGhAAAAPA"]
[Tue Jul 21 08:52:08.997383 2026] [security2:error] [pid 533360:tid 533440] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/k.php"] [unique_id "al9daHUPuLYrePtEkUcGhQAAtEw"]
[Tue Jul 21 08:52:09.027147 2026] [security2:error] [pid 533360:tid 533442] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/blurbs.php"] [unique_id "al9daXUPuLYrePtEkUcGhwAAnk4"]
[Tue Jul 21 08:52:09.048509 2026] [security2:error] [pid 533360:tid 533428] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/bajah.php"] [unique_id "al9daXUPuLYrePtEkUcGiAAAsEA"]
[Tue Jul 21 08:52:09.096382 2026] [security2:error] [pid 533360:tid 533564] [client 34.168.88.184:56498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9daXUPuLYrePtEkUcGjAAAAMw"]
[Tue Jul 21 08:52:09.163675 2026] [security2:error] [pid 533360:tid 533446] [remote 45.79.123.44:57240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kaducontractor.com"] [uri "/wp-login.php"] [unique_id "al9daXUPuLYrePtEkUcGkAAAoVI"]
[Tue Jul 21 08:52:09.317196 2026] [security2:error] [pid 533360:tid 533597] [client 173.252.95.0:52052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9daXUPuLYrePtEkUcGkQAAAO0"]
[Tue Jul 21 08:52:09.374667 2026] [security2:error] [pid 533360:tid 533513] [client 168.167.81.163:59582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9daXUPuLYrePtEkUcGkwAAAJk"]
[Tue Jul 21 08:52:09.374788 2026] [security2:error] [pid 533360:tid 533513] [client 168.167.81.163:59582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9daXUPuLYrePtEkUcGkwAAAJk"]
[Tue Jul 21 08:52:09.403656 2026] [security2:error] [pid 533360:tid 533579] [client 20.104.96.117:59165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/file88.php"] [unique_id "al9daXUPuLYrePtEkUcGmAAAANs"]
[Tue Jul 21 08:52:09.476220 2026] [security2:error] [pid 533360:tid 533603] [client 34.168.88.184:60665] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com.efrelectronics.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9daXUPuLYrePtEkUcGnQAAAPM"]
[Tue Jul 21 08:52:09.485881 2026] [security2:error] [pid 533360:tid 533595] [client 34.168.88.184:64712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9daXUPuLYrePtEkUcGngAAAOs"]
[Tue Jul 21 08:52:09.540943 2026] [security2:error] [pid 533360:tid 533453] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/a.php"] [unique_id "al9daXUPuLYrePtEkUcGoQAAsFk"]
[Tue Jul 21 08:52:09.830791 2026] [security2:error] [pid 533360:tid 533524] [client 34.168.88.184:65439] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com.efrelectronics.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9daXUPuLYrePtEkUcGtAAAAKQ"]
[Tue Jul 21 08:52:10.016904 2026] [security2:error] [pid 533360:tid 533555] [client 34.168.88.184:57515] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9danUPuLYrePtEkUcGvQAAAMM"]
[Tue Jul 21 08:52:10.032243 2026] [security2:error] [pid 533360:tid 533474] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/edit.php"] [unique_id "al9danUPuLYrePtEkUcGvgAA_G4"]
[Tue Jul 21 08:52:10.054685 2026] [security2:error] [pid 533360:tid 533478] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/hosty.php"] [unique_id "al9danUPuLYrePtEkUcGwAAAqXI"]
[Tue Jul 21 08:52:10.074390 2026] [security2:error] [pid 533360:tid 533498] [client 203.25.124.4:58069] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwentyfive/patterns/template-singl-portfolio.php"] [unique_id "al9danUPuLYrePtEkUcGwQAAAIo"]
[Tue Jul 21 08:52:10.128769 2026] [security2:error] [pid 533360:tid 533532] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9danUPuLYrePtEkUcGvwAArGU"]
[Tue Jul 21 08:52:10.335245 2026] [security2:error] [pid 533360:tid 533564] [client 34.168.88.184:60414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com.efrelectronics.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9danUPuLYrePtEkUcG0AAAAMw"]
[Tue Jul 21 08:52:10.359544 2026] [security2:error] [pid 533360:tid 533542] [client 20.220.225.223:6085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9danUPuLYrePtEkUcG0wAAALY"]
[Tue Jul 21 08:52:10.367761 2026] [security2:error] [pid 533360:tid 533561] [client 34.168.88.184:59279] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9danUPuLYrePtEkUcG1AAAAMk"]
[Tue Jul 21 08:52:10.431170 2026] [security2:error] [pid 533360:tid 533488] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/k.php"] [unique_id "al9danUPuLYrePtEkUcG1wAAvXw"]
[Tue Jul 21 08:52:10.450602 2026] [security2:error] [pid 533360:tid 533450] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/aaa.php"] [unique_id "al9danUPuLYrePtEkUcG2QAAhVY"]
[Tue Jul 21 08:52:10.477035 2026] [security2:error] [pid 533360:tid 533373] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/file5.php"] [unique_id "al9danUPuLYrePtEkUcG2wAAoQk"]
[Tue Jul 21 08:52:10.610737 2026] [security2:error] [pid 533360:tid 533502] [client 5.31.193.106:58589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.193.31.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9danUPuLYrePtEkUcG4QAAAI4"]
[Tue Jul 21 08:52:10.610859 2026] [security2:error] [pid 533360:tid 533502] [client 5.31.193.106:58589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9danUPuLYrePtEkUcG4QAAAI4"]
[Tue Jul 21 08:52:10.668089 2026] [security2:error] [pid 533360:tid 533512] [client 20.220.225.223:19269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/fz.php"] [unique_id "al9danUPuLYrePtEkUcG4wAAAJg"]
[Tue Jul 21 08:52:10.719014 2026] [security2:error] [pid 533360:tid 533616] [client 34.168.88.184:56774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9danUPuLYrePtEkUcG6wAAAQA"]
[Tue Jul 21 08:52:10.752536 2026] [security2:error] [pid 533360:tid 533610] [client 203.25.124.39:37007] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/chosen.php"] [unique_id "al9danUPuLYrePtEkUcG8AAAAPo"]
[Tue Jul 21 08:52:10.756703 2026] [security2:error] [pid 533360:tid 533546] [client 34.168.88.184:53003] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com.efrelectronics.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9danUPuLYrePtEkUcG8gAAALo"]
[Tue Jul 21 08:52:10.843852 2026] [security2:error] [pid 533360:tid 533377] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9danUPuLYrePtEkUcG9AAAlg0"]
[Tue Jul 21 08:52:10.843988 2026] [security2:error] [pid 533360:tid 533510] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9danUPuLYrePtEkUcG9AAAlg0"]
[Tue Jul 21 08:52:10.872824 2026] [security2:error] [pid 533360:tid 533582] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9danUPuLYrePtEkUcG9wAAAN4"]
[Tue Jul 21 08:52:10.915997 2026] [security2:error] [pid 533360:tid 533605] [client 113.22.144.139:60435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9danUPuLYrePtEkUcG-QAAAPU"]
[Tue Jul 21 08:52:10.916496 2026] [security2:error] [pid 533360:tid 533605] [client 113.22.144.139:60435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9danUPuLYrePtEkUcG-QAAAPU"]
[Tue Jul 21 08:52:10.954138 2026] [security2:error] [pid 533360:tid 533388] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/222.php"] [unique_id "al9danUPuLYrePtEkUcG_QAAvBg"]
[Tue Jul 21 08:52:11.016587 2026] [security2:error] [pid 533360:tid 533496] [client 20.220.225.223:48193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/dr.php"] [unique_id "al9da3UPuLYrePtEkUcHAQAAAIg"]
[Tue Jul 21 08:52:11.035166 2026] [security2:error] [pid 533360:tid 533544] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9da3UPuLYrePtEkUcHBAAAALg"]
[Tue Jul 21 08:52:11.137353 2026] [security2:error] [pid 533360:tid 533557] [client 34.168.88.184:59183] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9da3UPuLYrePtEkUcHCQAAAMU"]
[Tue Jul 21 08:52:11.255859 2026] [security2:error] [pid 533360:tid 533513] [client 59.95.197.55:59234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9da3UPuLYrePtEkUcHDgAAAJk"]
[Tue Jul 21 08:52:11.255990 2026] [security2:error] [pid 533360:tid 533513] [client 59.95.197.55:59234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9da3UPuLYrePtEkUcHDgAAAJk"]
[Tue Jul 21 08:52:11.271458 2026] [security2:error] [pid 533360:tid 533573] [client 203.25.124.192:27831] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wso.php"] [unique_id "al9da3UPuLYrePtEkUcHEgAAANU"]
[Tue Jul 21 08:52:11.314208 2026] [security2:error] [pid 533360:tid 533503] [client 34.168.88.184:62775] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com.efrelectronics.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9da3UPuLYrePtEkUcHFAAAAI8"]
[Tue Jul 21 08:52:11.400894 2026] [security2:error] [pid 533360:tid 533499] [client 114.198.138.124:53716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9da3UPuLYrePtEkUcHGQAAAIs"]
[Tue Jul 21 08:52:11.400991 2026] [security2:error] [pid 533360:tid 533499] [client 114.198.138.124:53716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9da3UPuLYrePtEkUcHGQAAAIs"]
[Tue Jul 21 08:52:11.402299 2026] [security2:error] [pid 533360:tid 533614] [client 65.21.113.253:58260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9da3UPuLYrePtEkUcHGAAAAP4"]
[Tue Jul 21 08:52:11.437570 2026] [security2:error] [pid 533360:tid 533581] [client 203.25.124.58:34565] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/SimplePie/src/Content/autoload_classmap.php"] [unique_id "al9da3UPuLYrePtEkUcHHAAAAN0"]
[Tue Jul 21 08:52:11.482472 2026] [security2:error] [pid 533360:tid 533517] [client 122.176.100.127:61014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9da3UPuLYrePtEkUcHIwAAAJ0"]
[Tue Jul 21 08:52:11.482615 2026] [security2:error] [pid 533360:tid 533517] [client 122.176.100.127:61014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9da3UPuLYrePtEkUcHIwAAAJ0"]
[Tue Jul 21 08:52:11.541541 2026] [security2:error] [pid 533360:tid 533520] [client 20.220.225.223:23479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9da3UPuLYrePtEkUcHJAAAAKA"]
[Tue Jul 21 08:52:11.678935 2026] [security2:error] [pid 533360:tid 533530] [client 34.168.88.184:56866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9da3UPuLYrePtEkUcHJwAAAKo"]
[Tue Jul 21 08:52:11.750217 2026] [security2:error] [pid 533360:tid 533552] [client 20.197.192.193:27158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/ms-new.php"] [unique_id "al9da3UPuLYrePtEkUcHKAAAAMA"]
[Tue Jul 21 08:52:11.780363 2026] [security2:error] [pid 533360:tid 533574] [client 34.168.88.184:51880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com.efrelectronics.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9da3UPuLYrePtEkUcHLQAAANY"]
[Tue Jul 21 08:52:11.786796 2026] [security2:error] [pid 533360:tid 533510] [client 20.104.96.117:59155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ccc.php"] [unique_id "al9da3UPuLYrePtEkUcHLwAAAJY"]
[Tue Jul 21 08:52:11.885510 2026] [security2:error] [pid 533360:tid 533546] [client 173.252.95.17:34370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9da3UPuLYrePtEkUcHQAAAALo"]
[Tue Jul 21 08:52:11.987132 2026] [security2:error] [pid 533360:tid 533417] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/test.php"] [unique_id "al9da3UPuLYrePtEkUcHRwAAvzU"]
[Tue Jul 21 08:52:12.007170 2026] [security2:error] [pid 533360:tid 533389] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/aaa.php"] [unique_id "al9dbHUPuLYrePtEkUcHSAAAuBk"]
[Tue Jul 21 08:52:12.039722 2026] [security2:error] [pid 533360:tid 533566] [client 20.220.225.223:35103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/wp-explorer.php"] [unique_id "al9dbHUPuLYrePtEkUcHSwAAAM4"]
[Tue Jul 21 08:52:12.058227 2026] [security2:error] [pid 533360:tid 533542] [client 98.159.37.246:32291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.37.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gtlocacoes.net"] [uri "/wp-login.php"] [unique_id "al9da3UPuLYrePtEkUcHQQAAALY"]
[Tue Jul 21 08:52:12.067407 2026] [security2:error] [pid 533360:tid 533501] [client 34.168.88.184:56788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9dbHUPuLYrePtEkUcHTAAAAI0"]
[Tue Jul 21 08:52:12.247492 2026] [security2:error] [pid 533360:tid 533600] [client 203.25.124.61:57335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/IXR/shadow-bot.php"] [unique_id "al9dbHUPuLYrePtEkUcHTgAAAPA"]
[Tue Jul 21 08:52:12.311802 2026] [security2:error] [pid 533360:tid 533513] [client 34.168.88.184:58871] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com.efrelectronics.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9dbHUPuLYrePtEkUcHVQAAAJk"]
[Tue Jul 21 08:52:12.374676 2026] [security2:error] [pid 533360:tid 533503] [client 212.32.76.55:28645] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-info.php"] [unique_id "al9dbHUPuLYrePtEkUcHVwAAAI8"]
[Tue Jul 21 08:52:12.449537 2026] [security2:error] [pid 533360:tid 533427] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dbHUPuLYrePtEkUcHWQAA6T8"]
[Tue Jul 21 08:52:12.449771 2026] [security2:error] [pid 533360:tid 533593] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dbHUPuLYrePtEkUcHWQAA6T8"]
[Tue Jul 21 08:52:12.476558 2026] [security2:error] [pid 533360:tid 533537] [client 65.21.113.253:55890] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dbHUPuLYrePtEkUcHTQAAALE"]
[Tue Jul 21 08:52:12.521684 2026] [security2:error] [pid 533360:tid 533614] [client 34.168.88.184:57239] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9dbHUPuLYrePtEkUcHWwAAAP4"]
[Tue Jul 21 08:52:12.665761 2026] [security2:error] [pid 533360:tid 533430] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/11.php"] [unique_id "al9dbHUPuLYrePtEkUcHXgAA-UI"]
[Tue Jul 21 08:52:12.759679 2026] [security2:error] [pid 533360:tid 533543] [client 34.168.88.184:55841] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com.efrelectronics.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9dbHUPuLYrePtEkUcHYAAAALc"]
[Tue Jul 21 08:52:13.093115 2026] [security2:error] [pid 533360:tid 533617] [client 46.105.38.210:22301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vestfitness.com.br"] [uri "/robots.txt"] [unique_id "al9dbXUPuLYrePtEkUcHbgAAAQE"]
[Tue Jul 21 08:52:13.093215 2026] [security2:error] [pid 533360:tid 533617] [client 46.105.38.210:22301] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vestfitness.com.br"] [uri "/robots.txt"] [unique_id "al9dbXUPuLYrePtEkUcHbgAAAQE"]
[Tue Jul 21 08:52:13.319405 2026] [security2:error] [pid 533360:tid 533541] [client 20.197.192.193:27184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/track.php"] [unique_id "al9dbXUPuLYrePtEkUcHcwAAALU"]
[Tue Jul 21 08:52:13.340220 2026] [security2:error] [pid 533360:tid 533605] [client 212.32.76.10:53089] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/chosen.php"] [unique_id "al9dbXUPuLYrePtEkUcHdQAAAPU"]
[Tue Jul 21 08:52:13.352250 2026] [security2:error] [pid 533360:tid 533535] [client 34.168.88.184:53512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com.efrelectronics.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9dbXUPuLYrePtEkUcHdgAAAK8"]
[Tue Jul 21 08:52:13.636536 2026] [security2:error] [pid 533360:tid 533566] [client 20.220.225.223:23431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/dp.php"] [unique_id "al9dbXUPuLYrePtEkUcHfQAAAM4"]
[Tue Jul 21 08:52:13.641062 2026] [security2:error] [pid 533360:tid 533428] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/mac.php"] [unique_id "al9dbXUPuLYrePtEkUcHfgAAxEA"]
[Tue Jul 21 08:52:13.662360 2026] [security2:error] [pid 533360:tid 533433] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/chosen.php"] [unique_id "al9dbXUPuLYrePtEkUcHfwAAtkU"]
[Tue Jul 21 08:52:13.684018 2026] [security2:error] [pid 533360:tid 533444] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/cream1.php"] [unique_id "al9dbXUPuLYrePtEkUcHgAAAzVA"]
[Tue Jul 21 08:52:13.759438 2026] [security2:error] [pid 533360:tid 533615] [client 20.220.225.223:19654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/la.php"] [unique_id "al9dbXUPuLYrePtEkUcHgwAAAP8"]
[Tue Jul 21 08:52:13.772518 2026] [authz_core:error] [pid 533360:tid 533406] [remote 20.197.195.24:0] AH01630: client denied by server configuration: /home4/serric15/public_html/wp-content/uploads/index.php
[Tue Jul 21 08:52:13.796943 2026] [security2:error] [pid 533360:tid 533514] [client 173.252.95.8:42744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dbXUPuLYrePtEkUcHhQAAAJo"]
[Tue Jul 21 08:52:13.846634 2026] [autoindex:error] [pid 533360:tid 533426] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home4/serric15/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:52:13.857608 2026] [security2:error] [pid 533360:tid 533573] [client 34.168.88.184:59656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "efrelectronics.com.efrelectronics.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9dbXUPuLYrePtEkUcHigAAANU"]
[Tue Jul 21 08:52:13.870386 2026] [security2:error] [pid 533360:tid 533403] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/dr.php"] [unique_id "al9dbXUPuLYrePtEkUcHjwAAqCc"]
[Tue Jul 21 08:52:13.926202 2026] [security2:error] [pid 533360:tid 533464] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/x.php"] [unique_id "al9dbXUPuLYrePtEkUcHnwAAoGQ"]
[Tue Jul 21 08:52:13.952073 2026] [security2:error] [pid 533360:tid 533479] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/155.php"] [unique_id "al9dbXUPuLYrePtEkUcHpQAA0XM"]
[Tue Jul 21 08:52:13.959173 2026] [security2:error] [pid 533360:tid 533597] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9dbXUPuLYrePtEkUcHpgAAAO0"]
[Tue Jul 21 08:52:14.021150 2026] [security2:error] [pid 533360:tid 533601] [client 20.104.96.117:4069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/public/css.php"] [unique_id "al9dbnUPuLYrePtEkUcHqQAAAPE"]
[Tue Jul 21 08:52:14.224181 2026] [security2:error] [pid 533360:tid 533477] [remote 104.207.56.69:37045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.56.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9dbnUPuLYrePtEkUcHqgAAnnE"]
[Tue Jul 21 08:52:14.252566 2026] [security2:error] [pid 533360:tid 533483] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/ops.php"] [unique_id "al9dbnUPuLYrePtEkUcHsQAApHc"]
[Tue Jul 21 08:52:14.257525 2026] [security2:error] [pid 533360:tid 533570] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9dbnUPuLYrePtEkUcHswAAANI"]
[Tue Jul 21 08:52:14.278315 2026] [security2:error] [pid 533360:tid 533555] [client 203.25.124.9:58343] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/s.php"] [unique_id "al9dbnUPuLYrePtEkUcHtwAAAMM"]
[Tue Jul 21 08:52:14.341521 2026] [security2:error] [pid 533360:tid 533550] [client 20.220.225.223:6117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/old.php"] [unique_id "al9dbnUPuLYrePtEkUcHuwAAAL4"]
[Tue Jul 21 08:52:14.393663 2026] [security2:error] [pid 533360:tid 533510] [client 173.252.95.58:60354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dbnUPuLYrePtEkUcHvwAAAJY"]
[Tue Jul 21 08:52:14.410708 2026] [security2:error] [pid 533360:tid 533541] [client 173.252.95.1:50228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dbnUPuLYrePtEkUcHwgAAALU"]
[Tue Jul 21 08:52:14.453615 2026] [security2:error] [pid 533360:tid 533450] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/file31.php"] [unique_id "al9dbnUPuLYrePtEkUcHxQAAxFY"]
[Tue Jul 21 08:52:14.473376 2026] [security2:error] [pid 533360:tid 533373] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/file6.php"] [unique_id "al9dbnUPuLYrePtEkUcHxwAAtgk"]
[Tue Jul 21 08:52:14.524482 2026] [autoindex:error] [pid 533360:tid 533371] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home4/serric15/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:52:14.555327 2026] [security2:error] [pid 533360:tid 533539] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9dbnUPuLYrePtEkUcHygAAALM"]
[Tue Jul 21 08:52:14.583128 2026] [security2:error] [pid 533360:tid 533366] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/adminfuns.php"] [unique_id "al9dbnUPuLYrePtEkUcHywAAmgI"]
[Tue Jul 21 08:52:14.604799 2026] [security2:error] [pid 533360:tid 533441] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/goods.php"] [unique_id "al9dbnUPuLYrePtEkUcHzwAAmU0"]
[Tue Jul 21 08:52:14.656389 2026] [security2:error] [pid 533360:tid 533470] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/100.php"] [unique_id "al9dbnUPuLYrePtEkUcH0AAAoWo"]
[Tue Jul 21 08:52:14.685544 2026] [security2:error] [pid 533360:tid 533384] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/about.php"] [unique_id "al9dbnUPuLYrePtEkUcH0wAAqBQ"]
[Tue Jul 21 08:52:14.707302 2026] [security2:error] [pid 533360:tid 533383] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/about.php"] [unique_id "al9dbnUPuLYrePtEkUcH1AAAuxM"]
[Tue Jul 21 08:52:14.773297 2026] [security2:error] [pid 533360:tid 533584] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9dbnUPuLYrePtEkUcH2AAAAOA"]
[Tue Jul 21 08:52:14.817295 2026] [security2:error] [pid 533360:tid 533593] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9dbnUPuLYrePtEkUcH2QAAAOk"]
[Tue Jul 21 08:52:14.826215 2026] [security2:error] [pid 533360:tid 533606] [client 20.220.225.223:23464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/ms-new.php"] [unique_id "al9dbnUPuLYrePtEkUcH2gAAAPY"]
[Tue Jul 21 08:52:14.853335 2026] [security2:error] [pid 533360:tid 533577] [client 20.197.192.193:27164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/2352356666.php"] [unique_id "al9dbnUPuLYrePtEkUcH2wAAANk"]
[Tue Jul 21 08:52:15.005586 2026] [security2:error] [pid 533360:tid 533515] [client 152.59.181.104:57198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9db3UPuLYrePtEkUcH4wAAAJs"]
[Tue Jul 21 08:52:15.005727 2026] [security2:error] [pid 533360:tid 533515] [client 152.59.181.104:57198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9db3UPuLYrePtEkUcH4wAAAJs"]
[Tue Jul 21 08:52:15.059892 2026] [security2:error] [pid 533360:tid 533601] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9db3UPuLYrePtEkUcH5QAAAPE"]
[Tue Jul 21 08:52:15.089279 2026] [security2:error] [pid 533360:tid 533585] [client 20.197.192.193:27147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/pn.php"] [unique_id "al9db3UPuLYrePtEkUcH5gAAAOE"]
[Tue Jul 21 08:52:15.092764 2026] [security2:error] [pid 533360:tid 533573] [client 195.49.128.211:50858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9db3UPuLYrePtEkUcH5wAAANU"]
[Tue Jul 21 08:52:15.092857 2026] [security2:error] [pid 533360:tid 533573] [client 195.49.128.211:50858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9db3UPuLYrePtEkUcH5wAAANU"]
[Tue Jul 21 08:52:15.095443 2026] [security2:error] [pid 533360:tid 533530] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9db3UPuLYrePtEkUcH6AAAAKo"]
[Tue Jul 21 08:52:15.292892 2026] [security2:error] [pid 533360:tid 533374] [remote 66.249.79.137:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sejabarbara.com.br"] [uri "/robots.txt"] [unique_id "al9db3UPuLYrePtEkUcH7QAA6Ao"]
[Tue Jul 21 08:52:15.351267 2026] [security2:error] [pid 533360:tid 533509] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9db3UPuLYrePtEkUcH7gAAAJU"]
[Tue Jul 21 08:52:15.381410 2026] [security2:error] [pid 533360:tid 533617] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9db3UPuLYrePtEkUcH8QAAAQE"]
[Tue Jul 21 08:52:15.445530 2026] [security2:error] [pid 533360:tid 533599] [client 5.38.115.39:54247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9db3UPuLYrePtEkUcH9wAAAO8"]
[Tue Jul 21 08:52:15.445625 2026] [security2:error] [pid 533360:tid 533599] [client 5.38.115.39:54247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9db3UPuLYrePtEkUcH9wAAAO8"]
[Tue Jul 21 08:52:15.480596 2026] [security2:error] [pid 533360:tid 533554] [client 203.25.124.246:62405] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/69.php"] [unique_id "al9db3UPuLYrePtEkUcH-QAAAMI"]
[Tue Jul 21 08:52:15.583638 2026] [security2:error] [pid 533360:tid 533534] [client 195.206.105.227:54650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.105.206.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9db3UPuLYrePtEkUcH-wAAAK4"]
[Tue Jul 21 08:52:15.583747 2026] [security2:error] [pid 533360:tid 533534] [client 195.206.105.227:54650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9db3UPuLYrePtEkUcH-wAAAK4"]
[Tue Jul 21 08:52:15.611426 2026] [security2:error] [pid 533360:tid 533542] [client 20.104.96.117:61084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/777.php"] [unique_id "al9db3UPuLYrePtEkUcH_AAAALY"]
[Tue Jul 21 08:52:15.636214 2026] [security2:error] [pid 533360:tid 533565] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9db3UPuLYrePtEkUcH_gAAAM0"]
[Tue Jul 21 08:52:15.647059 2026] [security2:error] [pid 533360:tid 533387] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/admin.php"] [unique_id "al9db3UPuLYrePtEkUcH_wAAyBc"]
[Tue Jul 21 08:52:15.659592 2026] [security2:error] [pid 533360:tid 533615] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9db3UPuLYrePtEkUcIAAAAAP8"]
[Tue Jul 21 08:52:15.665606 2026] [security2:error] [pid 533360:tid 533449] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/admin.php"] [unique_id "al9db3UPuLYrePtEkUcIAgAAslU"]
[Tue Jul 21 08:52:15.735882 2026] [security2:error] [pid 533360:tid 533576] [client 203.25.124.213:45781] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/prenota/gecko.php"] [unique_id "al9db3UPuLYrePtEkUcIBAAAANg"]
[Tue Jul 21 08:52:15.816218 2026] [security2:error] [pid 533360:tid 533385] [remote 217.182.128.41:39940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shop-officialstore.com"] [uri "/wp-login.php"] [unique_id "al9db3UPuLYrePtEkUcIBgAAxBU"]
[Tue Jul 21 08:52:15.819765 2026] [security2:error] [pid 533360:tid 533528] [client 20.220.225.223:23450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/track.php"] [unique_id "al9db3UPuLYrePtEkUcIBwAAAKg"]
[Tue Jul 21 08:52:15.824027 2026] [security2:error] [pid 533360:tid 533553] [client 47.128.36.53:24920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "blog.meuendocrinoonline.com.br"] [uri "/robots.txt"] [unique_id "al9db3UPuLYrePtEkUcICAAAAME"]
[Tue Jul 21 08:52:15.921340 2026] [security2:error] [pid 533360:tid 533537] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9db3UPuLYrePtEkUcIDgAAALE"]
[Tue Jul 21 08:52:15.942401 2026] [security2:error] [pid 533360:tid 533399] [remote 66.249.79.137:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sejabarbara.com.br"] [uri "/voce-esta-cansada-ou-insatisfeita/"] [unique_id "al9db3UPuLYrePtEkUcIEQAAmiM"]
[Tue Jul 21 08:52:16.000050 2026] [security2:error] [pid 533360:tid 533564] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9db3UPuLYrePtEkUcIEwAAAMw"]
[Tue Jul 21 08:52:16.019480 2026] [security2:error] [pid 533360:tid 533540] [client 49.144.66.253:32499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dcHUPuLYrePtEkUcIFAAAALQ"]
[Tue Jul 21 08:52:16.019589 2026] [security2:error] [pid 533360:tid 533540] [client 49.144.66.253:32499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dcHUPuLYrePtEkUcIFAAAALQ"]
[Tue Jul 21 08:52:16.203680 2026] [security2:error] [pid 533360:tid 533523] [client 41.89.234.2:62166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dcHUPuLYrePtEkUcIGAAAAKM"]
[Tue Jul 21 08:52:16.203853 2026] [security2:error] [pid 533360:tid 533523] [client 41.89.234.2:62166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dcHUPuLYrePtEkUcIGAAAAKM"]
[Tue Jul 21 08:52:16.260564 2026] [security2:error] [pid 533360:tid 533594] [client 65.21.113.253:58260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dcHUPuLYrePtEkUcIGgAAAOo"]
[Tue Jul 21 08:52:16.268893 2026] [security2:error] [pid 533360:tid 533515] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9dcHUPuLYrePtEkUcIGwAAAJs"]
[Tue Jul 21 08:52:16.280308 2026] [security2:error] [pid 533360:tid 533601] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9dcHUPuLYrePtEkUcIHAAAAPE"]
[Tue Jul 21 08:52:16.356992 2026] [security2:error] [pid 533360:tid 533530] [client 20.220.225.223:6122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/2352356666.php"] [unique_id "al9dcHUPuLYrePtEkUcIHgAAAKo"]
[Tue Jul 21 08:52:16.459542 2026] [security2:error] [pid 533360:tid 533378] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/themes.php"] [unique_id "al9dcHUPuLYrePtEkUcIJAAAng4"]
[Tue Jul 21 08:52:16.545021 2026] [security2:error] [pid 533360:tid 533599] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9dcHUPuLYrePtEkUcIJwAAAO8"]
[Tue Jul 21 08:52:16.552145 2026] [security2:error] [pid 533360:tid 533405] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dcHUPuLYrePtEkUcIKAAAqyk"]
[Tue Jul 21 08:52:16.552266 2026] [security2:error] [pid 533360:tid 533531] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dcHUPuLYrePtEkUcIKAAAqyk"]
[Tue Jul 21 08:52:16.556070 2026] [security2:error] [pid 533360:tid 533550] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9dcHUPuLYrePtEkUcIKQAAAL4"]
[Tue Jul 21 08:52:16.569988 2026] [security2:error] [pid 533360:tid 533498] [client 203.25.124.3:54545] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-crom.php"] [unique_id "al9dcHUPuLYrePtEkUcIKgAAAIo"]
[Tue Jul 21 08:52:16.633844 2026] [security2:error] [pid 533360:tid 533612] [client 34.168.88.184:58135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.88.168.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dcHUPuLYrePtEkUcILAAAAPw"]
[Tue Jul 21 08:52:16.633972 2026] [security2:error] [pid 533360:tid 533612] [client 34.168.88.184:58135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "efrelectronics.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dcHUPuLYrePtEkUcILAAAAPw"]
[Tue Jul 21 08:52:16.737490 2026] [security2:error] [pid 533360:tid 533609] [client 103.59.206.240:31512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dcHUPuLYrePtEkUcILgAAAPk"]
[Tue Jul 21 08:52:16.738093 2026] [security2:error] [pid 533360:tid 533609] [client 103.59.206.240:31512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dcHUPuLYrePtEkUcILgAAAPk"]
[Tue Jul 21 08:52:16.817840 2026] [security2:error] [pid 533360:tid 533495] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9dcHUPuLYrePtEkUcIMAAAAIc"]
[Tue Jul 21 08:52:16.852691 2026] [security2:error] [pid 533360:tid 533608] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9dcHUPuLYrePtEkUcIMgAAAPg"]
[Tue Jul 21 08:52:16.918175 2026] [security2:error] [pid 533360:tid 533606] [client 20.220.225.223:48239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/2x.php"] [unique_id "al9dcHUPuLYrePtEkUcINAAAAPY"]
[Tue Jul 21 08:52:16.931012 2026] [security2:error] [pid 533360:tid 533411] [remote 104.207.45.56:50507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.45.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9dcHUPuLYrePtEkUcILwAAvy8"]
[Tue Jul 21 08:52:17.081420 2026] [security2:error] [pid 533360:tid 533543] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9dcXUPuLYrePtEkUcIPgAAALc"]
[Tue Jul 21 08:52:17.122765 2026] [security2:error] [pid 533360:tid 533569] [client 20.197.192.193:27082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-wpbak.php"] [unique_id "al9dcXUPuLYrePtEkUcIPwAAANE"]
[Tue Jul 21 08:52:17.142956 2026] [security2:error] [pid 533360:tid 533523] [client 203.25.124.57:46519] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/css/as.php"] [unique_id "al9dcXUPuLYrePtEkUcIQAAAAKM"]
[Tue Jul 21 08:52:17.156431 2026] [security2:error] [pid 533360:tid 533583] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9dcXUPuLYrePtEkUcIQQAAAN8"]
[Tue Jul 21 08:52:17.332495 2026] [security2:error] [pid 533360:tid 533529] [client 65.21.113.253:55902] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dcHUPuLYrePtEkUcINQAAAKk"]
[Tue Jul 21 08:52:17.359439 2026] [security2:error] [pid 533360:tid 533611] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9dcXUPuLYrePtEkUcIQwAAAPs"]
[Tue Jul 21 08:52:17.430461 2026] [security2:error] [pid 533360:tid 533518] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9dcXUPuLYrePtEkUcIRAAAAJ4"]
[Tue Jul 21 08:52:17.573933 2026] [security2:error] [pid 533360:tid 533582] [client 20.104.96.117:61703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/output.php"] [unique_id "al9dcXUPuLYrePtEkUcITgAAAN4"]
[Tue Jul 21 08:52:17.582675 2026] [autoindex:error] [pid 533360:tid 533364] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home4/serric15/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:52:17.622321 2026] [security2:error] [pid 533360:tid 533522] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9dcXUPuLYrePtEkUcIUAAAAKI"]
[Tue Jul 21 08:52:17.687742 2026] [security2:error] [pid 533360:tid 533609] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9dcXUPuLYrePtEkUcIVQAAAPk"]
[Tue Jul 21 08:52:17.712774 2026] [security2:error] [pid 533360:tid 533410] [remote 130.51.180.8:46880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiapleno.com"] [uri "/wp-login.php"] [unique_id "al9dcXUPuLYrePtEkUcIVgAAiy4"]
[Tue Jul 21 08:52:17.871483 2026] [security2:error] [pid 533360:tid 533541] [client 203.25.124.6:62439] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9dcXUPuLYrePtEkUcIXgAAALU"]
[Tue Jul 21 08:52:17.890996 2026] [security2:error] [pid 533360:tid 533513] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9dcXUPuLYrePtEkUcIXwAAAJk"]
[Tue Jul 21 08:52:17.965449 2026] [security2:error] [pid 533360:tid 533549] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9dcXUPuLYrePtEkUcIYAAAAL0"]
[Tue Jul 21 08:52:18.178004 2026] [security2:error] [pid 533360:tid 533510] [client 182.189.99.211:48376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dcnUPuLYrePtEkUcIbgAAAJY"]
[Tue Jul 21 08:52:18.178129 2026] [security2:error] [pid 533360:tid 533510] [client 182.189.99.211:48376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dcnUPuLYrePtEkUcIbgAAAJY"]
[Tue Jul 21 08:52:18.288381 2026] [security2:error] [pid 533360:tid 533591] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9dcnUPuLYrePtEkUcIdAAAAOc"]
[Tue Jul 21 08:52:18.367893 2026] [security2:error] [pid 533360:tid 533532] [client 20.220.225.223:6104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/pn.php"] [unique_id "al9dcnUPuLYrePtEkUcIeAAAAKw"]
[Tue Jul 21 08:52:18.495632 2026] [security2:error] [pid 533360:tid 533435] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dcnUPuLYrePtEkUcIfgAAtEc"]
[Tue Jul 21 08:52:18.495792 2026] [security2:error] [pid 533360:tid 533540] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dcnUPuLYrePtEkUcIfgAAtEc"]
[Tue Jul 21 08:52:18.601332 2026] [security2:error] [pid 533360:tid 533612] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9dcnUPuLYrePtEkUcIhAAAAPw"]
[Tue Jul 21 08:52:18.612808 2026] [security2:error] [pid 533360:tid 533509] [client 203.25.124.57:63911] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/home-link/wp-login.php"] [unique_id "al9dcnUPuLYrePtEkUcIegAAAJU"]
[Tue Jul 21 08:52:18.735146 2026] [security2:error] [pid 533360:tid 533546] [client 20.104.96.117:46753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-file-120.php"] [unique_id "al9dcnUPuLYrePtEkUcIhQAAALo"]
[Tue Jul 21 08:52:19.034670 2026] [security2:error] [pid 533360:tid 533406] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dc3UPuLYrePtEkUcIkAABASo"]
[Tue Jul 21 08:52:19.034970 2026] [security2:error] [pid 533360:tid 533617] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dc3UPuLYrePtEkUcIkAABASo"]
[Tue Jul 21 08:52:19.067658 2026] [security2:error] [pid 533360:tid 533530] [client 136.108.12.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sobradoimoveis.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9dc3UPuLYrePtEkUcIkgAAAKo"]
[Tue Jul 21 08:52:19.075192 2026] [security2:error] [pid 533360:tid 533531] [client 203.25.124.254:38881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/click.php"] [unique_id "al9dc3UPuLYrePtEkUcIkwAAAKs"]
[Tue Jul 21 08:52:19.226592 2026] [security2:error] [pid 533360:tid 533573] [client 20.220.225.223:6098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wp-wpbak.php"] [unique_id "al9dc3UPuLYrePtEkUcIlgAAANU"]
[Tue Jul 21 08:52:19.323122 2026] [security2:error] [pid 533360:tid 533613] [client 20.197.192.193:27095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/dr.php"] [unique_id "al9dc3UPuLYrePtEkUcImAAAAP0"]
[Tue Jul 21 08:52:19.525334 2026] [security2:error] [pid 533360:tid 533568] [client 20.220.225.223:19298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/nhvoanpl.php"] [unique_id "al9dc3UPuLYrePtEkUcIpAAAANA"]
[Tue Jul 21 08:52:19.620908 2026] [security2:error] [pid 533360:tid 533448] [remote 65.111.7.78:27259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.7.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9dc3UPuLYrePtEkUcIngAAwlQ"]
[Tue Jul 21 08:52:19.631134 2026] [security2:error] [pid 533360:tid 533614] [client 20.197.192.193:27143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/2x.php"] [unique_id "al9dc3UPuLYrePtEkUcIqAAAAP4"]
[Tue Jul 21 08:52:19.866741 2026] [security2:error] [pid 533360:tid 533517] [client 20.104.96.117:61147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/for.php"] [unique_id "al9dc3UPuLYrePtEkUcIsQAAAJ0"]
[Tue Jul 21 08:52:19.961202 2026] [security2:error] [pid 533360:tid 533451] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/.well-known/about.php"] [unique_id "al9dc3UPuLYrePtEkUcIswAA0Vc"]
[Tue Jul 21 08:52:19.981012 2026] [security2:error] [pid 533360:tid 533454] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9dc3UPuLYrePtEkUcItAAAplo"]
[Tue Jul 21 08:52:19.999372 2026] [security2:error] [pid 533360:tid 533462] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/wefile.php"] [unique_id "al9dc3UPuLYrePtEkUcItQAAp2I"]
[Tue Jul 21 08:52:20.179146 2026] [security2:error] [pid 533360:tid 533497] [client 65.21.113.253:58260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9ddHUPuLYrePtEkUcIvgAAAIk"]
[Tue Jul 21 08:52:20.265677 2026] [security2:error] [pid 533360:tid 533518] [client 203.25.124.251:45455] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/byp.php"] [unique_id "al9ddHUPuLYrePtEkUcIwAAAAJ4"]
[Tue Jul 21 08:52:20.504294 2026] [access_compat:error] [pid 533360:tid 533498] [client 162.241.63.68:47478] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:52:20.621576 2026] [security2:error] [pid 533360:tid 533500] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9ddHUPuLYrePtEkUcIygAAjG4"]
[Tue Jul 21 08:52:20.832050 2026] [core:alert] [pid 533360:tid 533593] [client 57.141.18.37:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:52:21.241199 2026] [security2:error] [pid 533360:tid 533591] [client 203.25.124.50:53427] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/fix/admin.php"] [unique_id "al9ddXUPuLYrePtEkUcI7gAAAOc"]
[Tue Jul 21 08:52:21.281443 2026] [security2:error] [pid 533360:tid 533529] [client 203.25.124.7:38309] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/ateprivacy-policy-guide.php"] [unique_id "al9ddXUPuLYrePtEkUcI8QAAAKk"]
[Tue Jul 21 08:52:21.299787 2026] [security2:error] [pid 533360:tid 533563] [client 65.21.113.253:41182] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ddHUPuLYrePtEkUcI4QAAAMs"]
[Tue Jul 21 08:52:21.455971 2026] [security2:error] [pid 533360:tid 533578] [client 173.252.95.27:32962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ddXUPuLYrePtEkUcI-AAAANo"]
[Tue Jul 21 08:52:21.508673 2026] [security2:error] [pid 533360:tid 533570] [client 213.152.162.15:50070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9ddXUPuLYrePtEkUcI-QAAANI"]
[Tue Jul 21 08:52:21.508830 2026] [security2:error] [pid 533360:tid 533570] [client 213.152.162.15:50070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9ddXUPuLYrePtEkUcI-QAAANI"]
[Tue Jul 21 08:52:21.646431 2026] [security2:error] [pid 533360:tid 533597] [client 20.197.192.193:27089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/kq1.php"] [unique_id "al9ddXUPuLYrePtEkUcJBAAAAO0"]
[Tue Jul 21 08:52:21.726953 2026] [security2:error] [pid 533360:tid 533606] [client 59.95.197.55:59716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ddXUPuLYrePtEkUcJBQAAAPY"]
[Tue Jul 21 08:52:21.727487 2026] [security2:error] [pid 533360:tid 533606] [client 59.95.197.55:59716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ddXUPuLYrePtEkUcJBQAAAPY"]
[Tue Jul 21 08:52:21.922732 2026] [security2:error] [pid 533360:tid 533478] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ddXUPuLYrePtEkUcJCQAA9XI"]
[Tue Jul 21 08:52:21.922939 2026] [security2:error] [pid 533360:tid 533605] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ddXUPuLYrePtEkUcJCQAA9XI"]
[Tue Jul 21 08:52:21.948780 2026] [security2:error] [pid 533360:tid 533574] [client 122.176.100.127:61501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ddXUPuLYrePtEkUcJCgAAANY"]
[Tue Jul 21 08:52:21.948922 2026] [security2:error] [pid 533360:tid 533574] [client 122.176.100.127:61501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9ddXUPuLYrePtEkUcJCgAAANY"]
[Tue Jul 21 08:52:22.026981 2026] [security2:error] [pid 533360:tid 533495] [client 114.198.138.124:54295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9ddnUPuLYrePtEkUcJFAAAAIc"]
[Tue Jul 21 08:52:22.027090 2026] [security2:error] [pid 533360:tid 533495] [client 114.198.138.124:54295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9ddnUPuLYrePtEkUcJFAAAAIc"]
[Tue Jul 21 08:52:22.373862 2026] [security2:error] [pid 533360:tid 533591] [client 203.25.124.209:64523] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "al9ddnUPuLYrePtEkUcJHwAAAOc"]
[Tue Jul 21 08:52:22.558124 2026] [security2:error] [pid 533360:tid 533611] [client 20.104.96.117:60832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/special.php"] [unique_id "al9ddnUPuLYrePtEkUcJJAAAAPs"]
[Tue Jul 21 08:52:22.600764 2026] [security2:error] [pid 533360:tid 533547] [client 113.22.144.139:61053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ddnUPuLYrePtEkUcJJQAAALs"]
[Tue Jul 21 08:52:22.601503 2026] [security2:error] [pid 533360:tid 533547] [client 113.22.144.139:61053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ddnUPuLYrePtEkUcJJQAAALs"]
[Tue Jul 21 08:52:22.713065 2026] [security2:error] [pid 533360:tid 533532] [client 173.252.95.33:42308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9ddnUPuLYrePtEkUcJLwAAAKw"]
[Tue Jul 21 08:52:22.920095 2026] [security2:error] [pid 533360:tid 533449] [remote 130.185.118.215:45084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ddnUPuLYrePtEkUcJNgAAklU"]
[Tue Jul 21 08:52:22.944855 2026] [security2:error] [pid 533360:tid 533606] [client 203.25.124.211:56451] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/fix/ioxi-o.php"] [unique_id "al9ddnUPuLYrePtEkUcJNwAAAPY"]
[Tue Jul 21 08:52:23.226300 2026] [security2:error] [pid 533360:tid 533368] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9dd3UPuLYrePtEkUcJRgAAugQ"]
[Tue Jul 21 08:52:23.279358 2026] [security2:error] [pid 533360:tid 533495] [client 20.220.225.223:23477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/dr.php"] [unique_id "al9dd3UPuLYrePtEkUcJRwAAAIc"]
[Tue Jul 21 08:52:23.299963 2026] [autoindex:error] [pid 533360:tid 533399] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home4/serric15/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:52:23.351483 2026] [security2:error] [pid 533360:tid 533461] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dd3UPuLYrePtEkUcJSgAAqmE"]
[Tue Jul 21 08:52:23.351633 2026] [security2:error] [pid 533360:tid 533530] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dd3UPuLYrePtEkUcJSgAAqmE"]
[Tue Jul 21 08:52:23.385291 2026] [autoindex:error] [pid 533360:tid 533484] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home4/serric15/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:52:23.407794 2026] [security2:error] [pid 533360:tid 533378] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9dd3UPuLYrePtEkUcJTQAAtQ4"]
[Tue Jul 21 08:52:23.443400 2026] [security2:error] [pid 533360:tid 533404] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/8.php"] [unique_id "al9dd3UPuLYrePtEkUcJTgAA8Cg"]
[Tue Jul 21 08:52:23.465585 2026] [security2:error] [pid 533360:tid 533402] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9dd3UPuLYrePtEkUcJTwAAuCY"]
[Tue Jul 21 08:52:23.951235 2026] [security2:error] [pid 533360:tid 533412] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/f6.php"] [unique_id "al9dd3UPuLYrePtEkUcJZAAAozA"]
[Tue Jul 21 08:52:23.997720 2026] [security2:error] [pid 533360:tid 533415] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/inputs.php"] [unique_id "al9dd3UPuLYrePtEkUcJZQAAijM"]
[Tue Jul 21 08:52:24.017541 2026] [security2:error] [pid 533360:tid 533376] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/inputs.php"] [unique_id "al9deHUPuLYrePtEkUcJZgAA_ww"]
[Tue Jul 21 08:52:24.030918 2026] [security2:error] [pid 533360:tid 533550] [client 212.32.76.8:60261] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/ioxi-o.php"] [unique_id "al9deHUPuLYrePtEkUcJZwAAAL4"]
[Tue Jul 21 08:52:24.039220 2026] [security2:error] [pid 533360:tid 533395] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/classwithtostring.php"] [unique_id "al9deHUPuLYrePtEkUcJaAAAzx8"]
[Tue Jul 21 08:52:24.056279 2026] [security2:error] [pid 533360:tid 533469] [remote 4.205.168.44:34304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9deHUPuLYrePtEkUcJagAArGk"]
[Tue Jul 21 08:52:24.128852 2026] [security2:error] [pid 533360:tid 533418] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9deHUPuLYrePtEkUcJbAABAzY"]
[Tue Jul 21 08:52:24.149580 2026] [security2:error] [pid 533360:tid 533364] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/wp-blog.php"] [unique_id "al9deHUPuLYrePtEkUcJbQAAsgA"]
[Tue Jul 21 08:52:24.168921 2026] [security2:error] [pid 533360:tid 533562] [client 213.152.162.15:41114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9deHUPuLYrePtEkUcJbgAAAMo"]
[Tue Jul 21 08:52:24.169019 2026] [security2:error] [pid 533360:tid 533562] [client 213.152.162.15:41114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9deHUPuLYrePtEkUcJbgAAAMo"]
[Tue Jul 21 08:52:24.588135 2026] [security2:error] [pid 533360:tid 533612] [client 45.132.227.199:41499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.227.132.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9deHUPuLYrePtEkUcJfwAAAPw"]
[Tue Jul 21 08:52:24.590237 2026] [security2:error] [pid 533360:tid 533583] [client 185.251.19.59:24739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9deHUPuLYrePtEkUcJgAAAAN8"]
[Tue Jul 21 08:52:24.592504 2026] [security2:error] [pid 533360:tid 533545] [client 185.251.19.59:32679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drapatriciavarella.com.br"] [uri "/wp-login.php"] [unique_id "al9deHUPuLYrePtEkUcJgQAAALk"]
[Tue Jul 21 08:52:24.597032 2026] [autoindex:error] [pid 533360:tid 533389] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home4/serric15/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:52:24.638401 2026] [security2:error] [pid 533360:tid 533546] [client 20.220.225.223:19666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/inso.php"] [unique_id "al9deHUPuLYrePtEkUcJgwAAALo"]
[Tue Jul 21 08:52:24.642066 2026] [security2:error] [pid 533360:tid 533430] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9deHUPuLYrePtEkUcJhAAAmEI"]
[Tue Jul 21 08:52:24.689541 2026] [security2:error] [pid 533360:tid 533409] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/ms-edit.php"] [unique_id "al9deHUPuLYrePtEkUcJiAAA1y0"]
[Tue Jul 21 08:52:24.731938 2026] [security2:error] [pid 533360:tid 533434] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9deHUPuLYrePtEkUcJigABAEY"]
[Tue Jul 21 08:52:24.771062 2026] [autoindex:error] [pid 533360:tid 533417] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home4/serric15/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:52:24.824082 2026] [security2:error] [pid 533360:tid 533424] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9deHUPuLYrePtEkUcJkAAApjw"]
[Tue Jul 21 08:52:25.049274 2026] [security2:error] [pid 533360:tid 533547] [client 203.25.124.207:50051] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/bltm/wp-login.php"] [unique_id "al9deHUPuLYrePtEkUcJlwAAALs"]
[Tue Jul 21 08:52:25.164063 2026] [security2:error] [pid 533360:tid 533532] [client 65.21.113.253:58260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9deXUPuLYrePtEkUcJngAAAKw"]
[Tue Jul 21 08:52:25.263922 2026] [security2:error] [pid 533360:tid 533566] [client 20.220.225.223:23458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/2x.php"] [unique_id "al9deXUPuLYrePtEkUcJpQAAAM4"]
[Tue Jul 21 08:52:25.265716 2026] [security2:error] [pid 533360:tid 533607] [client 168.167.81.163:61130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9deXUPuLYrePtEkUcJpAAAAPc"]
[Tue Jul 21 08:52:25.265831 2026] [security2:error] [pid 533360:tid 533607] [client 168.167.81.163:61130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9deXUPuLYrePtEkUcJpAAAAPc"]
[Tue Jul 21 08:52:25.310904 2026] [security2:error] [pid 533360:tid 533506] [client 20.197.192.193:58451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9deXUPuLYrePtEkUcJqAAAAJI"]
[Tue Jul 21 08:52:25.321792 2026] [security2:error] [pid 533360:tid 533518] [client 20.197.192.193:58462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9deXUPuLYrePtEkUcJqgAAAJ4"]
[Tue Jul 21 08:52:25.332641 2026] [security2:error] [pid 533360:tid 533584] [client 20.197.192.193:58223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/dp.php"] [unique_id "al9deXUPuLYrePtEkUcJqwAAAOA"]
[Tue Jul 21 08:52:25.357605 2026] [security2:error] [pid 533360:tid 533568] [client 20.197.192.193:56401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/old.php"] [unique_id "al9deXUPuLYrePtEkUcJrAAAANA"]
[Tue Jul 21 08:52:25.370331 2026] [security2:error] [pid 533360:tid 533594] [client 20.197.192.193:58179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/ms-new.php"] [unique_id "al9deXUPuLYrePtEkUcJrQAAAOo"]
[Tue Jul 21 08:52:25.383023 2026] [security2:error] [pid 533360:tid 533605] [client 20.197.192.193:56447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/track.php"] [unique_id "al9deXUPuLYrePtEkUcJrgAAAPU"]
[Tue Jul 21 08:52:25.406531 2026] [security2:error] [pid 533360:tid 533593] [client 20.197.192.193:58220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/2352356666.php"] [unique_id "al9deXUPuLYrePtEkUcJsAAAAOk"]
[Tue Jul 21 08:52:25.420394 2026] [security2:error] [pid 533360:tid 533565] [client 20.197.192.193:58211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/pn.php"] [unique_id "al9deXUPuLYrePtEkUcJsQAAAM0"]
[Tue Jul 21 08:52:25.437846 2026] [security2:error] [pid 533360:tid 533511] [client 20.197.192.193:56393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9deXUPuLYrePtEkUcJsgAAAJc"]
[Tue Jul 21 08:52:25.461062 2026] [security2:error] [pid 533360:tid 533583] [client 20.197.192.193:49573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/dr.php"] [unique_id "al9deXUPuLYrePtEkUcJswAAAN8"]
[Tue Jul 21 08:52:25.495459 2026] [security2:error] [pid 533360:tid 533545] [client 20.197.192.193:27091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/zzz.php"] [unique_id "al9deXUPuLYrePtEkUcJtQAAALk"]
[Tue Jul 21 08:52:25.501672 2026] [security2:error] [pid 533360:tid 533589] [client 20.197.192.193:58487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/2x.php"] [unique_id "al9deXUPuLYrePtEkUcJtgAAAOU"]
[Tue Jul 21 08:52:25.537390 2026] [security2:error] [pid 533360:tid 533495] [client 20.197.192.193:58207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/kq1.php"] [unique_id "al9deXUPuLYrePtEkUcJuAAAAIc"]
[Tue Jul 21 08:52:25.571263 2026] [security2:error] [pid 533360:tid 533551] [client 20.197.192.193:40885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/zzz.php"] [unique_id "al9deXUPuLYrePtEkUcJuQAAAL8"]
[Tue Jul 21 08:52:25.592906 2026] [security2:error] [pid 533360:tid 533618] [client 20.197.192.193:58483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/wicked.php"] [unique_id "al9deXUPuLYrePtEkUcJugAAAQI"]
[Tue Jul 21 08:52:25.610013 2026] [security2:error] [pid 533360:tid 533579] [client 20.197.192.193:58492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/edit.php"] [unique_id "al9deXUPuLYrePtEkUcJuwAAANs"]
[Tue Jul 21 08:52:25.624321 2026] [security2:error] [pid 533360:tid 533599] [client 20.197.192.193:56384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/kua.php"] [unique_id "al9deXUPuLYrePtEkUcJvQAAAO8"]
[Tue Jul 21 08:52:25.638155 2026] [security2:error] [pid 533360:tid 533508] [client 20.197.192.193:58465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/ez.php"] [unique_id "al9deXUPuLYrePtEkUcJvgAAAJQ"]
[Tue Jul 21 08:52:25.650500 2026] [security2:error] [pid 533360:tid 533561] [client 20.197.192.193:58468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/fz.php"] [unique_id "al9deXUPuLYrePtEkUcJwAAAAMk"]
[Tue Jul 21 08:52:25.664149 2026] [security2:error] [pid 533360:tid 533516] [client 20.197.192.193:58189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/la.php"] [unique_id "al9deXUPuLYrePtEkUcJwQAAAJw"]
[Tue Jul 21 08:52:25.676682 2026] [security2:error] [pid 533360:tid 533502] [client 20.197.192.193:58479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9deXUPuLYrePtEkUcJwgAAAI4"]
[Tue Jul 21 08:52:25.711960 2026] [security2:error] [pid 533360:tid 533563] [client 20.197.192.193:58221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/inso.php"] [unique_id "al9deXUPuLYrePtEkUcJwwAAAMs"]
[Tue Jul 21 08:52:25.717423 2026] [security2:error] [pid 533360:tid 533552] [client 195.49.128.211:51464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9deXUPuLYrePtEkUcJxAAAAMA"]
[Tue Jul 21 08:52:25.717529 2026] [security2:error] [pid 533360:tid 533552] [client 195.49.128.211:51464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9deXUPuLYrePtEkUcJxAAAAMA"]
[Tue Jul 21 08:52:25.730628 2026] [security2:error] [pid 533360:tid 533536] [client 212.32.76.9:43529] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wpx/index.php"] [unique_id "al9deXUPuLYrePtEkUcJxQAAALA"]
[Tue Jul 21 08:52:25.734678 2026] [security2:error] [pid 533360:tid 533510] [client 20.220.225.223:37574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/akismet.php"] [unique_id "al9deXUPuLYrePtEkUcJxgAAAJY"]
[Tue Jul 21 08:52:25.739306 2026] [security2:error] [pid 533360:tid 533559] [client 20.197.192.193:58433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/wpx.php"] [unique_id "al9deXUPuLYrePtEkUcJyQAAAMc"]
[Tue Jul 21 08:52:25.742808 2026] [security2:error] [pid 533360:tid 533598] [client 152.59.181.104:57788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9deXUPuLYrePtEkUcJyAAAAO4"]
[Tue Jul 21 08:52:25.742921 2026] [security2:error] [pid 533360:tid 533598] [client 152.59.181.104:57788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9deXUPuLYrePtEkUcJyAAAAO4"]
[Tue Jul 21 08:52:25.752458 2026] [security2:error] [pid 533360:tid 533601] [client 20.197.192.193:58203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/berlin.php"] [unique_id "al9deXUPuLYrePtEkUcJzAAAAPE"]
[Tue Jul 21 08:52:25.764082 2026] [security2:error] [pid 533360:tid 533596] [client 20.197.192.193:56439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/billur.php"] [unique_id "al9deXUPuLYrePtEkUcJzQAAAOw"]
[Tue Jul 21 08:52:25.794696 2026] [security2:error] [pid 533360:tid 533542] [client 20.197.192.193:58480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/mimpi.php"] [unique_id "al9deXUPuLYrePtEkUcJzgAAALY"]
[Tue Jul 21 08:52:25.810086 2026] [security2:error] [pid 533360:tid 533619] [client 20.197.192.193:56445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/dp.php"] [unique_id "al9deXUPuLYrePtEkUcJzwAAAQM"]
[Tue Jul 21 08:52:25.820486 2026] [security2:error] [pid 533360:tid 533534] [client 20.197.192.193:56443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/bootstrap.php"] [unique_id "al9deXUPuLYrePtEkUcJ0gAAAK4"]
[Tue Jul 21 08:52:25.833079 2026] [security2:error] [pid 533360:tid 533566] [client 20.197.192.193:58450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/wp-editor.php"] [unique_id "al9deXUPuLYrePtEkUcJ1AAAAM4"]
[Tue Jul 21 08:52:25.855798 2026] [security2:error] [pid 533360:tid 533506] [client 20.197.192.193:58447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/cro.php"] [unique_id "al9deXUPuLYrePtEkUcJ1wAAAJI"]
[Tue Jul 21 08:52:25.877636 2026] [security2:error] [pid 533360:tid 533509] [client 20.197.192.193:58481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/cron-tab.php"] [unique_id "al9deXUPuLYrePtEkUcJ2AAAAJU"]
[Tue Jul 21 08:52:25.889130 2026] [autoindex:error] [pid 533360:tid 533400] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home4/serric15/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:52:25.891131 2026] [security2:error] [pid 533360:tid 533504] [client 20.197.192.193:58208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/koiy.php"] [unique_id "al9deXUPuLYrePtEkUcJ2gAAAJA"]
[Tue Jul 21 08:52:25.923193 2026] [security2:error] [pid 533360:tid 533568] [client 20.197.192.193:56396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/hp2.php"] [unique_id "al9deXUPuLYrePtEkUcJ2wAAANA"]
[Tue Jul 21 08:52:25.940880 2026] [authz_core:error] [pid 533360:tid 533456] [remote 20.197.195.24:0] AH01630: client denied by server configuration: /home4/serric15/public_html/wp-content/uploads/index.php
[Tue Jul 21 08:52:25.942672 2026] [security2:error] [pid 533360:tid 533605] [client 20.197.192.193:58434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/hp3.php"] [unique_id "al9deXUPuLYrePtEkUcJ3QAAAPU"]
[Tue Jul 21 08:52:25.961045 2026] [security2:error] [pid 533360:tid 533533] [client 20.197.192.193:58491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/aa1.php"] [unique_id "al9deXUPuLYrePtEkUcJ4AAAAK0"]
[Tue Jul 21 08:52:25.967622 2026] [security2:error] [pid 533360:tid 533448] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/abcd.php"] [unique_id "al9deXUPuLYrePtEkUcJ4QAAuFQ"]
[Tue Jul 21 08:52:25.976332 2026] [security2:error] [pid 533360:tid 533597] [client 20.197.192.193:56418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/acew67.php"] [unique_id "al9deXUPuLYrePtEkUcJ4gAAAO0"]
[Tue Jul 21 08:52:25.976868 2026] [security2:error] [pid 533360:tid 533593] [client 20.104.96.117:4061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/as.php"] [unique_id "al9deXUPuLYrePtEkUcJ4wAAAOk"]
[Tue Jul 21 08:52:25.989401 2026] [security2:error] [pid 533360:tid 533560] [client 20.197.192.193:58188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/bscclapb.php"] [unique_id "al9deXUPuLYrePtEkUcJ5AAAAMg"]
[Tue Jul 21 08:52:26.007320 2026] [security2:error] [pid 533360:tid 533577] [client 20.197.192.193:58454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/else1.php"] [unique_id "al9denUPuLYrePtEkUcJ5gAAANk"]
[Tue Jul 21 08:52:26.025359 2026] [security2:error] [pid 533360:tid 533589] [client 20.197.192.193:56423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/tkikikoko.php"] [unique_id "al9denUPuLYrePtEkUcJ5wAAAOU"]
[Tue Jul 21 08:52:26.043860 2026] [security2:error] [pid 533360:tid 533546] [client 20.197.192.193:58467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9denUPuLYrePtEkUcJ6AAAALo"]
[Tue Jul 21 08:52:26.057610 2026] [security2:error] [pid 533360:tid 533495] [client 20.197.192.193:58210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/wp-css.php"] [unique_id "al9denUPuLYrePtEkUcJ6QAAAIc"]
[Tue Jul 21 08:52:26.072005 2026] [security2:error] [pid 533360:tid 533541] [client 20.197.192.193:56427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/wp-explorer.php"] [unique_id "al9denUPuLYrePtEkUcJ6gAAALU"]
[Tue Jul 21 08:52:26.078736 2026] [security2:error] [pid 533360:tid 533549] [client 185.117.225.17:59014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "serbetoadv.com"] [uri "/robots.txt"] [unique_id "al9denUPuLYrePtEkUcJ6wAAAL0"]
[Tue Jul 21 08:52:26.091231 2026] [security2:error] [pid 533360:tid 533558] [client 20.197.192.193:58200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/akismet.php"] [unique_id "al9denUPuLYrePtEkUcJ7AAAAMY"]
[Tue Jul 21 08:52:26.113986 2026] [security2:error] [pid 533360:tid 533524] [client 20.197.192.193:58183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/ace2.php"] [unique_id "al9denUPuLYrePtEkUcJ7QAAAKQ"]
[Tue Jul 21 08:52:26.138633 2026] [security2:error] [pid 533360:tid 533564] [client 20.197.192.193:40834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "azusacorretora.com.br"] [uri "/ms.php"] [unique_id "al9denUPuLYrePtEkUcJ7gAAAMw"]
[Tue Jul 21 08:52:26.226331 2026] [security2:error] [pid 533360:tid 533520] [client 5.38.115.39:50176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9denUPuLYrePtEkUcJ8AAAAKA"]
[Tue Jul 21 08:52:26.226470 2026] [security2:error] [pid 533360:tid 533520] [client 5.38.115.39:50176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9denUPuLYrePtEkUcJ8AAAAKA"]
[Tue Jul 21 08:52:26.276082 2026] [security2:error] [pid 533360:tid 533616] [client 65.21.113.253:41188] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9deXUPuLYrePtEkUcJ1QAAAQA"]
[Tue Jul 21 08:52:26.299369 2026] [security2:error] [pid 533360:tid 533543] [client 20.220.225.223:19326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wpx.php"] [unique_id "al9denUPuLYrePtEkUcJ9AAAALc"]
[Tue Jul 21 08:52:26.473713 2026] [security2:error] [pid 533360:tid 533586] [client 203.25.124.199:37765] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/includes/nav.php"] [unique_id "al9denUPuLYrePtEkUcJ-QAAAOI"]
[Tue Jul 21 08:52:26.511225 2026] [security2:error] [pid 533360:tid 533569] [client 20.151.10.161:49124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9denUPuLYrePtEkUcJ-gAAANE"]
[Tue Jul 21 08:52:26.772135 2026] [security2:error] [pid 533360:tid 533602] [client 41.89.234.2:62645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9denUPuLYrePtEkUcKBAAAAPI"]
[Tue Jul 21 08:52:26.772285 2026] [security2:error] [pid 533360:tid 533602] [client 41.89.234.2:62645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9denUPuLYrePtEkUcKBAAAAPI"]
[Tue Jul 21 08:52:26.894467 2026] [security2:error] [pid 533360:tid 533464] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/file15.php"] [unique_id "al9denUPuLYrePtEkUcKCgABA2Q"]
[Tue Jul 21 08:52:27.019174 2026] [security2:error] [pid 533360:tid 533437] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9de3UPuLYrePtEkUcKCwAAikk"]
[Tue Jul 21 08:52:27.019382 2026] [security2:error] [pid 533360:tid 533498] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9de3UPuLYrePtEkUcKCwAAikk"]
[Tue Jul 21 08:52:27.039007 2026] [security2:error] [pid 533360:tid 533518] [client 203.25.124.211:34117] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-matcha1.php"] [unique_id "al9de3UPuLYrePtEkUcKDAAAAJ4"]
[Tue Jul 21 08:52:27.158943 2026] [core:error] [pid 533360:tid 533528] [client 66.249.66.67:47092] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:52:27.158963 2026] [core:error] [pid 533360:tid 533528] [client 66.249.66.67:47092] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:52:27.216009 2026] [security2:error] [pid 533360:tid 533553] [client 20.220.225.223:52189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/kq1.php"] [unique_id "al9de3UPuLYrePtEkUcKEgAAAME"]
[Tue Jul 21 08:52:27.261186 2026] [security2:error] [pid 533360:tid 533606] [client 20.220.225.223:19270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/berlin.php"] [unique_id "al9de3UPuLYrePtEkUcKFAAAAPY"]
[Tue Jul 21 08:52:27.280577 2026] [security2:error] [pid 533360:tid 533535] [client 203.25.124.204:39247] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/shell3.php"] [unique_id "al9de3UPuLYrePtEkUcKFgAAAK8"]
[Tue Jul 21 08:52:27.347528 2026] [security2:error] [pid 533360:tid 533506] [client 49.144.66.253:32939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9de3UPuLYrePtEkUcKGQAAAJI"]
[Tue Jul 21 08:52:27.347649 2026] [security2:error] [pid 533360:tid 533506] [client 49.144.66.253:32939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9de3UPuLYrePtEkUcKGQAAAJI"]
[Tue Jul 21 08:52:27.668228 2026] [security2:error] [pid 533360:tid 533397] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/jp.php"] [unique_id "al9de3UPuLYrePtEkUcKHgAA1yE"]
[Tue Jul 21 08:52:28.041152 2026] [security2:error] [pid 533360:tid 533540] [client 212.32.76.13:25889] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwenty/assets/js/index.php"] [unique_id "al9dfHUPuLYrePtEkUcKLAAAALQ"]
[Tue Jul 21 08:52:28.168045 2026] [security2:error] [pid 533360:tid 533438] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/f35.php"] [unique_id "al9dfHUPuLYrePtEkUcKMQAA0Uo"]
[Tue Jul 21 08:52:28.188213 2026] [security2:error] [pid 533360:tid 533489] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/wp-load.php"] [unique_id "al9dfHUPuLYrePtEkUcKMgAAkX0"]
[Tue Jul 21 08:52:28.202007 2026] [security2:error] [pid 533360:tid 533580] [client 20.151.10.161:49134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9dfHUPuLYrePtEkUcKMwAAANw"]
[Tue Jul 21 08:52:28.211153 2026] [security2:error] [pid 533360:tid 533445] [remote 100.42.189.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9dfHUPuLYrePtEkUcKNAAAm1E"]
[Tue Jul 21 08:52:28.329036 2026] [security2:error] [pid 533360:tid 533595] [client 20.197.192.193:27197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wicked.php"] [unique_id "al9dfHUPuLYrePtEkUcKOQAAAOs"]
[Tue Jul 21 08:52:28.505965 2026] [security2:error] [pid 533360:tid 533521] [client 20.220.225.223:23449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/zzz.php"] [unique_id "al9dfHUPuLYrePtEkUcKQQAAAKE"]
[Tue Jul 21 08:52:28.528607 2026] [security2:error] [pid 533360:tid 533608] [client 20.220.225.223:43185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/ace2.php"] [unique_id "al9dfHUPuLYrePtEkUcKQwAAAPg"]
[Tue Jul 21 08:52:28.680845 2026] [security2:error] [pid 533360:tid 533504] [client 203.25.124.199:46345] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/hplfuns.php"] [unique_id "al9dfHUPuLYrePtEkUcKSQAAAJA"]
[Tue Jul 21 08:52:28.688761 2026] [security2:error] [pid 533360:tid 533570] [client 182.189.99.211:48241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dfHUPuLYrePtEkUcKSgAAANI"]
[Tue Jul 21 08:52:28.688950 2026] [security2:error] [pid 533360:tid 533570] [client 182.189.99.211:48241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dfHUPuLYrePtEkUcKSgAAANI"]
[Tue Jul 21 08:52:29.003769 2026] [security2:error] [pid 533360:tid 533480] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/xyn.php"] [unique_id "al9dfXUPuLYrePtEkUcKVAAAsHQ"]
[Tue Jul 21 08:52:29.084827 2026] [security2:error] [pid 533360:tid 533458] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dfXUPuLYrePtEkUcKWQAAmF4"]
[Tue Jul 21 08:52:29.085082 2026] [security2:error] [pid 533360:tid 533512] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dfXUPuLYrePtEkUcKWQAAmF4"]
[Tue Jul 21 08:52:29.245190 2026] [security2:error] [pid 533360:tid 533575] [client 65.21.113.253:58260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dfXUPuLYrePtEkUcKXAAAANc"]
[Tue Jul 21 08:52:29.245388 2026] [security2:error] [pid 533360:tid 533541] [client 203.25.124.40:56323] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/dlex/dlex.php"] [unique_id "al9dfXUPuLYrePtEkUcKXQAAALU"]
[Tue Jul 21 08:52:29.270829 2026] [security2:error] [pid 533360:tid 533549] [client 20.104.96.117:59169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/ssla.php"] [unique_id "al9dfXUPuLYrePtEkUcKYAAAAL0"]
[Tue Jul 21 08:52:29.284328 2026] [security2:error] [pid 533360:tid 533524] [client 20.220.225.223:19674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/billur.php"] [unique_id "al9dfXUPuLYrePtEkUcKYQAAAKQ"]
[Tue Jul 21 08:52:29.377307 2026] [security2:error] [pid 533360:tid 533513] [client 203.25.124.191:48105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/admin/index.php"] [unique_id "al9dfXUPuLYrePtEkUcKZgAAAJk"]
[Tue Jul 21 08:52:29.607169 2026] [security2:error] [pid 533360:tid 533602] [client 20.151.10.161:49138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/x.php"] [unique_id "al9dfXUPuLYrePtEkUcKcQAAAPI"]
[Tue Jul 21 08:52:29.689753 2026] [security2:error] [pid 533360:tid 533365] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dfXUPuLYrePtEkUcKgAAA2gE"]
[Tue Jul 21 08:52:29.689975 2026] [security2:error] [pid 533360:tid 533578] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dfXUPuLYrePtEkUcKgAAA2gE"]
[Tue Jul 21 08:52:30.044651 2026] [security2:error] [pid 533360:tid 533584] [client 203.25.124.72:62707] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/view-source/ioxi-o.php"] [unique_id "al9dfnUPuLYrePtEkUcKjQAAAOA"]
[Tue Jul 21 08:52:30.333246 2026] [security2:error] [pid 533360:tid 533616] [client 65.21.113.253:60606] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dfXUPuLYrePtEkUcKiQAAAQA"]
[Tue Jul 21 08:52:30.535747 2026] [security2:error] [pid 533360:tid 533589] [client 20.197.192.193:27076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/edit.php"] [unique_id "al9dfnUPuLYrePtEkUcKoQAAAOU"]
[Tue Jul 21 08:52:30.577411 2026] [security2:error] [pid 533360:tid 533541] [client 212.32.76.64:50515] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/admin-wolf.php"] [unique_id "al9dfnUPuLYrePtEkUcKpAAAALU"]
[Tue Jul 21 08:52:30.773083 2026] [security2:error] [pid 533360:tid 533569] [client 20.220.225.223:23481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wicked.php"] [unique_id "al9dfnUPuLYrePtEkUcKrgAAANE"]
[Tue Jul 21 08:52:30.878572 2026] [security2:error] [pid 533360:tid 533609] [client 20.220.225.223:19278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/mimpi.php"] [unique_id "al9dfnUPuLYrePtEkUcKtwAAAPk"]
[Tue Jul 21 08:52:30.960104 2026] [autoindex:error] [pid 533360:tid 533436] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home4/serric15/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:52:30.996799 2026] [security2:error] [pid 533360:tid 533573] [client 198.44.157.34:46244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9dfnUPuLYrePtEkUcKygAAANU"]
[Tue Jul 21 08:52:30.996908 2026] [security2:error] [pid 533360:tid 533573] [client 198.44.157.34:46244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9dfnUPuLYrePtEkUcKygAAANU"]
[Tue Jul 21 08:52:31.064385 2026] [autoindex:error] [pid 533360:tid 533485] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home4/serric15/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:52:31.065323 2026] [security2:error] [pid 533360:tid 533421] [remote 47.128.43.216:54384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "essenceclinicadesaude.com.br"] [uri "/pj-categs/nutricao/"] [unique_id "al9df3UPuLYrePtEkUcKzQAAsjk"]
[Tue Jul 21 08:52:31.097917 2026] [security2:error] [pid 533360:tid 533383] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/ccc.php"] [unique_id "al9df3UPuLYrePtEkUcK-AAAxBM"]
[Tue Jul 21 08:52:31.145948 2026] [security2:error] [pid 533360:tid 533398] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/w.php"] [unique_id "al9df3UPuLYrePtEkUcK_AAAniI"]
[Tue Jul 21 08:52:31.158664 2026] [security2:error] [pid 533360:tid 533611] [client 20.151.10.161:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/j260624_13.php"] [unique_id "al9df3UPuLYrePtEkUcK_gAAAPs"]
[Tue Jul 21 08:52:31.212224 2026] [security2:error] [pid 533360:tid 533566] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9df3UPuLYrePtEkUcK_QAAznQ"]
[Tue Jul 21 08:52:31.242805 2026] [security2:error] [pid 533360:tid 533555] [client 212.32.76.12:47527] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/network/cache/index.php"] [unique_id "al9df3UPuLYrePtEkUcK_wAAAMM"]
[Tue Jul 21 08:52:31.390047 2026] [security2:error] [pid 533360:tid 533559] [client 20.104.96.117:46737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/cgi-bin/index.php"] [unique_id "al9df3UPuLYrePtEkUcLBQAAAMc"]
[Tue Jul 21 08:52:31.424823 2026] [security2:error] [pid 533360:tid 533520] [client 20.220.225.223:52185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/edit.php"] [unique_id "al9df3UPuLYrePtEkUcLCQAAAKA"]
[Tue Jul 21 08:52:31.697013 2026] [security2:error] [pid 533360:tid 533443] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9df3UPuLYrePtEkUcLDwAA7k8"]
[Tue Jul 21 08:52:31.773251 2026] [security2:error] [pid 533360:tid 533596] [client 203.25.124.198:32555] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "al9df3UPuLYrePtEkUcLEQAAAOw"]
[Tue Jul 21 08:52:31.836475 2026] [security2:error] [pid 533360:tid 533567] [client 168.167.81.163:61929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9df3UPuLYrePtEkUcLEgAAAM8"]
[Tue Jul 21 08:52:31.836599 2026] [security2:error] [pid 533360:tid 533567] [client 168.167.81.163:61929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9df3UPuLYrePtEkUcLEgAAAM8"]
[Tue Jul 21 08:52:31.980672 2026] [security2:error] [pid 533360:tid 533530] [client 20.220.225.223:35078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/ms.php"] [unique_id "al9df3UPuLYrePtEkUcLKQAAAKo"]
[Tue Jul 21 08:52:32.032879 2026] [security2:error] [pid 533360:tid 533542] [client 20.220.225.223:6109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/kua.php"] [unique_id "al9dgHUPuLYrePtEkUcLOQAAALY"]
[Tue Jul 21 08:52:32.202017 2026] [security2:error] [pid 533360:tid 533505] [client 59.95.197.55:60194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dgHUPuLYrePtEkUcLPgAAAJE"]
[Tue Jul 21 08:52:32.203020 2026] [security2:error] [pid 533360:tid 533505] [client 59.95.197.55:60194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dgHUPuLYrePtEkUcLPgAAAJE"]
[Tue Jul 21 08:52:32.216567 2026] [security2:error] [pid 533360:tid 533393] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/FWAZ.php"] [unique_id "al9dgHUPuLYrePtEkUcLQAAAzh0"]
[Tue Jul 21 08:52:32.463108 2026] [security2:error] [pid 533360:tid 533516] [client 122.176.100.127:61975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dgHUPuLYrePtEkUcLQgAAAJw"]
[Tue Jul 21 08:52:32.463245 2026] [security2:error] [pid 533360:tid 533516] [client 122.176.100.127:61975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dgHUPuLYrePtEkUcLQgAAAJw"]
[Tue Jul 21 08:52:32.472761 2026] [security2:error] [pid 533360:tid 533565] [client 114.198.138.124:54866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dgHUPuLYrePtEkUcLRAAAAM0"]
[Tue Jul 21 08:52:32.474309 2026] [security2:error] [pid 533360:tid 533565] [client 114.198.138.124:54866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dgHUPuLYrePtEkUcLRAAAAM0"]
[Tue Jul 21 08:52:32.624327 2026] [security2:error] [pid 533360:tid 533430] [remote 205.196.217.58:54672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.217.196.205.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiferreira.com.br"] [uri "/wp-login.php"] [unique_id "al9dgHUPuLYrePtEkUcLSAAAuUI"]
[Tue Jul 21 08:52:32.761391 2026] [security2:error] [pid 533360:tid 533422] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dgHUPuLYrePtEkUcLTQAA0Do"]
[Tue Jul 21 08:52:32.761632 2026] [security2:error] [pid 533360:tid 533568] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dgHUPuLYrePtEkUcLTQAA0Do"]
[Tue Jul 21 08:52:32.827237 2026] [proxy:error] [pid 533360:tid 533434] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:52:32.827269 2026] [proxy_http:error] [pid 533360:tid 533434] [remote 198.235.24.171:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:52:32.827730 2026] [proxy:error] [pid 533360:tid 533434] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:52:32.827752 2026] [proxy_http:error] [pid 533360:tid 533434] [remote 198.235.24.171:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:52:32.832499 2026] [security2:error] [pid 533360:tid 533512] [client 20.220.225.223:23427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/ez.php"] [unique_id "al9dgHUPuLYrePtEkUcLUQAAAJg"]
[Tue Jul 21 08:52:32.885935 2026] [security2:error] [pid 533360:tid 533541] [client 212.32.76.56:48455] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/2021/file.php"] [unique_id "al9dgHUPuLYrePtEkUcLVAAAALU"]
[Tue Jul 21 08:52:32.937192 2026] [security2:error] [pid 533360:tid 533606] [client 113.22.144.139:61549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dgHUPuLYrePtEkUcLVgAAAPY"]
[Tue Jul 21 08:52:32.939192 2026] [security2:error] [pid 533360:tid 533606] [client 113.22.144.139:61549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dgHUPuLYrePtEkUcLVgAAAPY"]
[Tue Jul 21 08:52:33.099753 2026] [security2:error] [pid 533360:tid 533432] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/miru1.php"] [unique_id "al9dgXUPuLYrePtEkUcLYAAA1EQ"]
[Tue Jul 21 08:52:33.239614 2026] [security2:error] [pid 533360:tid 533561] [client 203.25.124.31:24461] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/table/table/updater-tool.php"] [unique_id "al9dgXUPuLYrePtEkUcLbgAAAMk"]
[Tue Jul 21 08:52:33.801098 2026] [autoindex:error] [pid 533360:tid 533533] [client 54.164.167.77:44768] AH01276: Cannot serve directory /home2/prisse45/prissedermatologia.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:52:33.902850 2026] [security2:error] [pid 533360:tid 533498] [client 65.21.113.253:58260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dgXUPuLYrePtEkUcLggAAAIo"]
[Tue Jul 21 08:52:34.169314 2026] [security2:error] [pid 533360:tid 533494] [client 212.32.76.58:20857] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "al9dgnUPuLYrePtEkUcLiAAAAIY"]
[Tue Jul 21 08:52:34.196956 2026] [security2:error] [pid 533360:tid 533463] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/aa.php"] [unique_id "al9dgnUPuLYrePtEkUcLiQAAtWM"]
[Tue Jul 21 08:52:34.224346 2026] [security2:error] [pid 533360:tid 533610] [client 20.220.225.223:23448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/fz.php"] [unique_id "al9dgnUPuLYrePtEkUcLjAAAAPo"]
[Tue Jul 21 08:52:34.233037 2026] [security2:error] [pid 533360:tid 533528] [client 114.119.139.102:55301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "conhecaonordeste.com.br"] [uri "/trf1otrn/woman-killed-in-chesapeake-va"] [unique_id "al9dgnUPuLYrePtEkUcLjQAAAKg"], referer: https://conhecaonordeste.com.br/trf1otrn/woman-killed-in-chesapeake-va
[Tue Jul 21 08:52:34.240455 2026] [security2:error] [pid 533360:tid 533564] [client 20.197.192.193:26907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/kua.php"] [unique_id "al9dgnUPuLYrePtEkUcLjwAAAMw"]
[Tue Jul 21 08:52:34.246768 2026] [security2:error] [pid 533360:tid 533373] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dgnUPuLYrePtEkUcLkQAAiwk"]
[Tue Jul 21 08:52:34.246963 2026] [security2:error] [pid 533360:tid 533499] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dgnUPuLYrePtEkUcLkQAAiwk"]
[Tue Jul 21 08:52:34.251061 2026] [security2:error] [pid 533360:tid 533439] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/122.php"] [unique_id "al9dgnUPuLYrePtEkUcLkgAA-Us"]
[Tue Jul 21 08:52:34.289181 2026] [security2:error] [pid 533360:tid 533440] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/get.php"] [unique_id "al9dgnUPuLYrePtEkUcLlAAA4kw"]
[Tue Jul 21 08:52:34.315687 2026] [security2:error] [pid 533360:tid 533468] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/as.php"] [unique_id "al9dgnUPuLYrePtEkUcLlQAAyWg"]
[Tue Jul 21 08:52:34.629235 2026] [security2:error] [pid 533360:tid 533588] [client 212.32.76.12:31797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/maintenance.php"] [unique_id "al9dgnUPuLYrePtEkUcLuAAAAOQ"]
[Tue Jul 21 08:52:34.764975 2026] [security2:error] [pid 533360:tid 533369] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/ccou.php"] [unique_id "al9dgnUPuLYrePtEkUcLvAAA6gU"]
[Tue Jul 21 08:52:34.783561 2026] [security2:error] [pid 533360:tid 533441] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/w3lls.php"] [unique_id "al9dgnUPuLYrePtEkUcLvgAArU0"]
[Tue Jul 21 08:52:34.820153 2026] [security2:error] [pid 533360:tid 533383] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/test1.php"] [unique_id "al9dgnUPuLYrePtEkUcLwAAAjRM"]
[Tue Jul 21 08:52:34.838150 2026] [security2:error] [pid 533360:tid 533384] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/database.php"] [unique_id "al9dgnUPuLYrePtEkUcLwQAA7RQ"]
[Tue Jul 21 08:52:34.884533 2026] [security2:error] [pid 533360:tid 533480] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/file.php"] [unique_id "al9dgnUPuLYrePtEkUcLxQAA0HQ"]
[Tue Jul 21 08:52:34.946424 2026] [security2:error] [pid 533360:tid 533474] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/file.php"] [unique_id "al9dgnUPuLYrePtEkUcLxgAAmG4"]
[Tue Jul 21 08:52:35.031197 2026] [security2:error] [pid 533360:tid 533458] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/777.php"] [unique_id "al9dg3UPuLYrePtEkUcLygAA-V4"]
[Tue Jul 21 08:52:35.067204 2026] [security2:error] [pid 533360:tid 533508] [client 65.21.113.253:60610] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dgnUPuLYrePtEkUcLrwAAAJQ"]
[Tue Jul 21 08:52:35.079701 2026] [security2:error] [pid 533360:tid 533442] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/ssixta.php"] [unique_id "al9dg3UPuLYrePtEkUcLzgAAyU4"]
[Tue Jul 21 08:52:35.101821 2026] [security2:error] [pid 533360:tid 533443] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/1c.php"] [unique_id "al9dg3UPuLYrePtEkUcL0wAA_E8"]
[Tue Jul 21 08:52:35.153500 2026] [security2:error] [pid 533360:tid 533386] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/test2.php"] [unique_id "al9dg3UPuLYrePtEkUcL1QAA7BY"]
[Tue Jul 21 08:52:35.173084 2026] [security2:error] [pid 533360:tid 533484] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/buy.php"] [unique_id "al9dg3UPuLYrePtEkUcL1wAArHg"]
[Tue Jul 21 08:52:35.206086 2026] [security2:error] [pid 533360:tid 533399] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/ssend.php"] [unique_id "al9dg3UPuLYrePtEkUcL2AABASM"]
[Tue Jul 21 08:52:35.280278 2026] [security2:error] [pid 533360:tid 533374] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/item.php"] [unique_id "al9dg3UPuLYrePtEkUcL3gAA-Ao"]
[Tue Jul 21 08:52:35.284478 2026] [security2:error] [pid 533360:tid 533598] [client 203.25.124.12:37119] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "al9dg3UPuLYrePtEkUcL3wAAAO4"]
[Tue Jul 21 08:52:35.316695 2026] [security2:error] [pid 533360:tid 533390] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/ss.php"] [unique_id "al9dg3UPuLYrePtEkUcL4AAAyxo"]
[Tue Jul 21 08:52:35.333302 2026] [security2:error] [pid 533360:tid 533495] [client 185.117.225.17:58062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "serbetoadv.com"] [uri "/robots.txt"] [unique_id "al9dg3UPuLYrePtEkUcL4QAAAIc"]
[Tue Jul 21 08:52:35.726444 2026] [security2:error] [pid 533360:tid 533551] [client 20.151.10.161:49146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/d62.php"] [unique_id "al9dg3UPuLYrePtEkUcL6AAAAL8"]
[Tue Jul 21 08:52:36.032576 2026] [security2:error] [pid 533360:tid 533401] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/hypo.php"] [unique_id "al9dhHUPuLYrePtEkUcL-AAA0iU"]
[Tue Jul 21 08:52:36.187206 2026] [security2:error] [pid 533360:tid 533568] [client 20.104.96.117:3991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/w1px.php"] [unique_id "al9dhHUPuLYrePtEkUcL_QAAANA"]
[Tue Jul 21 08:52:36.203482 2026] [security2:error] [pid 533360:tid 533536] [client 20.220.225.223:23429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/la.php"] [unique_id "al9dhHUPuLYrePtEkUcL_wAAALA"]
[Tue Jul 21 08:52:36.276781 2026] [security2:error] [pid 533360:tid 533494] [client 203.25.124.12:24669] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/xml.php"] [unique_id "al9dhHUPuLYrePtEkUcMAAAAAIY"]
[Tue Jul 21 08:52:36.339132 2026] [security2:error] [pid 533360:tid 533586] [client 203.25.124.51:26009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/admin.php"] [unique_id "al9dhHUPuLYrePtEkUcMBAAAAOI"]
[Tue Jul 21 08:52:36.340141 2026] [security2:error] [pid 533360:tid 533602] [client 195.49.128.211:52065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dhHUPuLYrePtEkUcMBQAAAPI"]
[Tue Jul 21 08:52:36.340285 2026] [security2:error] [pid 533360:tid 533602] [client 195.49.128.211:52065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dhHUPuLYrePtEkUcMBQAAAPI"]
[Tue Jul 21 08:52:36.425220 2026] [security2:error] [pid 533360:tid 533471] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/users.php"] [unique_id "al9dhHUPuLYrePtEkUcMBgAA_Gs"]
[Tue Jul 21 08:52:36.520731 2026] [security2:error] [pid 533360:tid 533375] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/177.php"] [unique_id "al9dhHUPuLYrePtEkUcMCAAAxgs"]
[Tue Jul 21 08:52:36.549189 2026] [security2:error] [pid 533360:tid 533377] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/config.php"] [unique_id "al9dhHUPuLYrePtEkUcMCQAA1A0"]
[Tue Jul 21 08:52:36.569393 2026] [security2:error] [pid 533360:tid 533402] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/gettest.php"] [unique_id "al9dhHUPuLYrePtEkUcMCgABASY"]
[Tue Jul 21 08:52:36.575660 2026] [security2:error] [pid 533360:tid 533588] [client 152.59.181.104:58460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dhHUPuLYrePtEkUcMDAAAAOQ"]
[Tue Jul 21 08:52:36.575786 2026] [security2:error] [pid 533360:tid 533588] [client 152.59.181.104:58460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dhHUPuLYrePtEkUcMDAAAAOQ"]
[Tue Jul 21 08:52:36.614767 2026] [security2:error] [pid 533360:tid 533486] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/min.php"] [unique_id "al9dhHUPuLYrePtEkUcMDQAAxXo"]
[Tue Jul 21 08:52:36.636173 2026] [security2:error] [pid 533360:tid 533469] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/dvjul.php"] [unique_id "al9dhHUPuLYrePtEkUcMDgAApmk"]
[Tue Jul 21 08:52:36.699854 2026] [security2:error] [pid 533360:tid 533476] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/biufile.php"] [unique_id "al9dhHUPuLYrePtEkUcMFAAA7nA"]
[Tue Jul 21 08:52:36.725956 2026] [security2:error] [pid 533360:tid 533405] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/av.php"] [unique_id "al9dhHUPuLYrePtEkUcMFQAAyyk"]
[Tue Jul 21 08:52:36.746151 2026] [security2:error] [pid 533360:tid 533407] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/coffexium.php"] [unique_id "al9dhHUPuLYrePtEkUcMFwAA1Ss"]
[Tue Jul 21 08:52:36.766531 2026] [security2:error] [pid 533360:tid 533393] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/core.php"] [unique_id "al9dhHUPuLYrePtEkUcMGgAA_R0"]
[Tue Jul 21 08:52:36.915714 2026] [security2:error] [pid 533360:tid 533512] [client 5.38.115.39:64250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dhHUPuLYrePtEkUcMGwAAAJg"]
[Tue Jul 21 08:52:36.915917 2026] [security2:error] [pid 533360:tid 533512] [client 5.38.115.39:64250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dhHUPuLYrePtEkUcMGwAAAJg"]
[Tue Jul 21 08:52:37.049834 2026] [security2:error] [pid 533360:tid 533513] [client 20.197.192.193:27163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/ez.php"] [unique_id "al9dhXUPuLYrePtEkUcMHgAAAJk"]
[Tue Jul 21 08:52:37.366791 2026] [security2:error] [pid 533360:tid 533519] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9dhXUPuLYrePtEkUcMMgAAAJ8"]
[Tue Jul 21 08:52:37.414195 2026] [security2:error] [pid 533360:tid 533597] [client 20.220.225.223:19665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/dp.php"] [unique_id "al9dhXUPuLYrePtEkUcMXgAAAO0"]
[Tue Jul 21 08:52:37.430178 2026] [security2:error] [pid 533360:tid 533451] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dhXUPuLYrePtEkUcMXwAA8Vc"]
[Tue Jul 21 08:52:37.430379 2026] [security2:error] [pid 533360:tid 533601] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dhXUPuLYrePtEkUcMXwAA8Vc"]
[Tue Jul 21 08:52:37.468695 2026] [security2:error] [pid 533360:tid 533605] [client 203.25.124.5:27015] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-conflg/function.php"] [unique_id "al9dhXUPuLYrePtEkUcMYAAAAPU"]
[Tue Jul 21 08:52:37.603655 2026] [security2:error] [pid 533360:tid 533517] [client 41.89.234.2:63122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dhXUPuLYrePtEkUcMYwAAAJ0"]
[Tue Jul 21 08:52:37.603778 2026] [security2:error] [pid 533360:tid 533517] [client 41.89.234.2:63122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dhXUPuLYrePtEkUcMYwAAAJ0"]
[Tue Jul 21 08:52:37.831079 2026] [security2:error] [pid 533360:tid 533616] [client 84.17.60.251:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.60.17.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lunarium.tec.br"] [uri "/xmlrpc.php"] [unique_id "al9dhXUPuLYrePtEkUcMZgAAAQA"]
[Tue Jul 21 08:52:37.839659 2026] [security2:error] [pid 533360:tid 533457] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/als.php"] [unique_id "al9dhXUPuLYrePtEkUcMeQAApl0"]
[Tue Jul 21 08:52:37.867464 2026] [security2:error] [pid 533360:tid 533384] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/simple.php"] [unique_id "al9dhXUPuLYrePtEkUcMfgAA-BQ"]
[Tue Jul 21 08:52:37.890729 2026] [security2:error] [pid 533360:tid 533465] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/init.php"] [unique_id "al9dhXUPuLYrePtEkUcMigAAoWU"]
[Tue Jul 21 08:52:37.938329 2026] [security2:error] [pid 533360:tid 533541] [client 49.144.66.253:33322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dhXUPuLYrePtEkUcMiwAAALU"]
[Tue Jul 21 08:52:37.938514 2026] [security2:error] [pid 533360:tid 533541] [client 49.144.66.253:33322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dhXUPuLYrePtEkUcMiwAAALU"]
[Tue Jul 21 08:52:37.950628 2026] [security2:error] [pid 533360:tid 533615] [client 203.25.124.36:40021] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/home.php"] [unique_id "al9dhXUPuLYrePtEkUcMjAAAAP8"]
[Tue Jul 21 08:52:38.271907 2026] [security2:error] [pid 533360:tid 533487] [remote 216.73.216.184:37222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9dhnUPuLYrePtEkUcMqwAA53s"]
[Tue Jul 21 08:52:38.284158 2026] [security2:error] [pid 533360:tid 533568] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9dhnUPuLYrePtEkUcMrAAAANA"]
[Tue Jul 21 08:52:38.333580 2026] [security2:error] [pid 533360:tid 533412] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/fpwch.php"] [unique_id "al9dhnUPuLYrePtEkUcMrQAAkDA"]
[Tue Jul 21 08:52:38.373788 2026] [security2:error] [pid 533360:tid 533601] [client 203.25.124.188:47309] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/network_xo.php"] [unique_id "al9dhnUPuLYrePtEkUcMrwAAAPE"]
[Tue Jul 21 08:52:38.453301 2026] [security2:error] [pid 533360:tid 533506] [client 20.220.225.223:32399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/nhvoanpl.php"] [unique_id "al9dhnUPuLYrePtEkUcMuQAAAJI"]
[Tue Jul 21 08:52:38.518667 2026] [security2:error] [pid 533360:tid 533528] [client 20.151.10.161:49151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/ups.php"] [unique_id "al9dhnUPuLYrePtEkUcMuwAAAKg"]
[Tue Jul 21 08:52:38.568589 2026] [security2:error] [pid 533360:tid 533554] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9dhnUPuLYrePtEkUcMvQAAAMI"]
[Tue Jul 21 08:52:38.737652 2026] [security2:error] [pid 533360:tid 533532] [client 65.21.113.253:58260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dhnUPuLYrePtEkUcMxQAAAKw"]
[Tue Jul 21 08:52:38.852938 2026] [security2:error] [pid 533360:tid 533610] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9dhnUPuLYrePtEkUcMzAAAAPo"]
[Tue Jul 21 08:52:38.929645 2026] [security2:error] [pid 533360:tid 533434] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/domvf.php"] [unique_id "al9dhnUPuLYrePtEkUcMzgAA2kY"]
[Tue Jul 21 08:52:38.931801 2026] [security2:error] [pid 533360:tid 533430] [remote 124.55.178.99:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "printcom.com.br"] [uri "/wp-login.php"] [unique_id "al9dhnUPuLYrePtEkUcMzQAA-UI"]
[Tue Jul 21 08:52:38.939124 2026] [security2:error] [pid 533360:tid 533395] [remote 114.119.138.74:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hauptmann.com.br"] [uri "/imovel/apartamento-vittace-venda/"] [unique_id "al9dhnUPuLYrePtEkUcMzwAAjh8"], referer: https://hauptmann.com.br/opera%C3%A7%C3%A3o/urbanos/?doing_wp_cron=1627083368.9463798999786376953125
[Tue Jul 21 08:52:39.138238 2026] [security2:error] [pid 533360:tid 533505] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9dh3UPuLYrePtEkUcM1QAAAJE"]
[Tue Jul 21 08:52:39.204136 2026] [security2:error] [pid 533360:tid 533495] [client 20.220.225.223:38737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/zzz.php"] [unique_id "al9dh3UPuLYrePtEkUcM1gAAAIc"]
[Tue Jul 21 08:52:39.214181 2026] [security2:error] [pid 533360:tid 533508] [client 182.189.99.211:47969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dh3UPuLYrePtEkUcM1wAAAJQ"]
[Tue Jul 21 08:52:39.214365 2026] [security2:error] [pid 533360:tid 533508] [client 182.189.99.211:47969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dh3UPuLYrePtEkUcM1wAAAJQ"]
[Tue Jul 21 08:52:39.380357 2026] [security2:error] [pid 533360:tid 533498] [client 203.25.124.200:24595] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/sitemaps/"] [unique_id "al9dh3UPuLYrePtEkUcM3gAAAIo"]
[Tue Jul 21 08:52:39.428673 2026] [security2:error] [pid 533360:tid 533593] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9dh3UPuLYrePtEkUcM4QAAAOk"]
[Tue Jul 21 08:52:39.439074 2026] [security2:error] [pid 533360:tid 533580] [client 203.25.124.39:45157] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/oceanwp/content-index.php"] [unique_id "al9dh3UPuLYrePtEkUcM4wAAANw"]
[Tue Jul 21 08:52:39.623968 2026] [security2:error] [pid 533360:tid 533446] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dh3UPuLYrePtEkUcM6QAAm1I"]
[Tue Jul 21 08:52:39.624153 2026] [security2:error] [pid 533360:tid 533515] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dh3UPuLYrePtEkUcM6QAAm1I"]
[Tue Jul 21 08:52:39.685401 2026] [security2:error] [pid 533360:tid 533570] [client 185.117.225.17:44130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.serbetoadv.com"] [uri "/robots.txt"] [unique_id "al9dh3UPuLYrePtEkUcM6gAAANI"]
[Tue Jul 21 08:52:39.714018 2026] [security2:error] [pid 533360:tid 533520] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9dh3UPuLYrePtEkUcM6wAAAKA"]
[Tue Jul 21 08:52:39.727482 2026] [security2:error] [pid 533360:tid 533463] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/wp.php"] [unique_id "al9dh3UPuLYrePtEkUcM7AAA22M"]
[Tue Jul 21 08:52:39.749053 2026] [security2:error] [pid 533360:tid 533426] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/class.php"] [unique_id "al9dh3UPuLYrePtEkUcM7QAA-j4"]
[Tue Jul 21 08:52:39.777320 2026] [security2:error] [pid 533360:tid 533455] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/echkm.php"] [unique_id "al9dh3UPuLYrePtEkUcM7gAAxVs"]
[Tue Jul 21 08:52:39.868355 2026] [security2:error] [pid 533360:tid 533618] [client 65.21.113.253:54066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dh3UPuLYrePtEkUcM4AAAAQI"]
[Tue Jul 21 08:52:39.928202 2026] [security2:error] [pid 533360:tid 533523] [client 20.197.192.193:26905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/fz.php"] [unique_id "al9dh3UPuLYrePtEkUcM-AAAAKM"]
[Tue Jul 21 08:52:40.001509 2026] [security2:error] [pid 533360:tid 533566] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9diHUPuLYrePtEkUcM-wAAAM4"]
[Tue Jul 21 08:52:40.031108 2026] [security2:error] [pid 533360:tid 533370] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/lib.php"] [unique_id "al9diHUPuLYrePtEkUcM_gAAmgY"]
[Tue Jul 21 08:52:40.051263 2026] [security2:error] [pid 533360:tid 533462] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/login.php"] [unique_id "al9diHUPuLYrePtEkUcNAAAA6WI"]
[Tue Jul 21 08:52:40.210267 2026] [security2:error] [pid 533360:tid 533597] [client 20.220.225.223:19282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/bootstrap.php"] [unique_id "al9diHUPuLYrePtEkUcNAQAAAO0"]
[Tue Jul 21 08:52:40.253983 2026] [security2:error] [pid 533360:tid 533373] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9diHUPuLYrePtEkUcNAwAAvAk"]
[Tue Jul 21 08:52:40.254197 2026] [security2:error] [pid 533360:tid 533548] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9diHUPuLYrePtEkUcNAwAAvAk"]
[Tue Jul 21 08:52:40.287486 2026] [security2:error] [pid 533360:tid 533550] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9diHUPuLYrePtEkUcNBAAAAL4"]
[Tue Jul 21 08:52:40.304627 2026] [security2:error] [pid 533360:tid 533423] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/a2.php"] [unique_id "al9diHUPuLYrePtEkUcNBQAArTs"]
[Tue Jul 21 08:52:40.525780 2026] [security2:error] [pid 533360:tid 533614] [client 20.220.225.223:52196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/inso.php"] [unique_id "al9diHUPuLYrePtEkUcNDAAAAP4"]
[Tue Jul 21 08:52:40.532046 2026] [security2:error] [pid 533360:tid 533558] [client 20.151.10.161:49108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/k.php"] [unique_id "al9diHUPuLYrePtEkUcNDQAAAMY"]
[Tue Jul 21 08:52:40.571068 2026] [security2:error] [pid 533360:tid 533581] [client 20.104.96.117:59198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "andrelageorthobolics.com.br"] [uri "/zc-131.php"] [unique_id "al9diHUPuLYrePtEkUcNDwAAAN0"]
[Tue Jul 21 08:52:40.580436 2026] [security2:error] [pid 533360:tid 533517] [client 185.117.225.17:44132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.serbetoadv.com"] [uri "/robots.txt"] [unique_id "al9diHUPuLYrePtEkUcNEQAAAJ0"]
[Tue Jul 21 08:52:40.611579 2026] [security2:error] [pid 533360:tid 533530] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9diHUPuLYrePtEkUcNFAAAAKo"]
[Tue Jul 21 08:52:40.661221 2026] [security2:error] [pid 533360:tid 533456] [remote 100.42.189.89:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9diHUPuLYrePtEkUcNFQAAwlw"]
[Tue Jul 21 08:52:40.773637 2026] [security2:error] [pid 533360:tid 533579] [client 203.25.124.185:56845] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/pomo/index.php"] [unique_id "al9diHUPuLYrePtEkUcNFwAAANs"]
[Tue Jul 21 08:52:40.846745 2026] [security2:error] [pid 533360:tid 533610] [client 203.25.124.39:28839] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/Divi/content-index.php"] [unique_id "al9diHUPuLYrePtEkUcNGAAAAPo"]
[Tue Jul 21 08:52:40.894581 2026] [security2:error] [pid 533360:tid 533559] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9diHUPuLYrePtEkUcNHQAAAMc"]
[Tue Jul 21 08:52:41.113888 2026] [security2:error] [pid 533360:tid 533371] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/d61.php"] [unique_id "al9diXUPuLYrePtEkUcNJAAAqQc"]
[Tue Jul 21 08:52:41.179724 2026] [security2:error] [pid 533360:tid 533603] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9diXUPuLYrePtEkUcNJQAAAPM"]
[Tue Jul 21 08:52:41.336114 2026] [security2:error] [pid 533360:tid 533534] [client 88.214.1.73:32953] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bestsellerdigital.com.br"] [uri "/robots.txt"] [unique_id "al9diXUPuLYrePtEkUcNKAAAAK4"]
[Tue Jul 21 08:52:41.336233 2026] [security2:error] [pid 533360:tid 533534] [client 88.214.1.73:32953] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bestsellerdigital.com.br"] [uri "/robots.txt"] [unique_id "al9diXUPuLYrePtEkUcNKAAAAK4"]
[Tue Jul 21 08:52:41.339356 2026] [security2:error] [pid 533360:tid 533515] [client 168.167.81.163:63927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9diXUPuLYrePtEkUcNKQAAAJs"]
[Tue Jul 21 08:52:41.339456 2026] [security2:error] [pid 533360:tid 533515] [client 168.167.81.163:63927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9diXUPuLYrePtEkUcNKQAAAJs"]
[Tue Jul 21 08:52:41.466955 2026] [security2:error] [pid 533360:tid 533498] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9diXUPuLYrePtEkUcNMAAAAIo"]
[Tue Jul 21 08:52:41.754145 2026] [security2:error] [pid 533360:tid 533548] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9diXUPuLYrePtEkUcNOQAAALw"]
[Tue Jul 21 08:52:41.803587 2026] [security2:error] [pid 533360:tid 533513] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9diXUPuLYrePtEkUcNOAAAmUk"]
[Tue Jul 21 08:52:41.876425 2026] [security2:error] [pid 533360:tid 533589] [client 212.32.76.65:43299] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/plugins/revslider/includes/external/page/"] [unique_id "al9diXUPuLYrePtEkUcNPAAAAOU"]
[Tue Jul 21 08:52:42.039162 2026] [security2:error] [pid 533360:tid 533570] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9dinUPuLYrePtEkUcNRAAAANI"]
[Tue Jul 21 08:52:42.082269 2026] [security2:error] [pid 533360:tid 533596] [client 20.151.10.161:49025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/k2.php"] [unique_id "al9dinUPuLYrePtEkUcNRQAAAOw"]
[Tue Jul 21 08:52:42.133318 2026] [security2:error] [pid 533360:tid 533457] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/info.php"] [unique_id "al9dinUPuLYrePtEkUcNSwAAyV0"]
[Tue Jul 21 08:52:42.180894 2026] [security2:error] [pid 533360:tid 533464] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/11.php"] [unique_id "al9dinUPuLYrePtEkUcNTAAArGQ"]
[Tue Jul 21 08:52:42.213766 2026] [security2:error] [pid 533360:tid 533453] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/v2.php"] [unique_id "al9dinUPuLYrePtEkUcNTQAAoFk"]
[Tue Jul 21 08:52:42.260541 2026] [security2:error] [pid 533360:tid 533384] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/panel.php"] [unique_id "al9dinUPuLYrePtEkUcNUgAA-hQ"]
[Tue Jul 21 08:52:42.323650 2026] [security2:error] [pid 533360:tid 533598] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9dinUPuLYrePtEkUcNVgAAAO4"]
[Tue Jul 21 08:52:42.333920 2026] [security2:error] [pid 533360:tid 533494] [client 203.25.124.48:62647] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/exnova/content-index.php"] [unique_id "al9dinUPuLYrePtEkUcNVwAAAIY"]
[Tue Jul 21 08:52:42.357175 2026] [security2:error] [pid 533360:tid 533614] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dinUPuLYrePtEkUcNSgAA_nk"]
[Tue Jul 21 08:52:42.384634 2026] [security2:error] [pid 533360:tid 533559] [client 20.220.225.223:48223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/wicked.php"] [unique_id "al9dinUPuLYrePtEkUcNWQAAAMc"]
[Tue Jul 21 08:52:42.633835 2026] [security2:error] [pid 533360:tid 533508] [client 84.17.60.251:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lunarium.tec.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9dinUPuLYrePtEkUcNXgAAAJQ"]
[Tue Jul 21 08:52:42.694376 2026] [security2:error] [pid 533360:tid 533517] [client 59.95.197.55:60672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dinUPuLYrePtEkUcNYgAAAJ0"]
[Tue Jul 21 08:52:42.694511 2026] [security2:error] [pid 533360:tid 533517] [client 59.95.197.55:60672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dinUPuLYrePtEkUcNYgAAAJ0"]
[Tue Jul 21 08:52:42.781389 2026] [security2:error] [pid 533360:tid 533518] [client 203.25.124.199:31481] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "al9dinUPuLYrePtEkUcNZwAAAJ4"]
[Tue Jul 21 08:52:42.908982 2026] [security2:error] [pid 533360:tid 533616] [client 122.176.100.127:62456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dinUPuLYrePtEkUcNaAAAAQA"]
[Tue Jul 21 08:52:42.909170 2026] [security2:error] [pid 533360:tid 533616] [client 122.176.100.127:62456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dinUPuLYrePtEkUcNaAAAAQA"]
[Tue Jul 21 08:52:42.980790 2026] [security2:error] [pid 533360:tid 533495] [client 114.198.138.124:55444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dinUPuLYrePtEkUcNaQAAAIc"]
[Tue Jul 21 08:52:42.980910 2026] [security2:error] [pid 533360:tid 533495] [client 114.198.138.124:55444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dinUPuLYrePtEkUcNaQAAAIc"]
[Tue Jul 21 08:52:42.985444 2026] [security2:error] [pid 533360:tid 533478] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/dex.php"] [unique_id "al9dinUPuLYrePtEkUcNagAAmnI"]
[Tue Jul 21 08:52:43.013540 2026] [security2:error] [pid 533360:tid 533383] [remote 20.197.195.24:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "serri.com.br"] [uri "/1.php"] [unique_id "al9di3UPuLYrePtEkUcNbQAAjRM"]
[Tue Jul 21 08:52:43.013608 2026] [security2:error] [pid 533360:tid 533383] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/1.php"] [unique_id "al9di3UPuLYrePtEkUcNbQAAjRM"]
[Tue Jul 21 08:52:43.033850 2026] [security2:error] [pid 533360:tid 533454] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/ms.php"] [unique_id "al9di3UPuLYrePtEkUcNbwAAwVo"]
[Tue Jul 21 08:52:43.109043 2026] [autoindex:error] [pid 533360:tid 533386] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home4/serric15/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:52:43.130478 2026] [security2:error] [pid 533360:tid 533484] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/memberfuns.php"] [unique_id "al9di3UPuLYrePtEkUcNcwAAvHg"]
[Tue Jul 21 08:52:43.149122 2026] [security2:error] [pid 533360:tid 533390] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/0.php"] [unique_id "al9di3UPuLYrePtEkUcNdAAAvho"]
[Tue Jul 21 08:52:43.170200 2026] [security2:error] [pid 533360:tid 533366] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/BDKR28.php"] [unique_id "al9di3UPuLYrePtEkUcNdgAArQI"]
[Tue Jul 21 08:52:43.182001 2026] [security2:error] [pid 533360:tid 533510] [client 20.104.96.117:46724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/yawa.php"] [unique_id "al9di3UPuLYrePtEkUcNdwAAAJY"]
[Tue Jul 21 08:52:43.190602 2026] [security2:error] [pid 533360:tid 533387] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/green1.php"] [unique_id "al9di3UPuLYrePtEkUcNeQAA_Bc"]
[Tue Jul 21 08:52:43.336428 2026] [security2:error] [pid 533360:tid 533586] [client 65.21.113.253:58260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9di3UPuLYrePtEkUcNfgAAAOI"]
[Tue Jul 21 08:52:43.538767 2026] [security2:error] [pid 533360:tid 533604] [client 212.32.76.13:50769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/specia/content-index.php"] [unique_id "al9di3UPuLYrePtEkUcNiwAAAPQ"]
[Tue Jul 21 08:52:43.585734 2026] [security2:error] [pid 533360:tid 533549] [client 128.127.105.184:54388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9di3UPuLYrePtEkUcNkgAAAL0"]
[Tue Jul 21 08:52:43.585892 2026] [security2:error] [pid 533360:tid 533549] [client 128.127.105.184:54388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9di3UPuLYrePtEkUcNkgAAAL0"]
[Tue Jul 21 08:52:43.655511 2026] [security2:error] [pid 533360:tid 533476] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9di3UPuLYrePtEkUcNvgAAt3A"]
[Tue Jul 21 08:52:43.655674 2026] [security2:error] [pid 533360:tid 533543] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9di3UPuLYrePtEkUcNvgAAt3A"]
[Tue Jul 21 08:52:43.836512 2026] [security2:error] [pid 533360:tid 533508] [client 20.220.225.223:52190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wpx.php"] [unique_id "al9di3UPuLYrePtEkUcNxQAAAJQ"]
[Tue Jul 21 08:52:43.930459 2026] [security2:error] [pid 533360:tid 533541] [client 113.22.144.139:62091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9di3UPuLYrePtEkUcNxwAAALU"]
[Tue Jul 21 08:52:43.931085 2026] [security2:error] [pid 533360:tid 533541] [client 113.22.144.139:62091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9di3UPuLYrePtEkUcNxwAAALU"]
[Tue Jul 21 08:52:43.960566 2026] [security2:error] [pid 533360:tid 533394] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/nc4.php"] [unique_id "al9di3UPuLYrePtEkUcNywAAwx4"]
[Tue Jul 21 08:52:43.986945 2026] [security2:error] [pid 533360:tid 533428] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/a1.php"] [unique_id "al9di3UPuLYrePtEkUcNzQAAm0A"]
[Tue Jul 21 08:52:44.010123 2026] [security2:error] [pid 533360:tid 533411] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/eee.php"] [unique_id "al9djHUPuLYrePtEkUcNzgAA6C8"]
[Tue Jul 21 08:52:44.029569 2026] [security2:error] [pid 533360:tid 533439] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/wp-aothait.php"] [unique_id "al9djHUPuLYrePtEkUcN0AAAzks"]
[Tue Jul 21 08:52:44.049356 2026] [security2:error] [pid 533360:tid 533456] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/config.json.php"] [unique_id "al9djHUPuLYrePtEkUcN0QAAs1w"]
[Tue Jul 21 08:52:44.100528 2026] [security2:error] [pid 533360:tid 533371] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9djHUPuLYrePtEkUcN2AAA7wc"]
[Tue Jul 21 08:52:44.159141 2026] [security2:error] [pid 533360:tid 533475] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/k2.php"] [unique_id "al9djHUPuLYrePtEkUcN9gAAim8"]
[Tue Jul 21 08:52:44.198886 2026] [security2:error] [pid 533360:tid 533442] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/uiuvs58l.php"] [unique_id "al9djHUPuLYrePtEkUcN9wAAvE4"]
[Tue Jul 21 08:52:44.235179 2026] [security2:error] [pid 533360:tid 533417] [remote 104.131.116.82:58112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.116.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kaducontractor.com"] [uri "/wp-login.php"] [unique_id "al9djHUPuLYrePtEkUcN0gAA2TU"]
[Tue Jul 21 08:52:44.236450 2026] [security2:error] [pid 533360:tid 533409] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/40p9ixjd.php"] [unique_id "al9djHUPuLYrePtEkUcOAgAA4C0"]
[Tue Jul 21 08:52:44.269443 2026] [security2:error] [pid 533360:tid 533385] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/uiuvs58l.update.php"] [unique_id "al9djHUPuLYrePtEkUcOBAAApxU"]
[Tue Jul 21 08:52:44.273836 2026] [security2:error] [pid 533360:tid 533586] [client 20.220.225.223:19280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wp-editor.php"] [unique_id "al9djHUPuLYrePtEkUcOBQAAAOI"]
[Tue Jul 21 08:52:44.306308 2026] [security2:error] [pid 533360:tid 533386] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/for.php"] [unique_id "al9djHUPuLYrePtEkUcOBgAA0hY"]
[Tue Jul 21 08:52:44.326944 2026] [security2:error] [pid 533360:tid 533484] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "serri.com.br"] [uri "/raw.php"] [unique_id "al9djHUPuLYrePtEkUcOBwAAkng"]
[Tue Jul 21 08:52:44.562538 2026] [security2:error] [pid 533360:tid 533618] [client 65.21.113.253:54076] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9djHUPuLYrePtEkUcNzwAAAQI"]
[Tue Jul 21 08:52:44.640758 2026] [security2:error] [pid 533360:tid 533600] [client 203.25.124.33:45367] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "al9djHUPuLYrePtEkUcOEQAAAPA"]
[Tue Jul 21 08:52:44.795228 2026] [security2:error] [pid 533360:tid 533544] [client 193.31.75.177:34001] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bestsellerdigital.com.br"] [uri "/sitemap.xml"] [unique_id "al9djHUPuLYrePtEkUcOHQAAALg"]
[Tue Jul 21 08:52:44.795336 2026] [security2:error] [pid 533360:tid 533544] [client 193.31.75.177:34001] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bestsellerdigital.com.br"] [uri "/sitemap.xml"] [unique_id "al9djHUPuLYrePtEkUcOHQAAALg"]
[Tue Jul 21 08:52:44.921148 2026] [security2:error] [pid 533360:tid 533412] [remote 8.217.108.67:36190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zooparquevet.com.br"] [uri "/wp-login.php"] [unique_id "al9djHUPuLYrePtEkUcOHwAAsDA"]
[Tue Jul 21 08:52:44.971203 2026] [security2:error] [pid 533360:tid 533523] [client 212.32.76.66:52957] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/nrhogjyecktixbal0fnt5Cakc.php"] [unique_id "al9djHUPuLYrePtEkUcOIAAAAKM"]
[Tue Jul 21 08:52:44.977240 2026] [security2:error] [pid 533360:tid 533515] [client 20.220.225.223:52176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/berlin.php"] [unique_id "al9djHUPuLYrePtEkUcOIgAAAJs"]
[Tue Jul 21 08:52:45.174979 2026] [security2:error] [pid 533360:tid 533396] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9djXUPuLYrePtEkUcOMAAA2iA"]
[Tue Jul 21 08:52:45.175137 2026] [security2:error] [pid 533360:tid 533578] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9djXUPuLYrePtEkUcOMAAA2iA"]
[Tue Jul 21 08:52:46.114298 2026] [security2:error] [pid 533360:tid 533505] [client 20.220.225.223:6084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/billur.php"] [unique_id "al9djnUPuLYrePtEkUcOSQAAAJE"]
[Tue Jul 21 08:52:46.374504 2026] [security2:error] [pid 533360:tid 533499] [client 203.25.124.185:39425] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-trackback.php"] [unique_id "al9djnUPuLYrePtEkUcOVQAAAIs"]
[Tue Jul 21 08:52:47.000019 2026] [security2:error] [pid 533360:tid 533514] [client 195.49.128.211:52672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9djnUPuLYrePtEkUcOYwAAAJo"]
[Tue Jul 21 08:52:47.000167 2026] [security2:error] [pid 533360:tid 533514] [client 195.49.128.211:52672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9djnUPuLYrePtEkUcOYwAAAJo"]
[Tue Jul 21 08:52:47.332965 2026] [security2:error] [pid 533360:tid 533536] [client 152.59.181.104:59015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dj3UPuLYrePtEkUcObgAAALA"]
[Tue Jul 21 08:52:47.333079 2026] [security2:error] [pid 533360:tid 533536] [client 152.59.181.104:59015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dj3UPuLYrePtEkUcObgAAALA"]
[Tue Jul 21 08:52:47.470643 2026] [security2:error] [pid 533360:tid 533494] [client 203.25.124.182:29515] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/ty.php"] [unique_id "al9dj3UPuLYrePtEkUcOcwAAAIY"]
[Tue Jul 21 08:52:47.542705 2026] [security2:error] [pid 533360:tid 533588] [client 20.151.10.161:49089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/k3.php"] [unique_id "al9dj3UPuLYrePtEkUcOdAAAAOQ"]
[Tue Jul 21 08:52:47.630486 2026] [security2:error] [pid 533360:tid 533589] [client 5.38.115.39:61339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dj3UPuLYrePtEkUcOdgAAAOU"]
[Tue Jul 21 08:52:47.630597 2026] [security2:error] [pid 533360:tid 533589] [client 5.38.115.39:61339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dj3UPuLYrePtEkUcOdgAAAOU"]
[Tue Jul 21 08:52:47.773238 2026] [security2:error] [pid 533360:tid 533500] [client 20.220.225.223:6113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/mimpi.php"] [unique_id "al9dj3UPuLYrePtEkUcOgAAAAIw"]
[Tue Jul 21 08:52:47.894676 2026] [security2:error] [pid 533360:tid 533381] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dj3UPuLYrePtEkUcOggAAjhE"]
[Tue Jul 21 08:52:47.894874 2026] [security2:error] [pid 533360:tid 533502] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dj3UPuLYrePtEkUcOggAAjhE"]
[Tue Jul 21 08:52:48.138633 2026] [security2:error] [pid 533360:tid 533606] [client 203.25.124.212:54133] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/css/eroor.php"] [unique_id "al9dkHUPuLYrePtEkUcOjQAAAPY"]
[Tue Jul 21 08:52:48.259803 2026] [security2:error] [pid 533360:tid 533529] [client 20.220.225.223:23471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/dp.php"] [unique_id "al9dkHUPuLYrePtEkUcOkQAAAKk"]
[Tue Jul 21 08:52:48.282354 2026] [security2:error] [pid 533360:tid 533543] [client 41.89.234.2:63643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dkHUPuLYrePtEkUcOmAAAALc"]
[Tue Jul 21 08:52:48.282468 2026] [security2:error] [pid 533360:tid 533543] [client 41.89.234.2:63643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dkHUPuLYrePtEkUcOmAAAALc"]
[Tue Jul 21 08:52:48.378194 2026] [security2:error] [pid 533360:tid 533510] [client 203.25.124.189:22995] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/default.php"] [unique_id "al9dkHUPuLYrePtEkUcOnAAAAJY"]
[Tue Jul 21 08:52:48.715676 2026] [security2:error] [pid 533360:tid 533532] [client 49.144.66.253:33737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dkHUPuLYrePtEkUcOogAAAKw"]
[Tue Jul 21 08:52:48.715799 2026] [security2:error] [pid 533360:tid 533532] [client 49.144.66.253:33737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dkHUPuLYrePtEkUcOogAAAKw"]
[Tue Jul 21 08:52:48.727255 2026] [security2:error] [pid 533360:tid 533614] [client 20.197.192.193:27084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/la.php"] [unique_id "al9dkHUPuLYrePtEkUcOowAAAP4"]
[Tue Jul 21 08:52:48.902048 2026] [security2:error] [pid 533360:tid 533568] [client 20.220.225.223:23436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/bootstrap.php"] [unique_id "al9dkHUPuLYrePtEkUcOqQAAANA"]
[Tue Jul 21 08:52:48.939682 2026] [security2:error] [pid 533360:tid 533553] [client 212.32.76.13:37471] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/languages/themes/home.php"] [unique_id "al9dkHUPuLYrePtEkUcOqwAAAME"]
[Tue Jul 21 08:52:49.373933 2026] [security2:error] [pid 533360:tid 533606] [client 203.25.124.200:57011] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/SimplePie/font-editor.php"] [unique_id "al9dkXUPuLYrePtEkUcOuAAAAPY"]
[Tue Jul 21 08:52:49.702338 2026] [security2:error] [pid 533360:tid 533594] [client 182.189.99.211:47972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dkXUPuLYrePtEkUcOxAAAAOo"]
[Tue Jul 21 08:52:49.702492 2026] [security2:error] [pid 533360:tid 533594] [client 182.189.99.211:47972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dkXUPuLYrePtEkUcOxAAAAOo"]
[Tue Jul 21 08:52:49.943036 2026] [security2:error] [pid 533360:tid 533531] [client 203.25.124.69:50927] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/languages/plugins/options.php"] [unique_id "al9dkXUPuLYrePtEkUcOzgAAAKs"]
[Tue Jul 21 08:52:50.130302 2026] [security2:error] [pid 533360:tid 533437] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dknUPuLYrePtEkUcO1QAA0Uk"]
[Tue Jul 21 08:52:50.130417 2026] [security2:error] [pid 533360:tid 533569] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dknUPuLYrePtEkUcO1QAA0Uk"]
[Tue Jul 21 08:52:50.150590 2026] [security2:error] [pid 533360:tid 533500] [client 20.151.10.161:48576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/k4.php"] [unique_id "al9dknUPuLYrePtEkUcO1gAAAIw"]
[Tue Jul 21 08:52:50.182050 2026] [security2:error] [pid 533360:tid 533555] [client 203.25.124.251:45009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "al9dknUPuLYrePtEkUcO2AAAAMM"]
[Tue Jul 21 08:52:50.222074 2026] [autoindex:error] [pid 533360:tid 533521] [client 15.181.49.196:65384] AH01276: Cannot serve directory /home4/ciclod61/homemsedutoronline.com/wp-content/themes/blocksy/static/bundle/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://homemsedutoronline.com
[Tue Jul 21 08:52:50.803855 2026] [security2:error] [pid 533360:tid 533466] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dknUPuLYrePtEkUcO5wAA1mY"]
[Tue Jul 21 08:52:50.804044 2026] [security2:error] [pid 533360:tid 533574] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dknUPuLYrePtEkUcO5wAA1mY"]
[Tue Jul 21 08:52:51.035657 2026] [security2:error] [pid 533360:tid 533543] [client 203.25.124.48:51225] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/tinymce/themes/panel.php"] [unique_id "al9dk3UPuLYrePtEkUcO7QAAALc"]
[Tue Jul 21 08:52:51.181514 2026] [security2:error] [pid 533360:tid 533507] [client 20.220.225.223:23466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wp-editor.php"] [unique_id "al9dk3UPuLYrePtEkUcO8QAAAJM"]
[Tue Jul 21 08:52:51.276847 2026] [security2:error] [pid 533360:tid 533533] [client 203.25.124.182:64335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al9dk3UPuLYrePtEkUcO8wAAAK0"]
[Tue Jul 21 08:52:51.864239 2026] [security2:error] [pid 533360:tid 533493] [client 20.220.225.223:23474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/cro.php"] [unique_id "al9dk3UPuLYrePtEkUcPAwAAAIU"]
[Tue Jul 21 08:52:52.071259 2026] [security2:error] [pid 533360:tid 533600] [client 203.25.124.9:37291] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-atom.php"] [unique_id "al9dlHUPuLYrePtEkUcPCQAAAPA"]
[Tue Jul 21 08:52:52.075107 2026] [security2:error] [pid 533360:tid 533590] [client 168.167.81.163:59501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dlHUPuLYrePtEkUcPCgAAAOY"]
[Tue Jul 21 08:52:52.075203 2026] [security2:error] [pid 533360:tid 533590] [client 168.167.81.163:59501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dlHUPuLYrePtEkUcPCgAAAOY"]
[Tue Jul 21 08:52:52.152146 2026] [security2:error] [pid 533360:tid 533556] [client 203.25.124.50:50699] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Requests/Response/Response/multisite-setup.php"] [unique_id "al9dlHUPuLYrePtEkUcPEQAAAMQ"]
[Tue Jul 21 08:52:52.684924 2026] [security2:error] [pid 533360:tid 533582] [client 20.104.96.117:3968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/js.php"] [unique_id "al9dlHUPuLYrePtEkUcPHAAAAN4"]
[Tue Jul 21 08:52:52.688264 2026] [security2:error] [pid 533360:tid 533514] [client 20.220.225.223:6136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/cron-tab.php"] [unique_id "al9dlHUPuLYrePtEkUcPHQAAAJo"]
[Tue Jul 21 08:52:52.783398 2026] [security2:error] [pid 533360:tid 533597] [client 54.39.203.239:46098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.arcoll.com.br"] [uri "/robots.txt"] [unique_id "al9dlHUPuLYrePtEkUcPJQAAAO0"]
[Tue Jul 21 08:52:52.783501 2026] [security2:error] [pid 533360:tid 533597] [client 54.39.203.239:46098] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.arcoll.com.br"] [uri "/robots.txt"] [unique_id "al9dlHUPuLYrePtEkUcPJQAAAO0"]
[Tue Jul 21 08:52:52.881715 2026] [security2:error] [pid 533360:tid 533612] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dlHUPuLYrePtEkUcPIQAA_Bc"]
[Tue Jul 21 08:52:53.078825 2026] [security2:error] [pid 533360:tid 533527] [client 203.25.124.180:47567] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/tinymce/themes/inlite/"] [unique_id "al9dlXUPuLYrePtEkUcPLgAAAKc"]
[Tue Jul 21 08:52:53.179188 2026] [security2:error] [pid 533360:tid 533529] [client 59.95.197.55:61154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dlXUPuLYrePtEkUcPLwAAAKk"]
[Tue Jul 21 08:52:53.179345 2026] [security2:error] [pid 533360:tid 533529] [client 59.95.197.55:61154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dlXUPuLYrePtEkUcPLwAAAKk"]
[Tue Jul 21 08:52:53.329218 2026] [security2:error] [pid 533360:tid 533507] [client 122.176.100.127:62941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dlXUPuLYrePtEkUcPNgAAAJM"]
[Tue Jul 21 08:52:53.329364 2026] [security2:error] [pid 533360:tid 533507] [client 122.176.100.127:62941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dlXUPuLYrePtEkUcPNgAAAJM"]
[Tue Jul 21 08:52:53.372285 2026] [security2:error] [pid 533360:tid 533555] [client 65.21.113.253:59810] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dlXUPuLYrePtEkUcPOQAAAMM"]
[Tue Jul 21 08:52:53.639088 2026] [security2:error] [pid 533360:tid 533599] [client 203.25.124.212:34385] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/data.php"] [unique_id "al9dlXUPuLYrePtEkUcPRQAAAO8"]
[Tue Jul 21 08:52:53.692825 2026] [security2:error] [pid 533360:tid 533499] [client 114.198.138.124:56024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dlXUPuLYrePtEkUcPRwAAAIs"]
[Tue Jul 21 08:52:53.692956 2026] [security2:error] [pid 533360:tid 533499] [client 114.198.138.124:56024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dlXUPuLYrePtEkUcPRwAAAIs"]
[Tue Jul 21 08:52:53.770368 2026] [security2:error] [pid 533360:tid 533574] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dlXUPuLYrePtEkUcPRAAA1gE"]
[Tue Jul 21 08:52:54.126658 2026] [security2:error] [pid 533360:tid 533379] [remote 47.128.43.186:37992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "essenceclinicadesaude.com.br"] [uri "/pj-categs/nutricao/"] [unique_id "al9dlnUPuLYrePtEkUcPUgAAnw8"]
[Tue Jul 21 08:52:54.173540 2026] [security2:error] [pid 533360:tid 533548] [client 203.25.124.201:53135] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/uploads/about.php"] [unique_id "al9dlnUPuLYrePtEkUcPVAAAALw"]
[Tue Jul 21 08:52:54.195874 2026] [security2:error] [pid 533360:tid 533597] [client 54.39.203.248:53964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.arcoll.com.br"] [uri "/"] [unique_id "al9dlnUPuLYrePtEkUcPVQAAAO0"]
[Tue Jul 21 08:52:54.195987 2026] [security2:error] [pid 533360:tid 533597] [client 54.39.203.248:53964] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.arcoll.com.br"] [uri "/"] [unique_id "al9dlnUPuLYrePtEkUcPVQAAAO0"]
[Tue Jul 21 08:52:54.228702 2026] [security2:error] [pid 533360:tid 533565] [client 65.21.113.253:46078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dlnUPuLYrePtEkUcPTwAAAM0"]
[Tue Jul 21 08:52:54.571487 2026] [security2:error] [pid 533360:tid 533527] [client 20.151.10.161:49115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/k5.php"] [unique_id "al9dlnUPuLYrePtEkUcPXwAAAKc"]
[Tue Jul 21 08:52:54.677378 2026] [security2:error] [pid 533360:tid 533380] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dlnUPuLYrePtEkUcPYwAAphA"]
[Tue Jul 21 08:52:54.677518 2026] [security2:error] [pid 533360:tid 533526] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dlnUPuLYrePtEkUcPYwAAphA"]
[Tue Jul 21 08:52:54.837614 2026] [security2:error] [pid 533360:tid 533557] [client 113.22.144.139:62631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dlnUPuLYrePtEkUcPawAAAMU"]
[Tue Jul 21 08:52:54.838675 2026] [security2:error] [pid 533360:tid 533557] [client 113.22.144.139:62631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dlnUPuLYrePtEkUcPawAAAMU"]
[Tue Jul 21 08:52:54.945745 2026] [security2:error] [pid 533360:tid 533595] [client 203.25.124.35:41229] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/crop/crop/sitemap-generator.php"] [unique_id "al9dlnUPuLYrePtEkUcPbwAAAOs"]
[Tue Jul 21 08:52:55.265518 2026] [security2:error] [pid 533360:tid 533499] [client 148.113.128.215:25888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "manosorvetes.com.br"] [uri "/robots.txt"] [unique_id "al9dl3UPuLYrePtEkUcPewAAAIs"]
[Tue Jul 21 08:52:55.265627 2026] [security2:error] [pid 533360:tid 533499] [client 148.113.128.215:25888] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "manosorvetes.com.br"] [uri "/robots.txt"] [unique_id "al9dl3UPuLYrePtEkUcPewAAAIs"]
[Tue Jul 21 08:52:55.273709 2026] [security2:error] [pid 533360:tid 533560] [client 203.25.124.254:37427] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/covr-wpcom/assets/fonts/manrope_normal.php"] [unique_id "al9dl3UPuLYrePtEkUcPfAAAAMg"]
[Tue Jul 21 08:52:55.337521 2026] [security2:error] [pid 533360:tid 533520] [client 65.21.113.253:46090] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dlnUPuLYrePtEkUcPbQAAAKA"]
[Tue Jul 21 08:52:55.395522 2026] [security2:error] [pid 533360:tid 533590] [client 20.220.225.223:48202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/edit.php"] [unique_id "al9dl3UPuLYrePtEkUcPgwAAAOY"]
[Tue Jul 21 08:52:55.483311 2026] [security2:error] [pid 533360:tid 533516] [client 20.104.96.117:4094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/core.php"] [unique_id "al9dl3UPuLYrePtEkUcPhwAAAJw"]
[Tue Jul 21 08:52:55.733323 2026] [security2:error] [pid 533360:tid 533572] [client 194.99.104.35:33562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9dl3UPuLYrePtEkUcPjgAAANQ"]
[Tue Jul 21 08:52:55.733443 2026] [security2:error] [pid 533360:tid 533572] [client 194.99.104.35:33562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9dl3UPuLYrePtEkUcPjgAAANQ"]
[Tue Jul 21 08:52:55.789633 2026] [security2:error] [pid 533360:tid 533539] [client 20.220.225.223:22578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9dl3UPuLYrePtEkUcPjwAAALM"]
[Tue Jul 21 08:52:55.831829 2026] [security2:error] [pid 533360:tid 533588] [client 20.220.225.223:23435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/koiy.php"] [unique_id "al9dl3UPuLYrePtEkUcPkAAAAOQ"]
[Tue Jul 21 08:52:55.875637 2026] [security2:error] [pid 533360:tid 533527] [client 20.220.225.223:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9dl3UPuLYrePtEkUcPkQAAAKc"]
[Tue Jul 21 08:52:56.037061 2026] [security2:error] [pid 533360:tid 533515] [client 203.25.124.53:26221] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Requests/Transport/Transport/spam-filter.php"] [unique_id "al9dmHUPuLYrePtEkUcPmwAAAJs"]
[Tue Jul 21 08:52:56.169581 2026] [security2:error] [pid 533360:tid 533381] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dmHUPuLYrePtEkUcPpgAA6BE"]
[Tue Jul 21 08:52:56.169800 2026] [security2:error] [pid 533360:tid 533592] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dmHUPuLYrePtEkUcPpgAA6BE"]
[Tue Jul 21 08:52:56.178038 2026] [security2:error] [pid 533360:tid 533545] [client 212.32.76.55:48893] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/js/privacy-tools.min.php"] [unique_id "al9dmHUPuLYrePtEkUcPpwAAALk"]
[Tue Jul 21 08:52:56.607107 2026] [security2:error] [pid 533360:tid 533410] [remote 5.252.52.249:50370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9dmHUPuLYrePtEkUcPuQAA3C4"]
[Tue Jul 21 08:52:56.662433 2026] [security2:error] [pid 533360:tid 533516] [client 20.104.96.117:4082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/19.php"] [unique_id "al9dmHUPuLYrePtEkUcPvgAAAJw"]
[Tue Jul 21 08:52:56.718697 2026] [security2:error] [pid 533360:tid 533586] [client 54.38.147.210:18544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "manosorvetes.com.br"] [uri "/"] [unique_id "al9dmHUPuLYrePtEkUcPwgAAAOI"]
[Tue Jul 21 08:52:56.718794 2026] [security2:error] [pid 533360:tid 533586] [client 54.38.147.210:18544] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "manosorvetes.com.br"] [uri "/"] [unique_id "al9dmHUPuLYrePtEkUcPwgAAAOI"]
[Tue Jul 21 08:52:57.142656 2026] [security2:error] [pid 533360:tid 533614] [client 212.32.76.2:35291] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/db-status.php"] [unique_id "al9dmXUPuLYrePtEkUcPzQAAAP4"]
[Tue Jul 21 08:52:57.184352 2026] [security2:error] [pid 533360:tid 533557] [client 203.25.124.191:54695] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/options.php"] [unique_id "al9dmXUPuLYrePtEkUcP0gAAAMU"]
[Tue Jul 21 08:52:57.450827 2026] [security2:error] [pid 533360:tid 533544] [client 20.220.225.223:6129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/hp2.php"] [unique_id "al9dmXUPuLYrePtEkUcP3gAAALg"]
[Tue Jul 21 08:52:57.633749 2026] [security2:error] [pid 533360:tid 533474] [remote 148.113.128.77:37938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "powerflats.com.br"] [uri "/robots.txt"] [unique_id "al9dmXUPuLYrePtEkUcP5QAAkW4"]
[Tue Jul 21 08:52:57.633919 2026] [security2:error] [pid 533360:tid 533505] [client 148.113.128.77:37938] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "powerflats.com.br"] [uri "/robots.txt"] [unique_id "al9dmXUPuLYrePtEkUcP5QAAkW4"]
[Tue Jul 21 08:52:57.653127 2026] [security2:error] [pid 533360:tid 533495] [client 20.197.192.193:27092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/nhvoanpl.php"] [unique_id "al9dmXUPuLYrePtEkUcP5gAAAIc"]
[Tue Jul 21 08:52:57.665643 2026] [security2:error] [pid 533360:tid 533500] [client 195.49.128.211:53276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dmXUPuLYrePtEkUcP5wAAAIw"]
[Tue Jul 21 08:52:57.665844 2026] [security2:error] [pid 533360:tid 533500] [client 195.49.128.211:53276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dmXUPuLYrePtEkUcP5wAAAIw"]
[Tue Jul 21 08:52:57.943336 2026] [security2:error] [pid 533360:tid 533586] [client 20.220.225.223:6123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/hp3.php"] [unique_id "al9dmXUPuLYrePtEkUcP8wAAAOI"]
[Tue Jul 21 08:52:57.997046 2026] [security2:error] [pid 533360:tid 533565] [client 20.220.225.223:52219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9dmXUPuLYrePtEkUcP9gAAAM0"]
[Tue Jul 21 08:52:58.083374 2026] [security2:error] [pid 533360:tid 533523] [client 152.59.181.104:59501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dmnUPuLYrePtEkUcP_gAAAKM"]
[Tue Jul 21 08:52:58.083481 2026] [security2:error] [pid 533360:tid 533523] [client 152.59.181.104:59501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dmnUPuLYrePtEkUcP_gAAAKM"]
[Tue Jul 21 08:52:58.138478 2026] [security2:error] [pid 533360:tid 533542] [client 212.32.76.9:59637] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/SimplePie/XML/XML/sitemap-generator.php"] [unique_id "al9dmnUPuLYrePtEkUcQAAAAALY"]
[Tue Jul 21 08:52:58.306384 2026] [security2:error] [pid 533360:tid 533443] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dmnUPuLYrePtEkUcQCAAAzE8"]
[Tue Jul 21 08:52:58.306584 2026] [security2:error] [pid 533360:tid 533564] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dmnUPuLYrePtEkUcQCAAAzE8"]
[Tue Jul 21 08:52:58.420215 2026] [security2:error] [pid 533360:tid 533593] [client 5.38.115.39:28436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dmnUPuLYrePtEkUcQDQAAAOk"]
[Tue Jul 21 08:52:58.420400 2026] [security2:error] [pid 533360:tid 533593] [client 5.38.115.39:28436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dmnUPuLYrePtEkUcQDQAAAOk"]
[Tue Jul 21 08:52:58.857498 2026] [security2:error] [pid 533360:tid 533590] [client 20.220.225.223:6140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/aa1.php"] [unique_id "al9dmnUPuLYrePtEkUcQWAAAAOY"]
[Tue Jul 21 08:52:58.943846 2026] [security2:error] [pid 533360:tid 533512] [client 41.89.234.2:64123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dmnUPuLYrePtEkUcQXAAAAJg"]
[Tue Jul 21 08:52:58.944048 2026] [security2:error] [pid 533360:tid 533512] [client 41.89.234.2:64123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dmnUPuLYrePtEkUcQXAAAAJg"]
[Tue Jul 21 08:52:59.042967 2026] [security2:error] [pid 533360:tid 533516] [client 20.151.10.161:49042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/w.php"] [unique_id "al9dm3UPuLYrePtEkUcQYAAAAJw"]
[Tue Jul 21 08:52:59.067522 2026] [security2:error] [pid 533360:tid 533536] [client 203.25.124.9:28753] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/user/wp-conflg.php"] [unique_id "al9dm3UPuLYrePtEkUcQYQAAALA"]
[Tue Jul 21 08:52:59.187123 2026] [security2:error] [pid 533360:tid 533459] [remote 54.39.89.194:40126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "powerflats.com.br"] [uri "/"] [unique_id "al9dm3UPuLYrePtEkUcQewAAn18"]
[Tue Jul 21 08:52:59.187323 2026] [security2:error] [pid 533360:tid 533519] [client 54.39.89.194:40126] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "powerflats.com.br"] [uri "/"] [unique_id "al9dm3UPuLYrePtEkUcQewAAn18"]
[Tue Jul 21 08:52:59.388153 2026] [security2:error] [pid 533360:tid 533555] [client 20.220.225.223:52194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9dm3UPuLYrePtEkUcQrgAAAMM"]
[Tue Jul 21 08:52:59.445886 2026] [security2:error] [pid 533360:tid 533493] [client 203.25.124.53:22005] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/test.php"] [unique_id "al9dm3UPuLYrePtEkUcQrwAAAIU"]
[Tue Jul 21 08:52:59.534841 2026] [security2:error] [pid 533360:tid 533556] [client 20.220.225.223:6124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/acew67.php"] [unique_id "al9dm3UPuLYrePtEkUcQsQAAAMQ"]
[Tue Jul 21 08:52:59.582614 2026] [security2:error] [pid 533360:tid 533532] [client 20.197.192.193:27142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/inso.php"] [unique_id "al9dm3UPuLYrePtEkUcQsgAAAKw"]
[Tue Jul 21 08:52:59.682187 2026] [security2:error] [pid 533360:tid 533567] [client 49.144.66.253:30121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dm3UPuLYrePtEkUcQwAAAAM8"]
[Tue Jul 21 08:52:59.682280 2026] [security2:error] [pid 533360:tid 533567] [client 49.144.66.253:30121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dm3UPuLYrePtEkUcQwAAAAM8"]
[Tue Jul 21 08:53:00.038786 2026] [security2:error] [pid 533360:tid 533552] [client 194.99.104.35:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9dnHUPuLYrePtEkUcQ3gAAAMA"]
[Tue Jul 21 08:53:00.038931 2026] [security2:error] [pid 533360:tid 533552] [client 194.99.104.35:37842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9dnHUPuLYrePtEkUcQ3gAAAMA"]
[Tue Jul 21 08:53:00.121504 2026] [security2:error] [pid 533360:tid 533395] [remote 72.167.132.114:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9dnHUPuLYrePtEkUcQ4AAAth8"]
[Tue Jul 21 08:53:00.154675 2026] [security2:error] [pid 533360:tid 533545] [client 20.220.225.223:52193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/bscclapb.php"] [unique_id "al9dnHUPuLYrePtEkUcQ4gAAALk"]
[Tue Jul 21 08:53:00.181313 2026] [security2:error] [pid 533360:tid 533562] [client 20.220.225.223:52183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/dp.php"] [unique_id "al9dnHUPuLYrePtEkUcQ5wAAAMo"]
[Tue Jul 21 08:53:00.273485 2026] [security2:error] [pid 533360:tid 533594] [client 203.25.124.193:28379] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/.well-known/"] [unique_id "al9dnHUPuLYrePtEkUcQ-QAAAOo"]
[Tue Jul 21 08:53:00.472295 2026] [security2:error] [pid 533360:tid 533493] [client 20.220.225.223:35109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9dnHUPuLYrePtEkUcRAwAAAIU"]
[Tue Jul 21 08:53:00.529663 2026] [proxy:error] [pid 533360:tid 533607] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:53:00.529744 2026] [proxy_http:error] [pid 533360:tid 533607] [client 147.185.132.135:64542] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:53:00.530422 2026] [proxy:error] [pid 533360:tid 533607] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:53:00.530464 2026] [proxy_http:error] [pid 533360:tid 533607] [client 147.185.132.135:64542] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:53:00.684799 2026] [security2:error] [pid 533360:tid 533364] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dnHUPuLYrePtEkUcRDAAAxgA"]
[Tue Jul 21 08:53:00.684961 2026] [security2:error] [pid 533360:tid 533558] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dnHUPuLYrePtEkUcRDAAAxgA"]
[Tue Jul 21 08:53:00.838129 2026] [security2:error] [pid 533360:tid 533507] [client 203.25.124.47:28073] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/jquery/ui/ui/forum-engine.php"] [unique_id "al9dnHUPuLYrePtEkUcREQAAAJM"]
[Tue Jul 21 08:53:00.974516 2026] [security2:error] [pid 533360:tid 533506] [client 212.32.76.55:24163] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-configs.php"] [unique_id "al9dnHUPuLYrePtEkUcRGQAAAJI"]
[Tue Jul 21 08:53:00.994592 2026] [security2:error] [pid 533360:tid 533518] [client 20.151.10.161:49027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/fpwch.php"] [unique_id "al9dnHUPuLYrePtEkUcRGgAAAJ4"]
[Tue Jul 21 08:53:01.023782 2026] [security2:error] [pid 533360:tid 533561] [client 20.104.96.117:4009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/inc.php"] [unique_id "al9dnXUPuLYrePtEkUcRHAAAAMk"]
[Tue Jul 21 08:53:01.084771 2026] [security2:error] [pid 533360:tid 533608] [client 182.189.99.211:47971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dnXUPuLYrePtEkUcRHQAAAPg"]
[Tue Jul 21 08:53:01.084949 2026] [security2:error] [pid 533360:tid 533608] [client 182.189.99.211:47971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dnXUPuLYrePtEkUcRHQAAAPg"]
[Tue Jul 21 08:53:01.132901 2026] [security2:error] [pid 533360:tid 533552] [client 20.220.225.223:6090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/else1.php"] [unique_id "al9dnXUPuLYrePtEkUcRHwAAAMA"]
[Tue Jul 21 08:53:01.229136 2026] [security2:error] [pid 533360:tid 533494] [client 20.220.225.223:6105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/old.php"] [unique_id "al9dnXUPuLYrePtEkUcRMAAAAIY"]
[Tue Jul 21 08:53:01.309513 2026] [security2:error] [pid 533360:tid 533449] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dnXUPuLYrePtEkUcRNgAAt1U"]
[Tue Jul 21 08:53:01.309685 2026] [security2:error] [pid 533360:tid 533543] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dnXUPuLYrePtEkUcRNgAAt1U"]
[Tue Jul 21 08:53:01.742026 2026] [security2:error] [pid 533360:tid 533609] [client 20.220.225.223:22534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/dp.php"] [unique_id "al9dnXUPuLYrePtEkUcRRwAAAPk"]
[Tue Jul 21 08:53:01.875968 2026] [security2:error] [pid 533360:tid 533592] [client 203.25.124.198:61911] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/class.php"] [unique_id "al9dnXUPuLYrePtEkUcRTgAAAOg"]
[Tue Jul 21 08:53:01.947774 2026] [security2:error] [pid 533360:tid 533495] [client 203.25.124.213:63829] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/tinymce/plugins/ms-files.php"] [unique_id "al9dnXUPuLYrePtEkUcRWQAAAIc"]
[Tue Jul 21 08:53:02.155099 2026] [security2:error] [pid 533360:tid 533619] [client 20.220.225.223:23473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/ms-new.php"] [unique_id "al9dnnUPuLYrePtEkUcRXgAAAQM"]
[Tue Jul 21 08:53:02.165088 2026] [security2:error] [pid 533360:tid 533549] [client 20.220.225.223:52186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/tkikikoko.php"] [unique_id "al9dnnUPuLYrePtEkUcRXwAAAL0"]
[Tue Jul 21 08:53:02.493929 2026] [security2:error] [pid 533360:tid 533584] [client 65.21.113.253:54140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dnnUPuLYrePtEkUcRagAAAOA"]
[Tue Jul 21 08:53:02.766444 2026] [security2:error] [pid 533360:tid 533531] [client 20.220.225.223:6132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wp-Blogs.php"] [unique_id "al9dnnUPuLYrePtEkUcRegAAAKs"]
[Tue Jul 21 08:53:02.771099 2026] [security2:error] [pid 533360:tid 533564] [client 212.32.76.57:52675] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Text/Diff/Engine/"] [unique_id "al9dnnUPuLYrePtEkUcRfAAAAMw"]
[Tue Jul 21 08:53:02.847984 2026] [security2:error] [pid 533360:tid 533398] [remote 104.207.39.237:42257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.39.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9dnnUPuLYrePtEkUcReQAAzSI"]
[Tue Jul 21 08:53:02.975544 2026] [security2:error] [pid 533360:tid 533592] [client 20.220.225.223:23463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/track.php"] [unique_id "al9dnnUPuLYrePtEkUcRjwAAAOg"]
[Tue Jul 21 08:53:03.202858 2026] [security2:error] [pid 533360:tid 533419] [remote 57.141.18.42:23998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9dn3UPuLYrePtEkUcRkQAA0Dc"]
[Tue Jul 21 08:53:03.239044 2026] [security2:error] [pid 533360:tid 533608] [client 203.25.124.55:37699] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/includes/includes/logo/se.php"] [unique_id "al9dn3UPuLYrePtEkUcRuQAAAPg"]
[Tue Jul 21 08:53:03.286223 2026] [security2:error] [pid 533360:tid 533552] [client 20.151.10.161:49030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/w2025.php"] [unique_id "al9dn3UPuLYrePtEkUcRvAAAAMA"]
[Tue Jul 21 08:53:03.516605 2026] [security2:error] [pid 533360:tid 533508] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dn3UPuLYrePtEkUcRxAAAlGA"]
[Tue Jul 21 08:53:03.626213 2026] [security2:error] [pid 533360:tid 533567] [client 65.21.113.253:45114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dn3UPuLYrePtEkUcRlAAAAM8"]
[Tue Jul 21 08:53:03.664894 2026] [security2:error] [pid 533360:tid 533512] [client 59.95.197.55:61634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dn3UPuLYrePtEkUcRyQAAAJg"]
[Tue Jul 21 08:53:03.665537 2026] [security2:error] [pid 533360:tid 533512] [client 59.95.197.55:61634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dn3UPuLYrePtEkUcRyQAAAJg"]
[Tue Jul 21 08:53:03.698267 2026] [security2:error] [pid 533360:tid 533604] [client 20.220.225.223:52182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wp-css.php"] [unique_id "al9dn3UPuLYrePtEkUcRygAAAPQ"]
[Tue Jul 21 08:53:03.699379 2026] [security2:error] [pid 533360:tid 533498] [client 20.220.225.223:23468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/2352356666.php"] [unique_id "al9dn3UPuLYrePtEkUcRywAAAIo"]
[Tue Jul 21 08:53:03.838593 2026] [security2:error] [pid 533360:tid 533561] [client 122.176.100.127:63422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dn3UPuLYrePtEkUcRzwAAAMk"]
[Tue Jul 21 08:53:03.838853 2026] [security2:error] [pid 533360:tid 533561] [client 122.176.100.127:63422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dn3UPuLYrePtEkUcRzwAAAMk"]
[Tue Jul 21 08:53:04.069647 2026] [security2:error] [pid 533360:tid 533522] [client 20.151.10.161:49101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/scxy.php"] [unique_id "al9doHUPuLYrePtEkUcR2wAAAKI"]
[Tue Jul 21 08:53:04.182356 2026] [security2:error] [pid 533360:tid 533565] [client 114.198.138.124:56596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9doHUPuLYrePtEkUcR3gAAAM0"]
[Tue Jul 21 08:53:04.182454 2026] [security2:error] [pid 533360:tid 533565] [client 114.198.138.124:56596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9doHUPuLYrePtEkUcR3gAAAM0"]
[Tue Jul 21 08:53:04.436145 2026] [security2:error] [pid 533360:tid 533507] [client 168.167.81.163:59510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9doHUPuLYrePtEkUcR5QAAAJM"]
[Tue Jul 21 08:53:04.436279 2026] [security2:error] [pid 533360:tid 533507] [client 168.167.81.163:59510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9doHUPuLYrePtEkUcR5QAAAJM"]
[Tue Jul 21 08:53:04.472635 2026] [security2:error] [pid 533360:tid 533558] [client 212.32.76.62:60613] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/content.php"] [unique_id "al9doHUPuLYrePtEkUcR5gAAAMY"]
[Tue Jul 21 08:53:04.527416 2026] [security2:error] [pid 533360:tid 533549] [client 203.25.124.52:38965] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/widgets/shadow-bot.php"] [unique_id "al9doHUPuLYrePtEkUcR7wAAAL0"]
[Tue Jul 21 08:53:04.748204 2026] [security2:error] [pid 533360:tid 533576] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9doHUPuLYrePtEkUcR8gAA2C4"]
[Tue Jul 21 08:53:04.914207 2026] [security2:error] [pid 533360:tid 533534] [client 20.220.225.223:6103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/pn.php"] [unique_id "al9doHUPuLYrePtEkUcR_AAAAK4"]
[Tue Jul 21 08:53:04.914258 2026] [security2:error] [pid 533360:tid 533533] [client 20.220.225.223:6094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wp-explorer.php"] [unique_id "al9doHUPuLYrePtEkUcR_QAAAK0"]
[Tue Jul 21 08:53:05.342281 2026] [security2:error] [pid 533360:tid 533413] [remote 45.79.123.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9doXUPuLYrePtEkUcSHAAAmzE"]
[Tue Jul 21 08:53:05.342418 2026] [security2:error] [pid 533360:tid 533515] [client 45.79.123.44:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9doXUPuLYrePtEkUcSHAAAmzE"]
[Tue Jul 21 08:53:05.436691 2026] [core:alert] [pid 533360:tid 533507] [client 66.249.92.139:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:53:05.438604 2026] [security2:error] [pid 533360:tid 533596] [client 20.220.225.223:6080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wp-wpbak.php"] [unique_id "al9doXUPuLYrePtEkUcSIwAAAOw"]
[Tue Jul 21 08:53:05.468220 2026] [security2:error] [pid 533360:tid 533550] [client 20.220.225.223:23446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/akismet.php"] [unique_id "al9doXUPuLYrePtEkUcSJAAAAL4"]
[Tue Jul 21 08:53:05.572484 2026] [security2:error] [pid 533360:tid 533538] [client 212.32.76.65:34779] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/css/dist/block-library/"] [unique_id "al9doXUPuLYrePtEkUcSKQAAALI"]
[Tue Jul 21 08:53:05.596182 2026] [security2:error] [pid 533360:tid 533454] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9doXUPuLYrePtEkUcSKgAAo1o"]
[Tue Jul 21 08:53:05.596333 2026] [security2:error] [pid 533360:tid 533523] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9doXUPuLYrePtEkUcSKgAAo1o"]
[Tue Jul 21 08:53:05.756209 2026] [security2:error] [pid 533360:tid 533526] [client 113.22.144.139:63167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9doXUPuLYrePtEkUcSLgAAAKY"]
[Tue Jul 21 08:53:05.756949 2026] [security2:error] [pid 533360:tid 533526] [client 113.22.144.139:63167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9doXUPuLYrePtEkUcSLgAAAKY"]
[Tue Jul 21 08:53:06.006719 2026] [security2:error] [pid 533360:tid 533429] [remote 65.111.2.13:62503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.2.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9doXUPuLYrePtEkUcSMAAAnUE"]
[Tue Jul 21 08:53:06.036604 2026] [security2:error] [pid 533360:tid 533585] [client 20.151.10.161:49051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/FWAZ.php"] [unique_id "al9donUPuLYrePtEkUcSNwAAAOE"]
[Tue Jul 21 08:53:06.062963 2026] [security2:error] [pid 533360:tid 533546] [client 20.220.225.223:59143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/dr.php"] [unique_id "al9donUPuLYrePtEkUcSOwAAALo"]
[Tue Jul 21 08:53:06.143154 2026] [security2:error] [pid 533360:tid 533614] [client 20.220.225.223:23487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/ace2.php"] [unique_id "al9donUPuLYrePtEkUcSPwAAAP4"]
[Tue Jul 21 08:53:06.244468 2026] [security2:error] [pid 533360:tid 533509] [client 20.197.192.193:27191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wpx.php"] [unique_id "al9donUPuLYrePtEkUcSQgAAAJU"]
[Tue Jul 21 08:53:06.380670 2026] [security2:error] [pid 533360:tid 533499] [client 203.25.124.7:36259] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/post-terms/"] [unique_id "al9donUPuLYrePtEkUcSRAAAAIs"]
[Tue Jul 21 08:53:06.737256 2026] [security2:error] [pid 533360:tid 533610] [client 203.25.124.41:30153] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/login.php"] [unique_id "al9donUPuLYrePtEkUcSWAAAAPo"]
[Tue Jul 21 08:53:06.925960 2026] [security2:error] [pid 533360:tid 533551] [client 74.7.228.21:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "tamiresalvesdacosta1782320990238.0711679.meusitehostgator.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9donUPuLYrePtEkUcSWQAAvzc"]
[Tue Jul 21 08:53:07.100184 2026] [security2:error] [pid 533360:tid 533375] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9do3UPuLYrePtEkUcSZQAAows"]
[Tue Jul 21 08:53:07.100342 2026] [security2:error] [pid 533360:tid 533523] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9do3UPuLYrePtEkUcSZQAAows"]
[Tue Jul 21 08:53:07.134701 2026] [security2:error] [pid 533360:tid 533604] [client 20.104.96.117:4088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-ppoxua4.php"] [unique_id "al9do3UPuLYrePtEkUcSZgAAAPQ"]
[Tue Jul 21 08:53:07.171782 2026] [security2:error] [pid 533360:tid 533535] [client 203.25.124.7:55261] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/b.php"] [unique_id "al9do3UPuLYrePtEkUcSaAAAAK8"]
[Tue Jul 21 08:53:07.239365 2026] [security2:error] [pid 533360:tid 533614] [client 65.21.113.253:54140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9do3UPuLYrePtEkUcSagAAAP4"]
[Tue Jul 21 08:53:07.438979 2026] [security2:error] [pid 533360:tid 533593] [client 203.25.124.211:26695] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/well-known/index.php"] [unique_id "al9do3UPuLYrePtEkUcSfgAAAOk"]
[Tue Jul 21 08:53:07.443438 2026] [security2:error] [pid 533360:tid 533574] [client 20.220.225.223:23483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/ms.php"] [unique_id "al9do3UPuLYrePtEkUcSfwAAANY"]
[Tue Jul 21 08:53:07.447015 2026] [security2:error] [pid 533360:tid 533579] [client 20.220.225.223:23445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/2x.php"] [unique_id "al9do3UPuLYrePtEkUcSgAAAANs"]
[Tue Jul 21 08:53:08.139221 2026] [security2:error] [pid 533360:tid 533599] [client 20.151.10.161:49132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/qterm.php"] [unique_id "al9dpHUPuLYrePtEkUcSkwAAAO8"]
[Tue Jul 21 08:53:08.170347 2026] [security2:error] [pid 533360:tid 533559] [client 212.32.76.63:31045] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/blocks/audio/"] [unique_id "al9dpHUPuLYrePtEkUcSmAAAAMc"]
[Tue Jul 21 08:53:08.223705 2026] [security2:error] [pid 533360:tid 533536] [client 195.49.128.211:53872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dpHUPuLYrePtEkUcSmwAAALA"]
[Tue Jul 21 08:53:08.223855 2026] [security2:error] [pid 533360:tid 533536] [client 195.49.128.211:53872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9dpHUPuLYrePtEkUcSmwAAALA"]
[Tue Jul 21 08:53:08.294971 2026] [security2:error] [pid 533360:tid 533550] [client 65.21.113.253:45130] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9do3UPuLYrePtEkUcSjwAAAL4"]
[Tue Jul 21 08:53:08.441978 2026] [security2:error] [pid 533360:tid 533534] [client 20.220.225.223:59193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/kq1.php"] [unique_id "al9dpHUPuLYrePtEkUcSowAAAK4"]
[Tue Jul 21 08:53:08.657285 2026] [security2:error] [pid 533360:tid 533499] [client 203.25.124.67:46887] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/backup.php"] [unique_id "al9dpHUPuLYrePtEkUcSrQAAAIs"]
[Tue Jul 21 08:53:08.758874 2026] [security2:error] [pid 533360:tid 533560] [client 74.7.175.185:57250] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.solucoesdeti.com"] [uri "/robots.txt"] [unique_id "al9dpHUPuLYrePtEkUcSswAAyDA"]
[Tue Jul 21 08:53:08.809967 2026] [security2:error] [pid 533360:tid 533381] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dpHUPuLYrePtEkUcStQAArxE"]
[Tue Jul 21 08:53:08.810134 2026] [security2:error] [pid 533360:tid 533535] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dpHUPuLYrePtEkUcStQAArxE"]
[Tue Jul 21 08:53:08.848917 2026] [security2:error] [pid 533360:tid 533552] [client 152.59.181.104:4870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dpHUPuLYrePtEkUcStgAAAMA"]
[Tue Jul 21 08:53:08.849096 2026] [security2:error] [pid 533360:tid 533552] [client 152.59.181.104:4870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dpHUPuLYrePtEkUcStgAAAMA"]
[Tue Jul 21 08:53:08.924525 2026] [security2:error] [pid 533360:tid 533501] [client 45.8.19.169:20105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.19.8.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "luanaarruda.com"] [uri "/wp-login.php"] [unique_id "al9dpHUPuLYrePtEkUcStwAAAI0"]
[Tue Jul 21 08:53:09.119615 2026] [security2:error] [pid 533360:tid 533585] [client 5.38.115.39:62443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dpXUPuLYrePtEkUcSvgAAAOE"]
[Tue Jul 21 08:53:09.119735 2026] [security2:error] [pid 533360:tid 533585] [client 5.38.115.39:62443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dpXUPuLYrePtEkUcSvgAAAOE"]
[Tue Jul 21 08:53:09.173448 2026] [security2:error] [pid 533360:tid 533580] [client 203.25.124.208:22513] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/class-db.php"] [unique_id "al9dpXUPuLYrePtEkUcS0QAAANw"]
[Tue Jul 21 08:53:09.193244 2026] [security2:error] [pid 533360:tid 533608] [client 20.220.225.223:22571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/old.php"] [unique_id "al9dpXUPuLYrePtEkUcS1AAAAPg"]
[Tue Jul 21 08:53:09.349806 2026] [security2:error] [pid 533360:tid 533619] [client 203.25.124.68:23711] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/user/freedoms-old.php"] [unique_id "al9dpXUPuLYrePtEkUcS2AAAAQM"]
[Tue Jul 21 08:53:09.392824 2026] [security2:error] [pid 533360:tid 533581] [client 173.252.95.14:52220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dpXUPuLYrePtEkUcS2QAAAN0"]
[Tue Jul 21 08:53:09.487029 2026] [security2:error] [pid 533360:tid 533592] [client 173.252.95.24:64672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dpXUPuLYrePtEkUcS2gAAAOg"]
[Tue Jul 21 08:53:09.534087 2026] [security2:error] [pid 533360:tid 533599] [client 20.151.10.161:49149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/blurbs.php"] [unique_id "al9dpXUPuLYrePtEkUcS2wAAAO8"]
[Tue Jul 21 08:53:09.577232 2026] [security2:error] [pid 533360:tid 533507] [client 41.89.234.2:64590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dpXUPuLYrePtEkUcS3AAAAJM"]
[Tue Jul 21 08:53:09.577365 2026] [security2:error] [pid 533360:tid 533507] [client 41.89.234.2:64590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dpXUPuLYrePtEkUcS3AAAAJM"]
[Tue Jul 21 08:53:09.764294 2026] [security2:error] [pid 533360:tid 533553] [client 20.220.225.223:23430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/zzz.php"] [unique_id "al9dpXUPuLYrePtEkUcS7AAAAME"]
[Tue Jul 21 08:53:10.268596 2026] [security2:error] [pid 533360:tid 533575] [client 203.25.124.200:42763] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/readme.php"] [unique_id "al9dpnUPuLYrePtEkUcTAAAAANc"]
[Tue Jul 21 08:53:10.415032 2026] [security2:error] [pid 533360:tid 533524] [client 20.151.10.161:55858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9dpnUPuLYrePtEkUcTBwAAAKQ"]
[Tue Jul 21 08:53:10.506958 2026] [security2:error] [pid 533360:tid 533520] [client 49.144.66.253:30572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dpnUPuLYrePtEkUcTCQAAAKA"]
[Tue Jul 21 08:53:10.507109 2026] [security2:error] [pid 533360:tid 533520] [client 49.144.66.253:30572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dpnUPuLYrePtEkUcTCQAAAKA"]
[Tue Jul 21 08:53:10.539620 2026] [security2:error] [pid 533360:tid 533580] [client 203.25.124.74:37411] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/post-author-name-path.php"] [unique_id "al9dpnUPuLYrePtEkUcTCwAAANw"]
[Tue Jul 21 08:53:10.563041 2026] [security2:error] [pid 533360:tid 533554] [client 209.141.34.121:51583] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "lirioshoppy.com.br"] [uri "/"] [unique_id "al9dpnUPuLYrePtEkUcTDAAAAMI"]
[Tue Jul 21 08:53:10.730402 2026] [security2:error] [pid 533360:tid 533474] [remote 192.241.143.148:58624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/wp-login.php"] [unique_id "al9dpnUPuLYrePtEkUcTIwAAmW4"]
[Tue Jul 21 08:53:10.875605 2026] [security2:error] [pid 533360:tid 533501] [client 182.189.99.211:48443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dpnUPuLYrePtEkUcTLQAAAI0"]
[Tue Jul 21 08:53:10.875704 2026] [security2:error] [pid 533360:tid 533501] [client 182.189.99.211:48443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dpnUPuLYrePtEkUcTLQAAAI0"]
[Tue Jul 21 08:53:11.078272 2026] [security2:error] [pid 533360:tid 533510] [client 209.141.34.121:51618] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "lirioshoppy.com.br"] [uri "/"] [unique_id "al9dp3UPuLYrePtEkUcTMwAAAJY"]
[Tue Jul 21 08:53:11.212711 2026] [security2:error] [pid 533360:tid 533438] [remote 117.212.93.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.93.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dp3UPuLYrePtEkUcTOAAAsEo"]
[Tue Jul 21 08:53:11.212898 2026] [security2:error] [pid 533360:tid 533536] [client 117.212.93.20:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9dp3UPuLYrePtEkUcTOAAAsEo"]
[Tue Jul 21 08:53:11.468429 2026] [security2:error] [pid 533360:tid 533580] [client 203.25.124.204:51199] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/files/index.php"] [unique_id "al9dp3UPuLYrePtEkUcTRQAAANw"]
[Tue Jul 21 08:53:11.602003 2026] [security2:error] [pid 533360:tid 533539] [client 20.151.10.161:49044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/v543.php"] [unique_id "al9dp3UPuLYrePtEkUcTSwAAALM"]
[Tue Jul 21 08:53:11.720234 2026] [security2:error] [pid 533360:tid 533611] [client 20.220.225.223:52199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wicked.php"] [unique_id "al9dp3UPuLYrePtEkUcTUAAAAPs"]
[Tue Jul 21 08:53:11.885186 2026] [security2:error] [pid 533360:tid 533402] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dp3UPuLYrePtEkUcTVQAAjCY"]
[Tue Jul 21 08:53:11.885400 2026] [security2:error] [pid 533360:tid 533500] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dp3UPuLYrePtEkUcTVQAAjCY"]
[Tue Jul 21 08:53:12.130535 2026] [security2:error] [pid 533360:tid 533598] [client 198.44.157.162:50978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9dqHUPuLYrePtEkUcTWgAAAO4"]
[Tue Jul 21 08:53:12.130638 2026] [security2:error] [pid 533360:tid 533598] [client 198.44.157.162:50978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9dqHUPuLYrePtEkUcTWgAAAO4"]
[Tue Jul 21 08:53:12.405947 2026] [security2:error] [pid 533360:tid 533491] [remote 45.3.44.9:38791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9dqHUPuLYrePtEkUcTXgABAX8"]
[Tue Jul 21 08:53:12.473050 2026] [security2:error] [pid 533360:tid 533574] [client 212.32.76.55:21171] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Text/index.php"] [unique_id "al9dqHUPuLYrePtEkUcTZwAAANY"]
[Tue Jul 21 08:53:12.837793 2026] [security2:error] [pid 533360:tid 533570] [client 212.32.76.13:42157] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/class-wp-error-character.php"] [unique_id "al9dqHUPuLYrePtEkUcTngAAANI"]
[Tue Jul 21 08:53:12.908541 2026] [security2:error] [pid 533360:tid 533459] [remote 192.241.143.148:41882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9dqHUPuLYrePtEkUcTpAAAkV8"]
[Tue Jul 21 08:53:12.963397 2026] [security2:error] [pid 533360:tid 533500] [client 20.104.96.117:4048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-u3nxbvx.php"] [unique_id "al9dqHUPuLYrePtEkUcTpQAAAIw"]
[Tue Jul 21 08:53:12.977537 2026] [security2:error] [pid 533360:tid 533615] [client 20.220.225.223:6107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/edit.php"] [unique_id "al9dqHUPuLYrePtEkUcTpgAAAP8"]
[Tue Jul 21 08:53:13.032185 2026] [security2:error] [pid 533360:tid 533527] [client 20.151.10.161:49117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/w3lls.php"] [unique_id "al9dqXUPuLYrePtEkUcTpwAAAKc"]
[Tue Jul 21 08:53:13.780058 2026] [security2:error] [pid 533360:tid 533515] [client 20.220.225.223:23486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/kua.php"] [unique_id "al9dqXUPuLYrePtEkUcT1QAAAJs"]
[Tue Jul 21 08:53:13.975906 2026] [security2:error] [pid 533360:tid 533611] [client 203.25.124.9:63789] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/js/"] [unique_id "al9dqXUPuLYrePtEkUcT3wAAAPs"]
[Tue Jul 21 08:53:14.134478 2026] [security2:error] [pid 533360:tid 533613] [client 203.25.124.35:25735] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-cron-element.php"] [unique_id "al9dqnUPuLYrePtEkUcT7gAAAP0"]
[Tue Jul 21 08:53:14.141908 2026] [security2:error] [pid 533360:tid 533522] [client 59.95.197.55:62117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dqnUPuLYrePtEkUcT7wAAAKI"]
[Tue Jul 21 08:53:14.142019 2026] [security2:error] [pid 533360:tid 533522] [client 59.95.197.55:62117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dqnUPuLYrePtEkUcT7wAAAKI"]
[Tue Jul 21 08:53:14.223965 2026] [security2:error] [pid 533360:tid 533538] [client 20.220.225.223:23444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/ez.php"] [unique_id "al9dqnUPuLYrePtEkUcT8AAAALI"]
[Tue Jul 21 08:53:14.304124 2026] [security2:error] [pid 533360:tid 533475] [remote 188.164.197.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "extrapro21.com"] [uri "/wp-login.php"] [unique_id "al9dqnUPuLYrePtEkUcT8wAA0G8"]
[Tue Jul 21 08:53:14.316847 2026] [security2:error] [pid 533360:tid 533580] [client 122.176.100.127:63886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.100.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dqnUPuLYrePtEkUcT9AAAANw"]
[Tue Jul 21 08:53:14.317088 2026] [security2:error] [pid 533360:tid 533580] [client 122.176.100.127:63886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "albuquerqueeharo.com"] [uri "/xmlrpc.php"] [unique_id "al9dqnUPuLYrePtEkUcT9AAAANw"]
[Tue Jul 21 08:53:14.705274 2026] [security2:error] [pid 533360:tid 533595] [client 114.198.138.124:57174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dqnUPuLYrePtEkUcUAwAAAOs"]
[Tue Jul 21 08:53:14.705398 2026] [security2:error] [pid 533360:tid 533595] [client 114.198.138.124:57174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dqnUPuLYrePtEkUcUAwAAAOs"]
[Tue Jul 21 08:53:14.707029 2026] [security2:error] [pid 533360:tid 533597] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dqnUPuLYrePtEkUcT_wAA7Q0"]
[Tue Jul 21 08:53:14.834925 2026] [security2:error] [pid 533360:tid 533576] [client 20.220.225.223:52196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/fz.php"] [unique_id "al9dqnUPuLYrePtEkUcUCwAAANg"]
[Tue Jul 21 08:53:14.906795 2026] [security2:error] [pid 533360:tid 533573] [client 172.236.244.218:41610] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "jorgecostaadvogados.com"] [uri "/wp-json/batch/v1"] [unique_id "al9dqnUPuLYrePtEkUcUDAAAANU"]
[Tue Jul 21 08:53:15.027357 2026] [security2:error] [pid 533360:tid 533584] [client 20.151.10.161:49034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-ws68.php"] [unique_id "al9dq3UPuLYrePtEkUcUFQAAAOA"]
[Tue Jul 21 08:53:15.073873 2026] [security2:error] [pid 533360:tid 533618] [client 203.25.124.206:39981] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-includes/Requests/library/"] [unique_id "al9dq3UPuLYrePtEkUcUFwAAAQI"]
[Tue Jul 21 08:53:15.076170 2026] [security2:error] [pid 533360:tid 533533] [client 172.236.244.218:41610] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "jorgecostaadvogados.com"] [uri "/"] [unique_id "al9dq3UPuLYrePtEkUcUFgAAAK0"]
[Tue Jul 21 08:53:15.343357 2026] [security2:error] [pid 533360:tid 533499] [client 203.25.124.53:22095] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/sitemaps/chosen.php"] [unique_id "al9dq3UPuLYrePtEkUcUIAAAAIs"]
[Tue Jul 21 08:53:15.585440 2026] [security2:error] [pid 533360:tid 533602] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dq3UPuLYrePtEkUcUJwAA8iQ"]
[Tue Jul 21 08:53:15.631650 2026] [security2:error] [pid 533360:tid 533564] [client 65.21.113.253:43872] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dq3UPuLYrePtEkUcUMgAAAMw"]
[Tue Jul 21 08:53:15.831970 2026] [security2:error] [pid 533360:tid 533528] [client 20.220.225.223:60263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/ez.php"] [unique_id "al9dq3UPuLYrePtEkUcUNwAAAKg"]
[Tue Jul 21 08:53:15.879268 2026] [security2:error] [pid 533360:tid 533554] [client 203.25.124.184:56095] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/twentytwentyfour/"] [unique_id "al9dq3UPuLYrePtEkUcUOAAAAMI"]
[Tue Jul 21 08:53:15.916469 2026] [security2:error] [pid 533360:tid 533597] [client 20.220.225.223:59167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/la.php"] [unique_id "al9dq3UPuLYrePtEkUcUOgAAAO0"]
[Tue Jul 21 08:53:15.944075 2026] [security2:error] [pid 533360:tid 533520] [client 168.167.81.163:59556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dq3UPuLYrePtEkUcUPgAAAKA"]
[Tue Jul 21 08:53:15.944220 2026] [security2:error] [pid 533360:tid 533520] [client 168.167.81.163:59556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dq3UPuLYrePtEkUcUPgAAAKA"]
[Tue Jul 21 08:53:16.286759 2026] [security2:error] [pid 533360:tid 533457] [remote 188.95.113.76:50680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "companhiatop.com.br"] [uri "/wp-login.php"] [unique_id "al9drHUPuLYrePtEkUcURgABA10"]
[Tue Jul 21 08:53:16.431115 2026] [security2:error] [pid 533360:tid 533404] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9drHUPuLYrePtEkUcUTQAAkSg"]
[Tue Jul 21 08:53:16.431314 2026] [security2:error] [pid 533360:tid 533505] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9drHUPuLYrePtEkUcUTQAAkSg"]
[Tue Jul 21 08:53:16.455643 2026] [security2:error] [pid 533360:tid 533539] [client 203.25.124.33:22057] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/antiperfo.php"] [unique_id "al9drHUPuLYrePtEkUcUTgAAALM"]
[Tue Jul 21 08:53:16.470903 2026] [security2:error] [pid 533360:tid 533592] [client 113.22.144.139:63698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9drHUPuLYrePtEkUcUTwAAAOg"]
[Tue Jul 21 08:53:16.471093 2026] [security2:error] [pid 533360:tid 533592] [client 113.22.144.139:63698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9drHUPuLYrePtEkUcUTwAAAOg"]
[Tue Jul 21 08:53:16.621254 2026] [security2:error] [pid 533360:tid 533548] [client 20.220.225.223:23424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/nhvoanpl.php"] [unique_id "al9drHUPuLYrePtEkUcUVgAAALw"]
[Tue Jul 21 08:53:16.724785 2026] [security2:error] [pid 533360:tid 533546] [client 65.21.113.253:35456] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9drHUPuLYrePtEkUcURwAAALo"]
[Tue Jul 21 08:53:16.972181 2026] [security2:error] [pid 533360:tid 533502] [client 203.25.124.180:57071] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-content/themes/radio.php"] [unique_id "al9drHUPuLYrePtEkUcUXgAAAI4"]
[Tue Jul 21 08:53:17.287650 2026] [autoindex:error] [pid 533360:tid 533515] [client 44.220.233.148:46788] AH01276: Cannot serve directory /home3/eslang81/sistema/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:53:17.601039 2026] [security2:error] [pid 533360:tid 533594] [client 20.151.10.161:49029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/xyn.php"] [unique_id "al9drXUPuLYrePtEkUcUeQAAAOo"]
[Tue Jul 21 08:53:17.686292 2026] [security2:error] [pid 533360:tid 533516] [client 20.220.225.223:19685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/cron-tab.php"] [unique_id "al9drXUPuLYrePtEkUcUegAAAJw"]
[Tue Jul 21 08:53:17.774144 2026] [security2:error] [pid 533360:tid 533500] [client 212.32.76.54:41923] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/shell.php"] [unique_id "al9drXUPuLYrePtEkUcUfAAAAIw"]
[Tue Jul 21 08:53:17.947216 2026] [security2:error] [pid 533360:tid 533538] [client 212.32.76.12:46143] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/blog-stream/inc/upgrade-to-pro/section-pro.php"] [unique_id "al9drXUPuLYrePtEkUcUfgAAALI"]
[Tue Jul 21 08:53:18.055638 2026] [security2:error] [pid 533360:tid 533439] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9drnUPuLYrePtEkUcUgAAA5ks"]
[Tue Jul 21 08:53:18.055765 2026] [security2:error] [pid 533360:tid 533590] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9drnUPuLYrePtEkUcUgAAA5ks"]
[Tue Jul 21 08:53:18.933967 2026] [security2:error] [pid 533360:tid 533543] [client 195.49.128.211:54481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.128.49.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9drnUPuLYrePtEkUcUmwAAALc"]
[Tue Jul 21 08:53:18.934101 2026] [security2:error] [pid 533360:tid 533543] [client 195.49.128.211:54481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "espacofabula.com"] [uri "/xmlrpc.php"] [unique_id "al9drnUPuLYrePtEkUcUmwAAALc"]
[Tue Jul 21 08:53:18.971725 2026] [security2:error] [pid 533360:tid 533524] [client 203.25.124.202:36025] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fgengenharia.eng.br"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "al9drnUPuLYrePtEkUcUnQAAAKQ"]
[Tue Jul 21 08:53:19.194097 2026] [security2:error] [pid 533360:tid 533376] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dr3UPuLYrePtEkUcUpQAAvgw"]
[Tue Jul 21 08:53:19.194211 2026] [security2:error] [pid 533360:tid 533550] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dr3UPuLYrePtEkUcUpQAAvgw"]
[Tue Jul 21 08:53:19.250841 2026] [security2:error] [pid 533360:tid 533516] [client 20.220.225.223:23462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/inso.php"] [unique_id "al9dr3UPuLYrePtEkUcUqAAAAJw"]
[Tue Jul 21 08:53:19.285479 2026] [security2:error] [pid 533360:tid 533562] [client 128.127.105.184:53132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9dr3UPuLYrePtEkUcUrQAAAMo"]
[Tue Jul 21 08:53:19.285590 2026] [security2:error] [pid 533360:tid 533562] [client 128.127.105.184:53132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9dr3UPuLYrePtEkUcUrQAAAMo"]
[Tue Jul 21 08:53:19.508063 2026] [core:error] [pid 533360:tid 533523] [client 66.249.66.69:41124] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:53:19.508092 2026] [core:error] [pid 533360:tid 533523] [client 66.249.66.69:41124] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:53:19.527670 2026] [security2:error] [pid 533360:tid 533506] [client 152.59.181.104:60464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dr3UPuLYrePtEkUcUsQAAAJI"]
[Tue Jul 21 08:53:19.527893 2026] [security2:error] [pid 533360:tid 533506] [client 152.59.181.104:60464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dr3UPuLYrePtEkUcUsQAAAJI"]
[Tue Jul 21 08:53:19.571166 2026] [security2:error] [pid 533360:tid 533547] [client 173.252.95.39:35018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dr3UPuLYrePtEkUcUsgAAALs"]
[Tue Jul 21 08:53:19.619468 2026] [security2:error] [pid 533360:tid 533510] [client 128.127.105.184:53148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9dr3UPuLYrePtEkUcUuQAAAJY"]
[Tue Jul 21 08:53:19.619596 2026] [security2:error] [pid 533360:tid 533510] [client 128.127.105.184:53148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9dr3UPuLYrePtEkUcUuQAAAJY"]
[Tue Jul 21 08:53:19.643979 2026] [security2:error] [pid 533360:tid 533610] [client 203.25.124.215:23171] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/fusion-styles/user/index.php"] [unique_id "al9dr3UPuLYrePtEkUcUugAAAPo"]
[Tue Jul 21 08:53:19.659304 2026] [security2:error] [pid 533360:tid 533617] [client 173.252.95.21:49524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dr3UPuLYrePtEkUcUuwAAAQE"]
[Tue Jul 21 08:53:19.845826 2026] [security2:error] [pid 533360:tid 533539] [client 5.38.115.39:15328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dr3UPuLYrePtEkUcUwwAAALM"]
[Tue Jul 21 08:53:19.845949 2026] [security2:error] [pid 533360:tid 533539] [client 5.38.115.39:15328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dr3UPuLYrePtEkUcUwwAAALM"]
[Tue Jul 21 08:53:19.885652 2026] [security2:error] [pid 533360:tid 533535] [client 65.21.113.253:43872] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dr3UPuLYrePtEkUcUxQAAAK8"]
[Tue Jul 21 08:53:19.961376 2026] [security2:error] [pid 533360:tid 533520] [client 128.127.105.184:53162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dr3UPuLYrePtEkUcUxgAAAKA"]
[Tue Jul 21 08:53:19.961472 2026] [security2:error] [pid 533360:tid 533520] [client 128.127.105.184:53162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dr3UPuLYrePtEkUcUxgAAAKA"]
[Tue Jul 21 08:53:20.221346 2026] [security2:error] [pid 533360:tid 533524] [client 69.171.230.16:45528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dsHUPuLYrePtEkUcU1QAAAKQ"]
[Tue Jul 21 08:53:20.251663 2026] [security2:error] [pid 533360:tid 533579] [client 41.89.234.2:65064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dsHUPuLYrePtEkUcU2QAAANs"]
[Tue Jul 21 08:53:20.251874 2026] [security2:error] [pid 533360:tid 533579] [client 41.89.234.2:65064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dsHUPuLYrePtEkUcU2QAAANs"]
[Tue Jul 21 08:53:20.509654 2026] [security2:error] [pid 533360:tid 533585] [client 20.220.225.223:6120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wpx.php"] [unique_id "al9dsHUPuLYrePtEkUcU3wAAAOE"]
[Tue Jul 21 08:53:20.539794 2026] [security2:error] [pid 533360:tid 533502] [client 203.25.124.213:39097] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwentyfive/parts/upgrade/index.php"] [unique_id "al9dsHUPuLYrePtEkUcU4QAAAI4"]
[Tue Jul 21 08:53:20.609918 2026] [security2:error] [pid 533360:tid 533560] [client 20.220.225.223:48238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/fz.php"] [unique_id "al9dsHUPuLYrePtEkUcU5AAAAMg"]
[Tue Jul 21 08:53:20.769975 2026] [security2:error] [pid 533360:tid 533617] [client 173.252.95.1:62426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dsHUPuLYrePtEkUcU8AAAAQE"]
[Tue Jul 21 08:53:20.868614 2026] [security2:error] [pid 533360:tid 533520] [client 20.151.10.161:49093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/green3.php"] [unique_id "al9dsHUPuLYrePtEkUcU8gAAAKA"]
[Tue Jul 21 08:53:20.894685 2026] [access_compat:error] [pid 533360:tid 533612] [client 162.241.63.68:56294] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:53:20.936980 2026] [security2:error] [pid 533360:tid 533539] [client 69.171.230.43:49818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dsHUPuLYrePtEkUcU9AAAALM"]
[Tue Jul 21 08:53:20.973760 2026] [security2:error] [pid 533360:tid 533584] [client 65.21.113.253:57158] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dsHUPuLYrePtEkUcU4gAAAOA"]
[Tue Jul 21 08:53:20.996435 2026] [security2:error] [pid 533360:tid 533504] [client 20.104.96.117:3989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/ss.php"] [unique_id "al9dsHUPuLYrePtEkUcU9QAAAJA"]
[Tue Jul 21 08:53:21.239631 2026] [security2:error] [pid 533360:tid 533568] [client 20.220.225.223:19285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/koiy.php"] [unique_id "al9dsXUPuLYrePtEkUcU_QAAANA"]
[Tue Jul 21 08:53:21.323157 2026] [security2:error] [pid 533360:tid 533542] [client 49.144.66.253:30998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dsXUPuLYrePtEkUcVBAAAALY"]
[Tue Jul 21 08:53:21.323281 2026] [security2:error] [pid 533360:tid 533542] [client 49.144.66.253:30998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dsXUPuLYrePtEkUcVBAAAALY"]
[Tue Jul 21 08:53:21.329514 2026] [security2:error] [pid 533360:tid 533543] [client 20.220.225.223:22541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/ms-new.php"] [unique_id "al9dsXUPuLYrePtEkUcVBQAAALc"]
[Tue Jul 21 08:53:21.336895 2026] [proxy:error] [pid 533360:tid 533533] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:53:21.336960 2026] [proxy_http:error] [pid 533360:tid 533533] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:53:21.337648 2026] [proxy:error] [pid 533360:tid 533533] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:53:21.337675 2026] [proxy_http:error] [pid 533360:tid 533533] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:53:21.385037 2026] [security2:error] [pid 533360:tid 533600] [client 182.189.99.211:48564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dsXUPuLYrePtEkUcVBwAAAPA"]
[Tue Jul 21 08:53:21.385179 2026] [security2:error] [pid 533360:tid 533600] [client 182.189.99.211:48564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dsXUPuLYrePtEkUcVBwAAAPA"]
[Tue Jul 21 08:53:21.412091 2026] [security2:error] [pid 533360:tid 533576] [client 69.171.230.116:40876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dsXUPuLYrePtEkUcVCAAAANg"]
[Tue Jul 21 08:53:21.643460 2026] [security2:error] [pid 533360:tid 533590] [client 212.32.76.11:30027] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/network/theme-install-variable.php"] [unique_id "al9dsXUPuLYrePtEkUcVCgAAAOY"]
[Tue Jul 21 08:53:21.693031 2026] [security2:error] [pid 533360:tid 533502] [client 20.220.225.223:52184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/berlin.php"] [unique_id "al9dsXUPuLYrePtEkUcVDgAAAI4"]
[Tue Jul 21 08:53:22.069955 2026] [security2:error] [pid 533360:tid 533515] [client 20.220.225.223:60272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/la.php"] [unique_id "al9dsnUPuLYrePtEkUcVGQAAAJs"]
[Tue Jul 21 08:53:22.102169 2026] [proxy:error] [pid 533360:tid 533604] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:53:22.102237 2026] [proxy_http:error] [pid 533360:tid 533604] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:53:22.102851 2026] [proxy:error] [pid 533360:tid 533604] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:53:22.102884 2026] [proxy_http:error] [pid 533360:tid 533604] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:53:22.110403 2026] [security2:error] [pid 533360:tid 533614] [client 69.171.230.27:36194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dsnUPuLYrePtEkUcVHAAAAP4"]
[Tue Jul 21 08:53:22.177355 2026] [security2:error] [pid 533360:tid 533557] [client 20.220.225.223:59175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/billur.php"] [unique_id "al9dsnUPuLYrePtEkUcVIQAAAMU"]
[Tue Jul 21 08:53:22.397004 2026] [security2:error] [pid 533360:tid 533468] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dsnUPuLYrePtEkUcVcQAA3Gg"]
[Tue Jul 21 08:53:22.397150 2026] [security2:error] [pid 533360:tid 533580] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dsnUPuLYrePtEkUcVcQAA3Gg"]
[Tue Jul 21 08:53:22.507770 2026] [proxy:error] [pid 533360:tid 533515] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:53:22.507849 2026] [proxy_http:error] [pid 533360:tid 533515] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:53:22.508552 2026] [proxy:error] [pid 533360:tid 533515] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:53:22.508589 2026] [proxy_http:error] [pid 533360:tid 533515] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:53:22.626826 2026] [security2:error] [pid 533360:tid 533397] [remote 51.161.37.204:22352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ffstrength.com"] [uri "/robots.txt"] [unique_id "al9dsnUPuLYrePtEkUcVtQAAuCE"]
[Tue Jul 21 08:53:22.627033 2026] [security2:error] [pid 533360:tid 533544] [client 51.161.37.204:22352] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ffstrength.com"] [uri "/robots.txt"] [unique_id "al9dsnUPuLYrePtEkUcVtQAAuCE"]
[Tue Jul 21 08:53:22.641249 2026] [security2:error] [pid 533360:tid 533593] [client 203.25.124.64:27197] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentynineteen/sass/site/index.php"] [unique_id "al9dsnUPuLYrePtEkUcVvgAAAOk"]
[Tue Jul 21 08:53:22.751440 2026] [security2:error] [pid 533360:tid 533579] [client 20.220.225.223:21571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/dp.php"] [unique_id "al9dsnUPuLYrePtEkUcV0QAAANs"]
[Tue Jul 21 08:53:22.757568 2026] [security2:error] [pid 533360:tid 533386] [remote 100.42.189.89:52304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "insp1.com.br"] [uri "/wp-login.php"] [unique_id "al9dsnUPuLYrePtEkUcV0gAAiBY"]
[Tue Jul 21 08:53:22.884377 2026] [security2:error] [pid 533360:tid 533506] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dsnUPuLYrePtEkUcV2AAAAJI"]
[Tue Jul 21 08:53:23.271715 2026] [security2:error] [pid 533360:tid 533541] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9ds3UPuLYrePtEkUcV-AAAALU"]
[Tue Jul 21 08:53:23.326882 2026] [security2:error] [pid 533360:tid 533611] [client 20.220.225.223:19652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/hp2.php"] [unique_id "al9ds3UPuLYrePtEkUcWBAAAAPs"]
[Tue Jul 21 08:53:23.771675 2026] [security2:error] [pid 533360:tid 533585] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9ds3UPuLYrePtEkUcWFwAAAOE"]
[Tue Jul 21 08:53:23.836974 2026] [security2:error] [pid 533360:tid 533502] [client 212.32.76.2:23405] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwentyone/assets/sass/05-blocks/preformatted/index.php"] [unique_id "al9ds3UPuLYrePtEkUcWHAAAAI4"]
[Tue Jul 21 08:53:24.165899 2026] [security2:error] [pid 533360:tid 533424] [remote 142.44.233.228:22116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "ffstrength.com"] [uri "/"] [unique_id "al9dtHUPuLYrePtEkUcWKgAAvTw"]
[Tue Jul 21 08:53:24.166049 2026] [security2:error] [pid 533360:tid 533549] [client 142.44.233.228:22116] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ffstrength.com"] [uri "/"] [unique_id "al9dtHUPuLYrePtEkUcWKgAAvTw"]
[Tue Jul 21 08:53:24.228433 2026] [security2:error] [pid 533360:tid 533541] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9dtHUPuLYrePtEkUcWLgAAALU"]
[Tue Jul 21 08:53:24.309837 2026] [security2:error] [pid 533360:tid 533599] [client 20.220.225.223:19295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/hp3.php"] [unique_id "al9dtHUPuLYrePtEkUcWOQAAAO8"]
[Tue Jul 21 08:53:24.314922 2026] [security2:error] [pid 533360:tid 533594] [client 20.220.225.223:6081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/mimpi.php"] [unique_id "al9dtHUPuLYrePtEkUcWOwAAAOo"]
[Tue Jul 21 08:53:24.380165 2026] [security2:error] [pid 533360:tid 533604] [client 65.21.113.253:43872] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dtHUPuLYrePtEkUcWQAAAAPQ"]
[Tue Jul 21 08:53:24.533002 2026] [security2:error] [pid 533360:tid 533615] [client 20.104.96.117:3980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/min.php"] [unique_id "al9dtHUPuLYrePtEkUcWSQAAAP8"]
[Tue Jul 21 08:53:24.613774 2026] [security2:error] [pid 533360:tid 533553] [client 59.95.197.55:62589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dtHUPuLYrePtEkUcWTAAAAME"]
[Tue Jul 21 08:53:24.613924 2026] [security2:error] [pid 533360:tid 533553] [client 59.95.197.55:62589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dtHUPuLYrePtEkUcWTAAAAME"]
[Tue Jul 21 08:53:24.750010 2026] [security2:error] [pid 533360:tid 533502] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9dtHUPuLYrePtEkUcWTgAAAI4"]
[Tue Jul 21 08:53:24.859428 2026] [security2:error] [pid 533360:tid 533425] [remote 154.61.75.100:53938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9dtHUPuLYrePtEkUcWUgAAlj0"]
[Tue Jul 21 08:53:25.041572 2026] [security2:error] [pid 533360:tid 533557] [client 20.220.225.223:48234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/old.php"] [unique_id "al9dtXUPuLYrePtEkUcWWAAAAMU"]
[Tue Jul 21 08:53:25.129780 2026] [security2:error] [pid 533360:tid 533547] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9dtXUPuLYrePtEkUcWXAAAALs"]
[Tue Jul 21 08:53:25.238603 2026] [security2:error] [pid 533360:tid 533536] [client 114.198.138.124:57759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dtXUPuLYrePtEkUcWXgAAALA"]
[Tue Jul 21 08:53:25.238719 2026] [security2:error] [pid 533360:tid 533536] [client 114.198.138.124:57759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dtXUPuLYrePtEkUcWXgAAALA"]
[Tue Jul 21 08:53:25.319499 2026] [security2:error] [pid 533360:tid 533549] [client 20.220.225.223:52180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/dp.php"] [unique_id "al9dtXUPuLYrePtEkUcWXwAAAL0"]
[Tue Jul 21 08:53:25.341093 2026] [security2:error] [pid 533360:tid 533612] [client 20.220.225.223:46391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/track.php"] [unique_id "al9dtXUPuLYrePtEkUcWYAAAAPw"]
[Tue Jul 21 08:53:25.359242 2026] [security2:error] [pid 533360:tid 533503] [client 20.197.192.193:27098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/billur.php"] [unique_id "al9dtXUPuLYrePtEkUcWYgAAAI8"]
[Tue Jul 21 08:53:25.488014 2026] [security2:error] [pid 533360:tid 533531] [client 65.21.113.253:57160] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dtXUPuLYrePtEkUcWWgAAAKs"]
[Tue Jul 21 08:53:25.529706 2026] [security2:error] [pid 533360:tid 533616] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9dtXUPuLYrePtEkUcWbAAAAQA"]
[Tue Jul 21 08:53:25.875422 2026] [security2:error] [pid 533360:tid 533495] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dtXUPuLYrePtEkUcWcwAAh1M"]
[Tue Jul 21 08:53:26.034069 2026] [security2:error] [pid 533360:tid 533512] [client 203.25.124.64:42875] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/elex/elex.php"] [unique_id "al9dtnUPuLYrePtEkUcWgQAAAJg"]
[Tue Jul 21 08:53:26.050292 2026] [security2:error] [pid 533360:tid 533494] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9dtnUPuLYrePtEkUcWggAAAIY"]
[Tue Jul 21 08:53:26.350754 2026] [security2:error] [pid 533360:tid 533536] [client 198.44.157.162:36902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dtnUPuLYrePtEkUcWjAAAALA"]
[Tue Jul 21 08:53:26.350893 2026] [security2:error] [pid 533360:tid 533536] [client 198.44.157.162:36902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9dtnUPuLYrePtEkUcWjAAAALA"]
[Tue Jul 21 08:53:26.456836 2026] [security2:error] [pid 533360:tid 533517] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9dtnUPuLYrePtEkUcWkQAAAJ0"]
[Tue Jul 21 08:53:26.508277 2026] [security2:error] [pid 533360:tid 533526] [client 20.220.225.223:38743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9dtnUPuLYrePtEkUcWnAAAAKY"]
[Tue Jul 21 08:53:26.612227 2026] [security2:error] [pid 533360:tid 533545] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dtnUPuLYrePtEkUcWmQAAuS8"]
[Tue Jul 21 08:53:26.748604 2026] [autoindex:error] [pid 533360:tid 533555] [client 44.220.233.148:50525] AH01276: Cannot serve directory /home1/ofic8899/prime-website.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:53:26.868495 2026] [security2:error] [pid 533360:tid 533556] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9dtnUPuLYrePtEkUcWpAAAAMQ"]
[Tue Jul 21 08:53:26.943467 2026] [security2:error] [pid 533360:tid 533538] [client 20.151.10.161:49036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/ccs.php"] [unique_id "al9dtnUPuLYrePtEkUcWpgAAALI"]
[Tue Jul 21 08:53:27.136568 2026] [security2:error] [pid 533360:tid 533568] [client 203.25.124.40:39233] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/oceanwp/sass/base/1.php"] [unique_id "al9dt3UPuLYrePtEkUcWsAAAANA"]
[Tue Jul 21 08:53:27.164924 2026] [security2:error] [pid 533360:tid 533569] [client 168.167.81.163:61398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dt3UPuLYrePtEkUcWsQAAANE"]
[Tue Jul 21 08:53:27.165040 2026] [security2:error] [pid 533360:tid 533569] [client 168.167.81.163:61398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dt3UPuLYrePtEkUcWsQAAANE"]
[Tue Jul 21 08:53:27.306694 2026] [security2:error] [pid 533360:tid 533588] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9dt3UPuLYrePtEkUcWtgAAAOQ"]
[Tue Jul 21 08:53:27.360957 2026] [security2:error] [pid 533360:tid 533366] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dt3UPuLYrePtEkUcWtwAAjgI"]
[Tue Jul 21 08:53:27.361184 2026] [security2:error] [pid 533360:tid 533502] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dt3UPuLYrePtEkUcWtwAAjgI"]
[Tue Jul 21 08:53:27.431198 2026] [core:alert] [pid 533360:tid 533517] [client 57.141.18.54:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:53:27.527663 2026] [security2:error] [pid 533360:tid 533522] [client 20.220.225.223:38731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/ms-new.php"] [unique_id "al9dt3UPuLYrePtEkUcWxAAAAKI"]
[Tue Jul 21 08:53:27.736365 2026] [security2:error] [pid 533360:tid 533496] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9dt3UPuLYrePtEkUcWywAAAIg"]
[Tue Jul 21 08:53:27.803026 2026] [security2:error] [pid 533360:tid 533534] [client 113.22.144.139:64261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dt3UPuLYrePtEkUcWzAAAAK4"]
[Tue Jul 21 08:53:27.803150 2026] [security2:error] [pid 533360:tid 533534] [client 113.22.144.139:64261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dt3UPuLYrePtEkUcWzAAAAK4"]
[Tue Jul 21 08:53:28.041497 2026] [security2:error] [pid 533360:tid 533510] [client 20.220.225.223:32385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/bootstrap.php"] [unique_id "al9duHUPuLYrePtEkUcW0gAAAJY"]
[Tue Jul 21 08:53:28.109616 2026] [security2:error] [pid 533360:tid 533575] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.danielecremascoparus1782135601414.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9duHUPuLYrePtEkUcW1QAAANc"]
[Tue Jul 21 08:53:28.155338 2026] [security2:error] [pid 533360:tid 533444] [remote 108.167.136.49:46680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.136.167.108.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tempex.com.br"] [uri "/wp-login.php"] [unique_id "al9duHUPuLYrePtEkUcW1gAA01A"]
[Tue Jul 21 08:53:28.218154 2026] [security2:error] [pid 533360:tid 533553] [client 185.198.240.183:48479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "dener.design"] [uri "/wp-login.php"] [unique_id "al9dtnUPuLYrePtEkUcWnQAAAME"]
[Tue Jul 21 08:53:28.775085 2026] [security2:error] [pid 533360:tid 533506] [client 157.66.56.90:55715] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "tkcorretoradeseguros.com.br"] [uri "/"] [unique_id "al9duHUPuLYrePtEkUcW6AAAAJI"]
[Tue Jul 21 08:53:28.912268 2026] [security2:error] [pid 533360:tid 533544] [client 20.220.225.223:60259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/track.php"] [unique_id "al9duHUPuLYrePtEkUcW6gAAALg"]
[Tue Jul 21 08:53:28.925948 2026] [security2:error] [pid 533360:tid 533546] [client 20.220.225.223:48220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/inso.php"] [unique_id "al9duHUPuLYrePtEkUcW6wAAALo"]
[Tue Jul 21 08:53:28.992339 2026] [security2:error] [pid 533360:tid 533583] [client 65.21.113.253:40144] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9duHUPuLYrePtEkUcW8gAAAN8"]
[Tue Jul 21 08:53:29.007518 2026] [security2:error] [pid 533360:tid 533443] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9duXUPuLYrePtEkUcW9AAAmk8"]
[Tue Jul 21 08:53:29.007623 2026] [security2:error] [pid 533360:tid 533514] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9duXUPuLYrePtEkUcW9AAAmk8"]
[Tue Jul 21 08:53:29.039799 2026] [security2:error] [pid 533360:tid 533498] [client 203.25.124.50:60723] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwentyone/emerance.php"] [unique_id "al9duXUPuLYrePtEkUcW9QAAAIo"]
[Tue Jul 21 08:53:29.647129 2026] [security2:error] [pid 533360:tid 533553] [client 20.220.225.223:23472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wp-editor.php"] [unique_id "al9duXUPuLYrePtEkUcXCgAAAME"]
[Tue Jul 21 08:53:29.649175 2026] [security2:error] [pid 533360:tid 533405] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9duXUPuLYrePtEkUcXCwAAiCk"]
[Tue Jul 21 08:53:29.649279 2026] [security2:error] [pid 533360:tid 533496] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9duXUPuLYrePtEkUcXCwAAiCk"]
[Tue Jul 21 08:53:29.833364 2026] [security2:error] [pid 533360:tid 533578] [client 65.21.113.253:38354] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9duXUPuLYrePtEkUcXDAAAANo"]
[Tue Jul 21 08:53:30.170422 2026] [security2:error] [pid 533360:tid 533506] [client 20.197.192.193:27170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/mimpi.php"] [unique_id "al9dunUPuLYrePtEkUcXHQAAAJI"]
[Tue Jul 21 08:53:30.301310 2026] [security2:error] [pid 533360:tid 533546] [client 65.21.113.253:35260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dunUPuLYrePtEkUcXHwAAALo"]
[Tue Jul 21 08:53:30.327198 2026] [security2:error] [pid 533360:tid 533519] [client 152.59.181.104:60950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dunUPuLYrePtEkUcXIAAAAJ8"]
[Tue Jul 21 08:53:30.327353 2026] [security2:error] [pid 533360:tid 533519] [client 152.59.181.104:60950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dunUPuLYrePtEkUcXIAAAAJ8"]
[Tue Jul 21 08:53:30.541323 2026] [security2:error] [pid 533360:tid 533555] [client 20.151.10.161:49143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/ccc.php"] [unique_id "al9dunUPuLYrePtEkUcXJQAAAMM"]
[Tue Jul 21 08:53:30.542022 2026] [security2:error] [pid 533360:tid 533576] [client 5.38.115.39:9895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dunUPuLYrePtEkUcXJwAAANg"]
[Tue Jul 21 08:53:30.542154 2026] [security2:error] [pid 533360:tid 533576] [client 5.38.115.39:9895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dunUPuLYrePtEkUcXJwAAANg"]
[Tue Jul 21 08:53:30.936250 2026] [security2:error] [pid 533360:tid 533568] [client 212.32.76.11:33517] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentynineteen/content-index.php"] [unique_id "al9dunUPuLYrePtEkUcXPAAAANA"]
[Tue Jul 21 08:53:30.955101 2026] [security2:error] [pid 533360:tid 533528] [client 20.220.225.223:19651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/aa1.php"] [unique_id "al9dunUPuLYrePtEkUcXPQAAAKg"]
[Tue Jul 21 08:53:31.055511 2026] [security2:error] [pid 533360:tid 533526] [client 41.89.234.2:65529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9du3UPuLYrePtEkUcXQwAAAKY"]
[Tue Jul 21 08:53:31.055625 2026] [security2:error] [pid 533360:tid 533526] [client 41.89.234.2:65529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9du3UPuLYrePtEkUcXQwAAAKY"]
[Tue Jul 21 08:53:31.216898 2026] [security2:error] [pid 533360:tid 533611] [client 20.220.225.223:38739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/wpx.php"] [unique_id "al9du3UPuLYrePtEkUcXSQAAAPs"]
[Tue Jul 21 08:53:31.318876 2026] [security2:error] [pid 533360:tid 533598] [client 173.252.95.27:42540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9du3UPuLYrePtEkUcXSwAAAO4"]
[Tue Jul 21 08:53:31.378521 2026] [security2:error] [pid 533360:tid 533520] [client 20.220.225.223:37584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/2352356666.php"] [unique_id "al9du3UPuLYrePtEkUcXTQAAAKA"]
[Tue Jul 21 08:53:31.456538 2026] [security2:error] [pid 533360:tid 533584] [client 65.21.113.253:38368] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9du3UPuLYrePtEkUcXPwAAAOA"]
[Tue Jul 21 08:53:31.649224 2026] [security2:error] [pid 533360:tid 533569] [client 103.59.206.240:31411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9du3UPuLYrePtEkUcXVAAAANE"]
[Tue Jul 21 08:53:31.649324 2026] [security2:error] [pid 533360:tid 533569] [client 103.59.206.240:31411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9du3UPuLYrePtEkUcXVAAAANE"]
[Tue Jul 21 08:53:31.742269 2026] [security2:error] [pid 533360:tid 533555] [client 20.104.96.117:46775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al9du3UPuLYrePtEkUcXVwAAAMM"]
[Tue Jul 21 08:53:31.883768 2026] [security2:error] [pid 533360:tid 533596] [client 173.252.95.54:37026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9du3UPuLYrePtEkUcXXQAAAOw"]
[Tue Jul 21 08:53:31.931486 2026] [security2:error] [pid 533360:tid 533514] [client 173.252.95.25:65040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9du3UPuLYrePtEkUcXYgAAAJo"]
[Tue Jul 21 08:53:31.952547 2026] [security2:error] [pid 533360:tid 533550] [client 182.189.99.211:48365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9du3UPuLYrePtEkUcXYwAAAL4"]
[Tue Jul 21 08:53:31.952643 2026] [security2:error] [pid 533360:tid 533550] [client 182.189.99.211:48365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9du3UPuLYrePtEkUcXYwAAAL4"]
[Tue Jul 21 08:53:32.028942 2026] [security2:error] [pid 533360:tid 533530] [client 20.220.225.223:23452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/cro.php"] [unique_id "al9dvHUPuLYrePtEkUcXZQAAAKo"]
[Tue Jul 21 08:53:32.046016 2026] [security2:error] [pid 533360:tid 533534] [client 212.32.76.10:57915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/responsive-lightbox/assets/nivo/themes/wp-load.php"] [unique_id "al9dvHUPuLYrePtEkUcXZwAAAK4"]
[Tue Jul 21 08:53:32.225779 2026] [security2:error] [pid 533360:tid 533529] [client 128.127.105.184:34624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9dvHUPuLYrePtEkUcXbwAAAKk"]
[Tue Jul 21 08:53:32.225917 2026] [security2:error] [pid 533360:tid 533529] [client 128.127.105.184:34624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9dvHUPuLYrePtEkUcXbwAAAKk"]
[Tue Jul 21 08:53:32.271441 2026] [security2:error] [pid 533360:tid 533582] [client 49.144.66.253:31455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.66.144.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dvHUPuLYrePtEkUcXcgAAAN4"]
[Tue Jul 21 08:53:32.272037 2026] [security2:error] [pid 533360:tid 533582] [client 49.144.66.253:31455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "blissfullcleaning.net"] [uri "/xmlrpc.php"] [unique_id "al9dvHUPuLYrePtEkUcXcgAAAN4"]
[Tue Jul 21 08:53:32.518898 2026] [security2:error] [pid 533360:tid 533526] [client 173.252.95.26:34510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9dvHUPuLYrePtEkUcXdQAAAKY"]
[Tue Jul 21 08:53:32.738335 2026] [security2:error] [pid 533360:tid 533506] [client 203.25.124.57:50783] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/responsive-lightbox/assets/jstree/themes/system.php"] [unique_id "al9dvHUPuLYrePtEkUcXfwAAAJI"]
[Tue Jul 21 08:53:32.929088 2026] [security2:error] [pid 533360:tid 533447] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dvHUPuLYrePtEkUcXhAAAoFM"]
[Tue Jul 21 08:53:32.929234 2026] [security2:error] [pid 533360:tid 533520] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dvHUPuLYrePtEkUcXhAAAoFM"]
[Tue Jul 21 08:53:33.034400 2026] [security2:error] [pid 533360:tid 533555] [client 128.127.105.184:56262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9dvXUPuLYrePtEkUcXhwAAAMM"]
[Tue Jul 21 08:53:33.034507 2026] [security2:error] [pid 533360:tid 533555] [client 128.127.105.184:56262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9dvXUPuLYrePtEkUcXhwAAAMM"]
[Tue Jul 21 08:53:33.344665 2026] [security2:error] [pid 533360:tid 533378] [remote 216.73.216.184:50040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemape.xml"] [unique_id "al9dvXUPuLYrePtEkUcXmwAAwg4"]
[Tue Jul 21 08:53:33.474002 2026] [security2:error] [pid 533360:tid 533532] [client 20.220.225.223:48227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/2352356666.php"] [unique_id "al9dvXUPuLYrePtEkUcXowAAAKw"]
[Tue Jul 21 08:53:33.698851 2026] [security2:error] [pid 533360:tid 533386] [remote 192.241.143.148:39628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9dvXUPuLYrePtEkUcXvgAA4RY"]
[Tue Jul 21 08:53:33.698967 2026] [security2:error] [pid 533360:tid 533585] [client 192.241.143.148:39628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9dvXUPuLYrePtEkUcXvgAA4RY"]
[Tue Jul 21 08:53:33.716076 2026] [security2:error] [pid 533360:tid 533613] [client 20.220.225.223:32386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/cron-tab.php"] [unique_id "al9dvXUPuLYrePtEkUcXvwAAAP0"]
[Tue Jul 21 08:53:33.924060 2026] [security2:error] [pid 533360:tid 533609] [client 194.99.104.35:53390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9dvXUPuLYrePtEkUcX6wAAAPk"]
[Tue Jul 21 08:53:33.924172 2026] [security2:error] [pid 533360:tid 533609] [client 194.99.104.35:53390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9dvXUPuLYrePtEkUcX6wAAAPk"]
[Tue Jul 21 08:53:34.037763 2026] [security2:error] [pid 533360:tid 533596] [client 203.25.124.212:50885] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/contact-form-7/includes/js/jquery-ui/themes/data.php"] [unique_id "al9dvnUPuLYrePtEkUcX9QAAAOw"]
[Tue Jul 21 08:53:34.140562 2026] [security2:error] [pid 533360:tid 533615] [client 20.151.10.161:52177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9dvnUPuLYrePtEkUcX_AAAAP8"]
[Tue Jul 21 08:53:34.906221 2026] [security2:error] [pid 533360:tid 533613] [client 20.220.225.223:59174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/koiy.php"] [unique_id "al9dvnUPuLYrePtEkUcYFQAAAP0"]
[Tue Jul 21 08:53:35.113491 2026] [security2:error] [pid 533360:tid 533513] [client 59.95.197.55:63066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dv3UPuLYrePtEkUcYHwAAAJk"]
[Tue Jul 21 08:53:35.113587 2026] [security2:error] [pid 533360:tid 533513] [client 59.95.197.55:63066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dv3UPuLYrePtEkUcYHwAAAJk"]
[Tue Jul 21 08:53:35.141455 2026] [security2:error] [pid 533360:tid 533595] [client 212.32.76.10:46929] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/windazo/inc/plugins/wp-blog-header.php"] [unique_id "al9dv3UPuLYrePtEkUcYIQAAAOs"]
[Tue Jul 21 08:53:35.165166 2026] [security2:error] [pid 533360:tid 533498] [client 65.21.113.253:35260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dv3UPuLYrePtEkUcYJAAAAIo"]
[Tue Jul 21 08:53:35.759952 2026] [security2:error] [pid 533360:tid 533494] [client 114.198.138.124:58338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dv3UPuLYrePtEkUcYMQAAAIY"]
[Tue Jul 21 08:53:35.760064 2026] [security2:error] [pid 533360:tid 533494] [client 114.198.138.124:58338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dv3UPuLYrePtEkUcYMQAAAIY"]
[Tue Jul 21 08:53:35.796378 2026] [security2:error] [pid 533360:tid 533495] [client 114.119.147.45:28733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tkcorretoradeseguros.com.br"] [uri "/"] [unique_id "al9dv3UPuLYrePtEkUcYNQAAAIc"], referer: http://tkcorretoradeseguros.com.br/?page_id=2
[Tue Jul 21 08:53:36.040013 2026] [security2:error] [pid 533360:tid 533570] [client 20.104.96.117:61722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/autoload_classmap.php"] [unique_id "al9dwHUPuLYrePtEkUcYQQAAANI"]
[Tue Jul 21 08:53:36.056289 2026] [security2:error] [pid 533360:tid 533559] [client 20.220.225.223:43193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/pn.php"] [unique_id "al9dwHUPuLYrePtEkUcYQwAAAMc"]
[Tue Jul 21 08:53:36.247417 2026] [security2:error] [pid 533360:tid 533619] [client 20.151.10.161:52221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9dwHUPuLYrePtEkUcYTgAAAQM"]
[Tue Jul 21 08:53:36.288024 2026] [security2:error] [pid 533360:tid 533579] [client 65.21.113.253:38378] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dv3UPuLYrePtEkUcYPAAAANs"]
[Tue Jul 21 08:53:36.425289 2026] [security2:error] [pid 533360:tid 533596] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dwHUPuLYrePtEkUcYUgAA7Ds"]
[Tue Jul 21 08:53:36.452145 2026] [security2:error] [pid 533360:tid 533528] [client 20.151.10.161:51071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/x.php"] [unique_id "al9dwHUPuLYrePtEkUcYVgAAAKg"]
[Tue Jul 21 08:53:36.739509 2026] [security2:error] [pid 533360:tid 533558] [client 203.25.124.47:61105] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/js_composer/include/classes/vendors/plugins/api.php"] [unique_id "al9dwHUPuLYrePtEkUcYXwAAAMY"]
[Tue Jul 21 08:53:36.851470 2026] [security2:error] [pid 533360:tid 533550] [client 20.220.225.223:19312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/acew67.php"] [unique_id "al9dwHUPuLYrePtEkUcYZwAAAL4"]
[Tue Jul 21 08:53:36.883331 2026] [security2:error] [pid 533360:tid 533597] [client 168.167.81.163:62576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dwHUPuLYrePtEkUcYaAAAAO0"]
[Tue Jul 21 08:53:36.883953 2026] [security2:error] [pid 533360:tid 533597] [client 168.167.81.163:62576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dwHUPuLYrePtEkUcYaAAAAO0"]
[Tue Jul 21 08:53:36.900085 2026] [security2:error] [pid 533360:tid 533508] [client 20.220.225.223:21901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/berlin.php"] [unique_id "al9dwHUPuLYrePtEkUcYagAAAJQ"]
[Tue Jul 21 08:53:36.999048 2026] [security2:error] [pid 533360:tid 533511] [client 20.151.10.161:52191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/x.php"] [unique_id "al9dwHUPuLYrePtEkUcYcQAAAJc"]
[Tue Jul 21 08:53:37.647375 2026] [security2:error] [pid 533360:tid 533529] [client 20.220.225.223:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/hp2.php"] [unique_id "al9dwXUPuLYrePtEkUcYhQAAAKk"]
[Tue Jul 21 08:53:37.666927 2026] [security2:error] [pid 533360:tid 533552] [client 20.151.10.161:52162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/j260624_13.php"] [unique_id "al9dwXUPuLYrePtEkUcYhgAAAMA"]
[Tue Jul 21 08:53:37.841889 2026] [security2:error] [pid 533360:tid 533543] [client 203.25.124.74:60631] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/stockholm/woocommerce/single-product/add-to-cart/internal.php"] [unique_id "al9dwXUPuLYrePtEkUcYjAAAALc"]
[Tue Jul 21 08:53:37.960842 2026] [security2:error] [pid 533360:tid 533532] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dwXUPuLYrePtEkUcYiQAArGY"]
[Tue Jul 21 08:53:38.110168 2026] [security2:error] [pid 533360:tid 533514] [client 20.197.192.193:50565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9dwnUPuLYrePtEkUcYlAAAAJo"]
[Tue Jul 21 08:53:38.176537 2026] [security2:error] [pid 533360:tid 533511] [client 20.220.225.223:46712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9dwnUPuLYrePtEkUcYmQAAAJc"]
[Tue Jul 21 08:53:38.295351 2026] [security2:error] [pid 533360:tid 533586] [client 113.22.144.139:64774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dwnUPuLYrePtEkUcYnwAAAOI"]
[Tue Jul 21 08:53:38.296160 2026] [security2:error] [pid 533360:tid 533586] [client 113.22.144.139:64774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dwnUPuLYrePtEkUcYnwAAAOI"]
[Tue Jul 21 08:53:38.322835 2026] [security2:error] [pid 533360:tid 533400] [remote 160.187.68.132:33266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rosisestefanoadvocacia.guiiaz.com.br"] [uri "/wp-login.php"] [unique_id "al9dwnUPuLYrePtEkUcYoAAAliQ"]
[Tue Jul 21 08:53:38.357357 2026] [security2:error] [pid 533360:tid 533398] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dwnUPuLYrePtEkUcYpAAAwiI"]
[Tue Jul 21 08:53:38.357612 2026] [security2:error] [pid 533360:tid 533554] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dwnUPuLYrePtEkUcYpAAAwiI"]
[Tue Jul 21 08:53:38.412981 2026] [security2:error] [pid 533360:tid 533562] [client 20.151.10.161:52098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/d62.php"] [unique_id "al9dwnUPuLYrePtEkUcYpQAAAMo"]
[Tue Jul 21 08:53:38.685522 2026] [security2:error] [pid 533360:tid 533494] [client 20.104.96.117:4049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-link-zorm.php"] [unique_id "al9dwnUPuLYrePtEkUcYrgAAAIY"]
[Tue Jul 21 08:53:38.774243 2026] [security2:error] [pid 533360:tid 533612] [client 20.151.10.161:52198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/ups.php"] [unique_id "al9dwnUPuLYrePtEkUcYsQAAAPw"]
[Tue Jul 21 08:53:38.849843 2026] [security2:error] [pid 533360:tid 533509] [client 198.44.157.162:33402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9dwnUPuLYrePtEkUcYsgAAAJU"]
[Tue Jul 21 08:53:38.849941 2026] [security2:error] [pid 533360:tid 533509] [client 198.44.157.162:33402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9dwnUPuLYrePtEkUcYsgAAAJU"]
[Tue Jul 21 08:53:38.951017 2026] [security2:error] [pid 533360:tid 533614] [client 20.220.225.223:6138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/hp3.php"] [unique_id "al9dwnUPuLYrePtEkUcYuQAAAP4"]
[Tue Jul 21 08:53:39.127411 2026] [security2:error] [pid 533360:tid 533530] [client 128.127.105.184:54028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9dw3UPuLYrePtEkUcYyQAAAKo"]
[Tue Jul 21 08:53:39.127498 2026] [security2:error] [pid 533360:tid 533530] [client 128.127.105.184:54028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9dw3UPuLYrePtEkUcYyQAAAKo"]
[Tue Jul 21 08:53:39.241761 2026] [security2:error] [pid 533360:tid 533551] [client 203.25.124.43:32807] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/post-template/index.php"] [unique_id "al9dw3UPuLYrePtEkUcYzQAAAL8"]
[Tue Jul 21 08:53:39.270456 2026] [security2:error] [pid 533360:tid 533567] [client 20.151.10.161:52116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/k.php"] [unique_id "al9dw3UPuLYrePtEkUcY0AAAAM8"]
[Tue Jul 21 08:53:39.673749 2026] [security2:error] [pid 533360:tid 533547] [client 20.151.10.161:55864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/j260624_13.php"] [unique_id "al9dw3UPuLYrePtEkUcY4wAAALs"]
[Tue Jul 21 08:53:39.751989 2026] [security2:error] [pid 533360:tid 533565] [client 74.7.175.153:45794] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "simleite.com.br"] [uri "/index.php"] [unique_id "al9dw3UPuLYrePtEkUcY4AAAzV8"]
[Tue Jul 21 08:53:39.821704 2026] [security2:error] [pid 533360:tid 533506] [client 65.21.113.253:35260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dw3UPuLYrePtEkUcY5gAAAJI"]
[Tue Jul 21 08:53:39.859676 2026] [security2:error] [pid 533360:tid 533564] [client 20.197.192.193:56786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9dw3UPuLYrePtEkUcY6AAAAMw"]
[Tue Jul 21 08:53:39.895316 2026] [security2:error] [pid 533360:tid 533574] [client 74.7.175.177:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.portal.paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9dwnUPuLYrePtEkUcYqAAAANY"]
[Tue Jul 21 08:53:39.896246 2026] [security2:error] [pid 533360:tid 533580] [client 74.7.175.177:60514] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.portal.paginadoproduto-oficial.com.br"] [uri "/robots.txt"] [unique_id "al9dwnUPuLYrePtEkUcYpgAA3Hs"]
[Tue Jul 21 08:53:39.955474 2026] [security2:error] [pid 533360:tid 533586] [client 74.7.244.62:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "portal.paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9dw3UPuLYrePtEkUcYxgAAAOI"]
[Tue Jul 21 08:53:39.956511 2026] [security2:error] [pid 533360:tid 533531] [client 74.7.244.62:56750] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "portal.paginadoproduto-oficial.com.br"] [uri "/robots.txt"] [unique_id "al9dw3UPuLYrePtEkUcYwwAAq2E"]
[Tue Jul 21 08:53:40.039875 2026] [security2:error] [pid 533360:tid 533491] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dxHUPuLYrePtEkUcY9QAAl38"]
[Tue Jul 21 08:53:40.040020 2026] [security2:error] [pid 533360:tid 533511] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dxHUPuLYrePtEkUcY9QAAl38"]
[Tue Jul 21 08:53:40.077620 2026] [security2:error] [pid 533360:tid 533550] [client 20.151.10.161:52123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/k2.php"] [unique_id "al9dxHUPuLYrePtEkUcY9gAAAL4"]
[Tue Jul 21 08:53:40.135095 2026] [security2:error] [pid 533360:tid 533429] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dxHUPuLYrePtEkUcZCQAA2kE"]
[Tue Jul 21 08:53:40.135231 2026] [security2:error] [pid 533360:tid 533578] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dxHUPuLYrePtEkUcZCQAA2kE"]
[Tue Jul 21 08:53:40.434066 2026] [security2:error] [pid 533360:tid 533556] [client 212.32.76.4:56041] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/images/index.php"] [unique_id "al9dxHUPuLYrePtEkUcZIQAAAMQ"]
[Tue Jul 21 08:53:40.446536 2026] [security2:error] [pid 533360:tid 533609] [client 20.197.192.193:52689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/wander.php"] [unique_id "al9dxHUPuLYrePtEkUcZIgAAAPk"]
[Tue Jul 21 08:53:40.526629 2026] [security2:error] [pid 533360:tid 533583] [client 74.7.175.177:60520] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "portal.paginadoproduto-oficial.com.br"] [uri "/robots.txt"] [unique_id "al9dxHUPuLYrePtEkUcZKgAA33k"], referer: https://www.portal.paginadoproduto-oficial.com.br/robots.txt
[Tue Jul 21 08:53:40.613793 2026] [security2:error] [pid 533360:tid 533550] [client 20.220.225.223:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/aa1.php"] [unique_id "al9dxHUPuLYrePtEkUcZMgAAAL4"]
[Tue Jul 21 08:53:40.776544 2026] [security2:error] [pid 533360:tid 533604] [client 20.151.10.161:52171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/k3.php"] [unique_id "al9dxHUPuLYrePtEkUcZPgAAAPQ"]
[Tue Jul 21 08:53:40.898802 2026] [security2:error] [pid 533360:tid 533585] [client 65.21.113.253:43442] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dxHUPuLYrePtEkUcZKQAAAOE"]
[Tue Jul 21 08:53:40.956416 2026] [security2:error] [pid 533360:tid 533586] [client 198.44.157.162:33410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9dxHUPuLYrePtEkUcZSwAAAOI"]
[Tue Jul 21 08:53:40.956509 2026] [security2:error] [pid 533360:tid 533586] [client 198.44.157.162:33410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9dxHUPuLYrePtEkUcZSwAAAOI"]
[Tue Jul 21 08:53:41.187700 2026] [security2:error] [pid 533360:tid 533601] [client 5.38.115.39:64119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dxXUPuLYrePtEkUcZeQAAAPE"]
[Tue Jul 21 08:53:41.187851 2026] [security2:error] [pid 533360:tid 533601] [client 5.38.115.39:64119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dxXUPuLYrePtEkUcZeQAAAPE"]
[Tue Jul 21 08:53:41.223583 2026] [security2:error] [pid 533360:tid 533578] [client 20.151.10.161:52185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/k4.php"] [unique_id "al9dxXUPuLYrePtEkUcZgwAAANo"]
[Tue Jul 21 08:53:41.448099 2026] [security2:error] [pid 533360:tid 533603] [client 203.25.124.72:56345] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/css/dist/block-directory/index.php"] [unique_id "al9dxXUPuLYrePtEkUcZrAAAAPM"]
[Tue Jul 21 08:53:41.589412 2026] [security2:error] [pid 533360:tid 533534] [client 20.151.10.161:51055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/d62.php"] [unique_id "al9dxXUPuLYrePtEkUcZtwAAAK4"]
[Tue Jul 21 08:53:41.607074 2026] [security2:error] [pid 533360:tid 533581] [client 41.89.234.2:49617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dxXUPuLYrePtEkUcZuAAAAN0"]
[Tue Jul 21 08:53:41.607199 2026] [security2:error] [pid 533360:tid 533581] [client 41.89.234.2:49617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dxXUPuLYrePtEkUcZuAAAAN0"]
[Tue Jul 21 08:53:41.608951 2026] [security2:error] [pid 533360:tid 533557] [client 20.151.10.161:52179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/k5.php"] [unique_id "al9dxXUPuLYrePtEkUcZuQAAAMU"]
[Tue Jul 21 08:53:41.717451 2026] [security2:error] [pid 533360:tid 533501] [client 152.59.181.104:61273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dxXUPuLYrePtEkUcZwQAAAI0"]
[Tue Jul 21 08:53:41.717572 2026] [security2:error] [pid 533360:tid 533501] [client 152.59.181.104:61273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9dxXUPuLYrePtEkUcZwQAAAI0"]
[Tue Jul 21 08:53:41.785501 2026] [security2:error] [pid 533360:tid 533578] [client 20.197.192.193:50585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/jga.php"] [unique_id "al9dxXUPuLYrePtEkUcZxwAAANo"]
[Tue Jul 21 08:53:41.919510 2026] [security2:error] [pid 533360:tid 533545] [client 103.59.206.240:31216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dxXUPuLYrePtEkUcZ0AAAALk"]
[Tue Jul 21 08:53:41.919619 2026] [security2:error] [pid 533360:tid 533545] [client 103.59.206.240:31216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dxXUPuLYrePtEkUcZ0AAAALk"]
[Tue Jul 21 08:53:42.064612 2026] [security2:error] [pid 533360:tid 533562] [client 20.220.225.223:59152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/acew67.php"] [unique_id "al9dxnUPuLYrePtEkUcZ2QAAAMo"]
[Tue Jul 21 08:53:42.276534 2026] [security2:error] [pid 533360:tid 533529] [client 20.151.10.161:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/w.php"] [unique_id "al9dxnUPuLYrePtEkUcZ4gAAAKk"]
[Tue Jul 21 08:53:42.308176 2026] [security2:error] [pid 533360:tid 533532] [client 20.220.225.223:19692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/bscclapb.php"] [unique_id "al9dxnUPuLYrePtEkUcZ5AAAAKw"]
[Tue Jul 21 08:53:42.308713 2026] [security2:error] [pid 533360:tid 533450] [remote 74.7.175.137:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "romuloalexssandro1751469573000.0721679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9dxnUPuLYrePtEkUcZ4wAAzVY"]
[Tue Jul 21 08:53:42.669843 2026] [security2:error] [pid 533360:tid 533508] [client 20.197.192.193:56808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/x.php"] [unique_id "al9dxnUPuLYrePtEkUcZ8wAAAJQ"]
[Tue Jul 21 08:53:42.742886 2026] [security2:error] [pid 533360:tid 533603] [client 212.32.76.9:52553] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/assets/about.php"] [unique_id "al9dxnUPuLYrePtEkUcZ9AAAAPM"]
[Tue Jul 21 08:53:42.761348 2026] [security2:error] [pid 533360:tid 533604] [client 20.151.10.161:52161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/fpwch.php"] [unique_id "al9dxnUPuLYrePtEkUcZ9gAAAPQ"]
[Tue Jul 21 08:53:43.048038 2026] [security2:error] [pid 533360:tid 533514] [client 20.104.96.117:4091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-link-szoppm.php"] [unique_id "al9dx3UPuLYrePtEkUcaBwAAAJo"]
[Tue Jul 21 08:53:43.254494 2026] [security2:error] [pid 533360:tid 533579] [client 20.151.10.161:52100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/w2025.php"] [unique_id "al9dx3UPuLYrePtEkUcaDwAAANs"]
[Tue Jul 21 08:53:43.350630 2026] [security2:error] [pid 533360:tid 533489] [remote 216.73.216.184:45785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapc.xml"] [unique_id "al9dx3UPuLYrePtEkUcaFQAAmX0"]
[Tue Jul 21 08:53:43.378264 2026] [security2:error] [pid 533360:tid 533440] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dx3UPuLYrePtEkUcaGQAA9Uw"]
[Tue Jul 21 08:53:43.378411 2026] [security2:error] [pid 533360:tid 533605] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9dx3UPuLYrePtEkUcaGQAA9Uw"]
[Tue Jul 21 08:53:43.467153 2026] [security2:error] [pid 533360:tid 533551] [client 182.189.99.211:48557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dx3UPuLYrePtEkUcaHgAAAL8"]
[Tue Jul 21 08:53:43.467319 2026] [security2:error] [pid 533360:tid 533551] [client 182.189.99.211:48557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dx3UPuLYrePtEkUcaHgAAAL8"]
[Tue Jul 21 08:53:43.494468 2026] [security2:error] [pid 533360:tid 533556] [client 20.220.225.223:59170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/bscclapb.php"] [unique_id "al9dx3UPuLYrePtEkUcaIwAAAMQ"]
[Tue Jul 21 08:53:43.572769 2026] [security2:error] [pid 533360:tid 533548] [client 20.151.10.161:52190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/scxy.php"] [unique_id "al9dx3UPuLYrePtEkUcaKQAAALw"]
[Tue Jul 21 08:53:43.755447 2026] [security2:error] [pid 533360:tid 533504] [client 201.20.42.46:50572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.42.20.201.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "girassollimpeza.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9dx3UPuLYrePtEkUcaGwAAAJA"]
[Tue Jul 21 08:53:43.755594 2026] [security2:error] [pid 533360:tid 533504] [client 201.20.42.46:50572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "girassollimpeza.com.br"] [uri "/wp-comments-post.php"] [unique_id "al9dx3UPuLYrePtEkUcaGwAAAJA"]
[Tue Jul 21 08:53:43.889315 2026] [security2:error] [pid 533360:tid 533507] [client 20.151.10.161:52187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/FWAZ.php"] [unique_id "al9dx3UPuLYrePtEkUcaMAAAAJM"]
[Tue Jul 21 08:53:44.156804 2026] [security2:error] [pid 533360:tid 533502] [client 20.197.192.193:52673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9dyHUPuLYrePtEkUcaPwAAAI4"]
[Tue Jul 21 08:53:44.238310 2026] [security2:error] [pid 533360:tid 533528] [client 20.151.10.161:52186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/qterm.php"] [unique_id "al9dyHUPuLYrePtEkUcaRgAAAKg"]
[Tue Jul 21 08:53:44.321616 2026] [security2:error] [pid 533360:tid 533508] [client 20.220.225.223:19725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/else1.php"] [unique_id "al9dyHUPuLYrePtEkUcaSwAAAJQ"]
[Tue Jul 21 08:53:44.364337 2026] [http2:info] [pid 559070:tid 559070] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 08:53:44.387215 2026] [security2:error] [pid 533360:tid 533509] [client 65.21.113.253:35260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dyHUPuLYrePtEkUcaUAAAAJU"]
[Tue Jul 21 08:53:44.439435 2026] [security2:error] [pid 533360:tid 533557] [client 203.25.124.71:50607] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/IXR/index.php"] [unique_id "al9dyHUPuLYrePtEkUcaUwAAAMU"]
[Tue Jul 21 08:53:44.444371 2026] [security2:error] [pid 533360:tid 533397] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9dyHUPuLYrePtEkUcaVAAAkCE"]
[Tue Jul 21 08:53:44.461880 2026] [security2:error] [pid 533360:tid 533417] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9dyHUPuLYrePtEkUcaVQAA7TU"]
[Tue Jul 21 08:53:44.509717 2026] [security2:error] [pid 559070:tid 559129] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/x.php"] [unique_id "al9dyCy1f1FtKC137xvxMQABkzo"]
[Tue Jul 21 08:53:44.525290 2026] [security2:error] [pid 533360:tid 533485] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/j260624_13.php"] [unique_id "al9dyHUPuLYrePtEkUcaWAAAknk"]
[Tue Jul 21 08:53:44.576085 2026] [security2:error] [pid 559070:tid 559210] [client 20.151.10.161:52181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/blurbs.php"] [unique_id "al9dyCy1f1FtKC137xvxNAAAAZk"]
[Tue Jul 21 08:53:44.637292 2026] [security2:error] [pid 559070:tid 559132] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/d62.php"] [unique_id "al9dyCy1f1FtKC137xvxOAABnT0"]
[Tue Jul 21 08:53:44.655619 2026] [security2:error] [pid 533360:tid 533466] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/ups.php"] [unique_id "al9dyHUPuLYrePtEkUcaXAAA3mY"]
[Tue Jul 21 08:53:44.671040 2026] [security2:error] [pid 559070:tid 559133] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/k.php"] [unique_id "al9dyCy1f1FtKC137xvxOQABoj4"]
[Tue Jul 21 08:53:44.685788 2026] [security2:error] [pid 533360:tid 533395] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/k2.php"] [unique_id "al9dyHUPuLYrePtEkUcaXQAA-h8"]
[Tue Jul 21 08:53:44.702546 2026] [security2:error] [pid 559070:tid 559134] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/k3.php"] [unique_id "al9dyCy1f1FtKC137xvxOgABoz8"]
[Tue Jul 21 08:53:44.740824 2026] [security2:error] [pid 533360:tid 533399] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/k4.php"] [unique_id "al9dyHUPuLYrePtEkUcaZQAAnCM"]
[Tue Jul 21 08:53:44.760391 2026] [security2:error] [pid 559070:tid 559139] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/k5.php"] [unique_id "al9dyCy1f1FtKC137xvxOwABpkQ"]
[Tue Jul 21 08:53:44.807127 2026] [security2:error] [pid 533360:tid 533502] [client 20.197.192.193:52677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/ee.php"] [unique_id "al9dyHUPuLYrePtEkUcaagAAAI4"]
[Tue Jul 21 08:53:44.868664 2026] [security2:error] [pid 533360:tid 533510] [client 20.151.10.161:52159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/v543.php"] [unique_id "al9dyHUPuLYrePtEkUcacQAAAJY"]
[Tue Jul 21 08:53:45.164623 2026] [security2:error] [pid 533360:tid 533565] [client 20.151.10.161:52126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/w3lls.php"] [unique_id "al9dyXUPuLYrePtEkUcaeQAAAM0"]
[Tue Jul 21 08:53:45.339770 2026] [security2:error] [pid 559070:tid 559201] [client 168.167.81.163:63071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dySy1f1FtKC137xvxQAAAAZA"]
[Tue Jul 21 08:53:45.340038 2026] [security2:error] [pid 559070:tid 559201] [client 168.167.81.163:63071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9dySy1f1FtKC137xvxQAAAAZA"]
[Tue Jul 21 08:53:45.404666 2026] [security2:error] [pid 533360:tid 533503] [client 20.151.10.161:51019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ups.php"] [unique_id "al9dyXUPuLYrePtEkUcagQAAAI8"]
[Tue Jul 21 08:53:45.417201 2026] [security2:error] [pid 533360:tid 533364] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/w.php"] [unique_id "al9dyXUPuLYrePtEkUcagwAA5QA"]
[Tue Jul 21 08:53:45.450354 2026] [security2:error] [pid 559070:tid 559249] [client 20.151.10.161:52206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-ws68.php"] [unique_id "al9dySy1f1FtKC137xvxQgAAAcA"]
[Tue Jul 21 08:53:45.518307 2026] [security2:error] [pid 559070:tid 559224] [client 65.21.113.253:43444] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dySy1f1FtKC137xvxPwAAAac"]
[Tue Jul 21 08:53:45.583705 2026] [security2:error] [pid 559070:tid 559203] [client 185.191.171.13:51290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "swingcuiaba.com.br"] [uri "/robots.txt"] [unique_id "al9dySy1f1FtKC137xvxRAAAAZI"]
[Tue Jul 21 08:53:45.583875 2026] [security2:error] [pid 559070:tid 559203] [client 185.191.171.13:51290] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "swingcuiaba.com.br"] [uri "/robots.txt"] [unique_id "al9dySy1f1FtKC137xvxRAAAAZI"]
[Tue Jul 21 08:53:45.584525 2026] [security2:error] [pid 533360:tid 533499] [client 59.95.197.55:63539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dyXUPuLYrePtEkUcaiQAAAIs"]
[Tue Jul 21 08:53:45.584613 2026] [security2:error] [pid 533360:tid 533499] [client 59.95.197.55:63539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dyXUPuLYrePtEkUcaiQAAAIs"]
[Tue Jul 21 08:53:45.751409 2026] [security2:error] [pid 559070:tid 559141] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/fpwch.php"] [unique_id "al9dySy1f1FtKC137xvxRgABt0Y"]
[Tue Jul 21 08:53:45.768441 2026] [security2:error] [pid 533360:tid 533486] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/w2025.php"] [unique_id "al9dyXUPuLYrePtEkUcajwAAmno"]
[Tue Jul 21 08:53:45.786119 2026] [security2:error] [pid 559070:tid 559142] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/scxy.php"] [unique_id "al9dySy1f1FtKC137xvxRwABukc"]
[Tue Jul 21 08:53:45.802066 2026] [security2:error] [pid 533360:tid 533394] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/FWAZ.php"] [unique_id "al9dyXUPuLYrePtEkUcakQAAih4"]
[Tue Jul 21 08:53:45.818083 2026] [security2:error] [pid 559070:tid 559143] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/qterm.php"] [unique_id "al9dySy1f1FtKC137xvxSAABu0g"]
[Tue Jul 21 08:53:45.845512 2026] [security2:error] [pid 559070:tid 559252] [client 20.197.192.193:50613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/blue.php"] [unique_id "al9dySy1f1FtKC137xvxSQAAAcM"]
[Tue Jul 21 08:53:45.855720 2026] [security2:error] [pid 533360:tid 533431] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/blurbs.php"] [unique_id "al9dyXUPuLYrePtEkUcakwAA2EM"]
[Tue Jul 21 08:53:45.924247 2026] [security2:error] [pid 559070:tid 559122] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/v543.php"] [unique_id "al9dySy1f1FtKC137xvxSgABxzM"]
[Tue Jul 21 08:53:45.942898 2026] [security2:error] [pid 533360:tid 533424] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/w3lls.php"] [unique_id "al9dyXUPuLYrePtEkUcalAAAzzw"]
[Tue Jul 21 08:53:45.971466 2026] [security2:error] [pid 559070:tid 559149] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-ws68.php"] [unique_id "al9dySy1f1FtKC137xvxTAABr04"]
[Tue Jul 21 08:53:46.040588 2026] [security2:error] [pid 559070:tid 559261] [client 203.25.124.70:21899] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/css/index.php"] [unique_id "al9dyiy1f1FtKC137xvxTwAAAcw"]
[Tue Jul 21 08:53:46.078034 2026] [security2:error] [pid 559070:tid 559250] [client 185.191.171.1:17350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "swingcuiaba.com.br"] [uri "/2320-2/"] [unique_id "al9dyiy1f1FtKC137xvxUAAAAcE"]
[Tue Jul 21 08:53:46.078165 2026] [security2:error] [pid 559070:tid 559250] [client 185.191.171.1:17350] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "swingcuiaba.com.br"] [uri "/2320-2/"] [unique_id "al9dyiy1f1FtKC137xvxUAAAAcE"]
[Tue Jul 21 08:53:46.090227 2026] [security2:error] [pid 559070:tid 559263] [client 20.151.10.161:52219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/xyn.php"] [unique_id "al9dyiy1f1FtKC137xvxUQAAAc4"]
[Tue Jul 21 08:53:46.119561 2026] [security2:error] [pid 533360:tid 533483] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/xyn.php"] [unique_id "al9dynUPuLYrePtEkUcamwAAnHc"]
[Tue Jul 21 08:53:46.151988 2026] [security2:error] [pid 559070:tid 559097] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/green3.php"] [unique_id "al9dyiy1f1FtKC137xvxUgABzxo"]
[Tue Jul 21 08:53:46.288399 2026] [security2:error] [pid 533360:tid 533461] [remote 195.26.244.42:58190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "essenceclinicadesaude.com.br"] [uri "/wp-login.php"] [unique_id "al9dynUPuLYrePtEkUcanwAAuWE"]
[Tue Jul 21 08:53:46.390067 2026] [security2:error] [pid 559070:tid 559260] [client 114.198.138.124:58924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dyiy1f1FtKC137xvxVQAAAcs"]
[Tue Jul 21 08:53:46.390195 2026] [security2:error] [pid 559070:tid 559260] [client 114.198.138.124:58924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9dyiy1f1FtKC137xvxVQAAAcs"]
[Tue Jul 21 08:53:46.418499 2026] [security2:error] [pid 559070:tid 559092] [remote 45.79.123.44:34518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detetiveespecialista.com"] [uri "/wp-login.php"] [unique_id "al9dyiy1f1FtKC137xvxVgABrhU"]
[Tue Jul 21 08:53:46.841115 2026] [security2:error] [pid 533360:tid 533377] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/ccs.php"] [unique_id "al9dynUPuLYrePtEkUcaqwAAig0"]
[Tue Jul 21 08:53:46.854692 2026] [security2:error] [pid 559070:tid 559276] [client 20.104.96.117:4078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/albin.php"] [unique_id "al9dyiy1f1FtKC137xvxWgAAAds"]
[Tue Jul 21 08:53:47.103253 2026] [security2:error] [pid 533360:tid 533612] [client 20.151.10.161:52167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/green3.php"] [unique_id "al9dy3UPuLYrePtEkUcasgAAAPw"]
[Tue Jul 21 08:53:47.118870 2026] [security2:error] [pid 559070:tid 559278] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9dyyy1f1FtKC137xvxWwAB3Ts"]
[Tue Jul 21 08:53:47.157435 2026] [security2:error] [pid 559070:tid 559184] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/ccc.php"] [unique_id "al9dyyy1f1FtKC137xvxXwAB5XE"]
[Tue Jul 21 08:53:47.229664 2026] [security2:error] [pid 533360:tid 533465] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/get.php"] [unique_id "al9dy3UPuLYrePtEkUcatgAA22U"]
[Tue Jul 21 08:53:47.244595 2026] [security2:error] [pid 533360:tid 533534] [client 212.32.76.8:61355] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/theme-check/theme-check.php"] [unique_id "al9dy3UPuLYrePtEkUcatwAAAK4"]
[Tue Jul 21 08:53:47.489934 2026] [security2:error] [pid 533360:tid 533453] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/images.php"] [unique_id "al9dy3UPuLYrePtEkUcawAAAr1k"]
[Tue Jul 21 08:53:47.504124 2026] [security2:error] [pid 559070:tid 559119] [remote 103.161.172.221:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samilacalculos.com.br"] [uri "/wp-login.php"] [unique_id "al9dyyy1f1FtKC137xvxZQAB6TA"]
[Tue Jul 21 08:53:47.609846 2026] [security2:error] [pid 533360:tid 533378] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/alls.php"] [unique_id "al9dy3UPuLYrePtEkUcaxQAA4g4"]
[Tue Jul 21 08:53:47.659455 2026] [security2:error] [pid 533360:tid 533560] [client 20.151.10.161:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/k.php"] [unique_id "al9dy3UPuLYrePtEkUcaxwAAAMg"]
[Tue Jul 21 08:53:47.676445 2026] [security2:error] [pid 559070:tid 559306] [client 20.151.10.161:52117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/ccs.php"] [unique_id "al9dyyy1f1FtKC137xvxZwAAAfk"]
[Tue Jul 21 08:53:47.725025 2026] [security2:error] [pid 533360:tid 533480] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/yyu.php"] [unique_id "al9dy3UPuLYrePtEkUcayQAAkHQ"]
[Tue Jul 21 08:53:47.969565 2026] [security2:error] [pid 533360:tid 533397] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/by.php"] [unique_id "al9dy3UPuLYrePtEkUcazwAA7iE"]
[Tue Jul 21 08:53:48.047923 2026] [security2:error] [pid 533360:tid 533411] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/FAQ.php"] [unique_id "al9dzHUPuLYrePtEkUca1AAA9i8"]
[Tue Jul 21 08:53:48.070094 2026] [security2:error] [pid 533360:tid 533416] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/coffexium.php"] [unique_id "al9dzHUPuLYrePtEkUca2AAA-zQ"]
[Tue Jul 21 08:53:48.085491 2026] [security2:error] [pid 533360:tid 533466] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/red.php"] [unique_id "al9dzHUPuLYrePtEkUca3AAAj2Y"]
[Tue Jul 21 08:53:48.117711 2026] [security2:error] [pid 533360:tid 533512] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dy3UPuLYrePtEkUcazgAAmC4"]
[Tue Jul 21 08:53:48.197312 2026] [security2:error] [pid 533360:tid 533535] [client 20.151.10.161:52211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/ccc.php"] [unique_id "al9dzHUPuLYrePtEkUca4QAAAK8"]
[Tue Jul 21 08:53:48.227252 2026] [security2:error] [pid 533360:tid 533478] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9dzHUPuLYrePtEkUca5QAAqXI"]
[Tue Jul 21 08:53:48.355341 2026] [security2:error] [pid 533360:tid 533510] [client 74.7.244.33:48856] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9dzHUPuLYrePtEkUca6AAAAJY"]
[Tue Jul 21 08:53:48.481629 2026] [security2:error] [pid 533360:tid 533589] [client 20.151.10.161:49026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/get.php"] [unique_id "al9dzHUPuLYrePtEkUca7gAAAOU"]
[Tue Jul 21 08:53:48.585804 2026] [security2:error] [pid 559070:tid 559322] [client 20.197.192.193:50614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/wp-signup.php"] [unique_id "al9dzCy1f1FtKC137xvxbgAAAgk"]
[Tue Jul 21 08:53:48.619968 2026] [security2:error] [pid 533360:tid 533429] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/footer.php"] [unique_id "al9dzHUPuLYrePtEkUca9AAA9UE"]
[Tue Jul 21 08:53:48.623134 2026] [security2:error] [pid 559070:tid 559327] [client 20.151.10.161:52210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/get.php"] [unique_id "al9dzCy1f1FtKC137xvxcgAAAg4"]
[Tue Jul 21 08:53:48.793907 2026] [security2:error] [pid 533360:tid 533449] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-content/index.php"] [unique_id "al9dzHUPuLYrePtEkUcbAQAA21U"]
[Tue Jul 21 08:53:48.826074 2026] [security2:error] [pid 533360:tid 533602] [client 65.21.113.253:35260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9dzHUPuLYrePtEkUcbAgAAAPI"]
[Tue Jul 21 08:53:48.837591 2026] [security2:error] [pid 533360:tid 533380] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/zoro.php"] [unique_id "al9dzHUPuLYrePtEkUcbAwAAxhA"]
[Tue Jul 21 08:53:48.884173 2026] [security2:error] [pid 533360:tid 533548] [client 74.7.244.33:41916] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dzHUPuLYrePtEkUca-AAAvCQ"], referer: http://transitoaberto.com.br/robots.txt
[Tue Jul 21 08:53:48.896282 2026] [security2:error] [pid 533360:tid 533393] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/admin.php"] [unique_id "al9dzHUPuLYrePtEkUcbBQAA3x0"]
[Tue Jul 21 08:53:49.030966 2026] [security2:error] [pid 533360:tid 533364] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/greap.php"] [unique_id "al9dzXUPuLYrePtEkUcbBwAArwA"]
[Tue Jul 21 08:53:49.082898 2026] [security2:error] [pid 533360:tid 533415] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/177.php"] [unique_id "al9dzXUPuLYrePtEkUcbCAAAqTM"]
[Tue Jul 21 08:53:49.112224 2026] [security2:error] [pid 533360:tid 533546] [client 20.151.10.161:52160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/images.php"] [unique_id "al9dzXUPuLYrePtEkUcbCgAAALo"]
[Tue Jul 21 08:53:49.113016 2026] [security2:error] [pid 533360:tid 533502] [client 113.22.144.139:65317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dzXUPuLYrePtEkUcbCwAAAI4"]
[Tue Jul 21 08:53:49.113085 2026] [security2:error] [pid 533360:tid 533502] [client 113.22.144.139:65317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dzXUPuLYrePtEkUcbCwAAAI4"]
[Tue Jul 21 08:53:49.120526 2026] [security2:error] [pid 533360:tid 533375] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/199.php"] [unique_id "al9dzXUPuLYrePtEkUcbDAAA6gs"]
[Tue Jul 21 08:53:49.209618 2026] [security2:error] [pid 533360:tid 533369] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/file52.php"] [unique_id "al9dzXUPuLYrePtEkUcbFAAA4gU"]
[Tue Jul 21 08:53:49.235304 2026] [security2:error] [pid 559070:tid 559220] [client 203.25.124.70:64717] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/wp-conflg.php"] [unique_id "al9dzSy1f1FtKC137xvxgAAAAaM"]
[Tue Jul 21 08:53:49.236152 2026] [security2:error] [pid 533360:tid 533462] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dzXUPuLYrePtEkUcbFwAAoGI"]
[Tue Jul 21 08:53:49.236287 2026] [security2:error] [pid 533360:tid 533520] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dzXUPuLYrePtEkUcbFwAAoGI"]
[Tue Jul 21 08:53:49.267611 2026] [security2:error] [pid 533360:tid 533486] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/122.php"] [unique_id "al9dzXUPuLYrePtEkUcbGQAAxXo"]
[Tue Jul 21 08:53:49.284452 2026] [security2:error] [pid 533360:tid 533394] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/green1.php"] [unique_id "al9dzXUPuLYrePtEkUcbGgAAsB4"]
[Tue Jul 21 08:53:49.301502 2026] [security2:error] [pid 533360:tid 533469] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/biufile.php"] [unique_id "al9dzXUPuLYrePtEkUcbGwAAmmk"]
[Tue Jul 21 08:53:49.365373 2026] [security2:error] [pid 533360:tid 533379] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wpconf.php"] [unique_id "al9dzXUPuLYrePtEkUcbHwAAzw8"]
[Tue Jul 21 08:53:49.403108 2026] [security2:error] [pid 533360:tid 533464] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/mosty.php"] [unique_id "al9dzXUPuLYrePtEkUcbIAAA2mQ"]
[Tue Jul 21 08:53:49.457429 2026] [security2:error] [pid 533360:tid 533424] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/dejavu.php"] [unique_id "al9dzXUPuLYrePtEkUcbJAAAzTw"]
[Tue Jul 21 08:53:49.483795 2026] [security2:error] [pid 533360:tid 533404] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/aaf.php"] [unique_id "al9dzXUPuLYrePtEkUcbJgAA2yg"]
[Tue Jul 21 08:53:49.500733 2026] [security2:error] [pid 533360:tid 533483] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/term.php"] [unique_id "al9dzXUPuLYrePtEkUcbJwAA9nc"]
[Tue Jul 21 08:53:49.516849 2026] [security2:error] [pid 533360:tid 533407] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/ha.php"] [unique_id "al9dzXUPuLYrePtEkUcbKAAA8Ss"]
[Tue Jul 21 08:53:49.546531 2026] [security2:error] [pid 533360:tid 533445] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/hur.php"] [unique_id "al9dzXUPuLYrePtEkUcbKwAA81E"]
[Tue Jul 21 08:53:49.584668 2026] [security2:error] [pid 559070:tid 559203] [client 20.151.10.161:37837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/alls.php"] [unique_id "al9dzSy1f1FtKC137xvxhQAAAZI"]
[Tue Jul 21 08:53:49.599595 2026] [security2:error] [pid 533360:tid 533461] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/h02ugyh.php"] [unique_id "al9dzXUPuLYrePtEkUcbLAAAxmE"]
[Tue Jul 21 08:53:49.616678 2026] [security2:error] [pid 533360:tid 533384] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/seiso.php"] [unique_id "al9dzXUPuLYrePtEkUcbLgABARQ"]
[Tue Jul 21 08:53:49.634556 2026] [security2:error] [pid 533360:tid 533418] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/155.php"] [unique_id "al9dzXUPuLYrePtEkUcbLwAA3zY"]
[Tue Jul 21 08:53:49.651902 2026] [security2:error] [pid 533360:tid 533396] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/ppp.php"] [unique_id "al9dzXUPuLYrePtEkUcbMAAAuSA"]
[Tue Jul 21 08:53:49.669057 2026] [security2:error] [pid 533360:tid 533377] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/201.php"] [unique_id "al9dzXUPuLYrePtEkUcbMwAAog0"]
[Tue Jul 21 08:53:49.706162 2026] [security2:error] [pid 533360:tid 533439] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/ops.php"] [unique_id "al9dzXUPuLYrePtEkUcbNAAA10s"]
[Tue Jul 21 08:53:49.723535 2026] [security2:error] [pid 533360:tid 533425] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/ingfo.php"] [unique_id "al9dzXUPuLYrePtEkUcbNQAAvj0"]
[Tue Jul 21 08:53:49.756965 2026] [security2:error] [pid 533360:tid 533489] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/error_log.php"] [unique_id "al9dzXUPuLYrePtEkUcbNgAAr30"]
[Tue Jul 21 08:53:49.772474 2026] [security2:error] [pid 533360:tid 533423] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/xenon1337.php"] [unique_id "al9dzXUPuLYrePtEkUcbNwAAqTs"]
[Tue Jul 21 08:53:49.892729 2026] [security2:error] [pid 533360:tid 533440] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/test11.php"] [unique_id "al9dzXUPuLYrePtEkUcbOgAA6kw"]
[Tue Jul 21 08:53:49.912840 2026] [security2:error] [pid 533360:tid 533365] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/koala.php"] [unique_id "al9dzXUPuLYrePtEkUcbPAAArAE"]
[Tue Jul 21 08:53:49.931096 2026] [security2:error] [pid 533360:tid 533605] [client 65.21.113.253:34854] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9dzXUPuLYrePtEkUcbKgAAAPU"]
[Tue Jul 21 08:53:50.084060 2026] [security2:error] [pid 533360:tid 533453] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/mac.php"] [unique_id "al9dznUPuLYrePtEkUcbQQAAx1k"]
[Tue Jul 21 08:53:50.094034 2026] [security2:error] [pid 533360:tid 533613] [client 20.220.225.223:59141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/else1.php"] [unique_id "al9dznUPuLYrePtEkUcbQgAAAP0"]
[Tue Jul 21 08:53:50.208970 2026] [security2:error] [pid 533360:tid 533491] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9dznUPuLYrePtEkUcbQwAAlX8"]
[Tue Jul 21 08:53:50.240902 2026] [security2:error] [pid 533360:tid 533507] [client 198.44.157.162:40232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9dznUPuLYrePtEkUcbRQAAAJM"]
[Tue Jul 21 08:53:50.241008 2026] [security2:error] [pid 533360:tid 533507] [client 198.44.157.162:40232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9dznUPuLYrePtEkUcbRQAAAJM"]
[Tue Jul 21 08:53:50.281681 2026] [security2:error] [pid 533360:tid 533378] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wefile.php"] [unique_id "al9dznUPuLYrePtEkUcbRwAA5Q4"]
[Tue Jul 21 08:53:50.436195 2026] [security2:error] [pid 533360:tid 533598] [client 20.151.10.161:37838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/yyu.php"] [unique_id "al9dznUPuLYrePtEkUcbTQAAAO4"]
[Tue Jul 21 08:53:50.629844 2026] [security2:error] [pid 533360:tid 533397] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9dznUPuLYrePtEkUcbVAAAnyE"]
[Tue Jul 21 08:53:50.634795 2026] [security2:error] [pid 559070:tid 559086] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dziy1f1FtKC137xvxmAAB1Q8"]
[Tue Jul 21 08:53:50.634949 2026] [security2:error] [pid 559070:tid 559270] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9dziy1f1FtKC137xvxmAAB1Q8"]
[Tue Jul 21 08:53:50.780765 2026] [security2:error] [pid 533360:tid 533416] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/2P.php"] [unique_id "al9dznUPuLYrePtEkUcbWgAAvjQ"]
[Tue Jul 21 08:53:50.797520 2026] [security2:error] [pid 533360:tid 533466] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/.well-known/about.php"] [unique_id "al9dznUPuLYrePtEkUcbWwAAqWY"]
[Tue Jul 21 08:53:50.830672 2026] [security2:error] [pid 533360:tid 533388] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9dznUPuLYrePtEkUcbXAAAkhg"]
[Tue Jul 21 08:53:50.847757 2026] [security2:error] [pid 533360:tid 533410] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/bob.php"] [unique_id "al9dznUPuLYrePtEkUcbXQAA0y4"]
[Tue Jul 21 08:53:50.885829 2026] [security2:error] [pid 559070:tid 559194] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dziy1f1FtKC137xvxngABrHs"]
[Tue Jul 21 08:53:50.886120 2026] [security2:error] [pid 559070:tid 559229] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9dziy1f1FtKC137xvxngABrHs"]
[Tue Jul 21 08:53:50.933893 2026] [security2:error] [pid 533360:tid 533528] [client 20.220.225.223:48232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/billur.php"] [unique_id "al9dznUPuLYrePtEkUcbYAAAAKg"]
[Tue Jul 21 08:53:50.963679 2026] [security2:error] [pid 559070:tid 559287] [client 20.151.10.161:52163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/by.php"] [unique_id "al9dziy1f1FtKC137xvxnwAAAeY"]
[Tue Jul 21 08:53:51.017054 2026] [security2:error] [pid 533360:tid 533374] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/crgio.php"] [unique_id "al9dz3UPuLYrePtEkUcbZgAAyAo"]
[Tue Jul 21 08:53:51.173354 2026] [security2:error] [pid 533360:tid 533504] [client 20.151.10.161:51031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/k2.php"] [unique_id "al9dz3UPuLYrePtEkUcbaAAAAJA"]
[Tue Jul 21 08:53:51.175700 2026] [security2:error] [pid 533360:tid 533442] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/pucci.php"] [unique_id "al9dz3UPuLYrePtEkUcbaQAAoE4"]
[Tue Jul 21 08:53:51.343590 2026] [security2:error] [pid 559070:tid 559294] [client 203.25.124.65:43923] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/function/function.php"] [unique_id "al9dzyy1f1FtKC137xvxoQAAAe0"]
[Tue Jul 21 08:53:51.571847 2026] [security2:error] [pid 533360:tid 533460] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-temp.php"] [unique_id "al9dz3UPuLYrePtEkUcbdwAA8WA"]
[Tue Jul 21 08:53:51.572780 2026] [security2:error] [pid 559070:tid 559259] [client 20.220.225.223:22547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/dr.php"] [unique_id "al9dzyy1f1FtKC137xvxqAAAAco"]
[Tue Jul 21 08:53:51.825500 2026] [security2:error] [pid 533360:tid 533534] [client 85.208.96.196:57404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivaconcierge.com.br"] [uri "/banners/banner-de-exemplo-01/"] [unique_id "al9dz3UPuLYrePtEkUcbewAAAK4"]
[Tue Jul 21 08:53:51.825596 2026] [security2:error] [pid 533360:tid 533534] [client 85.208.96.196:57404] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vivaconcierge.com.br"] [uri "/banners/banner-de-exemplo-01/"] [unique_id "al9dz3UPuLYrePtEkUcbewAAAK4"]
[Tue Jul 21 08:53:51.982641 2026] [security2:error] [pid 533360:tid 533578] [client 5.38.115.39:36930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dz3UPuLYrePtEkUcbfwAAANo"]
[Tue Jul 21 08:53:51.982745 2026] [security2:error] [pid 533360:tid 533578] [client 5.38.115.39:36930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9dz3UPuLYrePtEkUcbfwAAANo"]
[Tue Jul 21 08:53:52.103777 2026] [security2:error] [pid 559070:tid 559204] [client 20.151.10.161:46062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9d0Cy1f1FtKC137xvxtAAAAZM"]
[Tue Jul 21 08:53:52.137182 2026] [security2:error] [pid 559070:tid 559299] [client 20.104.96.117:3982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/cilus.php"] [unique_id "al9d0Cy1f1FtKC137xvxtQAAAfI"]
[Tue Jul 21 08:53:52.201272 2026] [security2:error] [pid 559070:tid 559292] [client 152.59.181.104:61755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9d0Cy1f1FtKC137xvxtgAAAes"]
[Tue Jul 21 08:53:52.205243 2026] [security2:error] [pid 559070:tid 559292] [client 152.59.181.104:61755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9d0Cy1f1FtKC137xvxtgAAAes"]
[Tue Jul 21 08:53:52.287098 2026] [security2:error] [pid 559070:tid 559297] [client 41.89.234.2:50097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d0Cy1f1FtKC137xvxtwAAAfA"]
[Tue Jul 21 08:53:52.287387 2026] [security2:error] [pid 559070:tid 559297] [client 41.89.234.2:50097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d0Cy1f1FtKC137xvxtwAAAfA"]
[Tue Jul 21 08:53:52.453573 2026] [security2:error] [pid 559070:tid 559211] [client 20.151.10.161:52188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/FAQ.php"] [unique_id "al9d0Cy1f1FtKC137xvxuQAAAZo"]
[Tue Jul 21 08:53:52.463621 2026] [security2:error] [pid 559070:tid 559215] [client 20.220.225.223:48246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/mimpi.php"] [unique_id "al9d0Cy1f1FtKC137xvxugAAAZ4"]
[Tue Jul 21 08:53:52.522083 2026] [security2:error] [pid 533360:tid 533516] [client 103.59.206.240:31174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d0HUPuLYrePtEkUcbhwAAAJw"]
[Tue Jul 21 08:53:52.522210 2026] [security2:error] [pid 533360:tid 533516] [client 103.59.206.240:31174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d0HUPuLYrePtEkUcbhwAAAJw"]
[Tue Jul 21 08:53:52.646505 2026] [security2:error] [pid 559070:tid 559248] [client 212.32.76.6:53547] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/index.php"] [unique_id "al9d0Cy1f1FtKC137xvxvQAAAb8"]
[Tue Jul 21 08:53:52.978872 2026] [security2:error] [pid 533360:tid 533546] [client 182.189.99.211:48316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d0HUPuLYrePtEkUcbkgAAALo"]
[Tue Jul 21 08:53:52.979005 2026] [security2:error] [pid 533360:tid 533546] [client 182.189.99.211:48316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d0HUPuLYrePtEkUcbkgAAALo"]
[Tue Jul 21 08:53:52.996520 2026] [security2:error] [pid 533360:tid 533462] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9d0HUPuLYrePtEkUcblQAA1GI"]
[Tue Jul 21 08:53:53.142120 2026] [security2:error] [pid 559070:tid 559266] [client 20.104.96.117:4008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/gptsh.php"] [unique_id "al9d0Sy1f1FtKC137xvxxgAAAdE"]
[Tue Jul 21 08:53:53.201615 2026] [security2:error] [pid 533360:tid 533469] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/puc.php"] [unique_id "al9d0XUPuLYrePtEkUcbmAAA5Wk"]
[Tue Jul 21 08:53:53.347434 2026] [security2:error] [pid 559070:tid 559231] [client 212.32.76.7:29579] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/network/upgrade/index.php"] [unique_id "al9d0Sy1f1FtKC137xvxyQAAAa4"]
[Tue Jul 21 08:53:53.357391 2026] [security2:error] [pid 533360:tid 533611] [client 65.21.113.253:35260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9d0XUPuLYrePtEkUcbmgAAAPs"]
[Tue Jul 21 08:53:53.412008 2026] [security2:error] [pid 533360:tid 533592] [client 20.151.10.161:46058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9d0XUPuLYrePtEkUcbngAAAOg"]
[Tue Jul 21 08:53:53.421438 2026] [security2:error] [pid 533360:tid 533601] [client 127.0.0.1:23160] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al9d0XUPuLYrePtEkUcbnQAAAPE"]
[Tue Jul 21 08:53:53.421504 2026] [security2:error] [pid 559070:tid 559269] [client 127.0.0.1:23154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.royalbsolutions.com"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al9d0Sy1f1FtKC137xvxywAAAdQ"]
[Tue Jul 21 08:53:53.421542 2026] [security2:error] [pid 533360:tid 533565] [client 74.7.241.139:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.royalbsolutions.com"] [uri "/robots.txt"] [unique_id "al9d0XUPuLYrePtEkUcbnAAAzWQ"]
[Tue Jul 21 08:53:53.601670 2026] [security2:error] [pid 533360:tid 533407] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/themes.php"] [unique_id "al9d0XUPuLYrePtEkUcbqAAA3Cs"]
[Tue Jul 21 08:53:53.641722 2026] [security2:error] [pid 533360:tid 533450] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/dx.php"] [unique_id "al9d0XUPuLYrePtEkUcbqgAAvlY"]
[Tue Jul 21 08:53:53.680995 2026] [security2:error] [pid 533360:tid 533461] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/p.php"] [unique_id "al9d0XUPuLYrePtEkUcbqwAAr2E"]
[Tue Jul 21 08:53:53.754420 2026] [security2:error] [pid 533360:tid 533458] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/bthil.php"] [unique_id "al9d0XUPuLYrePtEkUcbrQAAtF4"]
[Tue Jul 21 08:53:53.802526 2026] [security2:error] [pid 533360:tid 533396] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/7.php"] [unique_id "al9d0XUPuLYrePtEkUcbrwAAvCA"]
[Tue Jul 21 08:53:53.836267 2026] [security2:error] [pid 533360:tid 533490] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/8.php"] [unique_id "al9d0XUPuLYrePtEkUcbsAABAX4"]
[Tue Jul 21 08:53:53.889937 2026] [security2:error] [pid 533360:tid 533455] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9d0XUPuLYrePtEkUcbsgAA11s"]
[Tue Jul 21 08:53:53.890081 2026] [security2:error] [pid 533360:tid 533575] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9d0XUPuLYrePtEkUcbsgAA11s"]
[Tue Jul 21 08:53:53.960707 2026] [security2:error] [pid 559070:tid 559275] [client 20.151.10.161:51034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/k3.php"] [unique_id "al9d0Sy1f1FtKC137xvx1gAAAdo"]
[Tue Jul 21 08:53:54.044313 2026] [security2:error] [pid 559070:tid 559258] [client 203.25.124.74:36685] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "al9d0iy1f1FtKC137xvx2AAAAck"]
[Tue Jul 21 08:53:54.121624 2026] [security2:error] [pid 533360:tid 533425] [remote 20.206.105.145:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.wendelleite.com.br"] [uri "/1.php"] [unique_id "al9d0nUPuLYrePtEkUcbtgAAnD0"]
[Tue Jul 21 08:53:54.121732 2026] [security2:error] [pid 533360:tid 533425] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/1.php"] [unique_id "al9d0nUPuLYrePtEkUcbtgAAnD0"]
[Tue Jul 21 08:53:54.159287 2026] [security2:error] [pid 533360:tid 533402] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/100.php"] [unique_id "al9d0nUPuLYrePtEkUcbuQAA6iY"]
[Tue Jul 21 08:53:54.186772 2026] [security2:error] [pid 533360:tid 533436] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/about.php"] [unique_id "al9d0nUPuLYrePtEkUcbugAA4kg"]
[Tue Jul 21 08:53:54.199466 2026] [security2:error] [pid 533360:tid 533525] [client 45.15.74.108:61037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.74.15.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "homemsedutoronline.com"] [uri "/wp-comments-post.php"] [unique_id "al9d0nUPuLYrePtEkUcbtAAAAKU"], referer: https://homemsedutoronline.com/2023/07/18/hello-world/#comment-5387
[Tue Jul 21 08:53:54.199606 2026] [security2:error] [pid 533360:tid 533525] [client 45.15.74.108:61037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "homemsedutoronline.com"] [uri "/wp-comments-post.php"] [unique_id "al9d0nUPuLYrePtEkUcbtAAAAKU"], referer: https://homemsedutoronline.com/2023/07/18/hello-world/#comment-5387
[Tue Jul 21 08:53:54.294072 2026] [security2:error] [pid 533360:tid 533440] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/admin.php"] [unique_id "al9d0nUPuLYrePtEkUcbvAAAx0w"]
[Tue Jul 21 08:53:54.475160 2026] [security2:error] [pid 533360:tid 533441] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/edit.php"] [unique_id "al9d0nUPuLYrePtEkUcbwAAA9E0"]
[Tue Jul 21 08:53:54.496182 2026] [security2:error] [pid 533360:tid 533506] [client 65.21.113.253:34860] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9d0nUPuLYrePtEkUcbtQAAAJI"]
[Tue Jul 21 08:53:54.745748 2026] [security2:error] [pid 559070:tid 559210] [client 203.25.124.48:46429] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9d0iy1f1FtKC137xvx5AAAAZk"]
[Tue Jul 21 08:53:54.770960 2026] [security2:error] [pid 533360:tid 533385] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9d0nUPuLYrePtEkUcbyAAAphU"]
[Tue Jul 21 08:53:54.845201 2026] [security2:error] [pid 559070:tid 559297] [client 20.220.225.223:6143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/tkikikoko.php"] [unique_id "al9d0iy1f1FtKC137xvx5QAAAfA"]
[Tue Jul 21 08:53:55.061711 2026] [security2:error] [pid 559070:tid 559311] [client 173.252.95.30:47722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9d0yy1f1FtKC137xvx6QAAAf4"]
[Tue Jul 21 08:53:55.084898 2026] [security2:error] [pid 559070:tid 559242] [client 20.151.10.161:52222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/coffexium.php"] [unique_id "al9d0yy1f1FtKC137xvx6gAAAbk"]
[Tue Jul 21 08:53:55.160818 2026] [security2:error] [pid 533360:tid 533430] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/f6.php"] [unique_id "al9d03UPuLYrePtEkUcb0gAA80I"]
[Tue Jul 21 08:53:55.176586 2026] [security2:error] [pid 533360:tid 533477] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/inputs.php"] [unique_id "al9d03UPuLYrePtEkUcb0wAA2XE"]
[Tue Jul 21 08:53:55.193138 2026] [security2:error] [pid 533360:tid 533421] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/av.php"] [unique_id "al9d03UPuLYrePtEkUcb1AAAnzk"]
[Tue Jul 21 08:53:55.213860 2026] [security2:error] [pid 533360:tid 533397] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/classwithtostring.php"] [unique_id "al9d03UPuLYrePtEkUcb1QABAiE"]
[Tue Jul 21 08:53:55.343560 2026] [security2:error] [pid 533360:tid 533613] [client 172.238.32.188:54576] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "consultecobertura.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9d03UPuLYrePtEkUcb1wAAAP0"]
[Tue Jul 21 08:53:55.351493 2026] [security2:error] [pid 533360:tid 533454] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9d03UPuLYrePtEkUcb2AAA3Fo"]
[Tue Jul 21 08:53:55.503092 2026] [security2:error] [pid 533360:tid 533411] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-blog.php"] [unique_id "al9d03UPuLYrePtEkUcb4AAAty8"]
[Tue Jul 21 08:53:55.523740 2026] [security2:error] [pid 533360:tid 533532] [client 172.238.32.188:54576] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "consultecobertura.com.br"] [uri "/"] [unique_id "al9d03UPuLYrePtEkUcb4QAAAKw"]
[Tue Jul 21 08:53:55.738632 2026] [security2:error] [pid 559070:tid 559227] [client 20.104.96.117:46751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/rithin.php"] [unique_id "al9d0yy1f1FtKC137xvx8gAAAao"]
[Tue Jul 21 08:53:55.746370 2026] [security2:error] [pid 559070:tid 559250] [client 20.220.225.223:23482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wp-Blogs.php"] [unique_id "al9d0yy1f1FtKC137xvx8wAAAcE"]
[Tue Jul 21 08:53:55.749675 2026] [security2:error] [pid 533360:tid 533485] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9d03UPuLYrePtEkUcb6gAAyHk"]
[Tue Jul 21 08:53:55.767410 2026] [security2:error] [pid 533360:tid 533366] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/adminfuns.php"] [unique_id "al9d03UPuLYrePtEkUcb6wAAoQI"]
[Tue Jul 21 08:53:55.923934 2026] [security2:error] [pid 533360:tid 533559] [client 173.255.248.150:36832] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "br1102.hostgator.com.br"] [uri "/"] [unique_id "al9d03UPuLYrePtEkUcb7QAAAMc"]
[Tue Jul 21 08:53:56.031772 2026] [security2:error] [pid 559070:tid 559251] [client 59.95.197.55:64020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d1Cy1f1FtKC137xvx_AAAAcI"]
[Tue Jul 21 08:53:56.031891 2026] [security2:error] [pid 559070:tid 559251] [client 59.95.197.55:64020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d1Cy1f1FtKC137xvx_AAAAcI"]
[Tue Jul 21 08:53:56.043522 2026] [security2:error] [pid 559070:tid 559238] [client 203.25.124.52:37355] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/index.php"] [unique_id "al9d1Cy1f1FtKC137xvx_QAAAbU"]
[Tue Jul 21 08:53:56.070831 2026] [security2:error] [pid 559070:tid 559278] [client 20.151.10.161:52184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/red.php"] [unique_id "al9d1Cy1f1FtKC137xvx_gAAAd0"]
[Tue Jul 21 08:53:56.501455 2026] [proxy:error] [pid 559070:tid 559298] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:53:56.501501 2026] [proxy_http:error] [pid 559070:tid 559298] [client 20.151.10.161:52180] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:53:56.501991 2026] [proxy:error] [pid 559070:tid 559298] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:53:56.502020 2026] [proxy_http:error] [pid 559070:tid 559298] [client 20.151.10.161:52180] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:53:56.577804 2026] [security2:error] [pid 533360:tid 533489] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/goods.php"] [unique_id "al9d1HUPuLYrePtEkUccLgAA3H0"]
[Tue Jul 21 08:53:56.592661 2026] [security2:error] [pid 533360:tid 533503] [client 20.151.10.161:55835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/k4.php"] [unique_id "al9d1HUPuLYrePtEkUccLwAAAI8"]
[Tue Jul 21 08:53:56.671488 2026] [security2:error] [pid 533360:tid 533436] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/ms-edit.php"] [unique_id "al9d1HUPuLYrePtEkUccMgAAxUg"]
[Tue Jul 21 08:53:56.815697 2026] [security2:error] [pid 533360:tid 533430] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/222.php"] [unique_id "al9d1HUPuLYrePtEkUccQgAAr0I"]
[Tue Jul 21 08:53:56.832177 2026] [security2:error] [pid 533360:tid 533477] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9d1HUPuLYrePtEkUccQwAA03E"]
[Tue Jul 21 08:53:56.905135 2026] [security2:error] [pid 533360:tid 533454] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9d1HUPuLYrePtEkUccTwAAoVo"]
[Tue Jul 21 08:53:56.973343 2026] [security2:error] [pid 559070:tid 559302] [client 114.198.138.124:59504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9d1Cy1f1FtKC137xvyEwAAAfU"]
[Tue Jul 21 08:53:56.973513 2026] [security2:error] [pid 559070:tid 559302] [client 114.198.138.124:59504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9d1Cy1f1FtKC137xvyEwAAAfU"]
[Tue Jul 21 08:53:57.110010 2026] [security2:error] [pid 559070:tid 559246] [client 20.151.10.161:46025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/x.php"] [unique_id "al9d1Sy1f1FtKC137xvyFgAAAb0"]
[Tue Jul 21 08:53:57.228485 2026] [security2:error] [pid 533360:tid 533533] [client 203.25.124.41:52767] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/network/chosen.php"] [unique_id "al9d1XUPuLYrePtEkUccXgAAAK0"]
[Tue Jul 21 08:53:57.465579 2026] [security2:error] [pid 533360:tid 533390] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp.php"] [unique_id "al9d1XUPuLYrePtEkUccrgAAnxo"]
[Tue Jul 21 08:53:57.485542 2026] [security2:error] [pid 533360:tid 533378] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/abcd.php"] [unique_id "al9d1XUPuLYrePtEkUccrwABAg4"]
[Tue Jul 21 08:53:57.539306 2026] [security2:error] [pid 533360:tid 533437] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/a1.php"] [unique_id "al9d1XUPuLYrePtEkUccsQAArkk"]
[Tue Jul 21 08:53:57.556214 2026] [security2:error] [pid 533360:tid 533440] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9d1XUPuLYrePtEkUccsgAA6Ew"]
[Tue Jul 21 08:53:57.581701 2026] [security2:error] [pid 533360:tid 533583] [client 172.236.244.224:36436] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "rqracademy.com"] [uri "/wp-json/batch/v1"] [unique_id "al9d1XUPuLYrePtEkUccswAAAN8"]
[Tue Jul 21 08:53:57.694736 2026] [security2:error] [pid 533360:tid 533580] [client 20.151.10.161:52124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9d1XUPuLYrePtEkUccuQAAANw"]
[Tue Jul 21 08:53:57.758164 2026] [security2:error] [pid 533360:tid 533544] [client 172.236.244.224:36436] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "rqracademy.com"] [uri "/"] [unique_id "al9d1XUPuLYrePtEkUccuwAAALg"]
[Tue Jul 21 08:53:57.795957 2026] [security2:error] [pid 533360:tid 533553] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9d1XUPuLYrePtEkUcctwAAwQw"]
[Tue Jul 21 08:53:57.885729 2026] [security2:error] [pid 533360:tid 533571] [client 20.220.225.223:6130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wp-css.php"] [unique_id "al9d1XUPuLYrePtEkUccwAAAANM"]
[Tue Jul 21 08:53:58.054269 2026] [security2:error] [pid 533360:tid 533454] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9d1nUPuLYrePtEkUccxwAAs1o"]
[Tue Jul 21 08:53:58.203283 2026] [security2:error] [pid 533360:tid 533425] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/gettest.php"] [unique_id "al9d1nUPuLYrePtEkUcc8QAAxj0"]
[Tue Jul 21 08:53:58.211150 2026] [security2:error] [pid 533360:tid 533564] [client 65.21.113.253:35260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9d1nUPuLYrePtEkUcc8gAAAMw"]
[Tue Jul 21 08:53:58.355750 2026] [security2:error] [pid 559070:tid 559087] [remote 91.142.222.105:47746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "blissfullcleaning.net"] [uri "/wp-login.php"] [unique_id "al9d1iy1f1FtKC137xvyMgAB-RA"]
[Tue Jul 21 08:53:58.471318 2026] [security2:error] [pid 533360:tid 533581] [client 128.127.105.184:39922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9d1nUPuLYrePtEkUcc_wAAAN0"]
[Tue Jul 21 08:53:58.471367 2026] [proxy:error] [pid 559070:tid 559320] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:53:58.471397 2026] [security2:error] [pid 533360:tid 533581] [client 128.127.105.184:39922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9d1nUPuLYrePtEkUcc_wAAAN0"]
[Tue Jul 21 08:53:58.471411 2026] [proxy_http:error] [pid 559070:tid 559320] [client 20.151.10.161:52118] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:53:58.471978 2026] [proxy:error] [pid 559070:tid 559320] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:53:58.472003 2026] [proxy_http:error] [pid 559070:tid 559320] [client 20.151.10.161:52118] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:53:58.573091 2026] [security2:error] [pid 533360:tid 533469] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/simple.php"] [unique_id "al9d1nUPuLYrePtEkUcdAwAApWk"]
[Tue Jul 21 08:53:58.622119 2026] [security2:error] [pid 559070:tid 559205] [client 20.151.10.161:45985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/j260624_13.php"] [unique_id "al9d1iy1f1FtKC137xvyOgAAAZQ"]
[Tue Jul 21 08:53:58.672393 2026] [security2:error] [pid 559070:tid 559219] [client 20.197.192.193:50572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/csa.php"] [unique_id "al9d1iy1f1FtKC137xvyOwAAAaI"]
[Tue Jul 21 08:53:58.741207 2026] [security2:error] [pid 559070:tid 559307] [client 212.32.76.11:24651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/network/autoload_classmap.php"] [unique_id "al9d1iy1f1FtKC137xvyPAAAAfo"]
[Tue Jul 21 08:53:58.884047 2026] [autoindex:error] [pid 559070:tid 559242] [client 159.65.249.164:43458] AH01276: Cannot serve directory /home3/factor11/api.propostahub.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:53:59.020514 2026] [security2:error] [pid 559070:tid 559302] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9d1iy1f1FtKC137xvyPgAB9S0"]
[Tue Jul 21 08:53:59.025191 2026] [security2:error] [pid 559070:tid 559246] [client 20.151.10.161:52189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/footer.php"] [unique_id "al9d1yy1f1FtKC137xvyQAAAAb0"]
[Tue Jul 21 08:53:59.037540 2026] [security2:error] [pid 533360:tid 533461] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/xxx.php"] [unique_id "al9d13UPuLYrePtEkUcdDQAAqWE"]
[Tue Jul 21 08:53:59.097433 2026] [security2:error] [pid 533360:tid 533462] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/hypo.php"] [unique_id "al9d13UPuLYrePtEkUcdEAAApGI"]
[Tue Jul 21 08:53:59.164050 2026] [security2:error] [pid 559070:tid 559244] [client 20.220.225.223:59199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/wp-explorer.php"] [unique_id "al9d1yy1f1FtKC137xvyRwAAAbs"]
[Tue Jul 21 08:53:59.207224 2026] [autoindex:error] [pid 533360:tid 533616] [client 198.235.24.237:64254] AH01276: Cannot serve directory /home3/factor11/yunofp/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:53:59.333160 2026] [security2:error] [pid 559070:tid 559301] [client 65.21.113.253:34864] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9d1iy1f1FtKC137xvyPwAAAfQ"]
[Tue Jul 21 08:53:59.399611 2026] [proxy:error] [pid 533360:tid 533521] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:53:59.399696 2026] [proxy_http:error] [pid 533360:tid 533521] [client 20.151.10.161:52135] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:53:59.400175 2026] [proxy:error] [pid 533360:tid 533521] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:53:59.400204 2026] [proxy_http:error] [pid 533360:tid 533521] [client 20.151.10.161:52135] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:53:59.485330 2026] [security2:error] [pid 559070:tid 559270] [client 20.197.192.193:56822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/min.php"] [unique_id "al9d1yy1f1FtKC137xvyUAAAAdU"]
[Tue Jul 21 08:53:59.605696 2026] [autoindex:error] [pid 559070:tid 559235] [client 159.65.249.164:55606] AH01276: Cannot serve directory /home3/factor11/api.propostahub.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:53:59.623478 2026] [security2:error] [pid 559070:tid 559269] [client 20.151.10.161:51061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/k5.php"] [unique_id "al9d1yy1f1FtKC137xvyjAAAAdQ"]
[Tue Jul 21 08:53:59.685999 2026] [security2:error] [pid 533360:tid 533483] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/chosen.php"] [unique_id "al9d13UPuLYrePtEkUcdIAAA9Xc"]
[Tue Jul 21 08:53:59.855307 2026] [security2:error] [pid 533360:tid 533597] [client 20.151.10.161:45969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/d62.php"] [unique_id "al9d13UPuLYrePtEkUcdJAAAAO0"]
[Tue Jul 21 08:53:59.862230 2026] [security2:error] [pid 533360:tid 533559] [client 20.151.10.161:52178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-content/index.php"] [unique_id "al9d13UPuLYrePtEkUcdJQAAAMc"]
[Tue Jul 21 08:54:00.070081 2026] [security2:error] [pid 533360:tid 533367] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/als.php"] [unique_id "al9d2HUPuLYrePtEkUcdKwAApQM"]
[Tue Jul 21 08:54:00.221988 2026] [security2:error] [pid 533360:tid 533433] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d2HUPuLYrePtEkUcdLgAA1EU"]
[Tue Jul 21 08:54:00.222114 2026] [security2:error] [pid 533360:tid 533572] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d2HUPuLYrePtEkUcdLgAA1EU"]
[Tue Jul 21 08:54:00.227093 2026] [security2:error] [pid 559070:tid 559272] [client 113.22.144.139:49485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d2Cy1f1FtKC137xvytwAAAdc"]
[Tue Jul 21 08:54:00.227233 2026] [security2:error] [pid 559070:tid 559272] [client 113.22.144.139:49485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d2Cy1f1FtKC137xvytwAAAdc"]
[Tue Jul 21 08:54:00.238348 2026] [security2:error] [pid 559070:tid 559210] [client 203.25.124.57:40935] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/news-portal/fm.php"] [unique_id "al9d2Cy1f1FtKC137xvyuAAAAZk"]
[Tue Jul 21 08:54:00.263029 2026] [security2:error] [pid 533360:tid 533437] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/pol.php"] [unique_id "al9d2HUPuLYrePtEkUcdMAAA9Ek"]
[Tue Jul 21 08:54:00.286593 2026] [security2:error] [pid 533360:tid 533440] [remote 41.186.86.12:25227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onkosclinica.com.br"] [uri "/wp-login.php"] [unique_id "al9d2HUPuLYrePtEkUcdMQAA8Ew"]
[Tue Jul 21 08:54:00.319946 2026] [security2:error] [pid 533360:tid 533477] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/file5.php"] [unique_id "al9d2HUPuLYrePtEkUcdMgAAwHE"]
[Tue Jul 21 08:54:00.357517 2026] [security2:error] [pid 533360:tid 533421] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9d2HUPuLYrePtEkUcdNAAAzTk"]
[Tue Jul 21 08:54:00.374368 2026] [security2:error] [pid 533360:tid 533365] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/file.php"] [unique_id "al9d2HUPuLYrePtEkUcdNQAArgE"]
[Tue Jul 21 08:54:00.429912 2026] [security2:error] [pid 533360:tid 533401] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/cfile.php"] [unique_id "al9d2HUPuLYrePtEkUcdNwAA3CU"]
[Tue Jul 21 08:54:00.478776 2026] [security2:error] [pid 533360:tid 533463] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/class-wp.php"] [unique_id "al9d2HUPuLYrePtEkUcdOQAAxGM"]
[Tue Jul 21 08:54:00.495076 2026] [security2:error] [pid 533360:tid 533409] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/admin.php"] [unique_id "al9d2HUPuLYrePtEkUcdOgAAvi0"]
[Tue Jul 21 08:54:00.595837 2026] [security2:error] [pid 533360:tid 533397] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/aa2.php"] [unique_id "al9d2HUPuLYrePtEkUcdPQAAxSE"]
[Tue Jul 21 08:54:00.659872 2026] [security2:error] [pid 533360:tid 533503] [client 20.151.10.161:46079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/ups.php"] [unique_id "al9d2HUPuLYrePtEkUcdPgAAAI8"]
[Tue Jul 21 08:54:00.660599 2026] [security2:error] [pid 559070:tid 559242] [client 20.151.10.161:52102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/zoro.php"] [unique_id "al9d2Cy1f1FtKC137xvyvQAAAbk"]
[Tue Jul 21 08:54:00.691449 2026] [security2:error] [pid 533360:tid 533366] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/ccou.php"] [unique_id "al9d2HUPuLYrePtEkUcdQgAArwI"]
[Tue Jul 21 08:54:00.776351 2026] [security2:error] [pid 559070:tid 559123] [remote 188.95.113.76:35084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cestabasicadocarlao.com.br"] [uri "/wp-login.php"] [unique_id "al9d2Cy1f1FtKC137xvywgABojQ"]
[Tue Jul 21 08:54:00.783192 2026] [security2:error] [pid 533360:tid 533416] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/dr.php"] [unique_id "al9d2HUPuLYrePtEkUcdRAABADQ"]
[Tue Jul 21 08:54:00.824085 2026] [security2:error] [pid 533360:tid 533488] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/xamp.php"] [unique_id "al9d2HUPuLYrePtEkUcdRQAAwXw"]
[Tue Jul 21 08:54:00.918365 2026] [security2:error] [pid 533360:tid 533602] [client 20.104.96.117:61751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/fffm.php"] [unique_id "al9d2HUPuLYrePtEkUcdRgAAAPI"]
[Tue Jul 21 08:54:00.924524 2026] [security2:error] [pid 533360:tid 533589] [client 168.167.81.163:61752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9d2HUPuLYrePtEkUcdSAAAAOU"]
[Tue Jul 21 08:54:00.926765 2026] [security2:error] [pid 533360:tid 533466] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/bless.php"] [unique_id "al9d2HUPuLYrePtEkUcdSgAAzmY"]
[Tue Jul 21 08:54:00.935825 2026] [security2:error] [pid 533360:tid 533589] [client 168.167.81.163:61752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9d2HUPuLYrePtEkUcdSAAAAOU"]
[Tue Jul 21 08:54:01.056685 2026] [security2:error] [pid 533360:tid 533432] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/file46.php"] [unique_id "al9d2XUPuLYrePtEkUcdTwAAzEQ"]
[Tue Jul 21 08:54:01.129448 2026] [security2:error] [pid 533360:tid 533431] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9d2XUPuLYrePtEkUcdUQAAoUM"]
[Tue Jul 21 08:54:01.129615 2026] [security2:error] [pid 533360:tid 533521] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9d2XUPuLYrePtEkUcdUQAAoUM"]
[Tue Jul 21 08:54:01.149819 2026] [security2:error] [pid 533360:tid 533475] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/eee.php"] [unique_id "al9d2XUPuLYrePtEkUcdUgAApm8"]
[Tue Jul 21 08:54:01.169303 2026] [security2:error] [pid 533360:tid 533597] [client 20.151.10.161:51033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/w.php"] [unique_id "al9d2XUPuLYrePtEkUcdUwAAAO0"]
[Tue Jul 21 08:54:01.213447 2026] [security2:error] [pid 533360:tid 533559] [client 20.197.192.193:52687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/echkm.php"] [unique_id "al9d2XUPuLYrePtEkUcdVAAAAMc"]
[Tue Jul 21 08:54:01.270991 2026] [security2:error] [pid 533360:tid 533536] [client 20.151.10.161:52104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/admin.php"] [unique_id "al9d2XUPuLYrePtEkUcdVQAAALA"]
[Tue Jul 21 08:54:01.278761 2026] [security2:error] [pid 533360:tid 533489] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/file25.php"] [unique_id "al9d2XUPuLYrePtEkUcdVgAAun0"]
[Tue Jul 21 08:54:01.315560 2026] [security2:error] [pid 533360:tid 533420] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/file48.php"] [unique_id "al9d2XUPuLYrePtEkUcdVwAAqDg"]
[Tue Jul 21 08:54:01.438997 2026] [security2:error] [pid 559070:tid 559214] [client 20.151.10.161:46067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/k.php"] [unique_id "al9d2Sy1f1FtKC137xvyxwAAAZ0"]
[Tue Jul 21 08:54:01.563251 2026] [security2:error] [pid 559070:tid 559208] [client 20.220.225.223:60275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/dp.php"] [unique_id "al9d2Sy1f1FtKC137xvyzAAAAZc"]
[Tue Jul 21 08:54:01.564272 2026] [security2:error] [pid 533360:tid 533399] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/file6.php"] [unique_id "al9d2XUPuLYrePtEkUcdXgAA8SM"]
[Tue Jul 21 08:54:01.800138 2026] [security2:error] [pid 559070:tid 559158] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d2Sy1f1FtKC137xvyzgABy1c"]
[Tue Jul 21 08:54:01.800383 2026] [security2:error] [pid 559070:tid 559260] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d2Sy1f1FtKC137xvyzgABy1c"]
[Tue Jul 21 08:54:01.820061 2026] [security2:error] [pid 533360:tid 533569] [client 20.151.10.161:52218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/greap.php"] [unique_id "al9d2XUPuLYrePtEkUcdYwAAANE"]
[Tue Jul 21 08:54:01.942277 2026] [security2:error] [pid 559070:tid 559227] [client 203.25.124.39:51919] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/customize/index.php"] [unique_id "al9d2Sy1f1FtKC137xvy0gAAAao"]
[Tue Jul 21 08:54:02.275260 2026] [security2:error] [pid 533360:tid 533481] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/a2.php"] [unique_id "al9d2nUPuLYrePtEkUcdewAAh3U"]
[Tue Jul 21 08:54:02.306209 2026] [security2:error] [pid 533360:tid 533419] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/file15.php"] [unique_id "al9d2nUPuLYrePtEkUcdgwAA2jc"]
[Tue Jul 21 08:54:02.357136 2026] [security2:error] [pid 533360:tid 533522] [client 20.220.225.223:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/akismet.php"] [unique_id "al9d2nUPuLYrePtEkUcdhQAAAKI"]
[Tue Jul 21 08:54:02.414247 2026] [security2:error] [pid 533360:tid 533417] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/jp.php"] [unique_id "al9d2nUPuLYrePtEkUcdhgAAxzU"]
[Tue Jul 21 08:54:02.452192 2026] [security2:error] [pid 533360:tid 533498] [client 65.21.113.253:35260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9d2nUPuLYrePtEkUcdiAAAAIo"]
[Tue Jul 21 08:54:02.489111 2026] [security2:error] [pid 533360:tid 533579] [client 143.244.57.88:41948] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9d2nUPuLYrePtEkUcdigAAANs"]
[Tue Jul 21 08:54:02.506656 2026] [security2:error] [pid 559070:tid 559288] [client 20.151.10.161:46047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/k2.php"] [unique_id "al9d2iy1f1FtKC137xvy7wAAAec"]
[Tue Jul 21 08:54:02.587546 2026] [security2:error] [pid 533360:tid 533370] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/f35.php"] [unique_id "al9d2nUPuLYrePtEkUcdjAAA-wY"]
[Tue Jul 21 08:54:02.632726 2026] [security2:error] [pid 559070:tid 559322] [client 20.104.96.117:4015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/dfre.php"] [unique_id "al9d2iy1f1FtKC137xvy8AAAAgk"]
[Tue Jul 21 08:54:02.704171 2026] [security2:error] [pid 559070:tid 559217] [client 216.244.66.243:46986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ssvistorias.com.br"] [uri "/servico/consulta-para-compravenda/"] [unique_id "al9d2iy1f1FtKC137xvzCAAAAaA"]
[Tue Jul 21 08:54:02.704280 2026] [security2:error] [pid 559070:tid 559217] [client 216.244.66.243:46986] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ssvistorias.com.br"] [uri "/servico/consulta-para-compravenda/"] [unique_id "al9d2iy1f1FtKC137xvzCAAAAaA"]
[Tue Jul 21 08:54:02.735833 2026] [security2:error] [pid 533360:tid 533544] [client 5.38.115.39:65219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9d2nUPuLYrePtEkUcdjwAAALg"]
[Tue Jul 21 08:54:02.735961 2026] [security2:error] [pid 533360:tid 533544] [client 5.38.115.39:65219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9d2nUPuLYrePtEkUcdjwAAALg"]
[Tue Jul 21 08:54:02.775263 2026] [security2:error] [pid 559070:tid 559278] [client 41.89.234.2:50562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d2iy1f1FtKC137xvzCgAAAd0"]
[Tue Jul 21 08:54:02.775400 2026] [security2:error] [pid 559070:tid 559278] [client 41.89.234.2:50562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d2iy1f1FtKC137xvzCgAAAd0"]
[Tue Jul 21 08:54:02.837529 2026] [security2:error] [pid 559070:tid 559248] [client 20.151.10.161:51009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/fpwch.php"] [unique_id "al9d2iy1f1FtKC137xvzGQAAAb8"]
[Tue Jul 21 08:54:02.904865 2026] [security2:error] [pid 533360:tid 533618] [client 143.244.57.88:41962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mkt.inlaudo.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d2nUPuLYrePtEkUcdkgAAAQI"]
[Tue Jul 21 08:54:03.001611 2026] [security2:error] [pid 559070:tid 559245] [client 152.59.181.104:62234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9d2yy1f1FtKC137xvzLAAAAbw"]
[Tue Jul 21 08:54:03.001742 2026] [security2:error] [pid 559070:tid 559245] [client 152.59.181.104:62234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9d2yy1f1FtKC137xvzLAAAAbw"]
[Tue Jul 21 08:54:03.020897 2026] [security2:error] [pid 533360:tid 533556] [client 128.127.105.184:59660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9d23UPuLYrePtEkUcdlAAAAMQ"]
[Tue Jul 21 08:54:03.021012 2026] [security2:error] [pid 533360:tid 533556] [client 128.127.105.184:59660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9d23UPuLYrePtEkUcdlAAAAMQ"]
[Tue Jul 21 08:54:03.022143 2026] [security2:error] [pid 533360:tid 533429] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-load.php"] [unique_id "al9d23UPuLYrePtEkUcdlQAAvkE"]
[Tue Jul 21 08:54:03.156033 2026] [security2:error] [pid 559070:tid 559281] [client 212.32.76.8:59657] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css/colors/admin.php"] [unique_id "al9d2yy1f1FtKC137xvzdgAAAeA"]
[Tue Jul 21 08:54:03.219961 2026] [security2:error] [pid 533360:tid 533415] [remote 45.76.153.27:44914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.153.76.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9d23UPuLYrePtEkUcdmQAAvTM"]
[Tue Jul 21 08:54:03.220363 2026] [security2:error] [pid 559070:tid 559236] [client 103.59.206.240:31357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d2yy1f1FtKC137xvzegAAAbM"]
[Tue Jul 21 08:54:03.220481 2026] [security2:error] [pid 559070:tid 559236] [client 103.59.206.240:31357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d2yy1f1FtKC137xvzegAAAbM"]
[Tue Jul 21 08:54:03.503484 2026] [security2:error] [pid 533360:tid 533461] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/xwpg.php"] [unique_id "al9d23UPuLYrePtEkUcdpAAAsGE"]
[Tue Jul 21 08:54:03.504707 2026] [security2:error] [pid 533360:tid 533570] [client 182.189.99.211:48197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d23UPuLYrePtEkUcdogAAANI"]
[Tue Jul 21 08:54:03.504855 2026] [security2:error] [pid 533360:tid 533570] [client 182.189.99.211:48197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d23UPuLYrePtEkUcdogAAANI"]
[Tue Jul 21 08:54:03.528969 2026] [security2:error] [pid 533360:tid 533498] [client 143.244.57.88:41972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9d23UPuLYrePtEkUcdpgAAAIo"]
[Tue Jul 21 08:54:03.571661 2026] [security2:error] [pid 533360:tid 533603] [client 20.151.10.161:52170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/177.php"] [unique_id "al9d23UPuLYrePtEkUcdqAAAAPM"]
[Tue Jul 21 08:54:03.622688 2026] [security2:error] [pid 559070:tid 559249] [client 65.21.113.253:52876] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9d2yy1f1FtKC137xvzdwAAAcA"]
[Tue Jul 21 08:54:03.842172 2026] [security2:error] [pid 533360:tid 533600] [client 203.25.124.32:23769] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/images/wp-conflg.php"] [unique_id "al9d23UPuLYrePtEkUcdrAAAAPA"]
[Tue Jul 21 08:54:03.946595 2026] [security2:error] [pid 533360:tid 533535] [client 143.244.57.88:41974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9d23UPuLYrePtEkUcdsAAAAK8"]
[Tue Jul 21 08:54:04.082691 2026] [security2:error] [pid 559070:tid 559216] [client 20.151.10.161:46049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/k3.php"] [unique_id "al9d3Cy1f1FtKC137xvzpgAAAZ8"]
[Tue Jul 21 08:54:04.118839 2026] [security2:error] [pid 533360:tid 533373] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/waf.php"] [unique_id "al9d3HUPuLYrePtEkUcdtwAA7wk"]
[Tue Jul 21 08:54:04.308124 2026] [security2:error] [pid 533360:tid 533495] [client 20.104.96.117:3993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/wp-happy.php"] [unique_id "al9d3HUPuLYrePtEkUcduQAAAIc"]
[Tue Jul 21 08:54:04.356574 2026] [security2:error] [pid 533360:tid 533592] [client 143.244.57.88:41980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9d3HUPuLYrePtEkUcdvAAAAOg"]
[Tue Jul 21 08:54:04.462121 2026] [security2:error] [pid 533360:tid 533422] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/xstelth.php"] [unique_id "al9d3HUPuLYrePtEkUcdwAAArTo"]
[Tue Jul 21 08:54:04.480462 2026] [security2:error] [pid 533360:tid 533441] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-links.php"] [unique_id "al9d3HUPuLYrePtEkUcdwQAAqk0"]
[Tue Jul 21 08:54:04.498747 2026] [security2:error] [pid 559070:tid 559123] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9d3Cy1f1FtKC137xvzrQABmDQ"]
[Tue Jul 21 08:54:04.498958 2026] [security2:error] [pid 559070:tid 559209] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9d3Cy1f1FtKC137xvzrQABmDQ"]
[Tue Jul 21 08:54:04.543776 2026] [security2:error] [pid 533360:tid 533390] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9d3HUPuLYrePtEkUcdwgAAkRo"]
[Tue Jul 21 08:54:04.587998 2026] [security2:error] [pid 533360:tid 533378] [remote 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.wendelleite.com.br"] [uri "/aaa.php"] [unique_id "al9d3HUPuLYrePtEkUcdxAAA2g4"]
[Tue Jul 21 08:54:04.761707 2026] [security2:error] [pid 559070:tid 559214] [client 143.244.57.88:41990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9d3Cy1f1FtKC137xvzuAAAAZ0"]
[Tue Jul 21 08:54:04.911831 2026] [security2:error] [pid 559070:tid 559264] [client 20.220.225.223:52649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9d3Cy1f1FtKC137xvzuwAAAc8"]
[Tue Jul 21 08:54:04.938905 2026] [security2:error] [pid 533360:tid 533558] [client 203.25.124.43:61347] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Text/chosen.php"] [unique_id "al9d3HUPuLYrePtEkUcdygAAAMY"]
[Tue Jul 21 08:54:04.944871 2026] [security2:error] [pid 533360:tid 533437] [remote 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9d3HUPuLYrePtEkUcdywAAsEk"]
[Tue Jul 21 08:54:05.171961 2026] [security2:error] [pid 533360:tid 533508] [client 143.244.57.88:42002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9d3XUPuLYrePtEkUcd1QAAAJQ"]
[Tue Jul 21 08:54:05.565250 2026] [security2:error] [pid 559070:tid 559304] [client 20.151.10.161:55827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/w2025.php"] [unique_id "al9d3Sy1f1FtKC137xvzzAAAAfc"]
[Tue Jul 21 08:54:05.592520 2026] [security2:error] [pid 559070:tid 559200] [client 143.244.57.88:42016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al9d3Sy1f1FtKC137xvz0QAAAY8"]
[Tue Jul 21 08:54:05.622094 2026] [security2:error] [pid 559070:tid 559292] [client 20.197.192.193:56816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/mac.php"] [unique_id "al9d3Sy1f1FtKC137xvz1QAAAes"]
[Tue Jul 21 08:54:05.637356 2026] [security2:error] [pid 533360:tid 533499] [client 20.151.10.161:52143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/199.php"] [unique_id "al9d3XUPuLYrePtEkUcd2wAAAIs"]
[Tue Jul 21 08:54:05.954293 2026] [security2:error] [pid 559070:tid 559276] [client 203.25.124.57:32111] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/chosen.php"] [unique_id "al9d3Sy1f1FtKC137xv0GgAAAds"]
[Tue Jul 21 08:54:05.998567 2026] [security2:error] [pid 559070:tid 559281] [client 143.244.57.88:42032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9d3Sy1f1FtKC137xv0GwAAAeA"]
[Tue Jul 21 08:54:06.011322 2026] [security2:error] [pid 559070:tid 559231] [client 20.220.225.223:21569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9d3iy1f1FtKC137xv0HQAAAa4"]
[Tue Jul 21 08:54:06.164870 2026] [security2:error] [pid 533360:tid 533577] [client 20.151.10.161:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/k4.php"] [unique_id "al9d3nUPuLYrePtEkUcd4wAAANk"]
[Tue Jul 21 08:54:06.335986 2026] [security2:error] [pid 559070:tid 559320] [client 20.104.96.117:61727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/fpr4.php"] [unique_id "al9d3iy1f1FtKC137xv0LwAAAgc"]
[Tue Jul 21 08:54:06.404595 2026] [security2:error] [pid 533360:tid 533582] [client 143.244.57.88:42040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9d3nUPuLYrePtEkUcd6QAAAN4"]
[Tue Jul 21 08:54:06.594765 2026] [security2:error] [pid 533360:tid 533556] [client 20.151.10.161:45959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/k5.php"] [unique_id "al9d3nUPuLYrePtEkUcd7QAAAMQ"]
[Tue Jul 21 08:54:06.601294 2026] [security2:error] [pid 559070:tid 559256] [client 59.95.197.55:64500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d3iy1f1FtKC137xv0MwAAAcc"]
[Tue Jul 21 08:54:06.601483 2026] [security2:error] [pid 559070:tid 559256] [client 59.95.197.55:64500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d3iy1f1FtKC137xv0MwAAAcc"]
[Tue Jul 21 08:54:06.759223 2026] [security2:error] [pid 533360:tid 533616] [client 65.21.113.253:35260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9d3nUPuLYrePtEkUcd8QAAAQA"]
[Tue Jul 21 08:54:06.813030 2026] [security2:error] [pid 533360:tid 533604] [client 143.244.57.88:42052] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9d3nUPuLYrePtEkUcd8wAAAPQ"]
[Tue Jul 21 08:54:06.833480 2026] [security2:error] [pid 559070:tid 559221] [client 168.167.81.163:64091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9d3iy1f1FtKC137xv0OwAAAaQ"]
[Tue Jul 21 08:54:06.833594 2026] [security2:error] [pid 559070:tid 559221] [client 168.167.81.163:64091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9d3iy1f1FtKC137xv0OwAAAaQ"]
[Tue Jul 21 08:54:06.927445 2026] [security2:error] [pid 559070:tid 559278] [client 20.220.225.223:52191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/ace2.php"] [unique_id "al9d3iy1f1FtKC137xv0PAAAAd0"]
[Tue Jul 21 08:54:06.945664 2026] [security2:error] [pid 533360:tid 533553] [client 203.25.124.55:20983] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/system.php"] [unique_id "al9d3nUPuLYrePtEkUcd9gAAAME"]
[Tue Jul 21 08:54:07.210153 2026] [security2:error] [pid 533360:tid 533564] [client 20.151.10.161:55859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/scxy.php"] [unique_id "al9d33UPuLYrePtEkUcd-gAAAMw"]
[Tue Jul 21 08:54:07.218215 2026] [security2:error] [pid 533360:tid 533526] [client 143.244.57.88:35840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9d33UPuLYrePtEkUcd-wAAAKY"]
[Tue Jul 21 08:54:07.486025 2026] [security2:error] [pid 559070:tid 559311] [client 114.198.138.124:60080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9d3yy1f1FtKC137xv0WgAAAf4"]
[Tue Jul 21 08:54:07.486117 2026] [security2:error] [pid 559070:tid 559311] [client 114.198.138.124:60080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9d3yy1f1FtKC137xv0WgAAAf4"]
[Tue Jul 21 08:54:07.627780 2026] [security2:error] [pid 559070:tid 559321] [client 143.244.57.88:35844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9d3yy1f1FtKC137xv0ZwAAAgg"]
[Tue Jul 21 08:54:07.654682 2026] [security2:error] [pid 559070:tid 559260] [client 20.104.96.117:4039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/file88.php"] [unique_id "al9d3yy1f1FtKC137xv0awAAAcs"]
[Tue Jul 21 08:54:07.782228 2026] [security2:error] [pid 559070:tid 559306] [client 20.151.10.161:46045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/w.php"] [unique_id "al9d3yy1f1FtKC137xv0cwAAAfk"]
[Tue Jul 21 08:54:07.834184 2026] [security2:error] [pid 559070:tid 559307] [client 65.21.113.253:52884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9d3yy1f1FtKC137xv0VAAAAfo"]
[Tue Jul 21 08:54:08.030492 2026] [security2:error] [pid 533360:tid 533579] [client 143.244.57.88:35856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9d4HUPuLYrePtEkUceCQAAANs"]
[Tue Jul 21 08:54:08.047125 2026] [security2:error] [pid 559070:tid 559286] [client 203.25.124.41:30771] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/PHPMailer/wp-conflg.php"] [unique_id "al9d4Cy1f1FtKC137xv0dwAAAeU"]
[Tue Jul 21 08:54:08.440027 2026] [security2:error] [pid 533360:tid 533515] [client 143.244.57.88:35872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9d4HUPuLYrePtEkUceFQAAAJs"]
[Tue Jul 21 08:54:08.511403 2026] [security2:error] [pid 559070:tid 559234] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9d4Cy1f1FtKC137xv0gwABsXI"]
[Tue Jul 21 08:54:08.611545 2026] [security2:error] [pid 533360:tid 533514] [client 128.127.105.184:55112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9d4HUPuLYrePtEkUceFwAAAJo"]
[Tue Jul 21 08:54:08.611696 2026] [security2:error] [pid 533360:tid 533514] [client 128.127.105.184:55112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9d4HUPuLYrePtEkUceFwAAAJo"]
[Tue Jul 21 08:54:08.810806 2026] [security2:error] [pid 559070:tid 559275] [client 128.127.105.184:55124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9d4Cy1f1FtKC137xv0jwAAAdo"]
[Tue Jul 21 08:54:08.810900 2026] [security2:error] [pid 559070:tid 559275] [client 128.127.105.184:55124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9d4Cy1f1FtKC137xv0jwAAAdo"]
[Tue Jul 21 08:54:08.847214 2026] [security2:error] [pid 559070:tid 559250] [client 143.244.57.88:35886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9d4Cy1f1FtKC137xv0lQAAAcE"]
[Tue Jul 21 08:54:08.937007 2026] [security2:error] [pid 559070:tid 559228] [client 20.151.10.161:46077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/fpwch.php"] [unique_id "al9d4Cy1f1FtKC137xv0mAAAAas"]
[Tue Jul 21 08:54:09.101167 2026] [security2:error] [pid 559070:tid 559188] [remote 51.161.65.32:36602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "benattiodontologia.com.br"] [uri "/robots.txt"] [unique_id "al9d4Sy1f1FtKC137xv0nAAB9nU"]
[Tue Jul 21 08:54:09.101336 2026] [security2:error] [pid 559070:tid 559303] [client 51.161.65.32:36602] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "benattiodontologia.com.br"] [uri "/robots.txt"] [unique_id "al9d4Sy1f1FtKC137xv0nAAB9nU"]
[Tue Jul 21 08:54:09.141577 2026] [security2:error] [pid 559070:tid 559218] [client 212.32.76.14:24751] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/news-portal/wp-admins.php"] [unique_id "al9d4Sy1f1FtKC137xv0ngAAAaE"]
[Tue Jul 21 08:54:09.251929 2026] [security2:error] [pid 559070:tid 559306] [client 143.244.57.88:35888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mkt.inlaudo.com.br"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al9d4Sy1f1FtKC137xv0oQAAAfk"]
[Tue Jul 21 08:54:09.371248 2026] [security2:error] [pid 559070:tid 559232] [client 20.151.10.161:46077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/w2025.php"] [unique_id "al9d4Sy1f1FtKC137xv0pwAAAa8"]
[Tue Jul 21 08:54:09.376704 2026] [security2:error] [pid 559070:tid 559209] [client 20.151.10.161:52201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/file52.php"] [unique_id "al9d4Sy1f1FtKC137xv0qAAAAZg"]
[Tue Jul 21 08:54:09.626093 2026] [security2:error] [pid 533360:tid 533530] [client 20.197.192.193:27101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/bootstrap.php"] [unique_id "al9d4XUPuLYrePtEkUceMQAAAKo"]
[Tue Jul 21 08:54:09.727351 2026] [security2:error] [pid 559070:tid 559240] [client 127.0.0.1:48396] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al9d4Sy1f1FtKC137xv0rQAAAbc"]
[Tue Jul 21 08:54:09.727351 2026] [security2:error] [pid 559070:tid 559247] [client 74.7.230.63:56086] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.radiantus.online"] [uri "/robots.txt"] [unique_id "al9d4Sy1f1FtKC137xv0rAAAAb4"]
[Tue Jul 21 08:54:10.117330 2026] [security2:error] [pid 559070:tid 559172] [remote 168.138.197.172:36356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.197.138.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eclipsesofts.com"] [uri "/wp-login.php"] [unique_id "al9d4iy1f1FtKC137xv0ugACC2U"]
[Tue Jul 21 08:54:10.118317 2026] [security2:error] [pid 559070:tid 559315] [client 194.99.104.35:55798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9d4iy1f1FtKC137xv0uwAAAgI"]
[Tue Jul 21 08:54:10.118425 2026] [security2:error] [pid 559070:tid 559315] [client 194.99.104.35:55798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9d4iy1f1FtKC137xv0uwAAAgI"]
[Tue Jul 21 08:54:10.456193 2026] [security2:error] [pid 533360:tid 533538] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9d4nUPuLYrePtEkUcePAAAsjA"]
[Tue Jul 21 08:54:10.494799 2026] [security2:error] [pid 559070:tid 559262] [client 20.220.225.223:60281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/bootstrap.php"] [unique_id "al9d4iy1f1FtKC137xv0wAAAAc0"]
[Tue Jul 21 08:54:10.518453 2026] [security2:error] [pid 559070:tid 559236] [client 20.151.10.161:51008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/FWAZ.php"] [unique_id "al9d4iy1f1FtKC137xv0wgAAAbM"]
[Tue Jul 21 08:54:10.680624 2026] [security2:error] [pid 559070:tid 559133] [remote 54.39.136.253:16428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "benattiodontologia.com.br"] [uri "/dentes-amarelados-6-maneiras-de-evitar-este-mal/feed/"] [unique_id "al9d4iy1f1FtKC137xv0yAABuz4"]
[Tue Jul 21 08:54:10.680792 2026] [security2:error] [pid 559070:tid 559244] [client 54.39.136.253:16428] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "benattiodontologia.com.br"] [uri "/dentes-amarelados-6-maneiras-de-evitar-este-mal/feed/"] [unique_id "al9d4iy1f1FtKC137xv0yAABuz4"]
[Tue Jul 21 08:54:10.750004 2026] [security2:error] [pid 533360:tid 533532] [client 20.220.225.223:19655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wp-Blogs.php"] [unique_id "al9d4nUPuLYrePtEkUceSgAAAKw"]
[Tue Jul 21 08:54:10.841620 2026] [security2:error] [pid 559070:tid 559294] [client 113.22.144.139:50016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d4iy1f1FtKC137xv0zAAAAe0"]
[Tue Jul 21 08:54:10.841770 2026] [security2:error] [pid 559070:tid 559294] [client 113.22.144.139:50016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d4iy1f1FtKC137xv0zAAAAe0"]
[Tue Jul 21 08:54:10.904601 2026] [security2:error] [pid 533360:tid 533545] [client 20.151.10.161:46036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/scxy.php"] [unique_id "al9d4nUPuLYrePtEkUceTgAAALk"]
[Tue Jul 21 08:54:10.964632 2026] [security2:error] [pid 559070:tid 559186] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d4iy1f1FtKC137xv00gAB13M"]
[Tue Jul 21 08:54:10.964799 2026] [security2:error] [pid 559070:tid 559272] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d4iy1f1FtKC137xv00gAB13M"]
[Tue Jul 21 08:54:11.032364 2026] [security2:error] [pid 533360:tid 533600] [client 20.197.192.193:27103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-editor.php"] [unique_id "al9d43UPuLYrePtEkUceUQAAAPA"]
[Tue Jul 21 08:54:11.241015 2026] [security2:error] [pid 533360:tid 533593] [client 203.25.124.64:32217] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/images/chosen.php"] [unique_id "al9d43UPuLYrePtEkUceVAAAAOk"]
[Tue Jul 21 08:54:11.454454 2026] [security2:error] [pid 559070:tid 559260] [client 20.220.225.223:52210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dpatrick.dener.design"] [uri "/ms.php"] [unique_id "al9d4yy1f1FtKC137xv01wAAAcs"]
[Tue Jul 21 08:54:11.496312 2026] [security2:error] [pid 533360:tid 533462] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9d43UPuLYrePtEkUceWgAA3mI"]
[Tue Jul 21 08:54:11.496448 2026] [security2:error] [pid 533360:tid 533582] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9d43UPuLYrePtEkUceWgAA3mI"]
[Tue Jul 21 08:54:11.544794 2026] [security2:error] [pid 533360:tid 533553] [client 65.21.113.253:35260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9d43UPuLYrePtEkUceXAAAAME"]
[Tue Jul 21 08:54:12.051072 2026] [security2:error] [pid 559070:tid 559245] [client 20.151.10.161:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/FWAZ.php"] [unique_id "al9d5Cy1f1FtKC137xv1JgAAAbw"]
[Tue Jul 21 08:54:12.231151 2026] [security2:error] [pid 559070:tid 559221] [client 203.25.124.64:52305] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/css.php"] [unique_id "al9d5Cy1f1FtKC137xv1NQAAAaQ"]
[Tue Jul 21 08:54:12.448264 2026] [security2:error] [pid 533360:tid 533390] [remote 5.252.52.249:42988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9d5HUPuLYrePtEkUcedwAAkho"]
[Tue Jul 21 08:54:12.618399 2026] [security2:error] [pid 559070:tid 559167] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d5Cy1f1FtKC137xv1WAABt2A"]
[Tue Jul 21 08:54:12.618494 2026] [security2:error] [pid 559070:tid 559240] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d5Cy1f1FtKC137xv1WAABt2A"]
[Tue Jul 21 08:54:12.632833 2026] [security2:error] [pid 559070:tid 559098] [remote 47.86.33.52:44796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9d5Cy1f1FtKC137xv1XAABqxs"]
[Tue Jul 21 08:54:12.640219 2026] [security2:error] [pid 533360:tid 533559] [client 185.213.175.37:36516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "brilhantemoldurasedecor.moldurasbrilhante.com.br"] [uri "/"] [unique_id "al9d5HUPuLYrePtEkUcehgAAAMc"]
[Tue Jul 21 08:54:12.640295 2026] [security2:error] [pid 533360:tid 533559] [client 185.213.175.37:36516] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "brilhantemoldurasedecor.moldurasbrilhante.com.br"] [uri "/"] [unique_id "al9d5HUPuLYrePtEkUcehgAAAMc"]
[Tue Jul 21 08:54:12.755541 2026] [security2:error] [pid 559070:tid 559222] [client 65.21.113.253:55594] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9d5Cy1f1FtKC137xv1PQAAAaU"]
[Tue Jul 21 08:54:12.887463 2026] [security2:error] [pid 533360:tid 533591] [client 20.220.225.223:55744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9d5HUPuLYrePtEkUceiAAAAOc"]
[Tue Jul 21 08:54:12.993518 2026] [security2:error] [pid 533360:tid 533502] [client 20.104.96.117:46762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/ccc.php"] [unique_id "al9d5HUPuLYrePtEkUceiwAAAI4"]
[Tue Jul 21 08:54:13.303252 2026] [security2:error] [pid 559070:tid 559294] [client 5.38.115.39:49387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9d5Sy1f1FtKC137xv1kwAAAe0"]
[Tue Jul 21 08:54:13.303413 2026] [security2:error] [pid 559070:tid 559294] [client 5.38.115.39:49387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9d5Sy1f1FtKC137xv1kwAAAe0"]
[Tue Jul 21 08:54:13.375289 2026] [security2:error] [pid 559070:tid 559324] [client 41.89.234.2:5673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d5Sy1f1FtKC137xv1lgAAAgs"]
[Tue Jul 21 08:54:13.375441 2026] [security2:error] [pid 559070:tid 559324] [client 41.89.234.2:5673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d5Sy1f1FtKC137xv1lgAAAgs"]
[Tue Jul 21 08:54:13.539769 2026] [security2:error] [pid 559070:tid 559295] [client 212.32.76.8:62839] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "al9d5Sy1f1FtKC137xv1pwAAAe4"]
[Tue Jul 21 08:54:13.680163 2026] [security2:error] [pid 559070:tid 559228] [client 20.151.10.161:52205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/122.php"] [unique_id "al9d5Sy1f1FtKC137xv1qAAAAas"]
[Tue Jul 21 08:54:13.714415 2026] [security2:error] [pid 533360:tid 533574] [client 20.151.10.161:51057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/qterm.php"] [unique_id "al9d5XUPuLYrePtEkUcemwAAANY"]
[Tue Jul 21 08:54:13.948525 2026] [security2:error] [pid 559070:tid 559209] [client 103.59.206.240:31095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d5Sy1f1FtKC137xv1rAAAAZg"]
[Tue Jul 21 08:54:13.948649 2026] [security2:error] [pid 559070:tid 559209] [client 103.59.206.240:31095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d5Sy1f1FtKC137xv1rAAAAZg"]
[Tue Jul 21 08:54:14.043345 2026] [security2:error] [pid 559070:tid 559276] [client 182.189.99.211:47960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d5iy1f1FtKC137xv1sgAAAds"]
[Tue Jul 21 08:54:14.043505 2026] [security2:error] [pid 559070:tid 559276] [client 182.189.99.211:47960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d5iy1f1FtKC137xv1sgAAAds"]
[Tue Jul 21 08:54:14.331864 2026] [security2:error] [pid 559070:tid 559282] [client 198.44.157.162:36736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9d5iy1f1FtKC137xv1uAAAAeE"]
[Tue Jul 21 08:54:14.331991 2026] [security2:error] [pid 559070:tid 559282] [client 198.44.157.162:36736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9d5iy1f1FtKC137xv1uAAAAeE"]
[Tue Jul 21 08:54:14.540424 2026] [security2:error] [pid 533360:tid 533545] [client 212.32.76.13:53339] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/advanced-product-fields-for-woocommerce/db.php"] [unique_id "al9d5nUPuLYrePtEkUceqAAAALk"]
[Tue Jul 21 08:54:14.807139 2026] [security2:error] [pid 533360:tid 533559] [client 20.104.96.117:3986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/777.php"] [unique_id "al9d5nUPuLYrePtEkUcetQAAAMc"]
[Tue Jul 21 08:54:14.987897 2026] [security2:error] [pid 533360:tid 533450] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9d5nUPuLYrePtEkUcewgAA0VY"]
[Tue Jul 21 08:54:14.988002 2026] [security2:error] [pid 533360:tid 533569] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9d5nUPuLYrePtEkUcewgAA0VY"]
[Tue Jul 21 08:54:15.129261 2026] [security2:error] [pid 559070:tid 559306] [client 20.151.10.161:52209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/green1.php"] [unique_id "al9d5yy1f1FtKC137xv10AAAAfk"]
[Tue Jul 21 08:54:15.136699 2026] [security2:error] [pid 559070:tid 559309] [client 20.197.192.193:50571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/samll.php"] [unique_id "al9d5yy1f1FtKC137xv10QAAAfw"]
[Tue Jul 21 08:54:15.240282 2026] [security2:error] [pid 533360:tid 533389] [remote 179.184.131.173:47740] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "consultecobertura.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "al9d53UPuLYrePtEkUceywAA5xk"], referer: https://consultecobertura.com.br/
[Tue Jul 21 08:54:15.437564 2026] [security2:error] [pid 559070:tid 559255] [client 203.25.124.72:55513] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/wp.php"] [unique_id "al9d5yy1f1FtKC137xv11wAAAcY"]
[Tue Jul 21 08:54:15.510957 2026] [security2:error] [pid 533360:tid 533502] [client 20.220.225.223:19969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wp-css.php"] [unique_id "al9d53UPuLYrePtEkUce1QAAAI4"]
[Tue Jul 21 08:54:15.772189 2026] [security2:error] [pid 533360:tid 533386] [remote 202.51.202.242:40242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9d53UPuLYrePtEkUce2wAA7xY"]
[Tue Jul 21 08:54:15.887925 2026] [security2:error] [pid 559070:tid 559234] [client 128.127.105.184:55130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9d5yy1f1FtKC137xv15AAAAbE"]
[Tue Jul 21 08:54:15.888039 2026] [security2:error] [pid 559070:tid 559234] [client 128.127.105.184:55130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9d5yy1f1FtKC137xv15AAAAbE"]
[Tue Jul 21 08:54:15.901991 2026] [security2:error] [pid 559070:tid 559209] [client 20.151.10.161:52214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/biufile.php"] [unique_id "al9d5yy1f1FtKC137xv15gAAAZg"]
[Tue Jul 21 08:54:15.912872 2026] [security2:error] [pid 533360:tid 533620] [client 65.21.113.253:35260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9d53UPuLYrePtEkUce4QAAAQQ"]
[Tue Jul 21 08:54:16.472693 2026] [security2:error] [pid 533360:tid 533570] [client 20.151.10.161:52223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wpconf.php"] [unique_id "al9d6HUPuLYrePtEkUce-gAAANI"]
[Tue Jul 21 08:54:16.532528 2026] [security2:error] [pid 559070:tid 559253] [client 203.25.124.74:37505] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9d6Cy1f1FtKC137xv1_gAAAcQ"]
[Tue Jul 21 08:54:16.765693 2026] [security2:error] [pid 559070:tid 559257] [client 198.44.157.162:56694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9d6Cy1f1FtKC137xv2DQAAAcg"]
[Tue Jul 21 08:54:16.765803 2026] [security2:error] [pid 559070:tid 559257] [client 198.44.157.162:56694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9d6Cy1f1FtKC137xv2DQAAAcg"]
[Tue Jul 21 08:54:16.998345 2026] [security2:error] [pid 533360:tid 533603] [client 65.21.113.253:55608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9d6HUPuLYrePtEkUce_AAAAPM"]
[Tue Jul 21 08:54:17.063733 2026] [security2:error] [pid 559070:tid 559232] [client 59.95.197.55:64988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d6Sy1f1FtKC137xv2EgAAAa8"]
[Tue Jul 21 08:54:17.063883 2026] [security2:error] [pid 559070:tid 559232] [client 59.95.197.55:64988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d6Sy1f1FtKC137xv2EgAAAa8"]
[Tue Jul 21 08:54:17.086762 2026] [security2:error] [pid 533360:tid 533542] [client 20.151.10.161:37875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/mosty.php"] [unique_id "al9d6XUPuLYrePtEkUcfBQAAALY"]
[Tue Jul 21 08:54:17.195401 2026] [security2:error] [pid 533360:tid 533551] [client 168.167.81.163:64656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9d6XUPuLYrePtEkUcfCAAAAL8"]
[Tue Jul 21 08:54:17.195525 2026] [security2:error] [pid 533360:tid 533551] [client 168.167.81.163:64656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9d6XUPuLYrePtEkUcfCAAAAL8"]
[Tue Jul 21 08:54:17.661931 2026] [security2:error] [pid 559070:tid 559324] [client 20.151.10.161:52131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/dejavu.php"] [unique_id "al9d6Sy1f1FtKC137xv2GgAAAgs"]
[Tue Jul 21 08:54:17.882940 2026] [security2:error] [pid 559070:tid 559255] [client 20.104.96.117:4078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/for.php"] [unique_id "al9d6Sy1f1FtKC137xv2HQAAAcY"]
[Tue Jul 21 08:54:17.967347 2026] [security2:error] [pid 559070:tid 559225] [client 114.198.138.124:60657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9d6Sy1f1FtKC137xv2HgAAAag"]
[Tue Jul 21 08:54:17.967441 2026] [security2:error] [pid 559070:tid 559225] [client 114.198.138.124:60657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9d6Sy1f1FtKC137xv2HgAAAag"]
[Tue Jul 21 08:54:18.023530 2026] [security2:error] [pid 559070:tid 559076] [remote 45.90.123.233:59992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9d6iy1f1FtKC137xv2HwABvwU"]
[Tue Jul 21 08:54:18.318991 2026] [security2:error] [pid 533360:tid 533365] [remote 132.148.72.88:39960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9d6nUPuLYrePtEkUcfIAAA5wE"]
[Tue Jul 21 08:54:18.453890 2026] [security2:error] [pid 559070:tid 559238] [client 20.197.192.193:27185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/cro.php"] [unique_id "al9d6iy1f1FtKC137xv2KQAAAbU"]
[Tue Jul 21 08:54:18.640185 2026] [security2:error] [pid 559070:tid 559228] [client 203.25.124.211:21351] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9d6iy1f1FtKC137xv2LAAAAas"]
[Tue Jul 21 08:54:18.683634 2026] [security2:error] [pid 559070:tid 559272] [client 20.151.10.161:52212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/aaf.php"] [unique_id "al9d6iy1f1FtKC137xv2LgAAAdc"]
[Tue Jul 21 08:54:19.241425 2026] [security2:error] [pid 559070:tid 559225] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9d6yy1f1FtKC137xv2OQABqFY"]
[Tue Jul 21 08:54:19.343125 2026] [security2:error] [pid 559070:tid 559271] [client 20.151.10.161:45955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/qterm.php"] [unique_id "al9d6yy1f1FtKC137xv2QQAAAdY"]
[Tue Jul 21 08:54:19.348677 2026] [security2:error] [pid 559070:tid 559253] [client 20.151.10.161:37846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/term.php"] [unique_id "al9d6yy1f1FtKC137xv2QgAAAcQ"]
[Tue Jul 21 08:54:19.382784 2026] [autoindex:error] [pid 559070:tid 559270] [client 3.219.86.171:48593] AH01276: Cannot serve directory /home3/factor11/propostahub.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:54:19.531778 2026] [security2:error] [pid 559070:tid 559140] [remote 51.68.247.200:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "falarmelhor.com.br"] [uri "/curso-falar-melhor-destravar-comunicacao/"] [unique_id "al9d6yy1f1FtKC137xv2SAABokU"]
[Tue Jul 21 08:54:19.531966 2026] [security2:error] [pid 559070:tid 559219] [client 51.68.247.200:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "falarmelhor.com.br"] [uri "/curso-falar-melhor-destravar-comunicacao/"] [unique_id "al9d6yy1f1FtKC137xv2SAABokU"]
[Tue Jul 21 08:54:19.835736 2026] [security2:error] [pid 533360:tid 533590] [client 203.25.124.215:33285] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/Simple.php"] [unique_id "al9d63UPuLYrePtEkUcfPQAAAOY"]
[Tue Jul 21 08:54:19.844036 2026] [security2:error] [pid 559070:tid 559264] [client 20.151.10.161:52125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/ha.php"] [unique_id "al9d6yy1f1FtKC137xv2TQAAAc8"]
[Tue Jul 21 08:54:19.988534 2026] [security2:error] [pid 533360:tid 533600] [client 20.151.10.161:51048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/blurbs.php"] [unique_id "al9d63UPuLYrePtEkUcfQgAAAPA"]
[Tue Jul 21 08:54:20.129410 2026] [security2:error] [pid 559070:tid 559265] [client 20.220.225.223:60273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/dr.php"] [unique_id "al9d7Cy1f1FtKC137xv2UgAAAdA"]
[Tue Jul 21 08:54:20.302508 2026] [security2:error] [pid 559070:tid 559209] [client 20.104.96.117:4053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/ssla.php"] [unique_id "al9d7Cy1f1FtKC137xv2VQAAAZg"]
[Tue Jul 21 08:54:20.398788 2026] [security2:error] [pid 533360:tid 533420] [remote 179.184.131.173:47740] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "consultecobertura.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "al9d7HUPuLYrePtEkUcfRwAAwTg"], referer: https://consultecobertura.com.br/
[Tue Jul 21 08:54:20.490019 2026] [security2:error] [pid 559070:tid 559243] [client 20.151.10.161:52202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/hur.php"] [unique_id "al9d7Cy1f1FtKC137xv2WgAAAbo"]
[Tue Jul 21 08:54:20.740621 2026] [security2:error] [pid 559070:tid 559310] [client 203.25.124.71:23909] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/index.php"] [unique_id "al9d7Cy1f1FtKC137xv2ZgAAAf0"]
[Tue Jul 21 08:54:21.070248 2026] [access_compat:error] [pid 559070:tid 559234] [client 162.241.63.68:36484] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:54:21.087386 2026] [security2:error] [pid 559070:tid 559291] [client 20.151.10.161:52199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/h02ugyh.php"] [unique_id "al9d7Sy1f1FtKC137xv2cgAAAeo"]
[Tue Jul 21 08:54:21.441702 2026] [security2:error] [pid 559070:tid 559229] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9d7Sy1f1FtKC137xv2eQABrCY"]
[Tue Jul 21 08:54:21.530557 2026] [security2:error] [pid 559070:tid 559250] [client 20.151.10.161:37836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/seiso.php"] [unique_id "al9d7Sy1f1FtKC137xv2gQAAAcE"]
[Tue Jul 21 08:54:21.531453 2026] [security2:error] [pid 559070:tid 559098] [remote 20.153.140.50:49824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/wp-login.php"] [unique_id "al9d7Sy1f1FtKC137xv2gAAB7Rs"]
[Tue Jul 21 08:54:21.543142 2026] [security2:error] [pid 559070:tid 559230] [client 198.44.157.162:51880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9d7Sy1f1FtKC137xv2ggAAAa0"]
[Tue Jul 21 08:54:21.543233 2026] [security2:error] [pid 559070:tid 559230] [client 198.44.157.162:51880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9d7Sy1f1FtKC137xv2ggAAAa0"]
[Tue Jul 21 08:54:21.646472 2026] [security2:error] [pid 559070:tid 559248] [client 203.25.124.36:40435] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/storage/framework/views/shell.php"] [unique_id "al9d7Sy1f1FtKC137xv2hgAAAb8"]
[Tue Jul 21 08:54:21.662959 2026] [security2:error] [pid 533360:tid 533572] [client 20.220.225.223:19663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/wp-explorer.php"] [unique_id "al9d7XUPuLYrePtEkUcfXgAAANQ"]
[Tue Jul 21 08:54:21.756593 2026] [security2:error] [pid 533360:tid 533591] [client 113.22.144.139:50559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d7XUPuLYrePtEkUcfXwAAAOc"]
[Tue Jul 21 08:54:21.756723 2026] [security2:error] [pid 533360:tid 533591] [client 113.22.144.139:50559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d7XUPuLYrePtEkUcfXwAAAOc"]
[Tue Jul 21 08:54:21.848155 2026] [security2:error] [pid 559070:tid 559138] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d7Sy1f1FtKC137xv2iwAB1kM"]
[Tue Jul 21 08:54:21.848277 2026] [security2:error] [pid 559070:tid 559271] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d7Sy1f1FtKC137xv2iwAB1kM"]
[Tue Jul 21 08:54:22.033921 2026] [security2:error] [pid 533360:tid 533439] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9d7nUPuLYrePtEkUcfZAAAoUs"]
[Tue Jul 21 08:54:22.034073 2026] [security2:error] [pid 533360:tid 533521] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9d7nUPuLYrePtEkUcfZAAAoUs"]
[Tue Jul 21 08:54:22.087324 2026] [security2:error] [pid 559070:tid 559238] [client 20.151.10.161:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/blurbs.php"] [unique_id "al9d7iy1f1FtKC137xv2kAAAAbU"]
[Tue Jul 21 08:54:22.208214 2026] [security2:error] [pid 559070:tid 559265] [client 20.151.10.161:52121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/155.php"] [unique_id "al9d7iy1f1FtKC137xv2kQAAAdA"]
[Tue Jul 21 08:54:22.499369 2026] [security2:error] [pid 559070:tid 559282] [client 198.44.157.162:51888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9d7iy1f1FtKC137xv2mwAAAeE"]
[Tue Jul 21 08:54:22.499437 2026] [security2:error] [pid 559070:tid 559282] [client 198.44.157.162:51888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9d7iy1f1FtKC137xv2mwAAAeE"]
[Tue Jul 21 08:54:22.639171 2026] [security2:error] [pid 559070:tid 559218] [client 212.32.76.9:35511] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/tinyfilemanager/tinyfilemanager.php"] [unique_id "al9d7iy1f1FtKC137xv2ngAAAaE"]
[Tue Jul 21 08:54:22.696714 2026] [security2:error] [pid 559070:tid 559229] [client 20.104.96.117:46739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.gtlocacoes.net"] [uri "/zc-131.php"] [unique_id "al9d7iy1f1FtKC137xv2ogAAAaw"]
[Tue Jul 21 08:54:22.799104 2026] [security2:error] [pid 559070:tid 559207] [client 20.220.225.223:58939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/wander.php"] [unique_id "al9d7iy1f1FtKC137xv2pQAAAZY"]
[Tue Jul 21 08:54:22.821167 2026] [security2:error] [pid 559070:tid 559248] [client 20.151.10.161:52110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/ppp.php"] [unique_id "al9d7iy1f1FtKC137xv2pgAAAb8"]
[Tue Jul 21 08:54:23.187916 2026] [security2:error] [pid 559070:tid 559302] [client 20.151.10.161:52153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/201.php"] [unique_id "al9d7yy1f1FtKC137xv2sAAAAfU"]
[Tue Jul 21 08:54:23.416673 2026] [security2:error] [pid 559070:tid 559209] [client 20.220.225.223:48204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/2x.php"] [unique_id "al9d7yy1f1FtKC137xv2tgAAAZg"]
[Tue Jul 21 08:54:23.605118 2026] [security2:error] [pid 533360:tid 533601] [client 20.151.10.161:55867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/v543.php"] [unique_id "al9d73UPuLYrePtEkUcfgwAAAPE"]
[Tue Jul 21 08:54:23.641839 2026] [security2:error] [pid 559070:tid 559238] [client 107.181.154.175:44713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9d7yy1f1FtKC137xv2tQAAAbU"], referer: https://eclipsesofts.com/xmlrpc.php
[Tue Jul 21 08:54:23.671940 2026] [security2:error] [pid 533360:tid 533448] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d73UPuLYrePtEkUcfhQAAwVQ"]
[Tue Jul 21 08:54:23.672067 2026] [security2:error] [pid 533360:tid 533553] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d73UPuLYrePtEkUcfhQAAwVQ"]
[Tue Jul 21 08:54:23.746243 2026] [security2:error] [pid 559070:tid 559218] [client 20.151.10.161:52150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/ops.php"] [unique_id "al9d7yy1f1FtKC137xv2ugAAAaE"]
[Tue Jul 21 08:54:23.753803 2026] [security2:error] [pid 559070:tid 559229] [client 212.32.76.5:32075] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/shell.php"] [unique_id "al9d7yy1f1FtKC137xv2uwAAAaw"]
[Tue Jul 21 08:54:23.888120 2026] [security2:error] [pid 559070:tid 559292] [client 41.89.234.2:51791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d7yy1f1FtKC137xv2wAAAAes"]
[Tue Jul 21 08:54:23.888254 2026] [security2:error] [pid 559070:tid 559292] [client 41.89.234.2:51791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d7yy1f1FtKC137xv2wAAAAes"]
[Tue Jul 21 08:54:23.959479 2026] [security2:error] [pid 559070:tid 559312] [client 5.38.115.39:10068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9d7yy1f1FtKC137xv2wwAAAf8"]
[Tue Jul 21 08:54:23.959664 2026] [security2:error] [pid 559070:tid 559312] [client 5.38.115.39:10068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9d7yy1f1FtKC137xv2wwAAAf8"]
[Tue Jul 21 08:54:23.982658 2026] [security2:error] [pid 559070:tid 559306] [client 20.151.10.161:46043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/v543.php"] [unique_id "al9d7yy1f1FtKC137xv2xQAAAfk"]
[Tue Jul 21 08:54:24.031072 2026] [security2:error] [pid 559070:tid 559217] [client 20.197.192.193:56776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/abcd.php"] [unique_id "al9d8Cy1f1FtKC137xv2xgAAAaA"]
[Tue Jul 21 08:54:24.333961 2026] [core:error] [pid 559070:tid 559086] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:24.333993 2026] [core:error] [pid 559070:tid 559086] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:24.341709 2026] [security2:error] [pid 559070:tid 559264] [client 20.151.10.161:52109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/ingfo.php"] [unique_id "al9d8Cy1f1FtKC137xv2ywAAAc8"]
[Tue Jul 21 08:54:24.435262 2026] [security2:error] [pid 533360:tid 533596] [client 203.25.124.33:35215] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/aatdgetgdg/main.php"] [unique_id "al9d8HUPuLYrePtEkUcflQAAAOw"]
[Tue Jul 21 08:54:24.501890 2026] [security2:error] [pid 559070:tid 559225] [client 107.181.154.175:55831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "eclipsesofts.com"] [uri "/xmlrpc.php"] [unique_id "al9d8Cy1f1FtKC137xv2yAAAAag"], referer: https://eclipsesofts.com/xmlrpc.php
[Tue Jul 21 08:54:24.542112 2026] [security2:error] [pid 559070:tid 559253] [client 182.189.99.211:48085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d8Cy1f1FtKC137xv2zwAAAcQ"]
[Tue Jul 21 08:54:24.542214 2026] [security2:error] [pid 559070:tid 559253] [client 182.189.99.211:48085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d8Cy1f1FtKC137xv2zwAAAcQ"]
[Tue Jul 21 08:54:24.615531 2026] [security2:error] [pid 559070:tid 559153] [remote 91.142.222.105:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "promocao-relampago.club"] [uri "/wp/wp-login.php"] [unique_id "al9d8Cy1f1FtKC137xv20AABklI"]
[Tue Jul 21 08:54:24.663373 2026] [security2:error] [pid 559070:tid 559276] [client 20.151.10.161:45964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/w3lls.php"] [unique_id "al9d8Cy1f1FtKC137xv20QAAAds"]
[Tue Jul 21 08:54:24.781372 2026] [security2:error] [pid 533360:tid 533599] [client 152.59.181.104:62851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9d8HUPuLYrePtEkUcfmgAAAO8"]
[Tue Jul 21 08:54:24.781509 2026] [security2:error] [pid 533360:tid 533599] [client 152.59.181.104:62851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9d8HUPuLYrePtEkUcfmgAAAO8"]
[Tue Jul 21 08:54:24.788216 2026] [core:error] [pid 559070:tid 559142] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:24.788235 2026] [core:error] [pid 559070:tid 559142] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:25.068423 2026] [autoindex:error] [pid 533360:tid 533576] [client 3.219.86.171:14756] AH01276: Cannot serve directory /home2/cla35313/protetordegraxa.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:54:25.227008 2026] [security2:error] [pid 533360:tid 533497] [client 65.21.113.253:49112] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9d8XUPuLYrePtEkUcfqwAAAIk"]
[Tue Jul 21 08:54:25.238616 2026] [security2:error] [pid 533360:tid 533510] [client 203.25.124.2:64681] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/asasx.php"] [unique_id "al9d8XUPuLYrePtEkUcfrAAAAJY"]
[Tue Jul 21 08:54:25.259363 2026] [security2:error] [pid 559070:tid 559241] [client 20.220.225.223:19274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/akismet.php"] [unique_id "al9d8Sy1f1FtKC137xv23gAAAbg"]
[Tue Jul 21 08:54:25.363210 2026] [security2:error] [pid 533360:tid 533402] [remote 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.extrapro21.com"] [uri "/xmlrpc.php"] [unique_id "al9d8XUPuLYrePtEkUcfrwAAvyY"]
[Tue Jul 21 08:54:25.508651 2026] [security2:error] [pid 533360:tid 533408] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9d8XUPuLYrePtEkUcftgAAuCw"]
[Tue Jul 21 08:54:25.508772 2026] [security2:error] [pid 533360:tid 533544] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9d8XUPuLYrePtEkUcftgAAuCw"]
[Tue Jul 21 08:54:25.557199 2026] [core:error] [pid 559070:tid 559175] [remote 52.167.144.25:31869] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:25.557218 2026] [core:error] [pid 559070:tid 559175] [remote 52.167.144.25:31869] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:25.580167 2026] [security2:error] [pid 559070:tid 559088] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.extrapro21.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9d8Sy1f1FtKC137xv25AAB4RE"]
[Tue Jul 21 08:54:25.679735 2026] [core:error] [pid 559070:tid 559121] [remote 52.167.144.25:31869] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:25.679755 2026] [core:error] [pid 559070:tid 559121] [remote 52.167.144.25:31869] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:25.780287 2026] [security2:error] [pid 533360:tid 533440] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.extrapro21.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9d8XUPuLYrePtEkUcfuQAAwUw"]
[Tue Jul 21 08:54:25.825939 2026] [security2:error] [pid 559070:tid 559205] [client 20.151.10.161:52113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/error_log.php"] [unique_id "al9d8Sy1f1FtKC137xv26wAAAZQ"]
[Tue Jul 21 08:54:25.938482 2026] [security2:error] [pid 559070:tid 559324] [client 20.151.10.161:55819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/w3lls.php"] [unique_id "al9d8Sy1f1FtKC137xv27QAAAgs"]
[Tue Jul 21 08:54:26.047719 2026] [security2:error] [pid 559070:tid 559177] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.extrapro21.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9d8iy1f1FtKC137xv28gABpGo"]
[Tue Jul 21 08:54:26.130461 2026] [security2:error] [pid 559070:tid 559315] [client 20.151.10.161:46038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-ws68.php"] [unique_id "al9d8iy1f1FtKC137xv28wAAAgI"]
[Tue Jul 21 08:54:26.206293 2026] [core:error] [pid 559070:tid 559195] [remote 52.167.144.25:31869] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:26.206321 2026] [core:error] [pid 559070:tid 559195] [remote 52.167.144.25:31869] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:26.290402 2026] [security2:error] [pid 533360:tid 533463] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.extrapro21.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9d8nUPuLYrePtEkUcfwQAArGM"]
[Tue Jul 21 08:54:26.303663 2026] [security2:error] [pid 559070:tid 559218] [client 65.21.113.253:56074] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9d8Sy1f1FtKC137xv27AAAAaE"]
[Tue Jul 21 08:54:26.331474 2026] [core:error] [pid 559070:tid 559107] [remote 52.167.144.25:31869] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:26.331503 2026] [core:error] [pid 559070:tid 559107] [remote 52.167.144.25:31869] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:26.437346 2026] [security2:error] [pid 559070:tid 559234] [client 20.220.225.223:55745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/jga.php"] [unique_id "al9d8iy1f1FtKC137xv2-wAAAbE"]
[Tue Jul 21 08:54:26.442795 2026] [security2:error] [pid 559070:tid 559253] [client 203.25.124.49:43947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/template-wploader.php"] [unique_id "al9d8iy1f1FtKC137xv2_AAAAcQ"]
[Tue Jul 21 08:54:26.536992 2026] [security2:error] [pid 559070:tid 559076] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.extrapro21.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9d8iy1f1FtKC137xv3AAAB4QU"]
[Tue Jul 21 08:54:26.739865 2026] [core:error] [pid 533360:tid 533465] [remote 40.77.167.16:14349] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:26.739889 2026] [core:error] [pid 533360:tid 533465] [remote 40.77.167.16:14349] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:26.757191 2026] [security2:error] [pid 533360:tid 533416] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.extrapro21.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9d8nUPuLYrePtEkUcfzQAAzzQ"]
[Tue Jul 21 08:54:26.927631 2026] [autoindex:error] [pid 559070:tid 559294] [client 66.249.66.202:37847] AH01276: Cannot serve directory /home2/bavosc49/ia.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:54:26.973491 2026] [security2:error] [pid 559070:tid 559185] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.extrapro21.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9d8iy1f1FtKC137xv3BAACC3I"]
[Tue Jul 21 08:54:27.034226 2026] [security2:error] [pid 559070:tid 559219] [client 20.151.10.161:52183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/xenon1337.php"] [unique_id "al9d8yy1f1FtKC137xv3BwAAAaI"]
[Tue Jul 21 08:54:27.164088 2026] [security2:error] [pid 559070:tid 559198] [remote 124.55.178.99:32992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d8yy1f1FtKC137xv3CQABun8"]
[Tue Jul 21 08:54:27.164285 2026] [security2:error] [pid 559070:tid 559243] [client 124.55.178.99:32992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cdatecnologia.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d8yy1f1FtKC137xv3CQABun8"]
[Tue Jul 21 08:54:27.190449 2026] [security2:error] [pid 533360:tid 533432] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.extrapro21.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9d83UPuLYrePtEkUcf2gAA4EQ"]
[Tue Jul 21 08:54:27.415085 2026] [security2:error] [pid 559070:tid 559182] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.extrapro21.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9d8yy1f1FtKC137xv3DwABoW8"]
[Tue Jul 21 08:54:27.478488 2026] [security2:error] [pid 533360:tid 533521] [client 20.151.10.161:46075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xyn.php"] [unique_id "al9d83UPuLYrePtEkUcf4AAAAKE"]
[Tue Jul 21 08:54:27.531295 2026] [security2:error] [pid 559070:tid 559263] [client 59.95.197.55:65465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d8yy1f1FtKC137xv3EQAAAc4"]
[Tue Jul 21 08:54:27.531400 2026] [security2:error] [pid 559070:tid 559263] [client 59.95.197.55:65465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d8yy1f1FtKC137xv3EQAAAc4"]
[Tue Jul 21 08:54:27.580737 2026] [security2:error] [pid 559070:tid 559181] [remote 160.187.68.132:40548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/wp-login.php"] [unique_id "al9d8yy1f1FtKC137xv3EwAB1m4"]
[Tue Jul 21 08:54:27.581399 2026] [security2:error] [pid 559070:tid 559253] [client 20.220.225.223:58941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/x.php"] [unique_id "al9d8yy1f1FtKC137xv3FAAAAcQ"]
[Tue Jul 21 08:54:27.729297 2026] [security2:error] [pid 533360:tid 533489] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.extrapro21.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9d83UPuLYrePtEkUcf6QAApn0"]
[Tue Jul 21 08:54:27.816945 2026] [autoindex:error] [pid 533360:tid 533601] [client 66.249.66.165:46286] AH01276: Cannot serve directory /home2/bavosc49/ia.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:54:27.985637 2026] [security2:error] [pid 559070:tid 559146] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.extrapro21.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9d8yy1f1FtKC137xv3FwAB30s"]
[Tue Jul 21 08:54:28.023818 2026] [security2:error] [pid 559070:tid 559254] [client 168.167.81.163:62376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9d9Cy1f1FtKC137xv3GAAAAcU"]
[Tue Jul 21 08:54:28.023948 2026] [security2:error] [pid 559070:tid 559254] [client 168.167.81.163:62376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9d9Cy1f1FtKC137xv3GAAAAcU"]
[Tue Jul 21 08:54:28.029498 2026] [security2:error] [pid 533360:tid 533613] [client 20.197.192.193:27148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/cron-tab.php"] [unique_id "al9d9HUPuLYrePtEkUcf7QAAAP0"]
[Tue Jul 21 08:54:28.225780 2026] [security2:error] [pid 533360:tid 533384] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.extrapro21.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9d9HUPuLYrePtEkUcf9gAA7BQ"]
[Tue Jul 21 08:54:28.294453 2026] [security2:error] [pid 559070:tid 559250] [client 20.197.192.193:56817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/xyn.php"] [unique_id "al9d9Cy1f1FtKC137xv3GQAAAcE"]
[Tue Jul 21 08:54:28.434595 2026] [security2:error] [pid 559070:tid 559229] [client 203.25.124.71:62667] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/test.php"] [unique_id "al9d9Cy1f1FtKC137xv3GwAAAaw"]
[Tue Jul 21 08:54:28.455027 2026] [security2:error] [pid 533360:tid 533513] [client 20.220.225.223:38748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/kq1.php"] [unique_id "al9d9HUPuLYrePtEkUcf_QAAAJk"]
[Tue Jul 21 08:54:28.539932 2026] [security2:error] [pid 533360:tid 533612] [client 114.198.138.124:61233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9d9HUPuLYrePtEkUcf_gAAAPw"]
[Tue Jul 21 08:54:28.540035 2026] [security2:error] [pid 533360:tid 533612] [client 114.198.138.124:61233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9d9HUPuLYrePtEkUcf_gAAAPw"]
[Tue Jul 21 08:54:29.039951 2026] [security2:error] [pid 533360:tid 533503] [client 20.151.10.161:46026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/green3.php"] [unique_id "al9d9XUPuLYrePtEkUcgDQAAAI8"]
[Tue Jul 21 08:54:29.084715 2026] [security2:error] [pid 559070:tid 559324] [client 20.151.10.161:52175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/test11.php"] [unique_id "al9d9Sy1f1FtKC137xv3IAAAAgs"]
[Tue Jul 21 08:54:29.397644 2026] [security2:error] [pid 533360:tid 533540] [client 20.151.10.161:52108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/koala.php"] [unique_id "al9d9XUPuLYrePtEkUcgFQAAALQ"]
[Tue Jul 21 08:54:29.449224 2026] [security2:error] [pid 533360:tid 533464] [remote 212.64.199.62:37416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.199.64.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9d9XUPuLYrePtEkUcgFwAAuGQ"]
[Tue Jul 21 08:54:29.449360 2026] [security2:error] [pid 533360:tid 533544] [client 212.64.199.62:37416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9d9XUPuLYrePtEkUcgFwAAuGQ"]
[Tue Jul 21 08:54:29.829502 2026] [security2:error] [pid 533360:tid 533487] [remote 45.79.123.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onlinebuyerwebsite.com"] [uri "/wp-login.php"] [unique_id "al9d9XUPuLYrePtEkUcgIgABAHs"]
[Tue Jul 21 08:54:29.841617 2026] [security2:error] [pid 559070:tid 559315] [client 203.25.124.65:48201] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/network/index.php"] [unique_id "al9d9Sy1f1FtKC137xv3KgAAAgI"]
[Tue Jul 21 08:54:29.854372 2026] [security2:error] [pid 559070:tid 559100] [remote 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9d9Sy1f1FtKC137xv3KwABoB0"]
[Tue Jul 21 08:54:29.854534 2026] [security2:error] [pid 559070:tid 559217] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9d9Sy1f1FtKC137xv3KwABoB0"]
[Tue Jul 21 08:54:30.084265 2026] [security2:error] [pid 559070:tid 559203] [client 198.44.157.162:60858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9d9iy1f1FtKC137xv3LAAAAZI"]
[Tue Jul 21 08:54:30.084367 2026] [security2:error] [pid 559070:tid 559203] [client 198.44.157.162:60858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9d9iy1f1FtKC137xv3LAAAAZI"]
[Tue Jul 21 08:54:30.121340 2026] [security2:error] [pid 533360:tid 533517] [client 65.21.113.253:49112] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9d9nUPuLYrePtEkUcgJAAAAJ0"]
[Tue Jul 21 08:54:30.198938 2026] [security2:error] [pid 559070:tid 559269] [client 20.151.10.161:52208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/mac.php"] [unique_id "al9d9iy1f1FtKC137xv3MAAAAdQ"]
[Tue Jul 21 08:54:30.354173 2026] [security2:error] [pid 559070:tid 559139] [remote 57.141.18.34:54320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapk.xml"] [unique_id "al9d9iy1f1FtKC137xv3LgABsUQ"]
[Tue Jul 21 08:54:30.666029 2026] [security2:error] [pid 559070:tid 559292] [client 20.151.10.161:37841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/25d653587fdfd1.php"] [unique_id "al9d9iy1f1FtKC137xv3NgAAAes"]
[Tue Jul 21 08:54:30.834631 2026] [security2:error] [pid 533360:tid 533614] [client 203.25.124.43:24947] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/moon.php"] [unique_id "al9d9nUPuLYrePtEkUcgMwAAAP4"]
[Tue Jul 21 08:54:30.865241 2026] [security2:error] [pid 533360:tid 533497] [client 20.197.192.193:50566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/byp8.php"] [unique_id "al9d9nUPuLYrePtEkUcgNQAAAIk"]
[Tue Jul 21 08:54:31.009376 2026] [proxy:error] [pid 559070:tid 559243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:31.009481 2026] [proxy_http:error] [pid 559070:tid 559243] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:31.011177 2026] [proxy:error] [pid 559070:tid 559243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:31.011221 2026] [proxy_http:error] [pid 559070:tid 559243] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:31.165195 2026] [security2:error] [pid 559070:tid 559245] [client 20.151.10.161:49137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/yyu.php"] [unique_id "al9d9yy1f1FtKC137xv3QAAAAbw"]
[Tue Jul 21 08:54:31.204795 2026] [security2:error] [pid 559070:tid 559210] [client 20.151.10.161:45900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/ccs.php"] [unique_id "al9d9yy1f1FtKC137xv3QQAAAZk"]
[Tue Jul 21 08:54:31.223831 2026] [security2:error] [pid 559070:tid 559302] [client 20.220.225.223:19304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/ace2.php"] [unique_id "al9d9yy1f1FtKC137xv3QgAAAfU"]
[Tue Jul 21 08:54:31.238656 2026] [security2:error] [pid 559070:tid 559291] [client 65.21.113.253:54922] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9d9iy1f1FtKC137xv3OwAAAeo"]
[Tue Jul 21 08:54:31.250978 2026] [security2:error] [pid 559070:tid 559218] [client 20.151.10.161:52115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wefile.php"] [unique_id "al9d9yy1f1FtKC137xv3QwAAAaE"]
[Tue Jul 21 08:54:31.605566 2026] [proxy:error] [pid 533360:tid 533576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:31.605647 2026] [proxy_http:error] [pid 533360:tid 533576] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:31.606135 2026] [proxy:error] [pid 533360:tid 533576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:31.606185 2026] [proxy_http:error] [pid 533360:tid 533576] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:31.622195 2026] [security2:error] [pid 533360:tid 533608] [client 20.151.10.161:55868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-ws68.php"] [unique_id "al9d93UPuLYrePtEkUcgRgAAAPg"]
[Tue Jul 21 08:54:31.923318 2026] [proxy:error] [pid 533360:tid 533620] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:31.924724 2026] [proxy_http:error] [pid 533360:tid 533620] [client 20.151.10.161:37859] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:31.925674 2026] [proxy:error] [pid 533360:tid 533620] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:31.925719 2026] [proxy_http:error] [pid 533360:tid 533620] [client 20.151.10.161:37859] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:32.033682 2026] [security2:error] [pid 533360:tid 533539] [client 212.32.76.12:25667] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/upload/"] [unique_id "al9d-HUPuLYrePtEkUcgWwAAALM"]
[Tue Jul 21 08:54:32.141914 2026] [security2:error] [pid 559070:tid 559089] [remote 159.89.175.206:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.175.89.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9d9yy1f1FtKC137xv3TQACChI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:54:32.261269 2026] [security2:error] [pid 533360:tid 533476] [remote 159.89.175.206:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.175.89.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9d-HUPuLYrePtEkUcgXAAAjnA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:54:32.293676 2026] [security2:error] [pid 533360:tid 533368] [remote 159.89.175.206:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.175.89.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9d93UPuLYrePtEkUcgUwABAAQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:54:32.298211 2026] [security2:error] [pid 533360:tid 533401] [remote 159.89.175.206:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.175.89.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9d93UPuLYrePtEkUcgVQAAxyU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:54:32.299293 2026] [proxy:error] [pid 533360:tid 533558] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:32.299397 2026] [proxy_http:error] [pid 533360:tid 533558] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:32.301226 2026] [proxy:error] [pid 533360:tid 533558] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:32.301286 2026] [proxy_http:error] [pid 533360:tid 533558] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:32.335099 2026] [security2:error] [pid 533360:tid 533515] [client 20.151.10.161:46001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/ccc.php"] [unique_id "al9d-HUPuLYrePtEkUcgYAAAAJs"]
[Tue Jul 21 08:54:32.357900 2026] [proxy:error] [pid 533360:tid 533581] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:32.357992 2026] [proxy_http:error] [pid 533360:tid 533581] [client 20.151.10.161:37828] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:32.360936 2026] [proxy:error] [pid 533360:tid 533581] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:32.361016 2026] [proxy_http:error] [pid 533360:tid 533581] [client 20.151.10.161:37828] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:32.523002 2026] [security2:error] [pid 533360:tid 533416] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9d-HUPuLYrePtEkUcgZwAAtzQ"]
[Tue Jul 21 08:54:32.523195 2026] [security2:error] [pid 533360:tid 533543] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9d-HUPuLYrePtEkUcgZwAAtzQ"]
[Tue Jul 21 08:54:32.602148 2026] [security2:error] [pid 533360:tid 533488] [remote 159.89.175.206:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.175.89.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9d-HUPuLYrePtEkUcgagAA0Xw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:54:32.608904 2026] [security2:error] [pid 533360:tid 533466] [remote 159.89.175.206:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.175.89.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9d-HUPuLYrePtEkUcgawAAv2Y"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:54:32.642705 2026] [security2:error] [pid 533360:tid 533405] [remote 159.89.175.206:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.175.89.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9d-HUPuLYrePtEkUcgbQAA6Ck"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:54:32.675654 2026] [security2:error] [pid 533360:tid 533532] [client 113.22.144.139:51102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d-HUPuLYrePtEkUcgbgAAAKw"]
[Tue Jul 21 08:54:32.675791 2026] [security2:error] [pid 533360:tid 533532] [client 113.22.144.139:51102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d-HUPuLYrePtEkUcgbgAAAKw"]
[Tue Jul 21 08:54:32.696672 2026] [security2:error] [pid 533360:tid 533583] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9d-HUPuLYrePtEkUcgaAAA3ww"]
[Tue Jul 21 08:54:32.705243 2026] [security2:error] [pid 559070:tid 559218] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d-Cy1f1FtKC137xv3VQAAAaE"]
[Tue Jul 21 08:54:32.705845 2026] [security2:error] [pid 533360:tid 533516] [client 20.151.10.161:37869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9d-HUPuLYrePtEkUcgbwAAAJw"]
[Tue Jul 21 08:54:32.737375 2026] [security2:error] [pid 533360:tid 533432] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d-HUPuLYrePtEkUcgcAAAj0Q"]
[Tue Jul 21 08:54:32.737503 2026] [security2:error] [pid 533360:tid 533503] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d-HUPuLYrePtEkUcgcAAAj0Q"]
[Tue Jul 21 08:54:32.918502 2026] [security2:error] [pid 533360:tid 533486] [remote 159.89.175.206:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.175.89.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9d-HUPuLYrePtEkUcgdgAA4Xo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:54:32.923736 2026] [security2:error] [pid 533360:tid 533424] [remote 159.89.175.206:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.175.89.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9d-HUPuLYrePtEkUcgdwAA6zw"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:54:32.982036 2026] [security2:error] [pid 559070:tid 559113] [remote 159.89.175.206:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.175.89.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9d-Cy1f1FtKC137xv3WgABkSo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:54:33.040215 2026] [security2:error] [pid 533360:tid 533608] [client 203.25.124.73:25085] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/css/index.php"] [unique_id "al9d-XUPuLYrePtEkUcgegAAAPg"]
[Tue Jul 21 08:54:33.042808 2026] [security2:error] [pid 533360:tid 533480] [remote 159.89.175.206:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.175.89.159.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9d-XUPuLYrePtEkUcgewAAxXQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:54:33.115340 2026] [security2:error] [pid 559070:tid 559265] [client 20.220.225.223:48244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/cro.php"] [unique_id "al9d-Sy1f1FtKC137xv3WwAAAdA"]
[Tue Jul 21 08:54:33.117098 2026] [security2:error] [pid 533360:tid 533495] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9d-XUPuLYrePtEkUcgfQAAAIc"]
[Tue Jul 21 08:54:33.229855 2026] [security2:error] [pid 559070:tid 559282] [client 20.151.10.161:37858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/2P.php"] [unique_id "al9d-Sy1f1FtKC137xv3XgAAAeE"]
[Tue Jul 21 08:54:33.560484 2026] [security2:error] [pid 533360:tid 533591] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9d-XUPuLYrePtEkUcghAAAAOc"]
[Tue Jul 21 08:54:33.658184 2026] [security2:error] [pid 533360:tid 533593] [client 20.151.10.161:52176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/.well-known/about.php"] [unique_id "al9d-XUPuLYrePtEkUcgiAAAAOk"]
[Tue Jul 21 08:54:33.771595 2026] [security2:error] [pid 533360:tid 533558] [client 20.52.136.55:1570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9d-XUPuLYrePtEkUcgigAAAMY"]
[Tue Jul 21 08:54:33.784078 2026] [security2:error] [pid 559070:tid 559229] [client 20.220.225.223:52620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9d-Sy1f1FtKC137xv3ZQAAAaw"]
[Tue Jul 21 08:54:33.854215 2026] [security2:error] [pid 559070:tid 559289] [client 20.220.225.223:21892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/zzz.php"] [unique_id "al9d-Sy1f1FtKC137xv3ZgAAAeg"]
[Tue Jul 21 08:54:33.891406 2026] [security2:error] [pid 559070:tid 559223] [client 20.151.10.161:46039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/get.php"] [unique_id "al9d-Sy1f1FtKC137xv3aAAAAaY"]
[Tue Jul 21 08:54:34.009886 2026] [security2:error] [pid 559070:tid 559218] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9d-iy1f1FtKC137xv3bQAAAaE"]
[Tue Jul 21 08:54:34.036864 2026] [security2:error] [pid 559070:tid 559217] [client 212.32.76.9:42023] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/network/cache/"] [unique_id "al9d-iy1f1FtKC137xv3bwAAAaA"]
[Tue Jul 21 08:54:34.139905 2026] [security2:error] [pid 559070:tid 559258] [client 20.151.10.161:37845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9d-iy1f1FtKC137xv3cQAAAck"]
[Tue Jul 21 08:54:34.362507 2026] [security2:error] [pid 559070:tid 559215] [client 41.89.234.2:6454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d-iy1f1FtKC137xv3dAAAAZ4"]
[Tue Jul 21 08:54:34.362867 2026] [security2:error] [pid 559070:tid 559215] [client 41.89.234.2:6454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d-iy1f1FtKC137xv3dAAAAZ4"]
[Tue Jul 21 08:54:34.422170 2026] [core:alert] [pid 559070:tid 559225] [client 57.141.18.42:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:54:34.455207 2026] [security2:error] [pid 559070:tid 559238] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9d-iy1f1FtKC137xv3fQAAAbU"]
[Tue Jul 21 08:54:34.462688 2026] [security2:error] [pid 559070:tid 559300] [client 20.151.10.161:52182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/bob.php"] [unique_id "al9d-iy1f1FtKC137xv3fgAAAfM"]
[Tue Jul 21 08:54:34.524887 2026] [security2:error] [pid 533360:tid 533516] [client 65.21.113.253:49112] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9d-nUPuLYrePtEkUcgmwAAAJw"]
[Tue Jul 21 08:54:34.576936 2026] [security2:error] [pid 559070:tid 559131] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d-iy1f1FtKC137xv3gQABkTw"]
[Tue Jul 21 08:54:34.577108 2026] [security2:error] [pid 559070:tid 559202] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d-iy1f1FtKC137xv3gQABkTw"]
[Tue Jul 21 08:54:34.593376 2026] [security2:error] [pid 559070:tid 559229] [client 20.151.10.161:46021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/images.php"] [unique_id "al9d-iy1f1FtKC137xv3ggAAAaw"]
[Tue Jul 21 08:54:34.656157 2026] [security2:error] [pid 533360:tid 533579] [client 5.38.115.39:54367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9d-nUPuLYrePtEkUcgngAAANs"]
[Tue Jul 21 08:54:34.656250 2026] [security2:error] [pid 533360:tid 533579] [client 5.38.115.39:54367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9d-nUPuLYrePtEkUcgngAAANs"]
[Tue Jul 21 08:54:34.834349 2026] [proxy:error] [pid 533360:tid 533520] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:34.834429 2026] [proxy_http:error] [pid 533360:tid 533520] [client 20.151.10.161:52139] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:34.834861 2026] [proxy:error] [pid 533360:tid 533520] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:34.834882 2026] [proxy_http:error] [pid 533360:tid 533520] [client 20.151.10.161:52139] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:34.853219 2026] [security2:error] [pid 533360:tid 533585] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9d-nUPuLYrePtEkUcgogAAAOE"]
[Tue Jul 21 08:54:35.014062 2026] [security2:error] [pid 533360:tid 533566] [client 20.220.225.223:34862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/kq1.php"] [unique_id "al9d-3UPuLYrePtEkUcgqwAAAM4"]
[Tue Jul 21 08:54:35.049779 2026] [security2:error] [pid 559070:tid 559207] [client 182.189.99.211:48631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d-yy1f1FtKC137xv3iwAAAZY"]
[Tue Jul 21 08:54:35.049914 2026] [security2:error] [pid 559070:tid 559207] [client 182.189.99.211:48631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d-yy1f1FtKC137xv3iwAAAZY"]
[Tue Jul 21 08:54:35.143669 2026] [proxy:error] [pid 533360:tid 533561] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:35.143758 2026] [proxy_http:error] [pid 533360:tid 533561] [client 20.151.10.161:52114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:35.145131 2026] [proxy:error] [pid 533360:tid 533561] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:35.145169 2026] [proxy_http:error] [pid 533360:tid 533561] [client 20.151.10.161:52114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:35.153036 2026] [security2:error] [pid 559070:tid 559306] [client 103.59.206.240:31271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d-yy1f1FtKC137xv3jAAAAfk"]
[Tue Jul 21 08:54:35.153183 2026] [security2:error] [pid 559070:tid 559306] [client 103.59.206.240:31271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d-yy1f1FtKC137xv3jAAAAfk"]
[Tue Jul 21 08:54:35.223253 2026] [qos:error] [pid 559070:tid 559136] [remote 57.141.18.31:28078] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.31, id=al9d-yy1f1FtKC137xv3jwABnkE
[Tue Jul 21 08:54:35.292234 2026] [security2:error] [pid 559070:tid 559200] [client 20.151.10.161:45966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/alls.php"] [unique_id "al9d-yy1f1FtKC137xv3kAAAAY8"]
[Tue Jul 21 08:54:35.323195 2026] [security2:error] [pid 559070:tid 559254] [client 152.59.181.104:63349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.181.59.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9d-yy1f1FtKC137xv3kQAAAcU"]
[Tue Jul 21 08:54:35.328543 2026] [security2:error] [pid 559070:tid 559254] [client 152.59.181.104:63349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9d-yy1f1FtKC137xv3kQAAAcU"]
[Tue Jul 21 08:54:35.344112 2026] [security2:error] [pid 559070:tid 559252] [client 203.25.124.67:63411] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/abcd.php"] [unique_id "al9d-yy1f1FtKC137xv3kgAAAcM"]
[Tue Jul 21 08:54:35.347652 2026] [security2:error] [pid 559070:tid 559225] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9d-yy1f1FtKC137xv3kwAAAag"]
[Tue Jul 21 08:54:35.545784 2026] [security2:error] [pid 533360:tid 533511] [client 167.114.139.155:36658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "drjoaoguedes.com"] [uri "/robots.txt"] [unique_id "al9d-3UPuLYrePtEkUcgvAAAAJc"]
[Tue Jul 21 08:54:35.545907 2026] [security2:error] [pid 533360:tid 533511] [client 167.114.139.155:36658] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "drjoaoguedes.com"] [uri "/robots.txt"] [unique_id "al9d-3UPuLYrePtEkUcgvAAAAJc"]
[Tue Jul 21 08:54:35.606561 2026] [qos:error] [pid 559070:tid 559174] [remote 57.141.18.109:47498] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.109, id=al9d-yy1f1FtKC137xv3mAABk2c
[Tue Jul 21 08:54:35.665295 2026] [security2:error] [pid 559070:tid 559226] [client 65.21.113.253:54928] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9d-yy1f1FtKC137xv3jQAAAak"]
[Tue Jul 21 08:54:35.745996 2026] [security2:error] [pid 559070:tid 559230] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9d-yy1f1FtKC137xv3mgAAAa0"]
[Tue Jul 21 08:54:35.746486 2026] [security2:error] [pid 559070:tid 559241] [client 20.151.10.161:52107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/crgio.php"] [unique_id "al9d-yy1f1FtKC137xv3mwAAAbg"]
[Tue Jul 21 08:54:35.816525 2026] [security2:error] [pid 559070:tid 559291] [client 198.44.157.162:35224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9d-yy1f1FtKC137xv3nQAAAeo"]
[Tue Jul 21 08:54:35.816636 2026] [security2:error] [pid 559070:tid 559291] [client 198.44.157.162:35224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9d-yy1f1FtKC137xv3nQAAAeo"]
[Tue Jul 21 08:54:35.936952 2026] [qos:error] [pid 533360:tid 533469] [remote 57.141.18.92:37290] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.92, id=al9d-3UPuLYrePtEkUcgwwAAyGk
[Tue Jul 21 08:54:36.046182 2026] [security2:error] [pid 559070:tid 559142] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9d_Cy1f1FtKC137xv3ogAB-Uc"]
[Tue Jul 21 08:54:36.046314 2026] [security2:error] [pid 559070:tid 559306] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9d_Cy1f1FtKC137xv3ogAB-Uc"]
[Tue Jul 21 08:54:36.087090 2026] [security2:error] [pid 533360:tid 533540] [client 20.151.10.161:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/yyu.php"] [unique_id "al9d_HUPuLYrePtEkUcgzQAAALQ"]
[Tue Jul 21 08:54:36.108887 2026] [security2:error] [pid 559070:tid 559081] [remote 192.241.143.148:51406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "powerflats.com.br"] [uri "/wp-login.php"] [unique_id "al9d_Cy1f1FtKC137xv3pQAB7Ao"]
[Tue Jul 21 08:54:36.115702 2026] [security2:error] [pid 559070:tid 559250] [client 20.151.10.161:51016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/xyn.php"] [unique_id "al9d_Cy1f1FtKC137xv3pgAAAcE"]
[Tue Jul 21 08:54:36.171603 2026] [security2:error] [pid 559070:tid 559209] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9d_Cy1f1FtKC137xv3qwAAAZg"]
[Tue Jul 21 08:54:36.343433 2026] [security2:error] [pid 533360:tid 533593] [client 20.151.10.161:52096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/pucci.php"] [unique_id "al9d_HUPuLYrePtEkUcg4QAAAOk"]
[Tue Jul 21 08:54:36.571008 2026] [security2:error] [pid 559070:tid 559215] [client 128.127.105.184:46850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9d_Cy1f1FtKC137xv3vwAAAZ4"]
[Tue Jul 21 08:54:36.571115 2026] [security2:error] [pid 559070:tid 559215] [client 128.127.105.184:46850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9d_Cy1f1FtKC137xv3vwAAAZ4"]
[Tue Jul 21 08:54:36.584605 2026] [security2:error] [pid 533360:tid 533517] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9d_HUPuLYrePtEkUcg8AAAAJ0"]
[Tue Jul 21 08:54:36.639963 2026] [security2:error] [pid 533360:tid 533583] [client 203.25.124.33:55711] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwentyfour/patterns/template-singl-portfolio.php"] [unique_id "al9d_HUPuLYrePtEkUcg8wAAAN8"]
[Tue Jul 21 08:54:36.727940 2026] [proxy:error] [pid 533360:tid 533606] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:36.728010 2026] [proxy_http:error] [pid 533360:tid 533606] [client 20.151.10.161:52169] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:36.728510 2026] [proxy:error] [pid 533360:tid 533606] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:36.728542 2026] [proxy_http:error] [pid 533360:tid 533606] [client 20.151.10.161:52169] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:36.739753 2026] [security2:error] [pid 559070:tid 559292] [client 20.151.10.161:46019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/by.php"] [unique_id "al9d_Cy1f1FtKC137xv3xwAAAes"]
[Tue Jul 21 08:54:36.811117 2026] [core:error] [pid 533360:tid 533430] [remote 40.77.167.16:14337] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:36.811152 2026] [core:error] [pid 533360:tid 533430] [remote 40.77.167.16:14337] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:36.926791 2026] [security2:error] [pid 533360:tid 533494] [client 20.220.225.223:60274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/wicked.php"] [unique_id "al9d_HUPuLYrePtEkUchAQAAAIY"]
[Tue Jul 21 08:54:36.942431 2026] [core:error] [pid 533360:tid 533489] [remote 40.77.167.16:14337] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:36.942449 2026] [core:error] [pid 533360:tid 533489] [remote 40.77.167.16:14337] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:36.977777 2026] [security2:error] [pid 559070:tid 559314] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9d_Cy1f1FtKC137xv3zwAAAgE"]
[Tue Jul 21 08:54:37.052261 2026] [qos:error] [pid 533360:tid 533411] [remote 57.141.18.28:57996] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.28, id=al9d_XUPuLYrePtEkUchBwAAhy8
[Tue Jul 21 08:54:37.068087 2026] [core:error] [pid 533360:tid 533418] [remote 40.77.167.16:14337] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:37.068106 2026] [core:error] [pid 533360:tid 533418] [remote 40.77.167.16:14337] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:37.084242 2026] [security2:error] [pid 533360:tid 533522] [client 20.220.225.223:55746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/ee.php"] [unique_id "al9d_XUPuLYrePtEkUchCgAAAKI"]
[Tue Jul 21 08:54:37.084762 2026] [security2:error] [pid 559070:tid 559207] [client 128.127.105.184:46862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9d_Sy1f1FtKC137xv32gAAAZY"]
[Tue Jul 21 08:54:37.084848 2026] [security2:error] [pid 559070:tid 559207] [client 128.127.105.184:46862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9d_Sy1f1FtKC137xv32gAAAZY"]
[Tue Jul 21 08:54:37.134589 2026] [security2:error] [pid 559070:tid 559281] [client 51.222.168.248:40846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "drjoaoguedes.com"] [uri "/"] [unique_id "al9d_Sy1f1FtKC137xv32wAAAeA"]
[Tue Jul 21 08:54:37.134686 2026] [security2:error] [pid 559070:tid 559281] [client 51.222.168.248:40846] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "drjoaoguedes.com"] [uri "/"] [unique_id "al9d_Sy1f1FtKC137xv32wAAAeA"]
[Tue Jul 21 08:54:37.178733 2026] [qos:error] [pid 559070:tid 559139] [remote 57.141.18.26:41980] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.26, id=al9d_Sy1f1FtKC137xv33AACC0Q
[Tue Jul 21 08:54:37.180658 2026] [security2:error] [pid 533360:tid 533455] [remote 41.186.86.12:14911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinadona.com"] [uri "/wp-login.php"] [unique_id "al9d_XUPuLYrePtEkUchDAAAuls"]
[Tue Jul 21 08:54:37.259746 2026] [proxy:error] [pid 559070:tid 559280] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:37.259965 2026] [proxy_http:error] [pid 559070:tid 559280] [client 20.151.10.161:52194] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:37.261644 2026] [proxy:error] [pid 559070:tid 559280] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:37.261697 2026] [proxy_http:error] [pid 559070:tid 559280] [client 20.151.10.161:52194] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:37.361535 2026] [security2:error] [pid 533360:tid 533598] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9d_XUPuLYrePtEkUchDwAAAO4"]
[Tue Jul 21 08:54:37.408050 2026] [qos:error] [pid 533360:tid 533422] [remote 57.141.18.99:56048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.99, id=al9d_XUPuLYrePtEkUchEQAA7Do
[Tue Jul 21 08:54:37.503881 2026] [qos:error] [pid 559070:tid 559128] [remote 57.141.18.101:40008] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.101, id=al9d_Sy1f1FtKC137xv35QAB8zk
[Tue Jul 21 08:54:37.513601 2026] [security2:error] [pid 533360:tid 533523] [client 20.151.10.161:45972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/FAQ.php"] [unique_id "al9d_XUPuLYrePtEkUchEwAAAKM"]
[Tue Jul 21 08:54:37.551309 2026] [qos:error] [pid 559070:tid 559089] [remote 57.141.18.105:62510] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.105, id=al9d_Sy1f1FtKC137xv36AABrRI
[Tue Jul 21 08:54:37.613297 2026] [autoindex:error] [pid 559070:tid 559314] [client 147.185.132.55:61886] AH01276: Cannot serve directory /home4/arcoll06/a16.arcoll.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:54:37.637677 2026] [security2:error] [pid 559070:tid 559281] [client 203.25.124.67:21841] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/class-wp-smtp-bar.php"] [unique_id "al9d_Sy1f1FtKC137xv37gAAAeA"]
[Tue Jul 21 08:54:37.753986 2026] [security2:error] [pid 559070:tid 559317] [client 20.151.10.161:37783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-temp.php"] [unique_id "al9d_Sy1f1FtKC137xv37wAAAgQ"]
[Tue Jul 21 08:54:37.768514 2026] [security2:error] [pid 559070:tid 559292] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fernandaferreiragued1782145314174.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9d_Sy1f1FtKC137xv38AAAAes"]
[Tue Jul 21 08:54:37.772030 2026] [security2:error] [pid 559070:tid 559252] [client 20.151.10.161:49140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/by.php"] [unique_id "al9d_Sy1f1FtKC137xv38QAAAcM"]
[Tue Jul 21 08:54:37.907483 2026] [qos:error] [pid 559070:tid 559147] [remote 57.141.18.52:33238] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.52, id=al9d_Sy1f1FtKC137xv39QACCkw
[Tue Jul 21 08:54:38.136106 2026] [security2:error] [pid 559070:tid 559219] [client 59.95.197.55:49558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d_iy1f1FtKC137xv3_gAAAaI"]
[Tue Jul 21 08:54:38.136787 2026] [security2:error] [pid 559070:tid 559219] [client 59.95.197.55:49558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9d_iy1f1FtKC137xv3_gAAAaI"]
[Tue Jul 21 08:54:38.352300 2026] [proxy:error] [pid 533360:tid 533619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:38.352396 2026] [proxy_http:error] [pid 533360:tid 533619] [client 20.151.10.161:52203] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:38.354675 2026] [proxy:error] [pid 533360:tid 533619] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:38.354740 2026] [proxy_http:error] [pid 533360:tid 533619] [client 20.151.10.161:52203] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:38.627246 2026] [security2:error] [pid 533360:tid 533593] [client 212.32.76.11:44861] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/assets/images/selam.php"] [unique_id "al9d_nUPuLYrePtEkUchMAAAAOk"]
[Tue Jul 21 08:54:38.678164 2026] [security2:error] [pid 533360:tid 533557] [client 20.151.10.161:37778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9d_nUPuLYrePtEkUchNgAAAMU"]
[Tue Jul 21 08:54:38.686654 2026] [security2:error] [pid 559070:tid 559265] [client 168.167.81.163:62646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9d_iy1f1FtKC137xv4CQAAAdA"]
[Tue Jul 21 08:54:38.686743 2026] [security2:error] [pid 559070:tid 559265] [client 168.167.81.163:62646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9d_iy1f1FtKC137xv4CQAAAdA"]
[Tue Jul 21 08:54:38.864600 2026] [security2:error] [pid 533360:tid 533515] [client 20.220.225.223:21579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/edit.php"] [unique_id "al9d_nUPuLYrePtEkUchOwAAAJs"]
[Tue Jul 21 08:54:38.948863 2026] [security2:error] [pid 559070:tid 559241] [client 20.151.10.161:45960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/coffexium.php"] [unique_id "al9d_iy1f1FtKC137xv4DAAAAbg"]
[Tue Jul 21 08:54:38.977478 2026] [security2:error] [pid 559070:tid 559256] [client 20.197.192.193:56812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/user.php"] [unique_id "al9d_iy1f1FtKC137xv4DQAAAcc"]
[Tue Jul 21 08:54:39.044907 2026] [security2:error] [pid 533360:tid 533545] [client 114.198.138.124:61805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9d_3UPuLYrePtEkUchPwAAALk"]
[Tue Jul 21 08:54:39.045010 2026] [security2:error] [pid 533360:tid 533545] [client 114.198.138.124:61805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9d_3UPuLYrePtEkUchPwAAALk"]
[Tue Jul 21 08:54:39.069451 2026] [qos:error] [pid 559070:tid 559130] [remote 57.141.18.114:48426] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.114, id=al9d_yy1f1FtKC137xv4EQABqDs
[Tue Jul 21 08:54:39.105093 2026] [security2:error] [pid 559070:tid 559085] [remote 198.244.226.246:47336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "benti.com.br"] [uri "/robots.txt"] [unique_id "al9d_yy1f1FtKC137xv4EgABpg4"]
[Tue Jul 21 08:54:39.105257 2026] [security2:error] [pid 559070:tid 559223] [client 198.244.226.246:47336] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "benti.com.br"] [uri "/robots.txt"] [unique_id "al9d_yy1f1FtKC137xv4EgABpg4"]
[Tue Jul 21 08:54:39.118028 2026] [qos:error] [pid 533360:tid 533427] [remote 57.141.18.18:24552] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.18, id=al9d_3UPuLYrePtEkUchQwAA5j8
[Tue Jul 21 08:54:39.186385 2026] [security2:error] [pid 533360:tid 533583] [client 20.151.10.161:52101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/puc.php"] [unique_id "al9d_3UPuLYrePtEkUchRgAAAN8"]
[Tue Jul 21 08:54:39.296168 2026] [security2:error] [pid 533360:tid 533606] [client 65.21.113.253:49112] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9d_3UPuLYrePtEkUchRwAAAPY"]
[Tue Jul 21 08:54:39.541735 2026] [security2:error] [pid 533360:tid 533494] [client 198.44.157.162:52434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9d_3UPuLYrePtEkUchUAAAAIY"]
[Tue Jul 21 08:54:39.541854 2026] [security2:error] [pid 533360:tid 533494] [client 198.44.157.162:52434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9d_3UPuLYrePtEkUchUAAAAIY"]
[Tue Jul 21 08:54:39.559232 2026] [security2:error] [pid 533360:tid 533548] [client 168.119.123.75:39912] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9d_3UPuLYrePtEkUchUQAAALw"], referer: https://artetoner.com.br
[Tue Jul 21 08:54:39.648356 2026] [security2:error] [pid 559070:tid 559269] [client 20.151.10.161:37850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/themes.php"] [unique_id "al9d_yy1f1FtKC137xv4FgAAAdQ"]
[Tue Jul 21 08:54:39.775985 2026] [qos:error] [pid 533360:tid 533449] [remote 57.141.18.33:32330] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.33, id=al9d_3UPuLYrePtEkUchWQAA4VU
[Tue Jul 21 08:54:39.962882 2026] [qos:error] [pid 559070:tid 559153] [remote 57.141.18.30:36654] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.30, id=al9d_yy1f1FtKC137xv4HwABmVI
[Tue Jul 21 08:54:40.069359 2026] [security2:error] [pid 559070:tid 559274] [client 20.151.10.161:37812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/dx.php"] [unique_id "al9eACy1f1FtKC137xv4IgAAAdk"]
[Tue Jul 21 08:54:40.124307 2026] [security2:error] [pid 533360:tid 533612] [client 20.151.10.161:46074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/red.php"] [unique_id "al9eAHUPuLYrePtEkUchngAAAPw"]
[Tue Jul 21 08:54:40.329303 2026] [security2:error] [pid 559070:tid 559312] [client 212.32.76.7:61333] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/manager.php"] [unique_id "al9eACy1f1FtKC137xv4MQAAAf8"]
[Tue Jul 21 08:54:40.406363 2026] [security2:error] [pid 559070:tid 559086] [remote 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9eACy1f1FtKC137xv4NQABkg8"]
[Tue Jul 21 08:54:40.407226 2026] [security2:error] [pid 559070:tid 559203] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9eACy1f1FtKC137xv4NQABkg8"]
[Tue Jul 21 08:54:40.435864 2026] [security2:error] [pid 559070:tid 559299] [client 65.21.113.253:43650] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9d_yy1f1FtKC137xv4IAAAAfI"]
[Tue Jul 21 08:54:40.468668 2026] [security2:error] [pid 559070:tid 559243] [client 20.151.10.161:52200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/p.php"] [unique_id "al9eACy1f1FtKC137xv4QgAAAbo"]
[Tue Jul 21 08:54:40.523721 2026] [security2:error] [pid 533360:tid 533562] [client 20.151.10.161:51066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/green3.php"] [unique_id "al9eAHUPuLYrePtEkUciBgAAAMo"]
[Tue Jul 21 08:54:40.656867 2026] [autoindex:error] [pid 559070:tid 559276] [client 20.151.10.161:45962] AH01276: Cannot serve directory /home3/housei59/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:54:40.776198 2026] [proxy:error] [pid 533360:tid 533519] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:40.776262 2026] [proxy_http:error] [pid 533360:tid 533519] [client 20.151.10.161:52140] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:40.776700 2026] [proxy:error] [pid 533360:tid 533519] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:40.776720 2026] [proxy_http:error] [pid 533360:tid 533519] [client 20.151.10.161:52140] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:40.849995 2026] [security2:error] [pid 559070:tid 559142] [remote 54.39.210.140:27792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "benti.com.br"] [uri "/"] [unique_id "al9eACy1f1FtKC137xv4SQACAUc"]
[Tue Jul 21 08:54:40.850172 2026] [security2:error] [pid 559070:tid 559314] [client 54.39.210.140:27792] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "benti.com.br"] [uri "/"] [unique_id "al9eACy1f1FtKC137xv4SQACAUc"]
[Tue Jul 21 08:54:41.037033 2026] [security2:error] [pid 559070:tid 559202] [client 20.220.225.223:48208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/kua.php"] [unique_id "al9eASy1f1FtKC137xv4TQAAAZE"]
[Tue Jul 21 08:54:41.038146 2026] [security2:error] [pid 559070:tid 559245] [client 20.220.225.223:21582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/cron-tab.php"] [unique_id "al9eASy1f1FtKC137xv4TgAAAbw"]
[Tue Jul 21 08:54:41.094891 2026] [security2:error] [pid 559070:tid 559217] [client 20.151.10.161:45962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9eASy1f1FtKC137xv4UAAAAaA"]
[Tue Jul 21 08:54:41.104499 2026] [security2:error] [pid 559070:tid 559296] [client 20.151.10.161:52173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/bthil.php"] [unique_id "al9eASy1f1FtKC137xv4UQAAAe8"]
[Tue Jul 21 08:54:41.223774 2026] [core:error] [pid 559070:tid 559075] [remote 40.77.167.72:5499] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:41.223808 2026] [core:error] [pid 559070:tid 559075] [remote 40.77.167.72:5499] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:54:41.319039 2026] [security2:error] [pid 559070:tid 559250] [client 20.197.192.193:27108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/koiy.php"] [unique_id "al9eASy1f1FtKC137xv4WgAAAcE"]
[Tue Jul 21 08:54:41.409424 2026] [security2:error] [pid 559070:tid 559324] [client 20.151.10.161:52147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/7.php"] [unique_id "al9eASy1f1FtKC137xv4XQAAAgs"]
[Tue Jul 21 08:54:41.434392 2026] [autoindex:error] [pid 559070:tid 559217] [client 20.151.10.161:45940] AH01276: Cannot serve directory /home3/housei59/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:54:41.541080 2026] [security2:error] [pid 559070:tid 559258] [client 212.32.76.4:38597] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/upload.php"] [unique_id "al9eASy1f1FtKC137xv4YQAAAck"]
[Tue Jul 21 08:54:41.708571 2026] [security2:error] [pid 559070:tid 559299] [client 20.151.10.161:45940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/footer.php"] [unique_id "al9eASy1f1FtKC137xv4YgAAAfI"]
[Tue Jul 21 08:54:41.731762 2026] [security2:error] [pid 559070:tid 559225] [client 20.151.10.161:52213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/8.php"] [unique_id "al9eASy1f1FtKC137xv4YwAAAag"]
[Tue Jul 21 08:54:42.131032 2026] [autoindex:error] [pid 559070:tid 559256] [client 20.151.10.161:46033] AH01276: Cannot serve directory /home3/housei59/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:54:42.190300 2026] [security2:error] [pid 559070:tid 559208] [client 20.151.10.161:52192] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/1.php"] [unique_id "al9eAiy1f1FtKC137xv4bAAAAZc"]
[Tue Jul 21 08:54:42.190426 2026] [security2:error] [pid 559070:tid 559208] [client 20.151.10.161:52192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/1.php"] [unique_id "al9eAiy1f1FtKC137xv4bAAAAZc"]
[Tue Jul 21 08:54:42.432737 2026] [security2:error] [pid 559070:tid 559268] [client 20.151.10.161:46033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-content/index.php"] [unique_id "al9eAiy1f1FtKC137xv4cgAAAdM"]
[Tue Jul 21 08:54:42.636900 2026] [security2:error] [pid 559070:tid 559270] [client 203.25.124.64:37561] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "al9eAiy1f1FtKC137xv4dgAAAdU"]
[Tue Jul 21 08:54:42.990326 2026] [security2:error] [pid 559070:tid 559197] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eAiy1f1FtKC137xv4fgABj34"]
[Tue Jul 21 08:54:42.990476 2026] [security2:error] [pid 559070:tid 559200] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eAiy1f1FtKC137xv4fgABj34"]
[Tue Jul 21 08:54:43.052142 2026] [security2:error] [pid 559070:tid 559250] [client 20.151.10.161:46053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/zoro.php"] [unique_id "al9eAyy1f1FtKC137xv4fwAAAcE"]
[Tue Jul 21 08:54:43.054519 2026] [security2:error] [pid 533360:tid 533561] [client 20.151.10.161:52099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/100.php"] [unique_id "al9eA3UPuLYrePtEkUciZAAAAMk"]
[Tue Jul 21 08:54:43.066706 2026] [security2:error] [pid 533360:tid 533619] [client 20.151.10.161:55836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ccs.php"] [unique_id "al9eA3UPuLYrePtEkUciZgAAAQM"]
[Tue Jul 21 08:54:43.191455 2026] [security2:error] [pid 559070:tid 559312] [client 20.197.192.193:50602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/ops.php"] [unique_id "al9eAyy1f1FtKC137xv4gQAAAf8"]
[Tue Jul 21 08:54:43.390286 2026] [security2:error] [pid 559070:tid 559269] [client 113.22.144.139:51631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eAyy1f1FtKC137xv4hwAAAdQ"]
[Tue Jul 21 08:54:43.391082 2026] [security2:error] [pid 559070:tid 559269] [client 113.22.144.139:51631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eAyy1f1FtKC137xv4hwAAAdQ"]
[Tue Jul 21 08:54:43.472501 2026] [security2:error] [pid 559070:tid 559248] [client 20.151.10.161:46069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/admin.php"] [unique_id "al9eAyy1f1FtKC137xv4igAAAb8"]
[Tue Jul 21 08:54:43.549126 2026] [security2:error] [pid 533360:tid 533508] [client 20.220.225.223:19268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/ms.php"] [unique_id "al9eA3UPuLYrePtEkUcicwAAAJQ"]
[Tue Jul 21 08:54:43.575641 2026] [security2:error] [pid 533360:tid 533470] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eA3UPuLYrePtEkUcidAAAnWo"]
[Tue Jul 21 08:54:43.575759 2026] [security2:error] [pid 533360:tid 533517] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eA3UPuLYrePtEkUcidAAAnWo"]
[Tue Jul 21 08:54:43.649743 2026] [security2:error] [pid 533360:tid 533608] [client 203.25.124.66:55163] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/buy.php"] [unique_id "al9eA3UPuLYrePtEkUcidQAAAPg"]
[Tue Jul 21 08:54:43.728851 2026] [security2:error] [pid 559070:tid 559313] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eAyy1f1FtKC137xv4jgACAHs"]
[Tue Jul 21 08:54:43.803565 2026] [security2:error] [pid 559070:tid 559225] [client 20.151.10.161:37767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/about.php"] [unique_id "al9eAyy1f1FtKC137xv4jwAAAag"]
[Tue Jul 21 08:54:44.062203 2026] [security2:error] [pid 533360:tid 533617] [client 20.220.225.223:52245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/blue.php"] [unique_id "al9eBHUPuLYrePtEkUcilAAAAQE"]
[Tue Jul 21 08:54:44.235257 2026] [security2:error] [pid 559070:tid 559289] [client 20.220.225.223:60279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/ez.php"] [unique_id "al9eBCy1f1FtKC137xv4lwAAAeg"]
[Tue Jul 21 08:54:44.300062 2026] [security2:error] [pid 559070:tid 559233] [client 20.151.10.161:45994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/greap.php"] [unique_id "al9eBCy1f1FtKC137xv4mAAAAbA"]
[Tue Jul 21 08:54:44.302051 2026] [security2:error] [pid 533360:tid 533541] [client 65.21.113.253:49112] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eBHUPuLYrePtEkUcivQAAALU"]
[Tue Jul 21 08:54:44.549517 2026] [security2:error] [pid 559070:tid 559317] [client 20.52.136.55:1735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9eBCy1f1FtKC137xv4ogAAAgQ"]
[Tue Jul 21 08:54:44.729638 2026] [security2:error] [pid 559070:tid 559313] [client 20.151.10.161:37824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/admin.php"] [unique_id "al9eBCy1f1FtKC137xv4pQAAAgA"]
[Tue Jul 21 08:54:44.742666 2026] [security2:error] [pid 533360:tid 533536] [client 203.25.124.213:51129] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/zgbrarc/cong.php"] [unique_id "al9eBHUPuLYrePtEkUci1wAAALA"]
[Tue Jul 21 08:54:44.874205 2026] [security2:error] [pid 559070:tid 559225] [client 20.151.10.161:45895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/177.php"] [unique_id "al9eBCy1f1FtKC137xv4qgAAAag"]
[Tue Jul 21 08:54:45.031152 2026] [security2:error] [pid 559070:tid 559205] [client 41.89.234.2:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eBSy1f1FtKC137xv4tQAAAZQ"]
[Tue Jul 21 08:54:45.031318 2026] [security2:error] [pid 559070:tid 559205] [client 41.89.234.2:52822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eBSy1f1FtKC137xv4tQAAAZQ"]
[Tue Jul 21 08:54:45.297304 2026] [security2:error] [pid 533360:tid 533539] [client 5.38.115.39:45880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eBXUPuLYrePtEkUci5wAAALM"]
[Tue Jul 21 08:54:45.297499 2026] [security2:error] [pid 533360:tid 533539] [client 5.38.115.39:45880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eBXUPuLYrePtEkUci5wAAALM"]
[Tue Jul 21 08:54:45.417153 2026] [security2:error] [pid 533360:tid 533513] [client 65.21.113.253:43662] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eBHUPuLYrePtEkUci4gAAAJk"]
[Tue Jul 21 08:54:45.503338 2026] [proxy:error] [pid 559070:tid 559274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:45.503392 2026] [proxy_http:error] [pid 559070:tid 559274] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:45.503904 2026] [proxy:error] [pid 559070:tid 559274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:45.503929 2026] [proxy_http:error] [pid 559070:tid 559274] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:45.510940 2026] [security2:error] [pid 559070:tid 559247] [client 20.151.10.161:52127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/edit.php"] [unique_id "al9eBSy1f1FtKC137xv4vwAAAb4"]
[Tue Jul 21 08:54:45.541904 2026] [security2:error] [pid 559070:tid 559296] [client 182.189.99.211:48164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eBSy1f1FtKC137xv4wAAAAe8"]
[Tue Jul 21 08:54:45.541981 2026] [security2:error] [pid 559070:tid 559296] [client 182.189.99.211:48164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eBSy1f1FtKC137xv4wAAAAe8"]
[Tue Jul 21 08:54:45.571340 2026] [security2:error] [pid 559070:tid 559322] [client 20.151.10.161:46004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/199.php"] [unique_id "al9eBSy1f1FtKC137xv4wQAAAgk"]
[Tue Jul 21 08:54:45.596953 2026] [security2:error] [pid 533360:tid 533441] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eBXUPuLYrePtEkUci7gAArE0"]
[Tue Jul 21 08:54:45.597127 2026] [security2:error] [pid 533360:tid 533532] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eBXUPuLYrePtEkUci7gAArE0"]
[Tue Jul 21 08:54:45.747510 2026] [security2:error] [pid 559070:tid 559291] [client 203.25.124.48:50771] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9eBSy1f1FtKC137xv4wwAAAeo"]
[Tue Jul 21 08:54:45.786775 2026] [security2:error] [pid 559070:tid 559238] [client 172.233.211.105:9562] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "ns1103.hostgator.com.br"] [uri "/"] [unique_id "al9eBSy1f1FtKC137xv4xwAAAbU"]
[Tue Jul 21 08:54:45.875954 2026] [proxy:error] [pid 559070:tid 559237] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:45.876018 2026] [proxy_http:error] [pid 559070:tid 559237] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:45.876614 2026] [proxy:error] [pid 559070:tid 559237] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:45.876640 2026] [proxy_http:error] [pid 559070:tid 559237] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:46.023933 2026] [security2:error] [pid 559070:tid 559312] [client 20.151.10.161:52134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-content/admin.php"] [unique_id "al9eBiy1f1FtKC137xv40gAAAf8"]
[Tue Jul 21 08:54:46.313008 2026] [proxy:error] [pid 559070:tid 559206] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:46.313116 2026] [proxy_http:error] [pid 559070:tid 559206] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:46.315542 2026] [proxy:error] [pid 559070:tid 559206] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:46.315631 2026] [proxy_http:error] [pid 559070:tid 559206] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:46.323459 2026] [security2:error] [pid 533360:tid 533495] [client 20.151.10.161:45967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/file52.php"] [unique_id "al9eBnUPuLYrePtEkUci9wAAAIc"]
[Tue Jul 21 08:54:46.422958 2026] [security2:error] [pid 559070:tid 559123] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlinebuyerwebsite.com"] [uri "/wp-admin/install.php"] [unique_id "al9eBiy1f1FtKC137xv42QABsDQ"]
[Tue Jul 21 08:54:46.610897 2026] [security2:error] [pid 559070:tid 559073] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eBiy1f1FtKC137xv44QAB4AI"]
[Tue Jul 21 08:54:46.611101 2026] [security2:error] [pid 559070:tid 559281] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eBiy1f1FtKC137xv44QAB4AI"]
[Tue Jul 21 08:54:46.640883 2026] [security2:error] [pid 559070:tid 559217] [client 20.151.10.161:52207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/f6.php"] [unique_id "al9eBiy1f1FtKC137xv44gAAAaA"]
[Tue Jul 21 08:54:46.734602 2026] [security2:error] [pid 533360:tid 533557] [client 203.25.124.54:33645] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/customize/wp-conflg.php"] [unique_id "al9eBnUPuLYrePtEkUci_wAAAMU"]
[Tue Jul 21 08:54:46.749469 2026] [security2:error] [pid 533360:tid 533530] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eBnUPuLYrePtEkUcjAAAAAKo"]
[Tue Jul 21 08:54:46.754137 2026] [security2:error] [pid 533360:tid 533603] [client 216.244.66.229:34742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "megaroteiros.com.br"] [uri "/robots.txt"] [unique_id "al9eBnUPuLYrePtEkUcjAQAAAPM"]
[Tue Jul 21 08:54:46.754264 2026] [security2:error] [pid 533360:tid 533603] [client 216.244.66.229:34742] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "megaroteiros.com.br"] [uri "/robots.txt"] [unique_id "al9eBnUPuLYrePtEkUcjAQAAAPM"]
[Tue Jul 21 08:54:46.755079 2026] [security2:error] [pid 559070:tid 559261] [client 20.151.10.161:55826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ccc.php"] [unique_id "al9eBiy1f1FtKC137xv44wAAAcw"]
[Tue Jul 21 08:54:46.819934 2026] [security2:error] [pid 559070:tid 559276] [client 20.197.192.193:56800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/term.php"] [unique_id "al9eBiy1f1FtKC137xv45AAAAds"]
[Tue Jul 21 08:54:46.838445 2026] [security2:error] [pid 533360:tid 533520] [client 103.59.206.240:31147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eBnUPuLYrePtEkUcjAwAAAKA"]
[Tue Jul 21 08:54:46.838589 2026] [security2:error] [pid 533360:tid 533520] [client 103.59.206.240:31147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eBnUPuLYrePtEkUcjAwAAAKA"]
[Tue Jul 21 08:54:46.927588 2026] [security2:error] [pid 559070:tid 559090] [remote 185.241.208.244:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.208.241.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "onlinebuyerwebsite.com"] [uri "/wp-admin/setup-config.php"] [unique_id "al9eBiy1f1FtKC137xv45gAB0xM"]
[Tue Jul 21 08:54:47.220642 2026] [security2:error] [pid 559070:tid 559250] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9eByy1f1FtKC137xv47QAAAcE"]
[Tue Jul 21 08:54:47.291548 2026] [security2:error] [pid 533360:tid 533565] [client 20.220.225.223:48216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/koiy.php"] [unique_id "al9eB3UPuLYrePtEkUcjEAAAAM0"]
[Tue Jul 21 08:54:47.403054 2026] [security2:error] [pid 533360:tid 533610] [client 74.7.241.145:36738] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mcstiloimoveis.com.br"] [uri "/index.php"] [unique_id "al9eBnUPuLYrePtEkUci-QAA-k8"]
[Tue Jul 21 08:54:47.465311 2026] [security2:error] [pid 559070:tid 559289] [client 128.127.105.184:41654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9eByy1f1FtKC137xv47wAAAeg"]
[Tue Jul 21 08:54:47.465401 2026] [security2:error] [pid 559070:tid 559289] [client 128.127.105.184:41654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9eByy1f1FtKC137xv47wAAAeg"]
[Tue Jul 21 08:54:47.501276 2026] [security2:error] [pid 559070:tid 559100] [remote 124.55.178.99:53988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "casaejardimperfeito.com.br.lirioshoppy.com.br"] [uri "/wp-login.php"] [unique_id "al9eByy1f1FtKC137xv48QABxx0"]
[Tue Jul 21 08:54:47.511077 2026] [security2:error] [pid 559070:tid 559288] [client 20.151.10.161:46068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/122.php"] [unique_id "al9eByy1f1FtKC137xv48gAAAec"]
[Tue Jul 21 08:54:47.714103 2026] [security2:error] [pid 559070:tid 559230] [client 20.151.10.161:37867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/inputs.php"] [unique_id "al9eByy1f1FtKC137xv49QAAAa0"]
[Tue Jul 21 08:54:47.715237 2026] [security2:error] [pid 559070:tid 559223] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9eByy1f1FtKC137xv49gAAAaY"]
[Tue Jul 21 08:54:47.741146 2026] [security2:error] [pid 559070:tid 559291] [client 203.25.124.65:47187] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/themes.php"] [unique_id "al9eByy1f1FtKC137xv49wAAAeo"]
[Tue Jul 21 08:54:47.871179 2026] [security2:error] [pid 559070:tid 559293] [client 20.104.96.117:7953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9eByy1f1FtKC137xv4-QAAAew"]
[Tue Jul 21 08:54:48.306042 2026] [security2:error] [pid 533360:tid 533558] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9eCHUPuLYrePtEkUcjKAAAAMY"]
[Tue Jul 21 08:54:48.375413 2026] [security2:error] [pid 559070:tid 559317] [client 20.151.10.161:37874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/av.php"] [unique_id "al9eCCy1f1FtKC137xv4_wAAAgQ"]
[Tue Jul 21 08:54:48.378883 2026] [security2:error] [pid 559070:tid 559208] [client 20.197.192.193:50563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/ah25.php"] [unique_id "al9eCCy1f1FtKC137xv5AAAAAZc"]
[Tue Jul 21 08:54:48.525967 2026] [security2:error] [pid 533360:tid 533511] [client 65.21.113.253:49112] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eCHUPuLYrePtEkUcjLQAAAJc"]
[Tue Jul 21 08:54:48.553216 2026] [security2:error] [pid 533360:tid 533495] [client 20.151.10.161:46000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/green1.php"] [unique_id "al9eCHUPuLYrePtEkUcjLgAAAIc"]
[Tue Jul 21 08:54:48.592185 2026] [security2:error] [pid 559070:tid 559114] [remote 72.167.132.114:41506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "odontoclinicms.com.br"] [uri "/wp-login.php"] [unique_id "al9eCCy1f1FtKC137xv5CAABnCs"]
[Tue Jul 21 08:54:48.657087 2026] [security2:error] [pid 559070:tid 559281] [client 59.95.197.55:50244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eCCy1f1FtKC137xv5CwAAAeA"]
[Tue Jul 21 08:54:48.657183 2026] [security2:error] [pid 559070:tid 559281] [client 59.95.197.55:50244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eCCy1f1FtKC137xv5CwAAAeA"]
[Tue Jul 21 08:54:48.686371 2026] [security2:error] [pid 559070:tid 559253] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9eCCy1f1FtKC137xv5DwAAAcQ"]
[Tue Jul 21 08:54:48.840700 2026] [security2:error] [pid 533360:tid 533619] [client 20.151.10.161:52120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/classwithtostring.php"] [unique_id "al9eCHUPuLYrePtEkUcjMwAAAQM"]
[Tue Jul 21 08:54:48.893963 2026] [security2:error] [pid 559070:tid 559128] [remote 167.71.218.184:36724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9eCCy1f1FtKC137xv5EwABljk"]
[Tue Jul 21 08:54:48.894134 2026] [security2:error] [pid 559070:tid 559207] [client 167.71.218.184:36724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9eCCy1f1FtKC137xv5EwABljk"]
[Tue Jul 21 08:54:49.004130 2026] [security2:error] [pid 559070:tid 559303] [client 20.104.96.117:7997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9eCSy1f1FtKC137xv5FwAAAfY"]
[Tue Jul 21 08:54:49.037845 2026] [security2:error] [pid 559070:tid 559313] [client 203.25.124.64:59847] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/fmadmin.php"] [unique_id "al9eCSy1f1FtKC137xv5GwAAAgA"]
[Tue Jul 21 08:54:49.168889 2026] [security2:error] [pid 559070:tid 559300] [client 20.151.10.161:52152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9eCSy1f1FtKC137xv5HgAAAfM"]
[Tue Jul 21 08:54:49.226375 2026] [security2:error] [pid 559070:tid 559184] [remote 119.195.102.159:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.102.195.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dener.design"] [uri "/wp-login.php"] [unique_id "al9eCSy1f1FtKC137xv5HwACCXE"]
[Tue Jul 21 08:54:49.237571 2026] [security2:error] [pid 533360:tid 533597] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9eCXUPuLYrePtEkUcjQAAAAO0"]
[Tue Jul 21 08:54:49.249340 2026] [security2:error] [pid 559070:tid 559312] [client 20.151.10.161:51014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/get.php"] [unique_id "al9eCSy1f1FtKC137xv5IQAAAf8"]
[Tue Jul 21 08:54:49.470916 2026] [security2:error] [pid 533360:tid 533528] [client 20.52.136.55:1581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/wp.php"] [unique_id "al9eCXUPuLYrePtEkUcjRAAAAKg"]
[Tue Jul 21 08:54:49.473714 2026] [security2:error] [pid 559070:tid 559299] [client 20.151.10.161:37840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-blog.php"] [unique_id "al9eCSy1f1FtKC137xv5JQAAAfI"]
[Tue Jul 21 08:54:49.556063 2026] [security2:error] [pid 559070:tid 559314] [client 168.167.81.163:60836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eCSy1f1FtKC137xv5KAAAAgE"]
[Tue Jul 21 08:54:49.556201 2026] [security2:error] [pid 559070:tid 559314] [client 168.167.81.163:60836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eCSy1f1FtKC137xv5KAAAAgE"]
[Tue Jul 21 08:54:49.616857 2026] [security2:error] [pid 559070:tid 559213] [client 173.252.95.30:34518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eCSy1f1FtKC137xv5KgAAAZw"]
[Tue Jul 21 08:54:49.643690 2026] [security2:error] [pid 559070:tid 559200] [client 54.39.203.7:38920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "rqracademy.com"] [uri "/robots.txt"] [unique_id "al9eCSy1f1FtKC137xv5LAAAAY8"]
[Tue Jul 21 08:54:49.643772 2026] [security2:error] [pid 559070:tid 559200] [client 54.39.203.7:38920] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "rqracademy.com"] [uri "/robots.txt"] [unique_id "al9eCSy1f1FtKC137xv5LAAAAY8"]
[Tue Jul 21 08:54:49.647992 2026] [security2:error] [pid 533360:tid 533603] [client 65.21.113.253:43668] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eCXUPuLYrePtEkUcjOgAAAPM"]
[Tue Jul 21 08:54:49.655879 2026] [security2:error] [pid 559070:tid 559243] [client 20.220.225.223:48255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/hp2.php"] [unique_id "al9eCSy1f1FtKC137xv5LQAAAbo"]
[Tue Jul 21 08:54:49.740984 2026] [security2:error] [pid 533360:tid 533620] [client 203.25.124.52:56011] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/class.api.php"] [unique_id "al9eCXUPuLYrePtEkUcjTAAAAQQ"]
[Tue Jul 21 08:54:49.797550 2026] [security2:error] [pid 559070:tid 559207] [client 20.151.10.161:46071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/biufile.php"] [unique_id "al9eCSy1f1FtKC137xv5LgAAAZY"]
[Tue Jul 21 08:54:49.818260 2026] [proxy:error] [pid 559070:tid 559276] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:49.818313 2026] [proxy_http:error] [pid 559070:tid 559276] [client 20.151.10.161:52195] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:49.818906 2026] [proxy:error] [pid 559070:tid 559276] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:49.818930 2026] [proxy_http:error] [pid 559070:tid 559276] [client 20.151.10.161:52195] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:49.832802 2026] [security2:error] [pid 559070:tid 559292] [client 20.104.96.117:7571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/media.php"] [unique_id "al9eCSy1f1FtKC137xv5MAAAAes"]
[Tue Jul 21 08:54:49.853713 2026] [security2:error] [pid 559070:tid 559204] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9eCSy1f1FtKC137xv5MQAAAZM"]
[Tue Jul 21 08:54:50.121177 2026] [security2:error] [pid 559070:tid 559210] [client 20.151.10.161:37864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-content/admin.php"] [unique_id "al9eCiy1f1FtKC137xv5NAAAAZk"]
[Tue Jul 21 08:54:50.370254 2026] [security2:error] [pid 559070:tid 559289] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9eCiy1f1FtKC137xv5OgAAAeg"]
[Tue Jul 21 08:54:50.395437 2026] [security2:error] [pid 533360:tid 533588] [client 20.197.192.193:27171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/hp2.php"] [unique_id "al9eCnUPuLYrePtEkUcjWQAAAOQ"]
[Tue Jul 21 08:54:50.420136 2026] [security2:error] [pid 533360:tid 533511] [client 20.151.10.161:52204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/adminfuns.php"] [unique_id "al9eCnUPuLYrePtEkUcjWgAAAJc"]
[Tue Jul 21 08:54:50.627825 2026] [security2:error] [pid 559070:tid 559256] [client 114.198.138.124:62439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eCiy1f1FtKC137xv5PAAAAcc"]
[Tue Jul 21 08:54:50.627969 2026] [security2:error] [pid 559070:tid 559256] [client 114.198.138.124:62439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eCiy1f1FtKC137xv5PAAAAcc"]
[Tue Jul 21 08:54:50.639992 2026] [security2:error] [pid 559070:tid 559213] [client 20.104.96.117:7973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/images.php"] [unique_id "al9eCiy1f1FtKC137xv5PwAAAZw"]
[Tue Jul 21 08:54:50.746535 2026] [security2:error] [pid 533360:tid 533619] [client 203.25.124.212:58055] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/ID3/index.php"] [unique_id "al9eCnUPuLYrePtEkUcjYAAAAQM"]
[Tue Jul 21 08:54:50.748315 2026] [security2:error] [pid 559070:tid 559281] [client 20.151.10.161:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/goods.php"] [unique_id "al9eCiy1f1FtKC137xv5RAAAAeA"]
[Tue Jul 21 08:54:50.860211 2026] [security2:error] [pid 559070:tid 559218] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9eCiy1f1FtKC137xv5RwAAAaE"]
[Tue Jul 21 08:54:51.094393 2026] [security2:error] [pid 559070:tid 559250] [client 20.151.10.161:37886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/ms-edit.php"] [unique_id "al9eCyy1f1FtKC137xv5bAAAAcE"]
[Tue Jul 21 08:54:51.156408 2026] [security2:error] [pid 559070:tid 559107] [remote 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9eCyy1f1FtKC137xv5bgABniQ"]
[Tue Jul 21 08:54:51.156537 2026] [security2:error] [pid 559070:tid 559215] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9eCyy1f1FtKC137xv5bgABniQ"]
[Tue Jul 21 08:54:51.269115 2026] [security2:error] [pid 533360:tid 533575] [client 15.235.98.14:42174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "rqracademy.com"] [uri "/"] [unique_id "al9eC3UPuLYrePtEkUcjaAAAANc"]
[Tue Jul 21 08:54:51.269318 2026] [security2:error] [pid 533360:tid 533575] [client 15.235.98.14:42174] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "rqracademy.com"] [uri "/"] [unique_id "al9eC3UPuLYrePtEkUcjaAAAANc"]
[Tue Jul 21 08:54:51.283949 2026] [security2:error] [pid 559070:tid 559320] [client 20.151.10.161:55861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/images.php"] [unique_id "al9eCyy1f1FtKC137xv5cwAAAgc"]
[Tue Jul 21 08:54:51.314898 2026] [security2:error] [pid 559070:tid 559252] [client 20.151.10.161:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wpconf.php"] [unique_id "al9eCyy1f1FtKC137xv5dAAAAcM"]
[Tue Jul 21 08:54:51.319196 2026] [security2:error] [pid 559070:tid 559289] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9eCyy1f1FtKC137xv5dQAAAeg"]
[Tue Jul 21 08:54:51.389391 2026] [security2:error] [pid 559070:tid 559256] [client 20.151.10.161:52129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/222.php"] [unique_id "al9eCyy1f1FtKC137xv5eAAAAcc"]
[Tue Jul 21 08:54:51.474151 2026] [security2:error] [pid 559070:tid 559243] [client 20.104.96.117:7582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/gecko.php"] [unique_id "al9eCyy1f1FtKC137xv5fAAAAbo"]
[Tue Jul 21 08:54:51.669681 2026] [security2:error] [pid 559070:tid 559282] [client 20.151.10.161:52216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/cgi-bin/index.php"] [unique_id "al9eCyy1f1FtKC137xv5hAAAAeE"]
[Tue Jul 21 08:54:51.692168 2026] [security2:error] [pid 559070:tid 559202] [client 20.197.192.193:27137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/hp3.php"] [unique_id "al9eCyy1f1FtKC137xv5hQAAAZE"]
[Tue Jul 21 08:54:51.719374 2026] [security2:error] [pid 559070:tid 559313] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9eCyy1f1FtKC137xv5hgAAAgA"]
[Tue Jul 21 08:54:51.818933 2026] [security2:error] [pid 559070:tid 559300] [client 20.151.10.161:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/FAQ.php"] [unique_id "al9eCyy1f1FtKC137xv5igAAAfM"]
[Tue Jul 21 08:54:51.836367 2026] [security2:error] [pid 559070:tid 559249] [client 203.25.124.215:47525] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/includes/index.php"] [unique_id "al9eCyy1f1FtKC137xv5iwAAAcA"]
[Tue Jul 21 08:54:51.970491 2026] [proxy:error] [pid 559070:tid 559203] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:51.970571 2026] [proxy_http:error] [pid 559070:tid 559203] [client 20.151.10.161:37835] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:51.971273 2026] [proxy:error] [pid 559070:tid 559203] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:51.971369 2026] [proxy_http:error] [pid 559070:tid 559203] [client 20.151.10.161:37835] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:52.018313 2026] [security2:error] [pid 559070:tid 559278] [client 20.220.225.223:58923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/wp-signup.php"] [unique_id "al9eDCy1f1FtKC137xv5lQAAAd0"]
[Tue Jul 21 08:54:52.113465 2026] [security2:error] [pid 533360:tid 533549] [client 20.104.96.117:7581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/82.php"] [unique_id "al9eDHUPuLYrePtEkUcjhAAAAL0"]
[Tue Jul 21 08:54:52.125379 2026] [security2:error] [pid 559070:tid 559218] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9eDCy1f1FtKC137xv5lgAAAaE"]
[Tue Jul 21 08:54:52.345115 2026] [security2:error] [pid 533360:tid 533606] [client 20.151.10.161:52164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/BDKR28WP.php"] [unique_id "al9eDHUPuLYrePtEkUcjiQAAAPY"]
[Tue Jul 21 08:54:52.553307 2026] [security2:error] [pid 559070:tid 559312] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.franciscaadrianasouz1747421050940.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9eDCy1f1FtKC137xv5nAAAAf8"]
[Tue Jul 21 08:54:52.632616 2026] [proxy:error] [pid 533360:tid 533592] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:52.632696 2026] [proxy_http:error] [pid 533360:tid 533592] [client 20.151.10.161:52122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:52.633330 2026] [proxy:error] [pid 533360:tid 533592] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:52.633378 2026] [proxy_http:error] [pid 533360:tid 533592] [client 20.151.10.161:52122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:52.675328 2026] [security2:error] [pid 559070:tid 559300] [client 20.151.10.161:51065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/alls.php"] [unique_id "al9eDCy1f1FtKC137xv5ngAAAfM"]
[Tue Jul 21 08:54:52.742554 2026] [security2:error] [pid 559070:tid 559249] [client 203.25.124.54:38039] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/index.php"] [unique_id "al9eDCy1f1FtKC137xv5oAAAAcA"]
[Tue Jul 21 08:54:52.958912 2026] [proxy:error] [pid 559070:tid 559200] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:52.958981 2026] [proxy_http:error] [pid 559070:tid 559200] [client 20.151.10.161:52138] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:52.959512 2026] [proxy:error] [pid 559070:tid 559200] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:52.959537 2026] [proxy_http:error] [pid 559070:tid 559200] [client 20.151.10.161:52138] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:53.102182 2026] [security2:error] [pid 533360:tid 533540] [client 20.104.96.117:7580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/admin.php"] [unique_id "al9eDXUPuLYrePtEkUcjlwAAALQ"]
[Tue Jul 21 08:54:53.178786 2026] [security2:error] [pid 533360:tid 533581] [client 65.21.113.253:49112] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eDXUPuLYrePtEkUcjmAAAAN0"]
[Tue Jul 21 08:54:53.241951 2026] [security2:error] [pid 559070:tid 559261] [client 20.151.10.161:37788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp.php"] [unique_id "al9eDSy1f1FtKC137xv5qgAAAcw"]
[Tue Jul 21 08:54:53.289790 2026] [security2:error] [pid 533360:tid 533418] [remote 91.142.222.105:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deiacakes.com"] [uri "/wp-login.php"] [unique_id "al9eDXUPuLYrePtEkUcjnAABAzY"]
[Tue Jul 21 08:54:53.298348 2026] [security2:error] [pid 533360:tid 533579] [client 20.151.10.161:45968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/mosty.php"] [unique_id "al9eDXUPuLYrePtEkUcjnQAAANs"]
[Tue Jul 21 08:54:53.341147 2026] [security2:error] [pid 559070:tid 559083] [remote 91.142.222.105:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/wp-login.php"] [unique_id "al9eDSy1f1FtKC137xv5qwACAQw"]
[Tue Jul 21 08:54:53.382013 2026] [security2:error] [pid 559070:tid 559114] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eDSy1f1FtKC137xv5rAAB2ys"]
[Tue Jul 21 08:54:53.382202 2026] [security2:error] [pid 559070:tid 559276] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eDSy1f1FtKC137xv5rAAB2ys"]
[Tue Jul 21 08:54:53.556380 2026] [security2:error] [pid 559070:tid 559202] [client 20.151.10.161:52172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/abcd.php"] [unique_id "al9eDSy1f1FtKC137xv5sgAAAZE"]
[Tue Jul 21 08:54:53.750537 2026] [security2:error] [pid 559070:tid 559258] [client 212.32.76.4:25943] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/assets/index.php"] [unique_id "al9eDSy1f1FtKC137xv5twAAAck"]
[Tue Jul 21 08:54:53.857231 2026] [security2:error] [pid 559070:tid 559206] [client 20.151.10.161:52119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/a1.php"] [unique_id "al9eDSy1f1FtKC137xv5vgAAAZU"]
[Tue Jul 21 08:54:53.879657 2026] [rewrite:warn] [pid 533360:tid 533483] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:54:53.982096 2026] [security2:error] [pid 559070:tid 559261] [client 20.104.96.117:7553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/adminner.php"] [unique_id "al9eDSy1f1FtKC137xv50AAAAcw"]
[Tue Jul 21 08:54:54.073561 2026] [security2:error] [pid 559070:tid 559290] [client 20.151.10.161:55849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/yyu.php"] [unique_id "al9eDiy1f1FtKC137xv54QAAAek"]
[Tue Jul 21 08:54:54.155775 2026] [security2:error] [pid 559070:tid 559219] [client 20.151.10.161:46060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/dejavu.php"] [unique_id "al9eDiy1f1FtKC137xv56wAAAaI"]
[Tue Jul 21 08:54:54.244930 2026] [security2:error] [pid 559070:tid 559249] [client 20.151.10.161:37861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9eDiy1f1FtKC137xv5_gAAAcA"]
[Tue Jul 21 08:54:54.251277 2026] [security2:error] [pid 533360:tid 533618] [client 65.21.113.253:43246] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eDXUPuLYrePtEkUcjqAAAAQI"]
[Tue Jul 21 08:54:54.408433 2026] [security2:error] [pid 533360:tid 533541] [client 113.22.144.139:52163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eDnUPuLYrePtEkUcjswAAALU"]
[Tue Jul 21 08:54:54.408543 2026] [security2:error] [pid 533360:tid 533541] [client 113.22.144.139:52163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eDnUPuLYrePtEkUcjswAAALU"]
[Tue Jul 21 08:54:54.423656 2026] [security2:error] [pid 559070:tid 559173] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eDiy1f1FtKC137xv6FAABlmY"]
[Tue Jul 21 08:54:54.423765 2026] [security2:error] [pid 559070:tid 559207] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eDiy1f1FtKC137xv6FAABlmY"]
[Tue Jul 21 08:54:54.618571 2026] [security2:error] [pid 559070:tid 559321] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eDiy1f1FtKC137xv6HwACCCk"]
[Tue Jul 21 08:54:54.633559 2026] [proxy:error] [pid 559070:tid 559270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:54.633637 2026] [proxy_http:error] [pid 559070:tid 559270] [client 20.151.10.161:37848] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:54.634216 2026] [proxy:error] [pid 559070:tid 559270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:54.634245 2026] [proxy_http:error] [pid 559070:tid 559270] [client 20.151.10.161:37848] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:54.648573 2026] [security2:error] [pid 559070:tid 559211] [client 20.151.10.161:45957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/aaf.php"] [unique_id "al9eDiy1f1FtKC137xv6LgAAAZo"]
[Tue Jul 21 08:54:54.827921 2026] [security2:error] [pid 559070:tid 559195] [remote 124.55.178.99:50752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9eDiy1f1FtKC137xv6OAABl3w"]
[Tue Jul 21 08:54:54.828074 2026] [security2:error] [pid 559070:tid 559208] [client 124.55.178.99:50752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "projetoflechas.org.br"] [uri "/xmlrpc.php"] [unique_id "al9eDiy1f1FtKC137xv6OAABl3w"]
[Tue Jul 21 08:54:54.854680 2026] [security2:error] [pid 559070:tid 559300] [client 20.104.96.117:7954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/admin.php"] [unique_id "al9eDiy1f1FtKC137xv6OQAAAfM"]
[Tue Jul 21 08:54:54.918745 2026] [proxy:error] [pid 559070:tid 559203] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:54.918840 2026] [proxy_http:error] [pid 559070:tid 559203] [client 20.151.10.161:52103] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:54.919607 2026] [proxy:error] [pid 559070:tid 559203] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:54.919632 2026] [proxy_http:error] [pid 559070:tid 559203] [client 20.151.10.161:52103] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:54.995624 2026] [security2:error] [pid 559070:tid 559278] [client 20.220.225.223:52628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/csa.php"] [unique_id "al9eDiy1f1FtKC137xv6SQAAAd0"]
[Tue Jul 21 08:54:55.131126 2026] [security2:error] [pid 559070:tid 559218] [client 203.25.124.66:29361] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/news-portal/error.php"] [unique_id "al9eDyy1f1FtKC137xv6UgAAAaE"]
[Tue Jul 21 08:54:55.165640 2026] [security2:error] [pid 533360:tid 533505] [client 20.151.10.161:45954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/term.php"] [unique_id "al9eD3UPuLYrePtEkUcjxAAAAJE"]
[Tue Jul 21 08:54:55.187467 2026] [security2:error] [pid 559070:tid 559253] [client 198.44.157.162:37560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9eDyy1f1FtKC137xv6VgAAAcQ"]
[Tue Jul 21 08:54:55.187536 2026] [security2:error] [pid 559070:tid 559253] [client 198.44.157.162:37560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9eDyy1f1FtKC137xv6VgAAAcQ"]
[Tue Jul 21 08:54:55.495622 2026] [proxy:error] [pid 559070:tid 559204] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:55.495677 2026] [proxy_http:error] [pid 559070:tid 559204] [client 20.151.10.161:52137] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:55.496114 2026] [proxy:error] [pid 559070:tid 559204] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:55.496137 2026] [proxy_http:error] [pid 559070:tid 559204] [client 20.151.10.161:52137] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:55.520515 2026] [security2:error] [pid 559070:tid 559245] [client 41.89.234.2:7047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eDyy1f1FtKC137xv6gAAAAbw"]
[Tue Jul 21 08:54:55.520623 2026] [security2:error] [pid 559070:tid 559245] [client 41.89.234.2:7047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eDyy1f1FtKC137xv6gAAAAbw"]
[Tue Jul 21 08:54:55.558766 2026] [security2:error] [pid 533360:tid 533523] [client 20.104.96.117:7946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/k.php"] [unique_id "al9eD3UPuLYrePtEkUcj1gAAAKM"]
[Tue Jul 21 08:54:55.636978 2026] [security2:error] [pid 559070:tid 559324] [client 194.99.104.35:59934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9eDyy1f1FtKC137xv6hgAAAgs"]
[Tue Jul 21 08:54:55.637067 2026] [security2:error] [pid 559070:tid 559324] [client 194.99.104.35:59934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9eDyy1f1FtKC137xv6hgAAAgs"]
[Tue Jul 21 08:54:55.689223 2026] [security2:error] [pid 559070:tid 559253] [client 20.151.10.161:46022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/ha.php"] [unique_id "al9eDyy1f1FtKC137xv6iAAAAcQ"]
[Tue Jul 21 08:54:55.845006 2026] [security2:error] [pid 533360:tid 533591] [client 20.151.10.161:37877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9eD3UPuLYrePtEkUcj3AAAAOc"]
[Tue Jul 21 08:54:55.954751 2026] [security2:error] [pid 533360:tid 533528] [client 20.151.10.161:55851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/by.php"] [unique_id "al9eD3UPuLYrePtEkUcj3gAAAKg"]
[Tue Jul 21 08:54:55.985476 2026] [security2:error] [pid 559070:tid 559248] [client 20.104.96.117:7941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/blurbs.php"] [unique_id "al9eDyy1f1FtKC137xv6lgAAAb8"]
[Tue Jul 21 08:54:55.992128 2026] [security2:error] [pid 559070:tid 559265] [client 5.38.115.39:51717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eDyy1f1FtKC137xv6lwAAAdA"]
[Tue Jul 21 08:54:55.992210 2026] [security2:error] [pid 559070:tid 559265] [client 5.38.115.39:51717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eDyy1f1FtKC137xv6lwAAAdA"]
[Tue Jul 21 08:54:56.069511 2026] [security2:error] [pid 559070:tid 559314] [client 182.189.99.211:48037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eECy1f1FtKC137xv6mgAAAgE"]
[Tue Jul 21 08:54:56.069620 2026] [security2:error] [pid 559070:tid 559314] [client 182.189.99.211:48037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eECy1f1FtKC137xv6mgAAAgE"]
[Tue Jul 21 08:54:56.134457 2026] [security2:error] [pid 559070:tid 559320] [client 203.25.124.41:58281] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/load.php"] [unique_id "al9eECy1f1FtKC137xv6nAAAAgc"]
[Tue Jul 21 08:54:56.176634 2026] [security2:error] [pid 559070:tid 559233] [client 20.151.10.161:37834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/gettest.php"] [unique_id "al9eECy1f1FtKC137xv6nwAAAbA"]
[Tue Jul 21 08:54:56.344273 2026] [security2:error] [pid 533360:tid 533620] [client 20.151.10.161:46018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/hur.php"] [unique_id "al9eEHUPuLYrePtEkUcj6AAAAQQ"]
[Tue Jul 21 08:54:56.448677 2026] [security2:error] [pid 559070:tid 559225] [client 103.59.206.240:31052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eECy1f1FtKC137xv6uwAAAag"]
[Tue Jul 21 08:54:56.448806 2026] [security2:error] [pid 559070:tid 559225] [client 103.59.206.240:31052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eECy1f1FtKC137xv6uwAAAag"]
[Tue Jul 21 08:54:56.482879 2026] [security2:error] [pid 559070:tid 559190] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eECy1f1FtKC137xv6wQABoXc"]
[Tue Jul 21 08:54:56.483052 2026] [security2:error] [pid 559070:tid 559218] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eECy1f1FtKC137xv6wQABoXc"]
[Tue Jul 21 08:54:56.510748 2026] [proxy:error] [pid 559070:tid 559256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:56.510826 2026] [proxy_http:error] [pid 559070:tid 559256] [client 20.151.10.161:37829] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:56.511284 2026] [proxy:error] [pid 559070:tid 559256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:56.511310 2026] [proxy_http:error] [pid 559070:tid 559256] [client 20.151.10.161:37829] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:56.595836 2026] [security2:error] [pid 533360:tid 533557] [client 20.104.96.117:7958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/bajah.php"] [unique_id "al9eEHUPuLYrePtEkUcj-wAAAMU"]
[Tue Jul 21 08:54:56.757627 2026] [security2:error] [pid 559070:tid 559287] [client 20.151.10.161:46050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/h02ugyh.php"] [unique_id "al9eECy1f1FtKC137xv60wAAAeY"]
[Tue Jul 21 08:54:56.880636 2026] [security2:error] [pid 559070:tid 559253] [client 20.151.10.161:52154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/simple.php"] [unique_id "al9eECy1f1FtKC137xv62wAAAcQ"]
[Tue Jul 21 08:54:56.941787 2026] [security2:error] [pid 559070:tid 559282] [client 212.32.76.12:43197] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/index.php"] [unique_id "al9eECy1f1FtKC137xv63gAAAeE"]
[Tue Jul 21 08:54:57.090572 2026] [security2:error] [pid 559070:tid 559252] [client 198.44.157.162:37566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9eESy1f1FtKC137xv65gAAAcM"]
[Tue Jul 21 08:54:57.090668 2026] [security2:error] [pid 559070:tid 559252] [client 198.44.157.162:37566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9eESy1f1FtKC137xv65gAAAcM"]
[Tue Jul 21 08:54:57.098260 2026] [security2:error] [pid 559070:tid 559184] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eESy1f1FtKC137xv65wABm3E"]
[Tue Jul 21 08:54:57.098460 2026] [security2:error] [pid 559070:tid 559212] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eESy1f1FtKC137xv65wABm3E"]
[Tue Jul 21 08:54:57.117917 2026] [security2:error] [pid 559070:tid 559298] [client 20.151.10.161:45976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/seiso.php"] [unique_id "al9eESy1f1FtKC137xv66AAAAfE"]
[Tue Jul 21 08:54:57.287765 2026] [security2:error] [pid 533360:tid 533523] [client 20.104.96.117:7950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/a.php"] [unique_id "al9eEXUPuLYrePtEkUckAgAAAKM"]
[Tue Jul 21 08:54:57.374375 2026] [security2:error] [pid 559070:tid 559278] [client 20.151.10.161:37735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/xxx.php"] [unique_id "al9eESy1f1FtKC137xv68AAAAd0"]
[Tue Jul 21 08:54:57.457292 2026] [security2:error] [pid 559070:tid 559259] [client 20.197.192.193:27072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/aa1.php"] [unique_id "al9eESy1f1FtKC137xv6_gAAAco"]
[Tue Jul 21 08:54:57.492374 2026] [security2:error] [pid 533360:tid 533597] [client 20.151.10.161:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/155.php"] [unique_id "al9eEXUPuLYrePtEkUckBAAAAO0"]
[Tue Jul 21 08:54:57.698433 2026] [security2:error] [pid 559070:tid 559282] [client 20.151.10.161:37793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/hypo.php"] [unique_id "al9eESy1f1FtKC137xv7OQAAAeE"]
[Tue Jul 21 08:54:57.730730 2026] [security2:error] [pid 559070:tid 559128] [remote 84.247.172.23:57954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9eESy1f1FtKC137xv7OwAByTk"]
[Tue Jul 21 08:54:57.843071 2026] [security2:error] [pid 559070:tid 559322] [client 20.104.96.117:7947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/edit.php"] [unique_id "al9eESy1f1FtKC137xv7PAAAAgk"]
[Tue Jul 21 08:54:57.884577 2026] [security2:error] [pid 533360:tid 533583] [client 185.213.175.37:50748] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "brwmarcas.com.br"] [uri "/"] [unique_id "al9eEXUPuLYrePtEkUckCwAAAN8"]
[Tue Jul 21 08:54:57.927176 2026] [security2:error] [pid 533360:tid 533610] [client 20.151.10.161:45963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/ppp.php"] [unique_id "al9eEXUPuLYrePtEkUckDgAAAPo"]
[Tue Jul 21 08:54:58.081019 2026] [security2:error] [pid 533360:tid 533549] [client 65.21.113.253:49112] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eEnUPuLYrePtEkUckFAAAAL0"]
[Tue Jul 21 08:54:58.140539 2026] [security2:error] [pid 533360:tid 533519] [client 203.25.124.43:35651] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/k.php"] [unique_id "al9eEnUPuLYrePtEkUckFQAAAJ8"]
[Tue Jul 21 08:54:58.288781 2026] [security2:error] [pid 533360:tid 533620] [client 20.151.10.161:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/201.php"] [unique_id "al9eEnUPuLYrePtEkUckFwAAAQQ"]
[Tue Jul 21 08:54:58.305868 2026] [security2:error] [pid 533360:tid 533376] [remote 217.182.128.41:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fidellium.com"] [uri "/wp-login.php"] [unique_id "al9eEnUPuLYrePtEkUckGAAA1Aw"]
[Tue Jul 21 08:54:58.364514 2026] [security2:error] [pid 559070:tid 559312] [client 20.151.10.161:49094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/coffexium.php"] [unique_id "al9eEiy1f1FtKC137xv7SgAAAf8"]
[Tue Jul 21 08:54:58.367661 2026] [proxy:error] [pid 559070:tid 559276] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:58.367731 2026] [proxy_http:error] [pid 559070:tid 559276] [client 20.151.10.161:37831] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:58.368323 2026] [proxy:error] [pid 559070:tid 559276] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:58.368353 2026] [proxy_http:error] [pid 559070:tid 559276] [client 20.151.10.161:37831] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:58.564063 2026] [security2:error] [pid 533360:tid 533569] [client 20.104.96.117:7995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/hosty.php"] [unique_id "al9eEnUPuLYrePtEkUckHwAAANE"]
[Tue Jul 21 08:54:58.704952 2026] [security2:error] [pid 559070:tid 559147] [remote 192.241.143.148:60558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9eEiy1f1FtKC137xv7UwABzEw"]
[Tue Jul 21 08:54:58.798437 2026] [security2:error] [pid 533360:tid 533532] [client 173.252.95.18:35904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eEnUPuLYrePtEkUckJgAAAKw"]
[Tue Jul 21 08:54:58.798975 2026] [security2:error] [pid 533360:tid 533521] [client 20.151.10.161:46012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/ops.php"] [unique_id "al9eEnUPuLYrePtEkUckJwAAAKE"]
[Tue Jul 21 08:54:58.940984 2026] [security2:error] [pid 533360:tid 533515] [client 65.21.113.253:43248] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eEnUPuLYrePtEkUckJQAAAJs"]
[Tue Jul 21 08:54:59.002925 2026] [security2:error] [pid 559070:tid 559300] [client 20.220.225.223:52650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/min.php"] [unique_id "al9eEyy1f1FtKC137xv7VgAAAfM"]
[Tue Jul 21 08:54:59.051161 2026] [security2:error] [pid 533360:tid 533571] [client 203.25.124.42:52347] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-conflg.php"] [unique_id "al9eE3UPuLYrePtEkUckLQAAANM"]
[Tue Jul 21 08:54:59.114483 2026] [security2:error] [pid 533360:tid 533520] [client 20.104.96.117:7970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/k.php"] [unique_id "al9eE3UPuLYrePtEkUckMQAAAKA"]
[Tue Jul 21 08:54:59.149191 2026] [security2:error] [pid 559070:tid 559281] [client 59.95.197.55:50862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eEyy1f1FtKC137xv7WgAAAeA"]
[Tue Jul 21 08:54:59.149978 2026] [security2:error] [pid 559070:tid 559281] [client 59.95.197.55:50862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eEyy1f1FtKC137xv7WgAAAeA"]
[Tue Jul 21 08:54:59.208647 2026] [security2:error] [pid 559070:tid 559203] [client 20.151.10.161:37833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/chosen.php"] [unique_id "al9eEyy1f1FtKC137xv7XAAAAZI"]
[Tue Jul 21 08:54:59.225697 2026] [security2:error] [pid 559070:tid 559218] [client 20.151.10.161:46037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/ingfo.php"] [unique_id "al9eEyy1f1FtKC137xv7XQAAAaE"]
[Tue Jul 21 08:54:59.607132 2026] [security2:error] [pid 533360:tid 533575] [client 20.220.225.223:34863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/wicked.php"] [unique_id "al9eE3UPuLYrePtEkUckOAAAANc"]
[Tue Jul 21 08:54:59.717785 2026] [proxy:error] [pid 559070:tid 559256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:59.717886 2026] [proxy_http:error] [pid 559070:tid 559256] [client 20.151.10.161:52220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:54:59.718497 2026] [proxy:error] [pid 559070:tid 559256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:54:59.718524 2026] [proxy_http:error] [pid 559070:tid 559256] [client 20.151.10.161:52220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:55:00.011427 2026] [security2:error] [pid 559070:tid 559247] [client 65.21.113.253:50542] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eEyy1f1FtKC137xv7YgAAAb4"]
[Tue Jul 21 08:55:00.153361 2026] [security2:error] [pid 559070:tid 559287] [client 20.104.96.117:7559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/aaa.php"] [unique_id "al9eFCy1f1FtKC137xv7awAAAeY"]
[Tue Jul 21 08:55:00.156139 2026] [security2:error] [pid 533360:tid 533594] [client 114.198.138.124:63214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eFHUPuLYrePtEkUckQgAAAOo"]
[Tue Jul 21 08:55:00.156525 2026] [security2:error] [pid 533360:tid 533594] [client 114.198.138.124:63214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eFHUPuLYrePtEkUckQgAAAOo"]
[Tue Jul 21 08:55:00.248462 2026] [security2:error] [pid 559070:tid 559289] [client 20.151.10.161:46061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/error_log.php"] [unique_id "al9eFCy1f1FtKC137xv7bwAAAeg"]
[Tue Jul 21 08:55:00.464919 2026] [security2:error] [pid 533360:tid 533591] [client 20.151.10.161:37849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/als.php"] [unique_id "al9eFHUPuLYrePtEkUckSwAAAOc"]
[Tue Jul 21 08:55:00.705722 2026] [security2:error] [pid 533360:tid 533564] [client 31.57.219.92:47684] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "oficialwebsite.com.br"] [uri "/"] [unique_id "al9eFHUPuLYrePtEkUckTgAAAMw"]
[Tue Jul 21 08:55:00.780192 2026] [security2:error] [pid 559070:tid 559259] [client 20.151.10.161:55869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/FAQ.php"] [unique_id "al9eFCy1f1FtKC137xv7fQAAAco"]
[Tue Jul 21 08:55:00.817952 2026] [security2:error] [pid 533360:tid 533470] [remote 69.171.234.22:39992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.234.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9eFHUPuLYrePtEkUckTQAAn2o"]
[Tue Jul 21 08:55:00.864009 2026] [security2:error] [pid 559070:tid 559321] [client 20.151.10.161:37863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/pol.php"] [unique_id "al9eFCy1f1FtKC137xv7fwAAAgg"]
[Tue Jul 21 08:55:01.054689 2026] [security2:error] [pid 559070:tid 559265] [client 20.220.225.223:52637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/echkm.php"] [unique_id "al9eFSy1f1FtKC137xv7gwAAAdA"]
[Tue Jul 21 08:55:01.099364 2026] [security2:error] [pid 559070:tid 559299] [client 107.189.2.5:41838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "kettlebellevolution.com.br"] [uri "/.env.swp"] [unique_id "al9eFSy1f1FtKC137xv7hwAAAfI"]
[Tue Jul 21 08:55:01.099362 2026] [security2:error] [pid 559070:tid 559237] [client 107.189.2.5:41744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "kettlebellevolution.com.br"] [uri "/.env.bak"] [unique_id "al9eFSy1f1FtKC137xv7iAAAAbQ"]
[Tue Jul 21 08:55:01.099537 2026] [security2:error] [pid 559070:tid 559210] [client 107.189.2.5:41714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kettlebellevolution.com.br"] [uri "/.env"] [unique_id "al9eFSy1f1FtKC137xv7jwAAAZk"]
[Tue Jul 21 08:55:01.099763 2026] [security2:error] [pid 559070:tid 559242] [client 107.189.2.5:41764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "kettlebellevolution.com.br"] [uri "/.env.backup"] [unique_id "al9eFSy1f1FtKC137xv7kQAAAbk"]
[Tue Jul 21 08:55:01.099868 2026] [security2:error] [pid 559070:tid 559220] [client 107.189.2.5:41772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "kettlebellevolution.com.br"] [uri "/.env.old"] [unique_id "al9eFSy1f1FtKC137xv7kwAAAaM"]
[Tue Jul 21 08:55:01.099891 2026] [security2:error] [pid 559070:tid 559254] [client 107.189.2.5:41866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kettlebellevolution.com.br"] [uri "/backend/.env"] [unique_id "al9eFSy1f1FtKC137xv7kAAAAcU"]
[Tue Jul 21 08:55:01.099928 2026] [security2:error] [pid 533360:tid 533546] [client 107.189.2.5:41824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "kettlebellevolution.com.br"] [uri "/.env~"] [unique_id "al9eFXUPuLYrePtEkUckWAAAALo"]
[Tue Jul 21 08:55:01.339343 2026] [security2:error] [pid 533360:tid 533581] [client 20.151.10.161:37830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/file5.php"] [unique_id "al9eFXUPuLYrePtEkUckXgAAAN0"]
[Tue Jul 21 08:55:01.343953 2026] [security2:error] [pid 559070:tid 559281] [client 212.32.76.9:38943] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/block-bindings/"] [unique_id "al9eFSy1f1FtKC137xv7lQAAAeA"]
[Tue Jul 21 08:55:01.700513 2026] [security2:error] [pid 533360:tid 533531] [client 107.189.2.5:41824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kettlebellevolution.com.br"] [uri "/app/.env"] [unique_id "al9eFXUPuLYrePtEkUckZQAAAKs"]
[Tue Jul 21 08:55:01.701012 2026] [security2:error] [pid 559070:tid 559302] [client 107.189.2.5:41838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kettlebellevolution.com.br"] [uri "/web/.env"] [unique_id "al9eFSy1f1FtKC137xv7nQAAAfU"]
[Tue Jul 21 08:55:01.702199 2026] [security2:error] [pid 559070:tid 559308] [client 107.189.2.5:41764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kettlebellevolution.com.br"] [uri "/src/.env"] [unique_id "al9eFSy1f1FtKC137xv7oAAAAfs"]
[Tue Jul 21 08:55:01.702200 2026] [security2:error] [pid 559070:tid 559262] [client 107.189.2.5:41866] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kettlebellevolution.com.br"] [uri "/api/.env"] [unique_id "al9eFSy1f1FtKC137xv7nwAAAc0"]
[Tue Jul 21 08:55:01.702288 2026] [security2:error] [pid 559070:tid 559249] [client 107.189.2.5:41714] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kettlebellevolution.com.br"] [uri "/server/.env"] [unique_id "al9eFSy1f1FtKC137xv7oQAAAcA"]
[Tue Jul 21 08:55:01.702342 2026] [security2:error] [pid 559070:tid 559230] [client 107.189.2.5:41772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "kettlebellevolution.com.br"] [uri "/config/.env"] [unique_id "al9eFSy1f1FtKC137xv7ogAAAa0"]
[Tue Jul 21 08:55:01.780838 2026] [security2:error] [pid 559070:tid 559212] [client 20.151.10.161:45987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xenon1337.php"] [unique_id "al9eFSy1f1FtKC137xv7owAAAZs"]
[Tue Jul 21 08:55:01.860936 2026] [security2:error] [pid 559070:tid 559101] [remote 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9eFSy1f1FtKC137xv7pQACBx4"]
[Tue Jul 21 08:55:01.861109 2026] [security2:error] [pid 559070:tid 559320] [client 2409:40f2:2130:604e:b48f:c3b9:2841:7a5e:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "compranawebprodutos.com"] [uri "/xmlrpc.php"] [unique_id "al9eFSy1f1FtKC137xv7pQACBx4"]
[Tue Jul 21 08:55:01.906853 2026] [security2:error] [pid 533360:tid 533619] [client 20.151.10.161:37762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9eFXUPuLYrePtEkUckaAAAAQM"]
[Tue Jul 21 08:55:02.368020 2026] [security2:error] [pid 559070:tid 559324] [client 20.151.10.161:52128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/file.php"] [unique_id "al9eFiy1f1FtKC137xv7swAAAgs"]
[Tue Jul 21 08:55:02.794627 2026] [security2:error] [pid 533360:tid 533572] [client 20.220.225.223:58912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/mac.php"] [unique_id "al9eFnUPuLYrePtEkUckegAAANQ"]
[Tue Jul 21 08:55:03.030578 2026] [security2:error] [pid 533360:tid 533561] [client 198.44.157.162:47478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9eF3UPuLYrePtEkUckgQAAAMk"]
[Tue Jul 21 08:55:03.030697 2026] [security2:error] [pid 533360:tid 533561] [client 198.44.157.162:47478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9eF3UPuLYrePtEkUckgQAAAMk"]
[Tue Jul 21 08:55:03.142719 2026] [security2:error] [pid 533360:tid 533607] [client 203.25.124.55:21659] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-confiq.php"] [unique_id "al9eF3UPuLYrePtEkUckhgAAAPc"]
[Tue Jul 21 08:55:03.278548 2026] [security2:error] [pid 533360:tid 533566] [client 20.151.10.161:52142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/cfile.php"] [unique_id "al9eF3UPuLYrePtEkUckiAAAAM4"]
[Tue Jul 21 08:55:03.399057 2026] [security2:error] [pid 559070:tid 559265] [client 20.104.96.117:7574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/file5.php"] [unique_id "al9eFyy1f1FtKC137xv7zAAAAdA"]
[Tue Jul 21 08:55:03.697798 2026] [security2:error] [pid 533360:tid 533550] [client 20.151.10.161:37865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/class-wp.php"] [unique_id "al9eF3UPuLYrePtEkUckkAAAAL4"]
[Tue Jul 21 08:55:03.706911 2026] [security2:error] [pid 533360:tid 533540] [client 65.21.113.253:43394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eF3UPuLYrePtEkUckkQAAALQ"]
[Tue Jul 21 08:55:03.769759 2026] [security2:error] [pid 533360:tid 533611] [client 20.104.96.117:7975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/222.php"] [unique_id "al9eF3UPuLYrePtEkUckkwAAAPs"]
[Tue Jul 21 08:55:03.787893 2026] [security2:error] [pid 559070:tid 559291] [client 20.151.10.161:46054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/test11.php"] [unique_id "al9eFyy1f1FtKC137xv72QAAAeo"]
[Tue Jul 21 08:55:03.847619 2026] [security2:error] [pid 559070:tid 559161] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eFyy1f1FtKC137xv73AABxVo"]
[Tue Jul 21 08:55:03.847821 2026] [security2:error] [pid 559070:tid 559254] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eFyy1f1FtKC137xv73AABxVo"]
[Tue Jul 21 08:55:03.925393 2026] [security2:error] [pid 559070:tid 559200] [client 168.167.81.163:62030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eFyy1f1FtKC137xv73QAAAY8"]
[Tue Jul 21 08:55:03.928665 2026] [security2:error] [pid 559070:tid 559200] [client 168.167.81.163:62030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eFyy1f1FtKC137xv73QAAAY8"]
[Tue Jul 21 08:55:03.978868 2026] [security2:error] [pid 559070:tid 559112] [remote 41.186.86.12:49641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "monicamirandapereira1751478737000.bellarthconsultoria.com.br"] [uri "/wp-login.php"] [unique_id "al9eFyy1f1FtKC137xv73gAB8yk"]
[Tue Jul 21 08:55:04.063624 2026] [security2:error] [pid 533360:tid 533598] [client 172.234.215.24:59362] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "espacofabula.com"] [uri "/wp-json/batch/v1"] [unique_id "al9eGHUPuLYrePtEkUcknQAAAO4"]
[Tue Jul 21 08:55:04.134854 2026] [security2:error] [pid 559070:tid 559233] [client 20.104.96.117:7578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/test.php"] [unique_id "al9eGCy1f1FtKC137xv73wAAAbA"]
[Tue Jul 21 08:55:04.204123 2026] [security2:error] [pid 533360:tid 533542] [client 172.234.215.24:59362] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "espacofabula.com"] [uri "/"] [unique_id "al9eGHUPuLYrePtEkUckowAAALY"]
[Tue Jul 21 08:55:04.225858 2026] [security2:error] [pid 559070:tid 559296] [client 212.32.76.3:44285] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/fm.php/sts.php"] [unique_id "al9eGCy1f1FtKC137xv74wAAAe8"]
[Tue Jul 21 08:55:04.389503 2026] [security2:error] [pid 559070:tid 559262] [client 20.151.10.161:37817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/admin.php"] [unique_id "al9eGCy1f1FtKC137xv77QAAAc0"]
[Tue Jul 21 08:55:04.647766 2026] [security2:error] [pid 559070:tid 559237] [client 20.104.96.117:7960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/aaa.php"] [unique_id "al9eGCy1f1FtKC137xv7-QAAAbQ"]
[Tue Jul 21 08:55:04.774705 2026] [security2:error] [pid 533360:tid 533612] [client 65.21.113.253:50554] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eGHUPuLYrePtEkUckpQAAAPw"]
[Tue Jul 21 08:55:04.932862 2026] [security2:error] [pid 559070:tid 559279] [client 20.151.10.161:49109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/red.php"] [unique_id "al9eGCy1f1FtKC137xv8CAAAAd4"]
[Tue Jul 21 08:55:05.078334 2026] [security2:error] [pid 559070:tid 559260] [client 20.151.10.161:45917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/koala.php"] [unique_id "al9eGSy1f1FtKC137xv8DAAAAcs"]
[Tue Jul 21 08:55:05.123134 2026] [security2:error] [pid 559070:tid 559239] [client 20.151.10.161:52146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/aa2.php"] [unique_id "al9eGSy1f1FtKC137xv8DQAAAbY"]
[Tue Jul 21 08:55:05.238524 2026] [security2:error] [pid 559070:tid 559197] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eGSy1f1FtKC137xv8EAABkn4"]
[Tue Jul 21 08:55:05.238693 2026] [security2:error] [pid 559070:tid 559203] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eGSy1f1FtKC137xv8EAABkn4"]
[Tue Jul 21 08:55:05.320113 2026] [security2:error] [pid 559070:tid 559320] [client 113.22.144.139:52707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eGSy1f1FtKC137xv8EQAAAgc"]
[Tue Jul 21 08:55:05.320299 2026] [security2:error] [pid 559070:tid 559320] [client 113.22.144.139:52707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eGSy1f1FtKC137xv8EQAAAgc"]
[Tue Jul 21 08:55:05.351559 2026] [security2:error] [pid 533360:tid 533532] [client 20.220.225.223:52627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/samll.php"] [unique_id "al9eGXUPuLYrePtEkUckvQAAAKw"]
[Tue Jul 21 08:55:05.374526 2026] [security2:error] [pid 559070:tid 559302] [client 20.104.96.117:7938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/11.php"] [unique_id "al9eGSy1f1FtKC137xv8EgAAAfU"]
[Tue Jul 21 08:55:05.528155 2026] [security2:error] [pid 559070:tid 559202] [client 4.194.24.143:18227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/about/function.php"] [unique_id "al9eGSy1f1FtKC137xv8FAAAAZE"]
[Tue Jul 21 08:55:05.725384 2026] [security2:error] [pid 559070:tid 559283] [client 20.151.10.161:37720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/ccou.php"] [unique_id "al9eGSy1f1FtKC137xv8GAAAAeI"]
[Tue Jul 21 08:55:05.737949 2026] [security2:error] [pid 559070:tid 559248] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eGSy1f1FtKC137xv8FwABvxE"]
[Tue Jul 21 08:55:05.849174 2026] [security2:error] [pid 533360:tid 533515] [client 20.104.96.117:7956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/mac.php"] [unique_id "al9eGXUPuLYrePtEkUckyAAAAJs"]
[Tue Jul 21 08:55:06.060276 2026] [security2:error] [pid 559070:tid 559236] [client 41.89.234.2:53759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eGiy1f1FtKC137xv8IQAAAbM"]
[Tue Jul 21 08:55:06.060404 2026] [security2:error] [pid 559070:tid 559236] [client 41.89.234.2:53759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eGiy1f1FtKC137xv8IQAAAbM"]
[Tue Jul 21 08:55:06.300105 2026] [security2:error] [pid 559070:tid 559317] [client 20.104.96.117:7253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/chosen.php"] [unique_id "al9eGiy1f1FtKC137xv8JgAAAgQ"]
[Tue Jul 21 08:55:06.379140 2026] [security2:error] [pid 533360:tid 533610] [client 20.151.10.161:37827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/dr.php"] [unique_id "al9eGnUPuLYrePtEkUck0gAAAPo"]
[Tue Jul 21 08:55:06.558197 2026] [security2:error] [pid 533360:tid 533550] [client 182.189.99.211:48091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eGnUPuLYrePtEkUck1gAAAL4"]
[Tue Jul 21 08:55:06.558299 2026] [security2:error] [pid 533360:tid 533550] [client 182.189.99.211:48091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eGnUPuLYrePtEkUck1gAAAL4"]
[Tue Jul 21 08:55:06.574384 2026] [security2:error] [pid 533360:tid 533527] [client 20.220.225.223:58936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/abcd.php"] [unique_id "al9eGnUPuLYrePtEkUck2AAAAKc"]
[Tue Jul 21 08:55:06.620602 2026] [security2:error] [pid 559070:tid 559238] [client 4.194.24.143:7904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/admiin.php"] [unique_id "al9eGiy1f1FtKC137xv8LgAAAbU"]
[Tue Jul 21 08:55:06.685364 2026] [security2:error] [pid 559070:tid 559274] [client 20.104.96.117:7552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/cream1.php"] [unique_id "al9eGiy1f1FtKC137xv8LwAAAdk"]
[Tue Jul 21 08:55:06.687681 2026] [security2:error] [pid 559070:tid 559225] [client 20.151.10.161:49106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9eGiy1f1FtKC137xv8MAAAAag"]
[Tue Jul 21 08:55:06.777419 2026] [security2:error] [pid 559070:tid 559218] [client 5.38.115.39:27859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eGiy1f1FtKC137xv8MgAAAaE"]
[Tue Jul 21 08:55:06.777527 2026] [security2:error] [pid 559070:tid 559218] [client 5.38.115.39:27859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eGiy1f1FtKC137xv8MgAAAaE"]
[Tue Jul 21 08:55:06.941064 2026] [security2:error] [pid 559070:tid 559249] [client 203.25.124.64:52733] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/upload/index.php"] [unique_id "al9eGiy1f1FtKC137xv8NQAAAcA"]
[Tue Jul 21 08:55:06.949919 2026] [security2:error] [pid 533360:tid 533522] [client 20.151.10.161:52197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/xamp.php"] [unique_id "al9eGnUPuLYrePtEkUck3AAAAKI"]
[Tue Jul 21 08:55:07.071104 2026] [security2:error] [pid 533360:tid 533584] [client 103.59.206.240:31455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eG3UPuLYrePtEkUck4QAAAOA"]
[Tue Jul 21 08:55:07.071195 2026] [security2:error] [pid 533360:tid 533584] [client 103.59.206.240:31455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eG3UPuLYrePtEkUck4QAAAOA"]
[Tue Jul 21 08:55:07.288796 2026] [security2:error] [pid 559070:tid 559220] [client 20.151.10.161:52133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/bless.php"] [unique_id "al9eGyy1f1FtKC137xv8PgAAAaM"]
[Tue Jul 21 08:55:07.443284 2026] [security2:error] [pid 533360:tid 533541] [client 20.104.96.117:7560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/dr.php"] [unique_id "al9eG3UPuLYrePtEkUck6AAAALU"]
[Tue Jul 21 08:55:07.486703 2026] [security2:error] [pid 533360:tid 533502] [client 20.220.225.223:21608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/la.php"] [unique_id "al9eG3UPuLYrePtEkUck6gAAAI4"]
[Tue Jul 21 08:55:07.522610 2026] [security2:error] [pid 533360:tid 533457] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eG3UPuLYrePtEkUck6wAAnV0"]
[Tue Jul 21 08:55:07.522722 2026] [security2:error] [pid 533360:tid 533517] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eG3UPuLYrePtEkUck6wAAnV0"]
[Tue Jul 21 08:55:07.581180 2026] [security2:error] [pid 533360:tid 533516] [client 20.151.10.161:46072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/mac.php"] [unique_id "al9eG3UPuLYrePtEkUck7gAAAJw"]
[Tue Jul 21 08:55:07.614672 2026] [security2:error] [pid 559070:tid 559238] [client 20.151.10.161:37782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/file46.php"] [unique_id "al9eGyy1f1FtKC137xv8RgAAAbU"]
[Tue Jul 21 08:55:07.621938 2026] [security2:error] [pid 559070:tid 559213] [client 20.151.10.161:49118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/footer.php"] [unique_id "al9eGyy1f1FtKC137xv8RwAAAZw"]
[Tue Jul 21 08:55:07.630008 2026] [security2:error] [pid 559070:tid 559162] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eGyy1f1FtKC137xv8SAABl1s"]
[Tue Jul 21 08:55:07.630138 2026] [security2:error] [pid 559070:tid 559208] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eGyy1f1FtKC137xv8SAABl1s"]
[Tue Jul 21 08:55:07.705152 2026] [security2:error] [pid 559070:tid 559295] [client 4.194.24.143:7875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/admin-main/class-wp-http-core.php"] [unique_id "al9eGyy1f1FtKC137xv8SQAAAe4"]
[Tue Jul 21 08:55:07.787895 2026] [security2:error] [pid 559070:tid 559302] [client 20.151.10.161:51058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/coffexium.php"] [unique_id "al9eGyy1f1FtKC137xv8SwAAAfU"]
[Tue Jul 21 08:55:07.831290 2026] [security2:error] [pid 533360:tid 533495] [client 20.104.96.117:7977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/x.php"] [unique_id "al9eG3UPuLYrePtEkUck8gAAAIc"]
[Tue Jul 21 08:55:07.915686 2026] [security2:error] [pid 533360:tid 533586] [client 20.151.10.161:52141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/eee.php"] [unique_id "al9eG3UPuLYrePtEkUck9gAAAOI"]
[Tue Jul 21 08:55:08.205017 2026] [security2:error] [pid 533360:tid 533602] [client 65.21.113.253:43394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eHHUPuLYrePtEkUck-wAAAPI"]
[Tue Jul 21 08:55:08.368138 2026] [security2:error] [pid 559070:tid 559220] [client 20.104.96.117:7992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/155.php"] [unique_id "al9eHCy1f1FtKC137xv8UgAAAaM"]
[Tue Jul 21 08:55:08.396058 2026] [security2:error] [pid 533360:tid 533557] [client 20.151.10.161:52156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/file25.php"] [unique_id "al9eHHUPuLYrePtEkUclAAAAAMU"]
[Tue Jul 21 08:55:08.728915 2026] [security2:error] [pid 559070:tid 559225] [client 20.151.10.161:52158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/file48.php"] [unique_id "al9eHCy1f1FtKC137xv8ZAAAAag"]
[Tue Jul 21 08:55:08.762741 2026] [security2:error] [pid 533360:tid 533611] [client 4.194.24.143:18617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/admin-post.php"] [unique_id "al9eHHUPuLYrePtEkUclDQAAAPs"]
[Tue Jul 21 08:55:08.883045 2026] [security2:error] [pid 559070:tid 559080] [remote 5.252.52.249:36228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9eHCy1f1FtKC137xv8awAB-wk"]
[Tue Jul 21 08:55:08.969783 2026] [security2:error] [pid 533360:tid 533599] [client 20.151.10.161:49038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-content/index.php"] [unique_id "al9eHHUPuLYrePtEkUclFQAAAO8"]
[Tue Jul 21 08:55:09.092333 2026] [security2:error] [pid 533360:tid 533584] [client 20.104.96.117:7994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/ops.php"] [unique_id "al9eHXUPuLYrePtEkUclFwAAAOA"]
[Tue Jul 21 08:55:09.094990 2026] [security2:error] [pid 559070:tid 559214] [client 20.220.225.223:52242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/xyn.php"] [unique_id "al9eHSy1f1FtKC137xv8cAAAAZ0"]
[Tue Jul 21 08:55:09.121841 2026] [security2:error] [pid 559070:tid 559259] [client 20.151.10.161:37857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/file6.php"] [unique_id "al9eHSy1f1FtKC137xv8cQAAAco"]
[Tue Jul 21 08:55:09.263962 2026] [security2:error] [pid 559070:tid 559073] [remote 65.111.24.49:30789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9eHSy1f1FtKC137xv8dQAB4gI"]
[Tue Jul 21 08:55:09.303423 2026] [security2:error] [pid 533360:tid 533408] [remote 41.186.86.12:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "link.aede.com.br"] [uri "/wp-login.php"] [unique_id "al9eHXUPuLYrePtEkUclGQAAlCw"]
[Tue Jul 21 08:55:09.326973 2026] [security2:error] [pid 559070:tid 559238] [client 65.21.113.253:50566] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eHCy1f1FtKC137xv8bAAAAbU"]
[Tue Jul 21 08:55:09.426869 2026] [security2:error] [pid 559070:tid 559210] [client 20.151.10.161:37882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/a2.php"] [unique_id "al9eHSy1f1FtKC137xv8ewAAAZk"]
[Tue Jul 21 08:55:09.702164 2026] [security2:error] [pid 559070:tid 559276] [client 59.95.197.55:51417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eHSy1f1FtKC137xv8hAAAAds"]
[Tue Jul 21 08:55:09.702917 2026] [security2:error] [pid 559070:tid 559276] [client 59.95.197.55:51417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eHSy1f1FtKC137xv8hAAAAds"]
[Tue Jul 21 08:55:09.719033 2026] [security2:error] [pid 559070:tid 559204] [client 20.197.192.193:27149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/acew67.php"] [unique_id "al9eHSy1f1FtKC137xv8hQAAAZM"]
[Tue Jul 21 08:55:09.790720 2026] [security2:error] [pid 559070:tid 559216] [client 20.104.96.117:7568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/file31.php"] [unique_id "al9eHSy1f1FtKC137xv8hwAAAZ8"]
[Tue Jul 21 08:55:09.794505 2026] [security2:error] [pid 559070:tid 559316] [client 20.151.10.161:52149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/file15.php"] [unique_id "al9eHSy1f1FtKC137xv8iAAAAgM"]
[Tue Jul 21 08:55:09.835856 2026] [security2:error] [pid 559070:tid 559236] [client 203.25.124.41:32423] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/images/index.php"] [unique_id "al9eHSy1f1FtKC137xv8iQAAAbM"]
[Tue Jul 21 08:55:09.844508 2026] [security2:error] [pid 559070:tid 559211] [client 4.194.24.143:50418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/admin.php"] [unique_id "al9eHSy1f1FtKC137xv8igAAAZo"]
[Tue Jul 21 08:55:10.250056 2026] [security2:error] [pid 559070:tid 559290] [client 20.151.10.161:37862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/jp.php"] [unique_id "al9eHiy1f1FtKC137xv8mQAAAek"]
[Tue Jul 21 08:55:10.255712 2026] [security2:error] [pid 559070:tid 559275] [client 173.252.95.61:51640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eHiy1f1FtKC137xv8mgAAAdo"]
[Tue Jul 21 08:55:10.279283 2026] [security2:error] [pid 533360:tid 533544] [client 20.104.96.117:7558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/file6.php"] [unique_id "al9eHnUPuLYrePtEkUclLQAAALg"]
[Tue Jul 21 08:55:10.728976 2026] [security2:error] [pid 559070:tid 559212] [client 114.198.138.124:63846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eHiy1f1FtKC137xv8pwAAAZs"]
[Tue Jul 21 08:55:10.729113 2026] [security2:error] [pid 559070:tid 559212] [client 114.198.138.124:63846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eHiy1f1FtKC137xv8pwAAAZs"]
[Tue Jul 21 08:55:10.820154 2026] [security2:error] [pid 559070:tid 559299] [client 20.151.10.161:37810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/f35.php"] [unique_id "al9eHiy1f1FtKC137xv8qQAAAfI"]
[Tue Jul 21 08:55:10.866658 2026] [security2:error] [pid 559070:tid 559262] [client 20.104.96.117:7585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/adminfuns.php"] [unique_id "al9eHiy1f1FtKC137xv8qgAAAc0"]
[Tue Jul 21 08:55:10.904477 2026] [security2:error] [pid 559070:tid 559237] [client 20.151.10.161:49130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/zoro.php"] [unique_id "al9eHiy1f1FtKC137xv8rAAAAbQ"]
[Tue Jul 21 08:55:10.926469 2026] [security2:error] [pid 559070:tid 559324] [client 69.171.230.6:55278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eHiy1f1FtKC137xv8rQAAAgs"]
[Tue Jul 21 08:55:10.955680 2026] [security2:error] [pid 533360:tid 533382] [remote 104.207.62.150:53157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.62.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9eHnUPuLYrePtEkUclPgAAtBI"]
[Tue Jul 21 08:55:11.083120 2026] [security2:error] [pid 533360:tid 533384] [remote 216.73.216.184:7357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapd.xml"] [unique_id "al9eH3UPuLYrePtEkUclRQAA2xQ"]
[Tue Jul 21 08:55:11.143895 2026] [security2:error] [pid 559070:tid 559214] [client 212.32.76.5:20415] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/admin-header.php"] [unique_id "al9eHyy1f1FtKC137xv8uQAAAZ0"]
[Tue Jul 21 08:55:11.248886 2026] [security2:error] [pid 559070:tid 559241] [client 20.151.10.161:52151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-load.php"] [unique_id "al9eHyy1f1FtKC137xv8vQAAAbg"]
[Tue Jul 21 08:55:11.501281 2026] [security2:error] [pid 559070:tid 559217] [client 20.104.96.117:7573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/goods.php"] [unique_id "al9eHyy1f1FtKC137xv8xQAAAaA"]
[Tue Jul 21 08:55:11.606695 2026] [security2:error] [pid 533360:tid 533620] [client 69.171.230.38:61610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eH3UPuLYrePtEkUclTgAAAQQ"]
[Tue Jul 21 08:55:11.635687 2026] [security2:error] [pid 559070:tid 559274] [client 20.220.225.223:35086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/edit.php"] [unique_id "al9eHyy1f1FtKC137xv8zAAAAdk"]
[Tue Jul 21 08:55:11.654438 2026] [security2:error] [pid 533360:tid 533561] [client 128.127.105.184:53968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9eH3UPuLYrePtEkUclTwAAAMk"]
[Tue Jul 21 08:55:11.654518 2026] [security2:error] [pid 533360:tid 533561] [client 128.127.105.184:53968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9eH3UPuLYrePtEkUclTwAAAMk"]
[Tue Jul 21 08:55:11.760384 2026] [security2:error] [pid 559070:tid 559245] [client 168.167.81.163:64829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eHyy1f1FtKC137xv80QAAAbw"]
[Tue Jul 21 08:55:11.764365 2026] [security2:error] [pid 559070:tid 559245] [client 168.167.81.163:64829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eHyy1f1FtKC137xv80QAAAbw"]
[Tue Jul 21 08:55:12.009156 2026] [security2:error] [pid 559070:tid 559272] [client 20.151.10.161:37839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/xwpg.php"] [unique_id "al9eICy1f1FtKC137xv82AAAAdc"]
[Tue Jul 21 08:55:12.093438 2026] [security2:error] [pid 559070:tid 559242] [client 20.104.96.117:7555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/100.php"] [unique_id "al9eICy1f1FtKC137xv82gAAAbk"]
[Tue Jul 21 08:55:12.239581 2026] [security2:error] [pid 559070:tid 559287] [client 20.220.225.223:48194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9eICy1f1FtKC137xv83wAAAeY"]
[Tue Jul 21 08:55:12.260755 2026] [security2:error] [pid 559070:tid 559261] [client 127.0.0.1:20460] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al9eICy1f1FtKC137xv83gAAAcw"]
[Tue Jul 21 08:55:12.263550 2026] [security2:error] [pid 533360:tid 533551] [client 74.7.244.13:41222] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.elisamagri.com.br"] [uri "/robots.txt"] [unique_id "al9eIHUPuLYrePtEkUclYgAAv0c"]
[Tue Jul 21 08:55:12.274611 2026] [security2:error] [pid 559070:tid 559297] [client 69.171.230.6:55296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eICy1f1FtKC137xv84AAAAfA"]
[Tue Jul 21 08:55:12.424007 2026] [security2:error] [pid 559070:tid 559217] [client 20.220.225.223:22537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/kua.php"] [unique_id "al9eICy1f1FtKC137xv84wAAAaA"]
[Tue Jul 21 08:55:12.460427 2026] [security2:error] [pid 533360:tid 533593] [client 4.194.24.143:18229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/admin/function.php"] [unique_id "al9eIHUPuLYrePtEkUclZwAAAOk"]
[Tue Jul 21 08:55:12.519621 2026] [security2:error] [pid 533360:tid 533548] [client 74.7.230.1:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "buyonlinetodayatadiscount.net"] [uri "/cgi-sys/404.html"] [unique_id "al9eIHUPuLYrePtEkUclaQAAALw"]
[Tue Jul 21 08:55:12.520137 2026] [security2:error] [pid 559070:tid 559300] [client 74.7.230.1:34576] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "buyonlinetodayatadiscount.net"] [uri "/robots.txt"] [unique_id "al9eICy1f1FtKC137xv85QAB80w"]
[Tue Jul 21 08:55:12.535313 2026] [security2:error] [pid 559070:tid 559282] [client 20.197.192.193:56799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/red.php"] [unique_id "al9eICy1f1FtKC137xv86QAAAeE"]
[Tue Jul 21 08:55:12.575596 2026] [proxy:error] [pid 533360:tid 533575] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:55:12.575674 2026] [proxy_http:error] [pid 533360:tid 533575] [client 20.151.10.161:37816] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:55:12.576353 2026] [proxy:error] [pid 533360:tid 533575] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:55:12.576390 2026] [proxy_http:error] [pid 533360:tid 533575] [client 20.151.10.161:37816] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:55:12.681807 2026] [security2:error] [pid 559070:tid 559252] [client 20.104.96.117:7609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/about.php"] [unique_id "al9eICy1f1FtKC137xv87AAAAcM"]
[Tue Jul 21 08:55:12.729878 2026] [security2:error] [pid 559070:tid 559245] [client 20.151.10.161:55847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/red.php"] [unique_id "al9eICy1f1FtKC137xv88QAAAbw"]
[Tue Jul 21 08:55:12.738123 2026] [security2:error] [pid 533360:tid 533539] [client 203.25.124.53:30065] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/autoload_classmap/function.php"] [unique_id "al9eIHUPuLYrePtEkUclcQAAALM"]
[Tue Jul 21 08:55:12.840458 2026] [security2:error] [pid 533360:tid 533443] [remote 72.167.132.114:60408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9eIHUPuLYrePtEkUclcwAAxE8"]
[Tue Jul 21 08:55:12.849375 2026] [security2:error] [pid 533360:tid 533583] [client 65.21.113.253:43394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eIHUPuLYrePtEkUcldAAAAN8"]
[Tue Jul 21 08:55:13.059600 2026] [proxy:error] [pid 559070:tid 559215] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:55:13.059695 2026] [proxy_http:error] [pid 559070:tid 559215] [client 20.151.10.161:37773] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:55:13.060565 2026] [proxy:error] [pid 559070:tid 559215] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:55:13.060610 2026] [proxy_http:error] [pid 559070:tid 559215] [client 20.151.10.161:37773] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:55:13.171587 2026] [security2:error] [pid 533360:tid 533541] [client 20.220.225.223:43194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/ez.php"] [unique_id "al9eIXUPuLYrePtEkUclfAAAALU"]
[Tue Jul 21 08:55:13.246635 2026] [security2:error] [pid 533360:tid 533599] [client 20.220.225.223:38734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/inso.php"] [unique_id "al9eIXUPuLYrePtEkUclfQAAAO8"]
[Tue Jul 21 08:55:13.297482 2026] [security2:error] [pid 559070:tid 559207] [client 20.104.96.117:7962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/about.php"] [unique_id "al9eISy1f1FtKC137xv9AgAAAZY"]
[Tue Jul 21 08:55:13.485192 2026] [security2:error] [pid 533360:tid 533522] [client 4.194.24.143:7331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/adminfuns.php"] [unique_id "al9eIXUPuLYrePtEkUclfwAAAKI"]
[Tue Jul 21 08:55:13.591598 2026] [security2:error] [pid 533360:tid 533529] [client 20.197.192.193:63935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9eIXUPuLYrePtEkUclgwAAAKk"]
[Tue Jul 21 08:55:13.636094 2026] [security2:error] [pid 559070:tid 559274] [client 20.151.10.161:52215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/waf.php"] [unique_id "al9eISy1f1FtKC137xv9DgAAAdk"]
[Tue Jul 21 08:55:13.649474 2026] [security2:error] [pid 559070:tid 559220] [client 20.104.96.117:7242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/admin.php"] [unique_id "al9eISy1f1FtKC137xv9DwAAAaM"]
[Tue Jul 21 08:55:13.714479 2026] [security2:error] [pid 559070:tid 559101] [remote 188.95.113.76:50886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "agrocibus.com.br"] [uri "/wp-login.php"] [unique_id "al9eISy1f1FtKC137xv9EAAB4R4"]
[Tue Jul 21 08:55:13.840959 2026] [security2:error] [pid 559070:tid 559233] [client 212.32.76.3:24061] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/5PJcpMFsD8B.php"] [unique_id "al9eISy1f1FtKC137xv9EwAAAbA"]
[Tue Jul 21 08:55:13.891079 2026] [security2:error] [pid 559070:tid 559291] [client 65.21.113.253:41898] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eISy1f1FtKC137xv9CwAAAeo"]
[Tue Jul 21 08:55:14.014744 2026] [security2:error] [pid 559070:tid 559287] [client 20.220.225.223:22565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/fz.php"] [unique_id "al9eIiy1f1FtKC137xv9GgAAAeY"]
[Tue Jul 21 08:55:14.063785 2026] [security2:error] [pid 559070:tid 559227] [client 20.151.10.161:52154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/xstelth.php"] [unique_id "al9eIiy1f1FtKC137xv9GwAAAao"]
[Tue Jul 21 08:55:14.106865 2026] [security2:error] [pid 559070:tid 559202] [client 20.104.96.117:7936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/admin.php"] [unique_id "al9eIiy1f1FtKC137xv9HwAAAZE"]
[Tue Jul 21 08:55:14.163200 2026] [security2:error] [pid 559070:tid 559316] [client 198.204.224.34:33824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/wp-includes/qqf65547/73/index.php"] [unique_id "al9eIiy1f1FtKC137xv9GQAAAgM"], referer: http://roanalacerda.com.br/wp-includes/qqf65547/73/index.php
[Tue Jul 21 08:55:14.288708 2026] [security2:error] [pid 559070:tid 559110] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eIiy1f1FtKC137xv9IwACCSc"]
[Tue Jul 21 08:55:14.289065 2026] [security2:error] [pid 559070:tid 559322] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eIiy1f1FtKC137xv9IwACCSc"]
[Tue Jul 21 08:55:14.431231 2026] [security2:error] [pid 559070:tid 559237] [client 20.151.10.161:37724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-links.php"] [unique_id "al9eIiy1f1FtKC137xv9KAAAAbQ"]
[Tue Jul 21 08:55:14.478974 2026] [security2:error] [pid 559070:tid 559245] [client 198.204.224.34:33840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/re/embeds/19/index.php"] [unique_id "al9eIiy1f1FtKC137xv9KwAAAbw"], referer: http://roanalacerda.com.br/re/embeds/19/index.php
[Tue Jul 21 08:55:14.708503 2026] [security2:error] [pid 559070:tid 559253] [client 4.194.24.143:7329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/administrator/components/com_associations/layouts/joomla/searchtools/mainhack.php"] [unique_id "al9eIiy1f1FtKC137xv9LQAAAcQ"]
[Tue Jul 21 08:55:14.785428 2026] [security2:error] [pid 533360:tid 533610] [client 20.151.10.161:37853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9eInUPuLYrePtEkUclnAAAAPo"]
[Tue Jul 21 08:55:14.804119 2026] [security2:error] [pid 533360:tid 533575] [client 20.104.96.117:8083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/themes.php"] [unique_id "al9eInUPuLYrePtEkUclngAAANc"]
[Tue Jul 21 08:55:14.834325 2026] [security2:error] [pid 533360:tid 533613] [client 20.151.10.161:55843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9eInUPuLYrePtEkUclnwAAAP0"]
[Tue Jul 21 08:55:14.994542 2026] [security2:error] [pid 559070:tid 559286] [client 198.204.224.34:33850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/us/audits/6/index.php"] [unique_id "al9eIiy1f1FtKC137xv9MwAAAeU"], referer: http://roanalacerda.com.br/us/audits/6/index.php
[Tue Jul 21 08:55:15.141647 2026] [security2:error] [pid 533360:tid 533604] [client 212.32.76.3:52379] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/sketch/404.php"] [unique_id "al9eI3UPuLYrePtEkUclpQAAAPQ"]
[Tue Jul 21 08:55:15.142922 2026] [security2:error] [pid 533360:tid 533591] [client 20.151.10.161:45991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/25d653587fdfd1.php"] [unique_id "al9eI3UPuLYrePtEkUclpgAAAOc"]
[Tue Jul 21 08:55:15.159836 2026] [security2:error] [pid 559070:tid 559259] [client 20.151.10.161:37809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.hometohomelondon.com"] [uri "/aaa.php"] [unique_id "al9eIyy1f1FtKC137xv9NgAAAco"]
[Tue Jul 21 08:55:15.206856 2026] [security2:error] [pid 559070:tid 559312] [client 216.73.161.170:57725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9eIyy1f1FtKC137xv9OAAAAf8"]
[Tue Jul 21 08:55:15.227885 2026] [security2:error] [pid 559070:tid 559316] [client 20.220.225.223:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/byp8.php"] [unique_id "al9eIyy1f1FtKC137xv9OQAAAgM"]
[Tue Jul 21 08:55:15.306270 2026] [security2:error] [pid 533360:tid 533579] [client 198.204.224.34:33856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/us/query-content/7/index.php"] [unique_id "al9eI3UPuLYrePtEkUclrQAAANs"], referer: http://roanalacerda.com.br/us/query-content/7/index.php
[Tue Jul 21 08:55:15.584097 2026] [security2:error] [pid 533360:tid 533561] [client 20.104.96.117:7976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/.well-known/about.php"] [unique_id "al9eI3UPuLYrePtEkUclswAAAMk"]
[Tue Jul 21 08:55:15.609785 2026] [security2:error] [pid 559070:tid 559245] [client 15.235.27.2:30956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "issima.net.br"] [uri "/robots.txt"] [unique_id "al9eIyy1f1FtKC137xv9QgAAAbw"]
[Tue Jul 21 08:55:15.609891 2026] [security2:error] [pid 559070:tid 559245] [client 15.235.27.2:30956] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "issima.net.br"] [uri "/robots.txt"] [unique_id "al9eIyy1f1FtKC137xv9QgAAAbw"]
[Tue Jul 21 08:55:15.649789 2026] [security2:error] [pid 559070:tid 559247] [client 198.204.224.34:33866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/pro/78/index.php"] [unique_id "al9eIyy1f1FtKC137xv9RAAAAb4"], referer: http://roanalacerda.com.br/pro/78/index.php
[Tue Jul 21 08:55:15.728248 2026] [security2:error] [pid 559070:tid 559205] [client 4.194.24.143:18232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/ahax.php"] [unique_id "al9eIyy1f1FtKC137xv9RgAAAZQ"]
[Tue Jul 21 08:55:15.871717 2026] [security2:error] [pid 559070:tid 559283] [client 216.73.161.173:51275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.161.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vestfitness.com.br"] [uri "/wp-login.php"] [unique_id "al9eIyy1f1FtKC137xv9SAAAAeI"]
[Tue Jul 21 08:55:15.985331 2026] [security2:error] [pid 533360:tid 533497] [client 198.204.224.34:33876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/ra/12/index.php"] [unique_id "al9eI3UPuLYrePtEkUclvgAAAIk"], referer: http://roanalacerda.com.br/ra/12/index.php
[Tue Jul 21 08:55:16.016189 2026] [security2:error] [pid 559070:tid 559321] [client 20.220.225.223:21574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/wpx.php"] [unique_id "al9eJCy1f1FtKC137xv9SgAAAgg"]
[Tue Jul 21 08:55:16.030375 2026] [security2:error] [pid 559070:tid 559204] [client 113.22.144.139:53240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eJCy1f1FtKC137xv9SwAAAZM"]
[Tue Jul 21 08:55:16.030479 2026] [security2:error] [pid 559070:tid 559204] [client 113.22.144.139:53240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eJCy1f1FtKC137xv9SwAAAZM"]
[Tue Jul 21 08:55:16.111450 2026] [security2:error] [pid 559070:tid 559152] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eJCy1f1FtKC137xv9TwABllE"]
[Tue Jul 21 08:55:16.111577 2026] [security2:error] [pid 559070:tid 559207] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eJCy1f1FtKC137xv9TwABllE"]
[Tue Jul 21 08:55:16.214191 2026] [security2:error] [pid 559070:tid 559251] [client 20.104.96.117:7593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9eJCy1f1FtKC137xv9UQAAAcI"]
[Tue Jul 21 08:55:16.314231 2026] [security2:error] [pid 533360:tid 533535] [client 198.204.224.34:33890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/Avast/98/index.php"] [unique_id "al9eJHUPuLYrePtEkUclxQAAAK8"], referer: http://roanalacerda.com.br/Avast/98/index.php
[Tue Jul 21 08:55:16.357082 2026] [security2:error] [pid 559070:tid 559230] [client 20.151.10.161:51042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/footer.php"] [unique_id "al9eJCy1f1FtKC137xv9UwAAAa0"]
[Tue Jul 21 08:55:16.443819 2026] [security2:error] [pid 559070:tid 559235] [client 203.25.124.215:64221] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/languages/index.php"] [unique_id "al9eJCy1f1FtKC137xv9VgAAAbI"]
[Tue Jul 21 08:55:16.578830 2026] [security2:error] [pid 533360:tid 533505] [client 41.89.234.2:54227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eJHUPuLYrePtEkUclywAAAJE"]
[Tue Jul 21 08:55:16.578945 2026] [security2:error] [pid 533360:tid 533505] [client 41.89.234.2:54227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eJHUPuLYrePtEkUclywAAAJE"]
[Tue Jul 21 08:55:16.630089 2026] [security2:error] [pid 559070:tid 559258] [client 20.104.96.117:7569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wefile.php"] [unique_id "al9eJCy1f1FtKC137xv9XgAAAck"]
[Tue Jul 21 08:55:16.649282 2026] [security2:error] [pid 559070:tid 559275] [client 198.204.224.34:33896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/wp-includes/32/index.php"] [unique_id "al9eJCy1f1FtKC137xv9XwAAAdo"], referer: http://roanalacerda.com.br/wp-includes/32/index.php
[Tue Jul 21 08:55:16.806297 2026] [security2:error] [pid 559070:tid 559219] [client 194.99.104.35:48068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9eJCy1f1FtKC137xv9YQAAAaI"]
[Tue Jul 21 08:55:16.806375 2026] [security2:error] [pid 559070:tid 559219] [client 194.99.104.35:48068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9eJCy1f1FtKC137xv9YQAAAaI"]
[Tue Jul 21 08:55:16.808237 2026] [security2:error] [pid 559070:tid 559310] [client 4.194.24.143:7302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/ak.php"] [unique_id "al9eJCy1f1FtKC137xv9YgAAAf0"]
[Tue Jul 21 08:55:16.959709 2026] [security2:error] [pid 559070:tid 559204] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eJCy1f1FtKC137xv9YwABk0c"]
[Tue Jul 21 08:55:16.978764 2026] [security2:error] [pid 559070:tid 559286] [client 198.204.224.34:43666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/840cb/42/index.php"] [unique_id "al9eJCy1f1FtKC137xv9ZQAAAeU"], referer: http://roanalacerda.com.br/840cb/42/index.php
[Tue Jul 21 08:55:17.017618 2026] [security2:error] [pid 559070:tid 559277] [client 54.39.203.226:35816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "issima.net.br"] [uri "/"] [unique_id "al9eJSy1f1FtKC137xv9ZgAAAdw"]
[Tue Jul 21 08:55:17.017712 2026] [security2:error] [pid 559070:tid 559277] [client 54.39.203.226:35816] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "issima.net.br"] [uri "/"] [unique_id "al9eJSy1f1FtKC137xv9ZgAAAdw"]
[Tue Jul 21 08:55:17.047197 2026] [security2:error] [pid 559070:tid 559322] [client 182.189.99.211:48374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eJSy1f1FtKC137xv9aAAAAgk"]
[Tue Jul 21 08:55:17.047852 2026] [security2:error] [pid 559070:tid 559322] [client 182.189.99.211:48374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eJSy1f1FtKC137xv9aAAAAgk"]
[Tue Jul 21 08:55:17.112795 2026] [security2:error] [pid 559070:tid 559207] [client 20.104.96.117:7567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9eJSy1f1FtKC137xv9agAAAZY"]
[Tue Jul 21 08:55:17.195292 2026] [security2:error] [pid 559070:tid 559312] [client 194.99.104.35:38910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9eJSy1f1FtKC137xv9bAAAAf8"]
[Tue Jul 21 08:55:17.195398 2026] [security2:error] [pid 559070:tid 559312] [client 194.99.104.35:38910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9eJSy1f1FtKC137xv9bAAAAf8"]
[Tue Jul 21 08:55:17.220659 2026] [security2:error] [pid 559070:tid 559161] [remote 199.189.225.40:63733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "izabelreck.com"] [uri "/wp-login.php"] [unique_id "al9eJSy1f1FtKC137xv9bQABoVo"]
[Tue Jul 21 08:55:17.354641 2026] [security2:error] [pid 533360:tid 533579] [client 198.204.224.34:43668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.224.204.198.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "roanalacerda.com.br"] [uri "/us/10/index.php"] [unique_id "al9eJXUPuLYrePtEkUcl2gAAANs"], referer: http://roanalacerda.com.br/us/10/index.php
[Tue Jul 21 08:55:17.366171 2026] [security2:error] [pid 559070:tid 559301] [client 20.151.10.161:51049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-content/index.php"] [unique_id "al9eJSy1f1FtKC137xv9cQAAAfQ"]
[Tue Jul 21 08:55:17.380060 2026] [security2:error] [pid 533360:tid 533501] [client 65.21.113.253:43394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eJXUPuLYrePtEkUcl2wAAAI0"]
[Tue Jul 21 08:55:17.486610 2026] [security2:error] [pid 559070:tid 559248] [client 5.38.115.39:52851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eJSy1f1FtKC137xv9dAAAAb8"]
[Tue Jul 21 08:55:17.486744 2026] [security2:error] [pid 559070:tid 559248] [client 5.38.115.39:52851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eJSy1f1FtKC137xv9dAAAAb8"]
[Tue Jul 21 08:55:17.524962 2026] [security2:error] [pid 559070:tid 559326] [client 20.220.225.223:46386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/la.php"] [unique_id "al9eJSy1f1FtKC137xv9dQAAAg0"]
[Tue Jul 21 08:55:17.680552 2026] [security2:error] [pid 559070:tid 559281] [client 103.59.206.240:31058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eJSy1f1FtKC137xv9eQAAAeA"]
[Tue Jul 21 08:55:17.680705 2026] [security2:error] [pid 559070:tid 559281] [client 103.59.206.240:31058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eJSy1f1FtKC137xv9eQAAAeA"]
[Tue Jul 21 08:55:17.875776 2026] [security2:error] [pid 533360:tid 533541] [client 4.194.24.143:50387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/alfa-rex.php"] [unique_id "al9eJXUPuLYrePtEkUcl5AAAALU"]
[Tue Jul 21 08:55:17.888768 2026] [security2:error] [pid 559070:tid 559254] [client 20.151.10.161:49144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/admin.php"] [unique_id "al9eJSy1f1FtKC137xv9gAAAAcU"]
[Tue Jul 21 08:55:17.941028 2026] [security2:error] [pid 559070:tid 559297] [client 203.25.124.53:44261] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/media-new.php"] [unique_id "al9eJSy1f1FtKC137xv9ggAAAfA"]
[Tue Jul 21 08:55:17.992392 2026] [security2:error] [pid 559070:tid 559308] [client 194.99.104.35:48080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9eJSy1f1FtKC137xv9hAAAAfs"]
[Tue Jul 21 08:55:17.992509 2026] [security2:error] [pid 559070:tid 559308] [client 194.99.104.35:48080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9eJSy1f1FtKC137xv9hAAAAfs"]
[Tue Jul 21 08:55:18.031045 2026] [security2:error] [pid 559070:tid 559246] [client 20.104.96.117:7252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9eJiy1f1FtKC137xv9hgAAAb0"]
[Tue Jul 21 08:55:18.032582 2026] [security2:error] [pid 559070:tid 559112] [remote 104.207.46.162:33205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.46.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9eJSy1f1FtKC137xv9fwABySk"]
[Tue Jul 21 08:55:18.138863 2026] [security2:error] [pid 559070:tid 559105] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eJiy1f1FtKC137xv9iQAB5SI"]
[Tue Jul 21 08:55:18.139023 2026] [security2:error] [pid 559070:tid 559286] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eJiy1f1FtKC137xv9iQAB5SI"]
[Tue Jul 21 08:55:18.274575 2026] [security2:error] [pid 533360:tid 533599] [client 185.198.240.134:55575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "imperdivelbestpromotionofthedaytodayonly.com"] [uri "/wp-login.php"] [unique_id "al9eJnUPuLYrePtEkUcl6QAAAO8"]
[Tue Jul 21 08:55:18.536381 2026] [security2:error] [pid 559070:tid 559276] [client 65.21.113.253:41902] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eJiy1f1FtKC137xv9hwAAAds"]
[Tue Jul 21 08:55:18.703696 2026] [security2:error] [pid 559070:tid 559121] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eJiy1f1FtKC137xv9lwAB2jI"]
[Tue Jul 21 08:55:18.703886 2026] [security2:error] [pid 559070:tid 559275] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eJiy1f1FtKC137xv9lwAB2jI"]
[Tue Jul 21 08:55:18.752388 2026] [security2:error] [pid 559070:tid 559205] [client 20.151.10.161:51029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/zoro.php"] [unique_id "al9eJiy1f1FtKC137xv9mAAAAZQ"]
[Tue Jul 21 08:55:18.905990 2026] [security2:error] [pid 533360:tid 533617] [client 4.194.24.143:50417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/alfa.php"] [unique_id "al9eJnUPuLYrePtEkUcl9gAAAQE"]
[Tue Jul 21 08:55:19.120382 2026] [autoindex:error] [pid 533360:tid 533558] [client 198.235.24.59:60962] AH01276: Cannot serve directory /home2/italom32/condominiogreenvillage.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:55:19.127958 2026] [security2:error] [pid 533360:tid 533557] [client 20.151.10.161:49059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/greap.php"] [unique_id "al9eJ3UPuLYrePtEkUcl-wAAAMU"]
[Tue Jul 21 08:55:19.172344 2026] [security2:error] [pid 559070:tid 559246] [client 20.104.96.117:7290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/8.php"] [unique_id "al9eJyy1f1FtKC137xv9nwAAAb0"]
[Tue Jul 21 08:55:19.250577 2026] [security2:error] [pid 559070:tid 559299] [client 212.32.76.13:51557] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/tiny.php"] [unique_id "al9eJyy1f1FtKC137xv9ogAAAfI"]
[Tue Jul 21 08:55:19.320765 2026] [security2:error] [pid 559070:tid 559210] [client 20.197.192.193:61060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9eJyy1f1FtKC137xv9owAAAZk"]
[Tue Jul 21 08:55:19.698229 2026] [security2:error] [pid 559070:tid 559225] [client 20.151.10.161:50979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/admin.php"] [unique_id "al9eJyy1f1FtKC137xv9qgAAAag"]
[Tue Jul 21 08:55:19.969397 2026] [security2:error] [pid 559070:tid 559221] [client 4.194.24.143:7872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/amax.php"] [unique_id "al9eJyy1f1FtKC137xv9rgAAAaQ"]
[Tue Jul 21 08:55:19.974341 2026] [security2:error] [pid 533360:tid 533571] [client 20.104.96.117:7978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-content/admin.php"] [unique_id "al9eJ3UPuLYrePtEkUcmDQAAANM"]
[Tue Jul 21 08:55:20.187429 2026] [security2:error] [pid 559070:tid 559224] [client 59.95.197.55:51899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eKCy1f1FtKC137xv9sQAAAac"]
[Tue Jul 21 08:55:20.187442 2026] [security2:error] [pid 559070:tid 559212] [client 20.197.192.193:63890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/wander.php"] [unique_id "al9eKCy1f1FtKC137xv9sgAAAZs"]
[Tue Jul 21 08:55:20.187565 2026] [security2:error] [pid 559070:tid 559224] [client 59.95.197.55:51899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eKCy1f1FtKC137xv9sQAAAac"]
[Tue Jul 21 08:55:20.192332 2026] [security2:error] [pid 559070:tid 559252] [client 20.151.10.161:45980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wefile.php"] [unique_id "al9eKCy1f1FtKC137xv9swAAAcM"]
[Tue Jul 21 08:55:20.317868 2026] [security2:error] [pid 559070:tid 559219] [client 20.151.10.161:49033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/177.php"] [unique_id "al9eKCy1f1FtKC137xv9tQAAAaI"]
[Tue Jul 21 08:55:20.460346 2026] [security2:error] [pid 559070:tid 559227] [client 20.104.96.117:7952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/f6.php"] [unique_id "al9eKCy1f1FtKC137xv9ugAAAao"]
[Tue Jul 21 08:55:20.465383 2026] [security2:error] [pid 533360:tid 533523] [client 2a04:c300:400::99:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.joseantoniopereira1782236338228.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9eKHUPuLYrePtEkUcmFgAAAKM"]
[Tue Jul 21 08:55:20.525698 2026] [security2:error] [pid 559070:tid 559246] [client 20.151.10.161:51035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/greap.php"] [unique_id "al9eKCy1f1FtKC137xv9vgAAAb0"]
[Tue Jul 21 08:55:20.626048 2026] [security2:error] [pid 559070:tid 559259] [client 128.127.105.184:48908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9eKCy1f1FtKC137xv9wQAAAco"]
[Tue Jul 21 08:55:20.626177 2026] [security2:error] [pid 559070:tid 559259] [client 128.127.105.184:48908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9eKCy1f1FtKC137xv9wQAAAco"]
[Tue Jul 21 08:55:20.627343 2026] [security2:error] [pid 533360:tid 533499] [client 2a04:c300:400::99:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.joseantoniopereira1782236338228.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9eKHUPuLYrePtEkUcmGgAAAIs"]
[Tue Jul 21 08:55:20.826974 2026] [security2:error] [pid 559070:tid 559211] [client 2a04:c300:400::99:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.joseantoniopereira1782236338228.0711679.meusitehostgator.com.br"] [uri "/backend/.env"] [unique_id "al9eKCy1f1FtKC137xv9zgAAAZo"]
[Tue Jul 21 08:55:20.915439 2026] [security2:error] [pid 559070:tid 559282] [client 185.213.175.37:29826] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bracksimoveis.com.br"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al9eKCy1f1FtKC137xv90gAAAeE"]
[Tue Jul 21 08:55:20.924275 2026] [security2:error] [pid 559070:tid 559220] [client 20.197.192.193:56809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/fffm.php"] [unique_id "al9eKCy1f1FtKC137xv90wAAAaM"]
[Tue Jul 21 08:55:20.997835 2026] [security2:error] [pid 559070:tid 559212] [client 20.104.96.117:7565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/inputs.php"] [unique_id "al9eKCy1f1FtKC137xv91QAAAZs"]
[Tue Jul 21 08:55:21.032935 2026] [security2:error] [pid 559070:tid 559218] [client 4.194.24.143:20410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/archive.php"] [unique_id "al9eKSy1f1FtKC137xv92QAAAaE"]
[Tue Jul 21 08:55:21.036851 2026] [security2:error] [pid 559070:tid 559325] [client 20.151.10.161:55846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/177.php"] [unique_id "al9eKSy1f1FtKC137xv92gAAAgw"]
[Tue Jul 21 08:55:21.085143 2026] [access_compat:error] [pid 559070:tid 559275] [client 162.241.63.68:57866] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:55:21.234377 2026] [security2:error] [pid 533360:tid 533510] [client 114.198.138.124:64422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eKXUPuLYrePtEkUcmKwAAAJY"]
[Tue Jul 21 08:55:21.234470 2026] [security2:error] [pid 533360:tid 533510] [client 114.198.138.124:64422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eKXUPuLYrePtEkUcmKwAAAJY"]
[Tue Jul 21 08:55:21.244324 2026] [security2:error] [pid 559070:tid 559304] [client 20.220.225.223:48229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/berlin.php"] [unique_id "al9eKSy1f1FtKC137xv94AAAAfc"]
[Tue Jul 21 08:55:21.276653 2026] [security2:error] [pid 533360:tid 533546] [client 20.220.225.223:22977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9eKXUPuLYrePtEkUcmLAAAALo"]
[Tue Jul 21 08:55:21.381492 2026] [security2:error] [pid 533360:tid 533549] [client 20.104.96.117:7236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/inputs.php"] [unique_id "al9eKXUPuLYrePtEkUcmLgAAAL0"]
[Tue Jul 21 08:55:21.439385 2026] [security2:error] [pid 559070:tid 559258] [client 203.25.124.65:40335] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/license.php"] [unique_id "al9eKSy1f1FtKC137xv94gAAAck"]
[Tue Jul 21 08:55:21.497266 2026] [security2:error] [pid 533360:tid 533497] [client 172.234.129.144:53362] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "ericksheik.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9eKXUPuLYrePtEkUcmMgAAAIk"]
[Tue Jul 21 08:55:21.618088 2026] [security2:error] [pid 533360:tid 533535] [client 172.234.129.144:53362] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "ericksheik.com.br"] [uri "/"] [unique_id "al9eKXUPuLYrePtEkUcmNgAAAK8"]
[Tue Jul 21 08:55:21.648194 2026] [autoindex:error] [pid 559070:tid 559232] [client 100.50.152.193:0] AH01276: Cannot serve directory /home4/conte946/produtosnapromo.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:55:21.758692 2026] [security2:error] [pid 559070:tid 559203] [client 20.104.96.117:7942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/classwithtostring.php"] [unique_id "al9eKSy1f1FtKC137xv96wAAAZI"]
[Tue Jul 21 08:55:21.831553 2026] [security2:error] [pid 533360:tid 533595] [client 65.21.113.253:43394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eKXUPuLYrePtEkUcmOwAAAOs"]
[Tue Jul 21 08:55:21.940916 2026] [security2:error] [pid 559070:tid 559198] [remote 188.164.197.230:54608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9eKSy1f1FtKC137xv98AAB_38"]
[Tue Jul 21 08:55:21.944852 2026] [security2:error] [pid 559070:tid 559235] [client 20.151.10.161:50947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/199.php"] [unique_id "al9eKSy1f1FtKC137xv98QAAAbI"]
[Tue Jul 21 08:55:22.058438 2026] [security2:error] [pid 559070:tid 559214] [client 4.194.24.143:7885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/as.php"] [unique_id "al9eKiy1f1FtKC137xv99gAAAZ0"]
[Tue Jul 21 08:55:22.077602 2026] [security2:error] [pid 559070:tid 559290] [client 20.220.225.223:21577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/billur.php"] [unique_id "al9eKiy1f1FtKC137xv99wAAAek"]
[Tue Jul 21 08:55:22.183132 2026] [security2:error] [pid 559070:tid 559298] [client 20.104.96.117:7249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9eKiy1f1FtKC137xv9-QAAAfE"]
[Tue Jul 21 08:55:22.546626 2026] [security2:error] [pid 533360:tid 533584] [client 203.25.124.66:48363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/av.php"] [unique_id "al9eKnUPuLYrePtEkUcmSQAAAOA"]
[Tue Jul 21 08:55:22.597156 2026] [security2:error] [pid 533360:tid 533591] [client 20.151.10.161:55814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file52.php"] [unique_id "al9eKnUPuLYrePtEkUcmSwAAAOc"]
[Tue Jul 21 08:55:22.644195 2026] [autoindex:error] [pid 533360:tid 533601] [client 20.151.10.161:46064] AH01276: Cannot serve directory /home3/housei59/public_html/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:55:22.668741 2026] [security2:error] [pid 559070:tid 559322] [client 20.104.96.117:7562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-blog.php"] [unique_id "al9eKiy1f1FtKC137xv-AgAAAgk"]
[Tue Jul 21 08:55:22.924169 2026] [security2:error] [pid 533360:tid 533527] [client 65.21.113.253:47524] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eKnUPuLYrePtEkUcmSAAAAKc"]
[Tue Jul 21 08:55:22.977445 2026] [autoindex:error] [pid 533360:tid 533531] [client 20.151.10.161:46064] AH01276: Cannot serve directory /home3/housei59/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:55:23.108726 2026] [security2:error] [pid 559070:tid 559258] [client 4.194.24.143:7330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/asd.php"] [unique_id "al9eKyy1f1FtKC137xv-DgAAAck"]
[Tue Jul 21 08:55:23.122885 2026] [security2:error] [pid 559070:tid 559301] [client 20.197.192.193:27099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/bscclapb.php"] [unique_id "al9eKyy1f1FtKC137xv-DwAAAfQ"]
[Tue Jul 21 08:55:23.133931 2026] [security2:error] [pid 533360:tid 533507] [client 20.151.10.161:46064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al9eK3UPuLYrePtEkUcmVgAAAJM"]
[Tue Jul 21 08:55:23.177927 2026] [security2:error] [pid 559070:tid 559281] [client 20.104.96.117:7264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-content/admin.php"] [unique_id "al9eKyy1f1FtKC137xv-EgAAAeA"]
[Tue Jul 21 08:55:23.391923 2026] [security2:error] [pid 533360:tid 533561] [client 20.151.10.161:48583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/199.php"] [unique_id "al9eK3UPuLYrePtEkUcmWQAAAMk"]
[Tue Jul 21 08:55:23.441788 2026] [security2:error] [pid 559070:tid 559282] [client 203.25.124.73:30017] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-login-css.php"] [unique_id "al9eKyy1f1FtKC137xv-PAAAAeE"]
[Tue Jul 21 08:55:23.706403 2026] [security2:error] [pid 559070:tid 559307] [client 20.104.96.117:7940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/ms-edit.php"] [unique_id "al9eKyy1f1FtKC137xv-TAAAAfo"]
[Tue Jul 21 08:55:24.098721 2026] [security2:error] [pid 559070:tid 559207] [client 20.151.10.161:46015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/2P.php"] [unique_id "al9eLCy1f1FtKC137xv-VQAAAZY"]
[Tue Jul 21 08:55:24.120890 2026] [security2:error] [pid 559070:tid 559218] [client 20.151.10.161:55871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/122.php"] [unique_id "al9eLCy1f1FtKC137xv-VgAAAaE"]
[Tue Jul 21 08:55:24.170926 2026] [security2:error] [pid 533360:tid 533522] [client 20.220.225.223:21585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/mimpi.php"] [unique_id "al9eLHUPuLYrePtEkUcmbQAAAKI"]
[Tue Jul 21 08:55:24.172658 2026] [security2:error] [pid 533360:tid 533599] [client 4.194.24.143:50414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/assets/class-wp-http-client.php"] [unique_id "al9eLHUPuLYrePtEkUcmbgAAAO8"]
[Tue Jul 21 08:55:24.296698 2026] [security2:error] [pid 559070:tid 559304] [client 20.104.96.117:7575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/cgi-bin/index.php"] [unique_id "al9eLCy1f1FtKC137xv-WAAAAfc"]
[Tue Jul 21 08:55:24.540605 2026] [security2:error] [pid 559070:tid 559291] [client 203.25.124.41:25489] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/classwithtostring.php"] [unique_id "al9eLCy1f1FtKC137xv-XQAAAeo"]
[Tue Jul 21 08:55:24.675934 2026] [security2:error] [pid 559070:tid 559169] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eLCy1f1FtKC137xv-YgABtWI"]
[Tue Jul 21 08:55:24.676054 2026] [security2:error] [pid 559070:tid 559238] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eLCy1f1FtKC137xv-YgABtWI"]
[Tue Jul 21 08:55:24.793619 2026] [security2:error] [pid 559070:tid 559300] [client 20.151.10.161:46014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/.well-known/about.php"] [unique_id "al9eLCy1f1FtKC137xv-YwAAAfM"]
[Tue Jul 21 08:55:25.199613 2026] [security2:error] [pid 559070:tid 559216] [client 4.194.24.143:18180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/atomlib.php"] [unique_id "al9eLSy1f1FtKC137xv-bAAAAZ8"]
[Tue Jul 21 08:55:25.224200 2026] [security2:error] [pid 559070:tid 559237] [client 20.151.10.161:50997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/green1.php"] [unique_id "al9eLSy1f1FtKC137xv-bQAAAbQ"]
[Tue Jul 21 08:55:25.271241 2026] [security2:error] [pid 559070:tid 559284] [client 20.104.96.117:7996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/BDKR28WP.php"] [unique_id "al9eLSy1f1FtKC137xv-cAAAAeM"]
[Tue Jul 21 08:55:25.437073 2026] [security2:error] [pid 533360:tid 533601] [client 212.32.76.11:56847] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Text/Diff/Engine/template-singl-portfolio.php"] [unique_id "al9eLXUPuLYrePtEkUcmhwAAAPE"]
[Tue Jul 21 08:55:25.628685 2026] [security2:error] [pid 559070:tid 559204] [client 20.151.10.161:46051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9eLSy1f1FtKC137xv-dwAAAZM"]
[Tue Jul 21 08:55:25.854450 2026] [security2:error] [pid 559070:tid 559242] [client 168.167.81.163:63524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eLSy1f1FtKC137xv-gQAAAbk"]
[Tue Jul 21 08:55:25.854545 2026] [security2:error] [pid 559070:tid 559242] [client 168.167.81.163:63524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eLSy1f1FtKC137xv-gQAAAbk"]
[Tue Jul 21 08:55:26.250876 2026] [security2:error] [pid 559070:tid 559220] [client 20.151.10.161:46073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/bob.php"] [unique_id "al9eLiy1f1FtKC137xv-jAAAAaM"]
[Tue Jul 21 08:55:26.275311 2026] [security2:error] [pid 559070:tid 559222] [client 4.194.24.143:7319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/autoload_classmap.php"] [unique_id "al9eLiy1f1FtKC137xv-jQAAAaU"]
[Tue Jul 21 08:55:26.319570 2026] [security2:error] [pid 559070:tid 559322] [client 20.104.96.117:7949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/abcd.php"] [unique_id "al9eLiy1f1FtKC137xv-jgAAAgk"]
[Tue Jul 21 08:55:26.631696 2026] [security2:error] [pid 559070:tid 559273] [client 20.151.10.161:51017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/biufile.php"] [unique_id "al9eLiy1f1FtKC137xv-kgAAAdg"]
[Tue Jul 21 08:55:26.635747 2026] [security2:error] [pid 533360:tid 533532] [client 203.25.124.58:61491] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "al9eLnUPuLYrePtEkUcmnwAAAKw"]
[Tue Jul 21 08:55:26.748790 2026] [security2:error] [pid 533360:tid 533602] [client 65.21.113.253:43394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eLnUPuLYrePtEkUcmogAAAPI"]
[Tue Jul 21 08:55:26.828394 2026] [security2:error] [pid 559070:tid 559286] [client 20.104.96.117:7972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/file15.php"] [unique_id "al9eLiy1f1FtKC137xv-lwAAAeU"]
[Tue Jul 21 08:55:26.893110 2026] [security2:error] [pid 559070:tid 559140] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eLiy1f1FtKC137xv-mQABxUU"]
[Tue Jul 21 08:55:26.893251 2026] [security2:error] [pid 559070:tid 559254] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eLiy1f1FtKC137xv-mQABxUU"]
[Tue Jul 21 08:55:27.011900 2026] [security2:error] [pid 533360:tid 533497] [client 20.151.10.161:49100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/file52.php"] [unique_id "al9eL3UPuLYrePtEkUcmpgAAAIk"]
[Tue Jul 21 08:55:27.137309 2026] [security2:error] [pid 559070:tid 559246] [client 41.89.234.2:54697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eLyy1f1FtKC137xv-ngAAAb0"]
[Tue Jul 21 08:55:27.137435 2026] [security2:error] [pid 559070:tid 559246] [client 41.89.234.2:54697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eLyy1f1FtKC137xv-ngAAAb0"]
[Tue Jul 21 08:55:27.156425 2026] [security2:error] [pid 533360:tid 533599] [client 113.22.144.139:53789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eL3UPuLYrePtEkUcmqgAAAO8"]
[Tue Jul 21 08:55:27.156802 2026] [security2:error] [pid 533360:tid 533599] [client 113.22.144.139:53789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eL3UPuLYrePtEkUcmqgAAAO8"]
[Tue Jul 21 08:55:27.339063 2026] [security2:error] [pid 559070:tid 559298] [client 212.32.76.3:43431] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/lock360.php"] [unique_id "al9eLyy1f1FtKC137xv-owAAAfE"]
[Tue Jul 21 08:55:27.380580 2026] [security2:error] [pid 533360:tid 533594] [client 4.194.24.143:7939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/av.php"] [unique_id "al9eL3UPuLYrePtEkUcmswAAAOo"]
[Tue Jul 21 08:55:27.425600 2026] [autoindex:error] [pid 559070:tid 559326] [client 20.151.10.161:46055] AH01276: Cannot serve directory /home3/housei59/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:55:27.509596 2026] [security2:error] [pid 533360:tid 533598] [client 20.104.96.117:7605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/jp.php"] [unique_id "al9eL3UPuLYrePtEkUcmtQAAAO4"]
[Tue Jul 21 08:55:27.527625 2026] [security2:error] [pid 533360:tid 533516] [client 182.189.99.211:48333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eL3UPuLYrePtEkUcmtwAAAJw"]
[Tue Jul 21 08:55:27.527750 2026] [security2:error] [pid 533360:tid 533516] [client 182.189.99.211:48333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eL3UPuLYrePtEkUcmtwAAAJw"]
[Tue Jul 21 08:55:27.592838 2026] [security2:error] [pid 559070:tid 559265] [client 20.52.136.55:1552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/class-t.api.php"] [unique_id "al9eLyy1f1FtKC137xv-qQAAAdA"]
[Tue Jul 21 08:55:27.738599 2026] [security2:error] [pid 559070:tid 559222] [client 20.197.192.193:61072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/jga.php"] [unique_id "al9eLyy1f1FtKC137xv-rgAAAaU"]
[Tue Jul 21 08:55:27.776967 2026] [autoindex:error] [pid 559070:tid 559220] [client 20.151.10.161:46055] AH01276: Cannot serve directory /home3/housei59/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:55:27.798402 2026] [security2:error] [pid 559070:tid 559221] [client 2a04:c300:400::99:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.luizaugustoqueirozfe1782236343065.0711679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9eLyy1f1FtKC137xv-rwAAAaQ"]
[Tue Jul 21 08:55:27.804743 2026] [security2:error] [pid 559070:tid 559317] [client 65.21.113.253:47534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eLyy1f1FtKC137xv-pgAAAgQ"]
[Tue Jul 21 08:55:27.886588 2026] [security2:error] [pid 533360:tid 533572] [client 20.151.10.161:50944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wpconf.php"] [unique_id "al9eL3UPuLYrePtEkUcmwQAAANQ"]
[Tue Jul 21 08:55:27.914576 2026] [security2:error] [pid 559070:tid 559322] [client 20.151.10.161:46055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/crgio.php"] [unique_id "al9eLyy1f1FtKC137xv-sAAAAgk"]
[Tue Jul 21 08:55:27.948929 2026] [security2:error] [pid 533360:tid 533502] [client 2a04:c300:400::99:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.luizaugustoqueirozfe1782236343065.0711679.meusitehostgator.com.br"] [uri "/backend/.env"] [unique_id "al9eL3UPuLYrePtEkUcmxAAAAI4"]
[Tue Jul 21 08:55:27.965106 2026] [security2:error] [pid 559070:tid 559299] [client 2a04:c300:400::99:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.luizaugustoqueirozfe1782236343065.0711679.meusitehostgator.com.br"] [uri "/api/.env"] [unique_id "al9eLyy1f1FtKC137xv-ugAAAfI"]
[Tue Jul 21 08:55:28.015757 2026] [security2:error] [pid 559070:tid 559273] [client 20.104.96.117:7266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/f35.php"] [unique_id "al9eMCy1f1FtKC137xv-vQAAAdg"]
[Tue Jul 21 08:55:28.132978 2026] [security2:error] [pid 533360:tid 533615] [client 20.197.192.193:56795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/ftde.php"] [unique_id "al9eMHUPuLYrePtEkUcmyQAAAP8"]
[Tue Jul 21 08:55:28.150566 2026] [security2:error] [pid 533360:tid 533561] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eMHUPuLYrePtEkUcmxgAAyUo"]
[Tue Jul 21 08:55:28.200808 2026] [security2:error] [pid 559070:tid 559286] [client 20.151.10.161:45906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/pucci.php"] [unique_id "al9eMCy1f1FtKC137xv-wgAAAeU"]
[Tue Jul 21 08:55:28.232742 2026] [security2:error] [pid 559070:tid 559318] [client 5.38.115.39:53416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eMCy1f1FtKC137xv-wwAAAgU"]
[Tue Jul 21 08:55:28.232877 2026] [security2:error] [pid 559070:tid 559318] [client 5.38.115.39:53416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eMCy1f1FtKC137xv-wwAAAgU"]
[Tue Jul 21 08:55:28.454422 2026] [security2:error] [pid 559070:tid 559225] [client 4.194.24.143:7316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/b.php"] [unique_id "al9eMCy1f1FtKC137xv-xgAAAag"]
[Tue Jul 21 08:55:28.541785 2026] [security2:error] [pid 559070:tid 559235] [client 20.220.225.223:60269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/dp.php"] [unique_id "al9eMCy1f1FtKC137xv-yQAAAbI"]
[Tue Jul 21 08:55:28.544877 2026] [security2:error] [pid 559070:tid 559212] [client 203.25.124.2:52931] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/alfa.php"] [unique_id "al9eMCy1f1FtKC137xv-ygAAAZs"]
[Tue Jul 21 08:55:28.617855 2026] [security2:error] [pid 559070:tid 559095] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eMCy1f1FtKC137xv-zQAB8xg"]
[Tue Jul 21 08:55:28.618051 2026] [security2:error] [pid 559070:tid 559300] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eMCy1f1FtKC137xv-zQAB8xg"]
[Tue Jul 21 08:55:28.628451 2026] [security2:error] [pid 559070:tid 559185] [remote 192.241.143.148:44604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9eMCy1f1FtKC137xv-zgAB_3I"]
[Tue Jul 21 08:55:28.648245 2026] [security2:error] [pid 559070:tid 559294] [client 20.104.96.117:7584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-load.php"] [unique_id "al9eMCy1f1FtKC137xv-zwAAAe0"]
[Tue Jul 21 08:55:28.676318 2026] [proxy:error] [pid 533360:tid 533514] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:55:28.676382 2026] [proxy_http:error] [pid 533360:tid 533514] [client 198.235.24.66:61254] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:55:28.677609 2026] [proxy:error] [pid 533360:tid 533514] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:55:28.677646 2026] [proxy_http:error] [pid 533360:tid 533514] [client 198.235.24.66:61254] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:55:28.682268 2026] [autoindex:error] [pid 559070:tid 559247] [client 20.151.10.161:46059] AH01276: Cannot serve directory /home3/housei59/public_html/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:55:28.910400 2026] [security2:error] [pid 533360:tid 533497] [client 20.151.10.161:55889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/mosty.php"] [unique_id "al9eMHUPuLYrePtEkUcm3AAAAIk"]
[Tue Jul 21 08:55:28.979707 2026] [autoindex:error] [pid 559070:tid 559263] [client 20.151.10.161:46059] AH01276: Cannot serve directory /home3/housei59/public_html/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:55:29.120316 2026] [security2:error] [pid 559070:tid 559227] [client 20.151.10.161:46059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-temp.php"] [unique_id "al9eMSy1f1FtKC137xv-2wAAAao"]
[Tue Jul 21 08:55:29.187247 2026] [security2:error] [pid 559070:tid 559072] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eMSy1f1FtKC137xv-3QABqwE"]
[Tue Jul 21 08:55:29.187387 2026] [security2:error] [pid 559070:tid 559228] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eMSy1f1FtKC137xv-3QABqwE"]
[Tue Jul 21 08:55:29.377665 2026] [security2:error] [pid 533360:tid 533562] [client 20.220.225.223:52654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/user.php"] [unique_id "al9eMXUPuLYrePtEkUcm5wAAAMo"]
[Tue Jul 21 08:55:29.430076 2026] [security2:error] [pid 533360:tid 533607] [client 103.59.206.240:31508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eMXUPuLYrePtEkUcm6QAAAPc"]
[Tue Jul 21 08:55:29.430201 2026] [security2:error] [pid 533360:tid 533607] [client 103.59.206.240:31508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eMXUPuLYrePtEkUcm6QAAAPc"]
[Tue Jul 21 08:55:29.437505 2026] [security2:error] [pid 533360:tid 533434] [remote 85.204.70.100:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "serri.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9eMXUPuLYrePtEkUcm6gAA1UY"]
[Tue Jul 21 08:55:29.488005 2026] [security2:error] [pid 559070:tid 559259] [client 4.194.24.143:7892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/backup.php"] [unique_id "al9eMSy1f1FtKC137xv-4AAAAco"]
[Tue Jul 21 08:55:29.544691 2026] [security2:error] [pid 559070:tid 559266] [client 212.32.76.14:34359] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/maint/index.php"] [unique_id "al9eMSy1f1FtKC137xv-4QAAAdE"]
[Tue Jul 21 08:55:29.582197 2026] [security2:error] [pid 559070:tid 559193] [remote 85.204.70.100:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "serri.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eMSy1f1FtKC137xv-4gACBXo"]
[Tue Jul 21 08:55:29.679924 2026] [autoindex:error] [pid 559070:tid 559238] [client 20.151.10.161:46070] AH01276: Cannot serve directory /home3/housei59/public_html/wp-includes/blocks/buttons/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:55:29.944321 2026] [security2:error] [pid 559070:tid 559212] [client 20.151.10.161:55850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/dejavu.php"] [unique_id "al9eMSy1f1FtKC137xv-6AAAAZs"]
[Tue Jul 21 08:55:29.953545 2026] [security2:error] [pid 559070:tid 559216] [client 20.151.10.161:46070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-admin/js/index.php"] [unique_id "al9eMSy1f1FtKC137xv-6QAAAZ8"]
[Tue Jul 21 08:55:30.122639 2026] [security2:error] [pid 559070:tid 559294] [client 20.104.96.117:7589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/xyn.php"] [unique_id "al9eMiy1f1FtKC137xv-6gAAAe0"]
[Tue Jul 21 08:55:30.326575 2026] [security2:error] [pid 533360:tid 533519] [client 20.220.225.223:21625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/bootstrap.php"] [unique_id "al9eMnUPuLYrePtEkUcm_QAAAJ8"]
[Tue Jul 21 08:55:30.523482 2026] [security2:error] [pid 559070:tid 559092] [remote 41.186.86.12:33866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9eMiy1f1FtKC137xv-7wACDBU"]
[Tue Jul 21 08:55:30.551319 2026] [security2:error] [pid 533360:tid 533589] [client 4.194.24.143:7961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/baio/class-wp-http-client.php"] [unique_id "al9eMnUPuLYrePtEkUcnAgAAAOU"]
[Tue Jul 21 08:55:30.638658 2026] [security2:error] [pid 533360:tid 533577] [client 203.25.124.58:33023] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/templates/atomic/templates.php"] [unique_id "al9eMnUPuLYrePtEkUcnAwAAANk"]
[Tue Jul 21 08:55:30.663866 2026] [security2:error] [pid 559070:tid 559300] [client 59.95.197.55:52372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eMiy1f1FtKC137xv-8QAAAfM"]
[Tue Jul 21 08:55:30.663960 2026] [security2:error] [pid 559070:tid 559300] [client 59.95.197.55:52372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eMiy1f1FtKC137xv-8QAAAfM"]
[Tue Jul 21 08:55:30.768041 2026] [security2:error] [pid 533360:tid 533511] [client 20.197.192.193:27196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/else1.php"] [unique_id "al9eMnUPuLYrePtEkUcnCQAAAJc"]
[Tue Jul 21 08:55:30.939879 2026] [security2:error] [pid 559070:tid 559310] [client 20.151.10.161:45999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/puc.php"] [unique_id "al9eMiy1f1FtKC137xv-9AAAAf0"]
[Tue Jul 21 08:55:31.074312 2026] [security2:error] [pid 559070:tid 559307] [client 34.91.115.13:57344] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.grupotecc.com.br"] [uri "/"] [unique_id "al9eMyy1f1FtKC137xv--AAAAfo"]
[Tue Jul 21 08:55:31.074410 2026] [security2:error] [pid 559070:tid 559307] [client 34.91.115.13:57344] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.grupotecc.com.br"] [uri "/"] [unique_id "al9eMyy1f1FtKC137xv--AAAAfo"]
[Tue Jul 21 08:55:31.206123 2026] [security2:error] [pid 533360:tid 533497] [client 20.151.10.161:51015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/aaf.php"] [unique_id "al9eM3UPuLYrePtEkUcnEgAAAIk"]
[Tue Jul 21 08:55:31.624729 2026] [security2:error] [pid 533360:tid 533590] [client 4.194.24.143:7891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/bak.php"] [unique_id "al9eM3UPuLYrePtEkUcnHQAAAOY"]
[Tue Jul 21 08:55:31.869025 2026] [security2:error] [pid 533360:tid 533562] [client 114.198.138.124:64998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eM3UPuLYrePtEkUcnJgAAAMo"]
[Tue Jul 21 08:55:31.869128 2026] [security2:error] [pid 533360:tid 533562] [client 114.198.138.124:64998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eM3UPuLYrePtEkUcnJgAAAMo"]
[Tue Jul 21 08:55:31.932297 2026] [security2:error] [pid 533360:tid 533584] [client 20.151.10.161:49041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/122.php"] [unique_id "al9eM3UPuLYrePtEkUcnKAAAAOA"]
[Tue Jul 21 08:55:31.935582 2026] [security2:error] [pid 559070:tid 559267] [client 69.171.230.23:45338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eMyy1f1FtKC137xv_CQAAAdI"]
[Tue Jul 21 08:55:32.019608 2026] [security2:error] [pid 533360:tid 533370] [remote 162.19.246.208:35794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9eNHUPuLYrePtEkUcnKwAAnAY"]
[Tue Jul 21 08:55:32.037011 2026] [security2:error] [pid 533360:tid 533581] [client 203.25.124.31:50413] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-links.php"] [unique_id "al9eNHUPuLYrePtEkUcnLAAAAN0"]
[Tue Jul 21 08:55:32.099632 2026] [security2:error] [pid 559070:tid 559275] [client 20.220.225.223:52642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/ops.php"] [unique_id "al9eNCy1f1FtKC137xv_CwAAAdo"]
[Tue Jul 21 08:55:32.100043 2026] [core:error] [pid 559070:tid 559214] [client 144.225.6.182:54880] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Tue Jul 21 08:55:32.119245 2026] [security2:error] [pid 533360:tid 533539] [client 65.21.113.253:54964] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9eNHUPuLYrePtEkUcnMAAAALM"]
[Tue Jul 21 08:55:32.216669 2026] [security2:error] [pid 533360:tid 533572] [client 20.104.96.117:7591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/ccc.php"] [unique_id "al9eNHUPuLYrePtEkUcnNAAAANQ"]
[Tue Jul 21 08:55:32.389329 2026] [security2:error] [pid 559070:tid 559288] [client 173.252.95.11:49448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eNCy1f1FtKC137xv_EAAAAec"]
[Tue Jul 21 08:55:32.461143 2026] [security2:error] [pid 533360:tid 533415] [remote 85.204.70.100:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "serri.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eNHUPuLYrePtEkUcnPAAAlzM"]
[Tue Jul 21 08:55:32.461344 2026] [security2:error] [pid 533360:tid 533511] [client 85.204.70.100:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "serri.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eNHUPuLYrePtEkUcnPAAAlzM"]
[Tue Jul 21 08:55:32.468911 2026] [security2:error] [pid 559070:tid 559317] [client 20.151.10.161:50984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/term.php"] [unique_id "al9eNCy1f1FtKC137xv_EwAAAgQ"]
[Tue Jul 21 08:55:32.569352 2026] [security2:error] [pid 533360:tid 533600] [client 20.220.225.223:21927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/wp-editor.php"] [unique_id "al9eNHUPuLYrePtEkUcnQwAAAPA"]
[Tue Jul 21 08:55:32.680748 2026] [security2:error] [pid 533360:tid 533499] [client 4.194.24.143:24034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/bdkr28wp.php"] [unique_id "al9eNHUPuLYrePtEkUcnRQAAAIs"]
[Tue Jul 21 08:55:32.769445 2026] [security2:error] [pid 559070:tid 559145] [remote 64.225.121.94:52510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "projetoflechas.org.br"] [uri "/wp-login.php"] [unique_id "al9eNCy1f1FtKC137xv_FwAB80o"]
[Tue Jul 21 08:55:32.859802 2026] [security2:error] [pid 559070:tid 559230] [client 20.151.10.161:45981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/themes.php"] [unique_id "al9eNCy1f1FtKC137xv_GwAAAa0"]
[Tue Jul 21 08:55:32.951590 2026] [security2:error] [pid 559070:tid 559299] [client 65.21.113.253:41570] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eNCy1f1FtKC137xv_GAAAAfI"]
[Tue Jul 21 08:55:33.418017 2026] [security2:error] [pid 559070:tid 559325] [client 65.21.113.253:54970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eNSy1f1FtKC137xv_JgAAAgw"]
[Tue Jul 21 08:55:33.444807 2026] [security2:error] [pid 559070:tid 559321] [client 212.32.76.7:60785] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al9eNSy1f1FtKC137xv_JwAAAgg"]
[Tue Jul 21 08:55:33.517865 2026] [security2:error] [pid 533360:tid 533372] [remote 72.167.132.114:34922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "issimastore.com"] [uri "/wp-login.php"] [unique_id "al9eNXUPuLYrePtEkUcnVQAAhgg"]
[Tue Jul 21 08:55:33.527440 2026] [security2:error] [pid 559070:tid 559209] [client 20.151.10.161:49107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/green1.php"] [unique_id "al9eNSy1f1FtKC137xv_KAAAAZg"]
[Tue Jul 21 08:55:33.662118 2026] [security2:error] [pid 533360:tid 533558] [client 20.197.192.193:63879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/x.php"] [unique_id "al9eNXUPuLYrePtEkUcnWwAAAMY"]
[Tue Jul 21 08:55:33.749178 2026] [security2:error] [pid 559070:tid 559310] [client 20.151.10.161:55828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ha.php"] [unique_id "al9eNSy1f1FtKC137xv_LgAAAf0"]
[Tue Jul 21 08:55:33.750759 2026] [security2:error] [pid 559070:tid 559235] [client 4.194.24.143:7910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/bgymj.php"] [unique_id "al9eNSy1f1FtKC137xv_LwAAAbI"]
[Tue Jul 21 08:55:34.085598 2026] [security2:error] [pid 559070:tid 559228] [client 20.151.10.161:49081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/biufile.php"] [unique_id "al9eNiy1f1FtKC137xv_NQAAAas"]
[Tue Jul 21 08:55:34.086508 2026] [security2:error] [pid 533360:tid 533572] [client 20.104.96.117:7961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/w.php"] [unique_id "al9eNnUPuLYrePtEkUcnZAAAANQ"]
[Tue Jul 21 08:55:34.538661 2026] [security2:error] [pid 559070:tid 559258] [client 203.25.124.66:46325] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/about.php"] [unique_id "al9eNiy1f1FtKC137xv_RwAAAck"]
[Tue Jul 21 08:55:34.551356 2026] [security2:error] [pid 559070:tid 559222] [client 65.21.113.253:41582] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eNiy1f1FtKC137xv_NgAAAaU"]
[Tue Jul 21 08:55:34.574547 2026] [security2:error] [pid 559070:tid 559281] [client 20.65.185.21:53778] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "162.241.63.71"] [uri "/index.cgi"] [unique_id "al9eNiy1f1FtKC137xv_SgAAAeA"]
[Tue Jul 21 08:55:34.790893 2026] [security2:error] [pid 559070:tid 559263] [client 4.194.24.143:50426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/biufile.php"] [unique_id "al9eNiy1f1FtKC137xv_UAAAAc4"]
[Tue Jul 21 08:55:34.834528 2026] [security2:error] [pid 533360:tid 533426] [remote 104.207.58.59:11285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9eNnUPuLYrePtEkUcncgAA6T4"]
[Tue Jul 21 08:55:34.939593 2026] [security2:error] [pid 533360:tid 533604] [client 20.151.10.161:49028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wpconf.php"] [unique_id "al9eNnUPuLYrePtEkUcndAAAAPQ"]
[Tue Jul 21 08:55:34.940500 2026] [security2:error] [pid 533360:tid 533617] [client 168.167.81.163:59255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eNnUPuLYrePtEkUcndQAAAQE"]
[Tue Jul 21 08:55:34.940590 2026] [security2:error] [pid 533360:tid 533617] [client 168.167.81.163:59255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eNnUPuLYrePtEkUcndQAAAQE"]
[Tue Jul 21 08:55:35.020043 2026] [security2:error] [pid 559070:tid 559248] [client 185.213.175.37:22618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "brasilcertdigital.com.br"] [uri "/wp-json/"] [unique_id "al9eNyy1f1FtKC137xv_UgAAAb8"]
[Tue Jul 21 08:55:35.020103 2026] [security2:error] [pid 559070:tid 559248] [client 185.213.175.37:22618] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "brasilcertdigital.com.br"] [uri "/wp-json/"] [unique_id "al9eNyy1f1FtKC137xv_UgAAAb8"]
[Tue Jul 21 08:55:35.034867 2026] [security2:error] [pid 559070:tid 559265] [client 173.252.95.4:55540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eNyy1f1FtKC137xv_UwAAAdA"]
[Tue Jul 21 08:55:35.072130 2026] [security2:error] [pid 559070:tid 559275] [client 198.44.157.162:42676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9eNyy1f1FtKC137xv_VgAAAdo"]
[Tue Jul 21 08:55:35.072186 2026] [security2:error] [pid 559070:tid 559275] [client 198.44.157.162:42676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9eNyy1f1FtKC137xv_VgAAAdo"]
[Tue Jul 21 08:55:35.174653 2026] [security2:error] [pid 559070:tid 559148] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eNyy1f1FtKC137xv_XAABtE0"]
[Tue Jul 21 08:55:35.174788 2026] [security2:error] [pid 559070:tid 559237] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eNyy1f1FtKC137xv_XAABtE0"]
[Tue Jul 21 08:55:35.214569 2026] [security2:error] [pid 533360:tid 533504] [client 20.151.10.161:46065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/dx.php"] [unique_id "al9eN3UPuLYrePtEkUcnfwAAAJA"]
[Tue Jul 21 08:55:35.281613 2026] [security2:error] [pid 559070:tid 559247] [client 185.213.175.37:22656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "brasilcertdigital.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eNyy1f1FtKC137xv_WwAAAb4"]
[Tue Jul 21 08:55:35.634804 2026] [security2:error] [pid 559070:tid 559300] [client 203.25.124.54:44395] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/new.php"] [unique_id "al9eNyy1f1FtKC137xv_aAAAAfM"]
[Tue Jul 21 08:55:35.699496 2026] [security2:error] [pid 559070:tid 559226] [client 20.220.225.223:55749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/term.php"] [unique_id "al9eNyy1f1FtKC137xv_awAAAak"]
[Tue Jul 21 08:55:35.758981 2026] [security2:error] [pid 533360:tid 533590] [client 20.104.96.117:7965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9eN3UPuLYrePtEkUcnhQAAAOY"]
[Tue Jul 21 08:55:35.767622 2026] [security2:error] [pid 559070:tid 559259] [client 20.197.192.193:61106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9eNyy1f1FtKC137xv_bgAAAco"]
[Tue Jul 21 08:55:35.781893 2026] [security2:error] [pid 559070:tid 559132] [remote 51.75.236.156:55370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "projetoflechas.org.br"] [uri "/robots.txt"] [unique_id "al9eNyy1f1FtKC137xv_bwAB9T0"]
[Tue Jul 21 08:55:35.781996 2026] [security2:error] [pid 559070:tid 559302] [client 51.75.236.156:55370] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "projetoflechas.org.br"] [uri "/robots.txt"] [unique_id "al9eNyy1f1FtKC137xv_bwAB9T0"]
[Tue Jul 21 08:55:35.841785 2026] [security2:error] [pid 559070:tid 559202] [client 4.194.24.143:7902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/bless.php"] [unique_id "al9eNyy1f1FtKC137xv_cAAAAZE"]
[Tue Jul 21 08:55:36.020599 2026] [security2:error] [pid 533360:tid 533609] [client 20.151.10.161:48578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/mosty.php"] [unique_id "al9eOHUPuLYrePtEkUcniAAAAPk"]
[Tue Jul 21 08:55:36.388047 2026] [security2:error] [pid 559070:tid 559284] [client 20.197.192.193:27177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/tkikikoko.php"] [unique_id "al9eOCy1f1FtKC137xv_fAAAAeM"]
[Tue Jul 21 08:55:36.499504 2026] [security2:error] [pid 559070:tid 559269] [client 20.104.96.117:7259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/FWAZ.php"] [unique_id "al9eOCy1f1FtKC137xv_ggAAAdQ"]
[Tue Jul 21 08:55:36.689290 2026] [security2:error] [pid 559070:tid 559227] [client 20.197.192.193:56798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/yup.php"] [unique_id "al9eOCy1f1FtKC137xv_hQAAAao"]
[Tue Jul 21 08:55:36.840272 2026] [security2:error] [pid 533360:tid 533597] [client 203.25.124.48:26123] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "al9eOHUPuLYrePtEkUcnkwAAAO0"]
[Tue Jul 21 08:55:36.863087 2026] [security2:error] [pid 559070:tid 559306] [client 4.194.24.143:7991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/bolt.php"] [unique_id "al9eOCy1f1FtKC137xv_iAAAAfk"]
[Tue Jul 21 08:55:36.874591 2026] [security2:error] [pid 559070:tid 559259] [client 20.151.10.161:49075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/dejavu.php"] [unique_id "al9eOCy1f1FtKC137xv_iQAAAco"]
[Tue Jul 21 08:55:37.147036 2026] [security2:error] [pid 559070:tid 559211] [client 20.104.96.117:7937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/miru1.php"] [unique_id "al9eOSy1f1FtKC137xv_jwAAAZo"]
[Tue Jul 21 08:55:37.327015 2026] [security2:error] [pid 533360:tid 533485] [remote 142.44.225.130:28486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "projetoflechas.org.br"] [uri "/"] [unique_id "al9eOXUPuLYrePtEkUcnmwAAink"]
[Tue Jul 21 08:55:37.327320 2026] [security2:error] [pid 533360:tid 533498] [client 142.44.225.130:28486] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "projetoflechas.org.br"] [uri "/"] [unique_id "al9eOXUPuLYrePtEkUcnmwAAink"]
[Tue Jul 21 08:55:37.591520 2026] [security2:error] [pid 559070:tid 559253] [client 41.89.234.2:55169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eOSy1f1FtKC137xv_twAAAcQ"]
[Tue Jul 21 08:55:37.591596 2026] [security2:error] [pid 559070:tid 559253] [client 41.89.234.2:55169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eOSy1f1FtKC137xv_twAAAcQ"]
[Tue Jul 21 08:55:37.652550 2026] [security2:error] [pid 533360:tid 533477] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eOXUPuLYrePtEkUcnoAAA_nE"]
[Tue Jul 21 08:55:37.652656 2026] [security2:error] [pid 533360:tid 533614] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eOXUPuLYrePtEkUcnoAAA_nE"]
[Tue Jul 21 08:55:37.674079 2026] [security2:error] [pid 559070:tid 559209] [client 65.21.113.253:54970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eOSy1f1FtKC137xv_ugAAAZg"]
[Tue Jul 21 08:55:37.767189 2026] [security2:error] [pid 533360:tid 533501] [client 113.22.144.139:54318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eOXUPuLYrePtEkUcnpAAAAI0"]
[Tue Jul 21 08:55:37.767339 2026] [security2:error] [pid 533360:tid 533501] [client 113.22.144.139:54318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eOXUPuLYrePtEkUcnpAAAAI0"]
[Tue Jul 21 08:55:37.824267 2026] [security2:error] [pid 559070:tid 559247] [client 20.104.96.117:8086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/aa.php"] [unique_id "al9eOSy1f1FtKC137xv_wAAAAb4"]
[Tue Jul 21 08:55:37.885299 2026] [security2:error] [pid 533360:tid 533604] [client 20.151.10.161:49136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/aaf.php"] [unique_id "al9eOXUPuLYrePtEkUcnpQAAAPQ"]
[Tue Jul 21 08:55:37.922796 2026] [security2:error] [pid 559070:tid 559275] [client 4.194.24.143:7872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/bthil.php"] [unique_id "al9eOSy1f1FtKC137xv_1gAAAdo"]
[Tue Jul 21 08:55:37.978430 2026] [security2:error] [pid 533360:tid 533513] [client 20.197.192.193:61062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/ee.php"] [unique_id "al9eOXUPuLYrePtEkUcnqAAAAJk"]
[Tue Jul 21 08:55:37.987981 2026] [security2:error] [pid 559070:tid 559171] [remote 91.142.222.105:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samilacalculos.com.br"] [uri "/wp-login.php"] [unique_id "al9eOSy1f1FtKC137xv_1wAB-2Q"]
[Tue Jul 21 08:55:38.012714 2026] [security2:error] [pid 533360:tid 533585] [client 20.220.225.223:37590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/wpx.php"] [unique_id "al9eOnUPuLYrePtEkUcnqQAAAOE"]
[Tue Jul 21 08:55:38.047664 2026] [security2:error] [pid 533360:tid 533602] [client 20.197.192.193:50612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/jj.php"] [unique_id "al9eOnUPuLYrePtEkUcnqgAAAPI"]
[Tue Jul 21 08:55:38.083726 2026] [security2:error] [pid 533360:tid 533560] [client 182.189.99.211:48352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eOnUPuLYrePtEkUcnqwAAAMg"]
[Tue Jul 21 08:55:38.084015 2026] [security2:error] [pid 533360:tid 533560] [client 182.189.99.211:48352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eOnUPuLYrePtEkUcnqwAAAMg"]
[Tue Jul 21 08:55:38.242457 2026] [security2:error] [pid 533360:tid 533532] [client 20.104.96.117:7939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/122.php"] [unique_id "al9eOnUPuLYrePtEkUcnrgAAAKw"]
[Tue Jul 21 08:55:38.385090 2026] [security2:error] [pid 559070:tid 559283] [client 20.151.10.161:45995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/p.php"] [unique_id "al9eOiy1f1FtKC137xv_3wAAAeI"]
[Tue Jul 21 08:55:38.546449 2026] [security2:error] [pid 559070:tid 559312] [client 203.25.124.49:25921] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-links-opml.php"] [unique_id "al9eOiy1f1FtKC137xv_5QAAAf8"]
[Tue Jul 21 08:55:38.600702 2026] [security2:error] [pid 559070:tid 559102] [remote 156.67.31.167:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amandamorau.adv.br"] [uri "/wp-login.php"] [unique_id "al9eOiy1f1FtKC137xv_5gAB4B8"]
[Tue Jul 21 08:55:38.728805 2026] [security2:error] [pid 559070:tid 559238] [client 20.104.96.117:7964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/get.php"] [unique_id "al9eOiy1f1FtKC137xv_7AAAAbU"]
[Tue Jul 21 08:55:38.766628 2026] [security2:error] [pid 533360:tid 533590] [client 20.220.225.223:58910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/ah25.php"] [unique_id "al9eOnUPuLYrePtEkUcntwAAAOY"]
[Tue Jul 21 08:55:38.771849 2026] [security2:error] [pid 559070:tid 559294] [client 65.21.113.253:41588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eOiy1f1FtKC137xv_3gAAAe0"]
[Tue Jul 21 08:55:38.959083 2026] [security2:error] [pid 559070:tid 559246] [client 5.38.115.39:27881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eOiy1f1FtKC137xv_-QAAAb0"]
[Tue Jul 21 08:55:38.959267 2026] [security2:error] [pid 559070:tid 559246] [client 5.38.115.39:27881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eOiy1f1FtKC137xv_-QAAAb0"]
[Tue Jul 21 08:55:38.984210 2026] [security2:error] [pid 559070:tid 559307] [client 4.194.24.143:7935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/buy.php"] [unique_id "al9eOiy1f1FtKC137xv_-wAAAfo"]
[Tue Jul 21 08:55:39.122657 2026] [security2:error] [pid 559070:tid 559302] [client 103.59.206.240:31151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eOyy1f1FtKC137xv__AAAAfU"]
[Tue Jul 21 08:55:39.122785 2026] [security2:error] [pid 559070:tid 559302] [client 103.59.206.240:31151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eOyy1f1FtKC137xv__AAAAfU"]
[Tue Jul 21 08:55:39.250347 2026] [security2:error] [pid 559070:tid 559196] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eOyy1f1FtKC137xsAAQABvn0"]
[Tue Jul 21 08:55:39.250534 2026] [security2:error] [pid 559070:tid 559247] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eOyy1f1FtKC137xsAAQABvn0"]
[Tue Jul 21 08:55:39.327295 2026] [security2:error] [pid 559070:tid 559289] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eOyy1f1FtKC137xv__gAB6Dw"]
[Tue Jul 21 08:55:39.346553 2026] [security2:error] [pid 559070:tid 559285] [client 20.104.96.117:7604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/as.php"] [unique_id "al9eOyy1f1FtKC137xsAAgAAAeQ"]
[Tue Jul 21 08:55:39.512898 2026] [security2:error] [pid 533360:tid 533584] [client 20.151.10.161:49039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/term.php"] [unique_id "al9eO3UPuLYrePtEkUcnwgAAAOA"]
[Tue Jul 21 08:55:39.746117 2026] [security2:error] [pid 533360:tid 533506] [client 203.25.124.70:44263] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/revslider/includes/external/page/index.php"] [unique_id "al9eO3UPuLYrePtEkUcnxwAAAJI"]
[Tue Jul 21 08:55:39.996764 2026] [security2:error] [pid 533360:tid 533383] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eO3UPuLYrePtEkUcnygAAoxM"]
[Tue Jul 21 08:55:39.996886 2026] [security2:error] [pid 533360:tid 533523] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eO3UPuLYrePtEkUcnygAAoxM"]
[Tue Jul 21 08:55:40.005416 2026] [security2:error] [pid 533360:tid 533539] [client 4.194.24.143:19669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/byp.php"] [unique_id "al9ePHUPuLYrePtEkUcnywAAALM"]
[Tue Jul 21 08:55:40.216382 2026] [autoindex:error] [pid 533360:tid 533502] [client 43.166.247.82:42344] AH01276: Cannot serve directory /home2/italom32/rota40.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:55:40.232148 2026] [security2:error] [pid 559070:tid 559267] [client 20.220.225.223:48247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/else1.php"] [unique_id "al9ePCy1f1FtKC137xsAHAAAAdI"]
[Tue Jul 21 08:55:40.251902 2026] [security2:error] [pid 533360:tid 533605] [client 20.104.96.117:8072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/ccou.php"] [unique_id "al9ePHUPuLYrePtEkUcnzwAAAPU"]
[Tue Jul 21 08:55:40.309046 2026] [security2:error] [pid 559070:tid 559230] [client 20.197.192.193:63912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/blue.php"] [unique_id "al9ePCy1f1FtKC137xsAHwAAAa0"]
[Tue Jul 21 08:55:40.360023 2026] [security2:error] [pid 559070:tid 559229] [client 20.151.10.161:49129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/ha.php"] [unique_id "al9ePCy1f1FtKC137xsAIgAAAaw"]
[Tue Jul 21 08:55:40.645708 2026] [core:alert] [pid 533360:tid 533510] [client 57.141.18.124:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:55:40.850628 2026] [security2:error] [pid 559070:tid 559209] [client 74.7.241.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rustikusboxingschool.com"] [uri "/index.php"] [unique_id "al9ePCy1f1FtKC137xsAIwAAAZg"]
[Tue Jul 21 08:55:40.852458 2026] [security2:error] [pid 559070:tid 559202] [client 74.7.241.158:49886] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rustikusboxingschool.com"] [uri "/robots.txt"] [unique_id "al9ePCy1f1FtKC137xsAIAABkTs"]
[Tue Jul 21 08:55:40.924679 2026] [security2:error] [pid 533360:tid 533499] [client 91.148.244.131:44276] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/"] [unique_id "al9ePHUPuLYrePtEkUcn2gAAAIs"]
[Tue Jul 21 08:55:40.927023 2026] [security2:error] [pid 559070:tid 559289] [client 91.148.244.131:44288] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/"] [unique_id "al9ePCy1f1FtKC137xsAMgAAAeg"]
[Tue Jul 21 08:55:40.927061 2026] [security2:error] [pid 559070:tid 559303] [client 91.148.244.131:44270] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/"] [unique_id "al9ePCy1f1FtKC137xsAMQAAAfY"]
[Tue Jul 21 08:55:40.935075 2026] [security2:error] [pid 559070:tid 559300] [client 20.151.10.161:49119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/hur.php"] [unique_id "al9ePCy1f1FtKC137xsAMwAAAfM"]
[Tue Jul 21 08:55:40.937223 2026] [security2:error] [pid 559070:tid 559228] [client 203.25.124.36:39037] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/222.php"] [unique_id "al9ePCy1f1FtKC137xsANAAAAas"]
[Tue Jul 21 08:55:40.963939 2026] [security2:error] [pid 559070:tid 559316] [client 20.197.192.193:50569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/dragonshell.php"] [unique_id "al9ePCy1f1FtKC137xsANwAAAgM"]
[Tue Jul 21 08:55:40.997060 2026] [autoindex:error] [pid 559070:tid 559204] [client 20.151.10.161:46002] AH01276: Cannot serve directory /home3/housei59/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:55:41.051255 2026] [security2:error] [pid 533360:tid 533513] [client 4.194.24.143:19665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/bypass.php"] [unique_id "al9ePXUPuLYrePtEkUcn3QAAAJk"]
[Tue Jul 21 08:55:41.276957 2026] [security2:error] [pid 559070:tid 559254] [client 20.151.10.161:46002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/bthil.php"] [unique_id "al9ePSy1f1FtKC137xsAQgAAAcU"]
[Tue Jul 21 08:55:41.295440 2026] [security2:error] [pid 559070:tid 559237] [client 59.95.197.55:52844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ePSy1f1FtKC137xsAQwAAAbQ"]
[Tue Jul 21 08:55:41.295650 2026] [security2:error] [pid 559070:tid 559237] [client 59.95.197.55:52844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ePSy1f1FtKC137xsAQwAAAbQ"]
[Tue Jul 21 08:55:41.350932 2026] [security2:error] [pid 559070:tid 559220] [client 20.104.96.117:7979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/w3lls.php"] [unique_id "al9ePSy1f1FtKC137xsARAAAAaM"]
[Tue Jul 21 08:55:41.896455 2026] [security2:error] [pid 559070:tid 559235] [client 20.220.225.223:21584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/cro.php"] [unique_id "al9ePSy1f1FtKC137xsAUwAAAbI"]
[Tue Jul 21 08:55:41.993516 2026] [security2:error] [pid 533360:tid 533591] [client 20.151.10.161:49127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/h02ugyh.php"] [unique_id "al9ePXUPuLYrePtEkUcn6wAAAOc"]
[Tue Jul 21 08:55:42.031976 2026] [security2:error] [pid 559070:tid 559281] [client 65.21.113.253:54970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9ePiy1f1FtKC137xsAWgAAAeA"]
[Tue Jul 21 08:55:42.036150 2026] [security2:error] [pid 559070:tid 559272] [client 203.25.124.61:57673] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/about/function.php"] [unique_id "al9ePiy1f1FtKC137xsAWwAAAdc"]
[Tue Jul 21 08:55:42.129614 2026] [security2:error] [pid 533360:tid 533534] [client 4.194.24.143:20394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/cache.php"] [unique_id "al9ePnUPuLYrePtEkUcn7gAAAK4"]
[Tue Jul 21 08:55:42.270024 2026] [security2:error] [pid 533360:tid 533543] [client 20.197.192.193:63922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/wp-signup.php"] [unique_id "al9ePnUPuLYrePtEkUcn8gAAALc"]
[Tue Jul 21 08:55:42.376362 2026] [security2:error] [pid 533360:tid 533619] [client 114.198.138.124:49193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9ePnUPuLYrePtEkUcn9AAAAQM"]
[Tue Jul 21 08:55:42.376529 2026] [security2:error] [pid 533360:tid 533619] [client 114.198.138.124:49193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9ePnUPuLYrePtEkUcn9AAAAQM"]
[Tue Jul 21 08:55:42.881092 2026] [security2:error] [pid 559070:tid 559248] [client 20.151.10.161:45944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/7.php"] [unique_id "al9ePiy1f1FtKC137xsAbAAAAb8"]
[Tue Jul 21 08:55:43.151258 2026] [security2:error] [pid 559070:tid 559304] [client 65.21.113.253:35932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ePiy1f1FtKC137xsAaQAAAfc"]
[Tue Jul 21 08:55:43.171231 2026] [security2:error] [pid 559070:tid 559212] [client 4.194.24.143:7299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/cc.php"] [unique_id "al9ePyy1f1FtKC137xsAcwAAAZs"]
[Tue Jul 21 08:55:43.352652 2026] [security2:error] [pid 559070:tid 559247] [client 203.25.124.49:40303] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/maint/about.php"] [unique_id "al9ePyy1f1FtKC137xsAdwAAAb4"]
[Tue Jul 21 08:55:43.470082 2026] [security2:error] [pid 559070:tid 559113] [remote 45.90.123.233:34766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "manual.fernandohipolito.com.br"] [uri "/wp-login.php"] [unique_id "al9ePyy1f1FtKC137xsAfAABzio"]
[Tue Jul 21 08:55:43.526906 2026] [security2:error] [pid 559070:tid 559072] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbfservicos.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9ePyy1f1FtKC137xsAfQAB1AE"], referer: www.google.com
[Tue Jul 21 08:55:43.561877 2026] [security2:error] [pid 559070:tid 559188] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbfservicos.com.br"] [uri "/wp-plain.php"] [unique_id "al9ePyy1f1FtKC137xsAfwABsnU"], referer: www.google.com
[Tue Jul 21 08:55:43.565786 2026] [security2:error] [pid 559070:tid 559218] [client 20.151.10.161:51006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/hur.php"] [unique_id "al9ePyy1f1FtKC137xsAgAAAAaE"]
[Tue Jul 21 08:55:43.607512 2026] [security2:error] [pid 559070:tid 559207] [client 198.44.157.162:42754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ePyy1f1FtKC137xsAgQAAAZY"]
[Tue Jul 21 08:55:43.607633 2026] [security2:error] [pid 559070:tid 559207] [client 198.44.157.162:42754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ePyy1f1FtKC137xsAgQAAAZY"]
[Tue Jul 21 08:55:43.766346 2026] [security2:error] [pid 559070:tid 559306] [client 20.151.10.161:49050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/seiso.php"] [unique_id "al9ePyy1f1FtKC137xsAhgAAAfk"]
[Tue Jul 21 08:55:43.846137 2026] [security2:error] [pid 559070:tid 559214] [client 20.151.10.161:45979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/8.php"] [unique_id "al9ePyy1f1FtKC137xsAhwAAAZ0"]
[Tue Jul 21 08:55:43.862338 2026] [security2:error] [pid 559070:tid 559151] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbfservicos.com.br"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al9ePyy1f1FtKC137xsAiAABk1A"], referer: www.google.com
[Tue Jul 21 08:55:43.862348 2026] [security2:error] [pid 533360:tid 533429] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbfservicos.com.br"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "al9eP3UPuLYrePtEkUcoCgABAUE"]
[Tue Jul 21 08:55:43.868395 2026] [security2:error] [pid 559070:tid 559193] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbfservicos.com.br"] [uri "/retstewz.php"] [unique_id "al9ePyy1f1FtKC137xsAiQABqHo"], referer: www.google.com
[Tue Jul 21 08:55:43.891484 2026] [security2:error] [pid 559070:tid 559282] [client 20.104.96.117:7233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/test1.php"] [unique_id "al9ePyy1f1FtKC137xsAjAAAAeE"]
[Tue Jul 21 08:55:43.892859 2026] [security2:error] [pid 559070:tid 559315] [client 20.197.192.193:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/csa.php"] [unique_id "al9ePyy1f1FtKC137xsAjQAAAgI"]
[Tue Jul 21 08:55:43.957511 2026] [security2:error] [pid 559070:tid 559162] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbfservicos.com.br"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al9ePyy1f1FtKC137xsAkgAB7Vs"]
[Tue Jul 21 08:55:43.964795 2026] [security2:error] [pid 559070:tid 559267] [client 20.220.225.223:60257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/cron-tab.php"] [unique_id "al9ePyy1f1FtKC137xsAlAAAAdI"]
[Tue Jul 21 08:55:43.974359 2026] [security2:error] [pid 559070:tid 559312] [client 20.151.10.161:55818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/h02ugyh.php"] [unique_id "al9ePyy1f1FtKC137xsAlQAAAf8"]
[Tue Jul 21 08:55:44.179668 2026] [security2:error] [pid 559070:tid 559141] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbfservicos.com.br"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al9eQCy1f1FtKC137xsAnAAB50Y"]
[Tue Jul 21 08:55:44.387339 2026] [security2:error] [pid 559070:tid 559181] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbfservicos.com.br"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "al9eQCy1f1FtKC137xsAqQAB7G4"]
[Tue Jul 21 08:55:44.511913 2026] [security2:error] [pid 559070:tid 559315] [client 20.151.10.161:46035] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "houseincorporacoes.com"] [uri "/1.php"] [unique_id "al9eQCy1f1FtKC137xsArwAAAgI"]
[Tue Jul 21 08:55:44.512051 2026] [security2:error] [pid 559070:tid 559315] [client 20.151.10.161:46035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/1.php"] [unique_id "al9eQCy1f1FtKC137xsArwAAAgI"]
[Tue Jul 21 08:55:44.515669 2026] [security2:error] [pid 559070:tid 559219] [client 20.52.136.55:1540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/plugins.php"] [unique_id "al9eQCy1f1FtKC137xsAsAAAAaI"]
[Tue Jul 21 08:55:44.901676 2026] [security2:error] [pid 559070:tid 559298] [client 4.194.24.143:18208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/cgi-bin/admin.php"] [unique_id "al9eQCy1f1FtKC137xsAtgAAAfE"]
[Tue Jul 21 08:55:44.978693 2026] [security2:error] [pid 559070:tid 559119] [remote 185.242.3.192:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wbfservicos.com.br"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "al9eQCy1f1FtKC137xsAvAAB0jA"]
[Tue Jul 21 08:55:45.020705 2026] [security2:error] [pid 559070:tid 559295] [client 128.127.105.184:36664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9eQSy1f1FtKC137xsAvQAAAe4"]
[Tue Jul 21 08:55:45.020880 2026] [security2:error] [pid 559070:tid 559295] [client 128.127.105.184:36664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9eQSy1f1FtKC137xsAvQAAAe4"]
[Tue Jul 21 08:55:45.099758 2026] [security2:error] [pid 559070:tid 559288] [client 20.197.192.193:50607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/wp-mt.php"] [unique_id "al9eQSy1f1FtKC137xsAvgAAAec"]
[Tue Jul 21 08:55:45.219599 2026] [security2:error] [pid 559070:tid 559226] [client 20.151.10.161:45888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/100.php"] [unique_id "al9eQSy1f1FtKC137xsAxgAAAak"]
[Tue Jul 21 08:55:45.325879 2026] [security2:error] [pid 533360:tid 533616] [client 107.189.6.149:62978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "santotchay.com.br"] [uri "/"] [unique_id "al9eQXUPuLYrePtEkUcoHAAAAQA"]
[Tue Jul 21 08:55:45.382720 2026] [security2:error] [pid 559070:tid 559323] [client 20.151.10.161:51052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/seiso.php"] [unique_id "al9eQSy1f1FtKC137xsAxwAAAgo"]
[Tue Jul 21 08:55:45.540122 2026] [security2:error] [pid 559070:tid 559214] [client 20.151.10.161:49082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/155.php"] [unique_id "al9eQSy1f1FtKC137xsA0QAAAZ0"]
[Tue Jul 21 08:55:45.550056 2026] [security2:error] [pid 533360:tid 533576] [client 107.189.6.149:62977] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "santotchay.com.br"] [uri "/"] [unique_id "al9eQXUPuLYrePtEkUcoIAAAANg"]
[Tue Jul 21 08:55:45.630937 2026] [security2:error] [pid 559070:tid 559117] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eQSy1f1FtKC137xsA0gABky4"]
[Tue Jul 21 08:55:45.631090 2026] [security2:error] [pid 559070:tid 559204] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eQSy1f1FtKC137xsA0gABky4"]
[Tue Jul 21 08:55:45.723773 2026] [security2:error] [pid 533360:tid 533377] [remote 91.142.222.105:56224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colegioperseveranca.com"] [uri "/wp-login.php"] [unique_id "al9eQXUPuLYrePtEkUcoIgAAhg0"]
[Tue Jul 21 08:55:45.844939 2026] [security2:error] [pid 533360:tid 533543] [client 107.189.6.149:63023] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "santotchay.com.br"] [uri "/"] [unique_id "al9eQXUPuLYrePtEkUcoJwAAALc"]
[Tue Jul 21 08:55:45.934179 2026] [security2:error] [pid 559070:tid 559219] [client 203.25.124.54:22473] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/upload/upload.php"] [unique_id "al9eQSy1f1FtKC137xsA2AAAAaI"]
[Tue Jul 21 08:55:45.956420 2026] [security2:error] [pid 533360:tid 533592] [client 4.194.24.143:19663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/cgi-bin/class-wp-http-client.php"] [unique_id "al9eQXUPuLYrePtEkUcoKAAAAOg"]
[Tue Jul 21 08:55:46.101186 2026] [security2:error] [pid 559070:tid 559265] [client 20.104.96.117:7292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/database.php"] [unique_id "al9eQiy1f1FtKC137xsA4AAAAdA"]
[Tue Jul 21 08:55:46.124698 2026] [security2:error] [pid 559070:tid 559325] [client 20.220.225.223:21617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/koiy.php"] [unique_id "al9eQiy1f1FtKC137xsA4QAAAgw"]
[Tue Jul 21 08:55:46.228653 2026] [security2:error] [pid 559070:tid 559264] [client 65.21.113.253:54970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eQiy1f1FtKC137xsA4wAAAc8"]
[Tue Jul 21 08:55:46.251750 2026] [security2:error] [pid 559070:tid 559230] [client 74.7.175.129:58576] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "zohmfo.com"] [uri "/cgi-sys/404.html"] [unique_id "al9eQiy1f1FtKC137xsA5AABrSg"]
[Tue Jul 21 08:55:46.253214 2026] [security2:error] [pid 559070:tid 559229] [client 107.189.6.149:63047] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "santotchay.com.br"] [uri "/"] [unique_id "al9eQiy1f1FtKC137xsA5QAAAaw"]
[Tue Jul 21 08:55:46.495068 2026] [security2:error] [pid 559070:tid 559287] [client 20.151.10.161:55870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/155.php"] [unique_id "al9eQiy1f1FtKC137xsA6AAAAeY"]
[Tue Jul 21 08:55:46.631038 2026] [security2:error] [pid 559070:tid 559318] [client 20.151.10.161:49131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/ppp.php"] [unique_id "al9eQiy1f1FtKC137xsA6wAAAgU"]
[Tue Jul 21 08:55:46.786505 2026] [security2:error] [pid 559070:tid 559269] [client 20.151.10.161:45898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/about.php"] [unique_id "al9eQiy1f1FtKC137xsA8QAAAdQ"]
[Tue Jul 21 08:55:46.857082 2026] [security2:error] [pid 533360:tid 533529] [client 20.220.225.223:58935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/8.php"] [unique_id "al9eQnUPuLYrePtEkUcoOwAAAKk"]
[Tue Jul 21 08:55:46.883146 2026] [security2:error] [pid 559070:tid 559213] [client 91.148.244.131:42126] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/api/.env"] [unique_id "al9eQiy1f1FtKC137xsA8wAAAZw"]
[Tue Jul 21 08:55:46.885003 2026] [security2:error] [pid 533360:tid 533588] [client 91.148.244.131:42110] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9eQnUPuLYrePtEkUcoPAAAAOQ"]
[Tue Jul 21 08:55:46.885167 2026] [security2:error] [pid 559070:tid 559275] [client 91.148.244.131:42124] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/backup.zip"] [unique_id "al9eQiy1f1FtKC137xsA9AAAAdo"]
[Tue Jul 21 08:55:46.887027 2026] [security2:error] [pid 533360:tid 533561] [client 91.148.244.131:42098] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/config.xml"] [unique_id "al9eQnUPuLYrePtEkUcoPQAAAMk"]
[Tue Jul 21 08:55:46.938212 2026] [security2:error] [pid 559070:tid 559204] [client 20.220.225.223:21929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/hp2.php"] [unique_id "al9eQiy1f1FtKC137xsA-AAAAZM"]
[Tue Jul 21 08:55:46.982876 2026] [security2:error] [pid 559070:tid 559209] [client 4.194.24.143:18235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/chosen.php"] [unique_id "al9eQiy1f1FtKC137xsA-QAAAZg"]
[Tue Jul 21 08:55:47.318774 2026] [security2:error] [pid 533360:tid 533615] [client 65.21.113.253:35944] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eQnUPuLYrePtEkUcoPgAAAP8"]
[Tue Jul 21 08:55:47.521188 2026] [security2:error] [pid 533360:tid 533532] [client 173.252.95.34:41714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eQ3UPuLYrePtEkUcoSwAAAKw"]
[Tue Jul 21 08:55:47.645491 2026] [security2:error] [pid 533360:tid 533548] [client 168.167.81.163:64172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eQ3UPuLYrePtEkUcoTQAAALw"]
[Tue Jul 21 08:55:47.645637 2026] [security2:error] [pid 533360:tid 533548] [client 168.167.81.163:64172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eQ3UPuLYrePtEkUcoTQAAALw"]
[Tue Jul 21 08:55:47.710408 2026] [security2:error] [pid 559070:tid 559305] [client 20.197.192.193:63884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/min.php"] [unique_id "al9eQyy1f1FtKC137xsBBAAAAfg"]
[Tue Jul 21 08:55:47.758938 2026] [security2:error] [pid 559070:tid 559201] [client 128.127.105.184:36674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9eQyy1f1FtKC137xsBBgAAAZA"]
[Tue Jul 21 08:55:47.759053 2026] [security2:error] [pid 559070:tid 559201] [client 128.127.105.184:36674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9eQyy1f1FtKC137xsBBgAAAZA"]
[Tue Jul 21 08:55:47.860440 2026] [security2:error] [pid 559070:tid 559313] [client 91.148.244.131:42188] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/phpinfo.php"] [unique_id "al9eQyy1f1FtKC137xsBCQAAAgA"]
[Tue Jul 21 08:55:47.861488 2026] [security2:error] [pid 559070:tid 559284] [client 91.148.244.131:42180] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/docker-compose.yml"] [unique_id "al9eQyy1f1FtKC137xsBCgAAAeM"]
[Tue Jul 21 08:55:47.863149 2026] [security2:error] [pid 533360:tid 533575] [client 91.148.244.131:42152] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/server.key"] [unique_id "al9eQ3UPuLYrePtEkUcoUAAAANc"]
[Tue Jul 21 08:55:47.864131 2026] [security2:error] [pid 533360:tid 533557] [client 91.148.244.131:42164] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/user_secrets.yml"] [unique_id "al9eQ3UPuLYrePtEkUcoUQAAAMU"]
[Tue Jul 21 08:55:48.030905 2026] [security2:error] [pid 559070:tid 559237] [client 4.194.24.143:19699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/class-t.api.php"] [unique_id "al9eRCy1f1FtKC137xsBDwAAAbQ"]
[Tue Jul 21 08:55:48.065873 2026] [security2:error] [pid 559070:tid 559288] [client 91.148.244.131:42156] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/.env.production"] [unique_id "al9eRCy1f1FtKC137xsBEAAAAec"]
[Tue Jul 21 08:55:48.156887 2026] [security2:error] [pid 559070:tid 559267] [client 41.89.234.2:55644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eRCy1f1FtKC137xsBEwAAAdI"]
[Tue Jul 21 08:55:48.157004 2026] [security2:error] [pid 559070:tid 559267] [client 41.89.234.2:55644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eRCy1f1FtKC137xsBEwAAAdI"]
[Tue Jul 21 08:55:48.226511 2026] [security2:error] [pid 559070:tid 559259] [client 212.32.76.14:21049] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wpc.php"] [unique_id "al9eRCy1f1FtKC137xsBFgAAAco"]
[Tue Jul 21 08:55:48.268024 2026] [security2:error] [pid 559070:tid 559200] [client 91.148.244.131:42194] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9eRCy1f1FtKC137xsBGAAAAY8"]
[Tue Jul 21 08:55:48.268927 2026] [security2:error] [pid 559070:tid 559256] [client 91.148.244.131:42176] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/config/production.json"] [unique_id "al9eRCy1f1FtKC137xsBGQAAAcc"]
[Tue Jul 21 08:55:48.317382 2026] [security2:error] [pid 559070:tid 559077] [remote 54.39.0.61:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "marketingderua.com.br"] [uri "/automacao-em-ooh-como-escalar-campanhas-fisicas-com-software/"] [unique_id "al9eRCy1f1FtKC137xsBGwABugY"]
[Tue Jul 21 08:55:48.317730 2026] [security2:error] [pid 559070:tid 559243] [client 54.39.0.61:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "marketingderua.com.br"] [uri "/automacao-em-ooh-como-escalar-campanhas-fisicas-com-software/"] [unique_id "al9eRCy1f1FtKC137xsBGwABugY"]
[Tue Jul 21 08:55:48.475103 2026] [security2:error] [pid 559070:tid 559239] [client 20.220.225.223:48250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/hp3.php"] [unique_id "al9eRCy1f1FtKC137xsBHQAAAbY"]
[Tue Jul 21 08:55:48.613094 2026] [security2:error] [pid 559070:tid 559203] [client 182.189.99.211:48432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eRCy1f1FtKC137xsBHgAAAZI"]
[Tue Jul 21 08:55:48.613276 2026] [security2:error] [pid 559070:tid 559203] [client 182.189.99.211:48432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eRCy1f1FtKC137xsBHgAAAZI"]
[Tue Jul 21 08:55:48.636391 2026] [security2:error] [pid 559070:tid 559108] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eRCy1f1FtKC137xsBIAAB6iU"]
[Tue Jul 21 08:55:48.636535 2026] [security2:error] [pid 559070:tid 559291] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eRCy1f1FtKC137xsBIAAB6iU"]
[Tue Jul 21 08:55:48.776546 2026] [security2:error] [pid 559070:tid 559266] [client 113.22.144.139:54862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eRCy1f1FtKC137xsBIwAAAdE"]
[Tue Jul 21 08:55:48.776676 2026] [security2:error] [pid 559070:tid 559266] [client 113.22.144.139:54862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eRCy1f1FtKC137xsBIwAAAdE"]
[Tue Jul 21 08:55:48.778777 2026] [security2:error] [pid 559070:tid 559302] [client 20.197.192.193:61078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/echkm.php"] [unique_id "al9eRCy1f1FtKC137xsBJAAAAfU"]
[Tue Jul 21 08:55:49.028120 2026] [security2:error] [pid 533360:tid 533562] [client 20.151.10.161:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/admin.php"] [unique_id "al9eRXUPuLYrePtEkUcoYgAAAMo"]
[Tue Jul 21 08:55:49.077471 2026] [security2:error] [pid 559070:tid 559214] [client 91.148.244.131:42198] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/.bash_history"] [unique_id "al9eRSy1f1FtKC137xsBJgAAAZ0"]
[Tue Jul 21 08:55:49.080687 2026] [security2:error] [pid 533360:tid 533506] [client 91.148.244.131:42216] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/secrets.json"] [unique_id "al9eRXUPuLYrePtEkUcoZAAAAJI"]
[Tue Jul 21 08:55:49.081876 2026] [security2:error] [pid 559070:tid 559298] [client 91.148.244.131:42218] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/.npmrc"] [unique_id "al9eRSy1f1FtKC137xsBJwAAAfE"]
[Tue Jul 21 08:55:49.083114 2026] [security2:error] [pid 559070:tid 559265] [client 91.148.244.131:42200] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/.vscode/sftp.json"] [unique_id "al9eRSy1f1FtKC137xsBKAAAAdA"]
[Tue Jul 21 08:55:49.088870 2026] [security2:error] [pid 559070:tid 559326] [client 4.194.24.143:7010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/class-walker-footer-dev.php"] [unique_id "al9eRSy1f1FtKC137xsBKQAAAg0"]
[Tue Jul 21 08:55:49.280319 2026] [security2:error] [pid 559070:tid 559295] [client 91.148.244.131:42214] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/database_backup.sql"] [unique_id "al9eRSy1f1FtKC137xsBLQAAAe4"]
[Tue Jul 21 08:55:49.283392 2026] [security2:error] [pid 559070:tid 559264] [client 91.148.244.131:42236] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/database.sql"] [unique_id "al9eRSy1f1FtKC137xsBLgAAAc8"]
[Tue Jul 21 08:55:49.284280 2026] [security2:error] [pid 559070:tid 559325] [client 91.148.244.131:42206] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/wp-config.php"] [unique_id "al9eRSy1f1FtKC137xsBLwAAAgw"]
[Tue Jul 21 08:55:49.382102 2026] [security2:error] [pid 559070:tid 559235] [client 194.99.104.35:40754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9eRSy1f1FtKC137xsBMwAAAbI"]
[Tue Jul 21 08:55:49.382197 2026] [security2:error] [pid 559070:tid 559235] [client 194.99.104.35:40754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9eRSy1f1FtKC137xsBMwAAAbI"]
[Tue Jul 21 08:55:49.402455 2026] [security2:error] [pid 559070:tid 559269] [client 20.104.96.117:7955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/file.php"] [unique_id "al9eRSy1f1FtKC137xsBNAAAAdQ"]
[Tue Jul 21 08:55:49.445383 2026] [security2:error] [pid 559070:tid 559206] [client 203.25.124.215:49343] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "al9eRSy1f1FtKC137xsBNQAAAZU"]
[Tue Jul 21 08:55:49.520006 2026] [security2:error] [pid 533360:tid 533538] [client 5.38.115.39:49891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eRXUPuLYrePtEkUcoeAAAALI"]
[Tue Jul 21 08:55:49.520128 2026] [security2:error] [pid 533360:tid 533538] [client 5.38.115.39:49891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eRXUPuLYrePtEkUcoeAAAALI"]
[Tue Jul 21 08:55:49.761189 2026] [security2:error] [pid 559070:tid 559156] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eRSy1f1FtKC137xsBOgACA1U"]
[Tue Jul 21 08:55:49.761304 2026] [security2:error] [pid 559070:tid 559316] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eRSy1f1FtKC137xsBOgACA1U"]
[Tue Jul 21 08:55:49.848326 2026] [security2:error] [pid 533360:tid 533560] [client 20.151.10.161:51037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ppp.php"] [unique_id "al9eRXUPuLYrePtEkUcofwAAAMg"]
[Tue Jul 21 08:55:49.880223 2026] [security2:error] [pid 533360:tid 533579] [client 103.59.206.240:31131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eRXUPuLYrePtEkUcogAAAANs"]
[Tue Jul 21 08:55:49.880343 2026] [security2:error] [pid 533360:tid 533579] [client 103.59.206.240:31131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eRXUPuLYrePtEkUcogAAAANs"]
[Tue Jul 21 08:55:50.053692 2026] [security2:error] [pid 533360:tid 533602] [client 91.148.244.131:42286] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/dump.sql"] [unique_id "al9eRnUPuLYrePtEkUcohgAAAPI"]
[Tue Jul 21 08:55:50.054565 2026] [security2:error] [pid 559070:tid 559254] [client 91.148.244.131:42244] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/backup.sql"] [unique_id "al9eRiy1f1FtKC137xsBQQAAAcU"]
[Tue Jul 21 08:55:50.054809 2026] [security2:error] [pid 559070:tid 559213] [client 91.148.244.131:42262] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/config.php"] [unique_id "al9eRiy1f1FtKC137xsBQgAAAZw"]
[Tue Jul 21 08:55:50.056167 2026] [security2:error] [pid 533360:tid 533565] [client 91.148.244.131:42288] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9eRnUPuLYrePtEkUcohwAAAM0"]
[Tue Jul 21 08:55:50.072953 2026] [security2:error] [pid 559070:tid 559144] [remote 45.3.35.174:62641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.35.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9eRiy1f1FtKC137xsBQwAB3Uk"]
[Tue Jul 21 08:55:50.164261 2026] [security2:error] [pid 533360:tid 533555] [client 4.194.24.143:7021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/class-wp-http-client.php"] [unique_id "al9eRnUPuLYrePtEkUcoiAAAAMM"]
[Tue Jul 21 08:55:50.256128 2026] [security2:error] [pid 559070:tid 559306] [client 91.148.244.131:42260] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/actuator/heapdump"] [unique_id "al9eRiy1f1FtKC137xsBSQAAAfk"]
[Tue Jul 21 08:55:50.256571 2026] [security2:error] [pid 559070:tid 559203] [client 91.148.244.131:42280] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/.svn/wc.db"] [unique_id "al9eRiy1f1FtKC137xsBSgAAAZI"]
[Tue Jul 21 08:55:50.256625 2026] [security2:error] [pid 559070:tid 559297] [client 91.148.244.131:42256] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/backup.tar.gz"] [unique_id "al9eRiy1f1FtKC137xsBSwAAAfA"]
[Tue Jul 21 08:55:50.308327 2026] [security2:error] [pid 559070:tid 559230] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eRiy1f1FtKC137xsBRQABrTY"]
[Tue Jul 21 08:55:50.438243 2026] [security2:error] [pid 559070:tid 559284] [client 203.25.124.40:63425] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/as.php"] [unique_id "al9eRiy1f1FtKC137xsBTQAAAeM"]
[Tue Jul 21 08:55:50.813681 2026] [security2:error] [pid 559070:tid 559103] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eRiy1f1FtKC137xsBVAABzyA"]
[Tue Jul 21 08:55:50.813866 2026] [security2:error] [pid 559070:tid 559264] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eRiy1f1FtKC137xsBVAABzyA"]
[Tue Jul 21 08:55:50.989788 2026] [security2:error] [pid 559070:tid 559200] [client 65.21.113.253:54970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eRiy1f1FtKC137xsBVwAAAY8"]
[Tue Jul 21 08:55:51.041105 2026] [security2:error] [pid 559070:tid 559221] [client 91.148.244.131:42346] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9eRyy1f1FtKC137xsBWAAAAaQ"]
[Tue Jul 21 08:55:51.078025 2026] [security2:error] [pid 559070:tid 559282] [client 128.127.105.184:60054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9eRyy1f1FtKC137xsBWgAAAeE"]
[Tue Jul 21 08:55:51.078116 2026] [security2:error] [pid 559070:tid 559282] [client 128.127.105.184:60054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9eRyy1f1FtKC137xsBWgAAAeE"]
[Tue Jul 21 08:55:51.191306 2026] [security2:error] [pid 533360:tid 533616] [client 4.194.24.143:6987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/class.php"] [unique_id "al9eR3UPuLYrePtEkUcolwAAAQA"]
[Tue Jul 21 08:55:51.586801 2026] [security2:error] [pid 533360:tid 533607] [client 59.95.197.55:53321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eR3UPuLYrePtEkUcoowAAAPc"]
[Tue Jul 21 08:55:51.586938 2026] [security2:error] [pid 533360:tid 533607] [client 59.95.197.55:53321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eR3UPuLYrePtEkUcoowAAAPc"]
[Tue Jul 21 08:55:51.651247 2026] [security2:error] [pid 559070:tid 559248] [client 212.32.76.12:55107] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwentyfive/patterns/template-singl-portfolio.php"] [unique_id "al9eRyy1f1FtKC137xsBXwAAAb8"]
[Tue Jul 21 08:55:51.710001 2026] [security2:error] [pid 559070:tid 559238] [client 20.197.192.193:61093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/mac.php"] [unique_id "al9eRyy1f1FtKC137xsBYAAAAbU"]
[Tue Jul 21 08:55:51.804172 2026] [security2:error] [pid 559070:tid 559106] [remote 45.3.47.111:18285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.47.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9eRyy1f1FtKC137xsBZAAB0SM"]
[Tue Jul 21 08:55:51.858740 2026] [security2:error] [pid 533360:tid 533519] [client 198.44.157.162:59190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9eR3UPuLYrePtEkUcoqQAAAJ8"]
[Tue Jul 21 08:55:51.858834 2026] [security2:error] [pid 533360:tid 533519] [client 198.44.157.162:59190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9eR3UPuLYrePtEkUcoqQAAAJ8"]
[Tue Jul 21 08:55:51.959918 2026] [security2:error] [pid 559070:tid 559211] [client 20.220.225.223:60278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/aa1.php"] [unique_id "al9eRyy1f1FtKC137xsBawAAAZo"]
[Tue Jul 21 08:55:52.016960 2026] [security2:error] [pid 559070:tid 559312] [client 91.148.244.131:42380] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/.env"] [unique_id "al9eSCy1f1FtKC137xsBbQAAAf8"]
[Tue Jul 21 08:55:52.017085 2026] [security2:error] [pid 559070:tid 559278] [client 91.148.244.131:42390] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/.ssh/id_rsa"] [unique_id "al9eSCy1f1FtKC137xsBbgAAAd0"]
[Tue Jul 21 08:55:52.062998 2026] [security2:error] [pid 559070:tid 559298] [client 91.148.244.131:42304] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9eSCy1f1FtKC137xsBbwAAAfE"]
[Tue Jul 21 08:55:52.063996 2026] [security2:error] [pid 559070:tid 559326] [client 91.148.244.131:42362] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/.git/HEAD"] [unique_id "al9eSCy1f1FtKC137xsBcAAAAg0"]
[Tue Jul 21 08:55:52.082329 2026] [security2:error] [pid 533360:tid 533537] [client 65.21.113.253:39070] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eR3UPuLYrePtEkUcopAAAALE"]
[Tue Jul 21 08:55:52.140610 2026] [security2:error] [pid 559070:tid 559314] [client 20.220.225.223:48213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/tkikikoko.php"] [unique_id "al9eSCy1f1FtKC137xsBdAAAAgE"]
[Tue Jul 21 08:55:52.221362 2026] [security2:error] [pid 559070:tid 559283] [client 91.148.244.131:42364] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sigmas.app.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9eSCy1f1FtKC137xsBdQAAAeI"]
[Tue Jul 21 08:55:52.279249 2026] [security2:error] [pid 533360:tid 533598] [client 4.194.24.143:19682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/classsmtps.php"] [unique_id "al9eSHUPuLYrePtEkUcotwAAAO4"]
[Tue Jul 21 08:55:52.458972 2026] [security2:error] [pid 559070:tid 559200] [client 20.151.10.161:45830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/edit.php"] [unique_id "al9eSCy1f1FtKC137xsBeAAAAY8"]
[Tue Jul 21 08:55:52.603205 2026] [security2:error] [pid 533360:tid 533590] [client 20.104.96.117:7556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/file.php"] [unique_id "al9eSHUPuLYrePtEkUcovQAAAOY"]
[Tue Jul 21 08:55:52.645950 2026] [security2:error] [pid 533360:tid 533576] [client 203.25.124.54:33915] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wso.php"] [unique_id "al9eSHUPuLYrePtEkUcovwAAANg"]
[Tue Jul 21 08:55:52.966110 2026] [security2:error] [pid 533360:tid 533536] [client 114.198.138.124:49772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eSHUPuLYrePtEkUcoyQAAALA"]
[Tue Jul 21 08:55:52.966215 2026] [security2:error] [pid 533360:tid 533536] [client 114.198.138.124:49772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eSHUPuLYrePtEkUcoyQAAALA"]
[Tue Jul 21 08:55:53.349851 2026] [security2:error] [pid 559070:tid 559258] [client 4.194.24.143:7678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/classwithtostring.php"] [unique_id "al9eSSy1f1FtKC137xsBhAAAAck"]
[Tue Jul 21 08:55:53.657455 2026] [security2:error] [pid 559070:tid 559214] [client 20.151.10.161:51060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/201.php"] [unique_id "al9eSSy1f1FtKC137xsBiAAAAZ0"]
[Tue Jul 21 08:55:53.748602 2026] [security2:error] [pid 559070:tid 559326] [client 203.25.124.32:40463] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-info.php"] [unique_id "al9eSSy1f1FtKC137xsBiQAAAg0"]
[Tue Jul 21 08:55:53.941364 2026] [security2:error] [pid 559070:tid 559318] [client 20.151.10.161:46011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-content/admin.php"] [unique_id "al9eSSy1f1FtKC137xsBiwAAAgU"]
[Tue Jul 21 08:55:54.415850 2026] [security2:error] [pid 533360:tid 533565] [client 4.194.24.143:7004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/claude.php"] [unique_id "al9eSnUPuLYrePtEkUco6AAAAM0"]
[Tue Jul 21 08:55:54.641209 2026] [security2:error] [pid 559070:tid 559283] [client 203.25.124.32:52319] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/s.php"] [unique_id "al9eSiy1f1FtKC137xsBkwAAAeI"]
[Tue Jul 21 08:55:54.676021 2026] [security2:error] [pid 559070:tid 559169] [remote 8.217.108.67:6050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pousadanaturalis.com.br"] [uri "/wp-login.php"] [unique_id "al9eSiy1f1FtKC137xsBlgAB_WI"]
[Tue Jul 21 08:55:54.876259 2026] [security2:error] [pid 559070:tid 559204] [client 20.104.96.117:7611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/777.php"] [unique_id "al9eSiy1f1FtKC137xsBmwAAAZM"]
[Tue Jul 21 08:55:54.890082 2026] [rewrite:warn] [pid 559070:tid 559135] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:55:55.148708 2026] [security2:error] [pid 559070:tid 559244] [client 20.151.10.161:45952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/f6.php"] [unique_id "al9eSyy1f1FtKC137xsBoQAAAbs"]
[Tue Jul 21 08:55:55.205515 2026] [security2:error] [pid 533360:tid 533542] [client 20.220.225.223:48245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/acew67.php"] [unique_id "al9eS3UPuLYrePtEkUco-QAAALY"]
[Tue Jul 21 08:55:55.249486 2026] [security2:error] [pid 533360:tid 533459] [remote 54.64.35.240:54286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.35.64.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9eS3UPuLYrePtEkUco_AAA6l8"]
[Tue Jul 21 08:55:55.438486 2026] [security2:error] [pid 559070:tid 559273] [client 4.194.24.143:7032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/config.php"] [unique_id "al9eSyy1f1FtKC137xsBqAAAAdg"]
[Tue Jul 21 08:55:55.688968 2026] [security2:error] [pid 559070:tid 559254] [client 65.21.113.253:54970] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eSyy1f1FtKC137xsBqQAAAcU"]
[Tue Jul 21 08:55:55.743856 2026] [security2:error] [pid 533360:tid 533619] [client 212.32.76.3:57271] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/69.php"] [unique_id "al9eS3UPuLYrePtEkUcpDAAAAQM"]
[Tue Jul 21 08:55:56.030994 2026] [security2:error] [pid 533360:tid 533586] [client 20.197.192.193:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/ww.php"] [unique_id "al9eTHUPuLYrePtEkUcpEAAAAOI"]
[Tue Jul 21 08:55:56.057201 2026] [security2:error] [pid 559070:tid 559223] [client 20.220.225.223:48226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9eTCy1f1FtKC137xsBrgAAAaY"]
[Tue Jul 21 08:55:56.068956 2026] [security2:error] [pid 533360:tid 533394] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eTHUPuLYrePtEkUcpEQAA7h4"]
[Tue Jul 21 08:55:56.069202 2026] [security2:error] [pid 533360:tid 533598] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eTHUPuLYrePtEkUcpEQAA7h4"]
[Tue Jul 21 08:55:56.228656 2026] [security2:error] [pid 533360:tid 533596] [client 173.252.95.35:60490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eTHUPuLYrePtEkUcpFAAAAOw"]
[Tue Jul 21 08:55:56.500757 2026] [security2:error] [pid 559070:tid 559252] [client 4.194.24.143:6358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/.dj/index.php"] [unique_id "al9eTCy1f1FtKC137xsBtAAAAcM"]
[Tue Jul 21 08:55:56.506705 2026] [security2:error] [pid 559070:tid 559278] [client 20.52.136.55:1548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/jp.php"] [unique_id "al9eTCy1f1FtKC137xsBtQAAAd0"]
[Tue Jul 21 08:55:56.539096 2026] [security2:error] [pid 559070:tid 559230] [client 20.104.96.117:7990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/ssixta.php"] [unique_id "al9eTCy1f1FtKC137xsBtwAAAa0"]
[Tue Jul 21 08:55:56.796246 2026] [security2:error] [pid 559070:tid 559229] [client 65.21.113.253:39078] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eTCy1f1FtKC137xsBsgAAAaw"]
[Tue Jul 21 08:55:56.888384 2026] [security2:error] [pid 559070:tid 559318] [client 69.171.230.116:49540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eTCy1f1FtKC137xsBwAAAAgU"]
[Tue Jul 21 08:55:56.939792 2026] [security2:error] [pid 559070:tid 559218] [client 203.25.124.71:54419] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-crom.php"] [unique_id "al9eTCy1f1FtKC137xsBwQAAAaE"]
[Tue Jul 21 08:55:57.024765 2026] [security2:error] [pid 559070:tid 559264] [client 20.151.10.161:51010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ops.php"] [unique_id "al9eTSy1f1FtKC137xsBwwAAAc8"]
[Tue Jul 21 08:55:57.038307 2026] [security2:error] [pid 559070:tid 559320] [client 20.151.10.161:46009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/inputs.php"] [unique_id "al9eTSy1f1FtKC137xsBxAAAAgc"]
[Tue Jul 21 08:55:57.119767 2026] [security2:error] [pid 533360:tid 533513] [client 173.252.95.12:45652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eTXUPuLYrePtEkUcpIAAAAJk"]
[Tue Jul 21 08:55:57.377304 2026] [security2:error] [pid 559070:tid 559185] [remote 65.111.13.121:22959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.13.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9eTSy1f1FtKC137xsByQAB53I"]
[Tue Jul 21 08:55:57.454457 2026] [security2:error] [pid 559070:tid 559268] [client 20.197.192.193:26880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/wp-css.php"] [unique_id "al9eTSy1f1FtKC137xsBzQAAAdM"]
[Tue Jul 21 08:55:57.604620 2026] [security2:error] [pid 559070:tid 559239] [client 69.171.230.15:34136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eTSy1f1FtKC137xsB1wAAAbY"]
[Tue Jul 21 08:55:57.727375 2026] [security2:error] [pid 559070:tid 559261] [client 115.245.198.210:45697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9eTSy1f1FtKC137xsB0wAAAcw"]
[Tue Jul 21 08:55:57.727501 2026] [security2:error] [pid 559070:tid 559261] [client 115.245.198.210:45697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9eTSy1f1FtKC137xsB0wAAAcw"]
[Tue Jul 21 08:55:57.938567 2026] [security2:error] [pid 533360:tid 533591] [client 20.220.225.223:34717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9eTXUPuLYrePtEkUcpLgAAAOc"]
[Tue Jul 21 08:55:57.941497 2026] [security2:error] [pid 533360:tid 533616] [client 212.32.76.3:28861] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9eTXUPuLYrePtEkUcpLwAAAQA"]
[Tue Jul 21 08:55:57.948006 2026] [security2:error] [pid 533360:tid 533528] [client 20.151.10.161:46040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/av.php"] [unique_id "al9eTXUPuLYrePtEkUcpMAAAAKg"]
[Tue Jul 21 08:55:57.953170 2026] [security2:error] [pid 533360:tid 533566] [client 20.197.192.193:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/cron.php"] [unique_id "al9eTXUPuLYrePtEkUcpMQAAAM4"]
[Tue Jul 21 08:55:58.076512 2026] [security2:error] [pid 559070:tid 559214] [client 20.220.225.223:48225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/bscclapb.php"] [unique_id "al9eTiy1f1FtKC137xsB3wAAAZ0"]
[Tue Jul 21 08:55:58.097471 2026] [security2:error] [pid 533360:tid 533597] [client 128.127.105.184:36152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eTnUPuLYrePtEkUcpMwAAAO0"]
[Tue Jul 21 08:55:58.097568 2026] [security2:error] [pid 533360:tid 533597] [client 128.127.105.184:36152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eTnUPuLYrePtEkUcpMwAAAO0"]
[Tue Jul 21 08:55:58.212260 2026] [security2:error] [pid 533360:tid 533379] [remote 199.189.225.40:46867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deniansantos.com"] [uri "/wp-login.php"] [unique_id "al9eTnUPuLYrePtEkUcpOAAAnA8"]
[Tue Jul 21 08:55:58.216848 2026] [security2:error] [pid 559070:tid 559309] [client 20.104.96.117:7554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/1c.php"] [unique_id "al9eTiy1f1FtKC137xsB4AAAAfw"]
[Tue Jul 21 08:55:58.253195 2026] [security2:error] [pid 559070:tid 559308] [client 4.194.24.143:7018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/.vscode/class-wp-http-client.php"] [unique_id "al9eTiy1f1FtKC137xsB4gAAAfs"]
[Tue Jul 21 08:55:58.425390 2026] [security2:error] [pid 533360:tid 533525] [client 69.171.230.28:37312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eTnUPuLYrePtEkUcpOwAAAKU"]
[Tue Jul 21 08:55:58.431245 2026] [security2:error] [pid 559070:tid 559283] [client 20.151.10.161:51026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ingfo.php"] [unique_id "al9eTiy1f1FtKC137xsB5AAAAeI"]
[Tue Jul 21 08:55:58.678564 2026] [security2:error] [pid 533360:tid 533542] [client 41.89.234.2:56111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eTnUPuLYrePtEkUcpQgAAALY"]
[Tue Jul 21 08:55:58.678676 2026] [security2:error] [pid 533360:tid 533542] [client 41.89.234.2:56111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eTnUPuLYrePtEkUcpQgAAALY"]
[Tue Jul 21 08:55:58.712338 2026] [security2:error] [pid 559070:tid 559264] [client 20.151.10.161:45912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/classwithtostring.php"] [unique_id "al9eTiy1f1FtKC137xsB6wAAAc8"]
[Tue Jul 21 08:55:58.726376 2026] [security2:error] [pid 559070:tid 559088] [remote 65.111.27.104:60761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9eTiy1f1FtKC137xsB5gACChE"]
[Tue Jul 21 08:55:58.770381 2026] [security2:error] [pid 533360:tid 533559] [client 20.151.10.161:49145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/201.php"] [unique_id "al9eTnUPuLYrePtEkUcpRQAAAMc"]
[Tue Jul 21 08:55:58.845343 2026] [security2:error] [pid 559070:tid 559270] [client 203.25.124.67:54053] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/click.php"] [unique_id "al9eTiy1f1FtKC137xsB7gAAAdU"]
[Tue Jul 21 08:55:58.941751 2026] [security2:error] [pid 533360:tid 533531] [client 180.153.236.33:53779] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "espacocandeia.com"] [uri "/"] [unique_id "al9eTnUPuLYrePtEkUcpSQAAAKs"], referer: http://espacocandeia.com/
[Tue Jul 21 08:55:58.941866 2026] [security2:error] [pid 533360:tid 533531] [client 180.153.236.33:53779] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "espacocandeia.com"] [uri "/"] [unique_id "al9eTnUPuLYrePtEkUcpSQAAAKs"], referer: http://espacocandeia.com/
[Tue Jul 21 08:55:59.065452 2026] [rewrite:warn] [pid 559070:tid 559149] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:55:59.095036 2026] [security2:error] [pid 533360:tid 533562] [client 182.189.99.211:47958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eT3UPuLYrePtEkUcpTAAAAMo"]
[Tue Jul 21 08:55:59.095154 2026] [security2:error] [pid 533360:tid 533562] [client 182.189.99.211:47958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eT3UPuLYrePtEkUcpTAAAAMo"]
[Tue Jul 21 08:55:59.143496 2026] [security2:error] [pid 533360:tid 533613] [client 20.220.225.223:43172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/billur.php"] [unique_id "al9eT3UPuLYrePtEkUcpTgAAAP0"]
[Tue Jul 21 08:55:59.206387 2026] [security2:error] [pid 559070:tid 559212] [client 20.151.10.161:45992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-content/themes/index.php"] [unique_id "al9eTyy1f1FtKC137xsB9wAAAZs"]
[Tue Jul 21 08:55:59.351276 2026] [autoindex:error] [pid 559070:tid 559291] [client 4.194.24.143:0] AH01276: Cannot serve directory /home3/bilili18/tainux.org/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:55:59.528459 2026] [security2:error] [pid 533360:tid 533553] [client 20.104.96.117:7599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/test2.php"] [unique_id "al9eT3UPuLYrePtEkUcpUgAAAME"]
[Tue Jul 21 08:55:59.548392 2026] [security2:error] [pid 533360:tid 533488] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eT3UPuLYrePtEkUcpVAAAoXw"]
[Tue Jul 21 08:55:59.548548 2026] [security2:error] [pid 533360:tid 533521] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eT3UPuLYrePtEkUcpVAAAoXw"]
[Tue Jul 21 08:55:59.707702 2026] [security2:error] [pid 559070:tid 559306] [client 4.194.24.143:6393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/.well-known/about.php"] [unique_id "al9eTyy1f1FtKC137xsCCQAAAfk"]
[Tue Jul 21 08:55:59.734598 2026] [security2:error] [pid 533360:tid 533532] [client 20.151.10.161:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-blog.php"] [unique_id "al9eT3UPuLYrePtEkUcpWgAAAKw"]
[Tue Jul 21 08:55:59.745339 2026] [security2:error] [pid 533360:tid 533546] [client 203.25.124.57:52609] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/byp.php"] [unique_id "al9eT3UPuLYrePtEkUcpWwAAALo"]
[Tue Jul 21 08:55:59.881460 2026] [security2:error] [pid 559070:tid 559260] [client 113.22.144.139:55402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eTyy1f1FtKC137xsCKQAAAcs"]
[Tue Jul 21 08:55:59.882579 2026] [security2:error] [pid 559070:tid 559260] [client 113.22.144.139:55402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eTyy1f1FtKC137xsCKQAAAcs"]
[Tue Jul 21 08:56:00.066573 2026] [autoindex:error] [pid 559070:tid 559325] [client 20.151.10.161:45977] AH01276: Cannot serve directory /home3/housei59/public_html/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:00.128403 2026] [security2:error] [pid 559070:tid 559132] [remote 189.126.65.178:10819] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "inovamedfortaleza.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "al9eUCy1f1FtKC137xsCSAAB7D0"], referer: https://inovamedfortaleza.com.br/
[Tue Jul 21 08:56:00.200447 2026] [security2:error] [pid 559070:tid 559327] [client 5.38.115.39:63275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eUCy1f1FtKC137xsCSgAAAg4"]
[Tue Jul 21 08:56:00.200540 2026] [security2:error] [pid 559070:tid 559327] [client 5.38.115.39:63275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eUCy1f1FtKC137xsCSgAAAg4"]
[Tue Jul 21 08:56:00.330101 2026] [security2:error] [pid 559070:tid 559183] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eUCy1f1FtKC137xsCVAABvHA"]
[Tue Jul 21 08:56:00.330416 2026] [security2:error] [pid 559070:tid 559245] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eUCy1f1FtKC137xsCVAABvHA"]
[Tue Jul 21 08:56:00.459568 2026] [security2:error] [pid 559070:tid 559264] [client 20.151.10.161:45977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-content/admin.php"] [unique_id "al9eUCy1f1FtKC137xsCWAAAAc8"]
[Tue Jul 21 08:56:00.501319 2026] [security2:error] [pid 559070:tid 559270] [client 20.220.225.223:46364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/mimpi.php"] [unique_id "al9eUCy1f1FtKC137xsCWgAAAdU"]
[Tue Jul 21 08:56:00.503897 2026] [security2:error] [pid 559070:tid 559230] [client 103.59.206.240:31320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eUCy1f1FtKC137xsCWwAAAa0"]
[Tue Jul 21 08:56:00.504028 2026] [security2:error] [pid 559070:tid 559230] [client 103.59.206.240:31320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eUCy1f1FtKC137xsCWwAAAa0"]
[Tue Jul 21 08:56:00.587686 2026] [security2:error] [pid 559070:tid 559219] [client 20.151.10.161:51059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/error_log.php"] [unique_id "al9eUCy1f1FtKC137xsCXwAAAaI"]
[Tue Jul 21 08:56:00.755166 2026] [autoindex:error] [pid 559070:tid 559202] [client 4.194.24.143:0] AH01276: Cannot serve directory /home3/bilili18/tainux.org/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:00.838499 2026] [security2:error] [pid 559070:tid 559258] [client 20.197.192.193:56787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/xxx.php"] [unique_id "al9eUCy1f1FtKC137xsCaQAAAck"]
[Tue Jul 21 08:56:00.921357 2026] [security2:error] [pid 533360:tid 533581] [client 20.220.225.223:60250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/wp-css.php"] [unique_id "al9eUHUPuLYrePtEkUcpbQAAAN0"]
[Tue Jul 21 08:56:00.938331 2026] [security2:error] [pid 559070:tid 559266] [client 212.32.76.3:28131] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/ateprivacy-policy-guide.php"] [unique_id "al9eUCy1f1FtKC137xsCbgAAAdE"]
[Tue Jul 21 08:56:00.939851 2026] [security2:error] [pid 559070:tid 559281] [client 20.151.10.161:45919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/adminfuns.php"] [unique_id "al9eUCy1f1FtKC137xsCbwAAAeA"]
[Tue Jul 21 08:56:00.939897 2026] [security2:error] [pid 559070:tid 559251] [client 20.104.96.117:7566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/buy.php"] [unique_id "al9eUCy1f1FtKC137xsCcAAAAcI"]
[Tue Jul 21 08:56:01.343597 2026] [security2:error] [pid 559070:tid 559252] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eUSy1f1FtKC137xsCdwABw08"]
[Tue Jul 21 08:56:01.503699 2026] [security2:error] [pid 559070:tid 559175] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eUSy1f1FtKC137xsCgAAByGg"]
[Tue Jul 21 08:56:01.503939 2026] [security2:error] [pid 559070:tid 559257] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eUSy1f1FtKC137xsCgAAByGg"]
[Tue Jul 21 08:56:01.630236 2026] [security2:error] [pid 533360:tid 533619] [client 20.104.96.117:7561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/ssend.php"] [unique_id "al9eUXUPuLYrePtEkUcpdgAAAQM"]
[Tue Jul 21 08:56:01.813086 2026] [security2:error] [pid 533360:tid 533531] [client 4.194.24.143:7035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/.well-known/acme-challenge/muse.php"] [unique_id "al9eUXUPuLYrePtEkUcpfQAAAKs"]
[Tue Jul 21 08:56:01.840696 2026] [security2:error] [pid 533360:tid 533598] [client 203.25.124.73:49839] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/fonts/index.php"] [unique_id "al9eUXUPuLYrePtEkUcpfgAAAO4"]
[Tue Jul 21 08:56:01.897162 2026] [security2:error] [pid 559070:tid 559280] [client 20.151.10.161:55813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/xenon1337.php"] [unique_id "al9eUSy1f1FtKC137xsChwAAAd8"]
[Tue Jul 21 08:56:01.921035 2026] [security2:error] [pid 559070:tid 559225] [client 20.151.10.161:46034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/goods.php"] [unique_id "al9eUSy1f1FtKC137xsCiQAAAag"]
[Tue Jul 21 08:56:01.940625 2026] [security2:error] [pid 559070:tid 559219] [client 20.220.225.223:34731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9eUSy1f1FtKC137xsCigAAAaI"]
[Tue Jul 21 08:56:01.950651 2026] [security2:error] [pid 559070:tid 559244] [client 20.197.192.193:63882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/samll.php"] [unique_id "al9eUSy1f1FtKC137xsCiwAAAbs"]
[Tue Jul 21 08:56:02.072923 2026] [security2:error] [pid 559070:tid 559245] [client 59.95.197.55:53798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eUiy1f1FtKC137xsCmgAAAbw"]
[Tue Jul 21 08:56:02.077526 2026] [security2:error] [pid 559070:tid 559245] [client 59.95.197.55:53798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eUiy1f1FtKC137xsCmgAAAbw"]
[Tue Jul 21 08:56:02.159742 2026] [security2:error] [pid 559070:tid 559296] [client 20.104.96.117:7256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/item.php"] [unique_id "al9eUiy1f1FtKC137xsCqAAAAe8"]
[Tue Jul 21 08:56:02.344507 2026] [security2:error] [pid 533360:tid 533560] [client 20.220.225.223:48218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/else1.php"] [unique_id "al9eUnUPuLYrePtEkUcphwAAAMg"]
[Tue Jul 21 08:56:02.428060 2026] [security2:error] [pid 533360:tid 533499] [client 20.151.10.161:46056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/ms-edit.php"] [unique_id "al9eUnUPuLYrePtEkUcpiQAAAIs"]
[Tue Jul 21 08:56:02.711863 2026] [security2:error] [pid 533360:tid 533402] [remote 41.76.214.143:47230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "growe-ag.jaypi.com.br"] [uri "/wp-login.php"] [unique_id "al9eUnUPuLYrePtEkUcpjgAA7SY"]
[Tue Jul 21 08:56:02.803213 2026] [security2:error] [pid 533360:tid 533548] [client 20.104.96.117:7244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/ss.php"] [unique_id "al9eUnUPuLYrePtEkUcpkgAAALw"]
[Tue Jul 21 08:56:02.840721 2026] [security2:error] [pid 533360:tid 533539] [client 4.194.24.143:6336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/.well-known/bdkr28_61cohkhh.php"] [unique_id "al9eUnUPuLYrePtEkUcplgAAALM"]
[Tue Jul 21 08:56:02.939697 2026] [security2:error] [pid 533360:tid 533504] [client 20.151.10.161:45990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/222.php"] [unique_id "al9eUnUPuLYrePtEkUcplwAAAJA"]
[Tue Jul 21 08:56:03.254397 2026] [security2:error] [pid 559070:tid 559299] [client 20.151.10.161:46078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/cgi-bin/index.php"] [unique_id "al9eUyy1f1FtKC137xsCtwAAAfI"]
[Tue Jul 21 08:56:03.314449 2026] [security2:error] [pid 559070:tid 559314] [client 212.32.76.10:22441] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/bltm/wp-login.php"] [unique_id "al9eUyy1f1FtKC137xsCtQAAAgE"]
[Tue Jul 21 08:56:03.453194 2026] [security2:error] [pid 559070:tid 559229] [client 114.198.138.124:50375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eUyy1f1FtKC137xsCuwAAAaw"]
[Tue Jul 21 08:56:03.453309 2026] [security2:error] [pid 559070:tid 559229] [client 114.198.138.124:50375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eUyy1f1FtKC137xsCuwAAAaw"]
[Tue Jul 21 08:56:03.460871 2026] [security2:error] [pid 559070:tid 559252] [client 20.104.96.117:7969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/hypo.php"] [unique_id "al9eUyy1f1FtKC137xsCvAAAAcM"]
[Tue Jul 21 08:56:03.571260 2026] [autoindex:error] [pid 533360:tid 533582] [client 20.151.10.161:45931] AH01276: Cannot serve directory /home3/housei59/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:03.608409 2026] [security2:error] [pid 559070:tid 559211] [client 168.167.81.163:62638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eUyy1f1FtKC137xsCvQAAAZo"]
[Tue Jul 21 08:56:03.608551 2026] [security2:error] [pid 559070:tid 559211] [client 168.167.81.163:62638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eUyy1f1FtKC137xsCvQAAAZo"]
[Tue Jul 21 08:56:03.812959 2026] [security2:error] [pid 533360:tid 533583] [client 20.220.225.223:22551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/dp.php"] [unique_id "al9eU3UPuLYrePtEkUcpqwAAAN8"]
[Tue Jul 21 08:56:03.872243 2026] [security2:error] [pid 533360:tid 533599] [client 20.151.10.161:45931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/BDKR28WP.php"] [unique_id "al9eU3UPuLYrePtEkUcprgAAAO8"]
[Tue Jul 21 08:56:03.899237 2026] [security2:error] [pid 559070:tid 559231] [client 4.194.24.143:42139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/.well-known/class-wp-http-client.php"] [unique_id "al9eUyy1f1FtKC137xsCwwAAAa4"]
[Tue Jul 21 08:56:04.241759 2026] [security2:error] [pid 559070:tid 559219] [client 20.52.136.55:1753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/error.php"] [unique_id "al9eVCy1f1FtKC137xsCxgAAAaI"]
[Tue Jul 21 08:56:04.248004 2026] [security2:error] [pid 559070:tid 559288] [client 203.25.124.43:56097] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/includes/nav.php"] [unique_id "al9eVCy1f1FtKC137xsCyQAAAec"]
[Tue Jul 21 08:56:04.253682 2026] [autoindex:error] [pid 559070:tid 559244] [client 20.151.10.161:46057] AH01276: Cannot serve directory /home3/housei59/public_html/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:04.254727 2026] [security2:error] [pid 533360:tid 533619] [client 20.151.10.161:55852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/test11.php"] [unique_id "al9eVHUPuLYrePtEkUcpsgAAAQM"]
[Tue Jul 21 08:56:04.387385 2026] [security2:error] [pid 533360:tid 533527] [client 20.151.10.161:49099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/ops.php"] [unique_id "al9eVHUPuLYrePtEkUcpuAAAAKc"]
[Tue Jul 21 08:56:04.428115 2026] [security2:error] [pid 533360:tid 533598] [client 65.21.113.253:33018] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eVHUPuLYrePtEkUcpuQAAAO4"]
[Tue Jul 21 08:56:04.521127 2026] [security2:error] [pid 559070:tid 559301] [client 74.7.175.185:46158] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.cezaretto.com.br"] [uri "/index.php"] [unique_id "al9eUyy1f1FtKC137xsCsgAB9Eo"]
[Tue Jul 21 08:56:04.602229 2026] [security2:error] [pid 533360:tid 533537] [client 20.104.96.117:7608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/users.php"] [unique_id "al9eVHUPuLYrePtEkUcpvQAAALE"]
[Tue Jul 21 08:56:04.650021 2026] [autoindex:error] [pid 559070:tid 559202] [client 20.151.10.161:46057] AH01276: Cannot serve directory /home3/housei59/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:04.727443 2026] [security2:error] [pid 559070:tid 559238] [client 93.152.221.13:62535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.71"] [uri "/phpinfo.php"] [unique_id "al9eVCy1f1FtKC137xsC1AAAAbU"]
[Tue Jul 21 08:56:04.789434 2026] [security2:error] [pid 559070:tid 559223] [client 20.151.10.161:46057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp.php"] [unique_id "al9eVCy1f1FtKC137xsC1wAAAaY"]
[Tue Jul 21 08:56:04.841936 2026] [security2:error] [pid 533360:tid 533484] [remote 157.66.26.183:60750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rlvmultiofertas.com"] [uri "/xmlrpc.php"] [unique_id "al9eVHUPuLYrePtEkUcpwgAAmHg"]
[Tue Jul 21 08:56:04.842089 2026] [security2:error] [pid 533360:tid 533512] [client 157.66.26.183:60750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rlvmultiofertas.com"] [uri "/xmlrpc.php"] [unique_id "al9eVHUPuLYrePtEkUcpwgAAmHg"]
[Tue Jul 21 08:56:04.959126 2026] [security2:error] [pid 559070:tid 559241] [client 4.194.24.143:42135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "al9eVCy1f1FtKC137xsC2wAAAbg"]
[Tue Jul 21 08:56:05.037572 2026] [security2:error] [pid 533360:tid 533514] [client 203.25.124.53:56865] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/shell3.php"] [unique_id "al9eVXUPuLYrePtEkUcpxQAAAJo"]
[Tue Jul 21 08:56:05.105661 2026] [security2:error] [pid 559070:tid 559213] [client 20.151.10.161:49086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/ingfo.php"] [unique_id "al9eVSy1f1FtKC137xsC3wAAAZw"]
[Tue Jul 21 08:56:05.119416 2026] [security2:error] [pid 559070:tid 559203] [client 93.152.221.13:52834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.71"] [uri "/test.php"] [unique_id "al9eVSy1f1FtKC137xsC4AAAAZI"]
[Tue Jul 21 08:56:05.200030 2026] [security2:error] [pid 559070:tid 559207] [client 20.151.10.161:45998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/abcd.php"] [unique_id "al9eVSy1f1FtKC137xsC4wAAAZY"]
[Tue Jul 21 08:56:05.203235 2026] [security2:error] [pid 559070:tid 559305] [client 20.104.96.117:7986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/177.php"] [unique_id "al9eVSy1f1FtKC137xsC5AAAAfg"]
[Tue Jul 21 08:56:05.217503 2026] [rewrite:warn] [pid 559070:tid 559181] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:56:05.254883 2026] [security2:error] [pid 533360:tid 533511] [client 20.220.225.223:46351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/bootstrap.php"] [unique_id "al9eVXUPuLYrePtEkUcpygAAAJc"]
[Tue Jul 21 08:56:05.376561 2026] [security2:error] [pid 559070:tid 559303] [client 20.220.225.223:34720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/dp.php"] [unique_id "al9eVSy1f1FtKC137xsC6wAAAfY"]
[Tue Jul 21 08:56:05.387714 2026] [security2:error] [pid 533360:tid 533459] [remote 65.111.10.249:11287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9eVXUPuLYrePtEkUcpzQAAil8"]
[Tue Jul 21 08:56:05.409362 2026] [security2:error] [pid 559070:tid 559306] [client 74.7.175.185:46162] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cezaretto.com.br"] [uri "/index.php"] [unique_id "al9eVSy1f1FtKC137xsC4gAB-QM"], referer: https://www.cezaretto.com.br/robots.txt
[Tue Jul 21 08:56:05.555193 2026] [security2:error] [pid 533360:tid 533447] [remote 216.73.160.187:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marketingderua.com.br"] [uri "/wp-login.php"] [unique_id "al9eVXUPuLYrePtEkUcp0gAAuFM"]
[Tue Jul 21 08:56:05.560802 2026] [security2:error] [pid 559070:tid 559240] [client 65.21.113.253:32892] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eVSy1f1FtKC137xsC3gAAAbc"]
[Tue Jul 21 08:56:05.569116 2026] [security2:error] [pid 559070:tid 559318] [client 20.151.10.161:46007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/a1.php"] [unique_id "al9eVSy1f1FtKC137xsC8gAAAgU"]
[Tue Jul 21 08:56:05.572436 2026] [security2:error] [pid 533360:tid 533545] [client 20.151.10.161:49105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/error_log.php"] [unique_id "al9eVXUPuLYrePtEkUcp0wAAALk"]
[Tue Jul 21 08:56:05.657676 2026] [security2:error] [pid 559070:tid 559230] [client 20.104.96.117:7294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/config.php"] [unique_id "al9eVSy1f1FtKC137xsC8wAAAa0"]
[Tue Jul 21 08:56:05.876726 2026] [security2:error] [pid 559070:tid 559315] [client 20.197.192.193:56220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/hunter.php"] [unique_id "al9eVSy1f1FtKC137xsDMwAAAgI"]
[Tue Jul 21 08:56:05.913126 2026] [security2:error] [pid 533360:tid 533574] [client 93.152.221.13:52951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.71"] [uri "/info.php"] [unique_id "al9eVXUPuLYrePtEkUcp2QAAANY"]
[Tue Jul 21 08:56:05.940614 2026] [security2:error] [pid 533360:tid 533516] [client 203.25.124.36:33867] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/hplfuns.php"] [unique_id "al9eVXUPuLYrePtEkUcp3AAAAJw"]
[Tue Jul 21 08:56:05.970670 2026] [security2:error] [pid 533360:tid 533607] [client 20.151.10.161:45984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9eVXUPuLYrePtEkUcp3gAAAPc"]
[Tue Jul 21 08:56:06.045242 2026] [security2:error] [pid 533360:tid 533577] [client 4.194.24.143:8174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/.well-known/index.php"] [unique_id "al9eVnUPuLYrePtEkUcp4QAAANk"]
[Tue Jul 21 08:56:06.145554 2026] [security2:error] [pid 533360:tid 533391] [remote 120.72.98.5:61828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.98.72.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "growe-ag.jaypi.com.br"] [uri "/wp-login.php"] [unique_id "al9eVnUPuLYrePtEkUcp5QAA-xs"]
[Tue Jul 21 08:56:06.149544 2026] [security2:error] [pid 533360:tid 533552] [client 20.104.96.117:7272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/gettest.php"] [unique_id "al9eVnUPuLYrePtEkUcp5gAAAMA"]
[Tue Jul 21 08:56:06.304430 2026] [security2:error] [pid 559070:tid 559228] [client 93.152.221.13:51711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.71"] [uri "/php.php"] [unique_id "al9eViy1f1FtKC137xsDVwAAAas"]
[Tue Jul 21 08:56:06.487514 2026] [security2:error] [pid 559070:tid 559196] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eViy1f1FtKC137xsDnAAB430"]
[Tue Jul 21 08:56:06.487640 2026] [security2:error] [pid 559070:tid 559284] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eViy1f1FtKC137xsDnAAB430"]
[Tue Jul 21 08:56:06.542691 2026] [security2:error] [pid 533360:tid 533565] [client 20.151.10.161:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/xenon1337.php"] [unique_id "al9eVnUPuLYrePtEkUcp-AAAAM0"]
[Tue Jul 21 08:56:06.612620 2026] [security2:error] [pid 533360:tid 533523] [client 117.210.181.114:35617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.181.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9eVnUPuLYrePtEkUcp-wAAAKM"]
[Tue Jul 21 08:56:06.612746 2026] [security2:error] [pid 533360:tid 533523] [client 117.210.181.114:35617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9eVnUPuLYrePtEkUcp-wAAAKM"]
[Tue Jul 21 08:56:06.697863 2026] [security2:error] [pid 533360:tid 533612] [client 93.152.221.13:55236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.71"] [uri "/php_info.php"] [unique_id "al9eVnUPuLYrePtEkUcp_AAAAPw"]
[Tue Jul 21 08:56:06.931636 2026] [security2:error] [pid 559070:tid 559232] [client 203.25.124.67:58985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/admin/index.php"] [unique_id "al9eViy1f1FtKC137xsDoQAAAa8"]
[Tue Jul 21 08:56:07.068914 2026] [security2:error] [pid 533360:tid 533498] [client 4.194.24.143:8169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/.well-known/ws.php"] [unique_id "al9eV3UPuLYrePtEkUcqBQAAAIo"]
[Tue Jul 21 08:56:07.096020 2026] [security2:error] [pid 559070:tid 559237] [client 93.152.221.13:63574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.71"] [uri "/i.php"] [unique_id "al9eVyy1f1FtKC137xsDpwAAAbQ"]
[Tue Jul 21 08:56:07.155423 2026] [security2:error] [pid 533360:tid 533582] [client 20.104.96.117:7993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/min.php"] [unique_id "al9eV3UPuLYrePtEkUcqBwAAAN4"]
[Tue Jul 21 08:56:07.496049 2026] [security2:error] [pid 533360:tid 533516] [client 93.152.221.13:61051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.71"] [uri "/pi.php"] [unique_id "al9eV3UPuLYrePtEkUcqDAAAAJw"]
[Tue Jul 21 08:56:07.601255 2026] [security2:error] [pid 533360:tid 533574] [client 69.171.230.27:33214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9eV3UPuLYrePtEkUcqEAAAANY"]
[Tue Jul 21 08:56:07.790745 2026] [security2:error] [pid 559070:tid 559297] [client 20.151.10.161:55832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/koala.php"] [unique_id "al9eVyy1f1FtKC137xsDugAAAfA"]
[Tue Jul 21 08:56:07.835691 2026] [security2:error] [pid 559070:tid 559261] [client 62.60.130.128:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jurandirdasilvafigue1760046599000.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/"] [unique_id "al9eVyy1f1FtKC137xsDvAAAAcw"]
[Tue Jul 21 08:56:08.074164 2026] [security2:error] [pid 559070:tid 559216] [client 62.60.130.128:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jurandirdasilvafigue1760046599000.jurandirdasilvafigue1751139710288.0711679.meusitehostgator.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9eWCy1f1FtKC137xsDxgAAAZ8"]
[Tue Jul 21 08:56:08.123179 2026] [security2:error] [pid 559070:tid 559281] [client 4.194.24.143:6363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/.xa/class-wp-http-client.php"] [unique_id "al9eWCy1f1FtKC137xsDygAAAeA"]
[Tue Jul 21 08:56:08.138075 2026] [security2:error] [pid 559070:tid 559308] [client 212.32.76.5:65123] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/admin-wolf.php"] [unique_id "al9eWCy1f1FtKC137xsDzAAAAfs"]
[Tue Jul 21 08:56:08.155068 2026] [security2:error] [pid 559070:tid 559217] [client 185.191.171.3:45962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivaconcierge.com.br"] [uri "/en/_tipo_imovel/condominio/"] [unique_id "al9eWCy1f1FtKC137xsDzQAAAaA"]
[Tue Jul 21 08:56:08.155177 2026] [security2:error] [pid 559070:tid 559217] [client 185.191.171.3:45962] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vivaconcierge.com.br"] [uri "/en/_tipo_imovel/condominio/"] [unique_id "al9eWCy1f1FtKC137xsDzQAAAaA"]
[Tue Jul 21 08:56:08.209442 2026] [security2:error] [pid 559070:tid 559255] [client 20.220.225.223:48217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/wp-explorer.php"] [unique_id "al9eWCy1f1FtKC137xsDzgAAAcY"]
[Tue Jul 21 08:56:08.299679 2026] [security2:error] [pid 559070:tid 559321] [client 93.152.221.13:64308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.71"] [uri "/admin/phpinfo.php"] [unique_id "al9eWCy1f1FtKC137xsD0AAAAgg"]
[Tue Jul 21 08:56:08.413123 2026] [security2:error] [pid 559070:tid 559090] [remote 41.186.86.12:14912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "frsadvocacia.net"] [uri "/wp-login.php"] [unique_id "al9eWCy1f1FtKC137xsD0gABxxM"]
[Tue Jul 21 08:56:08.541956 2026] [security2:error] [pid 559070:tid 559289] [client 20.197.192.193:63874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/abcd.php"] [unique_id "al9eWCy1f1FtKC137xsD1AAAAeg"]
[Tue Jul 21 08:56:08.605655 2026] [security2:error] [pid 533360:tid 533536] [client 62.60.130.128:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jurandirdasilvafigue1760046599000.0711679.meusitehostgator.com.br"] [uri "/"] [unique_id "al9eWHUPuLYrePtEkUcqHwAAALA"]
[Tue Jul 21 08:56:08.620632 2026] [autoindex:error] [pid 533360:tid 533527] [client 54.164.167.77:31463] AH01276: Cannot serve directory /home2/prove728/provendasfilial.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:08.621216 2026] [autoindex:error] [pid 533360:tid 533578] [client 13.219.67.125:1456] AH01276: Cannot serve directory /home2/prove728/provendasfrios.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:08.698462 2026] [security2:error] [pid 533360:tid 533562] [client 93.152.221.13:63114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.71"] [uri "/pinfo.php"] [unique_id "al9eWHUPuLYrePtEkUcqJAAAAMo"]
[Tue Jul 21 08:56:08.811710 2026] [security2:error] [pid 559070:tid 559307] [client 20.151.10.161:50978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/mac.php"] [unique_id "al9eWCy1f1FtKC137xsD2gAAAfo"]
[Tue Jul 21 08:56:08.852629 2026] [security2:error] [pid 533360:tid 533585] [client 62.60.130.128:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "jurandirdasilvafigue1760046599000.0711679.meusitehostgator.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9eWHUPuLYrePtEkUcqKQAAAOE"]
[Tue Jul 21 08:56:08.960985 2026] [security2:error] [pid 559070:tid 559247] [client 20.151.10.161:49128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/test11.php"] [unique_id "al9eWCy1f1FtKC137xsD3QAAAb4"]
[Tue Jul 21 08:56:08.993858 2026] [autoindex:error] [pid 533360:tid 533539] [client 54.164.167.77:4011] AH01276: Cannot serve directory /home2/prove728/provendasfilial.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:09.019120 2026] [security2:error] [pid 559070:tid 559223] [client 20.104.96.117:8085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/dvjul.php"] [unique_id "al9eWSy1f1FtKC137xsD3gAAAaY"]
[Tue Jul 21 08:56:09.045763 2026] [security2:error] [pid 559070:tid 559311] [client 203.25.124.40:37181] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "al9eWSy1f1FtKC137xsD3wAAAf4"]
[Tue Jul 21 08:56:09.153323 2026] [security2:error] [pid 533360:tid 533575] [client 4.194.24.143:54814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/0.php"] [unique_id "al9eWXUPuLYrePtEkUcqMQAAANc"]
[Tue Jul 21 08:56:09.156637 2026] [autoindex:error] [pid 559070:tid 559301] [client 13.219.67.125:28741] AH01276: Cannot serve directory /home2/prove728/provendasfrios.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:09.212791 2026] [security2:error] [pid 559070:tid 559302] [client 20.151.10.161:45989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/cgi-bin/admin.php"] [unique_id "al9eWSy1f1FtKC137xsD4QAAAfU"]
[Tue Jul 21 08:56:09.231162 2026] [security2:error] [pid 559070:tid 559282] [client 93.152.221.13:64545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "162.241.63.71"] [uri "/php_version.php"] [unique_id "al9eWSy1f1FtKC137xsD4gAAAeE"]
[Tue Jul 21 08:56:09.262030 2026] [security2:error] [pid 559070:tid 559254] [client 41.89.234.2:56597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eWSy1f1FtKC137xsD4wAAAcU"]
[Tue Jul 21 08:56:09.262277 2026] [security2:error] [pid 559070:tid 559254] [client 41.89.234.2:56597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eWSy1f1FtKC137xsD4wAAAcU"]
[Tue Jul 21 08:56:09.358735 2026] [security2:error] [pid 533360:tid 533438] [remote 124.55.178.99:40164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supremaservices.net"] [uri "/wp-login.php"] [unique_id "al9eWXUPuLYrePtEkUcqOAAAyEo"]
[Tue Jul 21 08:56:09.361715 2026] [security2:error] [pid 533360:tid 533428] [remote 45.90.123.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/wp-login.php"] [unique_id "al9eWXUPuLYrePtEkUcqOQAAy0A"]
[Tue Jul 21 08:56:09.510441 2026] [security2:error] [pid 559070:tid 559153] [remote 189.126.65.178:14724] ModSecurity: Warning. Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "1439"] [id "9009999"] [msg "8 char spam"] [hostname "inovamedfortaleza.com.br"] [uri "/wp-content/plugins/burst-statistics/endpoint.php"] [unique_id "al9eWSy1f1FtKC137xsD7AABs1I"], referer: https://inovamedfortaleza.com.br/
[Tue Jul 21 08:56:09.626301 2026] [security2:error] [pid 559070:tid 559253] [client 182.189.99.211:48039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eWSy1f1FtKC137xsD7QAAAcQ"]
[Tue Jul 21 08:56:09.626416 2026] [security2:error] [pid 559070:tid 559253] [client 182.189.99.211:48039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eWSy1f1FtKC137xsD7QAAAcQ"]
[Tue Jul 21 08:56:09.770428 2026] [security2:error] [pid 559070:tid 559305] [client 20.151.10.161:55845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9eWSy1f1FtKC137xsD8gAAAfg"]
[Tue Jul 21 08:56:09.975207 2026] [security2:error] [pid 559070:tid 559218] [client 194.99.104.35:48542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9eWSy1f1FtKC137xsD9gAAAaE"]
[Tue Jul 21 08:56:09.975293 2026] [security2:error] [pid 559070:tid 559218] [client 194.99.104.35:48542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9eWSy1f1FtKC137xsD9gAAAaE"]
[Tue Jul 21 08:56:10.046378 2026] [security2:error] [pid 559070:tid 559217] [client 203.25.124.213:48509] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/2021/file.php"] [unique_id "al9eWiy1f1FtKC137xsD-QAAAaA"]
[Tue Jul 21 08:56:10.054670 2026] [security2:error] [pid 559070:tid 559275] [client 93.152.221.13:51326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.63.71"] [uri "/.env"] [unique_id "al9eWiy1f1FtKC137xsD-gAAAdo"]
[Tue Jul 21 08:56:10.106451 2026] [security2:error] [pid 559070:tid 559306] [client 65.21.113.253:51976] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eWiy1f1FtKC137xsD_AAAAfk"]
[Tue Jul 21 08:56:10.214044 2026] [security2:error] [pid 533360:tid 533584] [client 4.194.24.143:6993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/000.php"] [unique_id "al9eWnUPuLYrePtEkUcqRgAAAOA"]
[Tue Jul 21 08:56:10.238336 2026] [security2:error] [pid 533360:tid 533605] [client 20.151.10.161:45914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/gettest.php"] [unique_id "al9eWnUPuLYrePtEkUcqSAAAAPU"]
[Tue Jul 21 08:56:10.506836 2026] [security2:error] [pid 559070:tid 559102] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eWiy1f1FtKC137xsEBwABxx8"]
[Tue Jul 21 08:56:10.506988 2026] [security2:error] [pid 559070:tid 559256] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eWiy1f1FtKC137xsEBwABxx8"]
[Tue Jul 21 08:56:10.736367 2026] [security2:error] [pid 533360:tid 533501] [client 20.104.96.117:7576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/biufile.php"] [unique_id "al9eWnUPuLYrePtEkUcqUAAAAI0"]
[Tue Jul 21 08:56:10.775913 2026] [security2:error] [pid 533360:tid 533540] [client 5.38.115.39:5525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eWnUPuLYrePtEkUcqUQAAALQ"]
[Tue Jul 21 08:56:10.776005 2026] [security2:error] [pid 533360:tid 533540] [client 5.38.115.39:5525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eWnUPuLYrePtEkUcqUQAAALQ"]
[Tue Jul 21 08:56:10.907334 2026] [security2:error] [pid 559070:tid 559114] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eWiy1f1FtKC137xsEEAABrys"]
[Tue Jul 21 08:56:10.907480 2026] [security2:error] [pid 559070:tid 559232] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eWiy1f1FtKC137xsEEAABrys"]
[Tue Jul 21 08:56:10.941437 2026] [security2:error] [pid 559070:tid 559202] [client 203.25.124.61:42379] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwenty/404.php"] [unique_id "al9eWiy1f1FtKC137xsEEQAAAZE"]
[Tue Jul 21 08:56:10.990762 2026] [security2:error] [pid 559070:tid 559192] [remote 47.251.82.1:56726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.82.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9eWiy1f1FtKC137xsEEwABxXk"]
[Tue Jul 21 08:56:11.031465 2026] [security2:error] [pid 559070:tid 559300] [client 20.197.192.193:63873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/xyn.php"] [unique_id "al9eWyy1f1FtKC137xsEGQAAAfM"]
[Tue Jul 21 08:56:11.064354 2026] [security2:error] [pid 559070:tid 559265] [client 93.152.221.13:51326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "162.241.63.71"] [uri "/.env.backup"] [unique_id "al9eWyy1f1FtKC137xsEGwAAAdA"]
[Tue Jul 21 08:56:11.147609 2026] [security2:error] [pid 559070:tid 559228] [client 20.220.225.223:20885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/old.php"] [unique_id "al9eWyy1f1FtKC137xsEHAAAAas"]
[Tue Jul 21 08:56:11.149736 2026] [security2:error] [pid 559070:tid 559237] [client 65.21.113.253:51878] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eWiy1f1FtKC137xsEDAAAAbQ"]
[Tue Jul 21 08:56:11.263217 2026] [security2:error] [pid 559070:tid 559261] [client 93.152.221.13:51326] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "162.241.63.71"] [uri "/config/.env"] [unique_id "al9eWyy1f1FtKC137xsEHQAAAcw"]
[Tue Jul 21 08:56:11.276022 2026] [security2:error] [pid 559070:tid 559200] [client 4.194.24.143:42166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/002.php"] [unique_id "al9eWyy1f1FtKC137xsEHgAAAY8"]
[Tue Jul 21 08:56:11.286717 2026] [security2:error] [pid 559070:tid 559239] [client 20.220.225.223:48252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/tkikikoko.php"] [unique_id "al9eWyy1f1FtKC137xsEIAAAAbY"]
[Tue Jul 21 08:56:11.301420 2026] [security2:error] [pid 533360:tid 533470] [remote 154.61.75.100:58796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "caminhoneiro.giovanoniadv.com.br"] [uri "/wp-login.php"] [unique_id "al9eW3UPuLYrePtEkUcqWwAAxWo"]
[Tue Jul 21 08:56:11.358460 2026] [autoindex:error] [pid 559070:tid 559287] [client 205.210.31.9:64484] AH01276: Cannot serve directory /home2/bavosc49/finance.bavos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:11.396122 2026] [security2:error] [pid 559070:tid 559286] [client 113.22.144.139:55969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eWyy1f1FtKC137xsEJAAAAeU"]
[Tue Jul 21 08:56:11.396293 2026] [security2:error] [pid 559070:tid 559286] [client 113.22.144.139:55969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eWyy1f1FtKC137xsEJAAAAeU"]
[Tue Jul 21 08:56:11.747878 2026] [security2:error] [pid 559070:tid 559267] [client 212.32.76.5:60933] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "al9eWyy1f1FtKC137xsELQAAAdI"]
[Tue Jul 21 08:56:12.094398 2026] [security2:error] [pid 559070:tid 559231] [client 20.151.10.161:51013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wefile.php"] [unique_id "al9eXCy1f1FtKC137xsENAAAAa4"]
[Tue Jul 21 08:56:12.248323 2026] [security2:error] [pid 533360:tid 533532] [client 20.151.10.161:45890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/simple.php"] [unique_id "al9eXHUPuLYrePtEkUcqbwAAAKw"]
[Tue Jul 21 08:56:12.306407 2026] [security2:error] [pid 533360:tid 533590] [client 4.194.24.143:42165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/0x.php"] [unique_id "al9eXHUPuLYrePtEkUcqdAAAAOY"]
[Tue Jul 21 08:56:12.542359 2026] [security2:error] [pid 533360:tid 533450] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eXHUPuLYrePtEkUcqeAAAr1Y"]
[Tue Jul 21 08:56:12.542502 2026] [security2:error] [pid 533360:tid 533535] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eXHUPuLYrePtEkUcqeAAAr1Y"]
[Tue Jul 21 08:56:12.564468 2026] [security2:error] [pid 533360:tid 533575] [client 59.95.197.55:54278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eXHUPuLYrePtEkUcqeQAAANc"]
[Tue Jul 21 08:56:12.565180 2026] [security2:error] [pid 533360:tid 533575] [client 59.95.197.55:54278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eXHUPuLYrePtEkUcqeQAAANc"]
[Tue Jul 21 08:56:12.640166 2026] [security2:error] [pid 559070:tid 559126] [remote 104.207.53.166:32047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9eXCy1f1FtKC137xsEQQABvzc"]
[Tue Jul 21 08:56:12.915189 2026] [security2:error] [pid 533360:tid 533541] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eXHUPuLYrePtEkUcqfgAAtSY"]
[Tue Jul 21 08:56:13.208990 2026] [security2:error] [pid 533360:tid 533540] [client 20.104.96.117:7274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/av.php"] [unique_id "al9eXXUPuLYrePtEkUcqhwAAALQ"]
[Tue Jul 21 08:56:13.334251 2026] [security2:error] [pid 533360:tid 533611] [client 4.194.24.143:5458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/0xd.php"] [unique_id "al9eXXUPuLYrePtEkUcqiQAAAPs"]
[Tue Jul 21 08:56:13.836893 2026] [security2:error] [pid 559070:tid 559276] [client 203.25.124.37:50099] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/xml.php"] [unique_id "al9eXSy1f1FtKC137xsEXQAAAds"]
[Tue Jul 21 08:56:14.051485 2026] [security2:error] [pid 533360:tid 533612] [client 20.220.225.223:48198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9eXnUPuLYrePtEkUcqoAAAAPw"]
[Tue Jul 21 08:56:14.065301 2026] [security2:error] [pid 533360:tid 533521] [client 114.198.138.124:50981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eXnUPuLYrePtEkUcqoQAAAKE"]
[Tue Jul 21 08:56:14.065397 2026] [security2:error] [pid 533360:tid 533521] [client 114.198.138.124:50981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eXnUPuLYrePtEkUcqoQAAAKE"]
[Tue Jul 21 08:56:14.082719 2026] [security2:error] [pid 533360:tid 533609] [client 20.220.225.223:34708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/ms-new.php"] [unique_id "al9eXnUPuLYrePtEkUcqogAAAPk"]
[Tue Jul 21 08:56:14.153864 2026] [security2:error] [pid 533360:tid 533598] [client 168.167.81.163:61558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eXnUPuLYrePtEkUcqowAAAO4"]
[Tue Jul 21 08:56:14.153964 2026] [security2:error] [pid 533360:tid 533598] [client 168.167.81.163:61558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eXnUPuLYrePtEkUcqowAAAO4"]
[Tue Jul 21 08:56:14.243019 2026] [security2:error] [pid 559070:tid 559327] [client 20.151.10.161:45907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xxx.php"] [unique_id "al9eXiy1f1FtKC137xsEZgAAAg4"]
[Tue Jul 21 08:56:14.281895 2026] [security2:error] [pid 559070:tid 559292] [client 20.197.192.193:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/we.php"] [unique_id "al9eXiy1f1FtKC137xsEagAAAes"]
[Tue Jul 21 08:56:14.384769 2026] [security2:error] [pid 559070:tid 559270] [client 20.151.10.161:51028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9eXiy1f1FtKC137xsEbQAAAdU"]
[Tue Jul 21 08:56:14.395484 2026] [security2:error] [pid 533360:tid 533591] [client 4.194.24.143:6342] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "tainux.org"] [uri "/1.php"] [unique_id "al9eXnUPuLYrePtEkUcqrwAAAOc"]
[Tue Jul 21 08:56:14.395599 2026] [security2:error] [pid 533360:tid 533591] [client 4.194.24.143:6342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/1.php"] [unique_id "al9eXnUPuLYrePtEkUcqrwAAAOc"]
[Tue Jul 21 08:56:14.821532 2026] [security2:error] [pid 559070:tid 559293] [client 65.21.113.253:51976] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eXiy1f1FtKC137xsEdgAAAew"]
[Tue Jul 21 08:56:14.838253 2026] [security2:error] [pid 559070:tid 559223] [client 203.25.124.69:47755] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-conflg/function.php"] [unique_id "al9eXiy1f1FtKC137xsEdwAAAaY"]
[Tue Jul 21 08:56:15.173161 2026] [security2:error] [pid 533360:tid 533588] [client 20.197.192.193:56805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.carrosselbuique.com.br"] [uri "/phpinfo.php1"] [unique_id "al9eX3UPuLYrePtEkUcqvQAAAOQ"]
[Tue Jul 21 08:56:15.230122 2026] [security2:error] [pid 559070:tid 559322] [client 20.151.10.161:49151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/koala.php"] [unique_id "al9eXyy1f1FtKC137xsEfQAAAgk"]
[Tue Jul 21 08:56:15.236340 2026] [security2:error] [pid 559070:tid 559283] [client 20.104.96.117:7587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/coffexium.php"] [unique_id "al9eXyy1f1FtKC137xsEfgAAAeI"]
[Tue Jul 21 08:56:15.381410 2026] [security2:error] [pid 559070:tid 559304] [client 20.220.225.223:60282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/akismet.php"] [unique_id "al9eXyy1f1FtKC137xsEkAAAAfc"]
[Tue Jul 21 08:56:15.447165 2026] [security2:error] [pid 533360:tid 533495] [client 4.194.24.143:42123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/100.php"] [unique_id "al9eX3UPuLYrePtEkUcqvwAAAIc"]
[Tue Jul 21 08:56:15.528148 2026] [security2:error] [pid 559070:tid 559297] [client 20.151.10.161:46027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/hypo.php"] [unique_id "al9eXyy1f1FtKC137xsElwAAAfA"]
[Tue Jul 21 08:56:15.641554 2026] [security2:error] [pid 533360:tid 533510] [client 203.25.124.66:40161] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/network_xo.php"] [unique_id "al9eX3UPuLYrePtEkUcqxAAAAJY"]
[Tue Jul 21 08:56:15.743330 2026] [security2:error] [pid 559070:tid 559228] [client 20.220.225.223:37608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/wp-editor.php"] [unique_id "al9eXyy1f1FtKC137xsEsQAAAas"]
[Tue Jul 21 08:56:15.885729 2026] [security2:error] [pid 559070:tid 559241] [client 128.127.105.184:47118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9eXyy1f1FtKC137xsEtgAAAbg"]
[Tue Jul 21 08:56:15.885861 2026] [security2:error] [pid 559070:tid 559241] [client 128.127.105.184:47118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9eXyy1f1FtKC137xsEtgAAAbg"]
[Tue Jul 21 08:56:15.906761 2026] [security2:error] [pid 559070:tid 559268] [client 65.21.113.253:51884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eXyy1f1FtKC137xsEkgAAAdM"]
[Tue Jul 21 08:56:16.002204 2026] [security2:error] [pid 559070:tid 559276] [client 20.197.192.193:63902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/byp8.php"] [unique_id "al9eYCy1f1FtKC137xsEuAAAAds"]
[Tue Jul 21 08:56:16.259193 2026] [security2:error] [pid 559070:tid 559306] [client 20.220.225.223:48211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/wp-css.php"] [unique_id "al9eYCy1f1FtKC137xsEugAAAfk"]
[Tue Jul 21 08:56:16.466578 2026] [security2:error] [pid 559070:tid 559242] [client 4.194.24.143:42128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/12.php"] [unique_id "al9eYCy1f1FtKC137xsEvgAAAbk"]
[Tue Jul 21 08:56:16.645976 2026] [security2:error] [pid 559070:tid 559290] [client 203.25.124.72:24139] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/sitemaps/"] [unique_id "al9eYCy1f1FtKC137xsEwQAAAek"]
[Tue Jul 21 08:56:16.758703 2026] [security2:error] [pid 559070:tid 559289] [client 20.104.96.117:7944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/core.php"] [unique_id "al9eYCy1f1FtKC137xsEwwAAAeg"]
[Tue Jul 21 08:56:16.930571 2026] [security2:error] [pid 559070:tid 559187] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eYCy1f1FtKC137xsExQABz3Q"]
[Tue Jul 21 08:56:16.930745 2026] [security2:error] [pid 559070:tid 559264] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eYCy1f1FtKC137xsExQABz3Q"]
[Tue Jul 21 08:56:17.017258 2026] [autoindex:error] [pid 533360:tid 533509] [client 20.151.10.161:46076] AH01276: Cannot serve directory /home3/housei59/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:17.042490 2026] [security2:error] [pid 559070:tid 559311] [client 20.151.10.161:50962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/2P.php"] [unique_id "al9eYSy1f1FtKC137xsExgAAAf4"]
[Tue Jul 21 08:56:17.293402 2026] [security2:error] [pid 533360:tid 533569] [client 20.151.10.161:46076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/chosen.php"] [unique_id "al9eYXUPuLYrePtEkUcq3QAAANE"]
[Tue Jul 21 08:56:17.328475 2026] [security2:error] [pid 559070:tid 559227] [client 20.104.96.117:8067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/als.php"] [unique_id "al9eYSy1f1FtKC137xsEywAAAao"]
[Tue Jul 21 08:56:17.364327 2026] [security2:error] [pid 559070:tid 559200] [client 216.244.66.243:45978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ssvistorias.com.br"] [uri "/loj/is-there-another-surest-way-to-track-a-partner.html"] [unique_id "al9eYSy1f1FtKC137xsE0AAAAY8"]
[Tue Jul 21 08:56:17.364425 2026] [security2:error] [pid 559070:tid 559200] [client 216.244.66.243:45978] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ssvistorias.com.br"] [uri "/loj/is-there-another-surest-way-to-track-a-partner.html"] [unique_id "al9eYSy1f1FtKC137xsE0AAAAY8"]
[Tue Jul 21 08:56:17.397887 2026] [security2:error] [pid 559070:tid 559320] [client 117.210.181.114:44705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.181.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9eYSy1f1FtKC137xsE0QAAAgc"]
[Tue Jul 21 08:56:17.397964 2026] [security2:error] [pid 559070:tid 559320] [client 117.210.181.114:44705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9eYSy1f1FtKC137xsE0QAAAgc"]
[Tue Jul 21 08:56:17.529030 2026] [security2:error] [pid 559070:tid 559248] [client 4.194.24.143:54824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/123.php"] [unique_id "al9eYSy1f1FtKC137xsE1QAAAb8"]
[Tue Jul 21 08:56:17.545237 2026] [security2:error] [pid 559070:tid 559226] [client 203.25.124.71:58797] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/pomo/index.php"] [unique_id "al9eYSy1f1FtKC137xsE1wAAAak"]
[Tue Jul 21 08:56:17.636844 2026] [security2:error] [pid 559070:tid 559297] [client 20.151.10.161:48616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/mac.php"] [unique_id "al9eYSy1f1FtKC137xsE2AAAAfA"]
[Tue Jul 21 08:56:18.081613 2026] [security2:error] [pid 533360:tid 533514] [client 20.220.225.223:38751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/wp-explorer.php"] [unique_id "al9eYnUPuLYrePtEkUcq7gAAAJo"]
[Tue Jul 21 08:56:18.243247 2026] [security2:error] [pid 533360:tid 533617] [client 20.104.96.117:7248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/simple.php"] [unique_id "al9eYnUPuLYrePtEkUcq9QAAAQE"]
[Tue Jul 21 08:56:18.554693 2026] [security2:error] [pid 533360:tid 533584] [client 4.194.24.143:42146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/13.php"] [unique_id "al9eYnUPuLYrePtEkUcq-QAAAOA"]
[Tue Jul 21 08:56:18.583320 2026] [security2:error] [pid 559070:tid 559212] [client 20.220.225.223:34738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/track.php"] [unique_id "al9eYiy1f1FtKC137xsE5QAAAZs"]
[Tue Jul 21 08:56:18.638661 2026] [security2:error] [pid 559070:tid 559276] [client 20.220.225.223:21596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/ace2.php"] [unique_id "al9eYiy1f1FtKC137xsE6AAAAds"]
[Tue Jul 21 08:56:18.639740 2026] [security2:error] [pid 533360:tid 533536] [client 212.32.76.8:64333] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/plugins/revslider/includes/external/page/"] [unique_id "al9eYnUPuLYrePtEkUcq_AAAALA"]
[Tue Jul 21 08:56:19.145195 2026] [security2:error] [pid 559070:tid 559292] [client 20.220.225.223:34178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9eYyy1f1FtKC137xsE7QAAAes"]
[Tue Jul 21 08:56:19.152276 2026] [security2:error] [pid 533360:tid 533562] [client 20.151.10.161:49085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/25d653587fdfd1.php"] [unique_id "al9eY3UPuLYrePtEkUcrAQAAAMo"]
[Tue Jul 21 08:56:19.285379 2026] [security2:error] [pid 559070:tid 559123] [remote 114.34.90.9:38160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinculampe.com.br"] [uri "/wp-login.php"] [unique_id "al9eYyy1f1FtKC137xsE8AAByzQ"]
[Tue Jul 21 08:56:19.332796 2026] [security2:error] [pid 559070:tid 559295] [client 20.104.96.117:7998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/init.php"] [unique_id "al9eYyy1f1FtKC137xsE8wAAAe4"]
[Tue Jul 21 08:56:19.383520 2026] [security2:error] [pid 559070:tid 559220] [client 65.21.113.253:51976] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eYyy1f1FtKC137xsE9AAAAaM"]
[Tue Jul 21 08:56:19.542206 2026] [security2:error] [pid 533360:tid 533531] [client 212.32.76.7:47713] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "al9eY3UPuLYrePtEkUcrCwAAAKs"]
[Tue Jul 21 08:56:19.609969 2026] [security2:error] [pid 559070:tid 559319] [client 4.194.24.143:42120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/133.php"] [unique_id "al9eYyy1f1FtKC137xsE9gAAAgY"]
[Tue Jul 21 08:56:19.920573 2026] [security2:error] [pid 533360:tid 533558] [client 20.220.225.223:48228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/akismet.php"] [unique_id "al9eY3UPuLYrePtEkUcrFAAAAMY"]
[Tue Jul 21 08:56:19.931554 2026] [security2:error] [pid 533360:tid 533615] [client 41.89.234.2:57064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eY3UPuLYrePtEkUcrFQAAAP8"]
[Tue Jul 21 08:56:19.931675 2026] [security2:error] [pid 533360:tid 533615] [client 41.89.234.2:57064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eY3UPuLYrePtEkUcrFQAAAP8"]
[Tue Jul 21 08:56:20.172089 2026] [security2:error] [pid 559070:tid 559243] [client 20.220.225.223:34877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/cro.php"] [unique_id "al9eZCy1f1FtKC137xsE_AAAAbo"]
[Tue Jul 21 08:56:20.231009 2026] [security2:error] [pid 533360:tid 533540] [client 182.189.99.211:48419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eZHUPuLYrePtEkUcrGgAAALQ"]
[Tue Jul 21 08:56:20.231683 2026] [security2:error] [pid 533360:tid 533540] [client 182.189.99.211:48419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eZHUPuLYrePtEkUcrGgAAALQ"]
[Tue Jul 21 08:56:20.301641 2026] [security2:error] [pid 533360:tid 533576] [client 20.151.10.161:51024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/.well-known/about.php"] [unique_id "al9eZHUPuLYrePtEkUcrHAAAANg"]
[Tue Jul 21 08:56:20.335947 2026] [security2:error] [pid 559070:tid 559288] [client 198.44.157.162:57070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9eZCy1f1FtKC137xsFAgAAAec"]
[Tue Jul 21 08:56:20.336071 2026] [security2:error] [pid 559070:tid 559288] [client 198.44.157.162:57070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9eZCy1f1FtKC137xsFAgAAAec"]
[Tue Jul 21 08:56:20.354863 2026] [security2:error] [pid 559070:tid 559215] [client 20.104.96.117:7270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/fpwch.php"] [unique_id "al9eZCy1f1FtKC137xsFBAAAAZ4"]
[Tue Jul 21 08:56:20.426358 2026] [security2:error] [pid 559070:tid 559322] [client 20.220.225.223:34246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9eZCy1f1FtKC137xsFBQAAAgk"]
[Tue Jul 21 08:56:20.437467 2026] [security2:error] [pid 559070:tid 559248] [client 212.32.76.3:46637] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/nrhogjyecktixbal0fnt5Cakc.php"] [unique_id "al9eZCy1f1FtKC137xsFBgAAAb8"]
[Tue Jul 21 08:56:20.443388 2026] [security2:error] [pid 559070:tid 559204] [client 65.21.113.253:53436] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eZCy1f1FtKC137xsE-gAAAZM"]
[Tue Jul 21 08:56:20.644288 2026] [security2:error] [pid 559070:tid 559221] [client 4.194.24.143:42150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/155.php"] [unique_id "al9eZCy1f1FtKC137xsFCgAAAaQ"]
[Tue Jul 21 08:56:20.695005 2026] [security2:error] [pid 533360:tid 533517] [client 20.220.225.223:38733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.sscoenper.com.br"] [uri "/ms.php"] [unique_id "al9eZHUPuLYrePtEkUcrJAAAAJ0"]
[Tue Jul 21 08:56:20.849087 2026] [security2:error] [pid 559070:tid 559212] [client 20.151.10.161:49121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wefile.php"] [unique_id "al9eZCy1f1FtKC137xsFFgAAAZs"]
[Tue Jul 21 08:56:20.963248 2026] [security2:error] [pid 533360:tid 533554] [client 20.104.96.117:7577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/domvf.php"] [unique_id "al9eZHUPuLYrePtEkUcrKgAAAMI"]
[Tue Jul 21 08:56:20.972855 2026] [autoindex:error] [pid 533360:tid 533504] [client 20.151.10.161:46003] AH01276: Cannot serve directory /home3/housei59/public_html/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:21.271505 2026] [security2:error] [pid 533360:tid 533599] [client 20.151.10.161:46003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/als.php"] [unique_id "al9eZXUPuLYrePtEkUcrMAAAAO8"]
[Tue Jul 21 08:56:21.337468 2026] [security2:error] [pid 533360:tid 533494] [client 203.25.124.51:27551] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-trackback.php"] [unique_id "al9eZXUPuLYrePtEkUcrNAAAAIY"]
[Tue Jul 21 08:56:21.362385 2026] [security2:error] [pid 533360:tid 533567] [client 20.104.96.117:7564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp.php"] [unique_id "al9eZXUPuLYrePtEkUcrNgAAAM8"]
[Tue Jul 21 08:56:21.395222 2026] [security2:error] [pid 559070:tid 559194] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eZSy1f1FtKC137xsFGwAB3Hs"]
[Tue Jul 21 08:56:21.395362 2026] [security2:error] [pid 559070:tid 559277] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eZSy1f1FtKC137xsFGwAB3Hs"]
[Tue Jul 21 08:56:21.445943 2026] [security2:error] [pid 559070:tid 559125] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eZSy1f1FtKC137xsFHgAB_TY"]
[Tue Jul 21 08:56:21.446067 2026] [security2:error] [pid 559070:tid 559310] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eZSy1f1FtKC137xsFHgAB_TY"]
[Tue Jul 21 08:56:21.449716 2026] [access_compat:error] [pid 533360:tid 533611] [client 162.241.63.68:27756] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:56:21.565928 2026] [security2:error] [pid 559070:tid 559306] [client 5.38.115.39:56240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eZSy1f1FtKC137xsFIwAAAfk"]
[Tue Jul 21 08:56:21.566105 2026] [security2:error] [pid 559070:tid 559306] [client 5.38.115.39:56240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eZSy1f1FtKC137xsFIwAAAfk"]
[Tue Jul 21 08:56:21.674276 2026] [security2:error] [pid 533360:tid 533533] [client 4.194.24.143:54656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/166.php"] [unique_id "al9eZXUPuLYrePtEkUcrPwAAAK0"]
[Tue Jul 21 08:56:21.795355 2026] [security2:error] [pid 533360:tid 533600] [client 103.59.206.240:31296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eZXUPuLYrePtEkUcrQgAAAPA"]
[Tue Jul 21 08:56:21.795468 2026] [security2:error] [pid 533360:tid 533600] [client 103.59.206.240:31296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eZXUPuLYrePtEkUcrQgAAAPA"]
[Tue Jul 21 08:56:21.795681 2026] [security2:error] [pid 533360:tid 533603] [client 20.104.96.117:7981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/class.php"] [unique_id "al9eZXUPuLYrePtEkUcrQwAAAPM"]
[Tue Jul 21 08:56:21.831234 2026] [security2:error] [pid 559070:tid 559217] [client 113.22.144.139:56480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eZSy1f1FtKC137xsFJQAAAaA"]
[Tue Jul 21 08:56:21.832026 2026] [security2:error] [pid 559070:tid 559217] [client 113.22.144.139:56480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eZSy1f1FtKC137xsFJQAAAaA"]
[Tue Jul 21 08:56:22.010370 2026] [security2:error] [pid 559070:tid 559303] [client 20.197.192.193:61074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/user.php"] [unique_id "al9eZiy1f1FtKC137xsFJwAAAfY"]
[Tue Jul 21 08:56:22.115219 2026] [security2:error] [pid 559070:tid 559214] [client 20.104.96.117:7563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/echkm.php"] [unique_id "al9eZiy1f1FtKC137xsFKgAAAZ0"]
[Tue Jul 21 08:56:22.242058 2026] [security2:error] [pid 559070:tid 559230] [client 203.25.124.35:41927] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/ty.php"] [unique_id "al9eZiy1f1FtKC137xsFLgAAAa0"]
[Tue Jul 21 08:56:22.551405 2026] [security2:error] [pid 559070:tid 559215] [client 20.104.96.117:7982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/lib.php"] [unique_id "al9eZiy1f1FtKC137xsFNAAAAZ4"]
[Tue Jul 21 08:56:22.565422 2026] [security2:error] [pid 559070:tid 559110] [remote 72.167.132.114:47700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lp.agenciawats.com.br"] [uri "/wp-login.php"] [unique_id "al9eZiy1f1FtKC137xsFNQABoSc"]
[Tue Jul 21 08:56:22.730878 2026] [security2:error] [pid 559070:tid 559280] [client 4.194.24.143:28639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/2.php"] [unique_id "al9eZiy1f1FtKC137xsFNwAAAd8"]
[Tue Jul 21 08:56:22.787405 2026] [autoindex:error] [pid 559070:tid 559258] [client 205.210.31.164:0] AH01276: Cannot serve directory /home4/chefdo14/buddyclub.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:23.046509 2026] [security2:error] [pid 533360:tid 533548] [client 59.95.197.55:54766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eZ3UPuLYrePtEkUcrWgAAALw"]
[Tue Jul 21 08:56:23.046630 2026] [security2:error] [pid 533360:tid 533548] [client 59.95.197.55:54766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eZ3UPuLYrePtEkUcrWgAAALw"]
[Tue Jul 21 08:56:23.098023 2026] [security2:error] [pid 559070:tid 559283] [client 20.220.225.223:34263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/dp.php"] [unique_id "al9eZyy1f1FtKC137xsFPgAAAeI"]
[Tue Jul 21 08:56:23.141101 2026] [security2:error] [pid 559070:tid 559221] [client 20.104.96.117:7597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/login.php"] [unique_id "al9eZyy1f1FtKC137xsFPwAAAaQ"]
[Tue Jul 21 08:56:23.313003 2026] [security2:error] [pid 559070:tid 559203] [client 20.151.10.161:45899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/pol.php"] [unique_id "al9eZyy1f1FtKC137xsFQgAAAZI"]
[Tue Jul 21 08:56:23.329673 2026] [security2:error] [pid 559070:tid 559253] [client 212.32.76.7:46815] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/default.php"] [unique_id "al9eZyy1f1FtKC137xsFQwAAAcQ"]
[Tue Jul 21 08:56:23.511155 2026] [security2:error] [pid 533360:tid 533476] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eZ3UPuLYrePtEkUcraQAAjnA"]
[Tue Jul 21 08:56:23.511314 2026] [security2:error] [pid 533360:tid 533502] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eZ3UPuLYrePtEkUcraQAAjnA"]
[Tue Jul 21 08:56:23.708725 2026] [security2:error] [pid 533360:tid 533547] [client 20.104.96.117:7282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/a2.php"] [unique_id "al9eZ3UPuLYrePtEkUcrawAAALs"]
[Tue Jul 21 08:56:23.759132 2026] [security2:error] [pid 533360:tid 533543] [client 4.194.24.143:37400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/2026w.php"] [unique_id "al9eZ3UPuLYrePtEkUcrbAAAALc"]
[Tue Jul 21 08:56:23.934343 2026] [security2:error] [pid 559070:tid 559305] [client 20.197.192.193:27093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/akismet.php"] [unique_id "al9eZyy1f1FtKC137xsFSgAAAfg"]
[Tue Jul 21 08:56:24.017110 2026] [security2:error] [pid 559070:tid 559212] [client 65.21.113.253:51976] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eaCy1f1FtKC137xsFTAAAAZs"]
[Tue Jul 21 08:56:24.303274 2026] [security2:error] [pid 559070:tid 559274] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eaCy1f1FtKC137xsFTQAB2Xk"]
[Tue Jul 21 08:56:24.364696 2026] [security2:error] [pid 559070:tid 559241] [client 20.104.96.117:7983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/d61.php"] [unique_id "al9eaCy1f1FtKC137xsFUgAAAbg"]
[Tue Jul 21 08:56:24.483589 2026] [security2:error] [pid 559070:tid 559317] [client 20.151.10.161:45909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/file5.php"] [unique_id "al9eaCy1f1FtKC137xsFVwAAAgQ"]
[Tue Jul 21 08:56:24.537156 2026] [security2:error] [pid 533360:tid 533529] [client 20.220.225.223:22588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/cron-tab.php"] [unique_id "al9eaHUPuLYrePtEkUcregAAAKk"]
[Tue Jul 21 08:56:24.599896 2026] [security2:error] [pid 533360:tid 533611] [client 20.197.192.193:47356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/ops.php"] [unique_id "al9eaHUPuLYrePtEkUcrfAAAAPs"]
[Tue Jul 21 08:56:24.768337 2026] [security2:error] [pid 559070:tid 559224] [client 168.167.81.163:60293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eaCy1f1FtKC137xsFWgAAAac"]
[Tue Jul 21 08:56:24.768459 2026] [security2:error] [pid 559070:tid 559224] [client 168.167.81.163:60293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eaCy1f1FtKC137xsFWgAAAac"]
[Tue Jul 21 08:56:24.793786 2026] [security2:error] [pid 559070:tid 559284] [client 20.104.96.117:7984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/info.php"] [unique_id "al9eaCy1f1FtKC137xsFWwAAAeM"]
[Tue Jul 21 08:56:24.799582 2026] [security2:error] [pid 533360:tid 533522] [client 4.194.24.143:54819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/222.php"] [unique_id "al9eaHUPuLYrePtEkUcrhAAAAKI"]
[Tue Jul 21 08:56:25.086342 2026] [security2:error] [pid 533360:tid 533536] [client 65.21.113.253:53444] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eaHUPuLYrePtEkUcrfgAAALA"]
[Tue Jul 21 08:56:25.323355 2026] [security2:error] [pid 533360:tid 533597] [client 20.151.10.161:45893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9eaXUPuLYrePtEkUcrjgAAAO0"]
[Tue Jul 21 08:56:25.367986 2026] [security2:error] [pid 533360:tid 533546] [client 20.104.96.117:7957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/11.php"] [unique_id "al9eaXUPuLYrePtEkUcrjwAAALo"]
[Tue Jul 21 08:56:25.535447 2026] [security2:error] [pid 533360:tid 533444] [remote 54.39.203.115:37292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "jurencosmetics.com"] [uri "/product/senscience-true-hue-senscience-true-hue-home-care-shampoo-and-conditioner-kit-300-ml-10-2oz/"] [unique_id "al9eaXUPuLYrePtEkUcrmAAAs1A"]
[Tue Jul 21 08:56:25.535584 2026] [security2:error] [pid 533360:tid 533539] [client 54.39.203.115:37292] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jurencosmetics.com"] [uri "/product/senscience-true-hue-senscience-true-hue-home-care-shampoo-and-conditioner-kit-300-ml-10-2oz/"] [unique_id "al9eaXUPuLYrePtEkUcrmAAAs1A"]
[Tue Jul 21 08:56:25.597657 2026] [security2:error] [pid 559070:tid 559256] [client 114.198.138.124:51561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eaSy1f1FtKC137xsFZAAAAcc"]
[Tue Jul 21 08:56:25.597741 2026] [security2:error] [pid 559070:tid 559256] [client 114.198.138.124:51561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eaSy1f1FtKC137xsFZAAAAcc"]
[Tue Jul 21 08:56:25.645092 2026] [autoindex:error] [pid 559070:tid 559294] [client 101.33.80.42:53936] AH01276: Cannot serve directory /home2/adri0010/statusedigital.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:25.744931 2026] [security2:error] [pid 559070:tid 559320] [client 20.197.192.193:27181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/ace2.php"] [unique_id "al9eaSy1f1FtKC137xsFZwAAAgc"]
[Tue Jul 21 08:56:25.830000 2026] [security2:error] [pid 533360:tid 533570] [client 4.194.24.143:37389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/2p.php"] [unique_id "al9eaXUPuLYrePtEkUcrngAAANI"]
[Tue Jul 21 08:56:25.838982 2026] [security2:error] [pid 559070:tid 559280] [client 212.32.76.3:62681] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/SimplePie/font-editor.php"] [unique_id "al9eaSy1f1FtKC137xsFagAAAd8"]
[Tue Jul 21 08:56:25.873879 2026] [security2:error] [pid 559070:tid 559226] [client 20.197.192.193:63931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/term.php"] [unique_id "al9eaSy1f1FtKC137xsFawAAAak"]
[Tue Jul 21 08:56:26.312267 2026] [security2:error] [pid 559070:tid 559233] [client 20.220.225.223:58909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/fffm.php"] [unique_id "al9eaiy1f1FtKC137xsFdAAAAbA"]
[Tue Jul 21 08:56:26.623997 2026] [security2:error] [pid 533360:tid 533573] [client 20.220.225.223:34201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/old.php"] [unique_id "al9eanUPuLYrePtEkUcrrAAAANU"]
[Tue Jul 21 08:56:26.649940 2026] [security2:error] [pid 533360:tid 533545] [client 20.104.96.117:7985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/v2.php"] [unique_id "al9eanUPuLYrePtEkUcrrQAAALk"]
[Tue Jul 21 08:56:26.860033 2026] [security2:error] [pid 559070:tid 559216] [client 4.194.24.143:5459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/2p.update.php"] [unique_id "al9eaiy1f1FtKC137xsFfwAAAZ8"]
[Tue Jul 21 08:56:26.931087 2026] [security2:error] [pid 533360:tid 533549] [client 20.197.192.193:61073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/ah25.php"] [unique_id "al9eanUPuLYrePtEkUcrswAAAL0"]
[Tue Jul 21 08:56:27.124950 2026] [security2:error] [pid 559070:tid 559269] [client 20.104.96.117:7999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/panel.php"] [unique_id "al9eayy1f1FtKC137xsFhAAAAdQ"]
[Tue Jul 21 08:56:27.136819 2026] [security2:error] [pid 559070:tid 559242] [client 203.25.124.37:64111] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/wp-conflg.php"] [unique_id "al9eayy1f1FtKC137xsFhQAAAbk"]
[Tue Jul 21 08:56:27.248322 2026] [security2:error] [pid 559070:tid 559295] [client 194.99.104.35:56346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eayy1f1FtKC137xsFiAAAAe4"]
[Tue Jul 21 08:56:27.248433 2026] [security2:error] [pid 559070:tid 559295] [client 194.99.104.35:56346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eayy1f1FtKC137xsFiAAAAe4"]
[Tue Jul 21 08:56:27.386055 2026] [security2:error] [pid 559070:tid 559150] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eayy1f1FtKC137xsFiwAB4E8"]
[Tue Jul 21 08:56:27.386240 2026] [security2:error] [pid 559070:tid 559281] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eayy1f1FtKC137xsFiwAB4E8"]
[Tue Jul 21 08:56:27.496424 2026] [security2:error] [pid 533360:tid 533606] [client 20.10.88.236:5828] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rioclaroimovel.com.br"] [uri "/index.php"] [unique_id "al9ea3UPuLYrePtEkUcrtwAAAPY"]
[Tue Jul 21 08:56:27.662077 2026] [autoindex:error] [pid 559070:tid 559322] [client 44.220.233.148:43560] AH01276: Cannot serve directory /home3/agroci73/purityox.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:27.771232 2026] [security2:error] [pid 559070:tid 559324] [client 20.104.96.117:7586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/dex.php"] [unique_id "al9eayy1f1FtKC137xsFmgAAAgs"]
[Tue Jul 21 08:56:27.950523 2026] [security2:error] [pid 559070:tid 559315] [client 4.194.24.143:28669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/3pjcpmfsd8b.php"] [unique_id "al9eayy1f1FtKC137xsFoQAAAgI"]
[Tue Jul 21 08:56:28.087736 2026] [security2:error] [pid 559070:tid 559252] [client 117.210.181.114:54946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.181.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9ebCy1f1FtKC137xsFpQAAAcM"]
[Tue Jul 21 08:56:28.087895 2026] [security2:error] [pid 559070:tid 559252] [client 117.210.181.114:54946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9ebCy1f1FtKC137xsFpQAAAcM"]
[Tue Jul 21 08:56:28.351693 2026] [security2:error] [pid 559070:tid 559296] [client 65.21.113.253:51976] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9ebCy1f1FtKC137xsFqgAAAe8"]
[Tue Jul 21 08:56:28.432496 2026] [security2:error] [pid 559070:tid 559273] [client 20.104.96.117:7243] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "bravacomunicacao.com"] [uri "/1.php"] [unique_id "al9ebCy1f1FtKC137xsFrQAAAdg"]
[Tue Jul 21 08:56:28.432611 2026] [security2:error] [pid 559070:tid 559273] [client 20.104.96.117:7243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/1.php"] [unique_id "al9ebCy1f1FtKC137xsFrQAAAdg"]
[Tue Jul 21 08:56:28.434877 2026] [security2:error] [pid 559070:tid 559203] [client 203.25.124.53:31653] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al9ebCy1f1FtKC137xsFrgAAAZI"]
[Tue Jul 21 08:56:28.494439 2026] [security2:error] [pid 559070:tid 559287] [client 20.220.225.223:48254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/ace2.php"] [unique_id "al9ebCy1f1FtKC137xsFsQAAAeY"]
[Tue Jul 21 08:56:28.652506 2026] [security2:error] [pid 533360:tid 533584] [client 136.144.35.4:59693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "triaxion.com.br"] [uri "/wp-login.php"] [unique_id "al9ebHUPuLYrePtEkUcr0AAAAOA"]
[Tue Jul 21 08:56:28.859232 2026] [security2:error] [pid 559070:tid 559155] [remote 156.67.31.167:44106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9ebCy1f1FtKC137xsFtgAB-VQ"]
[Tue Jul 21 08:56:29.022483 2026] [security2:error] [pid 559070:tid 559259] [client 4.194.24.143:5456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/403.php"] [unique_id "al9ebSy1f1FtKC137xsFuAAAAco"]
[Tue Jul 21 08:56:29.105620 2026] [security2:error] [pid 559070:tid 559257] [client 20.151.10.161:45993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/file.php"] [unique_id "al9ebSy1f1FtKC137xsFuQAAAcg"]
[Tue Jul 21 08:56:29.111000 2026] [security2:error] [pid 559070:tid 559292] [client 20.104.96.117:7602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/ms.php"] [unique_id "al9ebSy1f1FtKC137xsFugAAAes"]
[Tue Jul 21 08:56:29.371983 2026] [security2:error] [pid 533360:tid 533452] [remote 45.3.52.200:13333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9ebXUPuLYrePtEkUcr4wAAyVg"]
[Tue Jul 21 08:56:29.404076 2026] [security2:error] [pid 533360:tid 533503] [client 20.197.192.193:63894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/8.php"] [unique_id "al9ebXUPuLYrePtEkUcr6AAAAI8"]
[Tue Jul 21 08:56:29.436684 2026] [security2:error] [pid 533360:tid 533587] [client 65.21.113.253:53446] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ebXUPuLYrePtEkUcr3wAAAOM"]
[Tue Jul 21 08:56:29.595212 2026] [security2:error] [pid 559070:tid 559243] [client 20.104.96.117:7980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/memberfuns.php"] [unique_id "al9ebSy1f1FtKC137xsFyAAAAbo"]
[Tue Jul 21 08:56:29.611920 2026] [security2:error] [pid 559070:tid 559313] [client 20.52.136.55:1549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/bless.php"] [unique_id "al9ebSy1f1FtKC137xsFyQAAAgA"]
[Tue Jul 21 08:56:29.939331 2026] [security2:error] [pid 559070:tid 559258] [client 212.32.76.4:56751] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-atom.php"] [unique_id "al9ebSy1f1FtKC137xsFzQAAAck"]
[Tue Jul 21 08:56:30.045197 2026] [security2:error] [pid 559070:tid 559288] [client 4.194.24.143:54664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/404.php"] [unique_id "al9ebiy1f1FtKC137xsF0QAAAec"]
[Tue Jul 21 08:56:30.053096 2026] [security2:error] [pid 559070:tid 559261] [client 20.104.96.117:7610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/0.php"] [unique_id "al9ebiy1f1FtKC137xsF0gAAAcw"]
[Tue Jul 21 08:56:30.058528 2026] [security2:error] [pid 533360:tid 533547] [client 20.197.192.193:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/red.php"] [unique_id "al9ebnUPuLYrePtEkUcr8wAAALs"]
[Tue Jul 21 08:56:30.441565 2026] [security2:error] [pid 533360:tid 533498] [client 41.89.234.2:57544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ebnUPuLYrePtEkUcr-AAAAIo"]
[Tue Jul 21 08:56:30.441700 2026] [security2:error] [pid 533360:tid 533498] [client 41.89.234.2:57544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ebnUPuLYrePtEkUcr-AAAAIo"]
[Tue Jul 21 08:56:30.607978 2026] [security2:error] [pid 533360:tid 533605] [client 20.104.96.117:7267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/BDKR28.php"] [unique_id "al9ebnUPuLYrePtEkUcr_QAAAPU"]
[Tue Jul 21 08:56:30.701451 2026] [security2:error] [pid 559070:tid 559142] [remote 45.79.123.44:53300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ebiy1f1FtKC137xsF2wABqEc"]
[Tue Jul 21 08:56:30.748974 2026] [security2:error] [pid 559070:tid 559202] [client 182.189.99.211:47968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ebiy1f1FtKC137xsF3AAAAZE"]
[Tue Jul 21 08:56:30.749064 2026] [security2:error] [pid 559070:tid 559202] [client 182.189.99.211:47968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ebiy1f1FtKC137xsF3AAAAZE"]
[Tue Jul 21 08:56:30.840713 2026] [security2:error] [pid 533360:tid 533563] [client 203.25.124.69:21587] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/tinymce/themes/inlite/"] [unique_id "al9ebnUPuLYrePtEkUcsAAAAAMs"]
[Tue Jul 21 08:56:31.078038 2026] [security2:error] [pid 533360:tid 533606] [client 4.194.24.143:63040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/4pjcpmfsd8b.php"] [unique_id "al9eb3UPuLYrePtEkUcsBwAAAPY"]
[Tue Jul 21 08:56:31.202885 2026] [security2:error] [pid 533360:tid 533600] [client 20.220.225.223:60268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.produtosnapromo.com.br"] [uri "/ms.php"] [unique_id "al9eb3UPuLYrePtEkUcsCAAAAPA"]
[Tue Jul 21 08:56:31.240078 2026] [security2:error] [pid 559070:tid 559287] [client 20.104.96.117:7974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/green1.php"] [unique_id "al9ebyy1f1FtKC137xsF5QAAAeY"]
[Tue Jul 21 08:56:31.437037 2026] [security2:error] [pid 559070:tid 559277] [client 20.197.192.193:61102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/fffm.php"] [unique_id "al9ebyy1f1FtKC137xsF6AAAAdw"]
[Tue Jul 21 08:56:31.819390 2026] [security2:error] [pid 533360:tid 533584] [client 20.151.10.161:45929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/cfile.php"] [unique_id "al9eb3UPuLYrePtEkUcsEgAAAOA"]
[Tue Jul 21 08:56:31.839694 2026] [security2:error] [pid 533360:tid 533596] [client 212.32.76.11:22115] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/uploads/about.php"] [unique_id "al9eb3UPuLYrePtEkUcsEwAAAOw"]
[Tue Jul 21 08:56:31.934159 2026] [security2:error] [pid 533360:tid 533517] [client 74.7.244.56:37152] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mail.amandamorau.adv.br"] [uri "/index.php"] [unique_id "al9ebnUPuLYrePtEkUcsAQAAnUo"]
[Tue Jul 21 08:56:31.941361 2026] [security2:error] [pid 559070:tid 559165] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9ebyy1f1FtKC137xsF8QAB914"]
[Tue Jul 21 08:56:31.941568 2026] [security2:error] [pid 559070:tid 559304] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9ebyy1f1FtKC137xsF8QAB914"]
[Tue Jul 21 08:56:32.079562 2026] [security2:error] [pid 559070:tid 559284] [client 20.104.96.117:7598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/nc4.php"] [unique_id "al9ecCy1f1FtKC137xsF8wAAAeM"]
[Tue Jul 21 08:56:32.136270 2026] [security2:error] [pid 533360:tid 533608] [client 5.38.115.39:40875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ecHUPuLYrePtEkUcsHwAAAPg"]
[Tue Jul 21 08:56:32.136368 2026] [security2:error] [pid 533360:tid 533608] [client 5.38.115.39:40875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ecHUPuLYrePtEkUcsHwAAAPg"]
[Tue Jul 21 08:56:32.136666 2026] [security2:error] [pid 533360:tid 533365] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ecHUPuLYrePtEkUcsIAAA0QE"]
[Tue Jul 21 08:56:32.136811 2026] [security2:error] [pid 533360:tid 533569] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ecHUPuLYrePtEkUcsIAAA0QE"]
[Tue Jul 21 08:56:32.142921 2026] [security2:error] [pid 533360:tid 533597] [client 4.194.24.143:37385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/666.php"] [unique_id "al9ecHUPuLYrePtEkUcsIQAAAO0"]
[Tue Jul 21 08:56:32.197743 2026] [security2:error] [pid 533360:tid 533586] [client 198.44.157.162:47254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9ecHUPuLYrePtEkUcsIgAAAOI"]
[Tue Jul 21 08:56:32.197893 2026] [security2:error] [pid 533360:tid 533586] [client 198.44.157.162:47254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9ecHUPuLYrePtEkUcsIgAAAOI"]
[Tue Jul 21 08:56:32.394455 2026] [security2:error] [pid 559070:tid 559307] [client 20.220.225.223:34875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/koiy.php"] [unique_id "al9ecCy1f1FtKC137xsF9wAAAfo"]
[Tue Jul 21 08:56:32.723146 2026] [security2:error] [pid 559070:tid 559256] [client 65.21.113.253:51976] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9ecCy1f1FtKC137xsF-wAAAcc"]
[Tue Jul 21 08:56:32.829004 2026] [security2:error] [pid 533360:tid 533615] [client 113.22.144.139:57022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ecHUPuLYrePtEkUcsLwAAAP8"]
[Tue Jul 21 08:56:32.829122 2026] [security2:error] [pid 533360:tid 533615] [client 113.22.144.139:57022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ecHUPuLYrePtEkUcsLwAAAP8"]
[Tue Jul 21 08:56:32.937875 2026] [security2:error] [pid 559070:tid 559233] [client 203.25.124.50:64399] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/covr-wpcom/assets/fonts/manrope_normal.php"] [unique_id "al9ecCy1f1FtKC137xsGAQAAAbA"]
[Tue Jul 21 08:56:32.988830 2026] [security2:error] [pid 559070:tid 559288] [client 20.104.96.117:7572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/a1.php"] [unique_id "al9ecCy1f1FtKC137xsGAwAAAec"]
[Tue Jul 21 08:56:33.125551 2026] [security2:error] [pid 559070:tid 559255] [client 20.151.10.161:45824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/class-wp.php"] [unique_id "al9ecSy1f1FtKC137xsGCAAAAcY"]
[Tue Jul 21 08:56:33.177844 2026] [security2:error] [pid 559070:tid 559313] [client 4.194.24.143:16970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/7.php"] [unique_id "al9ecSy1f1FtKC137xsGCgAAAgA"]
[Tue Jul 21 08:56:33.469058 2026] [security2:error] [pid 559070:tid 559213] [client 128.127.105.184:54076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9ecSy1f1FtKC137xsGEQAAAZw"]
[Tue Jul 21 08:56:33.469218 2026] [security2:error] [pid 559070:tid 559213] [client 128.127.105.184:54076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9ecSy1f1FtKC137xsGEQAAAZw"]
[Tue Jul 21 08:56:33.542233 2026] [security2:error] [pid 559070:tid 559280] [client 59.95.197.55:55243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ecSy1f1FtKC137xsGFAAAAd8"]
[Tue Jul 21 08:56:33.542397 2026] [security2:error] [pid 559070:tid 559280] [client 59.95.197.55:55243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ecSy1f1FtKC137xsGFAAAAd8"]
[Tue Jul 21 08:56:33.661536 2026] [security2:error] [pid 559070:tid 559314] [client 20.52.136.55:1538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/storage/index.php"] [unique_id "al9ecSy1f1FtKC137xsGFwAAAgE"]
[Tue Jul 21 08:56:33.708173 2026] [security2:error] [pid 533360:tid 533518] [client 20.104.96.117:8113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/eee.php"] [unique_id "al9ecXUPuLYrePtEkUcsPQAAAJ4"]
[Tue Jul 21 08:56:33.762797 2026] [security2:error] [pid 533360:tid 533504] [client 20.151.10.161:50986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9ecXUPuLYrePtEkUcsPgAAAJA"]
[Tue Jul 21 08:56:33.787711 2026] [security2:error] [pid 559070:tid 559238] [client 65.21.113.253:41150] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ecSy1f1FtKC137xsGDgAAAbU"]
[Tue Jul 21 08:56:33.915721 2026] [security2:error] [pid 533360:tid 533599] [client 34.91.119.153:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.linosguincho.com.br"] [uri "/"] [unique_id "al9ecXUPuLYrePtEkUcsQgAAAO8"]
[Tue Jul 21 08:56:33.915841 2026] [security2:error] [pid 533360:tid 533599] [client 34.91.119.153:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.linosguincho.com.br"] [uri "/"] [unique_id "al9ecXUPuLYrePtEkUcsQgAAAO8"]
[Tue Jul 21 08:56:34.062295 2026] [security2:error] [pid 533360:tid 533519] [client 20.197.192.193:61057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/ftde.php"] [unique_id "al9ecnUPuLYrePtEkUcsRwAAAJ8"]
[Tue Jul 21 08:56:34.071273 2026] [security2:error] [pid 559070:tid 559259] [client 20.151.10.161:45913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/admin.php"] [unique_id "al9eciy1f1FtKC137xsGHwAAAco"]
[Tue Jul 21 08:56:34.250148 2026] [security2:error] [pid 533360:tid 533589] [client 4.194.24.143:5570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/8.php"] [unique_id "al9ecnUPuLYrePtEkUcsSAAAAOU"]
[Tue Jul 21 08:56:34.307449 2026] [security2:error] [pid 559070:tid 559290] [client 20.104.96.117:8117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/wp-aothait.php"] [unique_id "al9eciy1f1FtKC137xsGIQAAAek"]
[Tue Jul 21 08:56:34.341629 2026] [security2:error] [pid 559070:tid 559298] [client 203.25.124.52:61981] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/js/privacy-tools.min.php"] [unique_id "al9eciy1f1FtKC137xsGIgAAAfE"]
[Tue Jul 21 08:56:34.343982 2026] [security2:error] [pid 533360:tid 533410] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ecnUPuLYrePtEkUcsSgAA9S4"]
[Tue Jul 21 08:56:34.344173 2026] [security2:error] [pid 533360:tid 533605] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ecnUPuLYrePtEkUcsSgAA9S4"]
[Tue Jul 21 08:56:34.559525 2026] [security2:error] [pid 559070:tid 559145] [remote 45.117.83.212:45750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "clinicaleonazevedo.com.br"] [uri "/wp-login.php"] [unique_id "al9eciy1f1FtKC137xsGJAAB_Uo"]
[Tue Jul 21 08:56:34.610017 2026] [security2:error] [pid 533360:tid 533595] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9ecnUPuLYrePtEkUcsUAAA63U"]
[Tue Jul 21 08:56:34.816486 2026] [security2:error] [pid 533360:tid 533565] [client 20.197.192.193:61086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/yup.php"] [unique_id "al9ecnUPuLYrePtEkUcsXAAAAM0"]
[Tue Jul 21 08:56:35.150259 2026] [security2:error] [pid 559070:tid 559227] [client 20.104.96.117:7246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/config.json.php"] [unique_id "al9ecyy1f1FtKC137xsGNAAAAao"]
[Tue Jul 21 08:56:35.162719 2026] [security2:error] [pid 533360:tid 533517] [client 114.198.138.124:52131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9ec3UPuLYrePtEkUcsaAAAAJ0"]
[Tue Jul 21 08:56:35.162844 2026] [security2:error] [pid 533360:tid 533517] [client 114.198.138.124:52131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9ec3UPuLYrePtEkUcsaAAAAJ0"]
[Tue Jul 21 08:56:35.337620 2026] [security2:error] [pid 559070:tid 559248] [client 203.25.124.49:33401] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/options.php"] [unique_id "al9ecyy1f1FtKC137xsGVgAAAb8"]
[Tue Jul 21 08:56:35.339327 2026] [security2:error] [pid 533360:tid 533506] [client 4.194.24.143:2214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/87.php"] [unique_id "al9ec3UPuLYrePtEkUcsawAAAJI"]
[Tue Jul 21 08:56:35.607007 2026] [security2:error] [pid 559070:tid 559313] [client 20.151.10.161:46063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/aa2.php"] [unique_id "al9ecyy1f1FtKC137xsGggAAAgA"]
[Tue Jul 21 08:56:36.020485 2026] [security2:error] [pid 533360:tid 533543] [client 20.104.96.117:7614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al9edHUPuLYrePtEkUcsegAAALc"]
[Tue Jul 21 08:56:36.214172 2026] [security2:error] [pid 559070:tid 559238] [client 20.220.225.223:52658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/ftde.php"] [unique_id "al9edCy1f1FtKC137xsGjQAAAbU"]
[Tue Jul 21 08:56:36.339492 2026] [security2:error] [pid 559070:tid 559315] [client 168.167.81.163:61484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9edCy1f1FtKC137xsGkAAAAgI"]
[Tue Jul 21 08:56:36.339619 2026] [security2:error] [pid 559070:tid 559315] [client 168.167.81.163:61484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9edCy1f1FtKC137xsGkAAAAgI"]
[Tue Jul 21 08:56:36.371135 2026] [security2:error] [pid 559070:tid 559265] [client 4.194.24.143:16149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/99.php"] [unique_id "al9edCy1f1FtKC137xsGkQAAAdA"]
[Tue Jul 21 08:56:36.540142 2026] [security2:error] [pid 533360:tid 533567] [client 20.104.96.117:8101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/k2.php"] [unique_id "al9edHUPuLYrePtEkUcshAAAAM8"]
[Tue Jul 21 08:56:36.540162 2026] [security2:error] [pid 533360:tid 533599] [client 203.25.124.70:48931] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/user/wp-conflg.php"] [unique_id "al9edHUPuLYrePtEkUcsggAAAO8"]
[Tue Jul 21 08:56:36.640716 2026] [security2:error] [pid 559070:tid 559150] [remote 104.207.60.40:31157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.60.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9edCy1f1FtKC137xsGlAABj08"]
[Tue Jul 21 08:56:36.763422 2026] [security2:error] [pid 559070:tid 559221] [client 114.119.152.142:42163] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "limaradiologiadigital.com.br"] [uri "/sa=U"] [unique_id "al9edCy1f1FtKC137xsGnwAAAaQ"], referer: https://limaradiologiadigital.com.br/sa=U
[Tue Jul 21 08:56:36.833284 2026] [security2:error] [pid 559070:tid 559289] [client 20.151.10.161:45997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/ccou.php"] [unique_id "al9edCy1f1FtKC137xsGowAAAeg"]
[Tue Jul 21 08:56:37.315594 2026] [security2:error] [pid 559070:tid 559321] [client 20.104.96.117:8082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/uiuvs58l.php"] [unique_id "al9edSy1f1FtKC137xsGpwAAAgg"]
[Tue Jul 21 08:56:37.436641 2026] [security2:error] [pid 559070:tid 559262] [client 4.194.24.143:7372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/a.php"] [unique_id "al9edSy1f1FtKC137xsGrAAAAc0"]
[Tue Jul 21 08:56:37.579544 2026] [security2:error] [pid 559070:tid 559223] [client 65.21.113.253:51976] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9edSy1f1FtKC137xsGrgAAAaY"]
[Tue Jul 21 08:56:37.805421 2026] [security2:error] [pid 559070:tid 559258] [client 20.104.96.117:7277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/40p9ixjd.php"] [unique_id "al9edSy1f1FtKC137xsGsgAAAck"]
[Tue Jul 21 08:56:37.845074 2026] [security2:error] [pid 559070:tid 559232] [client 203.25.124.39:41385] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/.well-known/"] [unique_id "al9edSy1f1FtKC137xsGswAAAa8"]
[Tue Jul 21 08:56:37.860435 2026] [security2:error] [pid 559070:tid 559157] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9edSy1f1FtKC137xsGtAABk1Y"]
[Tue Jul 21 08:56:37.860576 2026] [security2:error] [pid 559070:tid 559204] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9edSy1f1FtKC137xsGtAABk1Y"]
[Tue Jul 21 08:56:38.019607 2026] [security2:error] [pid 559070:tid 559283] [client 20.197.192.193:27080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diariomineral.com"] [uri "/ms.php"] [unique_id "al9ediy1f1FtKC137xsGuQAAAeI"]
[Tue Jul 21 08:56:38.054503 2026] [security2:error] [pid 533360:tid 533486] [remote 64.225.121.94:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ednUPuLYrePtEkUcsmwAAi3o"]
[Tue Jul 21 08:56:38.501874 2026] [security2:error] [pid 559070:tid 559268] [client 20.220.225.223:43185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/hp2.php"] [unique_id "al9ediy1f1FtKC137xsGwQAAAdM"]
[Tue Jul 21 08:56:38.508880 2026] [security2:error] [pid 533360:tid 533561] [client 20.104.96.117:7279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/uiuvs58l.update.php"] [unique_id "al9ednUPuLYrePtEkUcspQAAAMk"]
[Tue Jul 21 08:56:38.522524 2026] [security2:error] [pid 559070:tid 559229] [client 4.194.24.143:58773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/a4.php"] [unique_id "al9ediy1f1FtKC137xsGwgAAAaw"]
[Tue Jul 21 08:56:38.640929 2026] [security2:error] [pid 533360:tid 533539] [client 65.21.113.253:41164] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ednUPuLYrePtEkUcsnwAAALM"]
[Tue Jul 21 08:56:38.984360 2026] [security2:error] [pid 533360:tid 533472] [remote 45.3.42.127:13633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9ednUPuLYrePtEkUcssQABAWw"]
[Tue Jul 21 08:56:39.056742 2026] [security2:error] [pid 559070:tid 559273] [client 115.245.198.210:20450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9edyy1f1FtKC137xsGyQAAAdg"]
[Tue Jul 21 08:56:39.056892 2026] [security2:error] [pid 559070:tid 559273] [client 115.245.198.210:20450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9edyy1f1FtKC137xsGyQAAAdg"]
[Tue Jul 21 08:56:39.251424 2026] [security2:error] [pid 559070:tid 559260] [client 20.104.96.117:7260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/for.php"] [unique_id "al9edyy1f1FtKC137xsGzwAAAcs"]
[Tue Jul 21 08:56:39.468095 2026] [security2:error] [pid 559070:tid 559175] [remote 192.241.143.148:52786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9edyy1f1FtKC137xsG1QAB_Wg"]
[Tue Jul 21 08:56:39.536274 2026] [security2:error] [pid 559070:tid 559319] [client 203.25.124.51:45643] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-configs.php"] [unique_id "al9edyy1f1FtKC137xsG2AAAAgY"]
[Tue Jul 21 08:56:39.550722 2026] [security2:error] [pid 559070:tid 559292] [client 4.194.24.143:7419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/a7.php"] [unique_id "al9edyy1f1FtKC137xsG2QAAAes"]
[Tue Jul 21 08:56:39.939129 2026] [security2:error] [pid 559070:tid 559226] [client 20.104.96.117:8069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bravacomunicacao.com"] [uri "/raw.php"] [unique_id "al9edyy1f1FtKC137xsG3wAAAak"]
[Tue Jul 21 08:56:39.961336 2026] [security2:error] [pid 559070:tid 559320] [client 172.234.215.24:39070] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "filtrokangen.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9edyy1f1FtKC137xsG4gAAAgc"]
[Tue Jul 21 08:56:40.101896 2026] [security2:error] [pid 559070:tid 559282] [client 172.234.215.24:39070] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "filtrokangen.com.br"] [uri "/"] [unique_id "al9eeCy1f1FtKC137xsG5AAAAeE"]
[Tue Jul 21 08:56:40.294278 2026] [security2:error] [pid 559070:tid 559218] [client 20.220.225.223:55751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/yup.php"] [unique_id "al9eeCy1f1FtKC137xsG6AAAAaE"]
[Tue Jul 21 08:56:40.305452 2026] [security2:error] [pid 533360:tid 533545] [client 74.7.230.13:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "marmorariasolare.com.br"] [uri "/index.php"] [unique_id "al9ed3UPuLYrePtEkUcstQAAuQs"]
[Tue Jul 21 08:56:40.516180 2026] [security2:error] [pid 559070:tid 559253] [client 20.151.10.161:45920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/dr.php"] [unique_id "al9eeCy1f1FtKC137xsG7gAAAcQ"]
[Tue Jul 21 08:56:40.579951 2026] [security2:error] [pid 559070:tid 559302] [client 4.194.24.143:26735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/aa.php"] [unique_id "al9eeCy1f1FtKC137xsG8QAAAfU"]
[Tue Jul 21 08:56:40.938470 2026] [security2:error] [pid 533360:tid 533531] [client 203.25.124.64:25119] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/class.php"] [unique_id "al9eeHUPuLYrePtEkUcs1AAAAKs"]
[Tue Jul 21 08:56:40.984155 2026] [security2:error] [pid 559070:tid 559244] [client 41.89.234.2:10148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eeCy1f1FtKC137xsG9gAAAbs"]
[Tue Jul 21 08:56:40.984319 2026] [security2:error] [pid 559070:tid 559244] [client 41.89.234.2:10148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eeCy1f1FtKC137xsG9gAAAbs"]
[Tue Jul 21 08:56:41.207052 2026] [security2:error] [pid 559070:tid 559318] [client 182.189.99.211:48312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eeSy1f1FtKC137xsG_AAAAgU"]
[Tue Jul 21 08:56:41.207175 2026] [security2:error] [pid 559070:tid 559318] [client 182.189.99.211:48312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eeSy1f1FtKC137xsG_AAAAgU"]
[Tue Jul 21 08:56:41.611065 2026] [security2:error] [pid 533360:tid 533527] [client 4.194.24.143:58791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/aaa.php"] [unique_id "al9eeXUPuLYrePtEkUcs3wAAAKc"]
[Tue Jul 21 08:56:41.939290 2026] [security2:error] [pid 559070:tid 559265] [client 203.25.124.39:41599] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Text/Diff/Engine/"] [unique_id "al9eeSy1f1FtKC137xsHDAAAAdA"]
[Tue Jul 21 08:56:42.017644 2026] [security2:error] [pid 533360:tid 533610] [client 20.52.136.55:1582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/g.php"] [unique_id "al9eenUPuLYrePtEkUcs5AAAAPo"]
[Tue Jul 21 08:56:42.068645 2026] [security2:error] [pid 559070:tid 559320] [client 20.220.225.223:58917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/jj.php"] [unique_id "al9eeiy1f1FtKC137xsHEgAAAgc"]
[Tue Jul 21 08:56:42.371173 2026] [security2:error] [pid 559070:tid 559213] [client 65.21.113.253:51976] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eeiy1f1FtKC137xsHGQAAAZw"]
[Tue Jul 21 08:56:42.467589 2026] [security2:error] [pid 533360:tid 533421] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eenUPuLYrePtEkUcs8gAA6Dk"]
[Tue Jul 21 08:56:42.467725 2026] [security2:error] [pid 533360:tid 533592] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eenUPuLYrePtEkUcs8gAA6Dk"]
[Tue Jul 21 08:56:42.612974 2026] [security2:error] [pid 559070:tid 559263] [client 20.151.10.161:51021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/bob.php"] [unique_id "al9eeiy1f1FtKC137xsHGwAAAc4"]
[Tue Jul 21 08:56:42.642099 2026] [security2:error] [pid 559070:tid 559313] [client 4.194.24.143:59448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/ab.php"] [unique_id "al9eeiy1f1FtKC137xsHHwAAAgA"]
[Tue Jul 21 08:56:42.812300 2026] [security2:error] [pid 533360:tid 533460] [remote 72.167.132.114:54470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solarisimplementos.com"] [uri "/wp-login.php"] [unique_id "al9eenUPuLYrePtEkUcs9gABAGA"]
[Tue Jul 21 08:56:42.827755 2026] [security2:error] [pid 533360:tid 533573] [client 20.151.10.161:46013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xamp.php"] [unique_id "al9eenUPuLYrePtEkUcs9wAAANU"]
[Tue Jul 21 08:56:42.910638 2026] [security2:error] [pid 559070:tid 559297] [client 5.38.115.39:10300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eeiy1f1FtKC137xsHJQAAAfA"]
[Tue Jul 21 08:56:42.910763 2026] [security2:error] [pid 559070:tid 559297] [client 5.38.115.39:10300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9eeiy1f1FtKC137xsHJQAAAfA"]
[Tue Jul 21 08:56:43.051115 2026] [security2:error] [pid 559070:tid 559225] [client 157.90.155.240:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9eeyy1f1FtKC137xsHKAABqBU"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:56:43.114536 2026] [security2:error] [pid 559070:tid 559182] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eeyy1f1FtKC137xsHKQAB9W8"]
[Tue Jul 21 08:56:43.114793 2026] [security2:error] [pid 559070:tid 559302] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eeyy1f1FtKC137xsHKQAB9W8"]
[Tue Jul 21 08:56:43.148881 2026] [security2:error] [pid 559070:tid 559202] [client 103.59.206.240:31194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eeyy1f1FtKC137xsHLAAAAZE"]
[Tue Jul 21 08:56:43.149030 2026] [security2:error] [pid 559070:tid 559202] [client 103.59.206.240:31194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eeyy1f1FtKC137xsHLAAAAZE"]
[Tue Jul 21 08:56:43.429958 2026] [security2:error] [pid 533360:tid 533566] [client 65.21.113.253:47522] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ee3UPuLYrePtEkUcs_QAAAM4"]
[Tue Jul 21 08:56:43.437499 2026] [security2:error] [pid 559070:tid 559227] [client 20.220.225.223:34705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/pn.php"] [unique_id "al9eeyy1f1FtKC137xsHNwAAAao"]
[Tue Jul 21 08:56:43.598566 2026] [security2:error] [pid 559070:tid 559204] [client 20.220.225.223:35079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/hp3.php"] [unique_id "al9eeyy1f1FtKC137xsHRAAAAZM"]
[Tue Jul 21 08:56:43.603034 2026] [security2:error] [pid 559070:tid 559321] [client 157.90.155.240:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9eeyy1f1FtKC137xsHRQACCCY"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:56:43.639198 2026] [security2:error] [pid 559070:tid 559223] [client 203.25.124.70:58781] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/content.php"] [unique_id "al9eeyy1f1FtKC137xsHSQAAAaY"]
[Tue Jul 21 08:56:43.672302 2026] [security2:error] [pid 559070:tid 559205] [client 4.194.24.143:26746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/abc.php"] [unique_id "al9eeyy1f1FtKC137xsHSgAAAZQ"]
[Tue Jul 21 08:56:43.775215 2026] [security2:error] [pid 559070:tid 559151] [remote 157.66.26.183:36432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "seaportservicos.com.br"] [uri "/wp-login.php"] [unique_id "al9eeyy1f1FtKC137xsHSwAB-1A"]
[Tue Jul 21 08:56:43.858000 2026] [security2:error] [pid 559070:tid 559274] [client 113.22.144.139:57559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eeyy1f1FtKC137xsHTAAAAdk"]
[Tue Jul 21 08:56:43.858112 2026] [security2:error] [pid 559070:tid 559274] [client 113.22.144.139:57559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eeyy1f1FtKC137xsHTAAAAdk"]
[Tue Jul 21 08:56:44.020047 2026] [security2:error] [pid 559070:tid 559214] [client 59.95.197.55:55717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9efCy1f1FtKC137xsHTwAAAZ0"]
[Tue Jul 21 08:56:44.020207 2026] [security2:error] [pid 559070:tid 559214] [client 59.95.197.55:55717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9efCy1f1FtKC137xsHTwAAAZ0"]
[Tue Jul 21 08:56:44.158525 2026] [security2:error] [pid 559070:tid 559253] [client 54.39.136.18:44468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "companhiatop.com.br"] [uri "/robots.txt"] [unique_id "al9efCy1f1FtKC137xsHVAAAAcQ"]
[Tue Jul 21 08:56:44.158671 2026] [security2:error] [pid 559070:tid 559253] [client 54.39.136.18:44468] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "companhiatop.com.br"] [uri "/robots.txt"] [unique_id "al9efCy1f1FtKC137xsHVAAAAcQ"]
[Tue Jul 21 08:56:44.416673 2026] [security2:error] [pid 533360:tid 533575] [client 20.10.88.236:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "digital-universo.com"] [uri "/index.php"] [unique_id "al9efHUPuLYrePtEkUctFwAA1xY"]
[Tue Jul 21 08:56:44.752016 2026] [security2:error] [pid 559070:tid 559296] [client 4.194.24.143:58770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/abcd.php"] [unique_id "al9efCy1f1FtKC137xsHXAAAAe8"]
[Tue Jul 21 08:56:44.835383 2026] [security2:error] [pid 559070:tid 559221] [client 203.25.124.73:34531] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/css/dist/block-library/"] [unique_id "al9efCy1f1FtKC137xsHYAAAAaQ"]
[Tue Jul 21 08:56:44.916534 2026] [security2:error] [pid 559070:tid 559275] [client 20.151.10.161:45953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/bless.php"] [unique_id "al9efCy1f1FtKC137xsHYQAAAdo"]
[Tue Jul 21 08:56:45.192604 2026] [security2:error] [pid 533360:tid 533442] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9efXUPuLYrePtEkUctKwAA6k4"]
[Tue Jul 21 08:56:45.192762 2026] [security2:error] [pid 533360:tid 533594] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9efXUPuLYrePtEkUctKwAA6k4"]
[Tue Jul 21 08:56:45.573632 2026] [security2:error] [pid 559070:tid 559228] [client 142.132.180.39:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "albegaoficial.com.br"] [uri "/index.cgi"] [unique_id "al9efSy1f1FtKC137xsHagABqwQ"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:56:45.600648 2026] [security2:error] [pid 559070:tid 559316] [client 167.114.139.38:35798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "companhiatop.com.br"] [uri "/"] [unique_id "al9efSy1f1FtKC137xsHbQAAAgM"]
[Tue Jul 21 08:56:45.600722 2026] [security2:error] [pid 559070:tid 559316] [client 167.114.139.38:35798] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "companhiatop.com.br"] [uri "/"] [unique_id "al9efSy1f1FtKC137xsHbQAAAgM"]
[Tue Jul 21 08:56:45.643466 2026] [security2:error] [pid 559070:tid 559149] [remote 162.243.80.244:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "warleysonlacerdalope1782242261893.0721679.meusitehostgator.com.br"] [uri "/.env"] [unique_id "al9efSy1f1FtKC137xsHbgABpU4"]
[Tue Jul 21 08:56:45.687808 2026] [security2:error] [pid 533360:tid 533505] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9efXUPuLYrePtEkUctNgAAkTY"]
[Tue Jul 21 08:56:45.738909 2026] [security2:error] [pid 533360:tid 533532] [client 114.198.138.124:52710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9efXUPuLYrePtEkUctOwAAAKw"]
[Tue Jul 21 08:56:45.738999 2026] [security2:error] [pid 533360:tid 533532] [client 114.198.138.124:52710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9efXUPuLYrePtEkUctOwAAAKw"]
[Tue Jul 21 08:56:45.803189 2026] [security2:error] [pid 533360:tid 533508] [client 4.194.24.143:2190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/about.php"] [unique_id "al9efXUPuLYrePtEkUctPAAAAJQ"]
[Tue Jul 21 08:56:45.864434 2026] [security2:error] [pid 533360:tid 533519] [client 194.99.104.35:39770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9efXUPuLYrePtEkUctPwAAAJ8"]
[Tue Jul 21 08:56:45.864536 2026] [security2:error] [pid 533360:tid 533519] [client 194.99.104.35:39770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9efXUPuLYrePtEkUctPwAAAJ8"]
[Tue Jul 21 08:56:46.091595 2026] [security2:error] [pid 559070:tid 559213] [client 20.151.10.161:45936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/file46.php"] [unique_id "al9efiy1f1FtKC137xsHdgAAAZw"]
[Tue Jul 21 08:56:46.134342 2026] [security2:error] [pid 559070:tid 559324] [client 142.132.180.39:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "albegaoficial.com.br"] [uri "/404.html"] [unique_id "al9efiy1f1FtKC137xsHdwACC1U"], referer: https://albegaoficial.com.br
[Tue Jul 21 08:56:46.249841 2026] [security2:error] [pid 559070:tid 559308] [client 203.25.124.51:20363] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/post-terms/"] [unique_id "al9efiy1f1FtKC137xsHfQAAAfs"]
[Tue Jul 21 08:56:46.725088 2026] [core:error] [pid 559070:tid 559280] [client 185.213.175.37:14254] AH10244: invalid URI path (/%post_type%/qual-a-documentacao-necessaria-para-evitar-surpresas-na-hora-de-comprar-um-imovel/)
[Tue Jul 21 08:56:46.734475 2026] [security2:error] [pid 559070:tid 559225] [client 65.21.113.253:51976] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9efiy1f1FtKC137xsHhwAAAag"]
[Tue Jul 21 08:56:46.740138 2026] [core:error] [pid 559070:tid 559212] [client 185.213.175.37:14264] AH10244: invalid URI path (/%post_type%/dicas-para-voce-planejar-a-compra-de-seu-imovel/)
[Tue Jul 21 08:56:46.855323 2026] [security2:error] [pid 559070:tid 559301] [client 4.194.24.143:58761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-info.php"] [unique_id "al9efiy1f1FtKC137xsHiwAAAfQ"]
[Tue Jul 21 08:56:46.998595 2026] [security2:error] [pid 559070:tid 559313] [client 20.151.10.161:55910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/crgio.php"] [unique_id "al9efiy1f1FtKC137xsHjQAAAgA"]
[Tue Jul 21 08:56:47.551703 2026] [security2:error] [pid 559070:tid 559292] [client 212.32.76.4:49485] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/b.php"] [unique_id "al9efyy1f1FtKC137xsHmwAAAes"]
[Tue Jul 21 08:56:47.605758 2026] [security2:error] [pid 559070:tid 559143] [remote 5.182.209.54:51528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moneyclass.com.br"] [uri "/wp-login.php"] [unique_id "al9efyy1f1FtKC137xsHnAAB2kg"]
[Tue Jul 21 08:56:47.640388 2026] [core:alert] [pid 559070:tid 559322] [client 57.141.18.30:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:56:47.802204 2026] [security2:error] [pid 533360:tid 533605] [client 65.21.113.253:47534] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ef3UPuLYrePtEkUctWAAAAPU"]
[Tue Jul 21 08:56:47.931014 2026] [security2:error] [pid 559070:tid 559237] [client 20.197.192.193:63897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/jj.php"] [unique_id "al9efyy1f1FtKC137xsHpgAAAbQ"]
[Tue Jul 21 08:56:48.263769 2026] [security2:error] [pid 533360:tid 533441] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9egHUPuLYrePtEkUctxAAA3U0"]
[Tue Jul 21 08:56:48.263912 2026] [security2:error] [pid 533360:tid 533581] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9egHUPuLYrePtEkUctxAAA3U0"]
[Tue Jul 21 08:56:48.361941 2026] [security2:error] [pid 533360:tid 533610] [client 168.167.81.163:61541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9egHUPuLYrePtEkUctxQAAAPo"]
[Tue Jul 21 08:56:48.362060 2026] [security2:error] [pid 533360:tid 533610] [client 168.167.81.163:61541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9egHUPuLYrePtEkUctxQAAAPo"]
[Tue Jul 21 08:56:48.508879 2026] [autoindex:error] [pid 533360:tid 533508] [client 217.76.50.173:62138] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:48.537402 2026] [security2:error] [pid 559070:tid 559234] [client 203.25.124.51:28629] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/blocks/audio/"] [unique_id "al9egCy1f1FtKC137xsHwgAAAbE"]
[Tue Jul 21 08:56:48.537618 2026] [security2:error] [pid 559070:tid 559276] [client 20.220.225.223:58908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/dragonshell.php"] [unique_id "al9egCy1f1FtKC137xsHwwAAAds"]
[Tue Jul 21 08:56:48.599669 2026] [security2:error] [pid 559070:tid 559291] [client 4.194.24.143:6293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-links-opml.php"] [unique_id "al9egCy1f1FtKC137xsHxQAAAeo"]
[Tue Jul 21 08:56:48.764008 2026] [security2:error] [pid 533360:tid 533572] [client 20.197.192.193:61070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/dragonshell.php"] [unique_id "al9egHUPuLYrePtEkUctzgAAANQ"]
[Tue Jul 21 08:56:48.819616 2026] [autoindex:error] [pid 533360:tid 533498] [client 13.219.67.125:29218] AH01276: Cannot serve directory /home4/dralul00/psimilenefreitas.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:49.040106 2026] [security2:error] [pid 533360:tid 533530] [client 20.220.225.223:34745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/wp-wpbak.php"] [unique_id "al9egXUPuLYrePtEkUct1AAAAKo"]
[Tue Jul 21 08:56:49.301708 2026] [security2:error] [pid 559070:tid 559214] [client 20.197.192.193:61087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/wp-mt.php"] [unique_id "al9egSy1f1FtKC137xsHzwAAAZ0"]
[Tue Jul 21 08:56:49.463780 2026] [autoindex:error] [pid 533360:tid 533542] [client 217.76.50.173:62138] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:49.637810 2026] [security2:error] [pid 533360:tid 533568] [client 203.25.124.72:27411] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/class-db.php"] [unique_id "al9egXUPuLYrePtEkUct4gAAANA"]
[Tue Jul 21 08:56:49.656541 2026] [security2:error] [pid 533360:tid 533613] [client 4.194.24.143:7373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-links.php"] [unique_id "al9egXUPuLYrePtEkUct5AAAAP0"]
[Tue Jul 21 08:56:49.855117 2026] [security2:error] [pid 559070:tid 559296] [client 20.197.192.193:61076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/ww.php"] [unique_id "al9egSy1f1FtKC137xsH3gAAAe8"]
[Tue Jul 21 08:56:50.247598 2026] [security2:error] [pid 533360:tid 533580] [client 20.197.192.193:61065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/cron.php"] [unique_id "al9egnUPuLYrePtEkUct7gAAANw"]
[Tue Jul 21 08:56:50.301729 2026] [autoindex:error] [pid 533360:tid 533604] [client 217.76.50.173:62138] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:50.390154 2026] [security2:error] [pid 559070:tid 559293] [client 20.151.10.161:51051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/pucci.php"] [unique_id "al9egiy1f1FtKC137xsH8QAAAew"]
[Tue Jul 21 08:56:50.438337 2026] [security2:error] [pid 533360:tid 533614] [client 203.25.124.40:55867] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/readme.php"] [unique_id "al9egnUPuLYrePtEkUct8QAAAP4"]
[Tue Jul 21 08:56:50.688646 2026] [security2:error] [pid 559070:tid 559212] [client 4.194.24.143:4651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-load.php"] [unique_id "al9egiy1f1FtKC137xsIDgAAAZs"]
[Tue Jul 21 08:56:50.889524 2026] [security2:error] [pid 559070:tid 559237] [client 20.151.10.161:45891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/eee.php"] [unique_id "al9egiy1f1FtKC137xsIFgAAAbQ"]
[Tue Jul 21 08:56:50.999000 2026] [security2:error] [pid 533360:tid 533554] [client 20.197.192.193:61118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/xxx.php"] [unique_id "al9egnUPuLYrePtEkUct-QAAAMI"]
[Tue Jul 21 08:56:51.132770 2026] [security2:error] [pid 559070:tid 559324] [client 20.52.136.55:1747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/nf.php"] [unique_id "al9egyy1f1FtKC137xsIGgAAAgs"]
[Tue Jul 21 08:56:51.429031 2026] [security2:error] [pid 533360:tid 533463] [remote 151.123.178.184:23985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.178.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9eg3UPuLYrePtEkUcuBgAAkWM"]
[Tue Jul 21 08:56:51.467048 2026] [security2:error] [pid 559070:tid 559222] [client 41.89.234.2:10539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9egyy1f1FtKC137xsIIgAAAaU"]
[Tue Jul 21 08:56:51.467184 2026] [security2:error] [pid 559070:tid 559222] [client 41.89.234.2:10539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9egyy1f1FtKC137xsIIgAAAaU"]
[Tue Jul 21 08:56:51.557344 2026] [security2:error] [pid 559070:tid 559254] [client 65.21.113.253:51976] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9egyy1f1FtKC137xsIIwAAAcU"]
[Tue Jul 21 08:56:51.754175 2026] [security2:error] [pid 559070:tid 559201] [client 4.194.24.143:2189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-login.php"] [unique_id "al9egyy1f1FtKC137xsIKAAAAZA"]
[Tue Jul 21 08:56:51.771764 2026] [security2:error] [pid 559070:tid 559300] [client 182.189.99.211:48228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9egyy1f1FtKC137xsIKQAAAfM"]
[Tue Jul 21 08:56:51.771901 2026] [security2:error] [pid 559070:tid 559300] [client 182.189.99.211:48228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9egyy1f1FtKC137xsIKQAAAfM"]
[Tue Jul 21 08:56:51.951091 2026] [security2:error] [pid 533360:tid 533587] [client 20.197.192.193:63877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/hunter.php"] [unique_id "al9eg3UPuLYrePtEkUcuDwAAAOM"]
[Tue Jul 21 08:56:52.115269 2026] [security2:error] [pid 559070:tid 559215] [client 115.245.198.210:29729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9ehCy1f1FtKC137xsIMwAAAZ4"]
[Tue Jul 21 08:56:52.115388 2026] [security2:error] [pid 559070:tid 559215] [client 115.245.198.210:29729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9ehCy1f1FtKC137xsIMwAAAZ4"]
[Tue Jul 21 08:56:52.237672 2026] [security2:error] [pid 559070:tid 559304] [client 212.32.76.11:37581] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/files/index.php"] [unique_id "al9ehCy1f1FtKC137xsIOgAAAfc"]
[Tue Jul 21 08:56:52.252393 2026] [security2:error] [pid 559070:tid 559294] [client 20.220.225.223:20913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/dr.php"] [unique_id "al9ehCy1f1FtKC137xsIOwAAAe0"]
[Tue Jul 21 08:56:52.517138 2026] [security2:error] [pid 559070:tid 559298] [client 20.220.225.223:52632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/wp-mt.php"] [unique_id "al9ehCy1f1FtKC137xsIQwAAAfE"]
[Tue Jul 21 08:56:52.601866 2026] [security2:error] [pid 559070:tid 559248] [client 65.21.113.253:56496] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ehCy1f1FtKC137xsIOQAAAb8"]
[Tue Jul 21 08:56:52.658224 2026] [security2:error] [pid 559070:tid 559246] [client 20.151.10.161:45833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/file25.php"] [unique_id "al9ehCy1f1FtKC137xsISgAAAb0"]
[Tue Jul 21 08:56:52.806029 2026] [autoindex:error] [pid 533360:tid 533499] [client 217.76.50.173:62138] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:52.834767 2026] [security2:error] [pid 559070:tid 559305] [client 4.194.24.143:6328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-mail.php"] [unique_id "al9ehCy1f1FtKC137xsIUQAAAfg"]
[Tue Jul 21 08:56:52.995707 2026] [security2:error] [pid 533360:tid 533459] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9ehHUPuLYrePtEkUcuJwAAmV8"]
[Tue Jul 21 08:56:52.995850 2026] [security2:error] [pid 533360:tid 533513] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9ehHUPuLYrePtEkUcuJwAAmV8"]
[Tue Jul 21 08:56:53.234040 2026] [security2:error] [pid 533360:tid 533609] [client 203.25.124.47:51481] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Text/index.php"] [unique_id "al9ehXUPuLYrePtEkUcuKwAAAPk"]
[Tue Jul 21 08:56:53.387835 2026] [security2:error] [pid 533360:tid 533540] [client 20.197.192.193:63876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/we.php"] [unique_id "al9ehXUPuLYrePtEkUcuMAAAALQ"]
[Tue Jul 21 08:56:53.585895 2026] [security2:error] [pid 559070:tid 559202] [client 20.197.192.193:61104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yellowfoot.com.br"] [uri "/phpinfo.php1"] [unique_id "al9ehSy1f1FtKC137xsIWAAAAZE"]
[Tue Jul 21 08:56:53.649272 2026] [security2:error] [pid 559070:tid 559216] [client 5.38.115.39:9959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ehSy1f1FtKC137xsIWQAAAZ8"]
[Tue Jul 21 08:56:53.649427 2026] [security2:error] [pid 559070:tid 559216] [client 5.38.115.39:9959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ehSy1f1FtKC137xsIWQAAAZ8"]
[Tue Jul 21 08:56:53.762537 2026] [security2:error] [pid 559070:tid 559201] [client 20.220.225.223:34187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/track.php"] [unique_id "al9ehSy1f1FtKC137xsIWwAAAZA"]
[Tue Jul 21 08:56:53.898879 2026] [security2:error] [pid 533360:tid 533614] [client 4.194.24.143:44748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-signin.php"] [unique_id "al9ehXUPuLYrePtEkUcuNwAAAP4"]
[Tue Jul 21 08:56:53.948369 2026] [security2:error] [pid 559070:tid 559273] [client 212.32.76.7:26673] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/js/"] [unique_id "al9ehSy1f1FtKC137xsIXwAAAdg"]
[Tue Jul 21 08:56:53.978741 2026] [autoindex:error] [pid 533360:tid 533574] [client 217.76.50.173:62138] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:54.010568 2026] [security2:error] [pid 559070:tid 559166] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ehiy1f1FtKC137xsIYgAB5l8"]
[Tue Jul 21 08:56:54.010707 2026] [security2:error] [pid 559070:tid 559287] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ehiy1f1FtKC137xsIYgAB5l8"]
[Tue Jul 21 08:56:54.491002 2026] [security2:error] [pid 559070:tid 559296] [client 59.95.197.55:56203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ehiy1f1FtKC137xsIZwAAAe8"]
[Tue Jul 21 08:56:54.491136 2026] [security2:error] [pid 559070:tid 559296] [client 59.95.197.55:56203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ehiy1f1FtKC137xsIZwAAAe8"]
[Tue Jul 21 08:56:54.855457 2026] [security2:error] [pid 559070:tid 559297] [client 113.22.144.139:58100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ehiy1f1FtKC137xsIagAAAfA"]
[Tue Jul 21 08:56:54.855910 2026] [security2:error] [pid 559070:tid 559297] [client 113.22.144.139:58100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ehiy1f1FtKC137xsIagAAAfA"]
[Tue Jul 21 08:56:54.940051 2026] [security2:error] [pid 533360:tid 533611] [client 212.32.76.12:46885] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-includes/Requests/library/"] [unique_id "al9ehnUPuLYrePtEkUcuSgAAAPs"]
[Tue Jul 21 08:56:54.954821 2026] [security2:error] [pid 533360:tid 533588] [client 4.194.24.143:6304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-sigunq.php"] [unique_id "al9ehnUPuLYrePtEkUcuTQAAAOQ"]
[Tue Jul 21 08:56:55.183464 2026] [autoindex:error] [pid 533360:tid 533541] [client 217.76.50.173:62138] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:55.936323 2026] [security2:error] [pid 559070:tid 559232] [client 212.32.76.5:23621] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/twentytwentyfour/"] [unique_id "al9ehyy1f1FtKC137xsIfAAAAa8"]
[Tue Jul 21 08:56:55.983212 2026] [security2:error] [pid 559070:tid 559253] [client 4.194.24.143:4654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-the.php"] [unique_id "al9ehyy1f1FtKC137xsIfQAAAcQ"]
[Tue Jul 21 08:56:56.052554 2026] [security2:error] [pid 533360:tid 533499] [client 20.52.136.55:1734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/xda.php"] [unique_id "al9eiHUPuLYrePtEkUcuXgAAAIs"]
[Tue Jul 21 08:56:56.077609 2026] [security2:error] [pid 559070:tid 559252] [client 20.151.10.161:49035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9eiCy1f1FtKC137xsIgQAAAcM"]
[Tue Jul 21 08:56:56.117878 2026] [security2:error] [pid 559070:tid 559324] [client 198.44.157.162:36572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9eiCy1f1FtKC137xsIgwAAAgs"]
[Tue Jul 21 08:56:56.118030 2026] [security2:error] [pid 559070:tid 559324] [client 198.44.157.162:36572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9eiCy1f1FtKC137xsIgwAAAgs"]
[Tue Jul 21 08:56:56.212682 2026] [security2:error] [pid 559070:tid 559108] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eiCy1f1FtKC137xsIhAAB5yU"]
[Tue Jul 21 08:56:56.212699 2026] [security2:error] [pid 559070:tid 559246] [client 114.198.138.124:53295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eiCy1f1FtKC137xsIhQAAAb0"]
[Tue Jul 21 08:56:56.212785 2026] [security2:error] [pid 559070:tid 559246] [client 114.198.138.124:53295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eiCy1f1FtKC137xsIhQAAAb0"]
[Tue Jul 21 08:56:56.212808 2026] [security2:error] [pid 559070:tid 559288] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eiCy1f1FtKC137xsIhAAB5yU"]
[Tue Jul 21 08:56:56.226956 2026] [security2:error] [pid 559070:tid 559282] [client 65.21.113.253:51976] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eiCy1f1FtKC137xsIhgAAAeE"]
[Tue Jul 21 08:56:56.437339 2026] [autoindex:error] [pid 533360:tid 533609] [client 217.76.50.173:62138] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:56.505174 2026] [security2:error] [pid 559070:tid 559306] [client 128.127.105.184:33870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9eiCy1f1FtKC137xsIiwAAAfk"]
[Tue Jul 21 08:56:56.505254 2026] [security2:error] [pid 559070:tid 559306] [client 128.127.105.184:33870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9eiCy1f1FtKC137xsIiwAAAfk"]
[Tue Jul 21 08:56:56.629276 2026] [security2:error] [pid 533360:tid 533540] [client 20.220.225.223:46688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/aa1.php"] [unique_id "al9eiHUPuLYrePtEkUcuZwAAALQ"]
[Tue Jul 21 08:56:56.757500 2026] [security2:error] [pid 533360:tid 533565] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eiHUPuLYrePtEkUcuZgAAzWg"]
[Tue Jul 21 08:56:56.855221 2026] [security2:error] [pid 533360:tid 533516] [client 20.151.10.161:45928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/file48.php"] [unique_id "al9eiHUPuLYrePtEkUcugAAAAJw"]
[Tue Jul 21 08:56:56.952502 2026] [security2:error] [pid 533360:tid 533506] [client 203.25.124.64:31709] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-content/themes/radio.php"] [unique_id "al9eiHUPuLYrePtEkUcuhAAAAJI"]
[Tue Jul 21 08:56:57.013802 2026] [security2:error] [pid 533360:tid 533548] [client 4.194.24.143:7742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-themes.php"] [unique_id "al9eiXUPuLYrePtEkUcuhwAAALw"]
[Tue Jul 21 08:56:57.288723 2026] [security2:error] [pid 559070:tid 559309] [client 65.21.113.253:56502] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eiCy1f1FtKC137xsIjwAAAfw"]
[Tue Jul 21 08:56:57.320684 2026] [security2:error] [pid 559070:tid 559318] [client 20.220.225.223:55750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/ww.php"] [unique_id "al9eiSy1f1FtKC137xsIkgAAAgU"]
[Tue Jul 21 08:56:57.734695 2026] [autoindex:error] [pid 533360:tid 533535] [client 217.76.50.173:62138] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:56:58.120094 2026] [security2:error] [pid 533360:tid 533498] [client 4.194.24.143:4611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-trackback.php"] [unique_id "al9einUPuLYrePtEkUcumwAAAIo"]
[Tue Jul 21 08:56:58.398897 2026] [security2:error] [pid 559070:tid 559113] [remote 5.252.52.249:39548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "domuscondominios.com.br"] [uri "/wp-login.php"] [unique_id "al9eiiy1f1FtKC137xsImwABrSo"]
[Tue Jul 21 08:56:58.539408 2026] [security2:error] [pid 533360:tid 533575] [client 212.32.76.10:33081] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/shell.php"] [unique_id "al9einUPuLYrePtEkUcuogAAANc"]
[Tue Jul 21 08:56:58.749107 2026] [security2:error] [pid 533360:tid 533450] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9einUPuLYrePtEkUcuqQAA81Y"]
[Tue Jul 21 08:56:58.749250 2026] [security2:error] [pid 533360:tid 533603] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9einUPuLYrePtEkUcuqQAA81Y"]
[Tue Jul 21 08:56:59.096377 2026] [security2:error] [pid 533360:tid 533471] [remote 47.86.33.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wendelleite.com.br"] [uri "/wp-login.php"] [unique_id "al9ei3UPuLYrePtEkUcurQAA0Ws"]
[Tue Jul 21 08:56:59.203314 2026] [security2:error] [pid 533360:tid 533596] [client 4.194.24.143:4612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-user.php"] [unique_id "al9ei3UPuLYrePtEkUcusgAAAOw"]
[Tue Jul 21 08:56:59.439211 2026] [security2:error] [pid 559070:tid 559326] [client 212.32.76.10:63575] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "entrepaginasepratos.com.br"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "al9eiyy1f1FtKC137xsIpQAAAg0"]
[Tue Jul 21 08:57:00.105168 2026] [security2:error] [pid 559070:tid 559304] [client 20.151.10.161:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-temp.php"] [unique_id "al9ejCy1f1FtKC137xsIuAAAAfc"]
[Tue Jul 21 08:57:00.179341 2026] [security2:error] [pid 559070:tid 559302] [client 168.167.81.163:63746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9ejCy1f1FtKC137xsIuQAAAfU"]
[Tue Jul 21 08:57:00.179498 2026] [security2:error] [pid 559070:tid 559302] [client 168.167.81.163:63746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9ejCy1f1FtKC137xsIuQAAAfU"]
[Tue Jul 21 08:57:00.262207 2026] [security2:error] [pid 559070:tid 559296] [client 4.194.24.143:4649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-ver.php"] [unique_id "al9ejCy1f1FtKC137xsIuwAAAe8"]
[Tue Jul 21 08:57:01.261843 2026] [security2:error] [pid 559070:tid 559240] [client 20.220.225.223:37617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/acew67.php"] [unique_id "al9ejSy1f1FtKC137xsIygAAAbc"]
[Tue Jul 21 08:57:01.285499 2026] [security2:error] [pid 533360:tid 533549] [client 4.194.24.143:44771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp-ws68.php"] [unique_id "al9ejXUPuLYrePtEkUcu7QAAAL0"]
[Tue Jul 21 08:57:01.743892 2026] [security2:error] [pid 533360:tid 533512] [client 20.151.10.161:45902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/file6.php"] [unique_id "al9ejXUPuLYrePtEkUcu9AAAAJg"]
[Tue Jul 21 08:57:02.058880 2026] [security2:error] [pid 533360:tid 533575] [client 41.89.234.2:58963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ejnUPuLYrePtEkUcu-gAAANc"]
[Tue Jul 21 08:57:02.059023 2026] [security2:error] [pid 533360:tid 533575] [client 41.89.234.2:58963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ejnUPuLYrePtEkUcu-gAAANc"]
[Tue Jul 21 08:57:02.111127 2026] [security2:error] [pid 533360:tid 533562] [client 103.76.88.37:1187] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "beehead.des.br"] [uri "/.env"] [unique_id "al9ejnUPuLYrePtEkUcu_QAAAMo"]
[Tue Jul 21 08:57:02.185382 2026] [security2:error] [pid 533360:tid 533566] [client 20.220.225.223:52670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/cron.php"] [unique_id "al9ejnUPuLYrePtEkUcvAwAAAM4"]
[Tue Jul 21 08:57:02.328363 2026] [security2:error] [pid 533360:tid 533559] [client 182.189.99.211:48571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ejnUPuLYrePtEkUcvCgAAAMc"]
[Tue Jul 21 08:57:02.328479 2026] [security2:error] [pid 533360:tid 533559] [client 182.189.99.211:48571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ejnUPuLYrePtEkUcvCgAAAMc"]
[Tue Jul 21 08:57:02.346186 2026] [security2:error] [pid 533360:tid 533580] [client 4.194.24.143:6522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp.php"] [unique_id "al9ejnUPuLYrePtEkUcvCwAAANw"]
[Tue Jul 21 08:57:02.502881 2026] [proxy:error] [pid 559070:tid 559292] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:02.502972 2026] [proxy_http:error] [pid 559070:tid 559292] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:02.503849 2026] [proxy:error] [pid 559070:tid 559292] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:02.503891 2026] [proxy_http:error] [pid 559070:tid 559292] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:02.740168 2026] [security2:error] [pid 533360:tid 533547] [client 20.151.10.161:45894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/a2.php"] [unique_id "al9ejnUPuLYrePtEkUcvEgAAALs"]
[Tue Jul 21 08:57:02.986386 2026] [proxy:error] [pid 533360:tid 533544] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:02.986460 2026] [proxy_http:error] [pid 533360:tid 533544] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:02.987022 2026] [proxy:error] [pid 533360:tid 533544] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:02.987047 2026] [proxy_http:error] [pid 533360:tid 533544] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:03.249673 2026] [security2:error] [pid 559070:tid 559269] [client 20.151.10.161:45935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/file15.php"] [unique_id "al9ejyy1f1FtKC137xsI2gAAAdQ"]
[Tue Jul 21 08:57:03.332158 2026] [security2:error] [pid 559070:tid 559118] [remote 14.225.207.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.207.225.14.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ejyy1f1FtKC137xsI3gAB6C8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:57:03.366070 2026] [security2:error] [pid 559070:tid 559087] [remote 14.225.207.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.207.225.14.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ejyy1f1FtKC137xsI3wABnRA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:57:03.376030 2026] [security2:error] [pid 559070:tid 559221] [client 4.194.24.143:6320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp/002.php"] [unique_id "al9ejyy1f1FtKC137xsI4AAAAaQ"]
[Tue Jul 21 08:57:03.402658 2026] [security2:error] [pid 533360:tid 533506] [client 115.245.198.210:40674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9ej3UPuLYrePtEkUcvHwAAAJI"]
[Tue Jul 21 08:57:03.402763 2026] [security2:error] [pid 533360:tid 533506] [client 115.245.198.210:40674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9ej3UPuLYrePtEkUcvHwAAAJI"]
[Tue Jul 21 08:57:03.436319 2026] [security2:error] [pid 559070:tid 559251] [client 20.220.225.223:53491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9ejyy1f1FtKC137xsI4QAAAcI"]
[Tue Jul 21 08:57:03.437524 2026] [security2:error] [pid 533360:tid 533407] [remote 14.225.207.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.207.225.14.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ej3UPuLYrePtEkUcvIAAAmis"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:57:03.443951 2026] [proxy:error] [pid 533360:tid 533587] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:03.443991 2026] [proxy_http:error] [pid 533360:tid 533587] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:03.444488 2026] [proxy:error] [pid 533360:tid 533587] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:03.444509 2026] [proxy_http:error] [pid 533360:tid 533587] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:03.497444 2026] [security2:error] [pid 533360:tid 533411] [remote 14.225.207.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.207.225.14.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ej3UPuLYrePtEkUcvHQAAyy8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:57:03.577111 2026] [security2:error] [pid 559070:tid 559078] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9ejyy1f1FtKC137xsI4wABwQc"]
[Tue Jul 21 08:57:03.577261 2026] [security2:error] [pid 559070:tid 559250] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9ejyy1f1FtKC137xsI4wABwQc"]
[Tue Jul 21 08:57:03.752354 2026] [security2:error] [pid 559070:tid 559196] [remote 14.225.207.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.207.225.14.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ejyy1f1FtKC137xsI5gABqn0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:57:03.905694 2026] [security2:error] [pid 559070:tid 559272] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ejyy1f1FtKC137xsI6wAAAdc"]
[Tue Jul 21 08:57:03.948055 2026] [security2:error] [pid 559070:tid 559316] [client 20.151.10.161:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/jp.php"] [unique_id "al9ejyy1f1FtKC137xsI7AAAAgM"]
[Tue Jul 21 08:57:04.320610 2026] [security2:error] [pid 559070:tid 559282] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9ekCy1f1FtKC137xsI-AAAAeE"]
[Tue Jul 21 08:57:04.323917 2026] [security2:error] [pid 559070:tid 559178] [remote 14.225.207.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.207.225.14.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ekCy1f1FtKC137xsI-QAB42s"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:57:04.427778 2026] [security2:error] [pid 559070:tid 559257] [client 4.194.24.143:4642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wp/wp-content/themes/extendable/mg2.php"] [unique_id "al9ekCy1f1FtKC137xsJAQAAAcg"]
[Tue Jul 21 08:57:04.446109 2026] [security2:error] [pid 559070:tid 559072] [remote 14.225.207.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.207.225.14.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ekCy1f1FtKC137xsJAgABtAE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:57:04.452213 2026] [security2:error] [pid 559070:tid 559234] [client 5.38.115.39:58400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ekCy1f1FtKC137xsJAwAAAbE"]
[Tue Jul 21 08:57:04.452300 2026] [security2:error] [pid 559070:tid 559234] [client 5.38.115.39:58400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9ekCy1f1FtKC137xsJAwAAAbE"]
[Tue Jul 21 08:57:04.528967 2026] [security2:error] [pid 559070:tid 559206] [client 20.220.225.223:35113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/bscclapb.php"] [unique_id "al9ekCy1f1FtKC137xsJBAAAAZU"]
[Tue Jul 21 08:57:04.567887 2026] [security2:error] [pid 559070:tid 559120] [remote 14.225.207.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.207.225.14.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ekCy1f1FtKC137xsJBQABvDE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:57:04.709808 2026] [security2:error] [pid 559070:tid 559191] [remote 14.225.207.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.207.225.14.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ekCy1f1FtKC137xsJCAABuXg"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:57:04.734848 2026] [security2:error] [pid 559070:tid 559161] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ekCy1f1FtKC137xsJCQAB5lo"]
[Tue Jul 21 08:57:04.734993 2026] [security2:error] [pid 559070:tid 559287] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ekCy1f1FtKC137xsJCQAB5lo"]
[Tue Jul 21 08:57:04.789149 2026] [security2:error] [pid 559070:tid 559232] [client 194.99.104.35:37528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9ekCy1f1FtKC137xsJCwAAAa8"]
[Tue Jul 21 08:57:04.789232 2026] [security2:error] [pid 559070:tid 559232] [client 194.99.104.35:37528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9ekCy1f1FtKC137xsJCwAAAa8"]
[Tue Jul 21 08:57:04.809372 2026] [security2:error] [pid 559070:tid 559112] [remote 14.225.207.108:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.207.225.14.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9ekCy1f1FtKC137xsJEQAB3ik"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 08:57:04.959926 2026] [security2:error] [pid 559070:tid 559252] [client 103.59.206.240:31508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ekCy1f1FtKC137xsJFgAAAcM"]
[Tue Jul 21 08:57:04.960058 2026] [security2:error] [pid 559070:tid 559252] [client 103.59.206.240:31508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ekCy1f1FtKC137xsJFgAAAcM"]
[Tue Jul 21 08:57:04.966611 2026] [security2:error] [pid 559070:tid 559289] [client 20.151.10.161:45828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/f35.php"] [unique_id "al9ekCy1f1FtKC137xsJFwAAAeg"]
[Tue Jul 21 08:57:04.973398 2026] [security2:error] [pid 559070:tid 559214] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9ekCy1f1FtKC137xsJGAAAAZ0"]
[Tue Jul 21 08:57:04.986647 2026] [security2:error] [pid 559070:tid 559219] [client 59.95.197.55:56680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ekCy1f1FtKC137xsJGQAAAaI"]
[Tue Jul 21 08:57:04.987740 2026] [security2:error] [pid 559070:tid 559219] [client 59.95.197.55:56680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ekCy1f1FtKC137xsJGQAAAaI"]
[Tue Jul 21 08:57:04.999176 2026] [security2:error] [pid 533360:tid 533501] [client 65.21.113.253:38446] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9ekHUPuLYrePtEkUcvMgAAAI0"]
[Tue Jul 21 08:57:05.265101 2026] [security2:error] [pid 559070:tid 559295] [client 20.220.225.223:53476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9ekSy1f1FtKC137xsJIQAAAe4"]
[Tue Jul 21 08:57:05.363587 2026] [security2:error] [pid 559070:tid 559265] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9ekSy1f1FtKC137xsJIgAAAdA"]
[Tue Jul 21 08:57:05.377171 2026] [security2:error] [pid 533360:tid 533395] [remote 121.182.42.250:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "onkosclinica.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "al9ekXUPuLYrePtEkUcvNQAA-x8"]
[Tue Jul 21 08:57:05.481481 2026] [security2:error] [pid 559070:tid 559268] [client 4.194.24.143:19981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/ws.php"] [unique_id "al9ekSy1f1FtKC137xsJJgAAAdM"]
[Tue Jul 21 08:57:05.580626 2026] [security2:error] [pid 559070:tid 559269] [client 113.22.144.139:58629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ekSy1f1FtKC137xsJKAAAAdQ"]
[Tue Jul 21 08:57:05.580806 2026] [security2:error] [pid 559070:tid 559269] [client 113.22.144.139:58629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ekSy1f1FtKC137xsJKAAAAdQ"]
[Tue Jul 21 08:57:05.811181 2026] [proxy:error] [pid 559070:tid 559259] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:05.811243 2026] [proxy_http:error] [pid 559070:tid 559259] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:05.811698 2026] [proxy:error] [pid 559070:tid 559259] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:05.811731 2026] [proxy_http:error] [pid 559070:tid 559259] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:05.820727 2026] [security2:error] [pid 533360:tid 533503] [client 65.21.113.253:39286] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ekXUPuLYrePtEkUcvOwAAAI8"]
[Tue Jul 21 08:57:05.884540 2026] [security2:error] [pid 559070:tid 559204] [client 20.151.10.161:45897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-load.php"] [unique_id "al9ekSy1f1FtKC137xsJMAAAAZM"]
[Tue Jul 21 08:57:05.913956 2026] [security2:error] [pid 559070:tid 559284] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9ekSy1f1FtKC137xsJMgAAAeM"]
[Tue Jul 21 08:57:06.171645 2026] [core:error] [pid 559070:tid 559206] [client 88.151.33.203:33034] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Tue Jul 21 08:57:06.262231 2026] [security2:error] [pid 559070:tid 559149] [remote 20.75.217.64:8519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9ekiy1f1FtKC137xsJOgAB2U4"]
[Tue Jul 21 08:57:06.337862 2026] [proxy:error] [pid 533360:tid 533536] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:06.337925 2026] [proxy_http:error] [pid 533360:tid 533536] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:06.338436 2026] [proxy:error] [pid 533360:tid 533536] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:06.338468 2026] [proxy_http:error] [pid 533360:tid 533536] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:06.412741 2026] [security2:error] [pid 559070:tid 559201] [client 216.24.219.141:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "naldoinvest.com.br"] [uri "/wp-login.php"] [unique_id "al9ekCy1f1FtKC137xsJCgABkAY"]
[Tue Jul 21 08:57:06.474271 2026] [security2:error] [pid 559070:tid 559261] [client 185.191.171.13:51608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grupogradiente.com.br"] [uri "/robots.txt"] [unique_id "al9ekiy1f1FtKC137xsJPgAAAcw"]
[Tue Jul 21 08:57:06.474411 2026] [security2:error] [pid 559070:tid 559261] [client 185.191.171.13:51608] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "grupogradiente.com.br"] [uri "/robots.txt"] [unique_id "al9ekiy1f1FtKC137xsJPgAAAcw"]
[Tue Jul 21 08:57:06.477518 2026] [security2:error] [pid 559070:tid 559200] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9ekiy1f1FtKC137xsJPwAAAY8"]
[Tue Jul 21 08:57:06.499999 2026] [security2:error] [pid 559070:tid 559202] [client 20.220.225.223:20872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/2x.php"] [unique_id "al9ekiy1f1FtKC137xsJQgAAAZE"]
[Tue Jul 21 08:57:06.505668 2026] [security2:error] [pid 559070:tid 559223] [client 4.194.24.143:4656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/wso.php"] [unique_id "al9ekiy1f1FtKC137xsJQwAAAaY"]
[Tue Jul 21 08:57:06.736182 2026] [proxy:error] [pid 533360:tid 533529] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:06.736246 2026] [proxy_http:error] [pid 533360:tid 533529] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:06.736996 2026] [proxy:error] [pid 533360:tid 533529] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:06.737028 2026] [proxy_http:error] [pid 533360:tid 533529] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:06.770836 2026] [security2:error] [pid 559070:tid 559240] [client 47.128.34.193:33366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gnxinox.com.br"] [uri "/robots.txt"] [unique_id "al9ekiy1f1FtKC137xsJRgAAAbc"]
[Tue Jul 21 08:57:06.776855 2026] [security2:error] [pid 533360:tid 533605] [client 114.198.138.124:53873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eknUPuLYrePtEkUcvUAAAAPU"]
[Tue Jul 21 08:57:06.776934 2026] [security2:error] [pid 533360:tid 533605] [client 114.198.138.124:53873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9eknUPuLYrePtEkUcvUAAAAPU"]
[Tue Jul 21 08:57:06.882828 2026] [security2:error] [pid 533360:tid 533550] [client 65.21.113.253:39294] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eknUPuLYrePtEkUcvSwAAAL4"]
[Tue Jul 21 08:57:06.938860 2026] [security2:error] [pid 559070:tid 559219] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9ekiy1f1FtKC137xsJSAAAAaI"]
[Tue Jul 21 08:57:07.067781 2026] [security2:error] [pid 533360:tid 533410] [remote 41.186.86.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produto-express.com"] [uri "/wp-login.php"] [unique_id "al9ek3UPuLYrePtEkUcvVQAAuy4"]
[Tue Jul 21 08:57:07.105557 2026] [security2:error] [pid 533360:tid 533539] [client 20.151.10.161:45905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xwpg.php"] [unique_id "al9ek3UPuLYrePtEkUcvVgAAALM"]
[Tue Jul 21 08:57:07.126335 2026] [security2:error] [pid 533360:tid 533595] [client 185.191.171.13:51612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "grupogradiente.com.br"] [uri "/portfolio/energia-solar-em-casas-populares/"] [unique_id "al9ek3UPuLYrePtEkUcvVwAAAOs"]
[Tue Jul 21 08:57:07.126452 2026] [security2:error] [pid 533360:tid 533595] [client 185.191.171.13:51612] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "grupogradiente.com.br"] [uri "/portfolio/energia-solar-em-casas-populares/"] [unique_id "al9ek3UPuLYrePtEkUcvVwAAAOs"]
[Tue Jul 21 08:57:07.148279 2026] [security2:error] [pid 533360:tid 533373] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ek3UPuLYrePtEkUcvWQAA_wk"]
[Tue Jul 21 08:57:07.148400 2026] [security2:error] [pid 533360:tid 533615] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ek3UPuLYrePtEkUcvWQAA_wk"]
[Tue Jul 21 08:57:07.201840 2026] [security2:error] [pid 559070:tid 559265] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ekyy1f1FtKC137xsJUAAAAdA"]
[Tue Jul 21 08:57:07.331479 2026] [security2:error] [pid 533360:tid 533515] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9ek3UPuLYrePtEkUcvYAAAAJs"]
[Tue Jul 21 08:57:07.500153 2026] [security2:error] [pid 533360:tid 533563] [client 121.182.42.250:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "onkosclinica.com"] [uri "/wp-login.php"] [unique_id "al9ek3UPuLYrePtEkUcvYQAAyzw"], referer: https://onkosclinica.com/wp-login.php
[Tue Jul 21 08:57:07.536132 2026] [security2:error] [pid 559070:tid 559293] [client 4.194.24.143:6319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/x.php"] [unique_id "al9ekyy1f1FtKC137xsJWAAAAew"]
[Tue Jul 21 08:57:07.538512 2026] [security2:error] [pid 533360:tid 533582] [client 20.220.225.223:43184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/else1.php"] [unique_id "al9ek3UPuLYrePtEkUcvZQAAAN4"]
[Tue Jul 21 08:57:07.603073 2026] [security2:error] [pid 559070:tid 559212] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9ekyy1f1FtKC137xsJVgABm3o"]
[Tue Jul 21 08:57:07.721861 2026] [security2:error] [pid 559070:tid 559269] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9ekyy1f1FtKC137xsJWwAAAdQ"]
[Tue Jul 21 08:57:07.752967 2026] [security2:error] [pid 559070:tid 559317] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9ekyy1f1FtKC137xsJXAAAAgQ"]
[Tue Jul 21 08:57:07.801270 2026] [autoindex:error] [pid 559070:tid 559254] [client 20.151.10.161:45837] AH01276: Cannot serve directory /home3/housei59/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:08.010031 2026] [security2:error] [pid 559070:tid 559090] [remote 45.3.41.16:40183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9elCy1f1FtKC137xsJXwABoBM"]
[Tue Jul 21 08:57:08.123364 2026] [security2:error] [pid 559070:tid 559213] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9elCy1f1FtKC137xsJZgAAAZw"]
[Tue Jul 21 08:57:08.124315 2026] [autoindex:error] [pid 559070:tid 559322] [client 20.151.10.161:45837] AH01276: Cannot serve directory /home3/housei59/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:08.184971 2026] [security2:error] [pid 559070:tid 559208] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9elCy1f1FtKC137xsJaAAAAZc"]
[Tue Jul 21 08:57:08.206309 2026] [security2:error] [pid 559070:tid 559277] [client 20.151.10.161:49126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/2P.php"] [unique_id "al9elCy1f1FtKC137xsJaQAAAdw"]
[Tue Jul 21 08:57:08.281035 2026] [security2:error] [pid 559070:tid 559308] [client 20.151.10.161:45837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/waf.php"] [unique_id "al9elCy1f1FtKC137xsJagAAAfs"]
[Tue Jul 21 08:57:08.430637 2026] [security2:error] [pid 559070:tid 559274] [client 20.220.225.223:34711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/kq1.php"] [unique_id "al9elCy1f1FtKC137xsJbgAAAdk"]
[Tue Jul 21 08:57:08.484222 2026] [security2:error] [pid 559070:tid 559144] [remote 45.3.40.212:11279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.40.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9elCy1f1FtKC137xsJbQACAEk"]
[Tue Jul 21 08:57:08.522349 2026] [security2:error] [pid 559070:tid 559201] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9elCy1f1FtKC137xsJbwAAAZA"]
[Tue Jul 21 08:57:08.578843 2026] [security2:error] [pid 533360:tid 533587] [client 168.167.81.163:65071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9elHUPuLYrePtEkUcvcQAAAOM"]
[Tue Jul 21 08:57:08.578978 2026] [security2:error] [pid 533360:tid 533587] [client 168.167.81.163:65071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9elHUPuLYrePtEkUcvcQAAAOM"]
[Tue Jul 21 08:57:08.613535 2026] [security2:error] [pid 559070:tid 559262] [client 4.194.24.143:19987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/x86.php"] [unique_id "al9elCy1f1FtKC137xsJcQAAAc0"]
[Tue Jul 21 08:57:08.634240 2026] [security2:error] [pid 559070:tid 559238] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9elCy1f1FtKC137xsJcwAAAbU"]
[Tue Jul 21 08:57:08.890251 2026] [security2:error] [pid 559070:tid 559279] [client 198.44.157.162:54090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9elCy1f1FtKC137xsJeAAAAd4"]
[Tue Jul 21 08:57:08.890338 2026] [security2:error] [pid 559070:tid 559279] [client 198.44.157.162:54090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9elCy1f1FtKC137xsJeAAAAd4"]
[Tue Jul 21 08:57:08.962581 2026] [security2:error] [pid 559070:tid 559290] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9elCy1f1FtKC137xsJfQAAAek"]
[Tue Jul 21 08:57:09.003900 2026] [security2:error] [pid 559070:tid 559304] [client 20.151.10.161:45932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xstelth.php"] [unique_id "al9elSy1f1FtKC137xsJfgAAAfc"]
[Tue Jul 21 08:57:09.023612 2026] [security2:error] [pid 559070:tid 559311] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9elSy1f1FtKC137xsJfwAAAf4"]
[Tue Jul 21 08:57:09.231040 2026] [security2:error] [pid 533360:tid 533456] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9elXUPuLYrePtEkUcvhQAAnFw"]
[Tue Jul 21 08:57:09.231198 2026] [security2:error] [pid 533360:tid 533516] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9elXUPuLYrePtEkUcvhQAAnFw"]
[Tue Jul 21 08:57:09.355173 2026] [security2:error] [pid 559070:tid 559248] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9elSy1f1FtKC137xsJggAAAb8"]
[Tue Jul 21 08:57:09.589845 2026] [security2:error] [pid 533360:tid 533560] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leandrooliveiradasil1782145374926.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9elXUPuLYrePtEkUcvkAAAAMg"]
[Tue Jul 21 08:57:09.626116 2026] [security2:error] [pid 559070:tid 559230] [client 20.151.10.161:45983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-links.php"] [unique_id "al9elSy1f1FtKC137xsJhwAAAa0"]
[Tue Jul 21 08:57:09.640779 2026] [security2:error] [pid 559070:tid 559226] [client 4.194.24.143:7738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/xa.php"] [unique_id "al9elSy1f1FtKC137xsJiQAAAak"]
[Tue Jul 21 08:57:09.742764 2026] [security2:error] [pid 533360:tid 533596] [client 121.182.42.250:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "onkosclinica.com"] [uri "/wp-login.php"] [unique_id "al9elXUPuLYrePtEkUcvkwAA7Gw"], referer: https://onkosclinica.com/wp-login.php
[Tue Jul 21 08:57:09.795740 2026] [fcgid:warn] [pid 533360:tid 533528] (70014)End of file found: [client 118.193.45.235:46646] mod_fcgid: can't get data from http client
[Tue Jul 21 08:57:09.824436 2026] [security2:error] [pid 559070:tid 559259] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9elSy1f1FtKC137xsJkgAAAco"]
[Tue Jul 21 08:57:09.942944 2026] [security2:error] [pid 559070:tid 559138] [remote 65.111.15.6:53819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9elSy1f1FtKC137xsJsQABm0M"]
[Tue Jul 21 08:57:09.993840 2026] [security2:error] [pid 559070:tid 559326] [client 20.151.10.161:45834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9elSy1f1FtKC137xsJswAAAg0"]
[Tue Jul 21 08:57:10.135960 2026] [security2:error] [pid 533360:tid 533572] [client 20.151.10.161:55815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9elnUPuLYrePtEkUcvmgAAANQ"]
[Tue Jul 21 08:57:10.250673 2026] [security2:error] [pid 533360:tid 533495] [client 20.52.136.55:1737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/shell.php"] [unique_id "al9elnUPuLYrePtEkUcvnwAAAIc"]
[Tue Jul 21 08:57:10.262954 2026] [core:error] [pid 533360:tid 533372] [remote 40.77.167.16:17044] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:10.262975 2026] [core:error] [pid 533360:tid 533372] [remote 40.77.167.16:17044] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:10.341228 2026] [security2:error] [pid 533360:tid 533603] [client 20.151.10.161:45982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/aaa.php"] [unique_id "al9elnUPuLYrePtEkUcvoQAAAPM"]
[Tue Jul 21 08:57:10.366866 2026] [security2:error] [pid 559070:tid 559232] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9eliy1f1FtKC137xsJ0gAAAa8"]
[Tue Jul 21 08:57:10.682012 2026] [security2:error] [pid 559070:tid 559287] [client 4.194.24.143:7710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/xfun.php"] [unique_id "al9eliy1f1FtKC137xsJ2wAAAeY"]
[Tue Jul 21 08:57:10.756967 2026] [security2:error] [pid 533360:tid 533580] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9elnUPuLYrePtEkUcvqQAAANw"]
[Tue Jul 21 08:57:10.911623 2026] [security2:error] [pid 559070:tid 559300] [client 117.210.181.114:31489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.181.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9eliy1f1FtKC137xsJ3QAAAfM"]
[Tue Jul 21 08:57:10.911724 2026] [security2:error] [pid 559070:tid 559300] [client 117.210.181.114:31489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9eliy1f1FtKC137xsJ3QAAAfM"]
[Tue Jul 21 08:57:11.152050 2026] [security2:error] [pid 559070:tid 559209] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9elyy1f1FtKC137xsJ4AAAAZg"]
[Tue Jul 21 08:57:11.186577 2026] [security2:error] [pid 533360:tid 533547] [client 20.220.225.223:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/xxx.php"] [unique_id "al9el3UPuLYrePtEkUcvtAAAALs"]
[Tue Jul 21 08:57:11.603460 2026] [security2:error] [pid 559070:tid 559270] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9elyy1f1FtKC137xsJ9AAAAdU"]
[Tue Jul 21 08:57:11.664806 2026] [security2:error] [pid 559070:tid 559259] [client 20.220.225.223:46680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/tkikikoko.php"] [unique_id "al9elyy1f1FtKC137xsJ-AAAAco"]
[Tue Jul 21 08:57:11.673239 2026] [security2:error] [pid 533360:tid 533510] [client 121.182.42.250:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "onkosclinica.com"] [uri "/wp-login.php"] [unique_id "al9el3UPuLYrePtEkUcvwgAAlho"], referer: https://onkosclinica.com/wp-login.php
[Tue Jul 21 08:57:11.737086 2026] [security2:error] [pid 559070:tid 559291] [client 4.194.24.143:7719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/xleet.php"] [unique_id "al9elyy1f1FtKC137xsJ-gAAAeo"]
[Tue Jul 21 08:57:11.963911 2026] [autoindex:error] [pid 559070:tid 559282] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:12.031423 2026] [security2:error] [pid 533360:tid 533512] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9emHUPuLYrePtEkUcv0QAAAJg"]
[Tue Jul 21 08:57:12.331591 2026] [rewrite:warn] [pid 559070:tid 559120] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:57:12.363258 2026] [security2:error] [pid 559070:tid 559224] [client 20.197.192.193:44099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9emCy1f1FtKC137xsKBQAAAac"]
[Tue Jul 21 08:57:12.397459 2026] [security2:error] [pid 559070:tid 559208] [client 20.197.192.193:40806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9emCy1f1FtKC137xsKBwAAAZc"]
[Tue Jul 21 08:57:12.434076 2026] [security2:error] [pid 533360:tid 533538] [client 20.197.192.193:53252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/dp.php"] [unique_id "al9emHUPuLYrePtEkUcv1wAAALI"]
[Tue Jul 21 08:57:12.496633 2026] [security2:error] [pid 559070:tid 559239] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.leonardorodriguesfer1782152667630.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9emCy1f1FtKC137xsKCAAAAbY"]
[Tue Jul 21 08:57:12.502330 2026] [security2:error] [pid 559070:tid 559261] [client 20.197.192.193:44121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/old.php"] [unique_id "al9emCy1f1FtKC137xsKCQAAAcw"]
[Tue Jul 21 08:57:12.526225 2026] [security2:error] [pid 559070:tid 559266] [client 20.220.225.223:34706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/zzz.php"] [unique_id "al9emCy1f1FtKC137xsKCgAAAdE"]
[Tue Jul 21 08:57:12.602701 2026] [security2:error] [pid 559070:tid 559264] [client 41.89.234.2:11253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9emCy1f1FtKC137xsKDAAAAc8"]
[Tue Jul 21 08:57:12.602835 2026] [security2:error] [pid 559070:tid 559264] [client 41.89.234.2:11253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9emCy1f1FtKC137xsKDAAAAc8"]
[Tue Jul 21 08:57:12.668398 2026] [security2:error] [pid 559070:tid 559318] [client 20.197.192.193:44102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/ms-new.php"] [unique_id "al9emCy1f1FtKC137xsKDQAAAgU"]
[Tue Jul 21 08:57:12.766466 2026] [security2:error] [pid 559070:tid 559297] [client 4.194.24.143:4659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/xmlrpc.php"] [unique_id "al9emCy1f1FtKC137xsKEQAAAfA"]
[Tue Jul 21 08:57:12.816472 2026] [security2:error] [pid 533360:tid 533603] [client 182.189.99.211:48292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9emHUPuLYrePtEkUcv3wAAAPM"]
[Tue Jul 21 08:57:12.816591 2026] [security2:error] [pid 533360:tid 533603] [client 182.189.99.211:48292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9emHUPuLYrePtEkUcv3wAAAPM"]
[Tue Jul 21 08:57:12.823677 2026] [security2:error] [pid 533360:tid 533533] [client 20.197.192.193:40827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/track.php"] [unique_id "al9emHUPuLYrePtEkUcv4QAAAK0"]
[Tue Jul 21 08:57:12.877621 2026] [security2:error] [pid 559070:tid 559273] [client 20.197.192.193:44129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/2352356666.php"] [unique_id "al9emCy1f1FtKC137xsKEwAAAdg"]
[Tue Jul 21 08:57:12.944219 2026] [security2:error] [pid 559070:tid 559250] [client 20.197.192.193:40782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/pn.php"] [unique_id "al9emCy1f1FtKC137xsKFAAAAcE"]
[Tue Jul 21 08:57:13.109363 2026] [security2:error] [pid 559070:tid 559209] [client 20.197.192.193:40788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9emSy1f1FtKC137xsKFQAAAZg"]
[Tue Jul 21 08:57:13.241948 2026] [security2:error] [pid 533360:tid 533548] [client 20.197.192.193:40823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/dr.php"] [unique_id "al9emXUPuLYrePtEkUcv5gAAALw"]
[Tue Jul 21 08:57:13.310033 2026] [security2:error] [pid 533360:tid 533574] [client 20.197.192.193:53291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/2x.php"] [unique_id "al9emXUPuLYrePtEkUcv6gAAANY"]
[Tue Jul 21 08:57:13.388522 2026] [autoindex:error] [pid 533360:tid 533524] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:13.396273 2026] [security2:error] [pid 559070:tid 559320] [client 20.197.192.193:40819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/kq1.php"] [unique_id "al9emSy1f1FtKC137xsKHwAAAgc"]
[Tue Jul 21 08:57:13.446484 2026] [security2:error] [pid 559070:tid 559270] [client 20.197.192.193:44118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/zzz.php"] [unique_id "al9emSy1f1FtKC137xsKIAAAAdU"]
[Tue Jul 21 08:57:13.452707 2026] [proxy:error] [pid 533360:tid 533573] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:13.452791 2026] [proxy_http:error] [pid 533360:tid 533573] [client 195.96.139.22:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:13.453433 2026] [proxy:error] [pid 533360:tid 533573] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:13.453472 2026] [proxy_http:error] [pid 533360:tid 533573] [client 195.96.139.22:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:13.478990 2026] [security2:error] [pid 559070:tid 559317] [client 20.197.192.193:11472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wicked.php"] [unique_id "al9emSy1f1FtKC137xsKIQAAAgQ"]
[Tue Jul 21 08:57:13.513192 2026] [security2:error] [pid 559070:tid 559275] [client 20.197.192.193:44101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/edit.php"] [unique_id "al9emSy1f1FtKC137xsKIgAAAdo"]
[Tue Jul 21 08:57:13.532284 2026] [security2:error] [pid 559070:tid 559244] [client 20.197.192.193:40784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/kua.php"] [unique_id "al9emSy1f1FtKC137xsKIwAAAbs"]
[Tue Jul 21 08:57:13.588871 2026] [security2:error] [pid 533360:tid 533592] [client 20.197.192.193:44123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/ez.php"] [unique_id "al9emXUPuLYrePtEkUcv8QAAAOg"]
[Tue Jul 21 08:57:13.710330 2026] [security2:error] [pid 559070:tid 559217] [client 20.220.225.223:53452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/wander.php"] [unique_id "al9emSy1f1FtKC137xsKKAAAAaA"]
[Tue Jul 21 08:57:13.754900 2026] [security2:error] [pid 533360:tid 533505] [client 20.197.192.193:44139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/fz.php"] [unique_id "al9emXUPuLYrePtEkUcv9AAAAJE"]
[Tue Jul 21 08:57:13.789323 2026] [security2:error] [pid 533360:tid 533540] [client 4.194.24.143:4620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/xx.php"] [unique_id "al9emXUPuLYrePtEkUcv9QAAALQ"]
[Tue Jul 21 08:57:13.792324 2026] [security2:error] [pid 559070:tid 559204] [client 20.197.192.193:44126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/la.php"] [unique_id "al9emSy1f1FtKC137xsKMAAAAZM"]
[Tue Jul 21 08:57:13.822302 2026] [security2:error] [pid 559070:tid 559235] [client 65.21.113.253:44794] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9emSy1f1FtKC137xsKMwAAAbI"]
[Tue Jul 21 08:57:13.824028 2026] [security2:error] [pid 559070:tid 559303] [client 20.197.192.193:44148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9emSy1f1FtKC137xsKNAAAAfY"]
[Tue Jul 21 08:57:13.863719 2026] [security2:error] [pid 559070:tid 559258] [client 20.197.192.193:44150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/inso.php"] [unique_id "al9emSy1f1FtKC137xsKOAAAAck"]
[Tue Jul 21 08:57:13.881065 2026] [security2:error] [pid 559070:tid 559212] [client 121.182.42.250:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "onkosclinica.com"] [uri "/wp-login.php"] [unique_id "al9emSy1f1FtKC137xsKMgABmzg"], referer: https://onkosclinica.com/wp-login.php
[Tue Jul 21 08:57:13.901378 2026] [security2:error] [pid 559070:tid 559224] [client 20.197.192.193:44122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wpx.php"] [unique_id "al9emSy1f1FtKC137xsKPAAAAac"]
[Tue Jul 21 08:57:13.931398 2026] [security2:error] [pid 559070:tid 559208] [client 20.220.225.223:34714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/wicked.php"] [unique_id "al9emSy1f1FtKC137xsKQgAAAZc"]
[Tue Jul 21 08:57:13.956209 2026] [security2:error] [pid 559070:tid 559228] [client 20.197.192.193:40770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/berlin.php"] [unique_id "al9emSy1f1FtKC137xsKRAAAAas"]
[Tue Jul 21 08:57:13.988775 2026] [security2:error] [pid 559070:tid 559266] [client 20.220.225.223:34268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/pn.php"] [unique_id "al9emSy1f1FtKC137xsKRQAAAdE"]
[Tue Jul 21 08:57:14.010766 2026] [security2:error] [pid 559070:tid 559232] [client 194.99.104.35:57748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9emiy1f1FtKC137xsKRgAAAa8"]
[Tue Jul 21 08:57:14.010875 2026] [security2:error] [pid 559070:tid 559232] [client 194.99.104.35:57748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9emiy1f1FtKC137xsKRgAAAa8"]
[Tue Jul 21 08:57:14.060276 2026] [security2:error] [pid 533360:tid 533537] [client 20.197.192.193:44116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/billur.php"] [unique_id "al9emnUPuLYrePtEkUcv-gAAALE"]
[Tue Jul 21 08:57:14.161064 2026] [security2:error] [pid 559070:tid 559090] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9emiy1f1FtKC137xsKSQACARM"]
[Tue Jul 21 08:57:14.161254 2026] [security2:error] [pid 559070:tid 559314] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9emiy1f1FtKC137xsKSQACARM"]
[Tue Jul 21 08:57:14.187092 2026] [security2:error] [pid 559070:tid 559240] [client 20.197.192.193:44154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/mimpi.php"] [unique_id "al9emiy1f1FtKC137xsKSgAAAbc"]
[Tue Jul 21 08:57:14.227805 2026] [security2:error] [pid 559070:tid 559251] [client 20.151.10.161:49084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/.well-known/about.php"] [unique_id "al9emiy1f1FtKC137xsKSwAAAcI"]
[Tue Jul 21 08:57:14.238146 2026] [security2:error] [pid 533360:tid 533589] [client 20.197.192.193:44146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/dp.php"] [unique_id "al9emnUPuLYrePtEkUcv_gAAAOU"]
[Tue Jul 21 08:57:14.247875 2026] [security2:error] [pid 559070:tid 559101] [remote 67.20.76.238:42390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.76.20.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/wp-login.php"] [unique_id "al9emiy1f1FtKC137xsKTAABpR4"]
[Tue Jul 21 08:57:14.293086 2026] [security2:error] [pid 559070:tid 559221] [client 20.197.192.193:40814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/bootstrap.php"] [unique_id "al9emiy1f1FtKC137xsKTQAAAaQ"]
[Tue Jul 21 08:57:14.320854 2026] [security2:error] [pid 559070:tid 559294] [client 20.197.192.193:40781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wp-editor.php"] [unique_id "al9emiy1f1FtKC137xsKTgAAAe0"]
[Tue Jul 21 08:57:14.359538 2026] [security2:error] [pid 559070:tid 559227] [client 20.197.192.193:40793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/cro.php"] [unique_id "al9emiy1f1FtKC137xsKUQAAAao"]
[Tue Jul 21 08:57:14.404215 2026] [security2:error] [pid 559070:tid 559214] [client 20.197.192.193:40780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/cron-tab.php"] [unique_id "al9emiy1f1FtKC137xsKUgAAAZ0"]
[Tue Jul 21 08:57:14.486743 2026] [security2:error] [pid 559070:tid 559280] [client 20.197.192.193:53268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/koiy.php"] [unique_id "al9emiy1f1FtKC137xsKVAAAAd8"]
[Tue Jul 21 08:57:14.509863 2026] [security2:error] [pid 533360:tid 533513] [client 20.220.225.223:52618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/hunter.php"] [unique_id "al9emnUPuLYrePtEkUcwAwAAAJk"]
[Tue Jul 21 08:57:14.526251 2026] [security2:error] [pid 559070:tid 559139] [remote 45.79.123.44:56478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dscbrasil.com.br"] [uri "/wp-login.php"] [unique_id "al9emiy1f1FtKC137xsKVwABz0Q"]
[Tue Jul 21 08:57:14.526322 2026] [security2:error] [pid 559070:tid 559243] [client 20.197.192.193:40789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/hp2.php"] [unique_id "al9emiy1f1FtKC137xsKVgAAAbo"]
[Tue Jul 21 08:57:14.562434 2026] [security2:error] [pid 559070:tid 559203] [client 20.197.192.193:40775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/hp3.php"] [unique_id "al9emiy1f1FtKC137xsKWAAAAZI"]
[Tue Jul 21 08:57:14.614572 2026] [security2:error] [pid 559070:tid 559284] [client 20.197.192.193:44151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/aa1.php"] [unique_id "al9emiy1f1FtKC137xsKWQAAAeM"]
[Tue Jul 21 08:57:14.670580 2026] [security2:error] [pid 533360:tid 533519] [client 20.197.192.193:44142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/acew67.php"] [unique_id "al9emnUPuLYrePtEkUcwBQAAAJ8"]
[Tue Jul 21 08:57:14.702961 2026] [security2:error] [pid 559070:tid 559302] [client 20.197.192.193:53266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/bscclapb.php"] [unique_id "al9emiy1f1FtKC137xsKWwAAAfU"]
[Tue Jul 21 08:57:14.736384 2026] [security2:error] [pid 559070:tid 559265] [client 20.197.192.193:40812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/else1.php"] [unique_id "al9emiy1f1FtKC137xsKXgAAAdA"]
[Tue Jul 21 08:57:14.788123 2026] [security2:error] [pid 533360:tid 533611] [client 20.197.192.193:40777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/tkikikoko.php"] [unique_id "al9emnUPuLYrePtEkUcwCQAAAPs"]
[Tue Jul 21 08:57:14.876274 2026] [security2:error] [pid 533360:tid 533581] [client 4.194.24.143:7728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/xyn.php"] [unique_id "al9emnUPuLYrePtEkUcwDwAAAN0"]
[Tue Jul 21 08:57:14.885260 2026] [security2:error] [pid 559070:tid 559244] [client 20.197.192.193:44118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9emiy1f1FtKC137xsKYgAAAbs"]
[Tue Jul 21 08:57:14.923651 2026] [security2:error] [pid 559070:tid 559287] [client 65.21.113.253:34066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9emiy1f1FtKC137xsKVQAAAeY"]
[Tue Jul 21 08:57:14.932143 2026] [security2:error] [pid 559070:tid 559298] [client 20.197.192.193:40798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wp-css.php"] [unique_id "al9emiy1f1FtKC137xsKYwAAAfE"]
[Tue Jul 21 08:57:14.998801 2026] [security2:error] [pid 533360:tid 533529] [client 20.197.192.193:40802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wp-explorer.php"] [unique_id "al9emnUPuLYrePtEkUcwEQAAAKk"]
[Tue Jul 21 08:57:15.101104 2026] [security2:error] [pid 559070:tid 559304] [client 5.38.115.39:24669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9emyy1f1FtKC137xsKZAAAAfc"]
[Tue Jul 21 08:57:15.101242 2026] [security2:error] [pid 559070:tid 559304] [client 5.38.115.39:24669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9emyy1f1FtKC137xsKZAAAAfc"]
[Tue Jul 21 08:57:15.137556 2026] [security2:error] [pid 533360:tid 533575] [client 20.197.192.193:44156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/akismet.php"] [unique_id "al9em3UPuLYrePtEkUcwEwAAANc"]
[Tue Jul 21 08:57:15.188438 2026] [security2:error] [pid 559070:tid 559246] [client 20.197.192.193:40816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/ace2.php"] [unique_id "al9emyy1f1FtKC137xsKZQAAAb0"]
[Tue Jul 21 08:57:15.247251 2026] [security2:error] [pid 559070:tid 559235] [client 20.197.192.193:44105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/ms.php"] [unique_id "al9emyy1f1FtKC137xsKZwAAAbI"]
[Tue Jul 21 08:57:15.303738 2026] [security2:error] [pid 559070:tid 559136] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9emyy1f1FtKC137xsKaAACCEE"]
[Tue Jul 21 08:57:15.303930 2026] [security2:error] [pid 559070:tid 559321] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9emyy1f1FtKC137xsKaAACCEE"]
[Tue Jul 21 08:57:15.557484 2026] [security2:error] [pid 533360:tid 533613] [client 59.95.197.55:57163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9em3UPuLYrePtEkUcwHAAAAP0"]
[Tue Jul 21 08:57:15.557618 2026] [security2:error] [pid 533360:tid 533613] [client 59.95.197.55:57163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9em3UPuLYrePtEkUcwHAAAAP0"]
[Tue Jul 21 08:57:15.607528 2026] [autoindex:error] [pid 559070:tid 559228] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/Text/Diff/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:15.824808 2026] [security2:error] [pid 533360:tid 533395] [remote 217.181.91.131:62663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.91.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9em3UPuLYrePtEkUcwHQAA8x8"]
[Tue Jul 21 08:57:15.872540 2026] [security2:error] [pid 559070:tid 559221] [client 20.151.10.161:51038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/puc.php"] [unique_id "al9emyy1f1FtKC137xsKeQAAAaQ"]
[Tue Jul 21 08:57:15.920907 2026] [security2:error] [pid 533360:tid 533550] [client 4.194.24.143:7687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/y.php"] [unique_id "al9em3UPuLYrePtEkUcwIQAAAL4"]
[Tue Jul 21 08:57:16.164092 2026] [security2:error] [pid 559070:tid 559229] [client 121.182.42.250:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "onkosclinica.com"] [uri "/wp-login.php"] [unique_id "al9enCy1f1FtKC137xsKgAABrHU"], referer: https://onkosclinica.com/wp-login.php
[Tue Jul 21 08:57:16.395236 2026] [security2:error] [pid 559070:tid 559238] [client 113.22.144.139:59177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9enCy1f1FtKC137xsKgQAAAbU"]
[Tue Jul 21 08:57:16.395917 2026] [security2:error] [pid 559070:tid 559238] [client 113.22.144.139:59177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9enCy1f1FtKC137xsKgQAAAbU"]
[Tue Jul 21 08:57:16.654036 2026] [autoindex:error] [pid 559070:tid 559275] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:16.889553 2026] [security2:error] [pid 559070:tid 559110] [remote 184.168.124.4:55732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.124.168.184.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eduardogoesadv.com"] [uri "/wp-login.php"] [unique_id "al9enCy1f1FtKC137xsKiAABkic"]
[Tue Jul 21 08:57:16.984521 2026] [security2:error] [pid 559070:tid 559245] [client 4.194.24.143:62941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/z.php"] [unique_id "al9enCy1f1FtKC137xsKjAAAAbw"]
[Tue Jul 21 08:57:17.315283 2026] [security2:error] [pid 533360:tid 533580] [client 20.52.136.55:1573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/3.php"] [unique_id "al9enXUPuLYrePtEkUcwPgAAANw"]
[Tue Jul 21 08:57:17.380435 2026] [security2:error] [pid 533360:tid 533581] [client 114.198.138.124:54445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9enXUPuLYrePtEkUcwQAAAAN0"]
[Tue Jul 21 08:57:17.380541 2026] [security2:error] [pid 533360:tid 533581] [client 114.198.138.124:54445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9enXUPuLYrePtEkUcwQAAAAN0"]
[Tue Jul 21 08:57:17.552873 2026] [security2:error] [pid 559070:tid 559274] [client 20.220.225.223:60353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/jga.php"] [unique_id "al9enSy1f1FtKC137xsKlgAAAdk"]
[Tue Jul 21 08:57:17.627489 2026] [security2:error] [pid 533360:tid 533555] [client 128.127.105.184:38382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9enXUPuLYrePtEkUcwRAAAAMM"]
[Tue Jul 21 08:57:17.627604 2026] [security2:error] [pid 533360:tid 533555] [client 128.127.105.184:38382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9enXUPuLYrePtEkUcwRAAAAMM"]
[Tue Jul 21 08:57:17.746008 2026] [security2:error] [pid 559070:tid 559122] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9enSy1f1FtKC137xsKlwABuTM"]
[Tue Jul 21 08:57:17.746123 2026] [security2:error] [pid 559070:tid 559242] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9enSy1f1FtKC137xsKlwABuTM"]
[Tue Jul 21 08:57:17.990223 2026] [security2:error] [pid 559070:tid 559326] [client 20.197.192.193:44137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9enSy1f1FtKC137xsKmgAAAg0"]
[Tue Jul 21 08:57:18.023945 2026] [security2:error] [pid 533360:tid 533595] [client 20.197.192.193:40797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9ennUPuLYrePtEkUcwTQAAAOs"]
[Tue Jul 21 08:57:18.057434 2026] [security2:error] [pid 533360:tid 533605] [client 4.194.24.143:7729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tainux.org"] [uri "/zk81cwqsdefault.php"] [unique_id "al9ennUPuLYrePtEkUcwTgAAAPU"]
[Tue Jul 21 08:57:18.066178 2026] [security2:error] [pid 533360:tid 533573] [client 20.197.192.193:44115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/dp.php"] [unique_id "al9ennUPuLYrePtEkUcwTwAAANU"]
[Tue Jul 21 08:57:18.104581 2026] [security2:error] [pid 559070:tid 559202] [client 20.197.192.193:44131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/old.php"] [unique_id "al9eniy1f1FtKC137xsKnAAAAZE"]
[Tue Jul 21 08:57:18.138077 2026] [security2:error] [pid 533360:tid 533603] [client 20.197.192.193:44111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/ms-new.php"] [unique_id "al9ennUPuLYrePtEkUcwUQAAAPM"]
[Tue Jul 21 08:57:18.153384 2026] [security2:error] [pid 533360:tid 533619] [client 20.197.192.193:40820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/track.php"] [unique_id "al9ennUPuLYrePtEkUcwUwAAAQM"]
[Tue Jul 21 08:57:18.170253 2026] [core:error] [pid 533360:tid 533453] [remote 52.167.144.25:32322] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:18.170275 2026] [core:error] [pid 533360:tid 533453] [remote 52.167.144.25:32322] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:18.176839 2026] [security2:error] [pid 559070:tid 559240] [client 20.197.192.193:40785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/2352356666.php"] [unique_id "al9eniy1f1FtKC137xsKngAAAbc"]
[Tue Jul 21 08:57:18.177486 2026] [autoindex:error] [pid 533360:tid 533522] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:18.200238 2026] [security2:error] [pid 533360:tid 533539] [client 20.197.192.193:44119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/pn.php"] [unique_id "al9ennUPuLYrePtEkUcwVwAAALM"]
[Tue Jul 21 08:57:18.210851 2026] [security2:error] [pid 533360:tid 533541] [client 20.220.225.223:34185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9ennUPuLYrePtEkUcwWAAAALU"]
[Tue Jul 21 08:57:18.228659 2026] [security2:error] [pid 533360:tid 533563] [client 20.197.192.193:44112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9ennUPuLYrePtEkUcwWQAAAMs"]
[Tue Jul 21 08:57:18.265098 2026] [security2:error] [pid 533360:tid 533514] [client 20.197.192.193:40783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/dr.php"] [unique_id "al9ennUPuLYrePtEkUcwWgAAAJo"]
[Tue Jul 21 08:57:18.330614 2026] [security2:error] [pid 559070:tid 559325] [client 20.197.192.193:53258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/2x.php"] [unique_id "al9eniy1f1FtKC137xsKnwAAAgw"]
[Tue Jul 21 08:57:18.376580 2026] [security2:error] [pid 559070:tid 559221] [client 20.197.192.193:40813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/kq1.php"] [unique_id "al9eniy1f1FtKC137xsKoAAAAaQ"]
[Tue Jul 21 08:57:18.391298 2026] [security2:error] [pid 559070:tid 559232] [client 20.197.192.193:44124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/zzz.php"] [unique_id "al9eniy1f1FtKC137xsKoQAAAa8"]
[Tue Jul 21 08:57:18.436419 2026] [security2:error] [pid 559070:tid 559299] [client 20.197.192.193:40822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wicked.php"] [unique_id "al9eniy1f1FtKC137xsKogAAAfI"]
[Tue Jul 21 08:57:18.449452 2026] [security2:error] [pid 533360:tid 533528] [client 20.197.192.193:44153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/edit.php"] [unique_id "al9ennUPuLYrePtEkUcwYAAAAKg"]
[Tue Jul 21 08:57:18.455057 2026] [security2:error] [pid 533360:tid 533493] [client 121.182.42.250:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "onkosclinica.com"] [uri "/wp-login.php"] [unique_id "al9ennUPuLYrePtEkUcwXgAAhRM"], referer: https://onkosclinica.com/wp-login.php
[Tue Jul 21 08:57:18.472031 2026] [security2:error] [pid 533360:tid 533499] [client 20.197.192.193:40801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/kua.php"] [unique_id "al9ennUPuLYrePtEkUcwYQAAAIs"]
[Tue Jul 21 08:57:18.503214 2026] [security2:error] [pid 559070:tid 559290] [client 20.197.192.193:40831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/ez.php"] [unique_id "al9eniy1f1FtKC137xsKowAAAek"]
[Tue Jul 21 08:57:18.525990 2026] [security2:error] [pid 533360:tid 533494] [client 20.197.192.193:40807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/fz.php"] [unique_id "al9ennUPuLYrePtEkUcwYwAAAIY"]
[Tue Jul 21 08:57:18.548527 2026] [security2:error] [pid 533360:tid 533519] [client 20.197.192.193:40791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/la.php"] [unique_id "al9ennUPuLYrePtEkUcwZgAAAJ8"]
[Tue Jul 21 08:57:18.578819 2026] [security2:error] [pid 533360:tid 533587] [client 20.197.192.193:40826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9ennUPuLYrePtEkUcwaAAAAOM"]
[Tue Jul 21 08:57:18.596836 2026] [security2:error] [pid 559070:tid 559297] [client 20.197.192.193:40829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/inso.php"] [unique_id "al9eniy1f1FtKC137xsKqAAAAfA"]
[Tue Jul 21 08:57:18.652667 2026] [security2:error] [pid 533360:tid 533584] [client 20.197.192.193:40795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wpx.php"] [unique_id "al9ennUPuLYrePtEkUcwagAAAOA"]
[Tue Jul 21 08:57:18.655087 2026] [security2:error] [pid 533360:tid 533498] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9ennUPuLYrePtEkUcwZQAAikc"]
[Tue Jul 21 08:57:18.686634 2026] [security2:error] [pid 559070:tid 559243] [client 20.197.192.193:40773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/berlin.php"] [unique_id "al9eniy1f1FtKC137xsKqQAAAbo"]
[Tue Jul 21 08:57:18.708628 2026] [security2:error] [pid 559070:tid 559252] [client 20.197.192.193:44132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/billur.php"] [unique_id "al9eniy1f1FtKC137xsKqgAAAcM"]
[Tue Jul 21 08:57:18.733161 2026] [security2:error] [pid 559070:tid 559309] [client 20.197.192.193:44158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/mimpi.php"] [unique_id "al9eniy1f1FtKC137xsKqwAAAfw"]
[Tue Jul 21 08:57:18.752005 2026] [security2:error] [pid 559070:tid 559268] [client 20.197.192.193:44157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/dp.php"] [unique_id "al9eniy1f1FtKC137xsKrAAAAdM"]
[Tue Jul 21 08:57:18.775846 2026] [security2:error] [pid 559070:tid 559236] [client 20.197.192.193:11491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/bootstrap.php"] [unique_id "al9eniy1f1FtKC137xsKrQAAAbM"]
[Tue Jul 21 08:57:18.822938 2026] [security2:error] [pid 533360:tid 533570] [client 20.197.192.193:53264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wp-editor.php"] [unique_id "al9ennUPuLYrePtEkUcwbwAAANI"]
[Tue Jul 21 08:57:18.857460 2026] [security2:error] [pid 559070:tid 559248] [client 20.197.192.193:40776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/cro.php"] [unique_id "al9eniy1f1FtKC137xsKrgAAAb8"]
[Tue Jul 21 08:57:18.870844 2026] [security2:error] [pid 559070:tid 559275] [client 20.197.192.193:40804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/cron-tab.php"] [unique_id "al9eniy1f1FtKC137xsKsAAAAdo"]
[Tue Jul 21 08:57:18.914250 2026] [security2:error] [pid 559070:tid 559276] [client 20.197.192.193:53273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/koiy.php"] [unique_id "al9eniy1f1FtKC137xsKswAAAds"]
[Tue Jul 21 08:57:18.952101 2026] [security2:error] [pid 559070:tid 559312] [client 20.197.192.193:40771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/hp2.php"] [unique_id "al9eniy1f1FtKC137xsKtAAAAf8"]
[Tue Jul 21 08:57:18.979318 2026] [security2:error] [pid 559070:tid 559203] [client 20.197.192.193:40828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/hp3.php"] [unique_id "al9eniy1f1FtKC137xsKtQAAAZI"]
[Tue Jul 21 08:57:19.004001 2026] [security2:error] [pid 559070:tid 559259] [client 20.197.192.193:40778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/aa1.php"] [unique_id "al9enyy1f1FtKC137xsKtgAAAco"]
[Tue Jul 21 08:57:19.028324 2026] [security2:error] [pid 533360:tid 533501] [client 20.197.192.193:44148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/acew67.php"] [unique_id "al9en3UPuLYrePtEkUcwdAAAAI0"]
[Tue Jul 21 08:57:19.076358 2026] [security2:error] [pid 559070:tid 559217] [client 20.197.192.193:53260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/bscclapb.php"] [unique_id "al9enyy1f1FtKC137xsKuAAAAaA"]
[Tue Jul 21 08:57:19.096465 2026] [security2:error] [pid 533360:tid 533616] [client 20.197.192.193:40769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/else1.php"] [unique_id "al9en3UPuLYrePtEkUcweQAAAQA"]
[Tue Jul 21 08:57:19.106323 2026] [security2:error] [pid 533360:tid 533580] [client 177.107.97.181:53717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.97.107.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "larissafurlaneto.online"] [uri "/xmlrpc.php"] [unique_id "al9en3UPuLYrePtEkUcweAAAANw"]
[Tue Jul 21 08:57:19.106440 2026] [security2:error] [pid 533360:tid 533580] [client 177.107.97.181:53717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "larissafurlaneto.online"] [uri "/xmlrpc.php"] [unique_id "al9en3UPuLYrePtEkUcweAAAANw"]
[Tue Jul 21 08:57:19.117774 2026] [security2:error] [pid 533360:tid 533555] [client 20.197.192.193:44097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/tkikikoko.php"] [unique_id "al9en3UPuLYrePtEkUcwegAAAMM"]
[Tue Jul 21 08:57:19.136574 2026] [security2:error] [pid 533360:tid 533620] [client 20.197.192.193:11490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9en3UPuLYrePtEkUcwfAAAAQQ"]
[Tue Jul 21 08:57:19.150606 2026] [security2:error] [pid 533360:tid 533538] [client 20.197.192.193:40803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wp-css.php"] [unique_id "al9en3UPuLYrePtEkUcwfQAAALI"]
[Tue Jul 21 08:57:19.161702 2026] [security2:error] [pid 533360:tid 533527] [client 20.197.192.193:53251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/wp-explorer.php"] [unique_id "al9en3UPuLYrePtEkUcwfgAAAKc"]
[Tue Jul 21 08:57:19.176448 2026] [security2:error] [pid 559070:tid 559246] [client 20.197.192.193:44107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/akismet.php"] [unique_id "al9enyy1f1FtKC137xsKuQAAAb0"]
[Tue Jul 21 08:57:19.194969 2026] [security2:error] [pid 559070:tid 559235] [client 20.197.192.193:44104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/ace2.php"] [unique_id "al9enyy1f1FtKC137xsKugAAAbI"]
[Tue Jul 21 08:57:19.262127 2026] [security2:error] [pid 533360:tid 533574] [client 20.197.192.193:44134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.guilhermeverissimo.com.br"] [uri "/ms.php"] [unique_id "al9en3UPuLYrePtEkUcwgAAAANY"]
[Tue Jul 21 08:57:19.334777 2026] [security2:error] [pid 559070:tid 559224] [client 65.21.113.253:50140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9enyy1f1FtKC137xsKwgAAAac"]
[Tue Jul 21 08:57:19.343243 2026] [autoindex:error] [pid 559070:tid 559306] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:19.394212 2026] [security2:error] [pid 559070:tid 559241] [client 74.7.241.192:38820] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "charts.tainux.io"] [uri "/robots.txt"] [unique_id "al9enyy1f1FtKC137xsKwwABuAI"]
[Tue Jul 21 08:57:19.437195 2026] [security2:error] [pid 559070:tid 559237] [client 128.127.105.184:41308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9enyy1f1FtKC137xsKxgAAAbQ"]
[Tue Jul 21 08:57:19.437317 2026] [security2:error] [pid 559070:tid 559237] [client 128.127.105.184:41308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9enyy1f1FtKC137xsKxgAAAbQ"]
[Tue Jul 21 08:57:19.557996 2026] [security2:error] [pid 533360:tid 533595] [client 20.151.10.161:49053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9en3UPuLYrePtEkUcwhAAAAOs"]
[Tue Jul 21 08:57:19.615942 2026] [security2:error] [pid 533360:tid 533509] [client 198.44.157.162:44554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9en3UPuLYrePtEkUcwiQAAAJU"]
[Tue Jul 21 08:57:19.616047 2026] [security2:error] [pid 533360:tid 533509] [client 198.44.157.162:44554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9en3UPuLYrePtEkUcwiQAAAJU"]
[Tue Jul 21 08:57:19.643161 2026] [security2:error] [pid 559070:tid 559304] [client 168.167.81.163:59734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9enyy1f1FtKC137xsKyQAAAfc"]
[Tue Jul 21 08:57:19.643303 2026] [security2:error] [pid 559070:tid 559304] [client 168.167.81.163:59734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9enyy1f1FtKC137xsKyQAAAfc"]
[Tue Jul 21 08:57:19.751871 2026] [security2:error] [pid 559070:tid 559085] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9enyy1f1FtKC137xsKywABzA4"]
[Tue Jul 21 08:57:19.752008 2026] [security2:error] [pid 559070:tid 559261] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9enyy1f1FtKC137xsKywABzA4"]
[Tue Jul 21 08:57:20.297016 2026] [proxy:error] [pid 533360:tid 533589] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:20.297091 2026] [proxy_http:error] [pid 533360:tid 533589] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:20.297740 2026] [proxy:error] [pid 533360:tid 533589] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:20.297787 2026] [proxy_http:error] [pid 533360:tid 533589] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:20.411840 2026] [security2:error] [pid 559070:tid 559262] [client 65.21.113.253:40688] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eoCy1f1FtKC137xsKzgAAAc0"]
[Tue Jul 21 08:57:20.414161 2026] [autoindex:error] [pid 559070:tid 559214] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:20.650934 2026] [security2:error] [pid 559070:tid 559311] [client 74.7.244.48:53610] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.tainux.io"] [uri "/cgi-sys/404.html"] [unique_id "al9eoCy1f1FtKC137xsK2AAB_jQ"]
[Tue Jul 21 08:57:20.730398 2026] [security2:error] [pid 559070:tid 559281] [client 20.151.10.161:50993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/themes.php"] [unique_id "al9eoCy1f1FtKC137xsK3AAAAeA"]
[Tue Jul 21 08:57:20.757922 2026] [proxy:error] [pid 559070:tid 559320] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:20.757974 2026] [proxy_http:error] [pid 559070:tid 559320] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:20.758503 2026] [proxy:error] [pid 559070:tid 559320] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:20.758532 2026] [proxy_http:error] [pid 559070:tid 559320] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:21.179340 2026] [proxy:error] [pid 533360:tid 533498] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:21.179401 2026] [proxy_http:error] [pid 533360:tid 533498] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:21.180132 2026] [proxy:error] [pid 533360:tid 533498] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:21.180165 2026] [proxy_http:error] [pid 533360:tid 533498] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:21.401853 2026] [security2:error] [pid 559070:tid 559302] [client 185.251.19.74:48815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9eoSy1f1FtKC137xsK4wAAAfU"]
[Tue Jul 21 08:57:21.402196 2026] [security2:error] [pid 559070:tid 559220] [client 185.251.19.72:34869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.19.251.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "efrelectronics.com.br"] [uri "/wp-login.php"] [unique_id "al9eoSy1f1FtKC137xsK5AAAAaM"]
[Tue Jul 21 08:57:21.493343 2026] [security2:error] [pid 533360:tid 533559] [client 20.151.10.161:4868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samavicosmeticos.com.br.provendasatacado.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9eoXUPuLYrePtEkUcwqwAAAMc"]
[Tue Jul 21 08:57:21.572189 2026] [security2:error] [pid 533360:tid 533503] [client 20.220.225.223:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/we.php"] [unique_id "al9eoXUPuLYrePtEkUcwrQAAAI8"]
[Tue Jul 21 08:57:21.613758 2026] [security2:error] [pid 533360:tid 533616] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eoXUPuLYrePtEkUcwrgAAAQA"]
[Tue Jul 21 08:57:21.669075 2026] [autoindex:error] [pid 559070:tid 559217] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:21.697987 2026] [access_compat:error] [pid 559070:tid 559254] [client 162.241.63.68:38206] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:57:21.770702 2026] [security2:error] [pid 559070:tid 559211] [client 20.151.10.161:4905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samavicosmeticos.com.br.provendasatacado.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9eoSy1f1FtKC137xsK6gAAAZo"]
[Tue Jul 21 08:57:21.808745 2026] [security2:error] [pid 559070:tid 559235] [client 128.127.105.184:50586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9eoSy1f1FtKC137xsK6wAAAbI"]
[Tue Jul 21 08:57:21.808865 2026] [security2:error] [pid 559070:tid 559235] [client 128.127.105.184:50586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9eoSy1f1FtKC137xsK6wAAAbI"]
[Tue Jul 21 08:57:22.028032 2026] [security2:error] [pid 533360:tid 533548] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9eonUPuLYrePtEkUcwtQAAALw"]
[Tue Jul 21 08:57:22.046280 2026] [security2:error] [pid 559070:tid 559308] [client 20.151.10.161:4908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samavicosmeticos.com.br.provendasatacado.com.br"] [uri "/images.php"] [unique_id "al9eoiy1f1FtKC137xsK7wAAAfs"]
[Tue Jul 21 08:57:22.218896 2026] [security2:error] [pid 559070:tid 559282] [client 20.220.225.223:53462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/x.php"] [unique_id "al9eoiy1f1FtKC137xsK8AAAAeE"]
[Tue Jul 21 08:57:22.321974 2026] [security2:error] [pid 559070:tid 559242] [client 20.151.10.161:4893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samavicosmeticos.com.br.provendasatacado.com.br"] [uri "/for.php"] [unique_id "al9eoiy1f1FtKC137xsK8gAAAbk"]
[Tue Jul 21 08:57:22.442770 2026] [security2:error] [pid 559070:tid 559321] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9eoiy1f1FtKC137xsK9AAAAgg"]
[Tue Jul 21 08:57:22.499682 2026] [security2:error] [pid 533360:tid 533506] [client 20.220.225.223:37586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9eonUPuLYrePtEkUcwvAAAAJI"]
[Tue Jul 21 08:57:22.586883 2026] [security2:error] [pid 559070:tid 559258] [client 117.214.78.59:52378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9eoiy1f1FtKC137xsK8wAAAck"]
[Tue Jul 21 08:57:22.587035 2026] [security2:error] [pid 559070:tid 559258] [client 117.214.78.59:52378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9eoiy1f1FtKC137xsK8wAAAck"]
[Tue Jul 21 08:57:22.597577 2026] [security2:error] [pid 559070:tid 559223] [client 20.151.10.161:4895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samavicosmeticos.com.br.provendasatacado.com.br"] [uri "/2larp.php"] [unique_id "al9eoiy1f1FtKC137xsK9gAAAaY"]
[Tue Jul 21 08:57:22.873521 2026] [security2:error] [pid 559070:tid 559210] [client 20.151.10.161:4926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samavicosmeticos.com.br.provendasatacado.com.br"] [uri "/adminner.php"] [unique_id "al9eoiy1f1FtKC137xsK-wAAAZk"]
[Tue Jul 21 08:57:22.883935 2026] [security2:error] [pid 559070:tid 559287] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9eoiy1f1FtKC137xsK_AAAAeY"]
[Tue Jul 21 08:57:22.925237 2026] [security2:error] [pid 559070:tid 559289] [client 20.151.10.161:55816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/dx.php"] [unique_id "al9eoiy1f1FtKC137xsK_QAAAeg"]
[Tue Jul 21 08:57:23.045670 2026] [autoindex:error] [pid 533360:tid 533515] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:23.051907 2026] [security2:error] [pid 533360:tid 533596] [client 20.220.225.223:52653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "humanizarmed.com.br"] [uri "/phpinfo.php1"] [unique_id "al9eo3UPuLYrePtEkUcwyAAAAOw"]
[Tue Jul 21 08:57:23.102994 2026] [security2:error] [pid 559070:tid 559263] [client 41.89.234.2:59912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eoyy1f1FtKC137xsLAwAAAc4"]
[Tue Jul 21 08:57:23.103150 2026] [security2:error] [pid 559070:tid 559263] [client 41.89.234.2:59912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eoyy1f1FtKC137xsLAwAAAc4"]
[Tue Jul 21 08:57:23.156928 2026] [security2:error] [pid 533360:tid 533537] [client 20.151.10.161:4259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samavicosmeticos.com.br.provendasatacado.com.br"] [uri "/82.php"] [unique_id "al9eo3UPuLYrePtEkUcwyQAAALE"]
[Tue Jul 21 08:57:23.276272 2026] [security2:error] [pid 559070:tid 559300] [client 185.191.171.19:12518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ellosemijoias.com.br"] [uri "/pagseguro/direct-payment/"] [unique_id "al9eoyy1f1FtKC137xsLBwAAAfM"]
[Tue Jul 21 08:57:23.276388 2026] [security2:error] [pid 559070:tid 559300] [client 185.191.171.19:12518] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ellosemijoias.com.br"] [uri "/pagseguro/direct-payment/"] [unique_id "al9eoyy1f1FtKC137xsLBwAAAfM"]
[Tue Jul 21 08:57:23.381491 2026] [security2:error] [pid 559070:tid 559227] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9eoyy1f1FtKC137xsLCgAAAao"]
[Tue Jul 21 08:57:23.431430 2026] [security2:error] [pid 559070:tid 559297] [client 20.151.10.161:4238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samavicosmeticos.com.br.provendasatacado.com.br"] [uri "/kir.php"] [unique_id "al9eoyy1f1FtKC137xsLCwAAAfA"]
[Tue Jul 21 08:57:23.800602 2026] [security2:error] [pid 533360:tid 533554] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9eo3UPuLYrePtEkUcw1gAAAMI"]
[Tue Jul 21 08:57:23.870859 2026] [security2:error] [pid 559070:tid 559229] [client 20.220.225.223:60371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9eoyy1f1FtKC137xsLDgAAAaw"]
[Tue Jul 21 08:57:23.973006 2026] [security2:error] [pid 559070:tid 559272] [client 65.21.113.253:50140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eoyy1f1FtKC137xsLEAAAAdc"]
[Tue Jul 21 08:57:24.213598 2026] [security2:error] [pid 559070:tid 559238] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9epCy1f1FtKC137xsLEwAAAbU"]
[Tue Jul 21 08:57:24.571123 2026] [security2:error] [pid 559070:tid 559275] [client 20.220.225.223:34247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/dr.php"] [unique_id "al9epCy1f1FtKC137xsLGQAAAdo"]
[Tue Jul 21 08:57:24.645998 2026] [security2:error] [pid 559070:tid 559098] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9epCy1f1FtKC137xsLGgACBxs"]
[Tue Jul 21 08:57:24.646172 2026] [security2:error] [pid 559070:tid 559320] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9epCy1f1FtKC137xsLGgACBxs"]
[Tue Jul 21 08:57:24.648544 2026] [security2:error] [pid 533360:tid 533542] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9epHUPuLYrePtEkUcw5AAAALY"]
[Tue Jul 21 08:57:24.761623 2026] [security2:error] [pid 533360:tid 533503] [client 85.208.96.203:21860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "startonesite.com.br"] [uri "/robots.txt"] [unique_id "al9epHUPuLYrePtEkUcw5wAAAI8"]
[Tue Jul 21 08:57:24.761747 2026] [security2:error] [pid 533360:tid 533503] [client 85.208.96.203:21860] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "startonesite.com.br"] [uri "/robots.txt"] [unique_id "al9epHUPuLYrePtEkUcw5wAAAI8"]
[Tue Jul 21 08:57:24.823795 2026] [security2:error] [pid 533360:tid 533527] [client 198.44.157.162:44570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9epHUPuLYrePtEkUcw6QAAAKc"]
[Tue Jul 21 08:57:24.823944 2026] [security2:error] [pid 533360:tid 533527] [client 198.44.157.162:44570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9epHUPuLYrePtEkUcw6QAAAKc"]
[Tue Jul 21 08:57:24.842183 2026] [autoindex:error] [pid 533360:tid 533609] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:24.887972 2026] [security2:error] [pid 533360:tid 533562] [client 115.245.198.210:58561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9epHUPuLYrePtEkUcw7gAAAMo"]
[Tue Jul 21 08:57:24.888109 2026] [security2:error] [pid 533360:tid 533562] [client 115.245.198.210:58561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9epHUPuLYrePtEkUcw7gAAAMo"]
[Tue Jul 21 08:57:25.039933 2026] [security2:error] [pid 533360:tid 533575] [client 65.21.113.253:40702] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9epHUPuLYrePtEkUcw4wAAANc"]
[Tue Jul 21 08:57:25.069662 2026] [security2:error] [pid 559070:tid 559317] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9epSy1f1FtKC137xsLIgAAAgQ"]
[Tue Jul 21 08:57:25.229058 2026] [security2:error] [pid 533360:tid 533573] [client 20.220.225.223:20905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/edit.php"] [unique_id "al9epXUPuLYrePtEkUcw9AAAANU"]
[Tue Jul 21 08:57:25.427205 2026] [security2:error] [pid 559070:tid 559313] [client 20.151.10.161:50998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/p.php"] [unique_id "al9epSy1f1FtKC137xsLJwAAAgA"]
[Tue Jul 21 08:57:25.470327 2026] [security2:error] [pid 533360:tid 533596] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9epXUPuLYrePtEkUcw-QAAAOw"]
[Tue Jul 21 08:57:25.640420 2026] [security2:error] [pid 559070:tid 559267] [client 185.191.171.18:10388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "startonesite.com.br"] [uri "/index.php/2020/09/11/ola-mundo/"] [unique_id "al9epSy1f1FtKC137xsLKwAAAdI"]
[Tue Jul 21 08:57:25.640550 2026] [security2:error] [pid 559070:tid 559267] [client 185.191.171.18:10388] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "startonesite.com.br"] [uri "/index.php/2020/09/11/ola-mundo/"] [unique_id "al9epSy1f1FtKC137xsLKwAAAdI"]
[Tue Jul 21 08:57:25.812748 2026] [autoindex:error] [pid 559070:tid 559289] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:25.814338 2026] [security2:error] [pid 559070:tid 559150] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9epSy1f1FtKC137xsLLwAByU8"]
[Tue Jul 21 08:57:25.814483 2026] [security2:error] [pid 559070:tid 559258] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9epSy1f1FtKC137xsLLwAByU8"]
[Tue Jul 21 08:57:25.857324 2026] [security2:error] [pid 559070:tid 559224] [client 5.38.115.39:49651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9epSy1f1FtKC137xsLMAAAAac"]
[Tue Jul 21 08:57:25.857426 2026] [security2:error] [pid 559070:tid 559224] [client 5.38.115.39:49651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9epSy1f1FtKC137xsLMAAAAac"]
[Tue Jul 21 08:57:25.919428 2026] [security2:error] [pid 559070:tid 559126] [remote 68.178.160.25:60940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9epSy1f1FtKC137xsLMQAB6jc"]
[Tue Jul 21 08:57:25.958003 2026] [security2:error] [pid 559070:tid 559306] [client 59.95.197.55:57635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9epSy1f1FtKC137xsLNAAAAfk"]
[Tue Jul 21 08:57:25.958184 2026] [security2:error] [pid 559070:tid 559306] [client 59.95.197.55:57635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9epSy1f1FtKC137xsLNAAAAfk"]
[Tue Jul 21 08:57:25.983360 2026] [security2:error] [pid 559070:tid 559273] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9epSy1f1FtKC137xsLNQAAAdg"]
[Tue Jul 21 08:57:26.003218 2026] [security2:error] [pid 559070:tid 559285] [client 20.151.10.161:49095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/bob.php"] [unique_id "al9epiy1f1FtKC137xsLNgAAAeQ"]
[Tue Jul 21 08:57:26.134526 2026] [security2:error] [pid 533360:tid 533499] [client 20.52.136.55:1543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/mds.php"] [unique_id "al9epnUPuLYrePtEkUcxCAAAAIs"]
[Tue Jul 21 08:57:26.165046 2026] [security2:error] [pid 559070:tid 559079] [remote 4.205.168.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "printcom.com.br"] [uri "/wp-login.php"] [unique_id "al9epiy1f1FtKC137xsLOgAB3wg"]
[Tue Jul 21 08:57:26.343945 2026] [core:error] [pid 533360:tid 533365] [remote 40.77.167.72:5440] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:26.343966 2026] [core:error] [pid 533360:tid 533365] [remote 40.77.167.72:5440] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:26.351832 2026] [security2:error] [pid 533360:tid 533541] [client 103.59.206.240:31268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9epnUPuLYrePtEkUcxDgAAALU"]
[Tue Jul 21 08:57:26.351940 2026] [security2:error] [pid 533360:tid 533541] [client 103.59.206.240:31268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9epnUPuLYrePtEkUcxDgAAALU"]
[Tue Jul 21 08:57:26.461755 2026] [security2:error] [pid 533360:tid 533565] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9epnUPuLYrePtEkUcxEAAAAM0"]
[Tue Jul 21 08:57:26.466897 2026] [core:error] [pid 533360:tid 533460] [remote 40.77.167.72:5440] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:26.466911 2026] [core:error] [pid 533360:tid 533460] [remote 40.77.167.72:5440] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:26.917507 2026] [security2:error] [pid 559070:tid 559320] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lucianedesouzarozeng1782152617420.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9epiy1f1FtKC137xsLQQAAAgc"]
[Tue Jul 21 08:57:26.936492 2026] [security2:error] [pid 559070:tid 559268] [client 182.189.99.211:48426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9epiy1f1FtKC137xsLQgAAAdM"]
[Tue Jul 21 08:57:26.936619 2026] [security2:error] [pid 559070:tid 559268] [client 182.189.99.211:48426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9epiy1f1FtKC137xsLQgAAAdM"]
[Tue Jul 21 08:57:27.040607 2026] [security2:error] [pid 559070:tid 559213] [client 20.220.225.223:20889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/kua.php"] [unique_id "al9epyy1f1FtKC137xsLQwAAAZw"]
[Tue Jul 21 08:57:27.145669 2026] [autoindex:error] [pid 533360:tid 533548] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:27.181118 2026] [core:error] [pid 533360:tid 533395] [remote 40.77.167.72:5440] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:27.181142 2026] [core:error] [pid 533360:tid 533395] [remote 40.77.167.72:5440] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:27.263311 2026] [security2:error] [pid 533360:tid 533531] [client 113.22.144.139:59837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ep3UPuLYrePtEkUcxHgAAAKs"]
[Tue Jul 21 08:57:27.264149 2026] [security2:error] [pid 533360:tid 533531] [client 113.22.144.139:59837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ep3UPuLYrePtEkUcxHgAAAKs"]
[Tue Jul 21 08:57:27.323023 2026] [security2:error] [pid 559070:tid 559211] [client 20.220.225.223:55752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/ee.php"] [unique_id "al9epyy1f1FtKC137xsLTwAAAZo"]
[Tue Jul 21 08:57:27.672389 2026] [security2:error] [pid 533360:tid 533379] [remote 45.3.54.255:43533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9ep3UPuLYrePtEkUcxJQAA_Q8"]
[Tue Jul 21 08:57:27.959141 2026] [security2:error] [pid 559070:tid 559259] [client 114.198.138.124:55019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9epyy1f1FtKC137xsLXgAAAco"]
[Tue Jul 21 08:57:27.959252 2026] [security2:error] [pid 559070:tid 559259] [client 114.198.138.124:55019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9epyy1f1FtKC137xsLXgAAAco"]
[Tue Jul 21 08:57:28.049068 2026] [autoindex:error] [pid 533360:tid 533596] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:28.385882 2026] [security2:error] [pid 533360:tid 533410] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eqHUPuLYrePtEkUcxOAAA0C4"]
[Tue Jul 21 08:57:28.385991 2026] [security2:error] [pid 533360:tid 533568] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eqHUPuLYrePtEkUcxOAAA0C4"]
[Tue Jul 21 08:57:28.538804 2026] [security2:error] [pid 559070:tid 559203] [client 168.167.81.163:61278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eqCy1f1FtKC137xsLdAAAAZI"]
[Tue Jul 21 08:57:28.538950 2026] [security2:error] [pid 559070:tid 559203] [client 168.167.81.163:61278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eqCy1f1FtKC137xsLdAAAAZI"]
[Tue Jul 21 08:57:28.666188 2026] [security2:error] [pid 559070:tid 559277] [client 20.220.225.223:53440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/blue.php"] [unique_id "al9eqCy1f1FtKC137xsLgAAAAdw"]
[Tue Jul 21 08:57:28.734013 2026] [security2:error] [pid 533360:tid 533424] [remote 185.254.75.46:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fidellium.com"] [uri "/.env"] [unique_id "al9eqHUPuLYrePtEkUcxQgAArzw"]
[Tue Jul 21 08:57:28.856732 2026] [security2:error] [pid 559070:tid 559234] [client 65.21.113.253:50140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eqCy1f1FtKC137xsLhQAAAbE"]
[Tue Jul 21 08:57:29.114998 2026] [security2:error] [pid 559070:tid 559266] [client 20.151.10.161:49068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/crgio.php"] [unique_id "al9eqSy1f1FtKC137xsLjQAAAdE"]
[Tue Jul 21 08:57:29.645776 2026] [security2:error] [pid 533360:tid 533581] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eqXUPuLYrePtEkUcxUAAA3Wo"]
[Tue Jul 21 08:57:29.756694 2026] [security2:error] [pid 533360:tid 533511] [client 20.151.10.161:50976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/bthil.php"] [unique_id "al9eqXUPuLYrePtEkUcxVgAAAJc"]
[Tue Jul 21 08:57:29.908742 2026] [security2:error] [pid 559070:tid 559210] [client 65.21.113.253:57008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eqSy1f1FtKC137xsLlgAAAZk"]
[Tue Jul 21 08:57:30.026411 2026] [security2:error] [pid 559070:tid 559217] [client 20.151.10.161:49037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/pucci.php"] [unique_id "al9eqiy1f1FtKC137xsLnQAAAaA"]
[Tue Jul 21 08:57:30.084063 2026] [security2:error] [pid 533360:tid 533405] [remote 185.254.75.46:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fidellium.com"] [uri "/.env"] [unique_id "al9eqnUPuLYrePtEkUcxXQAA-ik"]
[Tue Jul 21 08:57:30.256862 2026] [autoindex:error] [pid 533360:tid 533590] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:30.271759 2026] [autoindex:error] [pid 533360:tid 533417] [remote 74.7.243.202:56654] AH01276: Cannot serve directory /home2/inlaud99/erp.asserradaliberdade.ong.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:30.307058 2026] [security2:error] [pid 559070:tid 559181] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eqiy1f1FtKC137xsLowAB824"]
[Tue Jul 21 08:57:30.307205 2026] [security2:error] [pid 559070:tid 559300] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eqiy1f1FtKC137xsLowAB824"]
[Tue Jul 21 08:57:30.312979 2026] [security2:error] [pid 559070:tid 559321] [client 20.220.225.223:20899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/ez.php"] [unique_id "al9eqiy1f1FtKC137xsLpAAAAgg"]
[Tue Jul 21 08:57:30.329961 2026] [security2:error] [pid 559070:tid 559281] [client 20.220.225.223:53445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/wp-signup.php"] [unique_id "al9eqiy1f1FtKC137xsLpQAAAeA"]
[Tue Jul 21 08:57:30.540734 2026] [autoindex:error] [pid 559070:tid 559301] [client 170.106.161.78:49974] AH01276: Cannot serve directory /home3/eltonf08/efrelectronics.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:30.544947 2026] [security2:error] [pid 533360:tid 533525] [client 194.99.104.35:51930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9eqnUPuLYrePtEkUcxaQAAAKU"]
[Tue Jul 21 08:57:30.545025 2026] [security2:error] [pid 533360:tid 533525] [client 194.99.104.35:51930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9eqnUPuLYrePtEkUcxaQAAAKU"]
[Tue Jul 21 08:57:30.727263 2026] [security2:error] [pid 559070:tid 559203] [client 74.7.230.7:54784] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.erp.asserradaliberdade.ong.br"] [uri "/cgi-sys/404.html"] [unique_id "al9eqiy1f1FtKC137xsLqwABkg0"]
[Tue Jul 21 08:57:31.224467 2026] [core:error] [pid 559070:tid 559088] [remote 40.77.167.16:14729] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:31.224488 2026] [core:error] [pid 559070:tid 559088] [remote 40.77.167.16:14729] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:32.001590 2026] [autoindex:error] [pid 559070:tid 559221] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/js/codemirror/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:32.163244 2026] [security2:error] [pid 559070:tid 559322] [client 20.151.10.161:49122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-temp.php"] [unique_id "al9erCy1f1FtKC137xsLxAAAAgk"]
[Tue Jul 21 08:57:32.178592 2026] [security2:error] [pid 559070:tid 559244] [client 198.44.157.162:55600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9erCy1f1FtKC137xsLxgAAAbs"]
[Tue Jul 21 08:57:32.178678 2026] [security2:error] [pid 559070:tid 559244] [client 198.44.157.162:55600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9erCy1f1FtKC137xsLxgAAAbs"]
[Tue Jul 21 08:57:32.237498 2026] [core:error] [pid 559070:tid 559083] [remote 40.77.167.16:14729] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:32.237517 2026] [core:error] [pid 559070:tid 559083] [remote 40.77.167.16:14729] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:32.375862 2026] [core:error] [pid 559070:tid 559118] [remote 40.77.167.16:14729] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:32.375885 2026] [core:error] [pid 559070:tid 559118] [remote 40.77.167.16:14729] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:32.426585 2026] [security2:error] [pid 533360:tid 533412] [remote 185.88.154.76:55890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.154.88.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/wp-login.php"] [unique_id "al9erHUPuLYrePtEkUcxigAArzA"]
[Tue Jul 21 08:57:32.452307 2026] [security2:error] [pid 559070:tid 559280] [client 142.44.225.138:22426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "quattrotech.com.br"] [uri "/robots.txt"] [unique_id "al9erCy1f1FtKC137xsLzQAAAd8"]
[Tue Jul 21 08:57:32.452452 2026] [security2:error] [pid 559070:tid 559280] [client 142.44.225.138:22426] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "quattrotech.com.br"] [uri "/robots.txt"] [unique_id "al9erCy1f1FtKC137xsLzQAAAd8"]
[Tue Jul 21 08:57:32.498700 2026] [security2:error] [pid 533360:tid 533586] [client 117.214.78.59:52915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9erHUPuLYrePtEkUcxjAAAAOI"]
[Tue Jul 21 08:57:32.499509 2026] [security2:error] [pid 533360:tid 533586] [client 117.214.78.59:52915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9erHUPuLYrePtEkUcxjAAAAOI"]
[Tue Jul 21 08:57:32.501595 2026] [core:error] [pid 559070:tid 559196] [remote 40.77.167.16:14729] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:32.501617 2026] [core:error] [pid 559070:tid 559196] [remote 40.77.167.16:14729] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:33.151890 2026] [security2:error] [pid 559070:tid 559218] [client 65.21.113.253:50140] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9erSy1f1FtKC137xsL5gAAAaE"]
[Tue Jul 21 08:57:33.201973 2026] [security2:error] [pid 559070:tid 559246] [client 20.220.225.223:53499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/csa.php"] [unique_id "al9erSy1f1FtKC137xsL5wAAAb0"]
[Tue Jul 21 08:57:33.235304 2026] [security2:error] [pid 533360:tid 533491] [remote 185.254.75.46:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fidellium.com"] [uri "/fidellium.com/.env"] [unique_id "al9erXUPuLYrePtEkUcxmAAAkn8"]
[Tue Jul 21 08:57:33.387853 2026] [security2:error] [pid 533360:tid 533579] [client 128.127.105.184:33302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9erXUPuLYrePtEkUcxoAAAANs"]
[Tue Jul 21 08:57:33.387957 2026] [security2:error] [pid 533360:tid 533579] [client 128.127.105.184:33302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9erXUPuLYrePtEkUcxoAAAANs"]
[Tue Jul 21 08:57:33.402671 2026] [autoindex:error] [pid 533360:tid 533590] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/js/plupload/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:33.739945 2026] [security2:error] [pid 559070:tid 559294] [client 20.151.10.161:48599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-admin/js/index.php"] [unique_id "al9erSy1f1FtKC137xsL7gAAAe0"]
[Tue Jul 21 08:57:33.762932 2026] [security2:error] [pid 559070:tid 559234] [client 41.89.234.2:60385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9erSy1f1FtKC137xsL7wAAAbE"]
[Tue Jul 21 08:57:33.763074 2026] [security2:error] [pid 559070:tid 559234] [client 41.89.234.2:60385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9erSy1f1FtKC137xsL7wAAAbE"]
[Tue Jul 21 08:57:33.833806 2026] [security2:error] [pid 559070:tid 559311] [client 20.151.10.161:50960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/7.php"] [unique_id "al9erSy1f1FtKC137xsL8AAAAf4"]
[Tue Jul 21 08:57:33.873980 2026] [security2:error] [pid 533360:tid 533560] [client 51.222.168.218:17832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "quattrotech.com.br"] [uri "/"] [unique_id "al9erXUPuLYrePtEkUcxqgAAAMg"]
[Tue Jul 21 08:57:33.874078 2026] [security2:error] [pid 533360:tid 533560] [client 51.222.168.218:17832] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "quattrotech.com.br"] [uri "/"] [unique_id "al9erXUPuLYrePtEkUcxqgAAAMg"]
[Tue Jul 21 08:57:34.122730 2026] [security2:error] [pid 559070:tid 559309] [client 20.220.225.223:20869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/fz.php"] [unique_id "al9eriy1f1FtKC137xsL-AAAAfw"]
[Tue Jul 21 08:57:34.188784 2026] [security2:error] [pid 533360:tid 533443] [remote 185.254.75.46:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fidellium.com"] [uri "/fidellium.com/.env"] [unique_id "al9ernUPuLYrePtEkUcxrQAAmk8"]
[Tue Jul 21 08:57:34.252769 2026] [security2:error] [pid 533360:tid 533572] [client 34.91.115.13:57344] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.barcob.com"] [uri "/"] [unique_id "al9ernUPuLYrePtEkUcxrwAAANQ"]
[Tue Jul 21 08:57:34.252887 2026] [security2:error] [pid 533360:tid 533572] [client 34.91.115.13:57344] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "webmail.barcob.com"] [uri "/"] [unique_id "al9ernUPuLYrePtEkUcxrwAAANQ"]
[Tue Jul 21 08:57:34.272239 2026] [security2:error] [pid 533360:tid 533505] [client 65.21.113.253:57018] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9erXUPuLYrePtEkUcxqQAAAJE"]
[Tue Jul 21 08:57:34.889630 2026] [security2:error] [pid 559070:tid 559306] [client 20.220.225.223:53456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/min.php"] [unique_id "al9eriy1f1FtKC137xsMBQAAAfk"]
[Tue Jul 21 08:57:34.904554 2026] [autoindex:error] [pid 559070:tid 559213] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:35.228310 2026] [security2:error] [pid 559070:tid 559127] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eryy1f1FtKC137xsMCgAB9jg"]
[Tue Jul 21 08:57:35.228491 2026] [security2:error] [pid 559070:tid 559303] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eryy1f1FtKC137xsMCgAB9jg"]
[Tue Jul 21 08:57:35.230768 2026] [security2:error] [pid 559070:tid 559246] [client 194.99.104.35:60594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9eryy1f1FtKC137xsMCwAAAb0"]
[Tue Jul 21 08:57:35.230868 2026] [security2:error] [pid 559070:tid 559246] [client 194.99.104.35:60594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9eryy1f1FtKC137xsMCwAAAb0"]
[Tue Jul 21 08:57:35.240073 2026] [proxy_http:error] [pid 559070:tid 559077] (70008)Partial results are valid but processing is incomplete: [remote 173.252.87.115:52462] AH01110: error reading response
[Tue Jul 21 08:57:35.486062 2026] [security2:error] [pid 533360:tid 533461] [remote 185.254.75.46:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fidellium.com"] [uri "/vendor/.env"] [unique_id "al9er3UPuLYrePtEkUcxygAAsGE"]
[Tue Jul 21 08:57:35.812081 2026] [security2:error] [pid 559070:tid 559263] [client 180.153.236.197:27545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.kianesantana.online"] [uri "/"] [unique_id "al9eryy1f1FtKC137xsMGAAAAc4"], referer: http://www.kianesantana.online/
[Tue Jul 21 08:57:35.812230 2026] [security2:error] [pid 559070:tid 559263] [client 180.153.236.197:27545] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.kianesantana.online"] [uri "/"] [unique_id "al9eryy1f1FtKC137xsMGAAAAc4"], referer: http://www.kianesantana.online/
[Tue Jul 21 08:57:35.899939 2026] [security2:error] [pid 559070:tid 559274] [client 20.151.10.161:50948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/8.php"] [unique_id "al9eryy1f1FtKC137xsMGQAAAdk"]
[Tue Jul 21 08:57:36.043344 2026] [security2:error] [pid 533360:tid 533564] [client 114.119.146.126:60399] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "benattiodontologia.com.br"] [uri "/perguntas-frequentes-sobre-tratamentos-dentarios/tratamento-de-gengiva/doencas-da-gengiva-e-diabetes/"] [unique_id "al9esHUPuLYrePtEkUcx0QAAAMw"], referer: https://benattiodontologia.com.br/2025/page/9/
[Tue Jul 21 08:57:36.328684 2026] [rewrite:warn] [pid 559070:tid 559090] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:57:36.346119 2026] [security2:error] [pid 559070:tid 559101] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9esCy1f1FtKC137xsMLgABwx4"]
[Tue Jul 21 08:57:36.346256 2026] [security2:error] [pid 559070:tid 559252] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9esCy1f1FtKC137xsMLgABwx4"]
[Tue Jul 21 08:57:36.427697 2026] [security2:error] [pid 559070:tid 559223] [client 59.95.197.55:58111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9esCy1f1FtKC137xsMMAAAAaY"]
[Tue Jul 21 08:57:36.428239 2026] [security2:error] [pid 559070:tid 559223] [client 59.95.197.55:58111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9esCy1f1FtKC137xsMMAAAAaY"]
[Tue Jul 21 08:57:36.555638 2026] [security2:error] [pid 533360:tid 533620] [client 5.38.115.39:1221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9esHUPuLYrePtEkUcx1gAAAQQ"]
[Tue Jul 21 08:57:36.555762 2026] [security2:error] [pid 533360:tid 533620] [client 5.38.115.39:1221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9esHUPuLYrePtEkUcx1gAAAQQ"]
[Tue Jul 21 08:57:36.747692 2026] [security2:error] [pid 559070:tid 559210] [client 103.59.206.240:31061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9esCy1f1FtKC137xsMOwAAAZk"]
[Tue Jul 21 08:57:36.747837 2026] [security2:error] [pid 559070:tid 559210] [client 103.59.206.240:31061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9esCy1f1FtKC137xsMOwAAAZk"]
[Tue Jul 21 08:57:36.811159 2026] [core:error] [pid 559070:tid 559133] [remote 52.167.144.25:32378] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:36.811185 2026] [core:error] [pid 559070:tid 559133] [remote 52.167.144.25:32378] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:36.895971 2026] [security2:error] [pid 559070:tid 559240] [client 20.151.10.161:49123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/puc.php"] [unique_id "al9esCy1f1FtKC137xsMPQAAAbc"]
[Tue Jul 21 08:57:36.991713 2026] [security2:error] [pid 533360:tid 533421] [remote 185.254.75.46:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fidellium.com"] [uri "/vendor/.env"] [unique_id "al9esHUPuLYrePtEkUcx3wAAmzk"]
[Tue Jul 21 08:57:37.255526 2026] [autoindex:error] [pid 559070:tid 559307] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-content/languages/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:37.355748 2026] [security2:error] [pid 559070:tid 559226] [client 20.220.225.223:34275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/2x.php"] [unique_id "al9esSy1f1FtKC137xsMRwAAAak"]
[Tue Jul 21 08:57:37.815620 2026] [security2:error] [pid 533360:tid 533588] [client 65.21.113.253:57426] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9esXUPuLYrePtEkUcx7AAAAOQ"]
[Tue Jul 21 08:57:38.022096 2026] [security2:error] [pid 559070:tid 559279] [client 20.151.10.161:51069] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/1.php"] [unique_id "al9esiy1f1FtKC137xsMTQAAAd4"]
[Tue Jul 21 08:57:38.022208 2026] [security2:error] [pid 559070:tid 559279] [client 20.151.10.161:51069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/1.php"] [unique_id "al9esiy1f1FtKC137xsMTQAAAd4"]
[Tue Jul 21 08:57:38.260070 2026] [autoindex:error] [pid 533360:tid 533587] [client 198.235.24.173:61776] AH01276: Cannot serve directory /home1/princ430/cms.principiamatematica.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:38.437451 2026] [security2:error] [pid 559070:tid 559071] [remote 41.186.86.12:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "produto-express.com"] [uri "/wp-login.php"] [unique_id "al9esiy1f1FtKC137xsMVQABogA"]
[Tue Jul 21 08:57:38.505396 2026] [security2:error] [pid 559070:tid 559304] [client 114.198.138.124:55588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9esiy1f1FtKC137xsMWAAAAfc"]
[Tue Jul 21 08:57:38.505501 2026] [security2:error] [pid 559070:tid 559304] [client 114.198.138.124:55588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9esiy1f1FtKC137xsMWAAAAfc"]
[Tue Jul 21 08:57:38.645946 2026] [security2:error] [pid 559070:tid 559284] [client 65.21.113.253:57026] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9esiy1f1FtKC137xsMVgAAAeM"]
[Tue Jul 21 08:57:38.875567 2026] [security2:error] [pid 559070:tid 559218] [client 20.151.10.161:49101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/themes.php"] [unique_id "al9esiy1f1FtKC137xsMagAAAaE"]
[Tue Jul 21 08:57:38.886030 2026] [security2:error] [pid 559070:tid 559115] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9esiy1f1FtKC137xsMawAB_Sw"]
[Tue Jul 21 08:57:38.886202 2026] [security2:error] [pid 559070:tid 559310] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9esiy1f1FtKC137xsMawAB_Sw"]
[Tue Jul 21 08:57:39.087168 2026] [security2:error] [pid 533360:tid 533467] [remote 8.217.108.67:44912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "runnezy.com.br"] [uri "/wp-login.php"] [unique_id "al9es3UPuLYrePtEkUcx-wAAkGc"]
[Tue Jul 21 08:57:39.091802 2026] [security2:error] [pid 559070:tid 559240] [client 65.21.113.253:57440] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9esyy1f1FtKC137xsMcwAAAbc"]
[Tue Jul 21 08:57:39.189653 2026] [security2:error] [pid 559070:tid 559316] [client 168.167.81.163:60595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9esyy1f1FtKC137xsMdQAAAgM"]
[Tue Jul 21 08:57:39.189835 2026] [security2:error] [pid 559070:tid 559316] [client 168.167.81.163:60595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9esyy1f1FtKC137xsMdQAAAgM"]
[Tue Jul 21 08:57:39.224277 2026] [security2:error] [pid 559070:tid 559244] [client 113.22.144.139:60659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9esyy1f1FtKC137xsMdwAAAbs"]
[Tue Jul 21 08:57:39.224395 2026] [security2:error] [pid 559070:tid 559244] [client 113.22.144.139:60659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9esyy1f1FtKC137xsMdwAAAbs"]
[Tue Jul 21 08:57:39.320690 2026] [security2:error] [pid 559070:tid 559099] [remote 185.254.75.46:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fidellium.com"] [uri "/fidellium.com/.env"] [unique_id "al9esyy1f1FtKC137xsMfAABqRw"]
[Tue Jul 21 08:57:39.753772 2026] [security2:error] [pid 559070:tid 559263] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9esyy1f1FtKC137xsMgwAAAc4"]
[Tue Jul 21 08:57:39.754289 2026] [security2:error] [pid 533360:tid 533565] [client 184.154.36.163:38780] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "hoterplast.com.br"] [uri "/th1s_1s_a_4o4.html"] [unique_id "al9es3UPuLYrePtEkUcyBAAAAM0"]
[Tue Jul 21 08:57:40.158245 2026] [security2:error] [pid 559070:tid 559234] [client 65.21.113.253:34410] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9esyy1f1FtKC137xsMhwAAAbE"]
[Tue Jul 21 08:57:40.236687 2026] [security2:error] [pid 559070:tid 559302] [client 20.220.225.223:34183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/kq1.php"] [unique_id "al9etCy1f1FtKC137xsMlgAAAfU"]
[Tue Jul 21 08:57:40.327139 2026] [autoindex:error] [pid 533360:tid 533494] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:40.353742 2026] [security2:error] [pid 559070:tid 559228] [client 20.151.10.161:55854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/100.php"] [unique_id "al9etCy1f1FtKC137xsMmwAAAas"]
[Tue Jul 21 08:57:40.394238 2026] [security2:error] [pid 559070:tid 559269] [client 20.151.10.161:49090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/dx.php"] [unique_id "al9etCy1f1FtKC137xsMnAAAAdQ"]
[Tue Jul 21 08:57:40.416448 2026] [security2:error] [pid 559070:tid 559117] [remote 185.254.75.46:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fidellium.com"] [uri "/fidellium.com/.env"] [unique_id "al9etCy1f1FtKC137xsMnQAB3C4"]
[Tue Jul 21 08:57:40.691475 2026] [security2:error] [pid 533360:tid 533552] [client 20.220.225.223:20900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/la.php"] [unique_id "al9etHUPuLYrePtEkUcyGAAAAMA"]
[Tue Jul 21 08:57:40.691488 2026] [security2:error] [pid 533360:tid 533590] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9etHUPuLYrePtEkUcyFgAA5n4"]
[Tue Jul 21 08:57:40.730545 2026] [security2:error] [pid 533360:tid 533375] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9etHUPuLYrePtEkUcyGwAA9Qs"]
[Tue Jul 21 08:57:40.730722 2026] [security2:error] [pid 533360:tid 533605] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9etHUPuLYrePtEkUcyGwAA9Qs"]
[Tue Jul 21 08:57:41.799328 2026] [security2:error] [pid 559070:tid 559325] [client 20.151.10.161:54922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/about.php"] [unique_id "al9etSy1f1FtKC137xsMsAAAAgw"]
[Tue Jul 21 08:57:42.174495 2026] [autoindex:error] [pid 559070:tid 559214] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:42.971518 2026] [security2:error] [pid 533360:tid 533594] [client 117.214.78.59:53340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9etnUPuLYrePtEkUcySgAAAOo"]
[Tue Jul 21 08:57:42.971633 2026] [security2:error] [pid 533360:tid 533594] [client 117.214.78.59:53340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9etnUPuLYrePtEkUcySgAAAOo"]
[Tue Jul 21 08:57:42.979977 2026] [security2:error] [pid 533360:tid 533580] [client 20.151.10.161:49032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/p.php"] [unique_id "al9etnUPuLYrePtEkUcySwAAANw"]
[Tue Jul 21 08:57:43.079598 2026] [security2:error] [pid 559070:tid 559300] [client 117.210.181.114:58561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.181.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9etyy1f1FtKC137xsM0AAAAfM"]
[Tue Jul 21 08:57:43.079723 2026] [security2:error] [pid 559070:tid 559300] [client 117.210.181.114:58561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9etyy1f1FtKC137xsM0AAAAfM"]
[Tue Jul 21 08:57:43.547429 2026] [security2:error] [pid 559070:tid 559220] [client 20.151.10.161:50980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/admin.php"] [unique_id "al9etyy1f1FtKC137xsM5gAAAaM"]
[Tue Jul 21 08:57:43.859603 2026] [security2:error] [pid 559070:tid 559327] [client 194.99.104.35:36198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9etyy1f1FtKC137xsM7QAAAg4"]
[Tue Jul 21 08:57:43.859716 2026] [security2:error] [pid 559070:tid 559327] [client 194.99.104.35:36198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9etyy1f1FtKC137xsM7QAAAg4"]
[Tue Jul 21 08:57:44.292792 2026] [security2:error] [pid 559070:tid 559260] [client 41.89.234.2:12247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9euCy1f1FtKC137xsM_QAAAcs"]
[Tue Jul 21 08:57:44.292955 2026] [security2:error] [pid 559070:tid 559260] [client 41.89.234.2:12247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9euCy1f1FtKC137xsM_QAAAcs"]
[Tue Jul 21 08:57:44.416838 2026] [security2:error] [pid 559070:tid 559192] [remote 65.111.3.233:31005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.3.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9euCy1f1FtKC137xsM-QABsXk"]
[Tue Jul 21 08:57:44.479634 2026] [autoindex:error] [pid 533360:tid 533525] [client 72.153.230.168:2560] AH01276: Cannot serve directory /home3/eslang81/sistema/notificacoes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:45.000555 2026] [security2:error] [pid 533360:tid 533515] [client 182.189.99.211:47665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9euXUPuLYrePtEkUcyagAAAJs"]
[Tue Jul 21 08:57:45.000793 2026] [security2:error] [pid 533360:tid 533515] [client 182.189.99.211:47665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9euXUPuLYrePtEkUcyagAAAJs"]
[Tue Jul 21 08:57:45.005034 2026] [security2:error] [pid 559070:tid 559294] [client 65.21.113.253:50266] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9euSy1f1FtKC137xsNEwAAAe0"]
[Tue Jul 21 08:57:45.447894 2026] [security2:error] [pid 559070:tid 559288] [client 45.146.54.48:31937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "inlaudo.com.br"] [uri "/wp-login.php"] [unique_id "al9euSy1f1FtKC137xsNFAAAAec"]
[Tue Jul 21 08:57:45.622982 2026] [security2:error] [pid 559070:tid 559113] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env"] [unique_id "al9euSy1f1FtKC137xsNIQACCCo"]
[Tue Jul 21 08:57:45.623484 2026] [security2:error] [pid 559070:tid 559074] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env.bak"] [unique_id "al9euSy1f1FtKC137xsNJQACCAM"]
[Tue Jul 21 08:57:45.623562 2026] [security2:error] [pid 559070:tid 559134] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env.backup"] [unique_id "al9euSy1f1FtKC137xsNJwACCD8"]
[Tue Jul 21 08:57:45.624067 2026] [security2:error] [pid 559070:tid 559096] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env"] [unique_id "al9euSy1f1FtKC137xsNLAACCBk"]
[Tue Jul 21 08:57:45.624527 2026] [security2:error] [pid 559070:tid 559078] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wp-config.php;/style.css"] [unique_id "al9euSy1f1FtKC137xsNMAACCAc"]
[Tue Jul 21 08:57:45.624529 2026] [security2:error] [pid 559070:tid 559087] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wp-config.php.bak"] [unique_id "al9euSy1f1FtKC137xsNLwACCBA"]
[Tue Jul 21 08:57:45.628125 2026] [security2:error] [pid 559070:tid 559160] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wp-config.php"] [unique_id "al9euSy1f1FtKC137xsNMgACCFk"]
[Tue Jul 21 08:57:45.666337 2026] [security2:error] [pid 533360:tid 533498] [client 209.141.34.121:61034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "rioclaroimovel.com.br"] [uri "/"] [unique_id "al9euXUPuLYrePtEkUcydQAAAIo"]
[Tue Jul 21 08:57:45.714303 2026] [security2:error] [pid 559070:tid 559304] [client 20.151.10.161:49025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/bthil.php"] [unique_id "al9euSy1f1FtKC137xsNNQAAAfc"]
[Tue Jul 21 08:57:45.734241 2026] [security2:error] [pid 533360:tid 533489] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9euXUPuLYrePtEkUcyeQAAmX0"]
[Tue Jul 21 08:57:45.734463 2026] [security2:error] [pid 533360:tid 533513] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9euXUPuLYrePtEkUcyeQAAmX0"]
[Tue Jul 21 08:57:45.768363 2026] [authz_core:error] [pid 559070:tid 559112] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:45.769131 2026] [security2:error] [pid 559070:tid 559151] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9euSy1f1FtKC137xsNPgACCFA"]
[Tue Jul 21 08:57:45.917135 2026] [security2:error] [pid 559070:tid 559127] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config/app.php"] [unique_id "al9euSy1f1FtKC137xsNQgACCDg"]
[Tue Jul 21 08:57:46.032231 2026] [security2:error] [pid 559070:tid 559187] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config/database.php"] [unique_id "al9euiy1f1FtKC137xsNRQACCHQ"]
[Tue Jul 21 08:57:46.032592 2026] [security2:error] [pid 559070:tid 559137] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config/mail.php"] [unique_id "al9euiy1f1FtKC137xsNRgACCEI"]
[Tue Jul 21 08:57:46.035473 2026] [security2:error] [pid 559070:tid 559190] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/backup.sql"] [unique_id "al9euiy1f1FtKC137xsNSAACCHc"]
[Tue Jul 21 08:57:46.044616 2026] [authz_core:error] [pid 559070:tid 559161] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:46.044670 2026] [security2:error] [pid 559070:tid 559104] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/dump.sql"] [unique_id "al9euiy1f1FtKC137xsNSQACCCE"]
[Tue Jul 21 08:57:46.044670 2026] [security2:error] [pid 559070:tid 559149] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.sql"] [unique_id "al9euiy1f1FtKC137xsNSgACCE4"]
[Tue Jul 21 08:57:46.044877 2026] [security2:error] [pid 559070:tid 559156] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env"] [unique_id "al9euiy1f1FtKC137xsNTAACCFU"]
[Tue Jul 21 08:57:46.088716 2026] [security2:error] [pid 559070:tid 559252] [client 20.220.225.223:34295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/zzz.php"] [unique_id "al9euiy1f1FtKC137xsNTQAAAcM"]
[Tue Jul 21 08:57:46.114226 2026] [security2:error] [pid 533360:tid 533549] [client 65.21.113.253:34424] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9euXUPuLYrePtEkUcydwAAAL0"]
[Tue Jul 21 08:57:46.171615 2026] [security2:error] [pid 559070:tid 559090] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wp-config.php"] [unique_id "al9euiy1f1FtKC137xsNUQACCBM"]
[Tue Jul 21 08:57:46.175334 2026] [security2:error] [pid 559070:tid 559133] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env.backup"] [unique_id "al9euiy1f1FtKC137xsNVAACCD4"]
[Tue Jul 21 08:57:46.180956 2026] [security2:error] [pid 559070:tid 559260] [client 209.141.34.121:61098] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "rioclaroimovel.com.br"] [uri "/"] [unique_id "al9euiy1f1FtKC137xsNVgAAAcs"]
[Tue Jul 21 08:57:46.186094 2026] [authz_core:error] [pid 559070:tid 559125] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:46.255087 2026] [autoindex:error] [pid 559070:tid 559265] [client 217.76.50.173:0] AH01276: Cannot serve directory /home1/mar73336/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:57:46.332097 2026] [authz_core:error] [pid 559070:tid 559139] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:46.480586 2026] [authz_core:error] [pid 559070:tid 559188] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd, referer: https://www.google.com/
[Tue Jul 21 08:57:46.648531 2026] [authz_core:error] [pid 559070:tid 559110] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd, referer: https://www.bing.com/
[Tue Jul 21 08:57:46.799434 2026] [security2:error] [pid 559070:tid 559234] [client 20.220.225.223:20871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/nhvoanpl.php"] [unique_id "al9euiy1f1FtKC137xsNcgAAAbE"]
[Tue Jul 21 08:57:46.831505 2026] [authz_core:error] [pid 559070:tid 559111] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd, referer: https://duckduckgo.com/
[Tue Jul 21 08:57:46.882680 2026] [security2:error] [pid 559070:tid 559244] [client 185.213.175.37:46874] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bracksimoveis.com.br"] [uri "/wp-content/plugins/ultimate-addons-for-contact-form-7/assets/css/form-style.css"] [unique_id "al9euiy1f1FtKC137xsNdwAAAbs"]
[Tue Jul 21 08:57:46.892287 2026] [security2:error] [pid 533360:tid 533370] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eunUPuLYrePtEkUcylAAAkgY"]
[Tue Jul 21 08:57:46.892437 2026] [security2:error] [pid 533360:tid 533506] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eunUPuLYrePtEkUcylAAAkgY"]
[Tue Jul 21 08:57:46.919389 2026] [security2:error] [pid 559070:tid 559220] [client 185.213.175.37:46844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bracksimoveis.com.br"] [uri "/xmlrpc.php"] [unique_id "al9euiy1f1FtKC137xsNbgAAAaM"]
[Tue Jul 21 08:57:46.928939 2026] [security2:error] [pid 559070:tid 559204] [client 185.213.175.37:46886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bracksimoveis.com.br"] [uri "/wp-content/themes/houzez/css/all-css.css"] [unique_id "al9euiy1f1FtKC137xsNegAAAZM"]
[Tue Jul 21 08:57:46.929027 2026] [security2:error] [pid 559070:tid 559204] [client 185.213.175.37:46886] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bracksimoveis.com.br"] [uri "/wp-content/themes/houzez/css/all-css.css"] [unique_id "al9euiy1f1FtKC137xsNegAAAZM"]
[Tue Jul 21 08:57:46.940629 2026] [security2:error] [pid 559070:tid 559312] [client 59.95.197.55:58594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9euiy1f1FtKC137xsNfQAAAf8"]
[Tue Jul 21 08:57:46.941502 2026] [security2:error] [pid 559070:tid 559312] [client 59.95.197.55:58594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9euiy1f1FtKC137xsNfQAAAf8"]
[Tue Jul 21 08:57:46.977495 2026] [security2:error] [pid 559070:tid 559284] [client 185.213.175.37:46922] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bracksimoveis.com.br"] [uri "/wp-includes/js/jquery/jquery-migrate.min.js"] [unique_id "al9euiy1f1FtKC137xsNfwAAAeM"]
[Tue Jul 21 08:57:46.985164 2026] [security2:error] [pid 559070:tid 559208] [client 185.213.175.37:46830] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "bracksimoveis.com.br"] [uri "/wp-content/themes/houzez-child/style.css"] [unique_id "al9euiy1f1FtKC137xsNggAAAZc"]
[Tue Jul 21 08:57:47.017516 2026] [authz_core:error] [pid 559070:tid 559091] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:47.044766 2026] [security2:error] [pid 559070:tid 559242] [client 20.151.10.161:49029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/7.php"] [unique_id "al9euyy1f1FtKC137xsNhQAAAbk"]
[Tue Jul 21 08:57:47.060496 2026] [security2:error] [pid 559070:tid 559217] [client 185.213.175.37:46914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bracksimoveis.com.br"] [uri "/wp-content/themes/houzez/css/font-awesome/css/all.min.css"] [unique_id "al9euyy1f1FtKC137xsNhwAAAaA"]
[Tue Jul 21 08:57:47.060638 2026] [security2:error] [pid 559070:tid 559217] [client 185.213.175.37:46914] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bracksimoveis.com.br"] [uri "/wp-content/themes/houzez/css/font-awesome/css/all.min.css"] [unique_id "al9euyy1f1FtKC137xsNhwAAAaA"]
[Tue Jul 21 08:57:47.189543 2026] [authz_core:error] [pid 559070:tid 559173] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:47.270201 2026] [security2:error] [pid 559070:tid 559275] [client 5.38.115.39:32313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9euyy1f1FtKC137xsNkQAAAdo"]
[Tue Jul 21 08:57:47.270334 2026] [security2:error] [pid 559070:tid 559275] [client 5.38.115.39:32313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9euyy1f1FtKC137xsNkQAAAdo"]
[Tue Jul 21 08:57:47.276768 2026] [security2:error] [pid 559070:tid 559267] [client 198.44.157.162:52252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9euyy1f1FtKC137xsNkwAAAdI"]
[Tue Jul 21 08:57:47.276886 2026] [security2:error] [pid 559070:tid 559267] [client 198.44.157.162:52252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9euyy1f1FtKC137xsNkwAAAdI"]
[Tue Jul 21 08:57:47.349147 2026] [security2:error] [pid 559070:tid 559239] [client 103.59.206.240:31074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9euyy1f1FtKC137xsNlgAAAbY"]
[Tue Jul 21 08:57:47.349301 2026] [security2:error] [pid 559070:tid 559239] [client 103.59.206.240:31074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9euyy1f1FtKC137xsNlgAAAbY"]
[Tue Jul 21 08:57:47.349739 2026] [authz_core:error] [pid 559070:tid 559105] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:47.480424 2026] [security2:error] [pid 533360:tid 533589] [client 20.220.225.223:34179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wicked.php"] [unique_id "al9eu3UPuLYrePtEkUcyogAAAOU"]
[Tue Jul 21 08:57:47.520243 2026] [authz_core:error] [pid 559070:tid 559115] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:47.884514 2026] [security2:error] [pid 559070:tid 559303] [client 45.227.253.15:54002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.253.227.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marianapsictrab.com.br"] [uri "/index.php/jk"] [unique_id "al9euyy1f1FtKC137xsNqQAAAfY"]
[Tue Jul 21 08:57:47.891740 2026] [security2:error] [pid 559070:tid 559264] [client 185.213.175.37:21520] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "branding.agenciawats.com.br"] [uri "/wp-content/uploads/2026/02/logo-wats-1.webp"] [unique_id "al9euyy1f1FtKC137xsNqwAAAc8"]
[Tue Jul 21 08:57:48.170685 2026] [security2:error] [pid 559070:tid 559258] [client 185.213.175.37:21570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.175.213.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "branding.agenciawats.com.br"] [uri "/xmlrpc.php"] [unique_id "al9evCy1f1FtKC137xsNtQAAAck"]
[Tue Jul 21 08:57:48.177081 2026] [security2:error] [pid 559070:tid 559208] [client 185.213.175.37:21534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "branding.agenciawats.com.br"] [uri "/wp-includes/blocks/navigation/style.min.css"] [unique_id "al9evCy1f1FtKC137xsNtgAAAZc"]
[Tue Jul 21 08:57:48.177211 2026] [security2:error] [pid 559070:tid 559208] [client 185.213.175.37:21534] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "branding.agenciawats.com.br"] [uri "/wp-includes/blocks/navigation/style.min.css"] [unique_id "al9evCy1f1FtKC137xsNtgAAAZc"]
[Tue Jul 21 08:57:48.301288 2026] [security2:error] [pid 559070:tid 559327] [client 185.213.175.37:21532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "branding.agenciawats.com.br"] [uri "/sample-page/"] [unique_id "al9evCy1f1FtKC137xsNwAAAAg4"]
[Tue Jul 21 08:57:48.301397 2026] [security2:error] [pid 559070:tid 559327] [client 185.213.175.37:21532] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "branding.agenciawats.com.br"] [uri "/sample-page/"] [unique_id "al9evCy1f1FtKC137xsNwAAAAg4"]
[Tue Jul 21 08:57:48.342625 2026] [security2:error] [pid 559070:tid 559099] [remote 18.61.192.253:38898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "woma.com.br"] [uri "/wp-login.php"] [unique_id "al9evCy1f1FtKC137xsNwQAB8hw"]
[Tue Jul 21 08:57:48.402481 2026] [security2:error] [pid 559070:tid 559314] [client 20.151.10.161:49138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/8.php"] [unique_id "al9evCy1f1FtKC137xsNwgAAAgE"]
[Tue Jul 21 08:57:48.607035 2026] [authz_core:error] [pid 559070:tid 559102] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:48.829370 2026] [security2:error] [pid 559070:tid 559320] [client 74.249.245.134:27325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9evCy1f1FtKC137xsNzgAAAgc"]
[Tue Jul 21 08:57:48.925317 2026] [security2:error] [pid 559070:tid 559244] [client 20.220.225.223:53473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9evCy1f1FtKC137xsN1AAAAbs"]
[Tue Jul 21 08:57:49.058356 2026] [security2:error] [pid 559070:tid 559313] [client 113.22.144.139:61143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9evSy1f1FtKC137xsN1gAAAgA"]
[Tue Jul 21 08:57:49.058482 2026] [security2:error] [pid 559070:tid 559313] [client 113.22.144.139:61143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9evSy1f1FtKC137xsN1gAAAgA"]
[Tue Jul 21 08:57:49.085109 2026] [security2:error] [pid 559070:tid 559231] [client 114.198.138.124:56164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9evSy1f1FtKC137xsN2AAAAa4"]
[Tue Jul 21 08:57:49.085274 2026] [security2:error] [pid 559070:tid 559231] [client 114.198.138.124:56164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9evSy1f1FtKC137xsN2AAAAa4"]
[Tue Jul 21 08:57:49.230991 2026] [security2:error] [pid 559070:tid 559243] [client 20.220.225.223:60375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/echkm.php"] [unique_id "al9evSy1f1FtKC137xsN3wAAAbo"]
[Tue Jul 21 08:57:49.379045 2026] [security2:error] [pid 559070:tid 559284] [client 128.127.105.184:54390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9evSy1f1FtKC137xsN6AAAAeM"]
[Tue Jul 21 08:57:49.379135 2026] [security2:error] [pid 559070:tid 559284] [client 128.127.105.184:54390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9evSy1f1FtKC137xsN6AAAAeM"]
[Tue Jul 21 08:57:49.448275 2026] [security2:error] [pid 533360:tid 533457] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9evXUPuLYrePtEkUcyxgAAzV0"]
[Tue Jul 21 08:57:49.448451 2026] [security2:error] [pid 533360:tid 533565] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9evXUPuLYrePtEkUcyxgAAzV0"]
[Tue Jul 21 08:57:49.521387 2026] [proxy:error] [pid 559070:tid 559288] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:49.521460 2026] [proxy_http:error] [pid 559070:tid 559288] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:49.522262 2026] [proxy:error] [pid 559070:tid 559288] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:49.522303 2026] [proxy_http:error] [pid 559070:tid 559288] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:49.565228 2026] [security2:error] [pid 559070:tid 559291] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/xmlrpc.php"] [unique_id "al9evSy1f1FtKC137xsN7QAAAeo"]
[Tue Jul 21 08:57:49.566293 2026] [security2:error] [pid 533360:tid 533519] [client 184.154.36.163:49204] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/xmlrpc.php"] [unique_id "al9evXUPuLYrePtEkUcywgAAAJ8"]
[Tue Jul 21 08:57:49.784695 2026] [core:error] [pid 559070:tid 559268] [client 66.249.66.164:60572] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:49.784721 2026] [core:error] [pid 559070:tid 559268] [client 66.249.66.164:60572] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:57:49.848215 2026] [security2:error] [pid 559070:tid 559254] [client 168.167.81.163:60723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9evSy1f1FtKC137xsN9wAAAcU"]
[Tue Jul 21 08:57:49.848342 2026] [security2:error] [pid 559070:tid 559254] [client 168.167.81.163:60723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9evSy1f1FtKC137xsN9wAAAcU"]
[Tue Jul 21 08:57:49.884382 2026] [authz_core:error] [pid 559070:tid 559128] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:50.050384 2026] [security2:error] [pid 559070:tid 559302] [client 20.151.10.161:51071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/edit.php"] [unique_id "al9eviy1f1FtKC137xsOAQAAAfU"]
[Tue Jul 21 08:57:50.052410 2026] [proxy:error] [pid 559070:tid 559231] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:50.052499 2026] [proxy_http:error] [pid 559070:tid 559231] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:50.053732 2026] [proxy:error] [pid 559070:tid 559231] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:50.053795 2026] [proxy_http:error] [pid 559070:tid 559231] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:50.167425 2026] [security2:error] [pid 533360:tid 533408] [remote 37.139.53.11:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.11" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9evnUPuLYrePtEkUcyzwAAxSw"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 08:57:50.167602 2026] [security2:error] [pid 533360:tid 533557] [client 37.139.53.11:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9evnUPuLYrePtEkUcyzwAAxSw"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 08:57:50.227047 2026] [security2:error] [pid 533360:tid 533494] [client 20.220.225.223:53498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9evnUPuLYrePtEkUcy1QAAAIY"]
[Tue Jul 21 08:57:50.383333 2026] [security2:error] [pid 533360:tid 533604] [client 74.249.245.134:27282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9evnUPuLYrePtEkUcy2QAAAPQ"]
[Tue Jul 21 08:57:50.406035 2026] [security2:error] [pid 559070:tid 559154] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.htpasswd;.php"] [unique_id "al9eviy1f1FtKC137xsOFAABoVM"]
[Tue Jul 21 08:57:50.466528 2026] [proxy:error] [pid 559070:tid 559293] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:50.466627 2026] [proxy_http:error] [pid 559070:tid 559293] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:50.468206 2026] [proxy:error] [pid 559070:tid 559293] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:57:50.468267 2026] [proxy_http:error] [pid 559070:tid 559293] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:57:50.484772 2026] [security2:error] [pid 559070:tid 559288] [client 65.21.113.253:47978] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eviy1f1FtKC137xsOFwAAAec"]
[Tue Jul 21 08:57:50.496896 2026] [security2:error] [pid 559070:tid 559291] [client 20.220.225.223:60370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/mac.php"] [unique_id "al9eviy1f1FtKC137xsOGAAAAeo"]
[Tue Jul 21 08:57:50.869206 2026] [security2:error] [pid 533360:tid 533428] [remote 185.254.75.46:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fidellium.com"] [uri "/fidellium.com/.env"] [unique_id "al9evnUPuLYrePtEkUcy4AABBEA"]
[Tue Jul 21 08:57:50.917018 2026] [security2:error] [pid 533360:tid 533619] [client 20.151.10.161:49115] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/1.php"] [unique_id "al9evnUPuLYrePtEkUcy4gAAAQM"]
[Tue Jul 21 08:57:50.917133 2026] [security2:error] [pid 533360:tid 533619] [client 20.151.10.161:49115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/1.php"] [unique_id "al9evnUPuLYrePtEkUcy4gAAAQM"]
[Tue Jul 21 08:57:50.918049 2026] [security2:error] [pid 559070:tid 559285] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eviy1f1FtKC137xsOIAAAAeQ"]
[Tue Jul 21 08:57:51.013881 2026] [authz_core:error] [pid 559070:tid 559157] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:51.022054 2026] [security2:error] [pid 559070:tid 559254] [client 20.151.10.161:55882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9evyy1f1FtKC137xsOIwAAAcU"]
[Tue Jul 21 08:57:51.165474 2026] [security2:error] [pid 559070:tid 559116] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9evyy1f1FtKC137xsOJwABzC0"]
[Tue Jul 21 08:57:51.165591 2026] [security2:error] [pid 559070:tid 559261] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9evyy1f1FtKC137xsOJwABzC0"]
[Tue Jul 21 08:57:51.396073 2026] [security2:error] [pid 559070:tid 559260] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9evyy1f1FtKC137xsOMwAAAcs"]
[Tue Jul 21 08:57:51.397014 2026] [security2:error] [pid 559070:tid 559246] [client 20.220.225.223:53461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/wander.php"] [unique_id "al9evyy1f1FtKC137xsONAAAAb0"]
[Tue Jul 21 08:57:51.419978 2026] [security2:error] [pid 533360:tid 533551] [client 20.151.10.161:55879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/f6.php"] [unique_id "al9ev3UPuLYrePtEkUcy6gAAAL8"]
[Tue Jul 21 08:57:51.465068 2026] [authz_core:error] [pid 559070:tid 559140] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:51.598218 2026] [security2:error] [pid 533360:tid 533579] [client 65.21.113.253:60108] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ev3UPuLYrePtEkUcy5wAAANs"]
[Tue Jul 21 08:57:51.630748 2026] [authz_core:error] [pid 559070:tid 559165] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:51.634313 2026] [security2:error] [pid 559070:tid 559295] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9evyy1f1FtKC137xsOOwAB7nk"]
[Tue Jul 21 08:57:51.775381 2026] [security2:error] [pid 559070:tid 559148] [remote 92.222.104.216:44096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.choppon24h.com.br"] [uri "/robots.txt"] [unique_id "al9evyy1f1FtKC137xsOQQABkU0"]
[Tue Jul 21 08:57:51.775546 2026] [security2:error] [pid 559070:tid 559202] [client 92.222.104.216:44096] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.choppon24h.com.br"] [uri "/robots.txt"] [unique_id "al9evyy1f1FtKC137xsOQQABkU0"]
[Tue Jul 21 08:57:51.785655 2026] [authz_core:error] [pid 559070:tid 559163] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:51.801397 2026] [security2:error] [pid 559070:tid 559314] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9evyy1f1FtKC137xsORQAAAgE"]
[Tue Jul 21 08:57:51.944564 2026] [authz_core:error] [pid 559070:tid 559181] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:52.108521 2026] [security2:error] [pid 559070:tid 559113] [remote 185.254.75.46:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "fidellium.com"] [uri "/fidellium.com/.env"] [unique_id "al9ewCy1f1FtKC137xsOTgABpCo"]
[Tue Jul 21 08:57:52.115669 2026] [authz_core:error] [pid 559070:tid 559074] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/.htpasswd
[Tue Jul 21 08:57:52.124391 2026] [security2:error] [pid 559070:tid 559303] [client 20.220.225.223:34297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/edit.php"] [unique_id "al9ewCy1f1FtKC137xsOUQAAAfY"]
[Tue Jul 21 08:57:52.146558 2026] [security2:error] [pid 559070:tid 559271] [client 20.220.225.223:60359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/samll.php"] [unique_id "al9ewCy1f1FtKC137xsOVAAAAdY"]
[Tue Jul 21 08:57:52.186797 2026] [security2:error] [pid 533360:tid 533485] [remote 209.251.16.179:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9ev3UPuLYrePtEkUcy9AAAsXk"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 08:57:52.220525 2026] [security2:error] [pid 533360:tid 533567] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9ewHUPuLYrePtEkUcy-AAAAM8"]
[Tue Jul 21 08:57:52.279736 2026] [security2:error] [pid 559070:tid 559171] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOXAACBGQ"]
[Tue Jul 21 08:57:52.280061 2026] [security2:error] [pid 559070:tid 559078] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOWAACBAc"]
[Tue Jul 21 08:57:52.280092 2026] [security2:error] [pid 559070:tid 559096] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOWwACBBk"]
[Tue Jul 21 08:57:52.280129 2026] [security2:error] [pid 559070:tid 559087] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOWQACBBA"]
[Tue Jul 21 08:57:52.280208 2026] [security2:error] [pid 559070:tid 559086] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOYAACBA8"]
[Tue Jul 21 08:57:52.280920 2026] [security2:error] [pid 559070:tid 559158] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOXwACBFc"]
[Tue Jul 21 08:57:52.281196 2026] [security2:error] [pid 559070:tid 559124] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOYwACBDU"]
[Tue Jul 21 08:57:52.281212 2026] [security2:error] [pid 559070:tid 559112] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOZwACBCk"]
[Tue Jul 21 08:57:52.281285 2026] [security2:error] [pid 559070:tid 559151] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOZgACBFA"]
[Tue Jul 21 08:57:52.281315 2026] [security2:error] [pid 559070:tid 559084] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOaAACBA0"]
[Tue Jul 21 08:57:52.282073 2026] [security2:error] [pid 559070:tid 559197] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOZQACBH4"]
[Tue Jul 21 08:57:52.282296 2026] [security2:error] [pid 559070:tid 559083] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOaQACBAw"]
[Tue Jul 21 08:57:52.282616 2026] [security2:error] [pid 559070:tid 559197] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOagACBH4"]
[Tue Jul 21 08:57:52.282637 2026] [security2:error] [pid 559070:tid 559109] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsObAACBCY"]
[Tue Jul 21 08:57:52.283196 2026] [security2:error] [pid 559070:tid 559072] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOawACBAE"]
[Tue Jul 21 08:57:52.311742 2026] [security2:error] [pid 533360:tid 533537] [client 209.251.16.179:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9ev3UPuLYrePtEkUcy9AAAsXk"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 08:57:52.444512 2026] [security2:error] [pid 559070:tid 559077] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOcQACBAY"]
[Tue Jul 21 08:57:52.444521 2026] [security2:error] [pid 559070:tid 559127] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOcAACBDg"]
[Tue Jul 21 08:57:52.452292 2026] [security2:error] [pid 559070:tid 559137] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOcwACBEI"]
[Tue Jul 21 08:57:52.453949 2026] [security2:error] [pid 559070:tid 559156] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOdgACBFU"]
[Tue Jul 21 08:57:52.453970 2026] [security2:error] [pid 559070:tid 559161] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOeAACBFo"]
[Tue Jul 21 08:57:52.454255 2026] [security2:error] [pid 559070:tid 559149] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOdwACBE4"]
[Tue Jul 21 08:57:52.454554 2026] [security2:error] [pid 559070:tid 559195] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOeQACBHw"]
[Tue Jul 21 08:57:52.454859 2026] [security2:error] [pid 559070:tid 559090] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOegACBBM"]
[Tue Jul 21 08:57:52.476984 2026] [security2:error] [pid 559070:tid 559125] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOfAACBDY"]
[Tue Jul 21 08:57:52.489623 2026] [security2:error] [pid 559070:tid 559120] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:path"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOfgACBDE"]
[Tue Jul 21 08:57:52.589357 2026] [security2:error] [pid 559070:tid 559182] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOgAACBG8"]
[Tue Jul 21 08:57:52.593010 2026] [security2:error] [pid 559070:tid 559082] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOgQACBAs"]
[Tue Jul 21 08:57:52.611968 2026] [security2:error] [pid 559070:tid 559080] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOggACBAk"]
[Tue Jul 21 08:57:52.613854 2026] [security2:error] [pid 559070:tid 559147] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOgwACBEw"]
[Tue Jul 21 08:57:52.622648 2026] [security2:error] [pid 559070:tid 559178] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOhAACBGs"]
[Tue Jul 21 08:57:52.624596 2026] [security2:error] [pid 559070:tid 559139] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOhQACBEQ"]
[Tue Jul 21 08:57:52.632075 2026] [security2:error] [pid 559070:tid 559191] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOhgACBHg"]
[Tue Jul 21 08:57:52.632601 2026] [security2:error] [pid 559070:tid 559170] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:page"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOiAACBGM"]
[Tue Jul 21 08:57:52.651508 2026] [security2:error] [pid 559070:tid 559121] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOjQACBDI"]
[Tue Jul 21 08:57:52.654602 2026] [security2:error] [pid 559070:tid 559144] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOjgACBEk"]
[Tue Jul 21 08:57:52.661543 2026] [security2:error] [pid 559070:tid 559265] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9ewCy1f1FtKC137xsOkAAAAdA"]
[Tue Jul 21 08:57:52.735960 2026] [security2:error] [pid 559070:tid 559188] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOkgACBHU"]
[Tue Jul 21 08:57:52.750325 2026] [security2:error] [pid 559070:tid 559110] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOkwACBCc"]
[Tue Jul 21 08:57:52.757001 2026] [security2:error] [pid 559070:tid 559071] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOlAACBAA"]
[Tue Jul 21 08:57:52.767027 2026] [security2:error] [pid 559070:tid 559111] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOlgACBCg"]
[Tue Jul 21 08:57:52.767180 2026] [security2:error] [pid 559070:tid 559103] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOmAACBCA"]
[Tue Jul 21 08:57:52.767408 2026] [security2:error] [pid 559070:tid 559136] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOlwACBEE"]
[Tue Jul 21 08:57:52.768567 2026] [security2:error] [pid 559070:tid 559091] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOmQACBBQ"]
[Tue Jul 21 08:57:52.771271 2026] [security2:error] [pid 559070:tid 559168] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOmgACBGE"]
[Tue Jul 21 08:57:52.777041 2026] [security2:error] [pid 559070:tid 559173] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOmwACBGY"]
[Tue Jul 21 08:57:52.779476 2026] [security2:error] [pid 559070:tid 559085] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOnAACBA4"]
[Tue Jul 21 08:57:52.795134 2026] [security2:error] [pid 559070:tid 559073] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:include"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOnwACBAI"]
[Tue Jul 21 08:57:52.882535 2026] [security2:error] [pid 559070:tid 559200] [client 74.7.244.54:46420] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "escoladaseguranca.com.br"] [uri "/index.php"] [unique_id "al9evyy1f1FtKC137xsOPAABj2g"]
[Tue Jul 21 08:57:52.896883 2026] [security2:error] [pid 559070:tid 559183] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOpgACBHA"]
[Tue Jul 21 08:57:52.904550 2026] [security2:error] [pid 559070:tid 559153] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOpwACBFI"]
[Tue Jul 21 08:57:52.955541 2026] [security2:error] [pid 559070:tid 559172] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOqQACBGU"]
[Tue Jul 21 08:57:52.956055 2026] [security2:error] [pid 559070:tid 559097] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOqAACBBo"]
[Tue Jul 21 08:57:52.959535 2026] [security2:error] [pid 559070:tid 559162] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOqgACBFs"]
[Tue Jul 21 08:57:52.984228 2026] [security2:error] [pid 559070:tid 559176] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOqwACBGk"]
[Tue Jul 21 08:57:52.990876 2026] [security2:error] [pid 559070:tid 559099] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOrAACBBw"]
[Tue Jul 21 08:57:52.990893 2026] [security2:error] [pid 559070:tid 559141] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOrQACBEY"]
[Tue Jul 21 08:57:52.991205 2026] [security2:error] [pid 559070:tid 559102] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOrgACBB8"]
[Tue Jul 21 08:57:52.991704 2026] [security2:error] [pid 559070:tid 559180] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewCy1f1FtKC137xsOrwACBG0"]
[Tue Jul 21 08:57:53.038718 2026] [security2:error] [pid 559070:tid 559123] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsOsAACBDQ"]
[Tue Jul 21 08:57:53.100180 2026] [security2:error] [pid 559070:tid 559117] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsOtAACBC4"]
[Tue Jul 21 08:57:53.100200 2026] [security2:error] [pid 559070:tid 559152] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:config. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:config"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsOswACBFE"]
[Tue Jul 21 08:57:53.100256 2026] [security2:error] [pid 559070:tid 559236] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9ewSy1f1FtKC137xsOtgAAAbM"]
[Tue Jul 21 08:57:53.131928 2026] [security2:error] [pid 559070:tid 559169] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsOwAACBGI"]
[Tue Jul 21 08:57:53.132187 2026] [security2:error] [pid 559070:tid 559129] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsOwQACBDo"]
[Tue Jul 21 08:57:53.164936 2026] [security2:error] [pid 559070:tid 559233] [client 20.220.225.223:53457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/jga.php"] [unique_id "al9ewSy1f1FtKC137xsOwwAAAbA"]
[Tue Jul 21 08:57:53.166850 2026] [security2:error] [pid 559070:tid 559257] [client 20.220.225.223:53467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/abcd.php"] [unique_id "al9ewSy1f1FtKC137xsOxAAAAcg"]
[Tue Jul 21 08:57:53.178835 2026] [security2:error] [pid 559070:tid 559126] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsOxgACBDc"]
[Tue Jul 21 08:57:53.248929 2026] [security2:error] [pid 559070:tid 559128] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsOygACBDk"]
[Tue Jul 21 08:57:53.249006 2026] [security2:error] [pid 559070:tid 559174] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsOywACBGc"]
[Tue Jul 21 08:57:53.279320 2026] [security2:error] [pid 559070:tid 559107] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsOzQACBCQ"]
[Tue Jul 21 08:57:53.281012 2026] [security2:error] [pid 559070:tid 559138] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsOzgACBEM"]
[Tue Jul 21 08:57:53.300764 2026] [security2:error] [pid 533360:tid 533545] [client 74.249.245.134:27208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/wp.php"] [unique_id "al9ewXUPuLYrePtEkUczCgAAALk"]
[Tue Jul 21 08:57:53.325976 2026] [security2:error] [pid 559070:tid 559166] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO0AACBF8"]
[Tue Jul 21 08:57:53.328823 2026] [security2:error] [pid 533360:tid 533475] [remote 54.39.0.124:34144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.choppon24h.com.br"] [uri "/"] [unique_id "al9ewXUPuLYrePtEkUczCwAA2W8"]
[Tue Jul 21 08:57:53.329057 2026] [security2:error] [pid 533360:tid 533577] [client 54.39.0.124:34144] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.choppon24h.com.br"] [uri "/"] [unique_id "al9ewXUPuLYrePtEkUczCwAA2W8"]
[Tue Jul 21 08:57:53.335539 2026] [security2:error] [pid 559070:tid 559321] [client 20.151.10.161:48579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/100.php"] [unique_id "al9ewSy1f1FtKC137xsO0QAAAgg"]
[Tue Jul 21 08:57:53.397642 2026] [security2:error] [pid 559070:tid 559154] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO1QACBFM"]
[Tue Jul 21 08:57:53.399365 2026] [security2:error] [pid 559070:tid 559142] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO1gACBEc"]
[Tue Jul 21 08:57:53.423863 2026] [security2:error] [pid 559070:tid 559094] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO1wACBBc"]
[Tue Jul 21 08:57:53.428957 2026] [security2:error] [pid 533360:tid 533478] [remote 185.254.75.46:0] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "fidellium.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9ewXUPuLYrePtEkUczDAAA6nI"]
[Tue Jul 21 08:57:53.467568 2026] [security2:error] [pid 559070:tid 559130] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO2QACBDs"]
[Tue Jul 21 08:57:53.491572 2026] [security2:error] [pid 559070:tid 559157] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:doc. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:doc"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO2gACBFY"]
[Tue Jul 21 08:57:53.513729 2026] [security2:error] [pid 559070:tid 559250] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9ewSy1f1FtKC137xsO3wAAAcE"]
[Tue Jul 21 08:57:53.525938 2026] [security2:error] [pid 533360:tid 533519] [client 117.214.78.59:53773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9ewXUPuLYrePtEkUczDgAAAJ8"]
[Tue Jul 21 08:57:53.526077 2026] [security2:error] [pid 533360:tid 533519] [client 117.214.78.59:53773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9ewXUPuLYrePtEkUczDgAAAJ8"]
[Tue Jul 21 08:57:53.544537 2026] [security2:error] [pid 559070:tid 559140] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO5AACBEU"]
[Tue Jul 21 08:57:53.556498 2026] [security2:error] [pid 559070:tid 559165] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO5gACBF4"]
[Tue Jul 21 08:57:53.579941 2026] [security2:error] [pid 559070:tid 559192] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO6QACBHk"]
[Tue Jul 21 08:57:53.617135 2026] [security2:error] [pid 559070:tid 559148] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO6gACBE0"]
[Tue Jul 21 08:57:53.634434 2026] [security2:error] [pid 559070:tid 559163] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO6wACBFw"]
[Tue Jul 21 08:57:53.690817 2026] [security2:error] [pid 559070:tid 559076] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO7AACBAU"]
[Tue Jul 21 08:57:53.705477 2026] [security2:error] [pid 559070:tid 559181] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:document. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO7QACBG4"]
[Tue Jul 21 08:57:53.724990 2026] [security2:error] [pid 559070:tid 559108] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:document. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:document"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO7gACBCU"]
[Tue Jul 21 08:57:53.759359 2026] [security2:error] [pid 559070:tid 559194] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:document. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:document"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO8QACBHs"]
[Tue Jul 21 08:57:53.778209 2026] [security2:error] [pid 559070:tid 559184] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:document. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:document"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO8gACBHE"]
[Tue Jul 21 08:57:53.832501 2026] [security2:error] [pid 559070:tid 559074] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:document. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:document"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO9gACBAM"]
[Tue Jul 21 08:57:53.866668 2026] [security2:error] [pid 559070:tid 559078] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:document. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:document"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO-wACBAc"]
[Tue Jul 21 08:57:53.901538 2026] [security2:error] [pid 559070:tid 559087] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:document. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:document"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewSy1f1FtKC137xsO_AACBBA"]
[Tue Jul 21 08:57:53.917411 2026] [security2:error] [pid 559070:tid 559289] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9ewSy1f1FtKC137xsO_QAAAeg"]
[Tue Jul 21 08:57:54.003879 2026] [security2:error] [pid 559070:tid 559252] [client 115.245.198.210:22337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9ewiy1f1FtKC137xsPAwAAAcM"]
[Tue Jul 21 08:57:54.004010 2026] [security2:error] [pid 559070:tid 559252] [client 115.245.198.210:22337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9ewiy1f1FtKC137xsPAwAAAcM"]
[Tue Jul 21 08:57:54.079500 2026] [security2:error] [pid 559070:tid 559235] [client 20.220.225.223:53495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xyn.php"] [unique_id "al9ewiy1f1FtKC137xsPBwAAAbI"]
[Tue Jul 21 08:57:54.258712 2026] [security2:error] [pid 559070:tid 559212] [client 20.151.10.161:49026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/about.php"] [unique_id "al9ewiy1f1FtKC137xsPDgAAAZs"]
[Tue Jul 21 08:57:54.311314 2026] [security2:error] [pid 559070:tid 559272] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9ewiy1f1FtKC137xsPDwAAAdc"]
[Tue Jul 21 08:57:54.426029 2026] [security2:error] [pid 559070:tid 559083] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPEgACBAw"]
[Tue Jul 21 08:57:54.430856 2026] [security2:error] [pid 559070:tid 559197] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPEwACBH4"]
[Tue Jul 21 08:57:54.439804 2026] [security2:error] [pid 559070:tid 559109] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPFAACBCY"]
[Tue Jul 21 08:57:54.447148 2026] [security2:error] [pid 559070:tid 559072] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPFQACBAE"]
[Tue Jul 21 08:57:54.454497 2026] [security2:error] [pid 559070:tid 559179] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPFgACBGw"]
[Tue Jul 21 08:57:54.465269 2026] [security2:error] [pid 559070:tid 559145] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPFwACBEo"]
[Tue Jul 21 08:57:54.474308 2026] [security2:error] [pid 559070:tid 559077] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:load. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPGAACBAY"]
[Tue Jul 21 08:57:54.491200 2026] [security2:error] [pid 559070:tid 559127] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:load. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:load"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPGQACBDg"]
[Tue Jul 21 08:57:54.496589 2026] [security2:error] [pid 559070:tid 559161] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:load. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:load"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPGgACBFo"]
[Tue Jul 21 08:57:54.501786 2026] [security2:error] [pid 559070:tid 559149] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:load. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:load"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPHAACBE4"]
[Tue Jul 21 08:57:54.513985 2026] [core:alert] [pid 533360:tid 533570] [client 57.141.18.102:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:57:54.567811 2026] [security2:error] [pid 559070:tid 559195] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:load. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:load"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPHQACBHw"]
[Tue Jul 21 08:57:54.580278 2026] [security2:error] [pid 559070:tid 559090] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:load. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:load"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPHwACBBM"]
[Tue Jul 21 08:57:54.587724 2026] [security2:error] [pid 559070:tid 559160] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:load. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:load"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPIAACBFk"]
[Tue Jul 21 08:57:54.638424 2026] [security2:error] [pid 559070:tid 559198] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPJgACBH8"]
[Tue Jul 21 08:57:54.644746 2026] [security2:error] [pid 559070:tid 559134] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPJwACBD8"]
[Tue Jul 21 08:57:54.683177 2026] [security2:error] [pid 559070:tid 559327] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9ewiy1f1FtKC137xsPKQAAAg4"]
[Tue Jul 21 08:57:54.743251 2026] [security2:error] [pid 533360:tid 533530] [client 198.44.157.162:43292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9ewnUPuLYrePtEkUczJgAAAKo"]
[Tue Jul 21 08:57:54.743375 2026] [security2:error] [pid 533360:tid 533530] [client 198.44.157.162:43292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9ewnUPuLYrePtEkUczJgAAAKo"]
[Tue Jul 21 08:57:54.784129 2026] [security2:error] [pid 559070:tid 559082] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPKwACBAs"]
[Tue Jul 21 08:57:54.784259 2026] [security2:error] [pid 559070:tid 559080] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPLAACBAk"]
[Tue Jul 21 08:57:54.786371 2026] [security2:error] [pid 559070:tid 559147] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPLQACBEw"]
[Tue Jul 21 08:57:54.786545 2026] [security2:error] [pid 559070:tid 559187] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPLgACBHQ"]
[Tue Jul 21 08:57:54.826024 2026] [security2:error] [pid 559070:tid 559190] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:read. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPLwACBHc"]
[Tue Jul 21 08:57:54.873008 2026] [security2:error] [pid 559070:tid 559287] [client 41.89.234.2:61331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ewiy1f1FtKC137xsPMQAAAeY"]
[Tue Jul 21 08:57:54.873108 2026] [security2:error] [pid 559070:tid 559287] [client 41.89.234.2:61331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ewiy1f1FtKC137xsPMQAAAeY"]
[Tue Jul 21 08:57:54.939391 2026] [security2:error] [pid 559070:tid 559178] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:read. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:read"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPNAACBGs"]
[Tue Jul 21 08:57:54.942726 2026] [security2:error] [pid 559070:tid 559139] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:read. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:read"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPNQACBEQ"]
[Tue Jul 21 08:57:54.953368 2026] [security2:error] [pid 559070:tid 559191] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:read. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:read"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPNgACBHg"]
[Tue Jul 21 08:57:54.954918 2026] [security2:error] [pid 559070:tid 559170] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:read. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:read"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewiy1f1FtKC137xsPNwACBGM"]
[Tue Jul 21 08:57:55.048023 2026] [security2:error] [pid 533360:tid 533607] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9ew3UPuLYrePtEkUczMAAAAPc"]
[Tue Jul 21 08:57:55.086610 2026] [security2:error] [pid 559070:tid 559092] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:read. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:read"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPPgACBBU"]
[Tue Jul 21 08:57:55.089265 2026] [security2:error] [pid 559070:tid 559121] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:read. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:read"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPPwACBDI"]
[Tue Jul 21 08:57:55.430904 2026] [security2:error] [pid 559070:tid 559091] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPSAACBBQ"]
[Tue Jul 21 08:57:55.433332 2026] [security2:error] [pid 559070:tid 559168] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPSQACBGE"]
[Tue Jul 21 08:57:55.441511 2026] [security2:error] [pid 559070:tid 559085] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPSwACBA4"]
[Tue Jul 21 08:57:55.441630 2026] [security2:error] [pid 559070:tid 559173] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPSgACBGY"]
[Tue Jul 21 08:57:55.442118 2026] [security2:error] [pid 559070:tid 559136] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPTAACBEE"]
[Tue Jul 21 08:57:55.442507 2026] [security2:error] [pid 559070:tid 559173] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPTgACBGY"]
[Tue Jul 21 08:57:55.444126 2026] [security2:error] [pid 559070:tid 559085] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:template. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPTQACBA4"]
[Tue Jul 21 08:57:55.460014 2026] [security2:error] [pid 559070:tid 559305] [client 20.151.10.161:49055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/admin.php"] [unique_id "al9ewyy1f1FtKC137xsPTwAAAfg"]
[Tue Jul 21 08:57:55.463078 2026] [security2:error] [pid 559070:tid 559183] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:template. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPUAACBHA"]
[Tue Jul 21 08:57:55.487327 2026] [security2:error] [pid 559070:tid 559153] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:template. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPUQACBFI"]
[Tue Jul 21 08:57:55.494077 2026] [security2:error] [pid 559070:tid 559309] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9ewyy1f1FtKC137xsPUgAAAfw"]
[Tue Jul 21 08:57:55.494593 2026] [security2:error] [pid 533360:tid 533578] [client 182.189.99.211:47758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ew3UPuLYrePtEkUczOAAAANo"]
[Tue Jul 21 08:57:55.494697 2026] [security2:error] [pid 533360:tid 533578] [client 182.189.99.211:47758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ew3UPuLYrePtEkUczOAAAANo"]
[Tue Jul 21 08:57:55.495595 2026] [security2:error] [pid 559070:tid 559172] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:template. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPUwACBGU"]
[Tue Jul 21 08:57:55.581017 2026] [security2:error] [pid 559070:tid 559162] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:template. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPVQACBFs"]
[Tue Jul 21 08:57:55.631481 2026] [security2:error] [pid 559070:tid 559117] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPXQACBC4"]
[Tue Jul 21 08:57:55.649833 2026] [security2:error] [pid 559070:tid 559169] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPYAACBGI"]
[Tue Jul 21 08:57:55.772624 2026] [security2:error] [pid 559070:tid 559129] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPZAACBDo"]
[Tue Jul 21 08:57:55.804065 2026] [security2:error] [pid 559070:tid 559126] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPZgACBDc"]
[Tue Jul 21 08:57:55.827135 2026] [security2:error] [pid 559070:tid 559131] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPaQACBDw"]
[Tue Jul 21 08:57:55.874382 2026] [security2:error] [pid 533360:tid 533606] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mikaeledamascenovian1782118009223.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9ew3UPuLYrePtEkUczPwAAAPY"]
[Tue Jul 21 08:57:55.957987 2026] [security2:error] [pid 559070:tid 559107] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPbwACBCQ"]
[Tue Jul 21 08:57:55.970487 2026] [security2:error] [pid 559070:tid 559138] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:view. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9ewyy1f1FtKC137xsPcAACBEM"]
[Tue Jul 21 08:57:56.023982 2026] [security2:error] [pid 559070:tid 559075] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:view. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:view"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPcgACBAQ"]
[Tue Jul 21 08:57:56.133358 2026] [security2:error] [pid 559070:tid 559186] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:view. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:view"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPcwACBHM"]
[Tue Jul 21 08:57:56.141737 2026] [security2:error] [pid 559070:tid 559101] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:view. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:view"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPdAACBB4"]
[Tue Jul 21 08:57:56.196347 2026] [security2:error] [pid 559070:tid 559193] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:view. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:view"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPdQACBHo"]
[Tue Jul 21 08:57:56.253079 2026] [security2:error] [pid 533360:tid 533594] [client 74.249.245.134:27316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/new.php"] [unique_id "al9exHUPuLYrePtEkUczQwAAAOo"]
[Tue Jul 21 08:57:56.305174 2026] [security2:error] [pid 559070:tid 559154] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9exCy1f1FtKC137xsPeAABnVM"]
[Tue Jul 21 08:57:56.305408 2026] [security2:error] [pid 559070:tid 559214] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9exCy1f1FtKC137xsPeAABnVM"]
[Tue Jul 21 08:57:56.306962 2026] [security2:error] [pid 559070:tid 559142] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:view. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:view"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPeQACBEc"]
[Tue Jul 21 08:57:56.358370 2026] [security2:error] [pid 559070:tid 559089] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:view. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:view"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPegACBBI"]
[Tue Jul 21 08:57:56.568052 2026] [security2:error] [pid 559070:tid 559165] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPgwACBF4"]
[Tue Jul 21 08:57:56.570446 2026] [security2:error] [pid 559070:tid 559148] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPhQACBE0"]
[Tue Jul 21 08:57:56.570860 2026] [security2:error] [pid 559070:tid 559163] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPhgACBFw"]
[Tue Jul 21 08:57:56.571948 2026] [security2:error] [pid 559070:tid 559181] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPhwACBG4"]
[Tue Jul 21 08:57:56.572360 2026] [security2:error] [pid 559070:tid 559108] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPiQACBCU"]
[Tue Jul 21 08:57:56.572736 2026] [security2:error] [pid 559070:tid 559194] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPigACBHs"]
[Tue Jul 21 08:57:56.580373 2026] [security2:error] [pid 559070:tid 559076] [remote 65.111.9.174:61777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.9.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9exCy1f1FtKC137xsPiAAB8QU"]
[Tue Jul 21 08:57:56.672194 2026] [security2:error] [pid 533360:tid 533590] [client 20.220.225.223:35123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/akismet.php"] [unique_id "al9exHUPuLYrePtEkUczTQAAAOY"]
[Tue Jul 21 08:57:56.702168 2026] [security2:error] [pid 533360:tid 533584] [client 65.21.113.253:47990] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9exHUPuLYrePtEkUczTgAAAOA"]
[Tue Jul 21 08:57:56.773226 2026] [security2:error] [pid 559070:tid 559119] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPnwACBDA"]
[Tue Jul 21 08:57:56.773257 2026] [security2:error] [pid 559070:tid 559098] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPoAACBBs"]
[Tue Jul 21 08:57:56.774031 2026] [security2:error] [pid 559070:tid 559079] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPoQACBAg"]
[Tue Jul 21 08:57:56.774182 2026] [security2:error] [pid 559070:tid 559159] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPogACBFg"]
[Tue Jul 21 08:57:56.855743 2026] [security2:error] [pid 559070:tid 559285] [client 20.220.225.223:53501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/byp8.php"] [unique_id "al9exCy1f1FtKC137xsPpAAAAeQ"]
[Tue Jul 21 08:57:56.937568 2026] [security2:error] [pid 559070:tid 559221] [client 20.220.225.223:53489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/x.php"] [unique_id "al9exCy1f1FtKC137xsPqQAAAaQ"]
[Tue Jul 21 08:57:56.959429 2026] [security2:error] [pid 559070:tid 559072] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:dir. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:dir"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPqwACBAE"]
[Tue Jul 21 08:57:56.959490 2026] [security2:error] [pid 559070:tid 559109] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:dir. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPqgACBCY"]
[Tue Jul 21 08:57:56.960281 2026] [security2:error] [pid 559070:tid 559179] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPrAACBGw"]
[Tue Jul 21 08:57:56.965055 2026] [security2:error] [pid 559070:tid 559145] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exCy1f1FtKC137xsPrQACBEo"]
[Tue Jul 21 08:57:57.150976 2026] [security2:error] [pid 559070:tid 559077] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:dir. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:dir"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exSy1f1FtKC137xsPrgACBAY"]
[Tue Jul 21 08:57:57.165760 2026] [security2:error] [pid 559070:tid 559161] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:dir. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:dir"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exSy1f1FtKC137xsPsAACBFo"]
[Tue Jul 21 08:57:57.196065 2026] [security2:error] [pid 559070:tid 559275] [client 20.151.10.161:49091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/edit.php"] [unique_id "al9exSy1f1FtKC137xsPsgAAAdo"]
[Tue Jul 21 08:57:57.196650 2026] [security2:error] [pid 559070:tid 559149] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:dir. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:dir"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exSy1f1FtKC137xsPsQACBE4"]
[Tue Jul 21 08:57:57.215839 2026] [security2:error] [pid 559070:tid 559318] [client 198.44.157.162:43296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9exSy1f1FtKC137xsPswAAAgU"]
[Tue Jul 21 08:57:57.215913 2026] [security2:error] [pid 559070:tid 559318] [client 198.44.157.162:43296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9exSy1f1FtKC137xsPswAAAgU"]
[Tue Jul 21 08:57:57.274717 2026] [security2:error] [pid 559070:tid 559310] [client 185.198.240.209:49683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9exSy1f1FtKC137xsPtQAAAf0"]
[Tue Jul 21 08:57:57.284124 2026] [security2:error] [pid 559070:tid 559248] [client 185.198.240.212:50007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "setpointgeradores.com.br"] [uri "/wp-login.php"] [unique_id "al9exSy1f1FtKC137xsPtAAAAb8"]
[Tue Jul 21 08:57:57.363992 2026] [security2:error] [pid 559070:tid 559104] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:dir. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:dir"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exSy1f1FtKC137xsPtgACBCE"]
[Tue Jul 21 08:57:57.365270 2026] [security2:error] [pid 559070:tid 559195] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:dir. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:dir"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exSy1f1FtKC137xsPtwACBHw"]
[Tue Jul 21 08:57:57.433478 2026] [security2:error] [pid 559070:tid 559198] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9exSy1f1FtKC137xsPvAAByn8"]
[Tue Jul 21 08:57:57.433710 2026] [security2:error] [pid 559070:tid 559259] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9exSy1f1FtKC137xsPvAAByn8"]
[Tue Jul 21 08:57:57.456105 2026] [security2:error] [pid 559070:tid 559327] [client 59.95.197.55:59073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9exSy1f1FtKC137xsPvgAAAg4"]
[Tue Jul 21 08:57:57.456402 2026] [security2:error] [pid 559070:tid 559327] [client 59.95.197.55:59073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9exSy1f1FtKC137xsPvgAAAg4"]
[Tue Jul 21 08:57:57.801754 2026] [security2:error] [pid 559070:tid 559244] [client 65.21.113.253:60118] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9exSy1f1FtKC137xsPuQAAAbs"]
[Tue Jul 21 08:57:57.936852 2026] [security2:error] [pid 559070:tid 559268] [client 5.38.115.39:14309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9exSy1f1FtKC137xsPyQAAAdM"]
[Tue Jul 21 08:57:57.936979 2026] [security2:error] [pid 559070:tid 559268] [client 5.38.115.39:14309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9exSy1f1FtKC137xsPyQAAAdM"]
[Tue Jul 21 08:57:58.048216 2026] [security2:error] [pid 533360:tid 533563] [client 103.59.206.240:31334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9exnUPuLYrePtEkUczcQAAAMs"]
[Tue Jul 21 08:57:58.048386 2026] [security2:error] [pid 533360:tid 533563] [client 103.59.206.240:31334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9exnUPuLYrePtEkUczcQAAAMs"]
[Tue Jul 21 08:57:58.427858 2026] [security2:error] [pid 559070:tid 559139] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP0gACBEQ"]
[Tue Jul 21 08:57:58.434226 2026] [security2:error] [pid 559070:tid 559191] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP0wACBHg"]
[Tue Jul 21 08:57:58.449009 2026] [security2:error] [pid 559070:tid 559170] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP1AACBGM"]
[Tue Jul 21 08:57:58.469009 2026] [security2:error] [pid 533360:tid 533545] [client 74.249.245.134:27313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/class-t.api.php"] [unique_id "al9exnUPuLYrePtEkUczeAAAALk"]
[Tue Jul 21 08:57:58.477668 2026] [security2:error] [pid 559070:tid 559092] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP1wACBBU"]
[Tue Jul 21 08:57:58.480553 2026] [security2:error] [pid 559070:tid 559121] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP2AACBDI"]
[Tue Jul 21 08:57:58.500138 2026] [security2:error] [pid 559070:tid 559116] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP2QACBC0"]
[Tue Jul 21 08:57:58.508193 2026] [security2:error] [pid 559070:tid 559164] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:show. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP2gACBF0"]
[Tue Jul 21 08:57:58.518974 2026] [security2:error] [pid 559070:tid 559171] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:show. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:show"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP2wACBGQ"]
[Tue Jul 21 08:57:58.526978 2026] [security2:error] [pid 559070:tid 559095] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:show. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:show"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP3QACBBg"]
[Tue Jul 21 08:57:58.527012 2026] [security2:error] [pid 559070:tid 559081] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:show. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:show"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP3AACBAo"]
[Tue Jul 21 08:57:58.528544 2026] [security2:error] [pid 559070:tid 559151] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:show. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:show"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP3wACBFA"]
[Tue Jul 21 08:57:58.547238 2026] [security2:error] [pid 559070:tid 559150] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:show. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:show"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP4QACBE8"]
[Tue Jul 21 08:57:58.571836 2026] [security2:error] [pid 559070:tid 559124] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:show. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:show"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP4gACBDU"]
[Tue Jul 21 08:57:58.600690 2026] [security2:error] [pid 559070:tid 559175] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP5wACBGg"]
[Tue Jul 21 08:57:58.610367 2026] [security2:error] [pid 559070:tid 559136] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP6AACBEE"]
[Tue Jul 21 08:57:58.618711 2026] [security2:error] [pid 559070:tid 559173] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP6QACBGY"]
[Tue Jul 21 08:57:58.621639 2026] [security2:error] [pid 559070:tid 559073] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP6gACBAI"]
[Tue Jul 21 08:57:58.634759 2026] [security2:error] [pid 559070:tid 559085] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP7AACBA4"]
[Tue Jul 21 08:57:58.642452 2026] [security2:error] [pid 559070:tid 559183] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP7QACBHA"]
[Tue Jul 21 08:57:58.649000 2026] [security2:error] [pid 559070:tid 559153] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:src. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP7gACBFI"]
[Tue Jul 21 08:57:58.660451 2026] [security2:error] [pid 559070:tid 559172] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:src. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:src"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP7wACBGU"]
[Tue Jul 21 08:57:58.691150 2026] [security2:error] [pid 559070:tid 559182] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:src. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:src"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP8AACBG8"]
[Tue Jul 21 08:57:58.692630 2026] [security2:error] [pid 559070:tid 559162] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:src. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:src"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP8QACBFs"]
[Tue Jul 21 08:57:58.693993 2026] [security2:error] [pid 559070:tid 559117] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:src. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:src"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP8gACBC4"]
[Tue Jul 21 08:57:58.741192 2026] [security2:error] [pid 559070:tid 559129] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:src. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:src"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP9QACBDo"]
[Tue Jul 21 08:57:58.782285 2026] [security2:error] [pid 559070:tid 559126] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:src. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:src"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP9gACBDc"]
[Tue Jul 21 08:57:58.824747 2026] [security2:error] [pid 559070:tid 559138] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP-wACBEM"]
[Tue Jul 21 08:57:58.825835 2026] [security2:error] [pid 559070:tid 559174] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP_QACBGc"]
[Tue Jul 21 08:57:58.827574 2026] [security2:error] [pid 559070:tid 559075] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP_gACBAQ"]
[Tue Jul 21 08:57:58.844495 2026] [security2:error] [pid 559070:tid 559186] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsP_wACBHM"]
[Tue Jul 21 08:57:58.846806 2026] [security2:error] [pid 559070:tid 559101] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsQAAACBB4"]
[Tue Jul 21 08:57:58.846942 2026] [security2:error] [pid 559070:tid 559193] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsQAQACBHo"]
[Tue Jul 21 08:57:58.861306 2026] [security2:error] [pid 559070:tid 559261] [client 20.151.10.161:48588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9exiy1f1FtKC137xsQAgAAAcw"]
[Tue Jul 21 08:57:58.894252 2026] [security2:error] [pid 559070:tid 559177] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:source. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsQBwACBGo"]
[Tue Jul 21 08:57:58.924006 2026] [security2:error] [pid 559070:tid 559110] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:source. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:source"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsQCAACBCc"]
[Tue Jul 21 08:57:58.968725 2026] [security2:error] [pid 559070:tid 559156] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:source. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:source"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsQCgACBFU"]
[Tue Jul 21 08:57:58.971261 2026] [security2:error] [pid 559070:tid 559093] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:source. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:source"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsQDAACBBY"]
[Tue Jul 21 08:57:58.971660 2026] [security2:error] [pid 559070:tid 559071] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:source. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:source"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsQCwACBAA"]
[Tue Jul 21 08:57:58.994920 2026] [security2:error] [pid 559070:tid 559176] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:source. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:source"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsQGQACBGk"]
[Tue Jul 21 08:57:58.994996 2026] [security2:error] [pid 559070:tid 559099] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:source. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:source"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exiy1f1FtKC137xsQGgACBBw"]
[Tue Jul 21 08:57:59.035255 2026] [security2:error] [pid 533360:tid 533560] [client 20.220.225.223:34254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9ex3UPuLYrePtEkUczhQAAAMg"]
[Tue Jul 21 08:57:59.111986 2026] [security2:error] [pid 559070:tid 559085] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQYgACBA4"]
[Tue Jul 21 08:57:59.134844 2026] [security2:error] [pid 559070:tid 559153] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQZAACBFI"]
[Tue Jul 21 08:57:59.134879 2026] [security2:error] [pid 559070:tid 559172] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQZQACBGU"]
[Tue Jul 21 08:57:59.253996 2026] [security2:error] [pid 559070:tid 559117] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQaQACBC4"]
[Tue Jul 21 08:57:59.279696 2026] [security2:error] [pid 559070:tid 559129] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQagACBDo"]
[Tue Jul 21 08:57:59.280963 2026] [security2:error] [pid 559070:tid 559126] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQawACBDc"]
[Tue Jul 21 08:57:59.438745 2026] [security2:error] [pid 559070:tid 559193] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:debug. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:debug"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQcgACBHo"]
[Tue Jul 21 08:57:59.443301 2026] [security2:error] [pid 559070:tid 559075] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:debug. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQcwACBAQ"]
[Tue Jul 21 08:57:59.511938 2026] [security2:error] [pid 559070:tid 559110] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:debug. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:debug"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQegACBCc"]
[Tue Jul 21 08:57:59.520997 2026] [security2:error] [pid 559070:tid 559093] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:debug. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:debug"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQfQACBBY"]
[Tue Jul 21 08:57:59.581461 2026] [security2:error] [pid 559070:tid 559142] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:debug. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:debug"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQggACBEc"]
[Tue Jul 21 08:57:59.609233 2026] [security2:error] [pid 559070:tid 559180] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:debug. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:debug"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQigACBG0"]
[Tue Jul 21 08:57:59.613128 2026] [security2:error] [pid 559070:tid 559094] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:debug. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:debug"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQiwACBBc"]
[Tue Jul 21 08:57:59.680810 2026] [security2:error] [pid 533360:tid 533570] [client 114.198.138.124:56741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9ex3UPuLYrePtEkUczmAAAANI"]
[Tue Jul 21 08:57:59.680922 2026] [security2:error] [pid 533360:tid 533570] [client 114.198.138.124:56741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9ex3UPuLYrePtEkUczmAAAANI"]
[Tue Jul 21 08:57:59.765536 2026] [security2:error] [pid 559070:tid 559163] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQoQACBFw"]
[Tue Jul 21 08:57:59.943265 2026] [security2:error] [pid 559070:tid 559072] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9exyy1f1FtKC137xsQpgACBAE"]
[Tue Jul 21 08:57:59.970068 2026] [security2:error] [pid 559070:tid 559109] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9exyy1f1FtKC137xsQpwABnSY"]
[Tue Jul 21 08:57:59.970170 2026] [security2:error] [pid 559070:tid 559214] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9exyy1f1FtKC137xsQpwABnSY"]
[Tue Jul 21 08:57:59.993005 2026] [security2:error] [pid 559070:tid 559245] [client 20.151.10.161:51068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/inputs.php"] [unique_id "al9exyy1f1FtKC137xsQqQAAAbw"]
[Tue Jul 21 08:58:00.048698 2026] [security2:error] [pid 533360:tid 533548] [client 113.22.144.139:61687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eyHUPuLYrePtEkUczpAAAALw"]
[Tue Jul 21 08:58:00.049281 2026] [security2:error] [pid 533360:tid 533548] [client 113.22.144.139:61687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eyHUPuLYrePtEkUczpAAAALw"]
[Tue Jul 21 08:58:00.098625 2026] [security2:error] [pid 559070:tid 559145] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQsAACBEo"]
[Tue Jul 21 08:58:00.239296 2026] [security2:error] [pid 559070:tid 559076] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQsgACBAU"]
[Tue Jul 21 08:58:00.382481 2026] [security2:error] [pid 559070:tid 559102] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQtAACBB8"]
[Tue Jul 21 08:58:00.415659 2026] [security2:error] [pid 559070:tid 559280] [client 20.220.225.223:34181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9eyCy1f1FtKC137xsQtQAAAd8"]
[Tue Jul 21 08:58:00.452383 2026] [security2:error] [pid 559070:tid 559157] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQtgACBFY"]
[Tue Jul 21 08:58:00.459128 2026] [security2:error] [pid 559070:tid 559194] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:log. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQtwACBHs"]
[Tue Jul 21 08:58:00.468788 2026] [security2:error] [pid 559070:tid 559210] [client 168.167.81.163:60449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eyCy1f1FtKC137xsQuQAAAZk"]
[Tue Jul 21 08:58:00.472428 2026] [security2:error] [pid 559070:tid 559143] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:log. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:log"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQugACBEg"]
[Tue Jul 21 08:58:00.473893 2026] [security2:error] [pid 559070:tid 559210] [client 168.167.81.163:60449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9eyCy1f1FtKC137xsQuQAAAZk"]
[Tue Jul 21 08:58:00.481860 2026] [security2:error] [pid 559070:tid 559087] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:log. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:log"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQuwACBBA"]
[Tue Jul 21 08:58:00.482747 2026] [security2:error] [pid 559070:tid 559190] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:log. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:log"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQvAACBHc"]
[Tue Jul 21 08:58:00.484300 2026] [security2:error] [pid 559070:tid 559130] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:log. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:log"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQvQACBDs"]
[Tue Jul 21 08:58:00.508079 2026] [security2:error] [pid 559070:tid 559192] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:log. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:log"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQvwACBHk"]
[Tue Jul 21 08:58:00.523041 2026] [security2:error] [pid 559070:tid 559078] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:log. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:log"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQwQACBAc"]
[Tue Jul 21 08:58:00.566930 2026] [security2:error] [pid 559070:tid 559106] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQyQACBCM"]
[Tue Jul 21 08:58:00.583680 2026] [security2:error] [pid 559070:tid 559115] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQygACBCw"]
[Tue Jul 21 08:58:00.592904 2026] [security2:error] [pid 559070:tid 559122] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQywACBDM"]
[Tue Jul 21 08:58:00.600053 2026] [security2:error] [pid 559070:tid 559191] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQzAACBHg"]
[Tue Jul 21 08:58:00.615026 2026] [security2:error] [pid 559070:tid 559104] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9eyCy1f1FtKC137xsQzQACBCE"]
[Tue Jul 21 08:58:00.736245 2026] [security2:error] [pid 533360:tid 533519] [client 20.220.225.223:53477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/user.php"] [unique_id "al9eyHUPuLYrePtEkUcztgAAAJ8"]
[Tue Jul 21 08:58:00.802647 2026] [security2:error] [pid 559070:tid 559204] [client 74.249.245.134:27326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/plugins.php"] [unique_id "al9eyCy1f1FtKC137xsQ0AAAAZM"]
[Tue Jul 21 08:58:00.820845 2026] [security2:error] [pid 559070:tid 559262] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9eyCy1f1FtKC137xsQzwAAAc0"]
[Tue Jul 21 08:58:00.832089 2026] [security2:error] [pid 559070:tid 559270] [client 194.99.104.35:50740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9eyCy1f1FtKC137xsQ0QAAAdU"]
[Tue Jul 21 08:58:00.832179 2026] [security2:error] [pid 559070:tid 559270] [client 194.99.104.35:50740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9eyCy1f1FtKC137xsQ0QAAAdU"]
[Tue Jul 21 08:58:01.179861 2026] [security2:error] [pid 559070:tid 559219] [client 20.220.225.223:53477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/tinyfilemanager.php"] [unique_id "al9eySy1f1FtKC137xsQ1wAAAaI"]
[Tue Jul 21 08:58:01.480807 2026] [security2:error] [pid 559070:tid 559121] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/dump.sql"] [unique_id "al9eySy1f1FtKC137xsQ5AAB-DI"]
[Tue Jul 21 08:58:01.482262 2026] [security2:error] [pid 559070:tid 559171] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env.bak"] [unique_id "al9eySy1f1FtKC137xsQ6QAB-GQ"]
[Tue Jul 21 08:58:01.492948 2026] [security2:error] [pid 559070:tid 559114] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env~"] [unique_id "al9eySy1f1FtKC137xsQ7QAB-Cs"]
[Tue Jul 21 08:58:01.603222 2026] [security2:error] [pid 559070:tid 559172] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eySy1f1FtKC137xsQ9AACAmU"]
[Tue Jul 21 08:58:01.603390 2026] [security2:error] [pid 559070:tid 559315] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eySy1f1FtKC137xsQ9AACAmU"]
[Tue Jul 21 08:58:01.609759 2026] [core:error] [pid 533360:tid 533365] [remote 103.215.74.213:3798] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/public/.env)
[Tue Jul 21 08:58:01.612118 2026] [security2:error] [pid 533360:tid 533395] [remote 103.215.74.213:3798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env.orig"] [unique_id "al9eyXUPuLYrePtEkUcz0QAA4h8"]
[Tue Jul 21 08:58:01.612120 2026] [security2:error] [pid 533360:tid 533446] [remote 103.215.74.213:3798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env.local.old"] [unique_id "al9eyXUPuLYrePtEkUczzwAA4lI"]
[Tue Jul 21 08:58:01.612599 2026] [security2:error] [pid 533360:tid 533446] [remote 103.215.74.213:3798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/opcache-status.php"] [unique_id "al9eyXUPuLYrePtEkUcz0gAA4lI"]
[Tue Jul 21 08:58:01.814427 2026] [security2:error] [pid 559070:tid 559277] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9eySy1f1FtKC137xsQ9wAAAdw"]
[Tue Jul 21 08:58:01.949508 2026] [security2:error] [pid 533360:tid 533495] [client 20.220.225.223:60373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/ops.php"] [unique_id "al9eyXUPuLYrePtEkUcz2AAAAIc"]
[Tue Jul 21 08:58:02.111906 2026] [http2:info] [pid 533360:tid 533586] [client 103.215.74.213:3798] AH10178: h2_stream(533360-1515-67,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:58:02.205037 2026] [security2:error] [pid 559070:tid 559308] [client 20.220.225.223:37576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "choppcontrol.com.br"] [uri "/ace2.php"] [unique_id "al9eyiy1f1FtKC137xsQ_gAAAfs"]
[Tue Jul 21 08:58:02.307536 2026] [security2:error] [pid 559070:tid 559187] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env.production.bak"] [unique_id "al9eySy1f1FtKC137xsRAQAB-HQ"]
[Tue Jul 21 08:58:02.330305 2026] [security2:error] [pid 559070:tid 559320] [client 74.249.245.134:27318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/jp.php"] [unique_id "al9eyiy1f1FtKC137xsRBgAAAgc"]
[Tue Jul 21 08:58:02.431331 2026] [security2:error] [pid 559070:tid 559074] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env.local.bak"] [unique_id "al9eySy1f1FtKC137xsRCwAB-AM"]
[Tue Jul 21 08:58:02.457586 2026] [security2:error] [pid 533360:tid 533564] [client 20.151.10.161:49096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/f6.php"] [unique_id "al9eynUPuLYrePtEkUcz4gAAAMw"]
[Tue Jul 21 08:58:02.487716 2026] [security2:error] [pid 559070:tid 559142] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.php.bak"] [unique_id "al9eySy1f1FtKC137xsRFgAB-Ec"]
[Tue Jul 21 08:58:02.487987 2026] [security2:error] [pid 559070:tid 559112] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env.backup"] [unique_id "al9eySy1f1FtKC137xsREQAB-Ck"]
[Tue Jul 21 08:58:02.487985 2026] [security2:error] [pid 559070:tid 559138] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env.old"] [unique_id "al9eySy1f1FtKC137xsRDwAB-EM"]
[Tue Jul 21 08:58:02.488024 2026] [security2:error] [pid 559070:tid 559135] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env.swp"] [unique_id "al9eySy1f1FtKC137xsRGQAB-EA"]
[Tue Jul 21 08:58:02.488237 2026] [security2:error] [pid 559070:tid 559149] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wp-config.php.old"] [unique_id "al9eySy1f1FtKC137xsRHgAB-E4"]
[Tue Jul 21 08:58:02.489152 2026] [security2:error] [pid 559070:tid 559135] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.php.old"] [unique_id "al9eySy1f1FtKC137xsRIQAB-EA"]
[Tue Jul 21 08:58:02.489380 2026] [security2:error] [pid 559070:tid 559141] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9eySy1f1FtKC137xsRIgAB-EY"]
[Tue Jul 21 08:58:02.489731 2026] [security2:error] [pid 559070:tid 559112] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/.env.orig"] [unique_id "al9eySy1f1FtKC137xsRHAAB-Ck"]
[Tue Jul 21 08:58:02.490026 2026] [security2:error] [pid 559070:tid 559135] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wp-content/plugins/w3-total-cache/readme.txt"] [unique_id "al9eySy1f1FtKC137xsRIwAB-EA"]
[Tue Jul 21 08:58:02.491578 2026] [security2:error] [pid 559070:tid 559141] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.yml.bak"] [unique_id "al9eySy1f1FtKC137xsRJAAB-EY"]
[Tue Jul 21 08:58:02.492377 2026] [security2:error] [pid 559070:tid 559141] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/phpinfo.php"] [unique_id "al9eySy1f1FtKC137xsRKAAB-EY"]
[Tue Jul 21 08:58:02.493907 2026] [security2:error] [pid 559070:tid 559141] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.py.bak"] [unique_id "al9eySy1f1FtKC137xsRKQAB-EY"]
[Tue Jul 21 08:58:02.643081 2026] [security2:error] [pid 559070:tid 559237] [client 65.21.113.253:54492] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9eyiy1f1FtKC137xsRLAAAAbQ"]
[Tue Jul 21 08:58:02.664578 2026] [cgid:error] [pid 559070:tid 559235] [client 217.76.50.173:0] AH01265: stderr from /home1/mar73336/public_html/cgi-bin/: attempt to invoke directory as script
[Tue Jul 21 08:58:02.766309 2026] [security2:error] [pid 559070:tid 559079] [remote 180.153.236.231:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ferlab3d.com.br"] [uri "/"] [unique_id "al9eyiy1f1FtKC137xsRMQABrAg"], referer: https://ferlab3d.com.br/
[Tue Jul 21 08:58:02.766546 2026] [security2:error] [pid 559070:tid 559229] [client 180.153.236.231:0] ModSecurity: Warning. Matched phrase "360Spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ferlab3d.com.br"] [uri "/"] [unique_id "al9eyiy1f1FtKC137xsRMQABrAg"], referer: https://ferlab3d.com.br/
[Tue Jul 21 08:58:02.876430 2026] [security2:error] [pid 559070:tid 559246] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9eyiy1f1FtKC137xsRMAABvVw"]
[Tue Jul 21 08:58:03.274958 2026] [lsapi:error] [pid 559070:tid 559178] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(GET /config.json HTTP/2.0); uri(/index.php)
[Tue Jul 21 08:58:03.279053 2026] [lsapi:error] [pid 559070:tid 559142] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(GET /wp-content/plugins/easy-wp-smtp/wp_easy_smtp_debug_log.txt HTTP/2.0); uri(/index.php)
[Tue Jul 21 08:58:03.279294 2026] [lsapi:error] [pid 559070:tid 559112] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(GET /wp-json/gravitysmtp/v1/logs HTTP/2.0); uri(/index.php)
[Tue Jul 21 08:58:03.279467 2026] [lsapi:error] [pid 559070:tid 559149] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(GET /wp-content/plugins/easy-wp-smtp/email-log.txt HTTP/2.0); uri(/index.php)
[Tue Jul 21 08:58:03.279557 2026] [lsapi:error] [pid 559070:tid 559094] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(GET /wp-content/plugins/wp-mail-smtp/vendor/ HTTP/2.0); uri(/index.php)
[Tue Jul 21 08:58:03.279634 2026] [lsapi:error] [pid 559070:tid 559180] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(GET /css HTTP/2.0); uri(/index.php)
[Tue Jul 21 08:58:03.279780 2026] [lsapi:error] [pid 559070:tid 559141] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(GET /wp-json/gravitysmtp/v1/connectors HTTP/2.0); uri(/index.php)
[Tue Jul 21 08:58:03.279786 2026] [lsapi:error] [pid 559070:tid 559135] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(GET /actuator/env HTTP/2.0); uri(/index.php)
[Tue Jul 21 08:58:03.279852 2026] [lsapi:error] [pid 559070:tid 559138] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(GET /wp-content/plugins/wp-smtp/wp-smtp.log HTTP/2.0); uri(/index.php)
[Tue Jul 21 08:58:03.279852 2026] [lsapi:error] [pid 559070:tid 559155] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(GET /api/v1/config HTTP/2.0); uri(/index.php)
[Tue Jul 21 08:58:03.279957 2026] [lsapi:error] [pid 559070:tid 559154] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(HEAD / HTTP/2.0); uri(/)
[Tue Jul 21 08:58:03.281416 2026] [lsapi:error] [pid 559070:tid 559156] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(GET /api/info HTTP/2.0); uri(/index.php)
[Tue Jul 21 08:58:03.281557 2026] [lsapi:error] [pid 559070:tid 559144] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(GET /?rest_route=/wp/v2/users&per_page=100 HTTP/2.0); uri(/?rest_route=/wp/v2/users&per_page=100)
[Tue Jul 21 08:58:03.284083 2026] [lsapi:error] [pid 559070:tid 559154] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(HEAD / HTTP/2.0); uri(/index.php)
[Tue Jul 21 08:58:03.284251 2026] [lsapi:error] [pid 559070:tid 559144] [remote 103.215.74.213:50770] [host paginadoproduto-oficial.com.br] Connect to backend rejected on sending request(GET /?rest_route=/wp/v2/users&per_page=100 HTTP/2.0); uri(/index.php)
[Tue Jul 21 08:58:03.332992 2026] [security2:error] [pid 559070:tid 559212] [client 143.244.57.90:41570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9eyyy1f1FtKC137xsRQwAAAZs"]
[Tue Jul 21 08:58:03.426993 2026] [http2:info] [pid 533360:tid 533586] [client 103.215.74.213:3798] AH10178: h2_stream(533360-1515-123,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:58:03.488696 2026] [core:error] [pid 533360:tid 533365] [remote 103.215.74.213:3798] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/opt/app/.env)
[Tue Jul 21 08:58:03.671432 2026] [security2:error] [pid 559070:tid 559271] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9eyyy1f1FtKC137xsRRwAAAdY"]
[Tue Jul 21 08:58:03.749640 2026] [security2:error] [pid 533360:tid 533611] [client 143.244.57.90:41576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/xmlrpc.php"] [unique_id "al9ey3UPuLYrePtEkUcz_wAAAPs"]
[Tue Jul 21 08:58:03.778895 2026] [security2:error] [pid 559070:tid 559303] [client 20.220.225.223:60353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/ee.php"] [unique_id "al9eyyy1f1FtKC137xsRTQAAAfY"]
[Tue Jul 21 08:58:03.800779 2026] [security2:error] [pid 559070:tid 559284] [client 65.21.113.253:41008] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9eyyy1f1FtKC137xsRQQAAAeM"]
[Tue Jul 21 08:58:03.828332 2026] [security2:error] [pid 559070:tid 559290] [client 74.249.245.134:27286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/error.php"] [unique_id "al9eyyy1f1FtKC137xsRTgAAAek"]
[Tue Jul 21 08:58:03.986699 2026] [security2:error] [pid 559070:tid 559285] [client 117.214.78.59:54205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9eyyy1f1FtKC137xsRUwAAAeQ"]
[Tue Jul 21 08:58:03.986852 2026] [security2:error] [pid 559070:tid 559285] [client 117.214.78.59:54205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9eyyy1f1FtKC137xsRUwAAAeQ"]
[Tue Jul 21 08:58:04.419928 2026] [security2:error] [pid 559070:tid 559197] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/mysql.sql"] [unique_id "al9eyiy1f1FtKC137xsRZAAB-H4"]
[Tue Jul 21 08:58:04.422767 2026] [security2:error] [pid 559070:tid 559131] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/export.sql"] [unique_id "al9eyiy1f1FtKC137xsRZwAB-Dw"]
[Tue Jul 21 08:58:04.539348 2026] [security2:error] [pid 559070:tid 559251] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9ezCy1f1FtKC137xsRYgAAAcI"]
[Tue Jul 21 08:58:04.833469 2026] [security2:error] [pid 559070:tid 559287] [client 115.245.198.210:31138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9ezCy1f1FtKC137xsRcgAAAeY"]
[Tue Jul 21 08:58:04.833593 2026] [security2:error] [pid 559070:tid 559287] [client 115.245.198.210:31138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9ezCy1f1FtKC137xsRcgAAAeY"]
[Tue Jul 21 08:58:04.900827 2026] [security2:error] [pid 559070:tid 559282] [client 20.151.10.161:49143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/inputs.php"] [unique_id "al9ezCy1f1FtKC137xsRcwAAAeE"]
[Tue Jul 21 08:58:05.293910 2026] [security2:error] [pid 533360:tid 533501] [client 41.89.234.2:61854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ezXUPuLYrePtEkUc0MgAAAI0"]
[Tue Jul 21 08:58:05.294210 2026] [security2:error] [pid 533360:tid 533501] [client 41.89.234.2:61854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ezXUPuLYrePtEkUc0MgAAAI0"]
[Tue Jul 21 08:58:05.458846 2026] [core:error] [pid 533360:tid 533471] [remote 103.215.74.213:3798] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/app/.env)
[Tue Jul 21 08:58:05.469862 2026] [http2:info] [pid 559070:tid 559305] [client 103.215.74.213:50770] AH10178: h2_stream(559070-971-1327,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:58:05.499805 2026] [core:error] [pid 533360:tid 533406] [remote 103.215.74.213:3798] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/public_html/.env)
[Tue Jul 21 08:58:05.514159 2026] [security2:error] [pid 559070:tid 559102] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/config/database.php"] [unique_id "al9eyyy1f1FtKC137xsRfwAB-B8"]
[Tue Jul 21 08:58:05.514167 2026] [security2:error] [pid 559070:tid 559197] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/wp-config.php"] [unique_id "al9eyyy1f1FtKC137xsRfgAB-H4"]
[Tue Jul 21 08:58:05.514507 2026] [security2:error] [pid 559070:tid 559102] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/application/database.php"] [unique_id "al9eyyy1f1FtKC137xsRgAAB-B8"]
[Tue Jul 21 08:58:05.514507 2026] [core:error] [pid 559070:tid 559148] [remote 103.215.74.213:50770] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/laravel/.env)
[Tue Jul 21 08:58:05.515111 2026] [core:error] [pid 559070:tid 559197] [remote 103.215.74.213:50770] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/api/.env)
[Tue Jul 21 08:58:05.582429 2026] [security2:error] [pid 533360:tid 533579] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9ezXUPuLYrePtEkUc0OgAAANs"]
[Tue Jul 21 08:58:05.583099 2026] [security2:error] [pid 559070:tid 559315] [client 184.154.36.163:50214] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoterplast.com.br"] [uri "/"] [unique_id "al9ezSy1f1FtKC137xsRfAAAAgI"]
[Tue Jul 21 08:58:05.717286 2026] [security2:error] [pid 559070:tid 559206] [client 20.220.225.223:55757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/term.php"] [unique_id "al9ezSy1f1FtKC137xsRigAAAZU"]
[Tue Jul 21 08:58:05.730829 2026] [security2:error] [pid 533360:tid 533494] [client 20.151.10.161:51062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/av.php"] [unique_id "al9ezXUPuLYrePtEkUc0QAAAAIY"]
[Tue Jul 21 08:58:06.044001 2026] [security2:error] [pid 559070:tid 559278] [client 162.241.63.68:45428] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "buyonlinetodayatadiscount.net"] [uri "/wp-cron.php"] [unique_id "al9eziy1f1FtKC137xsRjgAAAd0"]
[Tue Jul 21 08:58:06.230002 2026] [security2:error] [pid 533360:tid 533563] [client 128.127.105.184:59536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9eznUPuLYrePtEkUc0VQAAAMs"]
[Tue Jul 21 08:58:06.230143 2026] [security2:error] [pid 533360:tid 533563] [client 128.127.105.184:59536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9eznUPuLYrePtEkUc0VQAAAMs"]
[Tue Jul 21 08:58:06.284338 2026] [core:error] [pid 533360:tid 533471] [remote 103.215.74.213:3798] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/.env.local)
[Tue Jul 21 08:58:06.350916 2026] [security2:error] [pid 533360:tid 533539] [client 74.249.245.134:27284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/classwithtostring.php"] [unique_id "al9eznUPuLYrePtEkUc0XAAAALM"]
[Tue Jul 21 08:58:06.418437 2026] [core:error] [pid 533360:tid 533406] [remote 103.215.74.213:3798] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/.env)
[Tue Jul 21 08:58:06.422881 2026] [security2:error] [pid 559070:tid 559325] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9eziy1f1FtKC137xsRmwAAAgw"]
[Tue Jul 21 08:58:06.424433 2026] [security2:error] [pid 533360:tid 533608] [client 184.154.36.163:50220] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoterplast.com.br"] [uri "/"] [unique_id "al9eznUPuLYrePtEkUc0VwAAAPg"]
[Tue Jul 21 08:58:06.501133 2026] [core:error] [pid 533360:tid 533471] [remote 103.215.74.213:3798] AH10244: invalid URI path (/icons/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/var/www/html/.env)
[Tue Jul 21 08:58:06.501222 2026] [core:error] [pid 533360:tid 533369] [remote 103.215.74.213:3798] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/.env)
[Tue Jul 21 08:58:06.501626 2026] [core:error] [pid 533360:tid 533380] [remote 103.215.74.213:3798] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/etc/passwd)
[Tue Jul 21 08:58:06.548749 2026] [core:error] [pid 533360:tid 533406] [remote 103.215.74.213:3798] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/etc/passwd)
[Tue Jul 21 08:58:06.573784 2026] [security2:error] [pid 533360:tid 533503] [client 182.189.99.211:48607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eznUPuLYrePtEkUc0aQAAAI8"]
[Tue Jul 21 08:58:06.573897 2026] [security2:error] [pid 533360:tid 533503] [client 182.189.99.211:48607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9eznUPuLYrePtEkUc0aQAAAI8"]
[Tue Jul 21 08:58:06.632755 2026] [core:error] [pid 533360:tid 533380] [remote 103.215.74.213:3798] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/etc/passwd)
[Tue Jul 21 08:58:06.632755 2026] [core:error] [pid 533360:tid 533366] [remote 103.215.74.213:3798] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/srv/www/.env)
[Tue Jul 21 08:58:06.632882 2026] [security2:error] [pid 533360:tid 533420] [remote 103.215.74.213:3798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/var/www/html/wp-config.php"] [unique_id "al9ezXUPuLYrePtEkUc0bAAA4jg"]
[Tue Jul 21 08:58:06.633106 2026] [core:error] [pid 533360:tid 533381] [remote 103.215.74.213:3798] AH10244: invalid URI path (/icons/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/etc/passwd)
[Tue Jul 21 08:58:06.666978 2026] [security2:error] [pid 533360:tid 533551] [client 173.239.214.248:23915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "mbarcondicionados.com.br"] [uri "/wp-login.php"] [unique_id "al9ezHUPuLYrePtEkUc0FQAAAL8"]
[Tue Jul 21 08:58:06.790223 2026] [security2:error] [pid 533360:tid 533474] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eznUPuLYrePtEkUc0eAAAnW4"]
[Tue Jul 21 08:58:06.790426 2026] [security2:error] [pid 533360:tid 533517] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9eznUPuLYrePtEkUc0eAAAnW4"]
[Tue Jul 21 08:58:06.930793 2026] [security2:error] [pid 559070:tid 559262] [client 20.220.225.223:53452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/blue.php"] [unique_id "al9eziy1f1FtKC137xsRrgAAAc0"]
[Tue Jul 21 08:58:06.937264 2026] [security2:error] [pid 559070:tid 559251] [client 20.151.10.161:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/av.php"] [unique_id "al9eziy1f1FtKC137xsRrwAAAcI"]
[Tue Jul 21 08:58:06.954273 2026] [security2:error] [pid 559070:tid 559217] [client 198.44.157.162:53216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9eziy1f1FtKC137xsRsAAAAaA"]
[Tue Jul 21 08:58:06.954388 2026] [security2:error] [pid 559070:tid 559217] [client 198.44.157.162:53216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9eziy1f1FtKC137xsRsAAAAaA"]
[Tue Jul 21 08:58:07.055897 2026] [security2:error] [pid 559070:tid 559266] [client 143.244.57.90:41586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buyonlinetodayatadiscount.net"] [uri "/xmlrpc.php"] [unique_id "al9ezyy1f1FtKC137xsRswAAAdE"]
[Tue Jul 21 08:58:07.056023 2026] [security2:error] [pid 559070:tid 559266] [client 143.244.57.90:41586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "buyonlinetodayatadiscount.net"] [uri "/xmlrpc.php"] [unique_id "al9ezyy1f1FtKC137xsRswAAAdE"]
[Tue Jul 21 08:58:07.136878 2026] [security2:error] [pid 533360:tid 533476] [remote 5.252.52.249:47286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atilafagundes.com.br"] [uri "/wp-login.php"] [unique_id "al9ez3UPuLYrePtEkUc0hAAAvHA"]
[Tue Jul 21 08:58:07.176002 2026] [security2:error] [pid 533360:tid 533577] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9ez3UPuLYrePtEkUc0gQAAANk"]
[Tue Jul 21 08:58:07.229080 2026] [security2:error] [pid 559070:tid 559301] [client 209.141.34.121:62981] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "seguryredes.com.br"] [uri "/"] [unique_id "al9ezyy1f1FtKC137xsRuAAAAfQ"]
[Tue Jul 21 08:58:07.350754 2026] [security2:error] [pid 559070:tid 559236] [client 74.249.245.134:27265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/bless.php"] [unique_id "al9ezyy1f1FtKC137xsRuQAAAbM"]
[Tue Jul 21 08:58:07.356146 2026] [core:error] [pid 559070:tid 559148] [remote 103.215.74.213:50770] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/var/www/html/.env.production)
[Tue Jul 21 08:58:07.417310 2026] [security2:error] [pid 533360:tid 533406] [remote 103.215.74.213:3798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.php~"] [unique_id "al9eznUPuLYrePtEkUc0igAA4io"]
[Tue Jul 21 08:58:07.418300 2026] [security2:error] [pid 533360:tid 533406] [remote 103.215.74.213:3798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.php.bak"] [unique_id "al9eznUPuLYrePtEkUc0iwAA4io"]
[Tue Jul 21 08:58:07.450409 2026] [http2:info] [pid 559070:tid 559305] [client 103.215.74.213:50770] AH10178: h2_stream(559070-971-1571,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:58:07.519203 2026] [security2:error] [pid 533360:tid 533574] [client 103.59.44.113:48858] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "houseincorporacoes.com"] [uri "/wp-comments-post.php"] [unique_id "al9ez3UPuLYrePtEkUc0hgAAANY"]
[Tue Jul 21 08:58:07.537378 2026] [core:error] [pid 559070:tid 559148] [remote 103.215.74.213:50770] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/var/www/.env)
[Tue Jul 21 08:58:07.538004 2026] [core:error] [pid 559070:tid 559174] [remote 103.215.74.213:50770] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/var/www/html/.env)
[Tue Jul 21 08:58:07.538584 2026] [core:error] [pid 559070:tid 559162] [remote 103.215.74.213:50770] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/home/admin/web/public_html/.env)
[Tue Jul 21 08:58:07.576022 2026] [core:error] [pid 559070:tid 559160] [remote 103.215.74.213:50770] AH10244: invalid URI path (/cgi-bin/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/%%32%65/opt/app/.env)
[Tue Jul 21 08:58:07.742456 2026] [security2:error] [pid 533360:tid 533603] [client 209.141.34.121:63039] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "seguryredes.com.br"] [uri "/"] [unique_id "al9ez3UPuLYrePtEkUc0kAAAAPM"]
[Tue Jul 21 08:58:07.782236 2026] [security2:error] [pid 533360:tid 533596] [client 152.42.246.10:63744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "piskefotografia.com"] [uri "/license.txt"] [unique_id "al9ez3UPuLYrePtEkUc0kgAAAOw"]
[Tue Jul 21 08:58:07.912277 2026] [security2:error] [pid 533360:tid 533610] [client 59.95.197.55:59549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ez3UPuLYrePtEkUc0lQAAAPo"]
[Tue Jul 21 08:58:07.912848 2026] [security2:error] [pid 533360:tid 533610] [client 59.95.197.55:59549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ez3UPuLYrePtEkUc0lQAAAPo"]
[Tue Jul 21 08:58:07.935826 2026] [security2:error] [pid 559070:tid 559101] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ezyy1f1FtKC137xsRzAABmR4"]
[Tue Jul 21 08:58:07.935938 2026] [security2:error] [pid 559070:tid 559210] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9ezyy1f1FtKC137xsRzAABmR4"]
[Tue Jul 21 08:58:08.022393 2026] [security2:error] [pid 533360:tid 533574] [client 103.59.44.113:48858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "houseincorporacoes.com"] [uri "/wp-comments-post.php"] [unique_id "al9ez3UPuLYrePtEkUc0hgAAANY"]
[Tue Jul 21 08:58:08.165326 2026] [security2:error] [pid 559070:tid 559237] [client 65.21.113.253:54506] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9e0Cy1f1FtKC137xsR0gAAAbQ"]
[Tue Jul 21 08:58:08.175253 2026] [autoindex:error] [pid 559070:tid 559286] [client 185.93.44.121:0] AH01276: Cannot serve directory /home2/senatr95/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://aio.online
[Tue Jul 21 08:58:08.235549 2026] [security2:error] [pid 533360:tid 533552] [client 74.249.245.134:27310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/storage/index.php"] [unique_id "al9e0HUPuLYrePtEkUc0oQAAAMA"]
[Tue Jul 21 08:58:08.433940 2026] [security2:error] [pid 559070:tid 559224] [client 172.236.244.218:58216] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "sogastro.com.br"] [uri "/wp-json/batch/v1"] [unique_id "al9e0Cy1f1FtKC137xsR2QAAAac"]
[Tue Jul 21 08:58:08.566336 2026] [security2:error] [pid 559070:tid 559203] [client 5.38.115.39:62128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9e0Cy1f1FtKC137xsR3wAAAZI"]
[Tue Jul 21 08:58:08.566510 2026] [security2:error] [pid 559070:tid 559203] [client 5.38.115.39:62128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9e0Cy1f1FtKC137xsR3wAAAZI"]
[Tue Jul 21 08:58:08.599855 2026] [security2:error] [pid 559070:tid 559321] [client 172.236.244.218:58216] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "sogastro.com.br"] [uri "/"] [unique_id "al9e0Cy1f1FtKC137xsR4QAAAgg"]
[Tue Jul 21 08:58:08.633876 2026] [authz_core:error] [pid 559070:tid 559160] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/wp-content/uploads/index.php
[Tue Jul 21 08:58:08.635033 2026] [security2:error] [pid 559070:tid 559148] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9ezyy1f1FtKC137xsR7AAB-E0"]
[Tue Jul 21 08:58:08.665252 2026] [security2:error] [pid 559070:tid 559312] [client 103.59.206.240:31192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e0Cy1f1FtKC137xsR7wAAAf8"]
[Tue Jul 21 08:58:08.665355 2026] [security2:error] [pid 559070:tid 559312] [client 103.59.206.240:31192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e0Cy1f1FtKC137xsR7wAAAf8"]
[Tue Jul 21 08:58:09.152036 2026] [security2:error] [pid 559070:tid 559225] [client 194.99.104.35:40258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9e0Sy1f1FtKC137xsR-wAAAag"]
[Tue Jul 21 08:58:09.152131 2026] [security2:error] [pid 559070:tid 559225] [client 194.99.104.35:40258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9e0Sy1f1FtKC137xsR-wAAAag"]
[Tue Jul 21 08:58:09.230796 2026] [security2:error] [pid 559070:tid 559266] [client 65.21.113.253:41010] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9e0Cy1f1FtKC137xsR9gAAAdE"]
[Tue Jul 21 08:58:09.247832 2026] [security2:error] [pid 533360:tid 533539] [client 74.249.245.134:27271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/g.php"] [unique_id "al9e0XUPuLYrePtEkUc0vgAAALM"]
[Tue Jul 21 08:58:09.281042 2026] [security2:error] [pid 559070:tid 559148] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/configuration.php.copy"] [unique_id "al9ezyy1f1FtKC137xsR_QAB-E0"]
[Tue Jul 21 08:58:09.283560 2026] [security2:error] [pid 559070:tid 559148] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/configuration.php-backup"] [unique_id "al9ezyy1f1FtKC137xsSAAAB-E0"]
[Tue Jul 21 08:58:09.309995 2026] [security2:error] [pid 533360:tid 533599] [client 20.151.10.161:49148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/classwithtostring.php"] [unique_id "al9e0XUPuLYrePtEkUc0wAAAAO8"]
[Tue Jul 21 08:58:09.450001 2026] [security2:error] [pid 559070:tid 559148] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/adminer.php"] [unique_id "al9e0Cy1f1FtKC137xsSBgAB-E0"]
[Tue Jul 21 08:58:09.453976 2026] [access_compat:error] [pid 559070:tid 559160] [remote 103.215.74.213:50770] AH01797: client denied by server configuration: /home1/mili1165/public_html/server-status
[Tue Jul 21 08:58:09.581231 2026] [security2:error] [pid 559070:tid 559113] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9e0Sy1f1FtKC137xsSFgAB-Co"]
[Tue Jul 21 08:58:09.581552 2026] [security2:error] [pid 559070:tid 559076] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/configuration.php.bkp"] [unique_id "al9e0Sy1f1FtKC137xsSGAAB-AU"]
[Tue Jul 21 08:58:09.581626 2026] [security2:error] [pid 559070:tid 559164] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.php.orig"] [unique_id "al9e0Sy1f1FtKC137xsSGgAB-F0"]
[Tue Jul 21 08:58:09.582154 2026] [authz_core:error] [pid 559070:tid 559094] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/error_log
[Tue Jul 21 08:58:09.582768 2026] [security2:error] [pid 559070:tid 559148] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/dup-installer/main.installer.php"] [unique_id "al9e0Sy1f1FtKC137xsSHgAB-E0"]
[Tue Jul 21 08:58:09.583575 2026] [security2:error] [pid 559070:tid 559094] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wp-content/w3tc-config/master.php"] [unique_id "al9e0Sy1f1FtKC137xsSIAAB-Bc"]
[Tue Jul 21 08:58:09.583907 2026] [security2:error] [pid 559070:tid 559094] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.php.save"] [unique_id "al9e0Sy1f1FtKC137xsSIQAB-Bc"]
[Tue Jul 21 08:58:09.584184 2026] [security2:error] [pid 559070:tid 559094] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wp-content/plugins/w3-total-cache/pub/opt/detect-post-info.php"] [unique_id "al9e0Sy1f1FtKC137xsSIgAB-Bc"]
[Tue Jul 21 08:58:09.584423 2026] [security2:error] [pid 559070:tid 559094] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.php.swp"] [unique_id "al9e0Sy1f1FtKC137xsSIwAB-Bc"]
[Tue Jul 21 08:58:09.584735 2026] [security2:error] [pid 559070:tid 559094] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.php.tmp"] [unique_id "al9e0Sy1f1FtKC137xsSJAAB-Bc"]
[Tue Jul 21 08:58:09.585113 2026] [security2:error] [pid 559070:tid 559094] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9e0Sy1f1FtKC137xsSJQAB-Bc"]
[Tue Jul 21 08:58:09.585428 2026] [security2:error] [pid 559070:tid 559094] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/configuration.php.1"] [unique_id "al9e0Sy1f1FtKC137xsSJgAB-Bc"]
[Tue Jul 21 08:58:09.585743 2026] [security2:error] [pid 559070:tid 559094] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.php.old"] [unique_id "al9e0Sy1f1FtKC137xsSJwAB-Bc"]
[Tue Jul 21 08:58:09.588443 2026] [security2:error] [pid 559070:tid 559160] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.php~"] [unique_id "al9e0Sy1f1FtKC137xsSKgAB-Fk"]
[Tue Jul 21 08:58:09.589148 2026] [security2:error] [pid 559070:tid 559160] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.php.backup"] [unique_id "al9e0Sy1f1FtKC137xsSKwAB-Fk"]
[Tue Jul 21 08:58:09.590526 2026] [security2:error] [pid 533360:tid 533564] [client 20.220.225.223:53462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/wp-signup.php"] [unique_id "al9e0XUPuLYrePtEkUc0yAAAAMw"]
[Tue Jul 21 08:58:09.596517 2026] [http2:info] [pid 559070:tid 559305] [client 103.215.74.213:50770] AH10178: h2_stream(559070-971-1685,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:58:09.606795 2026] [security2:error] [pid 559070:tid 559121] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.php.bak"] [unique_id "al9e0Sy1f1FtKC137xsSLQAB-DI"]
[Tue Jul 21 08:58:09.608387 2026] [security2:error] [pid 559070:tid 559141] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.php-backup"] [unique_id "al9e0Sy1f1FtKC137xsSMAAB-EY"]
[Tue Jul 21 08:58:09.824091 2026] [security2:error] [pid 559070:tid 559307] [client 103.59.44.113:48962] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "houseincorporacoes.com"] [uri "/wp-comments-post.php"] [unique_id "al9e0Sy1f1FtKC137xsSOwAAAfo"]
[Tue Jul 21 08:58:09.913310 2026] [security2:error] [pid 559070:tid 559307] [client 103.59.44.113:48962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "houseincorporacoes.com"] [uri "/wp-comments-post.php"] [unique_id "al9e0Sy1f1FtKC137xsSOwAAAfo"]
[Tue Jul 21 08:58:10.164359 2026] [security2:error] [pid 533360:tid 533502] [client 69.165.75.222:61759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.75.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "premiercservices.com"] [uri "/index.php"] [unique_id "al9e0nUPuLYrePtEkUc00wAAAI4"], referer: https://premiercservices.com
[Tue Jul 21 08:58:10.220320 2026] [security2:error] [pid 533360:tid 533614] [client 114.198.138.124:57320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9e0nUPuLYrePtEkUc01AAAAP4"]
[Tue Jul 21 08:58:10.222080 2026] [security2:error] [pid 533360:tid 533614] [client 114.198.138.124:57320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9e0nUPuLYrePtEkUc01AAAAP4"]
[Tue Jul 21 08:58:10.265146 2026] [security2:error] [pid 559070:tid 559232] [client 74.249.245.134:27287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/nf.php"] [unique_id "al9e0iy1f1FtKC137xsSdAAAAa8"]
[Tue Jul 21 08:58:10.418544 2026] [security2:error] [pid 559070:tid 559171] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.php.bkp"] [unique_id "al9e0Sy1f1FtKC137xsSfAAB-GQ"]
[Tue Jul 21 08:58:10.419455 2026] [security2:error] [pid 559070:tid 559171] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.php.bak"] [unique_id "al9e0Sy1f1FtKC137xsSfgAB-GQ"]
[Tue Jul 21 08:58:10.419791 2026] [security2:error] [pid 559070:tid 559181] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.php.copy"] [unique_id "al9e0Sy1f1FtKC137xsSfwAB-G4"]
[Tue Jul 21 08:58:10.419926 2026] [security2:error] [pid 559070:tid 559126] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.php.1"] [unique_id "al9e0Sy1f1FtKC137xsSfQAB-Dc"]
[Tue Jul 21 08:58:10.420595 2026] [security2:error] [pid 559070:tid 559171] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.php.old"] [unique_id "al9e0Sy1f1FtKC137xsSggAB-GQ"]
[Tue Jul 21 08:58:10.420911 2026] [security2:error] [pid 559070:tid 559083] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.php.orig"] [unique_id "al9e0Sy1f1FtKC137xsSgQAB-Aw"]
[Tue Jul 21 08:58:10.420941 2026] [security2:error] [pid 559070:tid 559088] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wp-links-opml.php"] [unique_id "al9e0Sy1f1FtKC137xsShAAB-BE"]
[Tue Jul 21 08:58:10.421042 2026] [security2:error] [pid 559070:tid 559154] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.php~"] [unique_id "al9e0Sy1f1FtKC137xsShQAB-FM"]
[Tue Jul 21 08:58:10.421453 2026] [security2:error] [pid 559070:tid 559144] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.php.save"] [unique_id "al9e0iy1f1FtKC137xsShwAB-Ek"]
[Tue Jul 21 08:58:10.421485 2026] [security2:error] [pid 559070:tid 559088] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.php.swp"] [unique_id "al9e0iy1f1FtKC137xsShgAB-BE"]
[Tue Jul 21 08:58:10.421623 2026] [security2:error] [pid 559070:tid 559114] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/lib/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9e0iy1f1FtKC137xsSiQAB-Cs"]
[Tue Jul 21 08:58:10.421836 2026] [security2:error] [pid 559070:tid 559144] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.php.tmp"] [unique_id "al9e0iy1f1FtKC137xsSjQAB-Ek"]
[Tue Jul 21 08:58:10.421870 2026] [access_compat:error] [pid 559070:tid 559154] [remote 103.215.74.213:50770] AH01797: client denied by server configuration: /home1/mili1165/public_html/server-status
[Tue Jul 21 08:58:10.422071 2026] [security2:error] [pid 559070:tid 559170] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.php.copy"] [unique_id "al9e0iy1f1FtKC137xsSkAAB-GM"]
[Tue Jul 21 08:58:10.422397 2026] [authz_core:error] [pid 559070:tid 559142] [remote 103.215.74.213:50770] AH01630: client denied by server configuration: /home1/mili1165/public_html/error_log
[Tue Jul 21 08:58:10.423609 2026] [security2:error] [pid 559070:tid 559088] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.php.backup"] [unique_id "al9e0iy1f1FtKC137xsSjgAB-BE"]
[Tue Jul 21 08:58:10.423896 2026] [security2:error] [pid 559070:tid 559083] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.php.1"] [unique_id "al9e0iy1f1FtKC137xsSkgAB-Aw"]
[Tue Jul 21 08:58:10.423992 2026] [security2:error] [pid 559070:tid 559133] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9e0iy1f1FtKC137xsSkQAB-D4"]
[Tue Jul 21 08:58:10.424087 2026] [security2:error] [pid 559070:tid 559093] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.inc.php.bak"] [unique_id "al9e0iy1f1FtKC137xsSkwAB-BY"]
[Tue Jul 21 08:58:10.424231 2026] [security2:error] [pid 559070:tid 559170] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.php.bkp"] [unique_id "al9e0iy1f1FtKC137xsSlAAB-GM"]
[Tue Jul 21 08:58:10.424273 2026] [security2:error] [pid 559070:tid 559159] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.inc.php.old"] [unique_id "al9e0iy1f1FtKC137xsSlgAB-Fg"]
[Tue Jul 21 08:58:10.424820 2026] [security2:error] [pid 559070:tid 559098] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.inc.php.save"] [unique_id "al9e0iy1f1FtKC137xsSlQAB-Bs"]
[Tue Jul 21 08:58:10.425952 2026] [security2:error] [pid 559070:tid 559103] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.inc.php~"] [unique_id "al9e0iy1f1FtKC137xsSmAAB-CA"]
[Tue Jul 21 08:58:10.426038 2026] [security2:error] [pid 559070:tid 559132] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.inc.php.orig"] [unique_id "al9e0iy1f1FtKC137xsSmQAB-D0"]
[Tue Jul 21 08:58:10.426115 2026] [security2:error] [pid 559070:tid 559156] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.php-backup"] [unique_id "al9e0iy1f1FtKC137xsSjAAB-FU"]
[Tue Jul 21 08:58:10.493009 2026] [security2:error] [pid 533360:tid 533402] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e0nUPuLYrePtEkUc03AAA1yY"]
[Tue Jul 21 08:58:10.493152 2026] [security2:error] [pid 533360:tid 533575] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e0nUPuLYrePtEkUc03AAA1yY"]
[Tue Jul 21 08:58:10.754303 2026] [security2:error] [pid 559070:tid 559314] [client 198.44.157.162:53906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9e0iy1f1FtKC137xsSqQAAAgE"]
[Tue Jul 21 08:58:10.754438 2026] [security2:error] [pid 559070:tid 559314] [client 198.44.157.162:53906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9e0iy1f1FtKC137xsSqQAAAgE"]
[Tue Jul 21 08:58:10.893385 2026] [security2:error] [pid 533360:tid 533605] [client 168.167.81.163:62883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9e0nUPuLYrePtEkUc05gAAAPU"]
[Tue Jul 21 08:58:10.893506 2026] [security2:error] [pid 533360:tid 533605] [client 168.167.81.163:62883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9e0nUPuLYrePtEkUc05gAAAPU"]
[Tue Jul 21 08:58:10.953249 2026] [http2:info] [pid 559070:tid 559305] [client 103.215.74.213:50770] AH10178: h2_stream(559070-971-1747,IDLE): Request pseudo header exceeds LimitRequestFieldSize: :path
[Tue Jul 21 08:58:11.062545 2026] [security2:error] [pid 559070:tid 559206] [client 113.22.144.139:62222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e0yy1f1FtKC137xsSsAAAAZU"]
[Tue Jul 21 08:58:11.063190 2026] [security2:error] [pid 559070:tid 559206] [client 113.22.144.139:62222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e0yy1f1FtKC137xsSsAAAAZU"]
[Tue Jul 21 08:58:11.369917 2026] [security2:error] [pid 533360:tid 533589] [client 20.220.225.223:60371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/csa.php"] [unique_id "al9e03UPuLYrePtEkUc07wAAAOU"]
[Tue Jul 21 08:58:11.434048 2026] [security2:error] [pid 559070:tid 559114] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.inc.php.swp"] [unique_id "al9e0iy1f1FtKC137xsSuAAB-Cs"]
[Tue Jul 21 08:58:11.434621 2026] [security2:error] [pid 559070:tid 559140] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.inc.php.tmp"] [unique_id "al9e0iy1f1FtKC137xsSuQAB-EU"]
[Tue Jul 21 08:58:11.434977 2026] [security2:error] [pid 559070:tid 559140] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.inc.php.copy"] [unique_id "al9e0iy1f1FtKC137xsSuwAB-EU"]
[Tue Jul 21 08:58:11.435200 2026] [security2:error] [pid 559070:tid 559196] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.inc.php.backup"] [unique_id "al9e0iy1f1FtKC137xsSugAB-H0"]
[Tue Jul 21 08:58:11.435274 2026] [security2:error] [pid 559070:tid 559140] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.inc.php-backup"] [unique_id "al9e0iy1f1FtKC137xsSvQAB-EU"]
[Tue Jul 21 08:58:11.435610 2026] [security2:error] [pid 559070:tid 559114] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.inc.php.bkp"] [unique_id "al9e0iy1f1FtKC137xsSvAAB-Cs"]
[Tue Jul 21 08:58:11.435845 2026] [security2:error] [pid 559070:tid 559140] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local.php~"] [unique_id "al9e0iy1f1FtKC137xsSvgAB-EU"]
[Tue Jul 21 08:58:11.436126 2026] [security2:error] [pid 559070:tid 559153] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config.inc.php.1"] [unique_id "al9e0iy1f1FtKC137xsSwQAB-FI"]
[Tue Jul 21 08:58:11.436159 2026] [security2:error] [pid 559070:tid 559183] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local.php.bak"] [unique_id "al9e0iy1f1FtKC137xsSwwAB-HA"]
[Tue Jul 21 08:58:11.436178 2026] [security2:error] [pid 559070:tid 559140] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local.php.tmp"] [unique_id "al9e0iy1f1FtKC137xsSxQAB-EU"]
[Tue Jul 21 08:58:11.436222 2026] [security2:error] [pid 559070:tid 559150] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local.php.old"] [unique_id "al9e0iy1f1FtKC137xsSwAAB-E8"]
[Tue Jul 21 08:58:11.436255 2026] [security2:error] [pid 559070:tid 559081] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/laravel/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9e0iy1f1FtKC137xsSvwAB-Ao"]
[Tue Jul 21 08:58:11.436281 2026] [security2:error] [pid 559070:tid 559092] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local.php.orig"] [unique_id "al9e0iy1f1FtKC137xsSwgAB-BU"]
[Tue Jul 21 08:58:11.436305 2026] [security2:error] [pid 559070:tid 559114] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local.php.save"] [unique_id "al9e0iy1f1FtKC137xsSxAAB-Cs"]
[Tue Jul 21 08:58:11.436528 2026] [security2:error] [pid 559070:tid 559153] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local.php-backup"] [unique_id "al9e0iy1f1FtKC137xsSxwAB-FI"]
[Tue Jul 21 08:58:11.436622 2026] [security2:error] [pid 559070:tid 559188] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local.php.copy"] [unique_id "al9e0iy1f1FtKC137xsSywAB-HU"]
[Tue Jul 21 08:58:11.436648 2026] [security2:error] [pid 559070:tid 559081] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local.php.backup"] [unique_id "al9e0iy1f1FtKC137xsSyQAB-Ao"]
[Tue Jul 21 08:58:11.436676 2026] [security2:error] [pid 559070:tid 559140] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local.php.bkp"] [unique_id "al9e0iy1f1FtKC137xsSyAAB-EU"]
[Tue Jul 21 08:58:11.436723 2026] [security2:error] [pid 559070:tid 559150] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local.php.1"] [unique_id "al9e0iy1f1FtKC137xsSzAAB-E8"]
[Tue Jul 21 08:58:11.437249 2026] [security2:error] [pid 559070:tid 559092] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local.php.swp"] [unique_id "al9e0iy1f1FtKC137xsSygAB-BU"]
[Tue Jul 21 08:58:11.438621 2026] [security2:error] [pid 559070:tid 559153] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.py.bak"] [unique_id "al9e0iy1f1FtKC137xsSzQAB-FI"]
[Tue Jul 21 08:58:11.513702 2026] [security2:error] [pid 559070:tid 559227] [client 74.249.245.134:27220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/xda.php"] [unique_id "al9e0yy1f1FtKC137xsSzgAAAao"]
[Tue Jul 21 08:58:11.656784 2026] [security2:error] [pid 559070:tid 559316] [client 103.59.44.113:49022] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "houseincorporacoes.com"] [uri "/wp-comments-post.php"] [unique_id "al9e0yy1f1FtKC137xsS2QAAAgM"]
[Tue Jul 21 08:58:11.748953 2026] [security2:error] [pid 559070:tid 559316] [client 103.59.44.113:49022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "houseincorporacoes.com"] [uri "/wp-comments-post.php"] [unique_id "al9e0yy1f1FtKC137xsS2QAAAgM"]
[Tue Jul 21 08:58:11.996626 2026] [security2:error] [pid 559070:tid 559071] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.py.old"] [unique_id "al9e0yy1f1FtKC137xsS3wABoQA"]
[Tue Jul 21 08:58:11.997389 2026] [security2:error] [pid 559070:tid 559082] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9e0yy1f1FtKC137xsS4QAB-Qs"]
[Tue Jul 21 08:58:11.997481 2026] [security2:error] [pid 559070:tid 559306] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9e0yy1f1FtKC137xsS4QAB-Qs"]
[Tue Jul 21 08:58:11.998312 2026] [security2:error] [pid 559070:tid 559078] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.py~"] [unique_id "al9e0yy1f1FtKC137xsS4AABoQc"]
[Tue Jul 21 08:58:12.001351 2026] [security2:error] [pid 559070:tid 559186] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/www/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9e1Cy1f1FtKC137xsS6AABknM"]
[Tue Jul 21 08:58:12.002196 2026] [security2:error] [pid 559070:tid 559099] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.py.copy"] [unique_id "al9e1Cy1f1FtKC137xsS5QABkhw"]
[Tue Jul 21 08:58:12.002373 2026] [security2:error] [pid 559070:tid 559131] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.py.backup"] [unique_id "al9e1Cy1f1FtKC137xsS5AABkjw"]
[Tue Jul 21 08:58:12.015356 2026] [security2:error] [pid 559070:tid 559072] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local_settings.py.orig"] [unique_id "al9e1Cy1f1FtKC137xsS7gABkgE"]
[Tue Jul 21 08:58:12.015486 2026] [security2:error] [pid 559070:tid 559174] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local_settings.py.bak"] [unique_id "al9e1Cy1f1FtKC137xsS6QABkmc"]
[Tue Jul 21 08:58:12.015491 2026] [security2:error] [pid 559070:tid 559193] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.py.swp"] [unique_id "al9e1Cy1f1FtKC137xsS6gABkno"]
[Tue Jul 21 08:58:12.015523 2026] [security2:error] [pid 559070:tid 559129] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local_settings.py.old"] [unique_id "al9e1Cy1f1FtKC137xsS6wABkjo"]
[Tue Jul 21 08:58:12.015699 2026] [security2:error] [pid 559070:tid 559147] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local_settings.py~"] [unique_id "al9e1Cy1f1FtKC137xsS7QABkkw"]
[Tue Jul 21 08:58:12.018318 2026] [security2:error] [pid 559070:tid 559120] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local_settings.py.swp"] [unique_id "al9e1Cy1f1FtKC137xsS8AABkjE"]
[Tue Jul 21 08:58:12.020475 2026] [security2:error] [pid 559070:tid 559122] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/settings.py.orig"] [unique_id "al9e1Cy1f1FtKC137xsS8QABkjM"]
[Tue Jul 21 08:58:12.021864 2026] [security2:error] [pid 559070:tid 559108] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local_settings.py.backup"] [unique_id "al9e1Cy1f1FtKC137xsS9AABkiU"]
[Tue Jul 21 08:58:12.102033 2026] [security2:error] [pid 559070:tid 559209] [client 20.220.225.223:34203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/dp.php"] [unique_id "al9e1Cy1f1FtKC137xsS9QAAAZg"]
[Tue Jul 21 08:58:12.113928 2026] [security2:error] [pid 559070:tid 559233] [client 20.151.10.161:49056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9e1Cy1f1FtKC137xsS9gAAAbA"]
[Tue Jul 21 08:58:12.488732 2026] [security2:error] [pid 559070:tid 559096] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/local_settings.py.copy"] [unique_id "al9e1Cy1f1FtKC137xsTBQABthk"]
[Tue Jul 21 08:58:12.498858 2026] [security2:error] [pid 559070:tid 559181] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/yii/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9e1Cy1f1FtKC137xsTBwABtW4"]
[Tue Jul 21 08:58:12.512326 2026] [security2:error] [pid 559070:tid 559185] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wsgi.py~"] [unique_id "al9e1Cy1f1FtKC137xsTCQABtXI"]
[Tue Jul 21 08:58:12.530587 2026] [security2:error] [pid 559070:tid 559110] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wsgi.py.orig"] [unique_id "al9e1Cy1f1FtKC137xsTCwABtSc"]
[Tue Jul 21 08:58:12.530587 2026] [security2:error] [pid 559070:tid 559074] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wsgi.py.bak"] [unique_id "al9e1Cy1f1FtKC137xsTEAABtQM"]
[Tue Jul 21 08:58:12.530844 2026] [security2:error] [pid 559070:tid 559073] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wsgi.py.old"] [unique_id "al9e1Cy1f1FtKC137xsTDwABtQI"]
[Tue Jul 21 08:58:12.530848 2026] [security2:error] [pid 559070:tid 559126] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wsgi.py.swp"] [unique_id "al9e1Cy1f1FtKC137xsTDAABtTc"]
[Tue Jul 21 08:58:12.530921 2026] [security2:error] [pid 559070:tid 559137] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wsgi.py.backup"] [unique_id "al9e1Cy1f1FtKC137xsTEQABtUI"]
[Tue Jul 21 08:58:12.811880 2026] [security2:error] [pid 559070:tid 559088] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/wsgi.py.copy"] [unique_id "al9e1Cy1f1FtKC137xsTHAAByxE"]
[Tue Jul 21 08:58:12.864165 2026] [security2:error] [pid 559070:tid 559083] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.yml.bak"] [unique_id "al9e1Cy1f1FtKC137xsTHgABogw"]
[Tue Jul 21 08:58:12.865720 2026] [security2:error] [pid 559070:tid 559133] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.yml~"] [unique_id "al9e1Cy1f1FtKC137xsTHwABoj4"]
[Tue Jul 21 08:58:12.890336 2026] [security2:error] [pid 559070:tid 559098] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.yml.orig"] [unique_id "al9e1Cy1f1FtKC137xsTIwABohs"]
[Tue Jul 21 08:58:12.890336 2026] [security2:error] [pid 559070:tid 559159] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.yml.old"] [unique_id "al9e1Cy1f1FtKC137xsTIgABolg"]
[Tue Jul 21 08:58:12.943632 2026] [security2:error] [pid 559070:tid 559103] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9e1Cy1f1FtKC137xsTJAABoiA"]
[Tue Jul 21 08:58:12.945169 2026] [security2:error] [pid 559070:tid 559156] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.yml.swp"] [unique_id "al9e1Cy1f1FtKC137xsTJgABolU"]
[Tue Jul 21 08:58:12.985153 2026] [security2:error] [pid 559070:tid 559234] [client 74.249.245.134:27274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/shell.php"] [unique_id "al9e1Cy1f1FtKC137xsTKQAAAbE"]
[Tue Jul 21 08:58:12.993166 2026] [security2:error] [pid 559070:tid 559086] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.yml.backup"] [unique_id "al9e1Cy1f1FtKC137xsTKgABog8"]
[Tue Jul 21 08:58:12.993175 2026] [security2:error] [pid 559070:tid 559194] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.copy$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1269"] [id "390586"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .copy)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/database.yml.copy"] [unique_id "al9e1Cy1f1FtKC137xsTKwABons"]
[Tue Jul 21 08:58:13.041014 2026] [security2:error] [pid 559070:tid 559118] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/zend/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al9e1Sy1f1FtKC137xsTLwABoi8"]
[Tue Jul 21 08:58:13.074050 2026] [security2:error] [pid 559070:tid 559158] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/secrets.yml.bak"] [unique_id "al9e1Sy1f1FtKC137xsTMAABolc"]
[Tue Jul 21 08:58:13.096321 2026] [security2:error] [pid 559070:tid 559145] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/secrets.yml.old"] [unique_id "al9e1Sy1f1FtKC137xsTMgABoko"]
[Tue Jul 21 08:58:13.096321 2026] [security2:error] [pid 559070:tid 559113] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.orig$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1266"] [id "390584"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .orig)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/secrets.yml.orig"] [unique_id "al9e1Sy1f1FtKC137xsTMwABoio"]
[Tue Jul 21 08:58:13.097012 2026] [security2:error] [pid 559070:tid 559121] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[a-z0-9]~$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1257"] [id "390581"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup file (disable this rule if you require access to files that end with a tilde)"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/secrets.yml~"] [unique_id "al9e1Sy1f1FtKC137xsTNAABojI"]
[Tue Jul 21 08:58:13.118927 2026] [security2:error] [pid 559070:tid 559302] [client 65.21.113.253:54506] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9e1Sy1f1FtKC137xsTNgAAAfU"]
[Tue Jul 21 08:58:13.358022 2026] [security2:error] [pid 559070:tid 559094] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9e1Sy1f1FtKC137xsTPwABohc"]
[Tue Jul 21 08:58:13.499682 2026] [security2:error] [pid 559070:tid 559259] [client 103.59.44.113:49114] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "houseincorporacoes.com"] [uri "/wp-comments-post.php"] [unique_id "al9e1Sy1f1FtKC137xsTQQAAAco"]
[Tue Jul 21 08:58:13.536107 2026] [security2:error] [pid 559070:tid 559245] [client 20.220.225.223:53451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/min.php"] [unique_id "al9e1Sy1f1FtKC137xsTQgAAAbw"]
[Tue Jul 21 08:58:13.590086 2026] [security2:error] [pid 559070:tid 559259] [client 103.59.44.113:49114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "429"] [hostname "houseincorporacoes.com"] [uri "/wp-comments-post.php"] [unique_id "al9e1Sy1f1FtKC137xsTQQAAAco"]
[Tue Jul 21 08:58:13.954287 2026] [security2:error] [pid 559070:tid 559114] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9e1Sy1f1FtKC137xsTZgACDCs"]
[Tue Jul 21 08:58:13.963332 2026] [security2:error] [pid 559070:tid 559213] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9e1Sy1f1FtKC137xsTWgABnGU"]
[Tue Jul 21 08:58:14.173317 2026] [security2:error] [pid 559070:tid 559314] [client 65.21.113.253:44444] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9e1Sy1f1FtKC137xsTWAAAAgE"]
[Tue Jul 21 08:58:14.252880 2026] [security2:error] [pid 559070:tid 559234] [client 74.249.245.134:27292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/3.php"] [unique_id "al9e1iy1f1FtKC137xsTbQAAAbE"]
[Tue Jul 21 08:58:14.447350 2026] [security2:error] [pid 559070:tid 559327] [client 117.214.78.59:54639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9e1iy1f1FtKC137xsTtAAAAg4"]
[Tue Jul 21 08:58:14.447995 2026] [security2:error] [pid 559070:tid 559327] [client 117.214.78.59:54639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9e1iy1f1FtKC137xsTtAAAAg4"]
[Tue Jul 21 08:58:14.587373 2026] [security2:error] [pid 559070:tid 559154] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9e1iy1f1FtKC137xsTuwACCVM"]
[Tue Jul 21 08:58:14.724754 2026] [security2:error] [pid 559070:tid 559203] [client 20.220.225.223:34260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/ez.php"] [unique_id "al9e1iy1f1FtKC137xsTwAAAAZI"]
[Tue Jul 21 08:58:15.081942 2026] [security2:error] [pid 559070:tid 559289] [client 20.151.10.161:49058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-blog.php"] [unique_id "al9e1yy1f1FtKC137xsTyQAAAeg"]
[Tue Jul 21 08:58:15.192494 2026] [security2:error] [pid 559070:tid 559156] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9e1yy1f1FtKC137xsT0AABtFU"]
[Tue Jul 21 08:58:15.231010 2026] [security2:error] [pid 559070:tid 559313] [client 117.210.181.114:22242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.181.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9e1yy1f1FtKC137xsT0gAAAgA"]
[Tue Jul 21 08:58:15.231136 2026] [security2:error] [pid 559070:tid 559313] [client 117.210.181.114:22242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9e1yy1f1FtKC137xsT0gAAAgA"]
[Tue Jul 21 08:58:15.284938 2026] [security2:error] [pid 533360:tid 533506] [client 74.249.245.134:27312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/mds.php"] [unique_id "al9e13UPuLYrePtEkUc1NgAAAJI"]
[Tue Jul 21 08:58:15.342705 2026] [security2:error] [pid 559070:tid 559118] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9e1yy1f1FtKC137xsT1AABrS8"]
[Tue Jul 21 08:58:15.532278 2026] [security2:error] [pid 533360:tid 533552] [client 20.220.225.223:34287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/fz.php"] [unique_id "al9e13UPuLYrePtEkUc1OgAAAMA"]
[Tue Jul 21 08:58:15.625240 2026] [security2:error] [pid 559070:tid 559145] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9e1yy1f1FtKC137xsT2AABp0o"]
[Tue Jul 21 08:58:15.808430 2026] [security2:error] [pid 559070:tid 559090] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9e1yy1f1FtKC137xsT3AABsBM"]
[Tue Jul 21 08:58:15.901379 2026] [security2:error] [pid 533360:tid 533517] [client 41.89.234.2:62320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e13UPuLYrePtEkUc1SQAAAJ0"]
[Tue Jul 21 08:58:15.901487 2026] [security2:error] [pid 533360:tid 533517] [client 41.89.234.2:62320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e13UPuLYrePtEkUc1SQAAAJ0"]
[Tue Jul 21 08:58:16.001657 2026] [security2:error] [pid 559070:tid 559300] [client 20.220.225.223:53461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/ah25.php"] [unique_id "al9e2Cy1f1FtKC137xsT5QAAAfM"]
[Tue Jul 21 08:58:16.063440 2026] [security2:error] [pid 559070:tid 559170] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9e2Cy1f1FtKC137xsT5gABoWM"]
[Tue Jul 21 08:58:16.168872 2026] [security2:error] [pid 559070:tid 559143] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9e2Cy1f1FtKC137xsT6gABtkg"]
[Tue Jul 21 08:58:16.401394 2026] [security2:error] [pid 559070:tid 559294] [client 74.249.245.134:27209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/archive.php"] [unique_id "al9e2Cy1f1FtKC137xsT7QAAAe0"]
[Tue Jul 21 08:58:16.513125 2026] [security2:error] [pid 559070:tid 559190] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9e2Cy1f1FtKC137xsT8QABs3c"]
[Tue Jul 21 08:58:16.593348 2026] [security2:error] [pid 559070:tid 559100] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9e2Cy1f1FtKC137xsT8gABzh0"]
[Tue Jul 21 08:58:17.008936 2026] [security2:error] [pid 559070:tid 559142] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9e2Sy1f1FtKC137xsUAgAB-Ec"]
[Tue Jul 21 08:58:17.073263 2026] [security2:error] [pid 559070:tid 559180] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9e2Sy1f1FtKC137xsUAwABmG0"]
[Tue Jul 21 08:58:17.204131 2026] [security2:error] [pid 533360:tid 533422] [remote 104.207.59.140:58955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.59.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9e2XUPuLYrePtEkUc1XAAAlDo"]
[Tue Jul 21 08:58:17.282384 2026] [security2:error] [pid 533360:tid 533564] [client 20.220.225.223:30685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9e2XUPuLYrePtEkUc1YgAAAMw"]
[Tue Jul 21 08:58:17.286315 2026] [security2:error] [pid 559070:tid 559124] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9e2Sy1f1FtKC137xsUBwACADU"]
[Tue Jul 21 08:58:17.286549 2026] [security2:error] [pid 559070:tid 559313] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9e2Sy1f1FtKC137xsUBwACADU"]
[Tue Jul 21 08:58:17.323523 2026] [security2:error] [pid 559070:tid 559116] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php"] [unique_id "al9e2Sy1f1FtKC137xsUCgAB5i0"]
[Tue Jul 21 08:58:17.330763 2026] [security2:error] [pid 533360:tid 533504] [client 20.151.10.161:48592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9e2XUPuLYrePtEkUc1ZwAAAJA"]
[Tue Jul 21 08:58:17.381662 2026] [security2:error] [pid 559070:tid 559132] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9e2Sy1f1FtKC137xsUDQABpz0"]
[Tue Jul 21 08:58:17.704730 2026] [security2:error] [pid 559070:tid 559297] [client 20.220.225.223:60369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/8.php"] [unique_id "al9e2Sy1f1FtKC137xsUFQAAAfA"]
[Tue Jul 21 08:58:17.753602 2026] [security2:error] [pid 559070:tid 559105] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9e2Sy1f1FtKC137xsUFgAB_yI"]
[Tue Jul 21 08:58:17.759559 2026] [security2:error] [pid 559070:tid 559243] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9e2Sy1f1FtKC137xsUDgAAAbo"]
[Tue Jul 21 08:58:17.978213 2026] [security2:error] [pid 559070:tid 559222] [client 20.220.225.223:30899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9e2Sy1f1FtKC137xsUGwAAAaU"]
[Tue Jul 21 08:58:17.987381 2026] [security2:error] [pid 559070:tid 559263] [client 74.249.245.134:27315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/amax.php"] [unique_id "al9e2Sy1f1FtKC137xsUHAAAAc4"]
[Tue Jul 21 08:58:18.044667 2026] [security2:error] [pid 559070:tid 559162] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9e2iy1f1FtKC137xsUHgAB2Fs"]
[Tue Jul 21 08:58:18.203523 2026] [security2:error] [pid 559070:tid 559304] [client 20.151.10.161:48590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/adminfuns.php"] [unique_id "al9e2iy1f1FtKC137xsUKgAAAfc"]
[Tue Jul 21 08:58:18.333219 2026] [security2:error] [pid 559070:tid 559172] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9e2iy1f1FtKC137xsUKwABsWU"]
[Tue Jul 21 08:58:18.397578 2026] [security2:error] [pid 559070:tid 559260] [client 59.95.197.55:60033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e2iy1f1FtKC137xsULAAAAcs"]
[Tue Jul 21 08:58:18.398259 2026] [security2:error] [pid 559070:tid 559260] [client 59.95.197.55:60033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e2iy1f1FtKC137xsULAAAAcs"]
[Tue Jul 21 08:58:18.449990 2026] [security2:error] [pid 559070:tid 559079] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e2iy1f1FtKC137xsULwAByQg"]
[Tue Jul 21 08:58:18.450182 2026] [security2:error] [pid 559070:tid 559258] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e2iy1f1FtKC137xsULwAByQg"]
[Tue Jul 21 08:58:18.663124 2026] [security2:error] [pid 559070:tid 559167] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/index.php/_ignition/execute-solution"] [unique_id "al9e2iy1f1FtKC137xsUNgABsGA"]
[Tue Jul 21 08:58:18.892798 2026] [security2:error] [pid 533360:tid 533583] [client 20.151.10.161:49080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/goods.php"] [unique_id "al9e2nUPuLYrePtEkUc1fgAAAN8"]
[Tue Jul 21 08:58:19.067570 2026] [security2:error] [pid 533360:tid 533500] [client 65.21.113.253:39640] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9e23UPuLYrePtEkUc1gAAAAIw"]
[Tue Jul 21 08:58:19.136661 2026] [security2:error] [pid 559070:tid 559269] [client 20.52.136.55:1750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/moon.php"] [unique_id "al9e2yy1f1FtKC137xsUPwAAAdQ"]
[Tue Jul 21 08:58:19.140277 2026] [security2:error] [pid 559070:tid 559275] [client 5.38.115.39:45430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9e2yy1f1FtKC137xsUQAAAAdo"]
[Tue Jul 21 08:58:19.140433 2026] [security2:error] [pid 559070:tid 559275] [client 5.38.115.39:45430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9e2yy1f1FtKC137xsUQAAAAdo"]
[Tue Jul 21 08:58:19.316677 2026] [security2:error] [pid 533360:tid 533516] [client 74.249.245.134:27283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/moon.php"] [unique_id "al9e23UPuLYrePtEkUc1hwAAAJw"]
[Tue Jul 21 08:58:20.024021 2026] [security2:error] [pid 533360:tid 533574] [client 20.151.10.161:49141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/ms-edit.php"] [unique_id "al9e3HUPuLYrePtEkUc1kQAAANY"]
[Tue Jul 21 08:58:20.126586 2026] [security2:error] [pid 559070:tid 559325] [client 65.21.113.253:50192] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9e2yy1f1FtKC137xsUVQAAAgw"]
[Tue Jul 21 08:58:20.519723 2026] [security2:error] [pid 559070:tid 559296] [client 74.249.245.134:27278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/ws83.php"] [unique_id "al9e3Cy1f1FtKC137xsUbQAAAe8"]
[Tue Jul 21 08:58:20.646942 2026] [security2:error] [pid 533360:tid 533514] [client 20.220.225.223:60354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/red.php"] [unique_id "al9e3HUPuLYrePtEkUc1ngAAAJo"]
[Tue Jul 21 08:58:20.794875 2026] [security2:error] [pid 559070:tid 559264] [client 114.198.138.124:57905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9e3Cy1f1FtKC137xsUeAAAAc8"]
[Tue Jul 21 08:58:20.795036 2026] [security2:error] [pid 559070:tid 559264] [client 114.198.138.124:57905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9e3Cy1f1FtKC137xsUeAAAAc8"]
[Tue Jul 21 08:58:20.910826 2026] [security2:error] [pid 559070:tid 559202] [client 20.220.225.223:60359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/echkm.php"] [unique_id "al9e3Cy1f1FtKC137xsUegAAAZE"]
[Tue Jul 21 08:58:21.010810 2026] [security2:error] [pid 559070:tid 559129] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e3Sy1f1FtKC137xsUewABoTo"]
[Tue Jul 21 08:58:21.010978 2026] [security2:error] [pid 559070:tid 559218] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e3Sy1f1FtKC137xsUewABoTo"]
[Tue Jul 21 08:58:21.250493 2026] [security2:error] [pid 559070:tid 559274] [client 74.249.245.134:27299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/CDX1.php"] [unique_id "al9e3Sy1f1FtKC137xsUfwAAAdk"]
[Tue Jul 21 08:58:21.382860 2026] [security2:error] [pid 559070:tid 559268] [client 20.151.10.161:48971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/222.php"] [unique_id "al9e3Sy1f1FtKC137xsUgQAAAdM"]
[Tue Jul 21 08:58:21.464964 2026] [security2:error] [pid 533360:tid 533530] [client 168.167.81.163:65189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9e3XUPuLYrePtEkUc1qQAAAKo"]
[Tue Jul 21 08:58:21.465102 2026] [security2:error] [pid 533360:tid 533530] [client 168.167.81.163:65189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9e3XUPuLYrePtEkUc1qQAAAKo"]
[Tue Jul 21 08:58:21.824733 2026] [access_compat:error] [pid 559070:tid 559228] [client 162.241.63.68:34454] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:58:21.836095 2026] [security2:error] [pid 533360:tid 533500] [client 74.249.245.134:27210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/inputs.php"] [unique_id "al9e3XUPuLYrePtEkUc1rwAAAIw"]
[Tue Jul 21 08:58:22.055126 2026] [autoindex:error] [pid 533360:tid 533375] [remote 74.7.242.33:59238] AH01276: Cannot serve directory /home4/horicl01/dentistaguarulhos.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:58:22.083988 2026] [security2:error] [pid 559070:tid 559222] [client 113.22.144.139:62766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e3iy1f1FtKC137xsUkwAAAaU"]
[Tue Jul 21 08:58:22.084124 2026] [security2:error] [pid 559070:tid 559222] [client 113.22.144.139:62766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e3iy1f1FtKC137xsUkwAAAaU"]
[Tue Jul 21 08:58:22.398571 2026] [security2:error] [pid 559070:tid 559248] [client 74.7.241.184:60114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.dentistaguarulhos.horiclinicaguarulhos.com.br"] [uri "/cgi-sys/404.html"] [unique_id "al9e3iy1f1FtKC137xsUmAABv2I"]
[Tue Jul 21 08:58:22.411051 2026] [security2:error] [pid 559070:tid 559154] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9e3iy1f1FtKC137xsUmQABklM"]
[Tue Jul 21 08:58:22.411195 2026] [security2:error] [pid 559070:tid 559203] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9e3iy1f1FtKC137xsUmQABklM"]
[Tue Jul 21 08:58:22.707651 2026] [security2:error] [pid 559070:tid 559284] [client 20.151.10.161:49149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9e3iy1f1FtKC137xsUnwAAAeM"]
[Tue Jul 21 08:58:22.785533 2026] [security2:error] [pid 559070:tid 559250] [client 74.249.245.134:27206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/ms-edit.php"] [unique_id "al9e3iy1f1FtKC137xsUoAAAAcE"]
[Tue Jul 21 08:58:23.402603 2026] [security2:error] [pid 559070:tid 559275] [client 74.249.245.134:27303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/simple.php"] [unique_id "al9e3yy1f1FtKC137xsUqgAAAdo"]
[Tue Jul 21 08:58:23.864014 2026] [security2:error] [pid 533360:tid 533536] [client 20.220.225.223:20877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/berlin.php"] [unique_id "al9e33UPuLYrePtEkUc12wAAALA"]
[Tue Jul 21 08:58:23.879702 2026] [security2:error] [pid 559070:tid 559138] [remote 8.217.108.67:10342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "financasparaempreendedoras.com"] [uri "/wp-login.php"] [unique_id "al9e3yy1f1FtKC137xsUsAAB4UM"]
[Tue Jul 21 08:58:24.134672 2026] [security2:error] [pid 559070:tid 559158] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e4Cy1f1FtKC137xsUtAACAFc"]
[Tue Jul 21 08:58:24.136033 2026] [security2:error] [pid 559070:tid 559090] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e4Cy1f1FtKC137xsUtwACABM"]
[Tue Jul 21 08:58:24.136067 2026] [security2:error] [pid 559070:tid 559145] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e4Cy1f1FtKC137xsUtQACAEo"]
[Tue Jul 21 08:58:24.140766 2026] [security2:error] [pid 559070:tid 559190] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e4Cy1f1FtKC137xsUvQACAHc"]
[Tue Jul 21 08:58:24.140840 2026] [security2:error] [pid 559070:tid 559100] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e4Cy1f1FtKC137xsUvgACAB0"]
[Tue Jul 21 08:58:24.147152 2026] [security2:error] [pid 559070:tid 559178] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e4Cy1f1FtKC137xsUvwACAGs"]
[Tue Jul 21 08:58:24.273368 2026] [security2:error] [pid 559070:tid 559262] [client 184.154.36.163:42748] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-wpforms-063cb453c64ecfd3dafe.js"] [unique_id "al9e4Cy1f1FtKC137xsUxgAAAc0"]
[Tue Jul 21 08:58:24.354333 2026] [security2:error] [pid 559070:tid 559253] [client 74.249.245.134:27201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/404.php"] [unique_id "al9e4Cy1f1FtKC137xsUyAAAAcQ"]
[Tue Jul 21 08:58:24.381033 2026] [security2:error] [pid 559070:tid 559248] [client 20.151.10.161:50951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-content/themes/index.php"] [unique_id "al9e4Cy1f1FtKC137xsUyQAAAb8"]
[Tue Jul 21 08:58:24.604637 2026] [security2:error] [pid 533360:tid 533612] [client 20.220.225.223:34276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/la.php"] [unique_id "al9e4HUPuLYrePtEkUc16AAAAPw"]
[Tue Jul 21 08:58:24.608458 2026] [security2:error] [pid 559070:tid 559264] [client 65.21.113.253:40124] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9e4Cy1f1FtKC137xsU0gAAAc8"]
[Tue Jul 21 08:58:24.613288 2026] [security2:error] [pid 559070:tid 559171] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e4Cy1f1FtKC137xsU1AABkWQ"]
[Tue Jul 21 08:58:24.614786 2026] [security2:error] [pid 559070:tid 559155] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e4Cy1f1FtKC137xsU1wABkVQ"]
[Tue Jul 21 08:58:24.614988 2026] [security2:error] [pid 559070:tid 559141] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api"] [unique_id "al9e4Cy1f1FtKC137xsU1QABkUY"]
[Tue Jul 21 08:58:24.623770 2026] [security2:error] [pid 559070:tid 559151] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e4Cy1f1FtKC137xsU2QABkVA"]
[Tue Jul 21 08:58:24.677475 2026] [security2:error] [pid 559070:tid 559177] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api"] [unique_id "al9e4Cy1f1FtKC137xsU4QABkWo"]
[Tue Jul 21 08:58:24.708455 2026] [security2:error] [pid 559070:tid 559075] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api"] [unique_id "al9e4Cy1f1FtKC137xsU5QABkQQ"]
[Tue Jul 21 08:58:24.744866 2026] [security2:error] [pid 559070:tid 559233] [client 20.151.10.161:49061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9e4Cy1f1FtKC137xsU6QAAAbA"]
[Tue Jul 21 08:58:24.901721 2026] [security2:error] [pid 559070:tid 559284] [client 117.214.78.59:55168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9e4Cy1f1FtKC137xsU8AAAAeM"]
[Tue Jul 21 08:58:24.901823 2026] [security2:error] [pid 559070:tid 559284] [client 117.214.78.59:55168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9e4Cy1f1FtKC137xsU8AAAAeM"]
[Tue Jul 21 08:58:24.912567 2026] [security2:error] [pid 559070:tid 559191] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api"] [unique_id "al9e4Cy1f1FtKC137xsU8QACCXg"]
[Tue Jul 21 08:58:24.912582 2026] [security2:error] [pid 559070:tid 559167] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api"] [unique_id "al9e4Cy1f1FtKC137xsU8gACCWA"]
[Tue Jul 21 08:58:24.957885 2026] [security2:error] [pid 559070:tid 559137] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api"] [unique_id "al9e4Cy1f1FtKC137xsU9gACCUI"]
[Tue Jul 21 08:58:25.027498 2026] [security2:error] [pid 559070:tid 559073] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api"] [unique_id "al9e4Sy1f1FtKC137xsU9wACCQI"]
[Tue Jul 21 08:58:25.036881 2026] [security2:error] [pid 559070:tid 559165] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api"] [unique_id "al9e4Sy1f1FtKC137xsU-QACCV4"]
[Tue Jul 21 08:58:25.043026 2026] [security2:error] [pid 559070:tid 559293] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9e4Cy1f1FtKC137xsU9QAB7Dw"]
[Tue Jul 21 08:58:25.045939 2026] [security2:error] [pid 559070:tid 559185] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v1"] [unique_id "al9e4Sy1f1FtKC137xsU-wACCXI"]
[Tue Jul 21 08:58:25.055063 2026] [security2:error] [pid 559070:tid 559106] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api"] [unique_id "al9e4Sy1f1FtKC137xsU_gACCSM"]
[Tue Jul 21 08:58:25.180462 2026] [security2:error] [pid 559070:tid 559184] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v1"] [unique_id "al9e4Sy1f1FtKC137xsVBQACCXE"]
[Tue Jul 21 08:58:25.233909 2026] [security2:error] [pid 533360:tid 533551] [client 20.220.225.223:53449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/fffm.php"] [unique_id "al9e4XUPuLYrePtEkUc17wAAAL8"]
[Tue Jul 21 08:58:25.305732 2026] [security2:error] [pid 559070:tid 559147] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v1"] [unique_id "al9e4Sy1f1FtKC137xsVCgACCUw"]
[Tue Jul 21 08:58:25.360945 2026] [security2:error] [pid 559070:tid 559150] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v1"] [unique_id "al9e4Sy1f1FtKC137xsVDQACCU8"]
[Tue Jul 21 08:58:25.369795 2026] [security2:error] [pid 559070:tid 559250] [client 74.249.245.134:27211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/file3.php"] [unique_id "al9e4Sy1f1FtKC137xsVDgAAAcE"]
[Tue Jul 21 08:58:25.538775 2026] [security2:error] [pid 559070:tid 559117] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v1"] [unique_id "al9e4Sy1f1FtKC137xsVEQACCS4"]
[Tue Jul 21 08:58:25.573711 2026] [security2:error] [pid 559070:tid 559152] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v1"] [unique_id "al9e4Sy1f1FtKC137xsVFQACCVE"]
[Tue Jul 21 08:58:25.624303 2026] [security2:error] [pid 559070:tid 559134] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v1"] [unique_id "al9e4Sy1f1FtKC137xsVGQACCT8"]
[Tue Jul 21 08:58:25.687121 2026] [security2:error] [pid 559070:tid 559126] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v1"] [unique_id "al9e4Sy1f1FtKC137xsVHAACCTc"]
[Tue Jul 21 08:58:25.734523 2026] [security2:error] [pid 559070:tid 559078] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v1"] [unique_id "al9e4Sy1f1FtKC137xsVHgACCQc"]
[Tue Jul 21 08:58:25.740005 2026] [security2:error] [pid 559070:tid 559125] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v2"] [unique_id "al9e4Sy1f1FtKC137xsVIAACCTY"]
[Tue Jul 21 08:58:25.760392 2026] [security2:error] [pid 559070:tid 559271] [client 51.68.111.213:35697] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "benti.com.br"] [uri "/robots.txt"] [unique_id "al9e4Sy1f1FtKC137xsVIQAAAdY"]
[Tue Jul 21 08:58:25.760572 2026] [security2:error] [pid 559070:tid 559271] [client 51.68.111.213:35697] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "benti.com.br"] [uri "/robots.txt"] [unique_id "al9e4Sy1f1FtKC137xsVIQAAAdY"]
[Tue Jul 21 08:58:25.818750 2026] [security2:error] [pid 559070:tid 559310] [client 65.21.113.253:50204] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9e4Sy1f1FtKC137xsVCQAAAf0"]
[Tue Jul 21 08:58:26.052799 2026] [security2:error] [pid 559070:tid 559313] [client 194.99.104.35:58668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9e4iy1f1FtKC137xsVLAAAAgA"]
[Tue Jul 21 08:58:26.052900 2026] [security2:error] [pid 559070:tid 559313] [client 194.99.104.35:58668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9e4iy1f1FtKC137xsVLAAAAgA"]
[Tue Jul 21 08:58:26.054924 2026] [security2:error] [pid 533360:tid 533523] [client 115.245.198.210:48865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9e4nUPuLYrePtEkUc2BQAAAKM"]
[Tue Jul 21 08:58:26.055106 2026] [security2:error] [pid 533360:tid 533523] [client 115.245.198.210:48865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9e4nUPuLYrePtEkUc2BQAAAKM"]
[Tue Jul 21 08:58:26.364603 2026] [security2:error] [pid 559070:tid 559306] [client 41.89.234.2:13086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e4iy1f1FtKC137xsVNQAAAfk"]
[Tue Jul 21 08:58:26.364920 2026] [security2:error] [pid 559070:tid 559306] [client 41.89.234.2:13086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e4iy1f1FtKC137xsVNQAAAfk"]
[Tue Jul 21 08:58:26.400859 2026] [core:error] [pid 559070:tid 559154] [remote 52.167.144.214:2361] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:58:26.400893 2026] [core:error] [pid 559070:tid 559154] [remote 52.167.144.214:2361] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:58:26.447632 2026] [security2:error] [pid 559070:tid 559160] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v2"] [unique_id "al9e4iy1f1FtKC137xsVOQACCVk"]
[Tue Jul 21 08:58:26.456373 2026] [security2:error] [pid 559070:tid 559088] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v2"] [unique_id "al9e4iy1f1FtKC137xsVOgACCRE"]
[Tue Jul 21 08:58:26.522914 2026] [security2:error] [pid 559070:tid 559098] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v2"] [unique_id "al9e4iy1f1FtKC137xsVPwACCRs"]
[Tue Jul 21 08:58:26.527120 2026] [core:error] [pid 559070:tid 559144] [remote 52.167.144.214:2361] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:58:26.527145 2026] [core:error] [pid 559070:tid 559144] [remote 52.167.144.214:2361] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:58:26.534077 2026] [security2:error] [pid 559070:tid 559159] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v2"] [unique_id "al9e4iy1f1FtKC137xsVQAACCVg"]
[Tue Jul 21 08:58:26.537913 2026] [security2:error] [pid 533360:tid 533525] [client 74.249.245.134:27200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/wp-mail.php"] [unique_id "al9e4nUPuLYrePtEkUc2DwAAAKU"]
[Tue Jul 21 08:58:26.550483 2026] [security2:error] [pid 533360:tid 533496] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9e4nUPuLYrePtEkUc2CQAAAIg"]
[Tue Jul 21 08:58:26.600171 2026] [security2:error] [pid 559070:tid 559118] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v2"] [unique_id "al9e4iy1f1FtKC137xsVRgACCS8"]
[Tue Jul 21 08:58:26.611911 2026] [security2:error] [pid 559070:tid 559158] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v2"] [unique_id "al9e4iy1f1FtKC137xsVSAACCVc"]
[Tue Jul 21 08:58:26.617451 2026] [security2:error] [pid 559070:tid 559090] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v2"] [unique_id "al9e4iy1f1FtKC137xsVSQACCRM"]
[Tue Jul 21 08:58:26.677056 2026] [security2:error] [pid 559070:tid 559143] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/v2"] [unique_id "al9e4iy1f1FtKC137xsVSwABnkg"]
[Tue Jul 21 08:58:26.713208 2026] [security2:error] [pid 559070:tid 559100] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config"] [unique_id "al9e4iy1f1FtKC137xsVTQABvx0"]
[Tue Jul 21 08:58:26.760649 2026] [security2:error] [pid 559070:tid 559142] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config"] [unique_id "al9e4iy1f1FtKC137xsVUwABv0c"]
[Tue Jul 21 08:58:26.781381 2026] [security2:error] [pid 559070:tid 559170] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config"] [unique_id "al9e4iy1f1FtKC137xsVWAABv2M"]
[Tue Jul 21 08:58:26.830559 2026] [security2:error] [pid 533360:tid 533505] [client 184.154.36.163:42792] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/"] [unique_id "al9e4nUPuLYrePtEkUc2CAAAAJE"]
[Tue Jul 21 08:58:26.830619 2026] [security2:error] [pid 559070:tid 559186] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config"] [unique_id "al9e4iy1f1FtKC137xsVXQABv3M"]
[Tue Jul 21 08:58:26.862238 2026] [security2:error] [pid 559070:tid 559124] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config"] [unique_id "al9e4iy1f1FtKC137xsVXwABvzU"]
[Tue Jul 21 08:58:26.923641 2026] [security2:error] [pid 559070:tid 559141] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config"] [unique_id "al9e4iy1f1FtKC137xsVZgABv0Y"]
[Tue Jul 21 08:58:26.933958 2026] [security2:error] [pid 559070:tid 559151] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config"] [unique_id "al9e4iy1f1FtKC137xsVZwABv1A"]
[Tue Jul 21 08:58:26.978639 2026] [security2:error] [pid 559070:tid 559075] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config"] [unique_id "al9e4iy1f1FtKC137xsVbAABvwQ"]
[Tue Jul 21 08:58:26.994500 2026] [security2:error] [pid 559070:tid 559268] [client 20.151.10.161:55834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-blog.php"] [unique_id "al9e4iy1f1FtKC137xsVbQAAAdM"]
[Tue Jul 21 08:58:27.014065 2026] [security2:error] [pid 559070:tid 559105] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/config"] [unique_id "al9e4yy1f1FtKC137xsVbgABvyI"]
[Tue Jul 21 08:58:27.032156 2026] [core:error] [pid 559070:tid 559132] [remote 52.167.144.214:2361] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:58:27.032178 2026] [core:error] [pid 559070:tid 559132] [remote 52.167.144.214:2361] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:58:27.057176 2026] [security2:error] [pid 559070:tid 559305] [client 20.151.10.161:49134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp.php"] [unique_id "al9e4yy1f1FtKC137xsVcAAAAfg"]
[Tue Jul 21 08:58:27.071623 2026] [security2:error] [pid 533360:tid 533570] [client 185.198.240.113:50201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.240.198.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "voweltravel.com.br"] [uri "/wp-login.php"] [unique_id "al9e43UPuLYrePtEkUc2FgAAANI"]
[Tue Jul 21 08:58:27.117048 2026] [security2:error] [pid 559070:tid 559254] [client 182.189.99.211:48419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e4yy1f1FtKC137xsVdgAAAcU"]
[Tue Jul 21 08:58:27.117150 2026] [security2:error] [pid 559070:tid 559254] [client 182.189.99.211:48419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e4yy1f1FtKC137xsVdgAAAcU"]
[Tue Jul 21 08:58:27.132111 2026] [security2:error] [pid 559070:tid 559153] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/config"] [unique_id "al9e4yy1f1FtKC137xsVdwABv1I"]
[Tue Jul 21 08:58:27.439521 2026] [security2:error] [pid 559070:tid 559215] [client 74.249.245.134:27311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/about.php"] [unique_id "al9e4yy1f1FtKC137xsVfQAAAZ4"]
[Tue Jul 21 08:58:27.822532 2026] [security2:error] [pid 559070:tid 559131] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9e4yy1f1FtKC137xsVhwAB0Dw"]
[Tue Jul 21 08:58:27.822731 2026] [security2:error] [pid 559070:tid 559265] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9e4yy1f1FtKC137xsVhwAB0Dw"]
[Tue Jul 21 08:58:28.100710 2026] [security2:error] [pid 533360:tid 533587] [client 20.220.225.223:53470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/mac.php"] [unique_id "al9e5HUPuLYrePtEkUc2JAAAAOM"]
[Tue Jul 21 08:58:28.120394 2026] [security2:error] [pid 533360:tid 533511] [client 20.151.10.161:49024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/abcd.php"] [unique_id "al9e5HUPuLYrePtEkUc2JQAAAJc"]
[Tue Jul 21 08:58:28.423075 2026] [security2:error] [pid 559070:tid 559184] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/config"] [unique_id "al9e5Cy1f1FtKC137xsVlAABv3E"]
[Tue Jul 21 08:58:28.452806 2026] [security2:error] [pid 559070:tid 559326] [client 20.220.225.223:34265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9e5Cy1f1FtKC137xsVlgAAAg0"]
[Tue Jul 21 08:58:28.476071 2026] [security2:error] [pid 533360:tid 533597] [client 20.220.225.223:34257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/ms-new.php"] [unique_id "al9e5HUPuLYrePtEkUc2LAAAAO0"]
[Tue Jul 21 08:58:28.476876 2026] [security2:error] [pid 559070:tid 559295] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9e5Cy1f1FtKC137xsVkwAAAe4"]
[Tue Jul 21 08:58:28.484287 2026] [security2:error] [pid 559070:tid 559147] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/config"] [unique_id "al9e5Cy1f1FtKC137xsVlwABv0w"]
[Tue Jul 21 08:58:28.500040 2026] [security2:error] [pid 559070:tid 559188] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/config"] [unique_id "al9e5Cy1f1FtKC137xsVmwABv3U"]
[Tue Jul 21 08:58:28.517253 2026] [security2:error] [pid 559070:tid 559080] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/config"] [unique_id "al9e5Cy1f1FtKC137xsVnAABvwk"]
[Tue Jul 21 08:58:28.531124 2026] [security2:error] [pid 559070:tid 559130] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/config"] [unique_id "al9e5Cy1f1FtKC137xsVnQABvzs"]
[Tue Jul 21 08:58:28.543227 2026] [security2:error] [pid 559070:tid 559254] [client 74.249.245.134:27137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/adminfuns.php"] [unique_id "al9e5Cy1f1FtKC137xsVngAAAcU"]
[Tue Jul 21 08:58:28.548426 2026] [security2:error] [pid 559070:tid 559117] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/config"] [unique_id "al9e5Cy1f1FtKC137xsVnwABvy4"]
[Tue Jul 21 08:58:28.575400 2026] [security2:error] [pid 559070:tid 559152] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/config"] [unique_id "al9e5Cy1f1FtKC137xsVogABv1E"]
[Tue Jul 21 08:58:28.582698 2026] [security2:error] [pid 559070:tid 559129] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/api/config"] [unique_id "al9e5Cy1f1FtKC137xsVowABvzo"]
[Tue Jul 21 08:58:28.634250 2026] [security2:error] [pid 559070:tid 559126] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/login"] [unique_id "al9e5Cy1f1FtKC137xsVqQABvzc"]
[Tue Jul 21 08:58:28.703793 2026] [security2:error] [pid 559070:tid 559082] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/login"] [unique_id "al9e5Cy1f1FtKC137xsVrwABvws"]
[Tue Jul 21 08:58:28.731285 2026] [security2:error] [pid 559070:tid 559120] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/login"] [unique_id "al9e5Cy1f1FtKC137xsVsQABvzE"]
[Tue Jul 21 08:58:28.787789 2026] [security2:error] [pid 559070:tid 559146] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/login"] [unique_id "al9e5Cy1f1FtKC137xsVtQABv0s"]
[Tue Jul 21 08:58:28.791018 2026] [security2:error] [pid 559070:tid 559154] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/login"] [unique_id "al9e5Cy1f1FtKC137xsVtgABv1M"]
[Tue Jul 21 08:58:28.856119 2026] [security2:error] [pid 559070:tid 559160] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/login"] [unique_id "al9e5Cy1f1FtKC137xsVtwABv1k"]
[Tue Jul 21 08:58:28.872173 2026] [security2:error] [pid 559070:tid 559088] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/login"] [unique_id "al9e5Cy1f1FtKC137xsVuAABvxE"]
[Tue Jul 21 08:58:28.889755 2026] [security2:error] [pid 559070:tid 559071] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/login"] [unique_id "al9e5Cy1f1FtKC137xsVuQABvwA"]
[Tue Jul 21 08:58:28.890901 2026] [security2:error] [pid 559070:tid 559268] [client 59.95.197.55:60505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e5Cy1f1FtKC137xsVugAAAdM"]
[Tue Jul 21 08:58:28.890999 2026] [security2:error] [pid 559070:tid 559268] [client 59.95.197.55:60505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e5Cy1f1FtKC137xsVugAAAdM"]
[Tue Jul 21 08:58:28.947461 2026] [security2:error] [pid 559070:tid 559092] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/login"] [unique_id "al9e5Cy1f1FtKC137xsVvAABvxU"]
[Tue Jul 21 08:58:29.032505 2026] [security2:error] [pid 559070:tid 559098] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/contact"] [unique_id "al9e5Sy1f1FtKC137xsVwAABvxs"]
[Tue Jul 21 08:58:29.078665 2026] [security2:error] [pid 559070:tid 559280] [client 20.220.225.223:34303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/track.php"] [unique_id "al9e5Sy1f1FtKC137xsVwgAAAd8"]
[Tue Jul 21 08:58:29.097698 2026] [security2:error] [pid 559070:tid 559095] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e5Sy1f1FtKC137xsVwwABnhg"]
[Tue Jul 21 08:58:29.097876 2026] [security2:error] [pid 559070:tid 559215] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e5Sy1f1FtKC137xsVwwABnhg"]
[Tue Jul 21 08:58:29.409159 2026] [security2:error] [pid 533360:tid 533575] [client 74.249.245.134:27250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/php8.php"] [unique_id "al9e5XUPuLYrePtEkUc2NwAAANc"]
[Tue Jul 21 08:58:29.490991 2026] [security2:error] [pid 559070:tid 559282] [client 65.21.113.253:40124] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9e5Sy1f1FtKC137xsV0QAAAeE"]
[Tue Jul 21 08:58:29.557138 2026] [security2:error] [pid 559070:tid 559083] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/contact"] [unique_id "al9e5Sy1f1FtKC137xsV0wABvww"]
[Tue Jul 21 08:58:29.594653 2026] [security2:error] [pid 559070:tid 559143] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/contact"] [unique_id "al9e5Sy1f1FtKC137xsV1QABv0g"]
[Tue Jul 21 08:58:29.657218 2026] [security2:error] [pid 559070:tid 559186] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/contact"] [unique_id "al9e5Sy1f1FtKC137xsV2wABv3M"]
[Tue Jul 21 08:58:29.666980 2026] [security2:error] [pid 559070:tid 559124] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/contact"] [unique_id "al9e5Sy1f1FtKC137xsV3AABvzU"]
[Tue Jul 21 08:58:29.671336 2026] [security2:error] [pid 559070:tid 559155] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/contact"] [unique_id "al9e5Sy1f1FtKC137xsV3QABv1Q"]
[Tue Jul 21 08:58:29.676888 2026] [security2:error] [pid 559070:tid 559171] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/contact"] [unique_id "al9e5Sy1f1FtKC137xsV3gABv2Q"]
[Tue Jul 21 08:58:29.677919 2026] [security2:error] [pid 559070:tid 559141] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/contact"] [unique_id "al9e5Sy1f1FtKC137xsV3wABv0Y"]
[Tue Jul 21 08:58:29.703557 2026] [security2:error] [pid 559070:tid 559151] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/contact"] [unique_id "al9e5Sy1f1FtKC137xsV4AABv1A"]
[Tue Jul 21 08:58:29.822999 2026] [security2:error] [pid 559070:tid 559132] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/a2a"] [unique_id "al9e5Sy1f1FtKC137xsV5AABvz0"]
[Tue Jul 21 08:58:29.878691 2026] [security2:error] [pid 559070:tid 559263] [client 20.52.136.55:1736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/ws83.php"] [unique_id "al9e5Sy1f1FtKC137xsV6gAAAc4"]
[Tue Jul 21 08:58:30.034642 2026] [security2:error] [pid 533360:tid 533505] [client 216.244.66.243:51390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ssvistorias.com.br"] [uri "/hk9/ds/keylogger-for-bluetooth-keyboard"] [unique_id "al9e5nUPuLYrePtEkUc2RQAAAJE"]
[Tue Jul 21 08:58:30.034745 2026] [security2:error] [pid 533360:tid 533505] [client 216.244.66.243:51390] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ssvistorias.com.br"] [uri "/hk9/ds/keylogger-for-bluetooth-keyboard"] [unique_id "al9e5nUPuLYrePtEkUc2RQAAAJE"]
[Tue Jul 21 08:58:30.159086 2026] [security2:error] [pid 533360:tid 533533] [client 5.38.115.39:63263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.115.38.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9e5nUPuLYrePtEkUc2SAAAAK0"]
[Tue Jul 21 08:58:30.159168 2026] [security2:error] [pid 533360:tid 533533] [client 5.38.115.39:63263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9e5nUPuLYrePtEkUc2SAAAAK0"]
[Tue Jul 21 08:58:30.164332 2026] [security2:error] [pid 559070:tid 559266] [client 20.151.10.161:51048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9e5iy1f1FtKC137xsV9gAAAdE"]
[Tue Jul 21 08:58:30.222549 2026] [security2:error] [pid 559070:tid 559293] [client 20.220.225.223:53500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/ftde.php"] [unique_id "al9e5iy1f1FtKC137xsV-AAAAew"]
[Tue Jul 21 08:58:30.320861 2026] [security2:error] [pid 533360:tid 533601] [client 103.59.206.240:31222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e5nUPuLYrePtEkUc2SgAAAPE"]
[Tue Jul 21 08:58:30.321090 2026] [security2:error] [pid 533360:tid 533601] [client 103.59.206.240:31222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e5nUPuLYrePtEkUc2SgAAAPE"]
[Tue Jul 21 08:58:30.417285 2026] [security2:error] [pid 559070:tid 559178] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/a2a"] [unique_id "al9e5iy1f1FtKC137xsV-QABv2s"]
[Tue Jul 21 08:58:30.576514 2026] [security2:error] [pid 559070:tid 559076] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/a2a"] [unique_id "al9e5iy1f1FtKC137xsV_AABvwU"]
[Tue Jul 21 08:58:30.628892 2026] [security2:error] [pid 559070:tid 559202] [client 65.21.113.253:50880] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9e5iy1f1FtKC137xsV9AAAAZE"]
[Tue Jul 21 08:58:30.671352 2026] [security2:error] [pid 559070:tid 559162] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/a2a"] [unique_id "al9e5iy1f1FtKC137xsWAwABv1s"]
[Tue Jul 21 08:58:30.671595 2026] [security2:error] [pid 559070:tid 559148] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/a2a"] [unique_id "al9e5iy1f1FtKC137xsWBAABv00"]
[Tue Jul 21 08:58:30.676869 2026] [security2:error] [pid 559070:tid 559180] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/a2a"] [unique_id "al9e5iy1f1FtKC137xsWBQABv20"]
[Tue Jul 21 08:58:30.743235 2026] [security2:error] [pid 559070:tid 559122] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/a2a"] [unique_id "al9e5iy1f1FtKC137xsWCAABvzM"]
[Tue Jul 21 08:58:30.828416 2026] [security2:error] [pid 559070:tid 559197] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/a2a"] [unique_id "al9e5iy1f1FtKC137xsWCgABv34"]
[Tue Jul 21 08:58:30.828701 2026] [security2:error] [pid 559070:tid 559191] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/a2a"] [unique_id "al9e5iy1f1FtKC137xsWCwABv3g"]
[Tue Jul 21 08:58:30.897651 2026] [security2:error] [pid 559070:tid 559316] [client 20.151.10.161:49051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/a1.php"] [unique_id "al9e5iy1f1FtKC137xsWDgAAAgM"]
[Tue Jul 21 08:58:30.982986 2026] [security2:error] [pid 559070:tid 559073] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/mcp"] [unique_id "al9e5iy1f1FtKC137xsWEQABvwI"]
[Tue Jul 21 08:58:31.084016 2026] [security2:error] [pid 533360:tid 533619] [client 20.220.225.223:53470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/yup.php"] [unique_id "al9e53UPuLYrePtEkUc2VwAAAQM"]
[Tue Jul 21 08:58:31.101236 2026] [security2:error] [pid 559070:tid 559184] [remote 216.73.216.187:1938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e5iy1f1FtKC137xsWCQAB33E"]
[Tue Jul 21 08:58:31.453212 2026] [security2:error] [pid 559070:tid 559150] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/mcp"] [unique_id "al9e5yy1f1FtKC137xsWGwABv08"]
[Tue Jul 21 08:58:31.456544 2026] [security2:error] [pid 533360:tid 533604] [client 74.249.245.134:27213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/info.php"] [unique_id "al9e53UPuLYrePtEkUc2XgAAAPQ"]
[Tue Jul 21 08:58:31.459834 2026] [security2:error] [pid 559070:tid 559110] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:v. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/mcp"] [unique_id "al9e5yy1f1FtKC137xsWHQABvyc"]
[Tue Jul 21 08:58:31.569511 2026] [security2:error] [pid 533360:tid 533463] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e53UPuLYrePtEkUc2YgAAvGM"]
[Tue Jul 21 08:58:31.569724 2026] [security2:error] [pid 533360:tid 533548] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e53UPuLYrePtEkUc2YgAAvGM"]
[Tue Jul 21 08:58:31.616240 2026] [security2:error] [pid 559070:tid 559082] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/mcp"] [unique_id "al9e5yy1f1FtKC137xsWJgABvws"]
[Tue Jul 21 08:58:31.624507 2026] [security2:error] [pid 559070:tid 559154] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/mcp"] [unique_id "al9e5yy1f1FtKC137xsWKgABv1M"]
[Tue Jul 21 08:58:31.624597 2026] [security2:error] [pid 559070:tid 559077] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/mcp"] [unique_id "al9e5yy1f1FtKC137xsWKAABvwY"]
[Tue Jul 21 08:58:31.624626 2026] [security2:error] [pid 559070:tid 559146] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/mcp"] [unique_id "al9e5yy1f1FtKC137xsWKQABv0s"]
[Tue Jul 21 08:58:31.649784 2026] [security2:error] [pid 559070:tid 559071] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/mcp"] [unique_id "al9e5yy1f1FtKC137xsWLgABvwA"]
[Tue Jul 21 08:58:31.692419 2026] [security2:error] [pid 559070:tid 559092] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/mcp"] [unique_id "al9e5yy1f1FtKC137xsWLwABvxU"]
[Tue Jul 21 08:58:31.764052 2026] [security2:error] [pid 559070:tid 559089] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e5yy1f1FtKC137xsWMwABvxI"]
[Tue Jul 21 08:58:31.858930 2026] [security2:error] [pid 533360:tid 533585] [client 114.198.138.124:58481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9e53UPuLYrePtEkUc2awAAAOE"]
[Tue Jul 21 08:58:31.859037 2026] [security2:error] [pid 533360:tid 533585] [client 114.198.138.124:58481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9e53UPuLYrePtEkUc2awAAAOE"]
[Tue Jul 21 08:58:31.904992 2026] [security2:error] [pid 559070:tid 559118] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e5yy1f1FtKC137xsWOQABvy8"]
[Tue Jul 21 08:58:32.223677 2026] [security2:error] [pid 533360:tid 533519] [client 74.249.245.134:27305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/edit.php"] [unique_id "al9e6HUPuLYrePtEkUc2cQAAAJ8"]
[Tue Jul 21 08:58:32.463011 2026] [security2:error] [pid 559070:tid 559259] [client 20.220.225.223:34253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/2352356666.php"] [unique_id "al9e6Cy1f1FtKC137xsWRQAAAco"]
[Tue Jul 21 08:58:32.480346 2026] [security2:error] [pid 559070:tid 559174] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:file. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Cy1f1FtKC137xsWRgABv2c"]
[Tue Jul 21 08:58:32.496601 2026] [security2:error] [pid 559070:tid 559144] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Cy1f1FtKC137xsWSQABv0k"]
[Tue Jul 21 08:58:32.620781 2026] [security2:error] [pid 559070:tid 559083] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Cy1f1FtKC137xsWSgABvww"]
[Tue Jul 21 08:58:32.632876 2026] [security2:error] [pid 533360:tid 533584] [client 168.167.81.163:64536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9e6HUPuLYrePtEkUc2egAAAOA"]
[Tue Jul 21 08:58:32.632993 2026] [security2:error] [pid 533360:tid 533584] [client 168.167.81.163:64536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9e6HUPuLYrePtEkUc2egAAAOA"]
[Tue Jul 21 08:58:32.637710 2026] [security2:error] [pid 559070:tid 559143] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Cy1f1FtKC137xsWTAABv0g"]
[Tue Jul 21 08:58:32.655390 2026] [security2:error] [pid 559070:tid 559145] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Cy1f1FtKC137xsWTQABv0o"]
[Tue Jul 21 08:58:32.664499 2026] [security2:error] [pid 559070:tid 559186] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Cy1f1FtKC137xsWTgABv3M"]
[Tue Jul 21 08:58:32.666676 2026] [security2:error] [pid 559070:tid 559124] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Cy1f1FtKC137xsWTwABvzU"]
[Tue Jul 21 08:58:32.795377 2026] [security2:error] [pid 559070:tid 559166] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Cy1f1FtKC137xsWWQABv18"]
[Tue Jul 21 08:58:32.824534 2026] [security2:error] [pid 559070:tid 559234] [client 113.22.144.139:63291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e6Cy1f1FtKC137xsWXgAAAbE"]
[Tue Jul 21 08:58:32.824637 2026] [security2:error] [pid 559070:tid 559234] [client 113.22.144.139:63291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e6Cy1f1FtKC137xsWXgAAAbE"]
[Tue Jul 21 08:58:32.901965 2026] [security2:error] [pid 559070:tid 559090] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9e6Cy1f1FtKC137xsWYwABoxM"]
[Tue Jul 21 08:58:32.902194 2026] [security2:error] [pid 559070:tid 559220] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9e6Cy1f1FtKC137xsWYwABoxM"]
[Tue Jul 21 08:58:33.309032 2026] [security2:error] [pid 559070:tid 559267] [client 74.249.245.134:27212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/166.php"] [unique_id "al9e6Sy1f1FtKC137xsWZgAAAdI"]
[Tue Jul 21 08:58:33.454648 2026] [security2:error] [pid 559070:tid 559162] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Sy1f1FtKC137xsWcQABv1s"]
[Tue Jul 21 08:58:33.481254 2026] [security2:error] [pid 559070:tid 559180] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Sy1f1FtKC137xsWcwABv20"]
[Tue Jul 21 08:58:33.631243 2026] [security2:error] [pid 559070:tid 559073] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Sy1f1FtKC137xsWeQABvwI"]
[Tue Jul 21 08:58:33.631280 2026] [security2:error] [pid 559070:tid 559147] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Sy1f1FtKC137xsWegABv0w"]
[Tue Jul 21 08:58:33.771572 2026] [security2:error] [pid 559070:tid 559130] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Sy1f1FtKC137xsWfAABvzs"]
[Tue Jul 21 08:58:33.771580 2026] [security2:error] [pid 559070:tid 559184] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Sy1f1FtKC137xsWfQABv3E"]
[Tue Jul 21 08:58:33.771685 2026] [security2:error] [pid 559070:tid 559189] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Sy1f1FtKC137xsWfgABv3Y"]
[Tue Jul 21 08:58:33.788075 2026] [security2:error] [pid 559070:tid 559170] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Sy1f1FtKC137xsWfwABv2M"]
[Tue Jul 21 08:58:33.789240 2026] [security2:error] [pid 559070:tid 559137] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Sy1f1FtKC137xsWhAABv0I"]
[Tue Jul 21 08:58:33.929987 2026] [security2:error] [pid 559070:tid 559150] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6Sy1f1FtKC137xsWjgABv08"]
[Tue Jul 21 08:58:33.992428 2026] [security2:error] [pid 533360:tid 533607] [client 20.151.10.161:55858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/adminfuns.php"] [unique_id "al9e6XUPuLYrePtEkUc2lAAAAPc"]
[Tue Jul 21 08:58:34.404804 2026] [security2:error] [pid 559070:tid 559117] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:page. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6iy1f1FtKC137xsWlQABvy4"]
[Tue Jul 21 08:58:34.547882 2026] [security2:error] [pid 559070:tid 559077] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6iy1f1FtKC137xsWnAABvwY"]
[Tue Jul 21 08:58:34.569447 2026] [security2:error] [pid 559070:tid 559146] [remote 120.72.98.5:42722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.98.72.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sugar-delete.site"] [uri "/wp-login.php"] [unique_id "al9e6iy1f1FtKC137xsWngAB9Us"]
[Tue Jul 21 08:58:34.570578 2026] [security2:error] [pid 533360:tid 533579] [client 74.249.245.134:27248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/8.php"] [unique_id "al9e6nUPuLYrePtEkUc2nQAAANs"]
[Tue Jul 21 08:58:34.605141 2026] [security2:error] [pid 559070:tid 559071] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6iy1f1FtKC137xsWnwABvwA"]
[Tue Jul 21 08:58:34.634974 2026] [security2:error] [pid 559070:tid 559088] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6iy1f1FtKC137xsWoAABvxE"]
[Tue Jul 21 08:58:34.646689 2026] [security2:error] [pid 559070:tid 559092] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6iy1f1FtKC137xsWoQABvxU"]
[Tue Jul 21 08:58:34.648301 2026] [security2:error] [pid 559070:tid 559089] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6iy1f1FtKC137xsWogABvxI"]
[Tue Jul 21 08:58:34.650716 2026] [security2:error] [pid 559070:tid 559118] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6iy1f1FtKC137xsWowABvy8"]
[Tue Jul 21 08:58:34.698246 2026] [security2:error] [pid 559070:tid 559267] [client 20.220.225.223:60364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/samll.php"] [unique_id "al9e6iy1f1FtKC137xsWpAAAAdI"]
[Tue Jul 21 08:58:34.798482 2026] [security2:error] [pid 559070:tid 559174] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6iy1f1FtKC137xsWqQABv2c"]
[Tue Jul 21 08:58:35.234410 2026] [security2:error] [pid 533360:tid 533596] [client 74.249.245.134:43674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9e63UPuLYrePtEkUc2qgAAAOw"]
[Tue Jul 21 08:58:35.245966 2026] [security2:error] [pid 559070:tid 559281] [client 184.154.36.163:34132] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/wpforms-lite/assets/lib/jquery.validate.min.js"] [unique_id "al9e6yy1f1FtKC137xsWsgAAAeA"]
[Tue Jul 21 08:58:35.370992 2026] [security2:error] [pid 559070:tid 559272] [client 117.214.78.59:55740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9e6yy1f1FtKC137xsWtQAAAdc"]
[Tue Jul 21 08:58:35.371180 2026] [security2:error] [pid 559070:tid 559272] [client 117.214.78.59:55740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9e6yy1f1FtKC137xsWtQAAAdc"]
[Tue Jul 21 08:58:35.373075 2026] [core:error] [pid 559070:tid 559115] [remote 52.167.144.25:31847] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:58:35.373097 2026] [core:error] [pid 559070:tid 559115] [remote 52.167.144.25:31847] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:58:35.400364 2026] [security2:error] [pid 533360:tid 533598] [client 20.220.225.223:53471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/abcd.php"] [unique_id "al9e63UPuLYrePtEkUc2rQAAAO4"]
[Tue Jul 21 08:58:35.421937 2026] [security2:error] [pid 533360:tid 533403] [remote 162.19.246.208:40398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arielson.com.br"] [uri "/wp-login.php"] [unique_id "al9e63UPuLYrePtEkUc2rwAAwyc"]
[Tue Jul 21 08:58:35.515272 2026] [security2:error] [pid 559070:tid 559171] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6yy1f1FtKC137xsWwQABv2Q"]
[Tue Jul 21 08:58:35.573013 2026] [security2:error] [pid 559070:tid 559208] [client 20.151.10.161:49087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9e6yy1f1FtKC137xsWwwAAAZc"]
[Tue Jul 21 08:58:35.589582 2026] [security2:error] [pid 559070:tid 559193] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:include. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6yy1f1FtKC137xsWxAABv3o"]
[Tue Jul 21 08:58:35.647377 2026] [security2:error] [pid 559070:tid 559181] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6yy1f1FtKC137xsWxwABv24"]
[Tue Jul 21 08:58:35.656194 2026] [security2:error] [pid 559070:tid 559090] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6yy1f1FtKC137xsWyAABvxM"]
[Tue Jul 21 08:58:35.657879 2026] [security2:error] [pid 559070:tid 559153] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6yy1f1FtKC137xsWyQABv1I"]
[Tue Jul 21 08:58:35.670323 2026] [security2:error] [pid 559070:tid 559091] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6yy1f1FtKC137xsWygABvxQ"]
[Tue Jul 21 08:58:35.729900 2026] [security2:error] [pid 559070:tid 559134] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6yy1f1FtKC137xsWywABvz8"]
[Tue Jul 21 08:58:35.792371 2026] [security2:error] [pid 559070:tid 559086] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6yy1f1FtKC137xsWzQABvw8"]
[Tue Jul 21 08:58:35.871975 2026] [security2:error] [pid 559070:tid 559125] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e6yy1f1FtKC137xsW1AABvzY"]
[Tue Jul 21 08:58:35.907842 2026] [security2:error] [pid 559070:tid 559301] [client 5.78.140.151:49046] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mgugc.online"] [uri "/"] [unique_id "al9e6yy1f1FtKC137xsW1QAAAfQ"]
[Tue Jul 21 08:58:35.908085 2026] [security2:error] [pid 559070:tid 559268] [client 5.78.140.151:49058] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mgugc.online"] [uri "/"] [unique_id "al9e6yy1f1FtKC137xsW1gAAAdM"]
[Tue Jul 21 08:58:35.920672 2026] [security2:error] [pid 533360:tid 533545] [client 74.249.245.134:27308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/ws38.php"] [unique_id "al9e63UPuLYrePtEkUc2twAAALk"]
[Tue Jul 21 08:58:35.942354 2026] [rewrite:warn] [pid 533360:tid 533474] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:58:36.114885 2026] [security2:error] [pid 533360:tid 533583] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9e63UPuLYrePtEkUc2ugAAAN8"]
[Tue Jul 21 08:58:36.136377 2026] [security2:error] [pid 559070:tid 559311] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9e7Cy1f1FtKC137xsW3wAB_m0"]
[Tue Jul 21 08:58:36.281608 2026] [security2:error] [pid 533360:tid 533558] [client 20.197.192.193:62942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9e7HUPuLYrePtEkUc2vgAAAMY"]
[Tue Jul 21 08:58:36.381682 2026] [core:error] [pid 559070:tid 559259] [client 66.249.66.69:59370] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:58:36.381717 2026] [core:error] [pid 559070:tid 559259] [client 66.249.66.69:59370] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:58:36.413747 2026] [security2:error] [pid 559070:tid 559272] [client 20.197.192.193:3049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9e7Cy1f1FtKC137xsW6QAAAdc"]
[Tue Jul 21 08:58:36.429310 2026] [security2:error] [pid 559070:tid 559131] [remote 173.252.69.3:57748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.69.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9e7Cy1f1FtKC137xsW5AAB0Tw"]
[Tue Jul 21 08:58:36.438222 2026] [security2:error] [pid 559070:tid 559073] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7Cy1f1FtKC137xsW7AABvwI"]
[Tue Jul 21 08:58:36.494305 2026] [security2:error] [pid 559070:tid 559308] [client 194.99.104.35:57390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9e7Cy1f1FtKC137xsW7gAAAfs"]
[Tue Jul 21 08:58:36.494440 2026] [security2:error] [pid 559070:tid 559308] [client 194.99.104.35:57390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9e7Cy1f1FtKC137xsW7gAAAfs"]
[Tue Jul 21 08:58:36.580079 2026] [security2:error] [pid 559070:tid 559111] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7Cy1f1FtKC137xsW8QABvyg"]
[Tue Jul 21 08:58:36.592564 2026] [security2:error] [pid 559070:tid 559273] [client 194.99.104.35:36434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9e7Cy1f1FtKC137xsW8gAAAdg"]
[Tue Jul 21 08:58:36.592644 2026] [security2:error] [pid 559070:tid 559273] [client 194.99.104.35:36434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9e7Cy1f1FtKC137xsW8gAAAdg"]
[Tue Jul 21 08:58:36.639747 2026] [security2:error] [pid 559070:tid 559189] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7Cy1f1FtKC137xsW9QABv3Y"]
[Tue Jul 21 08:58:36.647029 2026] [security2:error] [pid 559070:tid 559157] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7Cy1f1FtKC137xsW9gABv1Y"]
[Tue Jul 21 08:58:36.672738 2026] [security2:error] [pid 559070:tid 559244] [client 20.197.192.193:62951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/dp.php"] [unique_id "al9e7Cy1f1FtKC137xsW9wAAAbs"]
[Tue Jul 21 08:58:36.725301 2026] [security2:error] [pid 559070:tid 559170] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7Cy1f1FtKC137xsW-AABv2M"]
[Tue Jul 21 08:58:36.779700 2026] [security2:error] [pid 559070:tid 559137] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7Cy1f1FtKC137xsW-wABv0I"]
[Tue Jul 21 08:58:36.787562 2026] [security2:error] [pid 559070:tid 559211] [client 20.197.192.193:62954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/old.php"] [unique_id "al9e7Cy1f1FtKC137xsW_QAAAZo"]
[Tue Jul 21 08:58:36.788105 2026] [security2:error] [pid 559070:tid 559161] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7Cy1f1FtKC137xsW_AABv1o"]
[Tue Jul 21 08:58:36.791944 2026] [security2:error] [pid 533360:tid 533539] [client 115.245.198.210:57249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9e7HUPuLYrePtEkUc2yQAAALM"]
[Tue Jul 21 08:58:36.792062 2026] [security2:error] [pid 533360:tid 533539] [client 115.245.198.210:57249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9e7HUPuLYrePtEkUc2yQAAALM"]
[Tue Jul 21 08:58:36.867433 2026] [security2:error] [pid 559070:tid 559150] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7Cy1f1FtKC137xsXAAABv08"]
[Tue Jul 21 08:58:36.956666 2026] [security2:error] [pid 559070:tid 559327] [client 41.89.234.2:13628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e7Cy1f1FtKC137xsXBwAAAg4"]
[Tue Jul 21 08:58:36.956855 2026] [security2:error] [pid 559070:tid 559327] [client 41.89.234.2:13628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e7Cy1f1FtKC137xsXBwAAAg4"]
[Tue Jul 21 08:58:37.057501 2026] [security2:error] [pid 559070:tid 559218] [client 184.154.36.163:34154] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/wpforms-lite/assets/js/frontend/wpforms.min.js"] [unique_id "al9e7Sy1f1FtKC137xsXCwAAAaE"]
[Tue Jul 21 08:58:37.068658 2026] [security2:error] [pid 559070:tid 559312] [client 20.197.192.193:62963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/ms-new.php"] [unique_id "al9e7Sy1f1FtKC137xsXDQAAAf8"]
[Tue Jul 21 08:58:37.234487 2026] [security2:error] [pid 559070:tid 559281] [client 20.197.192.193:62969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/track.php"] [unique_id "al9e7Sy1f1FtKC137xsXEQAAAeA"]
[Tue Jul 21 08:58:37.307079 2026] [security2:error] [pid 559070:tid 559324] [client 74.249.245.134:27204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/a7.php"] [unique_id "al9e7Sy1f1FtKC137xsXEwAAAgs"]
[Tue Jul 21 08:58:37.335852 2026] [security2:error] [pid 559070:tid 559242] [client 20.197.192.193:3025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/2352356666.php"] [unique_id "al9e7Sy1f1FtKC137xsXFAAAAbk"]
[Tue Jul 21 08:58:37.520222 2026] [security2:error] [pid 559070:tid 559244] [client 20.197.192.193:3043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/pn.php"] [unique_id "al9e7Sy1f1FtKC137xsXIAAAAbs"]
[Tue Jul 21 08:58:37.583773 2026] [security2:error] [pid 559070:tid 559201] [client 182.189.99.211:48547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e7Sy1f1FtKC137xsXIgAAAZA"]
[Tue Jul 21 08:58:37.584314 2026] [security2:error] [pid 559070:tid 559201] [client 182.189.99.211:48547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e7Sy1f1FtKC137xsXIgAAAZA"]
[Tue Jul 21 08:58:37.682317 2026] [security2:error] [pid 559070:tid 559118] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7Sy1f1FtKC137xsXLAABvy8"]
[Tue Jul 21 08:58:37.689336 2026] [security2:error] [pid 559070:tid 559174] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7Sy1f1FtKC137xsXLQABv2c"]
[Tue Jul 21 08:58:37.691190 2026] [security2:error] [pid 559070:tid 559120] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7Sy1f1FtKC137xsXLgABvzE"]
[Tue Jul 21 08:58:37.751727 2026] [security2:error] [pid 559070:tid 559301] [client 20.197.192.193:62967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9e7Sy1f1FtKC137xsXMAAAAfQ"]
[Tue Jul 21 08:58:37.834517 2026] [security2:error] [pid 559070:tid 559194] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7Sy1f1FtKC137xsXMQABv3s"]
[Tue Jul 21 08:58:37.835493 2026] [security2:error] [pid 559070:tid 559127] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7Sy1f1FtKC137xsXMgABvzg"]
[Tue Jul 21 08:58:37.835896 2026] [security2:error] [pid 559070:tid 559105] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7Sy1f1FtKC137xsXMwABvyI"]
[Tue Jul 21 08:58:37.846581 2026] [security2:error] [pid 559070:tid 559282] [client 20.197.192.193:3047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/dr.php"] [unique_id "al9e7Sy1f1FtKC137xsXNAAAAeE"]
[Tue Jul 21 08:58:38.017580 2026] [security2:error] [pid 559070:tid 559256] [client 20.197.192.193:62960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/2x.php"] [unique_id "al9e7iy1f1FtKC137xsXPgAAAcc"]
[Tue Jul 21 08:58:38.113975 2026] [security2:error] [pid 559070:tid 559295] [client 74.249.245.134:27280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/classsmtps.php"] [unique_id "al9e7iy1f1FtKC137xsXQAAAAe4"]
[Tue Jul 21 08:58:38.178271 2026] [security2:error] [pid 559070:tid 559200] [client 20.197.192.193:3041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/kq1.php"] [unique_id "al9e7iy1f1FtKC137xsXQgAAAY8"]
[Tue Jul 21 08:58:38.309959 2026] [security2:error] [pid 533360:tid 533422] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9e7nUPuLYrePtEkUc23gAArDo"]
[Tue Jul 21 08:58:38.310177 2026] [security2:error] [pid 533360:tid 533532] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9e7nUPuLYrePtEkUc23gAArDo"]
[Tue Jul 21 08:58:38.372753 2026] [security2:error] [pid 559070:tid 559299] [client 20.197.192.193:3046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/zzz.php"] [unique_id "al9e7iy1f1FtKC137xsXSwAAAfI"]
[Tue Jul 21 08:58:38.403554 2026] [security2:error] [pid 559070:tid 559145] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:src. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7iy1f1FtKC137xsXTAABv0o"]
[Tue Jul 21 08:58:38.629645 2026] [security2:error] [pid 559070:tid 559181] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:src. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7iy1f1FtKC137xsXWAABv24"]
[Tue Jul 21 08:58:38.649740 2026] [security2:error] [pid 559070:tid 559153] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at ARGS:src. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7iy1f1FtKC137xsXWgABv1I"]
[Tue Jul 21 08:58:38.695380 2026] [security2:error] [pid 559070:tid 559086] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7iy1f1FtKC137xsXXQABvw8"]
[Tue Jul 21 08:58:38.727036 2026] [security2:error] [pid 559070:tid 559302] [client 20.197.192.193:62940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/wicked.php"] [unique_id "al9e7iy1f1FtKC137xsXXwAAAfU"]
[Tue Jul 21 08:58:38.773787 2026] [security2:error] [pid 559070:tid 559159] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7iy1f1FtKC137xsXYQABv1g"]
[Tue Jul 21 08:58:38.789681 2026] [security2:error] [pid 559070:tid 559076] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7iy1f1FtKC137xsXYwABvwU"]
[Tue Jul 21 08:58:38.836053 2026] [security2:error] [pid 559070:tid 559113] [remote 103.215.74.213:50770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.74.215.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "paginadoproduto-oficial.com.br"] [uri "/"] [unique_id "al9e7iy1f1FtKC137xsXZAABvyo"]
[Tue Jul 21 08:58:38.839699 2026] [security2:error] [pid 559070:tid 559286] [client 20.197.192.193:62928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/edit.php"] [unique_id "al9e7iy1f1FtKC137xsXZQAAAeU"]
[Tue Jul 21 08:58:38.936530 2026] [security2:error] [pid 533360:tid 533588] [client 20.151.10.161:48597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9e7nUPuLYrePtEkUc28AAAAOQ"]
[Tue Jul 21 08:58:38.961838 2026] [security2:error] [pid 559070:tid 559281] [client 20.197.192.193:62971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/kua.php"] [unique_id "al9e7iy1f1FtKC137xsXZgAAAeA"]
[Tue Jul 21 08:58:38.961879 2026] [security2:error] [pid 559070:tid 559231] [client 20.220.225.223:53496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/jj.php"] [unique_id "al9e7iy1f1FtKC137xsXZwAAAa4"]
[Tue Jul 21 08:58:39.010496 2026] [security2:error] [pid 533360:tid 533601] [client 184.154.36.163:43908] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/wpforms-lite/assets/js/frontend/fields/address.min.js"] [unique_id "al9e73UPuLYrePtEkUc28wAAAPE"]
[Tue Jul 21 08:58:39.171887 2026] [security2:error] [pid 559070:tid 559262] [client 20.197.192.193:62931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/ez.php"] [unique_id "al9e7yy1f1FtKC137xsXbAAAAc0"]
[Tue Jul 21 08:58:39.215624 2026] [security2:error] [pid 559070:tid 559293] [client 20.151.10.161:55864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/goods.php"] [unique_id "al9e7yy1f1FtKC137xsXbgAAAew"]
[Tue Jul 21 08:58:39.391382 2026] [security2:error] [pid 533360:tid 533604] [client 20.197.192.193:62962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/fz.php"] [unique_id "al9e73UPuLYrePtEkUc2_AAAAPQ"]
[Tue Jul 21 08:58:39.397823 2026] [security2:error] [pid 559070:tid 559312] [client 59.95.197.55:60985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e7yy1f1FtKC137xsXdAAAAf8"]
[Tue Jul 21 08:58:39.398035 2026] [security2:error] [pid 559070:tid 559312] [client 59.95.197.55:60985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e7yy1f1FtKC137xsXdAAAAf8"]
[Tue Jul 21 08:58:39.419966 2026] [security2:error] [pid 533360:tid 533546] [client 74.249.245.134:27258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/rip.php"] [unique_id "al9e73UPuLYrePtEkUc2_QAAALo"]
[Tue Jul 21 08:58:39.480142 2026] [security2:error] [pid 559070:tid 559313] [client 216.73.160.39:60721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "daianapontes.com.br"] [uri "/wp-login.php"] [unique_id "al9e7yy1f1FtKC137xsXcAAAAgA"]
[Tue Jul 21 08:58:39.490191 2026] [security2:error] [pid 559070:tid 559227] [client 20.197.192.193:62957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/la.php"] [unique_id "al9e7yy1f1FtKC137xsXdQAAAao"]
[Tue Jul 21 08:58:39.541856 2026] [security2:error] [pid 533360:tid 533612] [client 65.21.113.253:36798] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9e73UPuLYrePtEkUc2_wAAAPw"]
[Tue Jul 21 08:58:39.542073 2026] [security2:error] [pid 533360:tid 533553] [client 20.197.192.193:3008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9e73UPuLYrePtEkUc3AAAAAME"]
[Tue Jul 21 08:58:39.613994 2026] [security2:error] [pid 559070:tid 559218] [client 20.197.192.193:62919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/inso.php"] [unique_id "al9e7yy1f1FtKC137xsXfAAAAaE"]
[Tue Jul 21 08:58:39.654088 2026] [security2:error] [pid 533360:tid 533405] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e73UPuLYrePtEkUc3AwAAvyk"]
[Tue Jul 21 08:58:39.654227 2026] [security2:error] [pid 533360:tid 533551] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e73UPuLYrePtEkUc3AwAAvyk"]
[Tue Jul 21 08:58:39.671969 2026] [security2:error] [pid 533360:tid 533524] [client 20.197.192.193:3036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/wpx.php"] [unique_id "al9e73UPuLYrePtEkUc3BAAAAKQ"]
[Tue Jul 21 08:58:39.712381 2026] [security2:error] [pid 559070:tid 559318] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9e7yy1f1FtKC137xsXewAAAgU"]
[Tue Jul 21 08:58:39.712902 2026] [security2:error] [pid 533360:tid 533538] [client 20.197.192.193:3030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/berlin.php"] [unique_id "al9e73UPuLYrePtEkUc3CAAAALI"]
[Tue Jul 21 08:58:39.797886 2026] [security2:error] [pid 533360:tid 533552] [client 20.197.192.193:62918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/billur.php"] [unique_id "al9e73UPuLYrePtEkUc3CgAAAMA"]
[Tue Jul 21 08:58:39.803493 2026] [core:error] [pid 533360:tid 533435] [remote 40.77.167.16:18110] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:58:39.803515 2026] [core:error] [pid 533360:tid 533435] [remote 40.77.167.16:18110] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:58:39.875986 2026] [security2:error] [pid 533360:tid 533594] [client 20.197.192.193:62973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/mimpi.php"] [unique_id "al9e73UPuLYrePtEkUc3DAAAAOo"]
[Tue Jul 21 08:58:39.936761 2026] [security2:error] [pid 533360:tid 533595] [client 20.197.192.193:3022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/dp.php"] [unique_id "al9e73UPuLYrePtEkUc3DQAAAOs"]
[Tue Jul 21 08:58:39.966536 2026] [security2:error] [pid 559070:tid 559279] [client 20.197.192.193:62934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/bootstrap.php"] [unique_id "al9e7yy1f1FtKC137xsXfQAAAd4"]
[Tue Jul 21 08:58:40.042334 2026] [security2:error] [pid 559070:tid 559259] [client 20.197.192.193:62943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/wp-editor.php"] [unique_id "al9e8Cy1f1FtKC137xsXfwAAAco"]
[Tue Jul 21 08:58:40.113532 2026] [security2:error] [pid 559070:tid 559200] [client 20.197.192.193:3018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/cro.php"] [unique_id "al9e8Cy1f1FtKC137xsXgQAAAY8"]
[Tue Jul 21 08:58:40.152109 2026] [security2:error] [pid 533360:tid 533494] [client 20.197.192.193:62975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/cron-tab.php"] [unique_id "al9e8HUPuLYrePtEkUc3EwAAAIY"]
[Tue Jul 21 08:58:40.222384 2026] [security2:error] [pid 533360:tid 533555] [client 20.197.192.193:62964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/koiy.php"] [unique_id "al9e8HUPuLYrePtEkUc3FwAAAMM"]
[Tue Jul 21 08:58:40.274504 2026] [security2:error] [pid 559070:tid 559325] [client 20.197.192.193:3053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/hp2.php"] [unique_id "al9e8Cy1f1FtKC137xsXhAAAAgw"]
[Tue Jul 21 08:58:40.303009 2026] [security2:error] [pid 533360:tid 533573] [client 20.197.192.193:62974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/hp3.php"] [unique_id "al9e8HUPuLYrePtEkUc3GAAAANU"]
[Tue Jul 21 08:58:40.364131 2026] [security2:error] [pid 533360:tid 533517] [client 20.197.192.193:3059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/aa1.php"] [unique_id "al9e8HUPuLYrePtEkUc3GQAAAJ0"]
[Tue Jul 21 08:58:40.526710 2026] [security2:error] [pid 559070:tid 559293] [client 20.197.192.193:3027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/acew67.php"] [unique_id "al9e8Cy1f1FtKC137xsXrgAAAew"]
[Tue Jul 21 08:58:40.635521 2026] [security2:error] [pid 533360:tid 533611] [client 74.249.245.134:27285] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "ia.bavos.com.br"] [uri "/1.php"] [unique_id "al9e8HUPuLYrePtEkUc3IwAAAPs"]
[Tue Jul 21 08:58:40.635637 2026] [security2:error] [pid 533360:tid 533611] [client 74.249.245.134:27285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/1.php"] [unique_id "al9e8HUPuLYrePtEkUc3IwAAAPs"]
[Tue Jul 21 08:58:40.653691 2026] [security2:error] [pid 559070:tid 559326] [client 65.21.113.253:45994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9e8Cy1f1FtKC137xsXgwAAAg0"]
[Tue Jul 21 08:58:40.668453 2026] [security2:error] [pid 533360:tid 533561] [client 198.44.157.162:44582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9e8HUPuLYrePtEkUc3JAAAAMk"]
[Tue Jul 21 08:58:40.668560 2026] [security2:error] [pid 533360:tid 533561] [client 198.44.157.162:44582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9e8HUPuLYrePtEkUc3JAAAAMk"]
[Tue Jul 21 08:58:40.745852 2026] [security2:error] [pid 533360:tid 533599] [client 20.197.192.193:62927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/bscclapb.php"] [unique_id "al9e8HUPuLYrePtEkUc3KAAAAO8"]
[Tue Jul 21 08:58:40.845144 2026] [security2:error] [pid 533360:tid 533529] [client 20.197.192.193:1445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/else1.php"] [unique_id "al9e8HUPuLYrePtEkUc3LAAAAKk"]
[Tue Jul 21 08:58:40.895568 2026] [security2:error] [pid 559070:tid 559254] [client 20.197.192.193:62920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/tkikikoko.php"] [unique_id "al9e8Cy1f1FtKC137xsXswAAAcU"]
[Tue Jul 21 08:58:40.900073 2026] [security2:error] [pid 533360:tid 533535] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9e8HUPuLYrePtEkUc3KwAAAK8"]
[Tue Jul 21 08:58:40.900546 2026] [security2:error] [pid 533360:tid 533523] [client 184.154.36.163:43922] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "hoterplast.com.br"] [uri "/recursos"] [unique_id "al9e8HUPuLYrePtEkUc3KQAAAKM"]
[Tue Jul 21 08:58:40.926970 2026] [security2:error] [pid 533360:tid 533551] [client 20.197.192.193:1445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9e8HUPuLYrePtEkUc3LQAAAL8"]
[Tue Jul 21 08:58:41.009387 2026] [security2:error] [pid 559070:tid 559316] [client 20.197.192.193:3045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/wp-css.php"] [unique_id "al9e8Sy1f1FtKC137xsXtAAAAgM"]
[Tue Jul 21 08:58:41.029931 2026] [security2:error] [pid 533360:tid 533502] [client 20.197.192.193:62935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/wp-explorer.php"] [unique_id "al9e8XUPuLYrePtEkUc3LwAAAI4"]
[Tue Jul 21 08:58:41.154396 2026] [security2:error] [pid 533360:tid 533594] [client 20.197.192.193:3062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/akismet.php"] [unique_id "al9e8XUPuLYrePtEkUc3NgAAAOo"]
[Tue Jul 21 08:58:41.249172 2026] [security2:error] [pid 533360:tid 533595] [client 20.197.192.193:3047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/ace2.php"] [unique_id "al9e8XUPuLYrePtEkUc3OAAAAOs"]
[Tue Jul 21 08:58:41.275976 2026] [security2:error] [pid 559070:tid 559275] [client 20.197.192.193:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.sogastro.com.br"] [uri "/ms.php"] [unique_id "al9e8Sy1f1FtKC137xsXuAAAAdo"]
[Tue Jul 21 08:58:41.306555 2026] [security2:error] [pid 533360:tid 533532] [client 20.151.10.161:51033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ms-edit.php"] [unique_id "al9e8XUPuLYrePtEkUc3OwAAAKw"]
[Tue Jul 21 08:58:41.813167 2026] [security2:error] [pid 559070:tid 559259] [client 74.249.245.134:27277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/chosen.php"] [unique_id "al9e8Sy1f1FtKC137xsXwgAAAco"]
[Tue Jul 21 08:58:41.847961 2026] [security2:error] [pid 533360:tid 533504] [client 20.220.225.223:58373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/old.php"] [unique_id "al9e8XUPuLYrePtEkUc3RAAAAJA"]
[Tue Jul 21 08:58:41.863281 2026] [security2:error] [pid 533360:tid 533533] [client 20.220.225.223:27145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/xyn.php"] [unique_id "al9e8XUPuLYrePtEkUc3RQAAAK0"]
[Tue Jul 21 08:58:41.987082 2026] [security2:error] [pid 559070:tid 559267] [client 114.198.138.124:59056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9e8Sy1f1FtKC137xsXxAAAAdI"]
[Tue Jul 21 08:58:41.987198 2026] [security2:error] [pid 559070:tid 559267] [client 114.198.138.124:59056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9e8Sy1f1FtKC137xsXxAAAAdI"]
[Tue Jul 21 08:58:41.996120 2026] [security2:error] [pid 559070:tid 559281] [client 184.154.36.163:43928] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/wpforms-lite/assets/lib/punycode.min.js"] [unique_id "al9e8Sy1f1FtKC137xsXxQAAAeA"]
[Tue Jul 21 08:58:42.019463 2026] [security2:error] [pid 559070:tid 559226] [client 198.44.157.162:49554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9e8iy1f1FtKC137xsXxwAAAak"]
[Tue Jul 21 08:58:42.019565 2026] [security2:error] [pid 559070:tid 559226] [client 198.44.157.162:49554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9e8iy1f1FtKC137xsXxwAAAak"]
[Tue Jul 21 08:58:42.128387 2026] [security2:error] [pid 533360:tid 533441] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e8nUPuLYrePtEkUc3TQAAtE0"]
[Tue Jul 21 08:58:42.128538 2026] [security2:error] [pid 533360:tid 533540] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e8nUPuLYrePtEkUc3TQAAtE0"]
[Tue Jul 21 08:58:42.238276 2026] [security2:error] [pid 533360:tid 533606] [client 20.151.10.161:49113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/gettest.php"] [unique_id "al9e8nUPuLYrePtEkUc3TwAAAPY"]
[Tue Jul 21 08:58:42.251204 2026] [core:error] [pid 559070:tid 559207] [client 66.249.66.74:35293] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:58:42.251229 2026] [core:error] [pid 559070:tid 559207] [client 66.249.66.74:35293] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:58:42.304672 2026] [security2:error] [pid 533360:tid 533562] [client 20.220.225.223:55802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/dragonshell.php"] [unique_id "al9e8nUPuLYrePtEkUc3UQAAAMo"]
[Tue Jul 21 08:58:42.571331 2026] [security2:error] [pid 559070:tid 559235] [client 184.154.36.163:43944] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-includes/js/jquery/jquery.min.js"] [unique_id "al9e8iy1f1FtKC137xsX0QAAAbI"]
[Tue Jul 21 08:58:42.803986 2026] [security2:error] [pid 559070:tid 559327] [client 20.220.225.223:34463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/pn.php"] [unique_id "al9e8iy1f1FtKC137xsX2AAAAg4"]
[Tue Jul 21 08:58:42.983788 2026] [security2:error] [pid 559070:tid 559200] [client 168.167.81.163:65061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9e8iy1f1FtKC137xsX2QAAAY8"]
[Tue Jul 21 08:58:42.983914 2026] [security2:error] [pid 559070:tid 559200] [client 168.167.81.163:65061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9e8iy1f1FtKC137xsX2QAAAY8"]
[Tue Jul 21 08:58:43.195679 2026] [security2:error] [pid 559070:tid 559248] [client 74.249.245.134:27279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/css.php"] [unique_id "al9e8yy1f1FtKC137xsX3wAAAb8"]
[Tue Jul 21 08:58:43.360768 2026] [security2:error] [pid 559070:tid 559153] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9e8yy1f1FtKC137xsX4wABkVI"]
[Tue Jul 21 08:58:43.360990 2026] [security2:error] [pid 559070:tid 559202] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9e8yy1f1FtKC137xsX4wABkVI"]
[Tue Jul 21 08:58:43.474968 2026] [security2:error] [pid 559070:tid 559221] [client 184.154.36.163:43956] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/wpforms-lite/assets/js/frontend/analytics.min.js"] [unique_id "al9e8yy1f1FtKC137xsX5gAAAaQ"]
[Tue Jul 21 08:58:43.720677 2026] [security2:error] [pid 533360:tid 533391] [remote 173.252.95.27:53968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9e83UPuLYrePtEkUc3bgAAjxs"]
[Tue Jul 21 08:58:43.818607 2026] [security2:error] [pid 559070:tid 559243] [client 113.22.144.139:63827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e8yy1f1FtKC137xsX8QAAAbo"]
[Tue Jul 21 08:58:43.819340 2026] [security2:error] [pid 559070:tid 559243] [client 113.22.144.139:63827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e8yy1f1FtKC137xsX8QAAAbo"]
[Tue Jul 21 08:58:43.879261 2026] [security2:error] [pid 559070:tid 559280] [client 20.220.225.223:30710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/ms-new.php"] [unique_id "al9e8yy1f1FtKC137xsX8wAAAd8"]
[Tue Jul 21 08:58:44.040782 2026] [security2:error] [pid 559070:tid 559271] [client 20.151.10.161:55874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/222.php"] [unique_id "al9e9Cy1f1FtKC137xsX9wAAAdY"]
[Tue Jul 21 08:58:44.356205 2026] [security2:error] [pid 559070:tid 559180] [remote 51.195.183.220:52850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "engeconconstrucoes.com.br"] [uri "/robots.txt"] [unique_id "al9e9Cy1f1FtKC137xsYAwABv20"]
[Tue Jul 21 08:58:44.356455 2026] [security2:error] [pid 559070:tid 559248] [client 51.195.183.220:52850] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "engeconconstrucoes.com.br"] [uri "/robots.txt"] [unique_id "al9e9Cy1f1FtKC137xsYAwABv20"]
[Tue Jul 21 08:58:44.659096 2026] [security2:error] [pid 533360:tid 533619] [client 20.220.225.223:53487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/byp8.php"] [unique_id "al9e9HUPuLYrePtEkUc3fAAAAQM"]
[Tue Jul 21 08:58:45.025366 2026] [security2:error] [pid 533360:tid 533546] [client 198.44.157.162:44584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9e9XUPuLYrePtEkUc3hwAAALo"]
[Tue Jul 21 08:58:45.025460 2026] [security2:error] [pid 533360:tid 533546] [client 198.44.157.162:44584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "topudi.online"] [uri "/xmlrpc.php"] [unique_id "al9e9XUPuLYrePtEkUc3hwAAALo"]
[Tue Jul 21 08:58:45.073959 2026] [security2:error] [pid 533360:tid 533500] [client 173.252.95.3:40512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9e9XUPuLYrePtEkUc3iAAAAIw"]
[Tue Jul 21 08:58:45.425568 2026] [security2:error] [pid 559070:tid 559090] [remote 47.128.124.74:57546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "prissedermatologia.com.br"] [uri "/5-perguntas-frequentes-sobre-preenchimento-com-acido-hialuronico/"] [unique_id "al9e9Sy1f1FtKC137xsYFwABpxM"]
[Tue Jul 21 08:58:45.607543 2026] [security2:error] [pid 559070:tid 559321] [client 65.21.113.253:36804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9e9Sy1f1FtKC137xsYGQAAAgg"]
[Tue Jul 21 08:58:45.721621 2026] [security2:error] [pid 559070:tid 559129] [remote 68.178.160.25:41984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spazziojardins.com"] [uri "/wp-login.php"] [unique_id "al9e9Sy1f1FtKC137xsYHQABqDo"]
[Tue Jul 21 08:58:45.860928 2026] [security2:error] [pid 559070:tid 559200] [client 117.214.78.59:56186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9e9Sy1f1FtKC137xsYIQAAAY8"]
[Tue Jul 21 08:58:45.861608 2026] [security2:error] [pid 559070:tid 559200] [client 117.214.78.59:56186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9e9Sy1f1FtKC137xsYIQAAAY8"]
[Tue Jul 21 08:58:45.910398 2026] [security2:error] [pid 559070:tid 559164] [remote 51.222.168.194:16806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "engeconconstrucoes.com.br"] [uri "/"] [unique_id "al9e9Sy1f1FtKC137xsYJAABvl0"]
[Tue Jul 21 08:58:45.910503 2026] [security2:error] [pid 559070:tid 559247] [client 51.222.168.194:16806] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "engeconconstrucoes.com.br"] [uri "/"] [unique_id "al9e9Sy1f1FtKC137xsYJAABvl0"]
[Tue Jul 21 08:58:46.121946 2026] [security2:error] [pid 559070:tid 559241] [client 74.249.245.134:27207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/php.php"] [unique_id "al9e9iy1f1FtKC137xsYKQAAAbg"]
[Tue Jul 21 08:58:46.628985 2026] [security2:error] [pid 559070:tid 559204] [client 20.151.10.161:51061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/cgi-bin/index.php"] [unique_id "al9e9iy1f1FtKC137xsYNQAAAZM"]
[Tue Jul 21 08:58:46.719095 2026] [security2:error] [pid 559070:tid 559207] [client 65.21.113.253:46002] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9e9iy1f1FtKC137xsYLQAAAZY"]
[Tue Jul 21 08:58:46.780151 2026] [security2:error] [pid 533360:tid 533575] [client 185.213.175.37:51634] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/"] [unique_id "al9e9nUPuLYrePtEkUc3pAAAANc"]
[Tue Jul 21 08:58:46.909208 2026] [security2:error] [pid 533360:tid 533545] [client 20.220.225.223:34469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9e9nUPuLYrePtEkUc3rAAAALk"]
[Tue Jul 21 08:58:47.075129 2026] [security2:error] [pid 559070:tid 559234] [client 117.210.181.114:47297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.181.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9e9yy1f1FtKC137xsYPgAAAbE"]
[Tue Jul 21 08:58:47.075488 2026] [security2:error] [pid 559070:tid 559234] [client 117.210.181.114:47297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9e9yy1f1FtKC137xsYPgAAAbE"]
[Tue Jul 21 08:58:47.427765 2026] [security2:error] [pid 533360:tid 533488] [remote 167.71.218.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "falarmelhor.com.br"] [uri "/wp-login.php"] [unique_id "al9e93UPuLYrePtEkUc3uwAAvXw"]
[Tue Jul 21 08:58:47.450864 2026] [security2:error] [pid 559070:tid 559293] [client 41.89.234.2:63742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e9yy1f1FtKC137xsYRgAAAew"]
[Tue Jul 21 08:58:47.450945 2026] [security2:error] [pid 559070:tid 559293] [client 41.89.234.2:63742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e9yy1f1FtKC137xsYRgAAAew"]
[Tue Jul 21 08:58:47.504171 2026] [security2:error] [pid 559070:tid 559281] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9e9yy1f1FtKC137xsYQQAB4Cg"]
[Tue Jul 21 08:58:47.546619 2026] [security2:error] [pid 533360:tid 533512] [client 154.182.128.22:51967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.128.182.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9e93UPuLYrePtEkUc3twAAAJg"]
[Tue Jul 21 08:58:47.546853 2026] [security2:error] [pid 533360:tid 533512] [client 154.182.128.22:51967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9e93UPuLYrePtEkUc3twAAAJg"]
[Tue Jul 21 08:58:47.600487 2026] [security2:error] [pid 559070:tid 559218] [client 104.238.222.26:62790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9e9yy1f1FtKC137xsYSAAAAaE"], referer: https://t.co/
[Tue Jul 21 08:58:47.939001 2026] [security2:error] [pid 533360:tid 533524] [client 104.238.222.26:49424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9e93UPuLYrePtEkUc3wQAAAKQ"], referer: https://www.google.com/
[Tue Jul 21 08:58:48.229199 2026] [security2:error] [pid 559070:tid 559220] [client 20.220.225.223:55756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/user.php"] [unique_id "al9e-Cy1f1FtKC137xsYVQAAAaM"]
[Tue Jul 21 08:58:48.549233 2026] [security2:error] [pid 559070:tid 559119] [remote 68.178.160.25:41998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9e-Cy1f1FtKC137xsYXQABojA"]
[Tue Jul 21 08:58:48.780865 2026] [security2:error] [pid 559070:tid 559226] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9e-Cy1f1FtKC137xsYZQAAAak"]
[Tue Jul 21 08:58:48.781601 2026] [security2:error] [pid 533360:tid 533494] [client 184.154.36.163:33656] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoterplast.com.br"] [uri "/"] [unique_id "al9e-HUPuLYrePtEkUc30gAAAIY"]
[Tue Jul 21 08:58:48.829257 2026] [security2:error] [pid 559070:tid 559166] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9e-Cy1f1FtKC137xsYZwABsV8"]
[Tue Jul 21 08:58:48.829412 2026] [security2:error] [pid 559070:tid 559234] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9e-Cy1f1FtKC137xsYZwABsV8"]
[Tue Jul 21 08:58:49.169771 2026] [security2:error] [pid 559070:tid 559299] [client 74.249.245.134:27302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/aa.php"] [unique_id "al9e-Sy1f1FtKC137xsYcgAAAfI"]
[Tue Jul 21 08:58:49.210944 2026] [proxy:error] [pid 533360:tid 533543] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:58:49.211021 2026] [proxy_http:error] [pid 533360:tid 533543] [client 134.199.234.66:49044] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:58:49.211506 2026] [proxy:error] [pid 533360:tid 533543] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:58:49.211534 2026] [proxy_http:error] [pid 533360:tid 533543] [client 134.199.234.66:49044] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:58:49.364250 2026] [security2:error] [pid 559070:tid 559204] [client 20.151.10.161:49062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/simple.php"] [unique_id "al9e-Sy1f1FtKC137xsYdQAAAZM"]
[Tue Jul 21 08:58:49.381308 2026] [security2:error] [pid 533360:tid 533595] [client 198.44.157.162:59514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9e-XUPuLYrePtEkUc33gAAAOs"]
[Tue Jul 21 08:58:49.381410 2026] [security2:error] [pid 533360:tid 533595] [client 198.44.157.162:59514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fecinc.org"] [uri "/xmlrpc.php"] [unique_id "al9e-XUPuLYrePtEkUc33gAAAOs"]
[Tue Jul 21 08:58:49.459234 2026] [security2:error] [pid 559070:tid 559217] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9e-Sy1f1FtKC137xsYdgAAAaA"]
[Tue Jul 21 08:58:49.460036 2026] [security2:error] [pid 533360:tid 533561] [client 184.154.36.163:33664] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoterplast.com.br"] [uri "/"] [unique_id "al9e-XUPuLYrePtEkUc33AAAAMk"]
[Tue Jul 21 08:58:49.575366 2026] [proxy:error] [pid 559070:tid 559216] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:58:49.575447 2026] [proxy_http:error] [pid 559070:tid 559216] [client 134.199.234.66:49046] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.eagastronomia.com.br/
[Tue Jul 21 08:58:49.575922 2026] [proxy:error] [pid 559070:tid 559216] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:58:49.575952 2026] [proxy_http:error] [pid 559070:tid 559216] [client 134.199.234.66:49046] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.eagastronomia.com.br/
[Tue Jul 21 08:58:49.605618 2026] [security2:error] [pid 559070:tid 559327] [client 20.220.225.223:34290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wpx.php"] [unique_id "al9e-Sy1f1FtKC137xsYewAAAg4"]
[Tue Jul 21 08:58:49.825088 2026] [security2:error] [pid 533360:tid 533540] [client 59.95.197.55:61468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e-XUPuLYrePtEkUc36wAAALQ"]
[Tue Jul 21 08:58:49.825196 2026] [security2:error] [pid 533360:tid 533540] [client 59.95.197.55:61468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e-XUPuLYrePtEkUc36wAAALQ"]
[Tue Jul 21 08:58:49.955974 2026] [security2:error] [pid 559070:tid 559236] [client 20.151.10.161:55906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/BDKR28WP.php"] [unique_id "al9e-Sy1f1FtKC137xsYgwAAAbM"]
[Tue Jul 21 08:58:50.099837 2026] [security2:error] [pid 559070:tid 559275] [client 20.220.225.223:53481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/wp-mt.php"] [unique_id "al9e-iy1f1FtKC137xsYiAAAAdo"]
[Tue Jul 21 08:58:50.150524 2026] [security2:error] [pid 559070:tid 559215] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9e-iy1f1FtKC137xsYhQAAAZ4"]
[Tue Jul 21 08:58:50.170214 2026] [security2:error] [pid 559070:tid 559151] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e-iy1f1FtKC137xsYiwABvlA"]
[Tue Jul 21 08:58:50.170397 2026] [security2:error] [pid 559070:tid 559247] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e-iy1f1FtKC137xsYiwABvlA"]
[Tue Jul 21 08:58:50.303220 2026] [proxy:error] [pid 533360:tid 533537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:58:50.303286 2026] [proxy_http:error] [pid 533360:tid 533537] [client 134.199.234.66:57672] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:58:50.305141 2026] [proxy:error] [pid 533360:tid 533537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:58:50.305195 2026] [proxy_http:error] [pid 533360:tid 533537] [client 134.199.234.66:57672] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:58:50.861613 2026] [security2:error] [pid 559070:tid 559272] [client 104.238.222.26:60846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.222.238.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9e-iy1f1FtKC137xsYnwAAAdc"], referer: https://www.google.com/search?q=wordpress
[Tue Jul 21 08:58:50.863134 2026] [security2:error] [pid 559070:tid 559243] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9e-iy1f1FtKC137xsYngAAAbo"]
[Tue Jul 21 08:58:51.011082 2026] [security2:error] [pid 559070:tid 559197] [remote 100.42.189.89:51520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guiasaudeplena.com.br.ciclododinheiro.com"] [uri "/wp-login.php"] [unique_id "al9e-yy1f1FtKC137xsYpgAB1X4"]
[Tue Jul 21 08:58:51.114917 2026] [security2:error] [pid 533360:tid 533606] [client 20.151.10.161:49069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/xxx.php"] [unique_id "al9e-3UPuLYrePtEkUc4BwAAAPY"]
[Tue Jul 21 08:58:51.129396 2026] [security2:error] [pid 559070:tid 559301] [client 182.189.99.211:48056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e-yy1f1FtKC137xsYqQAAAfQ"]
[Tue Jul 21 08:58:51.130116 2026] [security2:error] [pid 559070:tid 559301] [client 182.189.99.211:48056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e-yy1f1FtKC137xsYqQAAAfQ"]
[Tue Jul 21 08:58:51.144306 2026] [security2:error] [pid 533360:tid 533508] [client 65.21.113.253:43940] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9e-3UPuLYrePtEkUc4CAAAAJQ"]
[Tue Jul 21 08:58:51.586903 2026] [security2:error] [pid 559070:tid 559281] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9e-yy1f1FtKC137xsYrQAAAeA"]
[Tue Jul 21 08:58:51.650551 2026] [security2:error] [pid 559070:tid 559304] [client 103.59.206.240:31376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e-yy1f1FtKC137xsYtQAAAfc"]
[Tue Jul 21 08:58:51.650657 2026] [security2:error] [pid 559070:tid 559304] [client 103.59.206.240:31376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e-yy1f1FtKC137xsYtQAAAfc"]
[Tue Jul 21 08:58:52.003901 2026] [security2:error] [pid 559070:tid 559236] [client 194.99.104.35:45098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9e_Cy1f1FtKC137xsYvAAAAbM"]
[Tue Jul 21 08:58:52.004010 2026] [security2:error] [pid 559070:tid 559236] [client 194.99.104.35:45098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9e_Cy1f1FtKC137xsYvAAAAbM"]
[Tue Jul 21 08:58:52.217032 2026] [security2:error] [pid 533360:tid 533500] [client 65.21.113.253:40910] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9e-3UPuLYrePtEkUc4FQAAAIw"]
[Tue Jul 21 08:58:52.313355 2026] [security2:error] [pid 559070:tid 559327] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9e_Cy1f1FtKC137xsYvwAAAg4"]
[Tue Jul 21 08:58:52.410629 2026] [security2:error] [pid 559070:tid 559215] [client 74.249.245.134:27223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/bolt.php"] [unique_id "al9e_Cy1f1FtKC137xsYwgAAAZ4"]
[Tue Jul 21 08:58:52.462119 2026] [security2:error] [pid 533360:tid 533501] [client 114.198.138.124:59635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9e_HUPuLYrePtEkUc4IAAAAI0"]
[Tue Jul 21 08:58:52.462263 2026] [security2:error] [pid 533360:tid 533501] [client 114.198.138.124:59635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9e_HUPuLYrePtEkUc4IAAAAI0"]
[Tue Jul 21 08:58:52.636327 2026] [security2:error] [pid 533360:tid 533370] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e_HUPuLYrePtEkUc4JgAAmwY"]
[Tue Jul 21 08:58:52.636531 2026] [security2:error] [pid 533360:tid 533515] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e_HUPuLYrePtEkUc4JgAAmwY"]
[Tue Jul 21 08:58:53.219730 2026] [security2:error] [pid 559070:tid 559181] [remote 104.207.38.128:42029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.38.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9e_Sy1f1FtKC137xsYzgABqm4"]
[Tue Jul 21 08:58:53.655753 2026] [security2:error] [pid 559070:tid 559225] [client 20.151.10.161:49139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/hypo.php"] [unique_id "al9e_Sy1f1FtKC137xsY2AAAAag"]
[Tue Jul 21 08:58:53.762261 2026] [security2:error] [pid 559070:tid 559076] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9e_Sy1f1FtKC137xsY2QABtAU"]
[Tue Jul 21 08:58:53.762417 2026] [security2:error] [pid 559070:tid 559237] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9e_Sy1f1FtKC137xsY2QABtAU"]
[Tue Jul 21 08:58:54.063146 2026] [security2:error] [pid 559070:tid 559180] [remote 198.244.242.231:44936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "pomotionjustforyou.com"] [uri "/robots.txt"] [unique_id "al9e_iy1f1FtKC137xsY3gAB1W0"]
[Tue Jul 21 08:58:54.063329 2026] [security2:error] [pid 559070:tid 559270] [client 198.244.242.231:44936] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pomotionjustforyou.com"] [uri "/robots.txt"] [unique_id "al9e_iy1f1FtKC137xsY3gAB1W0"]
[Tue Jul 21 08:58:54.096733 2026] [security2:error] [pid 559070:tid 559248] [client 20.220.225.223:55781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/ww.php"] [unique_id "al9e_iy1f1FtKC137xsY4AAAAb8"]
[Tue Jul 21 08:58:54.622195 2026] [proxy:error] [pid 559070:tid 559240] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:58:54.622235 2026] [proxy_http:error] [pid 559070:tid 559240] [client 134.199.234.66:57746] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.eagastronomia.com.br/
[Tue Jul 21 08:58:54.622808 2026] [proxy:error] [pid 559070:tid 559240] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:58:54.622839 2026] [proxy_http:error] [pid 559070:tid 559240] [client 134.199.234.66:57746] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.eagastronomia.com.br/
[Tue Jul 21 08:58:54.623640 2026] [security2:error] [pid 559070:tid 559250] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9e_iy1f1FtKC137xsY8gAAAcE"]
[Tue Jul 21 08:58:54.633918 2026] [security2:error] [pid 559070:tid 559302] [client 184.154.36.163:33716] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/search/1/feed/rss2/"] [unique_id "al9e_iy1f1FtKC137xsY7wAAAfU"]
[Tue Jul 21 08:58:54.639512 2026] [security2:error] [pid 533360:tid 533535] [client 113.22.144.139:64366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e_nUPuLYrePtEkUc4WgAAAK8"]
[Tue Jul 21 08:58:54.640294 2026] [security2:error] [pid 533360:tid 533535] [client 113.22.144.139:64366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9e_nUPuLYrePtEkUc4WgAAAK8"]
[Tue Jul 21 08:58:54.777955 2026] [security2:error] [pid 533360:tid 533594] [client 20.220.225.223:34250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/berlin.php"] [unique_id "al9e_nUPuLYrePtEkUc4XAAAAOo"]
[Tue Jul 21 08:58:55.418946 2026] [security2:error] [pid 533360:tid 533575] [client 20.220.225.223:30713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/track.php"] [unique_id "al9e_3UPuLYrePtEkUc4aQAAANc"]
[Tue Jul 21 08:58:55.589559 2026] [security2:error] [pid 559070:tid 559112] [remote 54.39.203.204:56214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "pomotionjustforyou.com"] [uri "/"] [unique_id "al9e_yy1f1FtKC137xsZCwAB9yk"]
[Tue Jul 21 08:58:55.589703 2026] [security2:error] [pid 559070:tid 559304] [client 54.39.203.204:56214] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pomotionjustforyou.com"] [uri "/"] [unique_id "al9e_yy1f1FtKC137xsZCwAB9yk"]
[Tue Jul 21 08:58:55.637949 2026] [security2:error] [pid 533360:tid 533558] [client 20.220.225.223:53499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/ops.php"] [unique_id "al9e_3UPuLYrePtEkUc4bgAAAMY"]
[Tue Jul 21 08:58:56.144920 2026] [security2:error] [pid 559070:tid 559263] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fACy1f1FtKC137xsZGwAAAc4"]
[Tue Jul 21 08:58:56.145556 2026] [security2:error] [pid 559070:tid 559234] [client 184.154.36.163:33720] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoterplast.com.br"] [uri "/contato/"] [unique_id "al9fACy1f1FtKC137xsZGQAAAbE"]
[Tue Jul 21 08:58:56.346986 2026] [security2:error] [pid 559070:tid 559308] [client 117.214.78.59:56624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fACy1f1FtKC137xsZJgAAAfs"]
[Tue Jul 21 08:58:56.347164 2026] [security2:error] [pid 559070:tid 559308] [client 117.214.78.59:56624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fACy1f1FtKC137xsZJgAAAfs"]
[Tue Jul 21 08:58:56.612411 2026] [security2:error] [pid 559070:tid 559191] [remote 216.73.216.184:52077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapb.xml"] [unique_id "al9fACy1f1FtKC137xsZKQABung"]
[Tue Jul 21 08:58:56.618380 2026] [security2:error] [pid 559070:tid 559236] [client 74.249.245.134:27281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/x.php"] [unique_id "al9fACy1f1FtKC137xsZKgAAAbM"]
[Tue Jul 21 08:58:56.711784 2026] [security2:error] [pid 533360:tid 533518] [client 20.220.225.223:34280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/billur.php"] [unique_id "al9fAHUPuLYrePtEkUc4fgAAAJ4"]
[Tue Jul 21 08:58:56.857015 2026] [security2:error] [pid 559070:tid 559225] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fACy1f1FtKC137xsZLQAAAag"]
[Tue Jul 21 08:58:56.995458 2026] [security2:error] [pid 533360:tid 533567] [client 184.154.36.163:33732] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/contato/"] [unique_id "al9fAHUPuLYrePtEkUc4fwAAAM8"]
[Tue Jul 21 08:58:57.018246 2026] [security2:error] [pid 533360:tid 533587] [client 65.21.113.253:43942] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fAXUPuLYrePtEkUc4hQAAAOM"]
[Tue Jul 21 08:58:57.971724 2026] [security2:error] [pid 533360:tid 533585] [client 41.89.234.2:64209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fAXUPuLYrePtEkUc4kwAAAOE"]
[Tue Jul 21 08:58:57.971871 2026] [security2:error] [pid 533360:tid 533585] [client 41.89.234.2:64209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fAXUPuLYrePtEkUc4kwAAAOE"]
[Tue Jul 21 08:58:58.026713 2026] [security2:error] [pid 559070:tid 559234] [client 115.245.198.210:12034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fAiy1f1FtKC137xsZSAAAAbE"]
[Tue Jul 21 08:58:58.026833 2026] [security2:error] [pid 559070:tid 559234] [client 115.245.198.210:12034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fAiy1f1FtKC137xsZSAAAAbE"]
[Tue Jul 21 08:58:58.052483 2026] [security2:error] [pid 559070:tid 559274] [client 65.21.113.253:40918] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fASy1f1FtKC137xsZRQAAAdk"]
[Tue Jul 21 08:58:58.298144 2026] [autoindex:error] [pid 533360:tid 533522] [client 198.235.24.70:63808] AH01276: Cannot serve directory /home4/dralul00/ventdigital.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:58:58.479115 2026] [security2:error] [pid 559070:tid 559241] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fAiy1f1FtKC137xsZUgABuHk"]
[Tue Jul 21 08:58:58.485384 2026] [security2:error] [pid 559070:tid 559302] [client 154.182.128.22:52481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.128.182.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fAiy1f1FtKC137xsZVAAAAfU"]
[Tue Jul 21 08:58:58.485485 2026] [security2:error] [pid 559070:tid 559302] [client 154.182.128.22:52481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fAiy1f1FtKC137xsZVAAAAfU"]
[Tue Jul 21 08:58:58.534840 2026] [security2:error] [pid 533360:tid 533543] [client 20.220.225.223:34226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/mimpi.php"] [unique_id "al9fAnUPuLYrePtEkUc4oAAAALc"]
[Tue Jul 21 08:58:58.660532 2026] [security2:error] [pid 559070:tid 559286] [client 182.189.99.211:47662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fAiy1f1FtKC137xsZWQAAAeU"]
[Tue Jul 21 08:58:58.660665 2026] [security2:error] [pid 559070:tid 559286] [client 182.189.99.211:47662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fAiy1f1FtKC137xsZWQAAAeU"]
[Tue Jul 21 08:58:58.661622 2026] [security2:error] [pid 533360:tid 533597] [client 20.220.225.223:53472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/cron.php"] [unique_id "al9fAnUPuLYrePtEkUc4pgAAAO0"]
[Tue Jul 21 08:58:58.887556 2026] [security2:error] [pid 559070:tid 559266] [client 20.151.10.161:55905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp.php"] [unique_id "al9fAiy1f1FtKC137xsZXwAAAdE"]
[Tue Jul 21 08:58:59.086298 2026] [security2:error] [pid 533360:tid 533614] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fAnUPuLYrePtEkUc4rAAAAP4"]
[Tue Jul 21 08:58:59.087400 2026] [security2:error] [pid 533360:tid 533561] [client 184.154.36.163:52752] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoterplast.com.br"] [uri "/contato/"] [unique_id "al9fAnUPuLYrePtEkUc4qgAAAMk"]
[Tue Jul 21 08:58:59.330174 2026] [security2:error] [pid 533360:tid 533455] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fA3UPuLYrePtEkUc4twAAjFs"]
[Tue Jul 21 08:58:59.330407 2026] [security2:error] [pid 533360:tid 533500] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fA3UPuLYrePtEkUc4twAAjFs"]
[Tue Jul 21 08:58:59.750842 2026] [security2:error] [pid 533360:tid 533584] [client 114.119.137.238:55269] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "drapatriciavarella.com.br"] [uri "/blog/fertilizacao-in-vitro-e-inseminacao-artificial-qual-a-principal-diferenca"] [unique_id "al9fA3UPuLYrePtEkUc4wAAAAOA"], referer: https://drapatriciavarella.com.br/blog/como-aumentar-fertilidade-mulher
[Tue Jul 21 08:58:59.820947 2026] [security2:error] [pid 559070:tid 559280] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fAyy1f1FtKC137xsZcQAAAd8"]
[Tue Jul 21 08:58:59.885973 2026] [security2:error] [pid 559070:tid 559295] [client 20.151.10.161:49102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/chosen.php"] [unique_id "al9fAyy1f1FtKC137xsZcwAAAe4"]
[Tue Jul 21 08:58:59.894380 2026] [security2:error] [pid 533360:tid 533604] [client 74.249.245.134:27293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/jga.php"] [unique_id "al9fA3UPuLYrePtEkUc4xQAAAPQ"]
[Tue Jul 21 08:58:59.901352 2026] [security2:error] [pid 533360:tid 533588] [client 20.220.225.223:34264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/dp.php"] [unique_id "al9fA3UPuLYrePtEkUc4yAAAAOQ"]
[Tue Jul 21 08:58:59.956620 2026] [security2:error] [pid 533360:tid 533505] [client 20.220.225.223:60363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/term.php"] [unique_id "al9fA3UPuLYrePtEkUc4yQAAAJE"]
[Tue Jul 21 08:59:00.055984 2026] [security2:error] [pid 559070:tid 559317] [client 185.213.175.37:47164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/.env"] [unique_id "al9fBCy1f1FtKC137xsZdQAAAgQ"]
[Tue Jul 21 08:59:00.097098 2026] [security2:error] [pid 559070:tid 559218] [client 184.154.36.163:52754] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/contato/"] [unique_id "al9fAyy1f1FtKC137xsZbwAAAaE"]
[Tue Jul 21 08:59:00.312088 2026] [security2:error] [pid 533360:tid 533524] [client 59.95.197.55:61949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fBHUPuLYrePtEkUc40gAAAKQ"]
[Tue Jul 21 08:59:00.312326 2026] [security2:error] [pid 533360:tid 533524] [client 59.95.197.55:61949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fBHUPuLYrePtEkUc40gAAAKQ"]
[Tue Jul 21 08:59:00.389028 2026] [core:alert] [pid 533360:tid 533561] [client 57.141.18.2:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 08:59:00.723764 2026] [security2:error] [pid 533360:tid 533487] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fBHUPuLYrePtEkUc44QAAzns"]
[Tue Jul 21 08:59:00.723921 2026] [security2:error] [pid 533360:tid 533566] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fBHUPuLYrePtEkUc44QAAzns"]
[Tue Jul 21 08:59:00.841170 2026] [security2:error] [pid 559070:tid 559322] [client 185.213.175.37:15928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "budhug.com.br"] [uri "/.env"] [unique_id "al9fBCy1f1FtKC137xsZgAAAAgk"]
[Tue Jul 21 08:59:00.889059 2026] [security2:error] [pid 559070:tid 559210] [client 20.220.225.223:34739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/mimpi.php"] [unique_id "al9fBCy1f1FtKC137xsZggAAAZk"]
[Tue Jul 21 08:59:00.897206 2026] [security2:error] [pid 559070:tid 559264] [client 139.167.208.211:55629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.208.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fBCy1f1FtKC137xsZfwAAAc8"]
[Tue Jul 21 08:59:00.897349 2026] [security2:error] [pid 559070:tid 559264] [client 139.167.208.211:55629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fBCy1f1FtKC137xsZfwAAAc8"]
[Tue Jul 21 08:59:01.185974 2026] [security2:error] [pid 559070:tid 559187] [remote 167.71.218.184:60206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rgagestaodecondominios.adm.br"] [uri "/wp-login.php"] [unique_id "al9fBSy1f1FtKC137xsZiAABvXQ"]
[Tue Jul 21 08:59:01.847361 2026] [security2:error] [pid 533360:tid 533553] [client 65.21.113.253:43942] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fBXUPuLYrePtEkUc4_AAAAME"]
[Tue Jul 21 08:59:01.889255 2026] [security2:error] [pid 533360:tid 533511] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fBXUPuLYrePtEkUc4-QAAAJc"]
[Tue Jul 21 08:59:01.891064 2026] [security2:error] [pid 533360:tid 533606] [client 184.154.36.163:52762] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/search/1/feed/rss2/"] [unique_id "al9fBXUPuLYrePtEkUc49wAAAPY"]
[Tue Jul 21 08:59:01.932453 2026] [security2:error] [pid 559070:tid 559224] [client 103.59.206.240:37135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fBSy1f1FtKC137xsZlQAAAac"]
[Tue Jul 21 08:59:01.932578 2026] [security2:error] [pid 559070:tid 559224] [client 103.59.206.240:37135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fBSy1f1FtKC137xsZlQAAAac"]
[Tue Jul 21 08:59:01.993032 2026] [security2:error] [pid 559070:tid 559240] [client 20.151.10.161:48610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/als.php"] [unique_id "al9fBSy1f1FtKC137xsZmAAAAbc"]
[Tue Jul 21 08:59:02.822549 2026] [security2:error] [pid 533360:tid 533596] [client 20.220.225.223:34199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/bootstrap.php"] [unique_id "al9fBnUPuLYrePtEkUc5FQAAAOw"]
[Tue Jul 21 08:59:02.849667 2026] [security2:error] [pid 533360:tid 533604] [client 20.151.10.161:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/abcd.php"] [unique_id "al9fBnUPuLYrePtEkUc5FgAAAPQ"]
[Tue Jul 21 08:59:02.916887 2026] [security2:error] [pid 533360:tid 533570] [client 65.21.113.253:39020] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fBnUPuLYrePtEkUc5CwAAANI"]
[Tue Jul 21 08:59:02.978030 2026] [security2:error] [pid 533360:tid 533567] [client 128.127.105.184:46936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9fBnUPuLYrePtEkUc5HQAAAM8"]
[Tue Jul 21 08:59:02.978130 2026] [security2:error] [pid 533360:tid 533567] [client 128.127.105.184:46936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9fBnUPuLYrePtEkUc5HQAAAM8"]
[Tue Jul 21 08:59:03.050395 2026] [security2:error] [pid 559070:tid 559284] [client 114.198.138.124:60211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fByy1f1FtKC137xsZsgAAAeM"]
[Tue Jul 21 08:59:03.050539 2026] [security2:error] [pid 559070:tid 559284] [client 114.198.138.124:60211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fByy1f1FtKC137xsZsgAAAeM"]
[Tue Jul 21 08:59:03.117273 2026] [security2:error] [pid 533360:tid 533575] [client 20.151.10.161:49040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/pol.php"] [unique_id "al9fB3UPuLYrePtEkUc5IAAAANc"]
[Tue Jul 21 08:59:03.182834 2026] [security2:error] [pid 559070:tid 559075] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fByy1f1FtKC137xsZswAB_QQ"]
[Tue Jul 21 08:59:03.182957 2026] [security2:error] [pid 559070:tid 559310] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fByy1f1FtKC137xsZswAB_QQ"]
[Tue Jul 21 08:59:03.287459 2026] [security2:error] [pid 559070:tid 559308] [client 20.220.225.223:60373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/ah25.php"] [unique_id "al9fByy1f1FtKC137xsZtQAAAfs"]
[Tue Jul 21 08:59:03.428148 2026] [security2:error] [pid 559070:tid 559209] [client 198.44.157.162:44020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9fByy1f1FtKC137xsZvgAAAZg"]
[Tue Jul 21 08:59:03.428270 2026] [security2:error] [pid 559070:tid 559209] [client 198.44.157.162:44020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9fByy1f1FtKC137xsZvgAAAZg"]
[Tue Jul 21 08:59:03.820575 2026] [security2:error] [pid 559070:tid 559221] [client 117.235.80.45:49292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.80.235.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fByy1f1FtKC137xsZxQAAAaQ"]
[Tue Jul 21 08:59:03.820730 2026] [security2:error] [pid 559070:tid 559221] [client 117.235.80.45:49292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fByy1f1FtKC137xsZxQAAAaQ"]
[Tue Jul 21 08:59:04.170219 2026] [security2:error] [pid 559070:tid 559288] [client 20.220.225.223:20925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/dp.php"] [unique_id "al9fCCy1f1FtKC137xsZyQAAAec"]
[Tue Jul 21 08:59:04.229265 2026] [security2:error] [pid 533360:tid 533377] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fCHUPuLYrePtEkUc5OgAAoQ0"]
[Tue Jul 21 08:59:04.229437 2026] [security2:error] [pid 533360:tid 533521] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fCHUPuLYrePtEkUc5OgAAoQ0"]
[Tue Jul 21 08:59:04.485385 2026] [security2:error] [pid 559070:tid 559236] [client 20.220.225.223:34236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wp-editor.php"] [unique_id "al9fCCy1f1FtKC137xsZzwAAAbM"]
[Tue Jul 21 08:59:04.604037 2026] [security2:error] [pid 533360:tid 533537] [client 114.119.145.194:43737] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "carrosselbuique.com.br"] [uri "/sp_meios-de-transporte"] [unique_id "al9fCHUPuLYrePtEkUc5RQAAALE"], referer: https://carrosselbuique.com.br/jardim-i/
[Tue Jul 21 08:59:04.625202 2026] [security2:error] [pid 559070:tid 559311] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fByy1f1FtKC137xsZtwAAAf4"]
[Tue Jul 21 08:59:04.626232 2026] [security2:error] [pid 533360:tid 533617] [client 184.154.36.163:52778] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/search/1/feed/rss2/"] [unique_id "al9fB3UPuLYrePtEkUc5IwAAAQE"]
[Tue Jul 21 08:59:04.700038 2026] [security2:error] [pid 533360:tid 533568] [client 20.220.225.223:53490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/xxx.php"] [unique_id "al9fCHUPuLYrePtEkUc5RgAAANA"]
[Tue Jul 21 08:59:04.861482 2026] [security2:error] [pid 533360:tid 533544] [client 20.220.225.223:34283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/2x.php"] [unique_id "al9fCHUPuLYrePtEkUc5SQAAALg"]
[Tue Jul 21 08:59:04.998931 2026] [security2:error] [pid 533360:tid 533493] [client 20.151.10.161:49111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/file5.php"] [unique_id "al9fCHUPuLYrePtEkUc5TAAAAIU"]
[Tue Jul 21 08:59:05.175528 2026] [security2:error] [pid 559070:tid 559240] [client 194.99.104.35:51392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9fCSy1f1FtKC137xsZ4wAAAbc"]
[Tue Jul 21 08:59:05.175632 2026] [security2:error] [pid 559070:tid 559240] [client 194.99.104.35:51392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9fCSy1f1FtKC137xsZ4wAAAbc"]
[Tue Jul 21 08:59:05.423781 2026] [security2:error] [pid 559070:tid 559320] [client 74.249.245.134:27273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/k.php"] [unique_id "al9fCSy1f1FtKC137xsZ6QAAAgc"]
[Tue Jul 21 08:59:05.560412 2026] [security2:error] [pid 559070:tid 559272] [client 113.22.144.139:64900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fCSy1f1FtKC137xsZ7AAAAdc"]
[Tue Jul 21 08:59:05.561209 2026] [security2:error] [pid 559070:tid 559272] [client 113.22.144.139:64900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fCSy1f1FtKC137xsZ7AAAAdc"]
[Tue Jul 21 08:59:05.642909 2026] [security2:error] [pid 533360:tid 533579] [client 20.220.225.223:58368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/2352356666.php"] [unique_id "al9fCXUPuLYrePtEkUc5XAAAANs"]
[Tue Jul 21 08:59:05.786801 2026] [security2:error] [pid 533360:tid 533523] [client 104.28.219.193:20152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rustikusboxingschool.com"] [uri "/.env"] [unique_id "al9fCXUPuLYrePtEkUc5XgAAAKM"]
[Tue Jul 21 08:59:06.234285 2026] [security2:error] [pid 533360:tid 533597] [client 104.28.219.193:22985] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "rustikusboxingschool.com"] [uri "/wp-config.php~"] [unique_id "al9fCnUPuLYrePtEkUc5awAAAO0"]
[Tue Jul 21 08:59:06.297417 2026] [security2:error] [pid 559070:tid 559269] [client 85.8.130.92:53839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.130.8.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicabrasil.com.br"] [uri "/wp-login.php"] [unique_id "al9fCiy1f1FtKC137xsaBAAAAdQ"]
[Tue Jul 21 08:59:06.325456 2026] [security2:error] [pid 533360:tid 533617] [client 20.220.225.223:53486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/hunter.php"] [unique_id "al9fCnUPuLYrePtEkUc5cAAAAQE"]
[Tue Jul 21 08:59:06.814294 2026] [security2:error] [pid 533360:tid 533606] [client 20.220.225.223:34299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/kq1.php"] [unique_id "al9fCnUPuLYrePtEkUc5egAAAPY"]
[Tue Jul 21 08:59:06.838391 2026] [security2:error] [pid 533360:tid 533524] [client 117.214.78.59:57068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fCnUPuLYrePtEkUc5ewAAAKQ"]
[Tue Jul 21 08:59:06.838460 2026] [security2:error] [pid 533360:tid 533524] [client 117.214.78.59:57068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fCnUPuLYrePtEkUc5ewAAAKQ"]
[Tue Jul 21 08:59:07.044235 2026] [security2:error] [pid 559070:tid 559204] [client 74.249.245.134:43687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/wp.php"] [unique_id "al9fCyy1f1FtKC137xsaIgAAAZM"]
[Tue Jul 21 08:59:07.048493 2026] [security2:error] [pid 559070:tid 559213] [client 20.220.225.223:30886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/pn.php"] [unique_id "al9fCyy1f1FtKC137xsaIwAAAZw"]
[Tue Jul 21 08:59:07.136099 2026] [security2:error] [pid 559070:tid 559240] [client 104.28.219.193:35962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "rustikusboxingschool.com"] [uri "/wp-config.php.bak"] [unique_id "al9fCyy1f1FtKC137xsaKwAAAbc"]
[Tue Jul 21 08:59:07.431588 2026] [security2:error] [pid 559070:tid 559322] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fCyy1f1FtKC137xsaMgAAAgk"]
[Tue Jul 21 08:59:07.432168 2026] [security2:error] [pid 559070:tid 559295] [client 184.154.36.163:57836] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "hoterplast.com.br"] [uri "/contato/"] [unique_id "al9fCyy1f1FtKC137xsaLQAAAe4"]
[Tue Jul 21 08:59:07.485018 2026] [security2:error] [pid 559070:tid 559210] [client 104.28.219.193:35964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "rustikusboxingschool.com"] [uri "/wp-config.php.old"] [unique_id "al9fCyy1f1FtKC137xsaNgAAAZk"]
[Tue Jul 21 08:59:07.602552 2026] [security2:error] [pid 533360:tid 533545] [client 104.28.219.193:54236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "rustikusboxingschool.com"] [uri "/.env.backup"] [unique_id "al9fC3UPuLYrePtEkUc5iwAAALk"]
[Tue Jul 21 08:59:07.689538 2026] [security2:error] [pid 559070:tid 559315] [client 104.28.219.193:30446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "rustikusboxingschool.com"] [uri "/.env.bak"] [unique_id "al9fCyy1f1FtKC137xsaPAAAAgI"]
[Tue Jul 21 08:59:07.755142 2026] [security2:error] [pid 559070:tid 559234] [client 104.28.219.193:35965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.219.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rustikusboxingschool.com"] [uri "/wp-config.php"] [unique_id "al9fCyy1f1FtKC137xsaOQAAAbE"]
[Tue Jul 21 08:59:07.954247 2026] [security2:error] [pid 533360:tid 533481] [remote 37.139.53.5:0] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9fC3UPuLYrePtEkUc5kwAAonU"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 08:59:07.954399 2026] [security2:error] [pid 533360:tid 533522] [client 37.139.53.5:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9fC3UPuLYrePtEkUc5kwAAonU"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 08:59:07.956299 2026] [security2:error] [pid 559070:tid 559295] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fCyy1f1FtKC137xsaSAAAAe4"]
[Tue Jul 21 08:59:08.081441 2026] [security2:error] [pid 559070:tid 559310] [client 20.151.10.161:49071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9fDCy1f1FtKC137xsaTQAAAf0"]
[Tue Jul 21 08:59:08.150100 2026] [security2:error] [pid 559070:tid 559233] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fDCy1f1FtKC137xsaTAAAAbA"]
[Tue Jul 21 08:59:08.181105 2026] [security2:error] [pid 533360:tid 533550] [client 74.249.245.134:43676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/new.php"] [unique_id "al9fDHUPuLYrePtEkUc5mgAAAL4"]
[Tue Jul 21 08:59:08.200135 2026] [security2:error] [pid 533360:tid 533527] [client 104.28.219.193:20152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "rustikusboxingschool.com"] [uri "/.env.old"] [unique_id "al9fDHUPuLYrePtEkUc5nAAAAKc"]
[Tue Jul 21 08:59:08.230854 2026] [security2:error] [pid 559070:tid 559137] [remote 72.167.132.114:45508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rustikusboxingschool.com"] [uri "/wp-login.php"] [unique_id "al9fDCy1f1FtKC137xsaUwAB30I"]
[Tue Jul 21 08:59:08.344108 2026] [security2:error] [pid 533360:tid 533615] [client 20.151.10.161:50997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/a1.php"] [unique_id "al9fDHUPuLYrePtEkUc5oAAAAP8"]
[Tue Jul 21 08:59:08.420759 2026] [security2:error] [pid 559070:tid 559260] [client 117.210.181.114:2562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.181.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fDCy1f1FtKC137xsaXAAAAcs"]
[Tue Jul 21 08:59:08.420899 2026] [security2:error] [pid 559070:tid 559260] [client 117.210.181.114:2562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fDCy1f1FtKC137xsaXAAAAcs"]
[Tue Jul 21 08:59:08.428399 2026] [security2:error] [pid 559070:tid 559317] [client 184.154.36.163:57844] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/contato/"] [unique_id "al9fDCy1f1FtKC137xsaSQAAAgQ"]
[Tue Jul 21 08:59:08.486052 2026] [security2:error] [pid 533360:tid 533619] [client 41.89.234.2:64680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fDHUPuLYrePtEkUc5oQAAAQM"]
[Tue Jul 21 08:59:08.486202 2026] [security2:error] [pid 533360:tid 533619] [client 41.89.234.2:64680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fDHUPuLYrePtEkUc5oQAAAQM"]
[Tue Jul 21 08:59:08.787789 2026] [security2:error] [pid 559070:tid 559250] [client 65.21.113.253:39034] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fDCy1f1FtKC137xsaYQAAAcE"]
[Tue Jul 21 08:59:08.873996 2026] [security2:error] [pid 559070:tid 559257] [client 20.220.225.223:34300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/zzz.php"] [unique_id "al9fDCy1f1FtKC137xsaZQAAAcg"]
[Tue Jul 21 08:59:09.127357 2026] [security2:error] [pid 559070:tid 559240] [client 74.249.245.134:27236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/vx.php"] [unique_id "al9fDSy1f1FtKC137xsacQAAAbc"]
[Tue Jul 21 08:59:09.137724 2026] [security2:error] [pid 559070:tid 559266] [client 154.182.128.22:53109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.128.182.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fDSy1f1FtKC137xsacgAAAdE"]
[Tue Jul 21 08:59:09.137837 2026] [security2:error] [pid 559070:tid 559266] [client 154.182.128.22:53109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fDSy1f1FtKC137xsacgAAAdE"]
[Tue Jul 21 08:59:09.425069 2026] [security2:error] [pid 533360:tid 533578] [client 20.220.225.223:53448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/8.php"] [unique_id "al9fDXUPuLYrePtEkUc5tgAAANo"]
[Tue Jul 21 08:59:09.454111 2026] [qos:error] [pid 559070:tid 559187] [remote 57.141.18.85:50042] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.85, id=al9fDSy1f1FtKC137xsafwABpHQ
[Tue Jul 21 08:59:09.516721 2026] [security2:error] [pid 559070:tid 559271] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fDSy1f1FtKC137xsafAAB1gM"]
[Tue Jul 21 08:59:09.704211 2026] [security2:error] [pid 559070:tid 559106] [remote 47.128.124.225:43774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "prissedermatologia.com.br"] [uri "/5-perguntas-frequentes-sobre-preenchimento-com-acido-hialuronico/"] [unique_id "al9fDSy1f1FtKC137xsahAACBCM"]
[Tue Jul 21 08:59:09.743717 2026] [security2:error] [pid 559070:tid 559266] [client 74.249.245.134:43706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/class-t.api.php"] [unique_id "al9fDSy1f1FtKC137xsahQAAAdE"]
[Tue Jul 21 08:59:09.830433 2026] [security2:error] [pid 533360:tid 533594] [client 20.220.225.223:34194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wicked.php"] [unique_id "al9fDXUPuLYrePtEkUc5uwAAAOo"]
[Tue Jul 21 08:59:09.846663 2026] [security2:error] [pid 559070:tid 559234] [client 65.21.113.253:32946] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fDSy1f1FtKC137xsafgAAAbE"]
[Tue Jul 21 08:59:09.849940 2026] [security2:error] [pid 559070:tid 559127] [remote 209.59.231.224:0] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9fDSy1f1FtKC137xsagAAB5Tg"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 08:59:09.877617 2026] [qos:error] [pid 559070:tid 559110] [remote 57.141.18.26:45160] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.26, id=al9fDSy1f1FtKC137xsaiwAB6Cc
[Tue Jul 21 08:59:09.879236 2026] [security2:error] [pid 559070:tid 559163] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fDSy1f1FtKC137xsajAABx1w"]
[Tue Jul 21 08:59:09.879430 2026] [security2:error] [pid 559070:tid 559256] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fDSy1f1FtKC137xsajAABx1w"]
[Tue Jul 21 08:59:09.944334 2026] [autoindex:error] [pid 559070:tid 559185] [remote 43.157.147.3:0] AH01276: Cannot serve directory /home1/tavar035/brasilcertdigital.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.brasilcertdigital.online
[Tue Jul 21 08:59:09.944380 2026] [security2:error] [pid 559070:tid 559253] [client 20.151.10.161:55857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al9fDSy1f1FtKC137xsalgAAAcQ"]
[Tue Jul 21 08:59:09.988230 2026] [proxy:error] [pid 559070:tid 559204] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:09.989110 2026] [proxy_http:error] [pid 559070:tid 559204] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:09.989559 2026] [proxy:error] [pid 559070:tid 559204] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:09.989581 2026] [proxy_http:error] [pid 559070:tid 559204] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:10.074651 2026] [qos:error] [pid 533360:tid 533445] [remote 57.141.18.114:24624] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.114, id=al9fDnUPuLYrePtEkUc5wAAAmVE
[Tue Jul 21 08:59:10.140463 2026] [security2:error] [pid 559070:tid 559286] [client 209.59.231.224:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "shopmelhorcompraonline.com"] [uri "/wp-comments-post.php"] [unique_id "al9fDSy1f1FtKC137xsagAAB5Tg"], referer: https://shopmelhorcompraonline.com/hello-world/
[Tue Jul 21 08:59:10.175973 2026] [security2:error] [pid 533360:tid 533584] [client 20.151.10.161:48577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/file.php"] [unique_id "al9fDnUPuLYrePtEkUc5xQAAAOA"]
[Tue Jul 21 08:59:10.286241 2026] [qos:error] [pid 559070:tid 559105] [remote 57.141.18.40:28416] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.40, id=al9fDiy1f1FtKC137xsanwABtyI
[Tue Jul 21 08:59:10.354460 2026] [security2:error] [pid 559070:tid 559289] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fDiy1f1FtKC137xsangAAAeg"]
[Tue Jul 21 08:59:10.408905 2026] [proxy:error] [pid 559070:tid 559271] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:10.408987 2026] [proxy_http:error] [pid 559070:tid 559271] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:10.410512 2026] [proxy:error] [pid 559070:tid 559271] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:10.410579 2026] [proxy_http:error] [pid 559070:tid 559271] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:10.456723 2026] [security2:error] [pid 559070:tid 559319] [client 74.249.245.134:12918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/plugins.php"] [unique_id "al9fDiy1f1FtKC137xsapgAAAgY"]
[Tue Jul 21 08:59:10.463008 2026] [security2:error] [pid 533360:tid 533459] [remote 114.34.90.9:37792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.90.34.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "politicaemdebate.org"] [uri "/wp-login.php"] [unique_id "al9fDnUPuLYrePtEkUc5yQAA_F8"]
[Tue Jul 21 08:59:10.495228 2026] [security2:error] [pid 559070:tid 559307] [client 184.154.36.163:57854] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/contato/"] [unique_id "al9fDiy1f1FtKC137xsanAAAAfs"]
[Tue Jul 21 08:59:10.799715 2026] [proxy:error] [pid 559070:tid 559295] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:10.799776 2026] [proxy_http:error] [pid 559070:tid 559295] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:10.800307 2026] [proxy:error] [pid 559070:tid 559295] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:10.800332 2026] [proxy_http:error] [pid 559070:tid 559295] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:10.841614 2026] [qos:error] [pid 559070:tid 559167] [remote 57.141.18.85:50048] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.85, id=al9fDiy1f1FtKC137xsaqwAB5WA
[Tue Jul 21 08:59:10.951675 2026] [security2:error] [pid 533360:tid 533529] [client 139.167.208.211:56380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.208.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fDnUPuLYrePtEkUc51gAAAKk"]
[Tue Jul 21 08:59:10.951783 2026] [security2:error] [pid 533360:tid 533529] [client 139.167.208.211:56380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fDnUPuLYrePtEkUc51gAAAKk"]
[Tue Jul 21 08:59:11.047895 2026] [security2:error] [pid 533360:tid 533509] [client 74.249.245.134:12891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/jp.php"] [unique_id "al9fD3UPuLYrePtEkUc51wAAAJU"]
[Tue Jul 21 08:59:11.114767 2026] [qos:error] [pid 559070:tid 559085] [remote 57.141.18.64:60846] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.64, id=al9fDyy1f1FtKC137xsasgAB-w4
[Tue Jul 21 08:59:11.167194 2026] [qos:error] [pid 559070:tid 559180] [remote 57.141.18.48:36554] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.48, id=al9fDyy1f1FtKC137xsaswAByW0
[Tue Jul 21 08:59:11.190632 2026] [security2:error] [pid 533360:tid 533608] [client 20.220.225.223:55759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/we.php"] [unique_id "al9fD3UPuLYrePtEkUc52QAAAPg"]
[Tue Jul 21 08:59:11.203633 2026] [security2:error] [pid 533360:tid 533558] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fD3UPuLYrePtEkUc52wAAAMY"]
[Tue Jul 21 08:59:11.247090 2026] [security2:error] [pid 533360:tid 533432] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fD3UPuLYrePtEkUc53gAAh0Q"]
[Tue Jul 21 08:59:11.247199 2026] [security2:error] [pid 533360:tid 533495] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fD3UPuLYrePtEkUc53gAAh0Q"]
[Tue Jul 21 08:59:11.297161 2026] [security2:error] [pid 559070:tid 559209] [client 20.220.225.223:53475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/red.php"] [unique_id "al9fDyy1f1FtKC137xsatwAAAZg"]
[Tue Jul 21 08:59:11.396467 2026] [security2:error] [pid 559070:tid 559266] [client 59.95.197.55:62424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fDyy1f1FtKC137xsaugAAAdE"]
[Tue Jul 21 08:59:11.396576 2026] [security2:error] [pid 559070:tid 559266] [client 59.95.197.55:62424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fDyy1f1FtKC137xsaugAAAdE"]
[Tue Jul 21 08:59:11.407730 2026] [qos:error] [pid 559070:tid 559159] [remote 57.141.18.24:32072] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.24, id=al9fDyy1f1FtKC137xsauwABk1g
[Tue Jul 21 08:59:11.500384 2026] [qos:error] [pid 559070:tid 559182] [remote 57.141.18.30:24428] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.30, id=al9fDyy1f1FtKC137xsawgABqm8
[Tue Jul 21 08:59:11.553227 2026] [security2:error] [pid 559070:tid 559324] [client 20.151.10.161:51050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/cgi-bin/admin.php"] [unique_id "al9fDyy1f1FtKC137xsawwAAAgs"]
[Tue Jul 21 08:59:11.642901 2026] [security2:error] [pid 559070:tid 559311] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9fDyy1f1FtKC137xsaxwAAAf4"]
[Tue Jul 21 08:59:11.656737 2026] [security2:error] [pid 559070:tid 559317] [client 74.249.245.134:12894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/error.php"] [unique_id "al9fDyy1f1FtKC137xsayAAAAgQ"]
[Tue Jul 21 08:59:11.750606 2026] [core:error] [pid 533360:tid 533364] [remote 74.7.175.175:33524] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:59:11.750624 2026] [core:error] [pid 533360:tid 533364] [remote 74.7.175.175:33524] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:59:11.750808 2026] [security2:error] [pid 533360:tid 533594] [client 74.7.175.175:33524] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "hostserv.com.br.hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fD3UPuLYrePtEkUc56AAA6gA"]
[Tue Jul 21 08:59:11.776935 2026] [security2:error] [pid 533360:tid 533513] [client 20.151.10.161:48622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/cfile.php"] [unique_id "al9fD3UPuLYrePtEkUc56gAAAJk"]
[Tue Jul 21 08:59:11.782135 2026] [security2:error] [pid 559070:tid 559319] [client 20.220.225.223:42532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/wp-wpbak.php"] [unique_id "al9fDyy1f1FtKC137xsaygAAAgY"]
[Tue Jul 21 08:59:11.841767 2026] [qos:error] [pid 533360:tid 533458] [remote 57.141.18.91:44870] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.91, id=al9fD3UPuLYrePtEkUc57AAA7F4
[Tue Jul 21 08:59:11.861607 2026] [qos:error] [pid 559070:tid 559082] [remote 57.141.18.45:43704] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.45, id=al9fDyy1f1FtKC137xsaywAB9ws
[Tue Jul 21 08:59:11.867378 2026] [security2:error] [pid 559070:tid 559322] [client 20.220.225.223:34709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/bootstrap.php"] [unique_id "al9fDyy1f1FtKC137xsazAAAAgk"]
[Tue Jul 21 08:59:12.112696 2026] [security2:error] [pid 559070:tid 559264] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9fECy1f1FtKC137xsa0gAAAc8"]
[Tue Jul 21 08:59:12.207004 2026] [security2:error] [pid 559070:tid 559236] [client 182.189.99.211:48138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fECy1f1FtKC137xsa0wAAAbM"]
[Tue Jul 21 08:59:12.207155 2026] [security2:error] [pid 559070:tid 559236] [client 182.189.99.211:48138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fECy1f1FtKC137xsa0wAAAbM"]
[Tue Jul 21 08:59:12.224099 2026] [security2:error] [pid 559070:tid 559227] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fECy1f1FtKC137xsa0QAAAao"]
[Tue Jul 21 08:59:12.320203 2026] [security2:error] [pid 559070:tid 559274] [client 74.249.245.134:12819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/classwithtostring.php"] [unique_id "al9fECy1f1FtKC137xsa1gAAAdk"]
[Tue Jul 21 08:59:12.502014 2026] [security2:error] [pid 533360:tid 533584] [client 184.154.36.163:57858] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/contato/"] [unique_id "al9fEHUPuLYrePtEkUc58gAAAOA"]
[Tue Jul 21 08:59:12.519217 2026] [security2:error] [pid 533360:tid 533611] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9fEHUPuLYrePtEkUc5-wAAAPs"]
[Tue Jul 21 08:59:12.547566 2026] [security2:error] [pid 559070:tid 559233] [client 20.220.225.223:53498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tamoiomix.com.br"] [uri "/phpinfo.php1"] [unique_id "al9fECy1f1FtKC137xsa2wAAAbA"]
[Tue Jul 21 08:59:12.551762 2026] [security2:error] [pid 559070:tid 559204] [client 103.59.206.240:31020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fECy1f1FtKC137xsa3AAAAZM"]
[Tue Jul 21 08:59:12.551845 2026] [security2:error] [pid 559070:tid 559204] [client 103.59.206.240:31020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fECy1f1FtKC137xsa3AAAAZM"]
[Tue Jul 21 08:59:12.641573 2026] [security2:error] [pid 559070:tid 559301] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fECy1f1FtKC137xsa3gAAAfQ"]
[Tue Jul 21 08:59:12.985012 2026] [security2:error] [pid 533360:tid 533606] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9fEHUPuLYrePtEkUc6AwAAAPY"]
[Tue Jul 21 08:59:13.031175 2026] [security2:error] [pid 559070:tid 559236] [client 74.249.245.134:12811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/bless.php"] [unique_id "al9fESy1f1FtKC137xsa6AAAAbM"]
[Tue Jul 21 08:59:13.059159 2026] [security2:error] [pid 559070:tid 559271] [client 20.151.10.161:51032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/gettest.php"] [unique_id "al9fESy1f1FtKC137xsa6gAAAdY"]
[Tue Jul 21 08:59:13.370722 2026] [security2:error] [pid 559070:tid 559270] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9fESy1f1FtKC137xsa8gAAAdU"]
[Tue Jul 21 08:59:13.622350 2026] [security2:error] [pid 533360:tid 533579] [client 114.198.138.124:60783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fEXUPuLYrePtEkUc6EAAAANs"]
[Tue Jul 21 08:59:13.625661 2026] [security2:error] [pid 533360:tid 533579] [client 114.198.138.124:60783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fEXUPuLYrePtEkUc6EAAAANs"]
[Tue Jul 21 08:59:13.718726 2026] [security2:error] [pid 559070:tid 559315] [client 74.249.245.134:12884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/storage/index.php"] [unique_id "al9fESy1f1FtKC137xsa-wAAAgI"]
[Tue Jul 21 08:59:13.732209 2026] [security2:error] [pid 559070:tid 559140] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fESy1f1FtKC137xsa_AABk0U"]
[Tue Jul 21 08:59:13.732353 2026] [security2:error] [pid 559070:tid 559204] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fESy1f1FtKC137xsa_AABk0U"]
[Tue Jul 21 08:59:13.786660 2026] [security2:error] [pid 533360:tid 533596] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9fEXUPuLYrePtEkUc6EQAAAOw"]
[Tue Jul 21 08:59:13.816596 2026] [security2:error] [pid 559070:tid 559280] [client 69.171.230.40:52734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fESy1f1FtKC137xsbAAAAAd8"]
[Tue Jul 21 08:59:13.975776 2026] [security2:error] [pid 559070:tid 559310] [client 65.21.113.253:32948] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fESy1f1FtKC137xsa-gAAAf0"]
[Tue Jul 21 08:59:14.217659 2026] [security2:error] [pid 533360:tid 533537] [client 74.249.245.134:43649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/g.php"] [unique_id "al9fEnUPuLYrePtEkUc6GgAAALE"]
[Tue Jul 21 08:59:14.241554 2026] [security2:error] [pid 559070:tid 559236] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9fEiy1f1FtKC137xsbDAAAAbM"]
[Tue Jul 21 08:59:14.346264 2026] [security2:error] [pid 559070:tid 559256] [client 117.235.80.45:50010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.80.235.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fEiy1f1FtKC137xsbDQAAAcc"]
[Tue Jul 21 08:59:14.346551 2026] [security2:error] [pid 559070:tid 559256] [client 117.235.80.45:50010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fEiy1f1FtKC137xsbDQAAAcc"]
[Tue Jul 21 08:59:14.514320 2026] [security2:error] [pid 533360:tid 533619] [client 20.220.225.223:34248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/edit.php"] [unique_id "al9fEnUPuLYrePtEkUc6IQAAAQM"]
[Tue Jul 21 08:59:14.517464 2026] [security2:error] [pid 559070:tid 559227] [client 20.151.10.161:54929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/simple.php"] [unique_id "al9fEiy1f1FtKC137xsbEQAAAao"]
[Tue Jul 21 08:59:14.530620 2026] [core:error] [pid 533360:tid 533470] [remote 74.7.227.57:49634] AH10244: invalid URI path (/wp-content/plugins/powerpack-elements/assets/lib/magnific-popup/%url%), referer: https://sscoenper.com.br/wp-content/plugins/powerpack-elements/assets/lib/magnific-popup/jquery.magnific-popup.min.js?ver=2.2.1
[Tue Jul 21 08:59:14.682803 2026] [security2:error] [pid 533360:tid 533493] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9fEnUPuLYrePtEkUc6KgAAAIU"]
[Tue Jul 21 08:59:14.763805 2026] [security2:error] [pid 533360:tid 533376] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fEnUPuLYrePtEkUc6LQAAiQw"]
[Tue Jul 21 08:59:14.763990 2026] [security2:error] [pid 533360:tid 533497] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fEnUPuLYrePtEkUc6LQAAiQw"]
[Tue Jul 21 08:59:14.915093 2026] [security2:error] [pid 533360:tid 533514] [client 20.151.10.161:48605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/class-wp.php"] [unique_id "al9fEnUPuLYrePtEkUc6MQAAAJo"]
[Tue Jul 21 08:59:14.969854 2026] [security2:error] [pid 533360:tid 533575] [client 20.220.225.223:53458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/fffm.php"] [unique_id "al9fEnUPuLYrePtEkUc6NQAAANc"]
[Tue Jul 21 08:59:15.080151 2026] [security2:error] [pid 533360:tid 533555] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9fE3UPuLYrePtEkUc6OAAAAMM"]
[Tue Jul 21 08:59:15.306356 2026] [security2:error] [pid 559070:tid 559280] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fEyy1f1FtKC137xsbHgAAAd8"]
[Tue Jul 21 08:59:15.308597 2026] [security2:error] [pid 559070:tid 559237] [client 20.151.10.161:51045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/xxx.php"] [unique_id "al9fEyy1f1FtKC137xsbHwAAAbQ"]
[Tue Jul 21 08:59:15.345427 2026] [security2:error] [pid 533360:tid 533501] [client 20.10.88.201:1090] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shop-officialstore.com"] [uri "/index.php"] [unique_id "al9fE3UPuLYrePtEkUc6PgAAAI0"]
[Tue Jul 21 08:59:15.375331 2026] [autoindex:error] [pid 533360:tid 533614] [client 1.12.70.96:47724] AH01276: Cannot serve directory /home2/rebe1126/rebecavivone.online/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:59:15.538045 2026] [security2:error] [pid 559070:tid 559270] [client 74.249.245.134:12812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/nf.php"] [unique_id "al9fEyy1f1FtKC137xsbJQAAAdU"]
[Tue Jul 21 08:59:15.600259 2026] [security2:error] [pid 559070:tid 559320] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9fEyy1f1FtKC137xsbJwAAAgc"]
[Tue Jul 21 08:59:15.760216 2026] [autoindex:error] [pid 559070:tid 559289] [client 43.164.1.211:54628] AH01276: Cannot serve directory /home2/inlaud99/kenyetuquinha.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:59:15.834827 2026] [security2:error] [pid 559070:tid 559312] [client 74.249.245.134:27182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/ws77.php"] [unique_id "al9fEyy1f1FtKC137xsbKwAAAf8"]
[Tue Jul 21 08:59:16.028202 2026] [security2:error] [pid 559070:tid 559252] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9fFCy1f1FtKC137xsbMQAAAcM"]
[Tue Jul 21 08:59:16.425386 2026] [security2:error] [pid 533360:tid 533546] [client 198.44.157.162:42180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9fFHUPuLYrePtEkUc6TQAAALo"]
[Tue Jul 21 08:59:16.425497 2026] [security2:error] [pid 533360:tid 533546] [client 198.44.157.162:42180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healthandwellnessdaily.online"] [uri "/xmlrpc.php"] [unique_id "al9fFHUPuLYrePtEkUc6TQAAALo"]
[Tue Jul 21 08:59:16.445650 2026] [security2:error] [pid 533360:tid 533617] [client 20.151.10.161:55861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/hypo.php"] [unique_id "al9fFHUPuLYrePtEkUc6TgAAAQE"]
[Tue Jul 21 08:59:16.454254 2026] [security2:error] [pid 533360:tid 533544] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.phillipedesouza1782474872925.0721679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9fFHUPuLYrePtEkUc6TwAAALg"]
[Tue Jul 21 08:59:16.457253 2026] [security2:error] [pid 533360:tid 533593] [client 65.21.113.253:32960] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fE3UPuLYrePtEkUc6SAAAAOk"]
[Tue Jul 21 08:59:16.488130 2026] [security2:error] [pid 559070:tid 559308] [client 113.22.144.139:65447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fFCy1f1FtKC137xsbPQAAAfs"]
[Tue Jul 21 08:59:16.488272 2026] [security2:error] [pid 559070:tid 559308] [client 113.22.144.139:65447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fFCy1f1FtKC137xsbPQAAAfs"]
[Tue Jul 21 08:59:16.657962 2026] [security2:error] [pid 533360:tid 533493] [client 74.249.245.134:12900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/xda.php"] [unique_id "al9fFHUPuLYrePtEkUc6VQAAAIU"]
[Tue Jul 21 08:59:16.873157 2026] [security2:error] [pid 559070:tid 559315] [client 198.44.157.162:42190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9fFCy1f1FtKC137xsbSQAAAgI"]
[Tue Jul 21 08:59:16.873251 2026] [security2:error] [pid 559070:tid 559315] [client 198.44.157.162:42190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9fFCy1f1FtKC137xsbSQAAAgI"]
[Tue Jul 21 08:59:17.286434 2026] [security2:error] [pid 533360:tid 533580] [client 31.56.58.127:46718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mgugc.online"] [uri "/.env"] [unique_id "al9fFXUPuLYrePtEkUc6YwAAANw"]
[Tue Jul 21 08:59:17.294768 2026] [security2:error] [pid 559070:tid 559224] [client 117.214.78.59:57513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fFSy1f1FtKC137xsbUwAAAac"]
[Tue Jul 21 08:59:17.294993 2026] [security2:error] [pid 559070:tid 559224] [client 117.214.78.59:57513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fFSy1f1FtKC137xsbUwAAAac"]
[Tue Jul 21 08:59:17.309598 2026] [security2:error] [pid 533360:tid 533581] [client 91.148.245.81:53278] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/"] [unique_id "al9fFXUPuLYrePtEkUc6ZAAAAN0"]
[Tue Jul 21 08:59:17.311191 2026] [security2:error] [pid 559070:tid 559250] [client 91.148.245.81:53256] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/"] [unique_id "al9fFSy1f1FtKC137xsbVQAAAcE"]
[Tue Jul 21 08:59:17.312454 2026] [security2:error] [pid 559070:tid 559285] [client 91.148.245.81:53270] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/"] [unique_id "al9fFSy1f1FtKC137xsbVgAAAeQ"]
[Tue Jul 21 08:59:17.580153 2026] [security2:error] [pid 559070:tid 559078] [remote 47.86.33.52:22962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "potencialilimitado.com.br"] [uri "/wp-login.php"] [unique_id "al9fFSy1f1FtKC137xsbZQABqwc"]
[Tue Jul 21 08:59:17.685113 2026] [security2:error] [pid 533360:tid 533392] [remote 173.252.87.25:53560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.87.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9fFXUPuLYrePtEkUc6ZQAA6hw"]
[Tue Jul 21 08:59:17.692801 2026] [security2:error] [pid 533360:tid 533577] [client 20.220.225.223:53459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/ftde.php"] [unique_id "al9fFXUPuLYrePtEkUc6bwAAANk"]
[Tue Jul 21 08:59:17.740598 2026] [security2:error] [pid 533360:tid 533552] [client 185.213.175.37:32588] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/.env.local"] [unique_id "al9fFXUPuLYrePtEkUc6cAAAAMA"]
[Tue Jul 21 08:59:17.755586 2026] [security2:error] [pid 559070:tid 559289] [client 2.57.168.18:42563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.168.57.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cursosonlinesiteoficial.com"] [uri "/wp-login.php"] [unique_id "al9fFSy1f1FtKC137xsbaAAAAeg"]
[Tue Jul 21 08:59:17.768960 2026] [security2:error] [pid 559070:tid 559234] [client 74.249.245.134:43676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/shell.php"] [unique_id "al9fFSy1f1FtKC137xsbbAAAAbE"]
[Tue Jul 21 08:59:17.783971 2026] [security2:error] [pid 533360:tid 533557] [client 20.151.10.161:54913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/chosen.php"] [unique_id "al9fFXUPuLYrePtEkUc6cgAAAMU"]
[Tue Jul 21 08:59:17.910855 2026] [security2:error] [pid 533360:tid 533620] [client 20.151.10.161:49089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/admin.php"] [unique_id "al9fFXUPuLYrePtEkUc6dAAAAQQ"]
[Tue Jul 21 08:59:17.981018 2026] [proxy:error] [pid 533360:tid 533522] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:17.981098 2026] [proxy_http:error] [pid 533360:tid 533522] [client 64.227.109.168:53604] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:17.981826 2026] [proxy:error] [pid 533360:tid 533522] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:17.981855 2026] [proxy_http:error] [pid 533360:tid 533522] [client 64.227.109.168:53604] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:17.998290 2026] [security2:error] [pid 559070:tid 559310] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fFSy1f1FtKC137xsbbwAAAf0"]
[Tue Jul 21 08:59:18.283242 2026] [security2:error] [pid 533360:tid 533617] [client 91.148.245.81:53288] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/.ssh/id_rsa"] [unique_id "al9fFnUPuLYrePtEkUc6hAAAAQE"]
[Tue Jul 21 08:59:18.286014 2026] [security2:error] [pid 533360:tid 533593] [client 91.148.245.81:53280] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/database_backup.sql"] [unique_id "al9fFnUPuLYrePtEkUc6hQAAAOk"]
[Tue Jul 21 08:59:18.288599 2026] [security2:error] [pid 533360:tid 533568] [client 91.148.245.81:53292] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/.svn/wc.db"] [unique_id "al9fFnUPuLYrePtEkUc6hgAAANA"]
[Tue Jul 21 08:59:18.290424 2026] [security2:error] [pid 559070:tid 559308] [client 91.148.245.81:53290] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/storage/logs/laravel.log"] [unique_id "al9fFiy1f1FtKC137xsbdAAAAfs"]
[Tue Jul 21 08:59:18.335355 2026] [security2:error] [pid 533360:tid 533590] [client 74.249.245.134:27321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/2.php"] [unique_id "al9fFnUPuLYrePtEkUc6iQAAAOY"]
[Tue Jul 21 08:59:18.394266 2026] [security2:error] [pid 559070:tid 559093] [remote 45.79.123.44:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.123.79.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naturofarma.com.br"] [uri "/wp-login.php"] [unique_id "al9fFiy1f1FtKC137xsbdgABpBY"]
[Tue Jul 21 08:59:18.426473 2026] [proxy:error] [pid 533360:tid 533550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:18.426550 2026] [proxy_http:error] [pid 533360:tid 533550] [client 64.227.109.168:53612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.dinamicandoo.com.br/
[Tue Jul 21 08:59:18.427322 2026] [proxy:error] [pid 533360:tid 533550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:18.427354 2026] [proxy_http:error] [pid 533360:tid 533550] [client 64.227.109.168:53612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.dinamicandoo.com.br/
[Tue Jul 21 08:59:18.548955 2026] [security2:error] [pid 559070:tid 559252] [client 31.56.58.127:46734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.mgugc.online"] [uri "/.env"] [unique_id "al9fFiy1f1FtKC137xsbeAAAAcM"]
[Tue Jul 21 08:59:18.647692 2026] [security2:error] [pid 533360:tid 533564] [client 74.249.245.134:12815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/3.php"] [unique_id "al9fFnUPuLYrePtEkUc6jwAAAMw"]
[Tue Jul 21 08:59:18.728400 2026] [security2:error] [pid 559070:tid 559324] [client 20.220.225.223:34452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/kua.php"] [unique_id "al9fFiy1f1FtKC137xsbfwAAAgs"]
[Tue Jul 21 08:59:18.994336 2026] [security2:error] [pid 559070:tid 559320] [client 41.89.234.2:65152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fFiy1f1FtKC137xsbiAAAAgc"]
[Tue Jul 21 08:59:18.994536 2026] [security2:error] [pid 559070:tid 559320] [client 41.89.234.2:65152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fFiy1f1FtKC137xsbiAAAAgc"]
[Tue Jul 21 08:59:19.030850 2026] [security2:error] [pid 559070:tid 559224] [client 117.210.181.114:14401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.181.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fFyy1f1FtKC137xsbiQAAAac"]
[Tue Jul 21 08:59:19.031024 2026] [security2:error] [pid 559070:tid 559224] [client 117.210.181.114:14401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fFyy1f1FtKC137xsbiQAAAac"]
[Tue Jul 21 08:59:19.076999 2026] [security2:error] [pid 559070:tid 559258] [client 65.21.113.253:32968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fFiy1f1FtKC137xsbfgAAAck"]
[Tue Jul 21 08:59:19.139010 2026] [proxy:error] [pid 559070:tid 559301] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:19.139044 2026] [proxy_http:error] [pid 559070:tid 559301] [client 64.227.109.168:52940] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:19.139510 2026] [proxy:error] [pid 559070:tid 559301] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:19.139530 2026] [proxy_http:error] [pid 559070:tid 559301] [client 64.227.109.168:52940] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:19.299213 2026] [security2:error] [pid 559070:tid 559285] [client 91.148.245.81:53342] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/.ssh/id_ecdsa"] [unique_id "al9fFyy1f1FtKC137xsbmgAAAeQ"]
[Tue Jul 21 08:59:19.299506 2026] [security2:error] [pid 559070:tid 559253] [client 91.148.245.81:53318] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/backup.zip"] [unique_id "al9fFyy1f1FtKC137xsbmwAAAcQ"]
[Tue Jul 21 08:59:19.300666 2026] [security2:error] [pid 559070:tid 559247] [client 91.148.245.81:53314] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/backup.tar.gz"] [unique_id "al9fFyy1f1FtKC137xsbnAAAAb4"]
[Tue Jul 21 08:59:19.301150 2026] [security2:error] [pid 533360:tid 533615] [client 91.148.245.81:53300] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/.ssh/id_ed25519"] [unique_id "al9fF3UPuLYrePtEkUc7NQAAAP8"]
[Tue Jul 21 08:59:19.404280 2026] [security2:error] [pid 559070:tid 559298] [client 74.249.245.134:12878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/mds.php"] [unique_id "al9fFyy1f1FtKC137xsboQAAAfE"]
[Tue Jul 21 08:59:19.501800 2026] [security2:error] [pid 533360:tid 533578] [client 91.148.245.81:53348] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-config.php"] [unique_id "al9fF3UPuLYrePtEkUc7QAAAANo"]
[Tue Jul 21 08:59:19.502180 2026] [security2:error] [pid 559070:tid 559273] [client 91.148.245.81:53328] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/user_secrets.yml"] [unique_id "al9fFyy1f1FtKC137xsbowAAAdg"]
[Tue Jul 21 08:59:19.504963 2026] [security2:error] [pid 533360:tid 533513] [client 91.148.245.81:53308] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/actuator/heapdump"] [unique_id "al9fF3UPuLYrePtEkUc7QQAAAJk"]
[Tue Jul 21 08:59:19.580291 2026] [security2:error] [pid 533360:tid 533373] [remote 41.186.86.12:40912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "valloratoodo.com"] [uri "/wp-login.php"] [unique_id "al9fF3UPuLYrePtEkUc7QgAA_gk"]
[Tue Jul 21 08:59:19.587538 2026] [security2:error] [pid 559070:tid 559264] [client 20.220.225.223:34278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/ez.php"] [unique_id "al9fFyy1f1FtKC137xsbpgAAAc8"]
[Tue Jul 21 08:59:19.660044 2026] [security2:error] [pid 559070:tid 559220] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fFyy1f1FtKC137xsbpQAAAaM"]
[Tue Jul 21 08:59:19.680734 2026] [security2:error] [pid 533360:tid 533595] [client 20.220.225.223:34244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/cron-tab.php"] [unique_id "al9fF3UPuLYrePtEkUc7RAAAAOs"]
[Tue Jul 21 08:59:19.720941 2026] [security2:error] [pid 533360:tid 533594] [client 182.189.99.211:48081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fF3UPuLYrePtEkUc7RwAAAOo"]
[Tue Jul 21 08:59:19.721062 2026] [security2:error] [pid 533360:tid 533594] [client 182.189.99.211:48081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fF3UPuLYrePtEkUc7RwAAAOo"]
[Tue Jul 21 08:59:19.908545 2026] [security2:error] [pid 559070:tid 559268] [client 74.249.245.134:12886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/archive.php"] [unique_id "al9fFyy1f1FtKC137xsbrwAAAdM"]
[Tue Jul 21 08:59:19.938588 2026] [security2:error] [pid 559070:tid 559236] [client 184.154.36.163:59350] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/contato/"] [unique_id "al9fFyy1f1FtKC137xsbogAAAbM"]
[Tue Jul 21 08:59:20.036875 2026] [security2:error] [pid 559070:tid 559271] [client 154.182.128.22:53557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.128.182.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fGCy1f1FtKC137xsbsQAAAdY"]
[Tue Jul 21 08:59:20.037390 2026] [security2:error] [pid 559070:tid 559271] [client 154.182.128.22:53557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fGCy1f1FtKC137xsbsQAAAdY"]
[Tue Jul 21 08:59:20.302650 2026] [security2:error] [pid 559070:tid 559323] [client 91.148.245.81:53364] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/.git/HEAD"] [unique_id "al9fGCy1f1FtKC137xsbtgAAAgo"]
[Tue Jul 21 08:59:20.307233 2026] [security2:error] [pid 533360:tid 533587] [client 74.249.245.134:12807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/amax.php"] [unique_id "al9fGHUPuLYrePtEkUc7UQAAAOM"]
[Tue Jul 21 08:59:20.313576 2026] [security2:error] [pid 559070:tid 559252] [client 91.148.245.81:53384] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-admin/setup-config.php"] [unique_id "al9fGCy1f1FtKC137xsbtwAAAcM"]
[Tue Jul 21 08:59:20.315665 2026] [security2:error] [pid 559070:tid 559214] [client 91.148.245.81:53392] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/_vti_pvt/service.pwd"] [unique_id "al9fGCy1f1FtKC137xsbuAAAAZ0"]
[Tue Jul 21 08:59:20.318125 2026] [security2:error] [pid 533360:tid 533552] [client 20.220.225.223:30658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/dr.php"] [unique_id "al9fGHUPuLYrePtEkUc7UgAAAMA"]
[Tue Jul 21 08:59:20.405348 2026] [security2:error] [pid 559070:tid 559284] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fGCy1f1FtKC137xsbtAAB4zI"]
[Tue Jul 21 08:59:20.442452 2026] [security2:error] [pid 533360:tid 533490] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fGHUPuLYrePtEkUc7VQAAp34"]
[Tue Jul 21 08:59:20.442547 2026] [security2:error] [pid 533360:tid 533527] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fGHUPuLYrePtEkUc7VQAAp34"]
[Tue Jul 21 08:59:20.523434 2026] [security2:error] [pid 559070:tid 559295] [client 20.151.10.161:51018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/als.php"] [unique_id "al9fGCy1f1FtKC137xsbvgAAAe4"]
[Tue Jul 21 08:59:20.652239 2026] [security2:error] [pid 559070:tid 559308] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fGCy1f1FtKC137xsbvwAAAfs"]
[Tue Jul 21 08:59:20.708031 2026] [security2:error] [pid 533360:tid 533500] [client 194.99.104.35:50944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9fGHUPuLYrePtEkUc7WAAAAIw"]
[Tue Jul 21 08:59:20.708116 2026] [security2:error] [pid 533360:tid 533500] [client 194.99.104.35:50944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9fGHUPuLYrePtEkUc7WAAAAIw"]
[Tue Jul 21 08:59:20.799589 2026] [security2:error] [pid 533360:tid 533570] [client 20.220.225.223:34710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/wp-editor.php"] [unique_id "al9fGHUPuLYrePtEkUc7XgAAANI"]
[Tue Jul 21 08:59:21.318403 2026] [security2:error] [pid 533360:tid 533617] [client 59.95.197.55:62911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fGXUPuLYrePtEkUc7ZAAAAQE"]
[Tue Jul 21 08:59:21.318610 2026] [security2:error] [pid 533360:tid 533617] [client 59.95.197.55:62911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fGXUPuLYrePtEkUc7ZAAAAQE"]
[Tue Jul 21 08:59:21.451994 2026] [security2:error] [pid 533360:tid 533513] [client 74.249.245.134:43707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/moon.php"] [unique_id "al9fGXUPuLYrePtEkUc7aAAAAJk"]
[Tue Jul 21 08:59:21.566078 2026] [security2:error] [pid 559070:tid 559258] [client 139.167.208.211:57000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.208.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fGSy1f1FtKC137xsbzAAAAck"]
[Tue Jul 21 08:59:21.566225 2026] [security2:error] [pid 559070:tid 559258] [client 139.167.208.211:57000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fGSy1f1FtKC137xsbzAAAAck"]
[Tue Jul 21 08:59:21.576014 2026] [security2:error] [pid 533360:tid 533545] [client 91.148.245.81:53352] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/phpinfo.php"] [unique_id "al9fGXUPuLYrePtEkUc7bgAAALk"]
[Tue Jul 21 08:59:21.725146 2026] [security2:error] [pid 559070:tid 559220] [client 20.220.225.223:30904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/2x.php"] [unique_id "al9fGSy1f1FtKC137xsbzQAAAaM"]
[Tue Jul 21 08:59:21.736311 2026] [security2:error] [pid 533360:tid 533514] [client 65.21.113.253:35586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fGXUPuLYrePtEkUc7ZQAAAJo"]
[Tue Jul 21 08:59:21.759217 2026] [security2:error] [pid 559070:tid 559271] [client 91.148.245.81:53420] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/api/.env"] [unique_id "al9fGSy1f1FtKC137xsbzgAAAdY"]
[Tue Jul 21 08:59:21.780899 2026] [security2:error] [pid 559070:tid 559177] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fGSy1f1FtKC137xsbzwAB2Go"]
[Tue Jul 21 08:59:21.781051 2026] [security2:error] [pid 559070:tid 559273] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fGSy1f1FtKC137xsbzwAB2Go"]
[Tue Jul 21 08:59:21.848350 2026] [access_compat:error] [pid 533360:tid 533539] [client 162.241.63.68:33076] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 08:59:22.158381 2026] [security2:error] [pid 533360:tid 533508] [client 98.159.37.217:48155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.37.159.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mecdutos.com.br"] [uri "/wp-login.php"] [unique_id "al9fGXUPuLYrePtEkUc7eAAAAJQ"]
[Tue Jul 21 08:59:22.317526 2026] [security2:error] [pid 559070:tid 559285] [client 91.148.245.81:53450] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/.env"] [unique_id "al9fGiy1f1FtKC137xsb1QAAAeQ"]
[Tue Jul 21 08:59:22.318416 2026] [security2:error] [pid 533360:tid 533537] [client 91.148.245.81:53436] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/.env.production"] [unique_id "al9fGnUPuLYrePtEkUc7hQAAALE"]
[Tue Jul 21 08:59:22.340953 2026] [security2:error] [pid 559070:tid 559224] [client 20.151.10.161:49137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/aa2.php"] [unique_id "al9fGiy1f1FtKC137xsb1gAAAac"]
[Tue Jul 21 08:59:22.361194 2026] [security2:error] [pid 559070:tid 559227] [client 198.44.157.162:52966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9fGiy1f1FtKC137xsb1wAAAao"]
[Tue Jul 21 08:59:22.361407 2026] [security2:error] [pid 559070:tid 559227] [client 198.44.157.162:52966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9fGiy1f1FtKC137xsb1wAAAao"]
[Tue Jul 21 08:59:22.431203 2026] [security2:error] [pid 559070:tid 559274] [client 74.249.245.134:27296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/asd.php"] [unique_id "al9fGiy1f1FtKC137xsb2gAAAdk"]
[Tue Jul 21 08:59:22.687405 2026] [security2:error] [pid 559070:tid 559220] [client 91.148.245.81:53468] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/docker-compose.yml"] [unique_id "al9fGiy1f1FtKC137xsb5AAAAaM"]
[Tue Jul 21 08:59:22.687468 2026] [security2:error] [pid 559070:tid 559271] [client 91.148.245.81:53506] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/server.key"] [unique_id "al9fGiy1f1FtKC137xsb4wAAAdY"]
[Tue Jul 21 08:59:22.849654 2026] [security2:error] [pid 533360:tid 533524] [client 128.127.105.184:42750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9fGnUPuLYrePtEkUc7qgAAAKQ"]
[Tue Jul 21 08:59:22.849773 2026] [security2:error] [pid 533360:tid 533524] [client 128.127.105.184:42750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9fGnUPuLYrePtEkUc7qgAAAKQ"]
[Tue Jul 21 08:59:23.122655 2026] [security2:error] [pid 559070:tid 559308] [client 20.220.225.223:30671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/kq1.php"] [unique_id "al9fGyy1f1FtKC137xsb8gAAAfs"]
[Tue Jul 21 08:59:23.188513 2026] [security2:error] [pid 559070:tid 559324] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fGyy1f1FtKC137xsb9QAAAgs"]
[Tue Jul 21 08:59:23.231777 2026] [security2:error] [pid 533360:tid 533536] [client 103.59.206.240:37312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fG3UPuLYrePtEkUc7sAAAALA"]
[Tue Jul 21 08:59:23.231900 2026] [security2:error] [pid 533360:tid 533536] [client 103.59.206.240:37312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fG3UPuLYrePtEkUc7sAAAALA"]
[Tue Jul 21 08:59:23.310310 2026] [security2:error] [pid 533360:tid 533612] [client 91.148.245.81:54486] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/.vscode/sftp.json"] [unique_id "al9fG3UPuLYrePtEkUc7swAAAPw"]
[Tue Jul 21 08:59:23.459675 2026] [proxy:error] [pid 559070:tid 559277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:23.459741 2026] [proxy_http:error] [pid 559070:tid 559277] [client 64.227.109.168:53030] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.dinamicandoo.com.br/
[Tue Jul 21 08:59:23.460365 2026] [proxy:error] [pid 559070:tid 559277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:23.460394 2026] [proxy_http:error] [pid 559070:tid 559277] [client 64.227.109.168:53030] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.dinamicandoo.com.br/
[Tue Jul 21 08:59:23.516265 2026] [security2:error] [pid 559070:tid 559250] [client 185.8.106.219:2614] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "luanaarruda.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9fGyy1f1FtKC137xscAQAAAcE"]
[Tue Jul 21 08:59:23.620011 2026] [security2:error] [pid 559070:tid 559245] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fGyy1f1FtKC137xsb_gAAAbw"]
[Tue Jul 21 08:59:23.758476 2026] [security2:error] [pid 559070:tid 559282] [client 184.154.36.163:59370] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/contato/"] [unique_id "al9fGyy1f1FtKC137xsb-gAAAeE"]
[Tue Jul 21 08:59:23.808060 2026] [security2:error] [pid 559070:tid 559213] [client 185.8.106.219:54518] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "luanaarruda.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9fGyy1f1FtKC137xscBQAAAZw"]
[Tue Jul 21 08:59:24.104908 2026] [security2:error] [pid 533360:tid 533566] [client 20.151.10.161:51023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/pol.php"] [unique_id "al9fHHUPuLYrePtEkUc7vgAAAM4"]
[Tue Jul 21 08:59:24.151447 2026] [security2:error] [pid 559070:tid 559268] [client 114.198.138.124:61354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fHCy1f1FtKC137xscEAAAAdM"]
[Tue Jul 21 08:59:24.151594 2026] [security2:error] [pid 559070:tid 559268] [client 114.198.138.124:61354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fHCy1f1FtKC137xscEAAAAdM"]
[Tue Jul 21 08:59:24.290235 2026] [security2:error] [pid 533360:tid 533564] [client 91.148.245.81:54492] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/secrets.json"] [unique_id "al9fHHUPuLYrePtEkUc7wgAAAMw"]
[Tue Jul 21 08:59:24.290340 2026] [security2:error] [pid 533360:tid 533619] [client 91.148.245.81:54500] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/.npmrc"] [unique_id "al9fHHUPuLYrePtEkUc7wQAAAQM"]
[Tue Jul 21 08:59:24.329154 2026] [security2:error] [pid 559070:tid 559264] [client 65.21.113.253:35596] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fGyy1f1FtKC137xscBwAAAc8"]
[Tue Jul 21 08:59:24.348467 2026] [security2:error] [pid 559070:tid 559140] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fHCy1f1FtKC137xscEgABsUU"]
[Tue Jul 21 08:59:24.348742 2026] [security2:error] [pid 559070:tid 559234] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fHCy1f1FtKC137xscEgABsUU"]
[Tue Jul 21 08:59:24.455200 2026] [security2:error] [pid 533360:tid 533586] [client 20.52.136.55:1738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/ms-edit.php"] [unique_id "al9fHHUPuLYrePtEkUc7xgAAAOI"]
[Tue Jul 21 08:59:24.568430 2026] [security2:error] [pid 559070:tid 559218] [client 91.148.245.81:54468] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/config.php"] [unique_id "al9fHCy1f1FtKC137xscFAAAAaE"]
[Tue Jul 21 08:59:24.570690 2026] [security2:error] [pid 559070:tid 559214] [client 91.148.245.81:54454] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/config/production.json"] [unique_id "al9fHCy1f1FtKC137xscFQAAAZ0"]
[Tue Jul 21 08:59:24.570937 2026] [security2:error] [pid 559070:tid 559270] [client 91.148.245.81:54480] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/etc/ssl/private/server.key"] [unique_id "al9fHCy1f1FtKC137xscFgAAAdU"]
[Tue Jul 21 08:59:24.839372 2026] [security2:error] [pid 533360:tid 533537] [client 20.220.225.223:30707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/zzz.php"] [unique_id "al9fHHUPuLYrePtEkUc7zgAAALE"]
[Tue Jul 21 08:59:25.167892 2026] [security2:error] [pid 559070:tid 559241] [client 185.8.106.219:2630] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.luanaarruda.com"] [uri "/wp-json/gravitysmtp/v1/tests/mock-data"] [unique_id "al9fHSy1f1FtKC137xscHQAAAbg"]
[Tue Jul 21 08:59:25.212661 2026] [security2:error] [pid 533360:tid 533368] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fHXUPuLYrePtEkUc71gAAqgQ"]
[Tue Jul 21 08:59:25.212871 2026] [security2:error] [pid 533360:tid 533530] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fHXUPuLYrePtEkUc71gAAqgQ"]
[Tue Jul 21 08:59:25.256661 2026] [security2:error] [pid 559070:tid 559195] [remote 47.86.33.52:44452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "moneyclass.com.br"] [uri "/wp-login.php"] [unique_id "al9fHSy1f1FtKC137xscHwAB_Xw"]
[Tue Jul 21 08:59:25.325492 2026] [security2:error] [pid 559070:tid 559295] [client 117.235.80.45:50630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.80.235.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fHSy1f1FtKC137xscIAAAAe4"]
[Tue Jul 21 08:59:25.325795 2026] [security2:error] [pid 559070:tid 559295] [client 117.235.80.45:50630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fHSy1f1FtKC137xscIAAAAe4"]
[Tue Jul 21 08:59:25.601529 2026] [security2:error] [pid 533360:tid 533524] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fHXUPuLYrePtEkUc72AAAAKQ"]
[Tue Jul 21 08:59:25.878676 2026] [security2:error] [pid 559070:tid 559279] [client 184.154.36.163:59378] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/contato/"] [unique_id "al9fHSy1f1FtKC137xscIgAAAd4"]
[Tue Jul 21 08:59:26.038580 2026] [security2:error] [pid 559070:tid 559221] [client 74.249.245.134:12814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/ws83.php"] [unique_id "al9fHiy1f1FtKC137xscKgAAAaQ"]
[Tue Jul 21 08:59:26.073353 2026] [security2:error] [pid 559070:tid 559236] [client 128.127.105.184:42756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9fHiy1f1FtKC137xscKwAAAbM"]
[Tue Jul 21 08:59:26.073434 2026] [security2:error] [pid 559070:tid 559236] [client 128.127.105.184:42756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9fHiy1f1FtKC137xscKwAAAbM"]
[Tue Jul 21 08:59:26.096348 2026] [security2:error] [pid 533360:tid 533497] [client 20.220.225.223:60362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/yup.php"] [unique_id "al9fHnUPuLYrePtEkUc75AAAAIk"]
[Tue Jul 21 08:59:26.114763 2026] [security2:error] [pid 559070:tid 559315] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fHiy1f1FtKC137xscLAAAAgI"]
[Tue Jul 21 08:59:26.302385 2026] [security2:error] [pid 533360:tid 533518] [client 91.148.245.81:54538] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/backup.sql"] [unique_id "al9fHnUPuLYrePtEkUc76gAAAJ4"]
[Tue Jul 21 08:59:26.302952 2026] [security2:error] [pid 559070:tid 559298] [client 91.148.245.81:54550] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/.bash_history"] [unique_id "al9fHiy1f1FtKC137xscNAAAAfE"]
[Tue Jul 21 08:59:26.303047 2026] [security2:error] [pid 533360:tid 533609] [client 91.148.245.81:54558] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/database.sql"] [unique_id "al9fHnUPuLYrePtEkUc76QAAAPk"]
[Tue Jul 21 08:59:26.304792 2026] [security2:error] [pid 559070:tid 559285] [client 91.148.245.81:54574] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/config.xml"] [unique_id "al9fHiy1f1FtKC137xscNQAAAeQ"]
[Tue Jul 21 08:59:26.504476 2026] [security2:error] [pid 559070:tid 559320] [client 91.148.245.81:54508] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tkcorretoradeseguros.com.br"] [uri "/dump.sql"] [unique_id "al9fHiy1f1FtKC137xscOgAAAgc"]
[Tue Jul 21 08:59:26.514757 2026] [security2:error] [pid 559070:tid 559280] [client 20.151.10.161:50946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file5.php"] [unique_id "al9fHiy1f1FtKC137xscOwAAAd8"]
[Tue Jul 21 08:59:26.607396 2026] [security2:error] [pid 559070:tid 559308] [client 20.151.10.161:49042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/ccou.php"] [unique_id "al9fHiy1f1FtKC137xscPAAAAfs"]
[Tue Jul 21 08:59:26.786990 2026] [security2:error] [pid 559070:tid 559323] [client 185.8.106.219:2636] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "luanaarruda.com"] [uri "/"] [unique_id "al9fHiy1f1FtKC137xscPgAAAgo"]
[Tue Jul 21 08:59:27.081189 2026] [security2:error] [pid 559070:tid 559305] [client 74.7.228.31:54372] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "domineseucaos.com.br"] [uri "/index.php"] [unique_id "al9fHiy1f1FtKC137xscNgAB-DA"]
[Tue Jul 21 08:59:27.208395 2026] [security2:error] [pid 533360:tid 533619] [client 65.21.113.253:35598] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fHnUPuLYrePtEkUc79QAAAQM"]
[Tue Jul 21 08:59:27.514005 2026] [security2:error] [pid 559070:tid 559279] [client 113.22.144.139:49611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fHyy1f1FtKC137xscTAAAAd4"]
[Tue Jul 21 08:59:27.514102 2026] [security2:error] [pid 559070:tid 559279] [client 113.22.144.139:49611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fHyy1f1FtKC137xscTAAAAd4"]
[Tue Jul 21 08:59:27.795230 2026] [security2:error] [pid 559070:tid 559268] [client 117.214.78.59:57956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fHyy1f1FtKC137xscUwAAAdM"]
[Tue Jul 21 08:59:27.795320 2026] [security2:error] [pid 559070:tid 559268] [client 117.214.78.59:57956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fHyy1f1FtKC137xscUwAAAdM"]
[Tue Jul 21 08:59:27.834735 2026] [proxy:error] [pid 559070:tid 559264] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:27.834790 2026] [proxy_http:error] [pid 559070:tid 559264] [client 143.198.231.156:59286] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:27.835283 2026] [proxy:error] [pid 559070:tid 559264] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:27.835307 2026] [proxy_http:error] [pid 559070:tid 559264] [client 143.198.231.156:59286] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:27.848721 2026] [security2:error] [pid 559070:tid 559227] [client 20.220.225.223:34693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/cro.php"] [unique_id "al9fHyy1f1FtKC137xscVQAAAao"]
[Tue Jul 21 08:59:27.983240 2026] [security2:error] [pid 533360:tid 533544] [client 74.249.245.134:27226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/default.php"] [unique_id "al9fH3UPuLYrePtEkUc8CAAAALg"]
[Tue Jul 21 08:59:28.084416 2026] [security2:error] [pid 533360:tid 533611] [client 20.151.10.161:55833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/4PJcpMFsD8B.php"] [unique_id "al9fIHUPuLYrePtEkUc8CwAAAPs"]
[Tue Jul 21 08:59:28.195913 2026] [proxy:error] [pid 559070:tid 559209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:28.195991 2026] [proxy_http:error] [pid 559070:tid 559209] [client 143.198.231.156:59298] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.ubaloc.online/
[Tue Jul 21 08:59:28.196731 2026] [proxy:error] [pid 559070:tid 559209] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:28.196764 2026] [proxy_http:error] [pid 559070:tid 559209] [client 143.198.231.156:59298] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.ubaloc.online/
[Tue Jul 21 08:59:28.200820 2026] [core:error] [pid 533360:tid 533452] [remote 52.167.144.25:32358] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:59:28.200837 2026] [core:error] [pid 533360:tid 533452] [remote 52.167.144.25:32358] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:59:28.593603 2026] [security2:error] [pid 559070:tid 559231] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fICy1f1FtKC137xscXwAAAa4"]
[Tue Jul 21 08:59:28.606963 2026] [core:error] [pid 559070:tid 559106] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:59:28.606984 2026] [core:error] [pid 559070:tid 559106] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:59:28.779072 2026] [security2:error] [pid 559070:tid 559234] [client 20.220.225.223:34716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/cron-tab.php"] [unique_id "al9fICy1f1FtKC137xscYwAAAbE"]
[Tue Jul 21 08:59:28.910946 2026] [core:error] [pid 559070:tid 559184] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:59:28.910982 2026] [core:error] [pid 559070:tid 559184] [remote 35.233.163.26:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:59:28.916875 2026] [proxy:error] [pid 533360:tid 533518] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:28.916917 2026] [proxy_http:error] [pid 533360:tid 533518] [client 143.198.231.156:39206] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:28.917532 2026] [proxy:error] [pid 533360:tid 533518] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:28.917559 2026] [proxy_http:error] [pid 533360:tid 533518] [client 143.198.231.156:39206] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:29.474921 2026] [security2:error] [pid 559070:tid 559154] [remote 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.promocao-relampago.club"] [uri "/xmlrpc.php"] [unique_id "al9fISy1f1FtKC137xscbwAB51M"]
[Tue Jul 21 08:59:29.566998 2026] [security2:error] [pid 533360:tid 533564] [client 41.89.234.2:49238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fIXUPuLYrePtEkUc8LwAAAMw"]
[Tue Jul 21 08:59:29.567151 2026] [security2:error] [pid 533360:tid 533564] [client 41.89.234.2:49238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fIXUPuLYrePtEkUc8LwAAAMw"]
[Tue Jul 21 08:59:29.647642 2026] [security2:error] [pid 559070:tid 559213] [client 117.210.181.114:29922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.181.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fISy1f1FtKC137xsccAAAAZw"]
[Tue Jul 21 08:59:29.647778 2026] [security2:error] [pid 559070:tid 559213] [client 117.210.181.114:29922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fISy1f1FtKC137xsccAAAAZw"]
[Tue Jul 21 08:59:29.706827 2026] [security2:error] [pid 559070:tid 559280] [client 65.21.113.253:35602] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fISy1f1FtKC137xscbQAAAd8"]
[Tue Jul 21 08:59:29.755899 2026] [security2:error] [pid 559070:tid 559104] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.promocao-relampago.club"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9fISy1f1FtKC137xsccQABmiE"]
[Tue Jul 21 08:59:29.944023 2026] [security2:error] [pid 559070:tid 559110] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.promocao-relampago.club"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9fISy1f1FtKC137xscdAABryc"]
[Tue Jul 21 08:59:30.236635 2026] [security2:error] [pid 559070:tid 559078] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.promocao-relampago.club"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9fIiy1f1FtKC137xscdgABrQc"]
[Tue Jul 21 08:59:30.509836 2026] [security2:error] [pid 533360:tid 533529] [client 198.44.157.162:50930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9fInUPuLYrePtEkUc8QQAAAKk"]
[Tue Jul 21 08:59:30.509937 2026] [security2:error] [pid 533360:tid 533529] [client 198.44.157.162:50930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9fInUPuLYrePtEkUc8QQAAAKk"]
[Tue Jul 21 08:59:30.542522 2026] [security2:error] [pid 559070:tid 559087] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.promocao-relampago.club"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9fIiy1f1FtKC137xscggAB4xA"]
[Tue Jul 21 08:59:30.774088 2026] [security2:error] [pid 559070:tid 559188] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.promocao-relampago.club"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9fIiy1f1FtKC137xschwAB_3U"]
[Tue Jul 21 08:59:30.966628 2026] [security2:error] [pid 559070:tid 559093] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fIiy1f1FtKC137xscjQACAxY"]
[Tue Jul 21 08:59:30.966770 2026] [security2:error] [pid 559070:tid 559316] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fIiy1f1FtKC137xscjQACAxY"]
[Tue Jul 21 08:59:30.974370 2026] [security2:error] [pid 533360:tid 533576] [client 154.182.128.22:53990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.128.182.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fInUPuLYrePtEkUc8TgAAANg"]
[Tue Jul 21 08:59:30.974514 2026] [security2:error] [pid 533360:tid 533576] [client 154.182.128.22:53990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fInUPuLYrePtEkUc8TgAAANg"]
[Tue Jul 21 08:59:31.060850 2026] [security2:error] [pid 559070:tid 559127] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.promocao-relampago.club"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9fIyy1f1FtKC137xscjwABrzg"]
[Tue Jul 21 08:59:31.287896 2026] [security2:error] [pid 533360:tid 533505] [client 182.189.99.211:47996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fI3UPuLYrePtEkUc8VwAAAJE"]
[Tue Jul 21 08:59:31.288114 2026] [security2:error] [pid 533360:tid 533505] [client 182.189.99.211:47996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fI3UPuLYrePtEkUc8VwAAAJE"]
[Tue Jul 21 08:59:31.382614 2026] [security2:error] [pid 559070:tid 559075] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.promocao-relampago.club"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9fIyy1f1FtKC137xsckQABsQQ"]
[Tue Jul 21 08:59:31.428516 2026] [security2:error] [pid 559070:tid 559274] [client 45.3.40.43:60027] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "cmpartners.com.br"] [uri "/"] [unique_id "al9fIyy1f1FtKC137xsclgAAAdk"]
[Tue Jul 21 08:59:31.558960 2026] [security2:error] [pid 559070:tid 559214] [client 20.220.225.223:58391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/wicked.php"] [unique_id "al9fIyy1f1FtKC137xscnAAAAZ0"]
[Tue Jul 21 08:59:31.693528 2026] [security2:error] [pid 559070:tid 559277] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fIyy1f1FtKC137xscmwAB3AA"]
[Tue Jul 21 08:59:31.696576 2026] [security2:error] [pid 559070:tid 559270] [client 20.220.225.223:20963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/koiy.php"] [unique_id "al9fIyy1f1FtKC137xscnwAAAdU"]
[Tue Jul 21 08:59:31.703286 2026] [security2:error] [pid 559070:tid 559221] [client 45.3.40.43:60027] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "cmpartners.com.br"] [uri "/"] [unique_id "al9fIyy1f1FtKC137xscoAAAAaQ"]
[Tue Jul 21 08:59:31.764207 2026] [security2:error] [pid 559070:tid 559121] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.promocao-relampago.club"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9fIyy1f1FtKC137xscoQAB5DI"]
[Tue Jul 21 08:59:31.889991 2026] [security2:error] [pid 533360:tid 533518] [client 59.95.197.55:63388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fI3UPuLYrePtEkUc8YAAAAJ4"]
[Tue Jul 21 08:59:31.890790 2026] [security2:error] [pid 533360:tid 533518] [client 59.95.197.55:63388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fI3UPuLYrePtEkUc8YAAAAJ4"]
[Tue Jul 21 08:59:31.972948 2026] [security2:error] [pid 559070:tid 559301] [client 45.3.40.43:60027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cmpartners.com.br"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9fIyy1f1FtKC137xscpAAAAfQ"]
[Tue Jul 21 08:59:32.023990 2026] [security2:error] [pid 559070:tid 559167] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.promocao-relampago.club"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9fJCy1f1FtKC137xscqAABlmA"]
[Tue Jul 21 08:59:32.099797 2026] [security2:error] [pid 559070:tid 559235] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fJCy1f1FtKC137xscrAAAAbI"]
[Tue Jul 21 08:59:32.105948 2026] [security2:error] [pid 533360:tid 533573] [client 139.167.208.211:57607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.208.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fJHUPuLYrePtEkUc8ZwAAANU"]
[Tue Jul 21 08:59:32.106053 2026] [security2:error] [pid 533360:tid 533573] [client 139.167.208.211:57607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fJHUPuLYrePtEkUc8ZwAAANU"]
[Tue Jul 21 08:59:32.180013 2026] [security2:error] [pid 533360:tid 533502] [client 74.249.245.134:27247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/gettest.php"] [unique_id "al9fJHUPuLYrePtEkUc8aAAAAI4"]
[Tue Jul 21 08:59:32.231464 2026] [security2:error] [pid 559070:tid 559234] [client 198.44.157.162:45774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9fJCy1f1FtKC137xscsAAAAbE"]
[Tue Jul 21 08:59:32.231545 2026] [security2:error] [pid 559070:tid 559234] [client 198.44.157.162:45774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9fJCy1f1FtKC137xscsAAAAbE"]
[Tue Jul 21 08:59:32.249931 2026] [security2:error] [pid 559070:tid 559177] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.promocao-relampago.club"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9fJCy1f1FtKC137xscsQAB7Wo"]
[Tue Jul 21 08:59:32.304660 2026] [security2:error] [pid 559070:tid 559231] [client 74.249.245.134:43710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/CDX1.php"] [unique_id "al9fJCy1f1FtKC137xscsgAAAa4"]
[Tue Jul 21 08:59:32.305337 2026] [security2:error] [pid 559070:tid 559165] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fJCy1f1FtKC137xscswACA14"]
[Tue Jul 21 08:59:32.305610 2026] [security2:error] [pid 559070:tid 559316] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fJCy1f1FtKC137xscswACA14"]
[Tue Jul 21 08:59:32.674085 2026] [security2:error] [pid 559070:tid 559086] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.promocao-relampago.club"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9fJCy1f1FtKC137xscvgABmw8"]
[Tue Jul 21 08:59:32.839169 2026] [security2:error] [pid 533360:tid 533519] [client 20.220.225.223:20896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/hp2.php"] [unique_id "al9fJHUPuLYrePtEkUc8dwAAAJ8"]
[Tue Jul 21 08:59:32.875992 2026] [security2:error] [pid 559070:tid 559252] [client 45.3.40.43:9683] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "cmpartners.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fJCy1f1FtKC137xscvQAAAcM"]
[Tue Jul 21 08:59:32.918402 2026] [security2:error] [pid 559070:tid 559083] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.promocao-relampago.club"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9fJCy1f1FtKC137xscxwABsgw"]
[Tue Jul 21 08:59:33.145213 2026] [security2:error] [pid 559070:tid 559208] [client 45.3.40.43:9683] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ://%{SERVER_NAME}/" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "73"] [id "340012"] [rev "3"] [msg "Atomicorp.com WAF Rules: Unauthorized Proxy access attempt"] [data "http:/"] [severity "CRITICAL"] [hostname "cmpartners.com.br"] [uri "/"] [unique_id "al9fJSy1f1FtKC137xsczgAAAZc"]
[Tue Jul 21 08:59:33.218907 2026] [security2:error] [pid 559070:tid 559285] [client 65.21.113.253:60538] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fJCy1f1FtKC137xscwAAAAeQ"]
[Tue Jul 21 08:59:33.228569 2026] [security2:error] [pid 533360:tid 533594] [client 20.220.225.223:34291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/koiy.php"] [unique_id "al9fJXUPuLYrePtEkUc8hQAAAOo"]
[Tue Jul 21 08:59:33.238401 2026] [proxy:error] [pid 533360:tid 533600] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:33.238479 2026] [proxy_http:error] [pid 533360:tid 533600] [client 143.198.231.156:59494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.ubaloc.online/
[Tue Jul 21 08:59:33.239029 2026] [proxy:error] [pid 533360:tid 533600] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:33.239054 2026] [proxy_http:error] [pid 533360:tid 533600] [client 143.198.231.156:59494] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.ubaloc.online/
[Tue Jul 21 08:59:33.412797 2026] [security2:error] [pid 559070:tid 559259] [client 45.3.40.43:9683] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cmpartners.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9fJSy1f1FtKC137xsc1QAAAco"]
[Tue Jul 21 08:59:33.497618 2026] [security2:error] [pid 559070:tid 559112] [remote 199.189.225.40:57351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9fJSy1f1FtKC137xsc1gABuCk"]
[Tue Jul 21 08:59:33.509392 2026] [security2:error] [pid 533360:tid 533505] [client 198.44.157.162:50938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9fJXUPuLYrePtEkUc8igAAAJE"]
[Tue Jul 21 08:59:33.509478 2026] [security2:error] [pid 533360:tid 533505] [client 198.44.157.162:50938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9fJXUPuLYrePtEkUc8igAAAJE"]
[Tue Jul 21 08:59:33.542443 2026] [security2:error] [pid 559070:tid 559218] [client 20.151.10.161:48627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/dr.php"] [unique_id "al9fJSy1f1FtKC137xsc2AAAAaE"]
[Tue Jul 21 08:59:33.863270 2026] [security2:error] [pid 559070:tid 559316] [client 103.59.206.240:31299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fJSy1f1FtKC137xsc2wAAAgM"]
[Tue Jul 21 08:59:33.863389 2026] [security2:error] [pid 559070:tid 559316] [client 103.59.206.240:31299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fJSy1f1FtKC137xsc2wAAAgM"]
[Tue Jul 21 08:59:33.890568 2026] [security2:error] [pid 559070:tid 559258] [client 20.151.10.161:51067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file.php"] [unique_id "al9fJSy1f1FtKC137xsc3AAAAck"]
[Tue Jul 21 08:59:33.977268 2026] [security2:error] [pid 559070:tid 559268] [client 45.3.40.43:60615] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cmpartners.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9fJSy1f1FtKC137xsc3wAAAdM"]
[Tue Jul 21 08:59:34.530417 2026] [security2:error] [pid 559070:tid 559204] [client 45.3.40.43:22817] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cmpartners.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9fJiy1f1FtKC137xsc7QAAAZM"]
[Tue Jul 21 08:59:34.708280 2026] [security2:error] [pid 559070:tid 559221] [client 114.198.138.124:61929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fJiy1f1FtKC137xsc8gAAAaQ"]
[Tue Jul 21 08:59:34.708376 2026] [security2:error] [pid 559070:tid 559221] [client 114.198.138.124:61929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fJiy1f1FtKC137xsc8gAAAaQ"]
[Tue Jul 21 08:59:34.890176 2026] [security2:error] [pid 559070:tid 559198] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fJiy1f1FtKC137xsc8wABln8"]
[Tue Jul 21 08:59:34.890317 2026] [security2:error] [pid 559070:tid 559207] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fJiy1f1FtKC137xsc8wABln8"]
[Tue Jul 21 08:59:35.075075 2026] [security2:error] [pid 559070:tid 559323] [client 45.3.40.43:62393] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cmpartners.com.br"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al9fJyy1f1FtKC137xsc9wAAAgo"]
[Tue Jul 21 08:59:35.097617 2026] [security2:error] [pid 559070:tid 559258] [client 74.249.245.134:12912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/inputs.php"] [unique_id "al9fJyy1f1FtKC137xsc-AAAAck"]
[Tue Jul 21 08:59:35.169470 2026] [security2:error] [pid 559070:tid 559304] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fJyy1f1FtKC137xsc-wAAAfc"]
[Tue Jul 21 08:59:35.319549 2026] [security2:error] [pid 559070:tid 559318] [client 20.220.225.223:53494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/jj.php"] [unique_id "al9fJyy1f1FtKC137xsc_QAAAgU"]
[Tue Jul 21 08:59:35.392566 2026] [security2:error] [pid 559070:tid 559140] [remote 18.61.192.253:56892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "foreverconfidence.com"] [uri "/wp-login.php"] [unique_id "al9fJyy1f1FtKC137xsc_wAB5UU"]
[Tue Jul 21 08:59:35.621973 2026] [security2:error] [pid 559070:tid 559234] [client 45.3.40.43:51779] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cmpartners.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9fJyy1f1FtKC137xsdAwAAAbE"]
[Tue Jul 21 08:59:35.658762 2026] [security2:error] [pid 559070:tid 559176] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fJyy1f1FtKC137xsdBgABzWk"]
[Tue Jul 21 08:59:35.658938 2026] [security2:error] [pid 559070:tid 559262] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fJyy1f1FtKC137xsdBgABzWk"]
[Tue Jul 21 08:59:35.774088 2026] [security2:error] [pid 559070:tid 559265] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fJyy1f1FtKC137xsdBAAAAdA"]
[Tue Jul 21 08:59:35.774306 2026] [security2:error] [pid 533360:tid 533524] [client 184.154.36.163:35998] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/search/1/feed/rss2/"] [unique_id "al9fJ3UPuLYrePtEkUc8sgAAAKQ"]
[Tue Jul 21 08:59:35.846496 2026] [security2:error] [pid 559070:tid 559244] [client 117.235.80.45:51238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.80.235.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fJyy1f1FtKC137xsdCwAAAbs"]
[Tue Jul 21 08:59:35.846626 2026] [security2:error] [pid 559070:tid 559244] [client 117.235.80.45:51238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fJyy1f1FtKC137xsdCwAAAbs"]
[Tue Jul 21 08:59:36.139872 2026] [security2:error] [pid 559070:tid 559144] [remote 120.72.98.5:6010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.98.72.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/wp-login.php"] [unique_id "al9fKCy1f1FtKC137xsdDAABkEk"]
[Tue Jul 21 08:59:36.164496 2026] [security2:error] [pid 533360:tid 533590] [client 45.3.40.43:39549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cmpartners.com.br"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9fKHUPuLYrePtEkUc8vgAAAOY"]
[Tue Jul 21 08:59:36.222835 2026] [security2:error] [pid 559070:tid 559320] [client 65.21.113.253:60540] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fJyy1f1FtKC137xsdCgAAAgc"]
[Tue Jul 21 08:59:36.645508 2026] [security2:error] [pid 533360:tid 533586] [client 74.249.245.134:12803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/ms-edit.php"] [unique_id "al9fKHUPuLYrePtEkUc8yAAAAOI"]
[Tue Jul 21 08:59:36.714581 2026] [security2:error] [pid 533360:tid 533585] [client 45.3.40.43:27703] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cmpartners.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9fKHUPuLYrePtEkUc8zAAAAOE"]
[Tue Jul 21 08:59:37.057224 2026] [security2:error] [pid 533360:tid 533566] [client 185.213.175.37:33832] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "budhug.com.br"] [uri "/.env.production"] [unique_id "al9fKXUPuLYrePtEkUc80wAAAM4"]
[Tue Jul 21 08:59:37.102401 2026] [security2:error] [pid 559070:tid 559268] [client 74.7.230.24:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thiagomartins1751401662940.0711679.meusitehostgator.com.br"] [uri "/robots.txt"] [unique_id "al9fKSy1f1FtKC137xsdFQAB00w"]
[Tue Jul 21 08:59:37.219955 2026] [security2:error] [pid 559070:tid 559226] [client 20.220.225.223:42526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/edit.php"] [unique_id "al9fKSy1f1FtKC137xsdHAAAAak"]
[Tue Jul 21 08:59:37.264661 2026] [security2:error] [pid 559070:tid 559271] [client 45.3.40.43:54071] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cmpartners.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9fKSy1f1FtKC137xsdHQAAAdY"]
[Tue Jul 21 08:59:37.762876 2026] [security2:error] [pid 559070:tid 559286] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fKSy1f1FtKC137xsdKQAAAeU"]
[Tue Jul 21 08:59:37.804838 2026] [security2:error] [pid 559070:tid 559246] [client 45.3.40.43:50731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cmpartners.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9fKSy1f1FtKC137xsdKwAAAb0"]
[Tue Jul 21 08:59:37.869332 2026] [security2:error] [pid 559070:tid 559236] [client 20.220.225.223:53440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/dragonshell.php"] [unique_id "al9fKSy1f1FtKC137xsdLwAAAbM"]
[Tue Jul 21 08:59:38.025571 2026] [security2:error] [pid 559070:tid 559250] [client 168.167.81.163:63579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9fKiy1f1FtKC137xsdNAAAAcE"]
[Tue Jul 21 08:59:38.025653 2026] [security2:error] [pid 559070:tid 559250] [client 168.167.81.163:63579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9fKiy1f1FtKC137xsdNAAAAcE"]
[Tue Jul 21 08:59:38.254799 2026] [security2:error] [pid 559070:tid 559221] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fKiy1f1FtKC137xsdNwAAAaQ"]
[Tue Jul 21 08:59:38.255870 2026] [security2:error] [pid 559070:tid 559253] [client 184.154.36.163:41620] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/search/1/feed/rss2/"] [unique_id "al9fKiy1f1FtKC137xsdNQAAAcQ"]
[Tue Jul 21 08:59:38.272554 2026] [security2:error] [pid 559070:tid 559321] [client 117.214.78.59:58402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fKiy1f1FtKC137xsdPAAAAgg"]
[Tue Jul 21 08:59:38.272748 2026] [security2:error] [pid 559070:tid 559321] [client 117.214.78.59:58402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fKiy1f1FtKC137xsdPAAAAgg"]
[Tue Jul 21 08:59:38.320784 2026] [security2:error] [pid 559070:tid 559279] [client 216.244.66.244:55194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nrfilmes.com"] [uri "/robots.txt"] [unique_id "al9fKiy1f1FtKC137xsdPQAAAd4"]
[Tue Jul 21 08:59:38.320974 2026] [security2:error] [pid 559070:tid 559279] [client 216.244.66.244:55194] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nrfilmes.com"] [uri "/robots.txt"] [unique_id "al9fKiy1f1FtKC137xsdPQAAAd4"]
[Tue Jul 21 08:59:38.345519 2026] [security2:error] [pid 533360:tid 533570] [client 45.3.40.43:17801] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cmpartners.com.br"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9fKnUPuLYrePtEkUc86QAAANI"]
[Tue Jul 21 08:59:38.493082 2026] [security2:error] [pid 559070:tid 559323] [client 113.22.144.139:50155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fKiy1f1FtKC137xsdPwAAAgo"]
[Tue Jul 21 08:59:38.493295 2026] [security2:error] [pid 559070:tid 559323] [client 113.22.144.139:50155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fKiy1f1FtKC137xsdPwAAAgo"]
[Tue Jul 21 08:59:38.769442 2026] [security2:error] [pid 559070:tid 559137] [remote 84.247.172.23:55050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3d-surgery.com.br"] [uri "/wp-login.php"] [unique_id "al9fKiy1f1FtKC137xsdQwABrUI"]
[Tue Jul 21 08:59:38.848398 2026] [security2:error] [pid 559070:tid 559320] [client 65.21.113.253:60556] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fKiy1f1FtKC137xsdPgAAAgc"]
[Tue Jul 21 08:59:38.893105 2026] [security2:error] [pid 533360:tid 533594] [client 45.3.40.43:47967] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cmpartners.com.br"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9fKnUPuLYrePtEkUc89AAAAOo"]
[Tue Jul 21 08:59:39.135701 2026] [core:error] [pid 559070:tid 559135] [remote 147.185.132.22:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:59:39.135726 2026] [core:error] [pid 559070:tid 559135] [remote 147.185.132.22:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 08:59:39.435702 2026] [security2:error] [pid 559070:tid 559227] [client 45.3.40.43:38517] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cmpartners.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9fKyy1f1FtKC137xsdSgAAAao"]
[Tue Jul 21 08:59:39.445216 2026] [security2:error] [pid 559070:tid 559207] [client 74.249.245.134:12906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/simple.php"] [unique_id "al9fKyy1f1FtKC137xsdSwAAAZY"]
[Tue Jul 21 08:59:39.626911 2026] [security2:error] [pid 559070:tid 559143] [remote 199.189.225.40:57357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9fKyy1f1FtKC137xsdTQACAkg"]
[Tue Jul 21 08:59:39.771540 2026] [security2:error] [pid 533360:tid 533531] [client 74.249.245.134:27291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/tfm.php"] [unique_id "al9fK3UPuLYrePtEkUc9AwAAAKs"]
[Tue Jul 21 08:59:39.981781 2026] [security2:error] [pid 559070:tid 559304] [client 45.3.40.43:50341] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cmpartners.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9fKyy1f1FtKC137xsdVQAAAfc"]
[Tue Jul 21 08:59:40.123635 2026] [security2:error] [pid 559070:tid 559245] [client 41.89.234.2:49715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fLCy1f1FtKC137xsdVwAAAbw"]
[Tue Jul 21 08:59:40.123795 2026] [security2:error] [pid 559070:tid 559245] [client 41.89.234.2:49715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fLCy1f1FtKC137xsdVwAAAbw"]
[Tue Jul 21 08:59:40.376747 2026] [security2:error] [pid 533360:tid 533567] [client 20.220.225.223:30695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/kua.php"] [unique_id "al9fLHUPuLYrePtEkUc9DQAAAM8"]
[Tue Jul 21 08:59:40.456292 2026] [security2:error] [pid 533360:tid 533550] [client 115.245.198.210:64801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fLHUPuLYrePtEkUc9DwAAAL4"]
[Tue Jul 21 08:59:40.456419 2026] [security2:error] [pid 533360:tid 533550] [client 115.245.198.210:64801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fLHUPuLYrePtEkUc9DwAAAL4"]
[Tue Jul 21 08:59:40.589354 2026] [security2:error] [pid 533360:tid 533593] [client 65.21.113.253:37718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/robots.txt"] [unique_id "al9fLHUPuLYrePtEkUc9EAAAAOk"]
[Tue Jul 21 08:59:40.959923 2026] [security2:error] [pid 533360:tid 533589] [client 20.220.225.223:53444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/wp-mt.php"] [unique_id "al9fLHUPuLYrePtEkUc9FwAAAOU"]
[Tue Jul 21 08:59:41.161504 2026] [security2:error] [pid 559070:tid 559253] [client 20.52.136.55:1733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/simple.php"] [unique_id "al9fLSy1f1FtKC137xsdbAAAAcQ"]
[Tue Jul 21 08:59:41.446508 2026] [security2:error] [pid 559070:tid 559130] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fLSy1f1FtKC137xsdcgABmDs"]
[Tue Jul 21 08:59:41.446639 2026] [security2:error] [pid 559070:tid 559209] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fLSy1f1FtKC137xsdcgABmDs"]
[Tue Jul 21 08:59:41.475638 2026] [security2:error] [pid 559070:tid 559250] [client 65.21.113.253:41744] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fLSy1f1FtKC137xsdbQAAAcE"]
[Tue Jul 21 08:59:41.706175 2026] [security2:error] [pid 559070:tid 559274] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fLSy1f1FtKC137xsddwAAAdk"]
[Tue Jul 21 08:59:41.737835 2026] [security2:error] [pid 559070:tid 559276] [client 20.226.114.112:15908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nkpiscinas.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al9fLSy1f1FtKC137xsdewAAAds"]
[Tue Jul 21 08:59:41.769126 2026] [security2:error] [pid 559070:tid 559268] [client 20.226.114.112:14014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nkpiscinas.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9fLSy1f1FtKC137xsdfgAAAdM"]
[Tue Jul 21 08:59:41.789002 2026] [security2:error] [pid 533360:tid 533546] [client 20.226.114.112:14783] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nkpiscinas.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9fLXUPuLYrePtEkUc9JQAAALo"]
[Tue Jul 21 08:59:41.802361 2026] [security2:error] [pid 533360:tid 533594] [client 20.226.114.112:13978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nkpiscinas.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9fLXUPuLYrePtEkUc9JgAAAOo"]
[Tue Jul 21 08:59:41.813102 2026] [security2:error] [pid 533360:tid 533512] [client 20.226.114.112:13958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nkpiscinas.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al9fLXUPuLYrePtEkUc9JwAAAJg"]
[Tue Jul 21 08:59:41.825692 2026] [security2:error] [pid 533360:tid 533597] [client 20.226.114.112:15911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nkpiscinas.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9fLXUPuLYrePtEkUc9KAAAAO0"]
[Tue Jul 21 08:59:41.835253 2026] [security2:error] [pid 533360:tid 533529] [client 20.226.114.112:1219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nkpiscinas.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9fLXUPuLYrePtEkUc9KgAAAKk"]
[Tue Jul 21 08:59:41.879503 2026] [security2:error] [pid 559070:tid 559235] [client 20.226.114.112:1232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nkpiscinas.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al9fLSy1f1FtKC137xsdfwAAAbI"]
[Tue Jul 21 08:59:41.895195 2026] [security2:error] [pid 559070:tid 559211] [client 20.226.114.112:13987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nkpiscinas.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al9fLSy1f1FtKC137xsdgAAAAZo"]
[Tue Jul 21 08:59:41.914742 2026] [security2:error] [pid 559070:tid 559231] [client 20.226.114.112:1240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nkpiscinas.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9fLSy1f1FtKC137xsdggAAAa4"]
[Tue Jul 21 08:59:41.940526 2026] [security2:error] [pid 559070:tid 559214] [client 20.226.114.112:14726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "nkpiscinas.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9fLSy1f1FtKC137xsdgwAAAZ0"]
[Tue Jul 21 08:59:41.959171 2026] [security2:error] [pid 533360:tid 533524] [client 154.182.128.22:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.128.182.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fLXUPuLYrePtEkUc9MQAAAKQ"]
[Tue Jul 21 08:59:41.959295 2026] [security2:error] [pid 533360:tid 533524] [client 154.182.128.22:54436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fLXUPuLYrePtEkUc9MQAAAKQ"]
[Tue Jul 21 08:59:41.978445 2026] [security2:error] [pid 559070:tid 559315] [client 184.154.36.163:59390] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/wpforms-lite/assets/js/frontend/fields/address.min.js"] [unique_id "al9fLSy1f1FtKC137xsdhgAAAgI"]
[Tue Jul 21 08:59:41.999961 2026] [security2:error] [pid 559070:tid 559204] [client 173.252.95.24:44926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fLSy1f1FtKC137xsdhwAAAZM"]
[Tue Jul 21 08:59:42.193021 2026] [security2:error] [pid 559070:tid 559302] [client 20.220.225.223:34698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/hp3.php"] [unique_id "al9fLiy1f1FtKC137xsdjAAAAfU"]
[Tue Jul 21 08:59:42.424577 2026] [security2:error] [pid 533360:tid 533576] [client 59.95.197.55:63870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fLnUPuLYrePtEkUc9OAAAANg"]
[Tue Jul 21 08:59:42.424717 2026] [security2:error] [pid 533360:tid 533576] [client 59.95.197.55:63870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fLnUPuLYrePtEkUc9OAAAANg"]
[Tue Jul 21 08:59:42.444963 2026] [fcgid:warn] [pid 533360:tid 533573] (70014)End of file found: [client 184.154.36.163:41628] mod_fcgid: can't get data from http client
[Tue Jul 21 08:59:42.584296 2026] [security2:error] [pid 559070:tid 559154] [remote 20.153.140.50:55142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "siteecommerceshop.com"] [uri "/wp-login.php"] [unique_id "al9fLiy1f1FtKC137xsdkwAByVM"]
[Tue Jul 21 08:59:42.671968 2026] [security2:error] [pid 533360:tid 533579] [client 20.151.10.161:31370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/cfile.php"] [unique_id "al9fLnUPuLYrePtEkUc9PQAAANs"]
[Tue Jul 21 08:59:42.755266 2026] [security2:error] [pid 559070:tid 559257] [client 139.167.208.211:58212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.208.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fLiy1f1FtKC137xsdlQAAAcg"]
[Tue Jul 21 08:59:42.755436 2026] [security2:error] [pid 559070:tid 559257] [client 139.167.208.211:58212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fLiy1f1FtKC137xsdlQAAAcg"]
[Tue Jul 21 08:59:42.799405 2026] [security2:error] [pid 559070:tid 559229] [client 65.21.113.253:41750] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fLiy1f1FtKC137xsdjgAAAaw"]
[Tue Jul 21 08:59:42.889339 2026] [security2:error] [pid 533360:tid 533389] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fLnUPuLYrePtEkUc9QQAA7Bk"]
[Tue Jul 21 08:59:42.889494 2026] [security2:error] [pid 533360:tid 533596] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fLnUPuLYrePtEkUc9QQAA7Bk"]
[Tue Jul 21 08:59:43.077267 2026] [security2:error] [pid 533360:tid 533501] [client 173.252.95.11:48570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fL3UPuLYrePtEkUc9SQAAAI0"]
[Tue Jul 21 08:59:43.168139 2026] [security2:error] [pid 533360:tid 533414] [remote 84.247.172.23:58484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9fL3UPuLYrePtEkUc9SgAA9DI"]
[Tue Jul 21 08:59:43.405764 2026] [security2:error] [pid 559070:tid 559093] [remote 20.75.217.75:5088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "loopfinancas.com"] [uri "/wp-login.php"] [unique_id "al9fLyy1f1FtKC137xsdoAABshY"]
[Tue Jul 21 08:59:43.439221 2026] [security2:error] [pid 559070:tid 559230] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fLyy1f1FtKC137xsdnQABrRA"]
[Tue Jul 21 08:59:43.997892 2026] [security2:error] [pid 559070:tid 559302] [client 20.220.225.223:20927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/aa1.php"] [unique_id "al9fLyy1f1FtKC137xsdowAAAfU"]
[Tue Jul 21 08:59:44.065955 2026] [security2:error] [pid 533360:tid 533574] [client 74.249.245.134:43683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/404.php"] [unique_id "al9fMHUPuLYrePtEkUc9WQAAANY"]
[Tue Jul 21 08:59:44.238719 2026] [security2:error] [pid 559070:tid 559274] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fMCy1f1FtKC137xsdqgAAAdk"]
[Tue Jul 21 08:59:44.436590 2026] [security2:error] [pid 559070:tid 559254] [client 173.252.95.25:33220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fMCy1f1FtKC137xsdrAAAAcU"]
[Tue Jul 21 08:59:44.468844 2026] [security2:error] [pid 533360:tid 533610] [client 49.13.164.148:10156] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "artetoner.com.br"] [uri "/index.html"] [unique_id "al9fMHUPuLYrePtEkUc9YgAAAPo"], referer: https://artetoner.com.br
[Tue Jul 21 08:59:44.678721 2026] [security2:error] [pid 559070:tid 559261] [client 20.151.10.161:51016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/class-wp.php"] [unique_id "al9fMCy1f1FtKC137xsdswAAAcw"]
[Tue Jul 21 08:59:45.021243 2026] [proxy:error] [pid 533360:tid 533587] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:45.021320 2026] [proxy_http:error] [pid 533360:tid 533587] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:45.021941 2026] [proxy:error] [pid 533360:tid 533587] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:45.021973 2026] [proxy_http:error] [pid 533360:tid 533587] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:45.109567 2026] [security2:error] [pid 559070:tid 559250] [client 20.220.225.223:30857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/ez.php"] [unique_id "al9fMSy1f1FtKC137xsdvgAAAcE"]
[Tue Jul 21 08:59:45.235295 2026] [security2:error] [pid 559070:tid 559280] [client 114.198.138.124:62596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fMSy1f1FtKC137xsdvwAAAd8"]
[Tue Jul 21 08:59:45.235398 2026] [security2:error] [pid 559070:tid 559280] [client 114.198.138.124:62596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fMSy1f1FtKC137xsdvwAAAd8"]
[Tue Jul 21 08:59:45.389868 2026] [security2:error] [pid 559070:tid 559235] [client 65.21.113.253:41758] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fMCy1f1FtKC137xsduQAAAbI"]
[Tue Jul 21 08:59:45.402622 2026] [security2:error] [pid 533360:tid 533517] [client 74.249.245.134:27217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/ws81.php"] [unique_id "al9fMXUPuLYrePtEkUc9cwAAAJ0"]
[Tue Jul 21 08:59:45.427452 2026] [proxy:error] [pid 559070:tid 559274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:45.427525 2026] [proxy_http:error] [pid 559070:tid 559274] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:45.428233 2026] [proxy:error] [pid 559070:tid 559274] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:45.428267 2026] [proxy_http:error] [pid 559070:tid 559274] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:45.436761 2026] [security2:error] [pid 559070:tid 559071] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fMSy1f1FtKC137xsdwgABrAA"]
[Tue Jul 21 08:59:45.436889 2026] [security2:error] [pid 559070:tid 559229] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fMSy1f1FtKC137xsdwgABrAA"]
[Tue Jul 21 08:59:45.951554 2026] [security2:error] [pid 533360:tid 533507] [client 74.244.197.228:11029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.197.244.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lasferas.com"] [uri "/xmlrpc.php"] [unique_id "al9fMXUPuLYrePtEkUc9ewAAAJM"]
[Tue Jul 21 08:59:45.951740 2026] [security2:error] [pid 533360:tid 533507] [client 74.244.197.228:11029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lasferas.com"] [uri "/xmlrpc.php"] [unique_id "al9fMXUPuLYrePtEkUc9ewAAAJM"]
[Tue Jul 21 08:59:45.955387 2026] [proxy:error] [pid 559070:tid 559230] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:45.955452 2026] [proxy_http:error] [pid 559070:tid 559230] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:45.956329 2026] [proxy:error] [pid 559070:tid 559230] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 08:59:45.956359 2026] [proxy_http:error] [pid 559070:tid 559230] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 08:59:46.023525 2026] [rewrite:warn] [pid 559070:tid 559105] AH00665: RewriteCond: NoCase option for non-regex pattern '-f' is not supported and will be ignored. (/home2/farma860/public_html/.htaccess:12)
[Tue Jul 21 08:59:46.104934 2026] [security2:error] [pid 559070:tid 559177] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fMiy1f1FtKC137xsdzgABr2o"]
[Tue Jul 21 08:59:46.105085 2026] [security2:error] [pid 559070:tid 559232] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fMiy1f1FtKC137xsdzgABr2o"]
[Tue Jul 21 08:59:46.179031 2026] [security2:error] [pid 533360:tid 533516] [client 74.249.245.134:12827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/file3.php"] [unique_id "al9fMnUPuLYrePtEkUc9hQAAAJw"]
[Tue Jul 21 08:59:46.432658 2026] [security2:error] [pid 559070:tid 559245] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fMiy1f1FtKC137xsd0AAAAbw"]
[Tue Jul 21 08:59:46.435027 2026] [security2:error] [pid 533360:tid 533546] [client 117.235.80.45:51428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.80.235.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fMnUPuLYrePtEkUc9iAAAALo"]
[Tue Jul 21 08:59:46.435139 2026] [security2:error] [pid 533360:tid 533546] [client 117.235.80.45:51428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fMnUPuLYrePtEkUc9iAAAALo"]
[Tue Jul 21 08:59:46.780275 2026] [security2:error] [pid 559070:tid 559299] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fMiy1f1FtKC137xsd1QAAAfI"]
[Tue Jul 21 08:59:46.949137 2026] [security2:error] [pid 559070:tid 559220] [client 168.167.81.163:63908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9fMiy1f1FtKC137xsd1wAAAaM"]
[Tue Jul 21 08:59:46.949273 2026] [security2:error] [pid 559070:tid 559220] [client 168.167.81.163:63908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9fMiy1f1FtKC137xsd1wAAAaM"]
[Tue Jul 21 08:59:46.994243 2026] [security2:error] [pid 559070:tid 559274] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9fMiy1f1FtKC137xsd2AAAAdk"]
[Tue Jul 21 08:59:47.008804 2026] [security2:error] [pid 559070:tid 559281] [client 20.151.10.161:55840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/admin.php"] [unique_id "al9fMyy1f1FtKC137xsd2QAAAeA"]
[Tue Jul 21 08:59:47.429302 2026] [security2:error] [pid 533360:tid 533619] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9fM3UPuLYrePtEkUc9kgAAAQM"]
[Tue Jul 21 08:59:47.467253 2026] [security2:error] [pid 533360:tid 533538] [client 20.220.225.223:20890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/acew67.php"] [unique_id "al9fM3UPuLYrePtEkUc9lAAAALI"]
[Tue Jul 21 08:59:47.726729 2026] [security2:error] [pid 559070:tid 559283] [client 216.73.160.22:64799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9fMyy1f1FtKC137xsd6QAAAeI"]
[Tue Jul 21 08:59:47.739117 2026] [security2:error] [pid 533360:tid 533576] [client 216.73.160.191:55197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9fM3UPuLYrePtEkUc9nAAAANg"]
[Tue Jul 21 08:59:47.741938 2026] [security2:error] [pid 559070:tid 559229] [client 216.73.160.17:34505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.160.73.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9fMyy1f1FtKC137xsd6gAAAaw"]
[Tue Jul 21 08:59:47.823185 2026] [security2:error] [pid 559070:tid 559204] [client 74.249.245.134:12825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/wp-mail.php"] [unique_id "al9fMyy1f1FtKC137xsd7AAAAZM"]
[Tue Jul 21 08:59:47.846084 2026] [security2:error] [pid 533360:tid 533496] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9fM3UPuLYrePtEkUc9oAAAAIg"]
[Tue Jul 21 08:59:47.878687 2026] [security2:error] [pid 559070:tid 559218] [client 65.21.113.253:41774] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fMyy1f1FtKC137xsd4gAAAaE"]
[Tue Jul 21 08:59:48.346669 2026] [security2:error] [pid 533360:tid 533506] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9fNHUPuLYrePtEkUc9qAAAAJI"]
[Tue Jul 21 08:59:48.682168 2026] [security2:error] [pid 559070:tid 559308] [client 74.249.245.134:43692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/about.php"] [unique_id "al9fNCy1f1FtKC137xsd-QAAAfs"]
[Tue Jul 21 08:59:48.781518 2026] [security2:error] [pid 559070:tid 559244] [client 117.214.78.59:58846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fNCy1f1FtKC137xsd-gAAAbs"]
[Tue Jul 21 08:59:48.781629 2026] [security2:error] [pid 559070:tid 559244] [client 117.214.78.59:58846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fNCy1f1FtKC137xsd-gAAAbs"]
[Tue Jul 21 08:59:48.786350 2026] [security2:error] [pid 559070:tid 559270] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9fNCy1f1FtKC137xsd-wAAAdU"]
[Tue Jul 21 08:59:48.866504 2026] [security2:error] [pid 533360:tid 533588] [client 173.252.95.57:39546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fNHUPuLYrePtEkUc9rwAAAOQ"]
[Tue Jul 21 08:59:48.993061 2026] [security2:error] [pid 533360:tid 533551] [client 216.73.160.180:55295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "drjoaoguedes.com"] [uri "/wp-login.php"] [unique_id "al9fM3UPuLYrePtEkUc9nQAAAL8"]
[Tue Jul 21 08:59:49.222381 2026] [security2:error] [pid 533360:tid 533542] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9fNXUPuLYrePtEkUc9tgAAALY"]
[Tue Jul 21 08:59:49.318606 2026] [security2:error] [pid 559070:tid 559245] [client 20.151.10.161:55838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/aa2.php"] [unique_id "al9fNSy1f1FtKC137xseBgAAAbw"]
[Tue Jul 21 08:59:49.448282 2026] [security2:error] [pid 533360:tid 533524] [client 20.220.225.223:60372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/ww.php"] [unique_id "al9fNXUPuLYrePtEkUc9ugAAAKQ"]
[Tue Jul 21 08:59:49.492224 2026] [security2:error] [pid 559070:tid 559250] [client 20.220.225.223:20865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/bscclapb.php"] [unique_id "al9fNSy1f1FtKC137xseCAAAAcE"]
[Tue Jul 21 08:59:49.524441 2026] [security2:error] [pid 533360:tid 533581] [client 69.171.230.39:43756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fNXUPuLYrePtEkUc9uwAAAN0"]
[Tue Jul 21 08:59:49.657405 2026] [security2:error] [pid 559070:tid 559220] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9fNSy1f1FtKC137xseCQAAAaM"]
[Tue Jul 21 08:59:49.746444 2026] [security2:error] [pid 559070:tid 559267] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fNSy1f1FtKC137xseCwAAAdI"]
[Tue Jul 21 08:59:49.814231 2026] [security2:error] [pid 559070:tid 559321] [client 113.22.144.139:50716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fNSy1f1FtKC137xseDQAAAgg"]
[Tue Jul 21 08:59:49.814917 2026] [security2:error] [pid 559070:tid 559321] [client 113.22.144.139:50716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fNSy1f1FtKC137xseDQAAAgg"]
[Tue Jul 21 08:59:49.992641 2026] [security2:error] [pid 559070:tid 559200] [client 74.249.245.134:12903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/adminfuns.php"] [unique_id "al9fNSy1f1FtKC137xseDwAAAY8"]
[Tue Jul 21 08:59:50.017457 2026] [security2:error] [pid 559070:tid 559256] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "al9fNiy1f1FtKC137xseEgAAAcc"]
[Tue Jul 21 08:59:50.018171 2026] [security2:error] [pid 559070:tid 559274] [client 184.154.36.163:56620] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "al9fNiy1f1FtKC137xseEAAAAdk"]
[Tue Jul 21 08:59:50.072217 2026] [security2:error] [pid 533360:tid 533573] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9fNnUPuLYrePtEkUc9yQAAANU"]
[Tue Jul 21 08:59:50.509366 2026] [security2:error] [pid 559070:tid 559318] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9fNiy1f1FtKC137xseHwAAAgU"]
[Tue Jul 21 08:59:50.740084 2026] [security2:error] [pid 533360:tid 533543] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "al9fNnUPuLYrePtEkUc90AAAALc"]
[Tue Jul 21 08:59:50.742238 2026] [security2:error] [pid 559070:tid 559236] [client 184.154.36.163:39756] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "al9fNiy1f1FtKC137xseIQAAAbM"]
[Tue Jul 21 08:59:50.812457 2026] [security2:error] [pid 559070:tid 559301] [client 65.21.113.253:58118] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fNiy1f1FtKC137xseHgAAAfQ"]
[Tue Jul 21 08:59:50.827255 2026] [security2:error] [pid 559070:tid 559223] [client 20.151.10.161:51017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/ccou.php"] [unique_id "al9fNiy1f1FtKC137xseJgAAAaY"]
[Tue Jul 21 08:59:50.827375 2026] [security2:error] [pid 533360:tid 533579] [client 41.89.234.2:50191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fNnUPuLYrePtEkUc91AAAANs"]
[Tue Jul 21 08:59:50.827478 2026] [security2:error] [pid 533360:tid 533579] [client 41.89.234.2:50191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fNnUPuLYrePtEkUc91AAAANs"]
[Tue Jul 21 08:59:51.027983 2026] [security2:error] [pid 533360:tid 533519] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9fN3UPuLYrePtEkUc92AAAAJ8"]
[Tue Jul 21 08:59:51.177860 2026] [security2:error] [pid 559070:tid 559283] [client 115.245.198.210:17377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fNyy1f1FtKC137xseKQAAAeI"]
[Tue Jul 21 08:59:51.178034 2026] [security2:error] [pid 559070:tid 559283] [client 115.245.198.210:17377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fNyy1f1FtKC137xseKQAAAeI"]
[Tue Jul 21 08:59:51.397517 2026] [security2:error] [pid 559070:tid 559222] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9fNyy1f1FtKC137xseLQAAAaU"]
[Tue Jul 21 08:59:51.433987 2026] [security2:error] [pid 533360:tid 533587] [client 182.189.99.211:47628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fN3UPuLYrePtEkUc93gAAAOM"]
[Tue Jul 21 08:59:51.434093 2026] [security2:error] [pid 533360:tid 533587] [client 182.189.99.211:47628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fN3UPuLYrePtEkUc93gAAAOM"]
[Tue Jul 21 08:59:51.462879 2026] [security2:error] [pid 533360:tid 533617] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "al9fN3UPuLYrePtEkUc94wAAAQE"]
[Tue Jul 21 08:59:51.463590 2026] [security2:error] [pid 533360:tid 533522] [client 184.154.36.163:39760] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "al9fN3UPuLYrePtEkUc94QAAAKI"]
[Tue Jul 21 08:59:51.609601 2026] [security2:error] [pid 533360:tid 533500] [client 74.249.245.134:12860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/php8.php"] [unique_id "al9fN3UPuLYrePtEkUc95QAAAIw"]
[Tue Jul 21 08:59:51.816145 2026] [security2:error] [pid 533360:tid 533614] [client 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rafaelaparecidodesou1782438856690.0711679.meusitehostgator.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9fN3UPuLYrePtEkUc95wAAAP4"]
[Tue Jul 21 08:59:51.894988 2026] [security2:error] [pid 533360:tid 533539] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "al9fN3UPuLYrePtEkUc97QAAALM"]
[Tue Jul 21 08:59:51.895660 2026] [security2:error] [pid 559070:tid 559232] [client 184.154.36.163:56624] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "al9fNyy1f1FtKC137xseMgAAAa8"]
[Tue Jul 21 08:59:51.950294 2026] [security2:error] [pid 559070:tid 559156] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fNyy1f1FtKC137xseNQABrVU"]
[Tue Jul 21 08:59:51.950439 2026] [security2:error] [pid 559070:tid 559230] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fNyy1f1FtKC137xseNQABrVU"]
[Tue Jul 21 08:59:52.168065 2026] [security2:error] [pid 559070:tid 559326] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fOCy1f1FtKC137xseNwAAAg0"]
[Tue Jul 21 08:59:52.296601 2026] [security2:error] [pid 533360:tid 533578] [client 194.99.104.35:56228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9fOHUPuLYrePtEkUc99wAAANo"]
[Tue Jul 21 08:59:52.296796 2026] [security2:error] [pid 533360:tid 533578] [client 194.99.104.35:56228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9fOHUPuLYrePtEkUc99wAAANo"]
[Tue Jul 21 08:59:52.328208 2026] [security2:error] [pid 533360:tid 533564] [client 20.151.10.161:51066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/dr.php"] [unique_id "al9fOHUPuLYrePtEkUc9-wAAAMw"]
[Tue Jul 21 08:59:52.432724 2026] [security2:error] [pid 559070:tid 559274] [client 47.128.20.229:64992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "seaportservicos.com.br"] [uri "/robots.txt"] [unique_id "al9fOCy1f1FtKC137xseOwAAAdk"]
[Tue Jul 21 08:59:52.490854 2026] [security2:error] [pid 559070:tid 559304] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fOCy1f1FtKC137xseOQAAAfc"]
[Tue Jul 21 08:59:52.491184 2026] [security2:error] [pid 533360:tid 533503] [client 184.154.36.163:56628] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "al9fOHUPuLYrePtEkUc9-gAAAI8"]
[Tue Jul 21 08:59:52.772757 2026] [security2:error] [pid 559070:tid 559309] [client 74.249.245.134:43666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/info.php"] [unique_id "al9fOCy1f1FtKC137xseQgAAAfw"]
[Tue Jul 21 08:59:52.811032 2026] [security2:error] [pid 559070:tid 559214] [client 154.182.128.22:54881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.128.182.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fOCy1f1FtKC137xseQwAAAZ0"]
[Tue Jul 21 08:59:52.811263 2026] [security2:error] [pid 559070:tid 559214] [client 154.182.128.22:54881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fOCy1f1FtKC137xseQwAAAZ0"]
[Tue Jul 21 08:59:53.248717 2026] [security2:error] [pid 533360:tid 533616] [client 65.21.113.253:58130] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fOHUPuLYrePtEkUc-AwAAAQA"]
[Tue Jul 21 08:59:53.375288 2026] [security2:error] [pid 533360:tid 533389] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fOXUPuLYrePtEkUc-DgAA7Bk"]
[Tue Jul 21 08:59:53.375524 2026] [security2:error] [pid 533360:tid 533596] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fOXUPuLYrePtEkUc-DgAA7Bk"]
[Tue Jul 21 08:59:53.382155 2026] [security2:error] [pid 559070:tid 559223] [client 139.167.208.211:58823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.208.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fOSy1f1FtKC137xseSwAAAaY"]
[Tue Jul 21 08:59:53.382354 2026] [security2:error] [pid 559070:tid 559223] [client 139.167.208.211:58823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fOSy1f1FtKC137xseSwAAAaY"]
[Tue Jul 21 08:59:53.618627 2026] [security2:error] [pid 559070:tid 559244] [client 184.154.36.163:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "hoterplast.com.br"] [uri "/index.php"] [unique_id "al9fOSy1f1FtKC137xseUAAAAbs"]
[Tue Jul 21 08:59:53.624566 2026] [security2:error] [pid 533360:tid 533506] [client 184.154.36.163:39762] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "hoterplast.com.br"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "al9fOXUPuLYrePtEkUc-EAAAAJI"]
[Tue Jul 21 08:59:53.672611 2026] [security2:error] [pid 533360:tid 533414] [remote 68.178.160.25:42946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benattiodontologia.com.br"] [uri "/wp-login.php"] [unique_id "al9fOXUPuLYrePtEkUc-FAAAjTI"]
[Tue Jul 21 08:59:54.136792 2026] [security2:error] [pid 559070:tid 559202] [client 74.249.245.134:12800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/edit.php"] [unique_id "al9fOiy1f1FtKC137xseWwAAAZE"]
[Tue Jul 21 08:59:54.567632 2026] [security2:error] [pid 559070:tid 559258] [client 20.52.136.55:1595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/404.php"] [unique_id "al9fOiy1f1FtKC137xseZAAAAck"]
[Tue Jul 21 08:59:54.907333 2026] [security2:error] [pid 559070:tid 559312] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fOiy1f1FtKC137xseaQAAAf8"]
[Tue Jul 21 08:59:54.978442 2026] [security2:error] [pid 559070:tid 559252] [client 20.226.60.151:62626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9fOiy1f1FtKC137xsebAAAAcM"]
[Tue Jul 21 08:59:55.168414 2026] [security2:error] [pid 559070:tid 559276] [client 20.226.60.151:62598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9fOyy1f1FtKC137xseeAAAAds"]
[Tue Jul 21 08:59:55.169522 2026] [security2:error] [pid 533360:tid 533525] [client 198.44.157.162:59820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9fO3UPuLYrePtEkUc-LwAAAKU"]
[Tue Jul 21 08:59:55.169596 2026] [security2:error] [pid 533360:tid 533525] [client 198.44.157.162:59820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "medicaldigest.online"] [uri "/xmlrpc.php"] [unique_id "al9fO3UPuLYrePtEkUc-LwAAAKU"]
[Tue Jul 21 08:59:55.191162 2026] [security2:error] [pid 559070:tid 559230] [client 74.249.245.134:43663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/166.php"] [unique_id "al9fOyy1f1FtKC137xseeQAAAa0"]
[Tue Jul 21 08:59:55.413491 2026] [security2:error] [pid 533360:tid 533601] [client 103.59.206.240:31299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fO3UPuLYrePtEkUc-OgAAAPE"]
[Tue Jul 21 08:59:55.413609 2026] [security2:error] [pid 533360:tid 533601] [client 103.59.206.240:31299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fO3UPuLYrePtEkUc-OgAAAPE"]
[Tue Jul 21 08:59:55.645557 2026] [security2:error] [pid 559070:tid 559280] [client 20.226.60.151:62639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/media.php"] [unique_id "al9fOyy1f1FtKC137xseigAAAd8"]
[Tue Jul 21 08:59:55.765541 2026] [security2:error] [pid 533360:tid 533550] [client 20.151.10.161:51064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/xamp.php"] [unique_id "al9fO3UPuLYrePtEkUc-QAAAAL4"]
[Tue Jul 21 08:59:55.836171 2026] [security2:error] [pid 533360:tid 533552] [client 114.198.138.124:63326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fO3UPuLYrePtEkUc-QwAAAMA"]
[Tue Jul 21 08:59:55.836288 2026] [security2:error] [pid 533360:tid 533552] [client 114.198.138.124:63326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fO3UPuLYrePtEkUc-QwAAAMA"]
[Tue Jul 21 08:59:55.851331 2026] [security2:error] [pid 533360:tid 533543] [client 20.226.60.151:50411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/images.php"] [unique_id "al9fO3UPuLYrePtEkUc-RAAAALc"]
[Tue Jul 21 08:59:55.968997 2026] [security2:error] [pid 559070:tid 559245] [client 65.21.113.253:58142] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fOyy1f1FtKC137xseiAAAAbw"]
[Tue Jul 21 08:59:55.983363 2026] [security2:error] [pid 559070:tid 559155] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fOyy1f1FtKC137xsekgAB5VQ"]
[Tue Jul 21 08:59:55.983532 2026] [security2:error] [pid 559070:tid 559286] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fOyy1f1FtKC137xsekgAB5VQ"]
[Tue Jul 21 08:59:56.174394 2026] [security2:error] [pid 559070:tid 559308] [client 74.249.245.134:16740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/8.php"] [unique_id "al9fPCy1f1FtKC137xsemAAAAfs"]
[Tue Jul 21 08:59:56.191837 2026] [security2:error] [pid 559070:tid 559278] [client 185.213.175.37:49012] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "budhug.com.br"] [uri "/.env.development"] [unique_id "al9fPCy1f1FtKC137xsemQAAAd0"]
[Tue Jul 21 08:59:56.196335 2026] [security2:error] [pid 533360:tid 533545] [client 117.235.80.45:52356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.80.235.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fPHUPuLYrePtEkUc-TQAAALk"]
[Tue Jul 21 08:59:56.196484 2026] [security2:error] [pid 533360:tid 533545] [client 117.235.80.45:52356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fPHUPuLYrePtEkUc-TQAAALk"]
[Tue Jul 21 08:59:56.251957 2026] [security2:error] [pid 559070:tid 559212] [client 35.252.209.37:53023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.209.252.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bubaby.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fPCy1f1FtKC137xsemgAAAZs"]
[Tue Jul 21 08:59:56.494463 2026] [security2:error] [pid 533360:tid 533587] [client 20.226.60.151:62607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/gecko.php"] [unique_id "al9fPHUPuLYrePtEkUc-UAAAAOM"]
[Tue Jul 21 08:59:56.565424 2026] [security2:error] [pid 559070:tid 559119] [remote 180.194.103.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.103.194.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fPCy1f1FtKC137xseoQAByjA"]
[Tue Jul 21 08:59:56.565567 2026] [security2:error] [pid 559070:tid 559259] [client 180.194.103.26:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fPCy1f1FtKC137xseoQAByjA"]
[Tue Jul 21 08:59:56.964996 2026] [security2:error] [pid 533360:tid 533582] [client 74.7.228.3:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "carolinadonagomes1782866894430.0711679.meusitehostgator.com.br"] [uri "/index.php"] [unique_id "al9fO3UPuLYrePtEkUc-RQAA3n4"]
[Tue Jul 21 08:59:56.972380 2026] [security2:error] [pid 559070:tid 559296] [client 20.220.225.223:34451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/hp3.php"] [unique_id "al9fPCy1f1FtKC137xserQAAAe8"]
[Tue Jul 21 08:59:56.979455 2026] [security2:error] [pid 559070:tid 559220] [client 74.249.245.134:12921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/ws38.php"] [unique_id "al9fPCy1f1FtKC137xsergAAAaM"]
[Tue Jul 21 08:59:57.012296 2026] [security2:error] [pid 559070:tid 559221] [client 173.252.95.8:64522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fPSy1f1FtKC137xserwAAAaQ"]
[Tue Jul 21 08:59:57.070110 2026] [security2:error] [pid 533360:tid 533597] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fPHUPuLYrePtEkUc-XAAA7UM"]
[Tue Jul 21 08:59:57.138393 2026] [security2:error] [pid 559070:tid 559274] [client 20.220.225.223:30891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/fz.php"] [unique_id "al9fPSy1f1FtKC137xsesQAAAdk"]
[Tue Jul 21 08:59:57.308123 2026] [security2:error] [pid 533360:tid 533523] [client 20.226.60.151:62070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/82.php"] [unique_id "al9fPXUPuLYrePtEkUc-ZAAAAKM"]
[Tue Jul 21 08:59:57.344312 2026] [security2:error] [pid 533360:tid 533600] [client 35.252.209.37:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bubaby.com.br"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9fPXUPuLYrePtEkUc-ZQAAAPA"]
[Tue Jul 21 08:59:57.567564 2026] [security2:error] [pid 559070:tid 559260] [client 173.252.95.54:39980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fPSy1f1FtKC137xseswAAAcs"]
[Tue Jul 21 08:59:57.568520 2026] [security2:error] [pid 533360:tid 533572] [client 74.249.245.134:27289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/222.php"] [unique_id "al9fPXUPuLYrePtEkUc-bAAAANQ"]
[Tue Jul 21 08:59:57.724059 2026] [security2:error] [pid 559070:tid 559229] [client 74.249.245.134:12840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/a7.php"] [unique_id "al9fPSy1f1FtKC137xse7AAAAaw"]
[Tue Jul 21 08:59:57.726759 2026] [security2:error] [pid 533360:tid 533505] [client 20.220.225.223:53442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/cron.php"] [unique_id "al9fPXUPuLYrePtEkUc-cAAAAJE"]
[Tue Jul 21 08:59:57.752659 2026] [security2:error] [pid 559070:tid 559293] [client 168.167.81.163:63348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9fPSy1f1FtKC137xse7QAAAew"]
[Tue Jul 21 08:59:57.752791 2026] [security2:error] [pid 559070:tid 559293] [client 168.167.81.163:63348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9fPSy1f1FtKC137xse7QAAAew"]
[Tue Jul 21 08:59:58.003255 2026] [security2:error] [pid 559070:tid 559212] [client 20.226.60.151:62633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/admin.php"] [unique_id "al9fPiy1f1FtKC137xse_AAAAZs"]
[Tue Jul 21 08:59:58.144443 2026] [security2:error] [pid 533360:tid 533552] [client 173.252.95.26:37384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fPnUPuLYrePtEkUc-fAAAAMA"]
[Tue Jul 21 08:59:58.181307 2026] [security2:error] [pid 533360:tid 533510] [client 35.252.209.37:53592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bubaby.com.br"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9fPnUPuLYrePtEkUc-fQAAAJY"]
[Tue Jul 21 08:59:58.188120 2026] [security2:error] [pid 559070:tid 559230] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fPiy1f1FtKC137xsfBwAAAa0"]
[Tue Jul 21 08:59:58.262137 2026] [security2:error] [pid 533360:tid 533593] [client 20.226.60.151:62643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/adminner.php"] [unique_id "al9fPnUPuLYrePtEkUc-gAAAAOk"]
[Tue Jul 21 08:59:58.552734 2026] [security2:error] [pid 533360:tid 533500] [client 20.220.225.223:30879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/la.php"] [unique_id "al9fPnUPuLYrePtEkUc-hwAAAIw"]
[Tue Jul 21 08:59:58.582018 2026] [security2:error] [pid 533360:tid 533513] [client 20.226.60.151:62044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/admin.php"] [unique_id "al9fPnUPuLYrePtEkUc-iAAAAJk"]
[Tue Jul 21 08:59:58.595914 2026] [security2:error] [pid 559070:tid 559326] [client 20.220.225.223:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/xxx.php"] [unique_id "al9fPiy1f1FtKC137xsfDQAAAg0"]
[Tue Jul 21 08:59:58.932425 2026] [autoindex:error] [pid 533360:tid 533511] [client 185.213.175.37:52060] AH01276: Cannot serve directory /home2/roseol85/cachorrinhalolla.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 08:59:59.043596 2026] [security2:error] [pid 533360:tid 533539] [client 173.252.95.43:42032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fP3UPuLYrePtEkUc-kwAAALM"]
[Tue Jul 21 08:59:59.076055 2026] [security2:error] [pid 533360:tid 533588] [client 74.249.245.134:12838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/classsmtps.php"] [unique_id "al9fP3UPuLYrePtEkUc-lAAAAOQ"]
[Tue Jul 21 08:59:59.102062 2026] [security2:error] [pid 559070:tid 559202] [client 35.252.209.37:57435] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bubaby.com.br"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9fPyy1f1FtKC137xsfFgAAAZE"]
[Tue Jul 21 08:59:59.238477 2026] [security2:error] [pid 559070:tid 559235] [client 65.21.113.253:58154] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fPiy1f1FtKC137xsfEwAAAbI"]
[Tue Jul 21 08:59:59.295533 2026] [security2:error] [pid 533360:tid 533582] [client 117.214.78.59:59297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fP3UPuLYrePtEkUc-mwAAAN4"]
[Tue Jul 21 08:59:59.295710 2026] [security2:error] [pid 533360:tid 533582] [client 117.214.78.59:59297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fP3UPuLYrePtEkUc-mwAAAN4"]
[Tue Jul 21 08:59:59.424129 2026] [security2:error] [pid 559070:tid 559246] [client 20.226.60.151:62033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/k.php"] [unique_id "al9fPyy1f1FtKC137xsfHQAAAb0"]
[Tue Jul 21 08:59:59.753804 2026] [security2:error] [pid 533360:tid 533535] [client 74.249.245.134:12844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/rip.php"] [unique_id "al9fP3UPuLYrePtEkUc-qAAAAK8"]
[Tue Jul 21 09:00:00.142478 2026] [security2:error] [pid 533360:tid 533577] [client 35.252.209.37:56715] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bubaby.com.br"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9fQHUPuLYrePtEkUc-sQAAANk"]
[Tue Jul 21 09:00:00.217871 2026] [security2:error] [pid 559070:tid 559260] [client 113.22.144.139:51228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fQCy1f1FtKC137xsfKQAAAcs"]
[Tue Jul 21 09:00:00.218007 2026] [security2:error] [pid 559070:tid 559260] [client 113.22.144.139:51228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fQCy1f1FtKC137xsfKQAAAcs"]
[Tue Jul 21 09:00:00.471634 2026] [security2:error] [pid 559070:tid 559326] [client 74.249.245.134:12869] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpanel.simleite.com.br"] [uri "/1.php"] [unique_id "al9fQCy1f1FtKC137xsfMAAAAg0"]
[Tue Jul 21 09:00:00.471732 2026] [security2:error] [pid 559070:tid 559326] [client 74.249.245.134:12869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/1.php"] [unique_id "al9fQCy1f1FtKC137xsfMAAAAg0"]
[Tue Jul 21 09:00:00.481105 2026] [autoindex:error] [pid 559070:tid 559251] [client 185.213.175.37:52072] AH01276: Cannot serve directory /home2/roseol85/cachorrinhalolla.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 09:00:00.493841 2026] [security2:error] [pid 533360:tid 533588] [client 20.226.60.151:50393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/blurbs.php"] [unique_id "al9fQHUPuLYrePtEkUc-uwAAAOQ"]
[Tue Jul 21 09:00:00.543411 2026] [security2:error] [pid 559070:tid 559231] [client 20.220.225.223:30662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9fQCy1f1FtKC137xsfMgAAAa4"]
[Tue Jul 21 09:00:00.777034 2026] [security2:error] [pid 533360:tid 533598] [client 194.99.104.35:55312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9fQHUPuLYrePtEkUc-wAAAAO4"]
[Tue Jul 21 09:00:00.777112 2026] [security2:error] [pid 533360:tid 533598] [client 194.99.104.35:55312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9fQHUPuLYrePtEkUc-wAAAAO4"]
[Tue Jul 21 09:00:01.019379 2026] [security2:error] [pid 559070:tid 559235] [client 35.252.209.37:52017] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bubaby.com.br"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9fQSy1f1FtKC137xsfOAAAAbI"]
[Tue Jul 21 09:00:01.060373 2026] [security2:error] [pid 559070:tid 559246] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fQSy1f1FtKC137xsfOQAAAb0"]
[Tue Jul 21 09:00:01.072441 2026] [security2:error] [pid 559070:tid 559250] [client 20.52.136.55:1788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/file3.php"] [unique_id "al9fQSy1f1FtKC137xsfOgAAAcE"]
[Tue Jul 21 09:00:01.126843 2026] [security2:error] [pid 559070:tid 559223] [client 20.220.225.223:55772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/hunter.php"] [unique_id "al9fQSy1f1FtKC137xsfOwAAAaY"]
[Tue Jul 21 09:00:01.141466 2026] [security2:error] [pid 559070:tid 559232] [client 41.89.234.2:50653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fQSy1f1FtKC137xsfPAAAAa8"]
[Tue Jul 21 09:00:01.141644 2026] [security2:error] [pid 559070:tid 559232] [client 41.89.234.2:50653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fQSy1f1FtKC137xsfPAAAAa8"]
[Tue Jul 21 09:00:01.376934 2026] [security2:error] [pid 533360:tid 533557] [client 74.249.245.134:12919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/chosen.php"] [unique_id "al9fQXUPuLYrePtEkUc-zwAAAMU"]
[Tue Jul 21 09:00:01.596519 2026] [security2:error] [pid 533360:tid 533519] [client 20.151.10.161:55866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/bless.php"] [unique_id "al9fQXUPuLYrePtEkUc-1gAAAJ8"]
[Tue Jul 21 09:00:01.894796 2026] [security2:error] [pid 559070:tid 559283] [client 20.226.60.151:62053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/bajah.php"] [unique_id "al9fQSy1f1FtKC137xsfRwAAAeI"]
[Tue Jul 21 09:00:01.908177 2026] [security2:error] [pid 559070:tid 559278] [client 35.252.209.37:62199] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bubaby.com.br"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9fQSy1f1FtKC137xsfSAAAAd0"]
[Tue Jul 21 09:00:02.015231 2026] [security2:error] [pid 533360:tid 533603] [client 20.220.225.223:34435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/aa1.php"] [unique_id "al9fQnUPuLYrePtEkUc-5QAAAPM"]
[Tue Jul 21 09:00:02.083778 2026] [security2:error] [pid 559070:tid 559251] [client 198.44.157.162:33036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9fQiy1f1FtKC137xsfTAAAAcI"]
[Tue Jul 21 09:00:02.083949 2026] [security2:error] [pid 559070:tid 559251] [client 198.44.157.162:33036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9fQiy1f1FtKC137xsfTAAAAcI"]
[Tue Jul 21 09:00:02.160763 2026] [security2:error] [pid 559070:tid 559316] [client 74.249.245.134:16745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/css.php"] [unique_id "al9fQiy1f1FtKC137xsfTgAAAgM"]
[Tue Jul 21 09:00:02.180050 2026] [security2:error] [pid 533360:tid 533381] [remote 57.141.18.79:20332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mdbroraima.org.br"] [uri "/"] [unique_id "al9fQnUPuLYrePtEkUc-6AAA2BE"]
[Tue Jul 21 09:00:02.206844 2026] [security2:error] [pid 533360:tid 533541] [client 74.249.245.134:27272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/t.php"] [unique_id "al9fQnUPuLYrePtEkUc-6QAAALU"]
[Tue Jul 21 09:00:02.462556 2026] [security2:error] [pid 559070:tid 559126] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fQiy1f1FtKC137xsfUQACBTc"]
[Tue Jul 21 09:00:02.462860 2026] [security2:error] [pid 559070:tid 559318] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fQiy1f1FtKC137xsfUQACBTc"]
[Tue Jul 21 09:00:02.520705 2026] [security2:error] [pid 533360:tid 533535] [client 65.21.113.253:39496] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fQXUPuLYrePtEkUc-3QAAAK8"]
[Tue Jul 21 09:00:02.554998 2026] [security2:error] [pid 559070:tid 559296] [client 20.220.225.223:53446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/we.php"] [unique_id "al9fQiy1f1FtKC137xsfUgAAAe8"]
[Tue Jul 21 09:00:02.776969 2026] [security2:error] [pid 533360:tid 533598] [client 35.252.209.37:62203] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bubaby.com.br"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9fQnUPuLYrePtEkUc-9QAAAO4"]
[Tue Jul 21 09:00:02.887495 2026] [security2:error] [pid 559070:tid 559290] [client 182.189.99.211:48083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fQiy1f1FtKC137xsfVQAAAek"]
[Tue Jul 21 09:00:02.887682 2026] [security2:error] [pid 559070:tid 559290] [client 182.189.99.211:48083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fQiy1f1FtKC137xsfVQAAAek"]
[Tue Jul 21 09:00:03.100756 2026] [security2:error] [pid 559070:tid 559272] [client 20.220.225.223:30849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/inso.php"] [unique_id "al9fQyy1f1FtKC137xsfWwAAAdc"]
[Tue Jul 21 09:00:03.279299 2026] [security2:error] [pid 559070:tid 559252] [client 20.226.60.151:62071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/a.php"] [unique_id "al9fQyy1f1FtKC137xsfXQAAAcM"]
[Tue Jul 21 09:00:03.395509 2026] [security2:error] [pid 559070:tid 559297] [client 74.249.245.134:12817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/php.php"] [unique_id "al9fQyy1f1FtKC137xsfYQAAAfA"]
[Tue Jul 21 09:00:03.437758 2026] [security2:error] [pid 559070:tid 559262] [client 59.95.197.55:64929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fQyy1f1FtKC137xsfYgAAAc0"]
[Tue Jul 21 09:00:03.438345 2026] [security2:error] [pid 559070:tid 559262] [client 59.95.197.55:64929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fQyy1f1FtKC137xsfYgAAAc0"]
[Tue Jul 21 09:00:03.709223 2026] [security2:error] [pid 533360:tid 533611] [client 20.151.10.161:55849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file46.php"] [unique_id "al9fQ3UPuLYrePtEkUc_AAAAAPs"]
[Tue Jul 21 09:00:03.731294 2026] [security2:error] [pid 559070:tid 559245] [client 154.182.128.22:55324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.128.182.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fQyy1f1FtKC137xsfaQAAAbw"]
[Tue Jul 21 09:00:03.731471 2026] [security2:error] [pid 559070:tid 559245] [client 154.182.128.22:55324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fQyy1f1FtKC137xsfaQAAAbw"]
[Tue Jul 21 09:00:03.877992 2026] [security2:error] [pid 559070:tid 559239] [client 20.220.225.223:34193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/la.php"] [unique_id "al9fQyy1f1FtKC137xsfagAAAbY"]
[Tue Jul 21 09:00:03.923957 2026] [security2:error] [pid 559070:tid 559104] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fQyy1f1FtKC137xsfbAABvyE"]
[Tue Jul 21 09:00:03.924150 2026] [security2:error] [pid 559070:tid 559248] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fQyy1f1FtKC137xsfbAABvyE"]
[Tue Jul 21 09:00:04.035195 2026] [security2:error] [pid 559070:tid 559309] [client 173.252.95.6:38454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fRCy1f1FtKC137xsfcAAAAfw"]
[Tue Jul 21 09:00:04.109145 2026] [security2:error] [pid 559070:tid 559212] [client 139.167.208.211:59441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.208.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fRCy1f1FtKC137xsfcQAAAZs"]
[Tue Jul 21 09:00:04.109314 2026] [security2:error] [pid 559070:tid 559212] [client 139.167.208.211:59441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fRCy1f1FtKC137xsfcQAAAZs"]
[Tue Jul 21 09:00:04.110066 2026] [security2:error] [pid 559070:tid 559257] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fRCy1f1FtKC137xsfcgAAAcg"]
[Tue Jul 21 09:00:04.202279 2026] [security2:error] [pid 533360:tid 533489] [remote 5.135.4.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.4.135.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fRHUPuLYrePtEkUc_BwAA7H0"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:04.205993 2026] [security2:error] [pid 533360:tid 533382] [remote 5.135.4.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.4.135.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fRHUPuLYrePtEkUc_BgAAhxI"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:04.208233 2026] [security2:error] [pid 533360:tid 533383] [remote 5.135.4.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.4.135.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fRHUPuLYrePtEkUc_CAAAixM"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:04.208341 2026] [security2:error] [pid 559070:tid 559151] [remote 5.135.4.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.4.135.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fRCy1f1FtKC137xsfbgABsVA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:04.218566 2026] [security2:error] [pid 559070:tid 559290] [client 20.52.136.55:1584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/wp-mail.php"] [unique_id "al9fRCy1f1FtKC137xsfdAAAAek"]
[Tue Jul 21 09:00:04.395051 2026] [security2:error] [pid 533360:tid 533460] [remote 5.135.4.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.4.135.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fRHUPuLYrePtEkUc_DwAAlWA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:04.395203 2026] [security2:error] [pid 533360:tid 533487] [remote 5.135.4.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.4.135.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fRHUPuLYrePtEkUc_EAAAlXs"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:04.400952 2026] [security2:error] [pid 533360:tid 533390] [remote 5.135.4.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.4.135.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fRHUPuLYrePtEkUc_EgAA-Bo"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:04.408429 2026] [core:error] [pid 533360:tid 533442] [remote 87.250.224.214:47088] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 09:00:04.408445 2026] [core:error] [pid 533360:tid 533442] [remote 87.250.224.214:47088] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 09:00:04.423610 2026] [security2:error] [pid 559070:tid 559291] [client 35.252.209.37:63813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bubaby.com.br"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9fRCy1f1FtKC137xsfmwAAAeo"]
[Tue Jul 21 09:00:04.432590 2026] [security2:error] [pid 559070:tid 559286] [client 20.220.225.223:34302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/nhvoanpl.php"] [unique_id "al9fRCy1f1FtKC137xsfnQAAAeU"]
[Tue Jul 21 09:00:04.555572 2026] [security2:error] [pid 559070:tid 559308] [client 20.220.225.223:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/acew67.php"] [unique_id "al9fRCy1f1FtKC137xsfvgAAAfs"]
[Tue Jul 21 09:00:04.661621 2026] [security2:error] [pid 559070:tid 559119] [remote 5.135.4.149:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.4.135.5.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fRCy1f1FtKC137xsfwAACADA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:04.857954 2026] [security2:error] [pid 533360:tid 533535] [client 20.220.225.223:34196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/bscclapb.php"] [unique_id "al9fRHUPuLYrePtEkUc_IgAAAK8"]
[Tue Jul 21 09:00:05.086253 2026] [security2:error] [pid 559070:tid 559217] [client 74.249.245.134:12843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/aa.php"] [unique_id "al9fRSy1f1FtKC137xsfxQAAAaA"]
[Tue Jul 21 09:00:05.209773 2026] [security2:error] [pid 559070:tid 559311] [client 65.21.113.253:39500] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fRCy1f1FtKC137xsfwQAAAf4"]
[Tue Jul 21 09:00:05.377351 2026] [security2:error] [pid 559070:tid 559278] [client 35.252.209.37:52394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bubaby.com.br"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9fRSy1f1FtKC137xsfywAAAd0"]
[Tue Jul 21 09:00:05.677450 2026] [security2:error] [pid 533360:tid 533589] [client 20.151.10.161:55823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/eee.php"] [unique_id "al9fRXUPuLYrePtEkUc_NAAAAOU"]
[Tue Jul 21 09:00:05.793281 2026] [security2:error] [pid 533360:tid 533545] [client 20.226.60.151:62642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/edit.php"] [unique_id "al9fRXUPuLYrePtEkUc_OAAAALk"]
[Tue Jul 21 09:00:06.028728 2026] [security2:error] [pid 533360:tid 533533] [client 20.220.225.223:34212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/inso.php"] [unique_id "al9fRnUPuLYrePtEkUc_QAAAAK0"]
[Tue Jul 21 09:00:06.035200 2026] [security2:error] [pid 533360:tid 533593] [client 74.249.245.134:12868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/bolt.php"] [unique_id "al9fRnUPuLYrePtEkUc_QQAAAOk"]
[Tue Jul 21 09:00:06.124801 2026] [security2:error] [pid 533360:tid 533537] [client 20.220.225.223:30681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/wpx.php"] [unique_id "al9fRnUPuLYrePtEkUc_QgAAALE"]
[Tue Jul 21 09:00:06.287776 2026] [security2:error] [pid 559070:tid 559212] [client 35.252.209.37:62562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bubaby.com.br"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9fRiy1f1FtKC137xsf2QAAAZs"]
[Tue Jul 21 09:00:06.321166 2026] [security2:error] [pid 533360:tid 533612] [client 74.249.245.134:27240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/a.php"] [unique_id "al9fRnUPuLYrePtEkUc_RQAAAPw"]
[Tue Jul 21 09:00:06.357737 2026] [security2:error] [pid 533360:tid 533510] [client 114.198.138.124:63943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fRnUPuLYrePtEkUc_RgAAAJY"]
[Tue Jul 21 09:00:06.357982 2026] [security2:error] [pid 533360:tid 533510] [client 114.198.138.124:63943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fRnUPuLYrePtEkUc_RgAAAJY"]
[Tue Jul 21 09:00:06.508746 2026] [security2:error] [pid 559070:tid 559175] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fRiy1f1FtKC137xsf3wABpmg"]
[Tue Jul 21 09:00:06.508935 2026] [security2:error] [pid 559070:tid 559223] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fRiy1f1FtKC137xsf3wABpmg"]
[Tue Jul 21 09:00:06.662015 2026] [security2:error] [pid 559070:tid 559313] [client 128.127.105.184:56682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9fRiy1f1FtKC137xsf4QAAAgA"]
[Tue Jul 21 09:00:06.662146 2026] [security2:error] [pid 559070:tid 559313] [client 128.127.105.184:56682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9fRiy1f1FtKC137xsf4QAAAgA"]
[Tue Jul 21 09:00:06.719784 2026] [security2:error] [pid 533360:tid 533499] [client 74.249.245.134:12880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/x.php"] [unique_id "al9fRnUPuLYrePtEkUc_SgAAAIs"]
[Tue Jul 21 09:00:06.897597 2026] [security2:error] [pid 559070:tid 559161] [remote 104.207.35.166:65363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.35.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9fRiy1f1FtKC137xsf4gABw1o"]
[Tue Jul 21 09:00:06.906240 2026] [security2:error] [pid 559070:tid 559263] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fRiy1f1FtKC137xsf5gAAAc4"]
[Tue Jul 21 09:00:06.917001 2026] [security2:error] [pid 559070:tid 559235] [client 117.235.80.45:52660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.80.235.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fRiy1f1FtKC137xsf5wAAAbI"]
[Tue Jul 21 09:00:06.917089 2026] [security2:error] [pid 559070:tid 559235] [client 117.235.80.45:52660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fRiy1f1FtKC137xsf5wAAAbI"]
[Tue Jul 21 09:00:06.930296 2026] [security2:error] [pid 559070:tid 559258] [client 20.151.10.161:48980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/bless.php"] [unique_id "al9fRiy1f1FtKC137xsf6AAAAck"]
[Tue Jul 21 09:00:07.379837 2026] [security2:error] [pid 559070:tid 559268] [client 20.151.10.161:54945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file25.php"] [unique_id "al9fRyy1f1FtKC137xsf7gAAAdM"]
[Tue Jul 21 09:00:07.387762 2026] [security2:error] [pid 559070:tid 559311] [client 173.252.95.4:61296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fRyy1f1FtKC137xsf7wAAAf4"]
[Tue Jul 21 09:00:07.661127 2026] [security2:error] [pid 559070:tid 559296] [client 128.127.105.184:56690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9fRyy1f1FtKC137xsf9QAAAe8"]
[Tue Jul 21 09:00:07.661222 2026] [security2:error] [pid 559070:tid 559296] [client 128.127.105.184:56690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9fRyy1f1FtKC137xsf9QAAAe8"]
[Tue Jul 21 09:00:07.746089 2026] [security2:error] [pid 559070:tid 559321] [client 74.249.245.134:12890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/jga.php"] [unique_id "al9fRyy1f1FtKC137xsf9gAAAgg"]
[Tue Jul 21 09:00:07.778281 2026] [core:alert] [pid 533360:tid 533555] [client 57.141.18.56:0] /home1/hostag18/fs3manutencao.com/.htaccess: </IfModule> without matching <IfModule> section
[Tue Jul 21 09:00:07.902637 2026] [security2:error] [pid 559070:tid 559157] [remote 192.241.143.148:42844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tecnoturbo.com.br"] [uri "/wp-login.php"] [unique_id "al9fRyy1f1FtKC137xsf-QABmFY"]
[Tue Jul 21 09:00:07.978411 2026] [security2:error] [pid 533360:tid 533541] [client 65.21.113.253:39506] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fR3UPuLYrePtEkUc_VwAAALU"]
[Tue Jul 21 09:00:08.065429 2026] [security2:error] [pid 559070:tid 559257] [client 74.7.228.14:40670] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "erp.appauto.com.br"] [uri "/index.php"] [unique_id "al9fSCy1f1FtKC137xsf_AAByD0"]
[Tue Jul 21 09:00:08.482876 2026] [security2:error] [pid 559070:tid 559229] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fSCy1f1FtKC137xsf_wABrCs"]
[Tue Jul 21 09:00:08.661085 2026] [security2:error] [pid 559070:tid 559104] [remote 65.111.12.222:50405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.12.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9fSCy1f1FtKC137xsgAgABvSE"]
[Tue Jul 21 09:00:08.825232 2026] [security2:error] [pid 533360:tid 533519] [client 20.220.225.223:30666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/berlin.php"] [unique_id "al9fSHUPuLYrePtEkUc_dgAAAJ8"]
[Tue Jul 21 09:00:08.827232 2026] [security2:error] [pid 559070:tid 559210] [client 74.249.245.134:27301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/a1.php"] [unique_id "al9fSCy1f1FtKC137xsgBAAAAZk"]
[Tue Jul 21 09:00:08.917133 2026] [security2:error] [pid 559070:tid 559243] [client 178.89.149.46:61683] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "meuflatnapraia.com.br"] [uri "/"] [unique_id "al9fSCy1f1FtKC137xsgBgAAAbo"]
[Tue Jul 21 09:00:08.992764 2026] [security2:error] [pid 533360:tid 533532] [client 173.252.95.115:60614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fSHUPuLYrePtEkUc_fQAAAKw"]
[Tue Jul 21 09:00:09.103114 2026] [security2:error] [pid 533360:tid 533553] [client 74.249.245.134:12866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/k.php"] [unique_id "al9fSXUPuLYrePtEkUc_ggAAAME"]
[Tue Jul 21 09:00:09.179223 2026] [security2:error] [pid 559070:tid 559262] [client 85.208.96.211:12554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dharmanet.com.br"] [uri "/mandala/animado.htm"] [unique_id "al9fSSy1f1FtKC137xsgCQAAAc0"]
[Tue Jul 21 09:00:09.179309 2026] [security2:error] [pid 559070:tid 559262] [client 85.208.96.211:12554] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.dharmanet.com.br"] [uri "/mandala/animado.htm"] [unique_id "al9fSSy1f1FtKC137xsgCQAAAc0"]
[Tue Jul 21 09:00:09.258019 2026] [security2:error] [pid 533360:tid 533568] [client 20.151.10.161:48576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/file46.php"] [unique_id "al9fSXUPuLYrePtEkUc_hQAAANA"]
[Tue Jul 21 09:00:09.811032 2026] [security2:error] [pid 559070:tid 559235] [client 117.214.78.59:59747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fSSy1f1FtKC137xsgEAAAAbI"]
[Tue Jul 21 09:00:09.811126 2026] [security2:error] [pid 559070:tid 559235] [client 117.214.78.59:59747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fSSy1f1FtKC137xsgEAAAAbI"]
[Tue Jul 21 09:00:09.890333 2026] [security2:error] [pid 533360:tid 533503] [client 74.249.245.134:27159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/w.php"] [unique_id "al9fSXUPuLYrePtEkUc_lQAAAI8"]
[Tue Jul 21 09:00:10.193145 2026] [security2:error] [pid 533360:tid 533517] [client 20.151.10.161:56296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9fSnUPuLYrePtEkUc_nwAAAJ0"]
[Tue Jul 21 09:00:10.291693 2026] [security2:error] [pid 533360:tid 533552] [client 173.252.95.3:40930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fSnUPuLYrePtEkUc_ogAAAMA"]
[Tue Jul 21 09:00:10.505259 2026] [security2:error] [pid 559070:tid 559318] [client 74.249.245.134:12882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/vx.php"] [unique_id "al9fSiy1f1FtKC137xsgGAAAAgU"]
[Tue Jul 21 09:00:10.526189 2026] [security2:error] [pid 559070:tid 559206] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fSiy1f1FtKC137xsgGQAAAZU"]
[Tue Jul 21 09:00:10.825584 2026] [security2:error] [pid 559070:tid 559209] [client 20.151.10.161:49144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/eee.php"] [unique_id "al9fSiy1f1FtKC137xsgHAAAAZg"]
[Tue Jul 21 09:00:10.941793 2026] [security2:error] [pid 559070:tid 559269] [client 20.151.10.161:51058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file48.php"] [unique_id "al9fSiy1f1FtKC137xsgHQAAAdQ"]
[Tue Jul 21 09:00:10.960887 2026] [security2:error] [pid 559070:tid 559303] [client 74.249.245.134:27202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/wp-good.php"] [unique_id "al9fSiy1f1FtKC137xsgHgAAAfY"]
[Tue Jul 21 09:00:11.033477 2026] [security2:error] [pid 533360:tid 533611] [client 113.22.144.139:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fS3UPuLYrePtEkUc_rwAAAPs"]
[Tue Jul 21 09:00:11.033597 2026] [security2:error] [pid 533360:tid 533611] [client 113.22.144.139:51766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fS3UPuLYrePtEkUc_rwAAAPs"]
[Tue Jul 21 09:00:11.163956 2026] [security2:error] [pid 559070:tid 559271] [client 20.151.10.161:56295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9fSyy1f1FtKC137xsgIgAAAdY"]
[Tue Jul 21 09:00:11.345986 2026] [security2:error] [pid 559070:tid 559229] [client 173.252.95.37:37180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fSyy1f1FtKC137xsgJQAAAaw"]
[Tue Jul 21 09:00:11.357280 2026] [security2:error] [pid 533360:tid 533539] [client 20.226.60.151:50414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/hosty.php"] [unique_id "al9fS3UPuLYrePtEkUc_tQAAALM"]
[Tue Jul 21 09:00:11.663464 2026] [security2:error] [pid 559070:tid 559274] [client 65.21.113.253:40690] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fSyy1f1FtKC137xsgIwAAAdk"]
[Tue Jul 21 09:00:11.688238 2026] [security2:error] [pid 559070:tid 559260] [client 20.151.10.161:56202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/x.php"] [unique_id "al9fSyy1f1FtKC137xsgKQAAAcs"]
[Tue Jul 21 09:00:11.774973 2026] [security2:error] [pid 559070:tid 559230] [client 74.249.245.134:12841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/ws77.php"] [unique_id "al9fSyy1f1FtKC137xsgKgAAAa0"]
[Tue Jul 21 09:00:11.809147 2026] [security2:error] [pid 559070:tid 559290] [client 41.89.234.2:51273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fSyy1f1FtKC137xsgKwAAAek"]
[Tue Jul 21 09:00:11.809301 2026] [security2:error] [pid 559070:tid 559290] [client 41.89.234.2:51273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fSyy1f1FtKC137xsgKwAAAek"]
[Tue Jul 21 09:00:11.821828 2026] [security2:error] [pid 533360:tid 533535] [client 20.220.225.223:34461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wpx.php"] [unique_id "al9fS3UPuLYrePtEkUc_vwAAAK8"]
[Tue Jul 21 09:00:12.219006 2026] [security2:error] [pid 559070:tid 559223] [client 117.210.181.114:26625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.181.210.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fTCy1f1FtKC137xsgNwAAAaY"]
[Tue Jul 21 09:00:12.219176 2026] [security2:error] [pid 559070:tid 559223] [client 117.210.181.114:26625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fTCy1f1FtKC137xsgNwAAAaY"]
[Tue Jul 21 09:00:12.314790 2026] [security2:error] [pid 559070:tid 559311] [client 20.52.136.55:1751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/about.php"] [unique_id "al9fTCy1f1FtKC137xsgOAAAAf4"]
[Tue Jul 21 09:00:12.389127 2026] [security2:error] [pid 559070:tid 559245] [client 74.249.245.134:27260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "ia.bavos.com.br"] [uri "/.info.php"] [unique_id "al9fTCy1f1FtKC137xsgOQAAAbw"]
[Tue Jul 21 09:00:12.391993 2026] [security2:error] [pid 533360:tid 533607] [client 182.189.99.211:48204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fTHUPuLYrePtEkUc_zgAAAPc"]
[Tue Jul 21 09:00:12.392097 2026] [security2:error] [pid 533360:tid 533607] [client 182.189.99.211:48204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fTHUPuLYrePtEkUc_zgAAAPc"]
[Tue Jul 21 09:00:12.400522 2026] [security2:error] [pid 559070:tid 559259] [client 20.151.10.161:56227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/j260624_13.php"] [unique_id "al9fTCy1f1FtKC137xsgOgAAAco"]
[Tue Jul 21 09:00:12.658180 2026] [security2:error] [pid 559070:tid 559190] [remote 212.64.199.62:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.199.64.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9fTCy1f1FtKC137xsgRAAB1Hc"]
[Tue Jul 21 09:00:12.658358 2026] [security2:error] [pid 559070:tid 559269] [client 212.64.199.62:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "assumaocontrole.com"] [uri "/xmlrpc.php"] [unique_id "al9fTCy1f1FtKC137xsgRAAB1Hc"]
[Tue Jul 21 09:00:12.703166 2026] [security2:error] [pid 533360:tid 533562] [client 74.249.245.134:12885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/2.php"] [unique_id "al9fTHUPuLYrePtEkUc_0wAAAMo"]
[Tue Jul 21 09:00:12.861823 2026] [security2:error] [pid 559070:tid 559212] [client 20.151.10.161:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/d62.php"] [unique_id "al9fTCy1f1FtKC137xsgRwAAAZs"]
[Tue Jul 21 09:00:12.990748 2026] [security2:error] [pid 559070:tid 559272] [client 20.220.225.223:58386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/billur.php"] [unique_id "al9fTCy1f1FtKC137xsgTQAAAdc"]
[Tue Jul 21 09:00:13.012602 2026] [security2:error] [pid 559070:tid 559078] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fTSy1f1FtKC137xsgTgAB-wc"]
[Tue Jul 21 09:00:13.012736 2026] [security2:error] [pid 559070:tid 559308] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fTSy1f1FtKC137xsgTgAB-wc"]
[Tue Jul 21 09:00:13.024707 2026] [security2:error] [pid 559070:tid 559253] [client 20.220.225.223:34271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/else1.php"] [unique_id "al9fTSy1f1FtKC137xsgTwAAAcQ"]
[Tue Jul 21 09:00:13.148371 2026] [security2:error] [pid 559070:tid 559274] [client 20.151.10.161:55826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file6.php"] [unique_id "al9fTSy1f1FtKC137xsgUQAAAdk"]
[Tue Jul 21 09:00:13.206850 2026] [security2:error] [pid 533360:tid 533577] [client 20.151.10.161:56257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/ups.php"] [unique_id "al9fTXUPuLYrePtEkUc_3wAAANk"]
[Tue Jul 21 09:00:13.423566 2026] [security2:error] [pid 559070:tid 559207] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fTSy1f1FtKC137xsgVAAAAZY"]
[Tue Jul 21 09:00:13.464380 2026] [security2:error] [pid 559070:tid 559217] [client 20.220.225.223:34214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/tkikikoko.php"] [unique_id "al9fTSy1f1FtKC137xsgVQAAAaA"]
[Tue Jul 21 09:00:13.479611 2026] [security2:error] [pid 533360:tid 533604] [client 20.226.60.151:62032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/k.php"] [unique_id "al9fTXUPuLYrePtEkUc_5gAAAPQ"]
[Tue Jul 21 09:00:13.745025 2026] [security2:error] [pid 559070:tid 559268] [client 198.44.157.162:59572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9fTSy1f1FtKC137xsgWgAAAdM"]
[Tue Jul 21 09:00:13.745131 2026] [security2:error] [pid 559070:tid 559268] [client 198.44.157.162:59572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitalityreviewcenter.online"] [uri "/xmlrpc.php"] [unique_id "al9fTSy1f1FtKC137xsgWgAAAdM"]
[Tue Jul 21 09:00:13.789777 2026] [security2:error] [pid 559070:tid 559314] [client 74.249.245.134:27245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/item.php"] [unique_id "al9fTSy1f1FtKC137xsgWwAAAgE"]
[Tue Jul 21 09:00:13.800797 2026] [security2:error] [pid 533360:tid 533539] [client 198.44.157.162:59576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9fTXUPuLYrePtEkUc_7AAAALM"]
[Tue Jul 21 09:00:13.800894 2026] [security2:error] [pid 533360:tid 533539] [client 198.44.157.162:59576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "todayvital.online"] [uri "/xmlrpc.php"] [unique_id "al9fTXUPuLYrePtEkUc_7AAAALM"]
[Tue Jul 21 09:00:13.829701 2026] [security2:error] [pid 559070:tid 559311] [client 20.151.10.161:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/file25.php"] [unique_id "al9fTSy1f1FtKC137xsgXAAAAf4"]
[Tue Jul 21 09:00:13.896903 2026] [security2:error] [pid 559070:tid 559259] [client 20.151.10.161:56304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/k.php"] [unique_id "al9fTSy1f1FtKC137xsgXgAAAco"]
[Tue Jul 21 09:00:13.948748 2026] [security2:error] [pid 533360:tid 533513] [client 59.95.197.55:65424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fTXUPuLYrePtEkUc_7wAAAJk"]
[Tue Jul 21 09:00:13.948877 2026] [security2:error] [pid 533360:tid 533513] [client 59.95.197.55:65424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fTXUPuLYrePtEkUc_7wAAAJk"]
[Tue Jul 21 09:00:14.035140 2026] [security2:error] [pid 559070:tid 559278] [client 74.249.245.134:12010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/asd.php"] [unique_id "al9fTiy1f1FtKC137xsgYQAAAd0"]
[Tue Jul 21 09:00:14.200514 2026] [security2:error] [pid 559070:tid 559315] [client 20.220.225.223:34221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9fTiy1f1FtKC137xsgZQAAAgI"]
[Tue Jul 21 09:00:14.445659 2026] [security2:error] [pid 533360:tid 533574] [client 20.220.225.223:30679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/mimpi.php"] [unique_id "al9fTnUPuLYrePtEkUc_-QAAANY"]
[Tue Jul 21 09:00:14.452765 2026] [security2:error] [pid 559070:tid 559122] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fTiy1f1FtKC137xsgaAAB5jM"]
[Tue Jul 21 09:00:14.452944 2026] [security2:error] [pid 559070:tid 559287] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fTiy1f1FtKC137xsgaAAB5jM"]
[Tue Jul 21 09:00:14.547158 2026] [security2:error] [pid 559070:tid 559185] [remote 188.164.197.230:39248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.197.164.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compressoresra.com.br"] [uri "/wp-login.php"] [unique_id "al9fTiy1f1FtKC137xsgZwABnnI"]
[Tue Jul 21 09:00:14.557663 2026] [security2:error] [pid 533360:tid 533545] [client 65.21.113.253:40698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fTnUPuLYrePtEkUc_8gAAALk"]
[Tue Jul 21 09:00:14.591246 2026] [security2:error] [pid 533360:tid 533619] [client 74.249.245.134:12856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/default.php"] [unique_id "al9fTnUPuLYrePtEkUc__AAAAQM"]
[Tue Jul 21 09:00:14.625845 2026] [security2:error] [pid 559070:tid 559248] [client 154.182.128.22:55773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.128.182.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fTiy1f1FtKC137xsgawAAAb8"]
[Tue Jul 21 09:00:14.626826 2026] [security2:error] [pid 559070:tid 559248] [client 154.182.128.22:55773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fTiy1f1FtKC137xsgawAAAb8"]
[Tue Jul 21 09:00:14.796592 2026] [security2:error] [pid 559070:tid 559233] [client 139.167.208.211:60072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.208.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fTiy1f1FtKC137xsgbgAAAbA"]
[Tue Jul 21 09:00:14.796726 2026] [security2:error] [pid 559070:tid 559233] [client 139.167.208.211:60072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fTiy1f1FtKC137xsgbgAAAbA"]
[Tue Jul 21 09:00:14.817030 2026] [security2:error] [pid 533360:tid 533601] [client 20.151.10.161:48598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/file48.php"] [unique_id "al9fTnUPuLYrePtEkUdAAQAAAPE"]
[Tue Jul 21 09:00:14.850693 2026] [security2:error] [pid 559070:tid 559240] [client 74.249.245.134:27262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/albin.php"] [unique_id "al9fTiy1f1FtKC137xsgbwAAAbc"]
[Tue Jul 21 09:00:15.157436 2026] [security2:error] [pid 559070:tid 559230] [client 5.180.61.69:54452] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "treeoflifehealth.online"] [uri "/"] [unique_id "al9fTyy1f1FtKC137xsgdAAAAa0"]
[Tue Jul 21 09:00:15.341125 2026] [security2:error] [pid 533360:tid 533618] [client 20.151.10.161:56281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/k2.php"] [unique_id "al9fT3UPuLYrePtEkUdACwAAAQI"]
[Tue Jul 21 09:00:15.566221 2026] [security2:error] [pid 559070:tid 559258] [client 5.180.61.69:54452] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1584"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "treeoflifehealth.online"] [uri "/wp-json/batch/v1"] [unique_id "al9fTyy1f1FtKC137xsgfQAAAck"]
[Tue Jul 21 09:00:15.733445 2026] [security2:error] [pid 559070:tid 559324] [client 74.249.245.134:27216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/alfa.php"] [unique_id "al9fTyy1f1FtKC137xsggAAAAgs"]
[Tue Jul 21 09:00:15.780525 2026] [security2:error] [pid 533360:tid 533499] [client 20.226.60.151:62021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/aaa.php"] [unique_id "al9fT3UPuLYrePtEkUdAFQAAAIs"]
[Tue Jul 21 09:00:15.975491 2026] [security2:error] [pid 559070:tid 559259] [client 5.180.61.69:54452] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "treeoflifehealth.online"] [uri "/"] [unique_id "al9fTyy1f1FtKC137xsghAAAAco"]
[Tue Jul 21 09:00:16.093543 2026] [security2:error] [pid 533360:tid 533596] [client 20.151.10.161:48580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/file6.php"] [unique_id "al9fUHUPuLYrePtEkUdAGwAAAOw"]
[Tue Jul 21 09:00:16.198712 2026] [security2:error] [pid 533360:tid 533508] [client 20.220.225.223:53491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "diziseguros.com.br"] [uri "/phpinfo.php1"] [unique_id "al9fUHUPuLYrePtEkUdAHgAAAJQ"]
[Tue Jul 21 09:00:16.242008 2026] [security2:error] [pid 559070:tid 559221] [client 74.249.245.134:12845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/gettest.php"] [unique_id "al9fUCy1f1FtKC137xsghwAAAaQ"]
[Tue Jul 21 09:00:16.362711 2026] [security2:error] [pid 559070:tid 559236] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fUCy1f1FtKC137xsgiQAAAbM"]
[Tue Jul 21 09:00:16.383748 2026] [security2:error] [pid 559070:tid 559318] [client 5.180.61.69:54452] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "treeoflifehealth.online"] [uri "/"] [unique_id "al9fUCy1f1FtKC137xsgigAAAgU"]
[Tue Jul 21 09:00:16.513632 2026] [security2:error] [pid 533360:tid 533553] [client 103.59.206.240:31222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fUHUPuLYrePtEkUdAJgAAAME"]
[Tue Jul 21 09:00:16.513840 2026] [security2:error] [pid 533360:tid 533553] [client 103.59.206.240:31222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fUHUPuLYrePtEkUdAJgAAAME"]
[Tue Jul 21 09:00:16.515363 2026] [security2:error] [pid 559070:tid 559279] [client 20.151.10.161:56225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/k3.php"] [unique_id "al9fUCy1f1FtKC137xsgkAAAAd4"]
[Tue Jul 21 09:00:16.594961 2026] [security2:error] [pid 559070:tid 559206] [client 173.252.95.6:43774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fUCy1f1FtKC137xsgkwAAAZU"]
[Tue Jul 21 09:00:16.794317 2026] [security2:error] [pid 559070:tid 559256] [client 5.180.61.69:54452] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "treeoflifehealth.online"] [uri "/"] [unique_id "al9fUCy1f1FtKC137xsglgAAAcc"]
[Tue Jul 21 09:00:16.902266 2026] [security2:error] [pid 533360:tid 533513] [client 114.198.138.124:64519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fUHUPuLYrePtEkUdALgAAAJk"]
[Tue Jul 21 09:00:16.902383 2026] [security2:error] [pid 533360:tid 533513] [client 114.198.138.124:64519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fUHUPuLYrePtEkUdALgAAAJk"]
[Tue Jul 21 09:00:16.914790 2026] [security2:error] [pid 559070:tid 559240] [client 20.220.225.223:30862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/dp.php"] [unique_id "al9fUCy1f1FtKC137xsgmAAAAbc"]
[Tue Jul 21 09:00:17.031724 2026] [security2:error] [pid 533360:tid 533529] [client 74.249.245.134:27162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9fUXUPuLYrePtEkUdAMAAAAKk"]
[Tue Jul 21 09:00:17.048174 2026] [security2:error] [pid 559070:tid 559109] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fUSy1f1FtKC137xsgnAABvyY"]
[Tue Jul 21 09:00:17.048295 2026] [security2:error] [pid 559070:tid 559248] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fUSy1f1FtKC137xsgnAABvyY"]
[Tue Jul 21 09:00:17.103854 2026] [security2:error] [pid 559070:tid 559291] [client 194.99.104.35:36510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9fUSy1f1FtKC137xsgngAAAeo"]
[Tue Jul 21 09:00:17.104013 2026] [security2:error] [pid 559070:tid 559291] [client 194.99.104.35:36510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9fUSy1f1FtKC137xsgngAAAeo"]
[Tue Jul 21 09:00:17.106999 2026] [security2:error] [pid 533360:tid 533548] [client 173.252.95.26:48252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fUXUPuLYrePtEkUdAMgAAALw"]
[Tue Jul 21 09:00:17.128472 2026] [security2:error] [pid 533360:tid 533524] [client 20.151.10.161:49094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/a2.php"] [unique_id "al9fUXUPuLYrePtEkUdANQAAAKQ"]
[Tue Jul 21 09:00:17.202975 2026] [security2:error] [pid 559070:tid 559275] [client 5.180.61.69:54452] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "treeoflifehealth.online"] [uri "/"] [unique_id "al9fUSy1f1FtKC137xsgoQAAAdo"]
[Tue Jul 21 09:00:17.310217 2026] [security2:error] [pid 559070:tid 559216] [client 20.151.10.161:56286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/k4.php"] [unique_id "al9fUSy1f1FtKC137xsgowAAAZ8"]
[Tue Jul 21 09:00:17.379908 2026] [security2:error] [pid 533360:tid 533557] [client 168.167.81.163:61628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9fUXUPuLYrePtEkUdAOQAAAMU"]
[Tue Jul 21 09:00:17.380057 2026] [security2:error] [pid 533360:tid 533557] [client 168.167.81.163:61628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9fUXUPuLYrePtEkUdAOQAAAMU"]
[Tue Jul 21 09:00:17.501169 2026] [security2:error] [pid 559070:tid 559286] [client 65.21.113.253:40704] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fUSy1f1FtKC137xsgmwAAAeU"]
[Tue Jul 21 09:00:17.510454 2026] [security2:error] [pid 559070:tid 559250] [client 117.235.80.45:53429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.80.235.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fUSy1f1FtKC137xsgpgAAAcE"]
[Tue Jul 21 09:00:17.510622 2026] [security2:error] [pid 559070:tid 559250] [client 117.235.80.45:53429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fUSy1f1FtKC137xsgpgAAAcE"]
[Tue Jul 21 09:00:17.536565 2026] [security2:error] [pid 533360:tid 533516] [client 74.249.245.134:43704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/tfm.php"] [unique_id "al9fUXUPuLYrePtEkUdAPQAAAJw"]
[Tue Jul 21 09:00:17.611549 2026] [security2:error] [pid 559070:tid 559281] [client 5.180.61.69:54452] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "treeoflifehealth.online"] [uri "/"] [unique_id "al9fUSy1f1FtKC137xsgqAAAAeA"]
[Tue Jul 21 09:00:17.662605 2026] [security2:error] [pid 533360:tid 533601] [client 173.252.95.35:61498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fUXUPuLYrePtEkUdAQgAAAPE"]
[Tue Jul 21 09:00:17.816294 2026] [security2:error] [pid 533360:tid 533530] [client 20.226.60.151:62018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/file5.php"] [unique_id "al9fUXUPuLYrePtEkUdARAAAAKo"]
[Tue Jul 21 09:00:17.824282 2026] [security2:error] [pid 533360:tid 533618] [client 20.220.225.223:30895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/bootstrap.php"] [unique_id "al9fUXUPuLYrePtEkUdARQAAAQI"]
[Tue Jul 21 09:00:17.951477 2026] [security2:error] [pid 559070:tid 559258] [client 20.220.225.223:34252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/billur.php"] [unique_id "al9fUSy1f1FtKC137xsgqwAAAck"]
[Tue Jul 21 09:00:18.021298 2026] [security2:error] [pid 559070:tid 559270] [client 5.180.61.69:54452] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1600"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "treeoflifehealth.online"] [uri "/"] [unique_id "al9fUiy1f1FtKC137xsgrAAAAdU"]
[Tue Jul 21 09:00:18.046502 2026] [security2:error] [pid 559070:tid 559251] [client 74.249.245.134:12823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/ws81.php"] [unique_id "al9fUiy1f1FtKC137xsgrQAAAcI"]
[Tue Jul 21 09:00:18.064727 2026] [security2:error] [pid 533360:tid 533582] [client 185.213.175.37:2432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/.env.bak"] [unique_id "al9fUnUPuLYrePtEkUdATgAAAN4"]
[Tue Jul 21 09:00:18.249605 2026] [security2:error] [pid 533360:tid 533499] [client 20.151.10.161:49082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/file15.php"] [unique_id "al9fUnUPuLYrePtEkUdAUQAAAIs"]
[Tue Jul 21 09:00:18.273625 2026] [security2:error] [pid 533360:tid 533577] [client 173.252.95.23:47908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fUnUPuLYrePtEkUdAUgAAANk"]
[Tue Jul 21 09:00:18.388524 2026] [security2:error] [pid 533360:tid 533542] [client 74.249.245.134:27327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/av.php"] [unique_id "al9fUnUPuLYrePtEkUdAUwAAALY"]
[Tue Jul 21 09:00:18.491611 2026] [security2:error] [pid 559070:tid 559304] [client 20.220.225.223:30900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/wp-editor.php"] [unique_id "al9fUiy1f1FtKC137xsgtAAAAfc"]
[Tue Jul 21 09:00:18.775618 2026] [security2:error] [pid 533360:tid 533554] [client 20.151.10.161:49100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/jp.php"] [unique_id "al9fUnUPuLYrePtEkUdAXQAAAMI"]
[Tue Jul 21 09:00:18.776773 2026] [security2:error] [pid 559070:tid 559228] [client 51.68.107.157:20993] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sistedu-mec.com"] [uri "/robots.txt"] [unique_id "al9fUiy1f1FtKC137xsgugAAAas"]
[Tue Jul 21 09:00:18.776940 2026] [security2:error] [pid 559070:tid 559228] [client 51.68.107.157:20993] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sistedu-mec.com"] [uri "/robots.txt"] [unique_id "al9fUiy1f1FtKC137xsgugAAAas"]
[Tue Jul 21 09:00:19.023012 2026] [security2:error] [pid 533360:tid 533597] [client 74.249.245.134:43667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/222.php"] [unique_id "al9fU3UPuLYrePtEkUdAYQAAAO0"]
[Tue Jul 21 09:00:19.147174 2026] [security2:error] [pid 559070:tid 559234] [client 20.220.225.223:34219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wp-css.php"] [unique_id "al9fUyy1f1FtKC137xsgwQAAAbE"]
[Tue Jul 21 09:00:19.254209 2026] [security2:error] [pid 559070:tid 559233] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fUyy1f1FtKC137xsgwgAAAbA"]
[Tue Jul 21 09:00:19.448327 2026] [security2:error] [pid 559070:tid 559212] [client 185.213.175.37:55604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "budhug.com.br"] [uri "/.env.bak"] [unique_id "al9fUyy1f1FtKC137xsgwwAAAZs"]
[Tue Jul 21 09:00:19.461652 2026] [security2:error] [pid 533360:tid 533510] [client 114.119.141.178:41823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "madeireirapiske.com.br"] [uri "/catalogo/v16"] [unique_id "al9fU3UPuLYrePtEkUdAbQAAAJY"], referer: https://madeireirapiske.com.br/catalogo/v16
[Tue Jul 21 09:00:19.663336 2026] [security2:error] [pid 559070:tid 559216] [client 198.44.157.162:47324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9fUyy1f1FtKC137xsgywAAAZ8"]
[Tue Jul 21 09:00:19.663408 2026] [security2:error] [pid 559070:tid 559216] [client 198.44.157.162:47324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "factorial.studio"] [uri "/xmlrpc.php"] [unique_id "al9fUyy1f1FtKC137xsgywAAAZ8"]
[Tue Jul 21 09:00:19.796629 2026] [security2:error] [pid 533360:tid 533586] [client 194.99.104.35:33202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9fU3UPuLYrePtEkUdAdQAAAOI"]
[Tue Jul 21 09:00:19.796745 2026] [security2:error] [pid 533360:tid 533586] [client 194.99.104.35:33202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9fU3UPuLYrePtEkUdAdQAAAOI"]
[Tue Jul 21 09:00:19.888643 2026] [security2:error] [pid 533360:tid 533498] [client 74.249.245.134:27323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/gg.php"] [unique_id "al9fU3UPuLYrePtEkUdAdgAAAIo"]
[Tue Jul 21 09:00:19.938963 2026] [security2:error] [pid 559070:tid 559252] [client 74.249.245.134:12841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/t.php"] [unique_id "al9fUyy1f1FtKC137xsgzQAAAcM"]
[Tue Jul 21 09:00:19.951888 2026] [security2:error] [pid 559070:tid 559297] [client 194.99.104.35:33204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9fUyy1f1FtKC137xsgzgAAAfA"]
[Tue Jul 21 09:00:19.952001 2026] [security2:error] [pid 559070:tid 559297] [client 194.99.104.35:33204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9fUyy1f1FtKC137xsgzgAAAfA"]
[Tue Jul 21 09:00:19.967795 2026] [security2:error] [pid 559070:tid 559295] [client 20.151.10.161:49065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/f35.php"] [unique_id "al9fUyy1f1FtKC137xsgzwAAAe4"]
[Tue Jul 21 09:00:20.148236 2026] [security2:error] [pid 533360:tid 533436] [remote 124.55.178.99:36222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9fVHUPuLYrePtEkUdAgQABA0g"]
[Tue Jul 21 09:00:20.148410 2026] [security2:error] [pid 533360:tid 533619] [client 124.55.178.99:36222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drjoaoguedes.com"] [uri "/xmlrpc.php"] [unique_id "al9fVHUPuLYrePtEkUdAgQABA0g"]
[Tue Jul 21 09:00:20.203960 2026] [security2:error] [pid 559070:tid 559235] [client 20.226.60.151:50417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/222.php"] [unique_id "al9fVCy1f1FtKC137xsg1gAAAbI"]
[Tue Jul 21 09:00:20.285603 2026] [security2:error] [pid 533360:tid 533516] [client 117.214.78.59:60204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fVHUPuLYrePtEkUdAgwAAAJw"]
[Tue Jul 21 09:00:20.285789 2026] [security2:error] [pid 533360:tid 533516] [client 117.214.78.59:60204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fVHUPuLYrePtEkUdAgwAAAJw"]
[Tue Jul 21 09:00:20.346304 2026] [security2:error] [pid 533360:tid 533613] [client 65.21.113.253:56972] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fU3UPuLYrePtEkUdAdwAAAP0"]
[Tue Jul 21 09:00:20.355115 2026] [security2:error] [pid 559070:tid 559316] [client 20.151.10.161:63371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al9fVCy1f1FtKC137xsg1wAAAgM"]
[Tue Jul 21 09:00:20.562800 2026] [security2:error] [pid 533360:tid 533575] [client 20.151.10.161:49142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-load.php"] [unique_id "al9fVHUPuLYrePtEkUdAhwAAANc"]
[Tue Jul 21 09:00:20.685295 2026] [security2:error] [pid 559070:tid 559317] [client 74.249.245.134:12870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/a.php"] [unique_id "al9fVCy1f1FtKC137xsg4gAAAgQ"]
[Tue Jul 21 09:00:20.716275 2026] [security2:error] [pid 559070:tid 559207] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fVCy1f1FtKC137xsg3AABlgo"]
[Tue Jul 21 09:00:20.833323 2026] [security2:error] [pid 533360:tid 533584] [client 74.249.245.134:27238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/sql.php"] [unique_id "al9fVHUPuLYrePtEkUdAjwAAAOA"]
[Tue Jul 21 09:00:20.993585 2026] [security2:error] [pid 559070:tid 559218] [client 20.151.10.161:56205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/k5.php"] [unique_id "al9fVCy1f1FtKC137xsg6AAAAaE"]
[Tue Jul 21 09:00:21.041218 2026] [security2:error] [pid 559070:tid 559203] [client 20.52.136.55:1558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/adminfuns.php"] [unique_id "al9fVSy1f1FtKC137xsg6QAAAZI"]
[Tue Jul 21 09:00:21.289219 2026] [security2:error] [pid 533360:tid 533537] [client 198.44.157.162:47326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9fVXUPuLYrePtEkUdAmAAAALE"]
[Tue Jul 21 09:00:21.289396 2026] [security2:error] [pid 533360:tid 533537] [client 198.44.157.162:47326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9fVXUPuLYrePtEkUdAmAAAALE"]
[Tue Jul 21 09:00:21.495465 2026] [security2:error] [pid 559070:tid 559272] [client 173.252.95.41:44316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fVSy1f1FtKC137xsg7gAAAdc"]
[Tue Jul 21 09:00:21.603030 2026] [security2:error] [pid 533360:tid 533588] [client 20.151.10.161:49106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/xwpg.php"] [unique_id "al9fVXUPuLYrePtEkUdAnAAAAOQ"]
[Tue Jul 21 09:00:21.998083 2026] [security2:error] [pid 533360:tid 533605] [client 20.220.225.223:20881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/tkikikoko.php"] [unique_id "al9fVXUPuLYrePtEkUdApwAAAPU"]
[Tue Jul 21 09:00:22.070378 2026] [security2:error] [pid 559070:tid 559216] [client 74.249.245.134:43681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/a1.php"] [unique_id "al9fViy1f1FtKC137xsg8gAAAZ8"]
[Tue Jul 21 09:00:22.098786 2026] [security2:error] [pid 533360:tid 533601] [client 74.249.245.134:27168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/up.php"] [unique_id "al9fVnUPuLYrePtEkUdAqwAAAPE"]
[Tue Jul 21 09:00:22.184477 2026] [security2:error] [pid 559070:tid 559230] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fViy1f1FtKC137xsg9gAAAa0"]
[Tue Jul 21 09:00:22.202233 2026] [security2:error] [pid 559070:tid 559266] [client 41.89.234.2:51883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fViy1f1FtKC137xsg-gAAAdE"]
[Tue Jul 21 09:00:22.202330 2026] [security2:error] [pid 559070:tid 559266] [client 41.89.234.2:51883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fViy1f1FtKC137xsg-gAAAdE"]
[Tue Jul 21 09:00:22.245621 2026] [access_compat:error] [pid 559070:tid 559319] [client 162.241.63.68:24318] AH01797: client denied by server configuration: /home2/osval053/public_html/wp-cron.php
[Tue Jul 21 09:00:22.572948 2026] [fcgid:warn] [pid 559070:tid 559258] (70014)End of file found: [client 199.45.155.80:57804] mod_fcgid: can't get data from http client
[Tue Jul 21 09:00:22.645718 2026] [security2:error] [pid 559070:tid 559262] [client 20.151.10.161:49079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/waf.php"] [unique_id "al9fViy1f1FtKC137xshAQAAAc0"]
[Tue Jul 21 09:00:22.735759 2026] [security2:error] [pid 533360:tid 533514] [client 74.249.245.134:12835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/w.php"] [unique_id "al9fVnUPuLYrePtEkUdAyAAAAJo"]
[Tue Jul 21 09:00:22.773261 2026] [security2:error] [pid 533360:tid 533560] [client 113.22.144.139:52344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fVnUPuLYrePtEkUdAyQAAAMg"]
[Tue Jul 21 09:00:22.773370 2026] [security2:error] [pid 533360:tid 533560] [client 113.22.144.139:52344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fVnUPuLYrePtEkUdAyQAAAMg"]
[Tue Jul 21 09:00:22.850181 2026] [security2:error] [pid 559070:tid 559259] [client 20.220.225.223:34289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/mimpi.php"] [unique_id "al9fViy1f1FtKC137xshDQAAAco"]
[Tue Jul 21 09:00:22.877357 2026] [security2:error] [pid 559070:tid 559208] [client 20.151.10.161:64193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al9fViy1f1FtKC137xshDgAAAZc"]
[Tue Jul 21 09:00:22.933700 2026] [security2:error] [pid 559070:tid 559250] [client 182.189.99.211:48284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fViy1f1FtKC137xshDwAAAcE"]
[Tue Jul 21 09:00:22.933809 2026] [security2:error] [pid 559070:tid 559250] [client 182.189.99.211:48284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fViy1f1FtKC137xshDwAAAcE"]
[Tue Jul 21 09:00:23.085805 2026] [security2:error] [pid 559070:tid 559206] [client 74.249.245.134:27296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/66.php"] [unique_id "al9fVyy1f1FtKC137xshEgAAAZU"]
[Tue Jul 21 09:00:23.149504 2026] [security2:error] [pid 559070:tid 559294] [client 114.119.143.225:48859] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tempex.com.br"] [uri "/2021/05/14/"] [unique_id "al9fVyy1f1FtKC137xshFwAAAe0"], referer: https://www.tempex.com.br/conheca-os-diferentes-tipos-de-silicone/
[Tue Jul 21 09:00:23.167193 2026] [security2:error] [pid 533360:tid 533490] [remote 116.179.37.179:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al9fV3UPuLYrePtEkUdA1gAAwX4"], referer: https://androapkmod.com/dev/seeplay-inc/
[Tue Jul 21 09:00:23.318681 2026] [security2:error] [pid 559070:tid 559272] [client 20.226.60.151:62037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/test.php"] [unique_id "al9fVyy1f1FtKC137xshHAAAAdc"]
[Tue Jul 21 09:00:23.352853 2026] [security2:error] [pid 533360:tid 533561] [client 65.21.113.253:56982] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fVnUPuLYrePtEkUdAzgAAAMk"]
[Tue Jul 21 09:00:23.369860 2026] [autoindex:error] [pid 559070:tid 559215] [client 199.45.155.80:57828] AH01276: Cannot serve directory /home3/creant42/creantivedesign.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 09:00:23.516805 2026] [security2:error] [pid 559070:tid 559216] [client 74.249.245.134:16744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/wp-good.php"] [unique_id "al9fVyy1f1FtKC137xshIAAAAZ8"]
[Tue Jul 21 09:00:23.565203 2026] [security2:error] [pid 533360:tid 533415] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fV3UPuLYrePtEkUdA3AAAwzM"]
[Tue Jul 21 09:00:23.565357 2026] [security2:error] [pid 533360:tid 533555] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fV3UPuLYrePtEkUdA3AAAwzM"]
[Tue Jul 21 09:00:23.740042 2026] [security2:error] [pid 559070:tid 559213] [client 20.220.225.223:30660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/cro.php"] [unique_id "al9fVyy1f1FtKC137xshIgAAAZw"]
[Tue Jul 21 09:00:23.755901 2026] [security2:error] [pid 533360:tid 533577] [client 115.245.198.210:59713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fV3UPuLYrePtEkUdA5AAAANk"]
[Tue Jul 21 09:00:23.756019 2026] [security2:error] [pid 533360:tid 533577] [client 115.245.198.210:59713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fV3UPuLYrePtEkUdA5AAAANk"]
[Tue Jul 21 09:00:23.975709 2026] [security2:error] [pid 559070:tid 559226] [client 20.151.10.161:56224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/w.php"] [unique_id "al9fVyy1f1FtKC137xshJQAAAak"]
[Tue Jul 21 09:00:24.017266 2026] [security2:error] [pid 559070:tid 559284] [client 20.151.10.161:63371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/media.php"] [unique_id "al9fWCy1f1FtKC137xshJgAAAeM"]
[Tue Jul 21 09:00:24.073068 2026] [security2:error] [pid 533360:tid 533541] [client 20.151.10.161:49036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/xstelth.php"] [unique_id "al9fWHUPuLYrePtEkUdA5wAAALU"]
[Tue Jul 21 09:00:24.440204 2026] [security2:error] [pid 559070:tid 559300] [client 74.249.245.134:12917] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/\\\\.[a-z0-9]{4}\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "784"] [id "900080"] [msg "PHP Mailer Access Attempt"] [hostname "cpanel.simleite.com.br"] [uri "/.info.php"] [unique_id "al9fWCy1f1FtKC137xshLAAAAfM"]
[Tue Jul 21 09:00:24.449533 2026] [security2:error] [pid 559070:tid 559230] [client 59.95.197.55:49522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fWCy1f1FtKC137xshLQAAAa0"]
[Tue Jul 21 09:00:24.449648 2026] [security2:error] [pid 559070:tid 559230] [client 59.95.197.55:49522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fWCy1f1FtKC137xshLQAAAa0"]
[Tue Jul 21 09:00:24.898401 2026] [security2:error] [pid 533360:tid 533439] [remote 165.245.189.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.189.245.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fWHUPuLYrePtEkUdA8QAA4ks"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:24.910252 2026] [security2:error] [pid 559070:tid 559206] [client 20.151.10.161:63388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/images.php"] [unique_id "al9fWCy1f1FtKC137xshNwAAAZU"]
[Tue Jul 21 09:00:24.957478 2026] [security2:error] [pid 559070:tid 559155] [remote 165.245.189.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.189.245.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fWCy1f1FtKC137xshMwAB0FQ"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:24.972867 2026] [security2:error] [pid 559070:tid 559229] [client 74.249.245.134:27232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/666.php"] [unique_id "al9fWCy1f1FtKC137xshOAAAAaw"]
[Tue Jul 21 09:00:24.988733 2026] [security2:error] [pid 559070:tid 559101] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fWCy1f1FtKC137xshOgABoR4"]
[Tue Jul 21 09:00:24.989006 2026] [security2:error] [pid 559070:tid 559218] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fWCy1f1FtKC137xshOgABoR4"]
[Tue Jul 21 09:00:24.991107 2026] [security2:error] [pid 533360:tid 533591] [client 20.151.10.161:49135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-links.php"] [unique_id "al9fWHUPuLYrePtEkUdA9wAAAOc"]
[Tue Jul 21 09:00:25.038783 2026] [security2:error] [pid 559070:tid 559148] [remote 165.245.189.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.189.245.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fWCy1f1FtKC137xshMAABs00"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:25.062585 2026] [security2:error] [pid 533360:tid 533396] [remote 165.245.189.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.189.245.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fWXUPuLYrePtEkUdA-AAAhiA"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:25.107884 2026] [security2:error] [pid 559070:tid 559241] [client 54.39.203.48:20454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dentepro.com.br"] [uri "/robots.txt"] [unique_id "al9fWSy1f1FtKC137xshPQAAAbg"]
[Tue Jul 21 09:00:25.107981 2026] [security2:error] [pid 559070:tid 559241] [client 54.39.203.48:20454] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dentepro.com.br"] [uri "/robots.txt"] [unique_id "al9fWSy1f1FtKC137xshPQAAAbg"]
[Tue Jul 21 09:00:25.148525 2026] [security2:error] [pid 559070:tid 559272] [client 20.220.225.223:34180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/dp.php"] [unique_id "al9fWSy1f1FtKC137xshQAAAAdc"]
[Tue Jul 21 09:00:25.262799 2026] [security2:error] [pid 533360:tid 533465] [remote 165.245.189.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.189.245.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fWXUPuLYrePtEkUdA-gAAm2U"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:25.317534 2026] [security2:error] [pid 559070:tid 559183] [remote 165.245.189.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.189.245.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fWSy1f1FtKC137xshQwAB73A"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:25.353681 2026] [security2:error] [pid 559070:tid 559279] [client 154.182.128.22:56218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.128.182.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fWSy1f1FtKC137xshRAAAAd4"]
[Tue Jul 21 09:00:25.353833 2026] [security2:error] [pid 559070:tid 559279] [client 154.182.128.22:56218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fWSy1f1FtKC137xshRAAAAd4"]
[Tue Jul 21 09:00:25.366506 2026] [security2:error] [pid 533360:tid 533498] [client 114.119.145.42:50025] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "northcomm.com.br"] [uri "/wp-includes/css/dist/editor/style.min.css"] [unique_id "al9fWXUPuLYrePtEkUdA_gAAAIo"], referer: https://northcomm.com.br/wp-includes/css/dist/editor/
[Tue Jul 21 09:00:25.387587 2026] [security2:error] [pid 559070:tid 559195] [remote 217.182.128.41:52214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nutrawidenews.com"] [uri "/wp-login.php"] [unique_id "al9fWSy1f1FtKC137xshPgAB8Xw"]
[Tue Jul 21 09:00:25.407902 2026] [security2:error] [pid 559070:tid 559250] [client 139.167.208.211:60693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.208.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fWSy1f1FtKC137xshRgAAAcE"]
[Tue Jul 21 09:00:25.408014 2026] [security2:error] [pid 559070:tid 559250] [client 139.167.208.211:60693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fWSy1f1FtKC137xshRgAAAcE"]
[Tue Jul 21 09:00:25.441062 2026] [security2:error] [pid 533360:tid 533401] [remote 165.245.189.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.189.245.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fWXUPuLYrePtEkUdBAgAA6yU"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:25.448198 2026] [security2:error] [pid 559070:tid 559176] [remote 165.245.189.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.189.245.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fWSy1f1FtKC137xshRwACCmk"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:25.495302 2026] [security2:error] [pid 559070:tid 559216] [client 74.249.245.134:16730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/item.php"] [unique_id "al9fWSy1f1FtKC137xshSAAAAZ8"]
[Tue Jul 21 09:00:25.586915 2026] [security2:error] [pid 559070:tid 559213] [client 74.249.245.134:27203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/byp.php"] [unique_id "al9fWSy1f1FtKC137xshSgAAAZw"]
[Tue Jul 21 09:00:25.619170 2026] [security2:error] [pid 559070:tid 559210] [client 20.151.10.161:49075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9fWSy1f1FtKC137xshSwAAAZk"]
[Tue Jul 21 09:00:25.626263 2026] [security2:error] [pid 533360:tid 533429] [remote 165.245.189.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.189.245.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fWXUPuLYrePtEkUdBBgAAyEE"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:25.677602 2026] [security2:error] [pid 559070:tid 559150] [remote 165.245.189.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.189.245.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fWSy1f1FtKC137xshTgAB6U8"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:25.806471 2026] [security2:error] [pid 533360:tid 533435] [remote 165.245.189.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.189.245.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.marmorariasolare.com.br"] [uri "/wp-login.php"] [unique_id "al9fWXUPuLYrePtEkUdBCAAAnEc"], referer: https://mail.marmorariasolare.com.br/wp-login.php
[Tue Jul 21 09:00:25.958897 2026] [security2:error] [pid 559070:tid 559314] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fWSy1f1FtKC137xshUwAAAgE"]
[Tue Jul 21 09:00:26.407307 2026] [security2:error] [pid 559070:tid 559317] [client 20.151.10.161:49107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.samavidistribuicao.com.br"] [uri "/aaa.php"] [unique_id "al9fWiy1f1FtKC137xshXAAAAgQ"]
[Tue Jul 21 09:00:26.469081 2026] [security2:error] [pid 559070:tid 559228] [client 20.220.225.223:34296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/bootstrap.php"] [unique_id "al9fWiy1f1FtKC137xshXwAAAas"]
[Tue Jul 21 09:00:26.516932 2026] [security2:error] [pid 559070:tid 559327] [client 148.113.128.143:56332] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "dentepro.com.br"] [uri "/"] [unique_id "al9fWiy1f1FtKC137xshYAAAAg4"]
[Tue Jul 21 09:00:26.517063 2026] [security2:error] [pid 559070:tid 559327] [client 148.113.128.143:56332] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dentepro.com.br"] [uri "/"] [unique_id "al9fWiy1f1FtKC137xshYAAAAg4"]
[Tue Jul 21 09:00:26.621616 2026] [security2:error] [pid 533360:tid 533512] [client 74.249.245.134:27230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/date.php"] [unique_id "al9fWnUPuLYrePtEkUdBGAAAAJg"]
[Tue Jul 21 09:00:26.642349 2026] [security2:error] [pid 559070:tid 559292] [client 20.151.10.161:55828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/a2.php"] [unique_id "al9fWiy1f1FtKC137xshYgAAAes"]
[Tue Jul 21 09:00:26.647104 2026] [security2:error] [pid 533360:tid 533567] [client 20.151.10.161:63394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/adminner.php"] [unique_id "al9fWnUPuLYrePtEkUdBGgAAAM8"]
[Tue Jul 21 09:00:26.772008 2026] [security2:error] [pid 559070:tid 559321] [client 20.220.225.223:30702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/cron-tab.php"] [unique_id "al9fWiy1f1FtKC137xshZgAAAgg"]
[Tue Jul 21 09:00:26.810535 2026] [security2:error] [pid 559070:tid 559236] [client 74.249.245.134:12875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/albin.php"] [unique_id "al9fWiy1f1FtKC137xshZwAAAbM"]
[Tue Jul 21 09:00:26.899874 2026] [security2:error] [pid 559070:tid 559320] [client 198.44.157.162:47328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9fWiy1f1FtKC137xshagAAAgc"]
[Tue Jul 21 09:00:26.899950 2026] [security2:error] [pid 559070:tid 559320] [client 198.44.157.162:47328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9fWiy1f1FtKC137xshagAAAgc"]
[Tue Jul 21 09:00:27.045016 2026] [security2:error] [pid 559070:tid 559326] [client 65.21.113.253:56994] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fWiy1f1FtKC137xshZAAAAg0"]
[Tue Jul 21 09:00:27.185411 2026] [security2:error] [pid 559070:tid 559207] [client 103.59.206.240:31024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fWyy1f1FtKC137xshcgAAAZY"]
[Tue Jul 21 09:00:27.188010 2026] [security2:error] [pid 559070:tid 559207] [client 103.59.206.240:31024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fWyy1f1FtKC137xshcgAAAZY"]
[Tue Jul 21 09:00:27.366244 2026] [security2:error] [pid 533360:tid 533525] [client 74.249.245.134:27179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/pomo.php"] [unique_id "al9fW3UPuLYrePtEkUdBIwAAAKU"]
[Tue Jul 21 09:00:27.372237 2026] [security2:error] [pid 533360:tid 533588] [client 114.119.148.102:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.imobiliariasobrado.com.br"] [uri "/index.php/imovel/sobrado-geminado-2-quartos-com-garagem-8927m2-venda-boehmerwald-joinville-sc-v28590"] [unique_id "al9fW3UPuLYrePtEkUdBJAAAAOQ"], referer: https://www.imobiliariasobrado.com.br/index.php/imovel/sobrado-geminado-2-quartos-com-garagem-8927m2-venda-boehmerwald-joinville-sc-v28590?opcao=V28590&cd_empresa=7
[Tue Jul 21 09:00:27.621474 2026] [security2:error] [pid 533360:tid 533455] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fW3UPuLYrePtEkUdBKQAAvFs"]
[Tue Jul 21 09:00:27.621645 2026] [security2:error] [pid 533360:tid 533548] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fW3UPuLYrePtEkUdBKQAAvFs"]
[Tue Jul 21 09:00:27.684160 2026] [security2:error] [pid 559070:tid 559247] [client 20.220.225.223:34220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wp-editor.php"] [unique_id "al9fWyy1f1FtKC137xsheQAAAb4"]
[Tue Jul 21 09:00:27.912371 2026] [security2:error] [pid 559070:tid 559226] [client 114.198.138.124:65149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fWyy1f1FtKC137xshegAAAak"]
[Tue Jul 21 09:00:27.912509 2026] [security2:error] [pid 559070:tid 559226] [client 114.198.138.124:65149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fWyy1f1FtKC137xshegAAAak"]
[Tue Jul 21 09:00:27.993512 2026] [security2:error] [pid 559070:tid 559282] [client 117.235.80.45:53992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.80.235.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fWyy1f1FtKC137xshfQAAAeE"]
[Tue Jul 21 09:00:27.993684 2026] [security2:error] [pid 559070:tid 559282] [client 117.235.80.45:53992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fWyy1f1FtKC137xshfQAAAeE"]
[Tue Jul 21 09:00:28.021532 2026] [security2:error] [pid 559070:tid 559223] [client 74.249.245.134:11973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/alfa.php"] [unique_id "al9fXCy1f1FtKC137xshfgAAAaY"]
[Tue Jul 21 09:00:28.062512 2026] [security2:error] [pid 559070:tid 559314] [client 20.220.225.223:34293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/cro.php"] [unique_id "al9fXCy1f1FtKC137xshgQAAAgE"]
[Tue Jul 21 09:00:28.148453 2026] [security2:error] [pid 559070:tid 559270] [client 74.249.245.134:27148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/test1.php"] [unique_id "al9fXCy1f1FtKC137xshggAAAdU"]
[Tue Jul 21 09:00:28.233206 2026] [security2:error] [pid 533360:tid 533543] [client 198.44.157.162:59950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9fXHUPuLYrePtEkUdBMwAAALc"]
[Tue Jul 21 09:00:28.233314 2026] [security2:error] [pid 533360:tid 533543] [client 198.44.157.162:59950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9fXHUPuLYrePtEkUdBMwAAALc"]
[Tue Jul 21 09:00:28.475383 2026] [security2:error] [pid 533360:tid 533572] [client 20.151.10.161:63451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/admin.php"] [unique_id "al9fXHUPuLYrePtEkUdBOAAAANQ"]
[Tue Jul 21 09:00:29.029354 2026] [security2:error] [pid 559070:tid 559212] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fXSy1f1FtKC137xshiwAAAZs"]
[Tue Jul 21 09:00:29.175686 2026] [autoindex:error] [pid 533360:tid 533562] [client 151.115.49.210:45814] AH01276: Cannot serve directory /home3/lianem44/ubaloc.store/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 09:00:29.320357 2026] [security2:error] [pid 533360:tid 533539] [client 74.249.245.134:27145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/fw.php"] [unique_id "al9fXXUPuLYrePtEkUdBTwAAALM"]
[Tue Jul 21 09:00:29.479438 2026] [security2:error] [pid 559070:tid 559237] [client 20.220.225.223:34476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/cron-tab.php"] [unique_id "al9fXSy1f1FtKC137xshjgAAAbQ"]
[Tue Jul 21 09:00:29.480831 2026] [security2:error] [pid 533360:tid 533554] [client 69.171.230.40:40780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fXXUPuLYrePtEkUdBVQAAAMI"]
[Tue Jul 21 09:00:29.506521 2026] [security2:error] [pid 559070:tid 559204] [client 20.220.225.223:34255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/akismet.php"] [unique_id "al9fXSy1f1FtKC137xshjwAAAZM"]
[Tue Jul 21 09:00:29.735626 2026] [security2:error] [pid 559070:tid 559280] [client 20.151.10.161:56232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/fpwch.php"] [unique_id "al9fXSy1f1FtKC137xshmgAAAd8"]
[Tue Jul 21 09:00:29.860180 2026] [security2:error] [pid 533360:tid 533524] [client 20.226.60.151:50384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/aaa.php"] [unique_id "al9fXXUPuLYrePtEkUdBXgAAAKQ"]
[Tue Jul 21 09:00:29.896513 2026] [security2:error] [pid 533360:tid 533606] [client 114.119.132.72:26559] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "startonesite.com.br"] [uri "/9613lnut14562_15wn76871363"] [unique_id "al9fXXUPuLYrePtEkUdBXwAAAPY"], referer: https://startonesite.com.br/9613lnut14562_15wn76871363
[Tue Jul 21 09:00:29.987796 2026] [security2:error] [pid 533360:tid 533564] [client 74.249.245.134:12908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/autoload_classmap.php"] [unique_id "al9fXXUPuLYrePtEkUdBYQAAAMw"]
[Tue Jul 21 09:00:30.015383 2026] [security2:error] [pid 559070:tid 559290] [client 20.151.10.161:64135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/k.php"] [unique_id "al9fXiy1f1FtKC137xshnQAAAek"]
[Tue Jul 21 09:00:30.098005 2026] [security2:error] [pid 533360:tid 533612] [client 20.220.225.223:34450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/koiy.php"] [unique_id "al9fXnUPuLYrePtEkUdBZgAAAPw"]
[Tue Jul 21 09:00:30.113951 2026] [security2:error] [pid 559070:tid 559254] [client 65.21.113.253:36732] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fXSy1f1FtKC137xshmQAAAcU"]
[Tue Jul 21 09:00:30.270690 2026] [security2:error] [pid 533360:tid 533602] [client 20.226.60.151:50404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/11.php"] [unique_id "al9fXnUPuLYrePtEkUdBaQAAAPI"]
[Tue Jul 21 09:00:30.370587 2026] [security2:error] [pid 559070:tid 559263] [client 74.249.245.134:27249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/fm.php"] [unique_id "al9fXiy1f1FtKC137xshpwAAAc4"]
[Tue Jul 21 09:00:30.388732 2026] [security2:error] [pid 559070:tid 559247] [client 20.226.60.151:62644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/mac.php"] [unique_id "al9fXiy1f1FtKC137xshqAAAAb4"]
[Tue Jul 21 09:00:30.454377 2026] [security2:error] [pid 559070:tid 559235] [client 20.226.60.151:50369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/chosen.php"] [unique_id "al9fXiy1f1FtKC137xshqgAAAbI"]
[Tue Jul 21 09:00:30.492272 2026] [security2:error] [pid 559070:tid 559276] [client 20.220.225.223:34703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/wp-Blogs.php"] [unique_id "al9fXiy1f1FtKC137xshqwAAAds"]
[Tue Jul 21 09:00:30.797526 2026] [security2:error] [pid 533360:tid 533533] [client 20.226.60.151:50406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/cream1.php"] [unique_id "al9fXnUPuLYrePtEkUdBcgAAAK0"]
[Tue Jul 21 09:00:30.805941 2026] [security2:error] [pid 559070:tid 559261] [client 117.214.78.59:60661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fXiy1f1FtKC137xshsgAAAcw"]
[Tue Jul 21 09:00:30.806076 2026] [security2:error] [pid 559070:tid 559261] [client 117.214.78.59:60661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fXiy1f1FtKC137xshsgAAAcw"]
[Tue Jul 21 09:00:30.807202 2026] [security2:error] [pid 533360:tid 533572] [client 20.220.225.223:34266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/ace2.php"] [unique_id "al9fXnUPuLYrePtEkUdBcwAAANQ"]
[Tue Jul 21 09:00:30.953237 2026] [security2:error] [pid 559070:tid 559322] [client 20.151.10.161:64148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/x.php"] [unique_id "al9fXiy1f1FtKC137xshtgAAAgk"]
[Tue Jul 21 09:00:31.065719 2026] [security2:error] [pid 533360:tid 533592] [client 198.44.157.162:59954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9fX3UPuLYrePtEkUdBdgAAAOg"]
[Tue Jul 21 09:00:31.065792 2026] [security2:error] [pid 533360:tid 533592] [client 198.44.157.162:59954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "virevahealth.online"] [uri "/xmlrpc.php"] [unique_id "al9fX3UPuLYrePtEkUdBdgAAAOg"]
[Tue Jul 21 09:00:31.577200 2026] [security2:error] [pid 559070:tid 559318] [client 74.249.245.134:27264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/ini.php"] [unique_id "al9fXyy1f1FtKC137xshvAAAAgU"]
[Tue Jul 21 09:00:31.577703 2026] [security2:error] [pid 533360:tid 533609] [client 20.151.10.161:56214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/w2025.php"] [unique_id "al9fX3UPuLYrePtEkUdBgQAAAPk"]
[Tue Jul 21 09:00:31.690809 2026] [security2:error] [pid 533360:tid 533553] [client 20.151.10.161:63397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/wss.php"] [unique_id "al9fX3UPuLYrePtEkUdBhgAAAME"]
[Tue Jul 21 09:00:31.944033 2026] [security2:error] [pid 533360:tid 533518] [client 74.249.245.134:12801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/av.php"] [unique_id "al9fX3UPuLYrePtEkUdBiwAAAJ4"]
[Tue Jul 21 09:00:32.142875 2026] [security2:error] [pid 533360:tid 533538] [client 20.151.10.161:55869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/file15.php"] [unique_id "al9fYHUPuLYrePtEkUdBkgAAALI"]
[Tue Jul 21 09:00:32.291729 2026] [security2:error] [pid 533360:tid 533588] [client 20.220.225.223:34263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/ms.php"] [unique_id "al9fYHUPuLYrePtEkUdBlQAAAOQ"]
[Tue Jul 21 09:00:32.464950 2026] [security2:error] [pid 559070:tid 559201] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fYCy1f1FtKC137xshyQAAAZA"]
[Tue Jul 21 09:00:32.678018 2026] [security2:error] [pid 559070:tid 559240] [client 114.119.128.20:39871] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oticapersona.com.br"] [uri "/produto/oculos-carrera-av90/"] [unique_id "al9fYCy1f1FtKC137xshywAAAbc"], referer: https://oticapersona.com.br/produto/oculos-carrera-av90
[Tue Jul 21 09:00:32.724114 2026] [security2:error] [pid 533360:tid 533549] [client 74.249.245.134:27300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/themes.php"] [unique_id "al9fYHUPuLYrePtEkUdBnwAAAL0"]
[Tue Jul 21 09:00:32.755681 2026] [security2:error] [pid 533360:tid 533610] [client 41.89.234.2:52402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fYHUPuLYrePtEkUdBowAAAPo"]
[Tue Jul 21 09:00:32.755916 2026] [security2:error] [pid 533360:tid 533610] [client 41.89.234.2:52402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fYHUPuLYrePtEkUdBowAAAPo"]
[Tue Jul 21 09:00:32.766678 2026] [security2:error] [pid 533360:tid 533535] [client 20.151.10.161:62925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/ty.php"] [unique_id "al9fYHUPuLYrePtEkUdBpAAAAK8"]
[Tue Jul 21 09:00:32.790149 2026] [security2:error] [pid 533360:tid 533612] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fYHUPuLYrePtEkUdBmgAA_Ag"]
[Tue Jul 21 09:00:32.992922 2026] [security2:error] [pid 533360:tid 533543] [client 20.226.60.151:62600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/dr.php"] [unique_id "al9fYHUPuLYrePtEkUdBpgAAALc"]
[Tue Jul 21 09:00:33.394208 2026] [security2:error] [pid 559070:tid 559283] [client 74.249.245.134:27304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/dropdown.php"] [unique_id "al9fYSy1f1FtKC137xsiBAAAAeI"]
[Tue Jul 21 09:00:33.469940 2026] [security2:error] [pid 559070:tid 559301] [client 74.249.245.134:43670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/gg.php"] [unique_id "al9fYSy1f1FtKC137xsiDgAAAfQ"]
[Tue Jul 21 09:00:33.611608 2026] [security2:error] [pid 533360:tid 533529] [client 65.21.113.253:36740] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fYXUPuLYrePtEkUdBqgAAAKk"]
[Tue Jul 21 09:00:33.664008 2026] [security2:error] [pid 533360:tid 533546] [client 113.22.144.139:52891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fYXUPuLYrePtEkUdBtAAAALo"]
[Tue Jul 21 09:00:33.664978 2026] [security2:error] [pid 533360:tid 533546] [client 113.22.144.139:52891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fYXUPuLYrePtEkUdBtAAAALo"]
[Tue Jul 21 09:00:33.791607 2026] [security2:error] [pid 559070:tid 559206] [client 20.151.10.161:63475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/155.php"] [unique_id "al9fYSy1f1FtKC137xsiSAAAAZU"]
[Tue Jul 21 09:00:33.811708 2026] [security2:error] [pid 559070:tid 559244] [client 20.220.225.223:34178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/hp2.php"] [unique_id "al9fYSy1f1FtKC137xsiSwAAAbs"]
[Tue Jul 21 09:00:33.966431 2026] [security2:error] [pid 559070:tid 559203] [client 20.220.225.223:30683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/koiy.php"] [unique_id "al9fYSy1f1FtKC137xsiUAAAAZI"]
[Tue Jul 21 09:00:34.074464 2026] [security2:error] [pid 559070:tid 559157] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fYiy1f1FtKC137xsiYQACDlY"]
[Tue Jul 21 09:00:34.074647 2026] [security2:error] [pid 559070:tid 559327] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fYiy1f1FtKC137xsiYQACDlY"]
[Tue Jul 21 09:00:34.285426 2026] [security2:error] [pid 533360:tid 533497] [client 74.249.245.134:27244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/wp-links.php"] [unique_id "al9fYnUPuLYrePtEkUdBxAAAAIk"]
[Tue Jul 21 09:00:34.346474 2026] [security2:error] [pid 559070:tid 559272] [client 20.226.60.151:62635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/x.php"] [unique_id "al9fYiy1f1FtKC137xsiZgAAAdc"]
[Tue Jul 21 09:00:34.401545 2026] [security2:error] [pid 559070:tid 559207] [client 20.151.10.161:51010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/jp.php"] [unique_id "al9fYiy1f1FtKC137xsibAAAAZY"]
[Tue Jul 21 09:00:34.439114 2026] [security2:error] [pid 533360:tid 533611] [client 182.189.99.211:48040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fYnUPuLYrePtEkUdBxwAAAPs"]
[Tue Jul 21 09:00:34.439484 2026] [security2:error] [pid 533360:tid 533611] [client 182.189.99.211:48040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fYnUPuLYrePtEkUdBxwAAAPs"]
[Tue Jul 21 09:00:34.496371 2026] [security2:error] [pid 533360:tid 533538] [client 20.151.10.161:64176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/ops.php"] [unique_id "al9fYnUPuLYrePtEkUdByAAAALI"]
[Tue Jul 21 09:00:34.501366 2026] [security2:error] [pid 559070:tid 559202] [client 20.10.88.227:0] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/index.php"] [unique_id "al9fYiy1f1FtKC137xsibQAAAZE"]
[Tue Jul 21 09:00:34.502214 2026] [security2:error] [pid 559070:tid 559275] [client 20.10.88.227:49222] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "solarisimplementos.com"] [uri "/robots.txt"] [unique_id "al9fYiy1f1FtKC137xsiaAAAAdo"]
[Tue Jul 21 09:00:34.642930 2026] [security2:error] [pid 533360:tid 533465] [remote 216.73.216.184:3637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapd.xml"] [unique_id "al9fYnUPuLYrePtEkUdBywAAjWU"]
[Tue Jul 21 09:00:34.660112 2026] [security2:error] [pid 533360:tid 533523] [client 20.220.225.223:20923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/wp-css.php"] [unique_id "al9fYnUPuLYrePtEkUdBzAAAAKM"]
[Tue Jul 21 09:00:34.745777 2026] [security2:error] [pid 559070:tid 559309] [client 168.167.81.163:59658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9fYiy1f1FtKC137xsidQAAAfw"]
[Tue Jul 21 09:00:34.745931 2026] [security2:error] [pid 559070:tid 559309] [client 168.167.81.163:59658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9fYiy1f1FtKC137xsidQAAAfw"]
[Tue Jul 21 09:00:34.907238 2026] [security2:error] [pid 533360:tid 533524] [client 198.44.157.162:59970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9fYnUPuLYrePtEkUdB1gAAAKQ"]
[Tue Jul 21 09:00:34.907318 2026] [security2:error] [pid 533360:tid 533524] [client 198.44.157.162:59970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rushoffers.store"] [uri "/xmlrpc.php"] [unique_id "al9fYnUPuLYrePtEkUdB1gAAAKQ"]
[Tue Jul 21 09:00:34.931390 2026] [security2:error] [pid 559070:tid 559250] [client 59.95.197.55:50122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fYiy1f1FtKC137xsiegAAAcE"]
[Tue Jul 21 09:00:34.931479 2026] [security2:error] [pid 559070:tid 559250] [client 59.95.197.55:50122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fYiy1f1FtKC137xsiegAAAcE"]
[Tue Jul 21 09:00:35.028854 2026] [security2:error] [pid 533360:tid 533535] [client 69.171.230.23:35858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fY3UPuLYrePtEkUdB1wAAAK8"]
[Tue Jul 21 09:00:35.053166 2026] [security2:error] [pid 559070:tid 559316] [client 20.226.60.151:62062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/155.php"] [unique_id "al9fYyy1f1FtKC137xsiewAAAgM"]
[Tue Jul 21 09:00:35.061024 2026] [security2:error] [pid 533360:tid 533540] [client 74.249.245.134:27322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/xmrlpc.php"] [unique_id "al9fY3UPuLYrePtEkUdB2wAAALQ"]
[Tue Jul 21 09:00:35.221600 2026] [security2:error] [pid 533360:tid 533443] [remote 216.73.216.184:3637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemapd.xml"] [unique_id "al9fY3UPuLYrePtEkUdB3wAAhk8"]
[Tue Jul 21 09:00:35.396764 2026] [security2:error] [pid 533360:tid 533534] [client 20.220.225.223:34467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/hp3.php"] [unique_id "al9fY3UPuLYrePtEkUdB5wAAAK4"]
[Tue Jul 21 09:00:35.407843 2026] [security2:error] [pid 559070:tid 559221] [client 20.151.10.161:64189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/ingfo.php"] [unique_id "al9fYyy1f1FtKC137xsigAAAAaQ"]
[Tue Jul 21 09:00:35.463038 2026] [security2:error] [pid 533360:tid 533582] [client 20.226.60.151:50375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/ops.php"] [unique_id "al9fY3UPuLYrePtEkUdB6QAAAN4"]
[Tue Jul 21 09:00:35.564107 2026] [security2:error] [pid 559070:tid 559104] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fYyy1f1FtKC137xsihgABuiE"]
[Tue Jul 21 09:00:35.564299 2026] [security2:error] [pid 559070:tid 559243] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fYyy1f1FtKC137xsihgABuiE"]
[Tue Jul 21 09:00:35.582550 2026] [security2:error] [pid 559070:tid 559091] [remote 65.111.29.226:65033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.29.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9fYyy1f1FtKC137xsigQAB1RQ"]
[Tue Jul 21 09:00:35.634849 2026] [security2:error] [pid 559070:tid 559245] [client 198.44.157.162:59976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9fYyy1f1FtKC137xsiiAAAAbw"]
[Tue Jul 21 09:00:35.634968 2026] [security2:error] [pid 559070:tid 559245] [client 198.44.157.162:59976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "senhordostelhados.site"] [uri "/xmlrpc.php"] [unique_id "al9fYyy1f1FtKC137xsiiAAAAbw"]
[Tue Jul 21 09:00:35.686430 2026] [security2:error] [pid 559070:tid 559222] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fYyy1f1FtKC137xsiiQAAAaU"]
[Tue Jul 21 09:00:35.911964 2026] [security2:error] [pid 559070:tid 559210] [client 115.245.198.210:11073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fYyy1f1FtKC137xsiigAAAZk"]
[Tue Jul 21 09:00:35.912051 2026] [security2:error] [pid 559070:tid 559210] [client 115.245.198.210:11073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fYyy1f1FtKC137xsiigAAAZk"]
[Tue Jul 21 09:00:36.003569 2026] [security2:error] [pid 559070:tid 559325] [client 114.119.142.72:62991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.rtdi.com.br"] [uri "/imoveis/para-alugar"] [unique_id "al9fZCy1f1FtKC137xsijAAAAgw"], referer: https://www.rtdi.com.br/imoveis/para-alugar?suites=4%2B
[Tue Jul 21 09:00:36.023749 2026] [security2:error] [pid 533360:tid 533575] [client 20.151.10.161:64240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/error_log.php"] [unique_id "al9fZHUPuLYrePtEkUdB-QAAANc"]
[Tue Jul 21 09:00:36.047312 2026] [security2:error] [pid 533360:tid 533539] [client 74.249.245.134:16761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/sql.php"] [unique_id "al9fZHUPuLYrePtEkUdB-gAAALM"]
[Tue Jul 21 09:00:36.060638 2026] [security2:error] [pid 559070:tid 559244] [client 20.10.88.227:3523] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "animale-me-ca.shop-officialstore.com"] [uri "/index.php"] [unique_id "al9fZCy1f1FtKC137xsijQAAAbs"]
[Tue Jul 21 09:00:36.111413 2026] [security2:error] [pid 559070:tid 559259] [client 139.167.208.211:61314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.208.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fZCy1f1FtKC137xsijgAAAco"]
[Tue Jul 21 09:00:36.111523 2026] [security2:error] [pid 559070:tid 559259] [client 139.167.208.211:61314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fZCy1f1FtKC137xsijgAAAco"]
[Tue Jul 21 09:00:36.180418 2026] [security2:error] [pid 559070:tid 559204] [client 154.182.128.22:56672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.128.182.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fZCy1f1FtKC137xsikAAAAZM"]
[Tue Jul 21 09:00:36.180534 2026] [security2:error] [pid 559070:tid 559204] [client 154.182.128.22:56672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fZCy1f1FtKC137xsikAAAAZM"]
[Tue Jul 21 09:00:36.517274 2026] [security2:error] [pid 533360:tid 533412] [remote 173.252.82.49:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.82.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gfacil.com.br"] [uri "/index.php"] [unique_id "al9fZHUPuLYrePtEkUdB_gAA3TA"]
[Tue Jul 21 09:00:36.541284 2026] [security2:error] [pid 559070:tid 559284] [client 20.226.60.151:62049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/file31.php"] [unique_id "al9fZCy1f1FtKC137xsimQAAAeM"]
[Tue Jul 21 09:00:36.765374 2026] [security2:error] [pid 533360:tid 533497] [client 65.21.113.253:36752] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fZHUPuLYrePtEkUdB_wAAAIk"]
[Tue Jul 21 09:00:36.940011 2026] [security2:error] [pid 533360:tid 533533] [client 114.119.148.60:63689] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jandel.com.br"] [uri "/ldwy6t6/symbolism-in-the-narrative-of-the-life-of-frederick-douglass"] [unique_id "al9fZHUPuLYrePtEkUdCCgAAAK0"], referer: https://jandel.com.br/ldwy6t6/symbolism-in-the-narrative-of-the-life-of-frederick-douglass
[Tue Jul 21 09:00:36.982523 2026] [security2:error] [pid 559070:tid 559266] [client 74.249.245.134:27298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/htaccess.php"] [unique_id "al9fZCy1f1FtKC137xsipwAAAdE"]
[Tue Jul 21 09:00:37.519361 2026] [security2:error] [pid 559070:tid 559307] [client 20.226.60.151:62603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/file6.php"] [unique_id "al9fZSy1f1FtKC137xsi2QAAAfo"]
[Tue Jul 21 09:00:37.647890 2026] [proxy:error] [pid 533360:tid 533392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:37.647943 2026] [proxy_http:error] [pid 533360:tid 533392] [remote 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:37.648837 2026] [security2:error] [pid 559070:tid 559223] [client 20.151.10.161:64236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/ok.php"] [unique_id "al9fZSy1f1FtKC137xsi2wAAAaY"]
[Tue Jul 21 09:00:37.648857 2026] [proxy:error] [pid 533360:tid 533392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:37.648887 2026] [proxy_http:error] [pid 533360:tid 533392] [remote 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:37.844141 2026] [proxy:error] [pid 533360:tid 533473] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:37.844240 2026] [proxy_http:error] [pid 533360:tid 533473] [remote 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:37.845505 2026] [proxy:error] [pid 533360:tid 533473] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:37.845543 2026] [proxy_http:error] [pid 533360:tid 533473] [remote 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:37.987760 2026] [security2:error] [pid 559070:tid 559311] [client 114.198.138.124:49390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fZSy1f1FtKC137xsi5QAAAf4"]
[Tue Jul 21 09:00:37.987875 2026] [security2:error] [pid 559070:tid 559311] [client 114.198.138.124:49390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fZSy1f1FtKC137xsi5QAAAf4"]
[Tue Jul 21 09:00:38.004550 2026] [security2:error] [pid 533360:tid 533515] [client 20.151.10.161:55871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/f35.php"] [unique_id "al9fZnUPuLYrePtEkUdCHwAAAJs"]
[Tue Jul 21 09:00:38.008073 2026] [security2:error] [pid 533360:tid 533493] [client 20.52.136.55:1556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/info.php"] [unique_id "al9fZnUPuLYrePtEkUdCIAAAAIU"]
[Tue Jul 21 09:00:38.054257 2026] [security2:error] [pid 559070:tid 559228] [client 20.10.88.236:5831] ModSecurity: Warning. Matched phrase "Claritybot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gnxinox.com.br"] [uri "/index.php"] [unique_id "al9fZSy1f1FtKC137xsi5AAAAas"]
[Tue Jul 21 09:00:38.138045 2026] [security2:error] [pid 559070:tid 559209] [client 20.151.10.161:63487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/mac.php"] [unique_id "al9fZiy1f1FtKC137xsi7AAAAZg"]
[Tue Jul 21 09:00:38.141554 2026] [security2:error] [pid 559070:tid 559117] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fZiy1f1FtKC137xsi7gAB1S4"]
[Tue Jul 21 09:00:38.141676 2026] [security2:error] [pid 559070:tid 559270] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fZiy1f1FtKC137xsi7gAB1S4"]
[Tue Jul 21 09:00:38.236730 2026] [security2:error] [pid 533360:tid 533459] [remote 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.shopmelhorcompraonline.com"] [uri "/xmlrpc.php"] [unique_id "al9fZnUPuLYrePtEkUdCIgAArl8"]
[Tue Jul 21 09:00:38.238727 2026] [security2:error] [pid 533360:tid 533461] [remote 216.73.216.184:3637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemape.xml"] [unique_id "al9fZnUPuLYrePtEkUdCIwAAumE"]
[Tue Jul 21 09:00:38.286644 2026] [security2:error] [pid 559070:tid 559295] [client 74.249.245.134:27252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/readme.php"] [unique_id "al9fZiy1f1FtKC137xsi8AAAAe4"]
[Tue Jul 21 09:00:38.387325 2026] [security2:error] [pid 533360:tid 533572] [client 20.151.10.161:56192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/scxy.php"] [unique_id "al9fZnUPuLYrePtEkUdCJwAAANQ"]
[Tue Jul 21 09:00:38.430969 2026] [security2:error] [pid 559070:tid 559278] [client 74.7.228.61:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "henriqueelegeda1743448307081.0711679.myhostgator.site"] [uri "/robots.txt"] [unique_id "al9fZiy1f1FtKC137xsi8wAB3UE"]
[Tue Jul 21 09:00:38.597097 2026] [security2:error] [pid 559070:tid 559245] [client 117.235.80.45:54282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.80.235.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fZiy1f1FtKC137xsi_QAAAbw"]
[Tue Jul 21 09:00:38.597201 2026] [security2:error] [pid 559070:tid 559245] [client 117.235.80.45:54282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fZiy1f1FtKC137xsi_QAAAbw"]
[Tue Jul 21 09:00:38.630719 2026] [security2:error] [pid 533360:tid 533426] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.shopmelhorcompraonline.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al9fZnUPuLYrePtEkUdCKgABAj4"]
[Tue Jul 21 09:00:38.699098 2026] [security2:error] [pid 559070:tid 559290] [client 20.151.10.161:64234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/wefile.php"] [unique_id "al9fZiy1f1FtKC137xsjAAAAAek"]
[Tue Jul 21 09:00:38.788928 2026] [security2:error] [pid 559070:tid 559313] [client 103.59.206.240:31376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fZiy1f1FtKC137xsjAgAAAgA"]
[Tue Jul 21 09:00:38.789050 2026] [security2:error] [pid 559070:tid 559313] [client 103.59.206.240:31376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fZiy1f1FtKC137xsjAgAAAgA"]
[Tue Jul 21 09:00:38.860716 2026] [security2:error] [pid 559070:tid 559316] [client 65.21.113.253:35814] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fZiy1f1FtKC137xsjBgAAAgM"]
[Tue Jul 21 09:00:38.942901 2026] [security2:error] [pid 533360:tid 533414] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.shopmelhorcompraonline.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al9fZnUPuLYrePtEkUdCMQAA_jI"]
[Tue Jul 21 09:00:39.044577 2026] [security2:error] [pid 533360:tid 533554] [client 74.249.245.134:43660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/up.php"] [unique_id "al9fZ3UPuLYrePtEkUdCNAAAAMI"]
[Tue Jul 21 09:00:39.207679 2026] [security2:error] [pid 533360:tid 533576] [client 20.151.10.161:63458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9fZ3UPuLYrePtEkUdCNgAAANg"]
[Tue Jul 21 09:00:39.282348 2026] [security2:error] [pid 559070:tid 559242] [client 20.220.225.223:20866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/wp-explorer.php"] [unique_id "al9fZyy1f1FtKC137xsjCgAAAbk"]
[Tue Jul 21 09:00:39.310918 2026] [security2:error] [pid 533360:tid 533399] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.shopmelhorcompraonline.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al9fZ3UPuLYrePtEkUdCOgAAuCM"]
[Tue Jul 21 09:00:39.318081 2026] [security2:error] [pid 559070:tid 559221] [client 20.226.60.151:50400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/adminfuns.php"] [unique_id "al9fZyy1f1FtKC137xsjDgAAAaQ"]
[Tue Jul 21 09:00:39.588443 2026] [security2:error] [pid 559070:tid 559259] [client 20.220.225.223:34446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/aa1.php"] [unique_id "al9fZyy1f1FtKC137xsjFQAAAco"]
[Tue Jul 21 09:00:39.647901 2026] [security2:error] [pid 533360:tid 533460] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.shopmelhorcompraonline.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al9fZ3UPuLYrePtEkUdCQQAAx2A"]
[Tue Jul 21 09:00:39.846531 2026] [security2:error] [pid 533360:tid 533383] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.shopmelhorcompraonline.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al9fZ3UPuLYrePtEkUdCRAAAjBM"]
[Tue Jul 21 09:00:39.900237 2026] [security2:error] [pid 559070:tid 559223] [client 65.21.113.253:56464] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fZyy1f1FtKC137xsjEwAAAaY"]
[Tue Jul 21 09:00:39.937260 2026] [security2:error] [pid 559070:tid 559237] [client 20.151.10.161:63430] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.madmoholding.com.br"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al9fZyy1f1FtKC137xsjGwAAAbQ"]
[Tue Jul 21 09:00:39.962250 2026] [security2:error] [pid 533360:tid 533610] [client 20.151.10.161:56208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/FWAZ.php"] [unique_id "al9fZ3UPuLYrePtEkUdCRwAAAPo"]
[Tue Jul 21 09:00:40.075270 2026] [security2:error] [pid 533360:tid 533487] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.shopmelhorcompraonline.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al9faHUPuLYrePtEkUdCTQAA9Xs"]
[Tue Jul 21 09:00:40.086349 2026] [security2:error] [pid 559070:tid 559312] [client 185.213.175.37:35408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "buffetadomiciliojundiai.com.br"] [uri "/.env.backup"] [unique_id "al9faCy1f1FtKC137xsjHwAAAf8"]
[Tue Jul 21 09:00:40.238401 2026] [security2:error] [pid 559070:tid 559256] [client 114.119.136.64:20061] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.vivaconcierge.com.br"] [uri "/property/casa-hermenegildo/"] [unique_id "al9faCy1f1FtKC137xsjIAAAAcc"], referer: https://www.vivaconcierge.com.br/property/casa-hermenegildo/
[Tue Jul 21 09:00:40.271640 2026] [security2:error] [pid 533360:tid 533441] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.shopmelhorcompraonline.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al9faHUPuLYrePtEkUdCUwAAv00"]
[Tue Jul 21 09:00:40.321571 2026] [security2:error] [pid 559070:tid 559287] [client 20.220.225.223:30868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/hp2.php"] [unique_id "al9faCy1f1FtKC137xsjIgAAAeY"]
[Tue Jul 21 09:00:40.371358 2026] [security2:error] [pid 559070:tid 559201] [client 20.151.10.161:64231] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.madmoholding.com.br"] [uri "/wp-admin/js/"] [unique_id "al9faCy1f1FtKC137xsjIwAAAZA"]
[Tue Jul 21 09:00:40.557374 2026] [security2:error] [pid 533360:tid 533467] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.shopmelhorcompraonline.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al9faHUPuLYrePtEkUdCVQAAm2c"]
[Tue Jul 21 09:00:40.564643 2026] [mpm_event:notice] [pid 131539:tid 131539] AH00493: SIGUSR1 received.  Doing graceful restart
[Tue Jul 21 09:00:40.656428 2026] [security2:error] [pid 559070:tid 559202] [client 185.213.175.37:32058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "budhug.com.br"] [uri "/.env.backup"] [unique_id "al9faCy1f1FtKC137xsjKQAAAZE"]
[Tue Jul 21 09:00:40.879515 2026] [security2:error] [pid 559070:tid 559265] [client 114.119.143.58:61205] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gfacil.com.br"] [uri "/201-6156108/oficina-da-moda-intima/detalhe.html"] [unique_id "al9faCy1f1FtKC137xsjKgAAAdA"], referer: https://www.pages24.com.br/rio-de-janeiro-rj/1237229-malu-moda-intima
[Tue Jul 21 09:00:41.770046 2026] [:notice] [pid 465548:tid 465548] [host root@br1102.hostgator.com.br] mod_lsapi:  Selfstarter 465548 stopped
[Tue Jul 21 09:00:44.311670 2026] [log_config:warn] [pid 559070:tid 559162] (32)Broken pipe: [remote 57.141.18.115:25732] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 09:00:44.311689 2026] [log_config:warn] [pid 559070:tid 559162] (32)Broken pipe: [remote 57.141.18.115:25732] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 09:00:44.320524 2026] [log_config:warn] [pid 559070:tid 559077] (32)Broken pipe: [remote 57.141.18.70:65124] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 09:00:44.320545 2026] [log_config:warn] [pid 559070:tid 559077] (32)Broken pipe: [remote 57.141.18.70:65124] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 09:00:44.341932 2026] [log_config:warn] [pid 533360:tid 533423] (32)Broken pipe: [remote 57.141.18.37:25032] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 09:00:44.341954 2026] [log_config:warn] [pid 533360:tid 533423] (32)Broken pipe: [remote 57.141.18.37:25032] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 09:00:44.344204 2026] [log_config:warn] [pid 533360:tid 533364] (32)Broken pipe: [remote 57.141.18.85:61432] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 09:00:44.344220 2026] [log_config:warn] [pid 533360:tid 533364] (32)Broken pipe: [remote 57.141.18.85:61432] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 09:00:44.351956 2026] [lsapi:notice] [pid 131539:tid 131539] mod_lsapi:  version 1.1-92
[Tue Jul 21 09:00:44.364070 2026] [:notice] [pid 575406:tid 575406] [host root@br1102.hostgator.com.br] mod_lsapi:  Selfstarter 575406 started
[Tue Jul 21 09:00:44.380729 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oppbrazil.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.382465 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: locadoracmd.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.388120 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbc.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.400131 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbr.com.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.413367 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: metodoatracaoconsciente.com.vanderleiasilva.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.415909 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sofiagheller1782846626000.argentajoias.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.416302 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sofiagheller1782846537000.argentajoias.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.421686 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: getveltrixhealth.com.shopmelhorcompraonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.423627 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: adloop.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.424148 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: contafic.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.424651 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: climadek.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.425018 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lojacasacosta.com.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.425521 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: voztricolor.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.425903 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arenaalphaville.com.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.426260 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rioclaroimovel.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.426616 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marketingderua.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.427148 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tabelionatoportoalegre.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.427647 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: learningsociety.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.427995 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: clubmarketplace.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.428482 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arenaalphaville.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.428857 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: app.itqmogiguacu.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.429248 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lp.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.429761 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.430246 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.meupsiquiatraonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.430596 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: empresas.meuendocrinoonline.com.br.serri.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.430983 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: dizi.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.431723 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rdgoseguros.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.432117 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: diziseguros.segurosrd.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.436951 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rilicitacoes.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.437423 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rilicitacoes.com.br.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.437938 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: espaconeuroascensao.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.438440 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: espaconeuroascensao.com.br.raphaelicarolicitacoes.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.441831 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sscoenper.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.442185 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ssvistorias.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.442515 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rastreamentobh.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.443012 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: locamotobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.443357 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: companhiatop.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.443909 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: acheservicos.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.444248 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aluguelmotobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.444579 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aluguelcarrobh.com.br.programasalvador.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.450699 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: patihipopressivo.com.patyhipopressivo.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.451076 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: patihipopressivo.com.br.patyhipopressivo.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.452504 2026] [log_config:warn] [pid 559070:tid 559072] (32)Broken pipe: [remote 57.141.18.30:60346] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 09:00:44.452519 2026] [log_config:warn] [pid 559070:tid 559072] (32)Broken pipe: [remote 57.141.18.30:60346] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 09:00:44.454808 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyer.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.455300 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyerapp.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.455669 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.456006 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vespnutricao.com.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.456502 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.com.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.456873 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nyersuplementos.com.br.nyerb2b.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.469876 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lojinhadoprofessor.lojinhadaprofessora.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.474355 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: leonardodossantoshen1782739753000.metropollitano.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.476521 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: unoperformancedigital.com.br.karenvieiramarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.477045 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jbms.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.477406 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: benti.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.477745 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: yuribenassi.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.478085 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: wbapoiocontabil.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.478418 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: movimenti.com.br.juliobenassi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.487405 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sigescala.com.sigescala.meusitehostgator.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.506617 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vivenciarempauta.vivenciarempauta.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.515239 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: 3d-surgery.3d-surgery.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.515913 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vivafinanceiras.com.br.vivafinanceira.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.523093 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: academycont.com.goldentrips40.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.527321 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: trendsol.com.br.fusoesaquisicoes.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.530879 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: libertysolutions.figempreendimentos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.534392 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: naturofarma.com.br.farmaciafarmula.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.535276 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: farmacianaturofarma.com.br.farmaciafarmula.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.536865 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: meuamordevoltaa.estriasnuncamaiss.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.538501 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atividadessprontas.online.estriasnuncamaiss.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.544184 2026] [log_config:warn] [pid 533360:tid 533428] (32)Broken pipe: [remote 57.141.18.111:28566] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 09:00:44.544201 2026] [log_config:warn] [pid 533360:tid 533428] (32)Broken pipe: [remote 57.141.18.111:28566] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 09:00:44.547770 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: esidiomass.com.br.eslanguageschool.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.548276 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: porondeeuestive.com.br.eslanguageschool.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.562685 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: deniltoncostasilva1748033966000.samanenergia.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.569141 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: santotchay.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.569740 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: santotchay.com.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.570597 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: osantotchay.com.br.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.571406 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oinglesdescomplicado.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.571998 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: brasilmotoeletrica.com.cursosnovaestetica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.584027 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: thenexbr.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.604561 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: c5liberdades.store.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.604969 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtoswendell.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.605453 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtosnapromo.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.606416 2026] [log_config:warn] [pid 559070:tid 559168] (32)Broken pipe: [remote 57.141.18.9:51412] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 09:00:44.606430 2026] [log_config:warn] [pid 559070:tid 559168] (32)Broken pipe: [remote 57.141.18.9:51412] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 09:00:44.606938 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: c5liberdades.com.br.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.615831 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtosnapromo.com.br.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.621401 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: weddinglarissaefelipe.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.624137 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: produtoswendellcarvalho.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.625168 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: exclusivepromotiontoday.com.conteudoos.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.631073 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pandie.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.631418 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guarushop.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.631783 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guarushop2.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.632150 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olhobionico.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.632486 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pandoradango.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.632854 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guiadeoferta.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.633194 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fofoqueironews.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.633527 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: reidocouro.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.633908 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bloquetebrasil.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.634269 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: protetordegraxa.com.br.olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.637720 2026] [log_config:warn] [pid 559070:tid 559084] (32)Broken pipe: [remote 57.141.18.48:51146] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 09:00:44.637733 2026] [log_config:warn] [pid 559070:tid 559084] (32)Broken pipe: [remote 57.141.18.48:51146] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 09:00:44.637901 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atom-growth.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.638420 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atom-growth.com.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.638953 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: confiancedigital.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.639308 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: buddyclub.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.639778 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gotavitaoriginal.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.640268 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: motoboyjaguariuna.com.br.chefdozzz.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.641121 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jandiraemdestaque.com.br.jornaldagrandesp.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.658277 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: accjbc.com.bcaccj.org:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.663952 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.665593 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sociooculto.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.666244 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: exnova.tech.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.667206 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.store.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.667548 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marlonbarreto.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.667893 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fit4me.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.668225 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atilafagundes.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.668552 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: suaconsulta.fun.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.669520 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: escolhasaudavel.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.670184 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinicius-schneider.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.670642 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sociooculto.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.670989 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olimposolar.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.671335 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nextfitjourney.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.671834 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: themaisonhommes.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.672165 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tamojuntomidias.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.672503 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gustvoferraritrader.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.672864 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marlonbarreto.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.673213 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: escolhasaudavel.shop.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.673565 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: atilafagundes.online.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.673905 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinicius-schneider.com.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.674381 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mariabonfim1762105378000.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.674724 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gustvoferraritrader.com.br.automatizeacademy.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.675900 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: flowwshop.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.676405 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agmiz.com.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.676904 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: comecx.online.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.677252 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: flowwshop.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.678240 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blog.findcomp.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.678746 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: importeicomponentes.com.br.agmiz.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.682483 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aede.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.682988 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: suora.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.683478 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: condmidia.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.683987 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: recowmenda.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.684444 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: valeuefalou.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.685030 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: trilhasdafe.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.685580 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bergsantana.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.686089 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: shyoftherock.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.686558 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pegueaestrada.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.687039 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nocaminhodafe.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.687497 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: arielson.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.687812 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: amareloturquesa.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.688149 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: terraluna.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.688480 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: zooparquevet.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.688791 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: nosnaestrada.com.br.arielsonmelo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.693851 2026] [log_config:warn] [pid 559070:tid 559128] (32)Broken pipe: [remote 57.141.18.27:23742] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 09:00:44.693861 2026] [log_config:warn] [pid 559070:tid 559128] (32)Broken pipe: [remote 57.141.18.27:23742] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 09:00:44.805746 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fusoesaquisicoes.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.837883 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conairmfg.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.842526 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: olhobionico.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.873994 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: revistareflexopolitico.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.874865 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ethanslowell.com.infoalert.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.876937 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: evolvaa.online.evolia.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.879121 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: bracks.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.883820 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: raimundol.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.887173 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conhecaonordeste.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.887523 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: overkotz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.887887 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lucaskotovicz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.888254 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: kotovicz.onfieldcomunicacao.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.891406 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agendazap.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.892667 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ebookswl.com.wendelleite.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.894723 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: empacta.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.895721 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: inovaeditorial.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.896379 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: volyoaudiobooks.com.volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.899905 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: slapingles.com.teacheraleff.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.900217 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: speakinglikeapro.teacheraleff.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.900547 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: brasilcertdigital.tavarescont.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.904100 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: wenith.com.br.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.904636 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783665345000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.905206 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783664968000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.905759 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783664932000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.906164 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: taliafernandavidi1783569474000.wenith.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.912515 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: solarisimplementos.com.solarisimplementos.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.914730 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: madmoholding.saojorgesiderurgia.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.918694 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: evolvaa.com.evolia.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.920761 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sulmov.com.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.921111 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: expovilhena.com.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.921462 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: tinybooks.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.921823 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: planamoveis.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.922165 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: paulakaoana.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.922498 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: expovilhena.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.922841 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: muskintranet.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.923171 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: infonetelecom.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.923498 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: agendamasutti.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.923863 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: politicabrasil.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.924194 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: acerteaquestao.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.924507 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mavieloeducacao.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.924830 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: noticiasrondonia.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.925163 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: jornalbrasileiro.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.925484 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mavieloperformance.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.925830 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: ceramicasantoaugusto.com.br.rondoniaturismo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.927628 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mrragrorepresentacoes.com.mrragrorepresentacoesltda.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.934967 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aprendizadosemlimites.store.peticoesvencedorasofc.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.941926 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: gabivet24h.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.942578 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: blessoriginal.com.br.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.943409 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marmorariasolare.com.br.fluxomarketing.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.984406 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: institutonwa.nwalouwacom.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.984901 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: deniansantos.com.nwalouwacom.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.985231 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: fitconecta.academiausina.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.985943 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: vinculampe.com.br.academiausina.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.990809 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: camilajung.mktcouple.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.991626 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mixpedido.mixpdv.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.992005 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: guianordestino.mixpdv.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.996726 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: sulprimesc.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.997716 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: zyveria.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.998546 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: multicarsc.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.998935 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: marquemarketing360.com.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.999437 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: pontodooleomecanica.com.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:44.999775 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: capitalautocentermecanica.com.br.marquemktdigital.com:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.004161 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.004677 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.store.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.005048 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: conquisteemcasa.online.lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.030601 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rcv.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.030958 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rtdi.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.031286 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rego.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.031604 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: forte.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.031957 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: claret.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.032302 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: portali.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.032637 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mcstilo.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.033003 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: joaorocha.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.033364 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: emonteiro.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.033728 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: robertinho.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.034093 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: parqueprado.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.034426 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: asrealestate.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.034740 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lopeslascasas.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.035081 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: rstlimoveis.com.br.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.035421 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: residencialvilaliviero.inhouseimobiliaria.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.042466 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: aengenhariadolucro.com.br.infoalert.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.076692 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: beautyline2.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.077429 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: thejapanway.com.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.078225 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: shopbestdaily.com.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.079573 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: oferta.roncostop.com.br.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.079943 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: artix.locaiestetica.com.br.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.080320 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: camillasandrini1772124780000.csdesigneweb.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.089978 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: potencialilimitado.com.br.alzirarhein.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.095691 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: volyo.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.101158 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: triviaodontologi.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.146870 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: mastercatu.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.154363 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: lylow.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.245946 2026] [ssl:warn] [pid 131539:tid 131539] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Tue Jul 21 09:00:45.266231 2026] [qos:notice] [pid 131539:tid 131539] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Tue Jul 21 09:00:45.597679 2026] [http2:info] [pid 131539:tid 131539] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Tue Jul 21 09:00:45.603573 2026] [mpm_event:notice] [pid 131539:tid 131539] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Tue Jul 21 09:00:45.603588 2026] [core:notice] [pid 131539:tid 131539] AH00094: Command line: '/usr/sbin/httpd'
[Tue Jul 21 09:00:46.682470 2026] [http2:info] [pid 575426:tid 575426] h2_workers: created with min=128 max=192 idle_ms=600000
[Tue Jul 21 09:00:46.703012 2026] [security2:error] [pid 575426:tid 575560] [client 20.52.136.55:1586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/edit.php"] [unique_id "al9fbnup4_xfiphSr1uhiAAAAAI"]
[Tue Jul 21 09:00:46.703955 2026] [security2:error] [pid 575426:tid 575565] [client 114.119.135.182:49317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vivermaishospital.com.br"] [uri "/wp-content/uploads/2019/07/tomar-sol-parque-ao-ar-livre-mae-filha-1523576873906_v2_900x506.jpg"] [unique_id "al9fbnup4_xfiphSr1uhiwAAAAc"], referer: http://vivermaishospital.com.br/wp-content/uploads/2019/07/tomar-sol-parque-ao-ar-livre-mae-filha-1523576873906_v2_900x506.jpg
[Tue Jul 21 09:00:46.704479 2026] [security2:error] [pid 575426:tid 575567] [client 74.249.245.134:43654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/66.php"] [unique_id "al9fbnup4_xfiphSr1uhjAAAAAk"]
[Tue Jul 21 09:00:46.705221 2026] [security2:error] [pid 575426:tid 575571] [client 74.249.245.134:27187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/403.php"] [unique_id "al9fbnup4_xfiphSr1uhjgAAAA0"]
[Tue Jul 21 09:00:46.705429 2026] [security2:error] [pid 575426:tid 575574] [client 20.151.10.161:63485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9fbnup4_xfiphSr1uhjwAAABA"]
[Tue Jul 21 09:00:46.705477 2026] [security2:error] [pid 575426:tid 575575] [client 20.226.60.151:50332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/goods.php"] [unique_id "al9fbnup4_xfiphSr1uhkAAAABE"]
[Tue Jul 21 09:00:46.705797 2026] [security2:error] [pid 575426:tid 575578] [client 20.151.10.161:51054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-load.php"] [unique_id "al9fbnup4_xfiphSr1uhkQAAABQ"]
[Tue Jul 21 09:00:46.709093 2026] [security2:error] [pid 575426:tid 575582] [client 20.151.10.161:56290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/qterm.php"] [unique_id "al9fbnup4_xfiphSr1uhkwAAABg"]
[Tue Jul 21 09:00:46.721081 2026] [security2:error] [pid 575426:tid 575594] [client 20.220.225.223:42760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/akismet.php"] [unique_id "al9fbnup4_xfiphSr1uhmgAAACQ"]
[Tue Jul 21 09:00:46.721127 2026] [security2:error] [pid 575426:tid 575590] [client 20.220.225.223:34269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/acew67.php"] [unique_id "al9fbnup4_xfiphSr1uhmAAAACA"]
[Tue Jul 21 09:00:46.721171 2026] [security2:error] [pid 575426:tid 575598] [client 20.220.225.223:30851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/hp3.php"] [unique_id "al9fbnup4_xfiphSr1uhnAAAACg"]
[Tue Jul 21 09:00:46.723203 2026] [security2:error] [pid 575426:tid 575583] [client 65.21.113.253:59350] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fbnup4_xfiphSr1uhlAAAABk"]
[Tue Jul 21 09:00:46.844480 2026] [core:error] [pid 575426:tid 575444] [remote 74.7.241.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 09:00:46.844503 2026] [core:error] [pid 575426:tid 575444] [remote 74.7.241.168:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Tue Jul 21 09:00:46.844724 2026] [security2:error] [pid 575426:tid 575619] [client 74.7.241.168:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "cpcalendars.onlinebuyerwebsite.com"] [uri "/___proxy_subdomain_cpcalendars/index.php"] [unique_id "al9fbnup4_xfiphSr1uhsgAAPQ8"]
[Tue Jul 21 09:00:46.855948 2026] [security2:error] [pid 575426:tid 575572] [client 173.252.95.20:56894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fbnup4_xfiphSr1uhwwAAAA4"]
[Tue Jul 21 09:00:46.893226 2026] [security2:error] [pid 575426:tid 575462] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.shopmelhorcompraonline.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al9fbnup4_xfiphSr1uh0gAAFyE"]
[Tue Jul 21 09:00:46.917766 2026] [security2:error] [pid 575426:tid 575464] [remote 37.59.204.140:17232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "foreverconfidence.com"] [uri "/robots.txt"] [unique_id "al9fbnup4_xfiphSr1uh2AAAUiM"]
[Tue Jul 21 09:00:46.918037 2026] [security2:error] [pid 575426:tid 575640] [client 37.59.204.140:17232] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "foreverconfidence.com"] [uri "/robots.txt"] [unique_id "al9fbnup4_xfiphSr1uh2AAAUiM"]
[Tue Jul 21 09:00:46.986612 2026] [security2:error] [pid 575426:tid 575466] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fbnup4_xfiphSr1uh4wAARSU"]
[Tue Jul 21 09:00:46.986880 2026] [security2:error] [pid 575426:tid 575627] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fbnup4_xfiphSr1uh4wAARSU"]
[Tue Jul 21 09:00:47.018341 2026] [security2:error] [pid 575426:tid 575468] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fb3up4_xfiphSr1uh6AAANCc"]
[Tue Jul 21 09:00:47.018562 2026] [security2:error] [pid 575426:tid 575610] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fb3up4_xfiphSr1uh6AAANCc"]
[Tue Jul 21 09:00:47.026133 2026] [security2:error] [pid 575426:tid 575604] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fbnup4_xfiphSr1uhpAAALgY"]
[Tue Jul 21 09:00:47.034947 2026] [security2:error] [pid 575426:tid 575469] [remote 154.61.75.100:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "androapkmod.com"] [uri "/wp-login.php"] [unique_id "al9fb3up4_xfiphSr1uh6gAAHig"]
[Tue Jul 21 09:00:47.107770 2026] [security2:error] [pid 575426:tid 575472] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.shopmelhorcompraonline.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al9fb3up4_xfiphSr1uh8AAADis"]
[Tue Jul 21 09:00:47.137868 2026] [security2:error] [pid 575426:tid 575673] [client 20.151.10.161:56311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/blurbs.php"] [unique_id "al9fb3up4_xfiphSr1uh8QAAAHM"]
[Tue Jul 21 09:00:47.235995 2026] [security2:error] [pid 575426:tid 575616] [client 154.182.128.22:57122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.128.182.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fb3up4_xfiphSr1uiAQAAADo"]
[Tue Jul 21 09:00:47.236190 2026] [security2:error] [pid 575426:tid 575616] [client 154.182.128.22:57122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fb3up4_xfiphSr1uiAQAAADo"]
[Tue Jul 21 09:00:47.261307 2026] [security2:error] [pid 575426:tid 575618] [client 35.148.23.53:9813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.23.148.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learningsociety.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fb3up4_xfiphSr1uh7wAAADw"]
[Tue Jul 21 09:00:47.261540 2026] [security2:error] [pid 575426:tid 575618] [client 35.148.23.53:9813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "learningsociety.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fb3up4_xfiphSr1uh7wAAADw"]
[Tue Jul 21 09:00:47.298054 2026] [log_config:warn] [pid 533360:tid 533580] (32)Broken pipe: [client 189.84.236.98:35052] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 09:00:47.298074 2026] [log_config:warn] [pid 533360:tid 533580] (32)Broken pipe: [client 189.84.236.98:35052] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 09:00:47.321187 2026] [security2:error] [pid 575426:tid 575607] [client 182.189.99.211:47773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fb3up4_xfiphSr1uiDAAAADE"]
[Tue Jul 21 09:00:47.321363 2026] [security2:error] [pid 575426:tid 575607] [client 182.189.99.211:47773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fb3up4_xfiphSr1uiDAAAADE"]
[Tue Jul 21 09:00:47.334128 2026] [security2:error] [pid 575426:tid 575493] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.shopmelhorcompraonline.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al9fb3up4_xfiphSr1uiDQAAXUA"]
[Tue Jul 21 09:00:47.437107 2026] [security2:error] [pid 575426:tid 575612] [client 139.167.208.211:61952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.208.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fb3up4_xfiphSr1uiHwAAADY"]
[Tue Jul 21 09:00:47.437275 2026] [security2:error] [pid 575426:tid 575612] [client 139.167.208.211:61952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fb3up4_xfiphSr1uiHwAAADY"]
[Tue Jul 21 09:00:47.470206 2026] [security2:error] [pid 575426:tid 575630] [client 115.245.198.210:24737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fb3up4_xfiphSr1uiIAAAAEg"]
[Tue Jul 21 09:00:47.470485 2026] [security2:error] [pid 575426:tid 575630] [client 115.245.198.210:24737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fb3up4_xfiphSr1uiIAAAAEg"]
[Tue Jul 21 09:00:47.474314 2026] [security2:error] [pid 575426:tid 575636] [client 20.220.225.223:20873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/ace2.php"] [unique_id "al9fb3up4_xfiphSr1uiIQAAAE4"]
[Tue Jul 21 09:00:47.479467 2026] [security2:error] [pid 575426:tid 575585] [client 20.151.10.161:56261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/v543.php"] [unique_id "al9fb3up4_xfiphSr1uiIwAAABs"]
[Tue Jul 21 09:00:47.482586 2026] [security2:error] [pid 575426:tid 575621] [client 113.22.144.139:53421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fb3up4_xfiphSr1uiIgAAAD8"]
[Tue Jul 21 09:00:47.482791 2026] [security2:error] [pid 575426:tid 575621] [client 113.22.144.139:53421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fb3up4_xfiphSr1uiIgAAAD8"]
[Tue Jul 21 09:00:47.664765 2026] [security2:error] [pid 575426:tid 575566] [client 20.220.225.223:34209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/bscclapb.php"] [unique_id "al9fb3up4_xfiphSr1uiKAAAAAg"]
[Tue Jul 21 09:00:47.668781 2026] [security2:error] [pid 575426:tid 575502] [remote 35.233.163.26:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.shopmelhorcompraonline.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al9fb3up4_xfiphSr1uiKgAAbUk"]
[Tue Jul 21 09:00:47.777321 2026] [security2:error] [pid 575426:tid 575663] [client 173.252.95.29:65016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fb3up4_xfiphSr1uiMAAAAGk"]
[Tue Jul 21 09:00:47.851244 2026] [security2:error] [pid 575426:tid 575662] [client 65.21.113.253:56472] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fb3up4_xfiphSr1uiFwAAAGg"]
[Tue Jul 21 09:00:48.002120 2026] [security2:error] [pid 575426:tid 575597] [client 20.151.10.161:56317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/w3lls.php"] [unique_id "al9fcHup4_xfiphSr1uiOAAAACc"]
[Tue Jul 21 09:00:48.008560 2026] [proxy:error] [pid 575426:tid 575607] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:48.008598 2026] [proxy_http:error] [pid 575426:tid 575607] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:48.009250 2026] [proxy:error] [pid 575426:tid 575607] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:48.009274 2026] [proxy_http:error] [pid 575426:tid 575607] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:48.118391 2026] [security2:error] [pid 575426:tid 575591] [client 20.220.225.223:34230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/else1.php"] [unique_id "al9fcHup4_xfiphSr1uiPwAAACE"]
[Tue Jul 21 09:00:48.335377 2026] [security2:error] [pid 575426:tid 575568] [client 20.151.10.161:55617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/wp-ws68.php"] [unique_id "al9fcHup4_xfiphSr1uiRQAAAAo"]
[Tue Jul 21 09:00:48.456927 2026] [security2:error] [pid 575426:tid 575515] [remote 15.235.27.218:64174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "foreverconfidence.com"] [uri "/"] [unique_id "al9fcHup4_xfiphSr1uiSAAANlY"]
[Tue Jul 21 09:00:48.457147 2026] [security2:error] [pid 575426:tid 575612] [client 15.235.27.218:64174] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "foreverconfidence.com"] [uri "/"] [unique_id "al9fcHup4_xfiphSr1uiSAAANlY"]
[Tue Jul 21 09:00:48.508356 2026] [security2:error] [pid 575426:tid 575575] [client 103.59.206.240:31231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fcHup4_xfiphSr1uiSQAAABE"]
[Tue Jul 21 09:00:48.508541 2026] [security2:error] [pid 575426:tid 575575] [client 103.59.206.240:31231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fcHup4_xfiphSr1uiSQAAABE"]
[Tue Jul 21 09:00:48.508951 2026] [security2:error] [pid 575426:tid 575588] [client 20.220.225.223:20897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wellnesstrade.shop"] [uri "/ms.php"] [unique_id "al9fcHup4_xfiphSr1uiSgAAAB4"]
[Tue Jul 21 09:00:48.518131 2026] [proxy:error] [pid 575426:tid 575516] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:48.518217 2026] [proxy_http:error] [pid 575426:tid 575516] [remote 205.210.31.156:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.cromobelo.com.br/
[Tue Jul 21 09:00:48.519731 2026] [proxy:error] [pid 575426:tid 575516] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:48.519796 2026] [proxy_http:error] [pid 575426:tid 575516] [remote 205.210.31.156:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.cromobelo.com.br/
[Tue Jul 21 09:00:48.557671 2026] [proxy:error] [pid 575426:tid 575635] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:48.557725 2026] [proxy_http:error] [pid 575426:tid 575635] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:48.558453 2026] [proxy:error] [pid 575426:tid 575635] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:48.558487 2026] [proxy_http:error] [pid 575426:tid 575635] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:48.612113 2026] [security2:error] [pid 575426:tid 575627] [client 114.198.138.124:50045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fcHup4_xfiphSr1uiUAAAAEU"]
[Tue Jul 21 09:00:48.612251 2026] [security2:error] [pid 575426:tid 575627] [client 114.198.138.124:50045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fcHup4_xfiphSr1uiUAAAAEU"]
[Tue Jul 21 09:00:48.613349 2026] [security2:error] [pid 575426:tid 575566] [client 20.220.225.223:34242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/tkikikoko.php"] [unique_id "al9fcHup4_xfiphSr1uiUQAAAAg"]
[Tue Jul 21 09:00:48.647483 2026] [security2:error] [pid 575426:tid 575613] [client 20.151.10.161:56291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/xyn.php"] [unique_id "al9fcHup4_xfiphSr1uiUgAAADc"]
[Tue Jul 21 09:00:48.712193 2026] [security2:error] [pid 575426:tid 575518] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fcHup4_xfiphSr1uiUwAAc1k"]
[Tue Jul 21 09:00:48.712342 2026] [security2:error] [pid 575426:tid 575673] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fcHup4_xfiphSr1uiUwAAc1k"]
[Tue Jul 21 09:00:48.737155 2026] [security2:error] [pid 575426:tid 575608] [client 128.127.105.184:41032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9fcHup4_xfiphSr1uiVgAAADI"]
[Tue Jul 21 09:00:48.737267 2026] [security2:error] [pid 575426:tid 575608] [client 128.127.105.184:41032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9fcHup4_xfiphSr1uiVgAAADI"]
[Tue Jul 21 09:00:48.811996 2026] [security2:error] [pid 575426:tid 575680] [client 74.249.245.134:27228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/max.php"] [unique_id "al9fcHup4_xfiphSr1uiXAAAAHo"]
[Tue Jul 21 09:00:48.921160 2026] [security2:error] [pid 575426:tid 575577] [client 173.252.95.23:55126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fcHup4_xfiphSr1uiXwAAABM"]
[Tue Jul 21 09:00:48.961223 2026] [security2:error] [pid 575426:tid 575637] [client 59.95.197.55:50693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fcHup4_xfiphSr1uiYAAAAE8"]
[Tue Jul 21 09:00:48.961334 2026] [security2:error] [pid 575426:tid 575637] [client 59.95.197.55:50693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fcHup4_xfiphSr1uiYAAAAE8"]
[Tue Jul 21 09:00:49.016333 2026] [security2:error] [pid 575426:tid 575643] [client 117.235.80.45:54800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.80.235.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fcXup4_xfiphSr1uiZQAAAFU"]
[Tue Jul 21 09:00:49.016472 2026] [security2:error] [pid 575426:tid 575643] [client 117.235.80.45:54800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fcXup4_xfiphSr1uiZQAAAFU"]
[Tue Jul 21 09:00:49.023612 2026] [security2:error] [pid 575426:tid 575670] [client 74.7.175.150:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bluezmodular.com.br"] [uri "/index.php"] [unique_id "al9fbnup4_xfiphSr1uhyAAAAHA"]
[Tue Jul 21 09:00:49.024609 2026] [security2:error] [pid 575426:tid 575584] [client 74.7.175.150:43728] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bluezmodular.com.br"] [uri "/robots.txt"] [unique_id "al9fbnup4_xfiphSr1uhqQAAGgo"]
[Tue Jul 21 09:00:49.028552 2026] [security2:error] [pid 575426:tid 575523] [remote 103.82.22.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "compranawebprodutos.com"] [uri "/wp-login.php"] [unique_id "al9fcXup4_xfiphSr1uiZgAAJ14"]
[Tue Jul 21 09:00:49.267215 2026] [security2:error] [pid 575426:tid 575601] [client 20.151.10.161:56229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/green3.php"] [unique_id "al9fcXup4_xfiphSr1uibgAAACs"]
[Tue Jul 21 09:00:49.283441 2026] [security2:error] [pid 575426:tid 575594] [client 91.192.10.181:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.joseantoniopereira1782236338228.0711679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al9fcXup4_xfiphSr1uicQAAACQ"]
[Tue Jul 21 09:00:49.318525 2026] [security2:error] [pid 575426:tid 575646] [client 20.226.60.151:62648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/100.php"] [unique_id "al9fcXup4_xfiphSr1uicwAAAFg"]
[Tue Jul 21 09:00:49.407889 2026] [security2:error] [pid 575426:tid 575531] [remote 45.3.51.111:33119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.51.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9fcXup4_xfiphSr1uidwAACWY"]
[Tue Jul 21 09:00:49.469328 2026] [security2:error] [pid 575426:tid 575630] [client 65.21.113.253:59350] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fcXup4_xfiphSr1uieAAAAEg"]
[Tue Jul 21 09:00:49.555041 2026] [security2:error] [pid 575426:tid 575605] [client 20.220.225.223:34292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9fcXup4_xfiphSr1uiegAAAC8"]
[Tue Jul 21 09:00:49.598435 2026] [security2:error] [pid 575426:tid 575633] [client 20.151.10.161:56215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/ccs.php"] [unique_id "al9fcXup4_xfiphSr1uifgAAAEs"]
[Tue Jul 21 09:00:49.760823 2026] [proxy:error] [pid 575426:tid 575664] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:49.760893 2026] [proxy_http:error] [pid 575426:tid 575664] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:49.761402 2026] [proxy:error] [pid 575426:tid 575664] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:49.761436 2026] [proxy_http:error] [pid 575426:tid 575664] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:49.925301 2026] [proxy:error] [pid 575426:tid 575663] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:49.925371 2026] [proxy_http:error] [pid 575426:tid 575663] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:49.925907 2026] [proxy:error] [pid 575426:tid 575663] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:49.925939 2026] [proxy_http:error] [pid 575426:tid 575663] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:50.014252 2026] [security2:error] [pid 575426:tid 575675] [client 91.192.10.181:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.joseantoniopereira1782236338228.0711679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/backend/.env"] [unique_id "al9fcnup4_xfiphSr1uijwAAAHU"]
[Tue Jul 21 09:00:50.015186 2026] [proxy:error] [pid 575426:tid 575586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:50.015239 2026] [proxy_http:error] [pid 575426:tid 575586] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:50.015333 2026] [proxy:error] [pid 575426:tid 575657] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:50.015373 2026] [proxy_http:error] [pid 575426:tid 575657] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:50.015696 2026] [proxy:error] [pid 575426:tid 575586] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:50.015722 2026] [proxy_http:error] [pid 575426:tid 575586] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:50.016061 2026] [proxy:error] [pid 575426:tid 575657] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:50.016097 2026] [proxy_http:error] [pid 575426:tid 575657] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:50.016358 2026] [proxy:error] [pid 575426:tid 575653] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:50.016387 2026] [proxy_http:error] [pid 575426:tid 575653] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:50.016859 2026] [proxy:error] [pid 575426:tid 575653] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:50.016883 2026] [proxy_http:error] [pid 575426:tid 575653] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:50.020515 2026] [security2:error] [pid 575426:tid 575676] [client 91.192.10.181:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.joseantoniopereira1782236338228.0711679.meusitehostgator.com.br"] [uri "/___proxy_subdomain_cpcalendars/api/.env"] [unique_id "al9fcnup4_xfiphSr1uikgAAAHY"]
[Tue Jul 21 09:00:50.023335 2026] [proxy:error] [pid 575426:tid 575580] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:50.023377 2026] [proxy_http:error] [pid 575426:tid 575580] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:50.023867 2026] [proxy:error] [pid 575426:tid 575580] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:50.023891 2026] [proxy_http:error] [pid 575426:tid 575580] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:50.065834 2026] [proxy:error] [pid 575426:tid 575640] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:50.065913 2026] [proxy_http:error] [pid 575426:tid 575640] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:50.066719 2026] [proxy:error] [pid 575426:tid 575640] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:00:50.066764 2026] [proxy_http:error] [pid 575426:tid 575640] [client 91.192.10.181:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:00:50.152453 2026] [security2:error] [pid 575426:tid 575582] [client 74.249.245.134:12837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/666.php"] [unique_id "al9fcnup4_xfiphSr1uilwAAABg"]
[Tue Jul 21 09:00:50.326626 2026] [security2:error] [pid 575426:tid 575678] [client 20.151.10.161:64129] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.madmoholding.com.br"] [uri "/wordpress/wp-admin/maint/"] [unique_id "al9fcnup4_xfiphSr1uipAAAAHg"]
[Tue Jul 21 09:00:50.555584 2026] [security2:error] [pid 575426:tid 575616] [client 65.21.113.253:58878] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fcnup4_xfiphSr1uilgAAADo"]
[Tue Jul 21 09:00:50.728928 2026] [security2:error] [pid 575426:tid 575574] [client 198.44.157.162:46958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9fcnup4_xfiphSr1uisQAAABA"]
[Tue Jul 21 09:00:50.729046 2026] [security2:error] [pid 575426:tid 575574] [client 198.44.157.162:46958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "treeoflifehealth.online"] [uri "/xmlrpc.php"] [unique_id "al9fcnup4_xfiphSr1uisQAAABA"]
[Tue Jul 21 09:00:50.759019 2026] [security2:error] [pid 575426:tid 575606] [client 20.151.10.161:56274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/ccc.php"] [unique_id "al9fcnup4_xfiphSr1uisgAAADA"]
[Tue Jul 21 09:00:50.782944 2026] [security2:error] [pid 575426:tid 575631] [client 205.185.113.241:41772] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "www.healthsmart.shop.oficialwebsite.com.br"] [uri "/"] [unique_id "al9fcnup4_xfiphSr1uiswAAAEk"]
[Tue Jul 21 09:00:50.809446 2026] [security2:error] [pid 575426:tid 575605] [client 205.185.113.241:41788] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1609"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "www.healthsmart.shop"] [uri "/"] [unique_id "al9fcnup4_xfiphSr1uitAAAAC8"]
[Tue Jul 21 09:00:50.981410 2026] [security2:error] [pid 575426:tid 575573] [client 20.226.60.151:50408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/about.php"] [unique_id "al9fcnup4_xfiphSr1uiuQAAAA8"]
[Tue Jul 21 09:00:51.011325 2026] [security2:error] [pid 575426:tid 575676] [client 194.99.104.35:41944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9fc3up4_xfiphSr1uiugAAAHY"]
[Tue Jul 21 09:00:51.011412 2026] [security2:error] [pid 575426:tid 575676] [client 194.99.104.35:41944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9fc3up4_xfiphSr1uiugAAAHY"]
[Tue Jul 21 09:00:51.128504 2026] [security2:error] [pid 575426:tid 575682] [client 114.119.136.238:52159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "essenceclinicadesaude.com.br"] [uri "/pj-categs/pharmacy"] [unique_id "al9fc3up4_xfiphSr1uivAAAAHw"], referer: https://essenceclinicadesaude.com.br/author/wolmkt/page/1
[Tue Jul 21 09:00:51.212447 2026] [security2:error] [pid 575426:tid 575670] [client 20.151.10.161:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/get.php"] [unique_id "al9fc3up4_xfiphSr1uiwAAAAHA"]
[Tue Jul 21 09:00:51.235293 2026] [log_config:warn] [pid 533360:tid 533528] (32)Broken pipe: [client 201.77.114.45:34113] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log, referer: https://brasilmotoeletrica.com/scooter-eletricas/?utm_medium=paid&utm_source=ig&utm_id=120247816625910549&utm_content=120248966318040549&utm_term=120247819525010549&utm_campaign=120247816625910549&fbclid=PAZXh0bgNhZW0BMABhZGlkAas1zDv_fvVzcnRjBmFwcF9pZA81NjcwNjczNDMzNTI0MjcAAadgMLd8-PrVgkkb-biK7Ac54jDoN0GRkdXuhZpVMSv9plQCznt6RPPK_pBCeA_aem_K-_ty9mO4TLBmQB33atpPQ
[Tue Jul 21 09:00:51.235311 2026] [log_config:warn] [pid 533360:tid 533528] (32)Broken pipe: [client 201.77.114.45:34113] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log, referer: https://brasilmotoeletrica.com/scooter-eletricas/?utm_medium=paid&utm_source=ig&utm_id=120247816625910549&utm_content=120248966318040549&utm_term=120247819525010549&utm_campaign=120247816625910549&fbclid=PAZXh0bgNhZW0BMABhZGlkAas1zDv_fvVzcnRjBmFwcF9pZA81NjcwNjczNDMzNTI0MjcAAadgMLd8-PrVgkkb-biK7Ac54jDoN0GRkdXuhZpVMSv9plQCznt6RPPK_pBCeA_aem_K-_ty9mO4TLBmQB33atpPQ
[Tue Jul 21 09:00:51.235352 2026] [log_config:warn] [pid 533360:tid 533528] (32)Broken pipe: [client 201.77.114.45:34113] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log, referer: https://brasilmotoeletrica.com/scooter-eletricas/?utm_medium=paid&utm_source=ig&utm_id=120247816625910549&utm_content=120248966318040549&utm_term=120247819525010549&utm_campaign=120247816625910549&fbclid=PAZXh0bgNhZW0BMABhZGlkAas1zDv_fvVzcnRjBmFwcF9pZA81NjcwNjczNDMzNTI0MjcAAadgMLd8-PrVgkkb-biK7Ac54jDoN0GRkdXuhZpVMSv9plQCznt6RPPK_pBCeA_aem_K-_ty9mO4TLBmQB33atpPQ
[Tue Jul 21 09:00:51.235356 2026] [log_config:warn] [pid 533360:tid 533528] (32)Broken pipe: [client 201.77.114.45:34113] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log, referer: https://brasilmotoeletrica.com/scooter-eletricas/?utm_medium=paid&utm_source=ig&utm_id=120247816625910549&utm_content=120248966318040549&utm_term=120247819525010549&utm_campaign=120247816625910549&fbclid=PAZXh0bgNhZW0BMABhZGlkAas1zDv_fvVzcnRjBmFwcF9pZA81NjcwNjczNDMzNTI0MjcAAadgMLd8-PrVgkkb-biK7Ac54jDoN0GRkdXuhZpVMSv9plQCznt6RPPK_pBCeA_aem_K-_ty9mO4TLBmQB33atpPQ
[Tue Jul 21 09:00:51.246426 2026] [log_config:warn] [pid 533360:tid 533556] (32)Broken pipe: [client 104.233.8.77:58572] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 09:00:51.246441 2026] [log_config:warn] [pid 533360:tid 533556] (32)Broken pipe: [client 104.233.8.77:58572] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 09:00:51.260258 2026] [security2:error] [pid 575426:tid 575558] [client 20.220.225.223:34282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wp-css.php"] [unique_id "al9fc3up4_xfiphSr1uiwQAAAAA"]
[Tue Jul 21 09:00:51.305022 2026] [security2:error] [pid 575426:tid 575671] [client 173.252.95.0:50580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fc3up4_xfiphSr1uiwgAAAHE"]
[Tue Jul 21 09:00:51.411031 2026] [security2:error] [pid 575426:tid 575593] [client 20.151.10.161:51040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/xwpg.php"] [unique_id "al9fc3up4_xfiphSr1uiwwAAACM"]
[Tue Jul 21 09:00:51.628681 2026] [security2:error] [pid 575426:tid 575651] [client 74.249.245.134:43665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/byp.php"] [unique_id "al9fc3up4_xfiphSr1uiyQAAAF0"]
[Tue Jul 21 09:00:51.736627 2026] [security2:error] [pid 575426:tid 575581] [client 74.249.245.134:27214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/m.php"] [unique_id "al9fc3up4_xfiphSr1uizwAAABc"]
[Tue Jul 21 09:00:51.800803 2026] [security2:error] [pid 575426:tid 575569] [client 117.214.78.59:61584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fc3up4_xfiphSr1ui0QAAAAs"]
[Tue Jul 21 09:00:51.800904 2026] [security2:error] [pid 575426:tid 575569] [client 117.214.78.59:61584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fc3up4_xfiphSr1ui0QAAAAs"]
[Tue Jul 21 09:00:51.843616 2026] [security2:error] [pid 575426:tid 575602] [client 20.151.10.161:56284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/images.php"] [unique_id "al9fc3up4_xfiphSr1ui0gAAACw"]
[Tue Jul 21 09:00:51.949574 2026] [security2:error] [pid 575426:tid 575627] [client 114.119.166.95:57879] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gradiente.com.br"] [uri "/mini-system/gradiente/139/de%20101W%20at%C3%A9%20500W/Conexao%20USB/Bivolt/Preto"] [unique_id "al9fc3up4_xfiphSr1ui1gAAAEU"], referer: https://www.gradiente.com.br/mini-system/139/de%20101W%20at%C3%A9%20500W/Conexao%20USB/Bivolt/Preto?PS=12&map=c%2CproductClusterSearchableIds%2CspecificationFilter_22%2CspecificationFilter_18%2CspecificationFilter_20%2CspecificationFilter_21
[Tue Jul 21 09:00:52.011675 2026] [security2:error] [pid 575426:tid 575620] [client 20.220.225.223:34200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/wp-explorer.php"] [unique_id "al9fdHup4_xfiphSr1ui2AAAAD4"]
[Tue Jul 21 09:00:52.056712 2026] [security2:error] [pid 575426:tid 575685] [client 20.220.225.223:30656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/aa1.php"] [unique_id "al9fdHup4_xfiphSr1ui2QAAAH8"]
[Tue Jul 21 09:00:52.160516 2026] [security2:error] [pid 575426:tid 575656] [client 20.151.10.161:56303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/alls.php"] [unique_id "al9fdHup4_xfiphSr1ui3AAAAGI"]
[Tue Jul 21 09:00:52.343033 2026] [autoindex:error] [pid 575426:tid 575441] [remote 141.51.110.129:27418] AH01276: Cannot serve directory /home4/ciclod61/bahtelecom.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 09:00:52.388495 2026] [security2:error] [pid 575426:tid 575663] [client 65.21.113.253:59350] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fdHup4_xfiphSr1ui4gAAAGk"]
[Tue Jul 21 09:00:52.693847 2026] [lsapi:error] [pid 559070:tid 559102] (70007)The timeout specified has expired: [remote 31.28.0.7:52527] [host avermetais.com.br] mod_lsapi:  Backend spawn failed: timeout exceeded on waiting for reading Notify from client pipe, referer: https://e.mail.ru/
[Tue Jul 21 09:00:52.724688 2026] [security2:error] [pid 575426:tid 575650] [client 168.167.81.163:60260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9fdHup4_xfiphSr1ui7AAAAFw"]
[Tue Jul 21 09:00:52.724806 2026] [security2:error] [pid 575426:tid 575650] [client 168.167.81.163:60260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9fdHup4_xfiphSr1ui7AAAAFw"]
[Tue Jul 21 09:00:52.781271 2026] [security2:error] [pid 575426:tid 575617] [client 41.89.234.2:52877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fdHup4_xfiphSr1ui7wAAADs"]
[Tue Jul 21 09:00:52.781409 2026] [security2:error] [pid 575426:tid 575617] [client 41.89.234.2:52877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fdHup4_xfiphSr1ui7wAAADs"]
[Tue Jul 21 09:00:52.854897 2026] [security2:error] [pid 575426:tid 575592] [client 194.99.104.35:40952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.104.99.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9fdHup4_xfiphSr1ui8QAAACI"]
[Tue Jul 21 09:00:52.854983 2026] [security2:error] [pid 575426:tid 575592] [client 194.99.104.35:40952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lifezen.online"] [uri "/xmlrpc.php"] [unique_id "al9fdHup4_xfiphSr1ui8QAAACI"]
[Tue Jul 21 09:00:52.944156 2026] [security2:error] [pid 575426:tid 575638] [client 103.219.58.100:19707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/ice"] [unique_id "al9fdHup4_xfiphSr1ui8gAAAFA"]
[Tue Jul 21 09:00:52.944547 2026] [security2:error] [pid 575426:tid 575651] [client 20.226.60.151:62036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/about.php"] [unique_id "al9fdHup4_xfiphSr1ui8wAAAF0"]
[Tue Jul 21 09:00:52.945492 2026] [security2:error] [pid 575426:tid 575604] [client 103.219.58.100:28242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/ice"] [unique_id "al9fdHup4_xfiphSr1ui9AAAAC4"]
[Tue Jul 21 09:00:52.993140 2026] [security2:error] [pid 575426:tid 575683] [client 20.151.10.161:51036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/waf.php"] [unique_id "al9fdHup4_xfiphSr1ui-AAAAH0"]
[Tue Jul 21 09:00:53.081071 2026] [security2:error] [pid 575426:tid 575581] [client 74.249.245.134:27268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/click.php"] [unique_id "al9fdXup4_xfiphSr1ui-wAAABc"]
[Tue Jul 21 09:00:53.187141 2026] [security2:error] [pid 575426:tid 575641] [client 114.119.158.18:43815] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.dharmanet.com.br"] [uri "/vajrayana/chagdud.htm"] [unique_id "al9fdXup4_xfiphSr1ui_QAAAFM"], referer: https://dharmalog.com/2002/11/19/o-cortejo-para-rinpoche
[Tue Jul 21 09:00:53.219517 2026] [security2:error] [pid 575426:tid 575563] [client 20.151.10.161:63454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/like.php"] [unique_id "al9fdXup4_xfiphSr1ui_gAAAAU"]
[Tue Jul 21 09:00:53.448856 2026] [security2:error] [pid 575426:tid 575619] [client 74.249.245.134:43693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/date.php"] [unique_id "al9fdXup4_xfiphSr1ujAAAAAD0"]
[Tue Jul 21 09:00:53.459085 2026] [security2:error] [pid 575426:tid 575469] [remote 114.119.136.30:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aud-7.com"] [uri "/good.php"] [unique_id "al9fdXup4_xfiphSr1ujAQAANCg"], referer: https://aud-7.com/good.php?qdfga/r1332201.html
[Tue Jul 21 09:00:53.479896 2026] [security2:error] [pid 575426:tid 575591] [client 65.21.113.253:58888] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fdXup4_xfiphSr1ui-gAAACE"]
[Tue Jul 21 09:00:53.509889 2026] [security2:error] [pid 575426:tid 575630] [client 103.219.58.100:12416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/iou"] [unique_id "al9fdXup4_xfiphSr1ujBwAAAEg"]
[Tue Jul 21 09:00:53.545111 2026] [security2:error] [pid 575426:tid 575631] [client 103.219.58.100:13761] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/iou"] [unique_id "al9fdXup4_xfiphSr1ujCQAAAEk"]
[Tue Jul 21 09:00:53.685377 2026] [security2:error] [pid 575426:tid 575574] [client 173.252.95.21:51842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9fdXup4_xfiphSr1ujCwAAABA"]
[Tue Jul 21 09:00:53.693970 2026] [lsapi:error] [pid 559070:tid 559102] [remote 31.28.0.7:52527] mod_lsapi: [host avermetais.com.br] [req GET /loja/hampton-circular-ii/ HTTP/2.0] Connect to backend failed: spawn backend error, referer: https://e.mail.ru/
[Tue Jul 21 09:00:53.696670 2026] [log_config:warn] [pid 559070:tid 559266] (32)Broken pipe: [client 31.28.0.7:52527] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log, referer: https://e.mail.ru/
[Tue Jul 21 09:00:53.696689 2026] [log_config:warn] [pid 559070:tid 559266] (32)Broken pipe: [client 31.28.0.7:52527] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log, referer: https://e.mail.ru/
[Tue Jul 21 09:00:53.827910 2026] [security2:error] [pid 575426:tid 575588] [client 20.151.10.161:56256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/yyu.php"] [unique_id "al9fdXup4_xfiphSr1ujEAAAAB4"]
[Tue Jul 21 09:00:54.032688 2026] [security2:error] [pid 575426:tid 575666] [client 20.151.10.161:51000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/xstelth.php"] [unique_id "al9fdnup4_xfiphSr1ujFAAAAGw"]
[Tue Jul 21 09:00:54.044014 2026] [security2:error] [pid 575426:tid 575565] [client 103.219.58.100:23034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/pal"] [unique_id "al9fdnup4_xfiphSr1ujFgAAAAc"]
[Tue Jul 21 09:00:54.136582 2026] [security2:error] [pid 575426:tid 575632] [client 103.219.58.100:15664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/pal"] [unique_id "al9fdnup4_xfiphSr1ujHQAAAEo"]
[Tue Jul 21 09:00:54.190530 2026] [security2:error] [pid 575426:tid 575582] [client 20.151.10.161:55555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/by.php"] [unique_id "al9fdnup4_xfiphSr1ujIwAAABg"]
[Tue Jul 21 09:00:54.401818 2026] [security2:error] [pid 575426:tid 575672] [client 20.226.60.151:50420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/admin.php"] [unique_id "al9fdnup4_xfiphSr1ujZQAAAHI"]
[Tue Jul 21 09:00:54.495087 2026] [security2:error] [pid 575426:tid 575618] [client 20.220.225.223:34200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/akismet.php"] [unique_id "al9fdnup4_xfiphSr1ujkgAAADw"]
[Tue Jul 21 09:00:54.573630 2026] [security2:error] [pid 575426:tid 575606] [client 103.219.58.100:11515] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/wal"] [unique_id "al9fdnup4_xfiphSr1ujmgAAADA"]
[Tue Jul 21 09:00:54.579581 2026] [security2:error] [pid 575426:tid 575600] [client 20.220.225.223:30871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/acew67.php"] [unique_id "al9fdnup4_xfiphSr1ujnwAAACo"]
[Tue Jul 21 09:00:54.613336 2026] [security2:error] [pid 575426:tid 575574] [client 74.249.245.134:27307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/lv.php"] [unique_id "al9fdnup4_xfiphSr1ujoQAAABA"]
[Tue Jul 21 09:00:54.737893 2026] [security2:error] [pid 575426:tid 575588] [client 103.219.58.100:30823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "inovamedfortaleza.com.br"] [uri "/wal"] [unique_id "al9fdnup4_xfiphSr1ujpAAAAB4"]
[Tue Jul 21 09:00:54.846492 2026] [security2:error] [pid 575426:tid 575663] [client 74.249.245.134:12015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/pomo.php"] [unique_id "al9fdnup4_xfiphSr1ujrAAAAGk"]
[Tue Jul 21 09:00:54.854192 2026] [security2:error] [pid 575426:tid 575608] [client 114.119.131.206:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.imobiliariasobrado.net.br"] [uri "/imovel/terreno-venda-vila-nova-joinville-sc-v16895"] [unique_id "al9fdnup4_xfiphSr1ujrQAAADI"], referer: https://www.imobiliariasobrado.net.br/
[Tue Jul 21 09:00:55.122569 2026] [security2:error] [pid 575426:tid 575468] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fd3up4_xfiphSr1ujvgAAdSc"]
[Tue Jul 21 09:00:55.122831 2026] [security2:error] [pid 575426:tid 575675] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fd3up4_xfiphSr1ujvgAAdSc"]
[Tue Jul 21 09:00:55.177839 2026] [security2:error] [pid 575426:tid 575595] [client 20.151.10.161:56287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/FAQ.php"] [unique_id "al9fd3up4_xfiphSr1ujwQAAACU"]
[Tue Jul 21 09:00:55.187268 2026] [security2:error] [pid 575426:tid 575638] [client 20.151.10.161:50952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-links.php"] [unique_id "al9fd3up4_xfiphSr1ujwgAAAFA"]
[Tue Jul 21 09:00:55.245911 2026] [security2:error] [pid 575426:tid 575465] [remote 216.73.216.184:15679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemap.xml"] [unique_id "al9fd3up4_xfiphSr1ujxgAASyQ"]
[Tue Jul 21 09:00:55.314834 2026] [security2:error] [pid 575426:tid 575615] [client 113.22.144.139:53962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fd3up4_xfiphSr1ujyAAAADk"]
[Tue Jul 21 09:00:55.315604 2026] [security2:error] [pid 575426:tid 575615] [client 113.22.144.139:53962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fd3up4_xfiphSr1ujyAAAADk"]
[Tue Jul 21 09:00:55.366550 2026] [security2:error] [pid 575426:tid 575634] [client 115.245.198.210:38241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fd3up4_xfiphSr1ujywAAAEw"]
[Tue Jul 21 09:00:55.366698 2026] [security2:error] [pid 575426:tid 575634] [client 115.245.198.210:38241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fd3up4_xfiphSr1ujywAAAEw"]
[Tue Jul 21 09:00:55.395989 2026] [security2:error] [pid 575426:tid 575572] [client 20.226.60.151:50410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/admin.php"] [unique_id "al9fd3up4_xfiphSr1ujzAAAAA4"]
[Tue Jul 21 09:00:55.545127 2026] [security2:error] [pid 575426:tid 575567] [client 216.73.160.39:55405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.160.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reserveseulugar.com.br"] [uri "/wp-login.php"] [unique_id "al9fd3up4_xfiphSr1ujyQAAAAk"]
[Tue Jul 21 09:00:55.552930 2026] [security2:error] [pid 575426:tid 575599] [client 65.21.113.253:59350] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fd3up4_xfiphSr1uj1gAAACk"]
[Tue Jul 21 09:00:55.742649 2026] [security2:error] [pid 575426:tid 575597] [client 182.189.99.211:48335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.99.189.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fd3up4_xfiphSr1uj3QAAACc"]
[Tue Jul 21 09:00:55.742771 2026] [security2:error] [pid 575426:tid 575597] [client 182.189.99.211:48335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "klvviagens.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fd3up4_xfiphSr1uj3QAAACc"]
[Tue Jul 21 09:00:55.827801 2026] [security2:error] [pid 575426:tid 575594] [client 74.249.245.134:27166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/cong.php"] [unique_id "al9fd3up4_xfiphSr1uj4AAAACQ"]
[Tue Jul 21 09:00:55.874000 2026] [security2:error] [pid 575426:tid 575622] [client 20.151.10.161:56272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/coffexium.php"] [unique_id "al9fd3up4_xfiphSr1uj5AAAAEA"]
[Tue Jul 21 09:00:55.926362 2026] [security2:error] [pid 575426:tid 575623] [client 59.95.197.55:51338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fd3up4_xfiphSr1uj5QAAAEE"]
[Tue Jul 21 09:00:55.926491 2026] [security2:error] [pid 575426:tid 575623] [client 59.95.197.55:51338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fd3up4_xfiphSr1uj5QAAAEE"]
[Tue Jul 21 09:00:56.007537 2026] [security2:error] [pid 575426:tid 575571] [client 20.151.10.161:64144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/.well-known/about.php"] [unique_id "al9feHup4_xfiphSr1uj5wAAAA0"]
[Tue Jul 21 09:00:56.260351 2026] [security2:error] [pid 575426:tid 575558] [client 173.252.95.8:43792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.95.252.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9feHup4_xfiphSr1uj7QAAAAA"]
[Tue Jul 21 09:00:56.441675 2026] [security2:error] [pid 575426:tid 575672] [client 20.151.10.161:55636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/red.php"] [unique_id "al9feHup4_xfiphSr1uj9gAAAHI"]
[Tue Jul 21 09:00:56.474434 2026] [security2:error] [pid 575426:tid 575683] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9feHup4_xfiphSr1uj8gAAfTY"]
[Tue Jul 21 09:00:56.588854 2026] [security2:error] [pid 575426:tid 575519] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9feHup4_xfiphSr1ukKgAAdVo"]
[Tue Jul 21 09:00:56.588968 2026] [security2:error] [pid 575426:tid 575675] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9feHup4_xfiphSr1ukKgAAdVo"]
[Tue Jul 21 09:00:56.594224 2026] [security2:error] [pid 575426:tid 575653] [client 65.21.113.253:58900] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9feHup4_xfiphSr1uj7AAAAF8"]
[Tue Jul 21 09:00:56.650678 2026] [security2:error] [pid 575426:tid 575637] [client 20.226.60.151:50385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/themes.php"] [unique_id "al9feHup4_xfiphSr1ukLgAAAE8"]
[Tue Jul 21 09:00:56.845852 2026] [security2:error] [pid 575426:tid 575627] [client 74.249.245.134:12922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/test1.php"] [unique_id "al9feHup4_xfiphSr1ukOgAAAEU"]
[Tue Jul 21 09:00:56.916091 2026] [security2:error] [pid 575426:tid 575628] [client 69.171.230.4:60466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9feHup4_xfiphSr1ukPgAAAEY"]
[Tue Jul 21 09:00:57.003430 2026] [security2:error] [pid 575426:tid 575682] [client 20.151.10.161:51070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/wp-admin/network/plugins.php"] [unique_id "al9feXup4_xfiphSr1ukQQAAAHw"]
[Tue Jul 21 09:00:57.068378 2026] [security2:error] [pid 575426:tid 575580] [client 20.220.225.223:34188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/ace2.php"] [unique_id "al9feXup4_xfiphSr1ukQwAAABY"]
[Tue Jul 21 09:00:57.294631 2026] [security2:error] [pid 575426:tid 575674] [client 20.52.136.55:1753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/166.php"] [unique_id "al9feXup4_xfiphSr1ukSwAAAHQ"]
[Tue Jul 21 09:00:57.347834 2026] [security2:error] [pid 575426:tid 575587] [client 20.151.10.161:63398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9feXup4_xfiphSr1ukTAAAAB0"]
[Tue Jul 21 09:00:57.416745 2026] [security2:error] [pid 575426:tid 575636] [client 139.167.208.211:62575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.208.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9feXup4_xfiphSr1ukTgAAAE4"]
[Tue Jul 21 09:00:57.416850 2026] [security2:error] [pid 575426:tid 575636] [client 139.167.208.211:62575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9feXup4_xfiphSr1ukTgAAAE4"]
[Tue Jul 21 09:00:57.590120 2026] [security2:error] [pid 575426:tid 575651] [client 69.171.230.41:51182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.230.171.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "saude.agendaclique.com.br"] [uri "/webhook/meta_router.php"] [unique_id "al9feXup4_xfiphSr1ukUwAAAF0"]
[Tue Jul 21 09:00:57.743362 2026] [autoindex:error] [pid 575426:tid 575457] [remote 141.51.110.129:50118] AH01276: Cannot serve directory /home4/ciclod61/bahtelecom.com.br/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Tue Jul 21 09:00:57.912223 2026] [security2:error] [pid 575426:tid 575601] [client 154.182.128.22:57572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.128.182.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9feXup4_xfiphSr1ukXQAAACs"]
[Tue Jul 21 09:00:57.912327 2026] [security2:error] [pid 575426:tid 575601] [client 154.182.128.22:57572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9feXup4_xfiphSr1ukXQAAACs"]
[Tue Jul 21 09:00:57.936929 2026] [security2:error] [pid 575426:tid 575570] [client 74.249.245.134:27178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/brand.php"] [unique_id "al9feXup4_xfiphSr1ukXgAAAAw"]
[Tue Jul 21 09:00:58.214456 2026] [security2:error] [pid 575426:tid 575448] [remote 65.111.3.187:52399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.3.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tkcorretoradeseguros.com.br"] [uri "/wp-login.php"] [unique_id "al9fenup4_xfiphSr1ukagAAJhM"]
[Tue Jul 21 09:00:58.216766 2026] [security2:error] [pid 575426:tid 575629] [client 20.226.60.151:50419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/.well-known/about.php"] [unique_id "al9fenup4_xfiphSr1ukbQAAAEc"]
[Tue Jul 21 09:00:58.273452 2026] [security2:error] [pid 575426:tid 575612] [client 65.21.113.253:59350] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fenup4_xfiphSr1ukcAAAADY"]
[Tue Jul 21 09:00:58.297767 2026] [security2:error] [pid 575426:tid 575658] [client 20.151.10.161:56314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al9fenup4_xfiphSr1ukcgAAAGQ"]
[Tue Jul 21 09:00:58.995912 2026] [security2:error] [pid 575426:tid 575564] [client 20.151.10.161:62938] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.madmoholding.com.br"] [uri "/wp-admin/css/"] [unique_id "al9fenup4_xfiphSr1ukfwAAAAY"]
[Tue Jul 21 09:00:59.102001 2026] [log_config:warn] [pid 533360:tid 533526] (32)Broken pipe: [client 36.82.9.97:56694] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --suffix=-bytes_log
[Tue Jul 21 09:00:59.102018 2026] [log_config:warn] [pid 533360:tid 533526] (32)Broken pipe: [client 36.82.9.97:56694] AH00646: Error writing to |/usr/local/cpanel/bin/splitlogs --dir=/etc/apache2/logs/domlogs --main=br1102.hostgator.com.br --mainout=/etc/apache2/logs/access_log
[Tue Jul 21 09:00:59.127725 2026] [security2:error] [pid 575426:tid 575664] [client 103.59.206.240:31259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fe3up4_xfiphSr1ukhAAAAGo"]
[Tue Jul 21 09:00:59.127848 2026] [security2:error] [pid 575426:tid 575664] [client 103.59.206.240:31259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fe3up4_xfiphSr1ukhAAAAGo"]
[Tue Jul 21 09:00:59.137079 2026] [security2:error] [pid 575426:tid 575679] [client 114.198.138.124:50681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fe3up4_xfiphSr1ukhQAAAHk"]
[Tue Jul 21 09:00:59.137158 2026] [security2:error] [pid 575426:tid 575679] [client 114.198.138.124:50681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fe3up4_xfiphSr1ukhQAAAHk"]
[Tue Jul 21 09:00:59.229415 2026] [security2:error] [pid 575426:tid 575555] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fe3up4_xfiphSr1ukhgAAdH4"]
[Tue Jul 21 09:00:59.229561 2026] [security2:error] [pid 575426:tid 575674] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fe3up4_xfiphSr1ukhgAAdH4"]
[Tue Jul 21 09:00:59.264435 2026] [security2:error] [pid 575426:tid 575681] [client 20.226.60.151:62023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/wp-includes/ID3/about.php"] [unique_id "al9fe3up4_xfiphSr1ukigAAAHs"]
[Tue Jul 21 09:00:59.324102 2026] [security2:error] [pid 575426:tid 575613] [client 65.21.113.253:58912] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fenup4_xfiphSr1ukfgAAADc"]
[Tue Jul 21 09:00:59.523982 2026] [security2:error] [pid 575426:tid 575640] [client 117.235.80.45:55330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.80.235.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fe3up4_xfiphSr1ukjQAAAFI"]
[Tue Jul 21 09:00:59.524125 2026] [security2:error] [pid 575426:tid 575640] [client 117.235.80.45:55330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fe3up4_xfiphSr1ukjQAAAFI"]
[Tue Jul 21 09:00:59.568307 2026] [security2:error] [pid 575426:tid 575593] [client 74.249.245.134:43679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/fw.php"] [unique_id "al9fe3up4_xfiphSr1ukjgAAACM"]
[Tue Jul 21 09:00:59.624085 2026] [security2:error] [pid 575426:tid 575648] [client 20.151.10.161:51041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluxactive.wayhealth.store.oficialwebsite.com.br"] [uri "/aaa.php"] [unique_id "al9fe3up4_xfiphSr1uklAAAAFo"]
[Tue Jul 21 09:00:59.641458 2026] [security2:error] [pid 575426:tid 575572] [client 74.249.245.134:27160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/atomlib.php"] [unique_id "al9fe3up4_xfiphSr1uklwAAAA4"]
[Tue Jul 21 09:00:59.718583 2026] [security2:error] [pid 575426:tid 575610] [client 114.119.152.86:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sobradoimoveis.com.br"] [uri "/imovel/apartamento-3-quartos-com-garagem-19207m2-venda-centro-joinville-sc-gr794"] [unique_id "al9fe3up4_xfiphSr1ukmAAAADQ"], referer: http://www.sobradoimoveis.com.br/
[Tue Jul 21 09:01:00.449809 2026] [security2:error] [pid 575426:tid 575658] [client 54.39.136.92:23488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "cenem.com.br"] [uri "/robots.txt"] [unique_id "al9ffHup4_xfiphSr1ukqgAAAGQ"]
[Tue Jul 21 09:01:00.449911 2026] [security2:error] [pid 575426:tid 575658] [client 54.39.136.92:23488] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cenem.com.br"] [uri "/robots.txt"] [unique_id "al9ffHup4_xfiphSr1ukqgAAAGQ"]
[Tue Jul 21 09:01:00.594140 2026] [security2:error] [pid 575426:tid 575663] [client 20.226.60.151:62061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/wefile.php"] [unique_id "al9ffHup4_xfiphSr1ukrAAAAGk"]
[Tue Jul 21 09:01:00.674940 2026] [security2:error] [pid 575426:tid 575444] [remote 114.119.135.245:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "androapkmod.com"] [uri "/real-driving-2-ultimate-car-simulator/"] [unique_id "al9ffHup4_xfiphSr1uksQAAbQ8"], referer: https://androapkmod.com/speed-%e2%80%8b%e2%80%8bmotor-dash/
[Tue Jul 21 09:01:00.916737 2026] [security2:error] [pid 575426:tid 575672] [client 47.237.92.86:60750] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mgugc.online"] [uri "/"] [unique_id "al9ffHup4_xfiphSr1ukuQAAAHI"]
[Tue Jul 21 09:01:00.918350 2026] [security2:error] [pid 575426:tid 575664] [client 20.151.10.161:56298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/footer.php"] [unique_id "al9ffHup4_xfiphSr1ukugAAAGo"]
[Tue Jul 21 09:01:00.995685 2026] [security2:error] [pid 575426:tid 575583] [client 20.151.10.161:63369] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.madmoholding.com.br"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al9ffHup4_xfiphSr1ukuwAAABk"]
[Tue Jul 21 09:01:01.278670 2026] [security2:error] [pid 575426:tid 575674] [client 74.249.245.134:43680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/fm.php"] [unique_id "al9ffXup4_xfiphSr1ukvwAAAHQ"]
[Tue Jul 21 09:01:01.756492 2026] [security2:error] [pid 575426:tid 575572] [client 185.213.175.37:24142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "budhug.com.br"] [uri "/config.json"] [unique_id "al9ffXup4_xfiphSr1ukzQAAAA4"]
[Tue Jul 21 09:01:01.756645 2026] [security2:error] [pid 575426:tid 575572] [client 185.213.175.37:24142] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "budhug.com.br"] [uri "/config.json"] [unique_id "al9ffXup4_xfiphSr1ukzQAAAA4"]
[Tue Jul 21 09:01:01.830489 2026] [security2:error] [pid 575426:tid 575651] [client 20.226.60.151:62069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al9ffXup4_xfiphSr1ukzgAAAF0"]
[Tue Jul 21 09:01:01.838131 2026] [security2:error] [pid 575426:tid 575655] [client 65.21.113.253:59350] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9ffXup4_xfiphSr1ukzwAAAGE"]
[Tue Jul 21 09:01:01.850489 2026] [security2:error] [pid 575426:tid 575562] [client 54.38.147.155:50908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "cenem.com.br"] [uri "/"] [unique_id "al9ffXup4_xfiphSr1uk0QAAAAQ"]
[Tue Jul 21 09:01:01.850672 2026] [security2:error] [pid 575426:tid 575562] [client 54.38.147.155:50908] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cenem.com.br"] [uri "/"] [unique_id "al9ffXup4_xfiphSr1uk0QAAAAQ"]
[Tue Jul 21 09:01:02.291073 2026] [security2:error] [pid 575426:tid 575605] [client 117.214.78.59:62046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9ffnup4_xfiphSr1uk3AAAAC8"]
[Tue Jul 21 09:01:02.291208 2026] [security2:error] [pid 575426:tid 575605] [client 117.214.78.59:62046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9ffnup4_xfiphSr1uk3AAAAC8"]
[Tue Jul 21 09:01:02.680269 2026] [security2:error] [pid 575426:tid 575577] [client 20.52.136.55:1581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/8.php"] [unique_id "al9ffnup4_xfiphSr1uk6gAAABM"]
[Tue Jul 21 09:01:02.735490 2026] [security2:error] [pid 575426:tid 575618] [client 128.127.105.184:44750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.105.127.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9ffnup4_xfiphSr1uk6wAAADw"]
[Tue Jul 21 09:01:02.735621 2026] [security2:error] [pid 575426:tid 575618] [client 128.127.105.184:44750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vitrineoriginal.online"] [uri "/xmlrpc.php"] [unique_id "al9ffnup4_xfiphSr1uk6wAAADw"]
[Tue Jul 21 09:01:02.748799 2026] [security2:error] [pid 575426:tid 575638] [client 168.167.81.163:60063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9ffnup4_xfiphSr1uk7AAAAFA"]
[Tue Jul 21 09:01:02.748978 2026] [security2:error] [pid 575426:tid 575638] [client 168.167.81.163:60063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9ffnup4_xfiphSr1uk7AAAAFA"]
[Tue Jul 21 09:01:02.921338 2026] [security2:error] [pid 575426:tid 575658] [client 65.21.113.253:55870] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9ffnup4_xfiphSr1uk4gAAAGQ"]
[Tue Jul 21 09:01:02.941392 2026] [security2:error] [pid 575426:tid 575639] [client 114.119.135.202:36163] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tragaseushow.com.br"] [uri "/2015/08/12/inspiration-rural-living/"] [unique_id "al9ffnup4_xfiphSr1uk8gAAAFE"], referer: https://tragaseushow.com.br/2015/08/12/inspiration-rural-living/
[Tue Jul 21 09:01:02.976960 2026] [security2:error] [pid 575426:tid 575657] [client 74.249.245.134:11976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/ini.php"] [unique_id "al9ffnup4_xfiphSr1uk9AAAAGM"]
[Tue Jul 21 09:01:03.262345 2026] [security2:error] [pid 575426:tid 575579] [client 20.151.10.161:56305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/wp-content/index.php"] [unique_id "al9ff3up4_xfiphSr1uk_wAAABU"]
[Tue Jul 21 09:01:03.409614 2026] [security2:error] [pid 575426:tid 575608] [client 114.119.154.67:53229] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acaiofficial.com.br"] [uri "/wp-includes/sodium_compat/src/Core32/"] [unique_id "al9ff3up4_xfiphSr1ulBgAAADI"], referer: https://acaiofficial.com.br/wp-includes/sodium_compat/src/Core32/ChaCha20/
[Tue Jul 21 09:01:03.500262 2026] [security2:error] [pid 575426:tid 575644] [client 20.220.225.223:34206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tracyacademy.com.br"] [uri "/ms.php"] [unique_id "al9ff3up4_xfiphSr1ulCQAAAFY"]
[Tue Jul 21 09:01:03.666470 2026] [security2:error] [pid 575426:tid 575651] [client 20.151.10.161:64184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/pucci.php"] [unique_id "al9ff3up4_xfiphSr1ulDwAAAF0"]
[Tue Jul 21 09:01:04.184807 2026] [security2:error] [pid 575426:tid 575663] [client 74.249.245.134:12847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/themes.php"] [unique_id "al9fgHup4_xfiphSr1ulHwAAAGk"]
[Tue Jul 21 09:01:04.185469 2026] [security2:error] [pid 575426:tid 575659] [client 20.226.60.151:50427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/wp-admin/css/colour.php"] [unique_id "al9fgHup4_xfiphSr1ulIAAAAGU"]
[Tue Jul 21 09:01:04.315989 2026] [security2:error] [pid 575426:tid 575599] [client 114.119.157.239:44201] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ellosemijoias.com.br"] [uri "/product-category/pulseiras/pulseiras-joia-na-prata/page/2/"] [unique_id "al9fgHup4_xfiphSr1ulIQAAACk"], referer: https://www.ellosemijoias.com.br/product-category/pulseiras/pulseiras-joia-na-prata/page/2/?orderby=price
[Tue Jul 21 09:01:04.321132 2026] [security2:error] [pid 575426:tid 575581] [client 41.89.234.2:53804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.234.89.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fgHup4_xfiphSr1ulIgAAABc"]
[Tue Jul 21 09:01:04.321329 2026] [security2:error] [pid 575426:tid 575581] [client 41.89.234.2:53804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fgHup4_xfiphSr1ulIgAAABc"]
[Tue Jul 21 09:01:04.553273 2026] [security2:error] [pid 575426:tid 575564] [client 65.21.113.253:59350] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fgHup4_xfiphSr1ulLwAAAAY"]
[Tue Jul 21 09:01:05.117746 2026] [security2:error] [pid 575426:tid 575572] [client 20.220.225.223:30893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/bscclapb.php"] [unique_id "al9fgXup4_xfiphSr1ulRQAAAA4"]
[Tue Jul 21 09:01:05.158978 2026] [security2:error] [pid 575426:tid 575616] [client 74.249.245.134:11979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/dropdown.php"] [unique_id "al9fgXup4_xfiphSr1ulRwAAADo"]
[Tue Jul 21 09:01:05.178861 2026] [security2:error] [pid 575426:tid 575601] [client 37.140.223.16:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "arenaalphaville.com"] [uri "/"] [unique_id "al9fgXup4_xfiphSr1ulSAAAACs"]
[Tue Jul 21 09:01:05.603277 2026] [security2:error] [pid 575426:tid 575593] [client 65.21.113.253:55884] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fgXup4_xfiphSr1ulSgAAACM"]
[Tue Jul 21 09:01:05.621424 2026] [security2:error] [pid 575426:tid 575487] [remote 37.232.59.241:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.59.232.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fgXup4_xfiphSr1ulUwAAZTo"]
[Tue Jul 21 09:01:05.621572 2026] [security2:error] [pid 575426:tid 575659] [client 37.232.59.241:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "confiancedigital.com"] [uri "/xmlrpc.php"] [unique_id "al9fgXup4_xfiphSr1ulUwAAZTo"]
[Tue Jul 21 09:01:05.700204 2026] [security2:error] [pid 575426:tid 575619] [client 37.140.223.16:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "arenaalphaville.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al9fgXup4_xfiphSr1ulVwAAAD0"]
[Tue Jul 21 09:01:05.830885 2026] [security2:error] [pid 575426:tid 575563] [client 114.119.137.122:29645] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "powerflats.com.br"] [uri "/page/63/"] [unique_id "al9fgXup4_xfiphSr1ulXAAAAAU"], referer: https://powerflats.com.br/page/61/
[Tue Jul 21 09:01:05.963890 2026] [security2:error] [pid 575426:tid 575591] [client 20.151.10.161:55629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/zoro.php"] [unique_id "al9fgXup4_xfiphSr1ulXwAAACE"]
[Tue Jul 21 09:01:06.161540 2026] [security2:error] [pid 575426:tid 575588] [client 114.119.142.15:24743] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bcsenepol.com.br"] [uri "/tag/photography"] [unique_id "al9fgnup4_xfiphSr1ulaQAAAB4"], referer: https://bcsenepol.com.br/tag/photography
[Tue Jul 21 09:01:06.233456 2026] [security2:error] [pid 575426:tid 575589] [client 74.249.245.134:12012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/wp-links.php"] [unique_id "al9fgnup4_xfiphSr1ulagAAAB8"]
[Tue Jul 21 09:01:06.246420 2026] [security2:error] [pid 575426:tid 575630] [client 20.220.225.223:30859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/else1.php"] [unique_id "al9fgnup4_xfiphSr1ulawAAAEg"]
[Tue Jul 21 09:01:06.368613 2026] [security2:error] [pid 575426:tid 575609] [client 37.140.223.16:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "arenaalphaville.com"] [uri "/media/system/js/core.js"] [unique_id "al9fgnup4_xfiphSr1ulbwAAADM"]
[Tue Jul 21 09:01:06.392314 2026] [security2:error] [pid 575426:tid 575581] [client 59.95.197.55:51817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.197.95.59.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fgnup4_xfiphSr1ulcAAAABc"]
[Tue Jul 21 09:01:06.393066 2026] [security2:error] [pid 575426:tid 575581] [client 59.95.197.55:51817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dealspark.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fgnup4_xfiphSr1ulcAAAABc"]
[Tue Jul 21 09:01:06.544106 2026] [security2:error] [pid 575426:tid 575597] [client 20.151.10.161:63387] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.madmoholding.com.br"] [uri "/wp-includes/blocks/details/"] [unique_id "al9fgnup4_xfiphSr1uldwAAACc"]
[Tue Jul 21 09:01:06.663170 2026] [security2:error] [pid 575426:tid 575572] [client 20.226.60.151:62608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/8.php"] [unique_id "al9fgnup4_xfiphSr1uleQAAAA4"]
[Tue Jul 21 09:01:06.788571 2026] [security2:error] [pid 575426:tid 575569] [client 20.52.136.55:1563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/ws38.php"] [unique_id "al9fgnup4_xfiphSr1ulfgAAAAs"]
[Tue Jul 21 09:01:06.828367 2026] [security2:error] [pid 575426:tid 575678] [client 114.119.151.165:63723] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.simleite.com.br"] [uri "/arquivosAnais/arquivo21"] [unique_id "al9fgnup4_xfiphSr1ulfwAAAHg"], referer: https://www.simleite.com.br/anais/iii-simleite-48
[Tue Jul 21 09:01:06.830187 2026] [security2:error] [pid 575426:tid 575660] [client 113.22.144.139:54537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.144.22.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fgnup4_xfiphSr1ulgAAAAGY"]
[Tue Jul 21 09:01:06.832016 2026] [security2:error] [pid 575426:tid 575660] [client 113.22.144.139:54537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bavos.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fgnup4_xfiphSr1ulgAAAAGY"]
[Tue Jul 21 09:01:06.964435 2026] [security2:error] [pid 575426:tid 575611] [client 20.220.225.223:30907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/tkikikoko.php"] [unique_id "al9fgnup4_xfiphSr1ulgwAAADU"]
[Tue Jul 21 09:01:06.989434 2026] [security2:error] [pid 575426:tid 575653] [client 65.21.113.253:59350] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fgnup4_xfiphSr1ulhgAAAF8"]
[Tue Jul 21 09:01:07.092763 2026] [security2:error] [pid 575426:tid 575675] [client 114.119.157.43:28131] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.politicabrasil.com.br"] [uri "/post/pol%C3%ADticos-do-cear%C3%A1-se-preparam-para-mudar-de-partido-e-seguir-bolsonaro"] [unique_id "al9fg3up4_xfiphSr1uljwAAAHU"], referer: https://www.politicabrasil.com.br/blogentrelinhas/tags/governo-bolsonaro
[Tue Jul 21 09:01:07.114947 2026] [security2:error] [pid 575426:tid 575529] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fg3up4_xfiphSr1ulkAAAXWQ"]
[Tue Jul 21 09:01:07.115072 2026] [security2:error] [pid 575426:tid 575651] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fg3up4_xfiphSr1ulkAAAXWQ"]
[Tue Jul 21 09:01:07.167112 2026] [security2:error] [pid 575426:tid 575619] [client 20.151.10.161:56262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/admin.php"] [unique_id "al9fg3up4_xfiphSr1ulkgAAAD0"]
[Tue Jul 21 09:01:07.214094 2026] [security2:error] [pid 575426:tid 575640] [client 115.245.198.210:52385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.245.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fg3up4_xfiphSr1ullAAAAFI"]
[Tue Jul 21 09:01:07.214220 2026] [security2:error] [pid 575426:tid 575640] [client 115.245.198.210:52385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newpostapp.com"] [uri "/xmlrpc.php"] [unique_id "al9fg3up4_xfiphSr1ullAAAAFI"]
[Tue Jul 21 09:01:07.518884 2026] [security2:error] [pid 575426:tid 575669] [client 8.213.218.56:33036] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mgugc.online"] [uri "/"] [unique_id "al9fg3up4_xfiphSr1ulnAAAAG8"]
[Tue Jul 21 09:01:07.588579 2026] [security2:error] [pid 575426:tid 575578] [client 74.249.245.134:43664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/xmrlpc.php"] [unique_id "al9fg3up4_xfiphSr1ulngAAABQ"]
[Tue Jul 21 09:01:07.999349 2026] [security2:error] [pid 575426:tid 575586] [client 139.167.208.211:63218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.208.167.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fg3up4_xfiphSr1ulqQAAABw"]
[Tue Jul 21 09:01:07.999489 2026] [security2:error] [pid 575426:tid 575586] [client 139.167.208.211:63218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pedido-online.net"] [uri "/xmlrpc.php"] [unique_id "al9fg3up4_xfiphSr1ulqQAAABw"]
[Tue Jul 21 09:01:08.061749 2026] [security2:error] [pid 575426:tid 575571] [client 65.21.113.253:55886] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fg3up4_xfiphSr1ulpAAAAA0"]
[Tue Jul 21 09:01:08.067745 2026] [security2:error] [pid 575426:tid 575638] [client 20.151.10.161:63469] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.madmoholding.com.br"] [uri "/wp-includes/blocks/audio/"] [unique_id "al9fhHup4_xfiphSr1ulqgAAAFA"]
[Tue Jul 21 09:01:08.295164 2026] [security2:error] [pid 575426:tid 575597] [client 2800:cd0:7109:5a00:1897:7f82:1d42:321f:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "403"] [hostname "drasumaiajacob.com"] [uri "/xmlrpc.php"] [unique_id "al9fhHup4_xfiphSr1ulrgAAJ28"]
[Tue Jul 21 09:01:08.385133 2026] [security2:error] [pid 575426:tid 575653] [client 20.226.60.151:62016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/wp-content/admin.php"] [unique_id "al9fhHup4_xfiphSr1ulugAAAF8"]
[Tue Jul 21 09:01:08.709067 2026] [security2:error] [pid 575426:tid 575616] [client 154.182.128.22:58023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.128.182.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fhHup4_xfiphSr1ulxwAAADo"]
[Tue Jul 21 09:01:08.709398 2026] [security2:error] [pid 575426:tid 575616] [client 154.182.128.22:58023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pexbrasil.com"] [uri "/xmlrpc.php"] [unique_id "al9fhHup4_xfiphSr1ulxwAAADo"]
[Tue Jul 21 09:01:08.809495 2026] [security2:error] [pid 575426:tid 575680] [client 20.151.10.161:55622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/greap.php"] [unique_id "al9fhHup4_xfiphSr1ulzAAAAHo"]
[Tue Jul 21 09:01:09.254048 2026] [security2:error] [pid 575426:tid 575652] [client 103.173.21.219:53273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.21.173.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eduflow.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fhXup4_xfiphSr1ul0wAAAF4"]
[Tue Jul 21 09:01:09.254214 2026] [security2:error] [pid 575426:tid 575652] [client 103.173.21.219:53273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eduflow.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fhXup4_xfiphSr1ul0wAAAF4"]
[Tue Jul 21 09:01:09.303947 2026] [security2:error] [pid 575426:tid 575564] [client 20.151.10.161:56192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/177.php"] [unique_id "al9fhXup4_xfiphSr1ul2AAAAAY"]
[Tue Jul 21 09:01:09.320964 2026] [security2:error] [pid 575426:tid 575565] [client 65.21.113.253:59350] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fhXup4_xfiphSr1ul2QAAAAc"]
[Tue Jul 21 09:01:09.353221 2026] [security2:error] [pid 575426:tid 575643] [client 74.249.245.134:27192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ia.bavos.com.br"] [uri "/0x.php"] [unique_id "al9fhXup4_xfiphSr1ul2gAAAFU"]
[Tue Jul 21 09:01:09.679283 2026] [security2:error] [pid 575426:tid 575582] [client 114.198.138.124:51325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.138.198.114.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fhXup4_xfiphSr1ul5AAAABg"]
[Tue Jul 21 09:01:09.679360 2026] [security2:error] [pid 575426:tid 575582] [client 114.198.138.124:51325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "houseincorporacoes.com"] [uri "/xmlrpc.php"] [unique_id "al9fhXup4_xfiphSr1ul5AAAABg"]
[Tue Jul 21 09:01:09.725435 2026] [security2:error] [pid 575426:tid 575538] [remote 106.222.250.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.250.222.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fhXup4_xfiphSr1ul5QAAE20"]
[Tue Jul 21 09:01:09.725549 2026] [security2:error] [pid 575426:tid 575577] [client 106.222.250.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vidrosprovetro.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fhXup4_xfiphSr1ul5QAAE20"]
[Tue Jul 21 09:01:10.034516 2026] [security2:error] [pid 575426:tid 575560] [client 117.235.80.45:56106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.80.235.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fhnup4_xfiphSr1ul7wAAAAI"]
[Tue Jul 21 09:01:10.034634 2026] [security2:error] [pid 575426:tid 575560] [client 117.235.80.45:56106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "abbaprotect.com"] [uri "/xmlrpc.php"] [unique_id "al9fhnup4_xfiphSr1ul7wAAAAI"]
[Tue Jul 21 09:01:10.131291 2026] [security2:error] [pid 575426:tid 575641] [client 20.151.10.161:56260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/199.php"] [unique_id "al9fhnup4_xfiphSr1ul8QAAAFM"]
[Tue Jul 21 09:01:10.184762 2026] [security2:error] [pid 575426:tid 575683] [client 65.21.113.253:40602] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fhnup4_xfiphSr1ul7gAAAH0"]
[Tue Jul 21 09:01:10.224129 2026] [security2:error] [pid 575426:tid 575440] [remote 100.42.189.89:52342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "precisosolucao.com.br"] [uri "/wp-login.php"] [unique_id "al9fhnup4_xfiphSr1ul9wAAVgs"]
[Tue Jul 21 09:01:10.379983 2026] [security2:error] [pid 575426:tid 575621] [client 74.249.245.134:12804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/htaccess.php"] [unique_id "al9fhnup4_xfiphSr1ul_QAAAD8"]
[Tue Jul 21 09:01:10.622410 2026] [security2:error] [pid 575426:tid 575596] [client 20.220.225.223:30866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/wp-Blogs.php"] [unique_id "al9fhnup4_xfiphSr1ul_wAAACY"]
[Tue Jul 21 09:01:10.767973 2026] [security2:error] [pid 575426:tid 575599] [client 20.226.60.151:50380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/f6.php"] [unique_id "al9fhnup4_xfiphSr1umBQAAACk"]
[Tue Jul 21 09:01:10.844463 2026] [security2:error] [pid 575426:tid 575670] [client 103.59.206.240:31371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.206.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fhnup4_xfiphSr1umCgAAAHA"]
[Tue Jul 21 09:01:10.844620 2026] [security2:error] [pid 575426:tid 575670] [client 103.59.206.240:31371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "happynbox.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fhnup4_xfiphSr1umCgAAAHA"]
[Tue Jul 21 09:01:10.947524 2026] [security2:error] [pid 575426:tid 575564] [client 20.151.10.161:56318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.lupipet.com.br"] [uri "/file52.php"] [unique_id "al9fhnup4_xfiphSr1umDwAAAAY"]
[Tue Jul 21 09:01:11.142738 2026] [security2:error] [pid 575426:tid 575578] [client 20.220.225.223:58393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.kettlebellevolution.com.br"] [uri "/wp-css.php"] [unique_id "al9fh3up4_xfiphSr1umEwAAABQ"]
[Tue Jul 21 09:01:11.221960 2026] [security2:error] [pid 575426:tid 575591] [client 20.151.10.161:64253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.madmoholding.com.br"] [uri "/wp-temp.php"] [unique_id "al9fh3up4_xfiphSr1umFQAAACE"]
[Tue Jul 21 09:01:11.246021 2026] [security2:error] [pid 575426:tid 575585] [client 65.21.113.253:40608] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "transitoaberto.com.br"] [uri "/index.php"] [unique_id "al9fhnup4_xfiphSr1umDQAAABs"]
[Tue Jul 21 09:01:11.727252 2026] [security2:error] [pid 575426:tid 575683] [client 74.249.245.134:12806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/readme.php"] [unique_id "al9fh3up4_xfiphSr1umJQAAAH0"]
[Tue Jul 21 09:01:11.926148 2026] [security2:error] [pid 575426:tid 575664] [client 168.167.81.163:61044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.81.167.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9fh3up4_xfiphSr1umMQAAAGo"]
[Tue Jul 21 09:01:11.926253 2026] [security2:error] [pid 575426:tid 575664] [client 168.167.81.163:61044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bordignonconsultoria.com"] [uri "/xmlrpc.php"] [unique_id "al9fh3up4_xfiphSr1umMQAAAGo"]
[Tue Jul 21 09:01:11.950137 2026] [security2:error] [pid 575426:tid 575652] [client 114.119.155.2:43501] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ssvistorias.com.br"] [uri "/www.ssvistorias.com.br/inspecao-estruturas-industriais"] [unique_id "al9fh3up4_xfiphSr1umMwAAAF4"], referer: https://ssvistorias.com.br/www.ssvistorias.com.br/inspecao-estruturas-industriais
[Tue Jul 21 09:01:12.510516 2026] [proxy:error] [pid 575426:tid 575640] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:01:12.510585 2026] [proxy_http:error] [pid 575426:tid 575640] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:01:12.511276 2026] [proxy:error] [pid 575426:tid 575640] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:01:12.511303 2026] [proxy_http:error] [pid 575426:tid 575640] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:01:12.766775 2026] [security2:error] [pid 575426:tid 575665] [client 74.7.228.59:45968] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "siteecommerceshop.com"] [uri "/index.php"] [unique_id "al9fiHup4_xfiphSr1umbAAAa0o"]
[Tue Jul 21 09:01:12.795925 2026] [security2:error] [pid 575426:tid 575622] [client 117.214.78.59:62504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.78.214.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fiHup4_xfiphSr1umcAAAAEA"]
[Tue Jul 21 09:01:12.796083 2026] [security2:error] [pid 575426:tid 575622] [client 117.214.78.59:62504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "4inteligencia.com"] [uri "/xmlrpc.php"] [unique_id "al9fiHup4_xfiphSr1umcAAAAEA"]
[Tue Jul 21 09:01:12.906708 2026] [proxy:error] [pid 575426:tid 575602] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:01:12.906800 2026] [proxy_http:error] [pid 575426:tid 575602] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:01:12.908259 2026] [proxy:error] [pid 575426:tid 575602] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:01:12.908304 2026] [proxy_http:error] [pid 575426:tid 575602] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:01:12.995024 2026] [security2:error] [pid 575426:tid 575671] [client 20.226.60.151:62052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "protetordegraxa.com.br"] [uri "/inputs.php"] [unique_id "al9fiHup4_xfiphSr1umlgAAAHE"]
[Tue Jul 21 09:01:13.005273 2026] [security2:error] [pid 575426:tid 575579] [client 65.21.113.253:59350] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "transitoaberto.com.br"] [uri "/redirect.asp"] [unique_id "al9fiXup4_xfiphSr1umlwAAABU"]
[Tue Jul 21 09:01:13.294407 2026] [security2:error] [pid 575426:tid 575617] [client 74.249.245.134:12905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.simleite.com.br"] [uri "/403.php"] [unique_id "al9fiXup4_xfiphSr1umnAAAADs"]
[Tue Jul 21 09:01:13.314678 2026] [security2:error] [pid 575426:tid 575542] [remote 216.73.216.184:15679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rkcentroautomotivoo.com.br"] [uri "/sitemap.xml"] [unique_id "al9fiXup4_xfiphSr1umngAAOXE"]
[Tue Jul 21 09:01:13.432287 2026] [proxy:error] [pid 575426:tid 575641] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:01:13.432367 2026] [proxy_http:error] [pid 575426:tid 575641] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:01:13.433771 2026] [proxy:error] [pid 575426:tid 575641] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Tue Jul 21 09:01:13.433835 2026] [proxy_http:error] [pid 575426:tid 575641] [client 35.233.163.26:0] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Tue Jul 21 09:01:13.461726 2026] [security2:error] [pid 575426:tid 575624] [client 198.44.157.162:41828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9fiXup4_xfiphSr1umogAAAEI"]
[Tue Jul 21 09:01:13.461875 2026] [security2:error] [pid 575426:tid 575624] [client 198.44.157.162:41828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oscctvvperuibe.online"] [uri "/xmlrpc.php"] [unique_id "al9fiXup4_xfiphSr1umogAAAEI"]
[Tue Jul 21 09:01:13.539118 2026] [security2:error] [pid 575426:tid 575562] [client 20.52.136.55:1566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.136.52.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ruralab.com.br"] [uri "/a7.php"] [unique_id "al9fiXup4_xfiphSr1umowAAAAQ"]
[Tue Jul 21 09:01:13.642086 2026] [security2:error] [pid 575426:tid 575635] [client 198.44.157.162:57362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9fiXup4_xfiphSr1umpwAAAE0"]
[Tue Jul 21 09:01:13.642195 2026] [security2:error] [pid 575426:tid 575635] [client 198.44.157.162:57362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "weightloss-review.shop"] [uri "/xmlrpc.php"] [unique_id "al9fiXup4_xfiphSr1umpwAAAE0"]
[Tue Jul 21 09:01:13.815195 2026] [security2:error] [pid 575426:tid 575546] [remote 209.42.21.221:36090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "escoladaseguranca.com.br"] [uri "/wp-login.php"] [unique_id "al9fiXup4_xfiphSr1umrgAAUHU"]
[Tue Jul 21 09:01:13.831581 2026] [security2:error] [pid 575426:tid 575583] [client 35.233.163.26:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.163.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.suzanferreirabritoba1782418711695.0711679.meusitehostgator.com.br"] [uri "/xmlrpc.php"] [unique_id "al9fiXup4_xfiphSr1umswAAABk"]